31/05/2026
Релиз ядра linux-6.12.91-lvc22
Опубликован релиз ядра linux-6.12.91-lvc22, в котором:
- В качестве базовой версии ядра Linux используется версия 6.12.91
(вместо 6.12.89), что включает в себя исправления следующих уязвимостей:
- CVE-2026-46137 "mptcp: pm: ADD_ADDR rtx: fix potential data-race" (Уровень опасности 9.8)
- CVE-2026-46212 "batman-adv: bla: prevent use-after-free when deleting claims" (Уровень опасности 8.8)
- CVE-2026-46238 "batman-adv: stop caching unowned originator pointers in BAT IV" (Уровень опасности 8.8)
- CVE-2026-46198 "batman-adv: fix integer overflow on buff_pos" (Уровень опасности 8.8)
- CVE-2026-45843 "slip: bound decode() reads against the compressed packet length" (Уровень опасности 8.2)
- CVE-2026-31613 "smb: client: fix OOB reads parsing symlink error response" (Уровень опасности 8.1)
- CVE-2026-46232 "HID: playstation: Clamp num_touch_reports" (Уровень опасности 8.1)
- BDU:2026-06785 (CVE-2026-46300) "net: skbuff: preserve shared-frag marker during coalescing" (Уровень опасности 7.8)
- BDU:2026-07273 (CVE-2026-43494) "net/rds: reset op_nents when zerocopy page pin fails" (Уровень опасности 7.8)
- CVE-2026-43503 "net: skbuff: propagate shared-frag marker through frag-transfer helpers" (Уровень опасности 7.8)
- CVE-2026-23272 "netfilter: nf_tables: unconditionally bump set->nelems before insertion" (Уровень опасности 7.8)
- CVE-2026-23171 "bonding: fix use-after-free due to enslave fail after slave array update" (Уровень опасности 7.8)
- CVE-2026-46117 "RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()" (Уровень опасности 7.8)
- CVE-2026-46208 "batman-adv: stop tp_meter sessions during mesh teardown" (Уровень опасности 7.8)
- CVE-2026-46111 "Bluetooth: hci_conn: fix potential UAF in create_big_sync" (Уровень опасности 7.8)
- CVE-2026-46206 "batman-adv: reject new tp_meter sessions during teardown" (Уровень опасности 7.8)
- CVE-2026-46227 "sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL" (Уровень опасности 7.8)
- CVE-2026-46201 "drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import()" (Уровень опасности 7.8)
- CVE-2026-46197 "drm/amdkfd: validate SVM ioctl nattr against buffer size" (Уровень опасности 7.8)
- CVE-2026-46209 "drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()" (Уровень опасности 7.8)
- CVE-2026-46205 "staging: media: atomisp: Disallow all private IOCTLs" (Уровень опасности 7.8)
- CVE-2026-43245 "ntfs: ->d_compare() must not block" (Уровень опасности 7.5)
- CVE-2026-46237 "drm/amdgpu/vcn3: Avoid overflow on msg bound check" (Уровень опасности 7.1)
- CVE-2026-46230 "drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg" (Уровень опасности 7.1)
- CVE-2026-46199 "drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg" (Уровень опасности 7.1)
- CVE-2026-46204 "drm/amdgpu/vcn4: Prevent OOB reads when parsing IB" (Уровень опасности 7.1)
- CVE-2026-46218 "drm/amdgpu: Add bounds checking to ib_{get,set}_value" (Уровень опасности 7.1)
- CVE-2026-46164 "btrfs: fix double free in create_space_info_sub_group() error path" (Уровень опасности 7.0)
- CVE-2025-68251 "erofs: avoid infinite loops due to corrupted subpage compact indexes" (Уровень опасности 5.5)
- CVE-2026-46160 "btrfs: fix missing last_unlink_trans update when removing a directory"
- CVE-2026-45846 "bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst()"
- CVE-2026-45845 "net/sched: taprio: fix NULL pointer dereference in class dump"
- CVE-2026-45844 "netfilter: arp_tables: fix IEEE1394 ARP payload parsing"
- CVE-2026-45842 "slip: reject VJ receive packets on instances with no rstate array"
- CVE-2026-45841 "netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO"
- CVE-2026-45840 "openvswitch: cap upcall PID array size and pre-size vport replies"
- CVE-2026-45839 "bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec()"
- CVE-2026-45838 "bpf: fix end-of-list detection in cgroup_storage_get_next_key()"
- CVE-2026-46217 "drm/amdgpu/vcn4: Avoid overflow on msg bound check"
- CVE-2026-46214 "vsock/virtio: fix accept queue count leak on transport mismatch"
- CVE-2026-46207 "vsock/virtio: fix empty payload in tap skb for non-linear buffers"
- CVE-2026-46234 "vsock: fix buffer size clamping order"
- CVE-2026-46159 "btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak"
- CVE-2026-45836 "Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb()"
- CVE-2026-46191 "fbcon: Avoid OOB font access if console rotation fails"
- CVE-2026-46231 "batman-adv: bla: put backbone reference on failed claim hash insert"
- CVE-2026-46233 "batman-adv: bla: only purge non-released claims"
- CVE-2026-46220 "drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission"
- CVE-2026-46229 "drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure"
- CVE-2026-46211 "drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata()"
- CVE-2026-46219 "spi: mpc52xx: fix use-after-free on unbind"
- CVE-2026-46200 "spi: mpc52xx: fix controller deregistration"
- CVE-2026-46241 "spi: mpc52xx: fix use-after-free on registration failure"
- CVE-2026-46225 "spi: rspi: fix controller deregistration"
- CVE-2026-46226 "spi: fsl: fix controller deregistration"
- CVE-2026-46235 "media: saa7164: add ioremap return checks and cleanups"
- CVE-2026-46236 "media: rc: xbox_remote: heed DMA restrictions"
- Добавлен патч "net: sched: cls_u32: Avoid memcpy() false-positive warning in u32_init_knode()" (Jiayuan Chen <jiayuan.chen@shopee.com>, бэкпортирован Alexey Nepomnyashih <sdl@nppct.ru>), устраняющий ошибку "WARNING in u32_change"(https://gitlab.linuxtesting.ru/lvc/kernel-issues/-/issues/352).





