[ubuntu/resolute-proposed] linux-riscv 7.0.0-38.38.1 (Accepted)
Andy Whitcroft
apw at canonical.com
Thu Sep 24 23:52:17 UTC 2026
linux-riscv (7.0.0-38.38.1) resolute; urgency=medium
* resolute/linux-riscv: 7.0.0-38.38.1 -proposed tracker (LP: #2165484)
* resolute: llvm-21-dev build-depends breaks cross-builds (LP: #2165407)
- [Packaging] Fix cross-builds
* Zfhmin/Zvfhmin not reported when Zfh/Zvfh are present (LP: #2166547)
- riscv: report Zfhmin/Zvfhmin when Zfh/Zvfh are present
[ Ubuntu: 7.0.0-38.38 ]
* resolute/linux: 7.0.0-38.38 -proposed tracker (LP: #2166443)
* linux: dtbs_install fails on Resolute builders due to uutils install(1)
EEXIST race under parallel make (LP: #2166356)
- SAUCE: [Packaging] Serialise dtbs_install to work around uutils
install(1) race
* #510/p sleepable raw tracepoint reject from test_verifier in ubuntu_bpf
failed with resolute (7.0.0-33.33) generic amd64 (LP: #2165872)
- SAUCE: Revert "bpf: Verifier support for sleepable tracepoint programs"
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189)
- platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug
- selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs
- drm/virtio: fix deadlock in display_info_cb by removing hotplug from
dequeue worker
- seqlock: Allow UBSAN_ALIGNMENT to fail optimizing
- KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN
- crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin
- xprtrdma: Clear receive-side ownership pointers on release
- Input: ims-pcu - fix logic error in packet reset
- fuse: fix writeback array overflow when max_pages is one
- arm64: tegra: Remove fallback compatible for GPCDMA
- arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234
- xfrm: propagate -EINPROGRESS from validate_xmit_xfrm()
- mtd: mtdswap: remove debugfs stats file on teardown
- mtd: nand: mtk-ecc: stop on ECC idle timeouts
- btrfs: fallback to transaction csum tree on a commit root csum miss
- RDMA/cma: Fix hardware address comparison length in netevent callback
- RDMA/irdma: Remove redundant legacy_mode checks
- RDMA/erdma: initialize ret for empty receive WR lists
- RDMA/mana_ib: initialize err for empty send WR lists
- RDMA/hns: Fix potential integer overflow in mhop hem cleanup
- selftests/alsa: Fix memory leak in find_controls error path
- RDMA/irdma: Prevent overflows in memory contiguity checks
- wifi: cfg80211: derive S1G beacon TSF from S1G fields
- wifi: nl80211: validate nested MBSSID IE blobs
- wifi: nl80211: constrain MBSSID TX link ID range
- wifi: cfg80211: validate PMSR measurement type data
- wifi: cfg80211: reject unsupported PMSR FTM location requests
- wifi: mac80211: avoid non-S1G AID fallback for S1G assoc
- ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on
start/stop
- ASoC: amd: ps: disable MSI on resume in ACP PCI driver
- ASoC: amd: ps: fix wrong ACP version string in pci_request_regions()
- ASoC: amd: ps: replace bitwise OR with logical OR in IRQ return check
- ASoC: cs42l43: Correct report for forced microphone jack
- ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after
lookup
- firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context
- cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq
- udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf()
- ata: sata_dwc_460ex: use platform_get_irq()
- ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending
interrupts
- accel/ivpu: Fix wrong register read in LNL failure diagnostics
- ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC
- drm/i915/gt: use correct selftest config symbol
- powerpc/85xx: Add fsl,ifc to common device ids
- powerpc/time: Prepare to stop elapsing in dynticks-idle
- powerpc/vtime: Initialize starttime at boot for native accounting
- drm/panthor: Check debugfs GEM lock initialization
- riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus()
- can: j1939: fix lockless local-destination check
- drm/xe/wopcm: fix WOPCM size for LNL+
- drm/i915/wm: clear the plane ddb_y entries on plane disable
- drm/i915/selftests: Fix GT PM sort comparators
- USB: storage: add NO_ATA_1X quirk for Longmai USB Key
- usb: chipidea: fix usage_count leak when autosuspend_delay is negative
- USB: gadget: snps-udc: fix device name leak on probe failure
- USB: gadget: fsl-udc: fix device name leak on probe failure
- USB: gadget: fsl-udc: fix dev_printk() device
- USB: serial: ftdi_sio: add support for E+H FXA291
- USB: serial: keyspan_pda: fix data loss on receive throttling
- USB: serial: option: add TDTECH MT5710-CN
- SAUCE: Revert "usb: typec: ucsi: Detect and skip duplicate altmodes from
buggy firmware"
- usb: typec: ucsi: Detect and skip duplicate altmodes from buggy firmware
- wifi: mwifiex: fix freeze for 60 seconds caused by request_firmware
- RISC-V: KVM: Serialize virtual interrupt pending state updates
- Revert "drm/amd/display: Add missing kdoc for ALLM parameters"
- usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits
- selftests/bpf: Adjust verifier_map_ptr for the map's excl field
- selftests/bpf: Keep verifier_map_ptr exercising ops pointer access
- wifi: ath11k: Flush the posted write after writing to
PCIE_SOC_GLOBAL_RESET
- wifi: ath12k: Flush the posted write after writing to
PCIE_SOC_GLOBAL_RESET
- btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8
- btrfs: fix u32 to s64 type conversion in dirty_metadata_bytes accounting
- ASoC: sun4i-codec: Set quirks.playback_only for H616 codec
- ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI
- ASoC: cs35l56: Don't use devres to unregister component
- ASoC: cs35l56: Fix potential probe() deadlock
- ASoC: cs35l56: Use complete_all() to signal init_completion
- wifi: iwlwifi: mvm: validate SAR GEO response payload size
- wifi: iwlwifi: fix pointer arithmetic in iwl_add_mcc_to_tas_block_list
- wifi: iwlwifi: validate payload length in iwl_pnvm_complete_fn
- wifi: iwlwifi: mvm: fix read in wake packet notification handler
- usb: atm: ueagle-atm: reject descriptors that confuse probe and
disconnect
- drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook()
- hwmon: (asus-ec-sensors) fix looping over banks while reading from EC
- hwmon: (asus-ec-sensors) fix EC read intervals
- hwmon: (asus-ec-sensors) add missed handle for ENOMEM
- selftests/net: ovpn: fix getaddrinfo memory leak in ovpn_parse_remote()
- ovpn: use monotonic clock for peer keepalive timeouts
- regulator: mt6358: use regmap helper to read fixed LDO calibration
- net: phy: marvell: fix return code
- netlink: specs: rt-link: convert bridge port flag attributes to u8
- gtp: parse extension headers before reading inner protocol
- vhost-net: fix TX stall when vhost owns virtio-net header
- wifi: mac80211: recalculate TIM when a station enters power save
- pds_core: reject component parameter in legacy firmware update
- arm64: Correct value returned by ESR_ELx_FSC_ADDRSZ_nL()
- amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN
- soreuseport: Clear sk_reuseport_cb before failure in sk_clone().
- net: Call net_enable_timestamp() before failure in sk_clone().
- pds_core: yield the CPU while waiting for the adminq to drain
- pds_core: order completion reads after the ownership check
- pds_core: check for workqueue allocation failure
- tls: device: push pending open record on splice EOF
- selftests: af_unix: add USER_NS config
- selftests: openvswitch: add config file
- selftests: ovpn: add IPV6 and VETH configs
- selftests: ovpn: increase timeout
- selftests: drv-net: increase timeout
- ppp: don't store tx skb in the fastpath
- ppp: annotate concurrent dev->stats accesses
- ovl: fix trusted xattr escape prefix matching
- drm/panel: s6e3ha8: fix unmet dependency on DRM_DISPLAY_HELPER
- amt: make the head writable before rewriting the L2 header
- net: bridge: vlan: fix vlan range dumps starting with pvid
- net: dpaa: fix mode setting
- drm/xe/i2c: Allow per domain unique id
- iomap: correct the range of a partial dirty clear
- drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem
- net: stmmac: xgmac: fix l4 filter port overwrite on register update
- net: stmmac: fix l3l4 filter rejecting unsupported offload requests
- net: stmmac: reset residual action in L3L4 filters on delete
- net: stmmac: enable the MAC on link up for all supported speeds
- octeontx2-vf: set TC flower flag on MCAM entry allocation
- ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup
- ppp: annotate data races in ppp_generic
- hinic: remove unused ethtool RSS user configuration buffers
- raw: annotate lockless match fields in raw_v4_match()
- net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule
- net/mlx5e: Report zero bandwidth for non-ETS traffic classes
- net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation
- octeontx2-pf: tc: fix egress ratelimiting
- net: ipv6: fix dif and sdif mismatch in raw6_icmp_error
- ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV
- ice: fix LAG recipe to profile association
- ipv6: Change allocation flags to match rcu_read_lock section
requirements
- ptp: netc: explicitly clear TMR_OFF during initialization
- mctp: check register_netdevice_notifier() error in mctp_device_init()
- net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets()
- drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay
- drm: renesas: rzg2l_mipi_dsi: Move rzg2l_mipi_dsi_set_display_timing()
- drm/tidss: Fix missing drm_bridge_add() call
- drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video()
- drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't
at 0 (v2)
- drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older
- drm/sysfb: Do not page-align visible size of the framebuffer
- drm/sysfb: Avoid truncating maximum stride
- drm/amdgpu/gfx9: Fix Ring and IB test fail after mode2
- drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT
- drm/sysfb: Return errno code from drm_sysfb_get_visible_size()
- drm/displayid: fix Tiled Display Topology ID size
- drm/nouveau/acr: fix missing nvkm_done() in error path of
nvkm_acr_oneinit()
- drm/radeon: fix r100_copy_blit for large BOs
- drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds
- drm/amdkfd: Use kvcalloc to allocate arrays
- drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips
- drm/i915/hdcp: require monotonically increasing seq_num_v
- drm/amd/amdgpu: disable ASPM on VI if pcie dpm is disabled
- drm/amd/pm: fix smu14 power limit range calculation
- drm/gfx10: Program DB_RING_CONTROL
- drm/virtio: Don't detach GEM from a non-created context
- drm/panthor: return error on truncated firmware
- drm/amdgpu: Fix VFCT bus number matching with soft filter
- drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X)
- drm/amd/display: consolidate DCN vblank/flip handling onto
vupdate_no_lock
- drm/amd/display: Force PWM backlight on Lenovo Legion 5 15ARH05
- drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge
- drm/amd/display: Fix flip-done timeouts on mode1 reset
- drm/amd/display: Fix missing DCE check in
dm_gpureset_toggle_interrupts()
- drm/v3d: Reach the GMP through the hub registers on V3D 7.x
- media: aspeed: fix missing of_reserved_mem_device_release() on probe
failure
- media: cec: seco: unregister adapter on IR probe failure
- media: cedrus: clean up media device on probe failure
- media: cedrus: Fix missing cleanup in error path
- media: imx219: Fix maximum frame length in lines
- media: iris: Fix use IRQF_NO_AUTOEN when requesting the IRQ
- media: marvell-cam: fix missing pci_disable_device() on remove
- media: nuvoton: npcm-video: fix error handling in npcm_video_init()
- media: nxp: imx8-isi: Clean up already-initialized pipes on probe
failure
- media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init
error path
- media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding
- media: qcom: camss: Fix RDI streaming for CSID 680
- media: qcom: camss: Fix RDI streaming for CSID GEN2
- media: qcom: camss: Fix RDI streaming for CSID GEN3
- media: rzg2l-cru: Skip ICnMC configuration when ICnSVC is used
- media: synopsys: hdmirx: Fix HPD lane hold time
- media: tegra-video: vi: fix invalid u32 return value in format lookup
- media: v4l2-ctrls-request: add NULL check in
v4l2_ctrl_request_complete()
- media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely
- media: vb2: use ssize_t for vb2_read/vb2_write
- media: verisilicon: Export only needed pixels formats
- media: vidtv: fix reference leak on failed device registration
- media: vimc: fix reference leak on failed device registration
- media: vpif_capture: fix OF node reference imbalance
- ALSA: hda/realtek: Fix speakers on Lunnen Ground 14
- ALSA: hda: codecs: hdmi: disable keep-alive before audio format change
- wifi: brcmfmac: set F2 blocksize to 256 for BCM43752
- wifi: ath11k: fix refcount leak in ath11k_ahb_fw_resources_init()
- staging: rtl8723bs: fix inverted HT40 secondary channel offset
- platform/loongarch: laptop: Explicitly reset bl_powered state when
suspend
- rust_binder: only print failure if error has source
- rust: time: fix as_micros_ceil() to round correctly for negative Delta
- rust: allow `clippy::unwrap_or_default` globally
- objtool/rust: add one more `noreturn` Rust function for Rust 1.99.0
- LoongArch: Fix address space mismatch in kexec command line lookup
- LoongArch: Fix oops during single-step debugging
- LoongArch: Move jump_label_init() before parse_early_param()
- LoongArch: Retrieve CPU package ID from PPTT when available
- x86/boot/compressed: Disable jump tables
- uio_hv_generic: Bind to FCopy device by default
- serial: sc16is7xx: implement gpio get_direction() callback
- selftests: ntsync: correct CONFIG_NTSYNC name
- tracing: Fix context switch counter truncation
- tracing/eprobe: Fix exact system name matching in
eprobe_dyn_event_match()
- tracing/probes: Avoid temporary buffer truncation in
trace_probe_match_command_args()
- tracing/probes: Fix potential underflow in LEN_OR_ZERO macro
- tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err()
- mptcp: decrement subflows counter on failed passive join
- mptcp: only set DATA_FIN when a mapping is present
- mm/kmemleak: fix checksum computation for per-cpu objects
- mm/huge_memory: set PG_has_hwpoisoned only after new folio head is
established
- ceph: fix refcount leak in ceph_readdir()
- ceph: fix writeback_count leak in write_folio_nounlock()
- ASoC: fsl: imx-card: Skip sysclk reset for active DAIs in shutdown
- ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP
- io_uring/rw: fix missing ERESTARTSYS conversion in read paths
- iommu/vt-d: Disallow SVA if page walk is not coherent
- net: stmmac: intel: skip SerDes reconfig when rate is unchanged
- net: pcs: xpcs: fix SGMII state reading
- proc: Fix broken error paths for namespace links
- s390/ptff: Export ptff_function_mask[]
- smb: client: handle STATUS_STOPPED_ON_SYMLINK responses without a
symlink target
- ice: use READ_ONCE() to access cached PHC time
- ovpn: hold peer before scheduling keepalive work
- vsock/virtio: collapse receive queue under memory pressure
- watchdog: s32g_wdt: remove incorrect options in watchdog_info struct
- drm/amd/pm: fix amdgpu_pm_info power display units
- drm/amd/pm: make pp_features read-only when scpm is enabled
- drm/amdgpu/jpeg: fix jpeg_v4_0_3_is_idle detection
- drm/amdgpu/jpeg: fix jpeg_v5_0_1_is_idle detection
- drm/amdgpu/soc24: reset dGPU if suspend got aborted
- drm/amdgpu: fix resource leak on ACP reset timeout
- drm/amd/pm: fix smu13 power limit range calculation
- drm/amdgpu: fix check in amdgpu_hmm_invalidate_gfx
- drm/xe/uapi: Reject coh_none PAT index for CPU_ADDR_MIRROR
- net: qrtr: ns: Raise node count limit to 512
- drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources
- audit: widen ino fields to u64
- audit: use 'unsigned int' instead of 'unsigned'
- xfs: don't replace the wrong part of the cow fork
- netfilter: nf_tables: remove register tracking infrastructure
- drm: drop lib from header search path.
- SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists
- SUNRPC: Return an error from xdr_buf_to_bvec() on overflow
- SAUCE: Revert "mm/sparse-vmemmap: fix vmemmap accounting underflow"
- mm/sparse-vmemmap: fix vmemmap accounting underflow
- mmc: vub300: rename probe error labels
- net: mana: Optimize irq affinity for low vcpu configs
- bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c
- bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline()
- pmdomain: imx93-blk-ctrl: convert to devm_* only
- rust: allow `suspicious_runtime_symbol_definitions` lint for Rust >=
1.98
- rust: device: avoid trailing ; in printing macros
- sched_ext: Skip ops.set_weight() for disabled tasks
- sched_ext: Annotate ksyncs with __rcu in alloc/free_kick_syncs()
- reset: spacemit: k3: fix USB2 ahb reset
- wifi: cfg80211: reject empty PMSR peer lists
- ASoC: amd: acp: Fix linker error with SDCA quirks
- [Config] Adjust config SND_SOC_ACPI_AMD_SDCA_QUIRKS
- sched_ext: Enable tick for finite slices on nohz_full
- Bluetooth: mgmt: Translate HCI reason in Device Disconnected event
- riscv: Gate FUNCTION_ALIGNMENT_4B on DYNAMIC_FTRACE
- spi: cadence-quadspi: Fix indirect write timeout when DMA read mode is
enabled
- drm/xe: Assign queue name in time for drm_sched_init
- drm/xe: add WQ_PERCPU to alloc_workqueue users
- selftests: netconsole: only restore MAC when it changed on resume
- wifi: ath10k: fix skb leak on incomplete msdu during rx pop
- wifi: ath12k: Fix low MLO RX throughput on WCN7850
- iommu/amd: Fix nested domain leak
- arm_mpam: Fix software reset values of MPAMCFG_PRI
- arm_mpam: Fix MPAMCFG_MBW_PBM register setting
- hwmon: Drop unused i2c driver_data
- hwmon: Use named initializers for arrays of i2c_device_data
- hwmon: (pmbus/max34440): add support adpm12250
- hwmon: (pmbus/max34440) block unsupported VIN and IIN limit registers
- drm/i915/backlight: Remove DP_EDP_BACKLIGHT_AUX_ENABLE_CAP check for
DPCD backlight
- selftests/net: Fix tun IPv6 test addresses to avoid 6to4 range
- geneve: fix hint header definition wrt endianness
- geneve: ensure the skb is writable before fixing its headers
- accel: ethosu: Handle U85 internal chaining buffer
- selftests: drv-net: convert so_txtime to drv-net
- cifs: prevent readdir from changing file size due to stale directory
metadata
- wifi: mt76: fix airoha_npu dependency tracking
- [Config] Fix config dependencies for MT76_NPU
- drm/panel: ilitek-ili9882t: fix unmet dependency for
DRM_PANEL_ILITEK_ILI9882T
- iomap: fix incorrect did_zero setting in iomap_zero_iter()
- mpls: Set rt->rt_nhn just before returning from mpls_nh_build_multi().
- LoongArch: BPF: Zero-extend signed ALU32 div/mod results
- bnge/bng_re: fix ring ID widths
- pidfs: make pidfs_ino_lock static
- LoongArch: BPF: Fix memory leak in bpf_jit_free()
- drm/exynos: fbdev: Remove offset into screen_buffer
- drm/tegra: fbdev: Remove offset into framebuffer memory
- drm/i915/cdclk: Fix up CDCLK_FREQ_DECIMAL without a full PLL re-enable
- drm/amd/pm: re-enable MC access after PrepareMp1ForUnload on SMU V15
APUs
- bitmap: add test_zero_nbits()
- drm/xe: Add compact-PT and addr mask handling for page reclaim
- drm/amd/display: Restore periodic detection for DCN35
- drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions
- drm/amdkfd: Use exclusive bounds for SVM split alignment checks
- drm/i915/mtl+: Enable PPS before PLL
- drm/xe/oa: Fix offset alignment for MERT WHITELIST_OA_MERT_MMIO_TRG
- drm/xe/nvm: fix writable override for CRI
- drm/amdgpu: Check for multiplication overflow in checkpoint stack size
- drm/amdkfd: Guard m->cp_hqd_eop_control setting by
q->eop_ring_buffer_size
- drm/amdkfd: free MQD managers on DQM init failures
- drm/amd/display: set MSA MISC1 bit 6 when using VSC SDP for DCE 11.x
- drm/amdgpu: add the doorbell index input for suspending userq
- drm/amdgpu: remove deadlocks from amdgpu_userq_pre_reset
- drm/amd: Create a device link between APU display and XHCI devices
- drm/pagemap: Clear driver-provided PFNs from migration PFN array
- mm: add gpu active/reclaim per-node stat counters (v2)
- drm/ttm: use gpu mm stats to track gpu memory allocations. (v4)
- drm/ttm: Fix GPU MM stats during pool shrinking
- drm/ttm/pool: back up at native page order
- drm/gpusvm: Zero HMM PFNs before scanning ranges
- media: mali-c55: Add missing of_reserved_mem_device_release()
- media: mali-c55: Disable pm_runtime on probe error
- media: mali-c55: Power-off the peripheral in remove()
- media: qcom: camss: Fix RDI streaming for CSID 340
- media: rzv2h-ivc: Wait for frame end in stop_streaming
- media: ti: vpe: Fix fwnode_handle leak in vip_probe_complete()
- media: ti: vpe: Fix the error code of devm_request_irq()
- media: uapi: rkisp: Correct name version enum
- wifi: mt76: restrict NPU/PPE active checks to MMIO devices
- LoongArch: Fix build errors due to wrong instructions for 32BIT
- LoongArch: Increase TASK_STRUCT_OFFSET up to 2040 for 32BIT
- firmware: stratix10-svc: fix teardown order in remove to prevent race
- firmware: stratix10-svc: handle NO_RESPONSE in async poll
- tracing: perf: Fix stale head for perf syscall tracing
- arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates
- Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer
updates"
- selftests: mptcp: userspace_pm: fix undefined variable port
- m68k: avoid -Wunused-but-set-parameter in clear_user_page()
- mm/memory-failure: trace: change memory_failure_event to ras subsystem
- mm/slub: fix lost local objects when bulk remote free batch fills
- mm/slab: fix a memory leak due to bootstrapping sheaves twice
- drm/amdgpu: rework userq fence driver alloc/destroy
- drm/amdgpu: rework userq fence signal processing
- drm/amdgpu/gfx11: fix EOP interrupt routing for KQ and userq
- drm/amdgpu/gfx12: fix EOP interrupt routing for KQ and userq
- drm/amdgpu/mes11: set doorbell offset for suspending userq
- selftests: drv-net: add missing kconfig for psp.py
- mm/sparse-vmemmap: pass @pgmap argument to memory deactivation paths
- mm/sparse-vmemmap: fix DAX vmemmap accounting with optimization
- selftests: drv-net: cope with slow env in so_txtime.py test
- selftests: drv-net: so_txtime: relax variance bounds
- cifs: fix time_last_write stamp placement in setattr/truncate paths
- cifs: consolidate time_last_write stamp into _cifsFileInfo_put()
- Upstream stable to v6.18.41, v6.18.42, v6.18.43, v7.1.6, v7.1.7
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68480
- x86/bugs: Make Safe-RET robust against interrupt injection
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68105
- drm/amdgpu: Fix kernel panic during driver load failure
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68109
- drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68114
- drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68431
- ksmbd: validate minimum PDU size for transform requests
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68138
- net/sched: serialize qdisc_rtab_list against concurrent get/put
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68082
- libceph: fix two unsafe bare decodes in decode_lockers()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68159
- libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68163
- mm/page_vma_mapped: fix device-private PMD handling
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68166
- userfaultfd: prevent registration of special VMAs
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68170
- mptcp: fix stale skb->sk reference on subflow close
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68177
- tracing: Delay module ref count for "enable_event" trigger
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68191
- wifi: ath12k: fix NULL pointer dereference in rhash table destroy
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64586
- wifi: brcmfmac: drain bus_reset work on device removal
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68208
- media: ti: vpe: Fix the error code of devm_kzalloc() in
vip_probe_slice()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68224
- media: mali-c55: Fix possible ERR_PTR in enable_streams
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68237
- drm/amdgpu/userq: fix indefinite fence wait during GPU reset
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68240
- drm/gpusvm: publish dpagemap early to avoid device mapping leak on error
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68242
- drm/i915/gt: Fix NULL deref on sched_engine alloc failure
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68254
- drm/i915/vrr: require valid min/max vfreq for VRR
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68436
- drm/amd/display: use kvzalloc to allocate struct dc
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68447
- drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68264
- drm/xe/pt: Reset current_op in xe_pt_update_ops_init()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68265
- drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68267
- drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68273
- drm/amdgpu: Fix context pstate override handling
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68274
- drm/xe/guc: Fix buffer overflow in steered register list allocation
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68283
- tracing: Fix use-after-free freeing trigger private data
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68286
- drop_monitor: perform u64_stats updates under IRQ-disabled section
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68287
- drop_monitor: fix size calculations for 64-bit attributes
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68288
- net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68289
- tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68291
- idpf: fix max_vport related crash on allocation error during init
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68303
- drm/vc4: hvs/v3d: Fix null dereference in unbind
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68312
- cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain
paths
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68316
- accel: ethosu: Fix element size accounting for cmd stream validation
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68322
- rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68440
- net: txgbe: fix heap overflow when reading module EEPROM
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68323
- tipc: serialize udp bearer replicast list updates
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68441
- net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68337
- bpf: Reject redirect helpers without a bpf_net_context
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68345
- arm_mpam: guard MBWU state before adding it to garbage
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68347
- iommu/amd: Fix IRQ unsafe locking in gdom allocation
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68375
- bnxt_en: Handle partially initialized auxiliary devices
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68382
- drm/xe/guc: Hold device ref until queue teardown completes
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68383
- drm/xe/guc: Keep scheduler timeline name alive
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68390
- Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68399
- bpf: Fix UAF in sock clone early bailouts
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68404
- wifi: cfg80211: use wiphy work for socket owner autodisconnect
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64581
- xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68093
- KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision
after hotplug
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68367
- usb: gadget: f_tcm: synchronize delayed set_alt with teardown
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68164
- mm/damon/core: disallow overlapping input ranges for damon_set_regions()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68165
- mm/damon/core: validate ranges in damon_set_regions()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68095
- fuse-uring: fix race between registration and connection abortion
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68096
- audit: fix recursive locking deadlock in audit_dupe_exe()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68147
- fscrypt: Avoid dynamic allocation in fscrypt_get_devices()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68097
- ksmbd: validate ACE size against SID sub-authorities
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68098
- ksmbd: bound DACL dedup walk to copied ACEs
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68099
- ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68100
- ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68173
- ublk: wait on ublk_dev_ready() instead of ub->completion
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68104
- drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68106
- drm/amdgpu: fix division by zero with invalid uvd dimensions
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68429
- drm/dp_mst: Handle torn-down topology gracefully in
drm_dp_mst_topology_queue_probe()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68107
- drm/amdgpu/vcn4: avoid rereading IB param length
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68108
- drm/amdgpu/vce: fix integer overflow in image size
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68110
- drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68111
- drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68112
- drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68430
- drm/amdgpu/gfx8: drop unecessary BUG_ON()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68113
- drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68246
- drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68115
- drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68116
- vxlan: mdb: Fix source list corruption on a failed replace
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68117
- tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68118
- tcp: challenge ACK for non-exact RST in SYN-RECEIVED
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68119
- tcp: initialize standalone TCP-AO response padding
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68120
- rtase: Workaround for TX hang caused by hardware packet parsing
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68121
- pppoe: reload header pointer after dev_hard_header()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68122
- ovpn: fix peer refcount leak in TCP error paths
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68123
- openvswitch: fix GSO userspace truncation underflow
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68124
- mctp: serial: handle zero-length frames to prevent rx buffer overflow
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68125
- mac802154: llsec: reject frames shorter than the authentication tag
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68126
- mac802154: hold an interface reference across the scan worker
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68127
- ila: reload IPv6 header after pskb_may_pull in checksum adjust
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68128
- ice: reject out-of-range ptype in ice_parser_profile_init
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68129
- gve: fix Rx queue stall on alloc failure
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68130
- ksmbd: defer destroy_previous_session() until after NTLM authentication
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68131
- rbd: Reset positive result codes to zero in object map update path
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68132
- super: fix emergency thaw deadlock on frozen block devices
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68133
- ice: fix PTP Call Trace during PTP release
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68134
- ptp: ptp_s390: Add missing facility check
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68135
- net: hip04: fix RX buffer leak on build_skb failure
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68136
- net: gro: fix double aggregation of flush-marked skbs
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68137
- net/x25: fix use-after-free in x25_kill_by_neigh()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68139
- net/mlx5e: Use sender devcom for MPV master-up
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68140
- net/iucv: fix use-after-free of a severed iucv_path
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68141
- net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68142
- geneve: require CAP_NET_ADMIN in the device netns for changelink
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68143
- net: slip: serialize receive against buffer reallocation
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68432
- vxlan: require CAP_NET_ADMIN in the device netns for changelink
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68144
- phonet: pep: fix use-after-free in pep_get_sb()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68145
- iomap: fix out-of-bounds bitmap_set() with zero-length range
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68146
- ftrace: Add global mutex to serialize trace_parser access
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68148
- fscrypt: Add missing superblock check in find_or_insert_direct_key()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68149
- fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68150
- fs/super: fix emergency thaw double-unlock of s_umount
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68151
- binfmt_elf_fdpic: only honour the first PT_INTERP
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68152
- amt: fix use-after-free in AMT delayed works
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68153
- libceph: remove debugfs files before client teardown
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68154
- libceph: reject zero bucket types in crush_decode
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68155
- libceph: Reject monmaps advertising zero monitors
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68156
- libceph: refresh auth->authorizer_buf{,_len} after authorizer update
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68157
- libceph: guard missing CRUSH type name lookup
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68158
- libceph: Fix multiplication overflow in decode_new_up_state_weight()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68433
- libceph: bound get_version reply decode to front len
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68160
- ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68161
- sctp: close UDP tunnel sockets during netns teardown
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68162
- sctp: avoid auth_enable sysctl UAF during netns teardown
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64564
- sctp: don't free the ASCONF's own transport in DEL-IP processing
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68168
- afs: Fix afs_edit_dir_remove() to get, not find, block 0
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68169
- mptcp: pm: userspace: fix use-after-free in get_local_id
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68172
- arm64: make huge_ptep_get handled unaligned addresses
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68174
- tracing: Fix union collision of module and refcnt for dynamic events
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68175
- tracing: Fix resource leak on mmiotrace trace_pipe close
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68176
- tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68178
- misc: nsm: pin the module while the device is open
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68179
- misc: nsm: only unlock nsm_dev on post-lock error paths
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68180
- intel_th: fix MSC output device reference leak
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68181
- mei: bus: access mei_device under device_lock on cleanup
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68434
- serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR
platforms
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68182
- comedi: comedi_parport: deal with premature interrupt
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68183
- firmware: stratix10-svc: fix memory leaks and list corruption bugs
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64563
- rhashtable: clear stale iter->p on table restart
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68184
- cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68186
- binfmt_misc: set have_execfd only once the interpreter is opened
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68187
- exec: fix unsigned loop counter wrap in transfer_args_to_stack()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68188
- Bluetooth: RFCOMM: Fix session UAF in set_termios
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68189
- Bluetooth: hci_sync: Protect UUID list traversal
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68190
- staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68192
- wifi: brcmfmac: make release_scratchbuffers idempotent
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68193
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68194
- wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68195
- wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68196
- wifi: wilc1000: validate assoc response length before subtracting header
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68197
- wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-
oper
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68198
- wifi: ath6kl: fix use-after-free in aggr_reset_state()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68199
- wifi: ath6kl: fix OOB access from firmware ADDBA window size
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68200
- ALSA: timer: don't re-enter an instance callback that is still running
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68201
- ALSA: timer: drain a slave's callback before its master detaches it
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68202
- ALSA: seq: close a re-opened queue timer in the destructor
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68203
- media: vivid: fix cleanup bugs in vivid_init()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68204
- media: vivid: check for vb2_is_busy() when toggling caps
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68205
- media: v4l2-fwnode: Fix subdev owner overwritten in
v4l2_async_register_subdev_sensor()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68206
- media: v4l2-ctrls: validate HEVC active reference counts
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68207
- media: ti: vpe: unwind v4l2 device registration on probe error
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68209
- media: sun4i-csi: Return queued buffers on start_streaming() failure
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68210
- media: stm32: dcmi: unregister notifier on probe failure
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68211
- media: stm32-dcmipp: Return queued buffers on start_streaming() failure
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68212
- media: saa7134: Fix a possible memory leak in saa7134_video_init1
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68213
- media: rtl2832_sdr: Return queued buffers on start_streaming() failure
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68214
- media: rtl2832: fix use-after-free in rtl2832_remove()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68215
- media: radio-si476x: Unregister v4l2_device on probe failure
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68216
- media: pwc: Return queued buffers on start_streaming() failure
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68217
- media: pwc: Drain fill_buf on start_streaming() failure
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68218
- media: pci: dm1105: Free allocated workqueue
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68219
- media: nxp: imx8-isi: Fix potential out-of-bounds issues
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68220
- media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and
pipe
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68221
- media: nuvoton: npcm-video: fix memory leaks in probe and remove
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68222
- media: msi2500: Return queued buffers on start_streaming() failure
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68223
- media: meson: vdec: Fix memory leak in error path of vdec_open
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68225
- media: i2c: alvium: fix critical pointer access in alvium_ctrl_init
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68226
- media: cx23885: add ioremap return check and cleanup
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68227
- media: cx231xx: fix devres lifetime
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68228
- media: chips-media: wave5: Move src_buf Removal to finish_encode
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68229
- media: cedrus: skip invalid H.264 reference list entries
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68230
- media: amlogic-c3: Add validations for ae and awb config
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68231
- media: airspy: Return queued buffers on start_streaming() failure
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68232
- drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68445
- drm/vc4: Prevent shader BO mappings from becoming writable
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68446
- drm/vmwgfx: Validate vmw_surface_metadata::array_size
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68233
- drm/vc4: Shut down BO cache timer before teardown
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68234
- drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68235
- drm/amd/display: dce100: skip non-DP stream encoders for DP MST
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68236
- drm/amd/display: set new_stream to NULL after release
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68238
- drm/amdgpu: Release VFCT ACPI table reference
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68239
- drm/ttm: Account for NULL and handle pages in ttm_pool_backup
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68241
- drm/i915/mst: limit DP MST ESI service loop
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68243
- drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68244
- drm/i915/gem: Do not leak siblings[] on proto context error
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68245
- drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68247
- drm/i915/bios: range check LFP Data Block panel_type2
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68248
- drm/i915: Return NULL on error in active_instance
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68249
- drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68250
- drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68251
- drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68252
- drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68253
- drm/i915/hdcp: check streams[] bounds before overflow
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68255
- drm/virtio: bound EDID block reads to the response buffer
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68256
- drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path
leaks prev_sink reference
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68257
- drm/amdkfd: fix 32-bit overflow in CWSR total size calculation
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68258
- drm/amdkfd: Check bounds on CRIU restore queue type and mqd size
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68259
- drm/amdkfd: Check bounds in allocate_event_notification_slot
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68260
- drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68261
- drm/imagination: fix error checking of pvr_vm_context_lookup()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68262
- drm/imagination: Fix user array stride in pvr_set_uobj_array()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68263
- drm/imagination: Fix double call to drm_sched_entity_fini()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68266
- drm/xe: Hold a dma-buf reference for imported BOs
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68268
- drm/xe: Return error on non-migratable faults requiring devmem
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68269
- drm/i915/gem: Add missing nospec on parallel submit slot
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68270
- drm/sysfb: Avoid possible truncation with calculating visible size
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68271
- drm/nouveau: fix reversed error cleanup order in ucopy functions
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68272
- drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68275
- drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68276
- drm/amdgpu/gfx: fix cleaner shader IB buffer overflow
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68277
- drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68437
- drm/imagination: Fit paired fragment job in the correct CCCB
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68278
- drm/dp/mst: fix buffer overflows in sideband chunk accumulation
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68279
- drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68280
- drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68281
- drm/imagination: Count paired job fence as dependency in prepare_job()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68282
- drm/rockchip: analogix_dp: Add missing error check for
platform_get_resource()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68284
- bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68290
- rds: tcp: unregister sysctl before tearing down listen socket
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68292
- ice: prevent tstamp ring allocation for non-PF VSI types
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68293
- net/mlx5: Fix MCIA register buffer overflow on 32 dword reads
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68294
- net: qrtr: restrict socket creation to the initial network namespace
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68296
- net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64575
- bpf: tcp: fix double sock release on batch realloc
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68297
- tipc: fix u16 MTU truncation in media and bearer MTU validation
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68298
- drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68299
- vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68300
- sctp: auth: verify auth requirement when auth_chunk is NULL
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68301
- net: hsr: fix memory leak on slave unregistration by removing synced
VLANs
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68302
- amt: re-read skb header pointers after every pull
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68448
- ovl: check access to copy_file_range source with src mounter creds
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68304
- wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68306
- wifi: mt76: mt7996: fix possible NULL-pointer deref in
mt7996_mcu_sta_bfer_eht()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68307
- wifi: mt76: mt7925: fix crash in reset link replay
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68308
- wifi: mt76: mt7996: check pointer returned by
mt76_connac_get_he_phy_cap()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68439
- wifi: mt76: mt7925: fix possible NULL-pointer deref in
mt7925_mcu_bss_he_tlv()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68309
- wifi: mt76: connac: fix possible NULL-pointer deref in
mt76_connac_mcu_uni_bss_he_tlv()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68310
- wifi: mt76: mt7915: guard HE capability lookups
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68311
- wifi: mt76: mt7925: guard link STA in decap offload
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68313
- tipc: fix infinite loop in __tipc_nl_compat_dumpit
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64576
- nexthop: initialize extack in nh_res_bucket_migrate()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64577
- gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68314
- net: mctp i3c: clean up notifier and buses if driver register fails
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68315
- sctp: validate stream count in sctp_process_strreset_inreq()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68317
- pds_core: fix auxiliary device add/del races
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68318
- pds_core: fix use-after-free on workqueue during remove
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68319
- pds_core: fix deadlock between reset thread and remove
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68320
- sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68321
- net: txgbe: fix FDIR filter leak on remove
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68324
- iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68325
- iommu/amd: Bound the early ACPI HID map
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68326
- wifi: mwifiex: bound uAP association event IEs to the event buffer
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68327
- wan: wanxl: Only reset hardware after BAR mapping
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68328
- nfp: Check resource mutex allocation
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64574
- wifi: mac80211: tear down new links on vif update error path
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68329
- iommu/amd: Wait for completion instead of returning early in
iommu_completion_wait()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68330
- net: airoha: Fix DMA direction for NPU mailbox buffer
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68331
- dpaa2-eth: put MAC endpoint device on disconnect
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68332
- net: airoha: Fix potential use-after-free in airoha_ppe_deinit()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68333
- dpaa2-switch: put MAC endpoint device on disconnect
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68334
- rxrpc: fix io_thread race in rxrpc_wake_up_io_thread()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68335
- rds: drop incoming messages that cross network namespace boundaries
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68336
- bonding: fix devconf_all NULL dereference when IPv6 is disabled
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68338
- net/packet: avoid fanout hook re-registration after unregister
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68339
- Bluetooth: btusb: validate Realtek vendor event length
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68340
- hwmon: occ: validate poll response sensor blocks
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68341
- ovpn: fix use after free in unlock_ovpn()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68342
- ovpn: avoid putting unrelated P2P peer on socket release
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68343
- smb: client: validate DFS referral PathConsumed
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68346
- ALSA: hda: cs35l41: validate and free ACPI mute object
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68348
- ASoC: tas2781: bound firmware description string parsing
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68450
- btrfs: free mapping node on duplicate reloc root insert
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68442
- btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68349
- wifi: carl9170: fix buffer overflow in rx_stream failover path
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68350
- wifi: carl9170: fix OOB read from off-by-two in TX status handler
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68351
- wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68352
- wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68353
- wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68354
- firewire: net: Fix fragmented datagram reassembly
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68355
- wifi: ath11k: fix potential buffer underflow in
ath11k_hal_rx_msdu_list_get()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68356
- watchdog: airoha: Prevent division by zero when clock frequency is zero
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68357
- watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68358
- hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68359
- hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68443
- hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68360
- hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68361
- hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68362
- wifi: ath11k: fix NULL pointer dereference in
ath11k_hal_srng_access_begin
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68363
- wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware
request
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68365
- USB: serial: io_edgeport: cap received transmit credits
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68366
- usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64583
- usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before
teardown
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68368
- usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68369
- usb: gadget: printer: fix infinite loop in printer_read()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64584
- usb: gadget: f_midi: cancel pending IN work before freeing the midi
object
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68370
- usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68371
- usb: musb: omap2430: Do not put borrowed of_node in probe
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68373
- wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68374
- usb: core: sysfs: add lock to bos_descriptors_read()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64569
- mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68376
- sctp: fix auth_hmacs array size in struct sctp_cookie
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68377
- net/sched: act_tunnel_key: Defer dst_release to RCU callback
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68378
- dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68379
- tcp: fix TIME_WAIT socket reference leak on PSP policy failure
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68380
- accel/amdxdna: Fix use-after-free of mm_struct in job scheduler
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64578
- ksmbd: validate compound request size before reading StructureSize2
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68381
- ksmbd: pin conn during async oplock break notification
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68384
- drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68385
- s390/checksum: Fix csum_partial() without vector facility
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68386
- bpf, sockmap: Reject unhashed UDP sockets on sockmap update
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68387
- can: raw: add locking for raw flags bitfield
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68388
- smb/client: handle overlapping allocated ranges in fallocate
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68389
- Bluetooth: hci_qca: Clear memdump state on invalid dump size
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68391
- Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68392
- Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68393
- Bluetooth: hci_sync: extend conn_hash lookup critical sections
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68394
- Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64573
- Bluetooth: qca: fix NVM tag length underflow in TLV parser
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68449
- ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-
scanning
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68395
- ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is
registered
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68396
- scsi: core: wake eh reliably when using scsi_schedule_eh
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68397
- net/iucv: take a reference on the socket found in afiucv_hs_rcv()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64572
- ipv4: fib: free fib_alias with kfree_rcu() on insert error path
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68398
- ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68400
- firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset
calculation
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68401
- firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68402
- wifi: cfg80211: bound element ID read when checking non-inheritance
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68403
- wifi: brcmfmac: initialize SDIO data work before cleanup
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68405
- wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68406
- wifi: cfg80211: validate PMSR FTM preamble range
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68407
- wifi: nl80211: free RNR data on MBSSID mismatch
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68408
- wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64571
- wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68409
- wifi: mac80211: defer link RX stats percpu free to RCU
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68410
- wifi: libertas: fix memory leak in helper_firmware_cb()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64570
- wifi: mac80211: fix fils_discovery double free on alloc failure
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64568
- wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68411
- wifi: mac80211_hwsim: clamp virtio RX length before skb_put
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68412
- wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68413
- wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68414
- wifi: cfg80211: cancel sched scan results work on unregister
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64579
- xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64580
- xfrm6: clear dst.dev on error to avoid double netdev_put in
xfrm6_fill_dst()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64566
- xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68415
- xfrm: clear mode callbacks after failed mode setup
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68416
- mtd: fix double free and WARN_ON in add_mtd_device() error paths
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68417
- RDMA/siw: publish QP after initialization
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68418
- RDMA/irdma: Prevent user-triggered null deref on QP create
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68419
- RDMA/irdma: Prevent rereg_mr for non-mem regions
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68420
- xfrm: reject optional IPTFS templates in outbound policies
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68421
- sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68444
- firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68422
- btrfs: fix root leak if its reloc root is unexpected in
merge_reloc_roots()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64567
- btrfs: reject free space cache with more entries than pages
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68425
- IB/mad: Drop unmatched RMPP responses before reassembly
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68426
- xfrm: fix stale skb->prev after async crypto steals a GSO segment
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64565
- Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68427
- gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-68428
- KVM: x86/mmu: Fix use-after-free on vendor module reload
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64562
- KVM: nVMX: Hide shadow VMCS right after VMCLEAR
* Resolute update: upstream stable patchset 2026-08-26 (LP: #2165189) //
CVE-2026-64561
- KVM: x86: Check for invalid/obsolete root *after* making MMU pages
available
* resolute: llvm-21-dev build-depends breaks cross-builds (LP: #2165407)
- [Packaging] Fix cross-builds
* Resolute Stable Update v6.18.40, v7.1.5 bugs (LP: #2165040)
- accel/amdxdna: Allow forcing IOVA-based DMA via module parameter
- SAUCE: bpf: Add missing NULL argument to zap_page_range_single
- accel/amdxdna: Return ERR_PTR on dma_alloc_noncoherent failure
- accel/amdxdna: Fix memory leak in amdxdna_iommu_alloc()
* [SRU][HPE] Take Intel platform into account for old microcode checks
(LP: #2161748)
- x86/microcode: Refactor platform ID enumeration into a helper
- x86/cpu: Add platform ID to CPU info structure
- x86/cpu: Add platform ID to CPU matching structure
- x86/microcode: Add platform mask to Intel microcode "old" list
- x86/microcode: Do not access MSR_IA32_PLATFORM_ID when running as a
guest
* ice: E810 interface fails to initialize (ice_init_hw failed: -5) during
NVM read (LP: #2163508)
- ice: acquire NVM lock around each flash read
* WWAN modem unresponsive after freeze on Dell systems with DW5826e
(LP: #2163214)
- platform/x86: dell-dw5826e: Add reset driver for DW5826e
- platform/x86: dell-dw5826e: fix ACPI _DSM function index and bitmask
usage
- [Config] Add CONFIG_DELL_DW5826E_RESET=m
* amdgpu panel self-refresh on dual-gpu laptops causes complete built-in
panel freeze and severe system instability (LP: #2162904)
- SAUCE: drm/amdgpu: Do not enter PSR if multiple displays are active
* linux 7.0: dw9719 VCM never binds, disabling all IPU3 cameras (regression,
fixed upstream) (LP: #2162045)
- media: dw9719: Add back the I²C device id table
* Fix TAS2783 SoundWire amp resume timeout >5s (LP: #2164967)
- soundwire: Add a helper function to wait for device initialisation
- ASoC: tas2783: Use new SoundWire enumeration helper
- soundwire: Move wait for initialisation helper to header
- ASoC: codecs: tas2783-sdw: Propagate regcache_sync() errors
- ASoC: tas2783-sdw: drop stale regcache on uninitialized re-attach
* Linux, Ubuntu, 24.04, System hangs for about 10 seconds when unplug
external monitor cable on non TBT dock (LP: #2160082)
- SAUCE: drm/i915/tc: Revert forced DP-alt connected workaround
* Speakers not detected on HP systems with TI TAS2783 SoundWire amps
(LP: #2164504)
- ASoC: sdw_utils: Add missed component_name strings for TI amps
* [TWL][Desktop] intel_dmc_wait_fw_load() merge to Ubuntu next release
(LP: #2156316)
- SAUCE: drm/i915/dmc: fix assert_dmc_loaded WARN during async firmware
load
* Reboot machine with ext4 configured to data=journal could dump spurious
call trace (LP: #2164716)
- ext4: clear stale xarray tags on folios skipped during writeback
* [UBUNTU 22.04] s390/topology: Use zero-based numbering (LP: #2164516)
- s390/topology: Use zero-based numbering for containing entities
* Ethernet adapter unusable after suspend/resume on Advantech systems with
Intel I226-V (LP: #2163375)
- igc: fix netdev not re-attached after resume if interface is down
* ice: fix stale -EBUSY on resume of Intel E810 (LP: #2162803)
- ice: wait for reset completion in ice_resume()
* idxd: crash-kernel NULL-pointer Oops in `destroy_workqueue()` breaks kdump
on Intel DSA/IAA systems (LP: #2163062)
- SAUCE: dmaengine: idxd: Do not call destroy_workqueue with null idxd->wq
- SAUCE: dmaengine: idxd: fix duplicate memory frees on initialization
error path.
* [HP][ZBook Power 16 G11] Laptop freezed after upgrading the BIOS
(LP: #2132119)
- PCI/ASPM: Avoid L0s for Realtek RTS525A
* Fix noise of audio output on more Dell QCx1255 models after reboot
(LP: #2163293)
- ALSA: hda/realtek - Add quirk for Dell Pro QC1255
* Fix no audio input/output device on Dell WCL Slate platform with
CirrusLogic audio solution (LP: #2160200)
- ASoC: SDCA: fix the register to ctl value conversion for Q7.8 format
- ASoC: SOF: ipc4-control: Use local copy of IPC message for sending
* Fix no audio output and mute hotkey not working on HP ZBook 8 G2a
(LP: #2158858)
- ALSA: hda/realtek: Add inverted LED quirk for HP ZBook 8 G2a
* Dock ethernet stops working after Thunderbolt dock unplug on Dell systems
(LP: #2162704)
- usb: core: port: Deattach Type-C connector on component unbind
* USB-C alt mode dropped with false firmware bug warning on Dell systems
(LP: #2162695)
- Revert "usb: typec: ucsi: Detect and skip duplicate altmodes from buggy
firmware"
- Revert "usb: typec: ucsi: Add duplicate detection to nvidia registration
path"
- Revert "usb: typec: ucsi: yoga_c630: Remove redundant duplicate altmode
handling"
- usb: typec: ucsi: Detect and skip duplicate altmodes from buggy firmware
- usb: typec: ucsi: Add duplicate detection to nvidia registration path
- usb: typec: ucsi: yoga_c630: Remove redundant duplicate altmode handling
* Resolute update: upstream stable patchset 2026-08-20 (LP: #2164666)
- crypto: algif_skcipher - force synchronous processing
- crypto: sun4i-ss - Remove insecure and unused rng_alg
- [Config] Remove unused CRYPTO_DEV_SUN4I_SS_PRNG
- media: uvcvideo: Fix deadlock if uvc_status_stop is called from
async_ctrl.work
- bpf: Clear delta when clearing reg id for non-{add,sub} ops
- selftests/bpf: Add tests for delta tracking when src_reg == dst_reg
- selftests/bpf: Add tests for stale delta leaking through id reassignment
- ALSA: hda/realtek: Add quirk for TongFang X6xx45xU
- ALSA: hda: conexant: Remove mic bias threshold override
- ALSA: hda: Fix cached processing coefficient verbs
- ALSA: hda/realtek: Fix speakers on Legion Pro 7 16ARX8H with codec SSID
17aa:38a7
- media: uvcvideo: Use hw timestaming if the clock buffer is full
- media: uvcvideo: Avoid partial metadata buffers
- media: uvcvideo: Fix buffer sequence in frame gaps
- media: uvcvideo: Fix dev_sof filtering in hw timestamp
- media: uvcvideo: Do not add clock samples with small sof delta
- media: uvcvideo: Relax the constrains for interpolating the hw clock
- media: uvcvideo: Fix sequence number when no EOF
- dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties
- dt-bindings: power: imx93: Add MIPI PHY power domain
- serial: msm: Disable DMA for kernel console UART
- serial: max310x: implement gpio_chip::get_direction()
- serial: 8250_omap: clear rx_running on zero-length DMA completes
- rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc
- rxrpc: Fix socket notification race
- rxrpc: Fix leak of released call in recvmsg(MSG_PEEK)
- rxrpc: Fix potential infinite loop in rxrpc_recvmsg()
- rxrpc: Fix rxrpc_rotate_tx_rotate() to check there's something to rotate
- rxrpc: Fix oob challenge leak in cleanup after notification failure
- rxrpc: Fix ACKALL packet handling
- rxrpc: Fix the reception of a reply packet before data transmission
- rxrpc: Fix leak of connection from OOB challenge
- afs: fix NULL pointer dereference in afs_get_tree()
- afs: handle CB.InitCallBackState3 requests without a server record
- afs: Fix uncancelled rxrpc OOB message handler
- fbcon: fix NULL pointer dereference for a console without vc_data
- fbcon: Use correct type for vc_resize() return value
- openrisc: mm: Fix section mismatch between map_page and __set_fixmap
- clocksource/drivers/sun5i: Handle error returns from
devm_reset_control_get_optional_exclusive()
- accel/amdxdna: Fix leak when pinning ubuf pages
- drm/rockchip: dw_dp: Switch to drmm_kzalloc()
- drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove()
- drm/rockchip: Test for imported buffers with drm_gem_is_imported()
- drm/tidss: Drop extra drm_mode_config_reset() call
- drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges
- drm/gpuvm: Do not prepare NULL objects
- drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch()
- drm/radeon: fix integer overflow in radeon_align_pitch()
- drm/radeon: fix memory leak in radeon_ring_restore() on lock failure
- libbpf: Report error when a negative kprobe offset is specified
- selftests/bpf: Fix off-by-one in bpf_cpumask_populate related selftest
- dt-bindings: timer: Remove sifive,fine-ctr-bits property
- drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro
- selftests/bpf: Use local type for flow_offload_tuple_rhash in
xdp_flowtable
- selftests/bpf: Use local type for bpf_fou_encap in test_tunnel_kern
- Documentation: proc: fix section numbering in table of contents
- arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Cobra
- arm64: dts: rockchip: Fix gmac0 reset pin for NanoPi R5S
- arm64: dts: qcom: ipq5424: Fix USB simple_bus_reg warnings
- arm64: dts: qcom: sc8180x: Fix phy simple_bus_reg warning
- arm64: dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg
warning
- wifi: cfg80211: fix grammar in MLO group key error message
- arm64: tegra: Fix Tegra234 MGBE PTP clock
- dt-bindings: pinctrl: nvidia,tegra234: Add missing required block
- drm/amdkfd: Validate CRIU-restored IDs before idr_alloc
- driver core: use READ_ONCE() for dev->driver in dev_has_sync_state()
- wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers
- wifi: rtw88: fix wrong pci_get_drvdata type in AER handlers
- wifi: rtw89: Correct data type for scan index to avoid infinite loop
- wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA
buffer
- wifi: rtw89: add bounds check on firmware mac_id in link lookup
- kconfig: fix potential NULL pointer dereference in conf_askvalue
- soc: xilinx: Shutdown and free rx mailbox channel
- pinctrl: mediatek: eint: Drop base from mtk_eint_chip_write_mask()
- wifi: ath9k: fix OOB access from firmware tx status queue ID
- ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint
- Documentation/rv: Replace stale website link
- watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH
- watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5
- watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register
failure
- media: cedrus: Fix failure to clean up hardware on probe failure
- media: v4l2-common: Add YUV24 format info
- memory: tegra: Wire up system sleep PM ops
- crypto: qat - fix heartbeat error injection
- lib/vsprintf: Fix to check field_width and precision
- dts: spacemit: set console baud rate on bpif3
- pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path
- dt-bindings: vendor-prefixes: Add Displaytech Ltd.
- drm/gpuvm: take refcount on DRM device
- drm/panel: Clean up S6E3HA2 config dependencies and fill help text
- ARM: dts: rockchip: Add #{address,size}-cells to Chromium-based
/firmware
- arm64: dts: rockchip: Add #{address,size}-cells to Chromium-based
/firmware
- arm64: dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc
- arm64: dts: imx8x-colibri: Correct SODIMM PAD settings
- Revert "arm64: dts: imx8mm-kontron: Add support for reading SD_VSEL
signal"
- Revert "arm64: dts: imx8mp-kontron: Add support for reading SD_VSEL
signal"
- drm: renesas: rz-du: mipi_dsi: Fix return path on error
- alarmtimer: Remove stale return description from alarm_handle_timer()
- OPP: Fix race between OPP addition and lookup
- crypto: ccp - Reverse the cleanup order in psp_dev_destroy()
- crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one
- crypto: atmel-sha204a - fix blocking and non-blocking rng logic
- crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve
- crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents
- ARM: multi_v7_defconfig: Correct QCOM_RPMH and QCOM_RPMHPD
- nilfs2: fix backing_dev_info reference leak
- media: qcom: camss: vfe: fix PIX subdev naming on VFE lite
- media: iris: scale MMCX power domain on SM8250
- media: venus: scale MMCX power domain on SM8250
- iommu/amd: Fix a stale comment about which legacy mode is user visible
- soc: mediatek: mtk-mmsys: Restore MT8167 routing masks lost during merge
- bpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries
- uaccess: fix ignored_trailing logic in copy_struct_to_user()
- arm64: dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to
host
- rust: alloc: fix `Vec::extend_with` SAFETY comment
- clk: scmi: Fix clock rate rounding
- arm64: dts: qcom: kodiak: Fix ICE reg size
- arm64: dts: qcom: sm8450: Fix ICE reg size
- drm/hisilicon/hibmc: add updating link cap in DP detect()
- drm/hisilicon/hibmc: fix no showing when no connectors connected
- drm/hisilicon/hibmc: move display contrl config to hibmc_probe()
- drm/hisilicon/hibmc: use clock to look up the PLL value
- evm: terminate and bound the evm_xattrs read buffer
- thermal: hwmon: Fix critical temperature attribute removal
- clk: scpi: Unregister child clock providers on remove
- net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats()
- scsi: hisi_sas: Add slave_destroy interface for v3 hw
- crypto: ccp - Treat zero-length cert chain as query for blob lengths
- spi: hisi-kunpeng: Use dev_err_probe() for host registration failure
- net/sched: sch_htb: do not change sch->flags in htb_dump()
- net/sched: sch_htb: annotate data-races (I)
- IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier
- RDMA/hns: Fix arithmetic overflow in calc_hem_config()
- RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure
- RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference
- RDMA/hns: Initialize seqfile before creating file
- drm/syncobj: Fix memory leak in drm_syncobj_find_fence()
- selftests/bpf: Reject unsupported -k option in vmtest.sh
- selftests/bpf: Fix test for refinement of single-value tnum
- iommu/arm-smmu-qcom: Fix fastrpc compatible string in ACTLR client match
table
- selftests/mm: Fix resv_sz when parsing arm64 signal frame
- firmware: arm_ffa: Honor partition info descriptor size
- arm64: dts: imx8dxl-evk: Remove unnecessary PCIe EP properties
- arm64: dts: imx8qxp-mek: Remove unnecessary PCIe EP vpcie-supply
- arm64: dts: imx95-19x19-evk: Fix PCIe EP vpcie-supply
- media: atomisp: Fix memory leak in atomisp_fixed_pattern_table()
- media: atomisp: gc2235: fix UAF and memory leak
- staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy()
- riscv: dts: spacemit: set console baud rate on Milk-V Jupiter
- firmware: smccc: Fix Arm SMCCC SOC_ID name call
- firmware: arm_scmi: Read sensor config as 32-bit value
- sysfs: clamp show() return value in sysfs_kf_read()
- bitops: use common function parameter names
- regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions
- tools/nolibc: getopt: Fix potential out of bounds access
- nilfs2: Fix return in nilfs_mkdir
- net/sched: sch_drr: annotate data-races around cl->deficit
- media: rockchip: rga: fix too small buffer size
- firmware: arm_scmi: Fix OOB in scmi_power_name_get()
- arm64: dts: qcom: lemans: Add power-domain and iface clk for ice node
- arm64: dts: qcom: monaco: Add power-domain and iface clk for ice node
- arm64: dts: qcom: sc7180: Add power-domain and iface clk for ice node
- arm64: dts: qcom: kodiak: Add power-domain and iface clk for ice node
- arm64: dts: qcom: sm8450: Add power-domain and iface clk for ice node
- arm64: dts: qcom: sm8550: Add power-domain and iface clk for ice node
- arm64: dts: qcom: sm8650: Add power-domain and iface clk for ice node
- arm64: dts: qcom: sm8750: Add power-domain and iface clk for ice node
- tracing: Bound synthetic-field strings with seq_buf
- arm64: dts: qcom: lemans: Add eDP ref clock for eDP PHYs
- writeback: drop now-unnecessary rcu_barrier() in
cgroup_writeback_umount()
- kernfs: fix suspicious RCU usage in kernfs_put()
- device property: fix fwnode reference leak in
fwnode_graph_get_endpoint_by_id()
- driver core: Use mod_delayed_work to prevent lost deferred probe work
- Revert "treewide: Fix probing of devices in DT overlays"
- of: dynamic: Fix overlayed devices not probing because of fw_devlink
- crypto: eip93 - fix reset ring register definition
- cpufreq: Documentation: fix sampling_down_factor range
- cpufreq: conservative: Simplify frequency limit handling
- pwm: imx27: Fix variable truncation in .apply()
- RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed
- bus: sunxi-rsb: Always check register address validity
- pinctrl: spacemit: fix NULL check in spacemit_pin_set_config
- RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs
- RDMA/rxe: Fix a use-after-free problem in rxe_mmap
- IB/mlx4: Fix refcount leak in add_port() error path
- RDMA/hns: Fix warning in poll cq direct mode
- RDMA/hns: Fix log flood after cmd_mbox failure
- RDMA/counter: Fix incorrect port index in rdma_counter_init() error
cleanup
- pinctrl: meson: amlogic-a4: fix gpio output glitch
- PM: sleep: Use complete() in device_pm_sleep_init()
- MIPS: Fix big-endian stack argument fetching in o32 wrapper
- MIPS: DEC: Remove do_IRQ() call indirection
- mips: ralink: mt7621: add missing __iomem
- mips: n64: add __iomem for writel call
- driver core: Fix missing jiffies conversion in
deferred_probe_extend_timeout()
- driver core: Guard deferred probe timeout extension with
delayed_work_pending()
- mtd: spi-nor: debugfs: Fix the flags list
- mtd: spi-nor: Drop duplicate Kconfig dependency
- ALSA: xen-front: Reset event channel state on stream clear
- ALSA: xen-front: Connect event channel after stream prepare
- ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data
- ALSA: seq: midi: Serialize output teardown with event_input
- selftests: Fix Makefile target for nsfs
- pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table
- pinctrl: cs42l43: Fix leaked pm reference on error path
- pinctrl: cs42l43: Fix polarity on debounce
- init/initramfs_test: wait_for_initramfs() before running
- nvmet-tcp: fix page fragment cache leak in error path
- nvmet-tcp: check return value of nvmet_tcp_set_queue_sock
- nvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools
- workqueue: drop spurious '*' from print_worker_info() fn declaration
- ipv6: guard against possible NULL deref in __in6_dev_stats_get()
- net/sched: cls_bpf: prevent unbounded recursion in offload rollback
- iommu/amd: Fix premature break in init_iommu_one()
- rtla/actions: Restore continue flag in actions_perform()
- drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X
client is registered
- drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove
- gpu: host1x: Allow entries in BO caches to be freed
- drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output()
- gpu: host1x: Fix iommu_map_sgtable() return value check
- drm/tegra: Fix iommu_map_sgtable() return value check
- drm/nouveau/bios: specify correct display fuse register for Ampere and
Ada
- libbpf: Harden parse_vma_segs() path parsing
- bpftool: Fix typo in struct_ops map FD generation for light skeleton
- libbpf: Fix UAF in strset__add_str()
- ARM: tegra: Add #{address,size}-cells to Chromium-based /firmware
- arm64: tegra: Add #{address,size}-cells to Chromium-based /firmware
- dax/kmem: account for partial discontiguous resource upon removal
- rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc()
- ocfs2: don't BUG_ON an invalid journal dinode
- ocfs2: kill osb->system_file_mutex lock
- crypto: hisilicon/qm - disable error report before flr
- crypto: inside-secure/eip93 - Add check for devm_request_threaded_irq
- crypto: tegra - Fix dma_free_coherent size error
- crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm
- sched/deadline: Reject debugfs dl_server writes for offline CPUs
- drm/msm/dp: fix HPD state status bit shift value
- drm/msm/dp: Fix the ISR_* enum values
- EDAC/igen6: Fix call trace due to missing release()
- EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in
skx_get_dimm_info
- arm64: dts: st: Fix SAI addresses on stm32mp251
- RDMA/umem: Add ib_umem_is_contiguous() stub for
!CONFIG_INFINIBAND_USER_MEM
- RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe
- RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path
- Revert "media: venus: hfi_platform: Correct supported codecs for sc7280"
- media: qcom: venus: drop extra padding in NV12 raw size calculation
- media: qcom: venus: relax encoder frame/blur dimension steps on v4
- media: qcom: venus: relax encoder frame/blur step size on v6
- amba: use generic driver_override infrastructure
- cdx: use generic driver_override infrastructure
- Drivers: hv: vmbus: use generic driver_override infrastructure
- rpmsg: use generic driver_override infrastructure
- raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path
- bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat
- selftests/bpf: add verification for BPF_PROG_QUERY attr size boundaries
- libbpf: Skip hash computation when loader generation failed
- libbpf: Skip endianness swap when loader generation failed
- ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data
writeback
- spi: atmel: fix DMA channel and bounce buffer leaks
- ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble
- NFSD: Fix delegation reference leak in nfsd4_revoke_states
- ARM: imx3: Fix CCM node reference leak
- HID: wiimote: Fix table layout and whitespace errors
- wifi: ath12k: fix incorrect HT/VHT/HE/EHT MCS reporting in monitor mode
- wifi: ath12k: fix NULL deref in change_sta_links for unready link
- ata: libata: Fix ata_exec_internal()
- ARM: imx31: Fix IIM mapping leak in revision check
- x86/cpu: Keep the PROCESSOR_SELECT menu together
- nvdimm/btt: Handle preemption in BTT lane acquisition
- scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-
channel scans"
- bpf: Reject exclusive maps as inner maps in map-in-map
- libbpf: Reject non-exclusive metadata maps in the signed loader
- libbpf: Skip initial_value override on signed loaders
- libbpf: Skip max_entries override on signed loaders
- scsi: pm8001: Fix error code in non_fatal_log_show()
- scsi: ufs: Fix wrong value printed in unexpected UPIU response case
- bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs
- mm/fake-numa: fix under-allocation detection in uniform split
- ext2: fix ignored return value of generic_write_sync()
- sched: restore timer_slack_ns when resetting RT policy on fork
- driver core: Use system_percpu_wq instead of system_wq
- bpf: Reject exclusive maps for bpf_map_elem iterators
- tick/sched: Fix TOCTOU in nohz idle time fetch
- lib/test_meminit: use && for bools
- riscv: dts: sophgo: sg2044: use hex for CPU unit address
- riscv: dts: sophgo: sg2042: use hex for CPU unit address
- configfs_lookup(): don't leave ->s_dentry dangling on failure
- lockdep/selftests: Restore migrate_disable() state on PREEMPT_RT
- lockdep/selftests: Restore sched_rt_mutex state on PREEMPT_RT
- ext4: fix fast commit wait/wake bit mapping on 64-bit
- drm/amdgpu: set sub_block_index for mca ras sub-blocks
- bpftool: Use libbpf error code for flow dissector query
- vhost: fix vhost_get_avail_idx for a non empty ring
- iommu/vt-d: Fix RB-tree corruption in probe error path
- perf/x86/amd/core: Always use the NMI latency mitigation
- perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems
- perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains
- xfrm: fix NAT-related field inheritance in SA migration
- cxl/fwctl: Fix __fortify_panic
- drm/amdkfd: always resume_all after suspend_all
- of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array()
fails
- ocfs2: rebase copied fsdlm LVB pointers in locking_state
- lib: kunit_iov_iter: repeatedly call alloc_pages_bulk()
- ocfs2: fix buffer head management in ocfs2_read_blocks()
- ocfs2: reject FITRIM ranges shorter than a cluster
- ocfs2/dlm: require a ref for locking_state debugfs open
- ocfs2: fix race between ocfs2_control_install_private() and
ocfs2_control_release()
- netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures
- netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing
helper flags
- netfilter: synproxy: drop packets if timestamp adjustment fails
- netfilter: synproxy: adjust duplicate timestamp options
- netfilter: synproxy: fix unaligned memory access in timestamp adjustment
- netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock
- ALSA: usb-audio: qcom: Initialize offload control return value
- x86/cpu: Remove obsolete aperfmperf_get_khz() declaration
- netfilter: conntrack: revert ct extension genid infrastructure
- netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper
is pptp
- RDMA/hfi1: Open-code rvt_set_ibdev_name()
- IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path()
- ALSA: hda: fix Kconfig dependency of HD Audio PCI
- RDMA/irdma: Fix OOB read during CQ MR registration
- RDMA/irdma: Initialize iwmr->access during MR registration
- arm64: dts: imx8mp-kontron: Reduce EERAM SPI clock frequency
- arm64: dts: imx95: Correct PCIe outbound address space configuration
- arm64: dts: lx2162a-clearfog: use rev2 SoC dtsi
- arm64: dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as
well
- arm64: dts: imx8mp-kontron: Fix GPIO for display power switch
- bpf: Clear rb node linkage when freeing bpf_rb_root
- bpf: Check tail zero of bpf_map_info
- bpf: Check tail zero of bpf_prog_info
- bpf: Update transport_header when encapsulating UDP tunnel in lwt
- wifi: wcn36xx: fix heap overflow from oversized firmware HAL response
- wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO
indication
- wifi: wcn36xx: fix OOB read from short trigger BA firmware response
- ALSA: seq: Fix partial userptr event expansion
- riscv: cpu_ops: Change return value type of cpu_is_stopped() to bool
- riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe
- ALSA: seq: Clear variable event pointer on read
- bpf: Fix NMI/tracepoint re-entry deadlock on lru locks
- kunit:tool: Don't write to stdout when it should be disabled
- powerpc/8xx: implement get_direction() in cpm1
- bpf: Fix NULL pointer dereference in bpf_task_from_vpid()
- ACPI: IPMI: Fix message kref handling on dead device
- cpufreq: Documentation: fix conservative governor freq_step description
- thermal: testing: reject missing command arguments
- btrfs: don't force DIO writes to be serialized
- IB/mlx5: Don't take the rereg_mr fallback without a new translation
- IB/mlx5: Properly support implicit ODP rereg_mr
- IB/mlx5: Remove unused mkc bits in mlx5r_umr_update_mr_page_shift()
- IB/mlx5: Pull the pdn out of the depths of the umr machinery
- IB/mlx5: Don't mangle the mr->pd inside the rereg callback
- spi: ep93xx: fix double-free of zeropage on DMA setup failure
- ASoC: amd: acp-sdw-legacy: Bound DAI link iteration
- ASoC: amd: acp-sdw-sof: Bound DAI link iteration
- firmware_loader: Fix recursive lock in device_cache_fw_images()
- configfs: fix lockless traversals of ->s_children
- watchdog: unregister PM notifier on watchdog unregister
- pinctrl: qcom: Fix resolving register base address from device node
- scsi: target: Fix hexadecimal CHAP_I handling
- scsi: target: Remove tcm_loop target reset handling
- pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins
34-39
- pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins
34-39
- vmalloc: fix NULL pointer dereference in is_vm_area_hugepages()
- hwspinlock: qcom: avoid uninitialized struct members
- sched/fair: Fix cpu_util runnable_avg arithmetic
- ARM: configs: Drop duplicated CONFIG_EXT4_FS
- wifi: mt76: mt7925: clean up DMA on probe failure
- wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link
- wifi: mt76: mt7996: add missing max_remain_on_channel_duration
- wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links
- wifi: mt76: mt7925: keep TX BA state in the primary WCID
- wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX
- wifi: mt76: mt7925: validate skb length in testmode query
- wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb()
- wifi: mt76: mt7996: Fix possible NULL pointer dereference in
mt7996_mac_write_txwi_80211()
- wifi: mt76: mt7996: fix reading zeroed info->control.flags after
mt76_tx_status_skb_add()
- wifi: mt76: mt7996: limit work in set_bitrate_mask
- wifi: mt76: fix argument to ieee80211_is_first_frag()
- wifi: mt76: mt7915: fix potential tx_retries underflow
- wifi: mt76: mt7921: fix potential tx_retries underflow
- wifi: mt76: mt7925: fix potential tx_retries underflow
- wifi: mt76: mt7996: fix potential tx_retries underflow
- btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
- ALSA: aloop: Drop superfluous break
- gpio: mt7621: fix interrupt banks mapping on gpio chips
- wifi: ath12k: enable IEEE80211_VHT_EXT_NSS_BW_CAPABLE when NSS ratio is
reported
- fbdev: sm501fb: Fix buffer errors in OF binding code
- vfs: add FS_USERNS_DELEGATABLE flag and set it for NFS
- hwmon: (it87) Clamp negative values to zero in set_fan()
- btrfs: zoned: don't account data relocation space-info in statfs free
space
- Revert "btrfs: fix the file offset calculation inside
btrfs_decompress_buf2page()"
- btrfs: zoned: always set max_active_zones for zoned devices
- btrfs: annotate lockless read of defrag_bytes in should_nocow()
- btrfs: fix deadlock cloning inline extent when using flushoncommit
- igc: skip RX timestamp header for frame preemption verification
- ASoC: sma1307: Fix uevent string leaks in fault worker
- IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified
- NFSD: Handle layout stid in nfsd4_drop_revoked_stid()
- spi: meson-spifc: fix runtime PM leak on remove
- ASoC: codecs: aw88261: fix incorrect masks for boost regs
- vduse: hold vduse_lock across IDR lookup in open path
- vhost/vdpa: validate virtqueue index in mmap and fault paths
- virtio: rtc: tear down old virtqueues before restore
- virtio_console: read size from config space during device init
- vduse: Requeue failed read to send_list head
- tools/virtio: check mmap return value in vringh_test
- vdpa/octeon_ep: Fix PF->VF mailbox data address calculation
- vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
- ASoC: cs35l56: Fix missing calls to wm_adsp2_remove()
- ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails
- ext4: fix ERR_PTR(0) in ext4_mkdir()
- tools: missed broadcast_neigh if_link uapi header
- netlink: specs: rt-link: missed broadcast-neigh
- bonding: 3ad: add lacp_strict configuration knob
- bonding: 3ad: fix carrier when no usable slaves
- bonding: 3ad: fix mux port state on oper down
- ext4: fix kernel BUG in ext4_write_inline_data_end
- selftests/bpf: Fix bpf_iter/task_vma test
- cxl/test: Fix integer overflow in mock LSA bounds checks
- cxl/test: Zero out LSA backing memory to avoid leaking to user
- of: cpu: add check in __of_find_n_match_cpu_property()
- vfio/qat: fix f_pos race in qat_vf_resume_write()
- bpf: Tighten cgroup storage cookie checks for prog arrays
- pinctrl: sunxi: a523: Remove unneeded IRQ remuxing flag
- pinctrl: airoha: an7581: add missed gpio32 pin group
- pinctrl: airoha: an7581: fix misprint in gpio19 pinconf
- arm64: dts: allwinner: a523: Add missing GPIO interrupt
- ASoC: cs35l56: Fix possible uninitialized value in
cs35l56_spi_system_reset()
- s390/process: Fix kernel thread function pointer type
- Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for
non-serdev device
- Bluetooth: eir: Fix stack OOB write when prepending the Flags AD
- Bluetooth: hci_event: fix simultaneous discovery stuck in FINDING
- Bluetooth: hci_core: Fix UAF in hci_unregister_dev()
- Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path
- Bluetooth: hci: validate codec capability element length
- Bluetooth: vhci: validate devcoredump state before side effects
- fs: efs: remove unneeded debug prints
- RDMA/mlx5: Remove DCT restrack tracking
- RDMA/mlx5: Remove raw RSS QP restrack tracking
- RDMA/mlx5: Fix undefined shift of user RQ WQE size
- RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one
- ASoC: SOF: Intel: hda-sdw-bpt: select SND_SOF_SOF_HDA_SDW_BPT properly
- ASoC: codecs: hdac_hdmi: Validate written enum value
- ASoC: fsl: fsl_audmix: Validate written enum values
- ASoC: tegra: tegra210_ahub: Validate written enum value
- net: dsa: qca8k: fix led devicename when using external mdio bus
- net/sched: cls_flow: Dont expose folded kernel pointers
- net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().
- bridge: cfm: reject invalid CCM interval at configuration time
- net: pfcp: allocate per-cpu tstats for PFCP netdevs
- net/sched: sch_hfsc: Don't make class passive twice
- tipc: require net admin for TIPCv2 netlink mutators
- tipc: prevent snt_unacked underflow on CONN_ACK
- tipc: reject inverted service ranges from peer bindings
- cxl/test: Unregister cxl_acpi in cxl_test_init() error path
- cxl/test: Add check after kzalloc() memory in alloc_mock_res()
- crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
- crypto: cavium/cpt - fix DMA cleanup using wrong loop index
- crypto: rng - Free default RNG on module exit
- ALSA: usb-audio: qcom: Guard sideband endpoint removal
- ALSA: seq: Fix kernel heap address leak in bounce_error_event()
- spi: xilinx: use FIFO occupancy register to determine buffer size
- iommu: Avoid copying the user array twice in the full-array copy helper
- ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO
- power: supply: core: fix supplied_from allocations
- handshake: Require admin permission for DONE command
- virtio_net: do not allow tunnel csum offload for non GSO packets
- net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during
peek before restoring qlen
- net/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during
peek before restoring qlen
- net: mana: initialize gdma queue id to INVALID_QUEUE_ID
- net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check
- net: watchdog: fix refcount tracking races
- net: ethernet: mtk_wed: fix loading WO firmware for MT7986
- net/sched: sch_dualpi2: Add missing module alias
- bpf: Run generic devmap egress prog on private skb
- net/mlx5: Check max_macs devlink param value against max capability
- bpf: Fix setting retval to -EPERM for cgroup hooks not returning errno
- octeontx2-af: npc: Fix size of entry2cntr_map
- net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show()
- net: wwan: t7xx: check skb_clone in control TX
- dpll: fix stale iteration in dpll_pin_on_pin_unregister()
- dpll: send delete notification before unregister in on-pin rollback
- dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister()
- dpll: guard sync-pair removal on full pin unregister
- dpll: balance create/delete notifications in __dpll_pin_(un)register
- landlock: Fix unmarked concurrent access to socket family
- net: bcmgenet: Use weighted round-robin TX DMA arbitration
- net: airoha: Fix register index for Tx-fwd counter configuration
- net: airoha: Fix debugfs new-tuple display for IPv4 ROUTE entries
- kcm: use WRITE_ONCE() when changing lower socket callbacks
- ALSA: seq: oss: Serialize readq reset state with q->lock
- ALSA: seq: avoid stale FIFO cells during resize
- netfilter: nf_conncount: callers must hold rcu read lock
- ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait()
- cifs: remove all cifs files before kill super
- smb/client: always return a value for FS_IOC_GETFLAGS
- selftests/bpf: Fix typo in verify_umulti_link_info
- selftests/bpf: Initialize operation name before use
- bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket
- udf: fix nls leak on udf_fill_super() failure
- bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
- net: remove addr_len argument of recvmsg() handlers
- sockmap: Fix use-after-free in udp_bpf_recvmsg()
- bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check
- MIPS: mm: Fix out-of-bounds write in maar_res_walk()
- powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del
- powerpc/powernv: fix preempt count leak in
pnv_kexec_wait_secondaries_down
- powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus
- KEYS: Use acquire when reading state in keyring search
- tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)
- net: airoha: Fix always-true condition in PPE1 queue reservation loop
- net: ethernet: oa_tc6: Remove FCS size in RX frame
- ionic: Fix check in ionic_get_link_ext_stats
- RDMA/bnxt_re: Free SRQ toggle page after firmware teardown
- RDMA/bnxt_re: Avoid displaying the kernel pointer
- RDMA/bnxt_re: Fail DBR related page allocation UAPIs if the feature is
disabled
- ksmbd: fix use-after-free in same_client_has_lease()
- mfd: rsmu: Fix page register setup
- mfd: cs42l43: Sanity check firmware size
- ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write
- 9p: avoid returning ERR_PTR(0) from mkdir operations
- eventpoll: rename ep_remove_safe() back to ep_remove()
- eventpoll: expand top-of-file overview / locking doc
- eventpoll: rename attach_epitem() to ep_attach_file()
- eventpoll: split ep_insert() into alloc + register stages
- eventpoll: extract ep_deliver_event() from ep_send_events()
- eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers
- eventpoll: rename epi->next and txlist for clarity
- eventpoll: Fix epoll_wait() report false negative
- gpiolib: acpi: Only trigger ActiveBoth interrupts on boot
- i3c: master: svc: Fix missed IBI after false SLVSTART on NPCM845
- staging: nvec: fix use-after-free in nvec_rx_completed()
- perf debuginfo: Fix libdw API contract violations
- coresight: cti: Fix DT filter signals silently ignored
- soundwire: don't program SDW_SCP_BUSCLOCK_SCALE on a unattached
Peripheral
- soundwire: fix bug in sdw_add_element_group_count found by syzkaller
- coresight: ete: Always save state on power down
- coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore
- PCI/ASPM: Don't reconfigure ASPM entering low-power state
- PCI: Introduce named defines for PCI ROM
- PCI: Check ROM header and data structure addr before accessing
- x86/platform/olpc: xo15: Drop wakeup source on driver removal
- platform/x86: xo15-ebook: Fix wakeup source and GPE handling
- perf sched: Add missing mmap2 handler in timehist
- PCI: loongson: Do not ignore downstream devices on external bridges
- rust: alloc: fix assert in `Vec::reserve` doc test
- bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
- coresight: fix missing error code when trace ID is invalid
- clk: qcom: cmnpll: Account for reference clock divider
- phy: phy-can-transceiver: Check driver match and driver data against
NULL
- perf pmu: Skip test on Arm64 when #slots is zero
- clk: at91: sam9x7: Fix gmac_gclk clock definition
- soundwire: intel_ace2x: release bpt_stream when close it
- coresight: Fix source not disabled on idr_alloc_u32 failure
- mailbox: mpfs: fix check for syscon presence in mpfs_mbox_inbox_isr()
- mailbox: mtk-adsp: fix UAF during device teardown
- PCI: dwc: Fix signedness bug in fault injection test code
- perf build-id: Fix off-by-one bug when printing kernel/module build-id
- staging: most: video: avoid double free on video register failure
- usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
- usb: host: max3421: Reject hub port requests for non-existent ports
- perf test amd ibs: Fix incorrect kernel version check
- gpib: Fix inappropriate ioctl error return
- char: tlclk: fix use-after-free in tlclk_cleanup()
- gpib: fix double decrement of descriptor_busy in command_ioctl()
- clk: renesas: rzg2l: Rename iterator in for_each_mod_clock() to avoid
shadowing
- powerpc tools perf: Initialize error code in auxtrace_record_init
function
- PCI: qcom: Disable ASPM L0s for SA8775P
- perf header: Sanity check HEADER_EVENT_DESC attr.size before swap
- iio: light: si1133: reset counter to prevent race condition
- iio: light: si1133: prevent race condition on timeout
- iio: magnetometer: ak8975: fix potential kernel stack memory leak
- iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling
- iio: accel: mma8452: handle I2C read error(s) in mma8452_read()
- iio: tcs3472: power down chip on probe failure
- clk: at91: keep securam node alive while mapping it
- HID: logitech-hidpp: remove excess kernel-doc member in
hidpp_scroll_counter
- fs/ntfs3: add bounds check to run_get_highest_vcn()
- fs/ntfs3: fix mount failure on 64K page-size kernels
- drm/amd/display: Add missing kdoc for ALLM parameters
- thunderbolt: debugfs: Fix margining error counter buffer leak
- dmaengine: imx-sdma: Refine spba bus searching in probe
- dt-bindings: dma: nvidia,tegra186-gpc-dma: Make reset optional
- perf: Fix off-by-one stack buffer overflow in kallsyms__parse()
- perf annotate: Fix crashes on empty annotate windows
- perf tools: Guard test_bit from out-of-bounds sample CPU
- perf sched: Fix thread reference leak in latency_switch_event
- perf tools: Add bounds check to cpu__get_node()
- perf sched: Cap max_cpu at MAX_CPUS in timehist sample processing
- perf sched: Fix register_pid() overflow, strcpy, and BUG_ON
- perf mmap: Guard cpu__get_node() return in aio_bind()
- perf stat: Bounds-check CPU index in topology aggregation callbacks
- perf c2c: Bounds-check CPU and node IDs before bitmap and array access
- perf c2c: Bounds-check CPU IDs in setup_nodes() topology loop
- perf sched: Clean up idle_threads entry on init failure
- perf sched: Use thread__put() in free_idle_threads()
- perf sched: Replace BUG_ON and add NULL checks in replay event helpers
- perf mmap: Fix NULL deref in aio cleanup on alloc failure
- perf stat: Introduce perf_env__get_cpu_topology() to guard NULL env->cpu
- perf c2c: Fix use-after-free in he__get_c2c_hists() error path
- perf timechart: Fix cpu2y() OOB read on untrusted CPU index
- perf tools: Fix int16_t truncation of max_cpu_num in set_max_cpu_num()
- dt-bindings: clock: qcom: Add X1P42100 camera clock controller
- clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks
- mshv: add bounds check on vp_index in mshv_intercept_isr()
- dmaengine: qcom: gpi: set DMA_PRIVATE capability
- dmaengine: Fix possible use after free
- dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc
- dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor
- clk: qcom: a53: Corrected frequency multiplier for 1152MHz
- sunrpc: Fix error handling in rpc_sysfs_xprt_switch_add_xprt_store()
- pNFS/filelayout: fix cheking if a layout is striped
- NFSv4/pnfs: defer return_range callbacks until after inode unlock
- nfs: keep PG_UPTODATE clear after read errors in page groups
- NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect
errors
- NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in
pg_get_mirror_count_write
- PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro
- pwm: rzg2l-gpt: Add missing newlines to dev_err_probe() messages
- PCI: meson: Propagate devm_add_action_or_reset() failure
- PCI: meson: Add missing remove callback
- fs/ntfs3: resize log->one_page_buf when adopting on-disk page size
- platform/x86/intel/vsec: Decouple add/link helpers from PCI
- platform/x86/intel/vsec: Switch exported helpers from pci_dev to device
- platform/x86/intel/vsec: Return real error codes from registration path
- platform/x86/intel/vsec: Restore BAR fallback for header walk
- perf tools: Fix get_max_num() size_t underflow on empty sysfs file
- perf tools: Use scnprintf() in cpu_map__snprint() to prevent overflow
- perf tools: Use perf_env__get_cpu_topology() in machine__resolve()
- PCI: rcar-host: Remove unused LIST_HEAD(res)
- perf sched: Bounds-check prio before test_bit() in timehist
- perf sched: Fix idle-hist callchain display using wrong rb_first variant
- perf bpf: Use scnprintf() in snprintf_hex() and
synthesize_bpf_prog_name()
- perf hists: Fix snprintf() in hists__scnprintf_title() UID filter path
- xprtrdma: Fix ep kref imbalance on ADDR_CHANGE
- xprtrdma: Initialize re_id before removal registration
- xprtrdma: Check frwr_wp_create() during connect
- xprtrdma: Document and assert reply-handler invariants
- xprtrdma: Resize reply buffers before reposting receives
- xprtrdma: Sanitize the reply credit grant after parsing
- xprtrdma: Repost Receive buffers for malformed replies
- xprtrdma: Return sendctx slot after Send preparation failure
- perf s390: Fix TEXTREL in Python extension by compiling as PIC
- perf cs-etm: Queue context packets for frontend
- perf pmu: Fix pmu_id() heap underwrite on empty identifier file
- perf pmu: Fix perf_pmu__parse_scale/unit() OOB access on empty sysfs
file
- tools lib api: Fix missing null termination in filename__read_int/ull()
- perf symbols: Fix signed overflow in sysfs__read_build_id() size check
- perf symbols: Bounds-check .gnu_debuglink section data
- perf intel-pt: Fix snprintf size tracking bug in insn decoder
- perf tools: Fix thread__set_comm_from_proc() on empty comm file
- perf hwmon: Fix off-by-one null termination on sysfs reads
- perf hwmon: Use scnprintf() in hwmon_pmu__for_each_event()
- perf hwmon: Fix parse_hwmon_filename() strlcpy buffer overflow
- perf symbols: Bounds-check descsz in sysfs__read_build_id() GNU fallback
- perf hwmon: Guard label read against empty or failed reads
- perf tools: Use snprintf() in dso__read_running_kernel_build_id()
- tools lib api: Fix filename__write_int() writing uninitialized stack
data
- tools lib api: Fix mount_overload() snprintf truncation and toupper
range
- perf bpf: Add NULL check for btf__type_by_id() in
synthesize_bpf_prog_name()
- perf bpf: Fix map data leak in bpf_metadata_create() on alloc failure
- perf bpf: Fix metadata leak in perf_env__add_bpf_info() on duplicate
insert
- perf symbols: Add bounds checks to elf_read_build_id() note iteration
- perf symbols: Add bounds checks to read_build_id() note iteration in
minimal build
- dt-bindings: phy: sc8280xp-qmp-pcie: Disallow bifurcation register on
Purwa
- PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port()
- PCI: mediatek: Use actual physical address instead of virt_to_phys()
- phy: freescale: phy-fsl-imx8qm-lvds-phy: Fix missing
pm_runtime_disable() on probe error path
- PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when
no RAS DES capability
- Revert "PCI/MSI: Unmap MSI-X region on error"
- apparmor: fix shadowing of plabel that prevents cache from being updated
- apparmor: fix race in unix socket mediation when peer_path is used
- apparmor: fix refcount leak when updating the sk_ctx
- security/apparmor/apparmorfs.c: conditionally compile
get_loaddata_common_ref()
- apparmor: check label build before no_new_privs test
- apparmor: aa_label_alloc use aa_label_free on alloc failure
- SAUCE: Revert "UBUNTU: SAUCE: apparmor5.0.0 [41/57]: apparmor-next 7.1:
apparmor: fix rawdata_f_data implicit flex array"
- apparmor: fix rawdata_f_data implicit flex array
- SAUCE: Revert "UBUNTU: SAUCE: apparmor5.0.0 [38/57]: apparmor-next 7.1:
apparmor: grab ns lock and refresh when looking up changehat child
profiles"
- apparmor: grab ns lock and refresh when looking up changehat child
profiles
- SAUCE: Revert "UBUNTU: SAUCE: apparmor5.0.0 [44/57]: apparmor-next 7.1:
apparmor: fix potential UAF in aa_replace_profiles"
- apparmor: fix potential UAF in aa_replace_profiles
- SAUCE: Revert "UBUNTU: SAUCE: apparmor: fix NULL pointer dereference in
unpack_pdb"
- apparmor: fix NULL pointer dereference in unpack_pdb
- apparmor: remove or add symlinks to rawdata according to export_binary
- apparmor: Fix return in ns_mkdir_op
- apparmor: fail policy unpack on accept2 allocation failure
- apparmor: aa_getprocattr free procattr leak on format failure
- apparmor: put secmark label after secid lookup
- apparmor: don't audit files pointing to aa_null.dentry
- apparmor: fix uninitialised pointer passed to
audit_log_untrustedstring()
- i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring
- i3c: master: Make hot-join workqueue freezable to block hot-join during
suspend
- i3c: master: Move rstdaa error suppression
- i3c: master: Consolidate Hot-Join DAA work in the core
- i3c: master: Ensure Hot-Join operations are stopped on shutdown
- i3c: master: Defer new-device registration out of DAA caller context
- i3c: master: Prevent reuse of dynamic address on device add failure
- apparmor: fix label can not be immediately before a declaration
- accel/ivpu: fix HWS command queue leak on registration failure
- sparc: led: avoid trimming a newline from empty writes
- perf symbols: Fix bswap copy-paste error for 32-bit ELF p_filesz
- perf symbols: Validate p_filesz before use in filename__read_build_id()
- perf symbols: Break infinite loop on zero-filled notes in
sysfs__read_build_id()
- perf tools: Add O_CLOEXEC to open() calls in DSO and ELF code
- perf tools: Fix uninitialized pathname on uncompressed fallback in
filename__decompress()
- perf dso: Fix heap overflow in dso__get_filename() on decompressed path
- perf dso: Set error code when open() fails on uncompressed fallback path
- perf tools: Use snprintf() for root_dir path construction
- perf hwmon: Fix fd check to accept fd 0 in hwmon_pmu__describe_items()
- perf sched: Replace (void*)1 sentinel with proper runtime allocation
- perf bpf: Validate func_info_rec_size and sub_id in
synthesize_bpf_prog_name()
- perf bpf: Reject oversized BPF metadata events that truncate header.size
- perf bpf: Bounds-check array offsets in bpil_offs_to_addr()
- perf cs-etm: Reject CPU IDs that would overflow signed comparison
- gpio: mlxbf3: fail probe if gpiochip registration fails
- drm/i915: clear CRTC color blob pointers after dropping refs
- drm/xe: Fix wa_oob codegen recipe for external module builds
- spi: dw: fix wrong BAUDR setting after resume
- i3c: master: Update dev_nack_retry_count under maintenance lock
- i3c: master: Add missing runtime PM get in dev_nack_retry_count_store()
- ALSA: usb-audio: qcom: Free sideband sg_table objects
- xfrm: annotate data-races around xfrm_policy_count[] and
xfrm_policy_default[]
- xfrm: validate selector family and prefixlen during match
- perf machine: Use snprintf() for guestmount path construction
- perf cs-etm: Validate num_cpu before metadata allocation
- perf cs-etm: Require full global header in auxtrace_info size check
- perf cs-etm: Bounds-check CPU in cs_etm__get_queue()
- perf bpf: Validate array presence before casting BPF prog info pointers
- perf dso: Set standard errno on decompression failure
- ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode
- drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free
- drm/amd/display: Fix mem_type change detection for async flips
- drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm
- drm/amdgpu: initialize irq.lock spinlock earlier
- octeontx2-pf: Fix leak of SQ timestamp buffer on teardown
- net: psample: fix info leak in PSAMPLE_ATTR_DATA
- sctp: hold socket lock when dumping endpoints in sctp_diag
- ALSA: usb-audio: qcom: reject stream disable with no active interface
- ALSA: usb-audio: qcom: clear opened when stream enable fails
- PCI: iproc: Restore .map_irq() for the platform bus driver
- spi: rpc-if: Use correct device for hardware reinitialization on resume
- virtio-net: fix len check in receive_big()
- dpaa2-switch: fix VLAN upper check not rejecting bridge join
- devlink: Fix parent ref leak in devl_rate_node_create()
- devlink: Fix parent ref leak on tc-bw failure
- net: airoha: fix foe_check_time allocation size
- net: macb: add TX stall timeout callback to recover from lost TSTART
write
- flow_dissector: check device type before reading ETH_ADDRS
- selftests: vlan_bridge_binding: Fix flaky operational state check
- ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints
- arm64/hw_breakpoint: reject unaligned watchpoints that would truncate
BAS
- thermal: intel: Fix dangling resources on thermal_throttle_online()
failure
- ACPI: resource: Amend kernel-doc style
- ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone()
- ieee802154: Restore initial state on failed device_rename() in
cfg802154_switch_netns()
- ieee802154: Avoid calling WARN_ON() on -ENOMEM in
cfg802154_switch_netns()
- ieee802154: Remove WARN_ON() in cfg802154_pernet_exit()
- ieee802154: fix kernel-infoleak in dgram_recvmsg()
- mac802154: Prevent overwrite return code in
mac802154_perform_association()
- md/raid1: honor REQ_NOWAIT when waiting for behind writes
- md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on
retry
- netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
- netfilter: ipset: make sure gc is properly stopped
- netfilter: nft_payload: reject offsets exceeding 65535 bytes
- netfilter: nft_meta_bridge: add validate callback for get operations
- netfilter: nft_flow_offload: zero device address for non-ether case
- netfilter: nf_reject: skip iphdr options when looking for icmp header
- netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak
- mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx()
- irqchip/crossbar: Fix parent domain resource leak
- alloc_tag: fix use-after-free in /proc/allocinfo after module unload
- selftests/mm: restore default nr_hugepages value via exit trap in
charge_reserved_hugetlb.sh
- selftests/mm: restore default nr_hugepages value via exit trap in
hugetlb_reparenting_test.sh
- selftests/mm: fix hugetlb pathname construction in
hugetlb_reparenting_test.sh
- selftests/mm: fix cgroup task placement and drop memory.current checks
in hugetlb_reparenting_test.sh
- selftests/mm: size tmpfs according to PMD page size in
split_huge_page_test
- selftests/mm: free dynamically allocated PMD-sized buffers in
split_huge_page_test
- selftest/mm: register existing mapping with userfaultfd in hugetlb-
mremap
- selftests/mm: ensure destination is hugetlb-backed in hugetlb-mremap
- selftests/mm: skip uffd-stress test when nr_pages_per_cpu is zero
- selftests/mm: clarify alternate unmapping in compaction_test
- selftests/mm: allow PUD-level entries in compound testcase of hmm tests
- selftests/mm: fix exclusive_cow test fork() handling
- net: marvell: prestera: initialize err in prestera_port_sfp_bind
- tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
- net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths
- octeontx2-af: mcs: Fix unsupported secy stats read
- octeontx2-pf: Clear stats of all resources when freeing resources
- octeontx2-pf: mcs: Fix mcs resources free on PF shutdown
- net: emac: Fix NULL pointer dereference in emac_probe
- net/sched: act_ct: fix nf_connlabels leak on two error paths
- net: airoha: Fix skb->priority underflow in airoha_dev_select_queue()
- ipv6: ndisc: fix NULL deref in accept_untracked_na()
- dpaa2-switch: do not accept VLAN uppers while bridged
- rtc: abx80x: fix the RTC_VL_CLR clearing all status flags
- rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231
- bpf: Fix stack slot index in nospec checks
- bpftool: Fix vmlinux BTF leak in cgroup commands
- bpf: zero-initialize the fib lookup flow struct
- bpf: Fix effective prog array index with BPF_F_PREORDER
- power: sequencing: fix ABBA deadlock in pwrseq_device_unregister()
- gpiolib: initialize return value in gpiochip_set_multiple()
- drm/edid: fix OOB read in drm_parse_tiled_block()
- PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0
- PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0
- ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs()
- ice: fix AQ error code comparison in ice_set_pauseparam()
- ice: call netif_keep_dst() once when entering switchdev mode
- rtc: isl1208: Balance enable_irq_wake() with disable_irq_wake() on
cleanup
- ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info
- ice: dpll: fix memory leak in ice_dpll_init_info error paths
- i40e: Fix i40e_debug() to use struct i40e_hw argument
- rtc: msc313: fix NULL deref in shared IRQ handler at probe
- ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().
- eth: bnxt: rename ring_err_stats -> ring_drv_stats
- eth: bnxt: improve the timing of stats
- ipv4: fib: Don't ignore error route in local/main tables.
- md/raid5: use stripe state snapshot in break_stripe_batch_list()
- md/raid5: avoid R5_Overlap races while breaking stripe batches
- bpf: Disable xfrm_decode_session hook attachment
- netfilter: nf_nat: avoid invalid nat_net pointer use on failed
nf_nat_init()
- netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
- netfilter: nft_synproxy: stop bypassing the priv->info snapshot
- netfilter: nft_compat: ebtables emulation must reject non-bridge targets
- gpio: davinci: fix IRQ domain leak on devm_kzalloc failure
- NTB: epf: Make db_valid_mask cover only real doorbell bits
- NTB: epf: Report 0-based doorbell vector via ntb_db_event()
- NTB: epf: Fix doorbell bitmask and IRQ vector handling
- alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
- alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs
- net, bpf: check master for NULL in xdp_master_redirect()
- net: do not acquire dev->tx_global_lock in netdev_watchdog_up()
- net: dsa: sja1105: round up PTP perout pin duration
- veth: fix NAPI leak in XDP enable error path
- net: usb: lan78xx: restore VLAN and hash filters after link up
- ipv6: fix error handling in disable_ipv6 sysctl
- ipv6: fix error handling in ignore_routes_with_linkdown sysctl
- ipv6: fix error handling in forwarding sysctl
- ipv6: fix error handling in disable_policy sysctl
- ipv6: fix state corruption during proxy_ndp sysctl restart
- ipv6: fix missing notification for ignore_routes_with_linkdown
- eth: fbnic: fix ordering of heartbeat vs ownership
- thermal: testing: zone: Flush work items during cleanup
- ACPI: processor_idle: Mark LPI enter functions as __cpuidle
- smb/client: preserve errors from smb2_set_sparse()
- rtc: ds1307: Fix off-by-one issue with wday for rx8130
- rtc: cmos: unregister HPET IRQ handler on probe failure
- net: dsa: realtek: fix memory leak in rtl8366rb_setup_led()
- net: phy: realtek: Clear MDIO_AN_10GBT_CTRL_ADV10G bit
- octeontx2-af: Validate NIX maximum LFs correctly
- net: mvneta: re-enable percpu interrupt on resume
- net: sungem: fix probe error cleanup
- net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove
- LoongArch: Move struct kimage forward declaration before use
- LoongArch: BPF: Fix outdated tail call comments
- LoongArch: BPF: Fix off-by-one error in tail call
- ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count
- net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync
- dt-bindings: net: renesas,ether: Drop example "ethernet-phy-
ieee802.3-c22" fallback
- selftests: tls: size splice_short pipe by page size
- net: hns3: unify copper port ksettings configuration path
- net: hns3: refactor MAC autoneg and speed configuration
- net: hns3: fix permanent link down deadlock after reset
- net: hns3: differentiate autoneg default values between copper and fiber
- ALSA: FCP: Fix NULL pointer dereference in interface lookup
- tracing: probes: fix typo in a log message
- spi: sh-msiof: abort transfers when reset times out
- ACPI: RIMT: Only defer the IOMMU configuration in init stage
- riscv: Fix 32-bit call_on_irq_stack() frame pointer ABI
- gpio: mvebu: fail probe if gpiochip registration fails
- gpio: htc-egpio: use managed gpiochip registration
- net: pse-pd: scope pse_control regulator handle to kref lifetime
- seg6: validate SRH length before reading fixed fields
- qede: fix out-of-bounds check for cqe->len_list[]
- sctp: fix SCTP_RESET_STREAMS stream list length limit
- MIPS: DEC: Ensure RTC platform device deregistration upon failure
- MIPS: mm: Add check for highmem before removing memory block
- ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280
- hwmon: adm1275: Prevent reading uninitialized stack
- hwmon: (pmbus) Fix passing events to regulator core
- hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-
zero
- ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump
- usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()
- net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy
- net: libwx: fix VMDQ mask for 1-queue mode
- net: gianfar: dispose irq mappings on probe failure and device removal
- net/sched: sch_teql: Introduce slaves_lock to avoid race condition and
UAF
- bridge: stp: Fix a potential use-after-free when deleting a bridge
- drm/panthor: Fix potential invalid pointer deref in
group_process_tiler_oom()
- drm/panthor: Don't overrule pending immediate ticks in
sched_resume_tick()
- drm/panthor: Fix a leak when a group is evicted before the tiler OOM is
serviced
- drm/panthor: Interrupt group start/resumption if group_bind_locked()
fails
- tracing/eprobes: Allow use of BTF names to dereference pointers
- tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg
- tracing/events: Fix to check the simple_tsk_fn creation
- tracing: eprobe: read the complete FILTER_PTR_STRING pointer
- tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry()
- tracing/probes: Make the $ prefix mandatory for comm access
- irqchip/gic-v3-its: Fix OF node reference leak
- irqchip/ts4800: Fix missing chained handler cleanup on remove
- sctp: fix addr_wq_timer race in sctp_free_addr_wq()
- virtio_net: disable cb when NAPI is busy-polled
- cxgb4: Fix decode strings dump for T6 adapters
- selftests: drv-net: tso: don't touch dangerous feature bits
- net/sched: act_bpf: use rcu_dereference_bh() to read the filter
- ksmbd: reject undersized DACLs before parsing ACEs
- gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe
- pinctrl: meson: restore non-sleeping GPIO access
- net/sched: dualpi2: clear stale classification on filter miss
- net/sched: hhf: clear heavy-hitter state on reset
- fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid
- afs: Fix error code in afs_extract_vl_addrs()
- afs: Fix double netfs initialisation in afs_root_iget()
- afs: use kvfree() to free memory allocated by kvcalloc()
- afs: Remove erroneous seq |= 1 in volume lookup loop
- afs: Fix bulk lookup malfunction due to change in dir_emit() API
- afs: Fix misplaced inc of net->cells_outstanding
- afs: Fix reinitialisation of the inode, in particular ->lock_work
- afs: Fix callback service message parsers to pass through -EAGAIN
- afs: Fix missing NULL pointer check in afs_break_some_callbacks()
- afs: Fix vllist leak
- afs: Fix lack of locking around modifications of net->cells_dyn_ino
- afs: Fix premature cell exposure through /afs
- afs: Fix the volume AFS_VOLUME_RM_TREE is set on
- afs: Fix unchecked-length string display in debug statement
- minix: avoid overflow in bitmap block count calculation
- ovl: fix comment about locking order
- iomap: guard io_size EOF trim against concurrent truncate underflow
- netfs: Fix writethrough to use collection offload
- netfs: Fix writeback error handling
- netfs: Fix folio state after ENOMEM whilst under writeback iteration
- drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()
- drm/xe/userptr: Hold notifier_lock for write on inject test path
- drm/xe/hw_engine: Fix double-free of managed BO in error path
- drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays
- x86/uprobes: Keep shadow stack in sync for emulated CALLs
- uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline
- cifs: Fix missing credit release on failure in cifs_issue_read()
- ata: sata_gemini: unwind clocks on IDE pinctrl errors
- ata: libata-scsi: limit simulated SCSI command copy to response length
- HID: picolcd: prevent NULL pointer dereference in
picolcd_send_and_wait()
- HID: core: Fix OOB read in hid_get_report for numbered reports
- arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range()
- HID: bpf: Fix hid_bpf_get_data() range check
- selftests/hid: Load only requested struct_ops maps
- selftests/hid: Cover hid_bpf_get_data() size overflow
- arm64/sysreg: Fix BWE field encoding in ID_AA64DFR2_EL1
- net: usb: net1080: validate packet_len before pad-byte access in
rx_fixup
- netfilter: xt_u32: reject invalid shift counts
- netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()
- netfilter: nft_set_rbtree: get command skips end element with open
interval
- netfilter: xt_connmark: reject invalid shift parameters
- net/mlx5: LAG, MPESW, Fix missing complete() on devcom error
- net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation
- net/mlx5e: Fix HV VHCA stats agent registration race
- net/mlx5e: Fix publication race for priv->channel_stats[]
- net: microchip: vcap: fix races on the shared Super VCAP block
- net: qualcomm: rmnet: validate MAP frame length before ingress parsing
- net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload
- amt: fix size calculation in amt_get_size()
- Bluetooth: 6lowpan: hold L2CAP conn across debugfs control
- Bluetooth: MGMT: Fix adv monitor add failure cleanup
- Bluetooth: sco: Fix a race condition in sco_sock_timeout()
- Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length
- Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
- Bluetooth: L2CAP: fix tx ident leak for commands without a response
- ring-buffer: Fix event length with forced 8-byte alignment
- accel/amdxdna: Use unsigned long for nr_pages in amdxdna_hmm_register()
- net/tls: Consume empty data records in tls_sw_read_sock()
- net: usb: lan78xx: disable VLAN filter in promiscuous mode
- gpio: dwapb: reduce allocation to single kzalloc
- gpio: dwapb: Defer clock gating until noirq
- tracing: Make tracepoint_printk static as not exported
- accel/amdxdna: Fix potential amdxdna_umap lifetime race
- drm/v3d: Reject invalid indirect BO handle in indirect CSD setup
- net: mdio: select REGMAP_MMIO instead of depending on it
- net/sched: cake: reject overhead values that underflow length
- octeontx2-pf: check DMAC extraction support before filtering
- perf/x86/amd/core: Avoid enabling BRS from the SVM reload path
- gpio: mvebu: free generic chips on unbind
- ipv4: igmp: annotate data-races around im->users
- ipv4: igmp: annotate data-races around timer-related fields
- ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and
igmp_stop_timer()
- ipvs: pass parsed transport offset to state handlers
- ipvs: use parsed transport offset in TCP state lookup
- s390/zcrypt: Remove the empty file
- SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED
- dm era: fix NULL pointer dereference in metadata_open()
- regulator: core: regulator_lock_two() should test for EDEADLK not
EDEADLOCK
- selftests/net: fix EVP_MD_CTX leak in tcp_mmap
- net/mlx5: Fix L3 tunnel entropy refcount leak
- octeontx2-af: fix VF bringup affecting PF promiscuous state
- drm/xe: remove duplicate <kunit/test-bug.h> include
- smb: client: fix overflow in passthrough ioctl bounds check
- idpf: add padding to PTP virtchnl structures
- mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()
- mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()
- vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter
- ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put
- ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
- ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get
- ASoC: SOF: topology: validate vendor array size before parsing
- net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
- net: atm: reject out-of-range traffic classes in QoS validation
- octeontx2-pf: clear stale mailbox IRQ state before request_irq()
- octeontx2-vf: clear stale mailbox IRQ state before request_irq()
- arm64: fpsimd: Fix type mismatch in sve_{save,load}_state()
- arm64: dts: s32g3: Fix SWT8 watchdog address
- ARM: dts: imx6ul-var-som: fix warning for non-existent dc-supply
property
- arm64: dts: qcom: sdm630: describe adsp_mem region properly
- arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Ringneck
- ARM: dts: stm32: stm32mp15x-mecio1-io: Fix ADC sampling times
- ARM: dts: stm32: stm32mp15x-mecio1-io: Move divergent mecio1 ADC
channels to board files
- arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc
- ARM: dts: stm32: stm32mp15x-mecio1-io: Enable internal ADC reference
- arm64: dts: imx8ulp-evk: Correct Type-C int GPIO flags
- ARM: dts: stm32: stm32mp15x-mecio1-io: Fix GPIO names typo
- ARM: dts: stm32: stm32mp15x-mecio1-io: Move gpio-line-names to board
files
- ARM: dts: stm32: stm32mp15x-mecio1-io: Fix expander gpio line typo
- ARM: dts: stm32: stm32mp15x-mecio1-io: Move expander gpio-line-names to
board files
- LoongArch: KVM: Validate irqchip index in irqfd routing
- LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt()
- LoongArch: KVM: Check the return values for put_user()
- LoongArch: KVM: Fix FPU register width with user access API
- LoongArch: KVM: Return full old CSR value from kvm_emu_xchg_csr()
- powerpc/pseries/Kconfig: Enable CONFIG_VPA_PMU to be used with KVM
- KVM: s390: pci: Fix GISC refcount leak on AIF enable failure
- KVM: s390: pci: Fix handling of AIF enable without AISB
- KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs
- KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
- KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails
- KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid
guest state
- KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers
- KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2
- KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions
- KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
- fbdev: metronomefb: fix potential memory leak in metronomefb_probe()
- fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe()
- fbdev: hecubafb: fix potential memory leak in hecubafb_probe()
- fbdev: sm712: Fix operator precedence in big_swap macro
- fbdev: efifb: fix memory leak in efifb_probe()
- fbdev: radeon: fix potential memory leak in radeonfb_pci_register()
- fbdev: i740fb: fix potential memory leak in i740fb_probe()
- fbdev: s3fb: fix potential memory leak in s3_pci_probe()
- fbdev: uvesafb: fix potential memory leak in uvesafb_probe()
- fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe()
- fbdev: carminefb: fix potential memory leak in alloc_carmine_fb()
- fbdev: vesafb: fix memory leak in vesafb_probe()
- fbdev: nvidia: fix potential memory leak in nvidiafb_probe()
- fbdev: tridentfb: fix potential memory leak in trident_pci_probe()
- ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
- ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control
- ASoC: mediatek: mt8192: Check runtime resume during probe
- ASoC: mediatek: mt8192: Release reserved memory on cleanup
- ASoC: mediatek: mt8183: Check runtime resume during probe
- ASoC: mediatek: mt8183: Release reserved memory on cleanup
- ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback
- netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
- netfilter: nfnl_cthelper: apply per-class values when updating policies
- netfilter: xt_cluster: reject template conntracks in hash match
- netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst
- netfilter: nft_set_pipapo: don't leak bad clone into future transaction
- netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6
defrag
- netfilter: nf_conncount: fix zone comparison in tuple dedup
- netfilter: ecache: fix inverted time_after() check
- netfilter: xt_nat: reject unsupported target families
- netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
- gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error
path
- soc: ti: k3-ringacc: Fix access mode for
k3_ringacc_ring_pop_tail_io/proxy
- soc: fsl: qe: panic on ioremap() failure in qe_reset()
- selinux: check connect-related permissions on TCP Fast Open
- selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()
- selinux: fix incorrect execmem checks on overlayfs
- leds: uleds: Fix potential buffer overread
- mfd: sm501: Fix reference leak on failed device registration
- tools/power/x86/intel-speed-select: Harden daemon pidfile open
- x86/boot: Validate console=uart8250 baud rate to fix early boot hang
- x86/boot: Reject too long acpi_rsdp= values
- perf/x86/amd/brs: Fix kernel address leakage
- perf/x86/amd/lbr: Fix kernel address leakage
- cpufreq: schedutil: Fix uncleared need_freq_update on the .adjust_perf()
path
- cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF()
- s390/perf_cpum_cf: Add missing array_index_nospec() to
__hw_perf_event_init()
- batman-adv: gw: acquire ethernet header only after skb realloc
- batman-adv: retrieve ethhdr after potential skb realloc on RX
- batman-adv: dat: acquire ARP hw source only after skb realloc
- batman-adv: bla: reacquire gw address after skb realloc
- batman-adv: dat: ensure accessible eth_hdr proto field
- batman-adv: ensure minimal ethernet header on TX
- batman-adv: dat: fix tie-break for candidate selection
- batman-adv: tt: avoid request storms during pending request
- batman-adv: fix VLAN priority offset
- batman-adv: frag: free unfragmentable packet
- batman-adv: clean untagged VLAN on netdev registration failure
- batman-adv: frag: fix primary_if leak on failed linearization
- batman-adv: mcast: avoid OOB read of num_dests header
- cifs: invalidate cfid on unlink/rename/rmdir
- mfd: tps6586x: Fix OF node refcount
- HID: playstation: validate num_touch_reports in DualShock 4 reports
- Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready
- Bluetooth: SCO: hold sk properly in sco_conn_ready
- jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit()
- nvdimm/btt: Free arenas on btt_init() error paths
- nvdimm/btt: Free arena sub-allocations on discover_arenas() error path
- lockd: Plug nlm_file leak when nlm_do_fopen() fails
- lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure
- remoteproc: qcom: Fix leak when custom dump_segments addition fails
- MIPS: ip22-gio: fix gio device memory leak
- MIPS: ip22-gio: fix kfree() of static object
- MIPS: ip22-gio: fix device reference leak in probe
- MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf()
- mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages
- power: supply: cpcap-battery: Fix missing nvmem_device_put() causing
reference leak
- power: supply: max17042: fix OF node reference imbalance
- mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch
- mm/memory_hotplug: fix incorrect altmap passing in error path
- mm/damon/core: make charge_addr_from aware of end-address exclusivity
- fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename
- fs/ntfs3: bound DeleteIndexEntryAllocation memmove length
- fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass
- fs/ntfs3: bound attr_off in UpdateResidentValue against data_off
- fs/ntfs3: validate lcns_follow in log_replay conversion
- fs/ntfs3: bound NTFS_DE view.data_off in
UpdateRecordData{Root,Allocation}
- ntfs3: cap RESTART_TABLE free-chain walker at rt->used
- ntfs3: fix out-of-bounds read in decompress_lznt
- landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path
- power: supply: charger-manager: fix refcount leak in is_full_charged()
- selftests/landlock: Test SCOPE_SIGNAL on the SIGIO/fowner pgid path
- mips: sched: Fix CPUMASK_OFFSTACK memory corruption
- riscv: cacheinfo: Fix node reference leak in populate_cache_leaves
- mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs()
- mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error
- fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()
- fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry()
- proc: only bump parent nlink when registering directories
- fs/proc: fix KPF_KSM reported for all anonymous pages
- powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later
processors
- mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE
- kcov: use WRITE_ONCE() for selftest mode stores
- mtd: slram: remove failed entries from the device list
- 9p: skip nlink update in cacheless mode to fix WARN_ON
- power: supply: bq257xx: Fix VSYSMIN clamping logic
- scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished()
- scsi: sas: Skip opt_sectors when DMA reports no real optimization hint
- openrisc: Add full instruction cache invalidate functions
- ocfs2: use kzalloc for quota recovery bitmap allocation
- mtd: rawnand: pl353: fix probe resource allocation
- net/9p: fix infinite loop in p9_client_rpc on fatal signal
- mtd: rawnand: fix condition in 'nand_select_target()'
- ocfs2: avoid moving extents to occupied clusters
- ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits
- ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec
- ocfs2: add journal NULL check in ocfs2_checkpoint_inode()
- ocfs2: reject dinodes with non-canonical i_mode type
- ocfs2: reject dinodes whose i_rdev disagrees with the file type
- ocfs2: reject non-inline dinodes with i_size and zero i_clusters
- fpga: dfl: add bounds check in dfh_get_param_size()
- bus: mhi: host: pci_generic: Fix the physical function check
- bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path
- net: thunderbolt: Fix frags[] overflow by bounding frame_count
- fpga: microchip-spi: fix zero header_size OOB read in
mpf_ops_parse_header()
- s390/pkey: Check length in PKEY_VERIFYPROTK ioctl
- s390/pkey: Check length in pkey_pckmo handler implementation
- mtd: spi-nor: swp: Improve locking user experience
- mtd: spi-nor: spansion: use die erase for multi-die devices only
- mtd: rawnand: Pause continuous reads at block boundaries
- openrisc: Fix jump_label smp syncing
- mtd: maps: vmu-flash: fix NULL pointer dereference in initialization
- taskstats: retain dead thread stats in TGID queries
- irqchip/crossbar: Use correct index in crossbar_domain_free()
- tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat()
- tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt
- sunrpc: fix uninitialized xprt_create_args structure
- dmaengine: tegra: Fix burst size calculation
- dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and
ABORT_INT_MASK
- platform/x86: dell-laptop: fix missing cleanups in init error path
- platform/x86: ISST: Restore SST-PP control to all domains
- platform/x86/amd/pmc: Check for intermediate wakeup in function
- platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops
- platform/x86/amd/pmc: Add delay_suspend module parameter
- platform/x86/amd/pmc: Don't log during intermediate wakeups
- pkey: Move keytype check from pkey api to handler
- smb: client: use kvzalloc() for megabyte buffer in simple fallocate
- ksmbd: fix integer overflow in set_file_allocation_info()
- hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig
- hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig
- i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
- i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ)
- i2c: mediatek: fix WRRD for SoCs without auto_restart option
- i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource()
- i2c: spacemit: fix spurious IRQ handling returning IRQ_HANDLED
- ice: fix ice_init_link() error return preventing probe
- tcp: Decrement tcp_md5_needed static branch
- ufs: core: tracing: Do not dereference pointers in TP_printk()
- xen/gntdev: fix error handling in ioctl
- xfrm: use compat translator only for u64 alignment mismatch
- xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for
changelink
- tpm: fix event_size output in tpm1_binary_bios_measurements_show
- tpm: Make the TPM character devices non-seekable
- time: Fix off-by-one in compat settimeofday() usec validation
- spi: uniphier: Fix completion initialization order before
devm_request_irq()
- NFS: Charge unstable writes by request size, not folio size
- nvme-apple: Prevent shared tags across queues on Apple A11
- nvmet: fix refcount leak in nvmet_sq_create()
- netdev-genl: report NAPI thread PID in the caller's pid namespace
- can: esd_usb: kill anchored URBs before freeing netdevs
- can: isotp: use unconditional synchronize_rcu() in isotp_release()
- can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER
- can: isotp: serialize TX state transitions under so->rx_lock
- can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF
- can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure
- can: bcm: add missing rcu list annotations and operations
- bpf: Reset register bounds before narrowing retval range in
check_mem_access()
- bpf,fork: wipe ->bpf_storage before bailouts that access it
- bpf: Add missing access_ok call to copy_user_syms
- block: remove redundant GD_NEED_PART_SCAN in add_disk_final()
- block: fix race in blk_time_get_ns() returning 0
- block: fix IORING_URING_CMD_REISSUE flags check in blkdev_uring_cmd
- net: sparx5: unregister blocking notifier on init failure
- dm thin metadata: fix superblock refcount leak on snapshot shadow
failure
- dm thin metadata: fix metadata snapshot consistency on commit failure
- dm era: fix out-of-bounds memory access for non-zero start sector
- dm-bufio: fix wrong count calculation in dm_bufio_issue_discard
- dm-ioctl: fix a possible overflow in list_version_get_info
- dm-log: fix a bitset_size overflow on 32bit machines
- dm-pcache: reject option groups without values
- dm-stats: fix dm_jiffies_to_msec64
- dm-stats: fix merge accounting
- dm_early_create: fix freeing used table on dm_resume failure
- dm-integrity: fix leaking uninitialized kernel memory
- dm-integrity: fix a bug if the bio is out of limits
- dm-integrity: don't increment hash_offset twice
- dm-verity: avoid double increment of &use_bh_wq_enabled
- dm-verity: fix a possible NULL pointer dereference
- dm-verity: increase sprintf buffer size
- dm-verity: make error counter atomic
- dma-fence: Make dma_fence_dedup_array() robust against 0-count input
- accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap()
- accel/ivpu: Reject firmware log with size smaller than header
- scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path
- scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()
- scsi: sg: Report request-table problems when any status is set
- scsi: xen: scsiback: Free the command tag on the TMR submit-failure path
- scsi: elx: efct: Fix refcount leak in efct_hw_io_abort()
- scsi: elx: efct: Fix I/O leak on unsupported additional CDB
- Input: ims-pcu - fix use-after-free and double-free in disconnect
- Input: ims-pcu - only expose sysfs attributes on control interface
- Input: ims-pcu - release data interface on disconnect
- Input: ims-pcu - validate control endpoint type
- Input: ims-pcu - add response length checks
- Input: ims-pcu - fix DMA mapping violation in line setup
- Input: ims-pcu - fix firmware leak in async update
- Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging
- Input: ims-pcu - fix potential infinite loop in CDC union descriptor
parsing
- Input: ims-pcu - fix race condition in reset_device sysfs callback
- Input: ims-pcu - fix type confusion in CDC union descriptor parsing
- net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete
- tracing/user_events: Fix use-after-free in user_event_mm_dup()
- wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
- posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()
- selftests/ftrace: Drop invalid top-level local in test_ownership
- cpu: hotplug: Preserve per instance callback errors
- cpu: hotplug: Bound hotplug states sysfs output
- gpio: mt7621: more robust management of IRQ domain teardown
- gpio: tegra: do not call pinctrl for GPIO direction
- gpio: mt7621: be sure IRQ domain is created before exposing GPIO chips
- gpio-f7188x: Add support for NCT6126D version B
- gpio: mt7621: avoid corruption of shared interrupt trigger state
- gpios: palmas: add .get_direction() op
- net: sit: require CAP_NET_ADMIN in the device netns for changelink
- net: ethernet: ti: icssg: guard PA stat lookups
- net: wwan: t7xx: destroy DMA pool on CLDMA late init failure
- net: ixp4xx_hss: fix duplicate HDLC netdev allocation
- net/sched: act_ct: preserve tc_skb_cb across defragmentation
- selftests: net: fix file owner for broadcast_ether_dst test
- net: ena: clean up XDP TX queues when regular TX setup fails
- net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
- net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
- net: ipip: require CAP_NET_ADMIN in the device netns for changelink
- net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
- net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for
changelink
- octeontx2-af: Free BPID bitmap on setup failure
- ieee802154: admin-gate legacy LLSEC dump operations
- ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation
- ieee802154: ca8210: fix cas_ctl leak on spi_async failure
- ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit
- platform/x86/amd/pmc: Avoid logging "(null)" for DMI values
- net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants
- drm/xe/userptr: Stub notifier_lock helpers when DRM_GPUSVM=n
- pwm: rzg2l-gpt: Fix period_ticks type from u32 to u64
- LoongArch: Fix nr passing in set_direct_map_valid_noflush()
- LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()
- ipmi: Fix user refcount underflow in event delivery
- ipmi: fix refcount leak in i_ipmi_request()
- bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()
- rtc: renesas-rtca3: Fix PIE clear polling condition in alarm setup error
path
- rtc: mpfs: fix counter upload completion condition
- hwmon: (w83627hf) remove VID sysfs files on error and remove
- hwmon: (w83793) remove vrm sysfs file on probe failure
- net: liquidio: fix BAR resource leak on PF number failure
- hwmon: (occ) unregister sysfs devices outside occ lock
- fsl/fman: Free init resources on KeyGen failure in fman_init()
- net: lan743x: Initialize eth_syslock spinlock before use
- net/sched: sch_multiq: Replace direct dequeue call with peek and
qdisc_dequeue_peeked
- net/sched: sch_taprio: Replace direct dequeue call with peek and
qdisc_dequeue_peeked
- fhandle: reject detached mounts in capable_wrt_mount()
- hwmon: (max1619) add missing 'select REGMAP' to Kconfig
- tracing/probes: Fix double addition of offset for @+FOFFSET
- net/mlx5: HWS, fix matcher leak on resize target setup failure
- ata: pata_pxa: Fix DMA channel leak on probe error
- net: wwan: iosm: bound device offsets in the MUX downlink decoder
- hwmon: (asus_atk0110) Check package count before accessing element
- riscv: probes: save original sp in rethook trampoline
- mm/compaction: handle free_pages_prepare() properly in compaction_free()
- irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure
- s390/monwriter: Reject buffer reuse with different data length
- mac802154: remove interfaces with RCU list deletion
- octeontx2-pf: fix SQB pointer leak on init failure
- selftests: net: make busywait timeout clock portable
- llc: fix SAP refcount leak in llc_ui_autobind()
- ipvs: use parsed transport offset in SCTP state lookup
- macsec: don't read an unset MAC header in macsec_encrypt()
- dibs: loopback: validate offset and size in move_data()
- net: macb: drop in-flight Tx SKBs on close
- arm64: smp: Fix hot-unplug tearing by forcing unregistration
- cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable()
- fs/resctrl: Free mon_data structures on rdt_get_tree() failure
- fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
- ata: libata-core: Skip HPA resize for locked drives
- ata: libata-core: Allow capacity transition to zero for locked drives
- riscv: Prevent NULL pointer dereference in machine_kexec_prepare()
- tracing/osnoise: Call synchronize_rcu() when unregistering
- s390/diag: Add missing array_index_nospec() call to
memtop_get_page_count()
- s390/mm: Fix type mismatch in get_align_mask().
- selftests/rseq: Fix a building error for riscv arch
- cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed
- pmdomain: imx: Fix i.MX8MP power notifier
- pmdomain: imx: Fix i.MX8MP VC8000E power up sequence
- selftests/landlock: Skip scoped_signal subtest with MSG_OOB if not
available
- selftests/landlock: Fix screwed up pointers in the scoped_signal_test
- mmc: sdhci-esdhc-imx: restore pinctrl before restoring ios timing on
resume
- powerpc/pseries: fix memory leak on krealloc failure in papr_init
- net/mlx5: free mlx5_st_idx_data on final dealloc
- wifi: rt2x00: avoid full teardown before work setup in probe
- wifi: mwifiex: fix roaming to different channel in host_mlme mode
- wifi: mac80211: fix memory leak in ieee80211_register_hw()
- wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
- riscv: vdso: Do not use LTO for the vDSO
- regulator: ltc3676: Fix incorrect IRQSTAT bit offsets
- Bluetooth: btrtl: validate firmware patch bounds
- llc: fix SAP refcount leak when creating incoming sockets
- macsec: fix promiscuity refcount leak in macsec_dev_open()
- memstick: ms_block: reject a card that reports too many blocks
- reset: sunxi: fix memory region leak on ioremap failure
- powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()
- wifi: cfg80211: validate EHT MLE before MLD ID read
- wifi: ieee80211: validate MLE common info length
- wifi: mac80211: free ack status frame on TX header build failure
- wifi: mwifiex: fix permanently busy scans after multiple roam iterations
- mtd: onenand: samsung: report DMA completion timeouts
- mtd: mchp23k256: use SPI match data for chip caps
- mmc: vub300: defer reset until cmd_mutex is unlocked
- mtd: rawnand: fsl_ifc: return errors for failed page reads
- mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout
- mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout
- mmc: block: fix RPMB device unregister ordering
- mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe()
method
- mmc: sdhci-esdhc-imx: remove unnecessary mmc_card_wake_sdio_irq check
for tuning save/restore
- mmc: sdhci-esdhc-imx: restore DLL override for DDR modes on resume
- mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state
restore
- mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled
interrupt
- mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend
- mmc: sdhci-esdhc-imx: make non-fatal errors non-blocking in suspend
- mmc: sdhci-esdhc-imx: fix resume error handling
- crypto: xilinx-trng - Remove crypto_rng interface
- ACPI: bus: Introduce devm_acpi_install_notify_handler()
- ACPI: NFIT: core: Use devm_acpi_install_notify_handler()
- ACPI: NFIT: core: Fix possible deadlock and missing notifications
- iio: hid-sensor-rotation: Fix stale or zero output when reading raw
values
- ALSA: scarlett2: Allow selecting config_set by firmware version
- ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417
- firmware_loader: Add cancel helper for async requests
- ALSA: hda/tas2781: Cancel async firmware request at unbind
- binder: Use LIST_HEAD() to initialize on stack list head
- binder: cache secctx size before release zeroes it
- staging: rtl8723bs: fix spaces around binary operators
- Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister
- Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()
- proc: rename proc_setattr to proc_nochmod_setattr
- usb: dwc3: Support USB3340x ULPI PHY high-speed negotiation.
- usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()
- usb: atm: ueagle-atm: use dev_dbg() for 'device found' message
- usb: atm: ueagle-atm: remove function entry/exit debug messages
- usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()
- btrfs: remove folio parameter from ordered io related functions
- KVM: arm64: Ensure level is always initialized when relaxing perms
- KVM: arm64: Fix propagation of TLBI level in
kvm_pgtable_stage2_relax_perms()
- mm/damon/core: always put unsuccessfully committed target pids
- mm/damon/core: trace esz at first setup
- samples/damon/mtier: fail early if address range parameters are invalid
- perf callchain: Handle multiple address spaces
- soc: fsl: qe_ports_ic: Add missing cleanup on device removal
- drm/rockchip: inno-hdmi: Switch to drmm_kzalloc()
- accel/amdxdna: Create shared functions for AIE2 and AIE4
- Revert "UBUNTU: SAUCE: accel/amdxdna: Support sensors for column
utilization"
- accel/amdxdna: Support sensors for column utilization
- accel/amdxdna: Adjust size for copy_to_user()
- accel/amdxdna: Handle DETACH_DEBUG_BO through config_debug_bo path
- accel/amdxdna: Fix order of canceled mailbox messages
- accel/amdxdna: Guard management mailbox channel cleanup against NULL
pointer
- drm/amdkfd: fix redundant MQD iterations in GFX v12.1
- wifi: ath12k: Fix invalid IRQ requests during AHB probe
- libbpf: Fix deduplication of typedef with base definitions
- spi: atcspi200: Use helper function devm_clk_get_enabled()
- spi: atcspi200: fix use-after-free when driver unbind
- arm64: dts: rockchip: Fix vdec register blocks order on RK3576
- arm64: dts: rockchip: Update vdec register blocks order on RK3588
- dt-bindings: net: bluetooth: qualcomm: Fix WCN6855 regulator names
- x86/bug: Add printf() validation to HAVE_ARCH_BUG_FORMAT_ARGS WARNs
- arm64: dts: qcom: milos: Reduce rmtfs_mem size to 2.5MiB
- arm64: dts: qcom: sdm845-oneplus: Drop address from framebuffer node
- arm64: dts: qcom: sdm845-shift-axolotl: Correct touchscreen sleep state
- soc: xilinx: Fix race condition in event registration
- wifi: ath11k: cancel SSR work items during PCI shutdown
- ixgbe: fix unaligned u32 access in ixgbe_update_flash_X550()
- objtool/klp: Fix is_uncorrelated_static_local() for Clang
- objtool/klp: Fix .data..once static local non-correlation
- objtool/klp: Fix create_fake_symbols() skipping entsize-based sections
- objtool/klp: Fix handling of zero-length .altinstr_replacement sections
- objtool/klp: Fix cloning of zero-length section symbols
- objtool/klp: Fix extraction of text annotations for alternatives
- objtool/klp: Fix relocation conversion failures for R_X86_64_NONE
- objtool/klp: Use sym->demangled_name for symbol_name hash
- objtool/klp: Match symbols based on demangled_name for global variables
- objtool: Replace iterator callback with for_each_sym_by_mangled_name()
- objtool: Fix reloc hash collision in find_reloc_by_dest_range()
- klp-build: Fix hang on out-of-date .config
- klp-build: Fix checksum comparison for changed offsets
- riscv: dts: microchip: gpio controllers on mpfs need 2 interrupt cells
- riscv: dts: microchip: remove gpio hogs from beaglev-fire
- wifi: cfg80211: restrict LMR feedback check to TB and non-TB ranging
- drm/panel: Clean up SOFEF00 config dependencies
- drm/panel: Clean up S6E3FC2X01 config dependencies
- arm64: dts: marvell: samsung-coreprimevelte: Increase touchscreen
voltage
- arm64: dts: imx8mn-vhip4-evalboard-v1: Correct interrupt flags
- arm64: dts: imx8mn-vhip4-evalboard-v2: Correct interrupt flags
- crypto: ccp - Check for page allocation failure correctly in TIO
- crypto: ccp - Initialize data during __sev_snp_init_locked()
- accel/amdxdna: Fix clflush buffer size
- ntb: Store original DMA address for future release
- ntb: Use consistent DMA attributes when freeing DMA mappings
- riscv: dts: spacemit: k3: add clock tree
- dts: riscv: spacemit: correct 32k clock frequency
- arm64: dts: qcom: sdm660: set cdsp compute-cbs' regs properly
- arm64: dts: qcom: sdm630: set adsp compute-cbs' regs properly
- arm64: dts: qcom: lemans: Move PCIe devices into soc node
- sockptr: fix usize check in copy_struct_from_sockptr() for user pointers
- arm64: dts: mediatek: mt7988a-bpi-r4pro: rework pcie gpio-hog handling
- rhashtable: give each instance its own lockdep class
- thermal: hwmon: Register a hwmon device for each thermal zone
- crypto: ccp/sev-dev-tsm - bail out early when pdev->bus is NULL
- crypto: safexcel - Fix potential memory leak in safexcel_pci_probe()
- net/sched: add qdisc_qlen_inc() and qdisc_qlen_dec()
- net/sched: sch_dualpi2: annotate data-races in dualpi2_dump_stats()
- tools/rtla: Fix --dump-tasks usage in timerlat
- rtla: Stop the record trace on interrupt
- dm: limit target bio polling to one shot
- selftests/bpf: Override EXTRA_LDFLAGS for static builds
- sched/fair: Update util_est after updating util_avg during dequeue
- hfs: fix incorrect inode ID assignment in hfs_new_inode()
- vfio: selftests: Fix out-of-tree build with make O=
- vfio: selftests: Allow builds when ARCH=x86
- vfio/xe: avoid duplicate reset in xe_vfio_pci_reset_done
- arm64: dts: qcom: kaanapali: Add power-domain and iface clk for ice node
- arm64: dts: qcom: sdm845-xiaomi-beryllium: Correct IPA FW path
- ASoC: mediatek: mt8189: Fix probe resource cleanup
- drm/msm/mdss: correct UBWC programming sequences
- tools/nolibc: stackprotector: Avoid stalling program startup if crng is
not init yet
- ASoC: dapm: Fix widget lookup with prefixed names across DAPM contexts
- ACPI: PAD: Fix teardown ordering in acpi_pad_remove()
- wifi: ath12k: fix error unwind on arch_init() failure in PCI probe
- cpufreq: governor: Fix data races on per-CPU idle/nice baselines
- cpufreq: governor: Fix stale prev_cpu_nice spike when enabling
ignore_nice_load
- dt-bindings: vendor-prefixes: Add Verbatim Corporation
- drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info
- rust: devres: add 'static bound to Devres<T>
- lib/base64: validate before writing in decode tail path
- rust: uaccess: use INLINE_COPY_TO_USER to guard copy_to_user()
- uaccess: unify inline vs outline copy_{from,to}_user() selection
- uaccess: minimize INLINE_COPY_USER-related ifdefery
- crypto: ccp/tsm - Enable the root port after the endpoint
- firmware: samsung: acpm: Add devm_acpm_get_by_phandle helper
- firmware: samsung: acpm: remove compile-testing stubs
- drm/msm/a8xx: Make a8xx_recover IFPC safe
- drm/msm/a8xx: Fix RSCC offset
- EDAC/igen6: Fix memory topology parsing for Panther Lake-H SoCs
- arm: dts: bcm2711: Fix typo in gpio-line-names
- arm64: dts: renesas: r8a78000: Fix GIC-720AE View 1 Redistributor
description
- arm64: dts: renesas: ironhide: Describe all reserved memory
- md: replace wait loop with wait_event() in md_handle_request()
- md/raid1,raid10: fix deadlock in read error recovery path
- md/raid1,raid10: fix error-path detection with md_cloned_bio()
- md/raid1,raid10: fix bio accounting for split md cloned bios
- liveupdate: Use refcount_t for FLB reference counts
- liveupdate: Reference count incoming FLB data
- liveupdate: skip serialization for context-preserving kexec
- liveupdate: fix TOCTOU race in luo_session_retrieve()
- liveupdate: block session mutations during reboot
- spi: imx: replace dmaengine_terminate_all() with
dmaengine_terminate_sync()
- wifi: ath12k: fix memory leak in ath12k_wifi7_dp_rx_h_verify_tkip_mic()
- wifi: ath12k: fix inconsistent arvif state in vdev_create error paths
- ACPI: button: Fix lid_device value leak past driver removal
- drm/amd/pm: Add empty string validation to sysfs store functions
- accel/amdxdna: Return errors for failed debug BO commands
- mm: preserve PG_dropbehind flag during folio split
- perf/x86/intel/uncore: Fix PCI device refcount leak in UPI discovery
- wifi: wlcore: enable the right set of ciphers
- cxl/test: Fix __fortify_panic
- bpf: Take mmap_lock in zap_pages()
- ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent
- cxl/pci: Fix the incorrect check of pci_read_config_word() return
- cxl/pci: Convert PCIBIOS errors to errno on DVSEC config accesses
- netfilter: cttimeout: detach dataplane timeout policy and repurpose
refcount
- arm64: dts: imx94: fix DDR PMU interrupt number
- arm64: dts: freescale: fsl-ls1028a-tqmls1028a-mbls1028a: switch mmc
aliases
- selftests/bpf: Fix flaky file_reader test
- riscv: alternative: Use IS_ENABLED() over ifdeffery for
apply_vdso_alternatives()
- riscv: alternative: Pass vDSO start as parameter to
apply_vdso_alternatives()
- riscv: alternative: Also patch the CFI vDSO
- bpf: Verifier support for sleepable tracepoint programs
- bpf: Reject sleepable BPF_LSM_CGROUP programs at load time
- netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag
- filelock: fix break_lease() stub signature for CONFIG_FILE_LOCKING=n
- wifi: mac80211: bound S1G TIM PVB walk to the TIM element
- ACPI: processor: Add cpuidle driver check in
acpi_processor_register_idle_driver()
- RDMA/nldev: Fix locking when accessing mr->pd
- scsi: ufs: core: Handle PM commands timeout before SCSI EH
- iommufd: Destroy the pages content after detaching from dmabuf
- lib/test_hmm: fix memory leak in dmirror_migrate_to_system()
- rust: kbuild: show the right `quiet_cmd_rustc_procmacrolibrary`
- remoteproc: qcom_q6v5_wcss: drop redundant wcss_q6_bcr_reset
- wifi: mt76: mt7996: remove redundant pdev->bus check in probe
- wifi: ath12k: fix EAPOL TX failure caused by stale tcl_metadata bits
- memory: tegra186-emc: stop borrowing MC aggregate hook for EMC
- PM: QoS: Fix misc device registration unwind
- btrfs: lzo: reject compressed segment that overflows the compressed
input
- ixgbe: do not configure xps for XDP queues
- bpf: Cancel special fields on map value recycle
- clocksource: move NXP timer selection to drivers/clocksource
- [Config] Allow certain NXP timer selections for arm64
- vduse: fix compat handling for VDUSE_IOTLB_GET_FD/VDUSE_VQ_GET_INFO
- iomap: pass the correct len to fserror_report_io in __iomap_write_begin
- ASoC: cs35l56: Prevent double-free of debugfs
- ASoC: cs35l56: Cleanup if component_probe fails
- hwmon: (gpd-fan): drop global driver data and use per-device allocation
- hwmon: (gpd-fan): Initialize EC before registering hwmon device
- hwmon: (gpd-fan): fix race condition between device removal and sysfs
access
- ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT
- cxl/test: Verify cmd->size_in before accessing payload
- m68k: mcf5441x: fix clocks numbering
- pinctrl: airoha: an7583: add missed gpio32 pin group
- pinctrl: airoha: an7583: fix misprint in gpio19 pinconf
- pinctrl: airoha: an7581: fix incorrect led mapping in phy4_led1 pin
function
- pinctrl: airoha: an7583: fix incorrect led mapping in phy4_led1 pin
function
- pinctrl: airoha: fix pwm pin function for an7581 and an7583
- pinctrl: airoha: an7583: fix gpio21 pin group
- pinctrl: airoha: an7583: add missed gpio22 pin group
- pinctrl: airoha: an7583: fix phy1_led1 pin function
- pinctrl: airoha: an7583: remove undefined groups from pcm_spi pin
function
- Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-
serdev device
- Bluetooth: btintel: Replace CNVi id with hardware variant
- Bluetooth: btintel: Add DSBR support for ScP2 onwards
- Bluetooth: btintel_pcie: Load IOSF debug regs by controller variant
- ASoC: cs35l56: Fix wrong error test on simple_write_to_buffer()
- ASoC: SOF: Intel: select SND_SOC_SDW_UTILS=y from
SND_SOC_SOF_HDA_GENERIC=y
- ASoC: meson: aiu: Validate written enum values
- ASoC: topology: Check PCM and DAI name strings before use
- ipv4: fib: Don't dump dying fib_info in fib_leaf_notify().
- iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path
- iommufd: Clarify IOAS_MAP_FILE dma-buf support
- cxl/region: Fill first free targets[] slot during auto-discovery
- vfio: selftests: Ensure libvfio output dirs are always created
- cxl/region: Block region delete during region creation
- cxl/region: Resolve region deletion races
- cxl/memdev: Pin parents for entire memdev lifetime
- net: airoha: Fix error handling in airoha_ppe_flush_sram_entries()
- netfilter: nft_fwd_netdev: use recursion counter in neigh egress path
- netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use
them
- geneve: Fix off-by-one comparing with GRO_LEGACY_MAX_SIZE
- smb: client: fix conflicting option validation for new mount API
- btrfs: Drop WQ_PERCPU from ordered_flags in btrfs_init_workqueues()
- bpf: Guard __get_user acesss with access_ok for uprobe_multi data
- net: ti: icssg-prueth: Fix AF_XDP fill ring alloc and wakeup condition
- net: ti: icssg: Use undirected TX tag for native XDP in HSR offload mode
- net: ti: icssg: Use undirected TX tag for XDP zero copy in HSR offload
mode
- RDMA/bnxt_re: Free CQ toggle page after firmware teardown
- RDMA/bnxt_re: Reject GET_TOGGLE_MEM when toggle page was not allocated
- RDMA/hns: Fix memory leak of bonding resources
- mfd: bd72720: Drop BUCK11 ID
- 9p: Add missing read barrier in virtio zero-copy path
- perf dwarf-aux: Fix libdw segmentation fault in cu_walk_functions_at
- perf dwarf-aux: Fix libdw API contract violations
- perf srcline: Introduce inline_node__clear_frames()
- perf libdw: Fix libdw API contract violations and memory leaks
- perf probe-finder: Fix libdw API contract violations
- perf annotate-data: Fix libdw API contract violations
- coresight: tmc: Fix overflow when calculating is bigger than 2GiB
- perf tool: Fix missing schedstat delegates and dont_split_sample_group
in delegate_tool
- PCI: intel-gw: Move interrupt enable to own function
- PCI: intel-gw: Enable clock before PHY init
- PCI: intel-gw: Add .start_link() callback
- bus: mhi: ep: Add missing state_lock protection for mhi_state access
- PCI: dwc: Apply ECRC workaround for DesignWare cores prior to 5.10a
- PCI: qcom: Set max OPP before DBI access during resume
- perf pmu-events AMD: Switch l2_itlb_misses to
bp_l1_tlb_miss_l2_tlb_miss.all
- perf unwind: Refactor get_entries to allow dynamic libdw/libunwind
selection
- coresight: Handle helper enable failure properly
- mailbox: don't free the channel if the startup callback failed
- PCI/pwrctrl: Lock device when calling device_is_bound()
- coresight: platform: defer connection counter increment until alloc
succeeds
- platform/x86: classmate-laptop: Address memory leaks on driver removal
- clk: microchip: mpfs-ccc: fix peripheral driver registration failures
after oob fix
- perf sample: Add evsel to struct perf_sample
- perf event: Fix size of synthesized sample with branch stacks
- perf inject: Fix itrace branch stack synthesis
- gpib: cb7210: Fix region leak when request_irq fails
- timers/migration: Update stale @online doc to @available
- clk: spacemit: k3: Switch to pll2_d6 as parent for PCIe clock
- clk: spacemit: k3: Fix PCIe clock register offset
- fs/ntfs3: fix wrong LCN in run_remove_range() when splitting a run
- ntfs3: Allocate iomap inline_data using alloc_page
- perf sample: Add file_offset field to struct perf_sample
- perf sched: Replace BUG_ON on invalid CPU with graceful skip
- perf sched: Fix NULL dereference in latency_runtime_event
- perf sched: Fix comp_cpus heap overflow with cross-machine recordings
- perf tools: Guard remaining test_bit calls from OOB sample CPU
- perf sched: Fix thread reference leaks in timehist_get_thread()
- perf sched: Use is_idle_sample() for idle thread runtime cast guard
- perf sched: Fix thread reference leak in idle hist processing
- perf sched: Free callchain nodes in idle thread cleanup
- docs: memfd_preservation: fix rendering of ABI documentation
- virtio: add missing kernel-doc for map and vmap members
- fs/ntfs3: prevent potential lcn remains uninitialized
- perf tools: NULL bitmap pointers after bitmap_free()
- perf tools: Use scnprintf() in build_id__snprintf() and hwmon
read_events()
- perf data convert json: Fix addr_location leak on time-filtered samples
- perf tools: Use mkostemp() for O_CLOEXEC on temporary files
- phy: freescale: phy-fsl-imx8qm-lvds-phy: Use synchronous PM runtime put
in reset
- sparc: Avoid -Wunused-but-set-parameter in clear_user_page()
- apparmor: release exe file resources on path failure
- apparmor: remove unnecessary goto and associated label
- apparmor: Fix inverted comparison in cache_hold_inc()
- i3c: mipi-i3c-hci: Fix suspend behavior when bus disable falls back to
software reset
- i3c: master: Serialize i3c_set_hotjoin() with the maintenance lock
- i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev()
- perf maps: Add maps__mutate_mapping
- perf c2c: Free format list entries when releasing c2c hist entries
- regcache: Do not overwrite error code when finalizing cache after error
- erofs: call erofs_exit_ishare() before rcu_barrier()
- perf c2c: Free format list entries when c2c_hists__init() fails
- perf c2c: Fix hist entry and format list leaks in c2c_he_free()
- drm/amd/display: Skip PHY SSC reduction on some 8K panels
- net: ethernet: mtk_eth_soc: fix supported_interface set after
phylink_create
- selftests/ftrace: Fix trace_marker_raw test on 64K page kernels
- octeontx2-af: npc: Log successful MCAM drop-on-non-hit install at debug
level
- netconsole: don't drop the last byte of a full-sized message
- eth: fbnic: take netif_addr_lock_bh() around rx mode address programming
- arm64: static_call: include asm/insns.h
- md/raid1: fix writes_pending and barrier reference leaks on write
failures
- md/raid10: fix writes_pending leak on write request failures
- md/raid10: fix writes_pending and barrier reference leaks on discard
failures
- netfilter: ipset: Don't use test_bit() in lockless RCU readers in bitmap
types
- selftests/mm: fix hugetlb pathname construction in
charge_reserved_hugetlb.sh
- selftests/mm: run_vmtests.sh: free memory if available memory is low
- selftests/mm: move hwpoison setup into run_test() and silence modprobe
output for memory-failure category
- selftests/mm: remove hardcoded THP sizing assumptions in hmm tests
- net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone
- bpf: Fix partial copy of non-linear test_run output
- bpf: Fix BPF_PROG_ASSOC_STRUCT_OPS last field check
- erofs: handle 48-bit blocks_hi for compressed inodes
- ASoC: cs530x: Fix expected MCLK rates for CS5302/4/8
- PCI: endpoint: pci-epf-vntb: Document legacy MSI doorbell offset
- PCI: endpoint: pci-epf-vntb: Defer pci_epc_raise_irq() out of atomic
context
- PCI: endpoint: pci-epf-vntb: Report 0-based doorbell vector via
ntb_db_event()
- e1000e: Reconfigure PLL clock gate timeout and re-enable K1 on Meteor
Lake
- bpf: Guard conntrack opts error writes
- selftests/bpf: Cover small conntrack opts error writes
- netfilter: nf_conntrack_helper: dynamically allocate struct
nf_conntrack_helper
- netfilter: nf_conntrack_pptp: move GRE specific cleanup to GRE tracker
- netfilter: nf_conntrack_gre: fix gre keymap list corruption
- netfilter: conntrack: check NULL when retrieving ct extension
- netfilter: nf_conntrack_expect: use conntrack GC to reap expectations
- netfilter: nf_conntrack_expect: store master_tuple in expectation
- netfilter: nf_conntrack_expect: run expectation eviction with no helper
- netfilter: nft_ct: expectation timeouts are passed in milliseconds
- netfilter: nf_conntrack_helper: cap maximum number of expectation at
helper registration
- cpuidle: Allow exit latency to exceed target residency
- ASoC: SDCA: Validate written enum value in ge_put_enum_double()
- ASoC: rt5575: Use __le32 for SPI burst write address
- PCI: endpoint: pci-epf-vntb: Exclude reserved slots from db_valid_mask
- net: ti: icssg: Fix XSK zero copy TX during application wakeup
- net: lwtunnel: Drop skb metadata before LWT encapsulation
- sctp: fix err_chunk memory leaks in INIT handling
- net: dsa: mxl862xx: avoid unaligned 16-bit access in api_wrap
- octeontx2-af: fix CGX debugfs RVU AF PCI reference leaks
- geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
- geneve: validate inner network offset in geneve_gro_complete()
- tools: ynl: build archives with $(AR)
- net: enetc: fix potential divide-by-zero when num_vsi is zero
- udp_tunnel: Pass struct sock to setup_udp_tunnel_sock().
- tipc: avoid busy looping in tipc_exit_net()
- bpf: Mask pseudo pointer values in verifier logs
- bpf: Fix insn_aux_data leak on verifier err_free_env path
- hwmon: (pmbus/core) Add support for NVIDIA nvidia195mv mode
- hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid()
- gpio: shared-proxy: always serialize with a sleeping mutex
- drm/panthor: Always use the IRQ-safe variant when acquiring the fence
lock
- drm/panthor: Keep the reset work disabled until everything is
initialized
- drm/panthor: Fix panthor_pwr_unplug()
- spi: rzv2h-rspi: Fix DMA transfer error handling for signal interruption
- xen/pvcalls: bound backend response req_id before indexing rsp[]
- afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints
- afs: Fix directory inode initialisation order
- afs: Use scoped_seqlock_read() rather than manually doing seqlock stuff
- afs: Fix leak of ungot volume
- iomap: release pages on atomic dio size mismatch
- cachefiles: Fix double unlock in nomem_d_alloc error path
- cachefiles: Fix file burial to take lock when unsetting S_KERNEL_FILE
- drm/imagination: Fix returned size for DRM_IOCTL_PVR_DEV_QUERY
- iio: dac: mcp47feb02: Fix passing uninitialized vref1_uV for no Vref1
case
- net/mlx5: LAG, replace pf array with xarray
- net/mlx5: LAG, use xa_alloc to manage LAG device indices
- net/mlx5: Lag: refactor representor reload handling
- net/mlx5: E-Switch, add representor lifecycle lock
- net/mlx5: Lag, avoid LAG and representor lock cycles
- net/mlx5: LAG, factor out shared FDB code into dedicated file
- net/mlx5: LAG, replace peer count check with direct peer lookup
- net/mlx5: LAG, prepare for SD device integration
- net/mlx5: LAG, replace mlx5_get_dev_index with LAG sequence number
- net/mlx5: LAG, extend shared FDB API with group_id filter
- net/mlx5: LAG, Fix off-by-one in single-FDB error rollback
- ksmbd: fix multichannel binding and enforce channel limit
- smb: client: preserve leading slash for POSIX absolute symlink targets
- gpio: shared: make the voting mechanism adaptable
- drm/i915/ltphy: Fix SSC Enablement bit in PORT_CLOCK_CTL
- Bluetooth: 6lowpan: avoid untracked enable work
- Bluetooth: btintel_pcie: Support Product level reset
- [Config] Make BT_INTEL_PCIE depend on ACPI
- Bluetooth: btintel_pcie: Add support for smart trigger dump
- Bluetooth: btintel_pcie: Separate coredump work from RX work
- Bluetooth: btintel_pcie: Refactor FLR to use device_reprobe()
- Bluetooth: ISO: fix malformed ISO_END/CONT handling
- accel/amdxdna: Prevent PM resume deadlock in hwctx_sync_debug_bo()
- accel/amdxdna: Fix VMA access race
- net: rnpgbe: fix mailbox endianness and remove pointer casts
- drm: Guard DRM_CLIENT_CAP_PLANE_COLOR_PIPELINE
- smb: client: fix busy dentry warning on unmount after DIO
- drm/fb-helper: Only consider active CRTCs for vblank sync
- ethtool: rss: Fix hfunc and input_xfrm parsing on big endian
- drm/imagination: make pvr_fw_trace_init_mask_ops static
- VDUSE: avoid leaking information to userspace
- ASoC: SOF: ipc4-control: Validate notification payload size
- arm64: dts: renesas: ironhide: Describe inline ECC carveouts
- arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers
- KVM: s390: vsie: Fix allocation of struct vsie_rmap
- KVM: s390: vsie: Add missing radix_tree_preload() in
_gaccess_shadow_fault()
- KVM: s390: Add some useful mask macros
- KVM: s390: vsie: Fix rmap handling in _do_shadow_crste()
- KVM: s390: vsie: Fix redundant rmap entries
- KVM: s390: vsie: Use mmu cache to allocate rmap
- KVM: s390: Initialize KVM_S390_GET_CMMA_BITS memory
- KVM: TDX: Reject concurrent change to CPUID entry count
- ASoC: SOF: topology: fix memory leak in snd_sof_load_topology
- netfilter: nft_fib: reject fib expression on the netdev egress hook
- netfilter: nf_conntrack_sip: remove net variable shadowing
- netfilter: nf_conntrack_sip: validate skb_dst() before accessing it
- gpu/buddy: bail out of try_harder when alignment cannot be honoured
- backlight: ktd2801: Enable BL_CORE_SUSPENDRESUME
- cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size
- pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP
- remoteproc: xlnx: Check remote core state
- mm/sparse-vmemmap: fix vmemmap accounting underflow
- mm/huge_memory: preserve pmd_swp_uffd_wp on device-private PMD downgrade
- fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race
- fs/proc/task_mmu: do not warn on seeing non-migration pmd entry
- kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES
- mtd: maps: vmu-flash: fix fault in unaligned fixup
- dmaengine: dw-edma-pcie: Reject devices without driver data
- dmaengine: sh: rz-dmac: Move interrupt request after everything is set
up
- platform/x86: hp-wmi: Add support for Omen 16-ap0xxx (8D26)
- platform/x86: hp-wmi: Add support for Omen 16-ap0xxx (8E35)
- spi: imx: reconfigure for PIO when DMA cannot be started
- ovl: use linked upper dentry in copy-up tmpfile
- can: bcm: add locking when updating filter and timer values
- can: bcm: extend bcm_tx_lock usage for data and timer updates
- can: bcm: fix CAN frame rx/tx statistics
- can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()
- can: bcm: fix stale rx/tx ops after device removal
- can: bcm: track a single source interface for ANYDEV timeout/throttle
ops
- can: bcm: validate frame length in bcm_rx_setup() for RTR replies
- can: bcm: add missing device refcount for CAN filter removal
- selftests/bpf: Cover negative buffer pointer offsets
- dm: avoid leaking the caller's thread keyring via the table device file
- dma-buf: protected fence ops by RCU v8
- dma-fence: use correct callback in dma_fence_timeline_name()
- accel/amdxdna: reject command submission on devices without a submit op
- accel/amdxdna: reject user command submission without a command BO
- accel/amdxdna: Use caller client for debug BO sync
- fs/resctrl: Fix use-after-free during unmount
- mmc: vub300: fix use-after-free on probe failure
- octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF
- ksmbd: fix stack buffer overflow in multichannel session-key copy
- netfilter: nfnetlink_cthelper: cap to maximum number of expectation per
master
- netfilter: nfnetlink_cthelper: cap to maximum number of expectation per
master on updates
- riscv: vdso: Always declare vdso_start symbols
- ata: libata-core: Add NOLPM quirk for PNY CS900 1TB SSD
- ata: libata-core: Reject an invalid concurrent positioning ranges count
- net: ipa: fix SMEM state handle leaks in SMP2P init
- amdkfd: properly free secondary context id
- pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI
- pmdomain: mediatek: Fix possible nullptr KP in HWV cleanup/on-check
- arch/riscv: vdso: remove CFI landing pad from rt_sigreturn
- reset: imx7: Correct polarity of MIPI CSI resets on i.MX8MQ
- powerpc/uaccess: correct check for CONFIG_PPC_E500 in
mask_user_address()
- wifi: mac80211: validate extension-frame layout before RX
- xfs: factor out a xfs_zone_mark_free helper
- xfs: add newly added RTGs to the free pool in growfs
- liveupdate: validate session type before performing operation
- posix-timers: Expand timer_[re]arm() callbacks with a boolean return
value
- posix-cpu-timers: Prevent UAF caused by non-leader exec() race
- Revert "gpib: cb7210: Fix region leak when request_irq fails"
- Upstream stable to v6.18.40, v7.1.5
* Resolute update: upstream stable patchset 2026-08-20 (LP: #2164666) //
CVE-2023-20585
- iommu/amd: Use maximum Event log buffer size when SNP is enabled on
Family 0x19
- iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family
0x19
* [Regression] Laptop fails to power off completely when HDMI is connected
in kernel 7.0.0-28 (LP: #2163121) // CVE-2026-68364
- drm/amd/display: fix NULL ptr deref in ISM delayed work
- drm/amd/display: Fix ISM teardown crash from NULL dc dereference
- drm/amd/display: Fix ISM dc_lock deadlock during suspend
* CVE-2026-72064
- net: mana: Sync page pool RX frags for CPU
* CVE-2026-72065
- net: mana: Validate the packet length reported by the NIC
* CVE-2026-72098
- dm-verity-fec: replace {MAX,MIN}_RSN with {MIN,MAX}_ROOTS
- dm-verity: fix buffer overflow in FEC calculation
* CVE-2026-72248
- netfilter: flowtable: support IPIP tunnel with direct xmit
- netfilter: flowtable: use correct direction to set up tunnel route
* CVE-2026-72249
- netfilter: flowtable: use dst in this direction when pushing IPIP header
* CVE-2026-72287
- KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal"
checks
* CVE-2026-72329
- net/liquidio: drop cached VF pci_dev LUT
* CVE-2026-72355
- netfs: Fix barriering when walking subrequest list
* CVE-2026-72412
- s390/mm: Fix handling of _PAGE_UNUSED pte bit
* CVE-2026-72417
- netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()
* CVE-2026-72442
- netfilter: flowtable: fix and simplify IP6IP6 tunnel handling
* CVE-2026-72463
- xfrm: Fix dev use-after-free in xfrm async resumption
* CVE-2026-72477
- fs/ntfs3: call _ntfs_bad_inode() when failing to rename
* CVE-2026-72493
- net: serialize netif_running() check in enqueue_to_backlog()
* CVE-2026-72494
- RDMA/irdma: Replace waitqueue and flag with completion
* CVE-2026-72496
- RDMA/bnxt_re: Proper rollback if the ioremap fails
* CVE-2026-74269
- bnxt: fix head underflow on XDP head-grow
* CVE-2026-74350
- ocfs2: validate fast symlink target during inode read
* CVE-2026-72495
- RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
* CVE-2026-72501
- RDMA/bnxt_re: Initialize dpi variable to zero
* CVE-2026-72278
- KVM: arm64: nv: Re-translate VNCR before injecting abort
* CVE-2026-68083
- ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
* CVE-2026-68457
- ksmbd: use opener credentials for FSCTL mutations
* CVE-2026-68476
- ipvs: reload ip header after head reallocation
* CVE-2026-68477
- ipvs: fix more places with wrong ipv6 transport offsets
* CVE-2026-72014
- drbd: reject data replies with an out-of-range payload size
* CVE-2026-72020
- ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
* CVE-2026-72033
- orangefs: keep the readdir entry size 64-bit in fill_from_part()
* CVE-2026-72041
- espintcp: use sk_msg_free_partial to fix partial send
* CVE-2026-72046
- gve: fix header buffer corruption with header-split and HW-GRO
* CVE-2026-72069
- locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
* CVE-2026-72083
- scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
* CVE-2026-72084
- scsi: target: Bound PR-OUT TransportID parsing to the received buffer
* CVE-2026-72085
- scsi: xen: scsiback: Free unsubmitted command instead of double-putting
it
* CVE-2026-72129
- nvmet-rdma: handle inline data with a nonzero offset
* CVE-2026-72130
- nvmet-auth: reject short AUTH_RECEIVE buffers
* CVE-2026-64551
- sctp: validate STALE_COOKIE cause length before reading staleness
* CVE-2026-72137
- xfrm: nat_keepalive: avoid double free on send error
* CVE-2026-72139
- tcp: defer md5sig_info kfree past RCU grace period in tcp_connect
* CVE-2026-72191
- ntfs3: validate split-point offset in indx_insert_into_buffer
* CVE-2026-72192
- ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head
* CVE-2026-72194
- fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
* CVE-2026-72217
- SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
* CVE-2026-72220
- sunrpc: harden rq_procinfo lifecycle to prevent double-free
* CVE-2026-72221
- sunrpc: wait for in-flight TLS handshake callback when cancel loses race
* CVE-2026-72222
- sunrpc: pin svc_xprt across the asynchronous TLS handshake callback
* CVE-2026-72226
- batman-adv: tt: prevent TVLV OOB check overflow
* CVE-2026-72234
- batman-adv: access unicast_ttvn skb->data only after skb realloc
* CVE-2026-72251
- netfilter: nf_nat_sip: reload possible stale data pointer
* CVE-2026-72277
- KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN
- KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory
* CVE-2026-72279
- KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR
* CVE-2026-72288
- KVM: arm64: vgic: Handle race between interrupt affinity change and LPI
disabling
* CVE-2026-72289
- KVM: arm64: vgic: Check the interrupt is still ours before migrating it
* CVE-2026-72296
- net: ife: require ETH_HLEN to be pullable in ife_decode()
* CVE-2026-72299
- tipc: restrict socket queue dumps in enqueue tracepoints
* CVE-2026-72317
- SUNRPC: pin upper rpc_clnt across the TLS connect_worker
* CVE-2026-72318
- cifs: validate DFS referral string offsets
* CVE-2026-72319
- ipvs: fix PMTU for GUE/GRE tunnel ICMP errors
- ipvs: ensure inner headers in ICMP errors are in headroom
* CVE-2026-72320
- netfilter: nft_lookup: fix catchall element handling with inverted
lookups
* CVE-2026-72322
- ipv6: mcast: Fix potential UAF in MLD delayed work
* CVE-2026-72323
- ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
* CVE-2026-64541
- net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
* CVE-2026-72339
- qede: fix off-by-one in BD ring consumption on build_skb failure
* CVE-2026-72348
- netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
* CVE-2026-72351
- gue: validate REMCSUM private option length
* CVE-2026-72366
- netfs: Fix netfs_create_write_req() to handle async cache object
creation
* CVE-2026-72381
- ksmbd: fix use-after-free of fp->owner.name in durable handle owner
check
* CVE-2026-72393
- eth: fbnic: don't cache shinfo across skb realloc
* CVE-2026-72398
- sctp: add INIT verification after cookie unpacking
* CVE-2026-72399
- net: enetc: check the number of BDs needed for xdp_frame
* CVE-2026-64530
- net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
* CVE-2026-72422
- ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2
NEGOTIATE
* CVE-2026-72429
- ipv6: ioam: fix type confusion of dst_entry
* CVE-2026-72436
- netfilter: ipset: Fix data race between add and dump in all hash types
- netfilter: ipset: annotate "pos" for concurrent readers/writers
- netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash
types
* CVE-2026-72451
- xfrm: Fix xfrm state cache insertion race
* CVE-2026-72466
- xprtrdma: Fix bcall rep leak and unbounded peek
* CVE-2026-72472
- nfs: use nfsi->rwsem to protect traversal of the file lock list
* CVE-2026-72473
- xprtrdma: Avoid 250 ms delay on backlog wakeup
- xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot
- xprtrdma: Post receive buffers after RPC completion
- xprtrdma: Use sendctx DMA state for Send signaling
- xprtrdma: Decouple req recycling from RPC completion
* CVE-2026-72491
- net/9p: fix race condition on rdma->state in trans_rdma.c
* CVE-2026-72495 // CVE-2026-72501
- RDMA/bnxt_re: Move the UAPI methods to a dedicated file
* CVE-2026-74255
- tipc: fix UAF in tipc_l2_send_msg()
* CVE-2026-74267
- net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek
before restoring qlen
* CVE-2026-74268
- tcp: clear sock_ops cb flags before force-closing a child socket
* CVE-2026-74287
- sctp: validate embedded address parameter length
* CVE-2026-74310
- vhost/net: complete zerocopy ubufs only once
* CVE-2026-74345
- RDMA/siw: Fix endpoint/socket association handling
* CVE-2026-74361
- nvme: fix FDP fdpcidx bounds check
* CVE-2026-74376
- md/raid10: reset read_slot when reusing r10bio for discard
* CVE-2026-74384
- nvme-multipath: fix flex array size in struct nvme_ns_head
* CVE-2026-74394
- RDMA/srpt: fix integer overflow in immediate data length check
* CVE-2026-74398
- ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD
* CVE-2026-74401
- dlm: fix add msg handle in send_queue ordered
* CVE-2026-74406
- vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive().
* CVE-2026-74427
- afs: Fix netns teardown to cancel the preallocation charger
- afs: Fix further netns teardown to cancel the preallocation charger
* CVE-2026-74428
- rxrpc: Fix double unlock in rxrpc_recvmsg()
* CVE-2026-74433
- rxrpc: Fix UAF in rxgk_issue_challenge()
* CVE-2026-74434
- rxrpc: Don't move a peeked OOB message onto the pending queue
* CVE-2026-74436
- rxrpc: serialize kernel accept preallocation with socket teardown
* CVE-2026-64535
- nvmet-tcp: Fix potential UAF when ddgst mismatch
* CVE-2026-74439
- iommu/vt-d: Clear Present bit before tearing down scalable-mode context
entry
* CVE-2026-64534
- nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error
path
Date: 2026-09-21 15:28:44.900377+00:00
Changed-By: Sarah Emery <sarah.emery at canonical.com>
Signed-By: Andy Whitcroft <apw at canonical.com>
https://launchpad.net/ubuntu/+source/linux-riscv/7.0.0-38.38.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Resolute-changes
mailing list