stable.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: stable@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	patches@lists.linux.dev, syzkaller <syzkaller@googlegroups.com>,
	George Kennedy <george.kennedy@oracle.com>,
	Richard Weinberger <richard@nod.at>,
	Sasha Levin <sashal@kernel.org>
Subject: [PATCH 5.15 012/136] ubi: ensure that VID header offset + VID header size <= alloc, size
Date: Fri, 10 Mar 2023 14:42:14 +0100	[thread overview]
Message-ID: <20230310133707.296049413@linuxfoundation.org> (raw)
In-Reply-To: <20230310133706.811226272@linuxfoundation.org>

From: George Kennedy <george.kennedy@oracle.com>

[ Upstream commit 1b42b1a36fc946f0d7088425b90d491b4257ca3e ]

Ensure that the VID header offset + VID header size does not exceed
the allocated area to avoid slab OOB.

BUG: KASAN: slab-out-of-bounds in crc32_body lib/crc32.c:111 [inline]
BUG: KASAN: slab-out-of-bounds in crc32_le_generic lib/crc32.c:179 [inline]
BUG: KASAN: slab-out-of-bounds in crc32_le_base+0x58c/0x626 lib/crc32.c:197
Read of size 4 at addr ffff88802bb36f00 by task syz-executor136/1555

CPU: 2 PID: 1555 Comm: syz-executor136 Tainted: G        W
6.0.0-1868 #1
Hardware name: Red Hat KVM, BIOS 1.13.0-2.module+el8.3.0+7860+a7792d29
04/01/2014
Call Trace:
  <TASK>
  __dump_stack lib/dump_stack.c:88 [inline]
  dump_stack_lvl+0x85/0xad lib/dump_stack.c:106
  print_address_description mm/kasan/report.c:317 [inline]
  print_report.cold.13+0xb6/0x6bb mm/kasan/report.c:433
  kasan_report+0xa7/0x11b mm/kasan/report.c:495
  crc32_body lib/crc32.c:111 [inline]
  crc32_le_generic lib/crc32.c:179 [inline]
  crc32_le_base+0x58c/0x626 lib/crc32.c:197
  ubi_io_write_vid_hdr+0x1b7/0x472 drivers/mtd/ubi/io.c:1067
  create_vtbl+0x4d5/0x9c4 drivers/mtd/ubi/vtbl.c:317
  create_empty_lvol drivers/mtd/ubi/vtbl.c:500 [inline]
  ubi_read_volume_table+0x67b/0x288a drivers/mtd/ubi/vtbl.c:812
  ubi_attach+0xf34/0x1603 drivers/mtd/ubi/attach.c:1601
  ubi_attach_mtd_dev+0x6f3/0x185e drivers/mtd/ubi/build.c:965
  ctrl_cdev_ioctl+0x2db/0x347 drivers/mtd/ubi/cdev.c:1043
  vfs_ioctl fs/ioctl.c:51 [inline]
  __do_sys_ioctl fs/ioctl.c:870 [inline]
  __se_sys_ioctl fs/ioctl.c:856 [inline]
  __x64_sys_ioctl+0x193/0x213 fs/ioctl.c:856
  do_syscall_x64 arch/x86/entry/common.c:50 [inline]
  do_syscall_64+0x3e/0x86 arch/x86/entry/common.c:80
  entry_SYSCALL_64_after_hwframe+0x63/0x0
RIP: 0033:0x7f96d5cf753d
Code:
RSP: 002b:00007fffd72206f8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f96d5cf753d
RDX: 0000000020000080 RSI: 0000000040186f40 RDI: 0000000000000003
RBP: 0000000000400cd0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000400be0
R13: 00007fffd72207e0 R14: 0000000000000000 R15: 0000000000000000
  </TASK>

Allocated by task 1555:
  kasan_save_stack+0x20/0x3d mm/kasan/common.c:38
  kasan_set_track mm/kasan/common.c:45 [inline]
  set_alloc_info mm/kasan/common.c:437 [inline]
  ____kasan_kmalloc mm/kasan/common.c:516 [inline]
  __kasan_kmalloc+0x88/0xa3 mm/kasan/common.c:525
  kasan_kmalloc include/linux/kasan.h:234 [inline]
  __kmalloc+0x138/0x257 mm/slub.c:4429
  kmalloc include/linux/slab.h:605 [inline]
  ubi_alloc_vid_buf drivers/mtd/ubi/ubi.h:1093 [inline]
  create_vtbl+0xcc/0x9c4 drivers/mtd/ubi/vtbl.c:295
  create_empty_lvol drivers/mtd/ubi/vtbl.c:500 [inline]
  ubi_read_volume_table+0x67b/0x288a drivers/mtd/ubi/vtbl.c:812
  ubi_attach+0xf34/0x1603 drivers/mtd/ubi/attach.c:1601
  ubi_attach_mtd_dev+0x6f3/0x185e drivers/mtd/ubi/build.c:965
  ctrl_cdev_ioctl+0x2db/0x347 drivers/mtd/ubi/cdev.c:1043
  vfs_ioctl fs/ioctl.c:51 [inline]
  __do_sys_ioctl fs/ioctl.c:870 [inline]
  __se_sys_ioctl fs/ioctl.c:856 [inline]
  __x64_sys_ioctl+0x193/0x213 fs/ioctl.c:856
  do_syscall_x64 arch/x86/entry/common.c:50 [inline]
  do_syscall_64+0x3e/0x86 arch/x86/entry/common.c:80
  entry_SYSCALL_64_after_hwframe+0x63/0x0

The buggy address belongs to the object at ffff88802bb36e00
  which belongs to the cache kmalloc-256 of size 256
The buggy address is located 0 bytes to the right of
  256-byte region [ffff88802bb36e00, ffff88802bb36f00)

The buggy address belongs to the physical page:
page:00000000ea4d1263 refcount:1 mapcount:0 mapping:0000000000000000
index:0x0 pfn:0x2bb36
head:00000000ea4d1263 order:1 compound_mapcount:0 compound_pincount:0
flags: 0xfffffc0010200(slab|head|node=0|zone=1|lastcpupid=0x1fffff)
raw: 000fffffc0010200 ffffea000066c300 dead000000000003 ffff888100042b40
raw: 0000000000000000 0000000000100010 00000001ffffffff 0000000000000000
page dumped because: kasan: bad access detected

Memory state around the buggy address:
  ffff88802bb36e00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  ffff88802bb36e80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
>ffff88802bb36f00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
                    ^
  ffff88802bb36f80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
  ffff88802bb37000: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
==================================================================

Fixes: 801c135ce73d ("UBI: Unsorted Block Images")
Reported-by: syzkaller <syzkaller@googlegroups.com>
Signed-off-by: George Kennedy <george.kennedy@oracle.com>
Signed-off-by: Richard Weinberger <richard@nod.at>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/mtd/ubi/build.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/mtd/ubi/build.c b/drivers/mtd/ubi/build.c
index a32050fecabf3..53aa4de6b963f 100644
--- a/drivers/mtd/ubi/build.c
+++ b/drivers/mtd/ubi/build.c
@@ -663,6 +663,12 @@ static int io_init(struct ubi_device *ubi, int max_beb_per1024)
 	ubi->ec_hdr_alsize = ALIGN(UBI_EC_HDR_SIZE, ubi->hdrs_min_io_size);
 	ubi->vid_hdr_alsize = ALIGN(UBI_VID_HDR_SIZE, ubi->hdrs_min_io_size);
 
+	if (ubi->vid_hdr_offset && ((ubi->vid_hdr_offset + UBI_VID_HDR_SIZE) >
+	    ubi->vid_hdr_alsize)) {
+		ubi_err(ubi, "VID header offset %d too large.", ubi->vid_hdr_offset);
+		return -EINVAL;
+	}
+
 	dbg_gen("min_io_size      %d", ubi->min_io_size);
 	dbg_gen("max_write_size   %d", ubi->max_write_size);
 	dbg_gen("hdrs_min_io_size %d", ubi->hdrs_min_io_size);
-- 
2.39.2




  parent reply	other threads:[~2023-03-10 15:21 UTC|newest]

Thread overview: 143+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-03-10 13:42 [PATCH 5.15 000/136] 5.15.100-rc1 review Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 001/136] net/sched: Retire tcindex classifier Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 002/136] auxdisplay: hd44780: Fix potential memory leak in hd44780_remove() Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 003/136] fs/jfs: fix shift exponent db_agl2size negative Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 004/136] objtool: Fix memory leak in create_static_call_sections() Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 005/136] pwm: sifive: Reduce time the controller lock is held Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 006/136] pwm: sifive: Always let the first pwm_apply_state succeed Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 007/136] pwm: stm32-lp: fix the check on arr and cmp registers update Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 008/136] f2fs: use memcpy_{to,from}_page() where possible Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 009/136] fs: f2fs: initialize fsdata in pagecache_write() Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 010/136] f2fs: allow set compression option of files without blocks Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 011/136] um: vector: Fix memory leak in vector_config Greg Kroah-Hartman
2023-03-10 13:42 ` Greg Kroah-Hartman [this message]
2023-03-10 13:42 ` [PATCH 5.15 013/136] ubifs: Fix build errors as symbol undefined Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 014/136] ubifs: Rectify space budget for ubifs_symlink() if symlink is encrypted Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 015/136] ubifs: Rectify space budget for ubifs_xrename() Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 016/136] ubifs: Fix wrong dirty space budget for dirty inode Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 017/136] ubifs: do_rename: Fix wrong space budget when target inodes nlink > 1 Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 018/136] ubifs: Reserve one leb for each journal head while doing budget Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 019/136] ubi: Fix use-after-free when volume resizing failed Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 020/136] ubi: Fix unreferenced object reported by kmemleak in ubi_resize_volume() Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 021/136] ubifs: Fix memory leak in alloc_wbufs() Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 022/136] ubi: Fix possible null-ptr-deref in ubi_free_volume() Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 023/136] ubifs: Re-statistic cleaned znode count if commit failed Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 024/136] ubifs: dirty_cow_znode: Fix memleak in error handling path Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 025/136] ubifs: ubifs_writepage: Mark page dirty after writing inode failed Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 026/136] ubi: fastmap: Fix missed fm_anchor PEB in wear-leveling after disabling fastmap Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 027/136] ubi: Fix UAF wear-leveling entry in eraseblk_count_seq_show() Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 028/136] ubi: ubi_wl_put_peb: Fix infinite loop when wear-leveling work failed Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 029/136] f2fs: fix to avoid potential memory corruption in __update_iostat_latency() Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 030/136] ext4: use ext4_fc_tl_mem in fast-commit replay path Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 031/136] netfilter: nf_tables: allow to fetch set elements when table has an owner Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 032/136] x86: um: vdso: Add %rcx and %r11 to the syscall clobber list Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 033/136] um: virtio_uml: free command if adding to virtqueue failed Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 034/136] um: virtio_uml: mark device as unregistered when breaking it Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 035/136] um: virtio_uml: move device breaking into workqueue Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 036/136] um: virt-pci: properly remove PCI device from bus Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 037/136] watchdog: at91sam9_wdt: use devm_request_irq to avoid missing free_irq() in error path Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 038/136] watchdog: Fix kmemleak in watchdog_cdev_register Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 039/136] watchdog: pcwd_usb: Fix attempting to access uninitialized memory Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 040/136] watchdog: sbsa_wdog: Make sure the timeout programming is within the limits Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 041/136] netfilter: ctnetlink: fix possible refcount leak in ctnetlink_create_conntrack() Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 042/136] netfilter: ebtables: fix table blob use-after-free Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 043/136] netfilter: x_tables: fix percpu counter block leak on error path when creating new netns Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 044/136] ipv6: Add lwtunnel encap size of all siblings in nexthop calculation Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 045/136] sctp: add a refcnt in sctp_stream_priorities to avoid a nested loop Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 046/136] octeontx2-pf: Use correct struct reference in test condition Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 047/136] net: fix __dev_kfree_skb_any() vs drop monitor Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 048/136] 9p/xen: fix version parsing Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 049/136] 9p/xen: fix connection sequence Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 050/136] 9p/rdma: unmap receive dma buffer in rdma_request()/post_recv() Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 051/136] net/mlx5e: Verify flow_source cap before using it Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 052/136] net/mlx5: Geneve, Fix handling of Geneve object id as error code Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 053/136] nfc: fix memory leak of se_io context in nfc_genl_se_io Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 054/136] net/sched: transition act_pedit to rcu and percpu stats Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 055/136] net/sched: act_pedit: fix action bind logic Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 056/136] net/sched: act_mpls: " Greg Kroah-Hartman
2023-03-10 13:42 ` [PATCH 5.15 057/136] net/sched: act_sample: " Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 058/136] ARM: dts: spear320-hmi: correct STMPE GPIO compatible Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 059/136] tcp: tcp_check_req() can be called from process context Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 060/136] vc_screen: modify vcs_size() handling in vcs_read() Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 061/136] rtc: sun6i: Always export the internal oscillator Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 062/136] genirq: Refactor accessors to use irq_data_get_affinity_mask Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 063/136] genirq: Add and use an irq_data_update_affinity helper Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 064/136] scsi: ipr: Work around fortify-string warning Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 065/136] rtc: allow rtc_read_alarm without read_alarm callback Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 066/136] loop: loop_set_status_from_info() check before assignment Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 067/136] ASoC: adau7118: dont disable regulators on device unbind Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 068/136] ASoC: zl38060: Remove spurious gpiolib select Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 069/136] ASoC: zl38060 add gpiolib dependency Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 070/136] ASoC: mediatek: mt8195: add missing initialization Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 071/136] thermal: intel: quark_dts: fix error pointer dereference Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 072/136] thermal: intel: BXT_PMIC: select REGMAP instead of depending on it Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 073/136] tracing: Add NULL checks for buffer in ring_buffer_free_read_page() Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 074/136] kernel/printk/index.c: fix memory leak with using debugfs_lookup() Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 075/136] firmware/efi sysfb_efi: Add quirk for Lenovo IdeaPad Duet 3 Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 076/136] bootconfig: Increase max nodes of bootconfig from 1024 to 8192 for DCC support Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 077/136] mfd: arizona: Use pm_runtime_resume_and_get() to prevent refcnt leak Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 078/136] IB/hfi1: Update RMT size calculation Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 079/136] iommu/amd: Fix error handling for pdev_pri_ats_enable() Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 080/136] media: uvcvideo: Remove format descriptions Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 081/136] media: uvcvideo: Handle cameras with invalid descriptors Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 082/136] media: uvcvideo: Handle errors from calls to usb_string Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 083/136] media: uvcvideo: Quirk for autosuspend in Logitech B910 and C910 Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 084/136] media: uvcvideo: Silence memcpy() run-time false positive warnings Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 085/136] USB: fix memory leak with using debugfs_lookup() Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 086/136] staging: emxx_udc: Add checks for dma_alloc_coherent() Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 087/136] tty: fix out-of-bounds access in tty_driver_lookup_tty() Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 088/136] tty: serial: fsl_lpuart: disable the CTS when send break signal Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 089/136] serial: sc16is7xx: setup GPIO controller later in probe Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 090/136] mei: bus-fixup:upon error print return values of send and receive Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 091/136] tools/iio/iio_utils:fix memory leak Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 092/136] iio: accel: mma9551_core: Prevent uninitialized variable in mma9551_read_status_word() Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 093/136] iio: accel: mma9551_core: Prevent uninitialized variable in mma9551_read_config_word() Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 094/136] soundwire: bus_type: Avoid lockdep assert in sdw_drv_probe() Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 095/136] PCI: loongson: Prevent LS7A MRRS increases Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 096/136] USB: dwc3: fix memory leak with using debugfs_lookup() Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 097/136] USB: chipidea: " Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 098/136] USB: uhci: " Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 099/136] USB: sl811: " Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 100/136] USB: fotg210: " Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 101/136] USB: isp116x: " Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 102/136] USB: isp1362: " Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 103/136] USB: gadget: gr_udc: " Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 104/136] USB: gadget: bcm63xx_udc: " Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 105/136] USB: gadget: lpc32xx_udc: " Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 106/136] USB: gadget: pxa25x_udc: " Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 107/136] USB: gadget: pxa27x_udc: " Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 108/136] usb: host: xhci: mvebu: Iterate over array indexes instead of using pointer math Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 109/136] USB: ene_usb6250: Allocate enough memory for full object Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 110/136] usb: uvc: Enumerate valid values for color matching Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 111/136] usb: gadget: uvc: Make bSourceID read/write Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 112/136] PCI: Align extra resources for hotplug bridges properly Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 113/136] PCI: Take other bus devices into account when distributing resources Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 114/136] tty: pcn_uart: fix memory leak with using debugfs_lookup() Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 115/136] misc: vmw_balloon: " Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 116/136] drivers: base: component: " Greg Kroah-Hartman
2023-03-10 13:43 ` [PATCH 5.15 117/136] drivers: base: dd: " Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 118/136] kernel/fail_function: " Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 119/136] PCI: loongson: Add more devices that need MRRS quirk Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 120/136] PCI: Add ACS quirk for Wangxun NICs Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 121/136] phy: rockchip-typec: Fix unsigned comparison with less than zero Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 122/136] soundwire: cadence: Remove wasted space in response_buf Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 123/136] soundwire: cadence: Drain the RX FIFO after an IO timeout Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 124/136] net: tls: avoid hanging tasks on the tx_lock Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 125/136] x86/resctl: fix scheduler confusion with current Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 126/136] drm/display/dp_mst: Fix down/up message handling after sink disconnect Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 127/136] drm/display/dp_mst: Fix down message handling after a packet reception error Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 128/136] Bluetooth: hci_sock: purge socket queues in the destruct() callback Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 129/136] media: uvcvideo: Fix race condition with usb_kill_urb Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 130/136] drm/virtio: Fix error code in virtio_gpu_object_shmem_init() Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 131/136] Revert "scsi: mpt3sas: Fix return value check of dma_get_required_mask()" Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 132/136] scsi: mpt3sas: Dont change DMA mask while reallocating pools Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 133/136] scsi: mpt3sas: re-do lost mpt3sas DMA mask fix Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 134/136] scsi: mpt3sas: Remove usage of dma_get_required_mask() API Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 135/136] malidp: Fix NULL vs IS_ERR() checking Greg Kroah-Hartman
2023-03-10 13:44 ` [PATCH 5.15 136/136] usb: gadget: uvc: fix missing mutex_unlock() if kstrtou8() fails Greg Kroah-Hartman
2023-03-11  2:02 ` [PATCH 5.15 000/136] 5.15.100-rc1 review Shuah Khan
2023-03-11  3:30 ` Guenter Roeck
2023-03-11  4:12 ` Bagas Sanjaya
2023-03-11  6:18 ` Naresh Kamboju
2023-03-11 12:47 ` Sudip Mukherjee
2023-03-11 18:01 ` Florian Fainelli

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20230310133707.296049413@linuxfoundation.org \
    --to=gregkh@linuxfoundation.org \
    --cc=george.kennedy@oracle.com \
    --cc=patches@lists.linux.dev \
    --cc=richard@nod.at \
    --cc=sashal@kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=syzkaller@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).