In the Linux kernel, the following vulnerability has been resolved: Revert "Revert "block, bfq: honor already-setup queue merges"" A crash [1] happened to be triggered in conjunction with commit 2d52c58b9c9b ("block, bfq: honor already-setup queue merges"). The latter was then reverted by commit ebc69e897e17 ("Revert "block, bfq: honor already-setup queue merges""). Yet, the reverted commit was not the one introducing the bug. In fact, it actually triggered a UAF introduced by a different commit, and now fixed by commit d29bd41428cf ("block, bfq: reset last_bfqq_created on group change"). So, there is no point in keeping commit 2d52c58b9c9b ("block, bfq: honor already-setup queue merges") out. This commit restores it. [1] https://bugzilla.kernel.org/show_bug.cgi?id=214503
Update Linux/Linux to f990f0985eda59d4f29fc83fcf300c92b1225d39 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanRevert "Revert "block, bfq: honor already-setup queue merges"" affects Linux/Linux (generic), Linux/Linux (generic). Severity is unknown. In the Linux kernel, the following vulnerability has been resolved: Revert "Revert "block, bfq: honor already-setup queue merges"" A crash [1] happened to be triggered in conjunction with commit 2d52c58b9c9b ("block, bfq: honor already-setup queue merges"). The latter was then reverted by commit ebc69e897e17 ("Revert "block, bfq: honor already-setup queue merges""). Yet, the reverted commit was not the one introducing the bug. In fact, it actually triggered a UAF introduced by a different commit, and now fixed by commit d29bd41428cf ("block, bfq: reset last_bfqq_created on group change"). So, there is no point in keeping commit 2d52c58b9c9b ("block, bfq: honor already-setup queue merges") out. This commit restores it. [1] https://bugzilla.kernel.org/show_bug.cgi?id=214503
AI coding agents often install or upgrade packages automatically in generic. A unknown vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
In the Linux kernel, the following vulnerability has been resolved: Revert "Revert "block, bfq: honor already-setup queue merges"" A crash [1] happened to be triggered in conjunction with commit 2d52c58b9c9b ("block, bfq: honor already-setup queue merges"). The latter was then reverted by commit ebc69e897e17 ("Revert "block, bfq: honor already-setup queue merges""). Yet, the reverted commit was not the one introducing the bug. In fact, it actually triggered a UAF introduced by a different commit, and now fixed by commit d29bd41428cf ("block, bfq: reset last_bfqq_created on group change"). So, there is no point in keeping commit 2d52c58b9c9b ("block, bfq: honor already-setup queue merges") out. This commit restores it. [1] https://bugzilla.kernel.org/show_bug.cgi?id=214503
Update Linux/Linux to f990f0985eda59d4f29fc83fcf300c92b1225d39 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanRevert "Revert "block, bfq: honor already-setup queue merges"" affects Linux/Linux (generic), Linux/Linux (generic). Severity is unknown. In the Linux kernel, the following vulnerability has been resolved: Revert "Revert "block, bfq: honor already-setup queue merges"" A crash [1] happened to be triggered in conjunction with commit 2d52c58b9c9b ("block, bfq: honor already-setup queue merges"). The latter was then reverted by commit ebc69e897e17 ("Revert "block, bfq: honor already-setup queue merges""). Yet, the reverted commit was not the one introducing the bug. In fact, it actually triggered a UAF introduced by a different commit, and now fixed by commit d29bd41428cf ("block, bfq: reset last_bfqq_created on group change"). So, there is no point in keeping commit 2d52c58b9c9b ("block, bfq: honor already-setup queue merges") out. This commit restores it. [1] https://bugzilla.kernel.org/show_bug.cgi?id=214503
AI coding agents often install or upgrade packages automatically in generic. A unknown vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
| Linux/Linuxgeneric | >=aee69d78dec0ffdf82e35d57c626e80dddc314d5 <f990f0985eda59d4f29fc83fcf300c92b1225d39 || >=aee69d78dec0ffdf82e35d57c626e80dddc314d5 <931aff627469a75c77b9fd3823146d0575afffd6 || >=aee69d78dec0ffdf82e35d57c626e80dddc314d5 <cc051f497eac9d8a0d816cd4bffa3415f2724871 || >=aee69d78dec0ffdf82e35d57c626e80dddc314d5 <65d8a737452e88f251fe5d925371de6d606df613 || >=aee69d78dec0ffdf82e35d57c626e80dddc314d5 <abc2129e646af7b43025d90a071f83043f1ae76c || >=aee69d78dec0ffdf82e35d57c626e80dddc314d5 <4083925bd6dc89216d156474a8076feec904e607 || >=aee69d78dec0ffdf82e35d57c626e80dddc314d5 <15729ff8143f8135b03988a100a19e66d7cb7ecd | f990f0985eda59d4f29fc83fcf300c92b1225d39, 931aff627469a75c77b9fd3823146d0575afffd6, cc051f497eac9d8a0d816cd4bffa3415f2724871, 65d8a737452e88f251fe5d925371de6d606df613, abc2129e646af7b43025d90a071f83043f1ae76c, 4083925bd6dc89216d156474a8076feec904e607, 15729ff8143f8135b03988a100a19e66d7cb7ecd |
|---|---|---|
| Linux/Linuxgeneric | 4.12 | Not reported |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Linux/Linuxgeneric | >=aee69d78dec0ffdf82e35d57c626e80dddc314d5 <f990f0985eda59d4f29fc83fcf300c92b1225d39 || >=aee69d78dec0ffdf82e35d57c626e80dddc314d5 <931aff627469a75c77b9fd3823146d0575afffd6 || >=aee69d78dec0ffdf82e35d57c626e80dddc314d5 <cc051f497eac9d8a0d816cd4bffa3415f2724871 || >=aee69d78dec0ffdf82e35d57c626e80dddc314d5 <65d8a737452e88f251fe5d925371de6d606df613 || >=aee69d78dec0ffdf82e35d57c626e80dddc314d5 <abc2129e646af7b43025d90a071f83043f1ae76c || >=aee69d78dec0ffdf82e35d57c626e80dddc314d5 <4083925bd6dc89216d156474a8076feec904e607 || >=aee69d78dec0ffdf82e35d57c626e80dddc314d5 <15729ff8143f8135b03988a100a19e66d7cb7ecd | f990f0985eda59d4f29fc83fcf300c92b1225d39, 931aff627469a75c77b9fd3823146d0575afffd6, cc051f497eac9d8a0d816cd4bffa3415f2724871, 65d8a737452e88f251fe5d925371de6d606df613, abc2129e646af7b43025d90a071f83043f1ae76c, 4083925bd6dc89216d156474a8076feec904e607, 15729ff8143f8135b03988a100a19e66d7cb7ecd |
|---|---|---|
| Linux/Linuxgeneric | 4.12 | Not reported |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard