| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
media: pulse8-cec: fix data timestamp at pulse8_setup() stable inclusion from stable-6.6.61 commit 4264e26a34e3901a41e00bcd5e77bb3938497ff7 category: bugfix issue: #IB7W7N CVE: NA Signed-off-by: zhangshuqi <zhangshuqi3@huawei.com> --------------------------------------- commit ba9cf6b430433e57bfc8072364e944b7c0eca2a4 upstream. As pointed by Coverity, there is a hidden overflow condition there. As date is signed and u8 is unsigned, doing: date = (data[0] << 24) With a value bigger than 07f will make all upper bits of date 0xffffffff. This can be demonstrated with this small code: <code> typedef int64_t time64_t; typedef uint8_t u8; int main(void) { u8 data[] = { 0xde ,0xad , 0xbe, 0xef }; time64_t date; date = (data[0] << 24) | (data[1] << 16) | (data[2] << 8) | data[3]; printf("Invalid data = 0x%08lx\n", date); date = ((unsigned)data[0] << 24) | (data[1] << 16) | (data[2] << 8) | data[3]; printf("Expected data = 0x%08lx\n", date); return 0; } </code> Fix it by converting the upper bit calculation to unsigned. Fixes: cea28e7a55e7 ("media: pulse8-cec: reorganize function order") Cc: stable@vger.kernel.org Signed-off-by: Mauro Carvalho Chehab <mchehab+huawei@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Signed-off-by: zhangshuqi <zhangshuqi3@huawei.com> | 1 年前 | |
media: videobuf2: use sgtable-based scatterlist wrappers stable inclusion from stable-6.6.95 commit 17cb043ea1334ebe57377ab138e155beec870c97 category: bugfix issue: #ICCW0G CVE: NA Signed-off-by: Li Nan <linan122@huawei.com> --------------------------------------- commit a704a3c503ae1cfd9de8a2e2d16a0c9430e98162 upstream. Use common wrappers operating directly on the struct sg_table objects to fix incorrect use of scatterlists sync calls. dma_sync_sg_for_*() functions have to be called with the number of elements originally passed to dma_map_sg_*() function, not the one returned in sgt->nents. Fixes: d4db5eb57cab ("media: videobuf2: add begin/end cpu_access callbacks to dma-sg") CC: stable@vger.kernel.org Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com> Reviewed-by: Sergey Senozhatsky <senozhatsky@chromium.org> Acked-by: Tomasz Figa <tfiga@chromium.org> Signed-off-by: Hans Verkuil <hverkuil@xs4all.nl> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Signed-off-by: Li Nan <linan122@huawei.com> | 1 年前 | |
media: dvb-core: fix wrong reinitialization of ringbuffer on reopen commit bfbc0b5b32a8f28ce284add619bf226716a59bc0 upstream. dvb_dvr_open() calls dvb_ringbuffer_init() when a new reader opens the DVR device. dvb_ringbuffer_init() calls init_waitqueue_head(), which reinitializes the waitqueue list head to empty. Since dmxdev->dvr_buffer.queue is a shared waitqueue (all opens of the same DVR device share it), this orphans any existing waitqueue entries from io_uring poll or epoll, leaving them with stale prev/next pointers while the list head is reset to {self, self}. The waitqueue and spinlock in dvr_buffer are already properly initialized once in dvb_dmxdev_init(). The open path only needs to reset the buffer data pointer, size, and read/write positions. Replace the dvb_ringbuffer_init() call in dvb_dvr_open() with direct assignment of data/size and a call to dvb_ringbuffer_reset(), which properly resets pread, pwrite, and error with correct memory ordering without touching the waitqueue or spinlock. Cc: stable@vger.kernel.org Fixes: 34731df288a5f ("V4L/DVB (3501): Dmxdev: use dvb_ringbuffer") Reported-by: syzbot+ab12f0c08dd7ab8d057c@syzkaller.appspotmail.com Tested-by: syzbot+ab12f0c08dd7ab8d057c@syzkaller.appspotmail.com Link: https://lore.kernel.org/all/698a26d3.050a0220.3b3015.007d.GAE@google.com/ Signed-off-by: llj123 <luojie119@h-partners.com> | 4 个月前 | |
media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar [ Upstream commit ed0234c8458b3149f15e496b48a1c9874dd24a1b ] In w7090p_tuner_write_serpar, msg is controlled by user. When msg[0].buf is null and msg[0].len is zero, former checks on msg[0].buf would be passed. If accessing msg[0].buf[2] without sanity check, null pointer deref would happen. We add check on msg[0].len to prevent crash. Similar commit: commit 0ed554fd769a ("media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()") Link: https://lore.kernel.org/r/20250616013353.738790-1-alexguo1023@gmail.com Signed-off-by: llj123 <luojie119@h-partners.com> | 4 个月前 | |
media: firewire: firedtv-avc.c: replace BUG with proper, error return This resolves this smatch error: drivers/media/firewire/firedtv-avc.c:602 avc_tuner_dsd() error: uninitialized symbol 'pos'. Signed-off-by: Hans Verkuil <hverkuil-cisco@xs4all.nl> | 3 年前 | |
media: i2c: ov02a10: fix endpoint parsing use-after-free stable inclusion from stable-v6.6.157 commit 4c2988bf1ad2753240a38db10ce23e87ec542f8f category: bugfix issue: #1495 CVE: CVE-2026-89888 Signed-off-by: 姜小林 <jiangxiaolin11@h-partners.com> Co-Authored-By: Agent ------------------------------- media: i2c: ov02a10: fix endpoint parsing use-after-free commit 94971ba0592ca77ec99b292226a4b398763315b8 upstream. The ov02a10_check_hwcfg() function calls fwnode_handle_put(ep) immediately after allocating and parsing the endpoint. However, it subsequently calls fwnode_property_read_u32() using the same 'ep' handle, leading to a potential use-after-free. Additionally, reading the optional 'ovti,mipi-clock-voltage' property used to overwrite the 'ret' variable. If the property was missing, 'ret' would become negative, and this failure code would be incorrectly returned at the end of the function, causing probe to fail entirely. Fix the use-after-free by moving fwnode_property_read_u32() before the endpoint is parsed and freed. Avoid the error leak by not assigning the result of fwnode_property_read_u32() to 'ret'. Fixes: 91807efbe8ec ("media: i2c: add OV02A10 image sensor driver") Cc: stable@vger.kernel.org Signed-off-by: Biren Pandya <birenpandya@gmail.com> Reviewed-by: Vladimir Zapolskiy <vladimir.zapolskiy@linaro.org> Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Signed-off-by: 姜小林 <jiangxiaolin11@h-partners.com> AI[0%] Human Fixed[0%] Human[100%] AI Adopted[0%] Change-Id: I169d524681b251d907ac6dd816bae0542c66afa7 | 14 天前 | |
media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex mainline inclusion from mainline-6.6.131 commit bef4f4a88b73e4cc550d25f665b8a9952af22773 category: bugfix issue: #723 CVE: CVE-2026-31473 Signed-off-by: 姜小林 <jiangxiaolin11@huawei.com> ------------------------------- MEDIA_REQUEST_IOC_REINIT can run concurrently with VIDIOC_REQBUFS(0) queue teardown paths. This can race request object cleanup against vb2 queue cancellation and lead to use-after-free reports. We already serialize request queueing against STREAMON/OFF with req_queue_mutex. Extend that serialization to REQBUFS, and also take the same mutex in media_request_ioctl_reinit() so REINIT is in the same exclusion domain. This keeps request cleanup and queue cancellation from running in parallel for request-capable devices. Fixes: 6093d3002eab ("media: vb2: keep a reference to the request until dqbuf") Cc: stable@vger.kernel.org Signed-off-by: Yuchan Nam <entropy1110@gmail.com> Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com> Signed-off-by: Mauro Carvalho Chehab <mchehab+huawei@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 4 个月前 | |
media: media/*/Kconfig: sort entries Currently, the idems inside media Kconfig are out of order. Sort them using the script below: <script> use strict; use warnings; my %config; my @source; my $out; sub flush_config() { if (scalar %config) { for my $c (sort keys %config) { $out .= $config{$c} . "\n"; } %config = (); } return if (!scalar @source); $out .= "\n"; for my $s (sort @source) { $out .= $s; } $out .= "\n"; @source = (); } sub sort_kconfig($) { my $fname = shift; my $cur_config = ""; @source = (); $out = ""; %config = (); open IN, $fname or die; while (<IN>) { if (m/^config\s+(.*)/) { $cur_config = $1; $config{$cur_config} .= $_; } elsif (m/^source\s+(.*)/) { push @source, $_; } elsif (m/^\s+/) { if ($cur_config eq "") { $out .= $_; } else { $config{$cur_config} .= $_; } } else { flush_config(); $cur_config = ""; $out .= $_; } } close IN or die; flush_config(); $out =~ s/\n\n+/\n\n/g; $out =~ s/\n+$/\n/; open OUT, ">$fname"; print OUT $out; close OUT; } for my $fname(@ARGV) { sort_kconfig $fname } </script> Signed-off-by: Mauro Carvalho Chehab <mchehab@kernel.org> | 4 年前 | |
media: pci: cx23885: check cx23885_vdev_init() return stable inclusion from stable-6.6.48 commit b1397fb4a779fca560c43d2acf6702d41b4a495b category: bugfix issue: #IB7W7N CVE: NA Signed-off-by: zhangshuqi <zhangshuqi3@huawei.com> --------------------------------------- [ Upstream commit 15126b916e39b0cb67026b0af3c014bfeb1f76b3 ] cx23885_vdev_init() can return a NULL pointer, but that pointer is used in the next line without a check. Add a NULL pointer check and go to the error unwind if it is NULL. Signed-off-by: Hans Verkuil <hverkuil-cisco@xs4all.nl> Reported-by: Sicong Huang <huangsicong@iie.ac.cn> Signed-off-by: Sasha Levin <sashal@kernel.org> Signed-off-by: zhangshuqi <zhangshuqi3@huawei.com> | 1 年前 | |
media: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC mainline inclusion from mainline-6.6.100 commit e0203ddf9af7c8e170e1e99ce83b4dc07f0cd765 category: bugfix issue: #722 CVE: CVE-2026-43310 ------------------------------- media: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC For the i.MX8MQ platform, there is a hardware limitation: the g1 VPU and g2 VPU cannot decode simultaneously; otherwise, it will cause below bus error and produce corrupted pictures, even potentially lead to system hang. [ 110.527986] hantro-vpu 38310000.video-codec: frame decode timed out. [ 110.583517] hantro-vpu 38310000.video-codec: bus error detected. Therefore, it is necessary to ensure that g1 and g2 operate alternately. This allows for successful multi-instance decoding of H.264 and HEVC. To achieve this, g1 and g2 share the same v4l2_m2m_dev, and then the v4l2_m2m_dev can handle the scheduling. Fixes: cb5dd5a0fa518 ("media: hantro: Introduce G2/HEVC decoder") Cc: stable@vger.kernel.org Reviewed-by: Frank Li <Frank.Li@nxp.com> Co-developed-by: Nicolas Dufresne <nicolas.dufresne@collabora.com> Signed-off-by: Hun_Dun <18967138853@163.com> | 4 个月前 | |
