Skip to content

[rocky8_10] History Rebuild through kernel-4.18.0-553.159.1.el8_10 - #1573

Open
PlaidCat wants to merge 36 commits into
rocky8_10from
rocky8_10_rebuild
Open

[rocky8_10] History Rebuild through kernel-4.18.0-553.159.1.el8_10#1573
PlaidCat wants to merge 36 commits into
rocky8_10from
rocky8_10_rebuild

Conversation

@PlaidCat

@PlaidCat PlaidCat commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator

This is an automated kernel history rebuild using cron and internal tooling. It follows the same process used for previous history rebuilds:

  • Download all unprocessed src.rpm packages
  • For each src.rpm:
    • Identify all commits in the changelog up to the last known tag (4.18.0-553)
    • Replay commits in chronological order (oldest to newest in the changelog) using git cherry-pick
    • Replace the code in the branch with the output of rpmbuild -bp for the corresponding src.rpm
    • Tag the rebuild branch

JIRA Tickets

Rebuild Splat Inspection

kernel-4.18.0-553.159.1.el8_10

$ cat ciq/ciq_backports/kernel-4.18.0-553.159.1.el8_10/rebuild.details.txt
Rebuild_History BUILDABLE
Rebuilding Kernel from rpm changelog with Fuzz Limit: 87.50%
Number of commits in upstream range v4.18~1..kernel-mainline: 625874
Number of commits in rpm: 26
Number of commits matched with upstream: 8 (30.77%)
Number of commits in upstream but not in rpm: 625866
Number of commits NOT found in upstream: 18 (69.23%)

Rebuilding Kernel on Branch rocky8_10_rebuild_kernel-4.18.0-553.159.1.el8_10 for kernel-4.18.0-553.159.1.el8_10
Clean Cherry Picks: 6 (75.00%)
Empty Cherry Picks: 1 (12.50%)
_______________________________

__EMPTY COMMITS__________________________
6627eb25e40cc8d135d3f8d5391851d18ac497d7 x86/entry: Unify definitions from <asm/calling.h> and <asm/ptrace-abi.h>

__CHANGES NOT IN UPSTREAM________________
Adding prod certs and changed cert date to 20210620
Adding Rocky secure boot certs
Fixing vmlinuz removal
Fixing UEFI CA path
Porting to 8.10, debranding and Rocky branding
Fixing pesign_key_name values
net: ipv6: clear suppressed fib6 rule result
powerpc/pseries: lparcfg - fix kbufunderflow
RHEL only: Disable zram writeback support on non-4k page size systems
nfsd: release layout stid on setlease failure
NFSv4/flexfiles: reject zero filehandle version count
NFSv4: include MAY_WRITE in open permission mask for O_TRUNC
NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
nfsd: fix posix_acl leak on SETACL decode failure
x86/bugs: Make Safe-RET robust against interrupt injection
x86: Clean up names/macros conflicting with ptrace-abi.h
RDMA/siw: bound Read Response placement to the RREAD length
qede: fix off-by-one in BD ring consumption on build_skb failure

BUILD

$ grep -E -B 5 -A 5 "\[TIMER\]|^Starting Build" $(ls -t kbuild* | head -n1)
/mnt/code/kernel-src-tree-build
Running make mrproper...
  CLEAN   scripts/basic
  CLEAN   scripts/kconfig
[TIMER]{MRPROPER}: 4s
x86_64 architecture detected, copying config
'configs/kernel-x86_64.config' -> '.config'
Setting Local Version for build
CONFIG_LOCALVERSION="-rocky8_10_rebuild-5ced7ffceb6c"
Making olddefconfig
--
  HOSTLD  scripts/kconfig/conf
scripts/kconfig/conf  --olddefconfig Kconfig
#
# configuration written to .config
#
Starting Build
scripts/kconfig/conf  --syncconfig Kconfig
  SYSTBL  arch/x86/include/generated/asm/syscalls_32.h
  SYSHDR  arch/x86/include/generated/asm/unistd_32_ia32.h
  SYSHDR  arch/x86/include/generated/asm/unistd_64_x32.h
  SYSTBL  arch/x86/include/generated/asm/syscalls_64.h
--
  LD [M]  sound/usb/usx2y/snd-usb-usx2y.ko
  LD [M]  sound/virtio/virtio_snd.ko
  LD [M]  sound/x86/snd-hdmi-lpe-audio.ko
  LD [M]  sound/xen/snd_xen_front.ko
  LD [M]  virt/lib/irqbypass.ko
[TIMER]{BUILD}: 1533s
Making Modules
  INSTALL arch/x86/crypto/blowfish-x86_64.ko
  INSTALL arch/x86/crypto/camellia-aesni-avx-x86_64.ko
  INSTALL arch/x86/crypto/camellia-aesni-avx2.ko
  INSTALL arch/x86/crypto/camellia-x86_64.ko
--
  INSTALL sound/virtio/virtio_snd.ko
  INSTALL sound/x86/snd-hdmi-lpe-audio.ko
  INSTALL sound/xen/snd_xen_front.ko
  INSTALL virt/lib/irqbypass.ko
  DEPMOD  4.18.0-rocky8_10_rebuild-5ced7ffceb6c+
[TIMER]{MODULES}: 14s
Making Install
sh ./arch/x86/boot/install.sh 4.18.0-rocky8_10_rebuild-5ced7ffceb6c+ arch/x86/boot/bzImage \
	System.map "/boot"
[TIMER]{INSTALL}: 21s
Checking kABI
kABI check passed
Setting Default Kernel to /boot/vmlinuz-4.18.0-rocky8_10_rebuild-5ced7ffceb6c+ and Index to 0
Hopefully Grub2.0 took everything ... rebooting after time metrices
[TIMER]{MRPROPER}: 4s
[TIMER]{BUILD}: 1533s
[TIMER]{MODULES}: 14s
[TIMER]{INSTALL}: 21s
[TIMER]{TOTAL} 1577s
Rebooting in 10 seconds

KSelfTests

$ get_kselftest_diff.sh
ls: cannot access 'selftest-*': No such file or directory
kselftest.4.18.0-rocky8_10_rebuild-6c349d0f9706+.log
206
kselftest.4.18.0-rocky8_10_rebuild-f92f5b2bcd0a+.log
206
kselftest.4.18.0-rocky8_10_rebuild-1ef263699b13+.log
206
kselftest.4.18.0-rocky8_10_rebuild-5ced7ffceb6c+.log
206
Before: kselftest.4.18.0-rocky8_10_rebuild-1ef263699b13+.log
After: kselftest.4.18.0-rocky8_10_rebuild-5ced7ffceb6c+.log
Diff:
No differences found.

@PlaidCat PlaidCat self-assigned this Sep 3, 2026
@PlaidCat
PlaidCat requested review from a team September 3, 2026 10:46
bmastbergen
bmastbergen previously approved these changes Sep 4, 2026

@bmastbergen bmastbergen left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🥌

@bmastbergen
bmastbergen requested a review from a team September 4, 2026 15:06
@bmastbergen

Copy link
Copy Markdown
Collaborator

I THINK the last rocky8_10 rebase PR might have been merged via the github PR button instead of doing a fast-forward merge, which is why this is flagged as not mergeable. When this PR gets approved we'll need to do some manual work to get things fixed up correctly.

kerneltoast
kerneltoast previously approved these changes Sep 9, 2026

@kerneltoast kerneltoast left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:shipit:

jira KERNEL-1546
cve CVE-2024-57849
Rebuild_History Non-Buildable kernel-4.18.0-553.159.1.el8_10
commit-author Thomas Richter <tmricht@linux.ibm.com>
commit a0bd7da

CPU hotplug remove handling triggers the following function
call sequence:

   CPUHP_AP_PERF_S390_SF_ONLINE  --> s390_pmu_sf_offline_cpu()
   ...
   CPUHP_AP_PERF_ONLINE          --> perf_event_exit_cpu()

The s390 CPUMF sampling CPU hotplug handler invokes:

 s390_pmu_sf_offline_cpu()
 +-->  cpusf_pmu_setup()
       +--> setup_pmc_cpu()
            +--> deallocate_buffers()

This function de-allocates all sampling data buffers (SDBs) allocated
for that CPU at event initialization. It also clears the
PMU_F_RESERVED bit. The CPU is gone and can not be sampled.

With the event still being active on the removed CPU, the CPU event
hotplug support in kernel performance subsystem triggers the
following function calls on the removed CPU:

  perf_event_exit_cpu()
  +--> perf_event_exit_cpu_context()
       +--> __perf_event_exit_context()
	    +--> __perf_remove_from_context()
	         +--> event_sched_out()
	              +--> cpumsf_pmu_del()
	                   +--> cpumsf_pmu_stop()
                                +--> hw_perf_event_update()

to stop and remove the event. During removal of the event, the
sampling device driver tries to read out the remaining samples from
the sample data buffers (SDBs). But they have already been freed
(and may have been re-assigned). This may lead to a use after free
situation in which case the samples are most likely invalid. In the
best case the memory has not been reassigned and still contains
valid data.

Remedy this situation and check if the CPU is still in reserved
state (bit PMU_F_RESERVED set). In this case the SDBs have not been
released an contain valid data. This is always the case when
the event is removed (and no CPU hotplug off occured).
If the PMU_F_RESERVED bit is not set, the SDB buffers are gone.

	Signed-off-by: Thomas Richter <tmricht@linux.ibm.com>
	Reviewed-by: Hendrik Brueckner <brueckner@linux.ibm.com>
	Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
(cherry picked from commit a0bd7da)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1546
cve CVE-2026-45970
Rebuild_History Non-Buildable kernel-4.18.0-553.159.1.el8_10
commit-author Hangbin Liu <liuhangbin@gmail.com>
commit e6834a4

The ALB RX path may access rx_hashtbl concurrently with bond
teardown. During rapid bond up/down cycles, rlb_deinitialize()
frees rx_hashtbl while RX handlers are still running, leading
to a null pointer dereference detected by KASAN.

However, the root cause is that rlb_arp_recv() can still be accessed
after setting recv_probe to NULL, which is actually a use-after-free
(UAF) issue. That is the reason for using the referenced commit in the
Fixes tag.

[  214.174138] Oops: general protection fault, probably for non-canonical address 0xdffffc000000001d: 0000 [#1] SMP KASAN PTI
[  214.186478] KASAN: null-ptr-deref in range [0x00000000000000e8-0x00000000000000ef]
[  214.194933] CPU: 30 UID: 0 PID: 2375 Comm: ping Kdump: loaded Not tainted 6.19.0-rc8+ #2 PREEMPT(voluntary)
[  214.205907] Hardware name: Dell Inc. PowerEdge R730/0WCJNT, BIOS 2.14.0 01/14/2022
[  214.214357] RIP: 0010:rlb_arp_recv+0x505/0xab0 [bonding]
[  214.220320] Code: 0f 85 2b 05 00 00 48 b8 00 00 00 00 00 fc ff df 40 0f b6 ed 48 c1 e5 06 49 03 ad 78 01 00 00 48 8d 7d 28 48 89 fa 48 c1 ea 03 <0f> b6
 04 02 84 c0 74 06 0f 8e 12 05 00 00 80 7d 28 00 0f 84 8c 00
[  214.241280] RSP: 0018:ffffc900073d8870 EFLAGS: 00010206
[  214.247116] RAX: dffffc0000000000 RBX: ffff888168556822 RCX: ffff88816855681e
[  214.255082] RDX: 000000000000001d RSI: dffffc0000000000 RDI: 00000000000000e8
[  214.263048] RBP: 00000000000000c0 R08: 0000000000000002 R09: ffffed11192021c8
[  214.271013] R10: ffff8888c9010e43 R11: 0000000000000001 R12: 1ffff92000e7b119
[  214.278978] R13: ffff8888c9010e00 R14: ffff888168556822 R15: ffff888168556810
[  214.286943] FS:  00007f85d2d9cb80(0000) GS:ffff88886ccb3000(0000) knlGS:0000000000000000
[  214.295966] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[  214.302380] CR2: 00007f0d047b5e34 CR3: 00000008a1c2e002 CR4: 00000000001726f0
[  214.310347] Call Trace:
[  214.313070]  <IRQ>
[  214.315318]  ? __pfx_rlb_arp_recv+0x10/0x10 [bonding]
[  214.320975]  bond_handle_frame+0x166/0xb60 [bonding]
[  214.326537]  ? __pfx_bond_handle_frame+0x10/0x10 [bonding]
[  214.332680]  __netif_receive_skb_core.constprop.0+0x576/0x2710
[  214.339199]  ? __pfx_arp_process+0x10/0x10
[  214.343775]  ? sched_balance_find_src_group+0x98/0x630
[  214.349513]  ? __pfx___netif_receive_skb_core.constprop.0+0x10/0x10
[  214.356513]  ? arp_rcv+0x307/0x690
[  214.360311]  ? __pfx_arp_rcv+0x10/0x10
[  214.364499]  ? __lock_acquire+0x58c/0xbd0
[  214.368975]  __netif_receive_skb_one_core+0xae/0x1b0
[  214.374518]  ? __pfx___netif_receive_skb_one_core+0x10/0x10
[  214.380743]  ? lock_acquire+0x10b/0x140
[  214.385026]  process_backlog+0x3f1/0x13a0
[  214.389502]  ? process_backlog+0x3aa/0x13a0
[  214.394174]  __napi_poll.constprop.0+0x9f/0x370
[  214.399233]  net_rx_action+0x8c1/0xe60
[  214.403423]  ? __pfx_net_rx_action+0x10/0x10
[  214.408193]  ? lock_acquire.part.0+0xbd/0x260
[  214.413058]  ? sched_clock_cpu+0x6c/0x540
[  214.417540]  ? mark_held_locks+0x40/0x70
[  214.421920]  handle_softirqs+0x1fd/0x860
[  214.426302]  ? __pfx_handle_softirqs+0x10/0x10
[  214.431264]  ? __neigh_event_send+0x2d6/0xf50
[  214.436131]  do_softirq+0xb1/0xf0
[  214.439830]  </IRQ>

The issue is reproducible by repeatedly running
ip link set bond0 up/down while receiving ARP messages, where
rlb_arp_recv() can race with rlb_deinitialize() and dereference
a freed rx_hashtbl entry.

Fix this by setting recv_probe to NULL and then calling
synchronize_net() to wait for any concurrent RX processing to finish.
This ensures that no RX handler can access rx_hashtbl after it is freed
in bond_alb_deinitialize().

	Reported-by: Liang Li <liali@redhat.com>
Fixes: 3aba891 ("bonding: move processing of recv handlers into handle_frame()")
	Reviewed-by: Nikolay Aleksandrov <nikolay@nvidia.com>
	Acked-by: Jay Vosburgh <jv@jvosburgh.net>
	Signed-off-by: Hangbin Liu <liuhangbin@gmail.com>
Link: https://patch.msgid.link/20260218060919.101574-1-liuhangbin@gmail.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit e6834a4)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1546
cve CVE-2026-64018
Rebuild_History Non-Buildable kernel-4.18.0-553.159.1.el8_10
commit-author Aditya Garg <gargaditya@linux.microsoft.com>
commit b809d04

In mana_hwc_rx_event_handler(), rx_req_idx is derived from
sge->address in DMA-coherent memory. In Confidential VMs
(SEV-SNP/TDX), this memory is shared unencrypted and HW can modify
WQE contents at any time. No bounds check exists on rx_req_idx,
which can lead to an out-of-bounds access into reqs[].

Add bounds check on rx_req_idx in mana_hwc_rx_event_handler() before
using it to index the reqs[] array.

Fixes: ca9c54d ("net: mana: Add a driver for Microsoft Azure Network Adapter (MANA)")
	Signed-off-by: Aditya Garg <gargaditya@linux.microsoft.com>
	Reviewed-by: Haiyang Zhang <haiyangz@microsoft.com>
Link: https://patch.msgid.link/20260520051553.857120-1-gargaditya@linux.microsoft.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit b809d04)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1546
cve CVE-2025-71132
Rebuild_History Non-Buildable kernel-4.18.0-553.159.1.el8_10
commit-author Wang Hai <wanghai38@huawei.com>
commit bca9749

If try_toggle_control_gpio() failed in smc_drv_probe(), free_netdev(ndev)
should be called to free the ndev created earlier. Otherwise, a memleak
will occur.

Fixes: 7d2911c ("net: smc91x: Fix gpios for device tree based booting")
	Reported-by: Hulk Robot <hulkci@huawei.com>
	Signed-off-by: Wang Hai <wanghai38@huawei.com>
	Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit bca9749)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1546
cve CVE-2025-71132
Rebuild_History Non-Buildable kernel-4.18.0-553.159.1.el8_10
commit-author Yeoreum Yun <yeoreum.yun@arm.com>
commit 6402078

When smc91x.c is built with PREEMPT_RT, the following splat occurs
in FVP_RevC:

[   13.055000] smc91x LNRO0003:00 eth0: link up, 10Mbps, half-duplex, lpa 0x0000
[   13.062137] BUG: workqueue leaked atomic, lock or RCU: kworker/2:1[106]
[   13.062137]      preempt=0x00000000 lock=0->0 RCU=0->1 workfn=mld_ifc_work
[   13.062266] C
** replaying previous printk message **
[   13.062266] CPU: 2 UID: 0 PID: 106 Comm: kworker/2:1 Not tainted 6.18.0-dirty #179 PREEMPT_{RT,(full)}
[   13.062353] Hardware name:  , BIOS
[   13.062382] Workqueue: mld mld_ifc_work
[   13.062469] Call trace:
[   13.062494]  show_stack+0x24/0x40 (C)
[   13.062602]  __dump_stack+0x28/0x48
[   13.062710]  dump_stack_lvl+0x7c/0xb0
[   13.062818]  dump_stack+0x18/0x34
[   13.062926]  process_scheduled_works+0x294/0x450
[   13.063043]  worker_thread+0x260/0x3d8
[   13.063124]  kthread+0x1c4/0x228
[   13.063235]  ret_from_fork+0x10/0x20

This happens because smc_special_trylock() disables IRQs even on PREEMPT_RT,
but smc_special_unlock() does not restore IRQs on PREEMPT_RT.
The reason is that smc_special_unlock() calls spin_unlock_irqrestore(),
and rcu_read_unlock_bh() in __dev_queue_xmit() cannot invoke
rcu_read_unlock() through __local_bh_enable_ip() when current->softirq_disable_cnt becomes zero.

To address this issue, replace smc_special_trylock() with spin_trylock_irqsave().

Fixes: 342a932 ("locking/spinlock: Provide RT variant header: <linux/spinlock_rt.h>")
	Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
	Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20251217085115.1730036-1-yeoreum.yun@arm.com
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>

(cherry picked from commit 6402078)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1546
Rebuild_History Non-Buildable kernel-4.18.0-553.159.1.el8_10
commit-author H. Peter Anvin (Intel) <hpa@zytor.com>
commit 6627eb2
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-4.18.0-553.159.1.el8_10/6627eb25.failed

The register offsets in <asm/ptrace-abi.h> are duplicated in
entry/calling.h, but are formatted differently and therefore not
compatible. Use the version from <asm/ptrace-abi.h> consistently.

