mirror of
https://github.com/torvalds/linux.git
synced 2026-09-24 06:24:02 +02:00
v7.2-rc7
1464913 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
db2ddb8714 | Linux 7.2-rc7 | ||
|
|
b9b3e33b70 |
tracing fixes for 7.2:
- Fix use-after-free in eventfs_remove_rec() The freeing of the eventfs_inode children used list_for_each_entry() where the child is freed via srcu, but there's still a chance that it gets freed. It should be using list_for_each_entry_safe(). - Fix eventfs_inode SRCU use of list in freeing The iterator uses an SRCU protected list walk on the eventfs inodes. The eventfs inode uses its "list" field in a union with the RCU list head. When the inode gets added to the SRCU list it immediately corrupts the list pointer and can cause an issue with the iterator. Move the RCU list head to be shared with the children list head which allows the iterator to check the parent inode if is freed before referencing the child. Have the iterator check the parent "is_freed" field and break out if it is set. Also add memory barriers to make sure the ordering is correct. - Fix various RCU synchronization issues with direct_functions Updates to direct_functions have some missing RCU protection and synchronization. Restructure the code a bit to make sure updates to the direct_functions are protected. - Remove an unneeded comma from a scope_guard() There's a spurious comma in a scope_guard(). Remove it. - Fix race in per CPU buffer swap in the ring buffer When a per CPU buffer swap happens, it must make sure that it doesn't occur while a writer is active. Instead it returns an -EBUSY. But there's a small race window when a writer moves from one sub-buffer to the next that it resets the "committing" counter. If a swap happens at that moment, the buffer used for the commit of an event will not match the buffer the event is actually on. Instead of using the "committing" counter, use the recursive detection counter that does not get reset when the writer crosses sub-buffers. - Fix off-by-one in ftrace_free_mem() The function ftrace_free_mem() gets an "end_ptr" as a parameter that is exclusive to the rang to be freed. But its value is used to search for the records that expects an inclusive value. Subtract one from the parameter to convert it to an inclusive range. - Disable resizing of the ring buffer for persistent buffers Resizing the persistent buffer has undefined behavior. Prevent it from being resized. - Disable changing ring buffer subbuf order when resizing is disabled The ring buffer subbuffer order can not be changed during resizing. Use that instead of just checking if the buffer is mapped as mapped buffers also have resizing disabled. - Initialize subbuf_order of reader pages when they are created In rb_allocate_cpu_buffer() the bpage->order is not updated to the current subbuf_order leaving it as zero. This value is used when the page is freed. - Fix test_ringbuffer() to test for ERR_PTR before calling kthread_stop() The rb_threads[] array is assigned the output of kthread_run_on_cpu() which could return an ERR_PTR. At the end of the test, all threads in the array are cleaned up by kthread_stop() passing in the value in the array if it isn't zero. But if the array contains an ERR_PTR, kthread_stop() will not be able to handle it properly. -----BEGIN PGP SIGNATURE----- iIoEABYKADIWIQRRSw7ePDh/lE+zeZMp5XQQmuv6qgUCanicmBQccm9zdGVkdEBn b29kbWlzLm9yZwAKCRAp5XQQmuv6quonAP9HgM214Bt43edhuJb3oFy9fdS+sqYZ RIJ9q90iMDUH0AEAk3650lu7u80YniD4INKNrz5QMM2EbIMaNqtqwkS8uwQ= =tZwi -----END PGP SIGNATURE----- Merge tag 'trace-v7.2-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace Pull tracing fixes from Steven Rostedt: - Fix use-after-free in eventfs_remove_rec() The freeing of the eventfs_inode children used list_for_each_entry() where the child is freed via srcu, but there's still a chance that it gets freed. It should be using list_for_each_entry_safe(). - Fix eventfs_inode SRCU use of list in freeing The iterator uses an SRCU protected list walk on the eventfs inodes. The eventfs inode uses its "list" field in a union with the RCU list head. When the inode gets added to the SRCU list it immediately corrupts the list pointer and can cause an issue with the iterator. Move the RCU list head to be shared with the children list head which allows the iterator to check the parent inode if is freed before referencing the child. Have the iterator check the parent "is_freed" field and break out if it is set. Also add memory barriers to make sure the ordering is correct. - Fix various RCU synchronization issues with direct_functions Updates to direct_functions have some missing RCU protection and synchronization. Restructure the code a bit to make sure updates to the direct_functions are protected. - Remove an unneeded comma from a scope_guard() There's a spurious comma in a scope_guard(). Remove it. - Fix race in per CPU buffer swap in the ring buffer When a per CPU buffer swap happens, it must make sure that it doesn't occur while a writer is active. Instead it returns an -EBUSY. But there's a small race window when a writer moves from one sub-buffer to the next that it resets the "committing" counter. If a swap happens at that moment, the buffer used for the commit of an event will not match the buffer the event is actually on. Instead of using the "committing" counter, use the recursive detection counter that does not get reset when the writer crosses sub-buffers. - Fix off-by-one in ftrace_free_mem() The function ftrace_free_mem() gets an "end_ptr" as a parameter that is exclusive to the rang to be freed. But its value is used to search for the records that expects an inclusive value. Subtract one from the parameter to convert it to an inclusive range. - Disable resizing of the ring buffer for persistent buffers Resizing the persistent buffer has undefined behavior. Prevent it from being resized. - Disable changing ring buffer subbuf order when resizing is disabled The ring buffer subbuffer order can not be changed during resizing. Use that instead of just checking if the buffer is mapped as mapped buffers also have resizing disabled. - Initialize subbuf_order of reader pages when they are created In rb_allocate_cpu_buffer() the bpage->order is not updated to the current subbuf_order leaving it as zero. This value is used when the page is freed. - Fix test_ringbuffer() to test for ERR_PTR before calling kthread_stop() The rb_threads[] array is assigned the output of kthread_run_on_cpu() which could return an ERR_PTR. At the end of the test, all threads in the array are cleaned up by kthread_stop() passing in the value in the array if it isn't zero. But if the array contains an ERR_PTR, kthread_stop() will not be able to handle it properly. * tag 'trace-v7.2-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace: ring-buffer: Fix crash passing ERR_PTR to kthread_stop() ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer() ring-buffer: Prevent subbuf order change when resizing is disabled ring-buffer: Prevent resizing of persistent ring buffer ftrace: Fix off-by-one fentry site disable in ftrace_free_mem() ring-buffer: Use current_context for safe per-CPU buffer swap ftrace: Drop extra comma in trace_buffered_event_enable ftrace: Protect direct_functions in update_ftrace_direct_mod ftrace: Protect direct_functions in update_ftrace_direct_del ftrace: Protect direct_functions in ftrace_find_rec_direct eventfs: Use children field for rcu head and add memory barriers eventfs: Fix use-after-free in eventfs_remove_rec() |
||
|
|
b643e495ae |
s390 updates for 7.2-rc7
- Fix potential uninitialized memory reads and buffer overflows from malformed zcrypt CCA and EP11 requests by properly validating lengths and payloads - Fix possible out of bounds accesses in zcrypt EP11 domain handling by replacing fixed payload layout assumptions with parsing ASN.1 fields with bounds checks - Fix zcrypt CCA and EP11 request and reply buffer allocations missing required 4-byte padding, and scrub the full allocation on release - Fix zcrypt CCA and EP11 messages leaking up to 3 uninitialized bytes of memory by zeroing trailing alignment padding -----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEE3QHqV+H2a8xAv27vjYWKoQLXFBgFAmp4YYUACgkQjYWKoQLX FBh1tgf/ZZMzYxWDawMfYg2SoE16aLEG6M+I8qa1EmpxCXwu2Evl17LdMtkZFL1C ClDux15JGBhbpYyHyXhlsnUMRSHKLatLF2LU4KR6g3q5JgFcNRUVzSH8uuE40en5 UspMeEG09NENUJGveyZ8tEbGmkbI1hxAzicD4nRMTuin8VpXWKvHaNeQYXhkuDtr 5nuCiRmJUgMrwAVgtTXkdWzMaR0QwLWwkkLXLhnQk6NWyz1EhYmXWT+YG2axu7/y KUWU5jEs1AutO7YUxgTzrvxjS4M5IbokSXNyTUlLUqmPzdbXVWrpuF0nFEorBCA3 TzA7NCaJAChYWFfg54zQYdd4ijnf2Q== =iulo -----END PGP SIGNATURE----- Merge tag 's390-7.2-7' of git://git.kernel.org/pub/scm/linux/kernel/git/s390/linux Pull s390 fixes from Vasily Gorbik: - Fix potential uninitialized memory reads and buffer overflows from malformed zcrypt CCA and EP11 requests by properly validating lengths and payloads - Fix possible out of bounds accesses in zcrypt EP11 domain handling by replacing fixed payload layout assumptions with parsing ASN.1 fields with bounds checks - Fix zcrypt CCA and EP11 request and reply buffer allocations missing required 4-byte padding, and scrub the full allocation on release - Fix zcrypt CCA and EP11 messages leaking up to 3 uninitialized bytes of memory by zeroing trailing alignment padding * tag 's390-7.2-7' of git://git.kernel.org/pub/scm/linux/kernel/git/s390/linux: s390/zcrypt: Pad trailing CCA or EP11 message with zeros s390/zcrypt: Improve EP11 CPRB domain handling with ASN.1 parsing s390/zcrypt: Improve EP11 CPRB length and overflow checks s390/zcrypt: Improve CCA CPRB length and overflow checks s390/zcrypt: Fix CPRB memory allocation in zcrypt misc code |
||
|
|
91542863ab |
ring-buffer: Fix crash passing ERR_PTR to kthread_stop()
In test_ringbuffer()'s out_free cleanup loop, the check
`!rb_threads[cpu]` only catches NULL entries and misses entries that
hold an ERR_PTR.
rb_threads[] is static, so unassigned slots are NULL. But when
kthread_run_on_cpu() fails for a cpu, it stores ERR_PTR(-ENOMEM) (or
-EINTR) in rb_threads[cpu] before the creation loop jumps to out_free.
That entry is non-NULL, so the old `!ptr` check does not break, and the
cleanup proceeds to call kthread_stop() on the ERR_PTR. kthread_stop()
then dereferences the bogus pointer, crashing the kernel during the
late_initcall self-test.
crash logs:
BUG: kernel NULL pointer dereference, address: 000000000000001c
Oops: 0002 [#1] SMP NOPTI
CPU: 1 PID: 1 Comm: swapper/0 Not tainted 7.2.0-rc6-dirty #7 PREEMPT(lazy)
RIP: 0010:kthread_stop+0x2e/0x220
RBX: fffffffffffffff4
CR2: 000000000000001c
Call Trace:
<TASK>
test_ringbuffer+0x1ec/0x650
do_one_initcall+0x6c/0x2c0
kernel_init_freeable+0x21d/0x420
kernel_init+0x15/0x1c0
ret_from_fork+0x21b/0x320
</TASK>
Kernel panic - not syncing: Fatal exception
Cc: stable@vger.kernel.org
Fixes:
|
||
|
|
6d014e44b6 |
ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer()
In rb_allocate_cpu_buffer(), bpage->order was omitted, leaving it as 0.
This is an issue for a ring-buffer with subbufs bigger than PAGE_SIZE if
when freed: free_buffer_page() relies on this value. Align the value
with the actual allocation size (buffer::subbuf_order).
Cc: stable@vger.kernel.org
Fixes:
|
||
|
|
bf98d7b0d5 |
ring-buffer: Prevent subbuf order change when resizing is disabled
Because ring_buffer_subbuf_order_set() frees buffer pages, we can't
allow it when resizing is disabled. A non-consuming reader is at risk of
use-after-free (rb_advance_iter()).
Return -EBUSY on resize_disabled, matching ring_buffer_resize()
behaviour.
Cc: stable@vger.kernel.org
Fixes:
|
||
|
|
7c727dfce6 |
ring-buffer: Prevent resizing of persistent ring buffer
Dynamically resizing a persistent ring buffer is not possible. Disable
the feature.
Cc: stable@vger.kernel.org
Fixes:
|
||
|
|
8b8292d648 |
ftrace: Fix off-by-one fentry site disable in ftrace_free_mem()
When a module's init text is freed, do_init_module() calls
ftrace_free_mem() with a half-open [start, end) range. However the
ftrace_cmp_recs() comparator treats the upper bound as inclusive, as all
its other users do, passing 'ip + size - 1'. So ftrace_free_mem() can
delete a record sitting exactly at 'end', which is outside the freed
range.
For a kernel without CFI or IBT, the first record of a function is at
the function start, which for the first function in a module is also the
base of its text allocation. As the module allocator packs its regions,
that address is often the 'end' passed by a neighboring module's
do_init_module(), causing the first function's ftrace location to get
disabled, preventing an attempt to livepatch it:
livepatch: failed to find location for function 'pcspkr_probe'
Convert the exclusive end to the inclusive 'end - 1' the comparator
expects, and return early for an empty range to avoid the subtraction
from underflowing when the init text size is zero.
Cc: stable@vger.kernel.org
Fixes:
|
||
|
|
f27bdc4307 |
ring-buffer: Use current_context for safe per-CPU buffer swap
The ring_buffer_swap_cpu() function currently checks the per-CPU
committing counter to determine if a buffer is actively being written to
before performing the swap. However, there exists a race window where
this check can be bypassed:
ring_buffer_lock_reserve
cpu_buffer = buffer->buffers[cpu]; // cpu_buffer_a
rb_reserve_next_event
rb_start_commit // inc committing
if (unlikely(READ_ONCE(cpu_buffer->buffer) != buffer)) {...}
__rb_reserve_next
rb_move_tail
rb_end_commit(cpu_buffer); // dec committing => 0
/* interrupt hits here, successfully swaps! */
local_inc(&cpu_buffer->committing);
ring_buffer_unlock_commit
cpu_buffer = buffer->buffers[cpu]; // cpu_buffer_b
rb_commit
rb_end_commit
RB_WARN_ON(cpu_buffer, !local_read(&cpu_buffer->committing))
// triggers warning
The committing counter can temporarily drop to 0 during a single write
operation (within rb_move_tail), creating a window where swap can
succeed even though the write is still in progress. This leads to
inconsistent buffer state and triggers the RB_WARN_ON in rb_commit().
Replace the committing counter check with current_context checks, which
are set at the entry of ring_buffer_lock_reserve() and remain valid
throughout the entire write operation, providing a reliable indicator of
buffer busy state during swap.
Cc: stable@vger.kernel.org
Fixes:
|
||
|
|
06cf61899d |
- Fix MCE CMCI discovery initialization ordering bug
(Breno Leitao) Signed-off-by: Ingo Molnar <mingo@kernel.org> -----BEGIN PGP SIGNATURE----- iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmp3hxkRHG1pbmdvQGtl cm5lbC5vcmcACgkQEnMQ0APhK1iSyA/9EY/a7Ri29eYKrblSnPCAHyUIpo2oNNJM CVrC9TOPYPaPFQg7Py91B6+yry8aOtHVQpXygNVQJMgr8oz9QuQcfL6JumHXRYxX OV5+/S4Hba4dzhDeOEdethiz65Vp3rCm5Dl8D2/5g47CJp3JUM3WJ0GrJs6PWNST 446rTZXTVz8jVYNhFyGPJHqApMypMyqUnTS1zJsq+PEldzs+LV4YHaQ7PIvEl++w iA1yFdqvcStpeqfu/e0PwauiPH5tpwnde5ZxRjygCr9M7cWpL+wjhP4z5eGiSM1O Xgjr5tVfevbDC2LA5CZxdeFheSupUMxI/zfmYyCdCz3z22jEXMUghHUZvL+kY+cq ur6b9iFvC8R+Jwjp/pnTvqTS7xzcqXvMJFiaviiYXmeCLWu/Ah8e0v2ugmzUUxPp 5VHuhoVgyEr1eMPb2huzqozzTgqJEx5h3zOlo355IN0QjnKCMIGa8WrpkYQGTjW+ 5wl/PnPenMGl3FDHUq8IlvMlbQkbh/NLoy1EC6Kna9D46H0Cxu6NqHMu2uP6Flj7 sQxne+zdM/KLTPlPyHxtiQQCau9w0NYFsY9PtMgB/HyrjjjJiPKGL39j+kj1Yusa 2CSisQttseoNQA60Vh4o+jZ3MnnIijqPZnB4GokG2yRZ1v4GsmpacOs/VWqDrWnx sW2+z97qoZk= =YUDb -----END PGP SIGNATURE----- Merge tag 'x86-urgent-2026-08-08' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip Pull x86 fix from Ingo Molnar: - Fix MCE CMCI discovery initialization ordering bug (Breno Leitao) * tag 'x86-urgent-2026-08-08' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip: x86/mce: Set up the polling timer before CMCI discovery |
||
|
|
d4eee3bdb8 |
- Fix race in futex_pivot_pending() during private hash resize
that can cause stuck tasks (Yao Kai) Signed-off-by: Ingo Molnar <mingo@kernel.org> -----BEGIN PGP SIGNATURE----- iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmp3gQ8RHG1pbmdvQGtl cm5lbC5vcmcACgkQEnMQ0APhK1h0CQ//Wq3AnGGWisG9OAyn22xxlkh1lK4RqUeE uAYuLQmIAw481YjiVg7U0QTcyHrMrDHK5j902oc1Zd7Cyc+IqBaaZVPs63Vq0onh KAP19tbFz2w9D/mxyTkuxEekJ42w8a7bk5cHFL1rw0t/rSA51LixzbdW7DloC2vg So+quAtUcaXI8831ljnikN4OdNQOCLJCA9MemTpncIMuyL4BmhOXDRMwXneevg74 f6BOqrgbvKEgrBsVhWzGeDdq5ZHekmGVrHQeOxlDaQy/rZS+VE3VJwtMBwZvhn6X wU3CQdvkvDOeQvqXyfWxTbqhk7AJrIL5FKQrp5ZlhECw2WnPOUHwjAHQ8dKHaJEw wbv58RALcJ33s+PWy+0tYmOP4SPyICpQEmdp+SCaR0N4N/LtAScz05XAGnJ4S97+ t8LBmmJFmkxz4rDbTdawBV+sulDX/y+8xYu0/CZJhAyp1hEW9ajyMbRj5gVGOomT xKyyQAUTUUznStscc4hgTNVd1UAhuqUYlMNCJsEJOHNHvnq5qHT+ezPoZt5X5qd6 cDHCs5b+agQ/PIpW1vIiulCypelckAqvs+XdE0Pv3uPlNVjMLfZCTeyaOoXqIqI7 LpXkgR0UxkWmFf8vGncpPHjDCh3YqGgN66iE1qKohO1L9/uSxwwxEUOJIcPaOFtX C07TnEwMdK0= =3w7m -----END PGP SIGNATURE----- Merge tag 'locking-urgent-2026-08-08' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip Pull futex fix from Ingo Molnar: - Fix race in futex_pivot_pending() during private hash resize that can cause stuck tasks (Yao Kai) * tag 'locking-urgent-2026-08-08' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip: futex: Fix race in futex_pivot_pending() during private hash resize |
||
|
|
91a73db697 |
USB / Thunderbolt fixes for 7.2-rc7
Here are some small USB and Thunderbolt driver fixes for 7.2-rc7 that resolve some reported issues. Included in here are: - new quirk for some broken USB devices - thunderbolt device fixes for reported issues - usb gadget driver fix - usb atm driver fix - xhci driver fixes. - other minor USB driver fixes All of these have been in linux-next this week with no reported issues. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> -----BEGIN PGP SIGNATURE----- iGwEABECAC0WIQT0tgzFv3jCIUoxPcsxR9QN2y37KQUCandKCg8cZ3JlZ0Brcm9h aC5jb20ACgkQMUfUDdst+ymavgCgzIiJ6KRqYmikyHsPpfL6GNYtOLAAmOwaDTWL Zzvkgp8bIdQvqsPg6B0= =lR2e -----END PGP SIGNATURE----- Merge tag 'usb-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb Pull USB / Thunderbolt fixes from Greg KH: "Here are some small USB and Thunderbolt driver fixes for 7.2-rc7 that resolve some reported issues. Included in here are: - new quirk for some broken USB devices - thunderbolt device fixes for reported issues - usb gadget driver fix - usb atm driver fix - xhci driver fixes. - other minor USB driver fixes All of these have been in linux-next this week with no reported issues" * tag 'usb-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb: usb: xhci: use BIT_ULL for CRCR bits to fix incorrect 64bit mask usb: quirks: Add ShanWan gamepad to quirk list usb: hub: Split announce_device() to log device identity before enumeration usb: core: Add quirk for 255-bytes initial config read usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg usb: gadget: f_ncm: Use unsigned int for ndp_index usb: cdnsp: fix incorrect endian conversions for APB timeout register thunderbolt: Initialize ->domain_released completion before it is being used thunderbolt: icm: Preserve USB4 proxy data-valid bit thunderbolt: Bound the DROM dual link port number before indexing sw->ports thunderbolt: Fix bandwidth group reservation indexing thunderbolt: stream: Unmap buffers with mapped size |
||
|
|
e4836b67ba |
TTY / Serial / VT driver fixes for 7.2-rc7
Here are some small serial and vt tty driver fixes for 7.2-rc7 that resolve some reported problems. Included in here are: - 2 vt core fixes - amba-pl011 serial driver fixes - 8250_of and 8250_dma driver fixes - qcom-geni serial driver fix - sc16is7xx serial driver fix All of these have been in linux-next this week with no reported issues. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> -----BEGIN PGP SIGNATURE----- iG0EABECAC0WIQT0tgzFv3jCIUoxPcsxR9QN2y37KQUCandKkg8cZ3JlZ0Brcm9h aC5jb20ACgkQMUfUDdst+ylnjQCeND+mnhXzo7wmT4E2vHER2FG8UEEAmwXRTNe6 QzKAPXT2BgHPFW7Gy8dk =UY5p -----END PGP SIGNATURE----- Merge tag 'tty-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty Pull tty / serial / vt driver fixes from Greg KH: "Here are some small serial and vt tty driver fixes for 7.2-rc7 that resolve some reported problems. Included in here are: - two vt core fixes - amba-pl011 serial driver fixes - 8250_of and 8250_dma driver fixes - qcom-geni serial driver fix - sc16is7xx serial driver fix All of these have been in linux-next this week with no reported issues" * tag 'tty-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty: serial: amba-pl011: synchronize DMA teardown serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ serial: amba-pl011: fix indefinite RS485 post-send delay vt: add permission check for KDSKBMETA ioctl vt: stabilize tty reference in kbd_keycode with tty_port_tty_get serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx serial: qcom-geni: fix TX DMA buffer flush serial: 8250_dma: Clear stale RX state on shutdown serial: sc16is7xx: enable THRI before filling TX FIFO |
||
|
|
e663f6deac |
Staging driver fixes for 7.2-rc7
Here are some more small staging driver fixes, just for the rtl8723bs driver, for some reported problems found with it now that people are starting to actually test the thing with "bad" networks. Nothing major, but good to have in the -final release. All of these have been in linux-next for over a week with no reported problems. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> -----BEGIN PGP SIGNATURE----- iG0EABECAC0WIQT0tgzFv3jCIUoxPcsxR9QN2y37KQUCandJYA8cZ3JlZ0Brcm9h aC5jb20ACgkQMUfUDdst+ykIxACfTuHhJxAk0r/QsXGjmp/u8s733lYAnjVl7Kdm v7Q+WL8+jJnxPW8jpWcy =l2iZ -----END PGP SIGNATURE----- Merge tag 'staging-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/staging Pull staging driver fixes from Greg KH: "Here are some more small staging driver fixes, just for the rtl8723bs driver, for some reported problems found with it now that people are starting to actually test the thing with "bad" networks. Nothing major, but good to have in the -final release. All of these have been in linux-next for over a week with no reported problems" * tag 'staging-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/staging: staging: rtl8723bs: validate monitor transmit frame lengths staging: rtl8723bs: fix missing shared-key auth challenge length check staging: rtl8723bs: fix OOB read in WMM_param_handler() staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() |
||
|
|
5668ba2304 |
Char / Misc and documentation fixes for 7.2-rc7
Here are some small char/misc and nvmem and documentation fixes for
7.2-rc7 to resolve some reported issues. Included in here are:
- updates to the documentation for the kernel threat model and
security bugs to get the LLMs to actually follow what we have been
asking them to do (i.e. not claim security issues for things we do
not consider security issues.)
