lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <lrkyqikg8lfux.fsf_-_@dev-dsk-mngyadam-1c-cb3f7548.eu-west-1.amazon.com>
Date: Tue, 21 Oct 2025 12:16:22 +0200
From: Mahmoud Nagy Adam <mngyadam@...zon.de>
To: Greg KH <gregkh@...uxfoundation.org>
CC: <stable@...r.kernel.org>, <nagy@...aternagy.com>, Jens Axboe
	<axboe@...nel.dk>, Xiubo Li <xiubli@...hat.com>, Ilya Dryomov
	<idryomov@...il.com>, Jeff Layton <jlayton@...nel.org>, Alexander Viro
	<viro@...iv.linux.org.uk>, Theodore Ts'o <tytso@....edu>, Andreas Dilger
	<adilger.kernel@...ger.ca>, Jaegeuk Kim <jaegeuk@...nel.org>, Chao Yu
	<chao@...nel.org>, Christoph Hellwig <hch@...radead.org>, "Darrick J. Wong"
	<djwong@...nel.org>, Trond Myklebust <trond.myklebust@...merspace.com>, "Anna
 Schumaker" <anna@...nel.org>, Ryusuke Konishi <konishi.ryusuke@...il.com>,
	"Matthew Wilcox (Oracle)" <willy@...radead.org>, Andrew Morton
	<akpm@...ux-foundation.org>, Hannes Reinecke <hare@...e.de>, Damien Le Moal
	<dlemoal@...nel.org>, Luis Chamberlain <mcgrof@...nel.org>,
	<linux-block@...r.kernel.org>, <linux-kernel@...r.kernel.org>,
	<ceph-devel@...r.kernel.org>, <linux-fsdevel@...r.kernel.org>,
	<linux-ext4@...r.kernel.org>, <linux-f2fs-devel@...ts.sourceforge.net>,
	<linux-xfs@...r.kernel.org>, <linux-nfs@...r.kernel.org>,
	<linux-nilfs@...r.kernel.org>, <linux-mm@...ck.org>
Subject: Re: [PATCH 6.1 0/8] Backporting CVE-2025-38073 fix patch

Greg KH <gregkh@...uxfoundation.org> writes:

> On Tue, Oct 21, 2025 at 09:25:37AM +0200, Mahmoud Nagy Adam wrote:
>> Greg KH <gregkh@...uxfoundation.org> writes:
>>
>> >
>> >
>> > On Tue, Oct 21, 2025 at 09:03:35AM +0200, Mahmoud Adam wrote:
>> >> This series aims to fix the CVE-2025-38073 for 6.1 LTS.
>> >
>> > That's not going to work until there is a fix in the 6.6.y tree first.
>> > You all know this quite well :(
>> >
>> > Please work on that tree first, and then move to older ones.
>> >
>>
>> Yup, I've already sent a series for 6.6 yesterday:
>> https://lore.kernel.org/stable/20251020122541.7227-1-mngyadam@amazon.de/
>
> Ah, totally missed that as it was "just" a single backport, my fault.
>

6.6 had all the required dependencies already so it was fortunately a
simpler series :). I'll make sure to reference the other series in the
future as well.

> Thanks for this, I'll review this when I get a chance.  How was this
> tested?

This was tested by our internal testing over various EC2 instances
(x86_64 & ARM). Our testing includes running kselftests, fstests, LTP
suites.

If there are specific tests you’d like me to run or results to provide,
please let me know.

Thanks,
MNAdam



Amazon Web Services Development Center Germany GmbH
Tamara-Danz-Str. 13
10243 Berlin
Geschaeftsfuehrung: Christian Schlaeger
Eingetragen am Amtsgericht Charlottenburg unter HRB 257764 B
Sitz: Berlin
Ust-ID: DE 365 538 597

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