All of lore.kernel.org
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-kernel@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	stable@vger.kernel.org, Eric Dumazet <edumazet@google.com>,
	syzbot <syzkaller@googlegroups.com>,
	"David S. Miller" <davem@davemloft.net>
Subject: [PATCH 4.14 117/143] ipv6: mcast: fix a use-after-free in inet6_mc_check
Date: Fri,  2 Nov 2018 19:35:02 +0100	[thread overview]
Message-ID: <20181102182907.205964718@linuxfoundation.org> (raw)
In-Reply-To: <20181102182857.064326086@linuxfoundation.org>

4.14-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit dc012f3628eaecfb5ba68404a5c30ef501daf63d ]

syzbot found a use-after-free in inet6_mc_check [1]

The problem here is that inet6_mc_check() uses rcu
and read_lock(&iml->sflock)

So the fact that ip6_mc_leave_src() is called under RTNL
and the socket lock does not help us, we need to acquire
iml->sflock in write mode.

In the future, we should convert all this stuff to RCU.

[1]
BUG: KASAN: use-after-free in ipv6_addr_equal include/net/ipv6.h:521 [inline]
BUG: KASAN: use-after-free in inet6_mc_check+0xae7/0xb40 net/ipv6/mcast.c:649
Read of size 8 at addr ffff8801ce7f2510 by task syz-executor0/22432

CPU: 1 PID: 22432 Comm: syz-executor0 Not tainted 4.19.0-rc7+ #280
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
 __dump_stack lib/dump_stack.c:77 [inline]
 dump_stack+0x1c4/0x2b4 lib/dump_stack.c:113
 print_address_description.cold.8+0x9/0x1ff mm/kasan/report.c:256
 kasan_report_error mm/kasan/report.c:354 [inline]
 kasan_report.cold.9+0x242/0x309 mm/kasan/report.c:412
 __asan_report_load8_noabort+0x14/0x20 mm/kasan/report.c:433
 ipv6_addr_equal include/net/ipv6.h:521 [inline]
 inet6_mc_check+0xae7/0xb40 net/ipv6/mcast.c:649
 __raw_v6_lookup+0x320/0x3f0 net/ipv6/raw.c:98
 ipv6_raw_deliver net/ipv6/raw.c:183 [inline]
 raw6_local_deliver+0x3d3/0xcb0 net/ipv6/raw.c:240
 ip6_input_finish+0x467/0x1aa0 net/ipv6/ip6_input.c:345
 NF_HOOK include/linux/netfilter.h:289 [inline]
 ip6_input+0xe9/0x600 net/ipv6/ip6_input.c:426
 ip6_mc_input+0x48a/0xd20 net/ipv6/ip6_input.c:503
 dst_input include/net/dst.h:450 [inline]
 ip6_rcv_finish+0x17a/0x330 net/ipv6/ip6_input.c:76
 NF_HOOK include/linux/netfilter.h:289 [inline]
 ipv6_rcv+0x120/0x640 net/ipv6/ip6_input.c:271
 __netif_receive_skb_one_core+0x14d/0x200 net/core/dev.c:4913
 __netif_receive_skb+0x2c/0x1e0 net/core/dev.c:5023
 netif_receive_skb_internal+0x12c/0x620 net/core/dev.c:5126
 napi_frags_finish net/core/dev.c:5664 [inline]
 napi_gro_frags+0x75a/0xc90 net/core/dev.c:5737
 tun_get_user+0x3189/0x4250 drivers/net/tun.c:1923
 tun_chr_write_iter+0xb9/0x154 drivers/net/tun.c:1968
 call_write_iter include/linux/fs.h:1808 [inline]
 do_iter_readv_writev+0x8b0/0xa80 fs/read_write.c:680
 do_iter_write+0x185/0x5f0 fs/read_write.c:959
 vfs_writev+0x1f1/0x360 fs/read_write.c:1004
 do_writev+0x11a/0x310 fs/read_write.c:1039
 __do_sys_writev fs/read_write.c:1112 [inline]
 __se_sys_writev fs/read_write.c:1109 [inline]
 __x64_sys_writev+0x75/0xb0 fs/read_write.c:1109
 do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
 entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x457421
Code: 75 14 b8 14 00 00 00 0f 05 48 3d 01 f0 ff ff 0f 83 34 b5 fb ff c3 48 83 ec 08 e8 1a 2d 00 00 48 89 04 24 b8 14 00 00 00 0f 05 <48> 8b 3c 24 48 89 c2 e8 63 2d 00 00 48 89 d0 48 83 c4 08 48 3d 01
RSP: 002b:00007f2d30ecaba0 EFLAGS: 00000293 ORIG_RAX: 0000000000000014
RAX: ffffffffffffffda RBX: 000000000000003e RCX: 0000000000457421
RDX: 0000000000000001 RSI: 00007f2d30ecabf0 RDI: 00000000000000f0
RBP: 0000000020000500 R08: 00000000000000f0 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000293 R12: 00007f2d30ecb6d4
R13: 00000000004c4890 R14: 00000000004d7b90 R15: 00000000ffffffff

Allocated by task 22437:
 save_stack+0x43/0xd0 mm/kasan/kasan.c:448
 set_track mm/kasan/kasan.c:460 [inline]
 kasan_kmalloc+0xc7/0xe0 mm/kasan/kasan.c:553
 __do_kmalloc mm/slab.c:3718 [inline]
 __kmalloc+0x14e/0x760 mm/slab.c:3727
 kmalloc include/linux/slab.h:518 [inline]
 sock_kmalloc+0x15a/0x1f0 net/core/sock.c:1983
 ip6_mc_source+0x14dd/0x1960 net/ipv6/mcast.c:427
 do_ipv6_setsockopt.isra.9+0x3afb/0x45d0 net/ipv6/ipv6_sockglue.c:743
 ipv6_setsockopt+0xbd/0x170 net/ipv6/ipv6_sockglue.c:933
 rawv6_setsockopt+0x59/0x140 net/ipv6/raw.c:1069
 sock_common_setsockopt+0x9a/0xe0 net/core/sock.c:3038
 __sys_setsockopt+0x1ba/0x3c0 net/socket.c:1902
 __do_sys_setsockopt net/socket.c:1913 [inline]
 __se_sys_setsockopt net/socket.c:1910 [inline]
 __x64_sys_setsockopt+0xbe/0x150 net/socket.c:1910
 do_syscall_64+0x1b9/0x820 arch/x86/entry/common.c:290
 entry_SYSCALL_64_after_hwframe+0x49/0xbe

Freed by task 22430:
 save_stack+0x43/0xd0 mm/kasan/kasan.c:448
 set_track mm/kasan/kasan.c:460 [inline]
 __kasan_slab_free+0x102/0x150 mm/kasan/kasan.c:521
 kasan_slab_free+0xe/0x10 mm/kasan/kasan.c:528
 __cache_free mm/slab.c:3498 [inline]
 kfree+0xcf/0x230 mm/slab.c:3813
 __sock_kfree_s net/core/sock.c:2004 [inline]
 sock_kfree_s+0x29/0x60 net/core/sock.c:2010
 ip6_mc_leave_src+0x11a/0x1d0 net/ipv6/mcast.c:2448
 __ipv6_sock_mc_close+0x20b/0x4e0 net/ipv6/mcast.c:310
 ipv6_sock_mc_close+0x158/0x1d0 net/ipv6/mcast.c:328
 inet6_release+0x40/0x70 net/ipv6/af_inet6.c:452
 __sock_release+0xd7/0x250 net/socket.c:579
 sock_close+0x19/0x20 net/socket.c:1141
 __fput+0x385/0xa30 fs/file_table.c:278
 ____fput+0x15/0x20 fs/file_table.c:309
 task_work_run+0x1e8/0x2a0 kernel/task_work.c:113
 tracehook_notify_resume include/linux/tracehook.h:193 [inline]
 exit_to_usermode_loop+0x318/0x380 arch/x86/entry/common.c:166
 prepare_exit_to_usermode arch/x86/entry/common.c:197 [inline]
 syscall_return_slowpath arch/x86/entry/common.c:268 [inline]
 do_syscall_64+0x6be/0x820 arch/x86/entry/common.c:293
 entry_SYSCALL_64_after_hwframe+0x49/0xbe

The buggy address belongs to the object at ffff8801ce7f2500
 which belongs to the cache kmalloc-192 of size 192
The buggy address is located 16 bytes inside of
 192-byte region [ffff8801ce7f2500, ffff8801ce7f25c0)
The buggy address belongs to the page:
page:ffffea000739fc80 count:1 mapcount:0 mapping:ffff8801da800040 index:0x0
flags: 0x2fffc0000000100(slab)
raw: 02fffc0000000100 ffffea0006f6e548 ffffea000737b948 ffff8801da800040
raw: 0000000000000000 ffff8801ce7f2000 0000000100000010 0000000000000000
page dumped because: kasan: bad access detected

Memory state around the buggy address:
 ffff8801ce7f2400: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
 ffff8801ce7f2480: fb fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc
>ffff8801ce7f2500: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
                         ^
 ffff8801ce7f2580: fb fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc
 ffff8801ce7f2600: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: syzbot <syzkaller@googlegroups.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/ipv6/mcast.c |   16 ++++++++--------
 1 file changed, 8 insertions(+), 8 deletions(-)

--- a/net/ipv6/mcast.c
+++ b/net/ipv6/mcast.c
@@ -2412,17 +2412,17 @@ static int ip6_mc_leave_src(struct sock
 {
 	int err;
 
-	/* callers have the socket lock and rtnl lock
-	 * so no other readers or writers of iml or its sflist
-	 */
+	write_lock_bh(&iml->sflock);
 	if (!iml->sflist) {
 		/* any-source empty exclude case */
-		return ip6_mc_del_src(idev, &iml->addr, iml->sfmode, 0, NULL, 0);
+		err = ip6_mc_del_src(idev, &iml->addr, iml->sfmode, 0, NULL, 0);
+	} else {
+		err = ip6_mc_del_src(idev, &iml->addr, iml->sfmode,
+				iml->sflist->sl_count, iml->sflist->sl_addr, 0);
+		sock_kfree_s(sk, iml->sflist, IP6_SFLSIZE(iml->sflist->sl_max));
+		iml->sflist = NULL;
 	}
-	err = ip6_mc_del_src(idev, &iml->addr, iml->sfmode,
-		iml->sflist->sl_count, iml->sflist->sl_addr, 0);
-	sock_kfree_s(sk, iml->sflist, IP6_SFLSIZE(iml->sflist->sl_max));
-	iml->sflist = NULL;
+	write_unlock_bh(&iml->sflock);
 	return err;
 }
 



  parent reply	other threads:[~2018-11-02 18:54 UTC|newest]

