From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: stable@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
patches@lists.linux.dev,
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>,
Jakub Kicinski <kuba@kernel.org>, Sasha Levin <sashal@kernel.org>
Subject: [PATCH 6.12 199/215] net: qrtr: ns: Limit the maximum number of lookups
Date: Mon, 4 May 2026 15:53:38 +0200 [thread overview]
Message-ID: <20260504135137.857621888@linuxfoundation.org> (raw)
In-Reply-To: <20260504135130.169210693@linuxfoundation.org>
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit 5640227d9a21c6a8be249a10677b832e7f40dc55 ]
Current code does no bound checking on the number of lookups a client can
perform. Though the code restricts the lookups to local clients, there is
still a possibility of a malicious local client sending a flood of
NEW_LOOKUP messages over the same socket.
Fix this issue by limiting the maximum number of lookups to 64 globally.
Since the nameserver allows only atmost one local observer, this global
lookup count will ensure that the lookups stay within the limit.
Note that, limit of 64 is chosen based on the current platform
requirements. If requirement changes in the future, this limit can be
increased.
Cc: stable@vger.kernel.org
Fixes: 0c2204a4ad71 ("net: qrtr: Migrate nameservice to kernel from userspace")
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Link: https://patch.msgid.link/20260409-qrtr-fix-v3-2-00a8a5ff2b51@oss.qualcomm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[ adapted comment block to only mention QRTR_NS_MAX_LOOKUPS and kept kzalloc() instead of kzalloc_obj() due to missing prerequisite commits ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/qrtr/ns.c | 14 ++++++++++++++
1 file changed, 14 insertions(+)
--- a/net/qrtr/ns.c
+++ b/net/qrtr/ns.c
@@ -22,6 +22,7 @@ static struct {
struct socket *sock;
struct sockaddr_qrtr bcast_sq;
struct list_head lookups;
+ u32 lookup_count;
struct workqueue_struct *workqueue;
struct work_struct work;
void (*saved_data_ready)(struct sock *sk);
@@ -76,6 +77,11 @@ struct qrtr_node {
*/
#define QRTR_NS_MAX_SERVERS 256
+/* Max lookup limit is chosen based on the current platform requirements. If the
+ * requirement changes in the future, this value can be increased.
+ */
+#define QRTR_NS_MAX_LOOKUPS 64
+
static struct qrtr_node *node_get(unsigned int node_id)
{
struct qrtr_node *node;
@@ -444,6 +450,7 @@ static int ctrl_cmd_del_client(struct so
list_del(&lookup->li);
kfree(lookup);
+ qrtr_ns.lookup_count--;
}
/* Remove the server belonging to this port but don't broadcast
@@ -561,6 +568,11 @@ static int ctrl_cmd_new_lookup(struct so
if (from->sq_node != qrtr_ns.local_node)
return -EINVAL;
+ if (qrtr_ns.lookup_count >= QRTR_NS_MAX_LOOKUPS) {
+ pr_err_ratelimited("QRTR client node exceeds max lookup limit!\n");
+ return -ENOSPC;
+ }
+
lookup = kzalloc(sizeof(*lookup), GFP_KERNEL);
if (!lookup)
return -ENOMEM;
@@ -569,6 +581,7 @@ static int ctrl_cmd_new_lookup(struct so
lookup->service = service;
lookup->instance = instance;
list_add_tail(&lookup->li, &qrtr_ns.lookups);
+ qrtr_ns.lookup_count++;
memset(&filter, 0, sizeof(filter));
filter.service = service;
@@ -609,6 +622,7 @@ static void ctrl_cmd_del_lookup(struct s
list_del(&lookup->li);
kfree(lookup);
+ qrtr_ns.lookup_count--;
}
}
next prev parent reply other threads:[~2026-05-04 14:27 UTC|newest]
Thread overview: 226+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-05-04 13:50 [PATCH 6.12 000/215] 6.12.86-rc1 review Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 001/215] ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 002/215] ALSA: usb-audio: Avoid false E-MU sample-rate notifications Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 003/215] ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 004/215] usb: xhci: Make usb_host_endpoint.hcpriv survive endpoint_disable() Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 005/215] usb: chipidea: otg: not wait vbus drop if use role_switch Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 006/215] usb: chipidea: core: allow ci_irq_handler() handle both ID and VBUS change Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 007/215] ALSA: usb-audio: Evaluate packsize caps at the right place Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 008/215] LoongArch: Add spectre boundry for syscall dispatch table Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 009/215] drm/nouveau: fix u32 overflow in pushbuf reloc bounds check Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 010/215] leds: qcom-lpg: Check for array overflow when selecting the high resolution Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 011/215] greybus: gb-beagleplay: bound bootloader receive buffering Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 012/215] greybus: gb-beagleplay: fix sleep in atomic context in hdlc_tx_frames() Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 013/215] misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt() Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 014/215] ibmasm: fix OOB reads in command_file_write due to missing size checks Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 015/215] ibmasm: fix heap over-read in ibmasm_send_i2o_message() Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 016/215] driver core: Dont let a device probe until its ready Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 017/215] drm/nouveau: fix nvkm_device leak on aperture removal failure Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 018/215] kbuild: rust: allow `clippy::uninlined_format_args` Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 019/215] firmware: google: framebuffer: Do not mark framebuffer as busy Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 020/215] arm64/mm: Enable batched TLB flush in unmap_hotplug_range() Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 021/215] padata: Fix pd UAF once and for all Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 022/215] padata: Remove comment for reorder_work Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 023/215] rust: init: fix `clippy::undocumented_unsafe_blocks` warnings Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 024/215] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 025/215] drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 026/215] device property: Make modifications of fwnode "flags" thread safe Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 027/215] ocfs2: split transactions in dio completion to avoid credit exhaustion Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 028/215] zram: do not forget to endio for partial discard requests Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 029/215] wifi: rtw88: check for PCI upstream bridge existence Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 030/215] vfio/cdx: Serialize VFIO_DEVICE_SET_IRQS with a per-device mutex Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 031/215] vfio/cdx: Fix NULL pointer dereference in interrupt trigger path Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 032/215] um: drivers: call kernel_strrchr() explicitly in cow_user.c Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 033/215] spi: imx: fix use-after-free on unbind Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 034/215] spi: ch341: fix memory leaks on probe failures Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 035/215] mm/memory_hotplug: fix hwpoisoned large folio handling in do_migrate_range() Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 036/215] crypto: pcrypt - Fix handling of MAY_BACKLOG requests Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 037/215] of: unittest: fix use-after-free in of_unittest_changeset() Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 038/215] of: unittest: fix use-after-free in testdrv_probe() Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 039/215] hwmon: (powerz) Fix missing usb_kill_urb() on signal interrupt Greg Kroah-Hartman
2026-05-04 13:50 ` [PATCH 6.12 040/215] media: amphion: Fix race between m2m job_abort and device_run Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 041/215] ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names() Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 042/215] net: caif: clear client service pointer on teardown Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 043/215] net: strparser: fix skb_head leak in strp_abort_strp() Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 044/215] media: mtk-jpeg: fix use-after-free in release path due to uncancelled work Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 045/215] crypto: atmel-sha204a - Fix OTP sysfs read and error handling Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 046/215] PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 047/215] Revert "ALSA: usb: Increase volume range that triggers a warning" Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 048/215] PCI: epf-mhi: Return 0, not remaining timeout, when eDMA ops complete Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 049/215] lib/ts_kmp: fix integer overflow in pattern length calculation Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 050/215] media: i2c: imx219: Check return value of devm_gpiod_get_optional() in imx219_probe() Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 051/215] net: qrtr: ns: Fix use-after-free in driver remove() Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 052/215] ext2: reject inodes with zero i_nlink and valid mode in ext2_iget() Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 053/215] ALSA: aoa: i2sbus: fix OF node lifetime handling Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 054/215] ALSA: ctxfi: Add fallback to default RSR for S/PDIF Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 055/215] ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 056/215] erofs: fix the out-of-bounds nameoff handling for trailing dirents Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 057/215] jbd2: fix deadlock in jbd2_journal_cancel_revoke() Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 058/215] md/raid10: fix deadlock with check operation and nowait requests Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 059/215] mfd: stpmic1: Attempt system shutdown twice in case PMIC is confused Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 060/215] mtd: docg3: fix use-after-free in docg3_release() Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 061/215] nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 062/215] nvme: respect NVME_QUIRK_DISABLE_WRITE_ZEROES when wzsl is set Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 063/215] parisc: _llseek syscall is only available for 32-bit userspace Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 064/215] remoteproc: xlnx: Only access buffer information if IPI is buffered Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 065/215] sched: Use u64 for bandwidth ratio calculations Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 066/215] selftests/mqueue: Fix incorrectly named file Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 067/215] selftests/landlock: Fix format warning for __u64 in net_test Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 068/215] rbd: fix null-ptr-deref when device_add_disk() fails Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 069/215] block: fix zone write plugs refcount handling in disk_zone_wplug_schedule_bio_work() Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 070/215] io_uring/timeout: check unused sqe fields Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 071/215] iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 072/215] io_uring/poll: fix signed comparison in io_poll_get_ownership() Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 073/215] io_uring/poll: ensure EPOLL_ONESHOT is propagated for EPOLL_URING_WAKE Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 074/215] ALSA: core: Fix potential data race at fasync handling Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 075/215] ALSA: caiaq: Fix control_put() result and cache rollback Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 076/215] ALSA: caiaq: Handle probe errors properly Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 077/215] ALSA: 6fire: Fix input volume change detection Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 078/215] ALSA: pcmtest: fix reference leak on failed device registration Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 079/215] ALSA: pcmtest: Fix resource leaks in module init error paths Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 080/215] iio: adc: ad7768-1: fix one-shot mode data acquisition Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 081/215] rxrpc: Fix memory leaks in rxkad_verify_response() Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 082/215] rxrpc: Fix rxkad crypto unalignment handling Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 083/215] rxrpc: Fix re-decryption of RESPONSE packets Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 084/215] tools/accounting: handle truncated taskstats netlink messages Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 085/215] arm64: dts: marvell: uDPU: add ethernet aliases Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 086/215] net: qrtr: ns: Free the node during ctrl_cmd_bye() Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 087/215] net: rds: fix MR cleanup on copy error Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 088/215] net: txgbe: fix firmware version check Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 089/215] net/smc: avoid early lgr access in smc_clc_wait_msg Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 090/215] net: ks8851: Reinstate disabling of BHs around IRQ handler Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 091/215] netconsole: avoid out-of-bounds access on empty string in trim_newline() Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 092/215] net: ks8851: Avoid excess softirq scheduling Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 093/215] drm/arcpgu: fix device node leak Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 094/215] RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 095/215] ipv4: icmp: validate reply type before using icmp_pointers Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 096/215] libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 097/215] extract-cert: Wrap key_pass with #ifdef USE_PKCS11_ENGINE Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 098/215] tpm: avoid -Wunused-but-set-variable Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 099/215] LoongArch: Show CPU vulnerabilites correctly Greg Kroah-Hartman
2026-05-04 13:51 ` [PATCH 6.12 100/215] power: supply: axp288_charger: Do not cancel work before initializing it Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 101/215] hwmon: (pt5161l) Fix bugs in pt5161l_read_block_data() Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 102/215] randomize_kstack: Maintain kstack_offset per task Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 103/215] mmc: block: use single block write in retry Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 104/215] mmc: sdhci-of-dwcmshc: Disable clock before DLL configuration Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 105/215] arm64: dts: ti: am62-verdin: Enable pullup for eMMC data pins Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 106/215] xfs: fix a resource leak in xfs_alloc_buftarg() Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 107/215] firmware: google: framebuffer: Do not unregister platform device Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 108/215] crypto: talitos - fix SEC1 32k ahash request limitation Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 109/215] crypto: talitos - rename first/last to first_desc/last_desc Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 110/215] pwm: imx-tpm: Count the number of enabled channels in probe Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 111/215] tpm: Fix auth session leak in tpm2_get_random() error path Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 112/215] tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 113/215] tpm: tpm_tis: add error logging for data transfer Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 114/215] tpm: tpm_tis: stop transmit if retries are exhausted Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 115/215] rtc: ntxec: fix OF node reference imbalance Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 116/215] mm/damon/core: use time_in_range_open() for damos quota window start Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 117/215] userfaultfd: allow registration of ranges below mmap_min_addr Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 118/215] KVM: x86: Defer non-architectural deliver of exception payload to userspace read Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 119/215] KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 120/215] KVM: nSVM: Sync NextRIP to cached vmcb12 after VMRUN of L2 Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 121/215] KVM: nSVM: Sync interrupt shadow " Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 122/215] KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 123/215] KVM: SVM: Explicitly mark vmcb01 dirty after modifying VMCB intercepts Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 124/215] KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 125/215] KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested #VMEXIT Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 126/215] KVM: nSVM: Always inject a #GP if mapping VMCB12 fails on nested VMRUN Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 127/215] KVM: nSVM: Clear GIF on nested #VMEXIT(INVALID) Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 128/215] KVM: nSVM: Clear EVENTINJ fields in vmcb12 on nested #VMEXIT Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 129/215] KVM: nSVM: Clear tracking of L1->L2 NMI and soft IRQ " Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 130/215] KVM: nSVM: Add missing consistency check for EFER, CR0, CR4, and CS Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 131/215] KVM: nSVM: Add missing consistency check for nCR3 validity Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 132/215] KVM: nSVM: Raise #UD if unhandled VMMCALL isnt intercepted by L1 Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 133/215] KVM: nSVM: Always intercept VMMCALL when L2 is active Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 134/215] io_uring/poll: fix multishot recv missing EOF on wakeup race Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 135/215] perf annotate: Use jump__delete when freeing LoongArch jumps Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 136/215] ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 137/215] ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 138/215] mtd: spi-nor: sst: Fix write enable before AAI sequence Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 139/215] amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 140/215] md/raid5: fix soft lockup in retry_aligned_read() Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 141/215] md/raid5: validate payload size before accessing journal metadata Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 142/215] check-uapi: link into shared objects Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 143/215] HID: apple: ensure the keyboard backlight is off if suspending Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 144/215] inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 145/215] x86/cpu: Disable FRED when PTI is forced on Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 146/215] wifi: rtl8xxxu: fix potential use of uninitialized value Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 147/215] tcp: call sk_data_ready() after listener migration Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 148/215] taskstats: set version in TGID exit notifications Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 149/215] mfd: core: Preserve OF node when ACPI handle is present Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 150/215] apparmor: use target tasks context in apparmor_getprocattr() Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 151/215] Bluetooth: hci_event: fix potential UAF in SSP passkey handlers Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 152/215] bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 153/215] can: ucan: fix devres lifetime Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 154/215] crypto: arm64/aes - Fix 32-bit aes_mac_update() arg treated as 64-bit Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 155/215] crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 156/215] crypto: atmel-ecc - Release client on allocation failure Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 157/215] crypto: hisilicon - Fix dma_unmap_single() direction Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 158/215] crypto: ccree - fix a memory leak in cc_mac_digest() Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 159/215] crypto: atmel-tdes - fix DMA sync direction Greg Kroah-Hartman
2026-05-04 13:52 ` [PATCH 6.12 160/215] crypto: atmel-sha204a - Fix error codes in OTP reads Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 161/215] crypto: atmel-sha204a - Fix potential UAF and memory leak in remove path Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 162/215] crypto: atmel-sha204a - Fix uninitialized data access on OTP read error Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 163/215] crypto: nx - Fix packed layout in struct nx842_crypto_header Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 164/215] dm mirror: fix integer overflow in create_dirty_log() Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 165/215] ceph: only d_add() negative dentries when they are unhashed Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 166/215] IB/core: Fix zero dmac race in neighbor resolution Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 167/215] ktest: Fix the month in the name of the failure directory Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 168/215] ntfs3: add buffer boundary checks to run_unpack() Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 169/215] ntfs3: fix integer overflow in run_unpack() volume boundary check Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 170/215] rtmutex: Use waiter::task instead of current in remove_waiter() Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 171/215] scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 172/215] seg6: fix seg6 lwtunnel output redirect for L2 reduced encap mode Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 173/215] smb: client: validate the whole DACL before rewriting it in cifsacl Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 174/215] f2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io() Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 175/215] lib: test_hmm: evict device pages on file close to avoid use-after-free Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 176/215] f2fs: fix to do sanity check on dcc->discard_cmd_cnt conditionally Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 177/215] ksmbd: use msleep instaed of schedule_timeout_interruptible() Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 178/215] ksmbd: replace connection list with hash table Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 179/215] ksmbd: reset rcount per connection in ksmbd_conn_wait_idle_sess_id() Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 180/215] thermal: core: Fix thermal zone governor cleanup issues Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 181/215] wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 182/215] wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 183/215] wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 184/215] mm/migrate: factor out movable_ops page handling into migrate_movable_ops_page() Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 185/215] mm/migrate: move movable_ops page handling out of move_to_new_folio() Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 186/215] mm: migrate: requeue destination folio on deferred split queue Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 187/215] ALSA: aoa: Use guard() for mutex locks Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 188/215] ALSA: aoa: i2sbus: clear stale prepared state Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 189/215] mm/zsmalloc: copy KMSAN metadata in zs_page_migrate() Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 190/215] media: rc: ttusbir: respect DMA coherency rules Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 191/215] ALSA: aoa: Skip devices with no codecs in i2sbus_resume() Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 192/215] media: rc: igorplugusb: heed coherency rules Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 193/215] RDMA/mana_ib: Disable RX steering on RSS QP destroy Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 194/215] block: relax pgmap check in bio_add_page for compatible zone device pages Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 195/215] iio: frequency: admv1013: add dev variable Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 196/215] iio: frequency: admv1013: fix NULL pointer dereference on str Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 197/215] rxrpc: Fix potential UAF after skb_unshare() failure Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 198/215] net: qrtr: ns: Limit the maximum server registration per node Greg Kroah-Hartman
2026-05-04 13:53 ` Greg Kroah-Hartman [this message]
2026-05-04 13:53 ` [PATCH 6.12 200/215] net: bridge: use a stable FDB dst snapshot in RCU readers Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 201/215] net: mctp: fix dont require received header reserved bits to be zero Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 202/215] net: qrtr: ns: Limit the total number of nodes Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 203/215] spi: fix resource leaks on device setup failure Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 204/215] mm: prevent droppable mappings from being locked Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 205/215] crypto: authencesn - reject short ahash digests during instance creation Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 206/215] net: bonding: fix use-after-free in bond_xmit_broadcast() Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 207/215] driver core: Add kernel-doc for DEV_FLAG_COUNT enum value Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 208/215] ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 209/215] ALSA: caiaq: Dont abort when no input device is available Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 210/215] rxrpc: Fix rxrpc_input_call_event() to only unshare DATA packets Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 211/215] ipv6: rpl: reserve mac_len headroom when recompressed SRH grows Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 212/215] drm/amdgpu: fix zero-size GDS range init on RDNA4 Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 213/215] ALSA: caiaq: fix usb_dev refcount leak on probe failure Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 214/215] net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels Greg Kroah-Hartman
2026-05-04 13:53 ` [PATCH 6.12 215/215] netfilter: reject zero shift in nft_bitwise Greg Kroah-Hartman
2026-05-04 15:16 ` [PATCH 6.12 000/215] 6.12.86-rc1 review Brett A C Sheffield
2026-05-04 16:17 ` Peter Schneider
2026-05-04 18:02 ` Florian Fainelli
2026-05-05 4:55 ` Francesco Dolcini
2026-05-05 8:11 ` Ron Economos
2026-05-05 9:31 ` Miguel Ojeda
2026-05-05 12:33 ` Mark Brown
2026-05-05 15:55 ` Shuah Khan
2026-05-06 1:57 ` Barry K. Nathan
2026-05-07 12:04 ` Harshit Mogalapalli
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260504135137.857621888@linuxfoundation.org \
--to=gregkh@linuxfoundation.org \
--cc=kuba@kernel.org \
--cc=manivannan.sadhasivam@oss.qualcomm.com \
--cc=patches@lists.linux.dev \
--cc=sashal@kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox