In the Linux kernel, the following vulnerability has been resolved: arm64/gcs: Fix error handling in arch_set_shadow_stack_status() alloc_gcs() returns an error-encoded pointer on failure, which comes from do_mmap(), not NULL. The current NULL check fails to detect errors, which could lead to using an invalid GCS address. Use IS_ERR_VALUE() to properly detect errors, consistent with the check in gcs_alloc_thread_stack().
Update Linux/Linux to c787a235deb33be6eda40beee8f561da5fd8cb8c if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanarm64/gcs: Fix error handling in arch_set_shadow_stack_status() affects Linux/Linux (generic), Linux/Linux (generic). Severity is medium. In the Linux kernel, the following vulnerability has been resolved: arm64/gcs: Fix error handling in arch_set_shadow_stack_status() alloc_gcs() returns an error-encoded pointer on failure, which comes from do_mmap(), not NULL. The current NULL check fails to detect errors, which could lead to using an invalid GCS address. Use IS_ERR_VALUE() to properly detect errors, consistent with the check in gcs_alloc_thread_stack().
AI coding agents often install or upgrade packages automatically in generic. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b57180c75c7ebff6613886cb69ef6e283a10358b <c787a235deb33be6eda40beee8f561da5fd8cb8c || >=b57180c75c7ebff6613886cb69ef6e283a10358b <a4741114c9622346c4bbb8cc2bbd88153616ffaf || >=b57180c75c7ebff6613886cb69ef6e283a10358b <53c998527ffa60f9deda8974a11ad39790684159 |
In the Linux kernel, the following vulnerability has been resolved: arm64/gcs: Fix error handling in arch_set_shadow_stack_status() alloc_gcs() returns an error-encoded pointer on failure, which comes from do_mmap(), not NULL. The current NULL check fails to detect errors, which could lead to using an invalid GCS address. Use IS_ERR_VALUE() to properly detect errors, consistent with the check in gcs_alloc_thread_stack().
Update Linux/Linux to c787a235deb33be6eda40beee8f561da5fd8cb8c if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanarm64/gcs: Fix error handling in arch_set_shadow_stack_status() affects Linux/Linux (generic), Linux/Linux (generic). Severity is medium. In the Linux kernel, the following vulnerability has been resolved: arm64/gcs: Fix error handling in arch_set_shadow_stack_status() alloc_gcs() returns an error-encoded pointer on failure, which comes from do_mmap(), not NULL. The current NULL check fails to detect errors, which could lead to using an invalid GCS address. Use IS_ERR_VALUE() to properly detect errors, consistent with the check in gcs_alloc_thread_stack().
AI coding agents often install or upgrade packages automatically in generic. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b57180c75c7ebff6613886cb69ef6e283a10358b <c787a235deb33be6eda40beee8f561da5fd8cb8c || >=b57180c75c7ebff6613886cb69ef6e283a10358b <a4741114c9622346c4bbb8cc2bbd88153616ffaf || >=b57180c75c7ebff6613886cb69ef6e283a10358b <53c998527ffa60f9deda8974a11ad39790684159 |
| c787a235deb33be6eda40beee8f561da5fd8cb8c, a4741114c9622346c4bbb8cc2bbd88153616ffaf, 53c998527ffa60f9deda8974a11ad39790684159 |
| Linux/Linuxgeneric | 6.13 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| c787a235deb33be6eda40beee8f561da5fd8cb8c, a4741114c9622346c4bbb8cc2bbd88153616ffaf, 53c998527ffa60f9deda8974a11ad39790684159 |
| Linux/Linuxgeneric | 6.13 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard