#1144314 unprivileged user-triggerable use-after-free host panic bug

Package:
src:linux
Source:
src:linux
Submitter:
Noah Elias Feldt
Date:
2026-09-26 12:15:02 UTC
Severity:
normal
Tags:
#1144314#5
Date:
2026-08-13 14:38:34 UTC
From:
To:
Dear Maintainer,

An unprivileged local user can panic the entire host. Reading a cgroup's
world-readable cgroup.procs triggers a use-after-free of struct task_struct in
css_task_iter_next(), ending in "Kernel panic - not syncing: Fatal exception in
interrupt".
Nodes hard-panic and reboot organically under normal load on
the affected kernel. It also reproduces deterministically within seconds with
the attached PoC as an ordinary user (no root, no capabilities, no namespaces).

*** Reporter, please consider answering these questions, where appropriate ***

   * What led up to the situation?
     An unprivileged process reads its own world-readable cgroup.procs while,
     on the same CPU, thread-group leaders in that cgroup exit and are
     mass-reaped (attached poc.c). Not only synthetic: several of our production
     nodes have already panicked this way organically under normal container
     workload (Kubernetes / cri-o) on the affected kernel.

   * What exactly did you do?
     Ran the reproducer as an ordinary user on an Debian 13 KVM guest
     (trixie-backports kernel)

   * What was the outcome?
     In ~12-70 s: "refcount_t: addition on 0" in css_task_iter_next()
     (get_task_struct on usage==0) -> premature free -> NULL rcu_head.func in
     rcu_do_batch (RIP:0x0) -> "Kernel panic - not syncing". Host dead -- same
     signature as the organic production panics. Full trace attached (dmesg.log).

   * What outcome did you expect instead?
     Reading cgroup.procs must never crash the host.

#1144314#18
Date:
2026-08-14 19:36:27 UTC
From:
To:
Hi Noah,

I can reproduce the issue up to the current kernel version
7.2~rc7-1~exp1 in experimental. Are you able to narrow down more the
range and would you be able to bisect the issue?

I will see if I can otherwise poin point it as well and if there are
already upstream issues reported about this.

Regards,
Salvatore

#1144314#23
Date:
2026-08-15 12:59:39 UTC
From:
To:
We also fully reproduced it on our production system with a second, more targeted reproducer: inside an unprivileged container on a stock 7.0.13 node, the bare-metal host panicked within seconds. I didn't attach it since I think, it shouldn't be public yet. I can send it to you privately.

Sincerely,
Noah Feldt

#1144314#28
Date:
2026-08-15 17:43:32 UTC
From:
To:
Hi,

Thanks for sharing that, I initially wrongly guessed to be a
regression from 7.0 to 7.1-rc1 but it looks it is just bit harder to
trigger on older versions.

I think we can next forward this to upstream.

Regards,
Salvatore

#1144314#33
Date:
2026-08-15 19:15:55 UTC
From:
To:
Hi,
dying_tasks cleanup from cgroup_task_release() to
cgroup_task_free()"). But it is nearby to the commit you are spotting.

I will forward the issue upstream.

Regards,
Salvatore

#1144314#42
Date:
2026-08-15 19:41:14 UTC
From:
To:
Hi Tejun, Johannes and Michael,

In Debian Noah Elias Feldt reported a UAF which is hit in production
and provided a reproducer for the issue (attached as well), the
bugreport can be found at https://bugs.debian.org/1144314 . First
quoting the orignal post:

With an additional reproducer provided by Noah, I could bisect the
change down to

	commit 260fbcb92bbeacfcd050410fdc2d24ab15044400
	Author: Tejun Heo <tj@kernel.org>
	Date:   Tue Oct 28 20:19:16 2025 -1000

	    cgroup: Move dying_tasks cleanup from cgroup_task_release() to cgroup_task_free()

	    Currently, cgroup_task_exit() adds thread group leaders with live member
	    threads to their css_set's dying_tasks list (so cgroup.procs iteration can
	    still see the leader), and cgroup_task_release() later removes them with
	    list_del_init(&task->cg_list).

	    An upcoming patch will defer the dying_tasks list addition, moving it from
	    cgroup_task_exit() (called from do_exit()) to a new function called from
	    finish_task_switch(). However, release_task() (which calls
	    cgroup_task_release()) can run either before or after finish_task_switch(),
	    creating a race where cgroup_task_release() might try to remove the task from
	    dying_tasks before or while it's being added.

	    Move the list_del_init() from cgroup_task_release() to cgroup_task_free() to
	    fix this race. cgroup_task_free() runs from __put_task_struct(), which is
	    always after both paths, making the cleanup safe.

	    Cc: Dan Schatzberg <dschatzberg@meta.com>
	    Cc: Peter Zijlstra <peterz@infradead.org>
	    Signed-off-by: Tejun Heo <tj@kernel.org>

But there was the suspect that the matching commit might be
d245698d727a ("cgroup: Defer task cgroup unlink until after the task
is done switching out").

Using the provided reproducer in the Debian bug this leads to:

[ 2686.174523] ------------[ cut here ]------------
[ 2686.175443] refcount_t: addition on 0; use-after-free.
[ 2686.176414] WARNING: lib/refcount.c:25 at refcount_warn_saturate+0x6a/0x90, CPU#0: 1144314-poc/1170
[ 2686.178044] Modules linked in: binfmt_misc intel_rapl_msr intel_rapl_common kvm_amd ccp iTCO_wdt intel_pmc_bxt watchdog kvm i2c_i801 vga16fb i2c_smbus vgastate irqbypass lpc_ich pcspkr virtio_net button virtio_balloon net_failover failover joydev evdev nfsd auth_rpcgss nfs_acl lockd grace sunrpc drm efi_pstore configfs vsock_loopback vmw_vsock_virtio_transport vmw_vsock_virtio_transport_common vsock ext4 crc16 mbcache jbd2 crc32c_cryptoapi ahci xhci_pci libahci xhci_hcd libata usbcore scsi_mod psmouse virtio_blk scsi_common usb_common serio_raw dm_mirror dm_region_hash dm_log dm_mod qemu_fw_cfg virtio_rng autofs4 aesni_intel gf128mul
[ 2686.187398] CPU: 0 UID: 1000 PID: 1170 Comm: 1144314-poc Not tainted 7.2-amd64 #1 PREEMPT(lazy)  Debian 7.2~rc7-1~exp1
[ 2686.189214] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 2686.190800] RIP: 0010:refcount_warn_saturate+0x6a/0x90
[ 2686.191731] Code: 00 48 8d 3d 88 8f 8d 01 67 48 0f b9 3a e9 2e 37 73 00 48 8d 3d 87 8f 8d 01 67 48 0f b9 3a e9 1d 37 73 00 48 8d 3d 86 8f 8d 01 <67> 48 0f b9 3a e9 0c 37 73 00 48 8d 3d 85 8f 8d 01 67 48 0f b9 3a
[ 2686.194789] RSP: 0018:ffffcb9443cafa40 EFLAGS: 00010046
[ 2686.195752] RAX: ffff8b12532c8fa8 RBX: ffff8b1265ae6018 RCX: 0000000000000025
[ 2686.197023] RDX: 0000000000000000 RSI: 0000000000000002 RDI: ffffffffb15746b0
[ 2686.198268] RBP: 0000000000000206 R08: 0000000000000007 R09: 0000000000000004
[ 2686.199530] R10: ffff8b12673b3c40 R11: 0000000000000fdd R12: ffffcb9443cafb08
[ 2686.200782] R13: ffff8b1253899b40 R14: ffff8b124fbf0000 R15: 0000000000000000
[ 2686.202029] FS:  00007f0fff4266c0(0000) GS:ffff8b1309d55000(0000) knlGS:0000000000000000
[ 2686.203462] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 2686.204506] CR2: 00005639b734d010 CR3: 0000000115a8d000 CR4: 0000000000350ef0
[ 2686.205780] Call Trace:
[ 2686.206308]  <TASK>
[ 2686.206781]  css_task_iter_next+0xcc/0xf0
[ 2686.207552]  kernfs_seq_next+0x2a/0xa0
[ 2686.208291]  ? cgroup_procs_show+0x2a/0x40
[ 2686.209075]  seq_read_iter+0x2f5/0x490
[ 2686.209798]  vfs_read+0x268/0x390
[ 2686.210454]  ksys_read+0x73/0xf0
[ 2686.211114]  do_syscall_64+0xe1/0x640
[ 2686.211828]  ? do_syscall_64+0x11e/0x640
[ 2686.212580]  ? kernfs_seq_start+0x53/0xb0
[ 2686.213340]  ? __pfx_cgroup_seqfile_stop+0x10/0x10
[ 2686.214233]  ? __mod_memcg_state+0xd7/0x1d0
[ 2686.215035]  ? seq_read_iter+0x214/0x490
[ 2686.215782]  ? __memcg_slab_free_hook+0x16c/0x1c0
[ 2686.216664]  ? __memcg_slab_free_hook+0x16c/0x1c0
[ 2686.217594]  ? kmem_cache_free+0x25f/0x440
[ 2686.218490]  ? __x64_sys_close+0x3d/0x80
[ 2686.219281]  ? do_syscall_64+0x11e/0x640
[ 2686.220044]  ? __mod_memcg_state+0xd7/0x1d0
[ 2686.220839]  ? __memcg_slab_free_hook+0x16c/0x1c0
[ 2686.221719]  ? __memcg_slab_free_hook+0x16c/0x1c0
[ 2686.222616]  ? kmem_cache_free+0x25f/0x440
[ 2686.223403]  ? __x64_sys_close+0x3d/0x80
[ 2686.224167]  ? do_syscall_64+0x11e/0x640
[ 2686.224927]  ? do_syscall_64+0x11e/0x640
[ 2686.225686]  ? do_syscall_64+0x11e/0x640
[ 2686.226446]  ? do_syscall_64+0x98/0x640
[ 2686.227193]  entry_SYSCALL_64_after_hwframe+0x76/0x7e
[ 2686.228121] RIP: 0033:0x7f1010cea19e
[ 2686.228828] Code: 08 0f 85 35 4a ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 90 48 83 ec 08 bf 01 00 00 00 e8 82 dc 05 00 bf 01 00 00 00 89
[ 2686.231921] RSP: 002b:00007f0fff415e08 EFLAGS: 00000246 ORIG_RAX: 0000000000000000
[ 2686.233234] RAX: ffffffffffffffda RBX: 00007f0fff4266c0 RCX: 00007f1010cea19e
[ 2686.234465] RDX: 0000000000010000 RSI: 00007f0fff415e90 RDI: 0000000000000029
[ 2686.235710] RBP: 00007f0fff425ea0 R08: 0000000000000000 R09: 0000000000000000
[ 2686.236959] R10: 0000000000000000 R11: 0000000000000246 R12: 00007ffc3405bde0
[ 2686.238197] R13: 00007ffc3405bed6 R14: 00007f0fff426ce4 R15: 00007f0ffec26000
[ 2686.239444]  </TASK>
[ 2686.239922] ---[ end trace 0000000000000000 ]---
[ 2686.244408] ------------[ cut here ]------------
[ 2686.245246] WARNING: kernel/fork.c:790 at __put_task_struct+0x150/0x1c0, CPU#0: 1144314-poc/1164
[ 2686.246763] Modules linked in: binfmt_misc intel_rapl_msr intel_rapl_common kvm_amd ccp iTCO_wdt intel_pmc_bxt watchdog kvm i2c_i801 vga16fb i2c_smbus vgastate irqbypass lpc_ich pcspkr virtio_net button virtio_balloon net_failover failover joydev evdev nfsd auth_rpcgss nfs_acl lockd grace sunrpc drm efi_pstore configfs vsock_loopback vmw_vsock_virtio_transport vmw_vsock_virtio_transport_common vsock ext4 crc16 mbcache jbd2 crc32c_cryptoapi ahci xhci_pci libahci xhci_hcd libata usbcore scsi_mod psmouse virtio_blk scsi_common usb_common serio_raw dm_mirror dm_region_hash dm_log dm_mod qemu_fw_cfg virtio_rng autofs4 aesni_intel gf128mul
[ 2686.255681] CPU: 0 UID: 1000 PID: 1164 Comm: 1144314-poc Tainted: G        W           7.2-amd64 #1 PREEMPT(lazy)  Debian 7.2~rc7-1~exp1
[ 2686.257660] Tainted: [W]=WARN
[ 2686.258228] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 2686.259718] RIP: 0010:__put_task_struct+0x150/0x1c0
[ 2686.260570] Code: fe ff ff 48 89 cf be 03 00 00 00 e8 7a 73 72 00 48 89 df 48 83 c4 08 5b e9 2d fe ff ff 0f 0b 8b 43 28 85 c0 0f 84 da fe ff ff <0f> 0b 65 48 3b 1d ae ec 94 02 0f 85 d8 fe ff ff 0f 0b e9 d1 fe ff
[ 2686.263431] RSP: 0018:ffffcb9440003ed0 EFLAGS: 00010286
[ 2686.264319] RAX: 00000000c0000000 RBX: ffff8b12532c8000 RCX: ffff8b124022fac0
[ 2686.265494] RDX: ffffffffaf5743e0 RSI: 0000000000000001 RDI: ffff8b12532c8000
[ 2686.266667] RBP: ffff8b12bbc33500 R08: ffff8b125368b700 R09: ffffffffaf66e8e3
[ 2686.267832] R10: fffff61cc44da200 R11: ffff8b124022a700 R12: ffffcb9440003f10
[ 2686.269010] R13: ffff8b12468cb700 R14: 0000000000000003 R15: 0000000000000000
[ 2686.270176] FS:  00007f100242c6c0(0000) GS:ffff8b1309d55000(0000) knlGS:0000000000000000
[ 2686.271594] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 2686.272640] CR2: 00007f9e074e6b20 CR3: 0000000115a8d000 CR4: 0000000000350ef0
[ 2686.273817] Call Trace:
[ 2686.274307]  <IRQ>
[ 2686.274744]  rcu_do_batch+0x1b3/0x4f0
[ 2686.275413]  rcu_core+0x131/0x2b0
[ 2686.276030]  handle_softirqs+0xd8/0x310
[ 2686.276734]  ? clockevents_program_event+0xf5/0x1e0
[ 2686.277577]  __irq_exit_rcu+0x9e/0xf0
[ 2686.278243]  sysvec_apic_timer_interrupt+0x71/0x90
[ 2686.279087]  </IRQ>
[ 2686.279527]  <TASK>
[ 2686.279968]  asm_sysvec_apic_timer_interrupt+0x1a/0x20
[ 2686.280856] RIP: 0010:_raw_spin_unlock_irqrestore+0x1d/0x40
[ 2686.281795] Code: 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 0f 1f 44 00 00 e8 f2 07 00 00 90 f7 c6 00 02 00 00 74 06 fb 0f 1f 44 00 00 <65> ff 0d 5c 66 af 01 74 05 e9 65 24 00 00 e8 10 2d 0e ff e9 5b 24
[ 2686.284661] RSP: 0018:ffffcb9443c7fcf0 EFLAGS: 00000206
[ 2686.285549] RAX: 0000000000000001 RBX: ffff8b1265ae0558 RCX: ffff8b1261d4ac00
[ 2686.286727] RDX: ffff8b12485b5330 RSI: 0000000000000206 RDI: ffffffffb1f81d88
[ 2686.287891] RBP: 0000000000000206 R08: 0000000000000003 R09: 0000000000000004
[ 2686.289065] R10: ffff8b12673b3f50 R11: 0000000000000ff1 R12: ffffcb9443c7fdb8
[ 2686.290230] R13: ffff8b12665eb180 R14: ffff8b1240338000 R15: 0000000000000000
[ 2686.291402]  css_task_iter_next+0x95/0xf0
[ 2686.292117]  kernfs_seq_next+0x2a/0xa0
[ 2686.292806]  ? cgroup_procs_show+0x2a/0x40
[ 2686.293534]  seq_read_iter+0x2f5/0x490
[ 2686.294217]  vfs_read+0x268/0x390
[ 2686.294842]  ksys_read+0x73/0xf0
[ 2686.295447]  do_syscall_64+0xe1/0x640
[ 2686.296114]  ? kmem_cache_free+0x25f/0x440
[ 2686.296851]  ? __x64_sys_close+0x3d/0x80
[ 2686.297554]  ? do_syscall_64+0x11e/0x640
[ 2686.298257]  ? do_syscall_64+0x11e/0x640
[ 2686.298967]  ? do_syscall_64+0x11e/0x640
[ 2686.299777]  ? do_syscall_64+0x98/0x640
[ 2686.300606]  entry_SYSCALL_64_after_hwframe+0x76/0x7e
[ 2686.301529] RIP: 0033:0x7f1010cea19e
[ 2686.302231] Code: 08 0f 85 35 4a ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 90 48 83 ec 08 bf 01 00 00 00 e8 82 dc 05 00 bf 01 00 00 00 89
[ 2686.305341] RSP: 002b:00007f100241be08 EFLAGS: 00000246 ORIG_RAX: 0000000000000000
[ 2686.306708] RAX: ffffffffffffffda RBX: 00007f100242c6c0 RCX: 00007f1010cea19e
[ 2686.308108] RDX: 0000000000010000 RSI: 00007f100241be90 RDI: 000000000000002a
[ 2686.309527] RBP: 00007f100242bea0 R08: 0000000000000000 R09: 0000000000000000
[ 2686.310935] R10: 0000000000000000 R11: 0000000000000246 R12: 00007ffc3405bde0
[ 2686.312388] R13: 00007ffc3405bed6 R14: 00007f100242cce4 R15: 00007f1001c2c000
[ 2686.313805]  </TASK>
[ 2686.314326] ---[ end trace 0000000000000000 ]---
[ 2691.097916]  slab task_struct start ffff8b12532c8000 pointer offset 2600 size 7040
[ 2691.099234] list_del corruption. next->prev should be ffff8b124f3e0a28, but was ffff8b12514d8a28. (next=ffff8b12532c8a28)
[ 2691.101069] ------------[ cut here ]------------
[ 2691.101915] kernel BUG at lib/list_debug.c:65!
[ 2691.102745] Oops: invalid opcode: 0000 [#1] SMP NOPTI
[ 2691.103662] CPU: 0 UID: 1000 PID: 9204 Comm: 1144314-poc Tainted: G        W           7.2-amd64 #1 PREEMPT(lazy)  Debian 7.2~rc7-1~exp1
[ 2691.105695] Tainted: [W]=WARN
[ 2691.106288] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 2691.107892] RIP: 0010:__list_del_entry_valid_or_report+0x10a/0x120
[ 2691.108989] Code: 89 d7 48 89 14 24 e8 25 3c be ff 48 8b 14 24 48 8b 74 24 08 48 c7 c7 18 12 a7 b0 48 8b 42 08 48 89 d1 48 89 c2 e8 b6 d1 74 ff <0f> 0b 66 2e 0f 1f 84 00 00 00 00 00 66 2e 0f 1f 84 00 00 00 00 00
[ 2691.112049] RSP: 0018:ffffcb944927fb68 EFLAGS: 00010046
[ 2691.112991] RAX: 000000000000006d RBX: 0000000000000011 RCX: 0000000000000027
[ 2691.114228] RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff8b12bbc1d100
[ 2691.115474] RBP: ffff8b124f306300 R08: 0000000000000000 R09: ffffcb944927fa10
[ 2691.116712] R10: ffffffffb12f24b0 R11: 3fffffffffffefff R12: ffff8b1241f5d540
[ 2691.117950] R13: ffff8b124f3e4250 R14: ffff8b12508f8d80 R15: ffff8b124f3e0000
[ 2691.119196] FS:  0000000000000000(0000) GS:ffff8b1309d55000(0000) knlGS:0000000000000000
[ 2691.120587] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 2691.121611] CR2: 00007f1010e48000 CR3: 0000000161e2a000 CR4: 0000000000350ef0
[ 2691.122857] Call Trace:
[ 2691.123372]  <TASK>
[ 2691.123834]  release_task+0x436/0x560
[ 2691.124539]  do_exit+0x6a2/0xaa0
[ 2691.125178]  do_group_exit+0x2d/0xc0
[ 2691.125868]  __x64_sys_exit_group+0x18/0x20
[ 2691.126662]  x64_sys_call+0x102c/0x1530
[ 2691.127393]  do_syscall_64+0xe1/0x640
[ 2691.128098]  ? file_update_time_flags+0x81/0x110
[ 2691.128951]  ? fault_dirty_shared_page+0xa2/0x160
[ 2691.129816]  ? do_fault+0x146/0x580
[ 2691.130493]  ? __pte_offset_map+0x1b/0x100
[ 2691.131273]  ? __handle_mm_fault+0x960/0xf60
[ 2691.132074]  ? count_memcg_events+0xd9/0x210
[ 2691.132875]  ? handle_mm_fault+0x1e5/0x2f0
[ 2691.133643]  ? do_user_addr_fault+0x2b4/0x7b0
[ 2691.134456]  ? irqentry_exit+0x43/0x730
[ 2691.135194]  ? do_syscall_64+0x98/0x640
[ 2691.135927]  entry_SYSCALL_64_after_hwframe+0x76/0x7e
[ 2691.136843] RIP: 0033:0x7f1010d2c438
[ 2691.137540] Code: Unable to access opcode bytes at 0x7f1010d2c40e.
[ 2691.138633] RSP: 002b:00007ffc3405bf98 EFLAGS: 00000202 ORIG_RAX: 00000000000000e7
[ 2691.139859] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f1010d2c438
[ 2691.141027] RDX: 0000000000000002 RSI: ffffffffffffffb0 RDI: 0000000000000000
[ 2691.142186] RBP: 00007ffc3405bfb0 R08: 0000000000000000 R09: 0000000000000000
[ 2691.143352] R10: 0000000000000000 R11: 0000000000000202 R12: 00000000000003e8
[ 2691.144512] R13: 0000000000000002 R14: 0000000000000030 R15: 00005639b734cdd8
[ 2691.145673]  </TASK>
[ 2691.146124] Modules linked in: binfmt_misc intel_rapl_msr intel_rapl_common kvm_amd ccp iTCO_wdt intel_pmc_bxt watchdog kvm i2c_i801 vga16fb i2c_smbus vgastate irqbypass lpc_ich pcspkr virtio_net button virtio_balloon net_failover failover joydev evdev nfsd auth_rpcgss nfs_acl lockd grace sunrpc drm efi_pstore configfs vsock_loopback vmw_vsock_virtio_transport vmw_vsock_virtio_transport_common vsock ext4 crc16 mbcache jbd2 crc32c_cryptoapi ahci xhci_pci libahci xhci_hcd libata usbcore scsi_mod psmouse virtio_blk scsi_common usb_common serio_raw dm_mirror dm_region_hash dm_log dm_mod qemu_fw_cfg virtio_rng autofs4 aesni_intel gf128mul
[ 2691.154482] ---[ end trace 0000000000000000 ]---
[ 2691.155292] RIP: 0010:__list_del_entry_valid_or_report+0x10a/0x120
[ 2691.156315] Code: 89 d7 48 89 14 24 e8 25 3c be ff 48 8b 14 24 48 8b 74 24 08 48 c7 c7 18 12 a7 b0 48 8b 42 08 48 89 d1 48 89 c2 e8 b6 d1 74 ff <0f> 0b 66 2e 0f 1f 84 00 00 00 00 00 66 2e 0f 1f 84 00 00 00 00 00
[ 2691.159161] RSP: 0018:ffffcb944927fb68 EFLAGS: 00010046
[ 2691.160045] RAX: 000000000000006d RBX: 0000000000000011 RCX: 0000000000000027
[ 2691.161204] RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff8b12bbc1d100
[ 2691.162364] RBP: ffff8b124f306300 R08: 0000000000000000 R09: ffffcb944927fa10
[ 2691.163532] R10: ffffffffb12f24b0 R11: 3fffffffffffefff R12: ffff8b1241f5d540
[ 2691.164691] R13: ffff8b124f3e4250 R14: ffff8b12508f8d80 R15: ffff8b124f3e0000
[ 2691.165852] FS:  0000000000000000(0000) GS:ffff8b1309d55000(0000) knlGS:0000000000000000
[ 2691.167168] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 2691.168129] CR2: 00007f1010e48000 CR3: 0000000161e2a000 CR4: 0000000000350ef0
[ 2691.169290] note: 1144314-poc[9204] exited with irqs disabled
[ 2691.170276] note: 1144314-poc[9204] exited with preempt_count 3
[ 2691.171334] Fixing recursive fault but reboot is needed!

#regzbot introduced: 260fbcb92bbeacfcd050410fdc2d24ab15044400
#regzbot link: https://bugs.debian.org/1144314

Noah Elias Feldt is added here as well to provide more information as
needed.

Regards,
Salvatore

#1144314#49
Date:
2026-08-16 03:33:41 UTC
From:
To:
Salvatore Bonaccorso wrote:

As an extra data point, I couldn't reproduce the problem with 6.12.100+deb13-amd64 on Trixie.

#1144314#56
Date:
2026-08-21 16:59:26 UTC
From:
To:
Hi Salvatore,

thanks for the nice report and sorry for not so prompt response.

Good job.
cgroup_task_release() to cgroup_task_free()") it may be possible that
tasks on the dying_tasks list may drop their ->usage to zero (since the
actual unlinking only happens in __put_task_struct).
Most often those would be skipped due to PF_EXITING except for the case
of thread group leaders (which the reproducer stresses) whose refcount
apparently can drop to zero after task->signal->live > 0 made them
iterable :-/

A band-aid fix could be to use tryget_task_struct() in
css_task_iter_next() (I got that hint from a LLM) and "skip" zeroed
tasks. I see that commit fbe3fb103596b ("sched_ext: Replace
tryget_task_struct() with get_task_struct()"), assumes the iterator
always succeeds in obtaining the task reference (which was the
justification of tryget removal). I expect that sched_ext should still
be fine if dying_tasks with zero references are skipped. (What are they?
Tasks which literally no one should be interested in and they're only
waiting for __put_task_struct_rcu_cb() to be called [*]).

(I'm calling that band-aid because it'd resurrect usage of
tryget_task_struct() and it keeps the dying_tasks list a weird place to
be. If anyone has a better idea?)

The commit d245698d727a ("cgroup: Defer task cgroup unlink until after
the task is done switching out") seems a reasonable separation of the
stages to me.

Regards,
Michal


[*] Except for io_uring_drop_tctx_refs() that calls __put_task_struct()
directly (no RCU) but I'd argue the same, that those should not be
possibly iterated.

#1144314#61
Date:
2026-09-02 11:01:51 UTC
From:
To:
Hi Michal,

Thanks a lot for looking into this problem. Is there something Noah or
I could test?

Regards,
Salvatore

#1144314#70
Date:
2026-09-20 12:25:07 UTC
From:
To:
Hello,

Following this bug and the "cgroup: Avoid iteration of dying tasks with
zero refcount" thread on cgroups@vger.kernel.org
(https://lore.kernel.org/r/20260902161653.1051794-1-mkoutny@suse.com), I
have a desktop-side capture that looks related but may be a distinct bug
in the add/unlink path rather than the dying_tasks iterator.

Hardware: Lenovo ThinkPad P16v Gen 1, AMD Ryzen 7 PRO 7840HS (16 threads),
32 GB RAM, BIOS N3VET65W.
Kernel: 7.0.14-2-liquorix-amd64 (Debian 13 trixie base, systemd 257).
I checked vanilla 7.0.14 source: kernel/cgroup/cgroup.c:2626 is exactly
WARN_ON_ONCE(list_empty(&task->cg_list)) inside cgroup_migrate_add_task(),
matching Warning 1 below line-for-line, and :948 is the sibling
WARN_ON_ONCE(!list_empty(&task->cg_list)) in css_set_move_task, matching
Warning 1b. So this reproduces on stock kernel logic, not a Liquorix
scheduler patch.

Trigger: a VPN client (Windscribe 2.24.13) using per-app split tunneling
on a cgroup2-unified system. Its userspace helper mounts a cgroup v1
net_cls controller on top of v2 and migrates matched processes into it via
cgroup1_procs_write -> cgroup_attach_task. One matched binary is
/usr/bin/node, which forks many short-lived children, each migrated into
net_cls and then exiting — high churn through cgroup_migrate_add_task()
and cgroup_task_dead() concurrently. A watcher script reconnects the VPN
periodically, tearing down and recreating the cgroup mid-churn.

IMPORTANT CAVEAT: this is N=1. I have one boot with these warnings out of
many boots running the same workload, and cannot reproduce it on demand
yet. I'm reporting it because the forensics are unusually complete, not
because I'm claiming a reliable repro. I'm willing to test candidate
patches on this hardware.

Warning 1 (23:33:27, CPU 0), writer = Windscribe's helper process:
  WARNING: kernel/cgroup/cgroup.c:2626 at
cgroup_migrate_add_task.part.0+0x1d4/0x1e0
  Call Trace: cgroup_attach_task -> cgroup1_procs_write ->
kernfs_fop_write_iter
    -> vfs_write -> __x64_sys_write -> do_syscall_64

Warning 1b, same second, unrelated `node` process, on fork:
  WARNING: kernel/cgroup/cgroup.c:6991 at cgroup_post_fork+0x344/0x3e0
  WARNING: kernel/cgroup/cgroup.c:948  at cgroup_post_fork+0x34b/0x3e0
Because this fires on fork, the corrupted state appears to predate the
task actually being migrated — I suspect this is broader than a single
migration race.

Warning 2, 9 occurrences across two timestamps (23:33:54, 23:34:03), CPUs
0, 2, 6, 10, 14, all in __list_del_entry_valid_or_report reached from
cgroup_task_dead.cold -> finish_task_switch -> __schedule -> schedule_idle
-> cpu_startup_entry, context swapper/N (idle task). 7 of 9 stacks continue
through start_secondary -> common_startup_64 (secondary CPUs); 1 of 9
through rest_init -> start_kernel (boot CPU). Total window: 36 seconds
(23:33:27 to 23:34:03).

Each occurrence carries a slab diagnostic:
  slab task_struct start ffff8bb741695200 pointer offset 1696 size 5208
identifying the corrupted list as task_struct->cg_list. Across the 9
messages there are 10 distinct addresses; 8 are exactly (task_struct
base) + 1696 for 8 different task_struct instances, confirming this is
cg_list corruption spanning multiple tasks, not one bad pointer.

8 of 9 stale values equal the neighbouring node itself (prev->next "was"
== prev, or next->prev "was" == next) — the exact pattern list_del_init()
leaves behind (entry->next = entry->prev = entry). That means the
neighbouring node had already been unlinked and re-initialised at the
moment cgroup_task_dead() walked past it: the list was being mutated
concurrently, not merely stale. Within each check type the chain also
holds — each message's stale value is the next message's expected value
(4/4 for prev->next, 3/3 for next->prev) — consistent with one progressive
unlink walking an already-corrupted list.

The machine did not panic on these warnings; taint stayed [W]=WARN and the
boot continued for roughly 1m45s afterward before ending abruptly with no
clean shutdown — I don't have proof that final stop was caused by this
corruption and don't want to overstate the connection.

Environment note: /proc/mounts on this host shows only cgroup2 — no v1
net_cls mount is visible after the fact. Windscribe's own installer
script (cgroups-up) force-mounts a v1 net_cls hierarchy on v2-only systems
for the duration of a connection and unmounts it on disconnect, which
explains the discrepancy.

Why I think this may be distinct from the dying_tasks iterator race: the
warnings I see are in the migrate/exit add-and-unlink paths
(cgroup_migrate_add_task, css_set_move_task, cgroup_task_dead), not in
css_task_iter_next() reading cgroup.procs. The v3 fix
(https://lore.kernel.org/r/20260907170345.45316-1-mkoutny@suse.com and
follow-ups) changes only the iterator's handling of zero-refcount tasks on
dying_tasks. I don't see how it would touch the path I'm hitting, but I'd
appreciate correction if I'm wrong.

Full kernel journal for the affected boot (journalctl -k -b, boot ID
dba7f630b204448982167689c56dca52) is attached as
cgroup-corruption-journal.txt.

Thanks,
Eser

#1144314#75
Date:
2026-09-23 13:30:35 UTC
From:
To:
Hello,

I didn't try to verify if you're hitting the same issue thta is
discussed in this thread. If you're sure it is, please use an uptodate
kernel to provide your new insights. I don't know what liquorix is, but
even if the 7.0.14-2-liquorix-amd64 kernel is based on Debian's 7.0.14
kernel, we didn't have a 7.0.14-2 and we switched to 7.1.x already in
July.

I'm stopping processing of your mail here, as I'm sure it's not a
productive thing to do with my time.

Thanks
Uwe

#1144314#80
Date:
2026-09-26 12:13:53 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
linux, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144314@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated linux package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 26 Sep 2026 10:54:26 +0200
Source: linux
Architecture: source
Version: 7.2.8-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 1144314
Changes:
 linux (7.2.8-1) unstable; urgency=medium
 .
   * New upstream stable update:
https://www.kernel.org/pub/linux/kernel/v7.x/ChangeLog-7.2.8
     - sunvdc: fix -EIO issue due to lack of retries
     - xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk()
     - xfrm: add missing RCU read lock in xfrm_send_migrate_state()
     - xfrm: iptfs: fix runt reassembly panic from short inner tot_len
     - xfrm: fix compat ALLOCSPI request use-after-free
     - xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for
       xfrm_trans_reinject()
     - esp: downgrade zerocopy managed frags before mutating skb frags
     - [arm64] dts: amlogic: t7: use the real UART pclk
     - [arm64] dts: amlogic: t7: khadas-vim4: allow the SD card to be power
       cycled
     - [arm64] dts: amlogic: t7: fix the pin groups of two PWM outputs
     - [arm64] dts: amlogic: t7: khadas-vim4: add the PWM-driven supplies
     - [arm64] dts: amlogic: t7: fix the pin groups of the vsync PWM
     - RDMA/siw: Clear association under lock if siw_qp_modify fails in
       siw_accept
     - RDMA/rxe: validate access flags before swapping the MR's PD
     - RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
     - xfrm: hold net_device reference under RCU in bundle creation
     - [arm64] firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS
     - clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate
     - clk: scpi: register scpi-cpufreq once and clear on failure
     - RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths
     - RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds
     - RDMA/mlx5: Remove warn on missing representor in query_port_speed
     - RDMA/core: Reject unregistering netdevs in ib_get_eth_speed
     - RDMA/uverbs: Fix mmap_lock/disassociation_lock circular dependency
     - power: sequencing: Fix build issue with COMPILE_TEST
     - [arm64] dts: renesas: r9a09g057: Switch GBETH TX queue scheduling to WRR
     - [arm64] dts: renesas: r9a09g056: Switch GBETH TX queue scheduling to WRR
     - [arm64] dts: renesas: r9a09g047: Switch GBETH TX queue scheduling to WRR
     - [arm64] dts: renesas: r9a09g077: Switch GBETH TX queue scheduling to WRR
     - [arm64] dts: renesas: r9a09g087: Switch GBETH TX queue scheduling to WRR
     - IB/iser: reject a remote invalidation of an unregistered direction
     - IB/isert: wait for deferred control PDU completions before releasing the
       connection
     - RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup
     - RDMA/rtrs: guard against null kobj name
     - RDMA/bnxt_re: Avoid exposing umdbr to userspace
     - RDMA/uverbs: Fix potential leak of resources->collection in
       flow_resources_alloc()
     - RDMA/mad: Fix receive buffer leak when PKey enforcement fails
     - RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables
     - RDMA/irdma: Enforce local fence for IB_WR_REG_MR
     - RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted
     - dmaengine: mmp_pdma: fix wrong extended DRCMR base for SpacemiT K3
     - dmaengine: sprd: Fix runtime PM reference leak in probe
     - wifi: mac80211: include TIM bitmap control for buffered S1G mcast traffic
     - wifi: virt_wifi: free skb when disconnected
     - wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path
     - wifi: brcmfmac: cyw: pass PMKID to firmware if present
     - wifi: libipw: reject too-short beacon and probe responses
     - wifi: libipw: reject too-short association responses
     - IB/IPoIB: Avoid restoring OPER_UP after multicast flush
     - wifi: cfg80211: don't get the radio mask for netdev-less wdevs
     - wifi: cfg80211: check IP header size in cfg80211_classify8021d()
     - soundwire: cadence_master: wait and cancel cdns->work before clock stop
     - dma-coherent: report a failed reserved memory assignment
     - dma-mapping: don't trace the DMA address when the allocation fails
     - dmaengine: Fix device kref underflow in dma_chan_put()
     - dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
     - dmaengine: wait for RCU readers before releasing dma_device
     - wifi: cfg80211: don't free driver-owned scan requests
     - wifi: cfg80211: only group hidden BSSes with beacon entries
     - wifi: cfg80211: don't filter by BSS type when removing stale entries
     - wifi: cfg80211: ibss: ref BSS entry for joined event
     - wifi: cfg80211: fix NAN regulatory enforcement
     - wifi: mac80211: don't start a ROC while scanning
     - wifi: mac80211: don't warn when an IBSS has no channel to scan
     - wifi: mac80211: don't offload TC setup on AP_VLAN interfaces
     - wifi: mac80211: suppress chanctx warning for debugfs reset
     - wifi: mac80211: abort chanswitch when leaving a mesh
     - wifi: mac80211: reset state when starting AP fails
     - wifi: mac80211: reset the LED state when ifup fails
     - wifi: mac80211: only operate on TDLS peers in the TDLS code
     - wifi: cfg80211: restore netns_immutable on failures
     - wifi: cfg80211: undo netns switch if renaming the wiphy fails
     - wifi: mac80211: unlist vifs when their netdev is unregistered
     - wifi: cfg80211: get the wiphy out of a dying network namespace
     - wifi: mac80211_hwsim: don't hand frames to mac80211 while stopping
     - wifi: mac80211: don't allow injecting frames wider than the chanctx
     - wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown
     - wifi: mac80211: require a peer station for TDLS setup confirm
     - wifi: mac80211: don't allow link changes when iface is down
     - wifi: mac80211: don't RCU-dereference the mesh CSA settings we just set
     - wifi: mac80211: don't access the TSF of a down interface
     - wifi: mac80211: add HE 6 GHz capability in the scan elems len
     - wifi: mac80211: mesh: reset the CSA state when leaving
     - wifi: mac80211: mesh: release the channel if start fails
     - wifi: mac80211: set up the TX info early to fix failure paths
     - mm: memblock: show all region flags in debugfs
     - scsi: pm80xx: Fix the use_msix, use_tasklet and read_wwn parameter
       descriptions
     - scsi: qla2xxx: Fix the ql2xfc2target parameter description
     - dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order
     - dmaengine: pxa: fix double counting of the hw descriptors
     - dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic
       DMA
     - RDMA/efa: Keep admin queues alive while IRQ is registered
     - RDMA/efa: Keep EQ resources alive while IRQ is registered
     - RDMA/siw: Bound fragmented header copies by the remaining length
     - [amd64] x86/div64: Fix addition of large constants in
       mul_u64_add_u64_div_u64()
     - drm/msm: Fix the separate_gpu_kms parameter description
     - drm/msm/adreno: Fix the skip_gpu parameter description
     - netfilter: nft_nat: fully initialise new_addr in netmap setup
     - netfilter: nf_tables: fix device name and prefix match in hook lookup
     - netfilter: nf_nat: unregister and release hooks on error
     - netfilter: flowtable: hold reference on ct until flow is released
     - perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations
     - [arm64] hibernate: clone only the linear map that exists at runtime
     - [arm64] mte: Fix PTRACE_{PEEK,POKE}MTETAGS error documentation
     - drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr
     - smb: client: validate absolute native symlink targets before NT fixups
     - keys: fix lost wakeup when reaping a dead key type
     - neighbour: Add missing RCU annotation for neightbl_dump_info().
     - neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.
     - neighbour: Don't render blackhole_netdev via RTM_GETNEIGHTBL.
     - neighbour: Skip default parms when resumed in neightbl_dump_info().
     - ALSA: bcd2000: Fix race between rawmidi and disconnect
     - ntfs: use dynamic MFT tail reservation
     - ntfs: repack $MFT/$ATTRIBUTE LIST
     - ntfs: account for MFT records added during allocation
     - ntfs: protect runlist updates with the runlist lock
     - ntfs: propagate folio errors
     - ntfs: ignore interrupted inode reads as corruption
     - phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow
     - phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting
     - ALSA: pcm: set timer->private_data before registering the PCM timer
     - drm/msm/dp: skip PUSH_IDLE when the link was never enabled
     - drm/msm/dp: fix link bandwidth check when wide bus is enabled
     - ASoC: Rename snd_soc_dai_link_ch_map.ch_mask to cpu_ch_mask
     - ASoC: Add codec_ch_mask to snd_soc_dai_link_ch_map
     - ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params
     - spi: spi-qpic-snand: avoid writing QPIC_EBI2_ECC_BUF_CFG register
     - Input: trackpoint - fix the inertia attribute name in the ABI document
     - objtool: Validate disassembler headers in libopcodes probe
     - gpio: virtuser: skip free_irq when no IRQ is installed
     - ALSA: usb: 6fire: Avoid embedded URBs
     - ALSA: 6fire: fix OOB write from device-reported iso length
     - ksmbd: fix malformed procfs status output
     - ksmbd: extend procfs server statistics
     - ksmbd: follow SMB2 session expiration semantics
     - wifi: virt_wifi: don't transfer operstate before register
     - drm/xe/mmio_gem: forbid VMA split
     - drm/xe/mmio_gem: use write-back mapping for dummy page
     - drm/xe/mmio_gem: Revoke drm_vma_node on xe_mmio_gem destroy
     - drm/xe/shrinker: Return the freed page count through a parameter
     - drm/xe/shrinker: Take a runtime PM ref before shrinking non-system memory
     - drm/vc4: Use managed KMS polling to fix UAF on unbind
     - ALSA: hda: trace PCM open only after assigning a stream
     - wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all()
     - btrfs: tree-checker: print dev extent offset in error message
     - drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL
     - seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation
     - net: dsa: mxl862xx: disable the stats poll on teardown
     - net: bcmgenet: restore the hardware filters on open
     - sysctl: Check range in proc_dointvec_ms_jiffies_minmax
     - ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup
     - net: fddi: skfp: fix NULL deref when setting the MAC address while down
     - wifi: brcmfmac: fix lost 802.1x TX completion wakeup
     - net: bridge: mst: move switchdev call outside rcu
     - tcp: Don't call skb_clone_and_charge_r() for close()d listener in
       tcp_v6_do_rcv().
     - tcp: do not let tcp_rmem be set below 4096
     - ksmbd: return buffer overflow for partial filesystem info
     - ksmbd: fix partial file information responses
     - ksmbd: keep compound responses on query info errors
     - dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg()
     - Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained
     - Bluetooth: btintel_pcie: validate TX skb length in send_sync
     - Bluetooth: coredump: Quiesce dump work on unregister
     - Bluetooth: put the peer's on-air address on air when we cannot resolve
     - Bluetooth: hci_qca: Do not write to the serial port after it is closed
     - Bluetooth: ISO: Fix parent socket leak in iso_conn_ready()
     - Bluetooth: ISO: set BT_LISTEN before requesting a BIG sync
     - Bluetooth: btmtk: fix wrong status for short WMT FUNC_CTRL events
     - Bluetooth: btmtksdio, btmtkuart: validate WMT event length before struct
       access
     - Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown
     - Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit
     - Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup
     - af_unix: Unify scc_index when finalising SCC in __unix_walk_scc().
     - net: stmmac: fix TSO header length truncation
     - pppoatm: ensure a writable skb header and linear data
     - drop_monitor: synchronize tracepoint unregistration on error path
     - drop_monitor: use timer_shutdown_sync() to prevent timer rearming during
       teardown
     - drop_monitor: use raw_cpu_ptr() in tracepoint probes
     - drop_monitor: fix out-of-bounds write in reset_per_cpu_data()
     - net: stmmac: do not overwrite phc_index when no PTP clock is registered
     - net: bridge: vlan: fix bugs caused by switchdev deletion errors
     - netlink: do not free nlk->groups while lockless readers can use it
     - [powerpc*] KVM: PPC: Book3S HV: fix use-after-free in
       kvmhv_emulate_tlbie_all_lpid()
     - [powerpc*] KVM: PPC: Book3S HV: fix secure device page leak on
       uv_page_in() failure
     - [powerpc*] iommu: Fix the overflow validation in iommu_tce_check_ioba
     - Revert "drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable"
     - futex: Also allocate private hash on vfork()
     - drm/xe/i2c: Disable IRQ on unbind
     - btrfs: handle lack of space when cleaning up verity items
     - ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments
     - ASoC: hdmi-codec: Report a change when the channel status moves
     - ASoC: cs-amp-lib: Prevent NULL pointer if efi variable is zero length
     - ASoC: amd: acp: bounds-check SoundWire link ID in machine drivers
     - ASoC: sdw_utils: tidyup .count_sidecar
     - ASoC: sdw_utils: tidyup asoc_sdw_parse_sdw_endpoints()
     - [amd64] ASoC: amd: acp: refactor codec config count in SOF SoundWire
       machine driver
     - [amd64] ASoC: amd: acp: fix ffs() operator precedence for SoundWire link
       ID
     - net/sched: codel: bound the dropping loop per dequeue call
     - net: do not advance stack index from dev_fwd_path()
     - net: pass dst via net_device_path in dev_fill_forward_path()
     - net: pass net_device_path_ctx to dev_fill_forward_path()
     - net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check
     - net: netsec: fix device_node reference leak on phy_np
     - eth: fbnic: ring the doorbell if a burst ends in a drop
     - net: lock the socket in sock_gettstamp()
     - net: ethernet: cortina: Ack RX overrun interrupt correctly
     - net: stmmac: propagate FPE preemption-class mapping errors
     - net: prevent torn reads in netdev_tc_txq
     - net: stmmac: preserve real_num_tx_queues on mqprio setup failure
     - net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb()
     - [amd64] x86/kprobes: Fix crash when probing CS CALL instructions
     - net: macb: fix ordering around PTP timestamp read
     - net: mvpp2: prevent buffer overflow in page_pool allocation
     - net: skbuff: do not leave stale header offsets after pskb_carve()
     - drm/amdgpu: check ras and obj before dereference
     - drm/amd/display: fix MALL hysteresis timer underflow at high refresh rates
     - btrfs: abort transaction on failure to update inode for hole punching and
       reflinking
     - btrfs: check if there is space for chunk item when validating sys chunk
       array
     - perf: Fix null pointer access in is_include_guest_event()
     - sched/core: Avoid false migration warning for proxy donors
     - [amd64] x86/fred: Reconstruct the #GP context for rejected INT
       instructions
     - Input: eeti_ts - publish the OF module alias
     - hwmon: (gpio-fan) return IRQ_HANDLED from the shared alarm IRQ handler
     - hwmon: (hp-wmi-sensors) Improve raw WMI string handling
     - watchdog: da9062: fix suspend/resume handling of HW_RUNNING watchdog
     - Input: xpad - add support for Victrix Pro BFG Controller
     - Input: xpad - add support for Azeron devices
     - Input: xpad - fix PDP Marvel Xbox 360 controller
     - 9p: Fix v9fs_issue_write() to update i_size and remote_i_size
     - ALSA: core: Fix potential UAF after asynchronous card release
     - ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity
     - ALSA: virtio: reset device before deleting virtqueues
     - ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type
     - cgroup: Avoid iteration of dying tasks with zero refcount
       (Closes: #1144314) (CVE-2026-98163)
     - ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY
     - ata: libahci_platform: Fix device reference leak in
       ahci_platform_get_resources()
     - cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
     - exec: Cleanup POSIX timers right after de_thread()
     - fs/dax: check zero or empty entry before converting xarray entry
     - PCI: imx6: Move clock enable after core reset assertion
     - phy: renesas: rcar-gen3-usb2: Avoid long delay in atomic context
     - posix-cpu-timers: Prevent freeing a timer which is queued on the expiry
       list
     - rds: ib: use rds_conn_drop() on protocol version mismatch
     - signal: Prevent exec() race
     - rust: net: phy: fix off-by-one bit positions in device status accessors
     - Revert "nouveau/gsp: fix suspend/resume regression on r570 firmware"
     - drm/nouveau/gsp: Increase delay for magic sleep in r535_gsp_fini()
     - drm/nouveau/gsp/r570: Set GcOff = 0 in fbsr
     - drm/nouveau/gsp/r570: Enable S/R Display workaround in GSP
     - [amd64] x86/build/64: Prevent native builds from generating EGPR use
     - [amd64] x86/microcode/intel: Reject problematic loading on Granite Rapids
       systems
     - tcp: exclude old ACKs from tcp fast path
     - swiotlb: use the adjusted address for the highmem page lookup
     - soundwire: dmi-quirks: Disable ghost Realtek on Asus GX651AX
     - spi: fsl-qspi: Reprogram the clock rate when the operation frequency
       changes
     - spi: spi-zynqmp-gqspi: stop the controller on shutdown
     - spi: virtio: Use the per-transfer bits per word
     - RDMA/ucma: Serialize join and leave on copy_to_user failure
     - RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()
     - openvswitch: avoid reallocating confirmed conntrack labels
     - nfsd: fix handling of NFSEXP_PNFS in the netlink codepath
     - net: xfrm: reject unrepresentable espintcp transport headers
     - [arm64] hibernate: pass HVC_SET_VECTORS args to the resume hvc
     - [arm64] dts: renesas: r8a779f0: Set UFS lane count
     - [arm64] dts: socfpga: change access permission from 755 to 644
     - [arm64] percpu: Fix this_cpu_write() casting
     - [arm64] percpu: Fix this_cpu_and() mask generation
     - [arm64] percpu: Fix LSE operations on {8,16}-bit types
     - Bluetooth: btusb: fix NXP IW610 composite device handling
     - Bluetooth: eir: validate service data length before reading UUID
     - Bluetooth: hci_codec: validate vendor codec count length
     - Bluetooth: hci_sync: Serialize local codec list cleanup
     - Bluetooth: keep dst_type with dst when reusing an LE connection
     - btrfs: take commit root semaphore when iterating in
       mark_block_group_to_copy()
     - btrfs: fix creation of compressed inline extents that don't save space
     - btrfs: derive f_fsid with dev_t only when temp_fsid is active
     - btrfs: clear free space tree creation state on rebuild failure
     - gpiolib: Put fwnode reference on failure
     - gpiolib: of: don't mark hog nodes OF_POPULATED before a chip is found
     - dmaengine: sun6i: fix non-atomic read of DMA position registers
     - dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status
     - dmaengine: ti: k3-udma-glue: fix NULL dereference in
       k3_udma_glue_release_rx_chn()
     - dma-buf/dma-fence: fix checking signaling bit for timeline and driver name
       v3
     - dma-buf: Fix silent overflow for phys vec to sgt
     - dma-buf: Split sgl by largest page-aligned chunk
     - ipv6: xfrm: use full sockets in local error paths
     - net: ip_tunnel: initialize `options_len` before referencing options
     - net: lan743x: fix RX checksum use-after-free
     - net: phy: mediatek: do not report link and per-speed LED rules together
     - net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb()
     - net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain
     - net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value
     - net/sched: act_api: release tail references on DELACTION failure
     - net/sched: hhf: cap hh_flows_limit at change time
     - net/packet: clear RX owner on VNET header error
     - net/packet: avoid truncating TPACKET_V3 private size
     - scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable()
     - xfrm: serialize state GC with device state flush
     - xfrm: use hlist_del_init_rcu for state_cache and state_cache_input
     - xfrm: save input state data before secpath resets
     - soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node
     - mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
     - memcg: avoid charging the root memcg from obj_cgroup_charge_pages()
     - memstick: ms_block: destroy io_queue workqueue on removal
     - mm, swap: fix SWAP_USAGE_OFFLIST_BIT collision with real usage count
     - mm/huge_memory: bypass THP tuneables for huge pfnmap mappings
     - mm/mlock: use the IRQ-safe accessor for NR_MLOCK in __munlock_folio()
     - mm/mremap: account mm->locked_vm correctly for MREMAP_DONTUNMAP
     - mm/shrinker: fix bogus set_shrinker_bit() with cgroup.memory=nokmem
     - mm/vma: correctly unaccount on mmap_prepare() failure
     - mm: filemap: retain mapped dropbehind folios
     - KEYS: encrypted: fix integer overflow of datablob_len
     - keys: translate request_key_auth pid for the reading procfs instance
     - KEYS: trusted: Fix tpm2_load_cmd() boundary check
     - sched_ext: Fix NULL sched deref in kfunc sub-sched error paths
     - sched_ext: Close the pre-enable ops error claim window
     - i2c: at91: release DMA channels on remove and probe error
     - i2c: atr: fix dangling adapter pointer on add failure
     - i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove()
     - i2c: imx: release DMA channels on probe error
     - i2c: imx: disable autosuspend on remove
     - IB/mlx4: Fix use-after-free on pkey sysfs registration failure
     - IB/hfi1: Resolve the credit-return buffer through the send context's node
     - IB/hfi1: Fix the PIO_CRED credit-return mmap
     - selinux: preserve user SID across nested backing files
     - selinux: recheck intermediate backing files on mprotect()
     - selinux: always fill AVC decision in avc_has_perm_noaudit()
     - power: sequencing: don't call .post_enable() if pwrseq_unit_enable()
       failed
     - power: sequencing: fix NULL-pointer dereference in pwrseq_unit_new()
     - power: sequencing: fix NULL-pointer dereference in
       pwrseq_device_register()
     - mmc: core: Cancel SDIO IRQ work before freeing host
     - mmc: core: Fix OF node reference leak on card add failure
     - mmc: hsq: Fix use-after-free in retry work
     - mmc: mmci: Fix use-after-free in busy-timeout work
     - mmc: mxcmmc: cancel data work and watchdog on remove
     - mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260
     - mmc: sdhci-of-aspeed: Remove children before releasing SDC resources
     - mmc: sdio_uart: fix xmit_fifo leak when the port table is full
     - mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt
     - mmc: spi: reset bytes_xfered before retrying CRC failures
     - mmc: sdhci_am654: Move tuning_loop to local variable
     - mmc: sdhci_am654: Reset command and data lines on failed tuning
     - mmc: sdhci_am654: Clear ITAPDLY on tuning failure
     - mmc: sdhci_am654: Fallback to DT-provided itap delay on DDR50 tuning
       failure
     - Input: adp5588-keys - cache GPIO state before registering the gpiochip
     - Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026
     - Input: cyttsp5 - clamp the HID report size before memcpy
     - Input: evdev - zero absinfo before partial copy in EVIOCSABS
     - Input: hp_sdc - shut down kicker timer on module exit
     - Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P
     - Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()
     - Input: soc_button_array - fix MS Surface Pro 11 probe failure
     - Input: soc_button_array - check btns_desc->package.count
     - Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722)
     - Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound
     - Input: zero ff_effect before compat copy in input_ff_effect_from_user
     - hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()
     - hwmon: (pmbus/core) increase number of phases and add new mask
     - hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding
     - hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676
     - hwmon: (pwm-fan) Stop RPM timer before freeing tach data
     - hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove
     - hwmon: (w83793) release probe data through kref
     - hwmon: (cgbc-hwmon) Fix current sensors ID lookup
     - hwmon: (cgbc-hwmon) Add missing sensors
     - watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog
     - watchdog: digicolor: Avoid division by zero
     - watchdog: msc313e: Fix premature reset during timeout update
     - watchdog: msc313e: Propagate error code in resume()
     - watchdog: rtd119x: Avoid division by zero
     - watchdog: rzv2h: Avoid division by zero
     - watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init()
     - watchdog: starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start()
     - wifi: brcmsmac: fix UAF in brcms_free_timer()
     - wifi: iwlegacy: fix broadcast stations deallocation
     - wifi: libertas_tf: fix UAF in lbtf_free_adapter()
     - wifi: libipw: reject TKIP frames without a full MIC
     - wifi: rsi: fix heap OOB write on key removal
     - wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown
     - wifi: wlcore: release runtime PM ref on regdomain config failure
     - wifi: wilc1000: fix out-of-bounds read in P2P public action frames
     - wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext()
     - wifi: p54: validate curve data length in the calibration curve converters
     - wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST
     - wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length
     - wifi: mwifiex: validate scan response extents
     - wifi: mwifiex: prevent authentication frame length truncation
     - wifi: mwifiex: validate action frame fixed fields
     - wifi: mac80211: avoid WARN in set_bitrate_mask when sdata not in driver
     - wifi: mac80211: avoid out-of-bounds read for empty PREQ elements
     - wifi: mac80211: refuse to make a monitor active when it has no queue
     - drm/gud: fix out-of-bounds write in gud_plane_atomic_check()
     - drm/gud: Ignore damage clips in full update mode
     - drm/msm/adreno: fix autosuspend cleanup during teardown
     - drm/msm/dpu: clear pending peripheral flush state
     - drm/msm/hdmi_phy: fix runtime PM cleanup on probe failure
     - drm/msm: RCU-free the scheduler-containing ring and VM objects
     - drm/sched: Fix virtual runtime race
     - drm/amdgpu: fix rmmio iounmap skipped on device removal
     - drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments
     - drm/amdgpu: Skip KFD mapping clear before initialization
     - drm/amdkfd: Avoid integer underflow in EOP ring size calculation.
     - drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc
     - drm/amdkfd: implement restore_mqd callbacks for GFX12/12.1
     - smb: client: cancel reconnect work in clean_demultiplex_info()
     - smb/client: send lease break ACKs thru correct session for multiuser
       mounts
     - smb: client: fix rlist race and missing initialization
     - smb: client: fix use-after-free of iface in cifs_try_adding_channels()
     - smb: client: reject short Next offsets in parse_server_interfaces()
     - smb: client: fix smbd_connection leak on cifs_get_tcp_session() error
     - smb: client: fix unaligned access in WSL reparse point parser
     - smb: client: fix fattr leaking on wsl_to_fattr() failure
     - smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
     - smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
     - smb: client: fix potential OOB read in smb3_enum_snapshots()
     - smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
     - smb: client: fix server->total_read for compound encrypted PDUs
     - smb: client: fix missing lower-bound check on DFS referral string offsets
     - smb: client: fix missing iov bounds check in parse_posix_sids()
     - fs/super: skip non-memcg-aware nr_cached_objects in memcg slab shrink
     - fs: fix missed removal of super_fs_objects_eligible()
     - scsi: fnic: Make debug logging protocol independent
     - scsi: fnic: Bump up version number
     - scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU
     - drm/amdgpu: reduce early full GPU access during SR-IOV init
     - drm/amdgpu: Fix GPU PCIe link capability reporting
     - ntsync: reject wait ioctls with zero owner
     - drm/ttm: fix swapped-out resources never leaving their bulk_move range
     - drm/amdgpu: restrict BAR0 fallback read to SR-IOV VFs only
     - ksmbd: fix partial normalized name responses
Checksums-Sha1:
 ceaee50b071a4fb18e2a91b0ea007073f2c30959 188238 linux_7.2.8-1.dsc
 de1e390e87df65fb14f20542b06900c4b2b830f1 163638868 linux_7.2.8.orig.tar.xz
 f906087b5b336cdc5d5d8711fb5db08a6e2a2785 1478652 linux_7.2.8-1.debian.tar.xz
 7d3fb5083ff8b5a34c6706522a11481e35b1f98f 5896 linux_7.2.8-1_source.buildinfo
Checksums-Sha256:
 f295ccad09d398f6e0ccdbf073667d872731b648ebfe6948b9d5f56b60cc04cd 188238 linux_7.2.8-1.dsc
 08f058f9de8d487e32a5c9e2855ee7e35bee1a047e77d37ba797d734c0cc07b3 163638868 linux_7.2.8.orig.tar.xz
 0882144238490cd844202ea9a91bb6cc563103b4a11cc5fe488b1415b9be1354 1478652 linux_7.2.8-1.debian.tar.xz
 ffad8e31445d5ddacbf5af638a4a0c232695efa3f4490015d67bd2eb30ee3ae8 5896 linux_7.2.8-1_source.buildinfo
Files:
 66efbc6472ab9c29791605938240f90b 188238 kernel optional linux_7.2.8-1.dsc
 df06fd28177fb1debb946672c86e34ca 163638868 kernel optional linux_7.2.8.orig.tar.xz
 cbd6cb00e1d8bbb4cf6a13110e7e7afe 1478652 kernel optional linux_7.2.8-1.debian.tar.xz
 544cbdde0c03aede46447ef1d2e83ae7 5896 kernel optional linux_7.2.8-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmq3iKVfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89ES8gP/1yMWMj2Mg21QrypAOe+Sf8Y2stVO276
PKVEkn3LC27Un+SMV+xBkI8p629EejTTROB72sUs2Mck+yIJhtc5bHqb+3BnudGv
YWLf7dG0LHAfStWg8CQhkseQL5DJPnNUOrR7o8hc4ION8Nn7ExgVR3O6tLnQ3PCV
2C2WjEAAG17mKQkKFc4ZlVPTqlLghLS3AE3vogNyZYu5Oa5lopQYGw819tZxeXEm
xqsEbUJww8icdnHZ27IT2gYAk8+Qypb8u83KIaMvTFVGsD2pcIYLmgf7cDMUnOro
mnqRN9hey4mbJKjo8yYLc2ly1EnvJS+zjr8mUlnyHomZS2koZqpQrkHwvA5lCyyW
voVJsfen1TZUOHu9lqcidqJ9T55hDr1IzZKhm2P6DMEYB9P+PztVbaymTuxdC1PB
bIsHb41zRgQGuOw4fa8k7mt5HRzvU7JMeP6rBILu46Zkyi27Lnsf6E1y+dpd/lTi
JHyTWXdv4x0elwl2jZL01odojk62/1x42mQ0R2U9edGcIL4qRejrv4Is0nE0BuQM
zj3Buu23W82/n2soXhsut7TOO/6lDDF/s4FF6XNCdR5qOR5CEbw+VaRD6QgtDjHz
sLPemLDPZrbQZbfEjyavhSUyMmJXBN0zrDuzoBocQxSbh7SWaLe3r6qHu0iWOx7C
SUZDlIAc8/Na
=nTIf
-----END PGP SIGNATURE-----