All of lore.kernel.org
 help / color / mirror / Atom feed
From: Sean Christopherson <seanjc@google.com>
To: "IP over Parrots (with QoS)" <opensource@rfc2549.ca>
Cc: "stable@vger.kernel.org" <stable@vger.kernel.org>,
	"pbonzini@redhat.com" <pbonzini@redhat.com>,
	 "kvm@vger.kernel.org" <kvm@vger.kernel.org>,
	Sergey Senozhatsky <senozhatsky@chromium.org>
Subject: Re: 6.1.y status: 2abd5287f083 ("KVM: x86: Check for invalid/obsolete root *after* making MMU pages available") / CVE-2026-64561
Date: Tue, 11 Aug 2026 09:03:55 -0700	[thread overview]
Message-ID: <antH6ysN2SPR2gyV@google.com> (raw)
In-Reply-To: <ans1SMXHmdB3uEoe@google.com>

+Sergey

On Tue, Aug 11, 2026, Sean Christopherson wrote:
> On Tue, Aug 11, 2026, IP over Parrots (with QoS) wrote:
> > Hi,
> > 
> > Commit 2abd5287f083 ("KVM: x86: Check for invalid/obsolete root
> > *after* making MMU pages available"), which landed in 7.2-rc5 and is
> > tracked as CVE-2026-64561, does not appear to be present in
> > linux-6.1.y as of 6.1.182.
> > 
> > I checked with:
> > 
> >   git log --oneline origin/linux-6.1.y --grep='invalid/obsolete root'
> >   git log --oneline origin/linux-6.1.y --grep='2abd5287f083'
> > 
> > Neither returns a match and it doesn't seem to be in the queue.
> > The commit message notes the invariant being violated was
> > introduced in 5.9 by f95eec9bed76, so 6.1 looks in scope,
> > and both hunks sit in direct_page_fault() and FNAME(page_fault)(),
> > which appear structurally unchanged on that branch.
> > 
> > However the announcement[0] only mentions the fix landing in:
> > - 6.6.148
> > - 6.12.101
> > - 6.18.42
> > - 7.1.6
> > - 7.2-rc2
> > 
> > Is a 6.1.y backport planned, or was it skipped deliberately?
> 
> Now planned.  The fix doesn't apply cleanly to 6.1, and the resolving the conflict
> isn't super straightforward (though it's not thaaaat bad either).
> 
> https://lore.kernel.org/all/anpVAhjqvBvIuoa0@google.com
> 
> > The security tracker [1] for the Debian 12 stable kernel (6.1.y)
> > shows a vulnerable status.
> > 
> > I do not have a backport to offer, so this is just an inquiry.
> > I am happy to build and test a candidate on 6.1 if that would
> > be useful.
> 
> I'll post a patch today and Cc you (unless I get goldfish brain, in which case
> I apologize in advance).

Actually, duh, Sasha already posted backports[*], and his approach is much better
than manually resolving the conflicts.  Testing that now, I'll ACK those assuming
all goes well.

[*] https://lore.kernel.org/all/20260730121535.2208491-1-sashal@kernel.org




  reply	other threads:[~2026-08-11 16:03 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-11 13:41 6.1.y status: 2abd5287f083 ("KVM: x86: Check for invalid/obsolete root *after* making MMU pages available") / CVE-2026-64561 IP over Parrots (with QoS)
2026-08-11 14:44 ` Sean Christopherson
2026-08-11 16:03   ` Sean Christopherson [this message]
2026-08-12  5:07     ` Sergey Senozhatsky
2026-08-11 15:24 ` Paolo Bonzini
2026-08-12  1:08   ` IP over Parrots (with QoS)

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=antH6ysN2SPR2gyV@google.com \
    --to=seanjc@google.com \
    --cc=kvm@vger.kernel.org \
    --cc=opensource@rfc2549.ca \
    --cc=pbonzini@redhat.com \
    --cc=senozhatsky@chromium.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.