- platform/chrome: sensorhub: Fix dropped timestamp events and log spam
- ACPI: scan: Do not combine resources that overlap completely
- selftests/mm: fix on-fault-limit false failure under sudo-rs
- udf: Fix i_lenExtents truncation on 32-bit kernels
- timer: Keep debugobjects state consistent in migrate_timer_list()
- timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex()
- taskstats: fix cpumask parsing cutting off the last character
- smack: fix cred UAF in smack_file_send_sigiotask()
- signal: avoid shared siginfo namespace rewrites
- tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout
- zloop: truncate finished zones to zone capacity
- xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc()
- w1: ds28e17: reject an oversize length on an I2C block read
- vsock/virtio: flush works in dependency order
- wifi: mt76: mt7996: validate default EEPROM firmware size
- wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames
- wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy
- wifi: mt76: mt7925: cancel mlo_pm_work on stop
- wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy
From XanMod Kernel
- 48995b0a2757 Linux 7.2.4-xanmod1
- 2e766e62ad92 Merge tag 'v7.2.4' into 7.2
- 5015d0d945b3 Linux 7.2.4
- 702da34510f8 platform/chrome: sensorhub: Fix dropped timestamp events and log spam
- 7a315e6e2c36 ACPI: scan: Do not combine resources that overlap completely
- 33c7d01fb172 selftests/mm: fix on-fault-limit false failure under sudo-rs
- fafa98778383 udf: Fix i_lenExtents truncation on 32-bit kernels
- b63a6589984c timer: Keep debugobjects state consistent in migrate_timer_list()
- bc59dac50cb4 timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex()
- 3fb244bc24ae taskstats: fix cpumask parsing cutting off the last character
- b791401bf389 smack: fix cred UAF in smack_file_send_sigiotask()
- b655c2040ce8 signal: avoid shared siginfo namespace rewrites
- 1abe5e32a6c8 sticon/parisc: Detect default STI graphics card for console output
- a09bc4eaa67e sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]
- aee2296d09f6 tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout
- 23cb8d5fb33d zloop: truncate finished zones to zone capacity
- f40115b2575a xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc()
- 6df05f630c84 w1: ds28e17: reject an oversize length on an I2C block read
- da5e9f08714c vsock/virtio: flush works in dependency order
- 7074ec376982 wifi: mt76: mt7996: validate default EEPROM firmware size
- b754d3a6d44c wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames
- 6be59da2063d wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy
- 9e20da749ad2 wifi: mt76: mt7925: cancel mlo_pm_work on stop
- 5f48b0d752a7 wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy
- 44be85af3e17 wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex
- c1f214dd1351 wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot
- b1596e212ab1 wifi: rtw88: pci: fix resource leak on failed NAPI setup
- 51d8b3557472 wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()
- 7159e1e12468 wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars()
- 42785f7e8d31 wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids
- 46e3a14d901b wifi: rtl818x: initialize eeprom_93cx6 struct to zero
- d29a165588b6 wifi: mwifiex: Detach sync cmd buffer on interrupted wait
- 59ebe7b0ff64 mm/kmemleak: report RCU-tasks quiescent states during the scan
- 3ee49d4dbd08 mm/kmemleak: stop the task stack scan early when interrupted
- b64d49ca15e3 crypto: atmel-ecc - avoid stale fallback key after set_secret failure
- 50c52da15629 crypto: atmel-ecc - clean up and improve ECDH comments
- fcd86180ef78 crypto: iaa - unmap dst before software fallback on decompress
- a47a416ff68d fuse: copy request headers via a stack buffer for io-uring
- 303b6eeedf29 fuse: decouple fuse_ring creation from ent registration
- 972ab8b9c08f wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop
- ad2a9fdca4a7 wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()
- ba04715ee672 wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()
- 4437b09f82f6 i3c: renesas: Perform Dynamic Address Assignment on resume
- ba3c86a90280 i3c: renesas: Restore STDBR and EXTBR registers on resume
- 9206527c91b9 i3c: renesas: Reset the controller on resume
- de6aa7bd623f i3c: renesas: Reconfigure the DATBAS register on re-attach
- 3d62955cb4b7 i3c: renesas: Follow the reset deassert order used in probe
- 7ea5b0ca2f39 i3c: renesas: Clean DATBAS register on detach
- ec631aff9326 i3c: renesas: Check that the transfer is valid before accessing it
- aac3c5aababc i3c: master: svc: bound IBI payload to the requested max_payload_len
- 4837be0f9ac2 i3c: master: Fix info leak and UAF in device unregister path
- de8c32b0a246 i3c: master: adi: initialize the lock before enabling interrupts
- 251db58324ea i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode()
- f39a3e9cc594 dm-pcache: fix use-after-free and invalid seg operations in kset_replay()
- 8a2a2f78c6ba dm-pcache: fix implicit u8 truncation of gc_percent in message handler
- 692037ae1a7c dm-pcache: only hand out initialized cache segments
- 5311dfc5cd70 dm-pcache: detect a cycle in the last-kset chain during replay
- 1ab55354368d dm-pcache: clamp the tail kset read to the segment data region
- 8bf7a06ca3c1 dm-pcache: bound the persisted tail-position offset
- e889c0ee8116 dm-pcache: validate on-media seg_num against the cache device size
- 5ac38f4b4862 dm-pcache: validate kset key_num and intra-segment bounds
- 3e19172089ec dm-pcache: validate geometry fields from on-disk cache_info
- 8c52308f3805 dm-switch: use WRITE_ONCE() in switch_region_table_write()
- 0c8f7870ed3e dm-stats: fix a crash if allocation of per-cpu data fails
- 1f2f7d885bf8 arch_numa: avoid false positive fortify warning in setup_node_to_cpumask_map()
- ceab9302388b rust: num: reject Bounded::shr overshifts at build time
- 641dacada331 ALSA: hda/realtek: Fix Lenovo Yoga Slim 7 14AKP10 quirk ordering
- 2bfc88e83398 ALSA: hda/realtek: Enable micmute LED on HP EliteBook 6 G1a p/n: AD3Q9ET#UUG
- 013daf719370 ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r
- 17fc26d7bbe8 ALSA: hda/realtek: Add quirk for TongFang XxAF5xxx
- f48c5f3b03af ALSA: virmidi: Check card index validity at probe
- 6d6fdb24fe2e ALSA: serial-u16550: Check card index validity at probe
- e1ce8ad1009b ALSA: portman2x4: Check card index validity at probe
- 7cf280fbef5d ALSA: pcxhr: initialize mutexes before requesting threaded IRQ
- cf3af453a48c ALSA: mts64: Check card index validity at probe
- 8adda66edf79 ALSA: mpu401: Check card index validity at probe
- f78dc2ff60be ALSA: hda/ext: preserve PPLCCTL bits when clearing reset
