[ubuntu/resolute-proposed] linux-ibm 7.0.0-1016.16 (Accepted)
Timo Aaltonen
tjaalton at ubuntu.com
Thu Oct 1 22:13:39 UTC 2026
linux-ibm (7.0.0-1016.16) resolute; urgency=medium
* resolute/linux-ibm: 7.0.0-1016.16 -proposed tracker (LP: #2168055)
[ Ubuntu: 7.0.0-39.39 ]
* resolute/linux: 7.0.0-39.39 -proposed tracker (LP: #2168074)
* Include v4l2loopback in default modules set for 26.04 (LP: #2168012)
- [Packaging] Add dependency for v4l2loopback
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950)
- fsnotify: inotify: pass mark connector to fsnotify_recalc_mask()
- clk: qcom: gcc-mdm9607: Increase delay for USB PHY reset
- usb: f_mass_storage: Bump local buffer size in fsg_common_create_luns()
- usb: typec: qcom-pmic-typec: drain cc_debounce_dwork if port_start()
fails
- usb: typec: tcpm: constrain TCPM_SOURCING_VBUS event handling
- usb: typec: tipd: Fix Thunderbolt altmode VDOs for cd321x
- thermal/drivers/imx: Disable clock on runtime resume failure
- thermal/drivers/qoriq: Disable clock on resume failure
- userfaultfd: reset err to be 0 when move_pages_ptes succeeded
- soc: qcom: geni-se: Use HW PROG_RAM_DEPTH to validate firmware size
- spi: bcm63xx-hsspi: disable clocks on resume failure
- spi: bcm63xx: disable clock on resume failure
- spi: bcmbca-hsspi: disable clocks on resume failure
- mm/damon/vaddr-kunit: check region count in three_regions test
- samples/damon/mtier: handle damon_start() failure
- samples/damon/prcl: handle damon_start() failure
- samples/damon/prcl: stop and free damon ctx when damon_call() fails
- samples/damon/wsse: stop and free damon ctx when damon_call() fails
- mm/damon/sysfs-schemes: kobject_del() scheme action destination dirs
- mm/damon/sysfs-schemes: kobject_del() scheme dirs
- mm/damon/sysfs-schemes: kobject_del() scheme filter dirs
- mm/damon/sysfs-schemes: kobject_del() scheme quota goal dirs
- mm/damon/sysfs-schemes: kobject_del() scheme region dirs
- mm/damon/sysfs: kobject_del() region and target (error) dirs
- mm/damon/sysfs: kobject_del() target (normal), context and kdamond dirs
- mm/damon/core-kunit: check region count before testing in split_at()
- ftrace: Synchronize the initialization of ftrace_ops
- dmaengine: dw-edma: Fix HDMA channel status register access
- dmaengine: dw-edma: Complete descriptors before pausing
- cpuidle: psci: Fix support for probe deferral by dropping the faux
device
- block: flag zoned disks with GENHD_FL_NO_PART
- ata: ahci: work around lost interrupts on Marvell 88SE61xx
- irqchip/stm32mp-exti: Fix the unit of the hwspinlock timeout
- Input: aiptek - validate raw macro indices before updating state
- memcg: bypass the reclaim and oom killer for dying tasks once oom_reaper
is done
- memcg: make the v1 soft limit knob inert
- rtc: rzn1: Handle EPROBE_DEFER for optional pps interrupt
- rtc: rzn1: Fix weekday underflow when alarm crosses month boundary
- rtc: rzn1: Handle unset alarm weekday in rzn1_rtc_read_alarm
- rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers
- perf trace: Factor out BPF loop body
- perf trace: Refactor augmented_raw_syscalls using bpf_for
- perf hisi-ptt: Fix PTT trace TLP header parsing
- i2c: designware: Enable interrupt mask workaround for HJMC3001
- i2c: qcom-geni: update frequency table to fix timing parameters
- arm64: mm: Fix the lockless page-table walk in show_pte()
- arm64: errata: pass REVIDR when matching target implementation CPUs
- ALSA: rawmidi: Return the error from snd_rawmidi_input_params()
- pmdomain: airoha: fix unselectable AIROHA_CPU_PM_DOMAIN kconfig
- Revert "irqchip/mbigen: Fix mbigen node address layout"
- mm/hugetlb: fix missing migratable flag on same-node hugetlb migration
- mm/hugetlb: keep max_huge_pages when dissolving surplus folios
- mm/hugetlb_cgroup: call page_counter_set_max() outside VM_BUG_ON()
- parisc: Fix alignment of asm statements in head.S
- powerpc/pseries: Handle and log pseries-wdt registration failures
- powerpc/pseries: Move H_WATCHDOG definitions to a common header
- powerpc/crash: stop watchdogs before booting kdump kernel
- s390/vfio-ap: Fix stale do_remove flag across iterations in
vfio_ap_mdev_cfg_remove
- s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap
- s390/vfio-ap: Fix required lock not held during update of ap_matrix_mdev
object
- mtd: nand: realtek-ecc: add missing MODULE_DEVICE_TABLE()
- batman-adv: mcast: ensure unshared skb for multicast packets
- batman-adv: bla: prevent CRC corruptions after claim flush
- clk: clocking-wizard: fix integer overflow in rate calculation
- clk: mediatek: mt8196: Select REGMAP_MMIO for vlpckgen
- clk: qcom: gcc-msm8916: Fix enable_reg for gcc_blsp1_sleep_clk
- clk: qcom: gcc-msm8939: Fix enable_reg for gcc_blsp1_sleep_clk
- clk: rockchip: rk3588: Don't change PLL rates when setting dclk_vop2_src
- clk: qcom: gcc-mdm9607: Drop incorrect apss_tcu_clk_src
- clk: qcom: gcc-mdm9607: Drop incorrect system_noc_bfdcd_clk_src
- clk: qcom: gcc-mdm9607: Fix enable_reg for gcc_blsp1_sleep_clk
- clk: qcom: gcc-mdm9607: Fix halt_reg for gcc_apss_axi_clk
- clk: qcom: gcc-mdm9607: Drop incorrect BIMC PLL and related clocks
- i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure
- ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure
- ASoC: fsl_easrc: Use div64_u64 for 64-by-64 division
- AsoC: intel: sst: fix PCI device reference leak on probe failure
- ASoC: samsung: aries_audio_probe: double of_node_put due to direct
assignment without of_node_get
- iio: adc: adi-axi-adc: add data size support for AD408X backend
- iio: adc: max34408: add missing 'select REGMAP_I2C' to Kconfig
- iio: adc: pac1921: fix wrong channel used in trigger handler read
- iio: dac: ad3552r-hs: fix scnprintf() buffer bound in data source show
- iio: gyro: mpu3050: fix sign of raw angular velocity readings
- iio: light: cm32181: return zero after writing calibscale
- iio: light: gp2ap002: Disable regulators on resume failure
- iio: pressure: mpl115: Fix runtime PM cleanup
- iio: srf04: fix pm_runtime handling on probe error path
- iio: temperature: hid-sensor-temperature: switch to non-devm
iio_device_register()
- iio: ti-ads7138: Disable STATS_EN bit while reading conversion results
- iio: light: opt4060: Reject integration times with a non-zero seconds
part
- iio: light: opt4060: Fix incorrect register name in threshold read error
message
- iio: light: opt4001: Fix power down clearing bits of the wrong register
- iio: light: opt4001: Fix incompatible pointer type passed to
div_u64_rem()
- iio: light: opt4001: Reject integration times with a non-zero seconds
part
- iio: light: opt4001: Fix reversed GENMASK() arguments in fault count
mask
- KVM: PPC: Book3S HV: Validate arch_compat against host compatibility
mode
- KVM: nVMX: Decouple INVVPID operand checks from flushing of vpid02
- KVM: x86/mmu: Fold kvm_mmu_zap_memslot() into
kvm_arch_flush_shadow_memslot()
- KVM: x86/mmu: Split kvm_mmu_zap_all_fast() into "front" and "back"
halves
- KVM: x86/mmu: Use CMPXCHG when clearing Accessed bit in TDP MMU
- KVM: x86/mmu: Use split "zap all fast" helpers when invalidating memslot
- KVM: x86: Serialize writes to disabled_quirks using kvm->lock
- KVM: x86: Ensure runtime reads of disabled_quirks are resolved once
- KVM: s390: Zero initialize irq in reinject_machine_check
- KVM: s390: pv: Fix rc/rrc offset for PVM_DUMP
- KVM: s390: Restore sigset on error path
- KVM: arm64: Consider SCTLR_EL2.M when mapping the L1 VNCR page
- KVM: arm64: vgic: Fix detection of MI on no pending LR
- KVM: arm64: vgic: Reset in_kernel on private IRQ allocation failure
- LoongArch: KVM: Fix PC double advance in kernel MMIO read fast path
- LoongArch: KVM: Fix TOCTOU race on pv_features
- LoongArch: Add DIRECT_MAP_PHYSMEM_END definition
- LoongArch: BPF: Optimize redundant TCC loads in epilogue
- LoongArch: Do not select HAVE_RUST when KASAN is enabled
- rust: drm: ioctl: fix unbounded lifetimes in ioctl handler arguments
- media: amphion: Remove obsolete frame_count check in venc_start_session
- media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid
debugfs clash
- media: i2c: alvium: Fix: Correct name of register in
alvium_set_ctrl_auto_exposure
- media: i2c: imx415: Return test pattern write errors
- media: imx355: Avoid calling imx355_power_off twice in error path
- media: iris: Enumerate cap->bus_info to differentiate between encoder
and decoder
- media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common
- media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar
routing
- media: nxp: imx8-isi: Correct color map between V4L2 and ISI
- media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks
- media: rkvdec: Propagate platform_get_irq() errors
- media: rzg2l-cru: Align bytesperline to hardware DMA stride requirement
- media: v4l2-ctrls: Allow unknown HDR10 white point and luminance
- media: venus: fix payload size returned by parse_caps() and
parse_alloc_mode()
- media: venus: fix payload size calculation in parse_raw_formats()
- media: vimc: fix pixel format lookup in enum_framesizes
- media: qcom: iris: fix state-change debug log printing stale value
- media: chips-media: wave5: Guard bit depth check with
initial_info_obtained
- media: chips-media: wave5: Set inst->std during default format
initialization
- scsi: qla2xxx: Fix Name Server logout detection on FWI2 adapters
- scsi: qla2xxx: Check entry_status in qla24xx_modify_vp_config()
- scsi: qla2xxx: Fix response queue over-consumption in
__qla_consume_iocb()
- scsi: qla2xxx: Fix NVMe abort reference leak on repeated abort
- scsi: qla2xxx: Drop vport reference under lock in report ID acquisition
- scsi: qla2xxx: Use coherent DMA buffer for D_Port diagnostics
- f2fs: return symlink writeback errors
- f2fs: reject overlapping move range after len expansion
- f2fs: fix to avoid move_range and defragment on device_alias file
- f2fs: dirty directory inodes on mtime/ctime update
- f2fs: return writeback error from collapse range
- f2fs: fix to avoid potential section-unaligned pinfile
- f2fs: fix i_size when pinned fallocate partially fails
- f2fs: fix to off-by-one issue in f2fs_zero_post_eof_page()
- f2fs: fix to zero post-EOF data when extending file size
- drm/xe/vram: report FLAT_CCS base misalignment
- drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure
- drm/ssd130x: fix column and row end address in partial updates for
ssd132x
- drm/sun4i: fix refcount leak in sun4i_backend_init_sat()
- drm/ssd130x: fix column and row end address in partial updates in
ssd133x
- drm/nouveau/disp/r535: Add scanline position support + head state
support
- drm/hibmc: Fix list of formats on the primary plane
- drm/hibmc: Use drm_atomic_helper_check_plane_state()
- drm/gud: validate TV mode names before creating enum property
- drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value
- drm/amdgpu: check thunderbolt before switcheroo registration
- drm/amdgpu: Disable runtime PM for externally attached dGPUs
- drm/amdgpu: fix autosuspend cleanup during removal
- drm/amdgpu: Skip accessing psp rum time db for APUs
- drm/amdgpu: update the fw version for gfx11 userqueues
- drm/amdgpu: update the fw version for gfx12 userqueues
- drm/amdgpu: use AMDGPU_GPU_PAGE_SHIFT instead of PAGE_SHIFT
- drm/amdkfd: Reject zero-sized AQL queue allocations after size halving
- drm/sysfb: simpledrm: Improve framebuffer-size validation
- drm/sysfb: simpledrm: Improve panel-size validation
- drm/sysfb: simpledrm: Improve stride validation
- drm/sysfb: ofdrm: Fix is_avivo() constant comparison bug
- drm/nouveau/gsp: use per-version DP_CONFIG_STREAM params on r570
firmware
- drm/nouveau: Use write-combined maps for coherent
- drm/nouveau/disp: move GSP head-timing ISR and vblank helpers to tu102.c
- drm/nouveau/disp: move the GSP HDMI GCP AVMute write to engine/disp
- drm/nouveau/disp: route GSP-RM display MMIO through nvkm_disp_func hooks
- drm/nouveau/disp: fix HDMI vendor infoframes on GB20x
- drm/nouveau/disp: fix HDMI GCP AVMute register offsets on GB20x
- drm/nouveau/disp: fix head state readback on GB20x
- drm/nouveau/gsp: fix vblank interrupts on GB20x
- fuse: split off fuse_args and related definitions into a separate header
- fuse: remove fm arg of args->end callback
- crypto: atmel-ecc - replace min_t with min
- mm/hugetlb: defer vmemmap population for bootmem hugepages
- mm/hugetlb: refactor code around vmemmap_walk
- HID: sony: use guard() and scoped_guard()
- ACPI: CPPC: Reject desired_perf reads on _CPC revision 4+
- ACPI: x86: cmos_rtc: Create a CMOS RTC platform device
- ACPI: TAD: Rearrange RT data validation checking
- ACPI: TAD: Add locking around AML evaluations
- bpf: Factor stackid_init function from __bpf_get_stackid
- bpf: Factor stackid_fastpath function from __bpf_get_stackid
- bpf: Factor stackid_new_bucket from __bpf_get_stackid
- bpf: Use stack id functions instead of __bpf_get_stackid
- sched: Add assert_balance_callbacks_empty helper
- sched: Rework prev_balance() to avoid stale prev references
- remoteproc: qcom: pas: Guard dtb metadata release with dtb_pas_id check
- NFSD: Consolidate the revocation-path client unpin
- mm: rework compound_head() for power-of-2 sizeof(struct page)
- hugetlb: remove VMEMMAP_SYNCHRONIZE_RCU
- Docs/ABI/damon: fix typo in intervals_goal sysfs path
- power: supply: ab8500_fg: Remove redundant dev_err()/dev_err_probe()
- mm/damon/tests/core-kunit: catch test failure in test_merge_regions_of()
- mm/damon/vaddr: drop last same folio access check optimization
- mm/damon/paddr: drop last same folio access check reuse optimization
- mm/damon/ops-common: use nr_accesses moving sum for quota score
- mm/damon/core: skip aging from repeated aggressive merging
- mm/damon/sysfs: read addr_unit only once in damon_sysfs_apply_inputs()
- mm/damon/core-kunit: handle region split failure in filter_out()
- mm/damon/core: initialize damos->last_applied
- mm/hugetlb_vmemmap: fix incorrect vmemmap restore in rollback
- zram: move lockmap to be per-zram instead per table
- ACPI: battery: Use kstrtoul() over sscanf("%lu\n")
- ACPI: battery: Protect all properties with a separated mutex
- NFSD: Annotate caller preconditions for the state-table walkers
- usb: cdnsp: fix wakeup from S3 after controller context loss
- usb: dwc3: google: Initialise probe properties with
DWC3_DEFAULT_PROPERTIES
- tracing/probes: Fix anon_stack check for unnamed bitfields in
btf_find_struct_member
- tracing: Remove the backup instance automatically after read
- soc: fsl: qe: Add chained_irq_{enter,exit}() calls in cascade handler
- mm/damon/sysfs: read ops_id only once in damon_sysfs_apply_inputs()
- mm/damon/core-kunit: skip wrong dest walk in commit_dests_for()
- mm/damon/core-kunit: skip wrong quota goal walk in commit_quota_goals()
- mm/damon/core-kunit: skip wrong region walk in commit_target_regions()
- mm/secretmem: properly account locked pages
- futex: Provide rt_mutex_.*_schedule() equivalents for futex scheduling
- bpf, riscv: Make arena support depend on ZACAS
- misc: fastrpc: don't publish fd before copy_to_user() succeeds
- perf/x86/intel: Remove anythread_deprecated bit from perf_capabilities
- perf build: Add clang and rust target flags for LoongArch
- perf/core: Fix deadlock in perf_mmap() failure path
- i2c: qcom-cci: Do not check return value of cci_init()
- i2c: qcom-cci: Remove overcautious disable_irq() calls
- i2c: qcom-cci: fix autosuspend cleanup
- ring-buffer: Show persistent buffer dropped events in trace_pipe file
- ring-buffer: Allow splice reads on static buffers
- dma-buf: add dma_fence_was_initialized function v2
- nvme: fold nvme_config_discard() into nvme_update_disk_info()
- Revert "once: don't use a work queue to reset sleepable static key"
- mm: fix incorrect vm_flags usage when checking allowable orders for
tmpfs
- mtd: rawnand: pl353: Make sure we use the monolithic helpers for raw
accesses
- mtd: rawnand: sunxi: group controller delay tables
- mtd: rawnand: sunxi: describe tADL and tWHR delays
- mtd: rawnand: sunxi: fix H6/H616 controller timings
- batman-adv: fix TX priority extraction for BATADV_FORW_MCAST
- clk: microchip: mpfs: fix regmap_update_bits() mask/val order
- ASoC: adau1761: sort the register default table
- ASoC: cx2072x: sort the register default table
- ASoC: fsl_easrc: sort the register default table
- ASoC: max9860: sort the register default table
- ASoC: ml26124: sort the register default table
- ASoC: pcm512x: sort the register default table
- ASoC: pm4125-sdw: sort the register default table
- ASoC: rt1017-sdca-sdw: sort the register default table
- ASoC: rt1316-sdw: sort the register default table
- ASoC: rt1318-sdw: sort the register default table
- ASoC: rt1318: sort the register default table
- ASoC: rt274: sort the register default table
- ASoC: rt286: sort the register default table
- ASoC: rt298: sort the register default table
- ASoC: rt700: drop duplicate reg_default entry
- ASoC: rt700: sort the register default table
- ASoC: rt711-sdca: sort the register default tables
- ASoC: rt711: sort the register default table
- ASoC: rt712-sdca-dmic: sort the register default table
- ASoC: rt712-sdca-sdw: sort the register default table
- ASoC: rt715-sdca: drop duplicate reg_default entries
- ASoC: rt715-sdca: sort the register default tables
- ASoC: rt715: sort the register default table
- ASoC: rt721-sdca-sdw: sort the register default table
- ASoC: sgtl5000: sort the register default table
- ASoC: sti-sas: sort the register default table
- ASoC: tas2552: sort the register default table
- ASoC: tas2764: sort the register default table
- ASoC: tas2780: sort the register default table
- ASoC: tas2783-sdw: drop duplicate reg_default entry
- ASoC: tas2783-sdw: sort the register default table
- iio: adc: ad4080: configure backend data size
- iio: adc: max14001: add missing 'select REGMAP' to Kconfig
- iio: dac: ad5446: fix OF module device table
- iio: dac: mcp47feb02: add missing 'select REGMAP_I2C' to Kconfig
- KVM: x86: Move some EFER bits enablement to common code
- KVM: x86: Move enabling EFER.SVME and EFER.LMSLE to generic EFER setup
- KVM: arm64: nv: Fully update VNCR fixmap state in kvm_translate_vncr()
- LoongArch: Expand module virtual address space to 2GB
- LoongArch: BPF: Fix off-by-one error for insn_is_cast_user()
- media: dt-bindings: nxp,imx8-isi: Drop fsl,blk-ctrl requirement for
i.MX8ULP
- media: i2c: vd55g1: Fix manual digital gain on color variant
- media: i2c: vd55g1: Fix media bus code initialization
- media: mali-c55: fix dropped last AEC histogram zone weight
- media: mali-c55: Fix clock leak on reset deassert failure
- media: mali-c55: Fix AEXP IHIST disable bit shift
- media: mali-c55: Fix scaler factor overflow for large crop sizes
- media: rkvdec: hevc: tighten EXT SPS RPS control dimensions
- media: chips-media: wave5: avoid skipping device_run while VPU has work
- media: chips-media: wave5: Fix pipeline stall when queuing fails
- f2fs: embed f2fs_gc_kthread in f2fs_sb_info
- f2fs: fix to return -EFSCORRUPTED in f2fs_get_node_info() correctly
- f2fs: fix to reclaim space in f2fs_allocate_pinning_section()
- drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable
- drm/amd/display: Fix HPD consideration for VGA/LVDS connectors on DCE
- drm/amd/display: Set gpuvm min page size to 4K on dcn35/36
- drm/nouveau/dmem: fix callocated underflow on large folio split
- PCI: Introduce PCI_SLOT_PLACEHOLDER constant for slot_nr placeholder
value
- Upstream stable to v6.18.51, v7.2.5
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89795
- PCI: Allow per function PCI slots to fix slot reset on s390
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89796
- mm/damon/core: avoid infinite kdamond_merge_regions() internal loop
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89804
- drm/nouveau/dmem: fix mismatched DMA unmap size for large folios
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89809
- drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89812
- drm/amdgpu: force complete the MES ring fences on reset
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89813
- drm/amdgpu: force complete the KIQ ring fences on reset
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89815
- drm/ttm: Drop tt->restore after successful restore
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89827
- drm/amdgpu: avoid force-completing uninitialized UVD rings
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89831
- f2fs: protect critical_task_priority updates with s_umount
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89836
- f2fs: fix folio_nr_pages() race after put in large folio invalidate
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89838
- f2fs: limit recovery filename logging to stored length
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89840
- f2fs: validate MOVE_RANGE destination size
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89859
- scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89862
- scsi: qla2xxx: Fix BSG job leak on validate flash image error path
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89866
- media: chips-media: wave5: Resume device before setting EOS flag
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89867
- media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was
queued
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89868
- media: chips-media: wave5: Add timeout while stop_streaming
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89873
- media: v4l2-ctrls: validate HEVC EXT SPS RPS counts
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89875
- media: ti: vpe: quiesce overflow recovery before freeing streams
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89882
- media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89905
- LoongArch: BPF: Move arena register slot below TCC context
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89915
- KVM: arm64: Remove VM-wide VNCR mapping counter
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89917
- KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR
unmapping
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89919
- KVM: s390: keyop: use mmu_lock to read gmap->asce
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89921
- KVM: s390: Zero initialize data structures for inject_pfault_token
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89935
- iio: light: apds9306: fix PM reference leak in apds9306_read_data()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89966
- mm/hugetlb_cma: fix null nodemask dereference in
hugetlb_cma_alloc_frozen_folio
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89967
- mm/migrate_device: avoid out-of-bounds writes for compound folios
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89971
- nvme: skip the zoned limits update if the zone info query failed
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89976
- accel/ethosu: fix job completion fence cleanup
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89977
- accel/ethosu: check MMIO mapping errors in probe
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89978
- accel/amdxdna: return early from a zero-length flush
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89981
- arm64: Don't read GMID_EL1 when MTE is disabled
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89791
- perf: Fix use-after-free when perf mmap() revival races with the last
munmap()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89987
- mm/huge_memory: transfer the pmd dirty bit to the folio on zap
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89996
- dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90002
- ftrace: Take trace_array reference before accessing its ftrace_ops
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90013
- tracing: Take trace_array reference when opening options file
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90014
- tracing: Have show_event_filters/triggers files take trace array ref
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90016
- staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90023
- usb: gadget: f_mass_storage: fix null pointer dereference in
fsg_common_set_num_buffers()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90028
- usb: typec: hd3ss3220: track VBUS enable state per consumer
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90040
- KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is
zapped
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90043
- zram: fix slot lock bit position on big-endian 64-bit
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89794
- ksmbd: zero pipe read compound padding
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89797
- power: supply: ab8500_fg: fix use-after-free on remove
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90037
- NFSD: Prevent client use-after-free during close_lru reaping
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90036
- NFSD: Prevent client use-after-free during blocked-lock reaping
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89520
- sched/core: Make core-sched flips wait for in-flight selections
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89798
- rpcrdma: arm rn_done before publishing the notification
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89799
- bpf: Disable preemption in bpf_get_stackid
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90041
- HID: sony: clean up device list on probe failure
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90042
- ceph: properly decrypt filenames in vmalloc() buffers
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90039
- NFSD: Guard admin state-revocation walks with NFSD_NET_UP
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90044
- usb: gadget: f_fs: Fix Use-After-Free in AIO error path
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90045
- USB: gadget: ffs: fix mm lifetime handling
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90046
- mm/page_alloc: don't spin_trylock() in NMI on UP
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-80926
- ksmbd: fix use-after-free in oplock break notification
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89800
- drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89801
- drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89802
- drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89803
- drm/nouveau: unsubscribe the channel-kill event before the fence context
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89806
- drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89807
- drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89808
- drm/amdkfd: Fix the case that vm range is hole at
svm_migrate_copy_to_vram
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89810
- drm/amdkfd: Fix error path at svm_migrate_copy_to_ram
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89811
- drm/amdkfd: Add TLB flush after MES queue eviction/suspension
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89814
- drm/amdgpu: clamp the isolation index for rings outside a partition
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89816
- drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89817
- drm/gud: NUL-terminate TV mode names read from the device
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89818
- drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89819
- drm/amd/display: validate plane degamma LUT size for private color prop
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89820
- drm/amd/display: fix dc_lock leak on GPU reset error paths
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89821
- drm/amd/display: avoid divide-by-zero in __is_lut_linear()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89822
- drm/i915: Guard against NULL driver_data in i915_pci_probe()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89823
- drm: fix race between partial drm_dev_register() failure and ioctl
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89824
- drm/panel-edp: fix i2c adapter leak on probe failure
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89825
- drm/panthor: fix firmware control interface bounds checks
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89826
- drm/panthor: harden firmware build-info bounds checks
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89828
- drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89829
- f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89830
- f2fs: fix valid block count leak on data block allocation failure
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89832
- f2fs: fix to clear dirty flag on folio in error path
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89833
- f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89834
- f2fs: fix to migrate all curseg types during free_segment_range
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89835
- f2fs: avoid NULL checkpoint thread access in sysfs
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89837
- f2fs: fix dentry folio leak in find_in_level
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89839
- f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89841
- f2fs: only redirty pinned folios in redirty_blocks
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89842
- scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89843
- scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89844
- scsi: qla2xxx: Hold vport_slock for host map update in report ID
acquisition
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89845
- scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89846
- scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89847
- scsi: qla2xxx: Avoid double completion in async IOCB timeout
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89848
- scsi: qla2xxx: Quiesce response IRQ before freeing request queue
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89849
- scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89850
- scsi: qla2xxx: Don't query firmware state while chip is down
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89851
- scsi: qla2xxx: Fix FCE trace enable parsing in debugfs
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89852
- scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89853
- scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89854
- scsi: qla2xxx: Fix cs84xx use-after-free on host teardown
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89855
- scsi: qla2xxx: Serialize flash version read in reset handler
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89856
- scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89857
- scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89858
- scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89860
- scsi: qla2xxx: Initialize NVMe abort_work once at submission
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89861
- scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89863
- scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89864
- scsi: qla2xxx: Bound i2c->length in I2C bsg handlers
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89865
- scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89869
- media: qcom: iris: use disable_irq() during power-off
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89870
- media: zoran: Avoid freeing a registered video_device twice
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89871
- media: video-i2c: fix kthread error pointer left in kthread_vid_cap on
failure
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89872
- media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89874
- media: v4l2-async: avoid deleting unlinked ASC entry on link error
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89876
- media: tda18250: fix possible integer overflow
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89877
- media: saa7164: fix cleanup on resource allocation failure
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89878
- media: s2255: check firmware size before reading trailing marker
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89879
- media: s2255: bound JPEG frame size before copying into the buffer
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89880
- media: rtl2832_sdr: release URBs and stream buffers on start_streaming()
failure
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89881
- media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix
DMA leak
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89883
- media: rc: sunxi-cir: Unregister rc device on probe failure
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89884
- media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89885
- media: platform: mtk-mdp3: Fix SCP device refcounting
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89886
- media: intel/ipu6: fix async notifier cleanup leak on parse error
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89887
- media: i2c: ov7740: fix use-after-destroy in remove
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89888
- media: i2c: ov02a10: fix endpoint parsing use-after-free
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89889
- media: i2c: imx415: Release runtime PM reference on VBLANK error
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89890
- media: go7007: defer the ALSA v4l2 put until card release
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89891
- media: em28xx: fix use-after-free of dev_next->devlist on disconnect
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89892
- media: em28xx: defer audio-only extension registration
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89893
- media: cx23885: cancel NetUP CI work before teardown
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89894
- media: cx231xx: reject geometry changes while the VBI queue is busy
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89895
- media: cobalt: Avoid freeing ALSA private data twice
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89896
- media: cedrus: fix memory leak in cedrus_init_ctrls()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89897
- media: cec: Serialize exclusive follower delivery
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89898
- media: cec: extron-da-hd-4k-plus: add sanity check
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89899
- media: cec: disable delayed work before freeing an interrupted transmit
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89901
- media: airspy: use vb2_video_unregister_device() on disconnect to fix
NULL deref
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89902
- LoongArch: Avoid preempt count underflow without probe
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89903
- LoongArch: Do not save/restore percpu base register in rethook
trampoline
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89904
- LoongArch: Fix acpi_package_ids[] array overflow
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89906
- LoongArch: BPF: Refactor jump offset calculation in tail call
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89908
- LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89909
- LoongArch: KVM: Free init resources if kvm_init() fails
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89911
- KVM: arm64: Correctly cap TLBI Range to the architural limit
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89912
- KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89913
- KVM: arm64: vgic-v3: take an LPI reference in
vgic_v3_save_pending_tables
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89914
- KVM: arm64: Sign-extend VA for range-based TLBI invalidation
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89916
- KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89918
- KVM: arm64: Correctly handle end of VA space TLBI invalidation
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89775
- KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89920
- KVM: s390: Fix memory corruption by not reinjecting CK machine checks
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89922
- KVM: s390: Take srcu when importing watchpoint data
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89923
- KVM: s390: Free guest debug data on vcpu destroy
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89924
- KVM: s390: Fix old_data leak in guest debug error path
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89925
- KVM: s390: Fix memory leak in guest debug handling
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89926
- KVM: s390: Fix length check __import_wp_info()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89927
- KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89928
- KVM: x86/mmu: Consume the locked rmap value in the lockless rmap walk
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89929
- KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89930
- KVM: nVMX: Service local TLB flushes on failed nested VM-Enter
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89931
- KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89932
- KVM: nVMX: Always flush vpid02 on first use
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89933
- iio: pressure: dps310: fix NULL pointer dereference on ACPI probe
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89934
- iio: light: ltrf216a: fix runtime PM reference leak in error path
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89936
- iio: dac: m62332: Fix regulator reference count imbalance
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89937
- iio: chemical: sgp30: Handle IAQ thread creation failure
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89938
- iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove
UAF
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89939
- iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89940
- iio: buffer: Tie IIO dma fence lock lifetime to the fence
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89941
- iio: buffer: Make IIO DMA fence release RCU-safe
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89942
- iio: buffer: Fix potential use-after-free in anonymous buffer release
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89943
- ASoC: loongson: Fix error handling in ACPI property parsing
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89944
- ASoC: hdac_hda: Fix hlink refcount leak on component registration
failure
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89945
- ASoC: cs35l34: drain threaded IRQ before runtime suspend
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89946
- ASoC: cs35l33: drain threaded IRQ before runtime suspend
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89947
- clk: meson: align gxbb_32k_clk_sel number of parents with actual count
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89948
- batman-adv: bla: fix freeing of claims on meshif deletion
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89949
- batman-adv: dat: avoid unaligned fault in IP extraction
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89950
- batman-adv: mcast: linearize skbuff for packet generation
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89951
- batman-adv: fix stale receive device on merged fragments
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89952
- mtd: rawnand: validate ONFI extended parameter page sections
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89953
- mtd: mtdoops: free page bitmap when the backing MTD is removed
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89954
- mtd: afs: validate v2 image info bounds
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89955
- s390/vfio-ap: Fix NULL deref in status_show() during queue probe
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89956
- s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev
objects
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89957
- s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain
removed
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89958
- s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89959
- s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89960
- s390/vfio-ap: fix stale pqap_hook pointer on error in
vfio_ap_mdev_set_kvm()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89961
- powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89962
- powerpc/kexec_file: Prevent kexec range truncation
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89963
- powerpc/kexec_file: Fix null-ptr-def in extra size calculation
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89964
- parisc: eisa: Fix infinite loop when parsing invalid IRQ value
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89965
- nvdimm/btt: reject an arena whose nfree is below the lane count
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89968
- nvmet-tcp: reject unsolicited H2CData PDUs
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89969
- nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89970
- nvmet-auth: Synchronize timeout work during SQ teardown
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89972
- nvme: add missing SRCU grace period in error path
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89973
- nvme-tcp: check the data direction of a C2HData PDU
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89974
- nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89975
- nvme-fabrics: fix DHCHAP secret leak on parse failure
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89979
- ALSA: pcm: Fix race between non-atomic ops and trigger-start
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89980
- ALSA: harmony: initialize locks before requesting IRQ
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89982
- i2c: mux: Fix channel node leak on adapter add failure
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89983
- i2c: core: fix debugfs UAF on adapter removal
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89984
- perf/x86/intel: Fix kernel address leakages in LBR stack
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90048
- fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89986
- mm/mempolicy: fix sleeping allocation in
alloc_pages_bulk_weighted_interleave()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89988
- kprobes: Protect kprobe_blacklist with RCU
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89989
- ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89990
- ceph: lock mutex in ceph_mds_check_access()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89991
- bpf: Fix infinite loop in pcpu_freelist push with one possible CPU
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89992
- cpuidle: dt_idle_genpd: kfree() the original name allocation
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89993
- dmaengine: dw-edma: Initialize IRQ data before requesting IRQs
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89994
- dmaengine: fsl-edma: tracing: no ptr dereference during log output
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89995
- dma-direct: return struct page from dma_direct_alloc_from_pool()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89997
- dm: fix resume-vs-remove race
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89998
- dm: fix race when loading and unloading a table
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89999
- HID: wacom: validate report length in wacom_intuos_pro2_bt_irq
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90000
- HID: rmi: fix OOB access with undersized RMI reports
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90001
- HID: bpf: serialize device reference release in struct_ops destroy path
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90003
- futex: Prevent rcuwait use-after-free during requeue PI
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90005
- samples/damon/wsse: handle damon_start() failure
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90006
- samples/damon/mtier: handle damon_stop() failure
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90007
- scsi: pm8001: Use rollback index when freeing MSI-X vectors
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90011
- scsi: target: iscsi: Reserve a terminator byte for the login payload
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90012
- spi: Fix DMA mapping ownership on partial map failure
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-89793
- ublk: clear VM_MAYWRITE on read-only ublk char device mmap
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90015
- xhci: fix lost bounce buffers on TDs spanning several ring segments
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90017
- staging: rtl8723bs: fix OOB read in rtw_action_frame_parse()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90018
- staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90019
- usb: gadget: fix null pointer dereference in usb_put_function_instance()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90020
- USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90021
- usb: gadget: f_midi: initialize work in f_midi_alloc()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90022
- usb: gadget: f_midi2: fix use-after-free in string attribute show path
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90024
- usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90025
- usb: typec: ucsi: displayport: Fix OOB altmode array index
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90026
- usb: typec: qcom-pmic: cancel reset_work on stop
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90027
- usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90029
- usb: storage: realtek_cr: fix use-after-free on disconnect
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90030
- usb: dwc3: clear forceRM when issuing EndTransfer
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90031
- usb-storage: ene_ub6250: fix race between scan work and probe
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90032
- media: usbtv: keep device alive while ALSA card exists
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90033
- ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90034
- usb: image: mdc800: change kmalloc() to kzalloc()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90035
- drm/amd/display: fix division by zero in get_estimated_bw()
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90047
- drm/xe: Don't hand out the flat CCS storage as usable VRAM
* Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
CVE-2026-90049
- net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy()
* Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609)
- [Config] Remove CONFIG_CRYPTO_DEV_SUN8I_CE_PRNG
- [Config] Remove CONFIG_CRYPTO_DEV_SUN8I_SS_PRNG
- ASoC: tegra210_i2s: sort the register default table
- ASoC: tegra210_i2s: sort the Tegra264 register default table
- ASoC: tegra210_mixer: sort the register default table
- ASoC: tegra: Fix the I2S enable default value
- ASoC: tegra: Fix the MIXER enable default value
- ASoC: tegra: Sort ADMAIF register defaults
- ASoC: tegra: Sort MBDRC register defaults
- ring-buffer: Fix subbuf resize race with ring buffer readers
- drm/amd/display: hide Apple Studio Display secondary tile
- drm/amd/display: Prune per-tile Timing from Apple Studio Display Primary
Tile
- alpha: fix ieee_swcr_to_fpcr setting FPCR_DNOD unconditionally
- rust: time: fix as_micros_ceil() rounding near i64::MAX
- alpha: don't leak hardware-fabricated FP exception bits to user space
- clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error
path
- clocksource/drivers/timer-sun4i: Advertise a real minimum delta
- fs: fix user path of nested backing files
- ovl: fix double end_creating() on the casefold-mismatch path
- pidfd: hold exec_update_lock around namespace ioctl
- powerpc/pseries/iommu: switch to Default DMA window during kdump
- rust: fmt: fix {:p} printing stack addresses
- timers/itimer: Zero-init old itimerval before copy to userspace
- objtool/rust: add one more `noreturn` Rust function for Rust 1.99.0
- rust: bug: skip arch-specific asm in `testlib` builds
- rust: bug: fix warn_on macro build error on UML
- rust: bug: prevent dead_code warning from warn_on!'s flags constant
- rust: rust_is_available: warn for `bindgen` < 0.72.1 && libclang >= 22
- rust: kernel: list: fix incorrect pop_back example comment
- objtool/rust: add one more `noreturn` Rust function
- rust: num: restrict bool conversion to unsigned Bounded
- rust: cfi: disable function merging if CFI is enabled
- KEYS: trusted: Fix TPM teardown ordering
- apparmor: fix cred UAF caused by begin_current_label_crit_section()
- apparmor: fix out-of-bounds write when null terminating a label vec
- include/linux/list.h: mark list_add and __list_add as __always_inline
- mm, swap: ratelimit bad swap entry reports
- mm/gup: fix always draining LRU caches in
collect_longterm_unpinnable_folios()
- mm/huge_memory: skip device-private PMDs in madvise_free_huge_pmd
- mm/huge_memory: use folio's memcg inside __folio_split()
- mm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier
- mm/hugetlb_vmemmap: fix __hugetlb_vmemmap_optimize_folios()
- mm/kmemleak: avoid soft lockup when scanning task stacks
- mm/madvise: skip device-private PMDs in cold and pageout walks
- mm/mempolicy: skip non-present PMDs when queueing folios
- mm/mglru: use the common routine for dirty/writeback reactivation
- mm/mglru: fix and remove redundant unevictable folio handling
- mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()
- mm/migrate: use huge_ptep_get() in remove_migration_pte()
- mm/migrate_device: clear stale mapping after freeing swapcache
- mm/mm_init: deferred_grow_zone(): fix out-of-range first_deferred_pfn
- mm/page_owner: use memcg_data snapshot to avoid TOCTOU in
print_page_owner_memcg()
- mm/page_vma_mapped: use huge_ptep_get() for hugetlb
- mm/pagewalk: fix stale walk->action escaping walk_pmd_range()
- mm/rmap: use huge_ptep_get() in try_to_unmap_one()
- mm/rmap: use huge_ptep_get() in try_to_migrate_one()
- mm/slub: fix missing debugfs entries for caches created before sysfs
init
- mm/slub: prevent pfmemalloc objects from entering the barn
- mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()
- mm/zswap: fix global shrinker when memory cgroup is disabled
- mm: compaction: support non-movable compaction for pageblock requests
- mm: memcg-v1: fix wrong linux-mm list address in deprecation warnings
- mm: memcg-v1: fix memsw and TCP failcnt accounting
- mm: memcg: stop reclaim when a limit update is superseded
- mm: memcontrol: update state_local when flushing NMI stats
- mm: mempolicy: fix automatic numa balancing for shmem
- mm: page_alloc: __GFP_FS lockdep annotation for direct compaction
- mm: page_alloc: move capture_control to the page allocator
- mm: page_alloc: fix non-movable reclaim storm in defrag_mode
- mm: vmscan: fix node reclaim ignoring swappiness parameter
- tools/compiler: match glibc 2.42 definition of __attribute_const__
- x86/locking: Use sfence for wmb() if SSE is available
- x86/insn-eval: Move assign_register() out of KVM as insn_assign_reg()
- x86/tdx: Fix off-by-one in port I/O handling
- x86/tdx: Fix zero-extension for 32-bit port I/O
- x86/xen: fix init of balloon stats again
- hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start()
- tracing/user_events: Clear copied tracing state before fork duplication
- tracing: Fix crash passing ERR_PTR to kthread_stop()
- tracing: Fix logged instance name on creation failure
- tracing: Fix use-after-free in trace_pipe read on sub-buffer order
change
- tracing: Fix use-after-free with same-name named triggers
- cdx: Fix double free when sysfs file creation fails
- debugfs: Fix lockdown check for mmap_prepare
- device property: fix infinite loop in fwnode_for_each_child_node()
- misc: nsm: bound the device-reported response length
- powerpc/powermac: fix OF node refcount
- rapidio: mport_cdev: fix use-after-free in dma_req_free()
- Revert "media: v4l2-dev: fix error handling in
__video_register_device()"
- serial: imx: serialize imx_uart_ports[] lifetime
- staging: greybus: hid: fix SET_REPORT return value
- usb: dwc2: gadget: Exit partial power down state when changing USB pull-
up
- usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due
to race condition
- usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed
- USB: phy: fsl-usb: fix missing static keywords
- usb: typec: hd3ss3220: fix VBUS regulator error message
- usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive()
- usb: typec: thunderbolt: Disable work before freeing tbt on remove
- usb: typec: ucsi: use UCSI_TIMEOUT_MS for sync command completion
- usb: gadget: u_audio: Fix use-after-free on sound card disconnect
- usb: gadget: snps_udc_plat: clean up PHY on probe deferral
- usb: gadget: midi2: remove default configfs groups on teardown
- usb: gadget: f_tcm: fix deadlock in usbg_make_tpg()
- usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init()
- usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and
uvc_function_unbind()
- usb: gadget: f_fs: Prevent deadlock during ep0 read loop
- cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read
- fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write
- HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature
- i3c: renesas: Fix out-of-bounds access for newdevs mask
- KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID
- lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
- media: cec: stm32: prevent out-of-bounds write on RX overflow
- media: vicodec: fix out-of-bounds write in FWHT encoder
- nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after
truncation
- of: fix out-of-bounds read in of_alias_scan() stem parser
- PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io()
- phy: rockchip-samsung-dcphy: fix out-of-range max_register
- ubifs: fix out-of-bounds read in signature length check
- zram: fix out-of-bounds access in read_block_state()
- zram: fix out-of-bounds access in writeback_store()
- zram: set default primary compressor in zram_destroy_comps()
- zram: validate deflate params
- zsmalloc: account for handle size in class lookup
- NFS/localio: fix ref leak on nfs_uuid_add_file failure
- NFS: fix delegation_hash_table leak when nfs4_server_common_setup()
fails
- NFSD: check truncate permission under inode lock
- NFSD: Encode only the status in NFS-ACL v2 GETACL error replies
- NFSD: Fix off-by-one in DRC bucket pruning limit
- NFSD: fix up error returned by write_threads()
- NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock
- NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check
- nfsd: guard nfsd_serv deref in nfsd_file_net_dispose
- NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget
path
- pNFS: Fix EBUSY check in pnfs_layout_need_return
- lockd, nfsd: RCU-protect nlmsvc_ops dispatch
- nfsd: RCU-protect cl_cb_session to fix use-after-free on session
teardown
- nfsd: release path refs on follow_down() error
- nfsd: Reset write verifier when async COPY writeback fails
- nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit
paths
- nfsd: return NFS4ERR_NOTSUPP for unsupported netloc4 types
- nfsd: sample writeback error cursor before async COPY loop
- nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations
- nfsd: size fh_verify server sockaddr slot by xpt_locallen
- nfsd: validate nseconds in TIME_DELEG decode paths
- nfsd: validate sockaddr length per family in listener_set
- nfsd: validate symlink target length in NFSv4 CREATE
- nfsd: move struct nfsd_genl_rqstp to nfsctl.c
- nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage
- nfsd: add fh_want_write() for early-verified SETATTR in
nfsd_proc_setattr()
- nfsd: add filehandle match check to nfsd4_delegreturn()
- nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry
- nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref
- nfsd: cap decoded POSIX ACL count to bound sort cost
- nfsd: check client ownership when cancelling a copy-notify stateid
- nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()
- nfsd: clear CALLBACK_RUNNING on failed delegation recall queue
- nfsd: clear opcnt on compound arg release to prevent OOB read
- nfsd: convert nfsd_net boolean flags to unsigned long flags word
- nfsd: dedup nfs4_client_to_reclaim inserts
- nfsd: defer setting NFSD4_CALLBACK_RUNNING in deleg_reaper
- nfsd: defer vfree of compound ops to fix rpc_status UAF
- nfsd: don't free session slots that are still in use
- nfsd: drop the stateid, not the stateowner, on seqid_op replay retry
- nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file
- nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation
revoke
- nfsd: fix clock domain mismatch in clients_still_reclaiming()
- nfsd: fix cpntf publish race in nfs4_init_cp_state
- nfsd: fix dentry ref leak on V4ROOT export filehandle lookup
- nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net
- nfsd: fix FL_SLEEP being set unconditionally for all LOCK types
- nfsd: fix netlink dumpit error handling for rpc_status_get
- nfsd: fix nfsd_file leak on inter-server COPY setup failure
- nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs
- nfsd: fix partial-write detection in nfsd_direct_write
- nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file()
- nfsd: fix refcount leak in nfsd_file_lru_add on insertion failure
- nfsd: fix reply size estimate for GET_DIR_DELEGATION
- nfsd: fix stale s2s_cp_stateids IDR entry for async COPY
- nfsd: fix UAF in async copy cancel and shutdown
- nfsd: fix version mismatch loops in nfsd_acl_init_request()
- nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget
- nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo
- nfsd: gate nfs2 setacl by argp->mask
- nfsd: gate nfs3 setacl by argp->mask
- nfsd: hold rcu across localio cmpxchg retry
- nfsd: initialize copy-notify stateid before publishing it
- nfsd: initialize DRC hash table before registering shrinker
- nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd()
- nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache
- nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops
- nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE
- nfsd: reject reclaim LOCK after RECLAIM_COMPLETE
- nfsd: release OPEN-decoded posix ACLs via op_release
- nfsd: revoke copy-notify stateids before dropping their reference
- NFSD: Prevent lock owner use-after-free during client teardown
- NFSD: Prevent post-shutdown use-after-free in unlock_filesystem
- NFSD: Prevent client use-after-free during admin state revocation
- nfsd: convert global state_lock to per-net deleg_lock
- NFSD: Prevent client use-after-free during delegation revoke
- NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup
- nfsd: use test_and_clear_bit for somebody_reclaimed to prevent lost
update
- libceph: validate OSD extent maps before cursor advance
- libceph: reject buckets with mismatched CRUSH ids
- ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock
- ceph: fix UAF in check_new_map() on session freed during unlock
- ceph: force a cap message when a deferred revoke can't be acked
immediately
- ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
- ceph: bound copied dentry name length in NFS export get_name
- ceph: bound MDSCapAuth path and fs_name decode in handle_session()
- ceph: bound num_export_targets array for mds info v2/v3
- ceph: bound xattr value length in __build_xattrs()
- ceph: cap delegated inode count in ceph_parse_deleg_inos()
- ceph: do not repeat ceph_trim_dentries() if no progress possible
- ceph: fix leaked inode reference on writeback abort at umount
- btrfs: drop recovered reloc root refs on recovery failure
- btrfs: fix extent map leak in NOCOW direct I/O write
- btrfs: do not overwrite NODATASUM flag when removing NODATACOW flag
- audit: avoid dropping live tree ref on fsnotify rule autoremove
- smb: move some definitions from common/smb2pdu.h into common/fscc.h
- smb/client: reduce fallocate zero buffer allocation
- smb/client: emulate small EOF-extending mode 0 fallocate ranges
- cifs: add cifs_resize_file_locked() to guard fscache_resize_cookie()
under i_rwsem
- smb/client: do not account EOF extension as allocation
- cifs: call pagecache_isize_extended() in cifs_setsize() when extending
- cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size()
- cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
- cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC
- smb: client: clear setuid/setgid bit on write with
cifsacl/modefromsid/posix extensions
- smb: client: fix UAF and buffer leak in cifs_check_trans2() for
malformed secondary T2
- smb: client: clear ce->tgthint in free_tgts()
- smb: client: fix ALIGN() overflow in symlink_data() error context loop
- smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV
- smb: client: fix OOB read/write from unvalidated DataOffset in
coalesce_t2()
- smb: client: fix use-before-check of ReparseDataLength in
reparse_buf_ptr()
- smb: client: harden DFS cache against invalid target hints
- smb: client: reject a tree connect response whose byte count is too
small
- smb: client: restore the data_offset bound in is_valid_oplock_break()
- HID: apple: preserve keyboard backlight across T2 resume
- HID: corsair-void: Check size of status and firmware events before
reading them
- HID: picolcd: clamp eeprom debugfs read to bytes actually received
- HID: roccat: free buffered reports when destroying device
- HID: sensor: custom: Fix field sysfs group cleanup on failure
- HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind
- HID: universal-pidff: stop the device when force-feedback init fails
- HID: mcp2221: stop device IO before hid_hw_stop
- HID: mcp2221: fix OOB write in mcp2221_raw_event()
- HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes
- HID: mcp2221: validate report size in mcp2221_raw_event()
- HID: intel-thc-hid: intel-quickspi: validate report size before copy
- HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the
caller buffer
- HID: intel-thc-hid: intel-quicki2c: fix autosuspend cleanup during
teardown
- HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during
teardown
- eventfs: Initialize ei->children and ei->list in init_ei()
- fs/ntfs3: validate dirty page table on log replay
- fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()
- fs/ntfs3: bound page_lcns[] index by the log record
- eCryptfs: bound the packet-length peek to the user buffer
- ecryptfs: fix tag 11 packet exact-fit size check
- ecryptfs: hold msg ctx list lock when cleaning daemon queue
- ecryptfs: pass packet set buffer size to parser
- ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet
- ecryptfs: reject too-small tag 70 packets
- ecryptfs: release message context on send failure
- ecryptfs: show filename encryption options
- efivarfs: Rate limit statfs() handler
- entry: Fix seccomp bypass after ptrace with TSYNC
- erofs: skip sufficiently large global buffers when resizing
- ext2: Fix lost inode updates for IS_SYNC inodes
- fanotify: fix use-after-free of file range info
- fat: restore original value when fat_ent_write failed
- fbdev: omapfb: panel-dsi-cm: initialize lock before registering display
- fbdev: pvr2fb: correct user pointer annotation and sentinel initializer
- fbdev: ssd1307fb: defer I2C transfers from damage callbacks
- fbdev: uvesafb: unregister connector callback on init failure
- forcedeth: fix off-by-one when saving/restoring non-PCI config space
- fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration
- fsnotify: Fix stale object mask after concurrent mark updates
- hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device
- hugetlb: only adjust reservation during unmapping if mapcount is 0
- accel/rocket: fix NULL dereference and integer overflow in
rocket_job_push()
- accel/rocket: initialize job domain before cleanup paths
- accel/rocket: Fix error path handling in rocket_job_run()
- acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks
- ACPI: APEI: Fix ERST timeout unit conversion
- ACPI: APEI: GHES: fix ARM section length accounting after header
- ACPI: pfr_update: fix stack buffer overflow in query_capability()
- ACPI: scan: Avoid registering platform devices with resource overlaps
- alpha/PCI: Fix I/O port accessor argument order in pci_legacy_write()
- alpha: marvel: Fix irq_set_status_flags to use correct IRQ number
- alpha: marvel: Fix lock ordering in init_io7_irqs()
- ARM: 9477/1: Disable broken eBPF JIT on the Risc PC
- ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes
- auxdisplay: charlcd: cancel backlight work on registration failure
- backlight: aw99706: Fix DT property names to match binding
- backlight: aw99706: Honor the core blank state in update_status()
- block: validate user space vectors during extraction
- block: set QUEUE_FLAG_DYING unconditionally in blk_mark_disk_dead()
- Bluetooth: btusb: Add ASUS USB-BT540 for Realtek 8761CU
- Bluetooth: btusb: Add ASUS USB-BT600 for Realtek 8761CU
- Bluetooth: btusb: limit RTL8761B BROKEN_EXT_SCAN quirk to 0bda:a728
- Bluetooth: eir: Fix OOB read in eir_get_service_data()
- bnx2x: fix double free in bnx2x_init_firmware() error path
- bnxt_en: Write doorbell when linearizing skb fails
- bpf, x86: Fix per-CPU address resolution into an extended register
- bpf: Disable preemption in __bpf_get_stack
- buffer: avoid tail commit walk for uptodate folios
- bpf: Harden bloom filter sizing and indexing on 32-bit kernels
- dm-io: clone the source bio instead of copying its biovec
- dm-io: report non-retryable errors separatedly
- dm-era: fix shadowed superblock leak on take-snap failure
- dm raid1: reserve space for NUL-terminator in build_constructor_string()
- dm array: validate array block headers on read
- dm array: reject an array block whose value size is not the caller's
- coresight: etm3x: Fix cntr_val_show() to match cntr_val_store() behavior
- cpufreq: apple-soc: Fix OPP table cleanup
- cpufreq: schedutil: Fix rate limit overflow
- cxl/features: bound fwctl command payload to the input buffer
- dax/cxl, hmem: Initialize hmem early and defer dax_cxl binding
- cxl/region: Add helper to check Soft Reserved containment by CXL regions
- cxl/mce: Make the MCE notifier per-region
- cxl/pmem: Format the nvdimm serial number as unsigned decimal
- cxl/ras: Fix cxl_rch_get_aer_severity() wrong severity register
- Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on
BCM4378
- Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is
negative
- Bluetooth: hci_uart: Fix false success return in hci_uart_setup()
- Bluetooth: RFCOMM: serialize security confirmation handling
- Bluetooth: hci_conn: re-enable advertising only for peripheral role
- Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb
- Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection
- Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is
negative
- Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is
negative
- Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last
request
- kasan: fix cache shrink race with CPU hotplug
- jbd2: bound shrinker scans by examined checkpoint buffers
- jbd2: check need_resched() when skipping busy checkpoint buffers
- ipip: fix skb leak in collect_md mode when metadata_dst allocation fails
- ip: orphan prefetched skbs before multicast forwarding
- ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit()
- ip6_gre: fix hardware header length for NBMA tunnels
- ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()
- ipv6: use RCU iterator to dump route exceptions
- landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
- libnvdimm/labels: Prevent integer overflow in __nd_label_validate()
- mailbox: qcom-ipcc: fix duplicate channel allocation across holes
- md/raid10: fix still_degraded being inverted in raid10_sync_request()
- md: do overflow check for sb->bblog_shift in super_1_load()
- module: validate string table section types
- mpls: reload header after pskb_may_pull()
- mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction
- module/kallsyms: fix nextval for data symbol lookup
- nouveau/gem: reserve the bo in the info ioctl around the vma lookup
- params: fix charp corruption on allocation failure
- phy: fsl-imx8mq-usb: fix typec switch leak on probe error path
- SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow
- SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
- SUNRPC: svcauth_gss: enforce krb5 token minimum length
- sunrpc: route to a populated pool in svc_pool_for_cpu()
- SUNRPC: Restore NUMA_NO_NODE for svc thread allocations in global mode
- SUNRPC: always drain cache_cleaner before destroying a cache_detail
- SUNRPC: Check svc pool percpu counter allocation
- SUNRPC: close backchannel before destroying callback service
- sunrpc: defer rq_argp and rq_resp free until after RCU grace period
- SUNRPC: fix gssx_dec_option_array error path bugs
- sunrpc: fix use-after-free in __rpc_clnt_handle_event and
__rpc_clnt_remove_pipedir
- SUNRPC: Guard svcauth_gss_release() dispatch on rq_auth_stat
- SUNRPC: harden gss_krb5_unwrap_v2 against short tokens
- SUNRPC: harden gss_unwrap_resp_priv length checks
- sunrpc: init gssp_lock before publishing proc entry
- SUNRPC: reject duplicate CREDS_VALUE options
- SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field
- SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2
- SUNRPC: wait for in-flight client TLS handshake callback
- svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id
- svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails
- svcrdma: Fix offset arithmetic in read_chunk_range
- svcrdma: Fix pcl_for_each_segment for empty chunks
- svcrdma: Fix unmatched rn_unregister on failed accept
- svcrdma: Reject connection when transport allocation fails
- svcrdma: Reject inline replies that overflow the pull-up buffer
- svcrdma: Reject oversized Read segments at decode time
- svcrdma: Reject Read lists that exceed the page budget
- svcrdma: Reject Write/Reply chunks with segcount 0
- svcrdma: Use svc_xprt_put to free listener on create failure
- svcrdma: Validate Read chunk positions before reconstruction
- udf: reject VAT indexes equal to the entry count
- wifi: ath6kl: clamp assoc request/response lengths before subtracting IE
offsets
- wifi: mt76: mt7925: cancel pending mlo_pm_work
- staging: media: tegra-video: fix of_node_put() on VIP parse errors
- staging: media: tegra-video: vi: fix probe failure on skipped last port
- media: staging/ipu7: fix async notifier UAF on probe error path
- sched/core: Handle pick_task() releasing the rq lock
- sched_ext: Fix exit_task leak on fork failure during enable
- sched_ext: Fix inverted ops.core_sched_before() invocation
- sched_ext: Keep kick_sync waiting on the rq's own CPU
- scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables()
- scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock
- rpmsg: glink: smem: order FIFO read after availability check
- Revert "arm64: dts: rockchip: Further describe the WiFi for the
Pinephone Pro"
- arm64: dts: qcom: kodiak: avoid EFI overlap for ADSP remote heap
- arm64: dts: qcom: sm6115-pro1x: Correct touchscreen GPIO flags
- arm64: dts: qcom: x1-dell-thena: mark l12b and l15b always-on
- arm64: dts: rockchip: fix eMMC reset polarity on PP-1516
- arm64: dts: rockchip: fix eMMC reset polarity on PX30 Ringneck
- arm64: dts: rockchip: fix emmc reset polarity on px30-cobra
- arm64: dts: rockchip: Fix rk3399-roc-pc-plus analog audio
- arm64: dts: rockchip: Fix rk3588s-roc-pc audio description
- riscv: dts: spacemit: k1-bananapi-f3: fix maximum CPU core voltage
- riscv: dts: spacemit: k1-milkv-jupiter: fix maximum CPU core voltage
- RISC-V: KVM: Fix PMU event info array size overflow
- riscv: acpi: Handle LPI architectural context loss flags
- riscv: unaligned: stop using kthread for check_vector_unaligned_access()
- remoteproc: scp: Fix device reference leak on failed lookup
- qede: Fix NULL pointer dereference in TPA fragment processing
- RDMA/cxgb4: Cancel reg_work before freeing device on remove
- RDMA/ionic: Cap eq_count to the eth driver's interrupt vector budget
- RDMA/ionic: Embed counter driver data in rdma_counter allocation
- RDMA/ucma: Lock the handler in ucma_set_ib_path()
- RDMA/ucma: Lock the handler in ucma_write_cm_event()
- RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR
- regulator: as3722_get_regulator_dt_data: fix premature of_node_put
leaving dangling of_node pointer
- regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after
ownership transferred to rdata
- regulator: qcom-refgen: correct the regulator type to CURRENT
- ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page()
- ring-buffer: Free cpu_buffer::free_page with subbuf_order
- ring-buffer: Hold cpu_buffer::lock when resizing a subbuf
- ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page
- PM: sleep: Unblock runtime PM when device prepare fails
- orangefs: fix double-free of trailer_buf on readdir copy failure
- orangefs: skip leading spaces before parsing client debug masks
- ocfs2: always run deallocs on copy-on-write completion
- ocfs2: bound namelen in dlm_migrate_request_handler
- ocfs2: validate lengths in dlm_mig_lockres_handler
- ocfs2: validate rl_used against rl_count in refcount block validator
- ocfs2: validate dx_root extent list fields during block read
- ocfs2: validate directory-index entry counts when reading metadata
- ocfs2: cluster: don't sleep while holding o2hb_live_lock in
o2hb_region_pin()
- ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from
drop_item
- ocfs2: cluster: fix o2hb_dependent_users leak on pin failure
- ocfs2: fix cached cluster count after suballocator reclaim
- ocfs2: fix readdir position truncation on 32-bit kernels
- openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
- openvswitch: Fix CT limit teardown use-after-free
- openvswitch: only skb_tx_error() a packet we are about to drop
- ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion
- arm64: compat: Fix decrementing LDM/STM alignment emulation
- arm64: proton-pack: Restore the nospectre_bhb command-line option
- ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC
- ASoC: codecs: aw88261: reduce log spam
- ASoC: codecs: aw88261: only check PLL and clock state at power-up
- hwmon: (max6621) fix negative temperature offset and crit readings
- hwmon: (max6621) fix temperature clamp range
- i2c: mxs: fix DMA channel leak on probe error
- ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()
- lockd: pin next file across nlm_inspect_file lock-drop
- lockd: fix NULL dereference on lockowner allocation failure
- lockd: fix swapped arguments in nlmsvc_match_ip()
- nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in error
path
- nvme: zero the discard fallback page
- nvme-pci: disable controller on admin queue IRQ setup failure
- nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
- nvme-tcp: fix host memory disclosure on R2T for a read command
- nvme-tcp: reject a read that transferred too few bytes
- sctp: stop processing a packet once its association is deleted
- sctp: drop a chunk if its transport was removed
- sctp: fix NULL deref on untransmitted RECONF completion
- sctp: distinguish sequence zero from wildcard in reconf lookup
- sctp: fix stream->outcnt underflow on duplicate RECONF responses
- power: supply: bq24257: fix use-after-free on remove
- power: supply: bq256xx: drain usb_work before freeing the charger
- power: supply: bq25890: Fix power_supply reference leak
- power: supply: charger-manager: register regulators before exposing
sysfs
- power: supply: cros_usbpd-charger: bound the EC-reported port count
- power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS
- power: supply: lp8727: fix use-after-free in lp8727_release_irq()
- power: supply: lp8788-charger: fix use-after-free on remove
- power: supply: pf1550: enable charging when battery profile exists
- power: supply: qcom_battmgr: fix use-after-free
- power: supply: qcom_battmgr: terminate the strings from firmware
- power: supply: rt9455: quiesce delayed work before teardown
- power: supply: twl4030_charger: cancel workers via devm
- power: supply: ucs1002: fix use-after-free on remove
- power: supply: max17040: propagate register read errors
- power: supply: max17040: drop incorrect I2C functionality check
- power: supply: max17040: synchronize work cancellation on suspend
- s390/dasd: Do not complete a failed ESE read as successful
- s390/dasd: Guard sysfs discipline callbacks against unallocated private
data
- s390/dasd: Propagate partial completion length across ERP recovery
- PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip
- PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk
- PCI: meson: Fix GPIO state while requesting PERST#
- PCI: starfive: Fix resource leaks on error paths in host_init()
- PCI: plda: Fix use-after-free of event IRQs during teardown
- PCI: plda: Fix IRQ domain leaks in the error paths of
plda_init_interrupts()
- PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608]
- PCI/sysfs: Fix read byte order in pci_read_legacy_io()
- PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses
- PCI/AER: Emit TLP Log only for unmasked errors
- PCI/AER: Fix mapping of errors to agent & layer
- PCI/MSI: Enable memory decoding before restoring MSI-X messages
- PCI/proc: Avoid spurious runtime PM wakeup on config space accesses
- PCI/proc: Use file_ns_capable() when checking config space read access
- PCI/proc: Warn on writes to kernel-exclusive config space regions
- iommu/amd: Put PCI device after handling PPR faults
- iommu/msm: Unwind probe state on registration failure
- iommu/sva: Set handle->dev before the SVA handle is visible
- iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field
- iommu/arm-smmu-v3: Add HAFT support for SVA
- iommu/arm-smmu-v3: Manage teardown with devm
- iommu: Fix dev_iommu memory leak when device_add fails in
iommu_mock_device_add
- iommu/vt-d: Fix no_iommu to disable platform opt-in
- iommu/vt-d: Force requesting ACS when tboot is enabled
- iommupt: Return zero for invalid iova_to_phys() ranges
- iommufd: Avoid locking internal accesses during unmap
- iommufd: Release current IOAS on xa_store() failure
- iommufd: Fix UAF in selftest IOPF reporting
- platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer
- platform/x86: ISST: Validate level in perf mask ioctls
- platform/x86: ISST: Validate socket ID in clos_assoc ioctl
- mmc: via-sdmmc: cancel card-detect work on remove
- mmc: via-sdmmc: stop card-detect handling on probe failure
- platform/x86: ISST: Add a NULL check for sst_inst[]
- platform/x86: ISST: Just allow 2 bits for SST feature enable
- platform/x86: ISST: Use PP level enable mask
- platform/x86: ISST: Validate logical CPU id and clos id
- platform/x86: ISST: Validate max level for set feature
- platform/x86: ISST: Validate parameter for core power state
- platform/x86: ISST: Validate parameter for frequency and priority
- platform/x86: ISST: Return error during profile addition
- platform/x86: int1092: Fix potential memory leak in sar_probe()
- platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe
error path
- platform/x86: lenovo/ymc: Only match lower byte in WMI lid switch query
response
- platform/x86: think-lmi: Fix certificate thumbprint sysfs output
- platform/x86: think-lmi: Free system certificate signatures
- platform/x86: think-lmi: Fix current password length check
- platform/chrome: sensorhub: Bound the EC-reported sensor number
- platform/x86/amd/pmc: Restore msg_port on amd_stb_s2d_init() error paths
- platform/x86/amd/pmc: Propagate SMU errors and validate S2D address
- platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails
- platform/x86/amd/pmc: Fix msg_port restoration in
amd_stb_debugfs_open_v2()
- platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP
BIOS
- platform/x86: hp-bioscfg: advance elem past consumed array elements
- platform/x86: hp-bioscfg: bound ordered-list parsing by the package
count
- platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and
kek_store()
- platform/x86: hp-bioscfg: fix heap OOB read on empty password write
- platform/x86: hp-bioscfg: fix new_password_store() overwriting
current_password
- platform/x86: hp-bioscfg: fix off-by-one write in
hp_get_string_from_buffer()
- platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed
- platform/x86: hp-bioscfg: pass validated element count to package
parsers
- platform/x86: hp-bioscfg: warn on element type mismatch instead of
failing
- io_uring/waitid: honor task_work cancellation
- io_uring/waitid: avoid siginfo copy during ring teardown
- io_uring/query: cap user size passed to copy_struct_to_user
- interconnect: Fix use after free in icc_get() and of_icc_get_by_index()
- ipmi: ipmb: validate write message length
- ipmi: Remove all sysfs files on registration failure
- ipmi: si: Fix NULL pointer dereference after failed registration
- ipmi:msghandler: Cancel work cleanly on an error
- net/iucv: filter frames in afiucv_hs_rcv() by ingress device
- xdp: fix zero-copy frame layout
- slip: fix use-after-free in sl_sync()
- net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition
- net: tun: bound receive headroom
- net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO
- net: ibm: emac: mal: fix NAPI locking
- net: ipa: fix stalled modem TX queue after runtime resume
- net: l2tp: do not propagate multicast notification errors
- net: openvswitch: fix flow mask use-after-free on flow deletion
- net: openvswitch: fix nf_connlabels leak in ovs_ct_init
- net: phylink: correctly validate returned PCS in phylink_inband_caps
- net: ravb: avoid dereferencing an invalid PTP clock
- net: ravb: serialize PTP clock teardown
- net: thunderbolt: Release the Rx HopID that was handed out on mismatch
- net: thunderbolt: Mark the connection down when bringing it up fails
- NTB: ntb_transport: Recycle TX entries before client callbacks
- NTB: ntb_transport: Fail TX enqueue when the QP link is down
- NTB: ntb_transport: Reject oversized TX buffers
- net: ntb_netdev: Fix TX busy and drop handling
- net: ntb_netdev: Avoid double-accounting netif_rx() drops
- net: ntb_netdev: Count packets dropped on RX refill failure
- net/mlx5e: SHAMPO, Always calculate page size
- net/mlx5e: do not HW-GRO coalesce small frames
- net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages
- net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry
- net/smc: do not dereference an unset send buffer on the SMC-D teardown
path
- net/smc: fix socket refcount leak in smc_switch_conns()
- net/smc: fix use-after-free in smc_rx_pipe_buf_release()
- net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link()
- net/smc: stop killed, freed and out_of_sync sharing a byte
- net/smc: unregister the connection before draining the rx tasklet
- net: cap advertised IP tunnel headroom
- net: fix spurious TX timeout after dev_activate()
- net: skbuff: don't touch shared zerocopy state in skb_tx_error()
- seg6: reset IP6CB after IPv6 decapsulation
- hwrng: stm32 - Fix runtime PM cleanup on registration failure
- mfd: cgbc: Fix teardown ordering in cgbc_remove()
- mfd: qnap-mcu: keep the reply buffer alive past a command timeout
- mfd: sm501: Fix potential memory leaks during remove
- ALSA: 6fire: bound the MIDI event length from the device
- ALSA: aloop: Check card index validity at probe
- ALSA: bcd2000: clear the URB pointers on disconnect
- ALSA: FCP: do not copy out an uninitialised init response
- ALSA: hda/ext: preserve PPLCCTL bits when clearing reset
- ALSA: mpu401: Check card index validity at probe
- ALSA: mts64: Check card index validity at probe
- ALSA: pcxhr: initialize mutexes before requesting threaded IRQ
- ALSA: portman2x4: Check card index validity at probe
- ALSA: serial-u16550: Check card index validity at probe
- ALSA: virmidi: Check card index validity at probe
- ALSA: hda/realtek: Add quirk for TongFang XxAF5xxx
- ALSA: hda/realtek: Enable micmute LED on HP EliteBook 6 G1a p/n:
AD3Q9ET#UUG
- ALSA: hda/realtek: Fix Lenovo Yoga Slim 7 14AKP10 quirk ordering
- arch_numa: avoid false positive fortify warning in
setup_node_to_cpumask_map()
- dm-stats: fix a crash if allocation of per-cpu data fails
- dm-switch: use WRITE_ONCE() in switch_region_table_write()
- dm-pcache: validate geometry fields from on-disk cache_info
- dm-pcache: validate kset key_num and intra-segment bounds
- dm-pcache: validate on-media seg_num against the cache device size
- dm-pcache: bound the persisted tail-position offset
- dm-pcache: clamp the tail kset read to the segment data region
- dm-pcache: detect a cycle in the last-kset chain during replay
- dm-pcache: only hand out initialized cache segments
- dm-pcache: fix implicit u8 truncation of gc_percent in message handler
- dm-pcache: fix use-after-free and invalid seg operations in
kset_replay()
- i3c: Fix unlocked dereference of dev->desc in
i3c_device_get_supported_xfer_mode()
- i3c: master: adi: initialize the lock before enabling interrupts
- i3c: master: Fix info leak and UAF in device unregister path
- i3c: master: svc: bound IBI payload to the requested max_payload_len
- i3c: renesas: Check that the transfer is valid before accessing it
- i3c: renesas: Clean DATBAS register on detach
- i3c: renesas: Follow the reset deassert order used in probe
- i3c: renesas: Reconfigure the DATBAS register on re-attach
- i3c: renesas: Reset the controller on resume
- i3c: renesas: Restore STDBR and EXTBR registers on resume
- i3c: renesas: Perform Dynamic Address Assignment on resume
- wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()
- wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()
- wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop
- fuse-uring: refactor io-uring header copying to ring
- fuse-uring: refactor io-uring header copying from ring
- fuse-uring: use enum types for header copying
- fuse-uring: refactor setting up copy state for payload copying
- fuse-uring: use named constants for io-uring iovec indices
- fuse: copy request headers via a stack buffer for io-uring
- crypto: iaa - unmap dst before software fallback on decompress
- crypto: atmel-ecc - clean up and improve ECDH comments
- crypto: atmel-ecc - avoid stale fallback key after set_secret failure
- mm/kmemleak: stop the task stack scan early when interrupted
- mm/kmemleak: report RCU-tasks quiescent states during the scan
- wifi: mwifiex: Detach sync cmd buffer on interrupted wait
- wifi: rtl818x: initialize eeprom_93cx6 struct to zero
- wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids
- wifi: rtlwifi: rtl8192du: Fix possible memory leak in
rtl92du_init_sw_vars()
- wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()
- wifi: rtw88: pci: fix resource leak on failed NAPI setup
- wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on
reboot
- wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex
- wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE
copy
- wifi: mt76: mt7925: cancel mlo_pm_work on stop
- wifi: mt76: add external EEPROM support for mt799x chipsets
- wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE
copy
- wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames
- wifi: mt76: mt7996: validate default EEPROM firmware size
- vsock/virtio: flush works in dependency order
- w1: ds28e17: reject an oversize length on an I2C block read
- xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc()
- zloop: truncate finished zones to zone capacity
- tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout
- sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]
- sticon/parisc: Detect default STI graphics card for console output
- signal: avoid shared siginfo namespace rewrites
- smack: fix cred UAF in smack_file_send_sigiotask()
- taskstats: fix cpumask parsing cutting off the last character
- timekeeping: Check the return value of tk_get_aux_ts64 in
__do_adjtimex()
- timer: Keep debugobjects state consistent in migrate_timer_list()
- udf: Fix i_lenExtents truncation on 32-bit kernels
- selftests/mm: fix on-fault-limit false failure under sudo-rs
- resource: Add __resource_contains_unbound() for internal contains checks
- ACPI: scan: Do not combine resources that overlap completely
- platform/chrome: sensorhub: Fix dropped timestamp events and log spam
- Upstream stable to v6.18.49, v6.18.50, v7.2.2, v7.2.3, v7.2.4
* Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
CVE-2026-80724
- ptp: vmclock: prevent read-only mappings from becoming writable
* Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
CVE-2026-80914
- Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready
* Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
CVE-2026-80833
- crypto: sun8i-ss - Remove crypto_rng interface
* Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
CVE-2026-80834
- crypto: sun8i-ce - Remove crypto_rng interface
* Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
CVE-2026-80925
- vlan: fix skb_under_panic and races when toggling HW VLAN offload
* Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
CVE-2026-80857
- fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free
* Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
CVE-2026-80858
- fuse: publish io-uring queues with release semantics
* Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
CVE-2026-80859
- fuse: fix missing barrier when checking io-uring readiness
* Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
CVE-2026-80860
- fuse: fix race between interrupt and resend
* [SRU] Add support for amd-pmf AMDI0112 ID (LP: #2165251)
- SAUCE: platform/x86/amd/pmf: Add AMDI0112 ACPI ID
* Backport: "mm/gup: fix GUP-fast fallback for NULL-mapping order-0 folios"
(LP: #2162917)
- mm/gup: fix GUP-fast fallback for NULL-mapping order-0 folios
* Bluetooth: btmtk: Declare MT7920 (MT7961 1a) Bluetooth firmware
(LP: #2166944)
- Bluetooth: btmtk: Declare MT7920 (MT7961 1a) Bluetooth firmware
* System cannot enter s0ix suspend on Dell with RTL8116AF ethernet
(LP: #2160475)
- Revert "UBUNTU: SAUCE: r8169: add quirk for RTL8116af SerDes"
- SAUCE: r8169: add speed in private struct
- SAUCE: net: phy: phylink: add helper to modify pause
- SAUCE: r8169: add support for phylink
- SAUCE: r8169: add support for RTL8116af
- SAUCE: r8169: add support for RTL8127atf
- SAUCE: r8169: add ltr support for RTL8117 series
- SAUCE: r8169: fix RTL8116af can not enter s0idle and c10
* net:rtnetlink.sh in ubuntu_kselftests_net failed with ipsec_offload on
resolute (7.0.0-38.38) generic s390x (LP: #2166631)
- SAUCE: Fix selftest/net/rtnetlink.sh for Big Endian
* [UBUNTU 24.04] kernel: CPU hotplug unsupported by CPUMF (LP: #2165732)
- s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
* [Ubuntu 26.04] Failed install OS onto JBOD disk on B540d-2HS M.2
controller (LP: #2148534)
- scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame
* New 7.0 ubuntu_kselftests_net/net:tun tests flaky (LP: #2158217)
- SAUCE: selftests/net: Run tun tests in a dedicated network namespace
* ThinkPad X9-15 Gen 1: IPU7 camera probe fails — duplicate software_node
SONY471A-0 (-EEXIST), bridge init failed (LP: #2158540)
- SAUCE: media: ipu-bridge: drop duplicate IMX471 sensor config
* append bpf to CONFIG_LSM (LP: #2166235)
- [Config] append bpf to CONFIG_LSM
* Add a linux-main-modules dependency toggle to kernel build process
(LP: #2166181)
- [packaging] Create a linux-main-modules dependency toggle
* Resolute update: upstream stable patchset 2026-09-04 (LP: #2166517)
- RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
- RDMA/rxe: Fix OOB in free_rd_atomic_resources()
- KVM: x86/mmu: Check write tracking in all address spaces
- nvme-tcp: fix usage of page_frag_cache
- Revert "selinux: reject a permission value exceeding the class
permission count"
- selinux: use u16 for security classes
- selinux: more strict policy parsing
- selinux: reject a permission value exceeding the class permission count
- selinux: require a class's permission values to cover its permission
count
- selinux: switch two allocations to use kzalloc_objs()
- veth: fix OOB txq access in veth_poll() with asymmetric queue counts
- ksmbd: harden file lifetime during session teardown
- fpga: dfl: fme: add error handling
- accessibility: speakup: unregister tty ldisc on later init failures
- usb: xhci: Handle bogus TRB pointers in Missed Service Error events
- usb: xhci: Handle USB3 port events when there is one roothub
- xhci: dbgtty: Fix unregister on tty_register_driver() failure
- xhci: dbgtty: Fix unregister on tty_alloc_driver() failure
- fuse: fix invalidate lock leak on setattr writeback failure
- fuse: fix invalidate lock leak on open O_TRUNC DAX failure
- usb: usbtest: disable dynamic ID support
- usb: gadget: f_tcm: keep port count until LUN teardown completes
- KVM: SEV: Drop FOLL_WRITE for encrypted region registration
- KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests
- KVM: SEV: Extract loading of guest-provided VMSA to a separate helper
- KVM: SEV: Mark vCPU RUNNABLE after AP_CREATE, even if VMSA is unusable
- KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if
CONFIG_KVM_AMD_SEV=y
- tls: device: fix out-of-bounds write in tls_append_frag()
- gtp: serialize PDP context updates
- x86/CPU/AMD: Carve out a Zen5 models range
- net/tcp: fix TCP-AO key deletion in VRFs
- tcp: fix AO info use-after-free in tcp_ao_connect_init()
- net/tcp-ao: fix use-after-free of current_key on reconnect to another
peer
- xfrm: espintcp: fix UAF during close
- xfrm: drop ESP-in-TCP packets with no ingress device
- xfrm: avoid lock inversion in nat keepalive work
- xfrm: ah6: validate routing header segments_left
- xfrm: fix xfrm_state_construct() auth-trunc leak
- xfrm: bound nat keepalive state collection
- net: bridge: mcast: fix use-after-free of a master VLAN's multicast
context
- ipv6: seg6: clear IPv4 control block on IPIP decapsulation
- batman-adv: reject unrepresentable multicast TVLV offsets
- vxlan: keep the last remote linked during FDB flush
- netfilter: nft_set_pipapo_avx2: add missing vzeroupper
- netfilter: nf_tables: don't queue packet path object notifications
- mm/swap: reject swapon() on filesystem-level encrypted files
- kunit: irq: Continue increasing hrtimer interval for longer
- crypto: virtio - bound the akcipher result length
- crypto: qcom-rng - Enable clock in hwrng case
- crypto: qcom-rng - Remove crypto_rng interface
- crypto: qcom-rng - Allow zero as a random number
- crypto: atmel-tdes - use scatterlist length before DMA mapping
- crypto: krb5 - use kfree_sensitive() for derived key buffers
- crypto: qce - fix CCM AAD buffer underallocation
- crypto: mxs-dcp - fix source scatterlist length access
- crypto: qce - Remove unsafe/deprecated algorithms
- KVM: s390: vsie: zero stale crypto bits
- usb: core: Add lock to usb_wakeup_notification()
- usb: core: Strengthen error handling in hub_hub_status()
- ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
- ALSA: usb-audio: Complete cleanup after system-resume errors
- USB: serial: option: fix slab OOB read in interrupt URB callback
- USB: serial: spcp8x5: drop broken carrier detect support
- USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
- wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb
- usb: usbfs: fix use-after-free of usb_device in usbdev_release()
- usb: xhci: bail out of setup if the controller is inaccessible
- net: advertise TCP MSS from the configured MTU, not the learned PMTU
- tcp: clamp route advmss to TCP_MIN_MSS
- net/packet: defer vmalloc TX_RING free until skbs finish
- crypto: iaa - fall back to software for multi-entry scatterlists
- Upstream stable to v6.18.49, v7.1.13
* Resolute update: upstream stable patchset 2026-09-03 (LP: #2166363)
- xfs: add a xchk_ip_set_corrupt helper
- xfs: rtsummary scrub should treat rtbitmap corruption errors as an xref
error
- xfs: hoist per-bucket unlinked list check to helper
- xfs: don't livelock in scrub on a circular unlinked list
- PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
- Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept
- iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown
- iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process
when racing with iopt_map_file_pages
- ALSA: FCP: Use a private URB for the notification endpoint
- ALSA: scarlett2: Use a private URB for the notification endpoint
- rndis_host: add overflow check in rndis_rx_fixup()
- nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()
- io_uring/futex: don't mark futex wake requests as inflight
- ALSA: dummy: Check card index validity at probe
- io_uring/cmd: fix iovec leak when the async cmd is not recycled
- io_uring/io-wq: fix worker accounting when canceling creation callbacks
- io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec()
- io_uring/uring_cmd: don't skip completion for a synchronous multishot
cmd
- ocfs2: fix missing metadata reservation for large xattrs
- kcov: fix data corruption and race conditions on PREEMPT_RT
- ext4: stop retrying saturated xattr cache entries
- nilfs2: reject invalid block index in GC ioctl
- ext4: clear error before retrying inode xattr space fallback
- ext4: avoid tail write_begin walk for uptodate folios
- ext4: propagate errors from fast commit range replay
- ext4: don't enable DAX on new encrypted files
- ext4: fix incorrect function call when initializing s_resgid
- xfs: validate attr entry pointer before field access
- nfc: digital: clamp SENSF_RES length to the destination buffer
- nfc: fdp: bound the device-reported read length and fix an skb leak
- nfc: microread: validate target discovery payload lengths
- nfc: llcp: bound the connect_sn TLV walk to the skb
- nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
- nfc: llcp: reject PDUs shorter than the LLCP header
- nfc: pn533: purge fragmented skbs during cleanup
- nfc: st21nfca: validate ATR_REQ length against the received frame
- nfc: nci: add data_len bound checks to activation parameter extractors
- nfc: nci: fix out-of-bounds write in nci_target_auto_activated()
- nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
- nfc: nci: free destination parameters when closing a connection
- drm/xe: Fix DPT allocation paths.
- ipv4: reject undersized MTUs in ip_do_fragment()
- ipv6: fix use-after-free in ip6_finish_output2()
- mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()
- dmaengine: fsl-edma: Add error handling for devm_kasprintf
- nvmet-auth: zero the AUTH_RECEIVE response buffer
- nvmet-fc: fix invalid free in LS IOD error path
- nvmet-tcp: bound SGL data length before allocating command buffers
- nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations
- nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work()
- nvmet: pci-epf: put CQ ref on create_cq mapping failure
- mptcp: pm: use for_each_subflow helper
- mptcp: pm: rename add_entry structure to add_addr
- mptcp: pm: uniform announced addresses helpers
- mptcp: pm: fix memory leak from alloc-during-teardown race
- HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad
USB-C
- HID: magicmouse: re-enable multitouch after reset-resume
- HID: magicmouse: do not keep a stale msc->input if no input is claimed
- HID: magicmouse: Prevent out-of-bounds (OOB) read during
DOUBLE_REPORT_ID
- HID: core: fix OOB read of field->usage in hid_set_field()
- HID: pidff: fix OOB write when hid->inputs is empty
- net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
- futex/pi: Reject cross-mm private futex owners
- futex: Sanitize and document task_struct::futex::state transitions
- futex/pi: Plug private futex exec() race
- futex: Fix race on the initial mm->futex.phash.ref allocation
- futex: Fix might_sleep() warning in futex_pivot_pending()
- HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
- HID: nintendo: register input device after capabilities are set
- HID: nintendo: stop device IO before hid_hw_stop on probe failure
- HID: core: fix number/pointer type confusion on long items
- HID: sensor: custom: Fix use-after-free in enable_sensor
- HID: uclogic: fix use-after-free of inrange_timer on remove
- HID: hyperv: validate initial device info bounds
- Bluetooth: hci_event: fix LE list UAF on reset
- Bluetooth: hci_event: validate LE Set CIG Parameters response
- Bluetooth: hci_sync: Fix accept list UAF during suspend
- Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync
- Bluetooth: ISO: zero the sockaddr before returning it in getname
- Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255
- Bluetooth: hci_aml: validate firmware segment lengths
- futex: Avoid private hash use-after-free on final put
- io_uring/futex: only mark private futex waits as inflight
- io_uring: switch struct io_ring_ctx internal bitfields to flags
- io_uring: defer eventfd signaling when queued from a wakeup handler
- xfs: restore nofs context unconditionally in xfs_trans_roll
- fbdev: Wrap user-invoked calls to fb_set_var() in helper
- fbdev: serialize mode sysfs access with lock_fb_info()
- HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
- HID: asus: fix missing hid_is_usb() check
- HID: rapoo: fix missing hid_is_usb() check
- HID: ft260: fix stack-use-after-return write in I2C read race
- HID: input: read battery capacity from its actual report offset
- Upstream stable to v6.18.47, v6.18.48, v7.1.11, v7.1.12
* Resolute update: upstream stable patchset 2026-09-03 (LP: #2166363) //
CVE-2026-80590
- inet: frags: strip GSO state from fragments before reassembly
* Resolute update: upstream stable patchset 2026-09-03 (LP: #2166363) //
CVE-2026-80724
- ptp: vmclock: prevent read-only mappings from becoming writable
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029)
- mount: honour SB_NOUSER in the new mount API
- sched/fair: Revert 6d71a9c61604 ("sched/fair: Fix EEVDF entity placement
bug causing scheduling lag")
- selftests/bpf: Fail unbound UDP on sockmap update
- drm/amd/display: Add AV mute wait frames to dce110_set_avmute
- drm/amd/display: Check for tg ops in dce110_set_avmute
- arm64: dts: qcom: purwa: Fix GPU IOMMU property
- arm64: dts: qcom: sdm850-lenovo-yoga-c630: lower PSCI cluster idle
- arm64: dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer
- ARM: npcm: Fix OF node refcount leaks in SMP setup
- selftests/sched_ext: Handle sleeping task affinity changes in numa test
- pinctrl: qcom: ipq806x: mark gpio as a GPIO pin function
- pinctrl: qcom: ipq806x: mark pci reset as a GPIO pin function
- ovpn: add missing rtnl_link_ops->get_size callback
- ARM: dts: BCM5301X: fix PCIe controller 2 second interrupt
- ovpn: rehash peer in by_transp_addr table on CMD_PEER_SET
- ovpn: ensure socket is owned by ovpn before deref sk_user_data
- ovpn: zero-initialize sockaddr before learning a floated endpoint
- ovpn: hash floated peer by transport identity only
- ovpn: disable IPv4 redirects on MP interfaces
- ovpn: ensure TCP vars are initialized first
- ovpn: fix incorrect use of rcu_access_pointer()
- drm/bridge: ps8640: propagate AUX transfer register errors
- net: hns3: fix speed configuration residue after driver reload
- Revert "net: thunderbolt: Enable end-to-end flow control also in
transmit"
- net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock
- pds_core: keep the health thread stopped during reset
- pds_core: cancel pending PCI reset work on AER recovery
- netfilter: ipset: switch ext_size to atomic64_t
- ipvs: return the csum validation for forward hook
- watchdog: bd96801_wdt: Fix timeout for enabled WDG
- bpf: split check_reg_sane_offset() in two parts
- bpf: Propagate untrusted pointer state in commuted arithmetic
- net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete
- counter: microchip-tcb-capture: Fix DT channel validation
- vhost/vdpa: reject overflowing PA map page counts on 32-bit
- hwmon: (pmbus_core) Use guard() for mutex protection
- tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss()
- bnxt: fix memory leak in bnxt_queue_mem_alloc error cases
- xsk: pass TX metadata pointer by reference
- xsk: move xsk_tx_metadata_request() to xdp_sock_drv.h
- drm/xe/uc: Apply RCS/CCS yield policy to SR-IOV VFs
- hwmon: (nzxt-smart2) Check return value of init_device() in probe
- hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations
- selftests/ftrace: refactor eprobes test to fix argument checks
- net: stmmac: resume PHY before hardware setup when opening the interface
- bnge: use int for bnge_fix_rings_count() return value
- bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss()
- bnxt_en: Determine and store default RX ring in vnic structure
- bnxt_en: Refresh VNIC default ring on queue restart if needed
- bnxt_en: Fix PTP PPS setting bug
- sctp: fix addip_serial increment on ASCONF_ACK allocation failure
- net: remove WARN_ON_ONCE() from sk_mc_loop()
- ata: pata_sl82c105: fix bridge revision use-after-free
- bnge: Fix resource leak in bnge_init_nic() error path
- tls: don't abort the connection on signal-interrupted sends
- hwmon: (corsair-psu) fix possible out-of-bounds access on missing string
termination
- hwmon: (ads7828) Fix external VREF regulator handling
- hwmon: (ltc4282) Avoid overflow in maximum power calculation
- hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt
- usb: core: Add quirk for 255-bytes initial config read
- usb: quirks: Add ShanWan gamepad to quirk list
- thunderbolt: icm: Preserve USB4 proxy data-valid bit
- usb: cdnsp: fix incorrect endian conversions for APB timeout register
- ipvs: add totalconns for dest
- ipvs: properly update the overload flag on dest edit
- net: octeontx2-pf: Fix UB in shift operation
- net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header
- KVM: s390: pci: Fix aisb calculation
- dt-bindings: crypto: qcom,ice: Fix missing power-domain and iface clk
- Bluetooth: btrtl: fix RTL8761B/BU broken LE extended scan
- Bluetooth: btusb: Add TP-Link UB600 for Realtek 8761BUV
- selftests/bpf: Ensure UDP sockets are bound
- selftests/bpf: Adapt sockmap update error handling
- mei: pull kvfree out of spinlock
- nvmem: apple-spmi-nvmem: wrap regmap calls to satisfy CFI
- nvmem: layouts: Add fixed-layout driver
- rust_binder: do not query current thread for all ioctls
- serial: amba-pl011: fix indefinite RS485 post-send delay
- serial: amba-pl011: synchronize DMA teardown
- misc: fastrpc: Fix initial memory allocation for Audio PD memory pool
- misc: fastrpc: fix channel ctx ref leak when session alloc fails
- misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free
- ring-buffer: Fix crash passing ERR_PTR to kthread_stop()
- mm/damon: adjust isolated pages stat for DAMOS_MIGRATE_{HOT,COLD}
- ALSA: usb: Fix UAF at delayed release of MIDI2 EPs
- ALSA: hda/tas2781: fix ACPI reference handling
- net: phy: mediatek: fix TX blink masks using the RX bits
- arm64: remove redundant concurrent ptdump UAF mitigation
- x86/CPU: Add a tlbi= cmdline switch
- x86/mce: Set up the polling timer before CMCI discovery
- KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow
page
- sched/psi: Create the psimon kthread outside of cgroup_mutex
- fsverity: Fix silent truncation in bpf_get_fsverity_digest()
- scsi: scsi_debug: Negate wrapped memcmp() result
- thunderbolt: Fix bandwidth group reservation indexing
- netfilter: flowtable: ensure sufficient headroom in xmit path
- arm64: dts: qcom: monaco: Add default GIC address cells
- NFS: Decrement refcounts if allocating nfs_free_stateid_data fails
- btrfs: lzo: add error message for invalid headers
- btrfs: initialize inode mapping flags for cached inodes
- hwmon: (pmbus/core) Avoid race condition during probe
- bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie
- net: qrtr: ns: Raise lookup limit to 128
- hwmon: Support guard() and scoped_guard for subsystem locks
- hwmon: (corsair-psu) serialize debugfs access against hwmon
- usbnet: cap max_mtu for drivers without bind callback
- ipvs: separate destination availability state
- selftests/xsk: fix too-many-frags multi-buffer Tx test
- selftests/xsk: account reclaimed invalid Tx descriptors
- serial: sc16is7xx: enable THRI before filling TX FIFO
- mm/huge_memory: initialise workingset state before folio split
- net: ntb_netdev: Introduce per-queue context
- smb: client: fix SMB1 TRANS2 multi-response truncation in SendReceive()
- ring-buffer: Prevent resizing of persistent ring buffer
- Revert "thermal: hwmon: Register a hwmon device for each thermal zone"
- selinux: require every boolean value to be defined
- selinux: reject a class permission count below its inherited common
- selinux: do not cancel a policy conversion that never started
- selinux: reject an unclaimed class value in security_get_classes()
- selinux: reject a permission value exceeding the class permission count
- selftests: mptcp: join: mark tests with data corruption as failed
- mptcp: pm: fix data race in add_addr timer callback
- ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked()
- ASoC: cs4265: sort the register default table
- ASoC: cs35l45: sort the register default table
- ASoC: cs35l41: sort the register default table
- ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses
- drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12
- drm/amdgpu: fix JPEG v5.0.0 queue reset failure in DPG mode
- drm/amdgpu: fix JPEG v4.0.5 queue reset failure in DPG mode
- drm/amdgpu: fix aperture iounmap skipped on device removal
- ASoC: SOF: topology: Use acpi mach from the machine driver
- Input: xpad - add support for ZENAIM LEVERLESS
- powerpc/pseries: pci - logic bug
- Input: synaptics-rmi4 - fix F55 transmitter electrode count typo
- Input: psxpad-spi - set driver data before use
- Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal
keyboard
- powerpc/pseries: lparcfg - fix kbuf[] underflow
- crypto: starfive - use scatterlist length before DMA mapping
- selftests/ftrace: Convert ELF entry point to file offset in uprobe test
- gve: fix zero-length skb frag with header-split
- pmdomain: arm: Fix -EINVAL from scmi_pd_set_perf_state() on state 0
- ftrace: Protect direct_functions in ftrace_find_rec_direct
- ftrace: Fix off-by-one fentry site disable in ftrace_free_mem()
- Input: sur40 - fix V4L error path cleanup
- ceph: fix MDS random selection readiness predicate
- libceph: tolerate addrvecs with multiple entries of the same type
- mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit
- mmc: sdhci: unmap the bounce buffer before device release
- pmdomain: mediatek: fix remaining %pOF after of_node_put()
- mmc: sdhci: make tuning_err a signed int
- pmdomains: mediatek: Avoid setting RTFF's CLK_DIS before NRESTORE
- drm/connector/hdmi: Fix out of bounds memory read
- mmc: loongson2: Fix sg iteration in data reorder functions
- pmdomain: mediatek: Fix mt8183 hang on boot
- drm/xe: Order ring writes before ring tail updates
- drm/xe: Fix xe_device_probe() failure
- drm/radeon: fix autosuspend cleanup during teardown
- s390/vfio_ccw: Calculate idal length based on idaw type
- s390/zcrypt: Fix CPRB memory allocation in zcrypt misc code
- drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix
- drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE
- drm/amdgpu: Reject UVD message with invalid number of h265 refs
- drm/amdgpu: fix nbif 6.3.1 l1 low power not functional
- drm/amdgpu: check ASPM on the dGPU host link
- drm/amdgpu: Reject UVD message with dimensions above 4096
- drm/amdgpu: Fix UVD min buffer sizes
- drm/amdgpu: Fix UVD dpb min size calculation for H264
- xfs: mark nonzero sb_gquotino as corrupt on metadir filesystems
- xfs: clear zapped attr fork state when bmap repair finds no attr fork
- xfs: check cowextsize in xrep_inode_cowextsize
- xfs: fix transaction block reservation in xrep_rtbitmap
- xfs: zero i_nlink before repair puts inode on unlinked list
- xfs: only check mergeability of bnobt records
- xfs: set the prev pointer when reinserting an inode on the unlinked list
- xfs: pass runtime errors from xrep_iunlink_mark_ondisk_rec up to callers
- xfs: nlink scrub must take IOLOCK before determining ILOCK state
- xfs: load next_agino from the correct xfarray in
xrep_iunlink_relink_prev
- xfs: don't zap the attr fork on repair when there are queued pptr
updates
- xfs: fix allocated inodes that show up in the unlinked list
- xfs: don't return EFSCORRUPTED when scrubbing corrupt parent pointers
- xfs: don't ignore runtime errors in xrep_iunlink_reload_next
- xfs: check xfarray iteration errors when committing unlinked inode lists
- xfs: check v5 superblock features early
- futex: Fix race in futex_pivot_pending() during private hash resize
- sched_ext: Update p->scx.disallow warning in scx_init_task()
- sched_ext: Reorganize enable/disable path for multi-scheduler support
- ring-buffer: Store bpage pointers into subbuf_ids
- arm64: tegra: Add EL2 virtual timer interrupt for Tegra194
- crypto: ccm - Set rfc4309 maxauthsize from child
- riscv: ftrace: Fix ftrace_modify_call failure on kprobed functions
- gpio: ml-ioh: share the register lock across channels
- ASoC: tas2781: fix clang build error for goto bypassing cleanup variable
- netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort
path
- netfilter: ipset: fix list type element drift bug
- netfilter: ipset: let destroy callbacks adjust ext mem size
- eth: bnxt: cancel IRQ notifier before freeing affinity mask
- eth: bnxt: keep the aRFS rmap updated when TPH is enabled
- tcp: fix icsk_ack.ato bitfield overflow
- net: phy: realtek: fix EEE advertisement write on the internal PHY MMD
path
- net: packet: fix wrong transport_header when sending VLAN-tagged frame
- net: tap: fix wrong transport_header when sending VLAN-tagged frame
- net/tls: Fail tls_sw_splice_read() after a failed async decrypt
- ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers
- regmap: sdw-mbq: Fix swap of timeout and retry times
- af_packet: Don't send zero-byte data in tpacket_snd().
- m68k: Define NR_CPUS to 1
- accel/amdxdna: Skip unmapped range in aie2_populate_range()
- drm/xe/oa: Fix sync entry leak on OA config emit failure
- drm/log: Fix out-of-bounds read on empty message length
- drm/log: Fix infinite loop when scale is too large for display
- spi: virtio: mark device ready before registering the controller
- erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms
- ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r
- drm/amdgpu/userq: serialize queue map against GPU reset
- drm/amd: Disable DP audio spread spectrum for Cyan Skillfish
- drm/radeon: restore hardware polling in fence_is_signaled to fix
performance regression
- drm/amdgpu: fix JPEG v5.3.0 queue reset failure in DPG mode
- drm/amdgpu/gmc12.1: implement tlb inv semaphore
- drm/amdgpu/gmc12.1: fix MMHUB0 check in pasid tlb flush
- Input: atkbd - skip deactivate for HONOR ZQC-P
- pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev()
- ftrace: Protect direct_functions in update_ftrace_direct_del
- ftrace: Protect direct_functions in update_ftrace_direct_mod
- drm/xe/guc_ads: allocate UM queues in a separate BO
- drm/xe/guc_ads: allocate UM queues in VRAM on dGFX
- drm/xe/guc_ads: use uncached mapping for UM queue BO
- drm/amdgpu: fix missing check in vm_flush()
- drm/amdkfd: Add bounds check for CRAT subtype length
- net: rename netdev_ops_assert_locked()
- clk: spacemit: k3: fix USB2 bus clock
- gpiolib: Check gc->get_direction() before calling gpiod_get_direction()
- regulator: fp9931: Fix VPOS/VNEG voltage selector table
- ovpn: run deferred work on a module-owned workqueue
- tick: Include ktime.h and jiffies.h in linux/tick.h
- eth: bnxt: decrease indent in bnxt_request_irq()
- drm/xe/pxp: add termination on resume
- drm/xe/oa: Check managed mutex initialization errors
- drm/xe: Set GT rp min frequency as 1.2GHz default for BMG/CRI
- drm/xe: Fix a bug in pc_adjust_freq_bounds()
- drm/log: Fix division by zero when scale module parameter is 0
- Upstream stable to v6.18.45, v6.18.46, v7.1.9, v7.1.10
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74735
- l2tp: fix tunnel and session refcount leak on seq_file release
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74745
- eth: bnxt: avoid deadlock when canceling IRQ affinity notifier
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74747
- ipvs: revalidate ihl to prevent out-of-bounds access
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74750
- ovpn: defer key slot crypto freeing to workqueue
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74752
- sctp: validate cookie AUTH state before use
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74754
- scsi: core: pair EH runtime PM get and put
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80521
- af_unix: Unlink scc_entry in unix_del_edge().
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80523
- clk: spacemit: k3: set hdma clock as critical
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80524
- optee: ffa: Add NULL check in optee_ffa_lend_protmem
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80557
- libceph: fix OOB read in decode_watchers() via missing bounds check
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80579
- fbdev: clear fb_info->mode before deleting a videomode
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80580
- fbdev: bound mode sysfs output to the sysfs buffer
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80582
- drm/shmem_helper: Check VMA boundaries for PMD mappings
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80583
- ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74734
- firewire: ohci: fix NULL pointer dereference in ar_context_release
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74736
- net/sched: cls_bpf: reject dev-bound programs bound to a different
device
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74737
- net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74738
- regmap: sdw-mbq: don't call an unset readable_reg callback
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74739
- net/sched: cls_u32: skip hash tables in u32_bind_class()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74740
- net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74741
- net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74742
- veth: fix queue index used to wake the peer txq in veth_poll
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74743
- macvlan: inherit needed_headroom and needed_tailroom from lowerdev
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74744
- ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74746
- netfilter: flowtable: publish GC-visible tuple last
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74748
- netfilter: ipset: fix refcount race between list:set GC and swap
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74753
- perf: Reject exited events as group leaders
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80519
- ovpn: finish crypto callback cleanup before peer release
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80520
- ovpn: fix NULL dereference when killing missing key
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80522
- crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80525
- ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80526
- ASoC: tas2562: Validate values for volume writes
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80527
- ceph: fix hanging __ceph_get_caps() with stale mds_wanted
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80528
- ceph: avoid fs reclaim while using current->journal_info
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80529
- xfs: don't swallow dquot recovery verification errors
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80530
- xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80531
- xfs: avoid UAF on sc->tempip in xrep_tempfile_create
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80532
- xfs: fix another iunlink infinite loop bug in online fsck
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80533
- xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80534
- xfs: fix ilock leak on error in xfs_dq_get_next_id
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80535
- xfs: don't double-lock when deleting a self-referential directory
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80536
- xfs: bounds-check buffer log item's dirty bitmap
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80537
- xfs: fix off-by-one in rtrefcount btree root level validation
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80538
- xfs: propagate errors from xfs_rtginode_load
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80539
- drm/amdgpu: disallow multiple FENCE chunks in one submit
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80540
- drm/amdgpu: Fix UVD decode image min size calculation
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80541
- drm/amdgpu: validate GEM_CREATE domain combinations
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80542
- drm/amd/display: Fix NULL pointer dereference in
amdgpu_dm_crtc_set_vblank()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80547
- s390/vfio_ccw: Implement a crw lock
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80548
- s390/vfio_ccw: Selectively expand io_mutex
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80549
- s390/vfio_ccw: Move cp cleanup out of not operational
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80550
- s390/vfio_ccw: Fix out of bounds check on CCW array
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80551
- s390/vfio_ccw: Ensure first IDAW remains constant
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80552
- s390/vfio_ccw: Ensure index for read/write regions are within range
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80553
- s390/vfio_ccw: Cancel existing workqueues
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80554
- s390/vfio_ccw: Limit the number of channel program segments
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80555
- s390/vfio_ccw: Free all memory if cp_init() fails
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80556
- mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80558
- libceph: Avoid using invalid osd indices from primary_temp
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80559
- Input: sur40 - fix input device registration ordering
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80560
- openrisc: signal: do not restore privileged SR bits on sigreturn
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80561
- libceph: fix multiple unsafe decodes in decode_locker()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80562
- gpio: ml-ioh: use raw_spinlock_t for the register lock
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80563
- gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on
unbind
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80564
- gve: fix NULL dereference due to missing ptp adjfine
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80565
- crypto: qce - fix error path in devm_qce_register_algs
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80566
- Input: hynitron_cstxxx - validate touch count and finger IDs
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80567
- Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80568
- Input: synaptics-rmi4 - block s_input when F54 queue is busy
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80569
- Input: synaptics-rmi4 - bound the F54 report size to the allocated
buffer
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80570
- Input: synaptics-rmi4 - zero report size on F54 work error
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80571
- powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80572
- Input: byd - synchronize timer deletion before freeing private data
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80573
- Input: iforce - validate input packet lengths
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80574
- Input: focaltech - fix array out-of-bounds in
focaltech_process_rel_packet
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80575
- Input: cs40l50-vibra - validate custom data from user space
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80576
- drm/amdgpu: reject oversized IBs with per-ring packet limits
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80577
- drm/panthor: skip zero-sized firmware sections
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80578
- fbdev: core: Fix pointer desynchronization in fb_io_read()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80581
- ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC
timeout
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80584
- s390/qeth: validate user buffer length in SNMP and ARP query ioctls
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80585
- mptcp: fastopen: only mark MPTFO subflows with SYN data
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80586
- mptcp: options: reset DSS fields in case of unexpected size
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80587
- mptcp: avoid combining some incoming suboptions
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80588
- mptcp: reclaim forward-allocated memory on RX path errors
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-80589
- block: stop the timeout timer when releasing a never added disk
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74593
- sched_ext: Take cgroup_lock() first in scx_cgroup_lock()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74596
- fs,fsverity: remove check for fsverity being enabled in
setattr_prepare()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74600
- mm/page_table_check: skip special zero mappings
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74605
- eventfs: Use children field for rcu head and add memory barriers
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74626
- NTB: ntb_netdev: Preserve RX queue depth on allocation failure
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74645
- mm/damon/lru_sort: error out for >10000 active_mem_bp
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74674
- mm: fix incorrect flush address in direct page table reclaim
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74686
- rqspinlock: Reset tail when preserving queue on deadlock
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74699
- drm/xe: Fix memory leak in exec_queue_set_hang_replay_state()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74706
- bnge: Fix NULL pointer dereference in aux device release
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74713
- vhost_iotlb: bound map allocation in add_range
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74715
- bpf: Fix netns reference imbalance in conntrack kfuncs
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74716
- accel/amdxdna: Fix locally exploitable BUG_ON in amdxdna_insert_pages()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74721
- accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74723
- btrfs: lzo: reject inline extents without valid headers
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74729
- soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74733
- gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74585
- thunderbolt: Bound the DROM dual link port number before indexing
sw->ports
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74586
- sctp: clear new_transport when removing a peer
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74587
- sctp: fix use-after-free of cached ASCONF chunk
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74588
- sctp: keep chunk->transport in step with the list it is queued on
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74589
- bpf, sockmap: Fix sk_redir use-after-free in send verdict
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74590
- fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74591
- mm/filemap: __filemap_add_folio() restore index before retrying
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74592
- ima: Instantiate file_truncate and path_truncate hooks
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74594
- sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74595
- fscrypt: use the mount idmap for the owner check in
fscrypt_ioctl_set_policy()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74597
- ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74598
- ipv6: fix Route Information option length validation
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74599
- mm/ptdump: always stabilise against page table freeing using init_mm
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74601
- ring-buffer: Use current_context for safe per-CPU buffer swap
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74602
- ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74603
- ptp: ocp: Fix board ID over-read
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74604
- Revert "thermal/drivers/hwmon: Cleanup coding style a bit"
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74606
- eventfs: Fix use-after-free in eventfs_remove_rec()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74607
- KVM: SVM: Serialize accesses to the owner and mirror list with separate
lock
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74608
- smb: client: Fix use-after-free in cifs_try_adding_channels()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74609
- tipc: read le->link under the node lock in tipc_node_link_down()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74610
- tls: don't leave a full plaintext sk_msg ring unpushed
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74611
- tls: rx: restore msg_iter before TLS 1.3 optimistic retry
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74580
- vhost: reset the vring metadata cache on vring reconfiguration
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74612
- veth: fix skb length accounting after XDP frag adjustment
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74613
- vsock/virtio: avoid refilling the RX queue after teardown
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74614
- vsock/virtio: read virtqueues under worker locks
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74615
- vxlan: do not arm the ageing timer on a device that is down
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74616
- xdp: reject clones that overrun skb_shared_info tailroom
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74617
- dibs: initialise dibs->lock in dibs_dev_alloc()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74618
- binfmt_misc: don't warn when the mount is completed from another user
namespace
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74619
- ovl: don't warn when the mount is completed from another user namespace
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74620
- net/sched: act_gact, act_police: range check the fallback control action
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74621
- net/sched: act_ct: fix sk_buff leak when the header checks reject a
packet
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74622
- net: atlantic: free RX pages of consumed but not refilled buffers
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74623
- net: atlantic: free stranded TX buffers on ring deinit
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74624
- netfilter: nf_conntrack: defer invalid log until after unlock
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74625
- netfilter: bridge: release template ct on non-IP path
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74627
- net: devmem: prevent net-iov / page mixing
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74628
- net/x25: fix use-after-free of the socket by its timers
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74629
- net/dibs: Correct freeing of dmb_clientid_arr
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74630
- ipv6: prevent in6_dev_get() from resurrecting inet6_dev
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74631
- net: smc: fix splice entry lifetime imbalance in smc_rx_splice
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74632
- mm/huge_memory: fix huge_zero_pfn race
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74633
- tracing: Fix NULL pointer dereference in module event cache removal
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74634
- ring-buffer: Prevent subbuf order change when resizing is disabled
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74635
- fbdev: bitblit: bound-check glyph index in bit_cursor()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74636
- tracing: Fix race between update_event_fields and, event_define_fields
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74637
- perf/core: Fix group leader use-after-free after sibling detach
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74638
- drm/v3d: Serialize the scheduler timeout handlers
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74639
- ALSA: us144mkii: re-anchor capture URBs on resubmission
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74640
- ALSA: FCP: fix OOB write in fcp_meter_ctl_get()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74641
- ALSA: usx2y: bound the hwdep mmap fault offset
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74643
- samples/damon/mtier: error out for zero quota goal target values
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74644
- mm/damon/ops-common: putback folios on invalid migrate nid
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74646
- misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74647
- misc: fastrpc: Remove buffer from list prior to unmap operation
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74648
- staging: rtl8723bs: validate monitor transmit frame lengths
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74649
- staging: rtl8723bs: fix missing shared-key auth challenge length check
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74650
- staging: rtl8723bs: fix OOB read in WMM_param_handler()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74651
- staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74652
- serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74653
- serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74654
- serial: 8250_dma: Clear stale RX state on shutdown
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74655
- serial: qcom-geni: fix TX DMA buffer flush
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74656
- ipv4: fix use-after-free in fib_nhc_update_mtu()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74657
- ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74658
- futex: Prevent robust futex exit race some more
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74659
- net: bridge: mrp: fix uninitialised bytes on the wire
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74660
- netfilter: ebt_nflog: pin the NFLOG backend
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74661
- mac802154: fix netdev use-after-free in beacon worker
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74662
- inet: frags: publish queues before arming timer
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74663
- net/sched: reject overly deep qdisc hierarchies
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74664
- net: openvswitch: reallocate update replies for mismatched IDs
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74665
- net: fix skb length accounting after generic XDP frag adjustment
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74666
- packet: synchronize pressure clearing with ring reconfiguration
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74667
- net/packet: reset the MAC header on the packet-socket transmit path
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74668
- packet: use consistent hard_header_len in TX_RING send path
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74582
- packet: use consistent hard_header_len in non-ring send paths
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74669
- ipvs: clear IPv4 options after rebasing tunnel ICMP errors
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74670
- ipvs: stop estimator after disabled calc phase
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74671
- ima: fix out-of-bounds read in xattr_verify()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74672
- mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74673
- Input: evdev - fix information leak in evdev_pass_values()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74675
- vt: stabilize tty reference in kbd_keycode with tty_port_tty_get
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74676
- vt: add permission check for KDSKBMETA ioctl
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74677
- net: usb: ipheth: fix carrier_work UAF on disconnect
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74678
- net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74679
- usb: gadget: f_ncm: Use unsigned int for ndp_index
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74680
- usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74681
- usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74682
- ALSA: usb-audio: fix OOB write on Type II inbound URBs
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74683
- Input: evdev - sanitize event type index when fetching event masks
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74684
- net: tap: set skb->dev before parsing virtio net header in
tap_get_user_xdp()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74685
- hwmon: (ltc4282) Clamp negative current limits
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74687
- watchdog: at91sam9_wdt: prevent timer rearm during teardown
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74688
- sctp: clear control chunk transport if it is being removed
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74689
- net/atm: fix slab-out-of-bounds read in vcc_setsockopt()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74690
- s390/ism: Fix UAF of sba and ieq during ism_dev_exit()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74691
- net: thunderbolt: Tear down DMA paths before stopping the rings
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74692
- net/smc: fix TOCTOU race between smc_listen_out() and listener close
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74693
- net: prestera: validate firmware header length
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74694
- net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74695
- netfilter: nf_flow_table: drop existing skb dst before
skb_dst_set_noref()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74696
- tcp: fix TFO max_qlen accounting across reuseport migration
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74697
- bnxt_en: Disable EOP for TPA on all chips to prevent data corruption
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74698
- net/mlx5e: fix BQL reset on SQ re-activation
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74700
- net/sched: cls_api: Always acquire rtnl_lock when destroying locked
classifiers
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74701
- net/openvswitch: check Ethernet header length in key_extract()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74702
- vhost-scsi: reject feature changes after endpoint
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74703
- vhost-scsi: Validate T10 PI scatterlist counts
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74704
- net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74705
- udp: fix potential use-after-free in tunnel segmentation
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74707
- xsk: validate metadata when processing requests
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74708
- xsk: validate launch-time metadata size
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74709
- xsk: clear metadata pointer when no timestamp is requested
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74710
- xsk: require at least 16 bytes of TX metadata
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74711
- hwmon: (pmbus) Fix type confusion in notification logic
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74712
- vdpa/mlx5: Fix buffer length in create_direct_keys()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74714
- bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74717
- net/mlx5: fw_tracer, return NULL on create error
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74718
- devlink: fix net namespace reference leak in reload
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74583
- net/sched: cls_route: fix fastmap use-after-free on filter
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74719
- net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in
smc_llc_event_handler()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74720
- bpf: Preserve pointer state for commuted arithmetic
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74722
- btrfs: fix memory leak in btrfs_do_encoded_write()
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74724
- ipvs: avoid out-of-bounds write in ip_vs_nat_icmp
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74725
- enic: fix tx_hang_reset use-after-free on device removal
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74726
- bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74727
- ovpn: skip rehash for peers already removed from by_id
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74728
- xfs: handle NULL b_addr in xfs_buf_free
* Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
CVE-2026-74730
- NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942)
- kunit: tool: skip stty when stdin is not a tty
- kunit: tool: Terminate kernel under test on SIGINT
- netfilter: br_netfilter: Reallocate headroom if necessary in
neigh_hh_bridge()
- ALSA: hda/realtek: add quirk for HP Dragonfly Folio G3 2-in-1
- HID: logitech-dj: Standardise hid_report_enum variable nomenclature
- HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB
write
- HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report
- lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled()
- pinctrl: qcom: Unconditionally mark gpio as wakeup enable
- pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151
- dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA
- gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe()
- selftests/lkdtm: rename STACKLEAK_ERASING to KSTACK_ERASE
- Revert "UBUNTU: SAUCE: selftests/seccomp fix compilation issue for
amd64"
- selftests/seccomp: Fix pointer type mismatch build error
- ata: sata_mv: accept 1 or 2 resources in platform probe
- ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources()
- phy: qcom: m31-eusb2: Fix return value of init call
- ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup
- ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup
- of: reserved_mem: prevent OOB when too many dynamic regions are defined
- btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag
- btrfs: zoned: reset meta_write_pointer on zone reset
- btrfs: raid56: fix an incorrect csum skip during scrub
- phy: zynqmp: fix clock error handling in xpsgtr_phy_init()
- phy: zynqmp: fix runtime PM leak on probe allocation failure
- drm/mediatek: Check CRTC state before freeing
- Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep
annotation
- mshv: Fix duplicate GSI detection for GSI 0
- mshv: Fix sleeping under spinlock in mshv_portid_alloc
- KVM: arm64: Reject guest_memfd memslots when the VM has MTE
- KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return
type
- assoc_array: trim the final shortcut word using the current chunk end
- ipvs: fix the checksum validations
- ipvs: fix places with wrong packet offsets
- ipvs: do not mangle ICMP replies for non-first fragments
- ASoC: SDCA: Ensure that Control Range is large enough for header
- af_unix: fix listen() succeeding on sockets in the wrong state
- selftests/net/af_unix: test listen() rejects wrong socket states
- pinctrl-amd: Don't clear S4 wake bits at probe
- smb: client: fix buffer leaks in SMB1 read and write
- ASoC: tas2781: Use correct calibration data for SINEGAIN2 register
- spi: spi-cadence: Move TX FIFO full busy-wait into FIFO
- hwmon: (ina2xx) Make it easier to add more devices
- hwmon: (ina2xx) Add support for INA234
- hwmon: (ina2xx) Shift INA234 shunt and current registers
- hwmon: (ina2xx) Fix various overflow issues
- hwmon: (ltc4282) Fix reading the minimum alarm voltage
- hwmon: (sht3x) Fix unaligned accesses
- net: bridge: mrp: fix Option TLV length in MRP_Test frames
- hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors
- hwmon: (adt7470) Fix cache updated before hardware write on I2C error
- hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read()
- hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks
- hwmon: (adt7470) Use cached PWM frequency value
- hwmon: (adt7470) Fix PWM auto temp state array and bounds check
- powerpc/boot: Fix simpleboot CPU node lookup check
- powerpc/boot: Fix treeboot-currituck CPU node lookup check
- powerpc/boot: Fix treeboot-akebono CPU node lookup check
- wifi: mac80211: validate individual TWT params before driver setup
- netfs: clear PG_private_2 on copy-to-cache append failure
- netfs: handle single writeback rolling buffer allocation failure
- netfs: release readahead folios on iterator preparation failure
- net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in
poll_controller
- hwmon: (pmbus) Fix return value from pmbus_update_byte_data()
- idpf: adjust TxQ ring count minimum
- idpf: Fix mailbox IRQ name leak on request failure
- ice: suppress DPLL errors during reset recovery
- Bluetooth: ISO: Fix data-race on iso_pi(sk) in socket and HCI event
paths
- Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos
- Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis()
- Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release
- Bluetooth: ISO: ensure no dangling hcon references in iso_conn
- Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists
- Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync
- x86/boot: Add volatile, clobbers and zero-length test in memcmp()
- net: phylink: put link_gpio if phylink_create fails
- scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE
- scsi: ufs: core: Cancel RTC work in active-active suspend
- scsi: ufs: core: Avoid IRQ thread wakeup during active UIC command
- scsi: ufs: core: Revert "Delegate the interrupt service routine to a
threaded IRQ handler"
- scsi: zfcp: Fix memory leak during adapter release by destroying
gid_pn_req
- scsi: target: Clear cmd_cnt when initial counter enrollment fails
- net: sxgbe: check descriptor ring allocation failures
- can: isotp: check register_netdevice_notifier() error in module init
- drm/i915/dp: Ignore the sink's DSC max FRL rate without a PCON DSC
encoder
- fprobe: Fix module reference count leak on error in register_fprobe()
- tracing/mmiotrace: Reset dropped_count in mmio_reset_data()
- tracing/mmiotrace: Add NULL check for mmio_trace_array in logging
functions
- riscv: drop __init from vec_check_unaligned_access_speed_all_cpus
- accel/qaic: use sizeof(*trans_hdr) for transaction length check
- net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend
- net: dsa: mt7530: error out on failed reads in MT7531 PHY polling
- ptp: netc: fix potential interrupt storm caused by incorrect unbind
order
- net: libwx: fix FDIR ATR queue mismatch for software VLAN packets
- octeontx2-pf: Set correct sequence for carrier off and tx queue stop
- sched/deadline: Use revised wakeup rule only for running dl_server
- spi: spi-nxp-fspi: add per-SoC SDR/DTR clock rate limits for all
supported SoCs
- drm/i915/hdmi: Poll for 200 msec for TMDS_Scrambler_Status
- ksmbd: return success for deferred final close
- iomap: add a separate bio_set for iomap_split_ioend
- mshv: Fix race in mshv_irqfd_deassign
- mshv: Fix level-triggered check on uninitialized data
- mshv: Order pt_vp_array publish against irqfd assertion path
- iommufd/viommu: Release the igroup lock on the vdevice_size error path
- iommufd/viommu: Publish a vDEVICE only after vdevice_init() succeeds
- iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on
replace
- pinctrl: microchip-sgpio: add missing select REGMAP_MMIO
- erofs: cap LZMA stream pool size
- [Config] Add EROFS_FS_LZMA_DEFAULT_MAX_STREAMS
- pinctrl: bm1880: add missing select GENERIC_PINCONF
- fortify: Disable -Wstringop-overread in tests
- mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE
- mm/util: don't read __page_2 for order-1 folios in snapshot_page()
- selftest: fix headers in fclog.c
- fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes
- mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()
- mm/vmstat: fold stranded per-cpu node stats when a node comes online
- tracing/probes: Reject $arg0 in meta argument expansion
- tracing/fprobe: Roll back on enable_trace_fprobe() failure
- KVM: VMX: add memory clobber to asm for VMX instructions
- KVM: s390: pci: Fix missing error codes and memory unaccounting
- KVM: s390: pci: Fix NULL dereference on AIBV allocation failure
- KVM: s390: pci: Validate AIBV and AISB before pinning guest pages
- sctp: validate Adaptation Indication parameter length
- audit: fix potential integer overflow in audit_log_n_string()
- Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req()
- Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read()
- Bluetooth: SCO: give the socket its own sco_conn reference
- bpf: lwt: Fix dst reference leak on reroute failure
- afs: Fix afs_fs_fetch_data() to set call->async
- afs: Fix afs_fs_fetch_data() to subtract transferred from len
- ALSA: hda/realtek: Add quirk for TongFang X6SP45xU
- ALSA: lx6464es: fix period byte count for 16-bit streams
- ALSA: pcm: wake linked drain waiters on unlink
- ASoC: fsl_asrc: fix m2m_init error path to use goto instead of bare
return
- ASoC: fsl_easrc: fix m2m_init error path to use goto instead of bare
return
- ASoC: tas2562: fix DVC coefficient write order
- ASoC: tas2562: fix broken entries in the volume lookup table
- ata: libata-eh: Increase STANDBY IMMEDIATE timeout
- ata: libata-sata: fix ata_scsi_lpm_supported() iteration
- dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+
- e1000: fix memory leak in e1000_probe()
- igc: remove napi_synchronize() in igc_down()
- ipvs: do not propagate one-packet flag to synced conns
- mshv: fix hv_input_get_system_property struct
- io_uring/net: initialize mshot_len for send
- mm: memcg: initialize *locked in memcg1_oom_prepare() stub
- net: ipv6: clear suppressed fib6 rule result
- powerpc/ps3: Fix map failure path in dma_ioc0_map_pages()
- vxlan: re-fetch eth header after route_shortcircuit()
- vxlan: unclone skb head before modifying eth header in
route_shortcircuit()
- tracing/filters: Fix false positive match in regex_match_full()
- spi: spi-qpic-snand: write the feature value before executing
SET_FEATURE
- spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure
- selftests/mm: fix potential wild pointer access of getline due to
missing init
- selftests/clone3: fix wild pointer access of getline due to missing init
- sctp: reject stale cookies with mismatched verification tags
- hwmon: (npcm750-pwm-fan): stop fan timer on device detach
- hwmon: (pmbus/core) notify on the hwmon device, not the i2c client
- i2c: amd-mp2: Unregister callback on adapter add failure
- gpio: pca953x: fix cache_only and IRQ state on restore_context() failure
- cifs: add fscache_resize_cookie() to cifs_setsize()
- cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init()
- cpufreq: schedutil: Publish util hooks only after all sg_cpu are
initialized
- power: supply: bq25890: fix the -10 C NTC lookup entry
- power: supply: max17040: handle missing status supplier
- s390/pci: Fix s390_pci_mmio_write syscall error return without MIO
- s390/dasd: Fix potential NULL pointer dereference
- s390/dasd: Fix undersized format-check buffer
- s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs
- s390/zcrypt: Fix missing mem scrub at clear key import in
cca_clr2cipherkey()
- phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask
- phy: zynqmp: use read-modify-write for SERDES scrambler bypass
- phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB
- net: openvswitch: fix skb leak on flow key update failure during
recirculation
- ice: fix VF interrupts cleanup
- ice: fix memory leak in ice_lbtest_prepare_rings()
- i2c: spacemit: request IRQ after controller initialization
- i2c: qcom-cci: drop custom suspend/resume and rely on runtime PM helpers
- i2c: iproc: reset bus after timeout if START_BUSY is stuck
- i2c: imx: Fix slave registration race and error handling
- can: c_can: c_can_chip_config(): keep controller in init mode until
bittiming is configured
- can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb
allocation failure
- can: j1939: transport: j1939_session_fresh_new(): initialize receive
buffer
- can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking
- can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in
kvaser_usb_hydra_get_busparams()
- can: softing: fw_parse(): validate firmware record spans
- can: ctucanfd: add missing MODULE_DEVICE_TABLE()
- can: ctucanfd: use self-test mode for PRESUME_ACK
- can: ctucanfd: unmap BAR0 using base address
- can: ctucanfd: handle bus error interrupts
- can: ctucanfd: mark error-active controller status valid
- drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs
- drm/bridge: display-connector: Fix I2C adapter resource leak
- drm/mediatek: ovl_adaptor: balance component registrations
- drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini
- drm/amdgpu: restore UMD profile pstate after runtime resume
- drm/amd/pm: fix torn gpu metrics reads
- drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames
- drm/amd/display: use proper context for logging
- drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE
- drm/amdkfd: Handle invalid event type in CRIU event restore
- drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size
- drm/vmwgfx: clamp dirty-page range with min, not max
- drm/vmwgfx: take fman->lock around fence list mutation in fifo_down
- drm/vmwgfx: drop dma_buf reference on foreign-fd prime import
- drm/vmwgfx: enforce cursor size limits for MOB cursors
- drm/vmwgfx: use check_add_overflow for shader size+offset bound
- drm/vmwgfx: validate external BO copy bounds for both stride paths
- HID: logitech-dj: Fix maxfield check in DJ short report validation
- drm/xe/rtp: Maintain OA whitelists separately
- drm/xe/rtp: Keep track of non-OA nonpriv slots
- drm/xe/rtp: Generalize whitelist_apply_to_hwe
- drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs
- drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt
- drm/xe/oa: (De-)whitelist OA registers on OA stream open/release
- drm/xe/rtp: Ensure locking/ref counting for OA whitelists
- mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()
- fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes
- net/handshake: Close the submit-side sock_hold race
- usb: typec: ucsi: split connector lock classes
- media: chips-media: wave5: Support CBP profile
- drm/xe: add xe_migrate_resolve wrapper and is_vram_resolve support
- drm/xe/bo: Add purgeable bo state tracking and field madv to xe_bo
- drm/xe/vm: Prevent binding of purged buffer objects
- drm/exec: Remove the index parameter from
drm_exec_for_each_locked_obj[_reverse]
- can: isotp: fix timer drain order, wakeup handling and tx_gen ordering
- usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path
- mm/slab: decouple SLAB_NO_SHEAVES from SLAB_NO_OBJ_EXT
- ALSA: hda/realtek: Add quirk for HP Dragonfly Folio G3 2-in-1
(103c:8a05)
- KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context
- dmaengine: idxd: fix double free of wq, engine, and group structs
- btrfs: warn about extent buffer that can not be released
- btrfs: zoned: skip fully truncated ordered extents at zone finish
- rtla/timerlat_top: Fix on-threshold actions firing on signal
- selftests: netfilter: nft_flowtable.sh: fix offload counter verification
for tunnel tests
- netfilter: nf_conntrack_expect: add and use nf_ct_expect_related_pair()
- mshv_vtl: fix fd leak in mshv_ioctl_create_vtl()
- ipvs: clear the nfct flag under lock
- ASoC: SDCA: Correct pointer passed to devm_acpi_table_put
- ASoC: SDCA: Always free firmware in FDL path
- ASoC: SDCA: Make UMP message size check more robust
- xsk: provide sufficient space in pool->tx_descs
- net/sched: sch_cake: skip clearing unused tins during rate adjustment
- erofs: clean up erofs_ishare_fill_inode()
- erofs: remove fscache backend entirely
- [Config] Remove EROFS_FS_ONDEMAND
- erofs: ensure valid f_path for page cache sharing
- ASoC: sophgo: return 1 on volume change in cv1800b_adc_volume_set()
- ethtool: Embed FEC hist ranges as buffer in struct
- idpf: bound interrupt-vector register fill to the allocated array
- Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks
- Bluetooth: hci_sync: remove unnecessary hci_conn_get in create_conn_sync
- scsi: ufs: core: Initialize hba->rpmbs list in ufshcd
- drm/xe/pt: check no-DMA huge-pte cases before DMA segment test
- ipv6: release fib6_null_entry on subtree failure
- riscv: vdso: Only try to install vDSO when present
- net: dsa: mt7530: error out on failed reads in ATC/VTCR command polling
- net: stmmac: Fix E2E delay mechanism
- net: mana: Create separate EQs for each vPort
- net: mana: Return error code from mana_create_rxq()
- mshv: Fix missing error code on VP allocation failure
- mshv: Publish VP to pt_vp_array before installing the file descriptor
- iommufd: Reject DMABUF pages from the access pin path
- btrfs: raid56: fix scrub read assembly submitting no reads
- btrfs: zoned: fix missing chunk metadata reservation
- ocfs2: fix boundary check in ocfs2_check_dir_entry() to use buffer
offset
- userfaultfd: wait on source PMD during UFFDIO_MOVE
- KVM: s390: pci: Fix resource leak on IRQ registration failure
- Bluetooth: btmtk: Fix short read errors in btmtk_usb_reg_read()
- ata: libata-scsi: terminate deferred commands on time out
- ata: libata-scsi: schedule deferred atapi command
- PCI: imx6: Keep i.MX6 Root Port MSI/MSI-X Capabilities with iMSI-RX to
work around hardware bug
- io_uring: preserve task restrictions across exec
- scsi: libsas: terminate deferred commands on time out
- scsi: ufs: dt-bindings: Add missing mcq reg for qcom,sa8255p-ufshc
- can: rcar_canfd: change the initializing flow for clocks and resets
- drm/mediatek: mtk_hdmi: Fix DDC adapter double put in v2
- drm/amd/pm: hide pp_table sysfs on APUs
- drm/amd/pm: use milliwatts for GPU power sensors
- drm/amd/display: check if dml21_add_phantom_plane() is successful
- drm/xe: Drop unused param from xe_device_create()
- drm/xe: Move xe->info.force_execlist initialization
- drm/xe: Move xe->info.devid|revid initialization
- drm/xe: Drop unnecessary goto in xe_device_create
- drm/xe: Separate early xe_device initialization
- drm/xe: Set TTM device beneficial_order to 9 (2M)
- Upstream stable to v6.18.44, v7.1.8
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74449
- drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero
viewport
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74450
- drm/amd/pm: fix pptable use-after-free
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74466
- s390/zcrypt: Close speculative mem read possibility
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74483
- binfmt_misc: don't leak the user namespace when the mount fails
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74496
- fou: Fix use-after-free in fou_create()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74517
- KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74521
- ksmbd: use memcmp() to compare ClientGUIDs
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74526
- scsi: mpi3mr: Fix potential deadlock in mpi3mr_fault_uevent_emit
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74528
- Bluetooth: hci_sync: hold conn in hci_past_sync() callback
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74529
- Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74530
- Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74533
- Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74542
- netfs: Fix folio_queue ENOMEM in writeback by adding a mempool
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74544
- net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74554
- wifi: ath12k: fix out-of-bounds clear_bit in
ath12k_mac_dp_peer_cleanup()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74558
- xsk: reclaim invalid Tx descriptors in ZC batch path
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74561
- nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74562
- nexthop: take nh->lock for f6i_list walks in replace check and notify
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74571
- btrfs: skip global block reserve accounting for rescue mounts
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74440
- drm/xe: Wait on external BO kernel fences in exec IOCTL
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
[SRU] amdgpu: Fix garbled display when switching workspaces (LP: #2166730)
- drm/amd/display: check GRPH_FLIP status before sending event
- drm/amd/display: Exit idle optimizations before programming
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74441
- usb: typec: ucsi: Fix race condition and ordering in port unregistration
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74482
- mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74442
- drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74443
- drm/vmwgfx: bound DMA command body size against suffix pointer
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74444
- drm/vmwgfx: validate DRAW_PRIMITIVES header size before division
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74445
- drm/vmwgfx: reject DX_BIND_QUERY without a DX context
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74446
- drm/amdkfd: hold event_mutex while checkpointing CRIU events
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74447
- drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74448
- drm/amdkfd: fix QID bit leak in pqm_create_queue()
* [SRU] Fix incorrect GTT calculation on the APU systems (LP: #2162038) //
Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942)
- drm/amdgpu: cap GTT size to physical RAM on APUs
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74451
- drm/panthor: validate firmware interface structure sizes
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74452
- drm/panthor: reject firmware sections with oversized data
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74453
- drm/vc4: Zero the tile state data array before each BIN job
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74454
- drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO
size
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74455
- can: peak_usb: validate uCAN receive record lengths
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74456
- can: peak_usb: peak_usb_start(): fix double free of transfer buffer on
URB submit error
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74457
- can: peak_usb: add bounds check for USB channel index
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74458
- can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received
command extents
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74459
- can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB
resubmit failure
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74460
- can: ems_usb: validate CPC message lengths
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74461
- i2c: imx: Cancel hrtimer before clearing slave pointer
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74462
- i2c: imx: mark I2C adapter when hardware is powered down
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74463
- i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock
deadlock
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74464
- net: openvswitch: fix skb leak on flow key update failure during ct
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74465
- net: openvswitch: fix potential UAF on meter attach failure
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-68451
- s390/zcrypt: Validate length for CCA ECC private key requests
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-68452
- s390/zcrypt: Validate length for CCA AES cipher key requests
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-68453
- s390/zcrypt: Fix buffer over-read in cca_cipher2protkey
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74467
- s390/qeth: Check CAP_NET_ADMIN for private ioctls
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74468
- gpio: pch: use raw_spinlock_t for the register lock
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74469
- sctp: prevent peer transport count overflow
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74470
- scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74471
- tracing: Check return value of __register_event() in
trace_module_add_events()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74472
- ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74473
- vxlan: use pskb_network_may_pull() in route_shortcircuit()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74474
- vxlan: use pskb_network_may_pull() for transmit path header pulls
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74475
- vxlan: use neigh_ha_snapshot() in route_shortcircuit()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74476
- veth: convert frag_list skbs before running XDP
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74477
- uprobes: Fix NULL pointer dereference in hprobe_expire()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74478
- um: vector: fix use-after-free in vector_mmsg_rx()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74479
- net: pktgen: fix proc entry use-after-free
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74480
- net: bridge: stop fast-leave after deleting a port group
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74481
- mm/page_reporting: use system_freezable_wq to fix UAF during suspend
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74484
- binfmt_misc: don't let an 'F' entry pin its own instance
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74485
- binfmt_misc: reject a flag character as the field delimiter
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74486
- binfmt_misc: use exe_file_deny_write_access() for the interpreter clone
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74487
- binfmt_misc: restore write access when removing an entry
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74488
- wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74490
- tipc: avoid use-after-free in poll trace queue dumps
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74491
- of/address: Fix NULL bus dereference in of_pci_range_parser_one()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74492
- netfilter: ipset: do not update comments from kernel-side hash adds
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74493
- net/smc: fix socket use-after-free during link group termination
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74494
- ksmbd: reject repeated SMB2 NEGOTIATE requests
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74495
- igbvf: Fix leak in TX DMA error cleanup
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74497
- ALSA: usb-audio: Clamp frame size in implicit-feedback mode
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74498
- ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74499
- ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74500
- ALSA: usb-audio: fix stack info leak in RME Digiface status
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74501
- ALSA: usb-audio: fix use-after-free in ump_to_endpoint()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74502
- ALSA: ump: fix double free of out_cvts on rawmidi error
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74503
- ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74504
- ALSA: seq: Fix division by zero in initialize_timer()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74505
- ALSA: 6fire: Fix UAF at error handling during probe
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74506
- afs: Fix UAF when sending a message
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74507
- Bluetooth: HIDP: validate numbered report payloads
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74508
- Bluetooth: HIDP: reject frames without a transaction header
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74509
- Bluetooth: hci_sync: Fix advertising data UAFs
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74510
- Bluetooth: mgmt: fix UAF in pair command cancellation
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74511
- Bluetooth: mgmt: fix pending command UAF in EIR updates
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74512
- audit: fix potential use-after-free in audit_del_rule()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74513
- dibs: fix use-after-free of dmb_node in loopback
attach/detach/unregister
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74514
- KVM: s390: pci: Fix memory accounting for pinned/unpinned pages
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74515
- KVM: s390: pci: Reject adapter interrupt forwarding if already enabled
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74516
- KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is
active
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74518
- mm/hugetlb: fix list corruption in allocate_file_region_entries()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74519
- pinctrl: devicetree: don't free uninitialized dev_name on error path
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74520
- iommu/iommufd: Fix IOPF group ownership UAF
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74522
- ksmbd: fix use-after-free in __close_file_table_ids()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74523
- qede: sync udp_tunnel ports outside qede_lock in the recovery path
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74524
- riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74525
- net: sxgbe: free TX rings on RX allocation failure
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74531
- Bluetooth: hci_conn: hold conn reference in abort_conn_sync()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74532
- Bluetooth: btintel: Validate length before parsing diagnostics TLV
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74534
- Bluetooth: ISO: fix refcounting of iso_conn
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74535
- Bluetooth: ISO: avoid deadlocks in iso_sock_timeout
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74536
- Bluetooth: ISO: fix leaking sk after socket release
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74537
- Bluetooth: ISO: hold sk properly in iso_conn_ready
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74538
- Bluetooth: ISO: lock sk in iso_connect_ind
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74539
- Bluetooth: ISO: lock sk in iso_sock_getname
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74540
- Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74541
- Bluetooth: ISO: clear iso_data always when detaching conn from hcon
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74543
- net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74545
- rtase: fix double free of multi-frag skb on DMA map failure
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74546
- hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74547
- hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74548
- forcedeth: fix UAF of txrx_stats in nv_remove
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74549
- hwmon: (nct6775-core) Prevent access to unsupported weight registers
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74550
- net: do not send ICMP/NDISC Redirects when peer allocation fails
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74551
- hwmon: (nzxt-smart2) DMA-align output buffer
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74552
- hwmon: (lm90) Only report alarms if driver is ready
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74553
- hwmon: (nct6775-core) Fix number of temperature registers for NCT6116
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74555
- scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74556
- scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection
buffer
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74557
- scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74559
- xsk: drain continuation descs after overflow in xsk_build_skb()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74560
- xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74563
- rds: tcp: hold the RCU lock across ipv6_chk_addr() in
rds_tcp_laddr_check()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74579
- netfilter: nft_payload: fix mask build for partial field offload
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74564
- netfilter: xt_hashlimit: validate hashtable supports
XT_HASHLIMIT_RATE_MATCH
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74565
- netfilter: nf_tables: make nft_object rhltable per table
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74566
- keys: make keyring key-chunk byte order agree with
keyring_diff_objects()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74567
- keys: fix out-of-bounds read in keyring_get_key_chunk()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74569
- netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in
sip_help_tcp()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74572
- btrfs: zoned: fix deadlock between metadata writeback and transaction
commit
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74573
- iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74574
- dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open()
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74575
- thunderbolt: Prevent XDomain delayed work use-after-free on disconnect
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74576
- mm/slab: prevent unbounded recursion in free path with new kmalloc type
* Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
CVE-2026-74577
- net: mpls: initialize rtm_tos in mpls_getroute()
Date: 2026-09-28 09:45:11.622989+00:00
Changed-By: Kuba Pawlak <kuba.pawlak at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-ibm/7.0.0-1016.16
-------------- next part --------------
Sorry, changesfile not available.
More information about the Resolute-changes
mailing list