已合并
CVE修复: OpenHarmony-6.0-Release (76 个安全补丁) - 2026-04-20 #353
CVE修复: OpenHarmony-6.0-Release (76 个安全补丁) - 2026-04-20 #353
已合并
何京晶创建于 4月20日
何京晶
何京晶
4月20日

CVE 修复列表

CVE ID 标题 Commit
CVE-2024-27065 netfilter: nf_tables: do not compare internal tabl... 4a0e7f2decbf
CVE-2024-35843 iommu/vt-d: Use device rbtree in iopf reporting pa... def054b01a86
CVE-2024-57952 Revert "libfs: fix infinite directory reads for of... b662d858131d
CVE-2025-22022 usb: xhci: Apply the link chain quirk on NEC isoc ... bb0ba4cb1065
CVE-2025-38099 Bluetooth: Disable SCO support if READ_VOICE_SETTI... 14d17c78a4b1
CVE-2025-38206 exfat: fix double free in delayed_free 1f3d9724e16d
CVE-2025-38234 sched/rt: Fix race in push_rt_task 690e47d1403e
CVE-2025-38333 f2fs: fix to bail out in get_new_segment() bb5eb8a5b222
CVE-2025-38555 usb: gadget : fix use-after-free in composite_dev_... 151c0aa896c4
CVE-2025-38566 sunrpc: fix handling of server side tls alerts bee47cb026e7
CVE-2025-38571 sunrpc: fix client side handling of tls alerts cc5d59081fa2
CVE-2025-38578 f2fs: fix to avoid UAF in f2fs_sync_inode_meta() 7c30d7993013
CVE-2025-38579 f2fs: fix KMSAN uninit-value in extent_info usage 154467f4ad03
CVE-2025-38588 ipv6: prevent infinite loop in rt6_nlmsg_size() 54e6fe9dd3b0
CVE-2025-38609 PM / devfreq: Check governor before using governor... bab7834c0382
CVE-2025-38622 net: drop UFO packets in udp_rcv_segment() d46e51f1c78b
CVE-2025-38632 pinmux: fix race causing mux_owner NULL with activ... 0b075c011032
CVE-2025-38635 clk: davinci: Add NULL check in davinci_lpsc_clk_r... 13de464f445d
CVE-2025-38640 bpf: Disable migration in nf_hook_run_bpf(). 17ce3e5949bc
CVE-2025-38644 wifi: mac80211: reject TDLS operations when statio... 16ecdab5446f
CVE-2025-38653 proc: use the same treatment to check proc_lseek a... ff7ec8dc1b64
CVE-2025-38680 media: uvcvideo: Fix 1-byte out-of-bounds read in ... 782b6a718651
CVE-2025-38693 media: dvb-frontends: w7090p: fix null-ptr-deref i... ed0234c8458b
CVE-2025-38694 media: dvb-frontends: dib7090p: fix null-ptr-deref... ce5cac69b2ed
CVE-2025-38701 ext4: do not BUG when INLINE_DATA_FL lacks system.... 099b847ccc6c
CVE-2025-38704 rcu/nocb: Fix possible invalid rdp's->nocb_cb_kthr... 1bba3900ca18
CVE-2025-38709 loop: Avoid updating block size under exclusive ow... 7e49538288e5
CVE-2025-38725 net: usb: asix_devices: add phy_mask for ax88772 m... 4faff70959d5
CVE-2025-39689 ftrace: Also allocate and copy hash for reading of... bfb336cf97df
CVE-2025-71074 functionfs: fix the open/removal races e5bf5ee26663
CVE-2025-71095 net: stmmac: fix the crash issue for zero copy XDP... a48e23221000
CVE-2025-71200 mmc: sdhci-of-dwcmshc: Prevent illegal clock reduc... 3009738a855c
CVE-2025-71202 iommu/sva: invalidate stale IOTLB entries for kern... e37d5a2d60a3
CVE-2025-71224 wifi: mac80211: ocb: skip rx_no_sta when interface... ff4071c60018
CVE-2025-71227 wifi: mac80211: don't WARN for connections on inva... 99067b58a408
CVE-2026-22978 wifi: avoid kernel-infoleak from struct iw_point 21cbf883d073
