<feed xmlns='http://www.w3.org/2005/Atom'>
<title>vyos-build.git/scripts/package-build/linux-kernel/patches/kernel, branch current</title>
<subtitle>VyOS image build scripts (mirror of https://github.com/vyos/vyos-build.git)
</subtitle>
<id>https://git.amelek.net/vyos/vyos-build.git/atom?h=current</id>
<link rel='self' href='https://git.amelek.net/vyos/vyos-build.git/atom?h=current'/>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-build.git/'/>
<updated>2026-05-23T17:54:51+00:00</updated>
<entry>
<title>Kernel: T8919: Update Linux Kernel to 6.18.33</title>
<updated>2026-05-23T17:54:51+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-05-23T17:54:51+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-build.git/commit/?id=dc194b8f6275f55d812e316dcb55cd8f57056cf1'/>
<id>urn:sha1:dc194b8f6275f55d812e316dcb55cd8f57056cf1</id>
<content type='text'>
The Kernel 6.18.33 now has an upstream fix for the fragnesia vulnerability
</content>
</entry>
<entry>
<title>Kernel: T8871: Update Linux Kernel to 6.18.31</title>
<updated>2026-05-15T20:05:43+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-05-15T20:05:43+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-build.git/commit/?id=2d8bf69fb933b11ffc543121f9b0a9b461b6dc1e'/>
<id>urn:sha1:2d8bf69fb933b11ffc543121f9b0a9b461b6dc1e</id>
<content type='text'>
This fixes the LPE https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn
</content>
</entry>
<entry>
<title>kernel: T8871: add a patch for the ptrace vulnerability</title>
<updated>2026-05-15T10:41:06+00:00</updated>
<author>
<name>Daniil Baturin</name>
<email>daniil@baturin.org</email>
</author>
<published>2026-05-15T10:41:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-build.git/commit/?id=396f782580761804cbdcaf2589dbf378b55edfde'/>
<id>urn:sha1:396f782580761804cbdcaf2589dbf378b55edfde</id>
<content type='text'>
that allows unprivileged users to read files owned by any other user
</content>
</entry>
<entry>
<title>Kernel: T8864: add patch for "fragnesia" local privilege escalation</title>
<updated>2026-05-14T11:39:02+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-05-14T11:34:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-build.git/commit/?id=d2d23bb8cafb209fc4459adaf43748e304b84392'/>
<id>urn:sha1:d2d23bb8cafb209fc4459adaf43748e304b84392</id>
<content type='text'>
Fragnesia is a universal Linux local privilege escalation exploit, discovered
with V12 by William Bowling with the V12 team. Fragnesia is a member of the
Dirty Frag vulnerability class. This is a separate bug in the ESP/XFRM from
dirtyfrag which has received its own patch. However, it is in the same surface
and the mitigation is the same as for dirtyfrag.

It abuses a logic bug in the Linux XFRM ESP-in-TCP subsystem to achieve
arbitrary byte writes into the kernel page cache of read-only files, without
requiring any race condition.

The technique extends the page-cache write bug class that includes Dirty Pipe:
when a TCP socket transitions to espintcp ULP mode after data has already been
spliced from a file into the receive queue, the kernel processes the queued
file pages as ESP ciphertext. The AES-GCM keystream byte at counter block
position 2, byte 0 is XORed directly into the cached file page. By selecting
the IV nonce to produce a desired keystream byte, any target byte in the file
can be set to any value — one byte per trigger invocation.

From: https://github.com/v12-security/pocs/blob/532994fc003a7/fragnesia/README.md
</content>
</entry>
<entry>
<title>Kernel: T8147: upgrade to 6.18</title>
<updated>2026-05-03T18:35:31+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-05-02T18:21:00+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-build.git/commit/?id=739f904284ac4f96496cc9f3b080a5276a9b317c'/>
<id>urn:sha1:739f904284ac4f96496cc9f3b080a5276a9b317c</id>
<content type='text'>
* Forwared port all out-of-tree driver patches
* Add Intel QAT patch to make it compile for LInux 6.18
* Remove out-of-tree OpenVPN DCO module - now available upstream
</content>
</entry>
<entry>
<title>Kernel: T8147: drop out-of-tree INOTIFY_STACKFS patch</title>
<updated>2026-05-03T18:34:37+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-05-02T18:04:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-build.git/commit/?id=5a2c894fcabef4718d6f55b163fc0f250ecec5a0'/>
<id>urn:sha1:5a2c894fcabef4718d6f55b163fc0f250ecec5a0</id>
<content type='text'>
The inotify support for overlayfs is no longer needed. Native upstream support
landed in kernel 4.16 (commit 31747eda41ef/764baba80168 in 2018, which made
overlayfs hash inodes by their lower inode so fsnotify works on overlay mounts),
and kernel 6.8 (commit bc2473c90fca in 2023) extended it so fsnotify generates
events for operations on the real underlying files of an overlay.

The patch was an out-of-tree workaround that never went upstream and predates
these solutions.
</content>
</entry>
<entry>
<title>Kernel: T8427: Update Linux Kernel to 6.6.130</title>
<updated>2026-03-25T20:42:39+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-03-25T20:41:59+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-build.git/commit/?id=76d6e6204ef15fbab2ba1c5e40fb18802a67b178'/>
<id>urn:sha1:76d6e6204ef15fbab2ba1c5e40fb18802a67b178</id>
<content type='text'>
The custom patch "nft_ct: Added nfct_seqadj_ext_add() for DNAT'ed - conntrack."
is now available upstream in the Kernel tree.
</content>
</entry>
<entry>
<title>Kernel: T8345: Update Linux Kernel to 6.6.128</title>
<updated>2026-03-05T14:12:38+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-03-05T14:12:38+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-build.git/commit/?id=41dc49dc00e2f25864182ef56a630ccc4f578f43'/>
<id>urn:sha1:41dc49dc00e2f25864182ef56a630ccc4f578f43</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Kernel: T8203: update Linux Kernel to v6.6.121</title>
<updated>2026-01-24T06:07:22+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-01-24T06:00:40+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-build.git/commit/?id=b929786f031773756d99c28a1e468eacd8e3f6e7'/>
<id>urn:sha1:b929786f031773756d99c28a1e468eacd8e3f6e7</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Kernel: T8035: update Linux Kernel to v6.6.117</title>
<updated>2025-11-24T21:28:11+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2025-11-24T21:28:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-build.git/commit/?id=4bd00bd0e3535dd43a37c5be69a5548e946834b9'/>
<id>urn:sha1:4bd00bd0e3535dd43a37c5be69a5548e946834b9</id>
<content type='text'>
</content>
</entry>
</feed>
