# Linux Kernel 6.12.108 - Product: Linux Kernel (https://whatsnew.fyi/product/linux-kernel) - Vendor: Linux Kernel Organization - Date: 2026-09-02 - Version: 6.12.108 - Original notes: https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.108 - Permalink: https://whatsnew.fyi/product/linux-kernel/releases/6.12.108 - Labels: longterm What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **fixed** — usb: usbfs: fix use-after-free of usb_device in usbdev_release() - **fixed** — wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb - **fixed** — USB: c67x00: fix use-after-free in c67x00_add_iso_urb() - **removed** — USB: serial: spcp8x5: drop broken carrier detect support - **fixed** — USB: serial: option: fix slab OOB read in interrupt URB callback - **fixed** — ALSA: usb-audio: Complete cleanup after system-resume errors - **fixed** — ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() - **changed** — usb: core: Strengthen error handling in hub_hub_status() - **changed** — usb: core: Add lock to usb_wakeup_notification() - **fixed** — KVM: s390: vsie: zero stale crypto bits - **removed** — crypto: qce: Remove unsafe/deprecated algorithms - **fixed** — crypto: mxs-dcp: fix source scatterlist length access - **fixed** — crypto: qce: fix CCM AAD buffer underallocation - **fixed** — crypto: atmel-tdes: use scatterlist length before DMA mapping - **removed** — crypto: qcom-rng: Remove crypto_rng interface - **fixed** — crypto: qcom-rng: Allow zero as a random number - **fixed** — crypto: qcom-rng: Enable clock in hwrng case - **fixed** — mm/swap: reject swapon() on filesystem-level encrypted files - **fixed** — netfilter: nf_tables: don't queue packet path object notifications 100 commits in this release: - Linux 6.12.108 - usb: usbfs: fix use-after-free of usb_device in usbdev_release() - wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb - USB: c67x00: fix use-after-free in c67x00_add_iso_urb() - USB: serial: spcp8x5: drop broken carrier detect support - USB: serial: option: fix slab OOB read in interrupt URB callback - ALSA: usb-audio: Complete cleanup after system-resume errors - ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() - usb: core: Strengthen error handling in hub_hub_status() - usb: core: Add lock to usb_wakeup_notification() - KVM: s390: vsie: zero stale crypto bits - crypto: qce - Remove unsafe/deprecated algorithms - crypto: mxs-dcp - fix source scatterlist length access - crypto: qce - fix CCM AAD buffer underallocation - crypto: atmel-tdes - use scatterlist length before DMA mapping - crypto: qcom-rng - Remove crypto_rng interface - crypto: qcom-rng - Allow zero as a random number - crypto: qcom-rng - Enable clock in hwrng case - mm/swap: reject swapon() on filesystem-level encrypted files - netfilter: nf_tables: don't queue packet path object notifications - vxlan: keep the last remote linked during FDB flush - batman-adv: reject unrepresentable multicast TVLV offsets - ipv6: seg6: clear IPv4 control block on IPIP decapsulation - net: bridge: mcast: fix use-after-free of a master VLAN's multicast context - xfrm: bound nat keepalive state collection - xfrm: fix xfrm_state_construct() auth-trunc leak - xfrm: ah6: validate routing header segments_left - xfrm: avoid lock inversion in nat keepalive work - xfrm: drop ESP-in-TCP packets with no ingress device - xfrm: espintcp: fix UAF during close - net/tcp-ao: fix use-after-free of current_key on reconnect to another peer - tcp: fix AO info use-after-free in tcp_ao_connect_init() - net/tcp: fix TCP-AO key deletion in VRFs - x86/CPU/AMD: Carve out a Zen5 models range - gtp: serialize PDP context updates - tls: device: fix out-of-bounds write in tls_append_frag() - usb: gadget: f_tcm: keep port count until LUN teardown completes - usb: usbtest: disable dynamic ID support - fuse: fix invalidate lock leak on open O_TRUNC DAX failure - fuse: fix invalidate lock leak on setattr writeback failure - xhci: dbgtty: Fix unregister on tty_alloc_driver() failure - xhci: dbgtty: Fix unregister on tty_register_driver() failure - usb: xhci: Handle USB3 port events when there is one roothub - accessibility: speakup: unregister tty ldisc on later init failures - fpga: dfl: fme: add error handling - HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() - Bluetooth: hci_sync: Fix accept list UAF during suspend - Bluetooth: hci_sync: Use bt_dev_err() to log error message in hci_update_event_filter_sync() - HID: uclogic: fix use-after-free of inrange_timer on remove - HID: ft260: fix stack-use-after-return write in I2C read race - HID: ft260: validate i2c input report length - HID: asus: fix missing hid_is_usb() check - HID: asus: simplify RGB init sequence - HID: pidff: fix OOB write when hid->inputs is empty - HID: pidff: clang-format pass - HID: pidff: Use ARRAY_SIZE macro instead of sizeof - HID: pidff: Rework pidff_set_time() to fix warnings - nfc: nci: add data_len bound checks to activation parameter extractors - nilfs2: reject invalid block index in GC ioctl - nilfs2: correct return value kernel-doc descriptions for ioctl functions - ksmbd: harden file lifetime during session teardown - powerpc/hv-gpci: fix preempt count leak in sysfs show paths - veth: fix OOB txq access in veth_poll() with asymmetric queue counts - ring buffer: Propagate __rb_map_vma return value to caller - selinux: switch two allocations to use kzalloc_objs() - smc: Use __sk_dst_get() and dst_dev_rcu() in smc_vlan_by_tcpsk(). - ASoC: nau8821: Cancel pending work before suspend - Revert "PM: sleep: Use complete() in device_pm_sleep_init()" - riscv: Fix register corruption from uninitialized cregs on error - bpf: Fix use-after-free i _[Truncated at 4000 characters — full notes: https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.108]_