[ubuntu/noble-security] linux-qcom 6.8.0-1054.54 (Accepted)

Andy Whitcroft apw at canonical.com
Thu Sep 18 22:23:30 UTC 2025


linux-qcom (6.8.0-1054.54) noble; urgency=medium

  * noble/linux-qcom: 6.8.0-1054.54 -proposed tracker (LP: #2122312)

  * [RB8][x03] bam-dma-engine errors found in dmesg (LP: #2109950)
    - PENDING: arm64: dts: qcom: Add num-channels and num-ees for bam-dma

  * [qcom] Fix bug regarding DT qcom,phy-rst-gpio property (LP: #2120806)
    - QCLINUX: data-eth: qps615: Add fallback for PHY reset GPIO using
      alternate property

  * [qcom] real solution for thermal_sys failed to bind errors
    - QCLINUX: arm64: dts: qcom: Update cooling cell for cdsp node for qcm6490
    - QCLINUX: arm64: dts: qcom: Update cooling cell for msm_gpu node for
      qcm6490

  * camera-UAPI headers not packed as part of dev package
    - [Packaging] add usr/include/camera_kt/*.h files to linux-libc-dev-qcom

  * [RB8][x04] USB storage via type-c port not detected on second plug-in
    - Revert "usb: xhci: Implement xhci_handshake_check_state() helper"

linux-qcom (6.8.0-1053.53) noble; urgency=medium

  * noble/linux-qcom: 6.8.0-1053.53 -proposed tracker (LP: #2121844)

  * Packaging resync (LP: #1786013)
    - [Packaging] resync git-ubuntu-log
    - [Packaging] debian.qcom/dkms-versions -- update from kernel-versions
      (main/d2025.08.18)

  * [6490][x03-desktop] HDMI display cannot reach 4k resolution (LP: #2107745)
    - drm: msm: add 4k support through a bridge driver
    - SAUCE: sync msm_default from msm of -1053
    - SAUCE: Do the necessary change to support adreno

  * [RB8] [x04] Camera doesn't start with linux-qcom 1052 (LP: #2121043)
    - msm: camera: uapi: Roll back UAPI to the previous version

  * [RB8] 0004-QCLINUX-net-stmmac-Add-EEPROM-support-to-driver.patch feedback
    (LP: #2116922)
    - QCLINUX: data-eth: qps615: Switch to NVMEM for MAC address retrieval
    - PENDING: arm64: dts: qcom: Add nvmem-layout for eeprom on qcs9075
    - PENDING: arm64: dts: qcom: Expose Ethernet MAC address via NVMEM

  * Unable to hear the audio playback clip from the RB8 hardware speakers with
    Server & Desktop images
    - ASoC: qcs9075-iq-evk: Enable audio on qcs9075-iq-evk

  * Miscellaneous Ubuntu changes
    - [Config] update to Yocto GA 1.5
    - SAUCE: firmware: qcom: si-core:  include <workqueue_types.h>
    - SAUCE: remove +x bit from source

  * Miscellaneous upstream changes
    - PENDING: arm64: dts: qcom: Update the thermal sensor names
    - PENDING: drivers: pinctrl: Add support for context save/restore
    - PENDING: pinctrl: qcom: sa8775p: Add PM suspend callbacks
    - PENDING: arm64: dts: qcom: qcs8300: Update carveouts
    - QCLINUX: arm64: defconfigs: Enable SA8797P Pinctrl
    - PENDING: pinctrl: qcom: Add TLMM Driver for SA8797p platform
    - QCLINUX: iommu: Remove atomic allocation check to fix smmu mapping
      failure
    - QCLINUX: arm64: defconfig: Align Gen5auto configs with Gen4auto
    - PENDING: arm64: dts: qcom: qcs9075-rb8: Set the BT bootstrap bin when
      init Uart
    - PENDING: arm64: dts: qcom: sa8775p: add GPDSP fastrpc-compute-cb nodes
    - PENDING: misc: fastrpc: Add support for gpdsp remoteproc
    - QCLINUX: arm64: defconfig: Enable Tracer Configs
    - FROMLIST: soc: qcom: Add qcom_rproc_minidump module
    - FROMLIST: remoteproc: qcom_q6v5_pas: Use qcom_rproc_minidump()
    - FROMLIST: remoteproc: qcom: Remove minidump related data from
      qcom_common.c
    - FROMLIST: pstore/ram: Add ramoops information notifier support
    - FROMLIST: soc: qcom: Add Qualcomm APSS minidump kernel driver
    - QCLINUX: defconfig: Enable ebtables and netfilter configuration
    - PENDING: drm/msm/dp: correct the configuration ctrl reg for streams
    - UPSTREAM: arm64: dts: qcom: Fix max speed for usb_1 on qcs8300
    - QCLINUX: arm64: configs: qcom_debug: Fix up order of CONFIGs
    - PENDING: net: stmmac: Enable MMC counters for 25gmac
    - PENDING: ASoC: qcom: q6prm: Add lpass mclk id support
    - QCLINUX: firmware: qcom_scm_addon: Enable SCM for Memory Dump
    - FROMLIST: wifi: ath11k: add function to get next srng desc
    - PENDING: arm64: dts: qcom: sa8255p: Enable USB role switch
    - QCLINUX: arm64: configs: qcom_debug: Enable PSTORE
    - QCLINUX: arm64: configs: qcom_debug: Enable QCOM_MINIDUMP
    - FROMLIST: wifi: ath11k: fix HTC rx insufficient length
    - UPSTREAM: BACKPORT: arm64: dts: qcom: qcs6490-rb3gen2: Enable USB Type-C
      display
    - FROMLIST: wifi: ath11k: fix node corruption in ar->arvifs list
    - PENDING: arm64: dts: qcom: Enable tsens and thermal for QCS615 SoC
    - Revert "PENDING: net: stmmac: Create new mdio for every emac instance"
    - QCLINUX: firmware: qcom_scm_addon: Update SCM call for Memory Dump
    - PENDING: net: stmmac: Fix USXGMII link up sequence
    - QCLINUX: arm64: configs: qcom_debug: Enable QCOM_MINIDUMP
    - QCLINUX: ASoC: qcs9075: Add Stub AIF0 & AIF1
    - QCLINUX: arm64: dts: qcom: Add mem-object node for si_core
    - PENDING: firmware: qcom: Add si_core and si_core_xts
    - QCLINUX: Disable QCOM_SMCINVOKE
    - QCLINUX: Enable QCOM_SI_CORE and QCOM_SI_CORE_XTS
    - PENDING: drivers: mailbox: ipcc: Add Deep Sleep support for qcom-ipcc
      driver
    - QCLINUX: arm64: dts: qcom: Fix issue of USB hub & DP not working
      properly
    - PENDING: net: PCS: Rework and expose qcom_xpcs_destroy function
    - PENDING: net: stmmac: Use pcs_init and pcs_exit functions
    - PENDING: iommu/arm-smmu: add ACTLR data and support for sa8797p
    - PENDING: drm/msm/dpu: Correct the index of intf_6 vsync irq
    - FROMLIST: PCI: Add support for PCIe wake interrupt
    - PENDING: arm64: dts: qcom: sa8255p: Disable USB U1/U2 entry
    - PENDING: net: phy: aquantia: Add polling for global status register
      before checking for provision and firmware ID's
    - PENDING: drm/msm/dp: Add the stream 2 and stream 3 clk for 4 MST
    - PENDING: drm/msm/dp: add support for programming p2/p3 register block
    - QCLINUX: arm64: dts: qcom: Add PCIe wake for HSP
    - PENDING: drm/msm/dp: add support for programming mst2/mst3 register
      block
    - PENDING: drm/msm/dp: add catalog support for 4 streams MST
    - PENDING: drm/msm/dp: add interface map needed to enable 4 streams
    - PENDING: arm64/dts/qcom: add mst support for MST2/MST3 clk and registers
    - PENDING: net: stmmac: Reset few of the IO macro registers to POR values
      before programming
    - PENDING: net: stmmac: Enable L2 split header support on XGMAC
    - PENDING: net: pcs: Enable PCS Fusa Shared interrupt
    - PENDING: net: stmmac: Enable safety interrupt only after PCS link up
    - QCLINUX: ASoC: qcs8275: Add support for QCS8275 RB4
    - QCLINUX: iommu/arm-smmu: Invoke pm runtime for context fault
    - FROMGIT: serial: qcom-geni: Remove alias dependency from qcom serial
      driver
    - QCLINUX: Revert "serial: qcom-geni: fix receiver enable"
    - QCLINUX: Revert "Revert "FROMLIST: arm64: dts: qcom: sa8775p: Add CPUs
      to psci power domain""
    - QCLINUX: arm64: qcom_defconfig: Enable EXT4_FS_SECURITY
    - PENDING: scsi: ufs-qcom: Fix MCQ version handling to update CFG register
    - PENDING: soc: qcom: qcom_stats: Add SMEM items for multiple subsystems
    - PENDING: arm64: dts: qcom: sa7255p: Add PCIe EP nodes
    - PENDING: arm64: dts: qcom: Revert uart0 support for qcs9075-iq-9075-evk
    - PENDING: arm64: dts: qcom: qcs8300: Add gpu_speed_bin to qfprom node
    - QCLINUX: tz_log: Revert "QCLINUX: qcom: tz_log: differentiate hlos and
      hypversior of creating shmbridge"
    - QCLINUX: tz_log: Revert "QCLINUX: qcom: tz_log: enable tz_log support
      hypervisor"
    - QCLINUX: smcinvoke: Revert "QCLINUX: smcinvoke: Add support hypervisor
      of shmbridge"
    - PENDING: coresight: fix NULL pointer issue when get CSR's name
    - PENDING: arm64: dts: qcom: Add support for QCS8275 IQ8 EVK board
    - QCLINUX:arm64: dts: qcom: Add eMMC support for qcs8300
    - QCLINUX: dcc: Add Deep Sleep support for qcom-dcc driver
    - QCLINUX: firmware: qcom_scm_addon: Add SCM call to init multi GPU
      instance
    - QCLINUX: firmware: qcom_scm_addon: Add interface to load CCU
    - PENDING: Adapt to kennel v6.6.78, modify the corresponding driver
      function interface
    - FROMLIST: firmware: qcom_scm: Check for waitq state in
      wait_for_completion
    - PENDING: net: PCS: supply Tx to Rx loopback clock for HW configuration
    - QCLINUX: arm64: dts: qcom: Add msm-id & board-id for qcs8275 IQ8
    - PENDING: arm64: dts: qcom: Enable primary USB controller on QCS8275 RB4
    - FROMLIST: arm64: dts: qcom: sa8775p: add support for video node
    - FROMLIST: arm64: dts: qcom: sa8775p-ride: enable video
    - FROMLIST: arm64: dts: qcom: qcs8300: add support for video node
    - FROMLIST: arm64: dts: qcom: qcs8300-ride: enable video
    - PENDING: drivers: pinctrl: Add suspend to RAM support
    - Revert "QCLINUX: remoteproc: Panic on remoteproc crash"
    - PENDING: drivers: char: add remote debugger driver support for GDSP
    - PENDING: net: stmmac: Use generic PCS field and move pcs_pre_init before
      Serdes powerup
    - PENDING: arm64: dts: qcom: sa7255p: Enable uart12 in sa7255p
    - PENDING: pinctrl: qcom: sa8797p: Add PM suspend callbacks
    - QCLINUX: firmware: qcom: si-core: Switch to tzmem interfaces
    - PENDING: arm64: dts: qcom: Add support for the IQ-9075-evk mezz
    - PENDING: arm64: dts: qcom: tpm enablement for qcs9075-iq-9075-evk
    - PENDING: i2c: qcom-geni: Defer i2c geni driver probe if firmware file
      not found
    - PENDING: arm64: dts: qcom: Enable USB2 controller on QCS8275 IQ8 EVK
    - PENDING: arm64: dts: qcom: Add UFS support for QCS8275 IQ8 EVK
    - PENDING: arm64: dts: qcom: Flatten USB DT node for USB2 on QCS9075 RB8
      Platform
    - QCLINUX: arm64: dts: qcom: Add audio mdf reserved memory for sa7255
    - QCLINUX: firmware: Remove qtee_shmbridge driver
    - QCLINUX: arm64: defconfig: qcom: Enable AMC6821 Sensor driver
    - PENDING: arm64: qcs9075-evk: remove uart bt en and bootstrap pin in DTS
    - PENDING: arm64: dts: qcom: Enable PCIe0 & PCIe1 for QCS8275 IQ8 EVK
    - PENDING: arm64: dts: qcom: add gpio expander support for IQ8-8275-EVK
    - PENDING: arm64: dts: qcom: Add support for remoteproc instances
    - PENDING: arm64: dts: qcom: sa8775p: add rdbg nodes
    - QCLINUX: arm64: dts: qcom: qcs8275: addons dt support for IQ8 QCS8275
    - PENDING: arm64: dts: qcom: Flatten USB DT node
    - PENDING: arm64: dts: qcom: qcs8300: Define interconnect bandwidth value
    - PENDING: dt-bindings: arm: qcom: add the SoC ID for SA8650P
    - PENDING: arm64: dts: qcom: add support for IQ8-8275-evk mezz board
    - PENDING: arm64: dts: qcom: Enable BT on QCS8275 IQ8 EVK
    - PENDING: arm64: dts: qcom: Enable ethernet on QCS8275 IQ8 EVK
    - PENDING: arm64: dts: qcom: qcs8275: Enable gpi-dma node
    - FROMGIT: arm64: dts: qcom: sa8775p: Add default pin configurations for
      QUP SEs
    - PENDING: arm64: dts: qcom: Add fan controller support for
      qcs9075-iq-9075-evk
    - QCLINUX: dcc: Add suspend to RAM support for qcom-dcc driver
    - PENDING: drivers: mailbox: ipcc: Add suspend to RAM  support for qcom-
      ipcc driver
    - PENDING: net: stmmac: disable PCS interrupt if PCS
    - PENDING: arm64: dts: qcom: Add DRD mode support
    - QCLINUX: soc: qcom: Adapt smci header with latest copyright guidelines
    - PENDING: arm64: dts: qcom: Flatten USB DT node
    - QCLINUX: arm64: dts: qcom: Enable the second ethernet on QCS9075-IQ9
      Mezz
    - QCLINUX:arm64: dts: qcom: Add sdcard support for qcs9075 rb8
    - PENDING: drm/bridge: lt9611uxc: extend mode valid checks
    - PENDING: arm64: dts: qcom: Enable QPS615 on IQ8 EVK Mezz
    - PENDING: driver: bluetooth: hci_qca: Disable hci_auto_off when BT_EN is
      consistently pulled up by hardware
    - PENDING: driver: bluetooth: hci_qca: fix ssr fail when BT_EN is
      consistently pulled up by hardware
    - PENDING: arm64: dts: qcom: Enable QPS615 on IQ-9075-evk mezz
    - QCLINUX: arm64: dts: qcom: Add support for Eth0 and Eth1 on QPS615 for
    - BACKPORT: PCI: of: Add of_pci_get_equalization_presets() API
    - BACKPORT: PCI: dwc: Update pci->num_lanes to maximum supported link
      width
    - BACKPORT: PCI: Add lane equalization register offsets
    - BACKPORT: PCI: dwc: Add support for configuring lane equalization
      presets
    - PENDING: PCI: qcom: Add equalization settings for 8.0 GT/s
    - PENDING: arm64: dts: qcom: sa8775p: Add PCIe lane equalization preset
      properties
    - PENDING: arm64: dts: qcom: Make status disabled for remote endpoints on
      mezz
    - FROMLIST: PCI: dwc: Set PORT_LOGIC_LINK_WIDTH to one lane
    - FROMLIST: phy: qcom: qmp-pcie: Update PHY settings for SA8775P
    - PENDING: arm64: dts: qcom: Add support for QCS8275 IQ8 Pro SKU EVK board
    - QCLINUX: arm64: dts: qcom: Add msm-id & board-id for QCS8275 IQ8 Pro SKU
    - QCLINUX: arm64: dts: qcom: addons dt support for IQ8 QCS8275 Pro SKU
    - PENDING: arm64: dts: qcom: add io expander support for IQ8-8275 Pro SKU
    - PENDING: arm64: dts: qcom: Enable primary USB
    - PENDING: arm64: dts: qcom: Add DRD mode support
    - PENDING: arm64: dts: qcom: Enable USB2 controller
    - QCLINUX: usb: dwc3: qcom: Fix calling of regulator get
    - PENDING: arm64: dts: msm: Add UFS support for QCS8275 IQ8 Pro SKU EVK
    - PENDING: arm64: dts: qcom: Update phy reset GPIO for Eth0 and Eth1 on
    - PENDING: arm64: dts: qcom: Add wakeup source
    - PENDING: arm64: dts: qcom: Add wakeup source
    - PENDING: arm64: dts: qcom: Add usb conn gpio
    - PENDING: arm64: dts: qcom: Add SD card support for QCS8275 IQ EVK
    - PENDING: arm64: dts: qcom: Add SD card support for QCS8275 IQ8 Pro SKU
    - PENDING: arm64: dts: qcom: Enable PCIe for QCS8275 IQ8 Pro SKU EVK
    - PENDING: arm64: dts: qcom: Add wakeup source
    - PENDING: arm64: dts: qcom: Enable vqmmc voltage switching for qcs9075
      rb8
    - PENDING: usb: typec: Add wakeup support from
    - QCLINUX: arm64: dts: qcom: Fix eud ep in sa8775p-ride
    - PENDING: misc: eud: Add High-Speed Phy control for EUD operations
    - PENDING: misc: eud: Handle usb role switch notifications
    - PENDING: misc: eud: Add an API to identify the role switch context
    - PENDING: usb: dwc3: qcom: Handle Vbus OFF notification from EUD
    - PENDING: arm64: dts: qcom: Add HS Phy node to EUD for SC7280
    - PENDING: arm64: dts: qcom: Rearrange the role switch eps for QCM6490
    - PENDING: arm64: dts: qcom: Rearrange the role switch for QCS6490 RB3Gen2
    - PENDING: arm64: dts: qcom: Add status prop for ICE nodes
    - PENDING: arm64: dts: qcom: Enable ICE node for eMMC
    - PENDING: arm64: dts: qcom: tpm enablement for qcs8275-iq-8275-evk
    - QCLINUX: arm64: dts: qcom: Disable eMMC ICE
    - PENDING: arm64: dts: qcom: Add EEPROM support for IQ-9075-evk
    - QCLINUX: net: stmmac: Add EEPROM support to driver
    - kernel: arm64: dts: qcom: enable EEPROM Client Driver
    - kernel: config: qcom: enable AT24 EEPROM driver

  [ Ubuntu: 6.8.0-81.81 ]

  * noble/linux: 6.8.0-81.81 -proposed tracker (LP: #2121671)
  * Packaging resync (LP: #1786013)
    - [Packaging] debian.master/dkms-versions -- update from kernel-versions
      (main/2025.08.11)
  * nvme no longer detected on boot after upgrade to 6.8.0-60 (LP: #2111521)
    - SAUCE: PCI: Disable RRS polling for Intel SSDPE2KX020T8 nvme
  * No IP Address assigned after hot-plugging Ethernet cable on HP Platform
    (LP: #2115393)
    - Revert "e1000e: change k1 configuration on MTP and later platforms"
  * minimal kernel lacks modules for blk disk in arm64 openstack environments
    where config_drive is required (LP: #2118499)
    - [Config] Enable SYM53C8XX_2 on arm64
  * rcu: Eliminate deadlocks involving do_exit() and RCU tasks (LP: #2117123)
    - rcu-tasks: Initialize callback lists at rcu_init() time
    - rcu-tasks: Maintain lists to eliminate RCU-tasks/do_exit() deadlocks
    - rcu-tasks: Eliminate deadlocks involving do_exit() and RCU tasks
    - rcu-tasks: Maintain real-time response in rcu_tasks_postscan()
  * BPF header file in wrong location (LP: #2118965)
    - [Packaging] Install bpf header to correct location
  * i915: support ARL-H gpu (LP: #2117716)
    - drm/i915: Add additional ARL PCI IDs
    - drm/i915/mtl: Add fake PCH for Meteor Lake
    - drm/i915/mtl: Wake GT before sending H2G message
    - drm/i915/xelpg: Add workaround 14019877138
    - drm/i915/xelpg: Extend driver code of Xe_LPG to Xe_LPG+
    - drm/i915/display: correct dual pps handling for MTL_PCH+
  * Ubuntu 24.04.2: NULL pointer dereference with Ceph and selinux
    (LP: #2115447)
    - SAUCE: fs/ceph, selinux: fix NULL pointer dereference on CephFS write
      with SELinux in permissive mode
  * Noble update: upstream stable patchset 2025-08-04 (LP: #2119458)
    - clockevents/drivers/i8253: Fix stop sequence for timer 0
    - sched/isolation: Prevent boot crash when the boot CPU is nohz_full
    - hrtimer: Use and report correct timerslack values for realtime tasks
    - mm: add nommu variant of vm_insert_pages()
    - io_uring: get rid of remap_pfn_range() for mapping rings/sqes
    - io_uring: don't attempt to mmap larger than what the user asks for
    - io_uring: fix corner case forgetting to vunmap
    - io_uring: use vmap() for ring mapping
    - io_uring: unify io_pin_pages()
    - io_uring/kbuf: vmap pinned buffer ring
    - io_uring/kbuf: use vm_insert_pages() for mmap'ed pbuf ring
    - io_uring: use unpin_user_pages() where appropriate
    - io_uring: fix error pbuf checking
    - rust: Disallow BTF generation with Rust + LTO
    - rust: init: fix `Zeroable` implementation for `Option<NonNull<T>>` and
      `Option<KBox<T>>`
    - lib/buildid: Handle memfd_secret() files in build_id_parse()
    - mm: split critical region in remap_file_pages() and invoke LSMs in
      between
    - stmmac: loongson: Pass correct arg to PCI function
    - rust: lockdep: Remove support for dynamically allocated LockClassKeys
    - netfilter: nf_tables: allow clone callbacks to sleep
    - drm/amd/display: should support dmub hw lock on Replay
    - drm/amd/display: Use HW lock mgr for PSR1 when only one eDP
    - KVM: arm64: Calculate cptr_el2 traps on activating traps
    - KVM: arm64: Unconditionally save+flush host FPSIMD/SVE/SME state
    - KVM: arm64: Remove host FPSIMD saving for non-protected KVM
    - KVM: arm64: Remove VHE host restore of CPACR_EL1.ZEN
    - KVM: arm64: Remove VHE host restore of CPACR_EL1.SMEN
    - KVM: arm64: Refactor exit handlers
    - KVM: arm64: Eagerly switch ZCR_EL{1,2}
    - Revert "sched/core: Reduce cost of sched_move_task when config
      autogroup"
    - wifi: iwlwifi: support BIOS override for 5G9 in CA also in LARI version
      8
    - netfilter: nft_counter: Use u64_stats_t for statistic.
    - firmware: imx-scu: fix OF node leak in .probe()
    - arm64: dts: freescale: tqma8mpql: Fix vqmmc-supply
    - arm64: dts: rockchip: remove supports-cqe from rk3588 jaguar
    - xfrm: fix tunnel mode TX datapath in packet offload mode
    - xfrm_output: Force software GSO only in tunnel mode
    - soc: imx8m: Remove global soc_uid
    - soc: imx8m: Use devm_* to simplify probe failure handling
    - soc: imx8m: Unregister cpufreq and soc dev in cleanup path
    - ARM: dts: bcm2711: Fix xHCI power-domain
    - ARM: dts: bcm2711: PL011 UARTs are actually r1p5
    - arm64: dts: rockchip: Remove undocumented sdmmc property from lubancat-1
    - RDMA/bnxt_re: Add missing paranthesis in map_qp_id_to_tbl_indx
    - RDMA/mlx5: Handle errors returned from mlx5r_ib_rate()
    - ARM: OMAP1: select CONFIG_GENERIC_IRQ_CHIP
    - ARM: dts: bcm2711: Don't mark timer regs unconfigured
    - dma-mapping: fix missing clear bdr in check_ram_in_range_map()
    - RDMA/bnxt_re: Avoid clearing VLAN_ID mask in modify qp path
    - RDMA/hns: Fix soft lockup during bt pages loop
    - RDMA/hns: Fix unmatched condition in error path of alloc_user_qp_db()
    - RDMA/hns: Fix a missing rollback in error path of
      hns_roce_create_qp_common()
    - RDMA/hns: Fix missing xa_destroy()
    - RDMA/hns: Fix wrong value of max_sge_rd
    - Bluetooth: Fix error code in chan_alloc_skb_cb()
    - Bluetooth: hci_event: Fix connection regression between LE and non-LE
      adapters
    - accel/qaic: Fix possible data corruption in BOs > 2G
    - ARM: davinci: da850: fix selecting ARCH_DAVINCI_DA8XX
    - ipv6: Fix memleak of nhc_pcpu_rth_output in fib_check_nh_v6_gw().
    - ipv6: Set errno after ip_fib_metrics_init() in ip6_route_info_create().
    - devlink: fix xa_alloc_cyclic() error handling
    - dpll: fix xa_alloc_cyclic() error handling
    - gpu: host1x: Do not assume that a NULL domain means no DMA IOMMU
    - net: atm: fix use after free in lec_send()
    - net: lwtunnel: fix recursion loops
    - net: ipv6: ioam6: fix lwtunnel_output() loop
    - libfs: Fix duplicate directory entry in offset_dir_lookup
    - net/neighbor: add missing policy for NDTPA_QUEUE_LENBYTES
    - i2c: omap: fix IRQ storms
    - net: mana: Support holes in device list reply msg
    - can: rcar_canfd: Fix page entries in the AFL list
    - can: ucan: fix out of bound read in strscpy() source
    - can: flexcan: only change CAN state when link up in system PM
    - can: flexcan: disable transceiver during system PM
    - drm/xe: Fix exporting xe buffers multiple times
    - drm/v3d: Don't run jobs that have errors flagged in its fence
    - riscv: dts: starfive: Fix a typo in StarFive JH7110 pin function
      definitions
    - regulator: dummy: force synchronous probing
    - regulator: check that dummy regulator has been probed before using it
    - accel/qaic: Fix integer overflow in qaic_validate_req()
    - arm64: dts: freescale: imx8mp-verdin-dahlia: add Microphone Jack to
      sound card
    - arm64: dts: freescale: imx8mm-verdin-dahlia: add Microphone Jack to
      sound card
    - arm64: dts: rockchip: fix pinmux of UART0 for PX30 Ringneck on Haikou
    - mmc: sdhci-brcmstb: add cqhci suspend/resume to PM ops
    - mmc: atmel-mci: Add missing clk_disable_unprepare()
    - mm: fix error handling in __filemap_get_folio() with FGP_NOWAIT
    - mm/migrate: fix shmem xarray update during migration
    - proc: fix UAF in proc_get_inode()
    - ARM: dts: imx6qdl-apalis: Fix poweroff on Apalis iMX6
    - ARM: shmobile: smp: Enforce shmobile_smp_* alignment
    - efi/libstub: Avoid physical address 0x0 when doing random allocation
    - xsk: fix an integer overflow in xp_create_and_assign_umem()
    - batman-adv: Ignore own maximum aggregation size during RX
    - soc: qcom: pdr: Fix the potential deadlock
    - pmdomain: amlogic: fix T7 ISP secpower
    - drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse()
    - drm/sched: Fix fence reference count leak
    - drm/amd/display: Fix message for support_edp0_on_dp1
    - drm/amd/pm: add unique_id for gfx12
    - drm/amdgpu: Remove JPEG from vega and carrizo video caps
    - drm/amdgpu: Fix MPEG2, MPEG4 and VC1 video caps max size
    - drm/amdgpu: Fix JPEG video caps max size for navi1x and raven
    - ksmbd: fix incorrect validation for num_aces field of smb_acl
    - KVM: arm64: Mark some header functions as inline
    - arm64: dts: rockchip: fix u2phy1_host status for NanoPi R4S
    - mptcp: Fix data stream corruption in the address announcement
    - net: lwtunnel: disable BHs when required
    - Upstream stable to v6.6.84, v6.6.85, v6.12.21
  * Noble update: upstream stable patchset 2025-07-28 (LP: #2118927)
    - drm/i915/xe2lpd: Move D2D enable/disable
    - drm/i915/ddi: Fix HDMI port width programming in DDI_BUF_CTL
    - ibmvnic: Perform tx CSO during send scrq direct
    - ibmvnic: Inspect header requirements before using scrq direct
    - drm/amdgpu: Check extended configuration space register when system uses
      large bar
    - drm/amdgpu: disable BAR resize on Dell G5 SE
    - net: enetc: Remove setting of RX software timestamp
    - net: enetc: Replace ifdef with IS_ENABLED
    - net: enetc: VFs do not support HWTSTAMP_TX_ONESTEP_SYNC
    - NFS: O_DIRECT writes must check and adjust the file length
    - riscv: cacheinfo: remove the useless input parameter (node) of
      ci_leaf_init()
    - riscv: cacheinfo: initialize cacheinfo's level and type from ACPI PPTT
    - riscv: Prevent a bad reference count on CPU nodes
    - riscv: cacheinfo: Use of_property_present() for non-boolean properties
    - mm: hugetlb: Add huge page size param to huge_ptep_get_and_clear()
    - arm64: hugetlb: Fix huge_ptep_get_and_clear() for non-present ptes
    - drm/i915/dsi: Use TRANS_DDI_FUNC_CTL's own port width macro
    - x86/mm: Don't disable PCID when INVLPG has been fixed by microcode
    - ima: Reset IMA_NONACTION_RULE_FLAGS after post_setattr
    - x86/boot: Sanitize boot params before parsing command line
    - fbdev: hyperv_fb: iounmap() the correct memory when removing a device
    - pinctrl: bcm281xx: Fix incorrect regmap max_registers value
    - pinctrl: nuvoton: npcm8xx: Add NULL check in npcm8xx_gpio_fw
    - netfilter: nft_ct: Use __refcount_inc() for per-CPU
      nft_ct_pcpu_template.
    - ice: fix memory leak in aRFS after reset
    - netfilter: nf_conncount: garbage collection is not skipped when jiffies
      wrap around
    - netfilter: nf_tables: make destruction work queue pernet
    - sched: address a potential NULL pointer dereference in the GRED
      scheduler.
    - wifi: iwlwifi: mvm: fix PNVM timeout for non-MSI-X platforms
    - wifi: mac80211: don't queue sdata::work for a non-running sdata
    - wifi: cfg80211: cancel wiphy_work before freeing wiphy
    - Bluetooth: hci_event: Fix enabling passive scanning
    - net/mlx5: Fill out devlink dev info only for PFs
    - net: dsa: mv88e6xxx: Verify after ATU Load ops
    - net: mctp i3c: Copy headers if cloned
    - net: mctp i2c: Copy headers if cloned
    - netpoll: hold rcu read lock in __netpoll_send_skb()
    - drm/hyperv: Fix address space leak when Hyper-V DRM device is removed
    - fbdev: hyperv_fb: Fix hang in kdump kernel when on Hyper-V Gen 2 VMs
    - fbdev: hyperv_fb: Simplify hvfb_putmem
    - fbdev: hyperv_fb: Allow graceful removal of framebuffer
    - Drivers: hv: vmbus: Don't release fb_mmio resource in vmbus_free_mmio()
    - net/mlx5: handle errors in mlx5_chains_create_table()
    - eth: bnxt: fix truesize for mb-xdp-pass case
    - eth: bnxt: do not update checksum in bnxt_xdp_build_skb()
    - net: switchdev: Convert blocking notification chain to a raw one
    - net: mctp: unshare packets when reassembling
    - bonding: fix incorrect MAC address setting to receive NS messages
    - netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in
      insert_tree()
    - ipvs: prevent integer overflow in do_ip_vs_get_ctl()
    - netfilter: nft_exthdr: fix offset with ipv4_find_option()
    - net: openvswitch: remove misbehaving actions length check
    - net/mlx5: Lag, Check shared fdb before creating MultiPort E-Switch
    - net/mlx5: Bridge, fix the crash caused by LAG state check
    - net/mlx5e: Prevent bridge link show failure for non-eswitch-allowed
      devices
    - nvme-fc: go straight to connecting state when initializing
    - nvme-fc: do not ignore connectivity loss during connecting
    - hrtimers: Mark is_migration_base() with __always_inline
    - powercap: call put_device() on an error path in
      powercap_register_control_type()
    - futex: Pass in task to futex_queue()
    - sched/debug: Provide slice length for fair tasks
    - platform/x86/intel: pmc: fix ltr decode in pmc_core_ltr_show()
    - scsi: core: Use GFP_NOIO to avoid circular locking dependency
    - scsi: ufs: core: Fix error return with query response
    - scsi: qla1280: Fix kernel oops when debug level > 2
    - ACPI: resource: IRQ override for Eluktronics MECH-17
    - smb: client: fix noisy when tree connecting to DFS interlink targets
    - alpha/elf: Fix misc/setarch test of util-linux by removing 32bit support
    - vboxsf: fix building with GCC 15
    - HID: intel-ish-hid: fix the length of MNG_SYNC_FW_CLOCK in doorbell
    - HID: intel-ish-hid: Send clock sync message immediately after reset
    - HID: ignore non-functional sensor in HP 5MP Camera
    - HID: hid-steam: Fix issues with disabling both gamepad mode and lizard
      mode
    - usb: phy: generic: Use proper helper for property detection
    - HID: topre: Fix n-key rollover on Realforce R3S TKL boards
    - HID: hid-apple: Apple Magic Keyboard a3203 USB-C support
    - HID: apple: fix up the F6 key on the Omoton KB066 keyboard
    - objtool: Ignore dangling jump table entries
    - sched: Clarify wake_up_q()'s write to task->wake_q.next
    - platform/x86: thinkpad_acpi: Fix invalid fan speed on ThinkPad X120e
    - platform/x86: thinkpad_acpi: Support for V9 DYTC platform profiles
    - platform/x86: int3472: Use str_high_low()
    - platform/x86: int3472: Use GPIO_LOOKUP() macro
    - platform/x86: int3472: Use correct type for "polarity", call it
      gpio_flags
    - platform/x86: int3472: Call "reset" GPIO "enable" for INT347E
    - s390/cio: Fix CHPID "configure" attribute caching
    - thermal/cpufreq_cooling: Remove structure member documentation
    - LoongArch: KVM: Set host with kernel mode when switch to VM mode
    - arm64: amu: Delay allocating cpumask for AMU FIE support
    - Xen/swiotlb: mark xen_swiotlb_fixup() __init
    - Bluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd
    - selftests/bpf: Fix invalid flag of recv()
    - ASoC: Intel: sof_sdw: Add lookup of quirk using PCI subsystem ID
    - ASoC: simple-card-utils.c: add missing dlc->of_node
    - ALSA: hda/realtek: Limit mic boost on Positivo ARN50
    - ASoC: rsnd: indicate unsupported clock rate
    - ASoC: rsnd: don't indicate warning on rsnd_kctrl_accept_runtime()
    - ASoC: rsnd: adjust convert rate limitation
    - ASoC: arizona/madera: use fsleep() in up/down DAPM event delays.
    - ASoC: SOF: Intel: hda: add softdep pre to snd-hda-codec-hdmi module
    - ASoC: SOF: amd: Add post_fw_run_delay ACP quirk
    - ASoC: SOF: amd: Handle IPC replies before FW_BOOT_COMPLETE
    - net: wwan: mhi_wwan_mbim: Silence sequence number glitch errors
    - io-wq: backoff when retrying worker creation
    - nvme-pci: quirk Acer FA100 for non-uniqueue identifiers
    - nvmet-rdma: recheck queue state is LIVE in state lock in recv done
    - apple-nvme: Release power domains when probe fails
    - cifs: Treat unhandled directory name surrogate reparse points as mount
      directory nodes
    - sctp: Fix undefined behavior in left shift operation
    - nvme: only allow entering LIVE from CONNECTING state
    - phy: ti: gmii-sel: Simplify with dev_err_probe()
    - phy: ti: gmii-sel: Do not use syscon helper to build regmap
    - ASoC: tas2770: Fix volume scale
    - ASoC: tas2764: Fix power control mask
    - ASoC: tas2764: Set the SDOUT polarity correctly
    - fuse: don't truncate cached, mutated symlink
    - drm/vkms: Round fixp2int conversion in lerp_u16
    - perf/x86/intel: Use better start period for frequency mode
    - x86/irq: Define trace events conditionally
    - mptcp: safety check before fallback
    - drm/nouveau: Do not override forced connector status
    - net: Handle napi_schedule() calls from non-interrupt
    - block: fix 'kmem_cache of name 'bio-108' already exists'
    - cifs: Validate content of WSL reparse point buffers
    - cifs: Throw -EOPNOTSUPP error on unsupported reparse point type from
      parse_reparse_point()
    - Input: ads7846 - fix gpiod allocation
    - Input: iqs7222 - preserve system status register
    - Input: xpad - add 8BitDo SN30 Pro, Hyperkin X91 and Gamesir G7 SE
      controllers
    - Input: xpad - add multiple supported devices
    - Input: xpad - add support for ZOTAC Gaming Zone
    - Input: xpad - add support for TECNO Pocket Go
    - Input: xpad - rename QH controller to Legion Go S
    - Input: i8042 - swap old quirk combination with new quirk for NHxxRZQ
    - Input: i8042 - add required quirks for missing old boardnames
    - Input: i8042 - swap old quirk combination with new quirk for several
      devices
    - Input: i8042 - swap old quirk combination with new quirk for more
      devices
    - USB: serial: ftdi_sio: add support for Altera USB Blaster 3
    - USB: serial: option: add Telit Cinterion FE990B compositions
    - USB: serial: option: fix Telit Cinterion FE990A name
    - USB: serial: option: match on interface class for Telit FN990B
    - x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes
    - drm/i915/cdclk: Do cdclk post plane programming later
    - drm/atomic: Filter out redundant DPMS calls
    - drm/dp_mst: Fix locking when skipping CSN before topology probing
    - drm/amd/amdkfd: Evict all queues even HWS remove queue failed
    - drm/amd/display: Disable unneeded hpd interrupts during dm_init
    - drm/amd/display: Restore correct backlight brightness after a GPU reset
    - drm/amd/display: Assign normalized_pix_clk when color depth = 14
    - drm/amd/display: Fix slab-use-after-free on hdcp_work
    - ksmbd: fix use-after-free in ksmbd_free_work_struct
    - ksmbd: prevent connection release during oplock break notification
    - clk: samsung: update PLL locktime for PLL142XX used on FSD platform
    - clk: samsung: gs101: fix synchronous external abort in
      samsung_clk_save()
    - ASoC: amd: yc: Support mic on another Lenovo ThinkPad E16 Gen 2 model
    - dm-flakey: Fix memory corruption in optional corrupt_bio_byte feature
    - arm64: mm: Populate vmemmap at the page level if not section aligned
    - Fix mmu notifiers for range-based invalidates
    - qlcnic: fix memory leak issues in qlcnic_sriov_common.c
    - smb: client: fix regression with guest option
    - net: phy: nxp-c45-tja11xx: add TJA112X PHY configuration errata
    - net: phy: nxp-c45-tja11xx: add TJA112XB SGMII PCS restart errata
    - ASoC: ops: Consistently treat platform_max as control value
    - rust: error: add missing newline to pr_warn! calls
    - drm/gma500: Add NULL check for pci_gfx_root in mid_get_vbt_data()
    - ASoC: cs42l43: Fix maximum ADC Volume
    - rust: init: add missing newline to pr_info! calls
    - ASoC: rt722-sdca: add missing readable registers
    - drm/xe: cancel pending job timer before freeing scheduler
    - drm/xe: Release guc ids before cancelling work
    - ASoC: codecs: wm0010: Fix error handling path in wm0010_spi_probe()
    - scripts: generate_rust_analyzer: add missing macros deps
    - scripts: generate_rust_analyzer: add missing include_dirs
    - scripts: generate_rust_analyzer: add uapi crate
    - cifs: Fix integer overflow while processing acregmax mount option
    - cifs: Fix integer overflow while processing acdirmax mount option
    - cifs: Fix integer overflow while processing actimeo mount option
    - cifs: Fix integer overflow while processing closetimeo mount option
    - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware
      hypervisors
    - i2c: ali1535: Fix an error handling path in ali1535_probe()
    - i2c: ali15x3: Fix an error handling path in ali15x3_probe()
    - i2c: sis630: Fix an error handling path in sis630_probe()
    - mm/hugetlb: wait for hugetlb folios to be freed
    - smb3: add support for IAKerb
    - smb: client: Fix match_session bug preventing session reuse
    - Bluetooth: L2CAP: Fix corrupted list in hci_chan_del
    - nvme-fc: rely on state transitions to handle connectivity loss
    - HID: apple: disable Fn key handling on the Omoton KB066
    - Input: xpad - fix two controller table values
    - cifs: Ensure that all non-client-specific reparse points are processed
      by the server
    - wifi: cfg80211: init wiphy_work before allocating rfkill fails
    - ksmbd: fix r_count dec/increment mismatch
    - nvme: unblock ctrl state transition for firmware update
    - Upstream stable to v6.6.83, v6.12.20
  * Noble update: upstream stable patchset 2025-07-22 (LP: #2117533)
    - x86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range()
    - gpio: vf610: use generic device_get_match_data()
    - gpio: vf610: add locking to gpio direction functions
    - cifs: Remove symlink member from cifs_open_info_data union
    - smb311: failure to open files of length 1040 when mounting with SMB3.1.1
      POSIX extensions
    - btrfs: fix data overwriting bug during buffered write when block size <
      page size
    - x86/microcode/AMD: Add some forgotten models to the SHA check
    - rust: workqueue: remove unneeded ``#[allow(clippy::new_ret_no_self)]`
    - rust: init: remove unneeded `#[allow(clippy::disallowed_names)]`
    - rust: introduce `.clippy.toml`
    - rust: replace `clippy::dbg_macro` with `disallowed_macros`
    - rust: provide proper code documentation titles
    - rust: enable Clippy's `check-private-items`
    - Documentation: rust: add coding guidelines on lints
    - Documentation: rust: discuss `#[expect(...)]` in the guidelines
    - rust: error: make conversion functions public
    - rust: error: optimize error type to use nonzero
    - rust: error: check for config `test` in `Error::name`
    - rust: fix size_t in bindgen prototypes of C builtins
    - rust: map `__kernel_size_t` and friends also to usize/isize
    - tracing: tprobe-events: Fix a memory leak when tprobe with $retval
    - LoongArch: Convert unreachable() to BUG()
    - LoongArch: Use polling play_dead() when resuming from hibernation
    - LoongArch: Set max_pfn with the PFN of the last page
    - LoongArch: KVM: Add interrupt checking for AVEC
    - LoongArch: KVM: Reload guest CSR registers after sleep
    - LoongArch: KVM: Fix GPA size issue about VM
    - HID: appleir: Fix potential NULL dereference at raw event handle
    - ksmbd: fix type confusion via race condition when using
      ipc_msg_send_request
    - ksmbd: fix out-of-bounds in parse_sec_desc()
    - ksmbd: fix use-after-free in smb2_lock
    - ksmbd: fix bug on trap in smb2_lock
    - gpio: rcar: Use raw_spinlock to protect register access
    - ALSA: seq: Avoid module auto-load handling at event delivery
    - ALSA: hda: intel: Add Dell ALC3271 to power_save denylist
    - ALSA: hda/realtek: update ALC222 depop optimize
    - btrfs: fix a leaked chunk map issue in read_one_chunk()
    - hwmon: (peci/dimmtemp) Do not provide fake thresholds data
    - drm/amd/display: Fix null check for pipe_ctx->plane_state in
      resource_build_scaling_params
    - drm/imagination: avoid deadlock on fence release
    - drm/imagination: Hold drm_gem_gpuva lock for unmap
    - drm/imagination: only init job done fences once
    - drm/radeon: Fix rs400_gpu_init for ATI mobility radeon Xpress 200M
    - platform/x86: thinkpad_acpi: Add battery quirk for ThinkPad X131e
    - x86/cacheinfo: Validate CPUID leaf 0x2 EDX output
    - x86/cpu: Validate CPUID leaf 0x2 EDX output
    - x86/cpu: Properly parse CPUID leaf 0x2 TLB descriptor 0x63
    - Bluetooth: Add check for mgmt_alloc_skb() in mgmt_remote_name()
    - Bluetooth: Add check for mgmt_alloc_skb() in mgmt_device_connected()
    - wifi: cfg80211: regulatory: improve invalid hints checking
    - wifi: nl80211: reject cooked mode if it is set along with other flags
    - rapidio: add check for rio_add_net() in rio_scan_alloc_net()
    - rapidio: fix an API misues when rio_add_net() fails
    - dma: kmsan: export kmsan_handle_dma() for modules
    - s390/traps: Fix test_monitor_call() inline assembly
    - NFS: fix nfs_release_folio() to not deadlock via kcompactd writeback
    - userfaultfd: do not block on locking a large folio with raised refcount
    - block: fix conversion of GPT partition name to 7-bit
    - mm/page_alloc: fix uninitialized variable
    - mm: don't skip arch_sync_kernel_mappings() in error paths
    - wifi: iwlwifi: mvm: don't try to talk to a dead firmware
    - wifi: iwlwifi: limit printed string from FW file
    - HID: google: fix unused variable warning under !CONFIG_ACPI
    - HID: intel-ish-hid: Fix use-after-free issue in hid_ishtp_cl_remove()
    - HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove()
    - bluetooth: btusb: Initialize .owner field of force_poll_sync_fops
    - nvme-tcp: add basic support for the C2HTermReq PDU
    - nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()
    - net: gso: fix ownership in __udp_gso_segment
    - caif_virtio: fix wrong pointer check in cfv_probe()
    - perf/core: Fix pmus_lock vs. pmus_srcu ordering
    - hwmon: (pmbus) Initialise page count in pmbus_identify()
    - hwmon: (ntc_thermistor) Fix the ncpXXxh103 sensor table
    - hwmon: (ad7314) Validate leading zero bits and return error
    - tracing: probe-events: Remove unused MAX_ARG_BUF_LEN macro
    - drm/imagination: Fix timestamps in firmware traces
    - ALSA: usx2y: validate nrpacks module parameter on probe
    - llc: do not use skb_get() before dev_queue_xmit()
    - hwmon: fix a NULL vs IS_ERR_OR_NULL() check in xgene_hwmon_probe()
    - drm/sched: Fix preprocessor guard
    - be2net: fix sleeping while atomic bugs in be_ndo_bridge_getlink
    - net: hns3: make sure ptp clock is unregister and freed if
      hclge_ptp_get_cycle returns an error
    - net: ipa: Fix v4.7 resource group names
    - net: ipa: Fix QSB data for v4.7
    - net: ipa: Enable checksum for IPA_ENDPOINT_AP_MODEM_{RX,TX} for v4.7
    - ppp: Fix KMSAN uninit-value warning with bpf
    - vlan: enforce underlying device type
    - x86/sgx: Fix size overflows in sgx_encl_create()
    - exfat: fix soft lockup in exfat_clear_bitmap
    - exfat: short-circuit zero-byte writes in exfat_file_write_iter
    - net-timestamp: support TCP GSO case for a few missing flags
    - ublk: set_params: properly check if parameters can be applied
    - sched/fair: Fix potential memory corruption in child_cfs_rq_on_list
    - nvme-tcp: fix signedness bug in nvme_tcp_init_connection()
    - net: dsa: mt7530: Fix traffic flooding for MMIO devices
    - mctp i3c: handle NULL header address
    - net: ipv6: fix dst ref loop in ila lwtunnel
    - net: ipv6: fix missing dst ref drop in ila lwtunnel
    - gpio: rcar: Fix missing of_node_put() call
    - usb: renesas_usbhs: Call clk_put()
    - usb: renesas_usbhs: Use devm_usb_get_phy()
    - usb: hub: lack of clearing xHC resources
    - usb: quirks: Add DELAY_INIT and NO_LPM for Prolific Mass Storage Card
      Reader
    - usb: typec: ucsi: Fix NULL pointer access
    - usb: renesas_usbhs: Flush the notify_hotplug_work
    - usb: gadget: u_ether: Set is_suspend flag if remote wakeup fails
    - usb: atm: cxacru: fix a flaw in existing endpoint checks
    - usb: dwc3: Set SUSPENDENABLE soon after phy init
    - usb: dwc3: gadget: Prevent irq storm when TH re-executes
    - usb: typec: ucsi: increase timeout for PPM reset operations
    - usb: typec: tcpci_rt1711h: Unmask alert interrupts to fix functionality
    - usb: gadget: Set self-powered based on MaxPower and bmAttributes
    - usb: gadget: Fix setting self-powered state on suspend
    - usb: gadget: Check bmAttributes only if configuration is valid
    - kbuild: userprogs: use correct lld when linking through clang
    - xhci: pci: Fix indentation in the PCI device ID definitions
    - usb: xhci: Enable the TRB overfetch quirk on VIA VL805
    - KVM: SVM: Set RFLAGS.IF=1 in C code, to get VMRUN out of the STI shadow
    - KVM: SVM: Drop DEBUGCTL[5:2] from guest's effective value
    - KVM: SVM: Suppress DEBUGCTL.BTF on AMD
    - KVM: x86: Snapshot the host's DEBUGCTL in common x86
    - KVM: SVM: Manually context switch DEBUGCTL if LBR virtualization is
      disabled
    - KVM: x86: Snapshot the host's DEBUGCTL after disabling IRQs
    - KVM: x86: Explicitly zero EAX and EBX when PERFMON_V2 isn't supported by
      KVM
    - cdx: Fix possible UAF error in driver_override_show()
    - mei: me: add panther lake P DID
    - mei: vsc: Use "wakeuphostint" when getting the host wakeup GPIO
    - intel_th: pci: Add Arrow Lake support
    - intel_th: pci: Add Panther Lake-H support
    - intel_th: pci: Add Panther Lake-P/U support
    - slimbus: messaging: Free transaction ID in delayed interrupt scenario
    - bus: mhi: host: pci_generic: Use pci_try_reset_function() to avoid
      deadlock
    - eeprom: digsy_mtc: Make GPIO lookup table match the device
    - drivers: virt: acrn: hsm: Use kzalloc to avoid info leak in pmcmd_ioctl
    - iio: filter: admv8818: Force initialization of SDO
    - iio: dac: ad3552r: clear reset status flag
    - iio: adc: ad7192: fix channel select
    - iio: adc: at91-sama5d2_adc: fix sama7g5 realbits value
    - kbuild: hdrcheck: fix cross build with clang
    - nvme-tcp: Fix a C2HTermReq error message
    - docs: rust: remove spurious item in `expect` list
    - Upstream stable to v6.6.82, v6.12.19
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878)
    - IB/mlx5: Set and get correct qp_num for a DCT QP
    - RDMA/mana_ib: Allocate PAGE aligned doorbell index
    - scsi: ufs: core: Fix ufshcd_is_ufs_dev_busy() and ufshcd_eh_timed_out()
    - SUNRPC: convert RPC_TASK_* constants to enum
    - SUNRPC: Prevent looping due to rpc_signal_task() races
    - SUNRPC: Handle -ETIMEDOUT return from tlshd
    - RDMA/mlx5: Fix AH static rate parsing
    - scsi: core: Clear driver private data when retrying request
    - RDMA/mlx5: Fix bind QP error cleanup flow
    - sunrpc: suppress warnings for unused procfs functions
    - ALSA: usb-audio: Avoid dropping MIDI events at closing multiple ports
    - Bluetooth: L2CAP: Fix L2CAP_ECRED_CONN_RSP response
    - rxrpc: rxperf: Fix missing decoding of terminal magic cookie
    - afs: Fix the server_list to unuse a displaced server rather than putting
      it
    - net: loopback: Avoid sending IP packets without an Ethernet header
    - net: set the minimum for net_hotdata.netdev_budget_usecs
    - net/ipv4: add tracepoint for icmp_send
    - ipv4: icmp: Pass full DS field to ip_route_input()
    - ipv4: icmp: Unmask upper DSCP bits in icmp_route_lookup()
    - ipvlan: Unmask upper DSCP bits in ipvlan_process_v4_outbound()
    - ipv4: Convert icmp_route_lookup() to dscp_t.
    - ipv4: Convert ip_route_input() to dscp_t.
    - ipvlan: Prepare ipvlan_process_v4_outbound() to future .flowi4_tos
      conversion.
    - net: cadence: macb: Synchronize stats calculations
    - ASoC: es8328: fix route from DAC to output
    - ipvs: Always clear ipvs_property flag in skb_scrub_packet()
    - firmware: cs_dsp: Remove async regmap writes
    - ALSA: hda/realtek: Fix wrong mic setup for ASUS VivoBook 15
    - ice: add E830 HW VF mailbox message limit support
    - tcp: Defer ts_recent changes until req is owned
    - net: Clear old fragment checksum value in napi_reuse_skb
    - net: mvpp2: cls: Fixed Non IP flow, with vlan tag flow defination.
    - net/mlx5: IRQ, Fix null string in debug print
    - net: ipv6: fix dst ref loop on input in seg6 lwt
    - net: ipv6: fix dst ref loop on input in rpl lwt
    - net: ti: icss-iep: Remove spinlock-based synchronization
    - net: ti: icss-iep: Reject perout generation request
    - io_uring/net: save msg_control for compat
    - x86/CPU: Fix warm boot hang regression on AMD SC1100 SoC systems
    - phy: rockchip: naneng-combphy: compatible reset with old DT
    - RISCV: KVM: Introduce mp_state_lock to avoid lock inversion
    - riscv: KVM: Fix hart suspend status check
    - riscv: KVM: Fix SBI IPI error generation
    - riscv: KVM: Fix SBI TIME error generation
    - ALSA: usb-audio: Re-add sample rate quirk for Pioneer DJM-900NXS2
    - ALSA: hda/realtek: Fix microphone regression on ASUS N705UD
    - perf/x86: Fix low freqency setting issue
    - perf/core: Fix low freq setting via IOC_PERIOD
    - drm/amd/display: Disable PSR-SU on eDP panels
    - drm/amd/display: Fix HPD after gpu reset
    - i2c: ls2x: Fix frequency division register access
    - net: enetc: fix the off-by-one issue in enetc_map_tx_buffs()
    - net: enetc: keep track of correct Tx BD count in
      enetc_map_tx_tso_buffs()
    - net: enetc: update UDP checksum when updating originTimestamp field
    - net: enetc: correct the xdp_tx statistics
    - net: enetc: fix the off-by-one issue in enetc_map_tx_tso_buffs()
    - phy: tegra: xusb: reset VBUS & ID OVERRIDE
    - phy: exynos5-usbdrd: fix MPLL_MULTIPLIER and SSC_REFCLKSEL masks in
      refclk
    - mptcp: reset when MPTCP opts are dropped after join
    - vmlinux.lds: Ensure that const vars with relocations are mapped R/O
    - rcuref: Plug slowpath race in rcuref_put()
    - rseq/selftests: Fix riscv rseq_offset_deref_addv inline asm
    - riscv/futex: sign extend compare value in atomic cmpxchg
    - riscv: signal: fix signal frame size
    - rtla/timerlat_hist: Set OSNOISE_WORKLOAD for kernel threads
    - rtla/timerlat_top: Set OSNOISE_WORKLOAD for kernel threads
    - amdgpu/pm/legacy: fix suspend/resume issues
    - gve: set xdp redirect target only when it is available
    - x86/microcode/AMD: Use the family,model,stepping encoded in the patch ID
    - x86/microcode/AMD: Pay attention to the stepping dynamically
    - x86/microcode/AMD: Split load_microcode_amd()
    - x86/microcode/intel: Remove unnecessary cache writeback and invalidation
    - x86/microcode/AMD: Flush patch buffer mapping after application
    - x86/microcode/AMD: Return bool from find_blobs_in_containers()
    - x86/microcode/AMD: Make __verify_patch_size() return bool
    - x86/microcode/AMD: Have __apply_microcode_amd() return bool
    - x86/microcode/AMD: Merge early_apply_microcode() into its single
      callsite
    - x86/microcode/AMD: Get rid of the _load_microcode_amd() forward
      declaration
    - x86/microcode/AMD: Add get_patch_level()
    - x86/microcode/AMD: Load only SHA256-checksummed patches
    - x86/microcode/AMD: Fix a -Wsometimes-uninitialized clang false positive
    - RDMA/mlx5: Fix a race for DMABUF MR which can lead to CQE with error
    - RDMA/hns: Fix mbox timing out by adding retry mechanism
    - RDMA/bnxt_re: Allocate dev_attr information dynamically
    - RDMA/bnxt_re: Fix the statistics for Gen P7 VF
    - landlock: Fix non-TCP sockets restriction
    - RDMA/mlx5: Fix implicit ODP hang on parent deregistration
    - scsi: ufs: core: Set default runtime/system PM levels before
      ufshcd_hba_init()
    - afs: Give an afs_server object a ref on the afs_cell object it points to
    - ASoC: cs35l56: Prevent races when soft-resetting using SPI control
    - thermal: gov_power_allocator: Fix incorrect calculation in
      divvy_up_power()
    - unreachable: Unify
    - objtool: Remove annotate_{,un}reachable()
    - objtool: Fix C jump table annotations for Clang
    - riscv: KVM: Fix hart suspend_type use
    - KVM: arm64: Ensure a VMID is allocated before programming VTTBR_EL2
    - drm/xe/regs: remove a duplicate definition for RING_CTL_SIZE(size)
    - drm/xe/userptr: restore invalidation list on error
    - drm/amdkfd: Preserve cp_hqd_pq_control on update_mqd
    - drm/amd/display: Add option to configure mapping policy for edp0 on dp1
    - drm/amd/display: add a quirk to enable eDP0 on DP1
    - intel_idle: Handle older CPUs, which stop the TSC in deeper C states,
      correctly
    - selftests/landlock: Test that MPTCP actions are not restricted
    - selftests/landlock: Test TCP accesses with protocol=IPPROTO_TCP
    - riscv: signal: fix signal_minsigstksz
    - x86/microcode/AMD: Remove ugly linebreak in __verify_patch_section()
      signature
    - x86/microcode/AMD: Remove unused save_microcode_in_initrd_amd()
      declarations
    - Upstream stable to v6.6.81, v6.12.18
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2025-21872
    - efi: Don't map the entire mokvar table to determine its size
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2025-21880
    - drm/xe/userptr: fix EFAULT handling
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2025-21890
    - idpf: fix checksums set in idpf_rx_rsc()
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2025-21885
    - RDMA/bnxt_re: Fix the page details for the srq created by kernel
      consumers
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2025-21888
    - RDMA/mlx5: Fix a WARN during dereg_mr for DM type
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2025-21892
    - RDMA/mlx5: Fix the recovery flow of the UMR QP
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2025-21873
    - scsi: ufs: core: bsg: Fix crash when arpmb command fails
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2024-58090
    - sched/core: Prevent rescheduling when interrupts are disabled
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2025-21875
    - mptcp: always handle address removal under msk socket lock
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2025-21877
    - usbnet: gl620a: fix endpoint checking in genelink_bind()
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2025-21878
    - i2c: npcm: disable interrupt enable bit before devm_request_irq
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2025-21889
    - perf/core: Add RCU read lock protection to perf_iterate_ctx()
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2025-21898
    - ftrace: Avoid potential division by zero in function_stat_show()
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2025-21899
    - tracing: Fix bad hist from corrupting named_triggers list
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2025-21881
    - uprobes: Reject the shared zeropage in uprobe_write_opcode()
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2025-21895
    - perf/core: Order the PMU list to fix warning about unordered
      pmu_ctx_list
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2025-21883
    - ice: Fix deinitializing VF in error path
  * Noble update: upstream stable patchset 2025-07-14 (LP: #2116878) //
    CVE-2025-21891
    - ipvlan: ensure network headers are in skb linear part
  * CVE-2024-57996 // CVE-2025-37752
    - net_sched: sch_sfq: move the limit validation
  * CVE-2025-38350
    - net/sched: Always pass notifications when child class becomes empty
  * CVE-2025-21887
    - ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up

  [ Ubuntu: 6.8.0-78.78 ]

  * noble/linux: 6.8.0-78.78 -proposed tracker (LP: #2120405)
  * Incorrect backport for CVE-2025-21861 causes kernel hangs
    (LP: #2120330) // CVE-2025-21861
    - mm/migrate_device: don't add folio to be freed to LRU in
      migrate_device_finalize()
  * Incorrect backport for CVE-2025-21861 causes kernel hangs (LP: #2120330)
    - SAUCE: Revert "mm/migrate_device: don't add folio to be freed to LRU in
      migrate_device_finalize()"
    - mm: migrate_device: use more folio in migrate_device_finalize()

  [ Ubuntu: 6.8.0-72.72 ]

  * noble/linux: 6.8.0-72.72 -proposed tracker (LP: #2117691)
  * Packaging resync (LP: #1786013)
    - [Packaging] update annotations scripts
    - [Packaging] debian.master/dkms-versions -- update from kernel-versions
      (main/2025.07.14)
  * NVMe namespace ID mismatch on repeated map/unmap (LP: #2115209)
    - nvme: requeue namespace scan on missed AENs
    - nvme: re-read ANA log page after ns scan completes
    - nvme: fixup scan failure for non-ANA multipath controllers
  * integrated I219-LM network adapter appears to be running too fast, causing
    synchronization issues when using the I219-LM PTP feature (LP: #2116072)
    - e1000e: set fixed clock frequency indication for Nahum 11 and Nahum 13
  * intel_rapl: support ARL-H hardware (LP: #2115652)
    - powercap: intel_rapl_msr: Add PL4 support for ArrowLake-H
  * Ubuntu 24.04+ arm64: screen resolution fixed to 1024x768 with last kernel
    update (LP: #2115068)
    - [Config] Replace FB_HYPERV with DRM_HYPERV
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212)
    - arm64: mte: Do not allow PROT_MTE on MAP_HUGETLB user mappings
    - xfs: assert a valid limit in xfs_rtfind_forw
    - xfs: validate inumber in xfs_iget
    - xfs: fix a sloppy memory handling bug in xfs_iroot_realloc
    - xfs: fix a typo
    - xfs: skip background cowblock trims on inodes open for write
    - xfs: don't free cowblocks from under dirty pagecache on unshare
    - xfs: merge xfs_attr_leaf_try_add into xfs_attr_leaf_addname
    - xfs: return bool from xfs_attr3_leaf_add
    - xfs: distinguish extra split from real ENOSPC from xfs_attr3_leaf_split
    - xfs: distinguish extra split from real ENOSPC from
      xfs_attr_node_try_addname
    - xfs: fold xfs_bmap_alloc_userdata into xfs_bmapi_allocate
    - xfs: don't ifdef around the exact minlen allocations
    - xfs: call xfs_bmap_exact_minlen_extent_alloc from xfs_bmap_btalloc
    - xfs: support lowmode allocations in xfs_bmap_exact_minlen_extent_alloc
    - xfs: Use try_cmpxchg() in xlog_cil_insert_pcp_aggregate()
    - xfs: Remove empty declartion in header file
    - xfs: pass the exact range to initialize to xfs_initialize_perag
    - xfs: update the file system geometry after recoverying superblock
      buffers
    - xfs: error out when a superblock buffer update reduces the agcount
    - xfs: don't use __GFP_RETRY_MAYFAIL in xfs_initialize_perag
    - xfs: update the pag for the last AG at recovery time
    - xfs: Reduce unnecessary searches when searching for the best extents
    - xfs: streamline xfs_filestream_pick_ag
    - xfs: Check for delayed allocations before setting extsize
    - md/md-bitmap: replace md_bitmap_status() with a new helper
      md_bitmap_get_stats()
    - md/md-cluster: fix spares warnings for __le64
    - md/md-bitmap: add 'sync_size' into struct md_bitmap_stats
    - mm: update mark_victim tracepoints fields
    - cpufreq: dt-platdev: add missing MODULE_DESCRIPTION() macro
    - cpufreq: fix using cpufreq-dt as module
    - Bluetooth: qca: Support downloading board id specific NVM for WCN7850
    - Bluetooth: qca: Update firmware-name to support board specific nvm
    - Bluetooth: qca: Fix poor RF performance for WCN6855
    - Input: serio - define serio_pause_rx guard to pause and resume serio
      ports
    - ASoC: renesas: rz-ssi: Add a check for negative sample_space
    - ASoC: rockchip: i2s-tdm: fix shift config for SND_SOC_DAIFMT_DSP_[AB]
    - powerpc/64s/mm: Move __real_pte stubs into hash-4k.h
    - powerpc/64s: Rewrite __real_pte() and __rpte_to_hidx() as static inline
    - ALSA: seq: Drop UMP events when no UMP-conversion is set
    - ibmvnic: Return error code on TX scrq flush fail
    - ibmvnic: Introduce send sub-crq direct
    - ibmvnic: Add stat for tx direct vs tx batched
    - vsock/bpf: Warn on socket without transport
    - tcp: adjust rcvq_space after updating scaling ratio
    - geneve: Suppress list corruption splat in geneve_destroy_tunnels().
    - flow_dissector: Fix handling of mixed port and port-range keys
    - flow_dissector: Fix port range key handling in BPF conversion
    - net: Add non-RCU dev_getbyhwaddr() helper
    - arp: switch to dev_getbyhwaddr() in arp_req_set_public()
    - net: axienet: Set mac_managed_pm
    - bpf: unify VM_WRITE vs VM_MAYWRITE use in BPF map mmaping logic
    - strparser: Add read_sock callback
    - bpf: Fix wrong copied_seq calculation
    - bpf: Disable non stream socket for strparser
    - power: supply: da9150-fg: fix potential overflow
    - nouveau/svm: fix missing folio unlock + put after
      make_device_exclusive_range()
    - drm/msm: Avoid rounding up to one jiffy
    - nvme/ioctl: add missing space in err message
    - bpf: skip non exist keys in generic_map_lookup_batch
    - drm/nouveau/pmu: Fix gp10b firmware guard
    - drm/msm/dpu: Disable dither in phys encoder cleanup
    - drm/i915: Make sure all planes in use by the joiner have their crtc
      included
    - drm/i915/dp: Fix error handling during 128b/132b link training
    - soc: loongson: loongson2_guts: Add check for devm_kstrdup()
    - lib/iov_iter: fix import_iovec_ubuf iovec management
    - ASoC: fsl_micfil: Enable default case in micfil_set_quality()
    - ALSA: hda: Add error check for snd_ctl_rename_id() in
      snd_hda_create_dig_out_ctls()
    - ALSA: hda/conexant: Add quirk for HP ProBook 450 G4 mute LED
    - ASoC: SOF: pcm: Clear the susbstream pointer to NULL on close
    - acct: block access to kernel internal filesystems
    - mm,madvise,hugetlb: check for 0-length range after end address
      adjustment
    - mtd: rawnand: cadence: fix error code in cadence_nand_init()
    - mtd: rawnand: cadence: use dma_map_resource for sdma address
    - mtd: rawnand: cadence: fix incorrect device in dma_unmap_single
    - EDAC/qcom: Correct interrupt enable register configuration
    - ftrace: Correct preemption accounting for function tracing.
    - ftrace: Do not add duplicate entries in subops manager ops
    - arm64: dts: rockchip: change eth phy mode to rgmii-id for orangepi r1
      plus lts
    - x86/cpu/kvm: SRSO: Fix possible missing IBPB on VM-Exit
    - KVM: x86: Get vcpu->arch.apic_base directly and drop kvm_get_apic_base()
    - KVM: x86: Inline kvm_get_apic_mode() in lapic.h
    - KVM: Introduce vcpu->wants_to_run
    - KVM: nVMX: Defer SVI update to vmcs01 on EOI when L2 is active w/o VID
    - drm/amd/display: Refactoring if and endif statements to enable DC_LOGGER
    - arm64: dts: mt8183: add dpi node to mt8183
    - arm64: dts: mt8183: Add port node to dpi node
    - arm64: dts: mediatek: mt8183-kukui: Disable DPI display interface
    - arm64: dts: mediatek: mt8183: Disable DPI display output by default
    - arm64: dts: mediatek: mt8183-pumpkin: add HDMI support
    - arm64: dts: mediatek: mt8183: Disable DSI display output by default
    - accel/ivpu: Limit FW version string length
    - accel/ivpu: Add coredump support
    - accel/ivpu: Add FW state dump on TDR
    - accel/ivpu: Fix error handling in recovery/reset
    - ASoC: SOF: topology: dynamically allocate and store DAI widget->private
    - ASoC: SOF: topology: Parse DAI type token for dspless mode
    - ASoC: imx-audmix: remove cpu_mclk which is from cpu dai device
    - vsock/virtio: fix variables initialization during resuming
    - drm/msm/dpu: skip watchdog timer programming through TOP on >= SM8450
    - drm/msm/dpu: Don't leak bits_per_component into random DSC_ENC fields
    - drm/msm/dsi/phy: Protect PHY_CMN_CLK_CFG0 updated from driver side
    - drm/msm/dsi/phy: Protect PHY_CMN_CLK_CFG1 against clock driver
    - drm/msm/dsi/phy: Do not overwite PHY_CMN_CLK_CFG1 when choosing bitclk
      source
    - nvme: tcp: Fix compilation warning with W=1
    - nvme-tcp: fix connect failure on receiving partial ICResp PDU
    - drm: panel: jd9365da-h3: fix reset signal polarity
    - io_uring/rw: forbid multishot async reads
    - arm64: dts: rockchip: Fix broken tsadc pinctrl names for rk3588
    - arm64: dts: rockchip: Move uart5 pin configuration to px30 ringneck SoM
    - arm64: dts: rockchip: Disable DMA for uart5 on px30-ringneck
    - s390/boot: Fix ESSA detection
    - xfs: fix online repair probing when CONFIG_XFS_ONLINE_REPAIR=n
    - smb: client: fix chmod(2) regression with ATTR_READONLY
    - tracing: Fix using ret variable in tracing_set_tracer()
    - selftests/mm: build with -O2
    - Upstream stable to v6.6.80, v6.12.17
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21861
    - mm/migrate_device: don't add folio to be freed to LRU in
      migrate_device_finalize()
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21868
    - net: allow small head cache usage with large MAX_SKB_FRAGS values
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21869
    - powerpc/code-patching: Disable KASAN report during patching via
      temporary mm
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21870
    - ASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21844
    - smb: client: Add check for next_buffer in receive_encrypted_standard()
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21846
    - acct: perform last write from workqueue
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21847
    - ASoC: SOF: stream-ipc: Check for cstream nullity in sof_ipc_msg_data()
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21848
    - nfp: bpf: Add check for nfp_app_ctrl_msg_alloc()
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21862
    - drop_monitor: fix incorrect initialization order
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21871
    - tee: optee: Fix supplicant wait loop
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21863
    - io_uring: prevent opcode speculation
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2024-58088
    - bpf: Fix deadlock when freeing cgroup storage
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21853
    - bpf: avoid holding freeze_mutex during mmap operation
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21867
    - bpf, test_run: Fix use-after-free issue in eth_skb_pkt_type()
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21864
    - tcp: drop secpath at the same time as we currently drop dst
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21854
    - sockmap, vsock: For connectible sockets allow only connected
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21855
    - ibmvnic: Don't reference skb after sending to VIOS
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21856
    - s390/ism: add release function for struct device
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21857
    - net/sched: cls_api: fix error handling causing NULL dereference
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21858
    - geneve: Fix use-after-free in geneve_find_dev().
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21866
    - powerpc/code-patching: Fix KASAN hit by not flagging text patching area
      as VM_ALLOC
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21859
    - USB: gadget: f_midi: f_midi_complete to call queue_work
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21746
    - Input: synaptics - fix crash when enabling pass-through port
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2024-57977
    - memcg: fix soft lockup in the OOM process
  * Noble update: upstream stable patchset 2025-07-09 (LP: #2116212) //
    CVE-2025-21712
    - md/md-bitmap: Synchronize bitmap_get_stats() with bitmap lifetime
  * CVE-2024-58093
    - PCI/ASPM: Fix link state exit during switch upstream function removal
  * [SRU]Request E825-C driver into latest LTS of Ubuntu OS 24.04
    (LP: #2114785)
    - ice: add support for 3k signing DDP sections for E825C
    - ice: Add helper function ice_is_generic_mac
    - ice: introduce new E825C devices family
  * [UBUNTU 22.04] kernel: Fix z17 elf platform recognition (LP: #2114450)
    - s390: Add z17 elf platform
  * [UBUNTU 24.04] Kernel: Add CPUMF extended counter set for z17
    (LP: #2114258)
    - s390/cpumf: Update CPU Measurement facility extended counter set support
  * Noble update: upstream stable patchset 2025-06-29 (LP: #2115616)
    - nfsd: clear acl_access/acl_default after releasing them
    - NFSD: fix hang in nfsd4_shutdown_callback
    - pinctrl: cy8c95x0: Respect IRQ trigger settings from firmware
    - HID: multitouch: Add NULL check in mt_input_configured
    - HID: hid-thrustmaster: fix stack-out-of-bounds read in
      usb_check_int_endpoints()
    - spi: sn-f-ospi: Fix division by zero
    - ax25: Fix refcount leak caused by setting SO_BINDTODEVICE sockopt
    - ndisc: ndisc_send_redirect() must use dev_get_by_index_rcu()
    - vrf: use RCU protection in l3mdev_l3_out()
    - vxlan: check vxlan_vnigroup_init() return value
    - LoongArch: Fix idle VS timer enqueue
    - LoongArch: csum: Fix OoB access in IP checksum code for negative lengths
    - team: better TEAM_OPTION_TYPE_STRING validation
    - arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array
    - cgroup: Remove steal time from usage_usec
    - drm/i915/selftests: avoid using uninitialized context
    - gpio: bcm-kona: Fix GPIO lock/unlock for banks above bank 0
    - gpio: bcm-kona: Make sure GPIO bits are unlocked when requesting IRQ
    - gpio: bcm-kona: Add missing newline to dev_err format string
    - drm/amdgpu: bail out when failed to load fw in psp_init_cap_microcode()
    - xen/swiotlb: relax alignment requirements
    - x86/xen: allow larger contiguous memory regions in PV guests
    - block: cleanup and fix batch completion adding conditions
    - gpiolib: Fix crash on error in gpiochip_get_ngpios()
    - tools: fix annoying "mkdir -p ..." logs when building tools in parallel
    - RDMA/efa: Reset device on probe failure
    - fbdev: omap: use threaded IRQ for LCD DMA
    - soc/tegra: fuse: Update Tegra234 nvmem keepout list
    - media: cxd2841er: fix 64-bit division on gcc-9
    - media: i2c: ds90ub913: Add error handling to ub913_hw_init()
    - media: i2c: ds90ub953: Add error handling for i2c reads/writes
    - media: uvcvideo: Implement dual stream quirk to fix loss of usb packets
    - media: uvcvideo: Add new quirk definition for the Sonix Technology Co.
      292a camera
    - media: uvcvideo: Add Kurokesu C1 PRO camera
    - media: vidtv: Fix a null-ptr-deref in vidtv_mux_stop_thread
    - PCI/DPC: Quirk PIO log size for Intel Raptor Lake-P
    - PCI: switchtec: Add Microchip PCI100X device IDs
    - scsi: ufs: bsg: Set bsg_queue to NULL after removal
    - rtla/timerlat_hist: Abort event processing on second signal
    - rtla/timerlat_top: Abort event processing on second signal
    - vfio/pci: Enable iowrite64 and ioread64 for vfio pci
    - NFS: Fix potential buffer overflowin nfs_sysfs_link_rpc_client()
    - Grab mm lock before grabbing pt lock
    - selftests: gpio: gpio-sim: Fix missing chip disablements
    - ACPI: x86: Add skip i2c clients quirk for Vexia EDU ATLA 10 tablet 5V
    - x86/mm/tlb: Only trim the mm_cpumask once a second
    - orangefs: fix a oob in orangefs_debug_write
    - ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla 10 tablet 5V
    - batman-adv: fix panic during interface removal
    - batman-adv: Ignore neighbor throughput metrics in error case
    - batman-adv: Drop unmanaged ELP metric worker
    - drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()
    - KVM: x86: Reject Hyper-V's SEND_IPI hypercalls if local APIC isn't in-
      kernel
    - KVM: nSVM: Enter guest mode before initializing nested NPT MMU
    - perf/x86/intel: Ensure LBRs are disabled when a CPU is starting
    - usb: gadget: f_midi: Fixing wMaxPacketSize exceeded issue during MIDI
      bind retries
    - usb: dwc3: Fix timeout issue during controller enter/exit from halt
      state
    - usb: roles: set switch registered flag early on
    - usb: gadget: udc: renesas_usb3: Fix compiler warning
    - usb: dwc2: gadget: remove of_node reference upon udc_stop
    - USB: pci-quirks: Fix HCCPARAMS register error for LS7A EHCI
    - usb: core: fix pipe creation for get_bMaxPacketSize0
    - USB: quirks: add USB_QUIRK_NO_LPM quirk for Teclast dist
    - USB: Add USB_QUIRK_NO_LPM quirk for sony xperia xz1 smartphone
    - usb: gadget: f_midi: fix MIDI Streaming descriptor lengths
    - USB: hub: Ignore non-compliant devices with too many configs or
      interfaces
    - USB: cdc-acm: Fill in Renesas R-Car D3 USB Download mode quirk
    - usb: cdc-acm: Check control transfer buffer size before access
    - usb: cdc-acm: Fix handling of oversized fragments
    - USB: serial: option: add MeiG Smart SLM828
    - USB: serial: option: add Telit Cinterion FN990B compositions
    - USB: serial: option: fix Telit Cinterion FN990A name
    - USB: serial: option: drop MeiG Smart defines
    - can: ctucanfd: handle skb allocation failure
    - can: c_can: fix unbalanced runtime PM disable in error path
    - can: j1939: j1939_sk_send_loop(): fix unable to send messages with data
      length zero
    - can: etas_es58x: fix potential NULL pointer dereference on udev->serial
    - alpha: make stack 16-byte aligned (most cases)
    - wifi: ath12k: fix handling of 6 GHz rules
    - kbuild: userprogs: fix bitsize and target detection on clang
    - efi: Avoid cold plugged memory for placing the kernel
    - cgroup: fix race between fork and cgroup.kill
    - serial: port: Assign ->iotype correctly when ->iobase is set
    - serial: port: Always update ->iotype in __uart_read_properties()
    - serial: 8250: Fix fifo underflow on flush
    - alpha: align stack for page fault and user unaligned trap handlers
    - gpiolib: acpi: Add a quirk for Acer Nitro ANV14
    - gpio: stmpe: Check return value of stmpe_reg_read in
      stmpe_gpio_irq_sync_unlock
    - partitions: mac: fix handling of bogus partition table
    - regulator: qcom_smd: Add l2, l5 sub-node to mp5496 regulator
    - regmap-irq: Add missing kfree()
    - arm64: Handle .ARM.attributes section in linker scripts
    - mmc: mtk-sd: Fix register settings for hs400(es) mode
    - igc: Set buffer type for empty frames in igc_init_empty_frame
    - mlxsw: Add return value check for mlxsw_sp_port_get_stats_raw()
    - btrfs: fix hole expansion when writing at an offset beyond EOF
    - clocksource: Use pr_info() for "Checking clocksource synchronization"
      message
    - clocksource: Use migrate_disable() to avoid calling get_random_u32() in
      atomic context
    - ipv4: add RCU protection to ip4_dst_hoplimit()
    - net: add dev_net_rcu() helper
    - ipv4: use RCU protection in ipv4_default_advmss()
    - ipv4: use RCU protection in rt_is_expired()
    - ipv4: use RCU protection in inet_select_addr()
    - net: ipv4: Cache pmtu for all packet paths if multipath enabled
    - ipv4: use RCU protection in __ip_rt_update_pmtu()
    - ipv4: icmp: convert to dev_net_rcu()
    - flow_dissector: use RCU protection to fetch dev_net()
    - ipv6: use RCU protection in ip6_default_advmss()
    - ipv6: icmp: convert to dev_net_rcu()
    - HID: hid-steam: Add Deck IMU support
    - HID: hid-steam: Make sure rumble work is canceled on removal
    - HID: hid-steam: Move hidraw input (un)registering to work
    - ndisc: use RCU protection in ndisc_alloc_skb()
    - neighbour: delete redundant judgment statements
    - neighbour: use RCU protection in __neigh_notify()
    - arp: use RCU protection in arp_xmit()
    - openvswitch: use RCU protection in ovs_vport_cmd_fill_info()
    - ndisc: extend RCU protection in ndisc_send_skb()
    - ipv6: mcast: extend RCU protection in igmp6_send()
    - ipv6: mcast: add RCU protection to mld_newpack()
    - drm/tidss: Fix issue in irq handling causing irq-flood issue
    - drm/tidss: Clear the interrupt status for interrupts being disabled
    - drm/rcar-du: dsi: Fix PHY lock bit check
    - drm/v3d: Stop active perfmon if it is being destroyed
    - netdevsim: print human readable IP address
    - selftests: rtnetlink: update netdevsim ipsec output format
    - md/md-bitmap: factor behind write counters out from
      bitmap_{start/end}write()
    - md/md-bitmap: remove the last parameter for bimtap_ops->endwrite()
    - md/md-bitmap: move bitmap_{start, end}write to md upper layer
    - mm: gup: fix infinite loop within __get_longterm_locked
    - alpha: replace hardcoded stack offsets with autogenerated ones
    - HID: hid-steam: Don't use cancel_delayed_work_sync in IRQ context
    - io_uring/kbuf: reallocate buf lists on upgrade
    - x86/i8253: Disable PIT timer 0 when not in use
    - pinctrl: cy8c95x0: Rename PWMSEL to SELPWM
    - pinctrl: pinconf-generic: print hex value
    - pinctrl: pinconf-generic: Print unsigned value if a format is registered
    - idpf: fix handling rsc packet with a single segment
    - idpf: call set_real_num_queues in idpf_open
    - igc: Fix HW RX timestamp when passed by ZC XDP
    - LoongArch: KVM: Fix typo issue about GCFG feature detection
    - workqueue: Put the pwq after detaching the rescuer from the pool
    - perf/x86/intel: Clean up PEBS-via-PT on hybrid
    - drm/xe/client: bo->client does not need bos_lock
    - io_uring/waitid: don't abuse io_tw_state
    - drm: Fix DSC BPP increment decoding
    - i3c: mipi-i3c-hci: Add Intel specific quirk to ring resuming
    - i3c: mipi-i3c-hci: Add support for MIPI I3C HCI on PCI bus
    - [Config] updateconfigs for MIPI_I3C_HCI_PCI
    - serial: 8250_pci: Resolve WCH vendor ID ambiguity
    - serial: 8250_pci: Share WCH IDs with parport_serial driver
    - fs/ntfs3: Unify inode corruption marking with _ntfs_bad_inode()
    - kbuild: suppress stdout from merge_config for silent builds
    - KVM: x86: Load DR6 with guest value only before entering .vcpu_run()
      loop
    - perf/x86/intel: Fix ARCH_PERFMON_NUM_COUNTER_LEAF
    - USB: gadget: core: create sysfs link between udc and gadget
    - usb: gadget: core: flush gadget workqueue after device removal
    - include: net: add static inline dst_dev_overhead() to dst.h
    - net: ipv6: ioam6_iptunnel: mitigate 2-realloc issue
    - net: ipv6: seg6_iptunnel: mitigate 2-realloc issue
    - net: ipv6: rpl_iptunnel: mitigate 2-realloc issue
    - net: ipv6: fix dst ref loops in rpl, seg6 and ioam6 lwtunnels
    - scsi: ufs: core: Introduce ufshcd_has_pending_tasks()
    - scsi: ufs: core: Prepare to introduce a new clock_gating lock
    - scsi: ufs: core: Introduce a new clock_gating lock
    - scsi: ufs: Fix toggling of clk_gating.state when clock gating is not
      allowed
    - ipv4: use RCU protection in ip_dst_mtu_maybe_forward()
    - drm/tidss: Fix race condition while handling interrupt registers
    - drm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit()
    - wifi: rtw89: pci: disable PCIE wake bit when PCIE deinit
    - net: ipv6: fix dst refleaks in rpl, seg6 and ioam6 lwtunnels
    - scsi: ufs: core: Ensure clk_gating.lock is used only after
      initialization
    - serial: 8250_dma: terminate correct DMA in tx_dma_flush()
    - x86/mm: Eliminate window where TLB flushes may be inadvertently skipped
    - HID: hid-steam: Fix use-after-free when detaching device
    - block: change blk_mq_add_to_batch() third argument type to bool
    - nvme: move error logging from nvme_end_req() to __nvme_end_req()
    - Upstream stable to v6.6.79, v6.12.16
  * Noble update: upstream stable patchset 2025-06-17 (LP: #2114849)
    - ice: Add check for devm_kzalloc()
    - io_uring/rw: commit provided buffer state on async
    - mptcp: pm: only set fullmesh for subflow endp
    - selftests: mptcp: join: fix AF_INET6 variable
    - xfs: don't lose solo dquot update transactions
    - Upstream stable to v6.6.78, v6.12.15
  * [Regression Updates] "PCI: Explicitly put devices into D0 when
    initializing" breaks pci-pass-through in QEMU/KVM (LP: #2117494)
    - PCI/PM: Set up runtime PM even for devices without PCI PM
  * CVE-2025-38083
    - net_sched: prio: fix a race in prio_tune()
  * CVE-2025-37797
    - net_sched: hfsc: Fix a UAF vulnerability in class handling

  [ Ubuntu: 6.8.0-64.67 ]

  * noble/linux: 6.8.0-64.67 -proposed tracker (LP: #2114668)
  * Unexpected system reboot at loading GUI session on some AMD platforms
    (LP: #2112462)
    - drm/amdgpu/hdp4: use memcfg register to post the write for HDP flush
    - drm/amdgpu/hdp5: use memcfg register to post the write for HDP flush
    - drm/amdgpu/hdp5.2: use memcfg register to post the write for HDP flush
    - drm/amdgpu/hdp6: use memcfg register to post the write for HDP flush
  * [UBUNTU 24.04] s390/pci: Fix immediate re-add of PCI function after remove
    (LP: #2114174)
    - s390/pci: rename lock member in struct zpci_dev
    - s390/pci: introduce lock to synchronize state of zpci_dev's
    - s390/pci: remove hotplug slot when releasing the device
    - s390/pci: Remove redundant bus removal and disable from
      zpci_release_device()
    - s390/pci: Prevent self deletion in disable_slot()
    - s390/pci: Allow re-add of a reserved but not yet removed device
    - s390/pci: Serialize device addition and removal
  * [UBUNTU 24.04] s390/pci: Fix immediate re-add of PCI function after remove
    (LP: #2114174) // CVE-2025-37946
    - s390/pci: Fix duplicate pci_dev_put() in disable_slot() when PF has
      child VFs
  * [UBUNTU 24.04] s390/pci: Fix immediate re-add of PCI function after remove
    (LP: #2114174) // CVE-2025-37974
    - s390/pci: Fix missing check for zpci_create_device() error return
  * [UBUNTU 24.04] s390/pci: Fix immediate re-add of PCI function after remove
    (LP: #2114174) // CVE-2024-56699
    - s390/pci: Fix potential double remove of hotplug slot
  * System will restart while resuming with SATA HDD or nvme installed with
    password set (LP: #2110090)
    - PCI: Explicitly put devices into D0 when initializing
  * Noble update: upstream stable patchset 2025-06-12 (LP: #2114239)
    - btrfs: fix assertion failure when splitting ordered extent after
      transaction abort
    - btrfs: fix use-after-free when attempting to join an aborted transaction
    - arm64/mm: Ensure adequate HUGE_MAX_HSTATE
    - exec: fix up /proc/pid/comm in the execveat(AT_EMPTY_PATH) case
    - s390/stackleak: Use exrl instead of ex in __stackleak_poison()
    - btrfs: fix data race when accessing the inode's disk_i_size at
      btrfs_drop_extents()
    - btrfs: convert BUG_ON in btrfs_reloc_cow_block() to proper error
      handling
    - sched: Don't try to catch up excess steal time.
    - locking/ww_mutex/test: Use swap() macro
    - lockdep: Fix upper limit for LOCKDEP_*_BITS configs
    - x86/amd_nb: Restrict init function to AMD-based systems
    - drm/virtio: New fence for every plane update
    - drm: Add panel backlight quirks
    - drm: panel-backlight-quirks: Add Framework 13 matte panel
    - drm: panel-backlight-quirks: Add Framework 13 glossy and 2.8k panels
    - nvkm/gsp: correctly advance the read pointer of GSP message queue
    - nvkm: correctly calculate the available space of the GSP cmdq buffer
    - drm/amd/display: Populate chroma prefetch parameters, DET buffer fix
    - drm/amd/display: Overwriting dualDPP UBF values before usage
    - printk: Fix signed integer overflow when defining LOG_BUF_LEN_MAX
    - drm/connector: add mutex to protect ELD from concurrent access
    - drm/bridge: anx7625: use eld_mutex to protect access to connector->eld
    - drm/bridge: ite-it66121: use eld_mutex to protect access to
      connector->eld
    - drm/amd/display: use eld_mutex to protect access to connector->eld
    - drm/exynos: hdmi: use eld_mutex to protect access to connector->eld
    - drm/radeon: use eld_mutex to protect access to connector->eld
    - drm/sti: hdmi: use eld_mutex to protect access to connector->eld
    - drm/vc4: hdmi: use eld_mutex to protect access to connector->eld
    - drm/amd/display: Fix Mode Cutoff in DSC Passthrough to DP2.1 Monitor
    - drm/amdgpu: Don't enable sdma 4.4.5 CTXEMPTY interrupt
    - drm/amdkfd: Queue interrupt work to different CPU
    - drm/bridge: it6505: Change definition MAX_HDCP_DOWN_STREAM_COUNT
    - drm/bridge: it6505: fix HDCP Bstatus check
    - drm/bridge: it6505: fix HDCP encryption when R0 ready
    - drm/bridge: it6505: fix HDCP CTS compare V matching
    - drm/bridge: it6505: fix HDCP V match check is not performed correctly
    - drm/bridge: it6505: fix HDCP CTS KSV list wait timer
    - safesetid: check size of policy writes
    - drm/amd/display: Increase sanitizer frame larger than limit when compile
      testing with clang
    - drm/amd/display: Limit Scaling Ratio on DCN3.01
    - wifi: rtw89: add crystal_cap check to avoid setting as overflow value
    - tun: fix group permission check
    - mmc: core: Respect quirk_max_rate for non-UHS SDIO card
    - mmc: sdhci-esdhc-imx: enable 'SDHCI_QUIRK_NO_LED' quirk for S32G
    - wifi: brcmsmac: add gain range check to wlc_phy_iqcal_gainparams_nphy()
    - tomoyo: don't emit warning in tomoyo_write_control()
    - mfd: lpc_ich: Add another Gemini Lake ISA bridge PCI device-id
    - wifi: rtw88: add __packed attribute to efuse layout struct
    - clk: qcom: Make GCC_8150 depend on QCOM_GDSC
    - HID: multitouch: Add quirk for Hantick 5288 touchpad
    - HID: Wacom: Add PCI Wacom device support
    - net/mlx5: use do_aux_work for PHC overflow checks
    - wifi: brcmfmac: Check the return value of
      of_property_read_string_index()
    - wifi: iwlwifi: pcie: Add support for new device ids
    - wifi: iwlwifi: avoid memory leak
    - i2c: Force ELAN06FA touchpad I2C bus freq to 100KHz
    - APEI: GHES: Have GHES honor the panic= setting
    - Bluetooth: btusb: Add new VID/PID 13d3/3610 for MT7922
    - Bluetooth: btusb: Add new VID/PID 13d3/3628 for MT7925
    - Bluetooth: MGMT: Fix slab-use-after-free Read in
      mgmt_remove_adv_monitor_sync
    - net: wwan: iosm: Fix hibernation by re-binding the driver around it
    - mmc: sdhci-msm: Correctly set the load for the regulator
    - octeon_ep: update tx/rx stats locally for persistence
    - tipc: re-order conditions in tipc_crypto_key_rcv()
    - selftests/net/ipsec: Fix Null pointer dereference in rtattr_pack()
    - x86/kexec: Allocate PGD for x86_64 transition page tables separately
    - iommu/arm-smmu-qcom: add sdm670 adreno iommu compatible
    - iommu/arm-smmu-v3: Clean up more on probe failure
    - platform/x86: int3472: Check for adev == NULL
    - platform/x86: acer-wmi: Add support for Acer PH14-51
    - ASoC: soc-pcm: don't use soc_pcm_ret() on .prepare callback
    - platform/x86: acer-wmi: Add support for Acer Predator PH16-72
    - ASoC: amd: Add ACPI dependency to fix build error
    - Input: allocate keycode for phone linking
    - platform/x86: acer-wmi: add support for Acer Nitro AN515-58
    - platform/x86: acer-wmi: Ignore AC events
    - xfs: report realtime block quota limits on realtime directories
    - xfs: don't over-report free space or inodes in statvfs
    - tty: xilinx_uartps: split sysrq handling
    - tty: vt: pass proper pointers from tioclinux()
    - tty: Permit some TIOCL_SETSEL modes without CAP_SYS_ADMIN
    - tty: Require CAP_SYS_ADMIN for all usages of TIOCL_SELMOUSEREPORT
    - platform/x86: serdev_helpers: Check for serial_ctrl_uid == NULL
    - nvme: handle connectivity loss in nvme_set_queue_count
    - firmware: iscsi_ibft: fix ISCSI_IBFT Kconfig entry
    - gpu: drm_dp_cec: fix broken CEC adapter properties check
    - ice: put Rx buffers after being done with current frame
    - ice: gather page_count()'s of each frag right before XDP prog call
    - ice: stop storing XDP verdict within ice_rx_buf
    - nvme-fc: use ctrl state getter
    - net: bcmgenet: Correct overlaying of PHY and MAC Wake-on-LAN
    - vmxnet3: Fix tx queue race condition with XDP
    - tg3: Disable tg3 PCIe AER on system reboot
    - udp: gso: do not drop small packets when PMTU reduces
    - rxrpc: Fix the rxrpc_connection attend queue handling
    - gpio: pca953x: Improve interrupt support
    - net: atlantic: fix warning during hot unplug
    - net: rose: lock the socket in rose_bind()
    - ACPI: property: Fix return value for nval == 0 in acpi_data_prop_read()
    - tun: revert fix group permission check
    - net: sched: Fix truncation of offloaded action statistics
    - rxrpc: Fix call state set to not include the SERVER_SECURING state
    - cpufreq: s3c64xx: Fix compilation warning
    - leds: lp8860: Write full EEPROM, not only half of it
    - ALSA: hda/realtek: Enable Mute LED on HP Laptop 14s-fq1xxx
    - drm/modeset: Handle tiled displays in pan_display_atomic.
    - drm/client: Handle tiled displays better
    - smb: client: fix order of arguments of tracepoints
    - smb: client: change lease epoch type from unsigned int to __u16
    - s390/futex: Fix FUTEX_OP_ANDN implementation
    - arm64: Filter out SVE hwcaps when FEAT_SVE isn't implemented
    - m68k: vga: Fix I/O defines
    - fs/proc: do_task_stat: Fix ESP not readable during coredump
    - binfmt_flat: Fix integer overflow bug on 32 bit systems
    - accel/ivpu: Fix Qemu crash when running in passthrough
    - arm64/kvm: Configure HYP TCR.PS/DS based on host stage1
    - arm64/sme: Move storage of reg_smidr to __cpuinfo_store_cpu()
    - KVM: arm64: timer: Always evaluate the need for a soft timer
    - drm/rockchip: cdn-dp: Use drm_connector_helper_hpd_irq_event()
    - arm64: dts: rockchip: increase gmac rx_delay on rk3399-puma
    - remoteproc: omap: Handle ARM dma_iommu_mapping
    - KVM: Explicitly verify target vCPU is online in kvm_get_vcpu()
    - KVM: s390: vsie: fix some corner-cases when grabbing vsie pages
    - ksmbd: fix integer overflows on 32 bit systems
    - drm/amd/display: Optimize cursor position updates
    - drm/amd/pm: Mark MM activity as unsupported
    - drm/amdkfd: only flush the validate MES contex
    - drm/i915/guc: Debug print LRC state entries only if the context is
      pinned
    - drm/i915: Fix page cleanup on DMA remap failure
    - drm/komeda: Add check for komeda_get_layer_fourcc_list()
    - drm/i915/dp: Iterate DSC BPP from high to low on all platforms
    - drm/i915: Drop 64bpp YUV formats from ICL+ SDR planes
    - drm/amd/display: Fix seamless boot sequence
    - Bluetooth: L2CAP: accept zero as a special value for MTU auto-selection
    - clk: sunxi-ng: a100: enable MMC clock reparenting
    - clk: mmp2: call pm_genpd_init() only after genpd.name is set
    - media: i2c: ds90ub960: Fix UB9702 refclk register access
    - clk: qcom: clk-alpha-pll: fix alpha mode configuration
    - clk: qcom: gcc-sm8550: Do not turn off PCIe GDSCs during gdsc_disable()
    - clk: qcom: gcc-sm8650: Do not turn off PCIe GDSCs during gdsc_disable()
    - clk: qcom: gcc-sm6350: Add missing parent_map for two clocks
    - clk: qcom: dispcc-sm6350: Add missing parent_map for a clock
    - clk: qcom: gcc-mdm9607: Fix cmd_rcgr offset for blsp1_uart6 rcg
    - clk: qcom: clk-rpmh: prevent integer overflow in recalc_rate
    - clk: mediatek: mt2701-vdec: fix conversion to mtk_clk_simple_probe
    - clk: mediatek: mt2701-aud: fix conversion to mtk_clk_simple_probe
    - clk: mediatek: mt2701-bdp: add missing dummy clk
    - clk: mediatek: mt2701-img: add missing dummy clk
    - clk: mediatek: mt2701-mm: add missing dummy clk
    - blk-cgroup: Fix class @block_class's subsystem refcount leakage
    - efi: libstub: Use '-std=gnu11' to fix build with GCC 15
    - perf bench: Fix undefined behavior in cmpworker()
    - scsi: ufs: core: Fix the HIGH/LOW_TEMP Bit Definitions
    - of: Correct child specifier used as input of the 2nd nexus node
    - of: Fix of_find_node_opts_by_path() handling of alias+path+options
    - Input: bbnsm_pwrkey - add remove hook
    - HID: hid-sensor-hub: don't use stale platform-data on remove
    - ring-buffer: Do not allow events in NMI with generic atomic64 cmpxchg()
    - atomic64: Use arch_spin_locks instead of raw_spin_locks
    - wifi: rtlwifi: rtl8821ae: Fix media status report
    - wifi: brcmfmac: fix NULL pointer dereference in brcmf_txfinalize()
    - wifi: mt76: mt7921u: Add VID/PID for TP-Link TXE50UH
    - wifi: rtw88: sdio: Fix disconnection after beacon loss
    - wifi: mt76: mt7915: add module param to select 5 GHz or 6 GHz on MT7916
    - usb: gadget: f_tcm: Translate error to sense
    - usb: gadget: f_tcm: Decrement command ref count on cleanup
    - usb: gadget: f_tcm: ep_autoconfig with fullspeed endpoint
    - usb: gadget: f_tcm: Don't prepare BOT write request twice
    - usbnet: ipheth: fix possible overflow in DPE length check
    - usbnet: ipheth: use static NDP16 location in URB
    - usbnet: ipheth: check that DPE points past NCM header
    - usbnet: ipheth: refactor NCM datagram loop
    - usbnet: ipheth: break up NCM header size computation
    - usbnet: ipheth: fix DPE OoB read
    - usbnet: ipheth: document scope of NCM implementation
    - ASoC: acp: Support microphone from Lenovo Go S
    - soc: qcom: socinfo: Avoid out of bounds read of serial number
    - serial: sh-sci: Drop __initdata macro for port_cfg
    - serial: sh-sci: Do not probe the serial port if its slot in sci_ports[]
      is in use
    - MIPS: Loongson64: remove ROM Size unit in boardinfo
    - LoongArch: Extend the maximum number of watchpoints
    - powerpc/pseries/eeh: Fix get PE state translation
    - dm-crypt: don't update io->sector after kcryptd_crypt_write_io_submit()
    - dm-crypt: track tag_offset in convert_context
    - mips/math-emu: fix emulation of the prefx instruction
    - MIPS: pci-legacy: Override pci_address_to_pio
    - block: don't revert iter for -EIOCBQUEUED
    - firmware: qcom: scm: Fix missing read barrier in qcom_scm_is_available()
    - ALSA: hda/realtek: Enable headset mic on Positivo C6400
    - ALSA: hda: Fix headset detection failure due to unstable sort
    - ALSA: hda/realtek: Fix built-in mic on another ASUS VivoBook model
    - ALSA: hda/realtek: Fix built-in mic breakage on ASUS VivoBook X515JA
    - arm64: tegra: Fix Tegra234 PCIe interrupt-map
    - PCI: endpoint: Finish virtual EP removal in pci_epf_remove_vepf()
    - PCI: dwc: ep: Write BAR_MASK before iATU registers in pci_epc_set_bar()
    - PCI: dwc: ep: Prevent changing BAR size/flags in pci_epc_set_bar()
    - scsi: st: Don't set pos_unknown just after device recognition
    - scsi: qla2xxx: Move FCE Trace buffer allocation to user control
    - scsi: ufs: qcom: Fix crypto key eviction
    - scsi: ufs: core: Fix use-after free in init error and remove paths
    - scsi: storvsc: Set correct data length for sending SCSI command without
      payload
    - scsi: core: Do not retry I/Os during depopulation
    - kbuild: Move -Wenum-enum-conversion to W=2
    - rust: init: use explicit ABI to clean warning in future compilers
    - x86/boot: Use '-std=gnu11' to fix build with GCC 15
    - ubi: Add a check for ubi_num
    - ARM: dts: dra7: Add bus_dma_limit for l4 cfg bus
    - ARM: dts: ti/omap: gta04: fix pm issues caused by spi module
    - arm64: dts: qcom: sm6115: Fix MPSS memory length
    - arm64: dts: qcom: sm6115: Fix CDSP memory length
    - arm64: dts: qcom: sm6115: Fix ADSP memory base and length
    - arm64: dts: qcom: sm6350: Fix ADSP memory length
    - arm64: dts: qcom: sm6350: Fix MPSS memory length
    - arm64: dts: qcom: sm6350: Fix uart1 interconnect path
    - arm64: dts: qcom: sm6375: Fix ADSP memory length
    - arm64: dts: qcom: sm6375: Fix CDSP memory base and length
    - arm64: dts: qcom: sm6375: Fix MPSS memory base and length
    - arm64: dts: qcom: sm8350: Fix ADSP memory base and length
    - arm64: dts: qcom: sm8350: Fix CDSP memory base and length
    - arm64: dts: qcom: sm8350: Fix MPSS memory length
    - arm64: dts: qcom: sm8450: Fix CDSP memory length
    - arm64: dts: qcom: sm8450: Fix MPSS memory length
    - arm64: dts: qcom: sm8550: Fix CDSP memory length
    - arm64: dts: qcom: sm8550: Fix MPSS memory length
    - arm64: dts: qcom: sm8450: add missing qcom,non-secure-domain property
    - arm64: dts: qcom: sm8450: Fix ADSP memory base and length
    - arm64: dts: qcom: sm8550: add missing qcom,non-secure-domain property
    - arm64: dts: qcom: sm8550: Add dma-coherent property
    - arm64: dts: qcom: sm8550: Fix ADSP memory base and length
    - arm64: dts: qcom: sm8650: Fix CDSP memory length
    - arm64: dts: qcom: sm8650: Fix MPSS memory length
    - arm64: dts: qcom: sm8550: correct MDSS interconnects
    - arm64: dts: qcom: sm8650: correct MDSS interconnects
    - crypto: qce - fix priority to be less than ARMv8 CE
    - arm64: tegra: Fix typo in Tegra234 dce-fabric compatible
    - arm64: tegra: Disable Tegra234 sce-fabric node
    - parisc: Temporarily disable jump label support
    - pwm: microchip-core: fix incorrect comparison with max period
    - xfs: Propagate errors from xfs_reflink_cancel_cow_range in
      xfs_dax_write_iomap_end
    - xfs: Add error handling for xfs_reflink_cancel_cow_range
    - ACPI: PRM: Remove unnecessary strict handler address checks
    - tpm: Change to kvalloc() in eventlog/acpi.c
    - rv: Reset per-task monitors also for idle tasks
    - hrtimers: Force migrate away hrtimers queued after
      CPUHP_AP_HRTIMERS_DYING
    - kfence: skip __GFP_THISNODE allocations on NUMA systems
    - media: ccs: Clean up parsed CCS static data on parse failure
    - mm/hugetlb: fix avoid_reserve to allow taking folio from subpool
    - iio: light: as73211: fix channel handling in only-color triggered buffer
    - soc: mediatek: mtk-devapc: Fix leaking IO map on error paths
    - soc: mediatek: mtk-devapc: Fix leaking IO map on driver remove
    - soc: qcom: smem_state: fix missing of_node_put in error path
    - media: mmp: Bring back registration of the device
    - media: mc: fix endpoint iteration
    - media: nuvoton: Fix an error check in npcm_video_ece_init()
    - media: imx296: Add standby delay during probe
    - media: ov5640: fix get_light_freq on auto
    - media: stm32: dcmipp: correct dma_set_mask_and_coherent mask value
    - media: ccs: Fix CCS static data parsing for large block sizes
    - media: ccs: Fix cleanup order in ccs_probe()
    - media: i2c: ds90ub9x3: Fix extra fwnode_handle_put()
    - media: i2c: ds90ub960: Fix use of non-existing registers on UB9702
    - media: i2c: ds90ub960: Fix UB9702 VC map
    - media: i2c: ds90ub960: Fix logging SP & EQ status only for UB9702
    - media: uvcvideo: Fix crash during unbind if gpio unit is in use
    - media: uvcvideo: Fix event flags in uvc_ctrl_send_events
    - media: uvcvideo: Support partial control reads
    - media: uvcvideo: Remove redundant NULL assignment
    - media: uvcvideo: Refactor iterators
    - media: uvcvideo: Only save async fh if success
    - media: uvcvideo: Remove dangling pointers
    - mm: kmemleak: fix upper boundary check for physical address objects
    - mm/compaction: fix UBSAN shift-out-of-bounds warning
    - ata: libata-sff: Ensure that we cannot write outside the allocated
      buffer
    - crypto: qce - fix goto jump in error path
    - crypto: qce - unregister previously registered algos in error path
    - nvmem: qcom-spmi-sdam: Set size in struct nvmem_config
    - nvmem: core: improve range check for nvmem_cell_write()
    - nvmem: imx-ocotp-ele: simplify read beyond device check
    - nvmem: imx-ocotp-ele: fix MAC address byte order
    - nvmem: imx-ocotp-ele: fix reading from non zero offset
    - nvmem: imx-ocotp-ele: set word length to 1
    - io_uring: fix multishots with selected buffers
    - io_uring/net: don't retry connect operation on EPOLLERR
    - selftests: mptcp: connect: -f: no reconnect
    - pnfs/flexfiles: retry getting layout segment for reads
    - ocfs2: fix incorrect CPU endianness conversion causing mount failure
    - ocfs2: handle a symlink read error correctly
    - nilfs2: fix possible int overflows in nilfs_fiemap()
    - nfs: Make NFS_FSCACHE select NETFS_SUPPORT instead of depending on it
    - NFSD: Encode COMPOUND operation status on page boundaries
    - mailbox: tegra-hsp: Clear mailbox before using message
    - NFC: nci: Add bounds checking in nci_hci_create_pipe()
    - irqchip/apple-aic: Only handle PMC interrupt as FIQ when configured so
    - mtd: onenand: Fix uninitialized retlen in do_otp_read()
    - misc: misc_minor_alloc to use ida for all dynamic/misc dynamic minors
    - char: misc: deallocate static minor in error path
    - misc: fastrpc: Deregister device nodes properly in error scenarios
    - misc: fastrpc: Fix registered buffer page address
    - misc: fastrpc: Fix copy buffer page size
    - net/ncsi: wait for the last response to Deselect Package before
      configuring channel
    - net: phy: c45-tjaxx: add delay between MDIO write and read in soft_reset
    - maple_tree: simplify split calculation
    - scripts/gdb: fix aarch64 userspace detection in get_current_task
    - tracing/osnoise: Fix resetting of tracepoints
    - rtla/osnoise: Distinguish missing workload option
    - rtla: Add trace_instance_stop
    - rtla/timerlat_hist: Stop timerlat tracer on signal
    - rtla/timerlat_top: Stop timerlat tracer on signal
    - pinctrl: samsung: fix fwnode refcount cleanup if
      platform_get_irq_optional() fails
    - ptp: Ensure info->enable callback is always set
    - RDMA/mlx5: Fix a race for an ODP MR which leads to CQE with error
    - rtc: zynqmp: Fix optional clock name property
    - MIPS: ftrace: Declare ftrace_get_parent_ra_addr() as static
    - xfs: avoid nested calls to __xfs_trans_commit
    - xfs: don't lose solo superblock counter update transactions
    - spi: atmel-quadspi: Create `atmel_qspi_ops` to support newer SoC
      families
    - spi: atmel-qspi: Memory barriers after memory-mapped I/O
    - btrfs: avoid monopolizing a core when activating a swap file
    - mptcp: prevent excessive coalescing on receive
    - Revert "drm/amd/display: Fix green screen issue after suspend"
    - statmount: let unset strings be empty
    - arm64: dts: rockchip: add reset-names for combphy on rk3568
    - ocfs2: check dir i_size in ocfs2_find_entry
    - Upstream stable to v6.6.77, v6.12.14
  * kvmppc_set_passthru_irq_hv: Could not assign IRQ map traces are seen when
    pci device is attached to kvm guest when "xive=off" is set (LP: #2109951)
    - KVM: PPC: Book3S HV: Fix IRQ map warnings with XICS on pSeries KVM Guest
  * Latitude 5450 is experiencing packet loss on Ethernet in Ubuntu 22.04
    (LP: #2106558)
    - e1000e: change k1 configuration on MTP and later platforms
  * cpufreq amd-pstate: cpuinfo_max_freq reports incorrect value
    (LP: #2109609)
    - SAUCE: Revert "Revert "cpufreq: amd-pstate: Fix the inconsistency in max
      frequency units""
  * Backport pci=config_acs parameter with fix commit (LP: #2100340)
    - PCI: Extend ACS configurability
    - PCI: Fix pci_enable_acs() support for the ACS quirks
    - PCI/ACS: Fix 'pci=config_acs=' parameter
  * [UBUNTU 24.04] s390/pci: Fix zpci_bus_is_isolated_vf() for non-VF
    (LP: #2111599)
    - s390/pci: Fix zpci_bus_is_isolated_vf() for non-VFs
  * nvme/tcp hangs IO on arm (LP: #2106381)
    - nvmet-tcp: Fix a possible sporadic response drops in weakly ordered arch
  * CVE-2025-37750
    - smb: client: fix UAF in decryption with multichannel
  * CVE-2025-40364
    - io_uring: fix io_req_prep_async with provided buffers
  * CVE-2024-49887
    - f2fs: fix to handle segment allocation failure correctly
    - f2fs: fix to don't panic system for no free segment fault injection
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953)
    - powerpc/book3s64/hugetlb: Fix disabling hugetlb when fadump is active
    - dlm: fix srcu_read_lock() return type to int
    - afs: Fix EEXIST error returned from afs_rmdir() to be ENOTEMPTY
    - afs: Fix directory format encoding struct
    - afs: Fix cleanup of immediately failed async calls
    - fs: fix proc_handler for sysctl_nr_open
    - block: retry call probe after request_module in blk_request_module
    - pstore/blk: trivial typo fixes
    - nvme: Add error check for xa_store in nvme_get_effects_log
    - selftests/powerpc: Fix argument order to timer_sub()
    - nvme: Add error path for xa_store in nvme_init_effects
    - partitions: ldm: remove the initial kernel-doc notation
    - select: Fix unbalanced user_access_end()
    - nvme: fix bogus kzalloc() return check in nvme_init_effects_log()
    - afs: Fix the fallback handling for the YFS.RemoveFile2 RPC call
    - perf/core: Save raw sample data conditionally based on sample type
    - sched/fair: Fix value reported by hot tasks pulled in /proc/schedstat
    - x86/cpu: Enable SD_ASYM_PACKING for PKG domain on AMD
    - x86/topology: Use x86_sched_itmt_flags for PKG domain unconditionally
    - drm/msm/dp: set safe_to_exit_level before printing it
    - drm/etnaviv: Fix page property being used for non writecombine buffers
    - drm/amd/pm: Fix an error handling path in
      vega10_enable_se_edc_force_stall_config()
    - drm/rockchip: vop2: Fix cluster windows alpha ctrl regsiters offset
    - drm/rockchip: vop2: Fix the mixer alpha setup for layer 0
    - drm/rockchip: vop2: Fix the windows switch between different layers
    - drm/rockchip: vop2: Check linear format for Cluster windows on rk3566/8
    - drm/rockchip: vop2: include rockchip_drm_drv.h
    - drm/msm/dpu: link DSPP_2/_3 blocks on SM8150
    - drm/msm/dpu: link DSPP_2/_3 blocks on SC8180X
    - drm/msm/dpu: link DSPP_2/_3 blocks on SM8250
    - drm/msm/dpu: link DSPP_2/_3 blocks on SM8350
    - drm/msm/dpu: link DSPP_2/_3 blocks on SM8550
    - drm/msm: Check return value of of_dma_configure()
    - drm/bridge: it6505: Change definition of AUX_FIFO_MAX_SIZE
    - drm/amdgpu: tear down ttm range manager for doorbell in
      amdgpu_ttm_fini()
    - genirq: Make handle_enforce_irqctx() unconditionally available
    - wifi: ath11k: Fix unexpected return buffer manager error for
      WCN6750/WCN6855
    - wifi: rtlwifi: do not complete firmware loading needlessly
    - wifi: rtlwifi: rtl8192se: rise completion of firmware loading as last
      step
    - wifi: rtlwifi: wait for firmware loading before releasing memory
    - wifi: rtlwifi: fix init_sw_vars leak when probe fails
    - wifi: rtlwifi: usb: fix workqueue leak when probe fails
    - net_sched: sch_sfq: annotate data-races around q->perturb_period
    - net_sched: sch_sfq: handle bigger packets
    - spi: zynq-qspi: Add check for clk_enable()
    - dt-bindings: mmc: controller: clarify the address-cells description
    - of: remove internal arguments from of_property_for_each_u32()
    - clk: fix an OF node reference leak in of_clk_get_parent_name()
    - dt-bindings: leds: class-multicolor: Fix path to color definitions
    - wifi: rtlwifi: destroy workqueue at rtl_deinit_core
    - wifi: rtlwifi: pci: wait for firmware loading before releasing memory
    - HID: multitouch: fix support for Goodix PID 0x01e9
    - regulator: dt-bindings: mt6315: Drop regulator-compatible property
    - wifi: brcmfmac: add missing header include for brcmf_dbg
    - ACPI: fan: cleanup resources in the error path of .probe()
    - cpupower: fix TSC MHz calculation
    - dt-bindings: mfd: bd71815: Fix rsense and typos
    - leds: netxbig: Fix an OF node reference leak in
      netxbig_leds_get_of_pdata()
    - inetpeer: remove create argument of inet_getpeer_v[46]()
    - inetpeer: remove create argument of inet_getpeer()
    - inetpeer: update inetpeer timestamp in inet_getpeer()
    - inetpeer: do not get a refcount in inet_getpeer()
    - pwm: stm32-lp: Add check for clk_enable()
    - cpufreq: schedutil: Fix superfluous updates caused by need_freq_update
    - gpio: pca953x: log an error when failing to get the reset GPIO
    - cpufreq: qcom: Fix qcom_cpufreq_hw_recalc_rate() to query LUT if LMh IRQ
      is not available
    - cpufreq: qcom: Implement clk_ops::determine_rate() for qcom_cpufreq*
      clocks
    - clk: imx8mp: Fix clkout1/2 support
    - dt-bindings: clock: sunxi: Export PLL_VIDEO_2X and PLL_MIPI
    - clk: sunxi-ng: a64: drop redundant CLK_PLL_VIDEO0_2X and CLK_PLL_MIPI
    - clk: sunxi-ng: a64: stop force-selecting PLL-MIPI as TCON0 parent
    - regulator: of: Implement the unwind path of of_regulator_match()
    - OPP: OF: Fix an OF node leak in _opp_add_static_v2()
    - ipmi: ssif_bmc: Fix new request loss when bmc ready for a response
    - wifi: ath12k: fix tx power, max reg power update to firmware
    - clk: qcom: gcc-sdm845: Do not use shared clk_ops for QUPs
    - HID: fix generic desktop D-Pad controls
    - leds: cht-wcove: Use devm_led_classdev_register() to avoid memory leak
    - mfd: syscon: Remove extern from function prototypes
    - mfd: syscon: Add of_syscon_register_regmap() API
    - mfd: syscon: Use scoped variables with memory allocators to simplify
      error paths
    - mfd: syscon: Fix race in device_node_get_regmap()
    - samples/landlock: Fix possible NULL dereference in parse_path()
    - wifi: wlcore: fix unbalanced pm_runtime calls
    - wifi: mt76: mt7915: Fix mesh scan on MT7916 DBDC
    - wifi: mac80211: fix tid removal during mesh forwarding
    - wifi: mac80211: Fix common size calculation for ML element
    - net/smc: fix data error when recvmsg with MSG_PEEK flag
    - wifi: mt76: mt76u_vendor_request: Do not print error messages when
      -EPROTO
    - wifi: mt76: mt7921: fix using incorrect group cipher after
      disconnection.
    - wifi: mt76: mt7915: fix overflows seen when writing limit attributes
    - wifi: mt76: mt7996: fix rx filter setting for bfee functionality
    - wifi: mt76: mt7915: firmware restart on devices with a second pcie link
    - wifi: mt76: connac: move mt7615_mcu_del_wtbl_all to connac
    - wifi: mt76: mt7915: improve hardware restart reliability
    - wifi: mt76: mt7915: fix omac index assignment after hardware reset
    - wifi: mt76: mt7915: fix register mapping
    - wifi: mt76: mt7996: fix register mapping
    - wifi: mt76: mt7996: add max mpdu len capability
    - wifi: mt76: mt7996: fix the capability of reception of EHT MU PPDU
    - wifi: mt76: mt7996: fix HE Phy capability
    - wifi: mt76: mt7996: fix incorrect indexing of MIB FW event
    - wifi: mt76: mt7996: fix ldpc setting
    - cpufreq: ACPI: Fix max-frequency computation
    - selftests: timers: clocksource-switch: Adapt progress to kselftest
      framework
    - selftests: harness: fix printing of mismatch values in __EXPECT()
    - wifi: cfg80211: adjust allocation of colocated AP data
    - inet: ipmr: fix data-races
    - clk: analogbits: Fix incorrect calculation of vco rate delta
    - pwm: stm32: Add check for clk_enable()
    - selftests/landlock: Fix error message
    - net/mlxfw: Drop hard coded max FW flash image size
    - octeon_ep: remove firmware stats fetch in ndo_get_stats64
    - netfilter: nf_tables: fix set size with rbtree backend
    - netfilter: nft_flow_offload: update tcp state flags under lock
    - tcp_cubic: fix incorrect HyStart round start detection
    - libbpf: don't adjust USDT semaphore address if .stapsdt.base addr is
      missing
    - tools/testing/selftests/bpf/test_tc_tunnel.sh: Fix wait for server bind
    - libbpf: Fix segfault due to libelf functions not setting errno
    - ASoC: sun4i-spdif: Add clock multiplier settings
    - selftests/bpf: Fix fill_link_info selftest on powerpc
    - crypto: caam - use JobR's space to access page 0 regs
    - perf header: Fix one memory leakage in process_bpf_btf()
    - perf header: Fix one memory leakage in process_bpf_prog_info()
    - perf bpf: Fix two memory leakages when calling
      perf_env__insert_bpf_prog_info()
    - ASoC: renesas: rz-ssi: Use only the proper amount of dividers
    - perf expr: Initialize is_test value in expr__ctx_new()
    - ktest.pl: Remove unused declarations in run_bisect_test function
    - crypto: hisilicon/sec2 - fix for aead icv error
    - crypto: hisilicon/sec2 - fix for aead invalid authsize
    - crypto: ixp4xx - fix OF node reference leaks in init_ixp_crypto()
    - ALSA: seq: remove redundant 'tristate' for SND_SEQ_UMP_CLIENT
    - ALSA: seq: Make dependency on UMP clearer
    - padata: fix sysfs store callback check
    - perf top: Don't complain about lack of vmlinux when not resolving some
      kernel samples
    - perf machine: Don't ignore _etext when not a text symbol
    - perf namespaces: Introduce nsinfo__set_in_pidns()
    - perf namespaces: Fixup the nsinfo__in_pidns() return type, its bool
    - ASoC: Intel: avs: Prefix SKL/APL-specific members
    - ASoC: Intel: avs: Abstract IPC handling
    - ASoC: Intel: avs: Do not readq() u32 registers
    - ASoC: Intel: avs: Fix theoretical infinite loop
    - perf report: Fix misleading help message about --demangle
    - pinctrl: stm32: Add check for clk_enable()
    - pinctrl: amd: Take suspend type into consideration which pins are non-
      wake
    - bpf: tcp: Mark bpf_load_hdr_opt() arg2 as read-write
    - ALSA: hda/realtek - Fixed headphone distorted sound on Acer Aspire
      A115-31 laptop
    - perf lock: Fix parse_lock_type which only retrieve one lock flag
    - padata: add pd get/put refcnt helper
    - cifs: Use cifs_autodisable_serverino() for disabling
      CIFS_MOUNT_SERVER_INUM in readdir.c
    - soc: atmel: fix device_node release in atmel_soc_device_init()
    - ARM: at91: pm: change BU Power Switch to automatic mode
    - arm64: dts: mediatek: mt8186: Move wakeup to MTU3 to get working suspend
    - arm64: dts: mt8183: set DMIC one-wire mode on Damu
    - arm64: dts: mediatek: mt8516: fix GICv2 range
    - arm64: dts: mediatek: mt8516: fix wdt irq type
    - arm64: dts: mediatek: mt8516: add i2c clock-div property
    - arm64: dts: mediatek: mt8516: reserve 192 KiB for TF-A
    - ARM: dts: stm32: Fix IPCC EXTI declaration on stm32mp151
    - RDMA/mlx4: Avoid false error about access to uninitialized gids array
    - arm64: dts: mediatek: mt8173-evb: Drop regulator-compatible property
    - arm64: dts: mediatek: mt8173-elm: Drop regulator-compatible property
    - arm64: dts: mediatek: mt8192-asurada: Drop regulator-compatible property
    - arm64: dts: mediatek: mt8195-cherry: Drop regulator-compatible property
    - arm64: dts: mediatek: mt8195-demo: Drop regulator-compatible property
    - arm64: dts: mediatek: mt8173-elm: Fix MT6397 PMIC sub-node names
    - arm64: dts: mediatek: mt8173-evb: Fix MT6397 PMIC sub-node names
    - ARM: dts: aspeed: yosemite4: correct the compatible string of adm1272
    - ARM: dts: aspeed: yosemite4: Add required properties for IOE on fan
      boards
    - ARM: dts: aspeed: yosemite4: correct the compatible string for max31790
    - arm: dts: socfpga: use reset-name "stmmaceth-ocp" instead of "ahb"
    - RDMA/rxe: Improve newline in printing messages
    - RDMA/rxe: Fix mismatched max_msg_sz
    - arm64: dts: mediatek: mt8183: kenzo: Support second source touchscreen
    - arm64: dts: mediatek: mt8183: willow: Support second source touchscreen
    - RDMA/srp: Fix error handling in srp_add_port
    - arm64: dts: mediatek: mt8195: Remove suspend-breaking reset from pcie1
    - ARM: dts: stm32: Deduplicate serial aliases and chosen node for
      STM32MP15xx DHCOM SoM
    - ARM: dts: stm32: Swap USART3 and UART8 alias on STM32MP15xx DHCOM SoM
    - arm64: dts: mediatek: mt8183-kukui-jacuzzi: Drop pp3300_panel voltage
      settings
    - arm64: dts: qcom: msm8996-xiaomi-gemini: Fix LP5562 LED1 reg property
    - arm64: dts: qcom: move common parts for sa8775p-ride variants into a
      .dtsi
    - arm64: dts: qcom: sa8775p: Update sleep_clk frequency
    - arm64: dts: qcom: msm8996: Fix up USB3 interrupts
    - arm64: dts: qcom: msm8994: Describe USB interrupts
    - arm64: dts: qcom: sm7225-fairphone-fp4: Drop extra qcom,msm-id value
    - arm64: dts: qcom: msm8916: correct sleep clock frequency
    - arm64: dts: qcom: msm8939: correct sleep clock frequency
    - arm64: dts: qcom: msm8994: correct sleep clock frequency
    - arm64: dts: qcom: qcs404: correct sleep clock frequency
    - arm64: dts: qcom: q[dr]u1000: correct sleep clock frequency
    - arm64: dts: qcom: qrb4210-rb2: correct sleep clock frequency
    - arm64: dts: qcom: sc7280: correct sleep clock frequency
    - arm64: dts: qcom: sdx75: correct sleep clock frequency
    - arm64: dts: qcom: sm4450: correct sleep clock frequency
    - arm64: dts: qcom: sm6125: correct sleep clock frequency
    - arm64: dts: qcom: sm6375: correct sleep clock frequency
    - arm64: dts: qcom: sm8250: correct sleep clock frequency
    - arm64: dts: qcom: sm8350: correct sleep clock frequency
    - arm64: dts: qcom: sm8450: correct sleep clock frequency
    - ARM: dts: microchip: sama5d27_wlsom1_ek: Add no-1-8-v property to sdmmc0
      node
    - arm64: dts: ti: k3-am62: Remove duplicate GICR reg
    - arm64: dts: ti: k3-am62a: Remove duplicate GICR reg
    - arm64: dts: allwinner: a64: explicitly assign clock parent for TCON0
    - RDMA/bnxt_re: Fix to drop reference to the mmap entry in case of error
    - ARM: omap1: Fix up the Retu IRQ on Nokia 770
    - arm64: dts: qcom: sdm845-db845c-navigation-mezzanine: Convert mezzanine
      riser to dtso
    - arm64: dts: qcom: sdm845-db845c-navigation-mezzanine: remove disabled
      ov7251 camera
    - arm64: dts: qcom: sc7180-trogdor-quackingstick: add missing avee-supply
    - arm64: dts: qcom: sc7180-*: Remove thermal zone polling delays
    - arm64: dts: qcom: sc7180-trogdor-pompom: rename 5v-choke thermal zone
    - arm64: dts: qcom: sc7180: change labels to lower-case
    - arm64: dts: qcom: sc7180: fix psci power domain node names
    - arm64: dts: qcom: sm8150-microsoft-surface-duo: fix typos in da7280
      properties
    - arm64: dts: qcom: sc8280xp: Fix up remoteproc register space sizes
    - dts: arm64: mediatek: mt8195: Remove MT8183 compatible for OVL
    - arm64: dts: mediatek: add per-SoC compatibles for keypad nodes
    - arm64: dts: qcom: sdm845: Fix interrupt types of camss interrupts
    - arm64: dts: qcom: sm8250: Fix interrupt types of camss interrupts
    - ARM: dts: mediatek: mt7623: fix IR nodename
    - fbdev: omapfb: Fix an OF node leak in dss_of_port_get_parent_device()
    - arm64: tegra: Fix DMA ID for SPI2
    - i3c: dw: Add hot-join support.
    - RDMA/mlx5: Fix indirect mkey ODP page count
    - of: reserved-memory: Do not make kmemleak ignore freed address
    - efi: sysfb_efi: fix W=1 warnings when EFI is not set
    - spi: omap2-mcspi: Correctly handle devm_clk_get_optional() errors
    - media: rc: iguanair: handle timeouts
    - media: lmedm04: Handle errors for lme2510_int_read
    - PCI: endpoint: Destroy the EPC device in devm_pci_epc_destroy()
    - media: marvell: Add check for clk_enable()
    - media: i2c: imx290: Register 0x3011 varies between imx327 and imx290
    - media: i2c: imx412: Add missing newline to prints
    - media: i2c: ov9282: Correct the exposure offset
    - media: mipi-csis: Add check for clk_enable()
    - media: camif-core: Add check for clk_enable()
    - media: uvcvideo: Propagate buf->error to userspace
    - mtd: rawnand: brcmnand: fix status read of brcmnand_waitfunc
    - mtd: hyperbus: hbmc-am654: fix an OF node reference leak
    - media: nxp: imx8-isi: fix v4l2-compliance test errors
    - watchdog: rti_wdt: Fix an OF node leak in rti_wdt_probe()
    - staging: media: imx: fix OF node leak in imx_media_add_of_subdevs()
    - media: dvb-usb-v2: af9035: fix ISO C90 compilation error on
      af9035_i2c_master_xfer
    - PCI: endpoint: pci-epf-test: Set dma_chan_rx pointer to NULL on error
    - PCI: endpoint: pci-epf-test: Fix check for DMA MEMCPY test
    - scsi: mpt3sas: Set ioc->manu_pg11.EEDPTagMode directly to 1
    - scsi: ufs: bsg: Delete bsg_dev when setting up bsg fails
    - ocfs2: mark dquot as inactive if failed to start trans while releasing
      dquot
    - module: Extend the preempt disabled section in
      dereference_symbol_descriptor().
    - serial: 8250: Adjust the timeout for FIFO mode
    - NFSv4.2: fix COPY_NOTIFY xdr buf size calculation
    - NFSv4.2: mark OFFLOAD_CANCEL MOVEABLE
    - tools/bootconfig: Fix the wrong format specifier
    - xfrm: replay: Fix the update of replay_esn->oseq_hi for GSO
    - dmaengine: ti: edma: fix OF node reference leaks in edma_driver
    - rtc: loongson: clear TOY_MATCH0_REG in loongson_rtc_isr()
    - regulator: core: Add missing newline character
    - gpio: mxc: remove dead code after switch to DT-only
    - net: fec: implement TSO descriptor cleanup
    - PM: hibernate: Add error handling for syscore_suspend()
    - iavf: allow changing VLAN state without calling PF
    - net: netdevsim: try to close UDP port harness races
    - ptp: Properly handle compat ioctls
    - net: stmmac: Limit the number of MTL queues to hardware capability
    - net: stmmac: Limit FIFO size by hardware capability
    - perf trace: Fix runtime error of index out of bounds
    - Bluetooth: btnxpuart: Fix glitches seen in dual A2DP streaming
    - vsock: Allow retrying on connect() failure
    - bgmac: reduce max frame size to support just MTU 1500
    - net: sh_eth: Fix missing rtnl lock in suspend/resume path
    - genksyms: fix memory leak when the same symbol is added from source
    - genksyms: fix memory leak when the same symbol is read from *.symref
      file
    - RISC-V: Mark riscv_v_init() as __init
    - ASoC: rockchip: i2s_tdm: Re-add the set_sysclk callback
    - io_uring/uring_cmd: use cached cmd_op in io_uring_cmd_sock()
    - cifs: Fix getting and setting SACLs over SMB1
    - kconfig: fix file name in warnings when loading KCONFIG_DEFCONFIG_LIST
    - kconfig: fix memory leak in sym_warn_unmet_dep()
    - hexagon: fix using plain integer as NULL pointer warning in cmpxchg
    - hexagon: Fix unbalanced spinlock in die()
    - f2fs: Introduce linear search for dentries
    - Revert "SUNRPC: Reduce thread wake-up rate when receiving large RPC
      messages"
    - kbuild: switch from lz4c to lz4 for compression
    - selftests/rseq: Fix handling of glibc without rseq support
    - ktest.pl: Check kernelrelease return in get_version
    - ALSA: usb-audio: Add delay quirk for iBasso DC07 Pro
    - usb: gadget: f_tcm: Fix Get/SetInterface return value
    - usb: dwc3-am62: Fix an OF node leak in phy_syscon_pll_refclk()
    - usb: dwc3: core: Defer the probe until USB power supply ready
    - usb: typec: tcpm: set SRC_SEND_CAPABILITIES timeout to
      PD_T_SENDER_RESPONSE
    - usb: typec: tcpci: Prevent Sink disconnection before vPpsShutdown in SPR
      PPS
    - btrfs: output the reason for open_ctree() failure
    - s390: Add '-std=gnu11' to decompressor and purgatory CFLAGS
    - LoongArch: Change 8 to 14 for LOONGARCH_MAX_{BRP,WRP}
    - block: copy back bounce buffer to user-space correctly in case of split
    - nvme-tcp: Fix I/O queue cpu spreading for multiple controllers
    - sched/fair: Untangle NEXT_BUDDY and pick_next_task()
    - sched: Fix race between yield_to() and try_to_wake_up()
    - drm/v3d: Fix performance counter source settings on V3D 7.x
    - drm/rockchip: vop2: fix rk3588 dp+dsi maxclk verification
    - drm/rockchip: vop2: Set AXI id for rk3588
    - drm/rockchip: vop2: Setup delay cycle for Esmart2/3
    - drm/rockchip: vop2: Add check for 32 bpp format for rk3588
    - drm/msm/dpu: provide DSPP and correct LM config for SDM670
    - drm/msm/dpu: link DSPP_2/_3 blocks on SM8650
    - drm/msm: don't clean up priv->kms prematurely
    - drm/msm/mdp4: correct LCDC regulator name
    - wifi: rtlwifi: rtl8821ae: phy: restore removed code to fix infinite loop
    - selftests/bpf: Actuate tx_metadata_len in xdp_hw_metadata
    - selftests: ktap_helpers: Fix uninitialized variable
    - inet: constify inet_sk_bound_dev_eq() net parameter
    - inet: constify 'struct net' parameter of various lookup helpers
    - udp: constify 'struct net' parameter of socket lookups
    - inet6: constify 'struct net' parameter of various lookup helpers
    - ipv6: udp: constify 'struct net' parameter of socket lookups
    - dt-bindings: clock: imx93: Drop IMX93_CLK_END macro definition
    - dt-bindings: clock: Add i.MX91 clock support
    - dt-bindings: clock: imx93: Add SPDIF IPG clk
    - clk: imx93: Move IMX93_CLK_END macro to clk driver
    - clk: imx: add i.MX91 clk
    - clk: imx93: Add IMX93_CLK_SPDIF_IPG clock
    - arm64: dts: imx93: Use IMX93_CLK_SPDIF_IPG as SPDIF IPG clock
    - clk: imx: Apply some clks only for i.MX93
    - wifi: rtw89: mcc: consider time limits not divisible by 1024
    - wifi: iwlwifi: cleanup uefi variables loading
    - wifi: iwlwifi: fw: read STEP table from correct UEFI var
    - wifi: mt76: mt7996: fix overflows seen when writing limit attributes
    - wifi: mt76: mt7996: fix definition of tx descriptor
    - Bluetooth: btbcm: Fix NULL deref in btbcm_get_board_name()
    - platform/mellanox: mlxbf-pmc: incorrect type in assignment
    - platform/x86: x86-android-tablets: make platform data be static
    - crypto: api - Fix boot-up self-test race
    - pinctrl: nomadik: Add check for clk_enable()
    - rhashtable: Fix potential deadlock by moving schedule_work outside lock
    - crypto: iaa - Fix IAA disabling that occurs when sync_mode is set to
      'async'
    - perf maps: Fix display of kernel symbols
    - perf MANIFEST: Add arch/*/include/uapi/asm/bpf_perf_event.h to the perf
      tarball
    - ALSA: hda: Fix compilation of snd_hdac_adsp_xxx() helpers
    - tools: Sync if_xdp.h uapi tooling header
    - rhashtable: Fix rhashtable_try_insert test
    - ARM: dts: imx7-tqma7: add missing vs-supply for LM75A (rev. 01xxx)
    - arm64: dts: renesas: rzg3s-smarc: Fix the debug serial alias
    - arm64: dts: mediatek: mt8395-genio-1200-evk: Drop regulator-compatible
      property
    - arm64: dts: qcom: sm8550: correct sleep clock frequency
    - arm64: dts: qcom: sm8650: correct sleep clock frequency
    - arm64: dts: qcom: x1e80100: correct sleep clock frequency
    - ARM: dts: microchip: sama5d29_curiosity: Add no-1-8-v property to sdmmc0
      node
    - RDMA/hns: Clean up the legacy CONFIG_INFINIBAND_HNS
    - [Config] updateconfigs for INFINIBAND_HNS
    - RDMA/cxgb4: Notify rdma stack for IB_EVENT_QP_LAST_WQE_REACHED event
    - iommu: iommufd: fix WARNING in iommufd_device_unbind
    - remoteproc: mtk_scp: Only populate devices for SCP cores
    - PCI: imx6: Deassert apps_reset in imx_pcie_deassert_core_reset()
    - PCI: dwc: Always stop link in the dw_pcie_suspend_noirq
    - PCI: microchip: Add support for using either Root Port 1 or 2
    - PCI: microchip: Set inbound address translation for coherent or non-
      coherent mode
    - erofs: get rid of erofs_{find,insert}_workgroup
    - erofs: move erofs_workgroup operations into zdata.c
    - erofs: sunset `struct erofs_workgroup`
    - erofs: fix potential return value overflow of z_erofs_shrink_scan()
    - tty: mips_ejtag_fdc: fix one more u8 warning
    - xfrm: Add support for per cpu xfrm state handling.
    - xfrm: Cache used outbound xfrm states at the policy.
    - xfrm: Add an inbound percpu state cache.
    - xfrm: Don't disable preemption while looking up cache state.
    - idpf: add read memory barrier when checking descriptor done bit
    - net/ncsi: use dev_set_mac_address() for Get MC MAC Address handling
    - tools: ynl: c: correct reverse decode of empty attrs
    - selftests: mptcp: extend CFLAGS to keep options from environment
    - selftests: net/{lib,openvswitch}: extend CFLAGS to keep options from
      environment
    - net: ethtool: only allow set_rxnfc with rss + ring_cookie if driver opts
      in
    - ethtool: Fix set RXNFC command with symmetric RSS hash
    - tools/power turbostat: Fix forked child affinity regression
    - md: add a new callback pers->bitmap_sector()
    - md/raid5: implement pers->bitmap_sector()
    - xfs: check for dead buffers in xfs_buf_find_insert
    - xfs: don't shut down the filesystem for media failures beyond end of log
    - usb: dwc3: Skip resume if pm_runtime_set_active() fails
    - clk: qcom: gcc-x1e80100: Do not turn off usb_2 controller GDSC
    - xfrm: Add error handling when nla_put_u32() returns an error
    - xfrm: Fix acquire state insertion.
    - ethtool: Fix access to uninitialized fields in set RXNFC command
    - ASoC: da7213: Initialize the mutex
    - drm/amd/display: Add hubp cache reset when powergating
    - KVM: x86: Plumb in the vCPU to kvm_x86_ops.hwapic_isr_update()
    - ethtool: ntuple: fix rss + ring_cookie check
    - Upstream stable to v6.6.76, v6.12.13
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-57975
    - btrfs: do proper folio cleanup when run_delalloc_nocow() failed
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21714
    - RDMA/mlx5: Fix implicit ODP use after free
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21801
    - net: ravb: Fix missing rtnl lock in suspend/resume path
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21809
    - rxrpc, afs: Fix peer hash locking vs RCU callback
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-58057
    - idpf: convert workqueues to unbound
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-57953
    - rtc: tps6594: Fix integer overflow on 32bit systems
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-57982
    - xfrm: state: fix out-of-bounds read during lookup
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21721
    - nilfs2: handle errors that nilfs_prepare_chunk() may return
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21722
    - nilfs2: do not force clear folio if buffer is referenced
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21798
    - firewire: test: Fix potential null dereference in firewire kunit test
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21723
    - scsi: mpi3mr: Fix possible crash when setting up bsg fails
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21724
    - iommufd/iova_bitmap: Fix shift-out-of-bounds in
      iova_bitmap_offset_to_index()
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21825
    - bpf: Cancel the running bpf_timer through kworker for PREEMPT_RT
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-57990
    - wifi: mt76: mt7925: fix off by one in mt7925_load_clc()
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-57974
    - udp: Deal with race between UDP socket address change and rehash
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-57994
    - ptr_ring: do not block hard interrupts in ptr_ring_resize_multiple()
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-57999
    - powerpc/pseries/iommu: IOMMU incorrectly marks MMIO range in DDW
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-58054
    - staging: media: max96712: fix kernel oops when removing module
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-58055
    - usb: gadget: f_tcm: Don't free command immediately
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-57979
    - pps: Fix a use-after-free
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-57980
    - media: uvcvideo: Fix double free in error path
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-58056
    - remoteproc: core: Fix ida_free call while not allocated
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21705
    - mptcp: handle fastopen disconnect correctly
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21707
    - mptcp: consolidate suboption status
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-57981
    - usb: xhci: Fix NULL pointer dereference on certain command aborts
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21708
    - net: usb: rtl8150: enable basic endpoint checking
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21826
    - netfilter: nf_tables: reject mismatching sum of field_len with set key
      length
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21808
    - net: xdp: Disallow attaching device-bound programs in generic mode
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21710
    - tcp: correct handling of extreme memory squeeze
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21715
    - net: davicom: fix UAF in dm9000_drv_remove
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21716
    - vxlan: Fix uninit-value in vxlan_vnifilter_dump()
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21718
    - net: rose: fix timer races against user threads
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21719
    - ipmr: do not call mr_mfc_uses_dev() for unres entries
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21802
    - net: hns3: fix oops when unload drivers paralleling
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-58058
    - ubifs: skip dumping tnc tree when zroot is null
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-58069
    - rtc: pcf85063: fix potential OOB write in PCF85063 NVMEM read
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21720
    - xfrm: delete intermediate secpath entry in packet offload mode
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21803
    - LoongArch: Fix warnings during S3 suspend
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21810
    - driver core: class: Fix wild pointer dereferences in API
      class_dev_iter_next()
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21811
    - nilfs2: protect access to buffers with no active references
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21804
    - PCI: rcar-ep: Fix incorrect variable used when calling
      devm_request_mem_region()
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21829
    - RDMA/rxe: Fix the warning "__rxe_cleanup+0x12c/0x170 [rdma_rxe]"
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-57984
    - i3c: dw: Fix use-after-free in dw_i3c_master driver due to race
      condition
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-58034
    - memory: tegra20-emc: fix an OF node reference bug in
      tegra_emc_find_node_by_ram_code()
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-57973
    - rdma/cxgb4: Prevent potential integer overflow on 32bit
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21725
    - smb: client: fix oops due to unset link speed
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21726
    - padata: avoid UAF for reorder_work
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21727
    - padata: fix UAF in padata_reorder
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21728
    - bpf: Send signals asynchronously if !preemptible
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-58070
    - bpf: bpf_local_storage: Always use bpf_mem_alloc in PREEMPT_RT
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21711
    - net/rose: prevent integer overflows in rose_setsockopt()
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21799
    - net: ethernet: ti: am65-cpsw: fix freeing IRQ in
      am65_cpsw_nuss_remove_tx_chns()
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21806
    - net: let net.core.dev_weight always be non-zero
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21830
    - landlock: Handle weird files
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21828
    - wifi: mac80211: don't flush non-uploaded STAs
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-58061
    - wifi: mac80211: prohibit deactivating all links
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-57993
    - HID: hid-thrustmaster: Fix warning in thrustmaster_probe by adding
      endpoint check
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21812
    - ax25: rcu protect dev->ax25_ptr
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-58071
    - team: prevent adding a device which is already a team device lower
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-58063
    - wifi: rtlwifi: fix memory leaks and invalid access at probe error path
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-58072
    - wifi: rtlwifi: remove unused check_buddy_priv
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-58053
    - rxrpc: Fix handling of received connection abort
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-57996
    - net_sched: sch_sfq: don't allow 1 packet limit
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-57997
    - wifi: wcn36xx: fix channel survey memory allocation size
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-58051
    - ipmi: ipmb: Add check devm_kasprintf() returned value
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-58068
    - OPP: fix dev_pm_opp_find_bw_*() when bandwidth table not initialized
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-57998
    - OPP: add index check to assert to avoid buffer overflow in _read_freq()
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-58052
    - drm/amdgpu: Fix potential NULL pointer dereference in
      atomctrl_get_smc_sclk_range_table
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2024-57986
    - HID: core: Fix assumption that Resolution Multipliers must be in Logical
      Collections
  * Noble update: upstream stable patchset 2025-05-29 (LP: #2111953) //
    CVE-2025-21731
    - nbd: don't allow reconnect after disconnect
  * CVE-2025-37798
    - sch_htb: make htb_qlen_notify() idempotent
    - sch_htb: make htb_deactivate() idempotent
    - sch_drr: make drr_qlen_notify() idempotent
    - sch_hfsc: make hfsc_qlen_notify() idempotent
    - sch_qfq: make qfq_qlen_notify() idempotent
    - sch_ets: make est_qlen_notify() idempotent
    - codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog()
  * CVE-2025-37997
    - netfilter: ipset: fix region locking in hash types
  * CVE-2025-22088
    - RDMA/erdma: Prevent use-after-free in erdma_accept_newconn()
  * CVE-2025-37890
    - net_sched: hfsc: Fix a UAF vulnerability in class with netem as child
      qdisc
    - sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()
    - net_sched: hfsc: Address reentrant enqueue adding class to eltree twice
  * raid1: Fix NULL pointer dereference in process_checks() (LP: #2112519)
    - md/raid1: Add check for missing source disk in process_checks()
  * Packaging resync (LP: #1786013)
    - [Packaging] update variants
    - [Packaging] update annotations scripts

Date: 2025-09-08 14:47:22.013164+00:00
Changed-By: Hui Wang <hui.wang at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-qcom/6.8.0-1054.54
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list