Path: csiph.com!news.samoylyk.net!gothmog.csi.it!bofh.it!news.nic.it!robomod From: "Debian Bug Tracking System" Newsgroups: linux.debian.kernel Subject: Bug#1146105: marked as done ([PATCH] src:linux: CVE-2026-80725 backport for bookworm) Date: Sun, 30 Aug 2026 06:40:01 +0200 Message-ID: References: X-Mailbox-Line: From debian-kernel-request@lists.debian.org Sun Aug 30 04:37:23 2026 Old-Return-Path: X-Amavis-Spam-Status: No, score=-110.51 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, BODY_INCLUDES_PACKAGE=-5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FOURLA=0.1, LDO_WHITELIST=-5, MD5_SHA1_SUM=-1, RCVD_IN_DNSWL_NONE=-0.0001, USER_IN_DKIM_WELCOMELIST=-0.01, USER_IN_DKIM_WHITELIST=-100, YOURMESSAGEBOD=2.5] autolearn=ham autolearn_force=no MIME-Version: 1.0 X-Mailer: MIME-tools 5.510 (Entity 5.510) X-Debian-Pr-Message: closed 1146105 X-Debian-Pr-Package: src:linux X-Debian-Pr-Keywords: patch security X-Debian-Pr-Source: linux Reply-To: 1146105@bugs.debian.org Content-Type: multipart/mixed; boundary="----------=_1788064622-655162-0" X-Mailing-List: archive/latest/156968 List-ID: List-URL: List-Archive: https://lists.debian.org/msgid-search/handler.1146105.D1146105.1788064503654485.ackdone@bugs.debian.org Approved: robomod@news.nic.it Lines: 270 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Date: Sun, 30 Aug 2026 04:37:02 +0000 X-Original-Message-ID: X-Original-References: <20260829211445.111220-1-danielmaraboo@gmail.com> Xref: csiph.com linux.debian.kernel:93927 This is a multi-part message in MIME format... ------------=_1788064622-655162-0 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Your message dated Sun, 30 Aug 2026 06:34:57 +0200 with message-id and subject line Re: Bug#1146105: [PATCH] src:linux: CVE-2026-80725 backpor= t for bookworm has caused the Debian Bug report #1146105, regarding [PATCH] src:linux: CVE-2026-80725 backport for bookworm to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact owner@bugs.debian.org immediately.) --=20 1146105: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1146105 Debian Bug Tracking System Contact owner@bugs.debian.org with problems ------------=_1788064622-655162-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at submit) by bugs.debian.org; 29 Aug 2026 21:14:51 +0000 X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02 (2024-03-25) on buxtehude.debian.org X-Spam-Level: X-Spam-Status: No, score=-13.2 required=4.0 tests=BAYES_00, BODY_INCLUDES_PACKAGE,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU, DKIM_VALID_EF,FREEMAIL_FROM,HAS_PACKAGE,MD5_SHA1_SUM, RCVD_IN_DNSWL_NONE,RCVD_IN_SBLXBL,RCVD_IN_SBLXBL_CBL,SPF_HELO_NONE, SPF_PASS autolearn=ham autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02 X-Spam-Bayes: score:0.0000 Tokens: new, 108; hammy, 150; neutral, 65; spammy, 0. spammytokens: hammytokens:0.000-+--bookworm, 0.000-+--UD:kernel.org, 0.000-+--UD:security-tracker.debian.org, 0.000-+--securitytrackerdebianorg, 0.000-+--security-tracker.debian.org Return-path: Received: from mail-pl1-x630.google.com ([2607:f8b0:4864:20::630]:60455) by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_128_GCM:128) (Exim 4.96) (envelope-from ) id 1x0QO3-001igY-2e for submit@bugs.debian.org; Sat, 29 Aug 2026 21:14:51 +0000 Received: by mail-pl1-x630.google.com with SMTP id d9443c01a7336-2d8f265cbe6so5783055ad.0 for ; Sat, 29 Aug 2026 14:14:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788038090; x=1788642890; darn=bugs.debian.org; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=k7wkedtyPJsjlXzwZ3GPytf53p+BLHAc8/7T/iqkw8k=; b=dYnJR/BoelzJcwmJBiIff8ucz7mZWME8SrnJ/wbLWb86Gzgf1mOS6TUE/PTcFbarx+ FnxrCE3r2k6Hfw/NuSvINxDL+GLKiphi8eu45z6a3G2C7Lmvu+b+4tHfc2sdD8zoWkQ+ Gu9cSVnL6aVgJfJxV4gT59ze+lF5zpP1RKyPjaHf5AtI6P1p+tT5R1eH8icPz9UvxKVS UbDoOn0LakNRWnPd3Umt/72jrSSPI/9i6+8mhihAhryde29XhvOUlM1J2hswRmxoigpQ NehScETozUkWH65umLhB30kyw8o6YRmHtatXzFoUVN028/pK9ljmUNRNX4WOnvzQSF6B J1ow== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788038090; x=1788642890; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=k7wkedtyPJsjlXzwZ3GPytf53p+BLHAc8/7T/iqkw8k=; b=pQJziWv5DURgXWpc2unhE3O7JKD0lhsfxpOIXSxz/TDojhVhOCcj+e5JqjLoLErvxx qpDkTgzHtAy79RiTgLahCaQ/jTECIwZNSbXgd5hn70lYnn30dWlp+iLIVAb2gi0mZOkq 7J8NtJ9VoWBGQVYqZOs9Ey9IHFoir2zAnOzmXnKn5zOgzLoO/AnbIjtJnBbwqJuKuBGG fH7cn2L354GDrzzmfEUPExUqN59aJreHnm+ooQpJu14Z4yu6wVv1hZwp0cYysTX89Vfe zUcnfyqJscSlP/F7JwWCyidqE/oDQVtp4t7lOmeOphuLKpVJNNx84emkItnXhPvhmGSx qMfQ== X-Gm-Message-State: AFuF++nqsB+QugUyCJ5guMEJcWCrvUlcvFbUgpmPb7FZrr1+OaKBxout W5y+CD0gfA/5YI1LS3fggf2loQ9sR8Vdo/V58AZtVQXAAW0uCiTPb5eQ3kq2HlT9 X-Gm-Gg: AYBFou3QnxeNtp9zT0bvmerDSpe/J3coNjAqFQ4/0fLaKqfJOd0aHyaKSVfBbbpg3Wh MrLa62ZBmPi2Pzm4SfvjYIhYpzK9vCkhB4nXa1xd/Mx6jxF0QqCXd9xYkWT0Kdm8eM4IfIbEdsU 0z/E5Z8Y7tIFqyF4pGTRlvHWA1LxIGxe0gudGApAkRkDKSK9G3X5U0mQ3ke1XycApuxsJNyYObl lwpxeKFcHV4J6uPnuclDrAGL3VJEGXYqhF3VtS03cMn0mMLhs4GIxukxGluf+oFjwZKSe+h8odx 4zZahiSKt3U8cGQYkOlERCXt6zF7ptIqZefOdrFIQwyGz0psmJslD9Uew3Bq16kGDQTn9BOCWAH LJTj2PADk2aHwSJlqF7wssEVvHaDrG54tAUBNiJaeXvW8koa3vQ5clignmQuUi9yovGDwhC419J SbFugMuCwcDt/W0XbU1Uu/RIZodzAMj5ai0g3OcrAAOKBovUXQ/QGTlQLWX05uMmvG9Z3fZi0AE p7FTPndmUYmBw9A1W6LIpy0Ws481gCDtiaRiOPZTsps6qlJN93ZWEfKYJOWYwZwCToRd/TzLf/o oFXVjOiU1hzyMg== X-Received: by 2002:a17:903:3803:b0:2c8:2808:3ec9 with SMTP id d9443c01a7336-2d74df0328amr303109985ad.12.1788038089587; Sat, 29 Aug 2026 14:14:49 -0700 (PDT) Received: from penguin.bbrouter. ([200.218.229.14]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3286f552473sm20566442eec.0.2026.08.29.14.14.48 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 29 Aug 2026 14:14:49 -0700 (PDT) From: Daniel Pereira To: submit@bugs.debian.org Subject: [PATCH] src:linux: CVE-2026-80725 backport for bookworm Date: Sat, 29 Aug 2026 18:14:45 -0300 Message-ID: <20260829211445.111220-1-danielmaraboo@gmail.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Delivered-To: submit@bugs.debian.org Package: src:linux Version: 6.1.180-1 Severity: important Tags: patch security Dear Debian Kernel Team, I noticed that CVE-2026-80725 is currently vulnerable in Debian Bookworm (6.1.x), although it has been fixed in Sid and upstream. I have prepared and tested a backport of the upstream fix (commit 81be30c1f5f2bffda1f04c0efd0746af10b9643a) for the 6.1 kernel tree. --- From: Alice Mikityanska Date: Thu, 5 Feb 2026 15:39:16 +0200 Subject: net/ipv6: Drop HBH for BIG TCP on RX side Origin: upstream, https://git.kernel.org/linus/81be30c1f5f2bffda1f04c0efd0746af10b9643a Bug-Debian: https://security-tracker.debian.org/tracker/CVE-2026-80725 Description: Complementary to the previous commit, stop inserting HBH when building BIG TCP GRO SKBs. [ Daniel Pereira ] Backported to 6.1 by removing memmove in ip6_offload.c and adjusting iph->payload_len logic to match 6.1 context. Index: linux-6.1.176/net/core/gro.c =================================================================== --- linux-6.1.176.orig/net/core/gro.c +++ linux-6.1.176/net/core/gro.c @@ -182,7 +182,6 @@ int skb_gro_receive(struct sk_buff *p, s if (unlikely(p->len + len >= GRO_LEGACY_MAX_SIZE)) { if (p->protocol != htons(ETH_P_IPV6) || - skb_headroom(p) < sizeof(struct hop_jumbo_hdr) || ipv6_hdr(p)->nexthdr != IPPROTO_TCP || p->encapsulation) return -E2BIG; Index: linux-6.1.176/net/ipv6/ip6_offload.c =================================================================== --- linux-6.1.176.orig/net/ipv6/ip6_offload.c +++ linux-6.1.176/net/ipv6/ip6_offload.c @@ -350,34 +350,8 @@ INDIRECT_CALLABLE_SCOPE int ipv6_gro_com skb_set_inner_network_header(skb, nhoff); } - payload_len = skb->len - nhoff - sizeof(*iph); - if (unlikely(payload_len > IPV6_MAXPLEN)) { - struct hop_jumbo_hdr *hop_jumbo; - int hoplen = sizeof(*hop_jumbo); - - /* Move network header left */ - memmove(skb_mac_header(skb) - hoplen, skb_mac_header(skb), - skb->transport_header - skb->mac_header); - skb->data -= hoplen; - skb->len += hoplen; - skb->mac_header -= hoplen; - skb->network_header -= hoplen; - iph = (struct ipv6hdr *)(skb->data + nhoff); - hop_jumbo = (struct hop_jumbo_hdr *)(iph + 1); - - /* Build hop-by-hop options */ - hop_jumbo->nexthdr = iph->nexthdr; - hop_jumbo->hdrlen = 0; - hop_jumbo->tlv_type = IPV6_TLV_JUMBO; - hop_jumbo->tlv_len = 4; - hop_jumbo->jumbo_payload_len = htonl(payload_len + hoplen); - - iph->nexthdr = NEXTHDR_HOP; - iph->payload_len = 0; - } else { - iph = (struct ipv6hdr *)(skb->data + nhoff); - iph->payload_len = htons(payload_len); - } + iph = (struct ipv6hdr *)(skb->data + nhoff); + iph->payload_len = htons(skb->len - nhoff - sizeof(*iph)); nhoff += sizeof(*iph) + ipv6_exthdrs_len(iph, &ops); if (WARN_ON(!ops || !ops->callbacks.gro_complete)) ------------=_1788064622-655162-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at 1146105-done) by bugs.debian.org; 30 Aug 2026 04:35:03 +0000 X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02 (2024-03-25) on buxtehude.debian.org X-Spam-Level: X-Spam-Status: No, score=-111.1 required=4.0 tests=ALL_TRUSTED,BAYES_00, DKIMWL_WL_HIGH,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF, FOURLA,FROMDEVELOPER,HAS_BUG_NUMBER,MD5_SHA1_SUM,SPF_HELO_NONE, SPF_PASS,USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02 X-Spam-Bayes: score:0.0000 Tokens: new, 12; hammy, 138; neutral, 34; spammy, 0. spammytokens: hammytokens:0.000-+--Hx-spam-relays-external:sk:stravin, 0.000-+--H*RT:sk:stravin, 0.000-+--Hx-spam-relays-external:311, 0.000-+--H*RT:311, 0.000-+--H*RT:108 Return-path: Received: from stravinsky.debian.org ([2001:41b8:202:deb::311:108]:55376) by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from ) id 1x0XG3-002kEz-0r for 1146105-done@bugs.debian.org; Sun, 30 Aug 2026 04:35:03 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.stravinsky; h=X-Debian-User:In-Reply-To:Content-Type:MIME-Version: References:Message-ID:Subject:To:From:Date:Reply-To:Cc: Content-Transfer-Encoding:Content-ID:Content-Description; bh=vmPoQ4Z+R0CyHbKK4Ee+YyeJ8UY/2VEe/8rGjkDgips=; b=NZfc5pwqtOkgdQaHZSesHjzDZI pG8GwSjyiZy8RABlXJ1bg2ZLr4TdfgOmfzzAO4MSBkNHNjIwMR5IQlZ1iC99Epsha7lYQg9rWcr/3 8gEx0u4cqlG5NNUBCoJ1G6TUZxY1y8GMxm3+nn5eFVpkGEnW2KKlJF9OjUdTi4kmN2oAgCh80dGRH LV0rAeOvVe07GmDzLyFF6v6aDiy9m3FaSLO99aGzDeF8KL3aihg0ELlh7bGcCfzE4j7msZNMsJQVl QfbuHoxFovcdbg82l4sY63plI63AEx+CKLmRkO0iEH6S0mbxFE8R2lPYtkzQ6OjZ/c/8HWMWhfTD8 zuG+Hm9g==; Received: from authenticated-user by stravinsky.debian.org with esmtpsa (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from ) id 1x0XFy-000Tyj-1H; Sun, 30 Aug 2026 04:34:58 +0000 Received: by eldamar.lan (Postfix, from userid 1000) id 6E66EBE2DE0; Sun, 30 Aug 2026 06:34:57 +0200 (CEST) Date: Sun, 30 Aug 2026 06:34:57 +0200 From: Salvatore Bonaccorso To: Daniel Pereira , 1146105-done@bugs.debian.org Subject: Re: Bug#1146105: [PATCH] src:linux: CVE-2026-80725 backport for bookworm Message-ID: References: <20260829211445.111220-1-danielmaraboo@gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260829211445.111220-1-danielmaraboo@gmail.com> X-Debian-User: carnil Hi On Sat, Aug 29, 2026 at 06:14:45PM -0300, Daniel Pereira wrote: > Package: src:linux > Version: 6.1.180-1 > Severity: important > Tags: patch security > > Dear Debian Kernel Team, > > I noticed that CVE-2026-80725 is currently vulnerable in Debian > Bookworm (6.1.x), although it has been fixed in Sid and upstream. > I have prepared and tested a backport of the upstream fix (commit > 81be30c1f5f2bffda1f04c0efd0746af10b9643a) for the 6.1 kernel tree. Please do not fill bugs for CVEs in src:linux unless there is really need to, that just adds unnecessary overhead. In this case even the commit has already been backported upstream in 6.1.185 and is pending in the next upload. FWIW, when a backport is missing in a specific upstream stable series and you have mad a backport, submit it to the upstream stable list for inclusion and then it can be picked up in Debian as well. Regards, Salvatore ------------=_1788064622-655162-0--