All of lore.kernel.org
 help / color / mirror / Atom feed
* 6.1.y status: 2abd5287f083 ("KVM: x86: Check for invalid/obsolete root *after* making MMU pages available") / CVE-2026-64561
@ 2026-08-11 13:41 IP over Parrots (with QoS)
  2026-08-11 14:44 ` Sean Christopherson
  2026-08-11 15:24 ` Paolo Bonzini
  0 siblings, 2 replies; 6+ messages in thread
From: IP over Parrots (with QoS) @ 2026-08-11 13:41 UTC (permalink / raw)
  To: stable@vger.kernel.org
  Cc: seanjc@google.com, pbonzini@redhat.com, kvm@vger.kernel.org

Hi,

Commit 2abd5287f083 ("KVM: x86: Check for invalid/obsolete root
*after* making MMU pages available"), which landed in 7.2-rc5 and is
tracked as CVE-2026-64561, does not appear to be present in
linux-6.1.y as of 6.1.182.

I checked with:

  git log --oneline origin/linux-6.1.y --grep='invalid/obsolete root'
  git log --oneline origin/linux-6.1.y --grep='2abd5287f083'

Neither returns a match and it doesn't seem to be in the queue.
The commit message notes the invariant being violated was
introduced in 5.9 by f95eec9bed76, so 6.1 looks in scope,
and both hunks sit in direct_page_fault() and FNAME(page_fault)(),
which appear structurally unchanged on that branch.

However the announcement[0] only mentions the fix landing in:
- 6.6.148
- 6.12.101
- 6.18.42
- 7.1.6
- 7.2-rc2

Is a 6.1.y backport planned, or was it skipped deliberately?
The security tracker [1] for the Debian 12 stable kernel (6.1.y)
shows a vulnerable status.

I do not have a backport to offer, so this is just an inquiry.
I am happy to build and test a candidate on 6.1 if that would
be useful.

Thanks,

David Moreau-Simard

[0]: https://lore.kernel.org/linux-cve-announce/2026080401-CVE-2026-64561-d0d4@gregkh/T
[1]: https://security-tracker.debian.org/tracker/CVE-2026-64561

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-08-12  5:07 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-11 13:41 6.1.y status: 2abd5287f083 ("KVM: x86: Check for invalid/obsolete root *after* making MMU pages available") / CVE-2026-64561 IP over Parrots (with QoS)
2026-08-11 14:44 ` Sean Christopherson
2026-08-11 16:03   ` Sean Christopherson
2026-08-12  5:07     ` Sergey Senozhatsky
2026-08-11 15:24 ` Paolo Bonzini
2026-08-12  1:08   ` IP over Parrots (with QoS)

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.