# Linux Kernel 6.1.187 - Product: Linux Kernel (https://whatsnew.fyi/product/linux-kernel) - Vendor: Linux Kernel Organization - Date: 2026-09-02 - Version: 6.1.187 - Original notes: https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.187 - Permalink: https://whatsnew.fyi/product/linux-kernel/releases/6.1.187 - Labels: longterm What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **fixed** — usb: usbfs: fix use-after-free of usb_device in usbdev_release() - **fixed** — USB: c67x00: fix use-after-free in c67x00_add_iso_urb() - **removed** — USB: serial: spcp8x5: drop broken carrier detect support - **fixed** — USB: serial: option: fix slab OOB read in interrupt URB callback - **fixed** — ALSA: usb-audio: Complete cleanup after system-resume errors - **fixed** — ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() - **changed** — usb: core: Strengthen error handling in hub_hub_status() - **added** — usb: core: Add lock to usb_wakeup_notification() - **fixed** — Bluetooth: hci_core: Fix hci_conn_hash_lookup_cis - **fixed** — KVM: s390: vsie: zero stale crypto bits - **removed** — crypto: qce - Remove unsafe/deprecated algorithms - **fixed** — crypto: mxs-dcp - fix source scatterlist length access - **fixed** — crypto: qce - fix CCM AAD buffer underallocation - **fixed** — crypto: atmel-tdes - use scatterlist length before DMA mapping - **fixed** — mm/swap: reject swapon() on filesystem-level encrypted files - **fixed** — ipv6: seg6: clear IPv4 control block on IPIP decapsulation - **fixed** — net: bridge: mcast: fix use-after-free of a master VLAN's multicast context - **fixed** — xfrm: fix xfrm_state_construct() auth-trunc leak - **fixed** — xfrm: ah6: validate routing header segments_left - **fixed** — xfrm: drop ESP-in-TCP packets with no ingress device 93 commits in this release: - Linux 6.1.187 - usb: usbfs: fix use-after-free of usb_device in usbdev_release() - USB: c67x00: fix use-after-free in c67x00_add_iso_urb() - USB: serial: spcp8x5: drop broken carrier detect support - USB: serial: option: fix slab OOB read in interrupt URB callback - ALSA: usb-audio: Complete cleanup after system-resume errors - ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() - usb: core: Strengthen error handling in hub_hub_status() - usb: core: Add lock to usb_wakeup_notification() - Bluetooth: hci_core: Fix hci_conn_hash_lookup_cis - KVM: s390: vsie: zero stale crypto bits - crypto: qce - Remove unsafe/deprecated algorithms - crypto: mxs-dcp - fix source scatterlist length access - crypto: qce - fix CCM AAD buffer underallocation - crypto: atmel-tdes - use scatterlist length before DMA mapping - mm/swap: reject swapon() on filesystem-level encrypted files - ipv6: seg6: clear IPv4 control block on IPIP decapsulation - net: bridge: mcast: fix use-after-free of a master VLAN's multicast context - xfrm: fix xfrm_state_construct() auth-trunc leak - xfrm: ah6: validate routing header segments_left - xfrm: drop ESP-in-TCP packets with no ingress device - xfrm: espintcp: fix UAF during close - tls: device: fix out-of-bounds write in tls_append_frag() - usb: gadget: f_tcm: keep port count until LUN teardown completes - usb: usbtest: disable dynamic ID support - fuse: fix invalidate lock leak on open O_TRUNC DAX failure - fuse: fix invalidate lock leak on setattr writeback failure - xhci: dbgtty: Fix unregister on tty_alloc_driver() failure - xhci: dbgtty: Fix unregister on tty_register_driver() failure - usb: xhci: Handle USB3 port events when there is one roothub - accessibility: speakup: unregister tty ldisc on later init failures - fpga: dfl: fme: add error handling - ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() - Bluetooth: hci_event: validate LE Set CIG Parameters response - Bluetooth: hci_event: fix Set CIG Parameters error status handling - Bluetooth: ISO: use correct CIS order in Set CIG Parameters event - Bluetooth: hci_conn: Fix not matching by CIS ID - Bluetooth: hci_sync: Fix accept list UAF during suspend - Bluetooth: hci_sync: Use bt_dev_err() to log error message in hci_update_event_filter_sync() - HID: ft260: fix stack-use-after-return write in I2C read race - HID: ft260: validate i2c input report length - HID: ft260: missed NACK from busy device - HID: ft260: wake up device from power saving mode - HID: ft260: skip unexpected HID input reports - HID: ft260: improve i2c large reads performance - HID: ft260: improve i2c write performance - HID: uclogic: fix use-after-free of inrange_timer on remove - HID: nintendo: stop device IO before hid_hw_stop on probe failure - nvmet-tcp: bound SGL data length before allocating command buffers - nvme: rename CDR/MORE/DNR to NVME_STATUS_* - HID: magicmouse: re-enable multitouch after reset-resume - HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() - HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C - nfc: nci: add data_len bound checks to activation parameter extractors - nilfs2: reject invalid block index in GC ioctl - nilfs2: correct return value kernel-doc descriptions for ioctl functions - ext4: propagate errors from fast commit range replay - mptcp: pm: fix memory leak from alloc-during-teardown race - block: make bio_check_eod work for zero sized devices - ASoC: tegra: Fix Master Volume Control - Revert "smb: client: use kvzalloc() for megabyte buffer in simple fallocate" - Revert "mtd: maps: vmu-flash: fix fault in unaligned fixup" - selinux: switch two allocations to use kzalloc_objs() - smc: Use __sk_dst_get() and dst_dev_rcu() in smc_vlan_by_tcpsk(). - ASoC: nau8821: Cancel pending work before suspend - Revert "PM: sleep: Use complete() in device_pm_sleep_init()" - riscv: Fix register corruption from uninitialized cregs on error - bpf: Fix use-after-free in offloaded map _[Truncated at 4000 characters — full notes: https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.187]_