	Signed-off-by: H. Peter Anvin (Intel) <hpa@zytor.com>
	Signed-off-by: Ingo Molnar <mingo@kernel.org>
Link: https://lore.kernel.org/r/20210510185316.3307264-2-hpa@zytor.com
(cherry picked from commit 6627eb2)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	arch/x86/entry/calling.h
#	arch/x86/kernel/head_64.S
jira KERNEL-1546
Rebuild_History Non-Buildable kernel-4.18.0-553.159.1.el8_10
commit-author Suraj Jitindar Singh <sjitindarsingh@gmail.com>
commit 74422e2

In lparcfg_write we hard code kbuf_sz and then use this as the variable
length of kbuf creating a variable length array. Since we're hard coding
the length anyway just define the array using this as the length and
remove the need for kbuf_sz, thus removing the variable length array.

	Signed-off-by: Suraj Jitindar Singh <sjitindarsingh@gmail.com>
	Reviewed-by: Joel Stanley <joel@jms.id.au>
	Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
(cherry picked from commit 74422e2)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
Rebuild_History BUILDABLE
Rebuilding Kernel from rpm changelog with Fuzz Limit: 87.50%
Number of commits in upstream range v4.18~1..kernel-mainline: 625874
Number of commits in rpm: 26
Number of commits matched with upstream: 8 (30.77%)
Number of commits in upstream but not in rpm: 625866
Number of commits NOT found in upstream: 18 (69.23%)

Rebuilding Kernel on Branch rocky8_10_rebuild_kernel-4.18.0-553.159.1.el8_10 for kernel-4.18.0-553.159.1.el8_10
Clean Cherry Picks: 6 (75.00%)
Empty Cherry Picks: 1 (12.50%)
_______________________________

Full Details Located here:
ciq/ciq_backports/kernel-4.18.0-553.159.1.el8_10/rebuild.details.txt

Includes:
* git commit header above
* Empty Commits with upstream SHA
* RPM ChangeLog Entries that could not be matched

Individual Empty Commit failures contained in the same containing directory.
The git message for empty commits will have the path for the failed commit.
File names are the first 8 characters of the upstream SHA
@PlaidCat
PlaidCat dismissed stale reviews from kerneltoast and bmastbergen September 9, 2026 22:15

The merge-base changed after approval.

@PlaidCat

PlaidCat commented Sep 9, 2026

Copy link
Copy Markdown
Collaborator Author

I THINK the last rocky8_10 rebase PR might have been merged via the github PR button instead of doing a fast-forward merge, which is why this is flagged as not mergeable. When this PR gets approved we'll need to do some manual work to get things fixed up correctly.

You're correct I just fixed and force pushed the changes, there will be a new rebuild tonight added onto this commit.

jira KERNEL-1574
cve CVE-2026-53002
Rebuild_History Non-Buildable kernel-4.18.0-553.160.1.el8_10
commit-author Florian Westphal <fw@strlen.de>
commit 6e7066b

Replace it with scnprintf, the buffer sizes are expected to be large enough
to hold the result, no need for snprintf+overflow check.

Increase buffer size in mangle_content_len() while at it.

BUG: KASAN: stack-out-of-bounds in vsnprintf+0xea5/0x1270
Write of size 1 at addr [..]
 vsnprintf+0xea5/0x1270
 sprintf+0xb1/0xe0
 mangle_content_len+0x1ac/0x280
 nf_nat_sdp_session+0x1cc/0x240
 process_sdp+0x8f8/0xb80
 process_invite_request+0x108/0x2b0
 process_sip_msg+0x5da/0xf50
 sip_help_tcp+0x45e/0x780
 nf_confirm+0x34d/0x990
 [..]

Fixes: 9fafcd7 ("[NETFILTER]: nf_conntrack/nf_nat: add SIP helper port")
	Reported-by: Yiming Qian <yimingqian591@gmail.com>
	Signed-off-by: Florian Westphal <fw@strlen.de>
	Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
(cherry picked from commit 6e7066b)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1574
cve CVE-2026-64007
Rebuild_History Non-Buildable kernel-4.18.0-553.160.1.el8_10
commit-author Chris Mason <clm@meta.com>
commit 92170e6

synproxy_tstamp_adjust() rewrites the TCP timestamp option in place
and then patches the TCP checksum via inet_proto_csum_replace4() on
the caller-supplied tcphdr pointer.  Both ipv4_synproxy_hook() and
ipv6_synproxy_hook() obtain that pointer with skb_header_pointer()
before calling in, so it may either alias skb->head directly or
point at the caller's on-stack _tcph buffer.

Between obtaining the pointer and using it, the function calls
skb_ensure_writable(skb, optend), which on a cloned or non-linear
skb invokes pskb_expand_head() and frees the old skb->head.  After
that point the cached th is stale:

    caller (ipv[46]_synproxy_hook)
      th = skb_header_pointer(skb, ..., &_tcph)
      synproxy_tstamp_adjust(skb, protoff, th, ...)
        skb_ensure_writable(skb, optend)
          pskb_expand_head()        /* kfree(old skb->head) */
        ...
        inet_proto_csum_replace4(&th->check, ...)
                                    /* writes into freed head, or
                                       into the caller's stack copy
                                       leaving the on-wire checksum
                                       stale */

The option bytes are written through skb->data and are fine; only
the checksum update goes through th and so lands in the wrong
place.  The result is either a write into freed slab memory or a
packet leaving with a checksum that does not match its payload.

Fix by re-deriving th from skb->data + protoff immediately after
skb_ensure_writable() succeeds, so the subsequent checksum update
targets the linear, writable header.

Fixes: 48b1de4 ("netfilter: add SYNPROXY core/target")
Assisted-by: kres (claude-opus-4-7)
	Signed-off-by: Chris Mason <clm@meta.com>
	Reviewed-by: Fernando Fernandez Mancera <fmancera@suse.de>
	Signed-off-by: Florian Westphal <fw@strlen.de>
(cherry picked from commit 92170e6)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1574
cve CVE-2026-43493
Rebuild_History Non-Buildable kernel-4.18.0-553.160.1.el8_10
commit-author Herbert Xu <herbert@gondor.apana.org.au>
commit e8d9982

We should not be modifying the original request's MAY_SLEEP flag
upon completion.  It makes no sense to do so anyway.

	Reported-by: Eric Biggers <ebiggers@kernel.org>
Fixes: 5068c7a ("crypto: pcrypt - Add pcrypt crypto...")
	Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
	Tested-by: Eric Biggers <ebiggers@kernel.org>
	Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
(cherry picked from commit e8d9982)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1574
cve CVE-2026-43493
Rebuild_History Non-Buildable kernel-4.18.0-553.160.1.el8_10
commit-author Daniel Jordan <daniel.m.jordan@oracle.com>
commit 68b6dea

These three events can race when pcrypt is used multiple times in a
template ("pcrypt(pcrypt(...))"):

  1.  [taskA] The caller makes the crypto request via crypto_aead_encrypt()
  2.  [kworkerB] padata serializes the inner pcrypt request
  3.  [kworkerC] padata serializes the outer pcrypt request

3 might finish before the call to crypto_aead_encrypt() returns in 1,
resulting in two possible issues.

First, a use-after-free of the crypto request's memory when, for
example, taskA writes to the outer pcrypt request's padata->info in
pcrypt_aead_enc() after kworkerC completes the request.

Second, the outer pcrypt request overwrites the inner pcrypt request's
return code with -EINPROGRESS, making a successful request appear to
fail.  For instance, kworkerB writes the outer pcrypt request's
padata->info in pcrypt_aead_done() and then taskA overwrites it
in pcrypt_aead_enc().

Avoid both situations by delaying the write of padata->info until after
the inner crypto request's return code is checked.  This prevents the
use-after-free by not touching the crypto request's memory after the
next-inner crypto request is made, and stops padata->info from being
overwritten.

Fixes: 5068c7a ("crypto: pcrypt - Add pcrypt crypto parallelization wrapper")
	Reported-by: syzbot+b187b77c8474f9648fae@syzkaller.appspotmail.com
	Signed-off-by: Daniel Jordan <daniel.m.jordan@oracle.com>
	Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
(cherry picked from commit 68b6dea)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1574
cve CVE-2026-43493
Rebuild_History Non-Buildable kernel-4.18.0-553.160.1.el8_10
commit-author Herbert Xu <herbert@gondor.apana.org.au>
commit 915b692

MAY_BACKLOG requests can return EBUSY.  Handle them by checking
for that value and filtering out EINPROGRESS notifications.

	Reported-by: Yiming Qian <yimingqian591@gmail.com>
Fixes: 5a1436b ("crypto: pcrypt - call the complete function on error")
	Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
(cherry picked from commit 915b692)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
Rebuild_History BUILDABLE
Rebuilding Kernel from rpm changelog with Fuzz Limit: 87.50%
Number of commits in upstream range v4.18~1..kernel-mainline: 625874
Number of commits in rpm: 15
Number of commits matched with upstream: 5 (33.33%)
Number of commits in upstream but not in rpm: 625869
Number of commits NOT found in upstream: 10 (66.67%)

Rebuilding Kernel on Branch rocky8_10_rebuild_kernel-4.18.0-553.160.1.el8_10 for kernel-4.18.0-553.160.1.el8_10
Clean Cherry Picks: 5 (100.00%)
Empty Cherry Picks: 0 (0.00%)
_______________________________

Full Details Located here:
ciq/ciq_backports/kernel-4.18.0-553.160.1.el8_10/rebuild.details.txt

Includes:
* git commit header above
* Empty Commits with upstream SHA
* RPM ChangeLog Entries that could not be matched

Individual Empty Commit failures contained in the same containing directory.
The git message for empty commits will have the path for the failed commit.
File names are the first 8 characters of the upstream SHA
jira KERNEL-1574
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Maxim Mikityanskiy <maximmi@mellanox.com>
commit a0dce87

qdisc_pkt_len_init expects transport_header to be set for GSO packets.
Patch [1] skips transport_header validation for GSO packets that don't
have network_header set at the moment of calling virtio_net_hdr_to_skb,
and allows them to pass into the stack. After patch [2] no placeholder
value is assigned to transport_header if dissection fails, so this patch
adds a check to the place where the value of transport_header is used.

[1] https://patchwork.ozlabs.org/patch/1044429/
[2] https://patchwork.ozlabs.org/patch/1046122/

	Signed-off-by: Maxim Mikityanskiy <maximmi@mellanox.com>
	Acked-by: Willem de Bruijn <willemb@google.com>
	Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit a0dce87)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1574
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Eric Dumazet <edumazet@google.com>
commit f5fca21

We want to remove our use of skb_mac_header() in tx paths,
eg remove skb_reset_mac_header() from __dev_queue_xmit().

Idea is that ndo_start_xmit() can get the mac header
simply looking at skb->data.

	Signed-off-by: Eric Dumazet <edumazet@google.com>
	Reviewed-by: Simon Horman <simon.horman@corigine.com>
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit f5fca21)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1574
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Eric Dumazet <edumazet@google.com>
commit e495a96

We want to remove our use of skb_mac_header() in tx paths,
eg remove skb_reset_mac_header() from __dev_queue_xmit().

Idea is that ndo_start_xmit() can get the mac header
simply looking at skb->data.

	Signed-off-by: Eric Dumazet <edumazet@google.com>
	Reviewed-by: Simon Horman <simon.horman@corigine.com>
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit e495a96)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1574
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Fengyuan Gong <gfengyuan@google.com>
commit a41851b

Refine qdisc_pkt_len_init to include headers up through
the inner transport header when computing header size
for encapsulations. Also refine net/sched/sch_cake.c
borrowed from qdisc_pkt_len_init().

	Signed-off-by: Fengyuan Gong <gfengyuan@google.com>
	Reviewed-by: Willem de Bruijn <willemb@google.com>
	Reviewed-by: Eric Dumazet <edumazet@google.com>
	Acked-by: Toke Høiland-Jørgensen <toke@redhat.com>
Link: https://patch.msgid.link/20250702160741.1204919-1-gfengyuan@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit a41851b)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1574
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Eric Dumazet <edumazet@google.com>
commit b2a38f6
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-4.18.0-553.162.1.el8_10/b2a38f6d.failed

Add a new u16 field, next to pkt_len : pkt_segs

This will cache shinfo->gso_segs to speed up qdisc deqeue().

Move slave_dev_queue_mapping at the end of qdisc_skb_cb,
and move three bits from tc_skb_cb :
- post_ct
- post_ct_snat
- post_ct_dnat

	Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20251121083256.674562-2-edumazet@google.com
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>

(cherry picked from commit b2a38f6)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	include/net/sch_generic.h
#	net/core/dev.c
#	net/sched/act_ct.c
jira KERNEL-1574
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Eric Dumazet <edumazet@google.com>
commit ab9a9a9

One path takes care of SKB_GSO_DODGY, assuming
skb->len is bigger than hdr_len.

virtio_net_hdr_to_skb() does not fully dissect TCP headers,
it only make sure it is at least 20 bytes.

It is possible for an user to provide a malicious 'GSO' packet,
total length of 80 bytes.

- 20 bytes of IPv4 header
- 60 bytes TCP header
- a small gso_size like 8

virtio_net_hdr_to_skb() would declare this packet as a normal
GSO packet, because it would see 40 bytes of payload,
bigger than gso_size.

We need to make detect this case to not underflow
qdisc_skb_cb(skb)->pkt_len.

Fixes: 1def923 ("net_sched: more precise pkt_len computation")
	Signed-off-by: Eric Dumazet <edumazet@google.com>
	Reviewed-by: Willem de Bruijn <willemb@google.com>
	Reviewed-by: David Ahern <dsahern@kernel.org>
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>
(cherry picked from commit ab9a9a9)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1574
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Eric Dumazet <edumazet@google.com>
commit be1b70a

Qdisc use shinfo->gso_segs for their pkts stats in bstats_update(),
but this field needs to be initialized for SKB_GSO_DODGY users.

	Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20251121083256.674562-3-edumazet@google.com
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>

(cherry picked from commit be1b70a)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
…it()

jira KERNEL-1574
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Eric Dumazet <edumazet@google.com>
commit 874c192
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-4.18.0-553.162.1.el8_10/874c1928.failed

qdisc_pkt_len_init() is currently initalizing qdisc_skb_cb(skb)->pkt_len.

Add qdisc_skb_cb(skb)->pkt_segs initialization and rename this function
to qdisc_pkt_len_segs_init().

	Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20251121083256.674562-4-edumazet@google.com
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>

(cherry picked from commit 874c192)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/core/dev.c
jira KERNEL-1574
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Eric Dumazet <edumazet@google.com>
commit f9e00e5
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-4.18.0-553.162.1.el8_10/f9e00e51.failed

sch_handle_ingress() sets qdisc_skb_cb(skb)->pkt_len.

We also need to initialize qdisc_skb_cb(skb)->pkt_segs.

	Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20251121083256.674562-5-edumazet@google.com
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>

(cherry picked from commit f9e00e5)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/core/dev.c
jira KERNEL-1574
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Eric Dumazet <edumazet@google.com>
commit 30e02ec
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-4.18.0-553.162.1.el8_10/30e02ec3.failed

Reduce indentation level by returning early if the transport header
was not set.

Add an unlikely() clause as this is not the common case.

No functional change.

	Signed-off-by: Eric Dumazet <edumazet@google.com>
	Reviewed-by: Joe Damato <joe@dama.to>
Link: https://patch.msgid.link/20260403221540.3297753-2-edumazet@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 30e02ec)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/core/dev.c
jira KERNEL-1574
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Eric Dumazet <edumazet@google.com>
commit 7fb4c19
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-4.18.0-553.162.1.el8_10/7fb4c196.failed

Most ndo_start_xmit() methods expects headers of gso packets
to be already in skb->head.

net/core/tso.c users are particularly at risk, because tso_build_hdr()
does a memcpy(hdr, skb->data, hdr_len);

qdisc_pkt_len_segs_init() already does a dissection of gso packets.

Use pskb_may_pull() instead of skb_header_pointer() to make
sure drivers do not have to reimplement this.

Some malicious packets could be fed, detect them so that we can
drop them sooner with a new SKB_DROP_REASON_SKB_BAD_GSO drop_reason.

Fixes: e876f20 ("net: Add a software TSO helper API")
	Signed-off-by: Eric Dumazet <edumazet@google.com>
	Reviewed-by: Joe Damato <joe@dama.to>
Link: https://patch.msgid.link/20260403221540.3297753-3-edumazet@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 7fb4c19)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/core/dev.c
jira KERNEL-1574
cve CVE-2026-53091
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Cosmin Ratiu <cratiu@nvidia.com>
commit fa90a31

On VXLAN over IPsec egress, xfrm{4,6}_transport_output() blindly
overwrite inner_transport_header (== the inner TCP header saved in VXLAN
iptunnel_handle_offloads() -> skb_reset_inner_headers()) with the
current transport_header (== the VXLAN outer UDP header set by
udp_tunnel_xmit_skb()).

This was a latent bug, harmless until commit [1] added a doff validation
check in qdisc_pkt_len_segs_init() for encapsulated GSO packets. With
the wrong inner_transport_header set by xfrm, qdisc_pkt_len_segs_init()
interprets inner_transport_header as a TCP header, reads doff=0 from the
upper byte of the VNI and drops the packet with DROP_REASON_SKB_BAD_GSO.

Besides the use in GSO to determine the header size of segmented
packets, inner_transport_header might be used by drivers to set up
inner checksum offloading by pointing the HW to the inner transport
header. A quick browse through available drivers shows that mlx5 uses
skb->csum_start specifically for this scenario, while others either
don't support VXLAN over IPsec crypto offload (ixgbe) or the HW is
capable of parsing the packets itself (nfp, Chelsio).

But in all cases, it is more correct to let the inner_transport_header
point to the innermost header instead of overwriting it in xfrm.

So fix this by guarding all four inner header save sites in
xfrm_output.c (xfrm{4,6}_transport_output, xfrm{4,6}_tunnel_encap_add)
with a check for skb->inner_protocol. When inner_protocol is set, a
tunnel layer (VXLAN, Geneve, GRE, etc.) has already saved the correct
inner header offsets and they must not be overwritten. When
inner_protocol is zero, no prior tunnel encapsulation exists and xfrm
must save the inner headers itself. The tunnel mode checks are only
added for completion, since they aren't strictly required, as
xfrm_output() forces software GSO in tunnel mode before encap.

This makes the previously added test pass:
 # ./tools/testing/selftests/drivers/net/hw/ipsec_vxlan.py
 TAP version 13
 1..4
 ok 1 ipsec_vxlan.test_vxlan_ipsec_crypto_offload.outer_v4_inner_v4
 ok 2 ipsec_vxlan.test_vxlan_ipsec_crypto_offload.outer_v4_inner_v6
 ok 3 ipsec_vxlan.test_vxlan_ipsec_crypto_offload.outer_v6_inner_v4
 ok 4 ipsec_vxlan.test_vxlan_ipsec_crypto_offload.outer_v6_inner_v6
 # Totals: pass:4 fail:0 xfail:0 xpass:0 skip:0 error:0

[1] commit 7fb4c19 ("net: pull headers in qdisc_pkt_len_segs_init()")
Fixes: f1bd7d6 ("xfrm: Add encapsulation header offsets while SKB is not encrypted")
	Signed-off-by: Cosmin Ratiu <cratiu@nvidia.com>
	Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
(cherry picked from commit fa90a31)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1574
cve CVE-2026-64113
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Michael Bommarito <michael.bommarito@gmail.com>
commit 5d49b56

ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's
own address (VEPA multicast workaround) by freeing the skb and
continuing to the next descriptor:

    dev_kfree_skb_irq(skb);
    continue;

The skb pointer is declared outside the while loop and persists across
iterations.  Because the continue skips the "skb = NULL" reset at the
bottom of the loop, the next iteration enters the "else if (skb)" path
and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing
skb_shinfo(skb)->nr_frags - a use-after-free in NAPI softirq context.

The sibling driver iavf already handles this correctly by nulling the
pointer before continuing.  Apply the same pattern here.

I do not have ixgbevf hardware; the bug was found by static analysis
(scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool
corroboration with the highest score in the scan).  The UAF was confirmed
under KASAN by loading a test module that reproduces the exact code
pattern (alloc skb, kfree_skb, then read skb_shinfo(skb)->nr_frags):

  BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000
  Read of size 8 at addr 000000006163ae78 by task insmod/30
  freed 208-byte region [000000006163adc0, 000000006163ae90)

QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF
driver does not include the VEPA source pruning path, so a full
end-to-end reproduction with emulated hardware was not possible.

Fixes: bad1723 ("ixgbevf: Change receive model to use double buffered page based receives")
	Cc: stable@vger.kernel.org
	Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
	Reviewed-by: Simon Horman <horms@kernel.org>
	Tested-by: Rafal Romanowski <rafal.romanowski@intel.com>
	Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Link: https://patch.msgid.link/20260515182419.1597859-8-anthony.l.nguyen@intel.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 5d49b56)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1574
cve CVE-2026-64015
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Linus Torvalds <torvalds@linux-foundation.org>
commit 43a1e37

Nicholas Carlini reports that the keyring code calls assoc_array_find()
in find_key_to_update() without holding the RCU read lock, while the
assoc_array_gc() code really is designed around removing the node from
the tree and then freeing it after an RCU grace-period.

The regular key handling doesn't see this because holding the keyring
semaphore hides any lifetime issues, but the persistent key handling
uses a different model.

Instead of extending the keyring locking, just do the simple RCU locking
that the assoc_array was designed for.

	Reported-by: Nicholas Carlini <npc@anthropic.com>
	Cc: David Howells <dhowells@redhat.com>
	Cc: Jarkko Sakkinen <jarkko@kernel.org>
	Cc: Paul Moore <paul@paul-moore.com>
	Cc: James Morris James Morris <jmorris@namei.org>
	Cc: Serge E. Hallyn <serge@hallyn.com>
	Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
(cherry picked from commit 43a1e37)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
…how()

jira KERNEL-1574
cve CVE-2026-46149
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Greg Kroah-Hartman <gregkh@linuxfoundation.org>
commit 772a896

target_tg_pt_gp_members_show() formats LUN paths with snprintf() into a
256-byte stack buffer, then will memcpy() cur_len bytes from that
buffer.  snprintf() returns the length the output would have had, which
can exceed the buffer size when the fabric WWN is long because iSCSI IQN
names can be up to 223 bytes.  The check at the memcpy() site only
guards the destination page write, not the source read, so memcpy() will
read past the stack buffer and copy adjacent stack contents to the sysfs
reader, which when CONFIG_FORTIFY_SOURCE is enabled, fortify_panic()
will be triggered.

Commit 27e0665 ("scsi: target: target_core_configfs: Add length
check to avoid buffer overflow") added the same bound to the
target_lu_gp_members_show() but the tg_pt_gp variant was missed so
resolve that here.

	Cc: Martin K. Petersen <martin.petersen@oracle.com>
Fixes: c66ac9d ("[SCSI] target: Add LIO target core v4.0.0-rc6")
Assisted-by: gregkh_clanker_t1000
	Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Link: https://patch.msgid.link/2026041159-garter-theft-3be0@gregkh
	Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
(cherry picked from commit 772a896)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1574
cve CVE-2025-68745
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Tony Battersby <tonyb@cybernetics.com>
commit d46c69a

Commit aefed3e ("scsi: qla2xxx: target: Fix offline port handling
and host reset handling") caused two problems:

1. Commands sent to FW, after chip reset got stuck and never freed as FW
   is not going to respond to them anymore.

2. BUG_ON(cmd->sg_mapped) in qlt_free_cmd().  Commit 26f9ce5
   ("scsi: qla2xxx: Fix missed DMA unmap for aborted commands")
   attempted to fix this, but introduced another bug under different
   circumstances when two different CPUs were racing to call
   qlt_unmap_sg() at the same time: BUG_ON(!valid_dma_direction(dir)) in
   dma_unmap_sg_attrs().

So revert "scsi: qla2xxx: Fix missed DMA unmap for aborted commands" and
partially revert "scsi: qla2xxx: target: Fix offline port handling and
host reset handling" at __qla2x00_abort_all_cmds.

Fixes: aefed3e ("scsi: qla2xxx: target: Fix offline port handling and host reset handling")
Fixes: 26f9ce5 ("scsi: qla2xxx: Fix missed DMA unmap for aborted commands")
Co-developed-by: Dmitry Bogdanov <d.bogdanov@yadro.com>
	Signed-off-by: Dmitry Bogdanov <d.bogdanov@yadro.com>
	Signed-off-by: Tony Battersby <tonyb@cybernetics.com>
Link: https://patch.msgid.link/0e7e5d26-e7a0-42d1-8235-40eeb27f3e98@cybernetics.com
	Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
(cherry picked from commit d46c69a)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1574
cve CVE-2026-52986
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Florian Westphal <fw@strlen.de>
commit 8cf6809

Replace unsafe port parsing in epaddr_len(), ct_sip_parse_header_uri(),
and ct_sip_parse_request() with a new sip_parse_port() helper that
validates each digit against the buffer limit, eliminating the use of
simple_strtoul() which assumes NUL-terminated strings.

The previous code dereferenced pointers without bounds checks after
sip_parse_addr() and relied on simple_strtoul() on non-NUL-terminated
skb data. A port that reaches the buffer limit without a trailing
character is also rejected as malformed.

Also get rid of all simple_strtoul() usage in conntrack, prefer a
stricter version instead.  There are intentional changes:

- Bail out if number is > UINT_MAX and indicate a failure, same for
  too long sequences.
  While we do accept 05535 as port 5535, we will not accept e.g.
  'sip:10.0.0.1:005060'.  While its syntactically valid under RFC 3261,
  we should restrict this to not waste cycles when presented with
  malformed packets with 64k '0' characters.

- Force base 10 in ct_sip_parse_numerical_param(). This is used to fetch
  'expire=' and 'rports='; both are expected to use base-10.

- In nf_nat_sip.c, only accept the parsed value if its within the 1k-64k
  range.

- epaddr_len now returns 0 if the port is invalid, as it already does
  for invalid ip addresses.  This is intentional. nf_conntrack_sip
  performs lots of guesswork to find the right parts of the message
  to parse.  Being stricter could break existing setups.
  Connection tracking helpers are designed to allow traffic to
  pass, not to block it.

Based on an earlier patch from Jenny Guanni Qu <qguanni@gmail.com>.

Fixes: 05e3ced ("[NETFILTER]: nf_conntrack_sip: introduce SIP-URI parsing helper")
	Reported-by: Klaudia Kloc <klaudia@vidocsecurity.com>
	Reported-by: Dawid Moczadło <dawid@vidocsecurity.com>
	Reported-by: Jenny Guanni Qu <qguanni@gmail.com>.
	Signed-off-by: Florian Westphal <fw@strlen.de>
	Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
(cherry picked from commit 8cf6809)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1574
cve CVE-2026-53246
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Xin Long <lucien.xin@gmail.com>
commit 0861615
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-4.18.0-553.162.1.el8_10/0861615c.failed

When a listening SCTP server processes a COOKIE_ECHO chunk, the cached
peer INIT chunk embedded after the cookie is parsed and its parameters
are later walked by sctp_process_init() using sctp_walk_params().

However, the chunk header length of this cached INIT chunk was not
validated against the remaining buffer in the COOKIE_ECHO payload. If
the length field is inflated, the parameter walk can run beyond the
actual received data, leading to out-of-bounds reads and potential
memory corruption during later parameter handling (e.g. STATE_COOKIE
processing and kmemdup() copies).

Add a bounds check in sctp_unpack_cookie() to ensure the cached INIT
chunk length does not exceed the available data in the COOKIE_ECHO
buffer before it is used.

Fixes: 1da177e ("Linux-2.6.12-rc2")
	Reported-by: Brian Geffon <bgeffon@google.com>
	Signed-off-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/eb60825fa22d6f9e663c7d4dbb69f397b5d34d42.1780362366.git.lucien.xin@gmail.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 0861615)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/sctp/sm_make_chunk.c
jira KERNEL-1574
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Andreas Gruenbacher <agruenba@redhat.com>
commit d3b39fc
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-4.18.0-553.162.1.el8_10/d3b39fcb.failed

Use lockref_get_not_dead() instead of an unguarded __lockref_is_dead()
check.

	Signed-off-by: Andreas Gruenbacher <agruenba@redhat.com>
(cherry picked from commit d3b39fc)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	fs/gfs2/glock.c
jira KERNEL-1574
cve CVE-2026-52917
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Zhao Zhang <zzhan461@ucr.edu>
commit 5eba3e4

The SCTP exact sock_diag lookup can hold a transport reference, block on
lock_sock(sk), and then resume after sctp_association_free() has marked
the association dead and freed its bind address list.

When that happens, inet_assoc_attr_size() and
inet_diag_msg_sctpasoc_fill() can still dereference association state
that is no longer valid for reporting. In particular,
inet_diag_msg_sctpasoc_fill() may read an empty bind-address list as a
real sctp_sockaddr_entry and trigger an out-of-bounds read from
unrelated association memory.

Reject the association after taking the socket lock if it has been
reaped or detached from the endpoint, and report the lookup as stale.
This keeps the exact dump-one path from formatting torn association
state.

Fixes: 8f840e4 ("sctp: add the sctp_diag.c file")
	Cc: stable@kernel.org
	Reported-by: Yuan Tan <yuantan098@gmail.com>
	Reported-by: Yifan Wu <yifanwucs@gmail.com>
	Reported-by: Juefei Pu <tomapufckgml@gmail.com>
	Reported-by: Zhengchuan Liang <zcliangcn@gmail.com>
	Reported-by: Xin Liu <bird@lzu.edu.cn>
	Signed-off-by: Zhao Zhang <zzhan461@ucr.edu>
	Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
	Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/fac6043fa20a2ff68e12958c431836f692c51268.1780113823.git.zzhan461@ucr.edu
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 5eba3e4)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1574
cve CVE-2026-63971
Rebuild_History Non-Buildable kernel-4.18.0-553.162.1.el8_10
commit-author Zhenghang Xiao <kipreyyy@gmail.com>
commit f14fe63

sctp_wait_for_connect() drops and re-acquires the socket lock while
waiting for the association to reach ESTABLISHED state. During this
window, another thread can peeloff the association to a new socket via
getsockopt(SCTP_SOCKOPT_PEELOFF), changing asoc->base.sk. After
re-acquiring the old socket lock, sctp_wait_for_connect() returns
success without noticing the migration — the caller then accesses
the association under the wrong lock in sctp_datamsg_from_user().

Add the same sk != asoc->base.sk check that sctp_wait_for_sndbuf()
already has, returning an error if the association was migrated while
we slept.

Fixes: 668c9be ("sctp: implement assign_number for sctp_stream_interleave")
	Signed-off-by: Zhenghang Xiao <kipreyyy@gmail.com>
	Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260527032411.60959-1-kipreyyy@gmail.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit f14fe63)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
Rebuild_History BUILDABLE
Rebuilding Kernel from rpm changelog with Fuzz Limit: 87.50%
Number of commits in upstream range v4.18~1..kernel-mainline: 625874
Number of commits in rpm: 36
Number of commits matched with upstream: 22 (61.11%)
Number of commits in upstream but not in rpm: 625852
Number of commits NOT found in upstream: 14 (38.89%)

Rebuilding Kernel on Branch rocky8_10_rebuild_kernel-4.18.0-553.162.1.el8_10 for kernel-4.18.0-553.162.1.el8_10
Clean Cherry Picks: 14 (63.64%)
Empty Cherry Picks: 7 (31.82%)
_______________________________

Full Details Located here:
ciq/ciq_backports/kernel-4.18.0-553.162.1.el8_10/rebuild.details.txt

Includes:
* git commit header above
* Empty Commits with upstream SHA
* RPM ChangeLog Entries that could not be matched

Individual Empty Commit failures contained in the same containing directory.
The git message for empty commits will have the path for the failed commit.
File names are the first 8 characters of the upstream SHA
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants