Hi,
DSA reinstalled a loong64 physical machine (previously using the
debian-ports archive, now running latest sid), and we started observing
kernel warnings when starting a VM using KVM.
First warning:
| [ 2050.507635] ------------[ cut here ]------------
| [ 2050.507662] memcpy: detected field-spanning write (size 4) of single field "p" at arch/loongarch/kvm/intc/eiointc.c:520 (size 0)
| [ 2050.507682] WARNING: arch/loongarch/kvm/intc/eiointc.c:520 at kvm_eiointc_regs_access.isra.0+0x354/0x3c0, CPU#6: qemu-system-loo/16813
| [ 2050.507697] Modules linked in: bridge stp llc nls_ascii nls_cp437 vfat fat snd_hda_intel snd_intel_dspcfg snd_hda_codec snd_hda_core ast snd_hwdep drm_client_lib snd_pcm drm_shmem_helper sg drm_kms_helper snd_timer snd i2c_algo_bit evdev soundcore ip6t_REJECT nf_reject_ipv6 ip6table_filter ip6_tables xt_hashlimit ipt_REJECT nf_reject_ipv4 xt_NFLOG nfnetlink_log xt_multiport xt_tcpudp xt_conntrack nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 drm iptable_filter ip_tables x_tables dm_snapshot dm_bufio vhost_net vhost tun vhost_iotlb tap sch_fq tcp_bbr zlib_deflate configfs nfnetlink autofs4 ext4 crc16 mbcache jbd2 crc32c_cryptoapi raid10 raid456 async_raid6_recov async_memcpy async_pq async_xor async_tx xor raid6_pq raid0 dm_mod raid1 md_mod sd_mod cdc_ether usbnet mii ahci libahci xhci_pci ohci_pci xhci_hcd libata ehci_pci dwmac_loongson ehci_hcd stmmac_libpci megaraid_sas ohci_hcd stmmac usbcore scsi_mod r8169 pcs_xpcs realtek phylink scsi_common usb_common efivarfs
| [ 2050.507873] CPU: 6 UID: 0 PID: 16813 Comm: qemu-system-loo Not tainted 6.19.8+deb14-loong64 #1 PREEMPTLAZY Debian 6.19.8-1
| [ 2050.507879] Hardware name: LOONGSON Dabieshan/Loongson-LS2C50C6, BIOS Loongson UEFI (3C50007A2000_C6) V4.3.0-Dual 05/21/25 09:17:40
| [ 2050.507883] pc 9000000000280d74 ra 9000000000280d74 tp 900000010faac000 sp 900000010faafb20
| [ 2050.507887] a0 0000000000000074 a1 0000000000000000 a2 900000010faaf920 a3 900000010faaf918
| [ 2050.507890] a4 0000000000000000 a5 9000000001a8d960 a6 203a7970636d656d a7 293020657a697328
| [ 2050.507894] t0 6d08ee86308d20d5 t1 6d08ee86308d20d5 t2 90000000017e8000 t3 0000000000000001
| [ 2050.507897] t4 fffffffffffffffe t5 00000000ffffdfff t6 900010207ff04000 t7 0000000000000000
| [ 2050.507900] t8 0000000000000000 u0 900000011ad00050 s9 900000010faafec0 s0 900000010faafb90
| [ 2050.507903] s1 900000011ad00000 s2 900000011ad00050 s3 0000000000000000 s4 00007ffffbf39830
| [ 2050.507906] s5 000000000000002f s6 000055556b5480d0 s7 0000555559d0be48 s8 0000000000000000
| [ 2050.507910] ra: 9000000000280d74 kvm_eiointc_regs_access.isra.0+0x354/0x3c0
| [ 2050.507914] ERA: 9000000000280d74 kvm_eiointc_regs_access.isra.0+0x354/0x3c0
| [ 2050.507918] CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE)
| [ 2050.507932] PRMD: 00000000 (PPLV0 -PIE -PWE)
| [ 2050.507940] EUEN: 00000007 (+FPE +SXE +ASXE -BTE)
| [ 2050.507948] ECFG: 00071c1d (LIE=0,2-4,10-12 VS=7)
| [ 2050.507956] ESTAT: 000c0000 [BRK] (IS= ECode=12 EsubCode=0)
| [ 2050.507962] PRID: 0014c011 (Loongson-64bit, Loongson-3C5000)
| [ 2050.507966] CPU: 6 UID: 0 PID: 16813 Comm: qemu-system-loo Not tainted 6.19.8+deb14-loong64 #1 PREEMPTLAZY Debian 6.19.8-1
| [ 2050.507970] Hardware name: LOONGSON Dabieshan/Loongson-LS2C50C6, BIOS Loongson UEFI (3C50007A2000_C6) V4.3.0-Dual 05/21/25 09:17:40
| [ 2050.507972] Stack : 900000010faaf7f8 0000000000000000 9000000000238828 900000010faac000
| [ 2050.507978] 900000010faaf740 900000010faaf748 0000000000000000 900000010faaf888
| [ 2050.507983] 900000010faaf880 900000010faaf880 900010207ff19b40 6572617764726148
| [ 2050.507987] 203a656d616e2065 900000010faaf748 6d08ee86308d20d5 900000012859c840
| [ 2050.507992] 900000010faac000 90000000015c8868 00000000ffffdfff 900010207ff04000
| [ 2050.507997] 0000000000000000 0000000000000000 000000207b878000 900000010faafec0
| [ 2050.508002] 0000000000000000 90000000017e8000 0000000000000000 90000000015c8868
| [ 2050.508006] 0000000000000208 0000000000000009 000055556b5480d0 0000555559d0be48
| [ 2050.508011] 0000000000000000 0000000000000000 9000000000238844 000055556bcb67e8
| [ 2050.508016] 00000000000000b0 0000000000000000 0000000000000007 0000000000071c1d
| [ 2050.508020] ...
| [ 2050.508023] Call Trace:
| [ 2050.508026] [<9000000000238844>] show_stack+0x64/0x190
| [ 2050.508037] [<9000000000230fc8>] dump_stack_lvl+0x70/0x9c
| [ 2050.508041] [<9000000000289630>] __warn+0xa0/0x1b0
| [ 2050.508046] [<90000000012358e8>] __report_bug+0xa8/0x1c0
| [ 2050.508052] [<9000000001235af0>] report_bug+0x40/0xd0
| [ 2050.508055] [<90000000012791f4>] do_bp+0x254/0x420
| [ 2050.508066] [<0000000000000000>] 0x0
| [ 2050.508070] [<9000000000280d74>] kvm_eiointc_regs_access.isra.0+0x354/0x3c0
| [ 2050.508073] [<90000000002812bc>] kvm_eiointc_set_attr+0x34c/0x770
| [ 2050.508076] [<9000000000262f04>] kvm_device_ioctl+0x264/0x3a0
| [ 2050.508082] [<900000000075f09c>] sys_ioctl+0x52c/0x1150
| [ 2050.508089] [<9000000001279804>] do_syscall+0xc4/0x320
| [ 2050.508094] ---[ end trace 0000000000000000 ]---
This warning could have been introduced by the following upstream
commit:
commit 01a8e68396a6d51f5ba92021ad1a4b8eaabdd0e7
Author: Bibo Mao <maobibo@loongson.cn>
Date: Thu Sep 18 19:44:22 2025 +0800
LoongArch: KVM: Avoid copy_*_user() with lock hold in kvm_eiointc_sw_status_access()
The second one:
| [ 2050.508176] ------------[ cut here ]------------
| [ 2050.508179] UBSAN: array-index-out-of-bounds in /build/reproducible-path/linux-6.19.8/arch/loongarch/kvm/vcpu.c:569:20
| [ 2050.508234] index -1 is out of range for type 'kvm_phyid_info [256]'
| [ 2050.508248] CPU: 6 UID: 0 PID: 16813 Comm: qemu-system-loo Tainted: G W 6.19.8+deb14-loong64 #1 PREEMPTLAZY Debian 6.19.8-1
| [ 2050.508253] Tainted: [W]=WARN
| [ 2050.508254] Hardware name: LOONGSON Dabieshan/Loongson-LS2C50C6, BIOS Loongson UEFI (3C50007A2000_C6) V4.3.0-Dual 05/21/25 09:17:40
| [ 2050.508256] Stack : 900000010faaf8f8 0000000000000000 9000000000238828 900000010faac000
| [ 2050.508261] 900000010faaf840 900000010faaf848 0000000000000000 900000010faaf988
| [ 2050.508266] 900000010faaf980 900000010faaf980 900010207ff1a3f0 6572617764726148
| [ 2050.508271] 203a656d616e2065 900000010faaf848 6d08ee86308d20d5 900000012859c840
| [ 2050.508275] 900000010faac000 90000000015c8868 00000000ffffdfff 900010207ff04000
| [ 2050.508280] 0000000000000000 0000000000000000 000000207b878000 0000000000000000
| [ 2050.508284] 0000000000000000 90000000017e8000 0000000000000000 90000000015c8868
| [ 2050.508289] 0000000000000003 ffffffffffffffff 900000011ad020b8 0000000000000000
| [ 2050.508293] 900000011ad00000 0000000000000000 9000000000238844 000055556bcb67e8
| [ 2050.508298] 00000000000000b0 0000000000000007 0000000000000007 0000000000071c1d
| [ 2050.508302] ...
| [ 2050.508304] Call Trace:
| [ 2050.508306] [<9000000000238844>] show_stack+0x64/0x190
| [ 2050.508310] [<9000000000230fc8>] dump_stack_lvl+0x70/0x9c
| [ 2050.508314] [<900000000022bc60>] ubsan_epilogue+0xc/0x3c
| [ 2050.508318] [<9000000000bc61c4>] __ubsan_handle_out_of_bounds+0xa4/0xb0
| [ 2050.508322] [<900000000027a6c0>] kvm_get_vcpu_by_cpuid+0xb0/0xc0
| [ 2050.508326] [<90000000002813b8>] kvm_eiointc_set_attr+0x448/0x770
| [ 2050.508329] [<9000000000262f04>] kvm_device_ioctl+0x264/0x3a0
| [ 2050.508334] [<900000000075f09c>] sys_ioctl+0x52c/0x1150
| [ 2050.508338] [<9000000001279804>] do_syscall+0xc4/0x320
| [ 2050.508343] ---[ end trace ]---
The problem was not present when running kernel 6.17.7+deb14-loong64, so
it seems to be a relatively recent regression. Despite the warnings,
things seems to work relatively well.
Regards
Aurelien
Hi, Please find attached the corresponding configuration file used to build the kernel, extracted from the debian package. Regards Aurelien
We believe that the bug you reported is fixed in the latest version of linux, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1131431@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Salvatore Bonaccorso <carnil@debian.org> (supplier of updated linux package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Sun, 05 Apr 2026 08:17:47 +0200 Source: linux Architecture: source Version: 6.19.11-1 Distribution: unstable Urgency: medium Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Closes: 1131431 1131546 1132622 Changes: linux (6.19.11-1) unstable; urgency=medium . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.19.11 - cxl/port: Fix use after free of parent_port in cxl_detach_ep() - cxl/region: Fix leakage in __construct_region() - bpf: Reset register ID for BPF_END value tracking - bpf: Fix constant blinding for PROBE_MEM32 stores (CVE-2026-23417) (Closes: #1132622) - [amd64] x86/perf: Make sure to program the counter value for stopped events on migration - perf: Make sure to use pmu_ctx->pmu for groups - [s390x] mm: Add missing secure storage access fixups for donated memory - objtool/klp: fix data alignment in __clone_symbol() - livepatch/klp-build: Fix inconsistent kernel version - cxl/hdm: Avoid incorrect DVSEC fallback when HDM decoders are enabled - hwmon: axi-fan: don't use driver_override as IRQ name - driver core: generalize driver_override in struct device - driver core: platform: use generic driver_override infrastructure - perf metricgroup: Fix metricgroup__has_metric_or_groups() - bpf: Release module BTF IDR before module unload - cxl: Adjust the startup priority of cxl_pmem to be higher than that of cxl_acpi - bpf: Fix exception exit lock checking for subprogs - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN - bpf: Fix unsound scalar forking in maybe_fork_scalars() for BPF_OR - tracing: Revert "tracing: Remove pid in task_rename tracing output" - [amd64] platform/x86: hp-wmi: Add Omen 16-wf0xxx fan and thermal support - HID: asus: avoid memory leak in asus_report_fixup() - [amd64] platform/x86: intel-hid: Add Dell 14 Plus 2-in-1 to dmi_vgbs_allow_list - nvme-pci: cap queue creation to used queues - nvme-fabrics: use kfree_sensitive() for DHCHAP secrets - [amd64] platform/x86: hp-wmi: Add Omen 16-xd0xxx fan and thermal support - [amd64] platform/x86: intel-hid: Enable 5-button array on ThinkPad X1 Fold 16 Gen 1 - [amd64] platform/x86: touchscreen_dmi: Add quirk for y-inverted Goodix touchscreen on SUPI S10 - [amd64] platform/x86: hp-wmi: add Omen 14-fb1xxx (board 8E41) support - nvme-pci: ensure we're polling a polled queue - HID: magicmouse: fix battery reporting for Apple Magic Trackpad 2 - HID: magicmouse: avoid memory leak in magicmouse_report_fixup() - [amd64] platform/x86: hp-wmi: Add Victus 16-d0xxx support - [amd64] HID: intel-ish-hid: ipc: Add Nova Lake-H/S PCI device IDs - [amd64] platform/x86: oxpec: Add support for OneXPlayer APEX - HID: apple: Add EPOMAKER TH87 to the non-apple keyboards list - [amd64] platform/x86: oxpec: Add support for OneXPlayer X1z - net: usb: r8152: add TRENDnet TUC-ET2G - kbuild: install-extmod-build: Package resolve_btfids if necessary - [amd64] platform/x86: oxpec: Add support for Aokzoe A2 Pro - [amd64] platform/x86: oxpec: Add support for OneXPlayer X1 Air - HID: mcp2221: cancel last I2C command on read error - HID: asus: add xg mobile 2023 external hardware support - module: Fix kernel panic when a symbol st_shndx is out of bounds - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout - [amd64] ASoC: rt1321: fix DMIC ch2/3 mask issue - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP - [amd64] ASoC: Intel: sof_sdw: Add quirk for Alienware Area 51 (2025) 0CCD SKU - ALSA: hda/hdmi: Add Tegra238 HDA codec device ID - ASoC: cs35l56: Only patch ASP registers if the DAI is part of a DAIlink - dma-buf: Include ioctl.h in UAPI header - block: break pcpu_alloc_mutex dependency on freeze_lock - ALSA: hda/senary: Ensure EAPD is enabled during init - [amd64] ASoC: amd: acp: Add ACP6.3 match entries for Cirrus Logic parts - bpf: Fix u32/s32 bounds when ranges cross min/max boundary - HID: apple: avoid memory leak in apple_report_fixup() - sched_ext: Use WRITE_ONCE() for the write side of dsq->seq update - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create - objtool: Use HOSTCFLAGS for HAVE_XXHASH test - [powerpc*] powerpc64/ftrace: fix OOL stub count with clang - ALSA: hda/realtek: add HP Laptop 14s-dr5xxx mute LED quirk - objtool/klp: Disable unsupported pr_debug() usage - ALSA: hda/realtek: Add quirk for Gigabyte Technology to fix headphone - ALSA: hda/realtek: Add headset jack quirk for Thinkpad X390 - objtool: Handle Clang RSP musical chairs - nvmet: move async event work off nvmet-wq - drm/amdgpu: fix gpu idle power consumption issue for gfx v12 - usb: core: new quirk to handle devices with zero configurations - ALSA: usb-audio: Add iface reset and delay quirk for SPACETOUCH USB Audio - ALSA: hda/realtek: add quirk for ASUS UM6702RC - i3c: master: dw-i3c: Fix missing of_node for virtual I2C adapter - xfrm: add missing extack for XFRMA_SA_PCPU in add_acquire and allocspi - xfrm: fix the condition on x->pcpu_num in xfrm_sa_len - xfrm: call xdo_dev_state_delete during state update - esp: fix skb leak with espintcp and async crypto - [arm64] pinctrl: renesas: rzt2h: Fix device node leak in rzt2h_gpio_register() - xfrm: iptfs: fix skb_put() panic on non-linear skb during reassembly - [arm64] pinctrl: qcom: spmi-gpio: implement .get_direction() - xfrm: Fix work re-schedule after cancel in xfrm_nat_keepalive_net_fini() - xfrm: prevent policy_hthresh.work from racing with netns teardown - af_key: validate families in pfkey_send_migrate() - dma: swiotlb: add KMSAN annotations to swiotlb_bounce() - erofs: set fileio bio failed in short read case - can: statistics: add missing atomic access in hot path - Bluetooth: L2CAP: Fix stack-out-of-bounds read in l2cap_ecred_conn_req - Bluetooth: L2CAP: Validate PDU length before reading SDU length in l2cap_ecred_data_rcv() - Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold - Bluetooth: MGMT: Fix dangling pointer on mgmt_add_adv_patterns_monitor_complete - Bluetooth: hci_ll: Fix firmware leak on error path - Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb - [arm64] pinctrl: mediatek: common: Fix probe failure for devices without EINT - ionic: fix persistent MAC address override on PF - nfc: nci: fix circular locking dependency in nci_close_device - net: openvswitch: Avoid releasing netdev before teardown completes - openvswitch: defer tunnel netdev_put to RCU release - openvswitch: validate MPLS set/set_masked payload length - rtnetlink: count IFLA_PARENT_DEV_{NAME,BUS_NAME} in if_nlmsg_size - rtnetlink: count IFLA_INFO_SLAVE_KIND in if_nlmsg_size - net: bcmasp: streamline early exit in probe - net: bcmasp: fix double free of WoL irq - net: bcmasp: fix double disable of clk - [amd64] platform/x86: ISST: Check HWP support before MSR access - [amd64] platform/x86: lenovo: wmi-gamezone: Drop gz_chain_head - platform/olpc: olpc-xo175-ec: Fix overflow error message to print inlen - [amd64] platform/x86: intel-hid: disable wakeup_mode during hibernation - ice: fix inverted ready check for VF representors - ice: use ice_update_eth_stats() for representor stats - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() - ipv6: Remove permanent routes from tb6_gc_hlist when all exceptions expire. - ipv6: Don't remove permanent routes with exceptions from tb6_gc_hlist. - net: fix fanout UAF in packet_release() via NETDEV_UP race - net: airoha: add RCU lock around dev_fill_forward_path - net: b44: always select CONFIG_FIXED_PHY - udp: Fix wildcard bind conflict check when using hash2 - net: enetc: fix the output issue of 'ethtool --show-ring' - virtio-net: correct hdr_len handling for VIRTIO_NET_F_GUEST_HDRLEN - virtio-net: correct hdr_len handling for tunnel gso - team: fix header_ops type confusion with non-Ethernet ports - net: ti: icssg-prueth: fix use-after-free of CPPI descriptor in RX path - net: lan743x: fix duplex configuration in mac_link_up - rtnetlink: fix leak of SRCU struct in rtnl_link_register - net_sched: codel: fix stale state for empty flows in fq_codel - dma-mapping: add missing `inline` for `dma_free_attrs` - Bluetooth: L2CAP: Fix send LE flow credits in ACL link - Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock - Bluetooth: L2CAP: Fix not tracking outstanding TX ident - Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() - Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite loop - Bluetooth: btusb: clamp SCO altsetting table indices - tls: Purge async_hold in tls_decrypt_async_wait() (CVE-2026-23414) - netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD - netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() - netfilter: nft_set_rbtree: revisit array resize logic - netfilter: nf_conntrack_expect: skip expectations in other netns via proc - netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp - netfilter: ctnetlink: use netlink policy range checks - net: macb: use the current queue number for stats - RDMA/bng_re: Fix silent failure in HWRM version query - RDMA/efa: Check stored completion CTX command ID with received one - RDMA/efa: Improve admin completion context state machine - RDMA/efa: Fix use of completion ctx after free - regmap: Synchronize cache for the page selector - ALSA: hda/realtek: Sequence GPIO2 on Star Labs StarFighter - RDMA/rw: Fall back to direct SGE on MR pool exhaustion - RDMA/efa: Fix possible deadlock - ALSA: usb-audio: Exclude Scarlett 2i2 1st Gen from SKIP_IFACE_SETUP - RDMA/irdma: Initialize free_qp completion before using it - RDMA/irdma: Update ibqp state to error if QP is already in error state - RDMA/irdma: Remove a NOP wait_event() in irdma_modify_qp_roce() - RDMA/irdma: Clean up unnecessary dereference of event->cm_node - RDMA/irdma: Remove reset check from irdma_modify_qp_to_err() - RDMA/irdma: Fix deadlock during netdev reset with active connections - RDMA/irdma: Return EINVAL for invalid arp index error - RDMA/irdma: Harden depth calculation functions - ASoC: simple-card-utils: Check value of is_playback_only and is_capture_only - ASoC: fsl: imx-card: initialize playback_only and capture_only - scsi: scsi_transport_sas: Fix the maximum channel scanning issue - [amd64] x86/efi: efi_unmap_boot_services: fix calculation of ranges_to_free size - [arm64] drm/mediatek: dsi: Store driver data before invoking mipi_dsi_host_register - [amd64] drm/i915/gmbus: fix spurious timeout on 512-byte burst reads - PM: hibernate: Drain trailing zero pages on userspace restore - PM: sleep: Drop spurious WARN_ON() from pm_restore_gfp_mask() - drm/xe/pf: Fix use-after-free in migration restore - spi: sn-f-ospi: Fix resource leak in f_ospi_probe() - [amd64] ASoC: Intel: catpt: Fix the device initialization - spi: meson-spicc: Fix double-put in remove path - drm/amd/display: Do not skip unrelated mode changes in DSC validation - ASoC: dt-bindings: stm32: Fix incorrect compatible string in stm32h7-sai match - rust: regulator: do not assume that regulator_get() returns non-null - drm/xe: Implement recent spec updates to Wa_16025250150 - spi: use generic driver_override infrastructure - ACPI: EC: clean up handlers on probe failure in acpi_ec_setup() - drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib - hwmon: (adm1177) fix sysfs ABI violation and current unit conversion - ASoC: SDCA: fix finding wrong entity - hwmon: (pmbus) Mark lowest/average/highest/rated attributes as read-only - hwmon: (pmbus) Introduce the concept of "write-only" attributes - hwmon: (pmbus/core) Protect regulator operations with mutex - sysctl: fix uninitialized variable in proc_do_large_bitmap - spi: spi-fsl-lpspi: fix teardown order issue (UAF) - io_uring/fdinfo: fix SQE_MIXED SQE displaying - io_uring/fdinfo: fix OOB read in SQE_MIXED wrap check - ALSA: usb-audio: Exclude Scarlett 2i4 1st Gen from SKIP_IFACE_SETUP - [s390x] syscalls: Add spectre boundary for syscall dispatch table - [s390x] barrier: Make array_index_mask_nospec() __always_inline - [s390x] entry: Scrub r12 register on kernel entry - tracing: Drain deferred trigger frees if kthread creation fails - tracing: Fix potential deadlock in cpu hotplug with osnoise - drm/xe: always keep track of remap prev/next - ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() - ksmbd: fix potencial OOB in get_file_all_info() for compound requests - ksmbd: fix memory leaks and NULL deref in smb2_lock() - ksmbd: do not expire session on binding failure - Revert "ALSA: hda/intel: Add MSI X870E Tomahawk to denylist" - ALSA: hda/realtek: add quirk for ASUS Strix G16 G615JMR - ALSA: firewire-lib: fix uninitialized local variable - accel/ivpu: Add disable clock relinquish workaround for NVL-A0 - [arm64] ASoC: codecs: wcd934x: fix typo in dt parsing - [amd64] ASoC: SOF: ipc4-topology: Allow bytes controls without initial payload - can: gw: fix OOB heap access in cgw_csum_crc8_rel() - can: isotp: fix tx.buf use-after-free in isotp_sendmsg() - can: netlink: can_changelink(): add missing error handling to call can_ctrlmode_changelink() - cpufreq: Don't skip cpufreq_frequency_table_cpuinfo() - cpufreq: conservative: Reset requested_freq on limits change - kbuild: Delete .builtin-dtbs.S when running make clean - mm/damon/stat: monitor all System RAM resources - thermal: intel: int340x: soc_slider: Set offset only for balanced mode - RDMA/ionic: Preserve and set Ethernet source MAC after ib_ud_header_init() - [amd64] platform/x86: ISST: Correct locked bit width - [arm64] KVM: arm64: Discard PC update state on vcpu reset - [arm64] KVM: arm64: Fix the descriptor address in __kvm_at_swap_desc() - hwmon: (pmbus/ina233) Fix error handling and sign extension in shunt voltage read - hwmon: (pmbus/isl68137) Add mutex protection for AVS enable sysfs attributes - hwmon: (peci/cputemp) Fix crit_hyst returning delta instead of absolute temperature - hwmon: (peci/cputemp) Fix off-by-one in cputemp_is_visible() - media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex - media: verisilicon: Fix kernel panic due to __initconst misuse - xfrm: iptfs: validate inner IPv4 header length in IPTFS payload - xfrm: iptfs: only publish mode_data after clone setup - virt: tdx-guest: Fix handling of host controlled 'quote' buffer length - virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false - vfio/pci: Fix double free in dma-buf feature - erofs: add GFP_NOIO in the bio completion if needed - alarmtimer: Fix argument order in alarm_timer_forward() - mm/huge_memory: fix folio isn't locked in softleaf_to_folio() - writeback: don't block sync for filesystems with no data integrity guarantees - [amd64] x86/cpu: Enable FSGSBASE early in cpu_init_exception_handling() - [amd64] x86/cpu: Remove X86_CR4_FRED from the CR4 pinned bits mask - [amd64] x86/fred: Fix early boot failures on SEV-ES/SNP guests - phy: qcom: qmp-ufs: Fix SM8650 PCS table for Gear 4 - ovl: make fsync after metadata copy-up opt-in mount option - ovl: fix wrong detection of 32bit inode numbers - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() - scsi: ses: Handle positive SCSI error from ses_recv_diag() - net: macb: Move devm_{free,request}_irq() out of spin lock area - net: macb: Protect access to net_device::ip_ptr with RCU lock - net: macb: Use dev_consume_skb_any() to free TX SKBs - [amd64] KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE (CVE-2026-23401) - [amd64] KVM: x86/mmu: Only WARN in direct MMUs when overwriting shadow-present SPTE (CVE-2026-23402) - jbd2: gracefully abort on checkpointing state corruptions - [arm64] irqchip/qcom-mpm: Add missing mailbox TX done acknowledgment - iomap: fix invalid folio access when i_blkbits differs from I/O granularity - i2c: designware: amdisp: Fix resume-probe race condition issue - futex: Clear stale exiting pointer in futex_lock_pi() retry path - i2c: imx: fix i2c issue when reading multiple messages - i2c: imx: ensure no clock is generated after last read - dmaengine: fsl-edma: fix channel parameter config for fixed channel requests - drm/amdgpu: prevent immediate PASID reuse case - drm/amdgpu: fix strsep() corrupting lockup_timeout on multi-GPU (v3) - drm/amd/display: Fix DCE LVDS handling - drm/amd/display: Fix drm_edid leak in amdgpu_dm - drm/amd/display: check if ext_caps is valid in BL setup - [amd64] drm/i915/dp_tunnel: Fix error handling when clearing stream BW in atomic state - [amd64] drm/i915: Order OP vs. timeout correctly in __wait_for() - [amd64] drm/i915: Unlink NV12 planes earlier - [loong64] Fix missing NULL checks for kstrdup() - [loong64] vDSO: Emit GNU_EH_FRAME correctly - [loong64] Workaround LS2K/LS7A GPU DMA hang bug - [loong64] KVM: Make kvm_get_vcpu_by_cpuid() more robust (Closes: #1131431) - [loong64] KVM: Fix base address calculation in kvm_eiointc_regs_access() (Closes: #1131431) - [loong64] KVM: Handle the case that EIOINTC's coremap is empty (Closes: #1131431) - drm/amd/pm: Return -EOPNOTSUPP for unsupported OD_MCLK on smu_v13_0_6 - mm/memory: fix PMD/PUD checks in follow_pfnmap_start() - mm/mseal: update VMA end correctly on merge (CVE-2026-23416) - mm/damon/sysfs: fix param_ctx leak on damon_sysfs_new_test_ctx() failure - mm/damon/sysfs: check contexts->nr before accessing contexts_arr[0] - mm/damon/sysfs: check contexts->nr in repeat_call_fn - mm/pagewalk: fix race between concurrent split and refault - xfs: stop reclaim before pushing AIL during unmount - xfs: save ailp before dropping the AIL lock in push callbacks - xfs: avoid dereferencing log items after push callbacks - xfs: scrub: unlock dquot before early return in quota scrub - xfs: fix ri_total validation in xlog_recover_attri_commit_pass2 - xfs: don't irele after failing to iget in xfs_attri_recover_work - xfs: remove file_path tracepoint data - ext4: fix journal credit check when setting fscrypt context - ext4: convert inline data to extents when truncate exceeds inline size - ext4: fix stale xarray tags after writeback - ext4: do not check fast symlink during orphan recovery - ext4: fix fsync(2) for nojournal mode - ext4: make recently_deleted() properly work with lazy itable initialization - ext4: replace BUG_ON with proper error handling in ext4_read_inline_folio - ext4: publish jinode after initialization - ext4: test if inode's all dirty pages are submitted to disk - ext4: validate p_idx bounds in ext4_ext_correct_indexes - ext4: avoid infinite loops caused by residual data - ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() - ext4: reject mount if bigalloc with s_first_data_block != 0 - ext4: fix use-after-free in update_super_work when racing with umount - ext4: fix the might_sleep() warnings in kvfree() - ext4: handle wraparound when searching for blocks for indirect mapped blocks - ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths - ext4: always drain queued discard work in ext4_mb_release() - [arm64] dts: imx8mn-tqma8mqnl: fix LDO5 power off - [powerpc*] powerpc64/bpf: do not increment tailcall count when prog is NULL - mm/damon/core: avoid use of half-online-committed context - rust: pin-init: internal: init: document load-bearing fact of field accessors - ksmbd: fix use-after-free and NULL deref in smb_grant_oplock() - [amd64] dmaengine: idxd: Fix crash when the event log is disabled - [amd64] dmaengine: idxd: Fix possible invalid memory access after FLR - [amd64] dmaengine: idxd: Fix not releasing workqueue on .release() - [amd64] dmaengine: idxd: Fix memory leak when a wq is reset - [amd64] dmaengine: idxd: Fix freeing the allocated ida too late - [amd64] dmaengine: idxd: Fix leaking event log memory - phy: ti: j721e-wiz: Fix device node reference leak in wiz_get_lane_phy_types() - netfs: Fix kernel BUG in netfs_limit_iter() for ITER_KVEC iterators - netfs: Fix NULL pointer dereference in netfs_unbuffered_write() on retry - [amd64] dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc() - netfs: Fix read abandonment during retry - btrfs: fix super block offset in error message in btrfs_validate_super() - btrfs: fix leak of kobject name for sub-group space_info - btrfs: fix lost error when running device stats on multiple devices fs - xen/privcmd: unregister xenstore notifier on module exit - netfs: Fix the handling of stream->front by removing it - [arm64] irqchip/renesas-rzv2h: Fix error path in rzv2h_icu_probe_common() - futex: Require sys_futex_requeue() to have identical flags - futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() - ext4: introduce EXPORT_SYMBOL_FOR_EXT4_TEST() helper - ext4: fix mballoc-test.c is not compiled when EXT4_KUNIT_TESTS=M - bug: avoid format attribute warning for clang as well - Bluetooth: L2CAP: Fix regressions caused by reusing ident - Revert "perf jevents: Handle deleted JSONS in out of source builds" . [ Ben Hutchings ] * d/b/test-patches: Expect debian/control-real target to return 0 * d/b/test-patches: Disable signing so we build linux-image packages again (Closes: #1131546) Checksums-Sha1: f2b348cc24c2d88a022652620da9dd65d5d3473c 196166 linux_6.19.11-1.dsc ff546d848e80204f932d7e3c2d5fac53df6e06ef 159228696 linux_6.19.11.orig.tar.xz 3f30eae0fda560eb254f24f9f3faf8a88a1aba06 1485108 linux_6.19.11-1.debian.tar.xz 7335196aadfae1e963cce02fc1fd8dbc9aa840eb 6912 linux_6.19.11-1_source.buildinfo Checksums-Sha256: e117be10e21ce8df055692f360a7ccd60a4558d055d9ef3be5babffa3f4aad60 196166 linux_6.19.11-1.dsc e19d838c34519b050dd48334c673b07f4089d56449b453e6d1d04460e0667fa6 159228696 linux_6.19.11.orig.tar.xz 4a6ed4dca05d70ab91ddb81f81afb0e134917103907c90fd0051b2fe250001e1 1485108 linux_6.19.11-1.debian.tar.xz 1a69894c3b2117e6e54861ae28b9905e1c5aef513398ffb8d1982893b3afc0c8 6912 linux_6.19.11-1_source.buildinfo Files: 6677ded3b9cd48ce0423a20945f146d4 196166 kernel optional linux_6.19.11-1.dsc 6e186626d6177e0a1d9eae1224da59f4 159228696 kernel optional linux_6.19.11.orig.tar.xz 2132543f733e089d839440f9c959f3d0 1485108 kernel optional linux_6.19.11-1.debian.tar.xz ae70cd452e3fb8fc07256231d2a14cdf 6912 kernel optional linux_6.19.11-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmnR/vBfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89E+1gQAJq8k6iUr9LhHozUoZVUoaniYATPvgdL FZ0c1p38yEy/a03D+cCbH4xtRLwG/gdp5tsHI0zsnrDbN4hL2s0VFJVGNGLqz/bV Y58xs4jUMSzqe0vjTZeg9h2M7DT39f7CEuRB9F7wFQxsLiI9Uq1sv7BoNtlbewdA Z2hNSpF8r7hi7LhZd4Nx8t7zfQQJe36zBIk8Ia/K+CAkI5I6G7A/pUh1U9sJTtz3 fBS7w5THcfY8oVlByXX8AnVnDGlazJfKstKxf/zjnnX6Jv6wLPZHtFWAhLNlJcAE Dnrmb4TfEPh1jO8bl2FgJPj626H5n46m36kTNGaPphvPMBq6ECK6xpqHYBm6P8/d 6LvC8R+BmRKZlHqCO/0p0iP9vkfzxoBGvEBENhPG7iu7Xn07C9uos3+UZUnS9nvw A8OY/jCy0hPtbZ0H4IVPTQjnXudIbCeAfs/Q9KDCh58oLpHMC2bd5+lnTlEklTJO og5NCPs0zXWJXmNehu6vYDrvbzVruNrnqGdX+ojTbWGi30YKewm7f9/IgDhb/ifB m1+INx/TI1yysxWf8mUYZ6PvrgBXoG2U0/XhuAhqGJ4GXF91ZYsTx7lp/OJjsX6d 6WA9MSKS73q5tdlQuIhHWx4rOaxhEDboLdESub9/N79VPBebx3olhYxxbECSTDbS iXBB/LgnLNzi =gCuM -----END PGP SIGNATURE-----
Hi, ... Thanks, I confirm that the bug is indeed fixed. Regards Aurelien
We believe that the bug you reported is fixed in the latest version of
linux, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1131431@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Ben Hutchings <benh@debian.org> (supplier of updated linux package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 13 Apr 2026 18:00:30 +0200
Source: linux
Architecture: source
Version: 7.0-1~exp1
Distribution: experimental
Urgency: medium
Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org>
Changed-By: Ben Hutchings <benh@debian.org>
Closes: 1113728 1113996 1122357 1127612 1130971 1131166 1131431 1131546 1132155 1132201 1132622 1132796 1132814
Changes:
linux (7.0-1~exp1) experimental; urgency=medium
.
* New upstream release: https://kernelnewbies.org/Linux_7.0
- [amd64] platform/x86: hp-bioscfg: Support allocations of larger data
(Closes: #1127612)
- [amd64] crypto: padlock-sha - Disable for Zhaoxin processor
(Closes: #1113996)
- iommu: Fix mapping check for 0x0 to avoid re-mapping it (Closes: #1130971)
- bpf: Fix constant blinding for PROBE_MEM32 stores (CVE-2026-23417)
(Closes: #1132622)
- [loong64] KVM: Fix undefined behaviour found by UBSAN (Closes: #1131431):
+ Make kvm_get_vcpu_by_cpuid() more robust
+ Handle the case that EIOINTC's coremap is empty
+ Fix base address calculation in kvm_eiointc_regs_access()
.
[ Bastian Blank ]
* Merge kernel-wedge. This takes over maintenance of this code from the
installer team.
* Use non-aliases paths in udebs. (closes: #1122357)
.
[ Han Gao ]
* [riscv64] Enable RTC_DRV_EFI as module
* [riscv64] Enable SENSORS_PWM_FAN as module for Sophgo SG2042
* [riscv64] Enable SENSORS_MR75203 as module for THEAD TH1520
* [riscv64] Enable POWER_SEQUENCING as module for THEAD TH1520
* [riscv64] Enable POWER_SEQUENCING_TH1520_GPU as module for THEAD TH1520
* [riscv64] Enable SND_SOC_K1_I2S as module for Spacemit K1
* [riscv64] Enable CONFIG_PWM_TH1520 for THEAD TH1520
.
[ Salvatore Bonaccorso ]
* [amd64] drivers/platform/x86/uniwill: Enable X86_PLATFORM_DRIVERS_UNIWILL
* [amd64] drivers/platform/x86/uniwill: Enable UNIWILL_LAPTOP as module
(Closes: #1131166)
* [amd64] drivers/media/i2c: Enable VIDEO_OV02E10 as module (Closes: #1132201)
* [amd64] drivers/staging/media/ipu7: Enable VIDEO_INTEL_IPU7 as module
(Closes: #1132814)
.
[ Ben Hutchings ]
* Fix ordering of kernel version strings for multiple Debian revisions
(Closes: #1113728)
* d/b/test-patches: Expect debian/control-real target to return 0
* d/b/test-patches: Disable signing so we build linux-image packages again
(Closes: #1131546)
* kernel-wedge: Fix find-dups to not look for kernel-image-di
* kernel-wedge: Remove handling of unset $SOURCEDIR
* kernel-wedge: Remove support for non-Linux kernels
* kernel-wedge: Remove support for separate config directories
* kernel-wedge: Remove support for non-modular kernel
* kernel-wedge: Remove support for exclude-packages
* kernel-wedge: Use cpio instead of tar in copy-files
* kernel-wedge: Rewrite copy-files in Perl
* kernel-wedge: Fix copy-files to skip softdeps in depmod output
* kernel-wedge: Combine gen-deps with copy-files
* kernel-wedge, udeb: Define which packages to build through package-list
* [mips*,sh4] udeb: Remove minix-modules package
* [mips*] udeb: Remove affs-modules package
* udeb: Build {jfs,loop,ppp,squashfs,uinput,xfs}-modules everywhere we can
(Closes: #1132155)
.
[ Aurelien Jarno ]
* [riscv64] Enable SPACEMIT_K3_CCU
* [riscv64] Enable PINCTRL_PIC64GX and PINCTRL_POLARFIRE_SOC
* [riscv64] Enable CV1800_MBOX, SND_SOC_CV1800B_TDM,
SND_SOC_CV1800B_ADC_CODEC and SND_SOC_CV1800B_DAC_CODEC as modules
.
[ Morgwai Kotarbinski ]
* linux-kbuild: Include scripts/gen-btf.sh (Closes: #1132796)
Checksums-Sha1:
b7c0aa04b26599087cd3b320622747e8228b7fdf 183105 linux_7.0-1~exp1.dsc
0805573ce39c5657affaaadfe45e7e79c1b68944 160332840 linux_7.0.orig.tar.xz
3ed69a3345ad92384c6614d59ecb2afacc744f02 1451976 linux_7.0-1~exp1.debian.tar.xz
02d303b4cb1e903375d5f1b4e5ddfcb92231a480 6962 linux_7.0-1~exp1_source.buildinfo
Checksums-Sha256:
d18ff76532ab4dfe10a64d6d6068c78ab750ec53b4b5860a9171945b76afc5c8 183105 linux_7.0-1~exp1.dsc
84aabcbd9039469613e74fd735a5e9680c1958a9ff63f093ebd9e580f403d06f 160332840 linux_7.0.orig.tar.xz
569e4e3e998d48247dce25aaca1dd067a83773c1b5c7961c0422154b06d6ac51 1451976 linux_7.0-1~exp1.debian.tar.xz
95dcfcd511aca951b67f9b2b8ed51f926fdc04e95eb7cc0578c8b2744aea2794 6962 linux_7.0-1~exp1_source.buildinfo
Files:
483aae11d5269bc3be731565733ae3ba 183105 kernel optional linux_7.0-1~exp1.dsc
7ffdb1d8b58227d54d348b9bb9586821 160332840 kernel optional linux_7.0.orig.tar.xz
3107a8ea51576df21d858367afb6c960 1451976 kernel optional linux_7.0-1~exp1.debian.tar.xz
77feae1584d60399a450169007fdf84b 6962 kernel optional linux_7.0-1~exp1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEErCspvTSmr92z9o8157/I7JWGEQkFAmndjiwACgkQ57/I7JWG
EQmMKw/+IvmVy8jrjGonjuXCtEZ3a+nyCf6tWmV9YmKP+THJUQlo2RX+bpwM3CA6
gPO1sQBAs3g12ZatCT2qZUnrnyri+FH5NTXiPZkStMP2l0ShftP35lmHQbKPb+CD
iQOYN98DtRleQi6mZkgkhKqrGU8nZmz0fHfxF0eMcQLu1Q6qBxhcxAWcIPWg+zwl
crnNqZk2UQSB/ALbIfoPPyOFBilEpb39oYJ4LNz4aVAbJynhinGNB3CH+hnOj9yf
Dn7ry+rwkz/eRtJoy3eFShFi2n+WOdndTrDTKmf51zRN7X0cdfsI0vWa/6tyVNWy
SOZtZUAirKDyBPsGh4z8RLAUGLj5HoShE6x1nbxCb9TgcBYOlntWSL9RgmstNKZN
GzOzgWqiuUaURMsNaHAjElaXiU2G/XlZTQkjrpf/WLfZKEn3Sy5BX+JdcsV3W0Vc
4Y2NTziQVbxxs6yv8KlmP/hMZM6eNGZBu8owm70LGQe+rlzWImCRrAPRkyjzj0SY
hDyzM0buwWJbFk5HMex2nDt6PfvyviHXk90cWqUormDBsHDpdkBWHTOMtntWym9f
vnZUtH+siHxmtdulMH3OL6Y+UL+pVofWUaaAhWTKxtGOjaC0jtRaqnL3hidcezA5
rsbPdUAbHYUcT84rwo2cYe39GZu7S8yAFTt7Doojzv9FBp7bAdc=
=blsv
-----END PGP SIGNATURE-----