* Please consider these upstream CVE fixes for 6.6.y
@ 2026-08-30 8:27 Artem Dinaburg
2026-08-31 1:39 ` Sasha Levin
2026-09-01 1:21 ` Sasha Levin
0 siblings, 2 replies; 3+ messages in thread
From: Artem Dinaburg @ 2026-08-30 8:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, Sasha Levin
Hi Greg and Sasha,
Thanks for carrying the earlier 6.1.y fixes into the newer trees. After
dropping them, these four mainline fixes remain absent from 6.6.y and its
current stable queue. Linux CNA records mark v6.6.155 affected for each
CVE. Every newer tree has the first three fixes. The last remains absent
from 6.12.y and 6.18.y.
I applied the current 6.6.y queue to v6.6.155, then cherry-picked this set
without changes. The x86_64 allmodconfig kernel and modules built without
warnings with WERROR enabled. The PowerPC target compiled cleanly after I
enabled the related config options. I did not runtime-test these fixes.
Could you please queue these commits for 6.6.y?
0f022d32c3eca477fbf79a205243a6123ed0fe11 (CVE-2024-27010)
net/sched: Fix mirred deadlock on device recursion
d7f01649f4eaf1878472d3d3f480ae1e50d98f6c (CVE-2024-39478)
crypto: starfive - Do not free stack buffer
d48e1dea3931de64c26717adc2b89743c7ab6594 (CVE-2024-50225)
btrfs: fix error propagation of split bios
dbc30a57bd8e026995e9fa8e8c31cffd18542c01 (CVE-2026-64070)
powerpc/hv-gpci: fix preempt count leak in sysfs show paths
I used Codex to compare the histories and run the builds. I checked the
final list against vulns.git, the branch history, and stable-queue.
Assisted-by: Codex:GPT-5.6
Thanks,
Artem Dinaburg
Trail of Bits
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: Please consider these upstream CVE fixes for 6.6.y
2026-08-30 8:27 Please consider these upstream CVE fixes for 6.6.y Artem Dinaburg
@ 2026-08-31 1:39 ` Sasha Levin
2026-09-01 1:21 ` Sasha Levin
1 sibling, 0 replies; 3+ messages in thread
From: Sasha Levin @ 2026-08-31 1:39 UTC (permalink / raw)
To: stable; +Cc: Sasha Levin, Greg Kroah-Hartman, Artem Dinaburg
> Thanks for carrying the earlier 6.1.y fixes into the newer trees. After
> dropping them, these four mainline fixes remain absent from 6.6.y and its
> current stable queue. Linux CNA records mark v6.6.155 affected for each
> CVE. Every newer tree has the first three fixes. The last remains absent
> from 6.12.y and 6.18.y.
Queued the mirred deadlock fix and its noop_qdisc owner follow-up plus
the starfive fix for 6.6.y, and the hv-gpci fix for 6.18.y, 6.12.y and
6.6.y. Thanks.
Dropped the btrfs one - it doesn't build on 6.6 riscv, 1-byte cmpxchg
isn't supported there.
--
Thanks,
Sasha
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: Please consider these upstream CVE fixes for 6.6.y
2026-08-30 8:27 Please consider these upstream CVE fixes for 6.6.y Artem Dinaburg
2026-08-31 1:39 ` Sasha Levin
@ 2026-09-01 1:21 ` Sasha Levin
1 sibling, 0 replies; 3+ messages in thread
From: Sasha Levin @ 2026-09-01 1:21 UTC (permalink / raw)
To: stable; +Cc: Sasha Levin, Greg Kroah-Hartman, Artem Dinaburg
> I applied the current 6.6.y queue to v6.6.155, then cherry-picked this set
> without changes. The x86_64 allmodconfig kernel and modules built without
> warnings with WERROR enabled.
>
> Could you please queue these commits for 6.6.y?
>
> 0f022d32c3eca477fbf79a205243a6123ed0fe11 (CVE-2024-27010)
> net/sched: Fix mirred deadlock on device recursion
> d7f01649f4eaf1878472d3d3f480ae1e50d98f6c (CVE-2024-39478)
> crypto: starfive - Do not free stack buffer
> d48e1dea3931de64c26717adc2b89743c7ab6594 (CVE-2024-50225)
> btrfs: fix error propagation of split bios
> dbc30a57bd8e026995e9fa8e8c31cffd18542c01 (CVE-2026-64070)
> powerpc/hv-gpci: fix preempt count leak in sysfs show paths
Queued the mirred deadlock fix and its noop_qdisc owner follow-up, the
starfive fix, and the hv-gpci fix for 6.6.y (the hv-gpci fix also went
to 6.18.y and 6.12.y). Dropped the btrfs one as it doesn't build on 6.6
riscv.
--
Thanks,
Sasha
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-01 1:22 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-30 8:27 Please consider these upstream CVE fixes for 6.6.y Artem Dinaburg
2026-08-31 1:39 ` Sasha Levin
2026-09-01 1:21 ` Sasha Levin
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).