Thread overview: 171+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-11-02 18:33 [PATCH 4.14 000/143] 4.14.79-stable review Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 001/143] xfrm: Validate address prefix lengths in the xfrm selector Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 002/143] xfrm6: call kfree_skb when skb is toobig Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 003/143] xfrm: reset transport header back to network header after all input transforms ahave been applied Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 004/143] xfrm: reset crypto_done when iterating over multiple input xfrms Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 005/143] mac80211: Always report TX status Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 006/143] cfg80211: reg: Init wiphy_idx in regulatory_hint_core() Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 007/143] mac80211: fix pending queue hang due to TX_DROP Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 008/143] cfg80211: Address some corner cases in scan result channel updating Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 009/143] mac80211: TDLS: fix skb queue/priority assignment Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 010/143] mac80211: fix TX status reporting for ieee80211s Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 011/143] xfrm: Fix NULL pointer dereference when skb_dst_force clears the dst_entry Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 012/143] ARM: 8799/1: mm: fix pci_ioremap_io() offset check Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 013/143] xfrm: validate template mode Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 014/143] netfilter: bridge: Dont sabotage nf_hook calls from an l3mdev Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 015/143] arm64: hugetlb: Fix handling of young ptes Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 016/143] ARM: dts: BCM63xx: Fix incorrect interrupt specifiers Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 017/143] net: macb: Clean 64b dma addresses if they are not detected Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 018/143] soc: fsl: qbman: qman: avoid allocating from non existing gen_pool Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 019/143] soc: fsl: qe: Fix copy/paste bug in ucc_get_tdm_sync_shift() Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 020/143] nl80211: Fix possible Spectre-v1 for NL80211_TXRATE_HT Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 021/143] mac80211_hwsim: do not omit multicast announce of first added radio Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 022/143] Bluetooth: SMP: fix crash in unpairing Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 023/143] pxa168fb: prepare the clock Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 024/143] qed: Avoid implicit enum conversion in qed_set_tunn_cls_info Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 025/143] qed: Fix mask parameter in qed_vf_prep_tunn_req_tlv Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 026/143] qed: Avoid implicit enum conversion in qed_roce_mode_to_flavor Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 027/143] qed: Avoid constant logical operation warning in qed_vf_pf_acquire Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 028/143] qed: Avoid implicit enum conversion in qed_iwarp_parse_rx_pkt Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 029/143] nl80211: Fix possible Spectre-v1 for CQM RSSI thresholds Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 030/143] asix: Check for supported Wake-on-LAN modes Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 031/143] ax88179_178a: " Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 032/143] lan78xx: " Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 033/143] sr9800: " Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 034/143] r8152: Check for supported Wake-on-LAN Modes Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 035/143] smsc75xx: Check for Wake-on-LAN modes Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 036/143] smsc95xx: " Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 037/143] cfg80211: fix use-after-free in reg_process_hint() Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 038/143] perf/core: Fix perf_pmu_unregister() locking Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 039/143] perf/ring_buffer: Prevent concurent ring buffer access Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 040/143] perf/x86/intel/uncore: Fix PCI BDF address of M3UPI on SKX Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 041/143] perf/x86/amd/uncore: Set ThreadMask and SliceMask for L3 Cache perf events Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 042/143] net: fec: fix rare tx timeout Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 043/143] declance: Fix continuation with the adapter identification message Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 044/143] net: qualcomm: rmnet: Skip processing loopback packets Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 045/143] locking/ww_mutex: Fix runtime warning in the WW mutex selftest Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 046/143] be2net: dont flip hw_features when VXLANs are added/deleted Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 047/143] net: cxgb3_main: fix a missing-check bug Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 048/143] yam: " Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 049/143] ocfs2: fix crash in ocfs2_duplicate_clusters_by_page() Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 050/143] iwlwifi: mvm: check for short GI only for OFDM Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 051/143] iwlwifi: dbg: allow wrt collection before ALIVE Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 052/143] iwlwifi: fix the ALIVE notification layout Greg Kroah-Hartman
2018-11-02 18:33 ` [PATCH 4.14 053/143] x86/power: Fix some ordering bugs in __restore_processor_context() Greg Kroah-Hartman
2018-11-02 20:19   ` Sudip Mukherjee
2018-11-02 23:17     ` Sasha Levin
2018-11-03  8:40       ` Greg Kroah-Hartman
2018-11-03  8:41         ` Greg Kroah-Hartman
2018-11-03 12:51           ` Sasha Levin
2018-11-02 18:33 ` [PATCH 4.14 054/143] tools/testing/nvdimm: unit test clear-error commands Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 055/143] usbip: vhci_hcd: update status file header and format Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 056/143] scsi: aacraid: address UBSAN warning regression Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 057/143] IB/ipoib: Fix lockdep issue found on ipoib_ib_dev_heavy_flush Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 058/143] IB/rxe: put the pool on allocation failure Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 059/143] s390/qeth: fix error handling in adapter command callbacks Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 060/143] net/mlx5: Fix mlx5_get_vector_affinity function Greg Kroah-Hartman
2018-11-02 19:59   ` Sudip Mukherjee
2018-11-03  1:59     ` Sasha Levin
2018-11-02 18:34 ` [PATCH 4.14 061/143] powerpc/pseries: Add empty update_numa_cpu_lookup_table() for NUMA=n Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 062/143] dm integrity: fail early if required HMAC key is not available Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 063/143] net: phy: realtek: Use the dummy stubs for MMD register access for rtl8211b Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 064/143] net: phy: Add general dummy stubs for MMD register access Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 065/143] net/mlx5e: Refine ets validation function Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 066/143] scsi: qla2xxx: Avoid double completion of abort command Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 067/143] kbuild: set no-integrated-as before incl. arch Makefile Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 068/143] IB/mlx5: Avoid passing an invalid QP type to firmware Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 069/143] ARM: tegra: Fix ULPI regression on Tegra20 Greg Kroah-Hartman
2018-11-02 19:56   ` Sudip Mukherjee
2018-11-03  2:02     ` Sasha Levin
2018-11-05 14:05       ` Marcel Ziswiler
2018-11-06  6:31         ` Sasha Levin
2018-11-06  9:52           ` Marcel Ziswiler
2018-11-06 10:55           ` Dmitry Osipenko
2018-11-02 18:34 ` [PATCH 4.14 070/143] l2tp: remove configurable payload offset Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 071/143] cifs: Use ULL suffix for 64-bit constant Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 072/143] test_bpf: Fix testing with CONFIG_BPF_JIT_ALWAYS_ON=y on other arches Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 073/143] KVM: x86: Update the exit_qualification access bits while walking an address Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 074/143] sparc64: Fix regression in pmdp_invalidate() Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 075/143] tpm: move the delay_msec increment after sleep in tpm_transmit() Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 076/143] bpf: sockmap, map_release does not hold refcnt for pinned maps Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 077/143] tpm: tpm_crb: relinquish locality on error path Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 078/143] xen-netfront: Update features after registering netdev Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 079/143] xen-netfront: Fix mismatched rtnl_unlock Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 080/143] IB/usnic: Update with bug fixes from core code Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 081/143] mmc: dw_mmc-rockchip: correct property names in debug Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 082/143] MIPS: Workaround GCC __builtin_unreachable reordering bug Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 083/143] lan78xx: Dont reset the interface on open Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 084/143] enic: do not overwrite error code Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 085/143] iio: buffer: fix the function signature to match implementation Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 086/143] selftests/powerpc: Add ptrace hw breakpoint test Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 087/143] scsi: ibmvfc: Avoid unnecessary port relogin Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 088/143] scsi: sd: Remember that READ CAPACITY(16) succeeded Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 089/143] btrfs: quota: Set rescan progress to (u64)-1 if we hit last leaf Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 090/143] net: phy: phylink: Dont release NULL GPIO Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 091/143] x86/paravirt: Fix some warning messages Greg Kroah-Hartman
2018-11-02 18:34 ` Greg Kroah-Hartman
2018-11-02 18:34   ` Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 092/143] net: stmmac: mark PM functions as __maybe_unused Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 093/143] kconfig: fix the rule of mainmenu_stmt symbol Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 094/143] libertas: call into generic suspend code before turning off power Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 095/143] perf tests: Fix indexing when invoking subtests Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 096/143] compiler.h: Allow arch-specific asm/compiler.h Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 097/143] ARM: dts: imx53-qsb: disable 1.2GHz OPP Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 098/143] perf python: Use -Wno-redundant-decls to build with PYTHON=python3 Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 099/143] rxrpc: Dont check RXRPC_CALL_TX_LAST after calling rxrpc_rotate_tx_window() Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 100/143] rxrpc: Only take the rwind and mtu values from latest ACK Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 101/143] rxrpc: Fix connection-level abort handling Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 102/143] net: ena: fix warning in rmmod caused by double iounmap Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 103/143] net: ena: fix NULL dereference due to untimely napi initialization Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 104/143] selftests: rtnetlink.sh explicitly requires bash Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 105/143] fs/fat/fatent.c: add cond_resched() to fat_count_free_clusters() Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 106/143] sch_netem: restore skb->dev after dequeuing from the rbtree Greg Kroah-Hartman
2018-11-02 23:28   ` Josh Hunt
2018-11-03  2:03     ` Sasha Levin
2018-11-02 18:34 ` [PATCH 4.14 107/143] mtd: spi-nor: Add support for is25wp series chips Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 108/143] kvm: x86: fix WARN due to uninitialized guest FPU state Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 109/143] ARM: dts: r8a7790: Correct critical CPU temperature Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 110/143] media: uvcvideo: Fix driver reference counting Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 111/143] ALSA: usx2y: Fix invalid stream URBs Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 112/143] Revert "netfilter: ipv6: nf_defrag: drop skb dst before queueing" Greg Kroah-Hartman
2018-11-02 18:34   ` Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 113/143] perf tools: Disable parallelism for make clean Greg Kroah-Hartman
2018-11-02 18:34 ` [PATCH 4.14 114/143] drm/i915/gvt: fix memory leak of a cmd_entry struct on error exit path Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 115/143] bridge: do not add port to router list when receives query with source 0.0.0.0 Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 116/143] net: bridge: remove ipv6 zero address check in mcast queries Greg Kroah-Hartman
2018-11-02 18:35 ` Greg Kroah-Hartman [this message]
2018-11-02 18:35 ` [PATCH 4.14 118/143] ipv6/ndisc: Preserve IPv6 control buffer if protocol error handlers are called Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 119/143] llc: set SOCK_RCU_FREE in llc_sap_add_socket() Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 120/143] net: fec: dont dump RX FIFO register when not available Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 121/143] net/ipv6: Fix index counter for unicast addresses in in6_dump_addrs Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 122/143] net: sched: gred: pass the right attribute to gred_change_table_def() Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 123/143] net: socket: fix a missing-check bug Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 124/143] net: stmmac: Fix stmmac_mdio_reset() when building stmmac as modules Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 125/143] net: udp: fix handling of CHECKSUM_COMPLETE packets Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 126/143] r8169: fix NAPI handling under high load Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 127/143] sctp: fix race on sctp_id2asoc Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 128/143] udp6: fix encap return code for resubmitting Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 129/143] vhost: Fix Spectre V1 vulnerability Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 130/143] virtio_net: avoid using netif_tx_disable() for serializing tx routine Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 131/143] ethtool: fix a privilege escalation bug Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 132/143] bonding: fix length of actor system Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 133/143] ip6_tunnel: Fix encapsulation layout Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 134/143] openvswitch: Fix push/pop ethernet validation Greg Kroah-Hartman
2018-11-02 18:35   ` Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 135/143] net/mlx5: Take only bit 24-26 of wqe.pftype_wq for page fault type Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 136/143] net: sched: Fix for duplicate class dump Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 137/143] net: drop skb on failure in ip_check_defrag() Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 138/143] net: fix pskb_trim_rcsum_slow() with odd trim offset Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 139/143] net/mlx5e: fix csum adjustments caused by RXFCS Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 140/143] rtnetlink: Disallow FDB configuration for non-Ethernet device Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 141/143] net: ipmr: fix unresolved entry dumps Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 142/143] net: bcmgenet: Poll internal PHY for GENETv5 Greg Kroah-Hartman
2018-11-02 18:35 ` [PATCH 4.14 143/143] net/sched: cls_api: add missing validation of netlink attributes Greg Kroah-Hartman
2018-11-02 23:21 ` [PATCH 4.14 000/143] 4.14.79-stable review kernelci.org bot
2018-11-03 14:31 ` Guenter Roeck
2018-11-03 15:04   ` Greg Kroah-Hartman
2018-11-03 18:22     ` Guenter Roeck
2018-11-04  7:10       ` Greg Kroah-Hartman
2018-11-04  4:14     ` Naresh Kamboju
2018-11-05 11:21     ` Jon Hunter
2018-11-05 11:21       ` Jon Hunter

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20181102182907.205964718@linuxfoundation.org \
    --to=gregkh@linuxfoundation.org \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=syzkaller@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.