Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
53 commits
Select commit Hold shift + click to select a range
48be6be
rxrpc: only handle RESPONSE during service challenge
PlaidCat Aug 4, 2026
978b3ad
rxrpc: Fix conn-level packet handling to unshare RESPONSE packets
PlaidCat Aug 4, 2026
f7d6edc
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
PlaidCat Aug 4, 2026
2503184
rxrpc: Fix missing error checks for rxkad encryption/decryption failure
PlaidCat Aug 4, 2026
0d28ca1
rxrpc: Fix memory leaks in rxkad_verify_response()
PlaidCat Aug 4, 2026
37ee978
rxrpc: Fix rxkad crypto unalignment handling
PlaidCat Aug 4, 2026
da7af4f
rxgk: Fix potential integer overflow in length check
PlaidCat Aug 4, 2026
f133d56
rxrpc: Fix buffer overread in rxgk_do_verify_authenticator()
PlaidCat Aug 4, 2026
4c3a80d
rxrpc: Fix leak of rxgk context in rxgk_verify_response()
PlaidCat Aug 4, 2026
9cb14fa
rxrpc: Fix integer overflow in rxgk_verify_response()
PlaidCat Aug 4, 2026
6b3b031
rxrpc: fix oversized RESPONSE authenticator length check
PlaidCat Aug 4, 2026
586e4b3
crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks
PlaidCat Aug 4, 2026
d9f20a9
rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg
PlaidCat Aug 4, 2026
77fe052
rxrpc: Fix RESPONSE packet verification to extract skb to a linear bu…
PlaidCat Aug 4, 2026
0bb0ba3
rxrpc: Fix the ACK parser to extract the SACK table for parsing
PlaidCat Aug 4, 2026
b5fa763
rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc
PlaidCat Aug 4, 2026
a65d701
net: bridge: use a stable FDB dst snapshot in RCU readers
PlaidCat Aug 4, 2026
a1d3b5d
iommu/vt-d: Fix oops due to out of scope access
PlaidCat Aug 4, 2026
f03a848
iommu/vt-d: Avoid NULL pointer dereference or refcount corruption
PlaidCat Aug 4, 2026
ad1c8e4
tipc: fix double-free in tipc_buf_append()
PlaidCat Aug 4, 2026
2755995
ipv6: fix possible UAF in icmpv6_rcv()
PlaidCat Aug 4, 2026
c632f54
Rebuild rocky10_2 with kernel-6.12.0-211.40.1.el10_2
PlaidCat Aug 4, 2026
9a71efb
ASoC: Intel: sof_sdw: append dai type to dai link name unconditionally
PlaidCat Aug 4, 2026
ff3762f
isofs: validate Rock Ridge CE continuation extent against volume size
PlaidCat Aug 4, 2026
920a6a2
ksm: use range-walk function to jump over holes in scan_get_next_rmap…
PlaidCat Aug 4, 2026
f837028
net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
PlaidCat Aug 4, 2026
77d802e
Rebuild rocky10_2 with kernel-6.12.0-211.42.1.el10_2
PlaidCat Aug 4, 2026
b663f0a
net: wwan: t7xx: Add delay between MD and SAP suspend
PlaidCat Aug 4, 2026
50e064a
timers: Fix NULL function pointer race in timer_shutdown_sync()
PlaidCat Aug 4, 2026
f6854fe
procfs: avoid fetching build ID while holding VMA lock
PlaidCat Aug 4, 2026
9a7d3b8
procfs: fix possible double mmput() in do_procmap_query()
PlaidCat Aug 4, 2026
ea1628f
drm/i915/alpm: ALPM disable fixes
PlaidCat Aug 4, 2026
df04a2f
drm/i915/psr: Don't enable Panel Replay on sink if globally disabled
PlaidCat Aug 4, 2026
9ff2004
drm/i915/psr: Block DC states on vblank enable when Panel Replay supp…
PlaidCat Aug 4, 2026
113a2fc
drm/i915/psr: Use DC_OFF wake reference to block DC6 on vblank enable
PlaidCat Aug 4, 2026
ae2df57
dpll: export __dpll_pin_change_ntf() for use under dpll_lock
PlaidCat Aug 4, 2026
ab2494f
dpll: Prevent duplicate registrations
PlaidCat Aug 4, 2026
8797b8f
dpll: zl3073x: Use named initializers for struct i2c_device_id
PlaidCat Aug 4, 2026
fca60f7
dpll: zl3073x: fix memory leak on pin registration failure
PlaidCat Aug 4, 2026
cf755d2
dpll: change dpll_netdev_pin_handle_size() to assume DPLL_A_PIN_ID wi…
PlaidCat Aug 4, 2026
01c71c9
dpll: export __dpll_device_change_ntf() for use under dpll_lock
PlaidCat Aug 4, 2026
c7eb285
dpll: zl3073x: use __dpll_device_change_ntf() and remove change_work
PlaidCat Aug 4, 2026
0480a3c
dpll: zl3073x: make frequency monitor a per-device attribute
PlaidCat Aug 4, 2026
f603ad6
dpll: add generic DPLL type
PlaidCat Aug 4, 2026
bd5362c
dpll: allow registering FW-identified pin with a different DPLL
PlaidCat Aug 4, 2026
9b3faa0
dpll: fix stale iteration in dpll_pin_on_pin_unregister()
PlaidCat Aug 4, 2026
03fab2e
dpll: send delete notification before unregister in on-pin rollback
PlaidCat Aug 4, 2026
b1d445d
dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister()
PlaidCat Aug 4, 2026
f4d4584
dpll: guard sync-pair removal on full pin unregister
PlaidCat Aug 4, 2026
95c9b7d
dpll: balance create/delete notifications in __dpll_pin_(un)register
PlaidCat Aug 4, 2026
e72ed4a
dpll: extend pin notifier with notification source ID
PlaidCat Aug 4, 2026
4c37200
dpll: allow fwnode pins to attempt state change without capability bit
PlaidCat Aug 4, 2026
b0367ae
Rebuild rocky10_2 with kernel-6.12.0-211.43.1.el10_2
PlaidCat Aug 4, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
File renamed without changes.
3 changes: 3 additions & 0 deletions Documentation/netlink/specs/dpll.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -138,6 +138,9 @@ definitions:
-
name: eec
doc: dpll drives the Ethernet Equipment Clock
-
name: generic
doc: generic dpll type for devices outside PPS/EEC classes
render-max: true
-
type: enum
Expand Down
2 changes: 1 addition & 1 deletion Makefile.rhelver
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ RHEL_MINOR = 2
#
# Use this spot to avoid future merge conflicts.
# Do not trim this comment.
RHEL_RELEASE = 211.39.1
RHEL_RELEASE = 211.43.1

#
# RHEL_REBASE_NUM
Expand Down
94 changes: 94 additions & 0 deletions ciq/ciq_backports/kernel-6.12.0-211.40.1.el10_2/16c8ae97.failed
Original file line number Diff line number Diff line change
@@ -0,0 +1,94 @@
rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc

jira KERNEL-1416
Rebuild_History Non-Buildable kernel-6.12.0-211.40.1.el10_2
commit-author Jeffrey Altman <jaltman@auristor.com>
commit 16c8ae9735c5bd7e54dd7478d6348e0fc860842d
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-6.12.0-211.40.1.el10_2/16c8ae97.failed

rxrpc_recvmsg_data() calls rxrpc_verify_data() whenever the
rxrpc_call.rx_dec_buffer is unallocated and assumes that upon
successful return that rx_dec_buffer must be allocated.
However, rxrpc_verify_data() does not request an allocation if
the rxrpc_skb_priv.len is zero.

In addition, failure to allocate rx_dec_buffer will result in a
call to skb_copy_bits() with a NULL destination which can
trigger a NULL pointer dereference.

To prevent these issues rxrpc_verify_data() is modified to
always attempt to allocate the rxrpc_call.rx_dec_buffer if it
is NULL.

This issue was identified with assistance of a private
sashiko instance.

Fixes: d2bc90cf6c75cb ("rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg")
Reported-by: Simon Horman <simon.horman@redhat.com>
Signed-off-by: Jeffrey Altman <jaltman@auristor.com>
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Jiayuan Chen <jiayuan.chen@linux.dev>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: linux-afs@lists.infradead.org
cc: stable@kernel.org
Link: https://patch.msgid.link/20260609140911.838677-2-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 16c8ae9735c5bd7e54dd7478d6348e0fc860842d)
Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
# net/rxrpc/recvmsg.c
diff --cc net/rxrpc/recvmsg.c
index 7fa7e77f6bb9,a3cf5358f16e..000000000000
--- a/net/rxrpc/recvmsg.c
+++ b/net/rxrpc/recvmsg.c
@@@ -152,10 -159,40 +152,45 @@@ static void rxrpc_rotate_rx_window(stru
static int rxrpc_verify_data(struct rxrpc_call *call, struct sk_buff *skb)
{
struct rxrpc_skb_priv *sp = rxrpc_skb(skb);
- int ret;

++<<<<<<< HEAD
+ if (sp->flags & RXRPC_RX_VERIFIED)
+ return 0;
+ return call->security->verify_packet(call, skb);
++=======
+ if (sp->len > call->rx_dec_bsize || !call->rx_dec_buffer) {
+ /* Make sure we can hold a 1412-byte jumbo subpacket and make
+ * sure that the buffer size is aligned to a crypto blocksize.
+ */
+ size_t size = clamp(round_up(sp->len, 32), 2048, 65535);
+ void *buffer = krealloc(call->rx_dec_buffer, size, GFP_NOFS);
+
+ if (!buffer)
+ return -ENOMEM;
+ call->rx_dec_buffer = buffer;
+ call->rx_dec_bsize = size;
+ }
+
+ ret = -EFAULT;
+ if (skb_copy_bits(skb, sp->offset, call->rx_dec_buffer, sp->len) < 0)
+ goto err;
+
+ call->rx_dec_offset = 0;
+ call->rx_dec_len = sp->len;
+ call->rx_dec_seq = sp->hdr.seq;
+ ret = call->security->verify_packet(call, skb);
+ if (ret < 0)
+ goto err;
+ return 0;
+
+ err:
+ kfree(call->rx_dec_buffer);
+ call->rx_dec_buffer = NULL;
+ call->rx_dec_bsize = 0;
+ call->rx_dec_offset = 0;
+ call->rx_dec_len = 0;
+ return ret;
++>>>>>>> 16c8ae9735c5 (rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc)
}

/*
* Unmerged path net/rxrpc/recvmsg.c
179 changes: 179 additions & 0 deletions ciq/ciq_backports/kernel-6.12.0-211.40.1.el10_2/2b50acea.failed
Original file line number Diff line number Diff line change
@@ -0,0 +1,179 @@
crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks

jira KERNEL-1416
Rebuild_History Non-Buildable kernel-6.12.0-211.40.1.el10_2
commit-author David Howells <dhowells@redhat.com>
commit 2b50aceafe6606ea52ed42aadd1b4d44a188aade
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-6.12.0-211.40.1.el10_2/2b50acea.failed

Change the krb5 crypto library to provide facilities to precheck the length
of the message about to be decrypted or verified.

Fix AF_RXRPC to make use of this to validate DATA packets secured with
RxGK.

Fixes: 9d1d2b59341f ("rxrpc: rxgk: Implement the yfs-rxgk security class (GSSAPI)")
Closes: https://sashiko.dev/#/patchset/20260511160753.607296-1-dhowells%40redhat.com
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Herbert Xu <herbert@gondor.apana.org.au>
cc: Simon Horman <horms@kernel.org>
cc: Chuck Lever <chuck.lever@oracle.com>
cc: linux-afs@lists.infradead.org
Reviewed-by: Jeffrey Altman <jaltman@auristor.com>
Tested-by: Marc Dionne <marc.dionne@auristor.com>
Link: https://patch.msgid.link/20260515230516.2718212-2-dhowells@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 2b50aceafe6606ea52ed42aadd1b4d44a188aade)
Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
# Documentation/crypto/krb5.rst
* Unmerged path Documentation/crypto/krb5.rst
* Unmerged path Documentation/crypto/krb5.rst
diff --git a/crypto/krb5/krb5_api.c b/crypto/krb5/krb5_api.c
index 2b20284fa0ab..03395b89cc61 100644
--- a/crypto/krb5/krb5_api.c
+++ b/crypto/krb5/krb5_api.c
@@ -134,27 +134,69 @@ EXPORT_SYMBOL(crypto_krb5_how_much_data);
* Find the offset and size of the data in a secure message so that this
* information can be used in the metadata buffer which will get added to the
* digest by crypto_krb5_verify_mic().
+ *
+ * Return: 0 if successful, -EBADMSG if the message is too short or -EINVAL if
+ * the mode is unsupported.
*/
-void crypto_krb5_where_is_the_data(const struct krb5_enctype *krb5,
- enum krb5_crypto_mode mode,
- size_t *_offset, size_t *_len)
+int crypto_krb5_where_is_the_data(const struct krb5_enctype *krb5,
+ enum krb5_crypto_mode mode,
+ size_t *_offset, size_t *_len)
{
switch (mode) {
case KRB5_CHECKSUM_MODE:
+ if (*_len < krb5->cksum_len)
+ return -EBADMSG;
*_offset += krb5->cksum_len;
*_len -= krb5->cksum_len;
- return;
+ return 0;
case KRB5_ENCRYPT_MODE:
+ if (*_len < krb5->conf_len + krb5->cksum_len)
+ return -EBADMSG;
*_offset += krb5->conf_len;
*_len -= krb5->conf_len + krb5->cksum_len;
- return;
+ return 0;
default:
WARN_ON_ONCE(1);
- return;
+ return -EINVAL;
}
}
EXPORT_SYMBOL(crypto_krb5_where_is_the_data);

+/**
+ * crypto_krb5_check_data_len - Check a message is big enough
+ * @krb5: The encoding to use.
+ * @mode: Mode of operation.
+ * @len: The length of the secure blob.
+ * @min_content: Minimum length of the content inside the blob.
+ *
+ * Check that a message is large enough to hold whatever bits the encryption
+ * type wants to glue on (nonce, checksum) plus a minimum amount of content.
+ *
+ * Return: 0 if successful, -EBADMSG if the message is too short or -EINVAL if
+ * the mode is unsupported.
+ */
+int crypto_krb5_check_data_len(const struct krb5_enctype *krb5,
+ enum krb5_crypto_mode mode,
+ size_t len, size_t min_content)
+{
+ switch (mode) {
+ case KRB5_CHECKSUM_MODE:
+ if (len < krb5->cksum_len ||
+ len - krb5->cksum_len < min_content)
+ return -EBADMSG;
+ return 0;
+ case KRB5_ENCRYPT_MODE:
+ if (len < krb5->conf_len + krb5->cksum_len ||
+ len - (krb5->conf_len + krb5->cksum_len) < min_content)
+ return -EBADMSG;
+ return 0;
+ default:
+ WARN_ON_ONCE(1);
+ return -EINVAL;
+ }
+}
+EXPORT_SYMBOL(crypto_krb5_check_data_len);
+
/*
* Prepare the encryption with derived key data.
*/
diff --git a/include/crypto/krb5.h b/include/crypto/krb5.h
index 71dd38f59be1..aac3ecf88467 100644
--- a/include/crypto/krb5.h
+++ b/include/crypto/krb5.h
@@ -121,9 +121,12 @@ size_t crypto_krb5_how_much_buffer(const struct krb5_enctype *krb5,
size_t crypto_krb5_how_much_data(const struct krb5_enctype *krb5,
enum krb5_crypto_mode mode,
size_t *_buffer_size, size_t *_offset);
-void crypto_krb5_where_is_the_data(const struct krb5_enctype *krb5,
- enum krb5_crypto_mode mode,
- size_t *_offset, size_t *_len);
+int crypto_krb5_where_is_the_data(const struct krb5_enctype *krb5,
+ enum krb5_crypto_mode mode,
+ size_t *_offset, size_t *_len);
+int crypto_krb5_check_data_len(const struct krb5_enctype *krb5,
+ enum krb5_crypto_mode mode,
+ size_t len, size_t min_content);
struct crypto_aead *crypto_krb5_prepare_encryption(const struct krb5_enctype *krb5,
const struct krb5_buffer *TK,
u32 usage, gfp_t gfp);
diff --git a/include/trace/events/rxrpc.h b/include/trace/events/rxrpc.h
index 9c03f77e834c..04b6acc0dd31 100644
--- a/include/trace/events/rxrpc.h
+++ b/include/trace/events/rxrpc.h
@@ -71,6 +71,7 @@
EM(rxkad_abort_resp_unknown_tkt, "rxkad-resp-unknown-tkt") \
EM(rxkad_abort_resp_version, "rxkad-resp-version") \
/* RxGK security errors */ \
+ EM(rxgk_abort_1_short_header, "rxgk1-short-hdr") \
EM(rxgk_abort_1_verify_mic_eproto, "rxgk1-vfy-mic-eproto") \
EM(rxgk_abort_2_decrypt_eproto, "rxgk2-dec-eproto") \
EM(rxgk_abort_2_short_data, "rxgk2-short-data") \
diff --git a/net/rxrpc/rxgk.c b/net/rxrpc/rxgk.c
index 2a8a17f5367b..56959947df57 100644
--- a/net/rxrpc/rxgk.c
+++ b/net/rxrpc/rxgk.c
@@ -480,8 +480,12 @@ static int rxgk_verify_packet_integrity(struct rxrpc_call *call,

_enter("");

- crypto_krb5_where_is_the_data(gk->krb5, KRB5_CHECKSUM_MODE,
- &data_offset, &data_len);
+ if (crypto_krb5_where_is_the_data(gk->krb5, KRB5_CHECKSUM_MODE,
+ &data_offset, &data_len) < 0) {
+ ret = rxrpc_abort_eproto(call, skb, RXGK_PACKETSHORT,
+ rxgk_abort_1_short_header);
+ goto put_gk;
+ }

hdr = kzalloc(sizeof(*hdr), GFP_NOFS);
if (!hdr)
@@ -529,6 +533,13 @@ static int rxgk_verify_packet_encrypted(struct rxrpc_call *call,

_enter("");

+ if (crypto_krb5_check_data_len(gk->krb5, KRB5_ENCRYPT_MODE,
+ len, sizeof(hdr)) < 0) {
+ ret = rxrpc_abort_eproto(call, skb, RXGK_PACKETSHORT,
+ rxgk_abort_2_short_header);
+ goto error;
+ }
+
ret = rxgk_decrypt_skb(gk->krb5, gk->rx_enc, skb, &offset, &len, &ac);
if (ret < 0) {
if (ret != -ENOMEM)
Loading
Loading