Skip to content

[rocky9_8] History Rebuild through kernel-5.14.0-687.47.1.el9_8 - #1609

Open
PlaidCat wants to merge 75 commits into
rocky9_8from
rocky9_8_rebuild
Open

PlaidCat wants to merge 75 commits into
rocky9_8from
rocky9_8_rebuild

Conversation

@PlaidCat

@PlaidCat PlaidCat commented Sep 15, 2026

Copy link
Copy Markdown
Collaborator

This is an automated kernel history rebuild using cron and internal tooling. It follows the same process used for previous history rebuilds:

  • Download all unprocessed src.rpm packages
  • For each src.rpm:
    • Identify all commits in the changelog up to the last known tag (5.14.0-687)
    • Replay commits in chronological order (oldest to newest in the changelog) using git cherry-pick
    • Replace the code in the branch with the output of rpmbuild -bp for the corresponding src.rpm
    • Tag the rebuild branch

JIRA Tickets

Rebuild Splat Inspection

kernel-5.14.0-687.47.1.el9_8

$ cat ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/rebuild.details.txt
Rebuild_History BUILDABLE
Rebuilding Kernel from rpm changelog with Fuzz Limit: 87.50%
Number of commits in upstream range v5.14~1..kernel-mainline: 394115
Number of commits in rpm: 84
Number of commits matched with upstream: 67 (79.76%)
Number of commits in upstream but not in rpm: 394049
Number of commits NOT found in upstream: 17 (20.24%)

Rebuilding Kernel on Branch rocky9_8_rebuild_kernel-5.14.0-687.47.1.el9_8 for kernel-5.14.0-687.47.1.el9_8
Clean Cherry Picks: 51 (76.12%)
Empty Cherry Picks: 14 (20.90%)
_______________________________

__EMPTY COMMITS__________________________
8d567162ef288ee0df6674f291e3d9c290306f1e gfs2: Remove redundant check for GLF_INSTANTIATE_NEEDED
28690e5361c05fd4ef0ca3a17d1c667cba790554 rtnetlink: Add peer_type in struct rtnl_link_ops.
48327566769a6ff2e873b6bf075392bd756625ca rtnetlink: fix double call of rtnl_link_get_net_ifla()
954a2b40719a21e763a1bba2f0da92347e058fce rtnetlink: Try the outer netns attribute in rtnl_get_peer_net().
7b735ef81286007794a227ce2539419479c02a5f rtnetlink: add missing netlink_ns_capable() check for peer netns
3138df6f0cd04a75f8efa5b5270ba56d00a84ae6 rtla/timerlat: Exit top main loop on any non-zero wait_retval
0861615c28de668669d748ef4eb913ea9262d13b sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
6f4c80a2a7e6d06753b89a578b710a2499a5e62b sctp: validate embedded INIT chunk and address list lengths in cookie
5ceb87dc76ab269c940541ad9487cf0f3c0c793d selftests: netfilter: nft_queue.sh: fix spurious timeout on debug kernel
ba14798653bb815b4dcd116c5265a9f748bc0c7f selftests: netfilter: nft_queue.sh: avoid flakes on debug kernels
e306e3739d9a35c89176281f9ff6c600fcc859a4 kselftest: add test for nfqueue induced conntrack race
dde1a6084c5ca9d143a562540d5453454d79ea15 selftests: nft_queue.sh: add a parallel stress test
4f3a998a173b4325c2efd90bdadc6ccd3ad9a431 drm/xe: Open-code GGTT MMIO access protection
225d02cb46d0e567eb788308168159f61735c8fe drm/xe: Issue GGTT invalidation under lock in ggtt_node_remove

__CHANGES NOT IN UPSTREAM________________
Replace sbat with Rocky Linux sbat
Change bug tracker URL
Ensure appended release in sbat is removed'
dm-verity: fix buffer overflow in FEC calculation
mm/khugepaged: write all dirty file folios when collapsing
drm/xe/pt: Reset current_op in xe_pt_update_ops_init()
tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
sctp: validate stream count in sctp_process_strreset_inreq()
sctp: fix auth_hmacs array size in struct sctp_cookie
sctp: auth: verify auth requirement when auth_chunk is NULL
wifi: cfg80211: reject empty PMSR peer lists
wifi: cfg80211: reject unsupported PMSR FTM location requests
wifi: cfg80211: validate PMSR measurement type data
wifi: cfg80211: validate PMSR FTM preamble range
wifi: cfg80211: bound element ID read when checking non-inheritance
rtla/timerlat_top: Fix on-threshold actions firing on signal
qede: fix off-by-one in BD ring consumption on build_skb failure

BUILD

$ grep -E -B 5 -A 5 "\[TIMER\]|^Starting Build" $(ls -t kbuild* | head -n1)
/mnt/code/kernel-src-tree-build
Running make mrproper...
  CLEAN   scripts/basic
  CLEAN   scripts/kconfig
  CLEAN   include/config include/generated
[TIMER]{MRPROPER}: 5s
x86_64 architecture detected, copying config
'configs/kernel-x86_64-rhel.config' -> '.config'
Setting Local Version for build
CONFIG_LOCALVERSION="-rocky9_8_rebuild-328c63bb788e"
Making olddefconfig
--
  HOSTCC  scripts/kconfig/util.o
  HOSTLD  scripts/kconfig/conf
#
# configuration written to .config
#
Starting Build
  SYSHDR  arch/x86/include/generated/uapi/asm/unistd_32.h
  SYSHDR  arch/x86/include/generated/uapi/asm/unistd_64.h
  SYSHDR  arch/x86/include/generated/uapi/asm/unistd_x32.h
  SYSTBL  arch/x86/include/generated/asm/syscalls_32.h
  SYSHDR  arch/x86/include/generated/asm/unistd_32_ia32.h
--
  BTF [M] sound/usb/usx2y/snd-usb-us144mkii.ko
  BTF [M] sound/usb/usx2y/snd-usb-usx2y.ko
  BTF [M] sound/virtio/virtio_snd.ko
  BTF [M] sound/x86/snd-hdmi-lpe-audio.ko
  BTF [M] sound/xen/snd_xen_front.ko
[TIMER]{BUILD}: 1527s
Making Modules
  INSTALL /lib/modules/5.14.0-rocky9_8_rebuild-328c63bb788e/kernel/arch/x86/crypto/blake2s-x86_64.ko
  INSTALL /lib/modules/5.14.0-rocky9_8_rebuild-328c63bb788e/kernel/arch/x86/crypto/blowfish-x86_64.ko
  INSTALL /lib/modules/5.14.0-rocky9_8_rebuild-328c63bb788e/kernel/arch/x86/crypto/camellia-aesni-avx-x86_64.ko
  INSTALL /lib/modules/5.14.0-rocky9_8_rebuild-328c63bb788e/kernel/arch/x86/crypto/camellia-aesni-avx2.ko
--
  SIGN    /lib/modules/5.14.0-rocky9_8_rebuild-328c63bb788e/kernel/sound/virtio/virtio_snd.ko
  SIGN    /lib/modules/5.14.0-rocky9_8_rebuild-328c63bb788e/kernel/sound/usb/snd-usb-audio.ko
  STRIP   /lib/modules/5.14.0-rocky9_8_rebuild-328c63bb788e/kernel/sound/xen/snd_xen_front.ko
  SIGN    /lib/modules/5.14.0-rocky9_8_rebuild-328c63bb788e/kernel/sound/xen/snd_xen_front.ko
  DEPMOD  /lib/modules/5.14.0-rocky9_8_rebuild-328c63bb788e
[TIMER]{MODULES}: 10s
Making Install
sh ./arch/x86/boot/install.sh 5.14.0-rocky9_8_rebuild-328c63bb788e \
	arch/x86/boot/bzImage System.map "/boot"
[TIMER]{INSTALL}: 21s
Checking kABI
kABI check passed
Setting Default Kernel to /boot/vmlinuz-5.14.0-rocky9_8_rebuild-328c63bb788e and Index to 2
Hopefully Grub2.0 took everything ... rebooting after time metrices
[TIMER]{MRPROPER}: 5s
[TIMER]{BUILD}: 1527s
[TIMER]{MODULES}: 10s
[TIMER]{INSTALL}: 21s
[TIMER]{TOTAL} 1569s
Rebooting in 10 seconds

KSelfTests

$ get_kselftest_diff.sh
kselftest.5.14.0-rocky9_8_rebuild-e43b2c2d9676.log
311
kselftest.5.14.0-rocky9_8_rebuild-ee02e7dc85fd.log
311
kselftest.5.14.0-rocky9_8_rebuild-b5d4d49050ca.log
311
kselftest.5.14.0-rocky9_8_rebuild-328c63bb788e.log
311
Before: kselftest.5.14.0-rocky9_8_rebuild-b5d4d49050ca.log
After: kselftest.5.14.0-rocky9_8_rebuild-328c63bb788e.log
Diff:
No differences found.

jira KERNEL-1590
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Andreas Gruenbacher <agruenba@redhat.com>
commit fa58cc8

When a direct I/O write is performed, iomap_dio_rw() invalidates the
part of the page cache which the write is going to before carrying out
the write.  In the odd case, the direct I/O write will be reading from
the same page it is writing to.  gfs2 carries out writes with page
faults disabled, so it should have been obvious that this page
invalidation can cause iomap_dio_rw() to never make any progress.
Currently, gfs2 will end up in an endless retry loop in
gfs2_file_direct_write() instead, though.

Break this endless loop by limiting the number of retries and falling
back to buffered I/O after that.

Also simplify should_fault_in_pages() sightly and add a comment to make
the above case easier to understand.

	Reported-by: Jan Kara <jack@suse.cz>
	Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
(cherry picked from commit fa58cc8)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Andreas Gruenbacher <agruenba@redhat.com>
commit e411d74

In gfs2_fiemap(), we are calling iomap_fiemap() while holding the inode
glock.  This can lead to recursive glock taking if the fiemap buffer is
memory mapped to the same inode and accessing it triggers a page fault.

Fix by disabling page faults for iomap_fiemap() and faulting in the
buffer by hand if necessary.

Fixes xfstest generic/742.

	Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
(cherry picked from commit e411d74)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Andreas Gruenbacher <agruenba@redhat.com>
commit 8d56716
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/8d567162.failed

If the GLF_INSTANTIATE_NEEDED flag isn't set, gfs2_instantiate() is a
no-op.

	Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
(cherry picked from commit 8d56716)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	fs/gfs2/super.c
jira KERNEL-1590
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Bob Peterson <rpeterso@redhat.com>
commit f9da18c

This patch changes function evict_unlinked_inode so it does not call
gfs2_inode_remember_delete until it gets a good return code from
gfs2_dinode_dealloc.

	Signed-off-by: Bob Peterson <rpeterso@redhat.com>
	Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
(cherry picked from commit f9da18c)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Andreas Gruenbacher <agruenba@redhat.com>
commit 2ff7cf7

As Neil Brown describes in detail in the link referenced below, new
inodes must be unlocked before they can be instantiated.

An even better fix is to use d_instantiate_new(), which combines
d_instantiate() and unlock_new_inode().

Fixes: 3d36e57 ("gfs2: gfs2_create_inode rework")
	Reported-by: syzbot+0ea5108a1f5fb4fcc2d8@syzkaller.appspotmail.com
Link: https://lore.kernel.org/linux-fsdevel/177153754005.8396.8777398743501764194@noble.neil.brown.name/
	Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
(cherry picked from commit 2ff7cf7)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Andreas Gruenbacher <agruenba@redhat.com>
commit 0ac82bc

We are no longer using LM_FLAG_TRY or LM_FLAG_TRY_1CB during inode
evict, so ret cannot be GLR_TRYFAILED here.

	Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
(cherry picked from commit 0ac82bc)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Andreas Gruenbacher <agruenba@redhat.com>
commit e2de651

In evict_linked_inode(), the truncate_inode_pages() calls are carried
out inside a transaction.  This code was added to what was then function
gfs2_delete_inode() in commit 16615be ("[GFS2] Clean up journaled
data writing").

These transactions are only used for creating revokes for the jdata
buffers in the journal, so don't create such transactions when we know
that the address space doesn't contain any jdata buffers for this inode
and truncate the metadata address space outside of the transaction.

	Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
(cherry picked from commit e2de651)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Andreas Gruenbacher <agruenba@redhat.com>
commit 2b34a9e

Add gl helper variables in evict_unlinked_inode() and
evict_linked_inode().  This patch isn't very interesting by itself, but
it makes the next patch more readable.

	Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
(cherry picked from commit 2b34a9e)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Andreas Gruenbacher <agruenba@redhat.com>
commit bd67f17

When gfs2_evict_inode() is called on an inode with unwritten data in the
page cache, the page cache needs to be written before it can be
truncated.  This doesn't always happen.  Fix that by changing
gfs2_evict_inode() to always either call evict_linked_inode() or
evict_unlinked_inode().

Inside evict_unlinked_inode(), first check if the inode is dirty.  If it
is, make sure the inode glock is held and write back the data and
metadata.  If it isn't, skip those steps.

Also, make sure that gfs2_evict_inode() calls gfs2_evict_inode() and
evict_unlinked_inode() only if ip->i_gl is not NULL; this avoids
unnecessary complications there.

Fixes xfstest generic/211.

	Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
(cherry picked from commit bd67f17)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-31692
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Kuniyuki Iwashima <kuniyu@amazon.com>
commit 28690e5
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/28690e53.failed

In ops->newlink(), veth, vxcan, and netkit call rtnl_link_get_net() with
a net pointer, which is the first argument of ->newlink().

rtnl_link_get_net() could return another netns based on IFLA_NET_NS_PID
and IFLA_NET_NS_FD in the peer device's attributes.

We want to get it and fill rtnl_nets->nets[] in advance in rtnl_newlink()
for per-netns RTNL.

All of the three get the peer netns in the same way:

  1. Call rtnl_nla_parse_ifinfomsg()
  2. Call ops->validate() (vxcan doesn't have)
  3. Call rtnl_link_get_net_tb()

Let's add a new field peer_type to struct rtnl_link_ops and prefetch
netns in the peer ifla to add it to rtnl_nets in rtnl_newlink().

	Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
	Reviewed-by: Eric Dumazet <edumazet@google.com>
	Reviewed-by: Nikolay Aleksandrov <razor@blackwall.org>
Link: https://patch.msgid.link/20241108004823.29419-6-kuniyu@amazon.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 28690e5)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/core/rtnetlink.c
jira KERNEL-1590
cve CVE-2026-31692
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Kuniyuki Iwashima <kuniyu@amazon.com>
commit 0eb87b0

For per-netns RTNL, we need to prefetch the peer device's netns.

Let's set rtnl_link_ops.peer_type and accordingly remove duplicated
validation in ->newlink().

	Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
	Reviewed-by: Eric Dumazet <edumazet@google.com>
	Reviewed-by: Nikolay Aleksandrov <razor@blackwall.org>
Link: https://patch.msgid.link/20241108004823.29419-7-kuniyu@amazon.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 0eb87b0)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-31692
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Kuniyuki Iwashima <kuniyu@amazon.com>
commit 6b84e55

For per-netns RTNL, we need to prefetch the peer device's netns.

Let's set rtnl_link_ops.peer_type and accordingly remove duplicated
validation in ->newlink().

	Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
	Reviewed-by: Eric Dumazet <edumazet@google.com>
	Reviewed-by: Nikolay Aleksandrov <razor@blackwall.org>
Link: https://patch.msgid.link/20241108004823.29419-8-kuniyu@amazon.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 6b84e55)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-31692
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Cong Wang <cong.wang@bytedance.com>
commit 4832756
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/48327566.failed

Currently rtnl_link_get_net_ifla() gets called twice when we create
peer devices, once in rtnl_add_peer_net() and once in each ->newlink()
implementation.

This looks safer, however, it leads to a classic Time-of-Check to
Time-of-Use (TOCTOU) bug since IFLA_NET_NS_PID is very dynamic. And
because of the lack of checking error pointer of the second call, it
also leads to a kernel crash as reported by syzbot.

Fix this by getting rid of the second call, which already becomes
redudant after Kuniyuki's work. We have to propagate the result of the
first rtnl_link_get_net_ifla() down to each ->newlink().

	Reported-by: syzbot+21ba4d5adff0b6a7cfc6@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=21ba4d5adff0b6a7cfc6
Fixes: 0eb87b0 ("veth: Set VETH_INFO_PEER to veth_link_ops.peer_type.")
Fixes: 6b84e55 ("vxcan: Set VXCAN_INFO_PEER to vxcan_link_ops.peer_type.")
Fixes: fefd5d0 ("netkit: Set IFLA_NETKIT_PEER_INFO to netkit_link_ops.peer_type.")
	Cc: Kuniyuki Iwashima <kuniyu@amazon.com>
	Signed-off-by: Cong Wang <cong.wang@bytedance.com>
	Reviewed-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Link: https://patch.msgid.link/20241129212519.825567-1-xiyou.wangcong@gmail.com
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>

(cherry picked from commit 4832756)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	drivers/net/netkit.c
#	net/core/rtnetlink.c
jira KERNEL-1590
cve CVE-2026-31692
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Kuniyuki Iwashima <kuniyu@amazon.com>
commit 954a2b4
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/954a2b40.failed

Xiao Liang reported that the cited commit changed netns handling
in newlink() of netkit, veth, and vxcan.

Before the patch, if we don't find a netns attribute in the peer
device attributes, we tried to find another netns attribute in
the outer netlink attributes by passing it to rtnl_link_get_net().

Let's restore the original behaviour.

Fixes: 4832756 ("rtnetlink: fix double call of rtnl_link_get_net_ifla()")
	Reported-by: Xiao Liang <shaw.leon@gmail.com>
Closes: https://lore.kernel.org/netdev/CABAhCORBVVU8P6AHcEkENMj+gD2d3ce9t=A_o48E0yOQp8_wUQ@mail.gmail.com/#t
	Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
	Tested-by: Xiao Liang <shaw.leon@gmail.com>
Link: https://patch.msgid.link/20241216110432.51488-1-kuniyu@amazon.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 954a2b4)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/core/rtnetlink.c
jira KERNEL-1590
cve CVE-2026-31692
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Nikolaos Gkarlis <nickgarlis@gmail.com>
commit 7b735ef
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/7b735ef8.failed

rtnl_newlink() lacks a CAP_NET_ADMIN capability check on the peer
network namespace when creating paired devices (veth, vxcan,
netkit). This allows an unprivileged user with a user namespace
to create interfaces in arbitrary network namespaces, including
init_net.

Add a netlink_ns_capable() check for CAP_NET_ADMIN in the peer
namespace before allowing device creation to proceed.

Fixes: 81adee4 ("net: Support specifying the network namespace upon device creation.")
	Signed-off-by: Nikolaos Gkarlis <nickgarlis@gmail.com>
	Reviewed-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20260402181432.4126920-1-nickgarlis@gmail.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 7b735ef)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/core/rtnetlink.c
jira KERNEL-1590
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Crystal Wood <crwood@redhat.com>
commit 3138df6
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/3138df6f.failed

Comparing to exactly 1 will fail if more than one ring buffer
event was seen since the last call to timerlat_bpf_wait(), which
can happen in some race scenarios.

	Signed-off-by: Crystal Wood <crwood@redhat.com>
Link: https://lore.kernel.org/r/20251112152529.956778-5-crwood@redhat.com
	Signed-off-by: Tomas Glozar <tglozar@redhat.com>
(cherry picked from commit 3138df6)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	tools/tracing/rtla/src/timerlat_top.c
jira KERNEL-1590
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Fengyuan Gong <gfengyuan@google.com>
commit a41851b

Refine qdisc_pkt_len_init to include headers up through
the inner transport header when computing header size
for encapsulations. Also refine net/sched/sch_cake.c
borrowed from qdisc_pkt_len_init().

	Signed-off-by: Fengyuan Gong <gfengyuan@google.com>
	Reviewed-by: Willem de Bruijn <willemb@google.com>
	Reviewed-by: Eric Dumazet <edumazet@google.com>
	Acked-by: Toke Høiland-Jørgensen <toke@redhat.com>
Link: https://patch.msgid.link/20250702160741.1204919-1-gfengyuan@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit a41851b)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Eric Dumazet <edumazet@google.com>
commit b2a38f6

Add a new u16 field, next to pkt_len : pkt_segs

This will cache shinfo->gso_segs to speed up qdisc deqeue().

Move slave_dev_queue_mapping at the end of qdisc_skb_cb,
and move three bits from tc_skb_cb :
- post_ct
- post_ct_snat
- post_ct_dnat

	Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20251121083256.674562-2-edumazet@google.com
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>

(cherry picked from commit b2a38f6)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Eric Dumazet <edumazet@google.com>
commit be1b70a

Qdisc use shinfo->gso_segs for their pkts stats in bstats_update(),
but this field needs to be initialized for SKB_GSO_DODGY users.

	Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20251121083256.674562-3-edumazet@google.com
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>

(cherry picked from commit be1b70a)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
…it()

jira KERNEL-1590
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Eric Dumazet <edumazet@google.com>
commit 874c192

qdisc_pkt_len_init() is currently initalizing qdisc_skb_cb(skb)->pkt_len.

Add qdisc_skb_cb(skb)->pkt_segs initialization and rename this function
to qdisc_pkt_len_segs_init().

	Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20251121083256.674562-4-edumazet@google.com
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>

(cherry picked from commit 874c192)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Eric Dumazet <edumazet@google.com>
commit 30e02ec

Reduce indentation level by returning early if the transport header
was not set.

Add an unlikely() clause as this is not the common case.

No functional change.

	Signed-off-by: Eric Dumazet <edumazet@google.com>
	Reviewed-by: Joe Damato <joe@dama.to>
Link: https://patch.msgid.link/20260403221540.3297753-2-edumazet@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 30e02ec)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Eric Dumazet <edumazet@google.com>
commit 7fb4c19

Most ndo_start_xmit() methods expects headers of gso packets
to be already in skb->head.

net/core/tso.c users are particularly at risk, because tso_build_hdr()
does a memcpy(hdr, skb->data, hdr_len);

qdisc_pkt_len_segs_init() already does a dissection of gso packets.

Use pskb_may_pull() instead of skb_header_pointer() to make
sure drivers do not have to reimplement this.

Some malicious packets could be fed, detect them so that we can
drop them sooner with a new SKB_DROP_REASON_SKB_BAD_GSO drop_reason.

Fixes: e876f20 ("net: Add a software TSO helper API")
	Signed-off-by: Eric Dumazet <edumazet@google.com>
	Reviewed-by: Joe Damato <joe@dama.to>
Link: https://patch.msgid.link/20260403221540.3297753-3-edumazet@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 7fb4c19)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Cosmin Ratiu <cratiu@nvidia.com>
commit fa90a31

On VXLAN over IPsec egress, xfrm{4,6}_transport_output() blindly
overwrite inner_transport_header (== the inner TCP header saved in VXLAN
iptunnel_handle_offloads() -> skb_reset_inner_headers()) with the
current transport_header (== the VXLAN outer UDP header set by
udp_tunnel_xmit_skb()).

This was a latent bug, harmless until commit [1] added a doff validation
check in qdisc_pkt_len_segs_init() for encapsulated GSO packets. With
the wrong inner_transport_header set by xfrm, qdisc_pkt_len_segs_init()
interprets inner_transport_header as a TCP header, reads doff=0 from the
upper byte of the VNI and drops the packet with DROP_REASON_SKB_BAD_GSO.

Besides the use in GSO to determine the header size of segmented
packets, inner_transport_header might be used by drivers to set up
inner checksum offloading by pointing the HW to the inner transport
header. A quick browse through available drivers shows that mlx5 uses
skb->csum_start specifically for this scenario, while others either
don't support VXLAN over IPsec crypto offload (ixgbe) or the HW is
capable of parsing the packets itself (nfp, Chelsio).

But in all cases, it is more correct to let the inner_transport_header
point to the innermost header instead of overwriting it in xfrm.

So fix this by guarding all four inner header save sites in
xfrm_output.c (xfrm{4,6}_transport_output, xfrm{4,6}_tunnel_encap_add)
with a check for skb->inner_protocol. When inner_protocol is set, a
tunnel layer (VXLAN, Geneve, GRE, etc.) has already saved the correct
inner header offsets and they must not be overwritten. When
inner_protocol is zero, no prior tunnel encapsulation exists and xfrm
must save the inner headers itself. The tunnel mode checks are only
added for completion, since they aren't strictly required, as
xfrm_output() forces software GSO in tunnel mode before encap.

This makes the previously added test pass:
 # ./tools/testing/selftests/drivers/net/hw/ipsec_vxlan.py
 TAP version 13
 1..4
 ok 1 ipsec_vxlan.test_vxlan_ipsec_crypto_offload.outer_v4_inner_v4
 ok 2 ipsec_vxlan.test_vxlan_ipsec_crypto_offload.outer_v4_inner_v6
 ok 3 ipsec_vxlan.test_vxlan_ipsec_crypto_offload.outer_v6_inner_v4
 ok 4 ipsec_vxlan.test_vxlan_ipsec_crypto_offload.outer_v6_inner_v6
 # Totals: pass:4 fail:0 xfail:0 xpass:0 skip:0 error:0

[1] commit 7fb4c19 ("net: pull headers in qdisc_pkt_len_segs_init()")
Fixes: f1bd7d6 ("xfrm: Add encapsulation header offsets while SKB is not encrypted")
	Signed-off-by: Cosmin Ratiu <cratiu@nvidia.com>
	Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
(cherry picked from commit fa90a31)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-52918
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Jiexun Wang <wangjiexun2025@gmail.com>
commit e83f5e2

bt_sock_poll() walks the accept queue without synchronization, while
child teardown can unlink the same socket and drop its last reference.
The unsynchronized accept queue walk has existed since the initial
Bluetooth import.

Protect accept_q with a dedicated lock for queue updates and polling.
Also rework bt_accept_dequeue() to take temporary child references under
the queue lock before dropping it and locking the child socket.

Fixes: 1da177e ("Linux-2.6.12-rc2")
	Cc: stable@vger.kernel.org
	Reported-by: Jann Horn <jannh@google.com>
	Reported-by: Yuan Tan <yuantan098@gmail.com>
	Reported-by: Yifan Wu <yifanwucs@gmail.com>
	Reported-by: Juefei Pu <tomapufckgml@gmail.com>
	Reported-by: Xin Liu <bird@lzu.edu.cn>
	Signed-off-by: Jiexun Wang <wangjiexun2025@gmail.com>
	Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
	Signed-off-by: Jiexun Wang <wangjiexun2025@gmail.com>
	Reviewed-by: Jann Horn <jannh@google.com>
	Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
(cherry picked from commit e83f5e2)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-53256
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Zhang Cen <rollkingzzc@gmail.com>
commit 43c441e

rfcomm_get_sock_by_channel() scans rfcomm_sk_list under the list lock,
but returns the selected listener after dropping that lock without
taking a reference. rfcomm_connect_ind() then locks the listener,
queues a child socket on it, and may notify it after unlocking it.

The buggy scenario involves two paths, with each column showing the
order within that path:

rfcomm_connect_ind():            listener close:
  1. Find parent in              1. close() enters
     rfcomm_get_sock_by_channel()   rfcomm_sock_release().
  2. Drop rfcomm_sk_list.lock    2. rfcomm_sock_shutdown()
     without pinning parent.        closes the listener.
  3. Call lock_sock(parent) and  3. rfcomm_sock_kill()
     bt_accept_enqueue(parent,      unlinks and puts parent.
     sk, true).
  4. Read parent flags and may   4. parent can be freed.
     call sk_state_change().

If close wins the race, parent can be freed before
rfcomm_connect_ind() reaches lock_sock(), bt_accept_enqueue(), or the
deferred-setup callback.

Take a reference on the listener before leaving rfcomm_sk_list.lock.
After lock_sock() succeeds, recheck that it is still in BT_LISTEN
before queueing a child, cache the deferred-setup bit while the parent
is locked, and drop the reference after the last parent use.

KASAN reported a slab-use-after-free in lock_sock_nested() from
rfcomm_connect_ind(), with the freeing stack going through
rfcomm_sock_kill() and rfcomm_sock_release().

Fixes: 1da177e ("Linux-2.6.12-rc2")
	Signed-off-by: Zhang Cen <rollkingzzc@gmail.com>
	Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
(cherry picked from commit 43c441e)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-53254
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author SeungJu Cheon <suunj1331@gmail.com>
commit 23882b8

The RFCOMM MCC handlers cast skb->data to protocol-specific structs
without validating skb->len first. A malicious remote device can send
truncated MCC frames and trigger out-of-bounds reads in these handlers.

Fix this by using skb_pull_data() to validate and access the required
data before dereferencing it.

rfcomm_recv_rpn() requires special handling since ETSI TS 07.10 allows
1-byte RPN requests. Handle this by validating only the DLCI byte first,
and validating the full struct only when len > 1.

Fixes: 1da177e ("Linux-2.6.12-rc2")
	Suggested-by: Muhammad Bilal <meatuni001@gmail.com>
	Signed-off-by: SeungJu Cheon <suunj1331@gmail.com>
	Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
(cherry picked from commit 23882b8)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-63945
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Muhammad Bilal <meatuni001@gmail.com>
commit 4b5f8e6

iso_sock_close() calls iso_sock_clear_timer() before acquiring
lock_sock(sk).

iso_sock_clear_timer() reads iso_pi(sk)->conn twice without the
socket lock held:

    if (!iso_pi(sk)->conn)
        return;
    cancel_delayed_work(&iso_pi(sk)->conn->timeout_work);

Concurrently, iso_conn_del() executes under lock_sock(sk) and calls
iso_chan_del(), which sets iso_pi(sk)->conn to NULL and may result in
the final reference to the connection being dropped:

    CPU0                         CPU1
    ----                         ----
    iso_sock_clear_timer()
      if (conn != NULL) ...      lock_sock(sk)
                                   iso_chan_del()
                                   iso_pi(sk)->conn = NULL
      cancel_delayed_work(conn)  /* NULL deref or UAF */

iso_pi(sk)->conn is not stable across the unlock window, causing a
NULL pointer dereference or use-after-free.

Serialize iso_sock_clear_timer() with the socket lock by moving it
inside lock_sock()/release_sock(), matching the pattern used in
iso_conn_del() and all other call sites.

Fixes: ccf74f2 ("Bluetooth: Add BTPROTO_ISO socket type")
	Cc: stable@vger.kernel.org
	Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
	Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
(cherry picked from commit 4b5f8e6)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-53053
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Vasant Hegde <vasant.hegde@amd.com>
commit faad224

Currently clone_alias() assumes first argument (pdev) is always the
original device pointer. This function is called by
pci_for_each_dma_alias() which based on topology decides to send
original or alias device details in first argument.

This meant that the source devid used to look up and copy the DTE
may be incorrect, leading to wrong or stale DTE entries being
propagated to alias device.

Fix this by passing the original pdev as the opaque data argument to
both the direct clone_alias() call and pci_for_each_dma_alias(). Inside
clone_alias(), retrieve the original device from data and compute devid
from it.

Fixes: 3332364 ("iommu/amd: Support multiple PCI DMA aliases in device table")
	Signed-off-by: Vasant Hegde <vasant.hegde@amd.com>
	Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
(cherry picked from commit faad224)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
… pairing response

jira KERNEL-1590
cve CVE-2026-43334
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Oleh Konko <security@1seal.org>
commit d05111b

smp_cmd_pairing_req() currently builds the pairing response from the
initiator auth_req before enforcing the local BT_SECURITY_HIGH
requirement. If the initiator omits SMP_AUTH_MITM, the response can
also omit it even though the local side still requires MITM.

tk_request() then sees an auth value without SMP_AUTH_MITM and may
select JUST_CFM, making method selection inconsistent with the pairing
policy the responder already enforces.

When the local side requires HIGH security, first verify that MITM can
be achieved from the IO capabilities and then force SMP_AUTH_MITM in the
response in both rsp.auth_req and auth. This keeps the responder auth bits
and later method selection aligned.

Fixes: 2b64d15 ("Bluetooth: Add MITM mechanism to LE-SMP")
	Cc: stable@vger.kernel.org
	Suggested-by: Luiz Augusto von Dentz <luiz.dentz@gmail.com>
	Signed-off-by: Oleh Konko <security@1seal.org>
	Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
(cherry picked from commit d05111b)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-64113
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Michael Bommarito <michael.bommarito@gmail.com>
commit 5d49b56

ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's
own address (VEPA multicast workaround) by freeing the skb and
continuing to the next descriptor:

    dev_kfree_skb_irq(skb);
    continue;

The skb pointer is declared outside the while loop and persists across
iterations.  Because the continue skips the "skb = NULL" reset at the
bottom of the loop, the next iteration enters the "else if (skb)" path
and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing
skb_shinfo(skb)->nr_frags - a use-after-free in NAPI softirq context.

The sibling driver iavf already handles this correctly by nulling the
pointer before continuing.  Apply the same pattern here.

I do not have ixgbevf hardware; the bug was found by static analysis
(scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool
corroboration with the highest score in the scan).  The UAF was confirmed
under KASAN by loading a test module that reproduces the exact code
pattern (alloc skb, kfree_skb, then read skb_shinfo(skb)->nr_frags):

  BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000
  Read of size 8 at addr 000000006163ae78 by task insmod/30
  freed 208-byte region [000000006163adc0, 000000006163ae90)

QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF
driver does not include the VEPA source pruning path, so a full
end-to-end reproduction with emulated hardware was not possible.

Fixes: bad1723 ("ixgbevf: Change receive model to use double buffered page based receives")
	Cc: stable@vger.kernel.org
	Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
	Reviewed-by: Simon Horman <horms@kernel.org>
	Tested-by: Rafal Romanowski <rafal.romanowski@intel.com>
	Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Link: https://patch.msgid.link/20260515182419.1597859-8-anthony.l.nguyen@intel.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 5d49b56)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
…uild

jira KERNEL-1590
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Florian Westphal <fw@strlen.de>
commit 0a8b08c

The sctp selftest is very slow on debug kernels.

	Reported-by: Jakub Kicinski <kuba@kernel.org>
Closes: https://lore.kernel.org/netdev/20240826192500.32efa22c@kernel.org/
Fixes: 4e97d52 ("selftests: netfilter: nft_queue.sh: sctp coverage")
	Signed-off-by: Florian Westphal <fw@strlen.de>
	Acked-by: Pablo Neira Ayuso <pablo@netfilter.org>
Link: https://patch.msgid.link/20240827090023.8917-1-fw@strlen.de
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>

(cherry picked from commit 0a8b08c)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Florian Westphal <fw@strlen.de>
commit 5ceb87d
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/5ceb87dc.failed

The sctp selftest is very slow on debug kernels.

Its possible that the nf_queue listener program exits due to timeout
before first sctp packet is processed.

In this case socat hangs until script times out.
Fix this by removing the -t option where possible and kill the test
program once the file transfer/socat has exited.

-t sets SO_RCVTIMEO, its inteded for the 'ping' part of the selftest
where we want to make sure that packets get reinjected properly without
skipping a second queue request.

While at it, add a helper to compare the (binary) files instead of diff.
The 'diff' part was copied from a another sub-test that compares text.

Let helper dump file sizes on error so we can see the progress made.

Tested on an old 2010-ish box with a debug kernel and 100 iterations.

This is a followup to the earlier filesize reduction change.

	Reported-by: Jakub Kicinski <kuba@kernel.org>
Closes: https://lore.kernel.org/netdev/20240829080109.GB30766@breakpoint.cc/
Fixes: 0a8b08c ("selftests: netfilter: nft_queue.sh: reduce test file size for debug build")
	Signed-off-by: Florian Westphal <fw@strlen.de>
Link: https://patch.msgid.link/20240830092254.8029-1-fw@strlen.de
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>

(cherry picked from commit 5ceb87d)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	tools/testing/selftests/net/netfilter/nft_queue.sh
jira KERNEL-1590
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Florian Westphal <fw@strlen.de>
commit ba14798
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/ba147986.failed

Jakub reports test flakes on debug kernels:
 FAIL: test_udp_gro_ct: Expected software segmentation to occur, had 23 and 17

This test assumes that the kernels nfnetlink_queue module sees N GSO
packets, segments them into M skbs and queues them to userspace for
reinjection.

Hence, if M >= N, no segmentation occurred.

However, its possible that this happens:
- nfnetlink_queue gets GSO packet
- segments that into n skbs
- userspace buffer is full, kernel drops the segmented skbs

-> "toqueue" counter incremented by 1, "fromqueue" is unchanged.

If this happens often enough in a single run, M >= N check triggers
incorrectly.

To solve this, allow the nf_queue.c test program to set the FAIL_OPEN
flag so that the segmented skbs bypass the queueing step in the kernel
if the receive buffer is full.

Also, reduce number of sending socat instances, decrease their priority
and increase nice value for the nf_queue program itself to reduce the
probability of overruns happening in the first place.

Fixes: 59ecffa ("selftests: netfilter: nft_queue.sh: add udp fraglist gro test case")
	Reported-by: Jakub Kicinski <kuba@kernel.org>
Closes: https://lore.kernel.org/netdev/20260218184114.0b405b72@kernel.org/
	Signed-off-by: Florian Westphal <fw@strlen.de>
Link: https://patch.msgid.link/20260226161920.1205-1-fw@strlen.de
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit ba14798)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	tools/testing/selftests/net/netfilter/nft_queue.sh
jira KERNEL-1590
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Florian Westphal <fw@strlen.de>
commit e306e37
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/e306e373.failed

The netfilter race happens when two packets with the same tuple are DNATed
and enqueued with nfqueue in the postrouting hook.

Once one of the packet is reinjected it may be DNATed again to a different
destination, but the conntrack entry remains the same and the return packet
was dropped.

Based on earlier patch from Antonio Ojea.

Link: https://bugzilla.netfilter.org/show_bug.cgi?id=1766
Co-developed-by: Antonio Ojea <aojea@google.com>
	Signed-off-by: Antonio Ojea <aojea@google.com>
	Signed-off-by: Florian Westphal <fw@strlen.de>
	Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
(cherry picked from commit e306e37)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	tools/testing/selftests/net/netfilter/nft_queue.sh
jira KERNEL-1590
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Fernando Fernandez Mancera <fmancera@suse.de>
commit dde1a60
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/dde1a608.failed

Introduce a new stress test to check for race conditions in the
nfnetlink_queue subsystem, where an entry is freed while another CPU is
concurrently walking the global rhashtable.

To trigger this, `nf_queue.c` is extended with two new flags:
  * -O (out-of-order): Buffers packet IDs and flushes them in reverse.
  * -b (bogus verdicts): Floods the kernel with non-existent packet IDs.

The bogus verdict loop forces the kernel's lookup function to perform
full rhashtable bucket traversals (-ENOENT). Combined with reverse-order
flushing and heavy parallel UDP/ping flooding across 8 queues, this puts
the nfnetlink_queue code under pressure.

Joint work with Florian Westphal.

	Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
	Signed-off-by: Florian Westphal <fw@strlen.de>
(cherry picked from commit dde1a60)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	tools/testing/selftests/net/netfilter/nf_queue.c
#	tools/testing/selftests/net/netfilter/nft_queue.sh
jira KERNEL-1590
cve CVE-2026-52917
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Zhao Zhang <zzhan461@ucr.edu>
commit 5eba3e4

The SCTP exact sock_diag lookup can hold a transport reference, block on
lock_sock(sk), and then resume after sctp_association_free() has marked
the association dead and freed its bind address list.

When that happens, inet_assoc_attr_size() and
inet_diag_msg_sctpasoc_fill() can still dereference association state
that is no longer valid for reporting. In particular,
inet_diag_msg_sctpasoc_fill() may read an empty bind-address list as a
real sctp_sockaddr_entry and trigger an out-of-bounds read from
unrelated association memory.

Reject the association after taking the socket lock if it has been
reaped or detached from the endpoint, and report the lookup as stale.
This keeps the exact dump-one path from formatting torn association
state.

Fixes: 8f840e4 ("sctp: add the sctp_diag.c file")
	Cc: stable@kernel.org
	Reported-by: Yuan Tan <yuantan098@gmail.com>
	Reported-by: Yifan Wu <yifanwucs@gmail.com>
	Reported-by: Juefei Pu <tomapufckgml@gmail.com>
	Reported-by: Zhengchuan Liang <zcliangcn@gmail.com>
	Reported-by: Xin Liu <bird@lzu.edu.cn>
	Signed-off-by: Zhao Zhang <zzhan461@ucr.edu>
	Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
	Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/fac6043fa20a2ff68e12958c431836f692c51268.1780113823.git.zzhan461@ucr.edu
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 5eba3e4)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-63971
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Zhenghang Xiao <kipreyyy@gmail.com>
commit f14fe63

sctp_wait_for_connect() drops and re-acquires the socket lock while
waiting for the association to reach ESTABLISHED state. During this
window, another thread can peeloff the association to a new socket via
getsockopt(SCTP_SOCKOPT_PEELOFF), changing asoc->base.sk. After
re-acquiring the old socket lock, sctp_wait_for_connect() returns
success without noticing the migration — the caller then accesses
the association under the wrong lock in sctp_datamsg_from_user().

Add the same sk != asoc->base.sk check that sctp_wait_for_sndbuf()
already has, returning an error if the association was migrated while
we slept.

