KDKernelDiff

security review

Security-relevant kernel changes.

Security signals are derived from generated commit metadata, trailers, and parsed risk language. Applicability remains config and usage dependent.

cves

CVE-linked fixes

Only CVE IDs indexed from generated source records are shown here.

No generated CVE-linked records are indexed for the selected release yet.

Security-relevant signals without assigned CVE IDs are listed separately when present.

no cve assigned

Security-relevant, no CVE assigned

These are evidence-based labels, not vulnerability claims.

Fixes, UAFKVM: x86: Fix shadow paging use-after-free due to unexpected role

KVM: x86: Fix shadow paging use-after-free due to unexpected role. Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem arch/x86.

Fixesbatman-adv: tp_meter: avoid window underflow

batman-adv: tp_meter: avoid window underflow. Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem net.

Fixesbatman-adv: tp_meter: avoid divide-by-zero for dec_cwnd

batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd. Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem net.

Fixesbatman-adv: prevent ELP transmission interval underflow

batman-adv: prevent ELP transmission interval underflow. Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem net.

Fixesbatman-adv: frag: avoid underflow of TTL

batman-adv: frag: avoid underflow of TTL. Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem net.

Fixes, NULL, racebatman-adv: tvlv: avoid race of cifsnotfound handler state

batman-adv: tvlv: avoid race of cifsnotfound handler state. Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem net.

Fixes, UAF, stablemac802154: llsec: add skb_cow_data() before in-place crypto

mac802154: llsec: add skb_cow_data() before in-place crypto. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem net.

Fixes, UAF, race, stableapparmor: fix use-after-free in rawdata dedup loop

apparmor: fix use-after-free in rawdata dedup loop. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem security.

NULL, UAF, stablefbdev: fix use-after-free in store_modes()

fbdev: fix use-after-free in store_modes(). Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/video.

bounds, stablegcov: use atomic counter updates to fix concurrent access crashes

gcov: use atomic counter updates to fix concurrent access crashes. Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem Makefile.

Fixes, stableKEYS: fix overflow in keyctl_pkey_params_get_2()

KEYS: fix overflow in keyctl_pkey_params_get_2(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem security.

Fixes, UAF, stablekeys: Pin request_key_auth payload in instantiate paths

keys: Pin request_key_auth payload in instantiate paths. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem security.

Fixes, bounds, stableuserfaultfd: build __VMA_UFFD_FLAGS from config-gated masks

userfaultfd: build __VMA_UFFD_FLAGS from config-gated masks. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem include.

Fixes, race, stablewifi: rtw88: increase TX report timeout to fix race condition

wifi: rtw88: increase TX report timeout to fix race condition. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/net.

race, stablewifi: iwlwifi: mvm: fix race condition in PTP removal

wifi: iwlwifi: mvm: fix race condition in PTP removal. Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/net.

race, stablewifi: iwlwifi: mld: fix race condition in PTP removal

wifi: iwlwifi: mld: fix race condition in PTP removal. Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/net.

bounds, stablewifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers

wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers. Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/net.

Fixes, NULL, UAFf2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode

f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode. Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem fs/f2fs.

Fixes, bounds, stablef2fs: bound i_inline_xattr_size for non-inline-xattr inodes

f2fs: bound i_inline_xattr_size for non-inline-xattr inodes. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/f2fs.

Fixes, boundsf2fs: validate ACL entry sizes in f2fs_acl_from_disk()

f2fs: validate ACL entry sizes in f2fs_acl_from_disk(). Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem fs/f2fs.

Fixes, race, stableRevert "f2fs: remove non-uptodate folio from the page cache in move_data_block"

Revert "f2fs: remove non-uptodate folio from the page cache in move_data_block". Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/f2fs.

Fixes, race, stablef2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()

f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/f2fs.

Fixes, NULL, stablef2fs: read COW data with the original inode during atomic write

f2fs: read COW data with the original inode during atomic write. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/f2fs.

Fixes, NULL, stableblock: Avoid mounting the bdev pseudo-filesystem in userspace

block: Avoid mounting the bdev pseudo-filesystem in userspace. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem block.

Fixes, UAF, stableexfat: fix potential use-after-free in exfat_find_dir_entry()

exfat: fix potential use-after-free in exfat_find_dir_entry(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/exfat.

Fixes, bounds, stableKVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level

KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem arch/x86.

Fixes, UAF, stablegfs2: fix use-after-free in gfs2_qd_dealloc

gfs2: fix use-after-free in gfs2_qd_dealloc. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/gfs2.

Fixes, NULL, UAF, stablepwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()

pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/power.

Fixes, UAF, stablehdlc_ppp: sync per-proto timers before freeing hdlc state

hdlc_ppp: sync per-proto timers before freeing hdlc state. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/net.

Fixes, UAF, race, stableblk-cgroup: fix UAF in __blkcg_rstat_flush()

blk-cgroup: fix UAF in __blkcg_rstat_flush(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem block.

Fixes, UAF, stabletipc: fix slab-use-after-free Read in tipc_aead_decrypt_done

tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem net.

Fixes, UAF, stableLoongArch: Report dying CPU to RCU in stop_this_cpu()

LoongArch: Report dying CPU to RCU in stop_this_cpu(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem arch/loongarch.

Fixes, UAF, stablepNFS: Fix use-after-free in pnfs_update_layout()

pNFS: Fix use-after-free in pnfs_update_layout(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/nfs.

Fixes, UAF, bounds, stablesched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path

sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem kernel.

Fixes, NULL, UAF, stableirqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove

irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/irqchip.

Fixes, UAF, stablefpga: region: fix use-after-free in child_regions_with_firmware()

fpga: region: fix use-after-free in child_regions_with_firmware(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/fpga.

Fixes, NULL, UAF, stablerpmsg: char: Fix use-after-free on probe error path

rpmsg: char: Fix use-after-free on probe error path. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/rpmsg.

Fixes, UAF, stableocfs2: reject oversized group bitmap descriptors

ocfs2: reject oversized group bitmap descriptors. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/ocfs2.

Fixes, UAF, stable9p: avoid putting oldfid in p9_client_walk() error path

9p: avoid putting oldfid in p9_client_walk() error path. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem net.

Fixes, UAF, stableMIPS: smp: report dying CPU to RCU in stop_this_cpu()

MIPS: smp: report dying CPU to RCU in stop_this_cpu(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem arch/mips.

Fixes, UAF, bounds, stableKVM: x86: hyper-v: Bound the bank index when querying sparse banks

KVM: x86: hyper-v: Bound the bank index when querying sparse banks. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem arch/x86.

Fixes, UAF, stableKVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path

KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem arch/x86.

Fixes, UAF, stablepower: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()

power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/power.

Fixes, UAF, stableriscv: kfence: Call mark_new_valid_map() for kfence_unprotect()

riscv: kfence: Call mark_new_valid_map() for kfence_unprotect(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem arch/riscv.

UAF, stablentfs: serialize volume label accesses

ntfs: serialize volume label accesses. Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem fs/ntfs.

NULL, stablefbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var

fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var. Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/video.

Fixes, bounds, stablefbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()

fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/video.

UAF, race, stablefbdev: omap2: fix use-after-free in omapfb_mmap

fbdev: omap2: fix use-after-free in omapfb_mmap. Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/video.

NULL, UAF, stablefbdev: modedb: fix a possible UAF in fb_find_mode()

fbdev: modedb: fix a possible UAF in fb_find_mode(). Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/video.

Fixes, NULL, UAF, race, stablei2c: core: fix adapter registration race

i2c: core: fix adapter registration race. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/i2c.

Fixes, NULL, race, stablenfsd: avoid leaking pre-allocated openowner on unconfirmed retry race

nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/nfsd.

Fixes, NULL, regression, stableNFSv4/flexfiles: reject zero filehandle version count

NFSv4/flexfiles: reject zero filehandle version count. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/nfs.

Fixes, NULL, stableNFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr

NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/nfs.

Fixes, bounds, stableksmbd: fix out-of-bounds read in smb_check_perm_dacl()

ksmbd: fix out-of-bounds read in smb_check_perm_dacl(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/smb.

Fixes, NULL, UAFnet/tcp-ao: fix use-after-free of key in del_async path

net/tcp-ao: fix use-after-free of key in del_async path. Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem net.