Skip to content

[rocky8_10] History Rebuild through kernel-4.18.0-553.163.1.el8_10 - #1616

Open
PlaidCat wants to merge 9 commits into
rocky8_10from
rocky8_10_rebuild
Open

PlaidCat wants to merge 9 commits into
rocky8_10from
rocky8_10_rebuild

Conversation

@PlaidCat

@PlaidCat PlaidCat commented Sep 16, 2026

Copy link
Copy Markdown
Collaborator

This is an automated kernel history rebuild using cron and internal tooling. It follows the same process used for previous history rebuilds:

  • Download all unprocessed src.rpm packages
  • For each src.rpm:
    • Identify all commits in the changelog up to the last known tag (4.18.0-553)
    • Replay commits in chronological order (oldest to newest in the changelog) using git cherry-pick
    • Replace the code in the branch with the output of rpmbuild -bp for the corresponding src.rpm
    • Tag the rebuild branch

JIRA Tickets

Rebuild Splat Inspection

kernel-4.18.0-553.163.1.el8_10

$ cat ciq/ciq_backports/kernel-4.18.0-553.163.1.el8_10/rebuild.details.txt
Rebuild_History BUILDABLE
Rebuilding Kernel from rpm changelog with Fuzz Limit: 87.50%
Number of commits in upstream range v4.18~1..kernel-mainline: 625874
Number of commits in rpm: 19
Number of commits matched with upstream: 9 (47.37%)
Number of commits in upstream but not in rpm: 625865
Number of commits NOT found in upstream: 10 (52.63%)

Rebuilding Kernel on Branch rocky8_10_rebuild_kernel-4.18.0-553.163.1.el8_10 for kernel-4.18.0-553.163.1.el8_10
Clean Cherry Picks: 7 (77.78%)
Empty Cherry Picks: 1 (11.11%)
_______________________________

__EMPTY COMMITS__________________________
ebf71dd4aff46e8e421d455db3e231ba43d2fa8a net/rds: Restrict use of RDS/IB to the initial network namespace

__CHANGES NOT IN UPSTREAM________________
Adding prod certs and changed cert date to 20210620
Adding Rocky secure boot certs
Fixing vmlinuz removal
Fixing UEFI CA path
Porting to 8.10, debranding and Rocky branding
Fixing pesign_key_name values
scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer
dm-verity: fix buffer overflow in FEC calculation
wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove

BUILD

$ grep -E -B 5 -A 5 "\[TIMER\]|^Starting Build" $(ls -t kbuild* | head -n1)
/mnt/code/kernel-src-tree-build
Running make mrproper...
  CLEAN   scripts/basic
  CLEAN   scripts/kconfig
[TIMER]{MRPROPER}: 5s
x86_64 architecture detected, copying config
'configs/kernel-x86_64.config' -> '.config'
Setting Local Version for build
CONFIG_LOCALVERSION="-rocky8_10_rebuild-ccc496c5f72e"
Making olddefconfig
--
  HOSTLD  scripts/kconfig/conf
scripts/kconfig/conf  --olddefconfig Kconfig
#
# configuration written to .config
#
Starting Build
scripts/kconfig/conf  --syncconfig Kconfig
  SYSTBL  arch/x86/include/generated/asm/syscalls_32.h
  SYSHDR  arch/x86/include/generated/asm/unistd_32_ia32.h
  SYSHDR  arch/x86/include/generated/asm/unistd_64_x32.h
  SYSTBL  arch/x86/include/generated/asm/syscalls_64.h
--
  LD [M]  sound/usb/usx2y/snd-usb-usx2y.ko
  LD [M]  sound/virtio/virtio_snd.ko
  LD [M]  sound/x86/snd-hdmi-lpe-audio.ko
  LD [M]  sound/xen/snd_xen_front.ko
  LD [M]  virt/lib/irqbypass.ko
[TIMER]{BUILD}: 1529s
Making Modules
  INSTALL arch/x86/crypto/blowfish-x86_64.ko
  INSTALL arch/x86/crypto/camellia-aesni-avx-x86_64.ko
  INSTALL arch/x86/crypto/camellia-aesni-avx2.ko
  INSTALL arch/x86/crypto/camellia-x86_64.ko
--
  INSTALL sound/virtio/virtio_snd.ko
  INSTALL sound/x86/snd-hdmi-lpe-audio.ko
  INSTALL sound/xen/snd_xen_front.ko
  INSTALL virt/lib/irqbypass.ko
  DEPMOD  4.18.0-rocky8_10_rebuild-ccc496c5f72e+
[TIMER]{MODULES}: 10s
Making Install
sh ./arch/x86/boot/install.sh 4.18.0-rocky8_10_rebuild-ccc496c5f72e+ arch/x86/boot/bzImage \
	System.map "/boot"
[TIMER]{INSTALL}: 21s
Checking kABI
kABI check passed
Setting Default Kernel to /boot/vmlinuz-4.18.0-rocky8_10_rebuild-ccc496c5f72e+ and Index to 0
Hopefully Grub2.0 took everything ... rebooting after time metrices
[TIMER]{MRPROPER}: 5s
[TIMER]{BUILD}: 1529s
[TIMER]{MODULES}: 10s
[TIMER]{INSTALL}: 21s
[TIMER]{TOTAL} 1571s
Rebooting in 10 seconds

KSelfTests

$ get_kselftest_diff.sh
ls: cannot access 'selftest-*': No such file or directory
kselftest.4.18.0-rocky8_10_rebuild-1ef263699b13+.log
206
kselftest.4.18.0-rocky8_10_rebuild-5ced7ffceb6c+.log
206
kselftest.4.18.0-rocky8_10_rebuild-4b387634aa80+.log
206
kselftest.4.18.0-rocky8_10_rebuild-ccc496c5f72e+.log
206
Before: kselftest.4.18.0-rocky8_10_rebuild-4b387634aa80+.log
After: kselftest.4.18.0-rocky8_10_rebuild-ccc496c5f72e+.log
Diff:
No differences found.

jira KERNEL-1605
cve CVE-2026-43133
Rebuild_History Non-Buildable kernel-4.18.0-553.163.1.el8_10
commit-author Yosry Ahmed <yosry.ahmed@linux.dev>
commit 127ccae

Commit cc3ed80 ("KVM: nSVM: always use vmcb01 to for vmsave/vmload
of guest state") made KVM always use vmcb01 for the fields controlled by
VMSAVE/VMLOAD, but it missed updating the VMLOAD/VMSAVE emulation code
to always use vmcb01.

As a result, if VMSAVE/VMLOAD is executed by an L2 guest and is not
intercepted by L1, KVM will mistakenly use vmcb02. Always use vmcb01
instead of the current VMCB.

Fixes: cc3ed80 ("KVM: nSVM: always use vmcb01 to for vmsave/vmload of guest state")
	Cc: Maxim Levitsky <mlevitsk@redhat.com>
	Cc: stable@vger.kernel.org
	Signed-off-by: Yosry Ahmed <yosry.ahmed@linux.dev>
Link: https://patch.msgid.link/20260110004821.3411245-2-yosry.ahmed@linux.dev
	Signed-off-by: Sean Christopherson <seanjc@google.com>
(cherry picked from commit 127ccae)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1605
cve CVE-2026-63889
Rebuild_History Non-Buildable kernel-4.18.0-553.163.1.el8_10
commit-author Michael Bommarito <michael.bommarito@gmail.com>
commit a9a3923

An adjacent Fibre Channel fabric actor that can deliver an FPIN ELS
frame to an lpfc or qla2xxx Linux initiator can trigger a non-return in
the generic FC transport. This is not a local userspace or IP network
path; the attacker must be able to inject fabric traffic, for example as
a compromised switch or fabric controller, or as a same-zone N_Port on a
fabric that permits source spoofing.

The Link-Integrity and Peer-Congestion FPIN walkers used a u8 loop
counter against the 32-bit on-wire pname_count field, and did not bound
pname_count by the descriptor body already validated by the TLV walker.
A pname_count of 256 therefore wraps the counter and keeps the loop
condition true indefinitely.

Factor the shared pname_list[] walk into one helper, widen the counter
to u32, and clamp pname_count against the entries that fit in the
descriptor body before iterating.

Fixes: 3dcfe0d ("scsi: fc: Parse FPIN packets and update statistics")
	Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4-7
	Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
	Reviewed-by: Christoph Hellwig <hch@lst.de>
	Reviewed-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/20260520133015.1018937-1-michael.bommarito@gmail.com
	Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
(cherry picked from commit a9a3923)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1605
cve CVE-2026-53182
Rebuild_History Non-Buildable kernel-4.18.0-553.163.1.el8_10
commit-author Yuqi Xu <xuyuqiabc@gmail.com>
commit 4cd9295

nl80211_parse_rnr_elems() stores the parsed element count in a
u8-backed cfg80211_rnr_elems::cnt field and uses that count to size
the flexible array allocation.

Reject nested NL80211_ATTR_EMA_RNR_ELEMS input once the count reaches
255, before incrementing it again. This keeps the parser aligned with
the data structure it fills and matches the existing bound check used
by nl80211_parse_mbssid_elems().

Fixes: dbbb27e ("cfg80211: support RNR for EMA AP")
	Cc: stable@kernel.org
	Reported-by: Yuan Tan <yuantan098@gmail.com>
	Reported-by: Zhengchuan Liang <zcliangcn@gmail.com>
	Reported-by: Xin Liu <bird@lzu.edu.cn>
Assisted-by: Codex:gpt-5.4
	Signed-off-by: Yuqi Xu <xuyuqiabc@gmail.com>
	Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
Link: https://patch.msgid.link/20260529152542.1412734-1-n05ec@lzu.edu.cn
	Signed-off-by: Johannes Berg <johannes.berg@intel.com>
(cherry picked from commit 4cd9295)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1605
cve CVE-2025-71127
Rebuild_History Non-Buildable kernel-4.18.0-553.163.1.el8_10
commit-author Jouni Malinen <jouni.malinen@oss.qualcomm.com>
commit 193d18f

Beacon frames are required to be sent to the broadcast address, see IEEE
Std 802.11-2020, 11.1.3.1 ("The Address 1 field of the Beacon .. frame
shall be set to the broadcast address"). A unicast Beacon frame might be
used as a targeted attack to get one of the associated STAs to do
something (e.g., using CSA to move it to another channel). As such, it
is better have strict filtering for this on the received side and
discard all Beacon frames that are sent to an unexpected address.

This is even more important for cases where beacon protection is used.
The current implementation in mac80211 is correctly discarding unicast
Beacon frames if the Protected Frame bit in the Frame Control field is
set to 0. However, if that bit is set to 1, the logic used for checking
for configured BIGTK(s) does not actually work. If the driver does not
have logic for dropping unicast Beacon frames with Protected Frame bit
1, these frames would be accepted in mac80211 processing as valid Beacon
frames even though they are not protected. This would allow beacon
protection to be bypassed. While the logic for checking beacon
protection could be extended to cover this corner case, a more generic
check for discard all Beacon frames based on A1=unicast address covers
this without needing additional changes.

Address all these issues by dropping received Beacon frames if they are
sent to a non-broadcast address.

	Cc: stable@vger.kernel.org
Fixes: af2d14b ("mac80211: Beacon protection using the new BIGTK (STA)")
	Signed-off-by: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
Link: https://patch.msgid.link/20251215151134.104501-1-jouni.malinen@oss.qualcomm.com
	Signed-off-by: Johannes Berg <johannes.berg@intel.com>
(cherry picked from commit 193d18f)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1605
cve CVE-2026-64117
Rebuild_History Non-Buildable kernel-4.18.0-553.163.1.el8_10
commit-author Sarika Sharma <sarika.sharma@oss.qualcomm.com>
commit cc18fff

Currently, RX bitrate statistics are not updated for packets received
on the mesh forwarding path during fast RX processing. This results in
incomplete RX rate tracking in station dump outputs for mesh scenarios.

Update ieee80211_invoke_fast_rx() to record the RX rate using
sta_stats_encode_rate() and store it in the last_rate field of
ieee80211_sta_rx_stats when RX_QUEUED is returned from
ieee80211_rx_mesh_data(). This ensures that RX bitrate is properly
accounted for in both RSS and non-RSS paths.

	Signed-off-by: Sarika Sharma <sarika.sharma@oss.qualcomm.com>
Link: https://patch.msgid.link/20251024043627.1640447-1-sarika.sharma@oss.qualcomm.com
	Signed-off-by: Johannes Berg <johannes.berg@intel.com>
(cherry picked from commit cc18fff)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1605
cve CVE-2026-64117
Rebuild_History Non-Buildable kernel-4.18.0-553.163.1.el8_10
commit-author Zhao Li <enderaoelyther@gmail.com>
commit d71c841

ieee80211_invoke_fast_rx() reads RX status through
IEEE80211_SKB_RXCB(skb), which aliases the same skb->cb storage
that ieee80211_rx_mesh_data() reuses as IEEE80211_TX_INFO.  In the
unicast forward path, mesh_data does:

	info = IEEE80211_SKB_CB(fwd_skb);
	memset(info, 0, sizeof(*info));

on the same skb the caller still names via rx->skb, then either
queues the skb for TX (success) or kfree_skb()'s it (no-route)
before returning RX_QUEUED.  The caller's RX_QUEUED arm then
calls sta_stats_encode_rate(status) on memory that is either
zeroed (success path) or freed (no-route path).  The latter is
KASAN slab-use-after-free in ieee80211_prepare_and_rx_handle.

Fix by encoding the rate from status before invoking
ieee80211_rx_mesh_data(), so the RX_QUEUED arm consumes a value
captured while status was still backed by valid memory.

Fixes: 3468e1e ("wifi: mac80211: add mesh fast-rx support")
	Cc: stable@vger.kernel.org
	Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260509043427.60322-2-enderaoelyther@gmail.com
	Signed-off-by: Johannes Berg <johannes.berg@intel.com>
(cherry picked from commit d71c841)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1605
cve CVE-2026-68294
Rebuild_History Non-Buildable kernel-4.18.0-553.163.1.el8_10
Rebuild_CHGLOG: - net: qrtr: restrict socket creation to the initial network namespace (Jose Ignacio Tornos Martinez) [RHEL-239090] {CVE-2026-68294}
Rebuild_FUZZ: 80.30%
commit-author Greg Jumper <greg.jumper@oracle.com>
commit ebf71dd
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-4.18.0-553.163.1.el8_10/ebf71dd4.failed

Prevent using RDS/IB in network namespaces other than the initial one.
The existing RDS/IB code will not work properly in non-initial network
namespaces.

Fixes: d5a8ac2 ("RDS-TCP: Make RDS-TCP work correctly when it is set up in a netns other than init_net")
	Reported-by: syzbot+da8e060735ae02c8f3d1@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=da8e060735ae02c8f3d1
	Signed-off-by: Greg Jumper <greg.jumper@oracle.com>
	Signed-off-by: Allison Henderson <achender@kernel.org>
Link: https://patch.msgid.link/20260408080420.540032-3-achender@kernel.org
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit ebf71dd)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/rds/af_rds.c
#	net/rds/ib.c
jira KERNEL-1605
cve CVE-2024-53161
Rebuild_History Non-Buildable kernel-4.18.0-553.163.1.el8_10
commit-author David Thompson <davthompson@nvidia.com>
commit 1fe774a

The 64-bit argument for the "get DIMM info" SMC call consists of mem_ctrl_idx
left-shifted 16 bits and OR-ed with DIMM index.  With mem_ctrl_idx defined as
32-bits wide the left-shift operation truncates the upper 16 bits of
information during the calculation of the SMC argument.

The mem_ctrl_idx stack variable must be defined as 64-bits wide to prevent any
potential integer overflow, i.e. loss of data from upper 16 bits.

Fixes: 82413e5 ("EDAC, mellanox: Add ECC support for BlueField DDR4")
	Signed-off-by: David Thompson <davthompson@nvidia.com>
	Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
	Reviewed-by: Shravan Kumar Ramani <shravankr@nvidia.com>
Link: https://lore.kernel.org/r/20240930151056.10158-1-davthompson@nvidia.com
(cherry picked from commit 1fe774a)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
Rebuild_History BUILDABLE
Rebuilding Kernel from rpm changelog with Fuzz Limit: 87.50%
Number of commits in upstream range v4.18~1..kernel-mainline: 625874
Number of commits in rpm: 19
Number of commits matched with upstream: 9 (47.37%)
Number of commits in upstream but not in rpm: 625865
Number of commits NOT found in upstream: 10 (52.63%)

Rebuilding Kernel on Branch rocky8_10_rebuild_kernel-4.18.0-553.163.1.el8_10 for kernel-4.18.0-553.163.1.el8_10
Clean Cherry Picks: 7 (77.78%)
Empty Cherry Picks: 1 (11.11%)
_______________________________

Full Details Located here:
ciq/ciq_backports/kernel-4.18.0-553.163.1.el8_10/rebuild.details.txt

Includes:
* git commit header above
* Empty Commits with upstream SHA
* RPM ChangeLog Entries that could not be matched

Individual Empty Commit failures contained in the same containing directory.
The git message for empty commits will have the path for the failed commit.
File names are the first 8 characters of the upstream SHA
@PlaidCat PlaidCat self-assigned this Sep 16, 2026
@PlaidCat
PlaidCat requested review from a team September 16, 2026 10:47

@bmastbergen bmastbergen left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🥌

@bmastbergen
bmastbergen requested a review from a team September 16, 2026 14:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants