You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CVE-2026-31431 fix in candidate ref refs/remotes/stable/linux-7.0.y
yes
CVE-2026-31431 fix in candidate ref refs/remotes/longterm/linux-6.18.y
yes
Known fixed floors for this gate include: 5.10.254+, 5.15.204+, 6.1.170+, 6.6.137+, 6.12.85+, 6.18.22+, 6.19.12+, and 7.0+.
For vulnerable 6.19.x bases, build-rpm.sh applies the repo backport when present. CVE-2026-43284 Dirty Frag ESP fixed floors include 5.10.255+, 5.15.205+, 6.1.171+, 6.6.138+, 6.12.87+, 6.18.28+, and 7.0.5+; the EOL 6.19.x lab line stays conservative and uses the repo backport. CVE-2026-43500 Dirty Frag RxRPC is tracked by Debian security but not public in NVD/CVE.org in the last linux-xr check; no kernel.org upstream fixed floor is recorded here yet, so supported bases rely on the repo RXKAD/RXGK backports.
Carry Apply Triage
Target
Ref
Status
Detail
base
HEAD
clean
2/2 patches apply in series order
upstream
refs/remotes/upstream/master
clean
2/2 patches apply in series order
linux-7.0.y
refs/remotes/stable/linux-7.0.y
clean
2/2 patches apply in series order
linux-6.18.y
refs/remotes/longterm/linux-6.18.y
clean
2/2 patches apply in series order
Stable Summary
Candidate ref: refs/remotes/stable/linux-7.0.y (5d83f95062a8), latest tag v7.0.6
Candidate ref: refs/remotes/longterm/linux-6.18.y (d31a849ff501), latest tag v6.18.29
Next Actions
Resolve any vulnerable, backport-missing, or unknown security build route before release work.
Inspect the upstream-only commit list for merge candidates or conflicts.
Check whether every patch in xr/patches/series still applies cleanly.
Build both generic and RT variants if the carry set is unchanged.
Promote only after named-host validation on honey and yoga.
linux-xr Weekly Cadence Report
HEAD(da85976ef503)Carry Set
0007-vesa-dsc-bpp.patchbigscreen-beyond-edid.patchUpstream Summary
refs/remotes/upstream/master(5d6919055dec)unavailable1f318b96cc84Recent Upstream Commits
5d6919055decLinux 7.1-rc3aa54b1d27fe0rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present3ac1a467e376bpf: Fix off-by-one boundary validation in arena direct-value accessbf6d507f7e3cxskmap: reject TX-only AF_XDP sockets512809bb8a37bpf: Don't run arg-tracking analysis twice on main subprog9ef40a09c5deMAINTAINERS: Add Aksh Garg as PCIe CADENCE reviewer78e115d806b0MAINTAINERS: Update Hans Zhang email for PCIe CIX Sky1bf5421b3d8d3MAINTAINERS: Update Marek Vasut email for PCIe R-Carf45a49a2380aPCI: Initialize temporary device in new_id_store()909f7bf9b080PCI: Update saved_config_space upon resource assignmentRecent Fork Commits
da85976ef503docs: mark xr11 release published (docs: mark xr11 release published #70)99a8dbac353ddocs: mark xr11 signed release queue (docs: mark xr11 signed release queue #68)860e16fb65e5docs: refresh CVE and xr11 statuse33d9c0959e1security: cover Dirty Frag RxRPC RXGK pathsaa54797c347csecurity: allow absent usercopy default symbold4b510794cd3config: keep firmware helper disabled on 6.1286e5417b8c4acarry: enforce zero-fuzz patch checks95b7b1ca1a2fsecurity: track Dirty Frag CVE floorsc6f7142cb2c3carry: make dsc patch apply to 6.122e6ba8a8a125security: enable dirtyfrag rxrpc route for 6.12Security Watch
6.19.5vulnerablecve-2026-31431-algif-aead.patchpresentrepo-backport-applied-by-builda664bf3d603din upstream refyes6.19.5vulnerabledirtyfrag-esp-shared-frag.patchpresentrepo-backport-applied-by-buildf4c50a4034e6in upstream refyes6.19.5vulnerabledirtyfrag-rxrpc-linearize.patchpresentdirtyfrag-rxrpc-rxgk-linearize.patchpresentrepo-backport-applied-by-buildrefs/remotes/stable/linux-7.0.yyesrefs/remotes/longterm/linux-6.18.yyesKnown fixed floors for this gate include:
5.10.254+,5.15.204+,6.1.170+,6.6.137+,6.12.85+,6.18.22+,6.19.12+, and7.0+.For vulnerable
6.19.xbases,build-rpm.shapplies the repo backport when present.CVE-2026-43284 Dirty Frag ESP fixed floors include
5.10.255+,5.15.205+,6.1.171+,6.6.138+,6.12.87+,6.18.28+, and7.0.5+; the EOL6.19.xlab line stays conservative and uses the repo backport.CVE-2026-43500 Dirty Frag RxRPC is tracked by Debian security but not public in NVD/CVE.org in the last linux-xr check; no kernel.org upstream fixed floor is recorded here yet, so supported bases rely on the repo RXKAD/RXGK backports.
Carry Apply Triage
HEADcleanrefs/remotes/upstream/mastercleanrefs/remotes/stable/linux-7.0.ycleanrefs/remotes/longterm/linux-6.18.ycleanStable Summary
refs/remotes/stable/linux-7.0.y(5d83f95062a8), latest tagv7.0.6refs/remotes/longterm/linux-6.18.y(d31a849ff501), latest tagv6.18.29Next Actions
vulnerable,backport-missing, orunknownsecurity build route before release work.xr/patches/seriesstill applies cleanly.honeyandyoga.