7.1.3-xanmod1
Fixed 20
- apparmor: advertise the tcp fast open fix is applied
- net/tcp-ao: fix use-after-free of key in del_async path
- ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
- NFS: Prevent resource leak in nfs_alloc_server()
- NFSv4: clear exception state on successful mkdir retry
- NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
- NFSv4/flexfiles: reject zero filehandle version count
- nfsd: reset write verifier on deferred writeback errors
- nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
- nfsd: fix dead ACL conflict guard in nfsd4_create
- nfsd: check get_user() return when reading princhashlen
- nfsd: fix posix_acl leak and ignored error in nfsd4_create_file
- nfsd: fix inverted cp_ttl check in async copy reaper
- nfsd: fix posix_acl leak on SETACL decode failure
- NFSD: Fix SECINFO_NO_NAME decode error cleanup
- nfsd: release layout stid on setlease failure
- i2c: core: fix adapter registration race
- fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
- fbdev: modedb: fix a possible UAF in fb_find_mode()
- fbdev: omap2: fix use-after-free in omapfb_mmap
- ece066880fc5 Linux 7.1.3-xanmod1
- 2ddd8fb98217 Merge tag 'v7.1.3' into 7.1
- 199c9959d3a9 Linux 7.1.3
- 5b872b77bd35 apparmor: advertise the tcp fast open fix is applied
- 7ddc29a094d9 net/tcp-ao: fix use-after-free of key in del_async path
- e36e35660adb ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
- 65b1bb5d24e5 NFS: Prevent resource leak in nfs_alloc_server()
- a2c8befd06a4 NFSv4: clear exception state on successful mkdir retry
- 30aae62e50b4 NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
- 2131ed64b767 NFSv4/flexfiles: reject zero filehandle version count
- b027cca33c97 nfsd: reset write verifier on deferred writeback errors
- a10bf67fe064 nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
- 8371cc5c0a2c nfsd: fix dead ACL conflict guard in nfsd4_create
- ff3ecd17db74 nfsd: check get_user() return when reading princhashlen
- 18cf006a08ba nfsd: fix posix_acl leak and ignored error in nfsd4_create_file
- 80866c84137e nfsd: fix inverted cp_ttl check in async copy reaper
- a5b42c1e4ff2 nfsd: fix posix_acl leak on SETACL decode failure
- 46eb17d45be6 NFSD: Fix SECINFO_NO_NAME decode error cleanup
- 83c2b7797742 nfsd: release layout stid on setlease failure
- a4c8094bbf4c i2c: core: fix adapter registration race
- 7e58653d4352 fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
- 13b6f0cdd5cd fbdev: modedb: fix a possible UAF in fb_find_mode()
- 6eb6ebcc8590 fbdev: omap2: fix use-after-free in omapfb_mmap
- 39815715cbcf fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
- 88913059c77e fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
- acd744019460 ntfs: serialize volume label accesses
- 7f7a9d6cb0ed riscv: kfence: Call mark_new_valid_map() for kfence_unprotect()
- d6d6051fd15a riscv: mm: Extract helper mark_new_valid_map()
- d109e72f3fbc power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()
- 2753a097d1fe KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
- f636cf6a1e7b KVM: x86: hyper-v: Bound the bank index when querying sparse banks
- 9fef09df42df MIPS: smp: report dying CPU to RCU in stop_this_cpu()
- a7656d368265 9p: avoid putting oldfid in p9_client_walk() error path
- 99c21e726324 ocfs2: reject oversized group bitmap descriptors
- ff268cd9ccbc rpmsg: char: Fix use-after-free on probe error path
- 5e098e40e8ba fpga: region: fix use-after-free in child_regions_with_firmware()
- 0405a65e4ebd irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove
- 8d32856fb72b sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path
- 9645aaf689af pNFS: Fix use-after-free in pnfs_update_layout()
- 0833b2b84c2f LoongArch: Report dying CPU to RCU in stop_this_cpu()
- 1eea5e1820a2 tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
- afebe44facc4 blk-cgroup: fix UAF in __blkcg_rstat_flush()
- a594debfd4e7 hdlc_ppp: sync per-proto timers before freeing hdlc state
- 73569a44fca2 pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()
- 9d0d5ba20cad gfs2: fix use-after-free in gfs2_qd_dealloc
- 833033e6e55a crypto: nx - fix nx_crypto_ctx_exit argument
- 5c87b4737468 KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()
- b2ae3245ea44 KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
- 708b97e79294 exfat: fix potential use-after-free in exfat_find_dir_entry()
- 07c245bc39f9 MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
- 70df4de46577 bpf: use kvfree() for replaced sysctl write buffer
- 717f721eb67d block: Avoid mounting the bdev pseudo-filesystem in userspace
- a92332f32a8d f2fs: read COW data with the original inode during atomic write
- d52dbbcad61d f2fs: keep atomic write retry from zeroing original data
- edf12cbeeeab f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
- 6e035dae4415 Revert "f2fs: remove non-uptodate folio from the page cache in move_data_block"
- 5d8a39649947 f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
- 16bc237ce3c4 f2fs: bound i_inline_xattr_size for non-inline-xattr inodes
- 536c7e7482e0 f2fs: fix to round down start offset of fallocate for pin file
- a805fec35c20 f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
- 0969926d987b f2fs: validate compress cache inode only when enabled
- 2e12381d4495 f2fs: validate orphan inode entry count
- 0cc21c1ffe15 f2fs: fix to do sanity check on f2fs_get_node_folio_ra()
- f5b8b3dd6e85 f2fs: reject setattr size changes on large folio files
- 8a2d8a34ef0b f2fs: pass correct iostat type for single node writes
- 48c92559e7b6 f2fs: fix missing read bio submission on large folio error
- fe7f339f63c9 wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
- 9579781cd16d wifi: iwlwifi: mld: fix race condition in PTP removal
- 032e49805099 wifi: iwlwifi: mvm: fix race condition in PTP removal
- 8206d173d18e wifi: rtw88: usb: fix memory leaks on USB write failures
- a68c04f4ee6a wifi: rtw88: increase TX report timeout to fix race condition
- 2a42951e935f wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor
- 4b75e6180f46 wifi: rtl8xxxu: Detect the maximum supported channel width
- 051f954b9447 wifi: ath11k: fix warning when unbinding
- 84139c1ab368 wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer
- f10e6d5a35c4 wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S
- 5db89515fc28 userfaultfd: build __VMA_UFFD_FLAGS from config-gated masks
- 19ad7bfbd7f8 userfaultfd: ensure mremap_userfaultfd_fail() releases mmap_changing
- 83c0a1cb296d keys: Pin request_key_auth payload in instantiate paths
- 670fc6a311ed KEYS: fix overflow in keyctl_pkey_params_get_2()
- 5b959c1dbb45 gcov: use atomic counter updates to fix concurrent access crashes
- 450ee7ff510a err.h: use __always_inline on all error pointer helpers
- 8ead17358119 KVM: arm64: Omit tag sync on stage-2 mappings of the zero page
- dcb7416212e6 block: invalidate cached plug timestamp after task switch
- 77bba61a20f1 kernel/fork: clear PF_BLOCK_TS in copy_process()
- 43e40c7a7b26 fscrypt: Fix key setup in edge case with multiple data unit sizes
- 70f1e000b88c fbdev: fix use-after-free in store_modes()
- 9764a786ba98 NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR
- 5e34fa9f6f7c apparmor: fix use-after-free in rawdata dedup loop
- 45ebb934ea50 apparmor: mediate the implicit connect of TCP fast open sendmsg
- cbad530277b5 PCI/P2PDMA: Add Intel QAT, DSA, IAA devices to whitelist
- 47b5d3d50660 net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
- 21ed9540a8e1 net: skmsg: preserve sg.copy across SG transforms
- 86d531337ea1 mac802154: llsec: add skb_cow_data() before in-place crypto
- 55e014aaec65 wifi: mt76: add wcid publish check in mt76_sta_add
- 293a84fa40b3 ntfs3: reject direct userspace writes to reserved $LX* xattrs
- c04d9ece23de ipv4: account for fraggap on the paged allocation path
- e9eacf19281e ipv6: account for fraggap on the paged allocation path
- d25df4f62eea batman-adv: tvlv: avoid race of cifsnotfound handler state
- 56910cfd3116 batman-adv: tvlv: enforce 2-byte alignment
- 3e4555177235 batman-adv: dat: prevent false sharing between VLANs
- f91d579a085b batman-adv: tt: track roam count per VID
- 6ae315914113 batman-adv: tt: don't merge change entries with different VIDs
- 39aadfa35160 batman-adv: tp_meter: handle overlapping packets
- aa9fe4cb1acb batman-adv: tp_meter: prevent parallel modifications of last_recv
- 7c5f5f680dfc batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE
- 1fb8762600a3 batman-adv: tp_meter: restrict number of unacked list entries
- 86ab6b6fb5b8 batman-adv: v: prevent OGM aggregation on disabled hardif
- 5d8e32165427 batman-adv: frag: avoid underflow of TTL
- cc97b6311190 batman-adv: frag: ensure fragment is writable before modifying TTL
- 09927ad14a5d batman-adv: fix (m|b)cast csum after decrementing TTL
- 4f121f393811 batman-adv: ensure bcast is writable before modifying TTL
- c14d3619a1f7 batman-adv: gw: don't deselect gateway with active hardif
- 26ac02e6ae5d batman-adv: tp_meter: initialize last_recv_time during init
- b4284cac3095 batman-adv: prevent ELP transmission interval underflow
- 7f58e114c1f3 batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE
- bafe4928d321 batman-adv: tp_meter: add only finished tp_vars to lists
- 1d8b344e8dfc batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection
- 47ca1ecb85b9 batman-adv: tp_meter: fix fast recovery precondition
- 585616dab0aa batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
- f1be6ca7c183 batman-adv: tp_meter: avoid window underflow
- fa54b5d133cd batman-adv: tp_meter: initialize dec_cwnd explicitly
- fd46e54c0601 batman-adv: tp_meter: initialize dup_acks explicitly
- d7f6ffe69078 batman-adv: tp_meter: keep unacked list in ascending ordered
- 1ae7d5a6db6c KVM: x86: Fix shadow paging use-after-free due to unexpected role