CVE-2026-68480 mitigations for older stable series (was: Re: Linux 6.6.149)

Salvatore Bonaccorso <[email protected]>
Newsgroups org.kernel.vger.stable,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Hi Greg, hi Borislav,

On Thu, Aug 06, 2026 at 07:32:17PM +0200, Greg Kroah-Hartman wrote:
> I'm announcing the release of the 6.6.149 kernel.
> 
> All users of the 6.6 kernel series must upgrade.
> 
> The updated 6.6.y git tree can be found at:
> 	git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git linux-6.6.y
> and can be browsed at the normal kernel.org git web browser:
> 	https://git.kernel.org/?p=linux/kernel/git/stable/linux-stable.git;a=summary

It got mentioned outside of the stable list that the backports of
7e7f81cf6f5c ("x86/bugs: Make Safe-RET robust against interrupt
injection") to address CVE-2026-68480 will not work. So raising the
problem here.

In fact at least they depend on CONFIG_MITIGATION_SRSO, which only was
renamed in a033eec9a06c ("x86/bugs: Rename CONFIG_CPU_SRSO
=> CONFIG_MITIGATION_SRSO") v6.9-rc1, correct?

Borislav, can you have a look for the older backports?

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.