[ubuntu/noble-proposed] linux-nvidia-lowlatency 6.8.0-1065.68.1 (Accepted)

Timo Aaltonen tjaalton at ubuntu.com
Sat Oct 3 19:50:55 UTC 2026


linux-nvidia-lowlatency (6.8.0-1065.68.1) noble; urgency=medium

  * noble/linux-nvidia-lowlatency: 6.8.0-1065.68.1 -proposed tracker (LP: #2168116)

  [ Ubuntu-nvidia: 6.8.0-1065.68 ]

  * noble/linux-nvidia: 6.8.0-1065.68 -proposed tracker (LP: #2168118)
  [ Ubuntu: 6.8.0-147.147 ]
  * noble/linux: 6.8.0-147.147 -proposed tracker (LP: #2168142)
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026)
    - platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug
    - selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs
    - drm/virtio: fix deadlock in display_info_cb by removing hotplug from
      dequeue worker
    - mtd: mtdswap: remove debugfs stats file on teardown
    - seqlock: Cure some more scoped_seqlock() optimization fails
    - seqlock: Allow KASAN to fail optimizing
    - seqlock: Allow UBSAN_ALIGNMENT to fail optimizing
    - xprtrdma: Clear receive-side ownership pointers on release
    - Input: ims-pcu - fix logic error in packet reset
    - arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234
    - mtd: nand: mtk-ecc: stop on ECC idle timeouts
    - RDMA/cma: Fix hardware address comparison length in netevent callback
    - RDMA/umem: Add support for creating pinned DMABUF umem with a given dma
      device
    - RDMA/umem: Introduce an option to revoke DMABUF umem
    - RDMA/umem: Add ib_umem_dmabuf_get_pinned_and_lock helper
    - RDMA/umem: Move umem dmabuf revoke logic into helper function
    - RDMA/umem: Add pinned revocable dmabuf import interface
    - RDMA/umem: Add helpers for umem dmabuf revoke lock
    - RDMA/erdma: initialize ret for empty receive WR lists
    - RDMA/hns: Fix potential integer overflow in mhop hem cleanup
    - selftests/alsa: Fix memory leak in find_controls error path
    - RDMA/irdma: Prevent overflows in memory contiguity checks
    - wifi: nl80211: validate nested MBSSID IE blobs
    - wifi: cfg80211: validate PMSR measurement type data
    - wifi: cfg80211: reject unsupported PMSR FTM location requests
    - ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on
      start/stop
    - ASoC: amd: ps: fix wrong ACP version string in pci_request_regions()
    - ASoC: cs42l43: Correct report for forced microphone jack
    - ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after
      lookup
    - firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context
    - ata: sata_dwc_460ex: use platform_get_irq()
    - ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending
      interrupts
    - ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC
    - drm/i915/gt: use correct selftest config symbol
    - sched/vtime: Get rid of generic vtime_task_switch() implementation
    - powerpc/time: Prepare to stop elapsing in dynticks-idle
    - powerpc/vtime: Initialize starttime at boot for native accounting
    - can: j1939: fix lockless local-destination check
    - drm/i915/selftests: Fix GT PM sort comparators
    - USB: storage: add NO_ATA_1X quirk for Longmai USB Key
    - usb: chipidea: fix usage_count leak when autosuspend_delay is negative
    - USB: gadget: snps-udc: fix device name leak on probe failure
    - USB: gadget: fsl-udc: fix device name leak on probe failure
    - USB: serial: ftdi_sio: add support for E+H FXA291
    - USB: serial: keyspan_pda: fix data loss on receive throttling
    - USB: serial: option: add TDTECH MT5710-CN
    - crypto: rsa-pkcs1pad: Don't WARN on an empty digest
    - RISC-V: KVM: Serialize virtual interrupt pending state updates
    - usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits
    - wifi: ath11k: Flush the posted write after writing to
      PCIE_SOC_GLOBAL_RESET
    - wifi: ath12k: Flush the posted write after writing to
      PCIE_SOC_GLOBAL_RESET
    - btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8
    - ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI
    - ASoC: cs35l56: Don't use devres to unregister component
    - ASoC: cs35l56: Fix potential probe() deadlock
    - ASoC: cs35l56: Use complete_all() to signal init_completion
    - wifi: iwlwifi: mvm: validate SAR GEO response payload size
    - wifi: iwlwifi: mvm: fix read in wake packet notification handler
    - hwmon: (asus-ec-sensors) fix looping over banks while reading from EC
    - hwmon: (asus-ec-sensors) fix EC read intervals
    - hwmon: (asus-ec-sensors) add missed handle for ENOMEM
    - wifi: mac80211: recalculate TIM when a station enters power save
    - pds_core: reject component parameter in legacy firmware update
    - amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN
    - pds_core: yield the CPU while waiting for the adminq to drain
    - pds_core: order completion reads after the ownership check
    - pds_core: check for workqueue allocation failure
    - tls: device: push pending open record on splice EOF
    - selftest: af_unix: Add Kconfig file.
    - selftests: af_unix: add USER_NS config
    - selftests: openvswitch: add config file
    - amt: make the head writable before rewriting the L2 header
    - net: bridge: vlan: fix vlan range dumps starting with pvid
    - net: dpaa: fix mode setting
    - iomap: correct the range of a partial dirty clear
    - net: stmmac: fix l3l4 filter rejecting unsupported offload requests
    - net: stmmac: reset residual action in L3L4 filters on delete
    - net: stmmac: enable the MAC on link up for all supported speeds
    - octeontx2-vf: set TC flower flag on MCAM entry allocation
    - ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup
    - ppp: use IFF_NO_QUEUE in virtual interfaces
    - ppp: convert to percpu netstats
    - ppp: enable TX scatter-gather
    - ppp: annotate data races in ppp_generic
    - hinic: remove unused ethtool RSS user configuration buffers
    - net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule
    - net/mlx5e: Report zero bandwidth for non-ETS traffic classes
    - net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation
    - net: ipv6: fix dif and sdif mismatch in raw6_icmp_error
    - ice: fix LAG recipe to profile association
    - drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video()
    - drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't
      at 0 (v2)
    - drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older
    - drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT
    - drm/nouveau/acr: fix missing nvkm_done() in error path of
      nvkm_acr_oneinit()
    - drm/radeon: fix r100_copy_blit for large BOs
    - drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips
    - drm/amdgpu: Fix VFCT bus number matching with soft filter
    - drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X)
    - media: aspeed: fix missing of_reserved_mem_device_release() on probe
      failure
    - media: cec: seco: unregister adapter on IR probe failure
    - media: cedrus: clean up media device on probe failure
    - media: cedrus: Fix missing cleanup in error path
    - media: marvell-cam: fix missing pci_disable_device() on remove
    - media: nxp: imx8-isi: Clean up already-initialized pipes on probe
      failure
    - media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init
      error path
    - media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding
    - media: tegra-video: vi: fix invalid u32 return value in format lookup
    - media: v4l2-ctrls-request: add NULL check in
      v4l2_ctrl_request_complete()
    - media: vb2: use ssize_t for vb2_read/vb2_write
    - media: vidtv: fix reference leak on failed device registration
    - media: vimc: fix reference leak on failed device registration
    - media: vivid: add vivid_update_reduced_fps()
    - media: vpif_capture: fix OF node reference imbalance
    - staging: rtl8723bs: fix inverted HT40 secondary channel offset
    - platform/loongarch: laptop: Explicitly reset bl_powered state when
      suspend
    - LoongArch: Fix oops during single-step debugging
    - x86/boot/compressed: Disable jump tables
    - serial: sc16is7xx: implement gpio get_direction() callback
    - tracing/eprobe: Fix exact system name matching in
      eprobe_dyn_event_match()
    - tracing/probes: Avoid temporary buffer truncation in
      trace_probe_match_command_args()
    - tracing/probes: Fix potential underflow in LEN_OR_ZERO macro
    - tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err()
    - arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates
    - Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer
      updates"
    - mptcp: decrement subflows counter on failed passive join
    - mptcp: only set DATA_FIN when a mapping is present
    - iommu/vt-d: Disallow SVA if page walk is not coherent
    - ice: use READ_ONCE() to access cached PHC time
    - drm/amd/pm: make pp_features read-only when scpm is enabled
    - drm/amd/display: Fix dcn32 DTB DTO update breaking live pixel rate
      sources
    - io_uring/rw: fix missing ERESTARTSYS conversion in read paths
    - net: pcs: xpcs: fix SGMII state reading
    - bpf: drop bpf_lsm_getselfattr from hook list
    - udmabuf: Do not create malformed scatterlists
    - i2c: davinci: Unregister cpufreq notifier on probe failure
    - VFS/audit: introduce kern_path_parent() for audit
    - audit: widen ino fields to u64
    - audit: use 'unsigned int' instead of 'unsigned'
    - ALSA: hda: conexant: Remove mic bias threshold override
    - ALSA: hda: Fix cached processing coefficient verbs
    - rxrpc: Pull out certain app callback funcs into an ops table
    - fbcon: Rename struct fbcon_ops to struct fbcon_par
    - fbcon: Use correct type for vc_resize() return value
    - rxrpc: Don't need barrier for ->tx_bottom and ->acks_hard_ack
    - rxrpc: Use irq-disabling spinlocks between app and I/O thread
    - rxrpc: Fix notification vs call-release vs recvmsg
    - rxrpc: Fix socket notification race
    - vduse: Use fixed 4KB bounce pages for non-4KB page size
    - vduse: remove unused vaddr parameter of vduse_domain_free_coherent
    - vduse: take out allocations from vduse_dev_alloc_coherent
    - octeontx2: Annotate mmio regions as __iomem
    - octeontx2-pf: clear stale mailbox IRQ state before request_irq()
    - octeontx2-vf: clear stale mailbox IRQ state before request_irq()
    - fbdev/efifb: Replace references to global screen_info by local pointer
    - ASoC: mediatek: mt8192-afe-pcm: Convert to devm_pm_runtime_enable()
    - ASoC: mediatek: mt8192-afe-pcm: Simplify with dev_err_probe()
    - ASoC: mediatek: Use common mtk_afe_pcm_platform with common probe cb
    - ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable
    - ASoC: mediatek: mt8183: Check runtime resume during probe
    - netfilter: nft_set_pipapo: use GFP_KERNEL for insertions
    - netfilter: nft_set_pipapo: move prove_locking helper around
    - netfilter: nft_set_pipapo: make pipapo_clone helper return NULL
    - netfilter: nft_set_pipapo: prepare walk function for on-demand clone
    - netfilter: nft_set_pipapo: merge deactivate helper into caller
    - netfilter: nft_set_pipapo: prepare pipapo_get helper for on-demand clone
    - netfilter: nft_set_pipapo: move cloning of match info to insert/removal
      path
    - netfilter: nf_conntrack_sip: remove net variable shadowing
    - netfilter: nf_tables: Remove unused nft_reduce_is_readonly()
    - netfilter: nf_tables: remove register tracking infrastructure
    - NFSD: pass nfsd_file to nfsd_iter_read()
    - sunrpc: allocate a separate bvec array for socket sends
    - SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists
    - SUNRPC: Return an error from xdr_buf_to_bvec() on overflow
    - mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages
    - dma: dw-edma: Fix build warning in dw_edma_pcie_probe()
    - dmaengine: dw-edma: Fix confusing cleanup.h syntax
    - platform/x86: dell-smbios: Move request functions for reuse
    - i2c: imx: separate atomic, dma and non-dma use case
    - nfs: remove dead code for the old swap over NFS implementation
    - ovl: use linked upper dentry in copy-up tmpfile
    - bootconfig: do not put quotes on cmdline items unless necessary
    - bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c
    - bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline()
    - net: ipa: fix SMEM state handle leaks in SMP2P init
    - KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN
    - udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf()
    - rxrpc: Disable IRQ, not BH, to take the lock for ->attend_link
    - netfilter: nft_quota: use atomic64_xchg for reset
    - soc: qcom: ice: Allow explicit votes on 'iface' clock for ICE
    - wifi: cfg80211: pass net_device to .set_monitor_channel
    - wifi: cfg80211: define and use wiphy guard
    - wifi: cfg80211: derive S1G beacon TSF from S1G fields
    - riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus()
    - drm/xe/wopcm: fix WOPCM size for LNL+
    - smb: move some duplicate definitions to common/cifsglob.h
    - regulator: mt6358: use regmap helper to read fixed LDO calibration
    - netlink: specs: rt-link: convert bridge port flag attributes to u8
    - wifi: mt76: mt7925: extend mt7925_mcu_bss_he_tlv for per-link BSS
    - ovl: fix trusted xattr escape prefix matching
    - drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem
    - dpll: add clock quality level attribute and op
    - net/mlx5: DPLL, Add clock quality level op implementation
    - net/mlx5: Remove newline at the end of a netlink error message
    - net/mlx5: Refactor EEPROM query error handling to return status
      separately
    - octeontx2-pf: tc: fix egress ratelimiting
    - ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV
    - drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay
    - drm/displayid: move drm_displayid.h to drm_displayd_internal.h
    - drm/displayid: fix Tiled Display Topology ID size
    - drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds
    - drm/amdkfd: Use kvcalloc to allocate arrays
    - drm/gfx10: Program DB_RING_CONTROL
    - drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge
    - media: nuvoton: npcm-video: fix error handling in npcm_video_init()
    - media: qcom: camss: Fix RDI streaming for CSID GEN2
    - media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely
    - ALSA: timer: drain a slave's callback before its master detaches it
    - ALSA: timer: don't re-enter an instance callback that is still running
    - LoongArch: Retrieve CPU package ID from PPTT when available
    - sysctl: treewide: constify ctl_table_header::ctl_table_arg
    - ceph: fix refcount leak in ceph_readdir()
    - ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP
    - net: move skb_gro_receive_list from udp to core
    - net: add pskb_may_pull() to skb_gro_receive_list()
    - vsock/virtio: collapse receive queue under memory pressure
    - drm/amd/pm: fix amdgpu_pm_info power display units
    - drm/amd/pm: fix smu13 power limit range calculation
    - drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources
    - xfs: add an explicit owner field to xfs_da_args
    - xfs: factor out xfs_attr3_leaf_init
    - xfs: don't replace the wrong part of the cow fork
    - rxrpc: Fix CPU time starvation in I/O thread
    - ASoC: mediatek: mt8183-afe-pcm: Shorten memif_data table using macros
    - ASoC: mediatek: mt8183-afe-pcm: Support >32 bit DMA addresses
    - tcp: Decrement tcp_md5_needed static branch
    - nvmet: Introduce nvmet_req_transfer_len()
    - block: add helper add_disk_final()
    - block: remove redundant GD_NEED_PART_SCAN in add_disk_final()
    - Bluetooth: Add PA_LINK to distinguish BIG sync and PA sync connections
    - Bluetooth: hci_core: Fix not accounting for BIS/CIS/PA links separately
    - afs: Improve server refcount/active count tracing
    - afs: Make afs_lookup_cell() take a trace note
    - afs: Drop the net parameter from afs_unuse_cell()
    - rxrpc: Allow the app to store private data on peer structs
    - afs: Use the per-peer app data provided by rxrpc
    - afs: Fix afs_server ref accounting
    - afs: Simplify cell record handling
    - afs: Fix dynamic lookup to fail on cell lookup failure
    - afs: Fix lack of locking around modifications of net->cells_dyn_ino
    - lib/string_choices: Add str_plural() helper
    - USB: gadget: Use str_enable_disable-like helpers
    - usb: musb: omap2430: clean up probe error handling
    - net/mlx5e: Fix NULL pointer dereference in ioctl module EEPROM query
    - rxrpc: Fix locking issues with the peer record hash
    - wifi: nl80211: fix nl80211_start_radar_detection return value
    - afs: Set vllist to NULL if addr parsing fails
    - dpll: fix clock quality level reporting
    - afs: Fix delayed allocation of a cell's anonymous key
    - afs: handle CB.InitCallBackState3 requests without a server record
    - Bluetooth: hci_conn: Fix running bis_cleanup for hci_conn->type PA_LINK
    - Bluetooth: hci_conn: Fix not cleaning up Broadcaster/Broadcast Source
    - Bluetooth: hci_conn: Remove redundant memset after kzalloc
    - Bluetooth: hci_conn: Fix not cleaning up PA_LINK connections
    - Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate()
    - afs: Fix uninit var in afs_alloc_anon_key()
    - Upstream stable to v6.6.148, v6.12.101
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68371
    - usb: musb: omap2430: Do not put borrowed of_node in probe
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72130
    - nvmet-auth: reject short AUTH_RECEIVE buffers
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72168
    - mtd: maps: vmu-flash: fix fault in unaligned fixup
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72213
    - mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72244
    - gpu/buddy: bail out of try_harder when alignment cannot be honoured
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68129
    - gve: fix Rx queue stall on alloc failure
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-53078
    - bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68119
    - tcp: initialize standalone TCP-AO response padding
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68136
    - net: gro: fix double aggregation of flush-marked skbs
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68139
    - net/mlx5e: Use sender devcom for MPV master-up
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68145
    - iomap: fix out-of-bounds bitmap_set() with zero-length range
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68161
    - sctp: close UDP tunnel sockets during netns teardown
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68162
    - sctp: avoid auth_enable sysctl UAF during netns teardown
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68178
    - misc: nsm: pin the module while the device is open
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68179
    - misc: nsm: only unlock nsm_dev on post-lock error paths
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68183
    - firmware: stratix10-svc: fix memory leaks and list corruption bugs
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68193
    - wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68203
    - media: vivid: fix cleanup bugs in vivid_init()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68205
    - media: v4l2-fwnode: Fix subdev owner overwritten in
      v4l2_async_register_subdev_sensor()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68221
    - media: nuvoton: npcm-video: fix memory leaks in probe and remove
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68225
    - media: i2c: alvium: fix critical pointer access in alvium_ctrl_init
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68228
    - media: chips-media: wave5: Move src_buf Removal to finish_encode
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68235
    - drm/amd/display: dce100: skip non-DP stream encoders for DP MST
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68247
    - drm/i915/bios: range check LFP Data Block panel_type2
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68260
    - drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68261
    - drm/imagination: fix error checking of pvr_vm_context_lookup()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68262
    - drm/imagination: Fix user array stride in pvr_set_uobj_array()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68263
    - drm/imagination: Fix double call to drm_sched_entity_fini()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68437
    - drm/imagination: Fit paired fragment job in the correct CCCB
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68281
    - drm/imagination: Count paired job fence as dependency in prepare_job()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68290
    - rds: tcp: unregister sysctl before tearing down listen socket
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68293
    - net/mlx5: Fix MCIA register buffer overflow on 32 dword reads
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68439
    - wifi: mt76: mt7925: fix possible NULL-pointer deref in
      mt7925_mcu_bss_he_tlv()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68314
    - net: mctp i3c: clean up notifier and buses if driver register fails
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68318
    - pds_core: fix use-after-free on workqueue during remove
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68319
    - pds_core: fix deadlock between reset thread and remove
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68346
    - ALSA: hda: cs35l41: validate and free ACPI mute object
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2025-40098
    - ALSA: hda: cs35l41: Fix NULL pointer dereference in
      cs35l41_get_acpi_mute_state()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68442
    - btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68443
    - hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68372
    - usb: core: port: Deattach Type-C connector on component unbind
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68396
    - scsi: core: wake eh reliably when using scsi_schedule_eh
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68408
    - wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64570
    - wifi: mac80211: fix fils_discovery double free on alloc failure
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64568
    - wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72175
    - fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-45901
    - netfilter: nf_tables: revert commit_mutex usage in reset path
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-45897
    - netfilter: nft_counter: serialize reset with spinlock
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68093
    - KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision
      after hotplug
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68164
    - mm/damon/core: disallow overlapping input ranges for damon_set_regions()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68165
    - mm/damon/core: validate ranges in damon_set_regions()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72015
    - fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72017
    - net: macb: drop in-flight Tx SKBs on close
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72030
    - ata: libata-core: Reject an invalid concurrent positioning ranges count
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72023
    - octeontx2-pf: fix SQB pointer leak on init failure
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72040
    - ipmi: fix refcount leak in i_ipmi_request()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72045
    - octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72062
    - gpio: mt7621: avoid corruption of shared interrupt trigger state
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72051
    - net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for
      changelink
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72065
    - net: mana: Validate the packet length reported by the NIC
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72069
    - locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72070
    - wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72142
    - i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72147
    - dmaengine: dw-edma-pcie: Reject devices without driver data
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72254
    - netfilter: nft_fib: reject fib expression on the netdev egress hook
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72253
    - netfilter: nf_conntrack_sip: validate skb_dst() before accessing it
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72260
    - ASoC: mediatek: mt8192: Check runtime resume during probe
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72305
    - VDUSE: avoid leaking information to userspace
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72299
    - tipc: restrict socket queue dumps in enqueue tracepoints
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-74436
    - rxrpc: serialize kernel accept preallocation with socket teardown
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64205
    - i2c: i801: fix hardware state machine corruption in error path
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68096
    - audit: fix recursive locking deadlock in audit_dupe_exe()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64280
    - fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68147
    - fscrypt: Avoid dynamic allocation in fscrypt_get_devices()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68123
    - openvswitch: fix GSO userspace truncation underflow
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68097
    - ksmbd: validate ACE size against SID sub-authorities
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68098
    - ksmbd: bound DACL dedup walk to copied ACEs
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68099
    - ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68100
    - ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68104
    - drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68106
    - drm/amdgpu: fix division by zero with invalid uvd dimensions
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68429
    - drm/dp_mst: Handle torn-down topology gracefully in
      drm_dp_mst_topology_queue_probe()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68107
    - drm/amdgpu/vcn4: avoid rereading IB param length
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68108
    - drm/amdgpu/vce: fix integer overflow in image size
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68110
    - drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68111
    - drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68112
    - drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68430
    - drm/amdgpu/gfx8: drop unecessary BUG_ON()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68246
    - drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68115
    - drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68116
    - vxlan: mdb: Fix source list corruption on a failed replace
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68117
    - tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68121
    - pppoe: reload header pointer after dev_hard_header()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68124
    - mctp: serial: handle zero-length frames to prevent rx buffer overflow
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68125
    - mac802154: llsec: reject frames shorter than the authentication tag
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68126
    - mac802154: hold an interface reference across the scan worker
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68127
    - ila: reload IPv6 header after pskb_may_pull in checksum adjust
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68130
    - ksmbd: defer destroy_previous_session() until after NTLM authentication
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68131
    - rbd: Reset positive result codes to zero in object map update path
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68135
    - net: hip04: fix RX buffer leak on build_skb failure
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68137
    - net/x25: fix use-after-free in x25_kill_by_neigh()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68140
    - net/iucv: fix use-after-free of a severed iucv_path
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68141
    - net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68142
    - geneve: require CAP_NET_ADMIN in the device netns for changelink
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68143
    - net: slip: serialize receive against buffer reallocation
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68432
    - vxlan: require CAP_NET_ADMIN in the device netns for changelink
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68144
    - phonet: pep: fix use-after-free in pep_get_sb()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68146
    - ftrace: Add global mutex to serialize trace_parser access
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68148
    - fscrypt: Add missing superblock check in find_or_insert_direct_key()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68149
    - fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68151
    - binfmt_elf_fdpic: only honour the first PT_INTERP
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68153
    - libceph: remove debugfs files before client teardown
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68154
    - libceph: reject zero bucket types in crush_decode
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68155
    - libceph: Reject monmaps advertising zero monitors
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68156
    - libceph: refresh auth->authorizer_buf{,_len} after authorizer update
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68157
    - libceph: guard missing CRUSH type name lookup
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68158
    - libceph: Fix multiplication overflow in decode_new_up_state_weight()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68433
    - libceph: bound get_version reply decode to front len
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68160
    - ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68175
    - tracing: Fix resource leak on mmiotrace trace_pipe close
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68176
    - tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68180
    - intel_th: fix MSC output device reference leak
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68181
    - mei: bus: access mei_device under device_lock on cleanup
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68182
    - comedi: comedi_parport: deal with premature interrupt
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68184
    - cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68186
    - binfmt_misc: set have_execfd only once the interpreter is opened
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68187
    - exec: fix unsigned loop counter wrap in transfer_args_to_stack()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68188
    - Bluetooth: RFCOMM: Fix session UAF in set_termios
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68189
    - Bluetooth: hci_sync: Protect UUID list traversal
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68190
    - staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68192
    - wifi: brcmfmac: make release_scratchbuffers idempotent
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68194
    - wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68195
    - wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68196
    - wifi: wilc1000: validate assoc response length before subtracting header
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68197
    - wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-
      oper
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68199
    - wifi: ath6kl: fix OOB access from firmware ADDBA window size
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68202
    - ALSA: seq: close a re-opened queue timer in the destructor
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68204
    - media: vivid: check for vb2_is_busy() when toggling caps
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68206
    - media: v4l2-ctrls: validate HEVC active reference counts
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68207
    - media: ti: vpe: unwind v4l2 device registration on probe error
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68209
    - media: sun4i-csi: Return queued buffers on start_streaming() failure
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68210
    - media: stm32: dcmi: unregister notifier on probe failure
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68212
    - media: saa7134: Fix a possible memory leak in saa7134_video_init1
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68213
    - media: rtl2832_sdr: Return queued buffers on start_streaming() failure
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68214
    - media: rtl2832: fix use-after-free in rtl2832_remove()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68215
    - media: radio-si476x: Unregister v4l2_device on probe failure
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68216
    - media: pwc: Return queued buffers on start_streaming() failure
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68217
    - media: pwc: Drain fill_buf on start_streaming() failure
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68218
    - media: pci: dm1105: Free allocated workqueue
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68219
    - media: nxp: imx8-isi: Fix potential out-of-bounds issues
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68220
    - media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and
      pipe
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68222
    - media: msi2500: Return queued buffers on start_streaming() failure
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68223
    - media: meson: vdec: Fix memory leak in error path of vdec_open
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68226
    - media: cx23885: add ioremap return check and cleanup
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68227
    - media: cx231xx: fix devres lifetime
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68229
    - media: cedrus: skip invalid H.264 reference list entries
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68231
    - media: airspy: Return queued buffers on start_streaming() failure
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68445
    - drm/vc4: Prevent shader BO mappings from becoming writable
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68446
    - drm/vmwgfx: Validate vmw_surface_metadata::array_size
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68234
    - drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68236
    - drm/amd/display: set new_stream to NULL after release
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68243
    - drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68244
    - drm/i915/gem: Do not leak siblings[] on proto context error
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68248
    - drm/i915: Return NULL on error in active_instance
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68249
    - drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68250
    - drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68251
    - drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68255
    - drm/virtio: bound EDID block reads to the response buffer
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68256
    - drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path
      leaks prev_sink reference
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68259
    - drm/amdkfd: Check bounds in allocate_event_notification_slot
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68269
    - drm/i915/gem: Add missing nospec on parallel submit slot
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68271
    - drm/nouveau: fix reversed error cleanup order in ucopy functions
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68272
    - drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68277
    - drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68278
    - drm/dp/mst: fix buffer overflows in sideband chunk accumulation
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68279
    - drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68280
    - drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68284
    - bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68294
    - net: qrtr: restrict socket creation to the initial network namespace
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68297
    - tipc: fix u16 MTU truncation in media and bearer MTU validation
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68299
    - vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68300
    - sctp: auth: verify auth requirement when auth_chunk is NULL
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68301
    - net: hsr: fix memory leak on slave unregistration by removing synced
      VLANs
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68302
    - amt: re-read skb header pointers after every pull
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68304
    - wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68306
    - wifi: mt76: mt7996: fix possible NULL-pointer deref in
      mt7996_mcu_sta_bfer_eht()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68308
    - wifi: mt76: mt7996: check pointer returned by
      mt76_connac_get_he_phy_cap()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68309
    - wifi: mt76: connac: fix possible NULL-pointer deref in
      mt76_connac_mcu_uni_bss_he_tlv()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68310
    - wifi: mt76: mt7915: guard HE capability lookups
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68313
    - tipc: fix infinite loop in __tipc_nl_compat_dumpit
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64576
    - nexthop: initialize extack in nh_res_bucket_migrate()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64577
    - gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68315
    - sctp: validate stream count in sctp_process_strreset_inreq()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68317
    - pds_core: fix auxiliary device add/del races
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68320
    - sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68324
    - iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68325
    - iommu/amd: Bound the early ACPI HID map
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68326
    - wifi: mwifiex: bound uAP association event IEs to the event buffer
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68327
    - wan: wanxl: Only reset hardware after BAR mapping
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68328
    - nfp: Check resource mutex allocation
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64574
    - wifi: mac80211: tear down new links on vif update error path
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68329
    - iommu/amd: Wait for completion instead of returning early in
      iommu_completion_wait()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68331
    - dpaa2-eth: put MAC endpoint device on disconnect
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68333
    - dpaa2-switch: put MAC endpoint device on disconnect
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68335
    - rds: drop incoming messages that cross network namespace boundaries
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68336
    - bonding: fix devconf_all NULL dereference when IPv6 is disabled
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68338
    - net/packet: avoid fanout hook re-registration after unregister
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68339
    - Bluetooth: btusb: validate Realtek vendor event length
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68340
    - hwmon: occ: validate poll response sensor blocks
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68343
    - smb: client: validate DFS referral PathConsumed
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68348
    - ASoC: tas2781: bound firmware description string parsing
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68450
    - btrfs: free mapping node on duplicate reloc root insert
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68349
    - wifi: carl9170: fix buffer overflow in rx_stream failover path
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68350
    - wifi: carl9170: fix OOB read from off-by-two in TX status handler
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68351
    - wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68352
    - wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68353
    - wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68354
    - firewire: net: Fix fragmented datagram reassembly
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68355
    - wifi: ath11k: fix potential buffer underflow in
      ath11k_hal_rx_msdu_list_get()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68357
    - watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68359
    - hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68360
    - hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68361
    - hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68362
    - wifi: ath11k: fix NULL pointer dereference in
      ath11k_hal_srng_access_begin
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68363
    - wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware
      request
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68365
    - USB: serial: io_edgeport: cap received transmit credits
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68366
    - usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64583
    - usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before
      teardown
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68368
    - usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68369
    - usb: gadget: printer: fix infinite loop in printer_read()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64584
    - usb: gadget: f_midi: cancel pending IN work before freeing the midi
      object
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68370
    - usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68373
    - wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64569
    - mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68376
    - sctp: fix auth_hmacs array size in struct sctp_cookie
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68377
    - net/sched: act_tunnel_key: Defer dst_release to RCU callback
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64578
    - ksmbd: validate compound request size before reading StructureSize2
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68381
    - ksmbd: pin conn during async oplock break notification
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68386
    - bpf, sockmap: Reject unhashed UDP sockets on sockmap update
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68388
    - smb/client: handle overlapping allocated ranges in fallocate
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68389
    - Bluetooth: hci_qca: Clear memdump state on invalid dump size
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68391
    - Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68392
    - Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64573
    - Bluetooth: qca: fix NVM tag length underflow in TLV parser
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68449
    - ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-
      scanning
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68395
    - ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is
      registered
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68397
    - net/iucv: take a reference on the socket found in afiucv_hs_rcv()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64572
    - ipv4: fib: free fib_alias with kfree_rcu() on insert error path
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68398
    - ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68402
    - wifi: cfg80211: bound element ID read when checking non-inheritance
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68403
    - wifi: brcmfmac: initialize SDIO data work before cleanup
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68405
    - wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68406
    - wifi: cfg80211: validate PMSR FTM preamble range
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68407
    - wifi: nl80211: free RNR data on MBSSID mismatch
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64571
    - wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68410
    - wifi: libertas: fix memory leak in helper_firmware_cb()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68411
    - wifi: mac80211_hwsim: clamp virtio RX length before skb_put
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68413
    - wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68414
    - wifi: cfg80211: cancel sched scan results work on unregister
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64579
    - xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64580
    - xfrm6: clear dst.dev on error to avoid double netdev_put in
      xfrm6_fill_dst()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68416
    - mtd: fix double free and WARN_ON in add_mtd_device() error paths
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68417
    - RDMA/siw: publish QP after initialization
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68419
    - RDMA/irdma: Prevent rereg_mr for non-mem regions
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68444
    - firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68422
    - btrfs: fix root leak if its reloc root is unexpected in
      merge_reloc_roots()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64567
    - btrfs: reject free space cache with more entries than pages
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68425
    - IB/mad: Drop unmatched RMPP responses before reassembly
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64565
    - Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68427
    - gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72146
    - dmaengine: sh: rz-dmac: Move interrupt request after everything is set
      up
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72124
    - can: isotp: serialize TX state transitions under so->rx_lock
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72125
    - can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72115
    - can: bcm: track a single source interface for ANYDEV timeout/throttle
      ops
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72117
    - can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72116
    - can: bcm: fix stale rx/tx ops after device removal
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72113
    - can: bcm: add missing device refcount for CAN filter removal
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72114
    - can: bcm: validate frame length in bcm_rx_setup() for RTR replies
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72119
    - can: bcm: extend bcm_tx_lock usage for data and timer updates
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72118
    - can: bcm: fix CAN frame rx/tx statistics
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-72121
    - can: bcm: add locking when updating filter and timer values
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-68428
    - KVM: x86/mmu: Fix use-after-free on vendor module reload
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64562
    - KVM: nVMX: Hide shadow VMCS right after VMCLEAR
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-64561
    - KVM: x86: Check for invalid/obsolete root *after* making MMU pages
      available
  * Noble update: upstream stable patchset 2026-09-23 (LP: #2168026) //
    CVE-2026-53090
    - bpf: Fix ld_{abs,ind} failure path analysis in subprogs
  * test_vxlan_vnifiltering.sh from ubuntu_kselftests_net failed on linux-
    oem-6.8 (with ipv6 default rdst) (LP: #2071590)
    - selftests: net: use slowwait to make sure IPv6 setup finished
  *  ubuntu_bpf failed to build in noble (error: redefinition of
    'stack_load_preserves_const_precision') (LP: #2160493)
    - SAUCE: Revert "selftests/bpf: validate fake register spill/fill
      precision backtracking logic"
  * CVE-2026-64564
    - sctp: don't free the ASCONF's own transport in DEL-IP processing
  * Backport: "mm/gup: fix GUP-fast fallback for NULL-mapping order-0 folios"
    (LP: #2162917)
    - mm/gup: fix GUP-fast fallback for NULL-mapping order-0 folios
  * qrtr: ns: node limit of 64 breaks QRTR routing on large multi-node
    deployments (LP: #2165140)
    - net: qrtr: ns: Raise node count limit to 512
  * [UBUNTU 24.04] kernel: CPU hotplug unsupported by CPUMF (LP: #2165732)
    - s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
  * CVE-2026-68399
    - bpf: Fix UAF in sock clone early bailouts
  * CVE-2025-38563
    - perf/core: Prevent VMA split of buffer mappings
  * CVE-2025-38565
    - perf/core: Exit early on perf_mmap() fail
  * CVE-2025-38187
    - drm/nouveau: fix a use-after-free in r535_gsp_rpc_push()
  * CVE-2025-38069
    - PCI: endpoint: pci-epf-test: Fix double free that causes kernel to oops
  * CVE-2025-40014
    - objtool, spi: amd: Fix out-of-bounds stack access in amd_set_spi_freq()
  * CVE-2025-21985
    - drm/amd/display: Fix out-of-bound accesses
  * CVE-2024-56552
    - drm/xe/guc_submit: fix race around suspend_pending
  * CVE-2025-21687
    - vfio/platform: check the bounds of read/write syscalls
  * Noble update: upstream stable patchset 2026-09-14 (LP: #2167237)
    - ext4: fix fd leak in EXT4_IOC_MOVE_EXT cross-sb validation
    - mm: refactor mm_access() to not return NULL
    - Upstream stable to v6.6.146, v6.12.98, v6.6.147, v6.12.99, v6.12.100
  * Noble update: upstream stable patchset 2026-09-14 (LP: #2167237) //
    CVE-2026-64560
    - posix-cpu-timers: Prevent UAF caused by non-leader exec() race
  * Noble update: upstream stable patchset 2026-09-10 (LP: #2166995)
    - bpf, arm64: Reject out-of-range B.cond targets
    - nfsd: release layout stid on setlease failure
    - Bluetooth: btmtk: apply the common btmtk_fw_get_filename
    - Bluetooth: btmtk: Fix failed to send func ctrl for MediaTek devices.
    - Bluetooth: btmtk: Fix wait_on_bit_timeout interruption during shutdown
    - userfaultfd: gate must_wait writability check on pte_present()
    - perf: Fix dangling cgroup pointer in cpuctx backport
    - Bluetooth: btmtk: Fix btmtk.c undefined reference build error
    - device property: initialize the remaining fields of fwnode_handle in
      fwnode_init()
    - f2fs: validate orphan inode entry count
    - f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
    - f2fs: fix potential deadlock in f2fs_balance_fs()
    - f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs()
    - f2fs: fix listxattr handling of corrupted xattr entries
    - block: Avoid mounting the bdev pseudo-filesystem in userspace
    - i2c: core: fix irq domain leak on adapter registration failure
    - i2c: core: fix hang on adapter registration failure
    - i2c: core: fix NULL-deref on adapter registration failure
    - i2c: core: fix adapter debugfs creation
    - fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
    - NFSv4/flexfiles: reject zero filehandle version count
    - locking/rtmutex: Make sure we wake anything on the wake_q when we
      release the lock->wait_lock
    - bonding: fix xfrm offload feature setup on active-backup mode
    - mm/vmscan: flush deferred TLB before freeing large folios
    - perf trace beauty fcntl: Fix build with older kernel headers
    - ACPI: CPPC: Suppress UBSAN warning caused by field misuse
    - ACPI: NFIT: core: Fix possible NULL pointer dereference
    - perf/core: Detach event groups during remove_on_exec
    - arm64: sysreg: Add layout for ID_AA64MMFR4_EL1
    - virtio_net: Support dynamic rss indirection table size
    - LoongArch: Add PIO for early access before ACPI PCI root register
    - usb: gadget: function: rndis: add length check to response query
    - usb: gadget: function: rndis: add length check for header
    - iio: accel: bmc150: clamp the device-reported FIFO frame count
    - iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error
    - iio: adc: lpc32xx: Initialize completion before requesting IRQ
    - iio: adc: ti-ads124s08: Return reset GPIO lookup errors
    - iio: chemical: scd30: Cleanup initializations and fix sign-extension bug
    - iio: event: Fix event FIFO reset race
    - iio: gyro: bmg160: bail out when bandwidth/filter is not in table
    - iio: gyro: bmg160: wait full startup time after mode change at probe
    - iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ
    - iio: imu: st_lsm6dsx: deselect shub page before reading whoami
    - iio: light: al3010: fix incorrect scale for the highest gain range
    - iio: light: gp2ap002: fix runtime PM leak on read error
    - iio: light: opt3001: fix missing state reset on timeout
    - iio: light: tsl2591: return actual error from probe IRQ failure
    - iio: light: veml6030: fix channel type when pushing events
    - iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call
    - iio: temperature: ltc2983: Fix reinit_completion() called after
      conversion start
    - ALSA: virtio: Add missing 384 kHz PCM rate mapping
    - ALSA: ymfpci: check snd_ctl_new1() return value
    - ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input
      parser
    - ALSA: cmipci: check snd_ctl_new1() return value
    - ALSA: es1938: check snd_ctl_new1() return value
    - ALSA: firewire: isight: bound the sample count to the packet payload
    - ALSA: gus: check snd_ctl_new1() return value
    - ALSA: ice1712: check snd_ctl_new1() return value
    - ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()
    - ALSA: usb-audio: avoid kobject path lookup in DualSense match
    - ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put()
    - ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch
      put callbacks
    - ALSA: usb-audio: Update Babyface Pro control caches only after
      successful writes
    - ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful
      writes
    - vfio/pci: Use a private flag to prevent power state change with VFs
    - vfio/pci: Latch disable_idle_d3 per device
    - vfio/pci: Release the VGA arbiter client on register_device() failure
    - vfio/pci: Fix racy bitfields and tighten struct layout
    - vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc
    - Bluetooth: btusb: Add USB ID 2c4e:0128 for Mercusys MA60XNB
    - Bluetooth: btusb: fix use-after-free on registration failure
    - Bluetooth: btusb: fix use-after-free on marvell probe failure
    - Bluetooth: btusb: fix wakeup source leak on probe failure
    - binder: fix UAF in binder_thread_release()
    - binder: fix UAF in binder_free_transaction()
    - usb: xhci: Fix sleep in atomic context in xhci_free_streams()
    - PCI: altera: Do not dispose parent IRQ mapping
    - mm/damon/ops-common: handle extreme intervals in damon_hot_score()
    - netfilter: ipset: fix race between dump and ip_set_list resize
    - virtio-mmio: fix device release warning on module unload
    - hwrng: virtio: clamp device-reported used.len at copy_data()
    - USB: chaoskey: Fix slab-use-after-free in chaoskey_release()
    - usb: dwc3: run gadget disconnect from sleepable suspend context
    - 6lowpan: fix NHC entry use-after-free on error path
    - tipc: fix out-of-bounds read in broadcast Gap ACK blocks
    - staging: vme_user: bound slave read/write to the kern_buf size
    - smb: client: restrict implied bcc[0] exemption to responses without data
      area
    - staging: vme_user: fix location monitor leak in fake bridge
    - staging: vme_user: fix location monitor leak in tsi148 bridge
    - media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe
    - staging: media: atomisp: reduce load_primary_binaries() stack usage
    - staging: rtl8723bs: fix heap buffer overflow in
      rtw_cfg80211_set_wpa_ie()
    - staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()
    - staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop
    - staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop
    - staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and
      join_cmd_hdl()
    - staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop
    - staging: rtl8723bs: fix OOB write in HT_caps_handler()
    - crypto: amlogic - avoid double cleanup in meson_crypto_probe()
    - ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then
      SMB2_CANCEL
    - net: af_key: initialize alg_key_len for IPComp states
    - audit: Fix data races of skb_queue_len() readers on audit_queue
    - Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete
    - debugobjects: Plug race against a concurrent OOM disable
    - fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns
    - NTB: epf: Avoid calling pci_irq_vector() from hardirq context
    - io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item
    - ipv4: igmp: remove multicast group from hash table on device destruction
    - net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes
    - mfd: cros_ec: Delay dev_set_drvdata() until probe success
    - mm: shrinker: fix NULL pointer dereference in debugfs
    - netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump
    - f2fs: bound i_inline_xattr_size for non-inline-xattr inodes
    - drm/amd: Fix set but not used warnings
    - apparmor: advertise the tcp fast open fix is applied
    - nfsd: move name lookup out of nfsd4_list_rec_dir()
    - nfsd: change nfs4_client_to_reclaim() to allocate data
    - arm64: Treat HCR_EL2.E2H as RES1 when ID_AA64MMFR4_EL1.E2H0 is negative
    - arm64: Fix early handling of FEAT_E2H0 not being implemented
    - KVM: arm64: Initialize HCR_EL2.E2H early
    - arm64: Revamp HCR_EL2.E2H RES1 detection
    - arm64: sysreg: Correct sign definitions for EIESB and DoubleLock
    - iio: adc: spear: Initialize completion before requesting IRQ
    - iio: imu: inv_icm42600: fix timestamp clock period by using lower value
    - ALSA: usb-audio: Roll back quirk control caches on write errors
    - usb: typec: tcpci_rt1711h: unregister TCPCI port with devres
    - gpio: eic-sprd: use raw_spinlock_t in the irq startup path
    - netfilter: ebtables: module names must be null-terminated
    - netfilter: ebtables: terminate table name before find_table_lock()
    - Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()
    - Bluetooth: bnep: pin L2CAP connection during netdev registration
    - Bluetooth: btnxpuart: Fix out-of-bounds firmware read in
      nxp_recv_fw_req_v3()
    - Bluetooth: fix UAF in bt_accept_dequeue()
    - Bluetooth: L2CAP: validate option length before reading conf opt value
    - fs/ntfs3: fsync files by syncing parent inodes
    - fs/ntfs3: zero-fill folios beyond i_valid in ntfs_read_folio()
    - fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked()
    - coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()
    - smb/client: Fix error code in smb2_aead_req_alloc()
    - ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE
    - ksmbd: add a permission check for FSCTL_SET_ZERO_DATA
    - ksmbd: serialize QUERY_DIRECTORY requests per file
    - ksmbd: require source read access for duplicate extents
    - ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock
      cancellation
    - ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY
    - ksmbd: run set info with opener credentials
    - ksmbd: enforce FILE_READ_ATTRIBUTES on SMB_FIND_FILE_POSIX_INFORMATION
    - ksmbd: add per-handle permission check to FILE_LINK_INFORMATION
    - ksmbd: use opener credentials for delete-on-close
    - smb: client: fix query directory replay double-free
    - smb: client: fix query_info() replay double-free
    - smb: client: fix double-free in SMB2_ioctl() replay
    - smb: client: fix change notify replay double-free
    - smb: client: fix double-free in SMB2_flush() replay
    - smb: client: fix double-free in SMB2_open() replay
    - smb: client: fix double-free in SMB2_close() replay
    - smb: client: Fix next buffer leak in receive_encrypted_standard()
    - smb: client: use unaligned reads in parse_posix_ctxt()
    - smb: client: harden POSIX SID length parsing
    - smb: client: mask server-provided mode to 07777 in modefromsid
    - OPP: of: Fix potential memory leak in opp_parse_supplies()
    - firmware_loader: fix device reference leak in firmware_upload_register()
    - cpufreq: intel_pstate: Sync policy->cur during CPU offline
    - sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT
    - cpufreq: Fix hotplug-suspend race during reboot
    - cpufreq: pcc: fix use-after-free and double free in _OSC evaluation
    - posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path
    - clocksource/drivers/timer-tegra186: Fix support for multiple watchdog
      instances
    - X.509: Fix validation of ASN.1 certificate header
    - tools/mm/slabinfo: Fix trace disable logic inversion
    - tools/mm/slabinfo: fix total_objects attribute name
    - HID: wacom: stop hardware after post-start probe failures
    - HID: letsketch: fix UAF on inrange_timer at driver unbind
    - HID: lg-g15: cancel pending work on remove to fix a use-after-free
    - HID: sensor-hub: Add sensor_hub_input_attr_read_values() for multi-byte
      reads
    - hfs/hfsplus: zero-initialize buffer in hfs_bnode_read
    - nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers
    - media: mtk-jpeg: cancel workqueue on release for supported platforms
      only
    - xfs: use null daddr for unset first bad log block
    - xfs: fix unreachable BIGTIME check in dquot flush validation
    - bpf: Reject fragmented frames in devmap
    - bpf: Restore sysctl new-value from 1 to 0
    - net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()
    - usb: cdc_acm: Add quirk for Uniden BC125AT scanner
    - usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()
    - USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub
    - usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume()
    - usb: free iso schedules on failed submit
    - usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler
    - usb: gadget: udc: Fix use-after-free in gadget_match_driver
    - usb: gadget: f_printer: take kref only for successful open
    - USB: idmouse: fix use-after-free on disconnect race
    - USB: ldusb: fix use-after-free on disconnect race
    - USB: iowarrior: fix use-after-free on disconnect
    - USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD
    - USB: legousbtower: fix use-after-free on disconnect race
    - usb: sl811-hcd: disable controller wakeup on remove
    - USB: storage: include US_FL_NO_SAME in quirks mask
    - USB: misc: uss720: unregister parport on probe failure
    - usb: mtu3: unmap request DMA on queue failure
    - USB: serial: keyspan_pda: fix information leak
    - USB: serial: option: add Telit Cinterion FE990D50 compositions
    - USB: serial: digi_acceleport: fix broken rx after throttle
    - USB: serial: digi_acceleport: fix hard lockup on disconnect
    - USB: serial: digi_acceleport: fix write buffer corruption
    - USB: ulpi: fix memory leak on registration failure
    - USB: usb-storage: ene_ub6250: restore media-ready check
    - usbip: tools: support SuperSpeedPlus devices
    - usbip: vudc: fix NULL deref in vep_dequeue()
    - usb: typec: anx7411: use devm_pm_runtime_enable()
    - usb: typec: class: drop PD lookup reference
    - usb: typec: tcpm: Validate SVID index in svdm_consume_modes()
    - usb: typec: ucsi: Invert DisplayPort role assignment
    - usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt
      mode
    - usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove
    - usb: typec: ucsi: cancel pending work on system suspend
    - iio: temperature: ltc2983: Fix n_wires default bypassing rotation check
    - PCI: Always lift 2.5GT/s restriction in PCIe failed link retraining
    - udf: validate free block extents against the partition length
    - udf: validate VAT header length against the VAT inode size
    - udf: validate sparing table length as an entry count, not a byte count
    - hwrng: jh7110 - fix refcount leak in starfive_trng_read()
    - dm-ioctl: report an error if a device has no table
    - nvme-multipath: set BIO_REMAPPED on bios remapped to per-path namespace
      disks
    - btrfs: do not trim a device which is not writeable
    - partitions: aix: bound the pp_count scan to the ppe array
    - isofs: bound Rock Ridge symlink components to the SL record
    - crypto: af_alg - Remove zero-copy support from skcipher and aead
    - crypto: caam - use print_hex_dump_devel to guard key hex dumps
    - crypto: caam - use print_hex_dump_devel to guard key hex dumps again
    - crypto: ecc - Fix carry overflow in vli multiplication
    - crypto: pcrypt - restore callback for non-parallel fallback
    - crypto: drbg - Fix returning success on failure in CTR_DRBG
    - crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels
    - crypto: drbg - Fix the fips_enabled priority boost
    - crypto: qat - validate RSA CRT component lengths
    - crypto: talitos - use dma_sync_single_for_cpu() before reading
      descriptor header
    - crypto: talitos - add chaining of arbitrary number of descriptor for the
      SEC1
    - crypto: talitos - move dma unmapping code in flush_channel() into a
      standalone dma_unmap_request() function
    - crypto: talitos - move dma mapping code in talitos_submit() into a
      standalone dma_map_request() function
    - crypto: talitos - move code in current_desc_hdr() into a standalone
      function
    - crypto: talitos/hash - prepare SEC1 descriptor chaining, remove
      additional descriptor
    - crypto: talitos/hash - use descriptor chaining for SEC1 instead of
      workqueue
    - crypto: talitos/hash - drop workqueue mechanism for SEC1
    - crypto: talitos/hash - rename first_desc/last_desc to
      first_request/last_request
    - crypto: talitos/hash - remove useless wrapper
    - crypto: talitos/hash - fix SEC2 64k - 1 ahash request limitation
    - arm64: fpsimd: Fix type mismatch in sme_{save,load}_state()
    - spi: fsl-lpspi: replace dmaengine_terminate_all() with
      dmaengine_terminate_sync()
    - spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
    - EDAC/i10nm: Don't fail probing if ADXL is missing
    - watchdog: apple: Add "apple,t8103-wdt" compatible
    - tracing: Prevent out-of-bounds read in glob matching
    - NFSv4: include MAY_WRITE in open permission mask for O_TRUNC
    - module: decompress: check return value of module_extend_max_pages()
    - exfat: bound uniname advance in exfat_find_dir_entry()
    - NTB: epf: Fix request_irq() unwind in ntb_epf_init_isr()
    - KVM: VMX: Refresh GUEST_PENDING_DBG_EXCEPTIONS.BS on all injected #DBs
    - KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest
      mode
    - udmabuf: fix DMA direction mismatch in release_udmabuf()
    - i2c: core: fix adapter deregistration race
    - i2c: mpc: Fix timeout calculations
    - i2c: stm32f7: truncate clock period instead of rounding it
    - Input: synaptics-rmi4 - unregister function handlers on physical driver
      registration failure
    - Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count
    - Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
    - Input: elan_i2c - prevent division by zero and arithmetic underflow
    - Input: goodix - clamp the device-reported contact count
    - Input: iforce - bound the device-reported force-feedback effect index
    - Input: mms114 - fix touch indexing for MMS134S and MMS136
    - Input: touchwin - reset the packet index on every complete packet
    - Input: mms114 - reject an oversized device packet size
    - Input: maplemouse - fix NULL pointer dereference in open()
    - Input: mms114 - fix multi-touch slot corruption
    - Input: maple_keyb - set driver data before registering input device
    - Input: maplemouse - set driver data before registering input device
    - Input: maplecontrol - set driver data before registering input device
    - RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
    - fuse: fix device node leak in cuse_process_init_reply()
    - fuse: re-lock request before returning from fuse_ref_folio()
    - smb: client: reject overlapping data areas in SMB2 responses
    - xfs: fail recovery on a committed log item with no regions
    - xfs: resample the data fork mapping after cycling ILOCK
    - smb/server: do not require delete access for non-replacing links
    - sched/fair: Only update stats for allowed CPUs when looking for dst
      group
    - KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU
    - KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
    - nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error
      path
    - nvmet-tcp: Fix potential UAF when ddgst mismatch
    - crypto: sun4i-ss - Remove insecure and unused rng_alg
    - [Config] Remove CRYPTO_DEV_SUN4I_SS_PRNG
    - crypto: crypto4xx - Remove ahash-related code
    - bpf: Support for hardening against JIT spraying
    - x86/bugs: Enable IBPB flush on BPF JIT allocation
    - media: uvcvideo: Avoid partial metadata buffers
    - media: uvcvideo: Fix buffer sequence in frame gaps
    - media: uvcvideo: Fix sequence number when no EOF
    - dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties
    - dt-bindings: power: imx93: Add MIPI PHY power domain
    - serial: msm: Disable DMA for kernel console UART
    - serial: 8250_omap: clear rx_running on zero-length DMA completes
    - rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc
    - rxrpc: Fix leak of released call in recvmsg(MSG_PEEK)
    - afs: Fix netns teardown to cancel the preallocation charger
    - afs: fix NULL pointer dereference in afs_get_tree()
    - afs: Fix further netns teardown to cancel the preallocation charger
    - fbcon: fix NULL pointer dereference for a console without vc_data
    - clocksource/drivers/sun5i: Handle error returns from
      devm_reset_control_get_optional_exclusive()
    - drm/rockchip: Test for imported buffers with drm_gem_is_imported()
    - drm/tidss: Drop extra drm_mode_config_reset() call
    - drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch()
    - drm/radeon: fix integer overflow in radeon_align_pitch()
    - drm/radeon: fix memory leak in radeon_ring_restore() on lock failure
    - libbpf: Report error when a negative kprobe offset is specified
    - Documentation: proc: fix section numbering in table of contents
    - arm64: dts: rockchip: Fix gmac0 reset pin for NanoPi R5S
    - arm64: dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg
      warning
    - wifi: cfg80211: fix grammar in MLO group key error message
    - arm64: tegra: Fix Tegra234 MGBE PTP clock
    - dt-bindings: pinctrl: nvidia,tegra234: Add missing required block
    - drm/amdkfd: Validate CRIU-restored IDs before idr_alloc
    - driver core: use READ_ONCE() for dev->driver in dev_has_sync_state()
    - wifi: rtw89: Correct data type for scan index to avoid infinite loop
    - wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA
      buffer
    - kconfig: fix potential NULL pointer dereference in conf_askvalue
    - wifi: ath9k: fix OOB access from firmware tx status queue ID
    - ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint
    - watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH
    - watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5
    - watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register
      failure
    - media: cedrus: Fix failure to clean up hardware on probe failure
    - media: v4l2-common: Add YUV24 format info
    - pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path
    - arm64: dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc
    - arm64: dts: imx8x-colibri: Correct SODIMM PAD settings
    - vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive().
    - crypto: atmel-sha204a - fix blocking and non-blocking rng logic
    - crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve
    - crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents
    - dlm: fix add msg handle in send_queue ordered
    - nilfs2: fix backing_dev_info reference leak
    - iommu/amd: Fix a stale comment about which legacy mode is user visible
    - arm64: dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to
      host
    - arm64: dts: qcom: sm8450: Fix ICE reg size
    - drm/hisilicon/hibmc: use clock to look up the PLL value
    - evm: terminate and bound the evm_xattrs read buffer
    - thermal: hwmon: Fix critical temperature attribute removal
    - clk: scpi: Unregister child clock providers on remove
    - net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats()
    - crypto: ccp - Treat zero-length cert chain as query for blob lengths
    - spi: hisi-kunpeng: Use dev_err_probe() for host registration failure
    - net/sched: sch_htb: do not change sch->flags in htb_dump()
    - net/sched: sch_htb: annotate data-races (I)
    - ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD
    - IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier
    - RDMA/hns: Fix arithmetic overflow in calc_hem_config()
    - RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference
    - RDMA/srpt: fix integer overflow in immediate data length check
    - media: atomisp: Fix memory leak in atomisp_fixed_pattern_table()
    - firmware: arm_scmi: Read sensor config as 32-bit value
    - sysfs: clamp show() return value in sysfs_kf_read()
    - regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions
    - net/sched: sch_drr: annotate data-races around cl->deficit
    - firmware: arm_scmi: Fix OOB in scmi_power_name_get()
    - arm64: dts: qcom: sm8450: Add power-domain and iface clk for ice node
    - tracing: Bound synthetic-field strings with seq_buf
    - device property: fix fwnode reference leak in
      fwnode_graph_get_endpoint_by_id()
    - driver core: Use mod_delayed_work to prevent lost deferred probe work
    - cpufreq: Documentation: fix sampling_down_factor range
    - cpufreq: conservative: Simplify frequency limit handling
    - pwm: imx27: Fix variable truncation in .apply()
    - bus: sunxi-rsb: Always check register address validity
    - RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs
    - RDMA/rxe: Fix a use-after-free problem in rxe_mmap
    - IB/mlx4: Fix refcount leak in add_port() error path
    - RDMA/hns: Fix warning in poll cq direct mode
    - RDMA/counter: Fix incorrect port index in rdma_counter_init() error
      cleanup
    - MIPS: Fix big-endian stack argument fetching in o32 wrapper
    - MIPS: DEC: Remove do_IRQ() call indirection
    - mips: ralink: mt7621: add missing __iomem
    - mips: n64: add __iomem for writel call
    - mtd: spi-nor: Drop duplicate Kconfig dependency
    - ALSA: seq: midi: Serialize output teardown with event_input
    - pinctrl: cs42l43: Fix polarity on debounce
    - nvme-multipath: fix flex array size in struct nvme_ns_head
    - workqueue: drop spurious '*' from print_worker_info() fn declaration
    - ipv6: guard against possible NULL deref in __in6_dev_stats_get()
    - net/sched: cls_bpf: prevent unbounded recursion in offload rollback
    - drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X
      client is registered
    - drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove
    - gpu: host1x: Allow entries in BO caches to be freed
    - drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output()
    - gpu: host1x: Fix iommu_map_sgtable() return value check
    - drm/tegra: Fix iommu_map_sgtable() return value check
    - drm/nouveau/bios: specify correct display fuse register for Ampere and
      Ada
    - libbpf: Harden parse_vma_segs() path parsing
    - libbpf: Fix UAF in strset__add_str()
    - dax/kmem: account for partial discontiguous resource upon removal
    - rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc()
    - ocfs2: don't BUG_ON an invalid journal dinode
    - ocfs2: kill osb->system_file_mutex lock
    - crypto: hisilicon/qm - disable error report before flr
    - drm/msm/dp: fix HPD state status bit shift value
    - drm/msm/dp: Fix the ISR_* enum values
    - EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in
      skx_get_dimm_info
    - RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe
    - RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path
    - media: qcom: venus: drop extra padding in NV12 raw size calculation
    - media: qcom: venus: relax encoder frame/blur dimension steps on v4
    - media: qcom: venus: relax encoder frame/blur step size on v6
    - rpmsg: use generic driver_override infrastructure
    - md/raid10: reset read_slot when reusing r10bio for discard
    - RDMA/siw: bound Read Response placement to the RREAD length
    - block: skip sync_blockdev() on surprise removal in bdev_mark_dead()
    - crypto: algif_skcipher - force synchronous processing
    - crypto: crypto4xx - Remove insecure and unused rng_alg
    - crypto: hisi-trng - Remove crypto_rng interface
    - bpf: Restrict JIT predictor flush to cBPF
    - bpf: Skip redundant IBPB in pack allocator
    - bpf: Prefer packs that won't trigger an IBPB flush on allocation
    - bpf: Prefer dirty packs for eBPF allocations
    - clk: scmi: Fix clock rate rounding
    - drm/hisilicon/hibmc: move display contrl config to hibmc_probe()
    - bitops: use common function parameter names
    - media: rockchip: rga: fix too small buffer size
    - ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data
      writeback
    - ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble
    - ARM: imx3: Fix CCM node reference leak
    - HID: wiimote: Fix table layout and whitespace errors
    - ata: libata: Fix ata_exec_internal()
    - ARM: imx31: Fix IIM mapping leak in revision check
    - nvdimm/btt: Handle preemption in BTT lane acquisition
    - scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-
      channel scans"
    - scsi: pm8001: Fix error code in non_fatal_log_show()
    - scsi: ufs: Fix wrong value printed in unexpected UPIU response case
    - bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs
    - mm/fake-numa: fix under-allocation detection in uniform split
    - ext2: fix ignored return value of generic_write_sync()
    - sched: restore timer_slack_ns when resetting RT policy on fork
    - lib/test_meminit: use && for bools
    - configfs_lookup(): don't leave ->s_dentry dangling on failure
    - drm/amdgpu: set sub_block_index for mca ras sub-blocks
    - bpftool: Use libbpf error code for flow dissector query
    - perf/x86/amd/core: Always use the NMI latency mitigation
    - ocfs2: rebase copied fsdlm LVB pointers in locking_state
    - ocfs2: fix buffer head management in ocfs2_read_blocks()
    - ocfs2: reject FITRIM ranges shorter than a cluster
    - ocfs2/dlm: require a ref for locking_state debugfs open
    - ocfs2: fix race between ocfs2_control_install_private() and
      ocfs2_control_release()
    - netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures
    - netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock
    - netfilter: conntrack: revert ct extension genid infrastructure
    - netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper
      is pptp
    - IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path()
    - RDMA/irdma: Fix OOB read during CQ MR registration
    - RDMA/irdma: Initialize iwmr->access during MR registration
    - arm64: dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as
      well
    - bpf: Check tail zero of bpf_prog_info
    - bpf: Update transport_header when encapsulating UDP tunnel in lwt
    - wifi: wcn36xx: fix heap overflow from oversized firmware HAL response
    - wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO
      indication
    - wifi: wcn36xx: fix OOB read from short trigger BA firmware response
    - ALSA: seq: Fix partial userptr event expansion
    - riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe
    - ALSA: seq: Clear variable event pointer on read
    - ACPI: IPMI: Fix message kref handling on dead device
    - cpufreq: Documentation: fix conservative governor freq_step description
    - IB/mlx5: Don't take the rereg_mr fallback without a new translation
    - IB/mlx5: Properly support implicit ODP rereg_mr
    - spi: ep93xx: fix double-free of zeropage on DMA setup failure
    - firmware_loader: Fix recursive lock in device_cache_fw_images()
    - configfs: fix lockless traversals of ->s_children
    - watchdog: unregister PM notifier on watchdog unregister
    - scsi: target: Fix hexadecimal CHAP_I handling
    - scsi: target: Remove tcm_loop target reset handling
    - pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins
      34-39
    - pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins
      34-39
    - vmalloc: fix NULL pointer dereference in is_vm_area_hugepages()
    - hwspinlock: qcom: avoid uninitialized struct members
    - sched/fair: Fix cpu_util runnable_avg arithmetic
    - wifi: mt76: fix argument to ieee80211_is_first_frag()
    - wifi: mt76: mt7915: fix potential tx_retries underflow
    - wifi: mt76: mt7921: fix potential tx_retries underflow
    - btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
    - fbdev: sm501fb: Fix buffer errors in OF binding code
    - hwmon: (it87) Clamp negative values to zero in set_fan()
    - btrfs: zoned: don't account data relocation space-info in statfs free
      space
    - IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified
    - spi: meson-spifc: fix runtime PM leak on remove
    - ASoC: codecs: aw88261: fix incorrect masks for boost regs
    - vduse: hold vduse_lock across IDR lookup in open path
    - vhost/vdpa: validate virtqueue index in mmap and fault paths
    - vduse: Requeue failed read to send_list head
    - vhost/net: complete zerocopy ubufs only once
    - tools/virtio: check mmap return value in vringh_test
    - ASoC: cs35l56: Fix missing calls to wm_adsp2_remove()
    - ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails
    - bonding: 3ad: fix mux port state on oper down
    - ext4: fix kernel BUG in ext4_write_inline_data_end
    - selftests/bpf: Fix bpf_iter/task_vma test
    - cxl/test: Fix integer overflow in mock LSA bounds checks
    - cxl/test: Zero out LSA backing memory to avoid leaking to user
    - of: cpu: add check in __of_find_n_match_cpu_property()
    - bpf: Tighten cgroup storage cookie checks for prog arrays
    - s390/process: Fix kernel thread function pointer type
    - Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for
      non-serdev device
    - Bluetooth: hci: validate codec capability element length
    - Bluetooth: vhci: validate devcoredump state before side effects
    - fs: efs: remove unneeded debug prints
    - RDMA/mlx5: Remove raw RSS QP restrack tracking
    - RDMA/mlx5: Fix undefined shift of user RQ WQE size
    - RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one
    - ASoC: codecs: hdac_hdmi: Validate written enum value
    - ASoC: fsl: fsl_audmix: Validate written enum values
    - ASoC: tegra: tegra210_ahub: Validate written enum value
    - net/sched: cls_flow: Dont expose folded kernel pointers
    - net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().
    - bridge: cfm: reject invalid CCM interval at configuration time
    - sctp: validate embedded address parameter length
    - net/sched: sch_hfsc: Don't make class passive twice
    - tipc: require net admin for TIPCv2 netlink mutators
    - tipc: prevent snt_unacked underflow on CONN_ACK
    - tipc: reject inverted service ranges from peer bindings
    - cxl/test: Add check after kzalloc() memory in alloc_mock_res()
    - crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
    - crypto: cavium/cpt - fix DMA cleanup using wrong loop index
    - crypto: rng - Free default RNG on module exit
    - spi: xilinx: use FIFO occupancy register to determine buffer size
    - ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO
    - power: supply: core: fix supplied_from allocations
    - handshake: Require admin permission for DONE command
    - net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during
      peek before restoring qlen
    - net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek
      before restoring qlen
    - net: mana: initialize gdma queue id to INVALID_QUEUE_ID
    - net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check
    - bpf: Run generic devmap egress prog on private skb
    - net/mlx5: Check max_macs devlink param value against max capability
    - net: wwan: t7xx: check skb_clone in control TX
    - net: bcmgenet: Use weighted round-robin TX DMA arbitration
    - kcm: use WRITE_ONCE() when changing lower socket callbacks
    - netfilter: nf_conncount: callers must hold rcu read lock
    - ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait()
    - cifs: remove all cifs files before kill super
    - smb/client: always return a value for FS_IOC_GETFLAGS
    - selftests/bpf: Initialize operation name before use
    - bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket
    - bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
    - bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check
    - MIPS: mm: Fix out-of-bounds write in maar_res_walk()
    - powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del
    - powerpc/powernv: fix preempt count leak in
      pnv_kexec_wait_secondaries_down
    - powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus
    - KEYS: Use acquire when reading state in keyring search
    - tipc: fix UAF in tipc_l2_send_msg()
    - tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)
    - ionic: Fix check in ionic_get_link_ext_stats
    - ksmbd: fix use-after-free in same_client_has_lease()
    - mfd: cs42l43: Sanity check firmware size
    - ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write
    - net/9p: fix race condition on rdma->state in trans_rdma.c
    - staging: nvec: fix use-after-free in nvec_rx_completed()
    - coresight: cti: Fix DT filter signals silently ignored
    - coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore
    - PCI/ASPM: Don't reconfigure ASPM entering low-power state
    - PCI: Introduce named defines for PCI ROM
    - PCI: Check ROM header and data structure addr before accessing
    - x86/platform/olpc: xo15: Drop wakeup source on driver removal
    - platform/x86: xo15-ebook: Fix wakeup source and GPE handling
    - PCI: loongson: Do not ignore downstream devices on external bridges
    - bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
    - phy: phy-can-transceiver: Check driver match and driver data against
      NULL
    - mailbox: mtk-adsp: fix UAF during device teardown
    - staging: most: video: avoid double free on video register failure
    - usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
    - usb: host: max3421: Reject hub port requests for non-existent ports
    - char: tlclk: fix use-after-free in tlclk_cleanup()
    - iio: light: si1133: reset counter to prevent race condition
    - iio: light: si1133: prevent race condition on timeout
    - iio: magnetometer: ak8975: fix potential kernel stack memory leak
    - iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling
    - iio: accel: mma8452: handle I2C read error(s) in mma8452_read()
    - iio: tcs3472: power down chip on probe failure
    - clk: at91: keep securam node alive while mapping it
    - HID: logitech-hidpp: remove excess kernel-doc member in
      hidpp_scroll_counter
    - fs/ntfs3: add bounds check to run_get_highest_vcn()
    - fs/ntfs3: fix mount failure on 64K page-size kernels
    - dmaengine: imx-sdma: Refine spba bus searching in probe
    - perf: Fix off-by-one stack buffer overflow in kallsyms__parse()
    - dmaengine: qcom: gpi: set DMA_PRIVATE capability
    - dmaengine: Fix possible use after free
    - clk: qcom: a53: Corrected frequency multiplier for 1152MHz
    - pNFS/filelayout: fix cheking if a layout is striped
    - xprtrdma: Remove temp allocation of rpcrdma_rep objects
    - xprtrdma: Avoid 250 ms delay on backlog wakeup
    - xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot
    - xprtrdma: Post receive buffers after RPC completion
    - xprtrdma: Use sendctx DMA state for Send signaling
    - xprtrdma: Decouple req recycling from RPC completion
    - NFSv4/pnfs: defer return_range callbacks until after inode unlock
    - nfs: keep PG_UPTODATE clear after read errors in page groups
    - NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect
      errors
    - PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro
    - PCI: meson: Propagate devm_add_action_or_reset() failure
    - fs/ntfs3: resize log->one_page_buf when adopting on-disk page size
    - PCI: rcar-host: Remove unused LIST_HEAD(res)
    - xprtrdma: Check frwr_wp_create() during connect
    - xprtrdma: Document and assert reply-handler invariants
    - xprtrdma: Resize reply buffers before reposting receives
    - xprtrdma: Fix bcall rep leak and unbounded peek
    - xprtrdma: Sanitize the reply credit grant after parsing
    - xprtrdma: Repost Receive buffers for malformed replies
    - xprtrdma: Return sendctx slot after Send preparation failure
    - tools lib api: Fix missing null termination in filename__read_int/ull()
    - tools lib api: Fix filename__write_int() writing uninitialized stack
      data
    - tools lib api: Fix mount_overload() snprintf truncation and toupper
      range
    - PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port()
    - PCI: mediatek: Use actual physical address instead of virt_to_phys()
    - security/apparmor/apparmorfs.c: conditionally compile
      get_loaddata_common_ref()
    - apparmor: aa_label_alloc use aa_label_free on alloc failure
    - apparmor: fix rawdata_f_data implicit flex array
    - apparmor: fix potential UAF in aa_replace_profiles
    - apparmor: aa_getprocattr free procattr leak on format failure
    - apparmor: put secmark label after secid lookup
    - i3c: master: Prevent reuse of dynamic address on device add failure
    - apparmor: fix label can not be immediately before a declaration
    - sparc: led: avoid trimming a newline from empty writes
    - gpio: mlxbf3: fail probe if gpiochip registration fails
    - spi: dw: fix wrong BAUDR setting after resume
    - xfrm: Support crypto offload for inbound IPv6 ESP packets not in GRO
      path
    - xfrm: annotate data-races around xfrm_policy_count[] and
      xfrm_policy_default[]
    - xfrm: validate selector family and prefixlen during match
    - ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode
    - drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free
    - drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm
    - octeontx2-pf: Fix leak of SQ timestamp buffer on teardown
    - net: psample: fix info leak in PSAMPLE_ATTR_DATA
    - sctp: hold socket lock when dumping endpoints in sctp_diag
    - PCI: iproc: Restore .map_irq() for the platform bus driver
    - spi: rpc-if: Use correct device for hardware reinitialization on resume
    - virtio-net: fix len check in receive_big()
    - devlink: Fix parent ref leak in devl_rate_node_create()
    - flow_dissector: check device type before reading ETH_ADDRS
    - ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints
    - arm64/hw_breakpoint: reject unaligned watchpoints that would truncate
      BAS
    - thermal: intel: Fix dangling resources on thermal_throttle_online()
      failure
    - ACPI: resource: Amend kernel-doc style
    - ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone()
    - ieee802154: Remove WARN_ON() in cfg802154_pernet_exit()
    - ieee802154: fix kernel-infoleak in dgram_recvmsg()
    - md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on
      retry
    - netfilter: ipset: Fix data race between add and dump in all hash types
    - netfilter: ipset: annotate "pos" for concurrent readers/writers
    - netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash
      types
    - netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
    - netfilter: nf_reject: skip iphdr options when looking for icmp header
    - netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak
    - irqchip/crossbar: Fix parent domain resource leak
    - selftests/mm: clarify alternate unmapping in compaction_test
    - selftests/mm: allow PUD-level entries in compound testcase of hmm tests
    - selftests/mm: fix exclusive_cow test fork() handling
    - net: marvell: prestera: initialize err in prestera_port_sfp_bind
    - tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
    - net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths
    - octeontx2-af: mcs: Fix unsupported secy stats read
    - octeontx2-pf: Clear stats of all resources when freeing resources
    - octeontx2-pf: mcs: Fix mcs resources free on PF shutdown
    - rtc: abx80x: fix the RTC_VL_CLR clearing all status flags
    - rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231
    - bpf: Fix stack slot index in nospec checks
    - bpf: zero-initialize the fib lookup flow struct
    - bpf: Fix effective prog array index with BPF_F_PREORDER
    - drm/edid: fix OOB read in drm_parse_tiled_block()
    - PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0
    - PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0
    - ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs()
    - ice: fix AQ error code comparison in ice_set_pauseparam()
    - i40e: Fix i40e_debug() to use struct i40e_hw argument
    - rtc: msc313: fix NULL deref in shared IRQ handler at probe
    - ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2
      NEGOTIATE
    - ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().
    - ipv4: fib: Don't ignore error route in local/main tables.
    - bpf, lsm: Add disabled BPF LSM hook list
    - bpf: Disable xfrm_decode_session hook attachment
    - netfilter: nf_nat: avoid invalid nat_net pointer use on failed
      nf_nat_init()
    - netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
    - netfilter: nft_synproxy: stop bypassing the priv->info snapshot
    - netfilter: nft_compat: ebtables emulation must reject non-bridge targets
    - NTB: epf: Make db_valid_mask cover only real doorbell bits
    - NTB: epf: Report 0-based doorbell vector via ntb_db_event()
    - NTB: epf: Fix doorbell bitmask and IRQ vector handling
    - alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
    - alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs
    - net, bpf: check master for NULL in xdp_master_redirect()
    - net: dsa: sja1105: round up PTP perout pin duration
    - veth: fix NAPI leak in XDP enable error path
    - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
    - ipv6: fix error handling in disable_ipv6 sysctl
    - ipv6: fix error handling in ignore_routes_with_linkdown sysctl
    - ipv6: fix error handling in forwarding sysctl
    - ipv6: fix error handling in disable_policy sysctl
    - smb/client: preserve errors from smb2_set_sparse()
    - rtc: ds1307: Fix off-by-one issue with wday for rx8130
    - rtc: cmos: unregister HPET IRQ handler on probe failure
    - net: mvneta: re-enable percpu interrupt on resume
    - net: sungem: fix probe error cleanup
    - net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove
    - ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count
    - dt-bindings: net: renesas,ether: Drop example "ethernet-phy-
      ieee802.3-c22" fallback
    - tracing: probes: fix typo in a log message
    - spi: sh-msiof: abort transfers when reset times out
    - gpio: mvebu: fail probe if gpiochip registration fails
    - gpio: htc-egpio: use managed gpiochip registration
    - seg6: validate SRH length before reading fixed fields
    - qede: fix out-of-bounds check for cqe->len_list[]
    - net: enetc: check the number of BDs needed for xdp_frame
    - sctp: fix SCTP_RESET_STREAMS stream list length limit
    - MIPS: DEC: Ensure RTC platform device deregistration upon failure
    - hwmon: adm1275: Prevent reading uninitialized stack
    - hwmon: (pmbus) Fix passing events to regulator core
    - usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()
    - NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in
      pg_get_mirror_count_write
    - apparmor: check label build before no_new_privs test
    - apparmor: grab ns lock and refresh when looking up changehat child
      profiles
    - drm/amdgpu: initialize irq.lock spinlock earlier
    - dpaa2-switch: fix VLAN upper check not rejecting bridge join
    - net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy
    - net: gianfar: dispose irq mappings on probe failure and device removal
    - net/sched: sch_teql: Introduce slaves_lock to avoid race condition and
      UAF
    - bridge: stp: Fix a potential use-after-free when deleting a bridge
    - tracing/events: Fix to check the simple_tsk_fn creation
    - tracing: eprobe: read the complete FILTER_PTR_STRING pointer
    - irqchip/gic-v3-its: Fix OF node reference leak
    - irqchip/ts4800: Fix missing chained handler cleanup on remove
    - cxgb4: Fix decode strings dump for T6 adapters
    - virtio_net: disable cb when NAPI is busy-polled
    - net/sched: act_bpf: use rcu_dereference_bh() to read the filter
    - ksmbd: reject undersized DACLs before parsing ACEs
    - gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe
    - pinctrl: meson: restore non-sleeping GPIO access
    - net/sched: hhf: clear heavy-hitter state on reset
    - fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid
    - afs: Fix error code in afs_extract_vl_addrs()
    - afs: use kvfree() to free memory allocated by kvcalloc()
    - afs: Fix callback service message parsers to pass through -EAGAIN
    - afs: Fix vllist leak
    - afs: Fix the volume AFS_VOLUME_RM_TREE is set on
    - afs: Fix unchecked-length string display in debug statement
    - minix: avoid overflow in bitmap block count calculation
    - ata: sata_gemini: unwind clocks on IDE pinctrl errors
    - HID: picolcd: prevent NULL pointer dereference in
      picolcd_send_and_wait()
    - HID: core: Fix OOB read in hid_get_report for numbered reports
    - arm64/mm: convert READ_ONCE(*ptep) to ptep_get(ptep)
    - arm64/mm: convert set_pte_at() to set_ptes(..., 1)
    - arm64/mm: convert ptep_clear() to ptep_get_and_clear()
    - arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range()
    - selftests/hid: convert the hid_bpf selftests with struct_ops
    - selftests/hid: Cover hid_bpf_get_data() size overflow
    - net: usb: net1080: validate packet_len before pad-byte access in
      rx_fixup
    - gue: validate REMCSUM private option length
    - netfilter: xt_u32: reject invalid shift counts
    - netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()
    - netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
    - netfilter: xt_connmark: reject invalid shift parameters
    - net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation
    - net/mlx5e: Fix HV VHCA stats agent registration race
    - net: microchip: vcap: fix races on the shared Super VCAP block
    - qede: fix off-by-one in BD ring consumption on build_skb failure
    - net: qualcomm: rmnet: validate MAP frame length before ingress parsing
    - net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload
    - net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
    - amt: fix size calculation in amt_get_size()
    - Bluetooth: 6lowpan: hold L2CAP conn across debugfs control
    - Bluetooth: MGMT: Fix adv monitor add failure cleanup
    - Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length
    - Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
    - ring-buffer: Fix event length with forced 8-byte alignment
    - net/tls: Consume empty data records in tls_sw_read_sock()
    - net: usb: lan78xx: move functions to avoid forward definitions
    - net: usb: lan78xx: disable VLAN filter in promiscuous mode
    - net/sched: cake: reject overhead values that underflow length
    - octeontx2-pf: check DMAC extraction support before filtering
    - ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
    - ipv6: mcast: Replace locking comments with lockdep annotations.
    - ipv6: mcast: Fix potential UAF in MLD delayed work
    - ipvs: pass parsed transport offset to state handlers
    - ipvs: use parsed transport offset in TCP state lookup
    - ipvs: fix PMTU for GUE/GRE tunnel ICMP errors
    - ipvs: ensure inner headers in ICMP errors are in headroom
    - s390/zcrypt: Remove the empty file
    - cifs: validate DFS referral string offsets
    - SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED
    - SUNRPC: pin upper rpc_clnt across the TLS connect_worker
    - dm era: fix NULL pointer dereference in metadata_open()
    - regulator: core: regulator_lock_two() should test for EDEADLK not
      EDEADLOCK
    - selftests/net: fix EVP_MD_CTX leak in tcp_mmap
    - net/mlx5: Fix L3 tunnel entropy refcount leak
    - octeontx2-af: fix VF bringup affecting PF promiscuous state
    - smb: client: fix overflow in passthrough ioctl bounds check
    - mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()
    - mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()
    - vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter
    - ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put
    - ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
    - ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get
    - ASoC: SOF: topology: validate vendor array size before parsing
    - net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
    - net: atm: reject out-of-range traffic classes in QoS validation
    - net: ife: require ETH_HLEN to be pullable in ife_decode()
    - arm64: fpsimd: Fix type mismatch in sve_{save,load}_state()
    - arm64: dts: qcom: sdm630: describe adsp_mem region properly
    - KVM: s390: pci: Fix GISC refcount leak on AIF enable failure
    - KVM: arm64: vgic: Check the interrupt is still ours before migrating it
    - KVM: s390: pci: Fix handling of AIF enable without AISB
    - KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
    - fbdev: metronomefb: fix potential memory leak in metronomefb_probe()
    - fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe()
    - fbdev: hecubafb: fix potential memory leak in hecubafb_probe()
    - fbdev: sm712: Fix operator precedence in big_swap macro
    - fbdev: radeon: fix potential memory leak in radeonfb_pci_register()
    - fbdev: i740fb: fix potential memory leak in i740fb_probe()
    - fbdev: s3fb: fix potential memory leak in s3_pci_probe()
    - fbdev: uvesafb: fix potential memory leak in uvesafb_probe()
    - fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe()
    - fbdev: carminefb: fix potential memory leak in alloc_carmine_fb()
    - fbdev: vesafb: fix memory leak in vesafb_probe()
    - fbdev: nvidia: fix potential memory leak in nvidiafb_probe()
    - fbdev: tridentfb: fix potential memory leak in trident_pci_probe()
    - ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
    - ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control
    - ASoC: mediatek: mt8192: Release reserved memory on cleanup
    - ASoC: mediatek: mt8183: Release reserved memory on cleanup
    - ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback
    - netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
    - netfilter: nfnl_cthelper: apply per-class values when updating policies
    - netfilter: xt_cluster: reject template conntracks in hash match
    - netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst
    - netfilter: nf_nat_sip: reload possible stale data pointer
    - netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6
      defrag
    - netfilter: nf_conncount: fix zone comparison in tuple dedup
    - netfilter: ecache: fix inverted time_after() check
    - netfilter: xt_nat: reject unsupported target families
    - netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
    - gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error
      path
    - soc: ti: k3-ringacc: Fix access mode for
      k3_ringacc_ring_pop_tail_io/proxy
    - soc: fsl: qe: panic on ioremap() failure in qe_reset()
    - selinux: check connect-related permissions on TCP Fast Open
    - leds: uleds: Fix potential buffer overread
    - mfd: sm501: Fix reference leak on failed device registration
    - tools/power/x86/intel-speed-select: Harden daemon pidfile open
    - x86/boot: Validate console=uart8250 baud rate to fix early boot hang
    - x86/boot: Reject too long acpi_rsdp= values
    - perf/x86/amd/lbr: Fix kernel address leakage
    - s390/perf_cpum_cf: Add missing array_index_nospec() to
      __hw_perf_event_init()
    - batman-adv: gw: acquire ethernet header only after skb realloc
    - batman-adv: access unicast_ttvn skb->data only after skb realloc
    - batman-adv: dat: acquire ARP hw source only after skb realloc
    - batman-adv: bla: reacquire gw address after skb realloc
    - batman-adv: dat: ensure accessible eth_hdr proto field
    - batman-adv: dat: fix tie-break for candidate selection
    - batman-adv: tt: avoid request storms during pending request
    - batman-adv: fix VLAN priority offset
    - batman-adv: frag: free unfragmentable packet
    - batman-adv: frag: fix primary_if leak on failed linearization
    - batman-adv: tt: prevent TVLV OOB check overflow
    - cifs: invalidate cfid on unlink/rename/rmdir
    - mfd: tps6586x: Fix OF node refcount
    - HID: playstation: validate num_touch_reports in DualShock 4 reports
    - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready
    - Bluetooth: SCO: hold sk properly in sco_conn_ready
    - jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit()
    - nvdimm/btt: Free arenas on btt_init() error paths
    - nvdimm/btt: Free arena sub-allocations on discover_arenas() error path
    - sunrpc: pin svc_xprt across the asynchronous TLS handshake callback
    - sunrpc: wait for in-flight TLS handshake callback when cancel loses race
    - lockd: Plug nlm_file leak when nlm_do_fopen() fails
    - lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure
    - SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
    - remoteproc: qcom: Fix leak when custom dump_segments addition fails
    - MIPS: ip22-gio: fix gio device memory leak
    - MIPS: ip22-gio: fix kfree() of static object
    - MIPS: ip22-gio: fix device reference leak in probe
    - MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf()
    - power: supply: cpcap-battery: Fix missing nvmem_device_put() causing
      reference leak
    - mm/damon/core: make charge_addr_from aware of end-address exclusivity
    - fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename
    - fs/ntfs3: bound DeleteIndexEntryAllocation memmove length
    - fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass
    - fs/ntfs3: bound attr_off in UpdateResidentValue against data_off
    - fs/ntfs3: validate lcns_follow in log_replay conversion
    - fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
    - fs/ntfs3: bound NTFS_DE view.data_off in
      UpdateRecordData{Root,Allocation}
    - ntfs3: cap RESTART_TABLE free-chain walker at rt->used
    - ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head
    - ntfs3: validate split-point offset in indx_insert_into_buffer
    - ntfs3: fix out-of-bounds read in decompress_lznt
    - power: supply: charger-manager: fix refcount leak in is_full_charged()
    - mips: sched: Fix CPUMASK_OFFSTACK memory corruption
    - riscv: cacheinfo: Fix node reference leak in populate_cache_leaves
    - mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs()
    - mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error
    - proc: only bump parent nlink when registering directories
    - mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE
    - mtd: slram: remove failed entries from the device list
    - 9p: skip nlink update in cacheless mode to fix WARN_ON
    - scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished()
    - scsi: sas: Skip opt_sectors when DMA reports no real optimization hint
    - ocfs2: use kzalloc for quota recovery bitmap allocation
    - mtd: rawnand: pl353: fix probe resource allocation
    - net/9p: fix infinite loop in p9_client_rpc on fatal signal
    - mtd: rawnand: fix condition in 'nand_select_target()'
    - ocfs2: avoid moving extents to occupied clusters
    - ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits
    - ocfs2: add journal NULL check in ocfs2_checkpoint_inode()
    - ocfs2: reject dinodes with non-canonical i_mode type
    - ocfs2: reject dinodes whose i_rdev disagrees with the file type
    - ocfs2: reject non-inline dinodes with i_size and zero i_clusters
    - fpga: dfl: add bounds check in dfh_get_param_size()
    - bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path
    - net: thunderbolt: Fix frags[] overflow by bounding frame_count
    - fpga: microchip-spi: fix zero header_size OOB read in
      mpf_ops_parse_header()
    - mtd: spi-nor: swp: Improve locking user experience
    - mtd: maps: vmu-flash: fix NULL pointer dereference in initialization
    - irqchip/crossbar: Use correct index in crossbar_domain_free()
    - tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat()
    - dmaengine: tegra: Fix burst size calculation
    - dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and
      ABORT_INT_MASK
    - platform/x86/amd/pmc: Check for intermediate wakeup in function
    - platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops
    - platform/x86/amd/pmc: Add delay_suspend module parameter
    - smb: client: use kvzalloc() for megabyte buffer in simple fallocate
    - ksmbd: fix integer overflow in set_file_allocation_info()
    - hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig
    - i2c: mediatek: fix WRRD for SoCs without auto_restart option
    - i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource()
    - ice: fix ice_init_link() error return preventing probe
    - xen/gntdev: fix error handling in ioctl
    - xfrm: use compat translator only for u64 alignment mismatch
    - net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
    - xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for
      changelink
    - tpm: fix event_size output in tpm1_binary_bios_measurements_show
    - tpm: Make the TPM character devices non-seekable
    - time: Fix off-by-one in compat settimeofday() usec validation
    - spi: uniphier: Fix completion initialization order before
      devm_request_irq()
    - sctp: validate STALE_COOKIE cause length before reading staleness
    - nvmet-rdma: handle inline data with a nonzero offset
    - can: esd_usb: kill anchored URBs before freeing netdevs
    - can: isotp: use unconditional synchronize_rcu() in isotp_release()
    - can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF
    - can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure
    - can: bcm: add missing rcu list annotations and operations
    - bpf,fork: wipe ->bpf_storage before bailouts that access it
    - bpf: Add missing access_ok call to copy_user_syms
    - net: sparx5: unregister blocking notifier on init failure
    - dm thin metadata: fix superblock refcount leak on snapshot shadow
      failure
    - dm thin metadata: fix metadata snapshot consistency on commit failure
    - dm era: fix out-of-bounds memory access for non-zero start sector
    - dm-bufio: fix wrong count calculation in dm_bufio_issue_discard
    - dm-ioctl: fix a possible overflow in list_version_get_info
    - dm-log: fix a bitset_size overflow on 32bit machines
    - dm-stats: fix dm_jiffies_to_msec64
    - dm-stats: fix merge accounting
    - dm_early_create: fix freeing used table on dm_resume failure
    - dm-integrity: don't increment hash_offset twice
    - dm-verity: fix a possible NULL pointer dereference
    - dm-verity: increase sprintf buffer size
    - scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path
    - scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()
    - scsi: sg: Report request-table problems when any status is set
    - scsi: xen: scsiback: Free the command tag on the TMR submit-failure path
    - scsi: xen: scsiback: Free unsubmitted command instead of double-putting
      it
    - scsi: target: Bound PR-OUT TransportID parsing to the received buffer
    - scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
    - scsi: elx: efct: Fix refcount leak in efct_hw_io_abort()
    - scsi: elx: efct: Fix I/O leak on unsupported additional CDB
    - Input: ims-pcu - fix use-after-free and double-free in disconnect
    - Input: ims-pcu - release data interface on disconnect
    - Input: ims-pcu - validate control endpoint type
    - Input: ims-pcu - add response length checks
    - Input: ims-pcu - fix DMA mapping violation in line setup
    - Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging
    - Input: ims-pcu - fix potential infinite loop in CDC union descriptor
      parsing
    - Input: ims-pcu - fix race condition in reset_device sysfs callback
    - Input: ims-pcu - fix type confusion in CDC union descriptor parsing
    - net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete
    - posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()
    - cpu: hotplug: Preserve per instance callback errors
    - cpu: hotplug: Bound hotplug states sysfs output
    - gpio-f7188x: Add support for NCT6126D version B
    - gpios: palmas: add .get_direction() op
    - net: sit: require CAP_NET_ADMIN in the device netns for changelink
    - net: wwan: t7xx: destroy DMA pool on CLDMA late init failure
    - net: ixp4xx_hss: fix duplicate HDLC netdev allocation
    - net/sched: act_ct: preserve tc_skb_cb across defragmentation
    - net: ena: clean up XDP TX queues when regular TX setup fails
    - net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
    - net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
    - net: ipip: require CAP_NET_ADMIN in the device netns for changelink
    - net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
    - ieee802154: admin-gate legacy LLSEC dump operations
    - ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation
    - ieee802154: ca8210: fix cas_ctl leak on spi_async failure
    - ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit
    - net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants
    - batman-adv: retrieve ethhdr after potential skb realloc on RX
    - batman-adv: ensure minimal ethernet header on TX
    - batman-adv: clean untagged VLAN on netdev registration failure
    - LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()
    - espintcp: use sk_msg_free_partial to fix partial send
    - bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()
    - rtc: mpfs: fix counter upload completion condition
    - hwmon: (w83627hf) remove VID sysfs files on error and remove
    - hwmon: (w83793) remove vrm sysfs file on probe failure
    - net: liquidio: fix BAR resource leak on PF number failure
    - hwmon: (occ) unregister sysfs devices outside occ lock
    - fsl/fman: Free init resources on KeyGen failure in fman_init()
    - net: lan743x: Initialize eth_syslock spinlock before use
    - net/sched: sch_multiq: Replace direct dequeue call with peek and
      qdisc_dequeue_peeked
    - net/sched: sch_taprio: Replace direct dequeue call with peek and
      qdisc_dequeue_peeked
    - tracing/probes: Fix double addition of offset for @+FOFFSET
    - orangefs: keep the readdir entry size 64-bit in fill_from_part()
    - ata: pata_pxa: Fix DMA channel leak on probe error
    - net: wwan: iosm: bound device offsets in the MUX downlink decoder
    - hwmon: (asus_atk0110) Check package count before accessing element
    - riscv: probes: save original sp in rethook trampoline
    - s390/monwriter: Reject buffer reuse with different data length
    - mac802154: remove interfaces with RCU list deletion
    - llc: fix SAP refcount leak in llc_ui_autobind()
    - ipvs: use parsed transport offset in SCTP state lookup
    - ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
    - macsec: don't read an unset MAC header in macsec_encrypt()
    - drbd: reject data replies with an out-of-range payload size
    - riscv: Prevent NULL pointer dereference in machine_kexec_prepare()
    - tracing/osnoise: Call synchronize_rcu() when unregistering
    - cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed
    - pmdomain: imx: Fix i.MX8MP power notifier
    - pmdomain: imx: Fix i.MX8MP VC8000E power up sequence
    - powerpc/pseries: fix memory leak on krealloc failure in papr_init
    - wifi: rt2x00: avoid full teardown before work setup in probe
    - wifi: mac80211: fix memory leak in ieee80211_register_hw()
    - regulator: ltc3676: Fix incorrect IRQSTAT bit offsets
    - Bluetooth: btrtl: validate firmware patch bounds
    - llc: fix SAP refcount leak when creating incoming sockets
    - macsec: fix promiscuity refcount leak in macsec_dev_open()
    - memstick: ms_block: reject a card that reports too many blocks
    - ipvs: fix more places with wrong ipv6 transport offsets
    - ipvs: reload ip header after head reallocation
    - reset: sunxi: fix memory region leak on ioremap failure
    - powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()
    - wifi: mac80211: free ack status frame on TX header build failure
    - wifi: mwifiex: fix permanently busy scans after multiple roam iterations
    - mtd: onenand: samsung: report DMA completion timeouts
    - mtd: mchp23k256: use SPI match data for chip caps
    - mmc: vub300: defer reset until cmd_mutex is unlocked
    - mtd: rawnand: fsl_ifc: return errors for failed page reads
    - mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout
    - mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout
    - perf/x86/amd/brs: Fix kernel address leakage
    - ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup
    - ACPI: bus: Introduce devm_acpi_install_notify_handler()
    - ACPI: NFIT: core: Use devm_acpi_install_notify_handler()
    - ACPI: NFIT: core: Fix possible deadlock and missing notifications
    - iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ
    - iio: hid-sensor-rotation: Fix stale or zero output when reading raw
      values
    - iio: invensense: remove redundant initialization of variable period
    - iio: invensense: fix timestamp glitches when switching frequency
    - iio: imu: inv_icm42600: stabilized timestamp in interrupt
    - iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading
    - iio: pressure: mpl115: fix runtime PM leak on read error
    - bitops: make BYTES_TO_BITS() treewide-available
    - iio: common: st_sensors: honour channel endianness in read_axis_data
    - ALSA: aoa: check snd_ctl_new1() return value
    - PCI: altera: Fix resource leaks on probe failure
    - vfio/mlx5: Fix racy bitfields and tighten struct layout
    - PCI: imx6: Fix IMX6SX_GPR12_PCIE_TEST_POWERDOWN handling
    - PCI: controller: Use dev_fwnode() instead of of_fwnode_handle()
    - PCI: mediatek: Convert bool to single quirks entry and bitmap
    - PCI: mediatek: Use generic MACRO for TPVPERL delay
    - PCI: mediatek: Fix IRQ domain leak when port fails to enable
    - PCI: Prevent resource tree corruption when BAR resize fails
    - PCI: Free saved list without holding pci_bus_sem
    - PCI: Fix restoring BARs on BAR resize rollback path
    - PCI: Add kerneldoc for pci_resize_resource()
    - PCI: Move Resizable BAR code to rebar.c
    - PCI: Skip Resizable BAR restore on read error
    - staging: rtl8723bs: core: move constants to right side in comparison
    - staging: rtl8723bs: fix spaces around binary operators
    - staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(),
      rtw_get_wapi_ie(), and rtw_get_wps_attr()
    - crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()
    - Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
    - mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()
    - coresight: etb10: restore atomic_t for shared reading state
    - gpio: sch: use raw_spinlock_t in the irq startup path
    - media: nxp: imx8-isi: Convert to platform remove callback returning void
    - media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code
    - media: nxp: imx8-isi: Fix use-after-free on remove
    - netfilter: ebtables: Use vmalloc_array() to improve code
    - netfilter: ebtables: zero chainstack array
    - Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
    - Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister
    - Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()
    - smb: client: Improve unlocking of a mutex in cifs_get_swn_reg()
    - smb: client: resolve SWN tcon from live registrations
    - ksmbd: use opener credentials for FSCTL mutations
    - ksmbd: centralize ksmbd_conn final release to plug transport leak
    - ksmbd: track the connection owning a byte-range lock
    - proc: rename proc_setattr to proc_nochmod_setattr
    - proc: protect ptrace_may_access() with exec_update_lock (FD links)
    - writeback: fix race between cgroup_writeback_umount() and
      inode_switch_wbs()
    - perf/x86/intel/uncore: Defer ADL global PMON enable to enable_box()
    - HID: add haptics page defines
    - HID: multitouch: fix out-of-bounds bit access on mt_io_flags
    - mm/slab: do not limit zeroing to orig_size when only red zoning is
      enabled
    - seqlock: Introduce scoped_seqlock_read()
    - seqlock: Change do_task_stat() to use scoped_seqlock_read()
    - proc: protect ptrace_may_access() with exec_update_lock (part 1)
    - treewide: Switch/rename to timer_delete[_sync]()
    - HID: appleir: fix UAF on pending key_up_timer in remove()
    - serial: 8250_mid: Disable DMA for selected platforms
    - hfs/hfsplus: prevent getting negative values of offset/length
    - hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length
    - bpf: Consistently use bpf_rcu_lock_held() everywhere
    - bpf: Allow LPM map access from sleepable BPF programs
    - usb: iowarrior: remove inherent race with minor number
    - usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()
    - usb: typec: tcpm: Fix VDM type for Enter Mode commands
    - crypto: atmel - Drop explicit initialization of struct
      i2c_device_id::driver_data to 0
    - crypto: atmel-sha204a - drop hwrng quality reduction for ATSHA204A
    - usb: gadget: f_fs: initialize reset_work at allocation time
    - nvmet: return DHCHAP status codes from nvmet_setup_auth()
    - nvmet-auth: validate reply message payload bounds against transfer
      length
    - usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile
    - btrfs: check and set EXTENT_DELALLOC_NEW before clearing EXTENT_DELALLOC
    - crypto: qat - fix restarting state leak on allocation failure
    - audit: add audit_log_nf_skb helper function
    - audit: fix potential integer overflow in audit_log_n_hex()
    - regulator: scmi: Simplify with scoped for each OF child loop
    - regulator: scmi: fix of_node refcount leak in scmi_regulator_probe()
    - mm: do file ownership checks with the proper mount idmap
    - exfat: move free cluster out of exfat_init_ext_entry()
    - exfat: remove unnecessary read entry in __exfat_rename()
    - exfat: rename argument name for exfat_move_file and exfat_rename_file
    - exfat: add exfat_get_dentry_set_by_ei() helper
    - exfat: move exfat_chain_set() out of __exfat_resolve_path()
    - exfat: preserve benign secondary entries during rename and move
    - btrfs: fix false IO failure after falling back to buffered write
    - btrfs: fix incorrect buffered IO fallback for append direct writes
    - Bluetooth: hci_core: Enable buffer flow control for SCO/eSCO
    - Bluetooth: separate CIS_LINK and BIS_LINK link types
    - Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()
    - KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers
    - seqlock: fix scoped_seqlock_read kernel-doc
    - Bluetooth: hci_core: Remove check of BDADDR_ANY in
      hci_conn_hash_lookup_big_state
    - Bluetooth: hci_sync: Fix attempting to send HCI_Disconnect to BIS handle
    - Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote
      netdev
    - selftests/hid: ensure CKI can compile our new tests on old kernels
    - Bluetooth: btmtk: Fix btmtk.c undefined reference build error harder
    - Bluetooth: btmtk: remove #ifdef around declarations
    - writeback: drop now-unnecessary rcu_barrier() in
      cgroup_writeback_umount()
    - jiffies: Define secs_to_jiffies()
    - jiffies: Cast to unsigned long in secs_to_jiffies() conversion
    - driver core: Fix missing jiffies conversion in
      deferred_probe_extend_timeout()
    - driver core: Guard deferred probe timeout extension with
      delayed_work_pending()
    - tools/testing: add linux/args.h header and fix radix, VMA tests
    - selftests/bpf: Add simple strscpy() implementation
    - bcachefs: avoid truncating fiemap extent length
    - gpio: rockchip: change the GPIO version judgment logic
    - gpio: rockchip: teardown bugs and resource leaks
    - gpio: rockchip: fix generic IRQ chip leak on remove
    - NFSv4/flexfiles: Remove cred local variable dependency
    - iio: resolver: ad2s1210: notify trigger and clear state on fault read
      error
    - iio: temperature: Build mlx90635 with CONFIG_MLX90635
    - vfio: Remove device debugfs before releasing devres
    - PCI: loongson: Override PCIe bridge supported speeds for Loongson-3C6000
      series
    - netpoll: fix a use-after-free on shutdown path
    - mm: shrinker: fix shrinker_info teardown race with expansion
    - NFSv4/flexfiles: Add data structure support for striped layouts
    - mm/khugepaged: write all dirty file folios when collapsing
    - platform/x86: intel-hid: Protect ACPI notify handler against recursion
    - Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled
    - Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync()
    - fs/ntfs3: rename ni_readpage_cmpr into ni_read_folio_cmpr
    - ksmbd: use __GFP_RETRY_MAYFAIL
    - ksmbd: use opener credentials for ADS I/O
    - cpufreq: Make cpufreq_driver->exit() return void
    - cpufreq: qcom-cpufreq-hw: Fix possible double free
    - nvme: target: rdma: fix ndev refcount leak on queue connect
    - nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
    - crypto: qat - keep VFs enabled during reset
    - crypto: qat - notify fatal error before AER reset preparation
    - crypto: qat - protect service table iterations with service_lock
    - selftests/mm: pagemap_ioctl: use the correct page size for
      transact_test()
    - iommufd: Set upper bounds on cache invalidation entry_num and entry_len
    - iommu/amd: Don't split flush for amd_iommu_domain_flush_all()
    - dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning
    - i2c: core: fix adapter probe deferral loop
    - xfs: fix null pointer dereference in tracepoint
    - xfs: don't wrap around quota ids in dqiterate
    - xfs: clamp timestamp nanoseconds correctly
    - xfs: don't zap bmbt forks if they are MAXLEVELS tall
    - iommu/vt-d: Clear Present bit before tearing down context entry
    - iommu: Pass old domain to set_dev_pasid op
    - iommu/vt-d: Cleanup intel_context_flush_present()
    - iommu/vt-d: Clear Present bit before tearing down scalable-mode context
      entry
    - vsock/virtio: bind uarg before filling zerocopy skb
    - iommu/amd: Use maximum Event log buffer size when SNP is enabled on
      Family 0x19
    - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family
      0x19
    - net: dropreason: Gather SOCKET_ drop reasons.
    - af_unix: Set drop reason in unix_release_sock().
    - af_unix: Set drop reason in manage_oob().
    - af_unix: Set drop reason in unix_stream_read_skb().
    - af_unix/scm: fix whitespace errors
    - af_unix: Don't hold unix_state_lock() in __unix_dgram_recvmsg().
    - af_unix: Don't check SOCK_DEAD in unix_stream_read_skb().
    - af_unix: Don't use skb_recv_datagram() in unix_stream_read_skb().
    - af_unix: Drop all SCM attributes for SOCKMAP.
    - time/jiffies: Change register_refined_jiffies() to void __init
    - media: uvcvideo: Fix dev_sof filtering in hw timestamp
    - media: uvcvideo: Relax the constrains for interpolating the hw clock
    - media: uvcvideo: Do not add clock samples with small sof delta
    - serial: max310x: replace bare use of 'unsigned' with 'unsigned int'
      (checkpatch)
    - serial: max310x: implement gpio_chip::get_direction()
    - drm/gpuvm: Do not prepare NULL objects
    - selftests/bpf: Use local type for bpf_fou_encap in test_tunnel_kern
    - soc: xilinx: Shutdown and free rx mailbox channel
    - crypto: qat - fix heartbeat error injection
    - memory: tegra: Wire up system sleep PM ops
    - drm/gpuvm: take refcount on DRM device
    - ARM: multi_v7_defconfig: Correct QCOM_RPMH and QCOM_RPMHPD
    - RDMA/hns: Initialize seqfile before creating file
    - selftests/bpf: Reject unsupported -k option in vmtest.sh
    - media: atomisp: gc2235: fix UAF and memory leak
    - staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy()
    - arm64: dts: qcom: sm8650: Add power-domain and iface clk for ice node
    - Revert "treewide: Fix probing of devices in DT overlays"
    - RDMA/hns: Fix log flood after cmd_mbox failure
    - net: introduce page_frag_cache_drain()
    - nvmet-tcp: fix page fragment cache leak in error path
    - amba: use generic driver_override infrastructure
    - cdx: use generic driver_override infrastructure
    - Drivers: hv: vmbus: use generic driver_override infrastructure
    - driver core: Use system_percpu_wq instead of system_wq
    - tick/sched: Fix TOCTOU in nohz idle time fetch
    - vhost: fix vhost_get_avail_idx for a non empty ring
    - perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems
    - x86/cpu/amd: Provide a separate accessor for Node ID
    - perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains
    - xfrm: fix NAT-related field inheritance in SA migration
    - netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing
      helper flags
    - netfilter: synproxy: drop packets if timestamp adjustment fails
    - netfilter: synproxy: adjust duplicate timestamp options
    - netfilter: synproxy: fix unaligned memory access in timestamp adjustment
    - RDMA/siw: Fix endpoint/socket association handling
    - riscv: cpu_ops: Change return value type of cpu_is_stopped() to bool
    - wifi: mt76: mt7925: clean up DMA on probe failure
    - wifi: mt76: mt7925: fix potential tx_retries underflow
    - wifi: mt76: mt7996: fix potential tx_retries underflow
    - btrfs: fix deadlock cloning inline extent when using flushoncommit
    - virtio_console: read size from config space during device init
    - ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT
    - Bluetooth: eir: Fix stack OOB write when prepending the Flags AD
    - Bluetooth: hci_core: Fix UAF in hci_unregister_dev()
    - net: dsa: qca8k: fix led devicename when using external mdio bus
    - ALSA: seq: Drop superfluous filter argument of get_event_dest_client()
    - ALSA: seq: Fix kernel heap address leak in bounce_error_event()
    - net: ethernet: mtk_wed: fix loading WO firmware for MT7986
    - octeontx2-af: npc: Fix size of entry2cntr_map
    - net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show()
    - dpll: add reference-sync netlink attribute
    - dpll: move xa_erase() call in to match dpll_pin_alloc() error path order
    - dpll: add reference sync get/set
    - dpll: Allow associating dpll pin with a firmware node
    - dpll: Add notifier chain for dpll events
    - dpll: Support dynamic pin index allocation
    - dpll: Enhance and consolidate reference counting logic
    - dpll: fix stale iteration in dpll_pin_on_pin_unregister()
    - dpll: send delete notification before unregister in on-pin rollback
    - dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister()
    - dpll: guard sync-pair removal on full pin unregister
    - dpll: balance create/delete notifications in __dpll_pin_(un)register
    - landlock: Fix unmarked concurrent access to socket family
    - selftests/bpf: Fix typo in verify_umulti_link_info
    - udf: fix nls leak on udf_fill_super() failure
    - mfd: rsmu: Fix page register setup
    - eventpoll: expand top-of-file overview / locking doc
    - eventpoll: rename attach_epitem() to ep_attach_file()
    - eventpoll: rename ep_remove_safe() back to ep_remove()
    - eventpoll: split ep_insert() into alloc + register stages
    - eventpoll: extract ep_deliver_event() from ep_send_events()
    - eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers
    - eventpoll: rename epi->next and txlist for clarity
    - eventpoll: Fix epoll_wait() report false negative
    - gpiolib: acpi: Only trigger ActiveBoth interrupts on boot
    - coresight: Fix source not disabled on idr_alloc_u32 failure
    - PCI: qcom: Disable ASPM L0s for SA8775P
    - dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor
    - PCI: meson: Add missing remove callback
    - xprtrdma: Fix ep kref imbalance on ADDR_CHANGE
    - Revert "PCI/MSI: Unmap MSI-X region on error"
    - apparmor: remove or add symlinks to rawdata according to export_binary
    - workqueue: Add new WQ_PERCPU flag
    - i3c: master: add WQ_PERCPU to alloc_workqueue users
    - i3c: master: Make hot-join workqueue freezable to block hot-join during
      suspend
    - xfrm: Fix xfrm state cache insertion race
    - mac802154: Prevent overwrite return code in
      mac802154_perform_association()
    - netfilter: ipset: make sure gc is properly stopped
    - mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx()
    - selftest/mm: register existing mapping with userfaultfd in hugetlb-
      mremap
    - selftests/mm: ensure destination is hugetlb-backed in hugetlb-mremap
    - selftests/mm: hugetlb_reparenting_test: do not unmount
    - selftests/mm: save and restore nr_hugepages value
    - selftests/mm: restore default nr_hugepages value via exit trap in
      charge_reserved_hugetlb.sh
    - net/sched: act_ct: fix nf_connlabels leak on two error paths
    - ipv6: annotate data-races around cnf.forwarding
    - ipv6/addrconf: annotate data-races around devconf fields (II)
    - ipv6: ndisc: fix NULL deref in accept_untracked_na()
    - dpaa2-switch: do not accept VLAN uppers while bridged
    - bpftool: Fix vmlinux BTF leak in cgroup commands
    - ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info
    - ice: dpll: fix memory leak in ice_dpll_init_info error paths
    - net: bnxt: use ethtool string helpers
    - eth: bnxt: gather and report HW-GRO stats
    - eth: bnxt: rename ring_err_stats -> ring_drv_stats
    - eth: bnxt: improve the timing of stats
    - md/raid5: use stripe state snapshot in break_stripe_batch_list()
    - md/raid5: avoid R5_Overlap races while breaking stripe batches
    - gpio: davinci: fix IRQ domain leak on devm_kzalloc failure
    - ipv6: Add __in6_dev_get_rtnl_net().
    - octeontx2-af: Validate NIX maximum LFs correctly
    - udp_tunnel: remove rtnl_lock dependency
    - net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync
    - net: hisilicon: hns3: use ethtool string helpers
    - net: hns3: use string choices helper
    - net: hns3: use hns3_get_ae_dev() helper to reduce the unnecessary middle
      layer conversion
    - net: hns3: use hns3_get_ops() helper to reduce the unnecessary middle
      layer conversion
    - net: hns3: clear hns alarm: comparison of integer expressions of
      different signedness
    - net: hns3: unify copper port ksettings configuration path
    - net: hns3: refactor MAC autoneg and speed configuration
    - net: hns3: fix permanent link down deadlock after reset
    - net: hns3: differentiate autoneg default values between copper and fiber
    - rtnetlink: Add per-netns RTNL.
    - [Config] Set CONFIG_DEBUG_NET_SMALL_RTNL=n
    - rtnetlink: Add assertion helpers for per-netns RTNL.
    - rtnetlink: Define rtnl_net_trylock().
    - ipv6: Convert net.ipv6.conf.${DEV}.XXX sysctl to per-netns RTNL.
    - ipv6: fix missing notification for ignore_routes_with_linkdown
    - ACPI: processor_idle: Mark LPI enter functions as __cpuidle
    - afs: Remove erroneous seq |= 1 in volume lookup loop
    - afs: Make /afs/.<cell> as well as /afs/<cell> mountpoints
    - afs: Add rootcell checks
    - afs: Make /afs/@cell and /afs/. at cell symlinks
    - afs: Fix afs_atcell_get_link() to handle RCU pathwalk
    - afs: Remove the "autocell" mount option
    - afs: Change dynroot to create contents on demand
    - afs: Fix misplaced inc of net->cells_outstanding
    - afs: Fix missing NULL pointer check in afs_break_some_callbacks()
    - ovl: fix comment about locking order
    - ata: libata-scsi: limit simulated SCSI command copy to response length
    - net/mlx5: LAG, MPESW, Fix missing complete() on devcom error
    - ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump
    - afs: Convert comma to semicolon
    - afs: Fix double netfs initialisation in afs_root_iget()
    - drm/xe: Add warn when level can not be zero.
    - drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()
    - drm/xe/hw_engine: Fix double-free of managed BO in error path
    - HID: bpf: Fix hid_bpf_get_data() range check
    - drm/v3d: Reject invalid indirect BO handle in indirect CSD setup
    - perf/x86/amd/core: Avoid enabling BRS from the SVM reload path
    - genirq/generic_chip: Introduce irq_domain_{alloc,remove}_generic_chips()
    - gpio: mvebu: free generic chips on unbind
    - netfilter: nft_lookup: fix catchall element handling with inverted
      lookups
    - drm/xe: remove duplicate <kunit/test-bug.h> include
    - LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt()
    - LoongArch: KVM: Check the return values for put_user()
    - LoongArch: KVM: Fix FPU register width with user access API
    - LoongArch: KVM: Return full old CSR value from kvm_emu_xchg_csr()
    - KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
    - fbdev: efifb: fix memory leak in efifb_probe()
    - netfilter: nft_set_pipapo: don't leak bad clone into future transaction
    - selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()
    - batman-adv: mcast: avoid OOB read of num_dests header
    - mm/memory_hotplug: fix incorrect altmap passing in error path
    - fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()
    - fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry()
    - mtd: spi-nor: spansion: use die erase for multi-die devices only
    - mtd: rawnand: Pause continuous reads at block boundaries
    - taskstats: retain dead thread stats in TGID queries
    - platform/x86: dell-laptop: fix missing cleanups in init error path
    - platform/x86/amd/pmc: Don't log during intermediate wakeups
    - NFS: Charge unstable writes by request size, not folio size
    - netdev-genl: report NAPI thread PID in the caller's pid namespace
    - dm-verity: avoid double increment of &use_bh_wq_enabled
    - dm-verity: make error counter atomic
    - accel/ivpu: Reject firmware log with size smaller than header
    - firmware_loader: introduce __free() cleanup hanler
    - Input: ims-pcu - fix firmware leak in async update
    - tracing/user_events: Fix use-after-free in user_event_mm_dup()
    - gpio: tegra: do not call pinctrl for GPIO direction
    - platform/x86/amd/pmc: Avoid logging "(null)" for DMI values
    - s390: Revert support for DCACHE_WORD_ACCESS
    - [Config] Set CONFIG_DCACHE_WORD_ACCESS=- for s390x
    - selftests: net: make busywait timeout clock portable
    - ata: libata: Use QUIRK instead of HORKAGE
    - ata: libata-core: Skip HPA resize for locked drives
    - mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe()
      method
    - ALSA: hda/cs35l41: Fix firmware load work teardown
    - io_uring/rw: ensure reissue path is correctly handled for IOPOLL
    - io_uring/rw: preserve partial result for iopoll
    - Bluetooth: L2CAP: Fix not tracking outstanding TX ident
    - mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless
      host
    - ksmbd_vfs_rename(): vfs_path_parent_lookup() accepts ERR_PTR() as name
    - vfs: make LAST_XXX private to fs/namei.c
    - ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
    - HID: pidff: Fix missing blank lines after declarations
    - HID: pidff: Add missing spaces
    - HID: pidff: Rework pidff_upload_effect
    - HID: pidff: Use correct effect type in effect update
    - bpf, arm64, powerpc: Add bpf_jit_bypass_spec_v1/v4()
    - USB: iowarrior: fix use-after-free on disconnect race
    - crypto: atmel-sha204a - fail on hwrng registration error in probe path
    - btrfs: concentrate the error handling of submit_one_sector()
    - btrfs: remove folio parameter from ordered io related functions
    - btrfs: remove the COW fixup mechanism
    - slab: Introduce kmalloc_obj() and family
    - slab: Introduce kmalloc_flex() and family
    - add default_gfp() helper macro and use it in the new *alloc_obj()
      helpers
    - default_gfp(): avoid using the "newfangled" __VA_OPT__ trick
    - slab: recognize @GFP parameter as optional in kernel-doc
    - fscrypt: Fix key setup in edge case with multiple data unit sizes
    - fscrypt: Replace mk_users keyring with simple list
    - KVM: arm64: Ensure level is always initialized when relaxing perms
    - KVM: arm64: Fix propagation of TLBI level in
      kvm_pgtable_stage2_relax_perms()
    - bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is
      uninitialized
    - rtnetlink: Make per-netns RTNL dereference helpers to macro.
    - afs: Fix afs_atcell_get_link() to check if ws_cell is unset first
    - afs: Fix afs_dynroot_readdir() to not use the RCU read lock
    - udp_tunnel: fix deadlock in udp_tunnel_nic_set_port_priv()
    - i40e: drop udp_tunnel_get_rx_info() call from i40e_open()
    - ice: drop udp_tunnel_get_rx_info() call from ndo_open()
    - Bluetooth: L2CAP: Fix regressions caused by reusing ident
    - Bluetooth: L2CAP: fix tx ident leak for commands without a response
    - dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync()
    - perf: Reject exited events as group leaders
    - serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR
      platforms
    - usb: atm: ueagle-atm: reject descriptors that confuse probe and
      disconnect
    - proc: Fix broken error paths for namespace links
    - Upstream stable to v6.6.145, v6.12.96, v6.12.97
  * Noble update: upstream stable patchset 2026-09-10 (LP: #2166995) //
    CVE-2026-53365
    - vsock/virtio: fix zerocopy completion for multi-skb sends
  * Noble update: upstream stable patchset 2026-09-10 (LP: #2166995) //
    CVE-2025-37964 -- to the 6.1, 6.6 and 6.12 trees ended up with two
    - x86/mm: Fix check/use ordering in switch_mm_irqs_off()
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192)
    - debugobjects: Allow to refill the pool before SYSTEM_SCHEDULING
    - debugobjects: Use LD_WAIT_CONFIG instead of LD_WAIT_SLEEP
    - debugobjects: Dont call fill_pool() in early boot hardirq context
    - ARM: group is_permission_fault() with is_translation_fault()
    - ARM: allow __do_kernel_fault() to report execution of memory faults
    - ARM: fix branch predictor hardening
    - RDMA/bnxt_re: zero shared page before exposing to userspace
    - selftests/bpf: Add test to ensure kprobe_multi is not sleepable
    - bpf: Remove mark_precise_scalar_ids()
    - selftests/bpf: Tests for per-insn sync_linked_regs() precision tracking
    - selftests/bpf: Update comments find_equal_scalars->sync_linked_regs
    - hv: utils: handle and propagate errors in kvp_register
    - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs
    - phonet: Pass ifindex to fill_addr().
    - phonet: Pass net and ifindex to phonet_address_notify().
    - scripts/sorttable: Remove unused macro defines
    - scripts/sorttable: Remove unused write functions
    - scripts/sorttable: Remove unneeded Elf_Rel
    - scripts/sorttable: Have the ORC code use the _r() functions to read
    - scripts/sorttable: Make compare_extable() into two functions
    - scripts/sorttable: Convert Elf_Ehdr to union
    - scripts/sorttable: Replace Elf_Shdr Macro with a union
    - scripts/sorttable: Convert Elf_Sym MACRO over to a union
    - scripts/sorttable: Add helper functions for Elf_Ehdr
    - scripts/sorttable: Add helper functions for Elf_Shdr
    - scripts/sorttable: Add helper functions for Elf_Sym
    - scripts/sorttable: Use uint64_t for mcount sorting
    - scripts/sorttable: Move code from sorttable.h into sorttable.c
    - scripts/sorttable: Get start/stop_mcount_loc from ELF file directly
    - scripts/sorttable: Use a structure of function pointers for elf helpers
    - arm64: scripts/sorttable: Implement sorting mcount_loc at boot for arm64
    - [Config] Set configs to sort mcount_loc at boot for arm64
    - scripts/sorttable: Have mcount rela sort use direct values
    - scripts/sorttable: Always use an array for the mcount_loc sorting
    - scripts/sorttable: Zero out weak functions in mcount_loc table
    - ftrace: Update the mcount_loc check of skipped entries
    - ftrace: Have ftrace pages output reflect freed pages
    - ftrace: Do not over-allocate ftrace memory
    - ftrace: Test mcount_loc addr before calling ftrace_call_addr()
    - ftrace: Check against is_kernel_text() instead of kaslr_offset()
    - scripts/sorttable: Use normal sort if theres no relocs in the mcount
      section
    - scripts/sorttable: Allow matches to functions before function entry
    - scripts/sorttable: Fix endianness handling in build-time mcount sort
    - file: add fput() cleanup helper
    - eventpoll: use hlist_is_singular_node() in __ep_remove()
    - Revert "ptp: add testptp mask test"
    - Bluetooth: btmtk: validate WMT event SKB length before struct access
    - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events
    - batman-adv: tp_meter: keep unacked list in ascending ordered
    - batman-adv: tp_meter: initialize dup_acks explicitly
    - batman-adv: tp_meter: initialize dec_cwnd explicitly
    - batman-adv: tp_meter: avoid window underflow
    - batman-adv: tp_meter: fix fast recovery precondition
    - batman-adv: tp_meter: handle seqno wrap-around for fast recovery
      detection
    - batman-adv: tp_meter: add only finished tp_vars to lists
    - batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE
    - batman-adv: prevent ELP transmission interval underflow
    - batman-adv: tp_meter: initialize last_recv_time during init
    - batman-adv: ensure bcast is writable before modifying TTL
    - batman-adv: fix (m|b)cast csum after decrementing TTL
    - batman-adv: frag: ensure fragment is writable before modifying TTL
    - batman-adv: frag: avoid underflow of TTL
    - batman-adv: tp_meter: annotate last_recv_time access with
      READ/WRITE_ONCE
    - batman-adv: tp_meter: prevent parallel modifications of last_recv
    - batman-adv: tp_meter: handle overlapping packets
    - batman-adv: tt: don't merge change entries with different VIDs
    - batman-adv: tt: track roam count per VID
    - batman-adv: dat: prevent false sharing between VLANs
    - batman-adv: tvlv: enforce 2-byte alignment
    - batman-adv: tvlv: avoid race of cifsnotfound handler state
    - inet: add indirect call wrapper for getfrag() calls
    - err.h: use __always_inline on all error pointer helpers
    - wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S
    - wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor
    - wifi: rtw88: increase TX report timeout to fix race condition
    - wifi: iwlwifi: mvm: fix race condition in PTP removal
    - f2fs: fix to round down start offset of fallocate for pin file
    - f2fs: keep atomic write retry from zeroing original data
    - MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
    - fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
    - nfsd: check get_user() return when reading princhashlen
    - NFS: Prevent resource leak in nfs_alloc_server()
    - serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero
    - wifi: mt76: mt7921: avoid undesired changes of the preset regulatory
      domain
    - ACPI: scan: Use async schedule function in acpi_scan_clear_dep_fn()
    - xfs: fix error returns in CoW fork repair
    - locking/mutex: Remove wakeups from under mutex::wait_lock
    - net: ipv6: Make udp_tunnel6_xmit_skb() void
    - Revert "PCI: qcom: Advertise Hotplug Slot Capability with no Command
      Completion support"
    - KVM: SEV: Ignore MMIO requests of length '0'
    - mtd: spi-nor: macronix: Add post_sfdp fixups for Quad Input Page Program
    - mtd: spi-nor: macronix: add support for mx66{l2, u1}g45g
    - LoongArch: Report dying CPU to RCU in stop_this_cpu()
    - MIPS: smp: report dying CPU to RCU in stop_this_cpu()
    - locking: rtmutex: Fix wake_q logic in task_blocks_on_rt_mutex
    - bonding: annotate data-races arcound churn variables
    - Upstream stable to v6.6.144, v6.12.95
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53389
    - net/tcp-ao: fix use-after-free of key in del_async path
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53393
    - nfsd: reset write verifier on deferred writeback errors
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53400
    - i2c: core: fix adapter registration race
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63806
    - KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with
      get_unaligned()
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63940
    - KVM: SEV: Ignore Port I/O requests of length '0'
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53387
    - iio: light: veml6075: add bounds check to veml6075_it_ms index
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53070
    - sctp: disable BH before calling udp_tunnel_xmit_skb()
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-43216
    - net: Drop the lock in skb_may_tx_timestamp()
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-64244
    - drivers/base/memory: set mem->altmap after successful device
      registration
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53384
    - serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53390
    - ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53391
    - NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53397
    - nfsd: fix posix_acl leak on SETACL decode failure
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53398
    - NFSD: Fix SECINFO_NO_NAME decode error cleanup
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-64245
    - fbdev: modedb: fix a possible UAF in fb_find_mode()
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53403
    - fbdev: Fix fb_new_modelist to prevent null-ptr-deref in
      fb_videomode_to_var
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-64246
    - power: reset: linkstation-poweroff: fix use-after-free in the
      linkstation_poweroff_init()
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63794
    - KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-64247
    - KVM: x86: hyper-v: Bound the bank index when querying sparse banks
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63795
    - 9p: avoid putting oldfid in p9_client_walk() error path
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63796
    - ocfs2: reject oversized group bitmap descriptors
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63797
    - rpmsg: char: Fix use-after-free on probe error path
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-64249
    - fpga: region: fix use-after-free in child_regions_with_firmware()
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63798
    - irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup
      on remove
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63800
    - pNFS: Fix use-after-free in pnfs_update_layout()
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63801
    - tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63802
    - blk-cgroup: fix UAF in __blkcg_rstat_flush()
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63803
    - hdlc_ppp: sync per-proto timers before freeing hdlc state
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63804
    - gfs2: fix use-after-free in gfs2_qd_dealloc
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63808
    - exfat: fix potential use-after-free in exfat_find_dir_entry()
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63809
    - bpf: use kvfree() for replaced sysctl write buffer
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63812
    - f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63814
    - f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63817
    - f2fs: validate compress cache inode only when enabled
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63821
    - wifi: rtw88: usb: fix memory leaks on USB write failures
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63822
    - wifi: ath11k: fix warning when unbinding
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63823
    - keys: Pin request_key_auth payload in instantiate paths
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63824
    - KEYS: fix overflow in keyctl_pkey_params_get_2()
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63826
    - fbdev: fix use-after-free in store_modes()
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-64254
    - NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG
      share BAR
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63827
    - apparmor: fix use-after-free in rawdata dedup loop
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63828
    - apparmor: mediate the implicit connect of TCP fast open sendmsg
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63830
    - net: skmsg: preserve sg.copy across SG transforms
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63831
    - mac802154: llsec: add skb_cow_data() before in-place crypto
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53361
    - af_unix: Set gc_in_progress to true in unix_gc().
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63833
    - ntfs3: reject direct userspace writes to reserved $LX* xattrs
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53366
    - ipv4: account for fraggap on the paged allocation path
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53362
    - ipv6: account for fraggap on the paged allocation path
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63834
    - batman-adv: tp_meter: restrict number of unacked list entries
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63835
    - batman-adv: v: prevent OGM aggregation on disabled hardif
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63836
    - batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-63807
    - KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping
      level
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53381
    - virtiofs: fix UAF on submount umount
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53382
    - media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53383
    - ksmbd: reject non-VALID session in compound request branch
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53385
    - vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent
      vcs_write
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53388
    - fuse: re-lock request before replacing page cache folio
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53157
    - net: phonet: free phonet_device after RCU grace period
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53163
    - locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2025-23131
    - dlm: prevent NPD when writing a positive value to event_done
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-46252
    - regulator: core: fix locking in regulator_resolve_supply() error path
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-52928
    - af_unix: Reject SIOCATMARK on non-stream sockets
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-43010
    - bpf: Reject sleepable kprobe_multi programs at attach time
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53325
    - agp/amd64: Fix broken error propagation in agp_amd64_probe()
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-64188
    - net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-64191
    - i2c: stub: Reject I2C block transfers with invalid length
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53327
    - debugobjects: Do not fill_pool() if pi_blocked_on
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-52909
    - ip6_vti: set netns_immutable on the fallback device.
  * Noble update: upstream stable patchset 2026-09-02 (LP: #2166192) //
    CVE-2026-53167
    - fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios

Date: 2026-10-01 21:47:26.094556+00:00
Changed-By: Manuel Diewald <manuel.diewald at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-nvidia-lowlatency/6.8.0-1065.68.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list