Fixes: 668c9be ("sctp: implement assign_number for sctp_stream_interleave")
	Signed-off-by: Zhenghang Xiao <kipreyyy@gmail.com>
	Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260527032411.60959-1-kipreyyy@gmail.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit f14fe63)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-23466
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Matthew Brost <matthew.brost@intel.com>
commit 4f3a998
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/4f3a998a.failed

GGTT MMIO access is currently protected by hotplug (drm_dev_enter),
which works correctly when the driver loads successfully and is later
unbound or unloaded. However, if driver load fails, this protection is
insufficient because drm_dev_unplug() is never called.

Additionally, devm release functions cannot guarantee that all BOs with
GGTT mappings are destroyed before the GGTT MMIO region is removed, as
some BOs may be freed asynchronously by worker threads.

To address this, introduce an open-coded flag, protected by the GGTT
lock, that guards GGTT MMIO access. The flag is cleared during the
dev_fini_ggtt devm release function to ensure MMIO access is disabled
once teardown begins.

	Cc: stable@vger.kernel.org
Fixes: 919bb54 ("drm/xe: Fix missing runtime outer protection for ggtt_remove_node")
	Reviewed-by: Zhanjun Dong <zhanjun.dong@intel.com>
	Signed-off-by: Matthew Brost <matthew.brost@intel.com>
Link: https://patch.msgid.link/20260310225039.1320161-8-zhanjun.dong@intel.com
(cherry picked from commit 4f3a998)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	drivers/gpu/drm/xe/xe_ggtt.c
jira KERNEL-1590
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Matthew Brost <matthew.brost@intel.com>
commit 225d02c
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/225d02cb.failed

Async work (e.g., GuC queue teardowns) can call ggtt_node_remove, so the
operation must be performed under the GGTT lock to ensure the GGTT
online check remains stable. GGTT insertion and removal are heavyweight
operations (e.g., queue create/destroy), so the additional serialization
cost is negligible compared to ensuring correctness.

Fixes: 4f3a998 ("drm/xe: Open-code GGTT MMIO access protection")
	Signed-off-by: Matthew Brost <matthew.brost@intel.com>
	Reviewed-by: Dnyaneshwar Bhadane <dnyaneshwar.bhadane@intel.com>
Link: https://patch.msgid.link/20260326011207.62373-1-matthew.brost@intel.com
(cherry picked from commit 225d02c)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	drivers/gpu/drm/xe/xe_ggtt.c
jira KERNEL-1590
cve CVE-2026-31479
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Matthew Auld <matthew.auld@intel.com>
commit aec6969

During 3D workload, user is reporting hitting:

[  413.361679] WARNING: drivers/gpu/drm/xe/xe_vm.c:1217 at vm_bind_ioctl_ops_unwind+0x1e2/0x2e0 [xe], CPU#7: vkd3d_queue/9925
[  413.361944] CPU: 7 UID: 1000 PID: 9925 Comm: vkd3d_queue Kdump: loaded Not tainted 7.0.0-070000rc3-generic #202603090038 PREEMPT(lazy)
[  413.361949] RIP: 0010:vm_bind_ioctl_ops_unwind+0x1e2/0x2e0 [xe]
[  413.362074] RSP: 0018:ffffd4c25c3df930 EFLAGS: 00010282
[  413.362077] RAX: 0000000000000000 RBX: ffff8f3ee817ed10 RCX: 0000000000000000
[  413.362078] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
[  413.362079] RBP: ffffd4c25c3df980 R08: 0000000000000000 R09: 0000000000000000
[  413.362081] R10: 0000000000000000 R11: 0000000000000000 R12: ffff8f41fbf99380
[  413.362082] R13: ffff8f3ee817e968 R14: 00000000ffffffef R15: ffff8f43d00bd380
[  413.362083] FS:  00000001040ff6c0(0000) GS:ffff8f4696d89000(0000) knlGS:00000000330b0000
[  413.362085] CS:  0010 DS: 002b ES: 002b CR0: 0000000080050033
[  413.362086] CR2: 00007ddfc4747000 CR3: 00000002e6262005 CR4: 0000000000f72ef0
[  413.362088] PKRU: 55555554
[  413.362089] Call Trace:
[  413.362092]  <TASK>
[  413.362096]  xe_vm_bind_ioctl+0xa9a/0xc60 [xe]

Which seems to hint that the vma we are re-inserting for the ops unwind
is either invalid or overlapping with something already inserted in the
vm. It shouldn't be invalid since this is a re-insertion, so must have
worked before. Leaving the likely culprit as something already placed
where we want to insert the vma.

Following from that, for the case where we do something like a rebind in
the middle of a vma, and one or both mapped ends are already compatible,
we skip doing the rebind of those vma and set next/prev to NULL. As well
as then adjust the original unmap va range, to avoid unmapping the ends.
However, if we trigger the unwind path, we end up with three va, with
the two ends never being removed and the original va range in the middle
still being the shrunken size.

If this occurs, one failure mode is when another unwind op needs to
interact with that range, which can happen with a vector of binds. For
example, if we need to re-insert something in place of the original va.
In this case the va is still the shrunken version, so when removing it
and then doing a re-insert it can overlap with the ends, which were
never removed, triggering a warning like above, plus leaving the vm in a
bad state.

With that, we need two things here:

 1) Stop nuking the prev/next tracking for the skip cases. Instead
    relying on checking for skip prev/next, where needed. That way on the
    unwind path, we now correctly remove both ends.

 2) Undo the unmap va shrinkage, on the unwind path. With the two ends
    now removed the unmap va should expand back to the original size again,
    before re-insertion.

v2:
  - Update the explanation in the commit message, based on an actual IGT of
    triggering this issue, rather than conjecture.
  - Also undo the unmap shrinkage, for the skip case. With the two ends
    now removed, the original unmap va range should expand back to the
    original range.
v3:
  - Track the old start/range separately. vma_size/start() uses the va
    info directly.

Link: https://gitlab.freedesktop.org/drm/xe/kernel/-/issues/7602
Fixes: 8f33b4f ("drm/xe: Avoid doing rebinds")
	Signed-off-by: Matthew Auld <matthew.auld@intel.com>
	Cc: Matthew Brost <matthew.brost@intel.com>
	Cc: <stable@vger.kernel.org> # v6.8+
	Reviewed-by: Matthew Brost <matthew.brost@intel.com>
Link: https://patch.msgid.link/20260318100208.78097-2-matthew.auld@intel.com
(cherry picked from commit aec6969)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-31566
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Srinivasan Shanmugam <srinivasan.shanmugam@amd.com>
commit 8b9e525

amdgpu_amdkfd_submit_ib() submits a GPU job and gets a fence
from amdgpu_ib_schedule(). This fence is used to wait for job
completion.

Currently, the code drops the fence reference using dma_fence_put()
before calling dma_fence_wait().

If dma_fence_put() releases the last reference, the fence may be
freed before dma_fence_wait() is called. This can lead to a
use-after-free.

Fix this by waiting on the fence first and releasing the reference
only after dma_fence_wait() completes.

Fixes the below:
drivers/gpu/drm/amd/amdgpu/amdgpu_amdkfd.c:697 amdgpu_amdkfd_submit_ib() warn: passing freed memory 'f' (line 696)

Fixes: 9ae55f0 ("drm/amdgpu: Follow up change to previous drm scheduler change.")
	Cc: Felix Kuehling <Felix.Kuehling@amd.com>
	Cc: Dan Carpenter <dan.carpenter@linaro.org>
	Cc: Christian König <christian.koenig@amd.com>
	Cc: Alex Deucher <alexander.deucher@amd.com>
	Signed-off-by: Srinivasan Shanmugam <srinivasan.shanmugam@amd.com>
	Reviewed-by: Christian König <christian.koenig@amd.com>
	Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 8b9e525)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-31656
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Sebastian Brzezinka <sebastian.brzezinka@intel.com>
commit 13238dc

A use-after-free / refcount underflow is possible when the heartbeat
worker and intel_engine_park_heartbeat() race to release the same
engine->heartbeat.systole request.

