Blog

Notes on Linux kernel bugs I have found and fixed. Dates are when the first version of each patch was posted to the mailing list.

When your touchpad lies to the kernel: fixing an ELAN0662 at 400 kHz

My own laptop's touchpad stuttered and dropped touches. The trail led from a libinput "Touch jump" warning, through a byte-level dissection of the ACPI DSDT, to a failed first fix (kernel OEM-revision rules), and finally a one-line upstream patch. Full detective story with every command and log line.

Fixing a use-after-free in Open vSwitch conntrack zone limits

Packet processing reads CT limit state under RCU while netns teardown frees it under a mutex — with no grace period in between. How an unprivileged user could turn that into a slab-use-after-free, and how the fix restructures the teardown.

An off-by-a-message offset in bpf_msg_push_data()

A one-character-class bug in the sockmap helper: a page-local fragment offset was advanced by a message-global insertion point. One line fixes it — finding that line was the hard part.

Rejecting duplicate cipher suites in wiphy_register()

Duplicate WEP entries in a wiphy description could overflow a fixed-size array in the WEXT compatibility code. The fix moves the invariant to where it belongs: registration time.

When decryption fails but parsing continues: an rxkad ticket bug

rxkad_decrypt_ticket() never checked whether crypto_skcipher_decrypt() succeeded, letting a malformed RESPONSE drive the ticket parser with attacker-controlled bytes.