Re: Requesting CVES to be merged into version 5.15.y
From: gregkh
Date: Sat Oct 10 2026 - 04:05:47 EST
On Sat, Oct 10, 2026 at 03:21:20PM +0800, yao.zhang1@xxxxxxxxxxx wrote:
> Hi stable team,
>
> While reviewing the CVE database against the 5.15.y series we run in
> production (currently 5.15.222), we found 27 security fixes that are
> already merged upstream / in newer stable series but are still missing
> from 5.15.y. Per Documentation/process/stable-kernel-rules.rst
> (Option 2), We would like to request that these commits be
> cherry-picked into 5.15.y.
>
> What is the plan for merging these CVEs into 5.15.y?
> When are they expected to be merged into 5.15.y?
Please feel free to submit these as tested patches that you know work to
these trees.
> Summary: 1 CRITICAL (CVSS 9.3), 21 HIGH, 5 unscored (kernel CVE team
> does not assign CVSS to all records). All commits below exist in
> mainline; none of them (nor an equivalent) is present in v5.15.y.
>
> Details, one entry per CVE (severity, CVE link, fix commit):
>
> * CVE-2022-49218 (CVSS 7.1 HIGH, CVE-2022-49218)
> commit a2151490cc6c57b368d7974ffd447a8b36ade639 upstream
> "drm/dp: Fix OOB read when handling Post Cursor2 register"
> already fixed in: 5.17.2, 5.18
Here's an example of why this is not in the 5.15.y tree, it does not
apply at all. How did you come up with this very small list of CVEs
when there are thousands of "missing" fixes in these older trees?
Have you tested this commit to verify it does work properly in the
5.15.y tree?
Again, if you wish to see these all applied, please submit the patches
that you have backported.
thanks,
greg k-h