Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3166-1

Опубликовано: 21 июл. 2026
Источник: suse-cvrf

Описание

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues

The following security issues were fixed:

  • CVE-2023-20585: iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603).
  • CVE-2025-71302: drm/panthor: fix for dma-fence safe access rules (bsc#1264837).
  • CVE-2026-31479: drm/xe: always keep track of remap prev/next (bsc#1262765).
  • CVE-2026-31503: udp: Fix wildcard bind conflict check when using hash2 (bsc#1263077).
  • CVE-2026-43019: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync (bsc#1264003).
  • CVE-2026-43057: net: mpls: error out if inner headers are not set (bsc#1264056).
  • CVE-2026-43092: xsk: validate MTU against usable frame size on bind (bsc#1264270).
  • CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545).
  • CVE-2026-43157: octeontx2-af: CGX: fix bitmap leaks (bsc#1264624).
  • CVE-2026-43167: xfrm: always flush state and policy upon NETDEV_UNREGISTER event (bsc#1264580).
  • CVE-2026-43191: drm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35 (bsc#1264548).
  • CVE-2026-43194: net: consume xmit errors of GSO frames (bsc#1264304).
  • CVE-2026-43199: net/mlx5e: Fix 'scheduling while atomic' in IPsec MAC address query (bsc#1264556).
  • CVE-2026-43204: ASoC: qcom: q6asm: handle the responses after closing (bsc#1264531).
  • CVE-2026-43205: dpaa2-switch: validate num_ifs to prevent out-of-bounds write (bsc#1264328).
  • CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544).
  • CVE-2026-43240: ima: verify the previous kernel's IMA buffer lies in addressable RAM (bsc#1264386).
  • CVE-2026-43244: kcm: fix zero-frag skb in frag_list on partial sendmsg error (bsc#1264321).
  • CVE-2026-43248: vhost: move vdpa group bound check to vhost_vdpa (bsc#1264302).
  • CVE-2026-43253: iommu/amd: move wait_on_sem() out of spinlock (bsc#1260593 bsc#1264419).
  • CVE-2026-43260: bnxt_en: Fix RSS context delete logic (bsc#1264429).
  • CVE-2026-43294: drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels (bsc#1264853).
  • CVE-2026-43304: libceph: define and enforce CEPH_MAX_KEY_LEN (bsc#1264993).
  • CVE-2026-43320: drm/amd/display: Fix dsc eDP issue (bsc#1264987).
  • CVE-2026-43337: drm/amd/display: Fix NULL pointer dereference in dcn401_init_hw() (bsc#1265112).
  • CVE-2026-43353: i3c: mipi-i3c-hci: Fix race in DMA ring dequeue (bsc#1265089).
  • CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079).
  • CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744).
  • CVE-2026-43445: e1000/e1000e: Fix leak in DMA error cleanup (bsc#1265041).
  • CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023).
  • CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794).
  • CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142).
  • CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (bsc#1264997).
  • CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790).
  • CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw->wq (bsc#1264978).
  • CVE-2026-43473: scsi: mpi3mr: Add NULL checks when resetting request and reply queues (bsc#1264731).
  • CVE-2026-43496: net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1266000).
  • CVE-2026-45839: bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() (bsc#1266399).
  • CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458).
  • CVE-2026-45858: ext4: subdivide EXT4_EXT_DATA_VALID1 (bsc#1266773).
  • CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883).
  • CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893).
  • CVE-2026-45922: RDMA/mlx5: Fix memory leak in GET_DATA_DIRECT_SYSFS_PATH handler (bsc#1266805).
  • CVE-2026-45981: s390/cio: Fix device lifecycle handling in css_alloc_subchannel() (bsc#1267204).
  • CVE-2026-45987: KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (bsc#1267213).
  • CVE-2026-45994: ibmasm: fix OOB reads in command_file_write due to missing size checks (bsc#1267432).
  • CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740).
  • CVE-2026-46023: dm mirror: fix integer overflow in create_dirty_log() (bsc#1267449).
  • CVE-2026-46027: net/smc: avoid early lgr access in smc_clc_wait_msg (bsc#1266744).
  • CVE-2026-46040: inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails (bsc#1267472).
  • CVE-2026-46046: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (bsc#1266726).
  • CVE-2026-46050: md/raid10: fix deadlock with check operation and nowait requests (bsc#1266686).
  • CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360).
  • CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494).
  • CVE-2026-46059: KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN (bsc#1267495).
  • CVE-2026-46064: ibmasm: fix heap over-read in ibmasm_send_i2o_message() (bsc#1267497).
  • CVE-2026-46068: crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx (bsc#1267592).
  • CVE-2026-46086: net: bridge: use a stable FDB dst snapshot in RCU readers (bsc#1267524).
  • CVE-2026-46089: zram: do not forget to endio for partial discard requests (bsc#1267445).
  • CVE-2026-46099: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (bsc#1266722).
  • CVE-2026-46102: net: strparser: fix skb_head leak in strp_abort_strp() (bsc#1267502).
  • CVE-2026-46132: net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo (bsc#1267616).
  • CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838).
  • CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493).
  • CVE-2026-46191: fbcon: Avoid OOB font access if console rotation fails (bsc#1267690).
  • CVE-2026-46207: vsock/virtio: fix length and offset in tap skb for split packets (bsc#1267691).
  • CVE-2026-46216: drm/xe/hdcp: Add NULL check for media_gt in (bsc#1267234).
  • CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618).
  • CVE-2026-46249: octeontx2-af: Fix PF driver crash with kexec kernel booting (bsc#1267683).
  • CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop (bsc#1267992).
  • CVE-2026-46321: tun: free page on short-frame rejection in tun_xdp_one() (bsc#1268024).
  • CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994).
  • CVE-2026-52915: netfilter: ip6t_hbh: reject oversized option lists (bsc#1269001).
  • CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036).
  • CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989).
  • CVE-2026-52953: iommu/vt-d: Fix oops due to out of scope access (bsc#1269133).
  • CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159).
  • CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172).
  • CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174).
  • CVE-2026-52961: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size (bsc#1269129).
  • CVE-2026-52981: neigh: let neigh_xmit take skb ownership (bsc#1269254).
  • CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193).
  • CVE-2026-52995: net/rds: zero per-item info buffer before handing it to visitors (bsc#1269124).
  • CVE-2026-53003: pppoe: drop PFC frames (bsc#1269111).
  • CVE-2026-53004: sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks (bsc#1269106).
  • CVE-2026-53009: ice: fix double-free of tx_buf skb (bsc#1269098).
  • CVE-2026-53013: macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF (bsc#1269095).
  • CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151).
  • CVE-2026-53035: bpf, sockmap: Fix af_unix iter deadlock (bsc#1269190).
  • CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389).
  • CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392).
  • CVE-2026-53049: gfs2: add some missing log locking (bsc#1269646).
  • CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188).
  • CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164).
  • CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690).
  • CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (bsc#1269700).
  • CVE-2026-53086: net: bcmgenet: fix racing timeout handler (bsc#1269537).
  • CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs (bsc#1269532).
  • CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups (bsc#1269262).
  • CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768).
  • CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories (bsc#1269645).
  • CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710).
  • CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795).
  • CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake (bsc#1269886).
  • CVE-2026-53186: RDMA/srp: bound SRP_RSP sense copy by the received length (bsc#1269663).
  • CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986).
  • CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use (bsc#1269680).
  • CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer (bsc#1269587).
  • CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset (bsc#1269989).
  • CVE-2026-53218: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (bsc#1269273).
  • CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997).
  • CVE-2026-53225: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() (bsc#1269711).
  • CVE-2026-53227: net: openvswitch: fix possible kfree_skb of ERR_PTR (bsc#1269877).
  • CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (bsc#1269691).
  • CVE-2026-53239: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (bsc#1269677).
  • CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (bsc#1269675).
  • CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988).
  • CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992).
  • CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993).
  • CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails (bsc#1269230).
  • CVE-2026-53268: netfilter: conntrack_irc: fix possible out-of-bounds read (bsc#1269257).
  • CVE-2026-53272: erofs: fix use-after-free on sbi->sync_decompress (bsc#1269809).
  • CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (bsc#1269651).
  • CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED (bsc#1269527).
  • CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814).
  • CVE-2026-53355: net: rds: clear i_sends on setup unwind (bsc#1270249).
  • CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257).
  • CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270302).
  • CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271366).

The following non security issues were fixed:

  • ALSA: hda: conexant: Remove mic bias threshold override (git-fixes).
  • ALSA: hda: Fix cached processing coefficient verbs (git-fixes).
  • ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (git-fixes).
  • ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() (git-fixes).
  • ASoC: cs42l43: Correct report for forced microphone jack (git-fixes).
  • ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (git-fixes).
  • ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (git-fixes).
  • batman-adv: access unicast_ttvn skb->data only after skb realloc (git-fixes).
  • batman-adv: bla: reacquire gw address after skb realloc (git-fixes).
  • batman-adv: dat: acquire ARP hw source only after skb realloc (git-fixes).
  • batman-adv: dat: ensure accessible eth_hdr proto field (git-fixes).
  • batman-adv: gw: acquire ethernet header only after skb realloc (git-fixes).
  • Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (git-fixes).
  • Bluetooth: bnep: pin L2CAP connection during netdev registration (git-fixes).
  • Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (git-fixes).
  • Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() (git-fixes).
  • Bluetooth: fix UAF in bt_accept_dequeue() (git-fixes).
  • Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (git-fixes).
  • Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (git-fixes).
  • Bluetooth: ISO: fix malformed ISO_END/CONT handling (git-fixes).
  • Bluetooth: L2CAP: validate option length before reading conf opt value (git-fixes).
  • Bluetooth: MGMT: Fix adv monitor add failure cleanup (git-fixes).
  • Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (git-fixes).
  • bnxt_en: Add a timeout parameter to bnxt_hwrm_port_ts_query() (bsc#1264180).
  • bnxt_en: Add is_ts_pkt field to struct bnxt_sw_tx_bd (bsc#1264180).
  • bnxt_en: Add new TX timestamp completion definitions (bsc#1264180).
  • bnxt_en: Add TX timestamp completion logic (bsc#1264180).
  • bnxt_en: Allow some TX packets to be unprocessed in NAPI (bsc#1264180).
  • bnxt_en: fix module unload sequence (bsc#1264180).
  • bnxt_en: Fix PTP firmware timeout parameter (bsc#1264180).
  • bnxt_en: improve TX timestamping FIFO configuration (bsc#1264180).
  • bnxt_en: Increase the max total outstanding PTP TX packets to 4 (bsc#1264180).
  • bnxt_en: Let bnxt_stamp_tx_skb() return error code (bsc#1264180).
  • bnxt_en: Refactor all PTP TX timestamp fields into a struct (bsc#1264180).
  • bnxt_en: Remove an impossible condition check for PTP TX pending SKB (bsc#1264180).
  • bnxt_en: Remove atomic operations on ptp->tx_avail (bsc#1264180).
  • bnxt_en: Retry PTP TX timestamp from FW for 1 second (bsc#1264180).
  • bnxt_en: silence clang build warning (bsc#1264180).
  • bpf: Disambiguate SCALAR register state output in verifier logs (bsc#1271249).
  • crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (stable-fixes).
  • crypto: qat - Return pointer directly in adf_ctl_alloc_resources (stable-fixes).
  • drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (git-fixes).
  • drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (git-fixes).
  • drm/amd/pm: fix amdgpu_pm_info power display units (git-fixes).
  • drm/amd/pm: fix smu13 power limit range calculation (git-fixes).
  • drm/amdgpu: fix aperture mapping leak (git-fixes).
  • drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (git-fixes).
  • drm/gfx10: Program DB_RING_CONTROL (git-fixes).
  • drm/i915/bios: range check LFP Data Block panel_type2 (git-fixes).
  • drm/i915/gem: Do not leak siblings[] on proto context error (git-fixes).
  • drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (git-fixes).
  • drm/i915: Return NULL on error in active_instance (git-fixes).
  • drm/imagination: Fix double call to drm_sched_entity_fini() (git-fixes).
  • drm/imagination: fix error checking of pvr_vm_context_lookup() (git-fixes).
  • drm/imagination: Fix returned size for DRM_IOCTL_PVR_DEV_QUERY (git-fixes).
  • drm/imagination: Fix user array stride in pvr_set_uobj_array() (git-fixes).
  • drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick() (git-fixes).
  • drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced (git-fixes).
  • drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom() (git-fixes).
  • drm/panthor: Interrupt group start/resumption if group_bind_locked() fails (git-fixes).
  • drm/v3d: Reject invalid indirect BO handle in indirect CSD setup (git-fixes).
  • drm/virtio: bound EDID block reads to the response buffer (git-fixes).
  • drm/xe/hw_engine: Fix double-free of managed BO in error path (git-fixes).
  • drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays (git-fixes).
  • drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() (git-fixes).
  • drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds (git-fixes).
  • drm/xe: remove duplicate <kunit/test-bug.h> include (git-fixes).
  • fbdev: efifb: fix memory leak in efifb_probe() (git-fixes).
  • fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (stable-fixes).
  • fbdev: fix use-after-free in store_modes() (stable-fixes).
  • fbdev: modedb: fix a possible UAF in fb_find_mode() (stable-fixes).
  • git_sort: Add workqueue maintainer tree.
  • git_sort: Update nf-next branch.
  • gpio-f7188x: Add support for NCT6126D version B (git-fixes).
  • gpio: htc-egpio: use managed gpiochip registration (git-fixes).
  • gpio: mvebu: fail probe if gpiochip registration fails (git-fixes).
  • gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (git-fixes).
  • gpios: palmas: add .get_direction() op (git-fixes).
  • HID: letsketch: fix UAF on inrange_timer at driver unbind (git-fixes).
  • HID: lg-g15: cancel pending work on remove to fix a use-after-free (git-fixes).
  • HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (git-fixes).
  • hwmon: (asus_atk0110) Check package count before accessing element (git-fixes).
  • hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (git-fixes).
  • hwmon: (occ) unregister sysfs devices outside occ lock (git-fixes).
  • hwmon: adm1275: Prevent reading uninitialized stack (git-fixes).
  • i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue (git-fixes).
  • i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring (git-fixes).
  • iio: accel: bmc150: clamp the device-reported FIFO frame count (git-fixes).
  • iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (git-fixes).
  • iio: adc: lpc32xx: Initialize completion before requesting IRQ (git-fixes).
  • iio: adc: spear: Initialize completion before requesting IRQ (git-fixes).
  • iio: adc: ti-ads124s08: Return reset GPIO lookup errors (git-fixes).
  • iio: event: Fix event FIFO reset race (git-fixes).
  • iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (git-fixes).
  • iio: imu: st_lsm6dsx: deselect shub page before reading whoami (git-fixes).
  • iio: light: al3010: fix incorrect scale for the highest gain range (git-fixes).
  • iio: light: gp2ap002: fix runtime PM leak on read error (git-fixes).
  • iio: light: tsl2591: return actual error from probe IRQ failure (git-fixes).
  • Input: maplemouse - fix NULL pointer dereference in open() (git-fixes).
  • Input: mms114 - fix multi-touch slot corruption (git-fixes).
  • io_uring/kbuf: fix missing BUF_MORE for incremental buffers at EOF (bsc#1261250).
  • io_uring/kbuf: propagate BUF_MORE through early buffer commit path (bsc#1261250).
  • io_uring/poll: ensure EPOLL_ONESHOT is propagated for EPOLL_URING_WAKE (git-fixes bsc#1261250 bsc#1271287).
  • iommu/amd: serialize sequence allocation under concurrent TLB invalidations (git-fixes).
  • ipvs: Move defense_work to system_dfl_long_wq (bsc#1257605).
  • ixgbe: reduce number of reads when getting OROM data (bsc#1269637).
  • KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050).
  • KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050).
  • KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050).
  • KVM: x86: Fix shadow paging use-after-free due to unexpected role (git-fixes).
  • mm/vmstat: defer the refresh_zone_stat_thresholds after all CPUs bringup (bsc#1270042 bsc#1270396).
  • mm: Do not allocate shrinker info with cgroup.memory=nokmem (bsc#1256564).
  • net/handshake: do not send request when the socket is closed (bsc#1251942).
  • net: mana: Sync page pool RX frags for CPU (git-fixes).
  • net: mana: Validate the packet length reported by the NIC (git-fixes).
  • net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (git-fixes).
  • net: usb: lan78xx: disable VLAN filter in promiscuous mode (git-fixes).
  • net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (git-fixes).
  • net: wwan: iosm: bound device offsets in the MUX downlink decoder (git-fixes).
  • page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches (bsc#1261562).
  • pinctrl: meson: restore non-sleeping GPIO access (git-fixes).
  • ppc/fadump: invoke kmsg_dump in fadump panic path (bsc#1270226 ltc#218302).
  • regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (git-fixes).
  • s390/ap: Externalize AP bus specific bitmap reading function (jsc#PED-15897).
  • s390/pkey: Check length in pkey_pckmo handler implementation (bsc#1270268).
  • s390/pkey: Check length in PKEY_VERIFYPROTK ioctl (bsc#1270263).
  • s390/vfio-ap: Add sysfs attr, ap_config, to export mdev state (jsc#PED-15897).
  • s390/vfio-ap: Add write support to sysfs attr ap_config (jsc#PED-15897).
  • s390/vfio-ap: Driver feature advertisement (jsc#PED-15897).
  • s390/vfio-ap: Ignore duplicate link requests in vfio_ap_mdev_link_queue (jsc#PED-15897).
  • scripts/submit_branch: do submission right after upload.
  • sctp: validate embedded address parameter length (git-fixes).
  • selftests/alsa: Fix memory leak in find_controls error path (git-fixes).
  • selftests/bpf: Add uprobe_multi to gen_tar target (bsc#1271248).
  • selftests/bpf: Make align selftests more robust (bsc#1271249).
  • serial: 8250_omap: clear rx_running on zero-length DMA completes (git-fixes).
  • serial: msm: Disable DMA for kernel console UART (git-fixes).
  • staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (git-fixes).
  • staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (git-fixes).
  • staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (git-fixes).
  • staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (git-fixes).
  • staging: rtl8723bs: fix OOB write in HT_caps_handler() (git-fixes).
  • staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (git-fixes).
  • tools: hv: Fix cross-compilation (git-fixes).
  • tpm: Make the TPM character devices non-seekable (git-fixes).
  • usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (git-fixes).
  • USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (git-fixes).
  • usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (git-fixes).
  • usb: dwc3: run gadget disconnect from sleepable suspend context (git-fixes).
  • usb: free iso schedules on failed submit (git-fixes).
  • usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (git-fixes).
  • usb: gadget: f_printer: take kref only for successful open (git-fixes).
  • USB: idmouse: fix use-after-free on disconnect race (git-fixes).
  • USB: iowarrior: fix use-after-free on disconnect (git-fixes).
  • USB: ldusb: fix use-after-free on disconnect race (git-fixes).
  • USB: legousbtower: fix use-after-free on disconnect race (git-fixes).
  • USB: misc: uss720: unregister parport on probe failure (git-fixes).
  • usb: mtu3: unmap request DMA on queue failure (git-fixes).
  • USB: serial: digi_acceleport: fix broken rx after throttle (git-fixes).
  • USB: serial: digi_acceleport: fix hard lockup on disconnect (git-fixes).
  • USB: serial: digi_acceleport: fix write buffer corruption (git-fixes).
  • USB: serial: keyspan_pda: fix information leak (git-fixes).
  • usb: sl811-hcd: disable controller wakeup on remove (git-fixes).
  • USB: storage: include US_FL_NO_SAME in quirks mask (git-fixes).
  • usb: typec: anx7411: use devm_pm_runtime_enable() (git-fixes).
  • usb: typec: class: drop PD lookup reference (git-fixes).
  • usb: typec: tcpm: Fix VDM type for Enter Mode commands (git-fixes).
  • usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (git-fixes).
  • usb: typec: ucsi: cancel pending work on system suspend (git-fixes).
  • usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (git-fixes).
  • usb: typec: ucsi: Invert DisplayPort role assignment (git-fixes).
  • usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (git-fixes).
  • USB: ulpi: fix memory leak on registration failure (git-fixes).
  • USB: usb-storage: ene_ub6250: restore media-ready check (git-fixes).
  • usb: xhci: Fix sleep in atomic context in xhci_free_streams() (git-fixes).
  • usbip: tools: support SuperSpeedPlus devices (git-fixes).
  • usbip: vudc: fix NULL deref in vep_dequeue() (git-fixes).
  • usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (git-fixes).
  • wifi: iwlwifi: mvm: fix race condition in PTP removal (stable-fixes).
  • wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (stable-fixes).
  • wifi: mt76: mt7921: avoid undesired changes of the preset regulatory domain (stable-fixes).

Список пакетов

Container bci/bci-sle15-kernel-module-devel:latest
kernel-default-devel-6.4.0-150700.53.73.2
kernel-devel-6.4.0-150700.53.73.1
kernel-macros-6.4.0-150700.53.73.1
kernel-syms-6.4.0-150700.53.73.1
SUSE Linux Enterprise High Availability Extension 15 SP7
cluster-md-kmp-default-6.4.0-150700.53.73.2
dlm-kmp-default-6.4.0-150700.53.73.2
gfs2-kmp-default-6.4.0-150700.53.73.2
ocfs2-kmp-default-6.4.0-150700.53.73.2
SUSE Linux Enterprise Live Patching 15 SP7
kernel-default-livepatch-6.4.0-150700.53.73.2
kernel-default-livepatch-devel-6.4.0-150700.53.73.2
kernel-livepatch-6_4_0-150700_53_73-default-1-150700.15.3.4
SUSE Linux Enterprise Module for Basesystem 15 SP7
kernel-64kb-6.4.0-150700.53.73.2
kernel-64kb-devel-6.4.0-150700.53.73.2
kernel-default-6.4.0-150700.53.73.2
kernel-default-base-6.4.0-150700.53.73.2.150700.17.41.4
kernel-default-devel-6.4.0-150700.53.73.2
kernel-devel-6.4.0-150700.53.73.1
kernel-macros-6.4.0-150700.53.73.1
kernel-zfcpdump-6.4.0-150700.53.73.2
SUSE Linux Enterprise Module for Development Tools 15 SP7
kernel-docs-6.4.0-150700.53.73.1
kernel-obs-build-6.4.0-150700.53.73.2
kernel-source-6.4.0-150700.53.73.1
kernel-syms-6.4.0-150700.53.73.1
SUSE Linux Enterprise Module for Legacy 15 SP7
reiserfs-kmp-default-6.4.0-150700.53.73.2
SUSE Linux Enterprise Module for Public Cloud 15 SP7
kernel-azure-6.4.0-150700.53.73.2
kernel-azure-devel-6.4.0-150700.53.73.2
SUSE Linux Enterprise Workstation Extension 15 SP7
kernel-default-extra-6.4.0-150700.53.73.2

Описание

Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds condition without RMP checks, resulting in a potential loss of confidential guest integrity.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: rpmsg: core: fix race in driver_override_show() and use core helper The driver_override_show function reads the driver_override string without holding the device_lock. However, the store function modifies and frees the string while holding the device_lock. This creates a race condition where the string can be freed by the store function while being read by the show function, leading to a use-after-free. To fix this, replace the rpmsg_string_attr macro with explicit show and store functions. The new driver_override_store uses the standard driver_set_override helper. Since the introduction of driver_set_override, the comments in include/linux/rpmsg.h have stated that this helper must be used to set or clear driver_override, but the implementation was not updated until now. Because driver_set_override modifies and frees the string while holding the device_lock, the new driver_override_show now correctly holds the device_lock during the read operation to prevent the race. Additionally, since rpmsg_string_attr has only ever been used for driver_override, removing the macro simplifies the code.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Correct the allocation size for bytes controls The size of the data behind of scontrol->ipc_control_data for bytes controls is: [1] sizeof(struct sof_ipc4_control_data) + // kernel only struct [2] sizeof(struct sof_abi_hdr)) + payload The max_size specifies the size of [2] and it is coming from topology. Change the function to take this into account and allocate adequate amount of memory behind scontrol->ipc_control_data. With the change we will allocate [1] amount more memory to be able to hold the full size of data.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: misc: bcm_vk: Fix possible null-pointer dereferences in bcm_vk_read() In the function bcm_vk_read(), the pointer entry is checked, indicating that it can be NULL. If entry is NULL and rc is set to -EMSGSIZE, the following code may cause null-pointer dereferences: struct vk_msg_blk tmp_msg = entry->to_h_msg[0]; set_msg_id(&tmp_msg, entry->usr_msg_id); tmp_msg.size = entry->to_h_blks - 1; To prevent these possible null-pointer dereferences, copy to_h_msg, usr_msg_id, and to_h_blks from iter into temporary variables, and return these temporary variables to the application instead of accessing them through a potentially NULL entry.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_config_trx_mode() rtw8822b_set_antenna() can be called from userspace when the chip is powered off. In that case a WARNING is triggered in rtw8822b_config_trx_mode() because trying to read the RF registers when the chip is powered off returns an unexpected value. Call rtw8822b_config_trx_mode() in rtw8822b_set_antenna() only when the chip is powered on. ------------[ cut here ]------------ write RF mode table fail WARNING: CPU: 0 PID: 7183 at rtw8822b.c:824 rtw8822b_config_trx_mode.constprop.0+0x835/0x840 [rtw88_8822b] CPU: 0 UID: 0 PID: 7183 Comm: iw Tainted: G W OE 6.17.5-arch1-1 #1 PREEMPT(full) 01c39fc421df2af799dd5e9180b572af860b40c1 Tainted: [W]=WARN, [O]=OOT_MODULE, [E]=UNSIGNED_MODULE Hardware name: LENOVO 82KR/LNVNB161216, BIOS HBCN18WW 08/27/2021 RIP: 0010:rtw8822b_config_trx_mode.constprop.0+0x835/0x840 [rtw88_8822b] Call Trace: <TASK> rtw8822b_set_antenna+0x57/0x70 [rtw88_8822b 370206f42e5890d8d5f48eb358b759efa37c422b] rtw_ops_set_antenna+0x50/0x80 [rtw88_core 711c8fb4f686162be4625b1d0b8e8c6a5ac850fb] ieee80211_set_antenna+0x60/0x100 [mac80211 f1845d85d2ecacf3b71867635a050ece90486cf3] nl80211_set_wiphy+0x384/0xe00 [cfg80211 296485ee85696d2150309a6d21a7fbca83d3dbda] ? netdev_run_todo+0x63/0x550 genl_family_rcv_msg_doit+0xfc/0x160 genl_rcv_msg+0x1aa/0x2b0 ? __pfx_nl80211_pre_doit+0x10/0x10 [cfg80211 296485ee85696d2150309a6d21a7fbca83d3dbda] ? __pfx_nl80211_set_wiphy+0x10/0x10 [cfg80211 296485ee85696d2150309a6d21a7fbca83d3dbda] ? __pfx_nl80211_post_doit+0x10/0x10 [cfg80211 296485ee85696d2150309a6d21a7fbca83d3dbda] ? __pfx_genl_rcv_msg+0x10/0x10 netlink_rcv_skb+0x59/0x110 genl_rcv+0x28/0x40 netlink_unicast+0x285/0x3c0 ? __alloc_skb+0xdb/0x1a0 netlink_sendmsg+0x20d/0x430 ____sys_sendmsg+0x39f/0x3d0 ? import_iovec+0x2f/0x40 ___sys_sendmsg+0x99/0xe0 ? refill_obj_stock+0x12e/0x240 __sys_sendmsg+0x8a/0xf0 do_syscall_64+0x81/0x970 ? do_syscall_64+0x81/0x970 ? ksys_read+0x73/0xf0 ? do_syscall_64+0x81/0x970 ? count_memcg_events+0xc2/0x190 ? handle_mm_fault+0x1d7/0x2d0 ? do_user_addr_fault+0x21a/0x690 ? exc_page_fault+0x7e/0x1a0 entry_SYSCALL_64_after_hwframe+0x76/0x7e </TASK> ---[ end trace 0000000000000000 ]---


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: fix for dma-fence safe access rules Commit 506aa8b02a8d6 ("dma-fence: Add safe access helpers and document the rules") details the dma-fence safe access rules. The most common culprit is that drm_sched_fence_get_timeline_name may race with group_free_queue.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/display/dp_mst: Add protection against 0 vcpi When releasing a timeslot there is a slight chance we may end up with the wrong payload mask due to overflow if the delayed_destroy_work ends up coming into play after a DP 2.1 monitor gets disconnected which causes vcpi to become 0 then we try to make the payload = ~BIT(vcpi - 1) which is a negative shift. VCPI id should never really be 0 hence skip changing the payload mask if VCPI is 0. Otherwise it leads to <7> [515.287237] xe 0000:03:00.0: [drm:drm_dp_mst_get_port_malloc [drm_display_helper]] port ffff888126ce9000 (3) <4> [515.287267] -----------[ cut here ]----------- <3> [515.287268] UBSAN: shift-out-of-bounds in ../drivers/gpu/drm/display/drm_dp_mst_topology.c:4575:36 <3> [515.287271] shift exponent -1 is negative <4> [515.287275] CPU: 7 UID: 0 PID: 3108 Comm: kworker/u64:33 Tainted: G S U 6.17.0-rc6-lgci-xe-xe-3795-3e79699fa1b216e92+ #1 PREEMPT(voluntary) <4> [515.287279] Tainted: [S]=CPU_OUT_OF_SPEC, [U]=USER <4> [515.287279] Hardware name: ASUS System Product Name/PRIME Z790-P WIFI, BIOS 1645 03/15/2024 <4> [515.287281] Workqueue: drm_dp_mst_wq drm_dp_delayed_destroy_work [drm_display_helper] <4> [515.287303] Call Trace: <4> [515.287304] <TASK> <4> [515.287306] dump_stack_lvl+0xc1/0xf0 <4> [515.287313] dump_stack+0x10/0x20 <4> [515.287316] __ubsan_handle_shift_out_of_bounds+0x133/0x2e0 <4> [515.287324] ? drm_atomic_get_private_obj_state+0x186/0x1d0 <4> [515.287333] drm_dp_atomic_release_time_slots.cold+0x17/0x3d [drm_display_helper] <4> [515.287355] mst_connector_atomic_check+0x159/0x180 [xe] <4> [515.287546] drm_atomic_helper_check_modeset+0x4d9/0xfa0 <4> [515.287550] ? __ww_mutex_lock.constprop.0+0x6f/0x1a60 <4> [515.287562] intel_atomic_check+0x119/0x2b80 [xe] <4> [515.287740] ? find_held_lock+0x31/0x90 <4> [515.287747] ? lock_release+0xce/0x2a0 <4> [515.287754] drm_atomic_check_only+0x6a2/0xb40 <4> [515.287758] ? drm_atomic_add_affected_connectors+0x12b/0x140 <4> [515.287765] drm_atomic_commit+0x6e/0xf0 <4> [515.287766] ? _pfx__drm_printfn_info+0x10/0x10 <4> [515.287774] drm_client_modeset_commit_atomic+0x25c/0x2b0 <4> [515.287794] drm_client_modeset_commit_locked+0x60/0x1b0 <4> [515.287795] ? mutex_lock_nested+0x1b/0x30 <4> [515.287801] drm_client_modeset_commit+0x26/0x50 <4> [515.287804] __drm_fb_helper_restore_fbdev_mode_unlocked+0xdc/0x110 <4> [515.287810] drm_fb_helper_hotplug_event+0x120/0x140 <4> [515.287814] drm_fbdev_client_hotplug+0x28/0xd0 <4> [515.287819] drm_client_hotplug+0x6c/0xf0 <4> [515.287824] drm_client_dev_hotplug+0x9e/0xd0 <4> [515.287829] drm_kms_helper_hotplug_event+0x1a/0x30 <4> [515.287834] drm_dp_delayed_destroy_work+0x3df/0x410 [drm_display_helper] <4> [515.287861] process_one_work+0x22b/0x6f0 <4> [515.287874] worker_thread+0x1e8/0x3d0 <4> [515.287879] ? __pfx_worker_thread+0x10/0x10 <4> [515.287882] kthread+0x11c/0x250 <4> [515.287886] ? __pfx_kthread+0x10/0x10 <4> [515.287890] ret_from_fork+0x2d7/0x310 <4> [515.287894] ? __pfx_kthread+0x10/0x10 <4> [515.287897] ret_from_fork_asm+0x1a/0x30


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Recover from panthor_gpu_flush_caches() failures We have seen a few cases where the whole memory subsystem is blocked and flush operations never complete. When that happens, we want to: - schedule a reset, so we can recover from this situation - in the reset path, we need to reset the pending_reqs so we can send new commands after the reset - if more panthor_gpu_flush_caches() operations are queued after the timeout, we skip them and return -EIO directly to avoid needless waits (the memory block won't miraculously work again) Note that we drop the WARN_ON()s because these hangs can be triggered with buggy GPU jobs created by the UMD, and there's no way we can prevent it. We do keep the error messages though. v2: - New patch v3: - Collect R-b - Explicitly mention the fact we dropped the WARN_ON()s in the commit message v4: - No changes


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: add xmit recursion limit to tunnel xmit functions Tunnel xmit functions (iptunnel_xmit, ip6tunnel_xmit) lack their own recursion limit. When a bond device in broadcast mode has GRE tap interfaces as slaves, and those GRE tunnels route back through the bond, multicast/broadcast traffic triggers infinite recursion between bond_xmit_broadcast() and ip_tunnel_xmit()/ip6_tnl_xmit(), causing kernel stack overflow. The existing XMIT_RECURSION_LIMIT (8) in the no-qdisc path is not sufficient because tunnel recursion involves route lookups and full IP output, consuming much more stack per level. Use a lower limit of 4 (IP_TUNNEL_RECURSION_LIMIT) to prevent overflow. Add recursion detection using dev_xmit_recursion helpers directly in iptunnel_xmit() and ip6tunnel_xmit() to cover all IPv4/IPv6 tunnel paths including UDP encapsulated tunnels (VXLAN, Geneve, etc.). Move dev_xmit_recursion helpers from net/core/dev.h to public header include/linux/netdevice.h so they can be used by tunnel code. BUG: KASAN: stack-out-of-bounds in blake2s.constprop.0+0xe7/0x160 Write of size 32 at addr ffff88810033fed0 by task kworker/0:1/11 Workqueue: mld mld_ifc_work Call Trace: <TASK> __build_flow_key.constprop.0 (net/ipv4/route.c:515) ip_rt_update_pmtu (net/ipv4/route.c:1073) iptunnel_xmit (net/ipv4/ip_tunnel_core.c:84) ip_tunnel_xmit (net/ipv4/ip_tunnel.c:847) gre_tap_xmit (net/ipv4/ip_gre.c:779) dev_hard_start_xmit (net/core/dev.c:3887) sch_direct_xmit (net/sched/sch_generic.c:347) __dev_queue_xmit (net/core/dev.c:4802) bond_dev_queue_xmit (drivers/net/bonding/bond_main.c:312) bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5279) bond_start_xmit (drivers/net/bonding/bond_main.c:5530) dev_hard_start_xmit (net/core/dev.c:3887) __dev_queue_xmit (net/core/dev.c:4841) ip_finish_output2 (net/ipv4/ip_output.c:237) ip_output (net/ipv4/ip_output.c:438) iptunnel_xmit (net/ipv4/ip_tunnel_core.c:86) gre_tap_xmit (net/ipv4/ip_gre.c:779) dev_hard_start_xmit (net/core/dev.c:3887) sch_direct_xmit (net/sched/sch_generic.c:347) __dev_queue_xmit (net/core/dev.c:4802) bond_dev_queue_xmit (drivers/net/bonding/bond_main.c:312) bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5279) bond_start_xmit (drivers/net/bonding/bond_main.c:5530) dev_hard_start_xmit (net/core/dev.c:3887) __dev_queue_xmit (net/core/dev.c:4841) ip_finish_output2 (net/ipv4/ip_output.c:237) ip_output (net/ipv4/ip_output.c:438) iptunnel_xmit (net/ipv4/ip_tunnel_core.c:86) ip_tunnel_xmit (net/ipv4/ip_tunnel.c:847) gre_tap_xmit (net/ipv4/ip_gre.c:779) dev_hard_start_xmit (net/core/dev.c:3887) sch_direct_xmit (net/sched/sch_generic.c:347) __dev_queue_xmit (net/core/dev.c:4802) bond_dev_queue_xmit (drivers/net/bonding/bond_main.c:312) bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5279) bond_start_xmit (drivers/net/bonding/bond_main.c:5530) dev_hard_start_xmit (net/core/dev.c:3887) __dev_queue_xmit (net/core/dev.c:4841) mld_sendpack mld_ifc_work process_one_work worker_thread </TASK>


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: X.509: Fix out-of-bounds access when parsing extensions Leo reports an out-of-bounds access when parsing a certificate with empty Basic Constraints or Key Usage extension because the first byte of the extension is read before checking its length. Fix it. The bug can be triggered by an unprivileged user by submitting a specially crafted certificate to the kernel through the keyrings(7) API. Leo has demonstrated this with a proof-of-concept program responsibly disclosed off-list.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: dmaengine: xilinx: xdma: Fix regmap init error handling devm_regmap_init_mmio returns an ERR_PTR() upon error, not NULL. Fix the error check and also fix the error message. Use the error code from ERR_PTR() instead of the wrong value in ret.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix leaking event log memory During the device remove process, the device is reset, causing the configuration registers to go back to their default state, which is zero. As the driver is checking if the event log support was enabled before deallocating, it will fail if a reset happened before. Do not check if the support was enabled, the check for 'idxd->evl' being valid (only allocated if the HW capability is available) is enough.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix memory leak when a wq is reset idxd_wq_disable_cleanup() which is called from the reset path for a workqueue, sets the wq type to NONE, which for other parts of the driver mean that the wq is empty (all its resources were released). Only set the wq type to NONE after its resources are released.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ext4: reject mount if bigalloc with s_first_data_block != 0 bigalloc with s_first_data_block != 0 is not supported, reject mounting it.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() isotp_sendmsg() uses only cmpxchg() on so->tx.state to serialize access to so->tx.buf. isotp_release() waits for ISOTP_IDLE via wait_event_interruptible() and then calls kfree(so->tx.buf). If a signal interrupts the wait_event_interruptible() inside close() while tx.state is ISOTP_SENDING, the loop exits early and release proceeds to force ISOTP_SHUTDOWN and continues to kfree(so->tx.buf) while sendmsg may still be reading so->tx.buf for the final CAN frame in isotp_fill_dataframe(). The so->tx.buf can be allocated once when the standard tx.buf length needs to be extended. Move the kfree() of this potentially extended tx.buf to sk_destruct time when either isotp_sendmsg() and isotp_release() are done.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/xe: always keep track of remap prev/next During 3D workload, user is reporting hitting: [ 413.361679] WARNING: drivers/gpu/drm/xe/xe_vm.c:1217 at vm_bind_ioctl_ops_unwind+0x1e2/0x2e0 [xe], CPU#7: vkd3d_queue/9925 [ 413.361944] CPU: 7 UID: 1000 PID: 9925 Comm: vkd3d_queue Kdump: loaded Not tainted 7.0.0-070000rc3-generic #202603090038 PREEMPT(lazy) [ 413.361949] RIP: 0010:vm_bind_ioctl_ops_unwind+0x1e2/0x2e0 [xe] [ 413.362074] RSP: 0018:ffffd4c25c3df930 EFLAGS: 00010282 [ 413.362077] RAX: 0000000000000000 RBX: ffff8f3ee817ed10 RCX: 0000000000000000 [ 413.362078] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 [ 413.362079] RBP: ffffd4c25c3df980 R08: 0000000000000000 R09: 0000000000000000 [ 413.362081] R10: 0000000000000000 R11: 0000000000000000 R12: ffff8f41fbf99380 [ 413.362082] R13: ffff8f3ee817e968 R14: 00000000ffffffef R15: ffff8f43d00bd380 [ 413.362083] FS: 00000001040ff6c0(0000) GS:ffff8f4696d89000(0000) knlGS:00000000330b0000 [ 413.362085] CS: 0010 DS: 002b ES: 002b CR0: 0000000080050033 [ 413.362086] CR2: 00007ddfc4747000 CR3: 00000002e6262005 CR4: 0000000000f72ef0 [ 413.362088] PKRU: 55555554 [ 413.362089] Call Trace: [ 413.362092] <TASK> [ 413.362096] xe_vm_bind_ioctl+0xa9a/0xc60 [xe] Which seems to hint that the vma we are re-inserting for the ops unwind is either invalid or overlapping with something already inserted in the vm. It shouldn't be invalid since this is a re-insertion, so must have worked before. Leaving the likely culprit as something already placed where we want to insert the vma. Following from that, for the case where we do something like a rebind in the middle of a vma, and one or both mapped ends are already compatible, we skip doing the rebind of those vma and set next/prev to NULL. As well as then adjust the original unmap va range, to avoid unmapping the ends. However, if we trigger the unwind path, we end up with three va, with the two ends never being removed and the original va range in the middle still being the shrunken size. If this occurs, one failure mode is when another unwind op needs to interact with that range, which can happen with a vector of binds. For example, if we need to re-insert something in place of the original va. In this case the va is still the shrunken version, so when removing it and then doing a re-insert it can overlap with the ends, which were never removed, triggering a warning like above, plus leaving the vm in a bad state. With that, we need two things here: 1) Stop nuking the prev/next tracking for the skip cases. Instead relying on checking for skip prev/next, where needed. That way on the unwind path, we now correctly remove both ends. 2) Undo the unmap va shrinkage, on the unwind path. With the two ends now removed the unmap va should expand back to the original size again, before re-insertion. v2: - Update the explanation in the commit message, based on an actual IGT of triggering this issue, rather than conjecture. - Also undo the unmap shrinkage, for the skip case. With the two ends now removed, the original unmap va range should expand back to the original range. v3: - Track the old start/range separately. vma_size/start() uses the va info directly. (cherry picked from commit aec6969f75afbf4e01fd5fb5850ed3e9c27043ac)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: spi: spi-fsl-lpspi: fix teardown order issue (UAF) There is a teardown order issue in the driver. The SPI controller is registered using devm_spi_register_controller(), which delays unregistration of the SPI controller until after the fsl_lpspi_remove() function returns. As the fsl_lpspi_remove() function synchronously tears down the DMA channels, a running SPI transfer triggers the following NULL pointer dereference due to use after free: | fsl_lpspi 42550000.spi: I/O Error in DMA RX | Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 [...] | Call trace: | fsl_lpspi_dma_transfer+0x260/0x340 [spi_fsl_lpspi] | fsl_lpspi_transfer_one+0x198/0x448 [spi_fsl_lpspi] | spi_transfer_one_message+0x49c/0x7c8 | __spi_pump_transfer_message+0x120/0x420 | __spi_sync+0x2c4/0x520 | spi_sync+0x34/0x60 | spidev_message+0x20c/0x378 [spidev] | spidev_ioctl+0x398/0x750 [spidev] [...] Switch from devm_spi_register_controller() to spi_register_controller() in fsl_lpspi_probe() and add the corresponding spi_unregister_controller() in fsl_lpspi_remove().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: clamp SCO altsetting table indices btusb_work() maps the number of active SCO links to USB alternate settings through a three-entry lookup table when CVSD traffic uses transparent voice settings. The lookup currently indexes alts[] with data->sco_num - 1 without first constraining sco_num to the number of available table entries. While the table only defines alternate settings for up to three SCO links, data->sco_num comes from hci_conn_num() and is used directly. Cap the lookup to the last table entry before indexing it so the driver keeps selecting the highest supported alternate setting without reading past alts[].


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite loop l2cap_config_req() processes CONFIG_REQ for channels in BT_CONNECTED state to support L2CAP reconfiguration (e.g. MTU changes). However, since both CONF_INPUT_DONE and CONF_OUTPUT_DONE are already set from the initial configuration, the reconfiguration path falls through to l2cap_ertm_init(), which re-initializes tx_q, srej_q, srej_list, and retrans_list without freeing the previous allocations and sets chan->sdu to NULL without freeing the existing skb. This leaks all previously allocated ERTM resources. Additionally, l2cap_parse_conf_req() does not validate the minimum value of remote_mps derived from the RFC max_pdu_size option. A zero value propagates to l2cap_segment_sdu() where pdu_len becomes zero, causing the while loop to never terminate since len is never decremented, exhausting all available memory. Fix the double-init by skipping l2cap_ertm_init() and l2cap_chan_ready() when the channel is already in BT_CONNECTED state, while still allowing the reconfiguration parameters to be updated through l2cap_parse_conf_req(). Also add a pdu_len zero check in l2cap_segment_sdu() as a safeguard.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: udp: Fix wildcard bind conflict check when using hash2 When binding a udp_sock to a local address and port, UDP uses two hashes (udptable->hash and udptable->hash2) for collision detection. The current code switches to "hash2" when hslot->count > 10. "hash2" is keyed by local address and local port. "hash" is keyed by local port only. The issue can be shown in the following bind sequence (pseudo code): bind(fd1, "[fd00::1]:8888") bind(fd2, "[fd00::2]:8888") bind(fd3, "[fd00::3]:8888") bind(fd4, "[fd00::4]:8888") bind(fd5, "[fd00::5]:8888") bind(fd6, "[fd00::6]:8888") bind(fd7, "[fd00::7]:8888") bind(fd8, "[fd00::8]:8888") bind(fd9, "[fd00::9]:8888") bind(fd10, "[fd00::10]:8888") /* Correctly return -EADDRINUSE because "hash" is used * instead of "hash2". udp_lib_lport_inuse() detects the * conflict. */ bind(fail_fd, "[::]:8888") /* After one more socket is bound to "[fd00::11]:8888", * hslot->count exceeds 10 and "hash2" is used instead. */ bind(fd11, "[fd00::11]:8888") bind(fail_fd, "[::]:8888") /* succeeds unexpectedly */ The same issue applies to the IPv4 wildcard address "0.0.0.0" and the IPv4-mapped wildcard address "::ffff:0.0.0.0". For example, if there are existing sockets bound to "192.168.1.[1-11]:8888", then binding "0.0.0.0:8888" or "[::ffff:0.0.0.0]:8888" can also miss the conflict when hslot->count > 10. TCP inet_csk_get_port() already has the correct check in inet_use_bhash2_on_bind(). Rename it to inet_use_hash2_on_bind() and move it to inet_hashtables.h so udp.c can reuse it in this fix.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix circular locking dependency in nci_close_device nci_close_device() flushes rx_wq and tx_wq while holding req_lock. This causes a circular locking dependency because nci_rx_work() running on rx_wq can end up taking req_lock too: nci_rx_work -> nci_rx_data_packet -> nci_data_exchange_complete -> __sk_destruct -> rawsock_destruct -> nfc_deactivate_target -> nci_deactivate_target -> nci_request -> mutex_lock(&ndev->req_lock) Move the flush of rx_wq after req_lock has been released. This should safe (I think) because NCI_UP has already been cleared and the transport is closed, so the work will see it and return -ENETDOWN. NIPA has been hitting this running the nci selftest with a debug kernel on roughly 4% of the runs.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb Before using sk pointer, check if it is null. Fix the following: KASAN: null-ptr-deref in range [0x0000000000000260-0x0000000000000267] CPU: 0 UID: 0 PID: 5985 Comm: kworker/0:5 Not tainted 7.0.0-rc4-00029-ga989fde763f4 #1 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.17.0-9.fc43 06/10/2025 Workqueue: events l2cap_info_timeout RIP: 0010:kasan_byte_accessible+0x12/0x30 Code: 79 ff ff ff 0f 1f 40 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 40 d6 48 c1 ef 03 48 b8 00 00 00 00 00 fc ff df <0f> b6 04 07 3c 08 0f 92 c0 c3 cc cce veth0_macvtap: entered promiscuous mode RSP: 0018:ffffc90006e0f808 EFLAGS: 00010202 RAX: dffffc0000000000 RBX: ffffffff89746018 RCX: 0000000080000001 RDX: 0000000000000000 RSI: ffffffff89746018 RDI: 000000000000004c RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000 R10: dffffc0000000000 R11: ffffffff8aae3e70 R12: 0000000000000000 R13: 0000000000000260 R14: 0000000000000260 R15: 0000000000000001 FS: 0000000000000000(0000) GS:ffff8880983c2000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00005582615a5008 CR3: 000000007007e000 CR4: 0000000000752ef0 PKRU: 55555554 Call Trace: <TASK> __kasan_check_byte+0x12/0x40 lock_acquire+0x79/0x2e0 lock_sock_nested+0x48/0x100 ? l2cap_sock_ready_cb+0x46/0x160 l2cap_sock_ready_cb+0x46/0x160 l2cap_conn_start+0x779/0xff0 ? __pfx_l2cap_conn_start+0x10/0x10 ? l2cap_info_timeout+0x60/0xa0 ? __pfx___mutex_lock+0x10/0x10 l2cap_info_timeout+0x68/0xa0 ? process_scheduled_works+0xa8d/0x18c0 process_scheduled_works+0xb6e/0x18c0 ? __pfx_process_scheduled_works+0x10/0x10 ? assign_work+0x3d5/0x5e0 worker_thread+0xa53/0xfc0 kthread+0x388/0x470 ? __pfx_worker_thread+0x10/0x10 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x51e/0xb90 ? __pfx_ret_from_fork+0x10/0x10 veth1_macvtap: entered promiscuous mode ? __switch_to+0xc7d/0x1450 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30 </TASK> Modules linked in: ---[ end trace 0000000000000000 ]--- batman_adv: batadv0: Interface activated: batadv_slave_0 batman_adv: batadv0: Interface activated: batadv_slave_1 netdevsim netdevsim7 netdevsim0: set [1, 0] type 2 family 0 port 6081 - 0 netdevsim netdevsim7 netdevsim1: set [1, 0] type 2 family 0 port 6081 - 0 netdevsim netdevsim7 netdevsim2: set [1, 0] type 2 family 0 port 6081 - 0 netdevsim netdevsim7 netdevsim3: set [1, 0] type 2 family 0 port 6081 - 0 RIP: 0010:kasan_byte_accessible+0x12/0x30 Code: 79 ff ff ff 0f 1f 40 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 40 d6 48 c1 ef 03 48 b8 00 00 00 00 00 fc ff df <0f> b6 04 07 3c 08 0f 92 c0 c3 cc cce ieee80211 phy39: Selected rate control algorithm 'minstrel_ht' RSP: 0018:ffffc90006e0f808 EFLAGS: 00010202 RAX: dffffc0000000000 RBX: ffffffff89746018 RCX: 0000000080000001 RDX: 0000000000000000 RSI: ffffffff89746018 RDI: 000000000000004c RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000 R10: dffffc0000000000 R11: ffffffff8aae3e70 R12: 0000000000000000 R13: 0000000000000260 R14: 0000000000000260 R15: 0000000000000001 FS: 0000000000000000(0000) GS:ffff8880983c2000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f7e16139e9c CR3: 000000000e74e000 CR4: 0000000000752ef0 PKRU: 55555554 Kernel panic - not syncing: Fatal exception


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix dangling pointer on mgmt_add_adv_patterns_monitor_complete This fixes the condition checking so mgmt_pending_valid is executed whenever status != -ECANCELED otherwise calling mgmt_pending_free(cmd) would kfree(cmd) without unlinking it from the list first, leaving a dangling pointer. Any subsequent list traversal (e.g., mgmt_pending_foreach during __mgmt_power_off, or another mgmt_pending_valid call) would dereference freed memory.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix stack-out-of-bounds read in l2cap_ecred_conn_req Syzbot reported a KASAN stack-out-of-bounds read in l2cap_build_cmd() that is triggered by a malformed Enhanced Credit Based Connection Request. The vulnerability stems from l2cap_ecred_conn_req(). The function allocates a local stack buffer (`pdu`) designed to hold a maximum of 5 Source Channel IDs (SCIDs), totaling 18 bytes. When an attacker sends a request with more than 5 SCIDs, the function calculates `rsp_len` based on this unvalidated `cmd_len` before checking if the number of SCIDs exceeds L2CAP_ECRED_MAX_CID. If the SCID count is too high, the function correctly jumps to the `response` label to reject the packet, but `rsp_len` retains the attacker's oversized value. Consequently, l2cap_send_cmd() is instructed to read past the end of the 18-byte `pdu` buffer, triggering a KASAN panic. Fix this by moving the assignment of `rsp_len` to after the `num_scid` boundary check. If the packet is rejected, `rsp_len` will safely remain 0, and the error response will only read the 8-byte base header from the stack.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: apple: avoid memory leak in apple_report_fixup() The apple_report_fixup() function was returning a newly kmemdup()-allocated buffer, but never freeing it. The caller of report_fixup() does not take ownership of the returned pointer, but it *is* permitted to return a sub-portion of the input rdesc, whose lifetime is managed by the caller.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: magicmouse: avoid memory leak in magicmouse_report_fixup() The magicmouse_report_fixup() function was returning a newly kmemdup()-allocated buffer, but never freeing it. The caller of report_fixup() does not take ownership of the returned pointer, but it *is* permitted to return a sub-portion of the input rdesc, whose lifetime is managed by the caller.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: nvme-pci: ensure we're polling a polled queue A user can change the polled queue count at run time. There's a brief window during a reset where a hipri task may try to poll that queue before the block layer has updated the queue maps, which would race with the now interrupt driven queue and may cause double completions.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: asus: avoid memory leak in asus_report_fixup() The asus_report_fixup() function was returning a newly allocated kmemdup()-allocated buffer, but never freeing it. Switch to devm_kzalloc() to ensure the memory is managed and freed automatically when the device is removed. The caller of report_fixup() does not take ownership of the returned pointer, but it is permitted to return a pointer whose lifetime is at least that of the input buffer. Also fix a harmless out-of-bounds read by copying only the original descriptor size.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: can: raw: fix ro->uniq use-after-free in raw_rcv() raw_release() unregisters raw CAN receive filters via can_rx_unregister(), but receiver deletion is deferred with call_rcu(). This leaves a window where raw_rcv() may still be running in an RCU read-side critical section after raw_release() frees ro->uniq, leading to a use-after-free of the percpu uniq storage. Move free_percpu(ro->uniq) out of raw_release() and into a raw-specific socket destructor. can_rx_unregister() takes an extra reference to the socket and only drops it from the RCU callback, so freeing uniq from sk_destruct ensures the percpu area is not released until the relevant callbacks have drained. [mkl: applied manually]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Check set_default_submission() before deferencing When the i915 driver firmware binaries are not present, the set_default_submission pointer is not set. This pointer is dereferenced during suspend anyways. Add a check to make sure it is set before dereferencing. [ 23.289926] PM: suspend entry (deep) [ 23.293558] Filesystems sync: 0.000 seconds [ 23.298010] Freezing user space processes [ 23.302771] Freezing user space processes completed (elapsed 0.000 seconds) [ 23.309766] OOM killer disabled. [ 23.313027] Freezing remaining freezable tasks [ 23.318540] Freezing remaining freezable tasks completed (elapsed 0.001 seconds) [ 23.342038] serial 00:05: disabled [ 23.345719] serial 00:02: disabled [ 23.349342] serial 00:01: disabled [ 23.353782] sd 0:0:0:0: [sda] Synchronizing SCSI cache [ 23.358993] sd 1:0:0:0: [sdb] Synchronizing SCSI cache [ 23.361635] ata1.00: Entering standby power mode [ 23.368863] ata2.00: Entering standby power mode [ 23.445187] BUG: kernel NULL pointer dereference, address: 0000000000000000 [ 23.452194] #PF: supervisor instruction fetch in kernel mode [ 23.457896] #PF: error_code(0x0010) - not-present page [ 23.463065] PGD 0 P4D 0 [ 23.465640] Oops: Oops: 0010 [#1] SMP NOPTI [ 23.469869] CPU: 8 UID: 0 PID: 211 Comm: kworker/u48:18 Tainted: G S W 6.19.0-rc4-00020-gf0b9d8eb98df #10 PREEMPT(voluntary) [ 23.482512] Tainted: [S]=CPU_OUT_OF_SPEC, [W]=WARN [ 23.496511] Workqueue: async async_run_entry_fn [ 23.501087] RIP: 0010:0x0 [ 23.503755] Code: Unable to access opcode bytes at 0xffffffffffffffd6. [ 23.510324] RSP: 0018:ffffb4a60065fca8 EFLAGS: 00010246 [ 23.515592] RAX: 0000000000000000 RBX: ffff9f428290e000 RCX: 000000000000000f [ 23.522765] RDX: 0000000000000000 RSI: 0000000000000282 RDI: ffff9f428290e000 [ 23.529937] RBP: ffff9f4282907070 R08: ffff9f4281130428 R09: 00000000ffffffff [ 23.537111] R10: 0000000000000000 R11: 0000000000000001 R12: ffff9f42829070f8 [ 23.544284] R13: ffff9f4282906028 R14: ffff9f4282900000 R15: ffff9f4282906b68 [ 23.551457] FS: 0000000000000000(0000) GS:ffff9f466b2cf000(0000) knlGS:0000000000000000 [ 23.559588] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 23.565365] CR2: ffffffffffffffd6 CR3: 000000031c230001 CR4: 0000000000f70ef0 [ 23.572539] PKRU: 55555554 [ 23.575281] Call Trace: [ 23.577770] <TASK> [ 23.579905] intel_engines_reset_default_submission+0x42/0x60 [ 23.585695] __intel_gt_unset_wedged+0x191/0x200 [ 23.590360] intel_gt_unset_wedged+0x20/0x40 [ 23.594675] gt_sanitize+0x15e/0x170 [ 23.598290] i915_gem_suspend_late+0x6b/0x180 [ 23.602692] i915_drm_suspend_late+0x35/0xf0 [ 23.607008] ? __pfx_pci_pm_suspend_late+0x10/0x10 [ 23.611843] dpm_run_callback+0x78/0x1c0 [ 23.615817] device_suspend_late+0xde/0x2e0 [ 23.620037] async_suspend_late+0x18/0x30 [ 23.624082] async_run_entry_fn+0x25/0xa0 [ 23.628129] process_one_work+0x15b/0x380 [ 23.632182] worker_thread+0x2a5/0x3c0 [ 23.635973] ? __pfx_worker_thread+0x10/0x10 [ 23.640279] kthread+0xf6/0x1f0 [ 23.643464] ? __pfx_kthread+0x10/0x10 [ 23.647263] ? __pfx_kthread+0x10/0x10 [ 23.651045] ret_from_fork+0x131/0x190 [ 23.654837] ? __pfx_kthread+0x10/0x10 [ 23.658634] ret_from_fork_asm+0x1a/0x30 [ 23.662597] </TASK> [ 23.664826] Modules linked in: [ 23.667914] CR2: 0000000000000000 [ 23.671271] ------------[ cut here ]------------ (cherry picked from commit daa199abc3d3d1740c9e3a2c3e9216ae5b447cad)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: NFC: nxp-nci: allow GPIOs to sleep Allow the firmware and enable GPIOs to sleep. This fixes a `WARN_ON' and allows the driver to operate GPIOs which are connected to I2C GPIO expanders. -- >8 -- kernel: WARNING: CPU: 3 PID: 2636 at drivers/gpio/gpiolib.c:3880 gpiod_set_value+0x88/0x98 -- >8 --


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: cancel pmsr_free_wk in cfg80211_pmsr_wdev_down When the nl80211 socket that originated a PMSR request is closed, cfg80211_release_pmsr() sets the request's nl_portid to zero and schedules pmsr_free_wk to process the abort asynchronously. If the interface is concurrently torn down before that work runs, cfg80211_pmsr_wdev_down() calls cfg80211_pmsr_process_abort() directly. However, the already- scheduled pmsr_free_wk work item remains pending and may run after the interface has been removed from the driver. This could cause the driver's abort_pmsr callback to operate on a torn-down interface, leading to undefined behavior and potential crashes. Cancel pmsr_free_wk synchronously in cfg80211_pmsr_wdev_down() before calling cfg80211_pmsr_process_abort(). This ensures any pending or in-progress work is drained before interface teardown proceeds, preventing the work from invoking the driver abort callback after the interface is gone.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: i2c: cp2615: fix serial string NULL-deref at probe The cp2615 driver uses the USB device serial string as the i2c adapter name but does not make sure that the string exists. Verify that the device has a serial number before accessing it to avoid triggering a NULL-pointer dereference (e.g. with malicious devices).


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: Fix static_branch_dec() underflow for aql_disable. syzbot reported static_branch_dec() underflow in aql_enable_write(). [0] The problem is that aql_enable_write() does not serialise concurrent write()s to the debugfs. aql_enable_write() checks static_key_false(&aql_disable.key) and later calls static_branch_inc() or static_branch_dec(), but the state may change between the two calls. aql_disable does not need to track inc/dec. Let's use static_branch_enable() and static_branch_disable(). [0]: val == 0 WARNING: kernel/jump_label.c:311 at __static_key_slow_dec_cpuslocked.part.0+0x107/0x120 kernel/jump_label.c:311, CPU#0: syz.1.3155/20288 Modules linked in: CPU: 0 UID: 0 PID: 20288 Comm: syz.1.3155 Tainted: G U L syzkaller #0 PREEMPT(full) Tainted: [U]=USER, [L]=SOFTLOCKUP Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/24/2026 RIP: 0010:__static_key_slow_dec_cpuslocked.part.0+0x107/0x120 kernel/jump_label.c:311 Code: f2 c9 ff 5b 5d c3 cc cc cc cc e8 54 f2 c9 ff 48 89 df e8 ac f9 ff ff eb ad e8 45 f2 c9 ff 90 0f 0b 90 eb a2 e8 3a f2 c9 ff 90 <0f> 0b 90 eb 97 48 89 df e8 5c 4b 33 00 e9 36 ff ff ff 0f 1f 80 00 RSP: 0018:ffffc9000b9f7c10 EFLAGS: 00010293 RAX: 0000000000000000 RBX: ffffffff9b3e5d40 RCX: ffffffff823c57b4 RDX: ffff8880285a0000 RSI: ffffffff823c5846 RDI: ffff8880285a0000 RBP: 0000000000000000 R08: 0000000000000005 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000000 R12: 000000000000000a R13: 1ffff9200173ef88 R14: 0000000000000001 R15: ffffc9000b9f7e98 FS: 00007f530dd726c0(0000) GS:ffff8881245e3000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000200000001140 CR3: 000000007cc4a000 CR4: 00000000003526f0 Call Trace: <TASK> __static_key_slow_dec_cpuslocked kernel/jump_label.c:297 [inline] __static_key_slow_dec kernel/jump_label.c:321 [inline] static_key_slow_dec+0x7c/0xc0 kernel/jump_label.c:336 aql_enable_write+0x2b2/0x310 net/mac80211/debugfs.c:343 short_proxy_write+0x133/0x1a0 fs/debugfs/file.c:383 vfs_write+0x2aa/0x1070 fs/read_write.c:684 ksys_pwrite64 fs/read_write.c:793 [inline] __do_sys_pwrite64 fs/read_write.c:801 [inline] __se_sys_pwrite64 fs/read_write.c:798 [inline] __x64_sys_pwrite64+0x1eb/0x250 fs/read_write.c:798 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xc9/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f530cf9aeb9 Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f530dd72028 EFLAGS: 00000246 ORIG_RAX: 0000000000000012 RAX: ffffffffffffffda RBX: 00007f530d215fa0 RCX: 00007f530cf9aeb9 RDX: 0000000000000003 RSI: 0000000000000000 RDI: 0000000000000010 RBP: 00007f530d008c1f R08: 0000000000000000 R09: 0000000000000000 R10: 4200000000000005 R11: 0000000000000246 R12: 0000000000000000 R13: 00007f530d216038 R14: 00007f530d215fa0 R15: 00007ffde89fb978 </TASK>


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom Since upstream commit e75665dd0968 ("wifi: wlcore: ensure skb headroom before skb_push"), wl1271_tx_allocate() and with it wl1271_prepare_tx_frame() returns -EAGAIN if pskb_expand_head() fails. However, in wlcore_tx_work_locked(), a return value of -EAGAIN from wl1271_prepare_tx_frame() is interpreted as the aggregation buffer being full. This causes the code to flush the buffer, put the skb back at the head of the queue, and immediately retry the same skb in a tight while loop. Because wlcore_tx_work_locked() holds wl->mutex, and the retry happens immediately with GFP_ATOMIC, this will result in an infinite loop and a CPU soft lockup. Return -ENOMEM instead so the packet is dropped and the loop terminates. The problem was found by an experimental code review agent based on gemini-3.1-pro while reviewing backports into v6.18.y.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: x86/cpu: Remove X86_CR4_FRED from the CR4 pinned bits mask Commit in Fixes added the FRED CR4 bit to the CR4 pinned bits mask so that whenever something else modifies CR4, that bit remains set. Which in itself is a perfectly fine idea. However, there's an issue when during boot FRED is initialized: first on the BSP and later on the APs. Thus, there's a window in time when exceptions cannot be handled. This becomes particularly nasty when running as SEV-{ES,SNP} or TDX guests which, when they manage to trigger exceptions during that short window described above, triple fault due to FRED MSRs not being set up yet. See Link tag below for a much more detailed explanation of the situation. So, as a result, the commit in that Link URL tried to address this shortcoming by temporarily disabling CR4 pinning when an AP is not online yet. However, that is a problem in itself because in this case, an attack on the kernel needs to only modify the online bit - a single bit in RW memory - and then disable CR4 pinning and then disable SM*P, leading to more and worse things to happen to the system. So, instead, remove the FRED bit from the CR4 pinning mask, thus obviating the need to temporarily disable CR4 pinning. If someone manages to disable FRED when poking at CR4, then idt_invalidate() would make sure the system would crash'n'burn on the first exception triggered, which is a much better outcome security-wise.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib amdgpu_amdkfd_submit_ib() submits a GPU job and gets a fence from amdgpu_ib_schedule(). This fence is used to wait for job completion. Currently, the code drops the fence reference using dma_fence_put() before calling dma_fence_wait(). If dma_fence_put() releases the last reference, the fence may be freed before dma_fence_wait() is called. This can lead to a use-after-free. Fix this by waiting on the fence first and releasing the reference only after dma_fence_wait() completes. Fixes the below: drivers/gpu/drm/amd/amdgpu/amdgpu_amdkfd.c:697 amdgpu_amdkfd_submit_ib() warn: passing freed memory 'f' (line 696) (cherry picked from commit 8b9e5259adc385b61a6590a13b82ae0ac2bd3482)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: s390/mm: Add missing secure storage access fixups for donated memory There are special cases where secure storage access exceptions happen in a kernel context for pages that don't have the PG_arch_1 bit set. That bit is set for non-exported guest secure storage (memory) but is absent on storage donated to the Ultravisor since the kernel isn't allowed to export donated pages. Prior to this patch we would try to export the page by calling arch_make_folio_accessible() which would instantly return since the arch bit is absent signifying that the page was already exported and no further action is necessary. This leads to secure storage access exception loops which can never be resolved. With this patch we unconditionally try to export and if that fails we fixup.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: hackrf: fix to not free memory after the device is registered in hackrf_probe() In hackrf driver, the following race condition occurs: ``` CPU0 CPU1 hackrf_probe() kzalloc(); // alloc hackrf_dev .... v4l2_device_register(); .... fd = sys_open("/path/to/dev"); // open hackrf fd .... v4l2_device_unregister(); .... kfree(); // free hackrf_dev .... sys_ioctl(fd, ...); v4l2_ioctl(); video_is_registered() // UAF!! .... sys_close(fd); v4l2_release() // UAF!! hackrf_video_release() kfree(); // DFB!! ``` When a V4L2 or video device is unregistered, the device node is removed so new open() calls are blocked. However, file descriptors that are already open-and any in-flight I/O-do not terminate immediately; they remain valid until the last reference is dropped and the driver's release() is invoked. Therefore, freeing device memory on the error path after hackrf_probe() has registered dev it will lead to a race to use-after-free vuln, since those already-open handles haven't been released yet. And since release() free memory too, race to use-after-free and double-free vuln occur. To prevent this, if device is registered from probe(), it should be modified to free memory only through release() rather than calling kfree() directly.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: as102: fix to not free memory after the device is registered in as102_usb_probe() In as102_usb driver, the following race condition occurs: ``` CPU0 CPU1 as102_usb_probe() kzalloc(); // alloc as102_dev_t .... usb_register_dev(); fd = sys_open("/path/to/dev"); // open as102 fd .... usb_deregister_dev(); .... kfree(); // free as102_dev_t .... sys_close(fd); as102_release() // UAF!! as102_usb_release() kfree(); // DFB!! ``` When a USB character device registered with usb_register_dev() is later unregistered (via usb_deregister_dev() or disconnect), the device node is removed so new open() calls fail. However, file descriptors that are already open do not go away immediately: they remain valid until the last reference is dropped and the driver's .release() is invoked. In as102, as102_usb_probe() calls usb_register_dev() and then, on an error path, does usb_deregister_dev() and frees as102_dev_t right away. If userspace raced a successful open() before the deregistration, that open FD will later hit as102_release() --> as102_usb_release() and access or free as102_dev_t again, occur a race to use-after-free and double-free vuln. The fix is to never kfree(as102_dev_t) directly once usb_register_dev() has succeeded. After deregistration, defer freeing memory to .release(). In other words, let release() perform the last kfree when the final open FD is closed.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire: fix use-after-free on disconnect In usb6fire_chip_abort(), the chip struct is allocated as the card's private data (via snd_card_new with sizeof(struct sfire_chip)). When snd_card_free_when_closed() is called and no file handles are open, the card and embedded chip are freed synchronously. The subsequent chip->card = NULL write then hits freed slab memory. Call trace: usb6fire_chip_abort sound/usb/6fire/chip.c:59 [inline] usb6fire_chip_disconnect+0x348/0x358 sound/usb/6fire/chip.c:182 usb_unbind_interface+0x1a8/0x88c drivers/usb/core/driver.c:458 ... hub_event+0x1a04/0x4518 drivers/usb/core/hub.c:5953 Fix by moving the card lifecycle out of usb6fire_chip_abort() and into usb6fire_chip_disconnect(). The card pointer is saved in a local before any teardown, snd_card_disconnect() is called first to prevent new opens, URBs are aborted while chip is still valid, and snd_card_free_when_closed() is called last so chip is never accessed after the card may be freed.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: em28xx: fix use-after-free in em28xx_v4l2_open() em28xx_v4l2_open() reads dev->v4l2 without holding dev->lock, creating a race with em28xx_v4l2_init()'s error path and em28xx_v4l2_fini(), both of which free the em28xx_v4l2 struct and set dev->v4l2 to NULL under dev->lock. This race leads to two issues: - use-after-free in v4l2_fh_init() when accessing vdev->ctrl_handler, since the video_device is embedded in the freed em28xx_v4l2 struct. - NULL pointer dereference in em28xx_resolution_set() when accessing v4l2->norm, since dev->v4l2 has been set to NULL. Fix this by moving the mutex_lock() before the dev->v4l2 read and adding a NULL check for dev->v4l2 under the lock.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix nfeeds state corruption on start_streaming failure syzbot reported a memory leak in vidtv_psi_service_desc_init [1]. When vidtv_start_streaming() fails inside vidtv_start_feed(), the nfeeds counter is left incremented even though no feed was actually started. This corrupts the driver state: subsequent start_feed calls see nfeeds > 1 and skip starting the mux, while stop_feed calls eventually try to stop a non-existent stream. This state corruption can also lead to memory leaks, since the mux and channel resources may be partially allocated during a failed start_streaming but never cleaned up, as the stop path finds dvb->streaming == false and returns early. Fix by decrementing nfeeds back when start_streaming fails, keeping the counter in sync with the actual number of active feeds. [1] BUG: memory leak unreferenced object 0xffff888145b50820 (size 32): comm "syz.0.17", pid 6068, jiffies 4294944486 backtrace (crc 90a0c7d4): vidtv_psi_service_desc_init+0x74/0x1b0 drivers/media/test-drivers/vidtv/vidtv_psi.c:288 vidtv_channel_s302m_init+0xb1/0x2a0 drivers/media/test-drivers/vidtv/vidtv_channel.c:83 vidtv_channels_init+0x1b/0x40 drivers/media/test-drivers/vidtv/vidtv_channel.c:524 vidtv_mux_init+0x516/0xbe0 drivers/media/test-drivers/vidtv/vidtv_mux.c:518 vidtv_start_streaming drivers/media/test-drivers/vidtv/vidtv_bridge.c:194 [inline] vidtv_start_feed+0x33e/0x4d0 drivers/media/test-drivers/vidtv/vidtv_bridge.c:239


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: q6apm: move component registration to unmanaged version q6apm component registers dais dynamically from ASoC toplology, which are allocated using device managed version apis. Allocating both component and dynamic dais using managed version could lead to incorrect free ordering, dai will be freed while component still holding references to it. Fix this issue by moving component to unmanged version so that the dai pointers are only freeded after the component is removed. ================================================================== BUG: KASAN: slab-use-after-free in snd_soc_del_component_unlocked+0x3d4/0x400 [snd_soc_core] Read of size 8 at addr ffff00084493a6e8 by task kworker/u48:0/3426 Tainted: [W]=WARN Hardware name: LENOVO 21N2ZC5PUS/21N2ZC5PUS, BIOS N42ET57W (1.31 ) 08/08/2024 Workqueue: pdr_notifier_wq pdr_notifier_work [pdr_interface] Call trace: show_stack+0x28/0x7c (C) dump_stack_lvl+0x60/0x80 print_report+0x160/0x4b4 kasan_report+0xac/0xfc __asan_report_load8_noabort+0x20/0x34 snd_soc_del_component_unlocked+0x3d4/0x400 [snd_soc_core] snd_soc_unregister_component_by_driver+0x50/0x88 [snd_soc_core] devm_component_release+0x30/0x5c [snd_soc_core] devres_release_all+0x13c/0x210 device_unbind_cleanup+0x20/0x190 device_release_driver_internal+0x350/0x468 device_release_driver+0x18/0x30 bus_remove_device+0x1a0/0x35c device_del+0x314/0x7f0 device_unregister+0x20/0xbc apr_remove_device+0x5c/0x7c [apr] device_for_each_child+0xd8/0x160 apr_pd_status+0x7c/0xa8 [apr] pdr_notifier_work+0x114/0x240 [pdr_interface] process_one_work+0x500/0xb70 worker_thread+0x630/0xfb0 kthread+0x370/0x6c0 ret_from_fork+0x10/0x20 Allocated by task 77: kasan_save_stack+0x40/0x68 kasan_save_track+0x20/0x40 kasan_save_alloc_info+0x44/0x58 __kasan_kmalloc+0xbc/0xdc __kmalloc_node_track_caller_noprof+0x1f4/0x620 devm_kmalloc+0x7c/0x1c8 snd_soc_register_dai+0x50/0x4f0 [snd_soc_core] soc_tplg_pcm_elems_load+0x55c/0x1eb8 [snd_soc_core] snd_soc_tplg_component_load+0x4f8/0xb60 [snd_soc_core] audioreach_tplg_init+0x124/0x1fc [snd_q6apm] q6apm_audio_probe+0x10/0x1c [snd_q6apm] snd_soc_component_probe+0x5c/0x118 [snd_soc_core] soc_probe_component+0x44c/0xaf0 [snd_soc_core] snd_soc_bind_card+0xad0/0x2370 [snd_soc_core] snd_soc_register_card+0x3b0/0x4c0 [snd_soc_core] devm_snd_soc_register_card+0x50/0xc8 [snd_soc_core] x1e80100_platform_probe+0x208/0x368 [snd_soc_x1e80100] platform_probe+0xc0/0x188 really_probe+0x188/0x804 __driver_probe_device+0x158/0x358 driver_probe_device+0x60/0x190 __device_attach_driver+0x16c/0x2a8 bus_for_each_drv+0x100/0x194 __device_attach+0x174/0x380 device_initial_probe+0x14/0x20 bus_probe_device+0x124/0x154 deferred_probe_work_func+0x140/0x220 process_one_work+0x500/0xb70 worker_thread+0x630/0xfb0 kthread+0x370/0x6c0 ret_from_fork+0x10/0x20 Freed by task 3426: kasan_save_stack+0x40/0x68 kasan_save_track+0x20/0x40 __kasan_save_free_info+0x4c/0x80 __kasan_slab_free+0x78/0xa0 kfree+0x100/0x4a4 devres_release_all+0x144/0x210 device_unbind_cleanup+0x20/0x190 device_release_driver_internal+0x350/0x468 device_release_driver+0x18/0x30 bus_remove_device+0x1a0/0x35c device_del+0x314/0x7f0 device_unregister+0x20/0xbc apr_remove_device+0x5c/0x7c [apr] device_for_each_child+0xd8/0x160 apr_pd_status+0x7c/0xa8 [apr] pdr_notifier_work+0x114/0x240 [pdr_interface] process_one_work+0x500/0xb70 worker_thread+0x630/0xfb0 kthread+0x370/0x6c0 ret_from_fork+0x10/0x20


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections syzbot reported a general protection fault in vidtv_psi_desc_assign [1]. vidtv_psi_pmt_stream_init() can return NULL on memory allocation failure, but vidtv_channel_pmt_match_sections() does not check for this. When tail is NULL, the subsequent call to vidtv_psi_desc_assign(&tail->descriptor, desc) dereferences a NULL pointer offset, causing a general protection fault. Add a NULL check after vidtv_psi_pmt_stream_init(). On failure, clean up the already-allocated stream chain and return. [1] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN PTI KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:vidtv_psi_desc_assign+0x24/0x90 drivers/media/test-drivers/vidtv/vidtv_psi.c:629 Call Trace: <TASK> vidtv_channel_pmt_match_sections drivers/media/test-drivers/vidtv/vidtv_channel.c:349 [inline] vidtv_channel_si_init+0x1445/0x1a50 drivers/media/test-drivers/vidtv/vidtv_channel.c:479 vidtv_mux_init+0x526/0xbe0 drivers/media/test-drivers/vidtv/vidtv_mux.c:519 vidtv_start_streaming drivers/media/test-drivers/vidtv/vidtv_bridge.c:194 [inline] vidtv_start_feed+0x33e/0x4d0 drivers/media/test-drivers/vidtv/vidtv_bridge.c:239


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: staging: sm750fb: fix division by zero in ps_to_hz() ps_to_hz() is called from hw_sm750_crtc_set_mode() without validating that pixclock is non-zero. A zero pixclock passed via FBIOPUT_VSCREENINFO causes a division by zero. Fix by rejecting zero pixclock in lynxfb_ops_check_var(), consistent with other framebuffer drivers.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: fix device leak on probe failure Driver core holds a reference to the USB interface and its parent USB device while the interface is bound to a driver and there is no need to take additional references unless the structures are needed after disconnect. This driver takes a reference to the USB device during probe but does not to release it on all probe errors (e.g. when descriptor parsing fails). Drop the redundant device reference to fix the leak, reduce cargo culting, make it easier to spot drivers where an extra reference is needed, and reduce the risk of further memory leaks.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO Much like commit 19f953e74356 ("fbdev: fb_pm2fb: Avoid potential divide by zero error"), we also need to prevent that same crash from happening in the udlfb driver as it uses pixclock directly when dividing, which will crash.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: renesas_usb3: validate endpoint index in standard request handlers The GET_STATUS and SET/CLEAR_FEATURE handlers extract the endpoint number from the host-supplied wIndex without any sort of validation. Fix this up by validating the number of endpoints actually match up with the number the device has before attempting to dereference a pointer based on this math. This is just like what was done in commit ee0d382feb44 ("usb: gadget: aspeed_udc: validate endpoint index for ast udc") for the aspeed driver.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete() A broken/bored/mean USB host can overflow the skb_shared_info->frags[] array on a Linux gadget exposing a Phonet function by sending an unbounded sequence of full-page OUT transfers. pn_rx_complete() finalizes the skb only when req->actual < req->length, where req->length is set to PAGE_SIZE by the gadget. If the host always sends exactly PAGE_SIZE bytes per transfer, fp->rx.skb will never be reset and each completion will add another fragment via skb_add_rx_frag(). Once nr_frags exceeds MAX_SKB_FRAGS (default 17), subsequent frag stores overwrite memory adjacent to the shinfo on the heap. Drop the skb and account a length error when the frag limit is reached, matching the fix applied in t7xx by commit f0813bcd2d9d ("net: wwan: t7xx: fix potential skb->frags overflow in RX path").


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb() The block_len read from the host-supplied NTB header is checked against ntb_max but has no lower bound. When block_len is smaller than opts->ndp_size, the bounds check of: ndp_index > (block_len - opts->ndp_size) will underflow producing a huge unsigned value that ndp_index can never exceed, defeating the check entirely. The same underflow occurs in the datagram index checks against block_len - opts->dpe_size. With those checks neutered, a malicious USB host can choose ndp_index and datagram offsets that point past the actual transfer, and the skb_put_data() copies adjacent kernel memory into the network skb. Fix this by rejecting block lengths that cannot hold at least the NTB header plus one NDP. This will make block_len - opts->ndp_size and block_len - opts->dpe_size both well-defined. Commit 8d2b1a1ec9f5 ("CDC-NCM: avoid overflow in sanity checking") fixed a related class of issues on the host side of NCM.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO Much like commit 19f953e74356 ("fbdev: fb_pm2fb: Avoid potential divide by zero error"), we also need to prevent that same crash from happening in the udlfb driver as it uses pixclock directly when dividing, which will crash.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: fireworks: bound device-supplied status before string array lookup The status field in an EFW response is a 32-bit value supplied by the firewire device. efr_status_names[] has 17 entries so a status value outside that range goes off into the weeds when looking at the %s value. Even worse, the status could return EFR_STATUS_INCOMPLETE which is 0x80000000, and is obviously not in that array of potential strings. Fix this up by properly bounding the index against the array size and printing "unknown" if it's not recognized.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete() A malicious USB device claiming to be a CDC Phonet modem can overflow the skb_shared_info->frags[] array by sending an unbounded sequence of full-page bulk transfers. Drop the skb and increment the length error when the frag limit is reached. This matches the same fix that commit f0813bcd2d9d ("net: wwan: t7xx: fix potential skb->frags overflow in RX path") did for the t7xx driver.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: core: clamp report_size in s32ton() to avoid undefined shift s32ton() shifts by n-1 where n is the field's report_size, a value that comes directly from a HID device. The HID parser bounds report_size only to <= 256, so a broken HID device can supply a report descriptor with a wide field that triggers shift exponents up to 256 on a 32-bit type when an output report is built via hid_output_field() or hid_set_field(). Commit ec61b41918587 ("HID: core: fix shift-out-of-bounds in hid_report_raw_event") added the same n > 32 clamp to the function snto32(), but s32ton() was never given the same fix as I guess syzbot hadn't figured out how to fuzz a device the same way. Fix this up by just clamping the max value of n, just like snto32() does.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: alps: fix NULL pointer dereference in alps_raw_event() Commit ecfa6f34492c ("HID: Add HID_CLAIMED_INPUT guards in raw_event callbacks missing them") attempted to fix up the HID drivers that had missed the previous fix that was done in 2ff5baa9b527 ("HID: appleir: Fix potential NULL dereference at raw event handle"), but the alps driver was missed. Fix this up by properly checking in the hid-alps driver that it had been claimed correctly before attempting to process the raw event.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify() Initialize le_tmp64 to zero in rtw_BIP_verify() to prevent using uninitialized data. Smatch warns that only 6 bytes are copied to this 8-byte (u64) variable, leaving the last two bytes uninitialized: drivers/staging/rtl8723bs/core/rtw_security.c:1308 rtw_BIP_verify() warn: not copying enough bytes for '&le_tmp64' (8 vs 6 bytes) Initializing the variable at the start of the function fixes this warning and ensures predictable behavior.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: i2c: s3c24xx: check the size of the SMBUS message before using it The first byte of an i2c SMBUS message is the size, and it should be verified to ensure that it is in the range of 0..I2C_SMBUS_BLOCK_MAX before processing it. This is the same logic that was added in commit a6e04f05ce0b ("i2c: tegra: check msg length in SMBUS block read") to the i2c tegra driver.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: fix NULL-deref on disconnect Make sure to deregister the controller before dropping the reference to the driver data on disconnect to avoid NULL-pointer dereferences or use-after-free.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: batman-adv: hold claim backbone gateways by reference batadv_bla_add_claim() can replace claim->backbone_gw and drop the old gateway's last reference while readers still follow the pointer. The netlink claim dump path dereferences claim->backbone_gw->orig and takes claim->backbone_gw->crc_lock without pinning the underlying backbone gateway. batadv_bla_check_claim() still has the same naked pointer access pattern. Reuse batadv_bla_claim_get_backbone_gw() in both readers so they operate on a stable gateway reference until the read-side work is complete. This keeps the dump and claim-check paths aligned with the lifetime rules introduced for the other BLA claim readers.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject oversized global TT response buffers batadv_tt_prepare_tvlv_global_data() builds the allocation length for a global TT response in 16-bit temporaries. When a remote originator advertises a large enough global TT, the TT payload length plus the VLAN header offset can exceed 65535 and wrap before kmalloc(). The full-table response path still uses the original TT payload length when it fills tt_change, so the wrapped allocation is too small and batadv_tt_prepare_tvlv_global_data() writes past the end of the heap object before the later packet-size check runs. Fix this by rejecting TT responses whose TVLV value length cannot fit in the 16-bit TVLV payload length field.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: allocate rx skb before consuming bytes pn532_receive_buf() reports the number of accepted bytes to the serdev core. The current code consumes bytes into recv_skb and may already hand a complete frame to pn533_recv_frame() before allocating a fresh receive buffer. If that alloc_skb() fails, the callback returns 0 even though it has already consumed bytes, and it leaves recv_skb as NULL for the next receive callback. That breaks the receive_buf() accounting contract and can also lead to a NULL dereference on the next skb_put_u8(). Allocate the receive skb lazily before consuming the next byte instead. If allocation fails, return the number of bytes already accepted.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmsmac: Fix dma_free_coherent() size dma_alloc_consistent() may change the size to align it. The new size is saved in alloced. Change the free size to match the allocation size.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Input: uinput - fix circular locking dependency with ff-core A lockdep circular locking dependency warning can be triggered reproducibly when using a force-feedback gamepad with uinput (for example, playing ELDEN RING under Wine with a Flydigi Vader 5 controller): ff->mutex -> udev->mutex -> input_mutex -> dev->mutex -> ff->mutex The cycle is caused by four lock acquisition paths: 1. ff upload: input_ff_upload() holds ff->mutex and calls uinput_dev_upload_effect() -> uinput_request_submit() -> uinput_request_send(), which acquires udev->mutex. 2. device create: uinput_ioctl_handler() holds udev->mutex and calls uinput_create_device() -> input_register_device(), which acquires input_mutex. 3. device register: input_register_device() holds input_mutex and calls kbd_connect() -> input_register_handle(), which acquires dev->mutex. 4. evdev release: evdev_release() calls input_flush_device() under dev->mutex, which calls input_ff_flush() acquiring ff->mutex. Fix this by introducing a new state_lock spinlock to protect udev->state and udev->dev access in uinput_request_send() instead of acquiring udev->mutex. The function only needs to atomically check device state and queue an input event into the ring buffer via uinput_dev_event() -- both operations are safe under a spinlock (ktime_get_ts64() and wake_up_interruptible() do not sleep). This breaks the ff->mutex -> udev->mutex link since a spinlock is a leaf in the lock ordering and cannot form cycles with mutexes. To keep state transitions visible to uinput_request_send(), protect writes to udev->state in uinput_create_device() and uinput_destroy_device() with the same state_lock spinlock. Additionally, move init_completion(&request->done) from uinput_request_send() to uinput_request_submit() before uinput_request_reserve_slot(). Once the slot is allocated, uinput_flush_requests() may call complete() on it at any time from the destroy path, so the completion must be initialised before the request becomes visible. Lock ordering after the fix: ff->mutex -> state_lock (spinlock, leaf) udev->mutex -> state_lock (spinlock, leaf) udev->mutex -> input_mutex -> dev->mutex -> ff->mutex (no back-edge)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00usb: fix devres lifetime USB drivers bind to USB interfaces and any device managed resources should have their lifetime tied to the interface rather than parent USB device. This avoids issues like memory leaks when drivers are unbound without their devices being physically disconnected (e.g. on probe deferral or configuration changes). Fix the USB anchor lifetime so that it is released on driver unbind.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: openvswitch: defer tunnel netdev_put to RCU release ovs_netdev_tunnel_destroy() may run after NETDEV_UNREGISTER already detached the device. Dropping the netdev reference in destroy can race with concurrent readers that still observe vport->dev. Do not release vport->dev in ovs_netdev_tunnel_destroy(). Instead, let vport_netdev_free() drop the reference from the RCU callback, matching the non-tunnel destroy path and avoiding additional synchronization under RTNL.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: gpio: omap: do not register driver in probe() Commit 11a78b794496 ("ARM: OMAP: MPUIO wake updates") registers the omap_mpuio_driver from omap_mpuio_init(), which is called from omap_gpio_probe(). However, it neither makes sense to register drivers from probe() callbacks of other drivers, nor does the driver core allow registering drivers with a device lock already being held. The latter was revealed by commit dc23806a7c47 ("driver core: enforce device_lock for driver_match_device()") leading to a potential deadlock condition described in [1]. Additionally, the omap_mpuio_driver is never unregistered from the driver core, even if the module is unloaded. Hence, register the omap_mpuio_driver from the module initcall and unregister it in module_exit().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: caiaq: take a reference on the USB device in create_card() The caiaq driver stores a pointer to the parent USB device in cdev->chip.dev but never takes a reference on it. The card's private_free callback, snd_usb_caiaq_card_free(), can run asynchronously via snd_card_free_when_closed() after the USB device has already been disconnected and freed, so any access to cdev->chip.dev in that path dereferences a freed usb_device. On top of the refcounting issue, the current card_free implementation calls usb_reset_device(cdev->chip.dev). A reset in a free callback is inappropriate: the device is going away, the call takes the device lock in a teardown context, and the reset races with the disconnect path that the callback is already cleaning up after. Take a reference on the USB device in create_card() with usb_get_dev(), drop it with usb_put_dev() in the free callback, and remove the usb_reset_device() call.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_uac1_legacy: validate control request size f_audio_complete() copies req->length bytes into a 4-byte stack variable: u32 data = 0; memcpy(&data, req->buf, req->length); req->length is derived from the host-controlled USB request path, which can lead to a stack out-of-bounds write. Validate req->actual against the expected payload size for the supported control selectors and decode only the expected amount of data. This avoids copying a host-influenced length into a fixed-size stack object.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: fix NULL pointer dereference during unbind race Commit b81ac4395bbe ("usb: gadget: uvc: allow for application to cleanly shutdown") introduced two stages of synchronization waits totaling 1500ms in uvc_function_unbind() to prevent several types of kernel panics. However, this timing-based approach is insufficient during power management (PM) transitions. When the PM subsystem starts freezing user space processes, the wait_event_interruptible_timeout() is aborted early, which allows the unbind thread to proceed and nullify the gadget pointer (cdev->gadget = NULL): [ 814.123447][ T947] configfs-gadget.g1 gadget.0: uvc: uvc_function_unbind() [ 814.178583][ T3173] PM: suspend entry (deep) [ 814.192487][ T3173] Freezing user space processes [ 814.197668][ T947] configfs-gadget.g1 gadget.0: uvc: uvc_function_unbind no clean disconnect, wait for release When the PM subsystem resumes or aborts the suspend and tasks are restarted, the V4L2 release path is executed and attempts to access the already nullified gadget pointer, triggering a kernel panic: [ 814.292597][ C0] PM: pm_system_irq_wakeup: 479 triggered dhdpcie_host_wake [ 814.386727][ T3173] Restarting tasks ... [ 814.403522][ T4558] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000030 [ 814.404021][ T4558] pc : usb_gadget_deactivate+0x14/0xf4 [ 814.404031][ T4558] lr : usb_function_deactivate+0x54/0x94 [ 814.404078][ T4558] Call trace: [ 814.404080][ T4558] usb_gadget_deactivate+0x14/0xf4 [ 814.404083][ T4558] usb_function_deactivate+0x54/0x94 [ 814.404087][ T4558] uvc_function_disconnect+0x1c/0x5c [ 814.404092][ T4558] uvc_v4l2_release+0x44/0xac [ 814.404095][ T4558] v4l2_release+0xcc/0x130 Address the race condition and NULL pointer dereference by: 1. State Synchronization (flag + mutex) Introduce a 'func_unbound' flag in struct uvc_device. This allows uvc_function_disconnect() to safely skip accessing the nullified cdev->gadget pointer. As suggested by Alan Stern, this flag is protected by a new mutex (uvc->lock) to ensure proper memory ordering and prevent instruction reordering or speculative loads. This mutex is also used to protect 'func_connected' for consistent state management. 2. Explicit Synchronization (completion) Use a completion to synchronize uvc_function_unbind() with the uvc_vdev_release() callback. This prevents Use-After-Free (UAF) by ensuring struct uvc_device is freed after all video device resources are released.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo Commit ec35c1969650 ("usb: gadget: f_ncm: Fix net_device lifecycle with device_move") reparents the gadget device to /sys/devices/virtual during unbind, clearing the gadget pointer. If the userspace tool queries on the surviving interface during this detached window, this leads to a NULL pointer dereference. Unable to handle kernel NULL pointer dereference Call trace: eth_get_drvinfo+0x50/0x90 ethtool_get_drvinfo+0x5c/0x1f0 __dev_ethtool+0xaec/0x1fe0 dev_ethtool+0x134/0x2e0 dev_ioctl+0x338/0x560 Add a NULL check for dev->gadget in eth_get_drvinfo(). When detached, skip copying the fw_version and bus_info strings, which is natively handled by ethtool_get_drvinfo for empty strings.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_ether: Fix race between gether_disconnect and eth_stop A race condition between gether_disconnect() and eth_stop() leads to a NULL pointer dereference. Specifically, if eth_stop() is triggered concurrently while gether_disconnect() is tearing down the endpoints, eth_stop() attempts to access the cleared endpoint descriptor, causing the following NPE: Unable to handle kernel NULL pointer dereference Call trace: __dwc3_gadget_ep_enable+0x60/0x788 dwc3_gadget_ep_enable+0x70/0xe4 usb_ep_enable+0x60/0x15c eth_stop+0xb8/0x108 Because eth_stop() crashes while holding the dev->lock, the thread running gether_disconnect() fails to acquire the same lock and spins forever, resulting in a hardlockup: Core - Debugging Information for Hardlockup core(7) Call trace: queued_spin_lock_slowpath+0x94/0x488 _raw_spin_lock+0x64/0x6c gether_disconnect+0x19c/0x1e8 ncm_set_alt+0x68/0x1a0 composite_setup+0x6a0/0xc50 The root cause is that the clearing of dev->port_usb in gether_disconnect() is delayed until the end of the function. Move the clearing of dev->port_usb to the very beginning of gether_disconnect() while holding dev->lock. This cuts off the link immediately, ensuring eth_stop() will see dev->port_usb as NULL and safely bail out.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: possible double-free of cctx->remote_heap fastrpc_init_create_static_process() may free cctx->remote_heap on the err_map path but does not clear the pointer. Later, fastrpc_rpmsg_remove() frees cctx->remote_heap again if it is non-NULL, which can lead to a double-free if the INIT_CREATE_STATIC ioctl hits the error path and the rpmsg device is subsequently removed/unbound. Clear cctx->remote_heap after freeing it in the error path to prevent the later cleanup from freeing it again. This issue was found by an in-house analysis workflow that extracts AST-based information and runs static checks, with LLM assistance for triage, and was confirmed by manual code review. No hardware testing was performed.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: comedi: me4000: Fix potential overrun of firmware buffer `me4000_xilinx_download()` loads the firmware that was requested by `request_firmware()`. It is possible for it to overrun the source buffer because it blindly trusts the file format. It reads a data stream length from the first 4 bytes into variable `file_length` and reads the data stream contents of length `file_length` from offset 16 onwards. Add a test to ensure that the supplied firmware is long enough to contain the header and the data stream. On failure, log an error and return `-EINVAL`. Note: The firmware loading was totally broken before commit ac584af59945 ("staging: comedi: me4000: fix firmware downloading"), but that is the most sensible target for this fix.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: comedi: me_daq: Fix potential overrun of firmware buffer `me2600_xilinx_download()` loads the firmware that was requested by `request_firmware()`. It is possible for it to overrun the source buffer because it blindly trusts the file format. It reads a data stream length from the first 4 bytes into variable `file_length` and reads the data stream contents of length `file_length` from offset 16 onwards. Although it checks that the supplied firmware is at least 16 bytes long, it does not check that it is long enough to contain the data stream. Add a test to ensure that the supplied firmware is long enough to contain the header and the data stream. On failure, log an error and return `-EINVAL`.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: comedi: ni_atmio16d: Fix invalid clean-up after failed attach If the driver's COMEDI "attach" handler function (`atmio16d_attach()`) returns an error, the COMEDI core will call the driver's "detach" handler function (`atmio16d_detach()`) to clean up. This calls `reset_atmio16d()` unconditionally, but depending on where the error occurred in the attach handler, the device may not have been sufficiently initialized to call `reset_atmio16d()`. It uses `dev->iobase` as the I/O port base address and `dev->private` as the pointer to the COMEDI device's private data structure. `dev->iobase` may still be set to its initial value of 0, which would result in undesired writes to low I/O port addresses. `dev->private` may still be `NULL`, which would result in null pointer dereferences. Fix `atmio16d_detach()` by checking that `dev->private` is valid (non-null) before calling `reset_atmio16d()`. This implies that `dev->iobase` was set correctly since that is set up before `dev->private`.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: comedi: dt2815: add hardware detection to prevent crash The dt2815 driver crashes when attached to I/O ports without actual hardware present. This occurs because syzkaller or users can attach the driver to arbitrary I/O addresses via COMEDI_DEVCONFIG ioctl. When no hardware exists at the specified port, inb() operations return 0xff (floating bus), but outb() operations can trigger page faults due to undefined behavior, especially under race conditions: BUG: unable to handle page fault for address: 000000007fffff90 #PF: supervisor write access in kernel mode #PF: error_code(0x0002) - not-present page RIP: 0010:dt2815_attach+0x6e0/0x1110 Add hardware detection by reading the status register before attempting any write operations. If the read returns 0xff, assume no hardware is present and fail the attach with -ENODEV. This prevents crashes from outb() operations on non-existent hardware.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: gadget: fix state inconsistency on gadget init failure When cdns3_gadget_start() fails, the DRD hardware is left in gadget mode while software state remains INACTIVE, creating hardware/software state inconsistency. When switching to host mode via sysfs: echo host > /sys/class/usb_role/13180000.usb-role-switch/role The role state is not set to CDNS_ROLE_STATE_ACTIVE due to the error, so cdns_role_stop() skips cleanup because state is still INACTIVE. This violates the DRD controller design specification (Figure22), which requires returning to idle state before switching roles. This leads to a synchronous external abort in xhci_gen_setup() when setting up the host controller: [ 516.440698] configfs-gadget 13180000.usb: failed to start g1: -19 [ 516.442035] cdns-usb3 13180000.usb: Failed to add gadget [ 516.443278] cdns-usb3 13180000.usb: set role 2 has failed ... [ 1301.375722] xhci-hcd xhci-hcd.1.auto: xHCI Host Controller [ 1301.377716] Internal error: synchronous external abort: 96000010 [#1] PREEMPT SMP [ 1301.382485] pc : xhci_gen_setup+0xa4/0x408 [ 1301.393391] backtrace: ... xhci_gen_setup+0xa4/0x408 <-- CRASH xhci_plat_setup+0x44/0x58 usb_add_hcd+0x284/0x678 ... cdns_role_set+0x9c/0xbc <-- Role switch Fix by calling cdns_drd_gadget_off() in the error path to properly clean up the DRD gadget state.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: gadget: fix NULL pointer dereference in ep_queue When the gadget endpoint is disabled or not yet configured, the ep->desc pointer can be NULL. This leads to a NULL pointer dereference when __cdns3_gadget_ep_queue() is called, causing a kernel crash. Add a check to return -ESHUTDOWN if ep->desc is NULL, which is the standard return code for unconfigured endpoints. This prevents potential crashes when ep_queue is called on endpoints that are not ready.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: gadget: Fix spin_lock/unlock mismatch in dwc2_hsotg_udc_stop() dwc2_gadget_exit_clock_gating() internally calls call_gadget() macro, which expects hsotg->lock to be held since it does spin_unlock/spin_lock around the gadget driver callback invocation. However, dwc2_hsotg_udc_stop() calls dwc2_gadget_exit_clock_gating() without holding the lock. This leads to: - spin_unlock on a lock that is not held (undefined behavior) - The lock remaining held after dwc2_gadget_exit_clock_gating() returns, causing a deadlock when spin_lock_irqsave() is called later in the same function. Fix this by acquiring hsotg->lock before calling dwc2_gadget_exit_clock_gating() and releasing it afterwards, which satisfies the locking requirement of the call_gadget() macro.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iio: gyro: mpu3050: Move iio_device_register() to correct location iio_device_register() should be at the end of the probe function to prevent race conditions. Place iio_device_register() at the end of the probe function and place iio_device_unregister() accordingly.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iio: gyro: mpu3050: Fix irq resource leak The interrupt handler is setup but only a few lines down if iio_trigger_register() fails the function returns without properly releasing the handler. Add cleanup goto to resolve resource leak. Detected by Smatch: drivers/iio/gyro/mpu3050-core.c:1128 mpu3050_trigger_probe() warn: 'irq' from request_threaded_irq() not released on lines: 1124.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iio: gyro: mpu3050: Fix incorrect free_irq() variable The handler for the IRQ part of this driver is mpu3050->trig but, in the teardown free_irq() is called with handler mpu3050. Use correct IRQ handler when calling free_irq().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Change AMDGPU_VA_RESERVED_TRAP_SIZE to 64KB Currently, AMDGPU_VA_RESERVED_TRAP_SIZE is hardcoded to 8KB, while KFD_CWSR_TBA_TMA_SIZE is defined as 2 * PAGE_SIZE. On systems with 4K pages, both values match (8KB), so allocation and reserved space are consistent. However, on 64K page-size systems, KFD_CWSR_TBA_TMA_SIZE becomes 128KB, while the reserved trap area remains 8KB. This mismatch causes the kernel to crash when running rocminfo or rccl unit tests. Kernel attempted to read user page (2) - exploit attempt? (uid: 1001) BUG: Kernel NULL pointer dereference on read at 0x00000002 Faulting instruction address: 0xc0000000002c8a64 Oops: Kernel access of bad area, sig: 11 [#1] LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=2048 NUMA pSeries CPU: 34 UID: 1001 PID: 9379 Comm: rocminfo Tainted: G E 6.19.0-rc4-amdgpu-00320-gf23176405700 #56 VOLUNTARY Tainted: [E]=UNSIGNED_MODULE Hardware name: IBM,9105-42A POWER10 (architected) 0x800200 0xf000006 of:IBM,FW1060.30 (ML1060_896) hv:phyp pSeries NIP: c0000000002c8a64 LR: c00000000125dbc8 CTR: c00000000125e730 REGS: c0000001e0957580 TRAP: 0300 Tainted: G E MSR: 8000000000009033 <SF,EE,ME,IR,DR,RI,LE> CR: 24008268 XER: 00000036 CFAR: c00000000125dbc4 DAR: 0000000000000002 DSISR: 40000000 IRQMASK: 1 GPR00: c00000000125d908 c0000001e0957820 c0000000016e8100 c00000013d814540 GPR04: 0000000000000002 c00000013d814550 0000000000000045 0000000000000000 GPR08: c00000013444d000 c00000013d814538 c00000013d814538 0000000084002268 GPR12: c00000000125e730 c000007e2ffd5f00 ffffffffffffffff 0000000000020000 GPR16: 0000000000000000 0000000000000002 c00000015f653000 0000000000000000 GPR20: c000000138662400 c00000013d814540 0000000000000000 c00000013d814500 GPR24: 0000000000000000 0000000000000002 c0000001e0957888 c0000001e0957878 GPR28: c00000013d814548 0000000000000000 c00000013d814540 c0000001e0957888 NIP [c0000000002c8a64] __mutex_add_waiter+0x24/0xc0 LR [c00000000125dbc8] __mutex_lock.constprop.0+0x318/0xd00 Call Trace: 0xc0000001e0957890 (unreliable) __mutex_lock.constprop.0+0x58/0xd00 amdgpu_amdkfd_gpuvm_alloc_memory_of_gpu+0x6fc/0xb60 [amdgpu] kfd_process_alloc_gpuvm+0x54/0x1f0 [amdgpu] kfd_process_device_init_cwsr_dgpu+0xa4/0x1a0 [amdgpu] kfd_process_device_init_vm+0xd8/0x2e0 [amdgpu] kfd_ioctl_acquire_vm+0xd0/0x130 [amdgpu] kfd_ioctl+0x514/0x670 [amdgpu] sys_ioctl+0x134/0x180 system_call_exception+0x114/0x300 system_call_vectored_common+0x15c/0x2ec This patch changes AMDGPU_VA_RESERVED_TRAP_SIZE to 64 KB and KFD_CWSR_TBA_TMA_SIZE to the AMD GPU page size. This means we reserve 64 KB for the trap in the address space, but only allocate 8 KB within it. With this approach, the allocation size never exceeds the reserved area. (cherry picked from commit 31b8de5e55666f26ea7ece5f412b83eab3f56dbb)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-adc161s626: use DMA-safe memory for spi_read() Add a DMA-safe buffer and use it for spi_read() instead of a stack memory. All SPI buffers must be DMA-safe. Since we only need up to 3 bytes, we just use a u8[] instead of __be16 and __be32 and change the conversion functions appropriately.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: hwmon: (occ) Fix division by zero in occ_show_power_1() In occ_show_power_1() case 1, the accumulator is divided by update_tag without checking for zero. If no samples have been collected yet (e.g. during early boot when the sensor block is included but hasn't been updated), update_tag is zero, causing a kernel divide-by-zero crash. The 2019 fix in commit 211186cae14d ("hwmon: (occ) Fix division by zero issue") only addressed occ_get_powr_avg() used by occ_show_power_2() and occ_show_power_a0(). This separate code path in occ_show_power_1() was missed. Fix this by reusing the existing occ_get_powr_avg() helper, which already handles the zero-sample case and uses mul_u64_u32_div() to multiply before dividing for better precision. Move the helper above occ_show_power_1() so it is visible at the call site. [groeck: Fix alignment problems reported by checkpatch]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SMP: derive legacy responder STK authentication from MITM state The legacy responder path in smp_random() currently labels the stored STK as authenticated whenever pending_sec_level is BT_SECURITY_HIGH. That reflects what the local service requested, not what the pairing flow actually achieved. For Just Works/Confirm legacy pairing, SMP_FLAG_MITM_AUTH stays clear and the resulting STK should remain unauthenticated even if the local side requested HIGH security. Use the established MITM state when storing the responder STK so the key metadata matches the pairing result. This also keeps the legacy path aligned with the Secure Connections code, which already treats JUST_WORKS/JUST_CFM as unauthenticated.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: ctxfi: Fix missing SPDIFI1 index handling SPDIF1 DAIO type isn't properly handled in daio_device_index() for hw20k2, and it returned -EINVAL, which ended up with the out-of-bounds array access. Follow the hw20k1 pattern and return the proper index for this type, too.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: caiaq: fix stack out-of-bounds read in init_card The loop creates a whitespace-stripped copy of the card shortname where `len < sizeof(card->id)` is used for the bounds check. Since sizeof(card->id) is 16 and the local id buffer is also 16 bytes, writing 16 non-space characters fills the entire buffer, overwriting the terminating nullbyte. When this non-null-terminated string is later passed to snd_card_set_id() -> copy_valid_id_string(), the function scans forward with `while (*nid && ...)` and reads past the end of the stack buffer, reading the contents of the stack. A USB device with a product name containing many non-ASCII, non-space characters (e.g. multibyte UTF-8) will reliably trigger this as follows: BUG: KASAN: stack-out-of-bounds in copy_valid_id_string sound/core/init.c:696 [inline] BUG: KASAN: stack-out-of-bounds in snd_card_set_id_no_lock+0x698/0x74c sound/core/init.c:718 The off-by-one has been present since commit bafeee5b1f8d ("ALSA: snd_usb_caiaq: give better shortname") from June 2009 (v2.6.31-rc1), which first introduced this whitespace-stripping loop. The original code never accounted for the null terminator when bounding the copy. Fix this by changing the loop bound to `sizeof(card->id) - 1`, ensuring at least one byte remains as the null terminator.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler() The memcpy function assumes the dynamic array notif->matches is at least as large as the number of bytes to copy. Otherwise, results->matches may contain unwanted data. To guarantee safety, extend the validation in one of the checks to ensure sufficient packet length. Found by Linux Verification Center (linuxtesting.org) with SVACE.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix u8 overflow in SSID scan buffer size calculation The variable valuesize is declared as u8 but accumulates the total length of all SSIDs to scan. Each SSID contributes up to 33 bytes (IEEE80211_MAX_SSID_LEN + 1), and with WILC_MAX_NUM_PROBED_SSID (10) SSIDs the total can reach 330, which wraps around to 74 when stored in a u8. This causes kmalloc to allocate only 75 bytes while the subsequent memcpy writes up to 331 bytes into the buffer, resulting in a 256-byte heap buffer overflow. Widen valuesize from u8 to u32 to accommodate the full range.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/ioc32: stop speculation on the drm_compat_ioctl path The drm compat ioctl path takes a user controlled pointer, and then dereferences it into a table of function pointers, the signature method of spectre problems. Fix this up by calling array_index_nospec() on the index to the function pointer list.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Handle DBC deactivation if the owner went away When a DBC is released, the device sends a QAIC_TRANS_DEACTIVATE_FROM_DEV transaction to the host over the QAIC_CONTROL MHI channel. QAIC handles this by calling decode_deactivate() to release the resources allocated for that DBC. Since that handling is done in the qaic_manage_ioctl() context, if the user goes away before receiving and handling the deactivation, the host will be out-of-sync with the DBCs available for use, and the DBC resources will not be freed unless the device is removed. If another user loads and requests to activate a network, then the device assigns the same DBC to that network, QAIC will "indefinitely" wait for dbc->in_use = false, leading the user process to hang. As a solution to this, handle QAIC_TRANS_DEACTIVATE_FROM_DEV transactions that are received after the user has gone away.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at line 48 and returns 1 (error). This error propagates back through the call chain: x25_queue_rx_frame returns 1 | v x25_state3_machine receives the return value 1 and takes the else branch at line 278, setting queued=0 and returning 0 | v x25_process_rx_frame returns queued=0 | v x25_backlog_rcv at line 452 sees queued=0 and calls kfree_skb(skb) again This would free the same skb twice. Looking at x25_backlog_rcv: net/x25/x25_in.c:x25_backlog_rcv() { ... queued = x25_process_rx_frame(sk, skb); ... if (!queued) kfree_skb(skb); }


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate mesh send advertising payload length mesh_send() currently bounds MGMT_OP_MESH_SEND by total command length, but it never verifies that the bytes supplied for the flexible adv_data[] array actually match the embedded adv_data_len field. MGMT_MESH_SEND_SIZE only covers the fixed header, so a truncated command can still pass the existing 20..50 byte range check and later drive the async mesh send path past the end of the queued command buffer. Keep rejecting zero-length and oversized advertising payloads, but validate adv_data_len explicitly and require the command length to exactly match the flexible array size before queueing the request.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt hci_conn lookup and field access must be covered by hdev lock in hci_le_remote_conn_param_req_evt, otherwise it's possible it is freed concurrently. Extend the hci_dev_lock critical section to cover all conn usage.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync hci_conn lookup and field access must be covered by hdev lock in set_cig_params_sync, otherwise it's possible it is freed concurrently. Take hdev lock to prevent hci_conn from being deleted or modified concurrently. Just RCU lock is not suitable here, as we also want to avoid "tearing" in the configuration.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate LTK enc_size on load Load Long Term Keys stores the user-provided enc_size and later uses it to size fixed-size stack operations when replying to LE LTK requests. An enc_size larger than the 16-byte key buffer can therefore overflow the reply stack buffer. Reject oversized enc_size values while validating the management LTK record so invalid keys never reach the stored key state.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: NFC: pn533: bound the UART receive buffer pn532_receive_buf() appends every incoming byte to dev->recv_skb and only resets the buffer after pn532_uart_rx_is_frame() recognizes a complete frame. A continuous stream of bytes without a valid PN532 frame header therefore keeps growing the skb until skb_put_u8() hits the tail limit. Drop the accumulated partial frame once the fixed receive buffer is full so malformed UART traffic cannot grow the skb past PN532_UART_SKB_BUFF_LEN.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: af-alg - fix NULL pointer dereference in scatterwalk The AF_ALG interface fails to unmark the end of a Scatter/Gather List (SGL) when chaining a new af_alg_tsgl structure. If a sendmsg() fills an SGL exactly to MAX_SGL_ENTS, the last entry is marked as the end. A subsequent sendmsg() allocates a new SGL and chains it, but fails to clear the end marker on the previous SGL's last data entry. This causes the crypto scatterwalk to hit a premature end, returning NULL on sg_next() and leading to a kernel panic during dereference. Fix this by explicitly unmarking the end of the previous SGL when performing sg_chain() in af_alg_alloc_tsgl().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: Check to ensure report responses match the request It is possible for a malicious (or clumsy) device to respond to a specific report's feature request using a completely different report ID. This can cause confusion in the HID core resulting in nasty side-effects such as OOB writes. Add a check to ensure that the report ID in the response, matches the one that was requested. If it doesn't, omit reporting the raw event and return early.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq The wacom_intuos_bt_irq() function processes Bluetooth HID reports without sufficient bounds checking. A maliciously crafted short report can trigger an out-of-bounds read when copying data into the wacom structure. Specifically, report 0x03 requires at least 22 bytes to safely read the processed data and battery status, while report 0x04 (which falls through to 0x03) requires 32 bytes. Add explicit length checks for these report IDs and log a warning if a short report is received.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback NETIF_F_IPV6_CSUM only advertises support for checksum offload of packets without IPv6 extension headers. Packets with extension headers must fall back onto software checksumming. Since TSO depends on checksum offload, those must revert to GSO. The below commit introduces that fallback. It always checks network header length. For tunneled packets, the inner header length must be checked instead. Extend the check accordingly. A special case is tunneled packets without inner IP protocol. Such as RFC 6951 SCTP in UDP. Those are not standard IPv6 followed by transport header either, so also must revert to the software GSO path.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix pass-by-value structs causing MSAN warnings vidtv_ts_null_write_into() and vidtv_ts_pcr_write_into() take their argument structs by value, causing MSAN to report uninit-value warnings. While only vidtv_ts_null_write_into() has triggered a report so far, both functions share the same issue. Fix by passing both structs by const pointer instead, avoiding the stack copy of the struct along with its MSAN shadow and origin metadata. The functions do not modify the structs, which is enforced by the const qualifier.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: serial: 8250: Fix TX deadlock when using DMA `dmaengine_terminate_async` does not guarantee that the `__dma_tx_complete` callback will run. The callback is currently the only place where `dma->tx_running` gets cleared. If the transaction is canceled and the callback never runs, then `dma->tx_running` will never get cleared and we will never schedule new TX DMA transactions again. This change makes it so we clear `dma->tx_running` after we terminate the DMA transaction. This is "safe" because `serial8250_tx_dma_flush` is holding the UART port lock. The first thing the callback does is also grab the UART port lock, so access to `dma->tx_running` is serialized.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp() l2cap_ecred_reconf_rsp() casts the incoming data to struct l2cap_ecred_conn_rsp (the ECRED *connection* response, 8 bytes with result at offset 6) instead of struct l2cap_ecred_reconf_rsp (2 bytes with result at offset 0). This causes two problems: - The sizeof(*rsp) length check requires 8 bytes instead of the correct 2, so valid L2CAP_ECRED_RECONF_RSP packets are rejected with -EPROTO. - rsp->result reads from offset 6 instead of offset 0, returning wrong data when the packet is large enough to pass the check. Fix by using the correct type. Also pass the already byte-swapped result variable to BT_DBG instead of the raw __le16 field.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix not releasing workqueue on .release() The workqueue associated with an DSA/IAA device is not released when the object is freed.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_ll: Fix firmware leak on error path Smatch reports: drivers/bluetooth/hci_ll.c:587 download_firmware() warn: 'fw' from request_firmware() not released on lines: 544. In download_firmware(), if request_firmware() succeeds but the returned firmware content is invalid (no data or zero size), the function returns without releasing the firmware, resulting in a resource leak. Fix this by calling release_firmware() before returning when request_firmware() succeeded but the firmware content is invalid.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: platform_get_irq_byname() returns an int platform_get_irq_byname() will return a negative value if an error happens, so it should be checked and not just passed directly into devm_request_threaded_irq() hoping all will be ok.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xsk: validate MTU against usable frame size on bind AF_XDP bind currently accepts zero-copy pool configurations without verifying that the device MTU fits into the usable frame space provided by the UMEM chunk. This becomes a problem since we started to respect tailroom which is subtracted from chunk_size (among with headroom). 2k chunk size might not provide enough space for standard 1500 MTU, so let us catch such settings at bind time. Furthermore, validate whether underlying HW will be able to satisfy configured MTU wrt XSK's frame size multiplied by supported Rx buffer chain length (that is exposed via net_device::xdp_zc_max_segs).


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: nfc: s3fwrn5: allocate rx skb before consuming bytes s3fwrn82_uart_read() reports the number of accepted bytes to the serdev core. The current code consumes bytes into recv_skb and may already deliver a complete frame before allocating a fresh receive buffer. If that alloc_skb() fails, the callback returns 0 even though it has already consumed bytes, and it leaves recv_skb as NULL for the next receive callback. That breaks the receive_buf() accounting contract and can also lead to a NULL dereference on the next skb_put_u8(). Allocate the receive skb lazily before consuming the next byte instead. If allocation fails, return the number of bytes already accepted.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Fix a memory leak in hang state error path When vc4_save_hang_state() encounters an early return condition, it returns without freeing the previously allocated `kernel_state`, leaking memory. Add the missing kfree() calls by consolidating the early return paths into a single place.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Fix memory leak of BO array in hang state The hang state's BO array is allocated separately with kzalloc() in vc4_save_hang_state() but never freed in vc4_free_hang_state(). Add the missing kfree() for the BO array before freeing the hang state struct.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: roccat: fix use-after-free in roccat_report_event roccat_report_event() iterates over the device->readers list without holding the readers_lock. This allows a concurrent roccat_release() to remove and free a reader while it's still being accessed, leading to a use-after-free. Protect the readers list traversal with the readers_lock mutex.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: validate packet IDs before indexing tx_frames wl1251_tx_packet_cb() uses the firmware completion ID directly to index the fixed 16-entry wl->tx_frames[] array. The ID is a raw u8 from the completion block, and the callback does not currently verify that it fits the array before dereferencing it. Reject completion IDs that fall outside wl->tx_frames[] and keep the existing NULL check in the same guard. This keeps the fix local to the trust boundary and avoids touching the rest of the completion flow.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() If overlay is used on top of btrfs, dentry->d_sb translates to overlay's super block and fsid assignment will lead to a crash. Use file_inode(file)->i_sb to always get btrfs_sb.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix zero size inode with non-zero size after log replay When logging that an inode exists, as part of logging a new name or logging new dir entries for a directory, we always set the generation of the logged inode item to 0. This is to signal during log replay (in overwrite_item()), that we should not set the i_size since we only logged that an inode exists, so the i_size of the inode in the subvolume tree must be preserved (as when we log new names or that an inode exists, we don't log extents). This works fine except when we have already logged an inode in full mode or it's the first time we are logging an inode created in a past transaction, that inode has a new i_size of 0 and then we log a new name for the inode (due to a new hardlink or a rename), in which case we log an i_size of 0 for the inode and a generation of 0, which causes the log replay code to not update the inode's i_size to 0 (in overwrite_item()). An example scenario: mkdir /mnt/dir xfs_io -f -c "pwrite 0 64K" /mnt/dir/foo sync xfs_io -c "truncate 0" -c "fsync" /mnt/dir/foo ln /mnt/dir/foo /mnt/dir/bar xfs_io -c "fsync" /mnt/dir <power fail> After log replay the file remains with a size of 64K. This is because when we first log the inode, when we fsync file foo, we log its current i_size of 0, and then when we create a hard link we log again the inode in exists mode (LOG_INODE_EXISTS) but we set a generation of 0 for the inode item we add to the log tree, so during log replay overwrite_item() sees that the generation is 0 and i_size is 0 so we skip updating the inode's i_size from 64K to 0. Fix this by making sure at fill_inode_item() we always log the real generation of the inode if it was logged in the current transaction with the i_size we logged before. Also if an inode created in a previous transaction is logged in exists mode only, make sure we log the i_size stored in the inode item located from the commit root, so that if we log multiple times that the inode exists we get the correct i_size. A test case for fstests will follow soon.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fbcon: check return value of con2fb_acquire_newinfo() If fbcon_open() fails when called from con2fb_acquire_newinfo() then info->fbcon_par pointer remains NULL which is later dereferenced. Add check for return value of the function con2fb_acquire_newinfo() to avoid it. Found by Linux Verification Center (linuxtesting.org) with SVACE.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: pstore: ram_core: fix incorrect success return when vmap() fails In persistent_ram_vmap(), vmap() may return NULL on failure. If offset is non-zero, adding offset_in_page(start) causes the function to return a non-NULL pointer even though the mapping failed. persistent_ram_buffer_map() therefore incorrectly returns success. Subsequent access to prz->buffer may dereference an invalid address and cause crashes. Add proper NULL checking for vmap() failures.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ima: verify the previous kernel's IMA buffer lies in addressable RAM Patch series "Address page fault in ima_restore_measurement_list()", v3. When the second-stage kernel is booted via kexec with a limiting command line such as "mem=<size>" we observe a pafe fault that happens. BUG: unable to handle page fault for address: ffff97793ff47000 RIP: ima_restore_measurement_list+0xdc/0x45a #PF: error_code(0x0000) not-present page This happens on x86_64 only, as this is already fixed in aarch64 in commit: cbf9c4b9617b ("of: check previous kernel's ima-kexec-buffer against memory bounds") This patch (of 3): When the second-stage kernel is booted with a limiting command line (e.g. "mem=<size>"), the IMA measurement buffer handed over from the previous kernel may fall outside the addressable RAM of the new kernel. Accessing such a buffer can fault during early restore. Introduce a small generic helper, ima_validate_range(), which verifies that a physical [start, end] range for the previous-kernel IMA buffer lies within addressable memory: - On x86, use pfn_range_is_mapped(). - On OF based architectures, use page_is_ram().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation Commit cc3ed80ae69f ("KVM: nSVM: always use vmcb01 to for vmsave/vmload of guest state") made KVM always use vmcb01 for the fields controlled by VMSAVE/VMLOAD, but it missed updating the VMLOAD/VMSAVE emulation code to always use vmcb01. As a result, if VMSAVE/VMLOAD is executed by an L2 guest and is not intercepted by L1, KVM will mistakenly use vmcb02. Always use vmcb01 instead of the current VMCB.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ This adds a check for encryption key size upon receiving L2CAP_LE_CONN_REQ which is required by L2CAP/LE/CFC/BV-15-C which expects L2CAP_CR_LE_BAD_KEY_SIZE.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: cx23885: Add missing unmap in snd_cx23885_hw_params() In error path, add cx23885_alsa_dma_unmap() to release the resource acquired by cx23885_alsa_dma_map().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Check maxfield in hidpp_get_report_length() Do not crash when a report has no fields. Fake USB gadgets can send their own HID report descriptors and can define report structures without valid fields. This can be used to crash the kernel over USB.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Intel: hda: Fix NULL pointer dereference If there's a mismatch between the DAI links in the machine driver and the topology, it is possible that the playback/capture widget is not set, especially in the case of loopback capture for echo reference where we use the dummy DAI link. Return the error when the widget is not set to avoid a null pointer dereference like below when the topology is broken. RIP: 0010:hda_dai_get_ops.isra.0+0x14/0xa0 [snd_sof_intel_hda_common]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: magicmouse: Do not crash on missing msc->input Fake USB devices can send their own report descriptors for which the input_mapping() hook does not get called. In this case, msc->input stays NULL, leading to a crash at a later time. Detect this condition in the input_configured() hook and reject the device. This is not supposed to happen with actual magic mouse devices, but can be provoked by imposing as a magic mouse USB device.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ntb: ntb_hw_switchtec: Fix shift-out-of-bounds for 0 mw lut Number of MW LUTs depends on NTB configuration and can be set to zero, in such scenario rounddown_pow_of_two will cause undefined behaviour and should not be performed. This patch ensures that rounddown_pow_of_two is called on valid value.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: mfd: core: Add locking around 'mfd_of_node_list' Manipulating a list in the kernel isn't safe without some sort of mutual exclusion. Add a mutex any time we access / modify 'mfd_of_node_list' to prevent possible crashes.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Revert "PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV" This reverts commit 05703271c3cd ("PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV"), which causes a deadlock by recursively taking pci_rescan_remove_lock when sriov_del_vfs() is called as part of pci_stop_and_remove_bus_device(). For example with the following sequence of commands: $ echo <NUM> > /sys/bus/pci/devices/<pf>/sriov_numvfs $ echo 1 > /sys/bus/pci/devices/<pf>/remove A trimmed trace of the deadlock on a mlx5 device is as below: zsh/5715 is trying to acquire lock: 000002597926ef50 (pci_rescan_remove_lock){+.+.}-{3:3}, at: sriov_disable+0x34/0x140 but task is already holding lock: 000002597926ef50 (pci_rescan_remove_lock){+.+.}-{3:3}, at: pci_stop_and_remove_bus_device_locked+0x24/0x80 ... Call Trace: [<00000259778c4f90>] dump_stack_lvl+0xc0/0x110 [<00000259779c844e>] print_deadlock_bug+0x31e/0x330 [<00000259779c1908>] __lock_acquire+0x16c8/0x32f0 [<00000259779bffac>] lock_acquire+0x14c/0x350 [<00000259789643a6>] __mutex_lock_common+0xe6/0x1520 [<000002597896413c>] mutex_lock_nested+0x3c/0x50 [<00000259784a07e4>] sriov_disable+0x34/0x140 [<00000258f7d6dd80>] mlx5_sriov_disable+0x50/0x80 [mlx5_core] [<00000258f7d5745e>] remove_one+0x5e/0xf0 [mlx5_core] [<00000259784857fc>] pci_device_remove+0x3c/0xa0 [<000002597851012e>] device_release_driver_internal+0x18e/0x280 [<000002597847ae22>] pci_stop_bus_device+0x82/0xa0 [<000002597847afce>] pci_stop_and_remove_bus_device_locked+0x5e/0x80 [<00000259784972c2>] remove_store+0x72/0x90 [<0000025977e6661a>] kernfs_fop_write_iter+0x15a/0x200 [<0000025977d7241c>] vfs_write+0x24c/0x300 [<0000025977d72696>] ksys_write+0x86/0x110 [<000002597895b61c>] __do_syscall+0x14c/0x400 [<000002597896e0ee>] system_call+0x6e/0x90 This alone is not a complete fix as it restores the issue the cited commit tried to solve. A new fix will be provided as a follow on.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: wan/fsl_ucc_hdlc: Fix dma_free_coherent() in uhdlc_memclean() The priv->rx_buffer and priv->tx_buffer are alloc'd together as contiguous buffers in uhdlc_init() but freed as two buffers in uhdlc_memclean(). Change the cleanup to only call dma_free_coherent() once on the whole buffer.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: hid-pl: handle probe errors Errors in init must be reported back or we'll follow a NULL pointer the first time FF is used.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: usb: pegasus: enable basic endpoint checking pegasus_probe() fills URBs with hardcoded endpoint pipes without verifying the endpoint descriptors: - usb_rcvbulkpipe(dev, 1) for RX data - usb_sndbulkpipe(dev, 2) for TX data - usb_rcvintpipe(dev, 3) for status interrupts A malformed USB device can present these endpoints with transfer types that differ from what the driver assumes. Add a pegasus_usb_ep enum for endpoint numbers, replacing magic constants throughout. Add usb_check_bulk_endpoints() and usb_check_int_endpoints() calls before any resource allocation to verify endpoint types before use, rejecting devices with mismatched descriptors at probe time, and avoid triggering assertion. Similar fix to - commit 90b7f2961798 ("net: usb: rtl8150: enable basic endpoint checking") - commit 9e7021d2aeae ("net: usb: catc: enable basic endpoint checking")


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: CGX: fix bitmap leaks The RX/TX flow-control bitmaps (rx_fc_pfvf_bmap and tx_fc_pfvf_bmap) are allocated by cgx_lmac_init() but never freed in cgx_lmac_exit(). Unbinding and rebinding the driver therefore triggers kmemleak: unreferenced object (size 16): backtrace: rvu_alloc_bitmap cgx_probe Free both bitmaps during teardown.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix null dereference in find_network The variable pwlan has the possibility of being NULL when passed into rtw_free_network_nolock() which would later dereference the variable.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: tegra-video: Fix memory leak in __tegra_channel_try_format() The state object allocated by __v4l2_subdev_state_alloc() must be freed with __v4l2_subdev_state_free() when it is no longer needed. In __tegra_channel_try_format(), two error paths return directly after v4l2_subdev_call() fails, without freeing the allocated 'sd_state' object. This violates the requirement and causes a memory leak. Fix this by introducing a cleanup label and using goto statements in the error paths to ensure that __v4l2_subdev_state_free() is always called before the function returns.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfrm: always flush state and policy upon NETDEV_UNREGISTER event syzbot is reporting that "struct xfrm_state" refcount is leaking. unregister_netdevice: waiting for netdevsim0 to become free. Usage count = 2 ref_tracker: netdev@ffff888052f24618 has 1/1 users at __netdev_tracker_alloc include/linux/netdevice.h:4400 [inline] netdev_tracker_alloc include/linux/netdevice.h:4412 [inline] xfrm_dev_state_add+0x3a5/0x1080 net/xfrm/xfrm_device.c:316 xfrm_state_construct net/xfrm/xfrm_user.c:986 [inline] xfrm_add_sa+0x34ff/0x5fa0 net/xfrm/xfrm_user.c:1022 xfrm_user_rcv_msg+0x58e/0xc00 net/xfrm/xfrm_user.c:3507 netlink_rcv_skb+0x158/0x420 net/netlink/af_netlink.c:2550 xfrm_netlink_rcv+0x71/0x90 net/xfrm/xfrm_user.c:3529 netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline] netlink_unicast+0x5aa/0x870 net/netlink/af_netlink.c:1344 netlink_sendmsg+0x8c8/0xdd0 net/netlink/af_netlink.c:1894 sock_sendmsg_nosec net/socket.c:727 [inline] __sock_sendmsg net/socket.c:742 [inline] ____sys_sendmsg+0xa5d/0xc30 net/socket.c:2592 ___sys_sendmsg+0x134/0x1d0 net/socket.c:2646 __sys_sendmsg+0x16d/0x220 net/socket.c:2678 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xcd/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f This is because commit d77e38e612a0 ("xfrm: Add an IPsec hardware offloading API") implemented xfrm_dev_unregister() as no-op despite xfrm_dev_state_add() from xfrm_state_construct() acquires a reference to "struct net_device". I guess that that commit expected that NETDEV_DOWN event is fired before NETDEV_UNREGISTER event fires, and also assumed that xfrm_dev_state_add() is called only if (dev->features & NETIF_F_HW_ESP) != 0. Sabrina Dubroca identified steps to reproduce the same symptoms as below. echo 0 > /sys/bus/netdevsim/new_device dev=$(ls -1 /sys/bus/netdevsim/devices/netdevsim0/net/) ip xfrm state add src 192.168.13.1 dst 192.168.13.2 proto esp \ spi 0x1000 mode tunnel aead 'rfc4106(gcm(aes))' $key 128 \ offload crypto dev $dev dir out ethtool -K $dev esp-hw-offload off echo 0 > /sys/bus/netdevsim/del_device Like these steps indicate, the NETIF_F_HW_ESP bit can be cleared after xfrm_dev_state_add() acquired a reference to "struct net_device". Also, xfrm_dev_state_add() does not check for the NETIF_F_HW_ESP bit when acquiring a reference to "struct net_device". Commit 03891f820c21 ("xfrm: handle NETDEV_UNREGISTER for xfrm device") re-introduced the NETDEV_UNREGISTER event to xfrm_dev_event(), but that commit for unknown reason chose to share xfrm_dev_down() between the NETDEV_DOWN event and the NETDEV_UNREGISTER event. I guess that that commit missed the behavior in the previous paragraph. Therefore, we need to re-introduce xfrm_dev_unregister() in order to release the reference to "struct net_device" by unconditionally flushing state and policy.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/buddy: Prevent BUG_ON by validating rounded allocation When DRM_BUDDY_CONTIGUOUS_ALLOCATION is set, the requested size is rounded up to the next power-of-two via roundup_pow_of_two(). Similarly, for non-contiguous allocations with large min_block_size, the size is aligned up via round_up(). Both operations can produce a rounded size that exceeds mm->size, which later triggers BUG_ON(order > mm->max_order). Example scenarios: - 9G CONTIGUOUS allocation on 10G VRAM memory: roundup_pow_of_two(9G) = 16G > 10G - 9G allocation with 8G min_block_size on 10G VRAM memory: round_up(9G, 8G) = 16G > 10G Fix this by checking the rounded size against mm->size. For non-contiguous or range allocations where size > mm->size is invalid, return -EINVAL immediately. For contiguous allocations without range restrictions, allow the request to fall through to the existing __alloc_contig_try_harder() fallback. This ensures invalid user input returns an error or uses the fallback path instead of hitting BUG_ON. v2: (Matt A) - Add Fixes, Cc stable, and Closes tags for context


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: ipu6: Fix RPM reference leak in probe error paths Several error paths in ipu6_pci_probe() were jumping directly to out_ipu6_bus_del_devices without releasing the runtime PM reference. Add pm_runtime_put_sync() before cleaning up other resources.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: usb: kaweth: remove TX queue manipulation in kaweth_set_rx_mode kaweth_set_rx_mode(), the ndo_set_rx_mode callback, calls netif_stop_queue() and netif_wake_queue(). These are TX queue flow control functions unrelated to RX multicast configuration. The premature netif_wake_queue() can re-enable TX while tx_urb is still in-flight, leading to a double usb_submit_urb() on the same URB: kaweth_start_xmit() { netif_stop_queue(); usb_submit_urb(kaweth->tx_urb); } kaweth_set_rx_mode() { netif_stop_queue(); netif_wake_queue(); // wakes TX queue before URB is done } kaweth_start_xmit() { netif_stop_queue(); usb_submit_urb(kaweth->tx_urb); // URB submitted while active } This triggers the WARN in usb_submit_urb(): "URB submitted while active" This is a similar class of bug fixed in rtl8150 by - commit 958baf5eaee3 ("net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast"). Also kaweth_set_rx_mode() is already functionally broken, the real set_rx_mode action is performed by kaweth_async_set_rx_mode(), which in turn is not a no-op only at ndo_open() time.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: ccs: Avoid possible division by zero Calculating maximum M for scaler configuration involves dividing by MIN_X_OUTPUT_SIZE limit register's value. Albeit the value is presumably non-zero, the driver was missing the check it in fact was. Fix this.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: cx25821: Fix a resource leak in cx25821_dev_setup() Add release_mem_region() if ioremap() fails to release the memory region obtained by cx25821_get_resources().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-async: Fix error handling on steps after finding a match Once an async connection is found to be matching with an fwnode, a sub-device may be registered (in case it wasn't already), its bound operation is called, ancillary links are created, the async connection is added to the sub-device's list of connections and removed from the global waiting connection list. Further on, the sub-device's possible own notifier is searched for possible additional matches. Fix these specific issues: - If v4l2_async_match_notify() failed before the sub-notifier handling, the async connection was unbound and its entry removed from the sub-device's async connection list. The latter part was also done in v4l2_async_match_notify(). - The async connection's sd field was only set after creating ancillary links in v4l2_async_match_notify(). It was however dereferenced in v4l2_async_unbind_subdev_one(), which was called on error path of v4l2_async_match_notify() failure.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35 [Why] A backport of the change made for DCN401 that addresses an issue where we turn off the PHY PLL when disabling TMDS output, which causes the OTG to remain stuck. The OTG being stuck can lead to a hang in the DCHVM's ability to ACK invalidations when it thinks the HUBP is still on but it's not receiving global sync. The transition to PLL_ON needs to be atomic as there's no guarantee that the thread isn't pre-empted or is able to complete before the IOMMU watchdog times out. [How] Backport the implementation from dcn401 back to dcn35. There's a functional difference in when the eDP output is disabled in dcn401 code so we don't want to utilize it directly.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: consume xmit errors of GSO frames udpgro_frglist.sh and udpgro_bench.sh are the flakiest tests currently in NIPA. They fail in the same exact way, TCP GRO test stalls occasionally and the test gets killed after 10min. These tests use veth to simulate GRO. They attach a trivial ("return XDP_PASS;") XDP program to the veth to force TSO off and NAPI on. Digging into the failure mode we can see that the connection is completely stuck after a burst of drops. The sender's snd_nxt is at sequence number N [1], but the receiver claims to have received (rcv_nxt) up to N + 3 * MSS [2]. Last piece of the puzzle is that senders rtx queue is not empty (let's say the block in the rtx queue is at sequence number N - 4 * MSS [3]). In this state, sender sends a retransmission from the rtx queue with a single segment, and sequence numbers N-4*MSS:N-3*MSS [3]. Receiver sees it and responds with an ACK all the way up to N + 3 * MSS [2]. But sender will reject this ack as TCP_ACK_UNSENT_DATA because it has no recollection of ever sending data that far out [1]. And we are stuck. The root cause is the mess of the xmit return codes. veth returns an error when it can't xmit a frame. We end up with a loss event like this: ------------------------------------------------- | GSO super frame 1 | GSO super frame 2 | |-----------------------------------------------| | seg | seg | seg | seg | seg | seg | seg | seg | | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | ------------------------------------------------- x ok ok <ok>| ok ok ok <x> \\ snd_nxt "x" means packet lost by veth, and "ok" means it went thru. Since veth has TSO disabled in this test it sees individual segments. Segment 1 is on the retransmit queue and will be resent. So why did the sender not advance snd_nxt even tho it clearly did send up to seg 8? tcp_write_xmit() interprets the return code from the core to mean that data has not been sent at all. Since TCP deals with GSO super frames, not individual segment the crux of the problem is that loss of a single segment can be interpreted as loss of all. TCP only sees the last return code for the last segment of the GSO frame (in <> brackets in the diagram above). Of course for the problem to occur we need a setup or a device without a Qdisc. Otherwise Qdisc layer disconnects the protocol layer from the device errors completely. We have multiple ways to fix this. 1) make veth not return an error when it lost a packet. While this is what I think we did in the past, the issue keeps reappearing and it's annoying to debug. The game of whack a mole is not great. 2) fix the damn return codes We only talk about NETDEV_TX_OK and NETDEV_TX_BUSY in the documentation, so maybe we should make the return code from ndo_start_xmit() a boolean. I like that the most, but perhaps some ancient, not-really-networking protocol would suffer. 3) make TCP ignore the errors It is not entirely clear to me what benefit TCP gets from interpreting the result of ip_queue_xmit()? Specifically once the connection is established and we're pushing data - packet loss is just packet loss? 4) this fix Ignore the rc in the Qdisc-less+GSO case, since it's unreliable. We already always return OK in the TCQ_F_CAN_BYPASS case. In the Qdisc-less case let's be a bit more conservative and only mask the GSO errors. This path is taken by non-IP-"networks" like CAN, MCTP etc, so we could regress some ancient thing. This is the simplest, but also maybe the hackiest fix? Similar fix has been proposed by Eric in the past but never committed because original reporter was working with an OOT driver and wasn't providing feedback (see Link).


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: soc: ti: pruss: Fix double free in pruss_clk_mux_setup() In the pruss_clk_mux_setup(), the devm_add_action_or_reset() indirectly calls pruss_of_free_clk_provider(), which calls of_node_put(clk_mux_np) on the error path. However, after the devm_add_action_or_reset() returns, the of_node_put(clk_mux_np) is called again, causing a double free. Fix by returning directly, to avoid the duplicate of_node_put().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query Fix a "scheduling while atomic" bug in mlx5e_ipsec_init_macs() by replacing mlx5_query_mac_address() with ether_addr_copy() to get the local MAC address directly from netdev->dev_addr. The issue occurs because mlx5_query_mac_address() queries the hardware which involves mlx5_cmd_exec() that can sleep, but it is called from the mlx5e_ipsec_handle_event workqueue which runs in atomic context. The MAC address is already available in netdev->dev_addr, so no need to query hardware. This avoids the sleeping call and resolves the bug. Call trace: BUG: scheduling while atomic: kworker/u112:2/69344/0x00000200 __schedule+0x7ab/0xa20 schedule+0x1c/0xb0 schedule_timeout+0x6e/0xf0 __wait_for_common+0x91/0x1b0 cmd_exec+0xa85/0xff0 [mlx5_core] mlx5_cmd_exec+0x1f/0x50 [mlx5_core] mlx5_query_nic_vport_mac_address+0x7b/0xd0 [mlx5_core] mlx5_query_mac_address+0x19/0x30 [mlx5_core] mlx5e_ipsec_init_macs+0xc1/0x720 [mlx5_core] mlx5e_ipsec_build_accel_xfrm_attrs+0x422/0x670 [mlx5_core] mlx5e_ipsec_handle_event+0x2b9/0x460 [mlx5_core] process_one_work+0x178/0x2e0 worker_thread+0x2ea/0x430


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Fix swapped parameters in pci_{primary/secondary}_epc_epf_unlink() functions struct configfs_item_operations callbacks are defined like the following: int (*allow_link)(struct config_item *src, struct config_item *target); void (*drop_link)(struct config_item *src, struct config_item *target); While pci_primary_epc_epf_link() and pci_secondary_epc_epf_link() specify the parameters in the correct order, pci_primary_epc_epf_unlink() and pci_secondary_epc_epf_unlink() specify the parameters in the wrong order, leading to the below kernel crash when using the unlink command in configfs: Unable to handle kernel paging request at virtual address 0000000300000857 Mem abort info: ... pc : string+0x54/0x14c lr : vsnprintf+0x280/0x6e8 ... string+0x54/0x14c vsnprintf+0x280/0x6e8 vprintk_default+0x38/0x4c vprintk+0xc4/0xe0 pci_epf_unbind+0xdc/0x108 configfs_unlink+0xe0/0x208+0x44/0x74 vfs_unlink+0x120/0x29c __arm64_sys_unlinkat+0x3c/0x90 invoke_syscall+0x48/0x134 do_el0_svc+0x1c/0x30prop.0+0xd0/0xf0 [mani: cced stable, changed commit message as per https://lore.kernel.org/linux-pci/aV9joi3jF1R6ca02@ryzen]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fbdev: vt8500lcdfb: fix missing dma_free_coherent() fbi->fb.screen_buffer is allocated with dma_alloc_coherent() but is not freed if the error path is reached.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: atm: fore200e: fix use-after-free in tasklets during device removal When the PCA-200E or SBA-200E adapter is being detached, the fore200e is deallocated. However, the tx_tasklet or rx_tasklet may still be running or pending, leading to use-after-free bug when the already freed fore200e is accessed again in fore200e_tx_tasklet() or fore200e_rx_tasklet(). One of the race conditions can occur as follows: CPU 0 (cleanup) | CPU 1 (tasklet) fore200e_pca_remove_one() | fore200e_interrupt() fore200e_shutdown() | tasklet_schedule() kfree(fore200e) | fore200e_tx_tasklet() | fore200e-> // UAF Fix this by ensuring tx_tasklet or rx_tasklet is properly canceled before the fore200e is released. Add tasklet_kill() in fore200e_shutdown() to synchronize with any pending or running tasklets. Moreover, since fore200e_reset() could prevent further interrupts or data transfers, the tasklet_kill() should be placed after fore200e_reset() to prevent the tasklet from being rescheduled in fore200e_interrupt(). Finally, it only needs to do tasklet_kill() when the fore200e state is greater than or equal to FORE200E_STATE_IRQ, since tasklets are uninitialized in earlier states. In a word, the tasklet_kill() should be placed in the FORE200E_STATE_IRQ branch within the switch...case structure. This bug was identified through static analysis.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: q6asm: drop DSP responses for closed data streams 'Commit a354f030dbce ("ASoC: qcom: q6asm: handle the responses after closing")' attempted to ignore DSP responses arriving after a stream had been closed. However, those responses were still handled, causing lockups. Fix this by unconditionally dropping all DSP responses associated with closed data streams.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: validate num_ifs to prevent out-of-bounds write The driver obtains sw_attr.num_ifs from firmware via dpsw_get_attributes() but never validates it against DPSW_MAX_IF (64). This value controls iteration in dpaa2_switch_fdb_get_flood_cfg(), which writes port indices into the fixed-size cfg->if_id[DPSW_MAX_IF] array. When firmware reports num_ifs >= 64, the loop can write past the array bounds. Add a bound check for num_ifs in dpaa2_switch_init(). dpaa2_switch_fdb_get_flood_cfg() appends the control interface (port num_ifs) after all matched ports. When num_ifs == DPSW_MAX_IF and all ports match the flood filter, the loop fills all 64 slots and the control interface write overflows by one entry. The check uses >= because num_ifs == DPSW_MAX_IF is also functionally broken. build_if_id_bitmap() silently drops any ID >= 64: if (id[i] < DPSW_MAX_IF) bmap[id[i] / 64] |= ...


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: mtk-mdp: Fix error handling in probe function Add mtk_mdp_unregister_m2m_device() on the error handling path to prevent resource leak. Add check for the return value of vpu_get_plat_device() to prevent null pointer dereference. And vpu_get_plat_device() increases the reference count of the returned platform device. Add platform_device_put() to prevent reference leak.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: PCI: Fix pci_slot_trylock() error handling Commit a4e772898f8b ("PCI: Add missing bridge lock to pci_bus_lock()") delegates the bridge device's pci_dev_trylock() to pci_bus_trylock() in pci_slot_trylock(), but it forgets to remove the corresponding pci_dev_unlock() when pci_bus_trylock() fails. Before a4e772898f8b, the code did: if (!pci_dev_trylock(dev)) /* <- lock bridge device */ goto unlock; if (dev->subordinate) { if (!pci_bus_trylock(dev->subordinate)) { pci_dev_unlock(dev); /* <- unlock bridge device */ goto unlock; } } After a4e772898f8b the bridge-device lock is no longer taken, but the pci_dev_unlock(dev) on the failure path was left in place, leading to the bug. This yields one of two errors: 1. A warning that the lock is being unlocked when no one holds it. 2. An incorrect unlock of a lock that belongs to another thread. Fix it by removing the now-redundant pci_dev_unlock(dev) on the failure path. [Same patch later posted by Keith at https://patch.msgid.link/20260116184150.3013258-1-kbusch@meta.com]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix locking usage for tcon fields We used to use the cifs_tcp_ses_lock to protect a lot of objects that are not just the server, ses or tcon lists. We later introduced srv_lock, ses_lock and tc_lock to protect fields within the corresponding structs. This was done to provide a more granular protection and avoid unnecessary serialization. There were still a couple of uses of cifs_tcp_ses_lock to provide tcon fields. In this patch, I've replaced them with tc_lock.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: i2c/tw9903: Fix potential memory leak in tw9903_probe() In one of the error paths in tw9903_probe(), the memory allocated in v4l2_ctrl_handler_init() and v4l2_ctrl_new_std() is not freed. Fix that by calling v4l2_ctrl_handler_free() on the handler in that error path.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: serialize sequence allocation under concurrent TLB invalidations With concurrent TLB invalidations, completion wait randomly gets timed out because cmd_sem_val was incremented outside the IOMMU spinlock, allowing CMD_COMPL_WAIT commands to be queued out of sequence and breaking the ordering assumption in wait_on_sem(). Move the cmd_sem_val increment under iommu->lock so completion sequence allocation is serialized with command queuing. And remove the unnecessary return.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: initialise event handler read bytes IPMB doesn't use i2c reads, but the handler needs to set a value. Otherwise an i2c read will return an uninitialised value from the bus driver.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: verisilicon: AV1: Fix tile info buffer size Each tile info is composed of: row_sb, col_sb, start_pos and end_pos (4 bytes each). So the total required memory is AV1_MAX_TILES * 16 bytes. Use the correct #define to allocate the buffer and avoid writing tile info in non-allocated memory.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: pvrusb2: fix URB leak in pvr2_send_request_ex When pvr2_send_request_ex() submits a write URB successfully but fails to submit the read URB (e.g. returns -ENOMEM), it returns immediately without waiting for the write URB to complete. Since the driver reuses the same URB structure, a subsequent call to pvr2_send_request_ex() attempts to submit the still-active write URB, triggering a 'URB submitted while active' warning in usb_submit_urb(). Fix this by ensuring the write URB is unlinked and waited upon if the read URB submission fails.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix memory leak on failure path cfg80211_inform_bss_frame() may return NULL on failure. In that case, the allocated buffer 'buf' is not freed and the function returns early, leading to potential memory leak. Fix this by ensuring that 'buf' is freed on both success and failure paths.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/rds: No shortcut out of RDS_CONN_ERROR RDS connections carry a state "rds_conn_path::cp_state" and transitions from one state to another and are conditional upon an expected state: "rds_conn_path_transition." There is one exception to this conditionality, which is "RDS_CONN_ERROR" that can be enforced by "rds_conn_path_drop" regardless of what state the condition is currently in. But as soon as a connection enters state "RDS_CONN_ERROR", the connection handling code expects it to go through the shutdown-path. The RDS/TCP multipath changes added a shortcut out of "RDS_CONN_ERROR" straight back to "RDS_CONN_CONNECTING" via "rds_tcp_accept_one_path" (e.g. after "rds_tcp_state_change"). A subsequent "rds_tcp_reset_callbacks" can then transition the state to "RDS_CONN_RESETTING" with a shutdown-worker queued. That'll trip up "rds_conn_init_shutdown", which was never adjusted to handle "RDS_CONN_RESETTING" and subsequently drops the connection with the dreaded "DR_INV_CONN_STATE", which leaves "RDS_SHUTDOWN_WORK_QUEUED" on forever. So we do two things here: a) Don't shortcut "RDS_CONN_ERROR", but take the longer path through the shutdown code. b) Add "RDS_CONN_RESETTING" to the expected states in "rds_conn_init_shutdown" so that we won't error out and get stuck, if we ever hit weird state transitions like this again."


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: radio-keene: fix memory leak in error path Fix a memory leak in usb_keene_probe(). The v4l2 control handler is initialized and controls are added, but if v4l2_device_register() or video_register_device() fails afterward, the handler was never freed, leaking memory. Add v4l2_ctrl_handler_free() call in the err_v4l2 error path to ensure the control handler is properly freed for all error paths after it is initialized.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets When the FarSync T-series card is being detached, the fst_card_info is deallocated in fst_remove_one(). However, the fst_tx_task or fst_int_task may still be running or pending, leading to use-after-free bugs when the already freed fst_card_info is accessed in fst_process_tx_work_q() or fst_process_int_work_q(). A typical race condition is depicted below: CPU 0 (cleanup) | CPU 1 (tasklet) | fst_start_xmit() fst_remove_one() | tasklet_schedule() unregister_hdlc_device()| | fst_process_tx_work_q() //handler kfree(card) //free | do_bottom_half_tx() | card-> //use The following KASAN trace was captured: ================================================================== BUG: KASAN: slab-use-after-free in do_bottom_half_tx+0xb88/0xd00 Read of size 4 at addr ffff88800aad101c by task ksoftirqd/3/32 ... Call Trace: <IRQ> dump_stack_lvl+0x55/0x70 print_report+0xcb/0x5d0 ? do_bottom_half_tx+0xb88/0xd00 kasan_report+0xb8/0xf0 ? do_bottom_half_tx+0xb88/0xd00 do_bottom_half_tx+0xb88/0xd00 ? _raw_spin_lock_irqsave+0x85/0xe0 ? __pfx__raw_spin_lock_irqsave+0x10/0x10 ? __pfx___hrtimer_run_queues+0x10/0x10 fst_process_tx_work_q+0x67/0x90 tasklet_action_common+0x1fa/0x720 ? hrtimer_interrupt+0x31f/0x780 handle_softirqs+0x176/0x530 __irq_exit_rcu+0xab/0xe0 sysvec_apic_timer_interrupt+0x70/0x80 ... Allocated by task 41 on cpu 3 at 72.330843s: kasan_save_stack+0x24/0x50 kasan_save_track+0x17/0x60 __kasan_kmalloc+0x7f/0x90 fst_add_one+0x1a5/0x1cd0 local_pci_probe+0xdd/0x190 pci_device_probe+0x341/0x480 really_probe+0x1c6/0x6a0 __driver_probe_device+0x248/0x310 driver_probe_device+0x48/0x210 __device_attach_driver+0x160/0x320 bus_for_each_drv+0x101/0x190 __device_attach+0x198/0x3a0 device_initial_probe+0x78/0xa0 pci_bus_add_device+0x81/0xc0 pci_bus_add_devices+0x7e/0x190 enable_slot+0x9b9/0x1130 acpiphp_check_bridge.part.0+0x2e1/0x460 acpiphp_hotplug_notify+0x36c/0x3c0 acpi_device_hotplug+0x203/0xb10 acpi_hotplug_work_fn+0x59/0x80 ... Freed by task 41 on cpu 1 at 75.138639s: kasan_save_stack+0x24/0x50 kasan_save_track+0x17/0x60 kasan_save_free_info+0x3b/0x60 __kasan_slab_free+0x43/0x70 kfree+0x135/0x410 fst_remove_one+0x2ca/0x540 pci_device_remove+0xa6/0x1d0 device_release_driver_internal+0x364/0x530 pci_stop_bus_device+0x105/0x150 pci_stop_and_remove_bus_device+0xd/0x20 disable_slot+0x116/0x260 acpiphp_disable_and_eject_slot+0x4b/0x190 acpiphp_hotplug_notify+0x230/0x3c0 acpi_device_hotplug+0x203/0xb10 acpi_hotplug_work_fn+0x59/0x80 ... The buggy address belongs to the object at ffff88800aad1000 which belongs to the cache kmalloc-1k of size 1024 The buggy address is located 28 bytes inside of freed 1024-byte region The buggy address belongs to the physical page: page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0xaad0 head: order:3 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 flags: 0x100000000000040(head|node=0|zone=1) page_type: f5(slab) raw: 0100000000000040 ffff888007042dc0 dead000000000122 0000000000000000 raw: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000 head: 0100000000000040 ffff888007042dc0 dead000000000122 0000000000000000 head: 0000000000000000 0000000080100010 00000000f5000000 0000000000000000 head: 0100000000000003 ffffea00002ab401 00000000ffffffff 00000000ffffffff head: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000 page dumped because: kasan: bad access detected Memory state around the buggy address: ffff88800aad0f00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc ffff88800aad0f80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc >ffff88800aad1000: fa fb ---truncated---


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release The atmel_hlcdc_plane_atomic_duplicate_state() callback was copying the atmel_hlcdc_plane state structure without properly duplicating the drm_plane_state. In particular, state->commit remained set to the old state commit, which can lead to a use-after-free in the next drm_atomic_commit() call. Fix this by calling __drm_atomic_helper_duplicate_plane_state(), which correctly clones the base drm_plane_state (including the ->commit pointer). It has been seen when closing and re-opening the device node while another DRM client (e.g. fbdev) is still attached: ============================================================================= BUG kmalloc-64 (Not tainted): Poison overwritten ----------------------------------------------------------------------------- 0xc611b344-0xc611b344 @offset=836. First byte 0x6a instead of 0x6b FIX kmalloc-64: Restoring Poison 0xc611b344-0xc611b344=0x6b Allocated in drm_atomic_helper_setup_commit+0x1e8/0x7bc age=178 cpu=0 pid=29 drm_atomic_helper_setup_commit+0x1e8/0x7bc drm_atomic_helper_commit+0x3c/0x15c drm_atomic_commit+0xc0/0xf4 drm_framebuffer_remove+0x4cc/0x5a8 drm_mode_rmfb_work_fn+0x6c/0x80 process_one_work+0x12c/0x2cc worker_thread+0x2a8/0x400 kthread+0xc0/0xdc ret_from_fork+0x14/0x28 Freed in drm_atomic_helper_commit_hw_done+0x100/0x150 age=8 cpu=0 pid=169 drm_atomic_helper_commit_hw_done+0x100/0x150 drm_atomic_helper_commit_tail+0x64/0x8c commit_tail+0x168/0x18c drm_atomic_helper_commit+0x138/0x15c drm_atomic_commit+0xc0/0xf4 drm_atomic_helper_set_config+0x84/0xb8 drm_mode_setcrtc+0x32c/0x810 drm_ioctl+0x20c/0x488 sys_ioctl+0x14c/0xc20 ret_fast_syscall+0x0/0x54 Slab 0xef8bc360 objects=21 used=16 fp=0xc611b7c0 flags=0x200(workingset|zone=0) Object 0xc611b340 @offset=832 fp=0xc611b7c0


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: x86/kexec: add a sanity check on previous kernel's ima kexec buffer When the second-stage kernel is booted via kexec with a limiting command line such as "mem=<size>", the physical range that contains the carried over IMA measurement list may fall outside the truncated RAM leading to a kernel panic. BUG: unable to handle page fault for address: ffff97793ff47000 RIP: ima_restore_measurement_list+0xdc/0x45a #PF: error_code(0x0000) - not-present page Other architectures already validate the range with page_is_ram(), as done in commit cbf9c4b9617b ("of: check previous kernel's ima-kexec-buffer against memory bounds") do a similar check on x86. Without carrying the measurement list across kexec, the attestation would fail.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ntb: ntb_hw_switchtec: Fix array-index-out-of-bounds access Number of MW LUTs depends on NTB configuration and can be set to MAX_MWS, This patch protects against invalid index out of bounds access to mw_sizes When invalid access print message to user that configuration is not valid.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: soc: ti: k3-socinfo: Fix regmap leak on probe failure The mmio regmap allocated during probe is never freed. Switch to using the device managed allocator so that the regmap is released on probe failures (e.g. probe deferral) and on driver unbind.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add signal type check for dcn401 get_phyd32clk_src Trying to access link enc on a dpia link will cause a crash otherwise


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: kcm: fix zero-frag skb in frag_list on partial sendmsg error Syzkaller reported a warning in kcm_write_msgs() when processing a message with a zero-fragment skb in the frag_list. When kcm_sendmsg() fills MAX_SKB_FRAGS fragments in the current skb, it allocates a new skb (tskb) and links it into the frag_list before copying data. If the copy subsequently fails (e.g. -EFAULT from user memory), tskb remains in the frag_list with zero fragments: head skb (msg being assembled, NOT yet in sk_write_queue) +-----------+ | frags[17] | (MAX_SKB_FRAGS, all filled with data) | frag_list-+--> tskb +-----------+ +----------+ | frags[0] | (empty! copy failed before filling) +----------+ For SOCK_SEQPACKET with partial data already copied, the error path saves this message via partial_message for later completion. For SOCK_SEQPACKET, sock_write_iter() automatically sets MSG_EOR, so a subsequent zero-length write(fd, NULL, 0) completes the message and queues it to sk_write_queue. kcm_write_msgs() then walks the frag_list and hits: WARN_ON(!skb_shinfo(skb)->nr_frags) TCP has a similar pattern where skbs are enqueued before data copy and cleaned up on failure via tcp_remove_empty_skb(). KCM was missing the equivalent cleanup. Fix this by tracking the predecessor skb (frag_prev) when allocating a new frag_list entry. On error, if the tail skb has zero frags, use frag_prev to unlink and free it in O(1) without walking the singly-linked frag_list. frag_prev is safe to dereference because the entire message chain is only held locally (or in kcm->seq_skb) and is not added to sk_write_queue until MSG_EOR, so the send path cannot free it underneath us. Also change the WARN_ON to WARN_ON_ONCE to avoid flooding the log if the condition is somehow hit repeatedly. There are currently no KCM selftests in the kernel tree; a simple reproducer is available at [1]. [1] https://gist.github.com/mrpre/a94d431c757e8d6f168f4dd1a3749daa


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: i2c/tw9906: Fix potential memory leak in tw9906_probe() In one of the error paths in tw9906_probe(), the memory allocated in v4l2_ctrl_handler_init() and v4l2_ctrl_new_std() is not freed. Fix that by calling v4l2_ctrl_handler_free() on the handler in that error path.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: vhost: move vdpa group bound check to vhost_vdpa Remove duplication by consolidating these here. This reduces the posibility of a parent driver missing them. While we're at it, fix a bug in vdpa_sim where a valid ASID can be assigned to a group equal to ngroups, causing an out of bound write.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: prodikeys: Check presence of pm->input_ep82 Fake USB devices can send their own report descriptors for which the input_mapping() hook does not get called. In this case, pm->input_ep82 stays NULL, which leads to a crash later. This does not happen with the real device, but can be provoked by imposing as one.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: move wait_on_sem() out of spinlock With iommu.strict=1, the existing completion wait path can cause soft lockups under stressed environment, as wait_on_sem() busy-waits under the spinlock with interrupts disabled. Move the completion wait in iommu_completion_wait() out of the spinlock. wait_on_sem() only polls the hardware-updated cmd_sem and does not require iommu->lock, so holding the lock during the busy wait unnecessarily increases contention and extends the time with interrupts disabled.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: fix WARNING in usb_tx_block The function usb_tx_block() submits cardp->tx_urb without ensuring that any previous transmission on this URB has completed. If a second call occurs while the URB is still active (e.g. during rapid firmware loading), usb_submit_urb() detects the active state and triggers a warning: 'URB submitted while active'. Fix this by enforcing serialization: call usb_kill_urb() before submitting the new request. This ensures the URB is idle and safe to reuse.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: qcom: camss: vfe: Fix out-of-bounds access in vfe_isr_reg_update() vfe_isr() iterates using MSM_VFE_IMAGE_MASTERS_NUM(7) as the loop bound and passes the index to vfe_isr_reg_update(). However, vfe->line[] array is defined with VFE_LINE_NUM_MAX(4): struct vfe_line line[VFE_LINE_NUM_MAX]; When index is 4, 5, 6, the access to vfe->line[line_id] exceeds the array bounds and resulting in out-of-bounds memory access. Fix this by using separate loops for output lines and write masters.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: cx88: Add missing unmap in snd_cx88_hw_params() In error path, add cx88_alsa_dma_unmap() to release resource acquired by cx88_alsa_dma_map().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix RSS context delete logic We need to free the corresponding RSS context VNIC in FW everytime an RSS context is deleted in driver. Commit 667ac333dbb7 added a check to delete the VNIC in FW only when netif_running() is true to help delete RSS contexts with interface down. Having that condition will make the driver leak VNICs in FW whenever close() happens with active RSS contexts. On the subsequent open(), as part of RSS context restoration, we will end up trying to create extra VNICs for which we did not make any reservation. FW can fail this request, thereby making us lose active RSS contexts. Suppose an RSS context is deleted already and we try to process a delete request again, then the HWRM functions will check for validity of the request and they simply return if the resource is already freed. So, even for delete-when-down cases, netif_running() check is not necessary. Remove the netif_running() condition check when deleting an RSS context.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fbdev: of: display_timing: fix refcount leak in of_get_display_timings() of_parse_phandle() returns a device_node with refcount incremented, which is stored in 'entry' and then copied to 'native_mode'. When the error paths at lines 184 or 192 jump to 'entryfail', native_mode's refcount is not decremented, causing a refcount leak. Fix this by changing the goto target from 'entryfail' to 'timingfail', which properly calls of_node_put(native_mode) before cleanup.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/atmel-hlcdc: fix memory leak from the atomic_destroy_state callback After several commits, the slab memory increases. Some drm_crtc_commit objects are not freed. The atomic_destroy_state callback only put the framebuffer. Use the __drm_atomic_helper_plane_destroy_state() function to put all the objects that are no longer needed. It has been seen after hours of usage of a graphics application or using kmemleak: unreferenced object 0xc63a6580 (size 64): comm "egt_basic", pid 171, jiffies 4294940784 hex dump (first 32 bytes): 40 50 34 c5 01 00 00 00 ff ff ff ff 8c 65 3a c6 @P4..........e:. 8c 65 3a c6 ff ff ff ff 98 65 3a c6 98 65 3a c6 .e:......e:..e:. backtrace (crc c25aa925): kmemleak_alloc+0x34/0x3c __kmalloc_cache_noprof+0x150/0x1a4 drm_atomic_helper_setup_commit+0x1e8/0x7bc drm_atomic_helper_commit+0x3c/0x15c drm_atomic_commit+0xc0/0xf4 drm_atomic_helper_set_config+0x84/0xb8 drm_mode_setcrtc+0x32c/0x810 drm_ioctl+0x20c/0x488 sys_ioctl+0x14c/0xc20 ret_fast_syscall+0x0/0x54


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: mtk-mdp: Fix a reference leak bug in mtk_mdp_remove() In mtk_mdp_probe(), vpu_get_plat_device() increases the reference count of the returned platform device. Add platform_device_put() to prevent reference leak.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: APEI/GHES: ensure that won't go past CPER allocated record The logic at ghes_new() prevents allocating too large records, by checking if they're bigger than GHES_ESTATUS_MAX_SIZE (currently, 64KB). Yet, the allocation is done with the actual number of pages from the CPER bios table location, which can be smaller. Yet, a bad firmware could send data with a different size, which might be bigger than the allocated memory, causing an OOPS: Unable to handle kernel paging request at virtual address fff00000f9b40000 Mem abort info: ESR = 0x0000000096000007 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x07: level 3 translation fault Data abort info: ISV = 0, ISS = 0x00000007, ISS2 = 0x00000000 CM = 0, WnR = 0, TnD = 0, TagAccess = 0 GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 swapper pgtable: 4k pages, 52-bit VAs, pgdp=000000008ba16000 [fff00000f9b40000] pgd=180000013ffff403, p4d=180000013fffe403, pud=180000013f85b403, pmd=180000013f68d403, pte=0000000000000000 Internal error: Oops: 0000000096000007 [#1] SMP Modules linked in: CPU: 0 UID: 0 PID: 303 Comm: kworker/0:1 Not tainted 6.19.0-rc1-00002-gda407d200220 #34 PREEMPT Hardware name: QEMU QEMU Virtual Machine, BIOS unknown 02/02/2022 Workqueue: kacpi_notify acpi_os_execute_deferred pstate: 214020c5 (nzCv daIF +PAN -UAO -TCO +DIT -SSBS BTYPE=--) pc : hex_dump_to_buffer+0x30c/0x4a0 lr : hex_dump_to_buffer+0x328/0x4a0 sp : ffff800080e13880 x29: ffff800080e13880 x28: ffffac9aba86f6a8 x27: 0000000000000083 x26: fff00000f9b3fffc x25: 0000000000000004 x24: 0000000000000004 x23: ffff800080e13905 x22: 0000000000000010 x21: 0000000000000083 x20: 0000000000000001 x19: 0000000000000008 x18: 0000000000000010 x17: 0000000000000001 x16: 00000007c7f20fec x15: 0000000000000020 x14: 0000000000000008 x13: 0000000000081020 x12: 0000000000000008 x11: ffff800080e13905 x10: ffff800080e13988 x9 : 0000000000000000 x8 : 0000000000000000 x7 : 0000000000000001 x6 : 0000000000000020 x5 : 0000000000000030 x4 : 00000000fffffffe x3 : 0000000000000000 x2 : ffffac9aba78c1c8 x1 : ffffac9aba76d0a8 x0 : 0000000000000008 Call trace: hex_dump_to_buffer+0x30c/0x4a0 (P) print_hex_dump+0xac/0x170 cper_estatus_print_section+0x90c/0x968 cper_estatus_print+0xf0/0x158 __ghes_print_estatus+0xa0/0x148 ghes_proc+0x1bc/0x220 ghes_notify_hed+0x5c/0xb8 notifier_call_chain+0x78/0x148 blocking_notifier_call_chain+0x4c/0x80 acpi_hed_notify+0x28/0x40 acpi_ev_notify_dispatch+0x50/0x80 acpi_os_execute_deferred+0x24/0x48 process_one_work+0x15c/0x3b0 worker_thread+0x2d0/0x400 kthread+0x148/0x228 ret_from_fork+0x10/0x20 Code: 6b14033f 540001ad a94707e2 f100029f (b8747b44) ---[ end trace 0000000000000000 ]--- Prevent that by taking the actual allocated are into account when checking for CPER length. [ rjw: Subject tweaks ]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: dm: clear cloned request bio pointer when last clone bio completes Stale rq->bio values have been observed to cause double-initialization of cloned bios in request-based device-mapper targets, leading to use-after-free and double-free scenarios. One such case occurs when using dm-multipath on top of a PCIe NVMe namespace, where cloned request bios are freed during blk_complete_request(), but rq->bio is left intact. Subsequent clone teardown then attempts to free the same bios again via blk_rq_unprep_clone(). The resulting double-free path looks like: nvme_pci_complete_batch() nvme_complete_batch() blk_mq_end_request_batch() blk_complete_request() // called on a DM clone request bio_endio() // first free of all clone bios ... rq->end_io() // end_clone_request() dm_complete_request(tio->orig) dm_softirq_done() dm_done() dm_end_request() blk_rq_unprep_clone() // second free of clone bios Fix this by clearing the clone request's bio pointer when the last cloned bio completes, ensuring that later teardown paths do not attempt to free already-released bios.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Add sanity check for OOB writes at silencing At silencing the playback URB packets in the implicit fb mode before the actual playback, we blindly assume that the received packets fit with the buffer size. But when the setup in the capture stream differs from the playback stream (e.g. due to the USB core limitation of max packet size), such an inconsistency may lead to OOB writes to the buffer, resulting in a crash. For addressing it, add a sanity check of the transfer buffer size at prepare_silent_urb(), and stop the data copy if the received data overflows. Also, report back the transfer error properly from there, too. Note that this doesn't fix the root cause of the playback error itself, but this merely covers the kernel Oops.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm: Account property blob allocations to memcg DRM_IOCTL_MODE_CREATEPROPBLOB allows userspace to allocate arbitrary-sized property blobs backed by kernel memory. Currently, the blob data allocation is not accounted to the allocating process's memory cgroup, allowing unprivileged users to trigger unbounded kernel memory consumption and potentially cause system-wide OOM. Mark the property blob data allocation with GFP_KERNEL_ACCOUNT so that the memory is properly charged to the caller's memcg. This ensures existing cgroup memory limits apply and prevents uncontrolled kernel memory growth without introducing additional policy or per-file limits.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: nfc: nci: Fix parameter validation for packet data Since commit 9c328f54741b ("net: nfc: nci: Add parameter validation for packet data") communication with nci nfc chips is not working any more. The mentioned commit tries to fix access of uninitialized data, but failed to understand that in some cases the data packet is of variable length and can therefore not be compared to the maximum packet length given by the sizeof(struct).


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels Since commit 56de5e305d4b ("clk: renesas: r9a07g044: Add MSTOP for RZ/G2L") we may get the following kernel panic, for some panels, when rebooting: systemd-shutdown[1]: Rebooting. Call trace: ... do_serror+0x28/0x68 el1h_64_error_handler+0x34/0x50 el1h_64_error+0x6c/0x70 rzg2l_mipi_dsi_host_transfer+0x114/0x458 (P) mipi_dsi_device_transfer+0x44/0x58 mipi_dsi_dcs_set_display_off_multi+0x9c/0xc4 ili9881c_unprepare+0x38/0x88 drm_panel_unprepare+0xbc/0x108 This happens for panels that need to send MIPI-DSI commands in their unprepare() callback. Since the MIPI-DSI interface is stopped at that point, rzg2l_mipi_dsi_host_transfer() triggers the kernel panic. Fix by moving rzg2l_mipi_dsi_stop() to new callback function rzg2l_mipi_dsi_atomic_post_disable(). With this change we now have the correct power-down/stop sequence: systemd-shutdown[1]: Rebooting. rzg2l-mipi-dsi 10850000.dsi: rzg2l_mipi_dsi_atomic_disable(): entry ili9881c-dsi 10850000.dsi.0: ili9881c_unprepare(): entry rzg2l-mipi-dsi 10850000.dsi: rzg2l_mipi_dsi_atomic_post_disable(): entry reboot: Restarting system


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: rapidio: replace rio_free_net() with kfree() in rio_scan_alloc_net() When idtab allocation fails, net is not registered with rio_add_net() yet, so kfree(net) is sufficient to release the memory. Set mport->net to NULL to avoid dangling pointer.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/panel: Fix a possible null-pointer dereference in jdi_panel_dsi_remove() In jdi_panel_dsi_remove(), jdi is explicitly checked, indicating that it may be NULL: if (!jdi) mipi_dsi_detach(dsi); However, when jdi is NULL, the function does not return and continues by calling jdi_panel_disable(): err = jdi_panel_disable(&jdi->base); Inside jdi_panel_disable(), jdi is dereferenced unconditionally, which can lead to a NULL-pointer dereference: struct jdi_panel *jdi = to_panel_jdi(panel); backlight_disable(jdi->backlight); To prevent such a potential NULL-pointer dereference, return early from jdi_panel_dsi_remove() when jdi is NULL.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Set DMA segment size to avoid debug warnings When using V3D rendering with CONFIG_DMA_API_DEBUG enabled, the kernel occasionally reports a segment size mismatch. This is because 'max_seg_size' is not set. The kernel defaults to 64K. setting 'max_seg_size' to the maximum will prevent 'debug_dma_map_sg()' from complaining about the over-mapping of the V3D segment length. DMA-API: v3d 1002000000.v3d: mapping sg segment longer than device claims to support [len=8290304] [max=65536] WARNING: CPU: 0 PID: 493 at kernel/dma/debug.c:1179 debug_dma_map_sg+0x330/0x388 CPU: 0 UID: 0 PID: 493 Comm: Xorg Not tainted 6.12.53-yocto-standard #1 Hardware name: Raspberry Pi 5 Model B Rev 1.0 (DT) pstate: 60400009 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : debug_dma_map_sg+0x330/0x388 lr : debug_dma_map_sg+0x330/0x388 sp : ffff8000829a3ac0 x29: ffff8000829a3ac0 x28: 0000000000000001 x27: ffff8000813fe000 x26: ffffc1ffc0000000 x25: ffff00010fdeb760 x24: 0000000000000000 x23: ffff8000816a9bf0 x22: 0000000000000001 x21: 0000000000000002 x20: 0000000000000002 x19: ffff00010185e810 x18: ffffffffffffffff x17: 69766564206e6168 x16: 74207265676e6f6c x15: 20746e656d676573 x14: 20677320676e6970 x13: 5d34303334393134 x12: 0000000000000000 x11: 00000000000000c0 x10: 00000000000009c0 x9 : ffff8000800e0b7c x8 : ffff00010a315ca0 x7 : ffff8000816a5110 x6 : 0000000000000001 x5 : 000000000000002b x4 : 0000000000000002 x3 : 0000000000000008 x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff00010a315280 Call trace: debug_dma_map_sg+0x330/0x388 __dma_map_sg_attrs+0xc0/0x278 dma_map_sgtable+0x30/0x58 drm_gem_shmem_get_pages_sgt+0xb4/0x140 v3d_bo_create_finish+0x28/0x130 [v3d] v3d_create_bo_ioctl+0x54/0x180 [v3d] drm_ioctl_kernel+0xc8/0x140 drm_ioctl+0x2d4/0x4d8


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: define and enforce CEPH_MAX_KEY_LEN When decoding the key, verify that the key material would fit into a fixed-size buffer in process_auth_done() and generally has a sane length. The new CEPH_MAX_KEY_LEN check replaces the existing check for a key with no key material which is a) not universal since CEPH_CRYPTO_NONE has to be excluded and b) doesn't provide much value since a smaller than needed key is just as invalid as no key -- this has to be handled elsewhere anyway.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov5647: Initialize subdev before controls In ov5647_init_controls() we call v4l2_get_subdevdata, but it is initialized by v4l2_i2c_subdev_init() in the probe, which currently happens after init_controls(). This can result in a segfault if the error condition is hit, and we try to access i2c_client, so fix the order.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: Fix NULL-pointer dereference in acpi_processor_errata_piix4() In acpi_processor_errata_piix4(), the pointer dev is first assigned an IDE device and then reassigned an ISA device: dev = pci_get_subsys(..., PCI_DEVICE_ID_INTEL_82371AB, ...); dev = pci_get_subsys(..., PCI_DEVICE_ID_INTEL_82371AB_0, ...); If the first lookup succeeds but the second fails, dev becomes NULL. This leads to a potential null-pointer dereference when dev_dbg() is called: if (errata.piix4.bmisx) dev_dbg(&dev->dev, ...); To prevent this, use two temporary pointers and retrieve each device independently, avoiding overwriting dev with a possible NULL value. [ rjw: Subject adjustment, added an empty code line ]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: dm: remove fake timeout to avoid leak request Since commit 15f73f5b3e59 ("blk-mq: move failure injection out of blk_mq_complete_request"), drivers are responsible for calling blk_should_fake_timeout() at appropriate code paths and opportunities. However, the dm driver does not implement its own timeout handler and relies on the timeout handling of its slave devices. If an io-timeout-fail error is injected to a dm device, the request will be leaked and never completed, causing tasks to hang indefinitely. Reproduce: 1. prepare dm which has iscsi slave device 2. inject io-timeout-fail to dm echo 1 >/sys/class/block/dm-0/io-timeout-fail echo 100 >/sys/kernel/debug/fail_io_timeout/probability echo 10 >/sys/kernel/debug/fail_io_timeout/times 3. read/write dm 4. iscsiadm -m node -u Result: hang task like below [ 862.243768] INFO: task kworker/u514:2:151 blocked for more than 122 seconds. [ 862.244133] Tainted: G E 6.19.0-rc1+ #51 [ 862.244337] "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. [ 862.244718] task:kworker/u514:2 state:D stack:0 pid:151 tgid:151 ppid:2 task_flags:0x4288060 flags:0x00080000 [ 862.245024] Workqueue: iscsi_ctrl_3:1 __iscsi_unbind_session [scsi_transport_iscsi] [ 862.245264] Call Trace: [ 862.245587] <TASK> [ 862.245814] __schedule+0x810/0x15c0 [ 862.246557] schedule+0x69/0x180 [ 862.246760] blk_mq_freeze_queue_wait+0xde/0x120 [ 862.247688] elevator_change+0x16d/0x460 [ 862.247893] elevator_set_none+0x87/0xf0 [ 862.248798] blk_unregister_queue+0x12e/0x2a0 [ 862.248995] __del_gendisk+0x231/0x7e0 [ 862.250143] del_gendisk+0x12f/0x1d0 [ 862.250339] sd_remove+0x85/0x130 [sd_mod] [ 862.250650] device_release_driver_internal+0x36d/0x530 [ 862.250849] bus_remove_device+0x1dd/0x3f0 [ 862.251042] device_del+0x38a/0x930 [ 862.252095] __scsi_remove_device+0x293/0x360 [ 862.252291] scsi_remove_target+0x486/0x760 [ 862.252654] __iscsi_unbind_session+0x18a/0x3e0 [scsi_transport_iscsi] [ 862.252886] process_one_work+0x633/0xe50 [ 862.253101] worker_thread+0x6df/0xf10 [ 862.253647] kthread+0x36d/0x720 [ 862.254533] ret_from_fork+0x2a6/0x470 [ 862.255852] ret_from_fork_asm+0x1a/0x30 [ 862.256037] </TASK> Remove the blk_should_fake_timeout() check from dm, as dm has no native timeout handling and should not attempt to fake timeouts.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: solo6x10: Check for out of bounds chip_id Clang with CONFIG_UBSAN_SHIFT=y noticed a condition where a signed type (literal "1" is an "int") could end up being shifted beyond 32 bits, so instrumentation was added (and due to the double is_tw286x() call seen via inlining), Clang decides the second one must now be undefined behavior and elides the rest of the function[1]. This is a known problem with Clang (that is still being worked on), but we can avoid the entire problem by actually checking the existing max chip ID, and now there is no runtime instrumentation added at all since everything is known to be within bounds. Additionally use an unsigned value for the shift to remove the instrumentation even without the explicit bounds checking. [hverkuil: fix checkpatch warning for is_tw286x]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify Invalidating a dmabuf will impact other users of the shared BO. In the scenario where process A moves the BO, it needs to inform process B about the move and process B will need to update its page table. The commit fixes a synchronisation bug caused by the use of the ticket: it made amdgpu_vm_handle_moved behave as if updating the page table immediately was correct but in this case it's not. An example is the following scenario, with 2 GPUs and glxgears running on GPU0 and Xorg running on GPU1, on a system where P2P PCI isn't supported: glxgears: export linear buffer from GPU0 and import using GPU1 submit frame rendering to GPU0 submit tiled->linear blit Xorg: copy of linear buffer The sequence of jobs would be: drm_sched_job_run # GPU0, frame rendering drm_sched_job_queue # GPU0, blit drm_sched_job_done # GPU0, frame rendering drm_sched_job_run # GPU0, blit move linear buffer for GPU1 access # amdgpu_dma_buf_move_notify -> update pt # GPU0 It this point the blit job on GPU0 is still running and would likely produce a page fault.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: spi: spidev: fix lock inversion between spi_lock and buf_lock The spidev driver previously used two mutexes, spi_lock and buf_lock, but acquired them in different orders depending on the code path: write()/read(): buf_lock -> spi_lock ioctl(): spi_lock -> buf_lock This AB-BA locking pattern triggers lockdep warnings and can cause real deadlocks: WARNING: possible circular locking dependency detected spidev_ioctl() -> mutex_lock(&spidev->buf_lock) spidev_sync_write() -> mutex_lock(&spidev->spi_lock) *** DEADLOCK *** The issue is reproducible with a simple userspace program that performs write() and SPI_IOC_WR_MAX_SPEED_HZ ioctl() calls from separate threads on the same spidev file descriptor. Fix this by simplifying the locking model and removing the lock inversion entirely. spidev_sync() no longer performs any locking, and all callers serialize access using spi_lock. buf_lock is removed since its functionality is fully covered by spi_lock, eliminating the possibility of lock ordering issues. This removes the lock inversion and prevents deadlocks without changing userspace ABI or behaviour.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dsc eDP issue [why] Need to add function hook check before use


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: USB: dummy-hcd: Fix interrupt synchronization error This fixes an error in synchronization in the dummy-hcd driver. The error has a somewhat involved history. The synchronization mechanism was introduced by commit 7dbd8f4cabd9 ("USB: dummy-hcd: Fix erroneous synchronization change"), which added an emulated "interrupts enabled" flag together with code emulating synchronize_irq() (it waits until all current handler callbacks have returned). But the emulated interrupt-disable occurred too late, after the driver containing the handler callback routines had been told that it was unbound and no more callbacks would occur. Commit 4a5d797a9f9c ("usb: gadget: dummy_hcd: fix gpf in gadget_setup") tried to fix this by moving the synchronize_irq() emulation code from dummy_stop() to dummy_pullup(), which runs before the unbind callback. There still were races, though, because the emulated interrupt-disable still occurred too late. It couldn't be moved to dummy_pullup(), because that routine can be called for reasons other than an impending unbind. Therefore commits 7dc0c55e9f30 ("USB: UDC core: Add udc_async_callbacks gadget op") and 04145a03db9d ("USB: UDC: Implement udc_async_callbacks in dummy-hcd") added an API allowing the UDC core to tell dummy-hcd exactly when emulated interrupts and their callbacks should be disabled. That brings us to the current state of things, which is still wrong because the emulated synchronize_irq() occurs before the emulated interrupt-disable! That's no good, beause it means that more emulated interrupts can occur after the synchronize_irq() emulation has run, leading to the possibility that a callback handler may be running when the gadget driver is unbound. To fix this, we have to move the synchronize_irq() emulation code yet again, to the dummy_udc_async_callbacks() routine, which takes care of enabling and disabling emulated interrupt requests. The synchronization will now run immediately after emulated interrupts are disabled, which is where it belongs.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: USB: dummy-hcd: Fix locking/synchronization error Syzbot testing was able to provoke an addressing exception and crash in the usb_gadget_udc_reset() routine in drivers/usb/gadgets/udc/core.c, resulting from the fact that the routine was called with a second ("driver") argument of NULL. The bad caller was set_link_state() in dummy_hcd.c, and the problem arose because of a race between a USB reset and driver unbind. These sorts of races were not supposed to be possible; commit 7dbd8f4cabd9 ("USB: dummy-hcd: Fix erroneous synchronization change"), along with a few followup commits, was written specifically to prevent them. As it turns out, there are (at least) two errors remaining in the code. Another patch will address the second error; this one is concerned with the first. The error responsible for the syzbot crash occurred because the stop_activity() routine will sometimes drop and then re-acquire the dum->lock spinlock. A call to stop_activity() occurs in set_link_state() when handling an emulated USB reset, after the test of dum->ints_enabled and before the increment of dum->callback_usage. This allowed another thread (doing a driver unbind) to sneak in and grab the spinlock, and then clear dum->ints_enabled and dum->driver. Normally this other thread would have to wait for dum->callback_usage to go down to 0 before it would clear dum->driver, but in this case it didn't have to wait since dum->callback_usage had not yet been incremented. The fix is to increment dum->callback_usage _before_ calling stop_activity() instead of after. Then the thread doing the unbind will not clear dum->driver until after the call to usb_gadget_udc_reset() safely returns and dum->callback_usage has been decremented again.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix NULL pointer dereference in dcn401_init_hw() dcn401_init_hw() assumes that update_bw_bounding_box() is valid when entering the update path. However, the existing condition: ((!fams2_enable && update_bw_bounding_box) || freq_changed) does not guarantee this, as the freq_changed branch can evaluate to true independently of the callback pointer. This can result in calling update_bw_bounding_box() when it is NULL. Fix this by separating the update condition from the pointer checks and ensuring the callback, dc->clk_mgr, and bw_params are validated before use. Fixes the below: ../dc/hwss/dcn401/dcn401_hwseq.c:367 dcn401_init_hw() error: we previously assumed 'dc->res_pool->funcs->update_bw_bounding_box' could be null (see line 362) (cherry picked from commit 86117c5ab42f21562fedb0a64bffea3ee5fcd477)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: comedi: Reinit dev->spinlock between attachments to low-level drivers `struct comedi_device` is the main controlling structure for a COMEDI device created by the COMEDI subsystem. It contains a member `spinlock` containing a spin-lock that is initialized by the COMEDI subsystem, but is reserved for use by a low-level driver attached to the COMEDI device (at least since commit 25436dc9d84f ("Staging: comedi: remove RT code")). Some COMEDI devices (those created on initialization of the COMEDI subsystem when the "comedi.comedi_num_legacy_minors" parameter is non-zero) can be attached to different low-level drivers over their lifetime using the `COMEDI_DEVCONFIG` ioctl command. This can result in inconsistent lock states being reported when there is a mismatch in the spin-lock locking levels used by each low-level driver to which the COMEDI device has been attached. Fix it by reinitializing `dev->spinlock` before calling the low-level driver's `attach` function pointer if `CONFIG_LOCKDEP` is enabled.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_rndis: Protect RNDIS options with mutex The class/subclass/protocol options are suspectible to race conditions as they can be accessed concurrently through configfs. Use existing mutex to protect these options. This issue was identified during code inspection.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_subset: Fix unbalanced refcnt in geth_free geth_alloc() increments the reference count, but geth_free() fails to decrement it. This prevents the configuration of attributes via configfs after unlinking the function. Decrement the reference count in geth_free() to ensure proper cleanup.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ice: ptp: don't WARN when controlling PF is unavailable In VFIO passthrough setups, it is possible to pass through only a PF which doesn't own the source timer. In that case the PTP controlling PF (adapter->ctrl_pf) is never initialized in the VM, so ice_get_ctrl_ptp() returns NULL and triggers WARN_ON() in ice_ptp_setup_pf(). Since this is an expected behavior in that configuration, replace WARN_ON() with an informational message and return -EOPNOTSUPP.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Fix race in DMA ring dequeue The HCI DMA dequeue path (hci_dma_dequeue_xfer()) may be invoked for multiple transfers that timeout around the same time. However, the function is not serialized and can race with itself. When a timeout occurs, hci_dma_dequeue_xfer() stops the ring, processes incomplete transfers, and then restarts the ring. If another timeout triggers a parallel call into the same function, the two instances may interfere with each other - stopping or restarting the ring at unexpected times. Add a mutex so that hci_dma_dequeue_xfer() is serialized with respect to itself.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iio: gyro: mpu3050-core: fix pm_runtime error handling The return value of pm_runtime_get_sync() is not checked, allowing the driver to access hardware that may fail to resume. The device usage count is also unconditionally incremented. Use pm_runtime_resume_and_get() which propagates errors and avoids incrementing the usage count on failure. In preenable, add pm_runtime_put_autosuspend() on set_8khz_samplerate() failure since postdisable does not run when preenable fails.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix use-after-free race in VM acquire Replace non-atomic vm->process_info assignment with cmpxchg() to prevent race when parent/child processes sharing a drm_file both try to acquire the same VM after fork(). (cherry picked from commit c7c573275ec20db05be769288a3e3bb2250ec618)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: ncsi: fix skb leak in error paths Early return paths in NCSI RX and AEN handlers fail to release the received skb, resulting in a memory leak. Specifically, ncsi_aen_handler() returns on invalid AEN packets without consuming the skb. Similarly, ncsi_rcv_rsp() exits early when failing to resolve the NCSI device, response handler, or request, leaving the skb unfreed.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/q54sj108a2) fix stack overflow in debugfs read The q54sj108a2_debugfs_read function suffers from a stack buffer overflow due to incorrect arguments passed to bin2hex(). The function currently passes 'data' as the destination and 'data_char' as the source. Because bin2hex() converts each input byte into two hex characters, a 32-byte block read results in 64 bytes of output. Since 'data' is only 34 bytes (I2C_SMBUS_BLOCK_MAX + 2), this writes 30 bytes past the end of the buffer onto the stack. Additionally, the arguments were swapped: it was reading from the zero-initialized 'data_char' and writing to 'data', resulting in all-zero output regardless of the actual I2C read. Fix this by: 1. Expanding 'data_char' to 66 bytes to safely hold the hex output. 2. Correcting the bin2hex() argument order and using the actual read count. 3. Using a pointer to select the correct output buffer for the final simple_read_from_buffer call.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: nouveau/dpcd: return EBUSY for aux xfer if the device is asleep If we have runtime suspended, and userspace wants to use /dev/drm_dp_* then just tell it the device is busy instead of crashing in the GSP code. WARNING: CPU: 2 PID: 565741 at drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/rpc.c:164 r535_gsp_msgq_wait+0x9a/0xb0 [nouveau] CPU: 2 UID: 0 PID: 565741 Comm: fwupd Not tainted 6.18.10-200.fc43.x86_64 #1 PREEMPT(lazy) Hardware name: LENOVO 20QTS0PQ00/20QTS0PQ00, BIOS N2OET65W (1.52 ) 08/05/2024 RIP: 0010:r535_gsp_msgq_wait+0x9a/0xb0 [nouveau] This is a simple fix to get backported. We should probably engineer a proper power domain solution to wake up devices and keep them awake while fw updates are happening.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: batman-adv: Avoid double-rtnl_lock ELP metric worker batadv_v_elp_get_throughput() might be called when the RTNL lock is already held. This could be problematic when the work queue item is cancelled via cancel_delayed_work_sync() in batadv_v_elp_iface_disable(). In this case, an rtnl_lock() would cause a deadlock. To avoid this, rtnl_trylock() was used in this function to skip the retrieval of the ethtool information in case the RTNL lock was already held. But for cfg80211 interfaces, batadv_get_real_netdev() was called - which also uses rtnl_lock(). The approach for __ethtool_get_link_ksettings() must also be used instead and the lockless version __batadv_get_real_netdev() has to be called.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/tcp-md5: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: properly validate the data in rtw_get_ie_ex() Just like in commit 154828bf9559 ("staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser"), we don't trust the data in the frame so we should check the length better before acting on it


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/xe/sync: Cleanup partially initialized sync on parse failure xe_sync_entry_parse() can allocate references (syncobj, fence, chain fence, or user fence) before hitting a later failure path. Several of those paths returned directly, leaving partially initialized state and leaking refs. Route these error paths through a common free_sync label and call xe_sync_entry_cleanup(sync) before returning the error. (cherry picked from commit f939bdd9207a5d1fc55cced5459858480686ce22)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: samsung-dsim: Fix memory leak in error path In samsung_dsim_host_attach(), drm_bridge_add() is called to add the bridge. However, if samsung_dsim_register_te_irq() or pdata->host_ops->attach() fails afterwards, the function returns without removing the bridge, causing a memory leak. Fix this by adding proper error handling with goto labels to ensure drm_bridge_remove() is called in all error paths. Also ensure that samsung_dsim_unregister_te_irq() is called if the attach operation fails after the TE IRQ has been registered. samsung_dsim_unregister_te_irq() function is moved without changes to be before samsung_dsim_host_attach() to avoid forward declaration.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: qdsp6: Fix q6apm remove ordering during ADSP stop and start During ADSP stop and start, the kernel crashes due to the order in which ASoC components are removed. On ADSP stop, the q6apm-audio .remove callback unloads topology and removes PCM runtimes during ASoC teardown. This deletes the RTDs that contain the q6apm DAI components before their removal pass runs, leaving those components still linked to the card and causing crashes on the next rebind. Fix this by ensuring that all dependent (child) components are removed first, and the q6apm component is removed last. [ 48.105720] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000d0 [ 48.114763] Mem abort info: [ 48.117650] ESR = 0x0000000096000004 [ 48.121526] EC = 0x25: DABT (current EL), IL = 32 bits [ 48.127010] SET = 0, FnV = 0 [ 48.130172] EA = 0, S1PTW = 0 [ 48.133415] FSC = 0x04: level 0 translation fault [ 48.138446] Data abort info: [ 48.141422] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 [ 48.147079] CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [ 48.152354] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [ 48.157859] user pgtable: 4k pages, 48-bit VAs, pgdp=00000001173cf000 [ 48.164517] [00000000000000d0] pgd=0000000000000000, p4d=0000000000000000 [ 48.171530] Internal error: Oops: 0000000096000004 [#1] SMP [ 48.177348] Modules linked in: q6prm_clocks q6apm_lpass_dais q6apm_dai snd_q6dsp_common q6prm snd_q6apm 8021q garp mrp stp llc snd_soc_hdmi_codec apr pdr_interface phy_qcom_edp fastrpc qcom_pd_mapper rpmsg_ctrl qrtr_smd rpmsg_char qcom_pdr_msg qcom_iris v4l2_mem2mem videobuf2_dma_contig ath11k_pci msm ubwc_config at24 ath11k videobuf2_memops mac80211 ocmem videobuf2_v4l2 libarc4 drm_gpuvm mhi qrtr videodev drm_exec snd_soc_sc8280xp gpu_sched videobuf2_common nvmem_qcom_spmi_sdam snd_soc_qcom_sdw drm_dp_aux_bus qcom_q6v5_pas qcom_spmi_temp_alarm snd_soc_qcom_common rtc_pm8xxx qcom_pon drm_display_helper cec qcom_pil_info qcom_stats soundwire_bus drm_client_lib mc dispcc0_sa8775p videocc_sa8775p qcom_q6v5 camcc_sa8775p snd_soc_dmic phy_qcom_sgmii_eth snd_soc_max98357a i2c_qcom_geni snd_soc_core dwmac_qcom_ethqos llcc_qcom icc_bwmon qcom_sysmon snd_compress qcom_refgen_regulator coresight_stm stmmac_platform snd_pcm_dmaengine qcom_common coresight_tmc stmmac coresight_replicator qcom_glink_smem coresight_cti stm_core [ 48.177444] coresight_funnel snd_pcm ufs_qcom phy_qcom_qmp_usb gpi phy_qcom_snps_femto_v2 coresight phy_qcom_qmp_ufs qcom_wdt gpucc_sa8775p pcs_xpcs mdt_loader qcom_ice icc_osm_l3 qmi_helpers snd_timer snd soundcore display_connector qcom_rng nvmem_reboot_mode drm_kms_helper phy_qcom_qmp_pcie sha256 cfg80211 rfkill socinfo fuse drm backlight ipv6 [ 48.301059] CPU: 2 UID: 0 PID: 293 Comm: kworker/u32:2 Not tainted 6.19.0-rc6-dirty #10 PREEMPT [ 48.310081] Hardware name: Qualcomm Technologies, Inc. Lemans EVK (DT) [ 48.316782] Workqueue: pdr_notifier_wq pdr_notifier_work [pdr_interface] [ 48.323672] pstate: 20400005 (nzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 48.330825] pc : mutex_lock+0xc/0x54 [ 48.334514] lr : soc_dapm_shutdown_dapm+0x44/0x174 [snd_soc_core] [ 48.340794] sp : ffff800084ddb7b0 [ 48.344207] x29: ffff800084ddb7b0 x28: ffff00009cd9cf30 x27: ffff00009cd9cc00 [ 48.351544] x26: ffff000099610190 x25: ffffa31d2f19c810 x24: ffffa31d2f185098 [ 48.358869] x23: ffff800084ddb7f8 x22: 0000000000000000 x21: 00000000000000d0 [ 48.366198] x20: ffff00009ba6c338 x19: ffff00009ba6c338 x18: 00000000ffffffff [ 48.373528] x17: 000000040044ffff x16: ffffa31d4ae6dca8 x15: 072007740775076f [ 48.380853] x14: 0765076d07690774 x13: 00313a323a656369 x12: 767265733a637673 [ 48.388182] x11: 00000000000003f9 x10: ffffa31d4c7dea98 x9 : 0000000000000001 [ 48.395519] x8 : ffff00009a2aadc0 x7 : 0000000000000003 x6 : 0000000000000000 [ 48.402854] x5 : 0000000000000 ---truncated---


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: image: mdc800: kill download URB on timeout mdc800_device_read() submits download_urb and waits for completion. If the timeout fires and the device has not responded, the function returns without killing the URB, leaving it active. A subsequent read() resubmits the same URB while it is still in-flight, triggering the WARN in usb_submit_urb(): "URB submitted while active" Check the return value of wait_event_timeout() and kill the URB if it indicates timeout, ensuring the URB is complete before its status is inspected or the URB is resubmitted. Similar to - commit 372c93131998 ("USB: yurex: fix control-URB timeout handling") - commit b98d5000c505 ("media: rc: iguanair: handle timeouts")


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: fix use-after-free in ISR during device removal In usbhs_remove(), the driver frees resources (including the pipe array) while the interrupt handler (usbhs_interrupt) is still registered. If an interrupt fires after usbhs_pipe_remove() but before the driver is fully unbound, the ISR may access freed memory, causing a use-after-free. Fix this by calling devm_free_irq() before freeing resources. This ensures the interrupt handler is both disabled and synchronized (waits for any running ISR to complete) before usbhs_pipe_remove() is called.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: class: cdc-wdm: fix reordering issue in read code path Quoting the bug report: Due to compiler optimization or CPU out-of-order execution, the desc->length update can be reordered before the memmove. If this happens, wdm_read() can see the new length and call copy_to_user() on uninitialized memory. This also violates LKMM data race rules [1]. Fix it by using WRITE_ONCE and memory barriers.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: USB: core: Limit the length of unkillable synchronous timeouts The usb_control_msg(), usb_bulk_msg(), and usb_interrupt_msg() APIs in usbcore allow unlimited timeout durations. And since they use uninterruptible waits, this leaves open the possibility of hanging a task for an indefinitely long time, with no way to kill it short of unplugging the target device. To prevent this sort of problem, enforce a maximum limit on the length of these unkillable timeouts. The limit chosen here, somewhat arbitrarily, is 60 seconds. On many systems (although not all) this is short enough to avoid triggering the kernel's hung-task detector. In addition, clear up the ambiguity of negative timeout values by treating them the same as 0, i.e., using the maximum allowed timeout.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: USB: usbtmc: Use usb_bulk_msg_killable() with user-specified timeouts The usbtmc driver accepts timeout values specified by the user in an ioctl command, and uses these timeouts for some usb_bulk_msg() calls. Since the user can specify arbitrarily long timeouts and usb_bulk_msg() uses unkillable waits, call usb_bulk_msg_killable() instead to avoid the possibility of the user hanging a kernel thread indefinitely.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: yurex: fix race in probe The bbu member of the descriptor must be set to the value standing for uninitialized values before the URB whose completion handler sets bbu is submitted. Otherwise there is a window during which probing can overwrite already retrieved data.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix memory leak in xhci_disable_slot() xhci_alloc_command() allocates a command structure and, when the second argument is true, also allocates a completion structure. Currently, the error handling path in xhci_disable_slot() only frees the command structure using kfree(), causing the completion structure to leak. Use xhci_free_command() instead of kfree(). xhci_free_command() correctly frees both the command structure and the associated completion structure. Since the command structure is allocated with zero-initialization, command->in_ctx is NULL and will not be erroneously freed by xhci_free_command(). This bug was found using an experimental static analysis tool we are developing. The tool is based on the LLVM framework and is specifically designed to detect memory management issues. It is currently under active development and not yet publicly available, but we plan to open-source it after our research is published. The bug was originally detected on v6.13-rc1 using our static analysis tool, and we have verified that the issue persists in the latest mainline kernel. We performed build testing on x86_64 with allyesconfig using GCC=11.4.0. Since triggering these error paths in xhci_disable_slot() requires specific hardware conditions or abnormal state, we were unable to construct a test case to reliably trigger these specific error paths at runtime.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Check endpoint numbers at parsing Scarlett2 mixer interfaces The Scarlett2 mixer quirk in USB-audio driver may hit a NULL dereference when a malformed USB descriptor is passed, since it assumes the presence of an endpoint in the parsed interface in scarlett2_find_fc_interface(), as reported by fuzzer. For avoiding the NULL dereference, just add the sanity check of bNumEndpoints and skip the invalid interface.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp-mach-common: Add missing error check for clock acquisition The acp_card_rt5682_init() and acp_card_rt5682s_init() functions did not check the return values of clk_get(). This could lead to a kernel crash when the invalid pointers are later dereferenced by clock core functions. Fix this by: 1. Changing clk_get() to the device-managed devm_clk_get(). 2. Adding IS_ERR() checks immediately after each clock acquisition.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Unreserve bo if queue update failed Error handling path should unreserve bo then return failed. (cherry picked from commit c24afed7de9ecce341825d8ab55a43a254348b33)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: e1000/e1000e: Fix leak in DMA error cleanup If an error is encountered while mapping TX buffers, the driver should unmap any buffers already mapped for that skb. Because count is incremented after a successful mapping, it will always match the correct number of unmappings needed when dma_error is reached. Decrementing count before the while loop in dma_error causes an off-by-one error. If any mapping was successful before an unsuccessful mapping, exactly one DMA mapping would leak. In these commits, a faulty while condition caused an infinite loop in dma_error: Commit 03b1320dfcee ("e1000e: remove use of skb_dma_map from e1000e driver") Commit 602c0554d7b0 ("e1000: remove use of skb_dma_map from e1000 driver") Commit c1fa347f20f1 ("e1000/e1000e/igb/igbvf/ixgb/ixgbe: Fix tests of unsigned in *_tx_map()") fixed the infinite loop, but introduced the off-by-one error. This issue may still exist in the igbvf driver, but I did not address it in this patch.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set dev->online_queues is a count incremented in nvme_init_queue. Thus, valid indices are 0 through dev->online_queues − 1. This patch fixes the loop condition to ensure the index stays within the valid range. Index 0 is excluded because it is the admin queue. KASAN splat: ================================================================== BUG: KASAN: slab-out-of-bounds in nvme_dbbuf_free drivers/nvme/host/pci.c:377 [inline] BUG: KASAN: slab-out-of-bounds in nvme_dbbuf_set+0x39c/0x400 drivers/nvme/host/pci.c:404 Read of size 2 at addr ffff88800592a574 by task kworker/u8:5/74 CPU: 0 UID: 0 PID: 74 Comm: kworker/u8:5 Not tainted 6.19.0-dirty #10 PREEMPT(voluntary) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 Workqueue: nvme-reset-wq nvme_reset_work Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0xea/0x150 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xce/0x5d0 mm/kasan/report.c:482 kasan_report+0xdc/0x110 mm/kasan/report.c:595 __asan_report_load2_noabort+0x18/0x20 mm/kasan/report_generic.c:379 nvme_dbbuf_free drivers/nvme/host/pci.c:377 [inline] nvme_dbbuf_set+0x39c/0x400 drivers/nvme/host/pci.c:404 nvme_reset_work+0x36b/0x8c0 drivers/nvme/host/pci.c:3252 process_one_work+0x956/0x1aa0 kernel/workqueue.c:3257 process_scheduled_works kernel/workqueue.c:3340 [inline] worker_thread+0x65c/0xe60 kernel/workqueue.c:3421 kthread+0x41a/0x930 kernel/kthread.c:463 ret_from_fork+0x6f8/0x8c0 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:246 </TASK> Allocated by task 34 on cpu 1 at 4.241550s: kasan_save_stack+0x2c/0x60 mm/kasan/common.c:57 kasan_save_track+0x1c/0x70 mm/kasan/common.c:78 kasan_save_alloc_info+0x3c/0x50 mm/kasan/generic.c:570 poison_kmalloc_redzone mm/kasan/common.c:398 [inline] __kasan_kmalloc+0xb5/0xc0 mm/kasan/common.c:415 kasan_kmalloc include/linux/kasan.h:263 [inline] __do_kmalloc_node mm/slub.c:5657 [inline] __kmalloc_node_noprof+0x2bf/0x8d0 mm/slub.c:5663 kmalloc_array_node_noprof include/linux/slab.h:1075 [inline] nvme_pci_alloc_dev drivers/nvme/host/pci.c:3479 [inline] nvme_probe+0x2f1/0x1820 drivers/nvme/host/pci.c:3534 local_pci_probe+0xef/0x1c0 drivers/pci/pci-driver.c:324 pci_call_probe drivers/pci/pci-driver.c:392 [inline] __pci_device_probe drivers/pci/pci-driver.c:417 [inline] pci_device_probe+0x743/0x920 drivers/pci/pci-driver.c:451 call_driver_probe drivers/base/dd.c:583 [inline] really_probe+0x29b/0xb70 drivers/base/dd.c:661 __driver_probe_device+0x3b0/0x4a0 drivers/base/dd.c:803 driver_probe_device+0x56/0x1f0 drivers/base/dd.c:833 __driver_attach_async_helper+0x155/0x340 drivers/base/dd.c:1159 async_run_entry_fn+0xa6/0x4b0 kernel/async.c:129 process_one_work+0x956/0x1aa0 kernel/workqueue.c:3257 process_scheduled_works kernel/workqueue.c:3340 [inline] worker_thread+0x65c/0xe60 kernel/workqueue.c:3421 kthread+0x41a/0x930 kernel/kthread.c:463 ret_from_fork+0x6f8/0x8c0 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:246 The buggy address belongs to the object at ffff88800592a000 which belongs to the cache kmalloc-2k of size 2048 The buggy address is located 244 bytes to the right of allocated 1152-byte region [ffff88800592a000, ffff88800592a480) The buggy address belongs to the physical page: page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x5928 head: order:3 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 anon flags: 0xfffffc0000040(head|node=0|zone=1|lastcpupid=0x1fffff) page_type: f5(slab) raw: 000fffffc0000040 ffff888001042000 0000000000000000 dead000000000001 raw: 0000000000000000 0000000000080008 00000000f5000000 0000000000000000 head: 000fffffc0000040 ffff888001042000 00000 ---truncated---


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() nfnl_cthelper_dump_table() has a 'goto restart' that jumps to a label inside the for loop body. When the "last" helper saved in cb->args[1] is deleted between dump rounds, every entry fails the (cur != last) check, so cb->args[1] is never cleared. The for loop finishes with cb->args[0] == nf_ct_helper_hsize, and the 'goto restart' jumps back into the loop body bypassing the bounds check, causing an 8-byte out-of-bounds read on nf_ct_helper_hash[nf_ct_helper_hsize]. The 'goto restart' block was meant to re-traverse the current bucket when "last" is no longer found, but it was placed after the for loop instead of inside it. Move the block into the for loop body so that the restart only occurs while cb->args[0] is still within bounds. BUG: KASAN: slab-out-of-bounds in nfnl_cthelper_dump_table+0x9f/0x1b0 Read of size 8 at addr ffff888104ca3000 by task poc_cthelper/131 Call Trace: nfnl_cthelper_dump_table+0x9f/0x1b0 netlink_dump+0x333/0x880 netlink_recvmsg+0x3e2/0x4b0 sock_recvmsg+0xde/0xf0 __sys_recvfrom+0x150/0x200 __x64_sys_recvfrom+0x76/0x90 do_syscall_64+0xc3/0x6e0 Allocated by task 1: __kvmalloc_node_noprof+0x21b/0x700 nf_ct_alloc_hashtable+0x65/0xd0 nf_conntrack_helper_init+0x21/0x60 nf_conntrack_init_start+0x18d/0x300 nf_conntrack_standalone_init+0x12/0xc0


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: guard option walkers against 1-byte tail reads When the last byte of options is a non-single-byte option kind, walkers that advance with i += op[i + 1] ? : 1 can read op[i + 1] past the end of the option area. Add an explicit i == optlen - 1 check before dereferencing op[i + 1] in xt_tcpudp and xt_dccp option walkers.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-core: flush delayed work before removing DAIs and widgets When a sound card is unbound while a PCM stream is open, a use-after-free can occur in snd_soc_dapm_stream_event(), called from the close_delayed_work workqueue handler. During unbind, snd_soc_unbind_card() flushes delayed work and then calls soc_cleanup_card_resources(). Inside cleanup, snd_card_disconnect_sync() releases all PCM file descriptors, and the resulting PCM close path can call snd_soc_dapm_stream_stop() which schedules new delayed work with a pmdown_time timer delay. Since this happens after the flush in snd_soc_unbind_card(), the new work is not caught. soc_remove_link_components() then frees DAPM widgets before this work fires, leading to the use-after-free. The existing flush in soc_free_pcm_runtime() also cannot help as it runs after soc_remove_link_components() has already freed the widgets. Add a flush in soc_cleanup_card_resources() after snd_card_disconnect_sync() (after which no new PCM closes can schedule further delayed work) and before soc_remove_link_dais() and soc_remove_link_components() (which tear down the structures the delayed work accesses).


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ XDP multi-buf programs can modify the layout of the XDP buffer when the program calls bpf_xdp_pull_data() or bpf_xdp_adjust_tail(). The referenced commit in the fixes tag corrected the assumption in the mlx5 driver that the XDP buffer layout doesn't change during a program execution. However, this fix introduced another issue: the dropped fragments still need to be counted on the driver side to avoid page fragment reference counting issues. The issue was discovered by the drivers/net/xdp.py selftest, more specifically the test_xdp_native_tx_mb: - The mlx5 driver allocates a page_pool page and initializes it with a frag counter of 64 (pp_ref_count=64) and the internal frag counter to 0. - The test sends one packet with no payload. - On RX (mlx5e_skb_from_cqe_mpwrq_nonlinear()), mlx5 configures the XDP buffer with the packet data starting in the first fragment which is the page mentioned above. - The XDP program runs and calls bpf_xdp_pull_data() which moves the header into the linear part of the XDP buffer. As the packet doesn't contain more data, the program drops the tail fragment since it no longer contains any payload (pp_ref_count=63). - mlx5 device skips counting this fragment. Internal frag counter remains 0. - mlx5 releases all 64 fragments of the page but page pp_ref_count is 63 => negative reference counting error. Resulting splat during the test: WARNING: CPU: 0 PID: 188225 at ./include/net/page_pool/helpers.h:297 mlx5e_page_release_fragmented.isra.0+0xbd/0xe0 [mlx5_core] Modules linked in: [...] CPU: 0 UID: 0 PID: 188225 Comm: ip Not tainted 6.18.0-rc7_for_upstream_min_debug_2025_12_08_11_44 #1 NONE Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 RIP: 0010:mlx5e_page_release_fragmented.isra.0+0xbd/0xe0 [mlx5_core] [...] Call Trace: <TASK> mlx5e_free_rx_mpwqe+0x20a/0x250 [mlx5_core] mlx5e_dealloc_rx_mpwqe+0x37/0xb0 [mlx5_core] mlx5e_free_rx_descs+0x11a/0x170 [mlx5_core] mlx5e_close_rq+0x78/0xa0 [mlx5_core] mlx5e_close_queues+0x46/0x2a0 [mlx5_core] mlx5e_close_channel+0x24/0x90 [mlx5_core] mlx5e_close_channels+0x5d/0xf0 [mlx5_core] mlx5e_safe_switch_params+0x2ec/0x380 [mlx5_core] mlx5e_change_mtu+0x11d/0x490 [mlx5_core] mlx5e_change_nic_mtu+0x19/0x30 [mlx5_core] netif_set_mtu_ext+0xfc/0x240 do_setlink.isra.0+0x226/0x1100 rtnl_newlink+0x7a9/0xba0 rtnetlink_rcv_msg+0x220/0x3c0 netlink_rcv_skb+0x4b/0xf0 netlink_unicast+0x255/0x380 netlink_sendmsg+0x1f3/0x420 __sock_sendmsg+0x38/0x60 ____sys_sendmsg+0x1e8/0x240 ___sys_sendmsg+0x7c/0xb0 [...] __sys_sendmsg+0x5f/0xb0 do_syscall_64+0x55/0xc70 The problem applies for XDP_PASS as well which is handled in a different code path in the driver. This patch fixes the issue by doing page frag counting on all the original XDP buffer fragments for all relevant XDP actions (XDP_TX , XDP_REDIRECT and XDP_PASS). This is basically reverting to the original counting before the commit in the fixes tag. As frag_page is still pointing to the original tail, the nr_frags parameter to xdp_update_skb_frags_info() needs to be calculated in a different way to reflect the new nr_frags.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery In case of a TX error CQE, a recovery flow is triggered, mlx5e_reset_txqsq_cc_pc() resets dma_fifo_cc to 0 but not dma_fifo_pc, desyncing the DMA FIFO producer and consumer. After recovery, the producer pushes new DMA entries at the old dma_fifo_pc, while the consumer reads from position 0. This causes us to unmap stale DMA addresses from before the recovery. The DMA FIFO is a purely software construct with no HW counterpart. At the point of reset, all WQEs have been flushed so dma_fifo_cc is already equal to dma_fifo_pc. There is no need to reset either counter, similar to how skb_fifo pc/cc are untouched. Remove the 'dma_fifo_cc = 0' reset. This fixes the following WARNING: WARNING: CPU: 0 PID: 0 at drivers/iommu/dma-iommu.c:1240 iommu_dma_unmap_page+0x79/0x90 Modules linked in: mlx5_vdpa vringh vdpa bonding mlx5_ib mlx5_vfio_pci ipip mlx5_fwctl tunnel4 mlx5_core ib_ipoib geneve ip6_gre ip_gre gre nf_tables ip6_tunnel rdma_ucm ib_uverbs ib_umad vfio_pci vfio_pci_core act_mirred act_skbedit act_vlan vhost_net vhost tap ip6table_mangle ip6table_nat ip6table_filter ip6_tables iptable_mangle cls_matchall nfnetlink_cttimeout act_gact cls_flower sch_ingress vhost_iotlb iptable_raw tunnel6 vfio_iommu_type1 vfio openvswitch nsh rpcsec_gss_krb5 auth_rpcgss oid_registry xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink iptable_nat nf_nat xt_addrtype br_netfilter overlay zram zsmalloc rpcrdma ib_iser libiscsi scsi_transport_iscsi rdma_cm iw_cm ib_cm ib_core fuse [last unloaded: nf_tables] CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.13.0-rc5_for_upstream_min_debug_2024_12_30_21_33 #1 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 RIP: 0010:iommu_dma_unmap_page+0x79/0x90 Code: 2b 4d 3b 21 72 26 4d 3b 61 08 73 20 49 89 d8 44 89 f9 5b 4c 89 f2 4c 89 e6 48 89 ef 5d 41 5c 41 5d 41 5e 41 5f e9 c7 ae 9e ff <0f> 0b 5b 5d 41 5c 41 5d 41 5e 41 5f c3 66 2e 0f 1f 84 00 00 00 00 Call Trace: <IRQ> ? __warn+0x7d/0x110 ? iommu_dma_unmap_page+0x79/0x90 ? report_bug+0x16d/0x180 ? handle_bug+0x4f/0x90 ? exc_invalid_op+0x14/0x70 ? asm_exc_invalid_op+0x16/0x20 ? iommu_dma_unmap_page+0x79/0x90 ? iommu_dma_unmap_page+0x2e/0x90 dma_unmap_page_attrs+0x10d/0x1b0 mlx5e_tx_wi_dma_unmap+0xbe/0x120 [mlx5_core] mlx5e_poll_tx_cq+0x16d/0x690 [mlx5_core] mlx5e_napi_poll+0x8b/0xac0 [mlx5_core] __napi_poll+0x24/0x190 net_rx_action+0x32a/0x3b0 ? mlx5_eq_comp_int+0x7e/0x270 [mlx5_core] ? notifier_call_chain+0x35/0xa0 handle_softirqs+0xc9/0x270 irq_exit_rcu+0x71/0xd0 common_interrupt+0x7f/0xa0 </IRQ> <TASK> asm_common_interrupt+0x22/0x40


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix crash when moving to switchdev mode When moving to switchdev mode when the device doesn't support IPsec, we try to clean up the IPsec resources anyway which causes the crash below, fix that by correctly checking for IPsec support before trying to clean up its resources. [27642.515799] WARNING: arch/x86/mm/fault.c:1276 at do_user_addr_fault+0x18a/0x680, CPU#4: devlink/6490 [27642.517159] Modules linked in: xt_conntrack xt_MASQUERADE ip6table_nat ip6table_filter ip6_tables iptable_nat nf_nat xt_addrtype rpcsec_gss_krb5 auth_rpcgss oid_registry overlay mlx5_fwctl nfnetlink zram zsmalloc mlx5_ib fuse rpcrdma rdma_ucm ib_uverbs ib_iser libiscsi scsi_transport_iscsi ib_umad rdma_cm ib_ipoib iw_cm ib_cm mlx5_core ib_core [27642.521358] CPU: 4 UID: 0 PID: 6490 Comm: devlink Not tainted 6.19.0-rc5_for_upstream_min_debug_2026_01_14_16_47 #1 NONE [27642.522923] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [27642.524528] RIP: 0010:do_user_addr_fault+0x18a/0x680 [27642.525362] Code: ff 0f 84 75 03 00 00 48 89 ee 4c 89 e7 e8 5e b9 22 00 49 89 c0 48 85 c0 0f 84 a8 02 00 00 f7 c3 60 80 00 00 74 22 31 c9 eb ae <0f> 0b 48 83 c4 10 48 89 ea 48 89 de 4c 89 f7 5b 5d 41 5c 41 5d 41 [27642.528166] RSP: 0018:ffff88810770f6b8 EFLAGS: 00010046 [27642.529038] RAX: 0000000000000000 RBX: 0000000000000002 RCX: ffff88810b980f00 [27642.530158] RDX: 00000000000000a0 RSI: 0000000000000002 RDI: ffff88810770f728 [27642.531270] RBP: 00000000000000a0 R08: 0000000000000000 R09: 0000000000000000 [27642.532383] R10: 0000000000000000 R11: 0000000000000000 R12: ffff888103f3c4c0 [27642.533499] R13: 0000000000000000 R14: ffff88810770f728 R15: 0000000000000000 [27642.534614] FS: 00007f197c741740(0000) GS:ffff88856a94c000(0000) knlGS:0000000000000000 [27642.535915] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [27642.536858] CR2: 00000000000000a0 CR3: 000000011334c003 CR4: 0000000000172eb0 [27642.537982] Call Trace: [27642.538466] <TASK> [27642.538907] exc_page_fault+0x76/0x140 [27642.539583] asm_exc_page_fault+0x22/0x30 [27642.540282] RIP: 0010:_raw_spin_lock_irqsave+0x10/0x30 [27642.541134] Code: 07 85 c0 75 11 ba ff 00 00 00 f0 0f b1 17 75 06 b8 01 00 00 00 c3 31 c0 c3 90 0f 1f 44 00 00 53 9c 5b fa 31 c0 ba 01 00 00 00 <f0> 0f b1 17 75 05 48 89 d8 5b c3 89 c6 e8 7e 02 00 00 48 89 d8 5b [27642.543936] RSP: 0018:ffff88810770f7d8 EFLAGS: 00010046 [27642.544803] RAX: 0000000000000000 RBX: 0000000000000202 RCX: ffff888113ad96d8 [27642.545916] RDX: 0000000000000001 RSI: ffff88810770f818 RDI: 00000000000000a0 [27642.547027] RBP: 0000000000000098 R08: 0000000000000400 R09: ffff88810b980f00 [27642.548140] R10: 0000000000000001 R11: ffff888101845a80 R12: 00000000000000a8 [27642.549263] R13: ffffffffa02a9060 R14: 00000000000000a0 R15: ffff8881130d8a40 [27642.550379] complete_all+0x20/0x90 [27642.551010] mlx5e_ipsec_disable_events+0xb6/0xf0 [mlx5_core] [27642.552022] mlx5e_nic_disable+0x12d/0x220 [mlx5_core] [27642.552929] mlx5e_detach_netdev+0x66/0xf0 [mlx5_core] [27642.553822] mlx5e_netdev_change_profile+0x5b/0x120 [mlx5_core] [27642.554821] mlx5e_vport_rep_load+0x419/0x590 [mlx5_core] [27642.555757] ? xa_load+0x53/0x90 [27642.556361] __esw_offloads_load_rep+0x54/0x70 [mlx5_core] [27642.557328] mlx5_esw_offloads_rep_load+0x45/0xd0 [mlx5_core] [27642.558320] esw_offloads_enable+0xb4b/0xc90 [mlx5_core] [27642.559247] mlx5_eswitch_enable_locked+0x34e/0x4f0 [mlx5_core] [27642.560257] ? mlx5_rescan_drivers_locked+0x222/0x2d0 [mlx5_core] [27642.561284] mlx5_devlink_eswitch_mode_set+0x5ac/0x9c0 [mlx5_core] [27642.562334] ? devlink_rate_set_ops_supported+0x21/0x3a0 [27642.563220] devlink_nl_eswitch_set_doit+0x67/0xe0 [27642.564026] genl_family_rcv_msg_doit+0xe0/0x130 [27642.564816] genl_rcv_msg+0x183/0x290 [27642.565466] ? __devlink_nl_pre_doit.isra.0+0x160/0x160 [27642.566329] ? d ---truncated---


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix deadlock between devlink lock and esw->wq esw->work_queue executes esw_functions_changed_event_handler -> esw_vfs_changed_event_handler and acquires the devlink lock. .eswitch_mode_set (acquires devlink lock in devlink_nl_pre_doit) -> mlx5_devlink_eswitch_mode_set -> mlx5_eswitch_disable_locked -> mlx5_eswitch_event_handler_unregister -> flush_workqueue deadlocks when esw_vfs_changed_event_handler executes. Fix that by no longer flushing the work to avoid the deadlock, and using a generation counter to keep track of work relevance. This avoids an old handler manipulating an esw that has undergone one or more mode changes: - the counter is incremented in mlx5_eswitch_event_handler_unregister. - the counter is read and passed to the ephemeral mlx5_host_work struct. - the work handler takes the devlink lock and bails out if the current generation is different than the one it was scheduled to operate on. - mlx5_eswitch_cleanup does the final draining before destroying the wq. No longer flushing the workqueue has the side effect of maybe no longer cancelling pending vport_change_handler work items, but that's ok since those are disabled elsewhere: - mlx5_eswitch_disable_locked disables the vport eq notifier. - mlx5_esw_vport_disable disarms the HW EQ notification and marks vport->enabled under state_lock to false to prevent pending vport handler from doing anything. - mlx5_eswitch_cleanup destroys the workqueue and makes sure all events are disabled/finished.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Add NULL checks when resetting request and reply queues The driver encountered a crash during resource cleanup when the reply and request queues were NULL due to freed memory. This issue occurred when the creation of reply or request queues failed, and the driver freed the memory first, but attempted to mem set the content of the freed memory, leading to a system crash. Add NULL pointer checks for reply and request queues before accessing the reply/request memory during cleanup


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iio: chemical: sps30_i2c: fix buffer size in sps30_i2c_read_meas() sizeof(num) evaluates to sizeof(size_t) (8 bytes on 64-bit) instead of the intended __be32 element size (4 bytes). Use sizeof(*meas) to correctly match the buffer element type.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition The acp3x_5682_init() function did not check the return value of clk_get(), which could lead to dereferencing error pointers in rt5682_clk_enable(). Fix this by: 1. Changing clk_get() to the device-managed devm_clk_get(). 2. Adding proper IS_ERR() checks for both clock acquisitions.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Prevent interrupt storm on host controller error (HCE) The xHCI controller reports a Host Controller Error (HCE) in UAS Storage Device plug/unplug scenarios on Android devices. HCE is checked in xhci_irq() function and causes an interrupt storm (since the interrupt isn't cleared), leading to severe system-level faults. When the xHC controller reports HCE in the interrupt handler, the driver only logs a warning and assumes xHC activity will stop as stated in xHCI specification. An interrupt storm does however continue on some hosts even after HCE, and only ceases after manually disabling xHC interrupt and stopping the controller by calling xhci_halt(). Add xhci_halt() to xhci_irq() function where STS_HCE status is checked, mirroring the existing error handling pattern used for STS_FATAL errors. This only fixes the interrupt storm. Proper HCE recovery requires resetting and re-initializing the xHC.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG requests MAY_BACKLOG requests can return EBUSY. Handle them by checking for that value and filtering out EINPROGRESS notifications.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked When red qdisc has children (eg qfq qdisc) whose peek() callback is qdisc_peek_dequeued(), we could get a kernel panic. When the parent of such qdiscs (eg illustrated in patch #3 as tbf) wants to retrieve an skb from its child (red in this case), it will do the following: 1a. do a peek() - and when sensing there's an skb the child can offer, then - the child in this case(red) calls its child's (qfq) peek. qfq does the right thing and will return the gso_skb queue packet. Note: if there wasnt a gso_skb entry then qfq will store it there. 1b. invoke a dequeue() on the child (red). And herein lies the problem. - red will call the child's dequeue() which will essentially just try to grab something of qfq's queue. [ 78.667668][ T363] KASAN: null-ptr-deref in range [0x0000000000000048-0x000000000000004f] [ 78.667927][ T363] CPU: 1 UID: 0 PID: 363 Comm: ping Not tainted 7.1.0-rc1-00033-g46f74a3f7d57-dirty #790 PREEMPT(full) [ 78.668263][ T363] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 78.668486][ T363] RIP: 0010:qfq_dequeue+0x446/0xc90 [sch_qfq] [ 78.668718][ T363] Code: 54 c0 e8 dd 90 00 f1 48 c7 c7 e0 03 54 c0 48 89 de e8 ce 90 00 f1 48 8d 7b 48 b8 ff ff 37 00 48 89 fa 48 c1 e0 2a 48 c1 ea 03 <80> 3c 02 00 74 05 e8 ef a1 e1 f1 48 8b 7b 48 48 8d 54 24 58 48 8d [ 78.669312][ T363] RSP: 0018:ffff88810de573e0 EFLAGS: 00010216 [ 78.669533][ T363] RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000 [ 78.669790][ T363] RDX: 0000000000000009 RSI: 0000000000000004 RDI: 0000000000000048 [ 78.670044][ T363] RBP: ffff888110dc4000 R08: ffffffffb1b0885a R09: fffffbfff6ba9078 [ 78.670297][ T363] R10: 0000000000000003 R11: ffff888110e31c80 R12: 0000001880000000 [ 78.670560][ T363] R13: ffff888110dc4150 R14: ffff888110dc42b8 R15: 0000000000000200 [ 78.670814][ T363] FS: 00007f66a8f09c40(0000) GS:ffff888163428000(0000) knlGS:0000000000000000 [ 78.671110][ T363] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 78.671324][ T363] CR2: 000055db4c6a30a8 CR3: 000000010da67000 CR4: 0000000000750ef0 [ 78.671585][ T363] PKRU: 55555554 [ 78.671713][ T363] Call Trace: [ 78.671843][ T363] <TASK> [ 78.671936][ T363] ? __pfx_qfq_dequeue+0x10/0x10 [sch_qfq] [ 78.672148][ T363] ? __pfx__printk+0x10/0x10 [ 78.672322][ T363] ? srso_alias_return_thunk+0x5/0xfbef5 [ 78.672496][ T363] ? lockdep_hardirqs_on_prepare+0xa8/0x1a0 [ 78.672706][ T363] ? srso_alias_return_thunk+0x5/0xfbef5 [ 78.672875][ T363] ? trace_hardirqs_on+0x19/0x1a0 [ 78.673047][ T363] red_dequeue+0x65/0x270 [sch_red] [ 78.673217][ T363] ? srso_alias_return_thunk+0x5/0xfbef5 [ 78.673385][ T363] tbf_dequeue.cold+0xb0/0x70c [sch_tbf] [ 78.673566][ T363] __qdisc_run+0x169/0x1900 The right thing to do in #1b is to grab the skb off gso_skb queue. This patchset fixes that issue by changing #1b to use qdisc_dequeue_peeked() method instead.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free dlfb_ops_mmap() uses remap_pfn_range() to map vmalloc framebuffer pages to userspace but sets no vm_ops on the VMA. This means the kernel cannot track active mmaps. When dlfb_realloc_framebuffer() replaces the backing buffer via FBIOPUT_VSCREENINFO, existing mmap PTEs are not invalidated. On USB disconnect, dlfb_ops_destroy() calls vfree() on the old pages while userspace PTEs still reference them, resulting in a use-after-free: the process retains read/write access to freed kernel pages. Add vm_operations_struct with open/close callbacks that maintain an atomic mmap_count on struct dlfb_data. In dlfb_realloc_framebuffer(), check mmap_count and return -EBUSY if the buffer is currently mapped, preventing buffer replacement while userspace holds stale PTEs. Tested with PoC using dummy_hcd + raw_gadget USB device emulation.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() Add the same NULL guard already present in l2cap_sock_resume_cb() and l2cap_sock_ready_cb().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() Add the same NULL guard already present in l2cap_sock_resume_cb() and l2cap_sock_ready_cb().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() CO-RE accessor strings are colon-separated indices that describe a path from a root BTF type to a target field, e.g. "0:1:2" walks through nested struct members. bpf_core_parse_spec() parses each component with sscanf("%d"), so negative values like -1 are silently accepted. The subsequent bounds checks (access_idx >= btf_vlen(t)) only guard the upper bound and always pass for negative values because C integer promotion converts the __u16 btf_vlen result to int, making the comparison (int)(-1) >= (int)(N) false for any positive N. When -1 reaches btf_member_bit_offset() it gets cast to u32 0xffffffff, producing an out-of-bounds read far past the members array. A crafted BPF program with a negative CO-RE accessor on any struct that exists in vmlinux BTF (e.g. task_struct) crashes the kernel deterministically during BPF_PROG_LOAD on any system with CONFIG_DEBUG_INFO_BTF=y (default on major distributions). The bug is reachable with CAP_BPF: BUG: unable to handle page fault for address: ffffed11818b6626 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page Oops: Oops: 0000 [#1] SMP KASAN NOPTI CPU: 0 UID: 0 PID: 85 Comm: poc Not tainted 7.0.0-rc6 #18 PREEMPT(full) RIP: 0010:bpf_core_parse_spec (tools/lib/bpf/relo_core.c:354) RAX: 00000000ffffffff Call Trace: <TASK> bpf_core_calc_relo_insn (tools/lib/bpf/relo_core.c:1321) bpf_core_apply (kernel/bpf/btf.c:9507) check_core_relo (kernel/bpf/verifier.c:19475) bpf_check (kernel/bpf/verifier.c:26031) bpf_prog_load (kernel/bpf/syscall.c:3089) __sys_bpf (kernel/bpf/syscall.c:6228) </TASK> CO-RE accessor indices are inherently non-negative (struct member index, array element index, or enumerator index), so reject them immediately after parsing.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: efi: Fix reservation of unaccepted memory table The reserve_unaccepted() function incorrectly calculates the size of the memblock reservation for the unaccepted memory table. It aligns the size of the table, but fails to account for cases where the table's starting physical address (efi.unaccepted) is not page-aligned. If the table starts at an offset within a page and its end crosses into a subsequent page that the aligned size does not cover, the end of the table will not be reserved. This can lead to the table being overwritten or inaccessible, causing a kernel panic in accept_memory(). This issue was observed when starting Intel TDX VMs with specific memory sizes (e.g., > 64GB). Fix this by calculating the end address first (including the unaligned start) and then aligning it up, ensuring the entire range is covered by the reservation.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Use kvfree instead of kfree in amdgpu_gmc_get_nps_memranges() amdgpu_discovery_get_nps_info() internally allocates memory for ranges using kvcalloc(), which may use vmalloc() for large allocation. Using kfree() to release vmalloc memory will lead to a memory corruption. Use kvfree() to safely handle both kmalloc and vmalloc allocations. Compile tested only. Issue found using a prototype static analysis tool and code review.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: scsi: csiostor: Fix dereference of null pointer rn The error exit path when rn is NULL ends up deferencing the null pointer rn via the use of the macro CSIO_INC_STATS. Fix this by adding a new error return path label after the use of the macro to avoid the deference.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1 When allocating initialized blocks from a large unwritten extent, or when splitting an unwritten extent during end I/O and converting it to initialized, there is currently a potential issue of stale data if the extent needs to be split in the middle. 0 A B N [UUUUUUUUUUUU] U: unwritten extent [--DDDDDDDD--] D: valid data |<- ->| ----> this range needs to be initialized ext4_split_extent() first try to split this extent at B with EXT4_EXT_DATA_ENTIRE_VALID1 and EXT4_EXT_MAY_ZEROOUT flag set, but ext4_split_extent_at() failed to split this extent due to temporary lack of space. It zeroout B to N and mark the entire extent from 0 to N as written. 0 A B N [WWWWWWWWWWWW] W: written extent [SSDDDDDDDDZZ] Z: zeroed, S: stale data ext4_split_extent() then try to split this extent at A with EXT4_EXT_DATA_VALID2 flag set. This time, it split successfully and left a stale written extent from 0 to A. 0 A B N [WW|WWWWWWWWWW] [SS|DDDDDDDDZZ] Fix this by pass EXT4_EXT_DATA_PARTIAL_VALID1 to ext4_split_extent_at() when splitting at B, don't convert the entire extent to written and left it as unwritten after zeroing out B to N. The remaining work is just like the standard two-part split. ext4_split_extent() will pass the EXT4_EXT_DATA_VALID2 flag when it calls ext4_split_extent_at() for the second time, allowing it to properly handle the split. If the split is successful, it will keep extent from 0 to A as unwritten.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: power: supply: act8945a: Fix use-after-free in power_supply_changed() Using the `devm_` variant for requesting IRQ _before_ the `devm_` variant for allocating/registering the `power_supply` handle, means that the `power_supply` handle will be deallocated/unregistered _before_ the interrupt handler (since `devm_` naturally deallocates in reverse allocation order). This means that during removal, there is a race condition where an interrupt can fire just _after_ the `power_supply` handle has been freed, *but* just _before_ the corresponding unregistration of the IRQ handler has run. This will lead to the IRQ handler calling `power_supply_changed()` with a freed `power_supply` handle. Which usually crashes the system or otherwise silently corrupts the memory... Note that there is a similar situation which can also happen during `probe()`; the possibility of an interrupt firing _before_ registering the `power_supply` handle. This would then lead to the nasty situation of using the `power_supply` handle *uninitialized* in `power_supply_changed()`. Fix this racy use-after-free by making sure the IRQ is requested _after_ the registration of the `power_supply` handle.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: pinctrl: single: fix refcount leak in pcs_add_gpio_func() of_parse_phandle_with_args() returns a device_node pointer with refcount incremented in gpiospec.np. The loop iterates through all phandles but never releases the reference, causing a refcount leak on each iteration. Add of_node_put() calls to release the reference after extracting the needed arguments and on the error path when devm_kzalloc() fails. This bug was detected by our static analysis tool and verified by my code review.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: power: supply: wm97xx: Fix NULL pointer dereference in power_supply_changed() In `probe()`, `request_irq()` is called before allocating/registering a `power_supply` handle. If an interrupt is fired between the call to `request_irq()` and `power_supply_register()`, the `power_supply` handle will be used uninitialized in `power_supply_changed()` in `wm97xx_bat_update()` (triggered from the interrupt handler). This will lead to a `NULL` pointer dereference since Fix this racy `NULL` pointer dereference by making sure the IRQ is requested _after_ the registration of the `power_supply` handle. Since the IRQ is the last thing requests in the `probe()` now, remove the error path for freeing it. Instead add one for unregistering the `power_supply` handle when IRQ request fails.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: tpm: st33zp24: Fix missing cleanup on get_burstcount() error get_burstcount() can return -EBUSY on timeout. When this happens, st33zp24_send() returns directly without releasing the locality acquired earlier. Use goto out_err to ensure proper cleanup when get_burstcount() fails.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: mfd: arizona: Fix regulator resource leak on wm5102_clear_write_sequencer() failure The wm5102_clear_write_sequencer() helper may return an error and just return, bypassing the cleanup sequence and causing regulators to remain enabled, leading to a resource leak. Change the direct return to jump to the err_reset label to properly free the resources.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients During a warm reset flow, the cl->device pointer may be NULL if the reset occurs while clients are still being enumerated. Accessing cl->device->reference_count without a NULL check leads to a kernel panic. This issue was identified during multi-unit warm reboot stress clycles. Add a defensive NULL check for cl->device to ensure stability under such intensive testing conditions. KASAN: null-ptr-deref in range [0000000000000000-0000000000000007] Workqueue: ish_fw_update_wq fw_reset_work_fn Call Trace: ishtp_bus_remove_all_clients+0xbe/0x130 [intel_ishtp] ishtp_reset_handler+0x85/0x1a0 [intel_ishtp] fw_reset_work_fn+0x8a/0xc0 [intel_ish_ipc]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: power: supply: bq25980: Fix use-after-free in power_supply_changed() Using the `devm_` variant for requesting IRQ _before_ the `devm_` variant for allocating/registering the `power_supply` handle, means that the `power_supply` handle will be deallocated/unregistered _before_ the interrupt handler (since `devm_` naturally deallocates in reverse allocation order). This means that during removal, there is a race condition where an interrupt can fire just _after_ the `power_supply` handle has been freed, *but* just _before_ the corresponding unregistration of the IRQ handler has run. This will lead to the IRQ handler calling `power_supply_changed()` with a freed `power_supply` handle. Which usually crashes the system or otherwise silently corrupts the memory... Note that there is a similar situation which can also happen during `probe()`; the possibility of an interrupt firing _before_ registering the `power_supply` handle. This would then lead to the nasty situation of using the `power_supply` handle *uninitialized* in `power_supply_changed()`. Fix this racy use-after-free by making sure the IRQ is requested _after_ the registration of the `power_supply` handle.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: PCI/P2PDMA: Release per-CPU pgmap ref when vm_insert_page() fails When vm_insert_page() fails in p2pmem_alloc_mmap(), p2pmem_alloc_mmap() doesn't invoke percpu_ref_put() to free the per-CPU ref of pgmap acquired after gen_pool_alloc_owner(), and memunmap_pages() will hang forever when trying to remove the PCI device. Fix it by adding the missed percpu_ref_put().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: soc: mediatek: svs: Fix memory leak in svs_enable_debug_write() In svs_enable_debug_write(), the buf allocated by memdup_user_nul() is leaked if kstrtoint() fails. Fix this by using __free(kfree) to automatically free buf, eliminating the need for explicit kfree() calls and preventing leaks. [Angelo: Added missing cleanup.h inclusion]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iio: sca3000: Fix a resource leak in sca3000_probe() spi->irq from request_threaded_irq() not released when iio_device_register() fails. Add an return value check and jump to a common error handler when iio_device_register() fails.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: power: supply: cpcap-battery: Fix use-after-free in power_supply_changed() Using the `devm_` variant for requesting IRQ _before_ the `devm_` variant for allocating/registering the `power_supply` handle, means that the `power_supply` handle will be deallocated/unregistered _before_ the interrupt handler (since `devm_` naturally deallocates in reverse allocation order). This means that during removal, there is a race condition where an interrupt can fire just _after_ the `power_supply` handle has been freed, *but* just _before_ the corresponding unregistration of the IRQ handler has run. This will lead to the IRQ handler calling `power_supply_changed()` with a freed `power_supply` handle. Which usually crashes the system or otherwise silently corrupts the memory... Note that there is a similar situation which can also happen during `probe()`; the possibility of an interrupt firing _before_ registering the `power_supply` handle. This would then lead to the nasty situation of using the `power_supply` handle *uninitialized* in `power_supply_changed()`. Fix this racy use-after-free by making sure the IRQ is requested _after_ the registration of the `power_supply` handle.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ext4: drop extent cache when splitting extent fails When the split extent fails, we might leave some extents still being processed and return an error directly, which will result in stale extent entries remaining in the extent status tree. So drop all of the remaining potentially stale extents if the splitting fails.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: power: supply: bq256xx: Fix use-after-free in power_supply_changed() Using the `devm_` variant for requesting IRQ _before_ the `devm_` variant for allocating/registering the `power_supply` handle, means that the `power_supply` handle will be deallocated/unregistered _before_ the interrupt handler (since `devm_` naturally deallocates in reverse allocation order). This means that during removal, there is a race condition where an interrupt can fire just _after_ the `power_supply` handle has been freed, *but* just _before_ the corresponding unregistration of the IRQ handler has run. This will lead to the IRQ handler calling `power_supply_changed()` with a freed `power_supply` handle. Which usually crashes the system or otherwise silently corrupts the memory... Note that there is a similar situation which can also happen during `probe()`; the possibility of an interrupt firing _before_ registering the `power_supply` handle. This would then lead to the nasty situation of using the `power_supply` handle *uninitialized* in `power_supply_changed()`. Fix this racy use-after-free by making sure the IRQ is requested _after_ the registration of the `power_supply` handle.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: fix role switching during resume If the role change while we are suspended, the cdns3 driver switches to the new mode during resume. However, switching to host mode in this context causes a NULL pointer dereference. The host role's start() operation registers a xhci-hcd device, but its probe is deferred while we are in the resume path. The host role's resume() operation assumes the xhci-hcd device is already probed, which is not the case, leading to the dereference. Since the start() operation of the new role is already called, the resume operation can be skipped. So skip the resume operation for the new role if a role switch occurs during resume. Once the resume sequence is complete, the xhci-hcd device can be probed in case of host mode. Unable to handle kernel NULL pointer dereference at virtual address 0000000000000208 Mem abort info: ... Data abort info: ... [0000000000000208] pgd=0000000000000000, p4d=0000000000000000 Internal error: Oops: 0000000096000004 [#1] SMP Modules linked in: CPU: 0 UID: 0 PID: 146 Comm: sh Not tainted 6.19.0-rc7-00013-g6e64f4aabfae-dirty #135 PREEMPT Hardware name: Texas Instruments J7200 EVM (DT) pstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : usb_hcd_is_primary_hcd+0x0/0x1c lr : cdns_host_resume+0x24/0x5c ... Call trace: usb_hcd_is_primary_hcd+0x0/0x1c (P) cdns_resume+0x6c/0xbc cdns3_controller_resume.isra.0+0xe8/0x17c cdns3_plat_resume+0x18/0x24 platform_pm_resume+0x2c/0x68 dpm_run_callback+0x90/0x248 device_resume+0x100/0x24c dpm_resume+0x190/0x2ec dpm_resume_end+0x18/0x34 suspend_devices_and_enter+0x2b0/0xa44 pm_suspend+0x16c/0x5fc state_store+0x80/0xec kobj_attr_store+0x18/0x2c sysfs_kf_write+0x7c/0x94 kernfs_fop_write_iter+0x130/0x1dc vfs_write+0x240/0x370 ksys_write+0x70/0x108 __arm64_sys_write+0x1c/0x28 invoke_syscall+0x48/0x10c el0_svc_common.constprop.0+0x40/0xe0 do_el0_svc+0x1c/0x28 el0_svc+0x34/0x108 el0t_64_sync_handler+0xa0/0xe4 el0t_64_sync+0x198/0x19c Code: 52800003 f9407ca5 d63f00a0 17ffffe4 (f9410401) ---[ end trace 0000000000000000 ]---


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Revert "hwmon: (ibmpex) fix use-after-free in high/low store" This reverts commit 6946c726c3f4c36f0f049e6f97e88c510b15f65d. Jean Delvare points out that the patch does not completely fix the reported problem, that it in fact introduces a (new) race condition, and that it may actually not be needed in the first place. Various AI reviews agree. Specific and relevant AI feedback: " This reordering sets the driver data to NULL before removing the sensor attributes in the loop below. ibmpex_show_sensor() retrieves this driver data via dev_get_drvdata() but does not check if it is NULL before dereferencing it to access data->sensors[]. If a userspace process reads a sensor file (like temp1_input) while this delete function is running, could it race with the dev_set_drvdata(..., NULL) call here and crash in ibmpex_show_sensor()? Would it be safer to keep the original order where device_remove_file() is called before clearing the driver data? device_remove_file() should wait for any active sysfs callbacks to complete, which might already prevent the use-after-free this patch intends to fix. " Revert the offending patch. If it can be shown that the originally reported alleged race condition does indeed exist, it can always be re-introduced with a complete fix.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: power: supply: sbs-battery: Fix use-after-free in power_supply_changed() Using the `devm_` variant for requesting IRQ _before_ the `devm_` variant for allocating/registering the `power_supply` handle, means that the `power_supply` handle will be deallocated/unregistered _before_ the interrupt handler (since `devm_` naturally deallocates in reverse allocation order). This means that during removal, there is a race condition where an interrupt can fire just _after_ the `power_supply` handle has been freed, *but* just _before_ the corresponding unregistration of the IRQ handler has run. This will lead to the IRQ handler calling `power_supply_changed()` with a freed `power_supply` handle. Which usually crashes the system or otherwise silently corrupts the memory... Note that there is a similar situation which can also happen during `probe()`; the possibility of an interrupt firing _before_ registering the `power_supply` handle. This would then lead to the nasty situation of using the `power_supply` handle *uninitialized* in `power_supply_changed()`. Fix this racy use-after-free by making sure the IRQ is requested _after_ the registration of the `power_supply` handle. Keep the old behavior of just printing a warning in case of any failures during the IRQ request and finishing the probe successfully.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: sched/rt: Skip currently executing CPU in rto_next_cpu() CPU0 becomes overloaded when hosting a CPU-bound RT task, a non-CPU-bound RT task, and a CFS task stuck in kernel space. When other CPUs switch from RT to non-RT tasks, RT load balancing (LB) is triggered; with HAVE_RT_PUSH_IPI enabled, they send IPIs to CPU0 to drive the execution of rto_push_irq_work_func. During push_rt_task on CPU0, if next_task->prio < rq->donor->prio, resched_curr() sets NEED_RESCHED and after the push operation completes, CPU0 calls rto_next_cpu(). Since only CPU0 is overloaded in this scenario, rto_next_cpu() should ideally return -1 (no further IPI needed). However, multiple CPUs invoking tell_cpu_to_push() during LB increments rd->rto_loop_next. Even when rd->rto_cpu is set to -1, the mismatch between rd->rto_loop and rd->rto_loop_next forces rto_next_cpu() to restart its search from -1. With CPU0 remaining overloaded (satisfying rt_nr_migratory && rt_nr_total > 1), it gets reselected, causing CPU0 to queue irq_work to itself and send self-IPIs repeatedly. As long as CPU0 stays overloaded and other CPUs run pull_rt_tasks(), it falls into an infinite self-IPI loop, which triggers a CPU hardlockup due to continuous self-interrupts. The trigging scenario is as follows: cpu0 cpu1 cpu2 pull_rt_task tell_cpu_to_push <------------irq_work_queue_on rto_push_irq_work_func push_rt_task resched_curr(rq) pull_rt_task rto_next_cpu tell_cpu_to_push <-------------------------- atomic_inc(rto_loop_next) rd->rto_loop != next rto_next_cpu irq_work_queue_on rto_push_irq_work_func Fix redundant self-IPI by filtering the initiating CPU in rto_next_cpu(). This solution has been verified to effectively eliminate spurious self-IPIs and prevent CPU hardlockup scenarios.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ext4: fix dirtyclusters double decrement on fs shutdown fstests test generic/388 occasionally reproduces a warning in ext4_put_super() associated with the dirty clusters count: WARNING: CPU: 7 PID: 76064 at fs/ext4/super.c:1324 ext4_put_super+0x48c/0x590 [ext4] Tracing the failure shows that the warning fires due to an s_dirtyclusters_counter value of -1. IOW, this appears to be a spurious decrement as opposed to some sort of leak. Further tracing of the dirty cluster count deltas and an LLM scan of the resulting output identified the cause as a double decrement in the error path between ext4_mb_mark_diskspace_used() and the caller ext4_mb_new_blocks(). First, note that generic/388 is a shutdown vs. fsstress test and so produces a random set of operations and shutdown injections. In the problematic case, the shutdown triggers an error return from the ext4_handle_dirty_metadata() call(s) made from ext4_mb_mark_context(). The changed value is non-zero at this point, so ext4_mb_mark_diskspace_used() does not exit after the error bubbles up from ext4_mb_mark_context(). Instead, the former decrements both cluster counters and returns the error up to ext4_mb_new_blocks(). The latter falls into the !ar->len out path which decrements the dirty clusters counter a second time, creating the inconsistency. To avoid this problem and simplify ownership of the cluster reservation in this codepath, lift the counter reduction to a single place in the caller. This makes it more clear that ext4_mb_new_blocks() is responsible for acquiring cluster reservation (via ext4_claim_free_clusters()) in the !delalloc case as well as releasing it, regardless of whether it ends up consumed or returned due to failure.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: mtd: parsers: Fix memory leak in mtd_parser_tplink_safeloader_parse() The function mtd_parser_tplink_safeloader_parse() allocates buf via mtd_parser_tplink_safeloader_read_table(). If the allocation for parts[idx].name fails inside the loop, the code jumps to the err_free label without freeing buf, leading to a memory leak. Fix this by freeing the temporary buffer buf in the err_free label. Compile tested only. Issue found using a prototype static analysis tool and code review.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix memory leak in GET_DATA_DIRECT_SYSFS_PATH handler The UVERBS_HANDLER(MLX5_IB_METHOD_GET_DATA_DIRECT_SYSFS_PATH) function allocates memory for the device path using kobject_get_path(). If the length of the device path exceeds the output buffer length, the function returns -ENOSPC but does not free the allocated memory, resulting in a memory leak. Add a kfree() call to the error path to ensure the allocated memory is properly freed. Compile tested only. Issue found using a prototype static analysis tool and code review.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: usb: catc: enable basic endpoint checking catc_probe() fills three URBs with hardcoded endpoint pipes without verifying the endpoint descriptors: - usb_sndbulkpipe(usbdev, 1) and usb_rcvbulkpipe(usbdev, 1) for TX/RX - usb_rcvintpipe(usbdev, 2) for interrupt status A malformed USB device can present these endpoints with transfer types that differ from what the driver assumes. Add a catc_usb_ep enum for endpoint numbers, replacing magic constants throughout. Add usb_check_bulk_endpoints() and usb_check_int_endpoints() calls after usb_set_interface() to verify endpoint types before use, rejecting devices with mismatched descriptors at probe time. Similar to - commit 90b7f2961798 ("net: usb: rtl8150: enable basic endpoint checking") which fixed the issue in rtl8150.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Fix memory leak on codec_info allocation failure In wave5_vpu_open_enc() and wave5_vpu_open_dec(), a vpu instance is allocated via kzalloc(). If the subsequent allocation for inst->codec_info fails, the functions return -ENOMEM without freeing the previously allocated instance, causing a memory leak. Fix this by calling kfree() on the instance in this error path to ensure it is properly released.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: power: supply: goldfish: Fix use-after-free in power_supply_changed() Using the `devm_` variant for requesting IRQ _before_ the `devm_` variant for allocating/registering the `power_supply` handle, means that the `power_supply` handle will be deallocated/unregistered _before_ the interrupt handler (since `devm_` naturally deallocates in reverse allocation order). This means that during removal, there is a race condition where an interrupt can fire just _after_ the `power_supply` handle has been freed, *but* just _before_ the corresponding unregistration of the IRQ handler has run. This will lead to the IRQ handler calling `power_supply_changed()` with a freed `power_supply` handle. Which usually crashes the system or otherwise silently corrupts the memory... Note that there is a similar situation which can also happen during `probe()`; the possibility of an interrupt firing _before_ registering the `power_supply` handle. This would then lead to the nasty situation of using the `power_supply` handle *uninitialized* in `power_supply_changed()`. Fix this racy use-after-free by making sure the IRQ is requested _after_ the registration of the `power_supply` handle.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure get_burstcount() can return -EBUSY on timeout. When this happens, the function returns directly without releasing the locality that was acquired at the beginning of tpm_tis_i2c_send(). Use goto out_err to ensure proper cleanup when get_burstcount() fails.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: power: supply: ab8500: Fix use-after-free in power_supply_changed() Using the `devm_` variant for requesting IRQ _before_ the `devm_` variant for allocating/registering the `power_supply` handle, means that the `power_supply` handle will be deallocated/unregistered _before_ the interrupt handler (since `devm_` naturally deallocates in reverse allocation order). This means that during removal, there is a race condition where an interrupt can fire just _after_ the `power_supply` handle has been freed, *but* just _before_ the corresponding unregistration of the IRQ handler has run. This will lead to the IRQ handler calling `power_supply_changed()` with a freed `power_supply` handle. Which usually crashes the system or otherwise silently corrupts the memory... Note that there is a similar situation which can also happen during `probe()`; the possibility of an interrupt firing _before_ registering the `power_supply` handle. This would then lead to the nasty situation of using the `power_supply` handle *uninitialized* in `power_supply_changed()`. Commit 1c1f13a006ed ("power: supply: ab8500: Move to componentized binding") introduced this issue during a refactorization. Fix this racy use-after-free by making sure the IRQ is requested _after_ the registration of the `power_supply` handle.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix memory leak in amdgpu_acpi_enumerate_xcc() In amdgpu_acpi_enumerate_xcc(), if amdgpu_acpi_dev_init() returns -ENOMEM, the function returns directly without releasing the allocated xcc_info, resulting in a memory leak. Fix this by ensuring that xcc_info is properly freed in the error paths. Compile tested only. Issue found using a prototype static analysis tool and code review.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fbdev: au1200fb: Fix a memory leak in au1200fb_drv_probe() In au1200fb_drv_probe(), when platform_get_irq fails(), it directly returns from the function with an error code, which causes a memory leak. Replace it with a goto label to ensure proper cleanup.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/exynos: vidi: fix to avoid directly dereferencing user pointer In vidi_connection_ioctl(), vidi->edid(user pointer) is directly dereferenced in the kernel. This allows arbitrary kernel memory access from the user space, so instead of directly accessing the user pointer in the kernel, we should modify it to copy edid to kernel memory using copy_from_user() and use it.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ASoC: nau8821: Cancel delayed work on component remove Attempting to unload the driver while a jack detection work is pending would likely crash the kernel when it is eventually scheduled for execution: [ 1984.896308] BUG: unable to handle page fault for address: ffffffffc10c2a20 [...] [ 1984.896388] Hardware name: Valve Jupiter/Jupiter, BIOS F7A0131 01/30/2024 [ 1984.896396] Workqueue: events nau8821_jdet_work [snd_soc_nau8821] [ 1984.896414] RIP: 0010:__mutex_lock+0x9f/0x11d0 [...] [ 1984.896504] Call Trace: [ 1984.896511] <TASK> [ 1984.896524] ? snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core] [ 1984.896572] ? snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core] [ 1984.896596] snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core] [ 1984.896622] nau8821_jdet_work+0xeb/0x1e0 [snd_soc_nau8821] [ 1984.896636] process_one_work+0x211/0x590 [ 1984.896649] ? srso_return_thunk+0x5/0x5f [ 1984.896670] worker_thread+0x1cd/0x3a0 Cancel unscheduled jdet_work or wait for its execution to finish before the component driver gets removed.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: playstation: Add missing check for input_ff_create_memless The ps_gamepad_create() function calls input_ff_create_memless() without verifying its return value, which can lead to incorrect behavior or potential crashes when FF effects are triggered. Add a check for the return value of input_ff_create_memless().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix memory leak in amdgpu_ras_init() When amdgpu_nbio_ras_sw_init() fails in amdgpu_ras_init(), the function returns directly without freeing the allocated con structure, leading to a memory leak. Fix this by jumping to the release_con label to properly clean up the allocated memory before returning the error code. Compile tested only. Issue found using a prototype static analysis tool and code review.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: s390/cio: Fix device lifecycle handling in css_alloc_subchannel() `css_alloc_subchannel()` calls `device_initialize()` before setting up the DMA masks. If `dma_set_coherent_mask()` or `dma_set_mask()` fails, the error path frees the subchannel structure directly, bypassing the device model reference counting. Once `device_initialize()` has been called, the embedded struct device must be released via `put_device()`, allowing the release callback to free the container structure. Fix the error path by dropping the initial device reference with `put_device()` instead of calling `kfree()` directly. This ensures correct device lifetime handling and avoids potential use-after-free or double-free issues.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ACPICA: Fix NULL pointer dereference in acpi_ev_address_space_dispatch() Cover a missed execution path with a new check.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: ccree - fix a memory leak in cc_mac_digest() Add cc_unmap_result() if cc_map_hash_request_final() fails to prevent potential memory leak.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 After VMRUN in guest mode, nested_sync_control_from_vmcb02() syncs fields written by the CPU from vmcb02 to the cached vmcb12. This is because the cached vmcb12 is used as the authoritative copy of some of the controls, and is the payload when saving/restoring nested state. int_state is also written by the CPU, specifically bit 0 (i.e. SVM_INTERRUPT_SHADOW_MASK) for nested VMs, but it is not sync'd to cached vmcb12. This does not cause a problem if KVM_SET_NESTED_STATE preceeds KVM_SET_VCPU_EVENTS in the restore path, as an interrupt shadow would be correctly restored to vmcb02 (KVM_SET_VCPU_EVENTS overwrites what KVM_SET_NESTED_STATE restored in int_state). However, if KVM_SET_VCPU_EVENTS preceeds KVM_SET_NESTED_STATE, an interrupt shadow would be restored into vmcb01 instead of vmcb02. This would mostly be benign for L1 (delays an interrupt), but not for L2. For L2, the vCPU could hang (e.g. if a wakeup interrupt is delivered before a HLT that should have been in an interrupt shadow). Sync int_state to the cached vmcb12 in nested_sync_control_from_vmcb02() to avoid this problem. With that, KVM_SET_NESTED_STATE restores the correct interrupt shadow state, and if KVM_SET_VCPU_EVENTS follows it would overwrite it with the same value.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ibmasm: fix OOB reads in command_file_write due to missing size checks The command_file_write() handler allocates a kernel buffer of exactly count bytes and copies user data into it, but does not validate the buffer against the dot command protocol before passing it to get_dot_command_size() and get_dot_command_timeout(). Since both the allocation size (count) and the header fields (command_size, data_size) are independently user-controlled, an attacker can cause get_dot_command_size() to return a value exceeding the allocation, triggering OOB reads in get_dot_command_timeout() and an out-of-bounds memcpy_toio() that leaks kernel heap memory to the service processor. Fix with two guards: reject writes smaller than sizeof(struct dot_command_header) before allocation, then after copying user data reject commands where the buffer is smaller than the total size declared by the header (sizeof(header) + command_size + data_size). This ensures all subsequent header and payload field accesses stay within the buffer.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: spi: imx: fix use-after-free on unbind The SPI subsystem frees the controller and any subsystem allocated driver data as part of deregistration (unless the allocation is device managed). Take another reference before deregistering the controller so that the driver data is not freed until the driver is done with it.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails If device_add(&sdkp->disk_dev) fails, put_device() runs scsi_disk_release(), which frees the scsi_disk but leaves the gendisk referenced. The device_add_disk() error path in sd_probe() calls put_disk(gd); call put_disk(gd) here to mirror that cleanup.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix u32 overflow in pushbuf reloc bounds check nouveau_gem_pushbuf_reloc_apply() validates each relocation with if (r->reloc_bo_offset + 4 > nvbo->bo.base.size) but reloc_bo_offset is __u32 (uapi/drm/nouveau_drm.h) and the integer literal 4 promotes to unsigned int, so the addition is performed in 32 bits and wraps before the comparison against the size_t bo size. Cast to u64 so the addition happens in 64-bit arithmetic. [ Add Fixes: tag. - Danilo ]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown epf_ntb_epc_destroy() duplicates the teardown that the caller is supposed to do later. This leads to an oops when .allow_link fails or when .drop_link is performed. Remove the helper. Also drop pci_epc_put(). EPC device refcounting is tied to configfs EPC group lifetime, and pci_epc_put() in the .drop_link path is sufficient.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: mtk-jpeg: fix use-after-free in release path due to uncancelled work The mtk_jpeg_release() function frees the context structure (ctx) without first cancelling any pending or running work in ctx->jpeg_work. This creates a race window where the workqueue callback may still be accessing the context memory after it has been freed. Race condition: CPU 0 (release) CPU 1 (workqueue) ---------------- ------------------ close() mtk_jpeg_release() mtk_jpegenc_worker() ctx = work->data // accessing ctx kfree(ctx) // freed! access ctx // UAF! The work is queued via queue_work() during JPEG encode/decode operations (via mtk_jpeg_device_run). If the device is closed while work is pending or running, the work handler will access freed memory. Fix this by calling cancel_work_sync() BEFORE acquiring the mutex. This ordering is critical: if cancel_work_sync() is called after mutex_lock(), and the work handler also tries to acquire the same mutex, it would cause a deadlock. Note: The open error path does NOT need cancel_work_sync() because INIT_WORK() only initializes the work structure - it does not schedule it. Work is only scheduled later during ioctl operations.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: remoteproc: xlnx: Only access buffer information if IPI is buffered In the receive callback check if message is NULL to prevent possibility of crash by NULL pointer dereferencing.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES parse_uac2_sample_rate_range() caps the number of enumerated rates at MAX_NR_RATES, but it only breaks out of the current rate loop. A malformed UAC2 RANGE response with additional triplets continues parsing the remaining triplets and repeatedly prints "invalid uac2 rates" while probe still holds register_mutex. Stop the whole parse once the cap is reached and return the number of rates collected so far.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup atmel_aes_buff_init() allocates 4 pages using __get_free_pages() with ATMEL_AES_BUFFER_ORDER, but atmel_aes_buff_cleanup() frees only the first page using free_page(), leaking the remaining 3 pages. Use free_pages() with ATMEL_AES_BUFFER_ORDER to fix the memory leak.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: dm mirror: fix integer overflow in create_dirty_log() The argument count calculation in create_dirty_log() performs `*args_used = 2 + param_count` before validating against argc. When a user provides a param_count close to UINT_MAX via the device mapper table string, this unsigned addition wraps around to a small value, causing the subsequent `argc < *args_used` check to be bypassed. The overflowed param_count is then passed as argc to dm_dirty_log_create(), where it can cause out-of-bounds reads on the argv array. Fix by comparing param_count against argc - 2 before performing the addition, following the same pattern used by parse_features() in the same file. Since argc >= 2 is already guaranteed, the subtraction is safe.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/smc: avoid early lgr access in smc_clc_wait_msg A CLC decline can be received while the handshake is still in an early stage, before the connection has been associated with a link group. The decline handling in smc_clc_wait_msg() updates link-group level sync state for first-contact declines, but that state only exists after link group setup has completed. Guard the link-group update accordingly and keep the per-socket peer diagnosis handling unchanged. This preserves the existing sync_err handling for established link-group contexts and avoids touching link-group state before it is available.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject short ahash digests during instance creation authencesn requires either a zero authsize or an authsize of at least 4 bytes because the ESN encrypt/decrypt paths always move 4 bytes of high-order sequence number data at the end of the authenticated data. While crypto_authenc_esn_setauthsize() already rejects explicit non-zero authsizes in the range 1..3, crypto_authenc_esn_create() still copied auth->digestsize into inst->alg.maxauthsize without validating it. The AEAD core then initialized the tfm's default authsize from that value. As a result, selecting an ahash with digest size 1..3, such as cbcmac(cipher_null), exposed authencesn instances whose default authsize was invalid even though setauthsize() would have rejected the same value. AF_ALG could then trigger the ESN tail handling with a too-short tag and hit an out-of-bounds access. Reject authencesn instances whose ahash digest size is in the invalid non-zero range 1..3 so that no tfm can inherit an unsupported default authsize.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails When fsnotify_add_inode_mark_locked() fails in inotify_new_watch(), the error path calls inotify_remove_from_idr() but does not call dec_inotify_watches() to undo the preceding inc_inotify_watches(). This leaks a watch count, and repeated failures can exhaust the max_user_watches limit with -ENOSPC even when no watches are active. Prior to commit 1cce1eea0aff ("inotify: Convert to using per-namespace limits"), the watch count was incremented after fsnotify_add_mark_locked() succeeded, so this path was not affected. The conversion moved inc_inotify_watches() before the mark insertion without adding the corresponding rollback. Add the missing dec_inotify_watches() call in the error path.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() The commit c8e008b60492 ("ext4: ignore xattrs past end") introduced a refcount leak in when block_csum is false. ext4_xattr_inode_dec_ref_all() calls ext4_get_inode_loc() to get iloc.bh, but never releases it with brelse().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: caiaq: fix usb_dev refcount leak on probe failure create_card() takes a reference on the USB device with usb_get_dev() and stores the matching usb_put_dev() in card_free(), which is installed as the snd_card's ->private_free destructor. However, ->private_free is only assigned near the end of init_card(), after several failure points (usb_set_interface(), EP type checks, usb_submit_urb(), the EP1_CMD_GET_DEVICE_INFO exchange, and its timeout). When any of those fail, init_card() returns an error to snd_probe(), which calls snd_card_free(card). Because ->private_free is still NULL, card_free() never runs, the usb_get_dev() reference is not dropped, and the struct usb_device leaks along with its descriptor allocations and device_private. syzbot reproduces this with a malformed UAC3 device whose only valid altsetting is 0; init_card()'s usb_set_interface(usb_dev, 0, 1) call fails with -EIO and triggers the leak. Move the ->private_free assignment into create_card(), immediately after usb_get_dev(), so that every error path reaching snd_card_free() balances the reference. card_free()'s callees (snd_usb_caiaq_input_free, free_urbs, kfree) already tolerate the partially-initialized state because the chip private area is zero-initialized by snd_card_new().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: ctxfi: Add fallback to default RSR for S/PDIF spdif_passthru_playback_get_resources() uses atc->pll_rate as the RSR for the MSR calculation loop. However, pll_rate is only updated in atc_pll_init() and not in hw_pll_init(), so it remains 0 after the card init. When spdif_passthru_playback_setup() skips atc_pll_init() for 32000 Hz, (rsr * desc.msr) always becomes 0, causing the loop to spin indefinitely. Add fallback to use atc->rsr when atc->pll_rate is 0. This reflects the hardware state, since hw_card_init() already configures the PLL to the default RSR.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix deadlock with check operation and nowait requests When an array check is running it will raise the barrier at which point normal requests will become blocked and increment the nr_pending value to signal there is work pending inside of wait_barrier(). NOWAIT requests do not block and so will return immediately with an error, and additionally do not increment nr_pending in wait_barrier(). Upstream change commit 43806c3d5b9b ("raid10: cleanup memleak at raid10_make_request") added a call to raid_end_bio_io() to fix a memory leak when NOWAIT requests hit this condition. raid_end_bio_io() eventually calls allow_barrier() and it will unconditionally do an atomic_dec_and_test(&conf->nr_pending) even though the corresponding increment on nr_pending didn't happen in the NOWAIT case. This can be easily seen by starting a check operation while an application is doing nowait IO on the same array. This results in a deadlocked state due to nr_pending value underflowing and so the md resync thread gets stuck waiting for nr_pending to == 0. Output of r10conf state of the array when we hit this condition: crash> struct r10conf barrier = 1, nr_pending = { counter = -41 }, nr_waiting = 15, nr_queued = 0, Example of md_sync thread stuck waiting on raise_barrier() and other requests stuck in wait_barrier(): md1_resync [<0>] raise_barrier+0xce/0x1c0 [<0>] raid10_sync_request+0x1ca/0x1ed0 [<0>] md_do_sync+0x779/0x1110 [<0>] md_thread+0x90/0x160 [<0>] kthread+0xbe/0xf0 [<0>] ret_from_fork+0x34/0x50 [<0>] ret_from_fork_asm+0x1a/0x30 kworker/u1040:2+flush-253:4 [<0>] wait_barrier+0x1de/0x220 [<0>] regular_request_wait+0x30/0x180 [<0>] raid10_make_request+0x261/0x1000 [<0>] md_handle_request+0x13b/0x230 [<0>] __submit_bio+0x107/0x1f0 [<0>] submit_bio_noacct_nocheck+0x16f/0x390 [<0>] ext4_io_submit+0x24/0x40 [<0>] ext4_do_writepages+0x254/0xc80 [<0>] ext4_writepages+0x84/0x120 [<0>] do_writepages+0x7a/0x260 [<0>] __writeback_single_inode+0x3d/0x300 [<0>] writeback_sb_inodes+0x1dd/0x470 [<0>] __writeback_inodes_wb+0x4c/0xe0 [<0>] wb_writeback+0x18b/0x2d0 [<0>] wb_workfn+0x2a1/0x400 [<0>] process_one_work+0x149/0x330 [<0>] worker_thread+0x2d2/0x410 [<0>] kthread+0xbe/0xf0 [<0>] ret_from_fork+0x34/0x50 [<0>] ret_from_fork_asm+0x1a/0x30


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: md/raid5: fix soft lockup in retry_aligned_read() When retry_aligned_read() encounters an overlapped stripe, it releases the stripe via raid5_release_stripe() which puts it on the lockless released_stripes llist. In the next raid5d loop iteration, release_stripe_list() drains the stripe onto handle_list (since STRIPE_HANDLE is set by the original IO), but retry_aligned_read() runs before handle_active_stripes() and removes the stripe from handle_list via find_get_stripe() -> list_del_init(). This prevents handle_stripe() from ever processing the stripe to resolve the overlap, causing an infinite loop and soft lockup. Fix this by using __release_stripe() with temp_inactive_list instead of raid5_release_stripe() in the failure path, so the stripe does not go through the released_stripes llist. This allows raid5d to break out of its loop, and the overlap will be resolved when the stripe is eventually processed by handle_stripe().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ceph: only d_add() negative dentries when they are unhashed Ceph can call d_add(dentry, NULL) on a negative dentry that is already present in the primary dcache hash. In the current VFS that is not safe. d_add() goes through __d_add() to __d_rehash(), which unconditionally reinserts dentry->d_hash into the hlist_bl bucket. If the dentry is already hashed, reinserting the same node can corrupt the bucket, including creating a self-loop. Once that happens, __d_lookup() can spin forever in the hlist_bl walk, typically looping only on the d_name.hash mismatch check and eventually triggering RCU stall reports like this one: rcu: INFO: rcu_sched self-detected stall on CPU rcu: 87-....: (2100 ticks this GP) idle=3a4c/1/0x4000000000000000 softirq=25003319/25003319 fqs=829 rcu: (t=2101 jiffies g=79058445 q=698988 ncpus=192) CPU: 87 UID: 2952868916 PID: 3933303 Comm: php-cgi8.3 Not tainted 6.18.17-i1-amd #950 NONE Hardware name: Dell Inc. PowerEdge R7615/0G9DHV, BIOS 1.6.6 09/22/2023 RIP: 0010:__d_lookup+0x46/0xb0 Code: c1 e8 07 48 8d 04 c2 48 8b 00 49 89 fc 49 89 f5 48 89 c3 48 83 e3 fe 48 83 f8 01 77 0f eb 2d 0f 1f 44 00 00 48 8b 1b 48 85 db <74> 20 39 6b 18 75 f3 48 8d 7b 78 e8 ba 85 d0 00 4c 39 63 10 74 1f RSP: 0018:ff745a70c8253898 EFLAGS: 00000282 RAX: ff26e470054cb208 RBX: ff26e470054cb208 RCX: 000000006e958966 RDX: ff26e48267340000 RSI: ff745a70c82539b0 RDI: ff26e458f74655c0 RBP: 000000006e958966 R08: 0000000000000180 R09: 9cd08d909b919a89 R10: ff26e458f74655c0 R11: 0000000000000000 R12: ff26e458f74655c0 R13: ff745a70c82539b0 R14: d0d0d0d0d0d0d0d0 R15: 2f2f2f2f2f2f2f2f FS: 00007f5770896980(0000) GS:ff26e482c5d88000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f5764de50c0 CR3: 000000a72abb5001 CR4: 0000000000771ef0 PKRU: 55555554 Call Trace: <TASK> lookup_fast+0x9f/0x100 walk_component+0x1f/0x150 link_path_walk+0x20e/0x3d0 path_lookupat+0x68/0x180 filename_lookup+0xdc/0x1e0 vfs_statx+0x6c/0x140 vfs_fstatat+0x67/0xa0 __do_sys_newfstatat+0x24/0x60 do_syscall_64+0x6a/0x230 entry_SYSCALL_64_after_hwframe+0x76/0x7e This is reachable with reused cached negative dentries. A Ceph lookup or atomic_open can be handed a negative dentry that is already hashed, and fs/ceph/dir.c then hits one of two paths that incorrectly assume "negative" also means "unhashed": - ceph_finish_lookup(): MDS reply is -ENOENT with no trace -> d_add(dentry, NULL) - ceph_lookup(): local ENOENT fast path for a complete directory with shared caps -> d_add(dentry, NULL) Both paths can therefore re-add an already-hashed negative dentry. Ceph already uses the correct pattern elsewhere: ceph_fill_trace() only calls d_add(dn, NULL) for a negative null-dentry reply when d_unhashed(dn) is true. Fix both fs/ceph/dir.c sites the same way: only call d_add() for a negative dentry when it is actually unhashed. If the negative dentry is already hashed, leave it in place and reuse it as-is. This preserves the existing behavior for unhashed dentries while avoiding d_hash list corruption for reused hashed negatives.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers hci_conn lookup and field access must be covered by hdev lock in hci_user_passkey_notify_evt() and hci_keypress_notify_evt(), otherwise the connection can be freed concurrently. Extend the hci_dev_lock critical section to cover all conn usage in both handlers. Keep the existing keypress notification behavior unchanged by routing the early exits through a common unlock path.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: amphion: Fix race between m2m job_abort and device_run Fix kernel panic caused by race condition where v4l2_m2m_ctx_release() frees m2m_ctx while v4l2_m2m_try_run() is about to call device_run with the same context. Race sequence: v4l2_m2m_try_run(): v4l2_m2m_ctx_release(): lock/unlock v4l2_m2m_cancel_job() job_abort() v4l2_m2m_job_finish() kfree(m2m_ctx) <- frees ctx device_run() <- use-after-free crash at 0x538 Crash trace: Unable to handle kernel read from unreadable memory at virtual address 0000000000000538 v4l2_m2m_try_run+0x78/0x138 v4l2_m2m_device_run_work+0x14/0x20 The amphion vpu driver does not rely on the m2m framework's device_run callback to perform encode/decode operations. Fix the race by preventing m2m framework job scheduling entirely: - Add job_ready callback returning 0 (no jobs ready for m2m framework) - Remove job_abort callback to avoid the race condition


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN For guests with NRIPS disabled, L1 does not provide NextRIP when running an L2 with an injected soft interrupt, instead it advances the current RIP before running it. KVM uses the current RIP as the NextRIP in vmcb02 to emulate a CPU without NRIPS. However, after L2 runs the first time, NextRIP will be updated by the CPU and/or KVM, and the current RIP is no longer the correct value to use in vmcb02. Hence, after save/restore, use the current RIP if and only if a nested run is pending, otherwise use NextRIP. Give soft_int_next_rip the same treatment, as it's the same logic, just for a narrower use case. [sean: give soft_int_next_rip the same treatment]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ibmasm: fix heap over-read in ibmasm_send_i2o_message() The ibmasm_send_i2o_message() function uses get_dot_command_size() to compute the byte count for memcpy_toio(), but this value is derived from user-controlled fields in the dot_command_header (command_size: u8, data_size: u16) and is never validated against the actual allocation size. A root user can write a small buffer with inflated header fields, causing memcpy_toio() to read up to ~65 KB past the end of the allocation into adjacent kernel heap, which is then forwarded to the service processor over MMIO. Silently clamping the copy size is not sufficient: if the header fields claim a larger size than the buffer, the SP receives a dot command whose own header is inconsistent with the I2O message length, which can cause the SP to desynchronize. Reject such commands outright by returning failure. Validate command_size before calling get_mfa_inbound() to avoid leaking an I2O message frame: reading INBOUND_QUEUE_PORT dequeues a hardware frame from the controller's free pool, and returning without a corresponding set_mfa_inbound() call would permanently exhaust it. Additionally, clamp command_size to I2O_COMMAND_SIZE before the memcpy_toio() so the MMIO write stays within the I2O message frame, consistent with the clamping already performed by outgoing_message_size() for the header field.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx The bounce buffers are allocated with __get_free_pages() using BOUNCE_BUFFER_ORDER (order 2 = 4 pages), but both the allocation error path and nx842_crypto_free_ctx() release the buffers with free_page(). Use free_pages() with the matching order instead.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-sha204a - Fix potential UAF and memory leak in remove path Unregister the hwrng to prevent new ->read() calls and flush the Atmel I2C workqueue before teardown to prevent a potential UAF if a queued callback runs while the device is being removed. Drop the early return to ensure sysfs entries are removed and ->hwrng.priv is freed, preventing a memory leak.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-tdes - fix DMA sync direction Before DMA output is consumed by the CPU, ->dma_addr_out must be synced with dma_sync_single_for_cpu() instead of dma_sync_single_for_device(). Using the wrong direction can return stale cache data on non-coherent platforms.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 INVLPGA should cause a #UD when EFER.SVME is not set. Add a check to properly inject #UD when EFER.SVME=0. [sean: tag for stable@]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: bridge: use a stable FDB dst snapshot in RCU readers Local FDB entries can be rewritten in place by `fdb_delete_local()`, which updates `f->dst` to another port or to `NULL` while keeping the entry alive. Several bridge RCU readers inspect `f->dst`, including `br_fdb_fillbuf()` through the `brforward_read()` sysfs path. These readers currently load `f->dst` multiple times and can therefore observe inconsistent values across the check and later dereference. In `br_fdb_fillbuf()`, this means a concurrent local-FDB update can change `f->dst` after the NULL check and before the `port_no` dereference, leading to a NULL-ptr-deref. Fix this by taking a single `READ_ONCE()` snapshot of `f->dst` in each affected RCU reader and using that snapshot for the rest of the access sequence. Also publish the in-place `f->dst` updates in `fdb_delete_local()` with `WRITE_ONCE()` so the readers and writer use matching access patterns.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names() snd_ctl_elem_init_enum_names() advances pointer p through the names buffer while decrementing buf_len. If buf_len reaches zero but items remain, the next iteration calls strnlen(p, 0). While strnlen(p, 0) returns 0 and would hit the existing name_len == 0 error path, CONFIG_FORTIFY_SOURCE's fortified strnlen() first checks maxlen against __builtin_dynamic_object_size(). When Clang loses track of p's object size inside the loop, this triggers a BRK exception panic before the return value is examined. Add a buf_len == 0 guard at the loop entry to prevent calling fortified strnlen() on an exhausted buffer. Found by kernel fuzz testing through Xiaomi Smartphone.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: zram: do not forget to endio for partial discard requests As reported by Qu Wenruo and Avinesh Kumar, the following getconf PAGESIZE 65536 blkdiscard -p 4k /dev/zram0 takes literally forever to complete. zram doesn't support partial discards and just returns immediately w/o doing any discard work in such cases. The problem is that we forget to endio on our way out, so blkdiscard sleeps forever in submit_bio_wait(). Fix this by jumping to end_bio label, which does bio_endio().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: check for PCI upstream bridge existence pci_upstream_bridge() returns NULL if the device is on a root bus. If 8821CE is installed in the system with such a PCI topology, the probing routine will crash. This has probably been unnoticed as 8821CE is mostly supplied in laptops where there is a PCI-to-PCI bridge located upstream from the device. However the card might be installed on a system with different configuration. Check if the bridge does exist for the specific workaround to be applied. Found by Linux Verification Center (linuxtesting.org) with Svace static analysis tool.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels seg6_input_core() and rpl_input() call ip6_route_input() which sets a NOREF dst on the skb, then pass it to dst_cache_set_ip6() invoking dst_hold() unconditionally. On PREEMPT_RT, ksoftirqd is preemptible and a higher-priority task can release the underlying pcpu_rt between the lookup and the caching through a concurrent FIB lookup on a shared nexthop. Simplified race sequence: ksoftirqd/X higher-prio task (same CPU X) ----------- -------------------------------- seg6_input_core(,skb)/rpl_input(skb) dst_cache_get() -> miss ip6_route_input(skb) -> ip6_pol_route(,skb,flags) [RT6_LOOKUP_F_DST_NOREF in flags] -> FIB lookup resolves fib6_nh [nhid=N route] -> rt6_make_pcpu_route() [creates pcpu_rt, refcount=1] pcpu_rt->sernum = fib6_sernum [fib6_sernum=W] -> cmpxchg(fib6_nh.rt6i_pcpu, NULL, pcpu_rt) [slot was empty, store succeeds] -> skb_dst_set_noref(skb, dst) [dst is pcpu_rt, refcount still 1] rt_genid_bump_ipv6() -> bumps fib6_sernum [fib6_sernum from W to Z] ip6_route_output() -> ip6_pol_route() -> FIB lookup resolves fib6_nh [nhid=N] -> rt6_get_pcpu_route() pcpu_rt->sernum != fib6_sernum [W <> Z, stale] -> prev = xchg(rt6i_pcpu, NULL) -> dst_release(prev) [prev is pcpu_rt, refcount 1->0, dead] dst = skb_dst(skb) [dst is the dead pcpu_rt] dst_cache_set_ip6(dst) -> dst_hold() on dead dst -> WARN / use-after-free For the race to occur, ksoftirqd must be preemptible (PREEMPT_RT without PREEMPT_RT_NEEDS_BH_LOCK) and a concurrent task must be able to release the pcpu_rt. Shared nexthop objects provide such a path, as two routes pointing to the same nhid share the same fib6_nh and its rt6i_pcpu entry. Fix seg6_input_core() and rpl_input() by calling skb_dst_force() after ip6_route_input() to force the NOREF dst into a refcounted one before caching. The output path is not affected as ip6_route_output() already returns a refcounted dst.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: strparser: fix skb_head leak in strp_abort_strp() When the stream parser is aborted, for example after a message assembly timeout, it can still hold a reference to a partially assembled message in strp->skb_head. That skb is not released in strp_abort_strp(), which leaks the partially assembled message and can be triggered repeatedly to exhaust memory. Fix this by freeing strp->skb_head and resetting the parser state in the abort path. Leave strp_stop() unchanged so final cleanup still happens in strp_done() after the work and timer have been synchronized.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: can: ucan: fix devres lifetime USB drivers bind to USB interfaces and any device managed resources should have their lifetime tied to the interface rather than parent USB device. This avoids issues like memory leaks when drivers are unbound without their devices being physically disconnected (e.g. on probe deferral or configuration changes). Fix the control message buffer lifetime so that it is released on driver unbind.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipmi:si: Return state to normal if message allocation fails There were places where nothing would get started if a message allocation failed, so the driver needs to return to normal state.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: b43: enforce bounds check on firmware key index in b43_rx() The firmware-controlled key index in b43_rx() can exceed the dev->key[] array size (58 entries). The existing B43_WARN_ON is non-enforcing in production builds, allowing an out-of-bounds read. Make the B43_WARN_ON check enforcing by dropping the frame when the firmware returns an invalid key index.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: remove station if connection prep fails If connection preparation fails for MLO connections, then the interface is completely reset to non-MLD. In this case, we must not keep the station since it's related to the link of the vif being removed. Delete an existing station. Any "new_sta" is already being removed, so that doesn't need changes. This fixes a use-after-free/double-free in debugfs if that's enabled, because a vif going from MLD (and to MLD, but that's not relevant here) recreates its entire debugfs.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipmi: Check event message buffer response for bad data The event message buffer response data size got checked later when processing, but check it right after the response comes back. It appears some BMCs may return an empty message instead of an error when fetching events. There are apparently some new BMCs that make this error, so we need to compensate.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: check for nEPT/nNPT in slow flush hypercalls Checking is_guest_mode(vcpu) is incorrect, because translate_nested_gpa() is only valid if an L2 guest is running *with nested EPT/NPT enabled*. Instead use the same condition as translate_nested_gpa() itself.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo rtnl_fill_vfinfo() declares struct ifla_vf_broadcast on the stack without initialisation: struct ifla_vf_broadcast vf_broadcast; The struct contains a single fixed 32-byte field: /* include/uapi/linux/if_link.h */ struct ifla_vf_broadcast { __u8 broadcast[32]; }; The function then copies dev->broadcast into it using dev->addr_len as the length: memcpy(vf_broadcast.broadcast, dev->broadcast, dev->addr_len); On Ethernet devices (the overwhelming majority of SR-IOV NICs) dev->addr_len is 6, so only the first 6 bytes of broadcast[] are written. The remaining 26 bytes retain whatever was previously on the kernel stack. The full struct is then handed to userspace via: nla_put(skb, IFLA_VF_BROADCAST, sizeof(vf_broadcast), &vf_broadcast) leaking up to 26 bytes of uninitialised kernel stack per VF per RTM_GETLINK request, repeatable. The other vf_* structs in the same function are explicitly zeroed for exactly this reason - see the memset() calls for ivi, vf_vlan_info, node_guid and port_guid a few lines above. vf_broadcast was simply missed when it was added. Reachability: any unprivileged local process can open AF_NETLINK / NETLINK_ROUTE without capabilities and send RTM_GETLINK with an IFLA_EXT_MASK attribute carrying RTEXT_FILTER_VF. The kernel walks each VF and emits IFLA_VF_BROADCAST, leaking 26 bytes of stack per VF per request. Stack residue at this call site can include return addresses and transient sensitive data; KASAN with stack instrumentation, or KMSAN, will flag the nla_put() when reproduced. Zero the on-stack struct before the partial memcpy, matching the existing pattern used for the other vf_* structs in the same function.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix a potential clc buffer length underflow The buf_len is used to limit the iterations for retrieving the country power setting and may underflow under certain conditions due to changes in the power table in CLC. This underflow leads to an almost infinite loop or an invalid power setting resulting in driver initialization failure.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt hci_le_create_big_complete_evt() iterates over BT_BOUND connections for a BIG handle using a while loop, accessing ev->bis_handle[i++] on each iteration. However, there is no check that i stays within ev->num_bis before the array access. When a controller sends a LE_Create_BIG_Complete event with fewer bis_handle entries than there are BT_BOUND connections for that BIG, or with num_bis=0, the loop reads beyond the valid bis_handle[] flex array into adjacent heap memory. Since the out-of-bounds values typically exceed HCI_CONN_HANDLE_MAX (0x0EFF), hci_conn_set_handle() rejects them and the connection remains in BT_BOUND state. The same connection is then found again by hci_conn_hash_lookup_big_state(), creating an infinite loop with hci_dev_lock held. Fix this by terminating the BIG if in case not all BIS could be setup properly.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtk: validate WMT event SKB length before struct access btmtk_usb_hci_wmt_sync() casts the WMT event response SKB data to struct btmtk_hci_wmt_evt (7 bytes) and struct btmtk_hci_wmt_evt_funcc (9 bytes) without first checking that the SKB contains enough data. A short firmware response causes out-of-bounds reads from SKB tailroom. Use skb_pull_data() to validate and advance past the base WMT event header. For the FUNC_CTRL case, pull the additional status field bytes before accessing them.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens As prepare can be called mulitple times, this can result in multiple graph opens for playback path. This will result in a memory leaks, fix this by adding a check before opening.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() The convert_chmap_v3() has a loop with its increment size of cs_desc->wLength, but we forgot to validate cs_desc->wLength itself, which may lead to potential endless loop by a malformed descriptor. Add a proper size check to abort the loop for plugging the hole.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: usblp: fix heap leak in IEEE 1284 device ID via short response usblp_ctrl_msg() collapses the usb_control_msg() return value to 0/-errno, discarding the actual number of bytes transferred. A broken printer can complete the GET_DEVICE_ID control transfer short and the driver has no way to know. usblp_cache_device_id_string() reads the 2-byte big-endian length prefix from the response and trusts it (clamped only to the buffer bounds). The buffer is kmalloc(1024) at probe time. A device that sends exactly two bytes (e.g. 0x03 0xFF, claiming a 1023-byte ID) leaves device_id_string[2..1022] holding stale kmalloc heap. That stale data is then exposed: - via the ieee1284_id sysfs attribute (sprintf("%s", buf+2), truncated at the first NUL in the stale heap), and - via the IOCNR_GET_DEVICE_ID ioctl, which copy_to_user()s the full claimed length regardless of NULs, up to 1021 bytes of uninitialized heap, with the leak size chosen by the device. Fix this up by just zapping the buffer with zeros before each request sent to the device.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: drop stray 'static' from fast-RX rx_result ieee80211_invoke_fast_rx() is documented as safe for parallel RX, but its per-invocation rx_result is declared static. Concurrent callers then share one instance and can overwrite each other's result between ieee80211_rx_mesh_data() and the switch on res. That can make a packet that was queued or consumed by ieee80211_rx_mesh_data() fall through into ieee80211_rx_8023(), or make a packet that should continue return as queued. Make res an automatic variable so each invocation keeps its own result.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies setup_geo() extracts near_copies (nc) and far_copies (fc) from the user-provided layout parameter without checking for zero. When fc=0 with the "improved" far set layout selected, 'geo->far_set_size = disks / fc' triggers a divide-by-zero. Validate nc and fc immediately after extraction, returning -1 if either is zero.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: b43legacy: enforce bounds check on firmware key index in RX path Same fix as b43: the firmware-controlled key index in b43legacy_rx() can exceed dev->max_nr_keys. The existing B43legacy_WARN_ON is non-enforcing in production builds, allowing an out-of-bounds read of dev->key[]. Make the check enforcing by dropping the frame for invalid indices.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: openvswitch: vport: fix self-deadlock on release of tunnel ports vports are used concurrently and protected by RCU, so netdev_put() must happen after the RCU grace period. So, either in an RCU call or after the synchronize_net(). The rtnl_delete_link() must happen under RTNL and so can't be executed in RCU context. Calling synchronize_net() while holding RTNL is not a good idea for performance and system stability under load in general, so calling netdev_put() in RCU call is the right solution here. However, when the device is deleted, rtnl_unlock() will call netdev_run_todo() and block until all the references are gone. In the current code this means that we never reach the call_rcu() and the vport is never freed and the reference is never released, causing a self-deadlock on device removal. Fix that by moving the rcu_call() before the rtnl_unlock(), so the scheduled RCU callback will be executed when synchronize_net() is called from the rtnl_unlock()->netdev_run_todo() while the RTNL itself is already released.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: use safe list iteration in radar detect work The call to ieee80211_dfs_cac_cancel can cause the iterated chanctx to be freed and removed from the list. Guard against this to avoid a slab-use-after-free error.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl Just like in a previous problem in this driver, usblp_ctrl_msg() will collapse the usb_control_msg() return value to 0/-errno, discarding the actual number of bytes transferred. Ideally that short command should be detected and error out, but many printers are known to send "incorrect" responses back so we can't just do that. statusbuf is kmalloc(8) at probe time and never filled before the first LPGETSTATUS ioctl. usblp_read_status() requests 1 byte. If a malicious printer responds with zero bytes, *statusbuf is one byte of stale kmalloc heap, sign-extended into the local int status, which the LPGETSTATUS path then copy_to_user()s directly to the ioctl caller. Fix this all by just zapping out the memory buffer when allocated at probe time. If a later call does a short read, the data will be identical to what the device sent it the last time, so there is no "leak" of information happening.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipmi: Add limits to event and receive message requests The driver would just fetch events and receive messages until the BMC said it was done. To avoid issues with BMCs that never say they are done, add a limit of 10 fetches at a time. In addition, an si interface has an attn state it can return from the hardware which is supposed to cause a flag fetch to see if the driver needs to fetch events or message or a few other things. If the attn bit gets stuck, it's a similar problem. So allow messages in between flag fetches so the driver itself doesn't get stuck. This is a more general fix than the previous fix for the specific bad BMC, but should fix the more general issue of a BMC that won't stop saying it has data. This has been there from the beginning of the driver. It's not a bug per-se, but it is accounting for bugs in BMCs.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() Sashiko points out that mlx4_srq_alloc() was not undone during error unwind, add the missing call to mlx4_srq_free().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Don't allow pointer operations on unconfigured streams When reporting the pointer for a compressed stream we report the current I/O frame position by dividing the position by the number of channels multiplied by the number of container bytes. These values default to 0 and are only configured as part of setting the stream parameters so this allows a divide by zero to be configured. Validate that they are non zero, returning an error if not


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: sound: ua101: fix division by zero at probe Add a missing sanity check for bNrChannels in detect_usb_format() to prevent a division by zero in playback_urb_complete() and capture_urb_complete(). USB core does not validate class-specific descriptor fields such as bNrChannels, so drivers must verify them before use. If a device provides bNrChannels = 0, frame_bytes becomes zero and is later used as a divisor in the URB completion handlers, leading to a kernel crash.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: validate rx pkt_type header length virtbt_rx_handle() reads the leading pkt_type byte from the RX skb and forwards the remainder to hci_recv_frame() for every event/ACL/SCO/ISO type, without checking that the remaining payload is at least the fixed HCI header for that type. After the preceding patch bounds the backend-supplied used.len to [1, VIRTBT_RX_BUF_SIZE], a one-byte completion still reaches hci_recv_frame() with skb->len already pulled to 0. If the byte happened to be HCI_ACLDATA_PKT, the ACL-vs-ISO classification fast-path in hci_dev_classify_pkt_type() dereferences hci_acl_hdr(skb)->handle whenever the HCI device has an active CIS_LINK, BIS_LINK, or PA_LINK connection, reading two bytes of uninitialized RX-buffer data. The same hazard exists for every packet type the driver accepts because none of the switch cases in virtbt_rx_handle() check skb->len against the per-type minimum HCI header size before handing the frame to the core. After stripping pkt_type, require skb->len to cover the fixed header size for the selected type (event 2, ACL 4, SCO 3, ISO 4) before calling hci_recv_frame(); drop ratelimited otherwise. Unknown pkt_type values still take the original kfree_skb() default path. Use bt_dev_err_ratelimited() because both the length and pkt_type values come from an untrusted backend that can otherwise flood the kernel log.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: rsi: fix kthread lifetime race between self-exit and external-stop RSI driver use both self-exit(kthread_complete_and_exit) and external-stop (kthread_stop) when killing a kthread. Generally, kthread_stop() is called first, and in this case, no particular issues occur. However, in rare instances where kthread_complete_and_exit() is called first and then kthread_stop() is called, a UAF occurs because the kthread object, which has already exited and been freed, is accessed again. Therefore, to prevent this with minimal modification, you must remove kthread_stop() and change the code to wait until the self-exit operation is completed.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() Sashiko noticed an out-of-bounds read [1]. In spi_nor_params_show(), the snor_f_names array is passed to spi_nor_print_flags() using sizeof(snor_f_names). Since snor_f_names is an array of pointers, sizeof() returns the total number of bytes occupied by the pointers (element_count * sizeof(void *)) rather than the element count itself. On 64-bit systems, this makes the passed length 8x larger than intended. Inside spi_nor_print_flags(), the 'names_len' argument is used to bounds-check the 'names' array access. An out-of-bounds read occurs if a flag bit is set that exceeds the array's actual element count but is within the inflated byte-size count. Correct this by using ARRAY_SIZE() to pass the actual number of string pointers in the array.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fbcon: Avoid OOB font access if console rotation fails Clear the font buffer if the reallocation during console rotation fails in fbcon_rotate_font(). The putcs implementations for the rotated buffer will return early in this case. See [1] for an example. Currently, fbcon_rotate_font() keeps the old buffer, which is too small for the rotated font. Printing to the rotated console with a high-enough character code will overflow the font buffer. v2: - fix typos in commit message


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix integer overflow on buff_pos Fixing an integer overflow present in batadv_iv_ogm_send_to_if. The size check is done using the int type in batadv_iv_ogm_aggr_packet whereas the buff_pos variable uses the s16 type. This could lead to an out-of-bound read.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg Check bounds against the end of the BO whenever we access the msg.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() When xe_dma_buf_init_obj() fails, the attachment from dma_buf_dynamic_attach() is not detached. Add dma_buf_detach() before returning the error. Note: we cannot use goto out_err here because xe_dma_buf_init_obj() already frees bo on failure, and out_err would double-free it. (cherry picked from commit a828eb185aac41800df8eae4b60501ccc0dbbe51)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB Rewrite the IB parsing to use amdgpu_ib_get_value() which handles the bounds checks.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: staging: media: atomisp: Disallow all private IOCTLs Disallow all private IOCTLs. These aren't quite as safe as one could assume of IOCTL handlers; disable them for now. Instead of removing the code, return in the beginning of the function if cmd is non-zero in order to keep static checkers happy.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject new tp_meter sessions during teardown Prevent tp_meter from starting new sender or receiver sessions after mesh_state has left BATADV_MESH_ACTIVE.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix empty payload in tap skb for non-linear buffers For non-linear skbs, virtio_transport_build_skb() goes through virtio_transport_copy_nonlinear_skb() to copy the original payload in the new skb to be delivered to the vsockmon tap device. This manually initializes an iov_iter but does not set iov_iter.count. Since the iov_iter is zero-initialized, the copy length is zero and no payload is actually copied to the monitor interface, leaving data un-initialized. Fix this by removing the linear vs non-linear split and using skb_copy_datagram_iter() with iov_iter_kvec() for all cases, as vhost-vsock already does. This handles both linear and non-linear skbs, properly initializes the iov_iter, and removes the now unused virtio_transport_copy_nonlinear_skb(). While touching this code, let's also check the return value of skb_copy_datagram_iter(), even though it's unlikely to fail.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata() msm_ioctl_gem_info_get_metadata() always returns 0 regardless of errors. When copy_to_user() fails or the user buffer is too small, the error code stored in ret is ignored because the function unconditionally returns 0. This causes userspace to believe the ioctl succeeded when it did not. Additionally, kmemdup() can return NULL on allocation failure, but the return value is not checked. This leads to a NULL pointer dereference in the subsequent copy_to_user() call. Add the missing NULL check for kmemdup() and return ret instead of 0. Note that the SET counterpart (msm_ioctl_gem_info_set_metadata) correctly returns ret. Patchwork: https://patchwork.freedesktop.org/patch/714478/


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: prevent use-after-free when deleting claims When batadv_bla_del_backbone_claims() removes all claims for a backbone, it does this by dropping the link entry in the hash list. This list entry itself was one of the references which need to be dropped at the same time via batadv_claim_put(). But the batadv_claim_put() must not be done before the last access to the claim object in this function. Otherwise the claim might be freed already by the batadv_claim_release() function before the list entry was dropped.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/xe/hdcp: Add NULL check for media_gt in intel_hdcp_gsc_check_status() When media GT is disabled via configfs, there is no allocation for media_gt, which is kept as NULL. In such scenario, intel_hdcp_gsc_check_status() results in a kernel pagefault error due to &gt->uc.gsc being evaluated as an invalid memory address. Fix that by introducing a NULL check on media_gt and bailing out early if so. While at it, also drop the NULL check for gsc, since it can't be NULL if media_gt is not NULL. v2: - Get address for gsc only after checking that gt is not NULL. (Shuicheng) - Drop the NULL check for gsc. (Shuicheng) v3: - Add "Fixes" and "Cc: <stable...>" tags. (Matt) (cherry picked from commit bfaf87e84ca3ca3f6e275f9ae56da47a8b55ffd1)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Add bounds checking to ib_{get,set}_value The uvd/vce/vcn code accesses the IB at predefined offsets without checking that the IB is large enough. Check the bounds here. The caller is responsible for making sure it can handle arbitrary return values. Also make the idx a uint32_t to prevent overflows causing the condition to fail.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix use-after-free on unbind The state machine work is scheduled by the interrupt handler and therefore needs to be cancelled after disabling interrupts to avoid a potential use-after-free.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission sdma_v4_0_ring_emit_fence() contains two BUG_ON(addr & 0x3) assertions that verify fence writeback addresses are dword-aligned. These assertions can be reached from unprivileged userspace via crafted DRM_IOCTL_AMDGPU_CS submissions, causing a fatal kernel panic in a scheduler worker thread. Replace both BUG_ON() calls with WARN_ON() to log the condition without crashing the kernel. A misaligned fence address at this point indicates a driver bug, but crashing the kernel is never the correct response when the assertion is reachable from userspace. The CS IOCTL path is the correct place to filter invalid submissions; the ring emission callback is too late to do anything about it. (cherry picked from commit b90250bd933afd1ba94d86d6b13821997b22b18e)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: spi: rspi: fix controller deregistration Make sure to deregister the controller before releasing underlying resources like DMA during driver unbind.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg Check bounds against the end of the BO whenever we access the msg.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: put backbone reference on failed claim hash insert When batadv_bla_add_claim() fails to insert a new claim into the hash, it leaked a reference to the backbone_gw for which the claim was intended. Call batadv_backbone_gw_put() on the error path to release the reference and avoid leaking the backbone_gw object.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: playstation: Clamp num_touch_reports A device would never lie about the number of touch reports would it? If it does the loop in dualshock4_parse_report will read off the end of the touch_reports array, up to about 2 KiB for the maximum number of 256 loop iteraions. The data that is read is emitted via evdev if the DS4_TOUCH_POINT_INACTIVE bit happens to be set. Protect against this by clamping the num_touch_reports value provided by the device to the maximum size of the touch_reports array.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: only purge non-released claims When batadv_bla_purge_claims() goes through the list of claims, it is only traversing the hash list with an rcu_read_lock(). Due to a potential parallel batadv_claim_put(), it can happen that it encounters a claim which was actually in the process of being released+freed by batadv_claim_release(). In this case, backbone_gw is set to NULL before the delayed RCU kfree is started. Calling batadv_bla_claim_get_backbone_gw() is then no longer allowed because it would cause a NULL-ptr derefence. To avoid this, only claims with a valid reference counter must be purged. All others are already taken care of.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: saa7164: add ioremap return checks and cleanups Add checks for ioremap return values in saa7164_dev_setup(). If ioremap for BAR0 or BAR2 fails, release the already allocated PCI memory regions, remove the device from the global list, decrement the device count, and return -ENODEV. This prevents potential null pointer dereferences and ensures proper cleanup on memory mapping failures.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: rc: xbox_remote: heed DMA restrictions The buffer for IO must not be part of the device structure because that violates the DMA coherency rules.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: batman-adv: stop caching unowned originator pointers in BAT IV BAT IV keeps the last-hop neighbor address in each neigh_node, but some paths also cache an originator pointer derived from a temporary lookup. That pointer is not owned by the neigh_node and may no longer refer to a live originator entry after purge handling runs. Stop storing the auxiliary originator pointer in the BAT IV neighbor state. When BAT IV needs the neighbor originator data, resolve it from the stored neighbor address and drop the reference again after use. [sven: avoid bonding logic for outgoing OGM]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside the critical section (is_file_epoll(), hlist_del_rcu() through the head, spin_unlock). A concurrent __fput() taking the eventpoll_release() fastpath in that window observed the transient NULL, skipped eventpoll_release_file() and ran to f_op->release / file_free(). For the epoll-watches-epoll case, f_op->release is ep_eventpoll_release() -> ep_clear_and_put() -> ep_free(), which kfree()s the watched struct eventpoll. Its embedded ->refs hlist_head is exactly where epi->fllink.pprev points, so the subsequent hlist_del_rcu()'s "*pprev = next" scribbles into freed kmalloc-192 memory. In addition, struct file is SLAB_TYPESAFE_BY_RCU, so the slot backing @file could be recycled by alloc_empty_file() -- reinitializing f_lock and f_ep -- while ep_remove() is still nominally inside that lock. The upshot is an attacker-controllable kmem_cache_free() against the wrong slab cache. Pin @file via epi_fget() at the top of ep_remove() and gate the critical section on the pin succeeding. With the pin held @file cannot reach refcount zero, which holds __fput() off and transitively keeps the watched struct eventpoll alive across the hlist_del_rcu() and the f_lock use, closing both UAFs. If the pin fails @file has already reached refcount zero and its __fput() is in flight. Because we bailed before clearing f_ep, that path takes the eventpoll_release() slow path into eventpoll_release_file() and blocks on ep->mtx until the waiter side's ep_clear_and_put() drops it. The bailed epi's share of ep->refcount stays intact, so the trailing ep_refcount_dec_and_test() in ep_clear_and_put() cannot free the eventpoll out from under eventpoll_release_file(); the orphaned epi is then cleaned up there. A successful pin also proves we are not racing eventpoll_release_file() on this epi, so drop the now-redundant re-check of epi->dying under f_lock. The cheap lockless READ_ONCE(epi->dying) fast-path bailout stays.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gfx3d: add parent to parent request map After commit d228ece36345 ("clk: divider: remove round_rate() in favor of determine_rate()") determining GFX3D clock rate crashes, because the passed parent map doesn't provide the expected best_parent_hw clock (with the roundd_rate path before the offending commit the best_parent_hw was ignored). Set the field in parent_req in addition to setting it in the req, fixing the crash. clk_hw_round_rate (drivers/clk/clk.c:1764) (P) clk_divider_bestdiv (drivers/clk/clk-divider.c:336) divider_determine_rate (drivers/clk/clk-divider.c:358) clk_alpha_pll_postdiv_determine_rate (drivers/clk/qcom/clk-alpha-pll.c:1275) clk_core_determine_round_nolock (drivers/clk/clk.c:1606) clk_core_round_rate_nolock (drivers/clk/clk.c:1701) __clk_determine_rate (drivers/clk/clk.c:1741) clk_gfx3d_determine_rate (drivers/clk/qcom/clk-rcg2.c:1268) clk_core_determine_round_nolock (drivers/clk/clk.c:1606) clk_core_round_rate_nolock (drivers/clk/clk.c:1701) clk_core_round_rate_nolock (drivers/clk/clk.c:1710) clk_round_rate (drivers/clk/clk.c:1804) dev_pm_opp_set_rate (drivers/opp/core.c:1440 (discriminator 1)) msm_devfreq_target (drivers/gpu/drm/msm/msm_gpu_devfreq.c:51) devfreq_set_target (drivers/devfreq/devfreq.c:360) devfreq_update_target (drivers/devfreq/devfreq.c:426) devfreq_monitor (drivers/devfreq/devfreq.c:458) process_one_work (arch/arm64/include/asm/jump_label.h:36 include/trace/events/workqueue.h:110 kernel/workqueue.c:3284) worker_thread (kernel/workqueue.c:3356 (discriminator 2) kernel/workqueue.c:3443 (discriminator 2)) kthread (kernel/kthread.c:467) ret_from_fork (arch/arm64/kernel/entry.S:861)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Fix PF driver crash with kexec kernel booting During a kexec reboot the hardware is not power-cycled, so AF state from the old kernel can persist into the new kernel. When AF and PF drivers are built as modules, the PF driver may probe before AF reinitializes the hardware. The PF driver treats the RVUM block revision as an indication that AF initialization is complete. If this value is left uncleared at shutdown, PF may incorrectly assume AF is ready and access stale hardware state, leading to a crash. Clear the RVUM block revision during AF shutdown to avoid PF mis-detecting AF readiness after kexec.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: regulator: core: fix locking in regulator_resolve_supply() error path If late enabling of a supply regulator fails in regulator_resolve_supply(), the code currently triggers a lockdep warning: WARNING: drivers/regulator/core.c:2649 at _regulator_put+0x80/0xa0, CPU#6: kworker/u32:4/596 ... Call trace: _regulator_put+0x80/0xa0 (P) regulator_resolve_supply+0x7cc/0xbe0 regulator_register_resolve_supply+0x28/0xb8 as the regulator_list_mutex must be held when calling _regulator_put(). To solve this, simply switch to using regulator_put(). While at it, we should also make sure that no concurrent access happens to our rdev while we clear out the supply pointer. Add appropriate locking to ensure that. While the code in question will be removed altogether in a follow-up commit, I believe it is still beneficial to have this corrected before removal for future reference.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: spi: wpcm-fiu: Fix potential NULL pointer dereference in wpcm_fiu_probe() platform_get_resource_byname() can return NULL, which would cause a crash when passed the pointer to resource_size(). Move the fiu->memory_size assignment after the error check for devm_ioremap_resource() to prevent the potential NULL pointer dereference.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds stream encoder index v3 eng_id can be negative and that stream_enc_regs[] can be indexed out of bounds. eng_id is used directly as an index into stream_enc_regs[], which has only 5 entries. When eng_id is 5 (ENGINE_ID_DIGF) or negative, this can access memory past the end of the array. Add a bounds check using ARRAY_SIZE() before using eng_id as an index. The unsigned cast also rejects negative values. This avoids out-of-bounds access. Fixes the below smatch error: dcn*_resource.c: stream_encoder_create() may index stream_enc_regs[eng_id] out of bounds (size 5). drivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn351/dcn351_resource.c 1246 static struct stream_encoder *dcn35_stream_encoder_create( 1247 enum engine_id eng_id, 1248 struct dc_context *ctx) 1249 { ... 1255 1256 /* Mapping of VPG, AFMT, DME register blocks to DIO block instance */ 1257 if (eng_id <= ENGINE_ID_DIGF) { ENGINE_ID_DIGF is 5. should <= be <? Unrelated but, ugh, why is Smatch saying that "eng_id" can be negative? end_id is type signed long, but there are checks in the caller which prevent it from being negative. 1258 vpg_inst = eng_id; 1259 afmt_inst = eng_id; 1260 } else 1261 return NULL; 1262 ... 1281 1282 dcn35_dio_stream_encoder_construct(enc1, ctx, ctx->dc_bios, 1283 eng_id, vpg, afmt, --> 1284 &stream_enc_regs[eng_id], ^^^^^^^^^^^^^^^^^^^^^^^ This stream_enc_regs[] array has 5 elements so we are one element beyond the end of the array. ... 1287 return &enc1->base; 1288 } v2: use explicit bounds check as suggested by Roman/Dan; avoid unsigned int cast v3: The compiler already knows how to compare the two values, so the cast (int) is not needed. (Roman)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: nfc: hci: shdlc: Stop timers and work before freeing context llc_shdlc_deinit() purges SHDLC skb queues and frees the llc_shdlc structure while its timers and state machine work may still be active. Timer callbacks can schedule sm_work, and sm_work accesses SHDLC state and the skb queues. If teardown happens in parallel with a queued/running work item, it can lead to UAF and other shutdown races. Stop all SHDLC timers and cancel sm_work synchronously before purging the queues and freeing the context. Found by Linux Verification Center (linuxtesting.org) with SVACE.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-after-free in power_supply_changed() Using the `devm_` variant for requesting IRQ _before_ the `devm_` variant for allocating/registering the `power_supply` handle, means that the `power_supply` handle will be deallocated/unregistered _before_ the interrupt handler (since `devm_` naturally deallocates in reverse allocation order). This means that during removal, there is a race condition where an interrupt can fire just _after_ the `power_supply` handle has been freed, *but* just _before_ the corresponding unregistration of the IRQ handler has run. This will lead to the IRQ handler calling `power_supply_changed()` with a freed `power_supply` handle. Which usually crashes the system or otherwise silently corrupts the memory... Note that there is a similar situation which can also happen during `probe()`; the possibility of an interrupt firing _before_ registering the `power_supply` handle. This would then lead to the nasty situation of using the `power_supply` handle *uninitialized* in `power_supply_changed()`. Fix this racy use-after-free by making sure the IRQ is requested _after_ the registration of the `power_supply` handle.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths Vulnerabilities leading to Use-After-Free (UAF) and Null Pointer Dereference (NPD) conditions were observed in the lifecycle management of hci_uart. The primary issue arises because the workqueues (init_ready and write_work) are only flushed/cancelled if the HCI_UART_PROTO_READY flag is set during TTY close. If a hangup occurs before setup completes, hci_uart_tty_close() skips the teardown of these workqueues and proceeds to free the `hu` struct. When the scheduled work executes later, it blindly dereferences the freed `hu` struct. Furthermore, several data races and UAFs were identified in the teardown sequence: 1. Calling hci_uart_flush() from hci_uart_close() without effectively disabling write_work causes a race condition where both can concurrently double-free hu->tx_skb. This happens because protocol timers can concurrently invoke hci_uart_tx_wakeup() and requeue write_work. 2. Calling hci_free_dev(hdev) before hu->proto->close(hu) causes a UAF when vendor specific protocol close callbacks dereference hu->hdev. 3. In the initialization error paths, failing to take the proto_lock write lock before clearing PROTO_READY leads to races with active readers. Additionally, hci_uart_tty_receive() accesses hu->hdev outside the read lock, leading to UAFs if the initialization error path frees hdev concurrently. Fix these synchronization and lifecycle issues by: 1. Re-ordering hci_uart_tty_close() to clear HCI_UART_PROTO_READY first, followed immediately by a cancel_work_sync(&hu->write_work). Clearing the flag locks out concurrent protocol timers from successfully invoking hci_uart_tx_wakeup(), effectively rendering the cancellation permanent and preventing the tx_skb double-free. 2. Note: Clearing PROTO_READY early causes hci_uart_close() to skip hu->proto->flush(). This is perfectly safe in the tty_close path because hu->proto->close() executes shortly after, which intrinsically purges all protocol SKB queues and tears down the state. 3. Relocating hu->proto->close(hu) strictly prior to hci_free_dev(hdev) across all close and error paths to prevent vendor-level UAFs. 4. Moving the hdev->stat.byte_rx increment in hci_uart_tty_receive() inside the proto_lock read-side critical section to safely synchronize with device unregistration. 5. Adding cancel_work_sync(&hu->write_work) to hci_uart_close() to safely flush the workqueue before hci_uart_flush() is invoked via the HCI core. 6. Utilizing cancel_work_sync() instead of disable_work_sync() across all paths to prevent permanently breaking user-space retry capabilities.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix zero-size GDS range init on RDNA4 RDNA4 (GFX 12) hardware removes the GDS, GWS, and OA on-chip memory resources. The gfx_v12_0 initialisation code correctly leaves adev->gds.gds_size, adev->gds.gws_size, and adev->gds.oa_size at zero to reflect this. amdgpu_ttm_init() unconditionally calls amdgpu_ttm_init_on_chip() for each of these resources regardless of size. When the size is zero, amdgpu_ttm_init_on_chip() forwards the call to ttm_range_man_init(), which calls drm_mm_init(mm, 0, 0). drm_mm_init() immediately fires DRM_MM_BUG_ON(start + size <= start) -- trivially true when size is zero -- crashing the kernel during modprobe of amdgpu on an RX 9070 XT. Guard against this by returning 0 early from amdgpu_ttm_init_on_chip() when size_in_page is zero. This skips TTM resource manager registration for hardware resources that are absent, without affecting any other GPU type. DRM_MM_BUG_ON() only asserts if CONFIG_DRM_DEBUG_MM is enabled in the kernel config. This is apparently rarely enabled as these chips have been in the market for over a year and this issue was only reported now. Oops-Analysis: http://oops.fenrus.org/reports/bugzilla.korg/221376/report.html (cherry picked from commit 5719ce5865279cad4fd5f01011fe037168503f2d)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: mtd: docg3: fix use-after-free in docg3_release() In docg3_release(), the docg3 pointer is obtained from cascade->floors[0]->priv before the loop that calls doc_release_device() on each floor. doc_release_device() frees the docg3 struct via kfree(docg3) at line 1881. After the loop, docg3->cascade->bch dereferences the already-freed pointer. Fix this by accessing cascade->bch directly, which is equivalent since docg3->cascade points back to the same cascade struct, and is already available as a local variable. This also removes the now-unused docg3 local variable.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: leds: qcom-lpg: Check for array overflow when selecting the high resolution When selecting the high resolution values from the array, FIELD_GET() is used to pull from a 3 bit register, yet the array being indexed has only 5 values in it. Odds are the hardware is sane, but just to be safe, properly check before just overflowing and reading random data and then setting up chip values based on that.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: dm: fix a buffer overflow in ioctl processing Tony Asleson (using Claude) found a buffer overflow in dm-ioctl in the function retrieve_status: 1. The code in retrieve_status checks that the output string fits into the output buffer and writes the output string there 2. Then, the code aligns the "outptr" variable to the next 8-byte boundary: outptr = align_ptr(outptr); 3. The alignment doesn't check overflow, so outptr could point past the buffer end 4. The "for" loop is iterated again, it executes: remaining = len - (outptr - outbuf); 5. If "outptr" points past "outbuf + len", the arithmetics wraps around and the variable "remaining" contains unusually high number 6. With "remaining" being high, the code writes more data past the end of the buffer Luckily, this bug has no security implications because: 1. Only root can issue device mapper ioctls 2. The commonly used libraries that communicate with device mapper (libdevmapper and devicemapper-rs) use buffer size that is aligned to 8 bytes - thus, "outptr = align_ptr(outptr)" can't overshoot the input buffer and the bug can't happen accidentally


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: ath5k: do not access array OOB Vincent reports: > The ath5k driver seems to do an array-index-out-of-bounds access as > shown by the UBSAN kernel message: > UBSAN: array-index-out-of-bounds in drivers/net/wireless/ath/ath5k/base.c:1741:20 > index 4 is out of range for type 'ieee80211_tx_rate [4]' > ... > Call Trace: > <TASK> > dump_stack_lvl+0x5d/0x80 > ubsan_epilogue+0x5/0x2b > __ubsan_handle_out_of_bounds.cold+0x46/0x4b > ath5k_tasklet_tx+0x4e0/0x560 [ath5k] > tasklet_action_common+0xb5/0x1c0 It is real. 'ts->ts_final_idx' can be 3 on 5212, so: info->status.rates[ts->ts_final_idx + 1].idx = -1; with the array defined as: struct ieee80211_tx_rate rates[IEEE80211_TX_MAX_RATES]; while the size is: #define IEEE80211_TX_MAX_RATES 4 is indeed bogus. Set this 'idx = -1' sentinel only if the array index is less than the array size. As mac80211 will not look at rates beyond the size (IEEE80211_TX_MAX_RATES). Note: The effect of the OOB write is negligible. It just overwrites the next member of info->status, i.e. ack_signal.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: videobuf2: Set vma_flags in vb2_dma_sg_mmap vb2_dma_contig sets VMA flags VM_DONTEXPAND and VM_DONTDUMP and I do not see a reason why vb2_dma_sg should behave differently. This avoids hitting `WARN_ON(!(vma->vm_flags & VM_DONTEXPAND));` in drm_gem_mmap_obj() during mmap() of an imported dma-buf from the out of tree Apple ISP camera capture driver which uses vb2_dma_sg_memops. gst-launch-1.0 v4l2src ! gtk4paintablesink [ 38.201528] ------------[ cut here ]------------ [ 38.202135] WARNING: CPU: 7 PID: 2362 at drivers/gpu/drm/drm_gem.c:1144 drm_gem_mmap_obj+0x1f8/0x210 [ 38.203278] Modules linked in: rfcomm snd_seq_dummy snd_hrtimer snd_seq snd_seq_device uinput nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 nf_tables qrtr bnep nls_ascii i2c_dev loop fuse dm_multipath nfnetlink brcmfmac_wcc hid_magicmouse hci_bcm4377 brcmfmac brcmutil bluetooth ecdh_generic cfg80211 ecc btrfs xor xor_neon rfkill hid_apple raid6_pq joydev aop_als apple_nvmem_spmi industrialio snd_soc_aop apple_z2 snd_soc_cs42l84 tps6598x snd_soc_tas2764 macsmc_reboot spi_nor macsmc_hwmon rtc_macsmc gpio_macsmc macsmc_power regmap_spmi macsmc_input dockchannel_hid panel_summit appledrm nvme_apple dwc3 snd_soc_macaudio drm_client_lib nvme_core phy_apple_atc hwmon apple_sart apple_dockchannel macsmc apple_rtkit_helper spmi_apple_controller aop apple_wdt mfd_core nvmem_apple_efuses pinctrl_apple_gpio apple_isp apple_dcp videobuf2_dma_sg mux_core spi_apple [ 38.203300] videobuf2_memops i2c_pasemi_platform snd_soc_apple_mca videobuf2_v4l2 videodev clk_apple_nco videobuf2_common snd_pcm_dmaengine adpdrm asahi apple_admac adpdrm_mipi drm_dma_helper pwm_apple i2c_pasemi_core drm_display_helper mc cec apple_dart ofpart apple_soc_cpufreq leds_pwm phram [ 38.217677] CPU: 7 UID: 1000 PID: 2362 Comm: gst-launch-1.0 Tainted: G W 6.17.6+ #asahi-dev PREEMPT(full) [ 38.219040] Tainted: [W]=WARN [ 38.219398] Hardware name: Apple MacBook Pro (13-inch, M2, 2022) (DT) [ 38.220213] pstate: 21400005 (nzCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--) [ 38.221088] pc : drm_gem_mmap_obj+0x1f8/0x210 [ 38.221643] lr : drm_gem_mmap_obj+0x78/0x210 [ 38.222178] sp : ffffc0008dc678e0 [ 38.222579] x29: ffffc0008dc678e0 x28: 0000000000042a97 x27: ffff8000b701b480 [ 38.223465] x26: 00000000000000fb x25: ffffc0008dc67d20 x24: ffffc0008dc67968 [ 38.224402] x23: ffff8000e3ca5600 x22: ffff8000265b7800 x21: ffff80003000c0c0 [ 38.225279] x20: 0000000000000000 x19: ffff8000b68c5200 x18: ffffc0008dc67968 [ 38.226151] x17: 0000000000000000 x16: 0000000000000000 x15: ffffc000810a30a8 [ 38.227042] x14: 00007fff637effff x13: 00005555de91ffff x12: 00007fff63293fff [ 38.227942] x11: 0000000000000000 x10: ffff8000184ecf08 x9 : ffffc0007a1900c8 [ 38.228824] x8 : ffffc0008dc67968 x7 : 0000000000000012 x6 : ffffc0015cf1c000 [ 38.229703] x5 : ffffc0008dc676a0 x4 : ffffc00081a27dc0 x3 : 0000000000000038 [ 38.230607] x2 : 0000000000000003 x1 : 0000000000000003 x0 : 00000000100000fb [ 38.231488] Call trace: [ 38.231806] drm_gem_mmap_obj+0x1f8/0x210 (P) [ 38.232342] drm_gem_mmap+0x140/0x260 [ 38.232813] __mmap_region+0x488/0x9a0 [ 38.233277] mmap_region+0xd0/0x148 [ 38.233703] do_mmap+0x350/0x5c0 [ 38.234148] vm_mmap_pgoff+0x14c/0x200 [ 38.234612] ksys_mmap_pgoff+0x150/0x208 [ 38.235107] __arm64_sys_mmap+0x34/0x50 [ 38.235611] invoke_syscall+0x50/0x120 [ 38.236075] el0_svc_common.constprop.0+0x48/0xf0 [ 38.236680] do_el0_svc+0x24/0x38 [ 38.237113] el0_svc+0x38/0x168 [ 38.237507] el0t_64_sync_handler+0xa0/0xe8 [ 38.238034] el0t_64_sync+0x198/0x1a0 [ 38.238491] ---[ end trace 0000000000000000 ]--- There were discussions in [1] at the end of 2023 that mmap() on imported ---truncated---


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: intel/ipu6: fix error pointer dereference In a error path isp->psys is confirmed to be an error pointer not NULL so this condition is true and the error pointer is dereferenced. So isp-psys should be set to NULL before going to out_ipu6_bus_del_devices. Detected by Smatch: drivers/media/pci/intel/ipu6/ipu6.c:690 ipu6_pci_probe() error: 'isp->psys' dereferencing possible ERR_PTR() [Sakari Ailus: Fix commit message.]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Reject empty multisync extension to prevent infinite loop v3d_get_extensions() walks a userspace-provided singly-linked list of ioctl extensions without any bound on the chain length. A local user can craft a self-referential extension (ext->next == &ext) with zero in_sync_count and out_sync_count, which bypasses the existing duplicate- extension guard: if (se->in_sync_count || se->out_sync_count) return -EINVAL; The guard never fires because v3d_get_multisync_post_deps() returns immediately when count is zero, leaving both fields at zero on every iteration. The result is an infinite loop in kernel context, blocking the calling thread and pegging a CPU core indefinitely. Fix this by rejecting a multisync extension where both in_sync_count and out_sync_count are zero in v3d_get_multisync_submit_deps(). An empty multisync carries no synchronization information and serves no useful purpose, so returning -EINVAL for such an extension is the correct defense against this attack vector.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_one() tun_xdp_one() returns -EINVAL on a frame shorter than ETH_HLEN without freeing the page that vhost_net_build_xdp() allocated for it. tun_sendmsg() discards that -EINVAL and still returns total_len, so vhost_tx_batch() takes the success path and never frees the page; each short frame in a batch leaks one page-frag chunk. A local process that can open /dev/net/tun and /dev/vhost-net can hit this path: it attaches a tun/tap device as the vhost-net backend and feeds TX descriptors whose length minus the virtio-net header is below ETH_HLEN. Each kick leaks the page-frag chunks for that batch, and a tight submission loop exhausts host memory and triggers an OOM panic. Free the page before returning -EINVAL, matching the XDP-program error path in the same function.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb failure in tun_xdp_one() When build_skb() fails in tun_xdp_one(), the function sets ret to -ENOMEM and jumps to the out label, which returns without freeing the page that vhost_net_build_xdp() allocated for the frame. As with the short-frame rejection path, tun_sendmsg() discards the per-buffer error and still returns total_len, so vhost_tx_batch() takes the success path and never frees the page. Each build_skb() failure in a batch leaks one page-frag chunk. Free the page before taking the error path, matching the put_page() the other error exits of tun_xdp_one() already perform.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Revert "net/smc: Introduce TCP ULP support" This reverts commit d7cd421da9da2cc7b4d25b8537f66db5c8331c40. As reported by Al Viro, the TCP ULP support for SMC is fundamentally broken. The implementation attempts to convert an active TCP socket into an SMC socket by modifying the underlying `struct file`, dentry, and inode in-place, which violates core VFS invariants that assume these structures are immutable for an open file, creating a risk of use after free errors and general system instability. Given the severity of this design flaw and the fact that cleaner alternatives (e.g., LD_PRELOAD, BPF) exist for legacy application transparency, the correct course of action is to remove this feature entirely.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix nvkm_device leak on aperture removal failure When aperture_remove_conflicting_pci_devices() fails during probe, the error path returns directly without unwinding the nvkm_device that was just allocated by nvkm_device_pci_new(). This leaks both the device wrapper and the pci_enable_device() reference taken inside it. Jump to the existing fail_nvkm label so nvkm_device_del() runs and balances both. The leak was introduced when the intermediate nvkm_device_del() between detection and aperture removal was dropped in favor of creating the pci device once.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounting batman-adv keeps a running payload length for queued fragments and uses it to validate a fragment chain before reassembly. That accounting currently allows the accumulated fragment length to be truncated during updates. As a result, malformed fragment chains can bypass the intended validation and drive reassembly with inconsistent length state, leading to a local denial of service. Fix the accounting by storing the accumulated length in a length-typed field and rejecting update overflows before the existing validation logic runs. The fix was verified against the original reproducer and against valid fragment reassembly paths.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_hbh: reject oversized option lists struct ip6t_opts stores at most IP6T_OPTS_OPTSNR option descriptors, but hbh_mt6_check() does not reject larger optsnr values supplied from userspace. Validate optsnr in the rule setup path so only match data that fits the fixed-size opts array can be installed. This follows the existing xtables pattern of rejecting invalid user-provided counts in checkentry() and keeps the packet matching path unchanged. `struct ip6t_opts` has a fixed `opts[IP6T_OPTS_OPTSNR]` array, where `IP6T_OPTS_OPTSNR` is 16, then off-by-one array access is possible: [ 137.924693][ T8692] UBSAN: array-index-out-of-bounds in ../net/ipv6/netfilter/ip6t_hbh.c:110:29 [ 137.926167][ T8692] index 16 is out of range for type '__u16 [16]'


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: batman-adv: frag: disallow unicast fragment in fragment batadv_frag_skb_buffer() is called by batadv_batman_skb_recv() when a BATADV_UNICAST_FRAG packet is received. Once all fragments are collected and the packet is reassembled, batadv_recv_frag_packet() calls batadv_batman_skb_recv() again to process the defragmented payload. A malicious sender can craft a BATADV_UNICAST_FRAG packet whose reassembled payload is itself a BATADV_UNICAST_FRAG packet (matryoshka-style nesting). Each nesting level recurses through batadv_batman_skb_recv() without bound, growing the kernel stack until it is exhausted. Since refragmentation or fragments in fragments are not actually allowed, discard all packets which are still BATADV_UNICAST_FRAG packets after the defragmentation process.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix tp_meter counter underflow during shutdown batadv_tp_sender_shutdown() unconditionally decrements the "sending" atomic counter. If multiple paths (e.g. timeout, user cancel, and normal finish) call this function, the counter can underflow to -1. Since the sender logic treats any non-zero value as "still sending", a negative value causes the sender kthread to loop indefinitely. This leads to a use-after-free when the interface is removed while the zombie thread is still active. Fix this by using atomic_xchg() to ensure the counter only transitions from 1 to 0 once. [sven: added missing change in batadv_tp_send]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: handle forward allocation error batadv_dat_forward_data() calls pskb_copy_for_clone() to duplicate an skb for each DHT candidate, but does not check the return value before passing it to batadv_send_skb_prepare_unicast_4addr(). That function dereferences the skb unconditionally, so a failed allocation triggers a NULL pointer dereference. Skip forwarding to the current DHT candidate on allocation failure.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only invoked when the association is moved into COOKIE_WAIT during association setup/reconfiguration. In this path, the outbound stream scheduler state (stream->out_curr) is expected to be clean, since no user data should have been transmitted yet unless the state machine has already partially progressed. However, a corner case exists in sctp_sf_do_5_2_6_stale(): when a Stale Cookie ERROR is received, the association is rolled back from COOKIE_ECHOED to COOKIE_WAIT. In this scenario, user data may already have been queued and even bundled with the COOKIE-ECHO chunk. During the rollback, sctp_stream_update() frees the old stream table and installs a new one, but it does not invalidate stream->out_curr. As a result, out_curr may still point to a freed sctp_stream_out entry from the previous stream state. Later, SCTP scheduler dequeue paths (FCFS, RR, PRIO, etc.) rely on stream->out_curr->ext, which can lead to use-after-free once the old stream state has been released via sctp_stream_free(). This results in crashes such as (reported by Yuqi): BUG: KASAN: slab-use-after-free in sctp_sched_fcfs_dequeue+0x13a/0x140 Read of size 8 at addr ff1100004d4d3208 by task mini_poc/9312 CPU: 1 UID: 1001 PID: 9312 Comm: mini_poc Not tainted 7.1.0-rc1-00305-gbd3a4795d574 #5 PREEMPT(full) sctp_sched_fcfs_dequeue+0x13a/0x140 sctp_outq_flush+0x1603/0x33e0 sctp_do_sm+0x31c9/0x5d30 sctp_assoc_bh_rcv+0x392/0x6f0 sctp_inq_push+0x1db/0x270 sctp_rcv+0x138d/0x3c10 Fix this by fully purging the association outqueue when handling the Stale Cookie case. This ensures all pending transmit and retransmit state is dropped, and any scheduler cached pointers are invalidated, making it safe to rebuild stream state during COOKIE_WAIT restart. Updating only stream->out_curr would be insufficient, since queued and retransmittable data would still reference the old stream state and trigger later use-after-free in dequeue paths.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: batman-adv: clear current gateway during teardown batadv_gw_node_free() removes the gateway list entries during mesh teardown, but it does not clear the currently selected gateway. This leaves stale gateway state behind across cleanup and can break a later mesh recreation. Clear bat_priv->gw.curr_gw before walking the gateway list so the selected gateway reference is dropped as part of teardown.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit sender vars batadv_tp_recv_ack() and batadv_tp_stop() are only valid for tp_vars in the BATADV_TP_SENDER role. When called with a BATADV_TP_RECEIVER role, it proceeds to read sender-only members that were never initialized, leading to undefined behavior. This can be triggered when a node that is currently acting as a receiver in an ongoing tp_meter session receives a malicious ACK packet. Guard against this by checking tp_vars->role immediately after the lookup and bailing out if it is not BATADV_TP_SENDER, before any of those members are accessed.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix signed comparison in io_poll_get_ownership() io_poll_get_ownership() uses a signed comparison to check whether poll_refs has reached the threshold for the slowpath: if (unlikely(atomic_read(&req->poll_refs) >= IO_POLL_REF_BIAS)) atomic_read() returns int (signed). When IO_POLL_CANCEL_FLAG (BIT(31)) is set in poll_refs, the value becomes negative in signed arithmetic, so the >= 128 comparison always evaluates to false and the slowpath is never taken. Fix this by casting the atomic_read() result to unsigned int before the comparison, so that the cancel flag is treated as a large positive value and correctly triggers the slowpath.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: jitterentropy - replace long-held spinlock with mutex jent_kcapi_random() serializes the shared jitterentropy state, but it currently holds a spinlock across the jent_read_entropy() call. That path performs expensive jitter collection and SHA3 conditioning, so parallel readers can trigger stalls as contending waiters spin for the same lock. To prevent non-preemptible lock hold, replace rng->jent_lock with a mutex so contended readers sleep instead of spinning on a shared lock held across expensive entropy generation.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl While fuzzing with Syzkaller, a persistent `schedule_timeout: wrong timeout value` warning was observed, accompanied by SMBus controller state machine corruption. The I2C_TIMEOUT ioctl accepts a user-provided timeout in multiples of 10 ms. The user argument is checked against INT_MAX, but it is subsequently multiplied by 10 before being passed to msecs_to_jiffies(). A malicious user can pass a large value (e.g., 429496729) that passes the `arg > INT_MAX` check but overflows when multiplied by 10. This results in a truncated 32-bit unsigned value that bypasses the internal `(int)m < 0` check in `msecs_to_jiffies()`. The truncated value is then assigned to `client->adapter->timeout` (a signed 32-bit int), which is reinterpreted as a negative number. When passed to wait_for_completion_timeout(), this negative value undergoes sign extension to a 64-bit unsigned long, triggering the `schedule_timeout` warning and causing premature returns. This leaves the SMBus state machine in an unrecoverable state, constituting a local Denial of Service (DoS). Fix this by bounding the user argument to `INT_MAX / 10`. [wsa: move the comment as well]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/xe/dma-buf: handle empty bo and UAF races There look to be some nasty races here when triggering the invalidate_mappings hook: 1) We do xe_bo_alloc() followed by the attach, before the actual full bo init step in xe_dma_buf_init_obj(). However the bo is visible on the attachments list after the attach. This is bad since exporter driver, say amdgpu, can at any time call back into our invalidate_mappings hook, with an empty/bogus bo, leading to potential bugs/crashes. 2) Similar to 1) but here we get a UAF, when the invalidate_mappings hook is triggered. For example, we get as far as xe_bo_init_locked() but this fails in some way. But here the bo will be freed on error, but we still have it attached from dma-buf pov, so if the invalidate_mappings is now triggered then the bo we access is gone and we trigger UAF and more bugs/crashes. To fix this, move the attach step until after we actually have a fully set up buffer object. Note that the bo is not published to userspace until later, so not sure what the comment "Don't publish the bo until we have a valid attachment", is referring to. We have at least two different customers reporting hitting a NULL ptr deref in evict_flags when importing something from amdgpu, followed by triggering the evict flow. Hit rate is also pretty low, which would hint at some kind of race, so something like 1) or 2) might explain this. v2: - Shuffle the order of the ops slightly (no functional change) - Improve the comment to better explain the ordering (Matt B) (cherry picked from commit af1f2ad0c59fe4e2f924c526f66e968289d77971)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix oops due to out of scope access Below oops triggers when kill QEMU process: Oops: general protection fault, probably for non-canonical address 0x7fffffff844eaaa7: 0000 [#1] SMP NOPTI Call Trace: <TASK> do_raw_spin_lock+0xaa/0xc0 _raw_spin_lock_irqsave+0x21/0x40 domain_remove_dev_pasid+0x52/0x160 intel_nested_set_dev_pasid+0x1b9/0x1e0 __iommu_set_group_pasid+0x56/0x120 pci_dev_reset_iommu_done+0xe3/0x180 pcie_flr+0x65/0x160 __pci_reset_function_locked+0x5b/0x120 vfio_pci_core_close_device+0x63/0xe0 [vfio_pci_core] vfio_df_close+0x4f/0xa0 vfio_df_unbind_iommufd+0x2d/0x60 vfio_device_fops_release+0x3e/0x40 __fput+0xe5/0x2c0 task_work_run+0x58/0xa0 do_exit+0x2c8/0x600 do_group_exit+0x2f/0xa0 get_signal+0x863/0x8c0 arch_do_signal_or_restart+0x24/0x100 exit_to_user_mode_loop+0x87/0x380 do_syscall_64+0x2ff/0x11e0 entry_SYSCALL_64_after_hwframe+0x76/0x7e The global static blocked domain is a dummy domain without corresponding dmar_domain structure, accessing beyond iommu_domain structure triggers oops easily. Fix it by return early in domain_remove_dev_pasid() like identity domain.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crush_decode() A message of type CEPH_MSG_OSD_MAP containing a crush map with at least one bucket has two fields holding the bucket algorithm. If the values in these two fields differ, an out-of-bounds access can occur. This is the case because the first algorithm field (alg) is used to allocate the correct amount of memory for a bucket of this type, while the second algorithm field inside the bucket (b->alg) is used in the subsequent processing. This patch fixes the issue by adding a check that compares alg and b->alg and aborts the processing in case they differ. Furthermore, b->alg is set to 0 in this case, because the destruction of the crush map also uses this field to determine the bucket type, which can again result in an out-of-bounds access when trying to free the memory pointed to by the fields of the bucket. To correctly free the memory allocated for the bucket in such a case, the corresponding call to kfree is moved from the algorithm-specific crush_destroy_bucket functions to the generic crush_destroy_bucket().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() In __ceph_x_decrypt(), a part of the buffer p is interpreted as a ceph_x_encrypt_header, and the magic field of this struct is accessed. This happens without any guarantee that the buffer is large enough to hold this struct. The function parameter ciphertext_len represents the length of the ciphertext to decrypt and is guaranteed to be at most the remaining size of the allocated buffer p. However, this value is not necessarily greater than sizeof(ceph_x_encrypt_header). E.g., a message frame of type FRAME_TAG_AUTH_REPLY_MORE, that is just as long to hold the ciphertext at its end with a ciphertext_len of 8 or less, can trigger an out-of-bounds memory access when accessing hdr->magic. This patch fixes the issue by adding a check to ensure that the decrypted plaintext in the buffer is large enough to represent at least the ceph_x_encrypt_header.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdmap_decode() When decoding osd_state and osd_weight from an incoming osdmap in osdmap_decode(), both are decoded for each osd, i.e., map->max_osd times. The ceph_decode_need() check only accounts for sizeof(*map->osd_weight) once. This can potentially result in an out-of-bounds memory access if the incoming message is corrupted such that the max_osd value exceeds the actual content of the osdmap message. This patch fixes the issue by changing the corresponding part in the ceph_decode_need() check to account for map->max_osd*sizeof(*map->osd_weight).


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size The generic/642 test-case can reproduce the kernel crash: [40243.605254] ------------[ cut here ]------------ [40243.605956] kernel BUG at fs/ceph/xattr.c:918! [40243.607142] Oops: invalid opcode: 0000 [#1] SMP PTI [40243.608067] CPU: 7 UID: 0 PID: 498762 Comm: kworker/7:1 Not tainted 7.0.0-rc7+ #3 PREEMPT(full) [40243.609700] Hardware name: QEMU Ubuntu 25.10 PC v2 (i440FX + PIIX, + 10.1 machine, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [40243.611820] Workqueue: ceph-msgr ceph_con_workfn [40243.612715] RIP: 0010:__ceph_build_xattrs_blob+0x1b8/0x1e0 [40243.613731] Code: 0f 84 82 fe ff ff e9 cf 8e 56 ff 48 8d 65 e8 31 c0 5b 41 5c 41 5d 5d 31 d2 31 c9 31 f6 31 ff 45 31 c0 45 31 c9 c3 cc cc cc cc <0f> 0b 4c 8b 62 08 41 8b 85 24 07 00 00 49 83 c4 04 41 89 44 24 fc [40243.616888] RSP: 0018:ffffcc80c4d4b688 EFLAGS: 00010287 [40243.617773] RAX: 0000000000010026 RBX: 0000000000000001 RCX: 0000000000000000 [40243.618928] RDX: ffff8a773798dee0 RSI: 0000000000000000 RDI: 0000000000000000 [40243.620158] RBP: ffffcc80c4d4b6a0 R08: 0000000000000000 R09: 0000000000000000 [40243.621573] R10: 0000000000000000 R11: 0000000000000000 R12: ffff8a75f3b58000 [40243.622907] R13: ffff8a75f3b58000 R14: 0000000000000080 R15: 000000000000bffd [40243.624054] FS: 0000000000000000(0000) GS:ffff8a787d1b4000(0000) knlGS:0000000000000000 [40243.625331] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [40243.626269] CR2: 000072f390b623c0 CR3: 000000011c02a003 CR4: 0000000000372ef0 [40243.627408] Call Trace: [40243.627839] <TASK> [40243.628188] __prep_cap+0x3fd/0x4a0 [40243.628789] ? do_raw_spin_unlock+0x4e/0xe0 [40243.629474] ceph_check_caps+0x46a/0xc80 [40243.630094] ? __lock_acquire+0x4a2/0x2650 [40243.630773] ? find_held_lock+0x31/0x90 [40243.631347] ? handle_cap_grant+0x79f/0x1060 [40243.632068] ? lock_release+0xd9/0x300 [40243.632696] ? __mutex_unlock_slowpath+0x3e/0x340 [40243.633429] ? lock_release+0xd9/0x300 [40243.634052] handle_cap_grant+0xcf6/0x1060 [40243.634745] ceph_handle_caps+0x122b/0x2110 [40243.635415] mds_dispatch+0x5bd/0x2160 [40243.636034] ? ceph_con_process_message+0x65/0x190 [40243.636828] ? lock_release+0xd9/0x300 [40243.637431] ceph_con_process_message+0x7a/0x190 [40243.638184] ? kfree+0x311/0x4f0 [40243.638749] ? kfree+0x311/0x4f0 [40243.639268] process_message+0x16/0x1a0 [40243.639915] ? sg_free_table+0x39/0x90 [40243.640572] ceph_con_v2_try_read+0xf58/0x2120 [40243.641255] ? lock_acquire+0xc8/0x300 [40243.641863] ceph_con_workfn+0x151/0x820 [40243.642493] process_one_work+0x22f/0x630 [40243.643093] ? process_one_work+0x254/0x630 [40243.643770] worker_thread+0x1e2/0x400 [40243.644332] ? __pfx_worker_thread+0x10/0x10 [40243.645020] kthread+0x109/0x140 [40243.645560] ? __pfx_kthread+0x10/0x10 [40243.646125] ret_from_fork+0x3f8/0x480 [40243.646752] ? __pfx_kthread+0x10/0x10 [40243.647316] ? __pfx_kthread+0x10/0x10 [40243.647919] ret_from_fork_asm+0x1a/0x30 [40243.648556] </TASK> [40243.648902] Modules linked in: overlay hctr2 libpolyval chacha libchacha adiantum libnh libpoly1305 essiv intel_rapl_msr intel_rapl_common intel_uncore_frequency_common skx_edac_common nfit kvm_intel kvm irqbypass joydev ghash_clmulni_intel aesni_intel rapl input_leds mac_hid psmouse vga16fb serio_raw vgastate floppy i2c_piix4 pata_acpi bochs qemu_fw_cfg i2c_smbus sch_fq_codel rbd dm_crypt msr parport_pc ppdev lp parport efi_pstore [40243.654766] ---[ end trace 0000000000000000 ]--- Commit d93231a6bc8a ("ceph: prevent a client from exceeding the MDS maximum xattr size") moved the required_blob_size computation to before the __build_xattrs() call, introducing a race. __build_xattrs() releases and reacquires i_ceph_lock during execution. In that window, handle_cap_grant() may update i_xattrs.blob with a newer MDS-provided blob and bump i_xattrs.version. When __bui ---truncated---


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Bound MIDI endpoint descriptor scans snd_usbmidi_get_ms_info() validates the internal MIDIStreaming endpoint descriptor size before using baAssocJackID[], but the descriptor walker can still return a class-specific endpoint descriptor whose bLength exceeds the remaining bytes in the endpoint-extra scan. That leaves later flexible-array reads bounded by bLength, but not by the remaining bytes in the endpoint-extra scan. Stop walking when bLength is zero or extends past the remaining endpoint-extra scan.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans The USB MIDI 2.0 endpoint parser has the same descriptor walking pattern as the legacy MIDI parser. It validates bLength against bNumGrpTrmBlock before reading baAssoGrpTrmBlkID[], but not against the remaining bytes in the endpoint-extra scan. A malformed device can therefore make later baAssoGrpTrmBlkID[] reads consume bytes past the walked descriptor. Reject zero-length and overlong descriptors while walking endpoint extras.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() Two error handling issues exist in xe_exec_queue_create_ioctl(): 1. When xe_hw_engine_group_add_exec_queue() fails, the error path jumps to put_exec_queue which skips xe_exec_queue_kill(). If the VM is in preempt fence mode, xe_vm_add_compute_exec_queue() has already added the queue to the VM's compute exec queue list. Skipping the kill leaves the queue on that list, leading to a dangling pointer after the queue is freed. 2. When xa_alloc() fails after xe_hw_engine_group_add_exec_queue() has succeeded, the error path does not call xe_hw_engine_group_del_exec_queue() to remove the queue from the hw engine group list. The queue is then freed while still linked into the hw engine group, causing a use-after-free. Fix both by: - Changing the xe_hw_engine_group_add_exec_queue() failure path to jump to kill_exec_queue so that xe_exec_queue_kill() properly removes the queue from the VM's compute list. - Adding a del_hw_engine_group label before kill_exec_queue for the xa_alloc() failure path, which removes the queue from the hw engine group before proceeding with the rest of the cleanup. (cherry picked from commit 37c831f401746a45d510b312b0ed7a77b1e06ec8)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: neigh: let neigh_xmit take skb ownership neigh_xmit always releases the skb, except when no neighbour table is found. But even the first added user of neigh_xmit (mpls) relied on neigh_xmit to release the skb (or queue it for tx). sashiko reported: If neigh_xmit() is called with an uninitialized neighbor table (for example, NEIGH_ND_TABLE when IPv6 is disabled), it returns -EAFNOSUPPORT and bypasses its internal out_kfree_skb error path. Because the return value of neigh_xmit() is ignored here, does this leak the SKB? Assume full ownership and remove the last code path that doesn't xmit or free skb.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() syzbot reported a KASAN slab-use-after-free read in rtl8150_start_xmit() when accessing skb->len for tx statistics after usb_submit_urb() has been called: BUG: KASAN: slab-use-after-free in rtl8150_start_xmit+0x71f/0x760 drivers/net/usb/rtl8150.c:712 Read of size 4 at addr ffff88810eb7a930 by task kworker/0:4/5226 The URB completion handler write_bulk_callback() frees the skb via dev_kfree_skb_irq(dev->tx_skb). The URB may complete on another CPU in softirq context before usb_submit_urb() returns in the submitter, so by the time the submitter reads skb->len the skb has already been queued to the per-CPU completion_queue and freed by net_tx_action(): CPU A (xmit) CPU B (USB completion softirq) ------------ ------------------------------ dev->tx_skb = skb; usb_submit_urb() --+ |-------> write_bulk_callback() | dev_kfree_skb_irq(dev->tx_skb) | net_tx_action() | napi_skb_cache_put() <-- free netdev->stats.tx_bytes | += skb->len; <-- UAF read Fix it by caching skb->len before submitting the URB and using the cached value when updating the tx_bytes counter. The pre-existing tx_bytes semantics are preserved: the counter tracks the original frame length (skb->len), not the ETH_ZLEN/USB-alignment padded "count" value that is handed to the device. Changing that would be a user-visible accounting change and is out of scope for this UAF fix.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers Currently, when nvmet_tcp_build_pdu_iovec() detects an out-of-bounds PDU length or offset, it triggers nvmet_tcp_fatal_error(cmd->queue) and returns early. However, because the function returns void, the callers are entirely unaware that a fatal error has occurred and that the cmd->recv_msg.msg_iter was left uninitialized. Callers such as nvmet_tcp_handle_h2c_data_pdu() proceed to blindly overwrite the queue state with queue->rcv_state = NVMET_TCP_RECV_DATA Consequently, the socket receiving loop may attempt to read incoming network data into the uninitialized iterator. Fix this by shifting the error handling responsibility to the callers.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was being called with a pointer to a local variable which was a copy of the caller's skb pointer. If the skb was reallocated and validation subsequently failed, the error handling path would free the original skb pointer, which had already been freed, leading to double-free. Fix this by checking if head now points to a newly allocated reassembled skb. If it does, reassign *headbuf for later freeing operations.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/rds: zero per-item info buffer before handing it to visitors rds_for_each_conn_info() and rds_walk_conn_path_info() both hand a caller-allocated on-stack u64 buffer to a per-connection visitor and then copy the full item_len bytes back to user space via rds_info_copy() regardless of how much of the buffer the visitor actually wrote. rds_ib_conn_info_visitor() and rds6_ib_conn_info_visitor() only write a subset of their output struct when the underlying rds_connection is not in state RDS_CONN_UP (src/dst addr, tos, sl and the two GIDs via explicit memsets). Several u32 fields (max_send_wr, max_recv_wr, max_send_sge, rdma_mr_max, rdma_mr_size, cache_allocs) and the 2-byte alignment hole between sl and cache_allocs remain as whatever stack contents preceded the visitor call and are then memcpy_to_user()'d out to user space. struct rds_info_rdma_connection and struct rds6_info_rdma_connection are the only rds_info_* structs in include/uapi/linux/rds.h that are not marked __attribute__((packed)), so they have a real alignment hole. The other info visitors (rds_conn_info_visitor, rds6_conn_info_visitor, rds_tcp_tc_info, ...) write all fields of their packed output struct today and are not known to be vulnerable, but a future visitor that adds a conditional write-path would have the same bug. Reproduction on a kernel built without CONFIG_INIT_STACK_ALL_ZERO=y: a local unprivileged user opens AF_RDS, sets SO_RDS_TRANSPORT=IB, binds to a local address on an RDMA-capable netdev (rxe soft-RoCE on any netdev is sufficient), sendto()'s any peer on the same subnet (fails cleanly but installs an rds_connection in the global hash in RDS_CONN_CONNECTING), then calls getsockopt(SOL_RDS, RDS_INFO_IB_CONNECTIONS). The returned 68-byte item contains 26 bytes of stack garbage including kernel text/data pointers: 0..7 0a 63 00 01 0a 63 00 02 src=10.99.0.1 dst=10.99.0.2 8..39 00 ... gids (memset-zeroed) 40..47 e0 92 a3 81 ff ff ff ff kernel pointer (max_send_wr) 48..55 7f 37 b5 81 ff ff ff ff kernel pointer (rdma_mr_max) 56..59 01 00 08 00 rdma_mr_size (garbage) 60..61 00 00 tos, sl 62..63 00 00 alignment padding 64..67 18 00 00 00 cache_allocs (garbage) Fix by zeroing the per-item buffer in both rds_for_each_conn_info() and rds_walk_conn_path_info() before invoking the visitor. This covers the IPv4/IPv6 IB visitors and hardens all current and future visitors against the same class of bug. No functional change for visitors that fully populate their output. Changes in v2: - retarget at the net tree (subject prefix "[PATCH net v2]", net/rds: prefix in the title) - pick up Reviewed-by tags from Sharath Srinivasan and Allison Henderson


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: pppoe: drop PFC frames RFC 2516 Section 7 states that Protocol Field Compression (PFC) is NOT RECOMMENDED for PPPoE. In practice, pppd does not support negotiating PFC for PPPoE sessions, and the current PPPoE driver assumes an uncompressed (2-byte) protocol field. However, the generic PPP layer function ppp_input() is not aware of the negotiation result, and still accepts PFC frames. If a peer with a broken implementation or an attacker sends a frame with a compressed (1-byte) protocol field, the subsequent PPP payload is shifted by one byte. This causes the network header to be 4-byte misaligned, which may trigger unaligned access exceptions on some architectures. To reduce the attack surface, drop PPPoE PFC frames. Introduce ppp_skb_is_compressed_proto() helper function to be used in both ppp_generic.c and pppoe.c to avoid open-coding.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks sctp_getsockopt_peer_auth_chunks() checks that the caller's optval buffer is large enough for the peer AUTH chunk list with if (len < num_chunks) return -EINVAL; but then writes num_chunks bytes to p->gauth_chunks, which lives at offset offsetof(struct sctp_authchunks, gauth_chunks) == 8 inside optval. The check is missing the sizeof(struct sctp_authchunks) = 8-byte header. When the caller supplies len == num_chunks (for any num_chunks > 0) the test passes but copy_to_user() writes sizeof(struct sctp_authchunks) = 8 bytes past the declared buffer. The sibling function sctp_getsockopt_local_auth_chunks() at the next line already has the correct check: if (len < sizeof(struct sctp_authchunks) + num_chunks) return -EINVAL; Align the peer variant with its sibling. Reproducer confirms on v7.0-13-generic: an unprivileged userspace caller that opens a loopback SCTP association with AUTH enabled, queries num_chunks with a short optval, then issues the real getsockopt with len == num_chunks and sentinel bytes painted past the buffer observes those sentinel bytes overwritten with the peer's AUTH chunk type. The bytes written are under the peer's control but land in the caller's own userspace; this is not a kernel memory corruption, but it is a kernel-side contract violation that can silently corrupt adjacent userspace data.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points to it and is marked as valid (ICE_TX_BUF_SKB). 'next_to_use' remains unchanged, so the potential problem will likely fix itself when the next packet is transmitted and the tx_buf gets overwritten. But if there is no next packet and the interface is brought down instead, ice_clean_tx_ring() -> ice_unmap_and_free_tx_buf() will find the tx_buf and free the skb for the second time. The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error path, so that ice_unmap_and_free_tx_buf(). Move the initialization of 'first' up, to ensure it's already valid in case we hit the linearization error path. The bug was spotted by AI while I had it looking for something else. It also proposed an initial version of the patch. I reproduced the bug and tested the fix by adding code to inject failures, on a build with KASAN. I looked for similar bugs in related Intel drivers and did not find any.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF macvlan_get_size() does not account for IFLA_MACVLAN_BC_CUTOFF, but macvlan_fill_info() conditionally includes it when port->bc_cutoff != 1. This causes nla_put_s32() to fail with -EMSGSIZE when the netlink skb runs out of space, triggering a WARN_ON in rtnetlink and preventing the interface from being dumped. The bug can be reproduced with: ip link add macvlan0 link eth0 type macvlan mode bridge ip link set macvlan0 type macvlan bc_cutoff 0 ip -d link show macvlan0 # fails with -EMSGSIZE The bc_cutoff feature was added in commit 954d1fa1ac93 ("macvlan: Add netlink attribute for broadcast cutoff"), which added the nla_put_s32() call in macvlan_fill_info() but missed adding the corresponding nla_total_size(4) in macvlan_get_size(). A follow-up commit 55cef78c244d ("macvlan: add forgotten nla_policy for IFLA_MACVLAN_BC_CUTOFF") fixed the missing nla_policy entry but still did not fix the size calculation.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix integer overflow in UNMAP bounds check sbc_execute_unmap() checks LBA + range does not exceed the device capacity, but does not guard against LBA + range wrapping around on 64-bit overflow. Add an overflow check matching the pattern already used for WRITE_SAME in the same file.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: bound enumeration string aggregation populate_enum_data() aggregates firmware-provided value-modifier and possible-value strings into fixed 512-byte struct members. The current code bounds each individual source string but then appends every string and separator with raw strcat() and no remaining-space check. Switch the aggregation loops to a bounded append helper and reject enumeration packages whose combined strings do not fit in the destination buffers. [ij: add include]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix af_unix iter deadlock bpf_iter_unix_seq_show() may deadlock when lock_sock_fast() takes the fast path and the iter prog attempts to update a sockmap. Which ends up spinning at sock_map_update_elem()'s bh_lock_sock(): WARNING: possible recursive locking detected test_progs/1393 is trying to acquire lock: ffff88811ec25f58 (slock-AF_UNIX){+...}-{3:3}, at: sock_map_update_elem+0xdb/0x1f0 but task is already holding lock: ffff88811ec25f58 (slock-AF_UNIX){+...}-{3:3}, at: __lock_sock_fast+0x37/0xe0 other info that might help us debug this: Possible unsafe locking scenario: CPU0 ---- lock(slock-AF_UNIX); lock(slock-AF_UNIX); *** DEADLOCK *** May be due to missing lock nesting notation 4 locks held by test_progs/1393: #0: ffff88814b59c790 (&p->lock){+.+.}-{4:4}, at: bpf_seq_read+0x59/0x10d0 #1: ffff88811ec25fd8 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: bpf_seq_read+0x42c/0x10d0 #2: ffff88811ec25f58 (slock-AF_UNIX){+...}-{3:3}, at: __lock_sock_fast+0x37/0xe0 #3: ffffffff85a6a7c0 (rcu_read_lock){....}-{1:3}, at: bpf_iter_run_prog+0x51d/0xb00 Call Trace: dump_stack_lvl+0x5d/0x80 print_deadlock_bug.cold+0xc0/0xce __lock_acquire+0x130f/0x2590 lock_acquire+0x14e/0x2b0 _raw_spin_lock+0x30/0x40 sock_map_update_elem+0xdb/0x1f0 bpf_prog_2d0075e5d9b721cd_dump_unix+0x55/0x4f4 bpf_iter_run_prog+0x5b9/0xb00 bpf_iter_unix_seq_show+0x1f7/0x2e0 bpf_seq_read+0x42c/0x10d0 vfs_read+0x171/0xb20 ksys_read+0xff/0x200 do_syscall_64+0x6b/0x3a0 entry_SYSCALL_64_after_hwframe+0x76/0x7e


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bpf, arm64: Fix off-by-one in check_imm signed range check check_imm(bits, imm) is used in the arm64 BPF JIT to verify that a branch displacement (in arm64 instruction units) fits into the signed N-bit immediate field of a B, B.cond or CBZ/CBNZ encoding before it is handed to the encoder. The macro currently tests for (imm > 0 && imm >> bits) || (imm < 0 && ~imm >> bits) which admits values in [-2^N, 2^N) - effectively a signed (N+1)-bit range. A signed N-bit field only holds [-2^(N-1), 2^(N-1)), so the check admits one extra bit of range on each side. In particular, for check_imm19(), values in [2^18, 2^19) slip past the check but do not fit into the 19-bit signed imm19 field of B.cond. aarch64_insn_encode_immediate() then masks the raw value into the 19-bit field, setting bit 18 (the sign bit) and flipping a forward branch into a backward one. Same class of issue exists for check_imm26() and the B/BL encoding. Shift by (bits - 1) instead of bits so the actual signed N-bit range is enforced.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: fix deadlock in hid_post_reset() You can build a USB device that includes a HID component and a storage or UAS component. The components can be reset only together. That means that hid_pre_reset() and hid_post_reset() are in the block IO error handling. Hence no memory allocation used in them may do block IO because the IO can deadlock on the mutex held while resetting a device and calling the interface drivers. Use GFP_NOIO for all allocations in them.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate group add input before caching [BUG] OCFS2_IOC_GROUP_ADD can trigger a BUG_ON in ocfs2_set_new_buffer_uptodate(): kernel BUG at fs/ocfs2/uptodate.c:509! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI RIP: 0010:ocfs2_set_new_buffer_uptodate+0x194/0x1e0 fs/ocfs2/uptodate.c:509 Code: ffffe88f 42b9fe4c 89e64889 dfe8b4df Call Trace: ocfs2_group_add+0x3f1/0x1510 fs/ocfs2/resize.c:507 ocfs2_ioctl+0x309/0x6e0 fs/ocfs2/ioctl.c:887 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:597 [inline] __se_sys_ioctl fs/ioctl.c:583 [inline] __x64_sys_ioctl+0x197/0x1e0 fs/ioctl.c:583 x64_sys_call+0x1144/0x26a0 arch/x86/include/generated/asm/syscalls_64.h:17 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x93/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7bbfb55a966d [CAUSE] ocfs2_group_add() calls ocfs2_set_new_buffer_uptodate() on a user-controlled group block before ocfs2_verify_group_and_input() validates that block number. That helper is only valid for newly allocated metadata and asserts that the block is not already present in the chosen metadata cache. The code also uses INODE_CACHE(inode) even though the group descriptor belongs to main_bm_inode and later journal accesses use that cache context instead. [FIX] Validate the on-disk group descriptor before caching it, then add it to the metadata cache tracked by INODE_CACHE(main_bm_inode). Keep the validation failure path separate from the later cleanup path so we only remove the buffer from that cache after it has actually been inserted. This keeps the group buffer lifetime consistent across validation, journaling, and cleanup.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: memory: tegra124-emc: Fix dll_change check The code checking whether the specified memory timing enables DLL in the EMRS register was reversed. DLL is enabled if bit A0 is low. Fix the check.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: efi/capsule-loader: fix incorrect sizeof in phys array reallocation The krealloc() call for cap_info->phys in __efi_capsule_setup_info() uses sizeof(phys_addr_t *) instead of sizeof(phys_addr_t), which might be causing an undersized allocation. The allocation is also inconsistent with the initial array allocation in efi_capsule_open() that allocates one entry with sizeof(phys_addr_t), and the efi_capsule_write() function that stores phys_addr_t values (not pointers) via page_to_phys(). On 64-bit systems where sizeof(phys_addr_t) == sizeof(phys_addr_t *), this goes unnoticed. On 32-bit systems with PAE where phys_addr_t is 64-bit but pointers are 32-bit, this allocates half the required space, which might lead to a heap buffer overflow when storing physical addresses. This is similar to the bug fixed in commit fccfa646ef36 ("efi/capsule-loader: fix incorrect allocation size") which fixed the same issue at the initial allocation site.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(), gfs2_ail1_wait(), and gfs2_ail1_empty() without holding sdp->sd_log_flush_lock, but these functions require exclusion against concurrent transactions. To fix that, add a non-locking __gfs2_log_flush() function. Then, in gfs2_logd(), take sdp->sd_log_flush_lock before calling the above mentioned log flushing functions and __gfs2_log_flush().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: quota: Fix race of dquot_scan_active() with quota deactivation dquot_scan_active() can race with quota deactivation in quota_release_workfn() like: CPU0 (quota_release_workfn) CPU1 (dquot_scan_active) ============================== ============================== spin_lock(&dq_list_lock); list_replace_init( &releasing_dquots, &rls_head); /* dquot X on rls_head, dq_count == 0, DQ_ACTIVE_B still set */ spin_unlock(&dq_list_lock); synchronize_srcu(&dquot_srcu); spin_lock(&dq_list_lock); list_for_each_entry(dquot, &inuse_list, dq_inuse) { /* finds dquot X */ dquot_active(X) -> true atomic_inc(&X->dq_count); } spin_unlock(&dq_list_lock); spin_lock(&dq_list_lock); dquot = list_first_entry(&rls_head); WARN_ON_ONCE(atomic_read(&dquot->dq_count)); The problem is not only a cosmetic one as under memory pressure the caller of dquot_scan_active() can end up working on freed dquot. Fix the problem by making sure the dquot is removed from releasing list when we acquire a reference to it.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: fix mismatch between power and frequency During DPU runtime suspend, calling dev_pm_opp_set_rate(dev, 0) drops the MMCX rail to MIN_SVS while the core clock frequency remains at its original (highest) rate. When runtime resume re-enables the clock, this may result in a mismatch between the rail voltage and the clock rate. For example, in the DPU bind path, the sequence could be: cpu0: dev_sync_state -> rpmhpd_sync_state cpu1: dpu_kms_hw_init timeline 0 ------------------------------------------------> t After rpmhpd_sync_state, the voltage performance is no longer guaranteed to stay at the highest level. During dpu_kms_hw_init, calling dev_pm_opp_set_rate(dev, 0) drops the voltage, causing the MMCX rail to fall to MIN_SVS while the core clock is still at its maximum frequency. When the power is re-enabled, only the clock is enabled, leading to a situation where the MMCX rail is at MIN_SVS but the core clock is at its highest rate. In this state, the rail cannot sustain the clock rate, which may cause instability or system crash. Remove the call to dev_pm_opp_set_rate(dev, 0) from dpu_runtime_suspend to ensure the correct vote is restored when DPU resumes. Patchwork: https://patchwork.freedesktop.org/patch/710077/


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable() In case if we get errors in cdns_mhdp_link_up() or cdns_mhdp_reg_read() in atomic_enable, we will go to cdns_mhdp_modeset_retry_fn() and will hit NULL pointer while trying to access the mutex. We need the connector to be set before that. Unlike in legacy cases with flag !DRM_BRIDGE_ATTACH_NO_CONNECTOR, we do not have connector initialised in bridge_attach(), so add the mhdp->connector_ptr in device structure to handle both cases with DRM_BRIDGE_ATTACH_NO_CONNECTOR and !DRM_BRIDGE_ATTACH_NO_CONNECTOR, set it in atomic_enable() earlier to avoid possible NULL pointer dereference in recovery paths like modeset_retry_fn() with the DRM_BRIDGE_ATTACH_NO_CONNECTOR flag set.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: dm cache metadata: fix memory leak on metadata abort retry When failing to acquire the root_lock in dm_cache_metadata_abort because the block_manager is read-only, the temporary block_manager created outside the root_lock is not properly released, causing a memory leak. Reproduce steps: This can be reproduced by reloading a new table while the metadata is read-only. While the second call to dm_cache_metadata_abort is caused by lack of support for table preload in dm-cache, mentioned in commit 9b1cc9f251af ("dm cache: share cache-metadata object across inactive and active DM tables"), it exposes the memory leak in dm_cache_metadata_abort when the function is called multiple times. Specifically, dm-cache fails to sync the new cache object's mode during preresume, creating the reproducer condition. This issue could also occur through concurrent metadata_operation_failed calls due to races in cache mode updates, but the table preload scenario below provides a reliable reproducer. 1. Create a cache device with some faulty trailing metadata blocks dmsetup create cmeta <<EOF 0 200 linear /dev/sdc 0 200 7992 error EOF dmsetup create cdata --table "0 131072 linear /dev/sdc 8192" dmsetup create corig --table "0 262144 linear /dev/sdc 262144" dd if=/dev/zero of=/dev/mapper/cmeta bs=4k count=1 oflag=direct dmsetup create cache --table "0 131072 cache /dev/mapper/cmeta \ /dev/mapper/cdata /dev/mapper/corig 128 1 writethrough smq 0" 2. Suspend and resume the cache to start a new metadata transaction and trigger metadata io errors on the next metadata commit. dmsetup suspend cache dmsetup resume cache 3. Write to the cache device to update metadata fio --filename=/dev/mapper/cache --name test --rw=randwrite --bs=4k \ --randrepeat=0 --direct=1 --size 64k 4. Preload the same table dmsetup reload cache --table "$(dmsetup table cache)" 5. Resume the new table. This triggers the memory leak. dmsetup suspend cache dmsetup resume cache kmemleak logs: <snip> unreferenced object 0xffff8880080c2010 (size 16): comm "dmsetup", pid 132, jiffies 4294982580 hex dump (first 16 bytes): 00 38 b9 07 80 88 ff ff 6a 6b 6b 6b 6b 6b 6b a5 ... backtrace (crc 3118f31c): kmemleak_alloc+0x28/0x40 __kmalloc_cache_noprof+0x3d9/0x510 dm_block_manager_create+0x51/0x140 dm_cache_metadata_abort+0x85/0x320 metadata_operation_failed+0x103/0x1e0 cache_preresume+0xacd/0xe70 dm_table_resume_targets+0xd3/0x320 __dm_resume+0x1b/0xf0 dm_resume+0x127/0x170 <snip>


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ASoC: sti: use managed regmap_field allocations The regmap_field objects allocated at player init are never freed and may leak resources if the driver is removed. Switch to devm_regmap_field_alloc() to automatically limit the lifetime of the allocations the lifetime of the device.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/sun4i: backend: fix error pointer dereference The function drm_atomic_get_plane_state() can return an error pointer and is not checked for it. Add error pointer check. Detected by Smatch: drivers/gpu/drm/sun4i/sun4i_backend.c:496 sun4i_backend_atomic_check() error: 'plane_state' dereferencing possible ERR_PTR()


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/komeda: fix integer overflow in AFBC framebuffer size check The AFBC framebuffer size validation calculates the minimum required buffer size by adding the AFBC payload size to the framebuffer offset. This addition is performed without checking for integer overflow. If the addition oveflows, the size check may incorrectly succed and allow userspace to provide an undersized drm_gem_object, potentially leading to out-of-bounds memory access. Add usage of check_add_overflow() to safely compute the minimum required size and reject the framebuffer if an overflow is detected. This makes the AFBC size validation more robust against malformed. Found by Linux Verification Center (linuxtesting.org) with SVACE.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: sctp: disable BH before calling udp_tunnel_xmit_skb() udp_tunnel_xmit_skb() / udp_tunnel6_xmit_skb() are expected to run with BH disabled. After commit 6f1a9140ecda ("add xmit recursion limit to tunnel xmit functions"), on the path: udp(6)_tunnel_xmit_skb() -> ip(6)tunnel_xmit() dev_xmit_recursion_inc()/dec() must stay balanced on the same CPU. Without local_bh_disable(), the context may move between CPUs, which can break the inc/dec pairing. This may lead to incorrect recursion level detection and cause packets to be dropped in ip(6)_tunnel_xmit() or __dev_queue_xmit(). Fix it by disabling BH around both IPv4 and IPv6 SCTP UDP xmit paths. In my testing, after enabling the SCTP over UDP: # ip net exec ha sysctl -w net.sctp.udp_port=9899 # ip net exec ha sysctl -w net.sctp.encap_port=9899 # ip net exec hb sysctl -w net.sctp.udp_port=9899 # ip net exec hb sysctl -w net.sctp.encap_port=9899 # ip net exec ha iperf3 -s - without this patch: # ip net exec hb iperf3 -c 192.168.0.1 --sctp [ 5] 0.00-10.00 sec 37.2 MBytes 31.2 Mbits/sec sender [ 5] 0.00-10.00 sec 37.1 MBytes 31.1 Mbits/sec receiver - with this patch: # ip net exec hb iperf3 -c 192.168.0.1 --sctp [ 5] 0.00-10.00 sec 3.14 GBytes 2.69 Gbits/sec sender [ 5] 0.00-10.00 sec 3.14 GBytes 2.69 Gbits/sec receiver


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error When hci_register_dev() fails in hci_uart_register_dev() HCI_UART_PROTO_INIT is not cleared before calling hu->proto->close(hu) and setting hu->hdev to NULL. This means incoming UART data will reach the protocol-specific recv handler in hci_uart_tty_receive() after resources are freed. Clear HCI_UART_PROTO_INIT with a write lock before calling hu->proto->close() and setting hu->hdev to NULL. The write lock ensures all active readers have completed and no new reader can enter the protocol recv path before resources are freed. This allows the protocol-specific recv functions to remove the "HCI_UART_REGISTERED" guard without risking a null pointer dereference if hci_register_dev() fails.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls /dev/ppp open is currently authorized against file->f_cred->user_ns, while unattached administrative ioctls operate on current->nsproxy->net_ns. As a result, a local unprivileged user can create a new user namespace with CLONE_NEWUSER, gain CAP_NET_ADMIN only in that new user namespace, and still issue PPPIOCNEWUNIT, PPPIOCATTACH, or PPPIOCATTCHAN against an inherited network namespace. Require CAP_NET_ADMIN in the user namespace that owns the target network namespace before handling unattached PPP administrative ioctls. This preserves normal pppd operation in the network namespace it is actually privileged in, while rejecting the userns-only inherited-netns case.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops When a BPF sock_ops program accesses ctx fields with dst_reg == src_reg, the SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros fail to zero the destination register in the !fullsock / !locked_tcp_sock path. Both macros borrow a temporary register to check is_fullsock / is_locked_tcp_sock when dst_reg == src_reg, because dst_reg holds the ctx pointer. When the check is false (e.g., TCP_NEW_SYN_RECV state with a request_sock), dst_reg should be zeroed but is not, leaving the stale ctx pointer: - SOCK_OPS_GET_SK: dst_reg retains the ctx pointer, passes NULL checks as PTR_TO_SOCKET_OR_NULL, and can be used as a bogus socket pointer, leading to stack-out-of-bounds access in helpers like bpf_skc_to_tcp6_sock(). - SOCK_OPS_GET_FIELD: dst_reg retains the ctx pointer which the verifier believes is a SCALAR_VALUE, leaking a kernel pointer. Fix both macros by: - Changing JMP_A(1) to JMP_A(2) in the fullsock path to skip the added instruction. - Adding BPF_MOV64_IMM(si->dst_reg, 0) after the temp register restore in the !fullsock path, placed after the restore because dst_reg == src_reg means we need src_reg intact to read ctx->temp.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_fw: fix NULL dereference of "old" filters before change() Like pointed out by Sashiko [1], since commit ed76f5edccc9 ("net: sched: protect filter_chain list with filter_chain_lock mutex") TC filters are added to a shared block and published to datapath before their ->change() function is called. This is a problem for cls_fw: an invalid filter created with the "old" method can still classify some packets before it is destroyed by the validation logic added by Xiang. Therefore, insisting with repeated runs of the following script: # ip link add dev crash0 type dummy # ip link set dev crash0 up # mausezahn crash0 -c 100000 -P 10 \ > -A 4.3.2.1 -B 1.2.3.4 -t udp "dp=1234" -q & # sleep 1 # tc qdisc add dev crash0 egress_block 1 clsact # tc filter add block 1 protocol ip prio 1 matchall \ > action skbedit mark 65536 continue # tc filter add block 1 protocol ip prio 2 fw # ip link del dev crash0 can still make fw_classify() hit the WARN_ON() in [2]: WARNING: ./include/net/pkt_cls.h:88 at fw_classify+0x244/0x250 [cls_fw], CPU#18: mausezahn/1399 Modules linked in: cls_fw(E) act_skbedit(E) CPU: 18 UID: 0 PID: 1399 Comm: mausezahn Tainted: G E 7.0.0-rc6-virtme #17 PREEMPT(full) Tainted: [E]=UNSIGNED_MODULE Hardware name: Red Hat KVM, BIOS 1.16.3-2.el9 04/01/2014 RIP: 0010:fw_classify+0x244/0x250 [cls_fw] Code: 5c 49 c7 45 00 00 00 00 00 41 5d 41 5e 41 5f 5d c3 cc cc cc cc 5b b8 ff ff ff ff 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc 90 <0f> 0b 90 eb a0 0f 1f 80 00 00 00 00 90 90 90 90 90 90 90 90 90 90 RSP: 0018:ffffd1b7026bf8a8 EFLAGS: 00010202 RAX: ffff8c5ac9c60800 RBX: ffff8c5ac99322c0 RCX: 0000000000000004 RDX: 0000000000000001 RSI: ffff8c5b74d7a000 RDI: ffff8c5ac8284f40 RBP: ffffd1b7026bf8d0 R08: 0000000000000000 R09: ffffd1b7026bf9b0 R10: 00000000ffffffff R11: 0000000000000000 R12: 0000000000010000 R13: ffffd1b7026bf930 R14: ffff8c5ac8284f40 R15: 0000000000000000 FS: 00007fca40c37740(0000) GS:ffff8c5b74d7a000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fca40e822a0 CR3: 0000000005ca0001 CR4: 0000000000172ef0 Call Trace: <TASK> tcf_classify+0x17d/0x5c0 tc_run+0x9d/0x150 __dev_queue_xmit+0x2ab/0x14d0 ip_finish_output2+0x340/0x8f0 ip_output+0xa4/0x250 raw_sendmsg+0x147d/0x14b0 __sys_sendto+0x1cc/0x1f0 __x64_sys_sendto+0x24/0x30 do_syscall_64+0x126/0xf80 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fca40e822ba Code: d8 64 89 02 48 c7 c0 ff ff ff ff eb b8 0f 1f 00 f3 0f 1e fa 41 89 ca 64 8b 04 25 18 00 00 00 85 c0 75 15 b8 2c 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 7e c3 0f 1f 44 00 00 41 54 48 83 ec 30 44 89 RSP: 002b:00007ffc248a42c8 EFLAGS: 00000246 ORIG_RAX: 000000000000002c RAX: ffffffffffffffda RBX: 000055ef233289d0 RCX: 00007fca40e822ba RDX: 000000000000001e RSI: 000055ef23328c30 RDI: 0000000000000003 RBP: 000055ef233289d0 R08: 00007ffc248a42d0 R09: 0000000000000010 R10: 0000000000000000 R11: 0000000000000246 R12: 000000000000001e R13: 00000000000186a0 R14: 0000000000000000 R15: 00007fca41043000 </TASK> irq event stamp: 1045778 hardirqs last enabled at (1045784): [<ffffffff864ec042>] __up_console_sem+0x52/0x60 hardirqs last disabled at (1045789): [<ffffffff864ec027>] __up_console_sem+0x37/0x60 softirqs last enabled at (1045426): [<ffffffff874d48c7>] __alloc_skb+0x207/0x260 softirqs last disabled at (1045434): [<ffffffff874fe8f8>] __dev_queue_xmit+0x78/0x14d0 Then, because of the value in the packet's mark, dereference on 'q->handle' with NULL 'q' occurs: BUG: kernel NULL pointer dereference, address: 0000000000000038 [...] RIP: 0010:fw_classify+0x1fe/0x250 [cls_fw] [...] Skip "old-style" classification on shared blocks, so that the NULL dereference is fixed and WARN_ON() is not hit anymore in the short lifetime of invalid cls_fw "old-style" filters. [1] https://sashiko.dev/#/patchset/2 ---truncated---


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix racing timeout handler The bcmgenet_timeout handler tries to take down all tx queues when a single queue times out. This is over zealous and causes many race conditions with queues that are still chugging along. Instead lets only restart the timed out queue.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix ld_{abs,ind} failure path analysis in subprogs Usage of ld_{abs,ind} instructions got extended into subprogs some time ago via commit 09b28d76eac4 ("bpf: Add abnormal return checks."). These are only allowed in subprograms when the latter are BTF annotated and have scalar return types. The code generator in bpf_gen_ld_abs() has an abnormal exit path (r0=0 + exit) from legacy cBPF times. While the enforcement is on scalar return types, the verifier must also simulate the path of abnormal exit if the packet data load via ld_{abs,ind} failed. This is currently not the case. Fix it by having the verifier simulate both success and failure paths, and extend it in similar ways as we do for tail calls. The success path (r0=unknown, continue to next insn) is pushed onto stack for later validation and the r0=0 and return to the caller is done on the fall-through side.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix error pointer dereference The function brcmf_chip_add_core() can return an error pointer and is not checked. Add checks for error pointer. Detected by Smatch: drivers/net/wireless/broadcom/brcm80211/brcmfmac/chip.c:1010 brcmf_chip_recognition() error: 'core' dereferencing possible ERR_PTR() drivers/net/wireless/broadcom/brcm80211/brcmfmac/chip.c:1013 brcmf_chip_recognition() error: 'core' dereferencing possible ERR_PTR() drivers/net/wireless/broadcom/brcm80211/brcmfmac/chip.c:1016 brcmf_chip_recognition() error: 'core' dereferencing possible ERR_PTR() drivers/net/wireless/broadcom/brcm80211/brcmfmac/chip.c:1019 brcmf_chip_recognition() error: 'core' dereferencing possible ERR_PTR() drivers/net/wireless/broadcom/brcm80211/brcmfmac/chip.c:1022 brcmf_chip_recognition() error: 'core' dereferencing possible ERR_PTR() [add missing wifi: prefix]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work() When the mt7915 pci chip is detaching, the mt7915_crash_data is released in mt7915_coredump_unregister(). However, the work item dump_work may still be running or pending, leading to UAF bugs when the already freed crash_data is dereferenced again in mt7915_mac_dump_work(). The race condition can occur as follows: CPU 0 (removal path) | CPU 1 (workqueue) mt7915_pci_remove() | mt7915_sys_recovery_set() mt7915_unregister_device() | mt7915_reset() mt7915_coredump_unregister() | queue_work() vfree(dev->coredump.crash_data) | mt7915_mac_dump_work() | crash_data-> // UAF Fix this by ensuring dump_work is properly canceled before the crash_data is deallocated. Add cancel_work_sync() in mt7915_unregister_device() to synchronize with any pending or executing dump work.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet The irq_prepare_bcn_tasklet is initialized in rtl_pci_init() and scheduled when RTL_IMR_BCNINT interrupt is triggered by hardware. But it is never killed in rtl_pci_deinit(). When the rtlwifi card probe fails or is being detached, the ieee80211_hw is deallocated. However, irq_prepare_bcn_tasklet may still be running or pending, leading to use-after-free when the freed ieee80211_hw is accessed in _rtl_pci_prepare_bcn_tasklet(). Similar to irq_tasklet, add tasklet_kill() in rtl_pci_deinit() to ensure that irq_prepare_bcn_tasklet is properly terminated before the ieee80211_hw is released. The issue was identified through static analysis.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs [Why & How] dp_sdp_message_debugfs_write() dereferences connector->base.state->crtc without checking for NULL. A connector can be connected but not bound to any CRTC (e.g. after hot-plug before the next atomic commit), causing a kernel crash when writing to the sdp_message debugfs node. The function also ignores the user-provided size argument and always passes 36 bytes to copy_from_user(), reading past the user buffer when size < 36. Fix both issues by: - Returning -ENODEV when connector->base.state or state->crtc is NULL - Clamping write_size to min(size, sizeof(data)) (cherry picked from commit 6ab4c36a522842ff70474a1c0af2e40e50fc8300)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size [Why & How] The VBIOS integrated info tables (v1_11 and v2_1) contain HdmiRegNum and Hdmi6GRegNum fields that are used as loop bounds when copying retimer I2C register settings into fixed-size arrays (dp*_ext_hdmi_reg_settings[9] and dp*_ext_hdmi_6g_reg_settings[3]). These u8 fields are not validated before use, so a malformed VBIOS can specify values up to 255, causing an out-of-bounds heap write during driver probe. Clamp each register count to the destination array size using min_t() before the copy loops, in both get_integrated_info_v11() and get_integrated_info_v2_1(). (cherry picked from commit 5a7f0ef90195940c54b0f5bb85b87da55f038c69)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size [Why & How] During HDCP 2.x repeater authentication over HDMI, the driver reads the sink's RxStatus register and extracts a 10-bit message size field (max value 1023). This value is used as the read length for the ReceiverID list without being clamped to the size of the destination buffer rx_id_list[177]. A malicious HDMI repeater could advertise a message size larger than the buffer, causing an out-of-bounds write during the I2C read. Clamp the read length in mod_hdcp_read_rx_id_list() to the size of the rx_id_list buffer, matching the approach already used in the DP branch. (cherry picked from commit 229212219e4247d9486f8ba41ef087358490be09)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Skip CSD when it has zeroed workgroups A compute shader dispatch encodes its workgroup counts in the CFG0..CFG2 registers. Kicking off a dispatch with a zero count in any of the three dimensions is invalid. First, the hardware will process 0 as 65536, while the user-space driver exposes a maximum of 65535. Over that, a submission with a zeroed workgroup dimension should be a no-op. These zeroed counts can reach the dispatch path through an indirect CSD job, whose workgroup counts are only known once the indirect buffer is read and may legitimately be zero, but such scenario should only result in a no-op. Overwrite the indirect CSD job workgroup counts with the indirect BO ones, even if they are zeroed, and don't submit the job to the hardware when any of the workgroup counts is zero, so the job completes immediately instead of running the shader.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups v3d_rewrite_csd_job_wg_counts_from_indirect() maps both the indirect buffer and the workgroup buffer and is expected to release them before returning. When any of the workgroup counts read from the buffer is zero, the function bailed out early and skipped the cleanup, leaking the vaddr mappings of both BOs. Jump to the cleanup path instead of returning directly, so the mappings are always dropped.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 The v11 MQD manager incorrectly assigned the CP-compute variants of checkpoint_mqd/restore_mqd for KFD_MQD_TYPE_SDMA queues. These functions use sizeof(struct v11_compute_mqd) (2048 bytes) instead of sizeof(struct v11_sdma_mqd) (512 bytes), causing a 1536-byte overflow. During CRIU checkpoint of an SDMA queue on Navi3x: - checkpoint_mqd() reads 2048 bytes from a 512-byte SDMA MQD buffer, leaking 1536 bytes of adjacent GTT memory to userspace During CRIU restore: - restore_mqd() writes 2048 bytes into a 512-byte SDMA MQD buffer, corrupting 1536 bytes of adjacent GTT memory (often the ring buffer or neighboring MQDs) This is a copy-paste regression unique to v11. All other ASIC backends (cik, vi, v9, v10, v12) correctly use the SDMA-specific variants. Add checkpoint_mqd_sdma() and restore_mqd_sdma() functions that properly handle the smaller v11_sdma_mqd structure, matching the pattern used in other MQD managers. (cherry picked from commit 6fa41db7ffdec97d62433adf03b7b9b759af8c2c)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix NULL dereference in get_queue_ids() When usr_queue_id_array is NULL and num_queues is non-zero, get_queue_ids() returns NULL. The callers check only IS_ERR() on the return value; since IS_ERR(NULL) == false the check passes, and suspend_queues() calls q_array_invalidate() which immediately dereferences NULL while iterating num_queues times. Userspace can trigger this via kfd_ioctl_set_debug_trap() by supplying num_queues > 0 with a zero queue_array_ptr, causing a kernel panic. A NULL usr_queue_id_array with num_queues == 0 is a legitimate no-op (q_array_invalidate never executes, and resume_queues already guards all queue_ids dereferences behind a NULL check). Return ERR_PTR(-EINVAL) only when num_queues is non-zero and the pointer is absent; both callers already propagate IS_ERR() returns correctly to userspace. (cherry picked from commit f165a82cdf503884bb1797771c61b2fcc72113d4)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Limit XDomain response copy to actual frame size tb_xdomain_copy() copies req->response_size bytes from the received packet buffer regardless of the actual frame size. When a short response arrives, this reads past the valid frame data in the DMA pool buffer into stale contents from previous transactions. Use the minimum of frame size and expected response size for the copy length.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Validate XDomain request packet size before type cast tb_xdp_handle_request() casts the received packet buffer to protocol-specific structs without verifying that the allocation is large enough for the target type. A peer can send a minimal XDomain packet that passes the generic header length check but is shorter than the struct accessed after the cast, causing out-of- bounds reads from the kmemdup allocation. Plumb the packet length through xdomain_request_work and validate it against the expected struct size before each cast.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Clamp XDomain response data copy to allocation size tb_xdp_properties_request() derives the per-packet copy length from the response header without checking that it fits in the previously allocated data buffer. A malicious peer can set its length field larger than the declared data_length, causing memcpy to write past the kcalloc allocation. Clamp the per-packet copy length so that the cumulative offset never exceeds data_len.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Bound root directory content to block size __tb_property_parse_dir() does not check that content_offset + content_len fits within block_len for the root directory case. When rootdir->length equals or exceeds block_len - 2, the entry loop reads past the allocated property block. Add a bounds check after computing content_offset and content_len to reject directories whose content extends past the block.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Reject zero-length property entries in validator tb_property_entry_valid() accepts entries with length == 0 for DIRECTORY, DATA, and TEXT types. A zero-length TEXT entry passes validation but causes an underflow in the null-termination logic: property->value.text[property->length * 4 - 1] = '\0'; When property->length is 0 this writes to offset -1 relative to the allocation. Reject zero-length entries early in the validator since they have no valid representation in the XDomain property protocol.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix NULL pointer dereference in rpmsg callback A NULL pointer dereference was observed on Hawi at boot when the DSP sends a glink message before fastrpc_rpmsg_probe() has completed initialization: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000178 pc : _raw_spin_lock_irqsave+0x34/0x8c lr : fastrpc_rpmsg_callback+0x3c/0xcc [fastrpc] ... Call trace: _raw_spin_lock_irqsave+0x34/0x8c (P) fastrpc_rpmsg_callback+0x3c/0xcc [fastrpc] qcom_glink_native_rx+0x538/0x6a4 qcom_glink_smem_intr+0x14/0x24 [qcom_glink_smem] The faulting address 0x178 corresponds to the lock variable inside struct fastrpc_channel_ctx, confirming that cctx is NULL when fastrpc_rpmsg_callback() attempts to take the spinlock. There are two issues here. First, dev_set_drvdata() is called before spin_lock_init() and idr_init(), leaving a window where the callback can retrieve a valid cctx pointer but operate on an uninitialized spinlock. Second, the rpmsg channel becomes live as soon as the driver is bound, so fastrpc_rpmsg_callback() can fire before dev_set_drvdata() is called at all, resulting in dev_get_drvdata() returning NULL. Fix both issues by moving all cctx initialization ahead of dev_set_drvdata() so the structure is fully initialized before it becomes visible to the callback, and add a NULL check in fastrpc_rpmsg_callback() as a guard against any remaining window.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix DMA address corruption due to find_vma misuse fastrpc_get_args() uses find_vma() to look up the VMA for a user-provided pointer and compute a DMA address offset. When the address falls in a gap before the returned VMA, (ptr & PAGE_MASK) - vma->vm_start underflows, corrupting the DMA address sent to the DSP. Replace find_vma() with vma_lookup(), which returns NULL when the address is not contained within any VMA.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free race in fastrpc_map_create fastrpc_map_lookup returns a raw pointer after releasing fl->lock. The caller fastrpc_map_create then calls fastrpc_map_get (kref_get_unless_zero) on this unprotected pointer. A concurrent MEM_UNMAP can free the map between the lock release and the kref operation, resulting in a use-after-free on the freed slab object. Restore the take_ref parameter to fastrpc_map_lookup so the reference is acquired atomically under fl->lock before the pointer is exposed to the caller.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context There is a race between fastrpc_device_release() and the workqueue that processes DSP responses. When the user closes the file descriptor, fastrpc_device_release() frees the fastrpc_user structure. Concurrently, an in-flight DSP invocation can complete and fastrpc_rpmsg_callback() schedules context cleanup via schedule_work(&ctx->put_work). If the workqueue runs fastrpc_context_free() in parallel with or after fastrpc_device_release() has freed the user structure, it dereferences the freed fastrpc_user. Depending on the state of the context at the time of the race, any one of the following accesses can be hit: 1. fastrpc_buf_free() calls fastrpc_ipa_to_dma_addr(buf->fl->cctx, ...) to strip the SID bits from the stored IOVA before passing the physical address to dma_free_coherent(). 2. fastrpc_free_map() reads map->fl->cctx->vmperms[0].vmid to reconstruct the source permission bitmask needed for the qcom_scm_assign_mem() call that returns memory from the DSP VM back to HLOS. 3. fastrpc_free_map() acquires map->fl->lock to safely remove the map node from the fl->maps list. The resulting use-after-free manifests as: pc : fastrpc_buf_free+0x38/0x80 [fastrpc] lr : fastrpc_context_free+0xa8/0x1b0 [fastrpc] fastrpc_context_free+0xa8/0x1b0 [fastrpc] fastrpc_context_put_wq+0x78/0xa0 [fastrpc] process_one_work+0x180/0x450 worker_thread+0x26c/0x388 Add kref-based reference counting to fastrpc_user. Have each invoke context take a reference on the user at allocation time and release it when the context is freed. Release the initial reference in fastrpc_device_release() at file close. Move the teardown of the user structure - freeing pending contexts, maps, mmaps, and the channel context reference - into the kref release callback fastrpc_user_free(), so that it runs only when the last reference is dropped, regardless of whether that happens at device close or after the final in-flight context completes.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios FUSE_NOTIFY_RETRIEVE must be limited to uptodate folios; !uptodate folios can contain uninitialized data. Since FUSE_NOTIFY_RETRIEVE is intended to only return data that is already in the page cache and not wait for data from the FUSE daemon, treat !uptodate folios as if they weren't present. This only has security impact on systems that don't enable automatic zero-initialization of all page allocations via CONFIG_INIT_ON_ALLOC_DEFAULT_ON or init_on_alloc=1.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fuse: reject fuse_notify() pagecache ops on directories The operations FUSE_NOTIFY_STORE and FUSE_NOTIFY_RETRIEVE allow the FUSE daemon to actively write/read pagecache contents. For directories with FOPEN_CACHE_DIR, the pagecache is used as kernel-internal cache storage, and userspace is not supposed to have direct access to this cache - in particular, fuse_parse_cache() will hit WARN_ON() if the cache contains bogus data. Reject FUSE_NOTIFY_STORE and FUSE_NOTIFY_RETRIEVE on anything other than regular files with -EINVAL.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband/ulp/isert/ib_isert.c, isert_login_recv_done() computes the login request payload length as wc->byte_len minus ISER_HEADERS_LEN with no lower bound, and login_req_len is a signed int. A remote iSER initiator can post a login Send work request carrying fewer than ISER_HEADERS_LEN (76) bytes, so the subtraction underflows and login_req_len becomes negative. isert_rx_login_req() then reads that negative length back into a signed int, takes size = min(rx_buflen, MAX_KEY_VALUE_PAIRS), and because the min() is signed it keeps the negative value; the value is then passed as the memcpy() length and sign-extended to a multi-gigabyte size_t. The copy into the 8192-byte login->req_buf runs far out of bounds and faults, crashing the target node. The login phase precedes iSCSI authentication, so no credentials are required to reach this path. Reject any login PDU shorter than ISER_HEADERS_LEN before the subtraction, mirroring the existing early return on a failed work completion, so login_req_len can never go negative. The upper bound was already safe: a posted login buffer cannot deliver more than ISER_RX_PAYLOAD_SIZE, so the difference stays at or below MAX_KEY_VALUE_PAIRS and the existing min() clamps it; only the missing lower bound needs to be added.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction Add guards to ensure ie_length is large enough before subtracting fixed IE offsets to prevent unsigned integer underflow.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: vsock/vmci: fix sk_ack_backlog leak on failed handshake When vmci_transport_recv_connecting_server() returns an error, vmci_transport_recv_listen() calls vsock_remove_pending() but never calls sk_acceptq_removed(). This leaves sk_ack_backlog incremented permanently. Repeated handshake failures (malformed packets, queue pair alloc failure, event subscribe failure) cause sk_ack_backlog to climb toward sk_max_ack_backlog. Once it reaches the limit the listener permanently refuses all new connections with -ECONNREFUSED, a silent denial of service requiring a process restart to recover. The two existing sk_acceptq_removed() calls in af_vsock.c do not cover this path: line 764 checks vsock_is_pending() which returns false after vsock_remove_pending(), and line 1889 is only reached on successful accept(). Fix by balancing sk_acceptq_added() with sk_acceptq_removed() on the error path.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received length srp_process_rsp() copies sense data from rsp->data + resp_data_len, where resp_data_len is the full 32-bit value supplied by the SRP target and is never checked against the number of bytes actually received (wc->byte_len). The copy length is bounded to SCSI_SENSE_BUFFERSIZE, so at most 96 bytes are copied, but the source offset is not bounded. A malicious or compromised SRP target on the InfiniBand/RoCE fabric that the initiator has logged into can return an SRP_RSP with SRP_RSP_FLAG_SNSVALID set and a large resp_data_len. The receive buffer is allocated at the target-chosen max_ti_iu_len, so the source of the sense copy lands past the bytes actually received; with resp_data_len near 0xFFFFFFFF it is gigabytes past the buffer and the read faults. Copy the sense data only if it has not been truncated, that is, only if the response header, the response data, and the sense region fit within the bytes actually received; otherwise drop the sense and log. The in-tree iSER and NVMe-RDMA receive paths already bound their parse by wc->byte_len; this brings ib_srp into line with them.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() dma_fence_unwrap_for_each() internally calls dma_fence_unwrap_first() which does cursor->chain = dma_fence_get(head), taking an extra reference. On normal loop completion, dma_fence_unwrap_next() releases this via dma_fence_chain_walk() -> dma_fence_put(). When virtio_gpu_do_fence_wait() fails and the function returns early from inside the loop, the cursor->chain reference is never released. This is the only caller in the entire kernel that does an early return inside dma_fence_unwrap_for_each. Add dma_fence_put(itr.chain) before the early return.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Fix UAF at snd_timer_user_params() At releasing a timer object, e.g. when a userspace timer (CONFIG_SND_UTIMER) gets closed and snd_timer_free() is called, it tries to detach the timer instances and release the resources. However, it's still possible that other in-flight tasks are holding the timer instance where the to-be-deleted timer object is associated, and this may lead to racy accesses. Fortunately, most of ioctls dealing with the timer instance list already have the protection with register_mutex, and this also avoids such races. But, SNDRV_TIMER_IOCTL_PARAMS isn't protected, hence the concurrent ioctl may lead to use-after-free. This patch just adds the guard with register_mutex to protect snd_timer_user_params() for covering the code path as a quick workaround. It's no hot-path but rather a rarely issued ioctl, so the performance penalty doesn't matter.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: USB: serial: kl5kusb105: fix bulk-out buffer overflow klsi_105_prepare_write_buffer() is called by the generic write path with the bulk-out buffer and its size (bulk_out_size, 64 bytes). It stores a two-byte length header at the start of the buffer and copies the payload from the write fifo starting at buf + KLSI_HDR_LEN, but passes the full buffer size as the number of bytes to copy: count = kfifo_out_locked(&port->write_fifo, buf + KLSI_HDR_LEN, size, &port->lock); When the fifo holds at least size bytes, size bytes are copied starting two bytes into the size-byte buffer, writing KLSI_HDR_LEN bytes past its end. Copy at most size - KLSI_HDR_LEN bytes instead, leaving room for the header as safe_serial already does. Writing bulk_out_size or more bytes to the tty triggers a slab out-of-bounds write, observed with KASAN by emulating the device with dummy_hcd and raw-gadget: BUG: KASAN: slab-out-of-bounds in kfifo_copy_out+0x83/0xc0 Write of size 64 at addr ffff888112c62202 by task python3 kfifo_copy_out klsi_105_prepare_write_buffer [kl5kusb105] usb_serial_generic_write_start [usbserial] Allocated by task 139: usb_serial_probe [usbserial] The buggy address is located 2 bytes inside of allocated 64-byte region The out-of-bounds write no longer occurs with this change applied.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() build_i2c_fw_hdr() allocates a fixed-size buffer of (16*1024 - 512) + sizeof(struct ti_i2c_firmware_rec) bytes, then copies le16_to_cpu(img_header->Length) bytes into it without validating that Length fits within the available space after the firmware record header. img_header->Length is a __le16 from the firmware file and can be up to 65535. check_fw_sanity() validates the total firmware size but not img_header->Length specifically. Fix by rejecting images where img_header->Length exceeds the available destination space.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in get_manuf_info() get_manuf_info() reads le16_to_cpu(rom_desc->Size) bytes from the device I2C EEPROM into a buffer allocated with kmalloc_obj(), which is sizeof(struct edge_ti_manuf_descriptor) = 10 bytes. The Size field comes from the device and is only validated (in check_i2c_image()) to make sure the descriptor fits within TI_MAX_I2C_SIZE (16384 bytes), not against the destination buffer size. A malicious USB device can therefore set Size to any value up to 16377, causing a heap overflow of up to 16367 bytes when plugged into a host running this driver. valid_csum() is called after read_rom() and also iterates buffer[0..Size-1], compounding the out-of-bounds access. Fix by rejecting descriptors with unexpected length before calling read_rom(). [ johan: amend commit message; also check for short descriptors ]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix signed integer truncation in IPC receive Fix potential buffer overflow where firmware-supplied data_size is cast to signed int before being used in min_t(). Large unsigned values (>= 0x80000000) become negative, causing unsigned wraparound and oversized memcpy operations that can overflow the stack buffer. Change min_t(int, ...) to min() as both values are unsigned and can be handled by min() without explicit cast.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add buffer overflow check in MS get_info_ioctl Add validation that the info size returned from the metric stream info query is not exceeded when checked against the allocated buffer size. If the firmware returns a size larger than the buffer, reject the operation with -EOVERFLOW instead of proceeding with an incorrect buffer copy.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig net/bluetooth/l2cap_core.c:l2cap_sig_channel() accepts BR/EDR signaling packets up to the channel MTU and dispatches each command without enforcing the signaling MTU (MTUsig). A Bluetooth BR/EDR peer within radio range can send a fixed-channel CID 0x0001 packet that is larger than MTUsig and contains many L2CAP_ECHO_REQ commands before pairing. In a real-radio stock-kernel run, one 681-byte signaling packet containing 168 zero-length ECHO_REQ commands made the target transmit 168 ECHO_RSP frames over about 220 ms. Impact: a Bluetooth BR/EDR peer within radio range, before pairing, can force 168 ECHO_RSP frames from one 681-byte fixed-channel signaling packet containing packed ECHO_REQ commands. Define Linux's BR/EDR signaling MTU as the spec minimum of 48 bytes and reject any larger signaling packet with one L2CAP_COMMAND_REJECT_RSP carrying L2CAP_REJ_MTU_EXCEEDED before any command is dispatched. The Bluetooth Core spec wording for MTUExceeded says the reject identifier shall match the first request command in the packet, and that packets containing only responses shall be silently discarded. Linux intentionally deviates from that prescription: silently discarding desynchronizes the peer because the remote stack never learns its responses were dropped, and locating the first request command requires walking command headers past MTUsig, i.e. processing bytes from a packet we have already decided is too large to process. We therefore always emit one reject and use the identifier from the first command header, a single fixed-offset byte read. The unrestricted BR/EDR signaling parser and ECHO_REQ response path both trace to the initial git import; no later introducing commit is available for a Fixes tag.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend Existing advertising instances can already hold the maximum extended advertising payload. When hci_adv_bcast_annoucement() prepends the Broadcast Announcement service data to that payload, the combined data may no longer fit in the temporary buffer used to rebuild the advertising data. Reject that case before copying the existing payload and report the failure through the device log. This keeps the existing advertising data intact and avoids overrunning the temporary buffer.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: fix krealloc() memory leak Don't just overwrite the original pointer passed to krealloc() with its return value without checking latter: MEM = krealloc(MEM, SZ, GFP); If krealloc() returns NULL, that erases the pointer to the still allocated memory, hence leaks this memory. Instead, use a temporary variable, check it's not NULL and only then assign it to the original pointer: TMP = krealloc(MEM, SZ, GFP); if (!TMP) return; MEM = TMP; While on it, use krealloc_array().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use The RX error path returns the current descriptor buffer to the hardware BM pool. That is only valid while the driver still owns the buffer. mvpp2_rx_refill() can fail after the current buffer has been handed to XDP or attached to an skb. In those cases mvpp2_run_xdp() may have recycled, redirected, or queued the page for XDP_TX, and an skb free also retires the data buffer. Returning such a buffer to BM lets hardware DMA into memory that is no longer owned by the RX ring. Refill the BM pool before handing the current buffer to XDP or to the skb. If the allocation fails there, drop the packet and return the still-owned current buffer to BM, preserving the pool depth. Once the refill succeeds, later local drops retire/free the current buffer instead of returning it to BM.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer mvpp2 has short and long BM pools, and short pool buffers can be smaller than PAGE_SIZE. The XDP path nevertheless initializes every xdp_buff with PAGE_SIZE as frame size. XDP helpers use frame_sz to validate tail growth and to derive the hard end of the data area. Advertising PAGE_SIZE for short buffers can let bpf_xdp_adjust_tail() grow a packet past the real allocation, corrupting memory or later tripping skb tailroom checks. Initialize the XDP buffer with bm_pool->frag_size so XDP tailroom matches the actual buffer backing the packet.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: sync RX data at the hardware packet offset mvpp2 programs the RX queue packet offset, so hardware writes received data at dma_addr + MVPP2_SKB_HEADROOM. The current CPU sync starts at dma_addr and only covers rx_bytes + MVPP2_MH_SIZE bytes, which syncs the unused headroom and misses the same number of bytes at the packet tail. On non-coherent DMA systems this can leave the CPU reading stale cache contents for the end of the received frame. Use dma_sync_single_range_for_cpu() with MVPP2_SKB_HEADROOM as the range offset so the sync covers the Marvell header and packet data actually written by hardware.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag nft_exthdr_init() passes user-controlled priv->len to nft_parse_register_store(), which marks that many bytes in the register bitmap as initialized. However, when NFT_EXTHDR_F_PRESENT is set, the eval paths write only 1 byte (nft_reg_store8) or 4 bytes (*dest = 0 on TCP/DCCP error path). When len > 4, registers beyond the first are never written, retaining uninitialized stack data from nft_regs. Bail out if userspace requests too much data when F_PRESENT is set.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list lengths in cookie sctp_unpack_cookie() only checked that the embedded INIT chunk length did not exceed the remaining cookie payload, but did not ensure that the INIT chunk is large enough to contain a complete INIT header. A malformed COOKIE_ECHO can therefore carry a truncated INIT chunk whose length field is smaller than sizeof(struct sctp_init_chunk). Later, sctp_process_init() accesses INIT parameters unconditionally, which may lead to out-of-bounds reads. In addition, raw_addr_list_len is not fully validated against the remaining cookie payload. When cookie authentication is disabled, an attacker can supply an oversized raw_addr_list_len and cause sctp_raw_to_bind_addrs() to read beyond the end of the cookie. The address parser also lacks sufficient bounds checks for parameter headers and lengths, allowing malformed address parameters to trigger out-of-bounds reads. Fix this by: - requiring the embedded INIT chunk length to be at least sizeof(struct sctp_init_chunk); - validating that the INIT chunk and raw address list together fit within the cookie payload; - verifying sufficient data exists for each address parameter header and payload before parsing it. Note that sctp_verify_init() must be called after sctp_unpack_cookie() and before sctp_process_init() when cookie authentication is disabled. This will be addressed in a separate patch.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parameter header, then calls af->from_addr_param(), which reads the full address (16 bytes for IPv6) trusting the parameter's declared length. An unauthenticated peer can send a truncated trailing ASCONF chunk that declares an IPv6 address parameter but stops after the 4-byte parameter header; reached from the no-association lookup path, from_addr_param() then reads uninitialized bytes past the parameter. Impact: an unauthenticated SCTP peer makes the receive path read up to 16 bytes of uninitialized memory past a truncated ASCONF address parameter. The sibling __sctp_rcv_init_lookup() bounds parameters with sctp_walk_params(); this path open-codes the fetch and omits the bound. Verify the whole address parameter lies within the chunk before from_addr_param() reads it, the same class of fix as commit 51e5ad549c43 ("net: sctp: fix KMSAN uninit-value in sctp_inq_pop").


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix possible kfree_skb of ERR_PTR After the patch in the "Fixes" tag, the allocation of the "reply" skb can happen either before or after locking the ovs_mutex. However, error cleanups still follow the classical reversed order, assuming "reply" is allocated before locking: it is freed after unlocking. If "reply" allocation happens after locking the mutex and it fails, "reply" is left with an ERR_PTR, and execution jumps to the correspondent cleanup stage which will try to free an invalid pointer. Fix this by setting the pointer to NULL after having saved its error value.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure In the XSK branch of mlx5e_xmit_xdp_buff(), when sq->xmit_xdp_frame() returns false (e.g. XDPSQ is full), the function returns without unmapping the DMA address or freeing the xdp_frame allocated by xdp_convert_zc_to_xdp_frame(). The xdpi_fifo push only happens on success, so the completion path cannot recover these entries. With CONFIG_DMA_API_DEBUG=y, the leak surfaces on driver unbind: DMA-API: pci 0000:08:00.0: device driver has pending DMA allocations while released from device [count=1116] One of leaked entries details: [device address=0x000000010ffd7028] [size=1534 bytes] [mapped with DMA_TO_DEVICE] [mapped as phy] WARNING: kernel/dma/debug.c:881 at dma_debug_device_change+0x127/0x180 ... DMA-API: Mapped at: debug_dma_map_phys+0x4b/0xd0 dma_map_phys+0xfd/0x2d0 mlx5e_xdp_handle+0x5ae/0xac0 [mlx5_core] mlx5e_xsk_skb_from_cqe_mpwrq_linear+0xc4/0x170 [mlx5_core] mlx5e_handle_rx_cqe_mpwrq+0xc1/0x290 [mlx5_core] Add the missing unmap + xdp_return_frame, matching the cleanup already done in mlx5e_xdp_xmit(). has_frags is rejected earlier in this branch, so no per-frag unmap is needed.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: gpio: mvebu: fix NULL pointer dereference in suspend/resume mvebu_pwm_suspend() and mvebu_pwm_resume() are called for all GPIO banks during suspend/resume, but not all banks have PWM functionality. GPIO banks without PWM have mvchip->mvpwm set to NULL. Calling mvebu_pwm_suspend() with mvpwm == NULL causes a NULL pointer dereference when it tries to access mvpwm->blink_select. Unable to handle kernel NULL pointer dereference at virtual address 00000020 when write [00000020] *pgd=00000000 Internal error: Oops: 815 [#1] PREEMPT ARM Modules linked in: CPU: 0 UID: 0 PID: 406 Comm: sh Not tainted 6.12.74-rt12-yocto-standard-g4e96f98fb7db-dirty #353 Hardware name: Marvell Armada 370/XP (Device Tree) PC is at regmap_mmio_read+0x38/0x54 LR is at regmap_mmio_read+0x38/0x54 pc : [<c05fd2ac>] lr : [<c05fd2ac>] psr: 200f0013 sp : f0c11d10 ip : 00000000 fp : c100d2f0 r10: c14fb854 r9 : 00000000 r8 : 00000000 r7 : c1799c00 r6 : 00000020 r5 : 00000020 r4 : c179c7c0 r3 : f0a231a0 r2 : 00000020 r1 : 00000020 r0 : 00000000 Flags: nzCv IRQs on FIQs on Mode SVC_32 ISA ARM Segment none Control: 10c5387d Table: 135ec059 DAC: 00000051 Call trace: regmap_mmio_read from _regmap_bus_reg_read+0x78/0xac _regmap_bus_reg_read from _regmap_read+0x60/0x154 _regmap_read from regmap_read+0x3c/0x60 regmap_read from mvebu_gpio_suspend+0xa4/0x14c mvebu_gpio_suspend from dpm_run_callback+0x54/0x180 dpm_run_callback from device_suspend+0x124/0x630 device_suspend from dpm_suspend+0x124/0x270 dpm_suspend from dpm_suspend_start+0x64/0x6c dpm_suspend_start from suspend_devices_and_enter+0x140/0x8e8 suspend_devices_and_enter from pm_suspend+0x2fc/0x308 pm_suspend from state_store+0x6c/0xc8 state_store from kernfs_fop_write_iter+0x10c/0x1f8 kernfs_fop_write_iter from vfs_write+0x270/0x468 vfs_write from ksys_write+0x70/0xf0 ksys_write from ret_fast_syscall+0x0/0x54 Add a NULL check for mvchip->mvpwm before calling the PWM suspend/resume functions.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() Fix the race by pruning the bin while still holding xfrm_policy_lock, before dropping it. Use __xfrm_policy_inexact_prune_bin() directly since the lock is already held. The wrapper xfrm_policy_inexact_prune_bin() becomes unused and is removed. Race: CPU0 (XFRM_MSG_DELPOLICY) CPU1 (XFRM_MSG_NEWSPDINFO) ========================== ========================== xfrm_policy_bysel_ctx(): spin_lock_bh(xfrm_policy_lock) bin = xfrm_policy_inexact_lookup() __xfrm_policy_unlink(pol) spin_unlock_bh(xfrm_policy_lock) xfrm_policy_kill(ret) // wide window, lock not held xfrm_hash_rebuild(): spin_lock_bh(xfrm_policy_lock) __xfrm_policy_inexact_flush(): kfree_rcu(bin) // bin freed spin_unlock_bh(xfrm_policy_lock) xfrm_policy_inexact_prune_bin(bin) // UAF: bin is freed


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: dummy: fix UMP event stack overread The dummy sequencer port forwards events by copying an incoming struct snd_seq_event into a stack temporary, rewriting source and destination, and dispatching the temporary to subscribers. That legacy event storage is smaller than struct snd_seq_ump_event. When a UMP event reaches the dummy client, the copy leaves the UMP flag set but only provides legacy-sized stack storage. The subscriber delivery path then uses snd_seq_event_packet_size() and copies a UMP-sized packet from that stack object, reading past the end of the temporary. Use the existing union __snd_seq_event storage and copy the packet size reported for the incoming event before rewriting the common routing fields. This preserves the full UMP packet for UMP events while keeping legacy event handling unchanged.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams snd_pcm_drain() uses init_waitqueue_entry which does not clear entry.prev/next, and add_wait_queue with a conditional remove_wait_queue that is skipped when to_check is no longer in the group after concurrent UNLINK. The orphaned wait entry remains on the unlinked substream sleep queue. On the next drain iteration, add_wait_queue adds the entry to a new queue while still linked on the old one, corrupting both lists. A subsequent wake_up dereferences NULL at the func pointer (mapped from the spinlock at offset 0 of the misinterpreted wait_queue_head_t), causing a kernel panic. Replace init_waitqueue_entry/add_wait_queue/conditional remove_wait_queue with init_wait_entry/prepare_to_wait/ finish_wait. init_wait_entry clears prev/next via INIT_LIST_HEAD on each iteration and sets autoremove_wake_function which auto-removes the entry on wake-up. finish_wait safely handles both the already-removed and still-queued cases.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr In mrp_pdu_parse_vecattr(), vector attribute events are encoded three per byte and valen tracks the number of events left to process. The parser decrements valen after processing the first and second events from each event byte, but not after processing the third one. When valen is exactly a multiple of three, the loop continues after the last valid event and consumes the next byte as a new event byte, applying a spurious event to the MRP applicant state. Additionally, when valen is zero the parser unconditionally consumes attrlen bytes as FirstValue and advances the offset, even though per IEEE 802.1ak a VectorAttribute with only a LeaveAllEvent has valen of zero and no FirstValue or Vector fields. This corrupts the offset for subsequent PDU parsing. Also, when valen exceeds three the loop crosses byte boundaries but the attribute value is not incremented between the last event of one byte and the first event of the next. This causes the first event of the next byte to use the same attribute value as the third event rather than the next consecutive value. Decrement valen after processing the third event, skip FirstValue consumption when valen is zero, and increment the attribute value at the end of each loop iteration.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing When a listening SCTP server processes a COOKIE_ECHO chunk, the cached peer INIT chunk embedded after the cookie is parsed and its parameters are later walked by sctp_process_init() using sctp_walk_params(). However, the chunk header length of this cached INIT chunk was not validated against the remaining buffer in the COOKIE_ECHO payload. If the length field is inflated, the parameter walk can run beyond the actual received data, leading to out-of-bounds reads and potential memory corruption during later parameter handling (e.g. STATE_COOKIE processing and kmemdup() copies). Add a bounds check in sctp_unpack_cookie() to ensure the cached INIT chunk length does not exceed the available data in the COOKIE_ECHO buffer before it is used.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options This patch restricts setting Loose Source and Record Route (LSRR) and Strict Source and Record Route (SSRR) IP options to users with CAP_NET_RAW capability. This prevents unprivileged applications from forcing packets to route through attacker-controlled nodes to leak TCP ISN and possibly other protocol information. While LSRR and SSRR are commonly filtered in many network environments, they may still be supported and forwarded along some network paths. RFC 7126 (Recommendations on Filtering of IPv4 Packets Containing IPv4 Options) recommend to drop these options in 4.3 and 4.4.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: validate skb length in MCC handlers The RFCOMM MCC handlers cast skb->data to protocol-specific structs without validating skb->len first. A malicious remote device can send truncated MCC frames and trigger out-of-bounds reads in these handlers. Fix this by using skb_pull_data() to validate and access the required data before dereferencing it. rfcomm_recv_rpn() requires special handling since ETSI TS 07.10 allows 1-byte RPN requests. Handle this by validating only the DLCI byte first, and validating the full struct only when len > 1.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate advertising TLV before type checks tlv_data_is_valid() reads each advertising data field length from data[i], then inspects data[i + 1] for managed EIR types before checking that the current field still fits inside the supplied buffer. A malformed field whose length byte is the last byte of the buffer can therefore make the parser read one byte past the advertising data. KASAN reported the following when a malformed MGMT_OP_ADD_ADVERTISING request reached that path: BUG: KASAN: vmalloc-out-of-bounds in tlv_data_is_valid() Read of size 1 Call trace: tlv_data_is_valid() add_advertising() hci_mgmt_cmd() hci_sock_sendmsg() Move the existing element-length check before any type-octet inspection so each non-empty element is proven to contain its type byte before the parser looks at data[i + 1].


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() rfcomm_get_sock_by_channel() scans rfcomm_sk_list under the list lock, but returns the selected listener after dropping that lock without taking a reference. rfcomm_connect_ind() then locks the listener, queues a child socket on it, and may notify it after unlocking it. The buggy scenario involves two paths, with each column showing the order within that path: rfcomm_connect_ind(): listener close: 1. Find parent in 1. close() enters rfcomm_get_sock_by_channel() rfcomm_sock_release(). 2. Drop rfcomm_sk_list.lock 2. rfcomm_sock_shutdown() without pinning parent. closes the listener. 3. Call lock_sock(parent) and 3. rfcomm_sock_kill() bt_accept_enqueue(parent, unlinks and puts parent. sk, true). 4. Read parent flags and may 4. parent can be freed. call sk_state_change(). If close wins the race, parent can be freed before rfcomm_connect_ind() reaches lock_sock(), bt_accept_enqueue(), or the deferred-setup callback. Take a reference on the listener before leaving rfcomm_sk_list.lock. After lock_sock() succeeds, recheck that it is still in BT_LISTEN before queueing a child, cache the deferred-setup bit while the parent is locked, and drop the reference after the last parent use. KASAN reported a slab-use-after-free in lock_sock_nested() from rfcomm_connect_ind(), with the freeing stack going through rfcomm_sock_kill() and rfcomm_sock_release().


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: fix leak if split 6 GHz scanning fails rdev->int_scan_req is leaked if cfg80211_scan() fails. Note that it's supposed to be released at ___cfg80211_scan_done() but this doesn't happen as rdev->scan_req is NULL at that point, too, leading to the early return from the freeing function. unreferenced object 0xffff8881161d0800 (size 512): comm "wpa_supplicant", pid 379, jiffies 4294749765 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 f0 81 13 16 81 88 ff ff ................ backtrace (crc c867fdb6): kmemleak_alloc+0x89/0x90 __kmalloc_noprof+0x2fd/0x410 cfg80211_scan+0x133/0x730 nl80211_trigger_scan+0xc69/0x1cc0 genl_family_rcv_msg_doit+0x204/0x2f0 genl_rcv_msg+0x431/0x6b0 netlink_rcv_skb+0x143/0x3f0 genl_rcv+0x27/0x40 netlink_unicast+0x4f6/0x820 netlink_sendmsg+0x797/0xce0 __sock_sendmsg+0xc4/0x160 ____sys_sendmsg+0x5e4/0x890 ___sys_sendmsg+0xf8/0x180 __sys_sendmsg+0x136/0x1e0 __x64_sys_sendmsg+0x76/0xc0 x64_sys_call+0x13f0/0x17d0 Found by Linux Verification Center (linuxtesting.org).


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack_irc: fix possible out-of-bounds read When parsing fails after we've matched the command string we should bail out instead of trying to match a different command. This helper should be deprecated, given prevalence of TLS I doubt it has any relevance in 2026.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: erofs: fix use-after-free on sbi->sync_decompress z_erofs_decompress_kickoff() can race with filesystem unmount, causing a use-after-free on sbi->sync_decompress. When I/O completes, z_erofs_endio() calls z_erofs_decompress_kickoff() to queue z_erofs_decompressqueue_work() asynchronously. Then, after all folios are unlocked, unmount workflow can proceed and sbi will be freed before accessing to sbi->sync_decompress. Thread (unmount) I/O completion kworker queue_work z_erofs_decompressqueue_work (all folios are unlocked) cleanup_mnt .. erofs_kill_sb erofs_sb_free kfree(sbi) access sbi->sync_decompress // UAF!!


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS A logic flaw in __smc_setsockopt() allows a local unprivileged user to cause a Denial of Service (DoS) by holding the socket lock indefinitely. The function __smc_setsockopt() calls copy_from_sockptr() while holding lock_sock(sk). By passing a userfaultfd-monitored memory page (or FUSE-backed memory on systems where unprivileged userfaultfd is disabled) as the optval, an attacker can halt execution during the copy operation, keeping the lock held. Combined with asynchronous tear-down operations like shutdown(), this exhausts the kernel wq (kworkers) and triggers the hung task watchdog. [ 240.123456] INFO: task kworker/u8:2 blocked for more than 120 seconds. [ 240.123489] Call Trace: [ 240.123501] smc_shutdown+... [ 240.123512] lock_sock_nested+... This patch moves the user-space copy outside the lock_sock() critical section to prevent the issue.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/gma500/oaktrail_lvds: fix hang on init failure The LVDS init code looks up an I2C adapter using i2c_get_adapter() and tries to read the EDID before falling back to allocating and registering its own adapter. The error handling does not separate these cases so on a late init failure it will try to deregister and free also an adapter that had previously been registered. Since i2c_get_adapter() takes another reference to the adapter, deregistration hangs indefinitely while waiting for the reference to be released. Fix this by only destroying adapters allocated during LVDS init on errors.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED [Why] dcn32_validate_bandwidth() wraps dcn32_internal_validate_bw() with DC_FP_START()/DC_FP_END(). In x86 non-RT, DC_FP_START takes fpregs_lock(), which disables local softirqs. The DML1 path through dcn32_enable_phantom_plane() calls kvzalloc() to allocate ~335 KiB for dc_plane_state. This triggers the vmalloc path, which calls BUG_ON(in_interrupt()) because it's invoked within the FPU-enabled (softirq disabled) region, leading to a kernel crash. [How] Wrap the dc_state_create_phantom_plane() call with the DC_RUN_WITH_PREEMPTION_ENABLED() macro to allow preemption during this memory allocation. (cherry picked from commit 885ccbef7b94a8b38f69c4211c679021aa27ad11)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG There were multiple issues in that code. First of all the order between the reset semaphore and the mm_lock was wrong (e.g. copy_to_user) was called while holding the lock. Then we allocated memory while holding the reset semaphore which is also a pretty big bug and can deadlock. Then we used down_read_trylock() instead of waiting for the reset to finish. (cherry picked from commit 361b6e6b303d4b691f6c5974d3eaab67ca6dd90e)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: tty: hvc_iucv: fix off-by-one in number of supported devices MAX_HVC_IUCV_LINES == HVC_ALLOC_TTY_ADAPTERS == 8. This is the number of entries in: static struct hvc_iucv_private *hvc_iucv_table[MAX_HVC_IUCV_LINES]; Sometimes hvc_iucv_table[] is limited by: (a) if (num > hvc_iucv_devices) // for error detection or (b) for (i = 0; i < hvc_iucv_devices; i++) // in 2 places (so these 2 don't agree; second one appears to be correct to me.) hvc_iucv_devices can be 0..8. This is a counter. (c) if (hvc_iucv_devices > MAX_HVC_IUCV_LINES) If hvc_iucv_devices == 8, (a) allows the code to access hvc_iucv_table[8]. Oops.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths In dc_dmub_srv_log_diagnostic_data() and dc_dmub_srv_enable_dpia_trace(). Both functions check: if (!dc_dmub_srv || !dc_dmub_srv->dmub) and then call DC_LOG_ERROR() inside that block. DC_LOG_ERROR() uses dc_dmub_srv->ctx internally. So if dc_dmub_srv is NULL, the logging itself can dereference a NULL pointer and cause a crash. Fix this by splitting the checks. First check if dc_dmub_srv is NULL and return immediately. Then check dc_dmub_srv->dmub and log the error only when dc_dmub_srv is valid. Fixes the below: ../display/dc/dc_dmub_srv.c:962 dc_dmub_srv_log_diagnostic_data() error: we previously assumed 'dc_dmub_srv' could be null (see line 961) ../display/dc/dc_dmub_srv.c:1167 dc_dmub_srv_enable_dpia_trace() error: we previously assumed 'dc_dmub_srv' could be null (see line 1166)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: agp/amd64: Fix broken error propagation in agp_amd64_probe() A NULL pointer dereference was observed in the AMD64 AGP driver when running in a virtualized environment (e.g. qemu/kvm) without a physical AMD northbridge. The crash occurs in amd64_fetch_size() when attempting to dereference the pointer returned by node_to_amd_nb(0). The root cause of this crash is broken error propagation in agp_amd64_probe(): When no AMD northbridges are found, cache_nbs() correctly returns -ENODEV. However, the probe function erroneously checks the return value against exactly -1, rather than < 0. As a result, the hardware absence error is masked, allowing the driver to improperly proceed with initialization. It eventually calls agp_add_bridge(), which invokes amd64_fetch_size(). Since the hardware does not exist, node_to_amd_nb(0) returns NULL, leading to a General Protection Fault (GPF) when accessing its ->misc member. Fix the issue by correcting the error check in agp_amd64_probe() to abort properly when cache_nbs() returns any negative error code. This prevents the driver from erroneously proceeding without hardware, thereby avoiding the subsequent NULL pointer dereference at its source.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Use krealloc_array() in dal_vector_reserve() [Why & How] dal_vector_reserve() computes the allocation size as "capacity * vector->struct_size" using uint32_t arithmetic, which can silently wrap to a small value on overflow. This would cause krealloc to return a smaller buffer than expected, leading to heap overflows on subsequent vector appends. Replace krealloc() with krealloc_array() which performs an internal overflow check and returns NULL on wrap, preventing the issue. (cherry picked from commit 37668568641ccc4cc1dbca4923d0a16609dd5707)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() On all modern platforms Qualcomm CCI controller provides two I2C masters, and on particular boards only one I2C master may be initialized, and in such cases the device unbinding or driver removal causes a NULL pointer dereference, because cci_halt() is called for all two I2C masters, but a completion is initialized only for the single enabled master: % rmmod i2c-qcom-cci Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 <snip> Call trace: __wait_for_common+0x194/0x1a8 (P) wait_for_completion_timeout+0x20/0x2c cci_remove+0xc4/0x138 [i2c_qcom_cci] platform_remove+0x20/0x30 device_remove+0x4c/0x80 device_release_driver_internal+0x1c8/0x224 driver_detach+0x50/0x98 bus_remove_driver+0x6c/0xbc driver_unregister+0x30/0x60 platform_driver_unregister+0x14/0x20 qcom_cci_driver_exit+0x18/0x1008 [i2c_qcom_cci] ....


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal with disabled KMS DRM atomic and modesetting aren't initialized if virtio-gpu driver built with disabled KMS, leading to access of uninitialized data on driver removal/unbinding and crashing kernel. Fix it by skipping shutting down atomic core with unavailable KMS.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ASoC: wm_adsp: Fix NULL dereference when removing firmware controls In wm_adsp_control_remove() check that the priv pointer is not NULL before attempting to cleanup what it points to. When cs_dsp creates a control it calls wm_adsp_control_add_cb() so that wm_adsp can create its own private control data. There are two cases where private data is not created: 1. The control is a SYSTEM control, so an ALSA control is not created. 2. The codec driver has registered a control_add() callback that hides the control, so wm_adsp_control_add() is not called. When cs_dsp_remove destroys its control list it calls wm_adsp_control_remove() for each control. But wm_adsp_control_remove() was attempting to cleanup the private data pointed to by cs_ctl->priv without checking the pointer for NULL.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is written so it can run during partial startup and on repeated shutdown attempts. It uses NULL pointers to distinguish resources that are still owned from resources that have already been released. When rds_ib_setup_qp() fails after allocating i_sends but before allocating i_recvs, the sends_out path frees i_sends without clearing the pointer. A later shutdown pass can still treat that stale pointer as a live send ring allocation. Clear i_sends after vfree() in the error unwind path so the existing shutdown logic continues to use the correct ownership state.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix phys BO pread/pwrite with offset sg_page() returns struct page pointer not (void *) so the scaling of pread/pwrite is wrong for phys BO and wrong parts of BO would be accessed if non-zero offset is used. Last impacted platform with overlay or cursor planes using phys mapping was Gen3/945G/Lakeport. (cherry picked from commit 3e49a2f85070b2fb672c1e0fdba281a4ea3aebe6)


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() bt_accept_dequeue() unlinks a not-yet-accepted child from the parent accept queue and release_sock()s it before returning, so the returned sk has no caller reference and is unlocked. l2cap_sock_cleanup_listen() walks these children on listening-socket close. A concurrent HCI disconnect drives hci_rx_work -> l2cap_conn_del() which runs l2cap_chan_del() + l2cap_sock_kill() and frees the child sk and its l2cap_chan; cleanup_listen() then uses both: BUG: KASAN: slab-use-after-free in l2cap_sock_kill l2cap_sock_kill / l2cap_sock_cleanup_listen / __x64_sys_close Freed by: l2cap_conn_del -> l2cap_sock_close_cb -> l2cap_sock_kill This is distinct from the two fixes already in this area: commit e83f5e24da741 ("Bluetooth: serialize accept_q access") serialises the accept_q list/poll and takes temporary refs inside bt_accept_dequeue(), and CVE-2025-39860 serialises the userspace close()/accept() race by calling cleanup_listen() under lock_sock() in l2cap_sock_release(). Neither covers l2cap_conn_del() running from hci_rx_work, so this UAF still reproduces on current bluetooth/master. Take the reference at the source: bt_accept_dequeue() does sock_hold() while sk is still locked, before release_sock(); callers sock_put(). cleanup_listen() pins the chan with l2cap_chan_hold_unless_zero() under a brief child sk lock (serialising vs l2cap_sock_teardown_cb()), drops it before l2cap_chan_lock(), and skips a duplicate l2cap_sock_kill() on SOCK_DEAD. conn->lock is not taken here: cleanup_listen() runs under the parent sk lock and that would invert conn->lock -> chan->lock -> sk_lock (lockdep). KASAN/SMP: an unprivileged listen/close vs HCI-disconnect race produced 12 use-after-free reports per run before this change; 0, and no lockdep report, over 1600+ raced iterations after it on bluetooth/master.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() l2cap_chan_close() removes the channel from conn->chan_l, which must be done under conn->lock. cleanup_listen() runs under the parent sk_lock, so acquiring conn->lock would invert the established conn->lock -> chan->lock -> sk_lock order. Instead of calling l2cap_chan_close() directly, schedule l2cap_chan_timeout with delay 0 to close the channel asynchronously. The timeout handler already acquires conn->lock and chan->lock in the correct order. The timer is only armed when chan->conn is still set: if it is already NULL, l2cap_conn_del() has already processed this channel (l2cap_chan_del + l2cap_sock_teardown_cb + l2cap_sock_close_cb), so there is nothing left to do. If l2cap_conn_del() races in after the timer is armed, __clear_chan_timer() inside l2cap_chan_del() cancels it; if the timer has already fired, the handler returns harmlessly because chan->conn was cleared.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. The rmap_remove() call would miss entries created after the PDE change because the GFN of the leaf SPTE does not match the GFN of the struct kvm_mmu_page. A similar hole however remains if the modified PDE points to a non-leaf page. In this case the gfn can be made to match, but the role does not match: the original large 2MB page creates a kvm_mmu_page with direct=1, while the new 4KB needs a kvm_mmu_page with direct=0. However, kvm_mmu_get_child_sp() does not compare the role, and therefore reuses the page. The next step is installing a leaf (4KB) SPTE on the new path which records an rmap entry under the gfn resolved by the walk. But when that child is zapped its parent kvm_mmu_page has direct=1 and kvm_mmu_page_get_gfn() computes the gfn for the 4KB page as sp->gfn + index instead of using sp->shadowed_translation[] (or sp->gfns[] in older kernels). It therefore fails to remove the recorded entry. When the memslot is dropped the shadow page is freed but the rmap entry survives, as in the scenario that was already fixed. Code that later walks that gfn (dirty logging, MMU notifier invalidation, and so on) dereferences an sptep that lies in the freed page, causing the use-after-free.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use As per the GHCB spec, when using GHCB v2+ require the software scratch area to reside in the GHCB's shared buffer. Note, things like Page State Change (PSC) requests _rely_ on this behavior, as the guest can't provide a length when making the request, i.e. the size of the guest payload is bounded by the size of the shared buffer. Failure to force usage of the GHCB, and a slew of other flaws, lets a malicious SNP guest corrupt host kernel heap memory, and leak host heap layout information. setup_vmgexit_scratch() allocates a buffer via kvzalloc(exit_info_2), where exit_info_2 is guest-controlled. With exit_info_2=24, this yields a 24-byte allocation in kmalloc-cg-32 (32-byte slab objects). The buffer holds an 8-byte psc_hdr followed by 8-byte psc_entry structs, so only entries[0] and entries[1] are in-bounds. snp_begin_psc() validates end_entry against VMGEXIT_PSC_MAX_COUNT (253) but NOT against the actual buffer size: idx_end = hdr->end_entry; if (idx_end >= VMGEXIT_PSC_MAX_COUNT) { // checks 253, not buffer snp_complete_psc(svm, ...); return 1; } for (idx = idx_start; idx <= idx_end; idx++) { entry_start = entries[idx]; // OOB when idx >= 2 The guest sets end_entry=10+, causing the host to iterate entries[2+] which are OOB into adjacent slab objects. For each OOB entry: - The host reads 8 bytes (OOB READ / info leak oracle) - If the data passes PSC validation, __snp_complete_one_psc() writes cur_page = 1 or 512 into the entry (OOB WRITE, sev.c:3806) - If validation fails, the error response reveals whether adjacent memory is zero vs non-zero (information disclosure to guest) The guest controls allocation size (exit_info_2), entry range (cur_entry/end_entry), and can fire unlimited VMGEXITs to repeatedly hit different slab positions. By exploiting the variety of bugs, a malicious SEV-SNP guest can: - OOB read adjacent kmalloc-cg-32 objects (heap layout disclosure) - OOB write cur_page bits into adjacent objects (heap corruption) - Trigger use-after-free conditions across VMGEXITs E.g. with KASAN enabled, a single insmod of the PoC guest module produces 73 KASAN reports: BUG: KASAN: slab-out-of-bounds in snp_begin_psc+0x126/0x890 Read of size 8 at addr ffff888219ffb5e0 by task qemu-system-x86/2199 BUG: KASAN: slab-out-of-bounds in snp_begin_psc+0x468/0x890 Write of size 8 at addr ffff888351566648 by task qemu-system-x86/2199 The buggy address belongs to the object at ffff888XXXXXXXXX which belongs to the cache kmalloc-cg-32 of size 32 The buggy address is located N bytes to the right of allocated 32-byte region [ffff888XXXXXXXXX, ffff888XXXXXXXXX) Breakdown: 62 slab-out-of-bounds (reads + writes past allocation) 7 slab-use-after-free 4 use-after-free All credit to Stan for the wonderful description and reproducer! [sean: write changelog]


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length + fraggap). When fraggap is non-zero, this is not the first skb and transhdrlen is zero. The fraggap bytes carried over from the previous skb are copied just past the fragment headers in the new skb's linear area. The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount, and the copy writes past skb->end into the trailing skb_shared_info. An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES. The bad accounting was introduced by commit 773ba4fe9104 ("ipv6: avoid partial copy for zc"). Before commit ce650a166335 ("udp6: Fix __ip6_append_data()'s handling of MSG_SPLICE_PAGES"), the negative copy value caused -EINVAL to be returned. That later commit allowed MSG_SPLICE_PAGES to proceed in this case, making the corruption triggerable. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic. Since a negative copy is no longer expected for a valid MSG_SPLICE_PAGES case, remove the MSG_SPLICE_PAGES exception from the negative copy check.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), when the paged-allocation branch is taken, alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap, but the fraggap bytes carried over from the previous skb are copied into the new skb's linear area at offset transhdrlen by the subsequent skb_copy_and_csum_bits(). The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:kernel-default-devel-6.4.0-150700.53.73.2
Container bci/bci-sle15-kernel-module-devel:latest:kernel-devel-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-macros-6.4.0-150700.53.73.1
Container bci/bci-sle15-kernel-module-devel:latest:kernel-syms-6.4.0-150700.53.73.1

Ссылки
Уязвимость SUSE-SU-2026:3166-1