[ubuntu/resolute-proposed] linux-riscv 7.0.0-38.38.1 (Accepted)

Andy Whitcroft apw at canonical.com
Thu Sep 24 23:52:17 UTC 2026


linux-riscv (7.0.0-38.38.1) resolute; urgency=medium

  * resolute/linux-riscv: 7.0.0-38.38.1 -proposed tracker (LP: #2165484)

  * resolute: llvm-21-dev build-depends breaks cross-builds (LP: #2165407)
    - [Packaging] Fix cross-builds

  *  Zfhmin/Zvfhmin not reported when Zfh/Zvfh are present  (LP: #2166547)
    - riscv: report Zfhmin/Zvfhmin when Zfh/Zvfh are present

  [ Ubuntu: 7.0.0-38.38 ]

  * resolute/linux: 7.0.0-38.38 -proposed tracker (LP: #2166443)
  * linux: dtbs_install fails on Resolute builders due to uutils install(1)
    EEXIST race under parallel make (LP: #2166356)
    - SAUCE: [Packaging] Serialise dtbs_install to work around uutils
      install(1) race
  * #510/p sleepable raw tracepoint reject from test_verifier in ubuntu_bpf
    failed with resolute (7.0.0-33.33) generic amd64 (LP: #2165872)
    - SAUCE: Revert "bpf: Verifier support for sleepable tracepoint programs"
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189)
    - platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug
    - selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs
    - drm/virtio: fix deadlock in display_info_cb by removing hotplug from
      dequeue worker
    - seqlock: Allow UBSAN_ALIGNMENT to fail optimizing
    - KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN
    - crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin
    - xprtrdma: Clear receive-side ownership pointers on release
    - Input: ims-pcu - fix logic error in packet reset
    - fuse: fix writeback array overflow when max_pages is one
    - arm64: tegra: Remove fallback compatible for GPCDMA
    - arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234
    - xfrm: propagate -EINPROGRESS from validate_xmit_xfrm()
    - mtd: mtdswap: remove debugfs stats file on teardown
    - mtd: nand: mtk-ecc: stop on ECC idle timeouts
    - btrfs: fallback to transaction csum tree on a commit root csum miss
    - RDMA/cma: Fix hardware address comparison length in netevent callback
    - RDMA/irdma: Remove redundant legacy_mode checks
    - RDMA/erdma: initialize ret for empty receive WR lists
    - RDMA/mana_ib: initialize err for empty send WR lists
    - RDMA/hns: Fix potential integer overflow in mhop hem cleanup
    - selftests/alsa: Fix memory leak in find_controls error path
    - RDMA/irdma: Prevent overflows in memory contiguity checks
    - wifi: cfg80211: derive S1G beacon TSF from S1G fields
    - wifi: nl80211: validate nested MBSSID IE blobs
    - wifi: nl80211: constrain MBSSID TX link ID range
    - wifi: cfg80211: validate PMSR measurement type data
    - wifi: cfg80211: reject unsupported PMSR FTM location requests
    - wifi: mac80211: avoid non-S1G AID fallback for S1G assoc
    - ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on
      start/stop
    - ASoC: amd: ps: disable MSI on resume in ACP PCI driver
    - ASoC: amd: ps: fix wrong ACP version string in pci_request_regions()
    - ASoC: amd: ps: replace bitwise OR with logical OR in IRQ return check
    - ASoC: cs42l43: Correct report for forced microphone jack
    - ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after
      lookup
    - firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context
    - cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq
    - udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf()
    - ata: sata_dwc_460ex: use platform_get_irq()
    - ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending
      interrupts
    - accel/ivpu: Fix wrong register read in LNL failure diagnostics
    - ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC
    - drm/i915/gt: use correct selftest config symbol
    - powerpc/85xx: Add fsl,ifc to common device ids
    - powerpc/time: Prepare to stop elapsing in dynticks-idle
    - powerpc/vtime: Initialize starttime at boot for native accounting
    - drm/panthor: Check debugfs GEM lock initialization
    - riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus()
    - can: j1939: fix lockless local-destination check
    - drm/xe/wopcm: fix WOPCM size for LNL+
    - drm/i915/wm: clear the plane ddb_y entries on plane disable
    - drm/i915/selftests: Fix GT PM sort comparators
    - USB: storage: add NO_ATA_1X quirk for Longmai USB Key
    - usb: chipidea: fix usage_count leak when autosuspend_delay is negative
    - USB: gadget: snps-udc: fix device name leak on probe failure
    - USB: gadget: fsl-udc: fix device name leak on probe failure
    - USB: gadget: fsl-udc: fix dev_printk() device
    - USB: serial: ftdi_sio: add support for E+H FXA291
    - USB: serial: keyspan_pda: fix data loss on receive throttling
    - USB: serial: option: add TDTECH MT5710-CN
    - SAUCE: Revert "usb: typec: ucsi: Detect and skip duplicate altmodes from
      buggy firmware"
    - usb: typec: ucsi: Detect and skip duplicate altmodes from buggy firmware
    - wifi: mwifiex: fix freeze for 60 seconds caused by request_firmware
    - RISC-V: KVM: Serialize virtual interrupt pending state updates
    - Revert "drm/amd/display: Add missing kdoc for ALLM parameters"
    - usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits
    - selftests/bpf: Adjust verifier_map_ptr for the map's excl field
    - selftests/bpf: Keep verifier_map_ptr exercising ops pointer access
    - wifi: ath11k: Flush the posted write after writing to
      PCIE_SOC_GLOBAL_RESET
    - wifi: ath12k: Flush the posted write after writing to
      PCIE_SOC_GLOBAL_RESET
    - btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8
    - btrfs: fix u32 to s64 type conversion in dirty_metadata_bytes accounting
    - ASoC: sun4i-codec: Set quirks.playback_only for H616 codec
    - ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI
    - ASoC: cs35l56: Don't use devres to unregister component
    - ASoC: cs35l56: Fix potential probe() deadlock
    - ASoC: cs35l56: Use complete_all() to signal init_completion
    - wifi: iwlwifi: mvm: validate SAR GEO response payload size
    - wifi: iwlwifi: fix pointer arithmetic in iwl_add_mcc_to_tas_block_list
    - wifi: iwlwifi: validate payload length in iwl_pnvm_complete_fn
    - wifi: iwlwifi: mvm: fix read in wake packet notification handler
    - usb: atm: ueagle-atm: reject descriptors that confuse probe and
      disconnect
    - drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook()
    - hwmon: (asus-ec-sensors) fix looping over banks while reading from EC
    - hwmon: (asus-ec-sensors) fix EC read intervals
    - hwmon: (asus-ec-sensors) add missed handle for ENOMEM
    - selftests/net: ovpn: fix getaddrinfo memory leak in ovpn_parse_remote()
    - ovpn: use monotonic clock for peer keepalive timeouts
    - regulator: mt6358: use regmap helper to read fixed LDO calibration
    - net: phy: marvell: fix return code
    - netlink: specs: rt-link: convert bridge port flag attributes to u8
    - gtp: parse extension headers before reading inner protocol
    - vhost-net: fix TX stall when vhost owns virtio-net header
    - wifi: mac80211: recalculate TIM when a station enters power save
    - pds_core: reject component parameter in legacy firmware update
    - arm64: Correct value returned by ESR_ELx_FSC_ADDRSZ_nL()
    - amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN
    - soreuseport: Clear sk_reuseport_cb before failure in sk_clone().
    - net: Call net_enable_timestamp() before failure in sk_clone().
    - pds_core: yield the CPU while waiting for the adminq to drain
    - pds_core: order completion reads after the ownership check
    - pds_core: check for workqueue allocation failure
    - tls: device: push pending open record on splice EOF
    - selftests: af_unix: add USER_NS config
    - selftests: openvswitch: add config file
    - selftests: ovpn: add IPV6 and VETH configs
    - selftests: ovpn: increase timeout
    - selftests: drv-net: increase timeout
    - ppp: don't store tx skb in the fastpath
    - ppp: annotate concurrent dev->stats accesses
    - ovl: fix trusted xattr escape prefix matching
    - drm/panel: s6e3ha8: fix unmet dependency on DRM_DISPLAY_HELPER
    - amt: make the head writable before rewriting the L2 header
    - net: bridge: vlan: fix vlan range dumps starting with pvid
    - net: dpaa: fix mode setting
    - drm/xe/i2c: Allow per domain unique id
    - iomap: correct the range of a partial dirty clear
    - drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem
    - net: stmmac: xgmac: fix l4 filter port overwrite on register update
    - net: stmmac: fix l3l4 filter rejecting unsupported offload requests
    - net: stmmac: reset residual action in L3L4 filters on delete
    - net: stmmac: enable the MAC on link up for all supported speeds
    - octeontx2-vf: set TC flower flag on MCAM entry allocation
    - ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup
    - ppp: annotate data races in ppp_generic
    - hinic: remove unused ethtool RSS user configuration buffers
    - raw: annotate lockless match fields in raw_v4_match()
    - net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule
    - net/mlx5e: Report zero bandwidth for non-ETS traffic classes
    - net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation
    - octeontx2-pf: tc: fix egress ratelimiting
    - net: ipv6: fix dif and sdif mismatch in raw6_icmp_error
    - ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV
    - ice: fix LAG recipe to profile association
    - ipv6: Change allocation flags to match rcu_read_lock section
      requirements
    - ptp: netc: explicitly clear TMR_OFF during initialization
    - mctp: check register_netdevice_notifier() error in mctp_device_init()
    - net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets()
    - drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay
    - drm: renesas: rzg2l_mipi_dsi: Move rzg2l_mipi_dsi_set_display_timing()
    - drm/tidss: Fix missing drm_bridge_add() call
    - drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video()
    - drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't
      at 0 (v2)
    - drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older
    - drm/sysfb: Do not page-align visible size of the framebuffer
    - drm/sysfb: Avoid truncating maximum stride
    - drm/amdgpu/gfx9: Fix Ring and IB test fail after mode2
    - drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT
    - drm/sysfb: Return errno code from drm_sysfb_get_visible_size()
    - drm/displayid: fix Tiled Display Topology ID size
    - drm/nouveau/acr: fix missing nvkm_done() in error path of
      nvkm_acr_oneinit()
    - drm/radeon: fix r100_copy_blit for large BOs
    - drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds
    - drm/amdkfd: Use kvcalloc to allocate arrays
    - drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips
    - drm/i915/hdcp: require monotonically increasing seq_num_v
    - drm/amd/amdgpu: disable ASPM on VI if pcie dpm is disabled
    - drm/amd/pm: fix smu14 power limit range calculation
    - drm/gfx10: Program DB_RING_CONTROL
    - drm/virtio: Don't detach GEM from a non-created context
    - drm/panthor: return error on truncated firmware
    - drm/amdgpu: Fix VFCT bus number matching with soft filter
    - drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X)
    - drm/amd/display: consolidate DCN vblank/flip handling onto
      vupdate_no_lock
    - drm/amd/display: Force PWM backlight on Lenovo Legion 5 15ARH05
    - drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge
    - drm/amd/display: Fix flip-done timeouts on mode1 reset
    - drm/amd/display: Fix missing DCE check in
      dm_gpureset_toggle_interrupts()
    - drm/v3d: Reach the GMP through the hub registers on V3D 7.x
    - media: aspeed: fix missing of_reserved_mem_device_release() on probe
      failure
    - media: cec: seco: unregister adapter on IR probe failure
    - media: cedrus: clean up media device on probe failure
    - media: cedrus: Fix missing cleanup in error path
    - media: imx219: Fix maximum frame length in lines
    - media: iris: Fix use IRQF_NO_AUTOEN when requesting the IRQ
    - media: marvell-cam: fix missing pci_disable_device() on remove
    - media: nuvoton: npcm-video: fix error handling in npcm_video_init()
    - media: nxp: imx8-isi: Clean up already-initialized pipes on probe
      failure
    - media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init
      error path
    - media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding
    - media: qcom: camss: Fix RDI streaming for CSID 680
    - media: qcom: camss: Fix RDI streaming for CSID GEN2
    - media: qcom: camss: Fix RDI streaming for CSID GEN3
    - media: rzg2l-cru: Skip ICnMC configuration when ICnSVC is used
    - media: synopsys: hdmirx: Fix HPD lane hold time
    - media: tegra-video: vi: fix invalid u32 return value in format lookup
    - media: v4l2-ctrls-request: add NULL check in
      v4l2_ctrl_request_complete()
    - media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely
    - media: vb2: use ssize_t for vb2_read/vb2_write
    - media: verisilicon: Export only needed pixels formats
    - media: vidtv: fix reference leak on failed device registration
    - media: vimc: fix reference leak on failed device registration
    - media: vpif_capture: fix OF node reference imbalance
    - ALSA: hda/realtek: Fix speakers on Lunnen Ground 14
    - ALSA: hda: codecs: hdmi: disable keep-alive before audio format change
    - wifi: brcmfmac: set F2 blocksize to 256 for BCM43752
    - wifi: ath11k: fix refcount leak in ath11k_ahb_fw_resources_init()
    - staging: rtl8723bs: fix inverted HT40 secondary channel offset
    - platform/loongarch: laptop: Explicitly reset bl_powered state when
      suspend
    - rust_binder: only print failure if error has source
    - rust: time: fix as_micros_ceil() to round correctly for negative Delta
    - rust: allow `clippy::unwrap_or_default` globally
    - objtool/rust: add one more `noreturn` Rust function for Rust 1.99.0
    - LoongArch: Fix address space mismatch in kexec command line lookup
    - LoongArch: Fix oops during single-step debugging
    - LoongArch: Move jump_label_init() before parse_early_param()
    - LoongArch: Retrieve CPU package ID from PPTT when available
    - x86/boot/compressed: Disable jump tables
    - uio_hv_generic: Bind to FCopy device by default
    - serial: sc16is7xx: implement gpio get_direction() callback
    - selftests: ntsync: correct CONFIG_NTSYNC name
    - tracing: Fix context switch counter truncation
    - tracing/eprobe: Fix exact system name matching in
      eprobe_dyn_event_match()
    - tracing/probes: Avoid temporary buffer truncation in
      trace_probe_match_command_args()
    - tracing/probes: Fix potential underflow in LEN_OR_ZERO macro
    - tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err()
    - mptcp: decrement subflows counter on failed passive join
    - mptcp: only set DATA_FIN when a mapping is present
    - mm/kmemleak: fix checksum computation for per-cpu objects
    - mm/huge_memory: set PG_has_hwpoisoned only after new folio head is
      established
    - ceph: fix refcount leak in ceph_readdir()
    - ceph: fix writeback_count leak in write_folio_nounlock()
    - ASoC: fsl: imx-card: Skip sysclk reset for active DAIs in shutdown
    - ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP
    - io_uring/rw: fix missing ERESTARTSYS conversion in read paths
    - iommu/vt-d: Disallow SVA if page walk is not coherent
    - net: stmmac: intel: skip SerDes reconfig when rate is unchanged
    - net: pcs: xpcs: fix SGMII state reading
    - proc: Fix broken error paths for namespace links
    - s390/ptff: Export ptff_function_mask[]
    - smb: client: handle STATUS_STOPPED_ON_SYMLINK responses without a
      symlink target
    - ice: use READ_ONCE() to access cached PHC time
    - ovpn: hold peer before scheduling keepalive work
    - vsock/virtio: collapse receive queue under memory pressure
    - watchdog: s32g_wdt: remove incorrect options in watchdog_info struct
    - drm/amd/pm: fix amdgpu_pm_info power display units
    - drm/amd/pm: make pp_features read-only when scpm is enabled
    - drm/amdgpu/jpeg: fix jpeg_v4_0_3_is_idle detection
    - drm/amdgpu/jpeg: fix jpeg_v5_0_1_is_idle detection
    - drm/amdgpu/soc24: reset dGPU if suspend got aborted
    - drm/amdgpu: fix resource leak on ACP reset timeout
    - drm/amd/pm: fix smu13 power limit range calculation
    - drm/amdgpu: fix check in amdgpu_hmm_invalidate_gfx
    - drm/xe/uapi: Reject coh_none PAT index for CPU_ADDR_MIRROR
    - net: qrtr: ns: Raise node count limit to 512
    - drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources
    - audit: widen ino fields to u64
    - audit: use 'unsigned int' instead of 'unsigned'
    - xfs: don't replace the wrong part of the cow fork
    - netfilter: nf_tables: remove register tracking infrastructure
    - drm: drop lib from header search path.
    - SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists
    - SUNRPC: Return an error from xdr_buf_to_bvec() on overflow
    - SAUCE: Revert "mm/sparse-vmemmap: fix vmemmap accounting underflow"
    - mm/sparse-vmemmap: fix vmemmap accounting underflow
    - mmc: vub300: rename probe error labels
    - net: mana: Optimize irq affinity for low vcpu configs
    - bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c
    - bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline()
    - pmdomain: imx93-blk-ctrl: convert to devm_* only
    - rust: allow `suspicious_runtime_symbol_definitions` lint for Rust >=
      1.98
    - rust: device: avoid trailing ; in printing macros
    - sched_ext: Skip ops.set_weight() for disabled tasks
    - sched_ext: Annotate ksyncs with __rcu in alloc/free_kick_syncs()
    - reset: spacemit: k3: fix USB2 ahb reset
    - wifi: cfg80211: reject empty PMSR peer lists
    - ASoC: amd: acp: Fix linker error with SDCA quirks
    - [Config] Adjust config SND_SOC_ACPI_AMD_SDCA_QUIRKS
    - sched_ext: Enable tick for finite slices on nohz_full
    - Bluetooth: mgmt: Translate HCI reason in Device Disconnected event
    - riscv: Gate FUNCTION_ALIGNMENT_4B on DYNAMIC_FTRACE
    - spi: cadence-quadspi: Fix indirect write timeout when DMA read mode is
      enabled
    - drm/xe: Assign queue name in time for drm_sched_init
    - drm/xe: add WQ_PERCPU to alloc_workqueue users
    - selftests: netconsole: only restore MAC when it changed on resume
    - wifi: ath10k: fix skb leak on incomplete msdu during rx pop
    - wifi: ath12k: Fix low MLO RX throughput on WCN7850
    - iommu/amd: Fix nested domain leak
    - arm_mpam: Fix software reset values of MPAMCFG_PRI
    - arm_mpam: Fix MPAMCFG_MBW_PBM register setting
    - hwmon: Drop unused i2c driver_data
    - hwmon: Use named initializers for arrays of i2c_device_data
    - hwmon: (pmbus/max34440): add support adpm12250
    - hwmon: (pmbus/max34440) block unsupported VIN and IIN limit registers
    - drm/i915/backlight: Remove DP_EDP_BACKLIGHT_AUX_ENABLE_CAP check for
      DPCD backlight
    - selftests/net: Fix tun IPv6 test addresses to avoid 6to4 range
    - geneve: fix hint header definition wrt endianness
    - geneve: ensure the skb is writable before fixing its headers
    - accel: ethosu: Handle U85 internal chaining buffer
    - selftests: drv-net: convert so_txtime to drv-net
    - cifs: prevent readdir from changing file size due to stale directory
      metadata
    - wifi: mt76: fix airoha_npu dependency tracking
    - [Config] Fix config dependencies for MT76_NPU
    - drm/panel: ilitek-ili9882t: fix unmet dependency for
      DRM_PANEL_ILITEK_ILI9882T
    - iomap: fix incorrect did_zero setting in iomap_zero_iter()
    - mpls: Set rt->rt_nhn just before returning from mpls_nh_build_multi().
    - LoongArch: BPF: Zero-extend signed ALU32 div/mod results
    - bnge/bng_re: fix ring ID widths
    - pidfs: make pidfs_ino_lock static
    - LoongArch: BPF: Fix memory leak in bpf_jit_free()
    - drm/exynos: fbdev: Remove offset into screen_buffer
    - drm/tegra: fbdev: Remove offset into framebuffer memory
    - drm/i915/cdclk: Fix up CDCLK_FREQ_DECIMAL without a full PLL re-enable
    - drm/amd/pm: re-enable MC access after PrepareMp1ForUnload on SMU V15
      APUs
    - bitmap: add test_zero_nbits()
    - drm/xe: Add compact-PT and addr mask handling for page reclaim
    - drm/amd/display: Restore periodic detection for DCN35
    - drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions
    - drm/amdkfd: Use exclusive bounds for SVM split alignment checks
    - drm/i915/mtl+: Enable PPS before PLL
    - drm/xe/oa: Fix offset alignment for MERT WHITELIST_OA_MERT_MMIO_TRG
    - drm/xe/nvm: fix writable override for CRI
    - drm/amdgpu: Check for multiplication overflow in checkpoint stack size
    - drm/amdkfd: Guard m->cp_hqd_eop_control setting by
      q->eop_ring_buffer_size
    - drm/amdkfd: free MQD managers on DQM init failures
    - drm/amd/display: set MSA MISC1 bit 6 when using VSC SDP for DCE 11.x
    - drm/amdgpu: add the doorbell index input for suspending userq
    - drm/amdgpu: remove deadlocks from amdgpu_userq_pre_reset
    - drm/amd: Create a device link between APU display and XHCI devices
    - drm/pagemap: Clear driver-provided PFNs from migration PFN array
    - mm: add gpu active/reclaim per-node stat counters (v2)
    - drm/ttm: use gpu mm stats to track gpu memory allocations. (v4)
    - drm/ttm: Fix GPU MM stats during pool shrinking
    - drm/ttm/pool: back up at native page order
    - drm/gpusvm: Zero HMM PFNs before scanning ranges
    - media: mali-c55: Add missing of_reserved_mem_device_release()
    - media: mali-c55: Disable pm_runtime on probe error
    - media: mali-c55: Power-off the peripheral in remove()
    - media: qcom: camss: Fix RDI streaming for CSID 340
    - media: rzv2h-ivc: Wait for frame end in stop_streaming
    - media: ti: vpe: Fix fwnode_handle leak in vip_probe_complete()
    - media: ti: vpe: Fix the error code of devm_request_irq()
    - media: uapi: rkisp: Correct name version enum
    - wifi: mt76: restrict NPU/PPE active checks to MMIO devices
    - LoongArch: Fix build errors due to wrong instructions for 32BIT
    - LoongArch: Increase TASK_STRUCT_OFFSET up to 2040 for 32BIT
    - firmware: stratix10-svc: fix teardown order in remove to prevent race
    - firmware: stratix10-svc: handle NO_RESPONSE in async poll
    - tracing: perf: Fix stale head for perf syscall tracing
    - arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates
    - Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer
      updates"
    - selftests: mptcp: userspace_pm: fix undefined variable port
    - m68k: avoid -Wunused-but-set-parameter in clear_user_page()
    - mm/memory-failure: trace: change memory_failure_event to ras subsystem
    - mm/slub: fix lost local objects when bulk remote free batch fills
    - mm/slab: fix a memory leak due to bootstrapping sheaves twice
    - drm/amdgpu: rework userq fence driver alloc/destroy
    - drm/amdgpu: rework userq fence signal processing
    - drm/amdgpu/gfx11: fix EOP interrupt routing for KQ and userq
    - drm/amdgpu/gfx12: fix EOP interrupt routing for KQ and userq
    - drm/amdgpu/mes11: set doorbell offset for suspending userq
    - selftests: drv-net: add missing kconfig for psp.py
    - mm/sparse-vmemmap: pass @pgmap argument to memory deactivation paths
    - mm/sparse-vmemmap: fix DAX vmemmap accounting with optimization
    - selftests: drv-net: cope with slow env in so_txtime.py test
    - selftests: drv-net: so_txtime: relax variance bounds
    - cifs: fix time_last_write stamp placement in setattr/truncate paths
    - cifs: consolidate time_last_write stamp into _cifsFileInfo_put()
    - Upstream stable to v6.18.41, v6.18.42, v6.18.43, v7.1.6, v7.1.7
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68480
    - x86/bugs: Make Safe-RET robust against interrupt injection
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68105
    - drm/amdgpu: Fix kernel panic during driver load failure
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68109
    - drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68114
    - drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68431
    - ksmbd: validate minimum PDU size for transform requests
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68138
    - net/sched: serialize qdisc_rtab_list against concurrent get/put
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68082
    - libceph: fix two unsafe bare decodes in decode_lockers()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68159
    - libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68163
    - mm/page_vma_mapped: fix device-private PMD handling
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68166
    - userfaultfd: prevent registration of special VMAs
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68170
    - mptcp: fix stale skb->sk reference on subflow close
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68177
    - tracing: Delay module ref count for "enable_event" trigger
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68191
    - wifi: ath12k: fix NULL pointer dereference in rhash table destroy
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64586
    - wifi: brcmfmac: drain bus_reset work on device removal
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68208
    - media: ti: vpe: Fix the error code of devm_kzalloc() in
      vip_probe_slice()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68224
    - media: mali-c55: Fix possible ERR_PTR in enable_streams
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68237
    - drm/amdgpu/userq: fix indefinite fence wait during GPU reset
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68240
    - drm/gpusvm: publish dpagemap early to avoid device mapping leak on error
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68242
    - drm/i915/gt: Fix NULL deref on sched_engine alloc failure
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68254
    - drm/i915/vrr: require valid min/max vfreq for VRR
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68436
    - drm/amd/display: use kvzalloc to allocate struct dc
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68447
    - drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68264
    - drm/xe/pt: Reset current_op in xe_pt_update_ops_init()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68265
    - drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68267
    - drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68273
    - drm/amdgpu: Fix context pstate override handling
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68274
    - drm/xe/guc: Fix buffer overflow in steered register list allocation
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68283
    - tracing: Fix use-after-free freeing trigger private data
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68286
    - drop_monitor: perform u64_stats updates under IRQ-disabled section
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68287
    - drop_monitor: fix size calculations for 64-bit attributes
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68288
    - net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68289
    - tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68291
    - idpf: fix max_vport related crash on allocation error during init
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68303
    - drm/vc4: hvs/v3d: Fix null dereference in unbind
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68312
    - cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain
      paths
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68316
    - accel: ethosu: Fix element size accounting for cmd stream validation
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68322
    - rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68440
    - net: txgbe: fix heap overflow when reading module EEPROM
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68323
    - tipc: serialize udp bearer replicast list updates
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68441
    - net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68337
    - bpf: Reject redirect helpers without a bpf_net_context
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68345
    - arm_mpam: guard MBWU state before adding it to garbage
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68347
    - iommu/amd: Fix IRQ unsafe locking in gdom allocation
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68375
    - bnxt_en: Handle partially initialized auxiliary devices
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68382
    - drm/xe/guc: Hold device ref until queue teardown completes
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68383
    - drm/xe/guc: Keep scheduler timeline name alive
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68390
    - Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68399
    - bpf: Fix UAF in sock clone early bailouts
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68404
    - wifi: cfg80211: use wiphy work for socket owner autodisconnect
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64581
    - xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68093
    - KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision
      after hotplug
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68367
    - usb: gadget: f_tcm: synchronize delayed set_alt with teardown
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68164
    - mm/damon/core: disallow overlapping input ranges for damon_set_regions()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68165
    - mm/damon/core: validate ranges in damon_set_regions()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68095
    - fuse-uring: fix race between registration and connection abortion
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68096
    - audit: fix recursive locking deadlock in audit_dupe_exe()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68147
    - fscrypt: Avoid dynamic allocation in fscrypt_get_devices()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68097
    - ksmbd: validate ACE size against SID sub-authorities
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68098
    - ksmbd: bound DACL dedup walk to copied ACEs
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68099
    - ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68100
    - ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68173
    - ublk: wait on ublk_dev_ready() instead of ub->completion
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68104
    - drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68106
    - drm/amdgpu: fix division by zero with invalid uvd dimensions
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68429
    - drm/dp_mst: Handle torn-down topology gracefully in
      drm_dp_mst_topology_queue_probe()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68107
    - drm/amdgpu/vcn4: avoid rereading IB param length
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68108
    - drm/amdgpu/vce: fix integer overflow in image size
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68110
    - drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68111
    - drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68112
    - drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68430
    - drm/amdgpu/gfx8: drop unecessary BUG_ON()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68113
    - drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68246
    - drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68115
    - drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68116
    - vxlan: mdb: Fix source list corruption on a failed replace
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68117
    - tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68118
    - tcp: challenge ACK for non-exact RST in SYN-RECEIVED
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68119
    - tcp: initialize standalone TCP-AO response padding
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68120
    - rtase: Workaround for TX hang caused by hardware packet parsing
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68121
    - pppoe: reload header pointer after dev_hard_header()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68122
    - ovpn: fix peer refcount leak in TCP error paths
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68123
    - openvswitch: fix GSO userspace truncation underflow
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68124
    - mctp: serial: handle zero-length frames to prevent rx buffer overflow
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68125
    - mac802154: llsec: reject frames shorter than the authentication tag
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68126
    - mac802154: hold an interface reference across the scan worker
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68127
    - ila: reload IPv6 header after pskb_may_pull in checksum adjust
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68128
    - ice: reject out-of-range ptype in ice_parser_profile_init
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68129
    - gve: fix Rx queue stall on alloc failure
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68130
    - ksmbd: defer destroy_previous_session() until after NTLM authentication
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68131
    - rbd: Reset positive result codes to zero in object map update path
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68132
    - super: fix emergency thaw deadlock on frozen block devices
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68133
    - ice: fix PTP Call Trace during PTP release
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68134
    - ptp: ptp_s390: Add missing facility check
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68135
    - net: hip04: fix RX buffer leak on build_skb failure
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68136
    - net: gro: fix double aggregation of flush-marked skbs
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68137
    - net/x25: fix use-after-free in x25_kill_by_neigh()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68139
    - net/mlx5e: Use sender devcom for MPV master-up
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68140
    - net/iucv: fix use-after-free of a severed iucv_path
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68141
    - net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68142
    - geneve: require CAP_NET_ADMIN in the device netns for changelink
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68143
    - net: slip: serialize receive against buffer reallocation
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68432
    - vxlan: require CAP_NET_ADMIN in the device netns for changelink
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68144
    - phonet: pep: fix use-after-free in pep_get_sb()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68145
    - iomap: fix out-of-bounds bitmap_set() with zero-length range
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68146
    - ftrace: Add global mutex to serialize trace_parser access
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68148
    - fscrypt: Add missing superblock check in find_or_insert_direct_key()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68149
    - fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68150
    - fs/super: fix emergency thaw double-unlock of s_umount
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68151
    - binfmt_elf_fdpic: only honour the first PT_INTERP
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68152
    - amt: fix use-after-free in AMT delayed works
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68153
    - libceph: remove debugfs files before client teardown
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68154
    - libceph: reject zero bucket types in crush_decode
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68155
    - libceph: Reject monmaps advertising zero monitors
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68156
    - libceph: refresh auth->authorizer_buf{,_len} after authorizer update
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68157
    - libceph: guard missing CRUSH type name lookup
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68158
    - libceph: Fix multiplication overflow in decode_new_up_state_weight()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68433
    - libceph: bound get_version reply decode to front len
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68160
    - ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68161
    - sctp: close UDP tunnel sockets during netns teardown
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68162
    - sctp: avoid auth_enable sysctl UAF during netns teardown
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64564
    - sctp: don't free the ASCONF's own transport in DEL-IP processing
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68168
    - afs: Fix afs_edit_dir_remove() to get, not find, block 0
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68169
    - mptcp: pm: userspace: fix use-after-free in get_local_id
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68172
    - arm64: make huge_ptep_get handled unaligned addresses
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68174
    - tracing: Fix union collision of module and refcnt for dynamic events
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68175
    - tracing: Fix resource leak on mmiotrace trace_pipe close
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68176
    - tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68178
    - misc: nsm: pin the module while the device is open
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68179
    - misc: nsm: only unlock nsm_dev on post-lock error paths
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68180
    - intel_th: fix MSC output device reference leak
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68181
    - mei: bus: access mei_device under device_lock on cleanup
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68434
    - serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR
      platforms
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68182
    - comedi: comedi_parport: deal with premature interrupt
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68183
    - firmware: stratix10-svc: fix memory leaks and list corruption bugs
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64563
    - rhashtable: clear stale iter->p on table restart
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68184
    - cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68186
    - binfmt_misc: set have_execfd only once the interpreter is opened
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68187
    - exec: fix unsigned loop counter wrap in transfer_args_to_stack()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68188
    - Bluetooth: RFCOMM: Fix session UAF in set_termios
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68189
    - Bluetooth: hci_sync: Protect UUID list traversal
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68190
    - staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68192
    - wifi: brcmfmac: make release_scratchbuffers idempotent
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68193
    - wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68194
    - wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68195
    - wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68196
    - wifi: wilc1000: validate assoc response length before subtracting header
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68197
    - wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-
      oper
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68198
    - wifi: ath6kl: fix use-after-free in aggr_reset_state()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68199
    - wifi: ath6kl: fix OOB access from firmware ADDBA window size
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68200
    - ALSA: timer: don't re-enter an instance callback that is still running
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68201
    - ALSA: timer: drain a slave's callback before its master detaches it
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68202
    - ALSA: seq: close a re-opened queue timer in the destructor
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68203
    - media: vivid: fix cleanup bugs in vivid_init()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68204
    - media: vivid: check for vb2_is_busy() when toggling caps
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68205
    - media: v4l2-fwnode: Fix subdev owner overwritten in
      v4l2_async_register_subdev_sensor()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68206
    - media: v4l2-ctrls: validate HEVC active reference counts
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68207
    - media: ti: vpe: unwind v4l2 device registration on probe error
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68209
    - media: sun4i-csi: Return queued buffers on start_streaming() failure
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68210
    - media: stm32: dcmi: unregister notifier on probe failure
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68211
    - media: stm32-dcmipp: Return queued buffers on start_streaming() failure
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68212
    - media: saa7134: Fix a possible memory leak in saa7134_video_init1
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68213
    - media: rtl2832_sdr: Return queued buffers on start_streaming() failure
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68214
    - media: rtl2832: fix use-after-free in rtl2832_remove()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68215
    - media: radio-si476x: Unregister v4l2_device on probe failure
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68216
    - media: pwc: Return queued buffers on start_streaming() failure
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68217
    - media: pwc: Drain fill_buf on start_streaming() failure
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68218
    - media: pci: dm1105: Free allocated workqueue
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68219
    - media: nxp: imx8-isi: Fix potential out-of-bounds issues
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68220
    - media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and
      pipe
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68221
    - media: nuvoton: npcm-video: fix memory leaks in probe and remove
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68222
    - media: msi2500: Return queued buffers on start_streaming() failure
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68223
    - media: meson: vdec: Fix memory leak in error path of vdec_open
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68225
    - media: i2c: alvium: fix critical pointer access in alvium_ctrl_init
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68226
    - media: cx23885: add ioremap return check and cleanup
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68227
    - media: cx231xx: fix devres lifetime
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68228
    - media: chips-media: wave5: Move src_buf Removal to finish_encode
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68229
    - media: cedrus: skip invalid H.264 reference list entries
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68230
    - media: amlogic-c3: Add validations for ae and awb config
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68231
    - media: airspy: Return queued buffers on start_streaming() failure
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68232
    - drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68445
    - drm/vc4: Prevent shader BO mappings from becoming writable
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68446
    - drm/vmwgfx: Validate vmw_surface_metadata::array_size
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68233
    - drm/vc4: Shut down BO cache timer before teardown
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68234
    - drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68235
    - drm/amd/display: dce100: skip non-DP stream encoders for DP MST
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68236
    - drm/amd/display: set new_stream to NULL after release
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68238
    - drm/amdgpu: Release VFCT ACPI table reference
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68239
    - drm/ttm: Account for NULL and handle pages in ttm_pool_backup
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68241
    - drm/i915/mst: limit DP MST ESI service loop
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68243
    - drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68244
    - drm/i915/gem: Do not leak siblings[] on proto context error
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68245
    - drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68247
    - drm/i915/bios: range check LFP Data Block panel_type2
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68248
    - drm/i915: Return NULL on error in active_instance
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68249
    - drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68250
    - drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68251
    - drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68252
    - drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68253
    - drm/i915/hdcp: check streams[] bounds before overflow
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68255
    - drm/virtio: bound EDID block reads to the response buffer
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68256
    - drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path
      leaks prev_sink reference
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68257
    - drm/amdkfd: fix 32-bit overflow in CWSR total size calculation
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68258
    - drm/amdkfd: Check bounds on CRIU restore queue type and mqd size
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68259
    - drm/amdkfd: Check bounds in allocate_event_notification_slot
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68260
    - drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68261
    - drm/imagination: fix error checking of pvr_vm_context_lookup()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68262
    - drm/imagination: Fix user array stride in pvr_set_uobj_array()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68263
    - drm/imagination: Fix double call to drm_sched_entity_fini()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68266
    - drm/xe: Hold a dma-buf reference for imported BOs
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68268
    - drm/xe: Return error on non-migratable faults requiring devmem
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68269
    - drm/i915/gem: Add missing nospec on parallel submit slot
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68270
    - drm/sysfb: Avoid possible truncation with calculating visible size
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68271
    - drm/nouveau: fix reversed error cleanup order in ucopy functions
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68272
    - drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68275
    - drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68276
    - drm/amdgpu/gfx: fix cleaner shader IB buffer overflow
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68277
    - drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68437
    - drm/imagination: Fit paired fragment job in the correct CCCB
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68278
    - drm/dp/mst: fix buffer overflows in sideband chunk accumulation
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68279
    - drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68280
    - drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68281
    - drm/imagination: Count paired job fence as dependency in prepare_job()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68282
    - drm/rockchip: analogix_dp: Add missing error check for
      platform_get_resource()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68284
    - bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68290
    - rds: tcp: unregister sysctl before tearing down listen socket
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68292
    - ice: prevent tstamp ring allocation for non-PF VSI types
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68293
    - net/mlx5: Fix MCIA register buffer overflow on 32 dword reads
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68294
    - net: qrtr: restrict socket creation to the initial network namespace
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68296
    - net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64575
    - bpf: tcp: fix double sock release on batch realloc
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68297
    - tipc: fix u16 MTU truncation in media and bearer MTU validation
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68298
    - drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68299
    - vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68300
    - sctp: auth: verify auth requirement when auth_chunk is NULL
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68301
    - net: hsr: fix memory leak on slave unregistration by removing synced
      VLANs
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68302
    - amt: re-read skb header pointers after every pull
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68448
    - ovl: check access to copy_file_range source with src mounter creds
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68304
    - wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68306
    - wifi: mt76: mt7996: fix possible NULL-pointer deref in
      mt7996_mcu_sta_bfer_eht()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68307
    - wifi: mt76: mt7925: fix crash in reset link replay
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68308
    - wifi: mt76: mt7996: check pointer returned by
      mt76_connac_get_he_phy_cap()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68439
    - wifi: mt76: mt7925: fix possible NULL-pointer deref in
      mt7925_mcu_bss_he_tlv()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68309
    - wifi: mt76: connac: fix possible NULL-pointer deref in
      mt76_connac_mcu_uni_bss_he_tlv()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68310
    - wifi: mt76: mt7915: guard HE capability lookups
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68311
    - wifi: mt76: mt7925: guard link STA in decap offload
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68313
    - tipc: fix infinite loop in __tipc_nl_compat_dumpit
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64576
    - nexthop: initialize extack in nh_res_bucket_migrate()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64577
    - gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68314
    - net: mctp i3c: clean up notifier and buses if driver register fails
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68315
    - sctp: validate stream count in sctp_process_strreset_inreq()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68317
    - pds_core: fix auxiliary device add/del races
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68318
    - pds_core: fix use-after-free on workqueue during remove
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68319
    - pds_core: fix deadlock between reset thread and remove
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68320
    - sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68321
    - net: txgbe: fix FDIR filter leak on remove
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68324
    - iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68325
    - iommu/amd: Bound the early ACPI HID map
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68326
    - wifi: mwifiex: bound uAP association event IEs to the event buffer
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68327
    - wan: wanxl: Only reset hardware after BAR mapping
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68328
    - nfp: Check resource mutex allocation
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64574
    - wifi: mac80211: tear down new links on vif update error path
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68329
    - iommu/amd: Wait for completion instead of returning early in
      iommu_completion_wait()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68330
    - net: airoha: Fix DMA direction for NPU mailbox buffer
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68331
    - dpaa2-eth: put MAC endpoint device on disconnect
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68332
    - net: airoha: Fix potential use-after-free in airoha_ppe_deinit()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68333
    - dpaa2-switch: put MAC endpoint device on disconnect
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68334
    - rxrpc: fix io_thread race in rxrpc_wake_up_io_thread()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68335
    - rds: drop incoming messages that cross network namespace boundaries
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68336
    - bonding: fix devconf_all NULL dereference when IPv6 is disabled
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68338
    - net/packet: avoid fanout hook re-registration after unregister
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68339
    - Bluetooth: btusb: validate Realtek vendor event length
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68340
    - hwmon: occ: validate poll response sensor blocks
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68341
    - ovpn: fix use after free in unlock_ovpn()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68342
    - ovpn: avoid putting unrelated P2P peer on socket release
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68343
    - smb: client: validate DFS referral PathConsumed
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68346
    - ALSA: hda: cs35l41: validate and free ACPI mute object
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68348
    - ASoC: tas2781: bound firmware description string parsing
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68450
    - btrfs: free mapping node on duplicate reloc root insert
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68442
    - btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68349
    - wifi: carl9170: fix buffer overflow in rx_stream failover path
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68350
    - wifi: carl9170: fix OOB read from off-by-two in TX status handler
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68351
    - wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68352
    - wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68353
    - wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68354
    - firewire: net: Fix fragmented datagram reassembly
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68355
    - wifi: ath11k: fix potential buffer underflow in
      ath11k_hal_rx_msdu_list_get()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68356
    - watchdog: airoha: Prevent division by zero when clock frequency is zero
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68357
    - watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68358
    - hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68359
    - hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68443
    - hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68360
    - hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68361
    - hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68362
    - wifi: ath11k: fix NULL pointer dereference in
      ath11k_hal_srng_access_begin
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68363
    - wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware
      request
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68365
    - USB: serial: io_edgeport: cap received transmit credits
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68366
    - usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64583
    - usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before
      teardown
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68368
    - usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68369
    - usb: gadget: printer: fix infinite loop in printer_read()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64584
    - usb: gadget: f_midi: cancel pending IN work before freeing the midi
      object
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68370
    - usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68371
    - usb: musb: omap2430: Do not put borrowed of_node in probe
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68373
    - wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68374
    - usb: core: sysfs: add lock to bos_descriptors_read()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64569
    - mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68376
    - sctp: fix auth_hmacs array size in struct sctp_cookie
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68377
    - net/sched: act_tunnel_key: Defer dst_release to RCU callback
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68378
    - dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68379
    - tcp: fix TIME_WAIT socket reference leak on PSP policy failure
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68380
    - accel/amdxdna: Fix use-after-free of mm_struct in job scheduler
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64578
    - ksmbd: validate compound request size before reading StructureSize2
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68381
    - ksmbd: pin conn during async oplock break notification
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68384
    - drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68385
    - s390/checksum: Fix csum_partial() without vector facility
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68386
    - bpf, sockmap: Reject unhashed UDP sockets on sockmap update
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68387
    - can: raw: add locking for raw flags bitfield
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68388
    - smb/client: handle overlapping allocated ranges in fallocate
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68389
    - Bluetooth: hci_qca: Clear memdump state on invalid dump size
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68391
    - Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68392
    - Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68393
    - Bluetooth: hci_sync: extend conn_hash lookup critical sections
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68394
    - Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64573
    - Bluetooth: qca: fix NVM tag length underflow in TLV parser
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68449
    - ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-
      scanning
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68395
    - ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is
      registered
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68396
    - scsi: core: wake eh reliably when using scsi_schedule_eh
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68397
    - net/iucv: take a reference on the socket found in afiucv_hs_rcv()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64572
    - ipv4: fib: free fib_alias with kfree_rcu() on insert error path
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68398
    - ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68400
    - firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset
      calculation
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68401
    - firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68402
    - wifi: cfg80211: bound element ID read when checking non-inheritance
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68403
    - wifi: brcmfmac: initialize SDIO data work before cleanup
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68405
    - wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68406
    - wifi: cfg80211: validate PMSR FTM preamble range
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68407
    - wifi: nl80211: free RNR data on MBSSID mismatch
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68408
    - wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64571
    - wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68409
    - wifi: mac80211: defer link RX stats percpu free to RCU
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68410
    - wifi: libertas: fix memory leak in helper_firmware_cb()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64570
    - wifi: mac80211: fix fils_discovery double free on alloc failure
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64568
    - wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68411
    - wifi: mac80211_hwsim: clamp virtio RX length before skb_put
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68412
    - wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68413
    - wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68414
    - wifi: cfg80211: cancel sched scan results work on unregister
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64579
    - xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64580
    - xfrm6: clear dst.dev on error to avoid double netdev_put in
      xfrm6_fill_dst()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64566
    - xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68415
    - xfrm: clear mode callbacks after failed mode setup
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68416
    - mtd: fix double free and WARN_ON in add_mtd_device() error paths
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68417
    - RDMA/siw: publish QP after initialization
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68418
    - RDMA/irdma: Prevent user-triggered null deref on QP create
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68419
    - RDMA/irdma: Prevent rereg_mr for non-mem regions
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68420
    - xfrm: reject optional IPTFS templates in outbound policies
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68421
    - sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68444
    - firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68422
    - btrfs: fix root leak if its reloc root is unexpected in
      merge_reloc_roots()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64567
    - btrfs: reject free space cache with more entries than pages
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68425
    - IB/mad: Drop unmatched RMPP responses before reassembly
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68426
    - xfrm: fix stale skb->prev after async crypto steals a GSO segment
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64565
    - Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68427
    - gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-68428
    - KVM: x86/mmu: Fix use-after-free on vendor module reload
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64562
    - KVM: nVMX: Hide shadow VMCS right after VMCLEAR
  * Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
    CVE-2026-64561
    - KVM: x86: Check for invalid/obsolete root *after* making MMU pages
      available
  * resolute: llvm-21-dev build-depends breaks cross-builds (LP: #2165407)
    - [Packaging] Fix cross-builds
  * Resolute Stable Update v6.18.40, v7.1.5 bugs (LP: #2165040)
    - accel/amdxdna: Allow forcing IOVA-based DMA via module parameter
    - SAUCE: bpf: Add missing NULL argument to zap_page_range_single
    - accel/amdxdna: Return ERR_PTR on dma_alloc_noncoherent failure
    - accel/amdxdna: Fix memory leak in amdxdna_iommu_alloc()
  * [SRU][HPE] Take Intel platform into account for old microcode checks
    (LP: #2161748)
    - x86/microcode: Refactor platform ID enumeration into a helper
    - x86/cpu: Add platform ID to CPU info structure
    - x86/cpu: Add platform ID to CPU matching structure
    - x86/microcode: Add platform mask to Intel microcode "old" list
    - x86/microcode: Do not access MSR_IA32_PLATFORM_ID when running as a
      guest
  * ice: E810 interface fails to initialize (ice_init_hw failed: -5) during
    NVM read (LP: #2163508)
    - ice: acquire NVM lock around each flash read
  * WWAN modem unresponsive after freeze on Dell systems with DW5826e
    (LP: #2163214)
    - platform/x86: dell-dw5826e: Add reset driver for DW5826e
    - platform/x86: dell-dw5826e: fix ACPI _DSM function index and bitmask
      usage
    - [Config] Add CONFIG_DELL_DW5826E_RESET=m
  * amdgpu panel self-refresh on dual-gpu laptops causes complete built-in
    panel freeze and severe system instability (LP: #2162904)
    - SAUCE: drm/amdgpu: Do not enter PSR if multiple displays are active
  * linux 7.0: dw9719 VCM never binds, disabling all IPU3 cameras (regression,
    fixed upstream) (LP: #2162045)
    - media: dw9719: Add back the I²C device id table
  * Fix TAS2783 SoundWire amp resume timeout  >5s (LP: #2164967)
    - soundwire: Add a helper function to wait for device initialisation
    - ASoC: tas2783: Use new SoundWire enumeration helper
    - soundwire: Move wait for initialisation helper to header
    - ASoC: codecs: tas2783-sdw: Propagate regcache_sync() errors
    - ASoC: tas2783-sdw: drop stale regcache on uninitialized re-attach
  * Linux, Ubuntu, 24.04, System hangs for about 10 seconds when unplug
    external monitor cable on non TBT dock  (LP: #2160082)
    - SAUCE: drm/i915/tc: Revert forced DP-alt connected workaround
  * Speakers not detected on HP systems with TI TAS2783 SoundWire amps
    (LP: #2164504)
    - ASoC: sdw_utils: Add missed component_name strings for TI amps
  * [TWL][Desktop] intel_dmc_wait_fw_load()  merge to Ubuntu next release
    (LP: #2156316)
    - SAUCE: drm/i915/dmc: fix assert_dmc_loaded WARN during async firmware
      load
  * Reboot machine with ext4 configured to data=journal could dump spurious
    call trace (LP: #2164716)
    - ext4: clear stale xarray tags on folios skipped during writeback
  * [UBUNTU 22.04] s390/topology: Use zero-based numbering (LP: #2164516)
    - s390/topology: Use zero-based numbering for containing entities
  * Ethernet adapter unusable after suspend/resume on Advantech systems with
    Intel I226-V (LP: #2163375)
    - igc: fix netdev not re-attached after resume if interface is down
  * ice: fix stale -EBUSY on resume of Intel E810 (LP: #2162803)
    - ice: wait for reset completion in ice_resume()
  * idxd: crash-kernel NULL-pointer Oops in `destroy_workqueue()` breaks kdump
    on Intel DSA/IAA systems (LP: #2163062)
    - SAUCE: dmaengine: idxd: Do not call destroy_workqueue with null idxd->wq
    - SAUCE: dmaengine: idxd: fix duplicate memory frees on initialization
      error path.
  * [HP][ZBook Power 16 G11] Laptop freezed after upgrading the BIOS
    (LP: #2132119)
    - PCI/ASPM: Avoid L0s for Realtek RTS525A
  * Fix noise of audio output on more Dell QCx1255 models after reboot
    (LP: #2163293)
    - ALSA: hda/realtek - Add quirk for Dell Pro QC1255
  * Fix no audio input/output device on Dell WCL Slate platform with
    CirrusLogic audio solution (LP: #2160200)
    - ASoC: SDCA: fix the register to ctl value conversion for Q7.8 format
    - ASoC: SOF: ipc4-control: Use local copy of IPC message for sending
  * Fix no audio output and mute hotkey not working on HP ZBook 8 G2a
    (LP: #2158858)
    - ALSA: hda/realtek: Add inverted LED quirk for HP ZBook 8 G2a
  * Dock ethernet stops working after Thunderbolt dock unplug on Dell systems
    (LP: #2162704)
    - usb: core: port: Deattach Type-C connector on component unbind
  * USB-C alt mode dropped with false firmware bug warning on Dell systems
    (LP: #2162695)
    - Revert "usb: typec: ucsi: Detect and skip duplicate altmodes from buggy
      firmware"
    - Revert "usb: typec: ucsi: Add duplicate detection to nvidia registration
      path"
    - Revert "usb: typec: ucsi: yoga_c630: Remove redundant duplicate altmode
      handling"
    - usb: typec: ucsi: Detect and skip duplicate altmodes from buggy firmware
    - usb: typec: ucsi: Add duplicate detection to nvidia registration path
    - usb: typec: ucsi: yoga_c630: Remove redundant duplicate altmode handling
  * Resolute update: upstream stable patchset 2026-08-20 (LP: #2164666)
    - crypto: algif_skcipher - force synchronous processing
    - crypto: sun4i-ss - Remove insecure and unused rng_alg
    - [Config] Remove unused CRYPTO_DEV_SUN4I_SS_PRNG
    - media: uvcvideo: Fix deadlock if uvc_status_stop is called from
      async_ctrl.work
    - bpf: Clear delta when clearing reg id for non-{add,sub} ops
    - selftests/bpf: Add tests for delta tracking when src_reg == dst_reg
    - selftests/bpf: Add tests for stale delta leaking through id reassignment
    - ALSA: hda/realtek: Add quirk for TongFang X6xx45xU
    - ALSA: hda: conexant: Remove mic bias threshold override
    - ALSA: hda: Fix cached processing coefficient verbs
    - ALSA: hda/realtek: Fix speakers on Legion Pro 7 16ARX8H with codec SSID
      17aa:38a7
    - media: uvcvideo: Use hw timestaming if the clock buffer is full
    - media: uvcvideo: Avoid partial metadata buffers
    - media: uvcvideo: Fix buffer sequence in frame gaps
    - media: uvcvideo: Fix dev_sof filtering in hw timestamp
    - media: uvcvideo: Do not add clock samples with small sof delta
    - media: uvcvideo: Relax the constrains for interpolating the hw clock
    - media: uvcvideo: Fix sequence number when no EOF
    - dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties
    - dt-bindings: power: imx93: Add MIPI PHY power domain
    - serial: msm: Disable DMA for kernel console UART
    - serial: max310x: implement gpio_chip::get_direction()
    - serial: 8250_omap: clear rx_running on zero-length DMA completes
    - rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc
    - rxrpc: Fix socket notification race
    - rxrpc: Fix leak of released call in recvmsg(MSG_PEEK)
    - rxrpc: Fix potential infinite loop in rxrpc_recvmsg()
    - rxrpc: Fix rxrpc_rotate_tx_rotate() to check there's something to rotate
    - rxrpc: Fix oob challenge leak in cleanup after notification failure
    - rxrpc: Fix ACKALL packet handling
    - rxrpc: Fix the reception of a reply packet before data transmission
    - rxrpc: Fix leak of connection from OOB challenge
    - afs: fix NULL pointer dereference in afs_get_tree()
    - afs: handle CB.InitCallBackState3 requests without a server record
    - afs: Fix uncancelled rxrpc OOB message handler
    - fbcon: fix NULL pointer dereference for a console without vc_data
    - fbcon: Use correct type for vc_resize() return value
    - openrisc: mm: Fix section mismatch between map_page and __set_fixmap
    - clocksource/drivers/sun5i: Handle error returns from
      devm_reset_control_get_optional_exclusive()
    - accel/amdxdna: Fix leak when pinning ubuf pages
    - drm/rockchip: dw_dp: Switch to drmm_kzalloc()
    - drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove()
    - drm/rockchip: Test for imported buffers with drm_gem_is_imported()
    - drm/tidss: Drop extra drm_mode_config_reset() call
    - drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges
    - drm/gpuvm: Do not prepare NULL objects
    - drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch()
    - drm/radeon: fix integer overflow in radeon_align_pitch()
    - drm/radeon: fix memory leak in radeon_ring_restore() on lock failure
    - libbpf: Report error when a negative kprobe offset is specified
    - selftests/bpf: Fix off-by-one in bpf_cpumask_populate related selftest
    - dt-bindings: timer: Remove sifive,fine-ctr-bits property
    - drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro
    - selftests/bpf: Use local type for flow_offload_tuple_rhash in
      xdp_flowtable
    - selftests/bpf: Use local type for bpf_fou_encap in test_tunnel_kern
    - Documentation: proc: fix section numbering in table of contents
    - arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Cobra
    - arm64: dts: rockchip: Fix gmac0 reset pin for NanoPi R5S
    - arm64: dts: qcom: ipq5424: Fix USB simple_bus_reg warnings
    - arm64: dts: qcom: sc8180x: Fix phy simple_bus_reg warning
    - arm64: dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg
      warning
    - wifi: cfg80211: fix grammar in MLO group key error message
    - arm64: tegra: Fix Tegra234 MGBE PTP clock
    - dt-bindings: pinctrl: nvidia,tegra234: Add missing required block
    - drm/amdkfd: Validate CRIU-restored IDs before idr_alloc
    - driver core: use READ_ONCE() for dev->driver in dev_has_sync_state()
    - wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers
    - wifi: rtw88: fix wrong pci_get_drvdata type in AER handlers
    - wifi: rtw89: Correct data type for scan index to avoid infinite loop
    - wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA
      buffer
    - wifi: rtw89: add bounds check on firmware mac_id in link lookup
    - kconfig: fix potential NULL pointer dereference in conf_askvalue
    - soc: xilinx: Shutdown and free rx mailbox channel
    - pinctrl: mediatek: eint: Drop base from mtk_eint_chip_write_mask()
    - wifi: ath9k: fix OOB access from firmware tx status queue ID
    - ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint
    - Documentation/rv: Replace stale website link
    - watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH
    - watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5
    - watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register
      failure
    - media: cedrus: Fix failure to clean up hardware on probe failure
    - media: v4l2-common: Add YUV24 format info
    - memory: tegra: Wire up system sleep PM ops
    - crypto: qat - fix heartbeat error injection
    - lib/vsprintf: Fix to check field_width and precision
    - dts: spacemit: set console baud rate on bpif3
    - pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path
    - dt-bindings: vendor-prefixes: Add Displaytech Ltd.
    - drm/gpuvm: take refcount on DRM device
    - drm/panel: Clean up S6E3HA2 config dependencies and fill help text
    - ARM: dts: rockchip: Add #{address,size}-cells to Chromium-based
      /firmware
    - arm64: dts: rockchip: Add #{address,size}-cells to Chromium-based
      /firmware
    - arm64: dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc
    - arm64: dts: imx8x-colibri: Correct SODIMM PAD settings
    - Revert "arm64: dts: imx8mm-kontron: Add support for reading SD_VSEL
      signal"
    - Revert "arm64: dts: imx8mp-kontron: Add support for reading SD_VSEL
      signal"
    - drm: renesas: rz-du: mipi_dsi: Fix return path on error
    - alarmtimer: Remove stale return description from alarm_handle_timer()
    - OPP: Fix race between OPP addition and lookup
    - crypto: ccp - Reverse the cleanup order in psp_dev_destroy()
    - crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one
    - crypto: atmel-sha204a - fix blocking and non-blocking rng logic
    - crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve
    - crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents
    - ARM: multi_v7_defconfig: Correct QCOM_RPMH and QCOM_RPMHPD
    - nilfs2: fix backing_dev_info reference leak
    - media: qcom: camss: vfe: fix PIX subdev naming on VFE lite
    - media: iris: scale MMCX power domain on SM8250
    - media: venus: scale MMCX power domain on SM8250
    - iommu/amd: Fix a stale comment about which legacy mode is user visible
    - soc: mediatek: mtk-mmsys: Restore MT8167 routing masks lost during merge
    - bpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries
    - uaccess: fix ignored_trailing logic in copy_struct_to_user()
    - arm64: dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to
      host
    - rust: alloc: fix `Vec::extend_with` SAFETY comment
    - clk: scmi: Fix clock rate rounding
    - arm64: dts: qcom: kodiak: Fix ICE reg size
    - arm64: dts: qcom: sm8450: Fix ICE reg size
    - drm/hisilicon/hibmc: add updating link cap in DP detect()
    - drm/hisilicon/hibmc: fix no showing when no connectors connected
    - drm/hisilicon/hibmc: move display contrl config to hibmc_probe()
    - drm/hisilicon/hibmc: use clock to look up the PLL value
    - evm: terminate and bound the evm_xattrs read buffer
    - thermal: hwmon: Fix critical temperature attribute removal
    - clk: scpi: Unregister child clock providers on remove
    - net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats()
    - scsi: hisi_sas: Add slave_destroy interface for v3 hw
    - crypto: ccp - Treat zero-length cert chain as query for blob lengths
    - spi: hisi-kunpeng: Use dev_err_probe() for host registration failure
    - net/sched: sch_htb: do not change sch->flags in htb_dump()
    - net/sched: sch_htb: annotate data-races (I)
    - IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier
    - RDMA/hns: Fix arithmetic overflow in calc_hem_config()
    - RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure
    - RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference
    - RDMA/hns: Initialize seqfile before creating file
    - drm/syncobj: Fix memory leak in drm_syncobj_find_fence()
    - selftests/bpf: Reject unsupported -k option in vmtest.sh
    - selftests/bpf: Fix test for refinement of single-value tnum
    - iommu/arm-smmu-qcom: Fix fastrpc compatible string in ACTLR client match
      table
    - selftests/mm: Fix resv_sz when parsing arm64 signal frame
    - firmware: arm_ffa: Honor partition info descriptor size
    - arm64: dts: imx8dxl-evk: Remove unnecessary PCIe EP properties
    - arm64: dts: imx8qxp-mek: Remove unnecessary PCIe EP vpcie-supply
    - arm64: dts: imx95-19x19-evk: Fix PCIe EP vpcie-supply
    - media: atomisp: Fix memory leak in atomisp_fixed_pattern_table()
    - media: atomisp: gc2235: fix UAF and memory leak
    - staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy()
    - riscv: dts: spacemit: set console baud rate on Milk-V Jupiter
    - firmware: smccc: Fix Arm SMCCC SOC_ID name call
    - firmware: arm_scmi: Read sensor config as 32-bit value
    - sysfs: clamp show() return value in sysfs_kf_read()
    - bitops: use common function parameter names
    - regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions
    - tools/nolibc: getopt: Fix potential out of bounds access
    - nilfs2: Fix return in nilfs_mkdir
    - net/sched: sch_drr: annotate data-races around cl->deficit
    - media: rockchip: rga: fix too small buffer size
    - firmware: arm_scmi: Fix OOB in scmi_power_name_get()
    - arm64: dts: qcom: lemans: Add power-domain and iface clk for ice node
    - arm64: dts: qcom: monaco: Add power-domain and iface clk for ice node
    - arm64: dts: qcom: sc7180: Add power-domain and iface clk for ice node
    - arm64: dts: qcom: kodiak: Add power-domain and iface clk for ice node
    - arm64: dts: qcom: sm8450: Add power-domain and iface clk for ice node
    - arm64: dts: qcom: sm8550: Add power-domain and iface clk for ice node
    - arm64: dts: qcom: sm8650: Add power-domain and iface clk for ice node
    - arm64: dts: qcom: sm8750: Add power-domain and iface clk for ice node
    - tracing: Bound synthetic-field strings with seq_buf
    - arm64: dts: qcom: lemans: Add eDP ref clock for eDP PHYs
    - writeback: drop now-unnecessary rcu_barrier() in
      cgroup_writeback_umount()
    - kernfs: fix suspicious RCU usage in kernfs_put()
    - device property: fix fwnode reference leak in
      fwnode_graph_get_endpoint_by_id()
    - driver core: Use mod_delayed_work to prevent lost deferred probe work
    - Revert "treewide: Fix probing of devices in DT overlays"
    - of: dynamic: Fix overlayed devices not probing because of fw_devlink
    - crypto: eip93 - fix reset ring register definition
    - cpufreq: Documentation: fix sampling_down_factor range
    - cpufreq: conservative: Simplify frequency limit handling
    - pwm: imx27: Fix variable truncation in .apply()
    - RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed
    - bus: sunxi-rsb: Always check register address validity
    - pinctrl: spacemit: fix NULL check in spacemit_pin_set_config
    - RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs
    - RDMA/rxe: Fix a use-after-free problem in rxe_mmap
    - IB/mlx4: Fix refcount leak in add_port() error path
    - RDMA/hns: Fix warning in poll cq direct mode
    - RDMA/hns: Fix log flood after cmd_mbox failure
    - RDMA/counter: Fix incorrect port index in rdma_counter_init() error
      cleanup
    - pinctrl: meson: amlogic-a4: fix gpio output glitch
    - PM: sleep: Use complete() in device_pm_sleep_init()
    - MIPS: Fix big-endian stack argument fetching in o32 wrapper
    - MIPS: DEC: Remove do_IRQ() call indirection
    - mips: ralink: mt7621: add missing __iomem
    - mips: n64: add __iomem for writel call
    - driver core: Fix missing jiffies conversion in
      deferred_probe_extend_timeout()
    - driver core: Guard deferred probe timeout extension with
      delayed_work_pending()
    - mtd: spi-nor: debugfs: Fix the flags list
    - mtd: spi-nor: Drop duplicate Kconfig dependency
    - ALSA: xen-front: Reset event channel state on stream clear
    - ALSA: xen-front: Connect event channel after stream prepare
    - ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data
    - ALSA: seq: midi: Serialize output teardown with event_input
    - selftests: Fix Makefile target for nsfs
    - pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table
    - pinctrl: cs42l43: Fix leaked pm reference on error path
    - pinctrl: cs42l43: Fix polarity on debounce
    - init/initramfs_test: wait_for_initramfs() before running
    - nvmet-tcp: fix page fragment cache leak in error path
    - nvmet-tcp: check return value of nvmet_tcp_set_queue_sock
    - nvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools
    - workqueue: drop spurious '*' from print_worker_info() fn declaration
    - ipv6: guard against possible NULL deref in __in6_dev_stats_get()
    - net/sched: cls_bpf: prevent unbounded recursion in offload rollback
    - iommu/amd: Fix premature break in init_iommu_one()
    - rtla/actions: Restore continue flag in actions_perform()
    - drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X
      client is registered
    - drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove
    - gpu: host1x: Allow entries in BO caches to be freed
    - drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output()
    - gpu: host1x: Fix iommu_map_sgtable() return value check
    - drm/tegra: Fix iommu_map_sgtable() return value check
    - drm/nouveau/bios: specify correct display fuse register for Ampere and
      Ada
    - libbpf: Harden parse_vma_segs() path parsing
    - bpftool: Fix typo in struct_ops map FD generation for light skeleton
    - libbpf: Fix UAF in strset__add_str()
    - ARM: tegra: Add #{address,size}-cells to Chromium-based /firmware
    - arm64: tegra: Add #{address,size}-cells to Chromium-based /firmware
    - dax/kmem: account for partial discontiguous resource upon removal
    - rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc()
    - ocfs2: don't BUG_ON an invalid journal dinode
    - ocfs2: kill osb->system_file_mutex lock
    - crypto: hisilicon/qm - disable error report before flr
    - crypto: inside-secure/eip93 - Add check for devm_request_threaded_irq
    - crypto: tegra - Fix dma_free_coherent size error
    - crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm
    - sched/deadline: Reject debugfs dl_server writes for offline CPUs
    - drm/msm/dp: fix HPD state status bit shift value
    - drm/msm/dp: Fix the ISR_* enum values
    - EDAC/igen6: Fix call trace due to missing release()
    - EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in
      skx_get_dimm_info
    - arm64: dts: st: Fix SAI addresses on stm32mp251
    - RDMA/umem: Add ib_umem_is_contiguous() stub for
      !CONFIG_INFINIBAND_USER_MEM
    - RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe
    - RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path
    - Revert "media: venus: hfi_platform: Correct supported codecs for sc7280"
    - media: qcom: venus: drop extra padding in NV12 raw size calculation
    - media: qcom: venus: relax encoder frame/blur dimension steps on v4
    - media: qcom: venus: relax encoder frame/blur step size on v6
    - amba: use generic driver_override infrastructure
    - cdx: use generic driver_override infrastructure
    - Drivers: hv: vmbus: use generic driver_override infrastructure
    - rpmsg: use generic driver_override infrastructure
    - raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path
    - bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat
    - selftests/bpf: add verification for BPF_PROG_QUERY attr size boundaries
    - libbpf: Skip hash computation when loader generation failed
    - libbpf: Skip endianness swap when loader generation failed
    - ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data
      writeback
    - spi: atmel: fix DMA channel and bounce buffer leaks
    - ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble
    - NFSD: Fix delegation reference leak in nfsd4_revoke_states
    - ARM: imx3: Fix CCM node reference leak
    - HID: wiimote: Fix table layout and whitespace errors
    - wifi: ath12k: fix incorrect HT/VHT/HE/EHT MCS reporting in monitor mode
    - wifi: ath12k: fix NULL deref in change_sta_links for unready link
    - ata: libata: Fix ata_exec_internal()
    - ARM: imx31: Fix IIM mapping leak in revision check
    - x86/cpu: Keep the PROCESSOR_SELECT menu together
    - nvdimm/btt: Handle preemption in BTT lane acquisition
    - scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-
      channel scans"
    - bpf: Reject exclusive maps as inner maps in map-in-map
    - libbpf: Reject non-exclusive metadata maps in the signed loader
    - libbpf: Skip initial_value override on signed loaders
    - libbpf: Skip max_entries override on signed loaders
    - scsi: pm8001: Fix error code in non_fatal_log_show()
    - scsi: ufs: Fix wrong value printed in unexpected UPIU response case
    - bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs
    - mm/fake-numa: fix under-allocation detection in uniform split
    - ext2: fix ignored return value of generic_write_sync()
    - sched: restore timer_slack_ns when resetting RT policy on fork
    - driver core: Use system_percpu_wq instead of system_wq
    - bpf: Reject exclusive maps for bpf_map_elem iterators
    - tick/sched: Fix TOCTOU in nohz idle time fetch
    - lib/test_meminit: use && for bools
    - riscv: dts: sophgo: sg2044: use hex for CPU unit address
    - riscv: dts: sophgo: sg2042: use hex for CPU unit address
    - configfs_lookup(): don't leave ->s_dentry dangling on failure
    - lockdep/selftests: Restore migrate_disable() state on PREEMPT_RT
    - lockdep/selftests: Restore sched_rt_mutex state on PREEMPT_RT
    - ext4: fix fast commit wait/wake bit mapping on 64-bit
    - drm/amdgpu: set sub_block_index for mca ras sub-blocks
    - bpftool: Use libbpf error code for flow dissector query
    - vhost: fix vhost_get_avail_idx for a non empty ring
    - iommu/vt-d: Fix RB-tree corruption in probe error path
    - perf/x86/amd/core: Always use the NMI latency mitigation
    - perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems
    - perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains
    - xfrm: fix NAT-related field inheritance in SA migration
    - cxl/fwctl: Fix __fortify_panic
    - drm/amdkfd: always resume_all after suspend_all
    - of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array()
      fails
    - ocfs2: rebase copied fsdlm LVB pointers in locking_state
    - lib: kunit_iov_iter: repeatedly call alloc_pages_bulk()
    - ocfs2: fix buffer head management in ocfs2_read_blocks()
    - ocfs2: reject FITRIM ranges shorter than a cluster
    - ocfs2/dlm: require a ref for locking_state debugfs open
    - ocfs2: fix race between ocfs2_control_install_private() and
      ocfs2_control_release()
    - netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures
    - netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing
      helper flags
    - netfilter: synproxy: drop packets if timestamp adjustment fails
    - netfilter: synproxy: adjust duplicate timestamp options
    - netfilter: synproxy: fix unaligned memory access in timestamp adjustment
    - netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock
    - ALSA: usb-audio: qcom: Initialize offload control return value
    - x86/cpu: Remove obsolete aperfmperf_get_khz() declaration
    - netfilter: conntrack: revert ct extension genid infrastructure
    - netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper
      is pptp
    - RDMA/hfi1: Open-code rvt_set_ibdev_name()
    - IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path()
    - ALSA: hda: fix Kconfig dependency of HD Audio PCI
    - RDMA/irdma: Fix OOB read during CQ MR registration
    - RDMA/irdma: Initialize iwmr->access during MR registration
    - arm64: dts: imx8mp-kontron: Reduce EERAM SPI clock frequency
    - arm64: dts: imx95: Correct PCIe outbound address space configuration
    - arm64: dts: lx2162a-clearfog: use rev2 SoC dtsi
    - arm64: dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as
      well
    - arm64: dts: imx8mp-kontron: Fix GPIO for display power switch
    - bpf: Clear rb node linkage when freeing bpf_rb_root
    - bpf: Check tail zero of bpf_map_info
    - bpf: Check tail zero of bpf_prog_info
    - bpf: Update transport_header when encapsulating UDP tunnel in lwt
    - wifi: wcn36xx: fix heap overflow from oversized firmware HAL response
    - wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO
      indication
    - wifi: wcn36xx: fix OOB read from short trigger BA firmware response
    - ALSA: seq: Fix partial userptr event expansion
    - riscv: cpu_ops: Change return value type of cpu_is_stopped() to bool
    - riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe
    - ALSA: seq: Clear variable event pointer on read
    - bpf: Fix NMI/tracepoint re-entry deadlock on lru locks
    - kunit:tool: Don't write to stdout when it should be disabled
    - powerpc/8xx: implement get_direction() in cpm1
    - bpf: Fix NULL pointer dereference in bpf_task_from_vpid()
    - ACPI: IPMI: Fix message kref handling on dead device
    - cpufreq: Documentation: fix conservative governor freq_step description
    - thermal: testing: reject missing command arguments
    - btrfs: don't force DIO writes to be serialized
    - IB/mlx5: Don't take the rereg_mr fallback without a new translation
    - IB/mlx5: Properly support implicit ODP rereg_mr
    - IB/mlx5: Remove unused mkc bits in mlx5r_umr_update_mr_page_shift()
    - IB/mlx5: Pull the pdn out of the depths of the umr machinery
    - IB/mlx5: Don't mangle the mr->pd inside the rereg callback
    - spi: ep93xx: fix double-free of zeropage on DMA setup failure
    - ASoC: amd: acp-sdw-legacy: Bound DAI link iteration
    - ASoC: amd: acp-sdw-sof: Bound DAI link iteration
    - firmware_loader: Fix recursive lock in device_cache_fw_images()
    - configfs: fix lockless traversals of ->s_children
    - watchdog: unregister PM notifier on watchdog unregister
    - pinctrl: qcom: Fix resolving register base address from device node
    - scsi: target: Fix hexadecimal CHAP_I handling
    - scsi: target: Remove tcm_loop target reset handling
    - pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins
      34-39
    - pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins
      34-39
    - vmalloc: fix NULL pointer dereference in is_vm_area_hugepages()
    - hwspinlock: qcom: avoid uninitialized struct members
    - sched/fair: Fix cpu_util runnable_avg arithmetic
    - ARM: configs: Drop duplicated CONFIG_EXT4_FS
    - wifi: mt76: mt7925: clean up DMA on probe failure
    - wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link
    - wifi: mt76: mt7996: add missing max_remain_on_channel_duration
    - wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links
    - wifi: mt76: mt7925: keep TX BA state in the primary WCID
    - wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX
    - wifi: mt76: mt7925: validate skb length in testmode query
    - wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb()
    - wifi: mt76: mt7996: Fix possible NULL pointer dereference in
      mt7996_mac_write_txwi_80211()
    - wifi: mt76: mt7996: fix reading zeroed info->control.flags after
      mt76_tx_status_skb_add()
    - wifi: mt76: mt7996: limit work in set_bitrate_mask
    - wifi: mt76: fix argument to ieee80211_is_first_frag()
    - wifi: mt76: mt7915: fix potential tx_retries underflow
    - wifi: mt76: mt7921: fix potential tx_retries underflow
    - wifi: mt76: mt7925: fix potential tx_retries underflow
    - wifi: mt76: mt7996: fix potential tx_retries underflow
    - btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
    - ALSA: aloop: Drop superfluous break
    - gpio: mt7621: fix interrupt banks mapping on gpio chips
    - wifi: ath12k: enable IEEE80211_VHT_EXT_NSS_BW_CAPABLE when NSS ratio is
      reported
    - fbdev: sm501fb: Fix buffer errors in OF binding code
    - vfs: add FS_USERNS_DELEGATABLE flag and set it for NFS
    - hwmon: (it87) Clamp negative values to zero in set_fan()
    - btrfs: zoned: don't account data relocation space-info in statfs free
      space
    - Revert "btrfs: fix the file offset calculation inside
      btrfs_decompress_buf2page()"
    - btrfs: zoned: always set max_active_zones for zoned devices
    - btrfs: annotate lockless read of defrag_bytes in should_nocow()
    - btrfs: fix deadlock cloning inline extent when using flushoncommit
    - igc: skip RX timestamp header for frame preemption verification
    - ASoC: sma1307: Fix uevent string leaks in fault worker
    - IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified
    - NFSD: Handle layout stid in nfsd4_drop_revoked_stid()
    - spi: meson-spifc: fix runtime PM leak on remove
    - ASoC: codecs: aw88261: fix incorrect masks for boost regs
    - vduse: hold vduse_lock across IDR lookup in open path
    - vhost/vdpa: validate virtqueue index in mmap and fault paths
    - virtio: rtc: tear down old virtqueues before restore
    - virtio_console: read size from config space during device init
    - vduse: Requeue failed read to send_list head
    - tools/virtio: check mmap return value in vringh_test
    - vdpa/octeon_ep: Fix PF->VF mailbox data address calculation
    - vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
    - ASoC: cs35l56: Fix missing calls to wm_adsp2_remove()
    - ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails
    - ext4: fix ERR_PTR(0) in ext4_mkdir()
    - tools: missed broadcast_neigh if_link uapi header
    - netlink: specs: rt-link: missed broadcast-neigh
    - bonding: 3ad: add lacp_strict configuration knob
    - bonding: 3ad: fix carrier when no usable slaves
    - bonding: 3ad: fix mux port state on oper down
    - ext4: fix kernel BUG in ext4_write_inline_data_end
    - selftests/bpf: Fix bpf_iter/task_vma test
    - cxl/test: Fix integer overflow in mock LSA bounds checks
    - cxl/test: Zero out LSA backing memory to avoid leaking to user
    - of: cpu: add check in __of_find_n_match_cpu_property()
    - vfio/qat: fix f_pos race in qat_vf_resume_write()
    - bpf: Tighten cgroup storage cookie checks for prog arrays
    - pinctrl: sunxi: a523: Remove unneeded IRQ remuxing flag
    - pinctrl: airoha: an7581: add missed gpio32 pin group
    - pinctrl: airoha: an7581: fix misprint in gpio19 pinconf
    - arm64: dts: allwinner: a523: Add missing GPIO interrupt
    - ASoC: cs35l56: Fix possible uninitialized value in
      cs35l56_spi_system_reset()
    - s390/process: Fix kernel thread function pointer type
    - Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for
      non-serdev device
    - Bluetooth: eir: Fix stack OOB write when prepending the Flags AD
    - Bluetooth: hci_event: fix simultaneous discovery stuck in FINDING
    - Bluetooth: hci_core: Fix UAF in hci_unregister_dev()
    - Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path
    - Bluetooth: hci: validate codec capability element length
    - Bluetooth: vhci: validate devcoredump state before side effects
    - fs: efs: remove unneeded debug prints
    - RDMA/mlx5: Remove DCT restrack tracking
    - RDMA/mlx5: Remove raw RSS QP restrack tracking
    - RDMA/mlx5: Fix undefined shift of user RQ WQE size
    - RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one
    - ASoC: SOF: Intel: hda-sdw-bpt: select SND_SOF_SOF_HDA_SDW_BPT properly
    - ASoC: codecs: hdac_hdmi: Validate written enum value
    - ASoC: fsl: fsl_audmix: Validate written enum values
    - ASoC: tegra: tegra210_ahub: Validate written enum value
    - net: dsa: qca8k: fix led devicename when using external mdio bus
    - net/sched: cls_flow: Dont expose folded kernel pointers
    - net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().
    - bridge: cfm: reject invalid CCM interval at configuration time
    - net: pfcp: allocate per-cpu tstats for PFCP netdevs
    - net/sched: sch_hfsc: Don't make class passive twice
    - tipc: require net admin for TIPCv2 netlink mutators
    - tipc: prevent snt_unacked underflow on CONN_ACK
    - tipc: reject inverted service ranges from peer bindings
    - cxl/test: Unregister cxl_acpi in cxl_test_init() error path
    - cxl/test: Add check after kzalloc() memory in alloc_mock_res()
    - crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
    - crypto: cavium/cpt - fix DMA cleanup using wrong loop index
    - crypto: rng - Free default RNG on module exit
    - ALSA: usb-audio: qcom: Guard sideband endpoint removal
    - ALSA: seq: Fix kernel heap address leak in bounce_error_event()
    - spi: xilinx: use FIFO occupancy register to determine buffer size
    - iommu: Avoid copying the user array twice in the full-array copy helper
    - ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO
    - power: supply: core: fix supplied_from allocations
    - handshake: Require admin permission for DONE command
    - virtio_net: do not allow tunnel csum offload for non GSO packets
    - net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during
      peek before restoring qlen
    - net/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during
      peek before restoring qlen
    - net: mana: initialize gdma queue id to INVALID_QUEUE_ID
    - net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check
    - net: watchdog: fix refcount tracking races
    - net: ethernet: mtk_wed: fix loading WO firmware for MT7986
    - net/sched: sch_dualpi2: Add missing module alias
    - bpf: Run generic devmap egress prog on private skb
    - net/mlx5: Check max_macs devlink param value against max capability
    - bpf: Fix setting retval to -EPERM for cgroup hooks not returning errno
    - octeontx2-af: npc: Fix size of entry2cntr_map
    - net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show()
    - net: wwan: t7xx: check skb_clone in control TX
    - dpll: fix stale iteration in dpll_pin_on_pin_unregister()
    - dpll: send delete notification before unregister in on-pin rollback
    - dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister()
    - dpll: guard sync-pair removal on full pin unregister
    - dpll: balance create/delete notifications in __dpll_pin_(un)register
    - landlock: Fix unmarked concurrent access to socket family
    - net: bcmgenet: Use weighted round-robin TX DMA arbitration
    - net: airoha: Fix register index for Tx-fwd counter configuration
    - net: airoha: Fix debugfs new-tuple display for IPv4 ROUTE entries
    - kcm: use WRITE_ONCE() when changing lower socket callbacks
    - ALSA: seq: oss: Serialize readq reset state with q->lock
    - ALSA: seq: avoid stale FIFO cells during resize
    - netfilter: nf_conncount: callers must hold rcu read lock
    - ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait()
    - cifs: remove all cifs files before kill super
    - smb/client: always return a value for FS_IOC_GETFLAGS
    - selftests/bpf: Fix typo in verify_umulti_link_info
    - selftests/bpf: Initialize operation name before use
    - bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket
    - udf: fix nls leak on udf_fill_super() failure
    - bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
    - net: remove addr_len argument of recvmsg() handlers
    - sockmap: Fix use-after-free in udp_bpf_recvmsg()
    - bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check
    - MIPS: mm: Fix out-of-bounds write in maar_res_walk()
    - powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del
    - powerpc/powernv: fix preempt count leak in
      pnv_kexec_wait_secondaries_down
    - powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus
    - KEYS: Use acquire when reading state in keyring search
    - tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)
    - net: airoha: Fix always-true condition in PPE1 queue reservation loop
    - net: ethernet: oa_tc6: Remove FCS size in RX frame
    - ionic: Fix check in ionic_get_link_ext_stats
    - RDMA/bnxt_re: Free SRQ toggle page after firmware teardown
    - RDMA/bnxt_re: Avoid displaying the kernel pointer
    - RDMA/bnxt_re: Fail DBR related page allocation UAPIs if the feature is
      disabled
    - ksmbd: fix use-after-free in same_client_has_lease()
    - mfd: rsmu: Fix page register setup
    - mfd: cs42l43: Sanity check firmware size
    - ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write
    - 9p: avoid returning ERR_PTR(0) from mkdir operations
    - eventpoll: rename ep_remove_safe() back to ep_remove()
    - eventpoll: expand top-of-file overview / locking doc
    - eventpoll: rename attach_epitem() to ep_attach_file()
    - eventpoll: split ep_insert() into alloc + register stages
    - eventpoll: extract ep_deliver_event() from ep_send_events()
    - eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers
    - eventpoll: rename epi->next and txlist for clarity
    - eventpoll: Fix epoll_wait() report false negative
    - gpiolib: acpi: Only trigger ActiveBoth interrupts on boot
    - i3c: master: svc: Fix missed IBI after false SLVSTART on NPCM845
    - staging: nvec: fix use-after-free in nvec_rx_completed()
    - perf debuginfo: Fix libdw API contract violations
    - coresight: cti: Fix DT filter signals silently ignored
    - soundwire: don't program SDW_SCP_BUSCLOCK_SCALE on a unattached
      Peripheral
    - soundwire: fix bug in sdw_add_element_group_count found by syzkaller
    - coresight: ete: Always save state on power down
    - coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore
    - PCI/ASPM: Don't reconfigure ASPM entering low-power state
    - PCI: Introduce named defines for PCI ROM
    - PCI: Check ROM header and data structure addr before accessing
    - x86/platform/olpc: xo15: Drop wakeup source on driver removal
    - platform/x86: xo15-ebook: Fix wakeup source and GPE handling
    - perf sched: Add missing mmap2 handler in timehist
    - PCI: loongson: Do not ignore downstream devices on external bridges
    - rust: alloc: fix assert in `Vec::reserve` doc test
    - bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
    - coresight: fix missing error code when trace ID is invalid
    - clk: qcom: cmnpll: Account for reference clock divider
    - phy: phy-can-transceiver: Check driver match and driver data against
      NULL
    - perf pmu: Skip test on Arm64 when #slots is zero
    - clk: at91: sam9x7: Fix gmac_gclk clock definition
    - soundwire: intel_ace2x: release bpt_stream when close it
    - coresight: Fix source not disabled on idr_alloc_u32 failure
    - mailbox: mpfs: fix check for syscon presence in mpfs_mbox_inbox_isr()
    - mailbox: mtk-adsp: fix UAF during device teardown
    - PCI: dwc: Fix signedness bug in fault injection test code
    - perf build-id: Fix off-by-one bug when printing kernel/module build-id
    - staging: most: video: avoid double free on video register failure
    - usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
    - usb: host: max3421: Reject hub port requests for non-existent ports
    - perf test amd ibs: Fix incorrect kernel version check
    - gpib: Fix inappropriate ioctl error return
    - char: tlclk: fix use-after-free in tlclk_cleanup()
    - gpib: fix double decrement of descriptor_busy in command_ioctl()
    - clk: renesas: rzg2l: Rename iterator in for_each_mod_clock() to avoid
      shadowing
    - powerpc tools perf: Initialize error code in auxtrace_record_init
      function
    - PCI: qcom: Disable ASPM L0s for SA8775P
    - perf header: Sanity check HEADER_EVENT_DESC attr.size before swap
    - iio: light: si1133: reset counter to prevent race condition
    - iio: light: si1133: prevent race condition on timeout
    - iio: magnetometer: ak8975: fix potential kernel stack memory leak
    - iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling
    - iio: accel: mma8452: handle I2C read error(s) in mma8452_read()
    - iio: tcs3472: power down chip on probe failure
    - clk: at91: keep securam node alive while mapping it
    - HID: logitech-hidpp: remove excess kernel-doc member in
      hidpp_scroll_counter
    - fs/ntfs3: add bounds check to run_get_highest_vcn()
    - fs/ntfs3: fix mount failure on 64K page-size kernels
    - drm/amd/display: Add missing kdoc for ALLM parameters
    - thunderbolt: debugfs: Fix margining error counter buffer leak
    - dmaengine: imx-sdma: Refine spba bus searching in probe
    - dt-bindings: dma: nvidia,tegra186-gpc-dma: Make reset optional
    - perf: Fix off-by-one stack buffer overflow in kallsyms__parse()
    - perf annotate: Fix crashes on empty annotate windows
    - perf tools: Guard test_bit from out-of-bounds sample CPU
    - perf sched: Fix thread reference leak in latency_switch_event
    - perf tools: Add bounds check to cpu__get_node()
    - perf sched: Cap max_cpu at MAX_CPUS in timehist sample processing
    - perf sched: Fix register_pid() overflow, strcpy, and BUG_ON
    - perf mmap: Guard cpu__get_node() return in aio_bind()
    - perf stat: Bounds-check CPU index in topology aggregation callbacks
    - perf c2c: Bounds-check CPU and node IDs before bitmap and array access
    - perf c2c: Bounds-check CPU IDs in setup_nodes() topology loop
    - perf sched: Clean up idle_threads entry on init failure
    - perf sched: Use thread__put() in free_idle_threads()
    - perf sched: Replace BUG_ON and add NULL checks in replay event helpers
    - perf mmap: Fix NULL deref in aio cleanup on alloc failure
    - perf stat: Introduce perf_env__get_cpu_topology() to guard NULL env->cpu
    - perf c2c: Fix use-after-free in he__get_c2c_hists() error path
    - perf timechart: Fix cpu2y() OOB read on untrusted CPU index
    - perf tools: Fix int16_t truncation of max_cpu_num in set_max_cpu_num()
    - dt-bindings: clock: qcom: Add X1P42100 camera clock controller
    - clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks
    - mshv: add bounds check on vp_index in mshv_intercept_isr()
    - dmaengine: qcom: gpi: set DMA_PRIVATE capability
    - dmaengine: Fix possible use after free
    - dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc
    - dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor
    - clk: qcom: a53: Corrected frequency multiplier for 1152MHz
    - sunrpc: Fix error handling in rpc_sysfs_xprt_switch_add_xprt_store()
    - pNFS/filelayout: fix cheking if a layout is striped
    - NFSv4/pnfs: defer return_range callbacks until after inode unlock
    - nfs: keep PG_UPTODATE clear after read errors in page groups
    - NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect
      errors
    - NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in
      pg_get_mirror_count_write
    - PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro
    - pwm: rzg2l-gpt: Add missing newlines to dev_err_probe() messages
    - PCI: meson: Propagate devm_add_action_or_reset() failure
    - PCI: meson: Add missing remove callback
    - fs/ntfs3: resize log->one_page_buf when adopting on-disk page size
    - platform/x86/intel/vsec: Decouple add/link helpers from PCI
    - platform/x86/intel/vsec: Switch exported helpers from pci_dev to device
    - platform/x86/intel/vsec: Return real error codes from registration path
    - platform/x86/intel/vsec: Restore BAR fallback for header walk
    - perf tools: Fix get_max_num() size_t underflow on empty sysfs file
    - perf tools: Use scnprintf() in cpu_map__snprint() to prevent overflow
    - perf tools: Use perf_env__get_cpu_topology() in machine__resolve()
    - PCI: rcar-host: Remove unused LIST_HEAD(res)
    - perf sched: Bounds-check prio before test_bit() in timehist
    - perf sched: Fix idle-hist callchain display using wrong rb_first variant
    - perf bpf: Use scnprintf() in snprintf_hex() and
      synthesize_bpf_prog_name()
    - perf hists: Fix snprintf() in hists__scnprintf_title() UID filter path
    - xprtrdma: Fix ep kref imbalance on ADDR_CHANGE
    - xprtrdma: Initialize re_id before removal registration
    - xprtrdma: Check frwr_wp_create() during connect
    - xprtrdma: Document and assert reply-handler invariants
    - xprtrdma: Resize reply buffers before reposting receives
    - xprtrdma: Sanitize the reply credit grant after parsing
    - xprtrdma: Repost Receive buffers for malformed replies
    - xprtrdma: Return sendctx slot after Send preparation failure
    - perf s390: Fix TEXTREL in Python extension by compiling as PIC
    - perf cs-etm: Queue context packets for frontend
    - perf pmu: Fix pmu_id() heap underwrite on empty identifier file
    - perf pmu: Fix perf_pmu__parse_scale/unit() OOB access on empty sysfs
      file
    - tools lib api: Fix missing null termination in filename__read_int/ull()
    - perf symbols: Fix signed overflow in sysfs__read_build_id() size check
    - perf symbols: Bounds-check .gnu_debuglink section data
    - perf intel-pt: Fix snprintf size tracking bug in insn decoder
    - perf tools: Fix thread__set_comm_from_proc() on empty comm file
    - perf hwmon: Fix off-by-one null termination on sysfs reads
    - perf hwmon: Use scnprintf() in hwmon_pmu__for_each_event()
    - perf hwmon: Fix parse_hwmon_filename() strlcpy buffer overflow
    - perf symbols: Bounds-check descsz in sysfs__read_build_id() GNU fallback
    - perf hwmon: Guard label read against empty or failed reads
    - perf tools: Use snprintf() in dso__read_running_kernel_build_id()
    - tools lib api: Fix filename__write_int() writing uninitialized stack
      data
    - tools lib api: Fix mount_overload() snprintf truncation and toupper
      range
    - perf bpf: Add NULL check for btf__type_by_id() in
      synthesize_bpf_prog_name()
    - perf bpf: Fix map data leak in bpf_metadata_create() on alloc failure
    - perf bpf: Fix metadata leak in perf_env__add_bpf_info() on duplicate
      insert
    - perf symbols: Add bounds checks to elf_read_build_id() note iteration
    - perf symbols: Add bounds checks to read_build_id() note iteration in
      minimal build
    - dt-bindings: phy: sc8280xp-qmp-pcie: Disallow bifurcation register on
      Purwa
    - PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port()
    - PCI: mediatek: Use actual physical address instead of virt_to_phys()
    - phy: freescale: phy-fsl-imx8qm-lvds-phy: Fix missing
      pm_runtime_disable() on probe error path
    - PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when
      no RAS DES capability
    - Revert "PCI/MSI: Unmap MSI-X region on error"
    - apparmor: fix shadowing of plabel that prevents cache from being updated
    - apparmor: fix race in unix socket mediation when peer_path is used
    - apparmor: fix refcount leak when updating the sk_ctx
    - security/apparmor/apparmorfs.c: conditionally compile
      get_loaddata_common_ref()
    - apparmor: check label build before no_new_privs test
    - apparmor: aa_label_alloc use aa_label_free on alloc failure
    - SAUCE: Revert "UBUNTU: SAUCE: apparmor5.0.0 [41/57]: apparmor-next 7.1:
      apparmor: fix rawdata_f_data implicit flex array"
    - apparmor: fix rawdata_f_data implicit flex array
    - SAUCE: Revert "UBUNTU: SAUCE: apparmor5.0.0 [38/57]: apparmor-next 7.1:
      apparmor: grab ns lock and refresh when looking up changehat child
      profiles"
    - apparmor: grab ns lock and refresh when looking up changehat child
      profiles
    - SAUCE: Revert "UBUNTU: SAUCE: apparmor5.0.0 [44/57]: apparmor-next 7.1:
      apparmor: fix potential UAF in aa_replace_profiles"
    - apparmor: fix potential UAF in aa_replace_profiles
    - SAUCE: Revert "UBUNTU: SAUCE: apparmor: fix NULL pointer dereference in
      unpack_pdb"
    - apparmor: fix NULL pointer dereference in unpack_pdb
    - apparmor: remove or add symlinks to rawdata according to export_binary
    - apparmor: Fix return in ns_mkdir_op
    - apparmor: fail policy unpack on accept2 allocation failure
    - apparmor: aa_getprocattr free procattr leak on format failure
    - apparmor: put secmark label after secid lookup
    - apparmor: don't audit files pointing to aa_null.dentry
    - apparmor: fix uninitialised pointer passed to
      audit_log_untrustedstring()
    - i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring
    - i3c: master: Make hot-join workqueue freezable to block hot-join during
      suspend
    - i3c: master: Move rstdaa error suppression
    - i3c: master: Consolidate Hot-Join DAA work in the core
    - i3c: master: Ensure Hot-Join operations are stopped on shutdown
    - i3c: master: Defer new-device registration out of DAA caller context
    - i3c: master: Prevent reuse of dynamic address on device add failure
    - apparmor: fix label can not be immediately before a declaration
    - accel/ivpu: fix HWS command queue leak on registration failure
    - sparc: led: avoid trimming a newline from empty writes
    - perf symbols: Fix bswap copy-paste error for 32-bit ELF p_filesz
    - perf symbols: Validate p_filesz before use in filename__read_build_id()
    - perf symbols: Break infinite loop on zero-filled notes in
      sysfs__read_build_id()
    - perf tools: Add O_CLOEXEC to open() calls in DSO and ELF code
    - perf tools: Fix uninitialized pathname on uncompressed fallback in
      filename__decompress()
    - perf dso: Fix heap overflow in dso__get_filename() on decompressed path
    - perf dso: Set error code when open() fails on uncompressed fallback path
    - perf tools: Use snprintf() for root_dir path construction
    - perf hwmon: Fix fd check to accept fd 0 in hwmon_pmu__describe_items()
    - perf sched: Replace (void*)1 sentinel with proper runtime allocation
    - perf bpf: Validate func_info_rec_size and sub_id in
      synthesize_bpf_prog_name()
    - perf bpf: Reject oversized BPF metadata events that truncate header.size
    - perf bpf: Bounds-check array offsets in bpil_offs_to_addr()
    - perf cs-etm: Reject CPU IDs that would overflow signed comparison
    - gpio: mlxbf3: fail probe if gpiochip registration fails
    - drm/i915: clear CRTC color blob pointers after dropping refs
    - drm/xe: Fix wa_oob codegen recipe for external module builds
    - spi: dw: fix wrong BAUDR setting after resume
    - i3c: master: Update dev_nack_retry_count under maintenance lock
    - i3c: master: Add missing runtime PM get in dev_nack_retry_count_store()
    - ALSA: usb-audio: qcom: Free sideband sg_table objects
    - xfrm: annotate data-races around xfrm_policy_count[] and
      xfrm_policy_default[]
    - xfrm: validate selector family and prefixlen during match
    - perf machine: Use snprintf() for guestmount path construction
    - perf cs-etm: Validate num_cpu before metadata allocation
    - perf cs-etm: Require full global header in auxtrace_info size check
    - perf cs-etm: Bounds-check CPU in cs_etm__get_queue()
    - perf bpf: Validate array presence before casting BPF prog info pointers
    - perf dso: Set standard errno on decompression failure
    - ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode
    - drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free
    - drm/amd/display: Fix mem_type change detection for async flips
    - drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm
    - drm/amdgpu: initialize irq.lock spinlock earlier
    - octeontx2-pf: Fix leak of SQ timestamp buffer on teardown
    - net: psample: fix info leak in PSAMPLE_ATTR_DATA
    - sctp: hold socket lock when dumping endpoints in sctp_diag
    - ALSA: usb-audio: qcom: reject stream disable with no active interface
    - ALSA: usb-audio: qcom: clear opened when stream enable fails
    - PCI: iproc: Restore .map_irq() for the platform bus driver
    - spi: rpc-if: Use correct device for hardware reinitialization on resume
    - virtio-net: fix len check in receive_big()
    - dpaa2-switch: fix VLAN upper check not rejecting bridge join
    - devlink: Fix parent ref leak in devl_rate_node_create()
    - devlink: Fix parent ref leak on tc-bw failure
    - net: airoha: fix foe_check_time allocation size
    - net: macb: add TX stall timeout callback to recover from lost TSTART
      write
    - flow_dissector: check device type before reading ETH_ADDRS
    - selftests: vlan_bridge_binding: Fix flaky operational state check
    - ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints
    - arm64/hw_breakpoint: reject unaligned watchpoints that would truncate
      BAS
    - thermal: intel: Fix dangling resources on thermal_throttle_online()
      failure
    - ACPI: resource: Amend kernel-doc style
    - ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone()
    - ieee802154: Restore initial state on failed device_rename() in
      cfg802154_switch_netns()
    - ieee802154: Avoid calling WARN_ON() on -ENOMEM in
      cfg802154_switch_netns()
    - ieee802154: Remove WARN_ON() in cfg802154_pernet_exit()
    - ieee802154: fix kernel-infoleak in dgram_recvmsg()
    - mac802154: Prevent overwrite return code in
      mac802154_perform_association()
    - md/raid1: honor REQ_NOWAIT when waiting for behind writes
    - md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on
      retry
    - netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
    - netfilter: ipset: make sure gc is properly stopped
    - netfilter: nft_payload: reject offsets exceeding 65535 bytes
    - netfilter: nft_meta_bridge: add validate callback for get operations
    - netfilter: nft_flow_offload: zero device address for non-ether case
    - netfilter: nf_reject: skip iphdr options when looking for icmp header
    - netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak
    - mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx()
    - irqchip/crossbar: Fix parent domain resource leak
    - alloc_tag: fix use-after-free in /proc/allocinfo after module unload
    - selftests/mm: restore default nr_hugepages value via exit trap in
      charge_reserved_hugetlb.sh
    - selftests/mm: restore default nr_hugepages value via exit trap in
      hugetlb_reparenting_test.sh
    - selftests/mm: fix hugetlb pathname construction in
      hugetlb_reparenting_test.sh
    - selftests/mm: fix cgroup task placement and drop memory.current checks
      in hugetlb_reparenting_test.sh
    - selftests/mm: size tmpfs according to PMD page size in
      split_huge_page_test
    - selftests/mm: free dynamically allocated PMD-sized buffers in
      split_huge_page_test
    - selftest/mm: register existing mapping with userfaultfd in hugetlb-
      mremap
    - selftests/mm: ensure destination is hugetlb-backed in hugetlb-mremap
    - selftests/mm: skip uffd-stress test when nr_pages_per_cpu is zero
    - selftests/mm: clarify alternate unmapping in compaction_test
    - selftests/mm: allow PUD-level entries in compound testcase of hmm tests
    - selftests/mm: fix exclusive_cow test fork() handling
    - net: marvell: prestera: initialize err in prestera_port_sfp_bind
    - tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
    - net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths
    - octeontx2-af: mcs: Fix unsupported secy stats read
    - octeontx2-pf: Clear stats of all resources when freeing resources
    - octeontx2-pf: mcs: Fix mcs resources free on PF shutdown
    - net: emac: Fix NULL pointer dereference in emac_probe
    - net/sched: act_ct: fix nf_connlabels leak on two error paths
    - net: airoha: Fix skb->priority underflow in airoha_dev_select_queue()
    - ipv6: ndisc: fix NULL deref in accept_untracked_na()
    - dpaa2-switch: do not accept VLAN uppers while bridged
    - rtc: abx80x: fix the RTC_VL_CLR clearing all status flags
    - rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231
    - bpf: Fix stack slot index in nospec checks
    - bpftool: Fix vmlinux BTF leak in cgroup commands
    - bpf: zero-initialize the fib lookup flow struct
    - bpf: Fix effective prog array index with BPF_F_PREORDER
    - power: sequencing: fix ABBA deadlock in pwrseq_device_unregister()
    - gpiolib: initialize return value in gpiochip_set_multiple()
    - drm/edid: fix OOB read in drm_parse_tiled_block()
    - PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0
    - PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0
    - ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs()
    - ice: fix AQ error code comparison in ice_set_pauseparam()
    - ice: call netif_keep_dst() once when entering switchdev mode
    - rtc: isl1208: Balance enable_irq_wake() with disable_irq_wake() on
      cleanup
    - ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info
    - ice: dpll: fix memory leak in ice_dpll_init_info error paths
    - i40e: Fix i40e_debug() to use struct i40e_hw argument
    - rtc: msc313: fix NULL deref in shared IRQ handler at probe
    - ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().
    - eth: bnxt: rename ring_err_stats -> ring_drv_stats
    - eth: bnxt: improve the timing of stats
    - ipv4: fib: Don't ignore error route in local/main tables.
    - md/raid5: use stripe state snapshot in break_stripe_batch_list()
    - md/raid5: avoid R5_Overlap races while breaking stripe batches
    - bpf: Disable xfrm_decode_session hook attachment
    - netfilter: nf_nat: avoid invalid nat_net pointer use on failed
      nf_nat_init()
    - netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
    - netfilter: nft_synproxy: stop bypassing the priv->info snapshot
    - netfilter: nft_compat: ebtables emulation must reject non-bridge targets
    - gpio: davinci: fix IRQ domain leak on devm_kzalloc failure
    - NTB: epf: Make db_valid_mask cover only real doorbell bits
    - NTB: epf: Report 0-based doorbell vector via ntb_db_event()
    - NTB: epf: Fix doorbell bitmask and IRQ vector handling
    - alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
    - alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs
    - net, bpf: check master for NULL in xdp_master_redirect()
    - net: do not acquire dev->tx_global_lock in netdev_watchdog_up()
    - net: dsa: sja1105: round up PTP perout pin duration
    - veth: fix NAPI leak in XDP enable error path
    - net: usb: lan78xx: restore VLAN and hash filters after link up
    - ipv6: fix error handling in disable_ipv6 sysctl
    - ipv6: fix error handling in ignore_routes_with_linkdown sysctl
    - ipv6: fix error handling in forwarding sysctl
    - ipv6: fix error handling in disable_policy sysctl
    - ipv6: fix state corruption during proxy_ndp sysctl restart
    - ipv6: fix missing notification for ignore_routes_with_linkdown
    - eth: fbnic: fix ordering of heartbeat vs ownership
    - thermal: testing: zone: Flush work items during cleanup
    - ACPI: processor_idle: Mark LPI enter functions as __cpuidle
    - smb/client: preserve errors from smb2_set_sparse()
    - rtc: ds1307: Fix off-by-one issue with wday for rx8130
    - rtc: cmos: unregister HPET IRQ handler on probe failure
    - net: dsa: realtek: fix memory leak in rtl8366rb_setup_led()
    - net: phy: realtek: Clear MDIO_AN_10GBT_CTRL_ADV10G bit
    - octeontx2-af: Validate NIX maximum LFs correctly
    - net: mvneta: re-enable percpu interrupt on resume
    - net: sungem: fix probe error cleanup
    - net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove
    - LoongArch: Move struct kimage forward declaration before use
    - LoongArch: BPF: Fix outdated tail call comments
    - LoongArch: BPF: Fix off-by-one error in tail call
    - ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count
    - net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync
    - dt-bindings: net: renesas,ether: Drop example "ethernet-phy-
      ieee802.3-c22" fallback
    - selftests: tls: size splice_short pipe by page size
    - net: hns3: unify copper port ksettings configuration path
    - net: hns3: refactor MAC autoneg and speed configuration
    - net: hns3: fix permanent link down deadlock after reset
    - net: hns3: differentiate autoneg default values between copper and fiber
    - ALSA: FCP: Fix NULL pointer dereference in interface lookup
    - tracing: probes: fix typo in a log message
    - spi: sh-msiof: abort transfers when reset times out
    - ACPI: RIMT: Only defer the IOMMU configuration in init stage
    - riscv: Fix 32-bit call_on_irq_stack() frame pointer ABI
    - gpio: mvebu: fail probe if gpiochip registration fails
    - gpio: htc-egpio: use managed gpiochip registration
    - net: pse-pd: scope pse_control regulator handle to kref lifetime
    - seg6: validate SRH length before reading fixed fields
    - qede: fix out-of-bounds check for cqe->len_list[]
    - sctp: fix SCTP_RESET_STREAMS stream list length limit
    - MIPS: DEC: Ensure RTC platform device deregistration upon failure
    - MIPS: mm: Add check for highmem before removing memory block
    - ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280
    - hwmon: adm1275: Prevent reading uninitialized stack
    - hwmon: (pmbus) Fix passing events to regulator core
    - hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-
      zero
    - ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump
    - usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()
    - net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy
    - net: libwx: fix VMDQ mask for 1-queue mode
    - net: gianfar: dispose irq mappings on probe failure and device removal
    - net/sched: sch_teql: Introduce slaves_lock to avoid race condition and
      UAF
    - bridge: stp: Fix a potential use-after-free when deleting a bridge
    - drm/panthor: Fix potential invalid pointer deref in
      group_process_tiler_oom()
    - drm/panthor: Don't overrule pending immediate ticks in
      sched_resume_tick()
    - drm/panthor: Fix a leak when a group is evicted before the tiler OOM is
      serviced
    - drm/panthor: Interrupt group start/resumption if group_bind_locked()
      fails
    - tracing/eprobes: Allow use of BTF names to dereference pointers
    - tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg
    - tracing/events: Fix to check the simple_tsk_fn creation
    - tracing: eprobe: read the complete FILTER_PTR_STRING pointer
    - tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry()
    - tracing/probes: Make the $ prefix mandatory for comm access
    - irqchip/gic-v3-its: Fix OF node reference leak
    - irqchip/ts4800: Fix missing chained handler cleanup on remove
    - sctp: fix addr_wq_timer race in sctp_free_addr_wq()
    - virtio_net: disable cb when NAPI is busy-polled
    - cxgb4: Fix decode strings dump for T6 adapters
    - selftests: drv-net: tso: don't touch dangerous feature bits
    - net/sched: act_bpf: use rcu_dereference_bh() to read the filter
    - ksmbd: reject undersized DACLs before parsing ACEs
    - gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe
    - pinctrl: meson: restore non-sleeping GPIO access
    - net/sched: dualpi2: clear stale classification on filter miss
    - net/sched: hhf: clear heavy-hitter state on reset
    - fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid
    - afs: Fix error code in afs_extract_vl_addrs()
    - afs: Fix double netfs initialisation in afs_root_iget()
    - afs: use kvfree() to free memory allocated by kvcalloc()
    - afs: Remove erroneous seq |= 1 in volume lookup loop
    - afs: Fix bulk lookup malfunction due to change in dir_emit() API
    - afs: Fix misplaced inc of net->cells_outstanding
    - afs: Fix reinitialisation of the inode, in particular ->lock_work
    - afs: Fix callback service message parsers to pass through -EAGAIN
    - afs: Fix missing NULL pointer check in afs_break_some_callbacks()
    - afs: Fix vllist leak
    - afs: Fix lack of locking around modifications of net->cells_dyn_ino
    - afs: Fix premature cell exposure through /afs
    - afs: Fix the volume AFS_VOLUME_RM_TREE is set on
    - afs: Fix unchecked-length string display in debug statement
    - minix: avoid overflow in bitmap block count calculation
    - ovl: fix comment about locking order
    - iomap: guard io_size EOF trim against concurrent truncate underflow
    - netfs: Fix writethrough to use collection offload
    - netfs: Fix writeback error handling
    - netfs: Fix folio state after ENOMEM whilst under writeback iteration
    - drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()
    - drm/xe/userptr: Hold notifier_lock for write on inject test path
    - drm/xe/hw_engine: Fix double-free of managed BO in error path
    - drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays
    - x86/uprobes: Keep shadow stack in sync for emulated CALLs
    - uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline
    - cifs: Fix missing credit release on failure in cifs_issue_read()
    - ata: sata_gemini: unwind clocks on IDE pinctrl errors
    - ata: libata-scsi: limit simulated SCSI command copy to response length
    - HID: picolcd: prevent NULL pointer dereference in
      picolcd_send_and_wait()
    - HID: core: Fix OOB read in hid_get_report for numbered reports
    - arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range()
    - HID: bpf: Fix hid_bpf_get_data() range check
    - selftests/hid: Load only requested struct_ops maps
    - selftests/hid: Cover hid_bpf_get_data() size overflow
    - arm64/sysreg: Fix BWE field encoding in ID_AA64DFR2_EL1
    - net: usb: net1080: validate packet_len before pad-byte access in
      rx_fixup
    - netfilter: xt_u32: reject invalid shift counts
    - netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()
    - netfilter: nft_set_rbtree: get command skips end element with open
      interval
    - netfilter: xt_connmark: reject invalid shift parameters
    - net/mlx5: LAG, MPESW, Fix missing complete() on devcom error
    - net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation
    - net/mlx5e: Fix HV VHCA stats agent registration race
    - net/mlx5e: Fix publication race for priv->channel_stats[]
    - net: microchip: vcap: fix races on the shared Super VCAP block
    - net: qualcomm: rmnet: validate MAP frame length before ingress parsing
    - net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload
    - amt: fix size calculation in amt_get_size()
    - Bluetooth: 6lowpan: hold L2CAP conn across debugfs control
    - Bluetooth: MGMT: Fix adv monitor add failure cleanup
    - Bluetooth: sco: Fix a race condition in sco_sock_timeout()
    - Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length
    - Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
    - Bluetooth: L2CAP: fix tx ident leak for commands without a response
    - ring-buffer: Fix event length with forced 8-byte alignment
    - accel/amdxdna: Use unsigned long for nr_pages in amdxdna_hmm_register()
    - net/tls: Consume empty data records in tls_sw_read_sock()
    - net: usb: lan78xx: disable VLAN filter in promiscuous mode
    - gpio: dwapb: reduce allocation to single kzalloc
    - gpio: dwapb: Defer clock gating until noirq
    - tracing: Make tracepoint_printk static as not exported
    - accel/amdxdna: Fix potential amdxdna_umap lifetime race
    - drm/v3d: Reject invalid indirect BO handle in indirect CSD setup
    - net: mdio: select REGMAP_MMIO instead of depending on it
    - net/sched: cake: reject overhead values that underflow length
    - octeontx2-pf: check DMAC extraction support before filtering
    - perf/x86/amd/core: Avoid enabling BRS from the SVM reload path
    - gpio: mvebu: free generic chips on unbind
    - ipv4: igmp: annotate data-races around im->users
    - ipv4: igmp: annotate data-races around timer-related fields
    - ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and
      igmp_stop_timer()
    - ipvs: pass parsed transport offset to state handlers
    - ipvs: use parsed transport offset in TCP state lookup
    - s390/zcrypt: Remove the empty file
    - SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED
    - dm era: fix NULL pointer dereference in metadata_open()
    - regulator: core: regulator_lock_two() should test for EDEADLK not
      EDEADLOCK
    - selftests/net: fix EVP_MD_CTX leak in tcp_mmap
    - net/mlx5: Fix L3 tunnel entropy refcount leak
    - octeontx2-af: fix VF bringup affecting PF promiscuous state
    - drm/xe: remove duplicate <kunit/test-bug.h> include
    - smb: client: fix overflow in passthrough ioctl bounds check
    - idpf: add padding to PTP virtchnl structures
    - mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()
    - mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()
    - vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter
    - ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put
    - ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
    - ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get
    - ASoC: SOF: topology: validate vendor array size before parsing
    - net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
    - net: atm: reject out-of-range traffic classes in QoS validation
    - octeontx2-pf: clear stale mailbox IRQ state before request_irq()
    - octeontx2-vf: clear stale mailbox IRQ state before request_irq()
    - arm64: fpsimd: Fix type mismatch in sve_{save,load}_state()
    - arm64: dts: s32g3: Fix SWT8 watchdog address
    - ARM: dts: imx6ul-var-som: fix warning for non-existent dc-supply
      property
    - arm64: dts: qcom: sdm630: describe adsp_mem region properly
    - arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Ringneck
    - ARM: dts: stm32: stm32mp15x-mecio1-io: Fix ADC sampling times
    - ARM: dts: stm32: stm32mp15x-mecio1-io: Move divergent mecio1 ADC
      channels to board files
    - arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc
    - ARM: dts: stm32: stm32mp15x-mecio1-io: Enable internal ADC reference
    - arm64: dts: imx8ulp-evk: Correct Type-C int GPIO flags
    - ARM: dts: stm32: stm32mp15x-mecio1-io: Fix GPIO names typo
    - ARM: dts: stm32: stm32mp15x-mecio1-io: Move gpio-line-names to board
      files
    - ARM: dts: stm32: stm32mp15x-mecio1-io: Fix expander gpio line typo
    - ARM: dts: stm32: stm32mp15x-mecio1-io: Move expander gpio-line-names to
      board files
    - LoongArch: KVM: Validate irqchip index in irqfd routing
    - LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt()
    - LoongArch: KVM: Check the return values for put_user()
    - LoongArch: KVM: Fix FPU register width with user access API
    - LoongArch: KVM: Return full old CSR value from kvm_emu_xchg_csr()
    - powerpc/pseries/Kconfig: Enable CONFIG_VPA_PMU to be used with KVM
    - KVM: s390: pci: Fix GISC refcount leak on AIF enable failure
    - KVM: s390: pci: Fix handling of AIF enable without AISB
    - KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs
    - KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
    - KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails
    - KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid
      guest state
    - KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers
    - KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2
    - KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions
    - KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
    - fbdev: metronomefb: fix potential memory leak in metronomefb_probe()
    - fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe()
    - fbdev: hecubafb: fix potential memory leak in hecubafb_probe()
    - fbdev: sm712: Fix operator precedence in big_swap macro
    - fbdev: efifb: fix memory leak in efifb_probe()
    - fbdev: radeon: fix potential memory leak in radeonfb_pci_register()
    - fbdev: i740fb: fix potential memory leak in i740fb_probe()
    - fbdev: s3fb: fix potential memory leak in s3_pci_probe()
    - fbdev: uvesafb: fix potential memory leak in uvesafb_probe()
    - fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe()
    - fbdev: carminefb: fix potential memory leak in alloc_carmine_fb()
    - fbdev: vesafb: fix memory leak in vesafb_probe()
    - fbdev: nvidia: fix potential memory leak in nvidiafb_probe()
    - fbdev: tridentfb: fix potential memory leak in trident_pci_probe()
    - ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
    - ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control
    - ASoC: mediatek: mt8192: Check runtime resume during probe
    - ASoC: mediatek: mt8192: Release reserved memory on cleanup
    - ASoC: mediatek: mt8183: Check runtime resume during probe
    - ASoC: mediatek: mt8183: Release reserved memory on cleanup
    - ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback
    - netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
    - netfilter: nfnl_cthelper: apply per-class values when updating policies
    - netfilter: xt_cluster: reject template conntracks in hash match
    - netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst
    - netfilter: nft_set_pipapo: don't leak bad clone into future transaction
    - netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6
      defrag
    - netfilter: nf_conncount: fix zone comparison in tuple dedup
    - netfilter: ecache: fix inverted time_after() check
    - netfilter: xt_nat: reject unsupported target families
    - netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
    - gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error
      path
    - soc: ti: k3-ringacc: Fix access mode for
      k3_ringacc_ring_pop_tail_io/proxy
    - soc: fsl: qe: panic on ioremap() failure in qe_reset()
    - selinux: check connect-related permissions on TCP Fast Open
    - selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()
    - selinux: fix incorrect execmem checks on overlayfs
    - leds: uleds: Fix potential buffer overread
    - mfd: sm501: Fix reference leak on failed device registration
    - tools/power/x86/intel-speed-select: Harden daemon pidfile open
    - x86/boot: Validate console=uart8250 baud rate to fix early boot hang
    - x86/boot: Reject too long acpi_rsdp= values
    - perf/x86/amd/brs: Fix kernel address leakage
    - perf/x86/amd/lbr: Fix kernel address leakage
    - cpufreq: schedutil: Fix uncleared need_freq_update on the .adjust_perf()
      path
    - cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF()
    - s390/perf_cpum_cf: Add missing array_index_nospec() to
      __hw_perf_event_init()
    - batman-adv: gw: acquire ethernet header only after skb realloc
    - batman-adv: retrieve ethhdr after potential skb realloc on RX
    - batman-adv: dat: acquire ARP hw source only after skb realloc
    - batman-adv: bla: reacquire gw address after skb realloc
    - batman-adv: dat: ensure accessible eth_hdr proto field
    - batman-adv: ensure minimal ethernet header on TX
    - batman-adv: dat: fix tie-break for candidate selection
    - batman-adv: tt: avoid request storms during pending request
    - batman-adv: fix VLAN priority offset
    - batman-adv: frag: free unfragmentable packet
    - batman-adv: clean untagged VLAN on netdev registration failure
    - batman-adv: frag: fix primary_if leak on failed linearization
    - batman-adv: mcast: avoid OOB read of num_dests header
    - cifs: invalidate cfid on unlink/rename/rmdir
    - mfd: tps6586x: Fix OF node refcount
    - HID: playstation: validate num_touch_reports in DualShock 4 reports
    - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready
    - Bluetooth: SCO: hold sk properly in sco_conn_ready
    - jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit()
    - nvdimm/btt: Free arenas on btt_init() error paths
    - nvdimm/btt: Free arena sub-allocations on discover_arenas() error path
    - lockd: Plug nlm_file leak when nlm_do_fopen() fails
    - lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure
    - remoteproc: qcom: Fix leak when custom dump_segments addition fails
    - MIPS: ip22-gio: fix gio device memory leak
    - MIPS: ip22-gio: fix kfree() of static object
    - MIPS: ip22-gio: fix device reference leak in probe
    - MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf()
    - mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages
    - power: supply: cpcap-battery: Fix missing nvmem_device_put() causing
      reference leak
    - power: supply: max17042: fix OF node reference imbalance
    - mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch
    - mm/memory_hotplug: fix incorrect altmap passing in error path
    - mm/damon/core: make charge_addr_from aware of end-address exclusivity
    - fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename
    - fs/ntfs3: bound DeleteIndexEntryAllocation memmove length
    - fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass
    - fs/ntfs3: bound attr_off in UpdateResidentValue against data_off
    - fs/ntfs3: validate lcns_follow in log_replay conversion
    - fs/ntfs3: bound NTFS_DE view.data_off in
      UpdateRecordData{Root,Allocation}
    - ntfs3: cap RESTART_TABLE free-chain walker at rt->used
    - ntfs3: fix out-of-bounds read in decompress_lznt
    - landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path
    - power: supply: charger-manager: fix refcount leak in is_full_charged()
    - selftests/landlock: Test SCOPE_SIGNAL on the SIGIO/fowner pgid path
    - mips: sched: Fix CPUMASK_OFFSTACK memory corruption
    - riscv: cacheinfo: Fix node reference leak in populate_cache_leaves
    - mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs()
    - mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error
    - fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()
    - fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry()
    - proc: only bump parent nlink when registering directories
    - fs/proc: fix KPF_KSM reported for all anonymous pages
    - powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later
      processors
    - mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE
    - kcov: use WRITE_ONCE() for selftest mode stores
    - mtd: slram: remove failed entries from the device list
    - 9p: skip nlink update in cacheless mode to fix WARN_ON
    - power: supply: bq257xx: Fix VSYSMIN clamping logic
    - scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished()
    - scsi: sas: Skip opt_sectors when DMA reports no real optimization hint
    - openrisc: Add full instruction cache invalidate functions
    - ocfs2: use kzalloc for quota recovery bitmap allocation
    - mtd: rawnand: pl353: fix probe resource allocation
    - net/9p: fix infinite loop in p9_client_rpc on fatal signal
    - mtd: rawnand: fix condition in 'nand_select_target()'
    - ocfs2: avoid moving extents to occupied clusters
    - ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits
    - ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec
    - ocfs2: add journal NULL check in ocfs2_checkpoint_inode()
    - ocfs2: reject dinodes with non-canonical i_mode type
    - ocfs2: reject dinodes whose i_rdev disagrees with the file type
    - ocfs2: reject non-inline dinodes with i_size and zero i_clusters
    - fpga: dfl: add bounds check in dfh_get_param_size()
    - bus: mhi: host: pci_generic: Fix the physical function check
    - bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path
    - net: thunderbolt: Fix frags[] overflow by bounding frame_count
    - fpga: microchip-spi: fix zero header_size OOB read in
      mpf_ops_parse_header()
    - s390/pkey: Check length in PKEY_VERIFYPROTK ioctl
    - s390/pkey: Check length in pkey_pckmo handler implementation
    - mtd: spi-nor: swp: Improve locking user experience
    - mtd: spi-nor: spansion: use die erase for multi-die devices only
    - mtd: rawnand: Pause continuous reads at block boundaries
    - openrisc: Fix jump_label smp syncing
    - mtd: maps: vmu-flash: fix NULL pointer dereference in initialization
    - taskstats: retain dead thread stats in TGID queries
    - irqchip/crossbar: Use correct index in crossbar_domain_free()
    - tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat()
    - tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt
    - sunrpc: fix uninitialized xprt_create_args structure
    - dmaengine: tegra: Fix burst size calculation
    - dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and
      ABORT_INT_MASK
    - platform/x86: dell-laptop: fix missing cleanups in init error path
    - platform/x86: ISST: Restore SST-PP control to all domains
    - platform/x86/amd/pmc: Check for intermediate wakeup in function
    - platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops
    - platform/x86/amd/pmc: Add delay_suspend module parameter
    - platform/x86/amd/pmc: Don't log during intermediate wakeups
    - pkey: Move keytype check from pkey api to handler
    - smb: client: use kvzalloc() for megabyte buffer in simple fallocate
    - ksmbd: fix integer overflow in set_file_allocation_info()
    - hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig
    - hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig
    - i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
    - i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ)
    - i2c: mediatek: fix WRRD for SoCs without auto_restart option
    - i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource()
    - i2c: spacemit: fix spurious IRQ handling returning IRQ_HANDLED
    - ice: fix ice_init_link() error return preventing probe
    - tcp: Decrement tcp_md5_needed static branch
    - ufs: core: tracing: Do not dereference pointers in TP_printk()
    - xen/gntdev: fix error handling in ioctl
    - xfrm: use compat translator only for u64 alignment mismatch
    - xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for
      changelink
    - tpm: fix event_size output in tpm1_binary_bios_measurements_show
    - tpm: Make the TPM character devices non-seekable
    - time: Fix off-by-one in compat settimeofday() usec validation
    - spi: uniphier: Fix completion initialization order before
      devm_request_irq()
    - NFS: Charge unstable writes by request size, not folio size
    - nvme-apple: Prevent shared tags across queues on Apple A11
    - nvmet: fix refcount leak in nvmet_sq_create()
    - netdev-genl: report NAPI thread PID in the caller's pid namespace
    - can: esd_usb: kill anchored URBs before freeing netdevs
    - can: isotp: use unconditional synchronize_rcu() in isotp_release()
    - can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER
    - can: isotp: serialize TX state transitions under so->rx_lock
    - can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF
    - can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure
    - can: bcm: add missing rcu list annotations and operations
    - bpf: Reset register bounds before narrowing retval range in
      check_mem_access()
    - bpf,fork: wipe ->bpf_storage before bailouts that access it
    - bpf: Add missing access_ok call to copy_user_syms
    - block: remove redundant GD_NEED_PART_SCAN in add_disk_final()
    - block: fix race in blk_time_get_ns() returning 0
    - block: fix IORING_URING_CMD_REISSUE flags check in blkdev_uring_cmd
    - net: sparx5: unregister blocking notifier on init failure
    - dm thin metadata: fix superblock refcount leak on snapshot shadow
      failure
    - dm thin metadata: fix metadata snapshot consistency on commit failure
    - dm era: fix out-of-bounds memory access for non-zero start sector
    - dm-bufio: fix wrong count calculation in dm_bufio_issue_discard
    - dm-ioctl: fix a possible overflow in list_version_get_info
    - dm-log: fix a bitset_size overflow on 32bit machines
    - dm-pcache: reject option groups without values
    - dm-stats: fix dm_jiffies_to_msec64
    - dm-stats: fix merge accounting
    - dm_early_create: fix freeing used table on dm_resume failure
    - dm-integrity: fix leaking uninitialized kernel memory
    - dm-integrity: fix a bug if the bio is out of limits
    - dm-integrity: don't increment hash_offset twice
    - dm-verity: avoid double increment of &use_bh_wq_enabled
    - dm-verity: fix a possible NULL pointer dereference
    - dm-verity: increase sprintf buffer size
    - dm-verity: make error counter atomic
    - dma-fence: Make dma_fence_dedup_array() robust against 0-count input
    - accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap()
    - accel/ivpu: Reject firmware log with size smaller than header
    - scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path
    - scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()
    - scsi: sg: Report request-table problems when any status is set
    - scsi: xen: scsiback: Free the command tag on the TMR submit-failure path
    - scsi: elx: efct: Fix refcount leak in efct_hw_io_abort()
    - scsi: elx: efct: Fix I/O leak on unsupported additional CDB
    - Input: ims-pcu - fix use-after-free and double-free in disconnect
    - Input: ims-pcu - only expose sysfs attributes on control interface
    - Input: ims-pcu - release data interface on disconnect
    - Input: ims-pcu - validate control endpoint type
    - Input: ims-pcu - add response length checks
    - Input: ims-pcu - fix DMA mapping violation in line setup
    - Input: ims-pcu - fix firmware leak in async update
    - Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging
    - Input: ims-pcu - fix potential infinite loop in CDC union descriptor
      parsing
    - Input: ims-pcu - fix race condition in reset_device sysfs callback
    - Input: ims-pcu - fix type confusion in CDC union descriptor parsing
    - net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete
    - tracing/user_events: Fix use-after-free in user_event_mm_dup()
    - wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
    - posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()
    - selftests/ftrace: Drop invalid top-level local in test_ownership
    - cpu: hotplug: Preserve per instance callback errors
    - cpu: hotplug: Bound hotplug states sysfs output
    - gpio: mt7621: more robust management of IRQ domain teardown
    - gpio: tegra: do not call pinctrl for GPIO direction
    - gpio: mt7621: be sure IRQ domain is created before exposing GPIO chips
    - gpio-f7188x: Add support for NCT6126D version B
    - gpio: mt7621: avoid corruption of shared interrupt trigger state
    - gpios: palmas: add .get_direction() op
    - net: sit: require CAP_NET_ADMIN in the device netns for changelink
    - net: ethernet: ti: icssg: guard PA stat lookups
    - net: wwan: t7xx: destroy DMA pool on CLDMA late init failure
    - net: ixp4xx_hss: fix duplicate HDLC netdev allocation
    - net/sched: act_ct: preserve tc_skb_cb across defragmentation
    - selftests: net: fix file owner for broadcast_ether_dst test
    - net: ena: clean up XDP TX queues when regular TX setup fails
    - net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
    - net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
    - net: ipip: require CAP_NET_ADMIN in the device netns for changelink
    - net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
    - net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for
      changelink
    - octeontx2-af: Free BPID bitmap on setup failure
    - ieee802154: admin-gate legacy LLSEC dump operations
    - ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation
    - ieee802154: ca8210: fix cas_ctl leak on spi_async failure
    - ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit
    - platform/x86/amd/pmc: Avoid logging "(null)" for DMI values
    - net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants
    - drm/xe/userptr: Stub notifier_lock helpers when DRM_GPUSVM=n
    - pwm: rzg2l-gpt: Fix period_ticks type from u32 to u64
    - LoongArch: Fix nr passing in set_direct_map_valid_noflush()
    - LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()
    - ipmi: Fix user refcount underflow in event delivery
    - ipmi: fix refcount leak in i_ipmi_request()
    - bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()
    - rtc: renesas-rtca3: Fix PIE clear polling condition in alarm setup error
      path
    - rtc: mpfs: fix counter upload completion condition
    - hwmon: (w83627hf) remove VID sysfs files on error and remove
    - hwmon: (w83793) remove vrm sysfs file on probe failure
    - net: liquidio: fix BAR resource leak on PF number failure
    - hwmon: (occ) unregister sysfs devices outside occ lock
    - fsl/fman: Free init resources on KeyGen failure in fman_init()
    - net: lan743x: Initialize eth_syslock spinlock before use
    - net/sched: sch_multiq: Replace direct dequeue call with peek and
      qdisc_dequeue_peeked
    - net/sched: sch_taprio: Replace direct dequeue call with peek and
      qdisc_dequeue_peeked
    - fhandle: reject detached mounts in capable_wrt_mount()
    - hwmon: (max1619) add missing 'select REGMAP' to Kconfig
    - tracing/probes: Fix double addition of offset for @+FOFFSET
    - net/mlx5: HWS, fix matcher leak on resize target setup failure
    - ata: pata_pxa: Fix DMA channel leak on probe error
    - net: wwan: iosm: bound device offsets in the MUX downlink decoder
    - hwmon: (asus_atk0110) Check package count before accessing element
    - riscv: probes: save original sp in rethook trampoline
    - mm/compaction: handle free_pages_prepare() properly in compaction_free()
    - irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure
    - s390/monwriter: Reject buffer reuse with different data length
    - mac802154: remove interfaces with RCU list deletion
    - octeontx2-pf: fix SQB pointer leak on init failure
    - selftests: net: make busywait timeout clock portable
    - llc: fix SAP refcount leak in llc_ui_autobind()
    - ipvs: use parsed transport offset in SCTP state lookup
    - macsec: don't read an unset MAC header in macsec_encrypt()
    - dibs: loopback: validate offset and size in move_data()
    - net: macb: drop in-flight Tx SKBs on close
    - arm64: smp: Fix hot-unplug tearing by forcing unregistration
    - cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable()
    - fs/resctrl: Free mon_data structures on rdt_get_tree() failure
    - fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
    - ata: libata-core: Skip HPA resize for locked drives
    - ata: libata-core: Allow capacity transition to zero for locked drives
    - riscv: Prevent NULL pointer dereference in machine_kexec_prepare()
    - tracing/osnoise: Call synchronize_rcu() when unregistering
    - s390/diag: Add missing array_index_nospec() call to
      memtop_get_page_count()
    - s390/mm: Fix type mismatch in get_align_mask().
    - selftests/rseq: Fix a building error for riscv arch
    - cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed
    - pmdomain: imx: Fix i.MX8MP power notifier
    - pmdomain: imx: Fix i.MX8MP VC8000E power up sequence
    - selftests/landlock: Skip scoped_signal subtest with MSG_OOB if not
      available
    - selftests/landlock: Fix screwed up pointers in the scoped_signal_test
    - mmc: sdhci-esdhc-imx: restore pinctrl before restoring ios timing on
      resume
    - powerpc/pseries: fix memory leak on krealloc failure in papr_init
    - net/mlx5: free mlx5_st_idx_data on final dealloc
    - wifi: rt2x00: avoid full teardown before work setup in probe
    - wifi: mwifiex: fix roaming to different channel in host_mlme mode
    - wifi: mac80211: fix memory leak in ieee80211_register_hw()
    - wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
    - riscv: vdso: Do not use LTO for the vDSO
    - regulator: ltc3676: Fix incorrect IRQSTAT bit offsets
    - Bluetooth: btrtl: validate firmware patch bounds
    - llc: fix SAP refcount leak when creating incoming sockets
    - macsec: fix promiscuity refcount leak in macsec_dev_open()
    - memstick: ms_block: reject a card that reports too many blocks
    - reset: sunxi: fix memory region leak on ioremap failure
    - powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()
    - wifi: cfg80211: validate EHT MLE before MLD ID read
    - wifi: ieee80211: validate MLE common info length
    - wifi: mac80211: free ack status frame on TX header build failure
    - wifi: mwifiex: fix permanently busy scans after multiple roam iterations
    - mtd: onenand: samsung: report DMA completion timeouts
    - mtd: mchp23k256: use SPI match data for chip caps
    - mmc: vub300: defer reset until cmd_mutex is unlocked
    - mtd: rawnand: fsl_ifc: return errors for failed page reads
    - mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout
    - mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout
    - mmc: block: fix RPMB device unregister ordering
    - mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe()
      method
    - mmc: sdhci-esdhc-imx: remove unnecessary mmc_card_wake_sdio_irq check
      for tuning save/restore
    - mmc: sdhci-esdhc-imx: restore DLL override for DDR modes on resume
    - mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state
      restore
    - mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled
      interrupt
    - mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend
    - mmc: sdhci-esdhc-imx: make non-fatal errors non-blocking in suspend
    - mmc: sdhci-esdhc-imx: fix resume error handling
    - crypto: xilinx-trng - Remove crypto_rng interface
    - ACPI: bus: Introduce devm_acpi_install_notify_handler()
    - ACPI: NFIT: core: Use devm_acpi_install_notify_handler()
    - ACPI: NFIT: core: Fix possible deadlock and missing notifications
    - iio: hid-sensor-rotation: Fix stale or zero output when reading raw
      values
    - ALSA: scarlett2: Allow selecting config_set by firmware version
    - ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417
    - firmware_loader: Add cancel helper for async requests
    - ALSA: hda/tas2781: Cancel async firmware request at unbind
    - binder: Use LIST_HEAD() to initialize on stack list head
    - binder: cache secctx size before release zeroes it
    - staging: rtl8723bs: fix spaces around binary operators
    - Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister
    - Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()
    - proc: rename proc_setattr to proc_nochmod_setattr
    - usb: dwc3: Support USB3340x ULPI PHY high-speed negotiation.
    - usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()
    - usb: atm: ueagle-atm: use dev_dbg() for 'device found' message
    - usb: atm: ueagle-atm: remove function entry/exit debug messages
    - usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()
    - btrfs: remove folio parameter from ordered io related functions
    - KVM: arm64: Ensure level is always initialized when relaxing perms
    - KVM: arm64: Fix propagation of TLBI level in
      kvm_pgtable_stage2_relax_perms()
    - mm/damon/core: always put unsuccessfully committed target pids
    - mm/damon/core: trace esz at first setup
    - samples/damon/mtier: fail early if address range parameters are invalid
    - perf callchain: Handle multiple address spaces
    - soc: fsl: qe_ports_ic: Add missing cleanup on device removal
    - drm/rockchip: inno-hdmi: Switch to drmm_kzalloc()
    - accel/amdxdna: Create shared functions for AIE2 and AIE4
    - Revert "UBUNTU: SAUCE: accel/amdxdna: Support sensors for column
      utilization"
    - accel/amdxdna: Support sensors for column utilization
    - accel/amdxdna: Adjust size for copy_to_user()
    - accel/amdxdna: Handle DETACH_DEBUG_BO through config_debug_bo path
    - accel/amdxdna: Fix order of canceled mailbox messages
    - accel/amdxdna: Guard management mailbox channel cleanup against NULL
      pointer
    - drm/amdkfd: fix redundant MQD iterations in GFX v12.1
    - wifi: ath12k: Fix invalid IRQ requests during AHB probe
    - libbpf: Fix deduplication of typedef with base definitions
    - spi: atcspi200: Use helper function devm_clk_get_enabled()
    - spi: atcspi200: fix use-after-free when driver unbind
    - arm64: dts: rockchip: Fix vdec register blocks order on RK3576
    - arm64: dts: rockchip: Update vdec register blocks order on RK3588
    - dt-bindings: net: bluetooth: qualcomm: Fix WCN6855 regulator names
    - x86/bug: Add printf() validation to HAVE_ARCH_BUG_FORMAT_ARGS WARNs
    - arm64: dts: qcom: milos: Reduce rmtfs_mem size to 2.5MiB
    - arm64: dts: qcom: sdm845-oneplus: Drop address from framebuffer node
    - arm64: dts: qcom: sdm845-shift-axolotl: Correct touchscreen sleep state
    - soc: xilinx: Fix race condition in event registration
    - wifi: ath11k: cancel SSR work items during PCI shutdown
    - ixgbe: fix unaligned u32 access in ixgbe_update_flash_X550()
    - objtool/klp: Fix is_uncorrelated_static_local() for Clang
    - objtool/klp: Fix .data..once static local non-correlation
    - objtool/klp: Fix create_fake_symbols() skipping entsize-based sections
    - objtool/klp: Fix handling of zero-length .altinstr_replacement sections
    - objtool/klp: Fix cloning of zero-length section symbols
    - objtool/klp: Fix extraction of text annotations for alternatives
    - objtool/klp: Fix relocation conversion failures for R_X86_64_NONE
    - objtool/klp: Use sym->demangled_name for symbol_name hash
    - objtool/klp: Match symbols based on demangled_name for global variables
    - objtool: Replace iterator callback with for_each_sym_by_mangled_name()
    - objtool: Fix reloc hash collision in find_reloc_by_dest_range()
    - klp-build: Fix hang on out-of-date .config
    - klp-build: Fix checksum comparison for changed offsets
    - riscv: dts: microchip: gpio controllers on mpfs need 2 interrupt cells
    - riscv: dts: microchip: remove gpio hogs from beaglev-fire
    - wifi: cfg80211: restrict LMR feedback check to TB and non-TB ranging
    - drm/panel: Clean up SOFEF00 config dependencies
    - drm/panel: Clean up S6E3FC2X01 config dependencies
    - arm64: dts: marvell: samsung-coreprimevelte: Increase touchscreen
      voltage
    - arm64: dts: imx8mn-vhip4-evalboard-v1: Correct interrupt flags
    - arm64: dts: imx8mn-vhip4-evalboard-v2: Correct interrupt flags
    - crypto: ccp - Check for page allocation failure correctly in TIO
    - crypto: ccp - Initialize data during __sev_snp_init_locked()
    - accel/amdxdna: Fix clflush buffer size
    - ntb: Store original DMA address for future release
    - ntb: Use consistent DMA attributes when freeing DMA mappings
    - riscv: dts: spacemit: k3: add clock tree
    - dts: riscv: spacemit: correct 32k clock frequency
    - arm64: dts: qcom: sdm660: set cdsp compute-cbs' regs properly
    - arm64: dts: qcom: sdm630: set adsp compute-cbs' regs properly
    - arm64: dts: qcom: lemans: Move PCIe devices into soc node
    - sockptr: fix usize check in copy_struct_from_sockptr() for user pointers
    - arm64: dts: mediatek: mt7988a-bpi-r4pro: rework pcie gpio-hog handling
    - rhashtable: give each instance its own lockdep class
    - thermal: hwmon: Register a hwmon device for each thermal zone
    - crypto: ccp/sev-dev-tsm - bail out early when pdev->bus is NULL
    - crypto: safexcel - Fix potential memory leak in safexcel_pci_probe()
    - net/sched: add qdisc_qlen_inc() and qdisc_qlen_dec()
    - net/sched: sch_dualpi2: annotate data-races in dualpi2_dump_stats()
    - tools/rtla: Fix --dump-tasks usage in timerlat
    - rtla: Stop the record trace on interrupt
    - dm: limit target bio polling to one shot
    - selftests/bpf: Override EXTRA_LDFLAGS for static builds
    - sched/fair: Update util_est after updating util_avg during dequeue
    - hfs: fix incorrect inode ID assignment in hfs_new_inode()
    - vfio: selftests: Fix out-of-tree build with make O=
    - vfio: selftests: Allow builds when ARCH=x86
    - vfio/xe: avoid duplicate reset in xe_vfio_pci_reset_done
    - arm64: dts: qcom: kaanapali: Add power-domain and iface clk for ice node
    - arm64: dts: qcom: sdm845-xiaomi-beryllium: Correct IPA FW path
    - ASoC: mediatek: mt8189: Fix probe resource cleanup
    - drm/msm/mdss: correct UBWC programming sequences
    - tools/nolibc: stackprotector: Avoid stalling program startup if crng is
      not init yet
    - ASoC: dapm: Fix widget lookup with prefixed names across DAPM contexts
    - ACPI: PAD: Fix teardown ordering in acpi_pad_remove()
    - wifi: ath12k: fix error unwind on arch_init() failure in PCI probe
    - cpufreq: governor: Fix data races on per-CPU idle/nice baselines
    - cpufreq: governor: Fix stale prev_cpu_nice spike when enabling
      ignore_nice_load
    - dt-bindings: vendor-prefixes: Add Verbatim Corporation
    - drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info
    - rust: devres: add 'static bound to Devres<T>
    - lib/base64: validate before writing in decode tail path
    - rust: uaccess: use INLINE_COPY_TO_USER to guard copy_to_user()
    - uaccess: unify inline vs outline copy_{from,to}_user() selection
    - uaccess: minimize INLINE_COPY_USER-related ifdefery
    - crypto: ccp/tsm - Enable the root port after the endpoint
    - firmware: samsung: acpm: Add devm_acpm_get_by_phandle helper
    - firmware: samsung: acpm: remove compile-testing stubs
    - drm/msm/a8xx: Make a8xx_recover IFPC safe
    - drm/msm/a8xx: Fix RSCC offset
    - EDAC/igen6: Fix memory topology parsing for Panther Lake-H SoCs
    - arm: dts: bcm2711: Fix typo in gpio-line-names
    - arm64: dts: renesas: r8a78000: Fix GIC-720AE View 1 Redistributor
      description
    - arm64: dts: renesas: ironhide: Describe all reserved memory
    - md: replace wait loop with wait_event() in md_handle_request()
    - md/raid1,raid10: fix deadlock in read error recovery path
    - md/raid1,raid10: fix error-path detection with md_cloned_bio()
    - md/raid1,raid10: fix bio accounting for split md cloned bios
    - liveupdate: Use refcount_t for FLB reference counts
    - liveupdate: Reference count incoming FLB data
    - liveupdate: skip serialization for context-preserving kexec
    - liveupdate: fix TOCTOU race in luo_session_retrieve()
    - liveupdate: block session mutations during reboot
    - spi: imx: replace dmaengine_terminate_all() with
      dmaengine_terminate_sync()
    - wifi: ath12k: fix memory leak in ath12k_wifi7_dp_rx_h_verify_tkip_mic()
    - wifi: ath12k: fix inconsistent arvif state in vdev_create error paths
    - ACPI: button: Fix lid_device value leak past driver removal
    - drm/amd/pm: Add empty string validation to sysfs store functions
    - accel/amdxdna: Return errors for failed debug BO commands
    - mm: preserve PG_dropbehind flag during folio split
    - perf/x86/intel/uncore: Fix PCI device refcount leak in UPI discovery
    - wifi: wlcore: enable the right set of ciphers
    - cxl/test: Fix __fortify_panic
    - bpf: Take mmap_lock in zap_pages()
    - ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent
    - cxl/pci: Fix the incorrect check of pci_read_config_word() return
    - cxl/pci: Convert PCIBIOS errors to errno on DVSEC config accesses
    - netfilter: cttimeout: detach dataplane timeout policy and repurpose
      refcount
    - arm64: dts: imx94: fix DDR PMU interrupt number
    - arm64: dts: freescale: fsl-ls1028a-tqmls1028a-mbls1028a: switch mmc
      aliases
    - selftests/bpf: Fix flaky file_reader test
    - riscv: alternative: Use IS_ENABLED() over ifdeffery for
      apply_vdso_alternatives()
    - riscv: alternative: Pass vDSO start as parameter to
      apply_vdso_alternatives()
    - riscv: alternative: Also patch the CFI vDSO
    - bpf: Verifier support for sleepable tracepoint programs
    - bpf: Reject sleepable BPF_LSM_CGROUP programs at load time
    - netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag
    - filelock: fix break_lease() stub signature for CONFIG_FILE_LOCKING=n
    - wifi: mac80211: bound S1G TIM PVB walk to the TIM element
    - ACPI: processor: Add cpuidle driver check in
      acpi_processor_register_idle_driver()
    - RDMA/nldev: Fix locking when accessing mr->pd
    - scsi: ufs: core: Handle PM commands timeout before SCSI EH
    - iommufd: Destroy the pages content after detaching from dmabuf
    - lib/test_hmm: fix memory leak in dmirror_migrate_to_system()
    - rust: kbuild: show the right `quiet_cmd_rustc_procmacrolibrary`
    - remoteproc: qcom_q6v5_wcss: drop redundant wcss_q6_bcr_reset
    - wifi: mt76: mt7996: remove redundant pdev->bus check in probe
    - wifi: ath12k: fix EAPOL TX failure caused by stale tcl_metadata bits
    - memory: tegra186-emc: stop borrowing MC aggregate hook for EMC
    - PM: QoS: Fix misc device registration unwind
    - btrfs: lzo: reject compressed segment that overflows the compressed
      input
    - ixgbe: do not configure xps for XDP queues
    - bpf: Cancel special fields on map value recycle
    - clocksource: move NXP timer selection to drivers/clocksource
    - [Config] Allow certain NXP timer selections for arm64
    - vduse: fix compat handling for VDUSE_IOTLB_GET_FD/VDUSE_VQ_GET_INFO
    - iomap: pass the correct len to fserror_report_io in __iomap_write_begin
    - ASoC: cs35l56: Prevent double-free of debugfs
    - ASoC: cs35l56: Cleanup if component_probe fails
    - hwmon: (gpd-fan): drop global driver data and use per-device allocation
    - hwmon: (gpd-fan): Initialize EC before registering hwmon device
    - hwmon: (gpd-fan): fix race condition between device removal and sysfs
      access
    - ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT
    - cxl/test: Verify cmd->size_in before accessing payload
    - m68k: mcf5441x: fix clocks numbering
    - pinctrl: airoha: an7583: add missed gpio32 pin group
    - pinctrl: airoha: an7583: fix misprint in gpio19 pinconf
    - pinctrl: airoha: an7581: fix incorrect led mapping in phy4_led1 pin
      function
    - pinctrl: airoha: an7583: fix incorrect led mapping in phy4_led1 pin
      function
    - pinctrl: airoha: fix pwm pin function for an7581 and an7583
    - pinctrl: airoha: an7583: fix gpio21 pin group
    - pinctrl: airoha: an7583: add missed gpio22 pin group
    - pinctrl: airoha: an7583: fix phy1_led1 pin function
    - pinctrl: airoha: an7583: remove undefined groups from pcm_spi pin
      function
    - Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-
      serdev device
    - Bluetooth: btintel: Replace CNVi id with hardware variant
    - Bluetooth: btintel: Add DSBR support for ScP2 onwards
    - Bluetooth: btintel_pcie: Load IOSF debug regs by controller variant
    - ASoC: cs35l56: Fix wrong error test on simple_write_to_buffer()
    - ASoC: SOF: Intel: select SND_SOC_SDW_UTILS=y from
      SND_SOC_SOF_HDA_GENERIC=y
    - ASoC: meson: aiu: Validate written enum values
    - ASoC: topology: Check PCM and DAI name strings before use
    - ipv4: fib: Don't dump dying fib_info in fib_leaf_notify().
    - iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path
    - iommufd: Clarify IOAS_MAP_FILE dma-buf support
    - cxl/region: Fill first free targets[] slot during auto-discovery
    - vfio: selftests: Ensure libvfio output dirs are always created
    - cxl/region: Block region delete during region creation
    - cxl/region: Resolve region deletion races
    - cxl/memdev: Pin parents for entire memdev lifetime
    - net: airoha: Fix error handling in airoha_ppe_flush_sram_entries()
    - netfilter: nft_fwd_netdev: use recursion counter in neigh egress path
    - netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use
      them
    - geneve: Fix off-by-one comparing with GRO_LEGACY_MAX_SIZE
    - smb: client: fix conflicting option validation for new mount API
    - btrfs: Drop WQ_PERCPU from ordered_flags in btrfs_init_workqueues()
    - bpf: Guard __get_user acesss with access_ok for uprobe_multi data
    - net: ti: icssg-prueth: Fix AF_XDP fill ring alloc and wakeup condition
    - net: ti: icssg: Use undirected TX tag for native XDP in HSR offload mode
    - net: ti: icssg: Use undirected TX tag for XDP zero copy in HSR offload
      mode
    - RDMA/bnxt_re: Free CQ toggle page after firmware teardown
    - RDMA/bnxt_re: Reject GET_TOGGLE_MEM when toggle page was not allocated
    - RDMA/hns: Fix memory leak of bonding resources
    - mfd: bd72720: Drop BUCK11 ID
    - 9p: Add missing read barrier in virtio zero-copy path
    - perf dwarf-aux: Fix libdw segmentation fault in cu_walk_functions_at
    - perf dwarf-aux: Fix libdw API contract violations
    - perf srcline: Introduce inline_node__clear_frames()
    - perf libdw: Fix libdw API contract violations and memory leaks
    - perf probe-finder: Fix libdw API contract violations
    - perf annotate-data: Fix libdw API contract violations
    - coresight: tmc: Fix overflow when calculating is bigger than 2GiB
    - perf tool: Fix missing schedstat delegates and dont_split_sample_group
      in delegate_tool
    - PCI: intel-gw: Move interrupt enable to own function
    - PCI: intel-gw: Enable clock before PHY init
    - PCI: intel-gw: Add .start_link() callback
    - bus: mhi: ep: Add missing state_lock protection for mhi_state access
    - PCI: dwc: Apply ECRC workaround for DesignWare cores prior to 5.10a
    - PCI: qcom: Set max OPP before DBI access during resume
    - perf pmu-events AMD: Switch l2_itlb_misses to
      bp_l1_tlb_miss_l2_tlb_miss.all
    - perf unwind: Refactor get_entries to allow dynamic libdw/libunwind
      selection
    - coresight: Handle helper enable failure properly
    - mailbox: don't free the channel if the startup callback failed
    - PCI/pwrctrl: Lock device when calling device_is_bound()
    - coresight: platform: defer connection counter increment until alloc
      succeeds
    - platform/x86: classmate-laptop: Address memory leaks on driver removal
    - clk: microchip: mpfs-ccc: fix peripheral driver registration failures
      after oob fix
    - perf sample: Add evsel to struct perf_sample
    - perf event: Fix size of synthesized sample with branch stacks
    - perf inject: Fix itrace branch stack synthesis
    - gpib: cb7210: Fix region leak when request_irq fails
    - timers/migration: Update stale @online doc to @available
    - clk: spacemit: k3: Switch to pll2_d6 as parent for PCIe clock
    - clk: spacemit: k3: Fix PCIe clock register offset
    - fs/ntfs3: fix wrong LCN in run_remove_range() when splitting a run
    - ntfs3: Allocate iomap inline_data using alloc_page
    - perf sample: Add file_offset field to struct perf_sample
    - perf sched: Replace BUG_ON on invalid CPU with graceful skip
    - perf sched: Fix NULL dereference in latency_runtime_event
    - perf sched: Fix comp_cpus heap overflow with cross-machine recordings
    - perf tools: Guard remaining test_bit calls from OOB sample CPU
    - perf sched: Fix thread reference leaks in timehist_get_thread()
    - perf sched: Use is_idle_sample() for idle thread runtime cast guard
    - perf sched: Fix thread reference leak in idle hist processing
    - perf sched: Free callchain nodes in idle thread cleanup
    - docs: memfd_preservation: fix rendering of ABI documentation
    - virtio: add missing kernel-doc for map and vmap members
    - fs/ntfs3: prevent potential lcn remains uninitialized
    - perf tools: NULL bitmap pointers after bitmap_free()
    - perf tools: Use scnprintf() in build_id__snprintf() and hwmon
      read_events()
    - perf data convert json: Fix addr_location leak on time-filtered samples
    - perf tools: Use mkostemp() for O_CLOEXEC on temporary files
    - phy: freescale: phy-fsl-imx8qm-lvds-phy: Use synchronous PM runtime put
      in reset
    - sparc: Avoid -Wunused-but-set-parameter in clear_user_page()
    - apparmor: release exe file resources on path failure
    - apparmor: remove unnecessary goto and associated label
    - apparmor: Fix inverted comparison in cache_hold_inc()
    - i3c: mipi-i3c-hci: Fix suspend behavior when bus disable falls back to
      software reset
    - i3c: master: Serialize i3c_set_hotjoin() with the maintenance lock
    - i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev()
    - perf maps: Add maps__mutate_mapping
    - perf c2c: Free format list entries when releasing c2c hist entries
    - regcache: Do not overwrite error code when finalizing cache after error
    - erofs: call erofs_exit_ishare() before rcu_barrier()
    - perf c2c: Free format list entries when c2c_hists__init() fails
    - perf c2c: Fix hist entry and format list leaks in c2c_he_free()
    - drm/amd/display: Skip PHY SSC reduction on some 8K panels
    - net: ethernet: mtk_eth_soc: fix supported_interface set after
      phylink_create
    - selftests/ftrace: Fix trace_marker_raw test on 64K page kernels
    - octeontx2-af: npc: Log successful MCAM drop-on-non-hit install at debug
      level
    - netconsole: don't drop the last byte of a full-sized message
    - eth: fbnic: take netif_addr_lock_bh() around rx mode address programming
    - arm64: static_call: include asm/insns.h
    - md/raid1: fix writes_pending and barrier reference leaks on write
      failures
    - md/raid10: fix writes_pending leak on write request failures
    - md/raid10: fix writes_pending and barrier reference leaks on discard
      failures
    - netfilter: ipset: Don't use test_bit() in lockless RCU readers in bitmap
      types
    - selftests/mm: fix hugetlb pathname construction in
      charge_reserved_hugetlb.sh
    - selftests/mm: run_vmtests.sh: free memory if available memory is low
    - selftests/mm: move hwpoison setup into run_test() and silence modprobe
      output for memory-failure category
    - selftests/mm: remove hardcoded THP sizing assumptions in hmm tests
    - net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone
    - bpf: Fix partial copy of non-linear test_run output
    - bpf: Fix BPF_PROG_ASSOC_STRUCT_OPS last field check
    - erofs: handle 48-bit blocks_hi for compressed inodes
    - ASoC: cs530x: Fix expected MCLK rates for CS5302/4/8
    - PCI: endpoint: pci-epf-vntb: Document legacy MSI doorbell offset
    - PCI: endpoint: pci-epf-vntb: Defer pci_epc_raise_irq() out of atomic
      context
    - PCI: endpoint: pci-epf-vntb: Report 0-based doorbell vector via
      ntb_db_event()
    - e1000e: Reconfigure PLL clock gate timeout and re-enable K1 on Meteor
      Lake
    - bpf: Guard conntrack opts error writes
    - selftests/bpf: Cover small conntrack opts error writes
    - netfilter: nf_conntrack_helper: dynamically allocate struct
      nf_conntrack_helper
    - netfilter: nf_conntrack_pptp: move GRE specific cleanup to GRE tracker
    - netfilter: nf_conntrack_gre: fix gre keymap list corruption
    - netfilter: conntrack: check NULL when retrieving ct extension
    - netfilter: nf_conntrack_expect: use conntrack GC to reap expectations
    - netfilter: nf_conntrack_expect: store master_tuple in expectation
    - netfilter: nf_conntrack_expect: run expectation eviction with no helper
    - netfilter: nft_ct: expectation timeouts are passed in milliseconds
    - netfilter: nf_conntrack_helper: cap maximum number of expectation at
      helper registration
    - cpuidle: Allow exit latency to exceed target residency
    - ASoC: SDCA: Validate written enum value in ge_put_enum_double()
    - ASoC: rt5575: Use __le32 for SPI burst write address
    - PCI: endpoint: pci-epf-vntb: Exclude reserved slots from db_valid_mask
    - net: ti: icssg: Fix XSK zero copy TX during application wakeup
    - net: lwtunnel: Drop skb metadata before LWT encapsulation
    - sctp: fix err_chunk memory leaks in INIT handling
    - net: dsa: mxl862xx: avoid unaligned 16-bit access in api_wrap
    - octeontx2-af: fix CGX debugfs RVU AF PCI reference leaks
    - geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
    - geneve: validate inner network offset in geneve_gro_complete()
    - tools: ynl: build archives with $(AR)
    - net: enetc: fix potential divide-by-zero when num_vsi is zero
    - udp_tunnel: Pass struct sock to setup_udp_tunnel_sock().
    - tipc: avoid busy looping in tipc_exit_net()
    - bpf: Mask pseudo pointer values in verifier logs
    - bpf: Fix insn_aux_data leak on verifier err_free_env path
    - hwmon: (pmbus/core) Add support for NVIDIA nvidia195mv mode
    - hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid()
    - gpio: shared-proxy: always serialize with a sleeping mutex
    - drm/panthor: Always use the IRQ-safe variant when acquiring the fence
      lock
    - drm/panthor: Keep the reset work disabled until everything is
      initialized
    - drm/panthor: Fix panthor_pwr_unplug()
    - spi: rzv2h-rspi: Fix DMA transfer error handling for signal interruption
    - xen/pvcalls: bound backend response req_id before indexing rsp[]
    - afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints
    - afs: Fix directory inode initialisation order
    - afs: Use scoped_seqlock_read() rather than manually doing seqlock stuff
    - afs: Fix leak of ungot volume
    - iomap: release pages on atomic dio size mismatch
    - cachefiles: Fix double unlock in nomem_d_alloc error path
    - cachefiles: Fix file burial to take lock when unsetting S_KERNEL_FILE
    - drm/imagination: Fix returned size for DRM_IOCTL_PVR_DEV_QUERY
    - iio: dac: mcp47feb02: Fix passing uninitialized vref1_uV for no Vref1
      case
    - net/mlx5: LAG, replace pf array with xarray
    - net/mlx5: LAG, use xa_alloc to manage LAG device indices
    - net/mlx5: Lag: refactor representor reload handling
    - net/mlx5: E-Switch, add representor lifecycle lock
    - net/mlx5: Lag, avoid LAG and representor lock cycles
    - net/mlx5: LAG, factor out shared FDB code into dedicated file
    - net/mlx5: LAG, replace peer count check with direct peer lookup
    - net/mlx5: LAG, prepare for SD device integration
    - net/mlx5: LAG, replace mlx5_get_dev_index with LAG sequence number
    - net/mlx5: LAG, extend shared FDB API with group_id filter
    - net/mlx5: LAG, Fix off-by-one in single-FDB error rollback
    - ksmbd: fix multichannel binding and enforce channel limit
    - smb: client: preserve leading slash for POSIX absolute symlink targets
    - gpio: shared: make the voting mechanism adaptable
    - drm/i915/ltphy: Fix SSC Enablement bit in PORT_CLOCK_CTL
    - Bluetooth: 6lowpan: avoid untracked enable work
    - Bluetooth: btintel_pcie: Support Product level reset
    - [Config] Make BT_INTEL_PCIE depend on ACPI
    - Bluetooth: btintel_pcie: Add support for smart trigger dump
    - Bluetooth: btintel_pcie: Separate coredump work from RX work
    - Bluetooth: btintel_pcie: Refactor FLR to use device_reprobe()
    - Bluetooth: ISO: fix malformed ISO_END/CONT handling
    - accel/amdxdna: Prevent PM resume deadlock in hwctx_sync_debug_bo()
    - accel/amdxdna: Fix VMA access race
    - net: rnpgbe: fix mailbox endianness and remove pointer casts
    - drm: Guard DRM_CLIENT_CAP_PLANE_COLOR_PIPELINE
    - smb: client: fix busy dentry warning on unmount after DIO
    - drm/fb-helper: Only consider active CRTCs for vblank sync
    - ethtool: rss: Fix hfunc and input_xfrm parsing on big endian
    - drm/imagination: make pvr_fw_trace_init_mask_ops static
    - VDUSE: avoid leaking information to userspace
    - ASoC: SOF: ipc4-control: Validate notification payload size
    - arm64: dts: renesas: ironhide: Describe inline ECC carveouts
    - arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers
    - KVM: s390: vsie: Fix allocation of struct vsie_rmap
    - KVM: s390: vsie: Add missing radix_tree_preload() in
      _gaccess_shadow_fault()
    - KVM: s390: Add some useful mask macros
    - KVM: s390: vsie: Fix rmap handling in _do_shadow_crste()
    - KVM: s390: vsie: Fix redundant rmap entries
    - KVM: s390: vsie: Use mmu cache to allocate rmap
    - KVM: s390: Initialize KVM_S390_GET_CMMA_BITS memory
    - KVM: TDX: Reject concurrent change to CPUID entry count
    - ASoC: SOF: topology: fix memory leak in snd_sof_load_topology
    - netfilter: nft_fib: reject fib expression on the netdev egress hook
    - netfilter: nf_conntrack_sip: remove net variable shadowing
    - netfilter: nf_conntrack_sip: validate skb_dst() before accessing it
    - gpu/buddy: bail out of try_harder when alignment cannot be honoured
    - backlight: ktd2801: Enable BL_CORE_SUSPENDRESUME
    - cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size
    - pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP
    - remoteproc: xlnx: Check remote core state
    - mm/sparse-vmemmap: fix vmemmap accounting underflow
    - mm/huge_memory: preserve pmd_swp_uffd_wp on device-private PMD downgrade
    - fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race
    - fs/proc/task_mmu: do not warn on seeing non-migration pmd entry
    - kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES
    - mtd: maps: vmu-flash: fix fault in unaligned fixup
    - dmaengine: dw-edma-pcie: Reject devices without driver data
    - dmaengine: sh: rz-dmac: Move interrupt request after everything is set
      up
    - platform/x86: hp-wmi: Add support for Omen 16-ap0xxx (8D26)
    - platform/x86: hp-wmi: Add support for Omen 16-ap0xxx (8E35)
    - spi: imx: reconfigure for PIO when DMA cannot be started
    - ovl: use linked upper dentry in copy-up tmpfile
    - can: bcm: add locking when updating filter and timer values
    - can: bcm: extend bcm_tx_lock usage for data and timer updates
    - can: bcm: fix CAN frame rx/tx statistics
    - can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()
    - can: bcm: fix stale rx/tx ops after device removal
    - can: bcm: track a single source interface for ANYDEV timeout/throttle
      ops
    - can: bcm: validate frame length in bcm_rx_setup() for RTR replies
    - can: bcm: add missing device refcount for CAN filter removal
    - selftests/bpf: Cover negative buffer pointer offsets
    - dm: avoid leaking the caller's thread keyring via the table device file
    - dma-buf: protected fence ops by RCU v8
    - dma-fence: use correct callback in dma_fence_timeline_name()
    - accel/amdxdna: reject command submission on devices without a submit op
    - accel/amdxdna: reject user command submission without a command BO
    - accel/amdxdna: Use caller client for debug BO sync
    - fs/resctrl: Fix use-after-free during unmount
    - mmc: vub300: fix use-after-free on probe failure
    - octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF
    - ksmbd: fix stack buffer overflow in multichannel session-key copy
    - netfilter: nfnetlink_cthelper: cap to maximum number of expectation per
      master
    - netfilter: nfnetlink_cthelper: cap to maximum number of expectation per
      master on updates
    - riscv: vdso: Always declare vdso_start symbols
    - ata: libata-core: Add NOLPM quirk for PNY CS900 1TB SSD
    - ata: libata-core: Reject an invalid concurrent positioning ranges count
    - net: ipa: fix SMEM state handle leaks in SMP2P init
    - amdkfd: properly free secondary context id
    - pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI
    - pmdomain: mediatek: Fix possible nullptr KP in HWV cleanup/on-check
    - arch/riscv: vdso: remove CFI landing pad from rt_sigreturn
    - reset: imx7: Correct polarity of MIPI CSI resets on i.MX8MQ
    - powerpc/uaccess: correct check for CONFIG_PPC_E500 in
      mask_user_address()
    - wifi: mac80211: validate extension-frame layout before RX
    - xfs: factor out a xfs_zone_mark_free helper
    - xfs: add newly added RTGs to the free pool in growfs
    - liveupdate: validate session type before performing operation
    - posix-timers: Expand timer_[re]arm() callbacks with a boolean return
      value
    - posix-cpu-timers: Prevent UAF caused by non-leader exec() race
    - Revert "gpib: cb7210: Fix region leak when request_irq fails"
    - Upstream stable to v6.18.40, v7.1.5
  * Resolute update: upstream stable patchset 2026-08-20 (LP: #2164666) //
    CVE-2023-20585
    - iommu/amd: Use maximum Event log buffer size when SNP is enabled on
      Family 0x19
    - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family
      0x19
  * [Regression] Laptop fails to power off completely when HDMI is connected
    in kernel 7.0.0-28 (LP: #2163121) // CVE-2026-68364
    - drm/amd/display: fix NULL ptr deref in ISM delayed work
    - drm/amd/display: Fix ISM teardown crash from NULL dc dereference
    - drm/amd/display: Fix ISM dc_lock deadlock during suspend
  * CVE-2026-72064
    - net: mana: Sync page pool RX frags for CPU
  * CVE-2026-72065
    - net: mana: Validate the packet length reported by the NIC
  * CVE-2026-72098
    - dm-verity-fec: replace {MAX,MIN}_RSN with {MIN,MAX}_ROOTS
    - dm-verity: fix buffer overflow in FEC calculation
  * CVE-2026-72248
    - netfilter: flowtable: support IPIP tunnel with direct xmit
    - netfilter: flowtable: use correct direction to set up tunnel route
  * CVE-2026-72249
    - netfilter: flowtable: use dst in this direction when pushing IPIP header
  * CVE-2026-72287
    - KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal"
      checks
  * CVE-2026-72329
    - net/liquidio: drop cached VF pci_dev LUT
  * CVE-2026-72355
    - netfs: Fix barriering when walking subrequest list
  * CVE-2026-72412
    - s390/mm: Fix handling of _PAGE_UNUSED pte bit
  * CVE-2026-72417
    - netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()
  * CVE-2026-72442
    - netfilter: flowtable: fix and simplify IP6IP6 tunnel handling
  * CVE-2026-72463
    - xfrm: Fix dev use-after-free in xfrm async resumption
  * CVE-2026-72477
    - fs/ntfs3: call _ntfs_bad_inode() when failing to rename
  * CVE-2026-72493
    - net: serialize netif_running() check in enqueue_to_backlog()
  * CVE-2026-72494
    - RDMA/irdma: Replace waitqueue and flag with completion
  * CVE-2026-72496
    - RDMA/bnxt_re: Proper rollback if the ioremap fails
  * CVE-2026-74269
    - bnxt: fix head underflow on XDP head-grow
  * CVE-2026-74350
    - ocfs2: validate fast symlink target during inode read
  * CVE-2026-72495
    - RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
  * CVE-2026-72501
    - RDMA/bnxt_re: Initialize dpi variable to zero
  * CVE-2026-72278
    - KVM: arm64: nv: Re-translate VNCR before injecting abort
  * CVE-2026-68083
    - ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
  * CVE-2026-68457
    - ksmbd: use opener credentials for FSCTL mutations
  * CVE-2026-68476
    - ipvs: reload ip header after head reallocation
  * CVE-2026-68477
    - ipvs: fix more places with wrong ipv6 transport offsets
  * CVE-2026-72014
    - drbd: reject data replies with an out-of-range payload size
  * CVE-2026-72020
    - ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
  * CVE-2026-72033
    - orangefs: keep the readdir entry size 64-bit in fill_from_part()
  * CVE-2026-72041
    - espintcp: use sk_msg_free_partial to fix partial send
  * CVE-2026-72046
    - gve: fix header buffer corruption with header-split and HW-GRO
  * CVE-2026-72069
    - locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
  * CVE-2026-72083
    - scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
  * CVE-2026-72084
    - scsi: target: Bound PR-OUT TransportID parsing to the received buffer
  * CVE-2026-72085
    - scsi: xen: scsiback: Free unsubmitted command instead of double-putting
      it
  * CVE-2026-72129
    - nvmet-rdma: handle inline data with a nonzero offset
  * CVE-2026-72130
    - nvmet-auth: reject short AUTH_RECEIVE buffers
  * CVE-2026-64551
    - sctp: validate STALE_COOKIE cause length before reading staleness
  * CVE-2026-72137
    - xfrm: nat_keepalive: avoid double free on send error
  * CVE-2026-72139
    - tcp: defer md5sig_info kfree past RCU grace period in tcp_connect
  * CVE-2026-72191
    - ntfs3: validate split-point offset in indx_insert_into_buffer
  * CVE-2026-72192
    - ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head
  * CVE-2026-72194
    - fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
  * CVE-2026-72217
    - SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
  * CVE-2026-72220
    - sunrpc: harden rq_procinfo lifecycle to prevent double-free
  * CVE-2026-72221
    - sunrpc: wait for in-flight TLS handshake callback when cancel loses race
  * CVE-2026-72222
    - sunrpc: pin svc_xprt across the asynchronous TLS handshake callback
  * CVE-2026-72226
    - batman-adv: tt: prevent TVLV OOB check overflow
  * CVE-2026-72234
    - batman-adv: access unicast_ttvn skb->data only after skb realloc
  * CVE-2026-72251
    - netfilter: nf_nat_sip: reload possible stale data pointer
  * CVE-2026-72277
    - KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN
    - KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory
  * CVE-2026-72279
    - KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR
  * CVE-2026-72288
    - KVM: arm64: vgic: Handle race between interrupt affinity change and LPI
      disabling
  * CVE-2026-72289
    - KVM: arm64: vgic: Check the interrupt is still ours before migrating it
  * CVE-2026-72296
    - net: ife: require ETH_HLEN to be pullable in ife_decode()
  * CVE-2026-72299
    - tipc: restrict socket queue dumps in enqueue tracepoints
  * CVE-2026-72317
    - SUNRPC: pin upper rpc_clnt across the TLS connect_worker
  * CVE-2026-72318
    - cifs: validate DFS referral string offsets
  * CVE-2026-72319
    - ipvs: fix PMTU for GUE/GRE tunnel ICMP errors
    - ipvs: ensure inner headers in ICMP errors are in headroom
  * CVE-2026-72320
    - netfilter: nft_lookup: fix catchall element handling with inverted
      lookups
  * CVE-2026-72322
    - ipv6: mcast: Fix potential UAF in MLD delayed work
  * CVE-2026-72323
    - ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
  * CVE-2026-64541
    - net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
  * CVE-2026-72339
    - qede: fix off-by-one in BD ring consumption on build_skb failure
  * CVE-2026-72348
    - netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
  * CVE-2026-72351
    - gue: validate REMCSUM private option length
  * CVE-2026-72366
    - netfs: Fix netfs_create_write_req() to handle async cache object
      creation
  * CVE-2026-72381
    - ksmbd: fix use-after-free of fp->owner.name in durable handle owner
      check
  * CVE-2026-72393
    - eth: fbnic: don't cache shinfo across skb realloc
  * CVE-2026-72398
    - sctp: add INIT verification after cookie unpacking
  * CVE-2026-72399
    - net: enetc: check the number of BDs needed for xdp_frame
  * CVE-2026-64530
    - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
  * CVE-2026-72422
    - ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2
      NEGOTIATE
  * CVE-2026-72429
    - ipv6: ioam: fix type confusion of dst_entry
  * CVE-2026-72436
    - netfilter: ipset: Fix data race between add and dump in all hash types
    - netfilter: ipset: annotate "pos" for concurrent readers/writers
    - netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash
      types
  * CVE-2026-72451
    - xfrm: Fix xfrm state cache insertion race
  * CVE-2026-72466
    - xprtrdma: Fix bcall rep leak and unbounded peek
  * CVE-2026-72472
    - nfs: use nfsi->rwsem to protect traversal of the file lock list
  * CVE-2026-72473
    - xprtrdma: Avoid 250 ms delay on backlog wakeup
    - xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot
    - xprtrdma: Post receive buffers after RPC completion
    - xprtrdma: Use sendctx DMA state for Send signaling
    - xprtrdma: Decouple req recycling from RPC completion
  * CVE-2026-72491
    - net/9p: fix race condition on rdma->state in trans_rdma.c
  * CVE-2026-72495 // CVE-2026-72501
    - RDMA/bnxt_re: Move the UAPI methods to a dedicated file
  * CVE-2026-74255
    - tipc: fix UAF in tipc_l2_send_msg()
  * CVE-2026-74267
    - net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek
      before restoring qlen
  * CVE-2026-74268
    - tcp: clear sock_ops cb flags before force-closing a child socket
  * CVE-2026-74287
    - sctp: validate embedded address parameter length
  * CVE-2026-74310
    - vhost/net: complete zerocopy ubufs only once
  * CVE-2026-74345
    - RDMA/siw: Fix endpoint/socket association handling
  * CVE-2026-74361
    - nvme: fix FDP fdpcidx bounds check
  * CVE-2026-74376
    - md/raid10: reset read_slot when reusing r10bio for discard
  * CVE-2026-74384
    - nvme-multipath: fix flex array size in struct nvme_ns_head
  * CVE-2026-74394
    - RDMA/srpt: fix integer overflow in immediate data length check
  * CVE-2026-74398
    - ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD
  * CVE-2026-74401
    - dlm: fix add msg handle in send_queue ordered
  * CVE-2026-74406
    - vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive().
  * CVE-2026-74427
    - afs: Fix netns teardown to cancel the preallocation charger
    - afs: Fix further netns teardown to cancel the preallocation charger
  * CVE-2026-74428
    - rxrpc: Fix double unlock in rxrpc_recvmsg()
  * CVE-2026-74433
    - rxrpc: Fix UAF in rxgk_issue_challenge()
  * CVE-2026-74434
    - rxrpc: Don't move a peeked OOB message onto the pending queue
  * CVE-2026-74436
    - rxrpc: serialize kernel accept preallocation with socket teardown
  * CVE-2026-64535
    - nvmet-tcp: Fix potential UAF when ddgst mismatch
  * CVE-2026-74439
    - iommu/vt-d: Clear Present bit before tearing down scalable-mode context
      entry
  * CVE-2026-64534
    - nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error
      path

Date: 2026-09-21 15:28:44.900377+00:00
Changed-By: Sarah Emery <sarah.emery at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-riscv/7.0.0-38.38.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list