CVE-2026-22979 net: fix memory leak in skb_segment_list for GRO p... 238e03d04662
CVE-2026-23060 crypto: authencesn - reject too-short AAD (assocle... 2397e9264676
CVE-2026-23071 regmap: Fix race condition in hwspinlock irqsave r... 4b58aac989c1
CVE-2026-23101 leds: led-class: Only Add LED to leds_list when it... d1883cefd317
CVE-2026-23107 arm64/fpsimd: signal: Allocate SSVE storage when r... ea8ccfddbce0
CVE-2026-23120 l2tp: avoid one data-race in l2tp_tunnel_del_work(... 7a29f6bf60f2
CVE-2026-23124 ipv6: annotate data-race in ndisc_router_discovery... 9a063f96d87e
CVE-2026-23128 arm64: Set __nocfi on swsusp_arch_resume() e2f8216ca2d8
CVE-2026-23168 flex_proportions: make fprop_new_period() hardirq ... dd9e2f5b38f1
CVE-2026-23226 ksmbd: add chann_lock to protect ksmbd_chann_list ... 4f3a06cc5797
CVE-2026-23227 drm/exynos: vidi: use ctx->lock to protect struct ... 52b330799e2d
CVE-2026-23245 net/sched: act_gate: snapshot parameters with RCU ... 62413a9c3cb1
CVE-2026-23246 wifi: mac80211: bounds-check link_id in ieee80211_... 162d331d833d
CVE-2026-23253 media: dvb-core: fix wrong reinitialization of rin... bfbc0b5b32a8
CVE-2026-23254 net: gro: fix outer network offset 5c2c3c38be39
CVE-2026-23255 net: add proper RCU protection to /proc/net/ptype f613e8b4afea
CVE-2026-23260 regmap: maple: free entry on mas_store_gfp() failu... f3f380ce6b3d
CVE-2026-23270 net/sched: Only allow act_ct to bind to clsact/ing... 11cb63b0d1a0
CVE-2026-23360 nvme: fix admin queue leak on controller reset b84bb7bd913d
CVE-2026-23461 Bluetooth: L2CAP: Fix use-after-free in l2cap_unre... 752a6c9596dd
CVE-2026-31411 net: atm: fix crash due to unvalidated vcc pointer... ae88a5d2f29b
CVE-2026-31412 usb: gadget: f_mass_storage: Fix potential integer... 8479891d1f04
CVE-2026-31414 netfilter: nf_conntrack_expect: use expect->helper f01794106042
CVE-2026-31415 ipv6: avoid overflows in ip6_datagram_send_ctl() 4e453375561f
CVE-2026-31416 netfilter: nfnetlink_log: account for netlink head... 6d52a4a0520a
CVE-2026-31417 net/x25: Fix overflow when accumulating packets a1822cb524e8
CVE-2026-31418 netfilter: ipset: drop logically empty buckets in ... 9862ef9ab0a1
CVE-2026-31419 net: bonding: fix use-after-free in bond_xmit_broa... 2884bf72fb8f
CVE-2026-31420 bridge: mrp: reject zero test interval to avoid OO... fa6e24963342
CVE-2026-31421 net/sched: cls_fw: fix NULL pointer dereference on... faeea8bbf6e9
CVE-2026-31422 net/sched: cls_flow: fix NULL pointer dereference ... 1a280dd4bd1d
CVE-2026-31423 net/sched: sch_hfsc: fix divide-by-zero in rtsc_mi... 4576100b8cd0
CVE-2026-31424 netfilter: x_tables: restrict xt_check_match/xt_ch... 3d5d488f1177
CVE-2026-31425 rds: ib: reject FRMR registration before IB connec... a54ecccfae62
CVE-2026-31426 ACPI: EC: clean up handlers on probe failure in ac... f6484cadbcaf
CVE-2026-31427 netfilter: nf_conntrack_sip: fix use of uninitiali... 6a2b724460cb
CVE-2026-31428 netfilter: nfnetlink_log: fix uninitialized paddin... 52025ebaa29f
CVE-2026-31788 xen/privcmd: restrict usage in unprivileged domU 453b8fb68f36

来源: Cherry-pick from stable-tags/v6.9-rc3~30^2~2^2~4

统计

  • 总数: 102
  • 成功: 76
  • 空提交(已存在): 15
  • 失败: 1
  • 跳过: 10

修复详情

CVE-2024-27065

  • Commit: 4a0e7f2decbf9bd72461226f1f5f7dcc4b08f139
  • Stable: tags/v6.9-rc1~31^2^2~1
  • 标题: netfilter: nf_tables: do not compare internal table flags on updates

CVE-2024-35843

  • Commit: def054b01a867822254e1dda13d587f5c7a99e2a
  • Stable: tags/v6.9-rc1~153^2^5~9
  • 标题: iommu/vt-d: Use device rbtree in iopf reporting path

CVE-2024-57952

  • Commit: b662d858131da9a8a14e68661656989b14dbf113
  • Stable: tags/v6.14-rc1~211^2^2~2
  • 标题: Revert "libfs: fix infinite directory reads for offset dir"

CVE-2025-22022

  • Commit: bb0ba4cb1065e87f9cc75db1fa454e56d0894d01
  • Stable: tags/v6.15-rc1~46^2~22
  • 标题: usb: xhci: Apply the link chain quirk on NEC isoc endpoints

CVE-2025-38099

  • Commit: 14d17c78a4b1660c443bae9d38c814edea506f62
  • Stable: tags/v6.15-rc1~160^2~3^2~26
  • 标题: Bluetooth: Disable SCO support if READ_VOICE_SETTING is unsupported/broken

CVE-2025-38206

  • Commit: 1f3d9724e16d62c7d42c67d6613b8512f2887c22
  • Stable: tags/v6.16-rc1~142^2~1
  • 标题: exfat: fix double free in delayed_free

CVE-2025-38234

  • Commit: 690e47d1403e90b7f2366f03b52ed3304194c793
  • Stable: tags/v6.16-rc1~197^2~11
  • 标题: sched/rt: Fix race in push_rt_task

CVE-2025-38333

  • Commit: bb5eb8a5b222fa5092f60d5555867a05ebc3bdf2
  • Stable: tags/v6.16-rc1~115^2~23
  • 标题: f2fs: fix to bail out in get_new_segment()

CVE-2025-38555

  • Commit: 151c0aa896c47a4459e07fee7d4843f44c1bb18e
  • Stable: tags/v6.17-rc1~175^2~17
  • 标题: usb: gadget : fix use-after-free in composite_dev_cleanup()

CVE-2025-38566

  • Commit: bee47cb026e762841f3faece47b51f985e215edb
  • Stable: tags/v6.17-rc2~25^2
  • 标题: sunrpc: fix handling of server side tls alerts

CVE-2025-38571

  • Commit: cc5d59081fa26506d02de2127ab822f40d88bc5a
  • Stable: tags/v6.17-rc1~21^2~5
  • 标题: sunrpc: fix client side handling of tls alerts

CVE-2025-38578

  • Commit: 7c30d79930132466f5be7d0b57add14d1a016bda
  • Stable: tags/v6.17-rc1~45^2~85
  • 标题: f2fs: fix to avoid UAF in f2fs_sync_inode_meta()

CVE-2025-38579

  • Commit: 154467f4ad033473e5c903a03e7b9bca7df9a0fa
  • Stable: tags/v6.17-rc1~45^2~97
  • 标题: f2fs: fix KMSAN uninit-value in extent_info usage

CVE-2025-38588

  • Commit: 54e6fe9dd3b0e7c481c2228782c9494d653546da
  • Stable: tags/v6.17-rc1~126^2~2^2^2~2
  • 标题: ipv6: prevent infinite loop in rt6_nlmsg_size()

CVE-2025-38609

  • Commit: bab7834c03820eb11269bc48f07c3800192460d2
  • Stable: tags/v6.17-rc1~190^2~3^4^2~4
  • 标题: PM / devfreq: Check governor before using governor->name

