<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux-toradex.git/drivers/tty/vt, branch master</title>
<subtitle>Linux kernel for Apalis and Colibri modules</subtitle>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/'/>
<entry>
<title>vt: selection: Fix unsigned underflow and slab-out-of-bounds read in paste_selection()</title>
<updated>2026-10-01T09:15:46+00:00</updated>
<author>
<name>Hui Peng</name>
<email>benquike@gmail.com</email>
</author>
<published>2026-09-19T11:00:41+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=39495ef5d6f8019e62d65807f217a7ca8232727a'/>
<id>39495ef5d6f8019e62d65807f217a7ca8232727a</id>
<content type='text'>
In paste_selection(), the loop copies min_t(unsigned int,
vc_sel.buf_len - pasted,tty-&gt;receive_room) bytes per iteration into
tty_ldisc_receive_buf() and increments pasted += count.

Because the selection mutex (vc_sel.lock) is dropped inside the loop
Whenever the line discipline buffer fills up and paste_selection()
sleeps on tty-&gt;write_wait, a concurrent TIOCLINUX (TIOCL_SETSEL) ioctl
can replace vc_sel.buffer with a shorter selection and reduce
vc_sel.buf_len below pasted.

When paste_selection() resumes, vc_sel.buf_len - pasted underflows as an
unsigned integer to a large positive value, causing
tty_ldisc_receive_buf(ld, vc_sel.buffer + pasted, NULL, count) to read
up to 4094 bytes out-of-bounds past the newly allocated vc_sel.buffer.

Fix this by terminating the loop when pasted &gt;= vc_sel.buf_len.

Kernel stack trace (Linux 7.3.0-rc3):
 ==================================================================
 BUG: KASAN: slab-out-of-bounds in n_tty_receive_buf_common+0xa01/0x1650
 Read of size 4094 at addr ffff888101c58010 by task kworker/u17:1/65
 Workqueue: events_unbound flush_to_ldisc
 Call Trace:
  &lt;TASK&gt;
  dump_stack_lvl+0x70/0xa0
  print_report+0x153/0x4c6
  kasan_report+0xf1/0x120
  kasan_check_range+0x11c/0x200
  __asan_memcpy+0x29/0x70
  n_tty_receive_buf_common+0xa01/0x1650
  tty_ldisc_receive_buf+0x66/0x110
  tty_port_default_receive_buf+0x6b/0xb0
  flush_to_ldisc+0x1b4/0x410
  process_one_work+0x6ff/0x1110
  worker_thread+0x4a8/0xb70
  kthread+0x307/0x3e0
  ret_from_fork+0x3ed/0x680
  &lt;/TASK&gt;
 ==================================================================

Fixes: e8c75a30a23c ("vt: selection, push sel_lock up")
Cc: stable &lt;stable@kernel.org&gt;
Assisted-by: LLM
Signed-off-by: Hui Peng &lt;benquike@gmail.com&gt;
Link: https://patch.msgid.link/20260919110041.3763078-1-benquike@gmail.com
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
In paste_selection(), the loop copies min_t(unsigned int,
vc_sel.buf_len - pasted,tty-&gt;receive_room) bytes per iteration into
tty_ldisc_receive_buf() and increments pasted += count.

Because the selection mutex (vc_sel.lock) is dropped inside the loop
Whenever the line discipline buffer fills up and paste_selection()
sleeps on tty-&gt;write_wait, a concurrent TIOCLINUX (TIOCL_SETSEL) ioctl
can replace vc_sel.buffer with a shorter selection and reduce
vc_sel.buf_len below pasted.

When paste_selection() resumes, vc_sel.buf_len - pasted underflows as an
unsigned integer to a large positive value, causing
tty_ldisc_receive_buf(ld, vc_sel.buffer + pasted, NULL, count) to read
up to 4094 bytes out-of-bounds past the newly allocated vc_sel.buffer.

Fix this by terminating the loop when pasted &gt;= vc_sel.buf_len.

Kernel stack trace (Linux 7.3.0-rc3):
 ==================================================================
 BUG: KASAN: slab-out-of-bounds in n_tty_receive_buf_common+0xa01/0x1650
 Read of size 4094 at addr ffff888101c58010 by task kworker/u17:1/65
 Workqueue: events_unbound flush_to_ldisc
 Call Trace:
  &lt;TASK&gt;
  dump_stack_lvl+0x70/0xa0
  print_report+0x153/0x4c6
  kasan_report+0xf1/0x120
  kasan_check_range+0x11c/0x200
  __asan_memcpy+0x29/0x70
  n_tty_receive_buf_common+0xa01/0x1650
  tty_ldisc_receive_buf+0x66/0x110
  tty_port_default_receive_buf+0x6b/0xb0
  flush_to_ldisc+0x1b4/0x410
  process_one_work+0x6ff/0x1110
  worker_thread+0x4a8/0xb70
  kthread+0x307/0x3e0
  ret_from_fork+0x3ed/0x680
  &lt;/TASK&gt;
 ==================================================================

Fixes: e8c75a30a23c ("vt: selection, push sel_lock up")
Cc: stable &lt;stable@kernel.org&gt;
Assisted-by: LLM
Signed-off-by: Hui Peng &lt;benquike@gmail.com&gt;
Link: https://patch.msgid.link/20260919110041.3763078-1-benquike@gmail.com
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>vt: skip screen update for DEC alignment test on backgroup consoles</title>
<updated>2026-10-01T09:15:34+00:00</updated>
<author>
<name>Zizhi Wo</name>
<email>wozizhi@huawei.com</email>
</author>
<published>2026-09-05T06:43:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=0928ed9bd7946baee911efa401088697836e3b1e'/>
<id>0928ed9bd7946baee911efa401088697836e3b1e</id>
<content type='text'>
[BUG]
Recently, we encountered a KASAN warning as follows:

BUG: KASAN: slab-out-of-bounds in fb_pad_aligned_buffer+0x11f/0x140
Read of size 1 at addr ff1100015fd9f6a4 by task tty_fbcon_oob/1239
CPU: 7 UID: 0 PID: 1239 Comm: tty_fbcon_oob Not tainted 7.3.0-rc1 #100 PREEMPT(full)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc41 04/01/2014
Call Trace:
 &lt;TASK&gt;
 ...
 kasan_report+0xf0/0x120
 fb_pad_aligned_buffer+0x11f/0x140
 ccw_putcs+0x86c/0xa80
 fbcon_putcs+0x338/0x410
 do_update_region+0x21d/0x450
 do_con_write+0x1e0e/0x4880
 con_write+0x13/0x80
 n_tty_write+0x374/0x1010
 file_tty_write.isra.0+0x404/0x7a0
 ...

reproduce:
1) open /dev/tty0, set a KDFONTOP ioctl with op.op = KD_FONT_OP_SET,
op.width = 8 and op.height = 16 (visible VC1)
2) open /dev/tty1, set a KDFONTOP ioctl with op.op = KD_FONT_OP_SET,
op.width = 28 and op.height = 24 (invisible VC2)
3) echo 3 &gt; /sys/devices/virtual/graphics/fbcon/rotate_all
4) write EShash8(esc hash8) to tty1

[CAUSE]
All VCs render to the framebuffer. setfont only modifies the target VC's
font without resizing the framebuffer backing buffer (par-&gt;rotated.buf);
the buffer is only resized for the visible VC
(fbcon_do_set_font -&gt; ... -&gt; vc_do_resize -&gt; update_screen). This relies on
the con_should_update() check performed before every update_region().

However, the ESC # 8 path (do_con_trol -&gt; do_update_region) omits the
con_should_update() check. After changing the font size of an invisible VC,
do_update_region() fills using the new font size against a buffer that was
never resized, causing an out-of-bounds access.

[FIX]
Only push the update when the console is visible and not blanked, add
the con_should_update() check in the do_con_trol() like every other call
site of do_update_region() (update_region(), invert_screen(), ...).

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable &lt;stable@kernel.org&gt;
Signed-off-by: Zizhi Wo &lt;wozizhi@huawei.com&gt;
Link: https://patch.msgid.link/20260905064337.3083103-1-wozizhi@huaweicloud.com
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
[BUG]
Recently, we encountered a KASAN warning as follows:

BUG: KASAN: slab-out-of-bounds in fb_pad_aligned_buffer+0x11f/0x140
Read of size 1 at addr ff1100015fd9f6a4 by task tty_fbcon_oob/1239
CPU: 7 UID: 0 PID: 1239 Comm: tty_fbcon_oob Not tainted 7.3.0-rc1 #100 PREEMPT(full)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc41 04/01/2014
Call Trace:
 &lt;TASK&gt;
 ...
 kasan_report+0xf0/0x120
 fb_pad_aligned_buffer+0x11f/0x140
 ccw_putcs+0x86c/0xa80
 fbcon_putcs+0x338/0x410
 do_update_region+0x21d/0x450
 do_con_write+0x1e0e/0x4880
 con_write+0x13/0x80
 n_tty_write+0x374/0x1010
 file_tty_write.isra.0+0x404/0x7a0
 ...

reproduce:
1) open /dev/tty0, set a KDFONTOP ioctl with op.op = KD_FONT_OP_SET,
op.width = 8 and op.height = 16 (visible VC1)
2) open /dev/tty1, set a KDFONTOP ioctl with op.op = KD_FONT_OP_SET,
op.width = 28 and op.height = 24 (invisible VC2)
3) echo 3 &gt; /sys/devices/virtual/graphics/fbcon/rotate_all
4) write EShash8(esc hash8) to tty1

[CAUSE]
All VCs render to the framebuffer. setfont only modifies the target VC's
font without resizing the framebuffer backing buffer (par-&gt;rotated.buf);
the buffer is only resized for the visible VC
(fbcon_do_set_font -&gt; ... -&gt; vc_do_resize -&gt; update_screen). This relies on
the con_should_update() check performed before every update_region().

However, the ESC # 8 path (do_con_trol -&gt; do_update_region) omits the
con_should_update() check. After changing the font size of an invisible VC,
do_update_region() fills using the new font size against a buffer that was
never resized, causing an out-of-bounds access.

[FIX]
Only push the update when the console is visible and not blanked, add
the con_should_update() check in the do_con_trol() like every other call
site of do_update_region() (update_region(), invert_screen(), ...).

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable &lt;stable@kernel.org&gt;
Signed-off-by: Zizhi Wo &lt;wozizhi@huawei.com&gt;
Link: https://patch.msgid.link/20260905064337.3083103-1-wozizhi@huaweicloud.com
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>vc_screen: reload vc pointer before if (ret) in vcs_write() to avoid UAF</title>
<updated>2026-10-01T09:15:09+00:00</updated>
<author>
<name>Yi Yang</name>
<email>yiyang13@huawei.com</email>
</author>
<published>2026-09-01T11:31:31+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=226bd5603371cd9f6642cbb9e9a677f445de3530'/>
<id>226bd5603371cd9f6642cbb9e9a677f445de3530</id>
<content type='text'>
The reload of 'vc' added by commit 8fb9ea65c9d1 ("vc_screen: reload load
of struct vc_data pointer in vcs_write() to avoid UAF") sits after the
'if (ret)' block, so the copy-failure break path exits the loop without
reloading vc. If the vc was kfree()'d via vc_port_destruct during the
unlocked copy_from_user() window, the post-loop
'if (written &amp;&amp; vc) vcs_scr_updated(vc)' is reached with a stale
non-NULL vc. The '&amp;&amp; vc' guard from commit a287620312dc ("vc_screen:
fix null-ptr-deref in vcs_notifier() during concurrent vcs_write") only
handles the NULL case, not this stale-non-NULL case; vcs_notifier() then
reads param-&gt;vc-&gt;vc_num from freed memory:

  BUG: KASAN: slab-use-after-free in vcs_notifier+0x7c/0xd0
  Read of size 2 at addr ffff888007149190
  Call Trace:
   vcs_notifier+0x7c/0xd0
   atomic_notifier_call_chain+0x70/0xa0
   vcs_scr_updated+0x77/0xa0
   vcs_write+0x71b/0x7e0
  Allocated by task: vc_allocate -&gt; con_install -&gt; tty_open
  Freed by task: kfree &lt;- vt_ioctl (VT_DISALLOCATE -&gt; vc_port_destruct)

Move the reload to immediately after console_lock(), before 'if (ret)',
so every break path below passes a fresh vc to the post-loop
vcs_scr_updated().

Fixes: a287620312dc ("vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write")
Cc: stable@kernel.org
Signed-off-by: Yi Yang &lt;yiyang13@huawei.com&gt;
Link: https://patch.msgid.link/20260901113131.2760010-1-yiyang13@huawei.com
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The reload of 'vc' added by commit 8fb9ea65c9d1 ("vc_screen: reload load
of struct vc_data pointer in vcs_write() to avoid UAF") sits after the
'if (ret)' block, so the copy-failure break path exits the loop without
reloading vc. If the vc was kfree()'d via vc_port_destruct during the
unlocked copy_from_user() window, the post-loop
'if (written &amp;&amp; vc) vcs_scr_updated(vc)' is reached with a stale
non-NULL vc. The '&amp;&amp; vc' guard from commit a287620312dc ("vc_screen:
fix null-ptr-deref in vcs_notifier() during concurrent vcs_write") only
handles the NULL case, not this stale-non-NULL case; vcs_notifier() then
reads param-&gt;vc-&gt;vc_num from freed memory:

  BUG: KASAN: slab-use-after-free in vcs_notifier+0x7c/0xd0
  Read of size 2 at addr ffff888007149190
  Call Trace:
   vcs_notifier+0x7c/0xd0
   atomic_notifier_call_chain+0x70/0xa0
   vcs_scr_updated+0x77/0xa0
   vcs_write+0x71b/0x7e0
  Allocated by task: vc_allocate -&gt; con_install -&gt; tty_open
  Freed by task: kfree &lt;- vt_ioctl (VT_DISALLOCATE -&gt; vc_port_destruct)

Move the reload to immediately after console_lock(), before 'if (ret)',
so every break path below passes a fresh vc to the post-loop
vcs_scr_updated().

Fixes: a287620312dc ("vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write")
Cc: stable@kernel.org
Signed-off-by: Yi Yang &lt;yiyang13@huawei.com&gt;
Link: https://patch.msgid.link/20260901113131.2760010-1-yiyang13@huawei.com
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>tty: vt: fix memory leak in vc_allocate()</title>
<updated>2026-09-23T09:54:16+00:00</updated>
<author>
<name>Mingyu Wang</name>
<email>25181214217@stu.xidian.edu.cn</email>
</author>
<published>2026-08-03T14:45:56+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=5b114bfc1dfd88f9d50822d532f7f1fce0f7388a'/>
<id>5b114bfc1dfd88f9d50822d532f7f1fce0f7388a</id>
<content type='text'>
If the screen buffer allocation fails in vc_allocate(), the error handling
path jumps to `err_free`. However, this path fails to release the unicode
screen map attached to `vc-&gt;uni_pagedict_loc`.

During the early stages of vc_allocate(), the unicode screen map is either
newly allocated via con_set_default_unimap() or shares the default unicode
map from a previously initialized console (which increments its refcount).
If the subsequent kzalloc() for the screen buffer fails, the err_free path
frees the vc structure but leaves the attached uni_pagedict with an
elevated refcount. This results in an unreferenced object memory leak, as
the reference to the dictionary is lost and its refcount can never reach
zero.

This issue was discovered by DevGen (an automated virtual device modeling
fuzzer based on Syzkaller). During fuzzing with kernel fault injection
(failslab) enabled, the fuzzer forcefully failed the kzalloc() for the
screen buffer, exposing this error-handling path leak.

Fix this by checking *vc-&gt;uni_pagedict_loc and calling con_free_unimap(vc)
in the err_free path before kfree(vc). This safely decrements the refcount
and releases the dictionary memory if this was the last reference. The
explicit check is added to maintain consistency with other callers.

Fixes: 34902b7f2754 ("tty: vt, get rid of weird source code flow")
Cc: stable &lt;stable@kernel.org&gt;
Signed-off-by: Mingyu Wang &lt;25181214217@stu.xidian.edu.cn&gt;
Link: https://patch.msgid.link/20260803144556.163856-1-25181214217@stu.xidian.edu.cn
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
If the screen buffer allocation fails in vc_allocate(), the error handling
path jumps to `err_free`. However, this path fails to release the unicode
screen map attached to `vc-&gt;uni_pagedict_loc`.

During the early stages of vc_allocate(), the unicode screen map is either
newly allocated via con_set_default_unimap() or shares the default unicode
map from a previously initialized console (which increments its refcount).
If the subsequent kzalloc() for the screen buffer fails, the err_free path
frees the vc structure but leaves the attached uni_pagedict with an
elevated refcount. This results in an unreferenced object memory leak, as
the reference to the dictionary is lost and its refcount can never reach
zero.

This issue was discovered by DevGen (an automated virtual device modeling
fuzzer based on Syzkaller). During fuzzing with kernel fault injection
(failslab) enabled, the fuzzer forcefully failed the kzalloc() for the
screen buffer, exposing this error-handling path leak.

Fix this by checking *vc-&gt;uni_pagedict_loc and calling con_free_unimap(vc)
in the err_free path before kfree(vc). This safely decrements the refcount
and releases the dictionary memory if this was the last reference. The
explicit check is added to maintain consistency with other callers.

Fixes: 34902b7f2754 ("tty: vt, get rid of weird source code flow")
Cc: stable &lt;stable@kernel.org&gt;
Signed-off-by: Mingyu Wang &lt;25181214217@stu.xidian.edu.cn&gt;
Link: https://patch.msgid.link/20260803144556.163856-1-25181214217@stu.xidian.edu.cn
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge tag 'fbdev-for-7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/deller/linux-fbdev</title>
<updated>2026-09-12T15:06:04+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-09-12T15:06:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=31a4327ffe2d8cbd0f51a3af6a3ffc5ecd7fdbee'/>
<id>31a4327ffe2d8cbd0f51a3af6a3ffc5ecd7fdbee</id>
<content type='text'>
Pull fbdev fixes from Helge Deller:
 "Two patches for VT core code and fbcon prevent potential out-of-bounds
  reads on font or screen size changes, one fix limits the Superblitter
  in atafb to supported modes only, and some minor fixes for vfb,
  ssd1307fb and omapfb"

* tag 'fbdev-for-7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/deller/linux-fbdev:
  fbdev: vfb: defer cleanup until the last reference
  fbdev: atafb: Restrict SuperBlitter to supported formats
  fbdev: ssd1307fb: fix NULL pointer dereference on missing match data
  fbcon: Fix KASAN slab-out-of-bounds Read in fbcon_prepare_logo
  fbdev: omapfb: Fix __be32 sparse warning in panel_enabled()
  vt: hide cursor prior to font changes to avoid out-of-bound reads
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull fbdev fixes from Helge Deller:
 "Two patches for VT core code and fbcon prevent potential out-of-bounds
  reads on font or screen size changes, one fix limits the Superblitter
  in atafb to supported modes only, and some minor fixes for vfb,
  ssd1307fb and omapfb"

* tag 'fbdev-for-7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/deller/linux-fbdev:
  fbdev: vfb: defer cleanup until the last reference
  fbdev: atafb: Restrict SuperBlitter to supported formats
  fbdev: ssd1307fb: fix NULL pointer dereference on missing match data
  fbcon: Fix KASAN slab-out-of-bounds Read in fbcon_prepare_logo
  fbdev: omapfb: Fix __be32 sparse warning in panel_enabled()
  vt: hide cursor prior to font changes to avoid out-of-bound reads
</pre>
</div>
</content>
</entry>
<entry>
<title>treewide: refresh kmalloc_obj() conversions</title>
<updated>2026-09-05T04:37:00+00:00</updated>
<author>
<name>Kees Cook</name>
<email>kees+treewide@kernel.org</email>
</author>
<published>2026-09-02T22:31:14+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=3a2c4d55e32ad65efebdb6de44eef3bfa08bb49d'/>
<id>3a2c4d55e32ad65efebdb6de44eef3bfa08bb49d</id>
<content type='text'>
This is another run of the Coccinelle script for converting kmalloc()
family of allocations to kmalloc_obj() via the existing rules in
scripts/coccinelle/api/kmalloc_objs.cocci

This catches both the set of kmalloc() uses added since the first
kmalloc_obj() conversions in v7.0 and adds a large group missed in the
first pass due to Coccinelle not interacting well with the cleanup.h
scoped_...() family of macros[1]. I worked around this with spatch's
"--macro-file" argument to a file with all the scoped_...() macros mapped
to Coccinelle's YACFE_ITERATOR[2] as that was the closest viable control
flow indicator I could find.

Build tested allmodconfig on x86, arm64, arm, loongarch, mips, powerpc,
riscv, and s390 with no new warnings.

Link: https://lore.kernel.org/lkml/202609021314.8A9C0B8@keescook/ [1]
Link: https://github.com/coccinelle/coccinelle/blob/master/standard.h [2]
Signed-off-by: Kees Cook &lt;kees+treewide@kernel.org&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This is another run of the Coccinelle script for converting kmalloc()
family of allocations to kmalloc_obj() via the existing rules in
scripts/coccinelle/api/kmalloc_objs.cocci

This catches both the set of kmalloc() uses added since the first
kmalloc_obj() conversions in v7.0 and adds a large group missed in the
first pass due to Coccinelle not interacting well with the cleanup.h
scoped_...() family of macros[1]. I worked around this with spatch's
"--macro-file" argument to a file with all the scoped_...() macros mapped
to Coccinelle's YACFE_ITERATOR[2] as that was the closest viable control
flow indicator I could find.

Build tested allmodconfig on x86, arm64, arm, loongarch, mips, powerpc,
riscv, and s390 with no new warnings.

Link: https://lore.kernel.org/lkml/202609021314.8A9C0B8@keescook/ [1]
Link: https://github.com/coccinelle/coccinelle/blob/master/standard.h [2]
Signed-off-by: Kees Cook &lt;kees+treewide@kernel.org&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge tag 'tty-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty</title>
<updated>2026-08-25T17:59:12+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-08-25T17:59:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=70f5376dbdefa675adec0800e9f21f20a0dc0cbd'/>
<id>70f5376dbdefa675adec0800e9f21f20a0dc0cbd</id>
<content type='text'>
Pull TTY / serial driver updates from Greg KH:
 "Here is the "big" set of tty and serial driver updates for 7.3-rc1.

  Not really all that much happened this development cycle for this
  subsystem, changes in here are:

   - removal of the ipwireless driver as it's no longer used or needed

   - new 8250_mxpcie driver added

   - qcom serial driver updates and additions

   - vt mode validation addition

   - lots of other small serial driver updates and additions

  All of these have been in linux-next for weeks with no reported issues"

* tag 'tty-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty: (97 commits)
  serial: imx: serialize imx_uart_ports[] lifetime
  tty: clear cdev pointer after cdev_add() failure
  tty: skip cdev_del() when no cdev is registered
  serial: core: clear freed pointers on uart_register_driver() failure
  serial: core: do fallible allocations before the console can be registered
  serial: 8250_mxpcie: implement rx_trig_bytes callbacks via MUEx50 RTL
  serial: 8250_mxpcie: introduce per-port private data structure
  serial: 8250: allow UART drivers to override rx_trig_bytes handling
  serial: 8250_mxpcie: add break support for RS485 using MUEx50 features
  serial: 8250: allow low-level drivers to override break control
  serial: 8250_mxpcie: support serial interface mode switching
  serial: 8250_mxpcie: speed up TX using memory-mapped FIFO window
  serial: 8250_mxpcie: speed up RX using memory-mapped FIFO window
  serial: 8250_mxpcie: add custom handle_irq callback
  serial: 8250_mxpcie: offload XON/XOFF flow control to MUEx50 hardware
  serial: 8250_mxpcie: enable automatic RTS/CTS flow control
  serial: 8250_mxpcie: enable enhanced mode and program FIFO trigger levels
  serial: 8250: add Moxa MUEx50 UART port type
  serial: 8250: split Moxa PCIe serial board support out of 8250_pci
  serial: qcom-geni: Use geni_se_set_perf_level() for baud rate perf level
  ...
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull TTY / serial driver updates from Greg KH:
 "Here is the "big" set of tty and serial driver updates for 7.3-rc1.

  Not really all that much happened this development cycle for this
  subsystem, changes in here are:

   - removal of the ipwireless driver as it's no longer used or needed

   - new 8250_mxpcie driver added

   - qcom serial driver updates and additions

   - vt mode validation addition

   - lots of other small serial driver updates and additions

  All of these have been in linux-next for weeks with no reported issues"

* tag 'tty-7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty: (97 commits)
  serial: imx: serialize imx_uart_ports[] lifetime
  tty: clear cdev pointer after cdev_add() failure
  tty: skip cdev_del() when no cdev is registered
  serial: core: clear freed pointers on uart_register_driver() failure
  serial: core: do fallible allocations before the console can be registered
  serial: 8250_mxpcie: implement rx_trig_bytes callbacks via MUEx50 RTL
  serial: 8250_mxpcie: introduce per-port private data structure
  serial: 8250: allow UART drivers to override rx_trig_bytes handling
  serial: 8250_mxpcie: add break support for RS485 using MUEx50 features
  serial: 8250: allow low-level drivers to override break control
  serial: 8250_mxpcie: support serial interface mode switching
  serial: 8250_mxpcie: speed up TX using memory-mapped FIFO window
  serial: 8250_mxpcie: speed up RX using memory-mapped FIFO window
  serial: 8250_mxpcie: add custom handle_irq callback
  serial: 8250_mxpcie: offload XON/XOFF flow control to MUEx50 hardware
  serial: 8250_mxpcie: enable automatic RTS/CTS flow control
  serial: 8250_mxpcie: enable enhanced mode and program FIFO trigger levels
  serial: 8250: add Moxa MUEx50 UART port type
  serial: 8250: split Moxa PCIe serial board support out of 8250_pci
  serial: qcom-geni: Use geni_se_set_perf_level() for baud rate perf level
  ...
</pre>
</div>
</content>
</entry>
<entry>
<title>vt: hide cursor prior to font changes to avoid out-of-bound reads</title>
<updated>2026-08-22T07:33:45+00:00</updated>
<author>
<name>Helge Deller</name>
<email>deller@gmx.de</email>
</author>
<published>2026-08-21T08:01:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=3c0ebc4c07ff1147724d8f370203e62390ae7ee7'/>
<id>3c0ebc4c07ff1147724d8f370203e62390ae7ee7</id>
<content type='text'>
KASAN reports slab-out-of-bounds errors:
BUG: KASAN: slab-out-of-bounds in soft_cursor+0x3eb/0xb70 drivers/video/fbdev/core/softcursor.c:70

When changing the size of a sceen font, the amount of columns and rows
on a screen may change and thus the current position of the cursor and
the selection may suddenly lay outside of the current screen limits.

Clear the selection and hide the cursor before any font changes to avoid
such possible out of bounds accesses.

Reported-by: Jaeyoung Chung &lt;jjy600901@snu.ac.kr&gt;
Signed-off-by: Helge Deller &lt;deller@gmx.de&gt;
Link: https://lore.kernel.org/all/20260819163440.3702924-1-jjy600901@snu.ac.kr/
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
KASAN reports slab-out-of-bounds errors:
BUG: KASAN: slab-out-of-bounds in soft_cursor+0x3eb/0xb70 drivers/video/fbdev/core/softcursor.c:70

When changing the size of a sceen font, the amount of columns and rows
on a screen may change and thus the current position of the cursor and
the selection may suddenly lay outside of the current screen limits.

Clear the selection and hide the cursor before any font changes to avoid
such possible out of bounds accesses.

Reported-by: Jaeyoung Chung &lt;jjy600901@snu.ac.kr&gt;
Signed-off-by: Helge Deller &lt;deller@gmx.de&gt;
Link: https://lore.kernel.org/all/20260819163440.3702924-1-jjy600901@snu.ac.kr/
</pre>
</div>
</content>
</entry>
<entry>
<title>vt: add permission check for KDSKBMETA ioctl</title>
<updated>2026-08-03T14:31:14+00:00</updated>
<author>
<name>Joshua Rogers</name>
<email>linux@joshua.hu</email>
</author>
<published>2026-07-31T07:56:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=a7ad0034453ba4c353f9b8f810ee2569de33d283'/>
<id>a7ad0034453ba4c353f9b8f810ee2569de33d283</id>
<content type='text'>
KDSKBMETA modifies keyboard meta mode but lacks the !perm check that all
other keyboard setter ioctls in vt_k_ioctl() enforce, allowing a process
to change meta mode on a non-controlling console without authorization.

Assisted-by: AISLE:Snapshot
Cc: stable &lt;stable@kernel.org&gt;
Signed-off-by: Joshua Rogers &lt;linux@joshua.hu&gt;
Link: https://patch.msgid.link/20260731-tty-vt-stuff-v1-2-be99b9da8e30@linuxfoundation.org
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
KDSKBMETA modifies keyboard meta mode but lacks the !perm check that all
other keyboard setter ioctls in vt_k_ioctl() enforce, allowing a process
to change meta mode on a non-controlling console without authorization.

Assisted-by: AISLE:Snapshot
Cc: stable &lt;stable@kernel.org&gt;
Signed-off-by: Joshua Rogers &lt;linux@joshua.hu&gt;
Link: https://patch.msgid.link/20260731-tty-vt-stuff-v1-2-be99b9da8e30@linuxfoundation.org
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>vt: stabilize tty reference in kbd_keycode with tty_port_tty_get</title>
<updated>2026-08-03T14:31:12+00:00</updated>
<author>
<name>Joshua Rogers</name>
<email>linux@joshua.hu</email>
</author>
<published>2026-07-31T07:56:16+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=e25d47a526939ad44b75f778b8a7500562b84fc1'/>
<id>e25d47a526939ad44b75f778b8a7500562b84fc1</id>
<content type='text'>
kbd_keycode() reads vc-&gt;port.tty without acquiring a tty reference,
racing against con_shutdown() which clears port.tty under a different
lock. Use tty_port_tty_get()/tty_kref_put() to hold a proper reference
for the duration the tty pointer is needed.

Assisted-by: AISLE:Snapshot
Signed-off-by: Joshua Rogers &lt;linux@joshua.hu&gt;
Cc: stable &lt;stable@kernel.org&gt;
Link: https://patch.msgid.link/20260731-tty-vt-stuff-v1-1-be99b9da8e30@linuxfoundation.org
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
kbd_keycode() reads vc-&gt;port.tty without acquiring a tty reference,
racing against con_shutdown() which clears port.tty under a different
lock. Use tty_port_tty_get()/tty_kref_put() to hold a proper reference
for the duration the tty pointer is needed.

Assisted-by: AISLE:Snapshot
Signed-off-by: Joshua Rogers &lt;linux@joshua.hu&gt;
Cc: stable &lt;stable@kernel.org&gt;
Link: https://patch.msgid.link/20260731-tty-vt-stuff-v1-1-be99b9da8e30@linuxfoundation.org
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</pre>
</div>
</content>
</entry>
</feed>
