已合并
CVE修复: kernel_linux_6.6 master (55 个安全补丁) - 2026-05-22 #384
CVE修复: kernel_linux_6.6 master (55 个安全补丁) - 2026-05-22 #384
已合并
何京晶创建于 5月22日
何京晶
何京晶
5月22日

CVE 修复列表

CVE ID 标题 Commit
CVE-2026-31726 usb: gadget: uvc: fix NULL pointer dereference dur... c78e463ee134
CVE-2026-31759 usb: ulpi: fix double free in ulpi_register_interf... aaeae6533d77
CVE-2026-43024 netfilter: nf_tables: reject immediate NF_QUEUE ve... 4b12a3cc3f07
CVE-2026-43026 netfilter: ctnetlink: zero expect NAT fields when ... 2898080c054e
CVE-2026-43027 netfilter: nf_conntrack_helper: pass helper to exp... 2cf2737c85a2
CVE-2026-43028 netfilter: x_tables: ensure names are nul-terminat... c2d4a3abb15c
CVE-2026-43035 net: sched: cls_api: fix tc_chain_fill_node to ini... e35f5195cd44
CVE-2026-43060 netfilter: nft_ct: drop pending enqueued packets o... e68a8db3a054
CVE-2026-43073 x86-64: rename misleadingly named '__copy_user_noc... d187a86de793
CVE-2026-43077 crypto: algif_aead - Fix minimum RX size check for... 3d14bd48e3a7
CVE-2026-43080 l2tp: Drop large packets with UDP encap ebe560ea5f54
CVE-2026-43082 net: txgbe: leave space for null terminators on pr... 5a37d228799b
CVE-2026-43085 netfilter: nfnetlink_log: initialize nfgenmsg in N... 1f3083aec883
CVE-2026-43086 ipvs: fix NULL deref in ip_vs_add_service error pa... 9a91797e61d2
CVE-2026-43088 net: af_key: zero aligned sockaddr tail in PF_KEY ... 426c355742f0
CVE-2026-43089 xfrm_user: fix info leak in build_mapping() 1beb76b2053b
CVE-2026-43091 xfrm: Wait for RCU readers during policy netns exi... 069daad4f2ae
CVE-2026-43107 xfrm: account XFRMA_IF_ID in aevent size calculati... 7081d46d3231
CVE-2026-43114 netfilter: nft_set_pipapo_avx2: don't return non-m... d3c0037ffe12
CVE-2026-43116 netfilter: ctnetlink: ensure safe access to master... bffcaad9afdf
CVE-2026-43128 RDMA/umem: Fix double dma_buf_unpin in failure pat... b324327ff6f4
CVE-2026-43129 ima: verify the previous kernel's IMA buffer lies ... 10d1c75ed438
CVE-2026-43130 iommu/vt-d: Flush dev-IOTLB only when PCIe device ... 01aed2f1d7cb
CVE-2026-43136 HID: logitech-hidpp: Check maxfield in hidpp_get_r... b74bf7d0d01f
CVE-2026-43139 xfrm6: fix uninitialized saddr in xfrm6_get_saddr(... 719918fc88df
CVE-2026-43161 iommu/vt-d: Skip dev-iotlb flush for inaccessible ... 42662d19839f
CVE-2026-43167 xfrm: always flush state and policy upon NETDEV_UN... 166801e49a5b
CVE-2026-43180 net: usb: kaweth: remove TX queue manipulation in ... ef9b10a02050
CVE-2026-43190 netfilter: xt_tcpmss: check remaining length befor... 07a9b32eaae7
CVE-2026-43199 net/mlx5e: Fix "scheduling while atomic" in IPsec ... 859380694f43
CVE-2026-43238 net/sched: act_skbedit: fix divide-by-zero in tcf_... 9c735a7d98c9
CVE-2026-43248 vhost: move vdpa group bound check to vhost_vdpa cd025c1e876b
CVE-2026-43281 mailbox: Prevent out-of-bounds access in fw_mbox_i... 31c4c67dec33
CVE-2026-43292 mm/vmalloc: prevent RCU stalls in kasan_release_vm... 5747435e0fd4
CVE-2026-43304 libceph: define and enforce CEPH_MAX_KEY_LEN e1dc45d97975
CVE-2026-43309 md raid: fix hang when stopping arrays with metada... cefcb9297fbd
CVE-2026-43310 media: verisilicon: Avoid G2 bus error while decod... e0203ddf9af7
CVE-2026-43319 spi: spidev: fix lock inversion between spi_lock a... 40534d19ed2a
CVE-2026-43324 USB: dummy-hcd: Fix interrupt synchronization erro... 5aa776c8615b
CVE-2026-43330 crypto: caam - fix overflow on long hmac keys 31022cfde523
CVE-2026-43332 thermal: core: Fix thermal zone device registratio... 9e796001af97
CVE-2026-43339 ipv6: prevent possible UaF in addrconf_permanent_a... 7d9f2f4aabd1
CVE-2026-43353 i3c: mipi-i3c-hci: Fix race in DMA ring dequeue 1dca8aee80ee
CVE-2026-43406 libceph: prevent potential out-of-bounds reads in ... 50156622eb08
CVE-2026-43413 scsi: hisi_sas: Fix NULL pointer exception during ... 70c78429ef38
CVE-2026-43439 cgroup: fix race between task migration and iterat... 3dfd1328c052
CVE-2026-43441 net: bonding: Fix nd_tbl NULL dereference when IPv... cf6099ef493b
CVE-2026-43450 netfilter: nfnetlink_cthelper: fix OOB read in nfn... 4a1f6ee69267
CVE-2026-43451 netfilter: nfnetlink_queue: fix entry leak in brid... 47b1c5d1b094
CVE-2026-43452 netfilter: x_tables: guard option walkers against ... 9b94f0e42ed2
CVE-2026-43453 netfilter: nft_set_pipapo: fix stack out-of-bounds... 0a55d62cdb62
CVE-2026-43456 bonding: fix type confusion in bond_setup_by_slave... 950803f72547
CVE-2026-43466 net/mlx5e: Fix DMA FIFO desync on error CQE SQ rec... 383b37c04a48
CVE-2026-43468 net/mlx5: Fix deadlock between devlink lock and es... 957d2a58f7f8
CVE-2026-43475 scsi: storvsc: Fix scheduling while atomic on PREE... e7919a293f9b

来源: Cherry-pick from stable-tags/v6.6.134~18

统计

  • 总数: 60
  • 成功: 55
  • 空提交(已存在): 3
  • 跳过: 2

修复详情

CVE-2026-31726

  • Commit: c78e463ee134b4669579d453c81ae00795e4c19a
  • Stable: tags/v6.6.134~18
  • 标题: usb: gadget: uvc: fix NULL pointer dereference during unbind race

CVE-2026-31759

  • Commit: aaeae6533d77e6ed4def85baec01e2815ebbef61
  • Stable: tags/v6.6.134~56
  • 标题: usb: ulpi: fix double free in ulpi_register_interface() error path

CVE-2026-43024

  • Commit: 4b12a3cc3f075e750cc3c5e693fd25fb400af4a2
  • Stable: tags/v6.6.134~116
  • 标题: netfilter: nf_tables: reject immediate NF_QUEUE verdict

CVE-2026-43026

  • Commit: 2898080c054ea4d6ddfaaf21bbedbc229a9a8376
  • Stable: tags/v6.6.134~122
  • 标题: netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent

CVE-2026-43027

  • Commit: 2cf2737c85a2ba2b52024dafe68ffad2676f97be
  • Stable: tags/v6.6.134~123
  • 标题: netfilter: nf_conntrack_helper: pass helper to expect cleanup

CVE-2026-43028

  • Commit: c2d4a3abb15ca14716c6d8b9ffcbcd7c63626af4
  • Stable: tags/v6.6.134~125
  • 标题: netfilter: x_tables: ensure names are nul-terminated

CVE-2026-43035

  • Commit: e35f5195cd44ff4053fbc5d71ea97681728a0099
  • Stable: tags/v6.6.134~132
  • 标题: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak

CVE-2026-43060

  • Commit: e68a8db3a0546482b34e9ca5ca886bcf73eb37bb
  • Stable: tags/v6.6.130~52
  • 标题: netfilter: nft_ct: drop pending enqueued packets on removal

CVE-2026-43073

  • Commit: d187a86de793f84766ea40b9ade7ac60aabbb4fe
  • Stable: tags/v7.1-rc1~251^2~2
  • 标题: x86-64: rename misleadingly named '__copy_user_nocache()' function

CVE-2026-43077

  • Commit: 3d14bd48e3a77091cbce637a12c2ae31b4a1687c
  • Stable: tags/v7.0~7^2
  • 标题: crypto: algif_aead - Fix minimum RX size check for decryption

CVE-2026-43080

  • Commit: ebe560ea5f54134279356703e73b7f867c89db13
  • Stable: tags/v7.0~27^2~2
  • 标题: l2tp: Drop large packets with UDP encap

CVE-2026-43082

  • Commit: 5a37d228799b0ec2c277459c83c814a59d310bc3
  • Stable: tags/v7.0~27^2~11
  • 标题: net: txgbe: leave space for null terminators on property_entry

CVE-2026-43085

  • Commit: 1f3083aec8836213da441270cdb1ab612dd82cf4
  • Stable: tags/v7.0~27^2~16^2~5
  • 标题: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator

CVE-2026-43086

  • Commit: 9a91797e61d286805ae10a92cc48959c30800556
  • Stable: tags/v7.0~27^2~16^2~6
  • 标题: ipvs: fix NULL deref in ip_vs_add_service error path

CVE-2026-43088

  • Commit: 426c355742f02cf743b347d9d7dbdc1bfbfa31ef
  • Stable: tags/v7.0~27^2~14^2
  • 标题: net: af_key: zero aligned sockaddr tail in PF_KEY exports

CVE-2026-43089

  • Commit: 1beb76b2053b68c491b78370794b8ff63c8f8c02
  • Stable: tags/v7.0~27^2~14^2~2
  • 标题: xfrm_user: fix info leak in build_mapping()

CVE-2026-43091

  • Commit: 069daad4f2ae9c5c108131995529d5f02392c446
  • Stable: tags/v7.0~27^2~14^2~5
  • 标题: xfrm: Wait for RCU readers during policy netns exit

CVE-2026-43107

  • Commit: 7081d46d32312f1a31f0e0e99c6835a394037599
  • Stable: tags/v7.0~27^2~14^2~6
  • 标题: xfrm: account XFRMA_IF_ID in aevent size calculation

CVE-2026-43114

  • Commit: d3c0037ffe1273fa1961e779ff6906234d6cf53c
  • Stable: tags/v7.0-rc6~40^2^2~11
  • 标题: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry

CVE-2026-43116

  • Commit: bffcaad9afdfe45d7fc777397d3b83c1e3ebffe5
  • Stable: tags/v7.0-rc6~40^2^2~4
  • 标题: netfilter: ctnetlink: ensure safe access to master conntrack

CVE-2026-43128

  • Commit: b324327ff6f48d8065dca67eb3b91357e72726bd
  • Stable: tags/v6.6.128~137
  • 标题: RDMA/umem: Fix double dma_buf_unpin in failure path

CVE-2026-43129

  • Commit: 10d1c75ed4382a8e79874379caa2ead8952734f9
  • Stable: tags/v7.0-rc1~46^2~76
  • 标题: ima: verify the previous kernel's IMA buffer lies in addressable RAM

CVE-2026-43130

  • Commit: 01aed2f1d7cb8fdf4c60c5bb4727608cb82b401d
  • Stable: tags/v6.6.128~70
  • 标题: iommu/vt-d: Flush dev-IOTLB only when PCIe device is accessible in scalable mode

CVE-2026-43136

  • Commit: b74bf7d0d01fa9b53653f58c29aa00772121f6e9
  • Stable: tags/v6.6.128~111
  • 标题: HID: logitech-hidpp: Check maxfield in hidpp_get_report_length()

CVE-2026-43139

  • Commit: 719918fc88df6da023dfff370cd965151a5afd7f
  • Stable: tags/v6.6.128~157
  • 标题: xfrm6: fix uninitialized saddr in xfrm6_get_saddr()

CVE-2026-43161

  • Commit: 42662d19839f34735b718129ea200e3734b07e50
  • Stable: tags/v7.0-rc1~137^2^3~6
  • 标题: iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode

CVE-2026-43167

  • Commit: 166801e49a5b5fc127b8c9e2f110f303cfddfbc3
  • Stable: tags/v6.6.128~154
  • 标题: xfrm: always flush state and policy upon NETDEV_UNREGISTER event

CVE-2026-43180

  • Commit: ef9b10a020503888eb6c8ed85a3d901a624ede4c
  • Stable: tags/v6.6.128~153
  • 标题: net: usb: kaweth: remove TX queue manipulation in kaweth_set_rx_mode

CVE-2026-43190

  • Commit: 07a9b32eaae792ff7d0fcac14d8920c937c0a9c3
  • Stable: tags/v6.6.128~240
  • 标题: netfilter: xt_tcpmss: check remaining length before reading optlen

CVE-2026-43199

  • Commit: 859380694f434597407632c29f30fdb5e763e6cc
  • Stable: tags/v7.0-rc2~36^2~4^2
  • 标题: net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query

CVE-2026-43238

  • Commit: 9c735a7d98c982a786b0db71eb6566ee00aaa04f
  • Stable: tags/v6.6.128~9
  • 标题: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash()

CVE-2026-43248

  • Commit: cd025c1e876b4e262e71398236a1550486a73ede
  • Stable: tags/v7.0-rc1~102^2~20
  • 标题: vhost: move vdpa group bound check to vhost_vdpa

CVE-2026-43281

  • Commit: 31c4c67dec3362094a6747a171a4848e98542265
  • Stable: tags/v6.6.130~501
  • 标题: mailbox: Prevent out-of-bounds access in fw_mbox_index_xlate()

CVE-2026-43292

  • Commit: 5747435e0fd474c24530ef1a6822f47e7d264b27
  • Stable: tags/v7.0-rc1~47^2~214
  • 标题: mm/vmalloc: prevent RCU stalls in kasan_release_vmalloc_node

CVE-2026-43304

  • Commit: e1dc45d97975f9db65694d234fbddf1915176e16
  • Stable: tags/v6.6.128~172
  • 标题: libceph: define and enforce CEPH_MAX_KEY_LEN

CVE-2026-43309

  • Commit: cefcb9297fbdb6d94b61787b4f8d84f55b741470
  • Stable: tags/v7.0-rc1~220^2~17^2
  • 标题: md raid: fix hang when stopping arrays with metadata through dm-raid

CVE-2026-43310

  • Commit: e0203ddf9af7c8e170e1e99ce83b4dc07f0cd765
  • Stable: tags/v7.0-rc1~149^2~261
  • 标题: media: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC

CVE-2026-43319

  • Commit: 40534d19ed2afb880ecf202dab26a8e7a5808d16
  • Stable: tags/v7.0-rc1~23^2
  • 标题: spi: spidev: fix lock inversion between spi_lock and buf_lock

CVE-2026-43324

  • Commit: 5aa776c8615bea3b1eaeec87b0788375800ead4f
  • Stable: tags/v6.6.134~26
  • 标题: USB: dummy-hcd: Fix interrupt synchronization error

CVE-2026-43330

  • Commit: 31022cfde5235c45fa765f0aabeff5f0652852f2
  • Stable: tags/v6.6.134~145
  • 标题: crypto: caam - fix overflow on long hmac keys

CVE-2026-43332

  • Commit: 9e796001af97a1f7368d5114b7a8533dd98d797a
  • Stable: tags/v6.6.134~30
  • 标题: thermal: core: Fix thermal zone device registration error path

CVE-2026-43339

  • Commit: 7d9f2f4aabd116ca68fbdab5d8fb8dac74c2ea1e
  • Stable: tags/v6.6.134~133
  • 标题: ipv6: prevent possible UaF in addrconf_permanent_addr()

CVE-2026-43353

  • Commit: 1dca8aee80eea76d2aae21265de5dd64f6ba0f09
  • Stable: tags/v7.0-rc4~11^2~10
  • 标题: i3c: mipi-i3c-hci: Fix race in DMA ring dequeue

CVE-2026-43406

  • Commit: 50156622eb0888e62541d715a98584480a1bc7cb
  • Stable: tags/v6.6.130~271
  • 标题: libceph: prevent potential out-of-bounds reads in process_message_header()

CVE-2026-43413

  • Commit: 70c78429ef383e35f9c58848994aeeac8083ae35
  • Stable: tags/v6.6.130~261
  • 标题: scsi: hisi_sas: Fix NULL pointer exception during user_scan()

CVE-2026-43439

  • Commit: 3dfd1328c05234e8d8fa61948b2ba82680594988
  • Stable: tags/v6.6.130~306
  • 标题: cgroup: fix race between task migration and iteration

CVE-2026-43441

  • Commit: cf6099ef493b94e140b0fad52482a78853115318
  • Stable: tags/v6.6.130~312
  • 标题: net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled

CVE-2026-43450

  • Commit: 4a1f6ee69267a5f524102c028981410eeacfa3da
  • Stable: tags/v6.6.130~324
  • 标题: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table()

CVE-2026-43451

  • Commit: 47b1c5d1b0944aa88299f55a846fabaefc756982
  • Stable: tags/v6.6.130~325
  • 标题: netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path

CVE-2026-43452

  • Commit: 9b94f0e42ed248eb31929da84ed9f5310d7ff540
  • Stable: tags/v6.6.130~326
  • 标题: netfilter: x_tables: guard option walkers against 1-byte tail reads

CVE-2026-43453

  • Commit: 0a55d62cdb628923d8a21724374a70c76ac7d19d
  • Stable: tags/v6.6.130~327
  • 标题: netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop()

CVE-2026-43456

  • Commit: 950803f7254721c1c15858fbbfae3deaaeeecb11
  • Stable: tags/v7.0-rc4~37^2~22
  • 标题: bonding: fix type confusion in bond_setup_by_slave()

CVE-2026-43466

  • Commit: 383b37c04a4827ba60b2bafc1a6cdfd995aed58f
  • Stable: tags/v6.6.130~343
  • 标题: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery

CVE-2026-43468

  • Commit: 957d2a58f7f8ebcbdd0a85935e0d2675134b890d
  • Stable: tags/v6.6.130~344
  • 标题: net/mlx5: Fix deadlock between devlink lock and esw->wq

CVE-2026-43475

  • Commit: e7919a293f9b6101e38bde0d8613daea6c9955df
  • Stable: tags/v6.6.130~369
  • 标题: scsi: storvsc: Fix scheduling while atomic on PREEMPT_RT

测试状态

  • 编译:待触发 CI
  • 测试:待执行

关联 Issue

已关联 Issue: #722


生成时间: 2026-05-22 22:50:49

likedislike
Pull Request已成功合入, 合并人@openharmony_ci
(感谢 何京晶 的贡献)
何京晶何京晶
5月22日 关联了issue:CVE修复跟踪: kernel_linux_6.6 master
openharmony_ciopenharmony_ci成员
5月22日 添加了label:waiting_on_author
openharmony_ci
openharmony_ci成员
5月22日 评论:

感谢提交 Pull Requests !此PR未通过DCO校验。
校验失败可能原因:

1. 未签署“DCO协议”(开发者原创声明协议),在线签署、查看签署状态

2. Commits 中未包含 Signed-off-by信息,参考FAQ处理

修复上述问题后,在PR的评论框输入“check dco” ,单击”评论”,系统将再次进行DCO校验。

当前检测到如下Commits的Signed-off-by邮箱未签署DCO协议:


Thanks for submitting a pull request. This pull request has not passed the DCO check.
Possible causes:

1. You have not signed the Developer Certificate of Origin (DCO). Sign the DCO and check DCO status.

2. The commits do not contain the Signed-off-by information. To resolve this issue, see FAQs.

After resolving the preceding issues, enter check dco in the comment box of this pull request and click Comment. The system will check DCO status again.

The Signed-off-by emails in the following commits have not signed the DCO:

likedislike
openharmony_ciopenharmony_ci成员
5月22日 添加了label:dco检查失败
openharmony_ci
openharmony_ci成员
5月22日 评论:

感谢提交 Pull Requests !此PR未通过DCO校验。
您可以通过DCO例外申请来解除限制


Thanks for submitting a pull request. This pull request has not passed the DCO check.
You can apply for DCO Exceptions Request to lift restrictions

likedislike
此处折叠了52条消息 查看更多
openharmony_ci
openharmony_ci成员
5月25日 评论:

您好,Committer @z-jax @leejiawei @weiyj__lk ,请分配检视人员检视该PR,可以通过命令"assign [@someone_id]"分配检视人员,也可以直接评论"assign"分配给自己进行检视。


Hello, Committer @z-jax @leejiawei @weiyj__lk . Please assign someone to review the PR. You can assign a reviewer by using the command "assign [@someone_id]", or you can comment "assign" to review the PR by yourself.

likedislike
openharmony_ciopenharmony_ci成员
5月25日 关闭了关联的issue
openharmony_ciopenharmony_ci成员
5月25日 合入了pull request,合并节点 SHA:06c19d2f87b5ceaa0a6865c08332ac18355910ec
openharmony_ciopenharmony_ci成员
5月25日 删除了label:waiting_for_review
openharmony_ciopenharmony_ci成员
5月25日 添加了label:merged