Skip to content

Commit 969097f

Browse files
Sync Collecting Fix Commits: Fri Sep 11 16:02:39 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent e754689 commit 969097f

7 files changed

Lines changed: 47 additions & 6 deletions

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 20 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,26 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-V36P-VV44-8QFG": {
5+
"cfbabc581694705b2380c49d4fb587f919554028": "Improve GHSA-v36p-vv44-8qfg"
6+
},
7+
"GHSA-MWQ5-V3W5-QR6V": {
8+
"083d271c4e283227db6416576ce80f90a2a5351f": "Improve GHSA-mwq5-v3w5-qr6v",
9+
"71dfac8fabfe606bf665528e8c15290280cfeb5f": "Improve GHSA-mwq5-v3w5-qr6v"
10+
},
11+
"GHSA-47M2-WP7J-P9VC": {
12+
"ea9f1fa52a3a6fdc14c4e5fcebd25d06464769d5": "Improve GHSA-47m2-wp7j-p9vc",
13+
"04ba504ff1a204d716cbd341f41cdb4a77ef28cf": "Improve GHSA-47m2-wp7j-p9vc"
14+
},
15+
"GHSA-W47M-JPV2-QFW5": {
16+
"517595c2eaac1270a272ce52b15d072b0d801e24": "Improve GHSA-w47m-jpv2-qfw5"
17+
},
18+
"GHSA-CP7G-R78M-CC2G": {
19+
"49aa6c1b1e1181f453e4cf9aa6892a7f23d1074a": "Publish GHSA-cp7g-r78m-cc2g"
20+
},
21+
"GHSA-Q873-4W8P-M645": {
22+
"5aebed84aebe3e1a8873e445da4c3cf9b95849c9": "Improve GHSA-q873-4w8p-m645"
23+
},
424
"GHSA-Q4WF-CMPG-8RHF": {
525
"32689229f09ef0d2ef68a9f9415b45512a22b1db": "Publish GHSA-q4wf-cmpg-8rhf"
626
},
@@ -1445,9 +1465,6 @@
14451465
"GHSA-PFMG-M2FV-V732": {
14461466
"b17707d977356935d32a5d9d665f67ee80969e82": "Publish Advisories\n\nGHSA-92px-7r7f-w562\nGHSA-jrwc-g36x-gqc7\nGHSA-pfmg-m2fv-v732"
14471467
},
1448-
"GHSA-47M2-WP7J-P9VC": {
1449-
"04ba504ff1a204d716cbd341f41cdb4a77ef28cf": "Improve GHSA-47m2-wp7j-p9vc"
1450-
},
14511468
"GHSA-53PF-4457-QG7G": {
14521469
"aa68f3b4c13f890e893747cf41cf76110ddadfff": "Publish Advisories\n\nGHSA-53pf-4457-qg7g\nGHSA-cq44-x9vf-fpqg"
14531470
},

data/fix-commits/james-project-2f162961.json

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,10 @@
11
{
22
"vcs_url": "https://github.com/apache/james-project",
33
"vulnerabilities": {
4+
"CVE-2025-67735": {
5+
"c93b1d6bf5eec138d1db38414ca43c5755097c6c": "[UPGRADE] Upgrade Netty 4.1.126.Final \u2192 4.1.132.Final (CVE-2025-67735)",
6+
"5d9f29746e5e9817d76214d4a709a4c9696750c8": "[UPGRADE] Upgrade Netty 4.1.126.Final \u2192 4.1.132.Final (CVE-2025-67735)"
7+
},
48
"CVE-2026-54475": {
59
"3480b6808e5fc5ed25f86a0a72c7fbe8178fd1d6": "[UPGRADE] activemq 6.2.6 -> 6.2.7 + arttemis 2.53.0 -> 2.55.0 to fix several CVEs\n\n - CVE-2026-54475: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination ownership takeover\n - CVE-2026-53917: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbounded memory allocation in OpenWire property unmarshalling\n - CVE-2026-53916: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec\n - CVE-2026-52760: Apache ActiveMQ, Apache ActiveMQ Web Console: Stored XSS via Unescaped values in ActiveMQ Web Console\n - CVE-2026-50750: Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire DoS following fix for CVE-2026-49270\n - CVE-2026-50734: Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire memory-allocation DoS during wire format negotiation\n - CVE-2026-49877: Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console\n - CVE-2026-49432: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length enables denial of service\n - CVE-2026-49434: Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConnector instantiates denied transports and a remote-properties broker",
610
"dbeadfa382dcb4001a4e3af996a9ea5ddbf9ae63": "[UPGRADE] activemq 6.2.6 -> 6.2.7 + arttemis 2.53.0 -> 2.55.0 to fix several CVEs\n\n - CVE-2026-54475: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination ownership takeover\n - CVE-2026-53917: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbounded memory allocation in OpenWire property unmarshalling\n - CVE-2026-53916: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec\n - CVE-2026-52760: Apache ActiveMQ, Apache ActiveMQ Web Console: Stored XSS via Unescaped values in ActiveMQ Web Console\n - CVE-2026-50750: Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire DoS following fix for CVE-2026-49270\n - CVE-2026-50734: Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire memory-allocation DoS during wire format negotiation\n - CVE-2026-49877: Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console\n - CVE-2026-49432: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length enables denial of service\n - CVE-2026-49434: Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConnector instantiates denied transports and a remote-properties broker"
@@ -44,9 +48,6 @@
4448
"CVE-2026-40914": {
4549
"dbaddeb365d76262cebbeddc03fed240de638ed1": "[UPGRADE] Artemis 2.52.0 -> 2.53.0 (CVE-2026-40914)"
4650
},
47-
"CVE-2025-67735": {
48-
"5d9f29746e5e9817d76214d4a709a4c9696750c8": "[UPGRADE] Upgrade Netty 4.1.126.Final \u2192 4.1.132.Final (CVE-2025-67735)"
49-
},
5051
"CVE-2026-41044": {
5152
"d8d6f8717fe3e409c20b771203010ea4f0bc0570": "[UPGRADE] activeMQ 6.2.4 -> 6.2.5 (CVE-2026-41044 CVE-2026-41043 CVE-2026-40466)"
5253
},

data/fix-commits/kubernetes-dd5bb6b7.json

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
{
22
"vcs_url": "https://github.com/kubernetes/kubernetes",
33
"vulnerabilities": {
4+
"CVE-2026-84445": {
5+
"bbd0a69d228a459fd069840c8fde86cd91e4c5fd": "Merge pull request #141976 from harshitgupta31415/codex/grpc-cve-2026-84445\n\ndeps: bump google.golang.org/grpc to v1.82.2"
6+
},
47
"CVE-2026-78662": {
58
"7abbc3e0709aa029b8209e2dae5b031f30ac5390": "Merge pull request #141886 from AboEl3iz/fix-cve-2026-78662\n\nupdate golang.org/x/crypto to v0.56.0"
69
},

data/fix-commits/lxd-ac1584d1.json

Lines changed: 5 additions & 0 deletions
Large diffs are not rendered by default.

data/fix-commits/qemu-0a8b25ef.json

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,12 @@
11
{
22
"vcs_url": "https://gitlab.com/qemu-project/qemu",
33
"vulnerabilities": {
4+
"CVE-2026-66899": {
5+
"fae2fdd161178eb78ea02c0e486c8e7eb9fb46ad": "virtio-balloon: fix free-page BH teardown on unrealize\n\nWhen a guest triggers PCIe hot-unplug while the free-page-hint BH\nis running on an IOThread, the BH will keep accessing\nvq->used_elems array when running it. Note that qemu_bh_delete\nmerely prevents new BHs from running, it does not wait\nfor already running ones to finish.\n\nWe need to wait for it to finish - do it like virtio scsi and\nrun a dummy oneshot AIO in the same context, and wait for it.\n\nBut there's a twist: BH could be blocked in qemu_cond_wait,\nthen AIO won't run.\n\nAdd a special reporting state FREE_PAGE_HINT_S_UNREALIZE to make BH exit\nimmediately.\n\nCc: David Hildenbrand <david@kernel.org>\nFixes: CVE-2026-66899\nResolves: https://gitlab.com/qemu-project/qemu/-/work_items/4079\nReported-by: mhun512 <mhun512@gmail.com>\nReviewed-by: David Hildenbrand <david@kernel.org>\nReviewed-by: Michael S. Tsirkin <mst@redhat.com>\nSigned-off-by: Michael S. Tsirkin <mst@redhat.com>\nMessage-ID: <0967d574d9ffe469edf5fc16da86237e54a69c34.1785327742.git.mst@redhat.com>"
6+
},
7+
"CVE-2026-66900": {
8+
"9ca7b8261eee82551674614ca09ef2cc0b8faf72": "hw/net/virtio-net: strip trailing padding when caching RSC segment\n\nWhen an RSC candidate packet has trailing padding bytes beyond the\ndeclared IP payload, virtio_net_rsc_cache_buf() copies the full wire\nsize into the coalescing buffer and sets seg->size to that value.\nThe bounds check in virtio_net_rsc_coalesce_data() uses the IP\nlength field (o_ip_len) which does not include the padding, so the\ncheck can pass while the subsequent memmove() overflows the buffer.\n\nFix this by computing the actual IP packet size from the IP header\nand using it for both the memcpy and seg->size, so that seg->size\nstays in sync with the IP length field. virtio_net_rsc_sanity_check4/6()\nguarantees that ip_size <= size.\n\nFixes: CVE-2026-66900\nFixes: 2974e916df87 (\"virtio-net: support RSC v4/v6 tcp traffic for Windows HCK\")\nCc: qemu-stable@nongnu.org\nCc: Yuri Benditovich <ybendito@redhat.com>\nResolves: https://gitlab.com/qemu-project/qemu/-/issues/3879\nReported-by: Sven <bestswngs@gmail.com>\nSigned-off-by: Laurent Vivier <lvivier@redhat.com>\nReviewed-by: Michael S. Tsirkin <mst@redhat.com>\nSigned-off-by: Michael S. Tsirkin <mst@redhat.com>\nMessage-ID: <20260728082311.4179910-1-lvivier@redhat.com>"
9+
},
410
"CVE-2026-66020": {
511
"5bf61eef114add377890fef01a5ed55de554241d": "Merge tag 'virtio-gpu-pr-v2' of https://gitlab.com/marcandre.lureau/qemu into staging\n\nVarious virtio-gpu/dmabuf related fixes\n\nWhile working on CVE-2026-66020 (which had a few revision on list), I\nkept finding several places where virtio-gpu scanout and dmabuf\nownership was unclear.\n\nThe CVE comes from using a blob after RESOURCE_DETACH_BACKING has\nunmapped its memory. Following that path also found stale dmabuf\nreferences, duplicated scanout bookkeeping, and inconsistent cleanup\nbetween display backends.\n\nThose changes touch a lot of area and I have done basic testing with the\nvarious backends. I would not recommend backporting them all to stable.\nThe first 2 patches address CVE-2026-66020 in the general case and\nshould be safe to backport.\n\n# -----BEGIN PGP SIGNATURE-----\n#\n# iQIzBAABCgAdFiEEh6m9kz+HxgbSdvYt2ujhCXWWnOUFAmqi0+8ACgkQ2ujhCXWW\n# nOVihA/+P9OvMzadaVVLXzML6uK+tHJfKiX6kFICIzXMYmVPyFO3ociPKS0n8645\n# CpaYNZc+xqXbtFtxXkzXW7Lg7dYkfYRKFS7IhgN7mSPo/f3+d3p/rMOsrraXZd8y\n# UnpDaEnheA9KWBmNHizVUv83PCsrCo19NkBnB13tcoc7Yiy+xE8/P20ohoxc+KDX\n# cchpy31x2ccqAv3P3gaclvlclsj4UaiNPT71oTbm1fZnfsGVWKdxnAxTY6mmtEC5\n# kP0MmK41wOUcxM9u/1qw95YVRYc7Fhdlxbf9ZaOli9mVFzGYC1LCCDu9xTxaIE6+\n# w0AXe1NVIdt9FpuraoOovsdFiF2NU8U6+kTVMOkSO8qP2UtIyvfbk65pCQOjClNr\n# S9fhS4+Gkx1dIjJASLfyd3Ej222safwmBHBrY9KgCZ8o439gQMjIgD9pUoS21Nak\n# j5H6eQ3YHCZcoSClQCPH+wl3elundraZO38wuME+3a4EcrFN3bFxOThws3Ns2Bf3\n# MlA73vZLHOC22x/RR3M4rxzoPKEKArBIQaHQXO8wqfsTABImPzGRYyjfXGRqGDEK\n# atBYTR++tS7lG8EM9a+IW482D4/tVCkvwMjA5G6+dyx7bUdJ3bhj854yce7wSI8u\n# PeUoP5QzqAxy4xRvWLWhRJIJiFzhK7Ag/BrzN7cTnefIa5L6mNQ=\n# =3aXk\n# -----END PGP SIGNATURE-----\n# gpg: Signature made Thu 10 Sep 2026 05:59:43 AM HST\n# gpg: using RSA key 87A9BD933F87C606D276F62DDAE8E10975969CE5\n# gpg: Good signature from \"Marc-Andr\u00e9 Lureau <marcandre.lureau@redhat.com>\" [unknown]\n# gpg: aka \"Marc-Andr\u00e9 Lureau <marcandre.lureau@gmail.com>\" [unknown]\n# gpg: WARNING: This key is not certified with a trusted signature!\n# gpg: There is no indication that the signature belongs to the owner.\n# Primary key fingerprint: 87A9 BD93 3F87 C606 D276 F62D DAE8 E109 7596 9CE5\n\n* tag 'virtio-gpu-pr-v2' of https://gitlab.com/marcandre.lureau/qemu: (24 commits)\n contrib/vhost-user-gpu: disable scanouts on resource unref\n virtio-gpu: extract virtio_gpu_disable_scanout_for_resource helper\n virtio-gpu/virgl: disable scanouts on resource unref\n virtio-gpu: minor refactoring\n virtio-gpu: consolidate disabling scanout\n virtio-gpu/virgl: release dmabuf when a texture replaces a scanout\n virtio-gpu: release dmabuf when switching to a surface\n virtio-gpu: drop scanout_bitmask bookkeeping\n virtio-gpu-rutabaga: fix scanout handling\n contrib/vhost-user-gpu: drop scanout_bitmask bookkeeping\n virtio-gpu: release the dmabuf when a scanout is disabled\n ui: make GL context current in display backend callbacks\n ui/dmabuf: own and close fds on free\n ui/sdl2: clear guest_fb.dmabuf on release\n ui/console: disable GL scanout when dmabuf is the active one\n virtio-gpu: store the scanout DMABUF in virtio_gpu_scanout\n ui/dbus: disable scanout iff dmabuf is current\n ui/gtk: move draw_submitted from QemuDmaBuf to VirtualGfxConsole\n ui/gtk: move GL fence tracking from QemuDmaBuf to VirtualGfxConsole\n hw/display/virtio-gpu: set share_handle for udmabuf blob resources\n ...\n\nSigned-off-by: Richard Henderson <richard.henderson@linaro.org>",
612
"3ece85b53c124142c7d5cbb1165d4da125b7c369": "virtio-gpu: disable blob scanouts on mapping cleanup\n\nWhen a blob resource backing is cleaned up (for ex via detach_backing),\nany scanouts referencing it must be disabled first to prevent the\ndmabuf from outliving its backing memory.\n\nFixes: CVE-2026-66020\nFixes: 32db3c63ae11 (\"virtio-gpu: Add virtio_gpu_set_scanout_blob\")\nReported-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>\nReviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>\nSigned-off-by: Marc-Andr\u00e9 Lureau <marcandre.lureau@redhat.com>"

data/fix-commits/qemu-11410379.json

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,12 @@
11
{
22
"vcs_url": "https://github.com/qemu/qemu",
33
"vulnerabilities": {
4+
"CVE-2026-66899": {
5+
"fae2fdd161178eb78ea02c0e486c8e7eb9fb46ad": "virtio-balloon: fix free-page BH teardown on unrealize\n\nWhen a guest triggers PCIe hot-unplug while the free-page-hint BH\nis running on an IOThread, the BH will keep accessing\nvq->used_elems array when running it. Note that qemu_bh_delete\nmerely prevents new BHs from running, it does not wait\nfor already running ones to finish.\n\nWe need to wait for it to finish - do it like virtio scsi and\nrun a dummy oneshot AIO in the same context, and wait for it.\n\nBut there's a twist: BH could be blocked in qemu_cond_wait,\nthen AIO won't run.\n\nAdd a special reporting state FREE_PAGE_HINT_S_UNREALIZE to make BH exit\nimmediately.\n\nCc: David Hildenbrand <david@kernel.org>\nFixes: CVE-2026-66899\nResolves: https://gitlab.com/qemu-project/qemu/-/work_items/4079\nReported-by: mhun512 <mhun512@gmail.com>\nReviewed-by: David Hildenbrand <david@kernel.org>\nReviewed-by: Michael S. Tsirkin <mst@redhat.com>\nSigned-off-by: Michael S. Tsirkin <mst@redhat.com>\nMessage-ID: <0967d574d9ffe469edf5fc16da86237e54a69c34.1785327742.git.mst@redhat.com>"
6+
},
7+
"CVE-2026-66900": {
8+
"9ca7b8261eee82551674614ca09ef2cc0b8faf72": "hw/net/virtio-net: strip trailing padding when caching RSC segment\n\nWhen an RSC candidate packet has trailing padding bytes beyond the\ndeclared IP payload, virtio_net_rsc_cache_buf() copies the full wire\nsize into the coalescing buffer and sets seg->size to that value.\nThe bounds check in virtio_net_rsc_coalesce_data() uses the IP\nlength field (o_ip_len) which does not include the padding, so the\ncheck can pass while the subsequent memmove() overflows the buffer.\n\nFix this by computing the actual IP packet size from the IP header\nand using it for both the memcpy and seg->size, so that seg->size\nstays in sync with the IP length field. virtio_net_rsc_sanity_check4/6()\nguarantees that ip_size <= size.\n\nFixes: CVE-2026-66900\nFixes: 2974e916df87 (\"virtio-net: support RSC v4/v6 tcp traffic for Windows HCK\")\nCc: qemu-stable@nongnu.org\nCc: Yuri Benditovich <ybendito@redhat.com>\nResolves: https://gitlab.com/qemu-project/qemu/-/issues/3879\nReported-by: Sven <bestswngs@gmail.com>\nSigned-off-by: Laurent Vivier <lvivier@redhat.com>\nReviewed-by: Michael S. Tsirkin <mst@redhat.com>\nSigned-off-by: Michael S. Tsirkin <mst@redhat.com>\nMessage-ID: <20260728082311.4179910-1-lvivier@redhat.com>"
9+
},
410
"CVE-2026-66020": {
511
"5bf61eef114add377890fef01a5ed55de554241d": "Merge tag 'virtio-gpu-pr-v2' of https://gitlab.com/marcandre.lureau/qemu into staging\n\nVarious virtio-gpu/dmabuf related fixes\n\nWhile working on CVE-2026-66020 (which had a few revision on list), I\nkept finding several places where virtio-gpu scanout and dmabuf\nownership was unclear.\n\nThe CVE comes from using a blob after RESOURCE_DETACH_BACKING has\nunmapped its memory. Following that path also found stale dmabuf\nreferences, duplicated scanout bookkeeping, and inconsistent cleanup\nbetween display backends.\n\nThose changes touch a lot of area and I have done basic testing with the\nvarious backends. I would not recommend backporting them all to stable.\nThe first 2 patches address CVE-2026-66020 in the general case and\nshould be safe to backport.\n\n# -----BEGIN PGP SIGNATURE-----\n#\n# iQIzBAABCgAdFiEEh6m9kz+HxgbSdvYt2ujhCXWWnOUFAmqi0+8ACgkQ2ujhCXWW\n# nOVihA/+P9OvMzadaVVLXzML6uK+tHJfKiX6kFICIzXMYmVPyFO3ociPKS0n8645\n# CpaYNZc+xqXbtFtxXkzXW7Lg7dYkfYRKFS7IhgN7mSPo/f3+d3p/rMOsrraXZd8y\n# UnpDaEnheA9KWBmNHizVUv83PCsrCo19NkBnB13tcoc7Yiy+xE8/P20ohoxc+KDX\n# cchpy31x2ccqAv3P3gaclvlclsj4UaiNPT71oTbm1fZnfsGVWKdxnAxTY6mmtEC5\n# kP0MmK41wOUcxM9u/1qw95YVRYc7Fhdlxbf9ZaOli9mVFzGYC1LCCDu9xTxaIE6+\n# w0AXe1NVIdt9FpuraoOovsdFiF2NU8U6+kTVMOkSO8qP2UtIyvfbk65pCQOjClNr\n# S9fhS4+Gkx1dIjJASLfyd3Ej222safwmBHBrY9KgCZ8o439gQMjIgD9pUoS21Nak\n# j5H6eQ3YHCZcoSClQCPH+wl3elundraZO38wuME+3a4EcrFN3bFxOThws3Ns2Bf3\n# MlA73vZLHOC22x/RR3M4rxzoPKEKArBIQaHQXO8wqfsTABImPzGRYyjfXGRqGDEK\n# atBYTR++tS7lG8EM9a+IW482D4/tVCkvwMjA5G6+dyx7bUdJ3bhj854yce7wSI8u\n# PeUoP5QzqAxy4xRvWLWhRJIJiFzhK7Ag/BrzN7cTnefIa5L6mNQ=\n# =3aXk\n# -----END PGP SIGNATURE-----\n# gpg: Signature made Thu 10 Sep 2026 05:59:43 AM HST\n# gpg: using RSA key 87A9BD933F87C606D276F62DDAE8E10975969CE5\n# gpg: Good signature from \"Marc-Andr\u00e9 Lureau <marcandre.lureau@redhat.com>\" [unknown]\n# gpg: aka \"Marc-Andr\u00e9 Lureau <marcandre.lureau@gmail.com>\" [unknown]\n# gpg: WARNING: This key is not certified with a trusted signature!\n# gpg: There is no indication that the signature belongs to the owner.\n# Primary key fingerprint: 87A9 BD93 3F87 C606 D276 F62D DAE8 E109 7596 9CE5\n\n* tag 'virtio-gpu-pr-v2' of https://gitlab.com/marcandre.lureau/qemu: (24 commits)\n contrib/vhost-user-gpu: disable scanouts on resource unref\n virtio-gpu: extract virtio_gpu_disable_scanout_for_resource helper\n virtio-gpu/virgl: disable scanouts on resource unref\n virtio-gpu: minor refactoring\n virtio-gpu: consolidate disabling scanout\n virtio-gpu/virgl: release dmabuf when a texture replaces a scanout\n virtio-gpu: release dmabuf when switching to a surface\n virtio-gpu: drop scanout_bitmask bookkeeping\n virtio-gpu-rutabaga: fix scanout handling\n contrib/vhost-user-gpu: drop scanout_bitmask bookkeeping\n virtio-gpu: release the dmabuf when a scanout is disabled\n ui: make GL context current in display backend callbacks\n ui/dmabuf: own and close fds on free\n ui/sdl2: clear guest_fb.dmabuf on release\n ui/console: disable GL scanout when dmabuf is the active one\n virtio-gpu: store the scanout DMABUF in virtio_gpu_scanout\n ui/dbus: disable scanout iff dmabuf is current\n ui/gtk: move draw_submitted from QemuDmaBuf to VirtualGfxConsole\n ui/gtk: move GL fence tracking from QemuDmaBuf to VirtualGfxConsole\n hw/display/virtio-gpu: set share_handle for udmabuf blob resources\n ...\n\nSigned-off-by: Richard Henderson <richard.henderson@linaro.org>",
612
"3ece85b53c124142c7d5cbb1165d4da125b7c369": "virtio-gpu: disable blob scanouts on mapping cleanup\n\nWhen a blob resource backing is cleaned up (for ex via detach_backing),\nany scanouts referencing it must be disabled first to prevent the\ndmabuf from outliving its backing memory.\n\nFixes: CVE-2026-66020\nFixes: 32db3c63ae11 (\"virtio-gpu: Add virtio_gpu_set_scanout_blob\")\nReported-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>\nReviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>\nSigned-off-by: Marc-Andr\u00e9 Lureau <marcandre.lureau@redhat.com>"

0 commit comments

Comments
 (0)