Hi, On Thu, Apr 30, 2026 at 05:52:37AM +0100, Sam James wrote: > Eddie Chapman <[email protected]> writes: > > > On 29/04/2026 21:23, Jan Schaumann wrote: > >> Affected and fixed versions > >> =========================== > >> Issue introduced in 4.14 with commit > >> 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 and fixed in > >> 6.18.22 with commit > >> fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8 > >> Issue introduced in 4.14 with commit > >> 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 and fixed in > >> 6.19.12 with commit > >> ce42ee423e58dffa5ec03524054c9d8bfd4f6237 > >> Issue introduced in 4.14 with commit > >> 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 and fixed in > >> 7.0 with commit > >> a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5 > >> https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8 > >> https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237 > >> https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5 > > > > So this is one of the worst make-me-root vulnerabilities in the kernel > > in recent times. I see that on the 11th of April 6.19.12 & 6.18.22 > > were released with the fix backported. > > > > Longterm 6.12, 6.6, 6.1, 5.15, 5.10 have not received the fix and I > > don't see anything in the upstream stable queues yet as I write. My > > guess is backporting that far back is not as straightforward. As this > > was introduced in 2017 all those older kernels are affected, right? Or > > am I missing something? > > It does not apply cleanly, no. Attached is the workaround we're going to > use. I'm not an expert on IPSec but I think this is the lesser evil. > > I attempted a backport but ran into a few API changes and wasn't > confident enough to muck around with it, especially for something to > deploy immediately.
Backports have just been posted, for 6.12.y: https://lore.kernel.org/stable/2026043038-unwilling-slogan-a20e@gregkh/T/#t (but I do not see them yet for all versions, but guess following soon) Regards, Salvatore
