<feed xmlns='http://www.w3.org/2005/Atom'>
<title>kernel/git/stable/linux-stable.git/drivers/virt, branch master</title>
<subtitle>Unnamed repository; edit this file 'description' to name the repository.</subtitle>
<id>http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/atom/drivers/virt?h=master</id>
<link rel='self' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/atom/drivers/virt?h=master'/>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/'/>
<updated>2026-10-03T16:05:47Z</updated>
<entry>
<title>Merge tag 'char-misc-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc</title>
<updated>2026-10-03T16:05:47Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-03T16:05:47Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=25d576ed11108470d0999054265108400db1b881'/>
<id>urn:sha1:25d576ed11108470d0999054265108400db1b881</id>
<content type='text'>
Pull char/misc/IIO fixes from Greg KH:
 "Here is a set of char/misc/iio and other small driver subsystem fixes
  for 7.3-rc6 that resolve a number of reported issues. Included in here
  are:

   - lots of small iio driver fixes for reported problems

   - interconnect driver revert to resolve a regression

   - nitro_enclaves driver fix for a use-after-free

   - binder driver fixes for reported problems (in both the rust and C
     versions)

  All of these have been in linux-next with no reported issues"

* tag 'char-misc-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc: (63 commits)
  iio: adc: ad_sigma_delta: fix use-after-free on unbind
  iio: accel: kxcjk-1013: reject duplicate event disable
  iio: buffer: serialize buffer teardown with mode claims
  iio: cdc: ad7150: fix OF matching and publish module aliases
  iio: adc: ade9000: fix NULL pointer dereference in clkout registration
  iio: adc: ad4030: fix invalid oversampling_ratio validation
  iio: adc: ad7173: Fix digital filter configuration
  iio: adc: stm32-adc: fix possible division by zero in processed channel
  iio: adc: stm32-adc: fix check on internal channel availability
  iio: proximity: isl29501: Fix return type of isl29501_register_write
  iio: imu: inv_icm42607: restore runtime PM on system resume errors
  iio: imu: inv_icm42607: propagate runtime suspend errors
  iio: adc: pac1934: check ACPI label duplication
  rust_binderfs: add transaction_report feature entry
  rust_binder: reschedule node refcount update on thread exit
  rust_binder: cancel deferred work items in thread exit
  binderfs: fix UAF write in binder_add_device
  binder: fix is_failure flag for superseded transaction cleanup
  binder: fix leaked fd fixups on TF_UPDATE_TXN supersede
  Revert "interconnect: qcom: x1e80100: enable QoS configuration"
  ...
</content>
</entry>
<entry>
<title>Merge tag 'io_uring-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux</title>
<updated>2026-10-02T19:17:24Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-02T19:17:24Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=3f1fe48a36b0b6722dc3fd421d93512bac138e9a'/>
<id>urn:sha1:3f1fe48a36b0b6722dc3fd421d93512bac138e9a</id>
<content type='text'>
Pull io_uring fixes from Jens Axboe:

 - Fix a task_work add use-after-free with SQPOLL.

   The sqpoll thread could pop and complete the last request while
   io_req_normal_work_add() was still looking at them after the mpscq
   push.

   Use the same approach as DEFER_TASKRUN to protect from that, holding
   an RCU read lock across the add, and have exit wait for an RCU grace
   period for SQPOLL rings as well.

 - CQE32 ring fixes: correct the free entry check for 32b CQEs, zero the
   big_cqe for aux CQEs, and only post the dummy skip CQE on CQE_MIXED
   rings

 - Mark the source filter table as COW when cloning bpf filters, so
   registering another filter on the source doesn't modify the shared
   table in place

 - Initialize the task context before running the BPF loop

 - Requeue zcrx multishot receives stopped by a local resource

 - End a TX_TIMESTAMP multishot cmd when the CQ is full (lollipopkit)

* tag 'io_uring-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux:
  io_uring: fix task_work add use-after-free with SQPOLL
  io_uring/cmd_net: end TX_TIMESTAMP multishot when the CQ is full
  io_uring/zcrx: requeue multishot receives stopped by a local resource
  io_uring: initialize task context before running the BPF loop
  io_uring: zero big_cqe for aux CQEs on CQE32 rings
  io_uring: fix free entry check for 32b CQEs on CQE32 rings
  io_uring: only post the dummy skip CQE on CQE_MIXED rings
  io_uring/bpf_filter: mark source as COW when cloning filters
</content>
</entry>
<entry>
<title>nitro_enclaves: fix use-after-free on SLOT_ALLOC failure</title>
<updated>2026-09-09T12:56:26Z</updated>
<author>
<name>Yuxiao Wang</name>
<email>yuxiao.wang@certik.com</email>
</author>
<published>2026-09-09T12:44:00Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=9bc184a2eda8b773c88ecbff934001ad649b9cc1'/>
<id>urn:sha1:9bc184a2eda8b773c88ecbff934001ad649b9cc1</id>
<content type='text'>
When ne_create_vm_ioctl() fails the SLOT_ALLOC request after
anon_inode_getfile() has succeeded, the error path calls
fput(enclave_file) and then frees ne_enclave.

In normal userspace context, fput() defers the final __fput() via
task_work. ne_enclave_release() therefore runs after ne_enclave has
already been freed and dereferences ne_enclave-&gt;slot_uid, causing a
use-after-free: KASAN: slab-use-after-free in ne_enclave_release.

The enclave has no slot allocated and is not yet linked into the
enclaves list on this error path, so ne_enclave_release() is expected
to return early when slot_uid is zero. However, reading slot_uid
already accesses the freed object.

Clear enclave_file-&gt;private_data before fput() on the error path.
ne_enclave_release() then returns immediately when private_data is
NULL, leaving the ioctl error path as the sole owner of ne_enclave.
This is safe because the file has not been fd_install()'d yet.

Tested on an AWS EC2 m5.2xlarge with CONFIG_KASAN=y. Without the
patch, the reproducer triggers a KASAN slab-use-after-free on every
SLOT_ALLOC failure. With the patch, no KASAN report is produced and
the SLOT_ALLOC error is still returned. Normal enclave creation and
teardown are unaffected.

Fixes: 9c8eb50fe9e2 ("nitro_enclaves: Add logic for terminating an enclave")
Cc: stable@vger.kernel.org
Co-developed-by: Zhaofeng Chen &lt;zhaofeng.chen@certik.com&gt;
Signed-off-by: Zhaofeng Chen &lt;zhaofeng.chen@certik.com&gt;
Signed-off-by: Yuxiao Wang &lt;yuxiao.wang@certik.com&gt;
Reviewed-by: Alexander Graf &lt;graf@amazon.com&gt;
Link: https://patch.msgid.link/20260909124400.27857-1-graf@amazon.com
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>Merge tag 'driver-core-7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/driver-core/driver-core</title>
<updated>2026-09-05T18:59:05Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-09-05T18:59:05Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=9f0346dcbea363787186c94ef94dd01aaa215afa'/>
<id>urn:sha1:9f0346dcbea363787186c94ef94dd01aaa215afa</id>
<content type='text'>
Pull driver core fixes from Danilo Krummrich:

 - Fix kernfs listxattr() not returning security xattr names (e.g.
   SELinux labels) when the kernfs node has no allocated kernfs_iattrs

 - Fix silent truncation of IRQ vector indices in the Rust PCI
   abstractions

 - Don't select OF from DRIVER_PE_KUNIT_TEST; skip the test when OF is
   disabled instead of silently enabling extra kernel functionality

 - Russ Weight is retiring from kernel development; update the Firmware
   Loader sysfs contact to the driver-core mailing list, add a CREDITS
   entry for Firmware Upload, and update MAINTAINERS accordingly

* tag 'driver-core-7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/driver-core/driver-core:
  MAINTAINERS: Remove Russ Weight from Firmware Loader
  CREDITS: Add CREDITS entry for Firmware Upload
  firmware_loader: Change contact for sysfs nodes
  rust: pci: reject IRQ vector indices that do not fit in u32
  kernfs: preserve security xattrs without allocating iattrs
  drivers: base: test: DRIVER_PE_KUNIT_TEST should not select OF
</content>
</entry>
</feed>
