Changelog in Linux kernel 5.15.220

 
accessibility: speakup: unregister tty ldisc on later init failures [+ + +]
Author: Haoxiang Li <[email protected]>
Date:   Mon Jun 1 01:08:04 2026 +0200

    accessibility: speakup: unregister tty ldisc on later init failures
    
    commit a76acbaec9b8fd74413646984d2e3626d0543e39 upstream.
    
    The ldisc registration is intentionally non-fatal, since some synth
    drivers do not use tty/ldisc.  However, once speakup_init() continues
    past the registration point and later fails, the init unwind path should
    mirror speakup_exit() and call spk_ttyio_unregister_ldisc().
    
    Add the missing unregister call to the error path after synth_release(),
    matching the normal module exit cleanup order.
    
    Signed-off-by: Haoxiang Li <[email protected]>
    Signed-off-by: Samuel Thibault <[email protected]>
    Fixes: e23a9b439ce9 ("staging: speakup: safely register and unregister ldisc")
    Cc: [email protected]
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() [+ + +]
Author: Mehul Rao <[email protected]>
Date:   Thu Mar 5 14:35:07 2026 -0500

    ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain()
    
    [ Upstream commit 9b1dbd69ba6f8f8c69bc7b77c2ce3b9c6ed05ba6 ]
    
    In the drain loop, the local variable 'runtime' is reassigned to a
    linked stream's runtime (runtime = s->runtime at line 2157).  After
    releasing the stream lock at line 2169, the code accesses
    runtime->no_period_wakeup, runtime->rate, and runtime->buffer_size
    (lines 2170-2178) — all referencing the linked stream's runtime without
    any lock or refcount protecting its lifetime.
    
    A concurrent close() on the linked stream's fd triggers
    snd_pcm_release_substream() → snd_pcm_drop() → pcm_release_private()
    → snd_pcm_unlink() → snd_pcm_detach_substream() → kfree(runtime).
    No synchronization prevents kfree(runtime) from completing while the
    drain path dereferences the stale pointer.
    
    Fix by caching the needed runtime fields (no_period_wakeup, rate,
    buffer_size) into local variables while still holding the stream lock,
    and using the cached values after the lock is released.
    
    Fixes: f2b3614cefb6 ("ALSA: PCM - Don't check DMA time-out too shortly")
    Cc: [email protected]
    Signed-off-by: Mehul Rao <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Takashi Iwai <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>

ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams [+ + +]
Author: Ji'an Zhou <[email protected]>
Date:   Thu Jun 4 14:25:59 2026 +0000

    ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
    
    [ Upstream commit 88fe2e3658726cb21ff2dcf9770bf672f9b9d31b ]
    
    snd_pcm_drain() uses init_waitqueue_entry which does not clear
    entry.prev/next, and add_wait_queue with a conditional
    remove_wait_queue that is skipped when to_check is no longer
    in the group after concurrent UNLINK.  The orphaned wait entry
    remains on the unlinked substream sleep queue.  On the next
    drain iteration, add_wait_queue adds the entry to a new queue
    while still linked on the old one, corrupting both lists.  A
    subsequent wake_up dereferences NULL at the func pointer
    (mapped from the spinlock at offset 0 of the misinterpreted
    wait_queue_head_t), causing a kernel panic.
    
    Replace init_waitqueue_entry/add_wait_queue/conditional
    remove_wait_queue with init_wait_entry/prepare_to_wait/
    finish_wait.  init_wait_entry clears prev/next via
    INIT_LIST_HEAD on each iteration and sets
    autoremove_wake_function which auto-removes the entry on
    wake-up.  finish_wait safely handles both the already-removed
    and still-queued cases.
    
    Fixes: 9b1dbd69ba6f ("ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain")
    Signed-off-by: Ji'an Zhou <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Takashi Iwai <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>

ALSA: pcm: fix wait_time calculations [+ + +]
Author: Oswald Buddenhagen <[email protected]>
Date:   Wed Apr 5 22:12:19 2023 +0200

    ALSA: pcm: fix wait_time calculations
    
    [ Upstream commit 3ed2b549b39f57239aad50a255ece353997183fd ]
    
    ... in wait_for_avail() and snd_pcm_drain().
    
    t was calculated in seconds, so it would be pretty much always zero, to
    be subsequently de-facto ignored due to being max(t, 10)'d. And then it
    (i.e., 10) would be treated as secs, which doesn't seem right.
    
    However, fixing it to properly calculate msecs would potentially cause
    timeouts when using twice the period size for the default timeout (which
    seems reasonable to me), so instead use the buffer size plus 10 percent
    to be on the safe side ... but that still seems insufficient, presumably
    because the hardware typically needs a moment to fire up. To compensate
    for this, we up the minimal timeout to 100ms, which is still two orders
    of magnitude less than the bogus minimum.
    
    substream->wait_time was also misinterpreted as jiffies, despite being
    documented as being in msecs. Only the soc/sof driver sets it - to 500,
    which looks very much like msecs were intended.
    
    Speaking of which, shouldn't snd_pcm_drain() also use substream->
    wait_time?
    
    As a drive-by, make the debug messages on timeout less confusing.
    
    Signed-off-by: Oswald Buddenhagen <[email protected]>
    Link: https://lore.kernel.org/r/[email protected]
    Signed-off-by: Takashi Iwai <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>

ALSA: usb-audio: Complete cleanup after system-resume errors [+ + +]
Author: Will Porter <[email protected]>
Date:   Mon Aug 24 17:57:57 2026 -0500

    ALSA: usb-audio: Complete cleanup after system-resume errors
    
    commit 1739a976312e110c93a8dee66a1cdf893a1b187e upstream.
    
    A failed system resume can leave the card unusable until reboot.
    usb_audio_resume() jumps to err_out when snd_usb_pcm_resume() or
    snd_usb_mixer_resume() fails. The error path skips the out: block, which
    restores D0 and decrements chip->num_suspended_intf.
    
    The card stays in SNDRV_CTL_POWER_D3hot, so later control access blocks in
    snd_power_ref_and_wait(). USB core logs an interface resume callback error.
    It does not retry that callback, so a later callback cannot complete the
    skipped cleanup.
    
    usb_audio_suspend() increments num_suspended_intf before returning success.
    A system-resume callback must consume the system-suspend count even if a
    component resume fails. Otherwise, the stranded count skews later suspend
    and resume cycles.
    
    Do not apply this cleanup to runtime-resume errors. Runtime PM can retry
    -EAGAIN or -EBUSY without another suspend callback. The count must continue
    to describe that suspended interface. Other runtime-resume errors latch
    runtime_error in the PM core and do not cause an immediate callback retry.
    
    Both parts of the system-resume error path are longstanding. Commit
    88a8516a2128a ("ALSA: usbaudio: implement USB autosuspend") introduced
    err_out past the D0 restore. Commit 862b2509d157c ("ALSA: usb-audio: Fix
    inconsistent card PM state after resume") later moved
    num_suspended_intf-- into the out: block. The error path now skips both
    operations.
    
    No third-party code is needed to reach the error path.
    snd_usb_mixer_resume() ends in snd_usb_mixer_activate(), which returns the
    result of usb_submit_urb() for devices that have a mixer status URB. Its
    mixer->private_resume hook can also fail through scarlett2_init_notify().
    snd_usb_pcm_resume() issues a SET_CUR request to a UAC3 power domain. It
    can return -EPIPE or -EIO when the device stalls the request.
    
    Route a component error through out: only when system_suspend is nonzero.
    Continue to return runtime-resume errors through err_out. Later component
    resume stages remain skipped. The original error still reaches USB core.
    A later transfer can fail if the device did not recover.
    
    I reproduced the system-resume failure on an Audient iD14 MkI with an
    out-of-tree diagnostic mixer resume hook. An injected -EIO on the unpatched
    core left control readers in uninterruptible sleep in
    snd_power_ref_and_wait() until a reboot. With this patch, the same failure
    restored control access. A second system suspend and resume also succeeded
    after I disabled fault injection.
    
    Assisted-by: Claude:claude-opus-5
    Assisted-by: Antigravity:gemini-3.1-pro-high
    Assisted-by: Codex:gpt-5.6-sol
    Fixes: 88a8516a2128a ("ALSA: usbaudio: implement USB autosuspend")
    Fixes: 862b2509d157c ("ALSA: usb-audio: Fix inconsistent card PM state after resume")
    Cc: <[email protected]>
    Signed-off-by: Will Porter <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Takashi Iwai <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() [+ + +]
Author: Marouane El Moufid <[email protected]>
Date:   Sun Aug 23 13:55:48 2026 +0000

    ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
    
    commit 1035a8f63bae28e498b0e7b5ac91d749844a7158 upstream.
    
    snd_usbmidi_novation_output() lays out a two-byte header at
    transfer_buffer[0..1] and passes &transfer_buffer[2] together with a
    length of ep->max_transfer - 2 to snd_rawmidi_transmit():
    
            count = snd_rawmidi_transmit(ep->ports[0].substream,
                                         &transfer_buffer[2],
                                         ep->max_transfer - 2);
    
    ep->max_transfer comes from the output endpoint's wMaxPacketSize via
    usb_maxpacket(). A malformed or malicious device can advertise a bulk
    OUT endpoint with a wMaxPacketSize of 1 - the USB core only clamps this
    value downwards - so ep->max_transfer becomes 1 and the count argument
    becomes -1.
    
    snd_rawmidi_transmit() passes the negative count on to
    __snd_rawmidi_transmit_peek(), where "if (count1 > count) count1 = count"
    leaves count1 negative; get_aligned_size() keeps it negative for a
    byte-stream substream, so the following memcpy(buffer, ..., count1) runs
    with a (size_t)-1 length and writes far past the transfer buffer, which
    was allocated with usb_alloc_coherent(ep->max_transfer).
    
    This is the same class of bug that was fixed for snd_usbmidi_akai_output()
    in commit 0970274613fb ("ALSA: usb-audio: fix OOB write in
    snd_usbmidi_akai_output()"); the novation output routine was left
    unguarded. Bail out when the endpoint cannot hold the two-byte header
    plus at least one payload byte.
    
    Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
    Cc: [email protected]
    Signed-off-by: Marouane El Moufid <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Takashi Iwai <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
ASoC: tegra: Fix Master Volume Control [+ + +]
Author: Jon Hunter <[email protected]>
Date:   Tue Jun 13 10:34:53 2023 +0100

    ASoC: tegra: Fix Master Volume Control
    
    [ Upstream commit f9fd804aa0a36f15a35ca070ec4c52650876cc29 ]
    
    Commit 3ed2b549b39f ("ALSA: pcm: fix wait_time calculations") corrected
    the PCM wait_time calculations and in doing so reduced the calculated
    wait_time. This exposed an issue with the Tegra Master Volume Control
    (MVC) device where the reduced wait_time caused the MVC to fail. For now
    fix this by setting the default wait_time for Tegra to be 500ms.
    
    Fixes: 3ed2b549b39f ("ALSA: pcm: fix wait_time calculations")
    Signed-off-by: Jon Hunter <[email protected]>
    Link: https://lore.kernel.org/r/[email protected]
    Signed-off-by: Mark Brown <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>

 
bpf: Fix use-after-free in offloaded map/prog info fill [+ + +]
Author: Jiayuan Chen <[email protected]>
Date:   Thu Apr 9 10:37:32 2026 +0800

    bpf: Fix use-after-free in offloaded map/prog info fill
    
    [ Upstream commit a0c584fc18056709c8e047a82a6045d6c209f4ce ]
    
    When querying info for an offloaded BPF map or program,
    bpf_map_offload_info_fill_ns() and bpf_prog_offload_info_fill_ns()
    obtain the network namespace with get_net(dev_net(offmap->netdev)).
    However, the associated netdev's netns may be racing with teardown
    during netns destruction. If the netns refcount has already reached 0,
    get_net() performs a refcount_t increment on 0, triggering:
    
      refcount_t: addition on 0; use-after-free.
    
    Although rtnl_lock and bpf_devs_lock ensure the netdev pointer remains
    valid, they cannot prevent the netns refcount from reaching zero.
    
    Fix this by using maybe_get_net() instead of get_net(). maybe_get_net()
    uses refcount_inc_not_zero() and returns NULL if the refcount is already
    zero, which causes ns_get_path_cb() to fail and the caller to return
    -ENOENT -- the correct behavior when the netns is being destroyed.
    
    Fixes: 675fc275a3a2d ("bpf: offload: report device information for offloaded programs")
    Fixes: 52775b33bb507 ("bpf: offload: report device information about offloaded maps")
    Reported-by: Yinhao Hu <[email protected]>
    Reported-by: Kaiyan Mei <[email protected]>
    Reviewed-by: Dongliang Mu <[email protected]>
    Closes: https://lore.kernel.org/bpf/[email protected]/
    Signed-off-by: Jiayuan Chen <[email protected]>
    Acked-by: Daniel Borkmann <[email protected]>
    Link: https://lore.kernel.org/r/[email protected]
    Signed-off-by: Alexei Starovoitov <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>

bpf: Remove tst_run from lwt_seg6local_prog_ops. [+ + +]
Author: Sebastian Andrzej Siewior <[email protected]>
Date:   Wed Jul 10 16:16:31 2024 +0200

    bpf: Remove tst_run from lwt_seg6local_prog_ops.
    
    [ Upstream commit c13fda93aca118b8e5cd202e339046728ee7dddb ]
    
    The syzbot reported that the lwt_seg6 related BPF ops can be invoked
    via bpf_test_run() without without entering input_action_end_bpf()
    first.
    
    Martin KaFai Lau said that self test for BPF_PROG_TYPE_LWT_SEG6LOCAL
    probably didn't work since it was introduced in commit 04d4b274e2a
    ("ipv6: sr: Add seg6local action End.BPF"). The reason is that the
    per-CPU variable seg6_bpf_srh_states::srh is never assigned in the self
    test case but each BPF function expects it.
    
    Remove test_run for BPF_PROG_TYPE_LWT_SEG6LOCAL.
    
    Suggested-by: Martin KaFai Lau <[email protected]>
    Reported-by: [email protected]
    Fixes: d1542d4ae4df ("seg6: Use nested-BH locking for seg6_bpf_srh_states.")
    Fixes: 004d4b274e2a ("ipv6: sr: Add seg6local action End.BPF")
    Signed-off-by: Sebastian Andrzej Siewior <[email protected]>
    Acked-by: Daniel Borkmann <[email protected]>
    Link: https://lore.kernel.org/r/[email protected]
    Signed-off-by: Martin KaFai Lau <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>

 
can: j1939: add missing calls in NETDEV_UNREGISTER notification handler [+ + +]
Author: Tetsuo Handa <[email protected]>
Date:   Sat Sep 27 21:11:16 2025 +0900

    can: j1939: add missing calls in NETDEV_UNREGISTER notification handler
    
    [ Upstream commit 93a27b5891b8194a8c083c9a80d2141d4bf47ba8 ]
    
    Currently NETDEV_UNREGISTER event handler is not calling
    j1939_cancel_active_session() and j1939_sk_queue_drop_all().
    This will result in these calls being skipped when j1939_sk_release() is
    called. And I guess that the reason syzbot is still reporting
    
      unregister_netdevice: waiting for vcan0 to become free. Usage count = 2
    
    is caused by lack of these calls.
    
    Calling j1939_cancel_active_session(priv, sk) from j1939_sk_release() can
    be covered by calling j1939_cancel_active_session(priv, NULL) from
    j1939_netdev_notify().
    
    Calling j1939_sk_queue_drop_all() from j1939_sk_release() can be covered
    by calling j1939_sk_netdev_event_netdown() from j1939_netdev_notify().
    
    Therefore, we can reuse j1939_cancel_active_session(priv, NULL) and
    j1939_sk_netdev_event_netdown(priv) for NETDEV_UNREGISTER event handler.
    
    Fixes: 7fcbe5b2c6a4 ("can: j1939: implement NETDEV_UNREGISTER notification handler")
    Signed-off-by: Tetsuo Handa <[email protected]>
    Tested-by: Oleksij Rempel <[email protected]>
    Acked-by: Oleksij Rempel <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Marc Kleine-Budde <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>

can: j1939: implement NETDEV_UNREGISTER notification handler [+ + +]
Author: Tetsuo Handa <[email protected]>
Date:   Mon Aug 25 23:07:24 2025 +0900

    can: j1939: implement NETDEV_UNREGISTER notification handler
    
    [ Upstream commit 7fcbe5b2c6a4b5407bf2241fdb71e0a390f6ab9a ]
    
    syzbot is reporting
    
      unregister_netdevice: waiting for vcan0 to become free. Usage count = 2
    
    problem, for j1939 protocol did not have NETDEV_UNREGISTER notification
    handler for undoing changes made by j1939_sk_bind().
    
    Commit 25fe97cb7620 ("can: j1939: move j1939_priv_put() into sk_destruct
    callback") expects that a call to j1939_priv_put() can be unconditionally
    delayed until j1939_sk_sock_destruct() is called. But we need to call
    j1939_priv_put() against an extra ref held by j1939_sk_bind() call
    (as a part of undoing changes made by j1939_sk_bind()) as soon as
    NETDEV_UNREGISTER notification fires (i.e. before j1939_sk_sock_destruct()
    is called via j1939_sk_release()). Otherwise, the extra ref on "struct
    j1939_priv" held by j1939_sk_bind() call prevents "struct net_device" from
    dropping the usage count to 1; making it impossible for
    unregister_netdevice() to continue.
    
    Reported-by: syzbot <[email protected]>
    Closes: https://syzkaller.appspot.com/bug?extid=881d65229ca4f9ae8c84
    Tested-by: syzbot <[email protected]>
    Fixes: 9d71dd0c7009 ("can: add support of SAE J1939 protocol")
    Fixes: 25fe97cb7620 ("can: j1939: move j1939_priv_put() into sk_destruct callback")
    Signed-off-by: Tetsuo Handa <[email protected]>
    Tested-by: Oleksij Rempel <[email protected]>
    Acked-by: Oleksij Rempel <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    [mkl: remove space in front of label]
    Signed-off-by: Marc Kleine-Budde <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>

can: j1939: make j1939_sk_bind() fail if device is no longer registered [+ + +]
Author: Tetsuo Handa <[email protected]>
Date:   Tue Nov 25 22:43:12 2025 +0900

    can: j1939: make j1939_sk_bind() fail if device is no longer registered
    
    [ Upstream commit 46cea215dc9444ec32a76b1b6a9cb809e17b64d5 ]
    
    There is a theoretical race window in j1939_sk_netdev_event_unregister()
    where two j1939_sk_bind() calls jump in between read_unlock_bh() and
    lock_sock().
    
    The assumption jsk->priv == priv can fail if the first j1939_sk_bind()
    call once made jsk->priv == NULL due to failed j1939_local_ecu_get() call
    and the second j1939_sk_bind() call again made jsk->priv != NULL due to
    successful j1939_local_ecu_get() call.
    
    Since the socket lock is held by both j1939_sk_netdev_event_unregister()
    and j1939_sk_bind(), checking ndev->reg_state with the socket lock held can
    reliably make the second j1939_sk_bind() call fail (and close this race
    window).
    
    Fixes: 7fcbe5b2c6a4 ("can: j1939: implement NETDEV_UNREGISTER notification handler")
    Signed-off-by: Tetsuo Handa <[email protected]>
    Acked-by: Oleksij Rempel <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Marc Kleine-Budde <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>

 
crypto: atmel-tdes - use scatterlist length before DMA mapping [+ + +]
Author: Thorsten Blum <[email protected]>
Date:   Thu Jun 11 12:36:35 2026 +0200

    crypto: atmel-tdes - use scatterlist length before DMA mapping
    
    commit ba199bdaa80b09a7dd92f28751de7f3dbb06c510 upstream.
    
    Using sg_dma_len() is only valid after mapping the scatterlist with
    dma_map_sg(). However, atmel_tdes_crypt_start() uses it before mapping
    to compare input/output lengths and to compute the transfer count.
    
    Use the original scatterlist lengths before DMA mapping to avoid reading
    stale or uninitialized DMA lengths when CONFIG_NEED_SG_DMA_LENGTH=y.
    
    Drop the output scatterlist length in the fast path since it is equal to
    ->in_sg->length and does not change the transfer count.
    
    Fixes: 13802005d8f2 ("crypto: atmel - add Atmel DES/TDES driver")
    Fixes: 1f858040c2f7 ("crypto: atmel-tdes - add support for latest release of the IP (0x700)")
    Cc: [email protected]
    Signed-off-by: Thorsten Blum <[email protected]>
    Signed-off-by: Herbert Xu <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

crypto: mxs-dcp - fix source scatterlist length access [+ + +]
Author: Thorsten Blum <[email protected]>
Date:   Sun Jun 21 21:26:16 2026 +0200

    crypto: mxs-dcp - fix source scatterlist length access
    
    commit c5bcb084a9871e5b62afb5f48b60adfa13b5d9f8 upstream.
    
    mxs_dcp_aes_block_crypt() uses sg_dma_len() without mapping the source
    scatterlist with dma_map_sg() first. Therefore, sg_dma_len() is invalid
    and could return zero or a stale DMA length, causing encryption and
    decryption to process the wrong number of bytes when
    CONFIG_NEED_SG_DMA_LENGTH=y.
    
    Use the original scatterlist length instead.
    
    Fixes: 15b59e7c3733 ("crypto: mxs - Add Freescale MXS DCP driver")
    Cc: [email protected]
    Signed-off-by: Thorsten Blum <[email protected]>
    Reviewed-by: Frank Li <[email protected]>
    Signed-off-by: Herbert Xu <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

crypto: qce - fix CCM AAD buffer underallocation [+ + +]
Author: Md Sadre Alam <[email protected]>
Date:   Fri Aug 7 12:24:54 2026 +0530

    crypto: qce - fix CCM AAD buffer underallocation
    
    commit 7f2345f47dd189625f657cd72437179ab4170ee1 upstream.
    
    The AAD buffer allocated in qce_aead_ccm_prepare_buf_assoclen()
    can be smaller than the length later programmed into the DMA
    scatterlist.
    
    The allocation size is currently calculated as:
    
      ALIGN(assoclen, 16) + MAX_CCM_ADATA_HEADER_LEN
    
    while the DMA length is set to:
    
      ALIGN(assoclen + adata_header_len, 16)
    
    Since ALIGN() does not distribute over addition, the allocation
    can be smaller than the DMA length. For example, when
    assoclen = 32 and adata_header_len = 2:
    
      allocation = ALIGN(32, 16) + 6 = 38
      DMA length = ALIGN(32 + 2, 16) = 48
    
    As a result, the QCE hardware can read beyond the allocated
    buffer while computing the CBC-MAC over the associated data.
    The extra bytes are folded into the authentication tag,
    resulting in an incorrect tag and causing CCM self-test
    failures such as:
    
      alg: aead: ccm-aes-qce encryption test failed (wrong result)
      on test vector 8
    
    Fix the allocation by adding the maximum possible AAD header
    length before alignment:
    
      ALIGN(assoclen + MAX_CCM_ADATA_HEADER_LEN, 16)
    
    This guarantees that the allocated buffer is large enough
    for the fully padded AAD data for all supported header sizes.
    
    Cc: [email protected]
    Fixes: 9363efb4181c ("crypto: qce - Add support for AEAD algorithms")
    Signed-off-by: Md Sadre Alam <[email protected]>
    Reviewed-by: Bartosz Golaszewski <[email protected]>
    Signed-off-by: Herbert Xu <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

crypto: qce - Remove unsafe/deprecated algorithms [+ + +]
Author: Bartosz Golaszewski <[email protected]>
Date:   Mon Jun 22 15:18:09 2026 +0200

    crypto: qce - Remove unsafe/deprecated algorithms
    
    commit 7e28b0a5c4b7d075b98ce6d8f5290a9d3deb5b92 upstream.
    
    Remove algorithms that are either unsafe or deprecated and have no
    in-kernel users that cannot be served by the ARM CE implementations.
    
    AES-ECB reveals plaintext patterns (identical plaintext blocks produce
    identical ciphertext blocks) and should not be exposed as a hardware-
    accelerated primitive. DES, Triple DES and HMAC-SHA1 have been
    deprecated for years.
    
    Remove sha1, ecb(aes), ecb(des), cbc(des), ecb(des3_ede), cbc(des3_ede),
    hmac(sha1) and all AEAD variants built on these primitives as well as
    authenc(hmac(sha256),cbc(des)). Also clean up the - now dead - code,
    flags and constants.
    
    Cc: [email protected]
    Acked-by: Eric Biggers <[email protected]>
    Tested-by: Kuldeep Singh <[email protected]>
    Signed-off-by: Bartosz Golaszewski <[email protected]>
    Signed-off-by: Herbert Xu <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
ext4: don't enable DAX on new encrypted files [+ + +]
Author: Eric Biggers <[email protected]>
Date:   Wed Aug 26 20:38:33 2026 -0700

    ext4: don't enable DAX on new encrypted files
    
    commit da32af420d6d466e247c43ac0b829edeac7ae0ad upstream.
    
    Currently, when a new encrypted regular file is created, the call to
    ext4_set_inode_flags(inode, init=true) in __ext4_new_inode() is made
    before EXT4_INODE_ENCRYPT is set.  As a result, it can set S_DAX if the
    filesystem is mounted with "-o dax=always".
    
    EXT4_INODE_ENCRYPT then actually gets set a bit later in
    __ext4_new_inode(), when it calls fscrypt_set_context() which calls
    ext4_set_context().  ext4_set_context() sets EXT4_INODE_ENCRYPT and
    calls ext4_set_inode_flags(inode, init=false) to set S_ENCRYPTED too.
    
    This was intended to clear S_DAX as well.  However, this was broken by
    commit 043546e46dc7 ("fs/ext4: Only change S_DAX on inode load").  This
    causes data written to the file to bypass encryption, also causing
    xfstests failures such as generic/548 (when "-o dax=always" is used).
    
    Fix this by simplifying the flow by making __ext4_new_inode() set
    EXT4_INODE_ENCRYPT earlier.  This makes it take effect in
    ext4_set_inode_flags(inode, init=true), making S_DAX never be set.
    
    Similarly, make EXT4_STATE_MAY_INLINE_DATA never be set in the first
    place on new encrypted inodes.  Then it doesn't need to be cleared.
    
    As a result of these simplifications, ext4_set_context() no longer needs
    to change inode flags or state when 'handle != NULL'.  Remove that too.
    
    Reported-by: Disha Goel <[email protected]>
    Reported-by: Ojaswin Mujoo <[email protected]>
    Closes: https://lore.kernel.org/r/[email protected]
    Fixes: 043546e46dc7 ("fs/ext4: Only change S_DAX on inode load")
    Cc: [email protected]
    Signed-off-by: Eric Biggers <[email protected]>
    Tested-by: Disha Goel <[email protected]>
    Reviewed-by: Ojaswin Mujoo <[email protected]>
    Reviewed-by: Jan Kara <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Theodore Ts'o <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>

ext4: propagate errors from fast commit range replay [+ + +]
Author: Guanghui Yang <[email protected]>
Date:   Tue Aug 25 21:17:47 2026 -0400

    ext4: propagate errors from fast commit range replay
    
    [ Upstream commit d8b8dd3530bf41e14b118702cdaf9de64bb96885 ]
    
    ext4_fc_replay() stops replaying fast commit tags only when a tag
    handler returns a negative error. However, ext4_fc_replay_add_range()
    and ext4_fc_replay_del_range() currently return 0 from their common
    exit paths even after internal failures.
    
    This hides errors from ext4_fc_record_modified_inode(),
    ext4_map_blocks(), ext4_find_extent(), ext4_ext_insert_extent(),
    ext4_ext_replay_update_ex(), and ext4_ext_remove_space(). As a result,
    a failed ADD_RANGE or DEL_RANGE replay can be treated as successful and
    the replay code may continue with subsequent fast commit tags.
    
    This is particularly problematic for DEL_RANGE because it may already
    have marked blocks as free before ext4_ext_remove_space() fails. If the
    error is swallowed, replay may continue from a partially applied range
    operation.
    
    Return the saved error from the common exit paths and make the
    ERR_PTR() cases in ADD_RANGE store PTR_ERR() before jumping to out.
    
    Fixes: 8016e29f4362 ("ext4: fast commit recovery path")
    Cc: [email protected]
    Signed-off-by: Guanghui Yang <[email protected]>
    Reviewed-by: Jan Kara <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Theodore Ts'o <[email protected]>
    [ kept the existing `ext4_find_extent(inode, cur, NULL, 0)` call and dropped the `ext4_ext_insert_extent()` error-capture hunk, since this tree's extents API predates the ppath rework and already returns errors via `int` ]
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
fpga: dfl: fme: add error handling [+ + +]
Author: Griffin Kroah-Hartman <[email protected]>
Date:   Mon Jul 6 16:58:21 2026 +0200

    fpga: dfl: fme: add error handling
    
    commit b5ba63e247075087ab8a6a087622c762dc4172e9 upstream.
    
    Add error handling to devm_kasprint in fme_perf_pmu_register().
    
    Assisted-by: gkh_clanker_2000
    Fixes: 724142f8c42a ("fpga: dfl: fme: add performance reporting support")
    Cc: [email protected]
    Cc: Xu Yilun <[email protected]>
    Cc: Tom Rix <[email protected]>
    Cc: Moritz Fischer <[email protected]>
    Signed-off-by: Griffin Kroah-Hartman <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>
    [ Yilun: Fix stable tag, add Fixes tag ]
    Reviewed-by: Xu Yilun <[email protected]>
    Link: https://lore.kernel.org/r/2026070620-unwired-clay-f6cc@gregkh
    Signed-off-by: Xu Yilun <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
fuse: fix invalidate lock leak on open O_TRUNC DAX failure [+ + +]
Author: Baokun Li <[email protected]>
Date:   Mon Aug 17 23:18:01 2026 +0800

    fuse: fix invalidate lock leak on open O_TRUNC DAX failure
    
    commit a927f1867e61b78f39f9da0bbba3c98c2ca151fe upstream.
    
    fuse_open() takes filemap_invalidate_lock() for a DAX truncate
    (dax_truncate = true) and releases it before the out_inode_unlock
    label.  But when fuse_dax_break_layouts() fails, the goto
    out_inode_unlock skips the unlock and leaks the rwsem, so any later
    fault or truncate on the file stalls on the stale lock.
    
    fuse_dax_break_layouts() can fail with -ERESTARTSYS when a signal
    interrupts the wait for busy DAX pages to drain:
    
      open("file", O_RDWR | O_TRUNC)
      └─ fuse_open()
         ├─ filemap_invalidate_lock()        # dax_truncate
         └─ fuse_dax_break_layouts()
            └─ dax_break_layout()
               └─ wait_page_idle()           # TASK_INTERRUPTIBLE
                  └─ fuse_wait_dax_page()    # unlock, schedule, re-lock
                     └─ signal → -ERESTARTSYS
         goto out_inode_unlock               # <- lock leaked
    
    Fix this by moving filemap_invalidate_unlock() below the label so
    that all error paths release the lock, and rename the label to
    out_unlock as it now covers more than just the inode lock.
    
    Fixes: 2fdbb8dd0155 ("fuse: fix deadlock between atomic O_TRUNC and page invalidation")
    Cc: [email protected] # v6.0+
    Signed-off-by: Baokun Li <[email protected]>
    Signed-off-by: Miklos Szeredi <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

fuse: fix invalidate lock leak on setattr writeback failure [+ + +]
Author: Baokun Li <[email protected]>
Date:   Mon Aug 17 23:18:00 2026 +0800

    fuse: fix invalidate lock leak on setattr writeback failure
    
    commit 9afeca0d569c9fc89d758fe7a9339d1e8afb1546 upstream.
    
    fuse_do_setattr() takes filemap_invalidate_lock() for a DAX truncate
    (fault_blocked = true) and releases it at the out:/error: labels.  But
    when a writeback flush is also needed, a write_inode_now() failure
    returns directly and leaks the lock, so any later fault or truncate on
    the file stalls on the stale rwsem.
    
    For example, truncate(2) on a setuid file reaches fuse_do_setattr()
    with both ATTR_SIZE and ATTR_MODE set:
    
      truncate(2)
      └─ do_truncate()
         ├─ dentry_needs_remove_privs()         # S_ISUID
         └─ notify_change()                     # KILL_SUID -> ATTR_MODE
            └─ fuse_setattr()                   # no killpriv:
               │                                #   ia_valid |= ATTR_MODE
               └─ fuse_do_setattr()
                  ├─ filemap_invalidate_lock()  # IS_DAX && is_truncate
                  └─ write_inode_now()          # is_wb && ATTR_MODE
                     └─ if (err)                # e.g. daemon -> -EIO
                        return err              # <- lock leaked
    
    Fix this by adding an unlock label that releases the lock before
    returning the error, and use it for the fuse_dax_break_layouts()
    failure path as well.
    
    Fixes: 6ae330cad6ef ("virtiofs: serialize truncate/punch_hole and dax fault path")
    Cc: [email protected] # v5.10+
    Signed-off-by: Baokun Li <[email protected]>
    Signed-off-by: Miklos Szeredi <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
HID: ft260: fix i2c probing for hwmon devices [+ + +]
Author: Michael Zaidman <[email protected]>
Date:   Thu Aug 27 00:39:59 2026 -0400

    HID: ft260: fix i2c probing for hwmon devices
    
    [ Upstream commit a94f61e63f337d95001e1a976ab701100fa1d666 ]
    
    The below scenario causes the kernel NULL pointer dereference failure:
    1. sudo insmod hid-ft260.ko
    2. sudo modprobe lm75
    3. unplug USB hid-ft260
    4. plug USB hid-ft260
    
    [  +0.000006] Call Trace:
    [  +0.000004]  __i2c_smbus_xfer.part.0+0xd1/0x310
    [  +0.000007]  ? ft260_smbus_write+0x140/0x140 [hid_ft260]
    [  +0.000005]  __i2c_smbus_xfer+0x2b/0x80
    [  +0.000004]  i2c_smbus_xfer+0x61/0xf0
    [  +0.000005]  i2c_default_probe+0xf9/0x130
    [  +0.000004]  i2c_detect_address+0x84/0x160
    [  +0.000004]  ? kmem_cache_alloc_trace+0xf6/0x200
    [  +0.000009]  ? i2c_detect.isra.0+0x69/0x130
    [  +0.000005]  i2c_detect.isra.0+0xbf/0x130
    [  +0.000004]  ? __process_new_driver+0x30/0x30
    [  +0.000004]  __process_new_adapter+0x18/0x20
    [  +0.000004]  bus_for_each_drv+0x84/0xd0
    [  +0.000003]  i2c_register_adapter+0x1e4/0x400
    [  +0.000005]  i2c_add_adapter+0x5c/0x80
    [  +0.000004]  ft260_probe.cold+0x222/0x2e2 [hid_ft260]
    [  +0.000006]  hid_device_probe+0x10e/0x170 [hid]
    [  +0.000009]  really_probe+0xff/0x460
    [  +0.000004]  driver_probe_device+0xe9/0x160
    [  +0.000003]  __device_attach_driver+0x71/0xd0
    [  +0.000004]  ? driver_allows_async_probing+0x50/0x50
    [  +0.000004]  bus_for_each_drv+0x84/0xd0
    [  +0.000002]  __device_attach+0xde/0x1e0
    [  +0.000004]  device_initial_probe+0x13/0x20
    [  +0.000004]  bus_probe_device+0x8f/0xa0
    [  +0.000003]  device_add+0x333/0x5f0
    
    It happened when i2c core probed for the devices associated with the lm75
    driver by invoking 2c_detect()-->..-->ft260_smbus_write() from within the
    ft260_probe before setting the adapter data with i2c_set_adapdata().
    
    Moving the i2c_set_adapdata() before i2c_add_adapter() fixed the failure.
    
    Signed-off-by: Michael Zaidman <[email protected]>
    Signed-off-by: Germain Hebert <[email protected]>
    Signed-off-by: Jiri Kosina <[email protected]>
    Stable-dep-of: bf3e39df3a39 ("HID: ft260: fix stack-use-after-return write in I2C read race")
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

HID: ft260: fix stack-use-after-return write in I2C read race [+ + +]
Author: Raman Varabets <[email protected]>
Date:   Thu Aug 27 00:40:06 2026 -0400

    HID: ft260: fix stack-use-after-return write in I2C read race
    
    [ Upstream commit bf3e39df3a397fd82967a31d17c4e02c7feab221 ]
    
    ft260_i2c_read() points dev->read_buf at a caller-supplied buffer
    (often an on-stack variable), arms a completion and waits up to five
    seconds for the device to return the data. The HID input callback
    ft260_raw_event() runs in the input/IRQ path, independent of the
    dev->lock mutex held by the read path, and copies the device-supplied
    payload into dev->read_buf after a plain NULL check.
    
    These two paths share read_buf, read_idx and read_len with no
    serialization. If the device delays its response until the read
    times out, ft260_i2c_read() resets the controller, clears read_buf
    and returns, unwinding the stack frame the buffer lived in. A
    response that arrives at that moment lets ft260_raw_event() pass the
    NULL check and then memcpy() the device-controlled payload into the
    now-freed stack location, a bounded but attacker-influenced
    stack-use-after-return write triggerable by malicious or
    malfunctioning hardware.
    
    Add a dedicated spinlock that serializes every access to read_buf,
    read_idx and read_len. ft260_raw_event() now holds it across the
    NULL check, the memcpy and the index update, while the read path
    takes it when arming and when clearing the buffer, so the teardown
    can no longer slip between the check and the copy.
    
    Fixes: 6a82582d9fa4 ("HID: ft260: add usb hid to i2c host bridge driver")
    Cc: [email protected]
    Signed-off-by: Raman Varabets <[email protected]>
    Reviewed-by: Michael Zaidman <[email protected]>
    Signed-off-by: Jiri Kosina <[email protected]>
    [ de-indented one tab and renamed `rd_len` to `len` since the chunking loop in `ft260_i2c_read()` is absent. ]
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

HID: ft260: improve i2c large reads performance [+ + +]
Author: Michael Zaidman <[email protected]>
Date:   Thu Aug 27 00:40:01 2026 -0400

    HID: ft260: improve i2c large reads performance
    
    [ Upstream commit 54410c14800ad652c77e5c6fc5c17baad6e42cb6 ]
    
    The patch increases the read buffer size to 180 bytes. It reduces
    the number of ft260_i2c_read() calls by three, improving the big
    reads performance.
    
    $ sudo i2ctransfer -y -f 13 w2@0x51 0x0 0x0 r180
    
    Before:
    
    [  +4.071878] ft260_i2c_write_read: off 0x0 rlen 180 wlen 2
    [  +0.000005] ft260_i2c_write: rep 0xd0 addr 0x51 off 0 len 2 wlen 2 flag 0x2 d[0] 0x0
    [  +0.001097] ft260_xfer_status: bus_status 0x41, clock 100
    [  +0.000175] ft260_xfer_status: bus_status 0x40, clock 100
    [  +0.000004] ft260_i2c_read: rep 0xc2 addr 0x51 len 180 rlen 60 flag 0x3
    [  +0.008579] ft260_raw_event: i2c resp: rep 0xde len 60
    [  +0.000208] ft260_xfer_status: bus_status 0x40, clock 100
    [  +0.000001] ft260_i2c_read: rep 0xc2 addr 0x51 len 120 rlen 60 flag 0x0
    [  +0.008794] ft260_raw_event: i2c resp: rep 0xde len 60
    [  +0.000181] ft260_xfer_status: bus_status 0x40, clock 100
    [  +0.000002] ft260_i2c_read: rep 0xc2 addr 0x51 len 60 rlen 60 flag 0x4
    [  +0.008817] ft260_raw_event: i2c resp: rep 0xde len 60
    [  +0.000223] ft260_xfer_status: bus_status 0x20, clock 100
    
    After:
    
    [ +11.611642] ft260_i2c_write_read: off 0x0 rlen 180 wlen 2
    [  +0.000005] ft260_i2c_write: rep 0xd0 addr 0x51 off 0 len 2 wlen 2 flag 0x2 d[0] 0x0
    [  +0.008001] ft260_xfer_status: bus_status 0x20, clock 100
    [  +0.000001] ft260_i2c_read: rep 0xc2 addr 0x51 len 180 rlen 180 flag 0x7
    [  +0.008994] ft260_raw_event: i2c resp: rep 0xde len 60
    [  +0.007987] ft260_raw_event: i2c resp: rep 0xde len 60
    [  +0.007992] ft260_raw_event: i2c resp: rep 0xde len 60
    [  +0.000206] ft260_xfer_status: bus_status 0x20, clock 100
    
    Suggested-by: Enrik Berkhan <[email protected]>
    Signed-off-by: Michael Zaidman <[email protected]>
    Signed-off-by: Jiri Kosina <[email protected]>
    Stable-dep-of: bf3e39df3a39 ("HID: ft260: fix stack-use-after-return write in I2C read race")
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

HID: ft260: improve i2c write performance [+ + +]
Author: Michael Zaidman <[email protected]>
Date:   Thu Aug 27 00:40:00 2026 -0400

    HID: ft260: improve i2c write performance
    
    [ Upstream commit 6fca5e3f5574ca1bd5bade5737848c816f924c6a ]
    
    The patch improves the I2C write performance by 20 - 30 percent by
    revising the sleep time in the ft260_hid_output_report_check_status()
    in the following ways:
    
    1. Reduce the wait time and start to poll earlier.
    
    Sending a large amount of data at a low I2C clock rate saturates the
    internal FT260 buffer and causes hiccups in status readiness, as shown
    below in the log fragment. Aligning the status check wait time to the
    worst case significantly reduces the write performance.
    
    [Oct22 10:28] ft260_i2c_write: rep 0xd8 addr 0x51 off 0 len 34 d[0] 0x0
    [  +0.005296] ft260_xfer_status: bus_status 0x20, clock 100
    [  +0.013460] ft260_i2c_write: rep 0xd8 addr 0x51 off 0 len 34 d[0] 0x0
    [  +0.003244] ft260_hid_output_report_check_status: wait 1920 usec, len 38
    [  +0.000190] ft260_xfer_status: bus_status 0x40, clock 100
    [  +0.015324] ft260_i2c_write: rep 0xd8 addr 0x51 off 0 len 34 d[0] 0x0
    [  +0.003491] ft260_hid_output_report_check_status: wait 1920 usec, len 38
    [  +0.000202] ft260_xfer_status: bus_status 0x40, clock 100
    [  +0.016047] ft260_i2c_write: rep 0xd8 addr 0x51 off 0 len 34 d[0] 0x0
    [  +0.002768] ft260_hid_output_report_check_status: wait 1920 usec, len 38
    [  +0.000150] ft260_xfer_status: bus_status 0x40, clock 100
    [  +0.011389] ft260_i2c_write: rep 0xd8 addr 0x51 off 0 len 34 d[0] 0x0
    [  +0.003467] ft260_hid_output_report_check_status: wait 1920 usec, len 38
    [  +0.000191] ft260_xfer_status: bus_status 0x41, clock 100
    [  +0.000172] ft260_xfer_status: bus_status 0x41, clock 100
    [  +0.000131] ft260_xfer_status: bus_status 0x41, clock 100
    [  +0.000241] ft260_xfer_status: bus_status 0x41, clock 100
    [  +0.000233] ft260_xfer_status: bus_status 0x41, clock 100
    [  +0.000190] ft260_xfer_status: bus_status 0x41, clock 100
    [  +0.000196] ft260_xfer_status: bus_status 0x40, clock 100
    [  +0.011314] ft260_i2c_write: rep 0xd8 addr 0x51 off 0 len 34 d[0] 0x0
    [  +0.003334] ft260_hid_output_report_check_status: wait 1920 usec, len 38
    [  +0.000227] ft260_xfer_status: bus_status 0x41, clock 100
    [  +0.000204] ft260_xfer_status: bus_status 0x41, clock 100
    [  +0.000198] ft260_xfer_status: bus_status 0x41, clock 100
    [  +0.000147] ft260_xfer_status: bus_status 0x40, clock 100
    [  +0.011060] ft260_i2c_write: rep 0xd8 addr 0x51 off 0 len 34 d[0] 0x0
    
      Before:
        $ sudo ./i2cperf -f 2 -o 2 -s 32 -r 0-0xff 13 0x51 -S
    
          Fill block with increment via i2ctransfer by chunks
          -------------------------------------------------------------------
          data rate(bps)  efficiency(%)  data size(B)  total IOs   IO size(B)
          -------------------------------------------------------------------
          40510           80             256           8           32
    
      After:
        $ sudo ./i2cperf -f 2 -o 2 -s 32 -r 0-0xff 13 0x51 -S
    
          Fill block with increment via i2ctransfer by chunks
          -------------------------------------------------------------------
          data rate(bps)  efficiency(%)  data size(B)  total IOs   IO size(B)
          -------------------------------------------------------------------
          52584           80             256           8           32
    
    2. Do not sleep if the estimated I2C transfer time is below 2 ms since
       the first xfer status query frequently takes around 1.5 ms, and the
       following status queries take about 200us on average. So we usually
       return from the routine after the first 1 - 3 status checks.
    
    [Oct22 11:14] ft260_i2c_write: rep 0xd4 addr 0x51 off 0 len 18 d[0] 0x0
    [  +0.004270] ft260_xfer_status: bus_status 0x20, clock 100
    [  +0.013889] ft260_i2c_write: rep 0xd4 addr 0x51 off 0 len 18 d[0] 0x0
    [  +0.000856] ft260_xfer_status: bus_status 0x41, clock 100
    [  +0.000138] ft260_xfer_status: bus_status 0x40, clock 100
    [  +0.013352] ft260_i2c_write: rep 0xd4 addr 0x51 off 0 len 18 d[0] 0x0
    [  +0.001501] ft260_xfer_status: bus_status 0x41, clock 100
    [  +0.000177] ft260_xfer_status: bus_status 0x40, clock 100
    [  +0.014477] ft260_i2c_write: rep 0xd4 addr 0x51 off 0 len 18 d[0] 0x0
    [  +0.001377] ft260_xfer_status: bus_status 0x41, clock 100
    [  +0.000233] ft260_xfer_status: bus_status 0x41, clock 100
    [  +0.000191] ft260_xfer_status: bus_status 0x40, clock 100
    [  +0.013197] ft260_i2c_write: rep 0xd4 addr 0x51 off 0 len 18 d[0] 0x0
    
      Before:
        $ sudo ./i2cperf -f 2 -o 2 -s 16 -r 0-0xff 13 0x51 -S
    
          Fill block with increment via i2ctransfer by chunks
          -------------------------------------------------------------------
          data rate(bps)  efficiency(%)  data size(B)  total IOs   IO size(B)
          -------------------------------------------------------------------
          28826           73             256           16          16
    
      After:
        $ sudo ./i2cperf -f 2 -o 2 -s 16 -r 0-0xff 13 0x51 -S
    
          Fill block with increment via i2ctransfer by chunks
          -------------------------------------------------------------------
          data rate(bps)  efficiency(%)  data size(B)  total IOs   IO size(B)
          -------------------------------------------------------------------
          45138           73             256           16          16
    
    Signed-off-by: Michael Zaidman <[email protected]>
    Tested-by: Guillaume Champagne <[email protected]>
    Signed-off-by: Jiri Kosina <[email protected]>
    Stable-dep-of: bf3e39df3a39 ("HID: ft260: fix stack-use-after-return write in I2C read race")
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

HID: ft260: missed NACK from busy device [+ + +]
Author: Michael Zaidman <[email protected]>
Date:   Thu Aug 27 00:40:04 2026 -0400

    HID: ft260: missed NACK from busy device
    
    [ Upstream commit 5afac727defa0b2a3dffb2abd5fb5f594b98d217 ]
    
    When writing into a slow device like an EEPROM chip, the
    controller may exit the busy state before the device releases
    the bus. In this case, the ft260_xfer_status returns success
    before the data transfer completion.
    
    The patch fixes it by returning from the ft260_xfer_status()
    with the "-EAGAIN" on both controller and bus busy status when
    appropriate.
    
    It does not apply to the i2c combined transactions when after
    the write IO, the controller keeps the bus busy until the read
    IO and then between reading IOs to ensure an atomic operation.
    
    Co-developed-by: Germain Hebert <[email protected]>
    Signed-off-by: Germain Hebert <[email protected]>
    Signed-off-by: Michael Zaidman <[email protected]>
    Signed-off-by: Jiri Kosina <[email protected]>
    Stable-dep-of: bf3e39df3a39 ("HID: ft260: fix stack-use-after-return write in I2C read race")
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

HID: ft260: skip unexpected HID input reports [+ + +]
Author: Michael Zaidman <[email protected]>
Date:   Thu Aug 27 00:40:02 2026 -0400

    HID: ft260: skip unexpected HID input reports
    
    [ Upstream commit b7121e3c04440cc2af9cabbabb24efd23741294a ]
    
    The FT260 is not supposed to generate unexpected HID reports. However,
    in theory, the unsolicited HID Input reports can be issued by a specially
    crafted malicious USB device masquerading as FT260 when the attacker has
    physical access to the USB port. In this case, the read_buf pointer points
    to the final data portion of the previous I2C Read transfer, and the memcpy
    invoked in the ft260_raw_event() will try copying the content of the
    unexpected report into the wrong location.
    
    This commit sets the Read buffer pointer to NULL on the I2C Read
    transaction completion and checks it in the ft260_raw_event() to detect
    and skip the unsolicited Input report.
    
    Reported-by: Enrik Berkhan <[email protected]>
    Signed-off-by: Michael Zaidman <[email protected]>
    Signed-off-by: Jiri Kosina <[email protected]>
    Stable-dep-of: bf3e39df3a39 ("HID: ft260: fix stack-use-after-return write in I2C read race")
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

HID: ft260: validate i2c input report length [+ + +]
Author: Michael Zaidman <[email protected]>
Date:   Thu Aug 27 00:40:05 2026 -0400

    HID: ft260: validate i2c input report length
    
    [ Upstream commit 80c4bbb2b38513e9c3d84805fa61a0ee16d79c45 ]
    
    Add two checks to ft260_raw_event() to prevent out-of-bounds reads
    from malicious or malfunctioning devices:
    
    First, reject reports shorter than the 2-byte header (report ID +
    length fields). Without this, even accessing xfer->length on a
    1-byte report is an OOB read.
    
    Second, validate xfer->length against the actual data capacity of
    the received HID report. Each I2C data report ID (0xD0 through
    0xDE) defines a different report size in the HID descriptor, so the
    available payload varies per report. A corrupted length field could
    cause memcpy to read beyond the report buffer.
    
    Reported-by: Sebastián Josué Alba Vives <[email protected]>
    Signed-off-by: Michael Zaidman <[email protected]>
    Signed-off-by: Jiri Kosina <[email protected]>
    Stable-dep-of: bf3e39df3a39 ("HID: ft260: fix stack-use-after-return write in I2C read race")
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

HID: ft260: wake up device from power saving mode [+ + +]
Author: Michael Zaidman <[email protected]>
Date:   Thu Aug 27 00:40:03 2026 -0400

    HID: ft260: wake up device from power saving mode
    
    [ Upstream commit 4b3da6853a619a952e8caf2e8393264dd42ffa27 ]
    
    The FT260 can enter a power saving mode after being idle for longer
    than 5 seconds.
    
    When being woken up from power saving mode by an I2C write request,
    a possible NACK is not correctly reported by the controller. As a
    workaround, the driver will issue an I2C status report two times in
    ft260_xfer_status() after the chip has been idle for more than 5s.
    
    Co-developed-by: Enrik Berkhan <[email protected]>
    Signed-off-by: Enrik Berkhan <[email protected]>
    Signed-off-by: Michael Zaidman <[email protected]>
    Signed-off-by: Jiri Kosina <[email protected]>
    Stable-dep-of: bf3e39df3a39 ("HID: ft260: fix stack-use-after-return write in I2C read race")
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

HID: input: read battery capacity from its actual report offset [+ + +]
Author: Jose Villaseñor Montfort <[email protected]>
Date:   Thu Aug 27 00:40:12 2026 -0400

    HID: input: read battery capacity from its actual report offset
    
    [ Upstream commit d07644524b6511b622ee7b0e2e68c9ee43d522a4 ]
    
    hidinput_query_battery_capacity() assumes the state-of-charge value is
    the first byte following the report ID (buf[1]) and ignores where the
    battery field actually sits within the report.
    
    An Apple Magic Trackpad 2 precedes the AbsoluteStateOfCharge byte with a
    byte of status flags in its battery reports, so this query returns the
    flags byte instead of the charge level.
    
    The device happens to make that easy to observe, because it exposes the
    same cell twice: its report descriptor declares AbsoluteStateOfCharge in
    two reports (0x90 and 0x9b), so hidinput_setup_battery() registers two
    power supplies. Only the first one is refreshed by hid-magicmouse -- it
    uses hid_get_battery(), which returns the first battery of the list --
    and that refresh goes through the report event path, which parses the
    field correctly. Nothing ever reports the second one, so every read of
    its capacity takes the query path above. On a USB-C Magic Trackpad over
    USB, on an unpatched 7.1.5:
    
      hid-<serial>-battery-144 = 100%  (Charging)      <- report event path
      hid-<serial>-battery-155 =   3%  (Discharging)   <- query path
    
    Both are the same physical battery. A raw HIDIOCGINPUT of the two
    reports at that same moment:
    
      report 0x90 -> [90 03 64]
      report 0x9b -> [9b 03 64 64 00 00 10 00 00 00 00 00 00 00]
                         ^flags ^SoC = 0x64 = 100%
    
    The device answers correctly in both cases; only the offset the kernel
    reads the capacity from is wrong. 0x03 is the flags byte (present,
    charging), reported as "3%".
    
    Bluetooth takes the same query path for its capacity, where the trackpad
    reported a bogus near-constant ~4% -- 0b100, the FullyCharged flag --
    regardless of the real charge.
    
    Store the battery field's offset within the report at setup time and use
    it when querying, so the capacity is read from its real position. The
    report event path already parses the field correctly through the HID
    core; only the explicit GET_REPORT query was wrong.
    
    Devices whose capacity field is the first field in the report have a
    report_offset of 0 and are unaffected (buf[1 + 0] == buf[1]).
    
    Fixes: 581c4484769e ("HID: input: map digitizer battery usage")
    Cc: [email protected]
    Signed-off-by: Jose Villaseñor Montfort <[email protected]>
    Reviewed-by: Alec Hall <[email protected]>
    Signed-off-by: Jiri Kosina <[email protected]>
    [ Adapted `bat->report_offset` and other `struct hid_battery` accessors to the flat `dev->battery_*` fields on `struct hid_device` and replaced `__free(kfree)` with manual `kfree(buf)` calls. ]
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() [+ + +]
Author: Jose Villaseñor Montfort <[email protected]>
Date:   Wed Aug 26 09:11:19 2026 -0400

    HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
    
    [ Upstream commit db8d634128d2ba88d79c0b601e983ebe14bb0519 ]
    
    magicmouse_raw_event() handles DOUBLE_REPORT_ID (0xf7) packets, which pack
    two touch reports into one, by splitting the packet and calling itself on
    each half. The only guard against runaway recursion is a "size < 1" check,
    which stops zero-sized calls but does not bound the recursion depth.
    
    A malicious HID device that matches this driver can send a report starting
    with DOUBLE_REPORT_ID and filled with the sequence [0xf7, 0x00]. Each level
    consumes two bytes and recurses on the remainder, so an incoming report of
    up to HID_MAX_BUFFER_SIZE (16 KiB) drives roughly 8000 nested calls. That
    easily exhausts the 16 KiB kernel stack, leading to a stack overflow: a
    panic with CONFIG_VMAP_STACK, or memory corruption without it.
    
    A double report only ever wraps two normal reports; it is never
    legitimately nested. Refuse to re-enter the DOUBLE_REPORT_ID case from a
    recursive call so the recursion depth is bounded to two, while all valid
    packets keep being parsed exactly as before.
    
    Fixes: a462230e16ac ("HID: magicmouse: enable Magic Trackpad support")
    Link: https://lore.kernel.org/linux-input/[email protected]/
    Cc: [email protected]
    Signed-off-by: Jose Villaseñor Montfort <[email protected]>
    Reviewed-by: Alec Hall <[email protected]>
    Tested-by: Alec Hall <[email protected]>
    Signed-off-by: Jiri Kosina <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

HID: uclogic: fix use-after-free of inrange_timer on remove [+ + +]
Author: Ibrahim Hashimov <[email protected]>
Date:   Wed Aug 26 13:47:45 2026 -0400

    HID: uclogic: fix use-after-free of inrange_timer on remove
    
    [ Upstream commit 506fd50a9027340f0e9dcc587d10ccb03312dba6 ]
    
    uclogic_remove() cancels the pen in-range timer and then stops the
    device:
    
            timer_delete_sync(&drvdata->inrange_timer);
            hid_hw_stop(hdev);
    
    timer_delete_sync() only guarantees the timer is idle at that instant.
    uclogic_raw_event_pen() keeps delivering pen reports until hid_hw_stop()
    stops the transport several lines later, and every report with
    pen->inrange == UCLOGIC_PARAMS_PEN_INRANGE_NONE re-arms the timer:
    
            mod_timer(&drvdata->inrange_timer, jiffies + msecs_to_jiffies(100));
    
    A report landing between the timer_delete_sync() call and the transport
    teardown in hid_hw_stop() re-arms inrange_timer after it was cancelled.
    uclogic_remove() then returns and the devm drvdata is freed, while
    hid_hw_stop() has already freed the input device drvdata->pen_input
    points at, so when the timer fires ~100 ms later
    uclogic_inrange_timeout() dereferences freed memory -- a use-after-free
    in timer-softirq context.
    
    Swapping the two calls is not a fix: stopping the device first frees
    drvdata->pen_input via hidinput_disconnect() while the timer may still
    be pending, so a timer already armed before removal fires on the freed
    input device in the window before timer_delete_sync() runs.
    
    Use timer_shutdown_sync() before hid_hw_stop() instead. It cancels the
    timer, waits for a running callback while pen_input is still valid, and
    prevents any further re-arming -- a later mod_timer() from an in-flight
    report is silently ignored -- so the timer is provably dead before
    hid_hw_stop() frees the inputs. This is the ordering the timer core
    documents for this "timer re-armed from another path" teardown case.
    
    Fixes: 01309e29eb95 ("HID: uclogic: Support in-range reporting emulation")
    Cc: [email protected]
    Signed-off-by: Ibrahim Hashimov <[email protected]>
    Assisted-by: AuditCode-AI:2026.07
    Signed-off-by: Jiri Kosina <[email protected]>
    [ changed timer_delete_sync() to del_timer_sync() in the removed line to match the pre-rename API on this branch ]
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
io_uring/io-wq: fix worker accounting when canceling creation callbacks [+ + +]
Author: Vishnu Razdan <[email protected]>
Date:   Tue Aug 25 09:54:10 2026 -0700

    io_uring/io-wq: fix worker accounting when canceling creation callbacks
    
    commit 297b5ccea4acacaa47c150f043bce695202afbf1 upstream.
    
    create_worker_cb() reserves an io-wq worker slot only after its
    task-work callback runs. If the callback is canceled before then,
    io_worker_cancel_cb() still decrements acct->nr_workers. When an
    existing worker retires with its creation callback pending, that
    worker has already decremented the same account's worker count.
    
    The resulting undercount permits worker creation beyond the account's
    configured limit. On an AST2600 OpenBMC system, an unchanged sensor
    daemon reached 4,291 threads with the original kernel. With an
    equivalent downstream fix, 25 passive samples under its normal
    workload showed 6-9 threads.
    
    Decrement nr_workers only when the canceled callback is not
    create_worker_cb(). Continuation callbacks still release their reserved
    slot, and both callback types retain the existing running-count,
    reference-count, and create-state cleanup.
    
    [ Backport: retain the existing worker->wqe->lock protecting worker
      accounting. ]
    
    Fixes: 1d5f5ea7cb7d ("io-wq: remove worker to owner tw dependency")
    Cc: [email protected]
    Assisted-by: Codex:gpt-5.6-sol
    Reviewed-by: Gabriel Krisman Bertazi <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Vishnu Razdan <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>

 
ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() [+ + +]
Author: Eric Dumazet <[email protected]>
Date:   Sun Jul 5 18:17:54 2026 +0000

    ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
    
    commit 7b19c0f81ed1fdaec6bc522569be367199a9edf3 upstream.
    
    A race condition exists between device teardown (inetdev_destroy) and
    incoming IGMP query processing (igmp_rcv), leading to a Use-After-Free
    in the IGMP timer callback.
    
    During device destruction, inetdev_destroy() drops the primary reference
    to in_device, which can drop its refcount to 0. The actual freeing of
    in_device memory is deferred via RCU (using call_rcu()).
    
    Concurrently, igmp_rcv() runs under RCU read lock and obtains the
    in_device pointer. Because the memory is RCU-protected, CPU-0 can safely
    dereference in_device even if its refcount has hit 0.
    
    However, if CPU-0 calls igmp_gq_start_timer() and re-arms the timer, it
    attempts to acquire a reference using in_dev_hold(). This increments the
    refcount from 0 to 1, triggering a "refcount_t: addition on 0" warning.
    Since the in_device memory is still scheduled to be freed after the RCU
    grace period (as the free callback does not check the refcount again),
    the device is freed while the timer is still armed. When the timer
    expires, it accesses the freed memory, causing a kernel panic.
    
    Fix this by using refcount_inc_not_zero() (via a new helper
    in_dev_hold_safe()) to prevent acquiring a reference if the device is
    already being destroyed. If the refcount is 0, we do not arm the timer.
    
    A similar issue in IPv6 MLD is fixed in a subsequent patch.
    
    Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
    Reported-by: Zero Day Initiative <[email protected]>
    Signed-off-by: Eric Dumazet <[email protected]>
    Reviewed-by: Ido Schimmel <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Paolo Abeni <[email protected]>
    [Denis Arefev: adapted for 5.10/5.15: keep prandom_u32(),
    get_random_u32_below() not used here]
    Signed-off-by: Denis Arefev <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
ipv6: seg6: clear IPv4 control block on IPIP decapsulation [+ + +]
Author: Kyle Zeng <[email protected]>
Date:   Mon Aug 17 08:58:38 2026 +0000

    ipv6: seg6: clear IPv4 control block on IPIP decapsulation
    
    commit 44930446dde45a7a90fe1446fa38eb0e2c561646 upstream.
    
    End.DX4 and End.DT4 decapsulate an IPv4 packet through
    decap_and_validate() and send it directly to IPv4 routing. The inner
    packet therefore bypasses ip_rcv_core(), which normally clears IPCB
    before IPv4 interprets skb->cb.
    
    The skb instead retains IP6CB data from the outer packet. IP6CB and
    IPCB use the same skb->cb storage, so IP6CB(skb)->lastopt overlaps
    IPCB(skb)->opt.optlen and srr, while IP6CB(skb)->nhoff overlaps rr and
    ts.
    
    The sender can make the stale optlen byte nonzero with a valid outer
    extension-header chain. The reproducers put an eight-byte Destination
    Options header immediately after the 40-byte IPv6 header and before the
    Segment Routing Header. ipv6_destopt_rcv() records the sender-controlled
    Destination Options offset in both lastopt and nhoff, setting them to
    40. On the reproduced little-endian x86-64 kernel, IPv4 therefore sees
    optlen = 40 and rr = 40.
    
    Both tcp_v4_save_options() and __ip_options_echo() skip option copying
    when optlen is zero. Here optlen is 40, so the TCP SYN path allocates
    room for 40 bytes of option data and calls __ip_options_echo(). The
    stale rr value makes that function read inner packet byte 41 as the
    Record Route option length. The reproducers set that sender-controlled
    byte to 255, so __ip_options_echo() copies 255 bytes into the 40-byte
    option-data area.
    
    Separate End.DX4 and End.DT4 reproducers on the unpatched v7.2-rc5
    kernel both produced:
    
      BUG: KASAN: slab-out-of-bounds in __ip_options_echo()
      Write of size 255
    
    The relevant End.DX4 call path is:
    
      __ip_options_echo
      tcp_v4_route_req
      tcp_conn_request
      tcp_v4_conn_request
      tcp_rcv_state_process
      tcp_v4_do_rcv
      tcp_v4_rcv
      ip_protocol_deliver_rcu
      ip_local_deliver_finish
      ip_local_deliver
      input_action_end_dx4_finish
      input_action_end_dx4
    
    The relevant End.DT4 call path is:
    
      __ip_options_echo
      tcp_v4_route_req
      tcp_conn_request
      tcp_v4_conn_request
      tcp_rcv_state_process
      tcp_v4_do_rcv
      tcp_v4_rcv
      ip_protocol_deliver_rcu
      ip_local_deliver_finish
      ip_local_deliver
      input_action_end_dt4
    
    tcp_v4_save_options() is inlined into the tcp_v4_route_req() path, so
    it does not appear as a separate frame.
    
    When decap_and_validate() handles IPPROTO_IPIP, save the ingress
    interface from IP6CB, clear IPCB, and restore the saved value. Doing
    this in the common decapsulation path covers End.DX4, End.DT4, and
    End.DT46's IPv4 arm.
    
    Use IP6CB(skb)->iif rather than skb->skb_iif. These actions run after
    l3mdev processing, which can replace skb_iif with the L3 master;
    IP6CB iif still records the receiving interface set at IPv6 ingress.
    
    Fixes: 891ef8dd2a8d ("ipv6: sr: implement additional seg6local actions")
    Cc: [email protected]
    Suggested-by: Andrea Mayer <[email protected]>
    Signed-off-by: Kyle Zeng <[email protected]>
    Co-developed-by: David Lee <[email protected]>
    Signed-off-by: David Lee <[email protected]>
    Reviewed-by: Andrea Mayer <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Jakub Kicinski <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
ipvs: reload ip header after head reallocation [+ + +]
Author: Florian Westphal <[email protected]>
Date:   Fri Aug 28 11:55:21 2026 +0300

    ipvs: reload ip header after head reallocation
    
    commit a2f57827bf7c695b8c72dc4511cae8e86582369d upstream.
    
    __ip_vs_get_out_rt() calls skb_ensure_writable() which may
    reallocate skb->head.
    
    Fixes: 8d8e20e2d7bb ("ipvs: Decrement ttl")
    Cc: [email protected]
    Assisted-by: Claude:claude-sonnet-4-6
    Acked-by: Julian Anastasov <[email protected]>
    Signed-off-by: Florian Westphal <[email protected]>
    [Denis Arefev: adapted for 5.10/6.1: keep EnterFunction/LeaveFunction
    instrumentation]
    Signed-off-by: Denis Arefev <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>

 
jfs: add check read-only before truncation in jfs_truncate_nolock() [+ + +]
Author: Vasiliy Kovalev <[email protected]>
Date:   Tue Dec 24 17:49:14 2024 +0300

    jfs: add check read-only before truncation in jfs_truncate_nolock()
    
    [ Upstream commit b5799dd77054c1ec49b0088b006c9908e256843b ]
    
    Added a check for "read-only" mode in the `jfs_truncate_nolock`
    function to avoid errors related to writing to a read-only
    filesystem.
    
    Call stack:
    
    block_write_begin() {
      jfs_write_failed() {
        jfs_truncate() {
          jfs_truncate_nolock() {
            txEnd() {
              ...
              log = JFS_SBI(tblk->sb)->log;
              // (log == NULL)
    
    If the `isReadOnly(ip)` condition is triggered in
    `jfs_truncate_nolock`, the function execution will stop, and no
    further data modification will occur. Instead, the `xtTruncate`
    function will be called with the "COMMIT_WMAP" flag, preventing
    modifications in "read-only" mode.
    
    Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
    Reported-by: [email protected]
    Link: https://syzkaller.appspot.com/bug?extid=4e89b5368baba8324e07
    Signed-off-by: Vasiliy Kovalev <[email protected]>
    Signed-off-by: Dave Kleikamp <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>

jfs: add check read-only before txBeginAnon() call [+ + +]
Author: Vasiliy Kovalev <[email protected]>
Date:   Tue Dec 24 17:49:13 2024 +0300

    jfs: add check read-only before txBeginAnon() call
    
    [ Upstream commit 0176e69743ecc02961f2ae1ea42439cd2bf9ed58 ]
    
    Added a read-only check before calling `txBeginAnon` in `extAlloc`
    and `extRecord`. This prevents modification attempts on a read-only
    mounted filesystem, avoiding potential errors or crashes.
    
    Call trace:
     txBeginAnon+0xac/0x154
     extAlloc+0xe8/0xdec fs/jfs/jfs_extent.c:78
     jfs_get_block+0x340/0xb98 fs/jfs/inode.c:248
     __block_write_begin_int+0x580/0x166c fs/buffer.c:2128
     __block_write_begin fs/buffer.c:2177 [inline]
     block_write_begin+0x98/0x11c fs/buffer.c:2236
     jfs_write_begin+0x44/0x88 fs/jfs/inode.c:299
    
    Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
    Reported-by: [email protected]
    Link: https://syzkaller.appspot.com/bug?extid=4e89b5368baba8324e07
    Signed-off-by: Vasiliy Kovalev <[email protected]>
    Signed-off-by: Dave Kleikamp <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>

 
kcov: fix data corruption and race conditions on PREEMPT_RT [+ + +]
Author: Tetsuo Handa <[email protected]>
Date:   Tue Aug 25 15:48:11 2026 -0400

    kcov: fix data corruption and race conditions on PREEMPT_RT
    
    [ Upstream commit 2eed77fdcb0cc48e8eccb2bcd4b7f2c6d650e84c ]
    
    syzbot is reporting KCOV state corruption on PREEMPT_RT kernels, for the
    temporary storage used for saving/restoring remote KCOV state is currently
    allocated as the per-CPU area.
    
    On PREEMPT_RT kernels, softirq handlers run as preemptible task threads
    (e.g., ksoftirqd). If a softirq context preempts a task running a remote
    KCOV session, it safely saves the task's state into the per-CPU area.
    However, if that softirq thread is subsequently preempted by a higher-
    priority softirq thread on the same CPU, the second softirq will overwrite
    the same per-CPU area, permanently destroying the original task's KCOV
    state.
    
    Fix this data corruption by moving the temporary storage from the per-CPU
    area to the per-thread area. Since each softirq thread now owns its own
    task context, nested softirq preemption no longer causes data overwrites.
    
    Note that while the temporary storage is now on a per-thread basis, the
    per-CPU kcov_percpu_data.lock must be retained, for we need to ensure that
    kcov_remote_start() and kcov_remote_stop() operate atomically without
    racing against asynchronous interrupts that manipulate the current task's
    KCOV state.
    
    It is likely that GFP_KERNEL allocation by vmalloc_node() in kcov_init()
    has already called panic() before returning NULL, for there will be no
    OOM-killable userspace processes when __init function of built-in module
    runs. But this patch also fixes crashing the kernel when vmalloc_node()
    in kcov_init() returned NULL, for kcov_init() left per-CPU irq_area == NULL
    but kcov_remote_start() depends on per-CPU irq_area != NULL, resulting in
    
      (1) doing vmalloc() in kcov_remote_start() despite !in_task() context
    
      (2) out-of-array-bounds access if (1) succeeded but
          kcov->remote_size < CONFIG_KCOV_IRQ_AREA_SIZE
    
      (3) always leak memory allocated by (1), eventually killing all
          OOM-killable userspace processes
    
    problems.
    
    Link: https://lore.kernel.org/[email protected]
    Reported-by: [email protected]
    Closes: https://syzkaller.appspot.com/bug?extid=3f51ad7ac3ae57a6fdcc
    Reported-by: [email protected]
    Closes: https://syzkaller.appspot.com/bug?extid=47cf95ca1f9dcca872c8
    Reported-by: [email protected]
    Closes: https://syzkaller.appspot.com/bug?extid=8a173e13208949931dc7
    Reported-by: [email protected]
    Closes: https://syzkaller.appspot.com/bug?extid=90984d3713722683112e
    Analyzed-by: AI Mode in Google Search (no mail address)
    Fixes: 5ff3b30ab57d ("kcov: collect coverage from interrupts")
    Signed-off-by: Tetsuo Handa <[email protected]>
    Reviewed-by: Alexander Potapenko <[email protected]>
    Cc: Alan Stern <[email protected]>
    Cc: Andrey Konovalov <[email protected]>
    Cc: Christoph Hellwig <[email protected]>
    Cc: Clark Williams <[email protected]>
    Cc: Dmitry Vyukov <[email protected]>
    Cc: Greg Kroah-Hartman <[email protected]>
    Cc: Marco Elver <[email protected]>
    Cc: Mark Brown <[email protected]>
    Cc: Roman Gushchin <[email protected]>
    Cc: Sebastian Andrzej Siewior <[email protected]>
    Cc: <[email protected]>
    Signed-off-by: Andrew Morton <[email protected]>
    [ Adjusted the `kcov_init()` deletion context to plain `vmalloc()` since 5.15 lacks the `vmalloc_node()`/`cpu_to_node()` conversion. ]
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

kcov: replace local_irq_save() with a local_lock_t [+ + +]
Author: Sebastian Andrzej Siewior <[email protected]>
Date:   Tue Aug 25 15:48:10 2026 -0400

    kcov: replace local_irq_save() with a local_lock_t
    
    [ Upstream commit d5d2c51f1e5f56ed01d2c773974630c007e5e5f5 ]
    
    The kcov code mixes local_irq_save() and spin_lock() in
    kcov_remote_{start|end}().  This creates a warning on PREEMPT_RT because
    local_irq_save() disables interrupts and spin_lock_t is turned into a
    sleeping lock which can not be acquired in a section with disabled
    interrupts.
    
    The kcov_remote_lock is used to synchronize the access to the hash-list
    kcov_remote_map.  The local_irq_save() block protects access to the
    per-CPU data kcov_percpu_data.
    
    There is no compelling reason to change the lock type to raw_spin_lock_t
    to make it work with local_irq_save().  Changing it would require to
    move memory allocation (in kcov_remote_add()) and deallocation outside
    of the locked section.
    
    Adding an unlimited amount of entries to the hashlist will increase the
    IRQ-off time during lookup.  It could be argued that this is debug code
    and the latency does not matter.  There is however no need to do so and
    it would allow to use this facility in an RT enabled build.
    
    Using a local_lock_t instead of local_irq_save() has the befit of adding
    a protection scope within the source which makes it obvious what is
    protected.  On a !PREEMPT_RT && !LOCKDEP build the local_lock_irqsave()
    maps directly to local_irq_save() so there is overhead at runtime.
    
    Replace the local_irq_save() section with a local_lock_t.
    
    Link: https://lkml.kernel.org/r/[email protected]
    Link: https://lore.kernel.org/r/[email protected]
    Reported-by: Clark Williams <[email protected]>
    Signed-off-by: Sebastian Andrzej Siewior <[email protected]>
    Acked-by: Dmitry Vyukov <[email protected]>
    Acked-by: Marco Elver <[email protected]>
    Tested-by: Marco Elver <[email protected]>
    Reviewed-by: Andrey Konovalov <[email protected]>
    Cc: Steven Rostedt <[email protected]>
    Signed-off-by: Andrew Morton <[email protected]>
    Signed-off-by: Linus Torvalds <[email protected]>
    Stable-dep-of: 2eed77fdcb0c ("kcov: fix data corruption and race conditions on PREEMPT_RT")
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
KVM: arm64: Prevent access to vCPU events before init [+ + +]
Author: Oliver Upton <[email protected]>
Date:   Tue Sep 30 01:52:37 2025 -0700

    KVM: arm64: Prevent access to vCPU events before init
    
    [ Upstream commit 0aa1b76fe1429629215a7c79820e4b96233ac4a3 ]
    
    Another day, another syzkaller bug. KVM erroneously allows userspace to
    pend vCPU events for a vCPU that hasn't been initialized yet, leading to
    KVM interpreting a bunch of uninitialized garbage for routing /
    injecting the exception.
    
    In one case the injection code and the hyp disagree on whether the vCPU
    has a 32bit EL1 and put the vCPU into an illegal mode for AArch64,
    tripping the BUG() in exception_target_el() during the next injection:
    
      kernel BUG at arch/arm64/kvm/inject_fault.c:40!
      Internal error: Oops - BUG: 00000000f2000800 [#1]  SMP
      CPU: 3 UID: 0 PID: 318 Comm: repro Not tainted 6.17.0-rc4-00104-g10fd0285305d #6 PREEMPT
      Hardware name: linux,dummy-virt (DT)
      pstate: 21402009 (nzCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)
      pc : exception_target_el+0x88/0x8c
      lr : pend_serror_exception+0x18/0x13c
      sp : ffff800082f03a10
      x29: ffff800082f03a10 x28: ffff0000cb132280 x27: 0000000000000000
      x26: 0000000000000000 x25: ffff0000c2a99c20 x24: 0000000000000000
      x23: 0000000000008000 x22: 0000000000000002 x21: 0000000000000004
      x20: 0000000000008000 x19: ffff0000c2a99c20 x18: 0000000000000000
      x17: 0000000000000000 x16: 0000000000000000 x15: 00000000200000c0
      x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000
      x11: 0000000000000000 x10: 0000000000000000 x9 : 0000000000000000
      x8 : ffff800082f03af8 x7 : 0000000000000000 x6 : 0000000000000000
      x5 : ffff800080f621f0 x4 : 0000000000000000 x3 : 0000000000000000
      x2 : 000000000040009b x1 : 0000000000000003 x0 : ffff0000c2a99c20
      Call trace:
       exception_target_el+0x88/0x8c (P)
       kvm_inject_serror_esr+0x40/0x3b4
       __kvm_arm_vcpu_set_events+0xf0/0x100
       kvm_arch_vcpu_ioctl+0x180/0x9d4
       kvm_vcpu_ioctl+0x60c/0x9f4
       __arm64_sys_ioctl+0xac/0x104
       invoke_syscall+0x48/0x110
       el0_svc_common.constprop.0+0x40/0xe0
       do_el0_svc+0x1c/0x28
       el0_svc+0x34/0xf0
       el0t_64_sync_handler+0xa0/0xe4
       el0t_64_sync+0x198/0x19c
      Code: f946bc01 b4fffe61 9101e020 17fffff2 (d4210000)
    
    Reject the ioctls outright as no sane VMM would call these before
    KVM_ARM_VCPU_INIT anyway. Even if it did the exception would've been
    thrown away by the eventual reset of the vCPU's state.
    
    Cc: [email protected] # 6.17
    Fixes: b7b27facc7b5 ("arm/arm64: KVM: Add KVM_GET/SET_VCPU_EVENTS")
    Signed-off-by: Oliver Upton <[email protected]>
    Signed-off-by: Marc Zyngier <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>

KVM: s390: vsie: zero stale crypto bits [+ + +]
Author: Christian Borntraeger <[email protected]>
Date:   Tue Aug 11 17:37:36 2026 +0200

    KVM: s390: vsie: zero stale crypto bits
    
    commit 34d5b5b646c91cfb9338d7a12c955a70ffb8c66b upstream.
    
    When shadowing crypto access bits from a format0 apcb (crycb 0 or 1),
    the bits 64..255 are unchanged from whatever is in the vsie page in the
    crycb and thus in the apcb. This gives a nested guest potential access
    to a device no longer available. Zero out the remaining bits.
    
    Fixes: 6b79de4b056e ("KVM: s390: vsie: allow guest FORMAT-1 CRYCB on host FORMAT-2")
    Cc: [email protected]
    Signed-off-by: Christian Borntraeger <[email protected]>
    Reviewed-by: Claudio Imbrenda <[email protected]>
    Signed-off-by: Claudio Imbrenda <[email protected]>
    Message-ID: <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
Linux: Linux 5.15.220 [+ + +]
Author: Greg Kroah-Hartman <[email protected]>
Date:   Wed Sep 2 14:27:29 2026 +0200

    Linux 5.15.220
    
    Link: https://lore.kernel.org/r/[email protected]
    Tested-by: Florian Fainelli <[email protected]>
    Tested-by: Brett A C Sheffield <[email protected]>
    Tested-by: Harshit Mogalapalli <[email protected]>
    Tested-by: Pavel Machek (CIP) <[email protected]>
    Tested-by: Shuah Khan <[email protected]>
    Tested-by: Ron Economos <[email protected]>
    Tested-by: Barry K. Nathan <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
mm/swap: reject swapon() on filesystem-level encrypted files [+ + +]
Author: Eric Biggers <[email protected]>
Date:   Mon Aug 3 11:04:26 2026 -0700

    mm/swap: reject swapon() on filesystem-level encrypted files
    
    commit c310a8932a3107c9bc8f01d473e9d085f8aa9c98 upstream.
    
    ext4 and f2fs don't prevent filesystem-level encrypted files from being
    set up directly as swap files.  In this case, encryption is bypassed.
    
    No one should be doing this, vs.  the methods of encrypted swap that
    actually do work (such as swapping to a dm-crypt device, or swapping to a
    loopback device on top of a filesystem-level encrypted file).
    
    Nevertheless, to prevent user error, make swapon() explicitly reject this
    case.  Document this behavior in fscrypt.rst as well.
    
    Link: https://lore.kernel.org/[email protected]
    Fixes: 9bd8212f981e ("ext4 crypto: add encryption policy and password salt support")
    Fixes: f424f664f0e8 ("f2fs crypto: add encryption policy and password salt support")
    Signed-off-by: Eric Biggers <[email protected]>
    Reviewed-by: Baoquan He <[email protected]>
    Reviewed-by: Muhammad Usama Anjum <[email protected]>
    Reviewed-by: "Darrick J. Wong" <[email protected]>
    Cc: Barry Song <[email protected]>
    Cc: Chris Li <[email protected]>
    Cc: Kairui Song <[email protected]>
    Cc: Kemeng Shi <[email protected]>
    Cc: Nhat Pham <[email protected]>
    Cc: <[email protected]>
    Signed-off-by: Andrew Morton <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
net: bridge: mcast: fix use-after-free of a master VLAN's multicast context [+ + +]
Author: Norbert Szetei <[email protected]>
Date:   Wed Aug 26 11:12:27 2026 +0200

    net: bridge: mcast: fix use-after-free of a master VLAN's multicast context
    
    commit 50e5c6605cc9c2dd57bd2d1b3459674d19738983 upstream.
    
    br_multicast_toggle_one_vlan() clears BR_VLFLAG_MCAST_ENABLED under
    br->multicast_lock before stopping a VLAN's multicast context.  That is
    the teardown handshake: lockless readers gate on the flag through
    br_multicast_ctx_should_use() -> br_multicast_ctx_vlan_disabled(), so
    once it is cleared under the lock no reader can arm the context again.
    
    For a master VLAN the handshake never runs.  __vlan_del() clears
    BRIDGE_VLAN_INFO_BRENTRY before calling br_vlan_put_master(), so
    br_multicast_toggle_one_vlan(masterv, false) returns early on
    !br_vlan_is_brentry(vlan): the flag stays set and br->multicast_lock is
    never taken.  br_vlan_put_master() then drains the context in
    br_multicast_ctx_deinit() and frees the VLAN through call_rcu(), while a
    reader still inside rcu_read_lock() sees the context as enabled and
    re-arms it.  The port and port-VLAN branch of the function has no
    br_vlan_is_brentry() test and flips the flag under br->multicast_lock,
    so it is not affected.
    
    The reader is the bridge transmit path.  For a master VLAN
    br_multicast_rcv() selects brmctx = &vlan->br_mcast_ctx with
    pmctx = NULL, so IGMP sent to the bridge device re-arms the context's
    timers after br_multicast_ctx_deinit() has already stopped them.
    
      BUG: KASAN: slab-use-after-free in detach_if_pending+0x412/0x4a0
      Write of size 8 at addr ffff88810ac39918 by task brmc/601
       __mod_timer+0x51a/0xc50
       br_multicast_host_join+0x25b/0x390
       __br_multicast_add_group+0x468/0x530
       br_ip4_multicast_add_group+0x1a0/0x260
       br_multicast_rcv+0x2cda/0x61e0
       br_dev_xmit+0x6c4/0x1540
      Allocated by task 610:
       br_vlan_add+0x111/0xb40
       br_vlan_info+0x370/0x3e0
      Freed by task 0:
       kfree+0x1a7/0x4f0
       rcu_core+0x7dc/0x10a0
    
    Only test br_vlan_is_brentry() when enabling, like the
    br_multicast_ctx_vlan_global_disabled() test next to it.  Disabling then
    always clears BR_VLFLAG_MCAST_ENABLED under br->multicast_lock before
    br_multicast_ctx_deinit() drains the context.
    
    Fixes: 7b54aaaf53cb ("net: bridge: multicast: add vlan state initialization and control")
    Cc: [email protected]
    Signed-off-by: Norbert Szetei <[email protected]>
    Acked-by: Nikolay Aleksandrov <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Jakub Kicinski <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
nfc: nci: add data_len bound checks to activation parameter extractors [+ + +]
Author: Bryam Vargas <[email protected]>
Date:   Wed Aug 26 08:45:03 2026 -0400

    nfc: nci: add data_len bound checks to activation parameter extractors
    
    [ Upstream commit 0428fa2c22e2ba0cff766d3b80d461e149102045 ]
    
    nci_extract_activation_params_iso_dep() and
    nci_extract_activation_params_nfc_dep() read an inner length byte from
    the NCI RF_INTF_ACTIVATED_NTF payload and use it to memcpy() into fixed
    kernel buffers, but neither function receives the caller-validated
    activation_params_len.  A crafted NCI notification with
    activation_params_len=1 and an inner length byte of up to 20 (NFC-A) or
    50 (NFC-B) causes memcpy() to read that many bytes past the one valid
    byte in the activation params region -- a slab out-of-bounds read of
    kernel memory adjacent to the NCI skb.
    
    The sibling nci_extract_rf_params_*() family was given equivalent
    protection by commit 571dcbeb8e63 ("net: nfc: nci: Fix parameter
    validation for packet data"), but the two activation parameter
    extractors were not updated at that time.
    
    Add a data_len parameter to both functions, guard against an empty
    region before consuming the inner length byte, decrement the remaining
    count after consuming it, and clamp the copy length to what is actually
    available.  Update both call sites to pass ntf.activation_params_len,
    which is already validated against the skb at ntf.c:801.
    
    Fixes: e8c0dacd9836 ("NFC: Update names and structs to NCI spec 1.0 d18")
    Cc: [email protected]
    Signed-off-by: Bryam Vargas <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: David Heidelberg <[email protected]>
    [ Replaced `NFC_ATS_MAXSIZE` with the literal `20` since that macro doesn't exist in this tree. ]
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
nilfs2: correct return value kernel-doc descriptions for ioctl functions [+ + +]
Author: Ryusuke Konishi <[email protected]>
Date:   Tue Aug 25 21:46:26 2026 -0400

    nilfs2: correct return value kernel-doc descriptions for ioctl functions
    
    [ Upstream commit 17c46a45cdb94c500f4e93b176cdd61931b03020 ]
    
    Patch series "nilfs2: fix kernel-doc comments for function return values",
    v2.
    
    This series fixes the inadequacies in the return value descriptions in
    nilfs2's kernel-doc comments (mainly incorrect formatting), as well as the
    lack of return value descriptions themselves, and fixes most of the
    remaining warnings that are output when the kernel-doc script is run with
    the "-Wall" option.
    
    This patch (of 7):
    
    In the kernel-doc comments for functions, there are many cases where the
    format of the return value description is inaccurate, such as "Return
    Value: ...", which causes many warnings to be output when the kernel-doc
    script is executed with the "-Wall" option.
    
    This fixes such incorrectly formatted return value descriptions for ioctl
    functions.
    
    Link: https://lkml.kernel.org/r/[email protected]
    Link: https://lkml.kernel.org/r/[email protected]
    Signed-off-by: Ryusuke Konishi <[email protected]>
    Cc: "Brian G ." <[email protected]>
    Signed-off-by: Andrew Morton <[email protected]>
    Stable-dep-of: a1735eae5544 ("nilfs2: reject invalid block index in GC ioctl")
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

nilfs2: reject invalid block index in GC ioctl [+ + +]
Author: Ryusuke Konishi <[email protected]>
Date:   Tue Aug 25 21:46:27 2026 -0400

    nilfs2: reject invalid block index in GC ioctl
    
    [ Upstream commit a1735eae55448bc79c2da6593455791e886f6ed8 ]
    
    Syzbot reported list corruption caused by a double list_add_tail() call on
    bh->b_assoc_buffers within nilfs_lookup_dirty_data_buffers().
    
    Analysis revealed that the root cause was the insertion of a page/folio
    with a page index of ULONG_MAX into the page cache via the GC ioctl.
    filemap_get_folios_tag(), called by nilfs_lookup_dirty_data_buffers(),
    repeatedly detects a dirty folio with a page index of ULONG_MAX due to
    index wrap-around, leading to duplicate processing of dirty buffers.
    
    As a preparatory step, the GC ioctl loads the page/folio of the block to
    be moved during GC and inserts it into the page cache based on information
    in the nilfs_vdesc structure passed as an argument.  Normally, this does
    not cause issues because the user-space GC library configures the
    nilfs_vdesc structure properly.  However, since there is no range check on
    the parameters determining the page index, a request with artificially
    crafted parameters -- such as those generated by Syzbot -- can result in a
    page/folio being inserted with a page index of ULONG_MAX, triggering the
    above problem.
    
    This resolves the issue by checking the ranges of 'vd_offset' and
    'vd_vblocknr' in the nilfs_vdesc structure that determine the page index,
    thereby preventing the invalid page/folio insertions.
    
    Reported-by: [email protected]
    Closes: https://syzkaller.appspot.com/bug?extid=c37bed40868932d790e9
    Fixes: 7942b919f732 ("nilfs2: ioctl operations")
    Cc: wuyankun <[email protected]>
    Cc: [email protected]
    Signed-off-by: Ryusuke Konishi <[email protected]>
    Signed-off-by: Viacheslav Dubeyko <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
nvme: rename CDR/MORE/DNR to NVME_STATUS_* [+ + +]
Author: Weiwen Hu <[email protected]>
Date:   Wed Aug 26 13:14:01 2026 -0400

    nvme: rename CDR/MORE/DNR to NVME_STATUS_*
    
    [ Upstream commit dd0b0a4a2c5d7209457dc172997d1243ad269cfa ]
    
    CDR/MORE/DNR fields are not belonging to SC in the NVMe spec, rename
    them to NVME_STATUS_* to avoid confusion.
    
    Signed-off-by: Weiwen Hu <[email protected]>
    Reviewed-by: Sagi Grimberg <[email protected]>
    Reviewed-by: Chaitanya Kulkarni <[email protected]>
    Reviewed-by: Christoph Hellwig <[email protected]>
    Signed-off-by: Keith Busch <[email protected]>
    Stable-dep-of: 4a3f00262a04 ("nvmet-tcp: bound SGL data length before allocating command buffers")
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
nvmet-tcp: bound SGL data length before allocating command buffers [+ + +]
Author: Ibrahim Hashimov <[email protected]>
Date:   Wed Aug 26 13:14:02 2026 -0400

    nvmet-tcp: bound SGL data length before allocating command buffers
    
    [ Upstream commit 4a3f00262a044e8e15064b1a6860968bf0500bf4 ]
    
    nvmet_tcp_map_data() reads the host-controlled 32-bit sgl->length
    and, for the in-capsule offset descriptor (type 0x01), checks it
    against port->inline_data_size before use. Any other SGL descriptor
    type -- including the non-inline transport SGL data-block descriptor
    (type (NVME_TRANSPORT_SGL_DATA_DESC << 4) | NVME_SGL_FMT_TRANSPORT_A,
    the type a real host uses for out-of-capsule writes) skips that check
    entirely and falls straight through to:
    
            cmd->req.sg = sgl_alloc(len, GFP_KERNEL, &cmd->req.sg_cnt);
    
    with len taken directly from the wire, unbounded up to 4 GiB.
    
    nvmet_req_init() only parses the command and never inspects
    sgl->length, and nvmet_check_transfer_len() -- the only other place
    transfer_len is validated -- runs later, from req->execute(), after
    the allocation has already happened. For a write command the target
    responds with an R2T and parks the command waiting for the host to
    send the data; if the host (or an unauthenticated peer that simply
    never follows up) never does, the sgl_alloc() buffer stays resident
    for the life of the command. NVMe/TCP has no mandatory authentication
    in the default configuration, so any peer able to reach the target
    portal and complete a Fabrics connect can drive this with a single
    crafted command, repeatable across queues and connections for
    amplification. This is unbounded kernel memory allocation
    triggered by a remote, effectively unauthenticated peer.
    
    Validate len against the same NVMET_TCP_MAXH2CDATA ceiling this file
    already uses to bound per-PDU H2C data, for every SGL descriptor type,
    before doing any allocation. This closes the gap for the non-inline
    descriptor while leaving the existing, tighter inline_data_size check
    in place for the in-capsule case.
    
    Runtime-verified on a v6.19 KASAN stand: with this bound in place, a
    crafted write command carrying an oversized non-inline SGL length is
    rejected before sgl_alloc() runs, where the same request previously
    drove an unbounded ~256 MiB kernel allocation (up to 4 GiB) that
    stayed resident pending an R2T the host never satisfies.
    
    Fixes: 872d26a391da ("nvmet-tcp: add NVMe over TCP target driver")
    Cc: [email protected]
    Reviewed-by: Christoph Hellwig <[email protected]>
    Signed-off-by: Ibrahim Hashimov <[email protected]>
    Assisted-by: AuditCode-AI:2026.07
    Signed-off-by: Keith Busch <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
RDMA/rxe: Fix OOB in free_rd_atomic_resources() [+ + +]
Author: Peiyang He <[email protected]>
Date:   Tue Aug 25 22:13:14 2026 +0200

    RDMA/rxe: Fix OOB in free_rd_atomic_resources()
    
    commit de329533792a373186d79dca1ca120f8fa0afd05 upstream.
    
    free_rd_atomic_resources() iterates using qp->attr.max_dest_rd_atomic.
    Updating max_dest_rd_atomic before freeing the old array can make the
    free path walk past the old allocation and trigger a slab out-of-bounds
    write catched by KASAN:
    ==================================================================
    BUG: KASAN: slab-out-of-bounds in free_rd_atomic_resource drivers/infiniband/sw/rxe/rxe_qp.c:180 [inline]
    BUG: KASAN: slab-out-of-bounds in free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:171 [inline]
    BUG: KASAN: slab-out-of-bounds in free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:163 [inline]
    BUG: KASAN: slab-out-of-bounds in rxe_qp_from_attr+0x1e88/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:712
    Write of size 4 at addr ffff88802b8dddb8 by task syz.3.451/11063
    
    CPU: 0 UID: 0 PID: 11063 Comm: syz.3.451 Not tainted 7.1.0 #2 PREEMPT(full)
    Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
    Call Trace:
     <TASK>
     __dump_stack lib/dump_stack.c:94 [inline]
     dump_stack_lvl+0x10e/0x1f0 lib/dump_stack.c:120
     print_address_description mm/kasan/report.c:378 [inline]
     print_report+0xf7/0x600 mm/kasan/report.c:482
     kasan_report+0xe4/0x120 mm/kasan/report.c:595
     free_rd_atomic_resource drivers/infiniband/sw/rxe/rxe_qp.c:180 [inline]
     free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:171 [inline]
     free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:163 [inline]
     rxe_qp_from_attr+0x1e88/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:712
     rxe_modify_qp+0x1e2/0x530 drivers/infiniband/sw/rxe/rxe_verbs.c:623
     ib_security_modify_qp+0x223/0xfa0 drivers/infiniband/core/security.c:625
     _ib_modify_qp+0x333/0xec0 drivers/infiniband/core/verbs.c:1915
     modify_qp+0x13ca/0x1940 drivers/infiniband/core/uverbs_cmd.c:1932
     ib_uverbs_modify_qp+0xcb/0x120 drivers/infiniband/core/uverbs_cmd.c:1958
     ib_uverbs_write+0xb86/0x1030 drivers/infiniband/core/uverbs_main.c:680
     vfs_write+0x2aa/0x1070 fs/read_write.c:686
     ksys_write+0x1f8/0x250 fs/read_write.c:740
     do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
     do_syscall_64+0x116/0x800 arch/x86/entry/syscall_64.c:94
     entry_SYSCALL_64_after_hwframe+0x77/0x7f
    RIP: 0033:0x7fefc75a70cd
    Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48
    RSP: 002b:00007fefc8495018 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
    RAX: ffffffffffffffda RBX: 00007fefc7835fa0 RCX: 00007fefc75a70cd
    RDX: 0000000000000078 RSI: 0000200000000240 RDI: 0000000000000007
    RBP: 00007fefc764f10f R08: 0000000000000000 R09: 0000000000000000
    R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
    R13: 00007fefc7836038 R14: 00007fefc7835fa0 R15: 00007ffcf0586aa0
     </TASK>
    
    Allocated by task 11063:
     kasan_save_stack+0x33/0x60 mm/kasan/common.c:57
     kasan_save_track+0x14/0x30 mm/kasan/common.c:78
     poison_kmalloc_redzone mm/kasan/common.c:398 [inline]
     __kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:415
     kasan_kmalloc include/linux/kasan.h:263 [inline]
     __do_kmalloc_node mm/slub.c:5296 [inline]
     __kmalloc_noprof+0x32a/0x850 mm/slub.c:5308
     kmalloc_noprof include/linux/slab.h:954 [inline]
     kzalloc_noprof include/linux/slab.h:1188 [inline]
     alloc_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:155 [inline]
     rxe_qp_from_attr+0x3f8/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:714
     rxe_modify_qp+0x1e2/0x530 drivers/infiniband/sw/rxe/rxe_verbs.c:623
     ib_security_modify_qp+0x223/0xfa0 drivers/infiniband/core/security.c:625
     _ib_modify_qp+0x333/0xec0 drivers/infiniband/core/verbs.c:1915
     modify_qp+0x13ca/0x1940 drivers/infiniband/core/uverbs_cmd.c:1932
     ib_uverbs_modify_qp+0xcb/0x120 drivers/infiniband/core/uverbs_cmd.c:1958
     ib_uverbs_write+0xb86/0x1030 drivers/infiniband/core/uverbs_main.c:680
     vfs_write+0x2aa/0x1070 fs/read_write.c:686
     ksys_write+0x1f8/0x250 fs/read_write.c:740
     do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
     do_syscall_64+0x116/0x800 arch/x86/entry/syscall_64.c:94
     entry_SYSCALL_64_after_hwframe+0x77/0x7f
    
    The buggy address belongs to the object at ffff88802b8ddd80
     which belongs to the cache kmalloc-64 of size 64
    The buggy address is located 0 bytes to the right of
     allocated 56-byte region [ffff88802b8ddd80, ffff88802b8dddb8)
    
    The buggy address belongs to the physical page:
    page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x2b8dd
    flags: 0xfff00000000000(node=0|zone=1|lastcpupid=0x7ff)
    page_type: f5(slab)
    raw: 00fff00000000000 ffff888015c418c0 dead000000000100 dead000000000122
    raw: 0000000000000000 0000000800200020 00000000f5000000 0000000000000000
    page dumped because: kasan: bad access detected
    page_owner tracks the page as allocated
    page last allocated via order 0, migratetype Unmovable, gfp_mask 0xd2c40(GFP_NOFS|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_NOMEMALLOC), pid 4651, tgid 4651 ((udev-worker)), ts 123427165316, free_ts 123425874255
     set_page_owner include/linux/page_owner.h:32 [inline]
     post_alloc_hook+0xfc/0x120 mm/page_alloc.c:1853
     prep_new_page mm/page_alloc.c:1861 [inline]
     get_page_from_freelist+0x75b/0x3220 mm/page_alloc.c:3941
     __alloc_frozen_pages_noprof+0x27e/0x2b00 mm/page_alloc.c:5221
     alloc_slab_page mm/slub.c:3278 [inline]
     allocate_slab mm/slub.c:3467 [inline]
     new_slab+0xa6/0x670 mm/slub.c:3525
     refill_objects+0x278/0x420 mm/slub.c:7272
     refill_sheaf mm/slub.c:2816 [inline]
     __pcs_replace_empty_main+0x2ed/0x640 mm/slub.c:4652
     alloc_from_pcs mm/slub.c:4750 [inline]
     slab_alloc_node mm/slub.c:4884 [inline]
     __do_kmalloc_node mm/slub.c:5295 [inline]
     __kmalloc_noprof+0x68d/0x850 mm/slub.c:5308
     kmalloc_noprof include/linux/slab.h:954 [inline]
     kzalloc_noprof include/linux/slab.h:1188 [inline]
     tomoyo_encode2+0x100/0x3e0 security/tomoyo/realpath.c:45
     tomoyo_encode+0x29/0x50 security/tomoyo/realpath.c:80
     tomoyo_realpath_from_path+0x18c/0x690 security/tomoyo/realpath.c:283
     tomoyo_get_realpath security/tomoyo/file.c:151 [inline]
     tomoyo_check_open_permission+0x2ab/0x3c0 security/tomoyo/file.c:776
     tomoyo_file_open+0x6b/0x90 security/tomoyo/tomoyo.c:334
     security_file_open+0x7a/0x1b0 security/security.c:2739
     do_dentry_open+0x57e/0x1690 fs/open.c:924
     vfs_open+0x82/0x3f0 fs/open.c:1079
     do_open fs/namei.c:4699 [inline]
     path_openat+0x218a/0x3190 fs/namei.c:4858
    page last free pid 1 tgid 1 stack trace:
     reset_page_owner include/linux/page_owner.h:25 [inline]
     __free_pages_prepare mm/page_alloc.c:1397 [inline]
     __free_frozen_pages+0x763/0xfc0 mm/page_alloc.c:2938
     selinux_genfs_get_sid security/selinux/hooks.c:1364 [inline]
     inode_doinit_with_dentry+0x903/0x1320 security/selinux/hooks.c:1563
     selinux_d_instantiate+0x26/0x30 security/selinux/hooks.c:6658
     security_d_instantiate+0x123/0x190 security/security.c:3704
     d_splice_alias_ops+0x92/0x850 fs/dcache.c:3141
     kernfs_iop_lookup+0x23f/0x2d0 fs/kernfs/dir.c:1289
     lookup_open.isra.0+0x659/0x1080 fs/namei.c:4484
     open_last_lookups fs/namei.c:4611 [inline]
     path_openat+0x17dd/0x3190 fs/namei.c:4855
     do_file_open+0x20c/0x430 fs/namei.c:4887
     do_sys_openat2+0x101/0x1d0 fs/open.c:1364
     do_sys_open fs/open.c:1370 [inline]
     __do_sys_openat fs/open.c:1386 [inline]
     __se_sys_openat fs/open.c:1381 [inline]
     __x64_sys_openat+0x141/0x200 fs/open.c:1381
     do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
     do_syscall_64+0x116/0x800 arch/x86/entry/syscall_64.c:94
     entry_SYSCALL_64_after_hwframe+0x77/0x7f
    
    Memory state around the buggy address:
     ffff88802b8ddc80: 00 00 00 00 00 00 fc fc fc fc fc fc fc fc fc fc
     ffff88802b8ddd00: fa fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc
    >ffff88802b8ddd80: 00 00 00 00 00 00 00 fc fc fc fc fc fc fc fc fc
                                            ^
     ffff88802b8dde00: 00 00 00 00 00 fc fc fc fc fc fc fc fc fc fc fc
     ffff88802b8dde80: 00 00 00 00 00 fc fc fc fc fc fc fc fc fc fc fc
    
    Fix the OOB by moving the assignment after free_rd_atomic_resources()
    so the old array is freed using the old bound. This matches the original
    ordering in commit 8700e3e7c485 ("Soft RoCE driver").
    
    Closes: https://lore.kernel.org/all/365C68B4923F8214+30195a67-0b90-4b92-ab96-2ce41517793c@smail.nju.edu.cn/
    Fixes: b6bbee0d2438 ("IB/rxe: Properly honor max IRD value for rd/atomic.")
    Cc: [email protected]
    Signed-off-by: Peiyang He <[email protected]>
    Reviewed-by: Zhu Yanjun <[email protected]>
    Signed-off-by: Leon Romanovsky <[email protected]>
    (cherry picked from commit de329533792a373186d79dca1ca120f8fa0afd05)
    [This commit is based on the upstream commit 6f7014237405 ("RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp")]
    Signed-off-by: Zhu Yanjun <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>
 
Revert "mtd: maps: vmu-flash: fix fault in unaligned fixup" [+ + +]
Author: Sasha Levin <[email protected]>
Date:   Sun Aug 30 11:07:47 2026 -0400

    Revert "mtd: maps: vmu-flash: fix fault in unaligned fixup"
    
    This reverts commit 631edc934e476991a04723d3283e6628d077f8c1.
    
    Signed-off-by: Sasha Levin <[email protected]>

 
Revert "PM: sleep: Use complete() in device_pm_sleep_init()" [+ + +]
Author: Sasha Levin <[email protected]>
Date:   Sat Aug 29 20:58:47 2026 -0400

    Revert "PM: sleep: Use complete() in device_pm_sleep_init()"
    
    This reverts commit 31064374d24dc18cf132ffb9d350f318f3274b06.
    
    Signed-off-by: Sasha Levin <[email protected]>

 
Revert "smb: client: use kvzalloc() for megabyte buffer in simple fallocate" [+ + +]
Author: Sasha Levin <[email protected]>
Date:   Sun Aug 30 11:08:17 2026 -0400

    Revert "smb: client: use kvzalloc() for megabyte buffer in simple fallocate"
    
    This reverts commit d1bc345f6229412d45bab2baf81d45d0e678253a.
    
    Signed-off-by: Sasha Levin <[email protected]>

 
selinux: switch two allocations to use kzalloc_objs() [+ + +]
Author: Stephen Smalley <[email protected]>
Date:   Wed Apr 29 15:18:40 2026 -0400

    selinux: switch two allocations to use kzalloc_objs()
    
    [ Upstream commit cf6a513f1937581eb012a217b29817e025a1a0ef ]
    
    These were the only two allocations in the policy loading logic
    that were not already using kzalloc_objs() for the policy
    data structures. Fix these to be consistent with the rest and
    to protect against ill-formed policy.
    
    Signed-off-by: Stephen Smalley <[email protected]>
    Signed-off-by: Paul Moore <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>

 
smc: Use __sk_dst_get() and dst_dev_rcu() in smc_vlan_by_tcpsk(). [+ + +]
Author: Kuniyuki Iwashima <[email protected]>
Date:   Tue Sep 16 21:47:22 2025 +0000

    smc: Use __sk_dst_get() and dst_dev_rcu() in smc_vlan_by_tcpsk().
    
    [ Upstream commit 0b0e4d51c6554e5ecc3f8cc73c2eaf12da21249a ]
    
    smc_vlan_by_tcpsk() fetches sk_dst_get(sk)->dev before RTNL and
    passes it to netdev_walk_all_lower_dev(), which is illegal.
    
    Also, smc_vlan_by_tcpsk_walk() does not require RTNL at all.
    
    Let's use __sk_dst_get(), dst_dev_rcu(), and
    netdev_walk_all_lower_dev_rcu().
    
    Note that the returned value of smc_vlan_by_tcpsk() is not used
    in the caller.
    
    Fixes: 0cfdd8f92cac ("smc: connection and link group creation")
    Signed-off-by: Kuniyuki Iwashima <[email protected]>
    Reviewed-by: Eric Dumazet <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Jakub Kicinski <[email protected]>
    Signed-off-by: Sasha Levin <[email protected]>

 
USB: c67x00: fix use-after-free in c67x00_add_iso_urb() [+ + +]
Author: Shuangpeng Bai <[email protected]>
Date:   Wed Aug 5 21:35:02 2026 -0400

    USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
    
    commit b1e24de475bf2d66fffc9103f3444b783527d55a upstream.
    
    When TD creation fails for the last packet of an isochronous URB,
    c67x00_add_iso_urb() gives the URB back before updating the endpoint
    scheduling state.
    
    c67x00_giveback_urb() frees the URB private data, and the completion
    callback may release the final URB reference. The following accesses to
    urbp->ep_data, urb->interval, and urbp->cnt can therefore use freed
    memory.
    
    Update next_frame and cnt before giving back the failed final packet,
    making the giveback the last operation that uses the URB and its private
    data.
    
    Fixes: e9b29ffc519b ("USB: add Cypress c67x00 OTG controller HCD driver")
    Cc: [email protected]
    Signed-off-by: Shuangpeng Bai <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
usb: core: Add lock to usb_wakeup_notification() [+ + +]
Author: Griffin Kroah-Hartman <[email protected]>
Date:   Mon Jul 13 17:43:53 2026 +0200

    usb: core: Add lock to usb_wakeup_notification()
    
    commit e263e18a9e7b1ff3e7301f0801c6ff87c31adfb6 upstream.
    
    Add a spin lock to usb_wakeup notification to prevent a race condition
    with dereferencing freed memory. This could be hit by the xHCI driver as
    it calls this function from an IRQ and could race with the
    hub_disconnect() function, which properly grabs this lock to protect the
    state of the device.
    
    Assisted-by: gkh_clanker_t1000
    Signed-off-by: Griffin Kroah-Hartman <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

usb: core: Strengthen error handling in hub_hub_status() [+ + +]
Author: Griffin Kroah-Hartman <[email protected]>
Date:   Wed Jul 22 10:17:39 2026 +0200

    usb: core: Strengthen error handling in hub_hub_status()
    
    commit a29496745aa335d97f617385809583241e118610 upstream.
    
    Add additional error handling after the call to get_hub_status() in
    hub_hub_status().
    
    get_hub_status() uses usb_control_msg() which does not verify that the
    message is the correct length, substituting it for
    usb_control_msg_recv() would also solve this issue but increase memory
    allocations.
    
    Instead, error handling is copied from the method used in
    hub_ext_port_status(), which shares the same flow of logic as
    hub_hub_status().
    
    Assisted-by: gkh_clanker_t1000
    Signed-off-by: Griffin Kroah-Hartman <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

usb: gadget: f_tcm: keep port count until LUN teardown completes [+ + +]
Author: Shuangpeng Bai <[email protected]>
Date:   Fri Aug 7 02:07:33 2026 -0400

    usb: gadget: f_tcm: keep port count until LUN teardown completes
    
    commit c39d0916da47d94909391876c9e5bd429ea7b1b9 upstream.
    
    tcm_usbg_drop_nexus() permits session removal once tpg_port_count
    reaches zero. However, usbg_port_unlink() currently decrements that
    count from the fabric_pre_unlink() callback, before core_dev_del_lun()
    waits for active se_lun references to drain.
    
    If removal of the last LUN races a nexus removal, the latter can observe
    a zero port count and call target_remove_session(). This frees
    sess_cmd_map while an in-flight struct usbg_cmd, including its work item,
    can still be accessed.
    
    Overlapping the last-LUN unlink with nexus removal reproduces this
    lifetime violation as a DEBUG_OBJECTS "free active" warning for
    usbg_cmd_work, followed by a target-core BUG/Oops.
    
    The generic target-core unlink path has no callback after
    core_dev_del_lun() completes. Add an optional fabric_post_unlink()
    callback and use it for the f_tcm port count. The count now remains
    nonzero until core_dev_del_lun() has finished draining active LUN
    references, preventing nexus removal from freeing the session during
    command completion.
    
    Fixes: c52661d60f63 ("usb-gadget: Initial merge of target module for UASP + BOT")
    Cc: [email protected]
    Signed-off-by: Shuangpeng Bai <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
USB: serial: option: fix slab OOB read in interrupt URB callback [+ + +]
Author: Jiale Yao <[email protected]>
Date:   Sun Jul 26 00:27:51 2026 +0800

    USB: serial: option: fix slab OOB read in interrupt URB callback
    
    commit 885d802f544ca7bfa8f3984d94233cce715bb6b3 upstream.
    
    The interrupt URB buffer is allocated in setup_port_interrupt_in() based
    on the endpoint's wMaxPacketSize:
    
        buffer_size = usb_endpoint_maxp(epd);
        port->interrupt_in_buffer = kmalloc(buffer_size, GFP_KERNEL);
    
    When a USB device declares wMaxPacketSize = 8 on its interrupt IN
    endpoint, the buffer is allocated from kmalloc-8 cache (exactly
    8 bytes).
    
    If the device sends a short packet (actual_length < wMaxPacketSize),
    the URB completes with status == 0 and the callback proceeds to read:
    
        data[sizeof(struct usb_ctrlrequest)]
    
    which evaluates to data[8], accessing 1 byte beyond the allocated 8-byte
    buffer. This results in a slab out-of-bounds read.
    
    Fix this by adding the missing bounds check: first verify that the
    actual length is large enough to contain the struct usb_ctrlrequest
    header before accessing req_pkt->bRequestType and req_pkt->bRequest,
    and then verify that there is an additional byte for the modem signal
    state before reading data[sizeof(struct usb_ctrlrequest)] inside the
    conditional.  Use sizeof(*req_pkt) instead of sizeof(struct
    usb_ctrlrequest) for consistency.
    
    Assisted-by: Claude:deepseek-v4-pro
    Signed-off-by: Jiale Yao <[email protected]>
    Fixes: 58cfe9113e48 ("[PATCH] USB: add Option Card driver")
    Cc: [email protected]      # v2.6.12
    [ johan: use dev_err(); split signals declaration and initialisation ]
    Signed-off-by: Johan Hovold <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

USB: serial: spcp8x5: drop broken carrier detect support [+ + +]
Author: Johan Hovold <[email protected]>
Date:   Thu Aug 6 15:52:48 2026 +0200

    USB: serial: spcp8x5: drop broken carrier detect support
    
    commit d37186bd95a07e334447f47274a38a311dad2172 upstream.
    
    The driver does not support modem status notifications and instead used
    to fetch the modem status once at open() and subsequently operate on and
    report stale state.
    
    As part of fixing this, a call to fetch the status was added to
    carrier_raised(), which does not work as that callback must not sleep
    (e.g. unlike tiocmget()).
    
    Drop the broken carrier detect support.
    
    Fixes: e1ed212d8593 ("USB: spcp8x5: add proper modem-status support")
    Cc: [email protected]      # 3.10
    Reported-by: [email protected]
    Link: https://lore.kernel.org/all/[email protected]
    Signed-off-by: Johan Hovold <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
usb: usbfs: fix use-after-free of usb_device in usbdev_release() [+ + +]
Author: Miguel Peñaranda <[email protected]>
Date:   Mon Aug 10 14:12:09 2026 +0200

    usb: usbfs: fix use-after-free of usb_device in usbdev_release()
    
    commit 0dd68b5d01d022fc9c5e71c82a82b0a94d3d0671 upstream.
    
    usbdev_release() drops its reference to the struct usb_device before
    draining the list of completed async URBs, but that drain path reads back
    through the same object: free_async() calls dec_usb_memory_use_count()
    for any URB whose buffer came from the usbfs mmap() region, and its first
    statement is bus_to_hcd(ps->dev->bus).
    
    After a disconnect the usbfs reference can be the last one, in which case
    usb_put_dev() frees the device and the subsequent loop reads offset 80 of
    freed memory and uses the result as a struct usb_hcd *, which
    hcd_buffer_free_pages() then dereferences.
    
    This is reachable by an unprivileged process that has read/write access to
    a /dev/bus/usb node: mmap() the fd, submit one URB with a buffer inside the
    mapping, wait for the device to be unplugged, then munmap() and close().
    It reproduces on every attempt rather than being a race, because a live
    MAP_SHARED vma holds a reference on the struct file, so usbdev_release()
    cannot run until the last vma is gone and the freeing branch of
    dec_usb_memory_use_count() is always taken.
    
      BUG: KASAN: slab-use-after-free in dec_usb_memory_use_count+0x3ae/0x410
      Read of size 8 at addr ffff8880122ee050 by task poc/769
      CPU: 1 UID: 1000 PID: 769 Comm: poc Tainted: G    B    6.12.94 #3
    
      Call Trace:
       dec_usb_memory_use_count+0x3ae/0x410
       free_async+0x2aa/0x4f0
       usbdev_release+0x375/0x460
       __fput+0x3ea/0xb50
       __x64_sys_close+0x86/0x100
    
      Allocated by task 11:
       usb_alloc_dev+0x55/0xd90
       hub_event+0x2524/0x43d0
    
      Freed by task 769:
       kfree+0x121/0x360
       device_release+0xd2/0x280
       usb_put_dev+0x23/0x30
       usbdev_release+0x2d8/0x460
    
    Release the device reference after the drain loop instead. Nothing between
    the two points requires it to have been dropped.
    
    Fixes: f7d34b445abc ("USB: Add support for usbfs zerocopy.")
    Cc: [email protected]
    Assisted-by: Claude:claude-opus-5
    Signed-off-by: Miguel Peñaranda <[email protected]>
    Reviewed-by: Alan Stern <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

usb: usbtest: disable dynamic ID support [+ + +]
Author: Aleksandr Nogikh <[email protected]>
Date:   Thu Aug 6 15:26:51 2026 +0000

    usb: usbtest: disable dynamic ID support
    
    commit 00e2071f6d5621a5ddea311a5e6b143ae6e474af upstream.
    
    The usbtest driver relies on the driver_info field of struct usb_device_id
    to point to a valid struct usbtest_info descriptor. This structure contains
    essential test configurations, such as endpoint addresses and test modes,
    which are required during probe.
    
    When a user dynamically adds a new device ID via the sysfs new_id
    interface without specifying a reference device, the USB core initializes
    driver_info to 0 (NULL). When a matching device is subsequently probed,
    usbtest_probe() unconditionally casts driver_info to a struct usbtest_info
    pointer and dereferences it, leading to a NULL pointer dereference crash:
    
      Oops: general protection fault, probably for non-canonical address
      0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI
      KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]
      RIP: 0010:usbtest_probe+0x3b9/0x1280 drivers/usb/misc/usbtest.c:2822
    
    Because usbtest strictly requires pre-defined usbtest_info descriptors
    to function, dynamic ID binding via sysfs is fundamentally unsupported
    for this driver.
    
    Fix this by setting .no_dynamic_id = 1 on usbtest_driver. This instructs
    the USB core to skip creating the new_id and remove_id sysfs interfaces
    for usbtest, preventing invalid dynamic ID entries from being created.
    
    Cc: [email protected]
    Reported-by: [email protected]
    Closes: https://syzkaller.appspot.com/bug?extid=7e1e5911f9eac50bedc7
    Signed-off-by: Aleksandr Nogikh <[email protected]>
    Tested-by: [email protected]
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
xfrm: ah6: validate routing header segments_left [+ + +]
Author: Asim Viladi Oglu Manizada <[email protected]>
Date:   Thu Jul 23 09:35:48 2026 +0000

    xfrm: ah6: validate routing header segments_left
    
    commit 7bad4bda74dc4713f398d3b7624ff05478e3a568 upstream.
    
    AH6 rearranges routing-header addresses before computing or verifying the
    ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than
    the number of addresses described by the routing header's hdrlen field.
    
    That assumption does not hold for raw IPv6 HDRINCL packets. A packet with
    hdrlen equal to 2 describes one address, but can carry an arbitrary
    segments_left value. With segments_left equal to 255, the function moves
    its address pointer 4,064 bytes backwards and passes a 4,064-byte length to
    memmove(), resulting in an out-of-bounds access.
    
    Validate the invariant locally before modifying the routing header or
    performing any address-pointer arithmetic, and propagate malformed-header
    errors to the existing AH6 input and output error paths.
    
    Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
    Cc: [email protected]
    Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix
    Signed-off-by: Asim Viladi Oglu Manizada <[email protected]>
    Signed-off-by: Steffen Klassert <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

xfrm: drop ESP-in-TCP packets with no ingress device [+ + +]
Author: Zhiling Zou <[email protected]>
Date:   Sat Jul 18 15:12:50 2026 +0800

    xfrm: drop ESP-in-TCP packets with no ingress device
    
    commit e1d7c5ac1c246ce5775f604515de0a59fbf2116e upstream.
    
    ESP-in-TCP receives records through the TCP strparser. handle_esp()
    restores skb->dev from the saved skb_iif before passing the packet into
    the XFRM input path.
    
    Queued TCP data can be processed after the original ingress device has
    been removed, for example during veth or net namespace teardown. In that
    case dev_get_by_index_rcu() returns NULL. The XFRM IPv4 and IPv6 input
    paths both expect skb->dev to be valid while building the route lookup,
    so queued ESP-in-TCP data can dereference a NULL device.
    
    Drop the packet if the saved ingress device can no longer be resolved.
    Such a packet can no longer be routed through the normal XFRM receive
    path, and this preserves the existing behaviour for packets whose ingress
    device still exists.
    
    Fixes: e27cca96cd68 ("xfrm: add espintcp (RFC 8229)")
    Cc: [email protected]
    Reported-by: Vega <[email protected]>
    Signed-off-by: Zhiling Zou <[email protected]>
    Assisted-by: Codex:gpt-5.4
    Reviewed-by: Ren Wei <[email protected]>
    Signed-off-by: Steffen Klassert <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

xfrm: espintcp: fix UAF during close [+ + +]
Author: Sabrina Dubroca <[email protected]>
Date:   Thu Jul 16 22:54:59 2026 +0200

    xfrm: espintcp: fix UAF during close
    
    commit deb232e884877bf10b4ce2580909eedec986c284 upstream.
    
    ZDI reported and analyzed a race condition during close for espintcp
    sockets:
    
        espintcp_close() frees emsg->skb via kfree_skb() without holding
        any socket lock. Concurrently, the xfrm_trans_reinject work queue
        invokes esp_output_tcp_finish() -> espintcp_push_skb() ->
        espintcp_push_msgs() -> skb_send_sock_locked(), which reads the
        same skb as a data source.
    
    Fix this by adding a synchronize_rcu() call after resetting sk_prot,
    since esp_output_tcp_finish() runs under RCU and won't use a socket
    with sk_prot == &tcp_prot.  Simply taking the socket lock in
    espintcp_close() could lead to leaks, if esp_output_tcp_finish()
    re-adds an skb in the slot we just freed. After this, the existing
    barrier() is no longer needed.
    
    Cc: [email protected]
    Fixes: e27cca96cd68 ("xfrm: add espintcp (RFC 8229)")
    Reported-by: [email protected]
    Signed-off-by: Sabrina Dubroca <[email protected]>
    Reviewed-by: Breno Leitao <[email protected]>
    Signed-off-by: Steffen Klassert <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

xfrm: fix xfrm_state_construct() auth-trunc leak [+ + +]
Author: Zihan Xi <[email protected]>
Date:   Tue Jul 28 01:30:32 2026 +0800

    xfrm: fix xfrm_state_construct() auth-trunc leak
    
    commit c12cbf56320fb633484ee0ca1fb7d68d6b64b213 upstream.
    
    attach_auth_trunc() can allocate x->aalg while leaving
    x->props.aalgo at zero when the selected auth algorithm has no
    sadb_alg_id. One real case is cmac(aes).
    
    xfrm_state_construct() then treats !x->props.aalgo as "no auth
    algorithm attached yet" and calls attach_auth(). That overwrites
    x->aalg and loses the first allocation. Any later failure or teardown
    only frees the replacement pointer.
    
    Check whether x->aalg is already attached instead of inferring that
    state from x->props.aalgo.
    
    Fixes: 4447bb33f094 ("xfrm: Store aalg in xfrm_state with a user specified truncation length")
    Cc: [email protected]
    Reported-by: Vega <[email protected]>
    Assisted-by: Codex:gpt-5.4
    Signed-off-by: Zihan Xi <[email protected]>
    Signed-off-by: Ren Wei <[email protected]>
    Signed-off-by: Steffen Klassert <[email protected]>
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

 
xhci: dbgtty: Fix unregister on tty_alloc_driver() failure [+ + +]
Author: Lucas De Marchi <[email protected]>
Date:   Thu Aug 6 17:21:04 2026 +0300

    xhci: dbgtty: Fix unregister on tty_alloc_driver() failure
    
    commit 25b8dfc13495a6c1cf4abacc8ef20196c7f20e5c upstream.
    
    Make sure to set dbc_tty_driver to NULL to match the check in
    dbc_tty_exit(). For that, make detached error handling path common to the
    other branch in the same function.
    
    Fixes: 4521f1613940 ("xhci: dbctty: split dbc tty driver registration and unregistration functions.")
    Cc: [email protected] # v5.10
    Cc: Mathias Nyman <[email protected]>
    Cc: Greg Kroah-Hartman <[email protected]>
    Signed-off-by: Lucas De Marchi <[email protected]>
    Signed-off-by: Mathias Nyman <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Greg Kroah-Hartman <[email protected]>

xhci: dbgtty: Fix unregister on tty_register_driver() failure [+ + +]
Author: Lucas De Marchi <[email protected]>
Date:   Thu Aug 6 17:21:03 2026 +0300

    xhci: dbgtty: Fix unregister on tty_register_driver() failure
    
    commit a916fa66a43e10f63198b6ce978badffc678821a upstream.
    
    If tty_register_driver() fails, it drops the reference, but fails to set
    the global dbc_tty_driver to NULL, causing the unregister to be called
    again when module exits.
    
    On module unload dbc_tty_exit() only gates its cleanup on the driver
    pointer being non-NULL, so it operates on the already-freed driver:
    
        module_init(xhci_hcd_init)
          xhci_hcd_init()
            xhci_dbc_init()                       [return value ignored]
              dbc_tty_init()
                tty_register_driver() fails
                  tty_driver_kref_put()           -> driver freed
                  (dbc_tty_driver left dangling)
        ...
        module_exit(xhci_hcd_fini)
          xhci_hcd_fini()
            xhci_dbc_exit()
              dbc_tty_exit()
                if (dbc_tty_driver)               -> true (dangling)
                  tty_unregister_driver()         -> use-after-free
    
    Fixes: 4521f1613940 ("xhci: dbctty: split dbc tty driver registration and unregistration functions.")
    Cc: [email protected] # v5.10
    Cc: Mathias Nyman <[email protected]>
    Cc: Greg Kroah-Hartman <[email protected]>
    Signed-off-by: Lucas De Marchi <[email protected]>
    Signed-off-by: Mathias Nyman <[email protected]>
    Link: https://patch.msgid.link/[email protected]
    Signed-off-by: Greg Kroah-Hartman <[email protected]>