commit | 3902637f63822ef11db79b963ab0f1e70cd63c87 | [log] [tgz] |
---|---|---|
author | Pindar Yang <pindaryang@google.com> | Thu Oct 12 09:55:10 2023 +0000 |
committer | Pindar Yang <pindaryang@google.com> | Thu Oct 12 09:55:10 2023 +0000 |
tree | eed6343bba0fa82f3e305ac56950750e5a917809 | |
parent | 673c777da0503819751d11e375cd35f8afdc3065 [diff] |
redbull: update kernel-and-modules prebuilt Linux version 4.19.282-g4b749a433956-ab10893502 (build-user@build- host) (Android (7284624, based on r416183b) clang version 12.0.5 (https://android.googlesource.com/toolchain/llvm-project c935d99d7cf2016289302412d708641d52d2f7ee), LLD 12.0.5 (/buildbot/src/android/llvm-toolchain/out/llvm-project/lld c935d99d7cf2016289302412d708641d52d2f7ee)) #1 SMP PREEMPT Fri Sep 22 09:02:07 UTC 2023 private/msm-google: (228 changes) 4b749a43 msm: adsprpc: Handle UAF in fastrpc internal munmap 7a484ed6 Merge android-msm-pixel-4.19-udc into android-msm-pixel-4.19-udc-qpr1 7b094464 UPSTREAM: net/sched: cls_fw: Fix improper refcount update leads to use-after-free d5057959 LTS: Merge android-4.19-stable (4.19.282) into android-msm-pixel-4.19-udc-qpr1 283b7446 GKI: Add and update XML representation 7b88bd86 Merge android-4.19-stable (4.19.282) into android-msm-pixel-4.19-lts ecf3519d Merge android-msm-pixel-4.19-udc into android-msm-pixel-4.19-udc-qpr1 ad910cc4 sched: cpufreq: Do not boost RT to max util 7f1bf479 Merge 4.19.282 into android-4.19-stable cdfda37a Linux 4.19.282 d52eaea9 ASN.1: Fix check for strdup() success 0915a439 iio: adc: at91-sama5d2_adc: fix an error code in at91_adc_allocate_trigger() 280b76c3 counter: 104-quad-8: Fix race condition between FLAG and CNTR reads 8af86ad5 sctp: Call inet6_destroy_sock() via sk->sk_destruct(). b165119e dccp: Call inet6_destroy_sock() via sk->sk_destruct(). e1820a93 inet6: Remove inet6_destroy_sock() in sk->sk_prot->destroy(). 1d8a87d6 tcp/udp: Call inet6_destroy_sock() in IPv6 sk->sk_destruct(). 9577d9f0 udp: Call inet6_destroy_sock() in setsockopt(IPV6_ADDRFORM). 50c3bf38 ext4: fix use-after-free in ext4_xattr_set_entry 7ad0e2fc ext4: remove duplicate definition of ext4_xattr_ibody_inline_set() 54e71759 Revert "ext4: fix use-after-free in ext4_xattr_set_entry" 1330c3f1 x86/purgatory: Don't generate debug info for purgatory.ro 70ae89da memstick: fix memory leak if card device is never registered c81ee933 nilfs2: initialize unused bytes in segment summary blocks a5353cde xen/netback: use same error messages for same errors 3a9f4f19 s390/ptrace: fix PTRACE_GET_LAST_BREAK error handling b95fde81 net: dsa: b53: mmap: add phy ops 5cca80d4 scsi: core: Improve scsi_vpd_inquiry() checks 5687c568 scsi: megaraid_sas: Fix fw_crash_buffer_show() 01a51919 selftests: sigaltstack: fix -Wuninitialized d8bbffdb Input: i8042 - add quirk for Fujitsu Lifebook A574/H 31b31965 f2fs: Fix f2fs_truncate_partial_nodes ftrace event 14d11725 e1000e: Disable TSO on i219-LM card to increase speed 8076c049 mlxfw: fix null-ptr-deref in mlxfw_mfa2_tlv_next() 5470461d i40e: fix i40e_setup_misc_vector() error handling 43d5d413 i40e: fix accessing vsi->active_filters without holding lock 0ba3c085 virtio_net: bugfix overflow inside xdp_linearize_page() 6ef81202 net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg 7d1594e4 ARM: dts: rockchip: fix a typo error for rk3288 spdif node 0b856698 Merge 4.19.281 into android-4.19-stable a5b79a58 Linux 4.19.281 17992d52 arm64: KVM: Fix system register enumeration 6f4eb3ca KVM: arm64: Filter out invalid core register IDs in KVM_GET_REG_LIST e072604c KVM: arm64: Factor out core register ID enumeration 495adb06 KVM: nVMX: add missing consistency checks for CR0 and CR4 08096e53 coresight-etm4: Fix for() loop drvdata->nr_addr_cmp range bug 8e39a623 watchdog: sbsa_wdog: Make sure the timeout programming is within the limits 30e138e2 cgroup/cpuset: Wake up cpuset_attach_wq tasks in cpuset_cancel_attach() 24c01263 ubi: Fix deadlock caused by recursively holding work_sem 6aee9f32 mtd: ubi: wl: Fix a couple of kernel-doc issues 7883799d ubi: Fix failure attaching when vid_hdr offset equals to (sub)page size 2529e660 x86/PCI: Add quirk for AMD XHCI controller that loses MSI-X state in D3hot 4e7c498c scsi: ses: Handle enclosure with just a primary component gracefully 96acda73 verify_pefile: relax wrapper length check 3af12083 efi: sysfb_efi: Add quirk for Lenovo Yoga Book X91F/L 63f6f20e i2c: imx-lpi2c: clean rx/tx buffers upon new message 65d5dd5d power: supply: cros_usbpd: reclassify "default case!" as debug 0638f2b9 udp6: fix potential access to stale information 82e626af net: macb: fix a memory corruption in extended buffer descriptor mode 4fbd094d sctp: fix a potential overflow in sctp_ifwdtsn_skip b53b009c qlcnic: check pci_reset_function result 4ec4f21a niu: Fix missing unwind goto in niu_alloc_channels() c078fcd3 9p/xen : Fix use after free bug in xen_9pfs_front_remove due to race condition 92fd37e0 mtdblock: tolerate corrected bit-flips 5f3d214d Bluetooth: Fix race condition in hidp_session_thread 1351551a Bluetooth: L2CAP: Fix use-after-free in l2cap_disconnect_{req,rsp} c51e9559 ALSA: hda/sigmatel: fix S/PDIF out on Intel D*45* motherboards a30a72f0 ALSA: i2c/cs8427: fix iec958 mixer control deactivation d34a86ed ALSA: hda/sigmatel: add pin overrides for Intel DP45SG motherboard 07c93160 ALSA: emu10k1: fix capture interrupt handler unlinking 3a7cccf8 Revert "pinctrl: amd: Disable and mask interrupts on resume" a55f268a mm/swap: fix swap_info_struct race between swapoff and get_swap_pages() f720853c ring-buffer: Fix race while reader and writer are on the same page 51ba3ee2 ftrace: Mark get_lock_parent_ip() __always_inline c1412fca perf/core: Fix the same task check in perf_event_set_output a230b53c ALSA: hda/realtek: Add quirk for Clevo X370SNW 5fe0ea14 nilfs2: fix sysfs interface lifetime 0dbf0e64 nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread() 28eb0ec6 tty: serial: sh-sci: Fix Rx on RZ/G2L SCI cc4c2fc2 tty: serial: sh-sci: Fix transmit end interrupt handler 80947117 iio: dac: cio-dac: Fix max DAC write value check for 12-bit 50aeb77f USB: serial: option: add Quectel RM500U-CN modem 91d494cb USB: serial: option: add Telit FE990 compositions 14d750b4 USB: serial: cp210x: add Silicon Labs IFS-USB-DATACABLE IDs 9f71fc8a gpio: davinci: Add irq chip flag to skip set wake f394f690 ipv6: Fix an uninit variable access bug in __ip6_make_skb() 9346a1a2 sctp: check send stream number after wait_for_sndbuf be71c3c7 net: don't let netpoll invoke NAPI if in xmit context 824bc1fd icmp: guard against too small mtu 7e68d7c6 wifi: mac80211: fix invalid drv_sta_pre_rcu_remove calls for non-uploaded sta 4f2e22f6 pwm: cros-ec: Explicitly set .polarity in .get_state() e573c833 NFSv4: Fix hangs when recovering open state after a server reboot 95823043 NFSv4: Check the return value of update_open_stateid() ca2e3cdc NFSv4: Convert struct nfs4_state to use refcount_t c65a5e3b pinctrl: amd: Disable and mask interrupts on resume 2c8989fe pinctrl: amd: disable and mask interrupts on probe 3a09370d pinctrl: amd: Use irqchip template 5bddf353 pinctrl: Added IRQF_SHARED flag for amd-pinctrl driver 9b68392a Revert "dm thin: fix deadlock when swapping to thin device" a73cc414 Merge "Merge 4.19.280 into android-4.19-stable" into android-4.19-stable ca61495e Merge 4.19.280 into android-4.19-stable c1102a2e UPSTREAM: ext4: fix kernel BUG in 'ext4_write_inline_data_end()' 5c096640 Linux 4.19.280 321488cf cgroup: Add missing cpus_read_lock() to cgroup_attach_task_all() e4463009 cgroup: Fix threadgroup_rwsem <-> cpus_read_lock() deadlock 22426258 cgroup/cpuset: Change cpuset_rwsem and hotplug lock order 8ed4c825 net: sched: cbq: dont intepret cls results when asked to drop 45df749f gfs2: Always check inode size of inline inodes 51a8f136 firmware: arm_scmi: Fix device node validation for mailbox transport 53bb0d3e ext4: fix kernel BUG in 'ext4_write_inline_data_end()' b27dd264 usb: host: ohci-pxa27x: Fix and & vs | typo 76d41dc2 s390/uaccess: add missing earlyclobber annotations to __clear_user() 0838cb21 drm/etnaviv: fix reference leak when mmaping imported buffer d3d1c1bb ALSA: usb-audio: Fix regression on detection of Roland VS-100 77cd8eda ALSA: hda/conexant: Partial revert of a quirk for Lenovo 628bbce0 pinctrl: at91-pio4: fix domain name assignment e1436989 xen/netback: don't do grant copy across page boundary 8afb1fab cifs: fix DFS traversal oops without CONFIG_CIFS_DFS_UPCALL 44b4c139 cifs: prevent infinite recursion in CIFSGetDFSRefer() 5262777c Input: focaltech - use explicitly signed char type 33e60ca0 Input: alps - fix compatibility with -funsigned-char 9f25e5cf net: mvneta: make tx buffer array agnostic 3b366c8e net: dsa: mv88e6xxx: Enable IGMP snooping on user ports only 09119a9f i40e: fix registers dump after run ethtool adapter self test 618b15d0 can: bcm: bcm_tx_setup(): fix KMSAN uninit-value in vfs_write 06ca4e9b scsi: megaraid_sas: Fix crash after a double completion 590c09e0 ca8210: Fix unsigned mac_len comparison with zero in ca8210_skb_tx() d53b89fc fbdev: au1200fb: Fix potential divide by zero a7134de6 fbdev: lxfb: Fix potential divide by zero 2961c0bd fbdev: intelfb: Fix potential divide by zero 06c72885 fbdev: nvidia: Fix potential divide by zero 178ff87d sched_getaffinity: don't assume 'cpumask_size()' is fully initialized 598dc990 fbdev: tgafb: Fix potential divide by zero 35904981 ALSA: hda/ca0132: fixup buffer overrun at tuning_ctl_set() 66925411 ALSA: asihpi: check pao in control_message() b7de906c md: avoid signed overflow in slot_store() 643170da bus: imx-weim: fix branch condition evaluates to a garbage value c26f3ff4 ocfs2: fix data corruption after failed write 8eb43d63 tun: avoid double free in tun_free_netdev 30d0a53d sched/fair: Sanitize vruntime of entity being migrated a398059a sched/fair: sanitize vruntime of entity being placed 7b9f8efb dm crypt: add cond_resched() to dmcrypt_write() 0d96bd50 dm stats: check for and propagate alloc_percpu failure 5fc2b948 i2c: xgene-slimpro: Fix out-of-bounds bug in xgene_slimpro_i2c_xfer() 9c5034e9 nilfs2: fix kernel-infoleak in nilfs_ioctl_wrap_copy() 0752a5ca usb: chipidea: core: fix possible concurrent when switch role 7a95f8c7 usb: chipdea: core: fix return -EINVAL if request role is the same with current role 84e13235 dm thin: fix deadlock when swapping to thin device 7d845e9a igb: revert rtnl_lock() that causes deadlock 3256e152 usb: gadget: u_audio: don't let userspace block driver unbind b5ea8bc3 scsi: core: Add BLIST_SKIP_VPD_PAGES for SKhynix H28U74301AMR 8dd74ca1 cifs: empty interface list when server doesn't support query interfaces a4e7fa8f sh: sanitize the flags on sigreturn bcc029c7 net: usb: qmi_wwan: add Telit 0x1080 composition dcfe63d3 net: usb: cdc_mbim: avoid altsetting toggling for Telit FE990 66084a02 scsi: ufs: core: Add soft dependency on governor_simpleondemand 9bb3a104 scsi: target: iscsi: Fix an error message in iscsi_check_key() f55cb52e m68k: Only force 030 bus error if PC not in exception table 5da4469a ca8210: fix mac_len negative array access fea40035 riscv: Bump COMMAND_LINE_SIZE value to 1024 1608a400 thunderbolt: Use const qualifier for `ring_interrupt_index` 98a357d8 uas: Add US_FL_NO_REPORT_OPCODES for JMicron JMS583Gen 2 2b486ecf hwmon (it87): Fix voltage scaling for chips with 10.9mV ADCs af4d4875 Bluetooth: btsdio: fix use after free bug in btsdio_remove due to unfinished work 709f207e Bluetooth: btqcomsmd: Fix command timeout after setting BD address 95f068c2 net: mdio: thunder: Add missing fwnode_handle_put() fb195060 hvc/xen: prevent concurrent accesses to the shared ring 5bf25672 net/sonic: use dma_mapping_error() for error check da149daf erspan: do not use skb_mac_header() in ndo_start_xmit() 944f944e atm: idt77252: fix kmemleak when rmmod idt77252 204fa0b0 net/mlx5: Read the TC mapping of all priorities on ETS query 42049e65 bpf: Adjust insufficient default bpf_jit_limit b6e6af5a net/ps3_gelic_net: Use dma_mapping_error 6cd06bf6 net/ps3_gelic_net: Fix RX sk_buff length 4bbc59ec net: qcom/emac: Fix use after free bug in emac_remove due to race condition 526660c2 xirc2ps_cs: Fix use after free bug in xirc2ps_detach 7742c08e qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info d3c145a4 net: usb: smsc95xx: Limit packet length to skb->len c110051d scsi: scsi_dh_alua: Fix memleak for 'qdata' in alua_activate() 6d2e42d9 i2c: imx-lpi2c: check only for enabled interrupt flags bd04a5d2 igbvf: Regard vf reset nack as success bceda410 intel/igbvf: free irq on the error path in igbvf_request_msix() a88903a0 iavf: fix inverted Rx hash condition leading to disabled hash 37836933 iavf: diet and reformat 0b7c849c intel-ethernet: rename i40evf to iavf a71e4c85 i40evf: Change a VF mac without reloading the VF driver 533d9158 power: supply: da9150: Fix use after free bug in da9150_charger_remove due to race condition e8676808 UPSTREAM: fsverity: don't drop pagecache at end of FS_IOC_ENABLE_VERITY 06930bc1 UPSTREAM: fsverity: Remove WQ_UNBOUND from fsverity read workqueue f198e0a1 BACKPORT: blk-mq: clear stale request in tags->rq[] before freeing one request pool b8d378e9 Merge 4.19.279 into android-4.19-stable 30baa092 Linux 4.19.279 cf6939a8 HID: uhid: Over-ride the default maximum data buffer value with our own e4bcc58a HID: core: Provide new max_buffer_size attribute to over-ride the default 1715b382 serial: 8250_em: Fix UART port type 2c04adc4 drm/i915: Don't use stolen memory for ring buffers with LLC ffdf8d81 x86/mm: Fix use of uninitialized buffer in sme_enable() e6d5a0a1 fbdev: stifb: Provide valid pixelclock and add fb_check_var() checks 7569ee04 ftrace: Fix invalid address access in lookup_rec() when index is 0 4bc5a4df tracing: Make tracepoint lockdep check actually test something 508db45b tracing: Check field value in hist_field_name() a7971d28 sh: intc: Avoid spurious sizeof-pointer-div warning 5a3fb3b7 drm/amdkfd: Fix an illegal memory access 64b72f5e ext4: fix task hung in ext4_xattr_delete_inode 3aea195a ext4: fail ext4_iget if special inode unallocated 38dede42 jffs2: correct logic when creating a hole in jffs2_write_begin 913e215c mmc: atmel-mci: fix race between stop command and start of next command 5deeac0b media: m5mols: fix off-by-one loop termination error e0a37b43 hwmon: (xgene) Fix use after free bug in xgene_hwmon_remove due to race condition 55d01536 hwmon: (adt7475) Fix masking of hysteresis registers ad2ae163 hwmon: (adt7475) Display smoothing attributes in correct order 7b517989 ethernet: sun: add check for the mdesc_grab() b0d2bb5e net/iucv: Fix size of interrupt data 89441504 net: usb: smsc75xx: Move packet length check to prevent kernel panic in skb_pull 1ed6495f ipv4: Fix incorrect table ID in IOCTL path c891037e block: sunvdc: add check for mdesc_grab() returning NULL fafcb4b2 nvmet: avoid potential UAF in nvmet_req_complete() 53966d57 net: usb: smsc75xx: Limit packet length to skb->len 3405eb64 nfc: st-nci: Fix use after free bug in ndlc_remove due to race condition cf98933c net: phy: smsc: bail out in lan87xx_read_status if genphy_read_status fails 51f3bd37 net: tunnels: annotate lockless accesses to dev->needed_headroom de69dc87 qed/qed_dev: guard against a possible division by zero 4c20a07e nfc: pn533: initialize struct pn533_out_arg properly e23ca307 tcp: tcp_make_synack() can be called from process context 1e6933f7 clk: HI655X: select REGMAP instead of depending on it 2a866458 fs: sysfs_emit_at: Remove PAGE_SIZE alignment check c3c0387c ext4: fix cgroup writeback accounting with fs-layer encryption 68e69330 UPSTREAM: ext4: fix another off-by-one fsmap error on 1k block filesystems private/msm-google-modules/wlan/qca-wifi-host-cmn: (1 change) 1981f47e qcacmn: Don't destroy uncreated completion_freeq_lock private/msm-google-modules/wlan/qcacld-3.0: (1 change) 77123c4e qcacld-3.0: Validate CSA frequency and bandwidth private/msm-google/techpack/audio: (13 changes) 1e8afb06 dsp: add lock in ion free to avoid use after free 4c70a119 ASoC: msm-pcm-q6-v2: Add dsp buf check b12f3bf7 dsp: afe: Add check for num_channels 8cdf963f dsp: q6voice: Add buf size check for cvs cal data 98361d95 dsp: asm: validate payload size before access a37ceaed dsp: q6core: Avoid OOB access in q6core df1e0e64 ASoC: msm-pcm-host-voice: Handle OOB access in hpcm_start 7265fe49 dsp: afe: Add check for sidetone iir config copy size 4584a0a8 Merge android-msm-pixel-4.19-udc into android-msm-pixel-4.19-udc-qpr1 e867414f dsp: q6core: validate payload size before access for AVCS 4523f236 ASoC: msm-pcm-host-voice: Address buffer overflow in hpcm copy bd01be2b ASoC: msm-pcm-voip: Avoid interger underflow 9b74f93b Merge android-msm-pixel-4.19-udc into android-msm-pixel-4.19-udc-qpr1 private/msm-google/techpack/camera: (4 changes) 6f86da56 Merge android-msm-pixel-4.19-udc into android-msm-pixel-4.19-udc-qpr1 81d1b630 Merge "msm: camera: smmu: Use get_file to increase ref count" into android-msm-pixel-4.19-udc 12b076d9 msm: camera: core: validation of session/device/link handle df7e0747 msm: camera: smmu: Use get_file to increase ref count Bug: 197804811 Bug: 257756238 Bug: 258533280 Bug: 258554362 Bug: 260486287 Bug: 266568298 Bug: 273320626 Bug: 275298674 Bug: 276762552 Bug: 280919362 Bug: 283319108 Bug: 283948235 Bug: 286258190 Bug: 290061915 Bug: 290783303 Bug: 292252062 Bug: 292447561 Bug: 295019252 Bug: 295039120 Bug: 295051806 Bug: 295051886 Bug: 295052084 Bug: 295052121 Bug: 295052332 Bug: 295052588 Bug: 299130860 Bug: 299146464 Pick-Prebuilt: 572793512 Build-Id: 10893502 Processing-Config: kernel_headers Change-Id: I002476b030506a9d4a02b0288103ce322b1f2f0b Signed-off-by: Pindar Yang <pindaryang@google.com>