The heartbeat worker reads engine->heartbeat.systole and calls
i915_request_put() on it when the request is complete, but clears
the pointer in a separate, non-atomic step. Concurrently, a request
retirement on another CPU can drop the engine wakeref to zero, triggering
__engine_park() -> intel_engine_park_heartbeat(). If the heartbeat
timer is pending at that point, cancel_delayed_work() returns true and
intel_engine_park_heartbeat() reads the stale non-NULL systole pointer
and calls i915_request_put() on it again, causing a refcount underflow:

```
<4> [487.221889] Workqueue: i915-unordered engine_retire [i915]
<4> [487.222640] RIP: 0010:refcount_warn_saturate+0x68/0xb0
...
<4> [487.222707] Call Trace:
<4> [487.222711]  <TASK>
<4> [487.222716]  intel_engine_park_heartbeat.part.0+0x6f/0x80 [i915]
<4> [487.223115]  intel_engine_park_heartbeat+0x25/0x40 [i915]
<4> [487.223566]  __engine_park+0xb9/0x650 [i915]
<4> [487.223973]  ____intel_wakeref_put_last+0x2e/0xb0 [i915]
<4> [487.224408]  __intel_wakeref_put_last+0x72/0x90 [i915]
<4> [487.224797]  intel_context_exit_engine+0x7c/0x80 [i915]
<4> [487.225238]  intel_context_exit+0xf1/0x1b0 [i915]
<4> [487.225695]  i915_request_retire.part.0+0x1b9/0x530 [i915]
<4> [487.226178]  i915_request_retire+0x1c/0x40 [i915]
<4> [487.226625]  engine_retire+0x122/0x180 [i915]
<4> [487.227037]  process_one_work+0x239/0x760
<4> [487.227060]  worker_thread+0x200/0x3f0
<4> [487.227068]  ? __pfx_worker_thread+0x10/0x10
<4> [487.227075]  kthread+0x10d/0x150
<4> [487.227083]  ? __pfx_kthread+0x10/0x10
<4> [487.227092]  ret_from_fork+0x3d4/0x480
<4> [487.227099]  ? __pfx_kthread+0x10/0x10
<4> [487.227107]  ret_from_fork_asm+0x1a/0x30
<4> [487.227141]  </TASK>
```

Fix this by replacing the non-atomic pointer read + separate clear with
xchg() in both racing paths. xchg() is a single indivisible hardware
instruction that atomically reads the old pointer and writes NULL. This
guarantees only one of the two concurrent callers obtains the non-NULL
pointer and performs the put, the other gets NULL and skips it.

Closes: https://gitlab.freedesktop.org/drm/i915/kernel/-/work_items/15880
Fixes: 058179e ("drm/i915/gt: Replace hangcheck by heartbeats")
	Cc: <stable@vger.kernel.org> # v5.5+
	Signed-off-by: Sebastian Brzezinka <sebastian.brzezinka@intel.com>
	Reviewed-by: Krzysztof Karas <krzysztof.karas@intel.com>
	Reviewed-by: Andi Shyti <andi.shyti@linux.intel.com>
	Signed-off-by: Andi Shyti <andi.shyti@linux.intel.com>
Link: https://lore.kernel.org/r/d4c1c14255688dd07cc8044973c4f032a8d1559e.1775038106.git.sebastian.brzezinka@intel.com
(cherry picked from commit 13238dc)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-43368
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Janusz Krzysztofik <janusz.krzysztofik@linux.intel.com>
commit 06249b4

When a scatterlists table of a GEM shmem object of size 4 GB or more is
populated with pages allocated from a folio, unsigned int .length
attribute of a scatterlist may get overflowed if total byte length of
pages allocated to that single scatterlist happens to reach or cross the
4GB limit.  As a consequence, users of the object may suffer from hitting
unexpected, premature end of the object's backing pages.

[278.780187] ------------[ cut here ]------------
[278.780377] WARNING: CPU: 1 PID: 2326 at drivers/gpu/drm/i915/i915_mm.c:55 remap_sg+0x199/0x1d0 [i915]
...
[278.780654] CPU: 1 UID: 0 PID: 2326 Comm: gem_mmap_offset Tainted: G S   U              6.17.0-rc1-CI_DRM_16981-ged823aaa0607+ #1 PREEMPT(voluntary)
[278.780656] Tainted: [S]=CPU_OUT_OF_SPEC, [U]=USER
[278.780658] Hardware name: Intel Corporation Meteor Lake Client Platform/MTL-P LP5x T3 RVP, BIOS MTLPFWI1.R00.3471.D91.2401310918 01/31/2024
[278.780659] RIP: 0010:remap_sg+0x199/0x1d0 [i915]
...
[278.780786] Call Trace:
[278.780787]  <TASK>
[278.780788]  ? __apply_to_page_range+0x3e6/0x910
[278.780795]  ? __pfx_remap_sg+0x10/0x10 [i915]
[278.780906]  apply_to_page_range+0x14/0x30
[278.780908]  remap_io_sg+0x14d/0x260 [i915]
[278.781013]  vm_fault_cpu+0xd2/0x330 [i915]
[278.781137]  __do_fault+0x3a/0x1b0
[278.781140]  do_fault+0x322/0x640
[278.781143]  __handle_mm_fault+0x938/0xfd0
[278.781150]  handle_mm_fault+0x12c/0x300
[278.781152]  ? lock_mm_and_find_vma+0x4b/0x760
[278.781155]  do_user_addr_fault+0x2d6/0x8e0
[278.781160]  exc_page_fault+0x96/0x2c0
[278.781165]  asm_exc_page_fault+0x27/0x30
...

That issue was apprehended by the author of a change that introduced it,
and potential risk even annotated with a comment, but then never addressed.

When adding folio pages to a scatterlist table, take care of byte length
of any single scatterlist not exceeding max_segment.

Fixes: 0b62af2 ("i915: convert shmem_sg_free_table() to use a folio_batch")
Closes: https://gitlab.freedesktop.org/drm/i915/kernel/-/issues/14809
	Cc: Matthew Wilcox (Oracle) <willy@infradead.org>
	Cc: Andrew Morton <akpm@linux-foundation.org>
	Cc: stable@vger.kernel.org # v6.5+
	Signed-off-by: Janusz Krzysztofik <janusz.krzysztofik@linux.intel.com>
	Reviewed-by: Andi Shyti <andi.shyti@linux.intel.com>
	Signed-off-by: Andi Shyti <andi.shyti@linux.intel.com>
Link: https://lore.kernel.org/r/20260224094944.2447913-2-janusz.krzysztofik@linux.intel.com
(cherry picked from commit 06249b4)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1590
cve CVE-2026-43370
Rebuild_History Non-Buildable kernel-5.14.0-687.47.1.el9_8
commit-author Alysa Liu <Alysa.Liu@amd.com>
commit c7c5732

Replace non-atomic vm->process_info assignment with cmpxchg()
to prevent race when parent/child processes sharing a drm_file
both try to acquire the same VM after fork().

	Reviewed-by: Harish Kasiviswanathan <Harish.Kasiviswanathan@amd.com>
	Signed-off-by: Alysa Liu <Alysa.Liu@amd.com>
	Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit c7c5732)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
Rebuild_History BUILDABLE
Rebuilding Kernel from rpm changelog with Fuzz Limit: 87.50%
Number of commits in upstream range v5.14~1..kernel-mainline: 394115
Number of commits in rpm: 84
Number of commits matched with upstream: 67 (79.76%)
Number of commits in upstream but not in rpm: 394049
Number of commits NOT found in upstream: 17 (20.24%)

Rebuilding Kernel on Branch rocky9_8_rebuild_kernel-5.14.0-687.47.1.el9_8 for kernel-5.14.0-687.47.1.el9_8
Clean Cherry Picks: 51 (76.12%)
Empty Cherry Picks: 14 (20.90%)
_______________________________

Full Details Located here:
ciq/ciq_backports/kernel-5.14.0-687.47.1.el9_8/rebuild.details.txt

Includes:
* git commit header above
* Empty Commits with upstream SHA
* RPM ChangeLog Entries that could not be matched

Individual Empty Commit failures contained in the same containing directory.
The git message for empty commits will have the path for the failed commit.
File names are the first 8 characters of the upstream SHA
@PlaidCat PlaidCat self-assigned this Sep 15, 2026
@PlaidCat
PlaidCat requested review from a team September 15, 2026 04:48
bmastbergen
bmastbergen previously approved these changes Sep 15, 2026

@bmastbergen bmastbergen left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🥌

@bmastbergen
bmastbergen requested a review from a team September 15, 2026 13:39
jira KERNEL-1595
cve CVE-2026-43248
Rebuild_History Non-Buildable kernel-5.14.0-687.48.1.el9_8
commit-author Eugenio Pérez <eperezma@redhat.com>
commit cd025c1
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.48.1.el9_8/cd025c1e.failed

Remove duplication by consolidating these here.  This reduces the
posibility of a parent driver missing them.

While we're at it, fix a bug in vdpa_sim where a valid ASID can be
assigned to a group equal to ngroups, causing an out of bound write.

	Cc: stable@vger.kernel.org
Fixes: bda324f ("vdpasim: control virtqueue support")
	Acked-by: Jason Wang <jasowang@redhat.com>
	Signed-off-by: Eugenio Pérez <eperezma@redhat.com>
	Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-Id: <20260119143306.1818855-2-eperezma@redhat.com>
(cherry picked from commit cd025c1)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	drivers/vdpa/mlx5/net/mlx5_vnet.c
jira KERNEL-1595
cve CVE-2026-64015
Rebuild_History Non-Buildable kernel-5.14.0-687.48.1.el9_8
commit-author Linus Torvalds <torvalds@linux-foundation.org>
commit 43a1e37

Nicholas Carlini reports that the keyring code calls assoc_array_find()
in find_key_to_update() without holding the RCU read lock, while the
assoc_array_gc() code really is designed around removing the node from
the tree and then freeing it after an RCU grace-period.

The regular key handling doesn't see this because holding the keyring
semaphore hides any lifetime issues, but the persistent key handling
uses a different model.

Instead of extending the keyring locking, just do the simple RCU locking
that the assoc_array was designed for.

	Reported-by: Nicholas Carlini <npc@anthropic.com>
	Cc: David Howells <dhowells@redhat.com>
	Cc: Jarkko Sakkinen <jarkko@kernel.org>
	Cc: Paul Moore <paul@paul-moore.com>
	Cc: James Morris James Morris <jmorris@namei.org>
	Cc: Serge E. Hallyn <serge@hallyn.com>
	Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
(cherry picked from commit 43a1e37)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1595
cve CVE-2026-68294
Rebuild_History Non-Buildable kernel-5.14.0-687.48.1.el9_8
Rebuild_CHGLOG: - net: qrtr: restrict socket creation to the initial network namespace (CKI Backport Bot) [RHEL-240242] {CVE-2026-68294}
Rebuild_FUZZ: 80.30%
commit-author Greg Jumper <greg.jumper@oracle.com>
commit ebf71dd
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.48.1.el9_8/ebf71dd4.failed

Prevent using RDS/IB in network namespaces other than the initial one.
The existing RDS/IB code will not work properly in non-initial network
namespaces.

Fixes: d5a8ac2 ("RDS-TCP: Make RDS-TCP work correctly when it is set up in a netns other than init_net")
	Reported-by: syzbot+da8e060735ae02c8f3d1@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=da8e060735ae02c8f3d1
	Signed-off-by: Greg Jumper <greg.jumper@oracle.com>
	Signed-off-by: Allison Henderson <achender@kernel.org>
Link: https://patch.msgid.link/20260408080420.540032-3-achender@kernel.org
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit ebf71dd)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/rds/ib.c
jira KERNEL-1595
cve CVE-2026-63923
Rebuild_History Non-Buildable kernel-5.14.0-687.48.1.el9_8
commit-author Michael Bommarito <michael.bommarito@gmail.com>
commit 2156a29
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.48.1.el9_8/2156a29a.failed

rvu_mbox_handler_rep_event_notify() in drivers/net/ethernet/marvell/
octeontx2/af/rvu_rep.c queues a sender-controlled REP_EVENT_NOTIFY
request body verbatim, and rvu_rep_up_notify() then forwards
event->pcifunc (the nested body field, distinct from the
AF-normalised header pcifunc) into rvu_get_pfvf(), rvu_get_pf() and
the AF->PF mailbox device index without any bounds check.

A VF attached to a PF that has been put into switchdev
representor mode reaches this path: the VF mailbox handler
otx2_pfvf_mbox_handler() forwards every message id including
MBOX_MSG_REP_EVENT_NOTIFY to AF without an allowlist, and the AF
dispatcher rewrites only msg->pcifunc, leaving struct
rep_event::pcifunc attacker-controlled.  The sibling
rvu_mbox_handler_esw_cfg() refuses requests whose header pcifunc
is not rvu->rep_pcifunc; this handler has no equivalent gate.

An out-of-range body pcifunc selects an &rvu->pf[]/&rvu->hwvf[]
element past the allocated array and, for RVU_EVENT_MAC_ADDR_CHANGE,
turns into a six-byte attacker-chosen OOB ether_addr_copy() target
inside the queued worker; KASAN reports a slab-out-of-bounds write
in rvu_rep_wq_handler.

Reject malformed requests at the handler entry by gating on
is_pf_func_valid(), which is already the canonical PF/VF range check
in this driver; expose it via rvu.h so callers in rvu_rep.c can use
it instead of open-coding the same range arithmetic.

Fixes: b8fea84 ("octeontx2-pf: Add support to sync link state between representor and VFs")
	Cc: stable@vger.kernel.org
	Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Link: https://patch.msgid.link/20260520154157.1439319-1-michael.bommarito@gmail.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 2156a29)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	drivers/net/ethernet/marvell/octeontx2/af/rvu_rep.c
jira KERNEL-1595
Rebuild_History Non-Buildable kernel-5.14.0-687.48.1.el9_8
commit-author Andreas Gruenbacher <agruenba@redhat.com>
commit 5a15907
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.48.1.el9_8/5a15907f.failed

These two helpers only hide the locking operation; they do not make
the code more readable.

Created with:

sed -i -e 's:gfs2_log_unlock(sdp):spin_unlock(\&sdp->sd_log_lock):' \
       -e 's:gfs2_log_lock(sdp):spin_lock(\&sdp->sd_log_lock):'

	Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
(cherry picked from commit 5a15907)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	fs/gfs2/glops.c
#	fs/gfs2/log.c
#	fs/gfs2/trans.c
jira KERNEL-1595
Rebuild_History Non-Buildable kernel-5.14.0-687.48.1.el9_8
commit-author Andreas Gruenbacher <agruenba@redhat.com>
commit 1086689

Move gfs2_remove_from_journal() from meta_io.c to log.c and fix a minor
indentation glitch.

With that, gfs2_remove_from_ail() is now only used inside log.c, so it
can be made static.

	Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
(cherry picked from commit 1086689)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1595
Rebuild_History Non-Buildable kernel-5.14.0-687.48.1.el9_8
commit-author Andreas Gruenbacher <agruenba@redhat.com>
commit 9e34adb

Rename trans_drain() to gfs2_trans_drain().

Add a new gfs2_trans_drain_list() helper and use it in
gfs2_trans_drain() to reduce code duplication.

	Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
(cherry picked from commit 9e34adb)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1595
Rebuild_History Non-Buildable kernel-5.14.0-687.48.1.el9_8
commit-author Andreas Gruenbacher <agruenba@redhat.com>
commit 6e1a833
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.48.1.el9_8/6e1a833d.failed

The locking in gfs2_trans_add_data() and gfs2_trans_add_meta() doesn't
follow the usual coding pattern of checking bh->b_private under lock,
allocating a new bufdata object with the locks dropped, and re-checking
once the lock has been reacquired.  Both functions set bh->b_private
without holding the buffer lock.  Fix that.

Also, in gfs2_trans_add_meta(), taking the folio lock during the
allocation doesn't actually do anything useful.

	Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
(cherry picked from commit 6e1a833)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	fs/gfs2/trans.c
Rebuild_History BUILDABLE
Rebuilding Kernel from rpm changelog with Fuzz Limit: 87.50%
Number of commits in upstream range v5.14~1..kernel-mainline: 394115
Number of commits in rpm: 14
Number of commits matched with upstream: 8 (57.14%)
Number of commits in upstream but not in rpm: 394107
Number of commits NOT found in upstream: 6 (42.86%)

Rebuilding Kernel on Branch rocky9_8_rebuild_kernel-5.14.0-687.48.1.el9_8 for kernel-5.14.0-687.48.1.el9_8
Clean Cherry Picks: 3 (37.50%)
Empty Cherry Picks: 5 (62.50%)
_______________________________

Full Details Located here:
ciq/ciq_backports/kernel-5.14.0-687.48.1.el9_8/rebuild.details.txt

Includes:
* git commit header above
* Empty Commits with upstream SHA
* RPM ChangeLog Entries that could not be matched

Individual Empty Commit failures contained in the same containing directory.
The git message for empty commits will have the path for the failed commit.
File names are the first 8 characters of the upstream SHA
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants