This patchset is same as that for 6.12.y.
Backport of the CVE-2026-52991 fix.
1/2 (94a4acfec146) clear of->priv on release, turning the UAF into an
easier-to-detect NULL deref.
2/2 (a5b98009f16d, the CVE fix) extend cgroup_mutex to cover all
of->priv accesses, read ctx after taking the kn lock, and NULL-check
of->priv. It depends on 1/2 as discussed in [0].
[0] https://lore.kernel.org/all/8a06c5c3-8f7a-4252-a3b1-0c0d812e2654@oracle.com/
Chen Ridong (1):
cgroup/psi: Set of->priv to NULL upon file release
Edward Adam Davis (1):
sched/psi: fix race between file release and pressure write
kernel/cgroup/cgroup.c | 25 +++++++++++++++++--------
1 file changed, 17 insertions(+), 8 deletions(-)
--
2.47.3