[ANNOUNCE] Release v5.10.260-cip75
<[email protected]> Sat, 11 Jul 2026 20:48:29 +0000
| Newsgroups | org.cip-project.lists.cip-dev |
|---|---|
| Message-ID | <TY7PR01MB148180F306E78E239D1453DE8CDFC2@TY7PR01MB14818.jpnprd01.prod.outlook.com> |
Hi all,
CIP kernel team has released Linux kernel v5.10.260-cip75.
The linux-5.10.y-cip tree has been updated base version from v5.10.258 to v5.10.260.
Information about this release is as follows:
v5.10.260-cip75:
repository:
https://git.kernel.org/pub/scm/linux/kernel/git/cip/linux-cip.git
branch:
linux-5.10.y-cip
commit hash:
b73e77b0c18cc1f30ddf28f058396899224a50a9
fixed CVEs:
CVE-2021-47211: ALSA: usb-audio: fix null pointer dereference on pointer cs_desc
CVE-2023-54129: octeontx2-af: Add validation for lmac type
CVE-2025-10263: TLBI errata in some Arm-based CPUs may allow writes to resources owned ...
CVE-2025-21863: io_uring: prevent opcode speculation
CVE-2025-22026: nfsd: don't ignore the return code of svc_proc_register()
CVE-2025-38129: page_pool: Fix use-after-free in page_pool_recycle_in_ring
CVE-2025-38250: Bluetooth: hci_core: Fix use-after-free in vhci_flush()
CVE-2025-39929: smb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path
CVE-2025-40164: usbnet: Fix using smp_processor_id() in preemptible code warnings
CVE-2025-68340: team: Move team device type change at the end of team_port_add
CVE-2026-23099: bonding: limit BOND_MODE_8023AD to Ethernet devices
CVE-2026-31449: ext4: validate p_idx bounds in ext4_ext_correct_indexes
CVE-2026-31489: spi: meson-spicc: Fix double-put in remove path
CVE-2026-31700: net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd()
CVE-2026-31708: smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path
CVE-2026-31715: f2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io()
CVE-2026-43052: wifi: mac80211: check tdls flag in ieee80211_tdls_oper
CVE-2026-43350: smb: client: require a full NFS mode SID before reading mode bits
CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl()
CVE-2026-45850: ipvs: skip ipv6 extension headers for csum checks
CVE-2026-45991: udf: fix partition descriptor append bookkeeping
CVE-2026-46003: net: qrtr: ns: Limit the total number of nodes
CVE-2026-46006: drm/nouveau: fix u32 overflow in pushbuf reloc bounds check
CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues
CVE-2026-46026: net: qrtr: ns: Limit the maximum number of lookups
CVE-2026-46038: net: qrtr: ns: Free the node during ctrl_cmd_bye()
CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed
CVE-2026-46056: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers
CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup()
CVE-2026-46078: erofs: fix the out-of-bounds nameoff handling for trailing dirents
CVE-2026-46086: net: bridge: use a stable FDB dst snapshot in RCU readers
CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop
CVE-2026-46091: media: rc: igorplugusb: heed coherency rules
CVE-2026-46103: can: ucan: fix devres lifetime
CVE-2026-46107: dm-thin: fix metadata refcount underflow
CVE-2026-46137: mptcp: pm: ADD_ADDR rtx: fix potential data-race
CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak
CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory
CVE-2026-46169: hfsplus: fix uninit-value by validating catalog record size
CVE-2026-46180: wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task
CVE-2026-46191: fbcon: Avoid OOB font access if console rotation fails
CVE-2026-46196: tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func()
CVE-2026-46208: batman-adv: stop tp_meter sessions during mesh teardown
CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key
CVE-2026-46292: pmdomain: core: Fix detach procedure for virtual devices in genpd
CVE-2026-46299: hfsplus: fix held lock freed on hfsplus_fill_super()
CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp()
CVE-2026-46321: tun: free page on short-frame rejection in tun_xdp_one()
CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one()
CVE-2026-52910: bpf: Free reuseport cBPF prog after RCU grace period.
CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued
CVE-2026-52913: batman-adv: v: stop OGMv2 on disabled interface
CVE-2026-52917: sctp: diag: reject stale associations in dump_one path
CVE-2026-52918: Bluetooth: serialize accept_q access
CVE-2026-52923: ipc: limit next_id allocation to the valid ID range
CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling
CVE-2026-52927: netfilter: ebtables: fix OOB read in compat_mtw_from_user
CVE-2026-52929: sctp: stream: fully roll back denied add-stream state
CVE-2026-52930: ipc/shm: serialize orphan cleanup with shm_nattch updates
CVE-2026-52934: batman-adv: tvlv: reject oversized TVLV packets
CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send
CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers
CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
CVE-2026-52947: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove
CVE-2026-52948: i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl
CVE-2026-53080: net/sched: cls_fw: fix NULL dereference of "old" filters before change()
CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G
CVE-2026-53134: netfilter: nft_fib: fix stale stack leak via the OIFNAME register
CVE-2026-53135: drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
CVE-2026-53137: drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
CVE-2026-53146: thunderbolt: Limit XDomain response copy to actual frame size
CVE-2026-53148: thunderbolt: Clamp XDomain response data copy to allocation size
CVE-2026-53149: thunderbolt: Bound root directory content to block size
CVE-2026-53150: thunderbolt: Reject zero-length property entries in validator
CVE-2026-53161: misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context
CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories
CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake
CVE-2026-53186: RDMA/srp: bound SRP_RSP sense copy by the received length
CVE-2026-53189: mm/huge_memory: update file PMD counter before folio_put()
CVE-2026-53192: ALSA: timer: Fix UAF at snd_timer_user_params()
CVE-2026-53194: USB: serial: kl5kusb105: fix bulk-out buffer overflow
CVE-2026-53195: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info()
CVE-2026-53199: hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf
CVE-2026-53208: Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
CVE-2026-53212: netfilter: nft_tunnel: fix use-after-free on object destroy
CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset
CVE-2026-53218: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag
CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers
CVE-2026-53221: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs
CVE-2026-53225: sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
CVE-2026-53227: net: openvswitch: fix possible kfree_skb of ERR_PTR
CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads
CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths
CVE-2026-53239: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()
CVE-2026-53242: ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr
CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
CVE-2026-53255: Bluetooth: MGMT: validate advertising TLV before type checks
CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
CVE-2026-53263: 6lowpan: fix off-by-one in multicast context address compression
CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle
CVE-2026-53265: dm cache policy smq: check allocation under invalidate lock
CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable
CVE-2026-53268: netfilter: conntrack_irc: fix possible out-of-bounds read
CVE-2026-53269: netfilter: synproxy: add mutex to guard hook reference counting
CVE-2026-53270: ipvs: clear the svc scheduler ptr early on edit
CVE-2026-53273: tee: optee: prevent use-after-free when the client exits before the supplicant
CVE-2026-53337: net: bonding: fix NULL pointer dereference in bond_do_ioctl()
CVE-2026-53339: i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()
CVE-2026-53352: signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()
CVE-2026-53354: arm64: errata: Mitigate TLBI errata on various Arm CPUs
CVE-2026-53355: net: rds: clear i_sends on setup unwind
CVE-2026-53356: drm/i915/gem: Fix phys BO pread/pwrite with offset
CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()
CVE-2026-53358: Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()
CVE-2022-49803: netdevsim: Fix memory leak of nsim_dev->fa_cookie
CVE-2022-50114: net: 9p: fix refcount leak in p9_read_work() error handling
CVE-2025-23131: dlm: prevent NPD when writing a positive value to event_done
CVE-2025-39931: crypto: af_alg - Set merge to zero early in af_alg_sendmsg
CVE-2026-23204: net/sched: cls_u32: use skb_header_pointer_careful()
CVE-2026-31451: ext4: replace BUG_ON with proper error handling in ext4_read_inline_folio
CVE-2026-31755: usb: cdns3: gadget: fix NULL pointer dereference in ep_queue
CVE-2026-43219: net: cpsw_new: Fix potential unregister of netdev that has not been registered yet
CVE-2026-46252: regulator: core: fix locking in regulator_resolve_supply() error path
CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache corruption
CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device.
CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops
CVE-2026-53157: net: phonet: free phonet_device after RCU grace period
CVE-2026-53158: misc: fastrpc: Fix NULL pointer dereference in rpmsg callback
CVE-2026-53159: misc: fastrpc: fix DMA address corruption due to find_vma misuse
CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
CVE-2026-53177: bnxt_en: Fix NULL pointer dereference
CVE-2026-53325: agp/amd64: Fix broken error propagation in agp_amd64_probe()
CVE-2026-53329: drm/amd/display: Use krealloc_array() in dal_vector_reserve()
CVE-2026-53332: slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd
added commits:
CIP: Bump version suffix to -cip75 after merge from stable
Best regards,
Nobuhiro