Re: 6.1.y status: 2abd5287f083 ("KVM: x86: Check for invalid/obsolete root *after* making MMU pages available") / CVE-2026-64561

"IP over Parrots (with QoS)" <[email protected]>
Newsgroups org.kernel.vger.stable,org.kernel.vger.kvm
Message-ID <6T0kMG3on8gqQNlDZpl6PONhbz3R4vadrMJ2QzJu-UPYXvT1OfqbLyc0CNuW3_Cj7YojbCpo-dn9MU_Etj4npJkWbhZhPDbEvJsHUk3Zm6o=@rfc2549.ca>
On Tuesday, August 11th, 2026 at 11:24 AM, Paolo Bonzini <[email protected]> wrote:
> Sean already answered about the backport; I will add that upstream
> maintainers, as a general rule, do not have the bandwidth to check
> which commits are needed in older backports. The older the kernel, the
> more we need the help from the community. Especially with the
> increased amount of reports we've gotten over the last few months,
> *there's no guarantee that LTS kernels get fixes for all
> vulnerabilities*.

That makes sense and I hope I didn't come across as complaining.
On the contrary I am willing to help to the extent that I can.

I am familiar with the maintenance burden but I am not intimate with
the inner workings of the Kernel yet so I figured I would ask the people
who know.

> If your distro or fridge is running an old kernel
> and is left vulnerable, complain with them.

To be fair, Debian 12 ships with 6.1.y which is still supported and they
have 6.1.182 already.

My inquiry was about whether this particular fix should land in 6.1.y.
Otherwise, if this was still supported by Debian (or RHEL), then I might
expect the distro to manually patch or backport it as you mention.

I now see that the fix will land and I am glad to have contributed in
some small way :)

Thanks all,

- dms
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.