Archive-only list for patches
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: stable@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	patches@lists.linux.dev, Eric Dumazet <edumazet@google.com>,
	Wang Liang <wangliang74@huawei.com>,
	Jakub Kicinski <kuba@kernel.org>, Alva Lan <alvalan9@foxmail.com>
Subject: [PATCH 5.10 114/133] net: fix data-races around sk->sk_forward_alloc
Date: Thu, 30 Jan 2025 15:01:43 +0100	[thread overview]
Message-ID: <20250130140147.122651459@linuxfoundation.org> (raw)
In-Reply-To: <20250130140142.491490528@linuxfoundation.org>

5.10-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wang Liang <wangliang74@huawei.com>

commit 073d89808c065ac4c672c0a613a71b27a80691cb upstream.

Syzkaller reported this warning:
 ------------[ cut here ]------------
 WARNING: CPU: 0 PID: 16 at net/ipv4/af_inet.c:156 inet_sock_destruct+0x1c5/0x1e0
 Modules linked in:
 CPU: 0 UID: 0 PID: 16 Comm: ksoftirqd/0 Not tainted 6.12.0-rc5 #26
 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
 RIP: 0010:inet_sock_destruct+0x1c5/0x1e0
 Code: 24 12 4c 89 e2 5b 48 c7 c7 98 ec bb 82 41 5c e9 d1 18 17 ff 4c 89 e6 5b 48 c7 c7 d0 ec bb 82 41 5c e9 bf 18 17 ff 0f 0b eb 83 <0f> 0b eb 97 0f 0b eb 87 0f 0b e9 68 ff ff ff 66 66 2e 0f 1f 84 00
 RSP: 0018:ffffc9000008bd90 EFLAGS: 00010206
 RAX: 0000000000000300 RBX: ffff88810b172a90 RCX: 0000000000000007
 RDX: 0000000000000002 RSI: 0000000000000300 RDI: ffff88810b172a00
 RBP: ffff88810b172a00 R08: ffff888104273c00 R09: 0000000000100007
 R10: 0000000000020000 R11: 0000000000000006 R12: ffff88810b172a00
 R13: 0000000000000004 R14: 0000000000000000 R15: ffff888237c31f78
 FS:  0000000000000000(0000) GS:ffff888237c00000(0000) knlGS:0000000000000000
 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
 CR2: 00007ffc63fecac8 CR3: 000000000342e000 CR4: 00000000000006f0
 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
 Call Trace:
  <TASK>
  ? __warn+0x88/0x130
  ? inet_sock_destruct+0x1c5/0x1e0
  ? report_bug+0x18e/0x1a0
  ? handle_bug+0x53/0x90
  ? exc_invalid_op+0x18/0x70
  ? asm_exc_invalid_op+0x1a/0x20
  ? inet_sock_destruct+0x1c5/0x1e0
  __sk_destruct+0x2a/0x200
  rcu_do_batch+0x1aa/0x530
  ? rcu_do_batch+0x13b/0x530
  rcu_core+0x159/0x2f0
  handle_softirqs+0xd3/0x2b0
  ? __pfx_smpboot_thread_fn+0x10/0x10
  run_ksoftirqd+0x25/0x30
  smpboot_thread_fn+0xdd/0x1d0
  kthread+0xd3/0x100
  ? __pfx_kthread+0x10/0x10
  ret_from_fork+0x34/0x50
  ? __pfx_kthread+0x10/0x10
  ret_from_fork_asm+0x1a/0x30
  </TASK>
 ---[ end trace 0000000000000000 ]---

Its possible that two threads call tcp_v6_do_rcv()/sk_forward_alloc_add()
concurrently when sk->sk_state == TCP_LISTEN with sk->sk_lock unlocked,
which triggers a data-race around sk->sk_forward_alloc:
tcp_v6_rcv
    tcp_v6_do_rcv
        skb_clone_and_charge_r
            sk_rmem_schedule
                __sk_mem_schedule
                    sk_forward_alloc_add()
            skb_set_owner_r
                sk_mem_charge
                    sk_forward_alloc_add()
        __kfree_skb
            skb_release_all
                skb_release_head_state
                    sock_rfree
                        sk_mem_uncharge
                            sk_forward_alloc_add()
                            sk_mem_reclaim
                                // set local var reclaimable
                                __sk_mem_reclaim
                                    sk_forward_alloc_add()

In this syzkaller testcase, two threads call
tcp_v6_do_rcv() with skb->truesize=768, the sk_forward_alloc changes like
this:
 (cpu 1)             | (cpu 2)             | sk_forward_alloc
 ...                 | ...                 | 0
 __sk_mem_schedule() |                     | +4096 = 4096
                     | __sk_mem_schedule() | +4096 = 8192
 sk_mem_charge()     |                     | -768  = 7424
                     | sk_mem_charge()     | -768  = 6656
 ...                 |    ...              |
 sk_mem_uncharge()   |                     | +768  = 7424
 reclaimable=7424    |                     |
                     | sk_mem_uncharge()   | +768  = 8192
                     | reclaimable=8192    |
 __sk_mem_reclaim()  |                     | -4096 = 4096
                     | __sk_mem_reclaim()  | -8192 = -4096 != 0

The skb_clone_and_charge_r() should not be called in tcp_v6_do_rcv() when
sk->sk_state is TCP_LISTEN, it happens later in tcp_v6_syn_recv_sock().
Fix the same issue in dccp_v6_do_rcv().

Suggested-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Fixes: e994b2f0fb92 ("tcp: do not lock listener to process SYN packets")
Signed-off-by: Wang Liang <wangliang74@huawei.com>
Link: https://patch.msgid.link/20241107023405.889239-1-wangliang74@huawei.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Alva Lan <alvalan9@foxmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/dccp/ipv6.c     |    2 +-
 net/ipv6/tcp_ipv6.c |    4 +---
 2 files changed, 2 insertions(+), 4 deletions(-)

--- a/net/dccp/ipv6.c
+++ b/net/dccp/ipv6.c
@@ -602,7 +602,7 @@ static int dccp_v6_do_rcv(struct sock *s
 	   by tcp. Feel free to propose better solution.
 					       --ANK (980728)
 	 */
-	if (np->rxopt.all)
+	if (np->rxopt.all && sk->sk_state != DCCP_LISTEN)
 		opt_skb = skb_clone_and_charge_r(skb, sk);
 
 	if (sk->sk_state == DCCP_OPEN) { /* Fast path */
--- a/net/ipv6/tcp_ipv6.c
+++ b/net/ipv6/tcp_ipv6.c
@@ -1484,7 +1484,7 @@ static int tcp_v6_do_rcv(struct sock *sk
 	   by tcp. Feel free to propose better solution.
 					       --ANK (980728)
 	 */
-	if (np->rxopt.all)
+	if (np->rxopt.all && sk->sk_state != TCP_LISTEN)
 		opt_skb = skb_clone_and_charge_r(skb, sk);
 
 	if (sk->sk_state == TCP_ESTABLISHED) { /* Fast path */
@@ -1521,8 +1521,6 @@ static int tcp_v6_do_rcv(struct sock *sk
 		if (nsk != sk) {
 			if (tcp_child_process(sk, nsk, skb))
 				goto reset;
-			if (opt_skb)
-				__kfree_skb(opt_skb);
 			return 0;
 		}
 	} else



  parent reply	other threads:[~2025-01-30 14:26 UTC|newest]

Thread overview: 143+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-01-30 13:59 [PATCH 5.10 000/133] 5.10.234-rc1 review Greg Kroah-Hartman
2025-01-30 13:59 ` [PATCH 5.10 001/133] ceph: give up on paths longer than PATH_MAX Greg Kroah-Hartman
2025-01-30 13:59 ` [PATCH 5.10 002/133] jbd2: flush filesystem device before updating tail sequence Greg Kroah-Hartman
2025-01-30 13:59 ` [PATCH 5.10 003/133] dm array: fix releasing a faulty array block twice in dm_array_cursor_end Greg Kroah-Hartman
2025-01-30 13:59 ` [PATCH 5.10 004/133] dm array: fix unreleased btree blocks on closing a faulty array cursor Greg Kroah-Hartman
2025-01-30 13:59 ` [PATCH 5.10 005/133] dm array: fix cursor index when skipping across block boundaries Greg Kroah-Hartman
2025-01-30 13:59 ` [PATCH 5.10 006/133] exfat: fix the infinite loop in exfat_readdir() Greg Kroah-Hartman
2025-01-30 13:59 ` [PATCH 5.10 007/133] ASoC: mediatek: disable buffer pre-allocation Greg Kroah-Hartman
2025-01-30 13:59 ` [PATCH 5.10 008/133] netfilter: nft_dynset: honor stateful expressions in set definition Greg Kroah-Hartman
2025-01-30 13:59 ` [PATCH 5.10 009/133] ieee802154: ca8210: Add missing check for kfifo_alloc() in ca8210_probe() Greg Kroah-Hartman
2025-01-30 13:59 ` [PATCH 5.10 010/133] net: 802: LLC+SNAP OID:PID lookup on start of skb data Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 011/133] tcp/dccp: complete lockless accesses to sk->sk_max_ack_backlog Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 012/133] tcp/dccp: allow a connection when sk_max_ack_backlog is zero Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 013/133] net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 014/133] cxgb4: Avoid removal of uninserted tid Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 015/133] tls: Fix tls_sw_sendmsg error handling Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 016/133] netfilter: nf_tables: imbalance in flowtable binding Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 017/133] netfilter: conntrack: clamp maximum hashtable size to INT_MAX Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 018/133] afs: Fix the maximum cell name length Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 019/133] dm thin: make get_first_thin use rcu-safe list first function Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 020/133] dm-ebs: dont set the flag DM_TARGET_PASSES_INTEGRITY Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 021/133] sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 022/133] sctp: sysctl: auth_enable: " Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 023/133] drm/amd/display: Add check for granularity in dml ceil/floor helpers Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 024/133] riscv: Fix sleeping in invalid context in die() Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 025/133] ACPI: resource: Add TongFang GM5HG0A to irq1_edge_low_force_override[] Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 026/133] ACPI: resource: Add Asus Vivobook X1504VAP to irq1_level_low_skip_override[] Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 027/133] drm/amd/display: increase MAX_SURFACES to the value supported by hw Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 028/133] scripts/sorttable: fix orc_sort_cmp() to maintain symmetry and transitivity Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 029/133] md/raid5: fix atomicity violation in raid5_cache_count Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 030/133] USB: serial: option: add MeiG Smart SRM815 Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 031/133] USB: serial: option: add Neoway N723-EA support Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 032/133] staging: iio: ad9834: Correct phase range check Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 033/133] staging: iio: ad9832: " Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 034/133] usb-storage: Add max sectors quirk for Nokia 208 Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 035/133] USB: serial: cp210x: add Phoenix Contact UPS Device Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 036/133] usb: dwc3: gadget: fix writing NYET threshold Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 037/133] usb: gadget: u_serial: Disable ep before setting port to null to fix the crash caused by port being null Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 038/133] USB: usblp: return error when setting unsupported protocol Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 039/133] USB: core: Disable LPM only for non-suspended ports Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 040/133] usb: fix reference leak in usb_new_device() Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 041/133] usb: gadget: f_fs: Remove WARN_ON in functionfs_bind Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 042/133] iio: pressure: zpa2326: fix information leak in triggered buffer Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 043/133] iio: dummy: iio_simply_dummy_buffer: " Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 044/133] iio: light: vcnl4035: " Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 045/133] iio: imu: kmx61: " Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 046/133] iio: adc: ti-ads8688: " Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 047/133] iio: gyro: fxas21002c: Fix missing data update in trigger handler Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 048/133] iio: adc: ti-ads124s08: Use gpiod_set_value_cansleep() Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 049/133] iio: adc: at91: call input_free_device() on allocated iio_dev Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 050/133] iio: inkern: call iio_device_put() only on mapped devices Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 051/133] arm64: dts: rockchip: add #power-domain-cells to power domain nodes Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 052/133] arm64: dts: rockchip: add hevc power domain clock to rk3328 Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 053/133] loop: let set_capacity_revalidate_and_notify update the bdev size Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 054/133] nvme: " Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 055/133] sd: update the bdev size in sd_revalidate_disk Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 056/133] block: remove the update_bdev parameter to set_capacity_revalidate_and_notify Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 057/133] phy: usb: Add "wake on" functionality for newer Synopsis XHCI controllers Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 058/133] phy: usb: Toggle the PHY power during init Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 059/133] ocfs2: correct return value of ocfs2_local_free_info() Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 060/133] ocfs2: fix slab-use-after-free due to dangling pointer dqi_priv Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 061/133] drm: bridge: adv7511: Remove redundant null check before clk_disable_unprepare Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 062/133] drm/mipi-dsi: Create devm device registration Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 063/133] drm/mipi-dsi: Create devm device attachment Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 064/133] drm/bridge: adv7533: Switch to devm MIPI-DSI helpers Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 065/133] drm: bridge: adv7511: unregister cec i2c device after cec adapter Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 066/133] drm: bridge: adv7511: use dev_err_probe in probe function Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 067/133] drm: adv7511: Fix use-after-free in adv7533_attach_dsi() Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 068/133] sctp: sysctl: rto_min/max: avoid using current->nsproxy Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 069/133] phy: usb: Use slow clock for wake enabled suspend Greg Kroah-Hartman
2025-01-30 14:00 ` [PATCH 5.10 070/133] phy: usb: Fix clock imbalance for suspend/resume Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 071/133] net: ethernet: ti: cpsw_ale: Fix cpsw_ale_get_field() Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 072/133] bpf: Fix bpf_sk_select_reuseport() memory leak Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 073/133] net: net_namespace: Optimize the code Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 074/133] net: add exit_batch_rtnl() method Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 075/133] gtp: use " Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 076/133] gtp: Use for_each_netdev_rcu() in gtp_genl_dump_pdp() Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 077/133] gtp: Destroy device along with udp sockets netns dismantle Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 078/133] nfp: bpf: prevent integer overflow in nfp_bpf_event_output() Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 079/133] net/mlx5: Add priorities for counters in RDMA namespaces Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 080/133] net/mlx5: Refactor mlx5_get_flow_namespace Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 081/133] net/mlx5: Fix RDMA TX steering prio Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 082/133] drm/v3d: Ensure job pointer is set to NULL after job completion Greg Kroah-Hartman
2025-01-30 15:56   ` Maíra Canal
2025-01-30 16:26     ` Greg Kroah-Hartman
2025-01-30 16:45       ` Maíra Canal
2025-01-30 17:05         ` Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 083/133] i2c: mux: demux-pinctrl: check initial mux selection, too Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 084/133] i2c: rcar: fix NACK handling when being a target Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 085/133] mac802154: check local interfaces before deleting sdata list Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 086/133] hfs: Sanity check the root record Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 087/133] fs: fix missing declaration of init_files Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 088/133] kheaders: Ignore silly-rename files Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 089/133] poll_wait: add mb() to fix theoretical race between waitqueue_active() and .poll() Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 090/133] nvmet: propagate npwg topology Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 091/133] x86/asm: Make serialize() always_inline Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 092/133] net: ethernet: xgbe: re-add aneg to supported features in PHY quirks Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 093/133] vsock/virtio: cancel close work in the destructor Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 094/133] vsock: reset socket state when de-assigning the transport Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 095/133] fs/proc: fix softlockup in __read_vmcore (part 2) Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 096/133] gpiolib: cdev: Fix use after free in lineinfo_changed_notify Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 097/133] irqchip/gic-v3: Handle CPU_PM_ENTER_FAILED correctly Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 098/133] hrtimers: Handle CPU state correctly on hotplug Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 099/133] Revert "PCI: Use preserve_config in place of pci_flags" Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 100/133] iio: imu: inv_icm42600: fix spi burst write not supported Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 101/133] iio: imu: inv_icm42600: fix timestamps after suspend if sensor is on Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 102/133] iio: adc: rockchip_saradc: fix information leak in triggered buffer Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 103/133] drm/radeon: check bo_va->bo is non-NULL before using it Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 104/133] vmalloc: fix accounting with i915 Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 105/133] RDMA/hns: Fix deadlock on SRQ async events Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 106/133] blk-cgroup: Fix UAF in blkcg_unpin_online() Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 107/133] ipv6: avoid possible NULL deref in rt6_uncached_list_flush_dev() Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 108/133] nfsd: add list_head nf_gc to struct nfsd_file Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 109/133] fou: remove warn in gue_gro_receive on unsupported protocol Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 110/133] vsock/virtio: discard packets if the transport changes Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 111/133] vsock: prevent null-ptr-deref in vsock_*[has_data|has_space] Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 112/133] x86/xen: fix SLS mitigation in xen_hypercall_iret() Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 113/133] scsi: sg: Fix slab-use-after-free read in sg_release() Greg Kroah-Hartman
2025-01-30 14:01 ` Greg Kroah-Hartman [this message]
2025-01-30 14:01 ` [PATCH 5.10 115/133] ASoC: wm8994: Add depends on MFD core Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 116/133] ASoC: samsung: Add missing selects for MFD_WM8994 Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 117/133] seccomp: Stub for !CONFIG_SECCOMP Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 118/133] scsi: iscsi: Fix redundant response for ISCSI_UEVENT_GET_HOST_STATS request Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 119/133] irqchip/sunxi-nmi: Add missing SKIP_WAKE flag Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 120/133] ASoC: samsung: Add missing depends on I2C Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 121/133] gfs2: Truncate address space when flipping GFS2_DIF_JDATA flag Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 122/133] net: sched: fix ets qdisc OOB Indexing Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 123/133] m68k: Update ->thread.esp0 before calling syscall_trace() in ret_from_signal Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 124/133] signal/m68k: Use force_sigsegv(SIGSEGV) in fpsp040_die Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 125/133] vfio/platform: check the bounds of read/write syscalls Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 126/133] Bluetooth: RFCOMM: Fix not validating setsockopt user input Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 127/133] ipv4: ip_tunnel: Fix suspicious RCU usage warning in ip_tunnel_find() Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 128/133] wifi: iwlwifi: add a few rate index validity checks Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 129/133] USB: serial: quatech2: fix null-ptr-deref in qt2_process_read_urb() Greg Kroah-Hartman
2025-01-30 14:01 ` [PATCH 5.10 130/133] Revert "usb: gadget: u_serial: Disable ep before setting port to null to fix the crash caused by port being null" Greg Kroah-Hartman
2025-01-30 14:02 ` [PATCH 5.10 131/133] Input: atkbd - map F23 key to support default copilot shortcut Greg Kroah-Hartman
2025-01-30 14:02 ` [PATCH 5.10 132/133] Input: xpad - add unofficial Xbox 360 wireless receiver clone Greg Kroah-Hartman
2025-01-30 14:02 ` [PATCH 5.10 133/133] Input: xpad - add support for wooting two he (arm) Greg Kroah-Hartman
2025-01-30 18:48 ` [PATCH 5.10 000/133] 5.10.234-rc1 review Mark Brown
2025-01-30 19:42 ` Naresh Kamboju
2025-01-30 20:50 ` Florian Fainelli
2025-01-30 22:19 ` Pavel Machek
2025-01-31  5:38 ` Jon Hunter

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250130140147.122651459@linuxfoundation.org \
    --to=gregkh@linuxfoundation.org \
    --cc=alvalan9@foxmail.com \
    --cc=edumazet@google.com \
    --cc=kuba@kernel.org \
    --cc=patches@lists.linux.dev \
    --cc=stable@vger.kernel.org \
    --cc=wangliang74@huawei.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox