100 Commits
Author SHA1 Message Date
CKI KWF Bot e8f60c28b2 [redhat] kernel-6.12.0-266.el10
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>
2026-09-04 02:47:26 -04:00
CKI KWF Bot e5bfbc5d56 Merge: Merge-up tag 'kernel-6.12.0-264.1.1.el10_3' into centos-stream/main
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3390

Merge the kernel MR's from RHEL-10.3 to centos-10/main.

MR for inclusion is :
https://gitlab.com/redhat/rhel/src/kernel/rhel-10/-/merge_requests/1832

Signed-off-by: Shivani Chandanshive schandan@redhat.com

Approved-by: Oleksii Baranov <olebaran@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-09-04 06:45:42 +00:00
CKI KWF Bot 5133ca4c80 Merge: [redhat] kabi/show-kabi: update stablelist file header
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3397

JIRA: INTERNAL
Upstream Status: RHEL only, https://gitlab.com/cki-project/kernel-ark

The kabi_stablelist file header is hard-coded to rhel9 and should reference RHEL_MAJOR instead.

Signed-off-by: Scott Weaver <scweaver@redhat.com>

Approved-by: Jarod Wilson <jarod@redhat.com>
Approved-by: Čestmír Kalina <ckalina@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-09-04 06:45:40 +00:00
CKI KWF Bot baf0ef0d5f Merge: Add Power11 capability support for Nested PAPR guests
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3388

Description: Add Power11 capability support for Nested PAPR guests

JIRA: https://issues.redhat.com/browse/RHEL-190876

Omitted-fix: e4de1b9cb3b5c981e4fe9bca253a7fb9161f5acd ("powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors")

Build Info: https://brewweb.engineering.redhat.com/brew/taskinfo?taskID=71691947

Tested: Verified Brew build test kernel RPMs

Signed-off-by: Mamatha Inamdar <minamdar@redhat.com>

Approved-by: Steve Best <sbest@redhat.com>
Approved-by: Audra Mitchell <aubaker@redhat.com>
Approved-by: Tony Camuso <tcamuso@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-09-04 06:45:39 +00:00
CKI KWF Bot ce98a89dba Merge: net: stmmac: backport multi-channel IRQs patches
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3360

## Summary of Changes

Backport multi-channel IRQ support in `dwmac-s32`.

## Approved Development Ticket(s)

JIRA: https://redhat.atlassian.net/browse/RHEL-168971

Signed-off-by: Jared Kangas <jkangas@redhat.com>

Approved-by: Michal Schmidt <mschmidt@redhat.com>
Approved-by: Eric Chanudet <echanude@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-09-04 06:45:37 +00:00
CKI KWF Bot c479115f05 Merge: S32G: update drivers to v7.2
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3359

## Summary of Changes

Update S32G-related drivers to sync with v7.2. This excludes a couple of areas:

* `hwmon` changes will be broken out into their own MR since there are nontrivial changes that are currently in `linux-next`.
* `stmmac` requires `ethernet` acks, so related changes are broken out to !3360 to make review easier and avoid blocking the rest of the S32G updates on those patches. Changes not specific to S32G are omitted since they'll presumably be picked up in the next subsystem update.

## Approved Development Ticket(s)

JIRA: https://redhat.atlassian.net/browse/RHEL-248519

Signed-off-by: Jared Kangas <jkangas@redhat.com>

Approved-by: Tony Camuso <tcamuso@redhat.com>
Approved-by: Eric Chanudet <echanude@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-09-04 06:45:35 +00:00
CKI KWF Bot cf47d0d0a6 Merge: replace kernel-qe-ci gating with osci tier0 plans
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2872

JIRA: https://redhat.atlassian.net/browse/RHEL-186035

Upstream-status: RHEL-Only

Signed-off-by: Bruno Goncalves <bgoncalv@redhat.com>

Approved-by: Jan Stancek <jstancek@redhat.com>
Approved-by: Oleksii Baranov <olebaran@redhat.com>
Approved-by: Mike Stowell <423711-stowellm@users.noreply.gitlab.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-09-04 06:45:34 +00:00
CKI KWF Bot 4650979d68 Merge: CVE-2026-46189: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2652

JIRA: https://redhat.atlassian.net/browse/RHEL-179960
CVE: CVE-2026-46189

Backported from tree(s): linux

```
commit e38e86995df27f1f854063dab1f0c6a513db3faf
Author: Jason Gunthorpe <jgg@nvidia.com>
Date:   Tue Apr 28 13:17:43 2026 -0300

    RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path

    Sashiko points out that pvrdma_uar_free() is already called within
    pvrdma_dealloc_ucontext(), so calling it before triggers a double free.

    Cc: stable@vger.kernel.org
    Fixes: 29c8d9eba5 ("IB: Add vmw_pvrdma driver")
    Link: https://sashiko.dev/#/patchset/0-v1-e911b76a94d1%2B65d95-rdma_udata_rep_jgg%40nvidia.com?part=4
    Link: https://patch.msgid.link/r/10-v1-41f3135e5565+9d2-rdma_ai_fixes1_jgg@nvidia.com
    Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>

```

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
[^footer]: Created 2026-05-28 14:29 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer]

Approved-by: roverflow <vmulugun@redhat.com>
Approved-by: Vitaly Kuznetsov <vkuznets@redhat.com>
Approved-by: Kamal Heib <kheib@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-09-04 06:45:33 +00:00
CKI KWF Bot 0164bebc29 [redhat] kernel-6.12.0-265.el10
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>
2026-09-01 03:29:16 -04:00
CKI KWF Bot d0632aa0dd Merge: redhat: bump RHEL_MINOR to 10.4
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3363

redhat: bump RHEL_MINOR to 10.4

JIRA: INTERNAL
Upstream Status: RHEL only

RHEL 10.4

Signed-off-by: Oleksii Baranov <olebaran@redhat.com>

Approved-by: Jan Stancek <jstancek@redhat.com>
Approved-by: Jarod Wilson <jarod@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-09-01 07:27:29 +00:00
CKI KWF Bot 3f9ecbf580 Merge: [RHEL 10.4] hwmon: (k10temp) Add per-CCD temperature monitoring for Zen5 Turin
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3358

JIRA: https://redhat.atlassian.net/browse/RHEL-247220

commit 8440d5aca227d623801b5f8a2b9e3d86b7daa8bf
Author: Gabriel Ford <gabriel@gford.dev>
Date:   Thu Aug 13 17:02:08 2026 +0000

    hwmon: (k10temp) Add per-CCD temperature monitoring for Zen5 Turin

    Add support for per-CCD temperature monitoring on Zen 5 Turin (EPYC 9005)
    CPUs, as they fall into a separate model range with a different offset
    and a higher maximum CCD count than their desktop counterparts. As such,
    this patch also updates the driver to support CPUs with up to 16 CCDs.
    Tested and working on an EPYC 9555P.

    Signed-off-by: Gabriel Ford <gabriel@gford.dev>
    Link: https://lore.kernel.org/r/20260813170232.3841-1-gabriel@gford.dev
    Signed-off-by: Guenter Roeck <linux@roeck-us.net>

(cherry picked from commit 8440d5aca227d623801b5f8a2b9e3d86b7daa8bf)
Assisted-by: Patchpal
Signed-off-by: Dennis Chen <dechen@redhat.com>

Approved-by: Steve Best <sbest@redhat.com>
Approved-by: David Arcari <darcari@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-09-01 07:27:27 +00:00
CKI KWF Bot 5856aaa753 Merge: s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3355

s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks

JIRA: https://redhat.atlassian.net/browse/RHEL-248146

commit 337bd95507a16063687cfc286ea90de5cca48c37

Author: Thomas Richter tmricht@linux.ibm.com

Date: Tue Aug 11 15:39:01 2026 +0200

```
    s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks

    The command 'perf stat -e cycles -- <command>' crashes the kernel
    when CPUs are hotplug added during that run.

    Root cause is the allocation of struct cpu_cf_events at first
    event initialization. The allocation is dynamic and the first
    event that has task context creates such a structure for
    each online CPU. This is not sufficient. CPUs may be offline
    during event creation and can be set online during the
    perf run time. For example commands

     # echo 0 > /sys/devices/system/cpu/cpu1/online
     # perf stat -e cycles -i -- stress-ng -t10s --matrix X
     # sleep 1
     # echo 1 > /sys/devices/system/cpu/cpu1/online

    create an event for CPUs 0,2-X. Since the events are created with
    task-context, the scheduler will eventually schedule the program
    on CPU1. This CPU has not created and initialized any per
    CPU event infrastructure as that CPU was not online at the time
    of the perf invocation. Thus when the scheduler runs stress-ng
    on CPU1, the function cpumf_pmu_add() refers to a NULL pointer:

     struct cpu_cf_events *cpuhw = this_cpu_cfhw();

    This function call is invoked after the task stress-ng has been
    made runnable on CPU1. And this_cpu_cfhw() returns NULL.

    The result is a panic:
    Unable to handle kernel pointer dereference in virtual kernel address space
    Failing address: 0000000000000000 TEID: 0000000000000483
    ....
    Krnl PSW : 0404d00180000000 000003ef8291fd0c (cpumf_pmu_add+0x3c/0x80)
    ....
    Call Trace:
     [<000003ef8291fd0c>] cpumf_pmu_add+0x3c/0x80
     [<000003ef82bb5e3e>] event_sched_in+0xae/0x190
     [<000003ef82bb60d6>] merge_sched_in+0x1b6/0x390
     [<000003ef82bb65b8>] visit_groups_merge.constprop.0.isra.0+0x308/0x5b0
     [<000003ef82bb689a>] pmu_groups_sched_in+0x3a/0x50
     [<000003ef82bb6a30>] ctx_sched_in+0x180/0x260
     [<000003ef82bb780c>] perf_event_context_sched_in+0x11c/0x2d0
     [<000003ef82bb79ee>] __perf_event_task_sched_in+0x2e/0xc0
     [<000003ef82994834>] finish_task_switch.isra.0+0x1a4/0x250
    ....
    Last Breaking-Event-Address:
     [<000003ef8291f1d8>] this_cpu_cfhw+0x38/0x40

    The issue arises only in per-task context when the CPUMF facility is
    used and the scheduler picks a random CPU for such a process to run on.
    The scheduler enables the CPUMF infrastructure via PMU callback
    functions pmu::add() and pmu::del().

    Introduce a CPU hotplug prepare/dead callback pair which creates and
    removes the per CPU counter data while the CPU is offline. Count the
    users which track every CPU (cpu == -1), that is perf_event_open()
    events with task context and /dev/hwctr device sessions, in the new
    counter cpu_cf_root::tskcnt, protected by pmc_reserve_mutex.
    This ensures the infrastructure is available when
    new CPU is selected to run the per-task context process.

    In cpum_cf_free_root() and cpum_cf_free_cpu() ensure the reference
    pointer to data structures is set to NULL before the data is freed
    to prevent interrupt handlers to access stale data.

    [gor@linux.ibm.com: change commit message]
    Fixes: 9b9cf3c77e ("s390/cpum_cf: rework PER_CPU_DEFINE of struct cpu_cf_events")
    Cc: stable@vger.kernel.org # v6.5+
    Suggested-by: Heiko Carstens <hca@linux.ibm.com>
    Suggested-by: Christian Borntraeger <borntraeger@linux.ibm.com>
    Assisted-by: Claude:claude-sonnet-5
    Signed-off-by: Thomas Richter <tmricht@linux.ibm.com>
    Acked-by: Heiko Carstens <hca@linux.ibm.com>
    Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
```

Signed-off-by: Jan Polensky <jpolensk@redhat.com>

Approved-by: Steve Best <sbest@redhat.com>
Approved-by: Tony Camuso <tcamuso@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-09-01 07:27:26 +00:00
CKI KWF Bot bfba0a0f8a Merge: fs/resctrl: Updates to Add "*" shorthand to set io_alloc CBM for all domains
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3346

Description:
updates to Add "*" shorthand to set io_alloc CBM for all domains

JIRA: https://issues.redhat.com/browse/RHEL-174711

Signed-off-by: Steve Best <sbest@redhat.com>

Approved-by: Tony Camuso <tcamuso@redhat.com>
Approved-by: David Arcari <darcari@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>
Approved-by: Gavin Shan <gshan@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-09-01 07:27:24 +00:00
CKI KWF Bot 32dd0177ae Merge: i3c: master: v6.19 sync and ACPI support
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3302

JIRA: https://issues.redhat.com/browse/RHEL-143335

Update the i3c master driver with all features added up to upstream
v6.19 and most fixes up to v7.2-rc7.

ACPI support for i3c is taken from one patch series in linux-next.

---

This MR includes a partial backport for only the hunks affecting i3c
from a couple treewide patches upstream. All of these fixes are related
to excluded hunks.

Omitted-fix: fd1d6b9d13f3 (`xz: fix arm fdt compile error for kmalloc replacement`)

Omitted-fix: 96a7b71c4438 (`ubd: Use pointer-to-pointers for io_thread_req arrays`)

Omitted-fix: 795469820c63 (`kcsan: test: Adjust "expect" allocation type for kmalloc_obj`)

Omitted-fix: 5548dd7fa845 (`tools/testing: fix testing/vma and testing/radix-tree build`)

Omitted-fix: 405ca72dc589 (`landlock: Fix formatting`)

Omitted-fix: 4c0134639694 (`KVM: PPC: e500: Fix build error due to using kmalloc_obj() with wrong type`)

Omitted-fix: 2d2b5507e598 (`btrfs: replace kcalloc() calls to kzalloc_objs()`)

Omitted-fix: 9f4ab0787e7b (`btrfs: do more kmalloc_obj()/kmalloc_objs() conversions`)

Omitted-fix: 37f1f51fba1a (`btrfs: convert kmalloc_array to kmalloc_objs in btrfs_calc_avail_data_space()`)

Omitted-fix: 4c6d43db2a4d (`net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone`)

Signed-off-by: Jennifer Berringer <jberring@redhat.com>

Approved-by: Mark Langsdorf <mlangsdo@redhat.com>
Approved-by: Mark Salter <msalter@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-09-01 07:27:23 +00:00
CKI KWF Bot 92d3079879 Merge: arm64: Add support for TSV110 Spectre-BHB mitigation
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3073

Backport upstream commit e3baa5d4b361 to add Spectre-BHB mitigation
support for the HiSilicon TSV110 processor.

TSV110 is vulnerable to Spectre-BHB, but it is missing from the existing
spectre_bhb_k32_list. As a result, the kernel may fail to select the
32-branch software mitigation when a suitable firmware workaround is not
available.

This change adds MIDR_HISI_TSV110 to the existing mitigation list. It
does not introduce new mitigation code or affect other ARM64 processors.

JIRA: https://issues.redhat.com/browse/RHEL-224485

Upstream commit:
e3baa5d4b361 ("arm64: Add support for TSV110 Spectre-BHB mitigation")

Signed-off-by: Steve Dunnagan <sdunnaga@redhat.com>

Approved-by: Charles Mirabile <cmirabil@redhat.com>
Approved-by: Mark Langsdorf <mlangsdo@redhat.com>
Approved-by: Mark Salter <msalter@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-09-01 07:27:21 +00:00
CKI KWF Bot 85753d3e48 Merge: rcu: Fix rcu_read_unlock() deadloop due to softirq
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2851

JIRA: https://issues.redhat.com/browse/RHEL-178446

There is a deadloop in rcu_read_unlock() that can be hit by ftrace (in particular while running the LTP ftrace-stress-test). When this happened, other processes get stuck in softlockup.

Signed-off-by: Jerome Marchand <jmarchan@redhat.com>

Approved-by: Phil Auld <pauld@redhat.com>
Approved-by: Waiman Long <longman@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-09-01 07:27:19 +00:00
CKI KWF Bot c9535ac102 [redhat] kernel-6.12.0-264.1.1.el10_3
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>
2026-08-31 09:19:23 +00:00
CKI KWF Bot 9d2c3bf254 Merge: CVE-2026-53153 kernel: mm/list_lru: drain before clearing xarray entry on reparent [rhel-10.3]
MR: https://gitlab.com/redhat/rhel/src/kernel/rhel-10/-/merge_requests/1832

JIRA: https://redhat.atlassian.net/browse/RHEL-227151
CVE: CVE-2026-53153

    commit 98733f3f0becb1ae0701d021c1748e974e5fa55c
    Author: Shakeel Butt <shakeel.butt@linux.dev>
    Date:   Mon Jun 1 09:15:01 2026 -0700

        mm/list_lru: drain before clearing xarray entry on reparent

Signed-off-by: Rafael Aquini <raquini@redhat.com>

Approved-by: Ricardo Robaina <rrobaina@redhat.com>
Approved-by: Jay Shin <jaeshin@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-31 09:18:00 +00:00
CKI KWF Bot cde8efee3f Merge: redhat: set defaults for RHEL 10.3
MR: https://gitlab.com/redhat/rhel/src/kernel/rhel-10/-/merge_requests/1850

JIRA: INTERNAL
Upstream Status: RHEL only

Now that we have forked from CentOS Stream, we need to switch the
release number to use the zstream scheme and update our default disttag
to match that used by the brew build environment for RHEL 10.3.

Signed-off-by: Shivani Chandanshive <schandan@redhat.com>

Approved-by: Jarod Wilson <jarod@redhat.com>
Approved-by: Tales da Aparecida <tales.aparecida@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>
Approved-by: Oleksii Baranov <olebaran@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-31 09:17:58 +00:00
CKI KWF Bot afa81ddbe0 [redhat] kernel-6.12.0-264.el10
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>
2026-08-23 14:52:58 -04:00
CKI KWF Bot 0a57f281ec Merge: net: Fix deadlock on netns change.
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2576

JIRA: https://redhat.atlassian.net/browse/RHEL-144808
Upstream Status: linux.git

Backport upstream commit 7ca486d08a30 ("rtnetlink: Create link directly in
target net namespace") and its dependencies, plus selftests.

Signed-off-by: Guillaume Nault <gnault@redhat.com>

Approved-by: Antoine Tenart <atenart@redhat.com>
Approved-by: José Ignacio Tornos Martínez <jtornosm@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:51:08 +00:00
CKI KWF Bot 618edff9f9 Merge: Backport AMD XDNA NPU driver from Linux 7.0.14
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3328

This backports the driver for the AMD XDNA NPU in AMD AI Ryzen processors, but does not enable it.

When temporarily enabled, the driver loads successfully on AMD Strix Point, Strix Halo, and Krackan Point processors.

JIRA: https://redhat.atlassian.net/browse/RHEL-222546

These fixes are false positives that do not affect the amdxdna driver:
Omitted-fix: fd1d6b9d13f3 ("xz: fix arm fdt compile error for kmalloc replacement")
Omitted-fix: 96a7b71c4438 ("ubd: Use pointer-to-pointers for io_thread_req arrays")
Omitted-fix: 795469820c63 ("kcsan: test: Adjust "expect" allocation type for kmalloc_obj")
Omitted-fix: 5548dd7fa845 ("tools/testing: fix testing/vma and testing/radix-tree build")
Omitted-fix: 405ca72dc589 ("landlock: Fix formatting")
Omitted-fix: 4c0134639694 ("KVM: PPC: e500: Fix build error due to using kmalloc_obj() with wrong type")
Omitted-fix: 4c6d43db2a4d ("net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone")
Omitted-fix: c7ee592dccab ("drm/rockchip: include drm_print.h where needed")
Omitted-fix: cb345f954eac ("drm/panfrost: Fix scheduler workqueue bug")
Omitted-fix: 2d2b5507e598 ("btrfs: replace kcalloc() calls to kzalloc_objs()")
Omitted-fix: 9f4ab0787e7b ("btrfs: do more kmalloc_obj()/kmalloc_objs() conversions")
Omitted-fix: 37f1f51fba1a ("btrfs: convert kmalloc_array to kmalloc_objs in btrfs_calc_avail_data_space()")
Omitted-fix: 218b15a3e975 ("accel/rocket: Fix Rockchip NPU compilation")

These fixes are part of 7.1 and 7.2, and will be included in the DRM backport:
Omitted-fix: f844177c6811 ("accel/amdxdna: Handle DETACH_DEBUG_BO through config_debug_bo path")
Omitted-fix: 62c1671f6454 ("accel/amdxdna: Return errors for failed debug BO commands")
Omitted-fix: 7caf2a2351d4 ("accel/amdxdna: Use caller client for debug BO sync")
Omitted-fix: e35c9cf55128 ("accel/amdxdna: Prevent PM resume deadlock in hwctx_sync_debug_bo()")
Omitted-fix: ec3304ddfd99 ("accel/amdxdna: Fix use-after-free in debug BO command handling")
Omitted-fix: c8d2530791cb ("accel/amdxdna: Fix deadlock on debug BO command timeout")
Omitted-fix: d946347edc4f ("accel/amdxdna: Fix leak when pinning ubuf pages")
Omitted-fix: 457b046b7dfc ("accel/amdxdna: Remove mmap and export support for ubuf")
Omitted-fix: 1ba02717e821 ("accel/amdxdna: Fix VMA access race")
Omitted-fix: 2f41af638c92 ("accel/amdxdna: Fix mm_struct reference leak in aie2_populate_range()")
Omitted-fix: 5c72124186d6 ("accel/amdxdna: Fix notifier_wq lifetime race during device removal")
Omitted-fix: 63bbf9ac5dde ("accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap()")
Omitted-fix: 14f172eff9c1 ("accel/amdxdna: Fix potential amdxdna_umap lifetime race")
Omitted-fix: 8d51e0fd3e69 ("accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages()")
Omitted-fix: 4a19f7ab5972 ("accel/amdxdna: Fix locally exploitable BUG_ON in amdxdna_insert_pages()")
Omitted-fix: 6c916e301fa1 ("accel/amdxdna: Skip unmapped range in aie2_populate_range()")
Omitted-fix: c83ad8ea6b0a ("accel/amdxdna: Fix order of canceled mailbox messages")
Omitted-fix: 6e87001fe19f ("accel/amdxdna: Adjust size for copy_to_user()")
Omitted-fix: ada61841caed ("accel/amdxdna: Fix clflush buffer size")
Omitted-fix: 44d8fddf1c87 ("accel/amdxdna: Check init_srcu_struct() return value")
Omitted-fix: 261c1fe3327a ("accel/amdxdna: reject user command submission without a command BO")
Omitted-fix: 38953513d731 ("accel/amdxdna: reject command submission on devices without a submit op")
Omitted-fix: faebb7ba1ac6 ("accel/amdxdna: Fix use-after-free of mm_struct in job scheduler")
Omitted-fix: 18aaebdf4336 ("accel/amdxdna: Use unsigned long for nr_pages in amdxdna_hmm_register()")
Omitted-fix: 1dbbc7f98cde ("accel/amdxdna: Fix amdxdna_client lifetime race during device removal")
Omitted-fix: d1c73884858c ("accel/amdxdna: fix missing newline in pr_err message")
Omitted-fix: 506255d46bdb ("accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer")
Omitted-fix: 0f092793a7b5 ("accel/amdxdna: Check drmm_mutex_init() return value")

Signed-off-by: Peter Colberg <pcolberg@redhat.com>

Approved-by: Karol Herbst <kherbst@redhat.com>
Approved-by: marpagan <marpagan@redhat.com>
Approved-by: Anusha Srivatsa <asrivats@redhat.com>
Approved-by: John Wiele <jwiele@redhat.com>
Approved-by: Oliver Gutiérrez <ogutsua@protonmail.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:51:05 +00:00
CKI KWF Bot 19b3294cb3 Merge: sctp: validate cached peer INIT chunk in cookie
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3227

JIRA: https://issues.redhat.com/browse/RHEL-190192
CVE: CVE-2026-53246

Patch 1 is CVE fix, and patch 2 is a similar fix for cookie.

Signed-off-by: Xin Long <lxin@redhat.com>

Approved-by: Jamie Bainbridge <jbainbri@redhat.com>
Approved-by: Marcelo Ricardo Leitner <mleitner@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:51:03 +00:00
CKI KWF Bot 6e25e46b40 Merge: CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3203

JIRA: https://redhat.atlassian.net/browse/RHEL-234289
CVE: CVE-2026-64564

Backported from tree(s): linux

```
sctp: don't free the ASCONF's own transport in DEL-IP processing

sctp_process_asconf() caches the transport the ASCONF chunk is processed
against in asconf->transport (== chunk->transport, set once in sctp_rcv()).
For an ASCONF located through its Address Parameter by
__sctp_rcv_asconf_lookup(), that cached transport corresponds to the
Address Parameter, which need not be the packet's source address.

sctp_process_asconf_param() rejects a DEL-IP for the packet source address
(ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport.
A single ASCONF can therefore carry, in order:

    [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0]

where L differs from the source. The DEL-IP for L passes the D8 check and
calls sctp_assoc_rm_peer() on the transport that asconf->transport still
points at, freeing it (RCU-deferred). The following wildcard DEL-IP then
reuses the now-dangling asconf->transport in sctp_assoc_set_primary() and
sctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed
transport (->ipaddr, ->state) and plants the dangling pointer into
asoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping
only the pointer that is no longer on the list, removes every real
transport, leaving the association with a transport_count of 0 and
primary_path/active_path pointing at freed memory.

Reject a DEL-IP that targets the transport the ASCONF is being processed
against, mirroring the existing source-address guard, so the wildcard
branch can never reuse a freed transport.

Fixes: 42e30bf346 ("[SCTP]: Handle the wildcard ADD-IP Address parameter")
Cc: stable@kernel.org
Signed-off-by: Jun Yang <junvyyang@tencent.com>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/tencent_73762ED1DF08CC9D5F5F61954B01350CFE0A@qq.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 9b2854f86f0b56e9027d68e7a3fc909d1a9b566f)

```

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
[^footer]: Created 2026-08-06 15:32 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer]

Approved-by: Xin Long <lxin@redhat.com>
Approved-by: Jamie Bainbridge <jbainbri@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:51:01 +00:00
CKI KWF Bot a0bcbb573b Merge: CVE-2026-64276: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3152

JIRA: https://redhat.atlassian.net/browse/RHEL-230267
CVE: CVE-2026-64276

Backported from tree(s): linux

```
Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count

rmi_f30_map_gpios() allocates gpioled_key_map with
min(gpioled_count, TRACKSTICK_RANGE_END) == at most 6 entries, but
rmi_f30_attention() iterates the full f30->gpioled_count (device query
register, range 0..31) and dereferences gpioled_key_map[i], and
input->keycodemax is set to the full gpioled_count while input->keycode
points at the 6-entry allocation.

A device that reports gpioled_count > 6 with GPIO support enabled
therefore causes an out-of-bounds read on the attention interrupt and
out-of-bounds read/write through the EVIOCGKEYCODE/EVIOCSKEYCODE ioctls,
which bound the index only against keycodemax. This is the same defect
as the F3A handler, which was copied from F30.

Size the keymap for the full gpioled_count; the mapping loop still
assigns only the first min(gpioled_count, TRACKSTICK_RANGE_END) entries.

Fixes: 3e64fcbdbd ("Input: synaptics-rmi4 - limit the range of what GPIOs are buttons")
Cc: stable@vger.kernel.org
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Link: https://patch.msgid.link/20260614-b4-disp-818d6bda-v1-2-cf39a3615085@proton.me
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
(cherry picked from commit d577e46785d45484b2ab7e7309c49b18764bf56c)

```

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
[^footer]: Created 2026-08-05 23:53 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer]

Approved-by: Tony Camuso <tcamuso@redhat.com>
Approved-by: Benjamin Tissoires <benjamin.tissoires@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:50:59 +00:00
CKI KWF Bot 4a59f80382 Merge: sctp: prevent peer transport count overflow [10.3]
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3016

JIRA: https://redhat.atlassian.net/browse/RHEL-214458

Backported from tree(s): net

```
sctp: prevent peer transport count overflow

sctp_assoc_add_peer() increments the association's 16-bit transport_count
for every new unique peer. Adding the 65,536th transport wraps the count to
zero.

SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,
then copies one sockaddr_storage for every entry in transport_addr_list.
After the wrap, a diagnostic dump reserves an empty payload and writes
8 MiB of peer addresses past the skb tail.

Reject a new unique peer when transport_count has reached U16_MAX. Perform
the check after the existing-peer lookup so a duplicate address continues
to return its existing transport at the limit.

Fixes: 8f840e47f1 ("sctp: add the sctp_diag.c file")
Cc: stable@vger.kernel.org
Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260725032053.521705-1-manizada@pm.me
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit bd0e9289e2642f6a5c54faad304ce0f41e926d22)

```

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
[^footer]: Created 2026-07-28 15:17 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer]

Approved-by: Jay Shin <jaeshin@redhat.com>
Approved-by: Jamie Bainbridge <jbainbri@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:50:57 +00:00
CKI KWF Bot d3af6f158f Merge: redhat/configs: re-enable CONFIG_PT_RECLAIM
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2963

JIRA: https://redhat.atlassian.net/browse/RHEL-186753
Upstream Status: RHEL-only

The MM rebase to v6.16 (RHEL-145694), brought in the fixes needed to
avoid the race that triggers a UAF in page->ptl during concurrent
MADV_DONNEED calls (RHEL-185104). Therefore, re-enable
CONFIG_PT_RECLAIM.

This essentially reverts commit b3fece8fc9.

Signed-off-by: Luiz Capitulino <luizcap@redhat.com>

Approved-by: Rafael Aquini <raquini@redhat.com>
Approved-by: Ricardo Robaina <rrobaina@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:50:55 +00:00
CKI KWF Bot 0c6a1a2f4c Merge: sctp: hold socket lock when dumping endpoints in sctp_diag
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2956

JIRA: https://redhat.atlassian.net/browse/RHEL-137943

    7d8297e26b4e ("sctp: hold socket lock when dumping endpoints in sctp_diag")

Signed-off-by: Jamie Bainbridge <jbainbri@redhat.com>

Approved-by: Xin Long <lxin@redhat.com>
Approved-by: Marcelo Ricardo Leitner <mleitner@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:50:52 +00:00
CKI KWF Bot 16f09a98b2 Merge: rh_message.h: Disable ConnectX-10 NVLink-C2C device
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2943

JIRA: https://redhat.atlassian.net/browse/RHEL-211847

Update rh_messages.h to be in line with hardware-removal-support.git commit
59b817e ("Merge branch 'RHEL-142604' into 'main'")

Signed-off-by: Benjamin Poirier <bpoirier@redhat.com>

Approved-by: Scott Weaver <scweaver@redhat.com>
Approved-by: Kamal Heib <kheib@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:50:50 +00:00
CKI KWF Bot 0d3943da43 Merge: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2915

# Merge Request Required Information

## Summary of Changes

KVM: x86: Fix shadow paging use-after-free due to unexpected role

```
JIRA: https://redhat.atlassian.net/browse/RHEL-192401
CVE: CVE-2026-53359
Backported from tree(s): linux

KVM: x86: Fix shadow paging use-after-free due to unexpected role

Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due
to unexpected GFN") fixed a shadow paging mismatch between stored and
computed GFNs; the bug could be triggered by changing a PDE mapping from
outside the guest, and then deleting a memslot.  The rmap_remove()
call would miss entries created after the PDE change because the GFN
of the leaf SPTE does not match the GFN of the struct kvm_mmu_page.

A similar hole however remains if the modified PDE points to a non-leaf
page.  In this case the gfn can be made to match, but the role does not
match: the original large 2MB page creates a kvm_mmu_page with direct=1,
while the new 4KB needs a kvm_mmu_page with direct=0.  However,
kvm_mmu_get_child_sp() does not compare the role, and therefore reuses
the page.

The next step is installing a leaf (4KB) SPTE on the new path which
records an rmap entry under the gfn resolved by the walk.  But when
that child is zapped its parent kvm_mmu_page has direct=1 and
kvm_mmu_page_get_gfn() computes the gfn for the 4KB page as
sp->gfn + index instead of using sp->shadowed_translation[] (or sp->gfns[]
in older kernels).  It therefore fails to remove the recorded entry.

When the memslot is dropped the shadow page is freed but the rmap
entry survives, as in the scenario that was already fixed.  Code that
later walks that gfn (dirty logging, MMU notifier invalidation, and
so on) dereferences an sptep that lies in the freed page, causing the
use-after-free.

Fixes: 2032a93d66 ("KVM: MMU: Don't allocate gfns page for direct mmu pages")
Reported-by: Hyunwoo Kim <imv4bel@gmail.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Aidan Wallace <awallace@redhat.com>
(cherry picked from commit 81ccda30b4e83d8f5cc4fd50503c44e3a33abfeb)
```

KVM: x86: Fix shadow paging use-after-free due to unexpected GFN

```
JIRA: https://redhat.atlassian.net/browse/RHEL-186699
CVE: CVE-2026-46113
Backported from tree(s): linux

KVM: x86: Fix shadow paging use-after-free due to unexpected GFN

The shadow MMU computes GFNs for direct shadow pages using sp->gfn plus
the SPTE index. This assumption breaks for shadow paging if the guest
page tables are modified between VM entries (similar to commit
aad885e77496, "KVM: x86/mmu: Drop/zap existing present SPTE even
when creating an MMIO SPTE", 2026-03-27).  The flow is as follows:

- a PDE is installed for a 2MB mapping, and a page in that area is
  accessed.  KVM creates a kvm_mmu_page consisting of 512 4KB pages;
  the kvm_mmu_page is marked by FNAME(fetch) as direct-mapped because
  the guest's mapping is a huge page (and thus contiguous).

- the PDE mapping is changed from outside the guest.

- the guest accesses another page in the same 2MB area.  KVM installs
  a new leaf SPTE and rmap entry; the SPTE uses the "correct" GFN
  (i.e. based on the new mapping, as changed in the previous step) but
  that GFN is outside of the [sp->gfn, sp->gfn + 511] range; therefore
  the rmap entry cannot be found and removed when the kvm_mmu_page
  is zapped.

- the memslot that covers the first 2MB mapping is deleted, and the
  kvm_mmu_page for the now-invalid GPA is zapped.  However, rmap_remove()
  only looks at the [sp->gfn, sp->gfn + 511] range established in step 1,
  and fails to find the rmap entry that was recorded by step 3.

- any operation that causes an rmap walk for the same page accessed
  by step 3 then walks a stale rmap and dereferences a freed kvm_mmu_page.
  This includes dirty logging or MMU notifier invalidations (e.g., from
  MADV_DONTNEED).

The underlying issue is that KVM's walking of shadow PTEs assumes that
if a SPTE is present when KVM wants to install a non-leaf SPTE, then the
existing kvm_mmu_page must be for the correct gfn.  Because the only way
for the gfn to be wrong is if KVM messed up and failed to zap a SPTE...
which shouldn't happen, but *actually* only happens in response to a
guest write.

That bug dates back literally forever, as even the first version of KVM
assumes that the GFN matches and walks into the "wrong" shadow page.
However, that was only an imprecision until 2032a93d66 ("KVM: MMU:
Don't allocate gfns page for direct mmu pages") came along.

Fix it by checking for a target gfn mismatch and zapping the existing
SPTE.  That way the old SP and rmap entries are gone, KVM installs
the rmap in the right location, and everyone is happy.

Fixes: 2032a93d66 ("KVM: MMU: Don't allocate gfns page for direct mmu pages")
Fixes: 6aa8b732ca ("kvm: userspace interface")
Reported-by: Alexander Bulekov <bkov@amazon.com>
Reported-by: Fred Griffoul <fgriffo@amazon.co.uk>
Cc: stable@vger.kernel.org
Signed-off-by: Sean Christopherson <seanjc@google.com>
Link: https://patch.msgid.link/20260503201029.106481-1-pbonzini@redhat.com/
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
(cherry picked from commit 0cb2af2ea66ad8ff195c156ea690f11216285bdf)
Signed-off-by: Aidan Wallace <awallace@redhat.com>
```

## Approved Development Ticket(s)

JIRAs:

    https://redhat.atlassian.net/browse/RHEL-192401

    https://redhat.atlassian.net/browse/RHEL-186699

<details>
<summary>Click for formatting instructions</summary>

 Please follow the CentOS Stream [contribution documentation](https://docs.centos.org/centos-stream-docs/contributors-guide/) for how to file this ticket and have it approved.

List tickets each on their own line of this description using the format "Resolves: RHEL-76229", "Related: RHEL-76229" or "Reverts: RHEL-76229", as appropriate.

</details>

Approved-by: Paolo Bonzini <bonzini@gnu.org>
Approved-by: Maxim Levitsky <mlevitsk@redhat.com>
Approved-by: Vitaly Kuznetsov <vkuznets@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:50:48 +00:00
CKI KWF Bot 09a534b1d6 Merge: firmware: arm_ffa: driver update to v7.2
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2908

JIRA: https://issues.redhat.com/browse/RHEL-179031

JIRA: https://issues.redhat.com/browse/RHEL-183180

Update the ARM Firmware Framework driver from v6.15 to v7.2-rc4.

Omitted-fix: 677042afb97ac (`tpm: tpm_crb_ffa: revert defered_probed when tpm_crb_ffa is built-in`)

Signed-off-by: Jennifer Berringer <jberring@redhat.com>

Approved-by: Mark Langsdorf <mlangsdo@redhat.com>
Approved-by: ekovsky <ekovsky@redhat.com>
Approved-by: Charles Mirabile <cmirabil@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:50:46 +00:00
CKI KWF Bot 8b335a099f Merge: CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2800

JIRA: https://redhat.atlassian.net/browse/RHEL-188204
CVE: CVE-2026-52924

Backported from tree(s): linux

```
sctp: purge outqueue on stale COOKIE-ECHO handling

sctp_stream_update() is only invoked when the association is moved into
COOKIE_WAIT during association setup/reconfiguration. In this path, the
outbound stream scheduler state (stream->out_curr) is expected to be
clean, since no user data should have been transmitted yet unless the
state machine has already partially progressed.

However, a corner case exists in sctp_sf_do_5_2_6_stale(): when a
Stale Cookie ERROR is received, the association is rolled back from
COOKIE_ECHOED to COOKIE_WAIT. In this scenario, user data may already
have been queued and even bundled with the COOKIE-ECHO chunk.

During the rollback, sctp_stream_update() frees the old stream table
and installs a new one, but it does not invalidate stream->out_curr.
As a result, out_curr may still point to a freed sctp_stream_out
entry from the previous stream state.

Later, SCTP scheduler dequeue paths (FCFS, RR, PRIO, etc.) rely on
stream->out_curr->ext, which can lead to use-after-free once the old
stream state has been released via sctp_stream_free().

This results in crashes such as (reported by Yuqi):

  BUG: KASAN: slab-use-after-free in sctp_sched_fcfs_dequeue+0x13a/0x140
  Read of size 8 at addr ff1100004d4d3208 by task mini_poc/9312
  CPU: 1 UID: 1001 PID: 9312 Comm: mini_poc Not tainted
     7.1.0-rc1-00305-gbd3a4795d574 #5 PREEMPT(full)
   sctp_sched_fcfs_dequeue+0x13a/0x140
   sctp_outq_flush+0x1603/0x33e0
   sctp_do_sm+0x31c9/0x5d30
   sctp_assoc_bh_rcv+0x392/0x6f0
   sctp_inq_push+0x1db/0x270
   sctp_rcv+0x138d/0x3c10

Fix this by fully purging the association outqueue when handling the
Stale Cookie case. This ensures all pending transmit and retransmit
state is dropped, and any scheduler cached pointers are invalidated,
making it safe to rebuild stream state during COOKIE_WAIT restart.

Updating only stream->out_curr would be insufficient, since queued
and retransmittable data would still reference the old stream state and
trigger later use-after-free in dequeue paths.

Fixes: 5bbbbe32a4 ("sctp: introduce stream scheduler foundations")
Reported-by: Yuan Tan <yuantan098@gmail.com>
Reported-by: Yifan Wu <yifanwucs@gmail.com>
Reported-by: Juefei Pu <tomapufckgml@gmail.com>
Reported-by: Zhengchuan Liang <zcliangcn@gmail.com>
Reported-by: Xin Liu <bird@lzu.edu.cn>
Reported-by: Yuqi Xu <xuyq21@lenovo.com>
Reported-by: Ren Wei <n05ec@lzu.edu.cn>
Signed-off-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/94318159b9052907a6cbb7256aee8b5f8dfbfccb.1780510304.git.lucien.xin@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit e374b22e9b07b72a25909621464ff74096151bfb)

```

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
[^footer]: Created 2026-06-24 17:09 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer]

Approved-by: Xin Long <lxin@redhat.com>
Approved-by: Jarod Wilson <jarod@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:50:44 +00:00
CKI KWF Bot 3a4c716a67 Merge: CVE-2026-31669: mptcp: fix slab-use-after-free in __inet_lookup_established
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2479

JIRA: https://redhat.atlassian.net/browse/RHEL-171511
CVE: CVE-2026-31669

```
commit 9b55b253907e7431210483519c5ad711a37dafa1
Author: Jiayuan Chen <jiayuan.chen@linux.dev>
Date:   Mon Apr 6 11:15:10 2026 +0800

    mptcp: fix slab-use-after-free in __inet_lookup_established

    The ehash table lookups are lockless and rely on
    SLAB_TYPESAFE_BY_RCU to guarantee socket memory stability
    during RCU read-side critical sections. Both tcp_prot and
    tcpv6_prot have their slab caches created with this flag
    via proto_register().

    However, MPTCP's mptcp_subflow_init() copies tcpv6_prot into
    tcpv6_prot_override during inet_init() (fs_initcall, level 5),
    before inet6_init() (module_init/device_initcall, level 6) has
    called proto_register(&tcpv6_prot). At that point,
    tcpv6_prot.slab is still NULL, so tcpv6_prot_override.slab
    remains NULL permanently.

    This causes MPTCP v6 subflow child sockets to be allocated via
    kmalloc (falling into kmalloc-4k) instead of the TCPv6 slab
    cache. The kmalloc-4k cache lacks SLAB_TYPESAFE_BY_RCU, so
    when these sockets are freed without SOCK_RCU_FREE (which is
    cleared for child sockets by design), the memory can be
    immediately reused. Concurrent ehash lookups under
    rcu_read_lock can then access freed memory, triggering a
    slab-use-after-free in __inet_lookup_established.

    Fix this by splitting the IPv6-specific initialization out of
    mptcp_subflow_init() into a new mptcp_subflow_v6_init(), called
    from mptcp_proto_v6_init() before protocol registration. This
    ensures tcpv6_prot_override.slab correctly inherits the
    SLAB_TYPESAFE_BY_RCU slab cache.

    Fixes: b19bc2945b ("mptcp: implement delegated actions")
    Cc: stable@vger.kernel.org
    Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
    Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
    Link: https://patch.msgid.link/20260406031512.189159-1-jiayuan.chen@linux.dev
    Signed-off-by: Jakub Kicinski <kuba@kernel.org>
```

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
[^footer]: Created 2026-04-28 12:12 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=12334433&issuetype=1&priority=4&summary=backporter+webhook+issue&components=kernel-workflow+/+backporter) [^footer]

Approved-by: Paolo Abeni <pabeni@redhat.com>
Approved-by: Davide Caratti <dcaratti@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:50:42 +00:00
CKI KWF Bot 4e43be9c27 Merge: net: lockless and NUMA aware skb_attempt_defer_free
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2445

JIRA: https://issues.redhat.com/browse/RHEL-123212

This should improve performances for a number of scenari on multi-NUMA hosts.

Signed-off-by: Antoine Tenart <atenart@redhat.com>

Approved-by: Jarod Wilson <jarod@redhat.com>
Approved-by: Xin Long <lxin@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:50:38 +00:00
CKI KWF Bot d6e9752f2d Merge: l2tp: stable backport for 10.3 phase 1
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2407

JIRA: https://redhat.atlassian.net/browse/RHEL-152732
Upstream Status: linux.git

L2TP fixes for RHEL 10.3.

Signed-off-by: Guillaume Nault <gnault@redhat.com>

Approved-by: Florian Westphal <fwestpha@redhat.com>
Approved-by: Antoine Tenart <atenart@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:50:35 +00:00
CKI KWF Bot 0278666955 Merge: mpls: stable backport for 10.3 phase 1
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2382

JIRA: https://redhat.atlassian.net/browse/RHEL-152709
Upstream Status: linux.git

MPLS fixes for RHEL 10.3.

Signed-off-by: Guillaume Nault <gnault@redhat.com>

Approved-by: Jamie Bainbridge <jbainbri@redhat.com>
Approved-by: Marcelo Ricardo Leitner <mleitner@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:50:33 +00:00
CKI KWF Bot a29e895ace Merge: ppp: stable backport for 10.3 phase 1
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2380

JIRA: https://redhat.atlassian.net/browse/RHEL-152724
Upstream Status: linux.git

PPP fixes for RHEL 10.3.

Signed-off-by: Guillaume Nault <gnault@redhat.com>

Approved-by: Jarod Wilson <jarod@redhat.com>
Approved-by: Paolo Abeni <pabeni@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:50:30 +00:00
CKI KWF Bot 1273f0fb36 Merge: srv6: stable backport for 10.3 phase 1
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2330

JIRA: https://redhat.atlassian.net/browse/RHEL-152736

 * 01c411238c06 seg6: Extend seg6_lookup_any_nexthop() with an oif argument
 * 3159671855d4 seg6: Call seg6_lookup_any_nexthop() from End.X behavior
 * a2840d4e2527 seg6: Allow End.X behavior to accept an oif
 * 04d752d60c19 selftests: seg6: Add test cases for End.X with link-local nexthop
 * db3e2ceab3c7 seg6: fix lenghts typo in a comment
 * 3bedaff19bd8 selftests: seg6: fix instaces typo in comments
 * 064137935262 ipv6: add NULL checks for idev in SRv6 paths

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
[^footer]: Created 2026-03-31 04:59 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=12334433&issuetype=1&priority=4&summary=backporter+webhook+issue&components=kernel-workflow+/+backporter) [^footer]

Approved-by: Guillaume Nault <gnault@redhat.com>
Approved-by: Florian Westphal <fwestpha@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-23 18:50:27 +00:00
CKI KWF Bot e2de28aaf5 [redhat] kernel-6.12.0-263.el10
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>
2026-08-21 05:21:08 -04:00
CKI KWF Bot d66016048e Merge: mm: consider non-anon swap cache folios in folio_expected_ref_count()
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3330

JIRA: https://redhat.atlassian.net/browse/RHEL-224504
Upstream Status: v6.19-rc4
Tested: PCDIMM can be hot removed after stress-ng workload

This picks upstream commit f183663901f2 ("mm: consider non-anon swap cache
folios in folio_expected_ref_count()"), which corrects the reference count
for non-anon swap cache folios. Otherwise, the hot added PCDIMM can't be
hot removed in an aarch64 guest after the excercise with 'stress-ng'.

Signed-off-by: Gavin Shan <gshan@redhat.com>

Approved-by: Waiman Long <longman@redhat.com>
Approved-by: Rafael Aquini <raquini@redhat.com>
Approved-by: Eric Auger <eric.auger@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-21 09:19:36 +00:00
CKI KWF Bot 8456a25e8b Merge: dm cache policy smq: check allocation under invalidate lock
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3301

JIRA: https://issues.redhat.com/browse/RHEL-231823
CVE: CVE-2026-53062
Tested: Reproducer and dm cache tests
Upstream Status: kernel/git/torvalds/linux.git

commit d3f0a606b9f278ece8a0df626ded9c4044071235
Author: Guangshuo Li <lgs201920130244@gmail.com>
Date:   Fri May 29 23:57:45 2026 +0800

    dm cache policy smq: check allocation under invalidate lock

    commit 2d1f7b65f5de ("dm cache policy smq: fix missing locks in
    invalidating cache blocks") added mq->lock around the destructive part of
    smq_invalidate_mapping(), but left the e->allocated check outside the
    critical section.

    That leaves a check-then-act race. Two concurrent invalidators can both
    observe e->allocated as true before either of them takes mq->lock. The
    first invalidator that acquires the lock removes the entry from the
    queues and hash table and then calls free_entry(), which clears
    e->allocated and puts the entry back on the free list. The second
    invalidator can then acquire mq->lock and continue with the stale result
    of the unlocked check.

    This can corrupt the SMQ queues or hash table by deleting an entry that
    is no longer on those structures. It can also hit the allocation check in
    free_entry() when the same entry is freed again.

    Move the allocation check under mq->lock so the predicate and the
    destructive operations are serialized by the same lock.

    Fixes: 2d1f7b65f5de ("dm cache policy smq: fix missing locks in invalidating cache blocks")
    Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
    Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>

Signed-off-by: Benjamin Marzinski <bmarzins@redhat.com>

Approved-by: Matthew Sakai <msakai@redhat.com>
Approved-by: Ming Hung Tsai <mtsai@redhat.com>
Approved-by: Kenneth Raeburn <raeburn@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-21 09:19:35 +00:00
CKI KWF Bot 50ebb3393f Merge: CVE-2026-43493 kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests [rhel-10.3]
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3255

JIRA: https://redhat.atlassian.net/browse/RHEL-226716
CVE: CVE-2026-43493

    commit 915b692e6cb723aac658c25eb82c58fd81235110
    Author: Herbert Xu <herbert@gondor.apana.org.au>
    Date:   Thu Apr 16 17:00:50 2026 +0800

        crypto: pcrypt - Fix handling of MAY_BACKLOG requests

Signed-off-by: Ricardo Robaina <rrobaina@redhat.com>

Approved-by: Bruno Meneguele <bmeneg@redhat.com>
Approved-by: Phil Auld <pauld@redhat.com>
Approved-by: Vladislav Dronov <vdronov@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-21 09:19:32 +00:00
CKI KWF Bot b3607ff92b Merge: CVE-2026-64277: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3170

JIRA: https://redhat.atlassian.net/browse/RHEL-231458
CVE: CVE-2026-64277

Backported from tree(s): linux

```
Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count

rmi_f3a_initialize() takes the GPIO count from the device query register
(f3a->gpio_count = buf & RMI_F3A_GPIO_COUNT, range 0..127).
rmi_f3a_map_gpios() then allocates gpio_key_map with
min(gpio_count, TRACKSTICK_RANGE_END) == at most 6 entries, but
rmi_f3a_attention() iterates the full gpio_count and dereferences
gpio_key_map[i], and input->keycodemax is set to the full gpio_count
while input->keycode points at the 6-entry allocation.

A device that reports gpio_count > 6 therefore causes an out-of-bounds
read of gpio_key_map[] on every attention interrupt, and out-of-bounds
accesses through the input core's default keymap ioctls: EVIOCGKEYCODE
reads past the buffer (leaking adjacent slab memory to user space) and
EVIOCSKEYCODE writes a caller-controlled value past it, for any process
able to open the evdev node, since input_default_getkeycode() and
input_default_setkeycode() only bound the index against keycodemax.

Size the keymap for the full gpio_count. The mapping loop is unchanged:
it still assigns only the first min(gpio_count, TRACKSTICK_RANGE_END)
entries; the remaining slots stay KEY_RESERVED (devm_kcalloc zero-fills)
and are skipped when reporting.

Fixes: 9e4c596bfd ("Input: synaptics-rmi4 - add support for F3A")
Cc: stable@vger.kernel.org
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Link: https://patch.msgid.link/20260614-b4-disp-818d6bda-v1-1-cf39a3615085@proton.me
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
(cherry picked from commit 57c10915f2c16c90e0d46ad00876bf39ece40fc2)

```

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
[^footer]: Created 2026-08-06 00:27 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer]

Approved-by: Benjamin Tissoires <benjamin.tissoires@redhat.com>
Approved-by: Tony Camuso <tcamuso@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-21 09:19:30 +00:00
CKI KWF Bot eae2ba4280 Merge: [RHEL-10.3] Recent upstream fixes for IOMMU subsystem
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2982

# Merge Request Required Information

JIRA: https://issues.redhat.com/browse/RHEL-213791
Upstream-Status: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git

CVE: CVE-2026-53053
CVE: CVE-2026-53372
CVE: CVE-2026-64149
CVE: CVE-2026-53283
CVE: CVE-2026-53164
CVE: CVE-2026-64186
CVE: CVE-2026-64151
CVE: CVE-2026-64152

## Summary of Changes

Recent upstream fixes touching commits in RHEL10.

Signed-off-by: Jerry Snitselaar <jsnitsel@redhat.com>

Approved-by: Eder Zulian <ezulian@redhat.com>
Approved-by: Rafael Aquini <raquini@redhat.com>
Approved-by: Steve Best <sbest@redhat.com>
Approved-by: Jocelyn Falempe <jfalempe@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-21 09:19:28 +00:00
CKI KWF Bot 7e818a1b98 Merge: CVE-2025-21834 kernel: seccomp: passthrough uretprobe systemcall without filtering
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2931

JIRA: https://issues.redhat.com/browse/RHEL-210962
CVE: CVE-2025-21834

Backport of upstream commit cf6cb56ef244 ("seccomp: passthrough uretprobe systemcall without filtering") to fix the CVE aforementioned.

Signed-off-by: Ricardo Robaina <rrobaina@redhat.com>

Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>
Approved-by: Bruno Meneguele <bmeneg@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-21 09:19:26 +00:00
CKI KWF Bot ce8e83a3e2 Merge: perf: Add Intel DMR and NVL support
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2891

JIRA: https://redhat.atlassian.net/browse/RHEL-95668

JIRA: https://redhat.atlassian.net/browse/RHEL-115120

JIRA: https://redhat.atlassian.net/browse/RHEL-115122

JIRA: https://redhat.atlassian.net/browse/RHEL-115124

JIRA: https://redhat.atlassian.net/browse/RHEL-117335

JIRA: https://redhat.atlassian.net/browse/RHEL-117337

JIRA: https://redhat.atlassian.net/browse/RHEL-120357

This MR brings PMU support for Intel Diamond Rapids and Nova Lake models.
The features are split into multiple JIRA tickets, but make sense to merge
together in one batch. This brings uncore, core and cstate support plus
some fixes and extensions required by the mentioned platforms.

Signed-off-by: Michael Petlan <mpetlan@redhat.com>

Approved-by: Steve Best <sbest@redhat.com>
Approved-by: tallison1 <tallison@redhat.com>
Approved-by: ashelat <ashelat@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-21 09:19:24 +00:00
CKI KWF Bot 42630645f0 Merge: CVE-2026-52923 kernel: ipc: limit next_id allocation to the valid ID range [rhel-10.3]
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2839

JIRA: https://redhat.atlassian.net/browse/RHEL-188220
CVE: CVE-2026-52923

commit fa0b9b2b7ae3539908d69c2b9ac0d144d9bc5139
Author: Linpu Yu <linpu5433@gmail.com>
Date:   Sun May 10 13:43:30 2026 +0800

    ipc: limit next_id allocation to the valid ID range

Signed-off-by: Rafael Aquini <raquini@redhat.com>

Approved-by: Phil Auld <pauld@redhat.com>
Approved-by: Luiz Capitulino <luizcap@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-21 09:19:21 +00:00
CKI KWF Bot 5ff962f661 Merge: KVM: arm64: pickup fixes up to v7.1
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2818

JIRA: https://redhat.atlassian.net/browse/RHEL-180320

Testing done: basic host regression test, basic VM tests, kvm selftests, kvm-unit-tests.

Backport fixes up to kernel 7.1 .

Signed-off-by: Sebastian Ott <sebott@redhat.com>

Approved-by: Eric Auger <eric.auger@redhat.com>
Approved-by: Gavin Shan <gshan@redhat.com>
Approved-by: Rafael Aquini <raquini@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-21 09:19:18 +00:00
CKI KWF Bot f837733be2 Merge: selftests/cgroup: Backport cgroup selftests updates and fixes
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2746

JIRA: https://redhat.atlassian.net/browse/RHEL-154157
JIRA: https://redhat.atlassian.net/browse/RHEL-154159
JIRA: https://redhat.atlassian.net/browse/RHEL-184801
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2746
Omitted-fix: d9b40d7262a2 ("selftests/x86: Add selftests include path for kselftest.h after centralization")

This series backports most of relevant cgroup selftests commits in linux
mainline and mm-stable maintainer tree to reduce the failure rate of
the cgroup selftests. This commits do not fix all the test failures but
still many of them should be gone.

By running the cgroup selftests 100 times on an arm64 and x86-64
systems, the table below shows the number of test failures before and
after applying the patches.

	x86-64
	======
	Test					  Before	After
	----					  ------	-----
	test_cpucg_nested_weight_overprovisioned    62		 66
	test_cpucg_stats			    50		 50
	test_cpucg_weight_overprovisioned	    62		 66
	test_memcg_low				   100		  6
	test_memcg_min				    29		  1
	test_memcg_sock				   100		  0
	test_zswap_writeback_disabled		   100		  0
	test_zswap_writeback_enabled		   100		  0
	test_zswapin				   100		  0

	aarch64
	=======
	Test					  Before	After
	----					  ------	-----
	test_cpucg_max				    39		 44
	test_cpucg_max_nested			    25		 23
	test_cpucg_nested_weight_overprovisioned    57		 58
	test_cpucg_nested_weight_underprovisioned    2		  3
	test_cpucg_nice				    95		 79
	test_cpucg_stats			    50		 50
	test_cpucg_weight_overprovisioned	    95		 91
	test_cgfreezer_ptrace			    50		 53
	test_memcg_low				   100		  0
	test_memcg_min				    82		 85
	test_memcg_sock				   100		100
	test_zswap_usage			   100		  0
	test_zswap_writeback_disabled		   100		  0
	test_zswap_writeback_enabled		   100		  0
	test_zswapin				   100		  0

The test_zswap failures are all gone and some of the test_memcontrol
failures are gone. However this MR has no real impact on test_cpu and
test_freezer failures.

Signed-off-by: Waiman Long <longman@redhat.com>

Approved-by: Herton R. Krzesinski <herton@redhat.com>
Approved-by: Phil Auld <pauld@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-21 09:19:16 +00:00
CKI KWF Bot 86281d3ba1 Merge: net: ipv6: P1 backports for 10.3
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2724

A set of various fixes and improvements in the IPv6 area for 10.3; backported as part of our P1 backports.

JIRA: https://redhat.atlassian.net/browse/RHEL-152712
Omitted-fix: fdd973148a11 ("selftests: net: add ipv6 RA route to ECMP merge test"). This is a false positive (only refers to a commit backported in there, not fixing anything).

Signed-off-by: Antoine Tenart <atenart@redhat.com>

Approved-by: Jamie Bainbridge <jbainbri@redhat.com>
Approved-by: Sabrina Dubroca <sdubroca@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-21 09:19:13 +00:00
CKI KWF Bot f0b99f65c7 [redhat] kernel-6.12.0-262.el10
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>
2026-08-20 05:16:26 -04:00
CKI KWF Bot c355914c3e Merge: CIFS: fix periodic IO errors when rename races with lease break [rhel-10.3]
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3287

- fix periodic IO errors when rename races with lease break

JIRA: https://redhat.atlassian.net/browse/RHEL-235460

Signed-off-by: Paulo Alcantara <paalcant@redhat.com>

Approved-by: Scott Mayhew <smayhew@redhat.com>
Approved-by: Jay Shin <jaeshin@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-20 09:15:05 +00:00
CKI KWF Bot cc34ccc099 Merge: smartpqi updates
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3261

# Merge Request Required Information

## Summary of Changes
[rhkl_cover_letter_cs10.3_jira_rhel-224341](/uploads/4186a67af4cfb9b0d5c94aef0a182786/rhkl_cover_letter_cs10.3_jira_rhel-224341)

## Approved Development Ticket(s)
JIRA: https://redhat.atlassian.net/browse/RHEL-224341

Signed-off-by: Don Brace <dbrace@redhat.com>

Approved-by: Laurence Oberman <loberman@redhat.com>
Approved-by: Tomas Henzl <thenzl@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-20 09:15:03 +00:00
CKI KWF Bot f3bb824a4e Merge: redhat/configs: automotive: disable CONFIG_MD
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3256

## Summary of Changes

CONFIG_MD=y has no effect in automotive; the subsystem's Makefile
doesn't have any obj-y additions, and the only Kconfigs enabled in
automotive that are used in the subsystem's Makefile are:

        $ git grep -Pho '\$\(CONFIG_[^)]+\)' drivers/md/Makefile |
                sort -u |
                tr -d '$()' |
                xargs -I{} grep -F "{}=" redhat/configs/kernel-*-automotive*.config
        redhat/configs/kernel-6.12.0-aarch64-automotive.config:CONFIG_BLK_DEV_ZONED=y
        redhat/configs/kernel-6.12.0-aarch64-automotive-debug.config:CONFIG_BLK_DEV_ZONED=y
        redhat/configs/kernel-6.12.0-x86_64-automotive.config:CONFIG_BLK_DEV_ZONED=y
        redhat/configs/kernel-6.12.0-x86_64-automotive-debug.config:CONFIG_BLK_DEV_ZONED=y
        redhat/configs/kernel-6.12.0-aarch64-automotive.config:CONFIG_IMA=y
        redhat/configs/kernel-6.12.0-aarch64-automotive-debug.config:CONFIG_IMA=y
        redhat/configs/kernel-6.12.0-x86_64-automotive.config:CONFIG_IMA=y
        redhat/configs/kernel-6.12.0-x86_64-automotive-debug.config:CONFIG_IMA=y

These Kconfigs are only used to modify dm-mod.o, which isn't built in
automotive kernels since it depends on CONFIG_BLK_DEV_DM.

CONFIG_MD is also the only MD-related Kconfig that's enabled in
automotive:

        $ grep -P 'CONFIG_(.+_)?MD[_=]' redhat/configs/kernel-*-automotive*.config
        redhat/configs/kernel-6.12.0-aarch64-automotive.config:CONFIG_MD=y
        redhat/configs/kernel-6.12.0-aarch64-automotive-debug.config:CONFIG_MD=y
        redhat/configs/kernel-6.12.0-x86_64-automotive.config:CONFIG_MD=y
        redhat/configs/kernel-6.12.0-x86_64-automotive-debug.config:CONFIG_MD=y

Since the Kconfig is essentially a no-op, disable it in automotive
kernels.

## Approved Development Ticket(s)

JIRA: https://redhat.atlassian.net/browse/RHEL-237678

Upstream ARK MR: https://gitlab.com/cki-project/kernel-ark/-/merge_requests/4642

Signed-off-by: Jared Kangas <jkangas@redhat.com>

Approved-by: Eric Chanudet <echanude@redhat.com>
Approved-by: Mattijs Korpershoek <mkorpershoek@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-20 09:15:01 +00:00
CKI KWF Bot b3d8b9d7aa Merge: mm/gup: fix GUP-fast fallback for NULL-mapping order-0 folios
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3250

JIRA: https://redhat.atlassian.net/browse/RHEL-231964
Upstream status: git://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git

    commit c494788faffe67216c56623d240541fde50139c3
    Author: John Hubbard <jhubbard@nvidia.com>
    Date:   Tue Jul 7 17:57:45 2026 -0700

        mm/gup: fix GUP-fast fallback for NULL-mapping order-0 folios

Signed-off-by: Rafael Aquini <raquini@redhat.com>

Approved-by: Luiz Capitulino <luizcap@redhat.com>
Approved-by: Mark Salter <msalter@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-20 09:14:59 +00:00
CKI KWF Bot 5bc7cede8b Merge: CVE-2026-64560: posix-cpu-timers: Prevent UAF caused by non-leader exec() race
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3215

JIRA: https://redhat.atlassian.net/browse/RHEL-227851
CVE: CVE-2026-64560
CVE: CVE-2026-64370
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3215

With the presence of commit 6017a158beb1 ("posix-timers: Embed sigqueue
in struct k_itimer") and other related posix-timers commits merged
in RHEL 10.2, commit fb3bbcfe344e ("exit: change the release_task()
paths to call flush_sigqueue() lockless") can be applied to reduce
merge conflict when applying the CVE fix commit. Similarly, the next
two commits are applied to further reduce conflicts.

Patch 4 is another CVE fix in the posix-timer code. The last patch is
the CVE-2026-64560 fix commit.

Signed-off-by: Waiman Long <longman@redhat.com>

Approved-by: Tony Camuso <tcamuso@redhat.com>
Approved-by: Phil Auld <pauld@redhat.com>
Approved-by: Rafael Aquini <raquini@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-20 09:14:57 +00:00
CKI KWF Bot 13a5607816 Merge: drm/xe: gate observation streams properly
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3204

JIRA: https://redhat.atlassian.net/browse/RHEL-212122

xe OA and EU-stall paths open-code a partial copy of the system-wide
perf CPU-event permission check:

    if (xe_observation_paranoid && !perfmon_capable())
            return -EACCES;

This open-coded check skips two things perf_allow_cpu() handles: the
graduated kernel.perf_event_paranoid policy that an administrator
may have tuned, and the security_perf_event_open() LSM hook.

Introduce xe_observation_paranoid_check() to wrap perf_allow_cpu(),
and convert the open-coded sites in xe_oa.c and xe_eu_stall.c. The
dev.xe.observation_paranoid sysctl still acts as an escape hatch
when cleared.

xe observation now consults kernel.perf_event_paranoid and the LSM
perf hook on every open. Sites that have already configured an LSM
perf policy or tuned the paranoid sysctl will see those settings
extend to xe.

Signed-off-by: Michael Petlan <mpetlan@redhat.com>

Approved-by: ashelat <ashelat@redhat.com>
Approved-by: tallison1 <tallison@redhat.com>
Approved-by: Gary Guo <gguo@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-20 09:14:55 +00:00
CKI KWF Bot 3579495c7e Merge: CVE-2026-63952: memfd: deny writeable mappings when implying SEAL_WRITE
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3133

JIRA: https://redhat.atlassian.net/browse/RHEL-228530
CVE: CVE-2026-63952

Backported from tree(s): linux

```
memfd: deny writeable mappings when implying SEAL_WRITE

When SEAL_EXEC is added, SEAL_WRITE is implied to make W^X.  But the
implied seal is set after the check that makes sure the memfd can not have
any writable mappings.  This means one can use SEAL_EXEC to apply
SEAL_WRITE while having writeable mappings.

This breaks the contract that SEAL_WRITE provides and can be used by an
attacker to pass a memfd that appears to be write sealed but can still be
modified arbitrarily.

Fix this by adding the implied seals before the call for
mapping_deny_writable() is done.

Link: https://lore.kernel.org/20260505133922.797635-1-pratyush@kernel.org
Fixes: c4f75bc8bd ("mm/memfd: add write seals when apply SEAL_EXEC to executable memfd")
Signed-off-by: Pratyush Yadav (Google) <pratyush@kernel.org>
Reviewed-by: Pasha Tatashin <pasha.tatashin@soleen.com>
Acked-by: Jeff Xu <jeffxu@google.com>
Cc: Baolin Wang <baolin.wang@linux.alibaba.com>
Cc: Brendan Jackman <jackmanb@google.com>
Cc: Greg Thelen <gthelen@google.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: Kees Cook <kees@kernel.org>
Cc: "David Hildenbrand (Arm)" <david@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
(cherry picked from commit 3b041514cb6eae45869b020f743c14d983363222)

```

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
[^footer]: Created 2026-08-05 23:21 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer]

Approved-by: Rafael Aquini <raquini@redhat.com>
Approved-by: Herton R. Krzesinski <herton@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-20 09:14:52 +00:00
CKI KWF Bot 875dd5b562 Merge: CVE-2026-53195 / CVE-2026-53196: USB: serial: io_ti: fix heap overflow attacks
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2849

JIRA: https://issues.redhat.com/browse/RHEL-191041
CVE: CVE-2026-53195
CVE: CVE-2026-53196

This MR fixes malicious heap overflow attack vulnerabilities in the Edge-
port USB Serial Converter driver. These attacks can be carried out by
sending a Size different than expected on get_manuf_info() and a Length on
build_i2c_fw_hdr(). In short, fixes reject values with unexpected lengths.

Signed-off-by: Desnes Nunes <desnesn@redhat.com>

Approved-by: David Marlin <dmarlin@redhat.com>
Approved-by: Tony Camuso <tcamuso@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-20 09:14:48 +00:00
CKI KWF Bot 45adac0204 Merge: DRM stable Backport v7.0
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2802

This is the DRM stable backport pulling in all fixes from 7.0.14 since 7.0

JIRA: https://issues.redhat.com/browse/RHEL-180328

Signed-off-by: Karol Herbst <kherbst@redhat.com>

False positive reported fixes:
```
Omitted-fix: ead6680f354f8 ("dma-buf: fix UAF in dma_buf_fd() tracepoint")
```

Approved-by: Jerry Snitselaar <jsnitsel@redhat.com>
Approved-by: Enric Balletbo i Serra <eballetbo@redhat.com>
Approved-by: José Expósito <jexposit@redhat.com>
Approved-by: Peter Colberg <pcolberg@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-20 09:14:46 +00:00
CKI KWF Bot 4c0b2c7690 Merge: CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2624

JIRA: https://redhat.atlassian.net/browse/RHEL-178409
CVE: CVE-2026-43501

Backported from tree(s): linux

```
commit 9e6bf146b55999a095bb14f73a843942456d1adc
Author: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Date:   Tue Apr 21 15:16:33 2026 +0200

    ipv6: rpl: reserve mac_len headroom when recompressed SRH grows

    ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps
    the next segment into ipv6_hdr->daddr, recompresses, then pulls the old
    header and pushes the new one plus the IPv6 header back.  The
    recompressed header can be larger than the received one when the swap
    reduces the common-prefix length the segments share with daddr (CmprI=0,
    CmprE>0, seg[0][0] != daddr[0] gives the maximum +8 bytes).

    pskb_expand_head() was gated on segments_left == 0, so on earlier
    segments the push consumed unchecked headroom.  Once skb_push() leaves
    fewer than skb->mac_len bytes in front of data,
    skb_mac_header_rebuild()'s call to:

            skb_set_mac_header(skb, -skb->mac_len);

    will store (data - head) - mac_len into the u16 mac_header field, which
    wraps to ~65530, and the following memmove() writes mac_len bytes ~64KiB
    past skb->head.

    A single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo with a two
    segment type-3 SRH (CmprI=0, CmprE=15) reaches headroom 8 after one
    pass; KASAN reports a 14-byte OOB write in ipv6_rthdr_rcv.

    Fix this by expanding the head whenever the remaining room is less than
    the push size plus mac_len, and request that much extra so the rebuilt
    MAC header fits afterwards.

    Fixes: 8610c7c6e3 ("net: ipv6: add support for rpl sr exthdr")
    Cc: stable <stable@kernel.org>
    Reported-by: Anthropic
    Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
    Link: https://patch.msgid.link/2026042133-gout-unvented-1bd9@gregkh
    Signed-off-by: Jakub Kicinski <kuba@kernel.org>

```

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
[^footer]: Created 2026-05-21 15:06 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer]

Approved-by: Jarod Wilson <jarod@redhat.com>
Approved-by: Sabrina Dubroca <sdubroca@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-20 09:14:44 +00:00
CKI KWF Bot 438bcf0c3b Merge: CVE-2026-43341: net/ipv6: ioam6: prevent schema length wraparound in trace fill
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2559

JIRA: https://redhat.atlassian.net/browse/RHEL-174787
CVE: CVE-2026-43341

```
commit 5e67ba9bb531e1ec6599a82a065dea9040b9ce50
Author: Pengpeng Hou <pengpeng@iscas.ac.cn>
Date:   Wed Mar 25 15:41:52 2026 +0800

    net/ipv6: ioam6: prevent schema length wraparound in trace fill

    ioam6_fill_trace_data() stores the schema contribution to the trace
    length in a u8. With bit 22 enabled and the largest schema payload,
    sclen becomes 1 + 1020 / 4, wraps from 256 to 0, and bypasses the
    remaining-space check. __ioam6_fill_trace_data() then positions the
    write cursor without reserving the schema area but still copies the
    4-byte schema header and the full schema payload, overrunning the trace
    buffer.

    Keep sclen in an unsigned int so the remaining-space check and the write
    cursor calculation both see the full schema length.

    Fixes: 8c6f6fa677 ("ipv6: ioam: IOAM Generic Netlink API")
    Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
    Reviewed-by: Justin Iurman <justin.iurman@gmail.com>
    Signed-off-by: David S. Miller <davem@davemloft.net>
```

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
[^footer]: Created 2026-05-08 19:28 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer]

Approved-by: Jarod Wilson <jarod@redhat.com>
Approved-by: Paolo Abeni <pabeni@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-20 09:14:41 +00:00
CKI KWF Bot 1dfd1381f8 Merge: xen: buffer overflow in drivers/xen/sys-hypervisor.c
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2529

JIRA: https://redhat.atlassian.net/browse/RHEL-172518
CVE: CVE-2026-31786

Fix a buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 / CVE-2026-31786)

Signed-off-by: Vitaly Kuznetsov <vkuznets@redhat.com>

Approved-by: Ani Sinha <anisinha@redhat.com>
Approved-by: simsingh <simsingh@redhat.com>
Approved-by: Maxim Levitsky <mlevitsk@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-20 09:14:38 +00:00
CKI KWF Bot 7bb035c5df Merge: ext4: revert crc32c library changes due to missing functionality
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2343

JIRA: https://redhat.atlassian.net/browse/RHEL-159116
Upstream Status: RHEL only.

This patch was backported a bit overzealously as part of a recent
ext4 upstream syncup. The requisite changes to connect the crc32c
library to the arch optimizations referred to in the original commit
do not exist in CS10, which means this actually causes a performance
degradation on high performance storage. Since the library changes
are unplanned, back out the change in ext4 to restore original
performance.

Signed-off-by: Brian Foster <bfoster@redhat.com>

Approved-by: Pavel Reichl <preichl@redhat.com>
Approved-by: Carlos Maiolino <cmaiolino@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-20 09:14:35 +00:00
CKI KWF Bot 619fbe8f94 [redhat] kernel-6.12.0-261.el10
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>
2026-08-18 06:06:11 -04:00
CKI KWF Bot 1366f919fa Merge: mm/util: don't read __page_2 for order-1 folios in snapshot_page()
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3288

JIRA: https://redhat.atlassian.net/browse/RHEL-214116

commit 7441d6348c70738e9ed307510db171c7a9b3f4bf
Author: Aboorva Devarajan <aboorvad@linux.ibm.com>
Date: Thu, 9 Jul 2026 01:49:54 +0530

    snapshot_page() currently reads __page_2 after checking nr_pages > 1, but
    it should only do so when nr_pages > 2.

    If an order-1 folio is allocated at the end of a vmemmap section,
    __page_2 will not exist and reading it will cause a fault.

    During DLPAR memory remove on a 22 TB ppc64le LPAR, snapshot_page() oopsed
    on the page isolation path while reading an order-1 folio's __page_2 from
    an adjacent absent section (unmapped vmemmap).

    Fix this to avoid reading memmap that doesn't exist (e.g., a vmemmap
    hole).

    Link: https://lore.kernel.org/20260708201954.686111-1-aboorvad@linux.ibm.com
    Fixes: 31a31da8a618 ("mm: move _pincount in folio to page[2] on 32bit")
    Signed-off-by: Aboorva Devarajan <aboorvad@linux.ibm.com>
    Reported-by: Sourabh Jain <sourabhjain@linux.ibm.com>
    Acked-by: David Hildenbrand (Arm) <david@kernel.org>
    Reviewed-by: Lorenzo Stoakes <ljs@kernel.org>
    Reviewed-by: Matthew Wilcox (Oracle) <willy@infradead.org>
    Reviewed-by: Luiz Capitulino <luizcap@redhat.com>
    Cc: Liam R. Howlett <liam@infradead.org>
    Cc: Michal Hocko <mhocko@suse.com>
    Cc: Mike Rapoport <rppt@kernel.org>
    Cc: "Ritesh Harjani (IBM)" <ritesh.list@gmail.com>
    Cc: Suren Baghdasaryan <surenb@google.com>
    Cc: Vlastimil Babka <vbabka@kernel.org>
    Cc: <stable@vger.kernel.org> # v6.15+
    Signed-off-by: Andrew Morton <akpm@linux-foundation.org>

Signed-off-by: Luiz Capitulino <luizcap@redhat.com>

Approved-by: Rafael Aquini <raquini@redhat.com>
Approved-by: Ricardo Robaina <rrobaina@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-18 10:04:35 +00:00
CKI KWF Bot 7287f6faad Merge: selftests: tls: Catch up to v7.2-rc1
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3277

JIRA: https://redhat.atlassian.net/browse/RHEL-153139

Testing: Ran
```
tools/testing/selftests/net/tls -r tls.12_aes_gcm.splice_short -r tls.13_aes_gcm.splice_short -r tls.12_chacha.splice_short -r tls.13_chacha.splice_short -r tls.12_aes_ccm.splice_short -r tls.13_aes_ccm.splice_short -r tls.12_aes_gcm_256.splice_short -r tls.13_aes_gcm_256.splice_short -r tls.13_nopad.splice_short
```

net/tls splice tests currently fail on 64k page kernel because of missing upstream commit:
  3e52f56875c6 ("selftests: tls: size splice_short pipe by page size")

This MR brings the net/tls selftest up to v7.2-rc1, which is the above commits plus two freebies.

Signed-off-by: Valentin Schneider <vschneid@redhat.com>

Approved-by: Tomas Glozar <tglozar@redhat.com>
Approved-by: Wander Lairson Costa <wander@redhat.com>
Approved-by: Sabrina Dubroca <sdubroca@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-18 10:04:33 +00:00
CKI KWF Bot 5fa25fd7a5 Merge: perf/aux: Fix page UAF in map_range()
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3249

JIRA: https://redhat.atlassian.net/browse/RHEL-218473

CVE: CVE-2026-64300

upstream
========
commit 5948aaf64f81f217a25dcc2bf6c0779bca19566c
Author: Lee Jia Jie <jiajie.lee@starlabs.sg>
Date: Thu Jul 9 21:56:19 2026 +0800

description
===========
map_range() reads rb->aux_pages[], rb->aux_nr_pages and rb->aux_pgoff via
perf_mmap_to_page() while holding only event->mmap_mutex. Those fields are
serialized by rb->aux_mutex, and mmap_mutex is per event.

Thus, two events sharing one rb via PERF_EVENT_IOC_SET_OUTPUT can race
rb_alloc_aux() with map_range(), leading to a page-UAF scenario as follows:

  CPU 0                           CPU 1
  =====                           =====
  rb_alloc_aux()                  map_range()
  [1]: allocate rb->aux_pages[0]
  [2]: rb->aux_nr_pages++
                                  [3]: perf_mmap_to_page()
                                         returns rb->aux_pages[0]
                                  [4]: map it as VM_PFNMAP
  [5]: rb->aux_pgoff = 1

  munmap the page
  [6]: free rb->aux_pages[0]

Pages mapped as VM_PFNMAP have no refcount protection, so CPU 1 holds a
mapping to a freed physical frame.

Fix this by taking rb->aux_mutex across the page walk in map_range().

Fixes: b709eb872e19 ("perf: map pages in advance")
    Signed-off-by: Lee Jia Jie <jiajie.lee@starlabs.sg>
    Signed-off-by: Ingo Molnar <mingo@kernel.org>
    Cc: stable@vger.kernel.org
    Cc: Peter Zijlstra <peterz@infradead.org>
    Cc: Arnaldo Carvalho de Melo <acme@redhat.com>
    Cc: Namhyung Kim <namhyung@kernel.org>

Signed-off-by: Michael Petlan <mpetlan@redhat.com>

Approved-by: tallison1 <tallison@redhat.com>
Approved-by: ashelat <ashelat@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-18 10:04:32 +00:00
CKI KWF Bot 994f2e5c2f Merge: CVE-2026-64557: Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3224

JIRA: https://redhat.atlassian.net/browse/RHEL-231358
CVE: CVE-2026-64557

 * 9707a015fe8f3ba8ec7c270f3b2b8efb38823d6b Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister [linux]
 * 6fef032af0092ed5ccb767239a9ac1bc38c08a40 Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() [linux]

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
[^footer]: Created 2026-08-10 19:08 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer]

Approved-by: David Marlin <dmarlin@redhat.com>
Approved-by: Charles Mirabile <cmirabil@redhat.com>
Approved-by: Tony Camuso <tcamuso@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-18 10:04:30 +00:00
CKI KWF Bot e0e4ef7be2 Merge: perf build-id: Fix off-by-one bug when printing kernel/module build-id
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3220

JIRA: https://redhat.atlassian.net/browse/RHEL-122642

Fix off by one byte error when printing build-id via snprintf as it doesn't handle the '\\0' terminating character.

Signed-off-by: Marek Pazur <mpazur@redhat.com>

Approved-by: ashelat <ashelat@redhat.com>
Approved-by: Michael Petlan <mpetlan@redhat.com>
Approved-by: tallison1 <tallison@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-18 10:04:27 +00:00
CKI KWF Bot deb2fc781d Merge: arm_mpam: Pull forward to 7.2+linux-next
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3208

JIRA: https://redhat.atlassian.net/browse/RHEL-218644

This brings the centos 10, MPAM system up to date with mainline 7.2rc

Signed-off-by: Jeremy Linton <jlinton@redhat.com>

Approved-by: Gavin Shan <gshan@redhat.com>
Approved-by: Mark Salter <msalter@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-18 10:04:24 +00:00
CKI KWF Bot 7a928b9bbe Merge: arm64: DTS updates from v6.19 for RHEL-relevant platforms
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3002

This MR backports selected arm64 DTS updates from the upstream v6.19 development cycle for RHEL 10.3.

The scope is limited to SoC-level DTSI updates for NXP/Freescale i.MX8 and TI K3/AM62 platforms. Board-specific DTS churn, defconfig-only changes, ARM64 core changes, MM/sysreg changes, crypto/FPSIMD changes, and unrelated dependency series were intentionally excluded to keep the MR focused and reviewable.

JIRA: https://issues.redhat.com/browse/RHEL-213310

Signed-off-by: Steve Dunnagan <sdunnaga@redhat.com>

Approved-by: Eric Chanudet <echanude@redhat.com>
Approved-by: Mark Salter <msalter@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-18 10:04:23 +00:00
CKI KWF Bot b5138b23a3 Merge: Recent upstream fixes for DMA engine drivers
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2984

JIRA: https://redhat.atlassian.net/browse/RHEL-213821

Upstream-Status: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git

Recent upstream fixes for DMA engine drivers

Signed-off-by: Eder Zulian <ezulian@redhat.com>

Approved-by: Tony Camuso <tcamuso@redhat.com>
Approved-by: Eric Chanudet <echanude@redhat.com>
Approved-by: Vladislav Dronov <vdronov@redhat.com>
Approved-by: Jerry Snitselaar <jsnitsel@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-18 10:04:20 +00:00
CKI KWF Bot c454b9e6cf Merge: CVE-2026-43276: net: mana: Fix double destroy_workqueue on service rescan PCI path
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2670

JIRA: https://redhat.atlassian.net/browse/RHEL-180276
CVE: CVE-2026-43276

 * f975a0955276579e2176a134366ed586071c7c6a net: mana: Fix double destroy_workqueue on service rescan PCI path [linux]
 * 87c2302813abc55c46485711a678e3c312b00666 net/mana: Null service_wq on setup error to prevent double destroy [linux]

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
[^footer]: Created 2026-05-29 08:18 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer]

Approved-by: ggoklani <ggoklani@redhat.com>
Approved-by: Ani Sinha <anisinha@redhat.com>
Approved-by: Vitaly Kuznetsov <vkuznets@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-18 10:04:18 +00:00
CKI KWF Bot bd1bea1d61 Merge: CVE-2026-46145: RDMA/mana: Validate rx_hash_key_len
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2661

JIRA: https://redhat.atlassian.net/browse/RHEL-180091
CVE: CVE-2026-46145

Backported from tree(s): linux

```
commit 6dd2d4ad9c8429523b1c220c5132bd551c006425
Author: Jason Gunthorpe <jgg@nvidia.com>
Date:   Tue Apr 28 13:17:37 2026 -0300

    RDMA/mana: Validate rx_hash_key_len

    Sashiko points out that rx_hash_key_len comes from a uAPI structure and is
    blindly passed to memcpy, allowing the userspace to trash kernel
    memory. Bounds check it so the memcpy cannot overflow.

    Cc: stable@vger.kernel.org
    Fixes: 0266a17763 ("RDMA/mana_ib: Add a driver for Microsoft Azure Network Adapter")
    Link: https://sashiko.dev/#/patchset/0-v2-1c49eeb88c48%2B91-rdma_udata_rep_jgg%40nvidia.com?part=1
    Link: https://patch.msgid.link/r/4-v1-41f3135e5565+9d2-rdma_ai_fixes1_jgg@nvidia.com
    Reviewed-by: Long Li <longli@microsoft.com>
    Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>

```

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
[^footer]: Created 2026-05-28 16:48 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer]

Approved-by: ggoklani <ggoklani@redhat.com>
Approved-by: Kamal Heib <kheib@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-18 10:04:15 +00:00
CKI KWF Bot 2996eb7e41 [redhat] kernel-6.12.0-260.el10
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>
2026-08-14 15:01:00 -04:00
CKI KWF Bot 89de473b0b Merge: x86/mce: Set up the polling timer before CMCI discovery
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3289

JIRA: https://redhat.atlassian.net/browse/RHEL-239086

commit a213dfaa2596c1c0dc4dae91c14fbfa499c03223
Author: Breno Leitao <leitao@debian.org>
Date:   Mon Aug 3 02:47:40 2026 -0700

    x86/mce: Set up the polling timer before CMCI discovery

    I hit the following on one of my machines:

      mce: CPU0 BANK15 CMCI inherited storm
      ------------[ cut here ]------------
      ODEBUG: assert_init not available (active state 0) object: (____ptrval____) object type: timer_list hint: 0x0
      WARNING: lib/debugobjects.c:632 at debug_object_assert_init+0x178/0x230, CPU#0: swapper/0/0
      CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 7.2.0-rc5 #3 PREEMPTLAZY
      RIP: 0010:debug_object_assert_init+0x18f/0x230
      Call Trace:
       <TASK>
       __mod_timer
       mce_timer_kick
       cmci_discover
       intel_init_cmci
       mce_intel_feature_init
       mcheck_cpu_init
       identify_cpu
       identify_boot_cpu
       arch_cpu_finalize_init
       start_kernel

    A second splat follows right after, from timer_setup() finding that same
    timer already queued:

      ODEBUG: init active (active state 0) object: (____ptrval____) object type: timer_list hint: stub_timer+0x0/0x10

    This is happening because CMCI storm detection is trying to modify the timer
    before latter was properly set up.

    Set up the timer first. __mcheck_cpu_setup_timer() only calls timer_setup(),
    and depends on neither the generic nor the vendor init.

      [ bp: Massage commit message. ]

    Fixes: 1f68ce2a02 ("x86/mce: Handle Intel threshold interrupt storms")
    Signed-off-by: Breno Leitao <leitao@debian.org>
    Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
    Cc: stable@vger.kernel.org
    Link: https://patch.msgid.link/20260803-mce_timer_init-v1-1-9539db424330@debian.org

Signed-off-by: Steve Best <sbest@redhat.com>

Approved-by: David Arcari <darcari@redhat.com>
Approved-by: Tony Camuso <tcamuso@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-14 18:59:08 +00:00
CKI KWF Bot c92224bccb Merge: scsi: target: Fix hexadecimal CHAP_I handling
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3279

# Merge Request Required Information

## Summary of Changes

JIRA: https://redhat.atlassian.net/browse/RHEL-231666

CVE: CVE-2026-63886

In the Linux kernel, the following vulnerability has been resolved:

scsi: target: iscsi: Validate CHAP_R length before base64 decode

chap_server_compute_hash() allocates client_digest as
kzalloc(chap->digest_size) and then, for BASE64-encoded responses,
passes chap_r directly to chap_base64_decode() without checking whether
the input length could produce more than digest_size bytes of output.

chap_base64_decode() writes to the destination unconditionally as long
as there is input to consume. With MAX_RESPONSE_LENGTH set to 128 and
the "0b" prefix stripped by extract_param(), up to 127 base64 characters
can reach the decoder. 127 characters decode to 95 bytes. For SHA-256
(digest_size=32) this overflows client_digest by 63 bytes; for MD5
(digest_size=16) the overflow is 79 bytes.

The length check at line 344 fires after the write has already happened.

The HEX branch in the same switch statement already validates the length
up front. Apply the same approach to the BASE64 branch: strip trailing
base64 padding characters, then reject any input whose data length
exceeds DIV_ROUND_UP(digest_size * 4, 3) before calling the decoder.

Stripping trailing '=' before the comparison handles both padded and
unpadded encodings. chap_base64_decode() already returns early on '=',
so the full original string is still passed to the decoder unchanged.

The mutual CHAP path decodes CHAP_C into initiatorchg_binhex, which is
kzalloc(CHAP_CHALLENGE_STR_LEN). extract_param() caps initiatorchg at
CHAP_CHALLENGE_STR_LEN characters, so at most CHAP_CHALLENGE_STR_LEN-1
base64 characters reach the decoder. The maximum decoded size,
DIV_ROUND_UP((CHAP_CHALLENGE_STR_LEN-1) * 3, 4), is less than
CHAP_CHALLENGE_STR_LEN, so no overflow is possible there. A comment is
added at the call site to document this.

Signed-off-by: Maurizio Lombardi <mlombard@redhat.com>

## Approved Development Ticket(s)
All submissions to CentOS Stream must reference a ticket in [Red Hat Jira](https://issues.redhat.com/).

<details><summary>Click for formatting instructions</summary>
Please follow the CentOS Stream [contribution documentation](https://docs.centos.org/centos-stream-docs/contributors-guide/) for how to file this ticket and have it approved.

List tickets each on their own line of this description using the format "Resolves: RHEL-76229", "Related: RHEL-76229" or "Reverts: RHEL-76229", as appropriate.
</details>

Approved-by: Laurence Oberman <loberman@redhat.com>
Approved-by: djeffery1 <djeffery@redhat.com>
Approved-by: Chris Leech <cleech@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-14 18:59:06 +00:00
CKI KWF Bot bb4e8b4bc7 Merge: thermal: core: Fix thermal zone device registration error path
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3258

JIRA: https://redhat.atlassian.net/browse/RHEL-226828
CVE: CVE-2026-43332

commit 9e07e3b81807edd356e1f794cffa00a428eff443
Author: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Date:   Wed Apr 1 16:33:53 2026 +0200

    thermal: core: Fix thermal zone device registration error path

    If thermal_zone_device_register_with_trips() fails after registering
    a thermal zone device, it needs to wait for the tz->removal completion
    like thermal_zone_device_unregister(), in case user space has managed
    to take a reference to the thermal zone device's kobject, in which case
    thermal_release() may not be called by the error path itself and tz may
    be freed prematurely.

    Add the missing wait_for_completion() call to the thermal zone device
    registration error path.

    Fixes: 04e6ccfc93 ("thermal: core: Fix NULL pointer dereference in zone registration error path")
    Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
    Cc: All applicable <stable@vger.kernel.org>
    Reviewed-by: Lukasz Luba <lukasz.luba@arm.com>
    Tested-by: Lukasz Luba <lukasz.luba@arm.com>
    Link: https://patch.msgid.link/2849815.mvXUDI8C0e@rafael.j.wysocki

Signed-off-by: Steve Best <sbest@redhat.com>

Approved-by: Tony Camuso <tcamuso@redhat.com>
Approved-by: David Arcari <darcari@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-14 18:59:05 +00:00
CKI KWF Bot 7dca812243 Merge: perf/arm_pmu: Skip PMCCNTR_EL0 on NVIDIA Olympus
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3246

JIRA: https://issues.redhat.com/browse/RHEL-176084

NVIDIA Olympus has SMT cores that share `PMCCNTR_EL0`. This results in the counter incrementing even during a WFI/WFE if the sibling is not idle which is unexpected. This patch avoids using `PMCCNTR_EL0` on the platform.

Signed-off-by: Charles Mirabile <cmirabil@redhat.com>

Approved-by: Mark Langsdorf <mlangsdo@redhat.com>
Approved-by: Mark Salter <msalter@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-14 18:59:03 +00:00
CKI KWF Bot 22ca799912 Merge: cpuidle: resolve a potential performance degradation
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3221

RESOLVES: RHEL-222582
JIRA: https://redhat.atlassian.net/browse/RHEL-222582
Upstream Status: RHEL-Only

This reverts commit 9216f15650.

Commit 9216f15650 reverted a
commit that caused a performance regression on some Intel
Jasper Lake systems. Reverting that commit caused a different
performance regression on some other systems. On balance,
we would prefer that those other systems have better performance
even if some Jasper Lake systems suffer worse performance.

Signed-off-by: Mark Langsdorf <mlangsdo@redhat.com>

Approved-by: Steve Best <sbest@redhat.com>
Approved-by: David Arcari <darcari@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-14 18:59:01 +00:00
CKI KWF Bot f78d306b03 Merge: drm: several CVE fixes GPU team spring 30
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3217

We are collecting several CVE fixes into single MRs for easier QE testing

JIRA: https://redhat.atlassian.net/browse/RHEL-222670

JIRA: https://redhat.atlassian.net/browse/RHEL-222688

JIRA: https://redhat.atlassian.net/browse/RHEL-222698

JIRA: https://redhat.atlassian.net/browse/RHEL-222746

JIRA: https://redhat.atlassian.net/browse/RHEL-222752

JIRA: https://redhat.atlassian.net/browse/RHEL-222574

JIRA: https://redhat.atlassian.net/browse/RHEL-222626

JIRA: https://redhat.atlassian.net/browse/RHEL-222650

```
CVE: CVE-2026-53329
CVE: CVE-2026-53136
CVE: CVE-2026-53143
CVE: CVE-2026-63884
CVE: CVE-2026-53356
CVE: CVE-2026-64219
CVE: CVE-2026-63879
CVE: CVE-2026-53374
Backported from tree(s): linux
```

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>

Signed-off-by: Karol Herbst <kherbst@redhat.com>

Approved-by: José Expósito <jexposit@redhat.com>
Approved-by: Peter Kopec <pekopec@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-14 18:59:00 +00:00
CKI KWF Bot 005667c2e6 Merge: KVM: VMX: introduce module parameter to disable CET
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3212

# Merge Request Required Information

## Summary of Changes

```
KVM: VMX: introduce module parameter to disable CET

JIRA: https://redhat.atlassian.net/browse/RHEL-235002

KVM: VMX: introduce module parameter to disable CET

There have been reports of host hangs caused by CET virtualization.
Until these are analyzed further, introduce a module parameter that
makes it possible to easily disable it.
```

## Approved Development Ticket(s)

Resolves: [RHEL-235002](https://redhat.atlassian.net/browse/RHEL-235002)

Signed-off-by: Aidan Wallace <awallace@redhat.com>

Approved-by: Paolo Bonzini <bonzini@gnu.org>
Approved-by: Maxim Levitsky <mlevitsk@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-14 18:58:58 +00:00
CKI KWF Bot dbb706437d Merge: perf/arm-cmn: Pull forward to 7.2rc
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3211

JIRA: https://redhat.atlassian.net/browse/RHEL-234652

This set pulls the arm-cmn driver forward to current mainline 7.2rc.

Signed-off-by: Jeremy Linton <jlinton@redhat.com>

Approved-by: Mark Langsdorf <mlangsdo@redhat.com>
Approved-by: Mark Salter <msalter@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-14 18:58:56 +00:00
CKI KWF Bot d0641739de Merge: perf trace: Refactor augmented_raw_syscalls using bpf_for
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3038

JIRA: https://redhat.atlassian.net/browse/RHEL-183355

Fix issue where perf built with clang-22 contains incompatible BPF code that is then refused by the kernel

Signed-off-by: Trevor Allison <tallison@redhat.com>

Approved-by: Michael Petlan <mpetlan@redhat.com>
Approved-by: ashelat <ashelat@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-14 18:58:55 +00:00
CKI KWF Bot 28e0de09ae Merge: ALSA - update drivers for 10.3 - upstream 7.1.5 (stable)
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3023

JIRA: https://issues.redhat.com/browse/RHEL-193253

This upstream patchset updates the ALSA driver code to upstream stable 7.1.5 kernel.

Omitted-fix: dd1bfaf9413e9c8a0fcfb45dcb735c6768a45251   # see commit - this revert is for 7.2+ kernel code

Omitted-fix: 99c159279c6dfa2c4867c7f76875f58263f8f43b   # used hash 225d70b8074502acee3943bf0c2e839e867cd38c for backport - already in RHEL kernel

Signed-off-by: Jaroslav Kysela <jkysela@redhat.com>

Approved-by: Krzysztof Pawlinski <kpawlins@redhat.com>
Approved-by: Desnes Nunes <desnesn@redhat.com>
Approved-by: Tony Camuso <tcamuso@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-14 18:58:53 +00:00
CKI KWF Bot 4932196eca Merge: [RHEL 10.3]: rebase HID subsystem to 7.1
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2819

This is the usual rebase of the HID subsystem up to kernel v7.1 for 10.3.

```
JIRA: https://issues.redhat.com/browse/RHEL-170872
JIRA: https://redhat.atlassian.net/browse/RHEL-183865

Depends: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2636

All following omitted-fix are not in drivers/hid/ and can thus safely be ignored:
Omitted-fix: fd1d6b9d13f35dccbacbae25ed53593cd9086f84 # xz not part of this MR
Omitted-fix: 96a7b71c4438d3b72d6c95e3efdc9e8e8aee6b78 # ubd not part of this MR
Omitted-fix: 795469820c638b4449f3bb90ee5e98ebccfbc480 # kcsan not part of this MR
Omitted-fix: 5548dd7fa84510f7bbce67c35cc3b388c86aeddf # testing/vma and testing/radix-tree not parts of this MR
Omitted-fix: 405ca72dc589dd746e5ee5378bb9d9ee7f844010 # landlock not part of this MR
Omitted-fix: 4c0134639694fcdc4ab041d7c53d6188a3e18040 # KVM not part of this MR
Omitted-fix: 4c6d43db2a4d2cef3921e885cf34798f790d34ea # net: dst_metadata not part of this MR
Omitted-fix: 01793374319cdb685bd487633bbd8bd57f416172 # m68k: defconfig not part of this MR
Omitted-fix: 94ff7c59cdfde3a16ab830531acbcb3091b292eb # RDMA not part of this MR
Omitted-fix: 2d2b5507e598984f5832f0c5193f35733c42995e # btrfs not part of this MR
Omitted-fix: 94ff7c59cdfde3a16ab830531acbcb3091b292eb # RDMA not part of this MR
Omitted-fix: 9f4ab0787e7bf6d2c709207317e9d4cd43909869 # btrfs not part of this MR
Omitted-fix: 37f1f51fba1a4320149b1ea3b21d254d4b221b0a # btrfs not part of this MR

Following one was silently dropped from Linus's tree during 7.2 pull request from Jiri Kosina, my HID co-maintainer:
Omitted-fix: d0ff08d946c83b51359a8063c41e9f5af067e628 # not making any effect in 7.2-rc1, silently dropped in a merge commit
```

Signed-off-by: Benjamin Tissoires <benjamin.tissoires@redhat.com>

Approved-by: Jarod Wilson <jarod@redhat.com>
Approved-by: Tony Camuso <tcamuso@redhat.com>
Approved-by: Eric Chanudet <echanude@redhat.com>
Approved-by: Andrea Arcangeli <aarcange@redhat.com>
Approved-by: David Arcari <darcari@redhat.com>
Approved-by: Barry Dunn <badunn@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-14 18:58:51 +00:00
CKI KWF Bot 50f0687005 [redhat] kernel-6.12.0-259.el10
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>
2026-08-13 04:31:41 -04:00
CKI KWF Bot 67043a4593 Merge: redhat/kernel.spec.template: Switch UKI addons back to 504 cert
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3282

JIRA: https://redhat.atlassian.net/browse/RHEL-238666

To make kernel's PCR7 measurement the same when UKI cmdline addons are used
and when they are not, the addons must be signed by the same cert as the
UKI. The switch to 801 was accidential.

Signed-off-by: Vitaly Kuznetsov <vkuznets@redhat.com>

Approved-by: Emanuele Giuseppe Esposito <eesposit@redhat.com>
Approved-by: Jan Stancek <jstancek@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-13 08:29:55 +00:00
CKI KWF Bot 68c83cdd8a Merge: CIFS: fix broken directory listing against old SMB1 servers [rhel-10.3]
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3222

- fix broken directory listing against old SMB1 servers

JIRA: https://redhat.atlassian.net/browse/RHEL-235810

Signed-off-by: Paulo Alcantara <paalcant@redhat.com>

Approved-by: Scott Mayhew <smayhew@redhat.com>
Approved-by: David Howells <dhowells@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-13 08:29:53 +00:00
CKI KWF Bot 54b94baabf Merge: CVE-2026-52991: sched/psi: fix race between file release and pressure write
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3188

JIRA: https://redhat.atlassian.net/browse/RHEL-232559
CVE: CVE-2026-52991

 * a5b98009f16d8a5fb4a8ff9a193f5735515c38fa sched/psi: fix race between file release and pressure write [linux]
 * fadeedd7cfc5d73d33fa3d7ac54b9b27aabd09d2 sched/psi: Create the psimon kthread outside of cgroup_mutex [linux]

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
[^footer]: Created 2026-08-06 00:56 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer]

Approved-by: Waiman Long <longman@redhat.com>
Approved-by: Phil Auld <pauld@redhat.com>
Approved-by: Rafael Aquini <raquini@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-13 08:29:52 +00:00
CKI KWF Bot 68916cdc7c Merge: vhost: reset the vring metadata cache on vring reconfiguration [10.3]
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3074

JIRA: https://redhat.atlassian.net/browse/RHEL-224534

Backported from tree(s): linux

```
vhost: reset the vring metadata cache on vring reconfiguration

vq->meta_iotlb[] caches the vhost_iotlb_map that backs each vring
metadata region, and iotlb_access_ok() returns early on a cache hit,
taking the hit as proof that the region has already been validated:

	if (vhost_vq_meta_fetch(vq, addr, len, type))
		return true;

The cache is reset on VHOST_IOTLB_UPDATE and VHOST_IOTLB_INVALIDATE, on
device IOTLB (re)initialisation and on vq reset, but not when
VHOST_SET_VRING_ADDR replaces vq->desc, vq->avail and vq->used, nor when
VHOST_SET_VRING_NUM changes the region sizes.

With a device IOTLB attached both ioctls are accepted while the vq is
live, and neither validates the addresses at ioctl time: vq_access_ok()
and vq_log_used_access_ok() return true early because the addresses are
GIOVAs, deferring validation to prefetch time.  Once the cache has been
populated that deferred validation no longer runs -- vq_meta_prefetch()
hits the stale entry and returns true -- and vhost_vq_meta_fetch() keeps
translating through the old mapping as

	map->addr + addr - map->start

for an address the mapping no longer covers.  vhost_copy_to_user() and
vhost_copy_from_user() consume the result with __copy_to_user() and
__copy_from_user(), which do not check it either, so a subsequent used
ring update or descriptor fetch accesses memory outside the region the
IOTLB actually maps.

Reset the metadata cache whenever the vring is reconfigured, so the new
addresses are pushed back through iotlb_access_ok()'s slow path.

Fixes: f889491380 ("vhost: introduce O(1) vq metadata cache")
Cc: stable@vger.kernel.org
Assisted-by: tencentos-corvus-ai:kimi-k3
Signed-off-by: Jun Yang <junvyyang@tencent.com>
Message-ID: <20260803014823.68623-1-juny24602@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
(cherry picked from commit de845981da67a6b049080c87e605130b0c30adc5)

```

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
[^footer]: Created 2026-08-05 13:42 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer]

Approved-by: MST <mst@redhat.com>
Approved-by: Stefano Garzarella <sgarzare@redhat.com>
Approved-by: Eugenio Pérez <eperezma@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-13 08:29:50 +00:00
CKI KWF Bot 93b969cd26 Merge: Fix bugs and performance of kstack offset randomisation
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3071

JIRA: https://redhat.atlassian.net/browse/RHEL-215975

Fix various issues with kstack randomization.

Signed-off-by: Mark Salter <msalter@redhat.com>

Approved-by: Jennifer Berringer <jberring@redhat.com>
Approved-by: Steve Best <sbest@redhat.com>
Approved-by: Rafael Aquini <raquini@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-13 08:29:48 +00:00
CKI KWF Bot 69e8c50312 Merge: DPLL: Add support for NCO (numerically controlled oscillator)
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2936

JIRA: https://redhat.atlassian.net/browse/RHEL-176048

 * b1d0c412088e dpll: add STATE_CONNECTED_OVERRIDE pin capability [net-next]
 * 0cc8348a9786 dpll: add DPLL_PIN_TYPE_INT_NCO pin type [net-next]
 * 2b11bde391c4 dpll: zl3073x: use per-operation poll timeouts [net-next]
 * 21460118d71b dpll: zl3073x: add per-DPLL serialization lock [net-next]
 * 3553976ffe2f dpll: zl3073x: add NCO virtual input pin [net-next]

Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com>
[^footer]: Created 2026-07-16 12:53 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer]

Approved-by: Ivan Vecera <ivecera@redhat.com>
Approved-by: Michal Schmidt <mschmidt@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-13 08:29:46 +00:00
CKI KWF Bot b122b344e2 Merge: netfilter: rebase on top of v7.2-rc3
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2914

JIRA: https://redhat.atlassian.net/browse/RHEL-185609

CVE: CVE-2026-53211
CVE: CVE-2026-53134
CVE: CVE-2026-53218
CVE: CVE-2026-52942
CVE: CVE-2026-53219
CVE: CVE-2026-53220
CVE: CVE-2026-53266
CVE: CVE-2026-53267
CVE: CVE-2026-53212
CVE: CVE-2026-53268
CVE: CVE-2026-53269
CVE: CVE-2026-53270
CVE: CVE-2026-64554

Next rebase to keep sizes more reviewable. This is very close to upstream with only a few conflicts.

Signed-off-by: Florian Westphal <fwestpha@redhat.com>

Approved-by: Phil Sutter <psutter@redhat.com>
Approved-by: Eric Garver <egarver@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-13 08:29:44 +00:00
CKI KWF Bot 81916a1f89 Merge: Enable batched TLB flush in unmap_hotplug_range()
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2909

JIRA: https://redhat.atlassian.net/browse/RHEL-184786

Use batched TLB flush to speed up unmap_hotplug_range().

Signed-off-by: Mark Salter <msalter@redhat.com>

Approved-by: Rafael Aquini <raquini@redhat.com>
Approved-by: Luiz Capitulino <luizcap@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-13 08:29:42 +00:00
CKI KWF Bot 2d4fe3e1e9 Merge: CNB103: devlink: update devlink to the v7.1
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2822

JIRA: https://redhat.atlassian.net/browse/RHEL-179081
Depends: !2273

Devlink update to version v7.1

Signed-off-by: Petr Oros <poros@redhat.com>

Approved-by: Tony Camuso <tcamuso@redhat.com>
Approved-by: Eric Chanudet <echanude@redhat.com>
Approved-by: Ivan Vecera <ivecera@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-13 08:29:40 +00:00
CKI KWF Bot dca2371bc7 Merge: Enable DWAPB I2C controller on Fujitsu MONAKA
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2328

Add Fujitsu Monaka ACPI HID to DWAPB I2C controller

JIRA: https://redhat.atlassian.net/browse/RHEL-23132

Signed-off-by: Mark Salter <msalter@redhat.com>

Approved-by: Tony Camuso <tcamuso@redhat.com>
Approved-by: Daniel Horak <dhorak@redhat.com>
Approved-by: Jiri Dluhos <jdluhos@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-13 08:29:37 +00:00
CKI KWF Bot ae83fae2e8 Merge: Enable DWAPB GPIO controller on Fujitsu MONAKA
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2327

Add Fujitsu Monaka ACPI HID to designware GPIO driver

JIRA: https://redhat.atlassian.net/browse/RHEL-23123

Signed-off-by: Mark Salter <msalter@redhat.com>

Approved-by: Daniel Horak <dhorak@redhat.com>
Approved-by: Jiri Dluhos <jdluhos@redhat.com>
Approved-by: Bastien Nocera <bnocera@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-13 08:29:34 +00:00
CKI KWF Bot 9065da685e Merge: stmmac driver update up to v6.17+
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2113

This MR was opened with patches from a previous MR due to difference conflicts.

Omitted-fix: eb6ac268a7c9b9e1c57daac4c68b634049d3d8c6 mips: configs: loongson1: Update defconfig

Omitted-fix: 89886abd073489e26614e4d80fb8eb70d3938a0b net: stmmac: dwc-qos: fix clk prepare/enable leak on probe failure

Omitted-fix: 8cff9dbe89d8bd44d9a5e631c9394dd3901ffd79 net: stmmac: Update default_an_inband before passing value to phylink_config

JIRA: https://issues.redhat.com/browse/RHEL-128151
JIRA: https://issues.redhat.com/browse/RHEL-100501

Signed-off-by: Izabela Bakollari <ibakolla@redhat.com>

Approved-by: Ivan Vecera <ivecera@redhat.com>
Approved-by: Jakub Ramaseuski <jramaseu@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>
2026-08-13 08:29:31 +00:00