[ubuntu/jammy-proposed] linux-kvm 5.15.0-1104.109 (Accepted)

Andy Whitcroft apw at canonical.com
Thu Jul 2 08:13:55 UTC 2026


linux-kvm (5.15.0-1104.109) jammy; urgency=medium

  * jammy/linux-kvm: 5.15.0-1104.109 -proposed tracker (LP: #2157390)

  * Packaging resync (LP: #1786013)
    - [Packaging] resync retpoline extraction

  [ Ubuntu: 5.15.0-186.196 ]

  * jammy/linux: 5.15.0-186.196 -proposed tracker (LP: #2157405)
  * [Jammy] Priority inversion problem in epoll for rt kernel (LP: #2154194)
    - eventpoll: Replace rwlock with spinlock
  * CVE-2026-46137
    - mptcp: pm: ADD_ADDR rtx: fix potential data-race
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901)
    - Linux 5.15.208
    - ALSA: asihpi: avoid write overflow check warning
    - can: mcp251x: add error handling for power enable in open and resume
    - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx
    - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list
    - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex
    - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW
      debouncer)
    - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3
    - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585
    - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J
    - soc: aspeed: socinfo: Mask table entries for accurate SoC ID matching
    - arm64: dts: imx8mq: Set the correct gpu_ahb clock frequency
    - PCI: hv: Set default NUMA node to 0 for devices without affinity info
    - drm/vc4: Protect madv read in vc4_gem_object_mmap() with madv_lock
    - epoll: use refcount to reduce ep_mutex contention
    - tracing/probe: reject non-closed empty immediate strings
    - e1000: check return value of e1000_read_eeprom
    - gpio: tegra: fix irq_release_resources calling enable instead of disable
    - i3c: fix uninitialized variable use in i2c setup
    - MIPS: mm: kmalloc tlb_vpn array to avoid stack overflow
    - mips: mm: Allocate tlb_vpn array atomically
    - MIPS: Always record SEGBITS in cpu_data.vmbits
    - MIPS: mm: Suppress TLB uniquification on EHINV hardware
    - MIPS: mm: Rewrite TLB uniquification for the hidden bit feature
    - ALSA: usb-audio: Update for native DSD support quirks
    - usb: storage: Expand range of matched versions for VL817 quirks entry
    - USB: serial: option: add Telit Cinterion FN990A MBIM composition
    - fsl-mc: Use driver_set_override() instead of open-coding
    - checkpatch: add support for Assisted-by tag
    - gfs2: Improve gfs2_consist_inode() usage
    - PCI/ACPI: Restrict program_hpx_type2() to AER bits
    - netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR
    - powerpc64/bpf: do not increment tailcall count when prog is NULL
    - arm64: dts: imx8mq-librem5: Set the DVS voltages lower
    - arm64: dts: imx8mq-librem5: Bump BUCK1 suspend voltage to 0.81V
    - Revert "arm64: dts: imx8mq-librem5: Set the DVS voltages lower"
    - arm64: dts: imx8mq-librem5: Bump BUCK1 suspend voltage up to 0.85V
    - ocfs2: add inline inode consistency check to
      ocfs2_validate_inode_block()
    - rxrpc: Fix key quota calculation for multitoken keys
    - fs/ocfs2: fix comments mentioning i_mutex
    - MPTCP: fix lock class name family in pm_nl_create_listen_socket
    - Revert "nvme: nvme-fc: Ensure ->ioerr_work is cancelled in
      nvme_fc_delete_ctrl()"
    - nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()
    - s390/xor: Fix xor_xc_2() inline assembly constraints
    - net: add skb_header_pointer_careful() helper
    - x86/uprobes: Fix XOL allocation failure for 32-bit tasks
    - iio: imu: inv_icm42600: fix odr switch when turning buffer off
    - vdpa: Add max vqp attr to vdpa_nl_policy for nlattr length check
    - net: usb: lan78xx: Fix double free issue with interrupt buffer
      allocation
    - SAUCE: Revert "fs/ntfs3: Fixed overflow check in mi_enum_attr()"
    - SAUCE: Revert "fs/ntfs3: Sequential field availability check in
      mi_enum_attr()"
    - SAUCE: Revert "ntfs3: Add bounds checking to mi_enum_attr()"
    - cpufreq: governor: Free dbs_data directly when gov->init() fails
    - scripts/dtc: Remove unused dts_version in dtc-lexer.l
    - rxrpc: Fix anonymous key handling
    - iommu: fix a reference count leak in iommu_sva_bind_device()
    - fuse: quiet down complaints in fuse_conn_limit_write
    - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu
    - tty: n_gsm: fix flow control handling in tx path
    - ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free
    - ALSA: usb-audio: Avoid false E-MU sample-rate notifications
    - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch
    - usb: xhci: Make usb_host_endpoint.hcpriv survive endpoint_disable()
    - ALSA: usb-audio: Evaluate packsize caps at the right place
    - firmware: google: framebuffer: Do not mark framebuffer as busy
    - device property: Make modifications of fwnode "flags" thread safe
    - driver core: Don't let a device probe until it's ready
    - um: drivers: call kernel_strrchr() explicitly in cow_user.c
    - Revert "ALSA: usb: Increase volume range that triggers a warning"
    - lib/ts_kmp: fix integer overflow in pattern length calculation
    - media: i2c: imx219: Check return value of devm_gpiod_get_optional() in
      imx219_probe()
    - ALSA: aoa: i2sbus: fix OF node lifetime handling
    - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes
    - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4
    - parisc: _llseek syscall is only available for 32-bit userspace
    - selftests/mqueue: Fix incorrectly named file
    - ALSA: caiaq: Fix control_put() result and cache rollback
    - ALSA: 6fire: Fix input volume change detection
    - iio: adc: ad7768-1: fix one-shot mode data acquisition
    - drm/arcpgu: fix device node leak
    - tpm: avoid -Wunused-but-set-variable
    - power: supply: axp288_charger: Do not cancel work before initializing it
    - mmc: block: use single block write in retry
    - tpm: tpm_tis: add error logging for data transfer
    - rtc: ntxec: fix OF node reference imbalance
    - userfaultfd: allow registration of ranges below mmap_min_addr
    - KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state
    - KVM: SVM: Explicitly mark vmcb01 dirty after modifying VMCB intercepts
    - KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode
    - KVM: nSVM: Always inject a #GP if mapping VMCB12 fails on nested VMRUN
    - KVM: nSVM: Clear GIF on nested #VMEXIT(INVALID)
    - KVM: nSVM: Add missing consistency check for nCR3 validity
    - io_uring/poll: fix EPOLL_URING_WAKE sometimes not being honored
    - io_uring/poll: fix backport of io_poll_add() changes
    - mtd: docg3: Convert to platform remove callback returning void
    - taskstats: set version in TGID exit notifications
    - crypto: arm64/aes - Fix 32-bit aes_mac_update() arg treated as 64-bit
    - crypto: atmel-ecc - Release client on allocation failure
    - crypto: hisilicon - Fix dma_unmap_single() direction
    - IB/core: Fix zero dmac race in neighbor resolution
    - ktest: Fix the month in the name of the failure directory
    - seg6: fix seg6 lwtunnel output redirect for L2 reduced encap mode
    - driver core: Add kernel-doc for DEV_FLAG_COUNT enum value
    - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path
    - ALSA: caiaq: Don't abort when no input device is available
    - drm/amdgpu: fix zero-size GDS range init on RDNA4
    - ALSA: caiaq: fix usb_dev refcount leak on probe failure
    - ACPI: scan: Use acpi_dev_put() in object add error paths
    - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug
    - ACPI: video: force native backlight on HP OMEN 16 (8A44)
    - spi: rockchip: fix controller deregistration
    - um: virt-pci: Fix build failure
    - ipmi:ssif: Fix a shutdown race
    - ipmi:ssif: Remove unnecessary indention
    - ipmi:ssif: NULL thread on error
    - ALSA: usb-audio: Fix UAC3 cluster descriptor size check
    - USB: omap_udc: DMA: Don't enable burst 4 mode
    - USB: serial: option: add Telit Cinterion LE910Cx compositions
    - usb: ulpi: fix memory leak on ulpi_register() error paths
    - ALSA: firewire-tascam: Do not drop unread control events
    - xfrm: provide message size for XFRM_MSG_MAPPING
    - spi: zynqmp-gqspi: fix controller deregistration
    - parisc: Fix IRQ leak in LASI driver
    - hwmon: (ltc2992) Clamp threshold writes to hardware range
    - hwmon: (ltc2992) Fix u32 overflow in power read path
    - hwmon: (corsair-psu) Close HID device on probe errors
    - extcon: ptn5150: handle pending IRQ events during system resume
    - hv_sock: fix ARM64 support
    - udf: reject descriptors with oversized CRC length
    - thermal/drivers/sprd: Fix temperature clamping in
      sprd_thm_temp_to_rawdata
    - thermal/drivers/sprd: Fix raw temperature clamping in
      sprd_thm_rawdata_to_temp
    - cpuidle: powerpc: avoid double clear when breaking snooze
    - ASoC: fsl_easrc: fix comment typo
    - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error
    - dm: don't report warning when doing deferred remove
    - dm-verity-fec: correctly reject too-small FEC devices
    - dm-verity-fec: correctly reject too-small hash devices
    - s390/debug: Reject zero-length input in debug_input_flush_fn()
    - PCI/AER: Clear only error bits in PCIe Device Status
    - PCI/AER: Stop ruling out unbound devices as error source
    - power: supply: max17042: avoid overflow when determining health
    - mptcp: use MPJoinSynAckHMacFailure for SynAck HMAC failure
    - mptcp: use MPTCP_RST_EMPTCP for ACK HMAC validation failure
    - mptcp: sockopt: set timestamp flags on subflow socket, not msk
    - platform/x86: hp-wmi: Ignore backlight and FnLock events
    - media: uvcvideo: Enable VB2_DMABUF for metadata stream
    - media: i2c: ov8856: free control handler on error in
      ov8856_init_controls()
    - regulator: max77650: fix OF node reference imbalance
    - media: rc: streamzap: Error handling in probe
    - regulator: act8945a: fix OF node reference imbalance
    - regulator: bd9571mwv: fix OF node reference imbalance
    - media: dib8000: avoid division by 0 in dib8000_set_dds()
    - media: i2c: imx412: Assert reset GPIO during probe
    - spi: mtk-nor: fix controller deregistration
    - spi: imx: fix runtime pm leak on probe deferral
    - spi: orion: fix clock imbalance on registration failure
    - drm/radeon: add missing revision check for CI
    - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ
    - drm/amdgpu/pm: add missing revision check for CI
    - drm/amdgpu/pm: align Hawaii mclk workaround with radeon
    - drm/amdgpu/vcn3: Avoid overflow on msg bound check
    - bcache: fix uninitialized closure object
    - fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START
    - drbd: Balance RCU calls in drbd_adm_dump_devices()
    - nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty()
    - pstore/ram: fix resource leak when ioremap() fails
    - devres: fix missing node debug info in devm_krealloc()
    - thermal/drivers/spear: Fix error condition for reading st,thermal-flags
    - debugfs: check for NULL pointer in debugfs_create_str()
    - irqchip/irq-pic32-evic: Address warning related to wrong printf()
      formatter
    - locking: Fix rwlock support in <linux/spinlock_up.h>
    - firmware: dmi: Correct an indexing error in dmi.h
    - wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt()
    - wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished
      irq_prepare_bcn_tasklet
    - dpaa2: add independent dependencies for FSL_DPAA2_SWITCH
    - [Config] Disable FSL_DPAA2_SWITCH on armhf, ppc64el
    - dpaa2: compile dpaa2 even CONFIG_FSL_DPAA2_ETH=n
    - kernel: param: rename locate_module_kobject
    - kernel: globalize lookup_or_create_module_kobject()
    - params: Replace __modinit with __init_or_module
    - module: Fix freeing of charp module parameters when CONFIG_SYSFS=n
    - bpf, devmap: Remove unnecessary if check in for loop
    - bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path
    - r8152: fix incorrect register write to USB_UPHY_XTAL
    - powerpc/crash: fix backup region offset update to elfcorehdr
    - macvlan: annotate data-races around port->bc_queue_len_used
    - wifi: brcmfmac: Fix error pointer dereference
    - bpf-lsm: Make bpf_lsm_userns_create() sleepable
    - bpf: Drop task_to_inode and inet_conn_established from lsm sleepable
      hooks
    - net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
    - netfilter: xt_socket: enable defrag after all other checks
    - netfilter: nft_fwd_netdev: check ttl/hl before forwarding
    - 6pack: propagage new tty types
    - net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf
    - net/rds: Optimize rds_ib_laddr_check
    - net/rds: Restrict use of RDS/IB to the initial network namespace
    - ppp: require CAP_NET_ADMIN in target netns for unattached ioctls
    - bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb
    - Bluetooth: L2CAP: Fix printing wrong information if SDU length exceeds
      MTU
    - Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error
    - Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER
    - Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp
    - net: phy: qcom: at803x: Use the correct bit to disable extended next
      page
    - sctp: fix missing encap_port propagation for GSO fragments
    - net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master
    - drm/komeda: fix integer overflow in AFBC framebuffer size check
    - ASoC: sti: Return errors from regmap_field_alloc()
    - ASoC: sti: use managed regmap_field allocations
    - dm cache: fix null-deref with concurrent writes in passthrough mode
    - dm cache: fix write path cache coherency in passthrough mode
    - dm cache policy smq: fix missing locks in invalidating cache blocks
    - dm cache: fix concurrent write failure in passthrough mode
    - dm cache: support shrinking the origin device
    - dm cache: fix dirty mapping checking in passthrough mode switching
    - dm cache metadata: fix memory leak on metadata abort retry
    - dm log: fix out-of-bounds write due to region_count overflow
    - spi: fsl-qspi: Use reinit_completion() for repeated operations
    - drm/sun4i: Fix resource leaks
    - dm init: ensure device probing has finished in dm-mod.waitfor=
    - fbdev: matroxfb: Mark variable with __maybe_unused to avoid W=1 build
      break
    - spi: hisi-kunpeng: prevent infinite while() loop in hisi_spi_flush_fifo
    - drm/msm/dsi: rename MSM8998 DSI version from V2_2_0 to V2_0_0
    - drm/panel: simple: Correct G190EAN01 prepare timing
    - ALSA: core: Validate compress device numbers without dynamic minors
    - drm/amd/pm/ci: Use highest MCLK on CI when MCLK DPM is disabled
    - drm/amd/pm/ci: Disable MCLK DPM on problematic CI ASICs
    - drm/amd/pm/smu7: Fix SMU7 voltage dependency on display clock
    - drm/amd/pm/ci: Fix powertune defaults for Hawaii 0x67B0
    - drm/amd/pm/ci: Clear EnabledForActivity field for memory levels
    - drm/amd/pm/ci: Fill DW8 fields from SMC
    - drm/amd/pm/smu7: Add SCLK cap for quirky Hawaii board
    - ALSA: hda/realtek: Whitespace fix
    - ALSA: hda/realtek: fix code style (ERROR: else should follow close brace
      '}')
    - drm/msm/a6xx: Fix HLSQ register dumping
    - drm/msm/a6xx: Use barriers while updating HFI Q headers
    - pmdomain: ti: omap_prm: Fix a reference leak on device node
    - pmdomain: imx: scu-pd: Fix device_node reference leak during ->probe()
    - ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_arc_mode_put()
    - ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_mode_put()
    - ASoC: fsl_easrc: Check the variable range in fsl_easrc_iec958_put_bits()
    - ASoC: fsl_easrc: Fix value type in fsl_easrc_iec958_get_bits()
    - ASoC: fsl_easrc: Change the type for iec958 channel status controls
    - PCI: Enable AtomicOps only if Root Port supports them
    - Documentation: fix a hugetlbfs reservation statement
    - selftest: memcg: skip memcg_sock test if address family not supported
    - PCI: Add PCIE_PME_TO_L2_TIMEOUT_US L2 ready timeout value
    - PCI: tegra194: Fix polling delay for L2 state
    - PCI: tegra194: Increase LTSSM poll time on surprise link down
    - PCI: tegra194: Disable LTSSM after transition to Detect on surprise link
      down
    - PCI: tegra194: Use devm_gpiod_get_optional() to parse "nvidia,refclk-
      select"
    - PCI: tegra194: Disable direct speed change for Endpoint mode
    - ALSA: sc6000: Use standard print API
    - ALSA: sc6000: Keep the programmed board state in card-private data
    - ktest: Avoid undef warning when WARNINGS_FILE is unset
    - ktest: Honor empty per-test option overrides
    - ktest: Run POST_KTEST hooks on failure and cancellation
    - quota: Fix race of dquot_scan_active() with quota deactivation
    - gfs2: add some missing log locking
    - gfs2: prevent NULL pointer dereference during unmount
    - efi/capsule-loader: fix incorrect sizeof in phys array reallocation
    - ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine
    - ARM: dts: mediatek: mt7623: fix efuse fallback compatible
    - memory: tegra124-emc: Fix dll_change check
    - memory: tegra30-emc: Fix dll_change check
    - soc: qcom: ocmem: use scoped device node handling to simplify error
      paths
    - soc: qcom: ocmem: register reasons for probe deferrals
    - soc: qcom: ocmem: return -EPROBE_DEFER is ocmem is not available
    - arm64: dts: qcom: sdm845-xiaomi-beryllium: Mark l1a regulator as powered
      during boot
    - unshare: fix nsproxy leak in ksys_unshare() on set_cred_ucounts()
      failure
    - ocfs2/dlm: validate qr_numregions in dlm_match_regions()
    - ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison
    - soc: qcom: aoss: compare against normalized cooling state
    - ocfs2: fix listxattr handling when the buffer is full
    - ocfs2: validate bg_bits during freefrag scan
    - ocfs2: validate group add input before caching
    - dmaengine: dw-axi-dmac: Remove unnecessary return statement from void
      function
    - dmaengine: mxs-dma: Fix missing return value from
      of_dma_controller_register()
    - tracing: Rebuild full_name on each hist_field_name() call
    - ima: check return value of crypto_shash_final() in boot aggregate
    - HID: asus: make asus_resume adhere to linux kernel coding standards
    - HID: asus: do not abort probe when not necessary
    - mtd: physmap_of_gemini: Fix disabled pinctrl state check
    - mtd: spi-nor: core: correct the op.dummy.nbytes when check read
      operations
    - mtd: spi-nor: swp: check SR_TB flag when getting tb_mask
    - mtd: parsers: ofpart: call of_node_put() only in ofpart_fail path
    - mtd: parsers: ofpart: call of_node_get() for dedicated subpartitions
    - mtd: rawnand: sunxi: fix sunxi_nfc_hw_ecc_read_extra_oob
    - HID: usbhid: fix deadlock in hid_post_reset()
    - pinctrl: pinctrl-pic32: Fix resource leak
    - perf branch: Avoid incrementing NULL
    - perf: tools: cs-etm: Fix print issue for Coresight debug in ETE/TRBE
      trace
    - pinctrl: abx500: Fix type of 'argument' variable
    - perf expr: Return -EINVAL for syntax error in expr__find_ids()
    - perf util: Kill die() prototype, dead for a long time
    - i3c: mipi-i3c-hci: fix IBI payload length calculation for final status
    - driver core: device.h: remove extern from function prototypes
    - driver core: Move dev_err_probe() to where it belogs
    - dev_printk: add new dev_err_probe() helpers
    - backlight: sky81452-backlight: Check return value of
      devm_gpiod_get_optional() in sky81452_bl_parse_dt()
    - platform/surface: surfacepro3_button: Drop wakeup source on remove
    - leds: lgm-sso: Remove duplicate assignments for priv->mmap
    - tty: hvc: remove HVC_IUCV_MAGIC
    - tty: hvc_iucv: fix off-by-one in number of supported devices
    - platform/x86: panasonic-laptop: Fix OPTD notifier registration and
      cleanup
    - mfd: mc13xxx-core: Fix memory leak in mc13xxx_add_subdevice_pdata()
    - nfs/blocklayout: Fix compilation error (`make W=1`) in
      bl_write_pagelist()
    - fs/ntfs3: terminate the cached volume label after UTF-8 conversion
    - platform/x86: dell_rbu: avoid uninit value usage in packet_size_write()
    - platform/x86: dell-wmi-sysman: bound enumeration string aggregation
    - RDMA/core: Prefer NLA_NUL_STRING
    - scsi: sg: Resolve soft lockup issue when opening /dev/sgX
    - scsi: target: core: Fix integer overflow in UNMAP bounds check
    - dt-bindings: clock: qcom,gcc-sc8180x: Add missing GDSCs
    - clk: qcom: gcc-sc8180x: Add missing GDSCs
    - clk: qcom: gcc-sc8180x: Use retention for USB power domains
    - clk: qcom: gcc-sc8180x: Use retention for PCIe power domains
    - clk: qcom: dispcc-sm8250: Use shared ops on the mdss vsync clk
    - clk: qcom: dispcc-sm8250: Enable parents for pixel clocks
    - clk: imx: imx6q: Fix device node reference leak in pll6_bypassed()
    - clk: imx: imx6q: Fix device node reference leak in
      of_assigned_ldb_sels()
    - clk: imx8mq: Correct the CSI PHY sels
    - clk: qoriq: avoid format string warning
    - clk: xgene: Fix mapping leak in xgene_pllclk_init()
    - dt-bindings: clock: qcom,dispcc-sc7180: Define MDSS resets
    - clk: qcom: dispcc-sc7180: Add missing MDSS resets
    - lib/hexdump: print_hex_dump_bytes() calls print_hex_dump_debug()
    - crypto: sa2ul - Fix AEAD fallback algorithm names
    - crypto: ccp - copy IV using skcipher ivsize
    - PCMCIA: Fix garbled log messages for KERN_CONT
    - net/sched: sch_cake: fix NAT destination port not being updated in
      cake_update_flowkeys
    - nexthop: fix IPv6 route referencing IPv4 nexthop
    - net/sched: taprio: stop going through private ops for dequeue and peek
    - net/sched: taprio: replace safety precautions with comments
    - net/sched: taprio: continue with other TXQs if one dequeue() failed
    - net/sched: taprio: refactor one skb dequeue from TXQ to separate
      function
    - net/sched: taprio: rename close_time to end_time
    - net/sched: taprio: fix use-after-free in advance_sched() on schedule
      switch
    - tcp: annotate data-races around (tp->write_seq - tp->snd_nxt)
    - i40e: don't advertise IFF_SUPP_NOFCS
    - e1000e: Unroll PTP in probe error handling
    - ipv6: fix possible UAF in icmpv6_rcv()
    - sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks
    - dissector: do not set invalid PPP protocol
    - flow_dissector: Add number of vlan tags dissector
    - flow_dissector: Add PPPoE dissectors
    - pppoe: drop PFC frames
    - netfilter: nft_osf: restrict it to ipv4
    - netfilter: conntrack: remove sprintf usage
    - netfilter: xtables: restrict several matches to inet family
    - ipvs: fix MTU check for GSO packets in tunnel mode
    - netfilter: nfnetlink_osf: fix out-of-bounds read on option matching
    - netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check
    - arm64: dts: meson-gxl-p230: fix ethernet PHY interrupt number
    - ksmbd: destroy tree_conn_ida in ksmbd_session_destroy()
    - ksmbd: scope conn->binding slowpath to bound sessions only
    - net/rds: zero per-item info buffer before handing it to visitors
    - net_sched: sch_hhf: annotate data-races in hhf_dump_stats()
    - net/sched: sch_pie: annotate data-races in pie_dump_stats()
    - net/sched: sch_fq_codel: remove data-races from fq_codel_dump_stats()
    - net: sched: gred/red: remove unused variables in struct red_stats
    - net/sched: sch_red: annotate data-races in red_dump_stats()
    - net/sched: sch_sfb: annotate data-races in sfb_dump_stats()
    - nfp: fix swapped arguments in nfp_encode_basic_qdr() calls
    - tipc: fix double-free in tipc_buf_append()
    - vhost_net: fix sleeping with preempt-disabled in vhost_net_busy_poll()
    - fs/adfs: validate nzones in adfs_validate_bblk()
    - rtc: abx80x: Disable alarm feature if no interrupt attached
    - fbdev: offb: fix PCI device reference leak on probe failure
    - mailbox: mailbox-test: free channels on probe error
    - cgroup/rdma: fix integer overflow in rdmacg_try_charge()
    - mailbox: add sanity check for channel array
    - mailbox: mailbox-test: don't free the reused channel
    - mailbox: mailbox-test: initialize struct earlier
    - mailbox: mailbox-test: make data_ready a per-instance variable
    - btrfs: fix double-decrement of bytes_may_use in
      submit_one_async_extent()
    - tracing: branch: Fix inverted check on stat tracer registration
    - drm/amdgpu: fix spelling typos
    - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated
    - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2)
    - netfilter: xt_policy: fix strict mode inbound policy matching
    - netfilter: nf_conntrack_sip: don't use simple_strtoul
    - scsi: sr: Add memory allocation failure handling for get_capabilities()
    - cdrom, scsi: sr: propagate read-only status to block layer via
      set_disk_ro()
    - netdevsim: zero initialize struct iphdr in dummy sk_buff
    - net: sched: sch_netem: Refactor code in 4-state loss generator
    - net/sched: netem: fix probability gaps in 4-state loss model
    - net/sched: netem: fix queue limit check to include reordered packets
    - net/sched: netem: validate slot configuration
    - net: sched: choke: remove unused variables in struct choke_sched_data
    - net/sched: sch_choke: annotate data-races in choke_dump_stats()
    - net/sched: sch_fq_pie: annotate data-races in fq_pie_dump_stats()
    - vrf: Fix a potential NPD when removing a port from a VRF
    - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()
    - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit
    - NFC: trf7970a: Ignore antenna noise when checking for RF field
    - net: phy: dp83869: fix setting CLK_O_SEL field.
    - ASoC: codecs: ab8500: Fix casting of private data
    - netfilter: skip recording stale or retransmitted INIT
    - sctp: discard stale INIT after handshake completion
    - ipv4: rename and move ip_route_output_tunnel()
    - ipv4: remove "proto" argument from udp_tunnel_dst_lookup()
    - ipv4: add new arguments to udp_tunnel_dst_lookup()
    - ipv6: rename and move ip6_dst_lookup_tunnel()
    - net/sched: sch_cake: annotate data-races in cake_dump_stats() (V)
    - ALSA: hda/conexant: add a new hda codec SN6140
    - ALSA: hda/conexant: fix some typos
    - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87
    - ALSA: hda/conexant: Fix missing error check for jack detection
    - drm/amd/display: Allow DCE link encoder without AUX registers
    - drm/amd/display: Read EDID from VBIOS embedded panel info
    - btrfs: tracepoints: fix sleep while in atomic context in
      btrfs_sync_file()
    - flow_dissector: do not dissect PPPoE PFC frames
    - flow_dissector: Do not count vlan tags inside tunnel payload
    - net/sched: sch_pie: annotate more data-races in pie_dump_stats()
    - crypto: af_alg - Cap AEAD AD length to 0x80000000
    - i40e: Cleanup PTP pins on probe failure
    - audit: fix incorrect inheritable capability in CAPSET records
    - netfilter: nft_ct: fix missing expect put in obj eval
    - net: atlantic: preserve PCI wake-from-D3 on shutdown when WOL enabled
    - audit: enforce AUDIT_LOCKED for AUDIT_TRIM and AUDIT_MAKE_EQUIV
    - KVM: Reject wrapped offset in kvm_reset_dirty_gfn()
    - KVM: x86: Fix Xen hypercall tracepoint argument assignment
    - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats
    - ALSA: usb-audio: Bound MIDI endpoint descriptor scans
    - ceph: fix a buffer leak in __ceph_setxattr()
    - powerpc/warp: Fix error handling in pika_dtm_thread
    - libceph: Fix potential out-of-bounds access in osdmap_decode()
    - libceph: Fix potential null-ptr-deref in decode_choose_args()
    - libceph: Fix potential out-of-bounds access in crush_decode()
    - libceph: handle rbtree insertion error in decode_choose_args()
    - iommu/vt-d: Disable DMAR for Intel Q35 IGFX
    - drm/i915: skip __i915_request_skip() for already signaled requests
    - drm/panfrost: Fix wait_bo ioctl leaking positive return from
      dma_resv_wait_timeout()
    - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup
    - s390/debug: Reject zero-length input before trimming a newline
    - Revert "x86/vdso: Fix output operand size of RDPID"
    - sysfs: don't remove existing directory on update failure
    - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX
    - ALSA: ua101: Reject too-short USB descriptors
    - ALSA: asihpi: Fix potential OOB array access at reading cache
    - net: wwan: iosm: fix potential memory leaks in ipc_imem_init()
    - Bluetooth: bnep: Fix UAF read of dev->name
    - phonet/pep: disable BH around forwarded sk_receive_skb()
    - net: bcmgenet: keep RBUF EEE/PM disabled
    - netfilter: ip6t_hbh: reject oversized option lists
    - netfilter: nf_queue: hold bridge skb->dev while queued
    - netfilter: ipset: stop hash:* range iteration at end
    - ring-buffer: Fix reporting of missed events in iterator
    - vsock/vmci: fix UAF when peer resets connection during handshake
    - wifi: ath11k: clear shared SRNG pointer state on restart
    - ipv4: raw: reject IP_HDRINCL packets with ihl < 5
    - ixgbevf: fix use-after-free in VEPA multicast source pruning
    - wifi: cfg80211: advance loop vars in cfg80211_merge_profile()
    - tracing: Do not call map->ops->elt_free() if elt_alloc() fails
    - scsi: isci: Fix use-after-free in device removal path
    - spi: sprd: fix error pointer deref after DMA setup failure
    - spi: ti-qspi: fix use-after-free after DMA setup failure
    - RDMA/siw: Reject MPA FPDU length underflow before signed receive math
    - device property: set fwnode->secondary to NULL in fwnode_init()
    - drm/bridge: it66121: acquire reset GPIO in probe
    - drm/bridge: megachips: remove bridge when irq request fails
    - drm/amd/display: Fix integer overflow in bios_get_image()
    - drm/amd/display: Validate payload length and link_index in
      dc_process_dmub_aux_transfer_async
    - batman-adv: mcast: fix use-after-free in orig_node RCU release
    - batman-adv: clear current gateway during teardown
    - batman-adv: dat: handle forward allocation error
    - batman-adv: fix fragment reassembly length accounting
    - batman-adv: fix tp_meter counter underflow during shutdown
    - batman-adv: frag: disallow unicast fragment in fragment
    - batman-adv: bla: fix report_work leak on backbone_gw purge
    - batman-adv: tp_meter: avoid use of uninit sender vars
    - batman-adv: tt: fix negative last_changeset_len
    - batman-adv: tt: fix negative tt_buff_len
    - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock
    - hwmon: (pmbus/adm1266) reject implausible blackbox record_count
    - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer
    - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized
      buffer
    - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR
    - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in
      get_multiple
    - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe()
    - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe()
    - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO
      accessors
    - firmware: arm_ffa: Check for NULL FF-A ID table while driver
      registration
    - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure
    - kunit: config: Enable KUNIT_DEBUGFS by default
    - kunit: config: KUNIT_DEBUGFS should depend on DEBUG_FS
    - ARM: integrator: Fix early initialization
    - netfilter: x_tables: unregister the templates first
    - tcp: Fix imbalanced icsk_accept_queue count.
    - ice: fix locking in ice_dcb_rebuild()
    - phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register
      access
    - irqchip/ath79-cpu: Remove unused function
    - net: ethernet: cortina: Make RX SKB per-port
    - net: ethernet: cortina: Drop half-assembled SKB
    - net: ethernet: cortina: Carry over frag counter
    - net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference
    - wifi: ath11k: fix error path leaks in some WMI WOW calls
    - HID: quirks: really enable the intended work around for appledisplay
    - ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics
    - drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN
    - net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring
    - net: tls: prevent chain-after-chain in plain text SG
    - drm/msm/snapshot: fix dumping of the unaligned regions
    - net: dsa: mt7530: sync driver-specific behavior of MT7531 variants
    - net: dsa: mt7530: fix FDB entries not aging out with short timeout
    - net: dsa: mt7530: rename mt753x_bpdu_port_fw enum to mt753x_to_cpu_fw
    - net: dsa: mt7530: preserve VLAN tags on trapped link-local frames
    - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer
    - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL
    - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL
    - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL
    - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL
    - RDMA/rtrs: Fix use-after-free in path file creation cleanup
    - net: bridge: Flush multicast groups when snooping is disabled
    - bridge: mcast: Fix a possible use-after-free when removing a bridge port
    - tracing: Avoid NULL return from hist_field_name() on truncation
    - net: ag71xx: check error for platform_get_irq
    - string: add mem_is_zero() helper to check if memory area is all zeros
    - gpiolib: cdev: use !mem_is_zero() instead of memchr_inv(s, 0, n)
    - gpio: cdev: check if uAPI v2 config attributes are correctly zeroed
    - net: mana: validate rx_req_idx to prevent out-of-bounds array access
    - Linux 5.15.209
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46275
    - Bluetooth: hci_uart: fix UAFs and race conditions in close and init
      paths
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2025-23141
    - KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory
      accesses
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43052
    - wifi: mac80211: check tdls flag in ieee80211_tdls_oper
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2025-22107
    - net: dsa: sja1105: fix kasan out-of-bounds warning in
      sja1105_table_delete_entry()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2025-21863
    - io_uring: prevent opcode speculation
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46274
    - io-wq: check that the predecessor is hashed in io_wq_remove_pending()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-45846
    - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-45844
    - netfilter: arp_tables: fix IEEE1394 ARP payload parsing
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-45843
    - slip: bound decode() reads against the compressed packet length
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-45842
    - slip: reject VJ receive packets on instances with no rstate array
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-45841
    - netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-45840
    - openvswitch: cap upcall PID array size and pre-size vport replies
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46319
    - net/sched: act_ct: Only release RCU read lock after ct_ft
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-45839
    - bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-45838
    - bpf: fix end-of-list detection in cgroup_storage_get_next_key()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46214
    - vsock/virtio: fix accept queue count leak on transport mismatch
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46234
    - vsock: fix buffer size clamping order
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-45836
    - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46231
    - batman-adv: bla: put backbone reference on failed claim hash insert
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46233
    - batman-adv: bla: only purge non-released claims
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46212
    - batman-adv: bla: prevent use-after-free when deleting claims
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46238
    - batman-adv: stop caching unowned originator pointers in BAT IV
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46206
    - batman-adv: reject new tp_meter sessions during teardown
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46198
    - batman-adv: fix integer overflow on buff_pos
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46227
    - sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in
      SCTP_SENDALL
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46220
    - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46197
    - drm/amdkfd: validate SVM ioctl nattr against buffer size
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46209
    - drm/gem: Fix inconsistent plane dimension calculation in
      drm_gem_fb_init_with_funcs()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46230
    - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46219
    - spi: mpc52xx: fix use-after-free on unbind
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46236
    - media: rc: xbox_remote: heed DMA restrictions
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46205
    - staging: media: atomisp: Disallow all private IOCTLs
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46168
    - mptcp: fix scheduling with atomic in timestamp sockopt
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46189
    - RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46133
    - RDMA/rxe: Reject unknown opcodes before ICRC processing
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46127
    - RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46178
    - RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46112
    - RDMA/hns: Fix unlocked call to hns_roce_qp_remove()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46304
    - nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46161
    - md/raid10: fix divide-by-zero in setup_geo() with zero far_copies
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46124
    - isofs: validate block number from NFS file handle in isofs_export_iget
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46303
    - isofs: validate Rock Ridge CE continuation extent against volume size
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46294
    - dm: fix a buffer overflow in ioctl processing
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46107
    - dm-thin: fix metadata refcount underflow
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46301
    - spi: topcliff-pch: fix use-after-free on unbind
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46273
    - ibmveth: Disable GSO for packets with small MSS
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43502
    - net/rds: handle zerocopy send cleanup before the message is queued
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46120
    - ip6_gre: Use cached t->net in ip6erspan_changelink().
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46184
    - sound: ua101: fix division by zero at probe
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46132
    - net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in
      rtnl_fill_vfinfo
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46150
    - fanotify: fix false positive on permission events
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-45834
    - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-45835
    - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46186
    - Bluetooth: virtio_bt: validate rx pkt_type header length
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46123
    - Bluetooth: virtio_bt: clamp rx length before skb_put
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46172
    - ipv6: xfrm6: release dst on error in xfrm6_rcv_encap()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46146
    - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46167
    - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46151
    - usb: usblp: fix heap leak in IEEE 1284 device ID via short response
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46122
    - wifi: b43: enforce bounds check on firmware key index in b43_rx()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46307
    - wifi: ath5k: do not access array OOB
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46187
    - wifi: rsi: fix kthread lifetime race between self-exit and external-stop
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46163
    - wifi: b43legacy: enforce bounds check on firmware key index in RX path
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46044
    - ipmi:ssif: Clean up kthread on errors
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43496
    - net/sched: sch_red: Replace direct dequeue call with peek and
      qdisc_dequeue_peeked
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2024-56727
    - octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_flows.c
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31489
    - spi: meson-spicc: Fix double-put in remove path
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31476
    - ksmbd: do not expire session on binding failure
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43497
    - fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46108
    - ipmi:si: Return state to normal if message allocation fails
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46128
    - ipmi: Check event message buffer response for bad data
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46177
    - ipmi: Add limits to event and receive message requests
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46149
    - scsi: target: configfs: Bound snprintf() return in
      tg_pt_gp_members_show()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46101
    - netfilter: reject zero shift in nft_bitwise
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46099
    - net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46033
    - crypto: authencesn - reject short ahash digests during instance creation
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46062
    - ntfs3: fix integer overflow in run_unpack() volume boundary check
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46072
    - ntfs3: add buffer boundary checks to run_unpack()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46023
    - dm mirror: fix integer overflow in create_dirty_log()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46077
    - crypto: atmel-tdes - fix DMA sync direction
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-45986
    - crypto: ccree - fix a memory leak in cc_mac_digest()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46019
    - crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46015
    - tcp: call sk_data_ready() after listener migration
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46040
    - inotify: fix watch count leak when fsnotify_add_inode_mark_locked()
      fails
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46070
    - md/raid5: validate payload size before accessing journal metadata
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46051
    - md/raid5: fix soft lockup in retry_aligned_read()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46046
    - ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46285
    - mtd: docg3: fix use-after-free in docg3_release()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46082
    - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-45987
    - KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46024
    - libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46037
    - ipv4: icmp: validate reply type before using icmp_pointers
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46027
    - net/smc: avoid early lgr access in smc_clc_wait_msg
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46053
    - net: rds: fix MR cleanup on copy error
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46004
    - ALSA: caiaq: Handle probe errors properly
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46050
    - md/raid10: fix deadlock with check operation and nowait requests
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46049
    - ALSA: ctxfi: Add fallback to default RSR for S/PDIF
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46002
    - ext2: reject inodes with zero i_nlink and valid mode in ext2_iget()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46047
    - net: qrtr: ns: Fix use-after-free in driver remove()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46009
    - PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46102
    - net: strparser: fix skb_head leak in strp_abort_strp()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46098
    - net: caif: clear client service pointer on teardown
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46088
    - ALSA: control: Validate buf_len before strnlen() in
      snd_ctl_elem_init_enum_names()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46080
    - ocfs2: split transactions in dio completion to avoid credit exhaustion
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2025-21739
    - scsi: ufs: core: Fix use-after free in init error and remove paths
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46064
    - ibmasm: fix heap over-read in ibmasm_send_i2o_message()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-45994
    - ibmasm: fix OOB reads in command_file_write due to missing size checks
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46022
    - misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46006
    - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-46018
    - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31696
    - rxrpc: Fix missing validation of ticket length in non-XDR key preparsing
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31697
    - crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31698
    - crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command
      failed
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31699
    - crypto: ccp: Don't attempt to copy CSR to userspace if PSP command
      failed
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31701
    - ALSA: caiaq: take a reference on the USB device in create_card()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31694
    - fuse: reject oversized dirents in page cache
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31716
    - fs/ntfs3: validate rec->used in journal-replay file record check
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31676
    - rxrpc: only handle RESPONSE during service challenge
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31409
    - ksmbd: unset conn->binding on failed binding request
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2023-53596
    - drivers: base: Free devm resources when unregistering a device
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2024-50012
    - cpufreq: Avoid a bad reference count on CPU node
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2025-38192
    - net: clear the dst when changing skb protocol
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2025-21712
    - md/md-bitmap: Synchronize bitmap_get_stats() with bitmap lifetime
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43328
    - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error
      path
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-23066
    - rxrpc: Fix recvmsg() unconditional requeue
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2024-50248
    - ntfs3: Add bounds checking to mi_enum_attr()
    - fs/ntfs3: Sequential field availability check in mi_enum_attr()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2024-27407
    - fs/ntfs3: Fixed overflow check in mi_enum_attr()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2023-45896
    - fs/ntfs3: Add more attributes checks in mi_enum_attr()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2023-52737
    - btrfs: lock the inode in shared mode before starting fiemap
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2025-38626
    - f2fs: fix to trigger foreground gc during f2fs_map_blocks() in lfs mode
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2025-68307
    - can: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted
      URBs
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2024-46770
    - ice: Add netif_device_attach/detach into PF reset flow
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2025-38105
    - ALSA: usb-audio: Kill timer properly at removal
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2024-27389
    - pstore: inode: Only d_invalidate() is needed
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2023-52682
    - f2fs: fix to wait on block writeback for post_read case
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2024-56719
    - net: stmmac: fix TSO DMA API usage causing oops
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2024-41079
    - nvmet: always initialize cqe.result
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2023-53545
    - drm/amdgpu: unmap and remove csa_va properly
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2025-68239
    - binfmt_misc: restore write access before closing files opened by
      open_exec()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2025-38659
    - gfs2: No more self recovery
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2022-49961
    - bpf: Do mark_chain_precision for ARG_CONST_ALLOC_SIZE_OR_ZERO
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2024-47809
    - dlm: fix possible lkb_resource null dereference
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2025-38250
    - Bluetooth: hci_core: Fix use-after-free in vhci_flush()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43281
    - mailbox: Prevent out-of-bounds access in of_mbox_index_xlate()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-23157
    - btrfs: do not strictly require dirty metadata threshold for metadata
      writepages
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-23141
    - btrfs: send: check for inline extents in range_is_hole_in_parent()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2025-40005
    - spi: cadence-quadspi: Implement refcount to handle unbind during busy
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2023-53629
    - fs: dlm: fix use after free in midcomms commit
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2025-71221
    - dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-23204
    - net/sched: cls_u32: use skb_header_pointer_careful()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2025-71161
    - dm-verity: disable recursive forward error correction
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2022-50552
    - blk-mq: use quiesced elevator switch when reinitializing queues
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2024-36922
    - wifi: iwlwifi: read txq->read_ptr under lock
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2024-53221
    - f2fs: fix null-ptr-deref in f2fs_submit_page_bio()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2024-56657
    - ALSA: control: Avoid WARN() for symlink errors
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2022-49803
    - netdevsim: Fix memory leak of nsim_dev->fa_cookie
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2022-50116
    - tty: n_gsm: fix deadlock and link starvation in outgoing data path
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31586
    - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31598
    - ocfs2: fix possible deadlock between unlink and dio_end_io_write
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31642
    - rxrpc: Fix call removal to use RCU safe deletion
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31664
    - xfrm: clear trailing padding in build_polexpire()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43075
    - ocfs2: fix out-of-bounds write in ocfs2_write_end_inline
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43076
    - ocfs2: validate inline data i_size during inode read
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-23444
    - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2025-38710
    - gfs2: Validate i_depth for exhash directories
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-23442
    - ipv6: add NULL checks for idev in SRv6 paths
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31594
    - PCI: endpoint: pci-epf-vntb: Remove duplicate resource teardown
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2022-50073
    - net: tap: NULL pointer derefence in dev_parse_header_protocol when
      skb->dev is null
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31576
    - media: hackrf: fix to not free memory after the device is registered in
      hackrf_probe()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43058
    - media: vidtv: fix pass-by-value structs causing MSAN warnings
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31577
    - nilfs2: fix NULL i_assoc_inode dereference in
      nilfs_mdt_save_to_shadow_map
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31578
    - media: as102: fix to not free memory after the device is registered in
      as102_usb_probe()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31580
    - bcache: fix cached_dev.sb_bio use-after-free and crash
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31581
    - ALSA: 6fire: fix use-after-free on disconnect
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31583
    - media: em28xx: fix use-after-free in em28xx_v4l2_open()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31585
    - media: vidtv: fix nfeeds state corruption on start_streaming failure
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31686
    - mm/kasan: fix double free for kasan pXds
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31588
    - KVM: x86: Use scratch field in MMIO fragment to hold small write values
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31630
    - rxrpc: proc: size address buffers for %pISpc output
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-23399
    - nf_tables: nft_dynset: fix possible stateful expression memleak in error
      path
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2024-35865
    - smb: client: fix potential UAF in smb2_is_valid_oplock_break()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31590
    - KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31596
    - ocfs2: handle invalid dinode in ocfs2_group_extend
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31597
    - ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31599
    - media: vidtv: fix NULL pointer dereference in
      vidtv_channel_pmt_match_sections
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31602
    - ALSA: ctxfi: Limit PTP to a single page
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31603
    - staging: sm750fb: fix division by zero in ps_to_hz()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31605
    - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31615
    - usb: gadget: renesas_usb3: validate endpoint index in standard request
      handlers
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31616
    - usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31617
    - usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31618
    - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31619
    - ALSA: fireworks: bound device-supplied status before string array lookup
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31622
    - NFC: digital: Bounds check NFC-A cascade depth in SDD response handler
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31623
    - net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31624
    - HID: core: clamp report_size in s32ton() to avoid undefined shift
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31625
    - HID: alps: fix NULL pointer dereference in alps_raw_event()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31626
    - staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31627
    - i2c: s3c24xx: check the size of the SMBUS message before using it
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31532
    - can: raw: fix ro->uniq use-after-free in raw_rcv()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31629
    - nfc: llcp: add missing return after LLCP_CLOSED checks
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31407
    - netfilter: conntrack: add missing netlink policy validations
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43079
    - perf/x86/intel/uncore: Skip discovery table for offline dies
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43080
    - l2tp: Drop large packets with UDP encap
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31673
    - af_unix: read UNIX_DIAG_VFS data under unix_state_lock
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31681
    - netfilter: xt_multiport: validate range encoding in checkentry
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43085
    - netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43089
    - xfrm_user: fix info leak in build_mapping()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43093
    - xsk: tighten UMEM headroom validation to account for tailroom and min
      frame
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43098
    - nfc: s3fwrn5: allocate rx skb before consuming bytes
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43099
    - ipv4: icmp: fix null-ptr-deref in icmp_build_probe()
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43103
    - net: lapbether: handle NETDEV_PRE_TYPE_CHANGE
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-31684
    - net: sched: act_csum: validate nested VLAN headers
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43074
    - eventpoll: defer struct eventpoll free to RCU grace period
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43104
    - drm/vc4: Fix a memory leak in hang state error path
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43105
    - drm/vc4: Fix memory leak of BO array in hang state
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43110
    - wifi: brcmfmac: validate bsscfg indices in IF events
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43111
    - HID: roccat: fix use-after-free in roccat_report_event
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43112
    - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath
  * Jammy update: v5.15.209 upstream stable release (LP: #2156901) //
    CVE-2026-43113
    - wifi: wl1251: validate packet IDs before indexing tx_frames
  * Jammy update: v5.15.207 upstream stable release (LP: #2156629)
    - Buffer overflow in drivers/xen/sys-hypervisor.c
    - xen/privcmd: fix double free via VMA splitting
    - Linux 5.15.204
    - Linux 5.15.205
    - Linux 5.15.206
    - Linux 5.15.207
  * Jammy update: v5.15.207 upstream stable release (LP: #2156629) //
    CVE-2025-54518 // CVE-2026-46174
    - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op
      cache
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550)
    - ARM: clean up the memset64() C wrapper
    - Revert "UBUNTU: SAUCE: Fix skb_vlan_inet_prepare() usage"
    - ip6_tunnel: Fix usage of skb_vlan_inet_prepare()
    - scsi: lpfc: Properly set WC for DPP mapping
    - scsi: ufs: core: Always initialize the UIC done completion
    - scsi: ufs: core: Move link recovery for hibern8 exit failure to
      wl_resume
    - ALSA: usb-audio: Cap the packet size pre-calculations
    - ALSA: usb-audio: Use inclusive terms
    - btrfs: fix incorrect key offset in error message in
      check_dev_extent_item()
    - memory: mtk-smi: Convert to platform remove callback returning void
    - ARM: OMAP2+: add missing of_node_put before break and return
    - ARM: omap2: Fix reference count leaks in omap_control_init()
    - scsi: ata: Call scsi_done() directly
    - ata: libata-scsi: drop DPRINTK calls for cdb translation
    - ata: libata: remove pointless VPRINTK() calls
    - ata: libata-scsi: refactor ata_scsi_translate()
    - drm/tegra: dsi: fix device leak on probe
    - mfd: qcom-pm8xxx: switch away from using chained IRQ handlers
    - mfd: qcom-pm8xxx: Convert to platform remove callback returning void
    - mfd: qcom-pm8xxx: Fix OF populate on driver rebind
    - mfd: omap-usb-host: Convert to platform remove callback returning void
    - mfd: omap-usb-host: Fix OF populate on driver rebind
    - clk: tegra: tegra124-emc: fix device leak on set_rate()
    - usb: cdns3: remove redundant if branch
    - usb: cdns3: call cdns_power_is_lost() only once in cdns_resume()
    - ALSA: hda/conexant: Add quirk for HP ZBook Studio G4
    - hwmon: (max16065) Use READ/WRITE_ONCE to avoid compiler optimization
      induced race
    - fbcon: Use delayed work for cursor
    - fbcon: Extract fbcon_open/release helpers
    - fbcon: move more common code into fb_open()
    - ALSA: hda/conexant: Fix headphone jack handling on Acer Swift SF314
    - net: arcnet: com20020-pci: fix support for 2.5Mbit cards
    - eventpoll: Fix integer overflow in ep_loop_check_proc()
    - platform/x86: dell-wmi: Add audio/mic mute key codes
    - selftests: mptcp: more stable simult_flows tests
    - platform/x86: thinkpad_acpi: Fix errors reading battery thresholds
    - net: ethernet: ti: am65-cpsw-nuss/cpsw-ale: Fix multicast entry handling
      in ALE table
    - net: dpaa2: replace dpaa2_mac_is_type_fixed() with
      dpaa2_mac_is_type_phy()
    - net: dpaa2-switch: assign port_priv->mac after dpaa2_mac_connect() call
    - net: dpaa2-switch replace direct MAC access with
      dpaa2_switch_port_has_mac()
    - net: dpaa2-switch: serialize changes to priv->mac with a mutex
    - dpaa2-switch: do not clear any interrupts automatically
    - dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ
      handler
    - indirect_call_wrapper: do not reevaluate function pointer
    - xen/acpi-processor: fix _CST detection using undersized evaluation
      buffer
    - amd-xgbe: fix sleep while atomic on suspend/resume
    - net: nfc: nci: Fix zero-length proprietary notifications
    - nfc: nci: clear NCI_DATA_EXCHANGE before calling completion callback
    - net: stmmac: Fix error handling in VLAN add and delete paths
    - ACPI: PM: Save NVS memory on Lenovo G70-35
    - ACPI: OSI: Add DMI quirk for Acer Aspire One D255
    - scsi: ses: Fix devices attaching to different hosts
    - ALSA: usb-audio: Avoid implicit feedback mode on DIYINHK USB Audio 2.0
    - ALSA: usb-audio: Check max frame size for implicit feedback mode, too
    - powerpc/uaccess: Fix inline assembly for clang build on PPC32
    - remoteproc: sysmon: Correct subsys_name_len type in QMI request
    - remoteproc: mediatek: Unprepare SCP clock during system suspend
    - powerpc: 83xx: km83xx: Fix keymile vendor prefix
    - bonding: handle BOND_LINK_FAIL, BOND_LINK_BACK as valid link states
    - ASoC: soc-core: drop delayed_work_pending() check before flush
    - ASoC: soc-core: accept zero format at snd_soc_runtime_set_dai_fmt()
    - ASoC: core: Exit all links before removing their components
    - ASoC: core: Do not call link_exit() on uninitialized rtd objects
    - can: hi311x: hi3110_open(): add check for hi3110_power_enable() return
      value
    - regulator: pca9450: Make IRQ optional
    - regulator: pca9450: Correct interrupt type
    - sched: idle: Make skipping governor callbacks more consistent
    - i40e: fix src IP mask checks and memcpy argument names in cloud filter
    - ACPI: OSL: fix __iomem type on return from acpi_os_map_generic_address()
    - ASoC: detect empty DMI strings
    - octeontx2-af: devlink: fix NIX RAS reporter recovery condition
    - net: usb: lan78xx: fix silent drop of packets with checksum errors
    - net: usb: lan78xx: skip LTM configuration for LAN7850
    - usb/core/quirks: Add Huawei ME906S-device to wakeup quirk
    - usb: misc: uss720: properly clean up reference in uss720_probe()
    - usb: core: don't power off roothub PHYs if phy_set_mode() fails
    - usb: cdc-acm: Restore CAP_BRK functionnality to CH343
    - USB: usbcore: Introduce usb_bulk_msg_killable()
    - usb: mdc800: handle signal and read racing
    - mm/tracing: rss_stat: ensure curr is false from kthread context
    - mmc: mmci: Fix device_node reference leak in of_get_dml_pipe_index()
    - libceph: reject preamble if control segment is empty
    - libceph: admit message frames only in CEPH_CON_S_OPEN state
    - time: add kernel-doc in time.c
    - time/jiffies: Mark jiffies_64_to_clock_t() notrace
    - device property: Allow secondary lookup in fwnode_get_next_child_node()
    - irqchip/gic-v3-its: Limit number of per-device MSIs to the range the ITS
      supports
    - net: mana: Ring doorbell at 4 CQ wraparounds
    - ice: fix retry for AQ command 0x06EE
    - parisc: Increase initial mapping to 64 MB with KALLSYMS
    - parisc: Fix initial page table creation for boot
    - net: ethernet: arc: emac: quiesce interrupts before requesting IRQ
    - tracing: Fix trace_buf_size= cmdline parameter with sizes >= 2G
    - lib/bootconfig: fix off-by-one in xbc_verify_tree() unclosed brace error
    - lib/bootconfig: fix snprintf truncation check in
      xbc_node_compose_key_after()
    - lib/bootconfig: check bounds before writing in __xbc_open_brace()
    - btrfs: abort transaction on failure to update root in the received
      subvol ioctl
    - iio: dac: ds4424: reject -128 RAW value
    - iio: chemical: sps30_serial: fix buffer size in sps30_serial_read_meas()
    - iio: potentiometer: mcp4131: fix double application of wiper shift
    - iio: chemical: bme680: Fix measurement wait duration calculation
    - iio: gyro: mpu3050-i2c: fix pm_runtime error handling
    - iio: imu: inv_icm42600: fix odr switch to the same value
    - i3c: mipi-i3c-hci: Use ETIMEDOUT instead of ETIME for timeout errors
    - i3c: mipi-i3c-hci: Restart DMA ring correctly after dequeue abort
    - i3c: mipi-i3c-hci: Add missing TID field to no-op command descriptor
    - l2tp: do not use sock_hold() in pppol2tp_session_get_sock()
    - mmc: sdhci-pci-gli: fix GL9750 DMA write corruption
    - mmc: sdhci: fix timing selection for 1-bit bus width
    - mtd: rawnand: pl353: make sure optimal timings are applied
    - mtd: rawnand: cadence: Fix error check for dma_alloc_coherent() in
      cadence_nand_init()
    - iommu/vt-d: Fix intel iommu iotlb sync hardlockup and retry
    - serial: 8250_pci: add support for the AX99100
    - serial: 8250: Add late synchronize_irq() to shutdown to handle DW UART
      BUSY
    - serial: uartlite: fix PM runtime usage count underflow on probe
    - drm/radeon: apply state adjust rules to some additional HAINAN vairants
    - mm/hugetlb: make detecting shared pte more reliable
    - mm/hugetlb: fix copy_hugetlb_page_range() to use ->pt_share_count
    - mm/hugetlb: fix two comments related to huge_pmd_unshare()
    - mm/rmap: fix two comments related to huge_pmd_unshare()
    - mm/hugetlb: fix excessive IPI broadcasts when unsharing PMD tables using
      mmu_gather
    - net: stmmac: dwmac-loongson: Set clk_csr_i to 100-150MHz
    - net: Handle napi_schedule() calls from non-interrupt
    - ext4: always allocate blocks only from groups inode can use
    - wifi: cfg80211: move scan done work to wiphy work
    - drm/amd/display: Use GFP_ATOMIC in dc_create_stream_for_sink
    - mptcp: pm: avoid sending RM_ADDR over same subflow
    - btrfs: tree-checker: fix misleading root drop_level error message
    - of: Add cleanup.h based auto release via __free(device_node) markings
    - firmware: arm_scpi: Fix device_node reference leak in probe path
    - Bluetooth: LE L2CAP: Disconnect if received packet's SDU exceeds IMTU
    - Bluetooth: LE L2CAP: Disconnect if sum of payload sizes exceed SDU
    - Bluetooth: SMP: make SM/PER/KDU/BI-04-C happy
    - Bluetooth: qca: fix ROM version reading on WCN3998 chips
    - netfilter: xt_time: use unsigned int for monthday bit shift
    - net: bcmgenet: increase WoL poll timeout
    - net: mana: Improve the HWC error handling
    - sched: idle: Consolidate the handling of two special cases
    - igc: fix missing update of skb->tail in igc_xmit_frame()
    - wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough
      headroom
    - ACPI: processor: Fix previous acpi_processor_errata_piix4() fix
    - net: macb: fix uninitialized rx_fs_lock
    - net: dsa: bcm_sf2: fix missing clk_disable_unprepare() in error paths
    - hwmon: (pmbus/isl68137) Fix unchecked return value and use sysfs_emit()
    - i2c: fsi: Fix a potential leak in fsi_i2c_probe()
    - mtd: rawnand: brcmnand: skip DMA during panic write
    - lib/bootconfig: check xbc_init_node() return in override path
    - tools/bootconfig: fix fd leak in load_xbc_file() on fstat failure
    - sh: platform_early: remove pdev->driver_override check
    - bpf: Release module BTF IDR before module unload
    - platform/x86: intel-hid: Add Dell 14 Plus 2-in-1 to dmi_vgbs_allow_list
    - nvme-pci: cap queue creation to used queues
    - platform/x86: intel-hid: Enable 5-button array on ThinkPad X1 Fold 16
      Gen 1
    - platform/x86: touchscreen_dmi: Add quirk for y-inverted Goodix
      touchscreen on SUPI S10
    - HID: magicmouse: fix battery reporting for Apple Magic Trackpad 2
    - net: usb: r8152: add TRENDnet TUC-ET2G
    - HID: mcp2221: cancel last I2C command on read error
    - ASoC: fsl_easrc: Fix event generation in fsl_easrc_iec958_set_reg()
    - ASoC: fsl_easrc: Fix event generation in fsl_easrc_iec958_put_bits()
    - dma-buf: Include ioctl.h in UAPI header
    - ALSA: hda/realtek: Add headset jack quirk for Thinkpad X390
    - xfrm: call xdo_dev_state_delete during state update
    - xfrm: Fix the usage of skb->sk
    - can: statistics: add missing atomic access in hot path
    - pinctrl: mediatek: common: Fix probe failure for devices without EINT
    - ionic: fix persistent MAC address override on PF
    - rtnetlink: count IFLA_INFO_SLAVE_KIND in if_nlmsg_size
    - platform/olpc: olpc-xo175-ec: Fix overflow error message to print inlen
    - net: enetc: fix the output issue of 'ethtool --show-ring'
    - dma-mapping: add missing `inline` for `dma_free_attrs`
    - netlink: introduce NLA_POLICY_MAX_BE
    - netfilter: nft_payload: reject out-of-range attributes via policy
    - netlink: hide validation union fields from kdoc
    - netlink: introduce bigendian integer types
    - netlink: allow be16 and be32 types in all uint policy checks
    - regmap: Synchronize cache for the page selector
    - RDMA/rw: Fall back to direct SGE on MR pool exhaustion
    - RDMA/irdma: Update ibqp state to error if QP is already in error state
    - RDMA/irdma: Remove a NOP wait_event() in irdma_modify_qp_roce()
    - RDMA/irdma: Clean up unnecessary dereference of event->cm_node
    - RDMA/irdma: Remove reset check from irdma_modify_qp_to_err()
    - RDMA/irdma: Return EINVAL for invalid arp index error
    - scsi: scsi_transport_sas: Fix the maximum channel scanning issue
    - x86/efi: efi_unmap_boot_services: fix calculation of ranges_to_free size
    - drm/i915/gmbus: fix spurious timeout on 512-byte burst reads
    - ASoC: Intel: catpt: Fix the device initialization
    - ACPICA: include/acpi/acpixf.h: Fix indentation
    - ACPICA: Allow address_space_handler Install and _REG execution as 2
      separate steps
    - ACPI: EC: Fix EC address space handler unregistration
    - ACPI: EC: Fix ECDT probe ordering issues
    - hwmon: (adm1177) fix sysfs ABI violation and current unit conversion
    - sysctl: fix uninitialized variable in proc_do_large_bitmap
    - ASoC: adau1372: Fix unchecked clk_prepare_enable() return value
    - ASoC: adau1372: Fix clock leak on PLL lock failure
    - s390/barrier: Make array_index_mask_nospec() __always_inline
    - cpufreq: conservative: Reset requested_freq on limits change
    - alarmtimer: Fix argument order in alarm_timer_forward()
    - scsi: ses: Handle positive SCSI error from ses_recv_diag()
    - jbd2: gracefully abort on checkpointing state corruptions
    - ext4: make recently_deleted() properly work with lazy itable
      initialization
    - phy: ti: j721e-wiz: Fix device node reference leak in
      wiz_get_lane_phy_types()
    - dmaengine: xilinx: xilinx_dma: Fix dma_device directions
    - dmaengine: xilinx: xilinx_dma: Fix residue calculation for cyclic DMA
    - dmaengine: xilinx: xilinx_dma: Fix unmasked residue subtraction
    - btrfs: fix super block offset in error message in btrfs_validate_super()
    - btrfs: fix lost error when running device stats on multiple devices fs
    - dmaengine: idxd: Remove usage of the deprecated ida_simple_xx() API
    - dmaengine: idxd: Fix freeing the allocated ida too late
    - dmaengine: xilinx_dma: Program interrupt delay timeout
    - dmaengine: xilinx_dma: Fix reset related timeout with two-channel AXIDMA
    - btrfs: don't take device_list_mutex when querying zone info
    - objtool: Fix Clang jump table detection
    - dt-bindings: auxdisplay: ht16k33: Use unevaluatedProperties to fix
      common property warning
    - tg3: Fix race for querying speed/duplex
    - net: xilinx: axienet: Correct BD length masks to match AXIDMA IP spec
    - netfilter: ipset: use nla_strcmp for IPSET_ATTR_NAME attr
    - net/mlx5: Avoid "No data available" when FW version queries fail
    - net: hsr: fix VLAN add unwind on slave errors
    - hwmon: (pxe1610) Check return value of page-select write in probe
    - hwmon: (tps53679) Fix device ID comparison and printing in
      tps53676_identify()
    - hwmon: (occ) Fix missing newline in occ_show_extended()
    - riscv: kgdb: fix several debug register assignment bugs
    - USB: serial: option: add MeiG Smart SRM825WN
    - MIPS: Fix the GCC version check for `__multi3' workaround
    - drm/ast: dp501: Fix initialization of SCU2C
    - USB: serial: io_edgeport: add support for Blackbox IC135A
    - USB: serial: option: add support for Rolling Wireless RW135R-GL
    - USB: core: add NO_LPM quirk for Razer Kiyo Pro webcam
    - Input: synaptics-rmi4 - fix a locking bug in an error path
    - Input: i8042 - add TUXEDO InfinityBook Max 16 Gen10 AMD to i8042 quirk
      table
    - Input: xpad - add support for Razer Wolverine V3 Pro
    - iio: dac: ad5770r: fix error return in ad5770r_read_raw()
    - iio: light: vcnl4035: fix scan buffer on big-endian
    - iio: imu: st_lsm6dsx: Set FIFO ODR for accelerometer and gyroscope only
    - iio: gyro: mpu3050: Fix out-of-sequence free_irq()
    - usb: quirks: add DELAY_INIT quirk for another Silicon Motion flash drive
    - usb: ehci-brcm: fix sleep during atomic
    - nvmet-tcp: fix use-before-check of sg in bounds validation
    - phy: renesas: rcar-gen3-usb2: Fix role detection on unbind/bind
    - phy: renesas: rcar-gen3-usb2: Move IRQ request in probe
    - phy: renesas: rcar-gen3-usb2: Lock around hardware registers and driver
      data
    - phy: renesas: rcar-gen3-usb2: Assert PLL reset on PHY power off
    - cdc-acm: new quirk for EPSON HMD
    - thunderbolt: Fix property read in nhi_wake_supported()
    - usb: gadget: dummy_hcd: fix premature URB completion when ZLP follows
      partial transfer
    - can: gs_usb: gs_usb_receive_bulk_callback(): unanchor URL on
      usb_submit_urb() error
    - can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
    - Input: uinput - take event lock when submitting FF request "event"
    - media: uvcvideo: Use heuristic to find stream entity
    - arm64: dts: hisilicon: poplar: Correct PCIe reset GPIO polarity
    - arm64: dts: hisilicon: hi3798cv200: Add missing dma-ranges
    - net: qualcomm: qca_uart: report the consumed byte on RX skb allocation
      failure
    - rxrpc: Fix key/keyring checks in setsockopt(RXRPC_SECURITY_KEY/KEYRING)
    - netlink: add nla be16/32 types to minlen array
    - xen/privcmd: unregister xenstore notifier on module exit
    - Revert "mptcp: add needs_id for netlink appending addr"
    - ext4: fix the might_sleep() warnings in kvfree()
    - dmaengine: sh: rz-dmac: Move CHCTRL updates under spinlock
    - dmaengine: sh: rz-dmac: Protect the driver specific lists
    - net: macb: Move devm_{free,request}_irq() out of spin lock area
    - x86/cpu: Enable FSGSBASE early in cpu_init_exception_handling()
    - i2c: cp2615: replace deprecated strncpy with strscpy
    - io_uring/poll: correctly handle io_poll_add() return value on update
    - Linux 5.15.203
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2025-71150
    - ksmbd: Fix refcount leak when invalid session is found on session lookup
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23395
    - Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31549
    - i2c: cp2615: fix serial string NULL-deref at probe
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31433
    - ksmbd: fix potencial OOB in get_file_all_info() for compound requests
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31480
    - tracing: Fix potential deadlock in cpu hotplug with osnoise
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31466
    - mm/huge_memory: fix folio isn't locked in softleaf_to_folio()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43054
    - scsi: target: tcm_loop: Drain commands in target_reset handler
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23401
    - KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO
      SPTE
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31454
    - xfs: save ailp before dropping the AIL lock in push callbacks
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31446
    - ext4: fix use-after-free in update_super_work when racing with umount
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31450
    - ext4: publish jinode after initialization
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31726
    - usb: gadget: uvc: fix NULL pointer dereference during unbind race
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31728
    - usb: gadget: u_ether: Fix race between gether_disconnect and eth_stop
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31721
    - usb: gadget: f_hid: move list and spinlock inits from bind to alloc
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31670
    - net: rfkill: prevent unlimited numbers of rfkill events from being
      created
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31634
    - rxrpc: fix reference count leak in rxrpc_server_keyring()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31651
    - mmc: vub300: fix NULL-deref on disconnect
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31656
    - drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31658
    - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31660
    - nfc: pn533: allocate rx skb before consuming bytes
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31661
    - wifi: brcmsmac: Fix dma_free_coherent() size
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31662
    - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31665
    - netfilter: nft_ct: fix use-after-free in timeout object destroy
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2024-56557
    - iio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xfer
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2024-36898
    - gpiolib: cdev: fix uninitialised kfifo
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2025-40016
    - media: uvcvideo: Mark invalid entities with id UVC_INVALID_ENTITY_ID
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31667
    - Input: uinput - fix circular locking dependency with ff-core
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31671
    - xfrm_user: fix info leak in build_report()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31672
    - wifi: rt2x00usb: fix devres lifetime
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43336
    - lib/crypto: chacha: Zeroize permuted_state before it leaves scope
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31695
    - wifi: virt_wifi: remove SET_NETDEV_DEV to avoid use-after-free
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2024-56584
    - io_uring/tctx: work around xa_store() allocation error issue
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31720
    - usb: gadget: f_uac1_legacy: validate control request size
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43342
    - usb: gadget: f_rndis: Protect RNDIS options with mutex
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43343
    - usb: gadget: f_subset: Fix unbalanced refcnt in geth_free
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2025-68256
    - staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2025-40103
    - smb: client: Fix refcount leak for cifs_sb_tlink
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2025-38006
    - net: mctp: Don't access ifa_index when missing
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2025-40323
    - fbcon: Set fb_display[i]->mode to NULL when the mode is released
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23031
    - can: gs_usb: gs_usb_receive_bulk_callback(): fix URB memory leak
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43324
    - USB: dummy-hcd: Fix interrupt synchronization error
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43327
    - USB: dummy-hcd: Fix locking/synchronization error
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31737
    - net: ftgmac100: fix ring allocation unwind on open failure
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31738
    - vxlan: validate ND option lengths in vxlan_na_create
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31747
    - comedi: me4000: Fix potential overrun of firmware buffer
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31748
    - comedi: me_daq: Fix potential overrun of firmware buffer
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31749
    - comedi: ni_atmio16d: Fix invalid clean-up after failed attach
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43340
    - comedi: Reinit dev->spinlock between attachments to low-level drivers
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31751
    - comedi: dt2815: add hardware detection to prevent crash
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31752
    - bridge: br_nd_send: validate ND option lengths
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31754
    - usb: cdns3: gadget: fix state inconsistency on gadget init failure
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31755
    - usb: cdns3: gadget: fix NULL pointer dereference in ep_queue
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31756
    - usb: dwc2: gadget: Fix spin_lock/unlock mismatch in
      dwc2_hsotg_udc_stop()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31758
    - usb: usbtmc: Flush anchored URBs in usbtmc_release
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31759
    - usb: ulpi: fix double free in ulpi_register_interface() error path
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31761
    - iio: gyro: mpu3050: Move iio_device_register() to correct location
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31762
    - iio: gyro: mpu3050: Fix irq resource leak
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31763
    - iio: gyro: mpu3050: Fix incorrect free_irq() variable
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31770
    - hwmon: (occ) Fix division by zero in occ_show_power_1()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43334
    - Bluetooth: SMP: force responder MITM requirements before building the
      pairing response
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31773
    - Bluetooth: SMP: derive legacy responder STK authentication from MITM
      state
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31776
    - ALSA: ctxfi: Fix missing SPDIFI1 index handling
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31778
    - ALSA: caiaq: fix stack out-of-bounds read in init_card
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31780
    - wifi: wilc1000: fix u8 overflow in SSID scan buffer size calculation
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31781
    - drm/ioc32: stop speculation on the drm_compat_ioctl path
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43333
    - bpf: reject direct access to nullable PTR_TO_BUF pointers
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31415
    - ipv6: avoid overflows in ip6_datagram_send_ctl()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31422
    - net/sched: cls_flow: fix NULL pointer dereference on shared blocks
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31421
    - net/sched: cls_fw: fix NULL pointer dereference on shared blocks
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31417
    - net/x25: Fix overflow when accumulating packets
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43014
    - net: macb: properly unregister fixed rate clocks
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43015
    - net: macb: fix clk handling on PCI glue driver removal
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31425
    - rds: ib: reject FRMR registration before IB connection is established
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43020
    - Bluetooth: MGMT: validate LTK enc_size on load
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43024
    - netfilter: nf_tables: reject immediate NF_QUEUE verdict
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31424
    - netfilter: x_tables: restrict xt_check_match/xt_check_target extensions
      for NFPROTO_ARP
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43026
    - netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43027
    - netfilter: nf_conntrack_helper: pass helper to expect cleanup
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43028
    - netfilter: x_tables: ensure names are nul-terminated
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31416
    - netfilter: nfnetlink_log: account for netlink header size
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43329
    - netfilter: flowtable: strictly check for maximum number of actions
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31680
    - net: ipv6: flowlabel: defer exclusive option free until RCU teardown
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43030
    - bpf: Fix regsafe() for pointers to packet
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43032
    - NFC: pn533: bound the UART receive buffer
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43035
    - net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to
      zero to prevent an info-leak
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43339
    - ipv6: prevent possible UaF in addrconf_permanent_addr()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31423
    - net/sched: sch_hfsc: fix divide-by-zero in rtsc_min()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43040
    - net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX
      fields to zero to prevent an info-leak
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43041
    - net: qrtr: replace qrtr_tx_flow radix_tree with xarray to fix memory
      leak
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43043
    - crypto: af-alg - fix NULL pointer dereference in scatterwalk
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43046
    - btrfs: reject root items with drop_progress and zero drop_level
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43047
    - HID: multitouch: Check to ensure report responses match the request
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43050
    - atm: lec: fix use-after-free in sock_def_readable()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43051
    - HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31555
    - futex: Clear stale exiting pointer in futex_lock_pi() retry path
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43065
    - ext4: always drain queued discard work in ext4_mb_release()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43066
    - ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31447
    - ext4: reject mount if bigalloc with s_first_data_block != 0
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43068
    - ext4: avoid allocate block from corrupted group in
      ext4_mb_find_by_goal()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31452
    - ext4: convert inline data to extents when truncate exceeds inline size
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31455
    - xfs: stop reclaim before pushing AIL during unmount
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31464
    - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31467
    - erofs: add GFP_NOIO in the bio completion if needed
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31469
    - virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and
      napi_tx is false
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31473
    - media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31570
    - can: gw: fix OOB heap access in cgw_csum_crc8_rel()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31483
    - s390/syscalls: Add spectre boundary for syscall dispatch table
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31485
    - spi: spi-fsl-lpspi: fix teardown order issue (UAF)
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31565
    - RDMA/irdma: Fix deadlock during netdev reset with active connections
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31494
    - net: macb: use the current queue number for stats
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31495
    - netfilter: ctnetlink: use netlink policy range checks
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31427
    - netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in
      process_sdp
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31674
    - netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31428
    - netfilter: nfnetlink_log: fix uninitialized padding leak in
      NFULA_PAYLOAD
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31497
    - Bluetooth: btusb: clamp SCO altsetting table indices
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31498
    - Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite loop
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31507
    - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice
      pipe buffer
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31679
    - openvswitch: validate MPLS set/set_masked payload length
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31508
    - net: openvswitch: Avoid releasing netdev before teardown completes
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31509
    - nfc: nci: fix circular locking dependency in nci_close_device
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31510
    - Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43069
    - Bluetooth: hci_ll: Fix firmware leak on error path
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31408
    - Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing
      sock_hold
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31512
    - Bluetooth: L2CAP: Validate PDU length before reading SDU length in
      l2cap_ecred_data_rcv()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31515
    - af_key: validate families in pfkey_send_migrate()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31518
    - esp: fix skb leak with espintcp and async crypto
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31521
    - module: Fix kernel panic when a symbol st_shndx is out of bounds
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31522
    - HID: magicmouse: avoid memory leak in magicmouse_report_fixup()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31523
    - nvme-pci: ensure we're polling a polled queue
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31524
    - HID: asus: avoid memory leak in asus_report_fixup()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31788
    - xen/privcmd: restrict usage in unprivileged domU
    - xen/privcmd: add boot control for restricted usage in domU
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31540
    - drm/i915/gt: Check set_default_submission() before deferencing
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23434
    - mtd: rawnand: serialize lock/unlock against other NAND operations
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23398
    - icmp: fix NULL pointer dereference in icmp_tag_validation()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23438
    - net: mvpp2: guard flow control update with global_tx_fc in buffer
      switching
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23397
    - nfnetlink_osf: validate individual option lengths in fingerprints
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31546
    - net: bonding: fix NULL deref in bond_debug_rlb_hash_show
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23439
    - udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23396
    - wifi: mac80211: fix NULL deref in mesh_matches_local()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23446
    - net: usb: aqc111: Do not perform PM inside suspend callback
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23452
    - PM: runtime: Fix a race condition related to device removal
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23454
    - net: mana: fix use-after-free in mana_hwc_destroy_channel() by
      reordering teardown
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23391
    - netfilter: xt_CT: drop pending enqueued packets on template removal
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43060
    - netfilter: nft_ct: drop pending enqueued packets on removal
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2025-68206
    - netfilter: nft_ct: add seqadj extension for natted connections
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23456
    - netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23457
    - netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in
      sip_help_tcp()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23458
    - netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2025-39764
    - netfilter: ctnetlink: remove refcounting in expectation dumpers
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23460
    - net/rose: fix NULL pointer dereference in rose_transmit_link on
      reconnect
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23462
    - Bluetooth: HIDP: Fix possible UAF
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31551
    - wifi: mac80211: Fix static_branch_dec() underflow for aql_disable.
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23463
    - soc: fsl: qbman: fix race condition in qman_destroy_fq
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31683
    - batman-adv: avoid OGM aggregation when skb tailroom is insufficient
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31550
    - pmdomain: bcm: bcm2835-power: Increase ASB control timeout
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23368
    - net: phy: register phy led_triggers during probe to avoid AB-BA deadlock
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23303
    - smb: client: Don't log plaintext credentials in cifs_set_cifscreds
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23335
    - RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23336
    - wifi: cfg80211: cancel rfkill_block work in wiphy_unregister()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23281
    - wifi: libertas: fix use-after-free in lbs_free_adapter()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2025-38562
    - ksmbd: fix null pointer dereference error in generate_encryptionkey
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-45920
    - ext4: fix dirtyclusters double decrement on fs shutdown
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-45899
    - ext4: drop extent cache when splitting extent fails
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-45985
    - ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting
      I/O
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-45924
    - ksmbd: call ksmbd_vfs_kern_path_end_removing() on some error paths
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23227
    - drm/exynos: vidi: use ctx->lock to protect struct vidi_context member
      variables related to memory alloc/free
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-45958
    - drm/exynos: vidi: fix to avoid directly dereferencing user pointer
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-45956
    - drm/exynos: vidi: use priv->vidi_dev for ctx lookup in
      vidi_connection_ioctl()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23100
    - mm/hugetlb: fix hugetlb_pmd_shared()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43061
    - serial: 8250: Fix TX deadlock when using DMA
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23474
    - mtd: Avoid boot crash in RedBoot partition table parser
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31393
    - Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43062
    - Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31396
    - net: macb: fix use-after-free access to PTP clock
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31545
    - NFC: nxp-nci: allow GPIOs to sleep
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31399
    - nvdimm/bus: Fix potential use after free in asynchronous initialization
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31400
    - sunrpc: fix cache_request leak in cache_release
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2024-46715
    - driver: iio: add missing checks on iio_info's callback access
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23113
    - io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2025-39748
    - bpf: Forget ranges when refining tnum after JSET
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43357
    - iio: gyro: mpu3050-core: fix pm_runtime error handling
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43476
    - iio: chemical: sps30_i2c: fix buffer size in sps30_i2c_read_meas()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43363
    - x86/apic: Disable x2apic on resume if the kernel expects so
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43365
    - xfs: fix undersized l_iclog_roundoff values
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43370
    - drm/amdgpu: Fix use-after-free race in VM acquire
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43373
    - net: ncsi: fix skb leak in error paths
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43380
    - hwmon: (pmbus/q54sj108a2) fix stack overflow in debugfs read
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43381
    - nouveau/dpcd: return EBUSY for aux xfer if the device is asleep
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43382
    - batman-adv: Avoid double-rtnl_lock ELP metric worker
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-31405
    - media: dvb-net: fix OOB access in ULE extension header tables
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43387
    - staging: rtl8723bs: properly validate the data in rtw_get_ie_ex()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43386
    - staging: rtl8723bs: fix potential out-of-bounds read in
      rtw_restruct_wmm_ie
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43420
    - ceph: fix i_nlink underrun during async unlink
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43405
    - libceph: Use u32 for non-negative values in ceph_monmap_decode()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43411
    - tipc: fix divide-by-zero in tipc_sk_filter_connect()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43484
    - mmc: core: Avoid bitfield RMW for claim/retune flags
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43425
    - usb: image: mdc800: kill download URB on timeout
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43426
    - usb: renesas_usbhs: fix use-after-free in ISR during device removal
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43427
    - usb: class: cdc-wdm: fix reordering issue in read code path
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43428
    - USB: core: Limit the length of unkillable synchronous timeouts
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43429
    - USB: usbtmc: Use usb_bulk_msg_killable() with user-specified timeouts
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43430
    - usb: yurex: fix race in probe
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43432
    - usb: xhci: Fix memory leak in xhci_disable_slot()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43439
    - cgroup: fix race between task migration and iteration
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43480
    - ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock
      acquisition
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43445
    - e1000/e1000e: Fix leak in DMA error cleanup
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43449
    - nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43450
    - netfilter: nfnetlink_cthelper: fix OOB read in
      nfnl_cthelper_dump_table()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43451
    - netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43452
    - netfilter: x_tables: guard option walkers against 1-byte tail reads
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43453
    - netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43458
    - serial: caif: hold tty->link reference in ldisc_open and ser_release
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43459
    - ASoC: soc-core: flush delayed work before removing DAIs and widgets
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23277
    - net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL
      slave xmit
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43466
    - net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43469
    - xprtrdma: Decrement re_receiving on the early exit paths
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2025-54505 // CVE-2026-31628
    - x86/CPU: Fix FPDSS on Zen1
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43472
    - unshare: fix unshare_fs() handling
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43473
    - scsi: mpi3mr: Add NULL checks when resetting request and reply queues
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43475
    - scsi: storvsc: Fix scheduling while atomic on PREEMPT_RT
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23270
    - net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared
      blocks
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23300
    - net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23293
    - net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23381
    - net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23372
    - nfc: rawsock: cancel tx_work before socket teardown
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23339
    - nfc: nci: free skb on nci_transceive early error paths
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23340
    - net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless
      qdiscs
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23304
    - ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23420
    - wifi: wlcore: Fix a locking bug
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23357
    - can: mcp251x: fix deadlock in error path of mcp251x_open
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23362
    - can: bcm: fix locking for bcm_op runtime updates
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23286
    - atm: lec: fix null-ptr-deref in lec_arp_clear_vccs
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23296
    - scsi: core: Fix refcount leak for tagset_refcnt
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23356
    - drbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23388
    - Squashfs: check metadata block offset is within range
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23379
    - net/sched: ets: fix divide by zero in the offload path
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23289
    - IB/mthca: Add missed mthca_unmap_user_db() for mthca_create_srq()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23279
    - wifi: mac80211: fix NULL pointer dereference in mesh_rx_csa_frame()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23367
    - wifi: radiotap: reject radiotap with unknown bits
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23318
    - ALSA: usb-audio: Use correct version for UAC3 header validation
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23370
    - platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23352
    - x86/efi: defer freeing of boot services memory
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23382
    - HID: Add HID_CLAIMED_INPUT guards in raw_event callbacks missing them
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23324
    - can: usb: etas_es58x: correctly anchor the urb in the read bulk callback
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23298
    - can: ucan: Fix infinite loop from zero-length messages
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23307
    - can: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a
      message
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23290
    - net: usb: pegasus: validate USB endpoints
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23365
    - net: usb: kalmia: validate USB endpoints
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23312
    - net: usb: kaweth: validate USB endpoints
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23291
    - nfc: pn533: properly drop the usb interface reference on disconnect
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23253
    - media: dvb-core: fix wrong reinitialization of ringbuffer on reopen
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-43123
    - fbcon: check return value of con2fb_acquire_newinfo()
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23220
    - ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error
      paths
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-45911
    - usb: cdns3: fix role switching during resume
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2025-71287
    - memory: mtk-smi: fix device leak on larb probe
  * Jammy update: v5.15.203 upstream stable release (LP: #2156550) //
    CVE-2026-23359
    - bpf: Fix stack-out-of-bounds write in devmap
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272)
    - auxdisplay: arm-charlcd: fix release_mem_region() size
    - i3c: remove i2c board info from i2c_dev_desc
    - i3c: Move device name assignment after i3c_bus_init
    - fs: add <linux/init_task.h> for 'init_fs'
    - gfs2: Add metapath_dibh helper
    - btrfs: qgroup: return correct error when deleting qgroup relation item
    - md/raid10: fix any_working flag handling in raid10_sync_request
    - iomap: fix submission side handling of completion side errors
    - PM: wakeup: Handle empty list in wakeup_sources_walk_start()
    - PM: sleep: wakeirq: harden dev_pm_clear_wake_irq() against races
    - libbpf: Fix dumping big-endian bitfields
    - libbpf: Fix OOB read in btf_dump_get_bitfield_value
    - ARM: VDSO: Patch out __vdso_clock_getres() if unavailable
    - crypto: cavium - fix dma_free_coherent() size
    - crypto: octeontx - fix dma_free_coherent() size
    - hrtimer: Fix trace oddity
    - crypto: hisilicon/trng - modifying the order of header files
    - crypto: hisilicon/trng - support tfms sharing the device
    - scsi: efct: Use IRQF_ONESHOT and default primary handler
    - EDAC/altera: Remove IRQF_ONESHOT
    - mfd: wm8350-core: Use IRQF_ONESHOT
    - EDAC/i5000: Fix snprintf() size calculation in calculate_dimm_size()
    - EDAC/i5400: Fix snprintf() limit calculation in calculate_dimm_size()
    - clk: qcom: Return correct error code in qcom_cc_probe_by_index()
    - arm64: dts: qcom: sdm630: correct QFPROM byte offsets
    - arm64: dts: qcom: sdm630: fix gpu_speed_bin size
    - arm64: dts: qcom: sdm845-oneplus: Don't mark ts supply boot-on
    - ARM: dts: allwinner: sun5i-a13-utoo-p66: delete "power-gpios" property
    - powerpc/uaccess: Move barrier_nospec() out of
      allow_read_{from/write}_user()
    - soc: qcom: cmd-db: Use devm_memremap() to fix memory leak in
      cmd_db_dev_probe
    - ARM: dts: lpc32xx: Set motor PWM #pwm-cells property value to 3 cells
    - arm: dts: lpc32xx: add clocks property to Motor Control PWM device tree
      node
    - arm64: dts: amlogic: axg: assign the MMC signal clocks
    - arm64: dts: amlogic: gx: assign the MMC signal clocks
    - arm64: dts: amlogic: g12: assign the MMC B and C signal clocks
    - arm64: dts: amlogic: g12: assign the MMC A signal clock
    - arm64: dts: qcom: sdm845-db845c: specify power for WiFi CH1
    - smack: /smack/doi must be > 0
    - drm/amdgpu: Use explicit VCN instance 0 in SR-IOV init
    - regulator: core: move supply check earlier in set_machine_constraints()
    - media: ccs: Accommodate C-PHY into the calculation
    - media: uvcvideo: Fix allocation for small frame sizes
    - platform/chrome: cros_ec_lightbar: Fix response size initialization
    - spi: tools: Add include folder to .gitignore
    - PCI: mediatek: Fix IRQ domain leak when MSI allocation fails
    - PCI: Do not attempt to set ExtTag for VFs
    - PCI/portdrv: Fix potential resource leak
    - netfilter: nf_conncount: make nf_conncount_gc_list() to disable BH
    - PCI: Mark 3ware-9650SA Root Port Extended Tags as broken
    - tcp: tcp_tx_timestamp() must look at the rtx queue
    - wifi: ath10k: sdio: add missing lock protection in
      ath10k_sdio_fw_crashed_dump()
    - PCI: Initialize RCB from pci_configure_device()
    - ucount: check for CAP_SYS_RESOURCE using ns_capable_noaudit()
    - bonding: only set speed/duplex to unknown, if getting speed failed
    - netfilter: nft_set_hash: fix get operation on big endian
    - ethtool: add support to set/get tx copybreak buf size via ethtool
    - net: hns3: add support to set/get tx copybreak buf size via ethtool for
      hns3 driver
    - net: hns3: remove the way to set tx spare buf via module parameter
    - net: hns3: fix ethtool tx copybreak buf size indicating not aligned
      issue
    - net: hns3: add max order judgement for tx spare buffer
    - ionic: Rate limit unknown xcvr type messages
    - octeontx2-pf: Unregister devlink on probe failure
    - RDMA/rtrs: server: remove dead code
    - IB/cache: update gid cache on client reregister event
    - RDMA/hns: Notify ULP of remaining soft-WCs during reset
    - power: supply: ab8500_bmdata: Use standard phandle
    - power: supply: ab8500: Use core battery parser
    - power: reset: nvmem-reboot-mode: respect cell size for nvmem_cell_write
    - power: supply: bq27xxx: fix wrong errno when bus ops are unsupported
    - RDMA/rtrs-srv: Refactor the handling of failure case in map_cont_bufs
    - RDMA/rtrs-srv: Correct the checking of ib_map_mr_sg
    - RDMA/rtrs-srv: fix SG mapping
    - mtd: rawnand: cadence: Fix return type of CDMA send-and-wait helper
    - crypto: ccp - Add an S4 restore flow
    - RDMA/core: Fix a couple of obvious typos in comments
    - svcrdma: Remove queue-shortening warnings
    - svcrdma: Clean up comment in svc_rdma_accept()
    - svcrdma: Increase the per-transport rw_ctx count
    - svcrdma: Reduce the number of rdma_rw contexts per-QP
    - RDMA/core: add rdma_rw_max_sge() helper for SQ sizing
    - mtd: parsers: ofpart: fix OF node refcount leak in
      parse_fixed_partitions()
    - RDMA/uverbs: Add __GFP_NOWARN to ib_uverbs_unmarshall_recv() kmalloc
    - pNFS: fix a missing wake up while waiting on NFS_LAYOUT_DRAIN
    - nvdimm: virtio_pmem: serialize flush requests
    - tracing: Remove duplicate ENABLE_EVENT_STR and DISABLE_EVENT_STR macros
    - clk: qcom: rcg2: compute 2d using duty fraction directly
    - clk: meson: gxbb: Limit the HDMI PLL OD to /4 on GXL/GXM SoCs
    - clk: qcom: gcc-msm8953: Remove ALWAYS_ON flag from cpp_gdsc
    - clk: Move clk_{save,restore}_context() to COMMON_CLK section
    - clk: qcom: dispcc-sdm845: Enable parents for pixel clocks
    - dmaengine: mediatek: uart-apdma: Fix above 4G addressing TX/RX
    - dma: dma-axi-dmac: fix SW cyclic transfers
    - serial: imx: change SERIAL_IMX_CONSOLE to bool
    - serial: SH_SCI: improve "DMA support" prompt
    - mmc: rtsx_pci_sdmmc: increase power-on settling delay to 5ms
    - coresight: etm3x: Fix cpulocked warning on cpuhp
    - Revert "mmc: rtsx_pci_sdmmc: increase power-on settling delay to 5ms"
    - drivers: iio: mpu3050: use dev_err_probe for regulator request
    - usb: bdc: fix sleep during atomic
    - pinctrl: equilibrium: Fix device node reference leak in pinbank_init()
    - ovl: Fix uninit-value in ovl_fill_real
    - pinctrl: qcom: Update macro name to LPI specific
    - pinctrl: qcom: Update lpi pin group custiom functions with framework
      generic functions
    - pinctrl: qcom: Extract chip specific LPASS LPI code
    - [Config] Enable CONFIG_PINCTRL_SM8250_LPASS_LPI=m
    - pinctrl: qcom: sm8250-lpass-lpi: Fix i2s2_data_groups definition
    - backlight: qcom-wled: Support ovp values for PMI8994
    - ACPI: CPPC: Fix remaining for_each_possible_cpu() to use online CPUs
    - selftests: mlxsw: tc_restrictions: Fix test failure with new iproute2
    - net/rds: rds_sendmsg should not discard payload_len
    - selftests: forwarding: vxlan_bridge_1d: fix test failure with
      br_netfilter enabled
    - netfilter: nf_conntrack_h323: don't pass uninitialised l3num value
    - ipv6: fix a race in ip6_sock_set_v6only()
    - bpftool: Fix truncated netlink dumps
    - octeontx2-af: Fix default entries mcam entry action
    - apparmor: fix rlimit for posix cpu timers
    - drm/i915/acpi: free _DSM package when no connectors
    - ext4: use optimized mballoc scanning regardless of inode format
    - ata: pata_ftide010: Fix some DMA timings
    - perf callchain: Fix srcline printing with inlines
    - libperf: Don't remove -g when EXTRA_CFLAGS are used
    - libperf build: Always place libperf includes first
    - rtc: interface: Alarm race handling should not discard preceding error
    - hfsplus: fix volume corruption issue for generic/498
    - i3c: master: svc: Initialize 'dev' to NULL in svc_i3c_master_ibi_isr()
    - tools/power cpupower: Reset errno before strtoull()
    - s390/purgatory: Add -Wno-default-const-init-unsafe to KBUILD_CFLAGS
    - x86/xen/pvh: Enable PAE mode for 32-bit guest only when CONFIG_X86_PAE
      is set
    - ACPICA: Abort AML bytecode execution when executing AML_FATAL_OP
    - s390/perf: Disable register readout on sampling events
    - xenbus: Use .freeze/.thaw to handle xenbus devices
    - blk-mq-debugfs: add missing debugfs_mutex in
      blk_mq_debugfs_register_hctxs()
    - sparc: Synchronize user stack on fork and clone
    - sparc: don't reference obsolete termio struct for TC* constants
    - bpf: verifier improvement in 32bit shift sign extension pattern
    - clocksource/drivers/timer-integrator-ap: Add missing Kconfig dependency
      on OF
    - mailbox: bcm-ferxrm-mailbox: Use default primary handler
    - char: tpm: cr50: Remove IRQF_ONESHOT
    - arm64: tegra: smaug: Add usb-role-switch support
    - parisc: Prevent interrupts during reboot
    - media: dvb-core: dmxdevfilter must always flush bufs
    - spi: stm32: fix Overrun issue at < 8bpw
    - media: omap3isp: isp_video_mbus_to_pix/pix_to_mbus fixes
    - media: omap3isp: isppreview: always clamp in preview_try_format()
    - media: omap3isp: set initial format
    - ASoC: wm8962: Add WM8962_ADC_MONOMIX to "3D Coefficients" mask
    - ASoC: wm8962: Don't report a microphone if it's shorted to ground on
      plug
    - media: adv7180: fix frame interval in progressive mode
    - drm/amdkfd: Fix GART PTE for non-4K pagesize in svm_migrate_gart_map()
    - hyper-v: Mark inner union in hv_kvp_exchg_msg_value as packed
    - virt: vbox: uapi: Mark inner unions in packed structs as packed
    - drm/atmel-hlcdc: don't reject the commit if the src rect has fractional
      parts
    - HID: multitouch: add eGalaxTouch EXC3188 support
    - HID: elecom: Add support for ELECOM HUGE Plus M-HT1MRBK
    - gpio: aspeed-sgpio: Change the macro to support deferred probe
    - spi: spi-mem: Protect dirmap_create() with spi_mem_access_start/end
    - ASoC: es8328: Add error unwind in resume
    - modpost: Amend ppc64 save/restfpr symnames for -Os build
    - ALSA: usb-audio: Add iface reset and delay quirk for AB13X USB Audio
    - jfs: Add missing set_freezable() for freezable kthread
    - iommu/arm-smmu-v3: Improve CMDQ lock fairness and efficiency
    - ipv6: annotate data-races in ip6_multipath_hash_{policy,fields}()
    - ipv6: exthdrs: annotate data-race over multiple sysctl
    - ext4: mark group add fast-commit ineligible
    - ext4: mark group extend fast-commit ineligible
    - netfilter: nf_conntrack: Add allow_clash to generic protocol handler
    - openrisc: define arch-specific version of nop()
    - net: usb: r8152: fix transmit queue timeout
    - net: hns3: extend HCLGE_FD_AD_QID to 11 bits
    - wifi: iwlegacy: add missing mutex protection in il4965_store_tx_power()
    - wifi: iwlegacy: add missing mutex protection in
      il3945_store_measurement()
    - ipv4: fib: Annotate access to struct fib_alias.fa_state.
    - Bluetooth: hci_conn: use mod_delayed_work for active mode timeout
    - Bluetooth: btusb: Add device ID for Realtek RTL8761BU
    - wifi: ath10k: fix lock protection in
      ath10k_wmi_event_peer_sta_ps_state_chg()
    - net: usb: sr9700: remove code to drive nonexistent multicast filter
    - vmw_vsock: bypass false-positive Wnonnull warning with gcc-16
    - PCI: Mark ASM1164 SATA controller to avoid bus reset
    - PCI/AER: Clear stale errors on reporting agents upon probe
    - PCI: Fix pci_slot_lock () device locking
    - PCI: Add ACS quirk for Qualcomm Hamoa & Glymur
    - PCI: Mark Nvidia GB10 to avoid bus reset
    - myri10ge: avoid uninitialized variable use
    - nfc: nxp-nci: remove interrupt trigger type
    - RDMA/rtrs-clt: For conn rejection use actual err number
    - scsi: buslogic: Reduce stack usage
    - tracing: Fix false sharing in hwlat get_sample()
    - mailbox: sprd: mask interrupts that are not handled
    - remoteproc: mediatek: Break lock dependency to `prepare_lock`
    - mailbox: sprd: clear delivery flag before handling TX done
    - clk: microchip: core: correct return value on *_get_parent()
    - m68k: nommu: fix memmove() with differently aligned src and dest for
      68000
    - staging: rtl8723bs: fix missing status update on sdio_alloc_irq()
      failure
    - serial: 8250_dw: handle clock enable errors in runtime_resume
    - misc: eeprom: Fix EWEN/EWDS/ERAL commands for 93xx56 and 93xx66
    - serial: 8250: 8250_omap.c: Clear DMA RX running status only after DMA
      termination is done
    - fix it87_wdt early reboot by reporting running timer
    - binder: don't use %pK through printk
    - phy: mvebu-cp110-utmi: fix dr_mode property read from dts
    - phy: fsl-imx8mq-usb: disable bind/unbind platform driver feature
    - Revert "mfd: da9052-spi: Change read-mask to write-mask"
    - iio: Use IRQF_NO_THREAD
    - iio: magnetometer: Remove IRQF_ONESHOT
    - MIPS: Loongson: Make cpumask_of_node() robust against NUMA_NO_NODE
    - fs/ntfs3: avoid calling run_get_entry() when run == NULL in
      ntfs_read_run_nb_ra()
    - include: uapi: netfilter_bridge.h: Cover for musl libc
    - ARM: 9467/1: mm: Don't use %pK through printk
    - drm/amd/display: Avoid updating surface with the same surface under MPO
    - drm/amdgpu: Adjust usleep_range in fence wait
    - ALSA: usb-audio: Update the number of packets properly at receiving
    - drm/amdgpu: Add HAINAN clock adjustment
    - drm/radeon: Add HAINAN clock adjustment
    - btrfs: replace BUG() with error handling in __btrfs_balance()
    - lan78xx: Fix memory allocation bug
    - net: usb: lan78xx: scan all MDIO addresses on LAN7801
    - wifi: cfg80211: wext: fix IGTK key ID off-by-one
    - Bluetooth: L2CAP: Fix invalid response to L2CAP_ECRED_RECONF_REQ
    - Bluetooth: hci_qca: Cleanup on all setup failures
    - Bluetooth: L2CAP: Fix response to L2CAP_ECRED_CONN_REQ
    - tipc: fix duplicate publication key in tipc_service_insert_publ()
    - RDMA/core: Fix stale RoCE GIDs during netdev events at registration
    - RDMA/efa: Fix typo in efa_alloc_mr()
    - fpga: dfl: use subsys_initcall to allow built-in drivers to be added
    - arm64: Disable branch profiling for all arm64 code
    - media: cx25821: Add missing unmap in snd_cx25821_hw_params()
    - media: i2c: ov5647: Correct pixel array offset
    - media: i2c: ov5647: Correct minimum VBLANK value
    - media: i2c: ov5647: Sensor should report RAW color space
    - media: i2c: ov5647: Fix PIXEL_RATE value for VGA mode
    - media: i2c: ov5647: use our own mutex for the ctrl lock
    - dm-integrity: fix a typo in the code for write/discard race
    - clk: tegra: tegra124-emc: Fix potential memory leak in
      tegra124_clk_register_emc()
    - s390/pci: Handle futile config accesses of disabled devices directly
    - dm-unstripe: fix mapping bug when there are multiple targets in a table
    - arm64: dts: rockchip: Do not enable hdmi_sound node on Pinebook Pro
    - media: venus: vdec: fix error state assignment for zero bytesused
    - drm: of: drm_of_panel_bridge_remove(): fix device_node leak
    - mm, page_alloc, thp: prevent reclaim for __GFP_THISNODE THP allocations
    - selftests/mm/charge_reserved_hugetlb: drop mount size for hugetlbfs
    - xfs: mark data structures corrupt on EIO and ENODATA
    - xfs: fix remote xattr valuelblk check
    - nfsd: fix return error code for nfsd_map_name_to_[ug]id
    - usb: gadget: tegra-xudc: Add handling for BLCG_COREPLL_PWRDN
    - bus: fsl-mc: fix an error handling in fsl_mc_device_add()
    - dm mpath: make pg_init_delay_msecs settable
    - iio: gyro: itg3200: Fix unchecked return value in read_raw
    - PCI/IOV: Fix race between SR-IOV enable/disable and hotplug
    - arm64: Fix non-atomic __READ_ONCE() with CONFIG_LTO=y
    - btrfs: continue trimming remaining devices on failure
    - usb: dwc2: fix resume failure if dr_mode is host
    - mtd: rawnand: pl353: Fix software ECC support
    - tipc: fix RCU dereference race in tipc_aead_users_dec()
    - net: cpsw_new: Fix unnecessary netdev unregistration in cpsw_probe()
      error path
    - parisc: kernel: replace kfree() with put_device() in create_tree_node()
    - MIPS: rb532: Fix MMIO UART resource registration
    - net: ethernet: marvell: skge: remove incorrect conflicting PCI ID
    - tracing: Fix to set write permission to per-cpu buffer_size_kb
    - net: intel: fix PCI device ID conflict between i40e and ipw2200
    - fbdev: ffb: fix corrupted video output on Sun FFB1
    - drm/amdgpu: keep vga memory on MacBooks with switchable graphics
    - NTB: ntb_transport: Fix too small buffer for debugfs_name
    - Linux 5.15.202
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43291
    - net: nfc: nci: Fix parameter validation for packet data
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43283
    - net: ethernet: ec_bhf: Fix dma_free_coherent() dma handle
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43264
    - fbdev: of: display_timing: fix refcount leak in of_get_display_timings()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43202
    - fbdev: vt8500lcdfb: fix missing dma_free_coherent()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43203
    - atm: fore200e: fix use-after-free in tasklets during device removal
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43149
    - net: wan/fsl_ucc_hdlc: Fix dma_free_coherent() in uhdlc_memclean()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43273
    - ceph: supply snapshot context in ceph_zero_partial_object()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43159
    - staging: rtl8723bs: fix null dereference in find_network
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43211
    - PCI: Fix pci_slot_trylock() error handling
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43206
    - drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43275
    - scsi: ufs: core: Flush exception handling work when RPM level is zero
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43145
    - remoteproc: imx_rproc: Fix invalid loaded resource table detection
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43147
    - Revert "PCI/IOV: Add PCI rescan-remove locking when enabling/disabling
      SR-IOV"
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43289
    - kexec: derive purgatory entry from symbol
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43168
    - ocfs2: fix reflink preserve cleanup issue
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43295
    - rapidio: replace rio_free_net() with kfree() in rio_scan_alloc_net()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43148
    - powerpc/smp: Add check for kcalloc() failure in parse_thread_groups()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43163
    - md/bitmap: fix GPF in write_page caused by resize race
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43200
    - PCI: endpoint: Fix swapped parameters in
      pci_{primary/secondary}_epc_epf_unlink() functions
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43158
    - xfs: fix freemap adjustments when adding xattrs to leaf blocks
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43187
    - xfs: delete attr leaf freemap entries when empty
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43130
    - iommu/vt-d: Flush dev-IOTLB only when PCIe device is accessible in
      scalable mode
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43133
    - KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43196
    - soc: ti: pruss: Fix double free in pruss_clk_mux_setup()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43242
    - soc: ti: k3-socinfo: Fix regmap leak on probe failure
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43278
    - dm: clear cloned request bio pointer when last clone bio completes
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43312
    - media: i2c: ov5647: Initialize subdev before controls
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43182
    - media: ccs: Avoid possible division by zero
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43246
    - media: i2c/tw9906: Fix potential memory leak in tw9906_probe()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43218
    - media: i2c/tw9903: Fix potential memory leak in tw9903_probe()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43135
    - media: cx23885: Add missing unmap in snd_cx23885_hw_params()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43257
    - media: cx88: Add missing unmap in snd_cx88_hw_params()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43231
    - media: radio-keene: fix memory leak in error path
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43136
    - HID: logitech-hidpp: Check maxfield in hidpp_get_report_length()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43251
    - HID: prodikeys: Check presence of pm->input_ep82
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43140
    - HID: magicmouse: Do not crash on missing msc->input
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43152
    - HID: hid-pl: handle probe errors
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43315
    - KVM: nSVM: Remove a user-triggerable WARN on nested_svm_load_cr3()
      succeeding
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43270
    - media: mtk-mdp: Fix a reference leak bug in mtk_mdp_remove()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43207
    - media: mtk-mdp: Fix error handling in probe function
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43132
    - dm-verity: correctly handle dm_bufio_client_create() failure
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2025-71274
    - rpmsg: core: fix race in driver_override_show() and use core helper
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43233
    - netfilter: nf_conntrack_h323: fix OOB read in decode_choice()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43205
    - dpaa2-switch: validate num_ifs to prevent out-of-bounds write
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43194
    - net: consume xmit errors of GSO frames
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43156
    - net: usb: pegasus: enable basic endpoint checking
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43232
    - net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43134
    - Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43180
    - net: usb: kaweth: remove TX queue manipulation in kaweth_set_rx_mode
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43139
    - xfrm6: fix uninitialized saddr in xfrm6_get_saddr()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43141
    - ntb: ntb_hw_switchtec: Fix shift-out-of-bounds for 0 mw lut
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43241
    - ntb: ntb_hw_switchtec: Fix array-index-out-of-bounds access
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43279
    - ALSA: usb-audio: Add sanity check for OOB writes at silencing
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2025-71267
    - fs: ntfs3: fix infinite loop triggered by zero-sized ATTR_LIST
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2025-71265
    - fs: ntfs3: fix infinite loop in attr_load_runs_range on inconsistent
      metadata
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2025-71266
    - fs: ntfs3: check return value of indx_find to avoid infinite loop
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43225
    - staging: rtl8723bs: fix memory leak on failure path
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43230
    - net/rds: Clear reconnect pending bit
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43296
    - octeontx2-af: Workaround SQM/PSE stalls by disabling sticky
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43226
    - net/rds: No shortcut out of RDS_CONN_ERROR
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43190
    - netfilter: xt_tcpmss: check remaining length before reading optlen
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43255
    - wifi: libertas: fix WARNING in usb_tx_block
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43314
    - dm: remove fake timeout to avoid leak request
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2025-71292
    - jfs: nlink overflow in jfs_rename
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43236
    - drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43269
    - drm/atmel-hlcdc: fix memory leak from the atomic_destroy_state callback
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43287
    - drm: Account property blob allocations to memcg
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43183
    - media: cx25821: Fix a resource leak in cx25821_dev_setup()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43316
    - media: solo6x10: Check for out of bounds chip_id
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43223
    - media: pvrusb2: fix URB leak in pvr2_send_request_ex
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43302
    - drm/v3d: Set DMA segment size to avoid debug warnings
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43124
    - pstore: ram_core: fix incorrect success return when vmap() fails
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43227
    - clocksource/drivers/sh_tmu: Always leave device running after probe
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43313
    - ACPI: processor: Fix NULL-pointer dereference in
      acpi_processor_errata_piix4()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43266
    - EFI/CPER: don't go past the ARM processor CPER record buffer
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43277
    - APEI/GHES: ensure that won't go past CPER allocated record
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43171
    - EFI/CPER: don't dump the entire memory region
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43184
    - rnbd-srv: Zero the rsp buffer before using it
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43261
    - arm64: Add support for TSV110 Spectre-BHB mitigation
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43262
    - gfs2: fiemap page fault fix
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43209
    - minix: Add required sanity checking to minix_check_superblock()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-43268
    - hfsplus: pretend special inodes as regular files
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-23241
    - audit: add missing syscalls to read class
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2025-71239
    - audit: add fchmodat2() to change attributes class
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45964
    - SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45870
    - SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45948
    - ext4: fix memory leak in ext4_ext_shift_extents()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45912
    - ext4: don't cache extent during splitting extent
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-46250
    - MIPS: Work around LLVM bug when gp is used as global register variable
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45974
    - btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not
      found
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45965
    - apparmor: fix invalid deref of rawdata when export_binary is unset
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45848
    - apparmor: fix NULL sock in aa_sock_file_perm
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45970
    - bonding: alb: fix UAF in rlb_arp_recv during bond up/down
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45847
    - net: remove WARN_ON_ONCE when accessing forward path array
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45890
    - xen-netback: reject zero-queue configuration from guest
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45968
    - cpuidle: Skip governor when only one idle state is available
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45935
    - fs/ntfs3: Fix slab-out-of-bounds read in DeleteIndexEntryRoot
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45864
    - fs/ntfs3: prevent infinite loops caused by the next valid being the same
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45868
    - pinctrl: single: fix refcount leak in pcs_add_gpio_func()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45883
    - iio: sca3000: Fix a resource leak in sca3000_probe()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45875
    - mfd: arizona: Fix regulator resource leak on
      wm5102_clear_write_sequencer() failure
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45978
    - staging: greybus: lights: avoid NULL deref
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45954
    - fbdev: au1200fb: Fix a memory leak in au1200fb_drv_probe()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45857
    - scsi: csiostor: Fix dereference of null pointer rn
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45856
    - RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45852
    - RDMA/rxe: Fix double free in rxe_srq_from_init
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45869
    - power: supply: wm97xx: Fix NULL pointer dereference in
      power_supply_changed()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45916
    - power: supply: sbs-battery: Fix use-after-free in power_supply_changed()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-46270
    - power: supply: rt9455: Fix use-after-free in power_supply_changed()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45936
    - power: supply: goldfish: Fix use-after-free in power_supply_changed()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45885
    - power: supply: cpcap-battery: Fix use-after-free in
      power_supply_changed()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45879
    - power: supply: bq25980: Fix use-after-free in power_supply_changed()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45902
    - power: supply: bq256xx: Fix use-after-free in power_supply_changed()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45867
    - power: supply: act8945a: Fix use-after-free in power_supply_changed()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45946
    - power: supply: ab8500: Fix use-after-free in power_supply_changed()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45866
    - serial: caif: fix use-after-free in caif_serial ldisc_close()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-31411
    - net: atm: fix crash due to unvalidated vcc pointer in sigd_send()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-46259
    - procfs: fix missing RCU protection when reading real_parent in
      do_task_stat()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45891
    - net: hns3: fix double free issue for tx spare buffer
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45873
    - netfilter: nft_set_rbtree: check for partial overlaps in anonymous sets
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-46267
    - nfc: hci: shdlc: Stop timers and work before freeing context
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-46249
    - octeontx2-af: Fix PF driver crash with kexec kernel booting
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45915
    - fat: avoid parent link count underflow in rmdir
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45983
    - nfsd: never defer requests during idmap lookup
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45862
    - iommu/vt-d: Flush cache for PASID table before using it
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45860
    - netfilter: nf_conncount: increase the connection clean up limit to 64
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45969
    - HID: playstation: Add missing check for input_ff_create_memless
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2025-71304
    - smack: /smack/doi: accept previously used values
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45904
    - powerpc/eeh: fix recursive pci_lock_rescan_remove locking in EEH event
      handling
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-46253
    - pstore/ram: fix buffer overflow in persistent_ram_save_old()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45919
    - sched/rt: Skip currently executing CPU in rto_next_cpu()
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45871
    - tpm: st33zp24: Fix missing cleanup on get_burstcount() error
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45941
    - tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45984
    - gfs2: Fix use-after-free in iomap inline data write path
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-45960
    - hfsplus: return error when node already exists in hfs_bnode_create
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-23243
    - RDMA/umad: Reject negative data_len in ib_umad_write
  * Jammy update: v5.15.202 upstream stable release (LP: #2156272) //
    CVE-2026-23242
    - RDMA/siw: Fix potential NULL pointer dereference in header processing
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198)
    - crypto: octeontx - Fix length check to avoid truncation in
      ucode_load_store
    - scsi: qla2xxx: Query FW again before proceeding with login
    - ALSA: hda/realtek: Fix headset mic for TongFang X6AR55xU
    - gpio: sprd: Change sprd_gpio lock to raw_spin_lock
    - drm/tegra: hdmi: sor: Fix error: variable ā€˜j’ set but not used
    - platform/x86: panasonic-laptop: Fix sysfs group leak in error path
    - gpiolib: acpi: Fix gpio count with string references
    - Revert "wireguard: device: enable threaded NAPI"
    - selftests: mptcp: pm: ensure unknown flags are ignored
    - crypto: virtio - Remove duplicated virtqueue_kick in
      virtio_crypto_skcipher_crypt_req
    - bus: fsl-mc: Replace snprintf and sprintf with sysfs_emit in sysfs show
      functions
    - scsi: qla2xxx: Use named initializers for port_[d]state_str
    - scsi: qla2xxx: Remove dead code (GNN ID)
    - scsi: qla2xxx: Reduce fabric scan duplicate code
    - PCI: endpoint: Automatically create a function specific attributes group
    - PCI: endpoint: Remove unused field in struct pci_epf_group
    - USB: serial: option: add Telit FN920C04 RNDIS compositions
    - Linux 5.15.201
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2026-23235
    - f2fs: fix out-of-bounds access in sysfs attribute read/write
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2026-23234
    - f2fs: fix to avoid UAF in f2fs_write_end_io()
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2026-23236
    - fbdev: smscufx: properly copy ioctl memory to kernelspace
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2026-23266
    - fbdev: rivafb: fix divide error in nv3_arb()
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2025-71233
    - PCI: endpoint: Avoid creating sub-groups asynchronously
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2025-71232
    - scsi: qla2xxx: Free sp in error path to fix system crash
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2025-71238
    - scsi: qla2xxx: Fix bsg_done() causing double free
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2026-23221
    - bus: fsl-mc: fix use-after-free in driver_override_show()
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2026-23228
    - smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection()
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2026-23169
    - mptcp: fix race in mptcp_pm_nl_flush_addrs_doit()
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2025-37786
    - net: dsa: free routing table on probe failure
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2025-68358
    - btrfs: fix racy bitfield write in btrfs_clear_space_info_full()
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2026-23237
    - platform/x86: classmate-laptop: Add missing NULL pointer checks
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2026-23238
    - romfs: check sb_set_blocksize() return value
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2026-31687
    - gpio: omap: do not register driver in probe()
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2025-71235
    - scsi: qla2xxx: Delay module unload while fabric scan in progress
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2025-71236
    - scsi: qla2xxx: Validate sp before freeing associated memory
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2025-71237
    - nilfs2: Fix potential block overflow that cause system hang
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2026-23229
    - crypto: virtio - Add spinlock protection with virtqueue notification
  * Jammy update: v5.15.201 upstream stable release (LP: #2155198) //
    CVE-2026-23222
    - crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly
  * CVE-2026-23392
    - netfilter: nf_tables: register hooks last when adding new
      chain/flowtable
    - netfilter: nf_tables: release flowtable after rcu grace period on error
  * CVE-2026-45988
    - rxrpc: Fix re-decryption of RESPONSE packets
  * CVE-2026-46195
    - smb: client: validate dacloffset before building DACL pointers
  * CVE-2026-46135
    - nvmet-tcp: fix race between ICReq handling and queue teardown
  * CVE-2026-31402
    - nfsd: fix heap overflow in NFSv4.0 LOCK replay cache
  * CVE-2026-43071
    - dcache: Limit the minimal number of bucket to two
  * CVE-2026-46119
    - libceph: Fix slab-out-of-bounds access in auth message processing
  * CVE-2026-43501
    - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
  * CVE-2026-46043
    - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
  * CVE-2026-43493
    - crypto: pcrypt - Fix handling of MAY_BACKLOG requests
  * CVE-2026-31637
    - rxrpc: reject undecryptable rxkad response tickets
  * CVE-2026-31657
    - batman-adv: hold claim backbone gateways by reference
  * CVE-2026-31685
    - netfilter: ip6t_eui64: reject invalid MAC header for all packets
  * CVE-2026-43117
    - btrfs: tracepoints: get correct superblock from dentry in event
      btrfs_sync_file()
  * CVE-2026-43114
    - netfilter: nft_set_pipapo_avx2: don't return non-matching entry on
      expiry
  * CVE-2026-31478
    - ksmbd: replace hardcoded hdr2_len with offsetof() in
      smb2_calc_max_out_buf_len()
  * CVE-2026-31668
    - seg6: separate dst_cache for input and output paths in seg6 lwtunnel
  * CVE-2026-31659
    - batman-adv: reject oversized global TT response buffers
  * CVE-2026-31649
    - net: stmmac: fix integer underflow in chain mode
  * CVE-2026-31669
    - mptcp: fix slab-use-after-free in __inet_lookup_established
  * CVE-2026-43011
    - net/x25: Fix potential double free of skb
  * CVE-2026-43037
    - ip6_tunnel: clear skb2->cb[] in ip4ip6_err()
  * CVE-2026-43038
    - ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
  * CVE-2026-31682
    - bridge: br_nd_send: linearize skb before parsing ND options
  * CVE-2026-23450
    - net/smc: Only save the original clcsock callback functions
    - net/smc: Fix slab-out-of-bounds issue in fallback
    - net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock()
  * CVE-2026-23428
    - ksmbd: fix use-after-free of share_conf in compound request
  * CVE-2026-23455
    - netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()
  * CVE-2026-43186
    - ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data()
  * CVE-2026-43185
    - ksmbd: fix signededness bug in smb_direct_prepare_negotiation()
  * CVE-2026-43341
    - net/ipv6: ioam6: prevent schema length wraparound in trace fill
  * CVE-2026-31607
    - usbip: validate number_of_packets in usbip_pack_ret_submit()
  * CVE-2026-43383
    - net/tcp-md5: Fix MAC comparison to be constant-time
  * CVE-2025-68263
    - ksmbd: ipc: fix use-after-free in ipc_msg_send_request
  * CVE-2026-46243
    - smb: client: reject userspace cifs.spnego descriptions
  * CVE-2026-43414
    - scsi: qla2xxx: Completely fix fcport double free
  * CVE-2026-43407
    - libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply()
  * CVE-2026-43406
    - libceph: prevent potential out-of-bounds reads in
      process_message_header()
  * CVE-2026-43304
    - libceph: define and enforce CEPH_MAX_KEY_LEN
  * CVE-2025-37924
    - ksmbd: fix use-after-free in kerberos authentication
  * CVE-2025-37778
    - ksmbd: Fix dangling pointer in krb_authenticate

linux-kvm (5.15.0-1103.108) jammy; urgency=medium

  * jammy/linux-kvm: 5.15.0-1103.108 -proposed tracker (LP: #2157239)

  [ Ubuntu: 5.15.0-185.195 ]

  * jammy/linux: 5.15.0-185.195 -proposed tracker (LP: #2157253)
  * Packaging resync (LP: #1786013)
    - [Packaging] update annotations scripts
    - [Packaging] resync retpoline extraction
  * CVE-2026-45988
    - rxrpc: Fix re-decryption of RESPONSE packets
  * CVE-2026-46195
    - smb: client: validate dacloffset before building DACL pointers
  * CVE-2026-46135
    - nvmet-tcp: fix race between ICReq handling and queue teardown
  * CVE-2026-31402
    - nfsd: fix heap overflow in NFSv4.0 LOCK replay cache
  * CVE-2026-43071
    - dcache: Limit the minimal number of bucket to two
  * CVE-2026-46119
    - libceph: Fix slab-out-of-bounds access in auth message processing
  * CVE-2026-43501
    - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
  * CVE-2026-46043
    - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
  * CVE-2026-43493
    - crypto: pcrypt - Fix handling of MAY_BACKLOG requests
  * CVE-2026-31637
    - rxrpc: reject undecryptable rxkad response tickets
  * CVE-2026-31657
    - batman-adv: hold claim backbone gateways by reference
  * CVE-2026-31685
    - netfilter: ip6t_eui64: reject invalid MAC header for all packets
  * CVE-2026-43117
    - btrfs: tracepoints: get correct superblock from dentry in event
      btrfs_sync_file()
  * CVE-2026-43114
    - netfilter: nft_set_pipapo_avx2: don't return non-matching entry on
      expiry
  * CVE-2026-31478
    - ksmbd: replace hardcoded hdr2_len with offsetof() in
      smb2_calc_max_out_buf_len()
  * CVE-2026-31668
    - seg6: separate dst_cache for input and output paths in seg6 lwtunnel
  * CVE-2026-31659
    - batman-adv: reject oversized global TT response buffers
  * CVE-2026-31649
    - net: stmmac: fix integer underflow in chain mode
  * CVE-2026-31669
    - mptcp: fix slab-use-after-free in __inet_lookup_established
  * CVE-2026-43011
    - net/x25: Fix potential double free of skb
  * CVE-2026-43037
    - ip6_tunnel: clear skb2->cb[] in ip4ip6_err()
  * CVE-2026-43038
    - ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
  * CVE-2026-31682
    - bridge: br_nd_send: linearize skb before parsing ND options
  * CVE-2026-23450
    - net/smc: Only save the original clcsock callback functions
    - net/smc: Fix slab-out-of-bounds issue in fallback
    - net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock()
  * CVE-2026-23428
    - ksmbd: fix use-after-free of share_conf in compound request
  * CVE-2026-23455
    - netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()
  * CVE-2026-43186
    - ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data()
  * CVE-2026-43185
    - ksmbd: fix signededness bug in smb_direct_prepare_negotiation()
  * CVE-2026-43341
    - net/ipv6: ioam6: prevent schema length wraparound in trace fill
  * CVE-2026-31607
    - usbip: validate number_of_packets in usbip_pack_ret_submit()
  * CVE-2026-43383
    - net/tcp-md5: Fix MAC comparison to be constant-time
  * CVE-2025-68263
    - ksmbd: ipc: fix use-after-free in ipc_msg_send_request
  * CVE-2026-46243
    - smb: client: reject userspace cifs.spnego descriptions
  * CVE-2026-43414
    - scsi: qla2xxx: Completely fix fcport double free
  * CVE-2026-43407
    - libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply()
  * CVE-2026-43406
    - libceph: prevent potential out-of-bounds reads in
      process_message_header()
  * CVE-2026-43304
    - libceph: define and enforce CEPH_MAX_KEY_LEN
  * CVE-2025-37924
    - ksmbd: fix use-after-free in kerberos authentication
  * CVE-2025-37778
    - ksmbd: Fix dangling pointer in krb_authenticate

Date: 2026-06-30 22:39:15.653706+00:00
Changed-By: Hannah Sofie Peuckmann <hannah.peuckmann at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-kvm/5.15.0-1104.109
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list