已合并
CVE修复: kernel_linux_6.6 master (20 个有效安全补丁) - 2026-05-21 #383
CVE修复: kernel_linux_6.6 master (20 个有效安全补丁) - 2026-05-21 #383
已合并
Provii创建于 5月21日
Provii
Provii
5月21日

CVE 修复列表

本 PR 针对 kernel_linux_6.6 的 master 分支,从 Linux 6.6 stable 树 cherry-pick 安全补丁。

统计概览

状态 数量
有效修复 20
修复后被 Revert(编译错误) 9
PR 中 commit 涉及 CVE 29

有效修复

# CVE ID Commit 标题
1 CVE-2026-23343 9c25eb234a6d xdp: produce a warning when calculated tailroom is negative
2 CVE-2026-23368 433e3809e920 net: phy: register phy led_triggers during probe to avoid AB-BA d
3 CVE-2026-23388 94df591b771f Squashfs: check metadata block offset is within range
4 CVE-2026-23391 7bb0f9d29aa3 netfilter: xt_CT: drop pending enqueued packets on template remov
5 CVE-2026-23419 a07a5a0d20a3 net/rds: Fix circular locking dependency in rds_tcp_tune
6 CVE-2026-23439 7537772204d1 udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG
7 CVE-2026-31414 876fb834e15a netfilter: nf_conntrack_expect: use expect->helper
8 CVE-2026-31415 98754dfdc91e ipv6: avoid overflows in ip6_datagram_send_ctl()
9 CVE-2026-31446 639688a91069 ext4: fix use-after-free in update_super_work when racing with um
10 CVE-2026-31448 c5b401a48a98 ext4: avoid infinite loops caused by residual data
11 CVE-2026-31451 abd9cea038cc ext4: replace BUG_ON with proper error handling in ext4_read_inli
12 CVE-2026-31452 55e2a2297550 ext4: convert inline data to extents when truncate exceeds inline
13 CVE-2026-31453 6adf88e38824 xfs: avoid dereferencing log items after push callbacks
14 CVE-2026-31473 161da64d456a media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mute
15 CVE-2026-31504 c4da2004bf8d net: fix fanout UAF in packet_release() via NETDEV_UP race
16 CVE-2026-31523 e607ed131049 nvme-pci: ensure we're polling a polled queue
17 CVE-2026-31528 d22dce73b9fa perf: Make sure to use pmu_ctx->pmu for groups
18 CVE-2026-31555 b698c643ddcf futex: Clear stale exiting pointer in futex_lock_pi() retry path
19 CVE-2026-31630 bac2268e4e54 rxrpc: proc: size address buffers for %pISpc output
20 CVE-2026-31681 bd90f7f0ba11 netfilter: xt_multiport: validate range encoding in checkentry

修复后被 Revert(AI backporting 编译错误,净效果为 0)

# CVE ID Commit 标题
1 CVE-2026-31449 6dcbcdc4b9e1 ext4: validate p_idx bounds in ext4_ext_correct_indexes
2 CVE-2026-31499 fb9377314856 Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del()
3 CVE-2026-31503 74da00ae1d89 udp: Fix wildcard bind conflict check when using hash2
4 CVE-2026-31516 49d0ba86e817 xfrm: prevent policy_hthresh.work from racing with netns teardown
5 CVE-2026-31531 b787896799f5 ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()
6 CVE-2026-31702 9512102bf861 f2fs: fix use-after-free of sbi in f2fs_compress_write_end_io()
7 CVE-2026-31722 89fd4df39260 usb: gadget: f_rndis: Fix net_device lifecycle with device_move
8 CVE-2026-31771 a7ce71b24cbc Bluetooth: hci_event: move wake reason storage into validated eve
9 CVE-2026-43022 0c16ae40d9b5 Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if

测试状态

  • 编译:待触发 CI
  • 测试:待执行

关联 Issue

已关联 Issue: #723


更新时间: 2026-05-22

likedislike
Pull Request已成功合入, 合并人@openharmony_ci
(感谢 Provii 的贡献)
ProviiProvii
5月21日 关联了issue:CVE修复跟踪: kernel_linux_6.6 master
openharmony_ciopenharmony_ci成员
5月21日 添加了label:waiting_on_author
openharmony_ci
openharmony_ci成员
5月21日 评论:

感谢提交 Pull Requests !此PR未通过DCO校验。
校验失败可能原因:

1. 未签署“DCO协议”(开发者原创声明协议),在线签署、查看签署状态。

2. Commits 中未包含 Signed-off-by信息,参考FAQ处理。

修复上述问题后,在PR的评论框输入“check dco” ,单击”评论”,系统将再次进行DCO校验。

当前检测到如下Commits的Signed-off-by邮箱未签署DCO协议:


当前检测到如下Commits 未包含Signed-off-by信息:

Thanks for submitting a pull request. This pull request has not passed the DCO check.
Possible causes:

1. You have not signed the Developer Certificate of Origin (DCO). Sign the DCO and check DCO status.

2. The commits do not contain the Signed-off-by information. To resolve this issue, see FAQs.

After resolving the preceding issues, enter check dco in the comment box of this pull request and click Comment. The system will check DCO status again.

The Signed-off-by emails in the following commits have not signed the DCO:


The following commits do not contain the Signed-off-by information:
likedislike
openharmony_ciopenharmony_ci成员
5月21日 添加了label:dco检查失败
openharmony_ci
openharmony_ci成员
5月21日 评论:

感谢提交 Pull Requests !此PR未通过DCO校验。
您可以通过DCO例外申请来解除限制


Thanks for submitting a pull request. This pull request has not passed the DCO check.
You can apply for DCO Exceptions Request to lift restrictions

likedislike
此处折叠了46条消息 查看更多
openharmony_ci
openharmony_ci成员
5月25日 评论:

您好,Committer @z-jax @leejiawei @weiyj__lk ,请分配检视人员检视该PR,可以通过命令"assign [@someone_id]"分配检视人员,也可以直接评论"assign"分配给自己进行检视。


Hello, Committer @z-jax @leejiawei @weiyj__lk . Please assign someone to review the PR. You can assign a reviewer by using the command "assign [@someone_id]", or you can comment "assign" to review the PR by yourself.

likedislike
openharmony_ciopenharmony_ci成员
5月25日 关闭了关联的issue
openharmony_ciopenharmony_ci成员
5月25日 合入了pull request,合并节点 SHA:8873eef5c99433c64d8dde1a629b6c3d10bd4dce
openharmony_ciopenharmony_ci成员
5月25日 删除了label:waiting_for_review
openharmony_ciopenharmony_ci成员
5月25日 添加了label:merged