security review
Security-relevant kernel changes.
Security signals are derived from generated commit metadata, trailers, and parsed risk language. Applicability remains config and usage dependent.
cves
CVE-linked fixes
Only CVE IDs indexed from generated source records are shown here.
No generated CVE-linked records are indexed for the selected release yet.
Security-relevant signals without assigned CVE IDs are listed separately when present.
no cve assigned
Security-relevant, no CVE assigned
These are evidence-based labels, not vulnerability claims.
KVM: x86: Fix shadow paging use-after-free due to unexpected role. Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem arch/x86.
Fixesbatman-adv: tp_meter: avoid window underflowbatman-adv: tp_meter: avoid window underflow. Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem net.
Fixesbatman-adv: tp_meter: avoid divide-by-zero for dec_cwndbatman-adv: tp_meter: avoid divide-by-zero for dec_cwnd. Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem net.
Fixesbatman-adv: prevent ELP transmission interval underflowbatman-adv: prevent ELP transmission interval underflow. Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem net.
Fixesbatman-adv: frag: avoid underflow of TTLbatman-adv: frag: avoid underflow of TTL. Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem net.
Fixes, NULL, racebatman-adv: tvlv: avoid race of cifsnotfound handler statebatman-adv: tvlv: avoid race of cifsnotfound handler state. Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem net.
Fixes, UAF, stablemac802154: llsec: add skb_cow_data() before in-place cryptomac802154: llsec: add skb_cow_data() before in-place crypto. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem net.
Fixes, UAF, race, stableapparmor: fix use-after-free in rawdata dedup loopapparmor: fix use-after-free in rawdata dedup loop. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem security.
NULL, UAF, stablefbdev: fix use-after-free in store_modes()fbdev: fix use-after-free in store_modes(). Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/video.
bounds, stablegcov: use atomic counter updates to fix concurrent access crashesgcov: use atomic counter updates to fix concurrent access crashes. Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem Makefile.
Fixes, stableKEYS: fix overflow in keyctl_pkey_params_get_2()KEYS: fix overflow in keyctl_pkey_params_get_2(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem security.
Fixes, UAF, stablekeys: Pin request_key_auth payload in instantiate pathskeys: Pin request_key_auth payload in instantiate paths. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem security.
Fixes, bounds, stableuserfaultfd: build __VMA_UFFD_FLAGS from config-gated masksuserfaultfd: build __VMA_UFFD_FLAGS from config-gated masks. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem include.
Fixes, race, stablewifi: rtw88: increase TX report timeout to fix race conditionwifi: rtw88: increase TX report timeout to fix race condition. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/net.
race, stablewifi: iwlwifi: mvm: fix race condition in PTP removalwifi: iwlwifi: mvm: fix race condition in PTP removal. Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/net.
race, stablewifi: iwlwifi: mld: fix race condition in PTP removalwifi: iwlwifi: mld: fix race condition in PTP removal. Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/net.
bounds, stablewifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlerswifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers. Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/net.
Fixes, NULL, UAFf2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inodef2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode. Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem fs/f2fs.
Fixes, bounds, stablef2fs: bound i_inline_xattr_size for non-inline-xattr inodesf2fs: bound i_inline_xattr_size for non-inline-xattr inodes. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/f2fs.
Fixes, boundsf2fs: validate ACL entry sizes in f2fs_acl_from_disk()f2fs: validate ACL entry sizes in f2fs_acl_from_disk(). Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem fs/f2fs.
Fixes, race, stableRevert "f2fs: remove non-uptodate folio from the page cache in move_data_block"Revert "f2fs: remove non-uptodate folio from the page cache in move_data_block". Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/f2fs.
Fixes, race, stablef2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/f2fs.
Fixes, NULL, stablef2fs: read COW data with the original inode during atomic writef2fs: read COW data with the original inode during atomic write. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/f2fs.
Fixes, NULL, stableblock: Avoid mounting the bdev pseudo-filesystem in userspaceblock: Avoid mounting the bdev pseudo-filesystem in userspace. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem block.
Fixes, UAF, stableexfat: fix potential use-after-free in exfat_find_dir_entry()exfat: fix potential use-after-free in exfat_find_dir_entry(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/exfat.
Fixes, bounds, stableKVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping levelKVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem arch/x86.
Fixes, UAF, stablegfs2: fix use-after-free in gfs2_qd_deallocgfs2: fix use-after-free in gfs2_qd_dealloc. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/gfs2.
Fixes, NULL, UAF, stablepwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/power.
Fixes, UAF, stablehdlc_ppp: sync per-proto timers before freeing hdlc statehdlc_ppp: sync per-proto timers before freeing hdlc state. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/net.
Fixes, UAF, race, stableblk-cgroup: fix UAF in __blkcg_rstat_flush()blk-cgroup: fix UAF in __blkcg_rstat_flush(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem block.
Fixes, UAF, stabletipc: fix slab-use-after-free Read in tipc_aead_decrypt_donetipc: fix slab-use-after-free Read in tipc_aead_decrypt_done. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem net.
Fixes, UAF, stableLoongArch: Report dying CPU to RCU in stop_this_cpu()LoongArch: Report dying CPU to RCU in stop_this_cpu(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem arch/loongarch.
Fixes, UAF, stablepNFS: Fix use-after-free in pnfs_update_layout()pNFS: Fix use-after-free in pnfs_update_layout(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/nfs.
Fixes, UAF, bounds, stablesched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup pathsched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem kernel.
Fixes, NULL, UAF, stableirqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on removeirqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/irqchip.
Fixes, UAF, stablefpga: region: fix use-after-free in child_regions_with_firmware()fpga: region: fix use-after-free in child_regions_with_firmware(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/fpga.
Fixes, NULL, UAF, stablerpmsg: char: Fix use-after-free on probe error pathrpmsg: char: Fix use-after-free on probe error path. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/rpmsg.
Fixes, UAF, stableocfs2: reject oversized group bitmap descriptorsocfs2: reject oversized group bitmap descriptors. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/ocfs2.
Fixes, UAF, stable9p: avoid putting oldfid in p9_client_walk() error path9p: avoid putting oldfid in p9_client_walk() error path. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem net.
Fixes, UAF, stableMIPS: smp: report dying CPU to RCU in stop_this_cpu()MIPS: smp: report dying CPU to RCU in stop_this_cpu(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem arch/mips.
Fixes, UAF, bounds, stableKVM: x86: hyper-v: Bound the bank index when querying sparse banksKVM: x86: hyper-v: Bound the bank index when querying sparse banks. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem arch/x86.
Fixes, UAF, stableKVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT pathKVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem arch/x86.
Fixes, UAF, stablepower: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/power.
Fixes, UAF, stableriscv: kfence: Call mark_new_valid_map() for kfence_unprotect()riscv: kfence: Call mark_new_valid_map() for kfence_unprotect(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem arch/riscv.
UAF, stablentfs: serialize volume label accessesntfs: serialize volume label accesses. Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem fs/ntfs.
NULL, stablefbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_varfbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var. Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/video.
Fixes, bounds, stablefbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/video.
UAF, race, stablefbdev: omap2: fix use-after-free in omapfb_mmapfbdev: omap2: fix use-after-free in omapfb_mmap. Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/video.
NULL, UAF, stablefbdev: modedb: fix a possible UAF in fb_find_mode()fbdev: modedb: fix a possible UAF in fb_find_mode(). Evidence: Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/video.
Fixes, NULL, UAF, race, stablei2c: core: fix adapter registration racei2c: core: fix adapter registration race. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem drivers/i2c.
Fixes, NULL, race, stablenfsd: avoid leaking pre-allocated openowner on unconfirmed retry racenfsd: avoid leaking pre-allocated openowner on unconfirmed retry race. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/nfsd.
Fixes, NULL, regression, stableNFSv4/flexfiles: reject zero filehandle version countNFSv4/flexfiles: reject zero filehandle version count. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/nfs.
Fixes, NULL, stableNFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addrNFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr. Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/nfs.
Fixes, bounds, stableksmbd: fix out-of-bounds read in smb_check_perm_dacl()ksmbd: fix out-of-bounds read in smb_check_perm_dacl(). Evidence: Fixes trailer, Cc stable, stable backport, risk/stable-fix signal; subsystem fs/smb.
Fixes, NULL, UAFnet/tcp-ao: fix use-after-free of key in del_async pathnet/tcp-ao: fix use-after-free of key in del_async path. Evidence: Fixes trailer, stable backport, risk/stable-fix signal; subsystem net.