Hi,

On Thu, Apr 30, 2026 at 05:52:37AM +0100, Sam James wrote:
> Eddie Chapman <[email protected]> writes:
> 
> > On 29/04/2026 21:23, Jan Schaumann wrote:
> >> Affected and fixed versions
> >> ===========================
> >> Issue introduced in 4.14 with commit
> >> 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 and fixed in
> >> 6.18.22 with commit
> >> fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8
> >> Issue introduced in 4.14 with commit
> >> 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 and fixed in
> >> 6.19.12 with commit
> >> ce42ee423e58dffa5ec03524054c9d8bfd4f6237
> >> Issue introduced in 4.14 with commit
> >> 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 and fixed in
> >> 7.0 with commit
> >> a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5
> >> https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8
> >> https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237
> >> https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5
> >
> > So this is one of the worst make-me-root vulnerabilities in the kernel
> > in recent times. I see that on the 11th of April 6.19.12 & 6.18.22
> > were released with the fix backported.
> >
> > Longterm 6.12, 6.6, 6.1, 5.15, 5.10 have not received the fix and I
> > don't see anything in the upstream stable queues yet as I write. My
> > guess is backporting that far back is not as straightforward. As this
> > was introduced in 2017 all those older kernels are affected, right? Or
> > am I missing something?
> 
> It does not apply cleanly, no. Attached is the workaround we're going to
> use. I'm not an expert on IPSec but I think this is the lesser evil.
> 
> I attempted a backport but ran into a few API changes and wasn't
> confident enough to muck around with it, especially for something to
> deploy immediately.

Backports have just been posted, for 6.12.y:
https://lore.kernel.org/stable/2026043038-unwilling-slogan-a20e@gregkh/T/#t

(but I do not see them yet for all versions, but guess following soon)

Regards,
Salvatore

Reply via email to