lp:~ubuntu-kernel/ubuntu/+source/linux/+git/noble

Get this repository:
git clone https://git.launchpad.net/~ubuntu-kernel/ubuntu/+source/linux/+git/noble
Members of Ubuntu Kernel Repositories can upload to this repository. Log in for directions.

Branches

Name Last Modified Last Commit
lowlatency-next 2026-09-30 18:23:41 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-147.147.1

Author: Manuel Diewald
Author Date: 2026-09-30 18:23:41 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-147.147.1

Signed-off-by: Manuel Diewald <manuel.diewald@canonical.com>

hwe-7.0-next 2026-09-28 09:23:50 UTC
UBUNTU: Ubuntu-hwe-7.0-7.0.0-39.39~24.04.1

Author: Kuba Pawlak
Author Date: 2026-09-28 09:23:50 UTC

UBUNTU: Ubuntu-hwe-7.0-7.0.0-39.39~24.04.1

Signed-off-by: Kuba Pawlak <kuba.pawlak@canonical.com>

master-next 2026-09-24 09:03:24 UTC
UBUNTU: Ubuntu-6.8.0-147.147

Author: Stefan Bader
Author Date: 2026-09-24 09:03:24 UTC

UBUNTU: Ubuntu-6.8.0-147.147

Signed-off-by: Stefan Bader <stefan.bader@canonical.com>

master-prep 2026-09-24 09:03:24 UTC
UBUNTU: Ubuntu-6.8.0-147.147

Author: Stefan Bader
Author Date: 2026-09-24 09:03:24 UTC

UBUNTU: Ubuntu-6.8.0-147.147

Signed-off-by: Stefan Bader <stefan.bader@canonical.com>

master-next--2026.09.28-1 2026-09-23 14:24:20 UTC
UBUNTU: Upstream stable to v6.6.148, v6.12.101

Author: Necromancer
Author Date: 2026-09-12 21:38:22 UTC

UBUNTU: Upstream stable to v6.6.148, v6.12.101

BugLink: https://bugs.launchpad.net/bugs/2168026

Signed-off-by: Necromancer <kernel-team@lists.ubuntu.com>
Signed-off-by: Manuel Diewald <manuel.diewald@canonical.com>
Signed-off-by: Stefan Bader <stefan.bader@canonical.com>

master-next--s2026.08.03-1 2026-08-28 17:39:14 UTC
UBUNTU: [Config] Enable CONFIG_ARM64_ERRATUM_4118414

Author: Bethany Jamison
Author Date: 2026-08-19 21:05:07 UTC

UBUNTU: [Config] Enable CONFIG_ARM64_ERRATUM_4118414

Signed-off-by: Bethany Jamison <bethany.jamison@canonical.com>
Signed-off-by: Edoardo Canepa <edoardo.canepa@canonical.com>
CVE-2025-10263
CVE-2026-53354
Signed-off-by: Manuel Diewald <manuel.diewald@canonical.com>

hwe-6.17-next 2026-08-01 02:03:31 UTC
UBUNTU: Ubuntu-hwe-6.17-6.17.0-44.44

Author: Edoardo Canepa
Author Date: 2026-08-01 02:03:31 UTC

UBUNTU: Ubuntu-hwe-6.17-6.17.0-44.44

Signed-off-by: Edoardo Canepa <edoardo.canepa@canonical.com>

master-next--s2026.07.06-1 2026-07-31 18:10:38 UTC
net: openvswitch: reject oversized nested action attrs

Author: Asim Viladi Oglu Manizada
Author Date: 2026-07-28 20:55:31 UTC

net: openvswitch: reject oversized nested action attrs

commit 3f1f755366687d051174739fb99f7d560202f60b upstream.

Open vSwitch stores generated flow actions as nlattrs, whose nla_len
field is u16. Commit a1e64addf3ff ("net: openvswitch: remove
misbehaving actions length check") allowed the total sw_flow_actions
stream to grow beyond 64 KiB, which is valid, but also removed the last
guard preventing a generated nested action attribute from exceeding
U16_MAX.

An oversized generated container can thus be closed with a truncated
nla_len. A later dump or teardown then walks a structurally different
stream than the one that was validated. In particular, an oversized
nested CLONE/CT action may cause subsequent bytes in the generated
stream to be interpreted as independent actions.

Keep the larger total-action-stream behavior, but make nested action
close reject generated containers that do not fit in nla_len, and return
the error through all callers. For recursive SAMPLE, CLONE, DEC_TTL, and
CHECK_PKT_LEN builders, trim resource-owning action-list tails in reverse
construction order before discarding failed wrappers, so resources copied
into the rejected tails are released before the wrappers are removed.

Most failed outer wrappers are discarded by truncating actions_len after
child resources have been released. CHECK_PKT_LEN also trims its parent
after branch resources are gone. SET/TUNNEL close failures unwind their
known tun_dst ownership directly, and SET_TO_MASKED has no external
ownership and truncates on close failure.

Fixes: a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check")
Cc: stable@vger.kernel.org
Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix
Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
Reviewed-by: Eelco Chaudron <echaudro@redhat.com>
Reviewed-by: Aaron Conole <aconole@redhat.com>
Reviewed-by: Ilya Maximets <i.maximets@ovn.org>
Link: https://patch.msgid.link/20260706094336.38639-1-manizada@pm.me
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
CVE-2026-64531
(cherry picked from commit d573250d228401f707f4dbc09d11227a6215ee5f linux-6.6.y)
Signed-off-by: Cengiz Can <cengiz.can@canonical.com>
Acked-by: Tim Whisonant <tim.whisonant@canonical.com>
Acked-by: Benjamin Wheeler <benjamin.wheeler@canonical.com>
Signed-off-by: Edoardo Canepa <edoardo.canepa@canonical.com>

hwe-6.17-next--s2026.07.06-1 2026-07-31 17:43:06 UTC
net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()

Author: Zhan Jun
Author Date: 2026-07-16 14:35:46 UTC

net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()

syzbot reported a KASAN slab-use-after-free read in rtl8150_start_xmit()
when accessing skb->len for tx statistics after usb_submit_urb() has
been called:

  BUG: KASAN: slab-use-after-free in rtl8150_start_xmit+0x71f/0x760
    drivers/net/usb/rtl8150.c:712
  Read of size 4 at addr ffff88810eb7a930 by task kworker/0:4/5226

The URB completion handler write_bulk_callback() frees the skb via
dev_kfree_skb_irq(dev->tx_skb). The URB may complete on another CPU
in softirq context before usb_submit_urb() returns in the submitter,
so by the time the submitter reads skb->len the skb has already been
queued to the per-CPU completion_queue and freed by net_tx_action():

  CPU A (xmit) CPU B (USB completion softirq)
  ------------ ------------------------------
  dev->tx_skb = skb;
  usb_submit_urb() --+
                          |-------> write_bulk_callback()
                          | dev_kfree_skb_irq(dev->tx_skb)
                          | net_tx_action()
                          | napi_skb_cache_put() <-- free
  netdev->stats.tx_bytes |
    += skb->len; <-- UAF read

Fix it by caching skb->len before submitting the URB and using the
cached value when updating the tx_bytes counter.

The pre-existing tx_bytes semantics are preserved: the counter tracks
the original frame length (skb->len), not the ETH_ZLEN/USB-alignment
padded "count" value that is handed to the device. Changing that
would be a user-visible accounting change and is out of scope for
this UAF fix.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: syzbot+3f46c095ac0ca048cb71@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/all/69e69ee7.050a0220.24bfd3.002b.GAE@google.com/
Closes: https://syzkaller.appspot.com/bug?extid=3f46c095ac0ca048cb71
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
Signed-off-by: Zhan Jun <zhanjun@uniontech.com>
Link: https://patch.msgid.link/809895186B866C10+20260423004913.136655-1-zhangdandan@uniontech.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 23f0e34c64acba15cad4d23e50f41f533da195fa)
CVE-2026-52982
Assisted-by: kybele:claude-opus-4.8
Signed-off-by: Cengiz Can <cengiz.can@canonical.com>
Acked-by: Edoardo Canepa <edoardo.canepa@canonical.com>
Acked-by: Benjamin Wheeler <benjamin.wheeler@canonical.com>
Signed-off-by: Edoardo Canepa <edoardo.canepa@canonical.com>

hwe-6.17-next--s2026.06.22-1 2026-07-23 16:39:18 UTC
UBUNTU: Ubuntu-hwe-6.17-6.17.0-42.42

Author: Edoardo Canepa
Author Date: 2026-07-23 16:39:18 UTC

UBUNTU: Ubuntu-hwe-6.17-6.17.0-42.42

Signed-off-by: Edoardo Canepa <edoardo.canepa@canonical.com>

hwe-7.0-next--s2026.06.22-1--auto 2026-07-21 13:11:23 UTC
UBUNTU: Ubuntu-hwe-7.0-7.0.0-29.29~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2026-07-21 13:11:22 UTC

UBUNTU: Ubuntu-hwe-7.0-7.0.0-29.29~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2026.06.22-1--auto 2026-07-21 12:17:57 UTC
UBUNTU: Ubuntu-6.8.0-137.137

Author: Ubuntu Kernel Bot
Author Date: 2026-07-21 12:17:57 UTC

UBUNTU: Ubuntu-6.8.0-137.137

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2026.06.22-1 2026-07-17 13:13:00 UTC
sctp: fix uninit-value in __sctp_rcv_asconf_lookup()

Author: Michael Bommarito
Author Date: 2026-07-17 11:29:09 UTC

sctp: fix uninit-value in __sctp_rcv_asconf_lookup()

__sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF
chunk can hold the ADDIP header and a parameter header, then calls
af->from_addr_param(), which reads the full address (16 bytes for IPv6)
trusting the parameter's declared length.

An unauthenticated peer can send a truncated trailing ASCONF chunk that
declares an IPv6 address parameter but stops after the 4-byte parameter
header; reached from the no-association lookup path, from_addr_param() then
reads uninitialized bytes past the parameter.

Impact: an unauthenticated SCTP peer makes the receive path read up to 16
bytes of uninitialized memory past a truncated ASCONF address parameter.

The sibling __sctp_rcv_init_lookup() bounds parameters with
sctp_walk_params(); this path open-codes the fetch and omits the bound.
Verify the whole address parameter lies within the chunk before
from_addr_param() reads it, the same class of fix as commit 51e5ad549c43
("net: sctp: fix KMSAN uninit-value in sctp_inq_pop").

Fixes: df2185771439 ("[SCTP]: Update association lookup to look at ASCONF chunks as well")
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260608122234.459098-1-michael.bommarito@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit f8373d7090b745728de66308deeecc67e8d319ce)
CVE-2026-53225
Assisted-by: kybele:claude-opus-4.8
Signed-off-by: Cengiz Can <cengiz.can@canonical.com>
Acked-by: Manuel Diewald <manuel.diewald@canonical.com>
Acked-by: Alessio Faina <alessio.faina@canonical.com>
Signed-off-by: Manuel Diewald <manuel.diewald@canonical.com>

master-next--s2026.05.18-1 2026-06-19 14:33:25 UTC
netfilter: nft_inner: Fix IPv6 inner_thoff desync

Author: Yizhou Zhao
Author Date: 2026-06-18 02:46:12 UTC

netfilter: nft_inner: Fix IPv6 inner_thoff desync

In nft_inner_parse_l2l3(), when processing inner IPv6 packets,
ipv6_find_hdr() correctly computes the transport header offset
traversing all extension headers, but the result is immediately
overwritten with nhoff + sizeof(_ip6h) (40 bytes), which only
accounts for the IPv6 base header. This creates a desync between
inner_thoff (wrong — points to extension header start) and l4proto
(correct — e.g., IPPROTO_TCP), enabling transport header forgery
and potential firewall bypass. This issue affects stable versions
from Linux 6.2.

For comparison, the normal (non-inner) IPv6 path correctly
preserves ipv6_find_hdr()'s result. Removing the incorrect overwrite
ensures that ipv6_find_hdr()'s calculated transport header offset is
preserved, thereby fixing the desynchronization.

Fixes: 3a07327d10a0 ("netfilter: nft_inner: support for inner tunnel header matching")
Cc: stable@vger.kernel.org
Reported-by: Yizhou Zhao <zhaoyz24@mails.tsinghua.edu.cn>
Reported-by: Yuxiang Yang <yangyx22@mails.tsinghua.edu.cn>
Reported-by: Xuewei Feng <fengxw06@126.com>
Reported-by: Qi Li <qli01@tsinghua.edu.cn>
Reported-by: Ke Xu <xuke@tsinghua.edu.cn>
Assisted-by: GLM:5.1 Z.ai
Signed-off-by: Yizhou Zhao <zhaoyz24@mails.tsinghua.edu.cn>
Reviewed-by: Fernando Fernandez Mancera <fmancera@suse.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
(cherry picked from commit b6a91f68ebfed9c38e0e9150f58a9b85da07181c)
CVE-2026-46244
Signed-off-by: Cengiz Can <cengiz.can@canonical.com>
Acked-by: Ross Porter via kernel-team <kernel-team@lists.ubuntu.com>
Acked-by: Alessio Faina via kernel-team <kernel-team@lists.ubuntu.com>
Signed-off-by: Manuel Diewald <manuel.diewald@canonical.com>

hwe-6.17-next--s2026.05.11-1--auto 2026-05-23 00:38:36 UTC
UBUNTU: Ubuntu-hwe-6.17-6.17.0-31.31~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2026-05-23 00:38:35 UTC

UBUNTU: Ubuntu-hwe-6.17-6.17.0-31.31~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2026.05.11-1 2026-05-22 13:22:23 UTC
net: skbuff: propagate shared-frag marker through frag-transfer helpers

Author: Hyunwoo Kim
Author Date: 2026-05-22 11:44:58 UTC

net: skbuff: propagate shared-frag marker through frag-transfer helpers

Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail
to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when
moving frags from source to destination. __pskb_copy_fclone() defers
the rest of the shinfo metadata to skb_copy_header() after copying
frag descriptors, but that helper only carries over gso_{size,segs,
type} and never touches skb_shinfo()->flags; skb_shift() moves frag
descriptors directly and leaves flags untouched. As a result, the
destination skb keeps a reference to the same externally-owned or
page-cache-backed pages while reporting skb_has_shared_frag() as
false.

The mismatch is harmful in any in-place writer that uses
skb_has_shared_frag() to decide whether shared pages must be detoured
through skb_cow_data(). ESP input is one such writer (esp4.c,
esp6.c), and a single nft 'dup to <local>' rule -- or any other
nf_dup_ipv4() / xt_TEE caller -- is enough to land a pskb_copy()'d
skb in esp_input() with the marker stripped, letting an unprivileged
user write into the page cache of a root-owned read-only file via
authencesn-ESN stray writes.

Set SKBFL_SHARED_FRAG on the destination whenever frag descriptors
were actually moved from the source. skb_copy() and skb_copy_expand()
share skb_copy_header() too but linearize all paged data into freshly
allocated head storage and emerge with nr_frags == 0, so
skb_has_shared_frag() returns false on its own; they need no change.

The same omission exists in skb_gro_receive() and skb_gro_receive_list().
The former moves the incoming skb's frag descriptors into the
accumulator's last sub-skb via two paths (a direct frag-move loop and
the head_frag + memcpy path); the latter chains the incoming skb whole
onto p's frag_list. Downstream skb_segment() reads only
skb_shinfo(p)->flags, and skb_segment_list() reuses each sub-skb's
shinfo as the nskb -- both p and lp must carry the marker.

The same omission also exists in tcp_clone_payload(), which builds an
MTU probe skb by moving frag descriptors from skbs on sk_write_queue
into a freshly allocated nskb. The helper falls into the same family
and warrants the same fix for consistency; no TCP TX-side in-place
writer is currently known to reach a user page through this gap, but
a future consumer depending on the marker would regress silently.

The same omission exists in skb_segment(): the per-iteration flag
merge takes only head_skb's flag, and the inner switch that rebinds
frag_skb to list_skb on head_skb-frags exhaustion does not fold the
new frag_skb's flag into nskb. Fold frag_skb's flag at both sites
so segments drawing frags from frag_list members carry the marker.

