Search results for “site:cos.googlesource.com”
About
14 results
c
cos.googlesource.com
third_party › kernel › + › 1c5a7e09f4791a79a02ae7d83967cd3e13b12755
sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() [ Upstream commit 3f981138109f63232a5fb7165938d4c945cc1b9d ] When enqueuing the first packet to an HFSC class, hfsc_enqueue() calls the child qdisc's peek() operation...
c
cos.googlesource.com
third_party › kernel › + › 269aea26c0f2e9675236f141e0a182b8c58e8e52
net_sched: hfsc: Address reentrant enqueue adding class to eltree twice Savino says: "We are writing to report that this recent patch (141d34391abbb315d68556b7c67ad97885407547) [1] can be bypassed, and a UAF can still occur when HFSC is...
In short: Critical security vulnerability in Google's kernel revealed: UAF can occur with HFSC and NETEM, bypassed patch. Learn how to fix the issue. (AI summary)
c
cos.googlesource.com
third_party › kernel › + › cbd62176e17d3c4d02a624ad951c16f9e6c8d5a4
net_sched: hfsc: Address reentrant enqueue adding class to eltree twice Savino says: "We are writing to report that this recent patch (141d34391abbb315d68556b7c67ad97885407547) [1] can be bypassed, and a UAF can still occur when HFSC is...
c
cos.googlesource.com
third_party › kernel › + › 2b6148ec22df8bd88c829407078577aecc9c764a
driver core: fix potential NULL pointer dereference in dev_uevent() commit 18daa52418e7e4629ed1703b64777294209d2622 upstream. If userspace reads "uevent" device attribute at the same time as another threads unbinds the device from its driver, change to dev->driver from a valid pointer to NULL may...
c
cos.googlesource.com
third_party › kernel › + › 2e89dc9fc1cfcb0184104491d7f412eee640086b
mm/vmscan: fix a bug calling wakeup_kswapd() with a wrong zone index commit 2774f256e7c0219e2b0a0894af1c76bdabc4f974 upstream. With numa balancing on, when a numa system is running where a numa node doesn't have its local memory so it has...
c
cos.googlesource.com
third_party › kernel › + › 49f714e11508237fec456345a90d7ebca354362f
bpf: Prevent tail call between progs attached to different hooks commit 28ead3eaabc16ecc907cfb71876da028080f6356 upstream. bpf progs can be attached to kernel functions, and the attached functions can take different parameters or return different return values. If prog attached to one kernel...
c
cos.googlesource.com
third_party › kernel › + › 7217e46094ce6bf030248161190afe8b3d8678e8
sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() [ Upstream commit 3f981138109f63232a5fb7165938d4c945cc1b9d ] When enqueuing the first packet to an HFSC class, hfsc_enqueue() calls the child qdisc's peek() operation...
c
cos.googlesource.com
third_party › kernel › + › 886b1d9ff3fa338cc9fcf17a29044e75e53b7703
COS Kernel Merge Bot <cloud-image-merge-automation@prod.google.com> Fri May 02 02:09:55 2025 -0700 committer tree 4ce7849f5b0763d685221fce0115b5b8a908a628 parent 47fa00f1eb2c0c37a5e65a0a1c80fb8a0688bbcb [diff] 71e4ec9b2abccce5adecb3b354d0d5003f6f88f2 [diff] merge-upstream/v6.6.89 from branch/tag...
c
cos.googlesource.com
third_party › kernel › + › 8f1ed7554eff45bf08c26fd7f15bc57a7ffac0b0
COS Kernel Merge Bot <cloud-image-merge-automation@prod.google.com> Fri Jun 06 01:57:21 2025 -0700 committer tree f0767878a7bb0f2641d9224763a3ffa7e7c8a35d parent 8ff56aa9d000fc42d1198f5e46504f60c75f29b2 [diff] c2603c511feb427b2b09f74b57816a81272932a1 [diff] merge-upstream/v6.6.93 from branch/tag...
c
cos.googlesource.com
third_party › kernel › + › 8ff56aa9d000fc42d1198f5e46504f60c75f29b2
net_sched: hfsc: Address reentrant enqueue adding class to eltree twice Savino says: "We are writing to report that this recent patch (141d34391abbb315d68556b7c67ad97885407547) [1] can be bypassed, and a UAF can still occur when HFSC is...