Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
76 commits
Select commit Hold shift + click to select a range
eb1bf0e
RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
Jul 12, 2026
6d124fb
RDMA/rxe: Fix OOB in free_rd_atomic_resources()
BaldDemian Jul 30, 2026
a3894b5
KVM: x86/mmu: Check write tracking in all address spaces
0range1337 Jul 21, 2026
5641a80
nvme-tcp: fix usage of page_frag_cache
logost Aug 27, 2026
d75081e
ASoC: nau8821: Cancel delayed work on component remove
cristicc Dec 31, 2025
9985ba7
bpf: Fix use-after-free in offloaded map/prog info fill
mrpre Apr 9, 2026
74dd8bc
riscv: Fix register corruption from uninitialized cregs on error
mikey May 1, 2026
f1cb4c4
ASoC: nau8821: Cancel pending work before suspend
cristicc Dec 31, 2025
ecb393d
selinux: switch two allocations to use kzalloc_objs()
stephensmalley Apr 29, 2026
2574a76
veth: fix OOB txq access in veth_poll() with asymmetric queue counts
netoptimizer May 5, 2026
b434cde
powerpc/hv-gpci: fix preempt count leak in sysfs show paths
AboorvaDevarajan May 8, 2026
77b60fe
io_uring/futex: only mark private futex waits as inflight
axboe Jul 30, 2026
3a4493b
io_uring: simplify IORING_SETUP_DEFER_TASKRUN && !SQPOLL check
calebsander Aug 25, 2026
bf1054e
io_uring/rsrc: improve regbuf iov validation
isilence Aug 25, 2026
f86a30c
io_uring: defer eventfd signaling when queued from a wakeup handler
axboe Aug 25, 2026
23474ec
HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
montfort Aug 26, 2026
25b3861
HID: asus: simplify RGB init sequence
antheas Aug 26, 2026
12899f7
HID: asus: fix missing hid_is_usb() check
thejh Aug 26, 2026
1b29fc4
HID: ft260: validate i2c input report length
MichaelZaidman Aug 26, 2026
5e1bbc9
HID: ft260: fix stack-use-after-return write in I2C read race
Aug 26, 2026
d5c8767
ksmbd: harden file lifetime during session teardown
charsyam Apr 28, 2026
aab12f6
fpga: dfl: fme: add error handling
griffinkh Jul 6, 2026
d4f8356
accessibility: speakup: unregister tty ldisc on later init failures
May 31, 2026
62203d8
usb: xhci: Handle bogus TRB pointers in Missed Service Error events
Aug 6, 2026
3248247
usb: xhci: Handle USB3 port events when there is one roothub
strrs Aug 6, 2026
36c3d91
xhci: dbgtty: Fix unregister on tty_register_driver() failure
lucasdemarchi Aug 6, 2026
fd2d2e7
xhci: dbgtty: Fix unregister on tty_alloc_driver() failure
lucasdemarchi Aug 6, 2026
4df88be
fuse: fix invalidate lock leak on setattr writeback failure
LiBaokun96 Aug 17, 2026
dc3d892
fuse: fix invalidate lock leak on open O_TRUNC DAX failure
LiBaokun96 Aug 17, 2026
9eab59e
usb: usbtest: disable dynamic ID support
a-nogikh Aug 6, 2026
eb820ae
usb: gadget: f_tcm: keep port count until LUN teardown completes
shuangpeng-kernel Aug 7, 2026
48e1669
KVM: SEV: Drop FOLL_WRITE for encrypted region registration
pagupta Jul 15, 2026
c86107f
KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests
sean-jc Jul 9, 2026
78711cb
KVM: SEV: Extract loading of guest-provided VMSA to a separate helper
sean-jc Jul 9, 2026
7cbfb9d
KVM: SEV: Mark vCPU RUNNABLE after AP_CREATE, even if VMSA is unusable
sean-jc Jul 9, 2026
7599121
KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if CONFIG_KVM_AM…
sean-jc Jul 9, 2026
bd45ab4
tls: device: fix out-of-bounds write in tls_append_frag()
mrpre Aug 23, 2026
e7c9e50
gtp: serialize PDP context updates
Aug 18, 2026
2cb309e
x86/CPU/AMD: Carve out a Zen5 models range
amd-pvishwak Jul 29, 2026
c585c33
net/tcp: fix TCP-AO key deletion in VRFs
rastislavs Aug 22, 2026
7609bbb
tcp: fix AO info use-after-free in tcp_ao_connect_init()
Aug 25, 2026
f3816ec
net/tcp-ao: fix use-after-free of current_key on reconnect to another…
V4bel Aug 16, 2026
c0c529f
xfrm: espintcp: fix UAF during close
qsn Jul 16, 2026
75293a5
xfrm: drop ESP-in-TCP packets with no ingress device
rr00xxyy Jul 18, 2026
0e1f8e9
xfrm: avoid lock inversion in nat keepalive work
Jul 21, 2026
154b327
xfrm: ah6: validate routing header segments_left
manizada Jul 23, 2026
c386492
xfrm: fix xfrm_state_construct() auth-trunc leak
Jul 27, 2026
85b2fe1
xfrm: bound nat keepalive state collection
Aug 17, 2026
95e856f
net: bridge: mcast: fix use-after-free of a master VLAN's multicast c…
nszetei Aug 26, 2026
ae8d197
ipv6: seg6: clear IPv4 control block on IPIP decapsulation
kylebot-oai Aug 17, 2026
9174215
batman-adv: reject unrepresentable multicast TVLV offsets
kylebot-oai Aug 17, 2026
42d8aa8
vxlan: keep the last remote linked during FDB flush
kylebot-oai Aug 10, 2026
93e4d78
netfilter: nft_set_pipapo_avx2: add missing vzeroupper
Aug 15, 2026
752a323
netfilter: nf_tables: don't queue packet path object notifications
corvusaisec Aug 10, 2026
7458ba0
mm/swap: reject swapon() on filesystem-level encrypted files
Aug 3, 2026
16b3409
kunit: irq: Continue increasing hrtimer interval for longer
Aug 3, 2026
86f3ad8
crypto: virtio - bound the akcipher result length
bryamzxz Jun 22, 2026
1ee4d66
crypto: qcom-rng - Enable clock in hwrng case
Jun 8, 2026
7ce1ac0
crypto: qcom-rng - Remove crypto_rng interface
Jun 8, 2026
c83eb47
crypto: qcom-rng - Allow zero as a random number
Jun 8, 2026
390c375
crypto: atmel-tdes - use scatterlist length before DMA mapping
toblux Jun 11, 2026
243cf49
crypto: krb5 - use kfree_sensitive() for derived key buffers
Aug 3, 2026
e4fc670
crypto: qce - fix CCM AAD buffer underallocation
mdalam-qcom Aug 7, 2026
e8840af
crypto: mxs-dcp - fix source scatterlist length access
toblux Jun 21, 2026
6e9ddb1
crypto: qce - Remove unsafe/deprecated algorithms
brgl Jun 22, 2026
4b21e95
KVM: s390: vsie: zero stale crypto bits
borntraeger Aug 11, 2026
8868c92
usb: core: Add lock to usb_wakeup_notification()
griffinkh Jul 13, 2026
8ea9ac5
usb: core: Strengthen error handling in hub_hub_status()
griffinkh Jul 22, 2026
0729171
ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
Espilon-Org Aug 23, 2026
6d31841
ALSA: usb-audio: Complete cleanup after system-resume errors
willyp713 Aug 24, 2026
3fe8ace
USB: serial: option: fix slab OOB read in interrupt URB callback
Jul 25, 2026
af2fb58
USB: serial: spcp8x5: drop broken carrier detect support
jhovold Aug 6, 2026
5aacf3e
USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
shuangpeng-kernel Aug 6, 2026
d0f4724
wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb
Lucid-Duck Jul 15, 2026
524095c
usb: usbfs: fix use-after-free of usb_device in usbdev_release()
mzereza Aug 10, 2026
9ada2c2
Linux 6.18.49
gregkh Sep 2, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions Documentation/filesystems/fscrypt.rst
Original file line number Diff line number Diff line change
Expand Up @@ -1245,6 +1245,10 @@ astute users may notice some differences in behavior:

- DAX (Direct Access) is not supported on encrypted files.

- Encrypted files cannot be used directly as swap files. To swap to
an encrypted file, set up a loopback device on top of it.
Alternatively, encrypted swap can use a dm-crypt device.

- The maximum length of an encrypted symlink is 2 bytes shorter than
the maximum length of an unencrypted symlink. For example, on an
EXT4 filesystem with a 4K block size, unencrypted symlinks can be up
Expand Down
2 changes: 1 addition & 1 deletion Makefile
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# SPDX-License-Identifier: GPL-2.0
VERSION = 6
PATCHLEVEL = 18
SUBLEVEL = 48
SUBLEVEL = 49
EXTRAVERSION =
NAME = Baby Opossum Posse

Expand Down
24 changes: 16 additions & 8 deletions arch/powerpc/perf/hv-gpci.c
Original file line number Diff line number Diff line change
Expand Up @@ -210,7 +210,7 @@ static ssize_t processor_bus_topology_show(struct device *dev, struct device_att
0, 0, buf, &n, arg);

if (!ret)
return n;
goto out_success;

if (ret != H_PARAMETER)
goto out;
Expand Down Expand Up @@ -244,12 +244,14 @@ static ssize_t processor_bus_topology_show(struct device *dev, struct device_att
starting_index, 0, buf, &n, arg);

if (!ret)
return n;
goto out_success;

if (ret != H_PARAMETER)
goto out;
}

out_success:
put_cpu_var(hv_gpci_reqb);
return n;

out:
Expand Down Expand Up @@ -278,7 +280,7 @@ static ssize_t processor_config_show(struct device *dev, struct device_attribute
0, 0, buf, &n, arg);

if (!ret)
return n;
goto out_success;

if (ret != H_PARAMETER)
goto out;
Expand Down Expand Up @@ -312,12 +314,14 @@ static ssize_t processor_config_show(struct device *dev, struct device_attribute
starting_index, 0, buf, &n, arg);

if (!ret)
return n;
goto out_success;

if (ret != H_PARAMETER)
goto out;
}

out_success:
put_cpu_var(hv_gpci_reqb);
return n;

out:
Expand Down Expand Up @@ -346,7 +350,7 @@ static ssize_t affinity_domain_via_virtual_processor_show(struct device *dev,
0, 0, buf, &n, arg);

if (!ret)
return n;
goto out_success;

if (ret != H_PARAMETER)
goto out;
Expand Down Expand Up @@ -382,12 +386,14 @@ static ssize_t affinity_domain_via_virtual_processor_show(struct device *dev,
starting_index, secondary_index, buf, &n, arg);

if (!ret)
return n;
goto out_success;

if (ret != H_PARAMETER)
goto out;
}

out_success:
put_cpu_var(hv_gpci_reqb);
return n;

out:
Expand Down Expand Up @@ -416,7 +422,7 @@ static ssize_t affinity_domain_via_domain_show(struct device *dev, struct device
0, 0, buf, &n, arg);

if (!ret)
return n;
goto out_success;

if (ret != H_PARAMETER)
goto out;
Expand Down Expand Up @@ -448,12 +454,14 @@ static ssize_t affinity_domain_via_domain_show(struct device *dev, struct device
starting_index, 0, buf, &n, arg);

if (!ret)
return n;
goto out_success;

if (ret != H_PARAMETER)
goto out;
}

out_success:
put_cpu_var(hv_gpci_reqb);
return n;

out:
Expand Down
2 changes: 2 additions & 0 deletions arch/riscv/kernel/compat_signal.c
Original file line number Diff line number Diff line change
Expand Up @@ -107,6 +107,8 @@ static long compat_restore_sigcontext(struct pt_regs *regs,

/* sc_regs is structured the same as the start of pt_regs */
err = __copy_from_user(&cregs, &sc->sc_regs, sizeof(sc->sc_regs));
if (unlikely(err))
return err;

cregs_to_regs(&cregs, regs);

Expand Down
4 changes: 2 additions & 2 deletions arch/riscv/kernel/ptrace.c
Original file line number Diff line number Diff line change
Expand Up @@ -372,8 +372,8 @@ static int compat_riscv_gpr_set(struct task_struct *target,
struct compat_user_regs_struct cregs;

ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &cregs, 0, -1);

cregs_to_regs(&cregs, task_pt_regs(target));
if (!ret)
cregs_to_regs(&cregs, task_pt_regs(target));

return ret;
}
Expand Down
1 change: 1 addition & 0 deletions arch/s390/kvm/vsie.c
Original file line number Diff line number Diff line change
Expand Up @@ -184,6 +184,7 @@ static int setup_apcb10(struct kvm_vcpu *vcpu, struct kvm_s390_apcb1 *apcb_s,
sizeof(struct kvm_s390_apcb0)))
return -EFAULT;

memset(apcb_s, 0, sizeof(*apcb_s));
apcb_s->apm[0] = apcb_h->apm[0] & tmp.apm[0];
apcb_s->aqm[0] = apcb_h->aqm[0] & tmp.aqm[0] & 0xffff000000000000UL;
apcb_s->adm[0] = apcb_h->adm[0] & tmp.adm[0] & 0xffff000000000000UL;
Expand Down
4 changes: 3 additions & 1 deletion arch/x86/kernel/cpu/amd.c
Original file line number Diff line number Diff line change
Expand Up @@ -514,11 +514,13 @@ static void bsp_init_amd(struct cpuinfo_x86 *c)
case 0x00 ... 0x2f:
case 0x40 ... 0x4f:
case 0x60 ... 0x7f:
case 0xd0 ... 0xd7:
setup_force_cpu_cap(X86_FEATURE_ZEN5);
break;
case 0x50 ... 0x5f:
case 0x80 ... 0xaf:
case 0xc0 ... 0xef:
case 0xc0 ... 0xcf:
case 0xd8 ... 0xef:
setup_force_cpu_cap(X86_FEATURE_ZEN6);
break;
default:
Expand Down
32 changes: 26 additions & 6 deletions arch/x86/kvm/mmu/page_track.c
Original file line number Diff line number Diff line change
Expand Up @@ -130,22 +130,42 @@ void __kvm_write_track_remove_gfn(struct kvm *kvm,
kvm_mmu_gfn_allow_lpage(slot, gfn);
}

/*
* check if the corresponding access on the specified guest page is tracked.
*/
static bool __kvm_gfn_is_write_tracked(const struct kvm_memory_slot *slot,
gfn_t gfn)
{
int index;

if (!slot)
return false;

index = gfn_to_index(gfn, slot->base_gfn, PG_LEVEL_4K);
return !!READ_ONCE(slot->arch.gfn_write_track[index]);
}

/* check if write access is tracked on the specified guest page. */
bool kvm_gfn_is_write_tracked(struct kvm *kvm,
const struct kvm_memory_slot *slot, gfn_t gfn)
{
int index;
const struct kvm_memory_slot *other_slot;

if (!slot)
return false;

if (!kvm_page_track_write_tracking_enabled(kvm))
return false;

index = gfn_to_index(gfn, slot->base_gfn, PG_LEVEL_4K);
return !!READ_ONCE(slot->arch.gfn_write_track[index]);
BUILD_BUG_ON(KVM_MAX_NR_ADDRESS_SPACES > 2);

if (__kvm_gfn_is_write_tracked(slot, gfn))
return true;

if (kvm_arch_nr_memslot_as_ids(kvm) > 1) {
other_slot = __gfn_to_memslot(__kvm_memslots(kvm, slot->as_id ^ 1), gfn);
if (__kvm_gfn_is_write_tracked(other_slot, gfn))
return true;
}

return false;
}

#ifdef CONFIG_KVM_EXTERNAL_WRITE_TRACKING
Expand Down
76 changes: 50 additions & 26 deletions arch/x86/kvm/svm/sev.c
Original file line number Diff line number Diff line change
Expand Up @@ -2844,8 +2844,12 @@ int sev_mem_enc_register_region(struct kvm *kvm,
if (!region)
return -ENOMEM;

/*
* Do NOT specify FOLL_WRITE, as KVM isn't using the pinned pages to
* write memory, and FOLL_LONGTERM itself triggers CoW unshare.
*/
region->pages = sev_pin_memory(kvm, range->addr, range->size, &region->npages,
FOLL_WRITE | FOLL_LONGTERM);
FOLL_LONGTERM);
if (IS_ERR(region->pages)) {
ret = PTR_ERR(region->pages);
goto e_free;
Expand Down Expand Up @@ -4199,43 +4203,29 @@ static int snp_begin_psc(struct vcpu_svm *svm)
BUG();
}

/*
* Invoked as part of svm_vcpu_reset() processing of an init event.
*/
static void sev_snp_init_protected_guest_state(struct kvm_vcpu *vcpu)
static void sev_snp_reload_vmsa(struct kvm_vcpu *vcpu, gpa_t gpa)
{
struct vcpu_svm *svm = to_svm(vcpu);
struct kvm_memory_slot *slot;
gfn_t gfn = gpa_to_gfn(gpa);
struct page *page;
kvm_pfn_t pfn;
gfn_t gfn;

guard(mutex)(&svm->sev_es.snp_vmsa_mutex);

if (!svm->sev_es.snp_ap_waiting_for_reset)
return;

svm->sev_es.snp_ap_waiting_for_reset = false;

/* Mark the vCPU as offline and not runnable */
vcpu->arch.pv.pv_unhalted = false;
kvm_set_mp_state(vcpu, KVM_MP_STATE_HALTED);
lockdep_assert_held(&svm->sev_es.snp_vmsa_mutex);

/* Clear use of the VMSA */
/* Clear use of the VMSA. */
svm->vmcb->control.vmsa_pa = INVALID_PAGE;
svm->sev_es.snp_guest_vmsa_gpa = INVALID_PAGE;

/*
* When replacing the VMSA during SEV-SNP AP creation,
* mark the VMCB dirty so that full state is always reloaded.
*/
vmcb_mark_all_dirty(svm->vmcb);

if (!VALID_PAGE(svm->sev_es.snp_vmsa_gpa))
if (!VALID_PAGE(gpa))
return;

gfn = gpa_to_gfn(svm->sev_es.snp_vmsa_gpa);
svm->sev_es.snp_vmsa_gpa = INVALID_PAGE;

slot = gfn_to_memslot(vcpu->kvm, gfn);
if (!slot)
return;
Expand All @@ -4259,11 +4249,9 @@ static void sev_snp_init_protected_guest_state(struct kvm_vcpu *vcpu)
svm->sev_es.snp_has_guest_vmsa = true;

/* Use the new VMSA */
svm->sev_es.snp_guest_vmsa_gpa = gpa;
svm->vmcb->control.vmsa_pa = pfn_to_hpa(pfn);

/* Mark the vCPU as runnable */
kvm_set_mp_state(vcpu, KVM_MP_STATE_RUNNABLE);

/*
* gmem pages aren't currently migratable, but if this ever changes
* then care should be taken to ensure svm->sev_es.vmsa is pinned
Expand All @@ -4272,6 +4260,40 @@ static void sev_snp_init_protected_guest_state(struct kvm_vcpu *vcpu)
kvm_release_page_clean(page);
}

/*
* Invoked as part of svm_vcpu_reset() processing of an init event.
*/
static void sev_snp_init_protected_guest_state(struct kvm_vcpu *vcpu)
{
struct vcpu_svm *svm = to_svm(vcpu);
gpa_t gpa;

guard(mutex)(&svm->sev_es.snp_vmsa_mutex);

if (!svm->sev_es.snp_ap_waiting_for_reset)
return;

svm->sev_es.snp_ap_waiting_for_reset = false;

/* Mark the vCPU as offline and not runnable */
vcpu->arch.pv.pv_unhalted = false;
kvm_set_mp_state(vcpu, KVM_MP_STATE_HALTED);

gpa = svm->sev_es.snp_pending_vmsa_gpa;
svm->sev_es.snp_pending_vmsa_gpa = INVALID_PAGE;

sev_snp_reload_vmsa(vcpu, gpa);

/*
* Mark the vCPU as runnable for CREATE requests, indicated by a valid
* VMSA GPA, even if installing the VMSA failed, so that KVM_RUN will
* fail instead of blocking indefinitely and hanging the vCPU, e.g. if
* the backing guest_memfd page is unavailable.
*/
if (VALID_PAGE(gpa))
kvm_set_mp_state(vcpu, KVM_MP_STATE_RUNNABLE);
}

static int sev_snp_ap_creation(struct vcpu_svm *svm)
{
struct kvm_sev_info *sev = to_kvm_sev_info(svm->vcpu.kvm);
Expand Down Expand Up @@ -4325,10 +4347,10 @@ static int sev_snp_ap_creation(struct vcpu_svm *svm)
return -EINVAL;
}

target_svm->sev_es.snp_vmsa_gpa = svm->vmcb->control.exit_info_2;
target_svm->sev_es.snp_pending_vmsa_gpa = svm->vmcb->control.exit_info_2;
break;
case SVM_VMGEXIT_AP_DESTROY:
target_svm->sev_es.snp_vmsa_gpa = INVALID_PAGE;
target_svm->sev_es.snp_pending_vmsa_gpa = INVALID_PAGE;
break;
default:
vcpu_unimpl(vcpu, "vmgexit: invalid AP creation request [%#x] from guest\n",
Expand Down Expand Up @@ -4922,6 +4944,8 @@ int sev_vcpu_create(struct kvm_vcpu *vcpu)
}

svm->sev_es.vmsa = page_address(vmsa_page);
svm->sev_es.snp_pending_vmsa_gpa = INVALID_PAGE;
svm->sev_es.snp_guest_vmsa_gpa = INVALID_PAGE;

vcpu->arch.guest_tsc_protected = snp_is_secure_tsc_enabled(vcpu->kvm);

Expand Down
8 changes: 4 additions & 4 deletions arch/x86/kvm/svm/svm.c
Original file line number Diff line number Diff line change
Expand Up @@ -5301,6 +5301,10 @@ struct kvm_x86_ops svm_x86_ops __initdata = {

.vm_copy_enc_context_from = sev_vm_copy_enc_context_from,
.vm_move_enc_context_from = sev_vm_move_enc_context_from,

.gmem_prepare = sev_gmem_prepare,
.gmem_invalidate = sev_gmem_invalidate,
.gmem_max_mapping_level = sev_gmem_max_mapping_level,
#endif
.check_emulate_instruction = svm_check_emulate_instruction,

Expand All @@ -5312,10 +5316,6 @@ struct kvm_x86_ops svm_x86_ops __initdata = {
.vcpu_deliver_sipi_vector = svm_vcpu_deliver_sipi_vector,
.vcpu_get_apicv_inhibit_reasons = avic_vcpu_get_apicv_inhibit_reasons,
.alloc_apic_backing_page = svm_alloc_apic_backing_page,

.gmem_prepare = sev_gmem_prepare,
.gmem_invalidate = sev_gmem_invalidate,
.gmem_max_mapping_level = sev_gmem_max_mapping_level,
};

/*
Expand Down
Loading
Loading