- nvmem driver fixes which required a tiny "layout" driver to be
added.
- fastrpc driver fixes
- mei driver fix
- counter driver fix
- binder driver fix
All of these have been in linux-next this week with no reported
problems.
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
-----BEGIN PGP SIGNATURE-----
iG0EABECAC0WIQT0tgzFv3jCIUoxPcsxR9QN2y37KQUCandLdw8cZ3JlZ0Brcm9h
aC5jb20ACgkQMUfUDdst+yldzACZAVaM2/I0hIeTnoBqRFIZBcroUQYAoNk5zQSW
qYG0DWUf4LJwj9WPQWIS
=e+LJ
-----END PGP SIGNATURE-----
Merge tag 'char-misc-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc
Pull char / misc and documentation fixes from Greg KH:
"Here are some small char/misc and nvmem and documentation fixes for
7.2-rc7 to resolve some reported issues. Included in here are:
- updates to the documentation for the kernel threat model and
security bugs to get the LLMs to actually follow what we have been
asking them to do (i.e. not claim security issues for things we do
not consider security issues.)
- nvmem driver fixes which required a tiny "layout" driver to be
added.
- fastrpc driver fixes
- mei driver fix
- counter driver fix
- binder driver fix
All of these have been in linux-next this week with no reported
problems"
* tag 'char-misc-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc:
docs: security-bugs: clarify some mandatory steps for AI reports
docs: coding-assistant: explain important steps when looking for bugs
docs: security-bugs: clarify what counts as a valid version
docs: threat-model: move fake devices out of "non production use"
docs: threat-model: clarify "security bug" vs "vulnerability"
counter: microchip-tcb-capture: Fix DT channel validation
mei: pull kvfree out of spinlock
rust_binder: do not query current thread for all ioctls
nvmem: layouts: Add fixed-layout driver
nvmem: apple-spmi-nvmem: wrap regmap calls to satisfy CFI
misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free
misc: fastrpc: fix channel ctx ref leak when session alloc fails
misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke
misc: fastrpc: Remove buffer from list prior to unmap operation
misc: fastrpc: Fix initial memory allocation for Audio PD memory pool
|
||
|
|
48f2fd0d93 |
ftrace: Drop extra comma in trace_buffered_event_enable
Drop the extra comma in "scoped_guard()" to cleanup the code. Link: https://patch.msgid.link/20260730150411.88667-5-leon.hwang@linux.dev Acked-by: Jiri Olsa <jolsa@kernel.org> Signed-off-by: Leon Hwang <leon.hwang@linux.dev> Signed-off-by: Steven Rostedt <rostedt@goodmis.org> |
||
|
|
092f8ec7db |
ftrace: Protect direct_functions in update_ftrace_direct_mod
Fix accessing the __rcu pointer direct_functions with RCU protection.
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260730150411.88667-4-leon.hwang@linux.dev
Fixes:
|
||
|
|
f26e5fa75f |
ftrace: Protect direct_functions in update_ftrace_direct_del
Fix accessing the __rcu pointer direct_functions with RCU protection.
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260730150411.88667-3-leon.hwang@linux.dev
Fixes:
|
||
|
|
63444b7617 |
ftrace: Protect direct_functions in ftrace_find_rec_direct
Fix accessing the __rcu pointer direct_functions with RCU protection.
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260730150411.88667-2-leon.hwang@linux.dev
Fixes:
|
||
|
|
a7c7074b58 |
fbdev core fixes for 7.2-rc7:
A few patches for the core fbdev layer which stabilize or fix potential issues with text font rendering after screen rotation or after user initiated font changes and locking fixes for sysfb during modifications of the graphics mode database. -----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQS86RI+GtKfB8BJu973ErUQojoPXwUCanbPzgAKCRD3ErUQojoP XyrEAPwJgK7J9UvN1Ii0V9p175Z/3Mzwo6DF1Z4KW5ctYVTAsQD/TC91d1vqKtJ7 SHgY6jCLegC/DpLk4dqshBPrdO2pAgM= =Y1ZB -----END PGP SIGNATURE----- Merge tag 'fbdev-for-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/deller/linux-fbdev Pull fbdev fixes from Helge Deller: "A few patches for the core fbdev layer which stabilize or fix potential issues with text font rendering after screen rotation or after user initiated font changes and locking fixes for sysfb during modifications of the graphics mode database" * tag 'fbdev-for-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/deller/linux-fbdev: fbdev: bitblit: bound-check glyph index in bit_cursor() fbdev: Fix out-of-bounds access when rotating console after font resize fbdev: core: Fix pointer desynchronization in fb_io_read() fbdev: serialize mode sysfs access with lock_fb_info() fbdev: clear fb_info->mode before deleting a videomode fbdev: bound mode sysfs output to the sysfs buffer |
||
|
|
f0ece16ffc |
eventfs: Use children field for rcu head and add memory barriers
When an eventfs inode is freed, it sets ei->is_freed and then uses its
ei->list to add it to the srcu link list as the list field is a union with
the rcu list head. As the ei->list is used to iterate over an SRCU
protected list without taking the eventfs_mutex, there's nothing stopping
the iteration over that list to see the ei->rcu instead of the ei->list
and it will read a corrupt target.
To fix this, change the union of the rcu list head with the children list.
On freeing the eventfs inode, set the is_free and execute a smp_wmb()
before adding the eventfs inode to the SRCU list.
On iteration of the ei->children list, at the start, execute a smp_rmb()
and then read the is_freed of the ei to see if the children list is still
valid. If is_freed is set, then the ei_child read is not valid and the
loop should exit immediately.
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260808094215.4252430d@robin
Fixes:
|
||
|
|
fd73b69170 |
eventfs: Fix use-after-free in eventfs_remove_rec()
eventfs_remove_rec() recursively removes the child at the current loop
position. After the recursive call returns, list_for_each_entry() advances
by reading list.next from the removed child.
If free_ei() drops the final reference, release_ei() reuses the list/rcu
union to queue an SRCU callback. The child may be freed before that read.
The eventfs_mutex serializes list updates, but it does not keep the removed
child alive or prevent the SRCU callback from running.
Use list_for_each_entry_safe() to save the next sibling before recursively
removing the current child.
Cc: stable@vger.kernel.org
Fixes:
|
||
|
|
361efac9e9 |
Driver core fixes for 7.2-rc7
- Fix Rust build failure on s390 by gating ioremap() / iounmap() helpers and the io::mem module on CONFIG_HAS_IOMEM; gate affected doctests as well. - Add missing kernel-doc for show_const / store_const union members in struct device_attribute. -----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQS2q/xV6QjXAdC7k+1FlHeO1qrKLgUCancYdAAKCRBFlHeO1qrK LneZAQD9bhMwOb9C8t+fLXEYd6WR+1n932bmKTBSscZ1evnojwD+M4MqTWDBDgal Mc8wasHQsQc7pqVFFHtFEUIAZjRlpAc= =KHk2 -----END PGP SIGNATURE----- Merge tag 'driver-core-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/driver-core/driver-core Pull driver core fixes from Danilo Krummrich: - Fix Rust build failure on s390 by gating ioremap() / iounmap() helpers and the io::mem module on CONFIG_HAS_IOMEM; gate affected doctests as well. - Add missing kernel-doc for show_const / store_const union members in struct device_attribute. * tag 'driver-core-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/driver-core/driver-core: rust: io: gate ioremap doctests on CONFIG_HAS_IOMEM rust: io: gate ioremap/iounmap on CONFIG_HAS_IOMEM driver core: add missing kernel-doc for union members |
||
|
|
7d8c681eef |
Input updates for v7.2-rc6
- Fixes for information leaks and OOB accesses across several drivers, including evdev, focaltech, edt-ft5x06, iforce, and cs40l50-vibra - Improvements to the synaptics-rmi4 driver to properly handle F54 worker errors and prevent buffer overflows - Input validation fixes in the hynitron_cstxxx touchscreen driver to prevent issues with invalid finger IDs and touch counts - Fixes for use-after-free and initialization bugs in the byd mouse and psxpad-spi drivers - New quirks for the atkbd driver to make keyboard work on HONOR and Xiaomi laptops - Support for the ZENAIM LEVERLESS controller in the xpad driver. -----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQST2eWILY88ieB2DOtAj56VGEWXnAUCana8zQAKCRBAj56VGEWX nAIMAQCFKhBk3M4Q+625XmMMcb9AV+Bl0TTCxXBbdrA8bYJ+IQEA0C9AQXCmIGzC lwr7jlgTET8vN/NrEVD+WN9jNzFmZgA= =jcbm -----END PGP SIGNATURE----- Merge tag 'input-for-v7.2-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input Pull input updates from Dmitry Torokhov: - Fixes for information leaks and OOB accesses across several drivers, including evdev, focaltech, edt-ft5x06, iforce, and cs40l50-vibra - Improvements to the synaptics-rmi4 driver to properly handle F54 worker errors and prevent buffer overflows - Input validation fixes in the hynitron_cstxxx touchscreen driver to prevent issues with invalid finger IDs and touch counts - Fixes for use-after-free and initialization bugs in the byd mouse and psxpad-spi drivers - New quirks for the atkbd driver to make keyboard work on HONOR and Xiaomi laptops - Support for the ZENAIM LEVERLESS controller in the xpad driver. * tag 'input-for-v7.2-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input: Input: evdev - sanitize event type index when fetching event masks Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue Input: synaptics-rmi4 - block s_input when F54 queue is busy Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer Input: synaptics-rmi4 - zero report size on F54 work error Input: synaptics-rmi4 - fix F55 transmitter electrode count typo Input: hynitron_cstxxx - validate touch count and finger IDs Input: evdev - fix information leak in evdev_pass_values() fixp-arith: convert comments to kernel-doc format Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet Input: atkbd - skip deactivate for HONOR ZQC-P Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard Input: iforce - validate input packet lengths Input: psxpad-spi - set driver data before use Input: cs40l50-vibra - validate custom data from user space Input: xpad - add support for ZENAIM LEVERLESS Input: edt-ft5x06 - ignore contacts with an out-of-range slot id Input: byd - synchronize timer deletion before freeing private data |
||
|
|
afe80aebd3 |
powerpc fixes for 7.2 #4
- Couple of fixes for mem leak and underflow case Thanks to: George Wilson, R Nageswara Sastry -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEqX2DNAOgU8sBX3pRpnEsdPSHZJQFAmp2vToACgkQpnEsdPSH ZJTdSRAAyU2MKr444tK8kb/wFlZJ2kT2nHmLvotr7OrTPfb3A48cTcUYqzi3aJ5r hbethTk1diJa5fM+hbN5AJLA3DBNSknAEDJiyQKeE1knOr0Q1qn3NIQL6ROJaIe0 vTeOkJHzDzpU9dWnYbhoAxuNC+rQCicuNjB5WPd93LayI2kP1BN94uEb6GU5AMOz HLqH3j/9kWtFTt+x6pbIzSiOQy6+p3lbtjJS/FMsn2wqeqRyY2IehFBP27+dpjJX z2S20qnrS+8CuZ6tut/vSJIdIozRROwGXLTx1jRHXAGsfdWCp3W+drcY3lmwFRtK xq1x6z0c6+JJvaBPGtLDQCi7wURZ3DAlBHEA8PbfLYLogt4AuVBA0WFSI1Vlr4LX rTsuG/eV4GgjSEFEHRCa68+PuQ4imjNauyX2Ty+74rqzQwIgG4O0btnJFiCHZymt hZXBDbdCr17U1+2mQI5T//n67i+sKSpgM492ti+vpaYK8Ou0Ki1oOKnPiH6KyTXz QkvwfOTKrdrMVVUgI1jtM/19ewa/z/0OoBQBT8vmRY6qkbR0k6SCV6Na9tQVAxpw l6JNcFpYidvLuXJq5NhtxdyGFqh1a/WvNR7Q/LkVmpNXVauqiYTRe4HA7RtCmOv2 JGTpk1fzn2aq+pojDZnUV7EoVg+keO1EGhPAWEJ/KDEoMEcI/5o= =HV3X -----END PGP SIGNATURE----- Merge tag 'powerpc-7.2-4' of git://git.kernel.org/pub/scm/linux/kernel/git/powerpc/linux Pull powerpc fixes from Madhavan Srinivasan: - A couple of fixes for a memory leak and a underflow case Thanks to George Wilson and R Nageswara Sastry * tag 'powerpc-7.2-4' of git://git.kernel.org/pub/scm/linux/kernel/git/powerpc/linux: powerpc/pseries: lparcfg - fix kbuf[] underflow powerpc/pseries: pci - logic bug powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak |
||
|
|
e033cbf397 |
fbdev: bitblit: bound-check glyph index in bit_cursor()
bit_cursor() fetches the glyph under the cursor with c = scr_readw(vc_pos); src = vc_font.data + ((c & charmask) * w * height); where charmask is 0x1ff when vc_hi_font_mask is set. The screen buffer value comes directly from scr_readw() and may be larger than the current font's glyph count. Syzkaller triggers this via vcs_write(). The Call Trace shows vcs_write() in vc_screen.c writing an arbitrary 16-bit value with writev() to /dev/vcsa, which vcs_write_buf() in vc_screen.c stores via vcs_scr_writew() without checking charcount. The stored value is later read in bit_cursor() in bitblit.c. When the font is changed from a font with 512 glyphs to a font with 256 glyphs, the screen buffer can retain characters with the high bit set from the previous mode, which could also produce the same out-of-bounds access. BUG: KASAN: global-out-of-bounds in soft_cursor+0x378/0x6bc drivers/video/fbdev/core/softcursor.c:70 Read of size 16 at addr ffff800086c57970 Call Trace: soft_cursor+0x378/0x6bc drivers/video/fbdev/core/softcursor.c:70 bit_cursor+0xa90/0x1108 drivers/video/fbdev/core/bitblit.c:365 fbcon_cursor+0x344/0x498 drivers/video/fbdev/core/fbcon.c:1427 hide_cursor+0xdc/0x2d0 drivers/tty/vt/vt.c:883 update_region+0x100/0x18c drivers/tty/vt/vt.c:669 vcs_write+0x8ec/0xaf0 drivers/tty/vt/vc_screen.c:685 bit_putcs_aligned() and bit_putcs_unaligned() already clamp the glyph index to vc_font.charcount. Apply the same clamp in bit_cursor() after extracting the attribute and masking, before indexing fontdata. The fix completes the bounds checking started in commit |
||
|
|
ef7656e85f |
fbdev: Fix out-of-bounds access when rotating console after font resize
[BUG] Recently, we encountered a KASAN warning as follows: BUG: KASAN: slab-out-of-bounds in ccw_putcs+0x8bd/0xa80 Read of size 1 at addr ff11000110067100 by task bash/1209 CPU: 10 UID: 0 PID: 1209 Comm: bash Not tainted 7.2.0-rc3 #69 PREEMPT(full) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc41 04/01/2014 Call Trace: <TASK> ... kasan_report+0xf0/0x120 ? ccw_putcs+0x8bd/0xa80 ccw_putcs+0x8bd/0xa80 ? __pfx_ccw_putcs+0x10/0x10 fbcon_putcs+0x338/0x410 ? __pfx_ccw_putcs+0x10/0x10 do_update_region+0x21d/0x450 invert_screen+0x29d/0x5e0 ? __kmalloc_noprof+0x493/0x640 ? vc_do_resize+0x17c/0xe50 clear_selection+0x4c/0x60 vc_do_resize+0xaee/0xe50 fbcon_modechanged+0x2bd/0x640 rotate_all_store+0x298/0x380 ... reproduce: 1) issue two ioctls: first a KDFONTOP ioctl with op.op = KD_FONT_OP_SET, op.width = 1 and op.height = 1, then a TIOCL_SETSEL ioctl 2) echo 2 > /sys/devices/virtual/graphics/fbcon/rotate_all 3) issue two ioctls: first a KDFONTOP ioctl with op.op = KD_FONT_OP_SET, op.width = 8 and op.height = 1, then a TIOCL_SETSEL ioctl 4) echo 3 > /sys/devices/virtual/graphics/fbcon/rotate_all [CAUSE] The root cause is that fbcon_modechanged() first sets the current rotate's corresponding ops. Subsequently, during vc_resize(), it may trigger clear_selection(), and in fbcon_putcs->ccw_putcs[rotate=3], this can result in an out-of-bounds access to "src". This happens because par->rotated.buf is reallocated in fbcon_rotate_font(): 1) When rotate=2, its size is (width + 7) / 8 * height 2) When rotate=3, its size is (height + 7) / 8 * width And the call to fbcon_rotate_font() occurs after clear_selection(). In other words, the fontbuffer is allocated using the size calculated from the previous rotation 2, but before reallocating it with the new size, con_putcs is already using the new rotation 3: rotate_all_store fbcon_rotate_all fbcon_set_all_vcs fbcon_modechanged set_blitting_type ... par->bitops = &ccw_fbcon_bitops vc_resize ... clear_selection highlight ... do_update_region fbcon_putcs ... image.dy = vyres - ((xx + count) * vc->vc_font.width) [1] // overflow! ccw_putcs_aligned // old buf size is still being used during the read! src = par->rotated.buf + (scr_readw(s--) & charmask) * cellsize fb_pad_aligned_buffer----[src KASAN!!!] [2] info->fbops->fb_imageblit(info, image) sys_imageblit fb_imageblit fb_address_forward // offset: image->dy * bits_per_line + image->dx * bpp unsigned int bits = (unsigned int)adr->bits + offset adr->address += (bits & ~(BITS_PER_LONG - 1u)) / BITS_PER_BYTE [3] fb_bitmap_imageblit ... fb_read_offset // page fault! [4] update_screen redraw_screen ... ccw_cursor soft_cursor memcpy(src, image->data, dsize)----[src KASAN again!!!] [5] fbcon_switch fbcon_rotate_font font_data_rotate dst = kmalloc_array(charcount, d_cellsize, GFP_KERNEL) // the new size is allocated only here! par->rotated.buf = buf [6] [FIX] A fairly obvious approach is to follow fbcon_switch(): in fbcon_modechanged(), call rotate_font() before vc_resize() so that a correctly sized buffer is allocated in time, as done in [6]. This fix is necessary, but it is not sufficient on its own. In [1] it causes an image.dy overflow (ccw_putcs: vyres = 768, image.dy = 4294967040), because vc_cols has not been updated in time at this point (it is likewise only updated after clear_selection()). This allows (xx + count) * width to exceed vyres, causing image.dy to overflow. Subsequently, address in [3] is incremented by an even larger amount, which triggers a page fault at [4]. Therefore, a second fix is required in combination with the first: move clear_selection() earlier, before set_blitting_type() in fbcon_set_all_vcs(), to prevent the out-of-bounds access. fbcon_rotate() has a similar problem, so add the same clear there. Since vc_is_sel() is not exported, the fbdev side is currently forced to call clear_selection() unconditionally, causing the global selection to be cleared prematurely. And this will not cause any other significant impact. Signed-off-by: Zizhi Wo <wozizhi@huawei.com> Signed-off-by: Helge Deller <deller@gmx.de> |
||
|
|
81cc73be40 |
fbdev: core: Fix pointer desynchronization in fb_io_read()
In fb_io_read(), if copy_to_user() performs a partial copy (e.g., due to
a faulty user buffer), the loop adjusts the chunk size 'c' and updates
the remaining 'count'. However, the hardware 'src' pointer has already
been eagerly advanced by the original chunk size.
