[ANNOUNCE] Release v6.1.177-cip58

<[email protected]> Tue, 21 Jul 2026 12:20:22 +0000
Newsgroups org.cip-project.lists.cip-dev
Message-ID <TY7PR01MB14818A3080106B78557C45BD2CDC22@TY7PR01MB14818.jpnprd01.prod.outlook.com>
Hi all,

CIP kernel team has released Linux kernel v6.1.177-cip58.
The linux-6.1.y-cip tree has been updated base version from v6.1.175 to v6.1.177.
In this release, we added DMA and multi-SoC support to the Renesas rzv2h-rspi
driver and enabled PCIe/SDHI in the device tree.

Information about this release is as follows:

  v6.1.177-cip58:
    repository:
      https://git.kernel.org/pub/scm/linux/kernel/git/cip/linux-cip.git
    branch:
      linux-6.1.y-cip
    commit hash:
      fc5e5c9987657c209a948e82e24f138430909af2
    fixed CVEs:
      CVE-2023-54125: fs/ntfs3: Return error for inconsistent extended attributes
      CVE-2023-54271: blk-cgroup: Fix NULL deref caused by blkg_policy_data being installed before init
      CVE-2024-27012: netfilter: nf_tables: restore set elements when delete set fails
      CVE-2025-10263: TLBI errata in some Arm-based CPUs may allow writes to resources owned by a higher exception level, potentially allowing privilege escalation
      CVE-2026-23310: bpf/bonding: reject vlan+srcmac xmit_hash_policy change when XDP is loaded
      CVE-2026-31700: net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd()
      CVE-2026-31709: smb: client: validate the whole DACL before rewriting it in cifsacl
      CVE-2026-31712: ksmbd: require minimum ACE size in smb_check_perm_dacl()
      CVE-2026-31715: f2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io()
      CVE-2026-31727: usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo
      CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack
      CVE-2026-43219: net: cpsw_new: Fix potential unregister of netdev that has not been registered yet
      CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare()
      CVE-2026-43421: usb: gadget: f_ncm: Fix net_device lifecycle with device_move
      CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl()
      CVE-2026-43495: net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler
      CVE-2026-45850: ipvs: skip ipv6 extension headers for csum checks
      CVE-2026-45930: net: mctp: ensure our nlmsg responses are initialised
      CVE-2026-45991: udf: fix partition descriptor append bookkeeping
      CVE-2026-45993: LoongArch: Add spectre boundry for syscall dispatch table
      CVE-2026-45996: spi: imx: fix use-after-free on unbind
      CVE-2026-45999: erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap()
      CVE-2026-46003: net: qrtr: ns: Limit the total number of nodes
      CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg()
      CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues
      CVE-2026-46026: net: qrtr: ns: Limit the maximum number of lookups
      CVE-2026-46038: net: qrtr: ns: Free the node during ctrl_cmd_bye()
      CVE-2026-46044: ipmi:ssif: Clean up kthread on errors
      CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed
      CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info
      CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup()
      CVE-2026-46083: spi: fix resource leaks on device setup failure
      CVE-2026-46086: net: bridge: use a stable FDB dst snapshot in RCU readers
      CVE-2026-46091: media: rc: igorplugusb: heed coherency rules
      CVE-2026-46110: net: stmmac: Prevent NULL deref when RX memory exhausted
      CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete
      CVE-2026-46125: wifi: mac80211: remove station if connection prep fails
      CVE-2026-46137: mptcp: pm: ADD_ADDR rtx: fix potential data-race
      CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak
      CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory
      CVE-2026-46164: btrfs: fix double free in create_space_info_sub_group() error path
      CVE-2026-46169: hfsplus: fix uninit-value by validating catalog record size
      CVE-2026-46180: wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task
      CVE-2026-46190: mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()
      CVE-2026-46191: fbcon: Avoid OOB font access if console rotation fails
      CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks
      CVE-2026-46195: smb: client: validate dacloffset before building DACL pointers
      CVE-2026-46196: tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func()
      CVE-2026-46208: batman-adv: stop tp_meter sessions during mesh teardown
      CVE-2026-46280: lib: test_hmm: evict device pages on file close to avoid use-after-free
      CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key
      CVE-2026-46292: pmdomain: core: Fix detach procedure for virtual devices in genpd
      CVE-2026-46296: spi: s3c64xx: fix NULL-deref on driver unbind
      CVE-2026-46299: hfsplus: fix held lock freed on hfsplus_fill_super()
      CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop
      CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp()
      CVE-2026-46321: tun: free page on short-frame rejection in tun_xdp_one()
      CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one()
      CVE-2026-46323: net: gro: don't merge zcopy skbs
      CVE-2026-52910: bpf: Free reuseport cBPF prog after RCU grace period.
      CVE-2026-52913: batman-adv: v: stop OGMv2 on disabled interface
      CVE-2026-52917: sctp: diag: reject stale associations in dump_one path
      CVE-2026-52918: Bluetooth: serialize accept_q access
      CVE-2026-52923: ipc: limit next_id allocation to the valid ID range
      CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling
      CVE-2026-52927: netfilter: ebtables: fix OOB read in compat_mtw_from_user
      CVE-2026-52929: sctp: stream: fully roll back denied add-stream state
      CVE-2026-52930: ipc/shm: serialize orphan cleanup with shm_nattch updates
      CVE-2026-52934: batman-adv: tvlv: reject oversized TVLV packets
      CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send
      CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
      CVE-2026-52942: netfilter: nf_log: validate MAC header was set before dumping it
      CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers
      CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
      CVE-2026-52947: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove
      CVE-2026-52948: i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl
      CVE-2026-53080: net/sched: cls_fw: fix NULL dereference of "old" filters before change()
      CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr()
      CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G
      CVE-2026-53134: netfilter: nft_fib: fix stale stack leak via the OIFNAME register
      CVE-2026-53135: drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
      CVE-2026-53136: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size
      CVE-2026-53137: drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
      CVE-2026-53146: thunderbolt: Limit XDomain response copy to actual frame size
      CVE-2026-53147: thunderbolt: Validate XDomain request packet size before type cast
      CVE-2026-53148: thunderbolt: Clamp XDomain response data copy to allocation size
      CVE-2026-53149: thunderbolt: Bound root directory content to block size
      CVE-2026-53150: thunderbolt: Reject zero-length property entries in validator
      CVE-2026-53159: misc: fastrpc: fix DMA address corruption due to find_vma misuse
      CVE-2026-53160: misc: fastrpc: fix use-after-free race in fastrpc_map_create
      CVE-2026-53161: misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context
      CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories
      CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
      CVE-2026-53177: bnxt_en: Fix NULL pointer dereference
      CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake
      CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists
      CVE-2026-53183: mptcp: allow subflow rcv wnd to shrink
      CVE-2026-53184: udp: clear skb->dev before running a sockmap verdict
      CVE-2026-53186: RDMA/srp: bound SRP_RSP sense copy by the received length
      CVE-2026-53189: mm/huge_memory: update file PMD counter before folio_put()
      CVE-2026-53192: ALSA: timer: Fix UAF at snd_timer_user_params()
      CVE-2026-53194: USB: serial: kl5kusb105: fix bulk-out buffer overflow
      CVE-2026-53195: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
      CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info()
      CVE-2026-53198: ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL
      CVE-2026-53199: hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf
      CVE-2026-53207: mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison
      CVE-2026-53208: Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
      CVE-2026-53209: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
      CVE-2026-53212: netfilter: nft_tunnel: fix use-after-free on object destroy
      CVE-2026-53213: drm/vc4: fix krealloc() memory leak
      CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use
      CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer
      CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset
      CVE-2026-53218: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag
      CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers
      CVE-2026-53221: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
      CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs
      CVE-2026-53225: sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
      CVE-2026-53227: net: openvswitch: fix possible kfree_skb of ERR_PTR
      CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads
      CVE-2026-53236: tcp: restrict SO_ATTACH_FILTER to priv users
      CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths
      CVE-2026-53239: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()
      CVE-2026-53242: ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
      CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr
      CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
      CVE-2026-53252: Bluetooth: fix memory leak in error path of hci_alloc_dev()
      CVE-2026-53253: Bluetooth: bnep: reject short frames before parsing
      CVE-2026-53254: Bluetooth: RFCOMM: validate skb length in MCC handlers
      CVE-2026-53255: Bluetooth: MGMT: validate advertising TLV before type checks
      CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
      CVE-2026-53263: 6lowpan: fix off-by-one in multicast context address compression
      CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle
      CVE-2026-53265: dm cache policy smq: check allocation under invalidate lock
      CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable
      CVE-2026-53268: netfilter: conntrack_irc: fix possible out-of-bounds read
      CVE-2026-53269: netfilter: synproxy: add mutex to guard hook reference counting
      CVE-2026-53270: ipvs: clear the svc scheduler ptr early on edit
      CVE-2026-53273: tee: optee: prevent use-after-free when the client exits before the supplicant
      CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS
      CVE-2026-53275: ipv6: mcast: Fix use-after-free when processing MLD queries
      CVE-2026-53329: drm/amd/display: Use krealloc_array() in dal_vector_reserve()
      CVE-2026-53331: slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock
      CVE-2026-53337: net: bonding: fix NULL pointer dereference in bond_do_ioctl()
      CVE-2026-53339: i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()
      CVE-2026-53343: ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow
      CVE-2026-53349: netfilter: nf_conntrack: destroy stale expectfn expectations on unregister
      CVE-2026-53350: ASoC: wm_adsp: Fix NULL dereference when removing firmware controls
      CVE-2026-53352: signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()
      CVE-2026-53354: arm64: errata: Mitigate TLBI errata on various Arm CPUs
      CVE-2026-53355: net: rds: clear i_sends on setup unwind
      CVE-2026-53356: drm/i915/gem: Fix phys BO pread/pwrite with offset
      CVE-2026-53358: Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()
      CVE-2025-23131: dlm: prevent NPD when writing a positive value to event_done
      CVE-2026-23272: netfilter: nf_tables: unconditionally bump set->nelems before insertion
      CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements
      CVE-2026-23302: net: annotate data-races around sk->sk_{data_ready,write_space}
      CVE-2026-31451: ext4: replace BUG_ON with proper error handling in ext4_read_inline_folio
      CVE-2026-46252: regulator: core: fix locking in regulator_resolve_supply() error path
      CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache corruption
      CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device.
      CVE-2026-52928: af_unix: Reject SIOCATMARK on non-stream sockets
      CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops
      CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups
      CVE-2026-53157: net: phonet: free phonet_device after RCU grace period
      CVE-2026-53158: misc: fastrpc: Fix NULL pointer dereference in rpmsg callback
      CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
      CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
      CVE-2026-53325: agp/amd64: Fix broken error propagation in agp_amd64_probe()
      CVE-2026-53326: debugobjects: Don't call fill_pool() in early boot hardirq context
      CVE-2026-53327: debugobjects: Do not fill_pool() if pi_blocked_on
      CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role
      CVE-2026-53362: ipv6: account for fraggap on the paged allocation path
    added commits:
      CIP: Bump version suffix to -cip58 after merge from stable
      i3c: master: dw: stop hardcoding initial speed
      arm64: dts: renesas: r9a09g047e57-smarc: Enable RSPI0
      arm64: dts: renesas: r9a09g047: Add RSPI nodes
      spi: rzv2h-rspi: Fix silent failure in clock setup error path
      spi: rzv2h-rspi: Simplify clock rate search function signatures
      spi: rzv2h-rspi: Fix invalid SPR=0/BRDV=0 clock configuration
      spi: rzv2h-rspi: Fix max_speed_hz advertising prohibited bit rate
      spi: rzv2h-rspi: add support for DMA mode
      spi: rzv2h-rspi: split out PIO transfer
      spi: rzv2h-rspi: enable TX buffer empty interrupt
      spi: rzv2h-rspi: set TX FIFO threshold to 0
      spi: rzv2h-rspi: set MUST_RX/MUST_TX
      spi: rzv2h-rspi: store RX interrupt in state
      spi: rzv2h-rspi: use device-managed APIs
      spi: rzv2h-rspi: remove call to spi_finalize_current_transfer()
      spi: rzv2h-rspi: fix rzv2h_rspi_transfer_one() indentation
      spi: rzv2h-rspi: add support for RZ/T2H and RZ/N2H
      spi: rzv2h-rspi: add support for loopback mode
      spi: rzv2h-rspi: add support for variable transfer clock
      spi: rzv2h-rspi: add support for using PCLK for transfer clock
      spi: rzv2h-rspi: make transfer clock rate finding chip-specific
      spi: rzv2h-rspi: avoid recomputing transfer frequency
      spi: rzv2h-rspi: move register writes out of rzv2h_rspi_setup_clock()
      spi: rzv2h-rspi: make clocks chip-specific
      spi: rzv2h-rspi: make FIFO size chip-specific
      spi: rzv2h-rspi: make resets optional
      spi: dt-bindings: renesas,rzv2h-rspi: Document RZ/G3E SoC support
      spi: dt-bindings: renesas,rzv2h-rspi: Document dmas property
      spi: dt-bindings: renesas,rzv2h-rspi: allow multiple DMAs
      spi: dt-bindings: renesas,rzv2h-rspi: document optional support for DMA
      clk: renesas: r9a09g047: Add entries for the RSPIs
      spi: Introduce internal spi_xfer_is_dma_mapped() helper
      dmaengine: Add devm_dma_request_chan()
      arm64: dts: renesas: r9a07g054: Add max-frequency to SDHI nodes
      arm64: dts: renesas: r9a07g044: Add max-frequency to SDHI nodes
      arm64: dts: renesas: r9a07g043: Add max-frequency to SDHI nodes
      arm64: dts: renesas: r9a09g056n48-rzv2n-evk: Enable PCIe
      arm64: dts: renesas: r9a09g056: Add PCIe node
      dt-bindings: PCI: renesas,r9a08g045-pcie: Add RZ/V2N support
      clk: renesas: r9a09g056: Add PCIe clocks and reset

Best regards,
  Nobuhiro