Fixes: cef401de7be8 ("net: fix possible wrong checksum generation")
Fixes: f4c50a4034e6 ("xfrm: esp: avoid in-place decrypt on shared skb frags")
Suggested-by: Sabrina Dubroca <sd@queasysnail.net>
Suggested-by: Sultan Alsawaf <sultan@kerneltoast.com>
Suggested-by: Ben Hutchings <ben@decadent.org.uk>
Suggested-by: Lin Ma <malin89@huawei.com>
Suggested-by: Jingguo Tan <tanjingguo@huawei.com>
Suggested-by: Aaron Esau <aaron1esau@gmail.com>
Cc: stable@vger.kernel.org
Signed-off-by: Hyunwoo Kim <imv4bel@gmail.com>
Tested-by: Rajat Gupta <rajat.gupta@oss.qualcomm.com>
Link: https://patch.msgid.link/ageeJfJHwgzmKXbh@v4bel
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
(backported from commit 48f6a5356a33dd78e7144ae1faef95ffc990aae0 netdev/net)
[cengizcan: skb_gro_receive_list() lives in net/ipv4/udp_offload.c on this tree, not in net/core/gro.c; applied that one hunk to udp_offload.c. All other hunks applied verbatim to net/core/skbuff.c (3 hunks: __pskb_copy_fclone, skb_shift, skb_segment), net/core/gro.c (skb_gro_receive 2 hunks), and net/ipv4/tcp_output.c (tcp_clone_payload).]
CVE-2026-46300
Signed-off-by: Cengiz Can <cengiz.can@canonical.com>
Acked-by: Manuel Diewald <manuel.diewald@canonical.com>
Acked-by: Alessio Faina <alessio.faina@canonical.com>
Signed-off-by: Manuel Diewald <manuel.diewald@canonical.com>

master-next--s2026.05.11-1--auto 2026-05-21 18:33:53 UTC
UBUNTU: Ubuntu-6.8.0-118.118

Author: Ubuntu Kernel Bot
Author Date: 2026-05-21 18:33:52 UTC

UBUNTU: Ubuntu-6.8.0-118.118

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--2026.05.18-2--auto 2026-05-13 09:40:30 UTC
UBUNTU: Ubuntu-6.8.0-118.118

Author: Ubuntu Kernel Bot
Author Date: 2026-05-13 09:40:30 UTC

UBUNTU: Ubuntu-6.8.0-118.118

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2026.04.13-1 2026-05-05 12:37:49 UTC
net: bonding: fix use-after-free in bond_xmit_broadcast()

Author: Xiang Mei
Author Date: 2026-04-23 20:48:37 UTC

net: bonding: fix use-after-free in bond_xmit_broadcast()

bond_xmit_broadcast() reuses the original skb for the last slave
(determined by bond_is_last_slave()) and clones it for others.
Concurrent slave enslave/release can mutate the slave list during
RCU-protected iteration, changing which slave is "last" mid-loop.
This causes the original skb to be double-consumed (double-freed).

Replace the racy bond_is_last_slave() check with a simple index
comparison (i + 1 == slaves_count) against the pre-snapshot slave
count taken via READ_ONCE() before the loop. This preserves the
zero-copy optimization for the last slave while making the "last"
determination stable against concurrent list mutations.

The UAF can trigger the following crash:

==================================================================
BUG: KASAN: slab-use-after-free in skb_clone
Read of size 8 at addr ffff888100ef8d40 by task exploit/147

CPU: 1 UID: 0 PID: 147 Comm: exploit Not tainted 7.0.0-rc3+ #4 PREEMPTLAZY
Call Trace:
 <TASK>
 dump_stack_lvl (lib/dump_stack.c:123)
 print_report (mm/kasan/report.c:379 mm/kasan/report.c:482)
 kasan_report (mm/kasan/report.c:597)
 skb_clone (include/linux/skbuff.h:1724 include/linux/skbuff.h:1792 include/linux/skbuff.h:3396 net/core/skbuff.c:2108)
 bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5334)
 bond_start_xmit (drivers/net/bonding/bond_main.c:5567 drivers/net/bonding/bond_main.c:5593)
 dev_hard_start_xmit (include/linux/netdevice.h:5325 include/linux/netdevice.h:5334 net/core/dev.c:3871 net/core/dev.c:3887)
 __dev_queue_xmit (include/linux/netdevice.h:3601 net/core/dev.c:4838)
 ip6_finish_output2 (include/net/neighbour.h:540 include/net/neighbour.h:554 net/ipv6/ip6_output.c:136)
 ip6_finish_output (net/ipv6/ip6_output.c:208 net/ipv6/ip6_output.c:219)
 ip6_output (net/ipv6/ip6_output.c:250)
 ip6_send_skb (net/ipv6/ip6_output.c:1985)
 udp_v6_send_skb (net/ipv6/udp.c:1442)
 udpv6_sendmsg (net/ipv6/udp.c:1733)
 __sys_sendto (net/socket.c:730 net/socket.c:742 net/socket.c:2206)
 __x64_sys_sendto (net/socket.c:2209)
 do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)
 entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)
 </TASK>

Allocated by task 147:

Freed by task 147:

The buggy address belongs to the object at ffff888100ef8c80
 which belongs to the cache skbuff_head_cache of size 224
The buggy address is located 192 bytes inside of
 freed 224-byte region [ffff888100ef8c80, ffff888100ef8d60)

Memory state around the buggy address:
 ffff888100ef8c00: fb fb fb fb fc fc fc fc fc fc fc fc fc fc fc fc
 ffff888100ef8c80: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
>ffff888100ef8d00: fb fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc
                                                    ^
 ffff888100ef8d80: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb
 ffff888100ef8e00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
==================================================================

Fixes: 4e5bd03ae346 ("net: bonding: fix bond_xmit_broadcast return value error bug")
Reported-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Link: https://patch.msgid.link/20260326075553.3960562-1-xmei5@asu.edu
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
(backported from commit 2884bf72fb8f03409e423397319205de48adca16)
[tswhison: leveraged ce7a381697c
("net: bonding: add broadcast_neighbor option for 802.3ad")
which was not present here to implement the looping logic, in
this case over bond->all_slaves. Using the indexed-based
looping logic avoids the race caused by bond_is_last_slave().]
CVE-2026-31419
Signed-off-by: Tim Whisonant <tim.whisonant@canonical.com>
Acked-by: Massimiliano Pellizzer <massimiliano.pellizzer@canonical.com>
Acked-by: Manuel Diewald <manuel.diewald@canonical.com>
Signed-off-by: Manuel Diewald <manuel.diewald@canonical.com>

master-next--s2026.03.09-1 2026-04-10 10:45:15 UTC
netfilter: nf_tables: fix use-after-free in nf_tables_addchain()

Author: Inseo An
Author Date: 2026-03-16 23:12:10 UTC

netfilter: nf_tables: fix use-after-free in nf_tables_addchain()

nf_tables_addchain() publishes the chain to table->chains via
list_add_tail_rcu() (in nft_chain_add()) before registering hooks.
If nf_tables_register_hook() then fails, the error path calls
nft_chain_del() (list_del_rcu()) followed by nf_tables_chain_destroy()
with no RCU grace period in between.

This creates two use-after-free conditions:

 1) Control-plane: nf_tables_dump_chains() traverses table->chains
    under rcu_read_lock(). A concurrent dump can still be walking
    the chain when the error path frees it.

 2) Packet path: for NFPROTO_INET, nf_register_net_hook() briefly
    installs the IPv4 hook before IPv6 registration fails. Packets
    entering nft_do_chain() via the transient IPv4 hook can still be
    dereferencing chain->blob_gen_X when the error path frees the
    chain.

Add synchronize_rcu() between nft_chain_del() and the chain destroy
so that all RCU readers -- both dump threads and in-flight packet
evaluation -- have finished before the chain is freed.

Fixes: 91c7b38dc9f0 ("netfilter: nf_tables: use new transaction infrastructure to handle chain")
Signed-off-by: Inseo An <y0un9sa@gmail.com>
Signed-off-by: Florian Westphal <fw@strlen.de>
(cherry picked from commit 71e99ee20fc3f662555118cf1159443250647533)
CVE-2026-23231
Signed-off-by: Tim Whisonant <tim.whisonant@canonical.com>
Acked-by: Yufeng Gao <yufeng.gao@canonical.com>
Acked-by: Masahiro Yamada <masahiro.yamada@canonical.com>
Signed-off-by: Mehmet Basaran <mehmet.basaran@canonical.com>

master-next--s2026.02.09-1 2026-03-13 13:04:28 UTC
net/sched: Enforce that teql can only be used as root qdisc

Author: Jamal Hadi Salim
Author Date: 2026-09-02 19:45:00 UTC

net/sched: Enforce that teql can only be used as root qdisc

Design intent of teql is that it is only supposed to be used as root qdisc.
We need to check for that constraint.

Although not important, I will describe the scenario that unearthed this
issue for the curious.

GangMin Kim<km.kim1503@gmail.com> managed to concot a scenario as follows:

ROOT qdisc 1:0 (QFQ)
   ├── class 1:1 (weight=15, lmax=16384) netem with delay 6.4s
   └── class 1:2 (weight=1, lmax=1514) teql

GangMin sends a packet which is enqueued to 1:1 (netem).
Any invocation of dequeue by QFQ from this class will not return a packet
until after 6.4s. In the meantime, a second packet is sent and it lands on
1:2. teql's enqueue will return success and this will activate class 1:2.
Main issue is that teql only updates the parent visible qlen (sch->q.qlen)
at dequeue. Since QFQ will only call dequeue if peek succeeds (and teql's
peek always returns NULL), dequeue will never be called and thus the qlen
will remain as 0. With that in mind, when GangMin updates 1:2's lmax value,
the qfq_change_class calls qfq_deact_rm_from_agg. Since the child qdisc's
qlen was not incremented, qfq fails to deactivate the class, but still
frees its pointers from the aggregate. So when the first packet is
rescheduled after 6.4 seconds (netem's delay), a dangling pointer is
accessed causing GangMin's causing a UAF.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: GangMin Kim<km.kim1503@gmail.com>
Tested-by: Victor Nogueira<victor@mojatatu.com>
Signed-off-by: Jamal Hadi Salim<jhs@mojatatu.com>
Link:https://patch.msgid.link/20260114160243.913069-2-jhs@mojatatu.com
Signed-off-by: Jakub Kicinski<kuba@kernel.org>

CVE-2026-23074
(cherry picked from commit 50da4b9d07a7a463e2cfb738f3ad4cff6b2c9c3b)
Signed-off-by: Tim Whisonant<tim.whisonant@canonical.com>
Acked-by: Abdur Rahman <abdur.rahman@canonical.com>
Acked-by: Austin Rhodes <austin.rhodes@canonical.com>
Signed-off-by: Stefan Bader <stefan.bader@canonical.com>

master-next--2026.02.09-3--auto 2026-02-13 17:29:37 UTC
UBUNTU: Ubuntu-6.8.0-102.102

Author: Ubuntu Kernel Bot
Author Date: 2026-02-13 17:29:37 UTC

UBUNTU: Ubuntu-6.8.0-102.102

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

lowlatency-next--2026.02.09-1--auto 2026-02-12 15:45:41 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-103.103.1

Author: Ubuntu Kernel Bot
Author Date: 2026-02-12 15:45:40 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-103.103.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--2026.02.09-2--auto 2026-02-10 10:38:07 UTC
UBUNTU: Ubuntu-6.8.0-102.102

Author: Ubuntu Kernel Bot
Author Date: 2026-02-10 10:38:06 UTC

UBUNTU: Ubuntu-6.8.0-102.102

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.17-next--2026.02.09-1--auto 2026-02-07 14:31:34 UTC
UBUNTU: Ubuntu-hwe-6.17-6.17.0-16.16~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2026-02-07 14:31:33 UTC

UBUNTU: Ubuntu-hwe-6.17-6.17.0-16.16~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--2026.02.09-1--auto 2026-02-07 04:38:45 UTC
UBUNTU: Ubuntu-6.8.0-102.102

Author: Ubuntu Kernel Bot
Author Date: 2026-02-07 04:38:44 UTC

UBUNTU: Ubuntu-6.8.0-102.102

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

lowlatency-next--s2026.01.12-2--auto 2026-02-07 01:07:01 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-101.101.1

Author: Ubuntu Kernel Bot
Author Date: 2026-02-07 01:07:00 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-101.101.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2026.01.12-1 2026-02-06 09:05:48 UTC
ksmbd: fix use-after-free in session logoff

Author: Sean Heelan
Author Date: 2025-11-27 16:23:37 UTC

ksmbd: fix use-after-free in session logoff

commit 2fc9feff45d92a92cd5f96487655d5be23fb7e2b upstream.

The sess->user object can currently be in use by another thread, for
example if another connection has sent a session setup request to
bind to the session being free'd. The handler for that connection could
be in the smb2_sess_setup function which makes use of sess->user.

Signed-off-by: Sean Heelan <seanheelan@gmail.com>
Acked-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Nazar Kalashnikov <sivartiwe@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
CVE-2025-37899
Signed-off-by: Manuel Diewald <manuel.diewald@canonical.com>

lowlatency-next--2026.01.12-1--auto 2026-01-19 15:57:18 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-100.100.1

Author: Ubuntu Kernel Bot
Author Date: 2026-01-19 15:57:17 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-100.100.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

lowlatency-next--s2025.11.17-1--auto 2026-01-10 01:48:27 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-94.96.1

Author: Ubuntu Kernel Bot
Author Date: 2026-01-10 01:48:24 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-94.96.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.17-next--2026.01.12-1--auto 2026-01-09 15:33:11 UTC
UBUNTU: Ubuntu-hwe-6.17-6.17.0-14.14~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2026-01-09 15:33:10 UTC

UBUNTU: Ubuntu-hwe-6.17-6.17.0-14.14~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2025.11.17-1--auto 2026-01-09 13:25:14 UTC
UBUNTU: Ubuntu-6.8.0-94.96

Author: Ubuntu Kernel Bot
Author Date: 2026-01-09 13:25:14 UTC

UBUNTU: Ubuntu-6.8.0-94.96

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2025.11.17 2026-01-09 10:42:10 UTC
crypto: essiv - Check ssize for decryption and in-place encryption

Author: Herbert Xu
Author Date: 2025-11-19 01:03:00 UTC

crypto: essiv - Check ssize for decryption and in-place encryption

Move the ssize check to the start in essiv_aead_crypt so that
it's also checked for decryption and in-place encryption.

Reported-by: Muhammad Alifa Ramdhan<ramdhan@starlabs.sg>
Fixes: be1eb7f78aa8 ("crypto: essiv - create wrapper template for ESSIV generation")
Signed-off-by: Herbert Xu<herbert@gondor.apana.org.au>

CVE-2025-40019
(cherry picked from commit 6bb73db6948c2de23e407fe1b7ef94bf02b7529f)
Signed-off-by: Ian Whitfield<ian.whitfield@canonical.com>
Acked-by: Tim Whisonant <tim.whisonant@canonical.com>
Acked-by: Philip Cox <philip.cox@canonical.com>
Signed-off-by: Stefan Bader <stefan.bader@canonical.com>

master-next--2025.11.17-3--auto 2025-12-13 15:54:12 UTC
UBUNTU: Ubuntu-6.8.0-91.92

Author: Ubuntu Kernel Bot
Author Date: 2025-12-13 15:54:11 UTC

UBUNTU: Ubuntu-6.8.0-91.92

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.17-prep 2025-12-01 11:27:40 UTC
UBUNTU: Ubuntu-hwe-6.17-6.17.0-9.9~24.04.2

Author: Stefan Bader
Author Date: 2025-12-01 11:26:44 UTC

UBUNTU: Ubuntu-hwe-6.17-6.17.0-9.9~24.04.2

Signed-off-by: Stefan Bader <stefan.bader@canonical.com>

master-next--2025.11.17-1--auto 2025-11-24 11:13:55 UTC
UBUNTU: Ubuntu-6.8.0-91.92

Author: Ubuntu Kernel Bot
Author Date: 2025-11-24 11:13:53 UTC

UBUNTU: Ubuntu-6.8.0-91.92

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.14-next 2025-11-20 08:36:06 UTC
UBUNTU: Ubuntu-hwe-6.14-6.14.0-37.37~24.04.1

Author: Stefan Bader
Author Date: 2025-11-20 08:36:06 UTC

UBUNTU: Ubuntu-hwe-6.14-6.14.0-37.37~24.04.1

Signed-off-by: Stefan Bader <stefan.bader@canonical.com>

lowlatency-next--s2025.10.13-3--auto 2025-11-18 13:42:34 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-90.91.1

Author: Ubuntu Kernel Bot
Author Date: 2025-11-18 13:42:33 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-90.91.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master 2025-11-18 11:26:33 UTC
UBUNTU: Ubuntu-6.8.0-90.91

Author: Manuel Diewald
Author Date: 2025-11-18 11:26:33 UTC

UBUNTU: Ubuntu-6.8.0-90.91

Signed-off-by: Manuel Diewald <manuel.diewald@canonical.com>

lowlatency-next--s2025.10.13-1--auto 2025-11-15 04:22:28 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-89.90.1

Author: Ubuntu Kernel Bot
Author Date: 2025-11-15 04:22:27 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-89.90.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.14-next--s2025.10.13-1--auto 2025-11-15 03:00:07 UTC
UBUNTU: Ubuntu-hwe-6.14-6.14.0-37.37~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-11-15 03:00:06 UTC

UBUNTU: Ubuntu-hwe-6.14-6.14.0-37.37~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2025.10.13-1--auto 2025-11-14 12:30:44 UTC
UBUNTU: Ubuntu-6.8.0-89.90

Author: Ubuntu Kernel Bot
Author Date: 2025-11-14 12:30:44 UTC

UBUNTU: Ubuntu-6.8.0-89.90

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

lowlatency-next--2025.10.13-1--auto 2025-10-15 14:54:06 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-88.89.1

Author: Ubuntu Kernel Bot
Author Date: 2025-10-15 14:54:05 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-88.89.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.14-next--2025.10.13-1--auto 2025-10-14 20:17:34 UTC
UBUNTU: Ubuntu-hwe-6.14-6.14.0-36.36~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-10-14 20:17:33 UTC

UBUNTU: Ubuntu-hwe-6.14-6.14.0-36.36~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.14-next--s2025.09.15-1--auto 2025-10-11 14:26:09 UTC
UBUNTU: Ubuntu-hwe-6.14-6.14.0-35.35~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-10-11 14:26:08 UTC

UBUNTU: Ubuntu-hwe-6.14-6.14.0-35.35~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

lowlatency-next--s2025.09.15-1--auto 2025-10-11 11:46:06 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-87.88.1

Author: Ubuntu Kernel Bot
Author Date: 2025-10-11 11:46:06 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-87.88.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--2025.10.13-1--auto 2025-10-10 19:10:47 UTC
UBUNTU: Ubuntu-6.8.0-87.88

Author: Ubuntu Kernel Bot
Author Date: 2025-10-10 19:10:47 UTC

UBUNTU: Ubuntu-6.8.0-87.88

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2025.09.15-1 2025-10-10 17:49:17 UTC
HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Du...

Author: Kaixin Wang
Author Date: 2025-10-02 23:28:56 UTC

HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition

In the ssi_protocol_probe() function, &ssi->work is bound with
ssip_xmit_work(), In ssip_pn_setup(), the ssip_pn_xmit() function
within the ssip_pn_ops structure is capable of starting the
work.

If we remove the module which will call ssi_protocol_remove()
to make a cleanup, it will free ssi through kfree(ssi),
while the work mentioned above will be used. The sequence
of operations that may lead to a UAF bug is as follows:

CPU0 CPU1

                        | ssip_xmit_work
ssi_protocol_remove |
kfree(ssi); |
                        | struct hsi_client *cl = ssi->cl;
                        | // use ssi

Fix it by ensuring that the work is canceled before proceeding
with the cleanup in ssi_protocol_remove().

Signed-off-by: Kaixin Wang <kxwang23@m.fudan.edu.cn>
Acked-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Link: https://lore.kernel.org/r/20240918120749.1730-1-kxwang23@m.fudan.edu.cn
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
(cherry picked from commit e3f88665a78045fe35c7669d2926b8d97b892c11)
CVE-2025-37838
Signed-off-by: Tim Whisonant <tim.whisonant@canonical.com>
Acked-by: Manuel Diewald <manuel.diewald@canonical.com>
Acked-by: Alessio Faina <alessio.faina@canonical.com>
Signed-off-by: Edoardo Canepa <edoardo.canepa@canonical.com>

master-next--s2025.09.15-1--auto 2025-10-10 12:48:36 UTC
UBUNTU: Ubuntu-6.8.0-87.88

Author: Ubuntu Kernel Bot
Author Date: 2025-10-10 12:48:36 UTC

UBUNTU: Ubuntu-6.8.0-87.88

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

lowlatency-next--2025.09.15-1--auto 2025-09-22 17:09:02 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-86.87.1

Author: Ubuntu Kernel Bot
Author Date: 2025-09-22 17:09:01 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-86.87.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--2025.09.15-1--auto 2025-09-22 11:23:02 UTC
UBUNTU: Ubuntu-6.8.0-86.86

Author: Ubuntu Kernel Bot
Author Date: 2025-09-22 11:23:00 UTC

UBUNTU: Ubuntu-6.8.0-86.86

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.14-next--2025.09.15-1--auto 2025-09-19 22:09:00 UTC
UBUNTU: Ubuntu-hwe-6.14-6.14.0-34.34~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-09-19 22:09:00 UTC

UBUNTU: Ubuntu-hwe-6.14-6.14.0-34.34~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

lowlatency-next--s2025.08.11-1--auto 2025-09-18 15:02:36 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-85.85.1

Author: Ubuntu Kernel Bot
Author Date: 2025-09-18 15:02:36 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-85.85.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2025.08.11-1--auto 2025-09-18 12:24:14 UTC
UBUNTU: Ubuntu-6.8.0-85.85

Author: Ubuntu Kernel Bot
Author Date: 2025-09-18 12:24:13 UTC

UBUNTU: Ubuntu-6.8.0-85.85

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2025.08.11-1 2025-09-18 10:42:20 UTC
xfrm: interface: fix use-after-free after changing collect_md xfrm interface

Author: Eyal Birger
Author Date: 2025-08-20 01:02:00 UTC

xfrm: interface: fix use-after-free after changing collect_md xfrm interface

collect_md property on xfrm interfaces can only be set on device creation,
thus xfrmi_changelink() should fail when called on such interfaces.

The check to enforce this was done only in the case where the xi was
returned from xfrmi_locate() which doesn't look for the collect_md
interface, and thus the validation was never reached.

Calling changelink would thus errornously place the special interface xi
in the xfrmi_net->xfrmi hash, but since it also exists in the
xfrmi_net->collect_md_xfrmi pointer it would lead to a double free when
the net namespace was taken down [1].

Change the check to use the xi from netdev_priv which is available earlier
in the function to prevent changes in xfrm collect_md interfaces.

[1] resulting oops:
[ 8.516540] kernel BUG at net/core/dev.c:12029!
[ 8.516552] Oops: invalid opcode: 0000 [#1] SMP NOPTI
[ 8.516559] CPU: 0 UID: 0 PID: 12 Comm: kworker/u80:0 Not tainted 6.15.0-virtme #5 PREEMPT(voluntary)
[ 8.516565] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 8.516569] Workqueue: netns cleanup_net
[ 8.516579] RIP: 0010:unregister_netdevice_many_notify+0x101/0xab0
[ 8.516590] Code: 90 0f 0b 90 48 8b b0 78 01 00 00 48 8b 90 80 01 00 00 48 89 56 08 48 89 32 4c 89 80 78 01 00 00 48 89 b8 80 01 00 00 eb ac 90 <0f> 0b 48 8b 45 00 4c 8d a0 88 fe ff ff 48 39 c5 74 5c 41 80 bc 24
[ 8.516593] RSP: 0018:ffffa93b8006bd30 EFLAGS: 00010206
[ 8.516598] RAX: ffff98fe4226e000 RBX: ffffa93b8006bd58 RCX: ffffa93b8006bc60
[ 8.516601] RDX: 0000000000000004 RSI: 0000000000000000 RDI: dead000000000122
[ 8.516603] RBP: ffffa93b8006bdd8 R08: dead000000000100 R09: ffff98fe4133c100
[ 8.516605] R10: 0000000000000000 R11: 00000000000003d2 R12: ffffa93b8006be00
[ 8.516608] R13: ffffffff96c1a510 R14: ffffffff96c1a510 R15: ffffa93b8006be00
[ 8.516615] FS: 0000000000000000(0000)GS:ffff98fee73b7000(0000) knlGS:0000000000000000
[ 8.516619] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 8.516622] CR2: 00007fcd2abd0700 CR3: 000000003aa40000 CR4: 0000000000752ef0
[ 8.516625] PKRU: 55555554
[ 8.516627] Call Trace:
[ 8.516632] <TASK>
[ 8.516635] ? rtnl_is_locked+0x15/0x20
[ 8.516641] ? unregister_netdevice_queue+0x29/0xf0
[ 8.516650] ops_undo_list+0x1f2/0x220
[ 8.516659] cleanup_net+0x1ad/0x2e0
[ 8.516664] process_one_work+0x160/0x380
[ 8.516673] worker_thread+0x2aa/0x3c0
[ 8.516679] ? __pfx_worker_thread+0x10/0x10
[ 8.516686] kthread+0xfb/0x200
[ 8.516690] ? __pfx_kthread+0x10/0x10
[ 8.516693] ? __pfx_kthread+0x10/0x10
[ 8.516697] ret_from_fork+0x82/0xf0
[ 8.516705] ? __pfx_kthread+0x10/0x10
[ 8.516709] ret_from_fork_asm+0x1a/0x30
[ 8.516718] </TASK>

Fixes: abc340b38ba2 ("xfrm: interface: support collect metadata mode")
Reported-by: Lonial Con<kongln9170@gmail.com>
Signed-off-by: Eyal Birger<eyal.birger@gmail.com>
Signed-off-by: Steffen Klassert<steffen.klassert@secunet.com>

CVE-2025-38500
(cherry picked from commit a90b2a1aaacbcf0f91d7e4868ad6c51c5dee814b)
Signed-off-by: Tim Whisonant<tim.whisonant@canonical.com>
Acked-by: Zixing Liu <zixing.liu@canonical.com>
Acked-by: Bethany Jamison <bethany.jamison@canonical.com>
Signed-off-by: Stefan Bader <stefan.bader@canonical.com>

hwe-6.14-next--s2025.08.11-1--auto 2025-09-18 01:05:07 UTC
UBUNTU: Ubuntu-hwe-6.14-6.14.0-33.33~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-09-18 01:05:07 UTC

UBUNTU: Ubuntu-hwe-6.14-6.14.0-33.33~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--2025.08.11-5--auto 2025-08-29 10:05:15 UTC
UBUNTU: Ubuntu-6.8.0-80.80

Author: Ubuntu Kernel Bot
Author Date: 2025-08-29 10:05:15 UTC

UBUNTU: Ubuntu-6.8.0-80.80

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

lowlatency-next--2025.08.11-1--auto 2025-08-16 16:25:47 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-80.80.1

Author: Ubuntu Kernel Bot
Author Date: 2025-08-16 16:25:46 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-80.80.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.14-next--2025.08.11-1--auto 2025-08-15 02:15:00 UTC
UBUNTU: Ubuntu-hwe-6.14-6.14.0-30.30~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-08-15 02:15:00 UTC

UBUNTU: Ubuntu-hwe-6.14-6.14.0-30.30~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--2025.08.11-3--auto 2025-08-12 11:42:26 UTC
UBUNTU: Ubuntu-6.8.0-74.74

Author: Ubuntu Kernel Bot
Author Date: 2025-08-12 11:42:24 UTC

UBUNTU: Ubuntu-6.8.0-74.74

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2025.07.14-2--auto 2025-08-12 11:01:33 UTC
UBUNTU: Ubuntu-6.8.0-79.79

Author: Ubuntu Kernel Bot
Author Date: 2025-08-12 11:01:33 UTC

UBUNTU: Ubuntu-6.8.0-79.79

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--2025.07.14-6--auto 2025-08-12 09:24:27 UTC
UBUNTU: Ubuntu-6.8.0-72.72

Author: Ubuntu Kernel Bot
Author Date: 2025-08-12 09:24:27 UTC

UBUNTU: Ubuntu-6.8.0-72.72

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--2025.08.11-2--auto 2025-08-08 23:32:58 UTC
UBUNTU: Ubuntu-6.8.0-74.74

Author: Ubuntu Kernel Bot
Author Date: 2025-08-08 23:32:57 UTC

UBUNTU: Ubuntu-6.8.0-74.74

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--2025.08.11-1--auto 2025-08-08 04:16:48 UTC
UBUNTU: Ubuntu-6.8.0-74.74

Author: Ubuntu Kernel Bot
Author Date: 2025-08-08 04:16:47 UTC

UBUNTU: Ubuntu-6.8.0-74.74

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.14-next--s2025.07.14-1--auto 2025-08-07 22:58:02 UTC
UBUNTU: Ubuntu-hwe-6.14-6.14.0-29.29~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-08-07 22:58:02 UTC

UBUNTU: Ubuntu-hwe-6.14-6.14.0-29.29~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

lowlatency-next--s2025.07.14-1--auto 2025-08-07 21:26:33 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-73.73.1

Author: Ubuntu Kernel Bot
Author Date: 2025-08-07 21:26:32 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-73.73.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2025.07.14-1--auto 2025-08-07 14:15:27 UTC
UBUNTU: Ubuntu-6.8.0-73.73

Author: Ubuntu Kernel Bot
Author Date: 2025-08-07 14:15:27 UTC

UBUNTU: Ubuntu-6.8.0-73.73

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2025.07.14-1 2025-08-07 13:59:28 UTC
net_sched: sch_sfq: move the limit validation

Author: Octavian Purdila
Author Date: 2025-07-12 01:28:21 UTC

net_sched: sch_sfq: move the limit validation

It is not sufficient to directly validate the limit on the data that
the user passes as it can be updated based on how the other parameters
are changed.

Move the check at the end of the configuration update process to also
catch scenarios where the limit is indirectly updated, for example
with the following configurations:

tc qdisc add dev dummy0 handle 1: root sfq limit 2 flows 1 depth 1
tc qdisc add dev dummy0 handle 1: root sfq limit 2 flows 1 divisor 1

This fixes the following syzkaller reported crash:

------------[ cut here ]------------
UBSAN: array-index-out-of-bounds in net/sched/sch_sfq.c:203:6
index 65535 is out of range for type 'struct sfq_head[128]'
CPU: 1 UID: 0 PID: 3037 Comm: syz.2.16 Not tainted 6.14.0-rc2-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 12/27/2024
Call Trace:
 <TASK>
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0x201/0x300 lib/dump_stack.c:120
 ubsan_epilogue lib/ubsan.c:231 [inline]
 __ubsan_handle_out_of_bounds+0xf5/0x120 lib/ubsan.c:429
 sfq_link net/sched/sch_sfq.c:203 [inline]
 sfq_dec+0x53c/0x610 net/sched/sch_sfq.c:231
 sfq_dequeue+0x34e/0x8c0 net/sched/sch_sfq.c:493
 sfq_reset+0x17/0x60 net/sched/sch_sfq.c:518
 qdisc_reset+0x12e/0x600 net/sched/sch_generic.c:1035
 tbf_reset+0x41/0x110 net/sched/sch_tbf.c:339
 qdisc_reset+0x12e/0x600 net/sched/sch_generic.c:1035
 dev_reset_queue+0x100/0x1b0 net/sched/sch_generic.c:1311
 netdev_for_each_tx_queue include/linux/netdevice.h:2590 [inline]
 dev_deactivate_many+0x7e5/0xe70 net/sched/sch_generic.c:1375

Reported-by: syzbot <syzkaller@googlegroups.com>
Fixes: 10685681bafc ("net_sched: sch_sfq: don't allow 1 packet limit")
Signed-off-by: Octavian Purdila <tavip@google.com>
Acked-by: Cong Wang <xiyou.wangcong@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(backported from commit b3bf8f63e6179076b57c9de660c9f80b5abefe70)
[tswhison: Used q->limit in if check, because
8c0cea59d40c ("net_sched: sch_sfq: use a temporary work
area for validating configuration")
is missing. Leave NL_SET_ERR_MSG_MOD() in place.]
CVE-2024-57996
CVE-2025-37752
Signed-off-by: Tim Whisonant <tim.whisonant@canonical.com>
Acked-by: Ian Whitfield <ian.whitfield@canonical.com>
Acked-by: John Cabaj <john.cabaj@canonical.com>
Signed-off-by: Mehmet Basaran <mehmet.basaran@canonical.com>

lowlatency-next--2025.07.14-3--auto 2025-07-23 12:31:14 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-72.72.1

Author: Ubuntu Kernel Bot
Author Date: 2025-07-23 12:31:14 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-72.72.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.14-next--2025.07.14-3--auto 2025-07-23 11:57:10 UTC
UBUNTU: Ubuntu-hwe-6.14-6.14.0-28.28~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-07-23 11:57:10 UTC

UBUNTU: Ubuntu-hwe-6.14-6.14.0-28.28~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--2025.07.14-3--auto 2025-07-23 10:07:25 UTC
UBUNTU: Ubuntu-6.8.0-72.72

Author: Ubuntu Kernel Bot
Author Date: 2025-07-23 10:07:24 UTC

UBUNTU: Ubuntu-6.8.0-72.72

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.14-next--s2025.06.16-3--auto 2025-07-22 15:26:36 UTC
UBUNTU: Ubuntu-hwe-6.14-6.14.0-27.27~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-07-22 15:26:32 UTC

UBUNTU: Ubuntu-hwe-6.14-6.14.0-27.27~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2025.06.16-3--auto 2025-07-22 14:02:44 UTC
UBUNTU: Ubuntu-6.8.0-65.68

Author: Ubuntu Kernel Bot
Author Date: 2025-07-22 14:02:44 UTC

UBUNTU: Ubuntu-6.8.0-65.68

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

lowlatency-next--2025.07.14-1--auto 2025-07-18 00:28:24 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-70.70.1

Author: Ubuntu Kernel Bot
Author Date: 2025-07-18 00:28:23 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-70.70.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.14-next--2025.07.14-1--auto 2025-07-18 00:06:21 UTC
UBUNTU: Ubuntu-hwe-6.14-6.14.0-26.26~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-07-18 00:06:20 UTC

UBUNTU: Ubuntu-hwe-6.14-6.14.0-26.26~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.14-next--s2025.06.16-1--auto 2025-07-11 18:09:45 UTC
UBUNTU: Ubuntu-hwe-6.14-6.14.0-25.25~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-07-11 18:09:44 UTC

UBUNTU: Ubuntu-hwe-6.14-6.14.0-25.25~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

lowlatency-next--s2025.06.16-1--auto 2025-07-11 16:48:19 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-65.68.1

Author: Ubuntu Kernel Bot
Author Date: 2025-07-11 16:48:19 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-65.68.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2025.06.16-1--auto 2025-07-11 11:08:04 UTC
UBUNTU: Ubuntu-6.8.0-65.68

Author: Ubuntu Kernel Bot
Author Date: 2025-07-11 11:08:03 UTC

UBUNTU: Ubuntu-6.8.0-65.68

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--2025.07.14-1--auto 2025-07-11 08:37:09 UTC
UBUNTU: Ubuntu-6.8.0-65.68

Author: Ubuntu Kernel Bot
Author Date: 2025-07-11 08:37:08 UTC

UBUNTU: Ubuntu-6.8.0-65.68

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2025.06.16-1 2025-07-11 07:50:55 UTC
net_sched: prio: fix a race in prio_tune()

Author: Eric Dumazet
Author Date: 2025-06-25 23:00:00 UTC

net_sched: prio: fix a race in prio_tune()

Gerrard Tai reported a race condition in PRIO, whenever SFQ perturb timer
fires at the wrong time.

The race is as follows:

CPU 0 CPU 1
[1]: lock root
[2]: qdisc_tree_flush_backlog()
[3]: unlock root
  |
  | [5]: lock root
  | [6]: rehash
  | [7]: qdisc_tree_reduce_backlog()
  |
[4]: qdisc_put()

This can be abused to underflow a parent's qlen.

Calling qdisc_purge_queue() instead of qdisc_tree_flush_backlog()
should fix the race, because all packets will be purged from the qdisc
before releasing the lock.

Fixes: 7b8e0b6e6599 ("net: sched: prio: delay destroying child qdiscs on change")
Reported-by: Gerrard Tai<gerrard.tai@starlabs.sg>
Suggested-by: Gerrard Tai<gerrard.tai@starlabs.sg>
Signed-off-by: Eric Dumazet<edumazet@google.com>
Link:https://patch.msgid.link/20250611111515.1983366-2-edumazet@google.com
Signed-off-by: Jakub Kicinski<kuba@kernel.org>

CVE-2025-38083
(cherry picked from commit d35acc1be3480505b5931f17e4ea9b7617fea4d3)
Signed-off-by: Tim Whisonant<tim.whisonant@canonical.com>
Acked-by: Stefan Bader <stefan.bader@canonical.com>
Acked-by: Wei-Lin Chang <weilin.chang@canonical.com>
Signed-off-by: Stefan Bader <stefan.bader@canonical.com>

hwe-6.14-next--2025.06.16-6--auto 2025-07-07 14:24:57 UTC
UBUNTU: Ubuntu-hwe-6.14-6.14.0-24.24~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-07-07 14:24:57 UTC

UBUNTU: Ubuntu-hwe-6.14-6.14.0-24.24~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

lowlatency-hwe-6.11-next 2025-07-03 17:50:22 UTC
UBUNTU: Ubuntu-lowlatency-hwe-6.11-6.11.0-1016.17~24.04.1

Author: Austin Rhodes
Author Date: 2025-07-03 17:50:22 UTC

UBUNTU: Ubuntu-lowlatency-hwe-6.11-6.11.0-1016.17~24.04.1

Signed-off-by: Austin Rhodes <austin.rhodes@canonical.com>

lowlatency-hwe-6.11-next--s2025.05.19-1--auto 2025-06-30 10:27:17 UTC
UBUNTU: Ubuntu-lowlatency-hwe-6.11-6.11.0-1016.17~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-06-30 10:27:16 UTC

UBUNTU: Ubuntu-lowlatency-hwe-6.11-6.11.0-1016.17~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.14-next--2025.06.16-3--auto 2025-06-27 08:30:40 UTC
UBUNTU: Ubuntu-hwe-6.14-6.14.0-24.24~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-06-27 08:30:40 UTC

UBUNTU: Ubuntu-hwe-6.14-6.14.0-24.24~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.11-next 2025-06-26 12:36:57 UTC
UBUNTU: Ubuntu-hwe-6.11-6.11.0-29.29~24.04.1

Author: Stefan Bader
Author Date: 2025-06-26 12:36:57 UTC

UBUNTU: Ubuntu-hwe-6.11-6.11.0-29.29~24.04.1

Signed-off-by: Stefan Bader <stefan.bader@canonical.com>

hwe-6.14-next--2025.06.16-1--auto 2025-06-24 00:14:24 UTC
UBUNTU: Ubuntu-hwe-6.14-6.14.0-24.24~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-06-24 00:14:24 UTC

UBUNTU: Ubuntu-hwe-6.14-6.14.0-24.24~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.11-next--s2025.05.19-1--auto 2025-06-23 22:54:04 UTC
UBUNTU: Ubuntu-hwe-6.11-6.11.0-29.29~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-06-23 22:54:03 UTC

UBUNTU: Ubuntu-hwe-6.11-6.11.0-29.29~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

lowlatency-next--2025.05.19-1--auto 2025-06-23 21:31:41 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-62.65.1

Author: Ubuntu Kernel Bot
Author Date: 2025-06-23 21:31:41 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-62.65.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.11-next--2025.05.19-1--auto 2025-06-23 21:09:08 UTC
UBUNTU: Ubuntu-hwe-6.11-6.11.0-28.28~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-06-23 21:09:08 UTC

UBUNTU: Ubuntu-hwe-6.11-6.11.0-28.28~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--2025.06.16-2--auto 2025-06-23 14:31:11 UTC
UBUNTU: Ubuntu-6.8.0-64.67

Author: Ubuntu Kernel Bot
Author Date: 2025-06-23 14:31:11 UTC

UBUNTU: Ubuntu-6.8.0-64.67

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

lowlatency-next--2025.06.16-2--auto 2025-06-23 13:16:40 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-64.67.1

Author: Ubuntu Kernel Bot
Author Date: 2025-06-23 13:16:39 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-64.67.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2025.05.19-1--auto 2025-06-18 12:43:54 UTC
UBUNTU: Ubuntu-6.8.0-63.66

Author: Ubuntu Kernel Bot
Author Date: 2025-06-18 12:43:54 UTC

UBUNTU: Ubuntu-6.8.0-63.66

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

hwe-6.14-next--s2025.05.19-1--auto 2025-06-17 22:11:56 UTC
UBUNTU: Ubuntu-hwe-6.14-6.14.0-23.23~24.04.1

Author: Ubuntu Kernel Bot
Author Date: 2025-06-17 22:11:56 UTC

UBUNTU: Ubuntu-hwe-6.14-6.14.0-23.23~24.04.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

lowlatency-next--s2025.05.19-1--auto 2025-06-17 18:56:32 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-63.66.1

Author: Ubuntu Kernel Bot
Author Date: 2025-06-17 18:56:32 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-63.66.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

master-next--s2025.05.19-1 2025-06-13 12:12:35 UTC
codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog()

Author: Cong Wang
Author Date: 2025-05-27 21:48:11 UTC

codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog()

After making all ->qlen_notify() callbacks idempotent, now it is safe to
remove the check of qlen!=0 from both fq_codel_dequeue() and
codel_qdisc_dequeue().

Reported-by: Gerrard Tai <gerrard.tai@starlabs.sg>
Fixes: 4b549a2ef4be ("fq_codel: Fair Queue Codel AQM")
Fixes: 76e3cc126bb2 ("codel: Controlled Delay AQM")
Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20250403211636.166257-1-xiyou.wangcong@gmail.com
Acked-by: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
(cherry picked from commit 342debc12183b51773b3345ba267e9263bdfaaef)
CVE-2025-37798
Signed-off-by: Ian Whitfield <ian.whitfield@canonical.com>
Acked-by: Stefan Bader <stefan.bader@canonical.com>
Acked-by: Edoardo Canepa <edoardo.canepa@canonical.com>
Signed-off-by: Mehmet Basaran <mehmet.basaran@canonical.com>

master-next--s2025.03.17-1 2025-04-11 09:55:25 UTC
Bluetooth: btmtk: avoid UAF in btmtk_process_coredump

Author: Thadeu Lima de Souza Cascardo
Author Date: 2025-03-13 04:21:44 UTC

Bluetooth: btmtk: avoid UAF in btmtk_process_coredump

[ Upstream commit b548f5e9456c568155499d9ebac675c0d7a296e8 ]

hci_devcd_append may lead to the release of the skb, so it cannot be
accessed once it is called.

==================================================================
BUG: KASAN: slab-use-after-free in btmtk_process_coredump+0x2a7/0x2d0 [btmtk]
Read of size 4 at addr ffff888033cfabb0 by task kworker/0:3/82

CPU: 0 PID: 82 Comm: kworker/0:3 Tainted: G U 6.6.40-lockdep-03464-g1d8b4eb3060e #1 b0b3c1cc0c842735643fb411799d97921d1f688c
Hardware name: Google Yaviks_Ufs/Yaviks_Ufs, BIOS Google_Yaviks_Ufs.15217.552.0 05/07/2024
Workqueue: events btusb_rx_work [btusb]
Call Trace:
 <TASK>
 dump_stack_lvl+0xfd/0x150
 print_report+0x131/0x780
 kasan_report+0x177/0x1c0
 btmtk_process_coredump+0x2a7/0x2d0 [btmtk 03edd567dd71a65958807c95a65db31d433e1d01]
 btusb_recv_acl_mtk+0x11c/0x1a0 [btusb 675430d1e87c4f24d0c1f80efe600757a0f32bec]
 btusb_rx_work+0x9e/0xe0 [btusb 675430d1e87c4f24d0c1f80efe600757a0f32bec]
 worker_thread+0xe44/0x2cc0
 kthread+0x2ff/0x3a0
 ret_from_fork+0x51/0x80
 ret_from_fork_asm+0x1b/0x30
 </TASK>

Allocated by task 82:
 stack_trace_save+0xdc/0x190
 kasan_set_track+0x4e/0x80
 __kasan_slab_alloc+0x4e/0x60
 kmem_cache_alloc+0x19f/0x360
 skb_clone+0x132/0xf70
 btusb_recv_acl_mtk+0x104/0x1a0 [btusb]
 btusb_rx_work+0x9e/0xe0 [btusb]
 worker_thread+0xe44/0x2cc0
 kthread+0x2ff/0x3a0
 ret_from_fork+0x51/0x80
 ret_from_fork_asm+0x1b/0x30

Freed by task 1733:
 stack_trace_save+0xdc/0x190
 kasan_set_track+0x4e/0x80
 kasan_save_free_info+0x28/0xb0
 ____kasan_slab_free+0xfd/0x170
 kmem_cache_free+0x183/0x3f0
 hci_devcd_rx+0x91a/0x2060 [bluetooth]
 worker_thread+0xe44/0x2cc0
 kthread+0x2ff/0x3a0
 ret_from_fork+0x51/0x80
 ret_from_fork_asm+0x1b/0x30

The buggy address belongs to the object at ffff888033cfab40
 which belongs to the cache skbuff_head_cache of size 232
The buggy address is located 112 bytes inside of
 freed 232-byte region [ffff888033cfab40, ffff888033cfac28)

The buggy address belongs to the physical page:
page:00000000a174ba93 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x33cfa
head:00000000a174ba93 order:1 entire_mapcount:0 nr_pages_mapped:0 pincount:0
anon flags: 0x4000000000000840(slab|head|zone=1)
page_type: 0xffffffff()
raw: 4000000000000840 ffff888100848a00 0000000000000000 0000000000000001
raw: 0000000000000000 0000000080190019 00000001ffffffff 0000000000000000
page dumped because: kasan: bad access detected

Memory state around the buggy address:
 ffff888033cfaa80: fb fb fb fb fb fb fb fb fb fb fb fb fb fc fc fc
 ffff888033cfab00: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb
>ffff888033cfab80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
                                     ^
 ffff888033cfac00: fb fb fb fb fb fc fc fc fc fc fc fc fc fc fc fc
 ffff888033cfac80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
==================================================================

Check if we need to call hci_devcd_complete before calling
hci_devcd_append. That requires that we check data->cd_info.cnt >=
MTK_COREDUMP_NUM instead of data->cd_info.cnt > MTK_COREDUMP_NUM, as we
increment data->cd_info.cnt only once the call to hci_devcd_append
succeeds.

Fixes: 0b7015132878 ("Bluetooth: btusb: mediatek: add MediaTek devcoredump support")
Signed-off-by: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
CVE-2024-56653
Signed-off-by: Koichiro Den <koichiro.den@canonical.com>
Signed-off-by: Manuel Diewald <manuel.diewald@canonical.com>

master-next--s2025.02.10-1 2025-03-14 12:58:10 UTC
drm/dp_mst: Ensure mst_primary pointer is valid in drm_dp_mst_handle_up_req()

Author: Imre Deak
Author Date: 2025-02-24 15:18:02 UTC

drm/dp_mst: Ensure mst_primary pointer is valid in drm_dp_mst_handle_up_req()

While receiving an MST up request message from one thread in
drm_dp_mst_handle_up_req(), the MST topology could be removed from
another thread via drm_dp_mst_topology_mgr_set_mst(false), freeing
mst_primary and setting drm_dp_mst_topology_mgr::mst_primary to NULL.
This could lead to a NULL deref/use-after-free of mst_primary in
drm_dp_mst_handle_up_req().

Avoid the above by holding a reference for mst_primary in
drm_dp_mst_handle_up_req() while it's used.

v2: Fix kfreeing the request if getting an mst_primary reference fails.

Cc: Lyude Paul <lyude@redhat.com>
Reviewed-by: Lyude Paul <lyude@redhat.com> (v1)
Signed-off-by: Imre Deak <imre.deak@intel.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20241204132007.3132494-1-imre.deak@intel.com

CVE-2024-57798
(cherry picked from commit e54b00086f7473dbda1a7d6fc47720ced157c6a8)
Signed-off-by: Massimiliano Pellizzer <massimiliano.pellizzer@canonical.com>
Acked-by: Koichiro Den <koichiro.den@canonical.com>
Acked-by: Stewart Hore <stewart.hore@canonical.com>
Signed-off-by: Koichiro Den <koichiro.den@canonical.com>

master-next--s2025.01.13-1 2025-02-12 17:13:41 UTC
UBUNTU: [Packaging] linux-tools: Fall back to old python perf path

Author: Juerg Haefliger
Author Date: 2025-01-23 16:06:35 UTC

UBUNTU: [Packaging] linux-tools: Fall back to old python perf path

BugLink: https://bugs.launchpad.net/bugs/2089411

linux-tools from older kernels without these patches provide the
perf python library in a different/broken path, so we have to look
there as well. Sigh.

Signed-off-by: Juerg Haefliger <juerg.haefliger@canonical.com>
Acked-by: Kevin Becker <kevin.becker@canonical.com>
Acked-by: Agathe Porte <agathe.porte@canonical.com>
Signed-off-by: Koichiro Den <koichiro.den@canonical.com>

master-next--s2024.12.02-1 2025-01-10 11:27:46 UTC
net: sched: fix ordering of qlen adjustment

Author: Lion Ackermann
Author Date: 2025-01-08 01:20:44 UTC

net: sched: fix ordering of qlen adjustment

Changes to sch->q.qlen around qdisc_tree_reduce_backlog() need to happen
_before_ a call to said function because otherwise it may fail to notify
parent qdiscs when the child is about to become empty.

Signed-off-by: Lion Ackermann <nnamrec@gmail.com>
Acked-by: Toke Høiland-Jørgensen <toke@toke.dk>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit 5eb7de8cd58e73851cd37ff8d0666517d9926948)
CVE-2024-53164
Signed-off-by: Ian Whitfield <ian.whitfield@canonical.com>
Acked-by: Magali Lemes <magali.lemes@canonical.com>
Acked-by: Benjamin M Romer <benjamin.romer@canonical.com>
Signed-off-by: Manuel Diewald <manuel.diewald@canonical.com>

lowlatency-next--2024.10.28-1--auto 2024-12-04 02:48:36 UTC
UBUNTU: Ubuntu-lowlatency-6.8.0-50.51.1

Author: Ubuntu Kernel Bot
Author Date: 2024-12-04 02:48:36 UTC

UBUNTU: Ubuntu-lowlatency-6.8.0-50.51.1

Signed-off-by: Ubuntu Kernel Bot <ubuntu-kernel-bot@canonical.com>

1 → 100 of 125 results
This repository contains Public information 
Everyone can see this information.