mirror of
https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10.git
synced 2026-09-09 00:07:04 +08:00
22ca7999128364224a179c71f381fd24d0572c73
100
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
22ca799912 |
Merge: cpuidle: resolve a potential performance degradation
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3221 RESOLVES: RHEL-222582 JIRA: https://redhat.atlassian.net/browse/RHEL-222582 Upstream Status: RHEL-Only This reverts commit |
||
|
|
f78d306b03 |
Merge: drm: several CVE fixes GPU team spring 30
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3217 We are collecting several CVE fixes into single MRs for easier QE testing JIRA: https://redhat.atlassian.net/browse/RHEL-222670 JIRA: https://redhat.atlassian.net/browse/RHEL-222688 JIRA: https://redhat.atlassian.net/browse/RHEL-222698 JIRA: https://redhat.atlassian.net/browse/RHEL-222746 JIRA: https://redhat.atlassian.net/browse/RHEL-222752 JIRA: https://redhat.atlassian.net/browse/RHEL-222574 JIRA: https://redhat.atlassian.net/browse/RHEL-222626 JIRA: https://redhat.atlassian.net/browse/RHEL-222650 ``` CVE: CVE-2026-53329 CVE: CVE-2026-53136 CVE: CVE-2026-53143 CVE: CVE-2026-63884 CVE: CVE-2026-53356 CVE: CVE-2026-64219 CVE: CVE-2026-63879 CVE: CVE-2026-53374 Backported from tree(s): linux ``` Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com> Signed-off-by: Karol Herbst <kherbst@redhat.com> Approved-by: José Expósito <jexposit@redhat.com> Approved-by: Peter Kopec <pekopec@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
005667c2e6 |
Merge: KVM: VMX: introduce module parameter to disable CET
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3212 # Merge Request Required Information ## Summary of Changes ``` KVM: VMX: introduce module parameter to disable CET JIRA: https://redhat.atlassian.net/browse/RHEL-235002 KVM: VMX: introduce module parameter to disable CET There have been reports of host hangs caused by CET virtualization. Until these are analyzed further, introduce a module parameter that makes it possible to easily disable it. ``` ## Approved Development Ticket(s) Resolves: [RHEL-235002](https://redhat.atlassian.net/browse/RHEL-235002) Signed-off-by: Aidan Wallace <awallace@redhat.com> Approved-by: Paolo Bonzini <bonzini@gnu.org> Approved-by: Maxim Levitsky <mlevitsk@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
dbb706437d |
Merge: perf/arm-cmn: Pull forward to 7.2rc
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3211 JIRA: https://redhat.atlassian.net/browse/RHEL-234652 This set pulls the arm-cmn driver forward to current mainline 7.2rc. Signed-off-by: Jeremy Linton <jlinton@redhat.com> Approved-by: Mark Langsdorf <mlangsdo@redhat.com> Approved-by: Mark Salter <msalter@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
d0641739de |
Merge: perf trace: Refactor augmented_raw_syscalls using bpf_for
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3038 JIRA: https://redhat.atlassian.net/browse/RHEL-183355 Fix issue where perf built with clang-22 contains incompatible BPF code that is then refused by the kernel Signed-off-by: Trevor Allison <tallison@redhat.com> Approved-by: Michael Petlan <mpetlan@redhat.com> Approved-by: ashelat <ashelat@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
28e0de09ae |
Merge: ALSA - update drivers for 10.3 - upstream 7.1.5 (stable)
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3023 JIRA: https://issues.redhat.com/browse/RHEL-193253 This upstream patchset updates the ALSA driver code to upstream stable 7.1.5 kernel. Omitted-fix: dd1bfaf9413e9c8a0fcfb45dcb735c6768a45251 # see commit - this revert is for 7.2+ kernel code Omitted-fix: 99c159279c6dfa2c4867c7f76875f58263f8f43b # used hash 225d70b8074502acee3943bf0c2e839e867cd38c for backport - already in RHEL kernel Signed-off-by: Jaroslav Kysela <jkysela@redhat.com> Approved-by: Krzysztof Pawlinski <kpawlins@redhat.com> Approved-by: Desnes Nunes <desnesn@redhat.com> Approved-by: Tony Camuso <tcamuso@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
4932196eca |
Merge: [RHEL 10.3]: rebase HID subsystem to 7.1
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2819 This is the usual rebase of the HID subsystem up to kernel v7.1 for 10.3. ``` JIRA: https://issues.redhat.com/browse/RHEL-170872 JIRA: https://redhat.atlassian.net/browse/RHEL-183865 Depends: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2636 All following omitted-fix are not in drivers/hid/ and can thus safely be ignored: Omitted-fix: fd1d6b9d13f35dccbacbae25ed53593cd9086f84 # xz not part of this MR Omitted-fix: 96a7b71c4438d3b72d6c95e3efdc9e8e8aee6b78 # ubd not part of this MR Omitted-fix: 795469820c638b4449f3bb90ee5e98ebccfbc480 # kcsan not part of this MR Omitted-fix: 5548dd7fa84510f7bbce67c35cc3b388c86aeddf # testing/vma and testing/radix-tree not parts of this MR Omitted-fix: 405ca72dc589dd746e5ee5378bb9d9ee7f844010 # landlock not part of this MR Omitted-fix: 4c0134639694fcdc4ab041d7c53d6188a3e18040 # KVM not part of this MR Omitted-fix: 4c6d43db2a4d2cef3921e885cf34798f790d34ea # net: dst_metadata not part of this MR Omitted-fix: 01793374319cdb685bd487633bbd8bd57f416172 # m68k: defconfig not part of this MR Omitted-fix: 94ff7c59cdfde3a16ab830531acbcb3091b292eb # RDMA not part of this MR Omitted-fix: 2d2b5507e598984f5832f0c5193f35733c42995e # btrfs not part of this MR Omitted-fix: 94ff7c59cdfde3a16ab830531acbcb3091b292eb # RDMA not part of this MR Omitted-fix: 9f4ab0787e7bf6d2c709207317e9d4cd43909869 # btrfs not part of this MR Omitted-fix: 37f1f51fba1a4320149b1ea3b21d254d4b221b0a # btrfs not part of this MR Following one was silently dropped from Linus's tree during 7.2 pull request from Jiri Kosina, my HID co-maintainer: Omitted-fix: d0ff08d946c83b51359a8063c41e9f5af067e628 # not making any effect in 7.2-rc1, silently dropped in a merge commit ``` Signed-off-by: Benjamin Tissoires <benjamin.tissoires@redhat.com> Approved-by: Jarod Wilson <jarod@redhat.com> Approved-by: Tony Camuso <tcamuso@redhat.com> Approved-by: Eric Chanudet <echanude@redhat.com> Approved-by: Andrea Arcangeli <aarcange@redhat.com> Approved-by: David Arcari <darcari@redhat.com> Approved-by: Barry Dunn <badunn@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
50f0687005 |
[redhat] kernel-6.12.0-259.el10
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> |
||
|
|
67043a4593 |
Merge: redhat/kernel.spec.template: Switch UKI addons back to 504 cert
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3282 JIRA: https://redhat.atlassian.net/browse/RHEL-238666 To make kernel's PCR7 measurement the same when UKI cmdline addons are used and when they are not, the addons must be signed by the same cert as the UKI. The switch to 801 was accidential. Signed-off-by: Vitaly Kuznetsov <vkuznets@redhat.com> Approved-by: Emanuele Giuseppe Esposito <eesposit@redhat.com> Approved-by: Jan Stancek <jstancek@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
68c83cdd8a |
Merge: CIFS: fix broken directory listing against old SMB1 servers [rhel-10.3]
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3222 - fix broken directory listing against old SMB1 servers JIRA: https://redhat.atlassian.net/browse/RHEL-235810 Signed-off-by: Paulo Alcantara <paalcant@redhat.com> Approved-by: Scott Mayhew <smayhew@redhat.com> Approved-by: David Howells <dhowells@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
54b94baabf |
Merge: CVE-2026-52991: sched/psi: fix race between file release and pressure write
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3188 JIRA: https://redhat.atlassian.net/browse/RHEL-232559 CVE: CVE-2026-52991 * a5b98009f16d8a5fb4a8ff9a193f5735515c38fa sched/psi: fix race between file release and pressure write [linux] * fadeedd7cfc5d73d33fa3d7ac54b9b27aabd09d2 sched/psi: Create the psimon kthread outside of cgroup_mutex [linux] Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com> [^footer]: Created 2026-08-06 00:56 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer] Approved-by: Waiman Long <longman@redhat.com> Approved-by: Phil Auld <pauld@redhat.com> Approved-by: Rafael Aquini <raquini@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
68916cdc7c |
Merge: vhost: reset the vring metadata cache on vring reconfiguration [10.3]
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3074
JIRA: https://redhat.atlassian.net/browse/RHEL-224534
Backported from tree(s): linux
```
vhost: reset the vring metadata cache on vring reconfiguration
vq->meta_iotlb[] caches the vhost_iotlb_map that backs each vring
metadata region, and iotlb_access_ok() returns early on a cache hit,
taking the hit as proof that the region has already been validated:
if (vhost_vq_meta_fetch(vq, addr, len, type))
return true;
The cache is reset on VHOST_IOTLB_UPDATE and VHOST_IOTLB_INVALIDATE, on
device IOTLB (re)initialisation and on vq reset, but not when
VHOST_SET_VRING_ADDR replaces vq->desc, vq->avail and vq->used, nor when
VHOST_SET_VRING_NUM changes the region sizes.
With a device IOTLB attached both ioctls are accepted while the vq is
live, and neither validates the addresses at ioctl time: vq_access_ok()
and vq_log_used_access_ok() return true early because the addresses are
GIOVAs, deferring validation to prefetch time. Once the cache has been
populated that deferred validation no longer runs -- vq_meta_prefetch()
hits the stale entry and returns true -- and vhost_vq_meta_fetch() keeps
translating through the old mapping as
map->addr + addr - map->start
for an address the mapping no longer covers. vhost_copy_to_user() and
vhost_copy_from_user() consume the result with __copy_to_user() and
__copy_from_user(), which do not check it either, so a subsequent used
ring update or descriptor fetch accesses memory outside the region the
IOTLB actually maps.
Reset the metadata cache whenever the vring is reconfigured, so the new
addresses are pushed back through iotlb_access_ok()'s slow path.
Fixes:
|
||
|
|
93b969cd26 |
Merge: Fix bugs and performance of kstack offset randomisation
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3071 JIRA: https://redhat.atlassian.net/browse/RHEL-215975 Fix various issues with kstack randomization. Signed-off-by: Mark Salter <msalter@redhat.com> Approved-by: Jennifer Berringer <jberring@redhat.com> Approved-by: Steve Best <sbest@redhat.com> Approved-by: Rafael Aquini <raquini@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
69e8c50312 |
Merge: DPLL: Add support for NCO (numerically controlled oscillator)
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2936 JIRA: https://redhat.atlassian.net/browse/RHEL-176048 * b1d0c412088e dpll: add STATE_CONNECTED_OVERRIDE pin capability [net-next] * 0cc8348a9786 dpll: add DPLL_PIN_TYPE_INT_NCO pin type [net-next] * 2b11bde391c4 dpll: zl3073x: use per-operation poll timeouts [net-next] * 21460118d71b dpll: zl3073x: add per-DPLL serialization lock [net-next] * 3553976ffe2f dpll: zl3073x: add NCO virtual input pin [net-next] Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com> [^footer]: Created 2026-07-16 12:53 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer] Approved-by: Ivan Vecera <ivecera@redhat.com> Approved-by: Michal Schmidt <mschmidt@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
b122b344e2 |
Merge: netfilter: rebase on top of v7.2-rc3
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2914 JIRA: https://redhat.atlassian.net/browse/RHEL-185609 CVE: CVE-2026-53211 CVE: CVE-2026-53134 CVE: CVE-2026-53218 CVE: CVE-2026-52942 CVE: CVE-2026-53219 CVE: CVE-2026-53220 CVE: CVE-2026-53266 CVE: CVE-2026-53267 CVE: CVE-2026-53212 CVE: CVE-2026-53268 CVE: CVE-2026-53269 CVE: CVE-2026-53270 CVE: CVE-2026-64554 Next rebase to keep sizes more reviewable. This is very close to upstream with only a few conflicts. Signed-off-by: Florian Westphal <fwestpha@redhat.com> Approved-by: Phil Sutter <psutter@redhat.com> Approved-by: Eric Garver <egarver@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
81916a1f89 |
Merge: Enable batched TLB flush in unmap_hotplug_range()
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2909 JIRA: https://redhat.atlassian.net/browse/RHEL-184786 Use batched TLB flush to speed up unmap_hotplug_range(). Signed-off-by: Mark Salter <msalter@redhat.com> Approved-by: Rafael Aquini <raquini@redhat.com> Approved-by: Luiz Capitulino <luizcap@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
2d4fe3e1e9 |
Merge: CNB103: devlink: update devlink to the v7.1
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2822 JIRA: https://redhat.atlassian.net/browse/RHEL-179081 Depends: !2273 Devlink update to version v7.1 Signed-off-by: Petr Oros <poros@redhat.com> Approved-by: Tony Camuso <tcamuso@redhat.com> Approved-by: Eric Chanudet <echanude@redhat.com> Approved-by: Ivan Vecera <ivecera@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
dca2371bc7 |
Merge: Enable DWAPB I2C controller on Fujitsu MONAKA
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2328 Add Fujitsu Monaka ACPI HID to DWAPB I2C controller JIRA: https://redhat.atlassian.net/browse/RHEL-23132 Signed-off-by: Mark Salter <msalter@redhat.com> Approved-by: Tony Camuso <tcamuso@redhat.com> Approved-by: Daniel Horak <dhorak@redhat.com> Approved-by: Jiri Dluhos <jdluhos@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
ae83fae2e8 |
Merge: Enable DWAPB GPIO controller on Fujitsu MONAKA
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2327 Add Fujitsu Monaka ACPI HID to designware GPIO driver JIRA: https://redhat.atlassian.net/browse/RHEL-23123 Signed-off-by: Mark Salter <msalter@redhat.com> Approved-by: Daniel Horak <dhorak@redhat.com> Approved-by: Jiri Dluhos <jdluhos@redhat.com> Approved-by: Bastien Nocera <bnocera@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
9065da685e |
Merge: stmmac driver update up to v6.17+
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2113 This MR was opened with patches from a previous MR due to difference conflicts. Omitted-fix: eb6ac268a7c9b9e1c57daac4c68b634049d3d8c6 mips: configs: loongson1: Update defconfig Omitted-fix: 89886abd073489e26614e4d80fb8eb70d3938a0b net: stmmac: dwc-qos: fix clk prepare/enable leak on probe failure Omitted-fix: 8cff9dbe89d8bd44d9a5e631c9394dd3901ffd79 net: stmmac: Update default_an_inband before passing value to phylink_config JIRA: https://issues.redhat.com/browse/RHEL-128151 JIRA: https://issues.redhat.com/browse/RHEL-100501 Signed-off-by: Izabela Bakollari <ibakolla@redhat.com> Approved-by: Ivan Vecera <ivecera@redhat.com> Approved-by: Jakub Ramaseuski <jramaseu@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
b2e46d1a0a |
[redhat] kernel-6.12.0-258.el10
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> |
||
|
|
3de2e81edd |
Merge: i2c: core: Updates to fix adapter deregistration race
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3065 Description: updates to fix adapter deregistration race JIRA: https://issues.redhat.com/browse/RHEL-222908 CVE: CVE-2026-64279 Signed-off-by: Steve Best <sbest@redhat.com> Approved-by: Tony Camuso <tcamuso@redhat.com> Approved-by: David Arcari <darcari@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
98a72659c1 |
Merge: CVE-2026-64496: iio: event: Fix event FIFO reset race
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3062
JIRA: https://redhat.atlassian.net/browse/RHEL-223371
CVE: CVE-2026-64496
Backported from tree(s): linux
```
iio: event: Fix event FIFO reset race
`iio_event_getfd()` creates the event file descriptor with
`anon_inode_getfd()`, which allocates a new fd, creates the anonymous
file and installs it in the process fd table before returning to the
caller.
The IIO code resets the event FIFO after `anon_inode_getfd()` has returned,
but before `IIO_GET_EVENT_FD_IOCTL` has copied the fd number to userspace.
But since fd tables are shared between threads, another thread can guess
the newly allocated fd number and issue a `read()` on it as soon as the fd
has been installed.
This means the `kfifo_to_user()` in `iio_event_chrdev_read()` can run in
parallel with the `kfifo_reset_out()` in `iio_event_getfd()`.
The kfifo documentation says that `kfifo_reset_out()` is only safe when it
is called from the reader thread and there is only one concurrent reader.
Otherwise it is dangerous and must be handled in the same way as
`kfifo_reset()`.
If that happens, `kfifo_to_user()` can advance the FIFO `out` index based
on state from before the reset, after the reset has already moved the `out`
index to the current `in` index. That can leave the FIFO with an `out`
index past the `in` index. A later `read()` can then see an underflowed
FIFO length and copy more data than the event FIFO buffer contains. This
can result in an out-of-bounds read and leak adjacent kernel memory to
userspace.
Move the FIFO reset before `anon_inode_getfd()`. At that point the event fd is
marked busy, but the new fd has not been installed yet, so userspace cannot
access it while the FIFO is reset.
Fixes:
|
||
|
|
8664709d12 |
Merge: SELinux TCP/MPTCP connect check bypass via TCP Fast Open
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3056 JIRA: https://redhat.atlassian.net/browse/RHEL-222799 Backported from tree(s): linux ``` selinux: check connect-related permissions on TCP Fast Open Similar to Landlock, SELinux was not updated when TCP Fast Open support was introduced to ensure connect-related permissions are checked when using TCP Fast Open. Update its socket_sendmsg() hook to call selinux_socket_connect() when MSG_FASTOPEN is passed. Cc: stable@vger.kernel.org Link: https://lore.kernel.org/linux-security-module/20260616201615.275032-1-hexlabsecurity@proton.me/ Link: https://lore.kernel.org/linux-security-module/20260617180526.15627-2-matthieu@buffet.re/ Reported-by: Bryam Vargas <hexlabsecurity@proton.me> Reported-by: Matthieu Buffet <matthieu@buffet.re> Reported-by: Mikhail Ivanov <ivanov.mikhail1@huawei-partners.com> Signed-off-by: Stephen Smalley <stephen.smalley.work@gmail.com> Tested-by: Bryam Vargas <hexlabsecurity@proton.me> Signed-off-by: Paul Moore <paul@paul-moore.com> (cherry picked from commit 44c74d27d1b9aaa99fa8a83640c1223575262b80) ``` Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com> [^footer]: Created 2026-08-03 08:12 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer] Approved-by: Ondrej Mosnáček <omosnacek@gmail.com> Approved-by: Ricardo Robaina <rrobaina@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
678cacd4fd |
Merge: mfd: intel-lpss: Add Intel Nova Lake-H PCI IDs
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3050 JIRA: https://redhat.atlassian.net/browse/RHEL-154489 commit d6e0ef44688249009dfa24f1cd619d41637de060 Author: Saranya Gopal <saranya.gopal@intel.com> Date: Fri Mar 13 12:03:37 2026 +0200 mfd: intel-lpss: Add Intel Nova Lake-H PCI IDs Add Intel Nova Lake-H LPSS PCI IDs. Signed-off-by: Saranya Gopal <saranya.gopal@intel.com> Co-developed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com> Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com> Reviewed-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com> Link: https://patch.msgid.link/20260313100337.3471-1-ilpo.jarvinen@linux.intel.com Signed-off-by: Lee Jones <lee@kernel.org> Signed-off-by: Steve Best <sbest@redhat.com> Approved-by: Tony Camuso <tcamuso@redhat.com> Approved-by: David Arcari <darcari@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
761311b5b0 |
Merge: CVE-2026-64531: net: openvswitch: reject oversized nested action attrs
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3041 JIRA: https://redhat.atlassian.net/browse/RHEL-222496 CVE: CVE-2026-64531 Backported from tree(s): linux ``` net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guard preventing a generated nested action attribute from exceeding U16_MAX. An oversized generated container can thus be closed with a truncated nla_len. A later dump or teardown then walks a structurally different stream than the one that was validated. In particular, an oversized nested CLONE/CT action may cause subsequent bytes in the generated stream to be interpreted as independent actions. Keep the larger total-action-stream behavior, but make nested action close reject generated containers that do not fit in nla_len, and return the error through all callers. For recursive SAMPLE, CLONE, DEC_TTL, and CHECK_PKT_LEN builders, trim resource-owning action-list tails in reverse construction order before discarding failed wrappers, so resources copied into the rejected tails are released before the wrappers are removed. Most failed outer wrappers are discarded by truncating actions_len after child resources have been released. CHECK_PKT_LEN also trims its parent after branch resources are gone. SET/TUNNEL close failures unwind their known tun_dst ownership directly, and SET_TO_MASKED has no external ownership and truncates on close failure. Fixes: a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") Cc: stable@vger.kernel.org Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me> Reviewed-by: Eelco Chaudron <echaudro@redhat.com> Reviewed-by: Aaron Conole <aconole@redhat.com> Reviewed-by: Ilya Maximets <i.maximets@ovn.org> Link: https://patch.msgid.link/20260706094336.38639-1-manizada@pm.me Signed-off-by: Paolo Abeni <pabeni@redhat.com> (cherry picked from commit 3f1f755366687d051174739fb99f7d560202f60b) ``` Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com> [^footer]: Created 2026-07-31 12:02 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer] Approved-by: Timothy Redaelli <tredaelli@redhat.com> Approved-by: Jarod Wilson <jarod@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
79b40df421 |
Merge: mei: bus: access mei_device under device_lock on cleanup
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3039 JIRA: https://redhat.atlassian.net/browse/RHEL-222295 commit f112ea910e554d58b4b39a4492b7d302f0f4204f Author: Alexander Usyskin <alexander.usyskin@intel.com> Date: Sun Jul 5 18:12:59 2026 +0300 mei: bus: access mei_device under device_lock on cleanup Fix couple of problems in mei_cl_bus_dev_release(): mei_cl_flush_queues() is running without lock. bus->file_list access after mei_dev_bus_put(bus) can become a use-after-free if this was the last reference to bus. Protect queues cleanup and WARN traversal by device lock there to avoid the concurrent access problems. Move WARN traversal before mei_dev_bus_put(bus). This file uses bus variable name for mei_device, adjust code of mei_cl_bus_dev_release() to use bus variable too. Cc: stable <stable@kernel.org> Fixes: 35e8a426b16a ("mei: bus: Check for still connected devices in mei_cl_bus_dev_release()") Reviewed-by: Menachem Adin <menachem.adin@intel.com> Signed-off-by: Alexander Usyskin <alexander.usyskin@intel.com> Link: https://patch.msgid.link/20260705151259.3054795-1-alexander.usyskin@intel.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Signed-off-by: Steve Best <sbest@redhat.com> Approved-by: Tony Camuso <tcamuso@redhat.com> Approved-by: David Arcari <darcari@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
ca96e3617f |
Merge: PM: EM: Fixes cost field and late boot with holes in CPU topology
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3035 Description: updates to Fix cost field and late boot with holes in CPU topology JIRA: https://issues.redhat.com/browse/RHEL-220528 Signed-off-by: Steve Best <sbest@redhat.com> Approved-by: Tony Camuso <tcamuso@redhat.com> Approved-by: Lenny Szubowicz <lszubowi@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
167d82ada9 |
Merge: soc/tegra: fuse: Fix spurious straps warning on SMCCC platforms
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3028 JIRA: https://issues.redhat.com/browse/RHEL-191743 This commit fixes a spurious warning seen frequently on NVIDIA platforms. Signed-off-by: Charles Mirabile <cmirabil@redhat.com> Approved-by: Eric Chanudet <echanude@redhat.com> Approved-by: Mark Salter <msalter@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
5d18076645 |
Merge: pinctrl-amd: Don't clear S4 wake bits at probe
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3014 JIRA: https://redhat.atlassian.net/browse/RHEL-212012 commit ffe8a0c6b55285ceaf2f42fc20c3a0594d14f1e9 Author: Mario Limonciello <mario.limonciello@amd.com> Date: Mon Jul 20 11:28:44 2026 -0500 pinctrl-amd: Don't clear S4 wake bits at probe commit |
||
|
|
d9c7877130 |
Merge: tools/power/x86/intel-speed-select: Harden daemon pidfile open
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3008
JIRA: https://redhat.atlassian.net/browse/RHEL-214504
commit 607af438e6430893a822964c841a1994b33acccc
Author: Ali Ahmet MEMIS <dev@unknownbbqr.xyz>
Date: Sun Apr 26 08:09:28 2026 -0700
tools/power/x86/intel-speed-select: Harden daemon pidfile open
Avoid symlink-based pidfile clobbering by opening the pidfile with
O_NOFOLLOW and validating it with fstat() before locking/writing.
The daemon currently uses a fixed pidfile path under /tmp. A local
unprivileged user can pre-create a symlink at that path and cause a
root-run daemon instance to write into an attacker-chosen file.
Fixes:
|
||
|
|
e16e1db3dd |
Merge: gve: fix netdev_lock deadlock in gve_add_napi by using netif_napi_set_irq_locked.
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3007
JIRA: https://redhat.atlassian.net/browse/RHEL-218195
Fix a deadlock introduced by https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/commit/83634e21c064.
Since queue operations require holding a lock, the operations inside should use the locked variant.
[mschmidt] The commit "net: hold netdev instance lock during queue operations" was already backported in RHEL 10.2 as commit
|
||
|
|
c87b51b595 |
Merge: platform/x86/intel/tpmi: Add notifiers support and move debugfs register before creating devices
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2997 Description: updates to Add notifiers support and move debugfs register before creating devices JIRA: https://issues.redhat.com/browse/RHEL-215232 Signed-off-by: Steve Best <sbest@redhat.com> Approved-by: Tony Camuso <tcamuso@redhat.com> Approved-by: Lenny Szubowicz <lszubowi@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
87e69294ba |
Merge: platform/x86/intel/vsec: Updates to fix enable_cnt imbalance on PCIe error recovery
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2993 Description: updates to Fix enable_cnt imbalance on PCIe error recovery JIRA: https://issues.redhat.com/browse/RHEL-213934 Signed-off-by: Steve Best <sbest@redhat.com> Approved-by: Tony Camuso <tcamuso@redhat.com> Approved-by: David Arcari <darcari@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
301d8a376c |
Merge: udf: fix partition descriptor append bookkeeping
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2992 JIRA: https://issues.redhat.com/browse/RHEL-179577 CVE: CVE-2026-45991 Backport of upstream commit 08841b06fa64d8edbd1a21ca6e613420c90cc4b8. Fixes heap OOB write in handle_partition_descriptor() triggered by crafted UDF images with repeated partition descriptors. Manual backport - trivial context conflict: upstream uses kzalloc_objs(), cs10 uses kcalloc().The allocation call itself is not modified by the fix. Signed-off-by: Ravi Singh <ravising@redhat.com> Approved-by: Carlos Maiolino <cmaiolino@redhat.com> Approved-by: Donald Douwsma <ddouwsma@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
4cd89b7da5 |
Merge: KVM: kvm fixes for 2026-07-21
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2977 KVM: kvm fixes for 2026-07-21 JIRA: https://redhat.atlassian.net/browse/RHEL-213327 CVE: CVE-2026-63807 Commits: ``` KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level KVM: nVMX: Hide shadow VMCS right after VMCLEAR KVM: x86: Check for invalid/obsolete root *after* making MMU pages available KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state ``` Signed-off-by: Aidan Wallace <awallace@redhat.com> Approved-by: Paolo Bonzini <bonzini@gnu.org> Approved-by: Maxim Levitsky <mlevitsk@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
da047dae90 |
Merge: cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF()
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2972
JIRA: https://redhat.atlassian.net/browse/RHEL-212894
commit 27d80e0f8b8dff97503fc0061754b1d3800cb961
Author: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Date: Tue Jul 7 19:19:55 2026 +0200
cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF()
Setting cpu->capacity_perf to cpu->pstate.max_pstate_physical in the
"no turbo" case is inconsistent with what happens elsewhere in the
driver and causes arch_scale_cpu_capacity() to be incorrect. It also
skews arch_scale_freq_capacity() which ends up differing from 1024 for
the guaranteed P-state.
Address that by setting capacity_perf to HWP_GUARANTEED_PERF() in the
"no turbo" case.
Fixes:
|
||
|
|
4bd0498586 |
Merge: thermal: intel: Fix dangling resources on thermal_throttle_online() failure
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2968
JIRA: https://issues.redhat.com/browse/RHEL-212369
commit b91d287fa7a1ba0727eed5823c6ee4924ee5fa31
Author: Ricardo Neri <ricardo.neri-calderon@linux.intel.com>
Date: Sat Jun 13 15:17:47 2026 -0700
thermal: intel: Fix dangling resources on thermal_throttle_online() failure
The function thermal_throttle_add_dev() may fail and abort a CPU hotplug
online operation. Since the failure occurs within the online callback,
thermal_throttle_online(), the CPU hotplug framework does not invoke the
corresponding offline callback. As a result, the hardware and software
resources set up during the failed operation are not torn down.
Since only thermal_throttle_add_dev() can fail, call it before setting up
the rest of the resources.
Fixes:
|
||
|
|
ae562ec0da |
Merge: platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2965
JIRA: https://redhat.atlassian.net/browse/RHEL-212368
commit 6b63520ed14b17bbe9c2103debbd2152dde1fba3
Author: Guixiong Wei <weiguixiong@bytedance.com>
Date: Tue Jun 2 10:07:52 2026 +0800
platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug
When the last CPU of a legacy uncore die goes offline,
uncore_freq_remove_die_entry() clears control_cpu. During CPU hotplug
re-add, uncore_freq_add_entry() still populates sysfs attributes before
assigning the new control CPU. As a result, the current frequency read
returns -ENXIO and current_freq_khz is omitted from the recreated sysfs
group.
Assign control_cpu before the initial read paths and before
create_attr_group() so sysfs recreation uses the new online CPU. If
sysfs creation fails, restore control_cpu to -1 to keep the error path
state consistent.
Fixes:
|
||
|
|
1e619169c1 |
Merge: x86/mm: Disable broadcast TLB flush when PCID is disabled
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2962 JIRA: https://redhat.atlassian.net/browse/RHEL-179500 ``` commit 44126343d58c68adaa8343fbf1c07dd20078c35e Author: Tom Lendacky <thomas.lendacky@amd.com> Date: Wed May 20 12:00:50 2026 -0500 x86/mm: Disable broadcast TLB flush when PCID is disabled ``` Signed-off-by: Rafael Aquini <raquini@redhat.com> Approved-by: Nico Pache <npache@redhat.com> Approved-by: David Arcari <darcari@redhat.com> Approved-by: Julia Denham <jdenham@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
cf77514c4c |
Merge: CVE-2025-71072 kernel: shmem: fix recovery on rename failures [rhel-10.3]
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2960 JIRA: https://redhat.atlassian.net/browse/RHEL-189572 CVE: CVE-2025-71072 ``` commit e1b4c6a58304fd490124cc2b454d80edc786665c Author: Al Viro <viro@zeniv.linux.org.uk> Date: Sat Dec 13 17:50:23 2025 -0500 shmem: fix recovery on rename failures ``` Signed-off-by: Rafael Aquini <raquini@redhat.com> Approved-by: Luiz Capitulino <luizcap@redhat.com> Approved-by: Ricardo Robaina <rrobaina@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
fd8b3f84d9 |
Merge: futex: Optimize futex hash bucket access patterns
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2946 JIRA: https://redhat.atlassian.net/browse/RHEL-193649 MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2946 Omitted-fix: fa188edc671d ("linux/bitfield.h: replace __auto_type with auto") This MR backports commit a734d9fca84e ("futex: Optimize futex hash bucket access patterns") to improve the futex hashing performance as measured by the "perf bench futex hash" benchmark to a level comparable with that of RHEL 9.7. Patch 1 is a dependency that is used to simplify the backport and patch 2 is its fix patch. When running the “perf bench futex hash” benchmark on a 2-sock 96-thread CascadeLake test system, the test results before and after the patch are as follows: ``` Baseline Patched Delta -b 16 131,592 154,034 +17.1% -b 64 209,511 280,855 +34.1% -b 256 501,989 670,136 +33.5% -b 512 702,066 1,010,336 +43.9% -b 1024 864,451 1,230,717 +42.4% -b 4096 1,555,876 1,592,870 + 2.4% -b 16384 1,595,744 1,653,120 + 3.6% -b 65536 1,664,668 1,773,148 + 6.5% ``` Signed-off-by: Waiman Long <longman@redhat.com> Approved-by: Rafael Aquini <raquini@redhat.com> Approved-by: Ricardo Robaina <rrobaina@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
14cb9f4bc6 |
Merge: ARM64: Mitigate TLBI errata on various CPUs
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2929 JIRA: https://redhat.atlassian.net/browse/RHEL-183605 CVE: CVE-2025-10263 Mitigate TLBI errata on: - Azure Cobalt 100 - Nvidia Olympus - Cortex A76, A76AE - Cortex A77 - Cortex A78, A78AE, A78C - Cortex A710 - Cortex X1, X1C, X2, X3, X4 - Cortex X925 - Cortex N1, N2 - Cortex V1, V2, V3, V3AE - C1-Premium, C1-Ultra Signed-off-by: Mark Salter <msalter@redhat.com> Approved-by: Mark Langsdorf <mlangsdo@redhat.com> Approved-by: Charles Mirabile <cmirabil@redhat.com> Approved-by: Steve Dunnagan <sdunnaga@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
a2cb7a3d93 |
Merge: [RHEL-10.3] Update IPMI drivers to upstream v7.1
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2799 JIRA: https://redhat.atlassian.net/browse/RHEL-187338 Brew: https://brewweb.engineering.redhat.com/brew/taskinfo?taskID=71129566 Backport updates for IPMI drivers from upstream v7.1 Signed-off-by: Dennis Chen <dechen@redhat.com> Approved-by: Tony Camuso <tcamuso@redhat.com> Approved-by: Steve Best <sbest@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
511f7e1119 |
Merge: [RHEL-10.3] Update IPMI documentation to upstream v7.1
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2795 JIRA: https://redhat.atlassian.net/browse/RHEL-187342 Update IPMI-related documentation to upstream v7.1. Signed-off-by: Dennis Chen <dechen@redhat.com> Approved-by: Tony Camuso <tcamuso@redhat.com> Approved-by: Steve Best <sbest@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
64f65ca0c3 |
Merge: ice: driver update to net/main 2026-06-23
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2791 JIRA: https://redhat.atlassian.net/browse/RHEL-187013 Update the ice driver with the latest from commits from net/main as of 2026-06-23. Depends: !2783 Signed-off-by: Michal Schmidt <mschmidt@redhat.com> Approved-by: Jarod Wilson <jarod@redhat.com> Approved-by: Kamal Heib <kheib@redhat.com> Approved-by: Jakub Ramaseuski <jramaseu@redhat.com> Approved-by: Ivan Vecera <ivecera@redhat.com> Approved-by: Petr Oros <poros@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
b6b5180ba8 |
Merge: Wireless core and drivers rebase to v7.1
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2764 JIRA: https://issues.redhat.com/browse/RHEL-184812 Tested: basic testing with several supported WiFi cards (Intel, Qualcomm, Mediatek and Realtek). Wireless core and drivers update to v7.1 Upstream status: linux.git Depends: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2748 Not supported drivers: Omitted-fix: c882b7a603ef wifi: at76c50x: drop redundant device reference Omitted-fix: ea06baf59bd4 wifi: ipw2x00: Rename michael_mic() to libipw_michael_mic() Omitted-fix: 32a0e1c63cdf wifi: ipw2x00: Use michael_mic() from cfg80211 Non-wireless fixes for treewide commits (only mac80211 is applied): Omitted-fix: fd1d6b9d13f3 xz: fix arm fdt compile error for kmalloc replacement Omitted-fix: 96a7b71c4438 ubd: Use pointer-to-pointers for io_thread_req arrays Omitted-fix: 795469820c63 kcsan: test: Adjust "expect" allocation type for kmalloc_obj Omitted-fix: 5548dd7fa845 tools/testing: fix testing/vma and testing/radix-tree build Omitted-fix: 405ca72dc589 landlock: Fix formatting Omitted-fix: 4c0134639694 KVM: PPC: e500: Fix build error due to using kmalloc_obj() with wrong type Omitted-fix: 94ff7c59cdfd RDMA: Complete k[z|m|c]alloc-to-k[z|m]alloc_obj conversion Omitted-fix: 2d2b5507e598 btrfs: replace kcalloc() calls to kzalloc_objs() Omitted-fix: 9f4ab0787e7b btrfs: do more kmalloc_obj()/kmalloc_objs() conversions Omitted-fix: 37f1f51fba1a btrfs: convert kmalloc_array to kmalloc_objs in btrfs_calc_avail_data_space() Omitted-fix: 4c6d43db2a4d net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone Non-important fixes: Omitted-fix: 44494b0d1d16 wifi: mac80211: allocate backup ieee80211_nan_sched_cfg off stack Signed-off-by: Jose Ignacio Tornos Martinez <jtornosm@redhat.com> Approved-by: Jarod Wilson <jarod@redhat.com> Approved-by: Kamal Heib <kheib@redhat.com> Approved-by: Ivan Vecera <ivecera@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
ccf31c85f3 |
Merge: mhi bus update to 7.1
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2748 JIRA: https://redhat.atlassian.net/browse/RHEL-184811 MHI bus rebase to linux kernel upstream version v7.1 It will be used by Wireless (Wifi and WWAN) and automotive components. Non-mhi fixes for treewide commits: Omitted-fix: fd1d6b9d13f3 xz: fix arm fdt compile error for kmalloc replacement Omitted-fix: 96a7b71c4438 ubd: Use pointer-to-pointers for io_thread_req arrays Omitted-fix: 795469820c63 kcsan: test: Adjust "expect" allocation type for kmalloc_obj Omitted-fix: 5548dd7fa845 tools/testing: fix testing/vma and testing/radix-tree build Omitted-fix: 405ca72dc589 landlock: Fix formatting Omitted-fix: 4c0134639694 KVM: PPC: e500: Fix build error due to using kmalloc_obj() with wrong type Omitted-fix: 94ff7c59cdfd RDMA: Complete k[z|m|c]alloc-to-k[z|m]alloc_obj conversion Omitted-fix: 2d2b5507e598 btrfs: replace kcalloc() calls to kzalloc_objs() Omitted-fix: 9f4ab0787e7b btrfs: do more kmalloc_obj()/kmalloc_objs() conversions Omitted-fix: 37f1f51fba1a btrfs: convert kmalloc_array to kmalloc_objs in btrfs_calc_avail_data_space() Omitted-fix: 4c6d43db2a4d net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone Signed-off-by: Jose Ignacio Tornos Martinez <jtornosm@redhat.com> Approved-by: Kamal Heib <kheib@redhat.com> Approved-by: Jakub Ramaseuski <jramaseu@redhat.com> Approved-by: Ivan Vecera <ivecera@redhat.com> Approved-by: Mattijs Korpershoek <mkorpershoek@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
75cc90f647 |
Merge: media: rebase the media to the upstream release 7.2-1
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2573 JIRA: https://redhat.atlassian.net/browse/RHEL-162129 JIRA: https://redhat.atlassian.net/browse/RHEL-23291 This work rebase the media tree against 06cb687a5132 (media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()) This work rebased the kernel media to the upstream commit. The major changes include: 1. IPU6 update. 2. The fixes for ov01a10 and also add support for ov01a1b image sensor. 3. Update the sensor IDs in ipu-bridge drivers. 4. UVC camera updates. 5. Include and enable AMD ISP4 (RHEL-23291) Omitted-fix: 04344d0b4929caa94c0df72f767752aa0935ef5d (airspy) Omitted-fix: 7201c17786a498497bca57752883b90914d405ac (msi2500) Omitted-fix: 33ca0aab6f4bd90921fc1395478f38f72c4d19af (rtl2832_sdr) Omitted-fix: ffc8eec06378a340d708c889184ab3e14b57d540 (stm32-dcmipp) Omitted-fix: bbba3e260a62810a717b4442a3bb96d0ec0f6309 (sun4i-csi) airspy, msi2500, rtl2832_sdr, stm32-dcmipp, and sun4i-csi aren't enabled in RHEL10 Depends: !2677 Signed-off-by: Kate Hsuan <hpa@redhat.com> Approved-by: Karol Herbst <kherbst@redhat.com> Approved-by: Jarod Wilson <jarod@redhat.com> Approved-by: David Arcari <darcari@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
a9cddb65a8 |
Merge: udp: stable backports from upstream for 10.3 phase 1
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2329 JIRA: https://issues.redhat.com/browse/RHEL-152739 Patch 1 and 3 address non critical issues. Patch 2 is a trivial pre-req for patch 3. Signed-off-by: Paolo Abeni <pabeni@redhat.com> Approved-by: Antoine Tenart <atenart@redhat.com> Approved-by: Guillaume Nault <gnault@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
31daee32f1 |
Merge: [RHEL-10] Update MM-core codebase and its dependencies to upstream v6.17
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2316 JIRA: https://issues.redhat.com/browse/RHEL-145695 Depends: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2267 List of CVEs addressed by this update: CVE: CVE-2026-43388 CVE: CVE-2026-23012 CVE: CVE-2026-31653 CVE: CVE-2025-40008 CVE: CVE-2025-40006 CVE: CVE-2025-39877 CVE: CVE-2025-39910 CVE: CVE-2025-39916 CVE: CVE-2025-39909 CVE: CVE-2025-39845 CVE: CVE-2025-39844 CVE: CVE-2025-39899 CVE: CVE-2025-39902 CVE: CVE-2025-39775 CVE: CVE-2025-38686 CVE: CVE-2025-38554 CVE: CVE-2025-39700 CVE: CVE-2025-38681 Set of changes to level the RHEL-10 MM-core and dependencies codebase up to upstream's v6.17 (stable). The following set of "omitted-fixes" is not critical, and the commits in the list below will eventually be picked up later on, without causing any further conflicts, when we wrap up the update work with v6.18 LTS. Omitted-fix: 1442bb87b878 ("s390/boot: Use entire page for PTEs") Omitted-fix: b4a96ab50f36 ("powerpc/kdump: Add support for crashkernel CMA reservation") Omitted-fix: 4ba5a8a7faa6 ("vmw_balloon: indicate success when effectively deflating during migration") Omitted-fix: 51e38e7d40d6 ("mm: add remap_pfn_range_prepare(), remap_pfn_range_complete()") Omitted-fix: dd3b304b9410 ("mm/page_alloc: use xxx_pageblock_isolate() for better reading") Omitted-fix: f04aad36a07c ("mm/ksm: fix flag-dropping behavior in ksm_madvise") Omitted-fix: c373f7f98e6a ("mm/sparse-vmemmap: fix vmemmap accounting underflow") Omitted-fix: 7e89979f6695 ("include/linux/pgtable.h: convert arch_enter_lazy_mmu_mode() and friends to static inlines") Omitted-fix: 84f4928446e6 ("tools/testing/selftests: add merge test for partial msealed range") Omitted-fix: bce1dabd310e ("selftests/mm: fix usage of FORCE_READ() in cow tests") Omitted-fix: d7484f6edd31 ("Docs/mm/damon/design: fix wrong link to intervals goal section") Omitted-fix: 1736047a4e96 ("mm/damon/core: cleanup targets and regions at once on kdamond termination") Omitted-fix: 0199390a6b92 ("mm/damon/sysfs: dealloc repeat_call_control if damon_call() fails") Omitted-fix: 4c04c6b47c36 ("mm/damon/stat: deallocate damon_call() failure leaking damon_ctx") Omitted-fix: 7e6cc35f5283 ("mm/damon/core: trace esz at first setup") Omitted-fix: 2f6ce7e714ef ("mm/damon/stat: change last_refresh_jiffies to a global variable") Omitted-fix: 84481e705ab0 ("mm/damon/stat: monitor all System RAM resources") Omitted-fix: e04ed278d25b ("mm/damon/stat: fix memory leak on damon_start() failure in damon_stat_start()") Omitted-fix: f98590bc08d4 ("mm/damon/stat: detect and use fresh enabled value") Omitted-fix: 7746d72c6405 ("samples/damon/mtier: fail early if address range parameters are invalid") Omitted-fix: c62cff40481c ("samples/damon/mtier: avoid starting DAMON before initialization") Omitted-fix: e6b733ca2f99 ("samples/damon/prcl: avoid starting DAMON before initialization") Omitted-fix: f826edeb888c ("samples/damon/wsse: avoid starting DAMON before initialization") Signed-off-by: Rafael Aquini <raquini@redhat.com> Approved-by: Luiz Capitulino <luizcap@redhat.com> Approved-by: Ricardo Robaina <rrobaina@redhat.com> Approved-by: Eder Zulian <ezulian@redhat.com> Approved-by: David Arcari <darcari@redhat.com> Approved-by: ashelat <ashelat@redhat.com> Approved-by: José Expósito <jexposit@redhat.com> Approved-by: Michael Petlan <mpetlan@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
ebb974fce7 |
Merge: cxgb4: flower: add support for fragmentation
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2286 JIRA: https://redhat.atlassian.net/browse/RHEL-128835 ``` commit 0d0eb186421d0886ac466008235f6d9eedaf918e Author: Harshita V Rajput <harshitha.vr@chelsio.com> Date: Tue Oct 28 13:22:55 2025 +0530 cxgb4: flower: add support for fragmentation This patch adds support for matching fragmented packets in tc flower filters. Previously, commit |
||
|
|
6738d1f143 |
[redhat] kernel-6.12.0-257.el10
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> |
||
|
|
3026f81a0d |
Merge: redhat/configs: automotive: debug: enable KASAN_INLINE
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3042 ## Summary of Changes Enable `KASAN_INLINE` instead of `KASAN_OUTLINE` to improve automotive debug kernel performance. This allows debug kernels to boot on the NXP S32G-VNP-RDB3 without running into timing issues, such as timeouts while waiting for rootfs to mount, sleeps taking longer than expected, and kernel timestamps going backwards. ## Approved Development Ticket(s) JIRA: https://redhat.atlassian.net/browse/RHEL-222562 Upstream ARK MR: https://gitlab.com/cki-project/kernel-ark/-/merge_requests/4637 Signed-off-by: Jared Kangas <jkangas@redhat.com> Approved-by: ernunes <ernunes@redhat.com> Approved-by: Eric Chanudet <echanude@redhat.com> Approved-by: Rafael Aquini <raquini@redhat.com> Approved-by: Ricardo Robaina <rrobaina@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
d04a12fab4 |
Merge: wifi: ath12k: fix NULL pointer dereference in rhash table destroy
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3036 JIRA: https://redhat.atlassian.net/browse/RHEL-213608 This fix is necessary to allow unbinding ath12k device in order to allow to apply the workaround to work on VMs. Signed-off-by: Filip Balluch <fballuch@redhat.com> Approved-by: José Ignacio Tornos Martínez <jtornosm@redhat.com> Approved-by: Michal Schmidt <mschmidt@redhat.com> Approved-by: Jarod Wilson <jarod@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
1d001b6a61 |
Merge: xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3027 xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN JIRA: https://redhat.atlassian.net/browse/RHEL-219079 Upstream Status: https://git.kernel.org/pub/scm/fs/xfs/xfs-linux.git Author: Lin Jiapeng <jiapenglin@tencent.com> Date: Tue, 28 Jul 2026 10:23:03 +0800 xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN When exchanging two full-file ranges, xmi_can_exchange_reflink_flags() can move the reflink inode flag from the file that currently has it to the other file, as long as exactly one side is marked. This assumes that the file contents, and therefore all shared extents, are exchanged. That assumption is not true when XFS_EXCHMAPS_INO1_WRITTEN is set. xfs_exchmaps_can_skip_mapping() can skip hole and unwritten mappings from file1, so an exchange can complete without moving every mapping that the earlier flag-swap decision accounted for. In that case the post-operation cleanup can clear the reflink flag from an inode that still owns shared written extents. Later writes then take the non-reflink write path and may update blocks that should still have been protected by CoW, which shows up as data corruption between reflink-related files. Fix this by disabling the reflink flag exchange whenever XFS_EXCHMAPS_INO1_WRITTEN is requested. The contents exchange can still proceed; the conservative outcome is that both inodes keep the reflink flag. The regular reflink flag cleanup path can drop the extra flag later once the inode no longer has shared extents. Signed-off-by: Lin Jiapeng <jiapenglin@tencent.com> v3: update upstream status Signed-off-by: Lukas Herbolt <lherbolt@redhat.com> Approved-by: Pavel Reichl <preichl@redhat.com> Approved-by: Carlos Maiolino <cmaiolino@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
98b4138745 |
Merge: rtla: Stop the record trace on interrupt && rtla/timerlat_top: Fix on-threshold actions firing on signal [rhel-10]
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3010 # Merge Request Required Information JIRA: https://redhat.atlassian.net/browse/RHEL-207634 ## Summary of Changes Tl;dr: RTLA 7.1 rebase MR (https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2265) pulled in an incorrect fix of an earlier issue that together with another oversight lead to a bug in on-threshold actions of rtla-timerlat-top tool (see the JIRA for details); this pulls in fixes for both. ## Approved Development Ticket(s) All submissions to CentOS Stream must reference a ticket in [Red Hat Jira](https://issues.redhat.com/). <details><summary>Click for formatting instructions</summary> Please follow the CentOS Stream [contribution documentation](https://docs.centos.org/centos-stream-docs/contributors-guide/) for how to file this ticket and have it approved. List tickets each on their own line of this description using the format "Resolves: RHEL-76229", "Related: RHEL-76229" or "Reverts: RHEL-76229", as appropriate. </details> Signed-off-by: Tomas Glozar <tglozar@redhat.com> Approved-by: Wander Lairson Costa <wander@redhat.com> Approved-by: Gabriele Monaco <gmonaco@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
bc0504ed33 |
Merge: dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync()
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2949 JIRA: https://redhat.atlassian.net/browse/RHEL-198358 Backported from tree(s): net ``` dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() When a dpll_pin is shared across multiple dpll_device instances and those devices are being unregistered (e.g. during driver module removal), a NULL pointer dereference can occur in dpll_msg_add_pin_ref_sync(). This happens under the following conditions: - A pin is registered with two or more dpll devices (dpll_A, dpll_B) - The pin has ref_sync pairs with other pins - During unregistration of dpll_A's pins, a ref_sync partner pin is unregistered first, removing it from dpll_A->pin_refs - But since the partner pin is still registered with dpll_B, its dpll_refs is not empty, so dpll_pin_ref_sync_pair_del() does NOT run and the partner stays in the pin's ref_sync_pins xarray - When the pin itself is then unregistered from dpll_A, the delete notification calls dpll_msg_add_pin_ref_sync() which finds the partner in ref_sync_pins, passes dpll_pin_available() (partner is still registered with dpll_B), but dpll_pin_on_dpll_priv(dpll_A, partner) returns NULL because partner was already removed from dpll_A->pin_refs - The NULL priv pointer is passed to the driver's ref_sync_get callback, which dereferences it BUG: kernel NULL pointer dereference, address: 0000000000000034 Oops: Oops: 0000 [#1] SMP NOPTI RIP: 0010:zl3073x_dpll_input_pin_ref_sync_get+0x73/0x80 [zl3073x] Call Trace: dpll_msg_add_pin_ref_sync+0xb8/0x200 dpll_cmd_pin_get_one+0x3b6/0x4b0 dpll_pin_event_send+0x72/0x140 __dpll_pin_unregister+0x5a/0x2b0 dpll_pin_unregister+0x49/0x70 Fix this by skipping ref_sync pins whose priv pointer cannot be resolved for the current dpll device. Fixes: 58256a26bfb3 ("dpll: add reference sync get/set") Signed-off-by: Ivan Vecera <ivecera@redhat.com> Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev> Reviewed-by: Jiri Pirko <jiri@nvidia.com> Link: https://patch.msgid.link/20260710193625.1378822-1-ivecera@redhat.com Signed-off-by: Paolo Abeni <pabeni@redhat.com> (cherry picked from commit d2e914a4a0d0f753dbae830264850d044026167c) ``` Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com> [^footer]: Created 2026-07-17 12:25 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer] Approved-by: Ivan Vecera <ivecera@redhat.com> Approved-by: Michal Schmidt <mschmidt@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
bc020d2e73 |
Merge: qede: build_skb failure causes off-by-one BD ring corruption and kernel panic
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2894 JIRA: https://redhat.atlassian.net/browse/RHEL-190430 Backported from tree(s): net ``` qede: fix off-by-one in BD ring consumption on build_skb failure qede_rx_build_skb() and qede_tpa_rx_build_skb() do not check for a NULL return from qede_build_skb(). When it returns NULL under memory pressure, the functions still consume a BD from the ring before returning NULL. The callers then recycle additional BDs, resulting in one extra BD being consumed (off-by-one). This desynchronizes the BD ring, which can corrupt DMA page reference counts and lead to SLUB freelist corruption. Commit |
||
|
|
db3ca86205 |
Merge: CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2866 JIRA: https://redhat.atlassian.net/browse/RHEL-190345 Upstream Status: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git CVE: CVE-2026-53281 The CVE fix is 79ea2feb917b ("iommu/vt-d: Avoid NULL pointer dereference or refcount corruption"), it was proposed during a code review of another relevant fix: a6dea58d8625 ("iommu/vt-d: Fix oops due to out of scope access") Both patches are relevant. Signed-off-by: Eder Zulian <ezulian@redhat.com> Approved-by: Jay Shin <jaeshin@redhat.com> Approved-by: jbrnak <jbrnak@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
35b43bcaaf |
Merge: Merge branch 'pci/resource'
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2743 ``` - Prevent assigning space to unimplemented bridge windows; previously we mistakenly assumed prefetchable window existed and assigned space and put a BAR there (Ahmed Naseef) - Avoid shrinking bridge windows to fit in the initial Root Port window; this fixes one problem with devices with large BARs connected via switches, e.g., Thunderbolt (Ilpo Järvinen) - Retain information about optional resources to make assignment during rescan more likely to succeed (Ilpo Järvinen) - Add __resource_contains_unbound() for use in finding space for resources with no address assigned (Ilpo Järvinen) - Pass full extent of empty space, not just the aligned space, to resource_alignf callback so free space before the requested alignment can be used (Ilpo Järvinen) - Remove unnecessary second alignment from ARM, m68k, MIPS (Ilpo Järvinen) - Place small resources before larger ones for better utilization of address space (Ilpo Järvinen) - Fix alignment calculation for resource size larger than align, e.g., bridge windows larger than the 1MB required alignment (Ilpo Järvinen) JIRA: https://issues.redhat.com/browse/RHEL-178011 Signed-off-by: Myron Stowe <mstowe@redhat.com> ``` Approved-by: Steve Best <sbest@redhat.com> Approved-by: Mark Langsdorf <mlangsdo@redhat.com> Approved-by: Jerry Snitselaar <jsnitsel@redhat.com> Approved-by: Rafael Aquini <raquini@redhat.com> Approved-by: Ricardo Robaina <rrobaina@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
1ea525c43b |
Merge: CNB103: net: Retire DCCP socket
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2649 JIRA: https://redhat.atlassian.net/browse/RHEL-179873 Commits: ``` 9aba55b1fbef ("selinux: apply clang format to security/selinux/nlmsgtab.c") b2bdce7adc90 ("selftest: net: Remove DCCP bits.") 2a63dd0edf38 ("net: Retire DCCP socket.") 22d6c9eebf2e ("net: Unexport shared functions for DCCP.") 235bd9d21fcd ("tcp: Rename tcp_or_dccp_get_hashinfo().") 9db0163e3cad ("tcp: Remove sk_protocol test for tcp_twsk_unique().") 2d842b6c670b ("tcp: Remove timewait_sock_ops.twsk_destructor().") 8150f3a44b17 ("tcp: Remove hashinfo test for inet6?_lookup_run_sk_lookup().") cb16f4b6c73d ("tcp: Don't pass hashinfo to socket lookup helpers.") f1241200cd66 ("tcp: Don't pass hashinfo to inet_diag helpers.") 382a4d9cb6dc ("tcp: Move TCP-specific diag functions to tcp_diag.c.") 425e080a1c34 ("dccp Remove inet_hashinfo2_init_mod().") e7a614c008efb ("selinux: suppress warning flood for retired DCCP netlink messages") ``` Signed-off-by: Ivan Vecera <ivecera@redhat.com> Approved-by: Ondrej Mosnáček <omosnacek@gmail.com> Approved-by: Felix Maurer <fmaurer@redhat.com> Approved-by: Ivan Vecera <ivecera@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
5920aa7562 |
Merge: redhat: sign UKI's inner vmlinuz with modules signing key
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2482 JIRA: https://redhat.atlassian.net/browse/RHEL-223625 The existing workflow which puts SB-signed vmlinuz in the UKI and then SB-signs the UKI itself may be problematic for the situation when build time signing is unavailable. Switch to using the transient module signing key for signing vmlinuz which gets included into the UKI. This ensures that the extracted vmlinuz can be used for kexec/kdump. Signed-off-by: Vitaly Kuznetsov <vkuznets@redhat.com> Approved-by: Jan Stancek <jstancek@redhat.com> Approved-by: Jarod Wilson <jarod@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
6faee173c1 |
[redhat] kernel-6.12.0-256.el10
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> |
||
|
|
5e397fd8b1 |
Merge: CVE-2026-64320: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3030
JIRA: https://redhat.atlassian.net/browse/RHEL-219622
CVE: CVE-2026-64320
Backported from tree(s): linux
```
nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
nvmet_execute_disc_get_log_page() validates only the dword alignment
of the host-supplied Log Page Offset (lpo). The 64-bit offset is then
added to a small kzalloc'd buffer that holds the discovery log page
and the result is passed straight to nvmet_copy_to_sgl(), which
memcpy()s data_len bytes out to the host with no source-side bound
check:
u64 offset = nvmet_get_log_page_offset(req->cmd); /* 64-bit host */
size_t data_len = nvmet_get_log_page_len(req->cmd); /* 32-bit host */
...
if (offset & 0x3) { ... } /* only check */
...
alloc_len = sizeof(*hdr) + entry_size * discovery_log_entries(req);
buffer = kzalloc(alloc_len, GFP_KERNEL);
...
status = nvmet_copy_to_sgl(req, 0, buffer + offset, data_len);
The Discovery controller is unauthenticated -- nvmet_host_allowed()
returns true unconditionally for the discovery subsystem -- so the call
is reachable pre-authentication by any TCP/RDMA/FC peer that can reach
the nvmet target. With a discovery log page of ~1 KiB, an attacker
requesting up to 4 KiB starting at offset == alloc_len reads the next
slab page out and gets its content returned over the fabric (an
empirical run on a default nvmet-tcp loopback target leaked 81
canonical kernel pointers in one Get Log Page response). Pointing the
offset at unmapped kernel memory faults the in-kernel memcpy and
crashes (or panics, on panic_on_oops=1) the target host instead.
The attacker-controlled source-side offset pattern
"nvmet_copy_to_sgl(req, 0, buffer + ATTACKER_OFFSET, ...)" is unique
to nvmet_execute_disc_get_log_page in the entire nvmet codebase: every
other Get Log Page handler in admin-cmd.c either ignores lpo (and
silently starts every response at offset 0) or tracks a local
destination offset with a fixed source pointer.
Validate the host-supplied offset against the log page size, cap the
copy length to what is actually available, and zero-fill any remainder
of the host transfer buffer. The zero-fill matches the existing
short-response pattern in nvmet_execute_get_log_changed_ns()
(admin-cmd.c) and prevents leaking transport SGL contents when the
host asks for more bytes than the log page contains.
Fixes:
|
||
|
|
fd053acc74 |
Merge: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2971
JIRA: https://redhat.atlassian.net/browse/RHEL-193996
Backported from tree(s): linux
```
net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list
mlx5_query_nic_vport_mac_list() sizes its firmware command buffer using
the PF's log_max_current_uc/mc_list capabilities. When querying a VF
vport with a larger configured max (via devlink), the firmware response
can overflow this buffer:
BUG: KASAN: slab-out-of-bounds in mlx5_query_nic_vport_mac_list+0x453/0x4c0 [mlx5_core]
Read of size 4 at addr ff1100013ffc8a12 by task kworker/u96:2/385
CPU: 12 UID: 0 PID: 385 Comm: kworker/u96:2 Not tainted 7.0.0-rc6+ #1 PREEMPT
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009)
Workqueue: mlx5_esw_wq esw_vport_change_handler [mlx5_core]
Call Trace:
<TASK>
dump_stack_lvl+0x69/0xa0
print_report+0x176/0x4e4
kasan_report+0xc8/0x100
mlx5_query_nic_vport_mac_list+0x453/0x4c0 [mlx5_core]
esw_update_vport_addr_list+0x2e3/0xda0 [mlx5_core]
esw_vport_change_handle_locked+0xa1f/0x1060 [mlx5_core]
esw_vport_change_handler+0x6a/0x90 [mlx5_core]
process_one_work+0x87f/0x15e0
worker_thread+0x62b/0x1020
kthread+0x375/0x490
ret_from_fork+0x4dc/0x810
ret_from_fork_asm+0x11/0x20
</TASK>
Fix by querying the vport's own HCA caps to size the buffer correctly.
Refactor the function to allocate and return the MAC list internally,
removing the caller's dependency on knowing the correct max.
Fixes:
|
||
|
|
7c0f4f8688 |
Merge: arm updates from v6.19
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2815 JIRA: https://redhat.atlassian.net/browse/RHEL-158921 Problem: RHEL 10.3 needs selected Arm core updates from the upstream v6.19 development cycle. These updates keep the RHEL Arm architecture code aligned with upstream maintenance, reduce downstream delta, and bring in relevant fixes and infrastructure changes for arm64 and related kernel areas. Solution: Backport the selected upstream v6.19 Arm core commits into the CentOS Stream 10 kernel. The changeset preserves upstream commit provenance where applicable and limits the update to the required core Arm-related changes for RHEL 10.3. The MR does not intentionally introduce new kernel configuration changes or UAPI changes. Testing: - Boot tested the resulting CentOS Stream 10 kernel on a Raspberry Pi 4. - Submitted through the CentOS Stream 10 kernel MR workflow and CKI/KWF validation. Signed-off-by: Steve Dunnagan <sdunnaga@redhat.com> Approved-by: Tony Camuso <tcamuso@redhat.com> Approved-by: Rafael Aquini <raquini@redhat.com> Approved-by: Mark Salter <msalter@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
ecb43f1523 |
Merge: igc: driver update to v7.1+
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2780 JIRA: https://redhat.atlassian.net/browse/RHEL-186597 Update the igc driver to v7.1 and beyond (Linus's master as of 2026-06-22). Omitted commit: - af1816babcd9 igc: Use provided clock ID for history snapshot - Missing dependencies. This MR partially backports from the treewide kmalloc_obj conversions, but only the igc parts. So the following fixes are irrelevant: Omitted-fix: 2d2b5507e598 ("btrfs: replace kcalloc() calls to kzalloc_objs()") Omitted-fix: 405ca72dc589 ("landlock: Fix formatting") Omitted-fix: 4c0134639694 ("KVM: PPC: e500: Fix build error due to using kmalloc_obj() with wrong type") Omitted-fix: 5548dd7fa845 ("tools/testing: fix testing/vma and testing/radix-tree build") Omitted-fix: 795469820c63 ("kcsan: test: Adjust "expect" allocation type for kmalloc_obj") Omitted-fix: 94ff7c59cdfd ("RDMA: Complete k[z|m|c]alloc-to-k[z|m]alloc_obj conversion") Omitted-fix: 96a7b71c4438 ("ubd: Use pointer-to-pointers for io_thread_req arrays") Omitted-fix: fd1d6b9d13f3 ("xz: fix arm fdt compile error for kmalloc replacement") Omitted-fix: 9f4ab0787e7b ("btrfs: do more kmalloc_obj()/kmalloc_objs() conversions") Omitted-fix: 37f1f51fba1a ("btrfs: convert kmalloc_array to kmalloc_objs in btrfs_calc_avail_data_space()") Omitted-fix: 4c6d43db2a4d ("net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone") Signed-off-by: Michal Schmidt <mschmidt@redhat.com> Approved-by: Ivan Vecera <ivecera@redhat.com> Approved-by: Jarod Wilson <jarod@redhat.com> Approved-by: Kamal Heib <kheib@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
d66055b0bc |
Merge: igb, igbvf: drivers update to v7.1+
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2779 JIRA: https://redhat.atlassian.net/browse/RHEL-177449 Update igb and igbvf to v7.1 and beyond (Linus's master as of 2026-06-22). This MR partially backports from the treewide kmalloc_obj conversions, but only the igb, igbvf parts. So the following fixes are irrelevant: Omitted-fix: 2d2b5507e598 ("btrfs: replace kcalloc() calls to kzalloc_objs()") Omitted-fix: 405ca72dc589 ("landlock: Fix formatting") Omitted-fix: 4c0134639694 ("KVM: PPC: e500: Fix build error due to using kmalloc_obj() with wrong type") Omitted-fix: 5548dd7fa845 ("tools/testing: fix testing/vma and testing/radix-tree build") Omitted-fix: 795469820c63 ("kcsan: test: Adjust "expect" allocation type for kmalloc_obj") Omitted-fix: 94ff7c59cdfd ("RDMA: Complete k[z|m|c]alloc-to-k[z|m]alloc_obj conversion") Omitted-fix: 96a7b71c4438 ("ubd: Use pointer-to-pointers for io_thread_req arrays") Omitted-fix: fd1d6b9d13f3 ("xz: fix arm fdt compile error for kmalloc replacement") Omitted-fix: 9f4ab0787e7b ("btrfs: do more kmalloc_obj()/kmalloc_objs() conversions") Omitted-fix: 37f1f51fba1a ("btrfs: convert kmalloc_array to kmalloc_objs in btrfs_calc_avail_data_space()") Omitted-fix: 4c6d43db2a4d ("net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone") Signed-off-by: Michal Schmidt <mschmidt@redhat.com> Approved-by: Jarod Wilson <jarod@redhat.com> Approved-by: Kamal Heib <kheib@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
c56864439b |
Merge: CVE-2024-53143 fsnotify: Fix ordering of iput() and watched_objects decrement
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2600 JIRA: https://redhat.atlassian.net/browse/RHEL-175863 CVE: CVE-2024-53143 - 21d1b618b6b9da46c5116c640ac4b1cc8d40d63a fsnotify: Fix ordering of iput() and watched_objects decrement Signed-off-by: Jay Shin <jaeshin@redhat.com> Approved-by: Brian Foster <bfoster@redhat.com> Approved-by: David Howells <dhowells@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
f1745d08ab |
Merge: scsi: mpt3sas driver fixes for RHEL10.3
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2415 JIRA: https://issues.redhat.com/browse/RHEL-141216 scsi: mpt3sas driver updates Upstream Status: Accepted Tested: Compiled and tested on Local Development Setup Signed-off-by: Chandrakanth Patil <chanpati@redhat.com> Approved-by: Tomas Henzl <thenzl@redhat.com> Approved-by: Chris Leech <cleech@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
64ca831f43 |
Merge: scsi: mpi3mr driver fixes for RHEL10.3
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2409 JIRA: https://issues.redhat.com/browse/RHEL-141215 scsi: mpi3mr driver updates Upstream Status: Accepted Tested: Compiled and tested on Local Development Setup Signed-off-by: Chandrakanth Patil <chanpati@redhat.com> Approved-by: Andrea Arcangeli <aarcange@redhat.com> Approved-by: djeffery1 <djeffery@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
3e438966b8 |
[redhat] kernel-6.12.0-255.el10
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> |
||
|
|
3a74712c51 |
Merge: [RHEL-10.3] crypto: tegra - fix rctx->cryptlen calculation
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3064
JIRA: https://redhat.atlassian.net/browse/RHEL-169756
Backported from tree(s): crypto, cryptodev
```
crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req()
Perform rctx->cryptlen calculation in tegra_gcm_do_one_req() the same way
it is done in tegra_ccm_crypt_init(). The current formulae may lead to a
crash if a caller does not call tegra_gcm_setauthsize() and so ctx->authsize
remains zero. Then a decrypt operation with incorrect rctx->cryptlen will
lead to a write beyound rctx->dst_sg buffer.
As a follow-up cleanup delete struct tegra_aead_ctx->authsize field since
it appears to be completely unused. Also simplify tegra_ccm_setauthsize()
and tegra_gcm_setauthsize() functions respectively.
Fixes:
|
||
|
|
20ed85b3ec |
Merge: xfrm: fix two CVE and one race issues
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3031 JIRA: https://redhat.atlassian.net/browse/RHEL-154898 JIRA: https://redhat.atlassian.net/browse/RHEL-180168 JIRA: https://redhat.atlassian.net/browse/RHEL-178329 CVE: CVE-2026-23239 CVE: CVE-2026-46116 Fix two CVE and one race issues Signed-off-by: Xin Long <lxin@redhat.com> Approved-by: Sabrina Dubroca <sdubroca@redhat.com> Approved-by: Íñigo Huguet <ihuguet@riseup.net> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
8b54f889c2 |
Merge: Add resource group monitoring
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3021 Description: Add resource group monitoring JIRA: https://issues.redhat.com/browse/RHEL-217019 Build Info: https://brewweb.engineering.redhat.com/brew/taskinfo?taskID=71406241 Tested: Verified Brew build test kernel RPMs Signed-off-by: Mamatha Inamdar <minamdar@redhat.com> Approved-by: Steve Best <sbest@redhat.com> Approved-by: David Arcari <darcari@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
c7d6293eb2 |
Merge: nvme: introduce support to tunable NVMe timeouts
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3000 # Merge Request Required Information ## Summary of Changes This patchset introduces support to the NVMe tunable device timeouts JIRA: https://redhat.atlassian.net/browse/RHEL-54175 Signed-off-by: Maurizio Lombardi <mlombard@redhat.com> ## Approved Development Ticket(s) All submissions to CentOS Stream must reference a ticket in [Red Hat Jira](https://issues.redhat.com/). <details><summary>Click for formatting instructions</summary> Please follow the CentOS Stream [contribution documentation](https://docs.centos.org/centos-stream-docs/contributors-guide/) for how to file this ticket and have it approved. List tickets each on their own line of this description using the format "Resolves: RHEL-76229", "Related: RHEL-76229" or "Reverts: RHEL-76229", as appropriate. </details> Approved-by: Kamal Heib <kheib@redhat.com> Approved-by: djeffery1 <djeffery@redhat.com> Approved-by: Chris Leech <cleech@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
dcf56fab5e |
Merge: ahci: driver fixes
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2979 JIRA: https://issues.redhat.com/browse/RHEL-157217 Driver fixes Signed-off-by: Tomas Henzl <thenzl@redhat.com> Approved-by: Maurizio Lombardi <mlombard@redhat.com> Approved-by: Chris Leech <cleech@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
ad89c8ce4f |
Merge: scsi: core: wake eh reliably when using scsi_schedule_eh
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2975
JIRA: https://redhat.atlassian.net/browse/RHEL-208594
Upstream Status: From upstream linux mainline
Drivers which use the scsi_schedule_eh function to run the error handler
currently risk the error handler thread never waking once all commands are
timed out or inactive. There is no enforced memory order between setting
the host into error recovery state and counting busy commands. This can
result in a race with scsi_dec_host_busy where neither CPU sees both
conditions of all commands inactive and the host error state to request
waking the error handler.
To fix this, run the scsi_schedule_eh's scsi_eh_wakeup from a new work item
which will use rcu to ensure scsi_schedule_eh's call to scsi_host_busy will
occur after the error state is globally visible and will be seen by any
current scsi_dec_host_busy callers.
Fixes:
|
||
|
|
88b84d06fd |
Merge: Sync CIFS/ksmbd/netfs/smbdirect/cachefiles with upstream [rhel-10]
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2945 - Sync CIFS/ksmbd/netfs/smbdirect/cachefiles with upstream JIRA: https://redhat.atlassian.net/browse/RHEL-190706 Signed-off-by: Paulo Alcantara <paalcant@redhat.com> Omitted-fix: fd1d6b9d13f3 ("xz: fix arm fdt compile error for kmalloc replacement") Omitted-fix: 96a7b71c4438 ("ubd: Use pointer-to-pointers for io_thread_req arrays") Omitted-fix: 795469820c63 ("kcsan: test: Adjust "expect" allocation type for kmalloc_obj") Omitted-fix: 5548dd7fa845 ("tools/testing: fix testing/vma and testing/radix-tree build") Omitted-fix: 405ca72dc589 ("landlock: Fix formatting") Omitted-fix: 4c0134639694 ("KVM: PPC: e500: Fix build error due to using kmalloc_obj() with wrong type") Omitted-fix: 4c6d43db2a4d ("net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone") Omitted-fix: 2d2b5507e598 ("btrfs: replace kcalloc() calls to kzalloc_objs()") Omitted-fix: 9f4ab0787e7b ("btrfs: do more kmalloc_obj()/kmalloc_objs() conversions") Omitted-fix: 37f1f51fba1a ("btrfs: convert kmalloc_array to kmalloc_objs in btrfs_calc_avail_data_space()") Approved-by: David Howells <dhowells@redhat.com> Approved-by: Roberto Bergantinos Corpas <rbergant@redhat.com> Approved-by: Scott Mayhew <smayhew@redhat.com> Approved-by: Rafael Aquini <raquini@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
5467d21db8 |
Merge: nvme-multipath: set BIO_REMAPPED on bios remapped to per-path namespace disks
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2924
# Merge Request Required Information
## Summary of Changes
JIRA: https://redhat.atlassian.net/browse/RHEL-194153
When nvme_ns_head_submit_bio() remaps a bio from the multipath head to a
per-path namespace, bio_set_dev() clears BIO_REMAPPED. The remapped bio
is then resubmitted through submit_bio_noacct() which calls
bio_check_eod() because BIO_REMAPPED is not set.
This races with nvme_ns_remove() which zeroes the per-path capacity
before synchronize_srcu():
CPU 0 (IO submission)
---------------------
srcu_read_lock()
nvme_find_path() -> ns
[NVME_NS_READY is set]
CPU 1 (namespace removal)
-------------------------
clear_bit(NVME_NS_READY)
set_capacity(ns->disk, 0)
synchronize_srcu() <- blocks
CPU 0 (IO submission)
---------------------
bio_set_dev(bio, ns->disk->part0)
[clears BIO_REMAPPED]
submit_bio_noacct(bio)
-> bio_check_eod() sees capacity=0
-> bio fails with IO error
The SRCU read lock prevents synchronize_srcu() from completing, but does
not prevent set_capacity(0) from executing. The bio fails the EOD check
before it reaches the NVMe driver, so nvme_failover_req() never gets a
chance to redirect it to another path of multipath. IO errors are
reported to the application despite another path being available.
On older kernels (before commit 0b64682e78f7 "block: skip unnecessary
checks for split bio"), the same race was also reachable through split
remainders resubmitted via submit_bio_noacct().
Fix this by setting BIO_REMAPPED after bio_set_dev() in
nvme_ns_head_submit_bio(). This skips bio_check_eod() on the per-path
device; the EOD check already passed on the multipath head.
NVMe per-path namespace devices are always whole disks (bd_partno=0), so
the blk_partition_remap() skip also gated by BIO_REMAPPED is a no-op.
The flag does not persist across failover and cannot go stale if the
namespace geometry changes between attempts: nvme_failover_req() calls
bio_set_dev() to redirect the bio back to the multipath head, which
clears BIO_REMAPPED. When nvme_requeue_work() resubmits through
submit_bio_noacct(), bio_check_eod() runs normally against the current
capacity.
Same approach as commit
|
||
|
|
ac4f2b354e |
Merge: tls: backport CVE and other bug fixes
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2890 JIRA: https://redhat.atlassian.net/browse/RHEL-152729 JIRA: https://redhat.atlassian.net/browse/RHEL-154841 JIRA: https://redhat.atlassian.net/browse/RHEL-189560 CVE: CVE-2026-23240 CVE: CVE-2025-40149 Backport some upstream fixes, including some CVEs. Signed-off-by: Sabrina Dubroca <sdubroca@redhat.com> Approved-by: Jarod Wilson <jarod@redhat.com> Approved-by: Jay Shin <jaeshin@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
c4f296739c |
Merge: CVE-2025-71113: crypto: af_alg - zero initialize memory allocated via sock_kmalloc
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2832 JIRA: https://redhat.atlassian.net/browse/RHEL-189578 CVE: CVE-2025-71113 Backported from tree(s): linux ``` crypto: af_alg - zero initialize memory allocated via sock_kmalloc Several crypto user API contexts and requests allocated with sock_kmalloc() were left uninitialized, relying on callers to set fields explicitly. This resulted in the use of uninitialized data in certain error paths or when new fields are added in the future. The ACVP patches also contain two user-space interface files: algif_kpp.c and algif_akcipher.c. These too rely on proper initialization of their context structures. A particular issue has been observed with the newly added 'inflight' variable introduced in af_alg_ctx by commit: |
||
|
|
2a179742c7 |
Merge: e1000, e1000e: drivers update to v7.1+
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2782 JIRA: https://redhat.atlassian.net/browse/RHEL-186602 Update the e1000 and e1000e drivers to v7.1 and beyond (Linus's master as of 2026-06-22). This MR partially backports from the treewide kmalloc_obj conversions, but only the e1000, e1000e parts. So the following fixes are irrelevant: Omitted-fix: 2d2b5507e598 ("btrfs: replace kcalloc() calls to kzalloc_objs()") Omitted-fix: 405ca72dc589 ("landlock: Fix formatting") Omitted-fix: 4c0134639694 ("KVM: PPC: e500: Fix build error due to using kmalloc_obj() with wrong type") Omitted-fix: 5548dd7fa845 ("tools/testing: fix testing/vma and testing/radix-tree build") Omitted-fix: 795469820c63 ("kcsan: test: Adjust "expect" allocation type for kmalloc_obj") Omitted-fix: 94ff7c59cdfd ("RDMA: Complete k[z|m|c]alloc-to-k[z|m]alloc_obj conversion") Omitted-fix: 96a7b71c4438 ("ubd: Use pointer-to-pointers for io_thread_req arrays") Omitted-fix: fd1d6b9d13f3 ("xz: fix arm fdt compile error for kmalloc replacement") Omitted-fix: 9f4ab0787e7b ("btrfs: do more kmalloc_obj()/kmalloc_objs() conversions") Omitted-fix: 37f1f51fba1a ("btrfs: convert kmalloc_array to kmalloc_objs in btrfs_calc_avail_data_space()") Omitted-fix: 4c6d43db2a4d ("net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone") Signed-off-by: Michal Schmidt <mschmidt@redhat.com> Approved-by: Jarod Wilson <jarod@redhat.com> Approved-by: Jakub Ramaseuski <jramaseu@redhat.com> Approved-by: Kamal Heib <kheib@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
df5fa48d5b |
Merge: octeon_ep_vf: bug fixes from v7.1
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2767 JIRA: https://redhat.atlassian.net/browse/RHEL-186335 * f93fc5d12d69 net: octeon_ep_vf: fix free_irq dev_id mismatch in IRQ rollback [linux] * 484e834d53cf octeon_ep_vf: ensure dbell BADDR updation [linux] * 2ae7d20fb24f octeon_ep_vf: Relocate counter updates before NAPI [linux] * 6c73126ecd10 octeon_ep_vf: avoid compiler and IQ/OQ reordering [linux] * 4e5bc3ff060e octeon_ep_vf: introduce octep_vf_oq_next_idx() helper [linux] * dd66b4285470 octeon_ep_vf: add NULL check for napi_build_skb() [linux] Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com> [^footer]: Created 2026-06-19 10:05 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=11779&issuetype=10016&priority=10001&summary=backporter+webhook+issue&components=66291) [^footer] Approved-by: Kamal Heib <kheib@redhat.com> Approved-by: José Ignacio Tornos Martínez <jtornosm@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
5abf57818b |
Merge: net: wwan: t7xx: fix regression with FM350GL
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2715 JIRA: https://redhat.atlassian.net/browse/RHEL-155042 Fix SAP suspend error independently of MM version. Signed-off-by: Jose Ignacio Tornos Martinez <jtornosm@redhat.com> Approved-by: Michal Schmidt <mschmidt@redhat.com> Approved-by: Desnes Nunes <desnesn@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
8513f26564 |
Merge: CVE-2026-46117: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2665
JIRA: https://redhat.atlassian.net/browse/RHEL-180156
CVE: CVE-2026-46117
Backported from tree(s): linux
```
commit 159f2efabc89d3f931d38f2d35876535d4abf0a3
Author: Jason Gunthorpe <jgg@nvidia.com>
Date: Tue Apr 28 13:17:38 2026 -0300
RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()
Sashiko points out that the user can specify WQs sharing the same CQ as a
part of the uAPI and this will trigger the WARN_ON() then go on to corrupt
the kernel.
Just reject it outright and fail the QP creation.
Cc: stable@vger.kernel.org
Fixes:
|
||
|
|
9eecaf198f |
Merge: [RHEL-10.3] Update drivers/input and related directories to upstream kernel V7.1+
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2636 Backport of latest drivers/input changes for supported devices. JIRA: https://redhat.atlassian.net/browse/RHEL-176366 Signed-off-by: Tony Camuso <tcamuso@redhat.com> Approved-by: Benjamin Tissoires <benjamin.tissoires@redhat.com> Approved-by: Steve Best <sbest@redhat.com> Approved-by: Eric Chanudet <echanude@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
41fbb1f9af |
[redhat] kernel-6.12.0-254.el10
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> |
||
|
|
0fd707ebdf |
Merge: Exploits (KEV)]: can: bcm: thrtimer use-after-free during RX operation teardown
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2967 JIRA: https://redhat.atlassian.net/browse/RHEL-212683 Backported from tree(s): linux ``` can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF commit 68973f9db76144825e4f35dfdc80fb8279eb2d57 Author: Lee Jones <lee@kernel.org> Date: Tue Jul 14 18:55:23 2026 +0200 can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF Commit |
||
|
|
9d0e99581b |
Merge: redhat/kernel.spec: derive pesign_name_0 from secureboot_key_0
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2926 JIRA: https://redhat.atlassian.net/browse/RHEL-169468 Upstream Status: ARK This MR is backporting ccd21c9ba57664045fcef29a4294bb0af5f549dc from ARK, and bringing in few dependencies: - redhat/kernel.spec.template: Fix indentation of uki-virt generation code - applied loosely as the c10s tree differs a lot, but all this is whitespace change - redhat/kernel.spec.template: Simplify uki-virt signing - cert names and code is re-arranged due to out of order backports - redhat/kernel.spec: derive pesign_name_0 from secureboot_key_0 - c10s does not have dtb The end result matches ARK code, with following minor differences: ```diff ⎿ --- a/redhat/kernel.spec.template (kernel-ark) +++ b/redhat/kernel.spec.template (centos-stream-10) @@ -79,6 +79,7 @@ else %if %{with_efiuki} %{log_msg "Setup the EFI UKI kernel"} + KernelUnifiedImageDir="$RPM_BUILD_ROOT/lib/modules/$KernelVer" KernelUnifiedImage="$KernelUnifiedImageDir/$InstallName-virt.efi" KernelUnifiedInitrd="$KernelUnifiedImageDir/$InstallName-virt.img" @@ -100,7 +101,7 @@ rm -f $KernelUnifiedInitrd - KernelAddonsDirOut="$KernelUnifiedImage.extras.optional/" + KernelAddonsDirOut="$KernelUnifiedImage.extra.d" mkdir -p $KernelAddonsDirOut python3 %{SOURCE151} %{SOURCE152} $KernelAddonsDirOut virt %{primary_target} %{_target_cpu} @uki-addons.sbat @@ -133,6 +134,6 @@ : # in case of empty block fi # "$Variant" == "rt" || "$Variant" == "rt-debug" || "$Variant" == "automotive" || "$Variant" == "automotive-debug" -%if %{with_dtbloader} - if [[ -z "$Variant" || "$Variant" == "debug" ]]; then + # + # Generate the modules files lists ---8<--- snip ---8<--- ``` Signed-off-by: Jan Stancek <jstancek@redhat.com> Approved-by: Oleksii Baranov <olebaran@redhat.com> Approved-by: Jarod Wilson <jarod@redhat.com> Approved-by: Scott Weaver <scweaver@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
0043876615 |
Merge: rtnetlink: add missing netlink_ns_capable() check for peer netns
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2605 JIRA: https://redhat.atlassian.net/browse/RHEL-172539 Upstream Status: linux.git CVE: CVE-2026-31692 Backport missing CAP_NET_ADMIN check when creating a virtual device in a peer network namespace. Signed-off-by: Guillaume Nault <gnault@redhat.com> Approved-by: Jarod Wilson <jarod@redhat.com> Approved-by: Davide Caratti <dcaratti@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
fb6e982ada |
Merge: Rebase KVM to upstream kernel 7.0
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2469 JIRA: https://issues.redhat.com/browse/RHEL-151869 Tested: kvm unit tests and selftests on Intel,AMD and aarch64 machine. Omitted-fix: 0354e81b7bd6 ("scripts/misc-check: update export checks for EXPORT_SYMBOL_FOR_MODULES()") Omitted-fix: 48dbe4732198 ("KVM: guest_memfd: fix NUMA interleave index double-counting") Omitted-fix: 97cd21d57e9b ("KVM: SEV: Mark source page dirty when writing back CPUID data on failure") Omitted-fix: 138f5f9cbe37 ("KVM: SEV: Unmap local kmaps in LIFO order, per highmem requirements") Omitted-fix: f13e90059908 ("KVM: SEV: Pin source page for write when adding CPUID data for SNP guest") Signed-off-by: Maxim Levitsky <mlevitsk@redhat.com> Approved-by: Tony Camuso <tcamuso@redhat.com> Approved-by: Rafael Aquini <raquini@redhat.com> Approved-by: David Arcari <darcari@redhat.com> Approved-by: Michael Petlan <mpetlan@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
bc7e786b9f |
Merge: CNB103: Single MSS length in UDP GSO_PARTIAL
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2284 JIRA: https://redhat.atlassian.net/browse/RHEL-156516 * b10b446ce7ad9 udp: gso: Use single MSS length in UDP header for GSO_PARTIAL * 8d2eda97f464d net/mlx5e: Remove redundant UDP length adjustment with GSO_PARTIAL * 5b4015ad833c7 net: aquantia: Remove redundant UDP length adjustment with GSO_PARTIAL Signed-off-by: CKI Backport Bot <cki-ci-bot+cki-gitlab-backport-bot@redhat.com> [^footer]: Created 2026-03-20 09:10 UTC by backporter - [KWF FAQ](https://red.ht/kernel_workflow_doc) - [Slack #team-kernel-workflow](https://redhat-internal.slack.com/archives/C04LRUPMJQ5) - [Source](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/webhook/utils/backporter.py) - [Documentation](https://gitlab.com/cki-project/kernel-workflow/-/blob/main/docs/README.backporter.md) - [Report an issue](https://redhat.atlassian.net/secure/CreateIssueDetails!init.jspa?pid=12334433&issuetype=1&priority=4&summary=backporter+webhook+issue&components=kernel-workflow+/+backporter) [^footer] Approved-by: Davide Caratti <dcaratti@redhat.com> Approved-by: Petr Oros <poros@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
7754a7e9cc |
[redhat] kernel-6.12.0-253.el10
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> |
||
|
|
3e6851bf4e |
Merge: redhat: add kmap.py tool and kernel-kmap-internal package
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/3025 JIRA: INTERNAL Upstream Status: RHEL-Only Introduce kmap.py, a tool that creates JSON mappings of which source files contribute to which kernel binaries (modules and vmlinux), and add a new kernel-kmap-internal RPM package that ships the generated mapping data. This enables tooling to trace kernel binaries back to their original source files, useful for debugging, security analysis, and build verification. The tool parses kernel build artifacts (.cmd files generated by kbuild) to extract compilation information. It supports: - C source files compiled with gcc or clang - Rust source files compiled with rustc - Built-in objects via vmlinux.a (upstream kbuild) - Multiple kernel variants merged into a single output file - Module-to-RPM package mapping The new kernel-kmap-internal package contains a JSON file (kernel-map-<KVERREL>.json) with the structure: ``` { "variants": ["stock", "rt", ...], "source-map": { "obj-src": {<object>: {<source>: [<variant_indices>]}}, "src-obj": {<source>: {<object>: [<variant_indices>]}} }, "module-map": { "module-rpm": {<module>: {<rpm_name>: [<variant_indices>]}}, "rpm-modules": {<rpm_name>: {<module>: [<variant_indices>]}} } } ``` Variant indices are positions in the 'variants' list, indicating which variants each mapping applies to. The package is built for x86_64, ppc64le, s390x, aarch64, and riscv64. Debug variants are skipped (same source mapping as base). Installed to: /usr/share/kernel-kmap-internal/kernel-map-<KVERREL>.json Backported from kernel-ark commit 46f9eda70367. Signed-off-by: Rado Vrbovsky <rvrbovsk@redhat.com> Co-authored-by: Cursor <cursoragent@cursor.com> Approved-by: Scott Weaver <scweaver@redhat.com> Approved-by: Jarod Wilson <jarod@redhat.com> Approved-by: Derek Barbosa <debarbos@redhat.com> Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com> |
||
|
|
031b06f656 |
Merge: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2991
JIRA: https://redhat.atlassian.net/browse/RHEL-214083
CVE: CVE-2026-64530
Backported from tree(s): linux
```
net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the
defragmentation engine (e.g. act_ct on out-of-order fragments). When
that happens the skb is no longer owned by the caller and must not be
touched again.
tcf_qevent_handle() did not handle TC_ACT_CONSUMED: it fell through the
switch and returned the skb to the caller as if classification had
passed. The only qdisc that wires up qevents today is RED, via three call sites
(qe_mark on RED_PROB_MARK/HARD_MARK, qe_early_drop on congestion_drop)
red_enqueue() was continuing to operate on an skb it no longer owns in this
case -- enqueueing it, dropping it, or updating statistics. Resulting in a UAF.
tc qdisc add dev eth0 root handle 1: red ... qevent early_drop block 10
tc filter add block 10 ... action ct
(with ct defrag enabled and traffic that produces out-of-order
fragments, e.g. a fragmented UDP stream)
Handle TC_ACT_CONSUMED in tcf_qevent_handle() the same way the ingress
and egress fast paths do: treat it as stolen and return NULL without
touching the skb. Unlike the TC_ACT_STOLEN case, the skb must not be
dropped/freed here, as it is no longer owned by us.
Fixes:
|
||
|
|
d59ba30247 |
Merge: x86/fpu: Ensure XFD state on signal delivery
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2980
JIRA: https://redhat.atlassian.net/browse/RHEL-213537
commit 388eff894d6bc5f921e9bfff0e4b0ab2684a96e9
Author: Chang S. Bae <chang.seok.bae@intel.com>
Date: Mon Jun 9 17:16:59 2025 -0700
x86/fpu: Ensure XFD state on signal delivery
Sean reported [1] the following splat when running KVM tests:
WARNING: CPU: 232 PID: 15391 at xfd_validate_state+0x65/0x70
Call Trace:
<TASK>
fpu__clear_user_states+0x9c/0x100
arch_do_signal_or_restart+0x142/0x210
exit_to_user_mode_loop+0x55/0x100
do_syscall_64+0x205/0x2c0
entry_SYSCALL_64_after_hwframe+0x4b/0x53
Chao further identified [2] a reproducible scenario involving signal
delivery: a non-AMX task is preempted by an AMX-enabled task which
modifies the XFD MSR.
When the non-AMX task resumes and reloads XSTATE with init values,
a warning is triggered due to a mismatch between fpstate::xfd and the
CPU's current XFD state. fpu__clear_user_states() does not currently
re-synchronize the XFD state after such preemption.
Invoke xfd_update_state() which detects and corrects the mismatch if
there is a dynamic feature.
This also benefits the sigreturn path, as fpu__restore_sig() may call
fpu__clear_user_states() when the sigframe is inaccessible.
[ dhansen: minor changelog munging ]
Closes: https://lore.kernel.org/lkml/aDCo_SczQOUaB2rS@google.com [1]
Fixes:
|
||
|
|
4b645a67cf |
Merge: platform/x86: intel-hid: Protect ACPI notify handler against recursion
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2976 JIRA: https://redhat.atlassian.net/browse/RHEL-213294 commit c085d82613d5618814b84406c8b2d64f1bc305e7 Author: HyeongJun An <sammiee5311@gmail.com> Date: Sat Jun 6 02:49:05 2026 +0900 platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit |
||
|
|
02674859e6 |
Merge: [RHEL 10.3] iTCO_wdt: mask NMI_NOW bit for update_no_reboot_bit() call
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/2969 JIRA: https://redhat.atlassian.net/browse/RHEL-212108 Upstream-status: v6.13 commit daa814d784ac034c62ab3fb0ef83daeafef527e2 Author: Oleksandr Ocheretnyi <oocheret@cisco.com> Date: Fri Sep 13 12:14:03 2024 -0700 iTCO_wdt: mask NMI_NOW bit for update_no_reboot_bit() call Commit |