- 29ab2df278ab ALSA: FCP: do not copy out an uninitialised init response
- b06ebc7fe25a ALSA: bcd2000: clear the URB pointers on disconnect
- efbc2e9e43a1 ALSA: aloop: Check card index validity at probe
- 34816e2cfeab ALSA: 6fire: bound the MIDI event length from the device
- c8be3a076a59 mfd: sm501: Fix potential memory leaks during remove
- 8391ee06d088 mfd: qnap-mcu: keep the reply buffer alive past a command timeout
- 3266537d0333 mfd: cgbc: Fix teardown ordering in cgbc_remove()
- 8f9332070243 hwrng: stm32 - Fix runtime PM cleanup on registration failure
- c73fb911e02b seg6: reset IP6CB after IPv6 decapsulation
- 0370da114a9b net: skbuff: don't touch shared zerocopy state in skb_tx_error()
- 497f3abfaa97 net: fix spurious TX timeout after dev_activate()
- 9144f2c53a04 net: cap advertised IP tunnel headroom
- b74d313567df net/smc: unregister the connection before draining the rx tasklet
- 2cb7a8d64b7e net/smc: stop killed, freed and out_of_sync sharing a byte
- adef84cc85d4 net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link()
- 0926f59ca0f9 net/smc: fix use-after-free in smc_rx_pipe_buf_release()
- d9a879ac2595 net/smc: fix socket refcount leak in smc_switch_conns()
- f517cf020338 net/smc: do not dereference an unset send buffer on the SMC-D teardown path
- 0d6f80be8ac5 net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry
- 5e5d9e6df677 net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages
- 7498cadd989d net/mlx5e: do not HW-GRO coalesce small frames
- 4cf9400f29e2 net: ntb_netdev: Count packets dropped on RX refill failure
- 759193a45dc6 net: ntb_netdev: Avoid double-accounting netif_rx() drops
- 1a522d4480c9 net: ntb_netdev: Fix TX busy and drop handling
- 75a604e9f1cf NTB: ntb_transport: Reject oversized TX buffers
- 89177732fe16 NTB: ntb_transport: Fail TX enqueue when the QP link is down
- a08423b7fe91 NTB: ntb_transport: Recycle TX entries before client callbacks
- d6c0af293129 net: thunderbolt: Mark the connection down when bringing it up fails
- 1c361f6cf39b net: thunderbolt: Release the Rx HopID that was handed out on mismatch
- 66b50c31419e net: ravb: serialize PTP clock teardown
- 0aaa53936419 net: ravb: avoid dereferencing an invalid PTP clock
- fb4d77553841 net: phylink: correctly validate returned PCS in phylink_inband_caps
- 9f316e64923a net: openvswitch: fix nf_connlabels leak in ovs_ct_init
- 7f072b84afd0 net: openvswitch: fix flow mask use-after-free on flow deletion
- cc561f8af255 net: mctp: hold a reference to the route device in mctp_route_lookup()
- 50c4038f1670 net: l2tp: do not propagate multicast notification errors
- 30cef9c1229a net: ipa: fix stalled modem TX queue after runtime resume
- cc29f15244e0 net: ibm: emac: mal: fix NAPI locking
- 48d1c9665db6 net: bnxt: ring the doorbell when SW USO exits early
- 1610a8c2b93e net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO
- 0ada54ea63e4 net: tun: bound receive headroom
- 4f67a23f3f8d net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition
- d6f25e5bd777 slip: fix use-after-free in sl_sync()
- 68d7cc551223 xdp: fix zero-copy frame layout
- a7f0130a0917 net/iucv: filter frames in afiucv_hs_rcv() by ingress device
- a496c51dd325 ipmi:msghandler: Cancel work cleanly on an error
- 8ada17dd4c4f ipmi: si: Fix NULL pointer dereference after failed registration
- b115b7d06f26 ipmi: Remove all sysfs files on registration failure
- a84c6e3d188f ipmi: ipmb: validate write message length
- d715d19cfcfe interconnect: Fix use after free in icc_get() and of_icc_get_by_index()
- 2b8ad4981ece io_uring/query: cap user size passed to copy_struct_to_user
- ef2bd2da1b77 io_uring/waitid: avoid siginfo copy during ring teardown
- 7bc98e2de8c5 io_uring/waitid: honor task_work cancellation
- 6dca6c4269b0 platform/x86: hp-bioscfg: warn on element type mismatch instead of failing
- 400cbc3ccc88 platform/x86: hp-bioscfg: pass validated element count to package parsers
- 4ef68ed53f09 platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed
- ddf98cf33529 platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()
- 550d80f69fe5 platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password
- b699e5c1f63a platform/x86: hp-bioscfg: fix heap OOB read on empty password write
- 67b60703d7d8 platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()
- c32ac3443e5a platform/x86: hp-bioscfg: bound ordered-list parsing by the package count
- ea069840cb75 platform/x86: hp-bioscfg: advance elem past consumed array elements
- ab3526ce387e platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS
- dd38ae725409 platform/x86/amd/pmc: Fix msg_port restoration in amd_stb_debugfs_open_v2()
- 30e5f4d0cd0b platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails
- 775d4cde1f97 platform/x86/amd/pmc: Propagate SMU errors and validate S2D address
- f1189a7665b0 platform/x86/amd/pmc: Restore msg_port on amd_stb_s2d_init() error paths
- 4d9bf63ed74f platform/chrome: sensorhub: Bound the EC-reported sensor number
- 91d761111307 platform/x86: think-lmi: Fix current password length check
- abbcc0354108 platform/x86: think-lmi: Free system certificate signatures
- 57d8750fd5ed platform/x86: think-lmi: Fix certificate thumbprint sysfs output
- a93df956ee4d platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[]
- 546a229829c6 platform/x86: lenovo/ymc: Only match lower byte in WMI lid switch query response
- 5c4c6514497d platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path
- 582b82e573a0 platform/x86: int1092: Fix potential memory leak in sar_probe()
- 9ed7240d6366 platform/x86: hp-wmi: Add support for OMEN MAX 16-ak0xxx (8DD6)
- 282cdcb7b03d platform/x86: ISST: Return error during profile addition
- 68148d064cbe platform/x86: ISST: Validate parameter for frequency and priority
- ecfe22c2b72e platform/x86: ISST: Validate parameter for core power state
- a352b135256b platform/x86: ISST: Validate max level for set feature
- 82d4afadb02f platform/x86: ISST: Validate logical CPU id and clos id
- fe6e73ef684d platform/x86: ISST: Use PP level enable mask
- 1b324191da70 platform/x86: ISST: Just allow 2 bits for SST feature enable
- ef7975af1512 platform/x86: ISST: Add a NULL check for sst_inst[]
- c2b8a6249119 mmc: via-sdmmc: stop card-detect handling on probe failure
- eaca730c6f5e mmc: via-sdmmc: cancel card-detect work on remove
- 207b4dc6eb10 platform/x86: ISST: Validate socket ID in clos_assoc ioctl
- d19385624bdf platform/x86: ISST: Validate level in perf mask ioctls
- eb73b9d51490 platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer
- e27e90bde68b iommufd: Fix UAF in selftest IOPF reporting
- 07b4fe1367f0 iommufd: Release current IOAS on xa_store() failure
- 50a66a63d1c8 iommufd: Avoid locking internal accesses during unmap
- efd9a33f2022 iommupt: Return zero for invalid iova_to_phys() ranges
- 87bc611c6c98 iommu/vt-d: Force requesting ACS when tboot is enabled
- f0a2c50254cf iommu/vt-d: Fix no_iommu to disable platform opt-in
- eaf44262af24 iommu: Fix dev_iommu memory leak when device_add fails in iommu_mock_device_add
- 78fd5a2d65f3 iommu/arm-smmu-v3: Manage teardown with devm
- f9b7375db3b3 iommu/arm-smmu-v3: Add HAFT support for SVA
- 445204550f89 iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field
- 37a96a30617a iommu/sva: Set handle->dev before the SVA handle is visible
- 7f7074a886c4 iommu/msm: Unwind probe state on registration failure
- d1470e16c197 iommu/amd: Put PCI device after handling PPR faults
- 4a5b7ee11cda PCI/proc: Warn on writes to kernel-exclusive config space regions
- 6351e9407632 PCI/proc: Use file_ns_capable() when checking config space read access
- 84536685a7f4 PCI/proc: Avoid spurious runtime PM wakeup on config space accesses
- a69a029f981d PCI/MSI: Enable memory decoding before restoring MSI-X messages
- 21fd595ad137 PCI/ASPM: Avoid L0s for Realtek RTS525A
- 329e42c0ff09 PCI/AER: Fix mapping of errors to agent & layer
- 271ce2317009 PCI/AER: Emit TLP Log only for unmasked errors
- 3dc196d3bbea PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses
- f8ed6f530141 PCI/sysfs: Fix read byte order in pci_read_legacy_io()
- 6453246da7df PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608]
- e54e8d2a0f9c PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts()
- e3589ca5f2e6 PCI: plda: Fix use-after-free of event IRQs during teardown
- d9ad2f0fe787 PCI: starfive: Fix resource leaks on error paths in host_init()
- 99e4d0286af3 PCI: meson: Fix GPIO state while requesting PERST#
- caf71f66d552 PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk
- 1f0269720d45 PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip
- 15ec03452c18 s390/dasd: Propagate partial completion length across ERP recovery
- 449f3bada7a9 s390/dasd: Guard sysfs discipline callbacks against unallocated private data
- b0d94dd6e82d s390/dasd: Do not complete a failed ESE read as successful
- 91770b08a120 s390/percpu: Fix MVIY_PERCPU() with older binutils
- 71d46de9153e s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
- 36e6ce0f402f power: supply: max17040: synchronize work cancellation on suspend
- ad8081ede936 power: supply: max17040: drop incorrect I2C functionality check
- c7aa4c3708cc power: supply: max17040: propagate register read errors
- 35242c93d35f power: supply: ucs1002: fix use-after-free on remove
- b955da82db41 power: supply: twl4030_charger: cancel workers via devm
- 7323e562f696 power: supply: rt9455: quiesce delayed work before teardown
- 6cc6c28c9ab6 power: supply: qcom_battmgr: terminate the strings from firmware
- 49fbcd3da295 power: supply: qcom_battmgr: fix use-after-free
- b64789e21699 power: supply: pf1550: enable charging when battery profile exists
- b4eb6a056b44 power: supply: lp8788-charger: fix use-after-free on remove
- 6ab3128292df power: supply: lp8727: fix use-after-free in lp8727_release_irq()
- 304a29ac55ba power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS
- 3d1e01443b22 power: supply: cros_usbpd-charger: bound the EC-reported port count
- 6d532582ff3c power: supply: charger-manager: register regulators before exposing sysfs
- 58f1025eca92 power: supply: bq25890: Fix power_supply reference leak
- c8addb842ae8 power: supply: bq256xx: drain usb_work before freeing the charger
- 47ccbad210f4 power: supply: bq24257: fix use-after-free on remove
- 8320cbd81bc2 sctp: fix stream->outcnt underflow on duplicate RECONF responses
- db8dc28b73b4 sctp: distinguish sequence zero from wildcard in reconf lookup
- 0ee697defc05 sctp: fix NULL deref on untransmitted RECONF completion
- 3537961df216 sctp: drop a chunk if its transport was removed
- a713e1b3a265 sctp: stop processing a packet once its association is deleted
- 832a685efeb5 nvme-tcp: reject a read that transferred too few bytes
- 3a0b05145053 nvme-tcp: fix host memory disclosure on R2T for a read command
- 641ad3a30ba5 nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
- f691394c1cc6 nvme-pci: disable controller on admin queue IRQ setup failure
- f5827817b4fc nvme: zero the discard fallback page
- 0b46ec7f28a0 nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in error path
- 21bcb609e0ab lockd: fix swapped arguments in nlmsvc_match_ip()
- 51af080ca4e5 lockd: fix NULL dereference on lockowner allocation failure
- da6e60e5b38f lockd: fix NLMv4 GRANTED_MSG handling
- e999a8813365 lockd: pin next file across nlm_inspect_file lock-drop
- 5dc0b2a9af95 ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()
- 6d512e1624b1 i2c: mxs: fix DMA channel leak on probe error
- daa6960b0df4 hwmon: (max6621) fix temperature clamp range
- 1daf80928fb5 hwmon: (max6621) fix negative temperature offset and crit readings
- 5fc3f547dd96 dma-contiguous: fix truncation of numa_cma / cma_pernuma sizes >= 2G
- 95a109f5af67 ASoC: codecs: aw88261: only check PLL and clock state at power-up
- 7992a923348e ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC
- e20902d383a6 arm64: proton-pack: Restore the nospectre_bhb command-line option
- 2d3137a332aa arm64: compat: Fix decrementing LDM/STM alignment emulation
- 97ab7c2ccffc ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion
- 5d85eef222cf openvswitch: only skb_tx_error() a packet we are about to drop
- 6a6d36fadb85 openvswitch: Fix CT limit teardown use-after-free
- b53435c079c7 openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
- b53e2b271eeb ocfs2: fix readdir position truncation on 32-bit kernels
- 7f5e32665598 ocfs2: fix cached cluster count after suballocator reclaim
- 67ba14821213 ocfs2: cluster: fix o2hb_dependent_users leak on pin failure
- 148e5019e1f9 ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from drop_item
- 470212a5eefa ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()
- b8a5c0c32df2 ocfs2: validate directory-index entry counts when reading metadata
- 04ead708e13d ocfs2: validate rl_used against rl_count in refcount block validator
- a8facb1670b4 ocfs2: validate lengths in dlm_mig_lockres_handler
- 2487bea20983 ocfs2: bound namelen in dlm_migrate_request_handler
- 09e93a60e18e ocfs2: always run deallocs on copy-on-write completion
- 1774c5b3713a orangefs: skip leading spaces before parsing client debug masks
- 519f4146b8b8 orangefs: fix double-free of trailer_buf on readdir copy failure
- 376796add2d7 PM: sleep: Unblock runtime PM when device prepare fails
- a14a97048e48 ring-buffer: Stop remote reader update when page swap fails
- d787d509bdf6 ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page
- bf242baf58de ring-buffer: Hold cpu_buffer::lock when resizing a subbuf
- 81063bbb16c4 ring-buffer: Free cpu_buffer::free_page with subbuf_order
- 53106e9262a3 ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page()
- dac639482116 regulator: qcom-refgen: correct the regulator type to CURRENT
- 16583ed17a26 regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata
- 8648e29e5c01 regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer
- edae84e54617 RDMA/uverbs: Guard legacy bundles without method_elm
- 9e71d0f4944b RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR
- 0be1955040a2 RDMA/ucma: Lock the handler in ucma_write_cm_event()
- 43a7d8ae9f64 RDMA/ucma: Lock the handler in ucma_set_ib_path()
- 08b8630b5578 RDMA/ionic: Embed counter driver data in rdma_counter allocation
- 94d393f8dd94 RDMA/ionic: Cap eq_count to the eth driver's interrupt vector budget
- 320e5258a53a RDMA/cxgb4: Cancel reg_work before freeing device on remove
- f5c8619ccbd7 qede: Fix NULL pointer dereference in TPA fragment processing
- 0ce59c4148ec ptp: vmclock: prevent read-only mappings from becoming writable
- 440bcb0948a1 remoteproc: scp: Fix device reference leak on failed lookup
- 098bfc94904e riscv: unaligned: stop using kthread for check_vector_unaligned_access()
- 6e7b8041068c riscv: acpi: Handle LPI architectural context loss flags
- 82088f88c96b RISC-V: KVM: Fix PMU event info array size overflow
- 4efc2b3f2c19 riscv: dts: spacemit: k1-orangepi-rv2: fix maximum CPU core voltage
- c853c8524756 riscv: dts: spacemit: k1-orangepi-r2s: fix maximum CPU core voltage
- 20a1c2869f12 riscv: dts: spacemit: k1-musepi-pro: fix maximum CPU core voltage
- 1f6b98158afe riscv: dts: spacemit: k1-milkv-jupiter: fix maximum CPU core voltage
- e86e01247ec2 riscv: dts: spacemit: k1-bananapi-f3: fix maximum CPU core voltage
- 2efa7a531c1c arm64: dts: rockchip: Fix rk3588s-roc-pc audio description
- 72c93c1f4f2c arm64: dts: rockchip: Fix rk3399-roc-pc-plus analog audio
- 11918726dadf arm64: dts: rockchip: fix emmc reset polarity on px30-cobra
- 53992f89da99 arm64: dts: rockchip: fix eMMC reset polarity on PX30 Ringneck
- 8f7c9ed1af20 arm64: dts: rockchip: fix eMMC reset polarity on PP-1516
- 91ee0d0c4b29 arm64: dts: qcom: x1-dell-thena: mark l12b and l15b always-on
- 866b788b1e74 arm64: dts: qcom: sm6115-pro1x: Correct touchscreen GPIO flags
- 7ee10b72558e arm64: dts: qcom: kodiak: avoid EFI overlap for ADSP remote heap
- 0131497574eb Revert "arm64: dts: rockchip: Further describe the WiFi for the Pinephone Pro"
- ba49fe53689d rpmsg: glink: smem: order FIFO read after availability check
- d86f65aed014 scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock
- 6fd1cce5018f scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables()
- c736ea0fe7b4 sched_ext: Keep kick_sync waiting on the rq's own CPU
- f974f54c3078 sched_ext: Fix scx_bpf_dsq_reenq___compat kfunc extern prototype
- c480961a1e79 sched_ext: Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users
- 1df5802fa783 sched_ext: Fix inverted ops.core_sched_before() invocation
- d644a145d76c sched_ext: Fix exit_task leak on fork failure during enable
- d863b1710d34 sched_ext: Fix scx_bpf_dsq_move_to_local___v2 compat detection
- 28cc9c9ade88 sched_ext: Count rq lock releases in rq->scx.lock_drop_seq
- cdafb68155be sched_ext: Fix rq->core_pick corruption under core scheduling
- 6d1890d3c613 sched_ext: Fix this_rq() assumptions in dispatch kfuncs
- 6f1d3bfe5443 sched_ext: Replace SCX_RQ_BAL_KEEP with a dispatch verdict return
- 23eda24f325a sched/core: Make core-sched flips wait for in-flight selections
- 88ed5a66467c sched/core: Handle pick_task() releasing the rq lock
- 323c411fb631 media: staging/ipu7: fix async notifier UAF on probe error path
- 95f54d10be87 staging: media: tegra-video: vi: fix probe failure on skipped last port
- fc9937019cf7 staging: media: tegra-video: fix of_node_put() on VIP parse errors
- c5e073f2fbfd wifi: mt76: mt7925: cancel pending mlo_pm_work
- 8eb73016fb39 wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets
- 1bd7947f1463 udf: reject VAT indexes equal to the entry count
- 577097455d08 svcrdma: Validate Read chunk positions before reconstruction
- ac1dd6002f75 svcrdma: Use svc_xprt_put to free listener on create failure
- 45dbdb2637b7 svcrdma: Reject Write/Reply chunks with segcount 0
- 465f511f59a0 svcrdma: Reject Read lists that exceed the page budget
- 5120fe54e0e2 svcrdma: Reject oversized Read segments at decode time
- 8ec60eb51fae svcrdma: Reject inline replies that overflow the pull-up buffer
- 1f6a14c142fe svcrdma: Reject connection when transport allocation fails
- 45a444a17240 svcrdma: Fix unmatched rn_unregister on failed accept
- 6d33a7e6bf6c svcrdma: Fix pcl_for_each_segment for empty chunks
- 4493c96bbd00 svcrdma: Fix offset arithmetic in read_chunk_range
- 673e358ab7c1 svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails
- cfca6eb3345b svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id
- 7fbb6d2ab039 SUNRPC: wait for in-flight client TLS handshake callback
- 7a946b2e7207 SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2
- 880effc943ed SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field
- 9d94f046b23d SUNRPC: reject duplicate CREDS_VALUE options
- 3f019571928b sunrpc: init gssp_lock before publishing proc entry
- d395c30d570c SUNRPC: harden gss_unwrap_resp_priv length checks
- a7894e10572d SUNRPC: harden gss_krb5_unwrap_v2 against short tokens
- 0bdb26b2534a SUNRPC: Guard svcauth_gss_release() dispatch on rq_auth_stat
- cdf7a233cb94 sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir
- f85a83774d7f SUNRPC: fix gssx_dec_option_array error path bugs
- e0c5693d3f9a sunrpc: defer rq_argp and rq_resp free until after RCU grace period
- 6debde9e3e6a SUNRPC: close backchannel before destroying callback service
- b541a1504697 SUNRPC: Check svc pool percpu counter allocation
- 3d60fdf95114 SUNRPC: always drain cache_cleaner before destroying a cache_detail
- 48d04a32eb44 SUNRPC: Restore NUMA_NO_NODE for svc thread allocations in global mode
- 8f766d2d0b4d sunrpc: route to a populated pool in svc_pool_for_cpu()
- 2eed1e6a976a SUNRPC: svcauth_gss: enforce krb5 token minimum length
- 0fa8a8acae57 SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
- 85e9602650e9 SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow
- 84646f5b945a phy: fsl-imx8mq-usb: fix typec switch leak on probe error path
- 0d8e2404925a params: fix charp corruption on allocation failure
- e60466011ac3 nouveau/gem: reserve the bo in the info ioctl around the vma lookup
- 6e3d09fcd97e module/kallsyms: fix nextval for data symbol lookup
- bf19d166337c mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction
- 49d38c1b4390 mpls: reload header after pskb_may_pull()
- e4496dda2c6d module: validate string table section types
- df7d4d011d5a md: do overflow check for sb->bblog_shift in super_1_load()
- 00449d752bee md/raid10: fix still_degraded being inverted in raid10_sync_request()
- bc584959c3a5 mailbox: qcom-ipcc: fix duplicate channel allocation across holes
- 69a734359639 libnvdimm/labels: Prevent integer overflow in __nd_label_validate()
- 0c3204aacbe8 landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
- f6b1b15848fd ipv6: use RCU iterator to dump route exceptions
- eab3a917cdcb ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()
- 565038b0092f ip6_gre: fix hardware header length for NBMA tunnels
- 8fc56ca49fc0 ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit()
- f1281d4b9908 ip: orphan prefetched skbs before multicast forwarding
- fd01f1a3ed4a ipip: fix skb leak in collect_md mode when metadata_dst allocation fails
- 595cac7f1b32 jbd2: check need_resched() when skipping busy checkpoint buffers
- c2c0fb364685 jbd2: bound shrinker scans by examined checkpoint buffers
- 42a6f03cf352 kho: fix size calculation in kho_preserved_memory_reserve()
- 3119d58e4ef8 kasan: fix cache shrink race with CPU hotplug
- 7dcf816c1592 Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request
- cf7686449338 Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative
- db1ff5dc173c Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative
- 9907e72f0f66 Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection
- 26f66d5b8a56 Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb
- 43b64cb6ed3b Bluetooth: hci_conn: re-enable advertising only for peripheral role
- fbf7961964a6 Bluetooth: RFCOMM: serialize security confirmation handling
- 03288b7447c9 Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready
- 1b2e9b2cf944 Bluetooth: hci_uart: Fix false success return in hci_uart_setup()
- 981f7c23025b Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative
- a79432a904df Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378
- ba147f2f56a9 cxl/ras: Fix cxl_rch_get_aer_severity() wrong severity register
- 7256c9bd929b cxl/pmem: Format the nvdimm serial number as unsigned decimal
- 491d8c9ac98d cxl/mce: Make the MCE notifier per-region
- d8957545fe96 cxl/features: bound fwctl command payload to the input buffer
- 8fddd484992a cpufreq: schedutil: Fix rate limit overflow
- 36c55d118d5e cpufreq: apple-soc: Fix OPP table cleanup
- 92f37721a33a coresight: etm3x: Fix cntr_val_show() to match cntr_val_store() behavior
- cb409b38b023 dm array: reject an array block whose value size is not the caller's
- 9808ddffb4bc dm array: validate array block headers on read
- f79b53ca3a68 dm raid1: reserve space for NUL-terminator in build_constructor_string()
- 6876ca330e74 dm-era: fix shadowed superblock leak on take-snap failure
- 15fc1ec72e1f dm-io: report non-retryable errors separatedly
- 8dc48b68d7c3 dm-io: clone the source bio instead of copying its biovec
- dff481e12b3f bpf: Harden bloom filter sizing and indexing on 32-bit kernels
- a1159c892612 buffer: avoid tail commit walk for uptodate folios
- 9a23747909fc bpf: Disable preemption in __bpf_get_stack
- 6a19b18d4588 bpf, x86: Fix per-CPU address resolution into an extended register
- e04b6f48dd44 bnxt_en: Write doorbell when linearizing skb fails
- a142c024f07d bnx2x: fix double free in bnx2x_init_firmware() error path
- bb56e97bd676 Bluetooth: eir: Fix OOB read in eir_get_service_data()
- 9fe52fd63e5b Bluetooth: btusb: limit RTL8761B BROKEN_EXT_SCAN quirk to 0bda:a728
- 186a0975283f Bluetooth: btusb: Add ASUS USB-BT600 for Realtek 8761CU
- 6b2da140580b Bluetooth: btusb: Add ASUS USB-BT540 for Realtek 8761CU
- c7c8e0454f31 block: set QUEUE_FLAG_DYING unconditionally in blk_mark_disk_dead()
- d44a97a3b1c0 block: validate user space vectors during extraction
- 0dc53c2dd593 backlight: aw99706: Honor the core blank state in update_status()
- 32a5f01bbbaf backlight: aw99706: Fix DT property names to match binding
- ff2fb3c1e60c auxdisplay: charlcd: cancel backlight work on registration failure
- 4a4268a0b0a5 ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes
- 1ff69db8f352 ARM: 9477/1: Disable broken eBPF JIT on the Risc PC
- 22a0982db25c alpha: marvel: Fix lock ordering in init_io7_irqs()
- 4722bedf7a93 alpha: marvel: Fix irq_set_status_flags to use correct IRQ number
- a7800cf56bb3 alpha/PCI: Fix I/O port accessor argument order in pci_legacy_write()
- 9a33db250f35 ACPI: TAD: Add locking around AML evaluations
- 495daa190369 ACPI: scan: Avoid registering platform devices with resource overlaps
- 15d2b7f38f95 ACPI: pfr_update: fix stack buffer overflow in query_capability()
- 3c0c3e96fccf ACPI: CPPC: Skip desired_perf read in cppc_get_perf()
- 712d9e196f82 ACPI: CPPC: Reject desired_perf reads on _CPC revision 4+
- b48b613073c3 ACPI: APEI: GHES: fix ARM section length accounting after header
- c9655ce86b75 ACPI: APEI: Fix ERST timeout unit conversion
- 0e25382b05de acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks
- 7d6fa298c234 accel/rocket: Fix error path handling in rocket_job_run()
- 81731f1eda5e accel/rocket: initialize job domain before cleanup paths
- dfff90a6eb22 accel/rocket: fix NULL dereference and integer overflow in rocket_job_push()
- 0f001491e5a2 hugetlb: only adjust reservation during unmapping if mapcount is 0
- fbffbfdae559 hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device
- ac8d8b599d46 fsnotify: Fix stale object mask after concurrent mark updates
- 397423af18b6 fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration
- c4f196bfeedd forcedeth: fix off-by-one when saving/restoring non-PCI config space
- c87d9c412bf9 fonts: fixup font.h kernel-doc warnings
- 9e768ae51426 fbdev: uvesafb: unregister connector callback on init failure
- 1981e54ac137 fbdev: ssd1307fb: defer I2C transfers from damage callbacks
- fab0234a97d2 fbdev: pvr2fb: correct user pointer annotation and sentinel initializer
- 09db79078f25 fbdev: omapfb: panel-dsi-cm: initialize lock before registering display
- e65d6326a763 fat: restore original value when fat_ent_write failed
- b8f73b163b64 fanotify: fix use-after-free of file range info
- 5efb3350230f ext2: Fix lost inode updates for IS_SYNC inodes
- 7f4a89d4f0d6 erofs: skip sufficiently large global buffers when resizing
- ab4647459098 entry: Fix seccomp bypass after ptrace with TSYNC
- 0dbc2e94b81d efivarfs: Rate limit statfs() handler
- 75101e106c42 ecryptfs: show filename encryption options
- 654b7e79443f ecryptfs: release message context on send failure
- d2869768eab5 ecryptfs: reject too-small tag 70 packets
- a419c9ebfc9a ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet
- 747fd45be396 ecryptfs: pass packet set buffer size to parser
- 4c02acbe0a26 ecryptfs: hold msg ctx list lock when cleaning daemon queue
- 7da5861dcc7b ecryptfs: fix tag 11 packet exact-fit size check
- 279b1663be4f eCryptfs: bound the packet-length peek to the user buffer
- 6e844d4b8243 ntfs: verify run length exceeding volume boundary
- cd7b3dc7557f ntfs: validate non-resident attribute offsets
- 8f8420b68a6f ntfs: reject invalid MFT LCNs from boot sector
- b0cc6dbc655e ntfs: reject invalid empty mapping pairs
- dc15a9f5307d ntfs: bound the free-cluster bitmap scan to the volume
- 1135ebc22599 fs/ntfs3: bound page_lcns[] index by the log record
- 4a1b39b2e10e fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()
- 0908da07c23b fs/ntfs3: validate dirty page table on log replay
- 76e0f85f6507 eventfs: Initialize ei->children and ei->list in init_ei()
- 2785f06aba4f HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during teardown
- 774609feaaf4 HID: intel-thc-hid: intel-quicki2c: fix autosuspend cleanup during teardown
- 54e0bafc0653 HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer
- ee8ad1bb1e96 HID: intel-thc-hid: intel-quickspi: validate report size before copy
- 7c18fb36708a HID: mcp2221: validate report size in mcp2221_raw_event()
- 968546b676d9 HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes
- 2eda1513f573 HID: mcp2221: stop device IO before hid_hw_stop
- c457bb516b61 HID: universal-pidff: stop the device when force-feedback init fails
- 3155dc327344 HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind
- d96f8958d446 HID: sensor: custom: Fix field sysfs group cleanup on failure
- fbb5a60f5c31 HID: roccat: free buffered reports when destroying device
- 699a3c8b56e1 HID: picolcd: clamp eeprom debugfs read to bytes actually received
- 0329354abba3 HID: corsair-void: Check size of status and firmware events before reading them
- df9168b2678b HID: apple: preserve keyboard backlight across T2 resume
- 5b16a1967a01 smb: client: restore the data_offset bound in is_valid_oplock_break()
- 411e484fe71a smb: client: reject a tree connect response whose byte count is too small
- 7e32da6047d9 smb: client: harden DFS cache against invalid target hints
- 711cf71300d7 smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr()
- 033bc80019f0 smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()
- ab284008d7d0 smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV
- 62a3025983c8 smb: client: fix ALIGN() overflow in symlink_data() error context loop
- 74e3ef4630f0 ksmbd: only rebind the reopened file's own oplock on durable reconnect
- 5baab40404a9 smb: client: clear ce->tgthint in free_tgts()
- 5e6533a683f6 smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2
- 69bfe810ecd1 smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions
- 81fc3868a7f7 cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC
- b057ca17b656 cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
- 4bea15d9c768 cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size()
- 12bafe32f09c cifs: call pagecache_isize_extended() in cifs_setsize() when extending
- 7d4312f0ca20 cifs: add cifs_resize_file_locked() to guard fscache_resize_cookie() under i_rwsem
- 583cf579b32d audit: avoid dropping live tree ref on fsnotify rule autoremove
- aeb5770732cd btrfs: do not overwrite NODATASUM flag when removing NODATACOW flag
- 05a1a816eef8 btrfs: fix extent map leak in NOCOW direct I/O write
- 4d43107e807b btrfs: drop recovered reloc root refs on recovery failure
- ac7a5a538576 ceph: fix leaked inode reference on writeback abort at umount
- 3d122b2feb1d ceph: do not repeat ceph_trim_dentries() if no progress possible
- f341270ac5f5 ceph: cap delegated inode count in ceph_parse_deleg_inos()
- b12b3320c81f ceph: bound xattr value length in __build_xattrs()
- 332c444f4dc6 ceph: bound num_export_targets array for mds info v2/v3
- 5f892c767b30 ceph: bound MDSCapAuth path and fs_name decode in handle_session()
- e7c2fd3893a7 ceph: bound copied dentry name length in NFS export get_name
- 96c3f5fbb0d5 ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
- 3d0311481b89 ceph: force a cap message when a deferred revoke can't be acked immediately
- 21d5be092d94 ceph: fix UAF in check_new_map() on session freed during unlock
- 2dba24dcd505 ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock
- 79900d978158 libceph: reject buckets with mismatched CRUSH ids
- 201db408872c libceph: validate OSD extent maps before cursor advance
- 9fb4c08ac2cb nfsd: use test_and_clear_bit for somebody_reclaimed to prevent lost update
- 81cf7f141386 NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup
- 2a9d637c2a8f NFSD: Prevent client use-after-free during delegation revoke
- bf1f94869152 NFSD: Prevent client use-after-free during admin state revocation
- 0c1a755b7212 NFSD: Prevent post-shutdown use-after-free in unlock_filesystem
- 8cf4ff0a7c08 NFSD: Prevent lock owner use-after-free during client teardown
- ff8a3cff02b9 nfsd: revoke copy-notify stateids before dropping their reference
- 5b3a7d7c23c0 nfsd: release OPEN-decoded posix ACLs via op_release
- aa34577f39e3 nfsd: reject reclaim LOCK after RECLAIM_COMPLETE
- 1195483965a5 nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE
- e2543852152b nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops
- 08af9593e2b4 nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache
- ab43ff94f5df nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd()
- 431c70ca5163 nfsd: initialize DRC hash table before registering shrinker
- 4cdef96892f4 nfsd: initialize copy-notify stateid before publishing it
- 559570f91a7d nfsd: hold rcu across localio cmpxchg retry
- ff99ed007f06 nfsd: gate nfs3 setacl by argp->mask
- 37eea38e7898 nfsd: gate nfs2 setacl by argp->mask
- 62e5949f0dd5 nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo
- c81cef6a805d nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget
- 58b35b13e537 nfsd: fix version mismatch loops in nfsd_acl_init_request()
- a385cf5e016b nfsd: fix UAF in async copy cancel and shutdown
- 14b978e8d05c nfsd: fix stale s2s_cp_stateids IDR entry for async COPY
- 2da9a73acd3b nfsd: fix reply size estimate for GET_DIR_DELEGATION
- a3c75f9bb6f5 nfsd: fix refcount leak in nfsd_file_lru_add on insertion failure
- 033e783709ce nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file()
- fa6590dfd16a nfsd: fix partial-write detection in nfsd_direct_write
- 3c896db12389 nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs
- 6ed8d6de7ec9 nfsd: fix nfsd_file leak on inter-server COPY setup failure
- daaf4d951f0f nfsd: fix netlink dumpit error handling for rpc_status_get
- a278d361e0e8 nfsd: fix layout fence worker double-reference race
- 66d89bc7ecf1 nfsd: fix FL_SLEEP being set unconditionally for all LOCK types
- cadc9036d5a8 nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net
- 11db8df188b3 nfsd: fix dentry ref leak on V4ROOT export filehandle lookup
- c7270f62e7a0 nfsd: fix cpntf publish race in nfs4_init_cp_state
- 984364919622 nfsd: fix clock domain mismatch in clients_still_reclaiming()
- 97bda8b4284d nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke
- a95a1cffacd0 nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file
- f7cb90ddc021 nfsd: drop the stateid, not the stateowner, on seqid_op replay retry
- b449b134e776 nfsd: don't free session slots that are still in use
- 19413ccc4507 nfsd: defer vfree of compound ops to fix rpc_status UAF
- fe574c8069db nfsd: defer setting NFSD4_CALLBACK_RUNNING in deleg_reaper
- 281cd65d9264 nfsd: dedup nfs4_client_to_reclaim inserts
- df5922fe09a8 nfsd: convert nfsd_net boolean flags to unsigned long flags word
- c1a4f7b1848f nfsd: clear opcnt on compound arg release to prevent OOB read
- cb2d0c4d1b3d nfsd: clear CALLBACK_RUNNING on failed delegation recall queue
- 80cebb0e8a8d nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()
- d801906165cb nfsd: check client ownership when cancelling a copy-notify stateid
- ea14d71d6ecb nfsd: cap decoded POSIX ACL count to bound sort cost
- bf4d338dc862 nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref
- 9b5f6475006c nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry
- b4c121e18628 nfsd: add filehandle match check to nfsd4_delegreturn()
- c4a409b86a92 nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()
- dcb69ad0dafb nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage
- 45ec115cbfec nfsd: validate symlink target length in NFSv4 CREATE
- 22d0e4752ca8 nfsd: validate sockaddr length per family in listener_set
- 5eb489831a9f nfsd: validate nseconds in TIME_DELEG decode paths
- 719a10e3f5f8 nfsd: size fh_verify server sockaddr slot by xpt_locallen
- a6d89032e5c6 nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations
- a1cbafe756cd nfsd: sample writeback error cursor before async COPY loop
- b63e4997c776 nfsd: return NFS4ERR_NOTSUPP for unsupported netloc4 types
- b08c30f08d57 nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths
- bf0cd31a9abc nfsd: Reset write verifier when async COPY writeback fails
- 2bc4343308d8 nfsd: release path refs on follow_down() error
- 13bdd486c3aa nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown
- 3c461a182008 lockd, nfsd: RCU-protect nlmsvc_ops dispatch
- 078ccf7321f0 pNFS: Fix EBUSY check in pnfs_layout_need_return
- 32ac1b0b7f1c NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path
- 766170b4fd2d nfsd: guard nfsd_serv deref in nfsd_file_net_dispose
- a275de3bac56 NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check
- 7377fa964b8a NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock
- df2bd155dc40 NFSD: fix up error returned by write_threads()
- 4876f345e42a NFSD: Fix off-by-one in DRC bucket pruning limit
- 6c14602c01a2 NFSD: Encode only the status in NFS-ACL v2 GETACL error replies
- 440862544790 NFSD: check truncate permission under inode lock
- 0fd2b9687dae NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails
- 9f59b05423ed NFS/localio: fix ref leak on nfs_uuid_add_file failure
- 9b8af4d3f623 zsmalloc: account for handle size in class lookup
- e23fac4ab2a5 zram: validate deflate params
- dea8f13c3dfa zram: set default primary compressor in zram_destroy_comps()
- 07a82a66f8c1 zram: fix out-of-bounds access in writeback_store()
- 5e458fa714a5 zram: fix out-of-bounds access in read_block_state()
- 83e1aa9f5f90 ubifs: fix out-of-bounds read in signature length check
- c1a62f9dcf53 phy: rockchip-samsung-dcphy: fix out-of-range max_register
- 7a99e9c70119 PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io()
- acd1b4904336 of: fix out-of-bounds read in of_alias_scan() stem parser
- 28362e8ce513 nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation
- b95315ffc66b media: vicodec: fix out-of-bounds write in FWHT encoder
- a85ce3b17561 media: cec: stm32: prevent out-of-bounds write on RX overflow
- 1b0dc3cbb863 lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
- 78b95c571d02 KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID
- 769f5a233efc i3c: renesas: Fix out-of-bounds access for newdevs mask
- bc3d72c44bff HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature
- 4dc1051939e4 fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write
- 8e3d9dbb25d3 cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read
- eac233e63f9d usb: gadget: f_fs: Prevent deadlock during ep0 read loop
- 38f822ddce93 usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()
- d511e015d067 usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init()
- d90b0f90e30c usb: gadget: f_tcm: fix deadlock in usbg_make_tpg()
- 9ea5dfb2bfef usb: gadget: midi2: remove default configfs groups on teardown
- 0245adc0ad35 usb: gadget: snps_udc_plat: clean up PHY on probe deferral
- 79a92896e2bb usb: gadget: u_audio: Fix use-after-free on sound card disconnect
- 584ec5152f87 usb: typec: ucsi: use UCSI_TIMEOUT_MS for sync command completion
- 0a25484fe22f usb: typec: thunderbolt: Disable work before freeing tbt on remove
- db0894b59bb9 usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive()
- 5c7678e38a09 usb: typec: hd3ss3220: fix VBUS regulator error message
- b729106ec974 USB: phy: fsl-usb: fix missing static keywords
- 557ef547d49f usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed
- 93e08b13a7a3 usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition
- cdc1085ad40c usb: dwc2: gadget: Exit partial power down state when changing USB pull-up
- fdc3fa9a38e1 staging: greybus: hid: fix SET_REPORT return value
- 7429dce56a73 serial: imx: serialize imx_uart_ports[] lifetime
- ce792b94e038 Revert "media: v4l2-dev: fix error handling in __video_register_device()"
- 211c68d817a3 rapidio: mport_cdev: fix use-after-free in dma_req_free()
- 71c8c1b06e6d powerpc/powermac: fix OF node refcount
- 2aa0fb9c96f8 misc: nsm: bound the device-reported response length
- 9cb6b223ef02 device property: fix infinite loop in fwnode_for_each_child_node()
- e7f6a6b5741d debugfs: Fix lockdown check for mmap_prepare
- 7e9451bf0bdb cdx: Fix double free when sysfs file creation fails
- 83d1ae0406d8 tracing: Fix use-after-free with same-name named triggers
- 7a49d19ff9ba tracing: Fix use-after-free in trace_pipe read on sub-buffer order change
- df02489aa3aa tracing: Fix retry exhaustion in simple ring buffer reader swap
- 57e8f60d3cdd tracing: Fix logged instance name on creation failure
- c40e0b4fa365 tracing: Fix crash passing ERR_PTR to kthread_stop()
- b799f67119af tracing/user_events: Clear copied tracing state before fork duplication
- 52848a7ef68f hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start()
- 6ac9f3783096 x86/xen: fix init of balloon stats again
- 148257843037 x86/tdx: Fix zero-extension for 32-bit port I/O
- bb45f705c444 x86/tdx: Fix off-by-one in port I/O handling
- 786508f8339c x86/insn-eval: Move assign_register() out of KVM as insn_assign_reg()
- 9eb3bfc11d6d x86/locking: Use sfence for wmb() if SSE is available
- d20f260388b3 tools/compiler: match glibc 2.42 definition of attribute_const
- e883a6bd96a4 mm: vmscan: fix node reclaim ignoring swappiness parameter
- 2dcdb27f6e42 mm: page_alloc: fix non-movable reclaim storm in defrag_mode
- d3f688e98da0 mm: page_alloc: move capture_control to the page allocator
- bf483ca703f1 mm: page_alloc: __GFP_FS lockdep annotation for direct compaction
- 89e8a4f0455a mm: mempolicy: fix automatic numa balancing for shmem
- 5dba2ce548db mm: memcontrol: update state_local when flushing NMI stats
- aab391074de9 mm: memcg: stop reclaim when a limit update is superseded
- a8058dfd0a51 mm: memcg-v1: fix memsw and TCP failcnt accounting
- 8823354b644c mm: memcg-v1: fix wrong linux-mm list address in deprecation warnings
- 3dcc2fdc4017 mm: compaction: support non-movable compaction for pageblock requests
- 684e175ffce0 mm/zswap: fix global shrinker when memory cgroup is disabled
- cf3ba0911a1c mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()
- cdfa3e2a1e91 mm/vmalloc: make vm_struct.nr_pages an unsigned long
- e734cdda6b85 mm/slub: prevent pfmemalloc objects from entering the barn
- f77cbe1f17a2 mm/slub: fix missing debugfs entries for caches created before sysfs init
- 240885926f3f mm/rmap: use huge_ptep_get() in try_to_migrate_one()
- 4b9cd315061a mm/rmap: use huge_ptep_get() in try_to_unmap_one()
- c05cdc2ab365 mm/pagewalk: fix stale walk->action escaping walk_pmd_range()
- 13e9a00e6baf mm/page_vma_mapped: use huge_ptep_get() for hugetlb
- 46761406e143 mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg()
- 84339578c2d6 mm/mm_init: deferred_grow_zone(): fix out-of-range first_deferred_pfn
- 8ffedc6573a6 mm/migrate_device: clear stale mapping after freeing swapcache
- cafccd266590 mm/migrate: use huge_ptep_get() in remove_migration_pte()
- 66734981b4d3 mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()
- 15d3a2a71c8b mm/mglru: fix and remove redundant unevictable folio handling
- 3d927093b2ad mm/mempolicy: skip non-present PMDs when queueing folios
- 5c0d7b658cda mm/madvise: skip device-private PMDs in cold and pageout walks
- 1838c704bcb4 mm/kmemleak: avoid soft lockup when scanning task stacks
- c97a016dd4b5 mm/hugetlb_vmemmap: fix __hugetlb_vmemmap_optimize_folios()
- 29968bc7aefb mm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier
- 2ddf429e25cf mm/hugetlb: fix boot panic with CONFIG_DEBUG_VM and HVO bootmem pages
- 6cd209dbb55f mm/huge_memory: use folio's memcg inside __folio_split()
- 5e3026bf7364 mm/huge_memory: skip device-private PMDs in madvise_free_huge_pmd
- ad41ca3534e6 mm/gup: fix always draining LRU caches in collect_longterm_unpinnable_folios()
- 183fe65b0979 mm, swap: ratelimit bad swap entry reports
- a6df73156f2d mm, swap: don't free a hibernation slot that is in the swap cache
- 5f8132f2c9a0 include/linux/list.h: mark list_add and __list_add as __always_inline
- 36bdd0b45ec3 apparmor: fix out-of-bounds write when null terminating a label vec
- 580f777d6d9f apparmor: fix cred UAF caused by begin_current_label_crit_section()
- 2f7541afbc57 KEYS: trusted: Fix TPM teardown ordering
- 553142f4c44c kbuild: rust: keep Rust objects out of Clang LTO with inline helpers
- fb760bdf799e kbuild: rust: preserve unreachable traps with inline helpers
- 793e49f4ff12 rust: cfi: disable function merging if CFI is enabled
- 9d9b98b39609 rust: num: restrict bool conversion to unsigned Bounded
- 66fff437a15f objtool/rust: add one more
noreturnRust function - 744794d8920e rust: kernel: list: fix incorrect pop_back example comment
- a7ef535bfdc1 rust: kbuild: disambiguate
zerocopy_deriveforrusttest - cdbbcd7c64c9 rust: devres: ensure revocation is complete before device finishes unbinding
- c7e3d57c705a rust: devres: fix race between concurrent revokers
- a6756230ab95 rust: dma: return zero for Coherent reads past EOF
- f72804337142 rust: rust_is_available: warn for
bindgen< 0.72.1 && libclang >= 22 - 0523fab5f6cf rust: bug: prevent dead_code warning from warn_on!'s flags constant
- f391fef4122a rust: bug: fix warn_on macro build error on UML
- f49982cc4b9b rust: bug: skip arch-specific asm in
testlibbuilds - d6d980e5208d rust: kbuild: disambiguate
zerocopyforrusttest - ffef68ecc191 objtool/rust: add one more
noreturnRust function for Rust 1.99.0 - 00ef529a5402 timers/itimer: Zero-init old itimerval before copy to userspace
- c0eab781e182 rust: fmt: fix {:p} printing stack addresses
- 2fd19075a07f powerpc/pseries/iommu: switch to Default DMA window during kdump
- e89318aa8629 pidfd: hold exec_update_lock around namespace ioctl
- b1aa8ab78a8e ovl: fix double end_creating() on the casefold-mismatch path
- a35cc2135573 fs: fix user path of nested backing files
- f0efafcdf6ee clocksource/drivers/timer-sun4i: Advertise a real minimum delta
- cdcd86112324 clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path
- 71f5f2f374df alpha: don't leak hardware-fabricated FP exception bits to user space
- 22429a4d2451 rust: time: fix as_micros_ceil() rounding near i64::MAX
- 65651f1001aa iomap: don't free integrity payload that doesn't exist
- 0cc4969fc915 alpha: fix ieee_swcr_to_fpcr setting FPCR_DNOD unconditionally
- f8ef75a263d4 drm/amd/display: Prune per-tile Timing from Apple Studio Display Primary Tile
- 8eefff582dcc drm/amd/display: hide Apple Studio Display secondary tile
- 0c7c517827a4 ring-buffer: Fix subbuf resize race with ring buffer readers
- 074c715e0b49 btrfs: write-protect folios during data writeback
- e2c8375e0c72 ASoC: tegra: Sort MBDRC register defaults
- 9b1a9434f487 ASoC: tegra: Sort ADMAIF register defaults
- 2b005289afbb ASoC: tegra: Fix the MIXER enable default value
- 777a6a9cf729 ASoC: tegra: Fix the I2S enable default value
- 8f98fbb7fd4a ASoC: tegra210_mixer: sort the register default table
- 0ade1c624b23 ASoC: tegra210_i2s: sort the Tegra264 register default table
- 3e1b654f5479 ASoC: tegra210_i2s: sort the register default table
- f733276ae737 drm/amd/display: Skip Update HDCP Config In Transition State