Re: 6.1.y status: 2abd5287f083 ("KVM: x86: Check for invalid/obsolete root *after* making MMU pages available") / CVE-2026-64561
"IP over Parrots (with QoS)" <[email protected]>
| Newsgroups | org.kernel.vger.stable,org.kernel.vger.kvm |
|---|---|
| Message-ID | <6T0kMG3on8gqQNlDZpl6PONhbz3R4vadrMJ2QzJu-UPYXvT1OfqbLyc0CNuW3_Cj7YojbCpo-dn9MU_Etj4npJkWbhZhPDbEvJsHUk3Zm6o=@rfc2549.ca> |
On Tuesday, August 11th, 2026 at 11:24 AM, Paolo Bonzini <[email protected]> wrote: > Sean already answered about the backport; I will add that upstream > maintainers, as a general rule, do not have the bandwidth to check > which commits are needed in older backports. The older the kernel, the > more we need the help from the community. Especially with the > increased amount of reports we've gotten over the last few months, > *there's no guarantee that LTS kernels get fixes for all > vulnerabilities*. That makes sense and I hope I didn't come across as complaining. On the contrary I am willing to help to the extent that I can. I am familiar with the maintenance burden but I am not intimate with the inner workings of the Kernel yet so I figured I would ask the people who know. > If your distro or fridge is running an old kernel > and is left vulnerable, complain with them. To be fair, Debian 12 ships with 6.1.y which is still supported and they have 6.1.182 already. My inquiry was about whether this particular fix should land in 6.1.y. Otherwise, if this was still supported by Debian (or RHEL), then I might expect the distro to manually patch or backport it as you mention. I now see that the fix will land and I am glad to have contributed in some small way :) Thanks all, - dms