From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: stable@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
patches@lists.linux.dev,
Luiz Augusto von Dentz <luiz.dentz@gmail.com>,
Chengfeng Ye <nicoyip.dev@gmail.com>,
Luiz Augusto von Dentz <luiz.von.dentz@intel.com>,
Sasha Levin <sashal@kernel.org>
Subject: [PATCH 6.6 108/166] Bluetooth: hci_sync: Fix advertising data UAFs
Date: Thu, 20 Aug 2026 16:56:07 +0200 [thread overview]
Message-ID: <20260820145214.413281718@linuxfoundation.org> (raw)
In-Reply-To: <20260820145211.194104353@linuxfoundation.org>
6.6-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chengfeng Ye <nicoyip.dev@gmail.com>
[ Upstream commit cdc36db204ffd97b947d64374cf23a210dc74777 ]
hci_find_adv_instance() returns an adv_info pointer that is valid only
while hdev->lock is held. The advertising command-sync paths perform
instance lookups without that lock and, in some cases, retain the pointer
while waiting for a controller response.
An advertising termination event can therefore interleave as follows:
hci_cmd_sync_work hci_rx_work
hci_find_adv_instance()
__hci_cmd_sync_status()
wait for controller reply hci_dev_lock()
hci_remove_adv_instance()
kfree(adv)
adv->scan_rsp_changed = false
KASAN reported:
BUG: KASAN: slab-use-after-free in hci_set_ext_scan_rsp_data_sync+0x2e1/0x300
Write of size 1 at addr ffff88810a45d21d by task kworker/u17:0/88
Workqueue: hci0 hci_cmd_sync_work
Call Trace:
hci_set_ext_scan_rsp_data_sync+0x2e1/0x300
hci_schedule_adv_instance_sync+0x390/0x4c0
hci_cmd_sync_work+0x173/0x300
Allocated by task 87:
hci_add_adv_instance+0x538/0xac0
add_advertising+0x885/0x1160
Freed by task 89:
kfree+0x131/0x3c0
hci_remove_adv_instance+0x1d8/0x3b0
hci_le_ext_adv_term_evt+0x17b/0x730
Protect the instance lookup and payload construction in the extended
advertising, scan response, and periodic advertising data paths. Snapshot
the advertising parameters under hdev->lock, but release the lock before
waiting for the controller.
Clear advertising-data dirty bits before issuing their commands and
restore them after a failure using a fresh lookup. Likewise, update the
reported transmit power through a fresh lookup after the parameter command
completes. No adv_info pointer then survives an HCI command wait.
Fixes: cba6b758711c ("Bluetooth: hci_sync: Make use of hci_cmd_sync_queue set 2")
Cc: stable@vger.kernel.org
Suggested-by: Luiz Augusto von Dentz <luiz.dentz@gmail.com>
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/hci_sync.c | 131 ++++++++++++++++++++++++++++++++++-------------
1 file changed, 97 insertions(+), 34 deletions(-)
--- a/net/bluetooth/hci_sync.c
+++ b/net/bluetooth/hci_sync.c
@@ -1252,10 +1252,11 @@ static int hci_set_adv_set_random_addr_s
}
static int
-hci_set_ext_adv_params_sync(struct hci_dev *hdev, struct adv_info *adv,
+hci_set_ext_adv_params_sync(struct hci_dev *hdev, u8 instance,
const struct hci_cp_le_set_ext_adv_params *cp,
struct hci_rp_le_set_ext_adv_params *rp)
{
+ struct adv_info *adv;
struct sk_buff *skb;
skb = __hci_cmd_sync(hdev, HCI_OP_LE_SET_EXT_ADV_PARAMS, sizeof(*cp),
@@ -1283,11 +1284,15 @@ hci_set_ext_adv_params_sync(struct hci_d
if (!rp->status) {
hdev->adv_addr_type = cp->own_addr_type;
- if (!cp->handle) {
+ if (!instance) {
/* Store in hdev for instance 0 */
hdev->adv_tx_power = rp->tx_power;
- } else if (adv) {
- adv->tx_power = rp->tx_power;
+ } else {
+ hci_dev_lock(hdev);
+ adv = hci_find_adv_instance(hdev, instance);
+ if (adv)
+ adv->tx_power = rp->tx_power;
+ hci_dev_unlock(hdev);
}
}
@@ -1303,9 +1308,13 @@ static int hci_set_ext_adv_data_sync(str
int err;
if (instance) {
+ hci_dev_lock(hdev);
+
adv = hci_find_adv_instance(hdev, instance);
- if (!adv || !adv->adv_data_changed)
+ if (!adv || !adv->adv_data_changed) {
+ hci_dev_unlock(hdev);
return 0;
+ }
}
len = eir_create_adv_data(hdev, instance, pdu->data,
@@ -1316,16 +1325,27 @@ static int hci_set_ext_adv_data_sync(str
pdu->operation = LE_SET_ADV_DATA_OP_COMPLETE;
pdu->frag_pref = LE_SET_ADV_DATA_NO_FRAG;
+ if (adv) {
+ adv->adv_data_changed = false;
+ hci_dev_unlock(hdev);
+ }
+
err = __hci_cmd_sync_status(hdev, HCI_OP_LE_SET_EXT_ADV_DATA,
struct_size(pdu, data, len), pdu,
HCI_CMD_TIMEOUT);
- if (err)
+ if (err) {
+ if (instance) {
+ hci_dev_lock(hdev);
+ adv = hci_find_adv_instance(hdev, instance);
+ if (adv)
+ adv->adv_data_changed = true;
+ hci_dev_unlock(hdev);
+ }
+
return err;
+ }
- /* Update data if the command succeed */
- if (adv) {
- adv->adv_data_changed = false;
- } else {
+ if (!instance) {
memcpy(hdev->adv_data, pdu->data, len);
hdev->adv_data_len = len;
}
@@ -1379,22 +1399,22 @@ int hci_setup_ext_adv_instance_sync(stru
struct adv_info *adv;
bool secondary_adv;
- if (instance > 0) {
- adv = hci_find_adv_instance(hdev, instance);
- if (!adv)
- return -EINVAL;
- } else {
- adv = NULL;
- }
-
/* Updating parameters of an active instance will return a
- * Command Disallowed error, so we must first disable the
- * instance if it is active.
+ * Command Disallowed error, so disable it before taking a snapshot.
*/
- if (adv) {
+ if (instance > 0) {
err = hci_disable_ext_adv_instance_sync(hdev, instance);
if (err)
return err;
+
+ hci_dev_lock(hdev);
+ adv = hci_find_adv_instance(hdev, instance);
+ if (!adv) {
+ hci_dev_unlock(hdev);
+ return -EINVAL;
+ }
+ } else {
+ adv = NULL;
}
flags = hci_adv_instance_flags(hdev, instance);
@@ -1405,8 +1425,11 @@ int hci_setup_ext_adv_instance_sync(stru
connectable = (flags & MGMT_ADV_FLAG_CONNECTABLE) ||
mgmt_get_connectable(hdev);
- if (!is_advertising_allowed(hdev, connectable))
+ if (!is_advertising_allowed(hdev, connectable)) {
+ if (instance)
+ hci_dev_unlock(hdev);
return -EPERM;
+ }
/* Set require_privacy to true only when non-connectable
* advertising is used and it is not periodic.
@@ -1417,8 +1440,11 @@ int hci_setup_ext_adv_instance_sync(stru
err = hci_get_random_address(hdev, require_privacy,
adv_use_rpa(hdev, flags), adv,
&own_addr_type, &random_addr);
- if (err < 0)
+ if (err < 0) {
+ if (instance)
+ hci_dev_unlock(hdev);
return err;
+ }
memset(&cp, 0, sizeof(cp));
@@ -1467,6 +1493,9 @@ int hci_setup_ext_adv_instance_sync(stru
cp.channel_map = hdev->le_adv_channel_map;
cp.handle = adv ? adv->handle : instance;
+ if (instance)
+ hci_dev_unlock(hdev);
+
if (flags & MGMT_ADV_FLAG_SEC_2M) {
cp.primary_phy = HCI_ADV_PHY_1M;
cp.secondary_phy = HCI_ADV_PHY_2M;
@@ -1479,12 +1508,12 @@ int hci_setup_ext_adv_instance_sync(stru
cp.secondary_phy = HCI_ADV_PHY_1M;
}
- err = hci_set_ext_adv_params_sync(hdev, adv, &cp, &rp);
+ err = hci_set_ext_adv_params_sync(hdev, instance, &cp, &rp);
if (err)
return err;
/* Update adv data as tx power is known now */
- err = hci_set_ext_adv_data_sync(hdev, cp.handle);
+ err = hci_set_ext_adv_data_sync(hdev, instance);
if (err)
return err;
@@ -1492,9 +1521,14 @@ int hci_setup_ext_adv_instance_sync(stru
own_addr_type == ADDR_LE_DEV_RANDOM_RESOLVED) &&
bacmp(&random_addr, BDADDR_ANY)) {
/* Check if random address need to be updated */
- if (adv) {
- if (!bacmp(&random_addr, &adv->random_addr))
+ if (instance) {
+ hci_dev_lock(hdev);
+ adv = hci_find_adv_instance(hdev, instance);
+ if (!adv || !bacmp(&random_addr, &adv->random_addr)) {
+ hci_dev_unlock(hdev);
return 0;
+ }
+ hci_dev_unlock(hdev);
} else {
if (!bacmp(&random_addr, &hdev->random_addr))
return 0;
@@ -1516,9 +1550,13 @@ static int hci_set_ext_scan_rsp_data_syn
int err;
if (instance) {
+ hci_dev_lock(hdev);
+
adv = hci_find_adv_instance(hdev, instance);
- if (!adv || !adv->scan_rsp_changed)
+ if (!adv || !adv->scan_rsp_changed) {
+ hci_dev_unlock(hdev);
return 0;
+ }
}
len = eir_create_scan_rsp(hdev, instance, pdu->data);
@@ -1528,15 +1566,27 @@ static int hci_set_ext_scan_rsp_data_syn
pdu->operation = LE_SET_ADV_DATA_OP_COMPLETE;
pdu->frag_pref = LE_SET_ADV_DATA_NO_FRAG;
+ if (adv) {
+ adv->scan_rsp_changed = false;
+ hci_dev_unlock(hdev);
+ }
+
err = __hci_cmd_sync_status(hdev, HCI_OP_LE_SET_EXT_SCAN_RSP_DATA,
struct_size(pdu, data, len), pdu,
HCI_CMD_TIMEOUT);
- if (err)
+ if (err) {
+ if (instance) {
+ hci_dev_lock(hdev);
+ adv = hci_find_adv_instance(hdev, instance);
+ if (adv)
+ adv->scan_rsp_changed = true;
+ hci_dev_unlock(hdev);
+ }
+
return err;
+ }
- if (adv) {
- adv->scan_rsp_changed = false;
- } else {
+ if (!instance) {
memcpy(hdev->scan_rsp_data, pdu->data, len);
hdev->scan_rsp_data_len = len;
}
@@ -1551,8 +1601,14 @@ static int __hci_set_scan_rsp_data_sync(
memset(&cp, 0, sizeof(cp));
+ if (instance)
+ hci_dev_lock(hdev);
+
len = eir_create_scan_rsp(hdev, instance, cp.data);
+ if (instance)
+ hci_dev_unlock(hdev);
+
if (hdev->scan_rsp_data_len == len &&
!memcmp(cp.data, hdev->scan_rsp_data, len))
return 0;
@@ -1687,9 +1743,13 @@ static int hci_set_per_adv_data_sync(str
struct adv_info *adv = NULL;
if (instance) {
+ hci_dev_lock(hdev);
+
adv = hci_find_adv_instance(hdev, instance);
- if (!adv || !adv->periodic)
+ if (!adv || !adv->periodic) {
+ hci_dev_unlock(hdev);
return 0;
+ }
}
len = eir_create_per_adv_data(hdev, instance, pdu->data);
@@ -1698,6 +1758,9 @@ static int hci_set_per_adv_data_sync(str
pdu->handle = adv ? adv->handle : instance;
pdu->operation = LE_SET_ADV_DATA_OP_COMPLETE;
+ if (adv)
+ hci_dev_unlock(hdev);
+
return __hci_cmd_sync_status(hdev, HCI_OP_LE_SET_PER_ADV_DATA,
struct_size(pdu, data, len), pdu,
HCI_CMD_TIMEOUT);
@@ -6402,7 +6465,7 @@ static int hci_le_ext_directed_advertisi
if (err)
return err;
- err = hci_set_ext_adv_params_sync(hdev, NULL, &cp, &rp);
+ err = hci_set_ext_adv_params_sync(hdev, 0, &cp, &rp);
if (err)
return err;
next prev parent reply other threads:[~2026-08-20 17:40 UTC|newest]
Thread overview: 171+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-20 14:54 [PATCH 6.6 000/166] 6.6.153-rc1 review Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 001/166] block: stop the timeout timer when releasing a never added disk Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 002/166] f2fs: fix UAF issue in f2fs_merge_page_bio() Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 003/166] ipvs: separate destination availability state Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 004/166] net: mana: Fix EQ leak in mana_remove on NULL port Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 005/166] selinux: require every boolean value to be defined Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 006/166] selinux: reject a class permission count below its inherited common Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 007/166] selinux: do not cancel a policy conversion that never started Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 008/166] selinux: reject an unclaimed class value in security_get_classes() Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 009/166] selftests: mptcp: join: mark tests with data corruption as failed Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 010/166] mptcp: avoid combining some incoming suboptions Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 011/166] mptcp: options: reset DSS fields in case of unexpected size Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 012/166] mptcp: fastopen: only mark MPTFO subflows with SYN data Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 013/166] s390/qeth: validate user buffer length in SNMP and ARP query ioctls Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 014/166] ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 015/166] ASoC: cs4265: sort the register default table Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 016/166] ASoC: cs35l45: " Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 017/166] ASoC: cs35l41: " Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 018/166] ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 019/166] fbdev: core: Fix pointer desynchronization in fb_io_read() Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 020/166] drm/amdgpu: fix aperture iounmap skipped on device removal Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 021/166] Input: xpad - add support for ZENAIM LEVERLESS Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 022/166] powerpc/pseries: pci - logic bug Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 023/166] Input: synaptics-rmi4 - fix F55 transmitter electrode count typo Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 024/166] Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 025/166] Input: psxpad-spi - set driver data before use Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 026/166] Input: atkbd - skip deactivate for Xiaomi Book Pro 14s internal keyboard Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 027/166] Input: iforce - validate input packet lengths Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 028/166] powerpc/pseries: lparcfg - fix kbuf[] underflow Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 029/166] Input: synaptics-rmi4 - zero report size on F54 work error Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 030/166] Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 031/166] Input: synaptics-rmi4 - block s_input when F54 queue is busy Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 032/166] Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 033/166] Input: hynitron_cstxxx - validate touch count and finger IDs Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 034/166] crypto: qce - fix error path in devm_qce_register_algs Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 035/166] libceph: fix multiple unsafe decodes in decode_locker() Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 036/166] ftrace: Protect direct_functions in ftrace_find_rec_direct Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 037/166] ftrace: Fix off-by-one fentry site disable in ftrace_free_mem() Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 038/166] openrisc: signal: do not restore privileged SR bits on sigreturn Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 039/166] Input: sur40 - fix input device registration ordering Greg Kroah-Hartman
2026-08-20 14:54 ` [PATCH 6.6 040/166] Input: sur40 - fix V4L error path cleanup Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 041/166] libceph: Avoid using invalid osd indices from primary_temp Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 042/166] ceph: fix MDS random selection readiness predicate Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 043/166] libceph: tolerate addrvecs with multiple entries of the same type Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 044/166] mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 045/166] mmc: sdhci: unmap the bounce buffer before device release Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 046/166] mmc: sdhci: make tuning_err a signed int Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 047/166] mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 048/166] drm/radeon: fix autosuspend cleanup during teardown Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 049/166] s390/vfio_ccw: Free all memory if cp_init() fails Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 050/166] s390/vfio_ccw: Limit the number of channel program segments Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 051/166] s390/vfio_ccw: Cancel existing workqueues Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 052/166] s390/vfio_ccw: Ensure index for read/write regions are within range Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 053/166] s390/vfio_ccw: Fix out of bounds check on CCW array Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 054/166] s390/vfio_ccw: Move cp cleanup out of not operational Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 055/166] s390/vfio_ccw: Selectively expand io_mutex Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 056/166] drm/amdgpu: Reject UVD message with invalid number of h265 refs Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 057/166] drm/amdgpu: validate GEM_CREATE domain combinations Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 058/166] drm/amdgpu: Reject UVD message with dimensions above 4096 Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 059/166] drm/amdgpu: Implement insert_end for VCE 3 Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 060/166] drm/amdgpu: Fix UVD min buffer sizes Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 061/166] drm/amdgpu: Fix UVD dpb min size calculation for H264 Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 062/166] drm/amdgpu: Fix UVD decode image min size calculation Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 063/166] drm/amdgpu: disallow multiple FENCE chunks in one submit Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 064/166] xfs: only check mergeability of bnobt records Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 065/166] xfs: fix ilock leak on error in xfs_dq_get_next_id Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 066/166] xfs: dont swallow dquot recovery verification errors Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 067/166] xfs: check v5 superblock features early Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 068/166] RISC-V: Provide pgtable_l5_enabled on rv32 Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 069/166] selftests: tls: add test with a partially invalid iov Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 070/166] ceph: avoid fs reclaim while using current->journal_info Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 071/166] ceph: Remove ceph_writepage() Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 072/166] ceph: fix hanging __ceph_get_caps() with stale mds_wanted Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 073/166] ceph: Use a folio in ceph_page_mkwrite() Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 074/166] libceph: Amend checking to fix `make W=1` build breakage Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 075/166] libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 076/166] ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 077/166] iomap: hold state_lock over call to ifs_set_range_uptodate() Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 078/166] iomap: fix out-of-bounds bitmap_set() with zero-length range Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 079/166] mm: userfaultfd: add pgtable_supports_uffd_wp() Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 080/166] userfaultfd: move vma_can_userfault out of line Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 081/166] userfaultfd: prevent registration of special VMAs Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 082/166] libceph: fix two unsafe bare decodes in decode_lockers() Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 083/166] net: move skb_gro_receive_list from udp to core Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 084/166] net: gro: fix double aggregation of flush-marked skbs Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 085/166] net/sched: serialize qdisc_rtab_list against concurrent get/put Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 086/166] super: fix emergency thaw deadlock on frozen block devices Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 087/166] smb: move smb_version_values to common/smbglob.h Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 088/166] smb: move get_rfc1002_len() " Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 089/166] smb/server: rename include guard in smb_common.h Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 090/166] ksmbd: rename smb2_get_msg to smb_get_msg Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 091/166] smb/server: fix minimum SMB1 PDU size Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 092/166] smb/server: fix minimum SMB2 " Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 093/166] ksmbd: validate minimum PDU size for transform requests Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 094/166] tcp: Pass flags to __tcp_send_ack Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 095/166] tcp: fast path functions later Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 096/166] tcp: challenge ACK for non-exact RST in SYN-RECEIVED Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 097/166] btrfs: add debug build only WARN Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 098/166] btrfs: add space_info argument to btrfs_chunk_alloc() Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 099/166] btrfs: remove fs_info argument from btrfs_zoned_activate_one_bg() Greg Kroah-Hartman
2026-08-20 14:55 ` [PATCH 6.6 100/166] btrfs: zoned: fix missing chunk metadata reservation Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 101/166] mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 102/166] ice: make use of DEFINE_FLEX() in ice_switch.c Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 103/166] ice: make ice_vsi_cfg_rxq() static Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 104/166] overflow: Change DEFINE_FLEX to take __counted_by member Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 105/166] Bluetooth: hci_conn, hci_sync: Use __counted_by() to avoid -Wfamnae warnings Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 106/166] Bluetooth: hci_core: Fix not handling hdev->le_num_of_adv_sets=1 Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 107/166] Bluetooth: eir: Fix possible crashes on eir_create_adv_data Greg Kroah-Hartman
2026-08-20 14:56 ` Greg Kroah-Hartman [this message]
2026-08-20 14:56 ` [PATCH 6.6 109/166] ASoC: tas2562: Validate values for volume writes Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 110/166] igc: remove napi_synchronize() in igc_down() Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 111/166] ksmbd: conn lock to serialize smb2 negotiate Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 112/166] ksmbd: reject repeated SMB2 NEGOTIATE requests Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 113/166] net: pktgen: fix code style (WARNING: Block comments) Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 114/166] net: pktgen: fix proc entry use-after-free Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 115/166] veth: convert frag_list skbs before running XDP Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 116/166] fs: dont block write during exec on pre-content watched files Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 117/166] binfmt_misc: restore write access when removing an entry Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 118/166] ice: fix VF interrupts cleanup Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 119/166] vxlan: Do not alloc tstats manually Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 120/166] net: core,vrf: Change pcpu_dstat fields to u64_stats_t Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 121/166] vrf: Make pcpu_dstats update functions available to other modules Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 122/166] vxlan: Handle stats using NETDEV_PCPU_STAT_DSTATS Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 123/166] vxlan: use pskb_network_may_pull() for transmit path header pulls Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 124/166] i2c: bcm-iproc: remove printout on handled timeouts Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 125/166] i2c: iproc: reset bus after timeout if START_BUSY is stuck Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 126/166] can: rcar_canfd: change the initializing flow for clocks and resets Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 127/166] drm/amd/pm: fix torn gpu metrics reads Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 128/166] drm/amd/pm: fix pptable use-after-free Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 129/166] drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 130/166] mm/pagewalk: split walk_page_range_novma() into kernel/user parts Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 131/166] mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 132/166] mm/ptdump: always stabilise against page table freeing using init_mm Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 133/166] KVM: SVM: Serialize accesses to the owner and mirror list with separate lock Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 134/166] selftests: tls: add rekey tests Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 135/166] tls: rx: restore msg_iter before TLS 1.3 optimistic retry Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 136/166] mm/huge_memory: fix huge_zero_pfn race Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 137/166] arm64: tegra: Add EL2 virtual timer interrupt for Tegra194 Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 138/166] crypto: ccm - Set rfc4309 maxauthsize from child Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 139/166] netfilter: ipset: fix refcount race between list:set GC and swap Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 140/166] netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 141/166] netfilter: flowtable: publish GC-visible tuple last Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 142/166] netfilter: ipset: fix list type element drift bug Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 143/166] netfilter: ipset: let destroy callbacks adjust ext mem size Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 144/166] ipvlan: inherit needed_headroom and needed_tailroom from phy_dev Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 145/166] macvlan: inherit needed_headroom and needed_tailroom from lowerdev Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 146/166] net: packet: fix wrong transport_header when sending VLAN-tagged frame Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 147/166] net/tls: Fail tls_sw_splice_read() after a failed async decrypt Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 148/166] ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 149/166] af_packet: Dont send zero-byte data in tpacket_snd() Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 150/166] net, sched: Make tc-related drop reason more flexible Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 151/166] net, sched: Add tcf_set_drop_reason for {__,}tcf_classify Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 152/166] net, sched: Fix SKB_NOT_DROPPED_YET splat under debug config Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 153/166] packet: add a generic drop reason for receive Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 154/166] net: sched: Move drop_reason to struct tc_skb_cb Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 155/166] net: sched: Add initial TC error skb drop reasons Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 156/166] net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 157/166] net/sched: cls_u32: skip hash tables in u32_bind_class() Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 158/166] dma-direct: add a CONFIG_ARCH_HAS_DMA_ALLOC symbol Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 159/166] m68k: use the coherent DMA code for coldfire without data cache Greg Kroah-Hartman
2026-08-20 14:56 ` [PATCH 6.6 160/166] m68k: Define NR_CPUS to 1 Greg Kroah-Hartman
2026-08-20 14:57 ` [PATCH 6.6 161/166] net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG Greg Kroah-Hartman
2026-08-20 14:57 ` [PATCH 6.6 162/166] net/sched: cls_bpf: reject dev-bound programs bound to a different device Greg Kroah-Hartman
2026-08-20 14:57 ` [PATCH 6.6 163/166] erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms Greg Kroah-Hartman
2026-08-20 14:57 ` [PATCH 6.6 164/166] net/x25: fix use-after-free of the socket by its timers Greg Kroah-Hartman
2026-08-20 14:57 ` [PATCH 6.6 165/166] binfmt_misc: use exe_file_deny_write_access() for the interpreter clone Greg Kroah-Hartman
2026-08-20 14:57 ` [PATCH 6.6 166/166] net: harmonize tstats and dstats Greg Kroah-Hartman
2026-08-20 18:30 ` [PATCH 6.6 000/166] 6.6.153-rc1 review Pavel Machek
2026-08-20 20:25 ` Brett A C Sheffield
2026-08-20 21:34 ` Florian Fainelli
2026-08-21 5:34 ` Ron Economos
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260820145214.413281718@linuxfoundation.org \
--to=gregkh@linuxfoundation.org \
--cc=luiz.dentz@gmail.com \
--cc=luiz.von.dentz@intel.com \
--cc=nicoyip.dev@gmail.com \
--cc=patches@lists.linux.dev \
--cc=sashal@kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.