CIP-dev Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Ulrich Hecht <uli@fpond.eu>
To: "cip-dev@lists.cip-project.org" <cip-dev@lists.cip-project.org>,
	"pavel@nabladev.com" <pavel@nabladev.com>,
	"jan.kiszka@siemens.com" <jan.kiszka@siemens.com>,
	"masami.ichikawa@cybertrust.co.jp"
	<masami.ichikawa@cybertrust.co.jp>,
	"chris.paterson2@renesas.com" <chris.paterson2@renesas.com>,
	"nobuhiro.iwamatsu.x90@mail.toshiba"
	<nobuhiro.iwamatsu.x90@mail.toshiba>
Subject: [ANNOUNCE] Release v4.19.325-cip136
Date: Fri, 11 Sep 2026 12:15:49 +0200 (CEST)	[thread overview]
Message-ID: <1432043768.88457.1789121749469@webmail.strato.de> (raw)

Hi,

the CIP kernel team has released Linux kernel v4.19.325-cip136. The linux-4.19.y-cip tree's base version has been updated to v4.19-st20. The trees are up-to-date with kernel 5.10.266.

You can get this release via the git tree or as a tarball from https://mirrors.edge.kernel.org/pub/linux/kernel/projects/cip/4.19/

  v4.19.325-cip136:
    repository:
      https://git.kernel.org/pub/scm/linux/kernel/git/cip/linux-cip.git
    branch:
      linux-4.19.y-cip
    commit hash:
      596368289cc36e634b7c43a93e9e81b117692845
    Fixed CVEs:
      CVE-2022-48785: ipv6: mcast: use rcu-safe version of ipv6_get_lladdr()
      CVE-2024-50125: Bluetooth: SCO: Fix UAF on sco_sock_timeout
      CVE-2025-38524: rxrpc: Fix recv-recv race of completed call
      CVE-2026-31408: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold
      CVE-2026-31650: mmc: vub300: fix use-after-free on disconnect
      CVE-2026-64540: usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()
      CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
      CVE-2026-64544: crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents
      CVE-2026-64546: drm/edid: fix OOB read in drm_parse_tiled_block()
      CVE-2026-64547: net: usb: net1080: validate packet_len before pad-byte access in rx_fixup
      CVE-2026-64549: Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
      CVE-2026-64551: sctp: validate STALE_COOKIE cause length before reading staleness
      CVE-2026-64553: net: psample: fix info leak in PSAMPLE_ATTR_DATA
      CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR
      CVE-2026-64563: rhashtable: clear stale iter->p on table restart
      CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing
      CVE-2026-64565: Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
      CVE-2026-64571: wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
      CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path
      CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap
      CVE-2026-64583: usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
      CVE-2026-64584: usb: gadget: f_midi: cancel pending IN work before freeing the midi object
      CVE-2026-68106: drm/amdgpu: fix division by zero with invalid uvd dimensions
      CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
      CVE-2026-68121: pppoe: reload header pointer after dev_hard_header()
      CVE-2026-68123: openvswitch: fix GSO userspace truncation underflow
      CVE-2026-68125: mac802154: llsec: reject frames shorter than the authentication tag
      CVE-2026-68127: ila: reload IPv6 header after pskb_may_pull in checksum adjust
      CVE-2026-68135: net: hip04: fix RX buffer leak on build_skb failure
      CVE-2026-68137: net/x25: fix use-after-free in x25_kill_by_neigh()
      CVE-2026-68140: net/iucv: fix use-after-free of a severed iucv_path
      CVE-2026-68141: net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
      CVE-2026-68142: geneve: require CAP_NET_ADMIN in the device netns for changelink
      CVE-2026-68143: net: slip: serialize receive against buffer reallocation
      CVE-2026-68144: phonet: pep: fix use-after-free in pep_get_sb()
      CVE-2026-68146: ftrace: Add global mutex to serialize trace_parser access
      CVE-2026-68151: binfmt_elf_fdpic: only honour the first PT_INTERP
      CVE-2026-68153: libceph: remove debugfs files before client teardown
      CVE-2026-68154: libceph: reject zero bucket types in crush_decode
      CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after authorizer update
      CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight()
      CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
      CVE-2026-68175: tracing: Fix resource leak on mmiotrace trace_pipe close
      CVE-2026-68176: tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
      CVE-2026-68182: comedi: comedi_parport: deal with premature interrupt
      CVE-2026-68184: cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
      CVE-2026-68187: exec: fix unsigned loop counter wrap in transfer_args_to_stack()
      CVE-2026-68188: Bluetooth: RFCOMM: Fix session UAF in set_termios
      CVE-2026-68192: wifi: brcmfmac: make release_scratchbuffers idempotent
      CVE-2026-68197: wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper
      CVE-2026-68198: wifi: ath6kl: fix use-after-free in aggr_reset_state()
      CVE-2026-68199: wifi: ath6kl: fix OOB access from firmware ADDBA window size
      CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor
      CVE-2026-68204: media: vivid: check for vb2_is_busy() when toggling caps
      CVE-2026-68212: media: saa7134: Fix a possible memory leak in saa7134_video_init1
      CVE-2026-68213: media: rtl2832_sdr: Return queued buffers on start_streaming() failure
      CVE-2026-68214: media: rtl2832: fix use-after-free in rtl2832_remove()
      CVE-2026-68215: media: radio-si476x: Unregister v4l2_device on probe failure
      CVE-2026-68216: media: pwc: Return queued buffers on start_streaming() failure
      CVE-2026-68217: media: pwc: Drain fill_buf on start_streaming() failure
      CVE-2026-68218: media: pci: dm1105: Free allocated workqueue
      CVE-2026-68222: media: msi2500: Return queued buffers on start_streaming() failure
      CVE-2026-68226: media: cx23885: add ioremap return check and cleanup
      CVE-2026-68227: media: cx231xx: fix devres lifetime
      CVE-2026-68231: media: airspy: Return queued buffers on start_streaming() failure
      CVE-2026-68234: drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
      CVE-2026-68277: drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
      CVE-2026-68278: drm/dp/mst: fix buffer overflows in sideband chunk accumulation
      CVE-2026-68279: drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
      CVE-2026-68294: net: qrtr: restrict socket creation to the initial network namespace
      CVE-2026-68297: tipc: fix u16 MTU truncation in media and bearer MTU validation
      CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
      CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL
      CVE-2026-68304: wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
      CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit
      CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq()
      CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
      CVE-2026-68322: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled
      CVE-2026-68326: wifi: mwifiex: bound uAP association event IEs to the event buffer
      CVE-2026-68327: wan: wanxl: Only reset hardware after BAR mapping
      CVE-2026-68328: nfp: Check resource mutex allocation
      CVE-2026-68335: rds: drop incoming messages that cross network namespace boundaries
      CVE-2026-68338: net/packet: avoid fanout hook re-registration after unregister
      CVE-2026-68344: usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect
      CVE-2026-68350: wifi: carl9170: fix OOB read from off-by-two in TX status handler
      CVE-2026-68351: wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
      CVE-2026-68352: wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
      CVE-2026-68353: wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
      CVE-2026-68354: firewire: net: Fix fragmented datagram reassembly
      CVE-2026-68357: watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
      CVE-2026-68363: wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
      CVE-2026-68365: USB: serial: io_edgeport: cap received transmit credits
      CVE-2026-68366: usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer
      CVE-2026-68368: usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
      CVE-2026-68370: usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
      CVE-2026-68373: wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
      CVE-2026-68376: sctp: fix auth_hmacs array size in struct sctp_cookie
      CVE-2026-68377: net/sched: act_tunnel_key: Defer dst_release to RCU callback
      CVE-2026-68395: ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered
      CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv()
      CVE-2026-68403: wifi: brcmfmac: initialize SDIO data work before cleanup
      CVE-2026-68405: wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
      CVE-2026-68410: wifi: libertas: fix memory leak in helper_firmware_cb()
      CVE-2026-68413: wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
      CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly
      CVE-2026-68428: KVM: x86/mmu: Fix use-after-free on vendor module reload
      CVE-2026-68430: drm/amdgpu/gfx8: drop unecessary BUG_ON()
      CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink
      CVE-2026-68433: libceph: bound get_version reply decode to front len
      CVE-2026-68434: serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms
      CVE-2026-68449: ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning
      CVE-2026-68456: usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()
      CVE-2026-68466: mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout
      CVE-2026-68469: wifi: mwifiex: fix permanently busy scans after multiple roam iterations
      CVE-2026-68474: powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()
      CVE-2026-68475: reset: sunxi: fix memory region leak on ioremap failure
      CVE-2026-68478: memstick: ms_block: reject a card that reports too many blocks
      CVE-2026-68479: Bluetooth: btrtl: validate firmware patch bounds
      CVE-2026-72005: wifi: rt2x00: avoid full teardown before work setup in probe
      CVE-2026-72010: cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed
      CVE-2026-72014: drbd: reject data replies with an out-of-range payload size
      CVE-2026-72015: fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
      CVE-2026-72019: macsec: don't read an unset MAC header in macsec_encrypt()
      CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
      CVE-2026-72021: ipvs: use parsed transport offset in SCTP state lookup
      CVE-2026-72022: llc: fix SAP refcount leak in llc_ui_autobind()
      CVE-2026-72024: mac802154: remove interfaces with RCU list deletion
      CVE-2026-72025: s390/monwriter: Reject buffer reuse with different data length
      CVE-2026-72033: orangefs: keep the readdir entry size 64-bit in fill_from_part()
      CVE-2026-72036: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked
      CVE-2026-72038: net: liquidio: fix BAR resource leak on PF number failure
      CVE-2026-72039: bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()
      CVE-2026-72047: ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit
      CVE-2026-72048: ieee802154: ca8210: fix cas_ctl leak on spi_async failure
      CVE-2026-72049: ieee802154: admin-gate legacy LLSEC dump operations
      CVE-2026-72051: net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink
      CVE-2026-72052: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
      CVE-2026-72053: net: ipip: require CAP_NET_ADMIN in the device netns for changelink
      CVE-2026-72054: net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
      CVE-2026-72055: net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
      CVE-2026-72061: net: sit: require CAP_NET_ADMIN in the device netns for changelink
      CVE-2026-72066: cpu: hotplug: Bound hotplug states sysfs output
      CVE-2026-72067: cpu: hotplug: Preserve per instance callback errors
      CVE-2026-72070: wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
      CVE-2026-72073: mmc: vub300: fix use-after-free on probe failure
      CVE-2026-72074: Input: ims-pcu - fix type confusion in CDC union descriptor parsing
      CVE-2026-72076: Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging
      CVE-2026-72078: Input: ims-pcu - validate control endpoint type
      CVE-2026-72079: Input: ims-pcu - fix use-after-free and double-free in disconnect
      CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
      CVE-2026-72096: dm-verity: make error counter atomic
      CVE-2026-72105: dm-log: fix a bitset_size overflow on 32bit machines
      CVE-2026-72107: dm era: fix out-of-bounds memory access for non-zero start sector
      CVE-2026-72108: dm thin metadata: fix metadata snapshot consistency on commit failure
      CVE-2026-72113: can: bcm: add missing device refcount for CAN filter removal
      CVE-2026-72114: can: bcm: validate frame length in bcm_rx_setup() for RTR replies
      CVE-2026-72115: can: bcm: track a single source interface for ANYDEV timeout/throttle ops
      CVE-2026-72116: can: bcm: fix stale rx/tx ops after device removal
      CVE-2026-72117: can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()
      CVE-2026-72118: can: bcm: fix CAN frame rx/tx statistics
      CVE-2026-72119: can: bcm: extend bcm_tx_lock usage for data and timer updates
      CVE-2026-72120: can: bcm: add missing rcu list annotations and operations
      CVE-2026-72121: can: bcm: add locking when updating filter and timer values
      CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF
      CVE-2026-72135: tpm: Make the TPM character devices non-seekable
      CVE-2026-72136: xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink
      CVE-2026-72138: xen/gntdev: fix error handling in ioctl
      CVE-2026-72142: i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
      CVE-2026-72153: irqchip/crossbar: Use correct index in crossbar_domain_free()
      CVE-2026-72157: net: thunderbolt: Fix frags[] overflow by bounding frame_count
      CVE-2026-72159: ocfs2: reject non-inline dinodes with i_size and zero i_clusters
      CVE-2026-72160: ocfs2: reject dinodes with non-canonical i_mode type
      CVE-2026-72164: ocfs2: avoid moving extents to occupied clusters
      CVE-2026-72166: net/9p: fix infinite loop in p9_client_rpc on fatal signal
      CVE-2026-72170: 9p: skip nlink update in cacheless mode to fix WARN_ON
      CVE-2026-72171: mtd: slram: remove failed entries from the device list
      CVE-2026-72181: mips: sched: Fix CPUMASK_OFFSTACK memory corruption
      CVE-2026-72215: MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf()
      CVE-2026-72223: nvdimm/btt: Free arena sub-allocations on discover_arenas() error path
      CVE-2026-72224: nvdimm/btt: Free arenas on btt_init() error paths
      CVE-2026-72226: batman-adv: tt: prevent TVLV OOB check overflow
      CVE-2026-72228: batman-adv: frag: fix primary_if leak on failed linearization
      CVE-2026-72230: batman-adv: frag: free unfragmentable packet
      CVE-2026-72231: batman-adv: tt: avoid request storms during pending request
      CVE-2026-72232: batman-adv: ensure minimal ethernet header on TX
      CVE-2026-72233: batman-adv: bla: reacquire gw address after skb realloc
      CVE-2026-72234: batman-adv: access unicast_ttvn skb->data only after skb realloc
      CVE-2026-72235: batman-adv: retrieve ethhdr after potential skb realloc on RX
      CVE-2026-72238: x86/boot: Validate console=uart8250 baud rate to fix early boot hang
      CVE-2026-72240: mfd: sm501: Fix reference leak on failed device registration
      CVE-2026-72242: selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()
      CVE-2026-72245: gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path
      CVE-2026-72247: netfilter: nf_conncount: fix zone comparison in tuple dedup
      CVE-2026-72250: netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag
      CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer
      CVE-2026-72256: netfilter: xt_cluster: reject template conntracks in hash match
      CVE-2026-72265: fbdev: nvidia: fix potential memory leak in nvidiafb_probe()
      CVE-2026-72269: fbdev: uvesafb: fix potential memory leak in uvesafb_probe()
      CVE-2026-72282: KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers
      CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it
      CVE-2026-72296: net: ife: require ETH_HLEN to be pullable in ife_decode()
      CVE-2026-72297: net: atm: reject out-of-range traffic classes in QoS validation
      CVE-2026-72298: net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
      CVE-2026-72307: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()
      CVE-2026-72316: dm era: fix NULL pointer dereference in metadata_open()
      CVE-2026-72319: ipvs: ensure inner headers in ICMP errors are in headroom
      CVE-2026-72322: ipv6: mcast: Fix potential UAF in MLD delayed work
      CVE-2026-72326: net/sched: cake: reject overhead values that underflow length
      CVE-2026-72339: qede: fix off-by-one in BD ring consumption on build_skb failure
      CVE-2026-72348: netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
      CVE-2026-72349: netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()
      CVE-2026-72350: netfilter: xt_u32: reject invalid shift counts
      CVE-2026-72351: gue: validate REMCSUM private option length
      CVE-2026-72374: afs: Fix callback service message parsers to pass through -EAGAIN
      CVE-2026-72392: ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump
      CVE-2026-72396: hwmon: adm1275: Prevent reading uninitialized stack
      CVE-2026-72400: seg6: validate SRH length before reading fixed fields
      CVE-2026-72406: net: sungem: fix probe error cleanup
      CVE-2026-72409: net: mvneta: re-enable percpu interrupt on resume
      CVE-2026-72418: netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
      CVE-2026-72421: ipv4: fib: Don't ignore error route in local/main tables.
      CVE-2026-72428: bpf: Fix stack slot index in nospec checks
      CVE-2026-72435: netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
      CVE-2026-72441: ieee802154: fix kernel-infoleak in dgram_recvmsg()
      CVE-2026-72450: xfrm: validate selector family and prefixlen during match
      CVE-2026-72481: iio: magnetometer: ak8975: fix potential kernel stack memory leak
      CVE-2026-72483: usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
      CVE-2026-72484: staging: most: video: avoid double free on video register failure
      CVE-2026-72489: staging: nvec: fix use-after-free in nvec_rx_completed()
      CVE-2026-72491: net/9p: fix race condition on rdma->state in trans_rdma.c
      CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)
      CVE-2026-74255: tipc: fix UAF in tipc_l2_send_msg()
      CVE-2026-74262: kcm: use WRITE_ONCE() when changing lower socket callbacks
      CVE-2026-74267: net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
      CVE-2026-74276: spi: xilinx: use FIFO occupancy register to determine buffer size
      CVE-2026-74279: crypto: cavium/cpt - fix DMA cleanup using wrong loop index
      CVE-2026-74282: tipc: prevent snt_unacked underflow on CONN_ACK
      CVE-2026-74283: tipc: require net admin for TIPCv2 netlink mutators
      CVE-2026-74284: net/sched: sch_hfsc: Don't make class passive twice
      CVE-2026-74287: sctp: validate embedded address parameter length
      CVE-2026-74288: net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().
      CVE-2026-74330: configfs: fix lockless traversals of ->s_children
      CVE-2026-74331: firmware_loader: Fix recursive lock in device_cache_fw_images()
      CVE-2026-74340: wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication
      CVE-2026-74348: ocfs2/dlm: require a ref for locking_state debugfs open
      CVE-2026-74349: ocfs2: reject FITRIM ranges shorter than a cluster
      CVE-2026-74351: ocfs2: rebase copied fsdlm LVB pointers in locking_state
      CVE-2026-74382: net/sched: cls_bpf: prevent unbounded recursion in offload rollback
      CVE-2026-74398: ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD
      CVE-2026-74408: wifi: ath9k: fix OOB access from firmware tx status queue ID
      CVE-2026-74416: drm/radeon: fix memory leak in radeon_ring_restore() on lock failure
      CVE-2026-74427: afs: Fix netns teardown to cancel the preallocation charger
      CVE-2026-74432: rxrpc: Fix leak of released call in recvmsg(MSG_PEEK)
      CVE-2026-74436: rxrpc: serialize kernel accept preallocation with socket teardown
      CVE-2026-74453: drm/vc4: Zero the tile state data array before each BIN job
      CVE-2026-74455: can: peak_usb: validate uCAN receive record lengths
      CVE-2026-74456: can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error
      CVE-2026-74457: can: peak_usb: add bounds check for USB channel index
      CVE-2026-74458: can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents
      CVE-2026-74463: i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock
      CVE-2026-74464: net: openvswitch: fix skb leak on flow key update failure during ct
      CVE-2026-74469: sctp: prevent peer transport count overflow
      CVE-2026-74471: tracing: Check return value of __register_event() in trace_module_add_events()
      CVE-2026-74473: vxlan: use pskb_network_may_pull() in route_shortcircuit()
      CVE-2026-74475: vxlan: use neigh_ha_snapshot() in route_shortcircuit()
      CVE-2026-74478: um: vector: fix use-after-free in vector_mmsg_rx()
      CVE-2026-74480: net: bridge: stop fast-leave after deleting a port group
      CVE-2026-74482: mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios
      CVE-2026-74485: binfmt_misc: reject a flag character as the field delimiter
      CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames
      CVE-2026-74495: igbvf: Fix leak in TX DMA error cleanup
      CVE-2026-74497: ALSA: usb-audio: Clamp frame size in implicit-feedback mode
      CVE-2026-74498: ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set
      CVE-2026-74499: ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
      CVE-2026-74505: ALSA: 6fire: Fix UAF at error handling during probe
      CVE-2026-74507: Bluetooth: HIDP: validate numbered report payloads
      CVE-2026-74508: Bluetooth: HIDP: reject frames without a transaction header
      CVE-2026-74512: audit: fix potential use-after-free in audit_del_rule()
      CVE-2026-74519: pinctrl: devicetree: don't free uninitialized dev_name on error path
      CVE-2026-74525: net: sxgbe: free TX rings on RX allocation failure
      CVE-2026-74547: hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread
      CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer
      CVE-2026-74557: scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer
      CVE-2026-74563: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()
      CVE-2026-74564: netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
      CVE-2026-74569: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()
      CVE-2026-74577: net: mpls: initialize rtm_tos in mpls_getroute()
      CVE-2026-74580: vhost: reset the vring metadata cache on vring reconfiguration
      CVE-2026-74583: net/sched: cls_route: fix fastmap use-after-free on filter
      CVE-2026-74585: thunderbolt: Bound the DROM dual link port number before indexing sw->ports
      CVE-2026-74586: sctp: clear new_transport when removing a peer
      CVE-2026-74587: sctp: fix use-after-free of cached ASCONF chunk
      CVE-2026-74588: sctp: keep chunk->transport in step with the list it is queued on
      CVE-2026-74597: ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
      CVE-2026-74598: ipv6: fix Route Information option length validation
      CVE-2026-74609: tipc: read le->link under the node lock in tipc_node_link_down()
      CVE-2026-74613: vsock/virtio: avoid refilling the RX queue after teardown
      CVE-2026-74630: ipv6: prevent in6_dev_get() from resurrecting inet6_dev
      CVE-2026-74648: staging: rtl8723bs: validate monitor transmit frame lengths
      CVE-2026-74651: staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()
      CVE-2026-74654: serial: 8250_dma: Clear stale RX state on shutdown
      CVE-2026-74658: futex: Prevent robust futex exit race some more
      CVE-2026-74660: netfilter: ebt_nflog: pin the NFLOG backend
      CVE-2026-74664: net: openvswitch: reallocate update replies for mismatched IDs
      CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors
      CVE-2026-74673: Input: evdev - fix information leak in evdev_pass_values()
      CVE-2026-74675: vt: stabilize tty reference in kbd_keycode with tty_port_tty_get
      CVE-2026-74679: usb: gadget: f_ncm: Use unsigned int for ndp_index
      CVE-2026-74680: usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
      CVE-2026-74682: ALSA: usb-audio: fix OOB write on Type II inbound URBs
      CVE-2026-74683: Input: evdev - sanitize event type index when fetching event masks
      CVE-2026-74688: sctp: clear control chunk transport if it is being removed
      CVE-2026-74701: net/openvswitch: check Ethernet header length in key_extract()
      CVE-2026-74704: net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter
      CVE-2026-74705: udp: fix potential use-after-free in tunnel segmentation
      CVE-2026-74726: bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor
      CVE-2026-74730: NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
      CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter()
      CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete
      CVE-2026-52942: netfilter: nf_log: validate MAC header was set before dumping it
      CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
      CVE-2026-53392: NFSv4/flexfiles: reject zero filehandle version count
      CVE-2026-53399: nfsd: release layout stid on setlease failure
      CVE-2026-53400: i2c: core: fix adapter registration race
      CVE-2026-63803: hdlc_ppp: sync per-proto timers before freeing hdlc state
      CVE-2026-63806: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()
      CVE-2026-63818: f2fs: validate orphan inode entry count
      CVE-2026-63828: apparmor: mediate the implicit connect of TCP fast open sendmsg
      CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
      CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize
      CVE-2026-64266: fuse: re-lock request before returning from fuse_ref_folio()
      CVE-2026-64270: Input: mms114 - reject an oversized device packet size
      CVE-2026-64271: Input: touchwin - reset the packet index on every complete packet
      CVE-2026-64276: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
      CVE-2026-64280: fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
      CVE-2026-64298: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC
      CVE-2026-64299: tracing: Prevent out-of-bounds read in glob matching
      CVE-2026-64304: crypto: qat - validate RSA CRT component lengths
      CVE-2026-64306: crypto: drbg - Fix returning success on failure in CTR_DRBG
      CVE-2026-64312: crypto: pcrypt - restore callback for non-parallel fallback
      CVE-2026-64313: crypto: ecc - Fix carry overflow in vli multiplication
      CVE-2026-64317: isofs: bound Rock Ridge symlink components to the SL record
      CVE-2026-64318: partitions: aix: bound the pp_count scan to the ppe array
      CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count
      CVE-2026-64323: udf: validate VAT header length against the VAT inode size
      CVE-2026-64324: udf: validate free block extents against the partition length
      CVE-2026-64330: usb: typec: tcpm: Validate SVID index in svdm_consume_modes()
      CVE-2026-64331: usbip: vudc: fix NULL deref in vep_dequeue()
      CVE-2026-64332: USB: ulpi: fix memory leak on registration failure
      CVE-2026-64333: USB: serial: digi_acceleport: fix write buffer corruption
      CVE-2026-64334: USB: serial: digi_acceleport: fix hard lockup on disconnect
      CVE-2026-64335: USB: serial: digi_acceleport: fix broken rx after throttle
      CVE-2026-64337: usb: mtu3: unmap request DMA on queue failure
      CVE-2026-64338: USB: misc: uss720: unregister parport on probe failure
      CVE-2026-64342: USB: iowarrior: fix use-after-free on disconnect
      CVE-2026-64343: USB: ldusb: fix use-after-free on disconnect race
      CVE-2026-64345: usb: gadget: f_printer: take kref only for successful open
      CVE-2026-64347: usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler
      CVE-2026-64348: usb: free iso schedules on failed submit
      CVE-2026-64351: net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()
      CVE-2026-64359: nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers
      CVE-2026-64360: hfs/hfsplus: zero-initialize buffer in hfs_bnode_read
      CVE-2026-64361: hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length
      CVE-2026-64363: HID: appleir: fix UAF on pending key_up_timer in remove()
      CVE-2026-64370: posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path
      CVE-2026-64372: cpufreq: pcc: fix use-after-free and double free in _OSC evaluation
      CVE-2026-64373: cpufreq: Fix hotplug-suspend race during reboot
      CVE-2026-64374: sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT
      CVE-2026-64378: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs()
      CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard()
      CVE-2026-64403: Bluetooth: L2CAP: validate option length before reading conf opt value
      CVE-2026-64406: Bluetooth: fix UAF in bt_accept_dequeue()
      CVE-2026-64408: Bluetooth: bnep: pin L2CAP connection during netdev registration
      CVE-2026-64411: netfilter: ebtables: terminate table name before find_table_lock()
      CVE-2026-64412: netfilter: ebtables: module names must be null-terminated
      CVE-2026-64422: net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes
      CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction
      CVE-2026-64429: gpio: eic-sprd: use raw_spinlock_t in the irq startup path
      CVE-2026-64434: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
      CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states
      CVE-2026-64442: staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()
      CVE-2026-64448: smb: client: restrict implied bcc[0] exemption to responses without data area
      CVE-2026-64452: 6lowpan: fix NHC entry use-after-free on error path
      CVE-2026-64455: USB: chaoskey: Fix slab-use-after-free in chaoskey_release()
      CVE-2026-64465: usb: xhci: Fix sleep in atomic context in xhci_free_streams()
      CVE-2026-64468: binder: fix UAF in binder_free_transaction()
      CVE-2026-64469: binder: fix UAF in binder_thread_release()
      CVE-2026-64470: Bluetooth: btusb: fix use-after-free on marvell probe failure
      CVE-2026-64471: Bluetooth: btusb: fix use-after-free on registration failure
      CVE-2026-64478: ALSA: usb-audio: avoid kobject path lookup in DualSense match
      CVE-2026-64483: ALSA: firewire: isight: bound the sample count to the packet payload
      CVE-2026-64484: ALSA: es1938: check snd_ctl_new1() return value
      CVE-2026-64487: ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser
      CVE-2026-64488: ALSA: aoa: check snd_ctl_new1() return value
      CVE-2026-64495: iio: gyro: bmg160: bail out when bandwidth/filter is not in table
      CVE-2026-64496: iio: event: Fix event FIFO reset race
      CVE-2026-64500: iio: adc: lpc32xx: Initialize completion before requesting IRQ
      CVE-2026-64503: iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error
      CVE-2026-64504: iio: accel: bmc150: clamp the device-reported FIFO frame count
      CVE-2026-64505: usb: gadget: function: rndis: add length check for header
      CVE-2026-64510: ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup
      CVE-2026-64589: i2c: core: fix NULL-deref on adapter registration failure
      CVE-2026-64593: btrfs: do not trim a device which is not writeable
      CVE-2026-64594: usb: gadget: f_fs: initialize reset_work at allocation time
      CVE-2026-64602: iio: adc: spear: Initialize completion before requesting IRQ
      CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers()
      CVE-2026-68088: usb: gadget: function: rndis: add length check to response query
      CVE-2026-68091: HID: wacom: stop hardware after post-start probe failures
      CVE-2026-68132: super: fix emergency thaw deadlock on frozen block devices
      CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
      CVE-2026-68162: sctp: avoid auth_enable sysctl UAF during netns teardown
      CVE-2026-74479: net: pktgen: fix proc entry use-after-free
      CVE-2026-74601: ring-buffer: Use current_context for safe per-CPU buffer swap
      CVE-2026-74631: net: smc: fix splice entry lifetime imbalance in smc_rx_splice
      CVE-2026-74635: fbdev: bitblit: bound-check glyph index in bit_cursor()
      CVE-2026-74746: netfilter: flowtable: publish GC-visible tuple last
      CVE-2026-74748: netfilter: ipset: fix refcount race between list:set GC and swap
      CVE-2026-80528: ceph: avoid fs reclaim while using current->journal_info
      CVE-2026-80540: drm/amdgpu: Fix UVD decode image min size calculation
      CVE-2026-80541: drm/amdgpu: validate GEM_CREATE domain combinations
      CVE-2026-80558: libceph: Avoid using invalid osd indices from primary_temp
      CVE-2026-80561: libceph: fix multiple unsafe decodes in decode_locker()
      CVE-2026-80568: Input: synaptics-rmi4 - block s_input when F54 queue is busy
      CVE-2026-80574: Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet
      CVE-2026-80591: f2fs: fix listxattr handling of corrupted xattr entries
      CVE-2026-80593: hwmon: (asus_atk0110) Check package count before accessing element
      CVE-2026-80594: Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing
      CVE-2026-80595: Input: ims-pcu - add response length checks
      CVE-2026-80599: batman-adv: dat: ensure accessible eth_hdr proto field
      CVE-2026-80601: batman-adv: gw: acquire ethernet header only after skb realloc
      CVE-2026-80603: netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
      CVE-2026-80605: HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait()
      CVE-2026-80619: apparmor: fix potential UAF in aa_replace_profiles
      CVE-2026-80622: char: tlclk: fix use-after-free in tlclk_cleanup()
      CVE-2026-80626: powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del
      CVE-2026-80630: net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
      CVE-2026-80644: ocfs2: don't BUG_ON an invalid journal dinode
      CVE-2026-80645: rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc()
      CVE-2026-80646: ipv6: guard against possible NULL deref in __in6_dev_stats_get()
      CVE-2026-80659: mmc: vub300: defer reset until cmd_mutex is unlocked
      CVE-2026-80664: netfilter: xt_nat: reject unsupported target families
      CVE-2026-80681: vxlan: re-fetch eth header after route_shortcircuit()
      CVE-2026-80706: can: softing: fw_parse(): validate firmware record spans
      CVE-2026-80714: ipvs: do not propagate one-packet flag to synced conns
      CVE-2026-80717: sctp: validate Adaptation Indication parameter length
      CVE-2026-80718: mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()
      CVE-2026-80731: net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header
      CVE-2026-80732: ata: pata_sl82c105: fix bridge revision use-after-free
      CVE-2026-80733: net: remove WARN_ON_ONCE() from sk_mc_loop()
      CVE-2026-80752: Input: psxpad-spi - set driver data before use
      CVE-2026-80754: Input: synaptics-rmi4 - fix F55 transmitter electrode count typo
      CVE-2026-80757: selinux: reject a class permission count below its inherited common
      CVE-2026-80875: ipvs: use parsed transport offset in TCP state lookup
      CVE-2026-80876: ring-buffer: Fix event length with forced 8-byte alignment
      CVE-2026-80881: ocfs2: fix buffer head management in ocfs2_read_blocks()
      CVE-2026-80886: serial: msm: Disable DMA for kernel console UART
      CVE-2026-80890: sctp: reject stale cookies with mismatched verification tags
      CVE-2026-80908: drm/amdgpu: Reject UVD message with dimensions above 4096
      CVE-2026-80909: drm/amdgpu: Reject UVD message with invalid number of h265 refs

Best regards,
Ulrich Hecht


                 reply	other threads:[~2026-09-11 10:16 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1432043768.88457.1789121749469@webmail.strato.de \
    --to=uli@fpond.eu \
    --cc=chris.paterson2@renesas.com \
    --cc=cip-dev@lists.cip-project.org \
    --cc=jan.kiszka@siemens.com \
    --cc=masami.ichikawa@cybertrust.co.jp \
    --cc=nobuhiro.iwamatsu.x90@mail.toshiba \
    --cc=pavel@nabladev.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox