Skip to content

[ciqlts8_6] Multiple patches tested (7 commits) - #1608

Open
ciq-kernel-automation[bot] wants to merge 7 commits into
ciqlts8_6from
{ciq_kernel_automation}_ciqlts8_6
Open

ciq-kernel-automation[bot] wants to merge 7 commits into
ciqlts8_6from
{ciq_kernel_automation}_ciqlts8_6

Conversation

@ciq-kernel-automation

Copy link
Copy Markdown

Summary

This PR has been automatically created after successful completion of all CI stages.

Commit Message(s)

can: bcm: switch timer to HRTIMER_MODE_SOFT and remove hrtimer_tasklet

jira VULN-193903
cve CVE-2026-17523
commit-author Thomas Gleixner <tglx@linutronix.de>
commit bf74aa86e111aa3b2fbb25db37e3a3fab71b5b68
Bluetooth: hci_event: fix potential UAF in SSP passkey handlers

jira VULN-186560
cve CVE-2026-46056
commit-author Shuvam Pandey <shuvampandey1@gmail.com>
commit 85fa3512048793076eef658f66489112dcc91993
Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp

jira VULN-189582
cve CVE-2026-53071
commit-author Dudu Lu <phx0fer@gmail.com>
commit 42776497cdbc9a665b384a6dcb85f0d4bd927eab
ice: fix double-free of tx_buf skb

jira VULN-189502
cve CVE-2026-53009
commit-author Michal Schmidt <mschmidt@redhat.com>
commit 1a303baa715e6b78d6a406aaf335f87ff35acfcd
upstream-diff Upstream uses `first->type = ICE_TX_BUF_EMPTY` from the
  ice_tx_buf_type enum introduced by aa1d3faf71a6 ("ice: Robustify
  cleaning/completing XDP Tx buffers"). This tree predates that refactor;
  ice_unmap_and_free_tx_buf() gates all freeing on `tx_buf->skb != NULL`,
  so the equivalent clear is `first->skb = NULL`.
ipv6: fix possible UAF in icmpv6_rcv()

jira VULN-189491
cve CVE-2026-53006
commit-author Eric Dumazet <edumazet@google.com>
commit f996edd7615e686ada141b7f3395025729ff8ccb
i2c: stub: Reject I2C block transfers with invalid length

jira VULN-192581
cve CVE-2026-64191
commit-author Weiming Shi <bestswngs@gmail.com>
commit 6036b5067a8199ba7a2dc7b377d4b9dd276d5f9e
USB: serial: io_ti: fix heap overflow in get_manuf_info()

jira VULN-189703
cve CVE-2026-53196
commit-author Adrian Korwel <adriank20047@gmail.com>
commit 183c1076eca43bbb3e7bdf597456f91d81c73e74

Test Results

✅ Build Stage

Architecture Build Time Total Time
x86_64 17m 50s 19m 0s
aarch64 9m 58s 10m 38s

✅ Boot Verification

✅ Kernel Selftests

Architecture Passed Failed Compared Against Status
x86_64 108 31 ciqlts8_6 ✅ No regressions
aarch64 66 21 ciqlts8_6 ✅ No regressions

✅ LTP Results

Architecture Passed Failed Compared Against Status
x86_64 1456 13 ciqlts8_6 ✅ No regressions
aarch64 1425 14 ciqlts8_6 ✅ No regressions

🤖 This PR was automatically generated by GitHub Actions
Run ID: 34856702243

CIQ Kernel Automation added 7 commits September 14, 2026 06:20
jira VULN-193903
cve CVE-2026-17523
commit-author Thomas Gleixner <tglx@linutronix.de>
commit bf74aa8

This patch switches the timer to HRTIMER_MODE_SOFT, which executed the
timer callback in softirq context and removes the hrtimer_tasklet.

	Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
	Signed-off-by: Anna-Maria Gleixner <anna-maria@linutronix.de>
	Acked-by: Oliver Hartkopp <socketcan@hartkopp.net>
	Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
(cherry picked from commit bf74aa8)
	Signed-off-by: CIQ Kernel Automation <ciq_kernel_automation@ciq.com>
jira VULN-186560
cve CVE-2026-46056
commit-author Shuvam Pandey <shuvampandey1@gmail.com>
commit 85fa351

hci_conn lookup and field access must be covered by hdev lock in
hci_user_passkey_notify_evt() and hci_keypress_notify_evt(), otherwise
the connection can be freed concurrently.

Extend the hci_dev_lock critical section to cover all conn usage in both
handlers.

Keep the existing keypress notification behavior unchanged by routing
the early exits through a common unlock path.

Fixes: 92a2525 ("Bluetooth: mgmt: Implement support for passkey notification")
	Cc: stable@vger.kernel.org
	Signed-off-by: Shuvam Pandey <shuvampandey1@gmail.com>
	Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
(cherry picked from commit 85fa351)
	Signed-off-by: CIQ Kernel Automation <ciq_kernel_automation@ciq.com>
jira VULN-189582
cve CVE-2026-53071
commit-author Dudu Lu <phx0fer@gmail.com>
commit 4277649

l2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding
l2cap_chan_lock(). Every other l2cap_chan_del() caller in the file
acquires the lock first. A remote BLE device can send a crafted
L2CAP ECRED reconfiguration response to corrupt the channel list
while another thread is iterating it.

Add l2cap_chan_hold() and l2cap_chan_lock() before l2cap_chan_del(),
and l2cap_chan_unlock() and l2cap_chan_put() after, matching the
pattern used in l2cap_ecred_conn_rsp() and l2cap_conn_del().

Fixes: 15f02b9 ("Bluetooth: L2CAP: Add initial code for Enhanced Credit Based Mode")
	Signed-off-by: Dudu Lu <phx0fer@gmail.com>
	Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
(cherry picked from commit 4277649)
	Signed-off-by: CIQ Kernel Automation <ciq_kernel_automation@ciq.com>
jira VULN-189502
cve CVE-2026-53009
commit-author Michal Schmidt <mschmidt@redhat.com>
commit 1a303ba
upstream-diff Upstream uses `first->type = ICE_TX_BUF_EMPTY` from the
  ice_tx_buf_type enum introduced by aa1d3fa ("ice: Robustify
  cleaning/completing XDP Tx buffers"). This tree predates that refactor;
  ice_unmap_and_free_tx_buf() gates all freeing on `tx_buf->skb != NULL`,
  so the equivalent clear is `first->skb = NULL`.

If ice_tso() or ice_tx_csum() fail, the error path in
ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points
to it and is marked as valid (ICE_TX_BUF_SKB).
'next_to_use' remains unchanged, so the potential problem will
likely fix itself when the next packet is transmitted and the tx_buf
gets overwritten. But if there is no next packet and the interface is
brought down instead, ice_clean_tx_ring() -> ice_unmap_and_free_tx_buf()
will find the tx_buf and free the skb for the second time.

The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error
path, so that ice_unmap_and_free_tx_buf().
Move the initialization of 'first' up, to ensure it's already valid in
case we hit the linearization error path.

The bug was spotted by AI while I had it looking for something else.
It also proposed an initial version of the patch.

I reproduced the bug and tested the fix by adding code to inject
failures, on a build with KASAN.

I looked for similar bugs in related Intel drivers and did not find any.

Fixes: d76a60b ("ice: Add support for VLANs and offloads")
Assisted-by: Claude:claude-4.6-opus-high Cursor
	Signed-off-by: Michal Schmidt <mschmidt@redhat.com>
	Signed-off-by: Jacob Keller <jacob.e.keller@intel.com>
Link: https://patch.msgid.link/20260416-iwl-net-submission-2026-04-14-v2-4-686c33c9828d@intel.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 1a303ba)
	Signed-off-by: CIQ Kernel Automation <ciq_kernel_automation@ciq.com>
jira VULN-189491
cve CVE-2026-53006
commit-author Eric Dumazet <edumazet@google.com>
commit f996edd

Caching saddr and daddr before pskb_pull() is problematic
since skb->head can change.

Remove these temporary variables:

- We only access &ipv6_hdr(skb)->saddr and &ipv6_hdr(skb)->daddr
  when net_dbg_ratelimited() is called in the slow path.

- Avoid potential future misuse after pskb_pull() call.

Fixes: 4b3418f ("ipv6: icmp: include addresses in debug messages")
	Signed-off-by: Eric Dumazet <edumazet@google.com>
	Reviewed-by: Fernando Fernandez Mancera <fmancera@suse.de>
	Reviewed-by: Joe Damato <joe@dama.to>
	Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260416103505.2380753-1-edumazet@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit f996edd)
	Signed-off-by: CIQ Kernel Automation <ciq_kernel_automation@ciq.com>
jira VULN-192581
cve CVE-2026-64191
commit-author Weiming Shi <bestswngs@gmail.com>
commit 6036b50

The I2C_SMBUS_I2C_BLOCK_DATA case in stub_xfer() uses data->block[0]
as the transfer length. The existing check only clamps it to avoid
overrunning the chip->words[256] register array, but does not validate
it against I2C_SMBUS_BLOCK_MAX (32), which is the limit of the union
i2c_smbus_data.block buffer (34 bytes total). The driver is a
development/test tool (CONFIG_I2C_STUB=m, not built by default)
that must be loaded with a chip_addr= parameter.

A local user with access to /dev/i2c-* can issue an I2C_SMBUS ioctl
with I2C_SMBUS_I2C_BLOCK_DATA and data->block[0] > 32, causing
stub_xfer() to read or write past the end of the union
i2c_smbus_data.block buffer:

 BUG: KASAN: stack-out-of-bounds in stub_xfer (drivers/i2c/i2c-stub.c:223)
 Read of size 1 at addr ffff88800abcfd92 by task exploit/81
 Call Trace:
  <TASK>
  stub_xfer (drivers/i2c/i2c-stub.c:223)
  __i2c_smbus_xfer (drivers/i2c/i2c-core-smbus.c:593)
  i2c_smbus_xfer (drivers/i2c/i2c-core-smbus.c:536)
  i2cdev_ioctl_smbus (drivers/i2c/i2c-dev.c:391)
  i2cdev_ioctl (drivers/i2c/i2c-dev.c:478)
  __x64_sys_ioctl (fs/ioctl.c:583)
  do_syscall_64 (arch/x86/entry/syscall_64.c:94)
  entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)
  </TASK>

The bug exists because i2c-stub implements .smbus_xfer directly,
bypassing the I2C_SMBUS_BLOCK_MAX validation in
i2c_smbus_xfer_emulated(). The I2C_SMBUS_BLOCK_DATA case in the same
function correctly validates against I2C_SMBUS_BLOCK_MAX, but the
I2C_SMBUS_I2C_BLOCK_DATA case does not.

Fix by rejecting transfers with data->block[0] == 0 or
data->block[0] > I2C_SMBUS_BLOCK_MAX with -EINVAL, consistent with
both the I2C_SMBUS_BLOCK_DATA case in the same function and the
I2C_SMBUS_I2C_BLOCK_DATA validation in i2c_smbus_xfer_emulated().

Fixes: 4710317 ("i2c-stub: Implement I2C block support")
	Reported-by: Xiang Mei <xmei5@asu.edu>
	Signed-off-by: Weiming Shi <bestswngs@gmail.com>
	Reviewed-by: Jean Delvare <jdelvare@suse.de>
	Signed-off-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
(cherry picked from commit 6036b50)
	Signed-off-by: CIQ Kernel Automation <ciq_kernel_automation@ciq.com>
jira VULN-189703
cve CVE-2026-53196
commit-author Adrian Korwel <adriank20047@gmail.com>
commit 183c107

get_manuf_info() reads le16_to_cpu(rom_desc->Size) bytes from the
device I2C EEPROM into a buffer allocated with kmalloc_obj(), which
is sizeof(struct edge_ti_manuf_descriptor) = 10 bytes.

The Size field comes from the device and is only validated (in
check_i2c_image()) to make sure the descriptor fits within
TI_MAX_I2C_SIZE (16384 bytes), not against the destination buffer size.
A malicious USB device can therefore set Size to any value up to 16377,
causing a heap overflow of up to 16367 bytes when plugged into a host
running this driver.

valid_csum() is called after read_rom() and also iterates
buffer[0..Size-1], compounding the out-of-bounds access.

Fix by rejecting descriptors with unexpected length before calling
read_rom().

Fixes: 1da177e ("Linux-2.6.12-rc2")
	Cc: stable@vger.kernel.org
	Signed-off-by: Adrian Korwel <adriank20047@gmail.com>
[ johan: amend commit message; also check for short descriptors ]
	Signed-off-by: Johan Hovold <johan@kernel.org>
(cherry picked from commit 183c107)
	Signed-off-by: CIQ Kernel Automation <ciq_kernel_automation@ciq.com>
@ciq-kernel-automation ciq-kernel-automation Bot added the created-by-kernelci Tag PRs that were automatically created when a user branch was pushed to the repo (kernelCI) label Sep 14, 2026
@github-actions

Copy link
Copy Markdown

🤖 Validation Checks In Progress Workflow run: https://github.com/ctrliq/kernel-src-tree/actions/runs/34882790808

@github-actions

Copy link
Copy Markdown

🔍 Interdiff Analysis

  • ⚠️ PR commit fb73e5552265 (can: bcm: switch timer to HRTIMER_MODE_SOFT and remove hrtimer_tasklet) → upstream bf74aa86e111
    Differences found:
================================================================================
*    CONTEXT DIFFERENCES - surrounding code differences between the patches    *
================================================================================

--- b/net/can/bcm.c
+++ b/net/can/bcm.c
@@ -539,3 +557,2 @@
 	/* create notification to user */
-	memset(&msg_head, 0, sizeof(msg_head));
 	msg_head.opcode  = RX_TIMEOUT;
  • ⚠️ PR commit 78d558b8e12e (Bluetooth: hci_event: fix potential UAF in SSP passkey handlers) → upstream 85fa35120487
    Differences found:
################################################################################
!    REJECTED PATCH2 HUNKS - could not be compared; manual review needed       !
################################################################################

--- b/net/bluetooth/hci_event.c
+++ b/net/bluetooth/hci_event.c
@@ -5521,6 +5526,8 @@
 
 	bt_dev_dbg(hdev, "");
 
+	hci_dev_lock(hdev);
+
 	conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
 	if (!conn)
 		return;
@@ -5523,7 +5530,7 @@
 
 	conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
 	if (!conn)
-		return;
+		goto unlock;
 
 	switch (ev->type) {
 	case HCI_KEYPRESS_STARTED:
@@ -5527,7 +5534,7 @@
 	switch (ev->type) {
 	case HCI_KEYPRESS_STARTED:
 		conn->passkey_entered = 0;
-		return;
+		goto unlock;
 
 	case HCI_KEYPRESS_ENTERED:
 		conn->passkey_entered++;
@@ -5543,7 +5550,7 @@
 		break;
 
 	case HCI_KEYPRESS_COMPLETED:
-		return;
+		goto unlock;
 	}
 
 	if (hci_dev_test_flag(hdev, HCI_MGMT))
@@ -5547,6 +5554,9 @@
 		mgmt_user_passkey_notify(hdev, &conn->dst, conn->type,
 					 conn->dst_type, conn->passkey_notify,
 					 conn->passkey_entered);
+
+unlock:
+	hci_dev_unlock(hdev);
 }
 
 static void hci_simple_pair_complete_evt(struct hci_dev *hdev, void *data,

================================================================================
*    CONTEXT DIFFERENCES - surrounding code differences between the patches    *
================================================================================

--- b/net/bluetooth/hci_event.c
+++ b/net/bluetooth/hci_event.c
@@ -4835,5 +4835,5 @@
 
-	BT_DBG("%s", hdev->name);
+	bt_dev_dbg(hdev, "");
 
 	conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
 	if (!conn)
@@ -4851,4 +5508,4 @@
 					 conn->passkey_entered);
 }
 
-static void hci_keypress_notify_evt(struct hci_dev *hdev, struct sk_buff *skb)
+static void hci_keypress_notify_evt(struct hci_dev *hdev, void *data,
@@ -4855,5 +5512,5 @@
 
-	BT_DBG("%s", hdev->name);
+	bt_dev_dbg(hdev, "");
 
 	conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
 	if (!conn)
@@ -4889,4 +5547,4 @@
 					 conn->passkey_entered);
 }
 
-static void hci_simple_pair_complete_evt(struct hci_dev *hdev,
+static void hci_simple_pair_complete_evt(struct hci_dev *hdev, void *data,
  • ⚠️ PR commit 788d75dc9364 (ice: fix double-free of tx_buf skb) → upstream 1a303baa715e
    Differences found:
================================================================================
*    DELTA DIFFERENCES - code changes that differ between the patches          *
================================================================================

--- b/drivers/net/ethernet/intel/ice/ice_txrx.c
+++ b/drivers/net/ethernet/intel/ice/ice_txrx.c
@@ -2355,7 +2355,7 @@
 out_drop:
 	ice_trace(xmit_frame_ring_drop, tx_ring, skb);
 	dev_kfree_skb_any(skb);
-	first->skb = NULL;
+	first->type = ICE_TX_BUF_EMPTY;
 	return NETDEV_TX_OK;
 }
 

================================================================================
*    CONTEXT DIFFERENCES - surrounding code differences between the patches    *
================================================================================

--- b/drivers/net/ethernet/intel/ice/ice_txrx.c
+++ b/drivers/net/ethernet/intel/ice/ice_txrx.c
@@ -2296,2 +2188,3 @@
 	first->skb = skb;
+	first->type = ICE_TX_BUF_SKB;
 	first->bytecount = max_t(unsigned int, skb->len, ETH_ZLEN);
  • ⚠️ PR commit 1064abc11089 (ipv6: fix possible UAF in icmpv6_rcv()) → upstream f996edd7615e
    Differences found:
================================================================================
*    CONTEXT DIFFERENCES - surrounding code differences between the patches    *
================================================================================

--- b/net/ipv6/icmp.c
+++ b/net/ipv6/icmp.c
@@ -810,5 +812,5 @@
 	struct inet6_dev *idev = __in6_dev_get(dev);
 	const struct in6_addr *saddr, *daddr;
 	struct icmp6hdr *hdr;
 	u8 type;
-	bool success = false;
+
@@ -838,5 +1133,5 @@
 
-	__ICMP6_INC_STATS(dev_net(dev), idev, ICMP6_MIB_INMSGS);
+	__ICMP6_INC_STATS(dev_net_rcu(dev), idev, ICMP6_MIB_INMSGS);
 
 	saddr = &ipv6_hdr(skb)->saddr;
 	daddr = &ipv6_hdr(skb)->daddr;

This is an automated interdiff check for backported commits.

@github-actions

Copy link
Copy Markdown

Validation checks completed successfully View full results: https://github.com/ctrliq/kernel-src-tree/actions/runs/34882790808

@bmastbergen
bmastbergen requested a review from a team September 15, 2026 13:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

created-by-kernelci Tag PRs that were automatically created when a user branch was pushed to the repo (kernelCI)

Development

Successfully merging this pull request may close these issues.

0 participants