[ubuntu/noble-proposed] linux-nvidia-lowlatency 6.8.0-1065.68.1 (Accepted)
Timo Aaltonen
tjaalton at ubuntu.com
Sat Oct 3 19:50:55 UTC 2026
linux-nvidia-lowlatency (6.8.0-1065.68.1) noble; urgency=medium
* noble/linux-nvidia-lowlatency: 6.8.0-1065.68.1 -proposed tracker (LP: #2168116)
[ Ubuntu-nvidia: 6.8.0-1065.68 ]
* noble/linux-nvidia: 6.8.0-1065.68 -proposed tracker (LP: #2168118)
[ Ubuntu: 6.8.0-147.147 ]
* noble/linux: 6.8.0-147.147 -proposed tracker (LP: #2168142)
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026)
- platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug
- selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs
- drm/virtio: fix deadlock in display_info_cb by removing hotplug from
dequeue worker
- mtd: mtdswap: remove debugfs stats file on teardown
- seqlock: Cure some more scoped_seqlock() optimization fails
- seqlock: Allow KASAN to fail optimizing
- seqlock: Allow UBSAN_ALIGNMENT to fail optimizing
- xprtrdma: Clear receive-side ownership pointers on release
- Input: ims-pcu - fix logic error in packet reset
- arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234
- mtd: nand: mtk-ecc: stop on ECC idle timeouts
- RDMA/cma: Fix hardware address comparison length in netevent callback
- RDMA/umem: Add support for creating pinned DMABUF umem with a given dma
device
- RDMA/umem: Introduce an option to revoke DMABUF umem
- RDMA/umem: Add ib_umem_dmabuf_get_pinned_and_lock helper
- RDMA/umem: Move umem dmabuf revoke logic into helper function
- RDMA/umem: Add pinned revocable dmabuf import interface
- RDMA/umem: Add helpers for umem dmabuf revoke lock
- RDMA/erdma: initialize ret for empty receive WR lists
- RDMA/hns: Fix potential integer overflow in mhop hem cleanup
- selftests/alsa: Fix memory leak in find_controls error path
- RDMA/irdma: Prevent overflows in memory contiguity checks
- wifi: nl80211: validate nested MBSSID IE blobs
- wifi: cfg80211: validate PMSR measurement type data
- wifi: cfg80211: reject unsupported PMSR FTM location requests
- ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on
start/stop
- ASoC: amd: ps: fix wrong ACP version string in pci_request_regions()
- ASoC: cs42l43: Correct report for forced microphone jack
- ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after
lookup
- firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context
- ata: sata_dwc_460ex: use platform_get_irq()
- ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending
interrupts
- ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC
- drm/i915/gt: use correct selftest config symbol
- sched/vtime: Get rid of generic vtime_task_switch() implementation
- powerpc/time: Prepare to stop elapsing in dynticks-idle
- powerpc/vtime: Initialize starttime at boot for native accounting
- can: j1939: fix lockless local-destination check
- drm/i915/selftests: Fix GT PM sort comparators
- USB: storage: add NO_ATA_1X quirk for Longmai USB Key
- usb: chipidea: fix usage_count leak when autosuspend_delay is negative
- USB: gadget: snps-udc: fix device name leak on probe failure
- USB: gadget: fsl-udc: fix device name leak on probe failure
- USB: serial: ftdi_sio: add support for E+H FXA291
- USB: serial: keyspan_pda: fix data loss on receive throttling
- USB: serial: option: add TDTECH MT5710-CN
- crypto: rsa-pkcs1pad: Don't WARN on an empty digest
- RISC-V: KVM: Serialize virtual interrupt pending state updates
- usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits
- wifi: ath11k: Flush the posted write after writing to
PCIE_SOC_GLOBAL_RESET
- wifi: ath12k: Flush the posted write after writing to
PCIE_SOC_GLOBAL_RESET
- btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8
- ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI
- ASoC: cs35l56: Don't use devres to unregister component
- ASoC: cs35l56: Fix potential probe() deadlock
- ASoC: cs35l56: Use complete_all() to signal init_completion
- wifi: iwlwifi: mvm: validate SAR GEO response payload size
- wifi: iwlwifi: mvm: fix read in wake packet notification handler
- hwmon: (asus-ec-sensors) fix looping over banks while reading from EC
- hwmon: (asus-ec-sensors) fix EC read intervals
- hwmon: (asus-ec-sensors) add missed handle for ENOMEM
- wifi: mac80211: recalculate TIM when a station enters power save
- pds_core: reject component parameter in legacy firmware update
- amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN
- pds_core: yield the CPU while waiting for the adminq to drain
- pds_core: order completion reads after the ownership check
- pds_core: check for workqueue allocation failure
- tls: device: push pending open record on splice EOF
- selftest: af_unix: Add Kconfig file.
- selftests: af_unix: add USER_NS config
- selftests: openvswitch: add config file
- amt: make the head writable before rewriting the L2 header
- net: bridge: vlan: fix vlan range dumps starting with pvid
- net: dpaa: fix mode setting
- iomap: correct the range of a partial dirty clear
- net: stmmac: fix l3l4 filter rejecting unsupported offload requests
- net: stmmac: reset residual action in L3L4 filters on delete
- net: stmmac: enable the MAC on link up for all supported speeds
- octeontx2-vf: set TC flower flag on MCAM entry allocation
- ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup
- ppp: use IFF_NO_QUEUE in virtual interfaces
- ppp: convert to percpu netstats
- ppp: enable TX scatter-gather
- ppp: annotate data races in ppp_generic
- hinic: remove unused ethtool RSS user configuration buffers
- net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule
- net/mlx5e: Report zero bandwidth for non-ETS traffic classes
- net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation
- net: ipv6: fix dif and sdif mismatch in raw6_icmp_error
- ice: fix LAG recipe to profile association
- drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video()
- drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't
at 0 (v2)
- drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older
- drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT
- drm/nouveau/acr: fix missing nvkm_done() in error path of
nvkm_acr_oneinit()
- drm/radeon: fix r100_copy_blit for large BOs
- drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips
- drm/amdgpu: Fix VFCT bus number matching with soft filter
- drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X)
- media: aspeed: fix missing of_reserved_mem_device_release() on probe
failure
- media: cec: seco: unregister adapter on IR probe failure
- media: cedrus: clean up media device on probe failure
- media: cedrus: Fix missing cleanup in error path
- media: marvell-cam: fix missing pci_disable_device() on remove
- media: nxp: imx8-isi: Clean up already-initialized pipes on probe
failure
- media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init
error path
- media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding
- media: tegra-video: vi: fix invalid u32 return value in format lookup
- media: v4l2-ctrls-request: add NULL check in
v4l2_ctrl_request_complete()
- media: vb2: use ssize_t for vb2_read/vb2_write
- media: vidtv: fix reference leak on failed device registration
- media: vimc: fix reference leak on failed device registration
- media: vivid: add vivid_update_reduced_fps()
- media: vpif_capture: fix OF node reference imbalance
- staging: rtl8723bs: fix inverted HT40 secondary channel offset
- platform/loongarch: laptop: Explicitly reset bl_powered state when
suspend
- LoongArch: Fix oops during single-step debugging
- x86/boot/compressed: Disable jump tables
- serial: sc16is7xx: implement gpio get_direction() callback
- tracing/eprobe: Fix exact system name matching in
eprobe_dyn_event_match()
- tracing/probes: Avoid temporary buffer truncation in
trace_probe_match_command_args()
- tracing/probes: Fix potential underflow in LEN_OR_ZERO macro
- tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err()
- arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates
- Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer
updates"
- mptcp: decrement subflows counter on failed passive join
- mptcp: only set DATA_FIN when a mapping is present
- iommu/vt-d: Disallow SVA if page walk is not coherent
- ice: use READ_ONCE() to access cached PHC time
- drm/amd/pm: make pp_features read-only when scpm is enabled
- drm/amd/display: Fix dcn32 DTB DTO update breaking live pixel rate
sources
- io_uring/rw: fix missing ERESTARTSYS conversion in read paths
- net: pcs: xpcs: fix SGMII state reading
- bpf: drop bpf_lsm_getselfattr from hook list
- udmabuf: Do not create malformed scatterlists
- i2c: davinci: Unregister cpufreq notifier on probe failure
- VFS/audit: introduce kern_path_parent() for audit
- audit: widen ino fields to u64
- audit: use 'unsigned int' instead of 'unsigned'
- ALSA: hda: conexant: Remove mic bias threshold override
- ALSA: hda: Fix cached processing coefficient verbs
- rxrpc: Pull out certain app callback funcs into an ops table
- fbcon: Rename struct fbcon_ops to struct fbcon_par
- fbcon: Use correct type for vc_resize() return value
- rxrpc: Don't need barrier for ->tx_bottom and ->acks_hard_ack
- rxrpc: Use irq-disabling spinlocks between app and I/O thread
- rxrpc: Fix notification vs call-release vs recvmsg
- rxrpc: Fix socket notification race
- vduse: Use fixed 4KB bounce pages for non-4KB page size
- vduse: remove unused vaddr parameter of vduse_domain_free_coherent
- vduse: take out allocations from vduse_dev_alloc_coherent
- octeontx2: Annotate mmio regions as __iomem
- octeontx2-pf: clear stale mailbox IRQ state before request_irq()
- octeontx2-vf: clear stale mailbox IRQ state before request_irq()
- fbdev/efifb: Replace references to global screen_info by local pointer
- ASoC: mediatek: mt8192-afe-pcm: Convert to devm_pm_runtime_enable()
- ASoC: mediatek: mt8192-afe-pcm: Simplify with dev_err_probe()
- ASoC: mediatek: Use common mtk_afe_pcm_platform with common probe cb
- ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable
- ASoC: mediatek: mt8183: Check runtime resume during probe
- netfilter: nft_set_pipapo: use GFP_KERNEL for insertions
- netfilter: nft_set_pipapo: move prove_locking helper around
- netfilter: nft_set_pipapo: make pipapo_clone helper return NULL
- netfilter: nft_set_pipapo: prepare walk function for on-demand clone
- netfilter: nft_set_pipapo: merge deactivate helper into caller
- netfilter: nft_set_pipapo: prepare pipapo_get helper for on-demand clone
- netfilter: nft_set_pipapo: move cloning of match info to insert/removal
path
- netfilter: nf_conntrack_sip: remove net variable shadowing
- netfilter: nf_tables: Remove unused nft_reduce_is_readonly()
- netfilter: nf_tables: remove register tracking infrastructure
- NFSD: pass nfsd_file to nfsd_iter_read()
- sunrpc: allocate a separate bvec array for socket sends
- SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists
- SUNRPC: Return an error from xdr_buf_to_bvec() on overflow
- mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages
- dma: dw-edma: Fix build warning in dw_edma_pcie_probe()
- dmaengine: dw-edma: Fix confusing cleanup.h syntax
- platform/x86: dell-smbios: Move request functions for reuse
- i2c: imx: separate atomic, dma and non-dma use case
- nfs: remove dead code for the old swap over NFS implementation
- ovl: use linked upper dentry in copy-up tmpfile
- bootconfig: do not put quotes on cmdline items unless necessary
- bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c
- bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline()
- net: ipa: fix SMEM state handle leaks in SMP2P init
- KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN
- udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf()
- rxrpc: Disable IRQ, not BH, to take the lock for ->attend_link
- netfilter: nft_quota: use atomic64_xchg for reset
- soc: qcom: ice: Allow explicit votes on 'iface' clock for ICE
- wifi: cfg80211: pass net_device to .set_monitor_channel
- wifi: cfg80211: define and use wiphy guard
- wifi: cfg80211: derive S1G beacon TSF from S1G fields
- riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus()
- drm/xe/wopcm: fix WOPCM size for LNL+
- smb: move some duplicate definitions to common/cifsglob.h
- regulator: mt6358: use regmap helper to read fixed LDO calibration
- netlink: specs: rt-link: convert bridge port flag attributes to u8
- wifi: mt76: mt7925: extend mt7925_mcu_bss_he_tlv for per-link BSS
- ovl: fix trusted xattr escape prefix matching
- drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem
- dpll: add clock quality level attribute and op
- net/mlx5: DPLL, Add clock quality level op implementation
- net/mlx5: Remove newline at the end of a netlink error message
- net/mlx5: Refactor EEPROM query error handling to return status
separately
- octeontx2-pf: tc: fix egress ratelimiting
- ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV
- drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay
- drm/displayid: move drm_displayid.h to drm_displayd_internal.h
- drm/displayid: fix Tiled Display Topology ID size
- drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds
- drm/amdkfd: Use kvcalloc to allocate arrays
- drm/gfx10: Program DB_RING_CONTROL
- drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge
- media: nuvoton: npcm-video: fix error handling in npcm_video_init()
- media: qcom: camss: Fix RDI streaming for CSID GEN2
- media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely
- ALSA: timer: drain a slave's callback before its master detaches it
- ALSA: timer: don't re-enter an instance callback that is still running
- LoongArch: Retrieve CPU package ID from PPTT when available
- sysctl: treewide: constify ctl_table_header::ctl_table_arg
- ceph: fix refcount leak in ceph_readdir()
- ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP
- net: move skb_gro_receive_list from udp to core
- net: add pskb_may_pull() to skb_gro_receive_list()
- vsock/virtio: collapse receive queue under memory pressure
- drm/amd/pm: fix amdgpu_pm_info power display units
- drm/amd/pm: fix smu13 power limit range calculation
- drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources
- xfs: add an explicit owner field to xfs_da_args
- xfs: factor out xfs_attr3_leaf_init
- xfs: don't replace the wrong part of the cow fork
- rxrpc: Fix CPU time starvation in I/O thread
- ASoC: mediatek: mt8183-afe-pcm: Shorten memif_data table using macros
- ASoC: mediatek: mt8183-afe-pcm: Support >32 bit DMA addresses
- tcp: Decrement tcp_md5_needed static branch
- nvmet: Introduce nvmet_req_transfer_len()
- block: add helper add_disk_final()
- block: remove redundant GD_NEED_PART_SCAN in add_disk_final()
- Bluetooth: Add PA_LINK to distinguish BIG sync and PA sync connections
- Bluetooth: hci_core: Fix not accounting for BIS/CIS/PA links separately
- afs: Improve server refcount/active count tracing
- afs: Make afs_lookup_cell() take a trace note
- afs: Drop the net parameter from afs_unuse_cell()
- rxrpc: Allow the app to store private data on peer structs
- afs: Use the per-peer app data provided by rxrpc
- afs: Fix afs_server ref accounting
- afs: Simplify cell record handling
- afs: Fix dynamic lookup to fail on cell lookup failure
- afs: Fix lack of locking around modifications of net->cells_dyn_ino
- lib/string_choices: Add str_plural() helper
- USB: gadget: Use str_enable_disable-like helpers
- usb: musb: omap2430: clean up probe error handling
- net/mlx5e: Fix NULL pointer dereference in ioctl module EEPROM query
- rxrpc: Fix locking issues with the peer record hash
- wifi: nl80211: fix nl80211_start_radar_detection return value
- afs: Set vllist to NULL if addr parsing fails
- dpll: fix clock quality level reporting
- afs: Fix delayed allocation of a cell's anonymous key
- afs: handle CB.InitCallBackState3 requests without a server record
- Bluetooth: hci_conn: Fix running bis_cleanup for hci_conn->type PA_LINK
- Bluetooth: hci_conn: Fix not cleaning up Broadcaster/Broadcast Source
- Bluetooth: hci_conn: Remove redundant memset after kzalloc
- Bluetooth: hci_conn: Fix not cleaning up PA_LINK connections
- Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate()
- afs: Fix uninit var in afs_alloc_anon_key()
- Upstream stable to v6.6.148, v6.12.101
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68371
- usb: musb: omap2430: Do not put borrowed of_node in probe
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72130
- nvmet-auth: reject short AUTH_RECEIVE buffers
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72168
- mtd: maps: vmu-flash: fix fault in unaligned fixup
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72213
- mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72244
- gpu/buddy: bail out of try_harder when alignment cannot be honoured
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68129
- gve: fix Rx queue stall on alloc failure
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-53078
- bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68119
- tcp: initialize standalone TCP-AO response padding
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68136
- net: gro: fix double aggregation of flush-marked skbs
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68139
- net/mlx5e: Use sender devcom for MPV master-up
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68145
- iomap: fix out-of-bounds bitmap_set() with zero-length range
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68161
- sctp: close UDP tunnel sockets during netns teardown
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68162
- sctp: avoid auth_enable sysctl UAF during netns teardown
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68178
- misc: nsm: pin the module while the device is open
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68179
- misc: nsm: only unlock nsm_dev on post-lock error paths
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68183
- firmware: stratix10-svc: fix memory leaks and list corruption bugs
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68193
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68203
- media: vivid: fix cleanup bugs in vivid_init()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68205
- media: v4l2-fwnode: Fix subdev owner overwritten in
v4l2_async_register_subdev_sensor()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68221
- media: nuvoton: npcm-video: fix memory leaks in probe and remove
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68225
- media: i2c: alvium: fix critical pointer access in alvium_ctrl_init
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68228
- media: chips-media: wave5: Move src_buf Removal to finish_encode
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68235
- drm/amd/display: dce100: skip non-DP stream encoders for DP MST
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68247
- drm/i915/bios: range check LFP Data Block panel_type2
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68260
- drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68261
- drm/imagination: fix error checking of pvr_vm_context_lookup()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68262
- drm/imagination: Fix user array stride in pvr_set_uobj_array()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68263
- drm/imagination: Fix double call to drm_sched_entity_fini()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68437
- drm/imagination: Fit paired fragment job in the correct CCCB
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68281
- drm/imagination: Count paired job fence as dependency in prepare_job()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68290
- rds: tcp: unregister sysctl before tearing down listen socket
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68293
- net/mlx5: Fix MCIA register buffer overflow on 32 dword reads
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68439
- wifi: mt76: mt7925: fix possible NULL-pointer deref in
mt7925_mcu_bss_he_tlv()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68314
- net: mctp i3c: clean up notifier and buses if driver register fails
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68318
- pds_core: fix use-after-free on workqueue during remove
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68319
- pds_core: fix deadlock between reset thread and remove
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68346
- ALSA: hda: cs35l41: validate and free ACPI mute object
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2025-40098
- ALSA: hda: cs35l41: Fix NULL pointer dereference in
cs35l41_get_acpi_mute_state()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68442
- btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68443
- hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68372
- usb: core: port: Deattach Type-C connector on component unbind
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68396
- scsi: core: wake eh reliably when using scsi_schedule_eh
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68408
- wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64570
- wifi: mac80211: fix fils_discovery double free on alloc failure
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64568
- wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72175
- fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-45901
- netfilter: nf_tables: revert commit_mutex usage in reset path
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-45897
- netfilter: nft_counter: serialize reset with spinlock
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68093
- KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision
after hotplug
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68164
- mm/damon/core: disallow overlapping input ranges for damon_set_regions()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68165
- mm/damon/core: validate ranges in damon_set_regions()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72015
- fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72017
- net: macb: drop in-flight Tx SKBs on close
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72030
- ata: libata-core: Reject an invalid concurrent positioning ranges count
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72023
- octeontx2-pf: fix SQB pointer leak on init failure
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72040
- ipmi: fix refcount leak in i_ipmi_request()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72045
- octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72062
- gpio: mt7621: avoid corruption of shared interrupt trigger state
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72051
- net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for
changelink
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72065
- net: mana: Validate the packet length reported by the NIC
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72069
- locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72070
- wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72142
- i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72147
- dmaengine: dw-edma-pcie: Reject devices without driver data
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72254
- netfilter: nft_fib: reject fib expression on the netdev egress hook
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72253
- netfilter: nf_conntrack_sip: validate skb_dst() before accessing it
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72260
- ASoC: mediatek: mt8192: Check runtime resume during probe
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72305
- VDUSE: avoid leaking information to userspace
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72299
- tipc: restrict socket queue dumps in enqueue tracepoints
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-74436
- rxrpc: serialize kernel accept preallocation with socket teardown
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64205
- i2c: i801: fix hardware state machine corruption in error path
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68096
- audit: fix recursive locking deadlock in audit_dupe_exe()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64280
- fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68147
- fscrypt: Avoid dynamic allocation in fscrypt_get_devices()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68123
- openvswitch: fix GSO userspace truncation underflow
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68097
- ksmbd: validate ACE size against SID sub-authorities
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68098
- ksmbd: bound DACL dedup walk to copied ACEs
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68099
- ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68100
- ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68104
- drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68106
- drm/amdgpu: fix division by zero with invalid uvd dimensions
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68429
- drm/dp_mst: Handle torn-down topology gracefully in
drm_dp_mst_topology_queue_probe()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68107
- drm/amdgpu/vcn4: avoid rereading IB param length
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68108
- drm/amdgpu/vce: fix integer overflow in image size
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68110
- drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68111
- drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68112
- drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68430
- drm/amdgpu/gfx8: drop unecessary BUG_ON()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68246
- drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68115
- drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68116
- vxlan: mdb: Fix source list corruption on a failed replace
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68117
- tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68121
- pppoe: reload header pointer after dev_hard_header()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68124
- mctp: serial: handle zero-length frames to prevent rx buffer overflow
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68125
- mac802154: llsec: reject frames shorter than the authentication tag
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68126
- mac802154: hold an interface reference across the scan worker
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68127
- ila: reload IPv6 header after pskb_may_pull in checksum adjust
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68130
- ksmbd: defer destroy_previous_session() until after NTLM authentication
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68131
- rbd: Reset positive result codes to zero in object map update path
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68135
- net: hip04: fix RX buffer leak on build_skb failure
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68137
- net/x25: fix use-after-free in x25_kill_by_neigh()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68140
- net/iucv: fix use-after-free of a severed iucv_path
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68141
- net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68142
- geneve: require CAP_NET_ADMIN in the device netns for changelink
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68143
- net: slip: serialize receive against buffer reallocation
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68432
- vxlan: require CAP_NET_ADMIN in the device netns for changelink
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68144
- phonet: pep: fix use-after-free in pep_get_sb()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68146
- ftrace: Add global mutex to serialize trace_parser access
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68148
- fscrypt: Add missing superblock check in find_or_insert_direct_key()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68149
- fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68151
- binfmt_elf_fdpic: only honour the first PT_INTERP
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68153
- libceph: remove debugfs files before client teardown
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68154
- libceph: reject zero bucket types in crush_decode
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68155
- libceph: Reject monmaps advertising zero monitors
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68156
- libceph: refresh auth->authorizer_buf{,_len} after authorizer update
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68157
- libceph: guard missing CRUSH type name lookup
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68158
- libceph: Fix multiplication overflow in decode_new_up_state_weight()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68433
- libceph: bound get_version reply decode to front len
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68160
- ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68175
- tracing: Fix resource leak on mmiotrace trace_pipe close
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68176
- tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68180
- intel_th: fix MSC output device reference leak
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68181
- mei: bus: access mei_device under device_lock on cleanup
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68182
- comedi: comedi_parport: deal with premature interrupt
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68184
- cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68186
- binfmt_misc: set have_execfd only once the interpreter is opened
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68187
- exec: fix unsigned loop counter wrap in transfer_args_to_stack()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68188
- Bluetooth: RFCOMM: Fix session UAF in set_termios
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68189
- Bluetooth: hci_sync: Protect UUID list traversal
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68190
- staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68192
- wifi: brcmfmac: make release_scratchbuffers idempotent
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68194
- wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68195
- wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68196
- wifi: wilc1000: validate assoc response length before subtracting header
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68197
- wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-
oper
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68199
- wifi: ath6kl: fix OOB access from firmware ADDBA window size
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68202
- ALSA: seq: close a re-opened queue timer in the destructor
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68204
- media: vivid: check for vb2_is_busy() when toggling caps
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68206
- media: v4l2-ctrls: validate HEVC active reference counts
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68207
- media: ti: vpe: unwind v4l2 device registration on probe error
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68209
- media: sun4i-csi: Return queued buffers on start_streaming() failure
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68210
- media: stm32: dcmi: unregister notifier on probe failure
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68212
- media: saa7134: Fix a possible memory leak in saa7134_video_init1
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68213
- media: rtl2832_sdr: Return queued buffers on start_streaming() failure
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68214
- media: rtl2832: fix use-after-free in rtl2832_remove()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68215
- media: radio-si476x: Unregister v4l2_device on probe failure
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68216
- media: pwc: Return queued buffers on start_streaming() failure
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68217
- media: pwc: Drain fill_buf on start_streaming() failure
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68218
- media: pci: dm1105: Free allocated workqueue
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68219
- media: nxp: imx8-isi: Fix potential out-of-bounds issues
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68220
- media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and
pipe
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68222
- media: msi2500: Return queued buffers on start_streaming() failure
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68223
- media: meson: vdec: Fix memory leak in error path of vdec_open
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68226
- media: cx23885: add ioremap return check and cleanup
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68227
- media: cx231xx: fix devres lifetime
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68229
- media: cedrus: skip invalid H.264 reference list entries
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68231
- media: airspy: Return queued buffers on start_streaming() failure
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68445
- drm/vc4: Prevent shader BO mappings from becoming writable
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68446
- drm/vmwgfx: Validate vmw_surface_metadata::array_size
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68234
- drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68236
- drm/amd/display: set new_stream to NULL after release
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68243
- drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68244
- drm/i915/gem: Do not leak siblings[] on proto context error
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68248
- drm/i915: Return NULL on error in active_instance
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68249
- drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68250
- drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68251
- drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68255
- drm/virtio: bound EDID block reads to the response buffer
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68256
- drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path
leaks prev_sink reference
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68259
- drm/amdkfd: Check bounds in allocate_event_notification_slot
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68269
- drm/i915/gem: Add missing nospec on parallel submit slot
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68271
- drm/nouveau: fix reversed error cleanup order in ucopy functions
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68272
- drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68277
- drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68278
- drm/dp/mst: fix buffer overflows in sideband chunk accumulation
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68279
- drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68280
- drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68284
- bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68294
- net: qrtr: restrict socket creation to the initial network namespace
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68297
- tipc: fix u16 MTU truncation in media and bearer MTU validation
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68299
- vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68300
- sctp: auth: verify auth requirement when auth_chunk is NULL
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68301
- net: hsr: fix memory leak on slave unregistration by removing synced
VLANs
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68302
- amt: re-read skb header pointers after every pull
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68304
- wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68306
- wifi: mt76: mt7996: fix possible NULL-pointer deref in
mt7996_mcu_sta_bfer_eht()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68308
- wifi: mt76: mt7996: check pointer returned by
mt76_connac_get_he_phy_cap()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68309
- wifi: mt76: connac: fix possible NULL-pointer deref in
mt76_connac_mcu_uni_bss_he_tlv()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68310
- wifi: mt76: mt7915: guard HE capability lookups
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68313
- tipc: fix infinite loop in __tipc_nl_compat_dumpit
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64576
- nexthop: initialize extack in nh_res_bucket_migrate()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64577
- gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68315
- sctp: validate stream count in sctp_process_strreset_inreq()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68317
- pds_core: fix auxiliary device add/del races
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68320
- sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68324
- iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68325
- iommu/amd: Bound the early ACPI HID map
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68326
- wifi: mwifiex: bound uAP association event IEs to the event buffer
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68327
- wan: wanxl: Only reset hardware after BAR mapping
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68328
- nfp: Check resource mutex allocation
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64574
- wifi: mac80211: tear down new links on vif update error path
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68329
- iommu/amd: Wait for completion instead of returning early in
iommu_completion_wait()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68331
- dpaa2-eth: put MAC endpoint device on disconnect
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68333
- dpaa2-switch: put MAC endpoint device on disconnect
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68335
- rds: drop incoming messages that cross network namespace boundaries
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68336
- bonding: fix devconf_all NULL dereference when IPv6 is disabled
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68338
- net/packet: avoid fanout hook re-registration after unregister
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68339
- Bluetooth: btusb: validate Realtek vendor event length
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68340
- hwmon: occ: validate poll response sensor blocks
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68343
- smb: client: validate DFS referral PathConsumed
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68348
- ASoC: tas2781: bound firmware description string parsing
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68450
- btrfs: free mapping node on duplicate reloc root insert
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68349
- wifi: carl9170: fix buffer overflow in rx_stream failover path
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68350
- wifi: carl9170: fix OOB read from off-by-two in TX status handler
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68351
- wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68352
- wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68353
- wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68354
- firewire: net: Fix fragmented datagram reassembly
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68355
- wifi: ath11k: fix potential buffer underflow in
ath11k_hal_rx_msdu_list_get()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68357
- watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68359
- hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68360
- hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68361
- hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68362
- wifi: ath11k: fix NULL pointer dereference in
ath11k_hal_srng_access_begin
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68363
- wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware
request
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68365
- USB: serial: io_edgeport: cap received transmit credits
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68366
- usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64583
- usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before
teardown
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68368
- usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68369
- usb: gadget: printer: fix infinite loop in printer_read()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64584
- usb: gadget: f_midi: cancel pending IN work before freeing the midi
object
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68370
- usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68373
- wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64569
- mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68376
- sctp: fix auth_hmacs array size in struct sctp_cookie
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68377
- net/sched: act_tunnel_key: Defer dst_release to RCU callback
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64578
- ksmbd: validate compound request size before reading StructureSize2
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68381
- ksmbd: pin conn during async oplock break notification
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68386
- bpf, sockmap: Reject unhashed UDP sockets on sockmap update
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68388
- smb/client: handle overlapping allocated ranges in fallocate
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68389
- Bluetooth: hci_qca: Clear memdump state on invalid dump size
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68391
- Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68392
- Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64573
- Bluetooth: qca: fix NVM tag length underflow in TLV parser
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68449
- ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-
scanning
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68395
- ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is
registered
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68397
- net/iucv: take a reference on the socket found in afiucv_hs_rcv()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64572
- ipv4: fib: free fib_alias with kfree_rcu() on insert error path
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68398
- ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68402
- wifi: cfg80211: bound element ID read when checking non-inheritance
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68403
- wifi: brcmfmac: initialize SDIO data work before cleanup
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68405
- wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68406
- wifi: cfg80211: validate PMSR FTM preamble range
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68407
- wifi: nl80211: free RNR data on MBSSID mismatch
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64571
- wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68410
- wifi: libertas: fix memory leak in helper_firmware_cb()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68411
- wifi: mac80211_hwsim: clamp virtio RX length before skb_put
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68413
- wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68414
- wifi: cfg80211: cancel sched scan results work on unregister
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64579
- xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64580
- xfrm6: clear dst.dev on error to avoid double netdev_put in
xfrm6_fill_dst()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68416
- mtd: fix double free and WARN_ON in add_mtd_device() error paths
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68417
- RDMA/siw: publish QP after initialization
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68419
- RDMA/irdma: Prevent rereg_mr for non-mem regions
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68444
- firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68422
- btrfs: fix root leak if its reloc root is unexpected in
merge_reloc_roots()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64567
- btrfs: reject free space cache with more entries than pages
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68425
- IB/mad: Drop unmatched RMPP responses before reassembly
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64565
- Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68427
- gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72146
- dmaengine: sh: rz-dmac: Move interrupt request after everything is set
up
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72124
- can: isotp: serialize TX state transitions under so->rx_lock
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72125
- can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72115
- can: bcm: track a single source interface for ANYDEV timeout/throttle
ops
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72117
- can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72116
- can: bcm: fix stale rx/tx ops after device removal
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72113
- can: bcm: add missing device refcount for CAN filter removal
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72114
- can: bcm: validate frame length in bcm_rx_setup() for RTR replies
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72119
- can: bcm: extend bcm_tx_lock usage for data and timer updates
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72118
- can: bcm: fix CAN frame rx/tx statistics
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-72121
- can: bcm: add locking when updating filter and timer values
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-68428
- KVM: x86/mmu: Fix use-after-free on vendor module reload
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64562
- KVM: nVMX: Hide shadow VMCS right after VMCLEAR
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-64561
- KVM: x86: Check for invalid/obsolete root *after* making MMU pages
available
* Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
CVE-2026-53090
- bpf: Fix ld_{abs,ind} failure path analysis in subprogs
* test_vxlan_vnifiltering.sh from ubuntu_kselftests_net failed on linux-
oem-6.8 (with ipv6 default rdst) (LP: #2071590)
- selftests: net: use slowwait to make sure IPv6 setup finished
* ubuntu_bpf failed to build in noble (error: redefinition of
'stack_load_preserves_const_precision') (LP: #2160493)
- SAUCE: Revert "selftests/bpf: validate fake register spill/fill
precision backtracking logic"
* CVE-2026-64564
- sctp: don't free the ASCONF's own transport in DEL-IP processing
* Backport: "mm/gup: fix GUP-fast fallback for NULL-mapping order-0 folios"
(LP: #2162917)
- mm/gup: fix GUP-fast fallback for NULL-mapping order-0 folios
* qrtr: ns: node limit of 64 breaks QRTR routing on large multi-node
deployments (LP: #2165140)
- net: qrtr: ns: Raise node count limit to 512
* [UBUNTU 24.04] kernel: CPU hotplug unsupported by CPUMF (LP: #2165732)
- s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
* CVE-2026-68399
- bpf: Fix UAF in sock clone early bailouts
* CVE-2025-38563
- perf/core: Prevent VMA split of buffer mappings
* CVE-2025-38565
- perf/core: Exit early on perf_mmap() fail
* CVE-2025-38187
- drm/nouveau: fix a use-after-free in r535_gsp_rpc_push()
* CVE-2025-38069
- PCI: endpoint: pci-epf-test: Fix double free that causes kernel to oops
* CVE-2025-40014
- objtool, spi: amd: Fix out-of-bounds stack access in amd_set_spi_freq()
* CVE-2025-21985
- drm/amd/display: Fix out-of-bound accesses
* CVE-2024-56552
- drm/xe/guc_submit: fix race around suspend_pending
* CVE-2025-21687
- vfio/platform: check the bounds of read/write syscalls
* Noble update: upstream stable patchset 2026-09-14 (LP: #2167237)
- ext4: fix fd leak in EXT4_IOC_MOVE_EXT cross-sb validation
- mm: refactor mm_access() to not return NULL
- Upstream stable to v6.6.146, v6.12.98, v6.6.147, v6.12.99, v6.12.100
* Noble update: upstream stable patchset 2026-09-14 (LP: #2167237) //
CVE-2026-64560
- posix-cpu-timers: Prevent UAF caused by non-leader exec() race
* Noble update: upstream stable patchset 2026-09-10 (LP: #2166995)
- bpf, arm64: Reject out-of-range B.cond targets
- nfsd: release layout stid on setlease failure
- Bluetooth: btmtk: apply the common btmtk_fw_get_filename
- Bluetooth: btmtk: Fix failed to send func ctrl for MediaTek devices.
- Bluetooth: btmtk: Fix wait_on_bit_timeout interruption during shutdown
- userfaultfd: gate must_wait writability check on pte_present()
- perf: Fix dangling cgroup pointer in cpuctx backport
- Bluetooth: btmtk: Fix btmtk.c undefined reference build error
- device property: initialize the remaining fields of fwnode_handle in
fwnode_init()
- f2fs: validate orphan inode entry count
- f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
- f2fs: fix potential deadlock in f2fs_balance_fs()
- f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs()
- f2fs: fix listxattr handling of corrupted xattr entries
- block: Avoid mounting the bdev pseudo-filesystem in userspace
- i2c: core: fix irq domain leak on adapter registration failure
- i2c: core: fix hang on adapter registration failure
- i2c: core: fix NULL-deref on adapter registration failure
- i2c: core: fix adapter debugfs creation
- fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
- NFSv4/flexfiles: reject zero filehandle version count
- locking/rtmutex: Make sure we wake anything on the wake_q when we
release the lock->wait_lock
- bonding: fix xfrm offload feature setup on active-backup mode
- mm/vmscan: flush deferred TLB before freeing large folios
- perf trace beauty fcntl: Fix build with older kernel headers
- ACPI: CPPC: Suppress UBSAN warning caused by field misuse
- ACPI: NFIT: core: Fix possible NULL pointer dereference
- perf/core: Detach event groups during remove_on_exec
- arm64: sysreg: Add layout for ID_AA64MMFR4_EL1
- virtio_net: Support dynamic rss indirection table size
- LoongArch: Add PIO for early access before ACPI PCI root register
- usb: gadget: function: rndis: add length check to response query
- usb: gadget: function: rndis: add length check for header
- iio: accel: bmc150: clamp the device-reported FIFO frame count
- iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error
- iio: adc: lpc32xx: Initialize completion before requesting IRQ
- iio: adc: ti-ads124s08: Return reset GPIO lookup errors
- iio: chemical: scd30: Cleanup initializations and fix sign-extension bug
- iio: event: Fix event FIFO reset race
- iio: gyro: bmg160: bail out when bandwidth/filter is not in table
- iio: gyro: bmg160: wait full startup time after mode change at probe
- iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ
- iio: imu: st_lsm6dsx: deselect shub page before reading whoami
- iio: light: al3010: fix incorrect scale for the highest gain range
- iio: light: gp2ap002: fix runtime PM leak on read error
- iio: light: opt3001: fix missing state reset on timeout
- iio: light: tsl2591: return actual error from probe IRQ failure
- iio: light: veml6030: fix channel type when pushing events
- iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call
- iio: temperature: ltc2983: Fix reinit_completion() called after
conversion start
- ALSA: virtio: Add missing 384 kHz PCM rate mapping
- ALSA: ymfpci: check snd_ctl_new1() return value
- ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input
parser
- ALSA: cmipci: check snd_ctl_new1() return value
- ALSA: es1938: check snd_ctl_new1() return value
- ALSA: firewire: isight: bound the sample count to the packet payload
- ALSA: gus: check snd_ctl_new1() return value
- ALSA: ice1712: check snd_ctl_new1() return value
- ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()
- ALSA: usb-audio: avoid kobject path lookup in DualSense match
- ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put()
- ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch
put callbacks
- ALSA: usb-audio: Update Babyface Pro control caches only after
successful writes
- ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful
writes
- vfio/pci: Use a private flag to prevent power state change with VFs
- vfio/pci: Latch disable_idle_d3 per device
- vfio/pci: Release the VGA arbiter client on register_device() failure
- vfio/pci: Fix racy bitfields and tighten struct layout
- vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc
- Bluetooth: btusb: Add USB ID 2c4e:0128 for Mercusys MA60XNB
- Bluetooth: btusb: fix use-after-free on registration failure
- Bluetooth: btusb: fix use-after-free on marvell probe failure
- Bluetooth: btusb: fix wakeup source leak on probe failure
- binder: fix UAF in binder_thread_release()
- binder: fix UAF in binder_free_transaction()
- usb: xhci: Fix sleep in atomic context in xhci_free_streams()
- PCI: altera: Do not dispose parent IRQ mapping
- mm/damon/ops-common: handle extreme intervals in damon_hot_score()
- netfilter: ipset: fix race between dump and ip_set_list resize
- virtio-mmio: fix device release warning on module unload
- hwrng: virtio: clamp device-reported used.len at copy_data()
- USB: chaoskey: Fix slab-use-after-free in chaoskey_release()
- usb: dwc3: run gadget disconnect from sleepable suspend context
- 6lowpan: fix NHC entry use-after-free on error path
- tipc: fix out-of-bounds read in broadcast Gap ACK blocks
- staging: vme_user: bound slave read/write to the kern_buf size
- smb: client: restrict implied bcc[0] exemption to responses without data
area
- staging: vme_user: fix location monitor leak in fake bridge
- staging: vme_user: fix location monitor leak in tsi148 bridge
- media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe
- staging: media: atomisp: reduce load_primary_binaries() stack usage
- staging: rtl8723bs: fix heap buffer overflow in
rtw_cfg80211_set_wpa_ie()
- staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()
- staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop
- staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop
- staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and
join_cmd_hdl()
- staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop
- staging: rtl8723bs: fix OOB write in HT_caps_handler()
- crypto: amlogic - avoid double cleanup in meson_crypto_probe()
- ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then
SMB2_CANCEL
- net: af_key: initialize alg_key_len for IPComp states
- audit: Fix data races of skb_queue_len() readers on audit_queue
- Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete
- debugobjects: Plug race against a concurrent OOM disable
- fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns
- NTB: epf: Avoid calling pci_irq_vector() from hardirq context
- io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item
- ipv4: igmp: remove multicast group from hash table on device destruction
- net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes
- mfd: cros_ec: Delay dev_set_drvdata() until probe success
- mm: shrinker: fix NULL pointer dereference in debugfs
- netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump
- f2fs: bound i_inline_xattr_size for non-inline-xattr inodes
- drm/amd: Fix set but not used warnings
- apparmor: advertise the tcp fast open fix is applied
- nfsd: move name lookup out of nfsd4_list_rec_dir()
- nfsd: change nfs4_client_to_reclaim() to allocate data
- arm64: Treat HCR_EL2.E2H as RES1 when ID_AA64MMFR4_EL1.E2H0 is negative
- arm64: Fix early handling of FEAT_E2H0 not being implemented
- KVM: arm64: Initialize HCR_EL2.E2H early
- arm64: Revamp HCR_EL2.E2H RES1 detection
- arm64: sysreg: Correct sign definitions for EIESB and DoubleLock
- iio: adc: spear: Initialize completion before requesting IRQ
- iio: imu: inv_icm42600: fix timestamp clock period by using lower value
- ALSA: usb-audio: Roll back quirk control caches on write errors
- usb: typec: tcpci_rt1711h: unregister TCPCI port with devres
- gpio: eic-sprd: use raw_spinlock_t in the irq startup path
- netfilter: ebtables: module names must be null-terminated
- netfilter: ebtables: terminate table name before find_table_lock()
- Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()
- Bluetooth: bnep: pin L2CAP connection during netdev registration
- Bluetooth: btnxpuart: Fix out-of-bounds firmware read in
nxp_recv_fw_req_v3()
- Bluetooth: fix UAF in bt_accept_dequeue()
- Bluetooth: L2CAP: validate option length before reading conf opt value
- fs/ntfs3: fsync files by syncing parent inodes
- fs/ntfs3: zero-fill folios beyond i_valid in ntfs_read_folio()
- fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked()
- coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()
- smb/client: Fix error code in smb2_aead_req_alloc()
- ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE
- ksmbd: add a permission check for FSCTL_SET_ZERO_DATA
- ksmbd: serialize QUERY_DIRECTORY requests per file
- ksmbd: require source read access for duplicate extents
- ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock
cancellation
- ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY
- ksmbd: run set info with opener credentials
- ksmbd: enforce FILE_READ_ATTRIBUTES on SMB_FIND_FILE_POSIX_INFORMATION
- ksmbd: add per-handle permission check to FILE_LINK_INFORMATION
- ksmbd: use opener credentials for delete-on-close
- smb: client: fix query directory replay double-free
- smb: client: fix query_info() replay double-free
- smb: client: fix double-free in SMB2_ioctl() replay
- smb: client: fix change notify replay double-free
- smb: client: fix double-free in SMB2_flush() replay
- smb: client: fix double-free in SMB2_open() replay
- smb: client: fix double-free in SMB2_close() replay
- smb: client: Fix next buffer leak in receive_encrypted_standard()
- smb: client: use unaligned reads in parse_posix_ctxt()
- smb: client: harden POSIX SID length parsing
- smb: client: mask server-provided mode to 07777 in modefromsid
- OPP: of: Fix potential memory leak in opp_parse_supplies()
- firmware_loader: fix device reference leak in firmware_upload_register()
- cpufreq: intel_pstate: Sync policy->cur during CPU offline
- sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT
- cpufreq: Fix hotplug-suspend race during reboot
- cpufreq: pcc: fix use-after-free and double free in _OSC evaluation
- posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path
- clocksource/drivers/timer-tegra186: Fix support for multiple watchdog
instances
- X.509: Fix validation of ASN.1 certificate header
- tools/mm/slabinfo: Fix trace disable logic inversion
- tools/mm/slabinfo: fix total_objects attribute name
- HID: wacom: stop hardware after post-start probe failures
- HID: letsketch: fix UAF on inrange_timer at driver unbind
- HID: lg-g15: cancel pending work on remove to fix a use-after-free
- HID: sensor-hub: Add sensor_hub_input_attr_read_values() for multi-byte
reads
- hfs/hfsplus: zero-initialize buffer in hfs_bnode_read
- nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers
- media: mtk-jpeg: cancel workqueue on release for supported platforms
only
- xfs: use null daddr for unset first bad log block
- xfs: fix unreachable BIGTIME check in dquot flush validation
- bpf: Reject fragmented frames in devmap
- bpf: Restore sysctl new-value from 1 to 0
- net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()
- usb: cdc_acm: Add quirk for Uniden BC125AT scanner
- usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()
- USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub
- usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume()
- usb: free iso schedules on failed submit
- usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler
- usb: gadget: udc: Fix use-after-free in gadget_match_driver
- usb: gadget: f_printer: take kref only for successful open
- USB: idmouse: fix use-after-free on disconnect race
- USB: ldusb: fix use-after-free on disconnect race
- USB: iowarrior: fix use-after-free on disconnect
- USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD
- USB: legousbtower: fix use-after-free on disconnect race
- usb: sl811-hcd: disable controller wakeup on remove
- USB: storage: include US_FL_NO_SAME in quirks mask
- USB: misc: uss720: unregister parport on probe failure
- usb: mtu3: unmap request DMA on queue failure
- USB: serial: keyspan_pda: fix information leak
- USB: serial: option: add Telit Cinterion FE990D50 compositions
- USB: serial: digi_acceleport: fix broken rx after throttle
- USB: serial: digi_acceleport: fix hard lockup on disconnect
- USB: serial: digi_acceleport: fix write buffer corruption
- USB: ulpi: fix memory leak on registration failure
- USB: usb-storage: ene_ub6250: restore media-ready check
- usbip: tools: support SuperSpeedPlus devices
- usbip: vudc: fix NULL deref in vep_dequeue()
- usb: typec: anx7411: use devm_pm_runtime_enable()
- usb: typec: class: drop PD lookup reference
- usb: typec: tcpm: Validate SVID index in svdm_consume_modes()
- usb: typec: ucsi: Invert DisplayPort role assignment
- usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt
mode
- usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove
- usb: typec: ucsi: cancel pending work on system suspend
- iio: temperature: ltc2983: Fix n_wires default bypassing rotation check
- PCI: Always lift 2.5GT/s restriction in PCIe failed link retraining
- udf: validate free block extents against the partition length
- udf: validate VAT header length against the VAT inode size
- udf: validate sparing table length as an entry count, not a byte count
- hwrng: jh7110 - fix refcount leak in starfive_trng_read()
- dm-ioctl: report an error if a device has no table
- nvme-multipath: set BIO_REMAPPED on bios remapped to per-path namespace
disks
- btrfs: do not trim a device which is not writeable
- partitions: aix: bound the pp_count scan to the ppe array
- isofs: bound Rock Ridge symlink components to the SL record
- crypto: af_alg - Remove zero-copy support from skcipher and aead
- crypto: caam - use print_hex_dump_devel to guard key hex dumps
- crypto: caam - use print_hex_dump_devel to guard key hex dumps again
- crypto: ecc - Fix carry overflow in vli multiplication
- crypto: pcrypt - restore callback for non-parallel fallback
- crypto: drbg - Fix returning success on failure in CTR_DRBG
- crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels
- crypto: drbg - Fix the fips_enabled priority boost
- crypto: qat - validate RSA CRT component lengths
- crypto: talitos - use dma_sync_single_for_cpu() before reading
descriptor header
- crypto: talitos - add chaining of arbitrary number of descriptor for the
SEC1
- crypto: talitos - move dma unmapping code in flush_channel() into a
standalone dma_unmap_request() function
- crypto: talitos - move dma mapping code in talitos_submit() into a
standalone dma_map_request() function
- crypto: talitos - move code in current_desc_hdr() into a standalone
function
- crypto: talitos/hash - prepare SEC1 descriptor chaining, remove
additional descriptor
- crypto: talitos/hash - use descriptor chaining for SEC1 instead of
workqueue
- crypto: talitos/hash - drop workqueue mechanism for SEC1
- crypto: talitos/hash - rename first_desc/last_desc to
first_request/last_request
- crypto: talitos/hash - remove useless wrapper
- crypto: talitos/hash - fix SEC2 64k - 1 ahash request limitation
- arm64: fpsimd: Fix type mismatch in sme_{save,load}_state()
- spi: fsl-lpspi: replace dmaengine_terminate_all() with
dmaengine_terminate_sync()
- spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
- EDAC/i10nm: Don't fail probing if ADXL is missing
- watchdog: apple: Add "apple,t8103-wdt" compatible
- tracing: Prevent out-of-bounds read in glob matching
- NFSv4: include MAY_WRITE in open permission mask for O_TRUNC
- module: decompress: check return value of module_extend_max_pages()
- exfat: bound uniname advance in exfat_find_dir_entry()
- NTB: epf: Fix request_irq() unwind in ntb_epf_init_isr()
- KVM: VMX: Refresh GUEST_PENDING_DBG_EXCEPTIONS.BS on all injected #DBs
- KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest
mode
- udmabuf: fix DMA direction mismatch in release_udmabuf()
- i2c: core: fix adapter deregistration race
- i2c: mpc: Fix timeout calculations
- i2c: stm32f7: truncate clock period instead of rounding it
- Input: synaptics-rmi4 - unregister function handlers on physical driver
registration failure
- Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count
- Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
- Input: elan_i2c - prevent division by zero and arithmetic underflow
- Input: goodix - clamp the device-reported contact count
- Input: iforce - bound the device-reported force-feedback effect index
- Input: mms114 - fix touch indexing for MMS134S and MMS136
- Input: touchwin - reset the packet index on every complete packet
- Input: mms114 - reject an oversized device packet size
- Input: maplemouse - fix NULL pointer dereference in open()
- Input: mms114 - fix multi-touch slot corruption
- Input: maple_keyb - set driver data before registering input device
- Input: maplemouse - set driver data before registering input device
- Input: maplecontrol - set driver data before registering input device
- RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
- fuse: fix device node leak in cuse_process_init_reply()
- fuse: re-lock request before returning from fuse_ref_folio()
- smb: client: reject overlapping data areas in SMB2 responses
- xfs: fail recovery on a committed log item with no regions
- xfs: resample the data fork mapping after cycling ILOCK
- smb/server: do not require delete access for non-replacing links
- sched/fair: Only update stats for allowed CPUs when looking for dst
group
- KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU
- KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
- nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error
path
- nvmet-tcp: Fix potential UAF when ddgst mismatch
- crypto: sun4i-ss - Remove insecure and unused rng_alg
- [Config] Remove CRYPTO_DEV_SUN4I_SS_PRNG
- crypto: crypto4xx - Remove ahash-related code
- bpf: Support for hardening against JIT spraying
- x86/bugs: Enable IBPB flush on BPF JIT allocation
- media: uvcvideo: Avoid partial metadata buffers
- media: uvcvideo: Fix buffer sequence in frame gaps
- media: uvcvideo: Fix sequence number when no EOF
- dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties
- dt-bindings: power: imx93: Add MIPI PHY power domain
- serial: msm: Disable DMA for kernel console UART
- serial: 8250_omap: clear rx_running on zero-length DMA completes
- rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc
- rxrpc: Fix leak of released call in recvmsg(MSG_PEEK)
- afs: Fix netns teardown to cancel the preallocation charger
- afs: fix NULL pointer dereference in afs_get_tree()
- afs: Fix further netns teardown to cancel the preallocation charger
- fbcon: fix NULL pointer dereference for a console without vc_data
- clocksource/drivers/sun5i: Handle error returns from
devm_reset_control_get_optional_exclusive()
- drm/rockchip: Test for imported buffers with drm_gem_is_imported()
- drm/tidss: Drop extra drm_mode_config_reset() call
- drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch()
- drm/radeon: fix integer overflow in radeon_align_pitch()
- drm/radeon: fix memory leak in radeon_ring_restore() on lock failure
- libbpf: Report error when a negative kprobe offset is specified
- Documentation: proc: fix section numbering in table of contents
- arm64: dts: rockchip: Fix gmac0 reset pin for NanoPi R5S
- arm64: dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg
warning
- wifi: cfg80211: fix grammar in MLO group key error message
- arm64: tegra: Fix Tegra234 MGBE PTP clock
- dt-bindings: pinctrl: nvidia,tegra234: Add missing required block
- drm/amdkfd: Validate CRIU-restored IDs before idr_alloc
- driver core: use READ_ONCE() for dev->driver in dev_has_sync_state()
- wifi: rtw89: Correct data type for scan index to avoid infinite loop
- wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA
buffer
- kconfig: fix potential NULL pointer dereference in conf_askvalue
- wifi: ath9k: fix OOB access from firmware tx status queue ID
- ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint
- watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH
- watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5
- watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register
failure
- media: cedrus: Fix failure to clean up hardware on probe failure
- media: v4l2-common: Add YUV24 format info
- pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path
- arm64: dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc
- arm64: dts: imx8x-colibri: Correct SODIMM PAD settings
- vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive().
- crypto: atmel-sha204a - fix blocking and non-blocking rng logic
- crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve
- crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents
- dlm: fix add msg handle in send_queue ordered
- nilfs2: fix backing_dev_info reference leak
- iommu/amd: Fix a stale comment about which legacy mode is user visible
- arm64: dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to
host
- arm64: dts: qcom: sm8450: Fix ICE reg size
- drm/hisilicon/hibmc: use clock to look up the PLL value
- evm: terminate and bound the evm_xattrs read buffer
- thermal: hwmon: Fix critical temperature attribute removal
- clk: scpi: Unregister child clock providers on remove
- net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats()
- crypto: ccp - Treat zero-length cert chain as query for blob lengths
- spi: hisi-kunpeng: Use dev_err_probe() for host registration failure
- net/sched: sch_htb: do not change sch->flags in htb_dump()
- net/sched: sch_htb: annotate data-races (I)
- ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD
- IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier
- RDMA/hns: Fix arithmetic overflow in calc_hem_config()
- RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference
- RDMA/srpt: fix integer overflow in immediate data length check
- media: atomisp: Fix memory leak in atomisp_fixed_pattern_table()
- firmware: arm_scmi: Read sensor config as 32-bit value
- sysfs: clamp show() return value in sysfs_kf_read()
- regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions
- net/sched: sch_drr: annotate data-races around cl->deficit
- firmware: arm_scmi: Fix OOB in scmi_power_name_get()
- arm64: dts: qcom: sm8450: Add power-domain and iface clk for ice node
- tracing: Bound synthetic-field strings with seq_buf
- device property: fix fwnode reference leak in
fwnode_graph_get_endpoint_by_id()
- driver core: Use mod_delayed_work to prevent lost deferred probe work
- cpufreq: Documentation: fix sampling_down_factor range
- cpufreq: conservative: Simplify frequency limit handling
- pwm: imx27: Fix variable truncation in .apply()
- bus: sunxi-rsb: Always check register address validity
- RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs
- RDMA/rxe: Fix a use-after-free problem in rxe_mmap
- IB/mlx4: Fix refcount leak in add_port() error path
- RDMA/hns: Fix warning in poll cq direct mode
- RDMA/counter: Fix incorrect port index in rdma_counter_init() error
cleanup
- MIPS: Fix big-endian stack argument fetching in o32 wrapper
- MIPS: DEC: Remove do_IRQ() call indirection
- mips: ralink: mt7621: add missing __iomem
- mips: n64: add __iomem for writel call
- mtd: spi-nor: Drop duplicate Kconfig dependency
- ALSA: seq: midi: Serialize output teardown with event_input
- pinctrl: cs42l43: Fix polarity on debounce
- nvme-multipath: fix flex array size in struct nvme_ns_head
- workqueue: drop spurious '*' from print_worker_info() fn declaration
- ipv6: guard against possible NULL deref in __in6_dev_stats_get()
- net/sched: cls_bpf: prevent unbounded recursion in offload rollback
- drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X
client is registered
- drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove
- gpu: host1x: Allow entries in BO caches to be freed
- drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output()
- gpu: host1x: Fix iommu_map_sgtable() return value check
- drm/tegra: Fix iommu_map_sgtable() return value check
- drm/nouveau/bios: specify correct display fuse register for Ampere and
Ada
- libbpf: Harden parse_vma_segs() path parsing
- libbpf: Fix UAF in strset__add_str()
- dax/kmem: account for partial discontiguous resource upon removal
- rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc()
- ocfs2: don't BUG_ON an invalid journal dinode
- ocfs2: kill osb->system_file_mutex lock
- crypto: hisilicon/qm - disable error report before flr
- drm/msm/dp: fix HPD state status bit shift value
- drm/msm/dp: Fix the ISR_* enum values
- EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in
skx_get_dimm_info
- RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe
- RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path
- media: qcom: venus: drop extra padding in NV12 raw size calculation
- media: qcom: venus: relax encoder frame/blur dimension steps on v4
- media: qcom: venus: relax encoder frame/blur step size on v6
- rpmsg: use generic driver_override infrastructure
- md/raid10: reset read_slot when reusing r10bio for discard
- RDMA/siw: bound Read Response placement to the RREAD length
- block: skip sync_blockdev() on surprise removal in bdev_mark_dead()
- crypto: algif_skcipher - force synchronous processing
- crypto: crypto4xx - Remove insecure and unused rng_alg
- crypto: hisi-trng - Remove crypto_rng interface
- bpf: Restrict JIT predictor flush to cBPF
- bpf: Skip redundant IBPB in pack allocator
- bpf: Prefer packs that won't trigger an IBPB flush on allocation
- bpf: Prefer dirty packs for eBPF allocations
- clk: scmi: Fix clock rate rounding
- drm/hisilicon/hibmc: move display contrl config to hibmc_probe()
- bitops: use common function parameter names
- media: rockchip: rga: fix too small buffer size
- ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data
writeback
- ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble
- ARM: imx3: Fix CCM node reference leak
- HID: wiimote: Fix table layout and whitespace errors
- ata: libata: Fix ata_exec_internal()
- ARM: imx31: Fix IIM mapping leak in revision check
- nvdimm/btt: Handle preemption in BTT lane acquisition
- scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-
channel scans"
- scsi: pm8001: Fix error code in non_fatal_log_show()
- scsi: ufs: Fix wrong value printed in unexpected UPIU response case
- bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs
- mm/fake-numa: fix under-allocation detection in uniform split
- ext2: fix ignored return value of generic_write_sync()
- sched: restore timer_slack_ns when resetting RT policy on fork
- lib/test_meminit: use && for bools
- configfs_lookup(): don't leave ->s_dentry dangling on failure
- drm/amdgpu: set sub_block_index for mca ras sub-blocks
- bpftool: Use libbpf error code for flow dissector query
- perf/x86/amd/core: Always use the NMI latency mitigation
- ocfs2: rebase copied fsdlm LVB pointers in locking_state
- ocfs2: fix buffer head management in ocfs2_read_blocks()
- ocfs2: reject FITRIM ranges shorter than a cluster
- ocfs2/dlm: require a ref for locking_state debugfs open
- ocfs2: fix race between ocfs2_control_install_private() and
ocfs2_control_release()
- netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures
- netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock
- netfilter: conntrack: revert ct extension genid infrastructure
- netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper
is pptp
- IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path()
- RDMA/irdma: Fix OOB read during CQ MR registration
- RDMA/irdma: Initialize iwmr->access during MR registration
- arm64: dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as
well
- bpf: Check tail zero of bpf_prog_info
- bpf: Update transport_header when encapsulating UDP tunnel in lwt
- wifi: wcn36xx: fix heap overflow from oversized firmware HAL response
- wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO
indication
- wifi: wcn36xx: fix OOB read from short trigger BA firmware response
- ALSA: seq: Fix partial userptr event expansion
- riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe
- ALSA: seq: Clear variable event pointer on read
- ACPI: IPMI: Fix message kref handling on dead device
- cpufreq: Documentation: fix conservative governor freq_step description
- IB/mlx5: Don't take the rereg_mr fallback without a new translation
- IB/mlx5: Properly support implicit ODP rereg_mr
- spi: ep93xx: fix double-free of zeropage on DMA setup failure
- firmware_loader: Fix recursive lock in device_cache_fw_images()
- configfs: fix lockless traversals of ->s_children
- watchdog: unregister PM notifier on watchdog unregister
- scsi: target: Fix hexadecimal CHAP_I handling
- scsi: target: Remove tcm_loop target reset handling
- pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins
34-39
- pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins
34-39
- vmalloc: fix NULL pointer dereference in is_vm_area_hugepages()
- hwspinlock: qcom: avoid uninitialized struct members
- sched/fair: Fix cpu_util runnable_avg arithmetic
- wifi: mt76: fix argument to ieee80211_is_first_frag()
- wifi: mt76: mt7915: fix potential tx_retries underflow
- wifi: mt76: mt7921: fix potential tx_retries underflow
- btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
- fbdev: sm501fb: Fix buffer errors in OF binding code
- hwmon: (it87) Clamp negative values to zero in set_fan()
- btrfs: zoned: don't account data relocation space-info in statfs free
space
- IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified
- spi: meson-spifc: fix runtime PM leak on remove
- ASoC: codecs: aw88261: fix incorrect masks for boost regs
- vduse: hold vduse_lock across IDR lookup in open path
- vhost/vdpa: validate virtqueue index in mmap and fault paths
- vduse: Requeue failed read to send_list head
- vhost/net: complete zerocopy ubufs only once
- tools/virtio: check mmap return value in vringh_test
- ASoC: cs35l56: Fix missing calls to wm_adsp2_remove()
- ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails
- bonding: 3ad: fix mux port state on oper down
- ext4: fix kernel BUG in ext4_write_inline_data_end
- selftests/bpf: Fix bpf_iter/task_vma test
- cxl/test: Fix integer overflow in mock LSA bounds checks
- cxl/test: Zero out LSA backing memory to avoid leaking to user
- of: cpu: add check in __of_find_n_match_cpu_property()
- bpf: Tighten cgroup storage cookie checks for prog arrays
- s390/process: Fix kernel thread function pointer type
- Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for
non-serdev device
- Bluetooth: hci: validate codec capability element length
- Bluetooth: vhci: validate devcoredump state before side effects
- fs: efs: remove unneeded debug prints
- RDMA/mlx5: Remove raw RSS QP restrack tracking
- RDMA/mlx5: Fix undefined shift of user RQ WQE size
- RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one
- ASoC: codecs: hdac_hdmi: Validate written enum value
- ASoC: fsl: fsl_audmix: Validate written enum values
- ASoC: tegra: tegra210_ahub: Validate written enum value
- net/sched: cls_flow: Dont expose folded kernel pointers
- net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().
- bridge: cfm: reject invalid CCM interval at configuration time
- sctp: validate embedded address parameter length
- net/sched: sch_hfsc: Don't make class passive twice
- tipc: require net admin for TIPCv2 netlink mutators
- tipc: prevent snt_unacked underflow on CONN_ACK
- tipc: reject inverted service ranges from peer bindings
- cxl/test: Add check after kzalloc() memory in alloc_mock_res()
- crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
- crypto: cavium/cpt - fix DMA cleanup using wrong loop index
- crypto: rng - Free default RNG on module exit
- spi: xilinx: use FIFO occupancy register to determine buffer size
- ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO
- power: supply: core: fix supplied_from allocations
- handshake: Require admin permission for DONE command
- net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during
peek before restoring qlen
- net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek
before restoring qlen
- net: mana: initialize gdma queue id to INVALID_QUEUE_ID
- net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check
- bpf: Run generic devmap egress prog on private skb
- net/mlx5: Check max_macs devlink param value against max capability
- net: wwan: t7xx: check skb_clone in control TX
- net: bcmgenet: Use weighted round-robin TX DMA arbitration
- kcm: use WRITE_ONCE() when changing lower socket callbacks
- netfilter: nf_conncount: callers must hold rcu read lock
- ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait()
- cifs: remove all cifs files before kill super
- smb/client: always return a value for FS_IOC_GETFLAGS
- selftests/bpf: Initialize operation name before use
- bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket
- bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
- bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check
- MIPS: mm: Fix out-of-bounds write in maar_res_walk()
- powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del
- powerpc/powernv: fix preempt count leak in
pnv_kexec_wait_secondaries_down
- powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus
- KEYS: Use acquire when reading state in keyring search
- tipc: fix UAF in tipc_l2_send_msg()
- tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)
- ionic: Fix check in ionic_get_link_ext_stats
- ksmbd: fix use-after-free in same_client_has_lease()
- mfd: cs42l43: Sanity check firmware size
- ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write
- net/9p: fix race condition on rdma->state in trans_rdma.c
- staging: nvec: fix use-after-free in nvec_rx_completed()
- coresight: cti: Fix DT filter signals silently ignored
- coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore
- PCI/ASPM: Don't reconfigure ASPM entering low-power state
- PCI: Introduce named defines for PCI ROM
- PCI: Check ROM header and data structure addr before accessing
- x86/platform/olpc: xo15: Drop wakeup source on driver removal
- platform/x86: xo15-ebook: Fix wakeup source and GPE handling
- PCI: loongson: Do not ignore downstream devices on external bridges
- bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
- phy: phy-can-transceiver: Check driver match and driver data against
NULL
- mailbox: mtk-adsp: fix UAF during device teardown
- staging: most: video: avoid double free on video register failure
- usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
- usb: host: max3421: Reject hub port requests for non-existent ports
- char: tlclk: fix use-after-free in tlclk_cleanup()
- iio: light: si1133: reset counter to prevent race condition
- iio: light: si1133: prevent race condition on timeout
- iio: magnetometer: ak8975: fix potential kernel stack memory leak
- iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling
- iio: accel: mma8452: handle I2C read error(s) in mma8452_read()
- iio: tcs3472: power down chip on probe failure
- clk: at91: keep securam node alive while mapping it
- HID: logitech-hidpp: remove excess kernel-doc member in
hidpp_scroll_counter
- fs/ntfs3: add bounds check to run_get_highest_vcn()
- fs/ntfs3: fix mount failure on 64K page-size kernels
- dmaengine: imx-sdma: Refine spba bus searching in probe
- perf: Fix off-by-one stack buffer overflow in kallsyms__parse()
- dmaengine: qcom: gpi: set DMA_PRIVATE capability
- dmaengine: Fix possible use after free
- clk: qcom: a53: Corrected frequency multiplier for 1152MHz
- pNFS/filelayout: fix cheking if a layout is striped
- xprtrdma: Remove temp allocation of rpcrdma_rep objects
- xprtrdma: Avoid 250 ms delay on backlog wakeup
- xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot
- xprtrdma: Post receive buffers after RPC completion
- xprtrdma: Use sendctx DMA state for Send signaling
- xprtrdma: Decouple req recycling from RPC completion
- NFSv4/pnfs: defer return_range callbacks until after inode unlock
- nfs: keep PG_UPTODATE clear after read errors in page groups
- NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect
errors
- PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro
- PCI: meson: Propagate devm_add_action_or_reset() failure
- fs/ntfs3: resize log->one_page_buf when adopting on-disk page size
- PCI: rcar-host: Remove unused LIST_HEAD(res)
- xprtrdma: Check frwr_wp_create() during connect
- xprtrdma: Document and assert reply-handler invariants
- xprtrdma: Resize reply buffers before reposting receives
- xprtrdma: Fix bcall rep leak and unbounded peek
- xprtrdma: Sanitize the reply credit grant after parsing
- xprtrdma: Repost Receive buffers for malformed replies
- xprtrdma: Return sendctx slot after Send preparation failure
- tools lib api: Fix missing null termination in filename__read_int/ull()
- tools lib api: Fix filename__write_int() writing uninitialized stack
data
- tools lib api: Fix mount_overload() snprintf truncation and toupper
range
- PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port()
- PCI: mediatek: Use actual physical address instead of virt_to_phys()
- security/apparmor/apparmorfs.c: conditionally compile
get_loaddata_common_ref()
- apparmor: aa_label_alloc use aa_label_free on alloc failure
- apparmor: fix rawdata_f_data implicit flex array
- apparmor: fix potential UAF in aa_replace_profiles
- apparmor: aa_getprocattr free procattr leak on format failure
- apparmor: put secmark label after secid lookup
- i3c: master: Prevent reuse of dynamic address on device add failure
- apparmor: fix label can not be immediately before a declaration
- sparc: led: avoid trimming a newline from empty writes
- gpio: mlxbf3: fail probe if gpiochip registration fails
- spi: dw: fix wrong BAUDR setting after resume
- xfrm: Support crypto offload for inbound IPv6 ESP packets not in GRO
path
- xfrm: annotate data-races around xfrm_policy_count[] and
xfrm_policy_default[]
- xfrm: validate selector family and prefixlen during match
- ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode
- drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free
- drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm
- octeontx2-pf: Fix leak of SQ timestamp buffer on teardown
- net: psample: fix info leak in PSAMPLE_ATTR_DATA
- sctp: hold socket lock when dumping endpoints in sctp_diag
- PCI: iproc: Restore .map_irq() for the platform bus driver
- spi: rpc-if: Use correct device for hardware reinitialization on resume
- virtio-net: fix len check in receive_big()
- devlink: Fix parent ref leak in devl_rate_node_create()
- flow_dissector: check device type before reading ETH_ADDRS
- ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints
- arm64/hw_breakpoint: reject unaligned watchpoints that would truncate
BAS
- thermal: intel: Fix dangling resources on thermal_throttle_online()
failure
- ACPI: resource: Amend kernel-doc style
- ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone()
- ieee802154: Remove WARN_ON() in cfg802154_pernet_exit()
- ieee802154: fix kernel-infoleak in dgram_recvmsg()
- md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on
retry
- netfilter: ipset: Fix data race between add and dump in all hash types
- netfilter: ipset: annotate "pos" for concurrent readers/writers
- netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash
types
- netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
- netfilter: nf_reject: skip iphdr options when looking for icmp header
- netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak
- irqchip/crossbar: Fix parent domain resource leak
- selftests/mm: clarify alternate unmapping in compaction_test
- selftests/mm: allow PUD-level entries in compound testcase of hmm tests
- selftests/mm: fix exclusive_cow test fork() handling
- net: marvell: prestera: initialize err in prestera_port_sfp_bind
- tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
- net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths
- octeontx2-af: mcs: Fix unsupported secy stats read
- octeontx2-pf: Clear stats of all resources when freeing resources
- octeontx2-pf: mcs: Fix mcs resources free on PF shutdown
- rtc: abx80x: fix the RTC_VL_CLR clearing all status flags
- rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231
- bpf: Fix stack slot index in nospec checks
- bpf: zero-initialize the fib lookup flow struct
- bpf: Fix effective prog array index with BPF_F_PREORDER
- drm/edid: fix OOB read in drm_parse_tiled_block()
- PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0
- PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0
- ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs()
- ice: fix AQ error code comparison in ice_set_pauseparam()
- i40e: Fix i40e_debug() to use struct i40e_hw argument
- rtc: msc313: fix NULL deref in shared IRQ handler at probe
- ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2
NEGOTIATE
- ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().
- ipv4: fib: Don't ignore error route in local/main tables.
- bpf, lsm: Add disabled BPF LSM hook list
- bpf: Disable xfrm_decode_session hook attachment
- netfilter: nf_nat: avoid invalid nat_net pointer use on failed
nf_nat_init()
- netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
- netfilter: nft_synproxy: stop bypassing the priv->info snapshot
- netfilter: nft_compat: ebtables emulation must reject non-bridge targets
- NTB: epf: Make db_valid_mask cover only real doorbell bits
- NTB: epf: Report 0-based doorbell vector via ntb_db_event()
- NTB: epf: Fix doorbell bitmask and IRQ vector handling
- alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
- alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs
- net, bpf: check master for NULL in xdp_master_redirect()
- net: dsa: sja1105: round up PTP perout pin duration
- veth: fix NAPI leak in XDP enable error path
- net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
- ipv6: fix error handling in disable_ipv6 sysctl
- ipv6: fix error handling in ignore_routes_with_linkdown sysctl
- ipv6: fix error handling in forwarding sysctl
- ipv6: fix error handling in disable_policy sysctl
- smb/client: preserve errors from smb2_set_sparse()
- rtc: ds1307: Fix off-by-one issue with wday for rx8130
- rtc: cmos: unregister HPET IRQ handler on probe failure
- net: mvneta: re-enable percpu interrupt on resume
- net: sungem: fix probe error cleanup
- net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove
- ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count
- dt-bindings: net: renesas,ether: Drop example "ethernet-phy-
ieee802.3-c22" fallback
- tracing: probes: fix typo in a log message
- spi: sh-msiof: abort transfers when reset times out
- gpio: mvebu: fail probe if gpiochip registration fails
- gpio: htc-egpio: use managed gpiochip registration
- seg6: validate SRH length before reading fixed fields
- qede: fix out-of-bounds check for cqe->len_list[]
- net: enetc: check the number of BDs needed for xdp_frame
- sctp: fix SCTP_RESET_STREAMS stream list length limit
- MIPS: DEC: Ensure RTC platform device deregistration upon failure
- hwmon: adm1275: Prevent reading uninitialized stack
- hwmon: (pmbus) Fix passing events to regulator core
- usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()
- NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in
pg_get_mirror_count_write
- apparmor: check label build before no_new_privs test
- apparmor: grab ns lock and refresh when looking up changehat child
profiles
- drm/amdgpu: initialize irq.lock spinlock earlier
- dpaa2-switch: fix VLAN upper check not rejecting bridge join
- net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy
- net: gianfar: dispose irq mappings on probe failure and device removal
- net/sched: sch_teql: Introduce slaves_lock to avoid race condition and
UAF
- bridge: stp: Fix a potential use-after-free when deleting a bridge
- tracing/events: Fix to check the simple_tsk_fn creation
- tracing: eprobe: read the complete FILTER_PTR_STRING pointer
- irqchip/gic-v3-its: Fix OF node reference leak
- irqchip/ts4800: Fix missing chained handler cleanup on remove
- cxgb4: Fix decode strings dump for T6 adapters
- virtio_net: disable cb when NAPI is busy-polled
- net/sched: act_bpf: use rcu_dereference_bh() to read the filter
- ksmbd: reject undersized DACLs before parsing ACEs
- gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe
- pinctrl: meson: restore non-sleeping GPIO access
- net/sched: hhf: clear heavy-hitter state on reset
- fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid
- afs: Fix error code in afs_extract_vl_addrs()
- afs: use kvfree() to free memory allocated by kvcalloc()
- afs: Fix callback service message parsers to pass through -EAGAIN
- afs: Fix vllist leak
- afs: Fix the volume AFS_VOLUME_RM_TREE is set on
- afs: Fix unchecked-length string display in debug statement
- minix: avoid overflow in bitmap block count calculation
- ata: sata_gemini: unwind clocks on IDE pinctrl errors
- HID: picolcd: prevent NULL pointer dereference in
picolcd_send_and_wait()
- HID: core: Fix OOB read in hid_get_report for numbered reports
- arm64/mm: convert READ_ONCE(*ptep) to ptep_get(ptep)
- arm64/mm: convert set_pte_at() to set_ptes(..., 1)
- arm64/mm: convert ptep_clear() to ptep_get_and_clear()
- arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range()
- selftests/hid: convert the hid_bpf selftests with struct_ops
- selftests/hid: Cover hid_bpf_get_data() size overflow
- net: usb: net1080: validate packet_len before pad-byte access in
rx_fixup
- gue: validate REMCSUM private option length
- netfilter: xt_u32: reject invalid shift counts
- netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()
- netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
- netfilter: xt_connmark: reject invalid shift parameters
- net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation
- net/mlx5e: Fix HV VHCA stats agent registration race
- net: microchip: vcap: fix races on the shared Super VCAP block
- qede: fix off-by-one in BD ring consumption on build_skb failure
- net: qualcomm: rmnet: validate MAP frame length before ingress parsing
- net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload
- net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
- amt: fix size calculation in amt_get_size()
- Bluetooth: 6lowpan: hold L2CAP conn across debugfs control
- Bluetooth: MGMT: Fix adv monitor add failure cleanup
- Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length
- Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
- ring-buffer: Fix event length with forced 8-byte alignment
- net/tls: Consume empty data records in tls_sw_read_sock()
- net: usb: lan78xx: move functions to avoid forward definitions
- net: usb: lan78xx: disable VLAN filter in promiscuous mode
- net/sched: cake: reject overhead values that underflow length
- octeontx2-pf: check DMAC extraction support before filtering
- ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
- ipv6: mcast: Replace locking comments with lockdep annotations.
- ipv6: mcast: Fix potential UAF in MLD delayed work
- ipvs: pass parsed transport offset to state handlers
- ipvs: use parsed transport offset in TCP state lookup
- ipvs: fix PMTU for GUE/GRE tunnel ICMP errors
- ipvs: ensure inner headers in ICMP errors are in headroom
- s390/zcrypt: Remove the empty file
- cifs: validate DFS referral string offsets
- SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED
- SUNRPC: pin upper rpc_clnt across the TLS connect_worker
- dm era: fix NULL pointer dereference in metadata_open()
- regulator: core: regulator_lock_two() should test for EDEADLK not
EDEADLOCK
- selftests/net: fix EVP_MD_CTX leak in tcp_mmap
- net/mlx5: Fix L3 tunnel entropy refcount leak
- octeontx2-af: fix VF bringup affecting PF promiscuous state
- smb: client: fix overflow in passthrough ioctl bounds check
- mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()
- mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()
- vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter
- ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put
- ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
- ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get
- ASoC: SOF: topology: validate vendor array size before parsing
- net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
- net: atm: reject out-of-range traffic classes in QoS validation
- net: ife: require ETH_HLEN to be pullable in ife_decode()
- arm64: fpsimd: Fix type mismatch in sve_{save,load}_state()
- arm64: dts: qcom: sdm630: describe adsp_mem region properly
- KVM: s390: pci: Fix GISC refcount leak on AIF enable failure
- KVM: arm64: vgic: Check the interrupt is still ours before migrating it
- KVM: s390: pci: Fix handling of AIF enable without AISB
- KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
- fbdev: metronomefb: fix potential memory leak in metronomefb_probe()
- fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe()
- fbdev: hecubafb: fix potential memory leak in hecubafb_probe()
- fbdev: sm712: Fix operator precedence in big_swap macro
- fbdev: radeon: fix potential memory leak in radeonfb_pci_register()
- fbdev: i740fb: fix potential memory leak in i740fb_probe()
- fbdev: s3fb: fix potential memory leak in s3_pci_probe()
- fbdev: uvesafb: fix potential memory leak in uvesafb_probe()
- fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe()
- fbdev: carminefb: fix potential memory leak in alloc_carmine_fb()
- fbdev: vesafb: fix memory leak in vesafb_probe()
- fbdev: nvidia: fix potential memory leak in nvidiafb_probe()
- fbdev: tridentfb: fix potential memory leak in trident_pci_probe()
- ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
- ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control
- ASoC: mediatek: mt8192: Release reserved memory on cleanup
- ASoC: mediatek: mt8183: Release reserved memory on cleanup
- ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback
- netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
- netfilter: nfnl_cthelper: apply per-class values when updating policies
- netfilter: xt_cluster: reject template conntracks in hash match
- netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst
- netfilter: nf_nat_sip: reload possible stale data pointer
- netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6
defrag
- netfilter: nf_conncount: fix zone comparison in tuple dedup
- netfilter: ecache: fix inverted time_after() check
- netfilter: xt_nat: reject unsupported target families
- netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
- gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error
path
- soc: ti: k3-ringacc: Fix access mode for
k3_ringacc_ring_pop_tail_io/proxy
- soc: fsl: qe: panic on ioremap() failure in qe_reset()
- selinux: check connect-related permissions on TCP Fast Open
- leds: uleds: Fix potential buffer overread
- mfd: sm501: Fix reference leak on failed device registration
- tools/power/x86/intel-speed-select: Harden daemon pidfile open
- x86/boot: Validate console=uart8250 baud rate to fix early boot hang
- x86/boot: Reject too long acpi_rsdp= values
- perf/x86/amd/lbr: Fix kernel address leakage
- s390/perf_cpum_cf: Add missing array_index_nospec() to
__hw_perf_event_init()
- batman-adv: gw: acquire ethernet header only after skb realloc
- batman-adv: access unicast_ttvn skb->data only after skb realloc
- batman-adv: dat: acquire ARP hw source only after skb realloc
- batman-adv: bla: reacquire gw address after skb realloc
- batman-adv: dat: ensure accessible eth_hdr proto field
- batman-adv: dat: fix tie-break for candidate selection
- batman-adv: tt: avoid request storms during pending request
- batman-adv: fix VLAN priority offset
- batman-adv: frag: free unfragmentable packet
- batman-adv: frag: fix primary_if leak on failed linearization
- batman-adv: tt: prevent TVLV OOB check overflow
- cifs: invalidate cfid on unlink/rename/rmdir
- mfd: tps6586x: Fix OF node refcount
- HID: playstation: validate num_touch_reports in DualShock 4 reports
- Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready
- Bluetooth: SCO: hold sk properly in sco_conn_ready
- jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit()
- nvdimm/btt: Free arenas on btt_init() error paths
- nvdimm/btt: Free arena sub-allocations on discover_arenas() error path
- sunrpc: pin svc_xprt across the asynchronous TLS handshake callback
- sunrpc: wait for in-flight TLS handshake callback when cancel loses race
- lockd: Plug nlm_file leak when nlm_do_fopen() fails
- lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure
- SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
- remoteproc: qcom: Fix leak when custom dump_segments addition fails
- MIPS: ip22-gio: fix gio device memory leak
- MIPS: ip22-gio: fix kfree() of static object
- MIPS: ip22-gio: fix device reference leak in probe
- MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf()
- power: supply: cpcap-battery: Fix missing nvmem_device_put() causing
reference leak
- mm/damon/core: make charge_addr_from aware of end-address exclusivity
- fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename
- fs/ntfs3: bound DeleteIndexEntryAllocation memmove length
- fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass
- fs/ntfs3: bound attr_off in UpdateResidentValue against data_off
- fs/ntfs3: validate lcns_follow in log_replay conversion
- fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
- fs/ntfs3: bound NTFS_DE view.data_off in
UpdateRecordData{Root,Allocation}
- ntfs3: cap RESTART_TABLE free-chain walker at rt->used
- ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head
- ntfs3: validate split-point offset in indx_insert_into_buffer
- ntfs3: fix out-of-bounds read in decompress_lznt
- power: supply: charger-manager: fix refcount leak in is_full_charged()
- mips: sched: Fix CPUMASK_OFFSTACK memory corruption
- riscv: cacheinfo: Fix node reference leak in populate_cache_leaves
- mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs()
- mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error
- proc: only bump parent nlink when registering directories
- mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE
- mtd: slram: remove failed entries from the device list
- 9p: skip nlink update in cacheless mode to fix WARN_ON
- scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished()
- scsi: sas: Skip opt_sectors when DMA reports no real optimization hint
- ocfs2: use kzalloc for quota recovery bitmap allocation
- mtd: rawnand: pl353: fix probe resource allocation
- net/9p: fix infinite loop in p9_client_rpc on fatal signal
- mtd: rawnand: fix condition in 'nand_select_target()'
- ocfs2: avoid moving extents to occupied clusters
- ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits
- ocfs2: add journal NULL check in ocfs2_checkpoint_inode()
- ocfs2: reject dinodes with non-canonical i_mode type
- ocfs2: reject dinodes whose i_rdev disagrees with the file type
- ocfs2: reject non-inline dinodes with i_size and zero i_clusters
- fpga: dfl: add bounds check in dfh_get_param_size()
- bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path
- net: thunderbolt: Fix frags[] overflow by bounding frame_count
- fpga: microchip-spi: fix zero header_size OOB read in
mpf_ops_parse_header()
- mtd: spi-nor: swp: Improve locking user experience
- mtd: maps: vmu-flash: fix NULL pointer dereference in initialization
- irqchip/crossbar: Use correct index in crossbar_domain_free()
- tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat()
- dmaengine: tegra: Fix burst size calculation
- dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and
ABORT_INT_MASK
- platform/x86/amd/pmc: Check for intermediate wakeup in function
- platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops
- platform/x86/amd/pmc: Add delay_suspend module parameter
- smb: client: use kvzalloc() for megabyte buffer in simple fallocate
- ksmbd: fix integer overflow in set_file_allocation_info()
- hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig
- i2c: mediatek: fix WRRD for SoCs without auto_restart option
- i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource()
- ice: fix ice_init_link() error return preventing probe
- xen/gntdev: fix error handling in ioctl
- xfrm: use compat translator only for u64 alignment mismatch
- net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
- xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for
changelink
- tpm: fix event_size output in tpm1_binary_bios_measurements_show
- tpm: Make the TPM character devices non-seekable
- time: Fix off-by-one in compat settimeofday() usec validation
- spi: uniphier: Fix completion initialization order before
devm_request_irq()
- sctp: validate STALE_COOKIE cause length before reading staleness
- nvmet-rdma: handle inline data with a nonzero offset
- can: esd_usb: kill anchored URBs before freeing netdevs
- can: isotp: use unconditional synchronize_rcu() in isotp_release()
- can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF
- can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure
- can: bcm: add missing rcu list annotations and operations
- bpf,fork: wipe ->bpf_storage before bailouts that access it
- bpf: Add missing access_ok call to copy_user_syms
- net: sparx5: unregister blocking notifier on init failure
- dm thin metadata: fix superblock refcount leak on snapshot shadow
failure
- dm thin metadata: fix metadata snapshot consistency on commit failure
- dm era: fix out-of-bounds memory access for non-zero start sector
- dm-bufio: fix wrong count calculation in dm_bufio_issue_discard
- dm-ioctl: fix a possible overflow in list_version_get_info
- dm-log: fix a bitset_size overflow on 32bit machines
- dm-stats: fix dm_jiffies_to_msec64
- dm-stats: fix merge accounting
- dm_early_create: fix freeing used table on dm_resume failure
- dm-integrity: don't increment hash_offset twice
- dm-verity: fix a possible NULL pointer dereference
- dm-verity: increase sprintf buffer size
- scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path
- scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()
- scsi: sg: Report request-table problems when any status is set
- scsi: xen: scsiback: Free the command tag on the TMR submit-failure path
- scsi: xen: scsiback: Free unsubmitted command instead of double-putting
it
- scsi: target: Bound PR-OUT TransportID parsing to the received buffer
- scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
- scsi: elx: efct: Fix refcount leak in efct_hw_io_abort()
- scsi: elx: efct: Fix I/O leak on unsupported additional CDB
- Input: ims-pcu - fix use-after-free and double-free in disconnect
- Input: ims-pcu - release data interface on disconnect
- Input: ims-pcu - validate control endpoint type
- Input: ims-pcu - add response length checks
- Input: ims-pcu - fix DMA mapping violation in line setup
- Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging
- Input: ims-pcu - fix potential infinite loop in CDC union descriptor
parsing
- Input: ims-pcu - fix race condition in reset_device sysfs callback
- Input: ims-pcu - fix type confusion in CDC union descriptor parsing
- net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete
- posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()
- cpu: hotplug: Preserve per instance callback errors
- cpu: hotplug: Bound hotplug states sysfs output
- gpio-f7188x: Add support for NCT6126D version B
- gpios: palmas: add .get_direction() op
- net: sit: require CAP_NET_ADMIN in the device netns for changelink
- net: wwan: t7xx: destroy DMA pool on CLDMA late init failure
- net: ixp4xx_hss: fix duplicate HDLC netdev allocation
- net/sched: act_ct: preserve tc_skb_cb across defragmentation
- net: ena: clean up XDP TX queues when regular TX setup fails
- net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
- net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
- net: ipip: require CAP_NET_ADMIN in the device netns for changelink
- net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
- ieee802154: admin-gate legacy LLSEC dump operations
- ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation
- ieee802154: ca8210: fix cas_ctl leak on spi_async failure
- ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit
- net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants
- batman-adv: retrieve ethhdr after potential skb realloc on RX
- batman-adv: ensure minimal ethernet header on TX
- batman-adv: clean untagged VLAN on netdev registration failure
- LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()
- espintcp: use sk_msg_free_partial to fix partial send
- bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()
- rtc: mpfs: fix counter upload completion condition
- hwmon: (w83627hf) remove VID sysfs files on error and remove
- hwmon: (w83793) remove vrm sysfs file on probe failure
- net: liquidio: fix BAR resource leak on PF number failure
- hwmon: (occ) unregister sysfs devices outside occ lock
- fsl/fman: Free init resources on KeyGen failure in fman_init()
- net: lan743x: Initialize eth_syslock spinlock before use
- net/sched: sch_multiq: Replace direct dequeue call with peek and
qdisc_dequeue_peeked
- net/sched: sch_taprio: Replace direct dequeue call with peek and
qdisc_dequeue_peeked
- tracing/probes: Fix double addition of offset for @+FOFFSET
- orangefs: keep the readdir entry size 64-bit in fill_from_part()
- ata: pata_pxa: Fix DMA channel leak on probe error
- net: wwan: iosm: bound device offsets in the MUX downlink decoder
- hwmon: (asus_atk0110) Check package count before accessing element
- riscv: probes: save original sp in rethook trampoline
- s390/monwriter: Reject buffer reuse with different data length
- mac802154: remove interfaces with RCU list deletion
- llc: fix SAP refcount leak in llc_ui_autobind()
- ipvs: use parsed transport offset in SCTP state lookup
- ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
- macsec: don't read an unset MAC header in macsec_encrypt()
- drbd: reject data replies with an out-of-range payload size
- riscv: Prevent NULL pointer dereference in machine_kexec_prepare()
- tracing/osnoise: Call synchronize_rcu() when unregistering
- cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed
- pmdomain: imx: Fix i.MX8MP power notifier
- pmdomain: imx: Fix i.MX8MP VC8000E power up sequence
- powerpc/pseries: fix memory leak on krealloc failure in papr_init
- wifi: rt2x00: avoid full teardown before work setup in probe
- wifi: mac80211: fix memory leak in ieee80211_register_hw()
- regulator: ltc3676: Fix incorrect IRQSTAT bit offsets
- Bluetooth: btrtl: validate firmware patch bounds
- llc: fix SAP refcount leak when creating incoming sockets
- macsec: fix promiscuity refcount leak in macsec_dev_open()
- memstick: ms_block: reject a card that reports too many blocks
- ipvs: fix more places with wrong ipv6 transport offsets
- ipvs: reload ip header after head reallocation
- reset: sunxi: fix memory region leak on ioremap failure
- powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()
- wifi: mac80211: free ack status frame on TX header build failure
- wifi: mwifiex: fix permanently busy scans after multiple roam iterations
- mtd: onenand: samsung: report DMA completion timeouts
- mtd: mchp23k256: use SPI match data for chip caps
- mmc: vub300: defer reset until cmd_mutex is unlocked
- mtd: rawnand: fsl_ifc: return errors for failed page reads
- mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout
- mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout
- perf/x86/amd/brs: Fix kernel address leakage
- ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup
- ACPI: bus: Introduce devm_acpi_install_notify_handler()
- ACPI: NFIT: core: Use devm_acpi_install_notify_handler()
- ACPI: NFIT: core: Fix possible deadlock and missing notifications
- iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ
- iio: hid-sensor-rotation: Fix stale or zero output when reading raw
values
- iio: invensense: remove redundant initialization of variable period
- iio: invensense: fix timestamp glitches when switching frequency
- iio: imu: inv_icm42600: stabilized timestamp in interrupt
- iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading
- iio: pressure: mpl115: fix runtime PM leak on read error
- bitops: make BYTES_TO_BITS() treewide-available
- iio: common: st_sensors: honour channel endianness in read_axis_data
- ALSA: aoa: check snd_ctl_new1() return value
- PCI: altera: Fix resource leaks on probe failure
- vfio/mlx5: Fix racy bitfields and tighten struct layout
- PCI: imx6: Fix IMX6SX_GPR12_PCIE_TEST_POWERDOWN handling
- PCI: controller: Use dev_fwnode() instead of of_fwnode_handle()
- PCI: mediatek: Convert bool to single quirks entry and bitmap
- PCI: mediatek: Use generic MACRO for TPVPERL delay
- PCI: mediatek: Fix IRQ domain leak when port fails to enable
- PCI: Prevent resource tree corruption when BAR resize fails
- PCI: Free saved list without holding pci_bus_sem
- PCI: Fix restoring BARs on BAR resize rollback path
- PCI: Add kerneldoc for pci_resize_resource()
- PCI: Move Resizable BAR code to rebar.c
- PCI: Skip Resizable BAR restore on read error
- staging: rtl8723bs: core: move constants to right side in comparison
- staging: rtl8723bs: fix spaces around binary operators
- staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(),
rtw_get_wapi_ie(), and rtw_get_wps_attr()
- crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()
- Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
- mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()
- coresight: etb10: restore atomic_t for shared reading state
- gpio: sch: use raw_spinlock_t in the irq startup path
- media: nxp: imx8-isi: Convert to platform remove callback returning void
- media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code
- media: nxp: imx8-isi: Fix use-after-free on remove
- netfilter: ebtables: Use vmalloc_array() to improve code
- netfilter: ebtables: zero chainstack array
- Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
- Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister
- Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()
- smb: client: Improve unlocking of a mutex in cifs_get_swn_reg()
- smb: client: resolve SWN tcon from live registrations
- ksmbd: use opener credentials for FSCTL mutations
- ksmbd: centralize ksmbd_conn final release to plug transport leak
- ksmbd: track the connection owning a byte-range lock
- proc: rename proc_setattr to proc_nochmod_setattr
- proc: protect ptrace_may_access() with exec_update_lock (FD links)
- writeback: fix race between cgroup_writeback_umount() and
inode_switch_wbs()
- perf/x86/intel/uncore: Defer ADL global PMON enable to enable_box()
- HID: add haptics page defines
- HID: multitouch: fix out-of-bounds bit access on mt_io_flags
- mm/slab: do not limit zeroing to orig_size when only red zoning is
enabled
- seqlock: Introduce scoped_seqlock_read()
- seqlock: Change do_task_stat() to use scoped_seqlock_read()
- proc: protect ptrace_may_access() with exec_update_lock (part 1)
- treewide: Switch/rename to timer_delete[_sync]()
- HID: appleir: fix UAF on pending key_up_timer in remove()
- serial: 8250_mid: Disable DMA for selected platforms
- hfs/hfsplus: prevent getting negative values of offset/length
- hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length
- bpf: Consistently use bpf_rcu_lock_held() everywhere
- bpf: Allow LPM map access from sleepable BPF programs
- usb: iowarrior: remove inherent race with minor number
- usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()
- usb: typec: tcpm: Fix VDM type for Enter Mode commands
- crypto: atmel - Drop explicit initialization of struct
i2c_device_id::driver_data to 0
- crypto: atmel-sha204a - drop hwrng quality reduction for ATSHA204A
- usb: gadget: f_fs: initialize reset_work at allocation time
- nvmet: return DHCHAP status codes from nvmet_setup_auth()
- nvmet-auth: validate reply message payload bounds against transfer
length
- usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile
- btrfs: check and set EXTENT_DELALLOC_NEW before clearing EXTENT_DELALLOC
- crypto: qat - fix restarting state leak on allocation failure
- audit: add audit_log_nf_skb helper function
- audit: fix potential integer overflow in audit_log_n_hex()
- regulator: scmi: Simplify with scoped for each OF child loop
- regulator: scmi: fix of_node refcount leak in scmi_regulator_probe()
- mm: do file ownership checks with the proper mount idmap
- exfat: move free cluster out of exfat_init_ext_entry()
- exfat: remove unnecessary read entry in __exfat_rename()
- exfat: rename argument name for exfat_move_file and exfat_rename_file
- exfat: add exfat_get_dentry_set_by_ei() helper
- exfat: move exfat_chain_set() out of __exfat_resolve_path()
- exfat: preserve benign secondary entries during rename and move
- btrfs: fix false IO failure after falling back to buffered write
- btrfs: fix incorrect buffered IO fallback for append direct writes
- Bluetooth: hci_core: Enable buffer flow control for SCO/eSCO
- Bluetooth: separate CIS_LINK and BIS_LINK link types
- Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()
- KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers
- seqlock: fix scoped_seqlock_read kernel-doc
- Bluetooth: hci_core: Remove check of BDADDR_ANY in
hci_conn_hash_lookup_big_state
- Bluetooth: hci_sync: Fix attempting to send HCI_Disconnect to BIS handle
- Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote
netdev
- selftests/hid: ensure CKI can compile our new tests on old kernels
- Bluetooth: btmtk: Fix btmtk.c undefined reference build error harder
- Bluetooth: btmtk: remove #ifdef around declarations
- writeback: drop now-unnecessary rcu_barrier() in
cgroup_writeback_umount()
- jiffies: Define secs_to_jiffies()
- jiffies: Cast to unsigned long in secs_to_jiffies() conversion
- driver core: Fix missing jiffies conversion in
deferred_probe_extend_timeout()
- driver core: Guard deferred probe timeout extension with
delayed_work_pending()
- tools/testing: add linux/args.h header and fix radix, VMA tests
- selftests/bpf: Add simple strscpy() implementation
- bcachefs: avoid truncating fiemap extent length
- gpio: rockchip: change the GPIO version judgment logic
- gpio: rockchip: teardown bugs and resource leaks
- gpio: rockchip: fix generic IRQ chip leak on remove
- NFSv4/flexfiles: Remove cred local variable dependency
- iio: resolver: ad2s1210: notify trigger and clear state on fault read
error
- iio: temperature: Build mlx90635 with CONFIG_MLX90635
- vfio: Remove device debugfs before releasing devres
- PCI: loongson: Override PCIe bridge supported speeds for Loongson-3C6000
series
- netpoll: fix a use-after-free on shutdown path
- mm: shrinker: fix shrinker_info teardown race with expansion
- NFSv4/flexfiles: Add data structure support for striped layouts
- mm/khugepaged: write all dirty file folios when collapsing
- platform/x86: intel-hid: Protect ACPI notify handler against recursion
- Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled
- Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync()
- fs/ntfs3: rename ni_readpage_cmpr into ni_read_folio_cmpr
- ksmbd: use __GFP_RETRY_MAYFAIL
- ksmbd: use opener credentials for ADS I/O
- cpufreq: Make cpufreq_driver->exit() return void
- cpufreq: qcom-cpufreq-hw: Fix possible double free
- nvme: target: rdma: fix ndev refcount leak on queue connect
- nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
- crypto: qat - keep VFs enabled during reset
- crypto: qat - notify fatal error before AER reset preparation
- crypto: qat - protect service table iterations with service_lock
- selftests/mm: pagemap_ioctl: use the correct page size for
transact_test()
- iommufd: Set upper bounds on cache invalidation entry_num and entry_len
- iommu/amd: Don't split flush for amd_iommu_domain_flush_all()
- dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning
- i2c: core: fix adapter probe deferral loop
- xfs: fix null pointer dereference in tracepoint
- xfs: don't wrap around quota ids in dqiterate
- xfs: clamp timestamp nanoseconds correctly
- xfs: don't zap bmbt forks if they are MAXLEVELS tall
- iommu/vt-d: Clear Present bit before tearing down context entry
- iommu: Pass old domain to set_dev_pasid op
- iommu/vt-d: Cleanup intel_context_flush_present()
- iommu/vt-d: Clear Present bit before tearing down scalable-mode context
entry
- vsock/virtio: bind uarg before filling zerocopy skb
- iommu/amd: Use maximum Event log buffer size when SNP is enabled on
Family 0x19
- iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family
0x19
- net: dropreason: Gather SOCKET_ drop reasons.
- af_unix: Set drop reason in unix_release_sock().
- af_unix: Set drop reason in manage_oob().
- af_unix: Set drop reason in unix_stream_read_skb().
- af_unix/scm: fix whitespace errors
- af_unix: Don't hold unix_state_lock() in __unix_dgram_recvmsg().
- af_unix: Don't check SOCK_DEAD in unix_stream_read_skb().
- af_unix: Don't use skb_recv_datagram() in unix_stream_read_skb().
- af_unix: Drop all SCM attributes for SOCKMAP.
- time/jiffies: Change register_refined_jiffies() to void __init
- media: uvcvideo: Fix dev_sof filtering in hw timestamp
- media: uvcvideo: Relax the constrains for interpolating the hw clock
- media: uvcvideo: Do not add clock samples with small sof delta
- serial: max310x: replace bare use of 'unsigned' with 'unsigned int'
(checkpatch)
- serial: max310x: implement gpio_chip::get_direction()
- drm/gpuvm: Do not prepare NULL objects
- selftests/bpf: Use local type for bpf_fou_encap in test_tunnel_kern
- soc: xilinx: Shutdown and free rx mailbox channel
- crypto: qat - fix heartbeat error injection
- memory: tegra: Wire up system sleep PM ops
- drm/gpuvm: take refcount on DRM device
- ARM: multi_v7_defconfig: Correct QCOM_RPMH and QCOM_RPMHPD
- RDMA/hns: Initialize seqfile before creating file
- selftests/bpf: Reject unsupported -k option in vmtest.sh
- media: atomisp: gc2235: fix UAF and memory leak
- staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy()
- arm64: dts: qcom: sm8650: Add power-domain and iface clk for ice node
- Revert "treewide: Fix probing of devices in DT overlays"
- RDMA/hns: Fix log flood after cmd_mbox failure
- net: introduce page_frag_cache_drain()
- nvmet-tcp: fix page fragment cache leak in error path
- amba: use generic driver_override infrastructure
- cdx: use generic driver_override infrastructure
- Drivers: hv: vmbus: use generic driver_override infrastructure
- driver core: Use system_percpu_wq instead of system_wq
- tick/sched: Fix TOCTOU in nohz idle time fetch
- vhost: fix vhost_get_avail_idx for a non empty ring
- perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems
- x86/cpu/amd: Provide a separate accessor for Node ID
- perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains
- xfrm: fix NAT-related field inheritance in SA migration
- netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing
helper flags
- netfilter: synproxy: drop packets if timestamp adjustment fails
- netfilter: synproxy: adjust duplicate timestamp options
- netfilter: synproxy: fix unaligned memory access in timestamp adjustment
- RDMA/siw: Fix endpoint/socket association handling
- riscv: cpu_ops: Change return value type of cpu_is_stopped() to bool
- wifi: mt76: mt7925: clean up DMA on probe failure
- wifi: mt76: mt7925: fix potential tx_retries underflow
- wifi: mt76: mt7996: fix potential tx_retries underflow
- btrfs: fix deadlock cloning inline extent when using flushoncommit
- virtio_console: read size from config space during device init
- ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT
- Bluetooth: eir: Fix stack OOB write when prepending the Flags AD
- Bluetooth: hci_core: Fix UAF in hci_unregister_dev()
- net: dsa: qca8k: fix led devicename when using external mdio bus
- ALSA: seq: Drop superfluous filter argument of get_event_dest_client()
- ALSA: seq: Fix kernel heap address leak in bounce_error_event()
- net: ethernet: mtk_wed: fix loading WO firmware for MT7986
- octeontx2-af: npc: Fix size of entry2cntr_map
- net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show()
- dpll: add reference-sync netlink attribute
- dpll: move xa_erase() call in to match dpll_pin_alloc() error path order
- dpll: add reference sync get/set
- dpll: Allow associating dpll pin with a firmware node
- dpll: Add notifier chain for dpll events
- dpll: Support dynamic pin index allocation
- dpll: Enhance and consolidate reference counting logic
- dpll: fix stale iteration in dpll_pin_on_pin_unregister()
- dpll: send delete notification before unregister in on-pin rollback
- dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister()
- dpll: guard sync-pair removal on full pin unregister
- dpll: balance create/delete notifications in __dpll_pin_(un)register
- landlock: Fix unmarked concurrent access to socket family
- selftests/bpf: Fix typo in verify_umulti_link_info
- udf: fix nls leak on udf_fill_super() failure
- mfd: rsmu: Fix page register setup
- eventpoll: expand top-of-file overview / locking doc
- eventpoll: rename attach_epitem() to ep_attach_file()
- eventpoll: rename ep_remove_safe() back to ep_remove()
- eventpoll: split ep_insert() into alloc + register stages
- eventpoll: extract ep_deliver_event() from ep_send_events()
- eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers
- eventpoll: rename epi->next and txlist for clarity
- eventpoll: Fix epoll_wait() report false negative
- gpiolib: acpi: Only trigger ActiveBoth interrupts on boot
- coresight: Fix source not disabled on idr_alloc_u32 failure
- PCI: qcom: Disable ASPM L0s for SA8775P
- dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor
- PCI: meson: Add missing remove callback
- xprtrdma: Fix ep kref imbalance on ADDR_CHANGE
- Revert "PCI/MSI: Unmap MSI-X region on error"
- apparmor: remove or add symlinks to rawdata according to export_binary
- workqueue: Add new WQ_PERCPU flag
- i3c: master: add WQ_PERCPU to alloc_workqueue users
- i3c: master: Make hot-join workqueue freezable to block hot-join during
suspend
- xfrm: Fix xfrm state cache insertion race
- mac802154: Prevent overwrite return code in
mac802154_perform_association()
- netfilter: ipset: make sure gc is properly stopped
- mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx()
- selftest/mm: register existing mapping with userfaultfd in hugetlb-
mremap
- selftests/mm: ensure destination is hugetlb-backed in hugetlb-mremap
- selftests/mm: hugetlb_reparenting_test: do not unmount
- selftests/mm: save and restore nr_hugepages value
- selftests/mm: restore default nr_hugepages value via exit trap in
charge_reserved_hugetlb.sh
- net/sched: act_ct: fix nf_connlabels leak on two error paths
- ipv6: annotate data-races around cnf.forwarding
- ipv6/addrconf: annotate data-races around devconf fields (II)
- ipv6: ndisc: fix NULL deref in accept_untracked_na()
- dpaa2-switch: do not accept VLAN uppers while bridged
- bpftool: Fix vmlinux BTF leak in cgroup commands
- ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info
- ice: dpll: fix memory leak in ice_dpll_init_info error paths
- net: bnxt: use ethtool string helpers
- eth: bnxt: gather and report HW-GRO stats
- eth: bnxt: rename ring_err_stats -> ring_drv_stats
- eth: bnxt: improve the timing of stats
- md/raid5: use stripe state snapshot in break_stripe_batch_list()
- md/raid5: avoid R5_Overlap races while breaking stripe batches
- gpio: davinci: fix IRQ domain leak on devm_kzalloc failure
- ipv6: Add __in6_dev_get_rtnl_net().
- octeontx2-af: Validate NIX maximum LFs correctly
- udp_tunnel: remove rtnl_lock dependency
- net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync
- net: hisilicon: hns3: use ethtool string helpers
- net: hns3: use string choices helper
- net: hns3: use hns3_get_ae_dev() helper to reduce the unnecessary middle
layer conversion
- net: hns3: use hns3_get_ops() helper to reduce the unnecessary middle
layer conversion
- net: hns3: clear hns alarm: comparison of integer expressions of
different signedness
- net: hns3: unify copper port ksettings configuration path
- net: hns3: refactor MAC autoneg and speed configuration
- net: hns3: fix permanent link down deadlock after reset
- net: hns3: differentiate autoneg default values between copper and fiber
- rtnetlink: Add per-netns RTNL.
- [Config] Set CONFIG_DEBUG_NET_SMALL_RTNL=n
- rtnetlink: Add assertion helpers for per-netns RTNL.
- rtnetlink: Define rtnl_net_trylock().
- ipv6: Convert net.ipv6.conf.${DEV}.XXX sysctl to per-netns RTNL.
- ipv6: fix missing notification for ignore_routes_with_linkdown
- ACPI: processor_idle: Mark LPI enter functions as __cpuidle
- afs: Remove erroneous seq |= 1 in volume lookup loop
- afs: Make /afs/.<cell> as well as /afs/<cell> mountpoints
- afs: Add rootcell checks
- afs: Make /afs/@cell and /afs/. at cell symlinks
- afs: Fix afs_atcell_get_link() to handle RCU pathwalk
- afs: Remove the "autocell" mount option
- afs: Change dynroot to create contents on demand
- afs: Fix misplaced inc of net->cells_outstanding
- afs: Fix missing NULL pointer check in afs_break_some_callbacks()
- ovl: fix comment about locking order
- ata: libata-scsi: limit simulated SCSI command copy to response length
- net/mlx5: LAG, MPESW, Fix missing complete() on devcom error
- ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump
- afs: Convert comma to semicolon
- afs: Fix double netfs initialisation in afs_root_iget()
- drm/xe: Add warn when level can not be zero.
- drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()
- drm/xe/hw_engine: Fix double-free of managed BO in error path
- HID: bpf: Fix hid_bpf_get_data() range check
- drm/v3d: Reject invalid indirect BO handle in indirect CSD setup
- perf/x86/amd/core: Avoid enabling BRS from the SVM reload path
- genirq/generic_chip: Introduce irq_domain_{alloc,remove}_generic_chips()
- gpio: mvebu: free generic chips on unbind
- netfilter: nft_lookup: fix catchall element handling with inverted
lookups
- drm/xe: remove duplicate <kunit/test-bug.h> include
- LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt()
- LoongArch: KVM: Check the return values for put_user()
- LoongArch: KVM: Fix FPU register width with user access API
- LoongArch: KVM: Return full old CSR value from kvm_emu_xchg_csr()
- KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
- fbdev: efifb: fix memory leak in efifb_probe()
- netfilter: nft_set_pipapo: don't leak bad clone into future transaction
- selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()
- batman-adv: mcast: avoid OOB read of num_dests header
- mm/memory_hotplug: fix incorrect altmap passing in error path
- fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()
- fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry()
- mtd: spi-nor: spansion: use die erase for multi-die devices only
- mtd: rawnand: Pause continuous reads at block boundaries
- taskstats: retain dead thread stats in TGID queries
- platform/x86: dell-laptop: fix missing cleanups in init error path
- platform/x86/amd/pmc: Don't log during intermediate wakeups
- NFS: Charge unstable writes by request size, not folio size
- netdev-genl: report NAPI thread PID in the caller's pid namespace
- dm-verity: avoid double increment of &use_bh_wq_enabled
- dm-verity: make error counter atomic
- accel/ivpu: Reject firmware log with size smaller than header
- firmware_loader: introduce __free() cleanup hanler
- Input: ims-pcu - fix firmware leak in async update
- tracing/user_events: Fix use-after-free in user_event_mm_dup()
- gpio: tegra: do not call pinctrl for GPIO direction
- platform/x86/amd/pmc: Avoid logging "(null)" for DMI values
- s390: Revert support for DCACHE_WORD_ACCESS
- [Config] Set CONFIG_DCACHE_WORD_ACCESS=- for s390x
- selftests: net: make busywait timeout clock portable
- ata: libata: Use QUIRK instead of HORKAGE
- ata: libata-core: Skip HPA resize for locked drives
- mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe()
method
- ALSA: hda/cs35l41: Fix firmware load work teardown
- io_uring/rw: ensure reissue path is correctly handled for IOPOLL
- io_uring/rw: preserve partial result for iopoll
- Bluetooth: L2CAP: Fix not tracking outstanding TX ident
- mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless
host
- ksmbd_vfs_rename(): vfs_path_parent_lookup() accepts ERR_PTR() as name
- vfs: make LAST_XXX private to fs/namei.c
- ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
- HID: pidff: Fix missing blank lines after declarations
- HID: pidff: Add missing spaces
- HID: pidff: Rework pidff_upload_effect
- HID: pidff: Use correct effect type in effect update
- bpf, arm64, powerpc: Add bpf_jit_bypass_spec_v1/v4()
- USB: iowarrior: fix use-after-free on disconnect race
- crypto: atmel-sha204a - fail on hwrng registration error in probe path
- btrfs: concentrate the error handling of submit_one_sector()
- btrfs: remove folio parameter from ordered io related functions
- btrfs: remove the COW fixup mechanism
- slab: Introduce kmalloc_obj() and family
- slab: Introduce kmalloc_flex() and family
- add default_gfp() helper macro and use it in the new *alloc_obj()
helpers
- default_gfp(): avoid using the "newfangled" __VA_OPT__ trick
- slab: recognize @GFP parameter as optional in kernel-doc
- fscrypt: Fix key setup in edge case with multiple data unit sizes
- fscrypt: Replace mk_users keyring with simple list
- KVM: arm64: Ensure level is always initialized when relaxing perms
- KVM: arm64: Fix propagation of TLBI level in
kvm_pgtable_stage2_relax_perms()
- bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is
uninitialized
- rtnetlink: Make per-netns RTNL dereference helpers to macro.
- afs: Fix afs_atcell_get_link() to check if ws_cell is unset first
- afs: Fix afs_dynroot_readdir() to not use the RCU read lock
- udp_tunnel: fix deadlock in udp_tunnel_nic_set_port_priv()
- i40e: drop udp_tunnel_get_rx_info() call from i40e_open()
- ice: drop udp_tunnel_get_rx_info() call from ndo_open()
- Bluetooth: L2CAP: Fix regressions caused by reusing ident
- Bluetooth: L2CAP: fix tx ident leak for commands without a response
- dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync()
- perf: Reject exited events as group leaders
- serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR
platforms
- usb: atm: ueagle-atm: reject descriptors that confuse probe and
disconnect
- proc: Fix broken error paths for namespace links
- Upstream stable to v6.6.145, v6.12.96, v6.12.97
* Noble update: upstream stable patchset 2026-09-10 (LP: #2166995) //
CVE-2026-53365
- vsock/virtio: fix zerocopy completion for multi-skb sends
* Noble update: upstream stable patchset 2026-09-10 (LP: #2166995) //
CVE-2025-37964 -- to the 6.1, 6.6 and 6.12 trees ended up with two
- x86/mm: Fix check/use ordering in switch_mm_irqs_off()
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192)
- debugobjects: Allow to refill the pool before SYSTEM_SCHEDULING
- debugobjects: Use LD_WAIT_CONFIG instead of LD_WAIT_SLEEP
- debugobjects: Dont call fill_pool() in early boot hardirq context
- ARM: group is_permission_fault() with is_translation_fault()
- ARM: allow __do_kernel_fault() to report execution of memory faults
- ARM: fix branch predictor hardening
- RDMA/bnxt_re: zero shared page before exposing to userspace
- selftests/bpf: Add test to ensure kprobe_multi is not sleepable
- bpf: Remove mark_precise_scalar_ids()
- selftests/bpf: Tests for per-insn sync_linked_regs() precision tracking
- selftests/bpf: Update comments find_equal_scalars->sync_linked_regs
- hv: utils: handle and propagate errors in kvp_register
- Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs
- phonet: Pass ifindex to fill_addr().
- phonet: Pass net and ifindex to phonet_address_notify().
- scripts/sorttable: Remove unused macro defines
- scripts/sorttable: Remove unused write functions
- scripts/sorttable: Remove unneeded Elf_Rel
- scripts/sorttable: Have the ORC code use the _r() functions to read
- scripts/sorttable: Make compare_extable() into two functions
- scripts/sorttable: Convert Elf_Ehdr to union
- scripts/sorttable: Replace Elf_Shdr Macro with a union
- scripts/sorttable: Convert Elf_Sym MACRO over to a union
- scripts/sorttable: Add helper functions for Elf_Ehdr
- scripts/sorttable: Add helper functions for Elf_Shdr
- scripts/sorttable: Add helper functions for Elf_Sym
- scripts/sorttable: Use uint64_t for mcount sorting
- scripts/sorttable: Move code from sorttable.h into sorttable.c
- scripts/sorttable: Get start/stop_mcount_loc from ELF file directly
- scripts/sorttable: Use a structure of function pointers for elf helpers
- arm64: scripts/sorttable: Implement sorting mcount_loc at boot for arm64
- [Config] Set configs to sort mcount_loc at boot for arm64
- scripts/sorttable: Have mcount rela sort use direct values
- scripts/sorttable: Always use an array for the mcount_loc sorting
- scripts/sorttable: Zero out weak functions in mcount_loc table
- ftrace: Update the mcount_loc check of skipped entries
- ftrace: Have ftrace pages output reflect freed pages
- ftrace: Do not over-allocate ftrace memory
- ftrace: Test mcount_loc addr before calling ftrace_call_addr()
- ftrace: Check against is_kernel_text() instead of kaslr_offset()
- scripts/sorttable: Use normal sort if theres no relocs in the mcount
section
- scripts/sorttable: Allow matches to functions before function entry
- scripts/sorttable: Fix endianness handling in build-time mcount sort
- file: add fput() cleanup helper
- eventpoll: use hlist_is_singular_node() in __ep_remove()
- Revert "ptp: add testptp mask test"
- Bluetooth: btmtk: validate WMT event SKB length before struct access
- Bluetooth: btmtk: accept too short WMT FUNC_CTRL events
- batman-adv: tp_meter: keep unacked list in ascending ordered
- batman-adv: tp_meter: initialize dup_acks explicitly
- batman-adv: tp_meter: initialize dec_cwnd explicitly
- batman-adv: tp_meter: avoid window underflow
- batman-adv: tp_meter: fix fast recovery precondition
- batman-adv: tp_meter: handle seqno wrap-around for fast recovery
detection
- batman-adv: tp_meter: add only finished tp_vars to lists
- batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE
- batman-adv: prevent ELP transmission interval underflow
- batman-adv: tp_meter: initialize last_recv_time during init
- batman-adv: ensure bcast is writable before modifying TTL
- batman-adv: fix (m|b)cast csum after decrementing TTL
- batman-adv: frag: ensure fragment is writable before modifying TTL
- batman-adv: frag: avoid underflow of TTL
- batman-adv: tp_meter: annotate last_recv_time access with
READ/WRITE_ONCE
- batman-adv: tp_meter: prevent parallel modifications of last_recv
- batman-adv: tp_meter: handle overlapping packets
- batman-adv: tt: don't merge change entries with different VIDs
- batman-adv: tt: track roam count per VID
- batman-adv: dat: prevent false sharing between VLANs
- batman-adv: tvlv: enforce 2-byte alignment
- batman-adv: tvlv: avoid race of cifsnotfound handler state
- inet: add indirect call wrapper for getfrag() calls
- err.h: use __always_inline on all error pointer helpers
- wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S
- wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor
- wifi: rtw88: increase TX report timeout to fix race condition
- wifi: iwlwifi: mvm: fix race condition in PTP removal
- f2fs: fix to round down start offset of fallocate for pin file
- f2fs: keep atomic write retry from zeroing original data
- MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
- fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
- nfsd: check get_user() return when reading princhashlen
- NFS: Prevent resource leak in nfs_alloc_server()
- serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero
- wifi: mt76: mt7921: avoid undesired changes of the preset regulatory
domain
- ACPI: scan: Use async schedule function in acpi_scan_clear_dep_fn()
- xfs: fix error returns in CoW fork repair
- locking/mutex: Remove wakeups from under mutex::wait_lock
- net: ipv6: Make udp_tunnel6_xmit_skb() void
- Revert "PCI: qcom: Advertise Hotplug Slot Capability with no Command
Completion support"
- KVM: SEV: Ignore MMIO requests of length '0'
- mtd: spi-nor: macronix: Add post_sfdp fixups for Quad Input Page Program
- mtd: spi-nor: macronix: add support for mx66{l2, u1}g45g
- LoongArch: Report dying CPU to RCU in stop_this_cpu()
- MIPS: smp: report dying CPU to RCU in stop_this_cpu()
- locking: rtmutex: Fix wake_q logic in task_blocks_on_rt_mutex
- bonding: annotate data-races arcound churn variables
- Upstream stable to v6.6.144, v6.12.95
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53389
- net/tcp-ao: fix use-after-free of key in del_async path
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53393
- nfsd: reset write verifier on deferred writeback errors
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53400
- i2c: core: fix adapter registration race
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63806
- KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with
get_unaligned()
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63940
- KVM: SEV: Ignore Port I/O requests of length '0'
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53387
- iio: light: veml6075: add bounds check to veml6075_it_ms index
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53070
- sctp: disable BH before calling udp_tunnel_xmit_skb()
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-43216
- net: Drop the lock in skb_may_tx_timestamp()
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-64244
- drivers/base/memory: set mem->altmap after successful device
registration
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53384
- serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53390
- ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53391
- NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53397
- nfsd: fix posix_acl leak on SETACL decode failure
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53398
- NFSD: Fix SECINFO_NO_NAME decode error cleanup
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-64245
- fbdev: modedb: fix a possible UAF in fb_find_mode()
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53403
- fbdev: Fix fb_new_modelist to prevent null-ptr-deref in
fb_videomode_to_var
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-64246
- power: reset: linkstation-poweroff: fix use-after-free in the
linkstation_poweroff_init()
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63794
- KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-64247
- KVM: x86: hyper-v: Bound the bank index when querying sparse banks
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63795
- 9p: avoid putting oldfid in p9_client_walk() error path
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63796
- ocfs2: reject oversized group bitmap descriptors
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63797
- rpmsg: char: Fix use-after-free on probe error path
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-64249
- fpga: region: fix use-after-free in child_regions_with_firmware()
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63798
- irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup
on remove
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63800
- pNFS: Fix use-after-free in pnfs_update_layout()
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63801
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63802
- blk-cgroup: fix UAF in __blkcg_rstat_flush()
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63803
- hdlc_ppp: sync per-proto timers before freeing hdlc state
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63804
- gfs2: fix use-after-free in gfs2_qd_dealloc
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63808
- exfat: fix potential use-after-free in exfat_find_dir_entry()
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63809
- bpf: use kvfree() for replaced sysctl write buffer
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63812
- f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63814
- f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63817
- f2fs: validate compress cache inode only when enabled
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63821
- wifi: rtw88: usb: fix memory leaks on USB write failures
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63822
- wifi: ath11k: fix warning when unbinding
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63823
- keys: Pin request_key_auth payload in instantiate paths
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63824
- KEYS: fix overflow in keyctl_pkey_params_get_2()
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63826
- fbdev: fix use-after-free in store_modes()
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-64254
- NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG
share BAR
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63827
- apparmor: fix use-after-free in rawdata dedup loop
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63828
- apparmor: mediate the implicit connect of TCP fast open sendmsg
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63830
- net: skmsg: preserve sg.copy across SG transforms
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63831
- mac802154: llsec: add skb_cow_data() before in-place crypto
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53361
- af_unix: Set gc_in_progress to true in unix_gc().
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63833
- ntfs3: reject direct userspace writes to reserved $LX* xattrs
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53366
- ipv4: account for fraggap on the paged allocation path
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53362
- ipv6: account for fraggap on the paged allocation path
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63834
- batman-adv: tp_meter: restrict number of unacked list entries
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63835
- batman-adv: v: prevent OGM aggregation on disabled hardif
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63836
- batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-63807
- KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping
level
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53381
- virtiofs: fix UAF on submount umount
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53382
- media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53383
- ksmbd: reject non-VALID session in compound request branch
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53385
- vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent
vcs_write
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53388
- fuse: re-lock request before replacing page cache folio
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53157
- net: phonet: free phonet_device after RCU grace period
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53163
- locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2025-23131
- dlm: prevent NPD when writing a positive value to event_done
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-46252
- regulator: core: fix locking in regulator_resolve_supply() error path
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-52928
- af_unix: Reject SIOCATMARK on non-stream sockets
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-43010
- bpf: Reject sleepable kprobe_multi programs at attach time
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53325
- agp/amd64: Fix broken error propagation in agp_amd64_probe()
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-64188
- net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-64191
- i2c: stub: Reject I2C block transfers with invalid length
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53327
- debugobjects: Do not fill_pool() if pi_blocked_on
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-52909
- ip6_vti: set netns_immutable on the fallback device.
* Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
CVE-2026-53167
- fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
Date: 2026-10-01 21:47:26.094556+00:00
Changed-By: Manuel Diewald <manuel.diewald at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-nvidia-lowlatency/6.8.0-1065.68.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the noble-changes
mailing list