[ubuntu/resolute-proposed] linux-ibm 7.0.0-1016.16 (Accepted)

Timo Aaltonen tjaalton at ubuntu.com
Thu Oct 1 22:13:39 UTC 2026


linux-ibm (7.0.0-1016.16) resolute; urgency=medium

  * resolute/linux-ibm: 7.0.0-1016.16 -proposed tracker (LP: #2168055)

  [ Ubuntu: 7.0.0-39.39 ]

  * resolute/linux: 7.0.0-39.39 -proposed tracker (LP: #2168074)
  * Include v4l2loopback in default modules set for 26.04 (LP: #2168012)
    - [Packaging] Add dependency for v4l2loopback
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950)
    - fsnotify: inotify: pass mark connector to fsnotify_recalc_mask()
    - clk: qcom: gcc-mdm9607: Increase delay for USB PHY reset
    - usb: f_mass_storage: Bump local buffer size in fsg_common_create_luns()
    - usb: typec: qcom-pmic-typec: drain cc_debounce_dwork if port_start()
      fails
    - usb: typec: tcpm: constrain TCPM_SOURCING_VBUS event handling
    - usb: typec: tipd: Fix Thunderbolt altmode VDOs for cd321x
    - thermal/drivers/imx: Disable clock on runtime resume failure
    - thermal/drivers/qoriq: Disable clock on resume failure
    - userfaultfd: reset err to be 0 when move_pages_ptes succeeded
    - soc: qcom: geni-se: Use HW PROG_RAM_DEPTH to validate firmware size
    - spi: bcm63xx-hsspi: disable clocks on resume failure
    - spi: bcm63xx: disable clock on resume failure
    - spi: bcmbca-hsspi: disable clocks on resume failure
    - mm/damon/vaddr-kunit: check region count in three_regions test
    - samples/damon/mtier: handle damon_start() failure
    - samples/damon/prcl: handle damon_start() failure
    - samples/damon/prcl: stop and free damon ctx when damon_call() fails
    - samples/damon/wsse: stop and free damon ctx when damon_call() fails
    - mm/damon/sysfs-schemes: kobject_del() scheme action destination dirs
    - mm/damon/sysfs-schemes: kobject_del() scheme dirs
    - mm/damon/sysfs-schemes: kobject_del() scheme filter dirs
    - mm/damon/sysfs-schemes: kobject_del() scheme quota goal dirs
    - mm/damon/sysfs-schemes: kobject_del() scheme region dirs
    - mm/damon/sysfs: kobject_del() region and target (error) dirs
    - mm/damon/sysfs: kobject_del() target (normal), context and kdamond dirs
    - mm/damon/core-kunit: check region count before testing in split_at()
    - ftrace: Synchronize the initialization of ftrace_ops
    - dmaengine: dw-edma: Fix HDMA channel status register access
    - dmaengine: dw-edma: Complete descriptors before pausing
    - cpuidle: psci: Fix support for probe deferral by dropping the faux
      device
    - block: flag zoned disks with GENHD_FL_NO_PART
    - ata: ahci: work around lost interrupts on Marvell 88SE61xx
    - irqchip/stm32mp-exti: Fix the unit of the hwspinlock timeout
    - Input: aiptek - validate raw macro indices before updating state
    - memcg: bypass the reclaim and oom killer for dying tasks once oom_reaper
      is done
    - memcg: make the v1 soft limit knob inert
    - rtc: rzn1: Handle EPROBE_DEFER for optional pps interrupt
    - rtc: rzn1: Fix weekday underflow when alarm crosses month boundary
    - rtc: rzn1: Handle unset alarm weekday in rzn1_rtc_read_alarm
    - rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers
    - perf trace: Factor out BPF loop body
    - perf trace: Refactor augmented_raw_syscalls using bpf_for
    - perf hisi-ptt: Fix PTT trace TLP header parsing
    - i2c: designware: Enable interrupt mask workaround for HJMC3001
    - i2c: qcom-geni: update frequency table to fix timing parameters
    - arm64: mm: Fix the lockless page-table walk in show_pte()
    - arm64: errata: pass REVIDR when matching target implementation CPUs
    - ALSA: rawmidi: Return the error from snd_rawmidi_input_params()
    - pmdomain: airoha: fix unselectable AIROHA_CPU_PM_DOMAIN kconfig
    - Revert "irqchip/mbigen: Fix mbigen node address layout"
    - mm/hugetlb: fix missing migratable flag on same-node hugetlb migration
    - mm/hugetlb: keep max_huge_pages when dissolving surplus folios
    - mm/hugetlb_cgroup: call page_counter_set_max() outside VM_BUG_ON()
    - parisc: Fix alignment of asm statements in head.S
    - powerpc/pseries: Handle and log pseries-wdt registration failures
    - powerpc/pseries: Move H_WATCHDOG definitions to a common header
    - powerpc/crash: stop watchdogs before booting kdump kernel
    - s390/vfio-ap: Fix stale do_remove flag across iterations in
      vfio_ap_mdev_cfg_remove
    - s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap
    - s390/vfio-ap: Fix required lock not held during update of ap_matrix_mdev
      object
    - mtd: nand: realtek-ecc: add missing MODULE_DEVICE_TABLE()
    - batman-adv: mcast: ensure unshared skb for multicast packets
    - batman-adv: bla: prevent CRC corruptions after claim flush
    - clk: clocking-wizard: fix integer overflow in rate calculation
    - clk: mediatek: mt8196: Select REGMAP_MMIO for vlpckgen
    - clk: qcom: gcc-msm8916: Fix enable_reg for gcc_blsp1_sleep_clk
    - clk: qcom: gcc-msm8939: Fix enable_reg for gcc_blsp1_sleep_clk
    - clk: rockchip: rk3588: Don't change PLL rates when setting dclk_vop2_src
    - clk: qcom: gcc-mdm9607: Drop incorrect apss_tcu_clk_src
    - clk: qcom: gcc-mdm9607: Drop incorrect system_noc_bfdcd_clk_src
    - clk: qcom: gcc-mdm9607: Fix enable_reg for gcc_blsp1_sleep_clk
    - clk: qcom: gcc-mdm9607: Fix halt_reg for gcc_apss_axi_clk
    - clk: qcom: gcc-mdm9607: Drop incorrect BIMC PLL and related clocks
    - i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure
    - ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure
    - ASoC: fsl_easrc: Use div64_u64 for 64-by-64 division
    - AsoC: intel: sst: fix PCI device reference leak on probe failure
    - ASoC: samsung: aries_audio_probe: double of_node_put due to direct
      assignment without of_node_get
    - iio: adc: adi-axi-adc: add data size support for AD408X backend
    - iio: adc: max34408: add missing 'select REGMAP_I2C' to Kconfig
    - iio: adc: pac1921: fix wrong channel used in trigger handler read
    - iio: dac: ad3552r-hs: fix scnprintf() buffer bound in data source show
    - iio: gyro: mpu3050: fix sign of raw angular velocity readings
    - iio: light: cm32181: return zero after writing calibscale
    - iio: light: gp2ap002: Disable regulators on resume failure
    - iio: pressure: mpl115: Fix runtime PM cleanup
    - iio: srf04: fix pm_runtime handling on probe error path
    - iio: temperature: hid-sensor-temperature: switch to non-devm
      iio_device_register()
    - iio: ti-ads7138: Disable STATS_EN bit while reading conversion results
    - iio: light: opt4060: Reject integration times with a non-zero seconds
      part
    - iio: light: opt4060: Fix incorrect register name in threshold read error
      message
    - iio: light: opt4001: Fix power down clearing bits of the wrong register
    - iio: light: opt4001: Fix incompatible pointer type passed to
      div_u64_rem()
    - iio: light: opt4001: Reject integration times with a non-zero seconds
      part
    - iio: light: opt4001: Fix reversed GENMASK() arguments in fault count
      mask
    - KVM: PPC: Book3S HV: Validate arch_compat against host compatibility
      mode
    - KVM: nVMX: Decouple INVVPID operand checks from flushing of vpid02
    - KVM: x86/mmu: Fold kvm_mmu_zap_memslot() into
      kvm_arch_flush_shadow_memslot()
    - KVM: x86/mmu: Split kvm_mmu_zap_all_fast() into "front" and "back"
      halves
    - KVM: x86/mmu: Use CMPXCHG when clearing Accessed bit in TDP MMU
    - KVM: x86/mmu: Use split "zap all fast" helpers when invalidating memslot
    - KVM: x86: Serialize writes to disabled_quirks using kvm->lock
    - KVM: x86: Ensure runtime reads of disabled_quirks are resolved once
    - KVM: s390: Zero initialize irq in reinject_machine_check
    - KVM: s390: pv: Fix rc/rrc offset for PVM_DUMP
    - KVM: s390: Restore sigset on error path
    - KVM: arm64: Consider SCTLR_EL2.M when mapping the L1 VNCR page
    - KVM: arm64: vgic: Fix detection of MI on no pending LR
    - KVM: arm64: vgic: Reset in_kernel on private IRQ allocation failure
    - LoongArch: KVM: Fix PC double advance in kernel MMIO read fast path
    - LoongArch: KVM: Fix TOCTOU race on pv_features
    - LoongArch: Add DIRECT_MAP_PHYSMEM_END definition
    - LoongArch: BPF: Optimize redundant TCC loads in epilogue
    - LoongArch: Do not select HAVE_RUST when KASAN is enabled
    - rust: drm: ioctl: fix unbounded lifetimes in ioctl handler arguments
    - media: amphion: Remove obsolete frame_count check in venc_start_session
    - media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid
      debugfs clash
    - media: i2c: alvium: Fix: Correct name of register in
      alvium_set_ctrl_auto_exposure
    - media: i2c: imx415: Return test pattern write errors
    - media: imx355: Avoid calling imx355_power_off twice in error path
    - media: iris: Enumerate cap->bus_info to differentiate between encoder
      and decoder
    - media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common
    - media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar
      routing
    - media: nxp: imx8-isi: Correct color map between V4L2 and ISI
    - media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks
    - media: rkvdec: Propagate platform_get_irq() errors
    - media: rzg2l-cru: Align bytesperline to hardware DMA stride requirement
    - media: v4l2-ctrls: Allow unknown HDR10 white point and luminance
    - media: venus: fix payload size returned by parse_caps() and
      parse_alloc_mode()
    - media: venus: fix payload size calculation in parse_raw_formats()
    - media: vimc: fix pixel format lookup in enum_framesizes
    - media: qcom: iris: fix state-change debug log printing stale value
    - media: chips-media: wave5: Guard bit depth check with
      initial_info_obtained
    - media: chips-media: wave5: Set inst->std during default format
      initialization
    - scsi: qla2xxx: Fix Name Server logout detection on FWI2 adapters
    - scsi: qla2xxx: Check entry_status in qla24xx_modify_vp_config()
    - scsi: qla2xxx: Fix response queue over-consumption in
      __qla_consume_iocb()
    - scsi: qla2xxx: Fix NVMe abort reference leak on repeated abort
    - scsi: qla2xxx: Drop vport reference under lock in report ID acquisition
    - scsi: qla2xxx: Use coherent DMA buffer for D_Port diagnostics
    - f2fs: return symlink writeback errors
    - f2fs: reject overlapping move range after len expansion
    - f2fs: fix to avoid move_range and defragment on device_alias file
    - f2fs: dirty directory inodes on mtime/ctime update
    - f2fs: return writeback error from collapse range
    - f2fs: fix to avoid potential section-unaligned pinfile
    - f2fs: fix i_size when pinned fallocate partially fails
    - f2fs: fix to off-by-one issue in f2fs_zero_post_eof_page()
    - f2fs: fix to zero post-EOF data when extending file size
    - drm/xe/vram: report FLAT_CCS base misalignment
    - drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure
    - drm/ssd130x: fix column and row end address in partial updates for
      ssd132x
    - drm/sun4i: fix refcount leak in sun4i_backend_init_sat()
    - drm/ssd130x: fix column and row end address in partial updates in
      ssd133x
    - drm/nouveau/disp/r535: Add scanline position support + head state
      support
    - drm/hibmc: Fix list of formats on the primary plane
    - drm/hibmc: Use drm_atomic_helper_check_plane_state()
    - drm/gud: validate TV mode names before creating enum property
    - drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value
    - drm/amdgpu: check thunderbolt before switcheroo registration
    - drm/amdgpu: Disable runtime PM for externally attached dGPUs
    - drm/amdgpu: fix autosuspend cleanup during removal
    - drm/amdgpu: Skip accessing psp rum time db for APUs
    - drm/amdgpu: update the fw version for gfx11 userqueues
    - drm/amdgpu: update the fw version for gfx12 userqueues
    - drm/amdgpu: use AMDGPU_GPU_PAGE_SHIFT instead of PAGE_SHIFT
    - drm/amdkfd: Reject zero-sized AQL queue allocations after size halving
    - drm/sysfb: simpledrm: Improve framebuffer-size validation
    - drm/sysfb: simpledrm: Improve panel-size validation
    - drm/sysfb: simpledrm: Improve stride validation
    - drm/sysfb: ofdrm: Fix is_avivo() constant comparison bug
    - drm/nouveau/gsp: use per-version DP_CONFIG_STREAM params on r570
      firmware
    - drm/nouveau: Use write-combined maps for coherent
    - drm/nouveau/disp: move GSP head-timing ISR and vblank helpers to tu102.c
    - drm/nouveau/disp: move the GSP HDMI GCP AVMute write to engine/disp
    - drm/nouveau/disp: route GSP-RM display MMIO through nvkm_disp_func hooks
    - drm/nouveau/disp: fix HDMI vendor infoframes on GB20x
    - drm/nouveau/disp: fix HDMI GCP AVMute register offsets on GB20x
    - drm/nouveau/disp: fix head state readback on GB20x
    - drm/nouveau/gsp: fix vblank interrupts on GB20x
    - fuse: split off fuse_args and related definitions into a separate header
    - fuse: remove fm arg of args->end callback
    - crypto: atmel-ecc - replace min_t with min
    - mm/hugetlb: defer vmemmap population for bootmem hugepages
    - mm/hugetlb: refactor code around vmemmap_walk
    - HID: sony: use guard() and scoped_guard()
    - ACPI: CPPC: Reject desired_perf reads on _CPC revision 4+
    - ACPI: x86: cmos_rtc: Create a CMOS RTC platform device
    - ACPI: TAD: Rearrange RT data validation checking
    - ACPI: TAD: Add locking around AML evaluations
    - bpf: Factor stackid_init function from __bpf_get_stackid
    - bpf: Factor stackid_fastpath function from __bpf_get_stackid
    - bpf: Factor stackid_new_bucket from __bpf_get_stackid
    - bpf: Use stack id functions instead of __bpf_get_stackid
    - sched: Add assert_balance_callbacks_empty helper
    - sched: Rework prev_balance() to avoid stale prev references
    - remoteproc: qcom: pas: Guard dtb metadata release with dtb_pas_id check
    - NFSD: Consolidate the revocation-path client unpin
    - mm: rework compound_head() for power-of-2 sizeof(struct page)
    - hugetlb: remove VMEMMAP_SYNCHRONIZE_RCU
    - Docs/ABI/damon: fix typo in intervals_goal sysfs path
    - power: supply: ab8500_fg: Remove redundant dev_err()/dev_err_probe()
    - mm/damon/tests/core-kunit: catch test failure in test_merge_regions_of()
    - mm/damon/vaddr: drop last same folio access check optimization
    - mm/damon/paddr: drop last same folio access check reuse optimization
    - mm/damon/ops-common: use nr_accesses moving sum for quota score
    - mm/damon/core: skip aging from repeated aggressive merging
    - mm/damon/sysfs: read addr_unit only once in damon_sysfs_apply_inputs()
    - mm/damon/core-kunit: handle region split failure in filter_out()
    - mm/damon/core: initialize damos->last_applied
    - mm/hugetlb_vmemmap: fix incorrect vmemmap restore in rollback
    - zram: move lockmap to be per-zram instead per table
    - ACPI: battery: Use kstrtoul() over sscanf("%lu\n")
    - ACPI: battery: Protect all properties with a separated mutex
    - NFSD: Annotate caller preconditions for the state-table walkers
    - usb: cdnsp: fix wakeup from S3 after controller context loss
    - usb: dwc3: google: Initialise probe properties with
      DWC3_DEFAULT_PROPERTIES
    - tracing/probes: Fix anon_stack check for unnamed bitfields in
      btf_find_struct_member
    - tracing: Remove the backup instance automatically after read
    - soc: fsl: qe: Add chained_irq_{enter,exit}() calls in cascade handler
    - mm/damon/sysfs: read ops_id only once in damon_sysfs_apply_inputs()
    - mm/damon/core-kunit: skip wrong dest walk in commit_dests_for()
    - mm/damon/core-kunit: skip wrong quota goal walk in commit_quota_goals()
    - mm/damon/core-kunit: skip wrong region walk in commit_target_regions()
    - mm/secretmem: properly account locked pages
    - futex: Provide rt_mutex_.*_schedule() equivalents for futex scheduling
    - bpf, riscv: Make arena support depend on ZACAS
    - misc: fastrpc: don't publish fd before copy_to_user() succeeds
    - perf/x86/intel: Remove anythread_deprecated bit from perf_capabilities
    - perf build: Add clang and rust target flags for LoongArch
    - perf/core: Fix deadlock in perf_mmap() failure path
    - i2c: qcom-cci: Do not check return value of cci_init()
    - i2c: qcom-cci: Remove overcautious disable_irq() calls
    - i2c: qcom-cci: fix autosuspend cleanup
    - ring-buffer: Show persistent buffer dropped events in trace_pipe file
    - ring-buffer: Allow splice reads on static buffers
    - dma-buf: add dma_fence_was_initialized function v2
    - nvme: fold nvme_config_discard() into nvme_update_disk_info()
    - Revert "once: don't use a work queue to reset sleepable static key"
    - mm: fix incorrect vm_flags usage when checking allowable orders for
      tmpfs
    - mtd: rawnand: pl353: Make sure we use the monolithic helpers for raw
      accesses
    - mtd: rawnand: sunxi: group controller delay tables
    - mtd: rawnand: sunxi: describe tADL and tWHR delays
    - mtd: rawnand: sunxi: fix H6/H616 controller timings
    - batman-adv: fix TX priority extraction for BATADV_FORW_MCAST
    - clk: microchip: mpfs: fix regmap_update_bits() mask/val order
    - ASoC: adau1761: sort the register default table
    - ASoC: cx2072x: sort the register default table
    - ASoC: fsl_easrc: sort the register default table
    - ASoC: max9860: sort the register default table
    - ASoC: ml26124: sort the register default table
    - ASoC: pcm512x: sort the register default table
    - ASoC: pm4125-sdw: sort the register default table
    - ASoC: rt1017-sdca-sdw: sort the register default table
    - ASoC: rt1316-sdw: sort the register default table
    - ASoC: rt1318-sdw: sort the register default table
    - ASoC: rt1318: sort the register default table
    - ASoC: rt274: sort the register default table
    - ASoC: rt286: sort the register default table
    - ASoC: rt298: sort the register default table
    - ASoC: rt700: drop duplicate reg_default entry
    - ASoC: rt700: sort the register default table
    - ASoC: rt711-sdca: sort the register default tables
    - ASoC: rt711: sort the register default table
    - ASoC: rt712-sdca-dmic: sort the register default table
    - ASoC: rt712-sdca-sdw: sort the register default table
    - ASoC: rt715-sdca: drop duplicate reg_default entries
    - ASoC: rt715-sdca: sort the register default tables
    - ASoC: rt715: sort the register default table
    - ASoC: rt721-sdca-sdw: sort the register default table
    - ASoC: sgtl5000: sort the register default table
    - ASoC: sti-sas: sort the register default table
    - ASoC: tas2552: sort the register default table
    - ASoC: tas2764: sort the register default table
    - ASoC: tas2780: sort the register default table
    - ASoC: tas2783-sdw: drop duplicate reg_default entry
    - ASoC: tas2783-sdw: sort the register default table
    - iio: adc: ad4080: configure backend data size
    - iio: adc: max14001: add missing 'select REGMAP' to Kconfig
    - iio: dac: ad5446: fix OF module device table
    - iio: dac: mcp47feb02: add missing 'select REGMAP_I2C' to Kconfig
    - KVM: x86: Move some EFER bits enablement to common code
    - KVM: x86: Move enabling EFER.SVME and EFER.LMSLE to generic EFER setup
    - KVM: arm64: nv: Fully update VNCR fixmap state in kvm_translate_vncr()
    - LoongArch: Expand module virtual address space to 2GB
    - LoongArch: BPF: Fix off-by-one error for insn_is_cast_user()
    - media: dt-bindings: nxp,imx8-isi: Drop fsl,blk-ctrl requirement for
      i.MX8ULP
    - media: i2c: vd55g1: Fix manual digital gain on color variant
    - media: i2c: vd55g1: Fix media bus code initialization
    - media: mali-c55: fix dropped last AEC histogram zone weight
    - media: mali-c55: Fix clock leak on reset deassert failure
    - media: mali-c55: Fix AEXP IHIST disable bit shift
    - media: mali-c55: Fix scaler factor overflow for large crop sizes
    - media: rkvdec: hevc: tighten EXT SPS RPS control dimensions
    - media: chips-media: wave5: avoid skipping device_run while VPU has work
    - media: chips-media: wave5: Fix pipeline stall when queuing fails
    - f2fs: embed f2fs_gc_kthread in f2fs_sb_info
    - f2fs: fix to return -EFSCORRUPTED in f2fs_get_node_info() correctly
    - f2fs: fix to reclaim space in f2fs_allocate_pinning_section()
    - drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable
    - drm/amd/display: Fix HPD consideration for VGA/LVDS connectors on DCE
    - drm/amd/display: Set gpuvm min page size to 4K on dcn35/36
    - drm/nouveau/dmem: fix callocated underflow on large folio split
    - PCI: Introduce PCI_SLOT_PLACEHOLDER constant for slot_nr placeholder
      value
    - Upstream stable to v6.18.51, v7.2.5
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89795
    - PCI: Allow per function PCI slots to fix slot reset on s390
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89796
    - mm/damon/core: avoid infinite kdamond_merge_regions() internal loop
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89804
    - drm/nouveau/dmem: fix mismatched DMA unmap size for large folios
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89809
    - drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89812
    - drm/amdgpu: force complete the MES ring fences on reset
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89813
    - drm/amdgpu: force complete the KIQ ring fences on reset
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89815
    - drm/ttm: Drop tt->restore after successful restore
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89827
    - drm/amdgpu: avoid force-completing uninitialized UVD rings
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89831
    - f2fs: protect critical_task_priority updates with s_umount
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89836
    - f2fs: fix folio_nr_pages() race after put in large folio invalidate
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89838
    - f2fs: limit recovery filename logging to stored length
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89840
    - f2fs: validate MOVE_RANGE destination size
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89859
    - scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89862
    - scsi: qla2xxx: Fix BSG job leak on validate flash image error path
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89866
    - media: chips-media: wave5: Resume device before setting EOS flag
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89867
    - media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was
      queued
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89868
    - media: chips-media: wave5: Add timeout while stop_streaming
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89873
    - media: v4l2-ctrls: validate HEVC EXT SPS RPS counts
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89875
    - media: ti: vpe: quiesce overflow recovery before freeing streams
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89882
    - media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89905
    - LoongArch: BPF: Move arena register slot below TCC context
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89915
    - KVM: arm64: Remove VM-wide VNCR mapping counter
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89917
    - KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR
      unmapping
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89919
    - KVM: s390: keyop: use mmu_lock to read gmap->asce
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89921
    - KVM: s390: Zero initialize data structures for inject_pfault_token
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89935
    - iio: light: apds9306: fix PM reference leak in apds9306_read_data()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89966
    - mm/hugetlb_cma: fix null nodemask dereference in
      hugetlb_cma_alloc_frozen_folio
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89967
    - mm/migrate_device: avoid out-of-bounds writes for compound folios
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89971
    - nvme: skip the zoned limits update if the zone info query failed
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89976
    - accel/ethosu: fix job completion fence cleanup
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89977
    - accel/ethosu: check MMIO mapping errors in probe
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89978
    - accel/amdxdna: return early from a zero-length flush
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89981
    - arm64: Don't read GMID_EL1 when MTE is disabled
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89791
    - perf: Fix use-after-free when perf mmap() revival races with the last
      munmap()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89987
    - mm/huge_memory: transfer the pmd dirty bit to the folio on zap
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89996
    - dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90002
    - ftrace: Take trace_array reference before accessing its ftrace_ops
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90013
    - tracing: Take trace_array reference when opening options file
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90014
    - tracing: Have show_event_filters/triggers files take trace array ref
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90016
    - staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90023
    - usb: gadget: f_mass_storage: fix null pointer dereference in
      fsg_common_set_num_buffers()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90028
    - usb: typec: hd3ss3220: track VBUS enable state per consumer
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90040
    - KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is
      zapped
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90043
    - zram: fix slot lock bit position on big-endian 64-bit
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89794
    - ksmbd: zero pipe read compound padding
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89797
    - power: supply: ab8500_fg: fix use-after-free on remove
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90037
    - NFSD: Prevent client use-after-free during close_lru reaping
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90036
    - NFSD: Prevent client use-after-free during blocked-lock reaping
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89520
    - sched/core: Make core-sched flips wait for in-flight selections
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89798
    - rpcrdma: arm rn_done before publishing the notification
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89799
    - bpf: Disable preemption in bpf_get_stackid
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90041
    - HID: sony: clean up device list on probe failure
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90042
    - ceph: properly decrypt filenames in vmalloc() buffers
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90039
    - NFSD: Guard admin state-revocation walks with NFSD_NET_UP
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90044
    - usb: gadget: f_fs: Fix Use-After-Free in AIO error path
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90045
    - USB: gadget: ffs: fix mm lifetime handling
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90046
    - mm/page_alloc: don't spin_trylock() in NMI on UP
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-80926
    - ksmbd: fix use-after-free in oplock break notification
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89800
    - drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89801
    - drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89802
    - drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89803
    - drm/nouveau: unsubscribe the channel-kill event before the fence context
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89806
    - drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89807
    - drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89808
    - drm/amdkfd: Fix the case that vm range is hole at
      svm_migrate_copy_to_vram
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89810
    - drm/amdkfd: Fix error path at svm_migrate_copy_to_ram
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89811
    - drm/amdkfd: Add TLB flush after MES queue eviction/suspension
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89814
    - drm/amdgpu: clamp the isolation index for rings outside a partition
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89816
    - drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89817
    - drm/gud: NUL-terminate TV mode names read from the device
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89818
    - drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89819
    - drm/amd/display: validate plane degamma LUT size for private color prop
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89820
    - drm/amd/display: fix dc_lock leak on GPU reset error paths
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89821
    - drm/amd/display: avoid divide-by-zero in __is_lut_linear()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89822
    - drm/i915: Guard against NULL driver_data in i915_pci_probe()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89823
    - drm: fix race between partial drm_dev_register() failure and ioctl
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89824
    - drm/panel-edp: fix i2c adapter leak on probe failure
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89825
    - drm/panthor: fix firmware control interface bounds checks
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89826
    - drm/panthor: harden firmware build-info bounds checks
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89828
    - drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89829
    - f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89830
    - f2fs: fix valid block count leak on data block allocation failure
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89832
    - f2fs: fix to clear dirty flag on folio in error path
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89833
    - f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89834
    - f2fs: fix to migrate all curseg types during free_segment_range
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89835
    - f2fs: avoid NULL checkpoint thread access in sysfs
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89837
    - f2fs: fix dentry folio leak in find_in_level
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89839
    - f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89841
    - f2fs: only redirty pinned folios in redirty_blocks
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89842
    - scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89843
    - scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89844
    - scsi: qla2xxx: Hold vport_slock for host map update in report ID
      acquisition
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89845
    - scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89846
    - scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89847
    - scsi: qla2xxx: Avoid double completion in async IOCB timeout
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89848
    - scsi: qla2xxx: Quiesce response IRQ before freeing request queue
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89849
    - scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89850
    - scsi: qla2xxx: Don't query firmware state while chip is down
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89851
    - scsi: qla2xxx: Fix FCE trace enable parsing in debugfs
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89852
    - scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89853
    - scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89854
    - scsi: qla2xxx: Fix cs84xx use-after-free on host teardown
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89855
    - scsi: qla2xxx: Serialize flash version read in reset handler
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89856
    - scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89857
    - scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89858
    - scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89860
    - scsi: qla2xxx: Initialize NVMe abort_work once at submission
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89861
    - scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89863
    - scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89864
    - scsi: qla2xxx: Bound i2c->length in I2C bsg handlers
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89865
    - scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89869
    - media: qcom: iris: use disable_irq() during power-off
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89870
    - media: zoran: Avoid freeing a registered video_device twice
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89871
    - media: video-i2c: fix kthread error pointer left in kthread_vid_cap on
      failure
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89872
    - media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89874
    - media: v4l2-async: avoid deleting unlinked ASC entry on link error
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89876
    - media: tda18250: fix possible integer overflow
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89877
    - media: saa7164: fix cleanup on resource allocation failure
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89878
    - media: s2255: check firmware size before reading trailing marker
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89879
    - media: s2255: bound JPEG frame size before copying into the buffer
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89880
    - media: rtl2832_sdr: release URBs and stream buffers on start_streaming()
      failure
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89881
    - media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix
      DMA leak
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89883
    - media: rc: sunxi-cir: Unregister rc device on probe failure
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89884
    - media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89885
    - media: platform: mtk-mdp3: Fix SCP device refcounting
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89886
    - media: intel/ipu6: fix async notifier cleanup leak on parse error
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89887
    - media: i2c: ov7740: fix use-after-destroy in remove
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89888
    - media: i2c: ov02a10: fix endpoint parsing use-after-free
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89889
    - media: i2c: imx415: Release runtime PM reference on VBLANK error
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89890
    - media: go7007: defer the ALSA v4l2 put until card release
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89891
    - media: em28xx: fix use-after-free of dev_next->devlist on disconnect
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89892
    - media: em28xx: defer audio-only extension registration
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89893
    - media: cx23885: cancel NetUP CI work before teardown
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89894
    - media: cx231xx: reject geometry changes while the VBI queue is busy
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89895
    - media: cobalt: Avoid freeing ALSA private data twice
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89896
    - media: cedrus: fix memory leak in cedrus_init_ctrls()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89897
    - media: cec: Serialize exclusive follower delivery
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89898
    - media: cec: extron-da-hd-4k-plus: add sanity check
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89899
    - media: cec: disable delayed work before freeing an interrupted transmit
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89901
    - media: airspy: use vb2_video_unregister_device() on disconnect to fix
      NULL deref
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89902
    - LoongArch: Avoid preempt count underflow without probe
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89903
    - LoongArch: Do not save/restore percpu base register in rethook
      trampoline
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89904
    - LoongArch: Fix acpi_package_ids[] array overflow
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89906
    - LoongArch: BPF: Refactor jump offset calculation in tail call
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89908
    - LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89909
    - LoongArch: KVM: Free init resources if kvm_init() fails
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89911
    - KVM: arm64: Correctly cap TLBI Range to the architural limit
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89912
    - KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89913
    - KVM: arm64: vgic-v3: take an LPI reference in
      vgic_v3_save_pending_tables
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89914
    - KVM: arm64: Sign-extend VA for range-based TLBI invalidation
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89916
    - KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89918
    - KVM: arm64: Correctly handle end of VA space TLBI invalidation
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89775
    - KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89920
    - KVM: s390: Fix memory corruption by not reinjecting CK machine checks
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89922
    - KVM: s390: Take srcu when importing watchpoint data
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89923
    - KVM: s390: Free guest debug data on vcpu destroy
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89924
    - KVM: s390: Fix old_data leak in guest debug error path
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89925
    - KVM: s390: Fix memory leak in guest debug handling
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89926
    - KVM: s390: Fix length check __import_wp_info()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89927
    - KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89928
    - KVM: x86/mmu: Consume the locked rmap value in the lockless rmap walk
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89929
    - KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89930
    - KVM: nVMX: Service local TLB flushes on failed nested VM-Enter
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89931
    - KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89932
    - KVM: nVMX: Always flush vpid02 on first use
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89933
    - iio: pressure: dps310: fix NULL pointer dereference on ACPI probe
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89934
    - iio: light: ltrf216a: fix runtime PM reference leak in error path
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89936
    - iio: dac: m62332: Fix regulator reference count imbalance
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89937
    - iio: chemical: sgp30: Handle IAQ thread creation failure
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89938
    - iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove
      UAF
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89939
    - iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89940
    - iio: buffer: Tie IIO dma fence lock lifetime to the fence
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89941
    - iio: buffer: Make IIO DMA fence release RCU-safe
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89942
    - iio: buffer: Fix potential use-after-free in anonymous buffer release
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89943
    - ASoC: loongson: Fix error handling in ACPI property parsing
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89944
    - ASoC: hdac_hda: Fix hlink refcount leak on component registration
      failure
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89945
    - ASoC: cs35l34: drain threaded IRQ before runtime suspend
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89946
    - ASoC: cs35l33: drain threaded IRQ before runtime suspend
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89947
    - clk: meson: align gxbb_32k_clk_sel number of parents with actual count
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89948
    - batman-adv: bla: fix freeing of claims on meshif deletion
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89949
    - batman-adv: dat: avoid unaligned fault in IP extraction
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89950
    - batman-adv: mcast: linearize skbuff for packet generation
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89951
    - batman-adv: fix stale receive device on merged fragments
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89952
    - mtd: rawnand: validate ONFI extended parameter page sections
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89953
    - mtd: mtdoops: free page bitmap when the backing MTD is removed
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89954
    - mtd: afs: validate v2 image info bounds
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89955
    - s390/vfio-ap: Fix NULL deref in status_show() during queue probe
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89956
    - s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev
      objects
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89957
    - s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain
      removed
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89958
    - s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89959
    - s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89960
    - s390/vfio-ap: fix stale pqap_hook pointer on error in
      vfio_ap_mdev_set_kvm()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89961
    - powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89962
    - powerpc/kexec_file: Prevent kexec range truncation
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89963
    - powerpc/kexec_file: Fix null-ptr-def in extra size calculation
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89964
    - parisc: eisa: Fix infinite loop when parsing invalid IRQ value
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89965
    - nvdimm/btt: reject an arena whose nfree is below the lane count
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89968
    - nvmet-tcp: reject unsolicited H2CData PDUs
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89969
    - nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89970
    - nvmet-auth: Synchronize timeout work during SQ teardown
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89972
    - nvme: add missing SRCU grace period in error path
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89973
    - nvme-tcp: check the data direction of a C2HData PDU
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89974
    - nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89975
    - nvme-fabrics: fix DHCHAP secret leak on parse failure
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89979
    - ALSA: pcm: Fix race between non-atomic ops and trigger-start
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89980
    - ALSA: harmony: initialize locks before requesting IRQ
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89982
    - i2c: mux: Fix channel node leak on adapter add failure
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89983
    - i2c: core: fix debugfs UAF on adapter removal
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89984
    - perf/x86/intel: Fix kernel address leakages in LBR stack
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90048
    - fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89986
    - mm/mempolicy: fix sleeping allocation in
      alloc_pages_bulk_weighted_interleave()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89988
    - kprobes: Protect kprobe_blacklist with RCU
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89989
    - ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89990
    - ceph: lock mutex in ceph_mds_check_access()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89991
    - bpf: Fix infinite loop in pcpu_freelist push with one possible CPU
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89992
    - cpuidle: dt_idle_genpd: kfree() the original name allocation
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89993
    - dmaengine: dw-edma: Initialize IRQ data before requesting IRQs
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89994
    - dmaengine: fsl-edma: tracing: no ptr dereference during log output
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89995
    - dma-direct: return struct page from dma_direct_alloc_from_pool()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89997
    - dm: fix resume-vs-remove race
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89998
    - dm: fix race when loading and unloading a table
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89999
    - HID: wacom: validate report length in wacom_intuos_pro2_bt_irq
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90000
    - HID: rmi: fix OOB access with undersized RMI reports
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90001
    - HID: bpf: serialize device reference release in struct_ops destroy path
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90003
    - futex: Prevent rcuwait use-after-free during requeue PI
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90005
    - samples/damon/wsse: handle damon_start() failure
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90006
    - samples/damon/mtier: handle damon_stop() failure
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90007
    - scsi: pm8001: Use rollback index when freeing MSI-X vectors
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90011
    - scsi: target: iscsi: Reserve a terminator byte for the login payload
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90012
    - spi: Fix DMA mapping ownership on partial map failure
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-89793
    - ublk: clear VM_MAYWRITE on read-only ublk char device mmap
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90015
    - xhci: fix lost bounce buffers on TDs spanning several ring segments
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90017
    - staging: rtl8723bs: fix OOB read in rtw_action_frame_parse()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90018
    - staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90019
    - usb: gadget: fix null pointer dereference in usb_put_function_instance()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90020
    - USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90021
    - usb: gadget: f_midi: initialize work in f_midi_alloc()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90022
    - usb: gadget: f_midi2: fix use-after-free in string attribute show path
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90024
    - usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90025
    - usb: typec: ucsi: displayport: Fix OOB altmode array index
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90026
    - usb: typec: qcom-pmic: cancel reset_work on stop
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90027
    - usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90029
    - usb: storage: realtek_cr: fix use-after-free on disconnect
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90030
    - usb: dwc3: clear forceRM when issuing EndTransfer
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90031
    - usb-storage: ene_ub6250: fix race between scan work and probe
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90032
    - media: usbtv: keep device alive while ALSA card exists
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90033
    - ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90034
    - usb: image: mdc800: change kmalloc() to kzalloc()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90035
    - drm/amd/display: fix division by zero in get_estimated_bw()
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90047
    - drm/xe: Don't hand out the flat CCS storage as usable VRAM
  * Resolute update: upstream stable patchset 2026-09-22 (LP: #2167950) //
    CVE-2026-90049
    - net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy()
  * Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609)
    - [Config] Remove CONFIG_CRYPTO_DEV_SUN8I_CE_PRNG
    - [Config] Remove CONFIG_CRYPTO_DEV_SUN8I_SS_PRNG
    - ASoC: tegra210_i2s: sort the register default table
    - ASoC: tegra210_i2s: sort the Tegra264 register default table
    - ASoC: tegra210_mixer: sort the register default table
    - ASoC: tegra: Fix the I2S enable default value
    - ASoC: tegra: Fix the MIXER enable default value
    - ASoC: tegra: Sort ADMAIF register defaults
    - ASoC: tegra: Sort MBDRC register defaults
    - ring-buffer: Fix subbuf resize race with ring buffer readers
    - drm/amd/display: hide Apple Studio Display secondary tile
    - drm/amd/display: Prune per-tile Timing from Apple Studio Display Primary
      Tile
    - alpha: fix ieee_swcr_to_fpcr setting FPCR_DNOD unconditionally
    - rust: time: fix as_micros_ceil() rounding near i64::MAX
    - alpha: don't leak hardware-fabricated FP exception bits to user space
    - clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error
      path
    - clocksource/drivers/timer-sun4i: Advertise a real minimum delta
    - fs: fix user path of nested backing files
    - ovl: fix double end_creating() on the casefold-mismatch path
    - pidfd: hold exec_update_lock around namespace ioctl
    - powerpc/pseries/iommu: switch to Default DMA window during kdump
    - rust: fmt: fix {:p} printing stack addresses
    - timers/itimer: Zero-init old itimerval before copy to userspace
    - objtool/rust: add one more `noreturn` Rust function for Rust 1.99.0
    - rust: bug: skip arch-specific asm in `testlib` builds
    - rust: bug: fix warn_on macro build error on UML
    - rust: bug: prevent dead_code warning from warn_on!'s flags constant
    - rust: rust_is_available: warn for `bindgen` < 0.72.1 && libclang >= 22
    - rust: kernel: list: fix incorrect pop_back example comment
    - objtool/rust: add one more `noreturn` Rust function
    - rust: num: restrict bool conversion to unsigned Bounded
    - rust: cfi: disable function merging if CFI is enabled
    - KEYS: trusted: Fix TPM teardown ordering
    - apparmor: fix cred UAF caused by begin_current_label_crit_section()
    - apparmor: fix out-of-bounds write when null terminating a label vec
    - include/linux/list.h: mark list_add and __list_add as __always_inline
    - mm, swap: ratelimit bad swap entry reports
    - mm/gup: fix always draining LRU caches in
      collect_longterm_unpinnable_folios()
    - mm/huge_memory: skip device-private PMDs in madvise_free_huge_pmd
    - mm/huge_memory: use folio's memcg inside __folio_split()
    - mm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier
    - mm/hugetlb_vmemmap: fix __hugetlb_vmemmap_optimize_folios()
    - mm/kmemleak: avoid soft lockup when scanning task stacks
    - mm/madvise: skip device-private PMDs in cold and pageout walks
    - mm/mempolicy: skip non-present PMDs when queueing folios
    - mm/mglru: use the common routine for dirty/writeback reactivation
    - mm/mglru: fix and remove redundant unevictable folio handling
    - mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()
    - mm/migrate: use huge_ptep_get() in remove_migration_pte()
    - mm/migrate_device: clear stale mapping after freeing swapcache
    - mm/mm_init: deferred_grow_zone(): fix out-of-range first_deferred_pfn
    - mm/page_owner: use memcg_data snapshot to avoid TOCTOU in
      print_page_owner_memcg()
    - mm/page_vma_mapped: use huge_ptep_get() for hugetlb
    - mm/pagewalk: fix stale walk->action escaping walk_pmd_range()
    - mm/rmap: use huge_ptep_get() in try_to_unmap_one()
    - mm/rmap: use huge_ptep_get() in try_to_migrate_one()
    - mm/slub: fix missing debugfs entries for caches created before sysfs
      init
    - mm/slub: prevent pfmemalloc objects from entering the barn
    - mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()
    - mm/zswap: fix global shrinker when memory cgroup is disabled
    - mm: compaction: support non-movable compaction for pageblock requests
    - mm: memcg-v1: fix wrong linux-mm list address in deprecation warnings
    - mm: memcg-v1: fix memsw and TCP failcnt accounting
    - mm: memcg: stop reclaim when a limit update is superseded
    - mm: memcontrol: update state_local when flushing NMI stats
    - mm: mempolicy: fix automatic numa balancing for shmem
    - mm: page_alloc: __GFP_FS lockdep annotation for direct compaction
    - mm: page_alloc: move capture_control to the page allocator
    - mm: page_alloc: fix non-movable reclaim storm in defrag_mode
    - mm: vmscan: fix node reclaim ignoring swappiness parameter
    - tools/compiler: match glibc 2.42 definition of __attribute_const__
    - x86/locking: Use sfence for wmb() if SSE is available
    - x86/insn-eval: Move assign_register() out of KVM as insn_assign_reg()
    - x86/tdx: Fix off-by-one in port I/O handling
    - x86/tdx: Fix zero-extension for 32-bit port I/O
    - x86/xen: fix init of balloon stats again
    - hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start()
    - tracing/user_events: Clear copied tracing state before fork duplication
    - tracing: Fix crash passing ERR_PTR to kthread_stop()
    - tracing: Fix logged instance name on creation failure
    - tracing: Fix use-after-free in trace_pipe read on sub-buffer order
      change
    - tracing: Fix use-after-free with same-name named triggers
    - cdx: Fix double free when sysfs file creation fails
    - debugfs: Fix lockdown check for mmap_prepare
    - device property: fix infinite loop in fwnode_for_each_child_node()
    - misc: nsm: bound the device-reported response length
    - powerpc/powermac: fix OF node refcount
    - rapidio: mport_cdev: fix use-after-free in dma_req_free()
    - Revert "media: v4l2-dev: fix error handling in
      __video_register_device()"
    - serial: imx: serialize imx_uart_ports[] lifetime
    - staging: greybus: hid: fix SET_REPORT return value
    - usb: dwc2: gadget: Exit partial power down state when changing USB pull-
      up
    - usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due
      to race condition
    - usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed
    - USB: phy: fsl-usb: fix missing static keywords
    - usb: typec: hd3ss3220: fix VBUS regulator error message
    - usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive()
    - usb: typec: thunderbolt: Disable work before freeing tbt on remove
    - usb: typec: ucsi: use UCSI_TIMEOUT_MS for sync command completion
    - usb: gadget: u_audio: Fix use-after-free on sound card disconnect
    - usb: gadget: snps_udc_plat: clean up PHY on probe deferral
    - usb: gadget: midi2: remove default configfs groups on teardown
    - usb: gadget: f_tcm: fix deadlock in usbg_make_tpg()
    - usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init()
    - usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and
      uvc_function_unbind()
    - usb: gadget: f_fs: Prevent deadlock during ep0 read loop
    - cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read
    - fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write
    - HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature
    - i3c: renesas: Fix out-of-bounds access for newdevs mask
    - KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID
    - lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
    - media: cec: stm32: prevent out-of-bounds write on RX overflow
    - media: vicodec: fix out-of-bounds write in FWHT encoder
    - nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after
      truncation
    - of: fix out-of-bounds read in of_alias_scan() stem parser
    - PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io()
    - phy: rockchip-samsung-dcphy: fix out-of-range max_register
    - ubifs: fix out-of-bounds read in signature length check
    - zram: fix out-of-bounds access in read_block_state()
    - zram: fix out-of-bounds access in writeback_store()
    - zram: set default primary compressor in zram_destroy_comps()
    - zram: validate deflate params
    - zsmalloc: account for handle size in class lookup
    - NFS/localio: fix ref leak on nfs_uuid_add_file failure
    - NFS: fix delegation_hash_table leak when nfs4_server_common_setup()
      fails
    - NFSD: check truncate permission under inode lock
    - NFSD: Encode only the status in NFS-ACL v2 GETACL error replies
    - NFSD: Fix off-by-one in DRC bucket pruning limit
    - NFSD: fix up error returned by write_threads()
    - NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock
    - NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check
    - nfsd: guard nfsd_serv deref in nfsd_file_net_dispose
    - NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget
      path
    - pNFS: Fix EBUSY check in pnfs_layout_need_return
    - lockd, nfsd: RCU-protect nlmsvc_ops dispatch
    - nfsd: RCU-protect cl_cb_session to fix use-after-free on session
      teardown
    - nfsd: release path refs on follow_down() error
    - nfsd: Reset write verifier when async COPY writeback fails
    - nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit
      paths
    - nfsd: return NFS4ERR_NOTSUPP for unsupported netloc4 types
    - nfsd: sample writeback error cursor before async COPY loop
    - nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations
    - nfsd: size fh_verify server sockaddr slot by xpt_locallen
    - nfsd: validate nseconds in TIME_DELEG decode paths
    - nfsd: validate sockaddr length per family in listener_set
    - nfsd: validate symlink target length in NFSv4 CREATE
    - nfsd: move struct nfsd_genl_rqstp to nfsctl.c
    - nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage
    - nfsd: add fh_want_write() for early-verified SETATTR in
      nfsd_proc_setattr()
    - nfsd: add filehandle match check to nfsd4_delegreturn()
    - nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry
    - nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref
    - nfsd: cap decoded POSIX ACL count to bound sort cost
    - nfsd: check client ownership when cancelling a copy-notify stateid
    - nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()
    - nfsd: clear CALLBACK_RUNNING on failed delegation recall queue
    - nfsd: clear opcnt on compound arg release to prevent OOB read
    - nfsd: convert nfsd_net boolean flags to unsigned long flags word
    - nfsd: dedup nfs4_client_to_reclaim inserts
    - nfsd: defer setting NFSD4_CALLBACK_RUNNING in deleg_reaper
    - nfsd: defer vfree of compound ops to fix rpc_status UAF
    - nfsd: don't free session slots that are still in use
    - nfsd: drop the stateid, not the stateowner, on seqid_op replay retry
    - nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file
    - nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation
      revoke
    - nfsd: fix clock domain mismatch in clients_still_reclaiming()
    - nfsd: fix cpntf publish race in nfs4_init_cp_state
    - nfsd: fix dentry ref leak on V4ROOT export filehandle lookup
    - nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net
    - nfsd: fix FL_SLEEP being set unconditionally for all LOCK types
    - nfsd: fix netlink dumpit error handling for rpc_status_get
    - nfsd: fix nfsd_file leak on inter-server COPY setup failure
    - nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs
    - nfsd: fix partial-write detection in nfsd_direct_write
    - nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file()
    - nfsd: fix refcount leak in nfsd_file_lru_add on insertion failure
    - nfsd: fix reply size estimate for GET_DIR_DELEGATION
    - nfsd: fix stale s2s_cp_stateids IDR entry for async COPY
    - nfsd: fix UAF in async copy cancel and shutdown
    - nfsd: fix version mismatch loops in nfsd_acl_init_request()
    - nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget
    - nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo
    - nfsd: gate nfs2 setacl by argp->mask
    - nfsd: gate nfs3 setacl by argp->mask
    - nfsd: hold rcu across localio cmpxchg retry
    - nfsd: initialize copy-notify stateid before publishing it
    - nfsd: initialize DRC hash table before registering shrinker
    - nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd()
    - nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache
    - nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops
    - nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE
    - nfsd: reject reclaim LOCK after RECLAIM_COMPLETE
    - nfsd: release OPEN-decoded posix ACLs via op_release
    - nfsd: revoke copy-notify stateids before dropping their reference
    - NFSD: Prevent lock owner use-after-free during client teardown
    - NFSD: Prevent post-shutdown use-after-free in unlock_filesystem
    - NFSD: Prevent client use-after-free during admin state revocation
    - nfsd: convert global state_lock to per-net deleg_lock
    - NFSD: Prevent client use-after-free during delegation revoke
    - NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup
    - nfsd: use test_and_clear_bit for somebody_reclaimed to prevent lost
      update
    - libceph: validate OSD extent maps before cursor advance
    - libceph: reject buckets with mismatched CRUSH ids
    - ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock
    - ceph: fix UAF in check_new_map() on session freed during unlock
    - ceph: force a cap message when a deferred revoke can't be acked
      immediately
    - ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
    - ceph: bound copied dentry name length in NFS export get_name
    - ceph: bound MDSCapAuth path and fs_name decode in handle_session()
    - ceph: bound num_export_targets array for mds info v2/v3
    - ceph: bound xattr value length in __build_xattrs()
    - ceph: cap delegated inode count in ceph_parse_deleg_inos()
    - ceph: do not repeat ceph_trim_dentries() if no progress possible
    - ceph: fix leaked inode reference on writeback abort at umount
    - btrfs: drop recovered reloc root refs on recovery failure
    - btrfs: fix extent map leak in NOCOW direct I/O write
    - btrfs: do not overwrite NODATASUM flag when removing NODATACOW flag
    - audit: avoid dropping live tree ref on fsnotify rule autoremove
    - smb: move some definitions from common/smb2pdu.h into common/fscc.h
    - smb/client: reduce fallocate zero buffer allocation
    - smb/client: emulate small EOF-extending mode 0 fallocate ranges
    - cifs: add cifs_resize_file_locked() to guard fscache_resize_cookie()
      under i_rwsem
    - smb/client: do not account EOF extension as allocation
    - cifs: call pagecache_isize_extended() in cifs_setsize() when extending
    - cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size()
    - cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
    - cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC
    - smb: client: clear setuid/setgid bit on write with
      cifsacl/modefromsid/posix extensions
    - smb: client: fix UAF and buffer leak in cifs_check_trans2() for
      malformed secondary T2
    - smb: client: clear ce->tgthint in free_tgts()
    - smb: client: fix ALIGN() overflow in symlink_data() error context loop
    - smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV
    - smb: client: fix OOB read/write from unvalidated DataOffset in
      coalesce_t2()
    - smb: client: fix use-before-check of ReparseDataLength in
      reparse_buf_ptr()
    - smb: client: harden DFS cache against invalid target hints
    - smb: client: reject a tree connect response whose byte count is too
      small
    - smb: client: restore the data_offset bound in is_valid_oplock_break()
    - HID: apple: preserve keyboard backlight across T2 resume
    - HID: corsair-void: Check size of status and firmware events before
      reading them
    - HID: picolcd: clamp eeprom debugfs read to bytes actually received
    - HID: roccat: free buffered reports when destroying device
    - HID: sensor: custom: Fix field sysfs group cleanup on failure
    - HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind
    - HID: universal-pidff: stop the device when force-feedback init fails
    - HID: mcp2221: stop device IO before hid_hw_stop
    - HID: mcp2221: fix OOB write in mcp2221_raw_event()
    - HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes
    - HID: mcp2221: validate report size in mcp2221_raw_event()
    - HID: intel-thc-hid: intel-quickspi: validate report size before copy
    - HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the
      caller buffer
    - HID: intel-thc-hid: intel-quicki2c: fix autosuspend cleanup during
      teardown
    - HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during
      teardown
    - eventfs: Initialize ei->children and ei->list in init_ei()
    - fs/ntfs3: validate dirty page table on log replay
    - fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()
    - fs/ntfs3: bound page_lcns[] index by the log record
    - eCryptfs: bound the packet-length peek to the user buffer
    - ecryptfs: fix tag 11 packet exact-fit size check
    - ecryptfs: hold msg ctx list lock when cleaning daemon queue
    - ecryptfs: pass packet set buffer size to parser
    - ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet
    - ecryptfs: reject too-small tag 70 packets
    - ecryptfs: release message context on send failure
    - ecryptfs: show filename encryption options
    - efivarfs: Rate limit statfs() handler
    - entry: Fix seccomp bypass after ptrace with TSYNC
    - erofs: skip sufficiently large global buffers when resizing
    - ext2: Fix lost inode updates for IS_SYNC inodes
    - fanotify: fix use-after-free of file range info
    - fat: restore original value when fat_ent_write failed
    - fbdev: omapfb: panel-dsi-cm: initialize lock before registering display
    - fbdev: pvr2fb: correct user pointer annotation and sentinel initializer
    - fbdev: ssd1307fb: defer I2C transfers from damage callbacks
    - fbdev: uvesafb: unregister connector callback on init failure
    - forcedeth: fix off-by-one when saving/restoring non-PCI config space
    - fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration
    - fsnotify: Fix stale object mask after concurrent mark updates
    - hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device
    - hugetlb: only adjust reservation during unmapping if mapcount is 0
    - accel/rocket: fix NULL dereference and integer overflow in
      rocket_job_push()
    - accel/rocket: initialize job domain before cleanup paths
    - accel/rocket: Fix error path handling in rocket_job_run()
    - acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks
    - ACPI: APEI: Fix ERST timeout unit conversion
    - ACPI: APEI: GHES: fix ARM section length accounting after header
    - ACPI: pfr_update: fix stack buffer overflow in query_capability()
    - ACPI: scan: Avoid registering platform devices with resource overlaps
    - alpha/PCI: Fix I/O port accessor argument order in pci_legacy_write()
    - alpha: marvel: Fix irq_set_status_flags to use correct IRQ number
    - alpha: marvel: Fix lock ordering in init_io7_irqs()
    - ARM: 9477/1: Disable broken eBPF JIT on the Risc PC
    - ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes
    - auxdisplay: charlcd: cancel backlight work on registration failure
    - backlight: aw99706: Fix DT property names to match binding
    - backlight: aw99706: Honor the core blank state in update_status()
    - block: validate user space vectors during extraction
    - block: set QUEUE_FLAG_DYING unconditionally in blk_mark_disk_dead()
    - Bluetooth: btusb: Add ASUS USB-BT540 for Realtek 8761CU
    - Bluetooth: btusb: Add ASUS USB-BT600 for Realtek 8761CU
    - Bluetooth: btusb: limit RTL8761B BROKEN_EXT_SCAN quirk to 0bda:a728
    - Bluetooth: eir: Fix OOB read in eir_get_service_data()
    - bnx2x: fix double free in bnx2x_init_firmware() error path
    - bnxt_en: Write doorbell when linearizing skb fails
    - bpf, x86: Fix per-CPU address resolution into an extended register
    - bpf: Disable preemption in __bpf_get_stack
    - buffer: avoid tail commit walk for uptodate folios
    - bpf: Harden bloom filter sizing and indexing on 32-bit kernels
    - dm-io: clone the source bio instead of copying its biovec
    - dm-io: report non-retryable errors separatedly
    - dm-era: fix shadowed superblock leak on take-snap failure
    - dm raid1: reserve space for NUL-terminator in build_constructor_string()
    - dm array: validate array block headers on read
    - dm array: reject an array block whose value size is not the caller's
    - coresight: etm3x: Fix cntr_val_show() to match cntr_val_store() behavior
    - cpufreq: apple-soc: Fix OPP table cleanup
    - cpufreq: schedutil: Fix rate limit overflow
    - cxl/features: bound fwctl command payload to the input buffer
    - dax/cxl, hmem: Initialize hmem early and defer dax_cxl binding
    - cxl/region: Add helper to check Soft Reserved containment by CXL regions
    - cxl/mce: Make the MCE notifier per-region
    - cxl/pmem: Format the nvdimm serial number as unsigned decimal
    - cxl/ras: Fix cxl_rch_get_aer_severity() wrong severity register
    - Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on
      BCM4378
    - Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is
      negative
    - Bluetooth: hci_uart: Fix false success return in hci_uart_setup()
    - Bluetooth: RFCOMM: serialize security confirmation handling
    - Bluetooth: hci_conn: re-enable advertising only for peripheral role
    - Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb
    - Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection
    - Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is
      negative
    - Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is
      negative
    - Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last
      request
    - kasan: fix cache shrink race with CPU hotplug
    - jbd2: bound shrinker scans by examined checkpoint buffers
    - jbd2: check need_resched() when skipping busy checkpoint buffers
    - ipip: fix skb leak in collect_md mode when metadata_dst allocation fails
    - ip: orphan prefetched skbs before multicast forwarding
    - ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit()
    - ip6_gre: fix hardware header length for NBMA tunnels
    - ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()
    - ipv6: use RCU iterator to dump route exceptions
    - landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
    - libnvdimm/labels: Prevent integer overflow in __nd_label_validate()
    - mailbox: qcom-ipcc: fix duplicate channel allocation across holes
    - md/raid10: fix still_degraded being inverted in raid10_sync_request()
    - md: do overflow check for sb->bblog_shift in super_1_load()
    - module: validate string table section types
    - mpls: reload header after pskb_may_pull()
    - mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction
    - module/kallsyms: fix nextval for data symbol lookup
    - nouveau/gem: reserve the bo in the info ioctl around the vma lookup
    - params: fix charp corruption on allocation failure
    - phy: fsl-imx8mq-usb: fix typec switch leak on probe error path
    - SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow
    - SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
    - SUNRPC: svcauth_gss: enforce krb5 token minimum length
    - sunrpc: route to a populated pool in svc_pool_for_cpu()
    - SUNRPC: Restore NUMA_NO_NODE for svc thread allocations in global mode
    - SUNRPC: always drain cache_cleaner before destroying a cache_detail
    - SUNRPC: Check svc pool percpu counter allocation
    - SUNRPC: close backchannel before destroying callback service
    - sunrpc: defer rq_argp and rq_resp free until after RCU grace period
    - SUNRPC: fix gssx_dec_option_array error path bugs
    - sunrpc: fix use-after-free in __rpc_clnt_handle_event and
      __rpc_clnt_remove_pipedir
    - SUNRPC: Guard svcauth_gss_release() dispatch on rq_auth_stat
    - SUNRPC: harden gss_krb5_unwrap_v2 against short tokens
    - SUNRPC: harden gss_unwrap_resp_priv length checks
    - sunrpc: init gssp_lock before publishing proc entry
    - SUNRPC: reject duplicate CREDS_VALUE options
    - SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field
    - SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2
    - SUNRPC: wait for in-flight client TLS handshake callback
    - svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id
    - svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails
    - svcrdma: Fix offset arithmetic in read_chunk_range
    - svcrdma: Fix pcl_for_each_segment for empty chunks
    - svcrdma: Fix unmatched rn_unregister on failed accept
    - svcrdma: Reject connection when transport allocation fails
    - svcrdma: Reject inline replies that overflow the pull-up buffer
    - svcrdma: Reject oversized Read segments at decode time
    - svcrdma: Reject Read lists that exceed the page budget
    - svcrdma: Reject Write/Reply chunks with segcount 0
    - svcrdma: Use svc_xprt_put to free listener on create failure
    - svcrdma: Validate Read chunk positions before reconstruction
    - udf: reject VAT indexes equal to the entry count
    - wifi: ath6kl: clamp assoc request/response lengths before subtracting IE
      offsets
    - wifi: mt76: mt7925: cancel pending mlo_pm_work
    - staging: media: tegra-video: fix of_node_put() on VIP parse errors
    - staging: media: tegra-video: vi: fix probe failure on skipped last port
    - media: staging/ipu7: fix async notifier UAF on probe error path
    - sched/core: Handle pick_task() releasing the rq lock
    - sched_ext: Fix exit_task leak on fork failure during enable
    - sched_ext: Fix inverted ops.core_sched_before() invocation
    - sched_ext: Keep kick_sync waiting on the rq's own CPU
    - scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables()
    - scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock
    - rpmsg: glink: smem: order FIFO read after availability check
    - Revert "arm64: dts: rockchip: Further describe the WiFi for the
      Pinephone Pro"
    - arm64: dts: qcom: kodiak: avoid EFI overlap for ADSP remote heap
    - arm64: dts: qcom: sm6115-pro1x: Correct touchscreen GPIO flags
    - arm64: dts: qcom: x1-dell-thena: mark l12b and l15b always-on
    - arm64: dts: rockchip: fix eMMC reset polarity on PP-1516
    - arm64: dts: rockchip: fix eMMC reset polarity on PX30 Ringneck
    - arm64: dts: rockchip: fix emmc reset polarity on px30-cobra
    - arm64: dts: rockchip: Fix rk3399-roc-pc-plus analog audio
    - arm64: dts: rockchip: Fix rk3588s-roc-pc audio description
    - riscv: dts: spacemit: k1-bananapi-f3: fix maximum CPU core voltage
    - riscv: dts: spacemit: k1-milkv-jupiter: fix maximum CPU core voltage
    - RISC-V: KVM: Fix PMU event info array size overflow
    - riscv: acpi: Handle LPI architectural context loss flags
    - riscv: unaligned: stop using kthread for check_vector_unaligned_access()
    - remoteproc: scp: Fix device reference leak on failed lookup
    - qede: Fix NULL pointer dereference in TPA fragment processing
    - RDMA/cxgb4: Cancel reg_work before freeing device on remove
    - RDMA/ionic: Cap eq_count to the eth driver's interrupt vector budget
    - RDMA/ionic: Embed counter driver data in rdma_counter allocation
    - RDMA/ucma: Lock the handler in ucma_set_ib_path()
    - RDMA/ucma: Lock the handler in ucma_write_cm_event()
    - RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR
    - regulator: as3722_get_regulator_dt_data: fix premature of_node_put
      leaving dangling of_node pointer
    - regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after
      ownership transferred to rdata
    - regulator: qcom-refgen: correct the regulator type to CURRENT
    - ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page()
    - ring-buffer: Free cpu_buffer::free_page with subbuf_order
    - ring-buffer: Hold cpu_buffer::lock when resizing a subbuf
    - ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page
    - PM: sleep: Unblock runtime PM when device prepare fails
    - orangefs: fix double-free of trailer_buf on readdir copy failure
    - orangefs: skip leading spaces before parsing client debug masks
    - ocfs2: always run deallocs on copy-on-write completion
    - ocfs2: bound namelen in dlm_migrate_request_handler
    - ocfs2: validate lengths in dlm_mig_lockres_handler
    - ocfs2: validate rl_used against rl_count in refcount block validator
    - ocfs2: validate dx_root extent list fields during block read
    - ocfs2: validate directory-index entry counts when reading metadata
    - ocfs2: cluster: don't sleep while holding o2hb_live_lock in
      o2hb_region_pin()
    - ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from
      drop_item
    - ocfs2: cluster: fix o2hb_dependent_users leak on pin failure
    - ocfs2: fix cached cluster count after suballocator reclaim
    - ocfs2: fix readdir position truncation on 32-bit kernels
    - openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
    - openvswitch: Fix CT limit teardown use-after-free
    - openvswitch: only skb_tx_error() a packet we are about to drop
    - ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion
    - arm64: compat: Fix decrementing LDM/STM alignment emulation
    - arm64: proton-pack: Restore the nospectre_bhb command-line option
    - ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC
    - ASoC: codecs: aw88261: reduce log spam
    - ASoC: codecs: aw88261: only check PLL and clock state at power-up
    - hwmon: (max6621) fix negative temperature offset and crit readings
    - hwmon: (max6621) fix temperature clamp range
    - i2c: mxs: fix DMA channel leak on probe error
    - ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()
    - lockd: pin next file across nlm_inspect_file lock-drop
    - lockd: fix NULL dereference on lockowner allocation failure
    - lockd: fix swapped arguments in nlmsvc_match_ip()
    - nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in error
      path
    - nvme: zero the discard fallback page
    - nvme-pci: disable controller on admin queue IRQ setup failure
    - nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
    - nvme-tcp: fix host memory disclosure on R2T for a read command
    - nvme-tcp: reject a read that transferred too few bytes
    - sctp: stop processing a packet once its association is deleted
    - sctp: drop a chunk if its transport was removed
    - sctp: fix NULL deref on untransmitted RECONF completion
    - sctp: distinguish sequence zero from wildcard in reconf lookup
    - sctp: fix stream->outcnt underflow on duplicate RECONF responses
    - power: supply: bq24257: fix use-after-free on remove
    - power: supply: bq256xx: drain usb_work before freeing the charger
    - power: supply: bq25890: Fix power_supply reference leak
    - power: supply: charger-manager: register regulators before exposing
      sysfs
    - power: supply: cros_usbpd-charger: bound the EC-reported port count
    - power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS
    - power: supply: lp8727: fix use-after-free in lp8727_release_irq()
    - power: supply: lp8788-charger: fix use-after-free on remove
    - power: supply: pf1550: enable charging when battery profile exists
    - power: supply: qcom_battmgr: fix use-after-free
    - power: supply: qcom_battmgr: terminate the strings from firmware
    - power: supply: rt9455: quiesce delayed work before teardown
    - power: supply: twl4030_charger: cancel workers via devm
    - power: supply: ucs1002: fix use-after-free on remove
    - power: supply: max17040: propagate register read errors
    - power: supply: max17040: drop incorrect I2C functionality check
    - power: supply: max17040: synchronize work cancellation on suspend
    - s390/dasd: Do not complete a failed ESE read as successful
    - s390/dasd: Guard sysfs discipline callbacks against unallocated private
      data
    - s390/dasd: Propagate partial completion length across ERP recovery
    - PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip
    - PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk
    - PCI: meson: Fix GPIO state while requesting PERST#
    - PCI: starfive: Fix resource leaks on error paths in host_init()
    - PCI: plda: Fix use-after-free of event IRQs during teardown
    - PCI: plda: Fix IRQ domain leaks in the error paths of
      plda_init_interrupts()
    - PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608]
    - PCI/sysfs: Fix read byte order in pci_read_legacy_io()
    - PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses
    - PCI/AER: Emit TLP Log only for unmasked errors
    - PCI/AER: Fix mapping of errors to agent & layer
    - PCI/MSI: Enable memory decoding before restoring MSI-X messages
    - PCI/proc: Avoid spurious runtime PM wakeup on config space accesses
    - PCI/proc: Use file_ns_capable() when checking config space read access
    - PCI/proc: Warn on writes to kernel-exclusive config space regions
    - iommu/amd: Put PCI device after handling PPR faults
    - iommu/msm: Unwind probe state on registration failure
    - iommu/sva: Set handle->dev before the SVA handle is visible
    - iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field
    - iommu/arm-smmu-v3: Add HAFT support for SVA
    - iommu/arm-smmu-v3: Manage teardown with devm
    - iommu: Fix dev_iommu memory leak when device_add fails in
      iommu_mock_device_add
    - iommu/vt-d: Fix no_iommu to disable platform opt-in
    - iommu/vt-d: Force requesting ACS when tboot is enabled
    - iommupt: Return zero for invalid iova_to_phys() ranges
    - iommufd: Avoid locking internal accesses during unmap
    - iommufd: Release current IOAS on xa_store() failure
    - iommufd: Fix UAF in selftest IOPF reporting
    - platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer
    - platform/x86: ISST: Validate level in perf mask ioctls
    - platform/x86: ISST: Validate socket ID in clos_assoc ioctl
    - mmc: via-sdmmc: cancel card-detect work on remove
    - mmc: via-sdmmc: stop card-detect handling on probe failure
    - platform/x86: ISST: Add a NULL check for sst_inst[]
    - platform/x86: ISST: Just allow 2 bits for SST feature enable
    - platform/x86: ISST: Use PP level enable mask
    - platform/x86: ISST: Validate logical CPU id and clos id
    - platform/x86: ISST: Validate max level for set feature
    - platform/x86: ISST: Validate parameter for core power state
    - platform/x86: ISST: Validate parameter for frequency and priority
    - platform/x86: ISST: Return error during profile addition
    - platform/x86: int1092: Fix potential memory leak in sar_probe()
    - platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe
      error path
    - platform/x86: lenovo/ymc: Only match lower byte in WMI lid switch query
      response
    - platform/x86: think-lmi: Fix certificate thumbprint sysfs output
    - platform/x86: think-lmi: Free system certificate signatures
    - platform/x86: think-lmi: Fix current password length check
    - platform/chrome: sensorhub: Bound the EC-reported sensor number
    - platform/x86/amd/pmc: Restore msg_port on amd_stb_s2d_init() error paths
    - platform/x86/amd/pmc: Propagate SMU errors and validate S2D address
    - platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails
    - platform/x86/amd/pmc: Fix msg_port restoration in
      amd_stb_debugfs_open_v2()
    - platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP
      BIOS
    - platform/x86: hp-bioscfg: advance elem past consumed array elements
    - platform/x86: hp-bioscfg: bound ordered-list parsing by the package
      count
    - platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and
      kek_store()
    - platform/x86: hp-bioscfg: fix heap OOB read on empty password write
    - platform/x86: hp-bioscfg: fix new_password_store() overwriting
      current_password
    - platform/x86: hp-bioscfg: fix off-by-one write in
      hp_get_string_from_buffer()
    - platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed
    - platform/x86: hp-bioscfg: pass validated element count to package
      parsers
    - platform/x86: hp-bioscfg: warn on element type mismatch instead of
      failing
    - io_uring/waitid: honor task_work cancellation
    - io_uring/waitid: avoid siginfo copy during ring teardown
    - io_uring/query: cap user size passed to copy_struct_to_user
    - interconnect: Fix use after free in icc_get() and of_icc_get_by_index()
    - ipmi: ipmb: validate write message length
    - ipmi: Remove all sysfs files on registration failure
    - ipmi: si: Fix NULL pointer dereference after failed registration
    - ipmi:msghandler: Cancel work cleanly on an error
    - net/iucv: filter frames in afiucv_hs_rcv() by ingress device
    - xdp: fix zero-copy frame layout
    - slip: fix use-after-free in sl_sync()
    - net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition
    - net: tun: bound receive headroom
    - net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO
    - net: ibm: emac: mal: fix NAPI locking
    - net: ipa: fix stalled modem TX queue after runtime resume
    - net: l2tp: do not propagate multicast notification errors
    - net: openvswitch: fix flow mask use-after-free on flow deletion
    - net: openvswitch: fix nf_connlabels leak in ovs_ct_init
    - net: phylink: correctly validate returned PCS in phylink_inband_caps
    - net: ravb: avoid dereferencing an invalid PTP clock
    - net: ravb: serialize PTP clock teardown
    - net: thunderbolt: Release the Rx HopID that was handed out on mismatch
    - net: thunderbolt: Mark the connection down when bringing it up fails
    - NTB: ntb_transport: Recycle TX entries before client callbacks
    - NTB: ntb_transport: Fail TX enqueue when the QP link is down
    - NTB: ntb_transport: Reject oversized TX buffers
    - net: ntb_netdev: Fix TX busy and drop handling
    - net: ntb_netdev: Avoid double-accounting netif_rx() drops
    - net: ntb_netdev: Count packets dropped on RX refill failure
    - net/mlx5e: SHAMPO, Always calculate page size
    - net/mlx5e: do not HW-GRO coalesce small frames
    - net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages
    - net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry
    - net/smc: do not dereference an unset send buffer on the SMC-D teardown
      path
    - net/smc: fix socket refcount leak in smc_switch_conns()
    - net/smc: fix use-after-free in smc_rx_pipe_buf_release()
    - net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link()
    - net/smc: stop killed, freed and out_of_sync sharing a byte
    - net/smc: unregister the connection before draining the rx tasklet
    - net: cap advertised IP tunnel headroom
    - net: fix spurious TX timeout after dev_activate()
    - net: skbuff: don't touch shared zerocopy state in skb_tx_error()
    - seg6: reset IP6CB after IPv6 decapsulation
    - hwrng: stm32 - Fix runtime PM cleanup on registration failure
    - mfd: cgbc: Fix teardown ordering in cgbc_remove()
    - mfd: qnap-mcu: keep the reply buffer alive past a command timeout
    - mfd: sm501: Fix potential memory leaks during remove
    - ALSA: 6fire: bound the MIDI event length from the device
    - ALSA: aloop: Check card index validity at probe
    - ALSA: bcd2000: clear the URB pointers on disconnect
    - ALSA: FCP: do not copy out an uninitialised init response
    - ALSA: hda/ext: preserve PPLCCTL bits when clearing reset
    - ALSA: mpu401: Check card index validity at probe
    - ALSA: mts64: Check card index validity at probe
    - ALSA: pcxhr: initialize mutexes before requesting threaded IRQ
    - ALSA: portman2x4: Check card index validity at probe
    - ALSA: serial-u16550: Check card index validity at probe
    - ALSA: virmidi: Check card index validity at probe
    - ALSA: hda/realtek: Add quirk for TongFang XxAF5xxx
    - ALSA: hda/realtek: Enable micmute LED on HP EliteBook 6 G1a p/n:
      AD3Q9ET#UUG
    - ALSA: hda/realtek: Fix Lenovo Yoga Slim 7 14AKP10 quirk ordering
    - arch_numa: avoid false positive fortify warning in
      setup_node_to_cpumask_map()
    - dm-stats: fix a crash if allocation of per-cpu data fails
    - dm-switch: use WRITE_ONCE() in switch_region_table_write()
    - dm-pcache: validate geometry fields from on-disk cache_info
    - dm-pcache: validate kset key_num and intra-segment bounds
    - dm-pcache: validate on-media seg_num against the cache device size
    - dm-pcache: bound the persisted tail-position offset
    - dm-pcache: clamp the tail kset read to the segment data region
    - dm-pcache: detect a cycle in the last-kset chain during replay
    - dm-pcache: only hand out initialized cache segments
    - dm-pcache: fix implicit u8 truncation of gc_percent in message handler
    - dm-pcache: fix use-after-free and invalid seg operations in
      kset_replay()
    - i3c: Fix unlocked dereference of dev->desc in
      i3c_device_get_supported_xfer_mode()
    - i3c: master: adi: initialize the lock before enabling interrupts
    - i3c: master: Fix info leak and UAF in device unregister path
    - i3c: master: svc: bound IBI payload to the requested max_payload_len
    - i3c: renesas: Check that the transfer is valid before accessing it
    - i3c: renesas: Clean DATBAS register on detach
    - i3c: renesas: Follow the reset deassert order used in probe
    - i3c: renesas: Reconfigure the DATBAS register on re-attach
    - i3c: renesas: Reset the controller on resume
    - i3c: renesas: Restore STDBR and EXTBR registers on resume
    - i3c: renesas: Perform Dynamic Address Assignment on resume
    - wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()
    - wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()
    - wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop
    - fuse-uring: refactor io-uring header copying to ring
    - fuse-uring: refactor io-uring header copying from ring
    - fuse-uring: use enum types for header copying
    - fuse-uring: refactor setting up copy state for payload copying
    - fuse-uring: use named constants for io-uring iovec indices
    - fuse: copy request headers via a stack buffer for io-uring
    - crypto: iaa - unmap dst before software fallback on decompress
    - crypto: atmel-ecc - clean up and improve ECDH comments
    - crypto: atmel-ecc - avoid stale fallback key after set_secret failure
    - mm/kmemleak: stop the task stack scan early when interrupted
    - mm/kmemleak: report RCU-tasks quiescent states during the scan
    - wifi: mwifiex: Detach sync cmd buffer on interrupted wait
    - wifi: rtl818x: initialize eeprom_93cx6 struct to zero
    - wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids
    - wifi: rtlwifi: rtl8192du: Fix possible memory leak in
      rtl92du_init_sw_vars()
    - wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()
    - wifi: rtw88: pci: fix resource leak on failed NAPI setup
    - wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on
      reboot
    - wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex
    - wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE
      copy
    - wifi: mt76: mt7925: cancel mlo_pm_work on stop
    - wifi: mt76: add external EEPROM support for mt799x chipsets
    - wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE
      copy
    - wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames
    - wifi: mt76: mt7996: validate default EEPROM firmware size
    - vsock/virtio: flush works in dependency order
    - w1: ds28e17: reject an oversize length on an I2C block read
    - xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc()
    - zloop: truncate finished zones to zone capacity
    - tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout
    - sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]
    - sticon/parisc: Detect default STI graphics card for console output
    - signal: avoid shared siginfo namespace rewrites
    - smack: fix cred UAF in smack_file_send_sigiotask()
    - taskstats: fix cpumask parsing cutting off the last character
    - timekeeping: Check the return value of tk_get_aux_ts64 in
      __do_adjtimex()
    - timer: Keep debugobjects state consistent in migrate_timer_list()
    - udf: Fix i_lenExtents truncation on 32-bit kernels
    - selftests/mm: fix on-fault-limit false failure under sudo-rs
    - resource: Add __resource_contains_unbound() for internal contains checks
    - ACPI: scan: Do not combine resources that overlap completely
    - platform/chrome: sensorhub: Fix dropped timestamp events and log spam
    - Upstream stable to v6.18.49, v6.18.50, v7.2.2, v7.2.3, v7.2.4
  * Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
    CVE-2026-80724
    - ptp: vmclock: prevent read-only mappings from becoming writable
  * Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
    CVE-2026-80914
    - Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready
  * Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
    CVE-2026-80833
    - crypto: sun8i-ss - Remove crypto_rng interface
  * Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
    CVE-2026-80834
    - crypto: sun8i-ce - Remove crypto_rng interface
  * Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
    CVE-2026-80925
    - vlan: fix skb_under_panic and races when toggling HW VLAN offload
  * Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
    CVE-2026-80857
    - fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free
  * Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
    CVE-2026-80858
    - fuse: publish io-uring queues with release semantics
  * Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
    CVE-2026-80859
    - fuse: fix missing barrier when checking io-uring readiness
  * Resolute update: upstream stable patchset 2026-09-17 (LP: #2167609) //
    CVE-2026-80860
    - fuse: fix race between interrupt and resend
  * [SRU] Add support for amd-pmf AMDI0112 ID (LP: #2165251)
    - SAUCE: platform/x86/amd/pmf: Add AMDI0112 ACPI ID
  * Backport: "mm/gup: fix GUP-fast fallback for NULL-mapping order-0 folios"
    (LP: #2162917)
    - mm/gup: fix GUP-fast fallback for NULL-mapping order-0 folios
  * Bluetooth: btmtk: Declare MT7920 (MT7961 1a) Bluetooth firmware
    (LP: #2166944)
    - Bluetooth: btmtk: Declare MT7920 (MT7961 1a) Bluetooth firmware
  * System cannot enter s0ix suspend on Dell with RTL8116AF ethernet
    (LP: #2160475)
    - Revert "UBUNTU: SAUCE: r8169: add quirk for RTL8116af SerDes"
    - SAUCE: r8169: add speed in private struct
    - SAUCE: net: phy: phylink: add helper to modify pause
    - SAUCE: r8169: add support for phylink
    - SAUCE: r8169: add support for RTL8116af
    - SAUCE: r8169: add support for RTL8127atf
    - SAUCE: r8169: add ltr support for RTL8117 series
    - SAUCE: r8169: fix RTL8116af can not enter s0idle and c10
  * net:rtnetlink.sh in ubuntu_kselftests_net failed with ipsec_offload on
    resolute (7.0.0-38.38) generic s390x (LP: #2166631)
    - SAUCE: Fix selftest/net/rtnetlink.sh for Big Endian
  * [UBUNTU 24.04] kernel: CPU hotplug unsupported by CPUMF (LP: #2165732)
    - s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
  * [Ubuntu 26.04] Failed install OS onto JBOD disk on B540d-2HS M.2
    controller (LP: #2148534)
    - scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame
  * New 7.0 ubuntu_kselftests_net/net:tun tests flaky (LP: #2158217)
    - SAUCE: selftests/net: Run tun tests in a dedicated network namespace
  * ThinkPad X9-15 Gen 1: IPU7 camera probe fails — duplicate software_node
    SONY471A-0 (-EEXIST), bridge init failed (LP: #2158540)
    - SAUCE: media: ipu-bridge: drop duplicate IMX471 sensor config
  * append bpf to CONFIG_LSM (LP: #2166235)
    - [Config] append bpf to CONFIG_LSM
  * Add a linux-main-modules dependency toggle to kernel build process
    (LP: #2166181)
    - [packaging] Create a linux-main-modules dependency toggle
  * Resolute update: upstream stable patchset 2026-09-04 (LP: #2166517)
    - RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
    - RDMA/rxe: Fix OOB in free_rd_atomic_resources()
    - KVM: x86/mmu: Check write tracking in all address spaces
    - nvme-tcp: fix usage of page_frag_cache
    - Revert "selinux: reject a permission value exceeding the class
      permission count"
    - selinux: use u16 for security classes
    - selinux: more strict policy parsing
    - selinux: reject a permission value exceeding the class permission count
    - selinux: require a class's permission values to cover its permission
      count
    - selinux: switch two allocations to use kzalloc_objs()
    - veth: fix OOB txq access in veth_poll() with asymmetric queue counts
    - ksmbd: harden file lifetime during session teardown
    - fpga: dfl: fme: add error handling
    - accessibility: speakup: unregister tty ldisc on later init failures
    - usb: xhci: Handle bogus TRB pointers in Missed Service Error events
    - usb: xhci: Handle USB3 port events when there is one roothub
    - xhci: dbgtty: Fix unregister on tty_register_driver() failure
    - xhci: dbgtty: Fix unregister on tty_alloc_driver() failure
    - fuse: fix invalidate lock leak on setattr writeback failure
    - fuse: fix invalidate lock leak on open O_TRUNC DAX failure
    - usb: usbtest: disable dynamic ID support
    - usb: gadget: f_tcm: keep port count until LUN teardown completes
    - KVM: SEV: Drop FOLL_WRITE for encrypted region registration
    - KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests
    - KVM: SEV: Extract loading of guest-provided VMSA to a separate helper
    - KVM: SEV: Mark vCPU RUNNABLE after AP_CREATE, even if VMSA is unusable
    - KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if
      CONFIG_KVM_AMD_SEV=y
    - tls: device: fix out-of-bounds write in tls_append_frag()
    - gtp: serialize PDP context updates
    - x86/CPU/AMD: Carve out a Zen5 models range
    - net/tcp: fix TCP-AO key deletion in VRFs
    - tcp: fix AO info use-after-free in tcp_ao_connect_init()
    - net/tcp-ao: fix use-after-free of current_key on reconnect to another
      peer
    - xfrm: espintcp: fix UAF during close
    - xfrm: drop ESP-in-TCP packets with no ingress device
    - xfrm: avoid lock inversion in nat keepalive work
    - xfrm: ah6: validate routing header segments_left
    - xfrm: fix xfrm_state_construct() auth-trunc leak
    - xfrm: bound nat keepalive state collection
    - net: bridge: mcast: fix use-after-free of a master VLAN's multicast
      context
    - ipv6: seg6: clear IPv4 control block on IPIP decapsulation
    - batman-adv: reject unrepresentable multicast TVLV offsets
    - vxlan: keep the last remote linked during FDB flush
    - netfilter: nft_set_pipapo_avx2: add missing vzeroupper
    - netfilter: nf_tables: don't queue packet path object notifications
    - mm/swap: reject swapon() on filesystem-level encrypted files
    - kunit: irq: Continue increasing hrtimer interval for longer
    - crypto: virtio - bound the akcipher result length
    - crypto: qcom-rng - Enable clock in hwrng case
    - crypto: qcom-rng - Remove crypto_rng interface
    - crypto: qcom-rng - Allow zero as a random number
    - crypto: atmel-tdes - use scatterlist length before DMA mapping
    - crypto: krb5 - use kfree_sensitive() for derived key buffers
    - crypto: qce - fix CCM AAD buffer underallocation
    - crypto: mxs-dcp - fix source scatterlist length access
    - crypto: qce - Remove unsafe/deprecated algorithms
    - KVM: s390: vsie: zero stale crypto bits
    - usb: core: Add lock to usb_wakeup_notification()
    - usb: core: Strengthen error handling in hub_hub_status()
    - ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
    - ALSA: usb-audio: Complete cleanup after system-resume errors
    - USB: serial: option: fix slab OOB read in interrupt URB callback
    - USB: serial: spcp8x5: drop broken carrier detect support
    - USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
    - wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb
    - usb: usbfs: fix use-after-free of usb_device in usbdev_release()
    - usb: xhci: bail out of setup if the controller is inaccessible
    - net: advertise TCP MSS from the configured MTU, not the learned PMTU
    - tcp: clamp route advmss to TCP_MIN_MSS
    - net/packet: defer vmalloc TX_RING free until skbs finish
    - crypto: iaa - fall back to software for multi-entry scatterlists
    - Upstream stable to v6.18.49, v7.1.13
  * Resolute update: upstream stable patchset 2026-09-03 (LP: #2166363)
    - xfs: add a xchk_ip_set_corrupt helper
    - xfs: rtsummary scrub should treat rtbitmap corruption errors as an xref
      error
    - xfs: hoist per-bucket unlinked list check to helper
    - xfs: don't livelock in scrub on a circular unlinked list
    - PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
    - Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept
    - iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown
    - iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process
      when racing with iopt_map_file_pages
    - ALSA: FCP: Use a private URB for the notification endpoint
    - ALSA: scarlett2: Use a private URB for the notification endpoint
    - rndis_host: add overflow check in rndis_rx_fixup()
    - nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()
    - io_uring/futex: don't mark futex wake requests as inflight
    - ALSA: dummy: Check card index validity at probe
    - io_uring/cmd: fix iovec leak when the async cmd is not recycled
    - io_uring/io-wq: fix worker accounting when canceling creation callbacks
    - io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec()
    - io_uring/uring_cmd: don't skip completion for a synchronous multishot
      cmd
    - ocfs2: fix missing metadata reservation for large xattrs
    - kcov: fix data corruption and race conditions on PREEMPT_RT
    - ext4: stop retrying saturated xattr cache entries
    - nilfs2: reject invalid block index in GC ioctl
    - ext4: clear error before retrying inode xattr space fallback
    - ext4: avoid tail write_begin walk for uptodate folios
    - ext4: propagate errors from fast commit range replay
    - ext4: don't enable DAX on new encrypted files
    - ext4: fix incorrect function call when initializing s_resgid
    - xfs: validate attr entry pointer before field access
    - nfc: digital: clamp SENSF_RES length to the destination buffer
    - nfc: fdp: bound the device-reported read length and fix an skb leak
    - nfc: microread: validate target discovery payload lengths
    - nfc: llcp: bound the connect_sn TLV walk to the skb
    - nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
    - nfc: llcp: reject PDUs shorter than the LLCP header
    - nfc: pn533: purge fragmented skbs during cleanup
    - nfc: st21nfca: validate ATR_REQ length against the received frame
    - nfc: nci: add data_len bound checks to activation parameter extractors
    - nfc: nci: fix out-of-bounds write in nci_target_auto_activated()
    - nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
    - nfc: nci: free destination parameters when closing a connection
    - drm/xe: Fix DPT allocation paths.
    - ipv4: reject undersized MTUs in ip_do_fragment()
    - ipv6: fix use-after-free in ip6_finish_output2()
    - mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()
    - dmaengine: fsl-edma: Add error handling for devm_kasprintf
    - nvmet-auth: zero the AUTH_RECEIVE response buffer
    - nvmet-fc: fix invalid free in LS IOD error path
    - nvmet-tcp: bound SGL data length before allocating command buffers
    - nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations
    - nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work()
    - nvmet: pci-epf: put CQ ref on create_cq mapping failure
    - mptcp: pm: use for_each_subflow helper
    - mptcp: pm: rename add_entry structure to add_addr
    - mptcp: pm: uniform announced addresses helpers
    - mptcp: pm: fix memory leak from alloc-during-teardown race
    - HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad
      USB-C
    - HID: magicmouse: re-enable multitouch after reset-resume
    - HID: magicmouse: do not keep a stale msc->input if no input is claimed
    - HID: magicmouse: Prevent out-of-bounds (OOB) read during
      DOUBLE_REPORT_ID
    - HID: core: fix OOB read of field->usage in hid_set_field()
    - HID: pidff: fix OOB write when hid->inputs is empty
    - net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
    - futex/pi: Reject cross-mm private futex owners
    - futex: Sanitize and document task_struct::futex::state transitions
    - futex/pi: Plug private futex exec() race
    - futex: Fix race on the initial mm->futex.phash.ref allocation
    - futex: Fix might_sleep() warning in futex_pivot_pending()
    - HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
    - HID: nintendo: register input device after capabilities are set
    - HID: nintendo: stop device IO before hid_hw_stop on probe failure
    - HID: core: fix number/pointer type confusion on long items
    - HID: sensor: custom: Fix use-after-free in enable_sensor
    - HID: uclogic: fix use-after-free of inrange_timer on remove
    - HID: hyperv: validate initial device info bounds
    - Bluetooth: hci_event: fix LE list UAF on reset
    - Bluetooth: hci_event: validate LE Set CIG Parameters response
    - Bluetooth: hci_sync: Fix accept list UAF during suspend
    - Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync
    - Bluetooth: ISO: zero the sockaddr before returning it in getname
    - Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255
    - Bluetooth: hci_aml: validate firmware segment lengths
    - futex: Avoid private hash use-after-free on final put
    - io_uring/futex: only mark private futex waits as inflight
    - io_uring: switch struct io_ring_ctx internal bitfields to flags
    - io_uring: defer eventfd signaling when queued from a wakeup handler
    - xfs: restore nofs context unconditionally in xfs_trans_roll
    - fbdev: Wrap user-invoked calls to fb_set_var() in helper
    - fbdev: serialize mode sysfs access with lock_fb_info()
    - HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
    - HID: asus: fix missing hid_is_usb() check
    - HID: rapoo: fix missing hid_is_usb() check
    - HID: ft260: fix stack-use-after-return write in I2C read race
    - HID: input: read battery capacity from its actual report offset
    - Upstream stable to v6.18.47, v6.18.48, v7.1.11, v7.1.12
  * Resolute update: upstream stable patchset 2026-09-03 (LP: #2166363) //
    CVE-2026-80590
    - inet: frags: strip GSO state from fragments before reassembly
  * Resolute update: upstream stable patchset 2026-09-03 (LP: #2166363) //
    CVE-2026-80724
    - ptp: vmclock: prevent read-only mappings from becoming writable
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029)
    - mount: honour SB_NOUSER in the new mount API
    - sched/fair: Revert 6d71a9c61604 ("sched/fair: Fix EEVDF entity placement
      bug causing scheduling lag")
    - selftests/bpf: Fail unbound UDP on sockmap update
    - drm/amd/display: Add AV mute wait frames to dce110_set_avmute
    - drm/amd/display: Check for tg ops in dce110_set_avmute
    - arm64: dts: qcom: purwa: Fix GPU IOMMU property
    - arm64: dts: qcom: sdm850-lenovo-yoga-c630: lower PSCI cluster idle
    - arm64: dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer
    - ARM: npcm: Fix OF node refcount leaks in SMP setup
    - selftests/sched_ext: Handle sleeping task affinity changes in numa test
    - pinctrl: qcom: ipq806x: mark gpio as a GPIO pin function
    - pinctrl: qcom: ipq806x: mark pci reset as a GPIO pin function
    - ovpn: add missing rtnl_link_ops->get_size callback
    - ARM: dts: BCM5301X: fix PCIe controller 2 second interrupt
    - ovpn: rehash peer in by_transp_addr table on CMD_PEER_SET
    - ovpn: ensure socket is owned by ovpn before deref sk_user_data
    - ovpn: zero-initialize sockaddr before learning a floated endpoint
    - ovpn: hash floated peer by transport identity only
    - ovpn: disable IPv4 redirects on MP interfaces
    - ovpn: ensure TCP vars are initialized first
    - ovpn: fix incorrect use of rcu_access_pointer()
    - drm/bridge: ps8640: propagate AUX transfer register errors
    - net: hns3: fix speed configuration residue after driver reload
    - Revert "net: thunderbolt: Enable end-to-end flow control also in
      transmit"
    - net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock
    - pds_core: keep the health thread stopped during reset
    - pds_core: cancel pending PCI reset work on AER recovery
    - netfilter: ipset: switch ext_size to atomic64_t
    - ipvs: return the csum validation for forward hook
    - watchdog: bd96801_wdt: Fix timeout for enabled WDG
    - bpf: split check_reg_sane_offset() in two parts
    - bpf: Propagate untrusted pointer state in commuted arithmetic
    - net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete
    - counter: microchip-tcb-capture: Fix DT channel validation
    - vhost/vdpa: reject overflowing PA map page counts on 32-bit
    - hwmon: (pmbus_core) Use guard() for mutex protection
    - tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss()
    - bnxt: fix memory leak in bnxt_queue_mem_alloc error cases
    - xsk: pass TX metadata pointer by reference
    - xsk: move xsk_tx_metadata_request() to xdp_sock_drv.h
    - drm/xe/uc: Apply RCS/CCS yield policy to SR-IOV VFs
    - hwmon: (nzxt-smart2) Check return value of init_device() in probe
    - hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations
    - selftests/ftrace: refactor eprobes test to fix argument checks
    - net: stmmac: resume PHY before hardware setup when opening the interface
    - bnge: use int for bnge_fix_rings_count() return value
    - bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss()
    - bnxt_en: Determine and store default RX ring in vnic structure
    - bnxt_en: Refresh VNIC default ring on queue restart if needed
    - bnxt_en: Fix PTP PPS setting bug
    - sctp: fix addip_serial increment on ASCONF_ACK allocation failure
    - net: remove WARN_ON_ONCE() from sk_mc_loop()
    - ata: pata_sl82c105: fix bridge revision use-after-free
    - bnge: Fix resource leak in bnge_init_nic() error path
    - tls: don't abort the connection on signal-interrupted sends
    - hwmon: (corsair-psu) fix possible out-of-bounds access on missing string
      termination
    - hwmon: (ads7828) Fix external VREF regulator handling
    - hwmon: (ltc4282) Avoid overflow in maximum power calculation
    - hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt
    - usb: core: Add quirk for 255-bytes initial config read
    - usb: quirks: Add ShanWan gamepad to quirk list
    - thunderbolt: icm: Preserve USB4 proxy data-valid bit
    - usb: cdnsp: fix incorrect endian conversions for APB timeout register
    - ipvs: add totalconns for dest
    - ipvs: properly update the overload flag on dest edit
    - net: octeontx2-pf: Fix UB in shift operation
    - net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header
    - KVM: s390: pci: Fix aisb calculation
    - dt-bindings: crypto: qcom,ice: Fix missing power-domain and iface clk
    - Bluetooth: btrtl: fix RTL8761B/BU broken LE extended scan
    - Bluetooth: btusb: Add TP-Link UB600 for Realtek 8761BUV
    - selftests/bpf: Ensure UDP sockets are bound
    - selftests/bpf: Adapt sockmap update error handling
    - mei: pull kvfree out of spinlock
    - nvmem: apple-spmi-nvmem: wrap regmap calls to satisfy CFI
    - nvmem: layouts: Add fixed-layout driver
    - rust_binder: do not query current thread for all ioctls
    - serial: amba-pl011: fix indefinite RS485 post-send delay
    - serial: amba-pl011: synchronize DMA teardown
    - misc: fastrpc: Fix initial memory allocation for Audio PD memory pool
    - misc: fastrpc: fix channel ctx ref leak when session alloc fails
    - misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free
    - ring-buffer: Fix crash passing ERR_PTR to kthread_stop()
    - mm/damon: adjust isolated pages stat for DAMOS_MIGRATE_{HOT,COLD}
    - ALSA: usb: Fix UAF at delayed release of MIDI2 EPs
    - ALSA: hda/tas2781: fix ACPI reference handling
    - net: phy: mediatek: fix TX blink masks using the RX bits
    - arm64: remove redundant concurrent ptdump UAF mitigation
    - x86/CPU: Add a tlbi= cmdline switch
    - x86/mce: Set up the polling timer before CMCI discovery
    - KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow
      page
    - sched/psi: Create the psimon kthread outside of cgroup_mutex
    - fsverity: Fix silent truncation in bpf_get_fsverity_digest()
    - scsi: scsi_debug: Negate wrapped memcmp() result
    - thunderbolt: Fix bandwidth group reservation indexing
    - netfilter: flowtable: ensure sufficient headroom in xmit path
    - arm64: dts: qcom: monaco: Add default GIC address cells
    - NFS: Decrement refcounts if allocating nfs_free_stateid_data fails
    - btrfs: lzo: add error message for invalid headers
    - btrfs: initialize inode mapping flags for cached inodes
    - hwmon: (pmbus/core) Avoid race condition during probe
    - bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie
    - net: qrtr: ns: Raise lookup limit to 128
    - hwmon: Support guard() and scoped_guard for subsystem locks
    - hwmon: (corsair-psu) serialize debugfs access against hwmon
    - usbnet: cap max_mtu for drivers without bind callback
    - ipvs: separate destination availability state
    - selftests/xsk: fix too-many-frags multi-buffer Tx test
    - selftests/xsk: account reclaimed invalid Tx descriptors
    - serial: sc16is7xx: enable THRI before filling TX FIFO
    - mm/huge_memory: initialise workingset state before folio split
    - net: ntb_netdev: Introduce per-queue context
    - smb: client: fix SMB1 TRANS2 multi-response truncation in SendReceive()
    - ring-buffer: Prevent resizing of persistent ring buffer
    - Revert "thermal: hwmon: Register a hwmon device for each thermal zone"
    - selinux: require every boolean value to be defined
    - selinux: reject a class permission count below its inherited common
    - selinux: do not cancel a policy conversion that never started
    - selinux: reject an unclaimed class value in security_get_classes()
    - selinux: reject a permission value exceeding the class permission count
    - selftests: mptcp: join: mark tests with data corruption as failed
    - mptcp: pm: fix data race in add_addr timer callback
    - ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked()
    - ASoC: cs4265: sort the register default table
    - ASoC: cs35l45: sort the register default table
    - ASoC: cs35l41: sort the register default table
    - ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses
    - drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12
    - drm/amdgpu: fix JPEG v5.0.0 queue reset failure in DPG mode
    - drm/amdgpu: fix JPEG v4.0.5 queue reset failure in DPG mode
    - drm/amdgpu: fix aperture iounmap skipped on device removal
    - ASoC: SOF: topology: Use acpi mach from the machine driver
    - Input: xpad - add support for ZENAIM LEVERLESS
    - powerpc/pseries: pci - logic bug
    - Input: synaptics-rmi4 - fix F55 transmitter electrode count typo
    - Input: psxpad-spi - set driver data before use
    - Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal
      keyboard
    - powerpc/pseries: lparcfg - fix kbuf[] underflow
    - crypto: starfive - use scatterlist length before DMA mapping
    - selftests/ftrace: Convert ELF entry point to file offset in uprobe test
    - gve: fix zero-length skb frag with header-split
    - pmdomain: arm: Fix -EINVAL from scmi_pd_set_perf_state() on state 0
    - ftrace: Protect direct_functions in ftrace_find_rec_direct
    - ftrace: Fix off-by-one fentry site disable in ftrace_free_mem()
    - Input: sur40 - fix V4L error path cleanup
    - ceph: fix MDS random selection readiness predicate
    - libceph: tolerate addrvecs with multiple entries of the same type
    - mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit
    - mmc: sdhci: unmap the bounce buffer before device release
    - pmdomain: mediatek: fix remaining %pOF after of_node_put()
    - mmc: sdhci: make tuning_err a signed int
    - pmdomains: mediatek: Avoid setting RTFF's CLK_DIS before NRESTORE
    - drm/connector/hdmi: Fix out of bounds memory read
    - mmc: loongson2: Fix sg iteration in data reorder functions
    - pmdomain: mediatek: Fix mt8183 hang on boot
    - drm/xe: Order ring writes before ring tail updates
    - drm/xe: Fix xe_device_probe() failure
    - drm/radeon: fix autosuspend cleanup during teardown
    - s390/vfio_ccw: Calculate idal length based on idaw type
    - s390/zcrypt: Fix CPRB memory allocation in zcrypt misc code
    - drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix
    - drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE
    - drm/amdgpu: Reject UVD message with invalid number of h265 refs
    - drm/amdgpu: fix nbif 6.3.1 l1 low power not functional
    - drm/amdgpu: check ASPM on the dGPU host link
    - drm/amdgpu: Reject UVD message with dimensions above 4096
    - drm/amdgpu: Fix UVD min buffer sizes
    - drm/amdgpu: Fix UVD dpb min size calculation for H264
    - xfs: mark nonzero sb_gquotino as corrupt on metadir filesystems
    - xfs: clear zapped attr fork state when bmap repair finds no attr fork
    - xfs: check cowextsize in xrep_inode_cowextsize
    - xfs: fix transaction block reservation in xrep_rtbitmap
    - xfs: zero i_nlink before repair puts inode on unlinked list
    - xfs: only check mergeability of bnobt records
    - xfs: set the prev pointer when reinserting an inode on the unlinked list
    - xfs: pass runtime errors from xrep_iunlink_mark_ondisk_rec up to callers
    - xfs: nlink scrub must take IOLOCK before determining ILOCK state
    - xfs: load next_agino from the correct xfarray in
      xrep_iunlink_relink_prev
    - xfs: don't zap the attr fork on repair when there are queued pptr
      updates
    - xfs: fix allocated inodes that show up in the unlinked list
    - xfs: don't return EFSCORRUPTED when scrubbing corrupt parent pointers
    - xfs: don't ignore runtime errors in xrep_iunlink_reload_next
    - xfs: check xfarray iteration errors when committing unlinked inode lists
    - xfs: check v5 superblock features early
    - futex: Fix race in futex_pivot_pending() during private hash resize
    - sched_ext: Update p->scx.disallow warning in scx_init_task()
    - sched_ext: Reorganize enable/disable path for multi-scheduler support
    - ring-buffer: Store bpage pointers into subbuf_ids
    - arm64: tegra: Add EL2 virtual timer interrupt for Tegra194
    - crypto: ccm - Set rfc4309 maxauthsize from child
    - riscv: ftrace: Fix ftrace_modify_call failure on kprobed functions
    - gpio: ml-ioh: share the register lock across channels
    - ASoC: tas2781: fix clang build error for goto bypassing cleanup variable
    - netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort
      path
    - netfilter: ipset: fix list type element drift bug
    - netfilter: ipset: let destroy callbacks adjust ext mem size
    - eth: bnxt: cancel IRQ notifier before freeing affinity mask
    - eth: bnxt: keep the aRFS rmap updated when TPH is enabled
    - tcp: fix icsk_ack.ato bitfield overflow
    - net: phy: realtek: fix EEE advertisement write on the internal PHY MMD
      path
    - net: packet: fix wrong transport_header when sending VLAN-tagged frame
    - net: tap: fix wrong transport_header when sending VLAN-tagged frame
    - net/tls: Fail tls_sw_splice_read() after a failed async decrypt
    - ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers
    - regmap: sdw-mbq: Fix swap of timeout and retry times
    - af_packet: Don't send zero-byte data in tpacket_snd().
    - m68k: Define NR_CPUS to 1
    - accel/amdxdna: Skip unmapped range in aie2_populate_range()
    - drm/xe/oa: Fix sync entry leak on OA config emit failure
    - drm/log: Fix out-of-bounds read on empty message length
    - drm/log: Fix infinite loop when scale is too large for display
    - spi: virtio: mark device ready before registering the controller
    - erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms
    - ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r
    - drm/amdgpu/userq: serialize queue map against GPU reset
    - drm/amd: Disable DP audio spread spectrum for Cyan Skillfish
    - drm/radeon: restore hardware polling in fence_is_signaled to fix
      performance regression
    - drm/amdgpu: fix JPEG v5.3.0 queue reset failure in DPG mode
    - drm/amdgpu/gmc12.1: implement tlb inv semaphore
    - drm/amdgpu/gmc12.1: fix MMHUB0 check in pasid tlb flush
    - Input: atkbd - skip deactivate for HONOR ZQC-P
    - pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev()
    - ftrace: Protect direct_functions in update_ftrace_direct_del
    - ftrace: Protect direct_functions in update_ftrace_direct_mod
    - drm/xe/guc_ads: allocate UM queues in a separate BO
    - drm/xe/guc_ads: allocate UM queues in VRAM on dGFX
    - drm/xe/guc_ads: use uncached mapping for UM queue BO
    - drm/amdgpu: fix missing check in vm_flush()
    - drm/amdkfd: Add bounds check for CRAT subtype length
    - net: rename netdev_ops_assert_locked()
    - clk: spacemit: k3: fix USB2 bus clock
    - gpiolib: Check gc->get_direction() before calling gpiod_get_direction()
    - regulator: fp9931: Fix VPOS/VNEG voltage selector table
    - ovpn: run deferred work on a module-owned workqueue
    - tick: Include ktime.h and jiffies.h in linux/tick.h
    - eth: bnxt: decrease indent in bnxt_request_irq()
    - drm/xe/pxp: add termination on resume
    - drm/xe/oa: Check managed mutex initialization errors
    - drm/xe: Set GT rp min frequency as 1.2GHz default for BMG/CRI
    - drm/xe: Fix a bug in pc_adjust_freq_bounds()
    - drm/log: Fix division by zero when scale module parameter is 0
    - Upstream stable to v6.18.45, v6.18.46, v7.1.9, v7.1.10
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74735
    - l2tp: fix tunnel and session refcount leak on seq_file release
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74745
    - eth: bnxt: avoid deadlock when canceling IRQ affinity notifier
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74747
    - ipvs: revalidate ihl to prevent out-of-bounds access
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74750
    - ovpn: defer key slot crypto freeing to workqueue
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74752
    - sctp: validate cookie AUTH state before use
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74754
    - scsi: core: pair EH runtime PM get and put
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80521
    - af_unix: Unlink scc_entry in unix_del_edge().
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80523
    - clk: spacemit: k3: set hdma clock as critical
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80524
    - optee: ffa: Add NULL check in optee_ffa_lend_protmem
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80557
    - libceph: fix OOB read in decode_watchers() via missing bounds check
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80579
    - fbdev: clear fb_info->mode before deleting a videomode
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80580
    - fbdev: bound mode sysfs output to the sysfs buffer
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80582
    - drm/shmem_helper: Check VMA boundaries for PMD mappings
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80583
    - ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74734
    - firewire: ohci: fix NULL pointer dereference in ar_context_release
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74736
    - net/sched: cls_bpf: reject dev-bound programs bound to a different
      device
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74737
    - net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74738
    - regmap: sdw-mbq: don't call an unset readable_reg callback
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74739
    - net/sched: cls_u32: skip hash tables in u32_bind_class()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74740
    - net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74741
    - net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74742
    - veth: fix queue index used to wake the peer txq in veth_poll
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74743
    - macvlan: inherit needed_headroom and needed_tailroom from lowerdev
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74744
    - ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74746
    - netfilter: flowtable: publish GC-visible tuple last
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74748
    - netfilter: ipset: fix refcount race between list:set GC and swap
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74753
    - perf: Reject exited events as group leaders
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80519
    - ovpn: finish crypto callback cleanup before peer release
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80520
    - ovpn: fix NULL dereference when killing missing key
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80522
    - crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80525
    - ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80526
    - ASoC: tas2562: Validate values for volume writes
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80527
    - ceph: fix hanging __ceph_get_caps() with stale mds_wanted
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80528
    - ceph: avoid fs reclaim while using current->journal_info
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80529
    - xfs: don't swallow dquot recovery verification errors
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80530
    - xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80531
    - xfs: avoid UAF on sc->tempip in xrep_tempfile_create
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80532
    - xfs: fix another iunlink infinite loop bug in online fsck
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80533
    - xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80534
    - xfs: fix ilock leak on error in xfs_dq_get_next_id
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80535
    - xfs: don't double-lock when deleting a self-referential directory
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80536
    - xfs: bounds-check buffer log item's dirty bitmap
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80537
    - xfs: fix off-by-one in rtrefcount btree root level validation
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80538
    - xfs: propagate errors from xfs_rtginode_load
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80539
    - drm/amdgpu: disallow multiple FENCE chunks in one submit
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80540
    - drm/amdgpu: Fix UVD decode image min size calculation
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80541
    - drm/amdgpu: validate GEM_CREATE domain combinations
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80542
    - drm/amd/display: Fix NULL pointer dereference in
      amdgpu_dm_crtc_set_vblank()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80547
    - s390/vfio_ccw: Implement a crw lock
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80548
    - s390/vfio_ccw: Selectively expand io_mutex
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80549
    - s390/vfio_ccw: Move cp cleanup out of not operational
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80550
    - s390/vfio_ccw: Fix out of bounds check on CCW array
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80551
    - s390/vfio_ccw: Ensure first IDAW remains constant
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80552
    - s390/vfio_ccw: Ensure index for read/write regions are within range
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80553
    - s390/vfio_ccw: Cancel existing workqueues
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80554
    - s390/vfio_ccw: Limit the number of channel program segments
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80555
    - s390/vfio_ccw: Free all memory if cp_init() fails
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80556
    - mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80558
    - libceph: Avoid using invalid osd indices from primary_temp
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80559
    - Input: sur40 - fix input device registration ordering
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80560
    - openrisc: signal: do not restore privileged SR bits on sigreturn
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80561
    - libceph: fix multiple unsafe decodes in decode_locker()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80562
    - gpio: ml-ioh: use raw_spinlock_t for the register lock
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80563
    - gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on
      unbind
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80564
    - gve: fix NULL dereference due to missing ptp adjfine
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80565
    - crypto: qce - fix error path in devm_qce_register_algs
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80566
    - Input: hynitron_cstxxx - validate touch count and finger IDs
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80567
    - Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80568
    - Input: synaptics-rmi4 - block s_input when F54 queue is busy
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80569
    - Input: synaptics-rmi4 - bound the F54 report size to the allocated
      buffer
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80570
    - Input: synaptics-rmi4 - zero report size on F54 work error
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80571
    - powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80572
    - Input: byd - synchronize timer deletion before freeing private data
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80573
    - Input: iforce - validate input packet lengths
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80574
    - Input: focaltech - fix array out-of-bounds in
      focaltech_process_rel_packet
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80575
    - Input: cs40l50-vibra - validate custom data from user space
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80576
    - drm/amdgpu: reject oversized IBs with per-ring packet limits
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80577
    - drm/panthor: skip zero-sized firmware sections
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80578
    - fbdev: core: Fix pointer desynchronization in fb_io_read()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80581
    - ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC
      timeout
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80584
    - s390/qeth: validate user buffer length in SNMP and ARP query ioctls
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80585
    - mptcp: fastopen: only mark MPTFO subflows with SYN data
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80586
    - mptcp: options: reset DSS fields in case of unexpected size
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80587
    - mptcp: avoid combining some incoming suboptions
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80588
    - mptcp: reclaim forward-allocated memory on RX path errors
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-80589
    - block: stop the timeout timer when releasing a never added disk
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74593
    - sched_ext: Take cgroup_lock() first in scx_cgroup_lock()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74596
    - fs,fsverity: remove check for fsverity being enabled in
      setattr_prepare()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74600
    - mm/page_table_check: skip special zero mappings
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74605
    - eventfs: Use children field for rcu head and add memory barriers
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74626
    - NTB: ntb_netdev: Preserve RX queue depth on allocation failure
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74645
    - mm/damon/lru_sort: error out for >10000 active_mem_bp
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74674
    - mm: fix incorrect flush address in direct page table reclaim
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74686
    - rqspinlock: Reset tail when preserving queue on deadlock
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74699
    - drm/xe: Fix memory leak in exec_queue_set_hang_replay_state()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74706
    - bnge: Fix NULL pointer dereference in aux device release
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74713
    - vhost_iotlb: bound map allocation in add_range
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74715
    - bpf: Fix netns reference imbalance in conntrack kfuncs
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74716
    - accel/amdxdna: Fix locally exploitable BUG_ON in amdxdna_insert_pages()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74721
    - accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74723
    - btrfs: lzo: reject inline extents without valid headers
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74729
    - soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74733
    - gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74585
    - thunderbolt: Bound the DROM dual link port number before indexing
      sw->ports
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74586
    - sctp: clear new_transport when removing a peer
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74587
    - sctp: fix use-after-free of cached ASCONF chunk
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74588
    - sctp: keep chunk->transport in step with the list it is queued on
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74589
    - bpf, sockmap: Fix sk_redir use-after-free in send verdict
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74590
    - fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74591
    - mm/filemap: __filemap_add_folio() restore index before retrying
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74592
    - ima: Instantiate file_truncate and path_truncate hooks
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74594
    - sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74595
    - fscrypt: use the mount idmap for the owner check in
      fscrypt_ioctl_set_policy()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74597
    - ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74598
    - ipv6: fix Route Information option length validation
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74599
    - mm/ptdump: always stabilise against page table freeing using init_mm
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74601
    - ring-buffer: Use current_context for safe per-CPU buffer swap
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74602
    - ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74603
    - ptp: ocp: Fix board ID over-read
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74604
    - Revert "thermal/drivers/hwmon: Cleanup coding style a bit"
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74606
    - eventfs: Fix use-after-free in eventfs_remove_rec()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74607
    - KVM: SVM: Serialize accesses to the owner and mirror list with separate
      lock
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74608
    - smb: client: Fix use-after-free in cifs_try_adding_channels()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74609
    - tipc: read le->link under the node lock in tipc_node_link_down()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74610
    - tls: don't leave a full plaintext sk_msg ring unpushed
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74611
    - tls: rx: restore msg_iter before TLS 1.3 optimistic retry
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74580
    - vhost: reset the vring metadata cache on vring reconfiguration
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74612
    - veth: fix skb length accounting after XDP frag adjustment
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74613
    - vsock/virtio: avoid refilling the RX queue after teardown
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74614
    - vsock/virtio: read virtqueues under worker locks
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74615
    - vxlan: do not arm the ageing timer on a device that is down
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74616
    - xdp: reject clones that overrun skb_shared_info tailroom
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74617
    - dibs: initialise dibs->lock in dibs_dev_alloc()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74618
    - binfmt_misc: don't warn when the mount is completed from another user
      namespace
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74619
    - ovl: don't warn when the mount is completed from another user namespace
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74620
    - net/sched: act_gact, act_police: range check the fallback control action
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74621
    - net/sched: act_ct: fix sk_buff leak when the header checks reject a
      packet
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74622
    - net: atlantic: free RX pages of consumed but not refilled buffers
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74623
    - net: atlantic: free stranded TX buffers on ring deinit
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74624
    - netfilter: nf_conntrack: defer invalid log until after unlock
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74625
    - netfilter: bridge: release template ct on non-IP path
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74627
    - net: devmem: prevent net-iov / page mixing
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74628
    - net/x25: fix use-after-free of the socket by its timers
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74629
    - net/dibs: Correct freeing of dmb_clientid_arr
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74630
    - ipv6: prevent in6_dev_get() from resurrecting inet6_dev
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74631
    - net: smc: fix splice entry lifetime imbalance in smc_rx_splice
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74632
    - mm/huge_memory: fix huge_zero_pfn race
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74633
    - tracing: Fix NULL pointer dereference in module event cache removal
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74634
    - ring-buffer: Prevent subbuf order change when resizing is disabled
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74635
    - fbdev: bitblit: bound-check glyph index in bit_cursor()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74636
    - tracing: Fix race between update_event_fields and, event_define_fields
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74637
    - perf/core: Fix group leader use-after-free after sibling detach
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74638
    - drm/v3d: Serialize the scheduler timeout handlers
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74639
    - ALSA: us144mkii: re-anchor capture URBs on resubmission
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74640
    - ALSA: FCP: fix OOB write in fcp_meter_ctl_get()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74641
    - ALSA: usx2y: bound the hwdep mmap fault offset
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74643
    - samples/damon/mtier: error out for zero quota goal target values
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74644
    - mm/damon/ops-common: putback folios on invalid migrate nid
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74646
    - misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74647
    - misc: fastrpc: Remove buffer from list prior to unmap operation
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74648
    - staging: rtl8723bs: validate monitor transmit frame lengths
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74649
    - staging: rtl8723bs: fix missing shared-key auth challenge length check
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74650
    - staging: rtl8723bs: fix OOB read in WMM_param_handler()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74651
    - staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74652
    - serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74653
    - serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74654
    - serial: 8250_dma: Clear stale RX state on shutdown
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74655
    - serial: qcom-geni: fix TX DMA buffer flush
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74656
    - ipv4: fix use-after-free in fib_nhc_update_mtu()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74657
    - ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74658
    - futex: Prevent robust futex exit race some more
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74659
    - net: bridge: mrp: fix uninitialised bytes on the wire
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74660
    - netfilter: ebt_nflog: pin the NFLOG backend
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74661
    - mac802154: fix netdev use-after-free in beacon worker
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74662
    - inet: frags: publish queues before arming timer
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74663
    - net/sched: reject overly deep qdisc hierarchies
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74664
    - net: openvswitch: reallocate update replies for mismatched IDs
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74665
    - net: fix skb length accounting after generic XDP frag adjustment
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74666
    - packet: synchronize pressure clearing with ring reconfiguration
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74667
    - net/packet: reset the MAC header on the packet-socket transmit path
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74668
    - packet: use consistent hard_header_len in TX_RING send path
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74582
    - packet: use consistent hard_header_len in non-ring send paths
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74669
    - ipvs: clear IPv4 options after rebasing tunnel ICMP errors
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74670
    - ipvs: stop estimator after disabled calc phase
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74671
    - ima: fix out-of-bounds read in xattr_verify()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74672
    - mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74673
    - Input: evdev - fix information leak in evdev_pass_values()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74675
    - vt: stabilize tty reference in kbd_keycode with tty_port_tty_get
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74676
    - vt: add permission check for KDSKBMETA ioctl
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74677
    - net: usb: ipheth: fix carrier_work UAF on disconnect
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74678
    - net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74679
    - usb: gadget: f_ncm: Use unsigned int for ndp_index
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74680
    - usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74681
    - usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74682
    - ALSA: usb-audio: fix OOB write on Type II inbound URBs
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74683
    - Input: evdev - sanitize event type index when fetching event masks
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74684
    - net: tap: set skb->dev before parsing virtio net header in
      tap_get_user_xdp()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74685
    - hwmon: (ltc4282) Clamp negative current limits
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74687
    - watchdog: at91sam9_wdt: prevent timer rearm during teardown
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74688
    - sctp: clear control chunk transport if it is being removed
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74689
    - net/atm: fix slab-out-of-bounds read in vcc_setsockopt()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74690
    - s390/ism: Fix UAF of sba and ieq during ism_dev_exit()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74691
    - net: thunderbolt: Tear down DMA paths before stopping the rings
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74692
    - net/smc: fix TOCTOU race between smc_listen_out() and listener close
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74693
    - net: prestera: validate firmware header length
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74694
    - net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74695
    - netfilter: nf_flow_table: drop existing skb dst before
      skb_dst_set_noref()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74696
    - tcp: fix TFO max_qlen accounting across reuseport migration
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74697
    - bnxt_en: Disable EOP for TPA on all chips to prevent data corruption
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74698
    - net/mlx5e: fix BQL reset on SQ re-activation
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74700
    - net/sched: cls_api: Always acquire rtnl_lock when destroying locked
      classifiers
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74701
    - net/openvswitch: check Ethernet header length in key_extract()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74702
    - vhost-scsi: reject feature changes after endpoint
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74703
    - vhost-scsi: Validate T10 PI scatterlist counts
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74704
    - net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74705
    - udp: fix potential use-after-free in tunnel segmentation
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74707
    - xsk: validate metadata when processing requests
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74708
    - xsk: validate launch-time metadata size
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74709
    - xsk: clear metadata pointer when no timestamp is requested
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74710
    - xsk: require at least 16 bytes of TX metadata
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74711
    - hwmon: (pmbus) Fix type confusion in notification logic
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74712
    - vdpa/mlx5: Fix buffer length in create_direct_keys()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74714
    - bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74717
    - net/mlx5: fw_tracer, return NULL on create error
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74718
    - devlink: fix net namespace reference leak in reload
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74583
    - net/sched: cls_route: fix fastmap use-after-free on filter
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74719
    - net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in
      smc_llc_event_handler()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74720
    - bpf: Preserve pointer state for commuted arithmetic
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74722
    - btrfs: fix memory leak in btrfs_do_encoded_write()
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74724
    - ipvs: avoid out-of-bounds write in ip_vs_nat_icmp
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74725
    - enic: fix tx_hang_reset use-after-free on device removal
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74726
    - bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74727
    - ovpn: skip rehash for peers already removed from by_id
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74728
    - xfs: handle NULL b_addr in xfs_buf_free
  * Resolute update: upstream stable patchset 2026-09-01 (LP: #2166029) //
    CVE-2026-74730
    - NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942)
    - kunit: tool: skip stty when stdin is not a tty
    - kunit: tool: Terminate kernel under test on SIGINT
    - netfilter: br_netfilter: Reallocate headroom if necessary in
      neigh_hh_bridge()
    - ALSA: hda/realtek: add quirk for HP Dragonfly Folio G3 2-in-1
    - HID: logitech-dj: Standardise hid_report_enum variable nomenclature
    - HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB
      write
    - HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report
    - lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled()
    - pinctrl: qcom: Unconditionally mark gpio as wakeup enable
    - pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151
    - dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA
    - gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe()
    - selftests/lkdtm: rename STACKLEAK_ERASING to KSTACK_ERASE
    - Revert "UBUNTU: SAUCE: selftests/seccomp fix compilation issue for
      amd64"
    - selftests/seccomp: Fix pointer type mismatch build error
    - ata: sata_mv: accept 1 or 2 resources in platform probe
    - ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources()
    - phy: qcom: m31-eusb2: Fix return value of init call
    - ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup
    - ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup
    - of: reserved_mem: prevent OOB when too many dynamic regions are defined
    - btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag
    - btrfs: zoned: reset meta_write_pointer on zone reset
    - btrfs: raid56: fix an incorrect csum skip during scrub
    - phy: zynqmp: fix clock error handling in xpsgtr_phy_init()
    - phy: zynqmp: fix runtime PM leak on probe allocation failure
    - drm/mediatek: Check CRTC state before freeing
    - Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep
      annotation
    - mshv: Fix duplicate GSI detection for GSI 0
    - mshv: Fix sleeping under spinlock in mshv_portid_alloc
    - KVM: arm64: Reject guest_memfd memslots when the VM has MTE
    - KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return
      type
    - assoc_array: trim the final shortcut word using the current chunk end
    - ipvs: fix the checksum validations
    - ipvs: fix places with wrong packet offsets
    - ipvs: do not mangle ICMP replies for non-first fragments
    - ASoC: SDCA: Ensure that Control Range is large enough for header
    - af_unix: fix listen() succeeding on sockets in the wrong state
    - selftests/net/af_unix: test listen() rejects wrong socket states
    - pinctrl-amd: Don't clear S4 wake bits at probe
    - smb: client: fix buffer leaks in SMB1 read and write
    - ASoC: tas2781: Use correct calibration data for SINEGAIN2 register
    - spi: spi-cadence: Move TX FIFO full busy-wait into FIFO
    - hwmon: (ina2xx) Make it easier to add more devices
    - hwmon: (ina2xx) Add support for INA234
    - hwmon: (ina2xx) Shift INA234 shunt and current registers
    - hwmon: (ina2xx) Fix various overflow issues
    - hwmon: (ltc4282) Fix reading the minimum alarm voltage
    - hwmon: (sht3x) Fix unaligned accesses
    - net: bridge: mrp: fix Option TLV length in MRP_Test frames
    - hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors
    - hwmon: (adt7470) Fix cache updated before hardware write on I2C error
    - hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read()
    - hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks
    - hwmon: (adt7470) Use cached PWM frequency value
    - hwmon: (adt7470) Fix PWM auto temp state array and bounds check
    - powerpc/boot: Fix simpleboot CPU node lookup check
    - powerpc/boot: Fix treeboot-currituck CPU node lookup check
    - powerpc/boot: Fix treeboot-akebono CPU node lookup check
    - wifi: mac80211: validate individual TWT params before driver setup
    - netfs: clear PG_private_2 on copy-to-cache append failure
    - netfs: handle single writeback rolling buffer allocation failure
    - netfs: release readahead folios on iterator preparation failure
    - net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in
      poll_controller
    - hwmon: (pmbus) Fix return value from pmbus_update_byte_data()
    - idpf: adjust TxQ ring count minimum
    - idpf: Fix mailbox IRQ name leak on request failure
    - ice: suppress DPLL errors during reset recovery
    - Bluetooth: ISO: Fix data-race on iso_pi(sk) in socket and HCI event
      paths
    - Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos
    - Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis()
    - Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release
    - Bluetooth: ISO: ensure no dangling hcon references in iso_conn
    - Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists
    - Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync
    - x86/boot: Add volatile, clobbers and zero-length test in memcmp()
    - net: phylink: put link_gpio if phylink_create fails
    - scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE
    - scsi: ufs: core: Cancel RTC work in active-active suspend
    - scsi: ufs: core: Avoid IRQ thread wakeup during active UIC command
    - scsi: ufs: core: Revert "Delegate the interrupt service routine to a
      threaded IRQ handler"
    - scsi: zfcp: Fix memory leak during adapter release by destroying
      gid_pn_req
    - scsi: target: Clear cmd_cnt when initial counter enrollment fails
    - net: sxgbe: check descriptor ring allocation failures
    - can: isotp: check register_netdevice_notifier() error in module init
    - drm/i915/dp: Ignore the sink's DSC max FRL rate without a PCON DSC
      encoder
    - fprobe: Fix module reference count leak on error in register_fprobe()
    - tracing/mmiotrace: Reset dropped_count in mmio_reset_data()
    - tracing/mmiotrace: Add NULL check for mmio_trace_array in logging
      functions
    - riscv: drop __init from vec_check_unaligned_access_speed_all_cpus
    - accel/qaic: use sizeof(*trans_hdr) for transaction length check
    - net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend
    - net: dsa: mt7530: error out on failed reads in MT7531 PHY polling
    - ptp: netc: fix potential interrupt storm caused by incorrect unbind
      order
    - net: libwx: fix FDIR ATR queue mismatch for software VLAN packets
    - octeontx2-pf: Set correct sequence for carrier off and tx queue stop
    - sched/deadline: Use revised wakeup rule only for running dl_server
    - spi: spi-nxp-fspi: add per-SoC SDR/DTR clock rate limits for all
      supported SoCs
    - drm/i915/hdmi: Poll for 200 msec for TMDS_Scrambler_Status
    - ksmbd: return success for deferred final close
    - iomap: add a separate bio_set for iomap_split_ioend
    - mshv: Fix race in mshv_irqfd_deassign
    - mshv: Fix level-triggered check on uninitialized data
    - mshv: Order pt_vp_array publish against irqfd assertion path
    - iommufd/viommu: Release the igroup lock on the vdevice_size error path
    - iommufd/viommu: Publish a vDEVICE only after vdevice_init() succeeds
    - iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on
      replace
    - pinctrl: microchip-sgpio: add missing select REGMAP_MMIO
    - erofs: cap LZMA stream pool size
    - [Config] Add EROFS_FS_LZMA_DEFAULT_MAX_STREAMS
    - pinctrl: bm1880: add missing select GENERIC_PINCONF
    - fortify: Disable -Wstringop-overread in tests
    - mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE
    - mm/util: don't read __page_2 for order-1 folios in snapshot_page()
    - selftest: fix headers in fclog.c
    - fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes
    - mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()
    - mm/vmstat: fold stranded per-cpu node stats when a node comes online
    - tracing/probes: Reject $arg0 in meta argument expansion
    - tracing/fprobe: Roll back on enable_trace_fprobe() failure
    - KVM: VMX: add memory clobber to asm for VMX instructions
    - KVM: s390: pci: Fix missing error codes and memory unaccounting
    - KVM: s390: pci: Fix NULL dereference on AIBV allocation failure
    - KVM: s390: pci: Validate AIBV and AISB before pinning guest pages
    - sctp: validate Adaptation Indication parameter length
    - audit: fix potential integer overflow in audit_log_n_string()
    - Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req()
    - Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read()
    - Bluetooth: SCO: give the socket its own sco_conn reference
    - bpf: lwt: Fix dst reference leak on reroute failure
    - afs: Fix afs_fs_fetch_data() to set call->async
    - afs: Fix afs_fs_fetch_data() to subtract transferred from len
    - ALSA: hda/realtek: Add quirk for TongFang X6SP45xU
    - ALSA: lx6464es: fix period byte count for 16-bit streams
    - ALSA: pcm: wake linked drain waiters on unlink
    - ASoC: fsl_asrc: fix m2m_init error path to use goto instead of bare
      return
    - ASoC: fsl_easrc: fix m2m_init error path to use goto instead of bare
      return
    - ASoC: tas2562: fix DVC coefficient write order
    - ASoC: tas2562: fix broken entries in the volume lookup table
    - ata: libata-eh: Increase STANDBY IMMEDIATE timeout
    - ata: libata-sata: fix ata_scsi_lpm_supported() iteration
    - dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+
    - e1000: fix memory leak in e1000_probe()
    - igc: remove napi_synchronize() in igc_down()
    - ipvs: do not propagate one-packet flag to synced conns
    - mshv: fix hv_input_get_system_property struct
    - io_uring/net: initialize mshot_len for send
    - mm: memcg: initialize *locked in memcg1_oom_prepare() stub
    - net: ipv6: clear suppressed fib6 rule result
    - powerpc/ps3: Fix map failure path in dma_ioc0_map_pages()
    - vxlan: re-fetch eth header after route_shortcircuit()
    - vxlan: unclone skb head before modifying eth header in
      route_shortcircuit()
    - tracing/filters: Fix false positive match in regex_match_full()
    - spi: spi-qpic-snand: write the feature value before executing
      SET_FEATURE
    - spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure
    - selftests/mm: fix potential wild pointer access of getline due to
      missing init
    - selftests/clone3: fix wild pointer access of getline due to missing init
    - sctp: reject stale cookies with mismatched verification tags
    - hwmon: (npcm750-pwm-fan): stop fan timer on device detach
    - hwmon: (pmbus/core) notify on the hwmon device, not the i2c client
    - i2c: amd-mp2: Unregister callback on adapter add failure
    - gpio: pca953x: fix cache_only and IRQ state on restore_context() failure
    - cifs: add fscache_resize_cookie() to cifs_setsize()
    - cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init()
    - cpufreq: schedutil: Publish util hooks only after all sg_cpu are
      initialized
    - power: supply: bq25890: fix the -10 C NTC lookup entry
    - power: supply: max17040: handle missing status supplier
    - s390/pci: Fix s390_pci_mmio_write syscall error return without MIO
    - s390/dasd: Fix potential NULL pointer dereference
    - s390/dasd: Fix undersized format-check buffer
    - s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs
    - s390/zcrypt: Fix missing mem scrub at clear key import in
      cca_clr2cipherkey()
    - phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask
    - phy: zynqmp: use read-modify-write for SERDES scrambler bypass
    - phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB
    - net: openvswitch: fix skb leak on flow key update failure during
      recirculation
    - ice: fix VF interrupts cleanup
    - ice: fix memory leak in ice_lbtest_prepare_rings()
    - i2c: spacemit: request IRQ after controller initialization
    - i2c: qcom-cci: drop custom suspend/resume and rely on runtime PM helpers
    - i2c: iproc: reset bus after timeout if START_BUSY is stuck
    - i2c: imx: Fix slave registration race and error handling
    - can: c_can: c_can_chip_config(): keep controller in init mode until
      bittiming is configured
    - can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb
      allocation failure
    - can: j1939: transport: j1939_session_fresh_new(): initialize receive
      buffer
    - can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking
    - can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in
      kvaser_usb_hydra_get_busparams()
    - can: softing: fw_parse(): validate firmware record spans
    - can: ctucanfd: add missing MODULE_DEVICE_TABLE()
    - can: ctucanfd: use self-test mode for PRESUME_ACK
    - can: ctucanfd: unmap BAR0 using base address
    - can: ctucanfd: handle bus error interrupts
    - can: ctucanfd: mark error-active controller status valid
    - drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs
    - drm/bridge: display-connector: Fix I2C adapter resource leak
    - drm/mediatek: ovl_adaptor: balance component registrations
    - drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini
    - drm/amdgpu: restore UMD profile pstate after runtime resume
    - drm/amd/pm: fix torn gpu metrics reads
    - drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames
    - drm/amd/display: use proper context for logging
    - drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE
    - drm/amdkfd: Handle invalid event type in CRIU event restore
    - drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size
    - drm/vmwgfx: clamp dirty-page range with min, not max
    - drm/vmwgfx: take fman->lock around fence list mutation in fifo_down
    - drm/vmwgfx: drop dma_buf reference on foreign-fd prime import
    - drm/vmwgfx: enforce cursor size limits for MOB cursors
    - drm/vmwgfx: use check_add_overflow for shader size+offset bound
    - drm/vmwgfx: validate external BO copy bounds for both stride paths
    - HID: logitech-dj: Fix maxfield check in DJ short report validation
    - drm/xe/rtp: Maintain OA whitelists separately
    - drm/xe/rtp: Keep track of non-OA nonpriv slots
    - drm/xe/rtp: Generalize whitelist_apply_to_hwe
    - drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs
    - drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt
    - drm/xe/oa: (De-)whitelist OA registers on OA stream open/release
    - drm/xe/rtp: Ensure locking/ref counting for OA whitelists
    - mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()
    - fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes
    - net/handshake: Close the submit-side sock_hold race
    - usb: typec: ucsi: split connector lock classes
    - media: chips-media: wave5: Support CBP profile
    - drm/xe: add xe_migrate_resolve wrapper and is_vram_resolve support
    - drm/xe/bo: Add purgeable bo state tracking and field madv to xe_bo
    - drm/xe/vm: Prevent binding of purged buffer objects
    - drm/exec: Remove the index parameter from
      drm_exec_for_each_locked_obj[_reverse]
    - can: isotp: fix timer drain order, wakeup handling and tx_gen ordering
    - usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path
    - mm/slab: decouple SLAB_NO_SHEAVES from SLAB_NO_OBJ_EXT
    - ALSA: hda/realtek: Add quirk for HP Dragonfly Folio G3 2-in-1
      (103c:8a05)
    - KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context
    - dmaengine: idxd: fix double free of wq, engine, and group structs
    - btrfs: warn about extent buffer that can not be released
    - btrfs: zoned: skip fully truncated ordered extents at zone finish
    - rtla/timerlat_top: Fix on-threshold actions firing on signal
    - selftests: netfilter: nft_flowtable.sh: fix offload counter verification
      for tunnel tests
    - netfilter: nf_conntrack_expect: add and use nf_ct_expect_related_pair()
    - mshv_vtl: fix fd leak in mshv_ioctl_create_vtl()
    - ipvs: clear the nfct flag under lock
    - ASoC: SDCA: Correct pointer passed to devm_acpi_table_put
    - ASoC: SDCA: Always free firmware in FDL path
    - ASoC: SDCA: Make UMP message size check more robust
    - xsk: provide sufficient space in pool->tx_descs
    - net/sched: sch_cake: skip clearing unused tins during rate adjustment
    - erofs: clean up erofs_ishare_fill_inode()
    - erofs: remove fscache backend entirely
    - [Config] Remove EROFS_FS_ONDEMAND
    - erofs: ensure valid f_path for page cache sharing
    - ASoC: sophgo: return 1 on volume change in cv1800b_adc_volume_set()
    - ethtool: Embed FEC hist ranges as buffer in struct
    - idpf: bound interrupt-vector register fill to the allocated array
    - Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks
    - Bluetooth: hci_sync: remove unnecessary hci_conn_get in create_conn_sync
    - scsi: ufs: core: Initialize hba->rpmbs list in ufshcd
    - drm/xe/pt: check no-DMA huge-pte cases before DMA segment test
    - ipv6: release fib6_null_entry on subtree failure
    - riscv: vdso: Only try to install vDSO when present
    - net: dsa: mt7530: error out on failed reads in ATC/VTCR command polling
    - net: stmmac: Fix E2E delay mechanism
    - net: mana: Create separate EQs for each vPort
    - net: mana: Return error code from mana_create_rxq()
    - mshv: Fix missing error code on VP allocation failure
    - mshv: Publish VP to pt_vp_array before installing the file descriptor
    - iommufd: Reject DMABUF pages from the access pin path
    - btrfs: raid56: fix scrub read assembly submitting no reads
    - btrfs: zoned: fix missing chunk metadata reservation
    - ocfs2: fix boundary check in ocfs2_check_dir_entry() to use buffer
      offset
    - userfaultfd: wait on source PMD during UFFDIO_MOVE
    - KVM: s390: pci: Fix resource leak on IRQ registration failure
    - Bluetooth: btmtk: Fix short read errors in btmtk_usb_reg_read()
    - ata: libata-scsi: terminate deferred commands on time out
    - ata: libata-scsi: schedule deferred atapi command
    - PCI: imx6: Keep i.MX6 Root Port MSI/MSI-X Capabilities with iMSI-RX to
      work around hardware bug
    - io_uring: preserve task restrictions across exec
    - scsi: libsas: terminate deferred commands on time out
    - scsi: ufs: dt-bindings: Add missing mcq reg for qcom,sa8255p-ufshc
    - can: rcar_canfd: change the initializing flow for clocks and resets
    - drm/mediatek: mtk_hdmi: Fix DDC adapter double put in v2
    - drm/amd/pm: hide pp_table sysfs on APUs
    - drm/amd/pm: use milliwatts for GPU power sensors
    - drm/amd/display: check if dml21_add_phantom_plane() is successful
    - drm/xe: Drop unused param from xe_device_create()
    - drm/xe: Move xe->info.force_execlist initialization
    - drm/xe: Move xe->info.devid|revid initialization
    - drm/xe: Drop unnecessary goto in xe_device_create
    - drm/xe: Separate early xe_device initialization
    - drm/xe: Set TTM device beneficial_order to 9 (2M)
    - Upstream stable to v6.18.44, v7.1.8
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74449
    - drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero
      viewport
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74450
    - drm/amd/pm: fix pptable use-after-free
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74466
    - s390/zcrypt: Close speculative mem read possibility
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74483
    - binfmt_misc: don't leak the user namespace when the mount fails
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74496
    - fou: Fix use-after-free in fou_create()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74517
    - KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74521
    - ksmbd: use memcmp() to compare ClientGUIDs
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74526
    - scsi: mpi3mr: Fix potential deadlock in mpi3mr_fault_uevent_emit
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74528
    - Bluetooth: hci_sync: hold conn in hci_past_sync() callback
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74529
    - Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74530
    - Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74533
    - Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74542
    - netfs: Fix folio_queue ENOMEM in writeback by adding a mempool
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74544
    - net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74554
    - wifi: ath12k: fix out-of-bounds clear_bit in
      ath12k_mac_dp_peer_cleanup()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74558
    - xsk: reclaim invalid Tx descriptors in ZC batch path
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74561
    - nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74562
    - nexthop: take nh->lock for f6i_list walks in replace check and notify
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74571
    - btrfs: skip global block reserve accounting for rescue mounts
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74440
    - drm/xe: Wait on external BO kernel fences in exec IOCTL
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    [SRU] amdgpu: Fix garbled display when switching workspaces (LP: #2166730)
    - drm/amd/display: check GRPH_FLIP status before sending event
    - drm/amd/display: Exit idle optimizations before programming
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74441
    - usb: typec: ucsi: Fix race condition and ordering in port unregistration
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74482
    - mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74442
    - drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74443
    - drm/vmwgfx: bound DMA command body size against suffix pointer
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74444
    - drm/vmwgfx: validate DRAW_PRIMITIVES header size before division
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74445
    - drm/vmwgfx: reject DX_BIND_QUERY without a DX context
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74446
    - drm/amdkfd: hold event_mutex while checkpointing CRIU events
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74447
    - drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74448
    - drm/amdkfd: fix QID bit leak in pqm_create_queue()
  * [SRU] Fix incorrect GTT calculation on the APU systems (LP: #2162038) //
    Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942)
    - drm/amdgpu: cap GTT size to physical RAM on APUs
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74451
    - drm/panthor: validate firmware interface structure sizes
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74452
    - drm/panthor: reject firmware sections with oversized data
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74453
    - drm/vc4: Zero the tile state data array before each BIN job
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74454
    - drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO
      size
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74455
    - can: peak_usb: validate uCAN receive record lengths
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74456
    - can: peak_usb: peak_usb_start(): fix double free of transfer buffer on
      URB submit error
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74457
    - can: peak_usb: add bounds check for USB channel index
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74458
    - can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received
      command extents
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74459
    - can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB
      resubmit failure
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74460
    - can: ems_usb: validate CPC message lengths
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74461
    - i2c: imx: Cancel hrtimer before clearing slave pointer
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74462
    - i2c: imx: mark I2C adapter when hardware is powered down
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74463
    - i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock
      deadlock
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74464
    - net: openvswitch: fix skb leak on flow key update failure during ct
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74465
    - net: openvswitch: fix potential UAF on meter attach failure
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-68451
    - s390/zcrypt: Validate length for CCA ECC private key requests
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-68452
    - s390/zcrypt: Validate length for CCA AES cipher key requests
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-68453
    - s390/zcrypt: Fix buffer over-read in cca_cipher2protkey
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74467
    - s390/qeth: Check CAP_NET_ADMIN for private ioctls
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74468
    - gpio: pch: use raw_spinlock_t for the register lock
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74469
    - sctp: prevent peer transport count overflow
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74470
    - scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74471
    - tracing: Check return value of __register_event() in
      trace_module_add_events()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74472
    - ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74473
    - vxlan: use pskb_network_may_pull() in route_shortcircuit()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74474
    - vxlan: use pskb_network_may_pull() for transmit path header pulls
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74475
    - vxlan: use neigh_ha_snapshot() in route_shortcircuit()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74476
    - veth: convert frag_list skbs before running XDP
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74477
    - uprobes: Fix NULL pointer dereference in hprobe_expire()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74478
    - um: vector: fix use-after-free in vector_mmsg_rx()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74479
    - net: pktgen: fix proc entry use-after-free
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74480
    - net: bridge: stop fast-leave after deleting a port group
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74481
    - mm/page_reporting: use system_freezable_wq to fix UAF during suspend
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74484
    - binfmt_misc: don't let an 'F' entry pin its own instance
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74485
    - binfmt_misc: reject a flag character as the field delimiter
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74486
    - binfmt_misc: use exe_file_deny_write_access() for the interpreter clone
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74487
    - binfmt_misc: restore write access when removing an entry
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74488
    - wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74490
    - tipc: avoid use-after-free in poll trace queue dumps
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74491
    - of/address: Fix NULL bus dereference in of_pci_range_parser_one()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74492
    - netfilter: ipset: do not update comments from kernel-side hash adds
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74493
    - net/smc: fix socket use-after-free during link group termination
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74494
    - ksmbd: reject repeated SMB2 NEGOTIATE requests
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74495
    - igbvf: Fix leak in TX DMA error cleanup
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74497
    - ALSA: usb-audio: Clamp frame size in implicit-feedback mode
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74498
    - ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74499
    - ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74500
    - ALSA: usb-audio: fix stack info leak in RME Digiface status
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74501
    - ALSA: usb-audio: fix use-after-free in ump_to_endpoint()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74502
    - ALSA: ump: fix double free of out_cvts on rawmidi error
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74503
    - ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74504
    - ALSA: seq: Fix division by zero in initialize_timer()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74505
    - ALSA: 6fire: Fix UAF at error handling during probe
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74506
    - afs: Fix UAF when sending a message
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74507
    - Bluetooth: HIDP: validate numbered report payloads
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74508
    - Bluetooth: HIDP: reject frames without a transaction header
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74509
    - Bluetooth: hci_sync: Fix advertising data UAFs
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74510
    - Bluetooth: mgmt: fix UAF in pair command cancellation
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74511
    - Bluetooth: mgmt: fix pending command UAF in EIR updates
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74512
    - audit: fix potential use-after-free in audit_del_rule()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74513
    - dibs: fix use-after-free of dmb_node in loopback
      attach/detach/unregister
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74514
    - KVM: s390: pci: Fix memory accounting for pinned/unpinned pages
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74515
    - KVM: s390: pci: Reject adapter interrupt forwarding if already enabled
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74516
    - KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is
      active
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74518
    - mm/hugetlb: fix list corruption in allocate_file_region_entries()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74519
    - pinctrl: devicetree: don't free uninitialized dev_name on error path
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74520
    - iommu/iommufd: Fix IOPF group ownership UAF
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74522
    - ksmbd: fix use-after-free in __close_file_table_ids()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74523
    - qede: sync udp_tunnel ports outside qede_lock in the recovery path
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74524
    - riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74525
    - net: sxgbe: free TX rings on RX allocation failure
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74531
    - Bluetooth: hci_conn: hold conn reference in abort_conn_sync()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74532
    - Bluetooth: btintel: Validate length before parsing diagnostics TLV
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74534
    - Bluetooth: ISO: fix refcounting of iso_conn
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74535
    - Bluetooth: ISO: avoid deadlocks in iso_sock_timeout
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74536
    - Bluetooth: ISO: fix leaking sk after socket release
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74537
    - Bluetooth: ISO: hold sk properly in iso_conn_ready
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74538
    - Bluetooth: ISO: lock sk in iso_connect_ind
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74539
    - Bluetooth: ISO: lock sk in iso_sock_getname
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74540
    - Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74541
    - Bluetooth: ISO: clear iso_data always when detaching conn from hcon
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74543
    - net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74545
    - rtase: fix double free of multi-frag skb on DMA map failure
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74546
    - hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74547
    - hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74548
    - forcedeth: fix UAF of txrx_stats in nv_remove
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74549
    - hwmon: (nct6775-core) Prevent access to unsupported weight registers
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74550
    - net: do not send ICMP/NDISC Redirects when peer allocation fails
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74551
    - hwmon: (nzxt-smart2) DMA-align output buffer
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74552
    - hwmon: (lm90) Only report alarms if driver is ready
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74553
    - hwmon: (nct6775-core) Fix number of temperature registers for NCT6116
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74555
    - scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74556
    - scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection
      buffer
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74557
    - scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74559
    - xsk: drain continuation descs after overflow in xsk_build_skb()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74560
    - xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74563
    - rds: tcp: hold the RCU lock across ipv6_chk_addr() in
      rds_tcp_laddr_check()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74579
    - netfilter: nft_payload: fix mask build for partial field offload
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74564
    - netfilter: xt_hashlimit: validate hashtable supports
      XT_HASHLIMIT_RATE_MATCH
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74565
    - netfilter: nf_tables: make nft_object rhltable per table
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74566
    - keys: make keyring key-chunk byte order agree with
      keyring_diff_objects()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74567
    - keys: fix out-of-bounds read in keyring_get_key_chunk()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74569
    - netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in
      sip_help_tcp()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74572
    - btrfs: zoned: fix deadlock between metadata writeback and transaction
      commit
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74573
    - iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74574
    - dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open()
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74575
    - thunderbolt: Prevent XDomain delayed work use-after-free on disconnect
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74576
    - mm/slab: prevent unbounded recursion in free path with new kmalloc type
  * Resolute update: upstream stable patchset 2026-08-31 (LP: #2165942) //
    CVE-2026-74577
    - net: mpls: initialize rtm_tos in mpls_getroute()

Date: 2026-09-28 09:45:11.622989+00:00
Changed-By: Kuba Pawlak <kuba.pawlak at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-ibm/7.0.0-1016.16
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list