mirror of
https://github.com/torvalds/linux.git
synced 2026-10-07 19:16:02 +02:00
17e7b8eacf
1483283 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
17e7b8eacf |
smb client fixes for v7.3-rc4
A batch of bug fixes for the smb client:
- Fix multiple out-of-bounds reads and use-after-frees in the SMB2/3
receive path that are reachable from a malicious or compromised
server: a stale next_buffer pointer and an integer overflow in
compound encrypted frame handling, missing minimum-PDU-size and
per-sub-PDU length validation before parsing command-specific
response fields, missing bounds checks in DFS referral, server
interface list, EA list, POSIX SID, snapshot enumeration and SMB1
reparse point parsing
- Fix use-after-frees and races in multichannel and connection
teardown, including an interface freed while still in use when
adding channels, a server used after its channel reference was
dropped, a reconnect work item left queued after the server is
freed and an uninitialized reconnect list node
- Fix a heap overflow in the native symlink parser: an absolute
target without an NT drive prefix caused out-of-bounds writes and a
u16 length underflow leading to a 64K memcpy into a small buffer,
triggerable by a user with write access to a mounted share under
default settings
- Fix WSL reparse point parsing: use unaligned accessors for the
packed extended-attribute payload to avoid alignment faults on some
architectures and stop leaving partially mutated fattr fields on
parse failure
- Fix lease break ACKs being sent through the wrong session on
multiuser mounts, which caused read failures (e.g. on NetApp
ONTAP/Azure Files) when copying files
- Fix an smbd_connection leak when cifs_get_tcp_session() fails after
an RDMA connection was already established
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQTcqRusfSdYROJQwGkpVtNKoQNdYwUCaq2frwAKCRApVtNKoQNd
Y1mcAQDcDTkep03jzghyJG6xWJ3S7KNbeYpjkOPnPyR+Et7HmAD/eXLFvgkJ3wC7
tBUDjDTLeyP6/DOBmDb/fIKEw2vfBQs=
=+Vsw
-----END PGP SIGNATURE-----
Merge tag 'cifs-fixes-7.3-rc4' of https://git.manguebit.org/linux
Pull smb client fixes from Paulo Alcantara:
"A batch of bug fixes for the smb client:
- Fix multiple out-of-bounds reads and use-after-frees in the SMB2/3
receive path that are reachable from a malicious or compromised
server: a stale next_buffer pointer and an integer overflow in
compound encrypted frame handling, missing minimum-PDU-size and
per-sub-PDU length validation before parsing command-specific
response fields, missing bounds checks in DFS referral, server
interface list, EA list, POSIX SID, snapshot enumeration and SMB1
reparse point parsing
- Fix use-after-frees and races in multichannel and connection
teardown, including an interface freed while still in use when
adding channels, a server used after its channel reference was
dropped, a reconnect work item left queued after the server is
freed and an uninitialized reconnect list node
- Fix a heap overflow in the native symlink parser: an absolute
target without an NT drive prefix caused out-of-bounds writes and a
u16 length underflow leading to a 64K memcpy into a small buffer,
triggerable by a user with write access to a mounted share under
default settings
- Fix WSL reparse point parsing: use unaligned accessors for the
packed extended-attribute payload to avoid alignment faults on some
architectures and stop leaving partially mutated fattr fields on
parse failure
- Fix lease break ACKs being sent through the wrong session on
multiuser mounts, which caused read failures (e.g. on NetApp
ONTAP/Azure Files) when copying files
- Fix an smbd_connection leak when cifs_get_tcp_session() fails after
an RDMA connection was already established"
* tag 'cifs-fixes-7.3-rc4' of https://git.manguebit.org/linux:
cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
smb: client: fix potential OOB read in smb3_enum_snapshots()
smb: client: fix missing iov bounds check in parse_posix_sids()
smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
smb: client: reject short Next offsets in parse_server_interfaces()
smb: client: fix missing lower-bound check on DFS referral string offsets
smb: client: fix server->total_read for compound encrypted PDUs
smb: client: validate minimum PDU size before smb2_get_data_area_len()
smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
smb: client: fix use-after-free of iface in cifs_try_adding_channels()
smb: client: fix fattr leaking on wsl_to_fattr() failure
smb: client: fix unaligned access in WSL reparse point parser
smb: client: fix smbd_connection leak on cifs_get_tcp_session() error
smb: client: fix rlist race and missing initialization
smb: client: cancel reconnect work in clean_demultiplex_info()
smb/client: send lease break ACKs thru correct session for multiuser mounts
smb: client: validate absolute native symlink targets before NT fixups
|
||
|
|
925724c081 |
SCSI fixes on 20260918
Four driver fixes, three of which are minor and one of which (fnic) tries to add some logic to try to avoid MSI-X being ineffective if hyperthreading is disabled. The core fix adds validation to mode sense buffer sizes because it is used by ATA and could, theoretically, be exploited by a specially crafted USB device that can simply be plugged in to any laptop or server. Signed-off-by: James E.J. Bottomley <James.Bottomley@HansenPartnership.com> -----BEGIN PGP SIGNATURE----- iLgEABMIAGAWIQTnYEDbdso9F2cI+arnQslM7pishQUCaq2P/hsUgAAAAAAEAA5t YW51MiwyLjUrMS4xMiwyLDImHGphbWVzLmJvdHRvbWxleUBoYW5zZW5wYXJ0bmVy c2hpcC5jb20ACgkQ50LJTO6YrIXJ6AD9FODcORvjoRDhcU626EWsG/Hoy7YcMH2T bZVtZwp3hH8BAPnKar5uj3fCQxJkvI+sLKjiGultTi3llt9VaZGSTFj2 =JgQF -----END PGP SIGNATURE----- Merge tag 'scsi-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi Pull SCSI fixes from James Bottomley: "Four driver fixes, three of which are minor and one of which (fnic) tries to add some logic to try to avoid MSI-X being ineffective if hyperthreading is disabled. The core fix adds validation to mode sense buffer sizes because it is used by ATA and could, theoretically, be exploited by a specially crafted USB device that can simply be plugged in to any laptop or server" * tag 'scsi-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi: scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable() scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU scsi: ibmvfc: Add Kconfig dependency to fix link failure when NVME_FC=m scsi: qla2xxx: Fix the ql2xfc2target parameter description scsi: pm80xx: Fix the use_msix, use_tasklet and read_wwn parameter descriptions |
||
|
|
ef31d04b6d |
pci-v7.3-fixes-1
-----BEGIN PGP SIGNATURE----- iQJIBAABCgAyFiEEgMe7l+5h9hnxdsnuWYigwDrT+vwFAmqtiM0UHGJoZWxnYWFz QGdvb2dsZS5jb20ACgkQWYigwDrT+vxDxg/+Nyqg0N+1xxHnG+bsbJ7XA7v7sQY5 DcvfvnMcJg3Lx5ioED4OJwr35rQZy8E3n/swFCxvzyZQ6gp+Q3sA2wUeuqd26kCS OSuMwRj3+HsnCVlYC/LL5fUoyZ+/FFv4drDPvIl3vCo5kIoNuWJslIox1eqPgmtZ SZO70qyQcA8jjCHYqQR07kvtqyainZrOoPP5uASnRqSGVlTLI3mzKdLtzrVytgel bAb6CPKrqF1XQY2HBBH3MEU6mhXbr7zeSrncZnb0QimqHCloq4dUK+WF9ZQnxSk5 wXgftOvg2ycYhE6hUVZGrRf/fMwzWatkD/Vi9a69wKN2lspwacKCGi0LhNS1u/Em ypak/Wg0sEic5y//eOgJjIfodJLsHiyvBIZxC3ziqZj1q6Kc4pCvg1iHePFYCSQj gB4Khkm6sWx63GX02g9ytc9bl00xCkjuck8OSVExP2MhaWajlksvzy9VXsZG9BzH QianraVVqVZd+LM3eFTy16qaD7jQuNMCIzOzB3UDh2gSzO+Lr9OtK36iTsn0NELc lKjrIlh5yEp5uD9vrrD4k8xAbaVGBnzzK7Whc42rt2n/gIs2SbV8TXWTyxtk29DJ XlbUAOiBLYEuO3YWAvq47kezyafwRtBqXxjyyoZajteD+hoRFFtkcT5OcaiWVZUL qzRbS1eB3IfB/q8= =9dUn -----END PGP SIGNATURE----- Merge tag 'pci-v7.3-fixes-1' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci Pull PCI fix from Bjorn Helgaas: - Enable clock after core reset is asserted to fix enumeration regression on i.MX6Q Apalis platforms with ASM1061/ASM1062 SATA controllers (Richard Zhu) * tag 'pci-v7.3-fixes-1' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci: PCI: imx6: Move clock enable after core reset assertion |
||
|
|
c3d85c669d |
- Fix session expiration so that valid sessions are no longer removed
after ten seconds of inactivity when a new session setup request is
received. Sessions now expire only after credential expiration, while
stale unauthenticated sessions are cleaned up after a 45-second timeout.
- Keep earlier responses in compound requests when Query Info fails
because the output buffer is too small. The error response is appended
without truncating preceding responses.
- Return STATUS_BUFFER_OVERFLOW for partial
FILE_NORMALIZED_NAME_INFORMATION responses instead of incorrectly
returning STATUS_INFO_LENGTH_MISMATCH.
-----BEGIN PGP SIGNATURE-----
iQJKBAABCgA0FiEE6NzKS6Uv/XAAGHgyZwv7A1FEIQgFAmqtTBMWHGxpbmtpbmpl
b25Aa2VybmVsLm9yZwAKCRBnC/sDUUQhCD2GD/9OzkmZ+/kIMum8IQi9upOM5zUD
+2nyFMebJ6qXmrhOuUgLn2ptUYxO3q1B9VvzTjKrM1Vun0VuvHmHQbGUp9a/3F7c
VTncl7E3FEHqlPkLWQJFv2dS+TYYcOhjoc2TDAY9093xktcMHK5zjv4E/DV2o0bf
NN/GcrrcWSxdJU8WI9JvY2kzmPQMDfM8uVbj2RqHSZ8m9mF5cajtDnzCCS0K6UOR
qzMrekzewIskUtcQNqU8hJWl1sgiYdD+16LmKmwLd3uOZISc3Miy5Bg8VpNN+B1g
XHhr49G4Fb8PkEYjncjxQH7zop1ID5UyC2xN63NuoH8+mkm4qn6uG2NrLhmVQO+f
Z81Ov3g77/jK3Z2fw00H3A7VGSPs931BaRTNj+lPkHTVVq3PyP1XZsfXkPUoRu1Q
xeaJydScGNYE+kaYbseXwN8haJGawd1Dd+Afn4W2zikUU5tKZxO9d2tBr4Fhl/Fm
0OBcAssTArhrY7PX2fAOQ4sUwAC4nMXSEIfdWIvcgU2OoyuFltQ55ooCoM0uLs6+
7R4rxZLipdZmKhuE2mlAWcFQJn8nS0EHXeyEDjO0u8KYsV6C8d+jDNpvtS+/5QVF
bKE4/uUX/lV0IZ55nFSPT7XdI+gxeiUql3+8bqOVqkw7wR4VjaC0xIQybyEBTMYH
IJEKfjx4tZcWGTzmdA==
=9nNl
-----END PGP SIGNATURE-----
Merge tag 'ksmbd-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb
Pull smb server fixes from Namjae Jeon:
- Fix session expiration so that valid sessions are no longer removed
after ten seconds of inactivity when a new session setup request is
received.
Sessions now expire only after credential expiration, while stale
unauthenticated sessions are cleaned up after a 45-second timeout.
- Keep earlier responses in compound requests when Query Info fails
because the output buffer is too small. The error response is
appended without truncating preceding responses.
- Return STATUS_BUFFER_OVERFLOW for partial
FILE_NORMALIZED_NAME_INFORMATION responses instead of incorrectly
returning STATUS_INFO_LENGTH_MISMATCH.
* tag 'ksmbd-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb:
ksmbd: keep compound responses on query info errors
ksmbd: fix partial normalized name responses
ksmbd: follow SMB2 session expiration semantics
|
||
|
|
bfda5a01aa |
- Make MFT extension work on existing Windows-created volumes by
dynamically reserving MFT tail records, accounting for records added
during allocation, and avoiding false -ENOSPC failures.
- Repack non-resident $MFT/$ATTRIBUTE_LIST when its mapping pairs no longer
fit in the base MFT record, while propagating allocation and writeback
errors.
- Serialize runlist updates with the runlist lock and restore both the
in-memory runlist and on-disk mapping pairs when allocation rollback is
required.
- Propagate folio errors and harden inode failure handling by treating
interrupted reads as transient failures and discarding and unhashing
inodes whose initialization fails.
- Fix the $MFTMirr write offset when mirror records span multiple folios,
preventing mirror records from overwriting the first record with large
MFT record sizes.
-----BEGIN PGP SIGNATURE-----
iQJKBAABCgA0FiEE6NzKS6Uv/XAAGHgyZwv7A1FEIQgFAmqtRIEWHGxpbmtpbmpl
b25Aa2VybmVsLm9yZwAKCRBnC/sDUUQhCBK8EAChFdTxig3sYog3dL27SX+1yNC4
S1QtSQMvPJzcvLG2/mESC57snx1u6AXZ6enaQ/m8zQQvkWHFdwD+odgjOQ3474Yc
MS7xQn5pCsAo3LmSWiDsQfHmvxgDMYlIRU1vmqr7fG2pj+W6BR2LB1PD3RI9exI7
0WWAXBPZH5w5C9GE1Zo7TF9Xwby5Or31RS8+R57PXA/PJ1ivpWnlkpfLi4M/YkZK
GIpunZafSpcKbEsuWcjhdz11bR4G9Qlwuuq0MDguLC/qsqsobHCeSbdx+4IsEAq5
02yBl5hYm2E4u2KBedpe7oRwFvlPN0uakEGYS8SA1ad9XamjGIw6T0tkzkDL48Pq
dhVAeX2oa8O9u+VK+qF/HIUylh/UbmHQJW8iSiZWO8WdULGBG8oCHI1hcSnMguwJ
njyK75UXz4fMsKW6ZpRu0sRGqtKKcbg8IrCvLslPIOS2A9OAwSzytDKI+x1Kbgu0
SVPYjf6XeOz83tvE+2OhfTT1hWkeKezMiUe4E/y9rgEDxv5vE4C5pvpDfRlj3oyn
2JTXXjjUQGSQw/9cKbLsbElDH/FLEojLAsIFgM+2FbcG+x7PUUgSGdC4R4qZ9MUF
cuMzfhi8vKyCYmJc8nNE4J6b6UkBNOFJMYBcArtByFW3LqfIzmqwW81Xx0Hz4cxi
dmOhD6gXXYoi9m3lBQ==
=rT1L
-----END PGP SIGNATURE-----
Merge tag 'ntfs-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/ntfs
Pull ntfs fixes from Namjae Jeon:
- Make MFT extension work on existing Windows-created volumes by
dynamically reserving MFT tail records, accounting for records added
during allocation, and avoiding false -ENOSPC failures
- Repack non-resident $MFT/$ATTRIBUTE_LIST when its mapping pairs no
longer fit in the base MFT record, while propagating allocation and
writeback errors
- Serialize runlist updates with the runlist lock and restore both the
in-memory runlist and on-disk mapping pairs when allocation rollback
is required
- Propagate folio errors and harden inode failure handling by treating
interrupted reads as transient failures and discarding and unhashing
inodes whose initialization fails
- Fix the $MFTMirr write offset when mirror records span multiple
folios, preventing mirror records from overwriting the first record
with large MFT record sizes
* tag 'ntfs-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/ntfs:
ntfs: fix $MFTMirr write offset when it spans multiple folios
ntfs: unhash failed inode reads
ntfs: discard inodes that fail initialization
ntfs: ignore interrupted inode reads as corruption
ntfs: propagate folio errors
ntfs: protect runlist updates with the runlist lock
ntfs: account for MFT records added during allocation
ntfs: repack $MFT/$ATTRIBUTE LIST
ntfs: use dynamic MFT tail reservation
|
||
|
|
8cb0606271 |
MMC core:
- Prevent potential use-after-free for SDIO IRQ work - Fix OF node reference leak on card add failure - Fix memory lea when the port table is full for sdio_uart MMC host: - hsq: Fix use-after-free in retry work - mmci: Fix use-after-free in busy-timeout work - mmc_spi: Reset bytes_xfered before retrying CRC failures - mxcmmc: Cancel data work and watchdog on remove - rtsx_pci_sdmmc: Ignore broken write-protect on ThinkPad X260 - sdhci_am654: A couple of fixes for the tuning sequence - sdhci-of-aspeed: Remove children before releasing SDC resources - sh_mmcif: Initialize IRQ-thread mutex before requesting interrupt MEMSTICK: - ms_block: Destroy io_queue workqueue on removal -----BEGIN PGP SIGNATURE----- iQJEBAABCgAuFiEEugLDXPmKSktSkQsV/iaEJXNYjCkFAmqtI4oQHHVsZmhAa2Vy bmVsLm9yZwAKCRD+JoQlc1iMKcjwD/91lyNP8fb8cxorEtmkiNt63Sb+glVEnobW aOlXS23GuV9ZsPw7kKEEfZ4EWCOTEZ86Lj0OMzlpXE8dxYHGlu0qG97uxSiJ4wux LQ0+OR5ljqDN48BWrn3wWsJ1YLfM4xXL7XukiCEuxLU9jwlbPHNjtY8c0+JqMapH D1yE7tH7/ZPJuYwKt9DJlx5DKg0BTiRn/7j+o3IETNyuBP05ZzrUjNdgQW8DVawg 2uR0GCZ268Asd7XhnywvLXbeg5jxRAEVMGVjEzn2CY5uY0YyUW9ye9e+TpbNqpYf OA2MnYiTNpcRIiI3Z8R5vrhGxMpqFd5hFdIUE64O5gnjSyrBKeo9SSw4huXlLvac xjdBYmtLxSQjIgvZaEG4hl12lJt/snLJODTEq690zei9oWCUnCKzZaargLFPcDje 0J8HwPYStynI0nc2Jc4oGZEGGwgvSmFPk15JtMEdmJb3eIwOfzGLA1ky9+5VEVCC zzMifnvnseAJwz+iAaJYxkED3Gd4t/jm4n8XIihddsKBQHAbMtGhUmhSzNnzD6NF xgscpv8s8SKExwS6X+6f/SBZD4VoF9b1JDhJ+fVUJDQ1Dsgv9AyT/bl8gDBHPNwr JHflPaQhc3hM9RppdcZnW3KSCu3DCJ04XaoHy6m5zKWZHUBEAtxujHA5u373Wv89 StY7v7d7UQ== =KPXN -----END PGP SIGNATURE----- Merge tag 'mmc-v7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/mmc Pull MMC/MEMSTICK fixes from Ulf Hansson: "MMC core: - Prevent potential use-after-free for SDIO IRQ work - Fix OF node reference leak on card add failure - Fix memory lea when the port table is full for sdio_uart MMC host: - hsq: Fix use-after-free in retry work - mmci: Fix use-after-free in busy-timeout work - mmc_spi: Reset bytes_xfered before retrying CRC failures - mxcmmc: Cancel data work and watchdog on remove - rtsx_pci_sdmmc: Ignore broken write-protect on ThinkPad X260 - sdhci_am654: A couple of fixes for the tuning sequence - sdhci-of-aspeed: Remove children before releasing SDC resources - sh_mmcif: Initialize IRQ-thread mutex before requesting interrupt MEMSTICK: - ms_block: Destroy io_queue workqueue on removal * tag 'mmc-v7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/mmc: mmc: sdhci-of-aspeed: Remove children before releasing SDC resources mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt mmc: core: Fix OF node reference leak on card add failure mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260 mmc: sdio_uart: fix xmit_fifo leak when the port table is full mmc: spi: reset bytes_xfered before retrying CRC failures mmc: sdhci_am654: Fallback to DT-provided itap delay on DDR50 tuning failure mmc: sdhci_am654: Clear ITAPDLY on tuning failure mmc: sdhci_am654: Reset command and data lines on failed tuning mmc: sdhci_am654: Move tuning_loop to local variable mmc: hsq: Fix use-after-free in retry work mmc: mxcmmc: cancel data work and watchdog on remove mmc: mmci: Fix use-after-free in busy-timeout work mmc: core: Cancel SDIO IRQ work before freeing host memstick: ms_block: destroy io_queue workqueue on removal |
||
|
|
ae09f35bd3 |
ata fixes for 7.4-rc4
- Explicitly clear upper address bits on quirked AHCI controllers
AHCI controllers that claim to support 64-bit DMA, but which have
been quirked to only do 32-bit DMA, could start the DMA engine
with a non-zero value in the upper address bits registers (me)
- Fix a resource leak in ahci_platform_get_resources() (Wentao)
- Fix invalid kernel-doc formatting for ata_dsm_trim_pages() (me)
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQRN+ES/c4tHlMch3DzJZDGjmcZNcgUCaq0h5wAKCRDJZDGjmcZN
cla0AQD9oseos93LDPzXR5SSMirdjoL9Qee8RsVeIMMlRtahiAD/Tx+vlEYrQ3QG
yESu9KV1YCaV2qDzG+nFjNt9Z6uc4wo=
=xqFb
-----END PGP SIGNATURE-----
Merge tag 'ata-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux
Pull ata fixes from Niklas Cassel:
- Explicitly clear upper address bits on quirked AHCI controllers
AHCI controllers that claim to support 64-bit DMA, but which have
been quirked to only do 32-bit DMA, could start the DMA engine with a
non-zero value in the upper address bits registers (me)
- Fix a resource leak in ahci_platform_get_resources() (Wentao)
- Fix invalid kernel-doc formatting for ata_dsm_trim_pages() (me)
* tag 'ata-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux:
ata: libata-scsi: fix ata_dsm_trim_pages() kernel-doc
ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources()
ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY
|
||
|
|
d24e3bf4c5 |
hwmon fixes for v7.3-rc4
* cgbc-hwmon: Add missing sensors, and fix current sensors ID lookup
* gpioufan: Return IRQ_HANDLED from the shared alarm IRQ handler to fix
possible interrupt storm
* hp-wmi-sensors: Improve raw WMI string handling, and fix UaF in show
function
* k10temp: Fix model id range of Zen5 Turin to stop reporting temperature
data for non-existing CCDs
* pmbus
- core: Increase number of phases to fix UaF problems
- tps53679: Fix TPS53676 phase page decoding, and select page 0
for single-page applications
* pwm-fan: Stop RPM timer before freeing tach data to fix UaF problem
* w83793: Release probe data through kref to fix UaF problem
* w83791d: Remove fan/pwm 4-5 sysfs group on remove to fix UaF problem
-----BEGIN PGP SIGNATURE-----
iQIzBAABCAAdFiEEiHPvMQj9QTOCiqgVyx8mb86fmYEFAmqtY4YACgkQyx8mb86f
mYHX0Q//UmlkmqkHH3XdKi1QX/RV60f82HfzXRkMq98FYocEYv4TKnru3U5pRLY3
Vs/h4GcDWT16ApqKbciBxgoUj72XBohm/T0gv8rhC/gkx4w8F7/CPuCB6vq9kIAj
EIOHM3KoulfwUN6K1JeFdo5sIrTMxYGnQoJjS31/HfExEGbcBMZjA4eWLkqA0s18
zmtYKbCJbG2WFRkI8/HKeQ2MwFE3RLNrxPVNvWJNzwIPjMvaAD7eDSsRjgXpaH6s
A2OHpnGkDLE1qeyuYYx+nFYmMQDGDxnt6QvEjX5cVUYE+jDIXuzF5HJVfLCaXoSJ
cFJmyNVTNE6Is1g6qeBRwObSq/NJH3O6p7kXCf5qwO27XBXgt/7K4q751tMq8oEE
kXiYn3WfBL4WJjYqQw8kEh2/D18fyj9XmoS7iBXzf1qXgRSROm/9irMBjsWiw0WF
92iE9U7UaE/a5fGX+dbRnB7QmLZ33U5TzA3ERb+MwJQj6o8Llvb5gmJOmlYebpa1
zRiu285Y3oGnjjkFgzvpps9hsVw3kb2Xs2utMbTPrJ2z4SUO9KInl+ifOr5w9VI+
sNU0Rn3eQ6IT40NMO9FhHPciZygKmob6hNDYh/6e+OulMDW7XW46ES2e8jjwME30
fjDpfKDxoAU/xQ548XQJBRcUNjUhV8S6NYZr3H4PpyWlPVmSkOY=
=lG35
-----END PGP SIGNATURE-----
Merge tag 'hwmon-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging
Pull hwmon fixes from Guenter Roeck:
- Add missing sensors, and fix current sensors ID lookup (cgbc-hwmon)
- Return IRQ_HANDLED from the shared alarm IRQ handler to fix possible
interrupt storm (gpioufan)
- Improve raw WMI string handling, and fix UaF in show function
(hp-wmi-sensors)
- Fix k10temp model id range of Zen5 Turin to stop reporting
temperature data for non-existing CCDs
- pmbus:
- Increase number of phases to fix UaF problems
- Fix TPS53676 phase page decoding, and select page 0 for
single-page applications
- Stop pwm-fan RPM timer before freeing tach data to fix UaF
- Release w83793 probe data through kref to fix UaF
- Remove w83791d fan/pwm 4-5 sysfs group on remove to fix UaF
* tag 'hwmon-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging:
hwmon: (hp-wmi-sensors) Improve raw WMI string handling
hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676
hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding
hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()
hwmon: (w83793) release probe data through kref
hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove
hwmon: (gpio-fan) return IRQ_HANDLED from the shared alarm IRQ handler
hwmon: (pmbus/core) increase number of phases and add new mask
hwmon: (cgbc-hwmon) Add missing sensors
hwmon: (cgbc-hwmon) Fix current sensors ID lookup
hwmon: (pwm-fan) Stop RPM timer before freeing tach data
hwmon: (k10temp) Fix model id range of Zen5 Turin
|
||
|
|
928ba50514 |
watchdog fixes for v7.3-rc4
* da9062, da9063: Fix suspend/resume handling of HW_RUNNING watchdog * digicolor, rtd119x, and rzv2h: Avoid division by zero if clock rate is 0 * msc313e: Fix premature reset during timeout update, and propagate error code in resume() * sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init() * starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start() -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEiHPvMQj9QTOCiqgVyx8mb86fmYEFAmqtZJEACgkQyx8mb86f mYGnwA/8C90wOrDbHonYx0SahuJaYniOmz6yHCuAR1AwtzKfXDua3WJ7ry4WfZXN WCACTcFCUp1CiLvstwpX7nDKGReYG47FOq6Rbou+JaJo43m9SGga5IGxKM28MBy7 F4TH3CDMSOcomlgPYeXc5jx0oRkNXyDPMDHtbCOM5h+WwJb0Zxtfh+77l5q2LrQg D7nIGCkoztl7PDIgbvYESp9DYVdUgT6paeIRjJbs5BCwmNleU9LInDPDAtcXHnRp cyCa8FlfPrQMxhtbF1YQyaEdU04GlAwtHW4HE55tcxY3pTE/9qqA5SUzQBDXT2gO yCCG1qIFOmJY6QnlSfIYpHZtNxcpA75d8fQvqm14H+ACxkbaRF1d+sobtJTTckTD WBSr6RlrB5f/DAltqbV2OAsLddhBl4rQkW2RiljTW4C4pUiedPoSR8StTpnM6lC3 VBpUdYp7tCIWihX/v/v+iRK1Y7JWVM+lhQnMpqBtpLtl3k7VLCLoFsmSbz0hHhu6 kAJ1ZWeBy2xYgiGOM+D361iKhefjsZk9tdrC8IxriJ/gUwlcazELqqcsvU+I5ebN sutAYvE6Vdl5qwiLIRRHNpHvKm0wu9URIpPJrdwDtAIbaT3joSZIkV3TA7ZFBwGG tU4Z9ok0O4N4DDPv0CAg82lXBrMiWt3agYKKkhKTsmKROqqWVa8= =oqFf -----END PGP SIGNATURE----- Merge tag 'watchdog-fixes-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging Pull watchdog fixes from Guenter Roeck: - Fix suspend/resume handling of HW_RUNNING watchdog (da9062, da9063) - Avoid division by zero if clock rate is 0 (digicolor, rtd119x, and rzv2h) - Fix premature reset during timeout update, and propagate error code in msc313e resume() - Fix pci_dev reference leak in sp5100_tco_init() - Fix runtime PM leak in starfive_wdt_pm_start() * tag 'watchdog-fixes-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging: watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog watchdog: starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start() watchdog: da9062: fix suspend/resume handling of HW_RUNNING watchdog watchdog: msc313e: Fix premature reset during timeout update watchdog: msc313e: Propagate error code in resume() watchdog: rzv2h: Avoid division by zero watchdog: rtd119x: Avoid division by zero watchdog: digicolor: Avoid division by zero watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init() |
||
|
|
5ad17a9760 |
This push fixes a regression in caam.
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEn51F/lCuNhUwmDeSxycdCkmxi6cFAmqqZ7AACgkQxycdCkmx i6d4jA/+Ozs275ubKEbaC+keI4/G8DZ/QDYFOTCr4SEBWHyhGh1od29AbHXhUGof 3Ev/Zzqg9mWRDhLo+tbx/ja9Qe3d7lHCHPcFPUsom0MumfGm8NaWgGxaxrrhRYwY EOks6UxolxUCw65/ECxcgxsOfp6LgcrNuapkIJRcg1R5s6kz9zAGhse+13AgAv1G 49x+AL1KkvJkPev6lZrhG+m0SX3P7CO5OVAe0NNFqSlaxBSg3JSO/JnEQK95B7vi cakFjskdfukqQs84hOq+KPI93pqbi7aZEemVsxGK2UdADVRr7C3Ls6nKiGQ7VtyR EW2hniQxHOruvDrXHMJpE92/Tw7g0LL6O5CZuKe+p2MfnQKEvVpPuWwysug0AhVU cKV4mBX/fu2bgV7o2QEGByhhAuCtcezGqbX5o2cYLdn/jX2DErNTWzLbdUHpcgLu bTWtIWzEwKZgqU5Oa9i4J6TdV6xcReh7gKKWykrQVodnvin6sUywsMmX3vkl33VJ upVo1FhLZnv0krUMTGUDNTzuVczEliM8c+dMEJcGLAzM3d0SdduRSukznX09Wrj8 yS0AH3Tqn81Ux5FWYxNMPSeKaTIRX14LG3jjzsLSq9iMTM50dZf6xmOS9ZyYh/+j tq3fPrBf3PVipdI9xhDOqDF9gYtG+FgVwt93Pb0Ao569HgWyS5c= =odnL -----END PGP SIGNATURE----- Merge tag 'v7.3-p4' of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6 Pull crypto fix from Herbert Xu: "Fix a regression in caam" * tag 'v7.3-p4' of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6: crypto: caam - map job ring registers without claiming region |
||
|
|
f259f446f5 |
soc: fixes for 7.3
The driver fixes are all for simple mistakes: a use-after-free bug on Samsung Exynos, error handling and reference counting on Arm SCMI firmware and a problem dealing with inconsistent firmware information. The rest are devicetree fixes for arm64 platforms from Altera, Renesas and Amlogic. On the Renesas platform, one patch addresses a boot time regression, the rest address minor performance and correctness issues. -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEo6/YBQwIrVS28WGKmmx57+YAGNkFAmqtProACgkQmmx57+YA GNku+BAAsyHGF7f7tniVyH1lDfZ+BY8G0i8856Pgi6xJfwTPcrtxJe15ALFJz5sa DRvCmt3fx2e4LmED2wEfTVYr+RIEmlgD27pT8lUvMo4avIcXlIxtAlqCOyKTOALS LzOJPD5VaEs/ZKXqqGDPnHzYJNO9DJ18uAuk8yGY7cK4z4IV+aANCJzCN83vhYu2 OAl37i/0PmaMhHTgLgIugd2uc28GJsyZQiFu9k9hlRWGjn9WpYivSohbF8p8Cqcw Eg/TzWVNcTrm95uuHbhaQ3tsYDtBHoy5V7e5w1a4NnJ7ufouW/I1Z9s2OrulWadY 3Hw/pEtrkWAgK1NMfAaXtErkWUjuKeMRzWwOZ0NR4Zi0Zsdt+VTyDajSLbUEuePI AfknmGcrgSIgK/HlSkLw5R0VnYI8duUjnBSDVTKBLMxFnAdBs/vDhr/ZDy8HgLjN i+Poe36q6JLTw88/d/uF+2T2HdZXwPiL9tDl16WmAUQOvZOcr6dfQdLZGIb8zwuV rghM9rnh7v2Lb5nFsC++MebH2xNw33faWplpnc0WxcUdzov20Wcr7IbdNVzKaVTn IcnjnTtCCaxXM9NxyjMrxJ8+tkkFAPyDczSPxcxL3xcOjoQ2nr4XlfPMaYwoV2N7 siwksezj55bWANuZwxObou3ZJgHHFqO0RYUdtJxDn/mBnWNOq3A= =Z5GP -----END PGP SIGNATURE----- Merge tag 'soc-fixes-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/soc/soc Pull SoC fixes from Arnd Bergmann: "The driver fixes are all for simple mistakes: a use-after-free bug on Samsung Exynos, error handling and reference counting on Arm SCMI firmware and a problem dealing with inconsistent firmware information. The rest are devicetree fixes for arm64 platforms from Altera, Renesas and Amlogic. On the Renesas platform, one patch addresses a boot time regression, the rest address minor performance and correctness issues" * tag 'soc-fixes-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/soc/soc: (21 commits) soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node arm64: dts: renesas: r8a779f0: Set UFS lane count firmware: arm_scmi: Fix typo "upto" in comment arm64: dts: renesas: r9a09g087: Switch GBETH TX queue scheduling to WRR arm64: dts: renesas: r9a09g077: Switch GBETH TX queue scheduling to WRR arm64: dts: renesas: r9a09g047: Switch GBETH TX queue scheduling to WRR arm64: dts: renesas: r9a09g056: Switch GBETH TX queue scheduling to WRR arm64: dts: renesas: r9a09g057: Switch GBETH TX queue scheduling to WRR firmware: arm_ffa: Tear down driver during shutdown clk: scpi: use PLATFORM_DEVID_NONE for scpi-cpufreq clk: scpi: register scpi-cpufreq once and clear on failure clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS firmware: arm_scpi: fix device_node leak in scpi_dev_domain_id arm64: dts: socfpga: change access permission from 755 to 644 ARM: socfpga: select the PL310 erratum 753970 workaround arm64: dts: amlogic: t7: fix the pin groups of the vsync PWM arm64: dts: amlogic: t7: khadas-vim4: add the PWM-driven supplies arm64: dts: amlogic: t7: fix the pin groups of two PWM outputs arm64: dts: amlogic: t7: khadas-vim4: allow the SD card to be power cycled ... |
||
|
|
a077be4fde |
arm64 fixes for -rc4
- Fix hypercall arguments when resetting EL2 vectors during hibernation
- Fix hibernation with 52-bit capable kernels on machines without
52-bit addressing, similarly to the recent kexec fix
- Fix a bunch of clumsy codegen issues with our per-cpu accessors
- Fix MTE ptrace documentation to reflect the de-facto ABI behaviour
- Fix pthread_join() usage in MTE selftest
- Fix port selection in the Arm CMN PMU driver
-----BEGIN PGP SIGNATURE-----
iQFEBAABCgAuFiEEPxTL6PPUbjXGY88ct6xw3ITBYzQFAmqtMZ4QHHdpbGxAa2Vy
bmVsLm9yZwAKCRC3rHDchMFjNNujB/4pa4pdivXRMOH39HSDu+8i3KlREGpTA9dq
LJvwUjlgoIw0d8/b5sMSAxJi8RA29IENJPqrU97eBBLKgC2gq1oMwjOaHNTV8XUj
gal9hwuZcfO5NIJi61TkyLxn++ysVYXD3J0tbhSXbqz2oeg/jxwj9SsFfQux34GY
GeGb2cWvEXznLgN0h+vZiNh6+FsQRN+dizpiHKLh+wpbZ/vIzuVTQEo6w/+BEUWg
R4YQlvpj/2yAC0BBdPb9gALUWFbjea6zpX5gM5/PgLoqW0CIJvGXahZ7T5kDoXBT
Xp5zsKvcC8dxM5nCJIJ7xRPg75v97toYrrl2AoNQN9bgOynQAI5k
=j0NQ
-----END PGP SIGNATURE-----
Merge tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux
Pull arm64 fixes from Will Deacon:
"In this batch we've got a couple of hibernation fixes, a couple of
minor MTE fixes, some per-cpu codegen fixes (which were found as part
of Mark's series adding preemptible this_cpu_*() operations) and a fix
for the Arm CMN PMU driver.
Summary:
- Fix hypercall arguments when resetting EL2 vectors during
hibernation
- Fix hibernation with 52-bit capable kernels on machines without
52-bit addressing, similarly to the recent kexec fix
- Fix a bunch of clumsy codegen issues with our per-cpu accessors
- Fix MTE ptrace documentation to reflect the de-facto ABI behaviour
- Fix pthread_join() usage in MTE selftest
- Fix port selection in the Arm CMN PMU driver"
* tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux:
arm64: mte: Fix PTRACE_{PEEK,POKE}MTETAGS error documentation
kselftest/arm64: Fix size of thread_data values for pthread_join()
arm64: percpu: Fix LSE operations on {8,16}-bit types
arm64: percpu: Fix this_cpu_and() mask generation
arm64: percpu: Fix this_cpu_write() casting
arm64: hibernate: clone only the linear map that exists at runtime
perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations
arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc
|
||
|
|
5023f5b861 |
- Fix kconfig dependencies for ECONET
- Enable weak reordering for EYEQ - Include USB FDT fixup for Octeon even when USB is modular -----BEGIN PGP SIGNATURE----- iQJOBAABCAA4FiEEbt46xwy6kEcDOXoUeZbBVTGwZHAFAmqs5dUaHHRzYm9nZW5k QGFscGhhLmZyYW5rZW4uZGUACgkQeZbBVTGwZHBYbg//QPIXQOga1IcvP7OJlLxu UocYmNpgVJtPCksDtnBUx82o/D+CZdqeGtHNP6ak5YpyXOcQpUdMuYSwHwIXsHLB HhVOBmyVgyNlP0zo8zXE3iW1JMz1wfSSigDZdPFX8Jq3O5RsMq3udHJYZtAEXnIM eV8m465I9DnJWX9mlETqTli5cwL5VpDYRSy1fmGF4CYgRvbErrUZ0iZSvqdwRe7v J/p+sLBsSmEoxXL5etpvHLet+Jr9Eb8v+1k8262YcoPfvENeu3cYJpvZnIgXmeol T912xD+JmLapcICNot0QvrMZJ3RVSu/Z6ddxCGqHmiEiQGMYB9xrWYbgfQ/9hGKp aup5G1X3n3YPKd60DKRnSFgZ4+xPzEoUTh5nKlMz0XqZmtoa9m00BRTXhi8XoqFK kvBRJREb4Za3Ig40dhIJTcluLoLjgPqUs+1MfwnFnXZTbuctSZ4BtEauQL1x/A6E EbQ7gvesMQHUwW6fb70U9UbhlKuI/8t1Ao7OuI5+qs6+qnvgiScavW8CDu+W16s1 tbFQFUN1ZkP0a0SXkl5JGu6WOkl9fc3TkBDrmfuK68Fu2hUMAiE/ffCoBq+6iZBj pkagkDr5CjFxogpKveE02l9WJAVAujzMmyCusTv2NQ53mu2ZloCT3BA3cKsM6vFP dPtQD7d5qIEK3WPMENxCrcA= =PNfi -----END PGP SIGNATURE----- Merge tag 'mips-fixes_7.3_1' of git://git.kernel.org/pub/scm/linux/kernel/git/mips/linux Pull MIPS fixes from Thomas Bogendoerfer: - Fix kconfig dependencies for ECONET - Enable weak reordering for EYEQ - Include USB FDT fixup for Octeon even when USB is modular * tag 'mips-fixes_7.3_1' of git://git.kernel.org/pub/scm/linux/kernel/git/mips/linux: MIPS: Octeon: apply USB FDT fixups also when USB is modular mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ MIPS: config: Add EcoNet EN751221 defconfig mips: econet: fix unmet dependencies for ECONET |
||
|
|
7cb575b71a |
watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog
da9063_wdt_suspend() and da9063_wdt_resume() only check watchdog_active(),
when the watchdog is left running by the driver sets
WDOG_HW_RUNNING in da9063_wdt_probe() but userspace never opens the
device, so WDOG_ACTIVE remains cleared, the wdt_disable() will not be
executed in da9063_wdt_suspend. In this case, the suspend callback is
a no-op and the watchdog keeps counting during system suspend,
leading to an unexpected system reset.
Check WDOG_HW_RUNNING and wdd,can fix this issue.
Fixes:
|
||
|
|
4dd1999783
|
soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node
The setup_cpuhp_and_cpuidle() parses the device tree node for the
interrupt generation block via of_parse_phandle() and decrements its
reference count using of_node_put() immediately after fetching the resource
address. However, later the intr_gen_node pointer is passed into
of_syscon_register_regmap().
Fix this by declaring intr_gen_node with __free() and removing
of_node_put().
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260513-exynos850-cpuhotplug-v4-0-54fec5f65362@linaro.org?part=3
Fixes:
|
||
|
|
2d5061ff37 |
Renesas fixes for v7.3 (take two)
- Fix UFS regression on R-Car S4. -----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQQ9qaHoIs/1I4cXmEiKwlD9ZEnxcAUCaqztfAAKCRCKwlD9ZEnx cLmlAP4hG63oxIP1QUeZpEMjRkTBGhFXnlSkvluVyrd8otWniQEAvCCC31KtKqqK B9W1mWzwBX9UITXB4cL69Zw/26W9+QI= =5xv9 -----END PGP SIGNATURE----- gpgsig -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEo6/YBQwIrVS28WGKmmx57+YAGNkFAmqtL8EACgkQmmx57+YA GNkQ9A/9FuSvFGANim6ksz5JN4ObTC4hjJu8rxrxF3uGekQNJZPO06EDU9DkM/bJ XOLDFkt3k+M3e60wdH9NKzEl54xQxyLre2XyRN2diit3ihDF9Jrv3YPFzuZcA+gR vmRh9LLIStdDNxGbRrEubfx1+WqbiNpkXqE8syXVsn93hYduMsWnrSReXA5jGENt Wjq9ghujL9Othgh8B1FOi6W4oupsBN1mCLAL0DJ0k8z0whBfb2Qkq5tnrDCPcjXc CVKzVWqe5nIMw5akMu14MToId3JpTxTrws5FOP4OUoxEVL/sCBUbS4PNujgHEMVh Ovd5DmpfNjWOB+rr4/B/u2H97e6AmNvCp5Sbd8gADBCO7RHD9zxYbGYPy9Pemhqd YBNAufAR3Bkkq0IheXVS5Dtzg2TSUchomaIz7o/hhMBu4lLdaVJyyalAy5bVOR1W l7DtetG1DqABWAsF5pm0Q8iy7lFEJlzWdhzONJn4TBCXOLi6k3lO07gmd+eIYhyM EvssZFTciDoyhurdDgqeLfjKQvvgiOi0l4SpdT606+YMipz5C5zo0oPOk4j26qvp 22Mw3JupFQCDCwsN37locBhQccdKfHuzfsy52vDMxHRuOcpnfIIcCsPkaMq5VMQu Bm8c3No5AJQGcODe4Rg7nmZrxzSNnilWGxKSkWH7C0J5vbzuXRY= =9HfJ -----END PGP SIGNATURE----- Merge tag 'renesas-fixes-for-v7.3-tag2' of git://git.kernel.org/pub/scm/linux/kernel/git/geert/renesas-devel into arm/fixes Renesas fixes for v7.3 (take two) - Fix UFS regression on R-Car S4. * tag 'renesas-fixes-for-v7.3-tag2' of git://git.kernel.org/pub/scm/linux/kernel/git/geert/renesas-devel: arm64: dts: renesas: r8a779f0: Set UFS lane count Signed-off-by: Arnd Bergmann <arnd@arndb.de> |
||
|
|
5dd1818b15 |
Hi
Please pull these bug fixes for keys accumulated since v7.3-rc1. BR, Jarkko -----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQRE6pSOnaBC00OEHEIaerohdGur0gUCaqxgxQAKCRAaerohdGur 0jQdAQDG18jcqZxuj+DC4H5FIqRNBn+YhhRA2iOT1Qwc6wSpNAEAkgl6rdm4KY8l EQj0HTbX8qEXSsuGGkoA41lYlwf0pAY= =jCQU -----END PGP SIGNATURE----- Merge tag 'for-next-keys-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd Pull key fixes from Jarkko Sakkinen. * tag 'for-next-keys-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd: KEYS: encrypted: fix integer overflow of datablob_len KEYS: trusted: Fix tpm2_load_cmd() boundary check keys: translate request_key_auth pid for the reading procfs instance keys: fix lost wakeup when reaping a dead key type |
||
|
|
717e0a2503 |
cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
When a secondary channel is no longer supported by the server,
cifs_chan_skip_or_disable() drops the channel reference with
cifs_put_tcp_session() and then continues to use the server pointer by
calling cifs_signal_cifsd_for_reconnect() on it and reading its
primary_server pointer. cifs_put_tcp_session() can drop the last
reference of the channel and tear it down, so both the channel and the
primary server (whose reference is also dropped by
cifs_put_tcp_session()) can be freed before they are signaled for
reconnect.
Signal the channel and the primary server and capture the primary
server pointer before dropping the channel reference with
cifs_put_tcp_session().
Fixes:
|
||
|
|
c9dc7d7303 |
PCI: imx6: Move clock enable after core reset assertion
Commit |
||
|
|
5f0306e731 |
smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
In cifs_query_reparse_point(), the start >= end check before casting to
struct reparse_data_buffer * only ensures the start pointer is within the
response. It fails to verify that there is enough space remaining for the
fixed 8-byte header of the structure.
If a server provides a DataOffset that leaves less than 8 bytes remaining,
the check passes, but subsequent reads of ReparseTag and ReparseDataLength
will occur out-of-bounds.
Fix this by ensuring the remaining space is at least the size of the
reparse_data_buffer structure before accessing its fields.
Fixes:
|
||
|
|
4775c3b7a5 |
smb: client: fix potential OOB read in smb3_enum_snapshots()
If snapshot_array_size is smaller than GMT_TOKEN_SIZE,
smb3_enum_snapshots() sets ret_data_len to
sizeof(struct smb_snapshot_array) without verifying the actual length
of the server's reply.
Because SMB2_ioctl() places no lower bound on the server-supplied
OutputCount and allocates retbuf to exactly that length, a short reply
results in ret_data_len exceeding the size of retbuf. The subsequent
copy_to_user() then reads past the end of retbuf, leaking adjacent slab
memory to userspace. The subsequent clamp check is ineffective as it
only reduces ret_data_len.
Fix this by rejecting replies shorter than
sizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set
to the 12-byte struct size rather than the 16-byte
MIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes
is exactly what copy_to_user() attempts to read.
Fixes:
|
||
|
|
b09d092eb2 |
smb: client: fix missing iov bounds check in parse_posix_sids()
In parse_posix_sids(), sidsbuf_end is calculated using the server-supplied
out_len without being validated against the actual length of the received
iov (iov_len).
If a server provides an inflated out_len, sidsbuf_end will point past the
end of the iov. This defeats the bounds guards in posix_info_sid_size(),
allowing out-of-bounds reads into adjacent kernel memory.
Fix this by rejecting responses where the calculated sidsbuf_end would
exceed the received iov boundaries or cause pointer wraparound.
Fixes: a90f37e3d7ac ("smb: client: parse owner/group when creating reparse points")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
|
||
|
|
eeb5ef6083 |
smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
In move_smb2_ea_to_cifs(), the while (src_size > 0) loop condition is
insufficient. It allows iteration to continue even if the remaining
src_size is too small to contain a complete smb2_ea_info structure.
Consequently, reads of ea_name_length and ea_value_length can occur
out-of-bounds.
Fix this by ensuring src_size >= sizeof(*src) before attempting to read
any structure fields. Additionally, reject any next_entry_offset that is
smaller than sizeof(*src) or that would advance the pointer beyond the
available buffer.
Note that for calls where the server returns a malformed EA list, the
error returned to userspace changes from -ENODATA (getxattr) or
-ERANGE (listxattr) to -EIO. This correctly signals a server protocol
error rather than misleadingly indicating "attribute not present" or
"output buffer too small".
Fixes:
|
||
|
|
1b3221bb12 |
smb: client: reject short Next offsets in parse_server_interfaces()
In parse_server_interfaces(), the server-supplied Next offset is
validated against bytes_left, but not against the size of the interface
structure itself.
A small, non-zero Next value can pass the bounds check but advance the
pointer by less than sizeof(*p). This causes the next iteration of the
loop to read misaligned, overlapping structure fields.
Fix this by ensuring the Next offset is at least sizeof(*p).
Fixes:
|
||
|
|
e83330c55e |
smb: client: fix missing lower-bound check on DFS referral string offsets
parse_dfs_referrals() checks that DfsPathOffset and NetworkAddressOffset
do not exceed the buffer end, but fails to check that they don't point
inside the referral header itself.
If a server provides an offset smaller than
sizeof(struct dfs_referral_level_3), the derived string pointer overlaps
with the struct fields, causing cifs_strndup_from_utf16() to interpret
header data as UTF-16 strings.
Fix this by enforcing that string offsets are at least sizeof(*ref).
Fixes:
|
||
|
|
f73726b83e |
smb: client: fix server->total_read for compound encrypted PDUs
In receive_encrypted_standard(), server->total_read is left at the
full decrypted frame size when walking sub-PDUs of a compound encrypted
frame. As a result, cifs_handle_standard() passes this full size
to smb2_check_message(), causing the PDU length guards to incorrectly
validate the entire compound frame instead of the current sub-PDU.
This allows truncated non-last sub-PDUs to bypass length validation,
leading to out-of-bounds reads in smb2_get_data_area_len().
Fix this by setting server->total_read to the true length of the
current sub-PDU: next_cmd for non-last sub-PDUs, and the remaining
pdu_length for the last one.
Fixes:
|
||
|
|
b4694f269e |
smb: client: validate minimum PDU size before smb2_get_data_area_len()
__smb2_calc_size() calls smb2_get_data_area_len(), which reads command-specific struct fields to locate the data area. However, smb2_check_message() only validates StructureSize2, meaning a truncated response could cause smb2_get_data_area_len() to read out-of-bounds. Replace has_smb2_data_area[] with smb2_min_pdu_len[], which is now used to indicate both whether a command's response has a data area and the size of that fixed response struct. A non-zero entry means the command has a data area, and is the minimum length required before the struct is read. For each command with a data area, PDUs shorter than this minimum size are rejected instead of parsed. The minimum is not applied to SMB2 error responses, which carry only the 9-byte error body, the same exemption the StructureSize2 check above it already makes. STATUS_MORE_PROCESSING_REQUIRED is treated as a normal reply, since an in-progress SESSION_SETUP response carries a full body and a security blob. Signed-off-by: Frank Sorenson <sorenson@redhat.com> Reviewed-by: David Howells <dhowells@redhat.com> Signed-off-by: Paulo Alcantara <pc@manguebit.org> |
||
|
|
05762c5bc1 |
smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
Fix several related bounds checking and pointer lifecycle issues in
receive_encrypted_standard()'s handling of compound encrypted frames:
- Clear next_buffer after assigning it to server->bigbuf. A stale
next_buffer pointer can lead to a use-after-free on subsequent
error paths.
- Update pdu_length to the decrypted plaintext size (buf_size). Using
the pre-decryption length allows NextCommand to point into stale
ciphertext residue.
- Reject next_cmd values smaller than MID_HEADER_SIZE(server).
- Fix an integer overflow in the upper bound check by verifying
pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the
trailing slice is large enough for a header.
Fixes:
|
||
|
|
b5a051f6b8 |
Including fixes from Netfilter, Bluetooth, IPSec and WiFi.
Previous releases - regressions:
- netfilter: hold reference on ct until flow is released
- bridge:
- move switchdev call outside rcu
- vlan: fix bugs caused by switchdev deletion errors
- wifi:
- mac80211: reset state when starting AP fails
- cfg80211: don't free driver-owned scan requests
- tcp: don't call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv().
- mptcp: return sk_wait_data() errors from recvmsg()
- xfrm: serialize state GC with device state flush
- drop_monitor: synchronize tracepoint unregistration on error path
- bluetooth:
- eir: validate service data length before reading UUID
- hci_sync: serialize local codec list cleanup
- RFCOMM: avoid socket lock inversion in listener cleanup
- eth: lan743x: fix RX checksum use-after-free
- eth: mvpp2: prevent buffer overflow in page_pool allocation
Previous releases - always broken:
- core: lock the socket in sock_gettstamp()
- neighbour: enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.
- sched: codel: bound the dropping loop per dequeue call
- wifi: mac80211: include TIM bitmap control for buffered S1G mcast traffic
- psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb()
- xfrm: fix stack OOB read in iptfs_skb_reset_frag_walk()
- bluetooth: hci_qca: do not write to the serial port after it is closed
- dsa: mxl862xx: disable the stats poll on teardown
- eth: stmmac: fix TSO header length truncation
- eth: ip_tunnel: initialize `options_len` before referencing options
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
-----BEGIN PGP SIGNATURE-----
iQJKBAABCgA0FiEEg1AjqC77wbdLX2LbKSR5jcyPE6QFAmqsEOsWHHBhb2xvLmFi
ZW5pQGdtYWlsLmNvbQAKCRApJHmNzI8TpKMnD/4vxx/YloxnyDssUB95WcTfiHau
XD+YDfTTf4Qy3DwKnMiesZ4w2547FXG+LwJZGpAGWpRSE99OawFHvx5gyn3Vf4IU
HEsOuZEYMwhSeeMJxGdCg8K6McNEQx+aAD7D8gLoisnJr/DCKBJtxFgKVEjaKUfP
aCG+FmbBqdS7hwBVbYREwmqwQSMnNzRWLd7/10/oYMcLfvgEsIkZisRErAW2BgZj
mzGw/IcG+QRldDPGDwLwLzfEG9o1a2JctSRrQ3uLHZ3VOdmpnSkmf25s2IaEFAn6
xfIhGPMgYIBDrakn/Ci4fAF0L98FtBq4Sa21HlvPMBst7rcce5x49ddSlIUWxRVZ
Fbvs/0IMN0cEpYGbVJxE8iF3yo+t8XvsMdGS1JXd/ycaL9lpF+9gCzNvChSxba3N
ik7BGAmlg76rqMuzeeMbWqMCmOcCBhQsb7iZXjNStJoiVY+UT2QfgvJ1TqF8Qrar
Eu/xFkaqk8i/7jrx4ujceg9XpRt1Y3Y3Pq0sgdzlzTm162AV/kg1fvwHc6ORIML7
71XpBSGvjyTHoh95ob/w3/5fec/ekzvWlCBL/cYIwBJ4R6n7Vk5e0Y1yZDffPSo3
xQR0r4YdLewkjQdtnGEih6FSyWsu6nYpVSuwHbof1bQSzvlIM6TAabJmtJckFTld
1bR2C9UVw5mQYMy8PA==
=Gw4S
-----END PGP SIGNATURE-----
Merge tag 'net-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net
Pull networking fixes from Paolo Abeni:
"Including fixes from Netfilter, Bluetooth, IPSec and WiFi.
Previous releases - regressions:
- netfilter: hold reference on ct until flow is released
- bridge:
- move switchdev call outside rcu
- vlan: fix bugs caused by switchdev deletion errors
- wifi:
- mac80211: reset state when starting AP fails
- cfg80211: don't free driver-owned scan requests
- tcp: don't call skb_clone_and_charge_r() for close()d listener in
tcp_v6_do_rcv()
- mptcp: return sk_wait_data() errors from recvmsg()
- xfrm: serialize state GC with device state flush
- drop_monitor: synchronize tracepoint unregistration on error path
- bluetooth:
- eir: validate service data length before reading UUID
- hci_sync: serialize local codec list cleanup
- RFCOMM: avoid socket lock inversion in listener cleanup
- eth:
- lan743x: fix RX checksum use-after-free
- mvpp2: prevent buffer overflow in page_pool allocation
Previous releases - always broken:
- core: lock the socket in sock_gettstamp()
- neighbour: enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.
- sched: codel: bound the dropping loop per dequeue call
- wifi: mac80211: include TIM bitmap control for buffered S1G mcast
traffic
- psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb()
- xfrm: fix stack OOB read in iptfs_skb_reset_frag_walk()
- bluetooth: hci_qca: do not write to the serial port after it is
closed
- dsa: mxl862xx: disable the stats poll on teardown
- eth:
- stmmac: fix TSO header length truncation
- ip_tunnel: initialize `options_len` before referencing options"
* tag 'net-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net: (159 commits)
mptcp: fix bad accounting in __mptcp_subflow_push_pending()
mptcp: close race between scheduler and state change
mptcp: avoid unneeded actions on subflow reset
net: skbuff: do not leave stale header offsets after pskb_carve()
selftests: net: packetdrill: test exclusion of old ACK from TCP fast path
tcp: exclude old ACKs from tcp fast path
dpll: reject a reference sync pin which is not on the pin's dpll
net: mvpp2: prevent buffer overflow in page_pool allocation
net: macb: fix ordering around PTP timestamp read
selftests: drv-net: psp: test PSP and TCP ULP mutual exclusion
net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb()
net: stmmac: preserve real_num_tx_queues on mqprio setup failure
net: stmmac: propagate FPE preemption-class mapping errors
net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb()
net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value
net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain
net: ethernet: cortina: Ack RX overrun interrupt correctly
net: lock the socket in sock_gettstamp()
eth: fbnic: ring the doorbell if a burst ends in a drop
net: netsec: fix device_node reference leak on phy_np
...
|
||
|
|
4982d3552a |
sound fixes for 7.3-rc4
A collection of small fixes. Most of them are device-specific fixes
while there are a few core fixes. The continued flux, but not too
scaring yet. Some highlights below.
ALSA Core:
- Fix potential UAF after asynchronous card release
- Fix a race condition in PCM timer initialization order
USB-Audio:
- Hardening fixes for issues reported by fuzzer for 6fire, bcd2000,
and implicit FB packets
- Fix double list addition in implicit FB handling
- Quirks for AVerMedia GC553Pro and Behringer FCA1616
HD-Audio:
- Quirks / fixes for HP OmniBook 7, OMEN 15, and Victus 15 laptops
ASoC:
- Support for DAI link codec channel mask to avoid mismatches
- Fix HDMI-codec channel status change report
- Fixes for various codecs and platforms: Realtek rt712/rt721
(calibration, reset fixes), Cirrus Logic (empty EFI variable
validation, capture channel fixup), AMD ACP SoundWire (bounds
checks, refactorings), ADAU1977 (OF match table support, SPI
cleanups), ES8336 (Huawei Matebook B3-420 quirk), UX500 (macro fix)
-----BEGIN PGP SIGNATURE-----
iQJCBAABCAAsFiEEIXTw5fNLNI7mMiVaLtJE4w1nLE8FAmqrwIYOHHRpd2FpQHN1
c2UuZGUACgkQLtJE4w1nLE8WeQ//eN0ufLXXqy5U6X7kri8eM4vjRDZa5v1z8oD/
oHBdkgPmSAOJOddCVHuyPyx5BP4reBgKbukxUTBjuJvVRD4iOYfvXSW1LzVCVcly
f60rJl1/Ck3RcXfVabNV9eeGCFtAwR00U/3oH7z0eDhjwisX2F4ucAMmgxyJUKTh
pLdMPFsI/XW5CWeVbPVObGlOB8Bf/c79wy5NAnpixAkR1WaXUSLKoF5djO9qIQex
eTIknPmMYLLSfzFfO0TWY1PPRPz5qJHDr6Acer0VMTHyZF0yg2bR+gRInbM1at2H
c/lg8m899ZbobSCiHFEJdPH/W5x3iHqFi3hKVtKtQ5niot+gWTirQpjUCZ2HxNOp
5fYEyieSJ0W/t2NfNW0SP+DUOvKaIxY9VUuGCW7z/YgjW5DvSxipd2FOC4Av0s6F
l67vYazzPzf9d34NIM333FHeSZ4WMXVKKTfB34CQD93lVB1GladNA6lFFer5zuqG
Sc8q+YGUF65OZEnbslANIDvqPG0eMNlqBn/iyqXQO+P/C6oXWIlqFm4DUtM5a8wB
3Vf/e9L4mzXwKZfoW2xsJLgfpAO0faYiTAO6fr7wjBPrRl7VoenOlsCshN5GLTmM
b4bQ29LZrpk9e3e8BdGdZzT/kfQEZ31O5sawaj6f+a2JG09xCi9qxklxV5wFvZ5E
FTO+HgE=
=PnHM
-----END PGP SIGNATURE-----
Merge tag 'sound-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound
Pull sound fixes from Takashi Iwai:
"A collection of small fixes. Most of them are device-specific fixes
while there are a few core fixes. The continued flux, but not too
scaring yet. Some highlights below.
ALSA Core:
- Fix potential UAF after asynchronous card release
- Fix a race condition in PCM timer initialization order
USB-Audio:
- Hardening fixes for issues reported by fuzzer for 6fire, bcd2000,
and implicit FB packets
- Fix double list addition in implicit FB handling
- Quirks for AVerMedia GC553Pro and Behringer FCA1616
HD-Audio:
- Quirks / fixes for HP OmniBook 7, OMEN 15, and Victus 15 laptops
ASoC:
- Support for DAI link codec channel mask to avoid mismatches
- Fix HDMI-codec channel status change report
- Fixes for various codecs and platforms: Realtek rt712/rt721
(calibration, reset fixes), Cirrus Logic (empty EFI variable
validation, capture channel fixup), AMD ACP SoundWire (bounds
checks, refactorings), ADAU1977 (OF match table support, SPI
cleanups), ES8336 (Huawei Matebook B3-420 quirk), UX500 (macro
fix)"
* tag 'sound-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound: (33 commits)
ASoC: adau1977-i2c: add OF match table for I2C
ASoC: adau1977-spi: drop __maybe_unused and of_match_ptr()
ASoC: adau1977: make the Kconfig symbols user selectable
ASoC: amd: acp: fix card name length warning in SOF SoundWire machine driver
ASoC: amd: acp: fix ffs() operator precedence for SoundWire link ID
ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver
ASoC: amd: acp: bounds-check SoundWire link ID in machine drivers
ASoC: cs-amp-lib: Prevent NULL pointer if efi variable is zero length
ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type
ASoC: hdmi-codec: Report a change when the channel status moves
ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments
ASoC: rt721: Reset codec to fix abnormal sound
ALSA: usb-audio: fix list_add double-add in push_back_to_ready_list
ALSA: hda: trace PCM open only after assigning a stream
ALSA: usb-audio: skip the broken mute control on AVerMedia GC553Pro
ALSA: hda/realtek: Enable mute LEDs on HP OmniBook 7 17-dc0xxx
ALSA: 6fire: fix OOB write from device-reported iso length
ALSA: usb-audio: Add capture quirk for Behringer FCA1616
ALSA: hda/realtek: Add mute LED quirk for HP OMEN 15-ax
ASoC: Intel: sof_es8336: Add a quirk for Huawei Matebook B3-420
...
|
||
|
|
f143ea21cf |
power sequencing fixes for v7.3-rc4
- fix kconfig issue in pwrseq-thread-gpu - fix error path logic in pwrseq_unit_enable() - fix two NULL-pointer dereference bugs in power sequencing core -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEkeUTLeW1Rh17omX8BZ0uy/82hMMFAmqrtNgACgkQBZ0uy/82 hMOupg/+Psfi2riTDG4/j6pzCWlLmOnL3Rfh1QLWMwGRKM7XHC8yN8CUHQS8ub2O l+z8ZZgJ663noQTLkjGbt4uOXyywykNaDnwQqO1DebWba4WgovIU6rVAbzaBOBqk 0XlAr0mSUu2P75JpJwUS1X3VCJ08r44U4kd1NeseNMrtAPSobB4BLmgN68Iku/tY AJ439da77hdZCxLEJQef1NU56r7q8toXQpq4thHanUrM66WT78vXwpiPqWnFSOuk eQkM033zsq2oc8Olc7XYr01r0KsdyhQKrC+L4H6pIsdzlGOKfxM7fsTGiyw+vu3/ IY+aHX+B2D5Zl9jX5bvkoQrgDjkBHQROXHvpQNgnTRL9gpNNUb1gdGPJkntptJ5w NCF+xg0TCRzaQZ5iVtN7QFlFUpDq5PQKQGAbh32PjnItJSvdfwE/+2BAGP2rAKui mosOAyQ2bQNQyje3vWSg+6I72fKKizGfH1rrOIKY2tK9vdnq9MYHpG+2tFkSJ+KZ 3yviZidGMgWT5t2XfUXq8+ZjiaCIyqV7l1NBAbuAUxWf6RUtNX1mLblYJfEvGIsg 6CfGmYKdn1dWC4FIGBoyYPb2ZQ1hCwuxZtdLRl8ARVdoW+yfTpcZEVoBqbunUsf9 2JFrax/SSJhT35v8drSRaDSs8YTNU1NrD3U8mUJcezMN91ZlCXs= =RnVa -----END PGP SIGNATURE----- Merge tag 'pwrseq-fixes-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux Pull power sequencing fixes from Bartosz Golaszewski: - fix kconfig issue in pwrseq-thread-gpu - fix error path logic in pwrseq_unit_enable() - fix two NULL-pointer dereference bugs in power sequencing core * tag 'pwrseq-fixes-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux: power: sequencing: fix NULL-pointer dereference in pwrseq_device_register() power: sequencing: fix NULL-pointer dereference in pwrseq_unit_new() power: sequencing: don't call .post_enable() if pwrseq_unit_enable() failed power: sequencing: Fix build issue with COMPILE_TEST |
||
|
|
61cc777ca7 |
gpio fixes for v7.3-rc4
- fix fwnode reference leak on failure in shared GPIO handling - fix regression in OF_POPULATED logic after the unification of GPIO hog handling between OF, ACPI and machine variants - don't call free_irq() if no IRQ is installed in gpio-virtuser -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEkeUTLeW1Rh17omX8BZ0uy/82hMMFAmqrs8YACgkQBZ0uy/82 hMPTsw/+Jm+8Z0tuCuryhBsDwMiqS4Gnr8TahCO3aB3UyMqApkiTS+hlqWGMRWbF Np07I4uu3ca6ohutKN/RN6K5hrjlJz6FhU1kliJ9RrK1a3bjLH4rbYoXBVsYeIpC mjLx9lyt6RmS4RaHPV75xPEmsAdxWbMyar6SQfiZT2t96Czsrph/VggX9kMbnXt3 SgKTM5SyHrKmw4DgnQmZ4OcWt8p2edW+5DO+jxRmPlWUvYE/q91yemaedw5wBEoz ftrvbuIr+JRKKOSugjbswwBbJ0pVUkMm+hwkyAfWSPp83aF+sm2rUB46Gkr6tfQ7 oJVqVewAV6vqW/XoAnB8vr2KO3As5HFEx8xLYZpEf9RlOIDsu8R3HOooFkvO0flP EsQSFccdX4WEHZoSc81iJl/TJjoM2gJtBZqqOvkHr2RZ7zdKPcnW81VHJGkSyZiW o70PMzcQ+FAu7I/o5Q+cqsw1eG68wHhRYZG0q38mJCRznjlEop9yBqCAx3yi+1mF cIhB37FlfRkFYGXByrqUFhi9V8gHWdDTChIQFJBMx1c99mBpT/eHD2hbGmac42LP QI4sbywoN6L3m+UJpuJwS7KoO4NtJaVN444nqnS5C8bxBGRdXV3JQHelzwhSSED9 cq+MyMQm5hjS+i6SrADGGg+PytUF9w5Z7yRq2LFNUFwcS0TaHpk= =NiRo -----END PGP SIGNATURE----- Merge tag 'gpio-fixes-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux Pull gpio fixes from Bartosz Golaszewski: - fix fwnode reference leak on failure in shared GPIO handling - fix regression in OF_POPULATED logic after the unification of GPIO hog handling between OF, ACPI and machine variants - don't call free_irq() if no IRQ is installed in gpio-virtuser * tag 'gpio-fixes-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux: gpio: virtuser: skip free_irq when no IRQ is installed gpiolib: of: don't mark hog nodes OF_POPULATED before a chip is found gpiolib: Put fwnode reference on failure |
||
|
|
3b95a04eb5 |
Merge branch 'mptcp-misc-fixes-for-v7-3-rc4'
Matthieu Baerts says: ==================== mptcp: misc fixes for v7.3-rc4 Here are two unrelated fixes: - Patch 1: avoid unneeded actions on subflow reset. A fix for another fix introduced in v6.12 and targeting a commit from v5.7. - Patch 2: close a possible race when scheduling a closing path. A fix for another fix introduced in v6.0 and targeting v5.10. - Patch 3: fix bad accounting when __subflow_push_pending returns an error. A fix for v6.6. ==================== Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-0-0cf5c72667c8@kernel.org Signed-off-by: Jakub Kicinski <kuba@kernel.org> |
||
|
|
f3ef033573 |
mptcp: fix bad accounting in __mptcp_subflow_push_pending()
If __subflow_push_pending() errors out we should avoid updating the
copied byte counters, to avoid mismatch push call later on.
Fixes:
|
||
|
|
42064de57f |
mptcp: close race between scheduler and state change
The mptcp scheduler may race with subflow sockets state change: data
transmission on the selected socket may fail and a later release could
try to use mss_now reset to 0 for a divide operation.
Address the issue by explicitly checking for the critical scenario.
Fixes:
|
||
|
|
2b0f561f21 |
mptcp: avoid unneeded actions on subflow reset
Once in a blue moon, the mptcp receive path can recursively call
mptcp_data_ready() via state change under unlucky error conditions, and
then try to hold the data lock again.
Break the recursion loop explicitly checking for the exceptional
condition.
Add a new flag instead of using an existing one like 'closing', to exit
early in subflow_state_change(), and explicitly flush the RX queue at
reset time.
This avoids unneeded processing to check for available data -- calling
get_mapping_status() and more on a dying subflow -- but also in error
reporting and worker scheduling.
Note that we must consume the currently peeked skb before invoking
mptcp_dss_corruption to avoid consuming it again after the eventual
reset has freed it.
Fixes:
|
||
|
|
4aec9ad1c6 |
dma-mapping fixes for Linux 7.3
A few fixes for the DMA-mapping code:
- resolved regression in accessing encrypted memory by IOMMU-backed
devices (Aneesh Kumar K.V),
- improved failure handling and removed rare bug in swiotlb/highmem
(Donggeun Yoo).
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQSrngzkoBtlA8uaaJ+Jp1EFxbsSRAUCaquwMwAKCRCJp1EFxbsS
RMT6AP0elpdaZXNY0KwUBTwU95H604J+donqriepHABIBhIDEQD9GWZqNf/m1gEI
tR5lHQ3+NGs0Q7Vd2ed1vSe82HQSsgU=
=QxUC
-----END PGP SIGNATURE-----
Merge tag 'dma-mapping-7.3-2026-09-17' of git://git.kernel.org/pub/scm/linux/kernel/git/mszyprowski/linux
Pull dma-mapping fixes from Marek Szyprowski:
"A few fixes for the DMA-mapping code:
- resolved regression in accessing encrypted memory by IOMMU-backed
devices (Aneesh Kumar K.V)
- improved failure handling and removed rare bug in swiotlb/highmem
(Donggeun Yoo)"
* tag 'dma-mapping-7.3-2026-09-17' of git://git.kernel.org/pub/scm/linux/kernel/git/mszyprowski/linux:
x86/mm: Don't force unencrypted DMA for IOMMU-backed devices
dma-mapping: don't trace the DMA address when the allocation fails
swiotlb: use the adjusted address for the highmem page lookup
dma-coherent: report a failed reserved memory assignment
|
||
|
|
a5117e1ecc |
net: skbuff: do not leave stale header offsets after pskb_carve()
pskb_carve_inside_header() and pskb_carve_inside_nonlinear() remove
the first bytes of a packet and reallocate skb->head.
All the headers that were present before the operation are gone,
but both functions call skb_headers_offset_update(skb, 0), which
is a no-op : skb->mac_header, skb->network_header,
skb->transport_header and skb->csum_start keep their old values and
now describe bytes which are no longer there.
Both helpers size the new head from the old skb_end_offset(), so the
stale offsets still land inside the new allocation. They point past
skb_tail_pointer() though, to bytes that were never initialized.
pskb_carve_inside_nonlinear() is the worst case, because it leaves a
zombie skb with an empty linear part (skb->data ==
skb_tail_pointer(skb), skb_headlen(skb) == 0), while
skb_mac_header_was_set() is still true and skb->mac_header is way
ahead of skb->data.
The only user of pskb_extract() is rds_tcp_data_recv(), and the
carved skb is queued on tinc->ti_skb_list. When the RDS incoming
message is released, rds_tcp_inc_free() calls skb_queue_purge(),
which frees the skbs with SKB_DROP_REASON_QUEUE_PURGE. This is
visible from drop_monitor, which then tries to pull back to the
(bogus) mac header :
skbuff: __skb_pull(len=234)
skb len=6968 data_len=6968 headroom=0 headlen=0 tailroom=0
end-tail=384 mac=(234,14) mac_len=14 net=(248,40) trans=288
shinfo(txflags=0 nr_frags=1 gso(size=1428 type=16 segs=5))
csum(0x100120 start=288 offset=16 ip_summed=3 complete_sw=0 valid=1 level=0)
hash(0x7b446c6c sw=0 l4=1) proto=0x86dd pkttype=0 iif=60
kernel BUG at ./include/linux/skbuff.h:2847!
Add skb_carve_reset_headers() to mark the mac and transport headers
as not set, reset the network header, clear skb->mac_len, and drop
a now meaningless CHECKSUM_PARTIAL (csum_start no longer describes
anything).
Invalidate the inner offsets as well. Unlike mac_header and
transport_header they have no "unset" sentinel, so a leftover
non-zero value still looks like a real header. Zero
skb->inner_mac_header, skb->inner_network_header,
skb->inner_transport_header, skb->inner_protocol and
skb->encapsulation, so that all the header state is invalidated in
one place.
v2: fixed an inaccurate changelog. The stale offsets stay inside the
new skb->head, which is never smaller than the old one, they
simply point past skb_tail_pointer() to bytes that are gone.
Thanks to Xuanqiang Luo for insisting on this.
Also invalidate the inner header state, as suggested by the
netdev AI review :
https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260911114922.621937-1-edumazet%40google.com
Fixes:
|
||
|
|
ad9c65b8f9 |
Merge branch 'tcp-exclude-old-acks-from-fast-path'
Inbal Schussheim says: ==================== tcp: exclude old ACKs from fast path Exclude ACKs outside [SND.UNA, SND.NXT] from TCP header prediction so that they fall through to the slow path, where ACK validation is applied. Add a packetdrill test for a data segment carrying an excessively old ACK. The test fails on the unpatched kernel and passes with the fix. v2: https://lore.kernel.org/netdev/20260909075644.1408171-1-inbal.lipshtat@mail.huji.ac.il/ v1: https://lore.kernel.org/netdev/20260906123151.1391349-1-inbal.lipshtat@mail.huji.ac.il/T/#u ==================== Link: https://patch.msgid.link/20260914090408.1435080-1-inbal.lipshtat@mail.huji.ac.il Signed-off-by: Paolo Abeni <pabeni@redhat.com> |
||
|
|
d841cd7513 |
selftests: net: packetdrill: test exclusion of old ACK from TCP fast path
Add a packetdrill test for an in-sequence data segment carrying an
excessively old ACK.
Verify that the segment falls through from the TCP fast path to the slow
path, where the existing ACK validation rejects it and sends a challenge
ACK. The payload is not accepted and RCV.NXT remains unchanged.
Based on the reproducer from Commit
|
||
|
|
f81e6c3fb0 |
tcp: exclude old ACKs from tcp fast path
Exclude old ACKs before SND.UNA from the tcp fast path as well as ACKs after SND.NXT. Such ACKs will fall through to the slow path, where tcp_ack() performs the appropriate validation and challenge ACK handling according to RFC5961 and Commit |
||
|
|
d798162eb3 |
dpll: reject a reference sync pin which is not on the pin's dpll
dpll_pin_ref_sync_state_set() resolves the partner's driver private data with dpll_pin_on_dpll_priv() and passes the result to ref_sync_get() and ref_sync_set() without looking at it. The helper returns NULL when the partner holds no ref on that dpll. Of the two drivers implementing the feature only zl3073x dereferences the pointer (sync_pin->id); ice ignores it, so ice cannot fault here. The NULL is a teardown race, not a steady state - zl3073x registers every input pin with every channel, so the partner is normally present on the dpll the base pin resolves to. zl3073x_dev_stop() unregisters pins one at a time, taking and dropping dpll_lock for each, and between the partner's turn and the base pin's the partner is out of that dpll's pin_refs while still registered with the channels not yet torn down, so dpll_pin_available() keeps passing. That path is not only driver removal: devlink reload and devlink dev flash both run zl3073x_dev_stop(). Reproduced by holding that state open with a mock dpll device, which is where the frame name comes from: BUG: kernel NULL pointer dereference, address: 0000000000000000 Oops: Oops: 0000 [#1] SMP NOPTI RIP: 0010:mock_ref_sync_get+0x5/0x30 Call Trace: <TASK> dpll_pin_ref_sync_set+0x19f/0x4a0 dpll_nl_pin_set_doit+0x17d/0x840 genl_family_rcv_msg_doit+0xd6/0x130 genl_rcv_msg+0x181/0x2b0 netlink_rcv_skb+0x55/0x100 genl_rcv+0x23/0x30 netlink_unicast+0x24d/0x370 netlink_sendmsg+0x1e2/0x420 __sys_sendto+0x1db/0x1f0 __x64_sys_sendto+0x1f/0x30 do_syscall_64+0xe1/0x490 Commit |
||
|
|
14cb1e7702 |
net: mvpp2: prevent buffer overflow in page_pool allocation
The per‑processor buffering scheme is supported only if the
number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS (8).
This is already checked in mvpp2_probe() during the initial
activation of percpu_pools.
However, mvpp2_change_mtu() may later call
mvpp2_bm_switch_buffers(priv, true) without this check, which can
lead to an out-of-bounds access in the priv->page_pool array in
mvpp2_bm_init(). The array is sized to hold MVPP2_PORT_MAX_RXQ
entries, and mvpp2_get_nrxqs() may return exactly that value. The
per-CPU scheme then doubles it to nrxqs * 2, exceeding the array
bounds.
Check that the hardware version is MVPP22 or newer and that the
number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS
before switching to per-CPU mode.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes:
|
||
|
|
9ca4ba2425 |
net: macb: fix ordering around PTP timestamp read
PTP_SYS_OFFSET_EXTENDED returns system timestamps that do not correctly
bracket the PHC register read on MACB/GEM. On a Raspberry Pi 5, the
returned interval can be as short as 37 ns, while an ordered register
read takes approximately 1 us. This biases the midpoint used by phc2sys,
causing CLOCK_REALTIME to run approximately 0.5 us ahead when synchronized
to the PHC.
gem_tsu_get_time() reads the nanoseconds register using the driver's
relaxed MMIO accessor. On weakly ordered systems, the subsequent system
timestamp can be taken before the register read completes. The internal
smp_rmb() in the pre-timestamp path also does not guarantee ordering
against the subsequent MMIO read.
Add rmb() before and after the bracketed nanoseconds read in both the
normal and seconds rollover paths so the system timestamps bracket the
PHC read. Adding the post-read barrier increases the minimum interval on
the same Raspberry Pi 5 to approximately 1 us.
Fixes:
|
||
|
|
546b928da0 |
ASoC: Fixes for v7.3
A relatively large pile of fixes here, a lot of driver specific stuff that's broadly unremarkable plus a few core fixes from Richard that fix issues where SoundWire systems with multiple CODECs on the same link would configure the CODECs to use the same bus slots leading to broken audio. -----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEEreZoqmdXGLWf4p/qJNaLcl1Uh9AFAmqrCNoACgkQJNaLcl1U h9DHWgf8D3dIL06bqj6IoyMLCFNrcQ8BYbWUeWNu5YE0vP29ybdpYidTxJFjqF2t TUB8fTO2u3LvfKIIgOSVyXN84i7/4EwtDjBz1iVzGhm0/2ZfEOitO2LtUvhCHiZi +JnEOXdwa7wM9jv0On6B81r8+vXj7FaNmq/TnLbUU3R/DeaRx571k913lazZSRb0 cfPj1FGMUvpfBZ7DC011yEufDD4C8qVaktV6IpRqeBAxks1vmXQX7Lt78gJCxvQt w8Uu2T8FpiTuYvObI7KW7IZr01IQtPpJ4N9ekUMuBfOqkjvG+XOETM2aEWg7q9Jk Qu5GfyB2LIav4/On4pCxwJGaJiUavQ== =IMNO -----END PGP SIGNATURE----- Merge tag 'asoc-fix-v7.3-rc3' of https://git.kernel.org/pub/scm/linux/kernel/git/broonie/sound into for-linus ASoC: Fixes for v7.3 A relatively large pile of fixes here, a lot of driver specific stuff that's broadly unremarkable plus a few core fixes from Richard that fix issues where SoundWire systems with multiple CODECs on the same link would configure the CODECs to use the same bus slots leading to broken audio. |
||
|
|
c9151088f1 |
Merge branch 'net-psp-avoid-conflicts-with-skb-decrypted-and-sk_validate_xmit_skb'
Daniel Zahka says:
====================
net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb()
Sashiko's review of commit da630d1da2b1 ("netdevsim: psp: drop tx key
ops") [1] showed that there is a hazard between PSP and offloaded TLS,
where both can clobber what the other set in the sk_validate_xmit_skb
callback.
It was discussed further on the mailing list [2], and it was pointed out
that there are conflicts with PSP and TLS ULP both using the
skb->decrypted bit.
The simplest fix is to make psp and tls mutually exclusive. This series
goes a bit further and makes psp exclusive with all TCP ULPs. The PSP
implementation that we have is not designed to be used with any TCP ULP,
so don't allow a socket to have state for both.
I will send a subsequent series to net-next which will remove the
ability to perform the rx-assoc and tx-assoc psp netlink calls on
sockets that are not in the TCP_ESTABLISHED state. This will close the
remaining quirk that a sk_clone() on a listen socket with psp tx-assoc
state will leave a stale sk->sk_validate_xmit_skb call back on a new,
non-psp socket. I do not believe that change needs to be regarded as a
fix, because it only stands to add unecessary validation code in the tx
path.
[1]: https://sashiko.dev/#/patchset/20260903-psp-prep-v1-0-d47e9c4c375d%40gmail.com
[2]: https://lore.kernel.org/netdev/20260903-psp-prep-v1-0-d47e9c4c375d@gmail.com/
====================
Link: https://patch.msgid.link/20260915-psp-ktls-fix-v2-0-0eedc3b148ec@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
|
||
|
|
b4288c59bd |
selftests: drv-net: psp: test PSP and TCP ULP mutual exclusion
Test both setting PSP after TLS ULP, and TLS ULP after PSP. Add CONFIG_TLS=y to the drivers/net/config. Signed-off-by: Daniel Zahka <daniel.zahka@gmail.com> Reviewed-by: Willem de Bruijn <willemb@google.com> Link: https://patch.msgid.link/20260915-psp-ktls-fix-v2-2-0eedc3b148ec@gmail.com Signed-off-by: Jakub Kicinski <kuba@kernel.org> |
||
|
|
a41f24c612 |
net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb()
PSP conflicts with TLS ULP in its usage of both skb->decrypted and
sk->sk_validate_xmit_skb().
Make PSP mutually exclusive with TLS ULP, the only other user of either
of these. As other users of skb->decrypted come along, they can be added
to sk_has_decrypt_user(). It would make sense to also assert that
sk->sk_validate_xmit_skb() is also NULL in both of these setup paths for
similar future proofing, but the PSP listener/sk_clone() path is still
broken and it could be seen as a regression to not allow rx assoc to run
on a child of a listener socket with PSP tx assoc state.
Include all TCP ULPs in the sk_has_decrypt_user() check, even though TLS
is the only one that conflicts with PSP via the decrypted bit. This is
intentional because PSP was not designed to be used with ULPs. It is
best to close off surface area that may make bugs reachable, until
someone wishes to design and test an actual user of PSP with ULPs.
Fixes:
|
||
|
|
dd56c0bc48 |
Merge branch 'net-stmmac-restore-previous-state-if-tc_setup_dwmac510_mqprio-fails'
Lorenzo Bianconi says: ==================== net: stmmac: restore previous state if tc_setup_dwmac510_mqprio() fails Restore previous mqprio qdisc configuration if tc_setup_dwmac510_mqprio() fails running the following configuration: $tc qdisc add dev eth0 root handle 1: mqprio queues 2@0 2@2 $tc qdisc replace dev eth0 root handle 2: mqprio queues 2@0 2@2 fp E P Propagate FPE preemption-class mapping errors in tc_setup_dwmac510_mqprio() and tc_taprio_configure(). ==================== Link: https://patch.msgid.link/20260911-stmmac-tc_setup_dwmac510_mqprio-error-path-v3-0-a76b1e2547c1@oss.qualcomm.com Signed-off-by: Jakub Kicinski <kuba@kernel.org> |
||
|
|
02fffd1939 |
net: stmmac: preserve real_num_tx_queues on mqprio setup failure
With the FPE preemption-class mapping error now propagated from
stmmac_fpe_map_preemption_class(), tc_setup_dwmac510_mqprio() can fail
on the mapping step. The error path used to call stmmac_reset_tc_mqprio(),
which resets the number of real TX queues to priv->plat->tx_queues_to_use
(the platform maximum), overwriting the value that was active before the
offload was attempted (for example a lower count left over from a previous
mqprio configuration).
The issue can be triggered using the following configuration:
# First mqprio config lowers the hw queue count below the platform
# default (e.g. 8 TX queues).
$tc qdisc add dev eth0 root handle 1: mqprio queues 2@0 2@2
# Replace mqprio configuration with a second one that fails FPE
# preemption-class mapping. stmmac driver resets the real_num_tx_queues
# to the platform maximum, losing the previous configuration.
$tc qdisc replace dev eth0 root handle 2: mqprio queues 2@0 2@2 fp E P
Save ndev->real_num_tx_queues before lowering it and restore it,
together with the TC-to-queue and priority-to-TC mappings, when the FPE
preemption-class mapping fails, instead of resetting the queue count to
the platform maximum.
Note that a failed setup makes the qdisc layer run mqprio_destroy() on
the new qdisc. Because priv->hw_offload is only assigned after
ndo_setup_tc() succeeds, mqprio_destroy() calls netdev_set_num_tc(dev, 0),
so dev->num_tc ends up 0 regardless of the driver-side restore and the
previous qdisc is not reactivated. The restore is still needed to keep
real_num_tx_queues and to avoid leaving the failed configuration's
TC-to-queue and priority-to-TC mappings in place.
Fixes:
|