media: wl128x: Fix atomicity violation in fmc_send_cmd() stable inclusion from stable-6.6.64 commit 378ce4e08ca2b1ac7bbf1d57b68643ca4226c5f8 category: bugfix issue: #IBE7K0 CVE: NA Signed-off-by: zyf1116 <zhouyongfei3@huawei.com> --------------------------------------- commit ca59f9956d4519ab18ab2270be47c6b8c6ced091 upstream. Atomicity violation occurs when the fmc_send_cmd() function is executed simultaneously with the modification of the fmdev->resp_skb value. Consider a scenario where, after passing the validity check within the function, a non-null fmdev->resp_skb variable is assigned a null value. This results in an invalid fmdev->resp_skb variable passing the validity check. As seen in the later part of the function, skb = fmdev->resp_skb; when the invalid fmdev->resp_skb passes the check, a null pointer dereference error may occur at line 478, evt_hdr = (void *)skb->data; To address this issue, it is recommended to include the validity check of fmdev->resp_skb within the locked section of the function. This modification ensures that the value of fmdev->resp_skb does not change during the validation process, thereby maintaining its validity. This possible bug is found by an experimental static analysis tool developed by our team. This tool analyzes the locking APIs to extract function pairs that can be concurrently executed, and then analyzes the instructions in the paired functions to identify possible concurrency bugs including data races and atomicity violations. Fixes: e8454ff7b9a4 ("[media] drivers:media:radio: wl128x: FM Driver Common sources") Cc: stable@vger.kernel.org Signed-off-by: Qiu-ji Chen <chenqiuji666@gmail.com> Signed-off-by: Hans Verkuil <hverkuil-cisco@xs4all.nl> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Signed-off-by: zyf1116 <zhouyongfei3@huawei.com> | 1 年前 | |
media: imon: make send_packet() more robust stable inclusion from stable-6.6.105 commit eecd203ada43a category: bugfix issue: #207 CVE: CVE-2025-68194 Signed-off-by: 何京晶 <18967138853@163.com> Co-Authored-By: Agent ------------------------------- media: imon: make send_packet() more robust syzbot is reporting that imon has three problems which result in hung tasks due to forever holding device lock [1]. First problem is that when usb_rx_callback_intf0() once got -EPROTO error after ictx->dev_present_intf0 became true, usb_rx_callback_intf0() resubmits urb after printk(), and resubmitted urb causes usb_rx_callback_intf0() to again get -EPROTO error. This results in printk() flooding (RCU stalls). Alan Stern commented [2] that In theory it's okay to resubmit _if_ the driver has a robust error-recovery scheme (such as giving up after some fixed limit on the number of errors or after some fixed time has elapsed, perhaps with a time delay to prevent a flood of errors). Most drivers don't bother to do this; they simply give up right away. This makes them more vulnerable to short-term noise interference during USB transfers, but in reality such interference is quite rare. There's nothing really wrong with giving up right away. but imon has a poor error-recovery scheme which just retries forever; this behavior should be fixed. Since I'm not sure whether it is safe for imon users to give up upon any error code, this patch takes care of only union of error codes chosen from modules in drivers/media/rc/ directory which handle -EPROTO error (i.e. ir_toy, mceusb and igorplugusb). Second problem is that when usb_rx_callback_intf0() once got -EPROTO error before ictx->dev_present_intf0 becomes true, usb_rx_callback_intf0() always resubmits urb due to commit 8791d63af0cf ("[media] imon: don't wedge hardware after early callbacks"). Move the ictx->dev_present_intf0 test introduced by commit 6f6b90c9231a ("[media] imon: don't parse scancodes until intf configured") to immediately before imon_incoming_packet(), or the first problem explained above happens without printk() flooding (i.e. hung task). Third problem is that when usb_rx_callback_intf0() is not called for some reason (e.g. flaky hardware; the reproducer for this problem sometimes prevents usb_rx_callback_intf0() from being called), wait_for_completion_interruptible() in send_packet() never returns (i.e. hung task). As a workaround for such situation, change send_packet() to wait for completion with timeout of 10 seconds. Link: https://syzkaller.appspot.com/bug?extid=592e2ab8775dbe0bf09a [1] Link: https://lkml.kernel.org/r/d6da6709-d799-4be3-a695-850bddd6eb24@rowland.harvard.edu [2] Signed-off-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp> Signed-off-by: Sean Young <sean@mess.org> Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org> Signed-off-by: 何京晶 <18967138853@163.com> | 7 个月前 | |
Merge tag 'media/v5.18-1' of git://git.kernel.org/pub/scm/linux/kernel/git/mchehab/linux-media Pull media updates from Mauro Carvalho Chehab: - a major reorg at platform Kconfig/Makefile files, organizing them per vendor. The other media Kconfig/Makefile files also sorted - New sensor drivers: hi847, isl7998x, ov08d10 - New Amphion vpu decoder stateful driver - New Atmel microchip csi2dc driver - tegra-vde driver promoted from staging - atomisp: some fixes for it to work on BYT - imx7-mipi-csis driver promoted from staging and renamed - camss driver got initial support for VFE hardware version Titan 480 - mtk-vcodec has gained support for MT8192 - lots of driver changes, fixes and improvements * tag 'media/v5.18-1' of git://git.kernel.org/pub/scm/linux/kernel/git/mchehab/linux-media: (417 commits) media: nxp: Restrict VIDEO_IMX_MIPI_CSIS to ARCH_MXC or COMPILE_TEST media: amphion: cleanup media device if register it fail media: amphion: fix some issues to improve robust media: amphion: fix some error related with undefined reference to __divdi3 media: amphion: fix an issue that using pm_runtime_get_sync incorrectly media: vidtv: use vfree() for memory allocated with vzalloc() media: m5mols/m5mols.h: document new reset field media: pixfmt-yuv-planar.rst: fix PIX_FMT labels media: platform: Remove unnecessary print function dev_err() media: amphion: Add missing of_node_put() in vpu_core_parse_dt() media: mtk-vcodec: Add missing of_node_put() in mtk_vdec_hw_prob_done() media: platform: amphion: Fix build error without MAILBOX media: spi: Kconfig: Place SPI drivers on a single menu media: i2c: Kconfig: move camera drivers to the top media: atomisp: fix bad usage at error handling logic media: platform: rename mediatek/mtk-jpeg/ to mediatek/jpeg/ media: media/*/Kconfig: sort entries media: Kconfig: cleanup VIDEO_DEV dependencies media: platform/*/Kconfig: make manufacturer menus more uniform media: platform: Create vendor/{Makefile,Kconfig} files ... | 4 年前 | |
media: vidtv: initialize local pointers upon transfer of memory ownership stable inclusion from stable-6.6.105 commit 98aabfe2d79f74613abc2b0b1cef08f97eaf5322 category: bugfix issue: #200 CVE: CVE-2025-68808 Signed-off-by: zhangxiaoliang <1554188414@qq.com> --------------------------------------- vidtv_channel_si_init() creates a temporary list (program, service, event) and ownership of the memory itself is transferred to the PAT/SDT/EIT tables through vidtv_psi_pat_program_assign(), vidtv_psi_sdt_service_assign(), vidtv_psi_eit_event_assign(). The problem here is that the local pointer where the memory ownership transfer was completed is not initialized to NULL. This causes the vidtv_psi_pmt_create_sec_for_each_pat_entry() function to fail, and in the flow that jumps to free_eit, the memory that was freed by vidtv_psi_*_table_destroy() can be accessed again by vidtv_psi_*_event_destroy() due to the uninitialized local pointer, so it is freed once again. Therefore, to prevent use-after-free and double-free vulnerability, local pointers must be initialized to NULL when transferring memory ownership. Cc: <stable@vger.kernel.org> Reported-by: syzbot+1d9c0edea5907af239e0@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=1d9c0edea5907af239e0 Fixes: 3be8037960bc ("media: vidtv: add error checks") Signed-off-by: Jeongjun Park <aha310510@gmail.com> Reviewed-by: Daniel Almeida <daniel.almeida@collabora.com> Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org> Signed-off-by: zhangxiaoliang <1554188414@qq.com> Change-Id: I82555c0a980104e16a95924eed876c8706f27187 | 7 个月前 | |
Revert "media: tuners: fix error return code of hybrid_tuner_request_state()" stable inclusion from stable-6.6.54 commit e48edd4762910d6ab0bc5edf00af4397d7b28253 category: bugfix issue: #IB7W7N CVE: NA Signed-off-by: zhangshuqi <zhangshuqi3@huawei.com> --------------------------------------- commit e25cc4be4616fcf5689622b3226d648aab253cdb upstream. This reverts commit b9302fa7ed979e84b454e4ca92192cf485a4ed41. As Fedor Pchelkin pointed out, this commit violates the convention of using the macro return value, which causes errors. For example, in functions tda18271_attach(), xc5000_attach(), simple_tuner_attach(). Link: https://lore.kernel.org/linux-media/20240424202031.syigrtrtipbq5f2l@fpc/ Suggested-by: Fedor Pchelkin <pchelkin@ispras.ru> Signed-off-by: Roman Smirnov <r.smirnov@omp.ru> Signed-off-by: Hans Verkuil <hverkuil-cisco@xs4all.nl> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Signed-off-by: zhangshuqi <zhangshuqi3@huawei.com> | 1 年前 | |
media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() Signed-off-by: llj123 <luojie119@h-partners.com> commit 782b6a718651eda3478b1824b37a8b3185d2740c upstream. The buffer length check before calling uvc_parse_format() only ensured that the buffer has at least 3 bytes (buflen > 2), buf the function accesses buffer[3], requiring at least 4 bytes. This can lead to an out-of-bounds read if the buffer has exactly 3 bytes. Fix it by checking that the buffer has at least 4 bytes in uvc_parse_format(). Signed-off-by: Youngjun Lee <yjjuny.lee@samsung.com> Reviewed-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com> Fixes: c0efd232929c ("V4L/DVB (8145a): USB Video Class driver") Cc: stable@vger.kernel.org Reviewed-by: Ricardo Ribalda <ribalda@chromium.org> Link: https://lore.kernel.org/r/20250610124107.37360-1-yjjuny.lee@samsung.com Signed-off-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com> Signed-off-by: Hans Verkuil <hverkuil@xs4all.nl> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> (cherry picked from commit 29af99191f322f8aeb79ac79130b6303875dd842) | 4 个月前 | |
!383 merge cve-fix-20260521-kernel_linux_6.6-master into master CVE修复: kernel_linux_6.6 master (20 个有效安全补丁) - 2026-05-21 Created-by: provii Commit-by: 姜小林;Pauli Virtanen;Oleh Konko;Kuen-Han Tsai;Pengpeng Hou;Fernando Fernandez Mancera;Hyunwoo Kim;Tejas Bharambe;Deepanshu Kartikey;Eric Dumazet;Xiang Mei;Yuchan Nam;Yuto Ohnuki;Yochai Eisenrich;Andrew Lunn;Pablo Neira Ayuso;Davidlohr Bueso;Keith Busch;Phillip Lougher;Minwoo Ra;Ren Wei;Jiayuan Chen;openharmony_ci Merged-by: openharmony_ci Description: ## CVE 修复列表 本 PR 针对 kernel_linux_6.6 的 master 分支,从 Linux 6.6 stable 树 cherry-pick 安全补丁。 ### 统计概览 | 状态 | 数量 | |------|------| | 有效修复 | 20 | | 修复后被 Revert(编译错误) | 9 | | **PR 中 commit 涉及 CVE** | **29** | ### 有效修复 | # | CVE ID | Commit | 标题 | |---|--------|--------|------| | 1 | CVE-2026-23343 | 9c25eb234a6d | xdp: produce a warning when calculated tailroom is negative | | 2 | CVE-2026-23368 | 433e3809e920 | net: phy: register phy led_triggers during probe to avoid AB-BA d | | 3 | CVE-2026-23388 | 94df591b771f | Squashfs: check metadata block offset is within range | | 4 | CVE-2026-23391 | 7bb0f9d29aa3 | netfilter: xt_CT: drop pending enqueued packets on template remov | | 5 | CVE-2026-23419 | a07a5a0d20a3 | net/rds: Fix circular locking dependency in rds_tcp_tune | | 6 | CVE-2026-23439 | 7537772204d1 | udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG | | 7 | CVE-2026-31414 | 876fb834e15a | netfilter: nf_conntrack_expect: use expect->helper | | 8 | CVE-2026-31415 | 98754dfdc91e | ipv6: avoid overflows in ip6_datagram_send_ctl() | | 9 | CVE-2026-31446 | 639688a91069 | ext4: fix use-after-free in update_super_work when racing with um | | 10 | CVE-2026-31448 | c5b401a48a98 | ext4: avoid infinite loops caused by residual data | | 11 | CVE-2026-31451 | abd9cea038cc | ext4: replace BUG_ON with proper error handling in ext4_read_inli | | 12 | CVE-2026-31452 | 55e2a2297550 | ext4: convert inline data to extents when truncate exceeds inline | | 13 | CVE-2026-31453 | 6adf88e38824 | xfs: avoid dereferencing log items after push callbacks | | 14 | CVE-2026-31473 | 161da64d456a | media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mute | | 15 | CVE-2026-31504 | c4da2004bf8d | net: fix fanout UAF in packet_release() via NETDEV_UP race | | 16 | CVE-2026-31523 | e607ed131049 | nvme-pci: ensure we're polling a polled queue | | 17 | CVE-2026-31528 | d22dce73b9fa | perf: Make sure to use pmu_ctx->pmu for groups | | 18 | CVE-2026-31555 | b698c643ddcf | futex: Clear stale exiting pointer in futex_lock_pi() retry path | | 19 | CVE-2026-31630 | bac2268e4e54 | rxrpc: proc: size address buffers for %pISpc output | | 20 | CVE-2026-31681 | bd90f7f0ba11 | netfilter: xt_multiport: validate range encoding in checkentry | ### 修复后被 Revert(AI backporting 编译错误,净效果为 0) | # | CVE ID | Commit | 标题 | |---|--------|--------|------| | 1 | CVE-2026-31449 | 6dcbcdc4b9e1 | ext4: validate p_idx bounds in ext4_ext_correct_indexes | | 2 | CVE-2026-31499 | fb9377314856 | Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() | | 3 | CVE-2026-31503 | 74da00ae1d89 | udp: Fix wildcard bind conflict check when using hash2 | | 4 | CVE-2026-31516 | 49d0ba86e817 | xfrm: prevent policy_hthresh.work from racing with netns teardown | | 5 | CVE-2026-31531 | b787896799f5 | ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() | | 6 | CVE-2026-31702 | 9512102bf861 | f2fs: fix use-after-free of sbi in f2fs_compress_write_end_io() | | 7 | CVE-2026-31722 | 89fd4df39260 | usb: gadget: f_rndis: Fix net_device lifecycle with device_move | | 8 | CVE-2026-31771 | a7ce71b24cbc | Bluetooth: hci_event: move wake reason storage into validated eve | | 9 | CVE-2026-43022 | 0c16ae40d9b5 | Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if | ## 测试状态 - 编译:待触发 CI - 测试:待执行 ## 关联 Issue 已关联 Issue: #723 --- *更新时间: 2026-05-22* See merge request: openharmony/kernel_linux_6.6!383 | 4 个月前 | |
media: Kconfig: Make DVB_CORE=m possible when MEDIA_SUPPORT=y A case that CONFIG_MEDIA_SUPPORT is y but we need DVB_CORE=m, and this doesn't work since DVB_CORE is default MEDIA_DIGITAL_TV_SUPPORT and then follows MEDIA_SUPPORT. Signed-off-by: Hans Verkuil <hverkuil-cisco@xs4all.nl> Signed-off-by: Lecopzer Chen <lecopzer.chen@mediatek.com> | 3 年前 | |
media: Makefiles: remove extra spaces It is hard to keep all those options aligned as newer config changes get added, and we really don't want to have patches adding new options also touching already existing entries. So, drop the extra spaces. Reviewed-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com> Signed-off-by: Mauro Carvalho Chehab <mchehab@kernel.org> | 4 年前 |