CVE-2025-38622

  • Commit: d46e51f1c78b9ab9323610feb14238d06d46d519
  • **Sta
likedislike
Pull Request已成功合入, 合并人@openharmony_ci
(感谢 何京晶 的贡献)
何京晶何京晶
4月20日 关联了issue:release-6.0-cve
何京晶何京晶
4月20日 强制推送  103 个提交:3d673d9d-76 commits from branch OpenHarmony-6.0-Release42141a71-mm: fix ptdesc_test_kernel const qualifier,f5dc339a-sched: add task_current_donor compatibility helper,7ee6d994-Bluetooth: add read_voice_setting_capable backport helper,bd3ce900-net/sched: sch_hfsc: fix divide-by-zero in rtsc_min(),59c2ba8e-netfilter: nfnetlink_log: account for netlink header size,b24cb1df-netfilter: ipset: drop logically empty buckets in mtype_del,dad3534a-netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD,92876113-netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP,4ad3b2bb-rds: ib: reject FRMR registration before IB connection is established,d415289f-netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp,6b19f010-ACPI: EC: clean up handlers on probe failure in acpi_ec_setup(),f89f69f2-net: bonding: fix use-after-free in bond_xmit_broadcast(),c4e8a622-net/sched: cls_fw: fix NULL pointer dereference on shared blocks,49ba6811-bridge: mrp: reject zero test interval to avoid OOM panic,53dc3f6c-net/x25: Fix overflow when accumulating packets,38b3a90d-ipv6: avoid overflows in ip6_datagram_send_ctl(),0d6bc1ad-net/sched: cls_flow: fix NULL pointer dereference on shared blocks,07028734-usb: gadget: f_mass_storage: Fix potential integer overflow in check_command_size_in_blocks(),9f0655b4-net: atm: fix crash due to unvalidated vcc pointer in sigd_send(),37d48dc0-net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks,e7ec97ea-netfilter: nf_conntrack_expect: use expect->helper,d1062b3c-nvme: fix admin queue leak on controller reset,44df8985-xen/privcmd: restrict usage in unprivileged domU,156993dd-net/sched: act_gate: snapshot parameters with RCU on replace,8b03cee9-drm/exynos: vidi: use ctx->lock to protect struct vidi_context member variables related to memory alloc/free,c9410b6f-ksmbd: add chann_lock to protect ksmbd_chann_list xarray,e94990c8-Merge remote-tracking branch 'origin/OpenHarmony-6.0-Release' into cve-fix-20260420-OpenHarmony-6.0-Release
openharmony_ciopenharmony_ci成员
4月20日 添加了label:waiting_on_author
openharmony_ci
openharmony_ci成员
4月20日 评论:

感谢提交 Pull Requests!如果您提交的PR已经开发完毕,请评论 "start build" 触发门禁,更多交互操作,请访问OpenHarmony社区支持命令清单。如果需要调整订阅PR、Issue的变更状态,请访问订阅链接


Thanks for submitting the pull request. If your Pull Request has already been developed, you can leave a "start build" comment to trigger the gated system. For more commands, please visit OpenHarmony Command List. If you need to change the subscription of a Pull Request or Issue, please visit the link.

likedislike
openharmony_ciopenharmony_ci成员
4月20日 添加了label:dco检查成功
何京晶何京晶
4月20日 修改了pull request 的描述
何京晶
何京晶
4月20日 评论:

start build

likedislike
openharmony_ci
openharmony_ci成员
4月20日 评论:

该提交没有关联任何Issue,请先关联一个Issue后再触发构建
The PR is not associated with any Issue, Please associate the PR with one Issue before trigger build.

likedislike
何京晶何京晶
4月20日 关联了issue:CVE漏洞处理
何京晶何京晶
4月20日 删除了关联的issue:CVE漏洞处理
何京晶何京晶
4月20日 关联了issue:6.6 Release 6.0 cve
何京晶
何京晶
4月20日 评论:

start build

likedislike
openharmony_ci
openharmony_ci成员
4月20日 评论:

首次触发
门禁构建开始,包含静态检查、代码编译和测试【hispark_taurus_Linux编译, dayu200测试, dayu200编译, hispark_taurus_LiteOS测试, hispark_taurus_LiteOS编译】,预计在60分钟内完成,门禁结果会同步发送到注册邮箱。您可以通过如下链接跟踪门禁进展:http://dcp.openharmony.cn/workbench/cicd/detail/69e61ba664650f998b155dd0/runlist

likedislike
openharmony_ciopenharmony_ci成员
4月20日 添加了label:编译成功
openharmony_ciopenharmony_ci成员
4月20日 添加了label:静态检查成功
openharmony_ciopenharmony_ci成员
4月20日 添加了label:冒烟测试成功
openharmony_ciopenharmony_ci成员
4月20日 通过测试
openharmony_ci
openharmony_ci成员
4月20日 评论:

代码门禁通过
您可以通过如下链接查看门禁报告:http://dcp.openharmony.cn/workbench/cicd/detail/69e61ba664650f998b155dd0/runlist

静态检查:

# check type result report
1 codeCheck pass >>>

编译测试:
# Device build result test result package
1 hispark_taurus_LiteOS success success >>>
2 hispark_taurus_Linux success NA >>>
3 dayu200 success success >>>

likedislike
openharmony_ciopenharmony_ci成员
4月20日 删除了label:waiting_on_author
openharmony_ciopenharmony_ci成员
4月20日 添加了label:waiting_for_review
openharmony_ci
openharmony_ci成员
4月20日 评论:

您好,Committer @z-jax @leejiawei @weiyj__lk ,请分配检视人员检视该PR,可以通过命令"assign [@someone_id]"分配检视人员,也可以直接评论"assign"分配给自己进行检视。


Hello, Committer @z-jax @leejiawei @weiyj__lk . Please assign someone to review the PR. You can assign a reviewer by using the command "assign [@someone_id]", or you can comment "assign" to review the PR by yourself.

likedislike
何京晶
何京晶
4月21日 评论:

image.png

likedislike
lijiaweilijiawei成员
4月21日 通过审查
openharmony_ci
openharmony_ci成员
4月21日 评论:

验证结果已超过12小时,之前验证结果无效,自动重新触发构建,请关注最新验证结果

likedislike
openharmony_ci
openharmony_ci成员
4月21日 评论:

start build

likedislike
openharmony_ciopenharmony_ci成员
4月21日 删除了label:编译成功
openharmony_ciopenharmony_ci成员
4月21日 删除了label:静态检查成功
openharmony_ciopenharmony_ci成员
4月21日 删除了label:冒烟测试成功
openharmony_ci
openharmony_ci成员
4月21日 评论:

上次构建已超过12小时,重新全量验证,重置所有关联PR的验证状态
门禁构建开始,包含静态检查、代码编译和测试【hispark_taurus_LiteOS测试, hispark_taurus_LiteOS编译, dayu200测试, hispark_taurus_Linux编译, dayu200编译】,预计在60分钟内完成,门禁结果会同步发送到注册邮箱。您可以通过如下链接跟踪门禁进展:http://dcp.openharmony.cn/workbench/cicd/detail/69e718d164650f998bbe9d8a/runlist

likedislike
zhongxiaoming
zhongxiaoming成员
4月21日 评论:

approve

likedislike
openharmony_ciopenharmony_ci成员
4月21日 添加了label:编译成功
openharmony_ciopenharmony_ci成员
4月21日 添加了label:静态检查成功
openharmony_ciopenharmony_ci成员
4月21日 添加了label:冒烟测试成功
openharmony_ciopenharmony_ci成员
4月21日 通过测试
openharmony_ci
openharmony_ci成员
4月21日 评论:

代码门禁通过
您可以通过如下链接查看门禁报告:http://dcp.openharmony.cn/workbench/cicd/detail/69e718d164650f998bbe9d8a/runlist

静态检查:

# check type result report
1 codeCheck pass >>>

编译测试:
# Device build result test result package
1 hispark_taurus_LiteOS success success >>>
2 hispark_taurus_Linux success NA >>>
3 dayu200 success success >>>

likedislike
openharmony_ci
openharmony_ci成员
4月21日 评论:

您好,Committer @z-jax @leejiawei @weiyj__lk ,请分配检视人员检视该PR,可以通过命令"assign [@someone_id]"分配检视人员,也可以直接评论"assign"分配给自己进行检视。


Hello, Committer @z-jax @leejiawei @weiyj__lk . Please assign someone to review the PR. You can assign a reviewer by using the command "assign [@someone_id]", or you can comment "assign" to review the PR by yourself.

likedislike
openharmony_ciopenharmony_ci成员
4月21日 合入了pull request,合并节点 SHA:94e4b6acc056ecd1d1ff0a0c0ddf0acb4a8a7d54
openharmony_ciopenharmony_ci成员
4月21日 删除了label:waiting_for_review
openharmony_ciopenharmony_ci成员
4月21日 添加了label:merged