Notes on Linux kernel bugs I have found and fixed. Dates are when the first version of each patch was posted to the mailing list.
My own laptop's touchpad stuttered and dropped touches. The trail led from a libinput "Touch jump" warning, through a byte-level dissection of the ACPI DSDT, to a failed first fix (kernel OEM-revision rules), and finally a one-line upstream patch. Full detective story with every command and log line.
Packet processing reads CT limit state under RCU while netns teardown frees it under a mutex — with no grace period in between. How an unprivileged user could turn that into a slab-use-after-free, and how the fix restructures the teardown.
A one-character-class bug in the sockmap helper: a page-local fragment offset was advanced by a message-global insertion point. One line fixes it — finding that line was the hard part.
Duplicate WEP entries in a wiphy description could overflow a fixed-size array in the WEXT compatibility code. The fix moves the invariant to where it belongs: registration time.
rxkad_decrypt_ticket() never checked whether crypto_skcipher_decrypt() succeeded, letting a malformed RESPONSE drive the ticket parser with attacker-controlled bytes.