If the loop is allowed to continue, the read will resume from an
incorrect, over-advanced offset. Since the remaining 'count' was only
decremented by the successful bytes, this desynchronization causes the
next iterations to execute more hardware reads than originally bounded,
eventually leading to out-of-bounds I/O reads.
Fix this by breaking out of the loop immediately upon a partial
copy_to_user(). A partial copy indicates a faulty user buffer, making
subsequent read attempts futile. Breaking out ensures we return the
number of successfully read bytes without risking out-of-bounds hardware
accesses in subsequent mismatched iterations.
Fixes:
|
||
|
|
061db6b7a9 |
fbdev: serialize mode sysfs access with lock_fb_info()
show_mode(), show_modes(), and store_mode() access fb_info->modelist and fb_info->mode without holding lock_fb_info(). store_modes() takes lock_fb_info() while replacing the modelist and freeing the old one. A concurrent reader or writer can load a pointer to an old modelist entry before store_modes() frees it, then dereference freed memory or store a stale freed pointer in fb_info->mode. Take lock_fb_info() in show_mode(), show_modes(), and store_mode() to serialize with store_modes(). In show_mode(), copy the mode to the stack and format after dropping the lock. In store_mode(), split activate() into a _locked variant to avoid double-locking, and hold the locks for the modelist walk, mode conversion, activation, and fb_info->mode assignment together. Cc: stable@vger.kernel.org # v7.1+ Signed-off-by: Melbin K Mathew <mlbnkm1@gmail.com> Signed-off-by: Helge Deller <deller@gmx.de> |
||
|
|
95e647d2a5 |
fbdev: clear fb_info->mode before deleting a videomode
fb_set_var() can delete a mode from info->modelist when userspace passes FB_ACTIVATE_INV_MODE through FBIOPUT_VSCREENINFO. The code checks that the mode being deleted is not the current info->var and that fbcon is not using it, but it does not check fb_info->mode. fb_info->mode may still point into the modelist entry being deleted. If the entry is freed, later mode sysfs reads through show_mode() can dereference a stale pointer. Clear fb_info->mode before calling fb_delete_videomode() when it matches the mode being removed. Cc: stable@vger.kernel.org # v7.1+ Signed-off-by: Melbin K Mathew <mlbnkm1@gmail.com> Signed-off-by: Helge Deller <deller@gmx.de> |
||
|
|
d15d51fb26 |
fbdev: bound mode sysfs output to the sysfs buffer
mode_string() uses snprintf() which can return a value larger than the remaining buffer space. show_modes() accumulates the return value into i without checking whether i has reached PAGE_SIZE, causing the offset to advance past the sysfs buffer if the modelist is long enough. Add a size parameter to mode_string() and use scnprintf() to return only the bytes actually written. Add an early return when offset already exceeds the buffer. In show_modes(), stop accumulating once the buffer is full. Cc: stable@vger.kernel.org # v7.1+ Signed-off-by: Melbin K Mathew <mlbnkm1@gmail.com> Signed-off-by: Helge Deller <deller@gmx.de> |
||
|
|
fb442a6673 |
powerpc/pseries: lparcfg - fix kbuf[] underflow
In lparcfg_write(), a count of 0 results in kbuf[] being indexed at -1.
Check for count == 0 in the existing check for count > sizeof(kbuf) and
return -EINVAL if true.
Fixes:
|
||
|
|
649c10bff5 |
powerpc/pseries: pci - logic bug
The checks on num_vfs in pseries_pci_sriov_enable() are ANDed where OR
was apparently intended. Change it to OR.
Fixes:
|
||
|
|
5b17f3f343 |
powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak
In papr_phy_attest_create_handle(), the params->cmd.length is not
validated before use, which can result in a buffer overlow. Check it and
return -EINVAL if it is either 0 or exceeds sizeof(params->cmd).
Also, params is freed on the success path but not error. Free it on
errors after memory allocation. And free it on negative fd.
Fixes:
|
||
|
|
a59f57e2aa |
watchdog fixes for v7.2-rc7
* at91sam9_wdt: prevent timer rearm during teardown * bd96801_wdt: Fix timeout for enabled WDG * atcwdt200: Fix return value when watchdog is enabled -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEiHPvMQj9QTOCiqgVyx8mb86fmYEFAmp2dMQACgkQyx8mb86f mYGaYw/+NLMhySF0tbh+WHyf5AZRxb87MaGjnBSGN0FO2aaY1FVSlEgH9ilZmKjG k4s6SblSK9cOS/EbHFFn9Jwg4WTUZmEI2udzPnRQqo27RpGXVmq9TtVinadS2y7+ OrzegwUVJ2g6Wk4mnk1VbDeR31GHZM5pHvPzTPnQ0EuITH4BJY2vzBHcZeHyoNEo BFS9Nt8uaWpVtzq0YpChb45Gjh26zA2pB8IUndLX7fRbZmI4YD937OdzItTIrHH+ idDy/pYu7s/s6s8dJ8NIj2vqxeOP7aQvuWTAiBYoCO2s4mgaF9kEo29IUSfFjEhh 0ljfiyodRuu/hDzBAVPHejqCahv4k/aWVaP+LZgxVkQ3mJq0MuC39DB61O3aUrLD 4giRWZPTYpz0P010aaL9cwv78upu64LQ0te1X31UsNcj1Hl//bnY9mQohwYajbbq qxcQp4I4k0/u9DxpX09yl0WNngNGWaxviETO1XOjIDOopHTxwNjfmT1B1pdGTLEk +YMPn5k/ZySYxzrzViBe7pHg/0cxRJ2gzSNhrpTDlIXPPk/JgmcI6zNC71vqADXQ O3Ge8si4F610QfDvqtGTE3Quzm0UMGWtKOUHhz/WtLXDLxaowaa5TQuF/W3E4Xlv cpv3jlIw5GkPcY6srMJ93iCuLLlPgD4Ic0LrF7VajsAtqadGPjU= =2zg4 -----END PGP SIGNATURE----- Merge tag 'watchdog-for-v7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging Pull watchdog fixes from Guenter Roeck: - at91sam9_wdt: prevent timer rearm during teardown - bd96801_wdt: Fix timeout for enabled WDG - atcwdt200: Fix return value when watchdog is enabled * tag 'watchdog-for-v7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging: watchdog: at91sam9_wdt: prevent timer rearm during teardown watchdog: bd96801_wdt: Fix timeout for enabled WDG watchdog: atcwdt200: fix return value when watchdog is enabled |
||
|
|
5d78d199be |
hwmon fixes for v7.2-rc7
Various fixes, most of them fixing critical or high severity bugs reported by Sashiko. * ads7828 - Fix external VREF regulator handling * corsair-psu - Fix linear11 calculation - Serialize debugfs access against hwmon - Fix possible out-of-bounds access on missing string termination * ltc4282 - Fix parsing adi,current-limit-sense-microvolt - Clamp negative current limits - Avoid overflow in maximum power calculation * nzxt-smart2 - Check return value of init_device() in probe * PMBus core - Fix type confusion in notification logic - Avoid race condition during probe * PMBus/lm25066 - Fix PMBus coefficient calculations -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEiHPvMQj9QTOCiqgVyx8mb86fmYEFAmp2c8wACgkQyx8mb86f mYEBzQ/8C6RlGpqieOaNrppHgD4kyjZTxsa1Zdg4HyVm0wG4NukwOzgXwwdukXCW vXsO7aDztPE0e6HHuBeeMtN838tKvGuNpeA4xXbel1VkKvho2whaMRT43kUGs9OF l9Mquauv1ts9VCKEdmtfrTBsH1EtYSG2avFd2BiIihnvzBViET2yEI/VmE/kF5YC q3osU7GxvElh9F+MeWhVrElWmwEBEaHJHmDOJr1ZBPGvqqG6tHtWf+8ZAAvZVwtW YWwiZwk1cgMKG+b35JGe1c2o+C+Eu26BC88zuu0dT6sZRFrJbWk2YFLNQFbyE1MJ C8ifRN5KgQSGLWyNfZTWeyPPy9K4Tp6Y8h6b0xqV0F3yvLp49cv06UyabhTOIsKS rWwu9Pz1YS7OED2ljfKkULbSNCX4PqoENK3KSPN9vMP0N55syVln3W+p+q7JmLxq ag8O95d8uAJD8WE8NtqbVyTY+rm7lJ+L0CxI1JRgNsA6ARD04+yX4yF4Fobdl0y7 IDdfQKlHOKvXuNjoDaqbDUuDFJV+izWAK/+XxXIYMOvuDrTDjB7zYoDcaPAyTCKa SQGDLYExzhXI3A17CkjXSQlKakuq9nww6ShFgsFZxXAgrAnAZ8GUE3r4HySZlSY+ wedjpB+OJVU7NzokFESxuFVmSuogavqmmBwq0Yo9n8I/hn0nwVc= =sLkT -----END PGP SIGNATURE----- Merge tag 'hwmon-for-v7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging Pull hwmon fixes from Guenter Roeck: "Various fixes, most of them fixing critical or high severity bugs reported by Sashiko. ads7828: - Fix external VREF regulator handling corsair-psu: - Fix linear11 calculation - Serialize debugfs access against hwmon - Fix possible out-of-bounds access on missing string termination ltc4282: - Fix parsing adi,current-limit-sense-microvolt - Clamp negative current limits - Avoid overflow in maximum power calculation nzxt-smart2: - Check return value of init_device() in probe PMBus core: - Fix type confusion in notification logic - Avoid race condition during probe PMBus/lm25066: - Fix PMBus coefficient calculations" * tag 'hwmon-for-v7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging: hwmon: (corsair-psu) Fix linear11 calculation hwmon: (corsair-psu) serialize debugfs access against hwmon hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt hwmon: (ltc4282) Clamp negative current limits hwmon: (ltc4282) Avoid overflow in maximum power calculation hwmon: (ads7828) Fix external VREF regulator handling hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations hwmon: (nzxt-smart2) Check return value of init_device() in probe hwmon: (pmbus) Fix type confusion in notification logic hwmon: (pmbus/core) Avoid race condition during probe |
||
|
|
9a143525f6 |
ata fixes for 7.2-rc7
- Disable liknk power management on yet another misbehaving WD drive
(Niklas).
- Fix a use after free issue in the pata_sl82c105 driver (Hongyan).
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQSRPv8tYSvhwAzJdzjdoc3SxdoYdgUCanZp5gAKCRDdoc3SxdoY
dtQwAP0Yq6NUePN6QaCMJL214S3VVASmM5HaDuj3pECJbXBUxgD+L+i3CkytaJKi
pII90cCwLvXXuRT35HO5XXQGxt3Z5AY=
=CUb4
-----END PGP SIGNATURE-----
Merge tag 'ata-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux
Pull ata fixes from Damien Le Moal:
- Disable link power management on yet another misbehaving WD drive
(Niklas)
- Fix a use after free issue in the pata_sl82c105 driver (Hongyan)
* tag 'ata-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux:
ata: pata_sl82c105: fix bridge revision use-after-free
ata: libata-core: Disable LPM on WDC WD141KFGX-68FH9N0
|
||
|
|
bcc44b6785 |
drm fixes for 7.2-rc7
shmem: - check VMA boundaries for PMD mappings xe: - Fix memory leak in exec_queue_set_hang_replay_state - Apply RCS/CCS yield policy to SR-IOV VFs amdgpu: - JPEG queue reset fixes - GC 12 fix - GMC 12.1 fixes - Lockdep false positive fix - Userq fix - Bounds checking fixes - Devcoredump fixes - DCN 2.0.1 fix - Aperture mapping fix - DC avmute fix - DC self refresh fix radeon: - Performance regression fix panthor: - skip zero sized firmware segments - check VMA boundaries for PMD mappings bridge: - ps8640: propagate AUX transfer register errors amdxdna: - Improve error handling in amdxdna_insert_pages. v3d: - serialise scheduler timeouts -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEEKbZHaGwW9KfbeusDHTzWXnEhr4FAmp2SKIACgkQDHTzWXnE hr7tMg/8Cr2JwdX1gtShUvxjcuil3Vb4pQbcKVCbAuDBvlXLLThAXqgb13y4CBsJ Isk6t4g4660HTDAmUBEfas0iP01rrp6f0qDVx7qFz6BkZJH9y0I4h4cuybUtKkX4 WXfYxV51+inWRI84++jPEdj6l9+acYVlbU1+/7LlGn2I2ggdxdDT9+Mo2v/92sUV P5tqOP9R7WxOHvDeGpRQqzhBSQYQVxVmjzXuRpQPEjxckYLIfCKZyDUeP4mPkFSE NcYksbB2bl186Vq4+KYd4P0uEAyYl27td0kQsJEpKvIRYrKVkEhq7gru70TBnPlE ZD1mnAhvDuHYoGlYcU5W5N5Pj2FKvpRqxfmwoT/HNP007rvVUOMVK7mDe7xyAj3j feAxFY7tAJduqx+DAOpU1IAtdPikrO/xjhxoGjUMtTeUOOebJNdNKK6O8dCMqcsX rl05bjWecGZwEmt+juEjVGeVjqIzQ+qAydPw/0OmxaQ/oQ307/ijTT61LG3yD81G fHdOdGdbV5JVn/D8TqPk6fPb5Vk+sRE/qznLVQhtI3u7/SstggiHpX6lTgRrOiO0 GI7pZuxl1zxQfV3/tj4jDBYi+ODA1Bs2enJwtq16FMkpqlEp/GpAb3S7qNNP1KI2 jm9NrVCYP0f3x2lT8CIy+mp2t+tg+RMyYK6kAbevRyrC65mQH3U= =6In+ -----END PGP SIGNATURE----- Merge tag 'drm-fixes-2026-08-08' of https://gitlab.freedesktop.org/drm/kernel Pull drm fixes from Dave Airlie: "Weekly fixes for drm, feels relatively quiet for the post-AI world, mostly amdgpu and xe with a few fixes across the board: shmem: - check VMA boundaries for PMD mappings xe: - Fix memory leak in exec_queue_set_hang_replay_state - Apply RCS/CCS yield policy to SR-IOV VFs amdgpu: - JPEG queue reset fixes - GC 12 fix - GMC 12.1 fixes - Lockdep false positive fix - Userq fix - Bounds checking fixes - Devcoredump fixes - DCN 2.0.1 fix - Aperture mapping fix - DC avmute fix - DC self refresh fix radeon: - Performance regression fix panthor: - skip zero sized firmware segments - check VMA boundaries for PMD mappings bridge: - ps8640: propagate AUX transfer register errors amdxdna: - Improve error handling in amdxdna_insert_pages. v3d: - serialise scheduler timeouts" * tag 'drm-fixes-2026-08-08' of https://gitlab.freedesktop.org/drm/kernel: (26 commits) drm/amd/display: allow self-refresh exit while entry is blocked drm/amdgpu: fix aperture iounmap skipped on device removal drm/amd/display: Check for tg ops in dce110_set_avmute Revert "drm/amdgpu: fix aperture mapping leak" drm/radeon: restore hardware polling in fence_is_signaled to fix performance regression drm/amd: Disable DP audio spread spectrum for Cyan Skillfish drm/amdgpu/gmc12.1: fix MMHUB0 check in pasid tlb flush drm/amdgpu: Allocate coredump ring buffers per ring drm/amdgpu: Use virtual alloc during coredump drm/amdgpu: reject oversized IBs with per-ring packet limits drm/amdgpu/userq: serialize queue map against GPU reset drm/amdgpu: Fix lockdep false positive in amdgpu_lockdep_init drm/amdgpu/gmc12.1: implement tlb inv semaphore drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12 drm/amdgpu: fix JPEG v5.3.0 queue reset failure in DPG mode drm/amdgpu: fix JPEG v4.0.5 queue reset failure in DPG mode drm/amdgpu: fix JPEG v5.0.0 queue reset failure in DPG mode drm/panthor: Check VMA boundaries for PMD mappings drm/xe/uc: Apply RCS/CCS yield policy to SR-IOV VFs drm/xe: Fix memory leak in exec_queue_set_hang_replay_state() ... |
||
|
|
3f00828032 |
Pin control fixes for v7.2:
Qualcomm fixes: some incorrectly defined groups in IPQ9650, two pins needing to be marked as GPIO in IPQ806X. -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEElDRnuGcz/wPCXQWMQRCzN7AZXXMFAmp2K4kACgkQQRCzN7AZ XXNfeRAAtZL/qwyt03wCaPCnpUVmtkcAdoKSKteUbGOf73w9VlEal8gZTY6K/EiE gCiLGJqBoB7cZqDUlt7wnv2SeW08P7NCwZz7QGWG728cx2c8gUrWtxUHbNcDrhps UpWIDF1E3khGDGki726nq2Qo1bYAG57tEVZtRsUjMTb+XQQI9JQKpvS3QECxTXwD f/QLUbkT5rRuOqXq+PQzCoD3zSkZTCWgJIL+B2uC+/CuHK682FPC+qa19i4Xdeju RZBbj6oEvt5jL52qq/jtFlRViUrdxPBb6ju1+2H3g2AUVLZe9kbSvbzO0XzO9Qvq dfLHRLBm9CcSBIcYJJwC1dVhh2Ekn5o87cxEQzBajpEaErTAac/xmblkKRKkpX/u VQTxH3IWs7ypoEB9u8c/nt6VixnvALJY/1ldznSANUstnSYrIO+mGQVDPqbfL41o K/JxaNvIKYQHfOpGcWG69hVf0ZP+NSsftfKubapiK0NO4cYnqzFpazfAvqL06Jeg jRiE0K4QWe/vraYXW/iXOw8Zb+IQAN3Z3w5KKeJg7qtPiYEdoyYp94mI3HQF5hdm hh42y0CIK3J9uXdE+s+5iNq65HGNZDzKceQ45j+Aof6w1ZhokwB3iJ4z7iQzNNgs 7VtSnTDWaqF2PS34gwLv36dAoeQ8qT33bmzVPA4xOwnIOJl2wfo= =8MB1 -----END PGP SIGNATURE----- Merge tag 'pinctrl-v7.2-3' of git://git.kernel.org/pub/scm/linux/kernel/git/linusw/linux-pinctrl Pull pin control fixes from Linus Walleij: "Qualcomm fixes: some incorrectly defined groups in IPQ9650, two pins needing to be marked as GPIO in IPQ806X" * tag 'pinctrl-v7.2-3' of git://git.kernel.org/pub/scm/linux/kernel/git/linusw/linux-pinctrl: pinctrl: qcom: ipq806x: mark pci reset as a GPIO pin function pinctrl: qcom: ipq806x: mark gpio as a GPIO pin function pinctrl: qcom: ipq9650: fix audio_sec_mclk_in1/out1 group pins |
||
|
|
8e7ff730dd |
futex: Fix race in futex_pivot_pending() during private hash resize
A task performing a custom private hash resize can remain blocked in
uninterruptible sleep indefinitely. The hung-task detector reports:
INFO: task futex-resizer:314 blocked for more than 10 seconds.
task:futex-resizer state:D stack:14824 pid:314 tgid:312 ppid:311
Call Trace:
__schedule+0x521/0xf30
schedule+0x22/0xa0
futex_hash_allocate+0x3db/0x490
__do_sys_prctl+0x6f5/0xbd0
do_syscall_64+0xf9/0x530
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Kernel panic - not syncing: hung_task: blocked tasks
futex_pivot_pending() allows the resize request to continue when
either no replacement hash is pending (hash_new == NULL) or the current
hash reference count has reached zero.
After the final-reference wake, another futex task can complete the
pivot between the two observations:
T1 T2
futex_hash_allocate()
wait_var_event(mm, ...)
futex_pivot_pending(mm)
hash_new != NULL
futex_hash()
futex_ref_get(old) -> false
futex_pivot_hash(mm)
hash_new = NULL
__futex_pivot_hash(mm, new)
rcu_assign_pointer(hash, new)
fph = rcu_dereference(hash) /* new */
futex_ref_is_dead(fph) -> false
schedule()
The pivot changes the state from hash_new != NULL with a dead current
hash to hash_new == NULL with a live current hash. Because
futex_pivot_pending() reads hash_new and hash without serialization,
the resize task can observe hash_new in the pre-pivot state and hash in
the post-pivot state, causing futex_pivot_pending() to return false even
though the pivot has completed. The task then goes to sleep after the
wakeup has already been consumed.
Serialize state reads in futex_pivot_pending() using futex_mm_phash::lock.
This guarantees that futex_pivot_pending() observes hash_new and hash
atomically, eliminating the race condition.
Fixes:
|
||
|
|
a13307e97d |
BPF fixes:
- Fix BPF verifier to preserve full pointer state for commuted
scalar += pointer arithmetic (Yiyang Chen, Eduard Zingerman)
- Fix a use-after-free of request sockets in the BPF TCP
iterator batching (Jose Fernandez)
- Fix a use-after-free of sk_redir in the BPF sockmap send
verdict path (Chengfeng Ye)
- Fix a netns reference imbalance in the BPF conntrack kfuncs
(Chengfeng Ye)
- Fix bpf_get_fsverity_digest() dynptr assumptions and silent
digest truncation (Eric Biggers)
- Fix bpf_tcp_{gen,check}_syncookie to check sk_state before
sk_protocol to make sure it is a full socket (Luxiao Xu)
- Fix rqspinlock to reset the tail when preserving the queue
on deadlock (Kumar Kartikeya Dwivedi)
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
-----BEGIN PGP SIGNATURE-----
iIsEABYKADMWIQTFp0I1jqZrAX+hPRXbK58LschIgwUCanXeCRUcZGFuaWVsQGlv
Z2VhcmJveC5uZXQACgkQ2yufC7HISIMfLQD9EWzi5MVBTcvg0XsHY1GZZBZUpfwo
VCrfPm9vHAVuqQ0A/0D9vWVRf1UEk9ccn+ebVKPuTuydGnDRR0Qovuca4gQF
=jZY8
-----END PGP SIGNATURE-----
Merge tag 'bpf-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf
Pull BPF fixes from Daniel Borkmann:
- Fix BPF verifier to preserve full pointer state for commuted
scalar += pointer arithmetic (Yiyang Chen, Eduard Zingerman)
- Fix a use-after-free of request sockets in the BPF TCP iterator
batching (Jose Fernandez)
- Fix a use-after-free of sk_redir in the BPF sockmap send verdict
path (Chengfeng Ye)
- Fix a netns reference imbalance in the BPF conntrack kfuncs
(Chengfeng Ye)
- Fix bpf_get_fsverity_digest() dynptr assumptions and silent
digest truncation (Eric Biggers)
- Fix bpf_tcp_{gen,check}_syncookie to check sk_state before
sk_protocol to make sure it is a full socket (Luxiao Xu)
- Fix rqspinlock to reset the tail when preserving the queue
on deadlock (Kumar Kartikeya Dwivedi)
* tag 'bpf-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf:
rqspinlock: Reset tail when preserving queue on deadlock
bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie
fsverity: Fix silent truncation in bpf_get_fsverity_digest()
fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions
bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()
bpf: Fix netns reference imbalance in conntrack kfuncs
bpf, sockmap: Fix sk_redir use-after-free in send verdict
selftests/bpf: Cover commuted pointer state propagation
bpf: Propagate untrusted pointer state in commuted arithmetic
bpf: Preserve pointer state for commuted arithmetic
bpf: Simplify sanitize_err() signature
|
||
|
|
0150da6be1 |
s390:
- fix a lot of small bugs and races
x86:
- fix missing locking related to KVM_CAP_MOVE_ENC_CONTEXT_FROM
- warn on creating a new page table that is the child of an invalid one,
and limit damage before it's too late
- disable use of INVLPGA when NPT is enabled, because it doesn't seem
to flush TLBs correctly
-----BEGIN PGP SIGNATURE-----
iQFIBAABCgAyFiEE8TM4V0tmI4mGbHaCv/vSX3jHroMFAmp14g0UHHBib256aW5p
QHJlZGhhdC5jb20ACgkQv/vSX3jHroPzrAf+KGSkR+qBbqgsSy0I86kw6VvX6h8i
TySes/l0JaNbVQDDt3vYzw/ZXhrm6dRA58i1mwjIVLIY3pflXzUrwqqXjLwvcGNf
1eX0jOZOg68fXPW22okR+7mNJdHSiRiX3Ozw20TrS5+33xN3dKa1xsTtNFRN99f6
h8mtQIP5L9dYn6y9lI27y51lkx3Ojd8SWAUJyXn8d3OA28mBcIShpq6BJsroHT34
HzibCnNAodFMGDsUJr93mpJisUV4EsWPKO2hzMm5FUUkV/JBD3GnqwF550Kwpc8a
ojuaHCEAnZXLoDuOTBiT8iQBa1fDUHizERlTkHD91s0ktwqf+e3p0azjMw==
=734T
-----END PGP SIGNATURE-----
Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm
Pull vkm fixes from Paolo Bonzini:
"s390:
- fix a lot of small bugs and races
x86:
- fix missing locking related to KVM_CAP_MOVE_ENC_CONTEXT_FROM
- warn on creating a new page table that is the child of an invalid
one, and limit damage before it's too late
- disable use of INVLPGA when NPT is enabled, because it doesn't seem
to flush TLBs correctly"
* tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm: (26 commits)
KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page
KVM: SVM: Serialize accesses to the owner and mirror list with separate lock
KVM: SVM: make svm_flush_tlb_gva do a full asid flush if NPT enabled
KVM: s390: Fix cleanup in kvm_s390_pv_create_cpu()
KVM: s390: Fix ordering when adding to SCA
KVM: s390: Return -EINTR if a signal is pending while faulting-in
KVM: s390: Free the mmu cache when kvm_arch_vcpu_create() fails
KVM: s390: ucontrol: Add missing locking around gmap_remove_child()
KVM: s390: cmma: Fix dirty tracking when removing memslot
KVM: s390: Fix race in __do_essa()
KVM: s390: Fix leaking of PGM_ADDRESSING to userspace
KVM: s390: ucontrol: Fix sca_clear_ext_call()
KVM: s390: Fix overclearing ESCA in case of error
KVM: s390: Fix kvm_s390_vcpu_unsetup_cmma()
KVM: s390: Do not free SCA if it was not allocated
KVM: s390: Fix unlikely NULL gmap dereference
s390/vfio_ccw: Implement a crw lock
s390/vfio_ccw: Selectively expand io_mutex
s390/vfio_ccw: Move cp cleanup out of not operational
s390/vfio_ccw: Cancel existing workqueues
...
|
||
|
|
7cbe91a4be |
Thermal control fixes for 7.2-rc7
Revert three thermal core updates, two recent ones and one older. The recent ones attempted to fix a design issue in the thermal core and simplify code on top of that, but they made changes visible to user space and made it unhappy. The older one is a misguided code cleanup that introduced a (potentially nasty) bug. -----BEGIN PGP SIGNATURE----- iQFGBAABCAAwFiEEcM8Aw/RY0dgsiRUR7l+9nS/U47UFAmp1yVQSHHJqd0Byand5 c29ja2kubmV0AAoJEO5fvZ0v1OO1gm8H/j6zXC1hbZbmLjQd9HSiNUgpuDOPMz9p 5oeacpOiu60PUA8a0IEEdQGHlihg4eStP8h9cSoYccKCl9MtIFHZQluPKF1Dh6NM 18749AZ0Ed2ZRZbar6ud+b88suUh9bTTWazjcwYoqr7vLtPO/1jFGDx4gED2LlEg c8CNeYzqO4KoG86qSe6gRtus6IigH0I95eFY/hlfzJrhU3v7GlGrWGuHKaNOZ85e Sv34E2UApV3s0VpU/zHpiFXJIP9eVYER8cHtUayZYOXc6wDf2jFfwYJixxn/T15F gUKpPUy0cOirobx1ZlQn5l5lVgtBuUj201XENcR1dfMINhdvuL6S1ik= =/1Jt -----END PGP SIGNATURE----- Merge tag 'thermal-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm Pull thermal control fixes from Rafael Wysocki: "Revert three thermal core updates, two recent ones and one older. The recent ones attempted to fix a design issue in the thermal core and simplify code on top of that, but they made changes visible to user space and made it unhappy. The older one is a misguided code cleanup that introduced a (potentially nasty) bug" * tag 'thermal-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm: Revert "thermal/drivers/hwmon: Cleanup coding style a bit" Revert "thermal: hwmon: Register a hwmon device for each thermal zone" Revert "thermal: hwmon: Use extra_groups for adding temperature attributes" |
||
|
|
7e73882ecf |
sound fixes for 7.2-rc7
A collection of small fixes since the last pull request.
More than few, but an enough-manageable amount at this time.
USB-audio:
- UAF, OOB and such hardening fixes for USB-audio, usx2y and us144mkii
- Mixer regression fixes for Logitech PRO X 2 LIGHTSPEED headset and
M-Audio Fast Track Ultra
HD-audio:
- Fix for an ACPI reference leak in TAS2781 HDA side-codec
ASoC:
- Fixes the default tables for Cirrus Logic codecs
- Fixes for invalid enum accesses for Qualcomm LPASS
- Error handling and robustness fixes for Intel SOF & Soundwire
- DMI quirks for a few AMD devices
-----BEGIN PGP SIGNATURE-----
iQJCBAABCAAsFiEEIXTw5fNLNI7mMiVaLtJE4w1nLE8FAmp1mRAOHHRpd2FpQHN1
c2UuZGUACgkQLtJE4w1nLE+8iw/8DBwUZT7mnytHB+QHF/STnt/kIZN1Y8LSRXMy
JegVVYVksW1b9nF/JAD02vl0CMJ/ZE3qQs1deMbbbF982tfATu1B0XzLO2AYXE5F
50KLlmkyHfybHVKlYvwGRrKEUbYsBOcoeCaFPFS3gDQfkXepBMK4yE9db+qpZvcS
ZLyv9Ff3rcsCfSTNyxCJdrfiespDC6H1Trj0CeGoyiHyNr5tKhQ6JByLjTLNjweF
Mi2UNa+cy5zQV4kWiv+RvQ6CWAJyETF7oZQvHKYfybkqr4GiyDjSVl5usEGOUNdh
vKuEIbzAprEmzQ/pjX27+ig53uiwDAMDGrRDwW3khqrm7XIDXEbL5iQNbBz5HRU5
GjWCbbJGoqDCdDg9dN3nEACH2sX6kDYt8I5RKQo4l/+3tMISNrFujdCXrYQbx6We
MLouuzjLbr+gyr2EVsKaNuZqVS6Li9OEwRloP7TJjI81UAaxfosMv+tmmB8d7P2v
xjuBDObs2JgROPWy0lVI62/1cL/KLLMHM8z/+VlYxMtYJ13ipySeXCRtaHSMX46c
76Vtgx42O3YOHTkNBg5zpRFTX7NnK0B7u8JWsYqb5HlLnvr1TeUWevq3UKAc/5mX
suj747xYrYcI6nXFN9CTnfz/V3RjQqWKooBgjbKdTe2QHkynQd2GI6Kb6dYIJ/R8
MFzD4EM=
=r8TD
-----END PGP SIGNATURE-----
Merge tag 'sound-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound
Pull sound fixes from Takashi Iwai:
"A collection of small fixes since the last pull request. More than
few, but an enough-manageable amount at this time.
USB-audio:
- UAF, OOB and such hardening fixes for USB-audio, usx2y and
us144mkii
- Mixer regression fixes for Logitech PRO X 2 LIGHTSPEED headset and
M-Audio Fast Track Ultra
HD-audio:
- Fix for an ACPI reference leak in TAS2781 HDA side-codec
ASoC:
- Fixes the default tables for Cirrus Logic codecs
- Fixes for invalid enum accesses for Qualcomm LPASS
- Error handling and robustness fixes for Intel SOF & Soundwire
- DMI quirks for a few AMD devices"
* tag 'sound-7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound: (22 commits)
ALSA: usb-audio: Fix sticky mixer regressions on M-Audio Fast Track Ultra
ASoC: cs4265: sort the register default table
ASoC: cs35l45: sort the register default table
ASoC: cs35l41: sort the register default table
ASoC: amd: yc: Add DMI quirk for MSI Raider A18 HX A7VHG
ASoC: amd: yc: Add DMI quirk for Xiaomi RedmiBook 16 2025
ALSA: usx2y: bound the hwdep mmap fault offset
ALSA: usb-audio: fix OOB write on Type II inbound URBs
ALSA: us144mkii: re-anchor capture URBs on resubmission
ALSA: FCP: fix OOB write in fcp_meter_ctl_get()
MAINTAINERS: add SpacemiT K1/K3 I2S entry
ASoC: rt5645: Make the Kconfig symbol user selectable
ALSA: usb-audio: Add QUIRK_FLAG_MIXER_GET_CUR_BROKEN for Logitech PRO X 2 LIGHTSPEED
ALSA: hda/tas2781: fix ACPI reference handling
ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses
ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses
ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout
ASoC: amd: yc: Add DMI quirk for HP Victus Laptop 16-e1xxx
ASoC/soundwire: Intel: reset the PCMSyCM registers in hda_sdw_bpt_close
ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked()
...
|
||
|
|
5fb210754e |
amd-drm-fixes-7.2-2026-08-06:
amdgpu: - JPEG queue reset fixes - GC 12 fix - GMC 12.1 fixes - Lockdep false positive fix - Userq fix - Bounds checking fixes - Devcoredump fixes - DCN 2.0.1 fix - Aperture mapping fix - DC avmute fix - DC self refresh fix radeon: - Performance regression fix -----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQQgO5Idg2tXNTSZAr293/aFa7yZ2AUCanT4qwAKCRC93/aFa7yZ 2MZ3AP44wgJjZEzph2TU9kggsQbh8voajhVEI4p29zGHfCorvwEAo2l3CmnnnZ6t tr8RD0YnJ9HyVk19RsEp+rr8JIx3Qwo= =mXZL -----END PGP SIGNATURE----- Merge tag 'amd-drm-fixes-7.2-2026-08-06' of https://gitlab.freedesktop.org/agd5f/linux into drm-fixes amd-drm-fixes-7.2-2026-08-06: amdgpu: - JPEG queue reset fixes - GC 12 fix - GMC 12.1 fixes - Lockdep false positive fix - Userq fix - Bounds checking fixes - Devcoredump fixes - DCN 2.0.1 fix - Aperture mapping fix - DC avmute fix - DC self refresh fix radeon: - Performance regression fix Signed-off-by: Dave Airlie <airlied@redhat.com> From: Alex Deucher <alexander.deucher@amd.com> Link: https://patch.msgid.link/20260806211538.994087-1-alexander.deucher@amd.com |
||
|
|
0f7f5029eb |
drm-misc-fixes for v7.2-rc6:
- panthor & shmem helpers: Check vma range inside pmd fault handler. - panthor: handle empty firmware sections correctly. - bridge/ps8640: Forward aux transfer errors. - amdxdna: Improve error handling in amdxdna_insert_pages. -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEuXvWqAysSYEJGuVH/lWMcqZwE8MFAmp030AACgkQ/lWMcqZw E8PCIA/+MSlxJ9hi2tPLylYzUooCJmsZ2JdDdLy2mwbgcVnXOZ3qAGEKOYYhAjKh L6KmYxSslO9TzqE7dkKcqVuYgJzmWwxYLoQYvRJODnAxjFZpAhhU7JCXJjmDMV4K cd9BA8IYtFrgOw+8dM+khZHVvf+f45ChRNkPhVzbsXMLPdW0CnWJQK9cqNozWane BwEeGcw1tH2Y3+X2MBFEIEj/gdBpn2nDXCTP9VPqF1k7wRaSIdSrJ9qOOYzGm34F WSuOtZ/BhAmPprDamZMSFshKpP83be+2Crrtd0OD6ayCY5h7ULl91KAV7DlTOn5m IpPdU4Oc2ku7XfB6SOyghADI7QFjt1+VGnFQGXXZhdTdiM1sbFnLtCYnCwL8iof1 z/Fzy7l4kOvl2WzoV77BwQHD4+o5aACExDXxkzyBm0R5dL2BQTRf1n74hPWmIiJ4 ZHmauyLaXMuZPdSLTTWFMWFE5q9S3wnBHP+EYPnPud3cIr281zNFX+iuuZaGHSgS 6xCOs5I2HVZve1sW1AH9Ftzie+egpRYHy9ds8ZuU9yE5GbUbYplHm6BYZ1rHzGtx kNjOrEtvmxR8UWpIKbT03U5Tnc3z+2+Trr5rN4doOQzUE8NeVWUyio5WPqbqhLF7 D3QhX3Wo6zIjgtvRDQHVt6zBNX4GBSPbqWM77D4+UhJqUgwy+L0= =ORsJ -----END PGP SIGNATURE----- Merge tag 'drm-misc-fixes-2026-08-06' of https://gitlab.freedesktop.org/drm/misc/kernel into drm-fixes drm-misc-fixes for v7.2-rc6: - panthor & shmem helpers: Check vma range inside pmd fault handler. - panthor: handle empty firmware sections correctly. - bridge/ps8640: Forward aux transfer errors. - amdxdna: Improve error handling in amdxdna_insert_pages. Signed-off-by: Dave Airlie <airlied@redhat.com> From: Maarten Lankhorst <maarten.lankhorst@linux.intel.com> Link: https://patch.msgid.link/415659f6-5199-4078-8319-22d7529e777d@linux.intel.com |
||
|
|
a8934c2c6d |
ALSA: usb-audio: Fix sticky mixer regressions on M-Audio Fast Track Ultra
The recent fix for sticky mixer volumes caused regressions of M-audio
Fast Track Ultra device, where the mixer state is kept to the default
value.
Add the quirk entries to tolerate the broken mixer behavior. As the
device is known to work in the implicit feedback mode, explicitly
enable the implicit feedback mode, too.
Since there are two FTU models that are almost identical, both entries
are added in this patch (0763:2080 and 0763:2081).
Fixes:
|
||
|
|
5ec42d5765 |
KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page
Explicitly clear role.invalid when deriving a child shadow page's role from
its parent to harden against bugs elsewhere in KVM, as violating KVM's
invariant that invalid pages are NOT on the list of active MMU pages leads
to use-after-free due to __kvm_mmu_prepare_zap_page() using list_add()
instead of list_move() when processing an invalid shadow page, i.e. makes a
bad situation far worse.
Yell loudly if the parent is invalid, as it means KVM has missed a validity
check, i.e. KVM is attempting to map memory using an invalid/obsolete root,
but continue on as the child is otherwise still a valid shadow page.
==================================================================
BUG: KASAN: slab-use-after-free in __kvm_mmu_get_shadow_page+0x1817/0x1860 [kvm]
Write of size 8 at addr ff11000153dd1368 by task repro/853
CPU: 1 UID: 1000 PID: 853 Comm: repro Not tainted 7.2.0-rc2-3aec122bdcaf-next-vm #5 PREEMPT
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015
Call Trace:
<TASK>
dump_stack_lvl+0x4b/0x70
print_report+0x153/0x49c
kasan_report+0xbc/0xf0
__kvm_mmu_get_shadow_page+0x1817/0x1860 [kvm]
mmu_alloc_root+0x141/0x320 [kvm]
kvm_mmu_load+0x612/0x20f0 [kvm]
kvm_arch_vcpu_ioctl_run+0x3dd5/0x6150 [kvm]
kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm]
__x64_sys_ioctl+0x131/0x1b0
do_syscall_64+0x67/0x5f0
entry_SYSCALL_64_after_hwframe+0x4b/0x53
</TASK>
Allocated by task 853:
kasan_save_stack+0x20/0x40
kasan_save_track+0x14/0x30
__kasan_slab_alloc+0x5f/0x70
kmem_cache_alloc_noprof+0xfe/0x2e0
__kvm_mmu_topup_memory_cache+0x135/0x530 [kvm]
paging64_page_fault+0x318/0x1e30 [kvm]
kvm_mmu_do_page_fault+0x21d/0x630 [kvm]
kvm_mmu_page_fault+0x18c/0x17b0 [kvm]
kvm_arch_vcpu_ioctl_run+0x1f35/0x6150 [kvm]
kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm]
__x64_sys_ioctl+0x131/0x1b0
do_syscall_64+0x67/0x5f0
entry_SYSCALL_64_after_hwframe+0x4b/0x53
Freed by task 853:
kasan_save_stack+0x20/0x40
kasan_save_track+0x14/0x30
kasan_save_free_info+0x3b/0x60
__kasan_slab_free+0x43/0x70
kmem_cache_free+0xe2/0x400
kvm_mmu_commit_zap_page.part.0+0x1e2/0x310 [kvm]
kvm_mmu_free_roots+0x283/0x560 [kvm]
kvm_arch_vcpu_ioctl_run+0x33c8/0x6150 [kvm]
kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm]
__x64_sys_ioctl+0x131/0x1b0
do_syscall_64+0x67/0x5f0
entry_SYSCALL_64_after_hwframe+0x4b/0x53
Reported-by: Hyunwoo Kim <imv4bel@gmail.com>
Fixes:
|
||
|
|
c6c4234928 |
hwmon: (corsair-psu) Fix linear11 calculation
In corsairpsu_linear11_to_int(), the mantissa is extracted using bitwise
operations and cast to s16 before being shifted left:
static int corsairpsu_linear11_to_int(const u16 val, const int scale)
{
...
const int mant = (((s16)(val & 0x7ff)) << 5) >> 5;
...
}
Due to C integer promotion rules, the masked value (which is always
positive) is promoted to a 32-bit integer before the left shift. As a
result, the sign bit is never extended to bit 31 of the promoted integer.
When the device hardware reports a negative temperature in Linear11 format
(such as an ambient temperature probe reporting sub-zero), the negative
mantissa is parsed incorrectly as a massive positive value. For example,
-1 becomes 2047, which scales to 2047 degrees Celsius.
Fix the problem by type casting the result of the left shift operation
to s16.
Another problem is left-shifting of negative values. In C, the result of
left-shifting negative values is undefined. Use a multiplication instead
to avoid the problem.
Also use a local s64 variable to store temporary results, change
the return value type from int to long, and clamp the final value
to LONG_MIN and LONG_MAX to avoid under- and overflow issues while
retaining as much information as possible.
Reported-by: Sashiko <sashiko-bot@kernel.org>
Cc: Wilken Gottwalt <wilken.gottwalt@posteo.net>
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Tested-by: Wilken Gottwalt <wilken.gottwalt@posteo.net>
Link: https://lore.kernel.org/r/20260804034811.2385506-1-linux@roeck-us.net
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
|
||
|
|
2da6050809 |
hwmon: (corsair-psu) serialize debugfs access against hwmon
corsairpsu_request() sends a rail select command and then the actual read as two separate transfers, both going through the single shared cmd_buffer and wait_completion in corsairpsu_usb_cmd(). The hwmon core serializes its own callers, but the debugfs files call corsairpsu_get_value() directly and never take that lock, so a debugfs read can land between another reader's rail select and its value read. The result is a value from the wrong rail reported as the right one, because corsairpsu_usb_cmd() only checks the command echo and both transfers echo the command it expects. It can also make a caller consume the reply meant for the other one, since raw_event() writes into the shared buffer and completes whoever happens to be waiting. Locking was dropped in commit |