[CVE-2026-68278][IMPORTANT] drm/dp/mst: fix buffer overflows in sideband chunk accumulation
2026-08-10 14:34 UTC
[CVE-2026-68128][IMPORTANT] ice: reject out-of-range ptype in ice_parser_profile_init
2026-08-10 14:30 UTC
[CVE-2026-68416][MODERATE 7.0] mtd: fix double free and WARN_ON in add_mtd_device() error paths [ Upstream
2026-08-10 14:26 UTC
[CVE-2026-68131][MODERATE 7.0] rbd: Reset positive result codes to zero in object map update path
2026-08-10 14:24 UTC
[CVE-2026-68384][MODERATE 7.0] drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves [ Upstream
2026-08-10 14:20 UTC
[CVE-2026-68419][MODERATE 7.0] RDMA/irdma: Prevent rereg_mr for non-mem regions [ Upstream
2026-08-10 14:18 UTC
[CVE-2026-68255][MODERATE 7.0] drm/virtio: bound EDID block reads to the response buffer
2026-08-10 14:14 UTC
[CVE-2026-68148][MODERATE 7.0] fscrypt: Add missing superblock check in find_or_insert_direct_key()
2026-08-10 14:10 UTC
[CVE-2026-68167][LOW] btrfs: do not try compression for data reloc inodes
2026-08-10 14:06 UTC
[CVE-2026-68118][MODERATE 7.0] tcp: challenge ACK for non-exact RST in SYN-RECEIVED
2026-08-10 14:06 UTC
[CVE-2026-68242][MODERATE REGULAR] drm/i915/gt: Fix NULL deref on sched_engine alloc failure
2026-08-10 14:03 UTC
[CVE-2026-68372][MODERATE REGULAR] usb: core: port: Deattach Type-C connector on component unbind
2026-08-10 14:03 UTC
[CVE-2026-68106][MODERATE REGULAR] drm/amdgpu: fix division by zero with invalid uvd dimensions
2026-08-10 13:57 UTC
[CVE-2026-68409][IMPORTANT] wifi: mac80211: defer link RX stats percpu free to RCU [ Upstream
2026-08-10 13:57 UTC
[CVE-2026-68239][MODERATE 7.0] drm/ttm: Account for NULL and handle pages in ttm_pool_backup
2026-08-10 13:53 UTC
[CVE-2026-68125][MODERATE 7.0] mac802154: llsec: reject frames shorter than the authentication tag
2026-08-10 13:51 UTC
[CVE-2026-68368][MODERATE 7.0] usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
2026-08-10 13:48 UTC
[CVE-2026-68376][IMPORTANT] sctp: fix auth_hmacs array size in struct sctp_cookie [ Upstream
2026-08-10 13:34 UTC
[CVE-2026-68108][MODERATE 7.0] drm/amdgpu/vce: fix integer overflow in image size
2026-08-10 13:34 UTC
[CVE-2026-68161][MODERATE 7.0] sctp: close UDP tunnel sockets during netns teardown [ Upstream
2026-08-10 13:34 UTC
[CVE-2026-68304][LOW] wifi: brcmfmac: fix 802.1X-SHA256 call trace warning [ Upstream
2026-08-10 13:30 UTC
[CVE-2026-68227][LOW] media: cx231xx: fix devres lifetime
2026-08-10 13:26 UTC
[CVE-2026-68391][MODERATE 7.0] Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds [ Upstream
2026-08-10 13:23 UTC
[CVE-2026-68364][MODERATE REGULAR] drm/amd/display: Fix ISM dc_lock deadlock during suspend [ Upstream
2026-08-10 13:19 UTC
[CVE-2026-68157][MODERATE 7.0] libceph: guard missing CRUSH type name lookup
2026-08-10 13:19 UTC
[CVE-2026-68133][LOW] ice: fix PTP Call Trace during PTP release
2026-08-10 13:15 UTC
[CVE-2026-68406][LOW] wifi: cfg80211: validate PMSR FTM preamble range [ Upstream
2026-08-10 13:11 UTC
[CVE-2026-68103][MODERATE 7.0] drm/amdgpu: reject mapping a reserved doorbell to a new queue
2026-08-10 13:07 UTC
[CVE-2026-68169][MODERATE 7.0] mptcp: pm: userspace: fix use-after-free in get_local_id [ Upstream
2026-08-10 13:07 UTC
[CVE-2026-68202][IMPORTANT] ALSA: seq: close a re-opened queue timer in the destructor
2026-08-10 13:02 UTC
[CVE-2026-68194][MODERATE REGULAR] wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
2026-08-10 12:59 UTC
[CVE-2026-68349][MODERATE 7.0] wifi: carl9170: fix buffer overflow in rx_stream failover path [ Upstream
2026-08-10 12:55 UTC
[CVE-2026-68316][MODERATE 7.0] accel: ethosu: Fix element size accounting for cmd stream validation [ Upstream
2026-08-10 12:51 UTC
[CVE-2026-68331][LOW] dpaa2-eth: put MAC endpoint device on disconnect [ Upstream
2026-08-10 12:51 UTC
[CVE-2026-68322][MODERATE REGULAR] rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled [ Upstream
2026-08-10 12:43 UTC
[CVE-2026-68082][MODERATE 7.0] libceph: fix two unsafe bare decodes in decode_lockers()
2026-08-08 9:54 UTC
[CVE-2026-68081][MODERATE 7.0] KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state
2026-08-08 9:51 UTC
[CVE-2026-31669][IMPORTANT] mptcp: fix slab-use-after-free in __inet_lookup_established
2026-08-07 16:00 UTC
[CVE-2026-46082][MODERATE REGULAR] KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0
2026-08-07 14:09 UTC
[CVE-2026-68480][MODERATE REGULAR] x86/bugs: Make Safe-RET robust against interrupt injection
2026-08-06 17:51 UTC
[CVE-2026-64590][LOW] dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning [ Upstream
2026-08-06 8:22 UTC
[CVE-2026-64601][MODERATE 7.0] ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission
2026-08-06 8:19 UTC
[CVE-2026-64598][MODERATE REGULAR] smb/client: Fix error code in smb2_aead_req_alloc()
2026-08-06 8:15 UTC
[CVE-2026-64597][IMPORTANT] smb: client: fix double-free in SMB2_close() replay
2026-08-06 8:11 UTC
[CVE-2026-64603][LOW] platform/x86: intel-hid: Protect ACPI notify handler against recursion
2026-08-06 8:07 UTC
[CVE-2026-64591][LOW] iommu/vt-d: Avoid WARNING in sva unbind path
2026-08-06 8:07 UTC
[CVE-2026-64604][MODERATE REGULAR] KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode
2026-08-06 8:03 UTC
[CVE-2026-64593][LOW] btrfs: do not trim a device which is not writeable [ Upstream
2026-08-06 8:00 UTC
[CVE-2026-64586][MODERATE 7.0] wifi: brcmfmac: drain bus_reset work on device removal
2026-08-06 7:55 UTC
[CVE-2026-64596][MODERATE REGULAR] libfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo()
2026-08-06 7:45 UTC
[CVE-2026-64582][IMPORTANT] RDMA/rxe: Fix a use-after-free problem in rxe_mmap [ Upstream
2026-08-05 11:51 UTC
[CVE-2026-64572][MODERATE 7.0] ipv4: fib: free fib_alias with kfree_rcu() on insert error path [ Upstream
2026-08-05 9:29 UTC
[CVE-2026-64569][MODERATE REGULAR] mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n [ Upstream
2026-08-05 9:25 UTC
[CVE-2026-64570][MODERATE 7.0] wifi: mac80211: fix fils_discovery double free on alloc failure [ Upstream
2026-08-05 9:22 UTC
[CVE-2026-64577][MODERATE 7.0] gtp: check skb_pull_data() return in gtp1u_send_echo_resp() [ Upstream
2026-08-05 9:17 UTC
[CVE-2026-64579][MODERATE 7.0] xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert [ Upstream
2026-08-05 9:17 UTC
[CVE-2026-64573][MODERATE 7.0] Bluetooth: qca: fix NVM tag length underflow in TLV parser [ Upstream
2026-08-05 9:13 UTC
[CVE-2026-64580][MODERATE 7.0] xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() [ Upstream
2026-08-05 9:13 UTC
[CVE-2026-64581][MODERATE 7.0] xfrm: fix sk_dst_cache double-free in xfrm_user_policy() [ Upstream
2026-08-05 9:09 UTC
[CVE-2026-64567][MODERATE 7.0] btrfs: reject free space cache with more entries than pages [ Upstream
2026-08-05 9:06 UTC
[CVE-2026-64568][MODERATE 7.0] wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure [ Upstream
2026-08-05 9:02 UTC
[CVE-2026-64576][MODERATE REGULAR] nexthop: initialize extack in nh_res_bucket_migrate() [ Upstream
2026-08-05 8:58 UTC
[CVE-2026-64575][MODERATE 7.0] bpf: tcp: fix double sock release on batch realloc [ Upstream
2026-08-05 8:53 UTC
[CVE-2026-64574][MODERATE 7.0] wifi: mac80211: tear down new links on vif update error path [ Upstream
2026-08-05 8:52 UTC
[CVE-2026-64564][IMPORTANT] sctp: don't free the ASCONF's own transport in DEL-IP processing
2026-08-04 7:02 UTC
[CVE-2026-64563][MODERATE 7.0] rhashtable: clear stale iter->p on table restart
2026-08-04 6:59 UTC
[CVE-2026-64562][MODERATE 7.0] KVM: nVMX: Hide shadow VMCS right after VMCLEAR
2026-08-04 6:55 UTC
[CVE-2026-64561][IMPORTANT] KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
2026-08-04 6:51 UTC
[CVE-2026-64549][MODERATE REGULAR] Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() [ Upstream
2026-08-02 13:03 UTC
[CVE-2025-71130][MODERATE 7.0] drm/i915/gem: Zero-initialize the eb.vma array in i915_gem_do_execbuffer
2026-08-02 11:49 UTC
[CVE-2026-31540][LOW] drm/i915/gt: Check set_default_submission() before deferencing [ Upstream
2026-08-02 11:40 UTC
[CVE-2025-68793][MODERATE 7.0] drm/amdgpu: fix a job->pasid access race in gpu recovery [ Upstream
2026-08-01 18:06 UTC
[CVE-2026-23034][MODERATE REGULAR] drm/amdgpu/userq: Fix fence reference leak on queue teardown v2 [ Upstream
2026-08-01 18:01 UTC
[CVE-2026-23051][LOW] drm/amdgpu: fix drm panic null pointer when driver not support atomic [ Upstream
2026-08-01 17:55 UTC
[CVE-2026-23163][MODERATE REGULAR] drm/amdgpu: fix NULL pointer dereference in amdgpu_gmc_filter_faults_remove [ Upstream
2026-08-01 17:50 UTC
[CVE-2026-31765][MODERATE REGULAR] drm/amdgpu: Change AMDGPU_VA_RESERVED_TRAP_SIZE to 64KB
2026-08-01 17:22 UTC
[CVE-2026-31766][IMPORTANT] drm/amdgpu: validate doorbell_offset in user queue creation
2026-08-01 17:16 UTC
[CVE-2026-43131][LOW] drm/amd/pm: Fix null pointer dereference issue [ Upstream
2026-08-01 17:10 UTC
[CVE-2026-43191][LOW] drm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35 [ Upstream
2026-08-01 17:07 UTC
[CVE-2026-43195][MODERATE REGULAR] drm/amdgpu: validate user queue size constraints [ Upstream
2026-08-01 17:02 UTC
[CVE-2026-43243][LOW] drm/amd/display: Add signal type check for dcn401 get_phyd32clk_src [ Upstream
2026-08-01 16:58 UTC
[CVE-2025-71293][MODERATE 7.0] drm/amdgpu/ras: Move ras data alloc before bad page check [ Upstream
2026-08-01 16:54 UTC
[CVE-2025-71294][LOW] drm/amdgpu: fix NULL pointer issue buffer funcs [ Upstream
2026-08-01 16:49 UTC
[CVE-2026-43298][LOW] drm/amdgpu: Skip vcn poison irq release on VF [ Upstream
2026-08-01 16:45 UTC
[CVE-2026-43305][LOW] drm/amd/display: Fix mismatched unlock for DMUB HW lock in HWSS fast path [ Upstream
2026-08-01 16:41 UTC
[CVE-2026-43318][MODERATE REGULAR] drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify [ Upstream
2026-08-01 16:37 UTC
[CVE-2026-43320][LOW] drm/amd/display: Fix dsc eDP issue [ Upstream
2026-08-01 16:33 UTC
[CVE-2026-43367][LOW] drm/amd: Fix a few more NULL pointer dereference in device cleanup
2026-08-01 16:29 UTC
[CVE-2026-43369][LOW] drm/amd: Fix NULL pointer dereference in device cleanup
2026-08-01 16:25 UTC
[CVE-2026-43398][MODERATE REGULAR] drm/amdgpu: add upper bound check on user inputs in wait ioctl
2026-08-01 16:21 UTC
[CVE-2026-43399][MODERATE REGULAR] drm/amdgpu/userq: Fix reference leak in amdgpu_userq_wait_ioctl
2026-08-01 16:17 UTC
[CVE-2026-43400][MODERATE REGULAR] drm/amdgpu: add upper bound check on user inputs in signal ioctl
2026-08-01 16:12 UTC
[CVE-2026-43444][LOW] drm/amdkfd: Unreserve bo if queue update failed [ Upstream
2026-08-01 16:07 UTC
[CVE-2026-45878][IMPORTANT] drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 [ Upstream
2026-08-01 15:54 UTC
[CVE-2026-45853][MODERATE 7.0] drm/amdgpu: Use kvfree instead of kfree in amdgpu_gmc_get_nps_memranges() [ Upstream
2026-08-01 15:47 UTC
[CVE-2026-45947][LOW] drm/amdgpu: Fix memory leak in amdgpu_acpi_enumerate_xcc() [ Upstream
2026-08-01 15:41 UTC
[CVE-2026-45979][LOW] drm/amdgpu: clean up the amdgpu_cs_parser_bos [ Upstream
2026-08-01 15:35 UTC
[CVE-2026-45976][LOW] drm/amdgpu: Fix memory leak in amdgpu_ras_init() [ Upstream
2026-08-01 15:29 UTC
[CVE-2026-46199][MODERATE 7.0] drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg
2026-08-01 14:17 UTC
[CVE-2026-46220][MODERATE REGULAR] drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission
2026-08-01 14:06 UTC
[CVE-2026-46229][MODERATE 7.0] drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure
2026-08-01 14:00 UTC
[CVE-2026-46204][MODERATE 7.0] drm/amdgpu/vcn4: Prevent OOB reads when parsing IB
2026-08-01 13:54 UTC
[CVE-2026-46197][MODERATE 7.0] drm/amdkfd: validate SVM ioctl nattr against buffer size
2026-08-01 13:51 UTC
[CVE-2026-46230][MODERATE 7.0] drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg
2026-08-01 13:41 UTC
[CVE-2026-46245][LOW] drm/amd/display: Fix dc_link NULL handling in HPD init [ Upstream
2026-08-01 13:37 UTC
[CVE-2026-46263][MODERATE REGULAR] drm/amd/display: Fix out-of-bounds stream encoder index v3 [ Upstream
2026-08-01 13:33 UTC
[CVE-2026-46276][LOW] drm/amdgpu: fix zero-size GDS range init on RDNA4
2026-08-01 13:27 UTC
[CVE-2026-46311][MODERATE 7.0] drm/amdgpu/userq: fix access to stale wptr mapping
2026-08-01 13:21 UTC
[CVE-2026-53135][LOW] drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
2026-07-31 20:53 UTC
[CVE-2026-53136][IMPORTANT] drm/amd/display: Clamp VBIOS HDMI retimer register count to array size
2026-07-31 20:39 UTC
[CVE-2026-53137][MODERATE 7.0] drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
2026-07-31 20:32 UTC
[CVE-2026-53138][MODERATE 7.0] drm/amd/display: Bound VBIOS record-chain walk loops
2026-07-31 20:27 UTC
[CVE-2026-43368][MODERATE 7.0] drm/i915: Fix potential overflow of shmem scatterlist length
2026-07-30 17:18 UTC
[CVE-2026-31656][MODERATE 7.0] drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat
2026-07-30 17:11 UTC
[CVE-2026-43237][IMPORTANT] drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 [ Upstream
2026-07-30 17:00 UTC
[CVE-2026-43206][IMPORTANT] drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() [ Upstream
2026-07-30 16:50 UTC
[CVE-2026-31566][IMPORTANT] drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib [ Upstream
2026-07-30 16:34 UTC
[CVE-2026-43370][MODERATE 7.0] drm/amdgpu: Fix use-after-free race in VM acquire
2026-07-30 16:21 UTC
[CVE-2022-4994][LOW] KVM: x86: wean fast IN from emulator_pio_in Use __emulator_pio_in() directly for fast PIO instead of bouncing through emulator_pio_in() now that __emulator_pio_in() fills "val" when handling in-kernel PIO. vcpu->arch.pio.count is guaranteed to be '0', so this a pure nop. emulator_pio_in_emulated is now the last caller of emulator_pio_in. No functional change intended. Signed-off-by: Paolo Bonzini <[email protected]>
2026-07-30 9:49 UTC
[CVE-2026-63886][IMPORTANT] scsi: target: iscsi: Validate CHAP_R length before base64 decode
2026-07-29 23:56 UTC (3+ messages)
` [CVE-2026-63886] scsi
[CVE-2026-64560][MODERATE 7.0] posix-cpu-timers: Prevent UAF caused by non-leader exec() race
2026-07-29 17:51 UTC
[CVE-2026-64559][MODERATE 7.0] s390/pkey: Check length in PKEY_VERIFYPROTK ioctl
2026-07-29 16:56 UTC
[CVE-2026-64558][IMPORTANT] s390/pkey: Check length in pkey_pckmo handler implementation
2026-07-29 16:51 UTC
[CVE-2026-64556][IMPORTANT] perf/core: Detach event groups during remove_on_exec [ Upstream
2026-07-29 8:55 UTC
[CVE-2026-64557][MODERATE 7.0] Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() [ Upstream
2026-07-29 8:51 UTC
[CVE-2026-64544][LOW] crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents [ Upstream
2026-07-29 6:26 UTC
[CVE-2026-64543][MODERATE 7.0] tipc: fix use-after-free of the discoverer in tipc_disc_rcv() [ Upstream
2026-07-29 6:03 UTC
[CVE-2026-64553][MODERATE REGULAR] net: psample: fix info leak in PSAMPLE_ATTR_DATA [ Upstream
2026-07-29 5:38 UTC
[CVE-2026-64539][MODERATE 7.0] Bluetooth: eir: Fix stack OOB write when prepending the Flags AD [ Upstream
2026-07-29 5:35 UTC
[CVE-2026-64547][MODERATE REGULAR] net: usb: net1080: validate packet_len before pad-byte access in rx_fixup [ Upstream
2026-07-29 5:21 UTC
[CVE-2026-64551][MODERATE 7.0] sctp: validate STALE_COOKIE cause length before reading staleness
2026-07-29 5:09 UTC
[CVE-2026-64540][MODERATE REGULAR] usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() [ Upstream
2026-07-29 5:06 UTC
[CVE-2026-64548][MODERATE 7.0] bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() [ Upstream
2026-07-28 2:31 UTC
[CVE-2026-64554][IMPORTANT] netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
2026-07-28 2:27 UTC
[CVE-2026-64545][MODERATE REGULAR] net, bpf: check master for NULL in xdp_master_redirect() [ Upstream
2026-07-28 2:23 UTC
[CVE-2026-64555][MODERATE 7.0] KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
2026-07-28 2:18 UTC
[CVE-2026-64537][LOW] bridge: cfm: reject invalid CCM interval at configuration time [ Upstream
2026-07-28 2:18 UTC
[CVE-2026-64541][MODERATE 7.0] net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket [ Upstream
2026-07-28 2:18 UTC
[CVE-2026-43097][LOW] PCI: hv: Fix double ida_free in hv_pci_probe error path [ Upstream
2026-07-28 2:15 UTC
[CVE-2026-64546][MODERATE REGULAR] drm/edid: fix OOB read in drm_parse_tiled_block() [ Upstream
2026-07-28 2:14 UTC
[CVE-2026-64538][MODERATE 7.0] ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). [ Upstream
2026-07-28 2:10 UTC
[CVE-2026-64552][IMPORTANT] virtio-net: fix len check in receive_big() [ Upstream
2026-07-27 22:42 UTC
[CVE-2026-64542][MODERATE REGULAR] ipv6: ndisc: fix NULL deref in accept_untracked_na() [ Upstream
2026-07-27 22:03 UTC
[CVE-2026-64535][IMPORTANT] nvmet-tcp: Fix potential UAF when ddgst mismatch
2026-07-27 6:58 UTC
[CVE-2026-64531][MODERATE 7.0] net: openvswitch: reject oversized nested action attrs
2026-07-27 6:55 UTC
[CVE-2026-64534][IMPORTANT] nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path
2026-07-27 6:51 UTC
[CVE-2024-14040][LOW] net: nexthop: Increase weight to u16 In CLOS networks, as link failures occur at various points in the network, ECMP weights of the involved nodes are adjusted to compensate. With high fan-out of the involved nodes, and overall high number of nodes, a (non-)ECMP weight ratio that we would like to configure does not fit into 8 bits. Instead of, say, 255:254, we might like to configure something like 1000:999. For these deployments, the 8-bit weight may not be enough. To that end, in this patch increase the next hop weight from u8 to u16. Increasing the width of an integral type can be tricky, because while the code still compiles, the types may not check out anymore, and numerical errors come up. To prevent this, the conversion was done in two steps. First the type was changed from u8 to a single-member structure, which invalidated all uses of the field. This allowed going through them one by one and audit for type correctness. Then the structure was replaced with a vanilla u16 again. This should ensure that no place was missed. The UAPI for configuring nexthop group members is that an attribute NHA_GROUP carries an array of struct nexthop_grp entries: struct nexthop_grp { __u32 id; /* nexthop id - must exist */ __u8 weight; /* weight of this nexthop */ __u8 resvd1; __u16 resvd2; }; The field resvd1 is currently validated and required to be zero. We can lift this requirement and carry high-order bits of the weight in the reserved field: struct nexthop_grp { __u32 id; /* nexthop id - must exist */ __u8 weight; /* weight of this nexthop */ __u8 weight_high; __u16 resvd2; }; Keeping the fields split this way was chosen in case an existing userspace makes assumptions about the width of the weight field, and to sidestep any endianness issues. The weight field is currently encoded as the weight value minus one, because weight of 0 is invalid. This same trick is impossible for the new weight_high field, because zero must mean actual zero. With this in place: - Old userspace is guaranteed to carry weight_high of 0, therefore configuring 8-bit weights as appropriate. When dumping nexthops with 16-bit weight, it would only show the lower 8 bits. But configuring such nexthops implies existence of userspace aware of the extension in the first place. - New userspace talking to an old kernel will work as long as it only attempts to configure 8-bit weights, where the high-order bits are zero. Old kernel will bounce attempts at configuring >8-bit weights. Renaming reserved fields as they are allocated for some purpose is commonly done in Linux. Whoever touches a reserved field is doing so at their own risk. nexthop_grp::resvd1 in particular is currently used by at least strace, however they carry an own copy of UAPI headers, and the conversion should be trivial. A helper is provided for decoding the weight out of the two fields. Forcing a conversion seems preferable to bending backwards and introducing anonymous unions or whatever. Signed-off-by: Petr Machata <[email protected]> Reviewed-by: Ido Schimmel <[email protected]> Reviewed-by: David Ahern <[email protected]> Reviewed-by: Przemek Kitszel <[email protected]> Link: https://patch.msgid.link/483e2fcf4beb0d9135d62e7d27b46fa2685479d4.1723036486.git.petrm@nvidia.com Signed-off-by: Jakub Kicinski <[email protected]>
2026-07-26 6:53 UTC
[CVE-2026-64530][IMPORTANT] net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle [ Upstream
2026-07-26 6:51 UTC
[CVE-2026-64383][IMPORTANT] smb: client: fix double-free in SMB2_flush() replay
2026-07-25 19:44 UTC
[CVE-2026-64340][MODERATE 7.0] USB: legousbtower: fix use-after-free on disconnect race
2026-07-25 19:41 UTC
[CVE-2026-64516][MODERATE 7.0] drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets [ Upstream
2026-07-25 19:37 UTC
[CVE-2026-64486][LOW] ALSA: cmipci: check snd_ctl_new1() return value
2026-07-25 19:37 UTC
[CVE-2026-64463][MODERATE 7.0] usb: typec: tcpci_rt1711h: unregister TCPCI port with devres
2026-07-25 19:33 UTC
[CVE-2026-64315][MODERATE REGULAR] crypto: caam - use print_hex_dump_devel to guard key hex dumps again
2026-07-25 19:30 UTC
[CVE-2026-64364][IMPORTANT] HID: multitouch: fix out-of-bounds bit access on mt_io_flags [ Upstream
2026-07-25 19:24 UTC
[CVE-2026-64357][MODERATE REGULAR] xfs: fix exchmaps reservation limit check
2026-07-25 19:22 UTC
[CVE-2026-64369][MODERATE REGULAR] s390: Revert support for DCACHE_WORD_ACCESS
2026-07-25 19:18 UTC
[CVE-2026-64515][MODERATE 7.0] wifi: mac80211: fix MLE defragmentation [ Upstream
2026-07-25 19:14 UTC
[CVE-2026-64265][IMPORTANT] fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req
2026-07-25 19:11 UTC
[CVE-2026-64419][LOW] mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show() [ Upstream
2026-07-25 19:09 UTC
[CVE-2026-64316][MODERATE REGULAR] crypto: caam - use print_hex_dump_devel to guard key hex dumps
2026-07-25 19:09 UTC
[CVE-2026-64522][LOW] net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA [ Upstream
2026-07-25 19:05 UTC
[CVE-2026-64309][MODERATE 7.0] crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)
2026-07-25 19:05 UTC
[CVE-2026-64320][IMPORTANT] nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
2026-07-25 19:01 UTC
[CVE-2026-64307][MODERATE 7.0] crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG) [ Upstream
2026-07-25 18:58 UTC
[CVE-2026-64323][MODERATE 7.0] udf: validate VAT header length against the VAT inode size
2026-07-25 18:54 UTC
[CVE-2026-64276][IMPORTANT] Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
2026-07-25 18:50 UTC
[CVE-2026-64404][MODERATE REGULAR] Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync()
2026-07-25 18:46 UTC
[CVE-2026-64346][MODERATE 7.0] usb: gadget: udc: Fix use-after-free in gadget_match_driver
2026-07-25 18:43 UTC
[CVE-2026-64525][MODERATE 7.0] xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit [ Upstream
2026-07-25 18:40 UTC
[CVE-2026-64523][MODERATE 7.0] net/handshake: Take a long-lived file reference at submit [ Upstream
2026-07-25 18:38 UTC
[CVE-2026-64360][MODERATE REGULAR] hfs/hfsplus: zero-initialize buffer in hfs_bnode_read
2026-07-25 18:35 UTC
[CVE-2026-64382][IMPORTANT] smb: client: fix double-free in SMB2_open() replay
2026-07-25 18:33 UTC
[CVE-2026-64460][MODERATE 7.0] PCI/IOV: Skip VF Resizable BAR restore on read error
2026-07-25 18:30 UTC
[CVE-2026-64470][MODERATE 7.0] Bluetooth: btusb: fix use-after-free on marvell probe failure [ Upstream
2026-07-25 18:27 UTC
[CVE-2026-64452][MODERATE 7.0] 6lowpan: fix NHC entry use-after-free on error path
2026-07-25 18:23 UTC
[CVE-2026-64365][MODERATE 7.0] HID: letsketch: fix UAF on inrange_timer at driver unbind
2026-07-25 18:19 UTC
[CVE-2026-64481][MODERATE 7.0] ALSA: hda/cs35l41: Fix firmware load work teardown [ Upstream
2026-07-25 18:15 UTC
[CVE-2026-64384][IMPORTANT] smb: client: fix change notify replay double-free
2026-07-25 18:12 UTC
[CVE-2026-64428][LOW] gpio: sch: use raw_spinlock_t in the irq startup path [ Upstream
2026-07-25 18:08 UTC
[CVE-2026-64266][MODERATE 7.0] fuse: re-lock request before returning from fuse_ref_folio()
2026-07-25 18:08 UTC
[CVE-2026-64424][MODERATE 7.0] netpoll: fix a use-after-free on shutdown path
2026-07-25 18:04 UTC
[CVE-2026-64356][LOW] xfs: fix memory leak in xfs_dqinode_metadir_create()
2026-07-25 18:01 UTC
[CVE-2026-64388][LOW] smb/client: fix chown/chgrp with SMB3 POSIX Extensions
2026-07-25 17:58 UTC
[CVE-2026-64325][MODERATE REGULAR] wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon [ Upstream
2026-07-25 17:55 UTC
[CVE-2026-64275][LOW] Input: elan_i2c - prevent division by zero and arithmetic underflow
2026-07-25 17:53 UTC
[CVE-2026-64336][MODERATE REGULAR] USB: serial: keyspan_pda: fix information leak
2026-07-25 17:48 UTC
[CVE-2026-64313][MODERATE 7.0] crypto: ecc - Fix carry overflow in vli multiplication
2026-07-25 17:45 UTC
[CVE-2026-64451][LOW] tracing: Fix NULL pointer dereference in func_set_flag()
2026-07-25 17:40 UTC
[CVE-2026-64453][MODERATE 7.0] usb: misc: usbio: fix disconnect UAF in client teardown
2026-07-25 17:39 UTC
[CVE-2026-64342][MODERATE 7.0] USB: iowarrior: fix use-after-free on disconnect
2026-07-25 17:37 UTC
[CVE-2026-64479][MODERATE REGULAR] ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()
2026-07-25 17:33 UTC
[CVE-2026-64308][MODERATE REGULAR] crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD)
2026-07-25 17:29 UTC
[CVE-2026-64507][MODERATE REGULAR] x86/bugs: Enable IBPB flush on BPF JIT allocation
2026-07-25 17:26 UTC
[CVE-2026-64529][MODERATE REGULAR] crypto: qat - remove unused character device and IOCTLs [ Upstream
2026-07-25 17:23 UTC
[CVE-2026-64317][MODERATE 7.0] isofs: bound Rock Ridge symlink components to the SL record
2026-07-25 17:18 UTC
[CVE-2026-64490][IMPORTANT] ALSA: virtio: Validate control metadata from the device
2026-07-25 17:14 UTC
[CVE-2026-64283][MODERATE 7.0] KVM: guest_memfd: Treat memslot binding offset+size as unsigned values
2026-07-25 17:10 UTC
[CVE-2026-64319][MODERATE 7.0] nvmet-auth: validate reply message payload bounds against transfer length [ Upstream
2026-07-25 17:10 UTC
page: next (older) | prev (newer) | latest
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox