Further restrict the characters allowed in a command-line supplied user
name, disallowing '$' and '\'.
Reported by SecBuddyF KeenLab Tencent (CodeBuddy Security).
drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments
From Mike Lothian
aeaa7bdc0ea2c725331a423575bb7f93c040f8fb in linux-6.18.y/6.18.54
636139603b99d2e3a18a46cf3f8d39313ce8042e in mainline linux
drm/amdgpu: lock bo before calling amdgpu_vm_bo_update_shared
From Pierre-Eric Pelloux-Prayer
801d8647dcb0d34f0654b11f932e4ed365092c5e in linux-6.18.y/6.18.54
36ffc58b8a8704e690a0ce679db26baa5759256f in mainline linux
drm/amdgpu: fix rmmio iounmap skipped on device removal
From Chengjun Yao
cd55dde2b63789a3dafe982c89844f537501d096 in linux-6.18.y/6.18.54
5155002b03b24ba3ef91c5c313b8cf0171b24904 in mainline linux
drm/amdgpu: check ras and obj before dereference
From Dmitriy Chumachenko
37583946d8751f8e285c467d770ac0b609b82a23 in linux-6.18.y/6.18.54
723d4dc628d764b19cf9efca14b82cca5ff020c9 in mainline linux
drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr
From Thadeu Lima de Souza Cascardo
daefd7ff159b0d1fb8c9e64430dcbe2aca1bdd09 in linux-6.18.y/6.18.54
9eb1a393c89a79c4210230d23e7d88d239c61d7b in mainline linux
Reserve a 16K-byte gap at the start of a swap partition.
Swap currently reserves PAGE_SIZE (4K, 8K or 16K depending on arch) bytes
as potential space for a disklabel and boot code.
A disklabel can be placed in the first or second DEV_BSIZE bytes of swap, with
some arch's needing up to 6 * DEV_BSIZE additional bytes for boot code and arch
dependent disklabel info.
New disklabel code will need to store a bigger disklabel structure
in 3 * DEV_BSIZE bytes of the *FIRST VIABLE PARTITION WITH A GAP*.
VIABLE PARTITIONS are filesystems (ffs and swap in particular) which have a
sufficiently large gap.
Increasing the swap partition gap makes it much more likely that those bytes
will be available.
Suggested by & ok deraadt@
rpki-client: add a copy of libcrypto's bytestring API
This will be used to replace the terrible CMS API from libcrypto. Longer
term this might also be used to implement better parsers for certs, CRLs
and the signed objects' eContent.
discussed with claudio and job
ok beck
libcrypto/bytestring: add some missing tag classes
This adds tags for NULL, PrintableString, UTCTime, and GeneralizedTime with
names matching BoringSSL.
ok kenjiro
libcrypto/bytestring: remove LIBRESSL_INTERNAL from bytestring.h
This currently marks the LibreSSL-specific additions to this API. It has
no effect other than getting in the way of other projects wanting to use
this since it is always compiled with LIBRESSL_INTERNAL.
ok kenjiro
sysv_shm: claim the vm_shm slot after uvm_map(), not before
sys_shmat() chose a free slot in the per-vmspace vm_shm array, then slept
in uvm_map(), then published into the slot it had chosen. Nothing marked
the slot taken across the sleep, so a sibling thread entering sys_shmat()
scanned the same array, found the same slot still reading -1, and took it
too. Both uvm_map() calls succeed at different addresses and the thread
that stores last wins; the other mapping is left with no vm_shm entry, so
shmdt() returns EINVAL for it and shmexit() cannot drop its shm_nattch.
The permanently raised count keeps IPC_RMID from deallocating the segment,
which then sits in shmsegs[] reachable by nobody; 128 of those and
shmget() returns ENOSPC system-wide.
uvm_map() is the only sleep between choosing the slot and filling it in,
so moving the scan below the map closes the window without a reserved
state that shmdt(), shmexit() and shmfork() would each have to learn
about. EMFILE is now discovered after the mapping exists, so that path
undoes it.
[9 lines not shown]
Backport fixes from libexpat version 2.8.5.
Relevant for OpenBSD are security fixes #1282, bug fixes #1346
#1371, other changes #1354 #1357 #1349 #1360 #1378. Library bump
is not necessary.
CVE-2026-93990
OK deraadt@
this is errata/7.9/033_expat.patch.sig
Backport fixes from libexpat version 2.8.5.
Relevant for OpenBSD are security fixes #1282, bug fixes #1346
#1371, other changes #1354 #1357 #1349 #1360 #1378. Library bump
is not necessary.
CVE-2026-93990
OK deraadt@
this is errata/7.8/069_expat.patch.sig
incorrect object being freed
from Franz Bettag / Bettag Systems
from deraadt@; OK markus@ hshoexer@ sthen@ mvs@
IKEv1 short-HASH heap overflow; second approach for fix
from Franz Bettag / Bettag Systems
from deraadt@; OK sthen@ mvs@
Franz Bettag sent a report & diff repairing the privsep monitor's
dangerous file behavior in /var/run, and I was shocked at what it
does. isakmpd never had a proper diagnosis and control program like
other daemons do, and instead accepts weird commands on a fifo and
splats files dangerously. Some path names can be manipulated. This
2600 line diff removes all of this session debugging mechanism which
is the main cause of that unsafe design. There are no reuseable parts
in that code (it cannot be reconstructed into a proper control program
interface). As a result, the privsep monitor now has unveil to the
config directory, and the network speaking process is "stdio sendfd
route recvfd inet". There is some loss of functionality, since some
[22 lines not shown]
incorrect object being freed
from Franz Bettag / Bettag Systems
from deraadt@; OK markus@ hshoexer@ sthen@ mvs@
IKEv1 short-HASH heap overflow; second approach for fix
from Franz Bettag / Bettag Systems
from deraadt@; OK sthen@ mvs@
Franz Bettag sent a report & diff repairing the privsep monitor's
dangerous file behavior in /var/run, and I was shocked at what it
does. isakmpd never had a proper diagnosis and control program like
other daemons do, and instead accepts weird commands on a fifo and
splats files dangerously. Some path names can be manipulated. This
2600 line diff removes all of this session debugging mechanism which
is the main cause of that unsafe design. There are no reuseable parts
in that code (it cannot be reconstructed into a proper control program
interface). As a result, the privsep monitor now has unveil to the
config directory, and the network speaking process is "stdio sendfd
route recvfd inet". There is some loss of functionality, since some
[22 lines not shown]