XanMod Kernel

Operating SystemsGPL-2.0+

Linux kernel built for desktop and gaming workloads, with a low-latency scheduler and current hardware support.

Latest 7.2.4-xanmod1 · by XanModWebsiteRSS

Branches

7
7.2.4-xanmod1
6
6.18.50-xanmod1

Release activity

Release activity — 30 releases across 13 days since Jun 27, 2026. Each cell is one day; darker means more releases that day. Nothing is recorded before Jun 27, 2026. Older weeks are hidden at this screen width.
JunJulAugSep
SundayNo releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026No releases on Aug 9, 2026No releases on Aug 16, 2026No releases on Aug 23, 2026No releases on Aug 30, 2026No releases on Sep 6, 2026
MondayNo releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 20262 releases on Aug 3, 20263 releases on Aug 10, 2026No releases on Aug 17, 2026No releases on Aug 24, 2026No releases on Aug 31, 20262 releases on Sep 7, 2026
TuesdayNo releases on Jun 30, 2026No releases on Jul 7, 2026No releases on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026No releases on Aug 11, 2026No releases on Aug 18, 20262 releases on Aug 25, 2026No releases on Sep 1, 2026No releases on Sep 8, 2026
WednesdayNo releases on Jul 1, 2026No releases on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 2026No releases on Aug 5, 2026No releases on Aug 12, 20262 releases on Aug 19, 2026No releases on Aug 26, 20264 releases on Sep 2, 2026No releases on Sep 9, 2026
ThursdayNo releases on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 20262 releases on Jul 30, 2026No releases on Aug 6, 2026No releases on Aug 13, 2026No releases on Aug 20, 20264 releases on Aug 27, 2026No releases on Sep 3, 2026No releases on Sep 10, 2026
FridayNo releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026No releases on Aug 14, 20261 release on Aug 21, 2026No releases on Aug 28, 2026No releases on Sep 4, 2026
Saturday1 release on Jun 27, 20263 releases on Jul 4, 2026No releases on Jul 11, 20262 releases on Jul 18, 20262 releases on Jul 25, 2026No releases on Aug 1, 2026No releases on Aug 8, 2026No releases on Aug 15, 2026No releases on Aug 22, 2026No releases on Aug 29, 2026No releases on Sep 5, 2026

30 releases since Jun 27, 2026, busiest day 4

Changelog

What changed from 6 to 7
Filter releases by branch
30 of 30 releases

7.2.4-xanmod1

Latest
Fixed 19
  • platform/chrome: sensorhub: Fix dropped timestamp events and log spam
  • ACPI: scan: Do not combine resources that overlap completely
  • selftests/mm: fix on-fault-limit false failure under sudo-rs
  • udf: Fix i_lenExtents truncation on 32-bit kernels
  • timer: Keep debugobjects state consistent in migrate_timer_list()
  • timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex()

From XanMod Kernel

  • 48995b0a2757 Linux 7.2.4-xanmod1
  • 2e766e62ad92 Merge tag 'v7.2.4' into 7.2
  • 5015d0d945b3 Linux 7.2.4
  • 702da34510f8 platform/chrome: sensorhub: Fix dropped timestamp events and log spam
  • 7a315e6e2c36 ACPI: scan: Do not combine resources that overlap completely
  • 33c7d01fb172 selftests/mm: fix on-fault-limit false failure under sudo-rs
  • fafa98778383 udf: Fix i_lenExtents truncation on 32-bit kernels
  • b63a6589984c timer: Keep debugobjects state consistent in migrate_timer_list()
  • bc59dac50cb4 timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex()
  • 3fb244bc24ae taskstats: fix cpumask parsing cutting off the last character
  • b791401bf389 smack: fix cred UAF in smack_file_send_sigiotask()
  • b655c2040ce8 signal: avoid shared siginfo namespace rewrites
  • 1abe5e32a6c8 sticon/parisc: Detect default STI graphics card for console output
  • a09bc4eaa67e sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]
  • aee2296d09f6 tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout
  • 23cb8d5fb33d zloop: truncate finished zones to zone capacity
  • f40115b2575a xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc()
  • 6df05f630c84 w1: ds28e17: reject an oversize length on an I2C block read
  • da5e9f08714c vsock/virtio: flush works in dependency order
  • 7074ec376982 wifi: mt76: mt7996: validate default EEPROM firmware size
  • b754d3a6d44c wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames
  • 6be59da2063d wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy
  • 9e20da749ad2 wifi: mt76: mt7925: cancel mlo_pm_work on stop
  • 5f48b0d752a7 wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy
  • 44be85af3e17 wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex
  • c1f214dd1351 wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot
  • b1596e212ab1 wifi: rtw88: pci: fix resource leak on failed NAPI setup
  • 51d8b3557472 wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()
  • 7159e1e12468 wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars()
  • 42785f7e8d31 wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids
  • 46e3a14d901b wifi: rtl818x: initialize eeprom_93cx6 struct to zero
  • d29a165588b6 wifi: mwifiex: Detach sync cmd buffer on interrupted wait
  • 59ebe7b0ff64 mm/kmemleak: report RCU-tasks quiescent states during the scan
  • 3ee49d4dbd08 mm/kmemleak: stop the task stack scan early when interrupted
  • b64d49ca15e3 crypto: atmel-ecc - avoid stale fallback key after set_secret failure
  • 50c52da15629 crypto: atmel-ecc - clean up and improve ECDH comments
  • fcd86180ef78 crypto: iaa - unmap dst before software fallback on decompress
  • a47a416ff68d fuse: copy request headers via a stack buffer for io-uring
  • 303b6eeedf29 fuse: decouple fuse_ring creation from ent registration
  • 972ab8b9c08f wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop
  • ad2a9fdca4a7 wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()
  • ba04715ee672 wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()
  • 4437b09f82f6 i3c: renesas: Perform Dynamic Address Assignment on resume
  • ba3c86a90280 i3c: renesas: Restore STDBR and EXTBR registers on resume
  • 9206527c91b9 i3c: renesas: Reset the controller on resume
  • de6aa7bd623f i3c: renesas: Reconfigure the DATBAS register on re-attach
  • 3d62955cb4b7 i3c: renesas: Follow the reset deassert order used in probe
  • 7ea5b0ca2f39 i3c: renesas: Clean DATBAS register on detach
  • ec631aff9326 i3c: renesas: Check that the transfer is valid before accessing it
  • aac3c5aababc i3c: master: svc: bound IBI payload to the requested max_payload_len
  • 4837be0f9ac2 i3c: master: Fix info leak and UAF in device unregister path
  • de8c32b0a246 i3c: master: adi: initialize the lock before enabling interrupts
  • 251db58324ea i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode()
  • f39a3e9cc594 dm-pcache: fix use-after-free and invalid seg operations in kset_replay()
  • 8a2a2f78c6ba dm-pcache: fix implicit u8 truncation of gc_percent in message handler
  • 692037ae1a7c dm-pcache: only hand out initialized cache segments
  • 5311dfc5cd70 dm-pcache: detect a cycle in the last-kset chain during replay
  • 1ab55354368d dm-pcache: clamp the tail kset read to the segment data region
  • 8bf7a06ca3c1 dm-pcache: bound the persisted tail-position offset
  • e889c0ee8116 dm-pcache: validate on-media seg_num against the cache device size
  • 5ac38f4b4862 dm-pcache: validate kset key_num and intra-segment bounds
  • 3e19172089ec dm-pcache: validate geometry fields from on-disk cache_info
  • 8c52308f3805 dm-switch: use WRITE_ONCE() in switch_region_table_write()
  • 0c8f7870ed3e dm-stats: fix a crash if allocation of per-cpu data fails
  • 1f2f7d885bf8 arch_numa: avoid false positive fortify warning in setup_node_to_cpumask_map()
  • ceab9302388b rust: num: reject Bounded::shr overshifts at build time
  • 641dacada331 ALSA: hda/realtek: Fix Lenovo Yoga Slim 7 14AKP10 quirk ordering
  • 2bfc88e83398 ALSA: hda/realtek: Enable micmute LED on HP EliteBook 6 G1a p/n: AD3Q9ET#UUG
  • 013daf719370 ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r
  • 17fc26d7bbe8 ALSA: hda/realtek: Add quirk for TongFang XxAF5xxx
  • f48c5f3b03af ALSA: virmidi: Check card index validity at probe
  • 6d6fdb24fe2e ALSA: serial-u16550: Check card index validity at probe
  • e1ce8ad1009b ALSA: portman2x4: Check card index validity at probe
  • 7cf280fbef5d ALSA: pcxhr: initialize mutexes before requesting threaded IRQ
  • cf3af453a48c ALSA: mts64: Check card index validity at probe
  • 8adda66edf79 ALSA: mpu401: Check card index validity at probe
  • f78dc2ff60be ALSA: hda/ext: preserve PPLCCTL bits when clearing reset
  • 29ab2df278ab ALSA: FCP: do not copy out an uninitialised init response
  • b06ebc7fe25a ALSA: bcd2000: clear the URB pointers on disconnect
  • efbc2e9e43a1 ALSA: aloop: Check card index validity at probe
  • 34816e2cfeab ALSA: 6fire: bound the MIDI event length from the device
  • c8be3a076a59 mfd: sm501: Fix potential memory leaks during remove
  • 8391ee06d088 mfd: qnap-mcu: keep the reply buffer alive past a command timeout
  • 3266537d0333 mfd: cgbc: Fix teardown ordering in cgbc_remove()
  • 8f9332070243 hwrng: stm32 - Fix runtime PM cleanup on registration failure
  • c73fb911e02b seg6: reset IP6CB after IPv6 decapsulation
  • 0370da114a9b net: skbuff: don't touch shared zerocopy state in skb_tx_error()
  • 497f3abfaa97 net: fix spurious TX timeout after dev_activate()
  • 9144f2c53a04 net: cap advertised IP tunnel headroom
  • b74d313567df net/smc: unregister the connection before draining the rx tasklet
  • 2cb7a8d64b7e net/smc: stop killed, freed and out_of_sync sharing a byte
  • adef84cc85d4 net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link()
  • 0926f59ca0f9 net/smc: fix use-after-free in smc_rx_pipe_buf_release()
  • d9a879ac2595 net/smc: fix socket refcount leak in smc_switch_conns()
  • f517cf020338 net/smc: do not dereference an unset send buffer on the SMC-D teardown path
  • 0d6f80be8ac5 net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry
  • 5e5d9e6df677 net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages
  • 7498cadd989d net/mlx5e: do not HW-GRO coalesce small frames
  • 4cf9400f29e2 net: ntb_netdev: Count packets dropped on RX refill failure
  • 759193a45dc6 net: ntb_netdev: Avoid double-accounting netif_rx() drops
  • 1a522d4480c9 net: ntb_netdev: Fix TX busy and drop handling
  • 75a604e9f1cf NTB: ntb_transport: Reject oversized TX buffers
  • 89177732fe16 NTB: ntb_transport: Fail TX enqueue when the QP link is down
  • a08423b7fe91 NTB: ntb_transport: Recycle TX entries before client callbacks
  • d6c0af293129 net: thunderbolt: Mark the connection down when bringing it up fails
  • 1c361f6cf39b net: thunderbolt: Release the Rx HopID that was handed out on mismatch
  • 66b50c31419e net: ravb: serialize PTP clock teardown
  • 0aaa53936419 net: ravb: avoid dereferencing an invalid PTP clock
  • fb4d77553841 net: phylink: correctly validate returned PCS in phylink_inband_caps
  • 9f316e64923a net: openvswitch: fix nf_connlabels leak in ovs_ct_init
  • 7f072b84afd0 net: openvswitch: fix flow mask use-after-free on flow deletion
  • cc561f8af255 net: mctp: hold a reference to the route device in mctp_route_lookup()
  • 50c4038f1670 net: l2tp: do not propagate multicast notification errors
  • 30cef9c1229a net: ipa: fix stalled modem TX queue after runtime resume
  • cc29f15244e0 net: ibm: emac: mal: fix NAPI locking
  • 48d1c9665db6 net: bnxt: ring the doorbell when SW USO exits early
  • 1610a8c2b93e net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO
  • 0ada54ea63e4 net: tun: bound receive headroom
  • 4f67a23f3f8d net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition
  • d6f25e5bd777 slip: fix use-after-free in sl_sync()
  • 68d7cc551223 xdp: fix zero-copy frame layout
  • a7f0130a0917 net/iucv: filter frames in afiucv_hs_rcv() by ingress device
  • a496c51dd325 ipmi:msghandler: Cancel work cleanly on an error
  • 8ada17dd4c4f ipmi: si: Fix NULL pointer dereference after failed registration
  • b115b7d06f26 ipmi: Remove all sysfs files on registration failure
  • a84c6e3d188f ipmi: ipmb: validate write message length
  • d715d19cfcfe interconnect: Fix use after free in icc_get() and of_icc_get_by_index()
  • 2b8ad4981ece io_uring/query: cap user size passed to copy_struct_to_user
  • ef2bd2da1b77 io_uring/waitid: avoid siginfo copy during ring teardown
  • 7bc98e2de8c5 io_uring/waitid: honor task_work cancellation
  • 6dca6c4269b0 platform/x86: hp-bioscfg: warn on element type mismatch instead of failing
  • 400cbc3ccc88 platform/x86: hp-bioscfg: pass validated element count to package parsers
  • 4ef68ed53f09 platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed
  • ddf98cf33529 platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()
  • 550d80f69fe5 platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password
  • b699e5c1f63a platform/x86: hp-bioscfg: fix heap OOB read on empty password write
  • 67b60703d7d8 platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()
  • c32ac3443e5a platform/x86: hp-bioscfg: bound ordered-list parsing by the package count
  • ea069840cb75 platform/x86: hp-bioscfg: advance elem past consumed array elements
  • ab3526ce387e platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS
  • dd38ae725409 platform/x86/amd/pmc: Fix msg_port restoration in amd_stb_debugfs_open_v2()
  • 30e5f4d0cd0b platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails
  • 775d4cde1f97 platform/x86/amd/pmc: Propagate SMU errors and validate S2D address
  • f1189a7665b0 platform/x86/amd/pmc: Restore msg_port on amd_stb_s2d_init() error paths
  • 4d9bf63ed74f platform/chrome: sensorhub: Bound the EC-reported sensor number
  • 91d761111307 platform/x86: think-lmi: Fix current password length check
  • abbcc0354108 platform/x86: think-lmi: Free system certificate signatures
  • 57d8750fd5ed platform/x86: think-lmi: Fix certificate thumbprint sysfs output
  • a93df956ee4d platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[]
  • 546a229829c6 platform/x86: lenovo/ymc: Only match lower byte in WMI lid switch query response
  • 5c4c6514497d platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path
  • 582b82e573a0 platform/x86: int1092: Fix potential memory leak in sar_probe()
  • 9ed7240d6366 platform/x86: hp-wmi: Add support for OMEN MAX 16-ak0xxx (8DD6)
  • 282cdcb7b03d platform/x86: ISST: Return error during profile addition
  • 68148d064cbe platform/x86: ISST: Validate parameter for frequency and priority
  • ecfe22c2b72e platform/x86: ISST: Validate parameter for core power state
  • a352b135256b platform/x86: ISST: Validate max level for set feature
  • 82d4afadb02f platform/x86: ISST: Validate logical CPU id and clos id
  • fe6e73ef684d platform/x86: ISST: Use PP level enable mask
  • 1b324191da70 platform/x86: ISST: Just allow 2 bits for SST feature enable
  • ef7975af1512 platform/x86: ISST: Add a NULL check for sst_inst[]
  • c2b8a6249119 mmc: via-sdmmc: stop card-detect handling on probe failure
  • eaca730c6f5e mmc: via-sdmmc: cancel card-detect work on remove
  • 207b4dc6eb10 platform/x86: ISST: Validate socket ID in clos_assoc ioctl
  • d19385624bdf platform/x86: ISST: Validate level in perf mask ioctls
  • eb73b9d51490 platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer
  • e27e90bde68b iommufd: Fix UAF in selftest IOPF reporting
  • 07b4fe1367f0 iommufd: Release current IOAS on xa_store() failure
  • 50a66a63d1c8 iommufd: Avoid locking internal accesses during unmap
  • efd9a33f2022 iommupt: Return zero for invalid iova_to_phys() ranges
  • 87bc611c6c98 iommu/vt-d: Force requesting ACS when tboot is enabled
  • f0a2c50254cf iommu/vt-d: Fix no_iommu to disable platform opt-in
  • eaf44262af24 iommu: Fix dev_iommu memory leak when device_add fails in iommu_mock_device_add
  • 78fd5a2d65f3 iommu/arm-smmu-v3: Manage teardown with devm
  • f9b7375db3b3 iommu/arm-smmu-v3: Add HAFT support for SVA
  • 445204550f89 iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field
  • 37a96a30617a iommu/sva: Set handle->dev before the SVA handle is visible
  • 7f7074a886c4 iommu/msm: Unwind probe state on registration failure
  • d1470e16c197 iommu/amd: Put PCI device after handling PPR faults
  • 4a5b7ee11cda PCI/proc: Warn on writes to kernel-exclusive config space regions
  • 6351e9407632 PCI/proc: Use file_ns_capable() when checking config space read access
  • 84536685a7f4 PCI/proc: Avoid spurious runtime PM wakeup on config space accesses
  • a69a029f981d PCI/MSI: Enable memory decoding before restoring MSI-X messages
  • 21fd595ad137 PCI/ASPM: Avoid L0s for Realtek RTS525A
  • 329e42c0ff09 PCI/AER: Fix mapping of errors to agent & layer
  • 271ce2317009 PCI/AER: Emit TLP Log only for unmasked errors
  • 3dc196d3bbea PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses
  • f8ed6f530141 PCI/sysfs: Fix read byte order in pci_read_legacy_io()
  • 6453246da7df PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608]
  • e54e8d2a0f9c PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts()
  • e3589ca5f2e6 PCI: plda: Fix use-after-free of event IRQs during teardown
  • d9ad2f0fe787 PCI: starfive: Fix resource leaks on error paths in host_init()
  • 99e4d0286af3 PCI: meson: Fix GPIO state while requesting PERST#
  • caf71f66d552 PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk
  • 1f0269720d45 PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip
  • 15ec03452c18 s390/dasd: Propagate partial completion length across ERP recovery
  • 449f3bada7a9 s390/dasd: Guard sysfs discipline callbacks against unallocated private data
  • b0d94dd6e82d s390/dasd: Do not complete a failed ESE read as successful
  • 91770b08a120 s390/percpu: Fix MVIY_PERCPU() with older binutils
  • 71d46de9153e s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
  • 36e6ce0f402f power: supply: max17040: synchronize work cancellation on suspend
  • ad8081ede936 power: supply: max17040: drop incorrect I2C functionality check
  • c7aa4c3708cc power: supply: max17040: propagate register read errors
  • 35242c93d35f power: supply: ucs1002: fix use-after-free on remove
  • b955da82db41 power: supply: twl4030_charger: cancel workers via devm
  • 7323e562f696 power: supply: rt9455: quiesce delayed work before teardown
  • 6cc6c28c9ab6 power: supply: qcom_battmgr: terminate the strings from firmware
  • 49fbcd3da295 power: supply: qcom_battmgr: fix use-after-free
  • b64789e21699 power: supply: pf1550: enable charging when battery profile exists
  • b4eb6a056b44 power: supply: lp8788-charger: fix use-after-free on remove
  • 6ab3128292df power: supply: lp8727: fix use-after-free in lp8727_release_irq()
  • 304a29ac55ba power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS
  • 3d1e01443b22 power: supply: cros_usbpd-charger: bound the EC-reported port count
  • 6d532582ff3c power: supply: charger-manager: register regulators before exposing sysfs
  • 58f1025eca92 power: supply: bq25890: Fix power_supply reference leak
  • c8addb842ae8 power: supply: bq256xx: drain usb_work before freeing the charger
  • 47ccbad210f4 power: supply: bq24257: fix use-after-free on remove
  • 8320cbd81bc2 sctp: fix stream->outcnt underflow on duplicate RECONF responses
  • db8dc28b73b4 sctp: distinguish sequence zero from wildcard in reconf lookup
  • 0ee697defc05 sctp: fix NULL deref on untransmitted RECONF completion
  • 3537961df216 sctp: drop a chunk if its transport was removed
  • a713e1b3a265 sctp: stop processing a packet once its association is deleted
  • 832a685efeb5 nvme-tcp: reject a read that transferred too few bytes
  • 3a0b05145053 nvme-tcp: fix host memory disclosure on R2T for a read command
  • 641ad3a30ba5 nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
  • f691394c1cc6 nvme-pci: disable controller on admin queue IRQ setup failure
  • f5827817b4fc nvme: zero the discard fallback page
  • 0b46ec7f28a0 nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in error path
  • 21bcb609e0ab lockd: fix swapped arguments in nlmsvc_match_ip()
  • 51af080ca4e5 lockd: fix NULL dereference on lockowner allocation failure
  • da6e60e5b38f lockd: fix NLMv4 GRANTED_MSG handling
  • e999a8813365 lockd: pin next file across nlm_inspect_file lock-drop
  • 5dc0b2a9af95 ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()
  • 6d512e1624b1 i2c: mxs: fix DMA channel leak on probe error
  • daa6960b0df4 hwmon: (max6621) fix temperature clamp range
  • 1daf80928fb5 hwmon: (max6621) fix negative temperature offset and crit readings
  • 5fc3f547dd96 dma-contiguous: fix truncation of numa_cma / cma_pernuma sizes >= 2G
  • 95a109f5af67 ASoC: codecs: aw88261: only check PLL and clock state at power-up
  • 7992a923348e ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC
  • e20902d383a6 arm64: proton-pack: Restore the nospectre_bhb command-line option
  • 2d3137a332aa arm64: compat: Fix decrementing LDM/STM alignment emulation
  • 97ab7c2ccffc ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion
  • 5d85eef222cf openvswitch: only skb_tx_error() a packet we are about to drop
  • 6a6d36fadb85 openvswitch: Fix CT limit teardown use-after-free
  • b53435c079c7 openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
  • b53e2b271eeb ocfs2: fix readdir position truncation on 32-bit kernels
  • 7f5e32665598 ocfs2: fix cached cluster count after suballocator reclaim
  • 67ba14821213 ocfs2: cluster: fix o2hb_dependent_users leak on pin failure
  • 148e5019e1f9 ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from drop_item
  • 470212a5eefa ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()
  • b8a5c0c32df2 ocfs2: validate directory-index entry counts when reading metadata
  • 04ead708e13d ocfs2: validate rl_used against rl_count in refcount block validator
  • a8facb1670b4 ocfs2: validate lengths in dlm_mig_lockres_handler
  • 2487bea20983 ocfs2: bound namelen in dlm_migrate_request_handler
  • 09e93a60e18e ocfs2: always run deallocs on copy-on-write completion
  • 1774c5b3713a orangefs: skip leading spaces before parsing client debug masks
  • 519f4146b8b8 orangefs: fix double-free of trailer_buf on readdir copy failure
  • 376796add2d7 PM: sleep: Unblock runtime PM when device prepare fails
  • a14a97048e48 ring-buffer: Stop remote reader update when page swap fails
  • d787d509bdf6 ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page
  • bf242baf58de ring-buffer: Hold cpu_buffer::lock when resizing a subbuf
  • 81063bbb16c4 ring-buffer: Free cpu_buffer::free_page with subbuf_order
  • 53106e9262a3 ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page()
  • dac639482116 regulator: qcom-refgen: correct the regulator type to CURRENT
  • 16583ed17a26 regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata
  • 8648e29e5c01 regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer
  • edae84e54617 RDMA/uverbs: Guard legacy bundles without method_elm
  • 9e71d0f4944b RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR
  • 0be1955040a2 RDMA/ucma: Lock the handler in ucma_write_cm_event()
  • 43a7d8ae9f64 RDMA/ucma: Lock the handler in ucma_set_ib_path()
  • 08b8630b5578 RDMA/ionic: Embed counter driver data in rdma_counter allocation
  • 94d393f8dd94 RDMA/ionic: Cap eq_count to the eth driver's interrupt vector budget
  • 320e5258a53a RDMA/cxgb4: Cancel reg_work before freeing device on remove
  • f5c8619ccbd7 qede: Fix NULL pointer dereference in TPA fragment processing
  • 0ce59c4148ec ptp: vmclock: prevent read-only mappings from becoming writable
  • 440bcb0948a1 remoteproc: scp: Fix device reference leak on failed lookup
  • 098bfc94904e riscv: unaligned: stop using kthread for check_vector_unaligned_access()
  • 6e7b8041068c riscv: acpi: Handle LPI architectural context loss flags
  • 82088f88c96b RISC-V: KVM: Fix PMU event info array size overflow
  • 4efc2b3f2c19 riscv: dts: spacemit: k1-orangepi-rv2: fix maximum CPU core voltage
  • c853c8524756 riscv: dts: spacemit: k1-orangepi-r2s: fix maximum CPU core voltage
  • 20a1c2869f12 riscv: dts: spacemit: k1-musepi-pro: fix maximum CPU core voltage
  • 1f6b98158afe riscv: dts: spacemit: k1-milkv-jupiter: fix maximum CPU core voltage
  • e86e01247ec2 riscv: dts: spacemit: k1-bananapi-f3: fix maximum CPU core voltage
  • 2efa7a531c1c arm64: dts: rockchip: Fix rk3588s-roc-pc audio description
  • 72c93c1f4f2c arm64: dts: rockchip: Fix rk3399-roc-pc-plus analog audio
  • 11918726dadf arm64: dts: rockchip: fix emmc reset polarity on px30-cobra
  • 53992f89da99 arm64: dts: rockchip: fix eMMC reset polarity on PX30 Ringneck
  • 8f7c9ed1af20 arm64: dts: rockchip: fix eMMC reset polarity on PP-1516
  • 91ee0d0c4b29 arm64: dts: qcom: x1-dell-thena: mark l12b and l15b always-on
  • 866b788b1e74 arm64: dts: qcom: sm6115-pro1x: Correct touchscreen GPIO flags
  • 7ee10b72558e arm64: dts: qcom: kodiak: avoid EFI overlap for ADSP remote heap
  • 0131497574eb Revert "arm64: dts: rockchip: Further describe the WiFi for the Pinephone Pro"
  • ba49fe53689d rpmsg: glink: smem: order FIFO read after availability check
  • d86f65aed014 scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock
  • 6fd1cce5018f scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables()
  • c736ea0fe7b4 sched_ext: Keep kick_sync waiting on the rq's own CPU
  • f974f54c3078 sched_ext: Fix scx_bpf_dsq_reenq___compat kfunc extern prototype
  • c480961a1e79 sched_ext: Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users
  • 1df5802fa783 sched_ext: Fix inverted ops.core_sched_before() invocation
  • d644a145d76c sched_ext: Fix exit_task leak on fork failure during enable
  • d863b1710d34 sched_ext: Fix scx_bpf_dsq_move_to_local___v2 compat detection
  • 28cc9c9ade88 sched_ext: Count rq lock releases in rq->scx.lock_drop_seq
  • cdafb68155be sched_ext: Fix rq->core_pick corruption under core scheduling
  • 6d1890d3c613 sched_ext: Fix this_rq() assumptions in dispatch kfuncs
  • 6f1d3bfe5443 sched_ext: Replace SCX_RQ_BAL_KEEP with a dispatch verdict return
  • 23eda24f325a sched/core: Make core-sched flips wait for in-flight selections
  • 88ed5a66467c sched/core: Handle pick_task() releasing the rq lock
  • 323c411fb631 media: staging/ipu7: fix async notifier UAF on probe error path
  • 95f54d10be87 staging: media: tegra-video: vi: fix probe failure on skipped last port
  • fc9937019cf7 staging: media: tegra-video: fix of_node_put() on VIP parse errors
  • c5e073f2fbfd wifi: mt76: mt7925: cancel pending mlo_pm_work
  • 8eb73016fb39 wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets
  • 1bd7947f1463 udf: reject VAT indexes equal to the entry count
  • 577097455d08 svcrdma: Validate Read chunk positions before reconstruction
  • ac1dd6002f75 svcrdma: Use svc_xprt_put to free listener on create failure
  • 45dbdb2637b7 svcrdma: Reject Write/Reply chunks with segcount 0
  • 465f511f59a0 svcrdma: Reject Read lists that exceed the page budget
  • 5120fe54e0e2 svcrdma: Reject oversized Read segments at decode time
  • 8ec60eb51fae svcrdma: Reject inline replies that overflow the pull-up buffer
  • 1f6a14c142fe svcrdma: Reject connection when transport allocation fails
  • 45a444a17240 svcrdma: Fix unmatched rn_unregister on failed accept
  • 6d33a7e6bf6c svcrdma: Fix pcl_for_each_segment for empty chunks
  • 4493c96bbd00 svcrdma: Fix offset arithmetic in read_chunk_range
  • 673e358ab7c1 svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails
  • cfca6eb3345b svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id
  • 7fbb6d2ab039 SUNRPC: wait for in-flight client TLS handshake callback
  • 7a946b2e7207 SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2
  • 880effc943ed SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field
  • 9d94f046b23d SUNRPC: reject duplicate CREDS_VALUE options
  • 3f019571928b sunrpc: init gssp_lock before publishing proc entry
  • d395c30d570c SUNRPC: harden gss_unwrap_resp_priv length checks
  • a7894e10572d SUNRPC: harden gss_krb5_unwrap_v2 against short tokens
  • 0bdb26b2534a SUNRPC: Guard svcauth_gss_release() dispatch on rq_auth_stat
  • cdf7a233cb94 sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir
  • f85a83774d7f SUNRPC: fix gssx_dec_option_array error path bugs
  • e0c5693d3f9a sunrpc: defer rq_argp and rq_resp free until after RCU grace period
  • 6debde9e3e6a SUNRPC: close backchannel before destroying callback service
  • b541a1504697 SUNRPC: Check svc pool percpu counter allocation
  • 3d60fdf95114 SUNRPC: always drain cache_cleaner before destroying a cache_detail
  • 48d04a32eb44 SUNRPC: Restore NUMA_NO_NODE for svc thread allocations in global mode
  • 8f766d2d0b4d sunrpc: route to a populated pool in svc_pool_for_cpu()
  • 2eed1e6a976a SUNRPC: svcauth_gss: enforce krb5 token minimum length
  • 0fa8a8acae57 SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
  • 85e9602650e9 SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow
  • 84646f5b945a phy: fsl-imx8mq-usb: fix typec switch leak on probe error path
  • 0d8e2404925a params: fix charp corruption on allocation failure
  • e60466011ac3 nouveau/gem: reserve the bo in the info ioctl around the vma lookup
  • 6e3d09fcd97e module/kallsyms: fix nextval for data symbol lookup
  • bf19d166337c mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction
  • 49d38c1b4390 mpls: reload header after pskb_may_pull()
  • e4496dda2c6d module: validate string table section types
  • df7d4d011d5a md: do overflow check for sb->bblog_shift in super_1_load()
  • 00449d752bee md/raid10: fix still_degraded being inverted in raid10_sync_request()
  • bc584959c3a5 mailbox: qcom-ipcc: fix duplicate channel allocation across holes
  • 69a734359639 libnvdimm/labels: Prevent integer overflow in __nd_label_validate()
  • 0c3204aacbe8 landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
  • f6b1b15848fd ipv6: use RCU iterator to dump route exceptions
  • eab3a917cdcb ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()
  • 565038b0092f ip6_gre: fix hardware header length for NBMA tunnels
  • 8fc56ca49fc0 ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit()
  • f1281d4b9908 ip: orphan prefetched skbs before multicast forwarding
  • fd01f1a3ed4a ipip: fix skb leak in collect_md mode when metadata_dst allocation fails
  • 595cac7f1b32 jbd2: check need_resched() when skipping busy checkpoint buffers
  • c2c0fb364685 jbd2: bound shrinker scans by examined checkpoint buffers
  • 42a6f03cf352 kho: fix size calculation in kho_preserved_memory_reserve()
  • 3119d58e4ef8 kasan: fix cache shrink race with CPU hotplug
  • 7dcf816c1592 Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request
  • cf7686449338 Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative
  • db1ff5dc173c Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative
  • 9907e72f0f66 Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection
  • 26f66d5b8a56 Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb
  • 43b64cb6ed3b Bluetooth: hci_conn: re-enable advertising only for peripheral role
  • fbf7961964a6 Bluetooth: RFCOMM: serialize security confirmation handling
  • 03288b7447c9 Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready
  • 1b2e9b2cf944 Bluetooth: hci_uart: Fix false success return in hci_uart_setup()
  • 981f7c23025b Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative
  • a79432a904df Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378
  • ba147f2f56a9 cxl/ras: Fix cxl_rch_get_aer_severity() wrong severity register
  • 7256c9bd929b cxl/pmem: Format the nvdimm serial number as unsigned decimal
  • 491d8c9ac98d cxl/mce: Make the MCE notifier per-region
  • d8957545fe96 cxl/features: bound fwctl command payload to the input buffer
  • 8fddd484992a cpufreq: schedutil: Fix rate limit overflow
  • 36c55d118d5e cpufreq: apple-soc: Fix OPP table cleanup
  • 92f37721a33a coresight: etm3x: Fix cntr_val_show() to match cntr_val_store() behavior
  • cb409b38b023 dm array: reject an array block whose value size is not the caller's
  • 9808ddffb4bc dm array: validate array block headers on read
  • f79b53ca3a68 dm raid1: reserve space for NUL-terminator in build_constructor_string()
  • 6876ca330e74 dm-era: fix shadowed superblock leak on take-snap failure
  • 15fc1ec72e1f dm-io: report non-retryable errors separatedly
  • 8dc48b68d7c3 dm-io: clone the source bio instead of copying its biovec
  • dff481e12b3f bpf: Harden bloom filter sizing and indexing on 32-bit kernels
  • a1159c892612 buffer: avoid tail commit walk for uptodate folios
  • 9a23747909fc bpf: Disable preemption in __bpf_get_stack
  • 6a19b18d4588 bpf, x86: Fix per-CPU address resolution into an extended register
  • e04b6f48dd44 bnxt_en: Write doorbell when linearizing skb fails
  • a142c024f07d bnx2x: fix double free in bnx2x_init_firmware() error path
  • bb56e97bd676 Bluetooth: eir: Fix OOB read in eir_get_service_data()
  • 9fe52fd63e5b Bluetooth: btusb: limit RTL8761B BROKEN_EXT_SCAN quirk to 0bda:a728
  • 186a0975283f Bluetooth: btusb: Add ASUS USB-BT600 for Realtek 8761CU
  • 6b2da140580b Bluetooth: btusb: Add ASUS USB-BT540 for Realtek 8761CU
  • c7c8e0454f31 block: set QUEUE_FLAG_DYING unconditionally in blk_mark_disk_dead()
  • d44a97a3b1c0 block: validate user space vectors during extraction
  • 0dc53c2dd593 backlight: aw99706: Honor the core blank state in update_status()
  • 32a5f01bbbaf backlight: aw99706: Fix DT property names to match binding
  • ff2fb3c1e60c auxdisplay: charlcd: cancel backlight work on registration failure
  • 4a4268a0b0a5 ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes
  • 1ff69db8f352 ARM: 9477/1: Disable broken eBPF JIT on the Risc PC
  • 22a0982db25c alpha: marvel: Fix lock ordering in init_io7_irqs()
  • 4722bedf7a93 alpha: marvel: Fix irq_set_status_flags to use correct IRQ number
  • a7800cf56bb3 alpha/PCI: Fix I/O port accessor argument order in pci_legacy_write()
  • 9a33db250f35 ACPI: TAD: Add locking around AML evaluations
  • 495daa190369 ACPI: scan: Avoid registering platform devices with resource overlaps
  • 15d2b7f38f95 ACPI: pfr_update: fix stack buffer overflow in query_capability()
  • 3c0c3e96fccf ACPI: CPPC: Skip desired_perf read in cppc_get_perf()
  • 712d9e196f82 ACPI: CPPC: Reject desired_perf reads on _CPC revision 4+
  • b48b613073c3 ACPI: APEI: GHES: fix ARM section length accounting after header
  • c9655ce86b75 ACPI: APEI: Fix ERST timeout unit conversion
  • 0e25382b05de acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks
  • 7d6fa298c234 accel/rocket: Fix error path handling in rocket_job_run()
  • 81731f1eda5e accel/rocket: initialize job domain before cleanup paths
  • dfff90a6eb22 accel/rocket: fix NULL dereference and integer overflow in rocket_job_push()
  • 0f001491e5a2 hugetlb: only adjust reservation during unmapping if mapcount is 0
  • fbffbfdae559 hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device
  • ac8d8b599d46 fsnotify: Fix stale object mask after concurrent mark updates
  • 397423af18b6 fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration
  • c4f196bfeedd forcedeth: fix off-by-one when saving/restoring non-PCI config space
  • c87d9c412bf9 fonts: fixup font.h kernel-doc warnings
  • 9e768ae51426 fbdev: uvesafb: unregister connector callback on init failure
  • 1981e54ac137 fbdev: ssd1307fb: defer I2C transfers from damage callbacks
  • fab0234a97d2 fbdev: pvr2fb: correct user pointer annotation and sentinel initializer
  • 09db79078f25 fbdev: omapfb: panel-dsi-cm: initialize lock before registering display
  • e65d6326a763 fat: restore original value when fat_ent_write failed
  • b8f73b163b64 fanotify: fix use-after-free of file range info
  • 5efb3350230f ext2: Fix lost inode updates for IS_SYNC inodes
  • 7f4a89d4f0d6 erofs: skip sufficiently large global buffers when resizing
  • ab4647459098 entry: Fix seccomp bypass after ptrace with TSYNC
  • 0dbc2e94b81d efivarfs: Rate limit statfs() handler
  • 75101e106c42 ecryptfs: show filename encryption options
  • 654b7e79443f ecryptfs: release message context on send failure
  • d2869768eab5 ecryptfs: reject too-small tag 70 packets
  • a419c9ebfc9a ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet
  • 747fd45be396 ecryptfs: pass packet set buffer size to parser
  • 4c02acbe0a26 ecryptfs: hold msg ctx list lock when cleaning daemon queue
  • 7da5861dcc7b ecryptfs: fix tag 11 packet exact-fit size check
  • 279b1663be4f eCryptfs: bound the packet-length peek to the user buffer
  • 6e844d4b8243 ntfs: verify run length exceeding volume boundary
  • cd7b3dc7557f ntfs: validate non-resident attribute offsets
  • 8f8420b68a6f ntfs: reject invalid MFT LCNs from boot sector
  • b0cc6dbc655e ntfs: reject invalid empty mapping pairs
  • dc15a9f5307d ntfs: bound the free-cluster bitmap scan to the volume
  • 1135ebc22599 fs/ntfs3: bound page_lcns[] index by the log record
  • 4a1b39b2e10e fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()
  • 0908da07c23b fs/ntfs3: validate dirty page table on log replay
  • 76e0f85f6507 eventfs: Initialize ei->children and ei->list in init_ei()
  • 2785f06aba4f HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during teardown
  • 774609feaaf4 HID: intel-thc-hid: intel-quicki2c: fix autosuspend cleanup during teardown
  • 54e0bafc0653 HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer
  • ee8ad1bb1e96 HID: intel-thc-hid: intel-quickspi: validate report size before copy
  • 7c18fb36708a HID: mcp2221: validate report size in mcp2221_raw_event()
  • 968546b676d9 HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes
  • 2eda1513f573 HID: mcp2221: stop device IO before hid_hw_stop
  • c457bb516b61 HID: universal-pidff: stop the device when force-feedback init fails
  • 3155dc327344 HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind
  • d96f8958d446 HID: sensor: custom: Fix field sysfs group cleanup on failure
  • fbb5a60f5c31 HID: roccat: free buffered reports when destroying device
  • 699a3c8b56e1 HID: picolcd: clamp eeprom debugfs read to bytes actually received
  • 0329354abba3 HID: corsair-void: Check size of status and firmware events before reading them
  • df9168b2678b HID: apple: preserve keyboard backlight across T2 resume
  • 5b16a1967a01 smb: client: restore the data_offset bound in is_valid_oplock_break()
  • 411e484fe71a smb: client: reject a tree connect response whose byte count is too small
  • 7e32da6047d9 smb: client: harden DFS cache against invalid target hints
  • 711cf71300d7 smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr()
  • 033bc80019f0 smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()
  • ab284008d7d0 smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV
  • 62a3025983c8 smb: client: fix ALIGN() overflow in symlink_data() error context loop
  • 74e3ef4630f0 ksmbd: only rebind the reopened file's own oplock on durable reconnect
  • 5baab40404a9 smb: client: clear ce->tgthint in free_tgts()
  • 5e6533a683f6 smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2
  • 69bfe810ecd1 smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions
  • 81fc3868a7f7 cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC
  • b057ca17b656 cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
  • 4bea15d9c768 cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size()
  • 12bafe32f09c cifs: call pagecache_isize_extended() in cifs_setsize() when extending
  • 7d4312f0ca20 cifs: add cifs_resize_file_locked() to guard fscache_resize_cookie() under i_rwsem
  • 583cf579b32d audit: avoid dropping live tree ref on fsnotify rule autoremove
  • aeb5770732cd btrfs: do not overwrite NODATASUM flag when removing NODATACOW flag
  • 05a1a816eef8 btrfs: fix extent map leak in NOCOW direct I/O write
  • 4d43107e807b btrfs: drop recovered reloc root refs on recovery failure
  • ac7a5a538576 ceph: fix leaked inode reference on writeback abort at umount
  • 3d122b2feb1d ceph: do not repeat ceph_trim_dentries() if no progress possible
  • f341270ac5f5 ceph: cap delegated inode count in ceph_parse_deleg_inos()
  • b12b3320c81f ceph: bound xattr value length in __build_xattrs()
  • 332c444f4dc6 ceph: bound num_export_targets array for mds info v2/v3
  • 5f892c767b30 ceph: bound MDSCapAuth path and fs_name decode in handle_session()
  • e7c2fd3893a7 ceph: bound copied dentry name length in NFS export get_name
  • 96c3f5fbb0d5 ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
  • 3d0311481b89 ceph: force a cap message when a deferred revoke can't be acked immediately
  • 21d5be092d94 ceph: fix UAF in check_new_map() on session freed during unlock
  • 2dba24dcd505 ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock
  • 79900d978158 libceph: reject buckets with mismatched CRUSH ids
  • 201db408872c libceph: validate OSD extent maps before cursor advance
  • 9fb4c08ac2cb nfsd: use test_and_clear_bit for somebody_reclaimed to prevent lost update
  • 81cf7f141386 NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup
  • 2a9d637c2a8f NFSD: Prevent client use-after-free during delegation revoke
  • bf1f94869152 NFSD: Prevent client use-after-free during admin state revocation
  • 0c1a755b7212 NFSD: Prevent post-shutdown use-after-free in unlock_filesystem
  • 8cf4ff0a7c08 NFSD: Prevent lock owner use-after-free during client teardown
  • ff8a3cff02b9 nfsd: revoke copy-notify stateids before dropping their reference
  • 5b3a7d7c23c0 nfsd: release OPEN-decoded posix ACLs via op_release
  • aa34577f39e3 nfsd: reject reclaim LOCK after RECLAIM_COMPLETE
  • 1195483965a5 nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE
  • e2543852152b nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops
  • 08af9593e2b4 nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache
  • ab43ff94f5df nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd()
  • 431c70ca5163 nfsd: initialize DRC hash table before registering shrinker
  • 4cdef96892f4 nfsd: initialize copy-notify stateid before publishing it
  • 559570f91a7d nfsd: hold rcu across localio cmpxchg retry
  • ff99ed007f06 nfsd: gate nfs3 setacl by argp->mask
  • 37eea38e7898 nfsd: gate nfs2 setacl by argp->mask
  • 62e5949f0dd5 nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo
  • c81cef6a805d nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget
  • 58b35b13e537 nfsd: fix version mismatch loops in nfsd_acl_init_request()
  • a385cf5e016b nfsd: fix UAF in async copy cancel and shutdown
  • 14b978e8d05c nfsd: fix stale s2s_cp_stateids IDR entry for async COPY
  • 2da9a73acd3b nfsd: fix reply size estimate for GET_DIR_DELEGATION
  • a3c75f9bb6f5 nfsd: fix refcount leak in nfsd_file_lru_add on insertion failure
  • 033e783709ce nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file()
  • fa6590dfd16a nfsd: fix partial-write detection in nfsd_direct_write
  • 3c896db12389 nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs
  • 6ed8d6de7ec9 nfsd: fix nfsd_file leak on inter-server COPY setup failure
  • daaf4d951f0f nfsd: fix netlink dumpit error handling for rpc_status_get
  • a278d361e0e8 nfsd: fix layout fence worker double-reference race
  • 66d89bc7ecf1 nfsd: fix FL_SLEEP being set unconditionally for all LOCK types
  • cadc9036d5a8 nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net
  • 11db8df188b3 nfsd: fix dentry ref leak on V4ROOT export filehandle lookup
  • c7270f62e7a0 nfsd: fix cpntf publish race in nfs4_init_cp_state
  • 984364919622 nfsd: fix clock domain mismatch in clients_still_reclaiming()
  • 97bda8b4284d nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke
  • a95a1cffacd0 nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file
  • f7cb90ddc021 nfsd: drop the stateid, not the stateowner, on seqid_op replay retry
  • b449b134e776 nfsd: don't free session slots that are still in use
  • 19413ccc4507 nfsd: defer vfree of compound ops to fix rpc_status UAF
  • fe574c8069db nfsd: defer setting NFSD4_CALLBACK_RUNNING in deleg_reaper
  • 281cd65d9264 nfsd: dedup nfs4_client_to_reclaim inserts
  • df5922fe09a8 nfsd: convert nfsd_net boolean flags to unsigned long flags word
  • c1a4f7b1848f nfsd: clear opcnt on compound arg release to prevent OOB read
  • cb2d0c4d1b3d nfsd: clear CALLBACK_RUNNING on failed delegation recall queue
  • 80cebb0e8a8d nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()
  • d801906165cb nfsd: check client ownership when cancelling a copy-notify stateid
  • ea14d71d6ecb nfsd: cap decoded POSIX ACL count to bound sort cost
  • bf4d338dc862 nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref
  • 9b5f6475006c nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry
  • b4c121e18628 nfsd: add filehandle match check to nfsd4_delegreturn()
  • c4a409b86a92 nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()
  • dcb69ad0dafb nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage
  • 45ec115cbfec nfsd: validate symlink target length in NFSv4 CREATE
  • 22d0e4752ca8 nfsd: validate sockaddr length per family in listener_set
  • 5eb489831a9f nfsd: validate nseconds in TIME_DELEG decode paths
  • 719a10e3f5f8 nfsd: size fh_verify server sockaddr slot by xpt_locallen
  • a6d89032e5c6 nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations
  • a1cbafe756cd nfsd: sample writeback error cursor before async COPY loop
  • b63e4997c776 nfsd: return NFS4ERR_NOTSUPP for unsupported netloc4 types
  • b08c30f08d57 nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths
  • bf0cd31a9abc nfsd: Reset write verifier when async COPY writeback fails
  • 2bc4343308d8 nfsd: release path refs on follow_down() error
  • 13bdd486c3aa nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown
  • 3c461a182008 lockd, nfsd: RCU-protect nlmsvc_ops dispatch
  • 078ccf7321f0 pNFS: Fix EBUSY check in pnfs_layout_need_return
  • 32ac1b0b7f1c NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path
  • 766170b4fd2d nfsd: guard nfsd_serv deref in nfsd_file_net_dispose
  • a275de3bac56 NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check
  • 7377fa964b8a NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock
  • df2bd155dc40 NFSD: fix up error returned by write_threads()
  • 4876f345e42a NFSD: Fix off-by-one in DRC bucket pruning limit
  • 6c14602c01a2 NFSD: Encode only the status in NFS-ACL v2 GETACL error replies
  • 440862544790 NFSD: check truncate permission under inode lock
  • 0fd2b9687dae NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails
  • 9f59b05423ed NFS/localio: fix ref leak on nfs_uuid_add_file failure
  • 9b8af4d3f623 zsmalloc: account for handle size in class lookup
  • e23fac4ab2a5 zram: validate deflate params
  • dea8f13c3dfa zram: set default primary compressor in zram_destroy_comps()
  • 07a82a66f8c1 zram: fix out-of-bounds access in writeback_store()
  • 5e458fa714a5 zram: fix out-of-bounds access in read_block_state()
  • 83e1aa9f5f90 ubifs: fix out-of-bounds read in signature length check
  • c1a62f9dcf53 phy: rockchip-samsung-dcphy: fix out-of-range max_register
  • 7a99e9c70119 PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io()
  • acd1b4904336 of: fix out-of-bounds read in of_alias_scan() stem parser
  • 28362e8ce513 nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation
  • b95315ffc66b media: vicodec: fix out-of-bounds write in FWHT encoder
  • a85ce3b17561 media: cec: stm32: prevent out-of-bounds write on RX overflow
  • 1b0dc3cbb863 lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
  • 78b95c571d02 KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID
  • 769f5a233efc i3c: renesas: Fix out-of-bounds access for newdevs mask
  • bc3d72c44bff HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature
  • 4dc1051939e4 fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write
  • 8e3d9dbb25d3 cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read
  • eac233e63f9d usb: gadget: f_fs: Prevent deadlock during ep0 read loop
  • 38f822ddce93 usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()
  • d511e015d067 usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init()
  • d90b0f90e30c usb: gadget: f_tcm: fix deadlock in usbg_make_tpg()
  • 9ea5dfb2bfef usb: gadget: midi2: remove default configfs groups on teardown
  • 0245adc0ad35 usb: gadget: snps_udc_plat: clean up PHY on probe deferral
  • 79a92896e2bb usb: gadget: u_audio: Fix use-after-free on sound card disconnect
  • 584ec5152f87 usb: typec: ucsi: use UCSI_TIMEOUT_MS for sync command completion
  • 0a25484fe22f usb: typec: thunderbolt: Disable work before freeing tbt on remove
  • db0894b59bb9 usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive()
  • 5c7678e38a09 usb: typec: hd3ss3220: fix VBUS regulator error message
  • b729106ec974 USB: phy: fsl-usb: fix missing static keywords
  • 557ef547d49f usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed
  • 93e08b13a7a3 usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition
  • cdc1085ad40c usb: dwc2: gadget: Exit partial power down state when changing USB pull-up
  • fdc3fa9a38e1 staging: greybus: hid: fix SET_REPORT return value
  • 7429dce56a73 serial: imx: serialize imx_uart_ports[] lifetime
  • ce792b94e038 Revert "media: v4l2-dev: fix error handling in __video_register_device()"
  • 211c68d817a3 rapidio: mport_cdev: fix use-after-free in dma_req_free()
  • 71c8c1b06e6d powerpc/powermac: fix OF node refcount
  • 2aa0fb9c96f8 misc: nsm: bound the device-reported response length
  • 9cb6b223ef02 device property: fix infinite loop in fwnode_for_each_child_node()
  • e7f6a6b5741d debugfs: Fix lockdown check for mmap_prepare
  • 7e9451bf0bdb cdx: Fix double free when sysfs file creation fails
  • 83d1ae0406d8 tracing: Fix use-after-free with same-name named triggers
  • 7a49d19ff9ba tracing: Fix use-after-free in trace_pipe read on sub-buffer order change
  • df02489aa3aa tracing: Fix retry exhaustion in simple ring buffer reader swap
  • 57e8f60d3cdd tracing: Fix logged instance name on creation failure
  • c40e0b4fa365 tracing: Fix crash passing ERR_PTR to kthread_stop()
  • b799f67119af tracing/user_events: Clear copied tracing state before fork duplication
  • 52848a7ef68f hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start()
  • 6ac9f3783096 x86/xen: fix init of balloon stats again
  • 148257843037 x86/tdx: Fix zero-extension for 32-bit port I/O
  • bb45f705c444 x86/tdx: Fix off-by-one in port I/O handling
  • 786508f8339c x86/insn-eval: Move assign_register() out of KVM as insn_assign_reg()
  • 9eb3bfc11d6d x86/locking: Use sfence for wmb() if SSE is available
  • d20f260388b3 tools/compiler: match glibc 2.42 definition of attribute_const
  • e883a6bd96a4 mm: vmscan: fix node reclaim ignoring swappiness parameter
  • 2dcdb27f6e42 mm: page_alloc: fix non-movable reclaim storm in defrag_mode
  • d3f688e98da0 mm: page_alloc: move capture_control to the page allocator
  • bf483ca703f1 mm: page_alloc: __GFP_FS lockdep annotation for direct compaction
  • 89e8a4f0455a mm: mempolicy: fix automatic numa balancing for shmem
  • 5dba2ce548db mm: memcontrol: update state_local when flushing NMI stats
  • aab391074de9 mm: memcg: stop reclaim when a limit update is superseded
  • a8058dfd0a51 mm: memcg-v1: fix memsw and TCP failcnt accounting
  • 8823354b644c mm: memcg-v1: fix wrong linux-mm list address in deprecation warnings
  • 3dcc2fdc4017 mm: compaction: support non-movable compaction for pageblock requests
  • 684e175ffce0 mm/zswap: fix global shrinker when memory cgroup is disabled
  • cf3ba0911a1c mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()
  • cdfa3e2a1e91 mm/vmalloc: make vm_struct.nr_pages an unsigned long
  • e734cdda6b85 mm/slub: prevent pfmemalloc objects from entering the barn
  • f77cbe1f17a2 mm/slub: fix missing debugfs entries for caches created before sysfs init
  • 240885926f3f mm/rmap: use huge_ptep_get() in try_to_migrate_one()
  • 4b9cd315061a mm/rmap: use huge_ptep_get() in try_to_unmap_one()
  • c05cdc2ab365 mm/pagewalk: fix stale walk->action escaping walk_pmd_range()
  • 13e9a00e6baf mm/page_vma_mapped: use huge_ptep_get() for hugetlb
  • 46761406e143 mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg()
  • 84339578c2d6 mm/mm_init: deferred_grow_zone(): fix out-of-range first_deferred_pfn
  • 8ffedc6573a6 mm/migrate_device: clear stale mapping after freeing swapcache
  • cafccd266590 mm/migrate: use huge_ptep_get() in remove_migration_pte()
  • 66734981b4d3 mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()
  • 15d3a2a71c8b mm/mglru: fix and remove redundant unevictable folio handling
  • 3d927093b2ad mm/mempolicy: skip non-present PMDs when queueing folios
  • 5c0d7b658cda mm/madvise: skip device-private PMDs in cold and pageout walks
  • 1838c704bcb4 mm/kmemleak: avoid soft lockup when scanning task stacks
  • c97a016dd4b5 mm/hugetlb_vmemmap: fix __hugetlb_vmemmap_optimize_folios()
  • 29968bc7aefb mm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier
  • 2ddf429e25cf mm/hugetlb: fix boot panic with CONFIG_DEBUG_VM and HVO bootmem pages
  • 6cd209dbb55f mm/huge_memory: use folio's memcg inside __folio_split()
  • 5e3026bf7364 mm/huge_memory: skip device-private PMDs in madvise_free_huge_pmd
  • ad41ca3534e6 mm/gup: fix always draining LRU caches in collect_longterm_unpinnable_folios()
  • 183fe65b0979 mm, swap: ratelimit bad swap entry reports
  • a6df73156f2d mm, swap: don't free a hibernation slot that is in the swap cache
  • 5f8132f2c9a0 include/linux/list.h: mark list_add and __list_add as __always_inline
  • 36bdd0b45ec3 apparmor: fix out-of-bounds write when null terminating a label vec
  • 580f777d6d9f apparmor: fix cred UAF caused by begin_current_label_crit_section()
  • 2f7541afbc57 KEYS: trusted: Fix TPM teardown ordering
  • 553142f4c44c kbuild: rust: keep Rust objects out of Clang LTO with inline helpers
  • fb760bdf799e kbuild: rust: preserve unreachable traps with inline helpers
  • 793e49f4ff12 rust: cfi: disable function merging if CFI is enabled
  • 9d9b98b39609 rust: num: restrict bool conversion to unsigned Bounded
  • 66fff437a15f objtool/rust: add one more noreturn Rust function
  • 744794d8920e rust: kernel: list: fix incorrect pop_back example comment
  • a7ef535bfdc1 rust: kbuild: disambiguate zerocopy_derive for rusttest
  • cdbbcd7c64c9 rust: devres: ensure revocation is complete before device finishes unbinding
  • c7e3d57c705a rust: devres: fix race between concurrent revokers
  • a6756230ab95 rust: dma: return zero for Coherent reads past EOF
  • f72804337142 rust: rust_is_available: warn for bindgen < 0.72.1 && libclang >= 22
  • 0523fab5f6cf rust: bug: prevent dead_code warning from warn_on!'s flags constant
  • f391fef4122a rust: bug: fix warn_on macro build error on UML
  • f49982cc4b9b rust: bug: skip arch-specific asm in testlib builds
  • d6d980e5208d rust: kbuild: disambiguate zerocopy for rusttest
  • ffef68ecc191 objtool/rust: add one more noreturn Rust function for Rust 1.99.0
  • 00ef529a5402 timers/itimer: Zero-init old itimerval before copy to userspace
  • c0eab781e182 rust: fmt: fix {:p} printing stack addresses
  • 2fd19075a07f powerpc/pseries/iommu: switch to Default DMA window during kdump
  • e89318aa8629 pidfd: hold exec_update_lock around namespace ioctl
  • b1aa8ab78a8e ovl: fix double end_creating() on the casefold-mismatch path
  • a35cc2135573 fs: fix user path of nested backing files
  • f0efafcdf6ee clocksource/drivers/timer-sun4i: Advertise a real minimum delta
  • cdcd86112324 clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path
  • 71f5f2f374df alpha: don't leak hardware-fabricated FP exception bits to user space
  • 22429a4d2451 rust: time: fix as_micros_ceil() rounding near i64::MAX
  • 65651f1001aa iomap: don't free integrity payload that doesn't exist
  • 0cc4969fc915 alpha: fix ieee_swcr_to_fpcr setting FPCR_DNOD unconditionally
  • f8ef75a263d4 drm/amd/display: Prune per-tile Timing from Apple Studio Display Primary Tile
  • 8eefff582dcc drm/amd/display: hide Apple Studio Display secondary tile
  • 0c7c517827a4 ring-buffer: Fix subbuf resize race with ring buffer readers
  • 074c715e0b49 btrfs: write-protect folios during data writeback
  • e2c8375e0c72 ASoC: tegra: Sort MBDRC register defaults
  • 9b1a9434f487 ASoC: tegra: Sort ADMAIF register defaults
  • 2b005289afbb ASoC: tegra: Fix the MIXER enable default value
  • 777a6a9cf729 ASoC: tegra: Fix the I2S enable default value
  • 8f98fbb7fd4a ASoC: tegra210_mixer: sort the register default table
  • 0ade1c624b23 ASoC: tegra210_i2s: sort the Tegra264 register default table
  • 3e1b654f5479 ASoC: tegra210_i2s: sort the register default table
  • f733276ae737 drm/amd/display: Skip Update HDCP Config In Transition State
View originalPermalink
How 7.2.4-xanmod1 went

6.18.50-xanmod1

Changed 1
  • sysctl: move the cad_pid entry from pid_table[] to kern_reboot_table[]
Fixed 18
  • mm/rmap: use huge_ptep_get() in try_to_unmap_one()
  • mm: avoid unnecessary use of is_swap_pmd()
  • platform/chrome: sensorhub: Fix dropped timestamp events and log spam
  • selftests/mm: fix on-fault-limit false failure under sudo-rs
  • udf: Fix i_lenExtents truncation on 32-bit kernels
  • timer: Keep debugobjects state consistent in migrate_timer_list()

From XanMod Kernel

  • 211a65465dd9 Linux 6.18.50-xanmod1
  • e8b3291361f1 Merge tag 'v6.18.50' into 6.18
  • 7cfc41f8e80f Linux 6.18.50
  • 8e30f5427f34 mm/rmap: use huge_ptep_get() in try_to_unmap_one()
  • 381a0a524e96 mm: avoid unnecessary use of is_swap_pmd()
  • 6a259dd31304 platform/chrome: sensorhub: Fix dropped timestamp events and log spam
  • e91d66e5ff66 selftests/mm: fix on-fault-limit false failure under sudo-rs
  • 2d6150e5e6aa udf: Fix i_lenExtents truncation on 32-bit kernels
  • b7eff3f621ef timer: Keep debugobjects state consistent in migrate_timer_list()
  • fecf1e377752 timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex()
  • 6067c39c2cec taskstats: fix cpumask parsing cutting off the last character
  • ed64aa505875 smack: fix cred UAF in smack_file_send_sigiotask()
  • a246da20c8e4 signal: avoid shared siginfo namespace rewrites
  • 236c8ecaafc6 sticon/parisc: Detect default STI graphics card for console output
  • e8527de7fea1 sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]
  • cde2d927c29e tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout
  • c3c7e87c76b4 zloop: truncate finished zones to zone capacity
  • f49e55b1c8fe xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc()
  • ae0c79a85270 w1: ds28e17: reject an oversize length on an I2C block read
  • 165a330a68b5 vsock/virtio: flush works in dependency order
  • 03b81f015dbb wifi: mt76: mt7996: validate default EEPROM firmware size
  • 01f2e0da8548 wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames
  • 304470333b7f wifi: mt76: mt7925: cancel mlo_pm_work on stop
  • 5fdaf7016d76 wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy
  • 4506e229b2e4 wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex
  • 34a505071d1f wifi: rtw88: pci: fix resource leak on failed NAPI setup
  • 7364713f0931 wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()
  • dc8b0be0ec4d wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars()
  • 0c0b374e12d5 wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids
  • 97a1af5ac131 wifi: rtl818x: initialize eeprom_93cx6 struct to zero
  • b1bbeb8970ee wifi: mwifiex: Detach sync cmd buffer on interrupted wait
  • 7c257a295e05 crypto: sun8i-ss - Remove crypto_rng interface
  • 8e4f9110aba3 crypto: sun8i-ce - Remove crypto_rng interface
  • 620acb1e8037 wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop
  • 84ba017a1e1e wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()
  • 261d7c7610b4 wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()
  • 7ef23317f997 i3c: renesas: Reconfigure the DATBAS register on re-attach
  • 9382fcf3a8c4 i3c: renesas: Clean DATBAS register on detach
  • 0093f9fc102b i3c: renesas: Check that the transfer is valid before accessing it
  • 5697d779577e i3c: master: svc: bound IBI payload to the requested max_payload_len
  • 94fb9786d67a i3c: master: Fix info leak and UAF in device unregister path
  • a15a1b95de98 i3c: master: adi: initialize the lock before enabling interrupts
  • 1894fc7a3bab dm-pcache: fix use-after-free and invalid seg operations in kset_replay()
  • 10acf740c3ad dm-pcache: fix implicit u8 truncation of gc_percent in message handler
  • 83e3116283ed dm-pcache: only hand out initialized cache segments
  • 663ee2f3824a dm-pcache: detect a cycle in the last-kset chain during replay
  • 2cd9776fe3f2 dm-pcache: clamp the tail kset read to the segment data region
  • ffd9a214a94f dm-pcache: bound the persisted tail-position offset
  • 91b93fe5cf4d dm-pcache: validate on-media seg_num against the cache device size
  • d8caf96040a0 dm-pcache: validate kset key_num and intra-segment bounds
  • ab5dcde6fa96 dm-pcache: validate geometry fields from on-disk cache_info
  • 296efdc110b1 dm-switch: use WRITE_ONCE() in switch_region_table_write()
  • 74210fa07296 dm-stats: fix a crash if allocation of per-cpu data fails
  • c860cd3f4038 arch_numa: avoid false positive fortify warning in setup_node_to_cpumask_map()
  • edf30d65e3ac net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry
  • 44dc702be9a9 rust: rust_is_available: warn for bindgen < 0.72.1 && libclang >= 22
  • b5fe67111e63 ovpn: run deferred work on a module-owned workqueue
  • 50f4a793c4ff ring-buffer: Fix subbuf resize race with ring buffer readers
  • 22fe01a2e2f7 ALSA: hda/realtek: Fix Lenovo Yoga Slim 7 14AKP10 quirk ordering
  • 37c3210c491a ALSA: hda/realtek: Enable micmute LED on HP EliteBook 6 G1a p/n: AD3Q9ET#UUG
  • 8acb66d0513d ALSA: hda/realtek: Add quirk for TongFang XxAF5xxx
  • 40ee4224e2fe ALSA: virmidi: Check card index validity at probe
  • 7555e83d7738 ALSA: serial-u16550: Check card index validity at probe
  • d7ef7890e3e3 ALSA: portman2x4: Check card index validity at probe
  • 7ef9ad82d95d ALSA: pcxhr: initialize mutexes before requesting threaded IRQ
  • a4e774eeb61a ALSA: mts64: Check card index validity at probe
  • cc4215cc2a4b ALSA: mpu401: Check card index validity at probe
  • 13d61a920435 ALSA: hda/ext: preserve PPLCCTL bits when clearing reset
  • 7df3194bdb74 ALSA: bcd2000: clear the URB pointers on disconnect
  • 7b3f98558493 ALSA: aloop: Check card index validity at probe
  • 2a6f6fba3bd3 ALSA: 6fire: bound the MIDI event length from the device
  • 94ca4f040ba4 mfd: sm501: Fix potential memory leaks during remove
  • 5e7fe9c6c8c3 mfd: cgbc: Fix teardown ordering in cgbc_remove()
  • efe0ed4c0f4e hwrng: stm32 - Fix runtime PM cleanup on registration failure
  • cfa186a0857a seg6: reset IP6CB after IPv6 decapsulation
  • 288f99706708 net: skbuff: don't touch shared zerocopy state in skb_tx_error()
  • 34ab62c959f5 net: fix spurious TX timeout after dev_activate()
  • af0ee8f04bea net: cap advertised IP tunnel headroom
  • 5bd8b764a610 net/smc: unregister the connection before draining the rx tasklet
  • 313f79149eb3 net/smc: stop killed, freed and out_of_sync sharing a byte
  • c52a998a223e net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link()
  • 0761e49aa78c net/smc: fix use-after-free in smc_rx_pipe_buf_release()
  • d89dc1bd8845 net/smc: fix socket refcount leak in smc_switch_conns()
  • f950e1b1f0aa net/smc: do not dereference an unset send buffer on the SMC-D teardown path
  • 486c699a8cde net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages
  • b893152a886b net: ntb_netdev: Count packets dropped on RX refill failure
  • 4fac86e97697 net: ntb_netdev: Avoid double-accounting netif_rx() drops
  • dfab7171cd39 net: ntb_netdev: Fix TX busy and drop handling
  • 6b6bbc6c878d NTB: ntb_transport: Reject oversized TX buffers
  • 894e136b432d NTB: ntb_transport: Fail TX enqueue when the QP link is down
  • 0c4aabc90449 NTB: ntb_transport: Recycle TX entries before client callbacks
  • f01e6a35c440 net: thunderbolt: Mark the connection down when bringing it up fails
  • 61ff3c353e5d net: thunderbolt: Release the Rx HopID that was handed out on mismatch
  • 67a82e6f886b net: ravb: serialize PTP clock teardown
  • 8d4d06d6e2b5 net: ravb: avoid dereferencing an invalid PTP clock
  • b6b533f83461 net: phylink: correctly validate returned PCS in phylink_inband_caps
  • 0860af127aa7 net: openvswitch: fix nf_connlabels leak in ovs_ct_init
  • ac73e3af571d net: openvswitch: fix flow mask use-after-free on flow deletion
  • 9c340473f482 net: l2tp: do not propagate multicast notification errors
  • 62da38b4b3a0 net: ipa: fix stalled modem TX queue after runtime resume
  • 42a33e679ea0 net: ibm: emac: mal: fix NAPI locking
  • f71087e7c63a net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO
  • e098d9cc8859 net: tun: bound receive headroom
  • 32785d75e60d net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition
  • 486577db8078 slip: fix use-after-free in sl_sync()
  • 15d1f3c0dbe7 xdp: fix zero-copy frame layout
  • 8e3763f1ccac net/iucv: filter frames in afiucv_hs_rcv() by ingress device
  • 99692252b348 ipmi:msghandler: Cancel work cleanly on an error
  • 53af3a8bae0a ipmi: si: Fix NULL pointer dereference after failed registration
  • d46c97eddcbc ipmi: Remove all sysfs files on registration failure
  • 5719431ca2b5 ipmi: ipmb: validate write message length
  • db8147c5d5ad interconnect: Fix use after free in icc_get() and of_icc_get_by_index()
  • 417e02f7b605 io_uring/query: cap user size passed to copy_struct_to_user
  • 0c12a798078b platform/x86: hp-bioscfg: warn on element type mismatch instead of failing
  • a38127df99ae platform/x86: hp-bioscfg: pass validated element count to package parsers
  • 95d2f9b5189d platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed
  • b15b334fbc3c platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()
  • e3c1c5d1c923 platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password
  • 0f9aad084248 platform/x86: hp-bioscfg: fix heap OOB read on empty password write
  • 7cd8fe01aba3 platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()
  • dea1a41160e7 platform/x86: hp-bioscfg: bound ordered-list parsing by the package count
  • 0cd1530f84e1 platform/x86: hp-bioscfg: advance elem past consumed array elements
  • 0a14d35ef529 platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS
  • bc9aa5fe21c3 platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails
  • 8178f59d7657 platform/x86/amd/pmc: Propagate SMU errors and validate S2D address
  • 98d91d5b6a98 platform/x86/amd/pmc: Restore msg_port on amd_stb_s2d_init() error paths
  • 5eaf7faa9957 platform/chrome: sensorhub: Bound the EC-reported sensor number
  • 56dc46094973 platform/x86: think-lmi: Fix current password length check
  • 9c28adde051f platform/x86: think-lmi: Free system certificate signatures
  • 89a076948ed6 platform/x86: think-lmi: Fix certificate thumbprint sysfs output
  • d7cd3e4d7603 platform/x86: lenovo/ymc: Only match lower byte in WMI lid switch query response
  • e1b3f89673bd platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path
  • e07a42bb9c90 platform/x86: ISST: Return error during profile addition
  • 62840acc3044 platform/x86: ISST: Validate parameter for frequency and priority
  • 93268bc3cd84 platform/x86: ISST: Validate parameter for core power state
  • 5b032e1dda48 platform/x86: ISST: Validate logical CPU id and clos id
  • b14db79d02bd platform/x86: ISST: Use PP level enable mask
  • 92c5fffa63ad platform/x86: ISST: Just allow 2 bits for SST feature enable
  • c280fcd53b93 platform/x86: ISST: Add a NULL check for sst_inst[]
  • 2550f89589ca mmc: via-sdmmc: stop card-detect handling on probe failure
  • f7ff3027ef00 mmc: via-sdmmc: cancel card-detect work on remove
  • 82e707eff9e3 platform/x86: ISST: Validate socket ID in clos_assoc ioctl
  • 1889a9156553 platform/x86: ISST: Validate level in perf mask ioctls
  • 22222f92b0a5 platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer
  • cab289572951 iommufd: Fix UAF in selftest IOPF reporting
  • 4c33d00ad9a9 iommufd: Release current IOAS on xa_store() failure
  • 436189ee4bb2 iommufd: Avoid locking internal accesses during unmap
  • 45705a6bfdb2 iommu/vt-d: Force requesting ACS when tboot is enabled
  • 364279b5623f iommu/vt-d: Fix no_iommu to disable platform opt-in
  • f80f3acb6916 iommu: Fix dev_iommu memory leak when device_add fails in iommu_mock_device_add
  • 2235eafda9b3 iommu/arm-smmu-v3: Manage teardown with devm
  • d903d99ffd22 iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field
  • 968e9a1f7114 iommu/sva: Set handle->dev before the SVA handle is visible
  • f532401be931 iommu/msm: Unwind probe state on registration failure
  • cfc5c1b2caa1 iommu/amd: Put PCI device after handling PPR faults
  • 238e1f7a1463 PCI/proc: Warn on writes to kernel-exclusive config space regions
  • c2d4174f4924 PCI/proc: Use file_ns_capable() when checking config space read access
  • 301288f85679 PCI/proc: Avoid spurious runtime PM wakeup on config space accesses
  • b30713111325 PCI/MSI: Enable memory decoding before restoring MSI-X messages
  • 0e59a232aaa0 PCI/ASPM: Avoid L0s for Realtek RTS525A
  • 39c4dc79d77f PCI/AER: Fix mapping of errors to agent & layer
  • 4f887d8ed75f PCI/AER: Emit TLP Log only for unmasked errors
  • 6beadccc432c PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses
  • 7f4db64f0ba7 PCI/sysfs: Fix read byte order in pci_read_legacy_io()
  • 43cf455dd5a9 PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608]
  • 4b575052ea65 PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts()
  • 01c2f0c66bd1 PCI: plda: Fix use-after-free of event IRQs during teardown
  • 5d4bc470330a PCI: meson: Fix GPIO state while requesting PERST#
  • 1ad699485385 PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk
  • 6053d6eacbfd PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip
  • ceafb262475a s390/dasd: Propagate partial completion length across ERP recovery
  • 6452c13646af s390/dasd: Guard sysfs discipline callbacks against unallocated private data
  • 52b331c99baa s390/dasd: Do not complete a failed ESE read as successful
  • dcce7a06ea69 s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
  • aad7247bd35a power: supply: max17040: synchronize work cancellation on suspend
  • 17d43f64b17e power: supply: max17040: drop incorrect I2C functionality check
  • 13fb0477da9b power: supply: max17040: propagate register read errors
  • 39b60d615dfa power: supply: ucs1002: fix use-after-free on remove
  • a4460e89d408 power: supply: twl4030_charger: cancel workers via devm
  • 1b9978433c61 power: supply: rt9455: quiesce delayed work before teardown
  • ee053561e21c power: supply: qcom_battmgr: terminate the strings from firmware
  • 06618447029c power: supply: qcom_battmgr: fix use-after-free
  • b3aa1e9509e1 power: supply: lp8788-charger: fix use-after-free on remove
  • ab6b1ad710be power: supply: lp8727: fix use-after-free in lp8727_release_irq()
  • 4b1f2be1e1b7 power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS
  • 78be8b7403ff power: supply: cros_usbpd-charger: bound the EC-reported port count
  • 86e4fa65368f power: supply: charger-manager: register regulators before exposing sysfs
  • 238320ad029a power: supply: bq25890: Fix power_supply reference leak
  • 9e1aba34df9a power: supply: bq256xx: drain usb_work before freeing the charger
  • f495808cdd6d power: supply: bq24257: fix use-after-free on remove
  • d02a5794c3de sctp: fix stream->outcnt underflow on duplicate RECONF responses
  • 7ad8933bca97 sctp: distinguish sequence zero from wildcard in reconf lookup
  • 25419f516ea8 sctp: fix NULL deref on untransmitted RECONF completion
  • 1035bdef1efb sctp: drop a chunk if its transport was removed
  • fa306a40e716 sctp: stop processing a packet once its association is deleted
  • 8a02ad98798f nvme-tcp: reject a read that transferred too few bytes
  • 3b3d27670c0c nvme-tcp: fix host memory disclosure on R2T for a read command
  • 6a01b5826310 nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
  • 0d4f317b07d6 nvme-pci: disable controller on admin queue IRQ setup failure
  • 67551d8430df nvme: zero the discard fallback page
  • 1e456cc2744e nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in error path
  • d662f7fc04fd lockd: fix NULL dereference on lockowner allocation failure
  • 41f0a6d31615 lockd: pin next file across nlm_inspect_file lock-drop
  • 3088e41292fe ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()
  • 6aeff1636b39 i2c: mxs: fix DMA channel leak on probe error
  • 8d2c120d2d5b hwmon: (max6621) fix temperature clamp range
  • 9b38d9a2e46a hwmon: (max6621) fix negative temperature offset and crit readings
  • 68c59343ad1a ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC
  • f2a1a83487c6 arm64: proton-pack: Restore the nospectre_bhb command-line option
  • e7c9b1d433b0 arm64: compat: Fix decrementing LDM/STM alignment emulation
  • 15d1feeae07d ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion
  • e41a59fc056f openvswitch: only skb_tx_error() a packet we are about to drop
  • d64a75369cd0 openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
  • c0c165487a2e ocfs2: fix readdir position truncation on 32-bit kernels
  • 0608018a71f2 ocfs2: cluster: fix o2hb_dependent_users leak on pin failure
  • 251e38f5af7b ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from drop_item
  • ce035f208d68 ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()
  • 0761d2c94944 ocfs2: validate rl_used against rl_count in refcount block validator
  • 50c4cc9183e1 ocfs2: validate lengths in dlm_mig_lockres_handler
  • de10cd3b062a ocfs2: bound namelen in dlm_migrate_request_handler
  • 71f07b7f90b3 ocfs2: always run deallocs on copy-on-write completion
  • 116d14f29a05 orangefs: skip leading spaces before parsing client debug masks
  • f796f38a324e orangefs: fix double-free of trailer_buf on readdir copy failure
  • bc6fdd425fde PM: sleep: Unblock runtime PM when device prepare fails
  • 6fcb0b745a0b ring-buffer: Hold cpu_buffer::lock when resizing a subbuf
  • 8c1ecdcdea73 ring-buffer: Free cpu_buffer::free_page with subbuf_order
  • 2dc510957fe8 ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page()
  • 1c3036a81800 regulator: qcom-refgen: correct the regulator type to CURRENT
  • 20e5fbb8c1a4 regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata
  • 95342d26f9c6 regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer
  • 71d5c41ac583 RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR
  • 4f8bb11dd2ff RDMA/ucma: Lock the handler in ucma_write_cm_event()
  • 28ac2dd41648 RDMA/ucma: Lock the handler in ucma_set_ib_path()
  • a38cd610b24f RDMA/ionic: Cap eq_count to the eth driver's interrupt vector budget
  • 85f438382a86 RDMA/cxgb4: Cancel reg_work before freeing device on remove
  • 2a952fb1b20d qede: Fix NULL pointer dereference in TPA fragment processing
  • 3f5677d2f817 ptp: vmclock: prevent read-only mappings from becoming writable
  • c7e32814a6bf remoteproc: scp: Fix device reference leak on failed lookup
  • 37797d5013c9 riscv: unaligned: stop using kthread for check_vector_unaligned_access()
  • 8f392916a354 riscv: acpi: Handle LPI architectural context loss flags
  • 5343399ed724 arm64: dts: rockchip: Fix rk3588s-roc-pc audio description
  • 8fc4bafabc06 arm64: dts: rockchip: Fix rk3399-roc-pc-plus analog audio
  • 650d2d5c0df7 arm64: dts: rockchip: fix emmc reset polarity on px30-cobra
  • 5512c2323120 arm64: dts: rockchip: fix eMMC reset polarity on PX30 Ringneck
  • fe455c13bf01 arm64: dts: rockchip: fix eMMC reset polarity on PP-1516
  • b6b3e4d5973b arm64: dts: qcom: x1-dell-thena: mark l12b and l15b always-on
  • 6bb9469c34ff arm64: dts: qcom: sm6115-pro1x: Correct touchscreen GPIO flags
  • ff23eb4823d8 Revert "arm64: dts: rockchip: Further describe the WiFi for the Pinephone Pro"
  • eb57632f9418 rpmsg: glink: smem: order FIFO read after availability check
  • e7143c3f4e5c scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables()
  • 2a8dd9fd12f3 media: staging/ipu7: fix async notifier UAF on probe error path
  • 7f6956b6dcd6 staging: media: tegra-video: vi: fix probe failure on skipped last port
  • 656d047dc0c2 staging: media: tegra-video: fix of_node_put() on VIP parse errors
  • 5be6d02837d4 wifi: mt76: mt7925: cancel pending mlo_pm_work
  • e1330d719c04 wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets
  • b95c33a4e743 udf: reject VAT indexes equal to the entry count
  • f84ec84d8d4b svcrdma: Validate Read chunk positions before reconstruction
  • a798714b5804 svcrdma: Reject Write/Reply chunks with segcount 0
  • 1949dd1576f7 svcrdma: Reject inline replies that overflow the pull-up buffer
  • 3cf372cec7ab svcrdma: Reject connection when transport allocation fails
  • 5aabe070c00e svcrdma: Fix unmatched rn_unregister on failed accept
  • a1c954ca4977 svcrdma: Fix pcl_for_each_segment for empty chunks
  • a46b35f213c2 svcrdma: Fix offset arithmetic in read_chunk_range
  • 1de391e8b94e SUNRPC: wait for in-flight client TLS handshake callback
  • 1f9856af065b SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field
  • 7a1d0501cbb9 SUNRPC: reject duplicate CREDS_VALUE options
  • edeefb111d61 sunrpc: init gssp_lock before publishing proc entry
  • ebcbd2523a85 SUNRPC: harden gss_unwrap_resp_priv length checks
  • 806584a4b67a SUNRPC: harden gss_krb5_unwrap_v2 against short tokens
  • fa46b6aa7a69 SUNRPC: Guard svcauth_gss_release() dispatch on rq_auth_stat
  • e769fcde3cc7 sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir
  • 08bc49e05412 sunrpc: defer rq_argp and rq_resp free until after RCU grace period
  • bd1ef2cfb44d SUNRPC: Check svc pool percpu counter allocation
  • 2e861ce2aaa4 SUNRPC: always drain cache_cleaner before destroying a cache_detail
  • 39981133df21 SUNRPC: Restore NUMA_NO_NODE for svc thread allocations in global mode
  • 9d04d64ad192 sunrpc: route to a populated pool in svc_pool_for_cpu()
  • de942dd8c2c8 SUNRPC: svcauth_gss: enforce krb5 token minimum length
  • e0778464049b SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
  • ad0cce80d4af SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow
  • f1b7b2c7ffa9 phy: fsl-imx8mq-usb: fix typec switch leak on probe error path
  • 704ecd010d4a params: fix charp corruption on allocation failure
  • ff110e85837d nouveau/gem: reserve the bo in the info ioctl around the vma lookup
  • 04ab51d4e369 module/kallsyms: fix nextval for data symbol lookup
  • 51887ccd8879 mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction
  • d82b90a38c2c mpls: reload header after pskb_may_pull()
  • 50d0aa7d25ba module: validate string table section types
  • 3b097416b4cf md: do overflow check for sb->bblog_shift in super_1_load()
  • 0efabe6229dc md/raid10: fix still_degraded being inverted in raid10_sync_request()
  • 121d35014e49 mailbox: qcom-ipcc: fix duplicate channel allocation across holes
  • 09e649117c54 libnvdimm/labels: Prevent integer overflow in __nd_label_validate()
  • 627ce4902df1 landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
  • a602cd128d17 ipv6: use RCU iterator to dump route exceptions
  • 63f50e9f90d0 ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()
  • b8282668d8fa ip6_gre: fix hardware header length for NBMA tunnels
  • b36dfd6e8cff ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit()
  • a8af6fbac895 ip: orphan prefetched skbs before multicast forwarding
  • 31e4be21dace ipip: fix skb leak in collect_md mode when metadata_dst allocation fails
  • f9182a85991a jbd2: check need_resched() when skipping busy checkpoint buffers
  • 71c6b872c746 jbd2: bound shrinker scans by examined checkpoint buffers
  • 30e8cb8598aa kasan: fix cache shrink race with CPU hotplug
  • 15deb4e33f47 Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request
  • 657054159d83 Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative
  • 94d548fc264a Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative
  • 1bad0896cbc0 Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection
  • d0b28e9655f4 Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb
  • 68e7a31abc88 Bluetooth: hci_conn: re-enable advertising only for peripheral role
  • 946d76db77ee Bluetooth: RFCOMM: serialize security confirmation handling
  • 49fd7116f76b Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready
  • ec3992e38f77 Bluetooth: hci_uart: Fix false success return in hci_uart_setup()
  • 62100186f177 Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative
  • 1ed5982c5369 Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378
  • c674c504bfdd cxl/pmem: Format the nvdimm serial number as unsigned decimal
  • 14d52c15d5d9 cxl/features: bound fwctl command payload to the input buffer
  • 2924b2e36514 cpufreq: schedutil: Fix rate limit overflow
  • a807a9ef87ad coresight: etm3x: Fix cntr_val_show() to match cntr_val_store() behavior
  • ac4a5eb8b002 dm array: reject an array block whose value size is not the caller's
  • b33f76d33aae dm array: validate array block headers on read
  • 644140527ae4 dm raid1: reserve space for NUL-terminator in build_constructor_string()
  • 36ff918637e3 dm-era: fix shadowed superblock leak on take-snap failure
  • 49694a363f7e dm-io: report non-retryable errors separatedly
  • 9493ac67623d dm-io: clone the source bio instead of copying its biovec
  • 272fcb4ba6fa bpf: Harden bloom filter sizing and indexing on 32-bit kernels
  • c9189693db47 buffer: avoid tail commit walk for uptodate folios
  • dbfecc8a6631 bpf: Disable preemption in __bpf_get_stack
  • 6886642414f5 bpf, x86: Fix per-CPU address resolution into an extended register
  • 49dcefa83c8a bnxt_en: Write doorbell when linearizing skb fails
  • 4d36e38e4834 bnx2x: fix double free in bnx2x_init_firmware() error path
  • c21fa79301d7 Bluetooth: eir: Fix OOB read in eir_get_service_data()
  • f609eac02d11 Bluetooth: btusb: limit RTL8761B BROKEN_EXT_SCAN quirk to 0bda:a728
  • bce588b4ca08 Bluetooth: btusb: Add ASUS USB-BT600 for Realtek 8761CU
  • aa7b93fe98ba Bluetooth: btusb: Add ASUS USB-BT540 for Realtek 8761CU
  • ce76ca5fb279 block: set QUEUE_FLAG_DYING unconditionally in blk_mark_disk_dead()
  • 84858671842a auxdisplay: charlcd: cancel backlight work on registration failure
  • c2e3dccd6870 ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes
  • fdc0a5e2cbac ARM: 9477/1: Disable broken eBPF JIT on the Risc PC
  • 87d07aa5d38b alpha: marvel: Fix lock ordering in init_io7_irqs()
  • 9e1eefc01912 alpha: marvel: Fix irq_set_status_flags to use correct IRQ number
  • 2fd984c44e3e alpha/PCI: Fix I/O port accessor argument order in pci_legacy_write()
  • 6d4ed2fd022b ACPI: pfr_update: fix stack buffer overflow in query_capability()
  • 452eb28e0301 ACPI: APEI: GHES: fix ARM section length accounting after header
  • b7476b29b696 ACPI: APEI: Fix ERST timeout unit conversion
  • c735dbce7ad0 acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks
  • 9ad8821573a3 accel/rocket: Fix error path handling in rocket_job_run()
  • 304323029665 accel/rocket: initialize job domain before cleanup paths
  • c1a5bf1b6e1d accel/rocket: fix NULL dereference and integer overflow in rocket_job_push()
  • a3c65af20cce hugetlb: only adjust reservation during unmapping if mapcount is 0
  • 4e019e5e247b hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device
  • 137c61a6cfd9 fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration
  • 0c3f4544ff38 forcedeth: fix off-by-one when saving/restoring non-PCI config space
  • 466a8af0dee2 fbdev: uvesafb: unregister connector callback on init failure
  • 3bcab9b21f71 fbdev: ssd1307fb: defer I2C transfers from damage callbacks
  • 3c1b5809615c fbdev: pvr2fb: correct user pointer annotation and sentinel initializer
  • 76818e81cfca fbdev: omapfb: panel-dsi-cm: initialize lock before registering display
  • 2f66f8ceefc2 fat: restore original value when fat_ent_write failed
  • 66aa9a9e6481 fanotify: fix use-after-free of file range info
  • 92895a14329c efivarfs: Rate limit statfs() handler
  • ce568f6e025d ecryptfs: show filename encryption options
  • 9319706316a8 ecryptfs: release message context on send failure
  • b31da1ecf139 ecryptfs: reject too-small tag 70 packets
  • 14cb36a500a5 ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet
  • e5d254e654f2 ecryptfs: pass packet set buffer size to parser
  • 0d9636ecba34 ecryptfs: hold msg ctx list lock when cleaning daemon queue
  • c1bc956a615d ecryptfs: fix tag 11 packet exact-fit size check
  • 98b890563424 eCryptfs: bound the packet-length peek to the user buffer
  • 7ccb94901f38 fs/ntfs3: bound page_lcns[] index by the log record
  • 376ee45659a4 fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()
  • 2d94ffc9d7b5 fs/ntfs3: validate dirty page table on log replay
  • 5333e18e6b42 eventfs: Initialize ei->children and ei->list in init_ei()
  • b2301bdb4b3e HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during teardown
  • 99f3e197920d HID: intel-thc-hid: intel-quicki2c: fix autosuspend cleanup during teardown
  • 72706b44b665 HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer
  • 6fcefe71aeb5 HID: intel-thc-hid: intel-quickspi: validate report size before copy
  • 127de5919820 HID: mcp2221: validate report size in mcp2221_raw_event()
  • c99ba6c234d4 HID: mcp2221: stop device IO before hid_hw_stop
  • 01d9874e84d3 HID: universal-pidff: stop the device when force-feedback init fails
  • 114a58640aaf HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind
  • f3f37b937a6e HID: sensor: custom: Fix field sysfs group cleanup on failure
  • da00eac19fee HID: roccat: free buffered reports when destroying device
  • 471f4a939c66 HID: picolcd: clamp eeprom debugfs read to bytes actually received
  • 79465a30050d HID: corsair-void: Check size of status and firmware events before reading them
  • e78973fe3ef5 HID: apple: preserve keyboard backlight across T2 resume
  • 846f0709559b smb: client: harden DFS cache against invalid target hints
  • 17a1922ada87 smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV
  • 1f824f61d1df smb: client: fix ALIGN() overflow in symlink_data() error context loop
  • 9ab46a13798a smb: client: clear ce->tgthint in free_tgts()
  • 8b9b10fe5b8b cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC
  • c2a0dcb5a7a1 cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
  • 4f18c9e7ee46 cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size()
  • 636a99bab36b audit: avoid dropping live tree ref on fsnotify rule autoremove
  • 25128202a8df btrfs: do not overwrite NODATASUM flag when removing NODATACOW flag
  • f42efd634c0a btrfs: fix extent map leak in NOCOW direct I/O write
  • 8a64baeb5bbb btrfs: drop recovered reloc root refs on recovery failure
  • ec32015a955c ceph: fix leaked inode reference on writeback abort at umount
  • 37d6edb2f03b ceph: do not repeat ceph_trim_dentries() if no progress possible
  • 1dd356310b16 ceph: bound xattr value length in __build_xattrs()
  • 58c2d3e954c1 ceph: bound num_export_targets array for mds info v2/v3
  • c37db86d2b5e ceph: bound MDSCapAuth path and fs_name decode in handle_session()
  • 06fb5e623cdc ceph: bound copied dentry name length in NFS export get_name
  • 4d298880f82c ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
  • fe46746087b5 ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock
  • 00562ccd4e88 libceph: reject buckets with mismatched CRUSH ids
  • 2571b3588326 libceph: validate OSD extent maps before cursor advance
  • b413ec5b23e3 NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup
  • 4804c58f73a8 NFSD: Prevent lock owner use-after-free during client teardown
  • b56d2c5f01cd nfsd: revoke copy-notify stateids before dropping their reference
  • dbc11a12aa54 nfsd: reject reclaim LOCK after RECLAIM_COMPLETE
  • ad02d095439f nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE
  • 54e02f5e32c5 nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops
  • 4ae5d7490ae6 nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd()
  • b57bd8cb739c nfsd: initialize DRC hash table before registering shrinker
  • a4d7fedcaaf3 nfsd: initialize copy-notify stateid before publishing it
  • 763c0bad8723 nfsd: hold rcu across localio cmpxchg retry
  • b3bff820d068 nfsd: gate nfs3 setacl by argp->mask
  • f951b22dbeec nfsd: gate nfs2 setacl by argp->mask
  • 41ebca28e17f nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo
  • 0380129b1373 nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget
  • 4106d7a6aaf1 nfsd: fix version mismatch loops in nfsd_acl_init_request()
  • 9b4e5e9ba5ae nfsd: fix stale s2s_cp_stateids IDR entry for async COPY
  • 2ebbf4e3e9cf nfsd: fix reply size estimate for GET_DIR_DELEGATION
  • cf081015a0d1 nfsd: fix refcount leak in nfsd_file_lru_add on insertion failure
  • 3c5119b799a7 nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs
  • 424d5c95108a nfsd: fix nfsd_file leak on inter-server COPY setup failure
  • 360e1b9e3f31 nfsd: fix netlink dumpit error handling for rpc_status_get
  • 65c79d9bb371 nfsd: fix FL_SLEEP being set unconditionally for all LOCK types
  • c1ae0f973bcb nfsd: fix dentry ref leak on V4ROOT export filehandle lookup
  • a631a26a8777 nfsd: fix cpntf publish race in nfs4_init_cp_state
  • 607a56fea772 nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke
  • 00843074d9b8 nfsd: drop the stateid, not the stateowner, on seqid_op replay retry
  • 72d40b103bb0 nfsd: don't free session slots that are still in use
  • 6703199f4d7e nfsd: defer vfree of compound ops to fix rpc_status UAF
  • 631b7d5dbbba nfsd: defer setting NFSD4_CALLBACK_RUNNING in deleg_reaper
  • e879148867bd nfsd: clear opcnt on compound arg release to prevent OOB read
  • b137930ee52e nfsd: clear CALLBACK_RUNNING on failed delegation recall queue
  • b42dc26a14b4 nfsd: check client ownership when cancelling a copy-notify stateid
  • 311f7d926630 nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref
  • 1aea0482b98e nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry
  • bff024551a71 nfsd: add filehandle match check to nfsd4_delegreturn()
  • 533964d420d3 nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()
  • 895a485cd375 nfsd: validate symlink target length in NFSv4 CREATE
  • 2aca70c18c5f nfsd: validate sockaddr length per family in listener_set
  • 7e7b93da7fa2 nfsd: validate nseconds in TIME_DELEG decode paths
  • 7ff8d6363cff nfsd: size fh_verify server sockaddr slot by xpt_locallen
  • 1e4795766719 nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations
  • 8277d4a11ae2 nfsd: sample writeback error cursor before async COPY loop
  • fc83f30731dd nfsd: return NFS4ERR_NOTSUPP for unsupported netloc4 types
  • 591134e059e3 nfsd: Reset write verifier when async COPY writeback fails
  • 467d56fd3ff5 nfsd: release path refs on follow_down() error
  • f164eb52b6f3 nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown
  • dc803d46a8b9 pNFS: Fix EBUSY check in pnfs_layout_need_return
  • 36e3f13bf072 NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path
  • 59baf45a0643 nfsd: guard nfsd_serv deref in nfsd_file_net_dispose
  • 7ef182a8fe9c NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check
  • 4ed8d2317aef NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock
  • 75d13317f163 NFSD: Fix off-by-one in DRC bucket pruning limit
  • e547b06234f8 NFSD: Encode only the status in NFS-ACL v2 GETACL error replies
  • d8352da19634 NFSD: check truncate permission under inode lock
  • f3adf1643517 NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails
  • 5215e734bf7c NFS/localio: fix ref leak on nfs_uuid_add_file failure
  • 344ae0e232d4 zsmalloc: account for handle size in class lookup
  • 923578d0f0d0 zram: validate deflate params
  • a1dc246f98bb ubifs: fix out-of-bounds read in signature length check
  • 14afe18655c0 phy: rockchip-samsung-dcphy: fix out-of-range max_register
  • e892f05f1f79 PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io()
  • 9253cfc5a85b of: fix out-of-bounds read in of_alias_scan() stem parser
  • 448636c745a3 nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation
  • 8c14472431e2 media: vicodec: fix out-of-bounds write in FWHT encoder
  • 0c260d3f97e5 media: cec: stm32: prevent out-of-bounds write on RX overflow
  • 7d658da725ea lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
  • 9f43499ce645 HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature
  • 827ec385458a fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write
  • 34e88f536146 usb: gadget: f_fs: Prevent deadlock during ep0 read loop
  • 9897b7da8c0a usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()
  • dbe2762ae8e5 usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init()
  • 6bcd9ee6ad69 usb: gadget: f_tcm: fix deadlock in usbg_make_tpg()
  • a15c2acd3083 usb: gadget: midi2: remove default configfs groups on teardown
  • 64005cf3e897 usb: gadget: snps_udc_plat: clean up PHY on probe deferral
  • 4e747c864a88 usb: gadget: u_audio: Fix use-after-free on sound card disconnect
  • 14fa29f3be06 usb: typec: ucsi: use UCSI_TIMEOUT_MS for sync command completion
  • ebb840d982a6 usb: typec: thunderbolt: Disable work before freeing tbt on remove
  • d793bd8422e7 usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive()
  • 12414bbd3e3f USB: phy: fsl-usb: fix missing static keywords
  • 51a311eb97e9 usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed
  • 448e95c0f3ea usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition
  • 316abfe39dce usb: dwc2: gadget: Exit partial power down state when changing USB pull-up
  • 78f5c6e6aef9 staging: greybus: hid: fix SET_REPORT return value
  • 28b932202fcd serial: imx: serialize imx_uart_ports[] lifetime
  • aad08b5f67d2 Revert "media: v4l2-dev: fix error handling in __video_register_device()"
  • e6e925cc1f80 rapidio: mport_cdev: fix use-after-free in dma_req_free()
  • c3d4be91c6fc powerpc/powermac: fix OF node refcount
  • 29e634a18957 misc: nsm: bound the device-reported response length
  • ba69d892ff4e device property: fix infinite loop in fwnode_for_each_child_node()
  • 4cd24873ab9f cdx: Fix double free when sysfs file creation fails
  • b1a49c22de01 tracing: Fix use-after-free with same-name named triggers
  • ddbe921ed16a tracing: Fix use-after-free in trace_pipe read on sub-buffer order change
  • cdb6fb6cf1a7 tracing: Fix logged instance name on creation failure
  • adadf4192f70 tracing: Fix crash passing ERR_PTR to kthread_stop()
  • 25a0758cf6bd tracing/user_events: Clear copied tracing state before fork duplication
  • b503a61d5d39 hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start()
  • 9b51dcb4f230 x86/tdx: Fix zero-extension for 32-bit port I/O
  • c4a221548708 x86/tdx: Fix off-by-one in port I/O handling
  • b9ae969e6f1e x86/locking: Use sfence for wmb() if SSE is available
  • 08b4cdef3c2e x86/insn-eval: Move assign_register() out of KVM as insn_assign_reg()
  • 968eea465942 tools/compiler: match glibc 2.42 definition of attribute_const
  • d4bf3a74e2ba mm: vmscan: fix node reclaim ignoring swappiness parameter
  • 461d23368f29 mm: page_alloc: fix non-movable reclaim storm in defrag_mode
  • d435ba3c21a0 mm: page_alloc: move capture_control to the page allocator
  • 0df04778ea14 mm: page_alloc: __GFP_FS lockdep annotation for direct compaction
  • b3d4b65085ef mm: mempolicy: fix automatic numa balancing for shmem
  • 5d866086d5f8 mm: memcontrol: update state_local when flushing NMI stats
  • 95d87030cae7 mm: memcg: stop reclaim when a limit update is superseded
  • 680b93894ddf mm: memcg-v1: fix memsw and TCP failcnt accounting
  • d0943afb5ed8 mm: memcg-v1: fix wrong linux-mm list address in deprecation warnings
  • 295f5a61d3ae mm: compaction: support non-movable compaction for pageblock requests
  • ef765a2e4f57 mm/zswap: fix global shrinker when memory cgroup is disabled
  • 3fd502399863 mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()
  • 895cd4ecbb2e mm/pagewalk: fix stale walk->action escaping walk_pmd_range()
  • 45489d4f9580 mm/mm_init: deferred_grow_zone(): fix out-of-range first_deferred_pfn
  • 5dc0daff0341 mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()
  • 3fc8044251de mm/kmemleak: avoid soft lockup when scanning task stacks
  • 2cfa9ae90813 mm/gup: fix always draining LRU caches in collect_longterm_unpinnable_folios()
  • d423737dca23 mm, swap: ratelimit bad swap entry reports
  • f2c14f4d427d include/linux/list.h: mark list_add and __list_add as __always_inline
  • 28069434aef6 apparmor: fix out-of-bounds write when null terminating a label vec
  • 587a6a92b93e apparmor: fix cred UAF caused by begin_current_label_crit_section()
  • 753c978f2400 KEYS: trusted: Fix TPM teardown ordering
  • 0a10989de610 rust: kernel: list: fix incorrect pop_back example comment
  • 138722d631ac rust: bug: skip arch-specific asm in testlib builds
  • 2bf5e8f7c9bf timers/itimer: Zero-init old itimerval before copy to userspace
  • e6da8a0f3976 powerpc/pseries/iommu: switch to Default DMA window during kdump
  • c03114634d34 fs: fix user path of nested backing files
  • bf38be01d43c clocksource/drivers/timer-sun4i: Advertise a real minimum delta
  • d53c29a89a15 clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path
  • 312f85fdd029 alpha: don't leak hardware-fabricated FP exception bits to user space
  • c25b2aa077d5 rust: time: fix as_micros_ceil() rounding near i64::MAX
  • 7d00a3ff6244 alpha: fix ieee_swcr_to_fpcr setting FPCR_DNOD unconditionally
  • 4628e40c9ca7 drm/amd/display: Prune per-tile Timing from Apple Studio Display Primary Tile
  • 7d860bed1336 drm/amd/display: hide Apple Studio Display secondary tile
  • c6b915f0df31 drm/amd/display: Refactor amdgpu_dm_connector_detect (v2)
  • a1fa3d1197cc drm/amd/display: Skip PHY SSC reduction on some 8K panels
  • d5c9d19b0ff2 netfs: Fix missing locking around retry adding new subreqs
  • ce493f9261cd platform/x86: lenovo-wmi-helpers: Fix memory leak in lwmi_dev_evaluate_int()
  • 2ab18de5ebb1 drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths
  • 24ebaf6676ae nsfs: tighten permission checks for handle opening
  • ea150ffa9fc9 bpf: Fix incorrect pruning due to atomic fetch precision tracking
  • 5d562153b471 ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS
  • a8bbb2a60513 fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free
  • 5fc3d921512d wifi: ath11k: fix memory leaks in beacon template setup
  • 8527ac1bce87 wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req()
  • c79ef3342632 perf/x86/intel/uncore: Fix die ID init and look up bugs
View originalPermalink
How 6.18.50-xanmod1 went

7.2.3-xanmod1

Changed 3
  • usb: core: Strengthen error handling in hub_hub_status()
  • usb: core: Add lock to usb_wakeup_notification()
  • crypto: krb5: use kfree_sensitive() for derived key buffers
Fixed 12
  • usb: usbfs: fix use-after-free of usb_device in usbdev_release()
  • wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb
  • USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
  • USB: serial: option: fix slab OOB read in interrupt URB callback
  • ALSA: usb-audio: Complete cleanup after system-resume errors
  • ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
Removed 4
  • USB: serial: spcp8x5: drop broken carrier detect support
  • crypto: qce: Remove unsafe/deprecated algorithms
  • crypto: sun8i-ss: Remove crypto_rng interface
  • crypto: sun8i-ce: Remove crypto_rng interface

From XanMod Kernel

  • 3b1e0e296cd6 Linux 7.2.3-xanmod1
  • a981f4bbb87f Merge tag 'v7.2.3' into 7.2
  • 58e7295cfeca Linux 7.2.3
  • 47a7f98fbb50 usb: usbfs: fix use-after-free of usb_device in usbdev_release()
  • e5e8fc11a7ac wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb
  • f24dcc61bd0e USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
  • 3720311fa519 USB: serial: spcp8x5: drop broken carrier detect support
  • d762aef4eba3 USB: serial: option: fix slab OOB read in interrupt URB callback
  • d1f643b1c025 ALSA: usb-audio: Complete cleanup after system-resume errors
  • 1074c2306901 ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
  • 8bf1cdb6d05c ALSA: usb-audio: Fix sample rates for PreSonus AudioBox USB
  • b471594da637 usb: core: Strengthen error handling in hub_hub_status()
  • 7c48aa0c1e79 usb: core: Add lock to usb_wakeup_notification()
  • 29b4f7bc2991 KVM: s390: vsie: zero stale crypto bits
  • 8cbd1539e00d crypto: qce - Remove unsafe/deprecated algorithms
  • 6ef9a4afb52c crypto: mxs-dcp - fix source scatterlist length access
  • 516a830e2f47 crypto: iaa - fall back to software for multi-entry scatterlists
  • 4839f4c21f9c crypto: qce - fix CCM AAD buffer underallocation
  • a1bf79365794 crypto: krb5 - use kfree_sensitive() for derived key buffers
  • 0dd2f638877a crypto: atmel-tdes - use scatterlist length before DMA mapping
  • 8ab58786b4c6 crypto: sun8i-ss - Remove crypto_rng interface
  • 1017f987c5f0 crypto: sun8i-ce - Remove crypto_rng interface
  • 3c7101cfc52e crypto: qcom-rng - Allow zero as a random number
  • 669d940351ed crypto: qcom-rng - Remove crypto_rng interface
  • b1d62624a13c crypto: qcom-rng - Enable clock in hwrng case
  • 1f9f877b1ef1 crypto: virtio - bound the akcipher result length
  • 8b9a857fcf32 kunit: irq: Continue increasing hrtimer interval for longer
  • 9b74e5633687 mm/swap: reject swapon() on filesystem-level encrypted files
  • 68de7f3a38ac netfilter: nf_tables: don't queue packet path object notifications
  • fbfa5944d221 netfilter: nft_set_pipapo_avx2: add missing vzeroupper
  • 4bbc76ee1b21 vxlan: keep the last remote linked during FDB flush
  • 2b46baa591d0 batman-adv: reject unrepresentable multicast TVLV offsets
  • f4be3b391265 ipv6: seg6: clear IPv4 control block on IPIP decapsulation
  • 550d00aa5819 net/packet: defer vmalloc TX_RING free until skbs finish
  • a29f3b884ba5 vlan: fix skb_under_panic and races when toggling HW VLAN offload
  • 57f94d3f4dee net: bridge: mcast: fix use-after-free of a master VLAN's multicast context
  • 3921c573d1ca xfrm: bound nat keepalive state collection
  • be19d20e53a2 xfrm: fix xfrm_state_construct() auth-trunc leak
  • 46640c814f25 xfrm: ah6: validate routing header segments_left
  • a9fa05b7a124 xfrm: avoid lock inversion in nat keepalive work
  • 943d95233b8b xfrm: drop ESP-in-TCP packets with no ingress device
  • 31cf23493619 tcp: clamp route advmss to TCP_MIN_MSS
  • 54b41ad14da9 xfrm: espintcp: fix UAF during close
  • 713ed6ce111e net: advertise TCP MSS from the configured MTU, not the learned PMTU
  • 2857dcbd03cf net/tcp-ao: fix use-after-free of current_key on reconnect to another peer
  • d17e88b6b60f tcp: fix AO info use-after-free in tcp_ao_connect_init()
  • a742178889f9 net/tcp: fix TCP-AO key deletion in VRFs
  • 1e995498d297 gtp: serialize PDP context updates
  • 7e1208c13561 tls: device: fix out-of-bounds write in tls_append_frag()
  • 60e5acbffcd4 KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if CONFIG_KVM_AMD_SEV=y
  • 6d989a0e2df2 KVM: SEV: Mark vCPU RUNNABLE after AP_CREATE, even if VMSA is unusable
  • 68a34115a423 KVM: SEV: Extract loading of guest-provided VMSA to a separate helper
  • 7813da74c6d3 KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests
  • c79c113b299b KVM: SEV: Drop FOLL_WRITE for encrypted region registration
  • 97f6402f5950 KVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts
  • eaa96a8458f5 usb: gadget: f_tcm: keep port count until LUN teardown completes
  • c6e90336ed7d usb: usbtest: disable dynamic ID support
  • e981474d7bf1 fuse: fix invalidate lock leak on open O_TRUNC DAX failure
  • e8457ebfd77a fuse: fix invalidate lock leak on setattr writeback failure
  • 715cb86e33cd fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free
  • a1bb359c443d fuse: publish io-uring queues with release semantics
  • dd9c835709f4 fuse: fix missing barrier when checking io-uring readiness
  • 26fbe4bc3ef3 fuse: fix race between interrupt and resend
  • 57881714412d xhci: dbgtty: Fix unregister on tty_alloc_driver() failure
  • 0e469b94fbba xhci: dbgtty: Fix unregister on tty_register_driver() failure
  • 0b31744f70c5 usb: xhci: bail out of setup if the controller is inaccessible
  • ed3c2adb57b5 usb: xhci: Handle USB3 port events when there is one roothub
  • 87dbc3fa08fc usb: xhci: Handle bogus TRB pointers in Missed Service Error events
  • aa323ccbc0a5 accessibility: speakup: unregister tty ldisc on later init failures
  • 5b2d5447730d fpga: dfl: fme: add error handling
  • 5b4be35d0228 selftests/bpf: Fix test_maps sockmap failure
  • 6e4cf2815587 nvme-tcp: fix usage of page_frag_cache
  • d219e7a8eed3 RDMA/rxe: Fix OOB in free_rd_atomic_resources()
  • 60dfd47929cd RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
  • 52c36105f76e Linux 7.2.2
  • da857e448322 inet: frags: strip GSO state from fragments before reassembly
View originalPermalink
How 7.2.3-xanmod1 went

7.1.13-xanmod1

Changed 4
  • usb: core: Strengthen error handling in hub_hub_status()
  • usb: core: Add lock to usb_wakeup_notification()
  • crypto: krb5: use kfree_sensitive() for derived key buffers
  • crypto: qcom-rng: Allow zero as a random number
Fixed 12
  • usb: usbfs: fix use-after-free of usb_device in usbdev_release()
  • wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb
  • USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
  • USB: serial: option: fix slab OOB read in interrupt URB callback
  • ALSA: usb-audio: Complete cleanup after system-resume errors
  • ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
Removed 3
  • USB: serial: spcp8x5: drop broken carrier detect support
  • crypto: qce: Remove unsafe/deprecated algorithms
  • crypto: qcom-rng: Remove crypto_rng interface

From XanMod Kernel

  • b553b3542801 Linux 7.1.13-xanmod1
  • 43ca95d8926c Merge tag 'v7.1.13' into 7.1
  • 81d3924095fd Linux 7.1.13
  • 7f0278e474c4 usb: usbfs: fix use-after-free of usb_device in usbdev_release()
  • 8d481f935889 wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb
  • 7983daa15998 USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
  • 6bfa6c003d16 USB: serial: spcp8x5: drop broken carrier detect support
  • a72a13c83a65 USB: serial: option: fix slab OOB read in interrupt URB callback
  • 6c94877b6bab ALSA: usb-audio: Complete cleanup after system-resume errors
  • 7f00dbddb51f ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
  • b7c47225d4e2 ALSA: usb-audio: Fix sample rates for PreSonus AudioBox USB
  • 3a607bf79f86 usb: core: Strengthen error handling in hub_hub_status()
  • 960ca456faf6 usb: core: Add lock to usb_wakeup_notification()
  • d4bcd2df6d0d KVM: s390: vsie: zero stale crypto bits
  • 14f8bdfc7ac9 crypto: qce - Remove unsafe/deprecated algorithms
  • 0e9edb108a63 crypto: mxs-dcp - fix source scatterlist length access
  • cec32be0dcbf crypto: iaa - fall back to software for multi-entry scatterlists
  • 46a84efe2dba crypto: qce - fix CCM AAD buffer underallocation
  • 91b96dc9cc25 crypto: krb5 - use kfree_sensitive() for derived key buffers
  • cd4dd09c3d2d crypto: atmel-tdes - use scatterlist length before DMA mapping
  • 143c74034a1c crypto: qcom-rng - Allow zero as a random number
  • 843e2bdaf8de crypto: qcom-rng - Remove crypto_rng interface
  • c3f6dd7ee8b2 crypto: qcom-rng - Enable clock in hwrng case
  • 3fda114a42f1 crypto: virtio - bound the akcipher result length
  • 4df26c3684a0 kunit: irq: Continue increasing hrtimer interval for longer
  • 1b0303ff6ec4 mm/swap: reject swapon() on filesystem-level encrypted files
  • e97e2d6d0b15 netfilter: nf_tables: don't queue packet path object notifications
  • d1893ebc5c85 netfilter: nft_set_pipapo_avx2: add missing vzeroupper
  • 8ba68fd6cdd1 vxlan: keep the last remote linked during FDB flush
  • 1b466746fe10 batman-adv: reject unrepresentable multicast TVLV offsets
  • bf1c1151560d ipv6: seg6: clear IPv4 control block on IPIP decapsulation
  • 0189dce07db2 net/packet: defer vmalloc TX_RING free until skbs finish
  • 3f4752996735 net: bridge: mcast: fix use-after-free of a master VLAN's multicast context
  • 505ac032a97c xfrm: bound nat keepalive state collection
  • 37426395cb90 xfrm: fix xfrm_state_construct() auth-trunc leak
  • 0bf11081ad37 xfrm: ah6: validate routing header segments_left
  • 89ef3a2e1e46 xfrm: avoid lock inversion in nat keepalive work
  • 7911e0236616 xfrm: drop ESP-in-TCP packets with no ingress device
  • 6b8c20bf6192 tcp: clamp route advmss to TCP_MIN_MSS
  • eb3bbf29c723 xfrm: espintcp: fix UAF during close
  • f19186bb71d0 net: advertise TCP MSS from the configured MTU, not the learned PMTU
  • e54ad693eddb net/tcp-ao: fix use-after-free of current_key on reconnect to another peer
  • 284d7fd0eec8 tcp: fix AO info use-after-free in tcp_ao_connect_init()
  • 38a28d5053a4 net/tcp: fix TCP-AO key deletion in VRFs
  • 6df4f05bc299 gtp: serialize PDP context updates
  • cd7e875b8959 tls: device: fix out-of-bounds write in tls_append_frag()
  • 8ee84f9b64fd KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if CONFIG_KVM_AMD_SEV=y
  • 9e2de3ee5720 KVM: SEV: Mark vCPU RUNNABLE after AP_CREATE, even if VMSA is unusable
  • 66c01137350b KVM: SEV: Extract loading of guest-provided VMSA to a separate helper
  • f24ff526fe1b KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests
  • 1c0bc4321d29 KVM: SEV: Drop FOLL_WRITE for encrypted region registration
  • bbd6aa311a9f usb: gadget: f_tcm: keep port count until LUN teardown completes
  • d2e0f9c96551 usb: usbtest: disable dynamic ID support
  • 1d3e701cda2f fuse: fix invalidate lock leak on open O_TRUNC DAX failure
  • dd278d954c0e fuse: fix invalidate lock leak on setattr writeback failure
  • e15f8bcaa5fa xhci: dbgtty: Fix unregister on tty_alloc_driver() failure
  • 33ed35ca6294 xhci: dbgtty: Fix unregister on tty_register_driver() failure
  • bf84c6b02649 usb: xhci: bail out of setup if the controller is inaccessible
  • ff4f51d0fe5a usb: xhci: Handle USB3 port events when there is one roothub
  • 766a3c7dddd9 usb: xhci: Handle bogus TRB pointers in Missed Service Error events
  • 6d39dff1705e accessibility: speakup: unregister tty ldisc on later init failures
  • b6c9ac95dc36 fpga: dfl: fme: add error handling
  • 0f23bfff6033 ext4: zero out whole block for clean edges in WRITE_ZEROES
  • 6cfbf7dea8a8 ext4: track partial-zero outcome per edge in ext4_zero_partial_blocks()
  • 2335e7f2cf44 ext4: write back partial-zeroed edges in WRITE_ZEROES
  • 3cc1c2d5fbd0 ext4: move partial block zeroing earlier in ext4_zero_range()
  • 7e9ff031a5bc ext4: protect WRITE_ZEROES written extents with orphan list
  • 41fab074d4a1 ext4: export converted block count from ext4_convert_unwritten_extents()
  • 30a5b97813db selinux: switch two allocations to use kzalloc_objs()
  • cd998a10d6c9 selinux: require a class's permission values to cover its permission count
  • a7f3d4f22d92 selinux: reject a permission value exceeding the class permission count
  • f1e4513e8f06 selinux: more strict policy parsing
  • 4b53bfa7cb19 selinux: use u16 for security classes
  • 6d810f75a312 Revert "selinux: reject a permission value exceeding the class permission count"
  • 0a9750263ffa nvme-tcp: fix usage of page_frag_cache
  • ec8fcaf354c1 KVM: x86/mmu: Check write tracking in all address spaces
  • 4e5f753e8c28 RDMA/rxe: Fix OOB in free_rd_atomic_resources()
  • d4cd32eb8bd2 RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
  • b66529dc933e bpf: reject overlarge global subprog argument sizes
  • badc4fe5a9c1 Linux 7.1.12
  • 69b73b74d9eb inet: frags: strip GSO state from fragments before reassembly
View originalPermalink
How 7.1.13-xanmod1 went

6.18.49-rt-xanmod1

Changed 3
  • usb: core: Strengthen error handling in hub_hub_status()
  • usb: core: Add lock to usb_wakeup_notification()
  • crypto: qcom-rng - Allow zero as a random number
Fixed 14
  • usb: usbfs: fix use-after-free of usb_device in usbdev_release()
  • wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb
  • USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
  • USB: serial: option: fix slab OOB read in interrupt URB callback
  • ALSA: usb-audio: Complete cleanup after system-resume errors
  • ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
Removed 3
  • USB: serial: spcp8x5: drop broken carrier detect support
  • crypto: qce - Remove unsafe/deprecated algorithms
  • crypto: qcom-rng - Remove crypto_rng interface

From XanMod Kernel

  • f3c8448605b9 Linux 6.18.49-rt-xanmod1
  • 9b47b9fa10b7 Merge branch '6.18' into 6.18-rt
  • 8408b39fb74d Linux 6.18.49-xanmod1
  • 92fbe2fcd8d9 Merge tag 'v6.18.49' into 6.18
  • 1c732c6b94f0 Linux 6.18.49
  • 5f08c45bdcfd usb: usbfs: fix use-after-free of usb_device in usbdev_release()
  • 22edb6786127 wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb
  • b4cb8081cf80 USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
  • 683df50fff0f USB: serial: spcp8x5: drop broken carrier detect support
  • 2ef5560387f2 USB: serial: option: fix slab OOB read in interrupt URB callback
  • 6d3e202670b8 ALSA: usb-audio: Complete cleanup after system-resume errors
  • 91919b3b99ab ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
  • 7eb02825b368 usb: core: Strengthen error handling in hub_hub_status()
  • d80b94680467 usb: core: Add lock to usb_wakeup_notification()
  • 935eeba27601 KVM: s390: vsie: zero stale crypto bits
  • 545a6b9c91e2 crypto: qce - Remove unsafe/deprecated algorithms
  • 182f16a20d32 crypto: mxs-dcp - fix source scatterlist length access
  • 2f65718b9c10 crypto: qce - fix CCM AAD buffer underallocation
  • 731a5b6fb4c1 crypto: krb5 - use kfree_sensitive() for derived key buffers
  • 302ecd110606 crypto: atmel-tdes - use scatterlist length before DMA mapping
  • 4c0018320942 crypto: qcom-rng - Allow zero as a random number
  • 14d9ee828646 crypto: qcom-rng - Remove crypto_rng interface
  • 070b73019a53 crypto: qcom-rng - Enable clock in hwrng case
  • 5545de5050cb crypto: virtio - bound the akcipher result length
  • e90bc78125cd kunit: irq: Continue increasing hrtimer interval for longer
  • 34f3c35dd13a mm/swap: reject swapon() on filesystem-level encrypted files
  • 6fa88d11983c netfilter: nf_tables: don't queue packet path object notifications
  • 07ee91e6b7b0 netfilter: nft_set_pipapo_avx2: add missing vzeroupper
  • a8820c8a7718 vxlan: keep the last remote linked during FDB flush
  • 916ec741e65a batman-adv: reject unrepresentable multicast TVLV offsets
  • 3e4476e58343 ipv6: seg6: clear IPv4 control block on IPIP decapsulation
  • c069f29da723 net: bridge: mcast: fix use-after-free of a master VLAN's multicast context
  • 50229d334558 xfrm: bound nat keepalive state collection
  • cf67361e78dc xfrm: fix xfrm_state_construct() auth-trunc leak
  • 6733ae71268a xfrm: ah6: validate routing header segments_left
  • 5c86c895d1ca xfrm: avoid lock inversion in nat keepalive work
  • 328e40aa774b xfrm: drop ESP-in-TCP packets with no ingress device
  • 24efebecf415 xfrm: espintcp: fix UAF during close
  • 73fde8fe4469 net/tcp-ao: fix use-after-free of current_key on reconnect to another peer
  • 70051a57786d tcp: fix AO info use-after-free in tcp_ao_connect_init()
  • 452774776023 net/tcp: fix TCP-AO key deletion in VRFs
  • b5d1534db32a x86/CPU/AMD: Carve out a Zen5 models range
  • 3d950e98f74a gtp: serialize PDP context updates
  • fadbc1ed2a87 tls: device: fix out-of-bounds write in tls_append_frag()
  • 0b0a668febb6 KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if CONFIG_KVM_AMD_SEV=y
  • 9a45e7b0b140 KVM: SEV: Mark vCPU RUNNABLE after AP_CREATE, even if VMSA is unusable
  • a3d45c2d645c KVM: SEV: Extract loading of guest-provided VMSA to a separate helper
  • 2de20fea6204 KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests
  • dd1638c95163 KVM: SEV: Drop FOLL_WRITE for encrypted region registration
  • 85aa61fedcb4 usb: gadget: f_tcm: keep port count until LUN teardown completes
  • 3f6face69034 usb: usbtest: disable dynamic ID support
  • 776e85fda752 fuse: fix invalidate lock leak on open O_TRUNC DAX failure
  • 1758730d9eaa fuse: fix invalidate lock leak on setattr writeback failure
  • 0f127d522dbc xhci: dbgtty: Fix unregister on tty_alloc_driver() failure
  • 0d0faf3cc44c xhci: dbgtty: Fix unregister on tty_register_driver() failure
  • 45dbddc389c5 usb: xhci: Handle USB3 port events when there is one roothub
  • 56f20a406cc3 usb: xhci: Handle bogus TRB pointers in Missed Service Error events
  • 9786c42df8ef accessibility: speakup: unregister tty ldisc on later init failures
  • 8ec7271e05df fpga: dfl: fme: add error handling
  • 6106fb7962a0 ksmbd: harden file lifetime during session teardown
  • a8e1f970f904 HID: ft260: fix stack-use-after-return write in I2C read race
  • 30c37ac21a45 HID: ft260: validate i2c input report length
  • 8b5debb6252c HID: asus: fix missing hid_is_usb() check
  • d0754db7883c HID: asus: simplify RGB init sequence
  • 70589b0c005d HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
  • e22f4494cc94 io_uring: defer eventfd signaling when queued from a wakeup handler
  • 0bcec5dda029 io_uring/rsrc: improve regbuf iov validation
  • e973a371d35a io_uring: simplify IORING_SETUP_DEFER_TASKRUN && !SQPOLL check
  • 2b7c6b90ce80 io_uring/futex: only mark private futex waits as inflight
  • b61ebb2826ca powerpc/hv-gpci: fix preempt count leak in sysfs show paths
  • f2192741bdfc veth: fix OOB txq access in veth_poll() with asymmetric queue counts
  • 34aef83af724 selinux: switch two allocations to use kzalloc_objs()
  • caacbfb36721 ASoC: nau8821: Cancel pending work before suspend
  • 0599aa23734c riscv: Fix register corruption from uninitialized cregs on error
  • 85dc711f742b bpf: Fix use-after-free in offloaded map/prog info fill
  • 13d20517bee1 ASoC: nau8821: Cancel delayed work on component remove
  • 9ebaeeb6c2d4 selinux: require a class's permission values to cover its permission count
  • dfc59a062c38 selinux: reject a permission value exceeding the class permission count
  • 42c5747a9f83 selinux: more strict policy parsing
  • 4ac3cc8a14db selinux: use u16 for security classes
  • 71ecdc1ba07f Revert "selinux: reject a permission value exceeding the class permission count"
  • 64561afb42d8 nvme-tcp: fix usage of page_frag_cache
  • c0a9bd5fca0b KVM: x86/mmu: Check write tracking in all address spaces
  • 8be5f23ae949 drm/xe/guc_ads: use uncached mapping for UM queue BO
  • a65b52f6cdc9 drm/xe/guc_ads: allocate UM queues in VRAM on dGFX
  • af2d3f6f29b0 drm/xe/guc_ads: allocate UM queues in a separate BO
  • bdf5deccfbf9 RDMA/rxe: Fix OOB in free_rd_atomic_resources()
  • ffa4f0be6965 RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
  • 5bbb9c9f8f80 Linux 6.18.48
  • c49f04e8d2b9 inet: frags: strip GSO state from fragments before reassembly
View originalPermalink
How 6.18.49-rt-xanmod1 went

6.18.49-xanmod1

Added 1
  • add lock to usb_wakeup_notification()
Changed 2
  • strengthen error handling in hub_hub_status()
  • allow zero as a random number in crypto qcom-rng
Fixed 14
  • fix use-after-free of usb_device in usbdev_release()
  • ensure tx headroom in usb_sdio_tx_prepare_skb
  • fix use-after-free in c67x00_add_iso_urb()
  • fix slab OOB read in interrupt URB callback in option driver
  • complete cleanup after system-resume errors in ALSA usb-audio
  • fix OOB write in snd_usbmidi_novation_output()
Removed 3
  • drop broken carrier detect support in USB serial spcp8x5
  • remove unsafe/deprecated algorithms from crypto qce
  • remove crypto_rng interface from crypto qcom-rng

From XanMod Kernel

  • 8408b39fb74d Linux 6.18.49-xanmod1
  • 92fbe2fcd8d9 Merge tag 'v6.18.49' into 6.18
  • 1c732c6b94f0 Linux 6.18.49
  • 5f08c45bdcfd usb: usbfs: fix use-after-free of usb_device in usbdev_release()
  • 22edb6786127 wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb
  • b4cb8081cf80 USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
  • 683df50fff0f USB: serial: spcp8x5: drop broken carrier detect support
  • 2ef5560387f2 USB: serial: option: fix slab OOB read in interrupt URB callback
  • 6d3e202670b8 ALSA: usb-audio: Complete cleanup after system-resume errors
  • 91919b3b99ab ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
  • 7eb02825b368 usb: core: Strengthen error handling in hub_hub_status()
  • d80b94680467 usb: core: Add lock to usb_wakeup_notification()
  • 935eeba27601 KVM: s390: vsie: zero stale crypto bits
  • 545a6b9c91e2 crypto: qce - Remove unsafe/deprecated algorithms
  • 182f16a20d32 crypto: mxs-dcp - fix source scatterlist length access
  • 2f65718b9c10 crypto: qce - fix CCM AAD buffer underallocation
  • 731a5b6fb4c1 crypto: krb5 - use kfree_sensitive() for derived key buffers
  • 302ecd110606 crypto: atmel-tdes - use scatterlist length before DMA mapping
  • 4c0018320942 crypto: qcom-rng - Allow zero as a random number
  • 14d9ee828646 crypto: qcom-rng - Remove crypto_rng interface
  • 070b73019a53 crypto: qcom-rng - Enable clock in hwrng case
  • 5545de5050cb crypto: virtio - bound the akcipher result length
  • e90bc78125cd kunit: irq: Continue increasing hrtimer interval for longer
  • 34f3c35dd13a mm/swap: reject swapon() on filesystem-level encrypted files
  • 6fa88d11983c netfilter: nf_tables: don't queue packet path object notifications
  • 07ee91e6b7b0 netfilter: nft_set_pipapo_avx2: add missing vzeroupper
  • a8820c8a7718 vxlan: keep the last remote linked during FDB flush
  • 916ec741e65a batman-adv: reject unrepresentable multicast TVLV offsets
  • 3e4476e58343 ipv6: seg6: clear IPv4 control block on IPIP decapsulation
  • c069f29da723 net: bridge: mcast: fix use-after-free of a master VLAN's multicast context
  • 50229d334558 xfrm: bound nat keepalive state collection
  • cf67361e78dc xfrm: fix xfrm_state_construct() auth-trunc leak
  • 6733ae71268a xfrm: ah6: validate routing header segments_left
  • 5c86c895d1ca xfrm: avoid lock inversion in nat keepalive work
  • 328e40aa774b xfrm: drop ESP-in-TCP packets with no ingress device
  • 24efebecf415 xfrm: espintcp: fix UAF during close
  • 73fde8fe4469 net/tcp-ao: fix use-after-free of current_key on reconnect to another peer
  • 70051a57786d tcp: fix AO info use-after-free in tcp_ao_connect_init()
  • 452774776023 net/tcp: fix TCP-AO key deletion in VRFs
  • b5d1534db32a x86/CPU/AMD: Carve out a Zen5 models range
  • 3d950e98f74a gtp: serialize PDP context updates
  • fadbc1ed2a87 tls: device: fix out-of-bounds write in tls_append_frag()
  • 0b0a668febb6 KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if CONFIG_KVM_AMD_SEV=y
  • 9a45e7b0b140 KVM: SEV: Mark vCPU RUNNABLE after AP_CREATE, even if VMSA is unusable
  • a3d45c2d645c KVM: SEV: Extract loading of guest-provided VMSA to a separate helper
  • 2de20fea6204 KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests
  • dd1638c95163 KVM: SEV: Drop FOLL_WRITE for encrypted region registration
  • 85aa61fedcb4 usb: gadget: f_tcm: keep port count until LUN teardown completes
  • 3f6face69034 usb: usbtest: disable dynamic ID support
  • 776e85fda752 fuse: fix invalidate lock leak on open O_TRUNC DAX failure
  • 1758730d9eaa fuse: fix invalidate lock leak on setattr writeback failure
  • 0f127d522dbc xhci: dbgtty: Fix unregister on tty_alloc_driver() failure
  • 0d0faf3cc44c xhci: dbgtty: Fix unregister on tty_register_driver() failure
  • 45dbddc389c5 usb: xhci: Handle USB3 port events when there is one roothub
  • 56f20a406cc3 usb: xhci: Handle bogus TRB pointers in Missed Service Error events
  • 9786c42df8ef accessibility: speakup: unregister tty ldisc on later init failures
  • 8ec7271e05df fpga: dfl: fme: add error handling
  • 6106fb7962a0 ksmbd: harden file lifetime during session teardown
  • a8e1f970f904 HID: ft260: fix stack-use-after-return write in I2C read race
  • 30c37ac21a45 HID: ft260: validate i2c input report length
  • 8b5debb6252c HID: asus: fix missing hid_is_usb() check
  • d0754db7883c HID: asus: simplify RGB init sequence
  • 70589b0c005d HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
  • e22f4494cc94 io_uring: defer eventfd signaling when queued from a wakeup handler
  • 0bcec5dda029 io_uring/rsrc: improve regbuf iov validation
  • e973a371d35a io_uring: simplify IORING_SETUP_DEFER_TASKRUN && !SQPOLL check
  • 2b7c6b90ce80 io_uring/futex: only mark private futex waits as inflight
  • b61ebb2826ca powerpc/hv-gpci: fix preempt count leak in sysfs show paths
  • f2192741bdfc veth: fix OOB txq access in veth_poll() with asymmetric queue counts
  • 34aef83af724 selinux: switch two allocations to use kzalloc_objs()
  • caacbfb36721 ASoC: nau8821: Cancel pending work before suspend
  • 0599aa23734c riscv: Fix register corruption from uninitialized cregs on error
  • 85dc711f742b bpf: Fix use-after-free in offloaded map/prog info fill
  • 13d20517bee1 ASoC: nau8821: Cancel delayed work on component remove
  • 9ebaeeb6c2d4 selinux: require a class's permission values to cover its permission count
  • dfc59a062c38 selinux: reject a permission value exceeding the class permission count
  • 42c5747a9f83 selinux: more strict policy parsing
  • 4ac3cc8a14db selinux: use u16 for security classes
  • 71ecdc1ba07f Revert "selinux: reject a permission value exceeding the class permission count"
  • 64561afb42d8 nvme-tcp: fix usage of page_frag_cache
  • c0a9bd5fca0b KVM: x86/mmu: Check write tracking in all address spaces
  • 8be5f23ae949 drm/xe/guc_ads: use uncached mapping for UM queue BO
  • a65b52f6cdc9 drm/xe/guc_ads: allocate UM queues in VRAM on dGFX
  • af2d3f6f29b0 drm/xe/guc_ads: allocate UM queues in a separate BO
  • bdf5deccfbf9 RDMA/rxe: Fix OOB in free_rd_atomic_resources()
  • ffa4f0be6965 RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
  • 5bbb9c9f8f80 Linux 6.18.48
  • c49f04e8d2b9 inet: frags: strip GSO state from fragments before reassembly
View originalPermalink
How 6.18.49-xanmod1 went

7.2.1-xanmod1

Fixed 20
  • ptp: vmclock: prevent read-only mappings from becoming writable
  • futex: Fix might_sleep() warning in futex_pivot_pending()
  • Bluetooth: hci_aml: validate firmware segment lengths
  • Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255
  • Bluetooth: ISO: zero the sockaddr before returning it in getname
  • Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync

From XanMod Kernel

  • 87d7e154ade4 Linux 7.2.1-xanmod1
  • 2112ca3bf8a8 Merge tag 'v7.2.1' into 7.2
  • 458fbaaefba2 Linux 7.2.1
  • 2e596e7814ba ptp: vmclock: prevent read-only mappings from becoming writable
  • 33b959876913 futex: Fix might_sleep() warning in futex_pivot_pending()
  • 2763b8bcb504 Bluetooth: hci_aml: validate firmware segment lengths
  • 6e1c44878aa3 Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255
  • 190b719b787e Bluetooth: ISO: zero the sockaddr before returning it in getname
  • 9f59f461dcae Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync
  • 29c59212a507 Bluetooth: hci_sync: Fix accept list UAF during suspend
  • 6fc540e835dd Bluetooth: hci_event: validate LE Set CIG Parameters response
  • 25b05e3ce31d Bluetooth: hci_event: fix LE list UAF on reset
  • bf05f17b8439 HID: input: read battery capacity from its actual report offset
  • c894143c508a HID: hyperv: validate initial device info bounds
  • f13d0a00204b HID: uclogic: fix use-after-free of inrange_timer on remove
  • 7bb79a3cf45e HID: sensor: custom: Fix use-after-free in enable_sensor
  • 77832d8f1c81 HID: ft260: fix stack-use-after-return write in I2C read race
  • e542edada3f7 HID: core: fix number/pointer type confusion on long items
  • 49b6fd28fbcc HID: rapoo: fix missing hid_is_usb() check
  • 2e0d98dc8a6d HID: nintendo: stop device IO before hid_hw_stop on probe failure
  • 27dc4b8eadac HID: nintendo: register input device after capabilities are set
  • 34725ed4719d HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
  • 9acc2463991c HID: huawei: fix missing hid_is_usb() check
  • ee883906cf66 HID: asus: fix missing hid_is_usb() check
  • ea081b443551 net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
  • 86b63adfa5e1 HID: pidff: fix OOB write when hid->inputs is empty
  • cbcc0e8dea49 HID: core: fix OOB read of field->usage in hid_set_field()
  • 2ef16934e069 HID: magicmouse: do not keep a stale msc->input if no input is claimed
  • 753786a7e6f9 HID: magicmouse: re-enable multitouch after reset-resume
  • d095de37f78c HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
  • 8384a2e1a9ab HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C
  • 56a7b6a6880d nvmet: pci-epf: put CQ ref on create_cq mapping failure
  • cede8d285257 nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work()
  • 9b770e40bc00 nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations
  • d895e66628f9 nvmet-tcp: bound SGL data length before allocating command buffers
  • 94334ea92f4d nvmet-fc: fix invalid free in LS IOD error path
  • 1d6837d98bf9 nvmet-auth: zero the AUTH_RECEIVE response buffer
  • 3256d648211e dmaengine: fsl-edma: Add error handling for devm_kasprintf
  • b233e7836d98 mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()
  • 73a187384a8c ipv6: fix use-after-free in ip6_finish_output2()
  • c8a74adccaf0 ipv4: reject undersized MTUs in ip_do_fragment()
  • 7b079b904691 nfc: nci: free destination parameters when closing a connection
  • d6f743d3d388 nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
  • 129032c0616d nfc: nci: fix out-of-bounds write in nci_target_auto_activated()
  • f5c534b53f8c nfc: nci: add data_len bound checks to activation parameter extractors
  • f33cecf69095 nfc: st21nfca: validate ATR_REQ length against the received frame
  • e95beff58b38 nfc: pn533: purge fragmented skbs during cleanup
  • d3d90243393c nfc: llcp: reject PDUs shorter than the LLCP header
  • 875285a165fd nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
  • 0cfbdb0e13ab nfc: llcp: bound the connect_sn TLV walk to the skb
  • 953963b9ac5e nfc: microread: validate target discovery payload lengths
  • 1aa3fc769b0c nfc: fdp: bound the device-reported read length and fix an skb leak
  • 31aa28ed732f nfc: digital: clamp SENSF_RES length to the destination buffer
  • 4d00a39c6762 xfs: restore nofs context unconditionally in xfs_trans_roll
  • c35da2bac6f7 xfs: validate attr entry pointer before field access
  • 2207f26ce715 ext4: fix incorrect function call when initializing s_resgid
  • e27bae352158 ext4: don't enable DAX on new encrypted files
  • 759830cde824 ext4: propagate errors from fast commit range replay
  • 29c2844d67c5 ext4: avoid tail write_begin walk for uptodate folios
  • f2c382914901 ext4: clear error before retrying inode xattr space fallback
  • fbcfb75c20d7 nilfs2: reject invalid block index in GC ioctl
  • dbd4aea175ad ext4: stop retrying saturated xattr cache entries
  • f8c9a3ec36b4 kcov: fix data corruption and race conditions on PREEMPT_RT
  • a04b3afd4f02 null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows
  • 50f0cbec45b0 ocfs2: fix missing metadata reservation for large xattrs
  • 40b6ccf68731 io_uring: defer eventfd signaling when queued from a wakeup handler
  • 771f6258c068 io_uring/uring_cmd: don't skip completion for a synchronous multishot cmd
  • 3267d7c8ba51 io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec()
  • 1bc9d45ebb81 io_uring/io-wq: fix worker accounting when canceling creation callbacks
  • 7068d3587a64 io_uring/cmd: fix iovec leak when the async cmd is not recycled
  • 690b721b9595 ALSA: dummy: Check card index validity at probe
  • cd4f44ede070 io_uring/futex: only mark private futex waits as inflight
  • d6d24b858b63 io_uring/futex: don't mark futex wake requests as inflight
  • c4b4972d8edc futex: Fix race on the initial mm->futex.phash.ref allocation
  • 25408c62ed4e futex: Avoid private hash use-after-free on final put
  • d7944cee62ec futex/pi: Plug private futex exec() race
  • 72fd9cbbe0cf futex: Sanitize and document task_struct::futex::state transitions
  • 43b148d796aa futex/pi: Reject cross-mm private futex owners
  • 123d664ac98d nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()
  • 2ded89ca77fa rndis_host: add overflow check in rndis_rx_fixup()
  • ecd2f83a4ddc ALSA: scarlett2: Use a private URB for the notification endpoint
  • 6db3c1d7e287 ALSA: FCP: Use a private URB for the notification endpoint
  • ffe6d379be20 iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages
  • 5994617e09ee iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown
  • b405c2f96ae2 Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept
  • 0916948026f6 PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
View originalPermalink
How 7.2.1-xanmod1 went

7.1.11-xanmod1

Fixed 20
  • ptp: vmclock: prevent read-only mappings from becoming writable
  • futex: Avoid private hash use-after-free on final put
  • Bluetooth: hci_aml: validate firmware segment lengths
  • Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255
  • Bluetooth: ISO: zero the sockaddr before returning it in getname
  • Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync

From XanMod Kernel

  • 15d529e612cf Linux 7.1.11-xanmod1
  • 11c2a2475860 Merge tag 'v7.1.11' into 7.1
  • 843fd19fe9a2 Linux 7.1.11
  • 2496e1418271 ptp: vmclock: prevent read-only mappings from becoming writable
  • 12cd315a7b6a futex: Avoid private hash use-after-free on final put
  • 6c7025346290 Bluetooth: hci_aml: validate firmware segment lengths
  • 0bd0195ce257 Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255
  • 9069be87c67f Bluetooth: ISO: zero the sockaddr before returning it in getname
  • 2941716c753a Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync
  • 95bb57bc11a9 Bluetooth: hci_sync: Fix accept list UAF during suspend
  • d83ecb7b9610 Bluetooth: hci_event: validate LE Set CIG Parameters response
  • b55e83a4ba31 Bluetooth: hci_event: fix LE list UAF on reset
  • b81edc5df6b6 HID: input: read battery capacity from its actual report offset
  • 2529737763cb HID: hyperv: validate initial device info bounds
  • f1b3ca063805 HID: uclogic: fix use-after-free of inrange_timer on remove
  • c0757f106105 HID: sensor: custom: Fix use-after-free in enable_sensor
  • d7ffbdc07667 HID: ft260: fix stack-use-after-return write in I2C read race
  • e60159f5ea60 HID: core: fix number/pointer type confusion on long items
  • 99ed3febafe0 HID: rapoo: fix missing hid_is_usb() check
  • 13a3edf96568 HID: nintendo: stop device IO before hid_hw_stop on probe failure
  • a9fc7547f911 HID: nintendo: register input device after capabilities are set
  • d4cabd4089ad HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
  • 66805454c01f HID: huawei: fix missing hid_is_usb() check
  • 1ddc2f5913be HID: asus: fix missing hid_is_usb() check
  • 36e6dc9f9cae futex: Fix might_sleep() warning in futex_pivot_pending()
  • ff252ed45c82 futex: Fix race on the initial mm->futex.phash.ref allocation
  • 19b4be0717fa futex: Fix race in futex_pivot_pending() during private hash resize
  • 0478bc6bf197 futex/pi: Plug private futex exec() race
  • 19702d0396ee futex: Sanitize and document task_struct::futex::state transitions
  • f7fb3e077526 futex/pi: Reject cross-mm private futex owners
  • f3868046e8e2 net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
  • d416eeb7d016 HID: pidff: fix OOB write when hid->inputs is empty
  • 5215ea00a747 HID: core: fix OOB read of field->usage in hid_set_field()
  • 0bf253e9ac99 HID: magicmouse: do not keep a stale msc->input if no input is claimed
  • a8bdd9e22a84 HID: magicmouse: re-enable multitouch after reset-resume
  • a33a596d3ad8 HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
  • dcc8cf9414d1 HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C
  • 6c290915a03f mptcp: pm: fix memory leak from alloc-during-teardown race
  • ab8bae2403a7 mptcp: pm: uniform announced addresses helpers
  • 2c5fca4da0a5 mptcp: pm: rename add_entry structure to add_addr
  • 480560491a72 drm/amdgpu: Allocate coredump ring buffers per ring
  • 4e9b4dee0777 drm/amdgpu: fix recursive ww_mutex acquire in amdgpu_devcoredump_format
  • 26135631ed8e fbdev: serialize mode sysfs access with lock_fb_info()
  • 07f7e46833f7 fbdev: Wrap user-invoked calls to fb_set_var() in helper
  • b5f97fae2503 nvmet: pci-epf: put CQ ref on create_cq mapping failure
  • 1ed1eeaef55c nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work()
  • 7fd6da0f2893 nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations
  • 14dbe37681a6 nvmet-tcp: bound SGL data length before allocating command buffers
  • bb9489f0dce5 nvmet-fc: fix invalid free in LS IOD error path
  • 2dcc9226203d nvmet-auth: zero the AUTH_RECEIVE response buffer
  • 7494a167b958 dmaengine: fsl-edma: Add error handling for devm_kasprintf
  • df5c9816986b mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()
  • 99219c82804f ipv6: fix use-after-free in ip6_finish_output2()
  • 3556beb8ca86 ipv4: reject undersized MTUs in ip_do_fragment()
  • 7eae53335dba nfc: nci: free destination parameters when closing a connection
  • 5bd00c0e1470 nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
  • d7083f41c21b nfc: nci: fix out-of-bounds write in nci_target_auto_activated()
  • cf9d44be50b9 nfc: nci: add data_len bound checks to activation parameter extractors
  • 304f5b414f40 nfc: st21nfca: validate ATR_REQ length against the received frame
  • e7ed2ea5590f nfc: pn533: purge fragmented skbs during cleanup
  • ae5f20f5842f nfc: llcp: reject PDUs shorter than the LLCP header
  • e84cdfdc4a6c nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
  • 22e5177ba119 nfc: llcp: bound the connect_sn TLV walk to the skb
  • dabfa26a208e nfc: microread: validate target discovery payload lengths
  • e5eec121f2c3 nfc: fdp: bound the device-reported read length and fix an skb leak
  • a1ef9bddfbb3 nfc: digital: clamp SENSF_RES length to the destination buffer
  • c457e2c845cc drm/xe: Fix DPT allocation paths.
  • f2db6d8f09e7 drm/i915: Introduce struct intel_fb_pin_params
  • be01fcca9deb drm/i915: Track fence region ID in plane state
  • 504f06fab58e drm/i915/pin: s/dev_priv/i915/ and drop struct drm_device usage
  • b09198cf90cc xfs: restore nofs context unconditionally in xfs_trans_roll
  • 9f92e749fc08 xfs: validate attr entry pointer before field access
  • f09c28b8a212 ext4: fix incorrect function call when initializing s_resgid
  • 3392391b363a ext4: don't enable DAX on new encrypted files
  • 25cb98ef87c0 ext4: propagate errors from fast commit range replay
  • a11dedb18cd0 ext4: avoid tail write_begin walk for uptodate folios
  • 23171304c2ee ext4: clear error before retrying inode xattr space fallback
  • ec6ddf271dfa nilfs2: reject invalid block index in GC ioctl
  • 55ee6533c1db ext4: stop retrying saturated xattr cache entries
  • 22670d1552fe kcov: fix data corruption and race conditions on PREEMPT_RT
  • e7f9b40517f0 null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows
  • a3ccb57086dd ocfs2: fix missing metadata reservation for large xattrs
  • b6bb334b0e93 io_uring: defer eventfd signaling when queued from a wakeup handler
  • 2c937b7488d9 io_uring/uring_cmd: don't skip completion for a synchronous multishot cmd
  • 6b308c37fbeb io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec()
  • 0b0ba5369c26 io_uring/io-wq: fix worker accounting when canceling creation callbacks
  • b290de4d16d7 io_uring/cmd: fix iovec leak when the async cmd is not recycled
  • 3dba0e92e189 ALSA: dummy: Check card index validity at probe
  • 4849afbf11f4 io_uring/futex: only mark private futex waits as inflight
  • b64ad7cedce7 io_uring/futex: don't mark futex wake requests as inflight
  • 2bc1e33ff6a5 nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()
  • be7dc3650f79 rndis_host: add overflow check in rndis_rx_fixup()
  • 04df0232a697 ALSA: scarlett2: Use a private URB for the notification endpoint
  • 5da21a434171 ALSA: FCP: Use a private URB for the notification endpoint
  • d9635e2507dc iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages
  • a94309bb99ea iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown
  • 355bfd57ca4c Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept
  • a199293f3038 PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
  • 0fcf72d06689 xfs: rtsummary scrub should treat rtbitmap corruption errors as an xref error
  • e07800c65537 xfs: add a xchk_ip_set_corrupt helper
  • 56407a61a8bb xfs: don't livelock in scrub on a circular unlinked list
  • 1b744c1bd41f xfs: hoist per-bucket unlinked list check to helper
View originalPermalink
How 7.1.11-xanmod1 went

6.18.47-rt-xanmod1

Fixed 20
  • Fix GRO BIG TCP aggregation validation to properly check criteria
  • Prevent ptp vmclock read-only mappings from becoming writable
  • Fix private hash use-after-free on final put in futex
  • Validate Bluetooth firmware segment lengths in hci_aml
  • Reject HCI_CMD_SYNC with params_len above 255 in Bluetooth MGMT
  • Zero the sockaddr before returning it in Bluetooth ISO getname

From XanMod Kernel

  • 782e1ccebdad Linux 6.18.47-rt-xanmod1
  • 48fc777af830 Merge branch '6.18' into 6.18-rt
  • b260538251f0 Linux 6.18.47-xanmod1
  • 3cefea4ac89f Merge tag 'v6.18.47' into 6.18
  • 7519e95095c9 Linux 6.18.47
  • 3ce832e2bd43 net: gro: properly validate BIG TCP aggregation criteria
  • 5b4f2bec7bea ptp: vmclock: prevent read-only mappings from becoming writable
  • dba60d26e9dd futex: Avoid private hash use-after-free on final put
  • e1534d49a7b8 Bluetooth: hci_aml: validate firmware segment lengths
  • b7d9edcf9fe6 Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255
  • 1f6d1f2611af Bluetooth: ISO: zero the sockaddr before returning it in getname
  • 753af97d8d42 Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync
  • fe93a697a7a9 Bluetooth: hci_sync: Fix accept list UAF during suspend
  • e3f82e8f2a59 Bluetooth: hci_event: validate LE Set CIG Parameters response
  • 39a3afb91be3 Bluetooth: hci_event: fix LE list UAF on reset
  • 608f8fd8c0f7 HID: hyperv: validate initial device info bounds
  • 849e537160bb HID: uclogic: fix use-after-free of inrange_timer on remove
  • 8406d4b69d48 HID: sensor: custom: Fix use-after-free in enable_sensor
  • 1fa1591efd41 HID: core: fix number/pointer type confusion on long items
  • 5efcd7bbfaae HID: nintendo: stop device IO before hid_hw_stop on probe failure
  • 268679f50138 HID: nintendo: register input device after capabilities are set
  • 51cfd1adbe7a HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
  • 942b89f7824f futex: Fix might_sleep() warning in futex_pivot_pending()
  • 86d12b34bafc futex: Fix race on the initial mm->futex.phash.ref allocation
  • fdf538b2e696 futex/pi: Plug private futex exec() race
  • 4da67def9efe futex: Sanitize and document task_struct::futex::state transitions
  • 2b92e5562653 futex/pi: Reject cross-mm private futex owners
  • f303f6a4c909 Input: atkbd - skip deactivate for HONOR ZQC-P
  • 936ea65543da Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard
  • 0ea8f0645401 xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
  • 39fc615e355b net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
  • 4529c03c3da8 HID: pidff: fix OOB write when hid->inputs is empty
  • 9a1d7c5f0d82 HID: core: fix OOB read of field->usage in hid_set_field()
  • ace7fc4d3879 HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID
  • 15b60ade825c HID: magicmouse: do not keep a stale msc->input if no input is claimed
  • 62ec3c591ee8 HID: magicmouse: re-enable multitouch after reset-resume
  • 02a88f8308ae HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C
  • b6baab796d11 ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses
  • 9fe5eebb664e mptcp: pm: fix memory leak from alloc-during-teardown race
  • 6fa2064761ec mptcp: pm: uniform announced addresses helpers
  • 714c6d11acea mptcp: pm: rename add_entry structure to add_addr
  • defc59e74c1b mptcp: pm: use for_each_subflow helper
  • f31650243c1a nvmet: pci-epf: put CQ ref on create_cq mapping failure
  • 20be486d1c22 nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work()
  • 9c95f7e66c62 nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations
  • 6d27199ebe8c nvmet-tcp: bound SGL data length before allocating command buffers
  • 8bce9cd08aae nvmet-fc: fix invalid free in LS IOD error path
  • b26189d28442 nvmet-auth: zero the AUTH_RECEIVE response buffer
  • 23a475ff24d2 dmaengine: fsl-edma: Add error handling for devm_kasprintf
  • 364edaedf412 mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()
  • 3dc98e5fe82d ipv6: fix use-after-free in ip6_finish_output2()
  • d9d1a676b033 ipv4: reject undersized MTUs in ip_do_fragment()
  • f03415030579 drm/xe: Fix DPT allocation paths.
  • 20892d2923e4 nfc: nci: free destination parameters when closing a connection
  • 0d4b5cfab689 nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
  • 2f08dbce3b37 nfc: nci: fix out-of-bounds write in nci_target_auto_activated()
  • 9620a91f8d64 nfc: nci: add data_len bound checks to activation parameter extractors
  • bfcca5f42c9a nfc: st21nfca: validate ATR_REQ length against the received frame
  • 2f5d093194ec nfc: pn533: purge fragmented skbs during cleanup
  • e969e9841005 nfc: llcp: reject PDUs shorter than the LLCP header
  • 2d239590d184 nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
  • e87527b506c4 nfc: llcp: bound the connect_sn TLV walk to the skb
  • d0902a7c4543 nfc: microread: validate target discovery payload lengths
  • db7e464b3509 nfc: fdp: bound the device-reported read length and fix an skb leak
  • a56773e649ea nfc: digital: clamp SENSF_RES length to the destination buffer
  • cb8246e5846d libceph: fix OOB read in decode_watchers() via missing bounds check
  • 184c1a80421a xfs: validate attr entry pointer before field access
  • e0e7f464d6ce ext4: fix incorrect function call when initializing s_resgid
  • 458776af0061 ext4: don't enable DAX on new encrypted files
  • f3d2fa3a9933 ext4: propagate errors from fast commit range replay
  • 5f46f084f74b ext4: avoid tail write_begin walk for uptodate folios
  • fb5980fbe44f ext4: clear error before retrying inode xattr space fallback
  • e447f7edb99b nilfs2: reject invalid block index in GC ioctl
  • 4902a5cba21a ext4: stop retrying saturated xattr cache entries
  • e11f5b48c827 kcov: fix data corruption and race conditions on PREEMPT_RT
  • 164ca33cf536 null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows
  • 6176313622e3 ocfs2: fix missing metadata reservation for large xattrs
  • 15ccf5370985 io_uring/uring_cmd: don't skip completion for a synchronous multishot cmd
  • 45c945107e00 io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec()
  • 4074ae2f1da9 io_uring/io-wq: fix worker accounting when canceling creation callbacks
  • b6a768aa975b io_uring/cmd: fix iovec leak when the async cmd is not recycled
  • f20c2c32ec1c ALSA: dummy: Check card index validity at probe
  • 3da64f2ed902 io_uring/futex: don't mark futex wake requests as inflight
  • 61dc1a37e04d nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()
  • e971d956353d rndis_host: add overflow check in rndis_rx_fixup()
  • 4305e4b52acc ALSA: scarlett2: Use a private URB for the notification endpoint
  • 65aceb45ca91 ALSA: FCP: Use a private URB for the notification endpoint
  • 7596354148c5 iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages
  • d2ab08437e91 iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown
  • d4b1a13b1eff Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept
  • 0c55707bd5d0 PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
  • 159d162fe80b xfs: don't livelock in scrub on a circular unlinked list
  • a05a1b663464 xfs: hoist per-bucket unlinked list check to helper
  • 8d678be8e58e xfs: rtsummary scrub should treat rtbitmap corruption errors as an xref error
  • 00e2baf0b5ea xfs: add a xchk_ip_set_corrupt helper
  • 755d0b7ee356 serial: sc16is7xx: enable THRI before filling TX FIFO
  • c5a12344a043 serial: sc16is7xx: use guards for simple mutex locks
  • 450fe8f6f1f8 serial: sc16is7xx: rename EFR mutex with generic name
  • d3fea146457b Linux 6.18.46-xanmod1
  • 8c0d3dba26dc Merge tag 'v6.18.46' into 6.18
  • 1f99e9ab748f Linux 6.18.46
  • b7ce4b3bc106 ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r
  • 192f44513a03 firewire: ohci: initialize page array to use alloc_pages_bulk() correctly
  • e5e6ce7009a6 drm/vmwgfx: Set surface-framebuffer GEM objects
  • 7e351209dc2f erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms
  • 67ac7e01c26b spi: virtio: mark device ready before registering the controller
  • a7d172b27aa3 drm/log: Fix infinite loop when scale is too large for display
  • a6325e2807dc drm/client: Remove drm_client_framebuffer_delete()
  • 329731b3119f drm/client: Deprecate struct drm_client_buffer.gem
  • 0763282e689e drm/client: Inline drm_client_buffer_addfb() and _rmfb()
  • 60f1a2ecdf8b drm/client: Move dumb-buffer handling to drm_client_framebuffer_create()
  • 841bc853a2b1 drm/client: Remove pitch from struct drm_client_buffer
  • 16a2716910ec drm/log: Fix out-of-bounds read on empty message length
  • 948f346fe36e drm/xe/oa: Fix sync entry leak on OA config emit failure
  • ed5470771c7e firewire: ohci: fix NULL pointer dereference in ar_context_release
  • 384d9f04b38f firewire: ohci: split page allocation from dma mapping
  • adb3e7c26a51 net/sched: cls_bpf: reject dev-bound programs bound to a different device
  • 1f493c44a2f0 accel/amdxdna: Skip unmapped range in aie2_populate_range()
  • 72e4e3d7efc3 net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG
  • 6cf600b276a5 regmap: sdw-mbq: don't call an unset readable_reg callback
  • c27eed546ae2 m68k: Define NR_CPUS to 1
  • 31f26a95eeee net/sched: cls_u32: skip hash tables in u32_bind_class()
  • abceabc4408f net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain
  • 98c5914d6b7b af_packet: Don't send zero-byte data in tpacket_snd().
  • 37c5ccaaacd4 regmap: sdw-mbq: Fix swap of timeout and retry times
  • f51a540b14ee ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers
  • 82d9269f01eb net/tls: Fail tls_sw_splice_read() after a failed async decrypt
  • cef4c5b9aca2 net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling
  • 5ffaa5d7f56a net: tap: fix wrong transport_header when sending VLAN-tagged frame
  • f9297abbcaba net: packet: fix wrong transport_header when sending VLAN-tagged frame
  • 0af3afd054e7 net: phy: realtek: fix EEE advertisement write on the internal PHY MMD path
  • 17e3181d740d tcp: fix icsk_ack.ato bitfield overflow
  • 73f8dd22b1e5 veth: fix queue index used to wake the peer txq in veth_poll
  • 96fa90b74385 macvlan: inherit needed_headroom and needed_tailroom from lowerdev
  • 5f33188457bb ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
  • 1072f0f44282 eth: bnxt: keep the aRFS rmap updated when TPH is enabled
  • 394f1b16c5d1 eth: bnxt: cancel IRQ notifier before freeing affinity mask
  • a26a1be1b654 netfilter: ipset: let destroy callbacks adjust ext mem size
  • 29c011b3537d netfilter: ipset: fix list type element drift bug
  • d9d3050a70ef netfilter: flowtable: publish GC-visible tuple last
  • 4a923fe60939 netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path
  • cb20da33839f netfilter: ipset: fix refcount race between list:set GC and swap
  • 9e75e7da4374 ASoC: tas2781: fix clang build error for goto bypassing cleanup variable
  • 24d0f33f5415 gpio: ml-ioh: share the register lock across channels
  • 7a03413f31c1 perf: Reject exited events as group leaders
  • 6c85d169eeec riscv: ftrace: Fix ftrace_modify_call failure on kprobed functions
  • a3a676495c64 ovpn: finish crypto callback cleanup before peer release
  • a47a080d06ee ovpn: fix NULL dereference when killing missing key
  • 99a18e1d979e crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req()
  • 3e4bf50c9451 crypto: ccm - Set rfc4309 maxauthsize from child
  • d9ecc9787e11 arm64: tegra: Add EL2 virtual timer interrupt for Tegra194
  • a4e340971fe8 NTB: ntb_netdev: Preserve RX queue depth on allocation failure
  • 08437c5156b0 net: ntb_netdev: Introduce per-queue context
  • 2a7d8fc0fd50 ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup
  • 8c685df5c3b2 drm/amd/pm: fix pptable use-after-free
  • 2895aeb4327c drm/amd/pm: adjust the visibility of pp_table sysfs node
  • 7755be923e32 mm/page_table_check: skip special zero mappings
  • 4ae625d16eef ring-buffer: Prevent resizing of persistent ring buffer
  • 54fc67500ad1 ring-buffer: Store bpage pointers into subbuf_ids
  • 27d7fcaf237d ring-buffer: Add helper functions for allocations
  • 2ca6b43edf83 sched_ext: Take cgroup_lock() first in scx_cgroup_lock()
  • f786e6652b93 sched_ext: Reorganize enable/disable path for multi-scheduler support
  • 0907f81536f7 sched_ext: Update p->scx.disallow warning in scx_init_task()
  • 4a7e941ca29a futex: Fix race in futex_pivot_pending() during private hash resize
  • 870f8392b284 can: rcar_canfd: change the initializing flow for clocks and resets
  • 45bf067681ad can: rcar_canfd: Extract rcar_canfd_global_{,de}init()
  • e7a4ca927857 can: rcar_canfd: Use devm_clk_get_optional() for RAM clk
  • f8c8c81707d1 can: rcar_canfd: Invert global vs. channel teardown
  • 562d4befa935 can: rcar_canfd: Invert reset assert order
  • 867aed6a4848 binfmt_misc: don't leak the user namespace when the mount fails
  • 4c8d7595a10a ata: libata-scsi: terminate deferred commands on time out
  • db488d653d89 ASoC: tas2562: Validate values for volume writes
  • 5f0a99ea7212 KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs
  • ef60eca789ee userfaultfd: wait on source PMD during UFFDIO_MOVE
  • ea563ed2b10a mm: replace pmd_to_swp_entry() with softleaf_from_pmd()
  • 54a09573eb44 fs/proc/task_mmu: refactor pagemap_pmd_range()
  • 549148d5aa4e btrfs: zoned: fix missing chunk metadata reservation
  • 58ae8b7e8dc8 btrfs: remove fs_info argument from btrfs_zoned_activate_one_bg()
  • d9e9753dfd43 ksmbd: validate minimum PDU size for transform requests
  • 15a2fedb5dff smb/server: fix minimum SMB2 PDU size
  • 23d34ce11885 smb/server: fix minimum SMB1 PDU size
  • 5649004f7161 ksmbd: rename smb2_get_msg to smb_get_msg
  • 29dbb4e29e1f ksmbd: Fix to handle removal of rfc1002 header from smb_hdr
  • df3cf61adbe6 smb/server: rename include guard in smb_common.h
  • 9d154c3c0f5d smb: move get_rfc1002_len() to common/smbglob.h
  • 8ddc2eb0d2da net/sched: serialize qdisc_rtab_list against concurrent get/put
  • 89df5d71f83f libceph: fix two unsafe bare decodes in decode_lockers()
  • 590b07ceea13 libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
  • 89a50fb32d69 libceph: Amend checking to fix make W=1 build breakage
  • a3bc6b3e9ef3 ceph: fix hanging __ceph_get_caps() with stale mds_wanted
  • 79d95b43ca09 ceph: avoid fs reclaim while using current->journal_info
  • bb13785d5499 xfs: check v5 superblock features early
  • 04228b8ba196 xfs: check xfarray iteration errors when committing unlinked inode lists
  • 33b56c6c465a xfs: don't ignore runtime errors in xrep_iunlink_reload_next
  • 38a4dbe588bd xfs: don't swallow dquot recovery verification errors
  • 0f27b22343b6 xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN
  • cd1f876d1bc2 xfs: avoid UAF on sc->tempip in xrep_tempfile_create
  • e75150d494dc xfs: don't return EFSCORRUPTED when scrubbing corrupt parent pointers
  • b6baf0db357f xfs: fix another iunlink infinite loop bug in online fsck
  • fc7d8a5c5fcc xfs: fix allocated inodes that show up in the unlinked list
  • c36d7f68f1c2 xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair
  • 73ffd2620df3 xfs: don't zap the attr fork on repair when there are queued pptr updates
  • 514a5d42d418 xfs: fix ilock leak on error in xfs_dq_get_next_id
  • 9680b1929d89 xfs: load next_agino from the correct xfarray in xrep_iunlink_relink_prev
  • 8b52fa8fb3ab xfs: nlink scrub must take IOLOCK before determining ILOCK state
  • 7d1d82c463e2 xfs: pass runtime errors from xrep_iunlink_mark_ondisk_rec up to callers
  • ab4e13337076 xfs: set the prev pointer when reinserting an inode on the unlinked list
  • ce2a7006ec5e xfs: don't double-lock when deleting a self-referential directory
  • 983588e756a3 xfs: only check mergeability of bnobt records
  • 62c0b1435dfe xfs: zero i_nlink before repair puts inode on unlinked list
  • a9114c6d4ec2 xfs: fix transaction block reservation in xrep_rtbitmap
  • 90a49b8fcf82 xfs: check cowextsize in xrep_inode_cowextsize
  • 069c0eadc8df xfs: clear zapped attr fork state when bmap repair finds no attr fork
  • aeadf3fd2dc3 xfs: mark nonzero sb_gquotino as corrupt on metadir filesystems
  • f8288214459e xfs: bounds-check buffer log item's dirty bitmap
  • 8a0ecae2ecda xfs: fix off-by-one in rtrefcount btree root level validation
  • ec19cea4ef1c xfs: propagate errors from xfs_rtginode_load
  • 71aa45f7bfe4 drm/amdgpu: disallow multiple FENCE chunks in one submit
  • 25ee120f3803 drm/amdgpu: Fix UVD decode image min size calculation
  • 38914cb2c6af drm/amdgpu: Fix UVD dpb min size calculation for H264
  • c76e5cca0675 drm/amdgpu: Fix UVD min buffer sizes
  • 86a5cb020322 drm/amdgpu: Implement insert_end for VCE 3
  • 339deb76ee48 drm/amdgpu: Reject UVD message with dimensions above 4096
  • 220aa2589d73 drm/amdgpu: validate GEM_CREATE domain combinations
  • a082bd76c5f2 drm/amdgpu: check ASPM on the dGPU host link
  • 916e8a1550be drm/amdgpu: fix nbif 6.3.1 l1 low power not functional
  • e304c3e0d9ce drm/amdgpu: Reject UVD message with invalid number of h265 refs
  • e3e6a631dcb1 drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE
  • cd99fa1cbaf5 drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix
  • 5045fb4c70bf drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank()
  • 95c1de6923b0 s390/zcrypt: Fix CPRB memory allocation in zcrypt misc code
  • 7902be374cbf s390/vfio_ccw: Implement a crw lock
  • 3b224d3c50a3 s390/vfio_ccw: Calculate idal length based on idaw type
  • b6aecea4b2b2 s390/vfio_ccw: Selectively expand io_mutex
  • af1759d8e6e6 s390/vfio_ccw: Move cp cleanup out of not operational
  • 4c2e1d359d7a s390/vfio_ccw: Fix out of bounds check on CCW array
  • 08ef2a821156 s390/vfio_ccw: Ensure first IDAW remains constant
  • 649badf3a2fd s390/vfio_ccw: Ensure index for read/write regions are within range
  • b7ae0f799386 s390/vfio_ccw: Cancel existing workqueues
  • 06f4d6e5a8af s390/vfio_ccw: Limit the number of channel program segments
  • 32e3d364a7b8 s390/vfio_ccw: Free all memory if cp_init() fails
  • 45aa38567c79 eth: bnxt: make sure we populate the qcfg defaults on old FW/HW
  • 0382ed41c664 eth: bnxt: always set the queue mgmt ops
  • 31ef57083e78 drm/radeon: fix autosuspend cleanup during teardown
  • 361114857813 drm/xe: Fix xe_device_probe() failure
  • 7b90db6f024b drm/xe: Order ring writes before ring tail updates
  • 198b4a89b903 pmdomain: mediatek: Fix mt8183 hang on boot
  • 8f7f7a6d5aed mmc: loongson2: Fix sg iteration in data reorder functions
  • e5b527804a1e drm/connector/hdmi: Fix out of bounds memory read
  • b5060ff2f546 mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition
  • 78e59ab34337 pmdomains: mediatek: Avoid setting RTFF's CLK_DIS before NRESTORE
  • 7c0d1767ce46 mmc: sdhci: make tuning_err a signed int
  • 970b9c83a07c pmdomain: mediatek: fix remaining %pOF after of_node_put()
  • 36d1b69c5c69 mmc: sdhci: unmap the bounce buffer before device release
  • 0418b7ed2c1c mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit
  • b37e84280045 libceph: tolerate addrvecs with multiple entries of the same type
  • 4490fad7992a ceph: fix MDS random selection readiness predicate
  • 4f392fec0755 libceph: Avoid using invalid osd indices from primary_temp
  • f3854719fba9 Input: sur40 - fix V4L error path cleanup
  • 5c1c5227c93f Input: sur40 - fix input device registration ordering
  • a88d688be8d7 openrisc: signal: do not restore privileged SR bits on sigreturn
  • f634598e8fb7 ftrace: Fix off-by-one fentry site disable in ftrace_free_mem()
  • f8fe843a9634 ftrace: Protect direct_functions in ftrace_find_rec_direct
  • d1bba38574d0 libceph: fix multiple unsafe decodes in decode_locker()
  • ebdecef6fd84 pmdomain: arm: Fix -EINVAL from scmi_pd_set_perf_state() on state 0
  • bc7934d0acd4 gpio: ml-ioh: use raw_spinlock_t for the register lock
  • 9e678cffc11c gve: fix zero-length skb frag with header-split
  • bd4e5a97edf8 selftests/ftrace: Convert ELF entry point to file offset in uprobe test
  • 23e9f32c0c7d gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind
  • e9482feeed66 gve: fix NULL dereference due to missing ptp adjfine
  • a134e4b8102c crypto: qce - fix error path in devm_qce_register_algs
  • ef92c0ad0268 crypto: starfive - use scatterlist length before DMA mapping
  • 38e7d5c1ade0 Input: hynitron_cstxxx - validate touch count and finger IDs
  • 70f9aad39435 Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue
  • ff0849705d29 Input: synaptics-rmi4 - block s_input when F54 queue is busy
  • 6b06aab79ff1 Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer
  • b28593a05afd Input: synaptics-rmi4 - zero report size on F54 work error
  • 828a8d1a9107 powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak
  • 2bdec532202b powerpc/pseries: lparcfg - fix kbuf[] underflow
  • 8dbfd8e32a13 Input: byd - synchronize timer deletion before freeing private data
  • a64a8b6b31cd Input: iforce - validate input packet lengths
  • e7b8a107ecad Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard
  • 8d622c58205a Input: psxpad-spi - set driver data before use
  • 83c265bfc084 Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet
  • 9b184c8337c6 Input: synaptics-rmi4 - fix F55 transmitter electrode count typo
  • 652e952850d9 powerpc/pseries: pci - logic bug
  • 52a818c586ae Input: cs40l50-vibra - validate custom data from user space
  • 455dbb5bdd81 Input: xpad - add support for ZENAIM LEVERLESS
  • 6635d544bd6b ASoC: SOF: topology: Use acpi mach from the machine driver
  • bcc66461f574 drm/amdgpu: fix aperture iounmap skipped on device removal
  • dffacbe8118f drm/amdgpu: fix JPEG v4.0.5 queue reset failure in DPG mode
  • e45356f6adae drm/amdgpu: fix JPEG v5.0.0 queue reset failure in DPG mode
  • 4550b90bd2e6 drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12
  • 1474f3970d1a drm/amdgpu: reject oversized IBs with per-ring packet limits
  • 25556a46ae6e drm/panthor: skip zero-sized firmware sections
  • 7ff87a01ae3a fbdev: core: Fix pointer desynchronization in fb_io_read()
  • 2fe7a89b2b5b ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses
  • cc61f0fa2c71 ASoC: cs35l41: sort the register default table
  • 3298f13d1f12 ASoC: cs35l45: sort the register default table
  • d7bd683b0d90 ASoC: cs4265: sort the register default table
  • f2435a46dfa1 ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout
  • 8cba53b862e1 ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked()
  • a30836477479 s390/qeth: validate user buffer length in SNMP and ARP query ioctls
  • 75e564b2ced1 mptcp: fastopen: only mark MPTFO subflows with SYN data
  • 3f8e5eb0c499 mptcp: pm: fix data race in add_addr timer callback
  • 1fade1b2ac5b mptcp: options: reset DSS fields in case of unexpected size
  • a04dcc784959 mptcp: avoid combining some incoming suboptions
  • 0cb3846c26c1 selftests: mptcp: join: mark tests with data corruption as failed
  • 473f1a5ab2ab mptcp: reclaim forward-allocated memory on RX path errors
  • 9b46fba7528f selinux: reject a permission value exceeding the class permission count
  • 841aea4d5a25 selinux: reject an unclaimed class value in security_get_classes()
  • 1b4ff94ae7c5 selinux: do not cancel a policy conversion that never started
  • acd5b09be98f selinux: reject a class permission count below its inherited common
  • 42a7107f99d8 selinux: require every boolean value to be defined
  • 1a4c3ffe2a48 ipvs: separate destination availability state
  • 9ff46bf75bfa ubi: fastmap: fix ubi->fm memory leak
  • 075036cea14a mtd: ubi: skip programming unused bits in ubi headers
  • bb03b56d1d75 block: stop the timeout timer when releasing a never added disk
  • e2c3337c2238 ALSA: hda/realtek: Add quirk for HP Dragonfly Folio G3 2-in-1 (103c:8a05)
  • e1e49f488a1c Linux 6.18.45-xanmod1
  • 474774fc02c5 Merge tag 'v6.18.45' into 6.18
  • bf3be28f6721 Linux 6.18.45
  • 1eb0dc458b6e netfilter: flowtable: ensure sufficient headroom in xmit path
  • 99ec511f258e netfilter: always set route tuple out ifindex
  • 9977321835c7 thunderbolt: Fix bandwidth group reservation indexing
  • 40d2ffb74094 thunderbolt: Bound the DROM dual link port number before indexing sw->ports
  • ca33df36aa01 sctp: clear new_transport when removing a peer
  • 07daf4f97501 sctp: fix use-after-free of cached ASCONF chunk
  • 2b3b5eec8b2c sctp: keep chunk->transport in step with the list it is queued on
  • 3bd46d33e3fd scsi: scsi_debug: Negate wrapped memcmp() result
  • a14e4ef1d90c bpf, sockmap: Fix sk_redir use-after-free in send verdict
  • 3c6d4ffa0c6d fsverity: Fix silent truncation in bpf_get_fsverity_digest()
  • 2a5cfcad1d56 fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions
  • 4917e3ebcab5 mm/filemap: __filemap_add_folio() restore index before retrying
  • dd21c96a71e8 ima: Instantiate file_truncate and path_truncate hooks
  • 102fb2dacf45 sched/psi: Create the psimon kthread outside of cgroup_mutex
  • 8037c5b2b2a4 sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
  • 653e888a24c8 fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()
  • 4eb15c465337 ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
  • 3b2231e358d2 ipv6: fix Route Information option length validation
  • 7f740664aec1 mm/ptdump: always stabilise against page table freeing using init_mm
  • 5b926fb04cb9 ring-buffer: Use current_context for safe per-CPU buffer swap
  • 2e37f2bf1114 ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer()
  • 5fd91dd4a143 ptp: ocp: Fix board ID over-read
  • 8d34019d1413 Revert "thermal/drivers/hwmon: Cleanup coding style a bit"
  • 5635211b4496 eventfs: Fix use-after-free in eventfs_remove_rec()
  • 66bc868a33cf KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page
  • 47976eaaf0a4 KVM: SVM: Serialize accesses to the owner and mirror list with separate lock
  • 1ffacbadc145 smb: client: Fix use-after-free in cifs_try_adding_channels()
  • c3f2347a4775 tipc: read le->link under the node lock in tipc_node_link_down()
  • 3fc5044796dd tls: don't leave a full plaintext sk_msg ring unpushed
  • 68787940274e tls: rx: restore msg_iter before TLS 1.3 optimistic retry
  • f1e21108e3dd vhost: reset the vring metadata cache on vring reconfiguration
  • cdf745b7a777 veth: fix skb length accounting after XDP frag adjustment
  • 38c7763fdc53 vsock/virtio: avoid refilling the RX queue after teardown
  • bd43a7ec668b vsock/virtio: read virtqueues under worker locks
  • 46bb297ad776 vxlan: do not arm the ageing timer on a device that is down
  • fab820f1691a xdp: reject clones that overrun skb_shared_info tailroom
  • e708fc1566eb x86/mce: Set up the polling timer before CMCI discovery
  • 846b92e26c8a x86/CPU: Add a tlbi= cmdline switch
  • 69298af46f39 arm64: remove redundant concurrent ptdump UAF mitigation
  • fe79571f4043 dibs: initialise dibs->lock in dibs_dev_alloc()
  • a2e326c52c4b Revert "drm/amdgpu: fix aperture mapping leak"
  • 24e95a24f151 binfmt_misc: don't warn when the mount is completed from another user namespace
  • be161fa31e3e ovl: don't warn when the mount is completed from another user namespace
  • 92f00f1d4d20 net/sched: act_gact, act_police: range check the fallback control action
  • b47bb899e04b net/sched: act_ct: fix sk_buff leak when the header checks reject a packet
  • 782cc40b7ade net: atlantic: free RX pages of consumed but not refilled buffers
  • b13202d401e1 net: atlantic: free stranded TX buffers on ring deinit
  • 0424186d570a netfilter: nf_conntrack: defer invalid log until after unlock
  • c58d34fe8b7e netfilter: bridge: release template ct on non-IP path
  • e9bfe12b1d04 net: devmem: prevent net-iov / page mixing
  • 4bc522b33438 net/x25: fix use-after-free of the socket by its timers
  • ece6426b6124 net/dibs: Correct freeing of dmb_clientid_arr
  • 680fbd794218 ipv6: prevent in6_dev_get() from resurrecting inet6_dev
  • 0b7d54cedea5 net: smc: fix splice entry lifetime imbalance in smc_rx_splice
  • b65c11bc6221 net: phy: mediatek: fix TX blink masks using the RX bits
  • 105d04edbec8 mm/huge_memory: fix huge_zero_pfn race
  • 152a00440dc6 tracing: Fix NULL pointer dereference in module event cache removal
  • 62978cf63479 ring-buffer: Prevent subbuf order change when resizing is disabled
  • bc9db0d879c6 fbdev: bitblit: bound-check glyph index in bit_cursor()
  • ed49684e69f8 tracing: Fix race between update_event_fields and, event_define_fields
  • a979a642402d perf/core: Fix group leader use-after-free after sibling detach
  • 5884851a096d drm/v3d: Serialize the scheduler timeout handlers
  • 7779249561d1 ALSA: us144mkii: re-anchor capture URBs on resubmission
  • a6b79dff1cc1 ALSA: hda/tas2781: fix ACPI reference handling
  • bb30e35c36ed ALSA: FCP: fix OOB write in fcp_meter_ctl_get()
  • f75d6f61f0d9 ALSA: usx2y: bound the hwdep mmap fault offset
  • d217d723c5e4 ALSA: usb: Fix UAF at delayed release of MIDI2 EPs
  • 976da5475472 mm/damon: adjust isolated pages stat for DAMOS_MIGRATE_{HOT,COLD}
  • e16b8d640ec9 samples/damon/mtier: error out for zero quota goal target values
  • 460181e4bb47 mm/damon/ops-common: putback folios on invalid migrate nid
  • 6dd7a06894d6 ring-buffer: Fix crash passing ERR_PTR to kthread_stop()
  • 688c71bed685 misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free
  • af6345159abc misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke
  • 9bf22a7d950c misc: fastrpc: Remove buffer from list prior to unmap operation
  • c5a03c2cadd2 misc: fastrpc: fix channel ctx ref leak when session alloc fails
  • cd02b9386315 misc: fastrpc: Fix initial memory allocation for Audio PD memory pool
  • 8b3e4ed9c35d staging: rtl8723bs: validate monitor transmit frame lengths
  • a28a4b0592e4 staging: rtl8723bs: fix missing shared-key auth challenge length check
  • e5b7610008f4 staging: rtl8723bs: fix OOB read in WMM_param_handler()
  • e167a38a8a8f staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()
  • 5974cb66681e serial: amba-pl011: synchronize DMA teardown
  • 759ead98a39f serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ
  • 2a0ee25f75cd serial: amba-pl011: fix indefinite RS485 post-send delay
  • 3ce24bc4d115 serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx
  • ae05d9e50b6b serial: 8250_dma: Clear stale RX state on shutdown
  • 1c31e2377f4c serial: qcom-geni: fix TX DMA buffer flush
  • dd6946a70ddb rust_binder: do not query current thread for all ioctls
  • 9dbe1d011189 nvmem: layouts: Add fixed-layout driver
  • da59844f561d nvmem: apple-spmi-nvmem: wrap regmap calls to satisfy CFI
  • 104c2e8b8e38 mei: pull kvfree out of spinlock
  • 63996ffc594d ipv4: fix use-after-free in fib_nhc_update_mtu()
  • a59edda6eda1 ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops
  • 94166072975a selftests/bpf: Adapt sockmap update error handling
  • edee58a9c460 selftests/bpf: Ensure UDP sockets are bound
  • dc0c462fa838 Bluetooth: btusb: Add TP-Link UB600 for Realtek 8761BUV
  • 373d425f7638 Bluetooth: btrtl: fix RTL8761B/BU broken LE extended scan
  • 8545f4ef9eae netfilter: nf_tables: avoid softlockup warnings in nft_chain_validate
  • 7b8c53263f88 futex: Prevent robust futex exit race some more
  • cf8a9672fc25 iommu/vt-d: Gather the unmapped range before freeing its page tables
  • 643b410bdfa4 dt-bindings: crypto: qcom,ice: Fix missing power-domain and iface clk
  • 8d817ef1aa4e KVM: s390: pci: Fix aisb calculation
  • cf895cd72e40 blk-mq: reinsert cached request to the list
  • 97e2d08de282 blk-mq: pop cached request if it is usable
  • 59b07ccca4c0 Revert "drm/amd/display: Fix backlight max_brightness to match exported range"
  • 5912cf1822fb net: bridge: mrp: fix uninitialised bytes on the wire
  • 47a119ec8a7e netfilter: ebt_nflog: pin the NFLOG backend
  • a0e76de6a2f2 igc: fix netdev not re-attached after resume if interface is down
  • e6cd416a899e mac802154: fix netdev use-after-free in beacon worker
  • 9f904dd3e455 inet: frags: publish queues before arming timer
  • dbb30dc943a9 net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header
  • 99ae2239069e net: octeontx2-pf: Fix UB in shift operation
  • a4b14a4df29d net/sched: reject overly deep qdisc hierarchies
  • 23716dd9d8d4 net: openvswitch: reallocate update replies for mismatched IDs
  • 5f30f9c302ce net: fix skb length accounting after generic XDP frag adjustment
  • 2c7b5eb87b2b packet: synchronize pressure clearing with ring reconfiguration
  • 971aa7d99242 net/packet: reset the MAC header on the packet-socket transmit path
  • 27e068d1b35d packet: use consistent hard_header_len in TX_RING send path
  • 5bb10753d428 packet: use consistent hard_header_len in non-ring send paths
  • 75eec935444d ipvs: clear IPv4 options after rebasing tunnel ICMP errors
  • 0f88fe0552be ipvs: properly update the overload flag on dest edit
  • 59b90c17bec5 ipvs: add totalconns for dest
  • e7f34f29b330 ipvs: stop estimator after disabled calc phase
  • 27f392406159 ima: fix out-of-bounds read in xattr_verify()
  • c5bf8cd148cf mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF
  • bd3c4108a56d Input: evdev - fix information leak in evdev_pass_values()
  • b664592e9ba8 vt: stabilize tty reference in kbd_keycode with tty_port_tty_get
  • a1c31e026c93 vt: add permission check for KDSKBMETA ioctl
  • 2c7496124e94 net: usb: ipheth: fix carrier_work UAF on disconnect
  • 58733b1dd46b net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()
  • d328fdc607fa usb: gadget: f_ncm: Use unsigned int for ndp_index
  • 2dfefdd498ab usb: cdnsp: fix incorrect endian conversions for APB timeout register
  • 6e4c09bea8e9 thunderbolt: icm: Preserve USB4 proxy data-valid bit
  • 2f73a065791d usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
  • ebfd1e82ab0a usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg
  • 04b71290fb41 usb: quirks: Add ShanWan gamepad to quirk list
  • 1740fd2aaa8f usb: core: Add quirk for 255-bytes initial config read
  • 0a235379825e ALSA: usb-audio: fix OOB write on Type II inbound URBs
  • 4034ef247a9d Input: evdev - sanitize event type index when fetching event masks
  • 8b444b126cd8 net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp()
  • fad7cecb5c2c net: fec: do not release NULL pages when RX buffer allocation fails
  • c768fb2e43c8 hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt
  • de58b90a4d14 hwmon: (ltc4282) Clamp negative current limits
  • 124bd4b00619 hwmon: (ltc4282) Avoid overflow in maximum power calculation
  • 678a76c8fd33 hwmon: (ads7828) Fix external VREF regulator handling
  • 5ee1f603a64b hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination
  • 29fe74c9aa69 watchdog: at91sam9_wdt: prevent timer rearm during teardown
  • 6d1d3ca6c8f4 tls: don't abort the connection on signal-interrupted sends
  • 18d704bdd809 sctp: clear control chunk transport if it is being removed
  • 9f77c1ab3821 net/atm: fix slab-out-of-bounds read in vcc_setsockopt()
  • fc3021284050 s390/ism: Fix UAF of sba and ieq during ism_dev_exit()
  • 8fa684db8709 bnge: Fix resource leak in bnge_init_nic() error path
  • a837deeaa37c ata: pata_sl82c105: fix bridge revision use-after-free
  • 4dd71cb0d23d net: thunderbolt: Tear down DMA paths before stopping the rings
  • 78e5ebcd1c10 net/smc: fix TOCTOU race between smc_listen_out() and listener close
  • c8f256dc8492 net: remove WARN_ON_ONCE() from sk_mc_loop()
  • 363e048a9d0a net: prestera: validate firmware header length
  • 02226af69362 net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length
  • 12afa450a6a6 netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()
  • 25d40cf9dab1 netfilter: flowtable: consolidate xmit path
  • a66e869cf0c9 tcp: fix TFO max_qlen accounting across reuseport migration
  • 6c24ec01fb76 sctp: fix addip_serial increment on ASCONF_ACK allocation failure
  • 1e8f24b1e3fe bnxt_en: Fix PTP PPS setting bug
  • aab3b5f4d8ec bnxt_en: Disable EOP for TPA on all chips to prevent data corruption
  • 6a2e50924e57 bnxt_en: Refresh VNIC default ring on queue restart if needed
  • f1a4e95e296b bnxt_en: Determine and store default RX ring in vnic structure
  • 965c45be24e1 bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss()
  • 88664c48d7d1 net/mlx5e: fix BQL reset on SQ re-activation
  • beb47092fe8f bnge: use int for bnge_fix_rings_count() return value
  • 4901b23b5ca7 net: stmmac: resume PHY before hardware setup when opening the interface
  • 99b7bcee0158 selftests/ftrace: refactor eprobes test to fix argument checks
  • a7a00ecf5424 hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations
  • 2e5ea8272cea hwmon: (nzxt-smart2) Check return value of init_device() in probe
  • 9fccf43f0531 drm/xe/uc: Apply RCS/CCS yield policy to SR-IOV VFs
  • d6222af7274f net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers
  • a8139285c892 net/openvswitch: check Ethernet header length in key_extract()
  • a06e4611d455 vhost-scsi: reject feature changes after endpoint
  • 2417a498cf3f vhost-scsi: Validate T10 PI scatterlist counts
  • cd2f1d9fe8a5 net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter
  • 64d322c28857 udp: fix potential use-after-free in tunnel segmentation
  • 5fd121971912 xsk: validate metadata when processing requests
  • 1a1534cc3b41 xsk: move xsk_tx_metadata_request() to xdp_sock_drv.h
  • af511afa1d29 xsk: validate launch-time metadata size
  • 0ba2e1eb07a8 xsk: clear metadata pointer when no timestamp is requested
  • 5ec4f525373b xsk: pass TX metadata pointer by reference
  • 642c6e73fce1 xsk: require at least 16 bytes of TX metadata
  • b0b7202f751b bnxt: fix memory leak in bnxt_queue_mem_alloc error cases
  • ad9ffc61fafe eth: bnxt: support qcfg provided rx page size
  • cd5485a702ef eth: bnxt: store rx buffer size per queue
  • 9c1406e2ecd2 net: pass queue rx page size from memory provider
  • b3fecb888e94 net: add bare bone queue configs
  • 96197286b0ac net: reduce indent of struct netdev_queue_mgmt_ops members
  • 34debe05685d bnxt_en: Do not set EOP on RX AGG BDs on 5760X chips
  • 5ba1a458c5e2 tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss()
  • 821f6416e697 hwmon: (pmbus) Fix type confusion in notification logic
  • 11720d869be1 hwmon: (pmbus_core) Use guard() for mutex protection
  • cde8931a2539 vdpa/mlx5: Fix buffer length in create_direct_keys()
  • a1c236b385d8 vhost/vdpa: reject overflowing PA map page counts on 32-bit
  • cefcbbe20846 bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()
  • 846ce792b6dd counter: microchip-tcb-capture: Fix DT channel validation
  • 80094352bd40 net/mlx5: fw_tracer, return NULL on create error
  • 7b02c6d2a3cd devlink: fix net namespace reference leak in reload
  • 1efcc7114009 net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete
  • 0e7a8cf8895b net/sched: cls_route: fix fastmap use-after-free on filter
  • 10cb31b2b74c net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()
  • d8a6f7993520 bpf: Propagate untrusted pointer state in commuted arithmetic
  • c2da73a1f715 bpf: split check_reg_sane_offset() in two parts
  • db6382ed3361 bpf: Preserve pointer state for commuted arithmetic
  • 24a8f2c29aeb btrfs: fix memory leak in btrfs_do_encoded_write()
  • 26e968526eb5 watchdog: bd96801_wdt: Fix timeout for enabled WDG
  • b3ff48c4ea8b ipvs: return the csum validation for forward hook
  • a69a4b3fff58 ipvs: avoid out-of-bounds write in ip_vs_nat_icmp
  • 1e8a5467a7a7 netfilter: ipset: switch ext_size to atomic64_t
  • 970e9494f44a pds_core: cancel pending PCI reset work on AER recovery
  • ef8e37ac448d pds_core: keep the health thread stopped during reset
  • ff9e7d5e3500 net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock
  • e506e704b747 enic: fix tx_hang_reset use-after-free on device removal
  • 2faf75a8a065 bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor
  • 35ddcc856b5b Revert "net: thunderbolt: Enable end-to-end flow control also in transmit"
  • d512823059af net: hns3: fix speed configuration residue after driver reload
  • 8701a643db23 drm/bridge: ps8640: propagate AUX transfer register errors
  • d47212d86690 ovpn: fix incorrect use of rcu_access_pointer()
  • 54dd83f24b91 ovpn: ensure TCP vars are initialized first
  • f34949d63cbb ovpn: disable IPv4 redirects on MP interfaces
  • e774f7d8fc73 ovpn: hash floated peer by transport identity only
  • 9a776388ef8d ovpn: zero-initialize sockaddr before learning a floated endpoint
  • 61fb3cca40ff ovpn: ensure socket is owned by ovpn before deref sk_user_data
  • 157164812a0c ovpn: rehash peer in by_transp_addr table on CMD_PEER_SET
  • d20c18108898 ovpn: skip rehash for peers already removed from by_id
  • 9e5e88fbfc87 ARM: dts: BCM5301X: fix PCIe controller 2 second interrupt
  • 92b9d92a35a0 ovpn: add missing rtnl_link_ops->get_size callback
  • d740dea9e255 pinctrl: qcom: ipq806x: mark pci reset as a GPIO pin function
  • 23c94a468efe pinctrl: qcom: ipq806x: mark gpio as a GPIO pin function
  • 913d2295b772 selftests/sched_ext: Handle sleeping task affinity changes in numa test
  • ce0212d230bd ARM: npcm: Fix OF node refcount leaks in SMP setup
  • ccf6738adcaf xfs: handle NULL b_addr in xfs_buf_free
  • d90599a42f6c arm64: dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer
  • d71dfffa512e NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
  • bd45b89d7346 arm64: dts: qcom: sdm850-lenovo-yoga-c630: lower PSCI cluster idle
  • df9d22383d7c arm64: dts: qcom: purwa: Fix GPU IOMMU property
  • 7a6e90afb696 arm64: dts: qcom: rename x1p42100 to purwa
  • 1e2b408c1a76 arm64: dts: qcom: Rework X1-based Asus Zenbook A14's displays
  • 387edbe4706b arm64: dts: qcom: rename x1e80100 to hamoa
  • d089f32d34f8 drm/amd/display: Check for tg ops in dce110_set_avmute
  • 8aba384bfc8a drm/amd/display: Add AV mute wait frames to dce110_set_avmute
  • 50359c42e0eb selftests/bpf: Fail unbound UDP on sockmap update
  • 62fefb817bb3 sched/fair: Revert 6d71a9c61604 ("sched/fair: Fix EEVDF entity placement bug causing scheduling lag")
  • 4043e196dc88 sched/fair: Separate se->vlag from se->vprot
  • 9a3eef676cd8 mount: honour SB_NOUSER in the new mount API
  • 79a45d44323b KVM: s390: pci: Fix resource leak on IRQ registration failure
View originalPermalink
How 6.18.47-rt-xanmod1 went

6.18.47-xanmod1

Fixed 20
  • net: gro: properly validate BIG TCP aggregation criteria
  • ptp: vmclock: prevent read-only mappings from becoming writable
  • futex: Avoid private hash use-after-free on final put
  • Bluetooth: hci_aml: validate firmware segment lengths
  • Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255
  • Bluetooth: ISO: zero the sockaddr before returning it in getname

From XanMod Kernel

  • b260538251f0 Linux 6.18.47-xanmod1
  • 3cefea4ac89f Merge tag 'v6.18.47' into 6.18
  • 7519e95095c9 Linux 6.18.47
  • 3ce832e2bd43 net: gro: properly validate BIG TCP aggregation criteria
  • 5b4f2bec7bea ptp: vmclock: prevent read-only mappings from becoming writable
  • dba60d26e9dd futex: Avoid private hash use-after-free on final put
  • e1534d49a7b8 Bluetooth: hci_aml: validate firmware segment lengths
  • b7d9edcf9fe6 Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255
  • 1f6d1f2611af Bluetooth: ISO: zero the sockaddr before returning it in getname
  • 753af97d8d42 Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync
  • fe93a697a7a9 Bluetooth: hci_sync: Fix accept list UAF during suspend
  • e3f82e8f2a59 Bluetooth: hci_event: validate LE Set CIG Parameters response
  • 39a3afb91be3 Bluetooth: hci_event: fix LE list UAF on reset
  • 608f8fd8c0f7 HID: hyperv: validate initial device info bounds
  • 849e537160bb HID: uclogic: fix use-after-free of inrange_timer on remove
  • 8406d4b69d48 HID: sensor: custom: Fix use-after-free in enable_sensor
  • 1fa1591efd41 HID: core: fix number/pointer type confusion on long items
  • 5efcd7bbfaae HID: nintendo: stop device IO before hid_hw_stop on probe failure
  • 268679f50138 HID: nintendo: register input device after capabilities are set
  • 51cfd1adbe7a HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
  • 942b89f7824f futex: Fix might_sleep() warning in futex_pivot_pending()
  • 86d12b34bafc futex: Fix race on the initial mm->futex.phash.ref allocation
  • fdf538b2e696 futex/pi: Plug private futex exec() race
  • 4da67def9efe futex: Sanitize and document task_struct::futex::state transitions
  • 2b92e5562653 futex/pi: Reject cross-mm private futex owners
  • f303f6a4c909 Input: atkbd - skip deactivate for HONOR ZQC-P
  • 936ea65543da Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard
  • 0ea8f0645401 xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
  • 39fc615e355b net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
  • 4529c03c3da8 HID: pidff: fix OOB write when hid->inputs is empty
  • 9a1d7c5f0d82 HID: core: fix OOB read of field->usage in hid_set_field()
  • ace7fc4d3879 HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID
  • 15b60ade825c HID: magicmouse: do not keep a stale msc->input if no input is claimed
  • 62ec3c591ee8 HID: magicmouse: re-enable multitouch after reset-resume
  • 02a88f8308ae HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C
  • b6baab796d11 ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses
  • 9fe5eebb664e mptcp: pm: fix memory leak from alloc-during-teardown race
  • 6fa2064761ec mptcp: pm: uniform announced addresses helpers
  • 714c6d11acea mptcp: pm: rename add_entry structure to add_addr
  • defc59e74c1b mptcp: pm: use for_each_subflow helper
  • f31650243c1a nvmet: pci-epf: put CQ ref on create_cq mapping failure
  • 20be486d1c22 nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work()
  • 9c95f7e66c62 nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations
  • 6d27199ebe8c nvmet-tcp: bound SGL data length before allocating command buffers
  • 8bce9cd08aae nvmet-fc: fix invalid free in LS IOD error path
  • b26189d28442 nvmet-auth: zero the AUTH_RECEIVE response buffer
  • 23a475ff24d2 dmaengine: fsl-edma: Add error handling for devm_kasprintf
  • 364edaedf412 mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()
  • 3dc98e5fe82d ipv6: fix use-after-free in ip6_finish_output2()
  • d9d1a676b033 ipv4: reject undersized MTUs in ip_do_fragment()
  • f03415030579 drm/xe: Fix DPT allocation paths.
  • 20892d2923e4 nfc: nci: free destination parameters when closing a connection
  • 0d4b5cfab689 nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
  • 2f08dbce3b37 nfc: nci: fix out-of-bounds write in nci_target_auto_activated()
  • 9620a91f8d64 nfc: nci: add data_len bound checks to activation parameter extractors
  • bfcca5f42c9a nfc: st21nfca: validate ATR_REQ length against the received frame
  • 2f5d093194ec nfc: pn533: purge fragmented skbs during cleanup
  • e969e9841005 nfc: llcp: reject PDUs shorter than the LLCP header
  • 2d239590d184 nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
  • e87527b506c4 nfc: llcp: bound the connect_sn TLV walk to the skb
  • d0902a7c4543 nfc: microread: validate target discovery payload lengths
  • db7e464b3509 nfc: fdp: bound the device-reported read length and fix an skb leak
  • a56773e649ea nfc: digital: clamp SENSF_RES length to the destination buffer
  • cb8246e5846d libceph: fix OOB read in decode_watchers() via missing bounds check
  • 184c1a80421a xfs: validate attr entry pointer before field access
  • e0e7f464d6ce ext4: fix incorrect function call when initializing s_resgid
  • 458776af0061 ext4: don't enable DAX on new encrypted files
  • f3d2fa3a9933 ext4: propagate errors from fast commit range replay
  • 5f46f084f74b ext4: avoid tail write_begin walk for uptodate folios
  • fb5980fbe44f ext4: clear error before retrying inode xattr space fallback
  • e447f7edb99b nilfs2: reject invalid block index in GC ioctl
  • 4902a5cba21a ext4: stop retrying saturated xattr cache entries
  • e11f5b48c827 kcov: fix data corruption and race conditions on PREEMPT_RT
  • 164ca33cf536 null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows
  • 6176313622e3 ocfs2: fix missing metadata reservation for large xattrs
  • 15ccf5370985 io_uring/uring_cmd: don't skip completion for a synchronous multishot cmd
  • 45c945107e00 io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec()
  • 4074ae2f1da9 io_uring/io-wq: fix worker accounting when canceling creation callbacks
  • b6a768aa975b io_uring/cmd: fix iovec leak when the async cmd is not recycled
  • f20c2c32ec1c ALSA: dummy: Check card index validity at probe
  • 3da64f2ed902 io_uring/futex: don't mark futex wake requests as inflight
  • 61dc1a37e04d nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()
  • e971d956353d rndis_host: add overflow check in rndis_rx_fixup()
  • 4305e4b52acc ALSA: scarlett2: Use a private URB for the notification endpoint
  • 65aceb45ca91 ALSA: FCP: Use a private URB for the notification endpoint
  • 7596354148c5 iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages
  • d2ab08437e91 iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown
  • d4b1a13b1eff Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept
  • 0c55707bd5d0 PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
  • 159d162fe80b xfs: don't livelock in scrub on a circular unlinked list
  • a05a1b663464 xfs: hoist per-bucket unlinked list check to helper
  • 8d678be8e58e xfs: rtsummary scrub should treat rtbitmap corruption errors as an xref error
  • 00e2baf0b5ea xfs: add a xchk_ip_set_corrupt helper
  • 755d0b7ee356 serial: sc16is7xx: enable THRI before filling TX FIFO
  • c5a12344a043 serial: sc16is7xx: use guards for simple mutex locks
  • 450fe8f6f1f8 serial: sc16is7xx: rename EFR mutex with generic name
View originalPermalink
How 6.18.47-xanmod1 went

7.1.10-xanmod1

Changed 1
  • Set GT rp min frequency as 1.2GHz default for BMG/CRI in drm/xe
Fixed 19
  • Enable headset mic on F+ FLAPTOP r
  • Fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms
  • Mark SPI virtio device ready before registering the controller
  • Fix infinite loop when scale is too large for display in drm/log
  • Fix out-of-bounds read on empty message length in drm/log
  • Fix division by zero when scale module parameter is 0 in drm/log

From XanMod Kernel

  • 0f1ac59df670 Linux 7.1.10-xanmod1
  • fc11d50c4815 Merge tag 'v7.1.10' into 7.1
  • 8d4e6356173a Linux 7.1.10
  • 93f4d99b7e06 ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r
  • d31639e0dd88 erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms
  • f07ab9771db5 spi: virtio: mark device ready before registering the controller
  • 50ca4dbbaf3e drm/log: Fix infinite loop when scale is too large for display
  • 16bcea56f420 drm/log: Fix out-of-bounds read on empty message length
  • 71ba3938cd57 drm/log: Fix division by zero when scale module parameter is 0
  • 1eea17a9184c drm/xe: Fix a bug in pc_adjust_freq_bounds()
  • e75b29f1d31c drm/xe: Set GT rp min frequency as 1.2GHz default for BMG/CRI
  • b3991da6ea98 drm/xe/oa: Check managed mutex initialization errors
  • 027150e24e17 drm/xe/oa: Fix sync entry leak on OA config emit failure
  • 24026a295e03 drm/xe/pxp: add termination on resume
  • 7d228ba43279 firewire: ohci: fix NULL pointer dereference in ar_context_release
  • ebe2774e9564 l2tp: fix tunnel and session refcount leak on seq_file release
  • 5685bbbd3cbf net/sched: cls_bpf: reject dev-bound programs bound to a different device
  • 499227ca8edc accel/amdxdna: Skip unmapped range in aie2_populate_range()
  • 914e0100df34 net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG
  • 5bd8e897ecf5 regmap: sdw-mbq: don't call an unset readable_reg callback
  • eb5ad008574d m68k: Define NR_CPUS to 1
  • d7c413bd421c pid: reject allocations through dead ancestor pid namespaces
  • e71f8e9ed6f3 net/sched: cls_u32: skip hash tables in u32_bind_class()
  • 6b70886ebc42 net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain
  • f09ac5682f1b af_packet: Don't send zero-byte data in tpacket_snd().
  • cc90447a7f79 regmap: sdw-mbq: Fix swap of timeout and retry times
  • 09e4c486348e ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers
  • 4b177911eb9f net/tls: Fail tls_sw_splice_read() after a failed async decrypt
  • 0ab482b2195e net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling
  • 88b79ac89ecc net: tap: fix wrong transport_header when sending VLAN-tagged frame
  • 6386a6ffa2ef net: packet: fix wrong transport_header when sending VLAN-tagged frame
  • fa8ceaae52d3 net: phy: realtek: fix EEE advertisement write on the internal PHY MMD path
  • 29633de25773 tcp: fix icsk_ack.ato bitfield overflow
  • 90bb11fb29d3 veth: fix queue index used to wake the peer txq in veth_poll
  • bc9a00fb78e3 macvlan: inherit needed_headroom and needed_tailroom from lowerdev
  • 5c2ca77212eb ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
  • 8b1118fc5a5d eth: bnxt: avoid deadlock when canceling IRQ affinity notifier
  • ae2e1c26082c eth: bnxt: decrease indent in bnxt_request_irq()
  • 2a64e5e75879 eth: bnxt: keep the aRFS rmap updated when TPH is enabled
  • 5f451cdb3f4e eth: bnxt: cancel IRQ notifier before freeing affinity mask
  • 0c60f26caca4 netfilter: ipset: let destroy callbacks adjust ext mem size
  • b88250102549 netfilter: ipset: fix list type element drift bug
  • d16b71231e65 netfilter: flowtable: publish GC-visible tuple last
  • c23620a0fa5b netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path
  • 5365f012451f ipvs: revalidate ihl to prevent out-of-bounds access
  • 24ffcb1e1688 netfilter: ipset: fix refcount race between list:set GC and swap
  • 8bfb93a35c9f tick: Include ktime.h and jiffies.h in linux/tick.h
  • f5bde482b242 ASoC: tas2781: fix clang build error for goto bypassing cleanup variable
  • 1eee6a92739a gpio: ml-ioh: share the register lock across channels
  • 8bbf4405050b rseq: Prevent hard lockup on granted time slice extension
  • 0f77ed5ee919 ovpn: defer key slot crypto freeing to workqueue
  • bbe81f40582d ovpn: run deferred work on a module-owned workqueue
  • e697e30f3dd2 riscv: lib: Fix ZBB strnlen reading past count boundary
  • 0663d1df8d28 ALSA: usb-audio: Fix mixer regression on SteelSeries Arctis Nova 5
  • 88619b117be1 sctp: validate cookie AUTH state before use
  • 7ce010275c53 perf: Reject exited events as group leaders
  • e83eed1bea14 scsi: core: pair EH runtime PM get and put
  • fe98491cb322 riscv: ftrace: Fix ftrace_modify_call failure on kprobed functions
  • 4b0de8be288f ovpn: finish crypto callback cleanup before peer release
  • acf32a5dff08 ovpn: fix NULL dereference when killing missing key
  • e3702470ced9 af_unix: Unlink scc_entry in unix_del_edge().
  • 92a959405383 regulator: fp9931: Fix VPOS/VNEG voltage selector table
  • d9daaca68ab9 gpiolib: Check gc->get_direction() before calling gpiod_get_direction()
  • 413be75118d1 rhashtable: fix false-positive lockdep splat on rhltable destruction
  • c6237834d999 crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req()
  • 3b8a9543801b crypto: ccm - Set rfc4309 maxauthsize from child
  • 487aa5391f91 arm64: tegra: Add EL2 virtual timer interrupt for Tegra194
  • bb81b608db63 clk: spacemit: k3: set hdma clock as critical
  • 294fd02f48c5 clk: spacemit: k3: fix USB2 bus clock
  • 94bf4fe0e463 optee: ffa: Add NULL check in optee_ffa_lend_protmem
  • 9114f72b9161 clk: qcom: dispcc-eliza: Fix disp_cc_mdss_mdp_clk_src RCG stall on Eliza EVK
  • 574498e56024 ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup
  • b0b98763cedb net: expect instance lock in netdev_queue_get_dma_dev()
  • 1be781e450c5 net: rename netdev_ops_assert_locked()
  • ca91e0cc8087 drm/amdkfd: Add bounds check for CRAT subtype length
  • 75db927187a1 drm/mediatek: mtk_dsi: Enable HS clock only at pre-enable
  • 6bd8d6b4eb51 drm/mediatek: Convert legacy DRM logging to drm_* helpers in mtk_dsi.c
  • c37a0461c0d0 ASoC: tas2562: Validate values for volume writes
  • 9e55fe24c548 ceph: fix hanging __ceph_get_caps() with stale mds_wanted
  • b6a098961307 ceph: avoid fs reclaim while using current->journal_info
  • 605cbdb7ed21 xfs: check v5 superblock features early
  • ff350e672534 xfs: check xfarray iteration errors when committing unlinked inode lists
  • 233557b7b1ed xfs: don't ignore runtime errors in xrep_iunlink_reload_next
  • 36a31b12540c xfs: don't swallow dquot recovery verification errors
  • 03c9c9116e6d xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN
  • 96246a3200d3 xfs: avoid UAF on sc->tempip in xrep_tempfile_create
  • 73ce20d9b6a9 xfs: don't return EFSCORRUPTED when scrubbing corrupt parent pointers
  • 23690064f235 xfs: fix another iunlink infinite loop bug in online fsck
  • 8ce03692a6b5 xfs: fix allocated inodes that show up in the unlinked list
  • a6cfd0e4bb1e xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair
  • 70714b154842 xfs: don't zap the attr fork on repair when there are queued pptr updates
  • 08bed2b67d2e xfs: fix ilock leak on error in xfs_dq_get_next_id
  • 8a5bb14cd964 xfs: load next_agino from the correct xfarray in xrep_iunlink_relink_prev
  • 2773bf5156d5 xfs: nlink scrub must take IOLOCK before determining ILOCK state
  • a3ce762bdb5d xfs: pass runtime errors from xrep_iunlink_mark_ondisk_rec up to callers
  • ca6085790659 xfs: set the prev pointer when reinserting an inode on the unlinked list
  • c57590447157 xfs: don't double-lock when deleting a self-referential directory
  • e753d3b5b21b xfs: only check mergeability of bnobt records
  • a68b492357e3 xfs: zero i_nlink before repair puts inode on unlinked list
  • b51051f7dc53 xfs: fix transaction block reservation in xrep_rtbitmap
  • 5faabb37dd60 xfs: check cowextsize in xrep_inode_cowextsize
  • c82c1279c90a xfs: clear zapped attr fork state when bmap repair finds no attr fork
  • ccad4a3b96eb xfs: mark nonzero sb_gquotino as corrupt on metadir filesystems
  • edaf5b6bd625 xfs: bounds-check buffer log item's dirty bitmap
  • ccebfc309441 xfs: fix off-by-one in rtrefcount btree root level validation
  • 61c5165f02de xfs: propagate errors from xfs_rtginode_load
  • e3ee74d6dbbe drm/amdgpu: disallow multiple FENCE chunks in one submit
  • 5cbd8af02b0b drm/amdgpu: Fix UVD decode image min size calculation
  • ff4361816b6b drm/amdgpu: Fix UVD dpb min size calculation for H264
  • 4530aa81c907 drm/amdgpu: Fix UVD min buffer sizes
  • de67fd77ff18 drm/amdgpu: Implement insert_end for VCE 3
  • 17fbb996c05f drm/amdgpu: Reject UVD message with dimensions above 4096
  • 80f0b53860d0 drm/amdgpu: validate GEM_CREATE domain combinations
  • 544f760f36d4 drm/amdgpu: check ASPM on the dGPU host link
  • 9213b2febc37 drm/amdgpu: fix missing check in vm_flush()
  • 33bd5194ea61 drm/amdgpu: fix nbif 6.3.1 l1 low power not functional
  • 476d259f285f drm/amdgpu: Prefer default discovery offset
  • 0acdf1a575f5 drm/amdgpu: Reject UVD message with invalid number of h265 refs
  • 2f41881e73f4 drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE
  • dacea1e4de8e drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix
  • 4a6bc92fac30 drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank()
  • 2db92a56b000 s390/zcrypt: Pad trailing CCA or EP11 message with zeros
  • db21b2cf6dd0 s390/zcrypt: Improve EP11 CPRB domain handling with ASN.1 parsing
  • 2976b9d2e716 s390/zcrypt: Improve EP11 CPRB length and overflow checks
  • 50fe5133dcb4 s390/zcrypt: Improve CCA CPRB length and overflow checks
  • 14d41e383241 s390/zcrypt: Fix CPRB memory allocation in zcrypt misc code
  • c76c4ee72bfc s390/vfio_ccw: Implement a crw lock
  • 83a73fdeff38 s390/vfio_ccw: Calculate idal length based on idaw type
  • 2a5ac0c0f1f7 s390/vfio_ccw: Selectively expand io_mutex
  • 56100baa0eb7 s390/vfio_ccw: Move cp cleanup out of not operational
  • d5d096cd9369 s390/vfio_ccw: Fix out of bounds check on CCW array
  • fc59e9482117 s390/vfio_ccw: Ensure first IDAW remains constant
  • 988d9b5be3c2 s390/vfio_ccw: Ensure index for read/write regions are within range
  • 77f5e888d2e6 s390/vfio_ccw: Cancel existing workqueues
  • 4ee94790490a s390/vfio_ccw: Limit the number of channel program segments
  • 4699b54fada1 s390/vfio_ccw: Free all memory if cp_init() fails
  • 6a06a99b9c60 drm/radeon: fix autosuspend cleanup during teardown
  • e4aff0f8bc31 drm/xe/guc_ads: use uncached mapping for UM queue BO
  • 02bc8cf239a7 drm/xe/guc_ads: allocate UM queues in VRAM on dGFX
  • 7b1ebb987d13 drm/xe/guc_ads: allocate UM queues in a separate BO
  • 4db2b608e5f3 drm/xe: Fix xe_device_probe() failure
  • dea635bd1317 drm/xe: Order ring writes before ring tail updates
  • a5805f9e24d6 riscv: hwprobe: Register unaligned probes before usermode
  • f1478e8d5334 pmdomain: mediatek: Fix mt8183 hang on boot
  • db368164383c mmc: loongson2: Fix sg iteration in data reorder functions
  • f72bb95732bc drm/connector/hdmi: Fix out of bounds memory read
  • 7599a73ff66d mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition
  • 0e1c00199394 pmdomains: mediatek: Avoid setting RTFF's CLK_DIS before NRESTORE
  • 3c6c28b9bee7 mmc: sdhci: make tuning_err a signed int
  • 10bf2d7261d7 pmdomain: mediatek: fix remaining %pOF after of_node_put()
  • ce508a334e9c mmc: sdhci: unmap the bounce buffer before device release
  • 4a0c11683a8f mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit
  • 3497102117e8 libceph: tolerate addrvecs with multiple entries of the same type
  • 7130d94846da libceph: fix OOB read in decode_watchers() via missing bounds check
  • a9e1d197953f ceph: fix MDS random selection readiness predicate
  • e009c5f0ad63 libceph: Avoid using invalid osd indices from primary_temp
  • daeaa22a37dd Input: sur40 - fix V4L error path cleanup
  • beb9b0bd6e6e Input: sur40 - fix input device registration ordering
  • 212fc482ddd7 openrisc: signal: do not restore privileged SR bits on sigreturn
  • 7e65a89124c1 ftrace: Fix off-by-one fentry site disable in ftrace_free_mem()
  • bd75a42cea7e ftrace: Protect direct_functions in update_ftrace_direct_mod
  • 35f8e0989985 ftrace: Protect direct_functions in update_ftrace_direct_del
  • 5ac91943ee59 ftrace: Protect direct_functions in ftrace_find_rec_direct
  • de4eec0dfde8 pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev()
  • 51c8d238fe72 libceph: fix multiple unsafe decodes in decode_locker()
  • cdefce49feed pmdomain: arm: Fix -EINVAL from scmi_pd_set_perf_state() on state 0
  • 10505f28146f pmdomain: qcom: rpmhpd: Add missing MXC and MMCX power domains for Eliza
  • 0559b86611c3 gpio: ml-ioh: use raw_spinlock_t for the register lock
  • 44ec5936ba15 gve: fix zero-length skb frag with header-split
  • 8021105545c1 selftests/ftrace: Convert ELF entry point to file offset in uprobe test
  • 24bef4918f6a gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind
  • fa9b991bf678 gve: fix NULL dereference due to missing ptp adjfine
  • 4e88b4fda482 crypto: qce - fix error path in devm_qce_register_algs
  • 61b20fba32d6 crypto: starfive - use scatterlist length before DMA mapping
  • 51c5503554c8 Input: hynitron_cstxxx - validate touch count and finger IDs
  • 9bbd3682f8a3 Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue
  • ddd9a53faf3b Input: synaptics-rmi4 - block s_input when F54 queue is busy
  • b7b9a8b1c303 Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer
  • 88c8174d7290 Input: synaptics-rmi4 - zero report size on F54 work error
  • ed98ce338f9a powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak
  • 6a4643f7eabe powerpc/pseries: lparcfg - fix kbuf[] underflow
  • 2e509ef60ee4 Input: byd - synchronize timer deletion before freeing private data
  • 84e5cb517f44 Input: iforce - validate input packet lengths
  • 594b79d024e5 Input: atkbd - skip deactivate for HONOR ZQC-P
  • da1ecf638cd8 Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard
  • 62e25677d144 Input: psxpad-spi - set driver data before use
  • 1842e4712681 Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet
  • a81cafe3c3c2 Input: synaptics-rmi4 - fix F55 transmitter electrode count typo
  • 360fc573e6cf powerpc/pseries: pci - logic bug
  • d38554602a0b Input: cs40l50-vibra - validate custom data from user space
  • a3da1fa14797 Input: xpad - add support for ZENAIM LEVERLESS
  • 2deef1c38c2c ASoC: SOF: topology: Use acpi mach from the machine driver
  • 0306873bbb3a drm/amdgpu/gmc12.1: fix MMHUB0 check in pasid tlb flush
  • d4ffb51b9f02 drm/amdgpu/gmc12.1: implement tlb inv semaphore
  • 1c73854a53bb drm/amdgpu: fix aperture iounmap skipped on device removal
  • a4d52348157e drm/amdgpu: fix JPEG v4.0.5 queue reset failure in DPG mode
  • 09ad1526c2ef drm/amdgpu: fix JPEG v5.0.0 queue reset failure in DPG mode
  • c79ec4aa250b drm/amdgpu: fix JPEG v5.3.0 queue reset failure in DPG mode
  • 9381d8ae3e31 drm/amdgpu: Use virtual alloc during coredump
  • fb0eb608570e drm/radeon: restore hardware polling in fence_is_signaled to fix performance regression
  • 34c5b3eca369 drm/amd: Disable DP audio spread spectrum for Cyan Skillfish
  • 91731dec60e9 drm/amdgpu/userq: serialize queue map against GPU reset
  • a4443c272578 drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12
  • 07fe270ec07c drm/amdgpu: reject oversized IBs with per-ring packet limits
  • 5d222b657f02 drm/panthor: skip zero-sized firmware sections
  • 7110b7b794a2 fbdev: core: Fix pointer desynchronization in fb_io_read()
  • ce7fef961c63 fbdev: clear fb_info->mode before deleting a videomode
  • 873a1aa15c31 fbdev: bound mode sysfs output to the sysfs buffer
  • 7bcdde412e6c ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses
  • 4fbbbb17edb4 ASoC: cs35l41: sort the register default table
  • 2b12126944d7 ASoC: cs35l45: sort the register default table
  • b3f8a818796b ASoC: cs4265: sort the register default table
  • 6b512a5330ef ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout
  • d48691e70d4a ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked()
  • 12803e89a1e5 drm/shmem_helper: Check VMA boundaries for PMD mappings
  • 3ee3c26ceee5 ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses
  • 2f578062a5f1 microblaze: restore the page alignment of swapper_pg_dir
  • 75fb3151513d s390/qeth: validate user buffer length in SNMP and ARP query ioctls
  • 72b4a0c51a4b mptcp: fastopen: only mark MPTFO subflows with SYN data
  • 5099027f98b2 mptcp: pm: fix data race in add_addr timer callback
  • 27ed642a4e7e mptcp: options: reset DSS fields in case of unexpected size
  • 6bab90729215 mptcp: avoid combining some incoming suboptions
  • e5791c03854b selftests: mptcp: join: mark tests with data corruption as failed
  • 8277f48a06d3 mptcp: reclaim forward-allocated memory on RX path errors
  • d81bda85d95f selinux: reject a permission value exceeding the class permission count
  • d8a10899ea3c selinux: reject an unclaimed class value in security_get_classes()
  • 219c96de5d9b selinux: do not cancel a policy conversion that never started
  • 1b995966c3ae selinux: reject a class permission count below its inherited common
  • ed901e88aa3f selinux: require every boolean value to be defined
  • 93d620519d71 block: stop the timeout timer when releasing a never added disk
View originalPermalink
How 7.1.10-xanmod1 went

6.18.46-xanmod1

Fixed 18
  • Enable headset mic on F+ FLAPTOP r
  • Initialize page array to use alloc_pages_bulk() correctly in firewire ohci
  • Set surface-framebuffer GEM objects in drm/vmwgfx
  • Fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms
  • Mark device ready before registering the controller in spi virtio
  • Fix infinite loop when scale is too large for display in drm/log
Removed 1
  • Remove drm_client_framebuffer_delete() function
Deprecated 1
  • Deprecate struct drm_client_buffer.gem

From XanMod Kernel

  • d3fea146457b Linux 6.18.46-xanmod1
  • 8c0d3dba26dc Merge tag 'v6.18.46' into 6.18
  • 1f99e9ab748f Linux 6.18.46
  • b7ce4b3bc106 ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r
  • 192f44513a03 firewire: ohci: initialize page array to use alloc_pages_bulk() correctly
  • e5e6ce7009a6 drm/vmwgfx: Set surface-framebuffer GEM objects
  • 7e351209dc2f erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms
  • 67ac7e01c26b spi: virtio: mark device ready before registering the controller
  • a7d172b27aa3 drm/log: Fix infinite loop when scale is too large for display
  • a6325e2807dc drm/client: Remove drm_client_framebuffer_delete()
  • 329731b3119f drm/client: Deprecate struct drm_client_buffer.gem
  • 0763282e689e drm/client: Inline drm_client_buffer_addfb() and _rmfb()
  • 60f1a2ecdf8b drm/client: Move dumb-buffer handling to drm_client_framebuffer_create()
  • 841bc853a2b1 drm/client: Remove pitch from struct drm_client_buffer
  • 16a2716910ec drm/log: Fix out-of-bounds read on empty message length
  • 948f346fe36e drm/xe/oa: Fix sync entry leak on OA config emit failure
  • ed5470771c7e firewire: ohci: fix NULL pointer dereference in ar_context_release
  • 384d9f04b38f firewire: ohci: split page allocation from dma mapping
  • adb3e7c26a51 net/sched: cls_bpf: reject dev-bound programs bound to a different device
  • 1f493c44a2f0 accel/amdxdna: Skip unmapped range in aie2_populate_range()
  • 72e4e3d7efc3 net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG
  • 6cf600b276a5 regmap: sdw-mbq: don't call an unset readable_reg callback
  • c27eed546ae2 m68k: Define NR_CPUS to 1
  • 31f26a95eeee net/sched: cls_u32: skip hash tables in u32_bind_class()
  • abceabc4408f net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain
  • 98c5914d6b7b af_packet: Don't send zero-byte data in tpacket_snd().
  • 37c5ccaaacd4 regmap: sdw-mbq: Fix swap of timeout and retry times
  • f51a540b14ee ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers
  • 82d9269f01eb net/tls: Fail tls_sw_splice_read() after a failed async decrypt
  • cef4c5b9aca2 net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling
  • 5ffaa5d7f56a net: tap: fix wrong transport_header when sending VLAN-tagged frame
  • f9297abbcaba net: packet: fix wrong transport_header when sending VLAN-tagged frame
  • 0af3afd054e7 net: phy: realtek: fix EEE advertisement write on the internal PHY MMD path
  • 17e3181d740d tcp: fix icsk_ack.ato bitfield overflow
  • 73f8dd22b1e5 veth: fix queue index used to wake the peer txq in veth_poll
  • 96fa90b74385 macvlan: inherit needed_headroom and needed_tailroom from lowerdev
  • 5f33188457bb ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
  • 1072f0f44282 eth: bnxt: keep the aRFS rmap updated when TPH is enabled
  • 394f1b16c5d1 eth: bnxt: cancel IRQ notifier before freeing affinity mask
  • a26a1be1b654 netfilter: ipset: let destroy callbacks adjust ext mem size
  • 29c011b3537d netfilter: ipset: fix list type element drift bug
  • d9d3050a70ef netfilter: flowtable: publish GC-visible tuple last
  • 4a923fe60939 netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path
  • cb20da33839f netfilter: ipset: fix refcount race between list:set GC and swap
  • 9e75e7da4374 ASoC: tas2781: fix clang build error for goto bypassing cleanup variable
  • 24d0f33f5415 gpio: ml-ioh: share the register lock across channels
  • 7a03413f31c1 perf: Reject exited events as group leaders
  • 6c85d169eeec riscv: ftrace: Fix ftrace_modify_call failure on kprobed functions
  • a3a676495c64 ovpn: finish crypto callback cleanup before peer release
  • a47a080d06ee ovpn: fix NULL dereference when killing missing key
  • 99a18e1d979e crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req()
  • 3e4bf50c9451 crypto: ccm - Set rfc4309 maxauthsize from child
  • d9ecc9787e11 arm64: tegra: Add EL2 virtual timer interrupt for Tegra194
  • a4e340971fe8 NTB: ntb_netdev: Preserve RX queue depth on allocation failure
  • 08437c5156b0 net: ntb_netdev: Introduce per-queue context
  • 2a7d8fc0fd50 ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup
  • 8c685df5c3b2 drm/amd/pm: fix pptable use-after-free
  • 2895aeb4327c drm/amd/pm: adjust the visibility of pp_table sysfs node
  • 7755be923e32 mm/page_table_check: skip special zero mappings
  • 4ae625d16eef ring-buffer: Prevent resizing of persistent ring buffer
  • 54fc67500ad1 ring-buffer: Store bpage pointers into subbuf_ids
  • 27d7fcaf237d ring-buffer: Add helper functions for allocations
  • 2ca6b43edf83 sched_ext: Take cgroup_lock() first in scx_cgroup_lock()
  • f786e6652b93 sched_ext: Reorganize enable/disable path for multi-scheduler support
  • 0907f81536f7 sched_ext: Update p->scx.disallow warning in scx_init_task()
  • 4a7e941ca29a futex: Fix race in futex_pivot_pending() during private hash resize
  • 870f8392b284 can: rcar_canfd: change the initializing flow for clocks and resets
  • 45bf067681ad can: rcar_canfd: Extract rcar_canfd_global_{,de}init()
  • e7a4ca927857 can: rcar_canfd: Use devm_clk_get_optional() for RAM clk
  • f8c8c81707d1 can: rcar_canfd: Invert global vs. channel teardown
  • 562d4befa935 can: rcar_canfd: Invert reset assert order
  • 867aed6a4848 binfmt_misc: don't leak the user namespace when the mount fails
  • 4c8d7595a10a ata: libata-scsi: terminate deferred commands on time out
  • db488d653d89 ASoC: tas2562: Validate values for volume writes
  • 5f0a99ea7212 KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs
  • ef60eca789ee userfaultfd: wait on source PMD during UFFDIO_MOVE
  • ea563ed2b10a mm: replace pmd_to_swp_entry() with softleaf_from_pmd()
  • 54a09573eb44 fs/proc/task_mmu: refactor pagemap_pmd_range()
  • 549148d5aa4e btrfs: zoned: fix missing chunk metadata reservation
  • 58ae8b7e8dc8 btrfs: remove fs_info argument from btrfs_zoned_activate_one_bg()
  • d9e9753dfd43 ksmbd: validate minimum PDU size for transform requests
  • 15a2fedb5dff smb/server: fix minimum SMB2 PDU size
  • 23d34ce11885 smb/server: fix minimum SMB1 PDU size
  • 5649004f7161 ksmbd: rename smb2_get_msg to smb_get_msg
  • 29dbb4e29e1f ksmbd: Fix to handle removal of rfc1002 header from smb_hdr
  • df3cf61adbe6 smb/server: rename include guard in smb_common.h
  • 9d154c3c0f5d smb: move get_rfc1002_len() to common/smbglob.h
  • 8ddc2eb0d2da net/sched: serialize qdisc_rtab_list against concurrent get/put
  • 89df5d71f83f libceph: fix two unsafe bare decodes in decode_lockers()
  • 590b07ceea13 libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
  • 89a50fb32d69 libceph: Amend checking to fix make W=1 build breakage
  • a3bc6b3e9ef3 ceph: fix hanging __ceph_get_caps() with stale mds_wanted
  • 79d95b43ca09 ceph: avoid fs reclaim while using current->journal_info
  • bb13785d5499 xfs: check v5 superblock features early
  • 04228b8ba196 xfs: check xfarray iteration errors when committing unlinked inode lists
  • 33b56c6c465a xfs: don't ignore runtime errors in xrep_iunlink_reload_next
  • 38a4dbe588bd xfs: don't swallow dquot recovery verification errors
  • 0f27b22343b6 xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN
  • cd1f876d1bc2 xfs: avoid UAF on sc->tempip in xrep_tempfile_create
  • e75150d494dc xfs: don't return EFSCORRUPTED when scrubbing corrupt parent pointers
  • b6baf0db357f xfs: fix another iunlink infinite loop bug in online fsck
  • fc7d8a5c5fcc xfs: fix allocated inodes that show up in the unlinked list
  • c36d7f68f1c2 xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair
  • 73ffd2620df3 xfs: don't zap the attr fork on repair when there are queued pptr updates
  • 514a5d42d418 xfs: fix ilock leak on error in xfs_dq_get_next_id
  • 9680b1929d89 xfs: load next_agino from the correct xfarray in xrep_iunlink_relink_prev
  • 8b52fa8fb3ab xfs: nlink scrub must take IOLOCK before determining ILOCK state
  • 7d1d82c463e2 xfs: pass runtime errors from xrep_iunlink_mark_ondisk_rec up to callers
  • ab4e13337076 xfs: set the prev pointer when reinserting an inode on the unlinked list
  • ce2a7006ec5e xfs: don't double-lock when deleting a self-referential directory
  • 983588e756a3 xfs: only check mergeability of bnobt records
  • 62c0b1435dfe xfs: zero i_nlink before repair puts inode on unlinked list
  • a9114c6d4ec2 xfs: fix transaction block reservation in xrep_rtbitmap
  • 90a49b8fcf82 xfs: check cowextsize in xrep_inode_cowextsize
  • 069c0eadc8df xfs: clear zapped attr fork state when bmap repair finds no attr fork
  • aeadf3fd2dc3 xfs: mark nonzero sb_gquotino as corrupt on metadir filesystems
  • f8288214459e xfs: bounds-check buffer log item's dirty bitmap
  • 8a0ecae2ecda xfs: fix off-by-one in rtrefcount btree root level validation
  • ec19cea4ef1c xfs: propagate errors from xfs_rtginode_load
  • 71aa45f7bfe4 drm/amdgpu: disallow multiple FENCE chunks in one submit
  • 25ee120f3803 drm/amdgpu: Fix UVD decode image min size calculation
  • 38914cb2c6af drm/amdgpu: Fix UVD dpb min size calculation for H264
  • c76e5cca0675 drm/amdgpu: Fix UVD min buffer sizes
  • 86a5cb020322 drm/amdgpu: Implement insert_end for VCE 3
  • 339deb76ee48 drm/amdgpu: Reject UVD message with dimensions above 4096
  • 220aa2589d73 drm/amdgpu: validate GEM_CREATE domain combinations
  • a082bd76c5f2 drm/amdgpu: check ASPM on the dGPU host link
  • 916e8a1550be drm/amdgpu: fix nbif 6.3.1 l1 low power not functional
  • e304c3e0d9ce drm/amdgpu: Reject UVD message with invalid number of h265 refs
  • e3e6a631dcb1 drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE
  • cd99fa1cbaf5 drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix
  • 5045fb4c70bf drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank()
  • 95c1de6923b0 s390/zcrypt: Fix CPRB memory allocation in zcrypt misc code
  • 7902be374cbf s390/vfio_ccw: Implement a crw lock
  • 3b224d3c50a3 s390/vfio_ccw: Calculate idal length based on idaw type
  • b6aecea4b2b2 s390/vfio_ccw: Selectively expand io_mutex
  • af1759d8e6e6 s390/vfio_ccw: Move cp cleanup out of not operational
  • 4c2e1d359d7a s390/vfio_ccw: Fix out of bounds check on CCW array
  • 08ef2a821156 s390/vfio_ccw: Ensure first IDAW remains constant
  • 649badf3a2fd s390/vfio_ccw: Ensure index for read/write regions are within range
  • b7ae0f799386 s390/vfio_ccw: Cancel existing workqueues
  • 06f4d6e5a8af s390/vfio_ccw: Limit the number of channel program segments
  • 32e3d364a7b8 s390/vfio_ccw: Free all memory if cp_init() fails
  • 45aa38567c79 eth: bnxt: make sure we populate the qcfg defaults on old FW/HW
  • 0382ed41c664 eth: bnxt: always set the queue mgmt ops
  • 31ef57083e78 drm/radeon: fix autosuspend cleanup during teardown
  • 361114857813 drm/xe: Fix xe_device_probe() failure
  • 7b90db6f024b drm/xe: Order ring writes before ring tail updates
  • 198b4a89b903 pmdomain: mediatek: Fix mt8183 hang on boot
  • 8f7f7a6d5aed mmc: loongson2: Fix sg iteration in data reorder functions
  • e5b527804a1e drm/connector/hdmi: Fix out of bounds memory read
  • b5060ff2f546 mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition
  • 78e59ab34337 pmdomains: mediatek: Avoid setting RTFF's CLK_DIS before NRESTORE
  • 7c0d1767ce46 mmc: sdhci: make tuning_err a signed int
  • 970b9c83a07c pmdomain: mediatek: fix remaining %pOF after of_node_put()
  • 36d1b69c5c69 mmc: sdhci: unmap the bounce buffer before device release
  • 0418b7ed2c1c mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit
  • b37e84280045 libceph: tolerate addrvecs with multiple entries of the same type
  • 4490fad7992a ceph: fix MDS random selection readiness predicate
  • 4f392fec0755 libceph: Avoid using invalid osd indices from primary_temp
  • f3854719fba9 Input: sur40 - fix V4L error path cleanup
  • 5c1c5227c93f Input: sur40 - fix input device registration ordering
  • a88d688be8d7 openrisc: signal: do not restore privileged SR bits on sigreturn
  • f634598e8fb7 ftrace: Fix off-by-one fentry site disable in ftrace_free_mem()
  • f8fe843a9634 ftrace: Protect direct_functions in ftrace_find_rec_direct
  • d1bba38574d0 libceph: fix multiple unsafe decodes in decode_locker()
  • ebdecef6fd84 pmdomain: arm: Fix -EINVAL from scmi_pd_set_perf_state() on state 0
  • bc7934d0acd4 gpio: ml-ioh: use raw_spinlock_t for the register lock
  • 9e678cffc11c gve: fix zero-length skb frag with header-split
  • bd4e5a97edf8 selftests/ftrace: Convert ELF entry point to file offset in uprobe test
  • 23e9f32c0c7d gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind
  • e9482feeed66 gve: fix NULL dereference due to missing ptp adjfine
  • a134e4b8102c crypto: qce - fix error path in devm_qce_register_algs
  • ef92c0ad0268 crypto: starfive - use scatterlist length before DMA mapping
  • 38e7d5c1ade0 Input: hynitron_cstxxx - validate touch count and finger IDs
  • 70f9aad39435 Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue
  • ff0849705d29 Input: synaptics-rmi4 - block s_input when F54 queue is busy
  • 6b06aab79ff1 Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer
  • b28593a05afd Input: synaptics-rmi4 - zero report size on F54 work error
  • 828a8d1a9107 powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak
  • 2bdec532202b powerpc/pseries: lparcfg - fix kbuf[] underflow
  • 8dbfd8e32a13 Input: byd - synchronize timer deletion before freeing private data
  • a64a8b6b31cd Input: iforce - validate input packet lengths
  • e7b8a107ecad Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard
  • 8d622c58205a Input: psxpad-spi - set driver data before use
  • 83c265bfc084 Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet
  • 9b184c8337c6 Input: synaptics-rmi4 - fix F55 transmitter electrode count typo
  • 652e952850d9 powerpc/pseries: pci - logic bug
  • 52a818c586ae Input: cs40l50-vibra - validate custom data from user space
  • 455dbb5bdd81 Input: xpad - add support for ZENAIM LEVERLESS
  • 6635d544bd6b ASoC: SOF: topology: Use acpi mach from the machine driver
  • bcc66461f574 drm/amdgpu: fix aperture iounmap skipped on device removal
  • dffacbe8118f drm/amdgpu: fix JPEG v4.0.5 queue reset failure in DPG mode
  • e45356f6adae drm/amdgpu: fix JPEG v5.0.0 queue reset failure in DPG mode
  • 4550b90bd2e6 drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12
  • 1474f3970d1a drm/amdgpu: reject oversized IBs with per-ring packet limits
  • 25556a46ae6e drm/panthor: skip zero-sized firmware sections
  • 7ff87a01ae3a fbdev: core: Fix pointer desynchronization in fb_io_read()
  • 2fe7a89b2b5b ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses
  • cc61f0fa2c71 ASoC: cs35l41: sort the register default table
  • 3298f13d1f12 ASoC: cs35l45: sort the register default table
  • d7bd683b0d90 ASoC: cs4265: sort the register default table
  • f2435a46dfa1 ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout
  • 8cba53b862e1 ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked()
  • a30836477479 s390/qeth: validate user buffer length in SNMP and ARP query ioctls
  • 75e564b2ced1 mptcp: fastopen: only mark MPTFO subflows with SYN data
  • 3f8e5eb0c499 mptcp: pm: fix data race in add_addr timer callback
  • 1fade1b2ac5b mptcp: options: reset DSS fields in case of unexpected size
  • a04dcc784959 mptcp: avoid combining some incoming suboptions
  • 0cb3846c26c1 selftests: mptcp: join: mark tests with data corruption as failed
  • 473f1a5ab2ab mptcp: reclaim forward-allocated memory on RX path errors
  • 9b46fba7528f selinux: reject a permission value exceeding the class permission count
  • 841aea4d5a25 selinux: reject an unclaimed class value in security_get_classes()
  • 1b4ff94ae7c5 selinux: do not cancel a policy conversion that never started
  • acd5b09be98f selinux: reject a class permission count below its inherited common
  • 42a7107f99d8 selinux: require every boolean value to be defined
  • 1a4c3ffe2a48 ipvs: separate destination availability state
  • 9ff46bf75bfa ubi: fastmap: fix ubi->fm memory leak
  • 075036cea14a mtd: ubi: skip programming unused bits in ubi headers
  • bb03b56d1d75 block: stop the timeout timer when releasing a never added disk
  • e2c3337c2238 ALSA: hda/realtek: Add quirk for HP Dragonfly Folio G3 2-in-1 (103c:8a05)
View originalPermalink
How 6.18.46-xanmod1 went

7.2.0-xanmod1

Added 15
  • Add sysctl to disallow unprivileged CLONE_NEWUSER by default
  • Enable overrides for missing ACS capabilities in PCI
  • Export file_close_fd() for use by modules
  • Allow __wake_up_pollfree() to be used from GPL modules
  • Add debug mask file for binder_alloc
  • Convert binder into a module
Changed 14
  • Update TCP 'bbr' congestion control module to BBRv3
  • Disable workqueues for crypto ops in dm-crypt
  • Use call_rcu when detaching client in input/evdev
  • Initialize ata before graphics
  • Improve rwsem spin performance
  • Enable stateless firmware loading

From XanMod Kernel

  • 275555fa1bf1 Linux 7.2.0-xanmod1
  • 29d92d1b92fb XANMOD: .gitlab-ci: Add gitlab-ci.yml file
  • f67bfad06094 XANMOD: Add GPLv2 license file
  • 020afb98da2e sysctl: add sysctl to disallow unprivileged CLONE_NEWUSER by default
  • 84598b0cf5c4 PCI: Enable overrides for missing ACS capabilities
  • a4c71e364327 file: export file_close_fd() instead of close_fd_get_file()
  • 049ff525581a wait: allow to use __wake_up_pollfree() from GPL modules
  • d72d6bc52918 binder: give binder_alloc its own debug mask file
  • 2b656afd62ec binder: turn into module
  • 8cba03efea37 mfd: steamdeck: Expose controller board power in sysfs
  • 53f4492f17e1 mfd: Add MFD core driver for Steam Deck
  • 92b109106b84 leds: steamdeck: Add support for Steam Deck LED
  • 4d95534fadd3 hwmon: steamdeck-hwmon: Add support for max battery level/rate
  • 824ae407514e hwmon: Add driver for Steam Deck's EC sensors
  • 8e799663139b extcon: Add driver for Steam Deck
  • 3b4d00f3a7bb netfilter: add xt_FLOWOFFLOAD target
  • 04edf698d915 netfilter: Add netfilter nf_tables fullcone support
  • 2bc6b0895f5c tcp: Add a sysctl to skip tcp collapse processing when the receive buffer is full
  • d50171100f3c tcp_bbr: v3: update TCP 'bbr' congestion control module to BBRv3
  • 9c594ca6d407 ZEN: dm-crypt: Disable workqueues for crypto ops
  • c1f19aa98e54 ZEN: input/evdev: Use call_rcu when detaching client
  • 66b54cff5cba drivers: initialize ata before graphics
  • 1c4833ae5add locking: rwsem: spin faster
  • dce6a5fdd743 firmware: Enable stateless firmware loading
  • 7c6a92846009 sched/wait: Do accept() in LIFO order for cache efficiency
  • 80af49bc67fa mm: Add working set protection for anon and clean file pages
  • 36d9622e03e8 XANMOD: Makefile: Move x86 instruction set selection to kernel-wide build
  • 4bc30ce6728f x86/kconfig: more x86-64 ISA levels and uarches
  • 231777ac25f3 XANMOD: x86/build: Prevent generating avx2 floating-point code
  • 0283427a0a31 XANMOD: scripts/setlocalversion: Move localversion* files to the end
  • 517afee9bc92 XANMOD: scripts/setlocalversion: remove '+' tag for git repo short version
  • f2ef9a46d11b XANMOD: lib/kconfig.debug: disable default SYMBOLIC_ERRNAME and DEBUG_BUGVERBOSE
  • ccc0f7ec88e3 XANMOD: cpufreq: tunes ondemand and conservative governor for performance
  • 5b4df09b709a XANMOD: mm/vmscan: Reduce amount of swapping
  • ed2a9eca2135 XANMOD: mm: Raise max_map_count default value
  • 7ac91c5588e7 XANMOD: vfs: Decrease rate at which vfs caches are reclaimed
  • 0988dbc5822a XANMOD: kconfig: add 500Hz timer interrupt kernel config option
  • 89d0ae046966 XANMOD: blk-wbt: Set wbt_default_latency_nsec() to 2msec
  • bae2948f36c9 XANMOD: block: Set rq_affinity to force complete I/O requests on same CPU
  • fd699380cd6a XANMOD: block/mq-deadline: Disable front_merges by default
  • 3868ed8dbd88 XANMOD: block/mq-deadline: Increase write priority to improve responsiveness
  • b746821c0765 XANMOD: fair: Set scheduler tunable latencies to unscaled
  • 19e5ebe24766 kbuild: Re-add .config file required to sign external modules
  • c9d752c21d51 XANMOD: kbuild: deb-pkg: Create -dbg when make DEB_DEBUG_PKG=1
  • 1d39a03d3382 XANMOD: kbuild: Add SMS-based software pipelining flags
  • 3b40b2850e79 XANMOD: kbuild: Add LLVM polyhedral loop optimizer flags
  • dd21db2d9881 XANMOD: x86/build: Add more CFLAGS optimizations
  • 8d3ae59288f1 Linux 7.2
View originalPermalink
How 7.2.0-xanmod1 went

7.1.9-xanmod1

Fixed 20
  • thunderbolt: Fix bandwidth group reservation indexing
  • thunderbolt: Bound the DROM dual link port number before indexing sw->ports
  • sctp: clear new_transport when removing a peer
  • sctp: fix use-after-free of cached ASCONF chunk
  • sctp: keep chunk->transport in step with the list it is queued on
  • scsi: scsi_debug: Negate wrapped memcmp() result

From XanMod Kernel

  • 762461b8ceec Linux 7.1.9-xanmod1
  • 75350514d3f8 Merge tag 'v7.1.9' into 7.1
  • ffc82ed66531 Linux 7.1.9
  • 0a8c9ed4f166 thunderbolt: Fix bandwidth group reservation indexing
  • f32c3a9a77cf thunderbolt: Bound the DROM dual link port number before indexing sw->ports
  • 163847552a57 sctp: clear new_transport when removing a peer
  • d949992bc3f0 sctp: fix use-after-free of cached ASCONF chunk
  • 5ccf35ef0ed6 sctp: keep chunk->transport in step with the list it is queued on
  • 65a740633570 scsi: scsi_debug: Negate wrapped memcmp() result
  • 1cec526cf0a2 bpf, sockmap: Fix sk_redir use-after-free in send verdict
  • 911d5c32a54c fsverity: Fix silent truncation in bpf_get_fsverity_digest()
  • 5bd63cad9df4 fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions
  • 267ecd2eb775 mm/filemap: __filemap_add_folio() restore index before retrying
  • 0baed1fa2184 ima: Instantiate file_truncate and path_truncate hooks
  • a054c9ffa9b7 sched_ext: Take cgroup_lock() first in scx_cgroup_lock()
  • d217d851f0a2 sched/psi: Create the psimon kthread outside of cgroup_mutex
  • 611e7821c4f8 sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
  • 98516ba8b817 fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()
  • 2d2b2ed7bdcc fs,fsverity: remove check for fsverity being enabled in setattr_prepare()
  • fbf40faa0414 ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
  • da64ed1f346b ipv6: fix Route Information option length validation
  • 4adc4c9a9a43 mm/ptdump: always stabilise against page table freeing using init_mm
  • b726eb3c94d2 mm/page_table_check: skip special zero mappings
  • 5e6e2a18c20e ring-buffer: Use current_context for safe per-CPU buffer swap
  • 3b3e0a6ee5bb ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer()
  • f8d7e5751267 ptp: ocp: Fix board ID over-read
  • 2004172036ec Revert "thermal: hwmon: Register a hwmon device for each thermal zone"
  • 6b446d335ba1 Revert "thermal/drivers/hwmon: Cleanup coding style a bit"
  • c4d0c93d2469 ring-buffer: Prevent resizing of persistent ring buffer
  • 004f7232e497 eventfs: Use children field for rcu head and add memory barriers
  • 74bb1eaf72d1 eventfs: Fix use-after-free in eventfs_remove_rec()
  • 9f7760a2e962 KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page
  • d728baba0f20 KVM: SVM: Serialize accesses to the owner and mirror list with separate lock
  • 79748c9f9b2f smb: client: fix SMB1 TRANS2 multi-response truncation in SendReceive()
  • 1305eadc6a7d smb: client: Fix use-after-free in cifs_try_adding_channels()
  • 5558a8312452 tipc: read le->link under the node lock in tipc_node_link_down()
  • 3c5f8f2aa57c tls: don't leave a full plaintext sk_msg ring unpushed
  • 3c837266a734 tls: rx: restore msg_iter before TLS 1.3 optimistic retry
  • b70ebe0bba25 vhost: reset the vring metadata cache on vring reconfiguration
  • 3205b0652a37 veth: fix skb length accounting after XDP frag adjustment
  • e82a5faea2e3 vsock/virtio: avoid refilling the RX queue after teardown
  • 1cecb4202afd vsock/virtio: read virtqueues under worker locks
  • 6b4119af5449 vxlan: do not arm the ageing timer on a device that is down
  • f463b6f4957c xdp: reject clones that overrun skb_shared_info tailroom
  • 4f4cba3947d2 x86/mce: Set up the polling timer before CMCI discovery
  • da6acd11d2f2 x86/CPU: Add a tlbi= cmdline switch
  • eb0a9fabb924 arm64: remove redundant concurrent ptdump UAF mitigation
  • 2926031acba1 dibs: initialise dibs->lock in dibs_dev_alloc()
  • 496846a94111 Revert "drm/amdgpu: fix aperture mapping leak"
  • 047f927f54c6 binfmt_misc: don't warn when the mount is completed from another user namespace
  • 42d99fcd8006 ovl: don't warn when the mount is completed from another user namespace
  • 2e8df8c91903 net/sched: act_gact, act_police: range check the fallback control action
  • 439d3e404f9d net/sched: act_ct: fix sk_buff leak when the header checks reject a packet
  • 24d87dc28ddd net: atlantic: free RX pages of consumed but not refilled buffers
  • dd633280de7f net: atlantic: free stranded TX buffers on ring deinit
  • c0224327b7cb netfilter: nf_conntrack: defer invalid log until after unlock
  • 7cff440d7026 netfilter: bridge: release template ct on non-IP path
  • 755fd7843f30 NTB: ntb_netdev: Preserve RX queue depth on allocation failure
  • ed08011ae0be net: devmem: prevent net-iov / page mixing
  • e92c7e2b41d1 net/x25: fix use-after-free of the socket by its timers
  • 7a1df20a8d2c net/dibs: Correct freeing of dmb_clientid_arr
  • 14e812ab41df ipv6: prevent in6_dev_get() from resurrecting inet6_dev
  • 4515c78f4d9f net: smc: fix splice entry lifetime imbalance in smc_rx_splice
  • aa03d76252cc net: phy: mediatek: fix TX blink masks using the RX bits
  • ab7e4b407c7f mm/huge_memory: fix huge_zero_pfn race
  • d858f7c9fc51 mm/huge_memory: initialise workingset state before folio split
  • ad4e9dd5fec7 tracing: Fix NULL pointer dereference in module event cache removal
  • 7568e9e717e7 ring-buffer: Prevent subbuf order change when resizing is disabled
  • 9ea879862e66 fbdev: bitblit: bound-check glyph index in bit_cursor()
  • f128740f39ab tracing: Fix race between update_event_fields and, event_define_fields
  • 1e7abfeb23c1 perf/core: Fix group leader use-after-free after sibling detach
  • c22a45817b9c drm/v3d: Serialize the scheduler timeout handlers
  • a5548ce91659 ALSA: us144mkii: re-anchor capture URBs on resubmission
  • 0582952cd6cc ALSA: hda/tas2781: fix ACPI reference handling
  • bb61dc2ae590 ALSA: FCP: fix OOB write in fcp_meter_ctl_get()
  • 5bf5ccddf00b ALSA: usx2y: bound the hwdep mmap fault offset
  • f9d492a39ebe ALSA: usb: Fix UAF at delayed release of MIDI2 EPs
  • 91e4538952a9 mm/damon: adjust isolated pages stat for DAMOS_MIGRATE_{HOT,COLD}
  • 684f271210be samples/damon/mtier: error out for zero quota goal target values
  • cfef454862b7 mm/damon/ops-common: putback folios on invalid migrate nid
  • e7e5e5e0dfe2 mm/damon/lru_sort: error out for >10000 active_mem_bp
  • 3ea2fd344d93 ring-buffer: Fix crash passing ERR_PTR to kthread_stop()
  • eaef442fe68c misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free
  • efd02f8d1a74 misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke
  • 0beaa9bd7eb1 misc: fastrpc: Remove buffer from list prior to unmap operation
  • 03a9cea00b39 misc: fastrpc: fix channel ctx ref leak when session alloc fails
  • 60c1c757fd4f misc: fastrpc: Fix initial memory allocation for Audio PD memory pool
  • bd88f6289b7e staging: rtl8723bs: validate monitor transmit frame lengths
  • 6235b5156b48 staging: rtl8723bs: fix missing shared-key auth challenge length check
  • e429c6dfd5d2 staging: rtl8723bs: fix OOB read in WMM_param_handler()
  • 01ab275f8f3e staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()
  • fdfb46c38724 serial: amba-pl011: synchronize DMA teardown
  • e57f0aa5c35b serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ
  • b49a43ebace1 serial: amba-pl011: fix indefinite RS485 post-send delay
  • 7795e8abedc8 serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx
  • e7e3cc6709ca serial: 8250_dma: Clear stale RX state on shutdown
  • b449429e9e78 serial: sc16is7xx: enable THRI before filling TX FIFO
  • b1801c0d40f6 serial: qcom-geni: fix TX DMA buffer flush
  • 5f1d56be1e9c rust_binder: do not query current thread for all ioctls
  • 1149ce318c2b nvmem: layouts: Add fixed-layout driver
  • d11b12dcdce9 nvmem: apple-spmi-nvmem: wrap regmap calls to satisfy CFI
  • d88678d3fcb0 mei: pull kvfree out of spinlock
  • ed503eaad62f ipv4: fix use-after-free in fib_nhc_update_mtu()
  • 9b22f13524fa ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops
  • 1dd48303931b selftests/bpf: Adapt sockmap update error handling
  • 8cf744abef6a selftests/bpf: Ensure UDP sockets are bound
  • 781d944ca910 Bluetooth: btusb: Add TP-Link UB600 for Realtek 8761BUV
  • d5977f4f995e Bluetooth: btrtl: fix RTL8761B/BU broken LE extended scan
  • e828321f9cfa selftests/xsk: account reclaimed invalid Tx descriptors
  • 6d419a03249c selftests/xsk: fix too-many-frags multi-buffer Tx test
  • 7cf710e70f9b futex: Prevent robust futex exit race some more
  • 86e48e822111 Revert "drm/amd/display: Fix backlight max_brightness to match exported range"
  • e08665218040 net: bridge: mrp: fix uninitialised bytes on the wire
  • e2ab7e878bdb netfilter: ebt_nflog: pin the NFLOG backend
  • ef365e8f9c24 igc: fix netdev not re-attached after resume if interface is down
  • 9d067e581597 mac802154: fix netdev use-after-free in beacon worker
  • 928128865e43 inet: frags: publish queues before arming timer
  • fc902f52a022 net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header
  • 3010b7f13647 net: octeontx2-pf: Fix UB in shift operation
  • e2d658c64278 net/sched: reject overly deep qdisc hierarchies
  • 20751193d83b net: openvswitch: reallocate update replies for mismatched IDs
  • ea1ccd6d1c63 net: fix skb length accounting after generic XDP frag adjustment
  • a08196c3cc10 packet: synchronize pressure clearing with ring reconfiguration
  • fdd4d7d52358 net/packet: reset the MAC header on the packet-socket transmit path
  • d48ea5c9c4c3 packet: use consistent hard_header_len in TX_RING send path
  • b06b6fce6d7d packet: use consistent hard_header_len in non-ring send paths
  • 384b4dae1427 ipvs: clear IPv4 options after rebasing tunnel ICMP errors
  • ad8439a21081 ipvs: separate destination availability state
  • bc1286dca5a4 ipvs: properly update the overload flag on dest edit
  • 7c3fdb37de14 ipvs: add totalconns for dest
  • 2335dedc1922 ipvs: stop estimator after disabled calc phase
  • dd04114af0d4 ima: fix out-of-bounds read in xattr_verify()
  • 3cc26c8907db mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF
  • 7e55ca1080f0 Input: evdev - fix information leak in evdev_pass_values()
  • 0b8ff21cbda8 mm: fix incorrect flush address in direct page table reclaim
  • cc4a1a2ce0c5 vt: stabilize tty reference in kbd_keycode with tty_port_tty_get
  • 7bf32337a710 vt: add permission check for KDSKBMETA ioctl
  • fdbf547d91bf usbnet: cap max_mtu for drivers without bind callback
  • 48303f3ae0fa net: usb: ipheth: fix carrier_work UAF on disconnect
  • 4039cd807a5a net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()
  • fc9e54e22845 usb: gadget: f_ncm: Use unsigned int for ndp_index
  • 4364486f249c usb: cdnsp: fix incorrect endian conversions for APB timeout register
  • 4e9b490e555e thunderbolt: icm: Preserve USB4 proxy data-valid bit
  • 0b1ea726c987 usb: xhci: use BIT_ULL for CRCR bits to fix incorrect 64bit mask
  • 0af047703dbe usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
  • 9ad0164f78b6 usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg
  • 7436fb2bed66 usb: quirks: Add ShanWan gamepad to quirk list
  • 015e71a1b565 usb: core: Add quirk for 255-bytes initial config read
  • d3ed4e6321bb ALSA: usb-audio: fix OOB write on Type II inbound URBs
  • 810e1883d481 Input: evdev - sanitize event type index when fetching event masks
  • 164c31ee252e net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp()
  • 4870189064dd ALSA: usb-audio: Fix sticky mixer regressions on M-Audio Fast Track Ultra
  • e732c3b62465 hwmon: (corsair-psu) serialize debugfs access against hwmon
  • 50401a9ac8ef hwmon: Support guard() and scoped_guard for subsystem locks
  • c1ab527775e0 hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt
  • 046e56b53c09 hwmon: (ltc4282) Clamp negative current limits
  • 87a58da555f3 hwmon: (ltc4282) Avoid overflow in maximum power calculation
  • 1d43e4ce054b hwmon: (ads7828) Fix external VREF regulator handling
  • e81580057e98 hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination
  • f54667b0c162 rqspinlock: Reset tail when preserving queue on deadlock
  • b7949b0a7d99 watchdog: at91sam9_wdt: prevent timer rearm during teardown
  • 8a4713fe08b0 tls: don't abort the connection on signal-interrupted sends
  • 4d6b9cac6df5 sctp: clear control chunk transport if it is being removed
  • 2c5988c7349c net/atm: fix slab-out-of-bounds read in vcc_setsockopt()
  • 774394d27930 s390/ism: Fix UAF of sba and ieq during ism_dev_exit()
  • a294c0aa5741 bnge: Fix resource leak in bnge_init_nic() error path
  • 56fd78c8c820 ata: pata_sl82c105: fix bridge revision use-after-free
  • 9a482b2b117e net: thunderbolt: Tear down DMA paths before stopping the rings
  • 764b422116d7 net: qrtr: ns: Raise lookup limit to 128
  • ff5bcd804b5b net/smc: fix TOCTOU race between smc_listen_out() and listener close
  • 0d75f2c1d076 net: remove WARN_ON_ONCE() from sk_mc_loop()
  • 7fa8a12296d8 net: prestera: validate firmware header length
  • 3a60b5af75ab net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length
  • 538e67e8c788 netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()
  • d974618b2097 tcp: fix TFO max_qlen accounting across reuseport migration
  • 23f682083aa3 bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie
  • 9e61709d8dc8 sctp: fix addip_serial increment on ASCONF_ACK allocation failure
  • 39d56ee7db0b bnxt_en: Fix PTP PPS setting bug
  • c1962ab4645a bnxt_en: Disable EOP for TPA on all chips to prevent data corruption
  • 04550ca58622 bnxt_en: Refresh VNIC default ring on queue restart if needed
  • a6b1bf29ec40 bnxt_en: Determine and store default RX ring in vnic structure
  • 2daf5903b946 bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss()
  • d2897717cd22 net/mlx5e: fix BQL reset on SQ re-activation
  • 41661a81be9b bnge: use int for bnge_fix_rings_count() return value
  • 937f785910ce net: stmmac: resume PHY before hardware setup when opening the interface
  • 6db775482108 selftests/ftrace: refactor eprobes test to fix argument checks
  • eeaddd910841 hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations
  • c36f2c22ffdf hwmon: (nzxt-smart2) Check return value of init_device() in probe
  • 961d25b77dd0 drm/xe/uc: Apply RCS/CCS yield policy to SR-IOV VFs
  • 410596743958 drm/xe: Fix memory leak in exec_queue_set_hang_replay_state()
  • a81f9c44d87f net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers
  • 9b8cfbb58b85 net/openvswitch: check Ethernet header length in key_extract()
  • 9a3eb77a612f vhost-scsi: reject feature changes after endpoint
  • f8fe3f8d342d vhost-scsi: Validate T10 PI scatterlist counts
  • a1ae353d8355 net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter
  • 588d4a6795d9 udp: fix potential use-after-free in tunnel segmentation
  • 83ef2f3cab7f bnge: Fix NULL pointer dereference in aux device release
  • 0cc7aa6e0d19 xsk: validate metadata when processing requests
  • 7806d4885c53 xsk: move xsk_tx_metadata_request() to xdp_sock_drv.h
  • bc63d47611c0 xsk: validate launch-time metadata size
  • eb4c613d4ebc xsk: clear metadata pointer when no timestamp is requested
  • 8948aab6c349 xsk: pass TX metadata pointer by reference
  • cfb9d2976b27 xsk: require at least 16 bytes of TX metadata
  • b478ff6edf58 bnxt: fix memory leak in bnxt_queue_mem_alloc error cases
  • d01923852e52 tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss()
  • 0b121de89a99 hwmon: (pmbus) Fix type confusion in notification logic
  • 5112365c6820 hwmon: (pmbus/core) Avoid race condition during probe
  • 6c8a9f7bc003 vdpa/mlx5: Fix buffer length in create_direct_keys()
  • bb9122ba4dc4 vhost/vdpa: reject overflowing PA map page counts on 32-bit
  • ae128dd19040 vhost_iotlb: bound map allocation in add_range
  • 95dc716ca52b ALSA: usb-audio: Add QUIRK_FLAG_MIXER_GET_CUR_BROKEN for Logitech PRO X 2 LIGHTSPEED
  • e3668bb2d152 ALSA: usb-audio: Add QUIRK_FLAG_MIXER_GET_CUR_BROKEN
  • 97e74d3e45d6 bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()
  • 99eb9bb12adb counter: microchip-tcb-capture: Fix DT channel validation
  • e5e060eb63d1 bpf: Fix netns reference imbalance in conntrack kfuncs
  • 13339132d89d accel/amdxdna: Fix locally exploitable BUG_ON in amdxdna_insert_pages()
  • 4aafa600d93e net/mlx5: fw_tracer, return NULL on create error
  • eda60c85b4f4 devlink: fix net namespace reference leak in reload
  • 49053a39815f net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete
  • ae9aff870252 net/sched: cls_route: fix fastmap use-after-free on filter
  • bfc336a9fbbf net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()
  • d90e72e5e0f9 bpf: Propagate untrusted pointer state in commuted arithmetic
  • eaffa1495e4f bpf: Preserve pointer state for commuted arithmetic
  • 1501e4d07c6f accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages()
  • 0d2624967117 btrfs: initialize inode mapping flags for cached inodes
  • 60b50ceba624 btrfs: fix memory leak in btrfs_do_encoded_write()
  • fc50b475ad27 btrfs: lzo: reject inline extents without valid headers
  • ffa355d5dff3 btrfs: lzo: add error message for invalid headers
  • ba3e2d9584a4 watchdog: bd96801_wdt: Fix timeout for enabled WDG
  • 369faf64ccbc ipvs: return the csum validation for forward hook
  • 243d0187ec4c ipvs: avoid out-of-bounds write in ip_vs_nat_icmp
  • 3d450788dc04 netfilter: ipset: switch ext_size to atomic64_t
  • 14328d1ecdda pds_core: cancel pending PCI reset work on AER recovery
  • 8530ea7ac96c pds_core: keep the health thread stopped during reset
  • 7165fe321c61 net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock
  • 4f3464fc6c1f enic: fix tx_hang_reset use-after-free on device removal
  • 257c4a3a34d8 bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor
  • e18f8d166a7c Revert "net: thunderbolt: Enable end-to-end flow control also in transmit"
  • fe450066628e net: hns3: fix speed configuration residue after driver reload
  • a272a3d3129d drm/bridge: ps8640: propagate AUX transfer register errors
  • e71780593647 ovpn: fix incorrect use of rcu_access_pointer()
  • af82e1375513 ovpn: ensure TCP vars are initialized first
  • ac5cce2e9557 ovpn: disable IPv4 redirects on MP interfaces
  • 844616a78baa ovpn: hash floated peer by transport identity only
  • 21a2eda3fcc6 ovpn: zero-initialize sockaddr before learning a floated endpoint
  • 43a31142e1d2 ovpn: ensure socket is owned by ovpn before deref sk_user_data
  • 4bc1c83a2e04 ovpn: rehash peer in by_transp_addr table on CMD_PEER_SET
  • 667454802987 ovpn: skip rehash for peers already removed from by_id
  • 8730ac05b2c5 ARM: dts: BCM5301X: fix PCIe controller 2 second interrupt
  • 147ebe15f955 ovpn: add missing rtnl_link_ops->get_size callback
  • f5d2914f93c2 pinctrl: qcom: ipq806x: mark pci reset as a GPIO pin function
  • 617724534a83 pinctrl: qcom: ipq806x: mark gpio as a GPIO pin function
  • 576b1c202fa0 selftests/sched_ext: Handle sleeping task affinity changes in numa test
  • 5edc5e1df6c0 ARM: npcm: Fix OF node refcount leaks in SMP setup
  • 3aa0c1d23ee1 xfs: handle NULL b_addr in xfs_buf_free
  • 131ab677b033 soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read
  • d2c8160da4e5 arm64: dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer
  • b77bd3f067a0 NFS: Decrement refcounts if allocating nfs_free_stateid_data fails
  • 80ed3d762628 NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
  • 517b1e4fe28b sched_ext: Don't enable non-ext tasks in the sub-sched task loops
  • 6428093a4a98 sched_ext: Skip sub-disable teardown for never-linked sub-schedulers
  • 592bc5000d6b sched_ext: Reject setting disallow from init_task outside the enable path
  • de6f2b6c8d22 arm64: dts: qcom: sdm850-lenovo-yoga-c630: lower PSCI cluster idle
  • 0a234a9a5c1e arm64: dts: qcom: sm8650: Fix IPA IMEM slice
  • 1d724dc6193c arm64: dts: qcom: monaco: Add default GIC address cells
  • d15ef483c54d arm64: dts: qcom: purwa: Fix GPU IOMMU property
  • 04d06aa023e3 arm64: dts: qcom: glymur: fix QUP serial engine IRQs
  • f7b52b18c04d arm64: dts: qcom: glymur: fix PCIe SMMU interrupts
  • 5edbb409b0bc drm/amd/display: Check for tg ops in dce110_set_avmute
  • 9d64e8854f5e drm/amd/display: Add AV mute wait frames to dce110_set_avmute
  • e6a2f5f845f5 gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock
  • 7fd0235c438c selftests/bpf: Add tests for sleepable tracepoint programs
  • 070d4ce6776f selftests/bpf: Fail unbound UDP on sockmap update
  • 300bb214c938 mount: honour SB_NOUSER in the new mount API
  • 62e211a80cfd XANMOD: Add GPLv2 license file
View originalPermalink
How 7.1.9-xanmod1 went

6.18.45-xanmod1

Fixed 20
  • netfilter: flowtable: ensure sufficient headroom in xmit path
  • netfilter: always set route tuple out ifindex
  • thunderbolt: Fix bandwidth group reservation indexing
  • thunderbolt: Bound the DROM dual link port number before indexing sw->ports
  • sctp: clear new_transport when removing a peer
  • sctp: fix use-after-free of cached ASCONF chunk

From XanMod Kernel

  • e1e49f488a1c Linux 6.18.45-xanmod1
  • 474774fc02c5 Merge tag 'v6.18.45' into 6.18
  • bf3be28f6721 Linux 6.18.45
  • 1eb0dc458b6e netfilter: flowtable: ensure sufficient headroom in xmit path
  • 99ec511f258e netfilter: always set route tuple out ifindex
  • 9977321835c7 thunderbolt: Fix bandwidth group reservation indexing
  • 40d2ffb74094 thunderbolt: Bound the DROM dual link port number before indexing sw->ports
  • ca33df36aa01 sctp: clear new_transport when removing a peer
  • 07daf4f97501 sctp: fix use-after-free of cached ASCONF chunk
  • 2b3b5eec8b2c sctp: keep chunk->transport in step with the list it is queued on
  • 3bd46d33e3fd scsi: scsi_debug: Negate wrapped memcmp() result
  • a14e4ef1d90c bpf, sockmap: Fix sk_redir use-after-free in send verdict
  • 3c6d4ffa0c6d fsverity: Fix silent truncation in bpf_get_fsverity_digest()
  • 2a5cfcad1d56 fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions
  • 4917e3ebcab5 mm/filemap: __filemap_add_folio() restore index before retrying
  • dd21c96a71e8 ima: Instantiate file_truncate and path_truncate hooks
  • 102fb2dacf45 sched/psi: Create the psimon kthread outside of cgroup_mutex
  • 8037c5b2b2a4 sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
  • 653e888a24c8 fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()
  • 4eb15c465337 ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
  • 3b2231e358d2 ipv6: fix Route Information option length validation
  • 7f740664aec1 mm/ptdump: always stabilise against page table freeing using init_mm
  • 5b926fb04cb9 ring-buffer: Use current_context for safe per-CPU buffer swap
  • 2e37f2bf1114 ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer()
  • 5fd91dd4a143 ptp: ocp: Fix board ID over-read
  • 8d34019d1413 Revert "thermal/drivers/hwmon: Cleanup coding style a bit"
  • 5635211b4496 eventfs: Fix use-after-free in eventfs_remove_rec()
  • 66bc868a33cf KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page
  • 47976eaaf0a4 KVM: SVM: Serialize accesses to the owner and mirror list with separate lock
  • 1ffacbadc145 smb: client: Fix use-after-free in cifs_try_adding_channels()
  • c3f2347a4775 tipc: read le->link under the node lock in tipc_node_link_down()
  • 3fc5044796dd tls: don't leave a full plaintext sk_msg ring unpushed
  • 68787940274e tls: rx: restore msg_iter before TLS 1.3 optimistic retry
  • f1e21108e3dd vhost: reset the vring metadata cache on vring reconfiguration
  • cdf745b7a777 veth: fix skb length accounting after XDP frag adjustment
  • 38c7763fdc53 vsock/virtio: avoid refilling the RX queue after teardown
  • bd43a7ec668b vsock/virtio: read virtqueues under worker locks
  • 46bb297ad776 vxlan: do not arm the ageing timer on a device that is down
  • fab820f1691a xdp: reject clones that overrun skb_shared_info tailroom
  • e708fc1566eb x86/mce: Set up the polling timer before CMCI discovery
  • 846b92e26c8a x86/CPU: Add a tlbi= cmdline switch
  • 69298af46f39 arm64: remove redundant concurrent ptdump UAF mitigation
  • fe79571f4043 dibs: initialise dibs->lock in dibs_dev_alloc()
  • a2e326c52c4b Revert "drm/amdgpu: fix aperture mapping leak"
  • 24e95a24f151 binfmt_misc: don't warn when the mount is completed from another user namespace
  • be161fa31e3e ovl: don't warn when the mount is completed from another user namespace
  • 92f00f1d4d20 net/sched: act_gact, act_police: range check the fallback control action
  • b47bb899e04b net/sched: act_ct: fix sk_buff leak when the header checks reject a packet
  • 782cc40b7ade net: atlantic: free RX pages of consumed but not refilled buffers
  • b13202d401e1 net: atlantic: free stranded TX buffers on ring deinit
  • 0424186d570a netfilter: nf_conntrack: defer invalid log until after unlock
  • c58d34fe8b7e netfilter: bridge: release template ct on non-IP path
  • e9bfe12b1d04 net: devmem: prevent net-iov / page mixing
  • 4bc522b33438 net/x25: fix use-after-free of the socket by its timers
  • ece6426b6124 net/dibs: Correct freeing of dmb_clientid_arr
  • 680fbd794218 ipv6: prevent in6_dev_get() from resurrecting inet6_dev
  • 0b7d54cedea5 net: smc: fix splice entry lifetime imbalance in smc_rx_splice
  • b65c11bc6221 net: phy: mediatek: fix TX blink masks using the RX bits
  • 105d04edbec8 mm/huge_memory: fix huge_zero_pfn race
  • 152a00440dc6 tracing: Fix NULL pointer dereference in module event cache removal
  • 62978cf63479 ring-buffer: Prevent subbuf order change when resizing is disabled
  • bc9db0d879c6 fbdev: bitblit: bound-check glyph index in bit_cursor()
  • ed49684e69f8 tracing: Fix race between update_event_fields and, event_define_fields
  • a979a642402d perf/core: Fix group leader use-after-free after sibling detach
  • 5884851a096d drm/v3d: Serialize the scheduler timeout handlers
  • 7779249561d1 ALSA: us144mkii: re-anchor capture URBs on resubmission
  • a6b79dff1cc1 ALSA: hda/tas2781: fix ACPI reference handling
  • bb30e35c36ed ALSA: FCP: fix OOB write in fcp_meter_ctl_get()
  • f75d6f61f0d9 ALSA: usx2y: bound the hwdep mmap fault offset
  • d217d723c5e4 ALSA: usb: Fix UAF at delayed release of MIDI2 EPs
  • 976da5475472 mm/damon: adjust isolated pages stat for DAMOS_MIGRATE_{HOT,COLD}
  • e16b8d640ec9 samples/damon/mtier: error out for zero quota goal target values
  • 460181e4bb47 mm/damon/ops-common: putback folios on invalid migrate nid
  • 6dd7a06894d6 ring-buffer: Fix crash passing ERR_PTR to kthread_stop()
  • 688c71bed685 misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free
  • af6345159abc misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke
  • 9bf22a7d950c misc: fastrpc: Remove buffer from list prior to unmap operation
  • c5a03c2cadd2 misc: fastrpc: fix channel ctx ref leak when session alloc fails
  • cd02b9386315 misc: fastrpc: Fix initial memory allocation for Audio PD memory pool
  • 8b3e4ed9c35d staging: rtl8723bs: validate monitor transmit frame lengths
  • a28a4b0592e4 staging: rtl8723bs: fix missing shared-key auth challenge length check
  • e5b7610008f4 staging: rtl8723bs: fix OOB read in WMM_param_handler()
  • e167a38a8a8f staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()
  • 5974cb66681e serial: amba-pl011: synchronize DMA teardown
  • 759ead98a39f serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ
  • 2a0ee25f75cd serial: amba-pl011: fix indefinite RS485 post-send delay
  • 3ce24bc4d115 serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx
  • ae05d9e50b6b serial: 8250_dma: Clear stale RX state on shutdown
  • 1c31e2377f4c serial: qcom-geni: fix TX DMA buffer flush
  • dd6946a70ddb rust_binder: do not query current thread for all ioctls
  • 9dbe1d011189 nvmem: layouts: Add fixed-layout driver
  • da59844f561d nvmem: apple-spmi-nvmem: wrap regmap calls to satisfy CFI
  • 104c2e8b8e38 mei: pull kvfree out of spinlock
  • 63996ffc594d ipv4: fix use-after-free in fib_nhc_update_mtu()
  • a59edda6eda1 ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops
  • 94166072975a selftests/bpf: Adapt sockmap update error handling
  • edee58a9c460 selftests/bpf: Ensure UDP sockets are bound
  • dc0c462fa838 Bluetooth: btusb: Add TP-Link UB600 for Realtek 8761BUV
  • 373d425f7638 Bluetooth: btrtl: fix RTL8761B/BU broken LE extended scan
  • 8545f4ef9eae netfilter: nf_tables: avoid softlockup warnings in nft_chain_validate
  • 7b8c53263f88 futex: Prevent robust futex exit race some more
  • cf8a9672fc25 iommu/vt-d: Gather the unmapped range before freeing its page tables
  • 643b410bdfa4 dt-bindings: crypto: qcom,ice: Fix missing power-domain and iface clk
  • 8d817ef1aa4e KVM: s390: pci: Fix aisb calculation
  • cf895cd72e40 blk-mq: reinsert cached request to the list
  • 97e2d08de282 blk-mq: pop cached request if it is usable
  • 59b07ccca4c0 Revert "drm/amd/display: Fix backlight max_brightness to match exported range"
  • 5912cf1822fb net: bridge: mrp: fix uninitialised bytes on the wire
  • 47a119ec8a7e netfilter: ebt_nflog: pin the NFLOG backend
  • a0e76de6a2f2 igc: fix netdev not re-attached after resume if interface is down
  • e6cd416a899e mac802154: fix netdev use-after-free in beacon worker
  • 9f904dd3e455 inet: frags: publish queues before arming timer
  • dbb30dc943a9 net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header
  • 99ae2239069e net: octeontx2-pf: Fix UB in shift operation
  • a4b14a4df29d net/sched: reject overly deep qdisc hierarchies
  • 23716dd9d8d4 net: openvswitch: reallocate update replies for mismatched IDs
  • 5f30f9c302ce net: fix skb length accounting after generic XDP frag adjustment
  • 2c7b5eb87b2b packet: synchronize pressure clearing with ring reconfiguration
  • 971aa7d99242 net/packet: reset the MAC header on the packet-socket transmit path
  • 27e068d1b35d packet: use consistent hard_header_len in TX_RING send path
  • 5bb10753d428 packet: use consistent hard_header_len in non-ring send paths
  • 75eec935444d ipvs: clear IPv4 options after rebasing tunnel ICMP errors
  • 0f88fe0552be ipvs: properly update the overload flag on dest edit
  • 59b90c17bec5 ipvs: add totalconns for dest
  • e7f34f29b330 ipvs: stop estimator after disabled calc phase
  • 27f392406159 ima: fix out-of-bounds read in xattr_verify()
  • c5bf8cd148cf mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF
  • bd3c4108a56d Input: evdev - fix information leak in evdev_pass_values()
  • b664592e9ba8 vt: stabilize tty reference in kbd_keycode with tty_port_tty_get
  • a1c31e026c93 vt: add permission check for KDSKBMETA ioctl
  • 2c7496124e94 net: usb: ipheth: fix carrier_work UAF on disconnect
  • 58733b1dd46b net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()
  • d328fdc607fa usb: gadget: f_ncm: Use unsigned int for ndp_index
  • 2dfefdd498ab usb: cdnsp: fix incorrect endian conversions for APB timeout register
  • 6e4c09bea8e9 thunderbolt: icm: Preserve USB4 proxy data-valid bit
  • 2f73a065791d usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
  • ebfd1e82ab0a usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg
  • 04b71290fb41 usb: quirks: Add ShanWan gamepad to quirk list
  • 1740fd2aaa8f usb: core: Add quirk for 255-bytes initial config read
  • 0a235379825e ALSA: usb-audio: fix OOB write on Type II inbound URBs
  • 4034ef247a9d Input: evdev - sanitize event type index when fetching event masks
  • 8b444b126cd8 net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp()
  • fad7cecb5c2c net: fec: do not release NULL pages when RX buffer allocation fails
  • c768fb2e43c8 hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt
  • de58b90a4d14 hwmon: (ltc4282) Clamp negative current limits
  • 124bd4b00619 hwmon: (ltc4282) Avoid overflow in maximum power calculation
  • 678a76c8fd33 hwmon: (ads7828) Fix external VREF regulator handling
  • 5ee1f603a64b hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination
  • 29fe74c9aa69 watchdog: at91sam9_wdt: prevent timer rearm during teardown
  • 6d1d3ca6c8f4 tls: don't abort the connection on signal-interrupted sends
  • 18d704bdd809 sctp: clear control chunk transport if it is being removed
  • 9f77c1ab3821 net/atm: fix slab-out-of-bounds read in vcc_setsockopt()
  • fc3021284050 s390/ism: Fix UAF of sba and ieq during ism_dev_exit()
  • 8fa684db8709 bnge: Fix resource leak in bnge_init_nic() error path
  • a837deeaa37c ata: pata_sl82c105: fix bridge revision use-after-free
  • 4dd71cb0d23d net: thunderbolt: Tear down DMA paths before stopping the rings
  • 78e5ebcd1c10 net/smc: fix TOCTOU race between smc_listen_out() and listener close
  • c8f256dc8492 net: remove WARN_ON_ONCE() from sk_mc_loop()
  • 363e048a9d0a net: prestera: validate firmware header length
  • 02226af69362 net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length
  • 12afa450a6a6 netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()
  • 25d40cf9dab1 netfilter: flowtable: consolidate xmit path
  • a66e869cf0c9 tcp: fix TFO max_qlen accounting across reuseport migration
  • 6c24ec01fb76 sctp: fix addip_serial increment on ASCONF_ACK allocation failure
  • 1e8f24b1e3fe bnxt_en: Fix PTP PPS setting bug
  • aab3b5f4d8ec bnxt_en: Disable EOP for TPA on all chips to prevent data corruption
  • 6a2e50924e57 bnxt_en: Refresh VNIC default ring on queue restart if needed
  • f1a4e95e296b bnxt_en: Determine and store default RX ring in vnic structure
  • 965c45be24e1 bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss()
  • 88664c48d7d1 net/mlx5e: fix BQL reset on SQ re-activation
  • beb47092fe8f bnge: use int for bnge_fix_rings_count() return value
  • 4901b23b5ca7 net: stmmac: resume PHY before hardware setup when opening the interface
  • 99b7bcee0158 selftests/ftrace: refactor eprobes test to fix argument checks
  • a7a00ecf5424 hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations
  • 2e5ea8272cea hwmon: (nzxt-smart2) Check return value of init_device() in probe
  • 9fccf43f0531 drm/xe/uc: Apply RCS/CCS yield policy to SR-IOV VFs
  • d6222af7274f net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers
  • a8139285c892 net/openvswitch: check Ethernet header length in key_extract()
  • a06e4611d455 vhost-scsi: reject feature changes after endpoint
  • 2417a498cf3f vhost-scsi: Validate T10 PI scatterlist counts
  • cd2f1d9fe8a5 net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter
  • 64d322c28857 udp: fix potential use-after-free in tunnel segmentation
  • 5fd121971912 xsk: validate metadata when processing requests
  • 1a1534cc3b41 xsk: move xsk_tx_metadata_request() to xdp_sock_drv.h
  • af511afa1d29 xsk: validate launch-time metadata size
  • 0ba2e1eb07a8 xsk: clear metadata pointer when no timestamp is requested
  • 5ec4f525373b xsk: pass TX metadata pointer by reference
  • 642c6e73fce1 xsk: require at least 16 bytes of TX metadata
  • b0b7202f751b bnxt: fix memory leak in bnxt_queue_mem_alloc error cases
  • ad9ffc61fafe eth: bnxt: support qcfg provided rx page size
  • cd5485a702ef eth: bnxt: store rx buffer size per queue
  • 9c1406e2ecd2 net: pass queue rx page size from memory provider
  • b3fecb888e94 net: add bare bone queue configs
  • 96197286b0ac net: reduce indent of struct netdev_queue_mgmt_ops members
  • 34debe05685d bnxt_en: Do not set EOP on RX AGG BDs on 5760X chips
  • 5ba1a458c5e2 tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss()
  • 821f6416e697 hwmon: (pmbus) Fix type confusion in notification logic
  • 11720d869be1 hwmon: (pmbus_core) Use guard() for mutex protection
  • cde8931a2539 vdpa/mlx5: Fix buffer length in create_direct_keys()
  • a1c236b385d8 vhost/vdpa: reject overflowing PA map page counts on 32-bit
  • cefcbbe20846 bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()
  • 846ce792b6dd counter: microchip-tcb-capture: Fix DT channel validation
  • 80094352bd40 net/mlx5: fw_tracer, return NULL on create error
  • 7b02c6d2a3cd devlink: fix net namespace reference leak in reload
  • 1efcc7114009 net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete
  • 0e7a8cf8895b net/sched: cls_route: fix fastmap use-after-free on filter
  • 10cb31b2b74c net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()
  • d8a6f7993520 bpf: Propagate untrusted pointer state in commuted arithmetic
  • c2da73a1f715 bpf: split check_reg_sane_offset() in two parts
  • db6382ed3361 bpf: Preserve pointer state for commuted arithmetic
  • 24a8f2c29aeb btrfs: fix memory leak in btrfs_do_encoded_write()
  • 26e968526eb5 watchdog: bd96801_wdt: Fix timeout for enabled WDG
  • b3ff48c4ea8b ipvs: return the csum validation for forward hook
  • a69a4b3fff58 ipvs: avoid out-of-bounds write in ip_vs_nat_icmp
  • 1e8a5467a7a7 netfilter: ipset: switch ext_size to atomic64_t
  • 970e9494f44a pds_core: cancel pending PCI reset work on AER recovery
  • ef8e37ac448d pds_core: keep the health thread stopped during reset
  • ff9e7d5e3500 net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock
  • e506e704b747 enic: fix tx_hang_reset use-after-free on device removal
  • 2faf75a8a065 bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor
  • 35ddcc856b5b Revert "net: thunderbolt: Enable end-to-end flow control also in transmit"
  • d512823059af net: hns3: fix speed configuration residue after driver reload
  • 8701a643db23 drm/bridge: ps8640: propagate AUX transfer register errors
  • d47212d86690 ovpn: fix incorrect use of rcu_access_pointer()
  • 54dd83f24b91 ovpn: ensure TCP vars are initialized first
  • f34949d63cbb ovpn: disable IPv4 redirects on MP interfaces
  • e774f7d8fc73 ovpn: hash floated peer by transport identity only
  • 9a776388ef8d ovpn: zero-initialize sockaddr before learning a floated endpoint
  • 61fb3cca40ff ovpn: ensure socket is owned by ovpn before deref sk_user_data
  • 157164812a0c ovpn: rehash peer in by_transp_addr table on CMD_PEER_SET
  • d20c18108898 ovpn: skip rehash for peers already removed from by_id
  • 9e5e88fbfc87 ARM: dts: BCM5301X: fix PCIe controller 2 second interrupt
  • 92b9d92a35a0 ovpn: add missing rtnl_link_ops->get_size callback
  • d740dea9e255 pinctrl: qcom: ipq806x: mark pci reset as a GPIO pin function
  • 23c94a468efe pinctrl: qcom: ipq806x: mark gpio as a GPIO pin function
  • 913d2295b772 selftests/sched_ext: Handle sleeping task affinity changes in numa test
  • ce0212d230bd ARM: npcm: Fix OF node refcount leaks in SMP setup
  • ccf6738adcaf xfs: handle NULL b_addr in xfs_buf_free
  • d90599a42f6c arm64: dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer
  • d71dfffa512e NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
  • bd45b89d7346 arm64: dts: qcom: sdm850-lenovo-yoga-c630: lower PSCI cluster idle
  • df9d22383d7c arm64: dts: qcom: purwa: Fix GPU IOMMU property
  • 7a6e90afb696 arm64: dts: qcom: rename x1p42100 to purwa
  • 1e2b408c1a76 arm64: dts: qcom: Rework X1-based Asus Zenbook A14's displays
  • 387edbe4706b arm64: dts: qcom: rename x1e80100 to hamoa
  • d089f32d34f8 drm/amd/display: Check for tg ops in dce110_set_avmute
  • 8aba384bfc8a drm/amd/display: Add AV mute wait frames to dce110_set_avmute
  • 50359c42e0eb selftests/bpf: Fail unbound UDP on sockmap update
  • 62fefb817bb3 sched/fair: Revert 6d71a9c61604 ("sched/fair: Fix EEVDF entity placement bug causing scheduling lag")
  • 4043e196dc88 sched/fair: Separate se->vlag from se->vprot
  • 9a3eef676cd8 mount: honour SB_NOUSER in the new mount API
  • 79a45d44323b KVM: s390: pci: Fix resource leak on IRQ registration failure
View originalPermalink
How 6.18.45-xanmod1 went

7.1.8-xanmod1

Added 1
  • media: chips-media: wave5: Support CBP profile
Changed 7
  • drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse]
  • drm/xe: Set TTM device beneficial_order to 9 (2M)
  • drm/xe: Separate early xe_device initialization
  • drm/xe: Move xe->info.devid|revid initialization
  • drm/xe: Move xe->info.force_execlist initialization
  • drm/xe: Drop unused param from xe_device_create()
  • usb: typec: ucsi: split connector lock classes
Fixed 11
  • usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path
  • drm/amd/display: Exit idle optimizations before programming
  • drm/amd/display: check GRPH_FLIP status before sending event
  • drm/xe: Wait on external BO kernel fences in exec IOCTL
  • usb: typec: ucsi: Fix race condition and ordering in port unregistration
  • drm/xe/rtp: Ensure locking/ref counting for OA whitelists
Security 1
  • drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE

From XanMod Kernel

  • a8992243188e Linux 7.1.8-xanmod1
  • 5dea5c12fecb Merge tag 'v7.1.8' into 7.1
  • 25c76bea853d Linux 7.1.8
  • bed97cd6f0ea usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path
  • 971962e96618 drm/amd/display: Exit idle optimizations before programming
  • be5c6ca1924a drm/amd/display: check GRPH_FLIP status before sending event
  • c1a029cb1aeb media: chips-media: wave5: Support CBP profile
  • 5d363d00bc97 drm/xe: Wait on external BO kernel fences in exec IOCTL
  • 1366bf0496c2 drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse]
  • 3e891bfe08b4 drm/xe: Set TTM device beneficial_order to 9 (2M)
  • 15dfb66b557a drm/xe: Separate early xe_device initialization
  • 805dcf380590 drm/xe: Move xe->info.devid|revid initialization
  • d4c139fe4548 drm/xe: Move xe->info.force_execlist initialization
  • f571c2616e58 drm/xe: Drop unused param from xe_device_create()
  • bc7a0f721123 usb: typec: ucsi: Fix race condition and ordering in port unregistration
  • 30df04e2d569 usb: typec: ucsi: split connector lock classes
  • 2c55034e53c5 drm/xe/rtp: Ensure locking/ref counting for OA whitelists
  • 3be72ad315db drm/xe/oa: (De-)whitelist OA registers on OA stream open/release
  • 43114690b12f drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt
  • e8d1f040eb15 drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs
  • ddcc9e4a8ebe drm/xe/rtp: Save OA nonpriv registers to register save/restore lists
  • 339bc3ab303e drm/xe/rtp: Generalize whitelist_apply_to_hwe
  • cc6b3f0c82b2 drm/xe/rtp: Keep track of non-OA nonpriv slots
  • 16449f284fa4 drm/xe/rtp: Maintain OA whitelists separately
  • 5e4a2d15637a drm/vmwgfx: validate external BO copy bounds for both stride paths
  • 5c725901908e drm/vmwgfx: use check_add_overflow for shader size+offset bound
  • 9109b7935b9c drm/vmwgfx: enforce cursor size limits for MOB cursors
  • 0ee0532f1d40 drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure
  • 9759da60e38d drm/vmwgfx: bound DMA command body size against suffix pointer
  • c77cf8edae2b drm/vmwgfx: validate DRAW_PRIMITIVES header size before division
  • 4df39eb99bb4 drm/vmwgfx: drop dma_buf reference on foreign-fd prime import
  • bacbdc0be793 drm/vmwgfx: take fman->lock around fence list mutation in fifo_down
  • 2c10e2271a08 drm/vmwgfx: clamp dirty-page range with min, not max
  • 6b1eb0b63cc1 drm/vmwgfx: reject DX_BIND_QUERY without a DX context
  • 3b2bb16a5b62 drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size
  • bed80be08c0b drm/amdkfd: hold event_mutex while checkpointing CRIU events
  • 46c6041c7b02 drm/amdkfd: Handle invalid event type in CRIU event restore
  • 7c54bd225d83 drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment
  • 7c35bf94150d drm/amdkfd: fix QID bit leak in pqm_create_queue()
  • 4070909ac042 drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE
  • f556bc844cc4 drm/amd/display: use proper context for logging
  • 1c0b90e44768 drm/amd/display: Silence link_dpms I2C retimer failures
  • 3fc61f526ffa drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames
  • 1f93537881fd drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero viewport
  • 062cfd6c678f drm/amd/display: check if dml21_add_phantom_plane() is successful
  • 221d2766fefa drm/amd/pm: use milliwatts for GPU power sensors
  • dfc5d288c7c9 drm/amd/pm: hide pp_table sysfs on APUs
  • b628f2c6feb3 drm/amd/pm: fix pptable use-after-free
  • 219eed1a041e drm/amd/pm: fix torn gpu metrics reads
  • 30e7e004bef7 drm/amdgpu: cap GTT size to physical RAM on APUs
  • 3529c9b1e4e7 drm/amdgpu: restore UMD profile pstate after runtime resume
  • a0062a4653e4 drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini
  • 4296fd8fe37a drm/mediatek: ovl_adaptor: balance component registrations
  • 2faeaaf28f92 drm/mediatek: mtk_hdmi: Fix DDC adapter double put in v2
  • ca41d9f3a215 drm/panthor: validate firmware interface structure sizes
  • 7f4674d986c1 drm/panthor: reject firmware sections with oversized data
  • f32aeba8e9ef drm/bridge: display-connector: Fix I2C adapter resource leak
  • a75c8f365e20 drm/vc4: Zero the tile state data array before each BIN job
  • 1e33ca7f44be drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size
  • f3d2397f5309 drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs
  • e49fa5a495af can: ctucanfd: mark error-active controller status valid
  • 5bdcb17d788b can: ctucanfd: handle bus error interrupts
  • 02170ecf8e2d can: ctucanfd: unmap BAR0 using base address
  • 8e4eadb4b770 can: ctucanfd: use self-test mode for PRESUME_ACK
  • 731ed47772a5 can: ctucanfd: add missing MODULE_DEVICE_TABLE()
  • d9c115948c3d can: peak_usb: validate uCAN receive record lengths
  • dfb17bf04a76 can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error
  • 0149fdb50a30 can: peak_usb: add bounds check for USB channel index
  • 808ed899dcf8 can: softing: fw_parse(): validate firmware record spans
  • 0e36a43dcdd4 can: rcar_canfd: change the initializing flow for clocks and resets
  • 21f0465fd86d can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents
  • 195e70e83a09 can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams()
  • 6fbf77ca59c9 can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking
  • d5b3613c7d69 can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer
  • 35c62ac98d06 can: isotp: fix timer drain order, wakeup handling and tx_gen ordering
  • 4976c9cf4186 can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure
  • 19c6c8c6cd5d can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure
  • df3ac2a672a5 can: ems_usb: validate CPC message lengths
  • 2ded503449ce can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured
  • dab4762ee7f3 i2c: imx: Cancel hrtimer before clearing slave pointer
  • 614ca6594e30 i2c: imx: Fix slave registration race and error handling
  • ec8e15e3e5c7 i2c: imx: mark I2C adapter when hardware is powered down
  • 83d48e4bf8a1 i2c: iproc: reset bus after timeout if START_BUSY is stuck
  • aa1944b52d64 i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock
  • 100f7fdc1398 i2c: qcom-cci: drop custom suspend/resume and rely on runtime PM helpers
  • f7f0b514ac66 i2c: spacemit: request IRQ after controller initialization
  • 85dc667f4aeb ice: fix memory leak in ice_lbtest_prepare_rings()
  • 5be4386042bb ice: fix VF interrupts cleanup
  • 2ee7feff7bfa ice: wait for reset completion in ice_resume()
  • 393f3c72600a net: openvswitch: fix skb leak on flow key update failure during ct
  • 378e341b29f9 net: openvswitch: fix skb leak on flow key update failure during recirculation
  • 431a295d93f7 net: openvswitch: fix potential UAF on meter attach failure
  • fa7da1efed83 phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB
  • 68c49df14c95 phy: zynqmp: use read-modify-write for SERDES scrambler bypass
  • 7e7b9c0dca77 phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask
  • 8fa3e9435a13 s390/zcrypt: Validate length for CCA ECC private key requests
  • 3859f630b674 s390/zcrypt: Validate length for CCA AES cipher key requests
  • ebfbb9ac7adb s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()
  • 3b2abee2a678 s390/zcrypt: Fix buffer over-read in cca_cipher2protkey
  • 82b62eda68ab s390/zcrypt: Close speculative mem read possibility
  • 1223477ca88e s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs
  • 87f3389cd392 s390/dasd: Fix undersized format-check buffer
  • 96b8e09b0953 s390/dasd: Fix potential NULL pointer dereference
  • 93a0a846ec59 s390/qeth: Check CAP_NET_ADMIN for private ioctls
  • e355752a94d9 s390/pci: Fix s390_pci_mmio_write syscall error return without MIO
  • ee2ea0c452ed power: supply: max17040: handle missing status supplier
  • 57694663d658 power: supply: macsmc: Support macOS 27 SMC firmware
  • 8a1b4b8a451e power: supply: bq25890: fix the -10 C NTC lookup entry
  • b6814d55ccd4 cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized
  • 8e787961a5dc cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init()
  • 304b5281191b cpufreq: cppc: Sanitize lockless policy limit snapshots
  • 3513f3931c57 cifs: add fscache_resize_cookie() to cifs_setsize()
  • c0a4ec89fc26 gpio: pch: use raw_spinlock_t for the register lock
  • a97d774fb738 gpio: pca953x: fix cache_only and IRQ state on restore_context() failure
  • a5012358afb6 gpiolib: tolerate gpio-hogs lacking a hogging state
  • 8bf719659406 i2c: amd-mp2: Unregister callback on adapter add failure
  • 705e87e35e54 hwmon: (pmbus/core) notify on the hwmon device, not the i2c client
  • 8583336d9e52 hwmon: (npcm750-pwm-fan): stop fan timer on device detach
  • 6201cd1d70f1 sctp: prevent peer transport count overflow
  • 35c279113498 sctp: reject stale cookies with mismatched verification tags
  • cad7ab03b989 scsi: ufs: dt-bindings: Add missing mcq reg for qcom,sa8255p-ufshc
  • d6e6da6bc3b5 scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
  • 73e4cf572507 scsi: libsas: terminate deferred commands on time out
  • e1d8f92f9603 selftests/clone3: fix wild pointer access of getline due to missing init
  • d7bd560e06ae selftests/mm: fix potential wild pointer access of getline due to missing init
  • 89fe0bddd429 spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure
  • 3ba021079ef2 spi: spi-qpic-snand: write the feature value before executing SET_FEATURE
  • 83c756f3f7a5 tracing/filters: Fix false positive match in regex_match_full()
  • 000765dcdc3e tracing: Check return value of __register_event() in trace_module_add_events()
  • 127033b79383 ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()
  • 4f3f96e771a2 vxlan: use pskb_network_may_pull() in route_shortcircuit()
  • 7076a34b6e33 vxlan: use pskb_network_may_pull() for transmit path header pulls
  • 05f2987f73da vxlan: use neigh_ha_snapshot() in route_shortcircuit()
  • e50da7442910 vxlan: unclone skb head before modifying eth header in route_shortcircuit()
  • c9dceac9e1c7 vxlan: re-fetch eth header after route_shortcircuit()
  • f9c1fff857e9 veth: convert frag_list skbs before running XDP
  • 06c275a6c0a9 uprobes: Fix NULL pointer dereference in hprobe_expire()
  • 804b681002ea um: vector: fix use-after-free in vector_mmsg_rx()
  • 95f05c1c0450 powerpc/ps3: Fix map failure path in dma_ioc0_map_pages()
  • 11ad86830a78 riscv/mm: use physical alignment for vmemmap_start_pfn
  • b006a5404470 net: pktgen: fix proc entry use-after-free
  • a341c091ca0b net: ipv6: clear suppressed fib6 rule result
  • 4c57056ca6aa net: bridge: stop fast-leave after deleting a port group
  • 2097e1ddf3a6 mm: memcg: initialize *locked in memcg1_oom_prepare() stub
  • faf439b5fa7b mm/page_reporting: use system_freezable_wq to fix UAF during suspend
  • d640efe94d86 mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios
  • fcef9325afee io_uring: preserve task restrictions across exec
  • ce5b96f9656d io_uring/net: initialize mshot_len for send
  • 87a4eb9bbb34 binfmt_misc: don't leak the user namespace when the mount fails
  • 098e92fe0f1b binfmt_misc: don't let an 'F' entry pin its own instance
  • 9a2d87db3898 binfmt_misc: reject a flag character as the field delimiter
  • f0edbaf487e4 binfmt_misc: use exe_file_deny_write_access() for the interpreter clone
  • 3b522487a3a9 binfmt_misc: restore write access when removing an entry
  • 5a21ab03829c wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames
  • 09fc36eec784 wifi: mac80211: fix tid_tx use-after-free on BA session stop
  • 882af7b84f97 x86/CPU/AMD: Carve out a Zen5 models range
  • ac2f787980fd tipc: avoid use-after-free in poll trace queue dumps
  • f448d2e9e938 PCI: imx6: Keep i.MX6 Root Port MSI/MSI-X Capabilities with iMSI-RX to work around hardware bug
  • eddd0159a876 of/address: Fix NULL bus dereference in of_pci_range_parser_one()
  • 77dbb248a5cc netfilter: ipset: do not update comments from kernel-side hash adds
  • f0541a775d04 net/smc: fix socket use-after-free during link group termination
  • b12378f6d1bb mshv: fix hv_input_get_system_property struct
  • 7e02cb30e8a1 ksmbd: reject repeated SMB2 NEGOTIATE requests
  • e7acfc990c29 ipvs: do not propagate one-packet flag to synced conns
  • 9a2b637aef4e igc: remove napi_synchronize() in igc_down()
  • df07003b5a6c igbvf: Fix leak in TX DMA error cleanup
  • a28d8903bfe7 fou: Fix use-after-free in fou_create()
  • 378768dbce47 e1000: fix memory leak in e1000_probe()
  • 5ccf1b76c239 dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+
  • 53f0aa37eb94 ALSA: usb-audio: Clamp frame size in implicit-feedback mode
  • bd65b7191683 ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set
  • 2b7a0f330dd9 ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
  • 98dbfbb38e29 ALSA: usb-audio: fix stack info leak in RME Digiface status
  • ae388c0e1bf7 ALSA: usb-audio: fix use-after-free in ump_to_endpoint()
  • 3164ce8ca109 ata: libata-scsi: schedule deferred atapi command
  • 5f19cc10afaa ata: libata-scsi: terminate deferred commands on time out
  • 1d8e0ff6eab8 ata: libata-sata: fix ata_scsi_lpm_supported() iteration
  • 410f7290dc15 ata: libata-eh: Increase STANDBY IMMEDIATE timeout
  • a4c7ae006ff5 ASoC: tas2562: fix broken entries in the volume lookup table
  • 97d20ff1ab70 ASoC: tas2562: fix DVC coefficient write order
  • 7e65b396192f ASoC: fsl_easrc: fix m2m_init error path to use goto instead of bare return
  • 637f7b361f10 ASoC: fsl_asrc: fix m2m_init error path to use goto instead of bare return
  • c57001f55f97 ALSA: ump: fix double free of out_cvts on rawmidi error
  • 0c561fab5099 ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes
  • 42c6543ff27e ALSA: seq: Fix division by zero in initialize_timer()
  • db09bc4ab19c ALSA: pcm: wake linked drain waiters on unlink
  • 1863097b1713 ALSA: lx6464es: fix period byte count for 16-bit streams
  • 61ddb594dba5 ALSA: hda/realtek: Add quirk for TongFang X6SP45xU
  • 630c8d6a93cb ALSA: 6fire: Fix UAF at error handling during probe
  • daaa726b14fc afs: Fix UAF when sending a message
  • cb20530c81eb afs: Fix afs_fs_fetch_data() to subtract transferred from len
  • 616a3b534e32 afs: Fix afs_fs_fetch_data() to set call->async
  • 8f0a7004755b bpf: lwt: Fix dst reference leak on reroute failure
  • 9c841f59e10b Bluetooth: HIDP: validate numbered report payloads
  • 854194494a6f Bluetooth: HIDP: reject frames without a transaction header
  • b16ebdbebd2d Bluetooth: hci_sync: Fix advertising data UAFs
  • 51be7280980f Bluetooth: mgmt: fix UAF in pair command cancellation
  • 8fe627192fa5 Bluetooth: SCO: give the socket its own sco_conn reference
  • 35464ff81816 Bluetooth: mgmt: fix pending command UAF in EIR updates
  • d9de4bd6bdf4 Bluetooth: btmtk: Fix short read errors in btmtk_usb_reg_read()
  • 1023e4524625 Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read()
  • 0fdd312c1396 Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req()
  • 5b8f46864f06 audit: fix potential use-after-free in audit_del_rule()
  • e18946575480 audit: fix potential integer overflow in audit_log_n_string()
  • bfa28cf99eb4 sctp: validate Adaptation Indication parameter length
  • 48c073f88c93 dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister
  • fbfe683f8b1a KVM: s390: pci: Validate AIBV and AISB before pinning guest pages
  • d1a103dc9016 KVM: s390: pci: Fix NULL dereference on AIBV allocation failure
  • 6a3339023e08 KVM: s390: pci: Fix resource leak on IRQ registration failure
  • 239d8c02c839 KVM: s390: pci: Fix missing error codes and memory unaccounting
  • e3f732e086e4 KVM: s390: pci: Fix memory accounting for pinned/unpinned pages
  • 591952b63a9f KVM: s390: pci: Reject adapter interrupt forwarding if already enabled
  • 89f9e8398e79 KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active
  • 2451c2f95c78 KVM: VMX: add memory clobber to asm for VMX instructions
  • c56baa99c5f4 tracing/fprobe: Roll back on enable_trace_fprobe() failure
  • cad531c857f4 tracing/probes: Reject $arg0 in meta argument expansion
  • ed56a6b58222 KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs
  • e2036b052a19 mm/vmstat: fold stranded per-cpu node stats when a node comes online
  • 43d3c86b1e80 userfaultfd: wait on source PMD during UFFDIO_MOVE
  • ac1bb7fd4508 mm/hugetlb: fix list corruption in allocate_file_region_entries()
  • 5c7fc39bf19a mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()
  • f7e22bcbec1a fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes
  • e20086c3be6e fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes
  • 45f6333ef56c selftest: fix headers in fclog.c
  • c64932457120 mm/util: don't read __page_2 for order-1 folios in snapshot_page()
  • 42f30fa5481a mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE
  • bcd83664c1c5 ocfs2: fix boundary check in ocfs2_check_dir_entry() to use buffer offset
  • c6e484fecc4d btrfs: zoned: fix missing chunk metadata reservation
  • afe9f6f9b6be lib: test_hmm: use device devt for coherent device range selection
  • 8ddfd1c1302d fortify: Disable -Wstringop-overread in tests
  • 8612c37c7e06 pinctrl: bm1880: add missing select GENERIC_PINCONF
  • e52da169b8c0 erofs: cap LZMA stream pool size
  • 6fedc49478be btrfs: raid56: fix scrub read assembly submitting no reads
  • 9d00a5ac7cd3 pinctrl: devicetree: don't free uninitialized dev_name on error path
  • f49b37761f24 pinctrl: microchip-sgpio: add missing select REGMAP_MMIO
  • 2fa11c60c9c0 mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()
  • fceb6b7f3dde mm: mglru: fix stale batch updates after memcg reparenting
  • 51b4c3743ab2 ACPI: CPPC: Check all controls for fast switching
  • 3edc387ba188 kbuild: Stop modifying $(objtree)/Makefile when building oot-kmods oos
  • 4e74a3692364 iommu/iommufd: Fix IOPF group ownership UAF
  • 8eb077025279 iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace
  • 41e615bc0e95 iommufd: Reject DMABUF pages from the access pin path
  • 0827a1ce6572 iommufd/viommu: Publish a vDEVICE only after vdevice_init() succeeds
  • ca9e49e1c893 iommufd/viommu: Release the igroup lock on the vdevice_size error path
  • 6f9fe8087bf1 ring-buffer: Fix subbuf_ids memory leak in rb_allocate_cpu_buffer() error path
  • bfc58bfd2415 mshv: Publish VP to pt_vp_array before installing the file descriptor
  • eba2bf5daa79 mshv: Order pt_vp_array publish against irqfd assertion path
  • 3fb8a6e89abe mshv: Fix missing error code on VP allocation failure
  • 363a6500ff31 mshv: Fix level-triggered check on uninitialized data
  • 4529a41a675b mshv: Fix race in mshv_irqfd_deassign
  • 4a869be56e9f iomap: add a separate bio_set for iomap_split_ioend
  • d53536329982 ksmbd: use memcmp() to compare ClientGUIDs
  • cffbdc86393b ksmbd: fix use-after-free in __close_file_table_ids()
  • a52601f2e2b4 ksmbd: return success for deferred final close
  • 54382aa779da drm/i915/hdmi: Poll for 200 msec for TMDS_Scrambler_Status
  • 6f1ef8170d3d qede: sync udp_tunnel ports outside qede_lock in the recovery path
  • bd2fc7a71dd2 spi: spi-nxp-fspi: add per-SoC SDR/DTR clock rate limits for all supported SoCs
  • 3ab00c9fd420 sched/deadline: Use revised wakeup rule only for running dl_server
  • aeddda24726c octeontx2-pf: Set correct sequence for carrier off and tx queue stop
  • 7416702c30ac net: libwx: fix FDIR ATR queue mismatch for software VLAN packets
  • 8486038decc6 ptp: netc: fix potential interrupt storm caused by incorrect unbind order
  • bc8ccdc869d5 net: mana: Return error code from mana_create_rxq()
  • 690ecb7bdfab net: mana: Create separate EQs for each vPort
  • 11b83d56d5f5 net: stmmac: Fix E2E delay mechanism
  • 0f30be7f2922 net: dsa: mt7530: error out on failed reads in MT7531 PHY polling
  • f3fc89593ef7 net: dsa: mt7530: error out on failed reads in ATC/VTCR command polling
  • fdefb3409f1c net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend
  • 9474b1eead40 riscv: vdso: Only try to install vDSO when present
  • 5cbcd7e4a18a ipv6: release fib6_null_entry on subtree failure
  • e0d8d33bac3b ring-buffer: Fix reader page read offset for remote buffers
  • 1bb0ef8069ef riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove
  • e9b98da3355e accel/qaic: use sizeof(*trans_hdr) for transaction length check
  • 25f228e6ac57 riscv: drop __init from vec_check_unaligned_access_speed_all_cpus
  • 60234845142f tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions
  • d9d771a6e503 tracing/mmiotrace: Reset dropped_count in mmio_reset_data()
  • ac61f5b01dfe fprobe: Fix module reference count leak on error in register_fprobe()
  • b641bfb518a3 drm/xe/pt: check no-DMA huge-pte cases before DMA segment test
  • fdffacb12279 drm/i915/dp: Ignore the sink's DSC max FRL rate without a PCON DSC encoder
  • ffa229d67de5 can: isotp: check register_netdevice_notifier() error in module init
  • 64442a301711 net: sxgbe: check descriptor ring allocation failures
  • f2e5bb9fb710 net: sxgbe: free TX rings on RX allocation failure
  • a29db0c7f695 scsi: ufs: core: Initialize hba->rpmbs list in ufshcd
  • df817b19dac7 scsi: mpi3mr: Fix potential deadlock in mpi3mr_fault_uevent_emit
  • d3c6b0f48f12 octeontx2-af: Block VFs from clobbering special CGX PKIND state
  • b21a2571f530 octeontx2: cn20k: Coordinate default rules with NIX LF lifecycle
  • bb0894e1eef6 scsi: target: Clear cmd_cnt when initial counter enrollment fails
  • deff324a327b scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req
  • 80aae06187d8 scsi: ufs: core: Revert "Delegate the interrupt service routine to a threaded IRQ handler"
  • 9265806bd1f9 scsi: ufs: core: Cancel RTC work in active-active suspend
  • f15bcf9a99b1 scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE
  • 4dc5361dd284 net: phylink: put link_gpio if phylink_create fails
  • f0bc7e69ba1b x86/boot: Add volatile, clobbers and zero-length test in memcmp()
  • 3f2ce63fe551 Bluetooth: hci_sync: remove unnecessary hci_conn_get in create_conn_sync
  • 236e5387cb09 Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync
  • e6792adef614 Bluetooth: hci_sync: hold conn in hci_past_sync() callback
  • c53c70ec289e Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback
  • 2d91e6244b69 Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback
  • 9a77f296aff4 Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks
  • fa812cfa81aa Bluetooth: hci_conn: hold conn reference in abort_conn_sync()
  • 6ec9c3dc5230 Bluetooth: btintel: Validate length before parsing diagnostics TLV
  • 876a3e94c70d Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero
  • 8208b4939afb Bluetooth: ISO: fix refcounting of iso_conn
  • cdce8af9291d Bluetooth: ISO: ensure no dangling hcon references in iso_conn
  • 3c3d5f85db80 Bluetooth: ISO: avoid deadlocks in iso_sock_timeout
  • e30e5ca63c8f Bluetooth: ISO: fix leaking sk after socket release
  • 1308d72903d7 Bluetooth: ISO: hold sk properly in iso_conn_ready
  • 171e71a6d661 Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis()
  • c46c7a22c496 Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos
  • 9bee7e476534 Bluetooth: ISO: lock sk in iso_connect_ind
  • 202670e6602e Bluetooth: ISO: lock sk in iso_sock_getname
  • b7dbf53fb3ca Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release
  • 09f447accc25 Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp
  • 69a4a7b162b3 Bluetooth: ISO: clear iso_data always when detaching conn from hcon
  • 4d0644bd7821 ice: suppress DPLL errors during reset recovery
  • b7f2c666fae8 idpf: Fix mailbox IRQ name leak on request failure
  • 372f458eef99 idpf: adjust TxQ ring count minimum
  • 41bb8748124d idpf: bound interrupt-vector register fill to the allocated array
  • 95599c050359 hwmon: (pmbus) Fix return value from pmbus_update_byte_data()
  • 7eb46318d539 net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller
  • 3f6d7f8a5416 netfs: Fix folio_queue ENOMEM in writeback by adding a mempool
  • 935e7b74bb23 netfs: release readahead folios on iterator preparation failure
  • e65e0c057664 netfs: handle single writeback rolling buffer allocation failure
  • 614b7f4bfcf6 netfs: clear PG_private_2 on copy-to-cache append failure
  • 47fb04c3826e wifi: mac80211: validate individual TWT params before driver setup
  • b322532a4b77 net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister()
  • 313cb9ffc410 net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds
  • c7116f38131d powerpc/boot: Fix treeboot-akebono CPU node lookup check
  • fe85d44d2c08 powerpc/boot: Fix treeboot-currituck CPU node lookup check
  • be2471a5af6d powerpc/boot: Fix simpleboot CPU node lookup check
  • f7bf8803e39c ethtool: Embed FEC hist ranges as buffer in struct
  • de691dc3227b rtase: fix double free of multi-frag skb on DMA map failure
  • 3a1c578d8539 hwmon: (adt7470) Fix PWM auto temp state array and bounds check
  • 76963b04b2d1 hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read
  • fe3c8c93d02d hwmon: (adt7470) Use cached PWM frequency value
  • c48557dc66c1 hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks
  • c6540a03838b hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read()
  • 5ea299c3aa42 hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread
  • 8a9492c467d6 hwmon: (adt7470) Fix cache updated before hardware write on I2C error
  • c8ee73e540f3 hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors
  • 201e05aa531e forcedeth: fix UAF of txrx_stats in nv_remove
  • 693ebff3e777 ASoC: sophgo: return 1 on volume change in cv1800b_adc_volume_set()
  • fec7c738e0f7 net: bridge: mrp: fix Option TLV length in MRP_Test frames
  • 4ad2972ef0e1 hwmon: (nct6775-core) Prevent access to unsupported weight registers
  • 828f6670d110 net: do not send ICMP/NDISC Redirects when peer allocation fails
  • 6a2dbce5da2d hwmon: (nzxt-smart2) DMA-align output buffer
  • f0b791a00651 hwmon: (lm90) Only report alarms if driver is ready
  • 1fb41650bc3e hwmon: (sht3x) Fix unaligned accesses
  • a0668ac20fea hwmon: (ltc4282) Fix reading the minimum alarm voltage
  • e9374bbeb8b7 hwmon: (ina2xx) Fix various overflow issues
  • a7f47f5246cd hwmon: (nct6775-core) Fix number of temperature registers for NCT6116
  • 8e89cc882f0a spi: spi-cadence: Move TX FIFO full busy-wait into FIFO
  • c0c99275cce5 ASoC: tas2781: Use correct calibration data for SINEGAIN2 register
  • 234b5cb81e6f wifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup()
  • 9703abd39ef0 ACPI: CPPC: Skip writes to unsupported performance controls
  • fbfa371a2fb3 gpio: gpio-by-pinctrl: Apply initial value in direction output wrapper
  • 3879657c4ffd erofs: ensure valid f_path for page cache sharing
  • f6145794f17a erofs: remove fscache backend entirely
  • fce6cd6f9845 erofs: clean up erofs_ishare_fill_inode()
  • b3e97ba24110 smb: client: fix buffer leaks in SMB1 read and write
  • b9c44a140620 scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race
  • b0aa3e8e2ab4 scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer
  • 1f07a897d43c scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer
  • a7c855969b1a pinctrl-amd: Don't clear S4 wake bits at probe
  • 3bb9cbcd944b net/sched: sch_cake: skip clearing unused tins during rate adjustment
  • e7ce2bad0c33 xsk: reclaim invalid Tx descriptors in ZC batch path
  • be1b85613ca7 xsk: provide sufficient space in pool->tx_descs
  • 5e94d74e4f3b xsk: drain continuation descs after overflow in xsk_build_skb()
  • a0528ab6af62 xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx
  • b0d8ecdac394 selftests/net/af_unix: test listen() rejects wrong socket states
  • 6c88d205c732 af_unix: fix listen() succeeding on sockets in the wrong state
  • 44f53e4331a3 nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush
  • bb2b072c619c nexthop: take nh->lock for f6i_list walks in replace check and notify
  • 8398bc477d3c rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()
  • 6a4d9d37c1c0 ASoC: SDCA: Ensure that Control Range is large enough for header
  • fe5c53a95297 ASoC: SDCA: Make UMP message size check more robust
  • 3712e66064a2 ASoC: SDCA: Always free firmware in FDL path
  • 5c595f2ef60a ASoC: SDCA: Correct pointer passed to devm_acpi_table_put
  • 630295d5bba1 netfilter: nft_payload: fix mask build for partial field offload
  • da286d421b9a ipvs: clear the nfct flag under lock
  • 92600ca75fda ipvs: do not mangle ICMP replies for non-first fragments
  • 79c1254f3dbd ipvs: fix places with wrong packet offsets
  • 5558a85add07 ipvs: fix the checksum validations
  • 06a76334243c netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
  • 7d4789b58761 netfilter: nf_tables: make nft_object rhltable per table
  • eec19d7c90cb ipvs: adjust double hashing when fwd method changes
  • 24053cfe4d50 assoc_array: trim the final shortcut word using the current chunk end
  • 7e5397a3fed0 keys: make keyring key-chunk byte order agree with keyring_diff_objects()
  • 8dba33c1e779 keys: fix out-of-bounds read in keyring_get_key_chunk()
  • b16272fe8916 KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type
  • 92e2c891a06b KVM: arm64: Reject guest_memfd memslots when the VM has MTE
  • c71729aab77d KVM: arm64: Add missing hyp_enter when trapping sysreg
  • 4c51944735f1 KVM: arm64: Fix hyp_trace_desc allocation size in hyp_trace_load()
  • c9a590838b73 KVM: arm64: Fix potential leak in hyp_trace_buffer_alloc_bpages_backing
  • 67baa93486bc KVM: arm64: Fix hyp_trace clock disabling
  • 72aea30c76d3 KVM: arm64: vgic: Mitigate potential LPI registration failure
  • 292e80a159aa KVM: arm64: vgic: Fix race between LPI release and re-registration
  • 668120335b89 mshv: Fix sleeping under spinlock in mshv_portid_alloc
  • c34ac583c2fa mshv: Fix duplicate GSI detection for GSI 0
  • 35dbc4cc58ce Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation
  • ccfb70d92a52 mshv_vtl: fix fd leak in mshv_ioctl_create_vtl()
  • 068f84c542b3 drm/mediatek: Check CRTC state before freeing
  • 8501ca88419a netfilter: nf_conntrack_expect: add and use nf_ct_expect_related_pair()
  • 5b361672720c selftests: netfilter: nft_flowtable.sh: fix offload counter verification for tunnel tests
  • ef5e2c6555d2 netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()
  • a6b6d16a5e1c phy: zynqmp: fix runtime PM leak on probe allocation failure
  • efea649f214f phy: zynqmp: fix clock error handling in xpsgtr_phy_init()
  • e8c5c80a20c7 rtla/timerlat_top: Fix on-threshold actions firing on signal
  • ed0d2e33fab5 ntfs: drop stale page-cache when shrinking a non-resident attr
  • 57e7b8bf7b02 ntfs: harden runlist realloc size calculations
  • 0e9dbc6d1f0d btrfs: zoned: skip fully truncated ordered extents at zone finish
  • 20f6badf1c2a btrfs: raid56: fix an incorrect csum skip during scrub
  • 076349e4c8d1 btrfs: skip global block reserve accounting for rescue mounts
  • b0c33c0628c5 btrfs: warn about extent buffer that can not be released
  • 920fe5b8317c btrfs: zoned: reset meta_write_pointer on zone reset
  • 75859a7cd77c btrfs: zoned: fix deadlock between metadata writeback and transaction commit
  • ec7959ecbfb0 btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag
  • de8ccbd6bf4e of: reserved_mem: prevent OOB when too many dynamic regions are defined
  • 0cd45057cd4b ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup
  • 4f385927d295 ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup
  • 5815ae160add phy: qcom: m31-eusb2: Fix return value of init call
  • 35ede850a936 ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources()
  • 99417b0dd4db ata: sata_mv: accept 1 or 2 resources in platform probe
  • 4180b67aeb8f ntfs: preserve RECALL_ON_OPEN on WSL special-file reparse points
  • 321c437d5c9c selftests/seccomp: Fix pointer type mismatch build error
  • 1dcffb3ecf54 selftests/lkdtm: rename STACKLEAK_ERASING to KSTACK_ERASE
  • 96c25ed04aa7 gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe()
  • 0acbc621341a iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE
  • 6e26a41c4c1a dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open()
  • c93a9f652b73 dmaengine: idxd: fix double free of wq, engine, and group structs
  • d4ba6aa65fcd dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA
  • dffcf5d44213 pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151
  • 85997b1c6a2e pinctrl: qcom: Unconditionally mark gpio as wakeup enable
  • 4087bf79d2a8 dmaengine: switchtec-dma: fix FIELD_GET misuse when programming SE threshold
  • f78f08b38a7f KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context
  • 2aa2cde2cc79 thunderbolt: Prevent XDomain delayed work use-after-free on disconnect
  • bd3fb6b74a49 ALSA: hda/realtek: Add quirk for HP Dragonfly Folio G3 2-in-1 (103c:8a05)
  • ebefca49e4c6 mm/slab: prevent unbounded recursion in free path with new kmalloc type
  • 2e048fda7bc7 lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled()
  • 4349e4dd25b2 mm/slab: decouple SLAB_NO_SHEAVES from SLAB_NO_OBJ_EXT
  • 2dc2fffc704a net: mpls: initialize rtm_tos in mpls_getroute()
  • c7ba9d6de43e Linux 7.1.7
  • 61649a2d61cb x86/bugs: Make Safe-RET robust against interrupt injection
View originalPermalink
How 7.1.8-xanmod1 went

6.18.44-rt-xanmod1

Added 5
  • drm/xe: Add page reclamation info to device info
  • drm/xe: Stub out new pagefault layer
  • drm/xe/bo: Add purgeable bo state tracking and field madv to xe_bo
  • drm/xe: add xe_migrate_resolve wrapper and is_vram_resolve support
  • drm/xe/pat: Add helper to query compression enable status
Changed 3
  • drm/xe: Use SVM range helpers in PT layer
  • drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable()
  • drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse]
Fixed 12
  • drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info
  • drm/fb-helper: Fix a locking bug in an error path
  • usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path
  • can: isotp: fix timer drain order, wakeup handling and tx_gen ordering
  • can: use skb hash instead of private variable in headroom
  • drm/xe/pt: Reset current_op in xe_pt_update_ops_init()

From XanMod Kernel

  • da3165ece5d7 Linux 6.18.44-rt-xanmod1
  • 3a2180dd4bbe Merge branch '6.18' into 6.18-rt
  • ad6ed82a8a85 Linux 6.18.44-xanmod1
  • 3412e4a7152c Merge tag 'v6.18.44' into 6.18
  • 1efe5d048a39 Linux 6.18.44
  • 358b5dcf1fd7 drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info
  • e7731507270c drm/fb-helper: Fix a locking bug in an error path
  • 7bc7af179916 usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path
  • 10be509fa8fd can: isotp: fix timer drain order, wakeup handling and tx_gen ordering
  • 0902f06a6c0b can: use skb hash instead of private variable in headroom
  • 157b1e3384d7 drm/xe/pt: Reset current_op in xe_pt_update_ops_init()
  • b1a71151317c drm/xe: Add page reclamation info to device info
  • 6107b64cfcce drm/xe: Stub out new pagefault layer
  • 184de3d31f72 drm/xe: Use SVM range helpers in PT layer
  • df1582c0a101 drm/i915/vrr: require valid min/max vfreq for VRR
  • 894d4a739566 drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable()
  • 21976fe52584 drm/xe: Wait on external BO kernel fences in exec IOCTL
  • b8ad916ba4e1 drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse]
  • d256dac008d1 drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC
  • 8fa8b0a46372 drm/xe/vm: Prevent binding of purged buffer objects
  • 1ba553ee0b52 drm/xe/bo: Add purgeable bo state tracking and field madv to xe_bo
  • 0015b054b06d drm/xe: add xe_migrate_resolve wrapper and is_vram_resolve support
  • 005b9b443160 drm/xe/pat: Add helper to query compression enable status
  • 3cb42a973f88 drm/amd/display: Exit idle optimizations before programming
  • dbbe08d73b8b drm/amd/display: check GRPH_FLIP status before sending event
  • b485bfb45555 drm/xe/guc: Fix buffer overflow in steered register list allocation
  • 30b2d0843a41 drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions
  • e06c39cc1c48 drm/amdgpu: Fix context pstate override handling
  • 4d49ca777cf1 drm/tegra: fbdev: Remove offset into framebuffer memory
  • 3f5807745798 drm/fb-helper: Allocate and release fb_info in single place
  • 165613191ad9 userfaultfd: prevent registration of special VMAs
  • 02d378828af8 wifi: brcmfmac: drain bus_reset work on device removal
  • d6f322d68abf media: uapi: rkisp: Correct name version enum
  • 5c6d5d2484ca media: qcom: camss: Fix RDI streaming for CSID 340
  • f730ee0ef8fa media: qcom: camss: csid-340: Fix unused variables
  • 276420a86e75 media: chips-media: wave5: Support CBP profile
  • 3f7b3728dd90 usb: typec: ucsi: Fix race condition and ordering in port unregistration
  • 58d9caa64f9c usb: typec: ucsi: split connector lock classes
  • 2bf24a7e190a net/handshake: Drain pending requests at net namespace exit
  • 6e7b52bd1394 net/handshake: Close the submit-side sock_hold race
  • 68eba6519cbd net/handshake: hand off the pinned file reference to accept_doit
  • b913801ad9b9 net/handshake: Take a long-lived file reference at submit
  • 5ddfc47e1228 net/handshake: Fix null-ptr-deref in handshake_complete()
  • 97e745b4ea05 net/handshake: convert handshake_nl_accept_doit() to FD_PREPARE()
  • f00dd592abe7 file: ensure cleanup
  • 10827847c40c file: add FD_{ADD,PREPARE}()
  • 10065fb89165 mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios
  • be11b4bf498a fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes
  • 2b9a07002c2f mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()
  • fc0c76b0450f drm/xe/rtp: Ensure locking/ref counting for OA whitelists
  • 9783d8662b56 drm/xe/oa: (De-)whitelist OA registers on OA stream open/release
  • f5966d900662 drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt
  • d43abc858f08 drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs
  • c2cfee9bf8d4 drm/xe/rtp: Save OA nonpriv registers to register save/restore lists
  • 4bb92418e749 drm/xe/rtp: Generalize whitelist_apply_to_hwe
  • cc716d3ac560 drm/xe/rtp: Keep track of non-OA nonpriv slots
  • f73e97080deb drm/xe/rtp: Maintain OA whitelists separately
  • 7982678fa21e drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists
  • 542d3b9fa8ec drm/xe/rtp: Refactor OAG MMIO trigger register whitelisting
  • 2b70bebc7094 HID: logitech-dj: Fix maxfield check in DJ short report validation
  • 6be3dbe45b28 spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX
  • 042ca3877955 drm/vmwgfx: validate external BO copy bounds for both stride paths
  • cfd163169af3 drm/vmwgfx: use check_add_overflow for shader size+offset bound
  • 1eb4f796695b drm/vmwgfx: enforce cursor size limits for MOB cursors
  • 96efee36453b drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure
  • 7e40e6120fb2 drm/vmwgfx: bound DMA command body size against suffix pointer
  • dc0be7662b7b drm/vmwgfx: validate DRAW_PRIMITIVES header size before division
  • a8434b145b1e drm/vmwgfx: drop dma_buf reference on foreign-fd prime import
  • b79e82ea1823 drm/vmwgfx: take fman->lock around fence list mutation in fifo_down
  • 10460699c312 drm/vmwgfx: clamp dirty-page range with min, not max
  • e479240a1e07 drm/vmwgfx: reject DX_BIND_QUERY without a DX context
  • 282f261cb035 drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size
  • 6a52f48157fa drm/amdkfd: hold event_mutex while checkpointing CRIU events
  • 6189ceca5ce7 drm/amdkfd: Handle invalid event type in CRIU event restore
  • 6dc0b4b39ed4 drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment
  • 5f0f2ddeac73 drm/amdkfd: fix QID bit leak in pqm_create_queue()
  • 9e52212aff8e drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE
  • 02647d983407 drm/amd/display: use proper context for logging
  • 3c2ae9509717 drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames
  • 1860818feb4d drm/amd/pm: fix torn gpu metrics reads
  • 45ba7f091abf drm/amdgpu: cap GTT size to physical RAM on APUs
  • d330ac90d85f drm/amdgpu: restore UMD profile pstate after runtime resume
  • 18d21c9d04b0 drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini
  • 0f1ff05c58e1 drm/mediatek: ovl_adaptor: balance component registrations
  • c835f2b0b716 drm/panthor: validate firmware interface structure sizes
  • 2a761b9be586 drm/panthor: reject firmware sections with oversized data
  • da898bb6faf3 drm/bridge: display-connector: Fix I2C adapter resource leak
  • 57667eb7548f drm/vc4: Zero the tile state data array before each BIN job
  • 6cd5acf6f87c drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size
  • 58d2bb394e88 drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs
  • e8b797940536 can: ctucanfd: mark error-active controller status valid
  • 7d1619f56a75 can: ctucanfd: handle bus error interrupts
  • 46fc5aecde5c can: ctucanfd: unmap BAR0 using base address
  • cae2880f8ffa can: ctucanfd: use self-test mode for PRESUME_ACK
  • aa5e790bf185 can: ctucanfd: add missing MODULE_DEVICE_TABLE()
  • 2427ef427bdd can: peak_usb: validate uCAN receive record lengths
  • 92d0de80ca22 can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error
  • 1acab790b7ce can: peak_usb: add bounds check for USB channel index
  • 2ee477e541a6 can: softing: fw_parse(): validate firmware record spans
  • 185cb1fa3814 can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents
  • 2e90b2b40607 can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams()
  • 54258ea8d61f can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking
  • 8604a3b81b9d can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer
  • 996eb21acdc9 can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure
  • c311f17c261f can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure
  • 0b23144c59c1 can: ems_usb: validate CPC message lengths
  • 26cf99713a96 can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured
  • affd62f5719a i2c: imx: Cancel hrtimer before clearing slave pointer
  • 12a4f0950a15 i2c: imx: Fix slave registration race and error handling
  • 7a5db225ab5a i2c: imx: mark I2C adapter when hardware is powered down
  • 82233ff0e36d i2c: iproc: reset bus after timeout if START_BUSY is stuck
  • 19b783335d62 i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock
  • 40dd71744599 i2c: qcom-cci: drop custom suspend/resume and rely on runtime PM helpers
  • d9b5419df065 i2c: spacemit: request IRQ after controller initialization
  • 6a5cc2b4e6fa ice: fix memory leak in ice_lbtest_prepare_rings()
  • 326c89ea2685 ice: fix VF interrupts cleanup
  • 7e8789f5b5d8 ice: wait for reset completion in ice_resume()
  • e0ba8eaef2a0 net: openvswitch: fix skb leak on flow key update failure during ct
  • 9c7246cc509f net: openvswitch: fix skb leak on flow key update failure during recirculation
  • 90623c949962 net: openvswitch: fix potential UAF on meter attach failure
  • 74b30e7ef461 phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB
  • 79a312664118 phy: zynqmp: use read-modify-write for SERDES scrambler bypass
  • 4211450f0fec phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask
  • 013a4484f061 s390/zcrypt: Validate length for CCA ECC private key requests
  • ad93a1f1a456 s390/zcrypt: Validate length for CCA AES cipher key requests
  • fbb0410986e8 s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()
  • a57fd7fcdb63 s390/zcrypt: Fix buffer over-read in cca_cipher2protkey
  • 672b12940e3f s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs
  • e16e0fc54120 s390/dasd: Fix undersized format-check buffer
  • 86cdfd061509 s390/dasd: Fix potential NULL pointer dereference
  • bd63c7879eaa s390/qeth: Check CAP_NET_ADMIN for private ioctls
  • ef1aa7cfb8c6 s390/pci: Fix s390_pci_mmio_write syscall error return without MIO
  • b039f13e095d power: supply: max17040: handle missing status supplier
  • 6d89f33a6467 power: supply: bq25890: fix the -10 C NTC lookup entry
  • 63d6c855b27d cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized
  • 437b38a08c0a cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init()
  • efbcecdecefc cifs: add fscache_resize_cookie() to cifs_setsize()
  • 466ab0c41d5f gpio: pch: use raw_spinlock_t for the register lock
  • 2e4bc8422cde gpio: pca953x: fix cache_only and IRQ state on restore_context() failure
  • 1883a09a37fe i2c: amd-mp2: Unregister callback on adapter add failure
  • 7a91d07939e0 hwmon: (pmbus/core) notify on the hwmon device, not the i2c client
  • 30ae66374637 hwmon: (npcm750-pwm-fan): stop fan timer on device detach
  • 4ba5bf7ed50f sctp: prevent peer transport count overflow
  • a0d1693923f4 sctp: reject stale cookies with mismatched verification tags
  • 2047ed09bf13 scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
  • 5b4d4d5a29f9 selftests/clone3: fix wild pointer access of getline due to missing init
  • a0bc578641d7 selftests/mm: fix potential wild pointer access of getline due to missing init
  • 2e047b4171de spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure
  • 581e5166f078 spi: spi-qpic-snand: write the feature value before executing SET_FEATURE
  • c26a6477e149 tracing/filters: Fix false positive match in regex_match_full()
  • cbb5ed3be9ca tracing: Check return value of __register_event() in trace_module_add_events()
  • 205feb72e5be ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()
  • ee799977d794 vxlan: use pskb_network_may_pull() in route_shortcircuit()
  • 94dee751aad6 vxlan: use pskb_network_may_pull() for transmit path header pulls
  • ff89415d34c3 vxlan: use neigh_ha_snapshot() in route_shortcircuit()
  • adeed09eeb3b vxlan: unclone skb head before modifying eth header in route_shortcircuit()
  • 1235e017aa11 vxlan: re-fetch eth header after route_shortcircuit()
  • b24ba0bbffe3 veth: convert frag_list skbs before running XDP
  • 3bd35a5e272a uprobes: Fix NULL pointer dereference in hprobe_expire()
  • 180ff4c81faf um: vector: fix use-after-free in vector_mmsg_rx()
  • e4b98f9778df powerpc/ps3: Fix map failure path in dma_ioc0_map_pages()
  • 4ef801b838d8 net: pktgen: fix proc entry use-after-free
  • dc3ab0422066 net: ipv6: clear suppressed fib6 rule result
  • 0309ebbc5700 net: bridge: stop fast-leave after deleting a port group
  • 332a546b4ee5 mm: memcg: initialize *locked in memcg1_oom_prepare() stub
  • b11907c905fa mm/page_reporting: use system_freezable_wq to fix UAF during suspend
  • 63b361f22886 io_uring/net: initialize mshot_len for send
  • 4dad8ca637d4 binfmt_misc: don't let an 'F' entry pin its own instance
  • 840bb9c49c3e binfmt_misc: reject a flag character as the field delimiter
  • 255a758697da binfmt_misc: use exe_file_deny_write_access() for the interpreter clone
  • fdc1d702bf30 binfmt_misc: restore write access when removing an entry
  • c9dcfe6b8b71 wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames
  • bed792737b5f tipc: avoid use-after-free in poll trace queue dumps
  • 88752b811f72 of/address: Fix NULL bus dereference in of_pci_range_parser_one()
  • 4ae701848e4b netfilter: ipset: do not update comments from kernel-side hash adds
  • f807a63d0d95 net/smc: fix socket use-after-free during link group termination
  • 2060764e0f46 mshv: fix hv_input_get_system_property struct
  • a60b5da05e31 ksmbd: reject repeated SMB2 NEGOTIATE requests
  • b5ee5b266f83 ipvs: do not propagate one-packet flag to synced conns
  • 3b5aee6fcbf6 igc: remove napi_synchronize() in igc_down()
  • 845a9cdd9b03 igbvf: Fix leak in TX DMA error cleanup
  • b10bb77e91e9 e1000: fix memory leak in e1000_probe()
  • b0bdca3a49cf dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+
  • 2db4535d6af7 ALSA: usb-audio: Clamp frame size in implicit-feedback mode
  • 04595233e560 ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set
  • b5305a0d0bb8 ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
  • 7ba01e0d3539 ALSA: usb-audio: fix stack info leak in RME Digiface status
  • cc014ebf8031 ALSA: usb-audio: fix use-after-free in ump_to_endpoint()
  • 79f8720029f2 ata: libata-sata: fix ata_scsi_lpm_supported() iteration
  • 9562ddbc6ed8 ata: libata-eh: Increase STANDBY IMMEDIATE timeout
  • 0a02b0c87807 ASoC: tas2562: fix broken entries in the volume lookup table
  • 35d5f1852e39 ASoC: tas2562: fix DVC coefficient write order
  • cac7d2066b2f ASoC: fsl_easrc: fix m2m_init error path to use goto instead of bare return
  • 6df5b3288160 ASoC: fsl_asrc: fix m2m_init error path to use goto instead of bare return
  • 032746c2dd9a ALSA: ump: fix double free of out_cvts on rawmidi error
  • a26a2e52736f ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes
  • 5260e195c53e ALSA: seq: Fix division by zero in initialize_timer()
  • 2940cc3cf43c ALSA: pcm: wake linked drain waiters on unlink
  • 4969533a1b95 ALSA: lx6464es: fix period byte count for 16-bit streams
  • 7484669d1fba ALSA: hda/realtek: Add quirk for TongFang X6SP45xU
  • 11e2953d9f4c ALSA: 6fire: Fix UAF at error handling during probe
  • c0d3b81f703b afs: Fix UAF when sending a message
  • d703f022a28a afs: Fix afs_fs_fetch_data() to subtract transferred from len
  • b53face003b4 afs: Fix afs_fs_fetch_data() to set call->async
  • 5c7fdcbecbab bpf: lwt: Fix dst reference leak on reroute failure
  • 27cc0e603355 Bluetooth: HIDP: validate numbered report payloads
  • 2ebf63aa557a Bluetooth: HIDP: reject frames without a transaction header
  • eb1d8318764d Bluetooth: hci_sync: Fix advertising data UAFs
  • c569def320aa Bluetooth: mgmt: fix UAF in pair command cancellation
  • a33bc07b4730 Bluetooth: SCO: give the socket its own sco_conn reference
  • 814f82f432dc Bluetooth: mgmt: fix pending command UAF in EIR updates
  • 6936b367ee6d Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read()
  • f14d41dbc2fd Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req()
  • cae0dfed5d30 audit: fix potential use-after-free in audit_del_rule()
  • 185c784c9809 audit: fix potential integer overflow in audit_log_n_string()
  • 17b412468c7a sctp: validate Adaptation Indication parameter length
  • c0837aeace96 dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister
  • b878ba7e2814 KVM: s390: pci: Validate AIBV and AISB before pinning guest pages
  • e137d082325b KVM: s390: pci: Fix NULL dereference on AIBV allocation failure
  • 1abf9ce39a86 KVM: s390: pci: Fix missing error codes and memory unaccounting
  • 70871b121f81 KVM: s390: pci: Fix memory accounting for pinned/unpinned pages
  • 6837f0ae85fd KVM: s390: pci: Reject adapter interrupt forwarding if already enabled
  • 7668c58dcf46 KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active
  • 5acc92947baa KVM: VMX: add memory clobber to asm for VMX instructions
  • e768ea3a422d tracing/fprobe: Roll back on enable_trace_fprobe() failure
  • 3b2e08e0ede7 tracing/probes: Reject $arg0 in meta argument expansion
  • e0fa737783b5 mm/vmstat: fold stranded per-cpu node stats when a node comes online
  • 126a70bf1a08 mm/hugetlb: fix list corruption in allocate_file_region_entries()
  • 32134cf9211b mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()
  • 7d3e1d3a0dce fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes
  • c091462e46f7 selftest: fix headers in fclog.c
  • 9668ffe0e2a5 mm/util: don't read __page_2 for order-1 folios in snapshot_page()
  • 2be94d6b2078 mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE
  • 2205263b1e01 fortify: Disable -Wstringop-overread in tests
  • 96b0aa79b0e1 pinctrl: bm1880: add missing select GENERIC_PINCONF
  • 5aaa06dfc10f erofs: cap LZMA stream pool size
  • ad0ad3c228b6 pinctrl: devicetree: don't free uninitialized dev_name on error path
  • 93d934668047 pinctrl: microchip-sgpio: add missing select REGMAP_MMIO
  • 6da8f37419dd iommu/iommufd: Fix IOPF group ownership UAF
  • 564ac339c0f8 iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace
  • ee2212b48232 iommufd/viommu: Publish a vDEVICE only after vdevice_init() succeeds
  • 294b464b2be7 iommufd/viommu: Release the igroup lock on the vdevice_size error path
  • 062aa5dcc49a mshv: Order pt_vp_array publish against irqfd assertion path
  • f50f5d3972da mshv: Fix level-triggered check on uninitialized data
  • fc362bfcb060 mshv: adjust interrupt control structure for ARM64
  • 72a90ce4918b mshv: Fix race in mshv_irqfd_deassign
  • cfc686a1174a iomap: add a separate bio_set for iomap_split_ioend
  • 9be4a66f019e ksmbd: fix use-after-free in __close_file_table_ids()
  • 213b4568f6e5 ksmbd: return success for deferred final close
  • cebba11df714 drm/i915/hdmi: Poll for 200 msec for TMDS_Scrambler_Status
  • e51becb8f337 qede: sync udp_tunnel ports outside qede_lock in the recovery path
  • 51c52e493346 spi: spi-nxp-fspi: add per-SoC SDR/DTR clock rate limits for all supported SoCs
  • caeaaf23f7c3 sched/deadline: Use revised wakeup rule only for running dl_server
  • 5a73e8c632c3 octeontx2-pf: Set correct sequence for carrier off and tx queue stop
  • b90916156b47 net: libwx: fix FDIR ATR queue mismatch for software VLAN packets
  • 6bf322ab0741 ptp: netc: fix potential interrupt storm caused by incorrect unbind order
  • 1e0dfb7e7a5d net: dsa: mt7530: error out on failed reads in MT7531 PHY polling
  • fd9586881d47 net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend
  • 54e07a158f7a riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove
  • b297559dc2f2 accel/qaic: use sizeof(*trans_hdr) for transaction length check
  • 01bd01b61ad9 riscv: drop __init from vec_check_unaligned_access_speed_all_cpus
  • a20a0010eb64 tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions
  • 9b604041f100 tracing/mmiotrace: Reset dropped_count in mmio_reset_data()
  • fc97dcb42fb4 fprobe: Fix module reference count leak on error in register_fprobe()
  • 84b5aa55de7c drm/i915/dp: Ignore the sink's DSC max FRL rate without a PCON DSC encoder
  • 50edffd0854f can: isotp: check register_netdevice_notifier() error in module init
  • b4f8c33593f2 net: sxgbe: check descriptor ring allocation failures
  • 42b87cfd9666 net: sxgbe: free TX rings on RX allocation failure
  • 69a258a5a322 scsi: target: Clear cmd_cnt when initial counter enrollment fails
  • 54c6fb24c602 scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req
  • ff333def3147 scsi: ufs: core: Revert "Delegate the interrupt service routine to a threaded IRQ handler"
  • c249cfe1d8df scsi: ufs: core: Avoid IRQ thread wakeup during active UIC command
  • e50420448999 scsi: ufs: core: Cancel RTC work in active-active suspend
  • bdd8a1297ef1 scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE
  • 613aaeeaf8cb net: phylink: put link_gpio if phylink_create fails
  • 5ea70ad040c1 x86/boot: Add volatile, clobbers and zero-length test in memcmp()
  • 5576afebf726 Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync
  • e8f9fef362ba Bluetooth: hci_conn: hold conn reference in abort_conn_sync()
  • de17305393ec Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists
  • c618a9a5b08e Bluetooth: btintel: Validate length before parsing diagnostics TLV
  • 3b921533e8aa Bluetooth: ISO: fix refcounting of iso_conn
  • e941799c31f6 Bluetooth: ISO: ensure no dangling hcon references in iso_conn
  • 82e982f54f96 Bluetooth: ISO: avoid deadlocks in iso_sock_timeout
  • e76a0ae6542a Bluetooth: ISO: fix leaking sk after socket release
  • 4e9b5e8669b3 Bluetooth: ISO: hold sk properly in iso_conn_ready
  • 09a69828ae59 Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release
  • cde36776cfe6 Bluetooth: ISO: Fix not updating BIS sender source address
  • dfce8d30fc5b Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis()
  • 1fc2132950c2 Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos
  • e8e9cff6d80e Bluetooth: ISO: lock sk in iso_connect_ind
  • 3120664aa333 Bluetooth: ISO: Fix data-race on iso_pi(sk) in socket and HCI event paths
  • f1f167991a68 Bluetooth: HCI: Add initial support for PAST
  • 72d5bb1d77d7 Bluetooth: ISO: lock sk in iso_sock_getname
  • 58e3c5289ad2 Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp
  • 63c0f396a18b Bluetooth: ISO: clear iso_data always when detaching conn from hcon
  • 4e1f45de5b31 ice: suppress DPLL errors during reset recovery
  • 6ebbf198e76c idpf: Fix mailbox IRQ name leak on request failure
  • d44081c61dc9 idpf: adjust TxQ ring count minimum
  • ae7120102e1b hwmon: (pmbus) Fix return value from pmbus_update_byte_data()
  • 276f1f180f55 net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller
  • 2c148a31ca01 netfs: release readahead folios on iterator preparation failure
  • 291ebecdf315 netfs: handle single writeback rolling buffer allocation failure
  • 627826ef4208 netfs: clear PG_private_2 on copy-to-cache append failure
  • b558e07708d8 wifi: mac80211: validate individual TWT params before driver setup
  • f82a2ded3d7a net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister()
  • acbf711a2066 powerpc/boot: Fix treeboot-akebono CPU node lookup check
  • b407b98cf665 powerpc/boot: Fix treeboot-currituck CPU node lookup check
  • 3d24f2e5641b powerpc/boot: Fix simpleboot CPU node lookup check
  • db986098f308 rtase: fix double free of multi-frag skb on DMA map failure
  • 5a6b0ccb8b01 hwmon: (adt7470) Fix PWM auto temp state array and bounds check
  • 96ad57d31763 hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read
  • ddd689bd7226 hwmon: (adt7470) Use cached PWM frequency value
  • 1d6b54dbe885 hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks
  • d5d4034bb6f6 hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read()
  • 82d65f7ef11e hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread
  • 3e06ff0c79ea hwmon: (adt7470) Fix cache updated before hardware write on I2C error
  • 28548ecc2b45 hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors
  • ae20a8a4de06 forcedeth: fix UAF of txrx_stats in nv_remove
  • 2e0c6761c055 net: bridge: mrp: fix Option TLV length in MRP_Test frames
  • 1b722740ac5c hwmon: (nct6775-core) Prevent access to unsupported weight registers
  • 5ec5f00fc606 net: do not send ICMP/NDISC Redirects when peer allocation fails
  • 2332d35aaf20 hwmon: (nzxt-smart2) DMA-align output buffer
  • 075fce376cf8 hwmon: (lm90) Only report alarms if driver is ready
  • c498adfd4c3e hwmon: (sht3x) Fix unaligned accesses
  • 08aee6d45eef hwmon: (ltc4282) Fix reading the minimum alarm voltage
  • b60e8486c04d hwmon: (ina2xx) Fix various overflow issues
  • e627f4ad9eea hwmon: (ina2xx) Shift INA234 shunt and current registers
  • fdfde077e025 hwmon: (ina2xx) Add support for INA234
  • 8da94361f9ae hwmon: (ina2xx) Make it easier to add more devices
  • a42d727dae57 hwmon: (nct6775-core) Fix number of temperature registers for NCT6116
  • e28d478c003d spi: spi-cadence: Move TX FIFO full busy-wait into FIFO
  • d3337eefab62 spi: spi-cadence: supports transmission with bits_per_word of 16 and 32
  • fcc3d77fef02 ASoC: tas2781: Use correct calibration data for SINEGAIN2 register
  • b2851429afc5 smb: client: fix buffer leaks in SMB1 read and write
  • 9e24b47ef81d scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race
  • 72815741715b scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer
  • 3ef209ca0b4b scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer
  • 8e0996418590 pinctrl-amd: Don't clear S4 wake bits at probe
  • ceb00cb87a22 xsk: drain continuation descs after overflow in xsk_build_skb()
  • 411554cb868b xsk: use a smaller new lock for shared pool case
  • 05e283466b86 xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx
  • 814c5b159003 selftests/net/af_unix: test listen() rejects wrong socket states
  • 643ec3e24a49 selftest: af_unix: Create its own .gitignore.
  • 0372a5219112 selftests: af_unix: Add tests for ECONNRESET and EOF semantics
  • 5c170577049f af_unix: fix listen() succeeding on sockets in the wrong state
  • b1d480fce05f rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()
  • f6787fdffcae rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled
  • 4147866087fb ASoC: SDCA: Ensure that Control Range is large enough for header
  • 16b553c46e34 netfilter: nft_payload: fix mask build for partial field offload
  • e6f4b4b40db8 ipvs: do not mangle ICMP replies for non-first fragments
  • ce96c40a049b ipvs: fix places with wrong packet offsets
  • 00eb23829fd0 ipvs: fix the checksum validations
  • d186f77d18bd netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
  • 63ba12b664a2 netfilter: nf_tables: make nft_object rhltable per table
  • adf1a3ba27ad assoc_array: trim the final shortcut word using the current chunk end
  • 3d9f16c0b643 keys: make keyring key-chunk byte order agree with keyring_diff_objects()
  • e9417d21a22a keys: fix out-of-bounds read in keyring_get_key_chunk()
  • 6469ad300508 KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type
  • 31d491f9da94 KVM: arm64: Reject guest_memfd memslots when the VM has MTE
  • db1c4a8e9080 mshv: Fix sleeping under spinlock in mshv_portid_alloc
  • a920ead0bc2f mshv: Fix duplicate GSI detection for GSI 0
  • b215cb70e14c Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation
  • d397787dbc4b Drivers: hv: Allocate the paravisor SynIC pages when required
  • 74d20e3cf88e Drivers: hv: Rename fields for SynIC message and event pages
  • 82cdbb6155a2 arch/x86: mshyperv: Discover Confidential VMBus availability
  • 6e70eba930a2 drm/mediatek: Check CRTC state before freeing
  • f74554e67ccf netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()
  • ec81ecd2ac09 phy: zynqmp: fix runtime PM leak on probe allocation failure
  • 86fb88ac8c91 phy: zynqmp: fix clock error handling in xpsgtr_phy_init()
  • dff474e723ed btrfs: raid56: fix an incorrect csum skip during scrub
  • 4d4ef6627304 btrfs: zoned: reset meta_write_pointer on zone reset
  • deddd28fd83c btrfs: zoned: fix deadlock between metadata writeback and transaction commit
  • 762561c43859 btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag
  • cfa7e2734877 of: reserved_mem: prevent OOB when too many dynamic regions are defined
  • f5edba9bc69d ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup
  • 3cbfb9b886dc ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup
  • 3fd94b9ffe99 phy: qcom: m31-eusb2: Fix return value of init call
  • 9355f526c821 ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources()
  • a0f288ebe6d8 ata: sata_mv: accept 1 or 2 resources in platform probe
  • 8229a5388854 selftests/seccomp: Fix pointer type mismatch build error
  • 99dc2c143dfc selftests/lkdtm: rename STACKLEAK_ERASING to KSTACK_ERASE
  • 094145989b31 gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe()
  • 3808bab5d95a iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE
  • 0679c0c189d2 dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open()
  • 9086b488f273 dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA
  • 2ef9bb422dd6 pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151
  • 3e55d2809547 pinctrl: qcom: Unconditionally mark gpio as wakeup enable
  • 54a62153c765 thunderbolt: Prevent XDomain delayed work use-after-free on disconnect
  • d01e88d421a6 mm/slab: prevent unbounded recursion in free path with new kmalloc type
  • 3e957c9b160c lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled()
  • 98f57011e6cd HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report
  • bc3bba4656ad HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write
  • df0f33293c0a HID: logitech-dj: Standardise hid_report_enum variable nomenclature
  • 302eb8765132 ALSA: hda/realtek: add quirk for HP Dragonfly Folio G3 2-in-1
  • e8362523fd1b drm/gpusvm: publish dpagemap early to avoid device mapping leak on error
  • a5cdd2407dd8 net: mpls: initialize rtm_tos in mpls_getroute()
  • 85b94a74a0b8 netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge()
  • 9bb3714e0998 kunit: tool: Terminate kernel under test on SIGINT
  • d36086cd1826 kunit: tool: skip stty when stdin is not a tty
  • 285641eb82f0 netfilter: nf_conntrack_expect: restore helper propagation via expectation
  • 7b923c78b50d Linux 6.18.43
  • bfe7f9993467 x86/bugs: Make Safe-RET robust against interrupt injection
  • 054f69ce6232 Linux 6.18.42-xanmod1
  • 764d67d28fa6 Merge tag 'v6.18.42' into 6.18
  • 856a9b51680c Linux 6.18.42
  • 0f33b1c457c2 KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug
  • 846ed916cfa0 gpu: Fix uninitialized buddy for built-in drivers
  • bcb29986bbba net: stmmac: fix dwmac4 transmit performance regression
  • a0d1a11b90a5 net/mlx5e: Fix NULL pointer dereference in ioctl module EEPROM query
  • f282242906c1 usb: gadget: f_tcm: synchronize delayed set_alt with teardown
  • aeebcfa8237c rust: device: avoid trailing ; in printing macros
  • e94e820df37d rust: allow suspicious_runtime_symbol_definitions lint for Rust >= 1.98
  • 6ce0db97fb37 mm/damon/core: disallow overlapping input ranges for damon_set_regions()
  • 4b6f1d6d5d07 mm/damon/core: validate ranges in damon_set_regions()
  • deead12d2e65 i3c: mipi-i3c-hci: Fix handling of shared IRQs during early initialization
  • 811b581fae65 i3c: mipi-i3c-hci: Fix Hot-Join NACK
  • 4fd5b33faf09 pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI
  • c389893bb403 pmdomain: imx93-blk-ctrl: convert to devm_* only
  • dc8347f263b2 net: ipa: fix SMEM state handle leaks in SMP2P init
  • 4c1e8ccd8655 ata: libata-core: Reject an invalid concurrent positioning ranges count
  • 9466dc5e377f bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline()
  • a88c2a70ea0a bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c
  • c73b8795b45f octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF
  • 4467fa514482 octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify
  • ae5ae3d5bfaa net: mana: Optimize irq affinity for low vcpu configs
  • 6d13eaa13341 net: mana: Validate the packet length reported by the NIC
  • 7b7bb07efe41 fs/resctrl: Fix use-after-free during unmount
  • d48cf914c739 fs/resctrl: Move RMID initialization to first mount
  • 682d3c2cd20e fs/resctrl: Move allocation/free of closid_num_dirty_rmid[]
  • 8c5925f0fa12 x86,fs/resctrl: Rename some L3 specific functions
  • 696c34a1964f x86,fs/resctrl: Rename struct rdt_mon_domain and rdt_hw_mon_domain
  • ad4ea2a169a4 fs/resctrl: Split L3 dependent parts out of __mon_event_count()
  • 5b82af744e06 mmc: vub300: fix use-after-free on probe failure
  • 73d397ab54f2 mmc: vub300: rename probe error labels
  • 8ced1d242c34 dm: avoid leaking the caller's thread keyring via the table device file
  • dd73cc92a55d cred: add kernel_cred() helper
  • af7a4c2caa7a accel/amdxdna: reject command submission on devices without a submit op
  • 62dae36be7a6 ovl: use linked upper dentry in copy-up tmpfile
  • 043acb00e4ed dmaengine: dw-edma-pcie: Reject devices without driver data
  • 277a035cda47 dmaengine: dw-edma: Fix confusing cleanup.h syntax
  • 19360c25135f mtd: maps: vmu-flash: fix fault in unaligned fixup
  • b8271be34bce kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES
  • 3d561f46fa78 mm/sparse-vmemmap: fix vmemmap accounting underflow
  • 8af652cd9946 remoteproc: xlnx: Check remote core state
  • 6fc1919a6f2e cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size
  • 89b2ae039d18 cxl/pci: Remove CXL VH handling in CONFIG_PCIEAER_CXL conditional blocks from core/pci.c
  • eeab77506992 cxl/pci: Remove unnecessary CXL RCH handling helper functions
  • a64661dccb2e cxl/pci: Remove unnecessary CXL Endpoint handling helper functions
  • 5d964cb2b7bc SUNRPC: Return an error from xdr_buf_to_bvec() on overflow
  • b50b2cb87e7a SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists
  • a112b91dd634 sunrpc: allocate a separate bvec array for socket sends
  • 3120f21df3fb NFSD: pass nfsd_file to nfsd_iter_read()
  • 6876f767b049 pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP
  • 7185c5262435 gpu/buddy: bail out of try_harder when alignment cannot be honoured
  • 9634fd144cdc drm: drop lib from header search path.
  • 65677f7a20c4 gpu: Move DRM buddy allocator one level up (part two)
  • 09755dc62b02 netfilter: nf_conntrack_sip: validate skb_dst() before accessing it
  • a1a94a00b884 netfilter: nf_conntrack_sip: remove net variable shadowing
  • d01c913febea netfilter: nft_fib: reject fib expression on the netdev egress hook
  • beeda5bf7857 netfilter: nf_tables: remove register tracking infrastructure
  • 1de827e24d0a arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers
  • 0d810ff7a6f6 arm64: dts: qcom: correct RBR opp entry
  • 690fb82c4122 VDUSE: avoid leaking information to userspace
  • 7764e9c727d5 vduse: take out allocations from vduse_dev_alloc_coherent
  • db5c554b36d5 vduse: remove unused vaddr parameter of vduse_domain_free_coherent
  • 82e48ad2a132 vduse: return internal vq group struct as map token
  • b1f38c3ec620 xfs: don't replace the wrong part of the cow fork
  • 3bca70235a70 fuse-uring: fix race between registration and connection abortion
  • 40879c39d674 audit: fix recursive locking deadlock in audit_dupe_exe()
  • 91b64f0be416 audit: use 'unsigned int' instead of 'unsigned'
  • eef6914f2b45 audit: widen ino fields to u64
  • c5772ced573e landlock: Account all audit data allocations to user space
  • a95b62759f3b landlock: Fix formatting
  • 682a0066dde0 drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources
  • 81ea8e822185 fscrypt: Avoid dynamic allocation in fscrypt_get_devices()
  • 337022d9dfac ksmbd: validate ACE size against SID sub-authorities
  • f1eba60db813 ksmbd: bound DACL dedup walk to copied ACEs
  • 847ecd4eb3c1 ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL
  • b6d3cc6a5244 ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
  • 17e6b8c4319f net: qrtr: ns: Raise node count limit to 512
  • 7dd26adf7e7d ublk: wait on ublk_dev_ready() instead of ub->completion
  • 5a15eaa50f92 drm/xe/uapi: Reject coh_none PAT index for CPU_ADDR_MIRROR
  • 5488d3a69d20 dm-verity: fix buffer overflow in FEC calculation
  • 3f31bde63f9a dm-verity-fec: replace {MAX,MIN}_RSN with {MIN,MAX}_ROOTS
  • d47281b9a447 dm-verity-fec: fix reading parity bytes split across blocks (take 3)
  • a556189c0675 dm-verity-fec: fix the size of dm_verity_fec_io::erasures
  • 22400725de07 bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops
  • 15a7cb71a574 drm/amdgpu: fix check in amdgpu_hmm_invalidate_gfx
  • ab7b40c638e0 drm/amd/pm: fix smu13 power limit range calculation
  • 6405c4e75b3b drm/amdgpu: fix aperture mapping leak
  • 08fee493e026 drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
  • 68eab5a64ddb drm/amdgpu: fix resource leak on ACP reset timeout
  • ffb33d466a68 drm/amdgpu: fix division by zero with invalid uvd dimensions
  • 8c6d84a54823 drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()
  • bd868c077f67 drm/amdgpu/vcn4: avoid rereading IB param length
  • 7eebef042c12 drm/amdgpu/vce: fix integer overflow in image size
  • f7e9eeaccca5 drm/amdgpu/soc24: reset dGPU if suspend got aborted
  • dc3f5da1ba8e drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()
  • 76c977d396f1 drm/amdgpu/jpeg: fix jpeg_v5_0_1_is_idle detection
  • 058373af5955 drm/amdgpu/jpeg: fix jpeg_v4_0_3_is_idle detection
  • 042c047e8bc9 drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()
  • 05aea3344c42 drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()
  • f70bd5235d9e drm/amdgpu/gfx8: drop unecessary BUG_ON()
  • 987bedd3ea89 drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()
  • dfd9bf09fd8f drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()
  • 7e22de67e545 drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()
  • e75f71143b68 drm/amd/pm: make pp_features read-only when scpm is enabled
  • ada47af5c215 drm/amd/pm: fix amdgpu_pm_info power display units
  • 7b263cf1dd4c watchdog: s32g_wdt: remove incorrect options in watchdog_info struct
  • 79370b573e92 vxlan: mdb: Fix source list corruption on a failed replace
  • f60bac115d8d vsock/virtio: collapse receive queue under memory pressure
  • 5f5a41a48dbf tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
  • 234f9ffbd9b2 tcp: challenge ACK for non-exact RST in SYN-RECEIVED
  • fadaff3f66e1 tcp: initialize standalone TCP-AO response padding
  • 4a4f3aa6af20 rtase: Workaround for TX hang caused by hardware packet parsing
  • 6866abf59976 pppoe: reload header pointer after dev_hard_header()
  • 460b9f0609d2 ovpn: hold peer before scheduling keepalive work
  • b08526bf0bbf ovpn: fix peer refcount leak in TCP error paths
  • 100a23b1613e openvswitch: fix GSO userspace truncation underflow
  • f80ba170d7b3 mctp: serial: handle zero-length frames to prevent rx buffer overflow
  • f20dedce0429 mac802154: llsec: reject frames shorter than the authentication tag
  • 59c1d5463b7b mac802154: hold an interface reference across the scan worker
  • 472aba2603ca ila: reload IPv6 header after pskb_may_pull in checksum adjust
  • 919d0accf260 ice: use READ_ONCE() to access cached PHC time
  • 5e496f2b615c ice: reject out-of-range ptype in ice_parser_profile_init
  • 91e0249f3ef6 gve: fix Rx queue stall on alloc failure
  • 18705cace061 ksmbd: defer destroy_previous_session() until after NTLM authentication
  • 6098b55f6a0c smb: client: handle STATUS_STOPPED_ON_SYMLINK responses without a symlink target
  • 34f2a2f32af5 rbd: Reset positive result codes to zero in object map update path
  • 63d78b546eef super: fix emergency thaw deadlock on frozen block devices
  • e4406cbdd915 ice: fix PTP Call Trace during PTP release
  • b3efb4744abf ptp: ptp_s390: Add missing facility check
  • 9a8a247f0f17 s390/ptff: Export ptff_function_mask[]
  • 4afc58ea75b9 proc: Fix broken error paths for namespace links
  • 4056cc19071a net: pcs: xpcs: fix SGMII state reading
  • 80d977f280b4 net: hip04: fix RX buffer leak on build_skb failure
  • a4dfd46cc8f0 net: gro: fix double aggregation of flush-marked skbs
  • ec6d91a1bf2e net/x25: fix use-after-free in x25_kill_by_neigh()
  • 40f9a124ebbe net/mlx5e: Use sender devcom for MPV master-up
  • 900cd6d8119b net/iucv: fix use-after-free of a severed iucv_path
  • 33736ff5e7c9 net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
  • f8c498585d2a geneve: require CAP_NET_ADMIN in the device netns for changelink
  • 5d07b178bef5 net: slip: serialize receive against buffer reallocation
  • 730c7e5fea7f vxlan: require CAP_NET_ADMIN in the device netns for changelink
  • a48a889b60f7 phonet: pep: fix use-after-free in pep_get_sb()
  • 03157872da5e net: stmmac: intel: skip SerDes reconfig when rate is unchanged
  • 1b44a5f584bf iommu/vt-d: Disallow SVA if page walk is not coherent
  • 7037e7bdcd26 iomap: fix out-of-bounds bitmap_set() with zero-length range
  • f139498c5ebd io_uring/rw: fix missing ERESTARTSYS conversion in read paths
  • 65bf73bee1a4 ftrace: Add global mutex to serialize trace_parser access
  • 95376fe9c145 fscrypt: Add missing superblock check in find_or_insert_direct_key()
  • a019b074903b fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
  • c78e38745ff1 fs/super: fix emergency thaw double-unlock of s_umount
  • 89b9121c3b01 binfmt_elf_fdpic: only honour the first PT_INTERP
  • d309f8b52b34 ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP
  • c4d77740eca2 ASoC: fsl: imx-card: Skip sysclk reset for active DAIs in shutdown
  • 1a644db2cf59 amt: fix use-after-free in AMT delayed works
  • 8f5a3abc54ba libceph: remove debugfs files before client teardown
  • 3b2f1937f5fc libceph: reject zero bucket types in crush_decode
  • e67e8b694872 libceph: Reject monmaps advertising zero monitors
  • 0060ec912292 libceph: refresh auth->authorizer_buf{,_len} after authorizer update
  • 4716a64b7cc2 libceph: guard missing CRUSH type name lookup
  • 1732d89dfcd7 libceph: Fix multiplication overflow in decode_new_up_state_weight()
  • 4e7ebfaa0d14 libceph: bound get_version reply decode to front len
  • 7d03e08b763f ceph: fix writeback_count leak in write_folio_nounlock()
  • a7c2dfa610a1 ceph: fix refcount leak in ceph_readdir()
  • a4228b93706f ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
  • 3bf0e349cbb4 sctp: close UDP tunnel sockets during netns teardown
  • be6aae9d1b91 sctp: avoid auth_enable sysctl UAF during netns teardown
  • 85aca407c560 sctp: don't free the ASCONF's own transport in DEL-IP processing
  • 3db217a4c2bd mm/huge_memory: set PG_has_hwpoisoned only after new folio head is established
  • ac7a6f61f56f mm/kmemleak: fix checksum computation for per-cpu objects
  • f2b293359924 afs: Fix afs_edit_dir_remove() to get, not find, block 0
  • d64f6c02495f mptcp: pm: userspace: fix use-after-free in get_local_id
  • 6cd3c3d63155 mptcp: only set DATA_FIN when a mapping is present
  • 6c936b5ad557 mptcp: decrement subflows counter on failed passive join
  • 35c4b274d4cc Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates"
  • 64ab0964c7db arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates
  • 9cd4b1a52eff arm64: make huge_ptep_get handled unaligned addresses
  • 9025946adec9 tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err()
  • 3b3be8653c59 tracing/probes: Fix potential underflow in LEN_OR_ZERO macro
  • 949ac1aeb37b tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args()
  • 6b5098d74581 tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match()
  • b6a4575f2292 tracing: Fix union collision of module and refcnt for dynamic events
  • cf5a82bef623 tracing: Fix resource leak on mmiotrace trace_pipe close
  • 8464427e1c17 tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
  • 1f2e7cd0ff97 tracing: Fix context switch counter truncation
  • 1da310b94504 misc: nsm: pin the module while the device is open
  • 8f068342096b misc: nsm: only unlock nsm_dev on post-lock error paths
  • caba30eb8bd3 intel_th: fix MSC output device reference leak
  • 59dd34854202 mei: bus: access mei_device under device_lock on cleanup
  • 511887235727 selftests: ntsync: correct CONFIG_NTSYNC name
  • b2a3eeb57ba2 serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms
  • 4fae473b856b serial: sc16is7xx: implement gpio get_direction() callback
  • 635be8b097f0 uio_hv_generic: Bind to FCopy device by default
  • cf26dd2d8415 comedi: comedi_parport: deal with premature interrupt
  • 9bb71b59e0aa x86/boot/compressed: Disable jump tables
  • 4f2db41a09eb firmware: stratix10-svc: fix memory leaks and list corruption bugs
  • 3ff7c1dbf722 rhashtable: clear stale iter->p on table restart
  • d43c5c0c9355 cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
  • 4427a33faabb LoongArch: Retrieve CPU package ID from PPTT when available
  • 38b025fcdc45 LoongArch: Move jump_label_init() before parse_early_param()
  • 6ab0abb5a2e0 LoongArch: Fix oops during single-step debugging
  • a94d6726ec86 LoongArch: Fix address space mismatch in kexec command line lookup
  • c404b1f30b25 objtool/rust: add one more noreturn Rust function for Rust 1.99.0
  • 8ccfb3b315a0 rust: allow clippy::unwrap_or_default globally
  • 6db0c42c87c4 rust: time: fix as_micros_ceil() to round correctly for negative Delta
  • 12be1d75e9b2 rust_binder: only print failure if error has source
  • cc3bbff10b1a platform/loongarch: laptop: Explicitly reset bl_powered state when suspend
  • 1cd4e9b7967d binfmt_misc: set have_execfd only once the interpreter is opened
  • 2bc6bf70d410 exec: fix unsigned loop counter wrap in transfer_args_to_stack()
  • 780b04d09c94 Bluetooth: RFCOMM: Fix session UAF in set_termios
  • a42f5536ea9c Bluetooth: hci_sync: Protect UUID list traversal
  • 91eff666c907 staging: rtl8723bs: fix inverted HT40 secondary channel offset
  • 875479f18835 staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()
  • 0dbaff14fd6a wifi: ath11k: fix refcount leak in ath11k_ahb_fw_resources_init()
  • efe9de178e4b wifi: brcmfmac: set F2 blocksize to 256 for BCM43752
  • 044fca8f45ba wifi: brcmfmac: make release_scratchbuffers idempotent
  • 9cb72f67e150 wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses
  • 263816e92e8d wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
  • ab4d213393e8 wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
  • e511e93abd6e wifi: wilc1000: validate assoc response length before subtracting header
  • 9375a4ea4121 wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper
  • 18965470d41e wifi: ath6kl: fix use-after-free in aggr_reset_state()
  • 58c6c8dc2e02 wifi: ath6kl: fix OOB access from firmware ADDBA window size
  • 1395327a9661 ALSA: timer: don't re-enter an instance callback that is still running
  • 426c0ff1c433 ALSA: timer: drain a slave's callback before its master detaches it
  • 3bc4de57fc7d ALSA: hda: codecs: hdmi: disable keep-alive before audio format change
  • 6a10025c7fd0 ALSA: seq: close a re-opened queue timer in the destructor
  • 2ec8f95a08fe ALSA: hda/realtek: Fix speakers on Lunnen Ground 14
  • 4091b216d11b media: vpif_capture: fix OF node reference imbalance
  • 1349af7f87df media: vivid: fix cleanup bugs in vivid_init()
  • 492c97cb50fe media: vivid: check for vb2_is_busy() when toggling caps
  • 26e7a8ac286f media: vivid: add vivid_update_reduced_fps()
  • 3780ad381071 media: vimc: fix reference leak on failed device registration
  • 86ece01fba2d media: vidtv: fix reference leak on failed device registration
  • 16ae8c166e78 media: verisilicon: Export only needed pixels formats
  • b88c929188e3 media: vb2: use ssize_t for vb2_read/vb2_write
  • 072a883061a4 media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely
  • cf9732fd6c4f media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()
  • 3068ab802fc9 media: v4l2-ctrls: validate HEVC active reference counts
  • 836cfffb2ddb media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete()
  • 7e6521dd747e media: ti: vpe: unwind v4l2 device registration on probe error
  • 127fc44e8325 media: tegra-video: vi: fix invalid u32 return value in format lookup
  • 118c2f5d1d36 media: synopsys: hdmirx: Fix HPD lane hold time
  • b5184b3f0e9d media: sun4i-csi: Return queued buffers on start_streaming() failure
  • 931abe1deb65 media: stm32: dcmi: unregister notifier on probe failure
  • ed342a86bb2f media: stm32-dcmipp: Return queued buffers on start_streaming() failure
  • b7936e8cbec1 media: saa7134: Fix a possible memory leak in saa7134_video_init1
  • a7a141e4e93c media: rzg2l-cru: Skip ICnMC configuration when ICnSVC is used
  • 894e83509c66 media: rtl2832_sdr: Return queued buffers on start_streaming() failure
  • 2c71bda6edc6 media: rtl2832: fix use-after-free in rtl2832_remove()
  • 64cb15878b35 media: radio-si476x: Unregister v4l2_device on probe failure
  • a58d01a0ed39 media: qcom: camss: Fix RDI streaming for CSID GEN3
  • c39a1d9fde82 media: qcom: camss: Fix RDI streaming for CSID GEN2
  • 4e451100b35e media: qcom: camss: Fix RDI streaming for CSID 680
  • cb16b79a2be2 media: pwc: Return queued buffers on start_streaming() failure
  • 9afd605dcd96 media: pwc: Drain fill_buf on start_streaming() failure
  • 08ddfd628a2d media: pci: dm1105: Free allocated workqueue
  • 4e077bcb5e1f media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding
  • 28ae75dba701 media: nxp: imx8-isi: Fix potential out-of-bounds issues
  • 659a7cea0be8 media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path
  • 4702afbd56f1 media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure
  • 9e61258fbc3c media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe
  • 181a0aeefd56 media: nuvoton: npcm-video: fix memory leaks in probe and remove
  • 2147acb948a9 media: nuvoton: npcm-video: fix error handling in npcm_video_init()
  • 264b5380c4f8 media: msi2500: Return queued buffers on start_streaming() failure
  • 1391b75bf011 media: meson: vdec: Fix memory leak in error path of vdec_open
  • 18e3b838e09d media: marvell-cam: fix missing pci_disable_device() on remove
  • cf48e9db8565 media: iris: Fix use IRQF_NO_AUTOEN when requesting the IRQ
  • d56044558a75 media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges
  • 00a98fb2a6fb media: imx219: Fix maximum frame length in lines
  • 7337c88205ed media: i2c: alvium: fix critical pointer access in alvium_ctrl_init
  • c68c4ce72feb media: cx23885: add ioremap return check and cleanup
  • f468b7ee5d63 media: cx231xx: fix devres lifetime
  • f24ca8b53fe1 media: chips-media: wave5: Move src_buf Removal to finish_encode
  • 9924cb548ee7 media: cedrus: skip invalid H.264 reference list entries
  • 000e51afb606 media: cedrus: Fix missing cleanup in error path
  • 73504935e436 media: cedrus: clean up media device on probe failure
  • 6efe665356ec media: cec: seco: unregister adapter on IR probe failure
  • 0459a4304cff media: aspeed: fix missing of_reserved_mem_device_release() on probe failure
  • 391fe3e36e59 media: amlogic-c3: Add validations for ae and awb config
  • 73bd27798653 media: airspy: Return queued buffers on start_streaming() failure
  • a096a6aba601 drm/v3d: Reach the GMP through the hub registers on V3D 7.x
  • a2212fef8e18 drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict
  • 6deaa3172018 drm/vc4: Prevent shader BO mappings from becoming writable
  • b1379f0c42b8 drm/vmwgfx: Validate vmw_surface_metadata::array_size
  • 2b85e19792be drm/amd/display: Fix missing DCE check in dm_gpureset_toggle_interrupts()
  • a38f2724eb93 drm/vc4: Shut down BO cache timer before teardown
  • ee44ea4f7e30 drm/amd/display: Fix flip-done timeouts on mode1 reset
  • ba7b6444097a drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
  • fd2de80f28a0 drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge
  • 490ceacd2162 drm/amd/display: Fix backlight max_brightness to match exported range
  • 9c0432044d34 drm/amd/display: Force PWM backlight on Lenovo Legion 5 15ARH05
  • 51ea665c30c4 drm/amd/display: dce100: skip non-DP stream encoders for DP MST
  • 0b9fa4272e24 drm/amd/display: consolidate DCN vblank/flip handling onto vupdate_no_lock
  • 679f23f0a360 drm/amd/display: set new_stream to NULL after release
  • 123692ebc1ea drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X)
  • d8dc3a9e815d drm/amdgpu: Fix VFCT bus number matching with soft filter
  • 312278b30919 drm/amdgpu: Release VFCT ACPI table reference
  • e64b2f1e826a drm/panthor: return error on truncated firmware
  • 22aa7fb4e7d0 drm/ttm: Account for NULL and handle pages in ttm_pool_backup
  • b2d8b66c6739 drm/virtio: Don't detach GEM from a non-created context
  • a4a1866d50c4 drm/gfx10: Program DB_RING_CONTROL
  • e163c5a0946d drm/amd/pm: fix smu14 power limit range calculation
  • e3bcd3bf7eec drm/i915/mst: limit DP MST ESI service loop
  • 726f27bca93e drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU
  • 37951ce1567c drm/i915/gem: Do not leak siblings[] on proto context error
  • 1173190412fb drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()
  • 5df5a59c32b4 drm/amd/amdgpu: disable ASPM on VI if pcie dpm is disabled
  • 8b2da44446f9 drm/i915/bios: range check LFP Data Block panel_type2
  • cbec6a57959a drm/i915: Return NULL on error in active_instance
  • d20b5c139b29 drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
  • 09da54636bac drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
  • 51fd52087165 drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()
  • 4c0948332536 drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()
  • 3d2ef8d38949 drm/i915/hdcp: check streams[] bounds before overflow
  • 1f876bd8adc7 drm/i915/hdcp: require monotonically increasing seq_num_v
  • 35be0e2c6862 drm/virtio: bound EDID block reads to the response buffer
  • 4ee77643e619 drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference
  • 8a77ccf9cb99 drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips
  • abce3276c57e drm/amdkfd: fix 32-bit overflow in CWSR total size calculation
  • fd1691ec6270 drm/amdkfd: Check bounds on CRIU restore queue type and mqd size
  • 50319efb865f drm/amdkfd: Check bounds in allocate_event_notification_slot
  • 14a631dca9df drm/amdkfd: Use kvcalloc to allocate arrays
  • 6253bb56bb2e drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM
  • c45fafa69fe3 drm/imagination: fix error checking of pvr_vm_context_lookup()
  • b983a35dad37 drm/imagination: Fix user array stride in pvr_set_uobj_array()
  • c88fdbf3da26 drm/imagination: Fix double call to drm_sched_entity_fini()
  • c1954c66662d drm/xe: Hold a dma-buf reference for imported BOs
  • 038d0b80ab77 drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds
  • 90a8a938e0ca drm/xe: Return error on non-migratable faults requiring devmem
  • 3e1f909556aa drm/radeon: fix r100_copy_blit for large BOs
  • fbb9effc8168 drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit()
  • 45db277b2e1e drm/i915/gem: Add missing nospec on parallel submit slot
  • 748d425e53c3 drm/displayid: fix Tiled Display Topology ID size
  • 5452eb5c1663 drm/sysfb: Return errno code from drm_sysfb_get_visible_size()
  • 154795885e8f drm/sysfb: Avoid possible truncation with calculating visible size
  • 4e109faa9ea2 drm/nouveau: fix reversed error cleanup order in ucopy functions
  • 315d2e5741a8 drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
  • 3fb10ec43c25 drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT
  • 9c2b01508831 drm/amdgpu/gfx9: Fix Ring and IB test fail after mode2
  • f835eda74cf6 drm/sysfb: Avoid truncating maximum stride
  • 7daefc6d5195 drm/sysfb: Do not page-align visible size of the framebuffer
  • ddba17b3dfa0 drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO
  • d068a2f53afc drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older
  • b3a01cda0ae1 drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2)
  • e28420e36542 drm/amdgpu/gfx: fix cleaner shader IB buffer overflow
  • d5c70523cafa drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
  • e2c29d51c0f6 drm/imagination: Fit paired fragment job in the correct CCCB
  • 1e5827839ad0 drm/dp/mst: fix buffer overflows in sideband chunk accumulation
  • 533d9e2bede4 drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
  • c0384d6872f4 drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
  • 943fa73ea0ef drm/imagination: Count paired job fence as dependency in prepare_job()
  • 6ab29a868357 drm/rockchip: analogix_dp: Add missing error check for platform_get_resource()
  • 50cd8a7e98dd drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video()
  • 86ab4d93b3d4 drm/tidss: Fix missing drm_bridge_add() call
  • 300a2d970a53 drm: renesas: rzg2l_mipi_dsi: Move rzg2l_mipi_dsi_set_display_timing()
  • aa8ad3e0d1fe drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay
  • 786d690257ec bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
  • 3a924139cf52 net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets()
  • 391a23c50385 mctp: check register_netdevice_notifier() error in mctp_device_init()
  • 74ecebfbf155 ptp: netc: explicitly clear TMR_OFF during initialization
  • 16df2d154ec8 rds: tcp: unregister sysctl before tearing down listen socket
  • 1db34097998c ipv6: Change allocation flags to match rcu_read_lock section requirements
  • 684d4d0bda95 ice: prevent tstamp ring allocation for non-PF VSI types
  • a32604e8d9e2 ice: fix LAG recipe to profile association
  • 3a8134546767 ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV
  • 5d54d603cf3e net: ipv6: fix dif and sdif mismatch in raw6_icmp_error
  • e60e6009d3ba octeontx2-pf: tc: fix egress ratelimiting
  • d612754a515c net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation
  • a7e430349fc5 net/mlx5e: Report zero bandwidth for non-ETS traffic classes
  • cdddc8188db4 net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule
  • 87b39a8c875c net/mlx5: Fix MCIA register buffer overflow on 32 dword reads
  • 5f2ef3d53d37 net/mlx5: Refactor EEPROM query error handling to return status separately
  • 953d47cfe529 raw: annotate lockless match fields in raw_v4_match()
  • 8150c48fb978 net: qrtr: restrict socket creation to the initial network namespace
  • 0d57d43d7c4c hinic: remove unused ethtool RSS user configuration buffers
  • 8fc45a2a7cc2 ppp: annotate data races in ppp_generic
  • 19fe119dfa93 ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup
  • e037a41938c6 octeontx2-vf: set TC flower flag on MCAM entry allocation
  • 15a1c5f2ed2e net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
  • 55515c1b1285 net: stmmac: enable the MAC on link up for all supported speeds
  • 1bcb737fb884 net: stmmac: reset residual action in L3L4 filters on delete
  • 370dde2b70e5 net: stmmac: fix l3l4 filter rejecting unsupported offload requests
  • 55d2a8d184e2 net: stmmac: xgmac: fix l4 filter port overwrite on register update
  • 40413da85036 net: stmmac: cores: remove many xxx_SHIFT definitions
  • 4a3eea468a04 net: stmmac: socfpga: Add hardware supported cross-timestamp
  • 01d45e6b2c50 net: stmmac: socfpga: Enable TBS support for Agilex5
  • dac8c2ab943a net: stmmac: socfpga: Agilex5 EMAC platform configuration
  • d67136a931e5 net: stmmac: remove xstats.pcs_* members
  • 9f27c4f0ae35 bpf: tcp: fix double sock release on batch realloc
  • b43bb9ab6003 drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem
  • 1b8fb5a20508 tipc: fix u16 MTU truncation in media and bearer MTU validation
  • c8e4b2a567ef iomap: correct the range of a partial dirty clear
  • 279339aa8bdc drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create()
  • d18d9b2c29a1 drm/xe/i2c: Allow per domain unique id
  • 4fdb0f162ccd vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
  • 18957373920c sctp: auth: verify auth requirement when auth_chunk is NULL
  • ae0ec759865e net: dpaa: fix mode setting
  • b5ded444621b net: hsr: fix memory leak on slave unregistration by removing synced VLANs
  • 17bb59682b8e net: bridge: vlan: fix vlan range dumps starting with pvid
  • 0a347ca1d6a2 amt: make the head writable before rewriting the L2 header
  • ca0e8b661957 amt: re-read skb header pointers after every pull
  • 9ec22c8113d8 ovl: check access to copy_file_range source with src mounter creds
  • 31f5f7c959c3 ovl: port ovl_copyfile() to cred guard
  • cde234a493f6 ovl: add override_creds cleanup guard extension for overlayfs
  • 35f0b504394e cred: add scoped_with_kernel_creds()
  • 3139b806923b drm/panel: s6e3ha8: fix unmet dependency on DRM_DISPLAY_HELPER
  • 790da254031c ovl: fix trusted xattr escape prefix matching
  • 00ebbf030d8c wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
  • d5628f39fccc wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()
  • 95b0cf02731c wifi: mt76: mt7925: fix crash in reset link replay
  • d14238523ca4 wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()
  • 313343ab8cab wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()
  • c058786b09cf wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()
  • 871549814eb4 wifi: mt76: mt7915: guard HE capability lookups
  • f1ee53e08fdd wifi: mt76: mt7925: guard link STA in decap offload
  • cc4d2f8b984c ppp: annotate concurrent dev->stats accesses
  • b52ff80948d1 ppp: don't store tx skb in the fastpath
  • cb9d3e0b5569 ppp: enable TX scatter-gather
  • e740e90ca8e7 tipc: fix infinite loop in __tipc_nl_compat_dumpit
  • d536bf205c71 nexthop: initialize extack in nh_res_bucket_migrate()
  • 961e9b1e3344 gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
  • 023c5e0d0294 selftests: drv-net: increase timeout
  • fa065685c8a9 selftests: ovpn: increase timeout
  • e2b3d426c7ee selftests: ovpn: add IPV6 and VETH configs
  • 69eab5c4d9aa selftests: openvswitch: add config file
  • 340c389fd3d5 selftests: af_unix: add USER_NS config
  • fbd91910c502 tls: device: push pending open record on splice EOF
  • a8bd8c109da5 net: mctp i3c: clean up notifier and buses if driver register fails
  • 1a10fe1aa9c0 sctp: validate stream count in sctp_process_strreset_inreq()
  • c984a4184f81 pds_core: check for workqueue allocation failure
  • cf0ed2ba202f pds_core: fix auxiliary device add/del races
  • 0e87fe52b560 pds_core: order completion reads after the ownership check
  • 3a831f40e88d pds_core: yield the CPU while waiting for the adminq to drain
  • 9e0f80fac50a pds_core: fix use-after-free on workqueue during remove
  • 19ef775c91c6 pds_core: fix deadlock between reset thread and remove
  • 11092d79eb2b sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
  • 2d34421bfa26 net: txgbe: fix FDIR filter leak on remove
  • 245bfe72a5ad net: Call net_enable_timestamp() before failure in sk_clone().
  • 412279292331 soreuseport: Clear sk_reuseport_cb before failure in sk_clone().
  • f97d19928768 amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN
  • e695cb9becbb arm64: Correct value returned by ESR_ELx_FSC_ADDRSZ_nL()
  • f5b8b8ccf9a4 pds_core: reject component parameter in legacy firmware update
  • b5fcd1da0562 wifi: mac80211: recalculate TIM when a station enters power save
  • d06fea9b85f0 iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
  • e5ebe8544df1 iommu/amd: Bound the early ACPI HID map
  • d21464d93f8b wifi: mwifiex: bound uAP association event IEs to the event buffer
  • a0980682d84d vhost-net: fix TX stall when vhost owns virtio-net header
  • 59cbe6cfa0fa wan: wanxl: Only reset hardware after BAR mapping
  • 3b1d4fc3b73e nfp: Check resource mutex allocation
  • 0f7eaeb950ad wifi: mac80211: tear down new links on vif update error path
  • d053eb7e09e1 iommu/amd: Wait for completion instead of returning early in iommu_completion_wait()
  • 76fc5604308a net: airoha: Fix DMA direction for NPU mailbox buffer
  • f112df0744e2 dpaa2-eth: put MAC endpoint device on disconnect
  • 46e3bed4b071 net: airoha: Fix potential use-after-free in airoha_ppe_deinit()
  • 26ac2d360234 dpaa2-switch: put MAC endpoint device on disconnect
  • c9165e199f56 rxrpc: fix io_thread race in rxrpc_wake_up_io_thread()
  • b78547914bee gtp: parse extension headers before reading inner protocol
  • 959104253314 rds: drop incoming messages that cross network namespace boundaries
  • 992dce02bdab bonding: fix devconf_all NULL dereference when IPv6 is disabled
  • 1bc55c29cd85 net/packet: avoid fanout hook re-registration after unregister
  • 9f4f75df77c8 netlink: specs: rt-link: convert bridge port flag attributes to u8
  • 4264dbc84ca0 net: phy: marvell: fix return code
  • 8881daaafadb Bluetooth: btusb: validate Realtek vendor event length
  • 9d208de7a8f6 regulator: mt6358: use regmap helper to read fixed LDO calibration
  • 538d862cc0db hwmon: occ: validate poll response sensor blocks
  • 2f0f66199894 ovpn: use monotonic clock for peer keepalive timeouts
  • 5b96227c0e8b ovpn: fix use after free in unlock_ovpn()
  • 47cd68e050a6 selftests/net: ovpn: fix getaddrinfo memory leak in ovpn_parse_remote()
  • c5bf6b39be23 ovpn: avoid putting unrelated P2P peer on socket release
  • 2fdd6d196c65 smb: client: validate DFS referral PathConsumed
  • d6959dd79088 hwmon: (asus-ec-sensors) add missed handle for ENOMEM
  • dd6f730be95b hwmon: (asus-ec-sensors) fix EC read intervals
  • 22e449c1dd54 hwmon: (asus-ec-sensors) fix looping over banks while reading from EC
  • d5913f97b5b6 drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook()
  • d0a57f19fe28 usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect
  • 2d5dec517b53 wifi: iwlwifi: mvm: fix read in wake packet notification handler
  • eae7fdf7d446 wifi: iwlwifi: validate payload length in iwl_pnvm_complete_fn
  • 70a6de303c9b wifi: iwlwifi: fix pointer arithmetic in iwl_add_mcc_to_tas_block_list
  • a076b0c457c7 wifi: iwlwifi: mvm: validate SAR GEO response payload size
  • cdf895bfd803 ASoC: cs35l56: Use complete_all() to signal init_completion
  • 3c26e8bb14cc ASoC: cs35l56: Fix potential probe() deadlock
  • 1ddb3e0e502a ASoC: cs35l56: Don't use devres to unregister component
  • 9153fa1ee99b ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI
  • 08433c71f159 ALSA: hda: cs35l41: validate and free ACPI mute object
  • eca9fcf9f5d8 ASoC: sun4i-codec: Set quirks.playback_only for H616 codec
  • 41ae2b7d37c3 ASoC: tas2781: bound firmware description string parsing
  • 797dc567146c btrfs: free mapping node on duplicate reloc root insert
  • 9304713b70e7 btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps
  • 39f196f64bd3 btrfs: fix u32 to s64 type conversion in dirty_metadata_bytes accounting
  • f49ff44831d5 btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8
  • 450382984335 wifi: carl9170: fix buffer overflow in rx_stream failover path
  • fab6ff91d5b8 wifi: carl9170: fix OOB read from off-by-two in TX status handler
  • 9aee949c68dc wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
  • 33b5342d2080 wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
  • eb636fbc4431 wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
  • 0177e578d7a8 firewire: net: Fix fragmented datagram reassembly
  • 51516fda914c wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET
  • 9a9b0ea72d8b wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET
  • a154ca3c441a wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()
  • 8681e5addf71 watchdog: airoha: Prevent division by zero when clock frequency is zero
  • 7d1658b066de watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
  • 305c23993e43 hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop
  • 205cff797a94 hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
  • f36e12cc8cfe hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
  • 56d2deb64483 hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
  • ec477af3a7e8 hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
  • e5394605f9a9 wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin
  • 48a69cedde73 wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
  • 593072aae7fc selftests/bpf: Keep verifier_map_ptr exercising ops pointer access
  • 938bcf99f53e selftests/bpf: Adjust verifier_map_ptr for the map's excl field
  • fe7892d46921 usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits
  • 958624d63860 Revert "drm/amd/display: Add missing kdoc for ALLM parameters"
  • 03eb7a809947 RISC-V: KVM: Serialize virtual interrupt pending state updates
  • 731acda5ba77 wifi: mwifiex: fix freeze for 60 seconds caused by request_firmware
  • 0905b3ce1deb usb: typec: ucsi: Add duplicate detection to nvidia registration path
  • fe8cde072293 usb: typec: ucsi: Detect and skip duplicate altmodes from buggy firmware
  • 67d2626827e3 USB: serial: option: add TDTECH MT5710-CN
  • 601f75671b8f USB: serial: keyspan_pda: fix data loss on receive throttling
  • cbe00048b69d USB: serial: io_edgeport: cap received transmit credits
  • c1611c6744e3 USB: serial: ftdi_sio: add support for E+H FXA291
  • 1f03658f3e9b usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer
  • dcf3e2f16443 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
  • 40c706a0224b usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
  • 12b3edca90d4 USB: gadget: fsl-udc: fix dev_printk() device
  • 66956a5a4258 USB: gadget: fsl-udc: fix device name leak on probe failure
  • e5ecfb776752 USB: gadget: snps-udc: fix device name leak on probe failure
  • 4cde0b38cc0c usb: gadget: printer: fix infinite loop in printer_read()
  • f45089eaad0a usb: gadget: f_midi: cancel pending IN work before freeing the midi object
  • e239ea91b481 usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
  • ace1a0adfc78 usb: chipidea: fix usage_count leak when autosuspend_delay is negative
  • 8eca14198c20 USB: storage: add NO_ATA_1X quirk for Longmai USB Key
  • 0950ac52426b usb: musb: omap2430: Do not put borrowed of_node in probe
  • 7714fb896ed3 usb: core: port: Deattach Type-C connector on component unbind
  • fb1b50ab6992 wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
  • 217774e143d7 usb: core: sysfs: add lock to bos_descriptors_read()
  • 5f6e7b32bd1f mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
  • a8d20ba0ab51 sctp: fix auth_hmacs array size in struct sctp_cookie
  • fed1b1ddab41 net/sched: act_tunnel_key: Defer dst_release to RCU callback
  • 51c2fcc4cd2e dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync()
  • e666af5dcc90 tcp: fix TIME_WAIT socket reference leak on PSP policy failure
  • 6875ee2bef48 accel/amdxdna: Fix use-after-free of mm_struct in job scheduler
  • f6b522033bc8 drm/i915/selftests: Fix GT PM sort comparators
  • c23abdb922c3 drm/i915/wm: clear the plane ddb_y entries on plane disable
  • f0e337e7db67 ksmbd: validate compound request size before reading StructureSize2
  • 6ecb252efa0b ksmbd: pin conn during async oplock break notification
  • 5e5f298d0af6 drm/xe/wopcm: fix WOPCM size for LNL+
  • 35ba43b54111 drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves
  • c1b19d855626 drm/xe/vf: Shadow buffer management for CCS read/write operations
  • bf293b5bcff4 drm/xe/sa: Shadow buffer support in the sub-allocator pool
  • 65129a03a801 drm/xe: Allow the caller to pass guc_buf_cache size
  • cfb66ad4aa8e can: j1939: fix lockless local-destination check
  • 3f398d45f3c7 riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus()
  • 1d9a2f01b3c4 s390/checksum: Fix csum_partial() without vector facility
  • 5b06cf93341f drm/panthor: Check debugfs GEM lock initialization
  • 250474c69bc3 bpf, sockmap: Reject unhashed UDP sockets on sockmap update
  • c3e61df6fabc powerpc/vtime: Initialize starttime at boot for native accounting
  • 5c3a1cede86f powerpc/time: Prepare to stop elapsing in dynticks-idle
  • c1bbd0a6906b powerpc/85xx: Add fsl,ifc to common device ids
  • 00ba4bf87982 can: raw: add locking for raw flags bitfield
  • 479425744b21 drm/i915/gt: use correct selftest config symbol
  • 7e08ab7a061b smb/client: handle overlapping allocated ranges in fallocate
  • cefb44c367b2 Bluetooth: hci_qca: Clear memdump state on invalid dump size
  • d5b3b484b62b Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
  • ca58ad287bfc Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
  • 83b7e67698d0 Bluetooth: hci_sync: extend conn_hash lookup critical sections
  • 57059ff14d81 Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update
  • a087ed960fce Bluetooth: qca: fix NVM tag length underflow in TLV parser
  • f4e23e661a25 ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC
  • b133f007ba02 accel/ivpu: Fix wrong register read in LNL failure diagnostics
  • 1842d45f461a ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning
  • d28920db5696 ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts
  • 678d874e6ae1 ata: sata_dwc_460ex: use platform_get_irq()
  • daa80b422ed9 ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered
  • c7a150912372 scsi: core: wake eh reliably when using scsi_schedule_eh
  • 2c77ed279c4b udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf()
  • c75a950e7735 net/iucv: take a reference on the socket found in afiucv_hs_rcv()
  • cb8be318b443 ipv4: fib: free fib_alias with kfree_rcu() on insert error path
  • c9574b8a8ede ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
  • 88f87cb4b52e cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq
  • 640a33e77f91 firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context
  • fb343716fad4 ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup
  • 7f2cb99eaf53 ASoC: cs42l43: Correct report for forced microphone jack
  • 9f393d816043 ASoC: amd: ps: replace bitwise OR with logical OR in IRQ return check
  • 3b2d32f52815 ASoC: amd: ps: fix wrong ACP version string in pci_request_regions()
  • f33ad19e3e3d ASoC: amd: ps: disable MSI on resume in ACP PCI driver
  • 4801f6690f98 ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop
  • b39b08e6bee8 firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation
  • cf5708c9d78c firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()
  • 11ac7a5e75f5 wifi: cfg80211: bound element ID read when checking non-inheritance
  • 5c342437ea44 wifi: brcmfmac: initialize SDIO data work before cleanup
  • a424985c3ef2 wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
  • 44eda4a8d1dc wifi: mac80211: avoid non-S1G AID fallback for S1G assoc
  • fbaa8c31ef94 wifi: cfg80211: reject unsupported PMSR FTM location requests
  • cfbda103aeae wifi: cfg80211: validate PMSR FTM preamble range
  • 0caf6416bfbb wifi: cfg80211: validate PMSR measurement type data
  • 0b6efde0ed97 wifi: nl80211: constrain MBSSID TX link ID range
  • f8c547e543e1 wifi: nl80211: validate nested MBSSID IE blobs
  • f649dc9c5e65 wifi: cfg80211: derive S1G beacon TSF from S1G fields
  • fb052a6e2fa8 wifi: nl80211: free RNR data on MBSSID mismatch
  • 133684982dd0 wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock
  • d38f5d868a0a wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
  • 2aa1789880fa wifi: mac80211: defer link RX stats percpu free to RCU
  • 6cda91bbb8dc wifi: libertas: fix memory leak in helper_firmware_cb()
  • 5baaa1042f71 wifi: mac80211: fix fils_discovery double free on alloc failure
  • d62b55b7c7dc wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
  • 6dc76371a9a3 wifi: mac80211_hwsim: clamp virtio RX length before skb_put
  • e67dc2b8d5ac wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()
  • f442e581a889 wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
  • 9293574ac208 wifi: cfg80211: cancel sched scan results work on unregister
  • 7acc5ed2f336 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
  • ff636d7b7cba xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()
  • d8aaf06b29f5 xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
  • 9845a35986a6 xfrm: clear mode callbacks after failed mode setup
  • 9e632a70f204 RDMA/irdma: Prevent overflows in memory contiguity checks
  • 124382a2a975 selftests/alsa: Fix memory leak in find_controls error path
  • f98ae09c727d mtd: fix double free and WARN_ON in add_mtd_device() error paths
  • fcc9d50022bc RDMA/siw: publish QP after initialization
  • e221dde026af RDMA/hns: Fix potential integer overflow in mhop hem cleanup
  • d842ef03d914 RDMA/mana_ib: initialize err for empty send WR lists
  • 14e519f93a48 RDMA/erdma: initialize ret for empty receive WR lists
  • ec675b4cdfd3 RDMA/irdma: Prevent user-triggered null deref on QP create
  • 1cd56258fe1a RDMA/irdma: Remove redundant legacy_mode checks
  • ca1c29f05274 RDMA/irdma: Prevent rereg_mr for non-mem regions
  • dbb945b80a3a RDMA/umem: Add pinned revocable dmabuf import interface
  • c4ef25de94d7 RDMA/cma: Fix hardware address comparison length in netevent callback
  • d7fc6f351c47 xfrm: reject optional IPTFS templates in outbound policies
  • 2907e9d0f05b sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx()
  • 57acd5192833 sched/ext: Avoid null ptr traversal when ->put_prev_task() is called with NULL next
  • 996c5c19d5b5 firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
  • 8edc92525178 btrfs: fallback to transaction csum tree on a commit root csum miss
  • a84ca16ce07e btrfs: use bool type for btrfs_path members used as booleans
  • 60a23d4ea169 btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()
  • 5e1b2ca6b349 btrfs: reject free space cache with more entries than pages
  • 0ac9c7d9ccfd mtd: nand: mtk-ecc: stop on ECC idle timeouts
  • fdb53a9b2607 mtd: mtdswap: remove debugfs stats file on teardown
  • 98d2d468b4fa IB/mad: Drop unmatched RMPP responses before reassembly
  • 59114e0ff6e3 firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits
  • 33e1b0d25ca0 xfrm: fix stale skb->prev after async crypto steals a GSO segment
  • eae16fbc7ce2 xfrm: propagate -EINPROGRESS from validate_xmit_xfrm()
  • 23bbb9eafec7 net: plumb drop reasons to __dev_queue_xmit()
  • 4cc4d6fb08e7 net: dropreason: add SKB_DROP_REASON_RECURSION_LIMIT
  • 4c22b4e3ff50 arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234
  • 0b9858484d09 arm64: tegra: Remove fallback compatible for GPCDMA
  • 903f2edc0477 fuse: fix writeback array overflow when max_pages is one
  • afe9cda0862a Input: ims-pcu - fix logic error in packet reset
  • d03a740e087d Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
  • 6cbed4be9a6c xprtrdma: Clear receive-side ownership pointers on release
  • 0892b427c4b8 crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin
  • 5f4de3c717d3 gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
  • ec9f66c91bff dmaengine: sh: rz-dmac: Move interrupt request after everything is set up
  • eca8b44d51fc can: bcm: track a single source interface for ANYDEV timeout/throttle ops
  • 136de17f3863 can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()
  • 6be3e1fedf03 can: bcm: fix stale rx/tx ops after device removal
  • b024c21c9066 can: bcm: add missing device refcount for CAN filter removal
  • deb6a697cce3 can: bcm: validate frame length in bcm_rx_setup() for RTR replies
  • bd46f55dec60 can: bcm: extend bcm_tx_lock usage for data and timer updates
  • 8104bcdb2612 can: bcm: fix CAN frame rx/tx statistics
  • 19b1994069dd can: bcm: add locking when updating filter and timer values
  • ec9daa8fd1b6 KVM: x86/mmu: Fix use-after-free on vendor module reload
  • 8001d2ce9d9b KVM: nVMX: Hide shadow VMCS right after VMCLEAR
  • dd50ad7935d5 KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN
  • f3477a6a4164 KVM: x86: Check for invalid/obsolete root after making MMU pages available
  • 865dfe76c150 seqlock: Allow UBSAN_ALIGNMENT to fail optimizing
  • 3958b1aeef43 seqlock: Allow KASAN to fail optimizing
  • ec46baf83082 seqlock: Cure some more scoped_seqlock() optimization fails
  • 8e39ed92d7c5 fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race
  • 89890a5fcefa drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker
  • f6410d18c1e2 netfilter: nf_tables: revert commit_mutex usage in reset path
  • 0c8a9022f4c5 netfilter: nft_quota: use atomic64_xchg for reset
  • cd968dcdec6a netfilter: nft_counter: serialize reset with spinlock
  • 55904f1a4689 selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs
  • ce01a4e5cfac bpf: Fix ld_{abs,ind} failure path analysis in subprogs
  • bffc0b27e457 platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug
View originalPermalink
How 6.18.44-rt-xanmod1 went

6.18.44-xanmod1

Added 5
  • drm/xe: Add page reclamation info to device info
  • drm/xe: Stub out new pagefault layer
  • drm/xe/bo: Add purgeable bo state tracking and field madv to xe_bo
  • drm/xe: add xe_migrate_resolve wrapper and is_vram_resolve support
  • drm/xe/pat: Add helper to query compression enable status
Changed 4
  • can: use skb hash instead of private variable in headroom
  • drm/xe: Use SVM range helpers in PT layer
  • drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable()
  • drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse]
Fixed 11
  • drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info
  • drm/fb-helper: Fix a locking bug in an error path
  • usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path
  • can: isotp: fix timer drain order, wakeup handling and tx_gen ordering
  • drm/xe/pt: Reset current_op in xe_pt_update_ops_init()
  • drm/i915/vrr: require valid min/max vfreq for VRR

From XanMod Kernel

  • ad6ed82a8a85 Linux 6.18.44-xanmod1
  • 3412e4a7152c Merge tag 'v6.18.44' into 6.18
  • 1efe5d048a39 Linux 6.18.44
  • 358b5dcf1fd7 drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info
  • e7731507270c drm/fb-helper: Fix a locking bug in an error path
  • 7bc7af179916 usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path
  • 10be509fa8fd can: isotp: fix timer drain order, wakeup handling and tx_gen ordering
  • 0902f06a6c0b can: use skb hash instead of private variable in headroom
  • 157b1e3384d7 drm/xe/pt: Reset current_op in xe_pt_update_ops_init()
  • b1a71151317c drm/xe: Add page reclamation info to device info
  • 6107b64cfcce drm/xe: Stub out new pagefault layer
  • 184de3d31f72 drm/xe: Use SVM range helpers in PT layer
  • df1582c0a101 drm/i915/vrr: require valid min/max vfreq for VRR
  • 894d4a739566 drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable()
  • 21976fe52584 drm/xe: Wait on external BO kernel fences in exec IOCTL
  • b8ad916ba4e1 drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse]
  • d256dac008d1 drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC
  • 8fa8b0a46372 drm/xe/vm: Prevent binding of purged buffer objects
  • 1ba553ee0b52 drm/xe/bo: Add purgeable bo state tracking and field madv to xe_bo
  • 0015b054b06d drm/xe: add xe_migrate_resolve wrapper and is_vram_resolve support
  • 005b9b443160 drm/xe/pat: Add helper to query compression enable status
  • 3cb42a973f88 drm/amd/display: Exit idle optimizations before programming
  • dbbe08d73b8b drm/amd/display: check GRPH_FLIP status before sending event
  • b485bfb45555 drm/xe/guc: Fix buffer overflow in steered register list allocation
  • 30b2d0843a41 drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions
  • e06c39cc1c48 drm/amdgpu: Fix context pstate override handling
  • 4d49ca777cf1 drm/tegra: fbdev: Remove offset into framebuffer memory
  • 3f5807745798 drm/fb-helper: Allocate and release fb_info in single place
  • 165613191ad9 userfaultfd: prevent registration of special VMAs
  • 02d378828af8 wifi: brcmfmac: drain bus_reset work on device removal
  • d6f322d68abf media: uapi: rkisp: Correct name version enum
  • 5c6d5d2484ca media: qcom: camss: Fix RDI streaming for CSID 340
  • f730ee0ef8fa media: qcom: camss: csid-340: Fix unused variables
  • 276420a86e75 media: chips-media: wave5: Support CBP profile
  • 3f7b3728dd90 usb: typec: ucsi: Fix race condition and ordering in port unregistration
  • 58d9caa64f9c usb: typec: ucsi: split connector lock classes
  • 2bf24a7e190a net/handshake: Drain pending requests at net namespace exit
  • 6e7b52bd1394 net/handshake: Close the submit-side sock_hold race
  • 68eba6519cbd net/handshake: hand off the pinned file reference to accept_doit
  • b913801ad9b9 net/handshake: Take a long-lived file reference at submit
  • 5ddfc47e1228 net/handshake: Fix null-ptr-deref in handshake_complete()
  • 97e745b4ea05 net/handshake: convert handshake_nl_accept_doit() to FD_PREPARE()
  • f00dd592abe7 file: ensure cleanup
  • 10827847c40c file: add FD_{ADD,PREPARE}()
  • 10065fb89165 mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios
  • be11b4bf498a fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes
  • 2b9a07002c2f mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()
  • fc0c76b0450f drm/xe/rtp: Ensure locking/ref counting for OA whitelists
  • 9783d8662b56 drm/xe/oa: (De-)whitelist OA registers on OA stream open/release
  • f5966d900662 drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt
  • d43abc858f08 drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs
  • c2cfee9bf8d4 drm/xe/rtp: Save OA nonpriv registers to register save/restore lists
  • 4bb92418e749 drm/xe/rtp: Generalize whitelist_apply_to_hwe
  • cc716d3ac560 drm/xe/rtp: Keep track of non-OA nonpriv slots
  • f73e97080deb drm/xe/rtp: Maintain OA whitelists separately
  • 7982678fa21e drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists
  • 542d3b9fa8ec drm/xe/rtp: Refactor OAG MMIO trigger register whitelisting
  • 2b70bebc7094 HID: logitech-dj: Fix maxfield check in DJ short report validation
  • 6be3dbe45b28 spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX
  • 042ca3877955 drm/vmwgfx: validate external BO copy bounds for both stride paths
  • cfd163169af3 drm/vmwgfx: use check_add_overflow for shader size+offset bound
  • 1eb4f796695b drm/vmwgfx: enforce cursor size limits for MOB cursors
  • 96efee36453b drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure
  • 7e40e6120fb2 drm/vmwgfx: bound DMA command body size against suffix pointer
  • dc0be7662b7b drm/vmwgfx: validate DRAW_PRIMITIVES header size before division
  • a8434b145b1e drm/vmwgfx: drop dma_buf reference on foreign-fd prime import
  • b79e82ea1823 drm/vmwgfx: take fman->lock around fence list mutation in fifo_down
  • 10460699c312 drm/vmwgfx: clamp dirty-page range with min, not max
  • e479240a1e07 drm/vmwgfx: reject DX_BIND_QUERY without a DX context
  • 282f261cb035 drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size
  • 6a52f48157fa drm/amdkfd: hold event_mutex while checkpointing CRIU events
  • 6189ceca5ce7 drm/amdkfd: Handle invalid event type in CRIU event restore
  • 6dc0b4b39ed4 drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment
  • 5f0f2ddeac73 drm/amdkfd: fix QID bit leak in pqm_create_queue()
  • 9e52212aff8e drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE
  • 02647d983407 drm/amd/display: use proper context for logging
  • 3c2ae9509717 drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames
  • 1860818feb4d drm/amd/pm: fix torn gpu metrics reads
  • 45ba7f091abf drm/amdgpu: cap GTT size to physical RAM on APUs
  • d330ac90d85f drm/amdgpu: restore UMD profile pstate after runtime resume
  • 18d21c9d04b0 drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini
  • 0f1ff05c58e1 drm/mediatek: ovl_adaptor: balance component registrations
  • c835f2b0b716 drm/panthor: validate firmware interface structure sizes
  • 2a761b9be586 drm/panthor: reject firmware sections with oversized data
  • da898bb6faf3 drm/bridge: display-connector: Fix I2C adapter resource leak
  • 57667eb7548f drm/vc4: Zero the tile state data array before each BIN job
  • 6cd5acf6f87c drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size
  • 58d2bb394e88 drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs
  • e8b797940536 can: ctucanfd: mark error-active controller status valid
  • 7d1619f56a75 can: ctucanfd: handle bus error interrupts
  • 46fc5aecde5c can: ctucanfd: unmap BAR0 using base address
  • cae2880f8ffa can: ctucanfd: use self-test mode for PRESUME_ACK
  • aa5e790bf185 can: ctucanfd: add missing MODULE_DEVICE_TABLE()
  • 2427ef427bdd can: peak_usb: validate uCAN receive record lengths
  • 92d0de80ca22 can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error
  • 1acab790b7ce can: peak_usb: add bounds check for USB channel index
  • 2ee477e541a6 can: softing: fw_parse(): validate firmware record spans
  • 185cb1fa3814 can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents
  • 2e90b2b40607 can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams()
  • 54258ea8d61f can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking
  • 8604a3b81b9d can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer
  • 996eb21acdc9 can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure
  • c311f17c261f can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure
  • 0b23144c59c1 can: ems_usb: validate CPC message lengths
  • 26cf99713a96 can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured
  • affd62f5719a i2c: imx: Cancel hrtimer before clearing slave pointer
  • 12a4f0950a15 i2c: imx: Fix slave registration race and error handling
  • 7a5db225ab5a i2c: imx: mark I2C adapter when hardware is powered down
  • 82233ff0e36d i2c: iproc: reset bus after timeout if START_BUSY is stuck
  • 19b783335d62 i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock
  • 40dd71744599 i2c: qcom-cci: drop custom suspend/resume and rely on runtime PM helpers
  • d9b5419df065 i2c: spacemit: request IRQ after controller initialization
  • 6a5cc2b4e6fa ice: fix memory leak in ice_lbtest_prepare_rings()
  • 326c89ea2685 ice: fix VF interrupts cleanup
  • 7e8789f5b5d8 ice: wait for reset completion in ice_resume()
  • e0ba8eaef2a0 net: openvswitch: fix skb leak on flow key update failure during ct
  • 9c7246cc509f net: openvswitch: fix skb leak on flow key update failure during recirculation
  • 90623c949962 net: openvswitch: fix potential UAF on meter attach failure
  • 74b30e7ef461 phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB
  • 79a312664118 phy: zynqmp: use read-modify-write for SERDES scrambler bypass
  • 4211450f0fec phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask
  • 013a4484f061 s390/zcrypt: Validate length for CCA ECC private key requests
  • ad93a1f1a456 s390/zcrypt: Validate length for CCA AES cipher key requests
  • fbb0410986e8 s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()
  • a57fd7fcdb63 s390/zcrypt: Fix buffer over-read in cca_cipher2protkey
  • 672b12940e3f s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs
  • e16e0fc54120 s390/dasd: Fix undersized format-check buffer
  • 86cdfd061509 s390/dasd: Fix potential NULL pointer dereference
  • bd63c7879eaa s390/qeth: Check CAP_NET_ADMIN for private ioctls
  • ef1aa7cfb8c6 s390/pci: Fix s390_pci_mmio_write syscall error return without MIO
  • b039f13e095d power: supply: max17040: handle missing status supplier
  • 6d89f33a6467 power: supply: bq25890: fix the -10 C NTC lookup entry
  • 63d6c855b27d cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized
  • 437b38a08c0a cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init()
  • efbcecdecefc cifs: add fscache_resize_cookie() to cifs_setsize()
  • 466ab0c41d5f gpio: pch: use raw_spinlock_t for the register lock
  • 2e4bc8422cde gpio: pca953x: fix cache_only and IRQ state on restore_context() failure
  • 1883a09a37fe i2c: amd-mp2: Unregister callback on adapter add failure
  • 7a91d07939e0 hwmon: (pmbus/core) notify on the hwmon device, not the i2c client
  • 30ae66374637 hwmon: (npcm750-pwm-fan): stop fan timer on device detach
  • 4ba5bf7ed50f sctp: prevent peer transport count overflow
  • a0d1693923f4 sctp: reject stale cookies with mismatched verification tags
  • 2047ed09bf13 scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
  • 5b4d4d5a29f9 selftests/clone3: fix wild pointer access of getline due to missing init
  • a0bc578641d7 selftests/mm: fix potential wild pointer access of getline due to missing init
  • 2e047b4171de spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure
  • 581e5166f078 spi: spi-qpic-snand: write the feature value before executing SET_FEATURE
  • c26a6477e149 tracing/filters: Fix false positive match in regex_match_full()
  • cbb5ed3be9ca tracing: Check return value of __register_event() in trace_module_add_events()
  • 205feb72e5be ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()
  • ee799977d794 vxlan: use pskb_network_may_pull() in route_shortcircuit()
  • 94dee751aad6 vxlan: use pskb_network_may_pull() for transmit path header pulls
  • ff89415d34c3 vxlan: use neigh_ha_snapshot() in route_shortcircuit()
  • adeed09eeb3b vxlan: unclone skb head before modifying eth header in route_shortcircuit()
  • 1235e017aa11 vxlan: re-fetch eth header after route_shortcircuit()
  • b24ba0bbffe3 veth: convert frag_list skbs before running XDP
  • 3bd35a5e272a uprobes: Fix NULL pointer dereference in hprobe_expire()
  • 180ff4c81faf um: vector: fix use-after-free in vector_mmsg_rx()
  • e4b98f9778df powerpc/ps3: Fix map failure path in dma_ioc0_map_pages()
  • 4ef801b838d8 net: pktgen: fix proc entry use-after-free
  • dc3ab0422066 net: ipv6: clear suppressed fib6 rule result
  • 0309ebbc5700 net: bridge: stop fast-leave after deleting a port group
  • 332a546b4ee5 mm: memcg: initialize *locked in memcg1_oom_prepare() stub
  • b11907c905fa mm/page_reporting: use system_freezable_wq to fix UAF during suspend
  • 63b361f22886 io_uring/net: initialize mshot_len for send
  • 4dad8ca637d4 binfmt_misc: don't let an 'F' entry pin its own instance
  • 840bb9c49c3e binfmt_misc: reject a flag character as the field delimiter
  • 255a758697da binfmt_misc: use exe_file_deny_write_access() for the interpreter clone
  • fdc1d702bf30 binfmt_misc: restore write access when removing an entry
  • c9dcfe6b8b71 wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames
  • bed792737b5f tipc: avoid use-after-free in poll trace queue dumps
  • 88752b811f72 of/address: Fix NULL bus dereference in of_pci_range_parser_one()
  • 4ae701848e4b netfilter: ipset: do not update comments from kernel-side hash adds
  • f807a63d0d95 net/smc: fix socket use-after-free during link group termination
  • 2060764e0f46 mshv: fix hv_input_get_system_property struct
  • a60b5da05e31 ksmbd: reject repeated SMB2 NEGOTIATE requests
  • b5ee5b266f83 ipvs: do not propagate one-packet flag to synced conns
  • 3b5aee6fcbf6 igc: remove napi_synchronize() in igc_down()
  • 845a9cdd9b03 igbvf: Fix leak in TX DMA error cleanup
  • b10bb77e91e9 e1000: fix memory leak in e1000_probe()
  • b0bdca3a49cf dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+
  • 2db4535d6af7 ALSA: usb-audio: Clamp frame size in implicit-feedback mode
  • 04595233e560 ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set
  • b5305a0d0bb8 ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
  • 7ba01e0d3539 ALSA: usb-audio: fix stack info leak in RME Digiface status
  • cc014ebf8031 ALSA: usb-audio: fix use-after-free in ump_to_endpoint()
  • 79f8720029f2 ata: libata-sata: fix ata_scsi_lpm_supported() iteration
  • 9562ddbc6ed8 ata: libata-eh: Increase STANDBY IMMEDIATE timeout
  • 0a02b0c87807 ASoC: tas2562: fix broken entries in the volume lookup table
  • 35d5f1852e39 ASoC: tas2562: fix DVC coefficient write order
  • cac7d2066b2f ASoC: fsl_easrc: fix m2m_init error path to use goto instead of bare return
  • 6df5b3288160 ASoC: fsl_asrc: fix m2m_init error path to use goto instead of bare return
  • 032746c2dd9a ALSA: ump: fix double free of out_cvts on rawmidi error
  • a26a2e52736f ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes
  • 5260e195c53e ALSA: seq: Fix division by zero in initialize_timer()
  • 2940cc3cf43c ALSA: pcm: wake linked drain waiters on unlink
  • 4969533a1b95 ALSA: lx6464es: fix period byte count for 16-bit streams
  • 7484669d1fba ALSA: hda/realtek: Add quirk for TongFang X6SP45xU
  • 11e2953d9f4c ALSA: 6fire: Fix UAF at error handling during probe
  • c0d3b81f703b afs: Fix UAF when sending a message
  • d703f022a28a afs: Fix afs_fs_fetch_data() to subtract transferred from len
  • b53face003b4 afs: Fix afs_fs_fetch_data() to set call->async
  • 5c7fdcbecbab bpf: lwt: Fix dst reference leak on reroute failure
  • 27cc0e603355 Bluetooth: HIDP: validate numbered report payloads
  • 2ebf63aa557a Bluetooth: HIDP: reject frames without a transaction header
  • eb1d8318764d Bluetooth: hci_sync: Fix advertising data UAFs
  • c569def320aa Bluetooth: mgmt: fix UAF in pair command cancellation
  • a33bc07b4730 Bluetooth: SCO: give the socket its own sco_conn reference
  • 814f82f432dc Bluetooth: mgmt: fix pending command UAF in EIR updates
  • 6936b367ee6d Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read()
  • f14d41dbc2fd Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req()
  • cae0dfed5d30 audit: fix potential use-after-free in audit_del_rule()
  • 185c784c9809 audit: fix potential integer overflow in audit_log_n_string()
  • 17b412468c7a sctp: validate Adaptation Indication parameter length
  • c0837aeace96 dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister
  • b878ba7e2814 KVM: s390: pci: Validate AIBV and AISB before pinning guest pages
  • e137d082325b KVM: s390: pci: Fix NULL dereference on AIBV allocation failure
  • 1abf9ce39a86 KVM: s390: pci: Fix missing error codes and memory unaccounting
  • 70871b121f81 KVM: s390: pci: Fix memory accounting for pinned/unpinned pages
  • 6837f0ae85fd KVM: s390: pci: Reject adapter interrupt forwarding if already enabled
  • 7668c58dcf46 KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active
  • 5acc92947baa KVM: VMX: add memory clobber to asm for VMX instructions
  • e768ea3a422d tracing/fprobe: Roll back on enable_trace_fprobe() failure
  • 3b2e08e0ede7 tracing/probes: Reject $arg0 in meta argument expansion
  • e0fa737783b5 mm/vmstat: fold stranded per-cpu node stats when a node comes online
  • 126a70bf1a08 mm/hugetlb: fix list corruption in allocate_file_region_entries()
  • 32134cf9211b mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()
  • 7d3e1d3a0dce fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes
  • c091462e46f7 selftest: fix headers in fclog.c
  • 9668ffe0e2a5 mm/util: don't read __page_2 for order-1 folios in snapshot_page()
  • 2be94d6b2078 mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE
  • 2205263b1e01 fortify: Disable -Wstringop-overread in tests
  • 96b0aa79b0e1 pinctrl: bm1880: add missing select GENERIC_PINCONF
  • 5aaa06dfc10f erofs: cap LZMA stream pool size
  • ad0ad3c228b6 pinctrl: devicetree: don't free uninitialized dev_name on error path
  • 93d934668047 pinctrl: microchip-sgpio: add missing select REGMAP_MMIO
  • 6da8f37419dd iommu/iommufd: Fix IOPF group ownership UAF
  • 564ac339c0f8 iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace
  • ee2212b48232 iommufd/viommu: Publish a vDEVICE only after vdevice_init() succeeds
  • 294b464b2be7 iommufd/viommu: Release the igroup lock on the vdevice_size error path
  • 062aa5dcc49a mshv: Order pt_vp_array publish against irqfd assertion path
  • f50f5d3972da mshv: Fix level-triggered check on uninitialized data
  • fc362bfcb060 mshv: adjust interrupt control structure for ARM64
  • 72a90ce4918b mshv: Fix race in mshv_irqfd_deassign
  • cfc686a1174a iomap: add a separate bio_set for iomap_split_ioend
  • 9be4a66f019e ksmbd: fix use-after-free in __close_file_table_ids()
  • 213b4568f6e5 ksmbd: return success for deferred final close
  • cebba11df714 drm/i915/hdmi: Poll for 200 msec for TMDS_Scrambler_Status
  • e51becb8f337 qede: sync udp_tunnel ports outside qede_lock in the recovery path
  • 51c52e493346 spi: spi-nxp-fspi: add per-SoC SDR/DTR clock rate limits for all supported SoCs
  • caeaaf23f7c3 sched/deadline: Use revised wakeup rule only for running dl_server
  • 5a73e8c632c3 octeontx2-pf: Set correct sequence for carrier off and tx queue stop
  • b90916156b47 net: libwx: fix FDIR ATR queue mismatch for software VLAN packets
  • 6bf322ab0741 ptp: netc: fix potential interrupt storm caused by incorrect unbind order
  • 1e0dfb7e7a5d net: dsa: mt7530: error out on failed reads in MT7531 PHY polling
  • fd9586881d47 net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend
  • 54e07a158f7a riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove
  • b297559dc2f2 accel/qaic: use sizeof(*trans_hdr) for transaction length check
  • 01bd01b61ad9 riscv: drop __init from vec_check_unaligned_access_speed_all_cpus
  • a20a0010eb64 tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions
  • 9b604041f100 tracing/mmiotrace: Reset dropped_count in mmio_reset_data()
  • fc97dcb42fb4 fprobe: Fix module reference count leak on error in register_fprobe()
  • 84b5aa55de7c drm/i915/dp: Ignore the sink's DSC max FRL rate without a PCON DSC encoder
  • 50edffd0854f can: isotp: check register_netdevice_notifier() error in module init
  • b4f8c33593f2 net: sxgbe: check descriptor ring allocation failures
  • 42b87cfd9666 net: sxgbe: free TX rings on RX allocation failure
  • 69a258a5a322 scsi: target: Clear cmd_cnt when initial counter enrollment fails
  • 54c6fb24c602 scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req
  • ff333def3147 scsi: ufs: core: Revert "Delegate the interrupt service routine to a threaded IRQ handler"
  • c249cfe1d8df scsi: ufs: core: Avoid IRQ thread wakeup during active UIC command
  • e50420448999 scsi: ufs: core: Cancel RTC work in active-active suspend
  • bdd8a1297ef1 scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE
  • 613aaeeaf8cb net: phylink: put link_gpio if phylink_create fails
  • 5ea70ad040c1 x86/boot: Add volatile, clobbers and zero-length test in memcmp()
  • 5576afebf726 Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync
  • e8f9fef362ba Bluetooth: hci_conn: hold conn reference in abort_conn_sync()
  • de17305393ec Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists
  • c618a9a5b08e Bluetooth: btintel: Validate length before parsing diagnostics TLV
  • 3b921533e8aa Bluetooth: ISO: fix refcounting of iso_conn
  • e941799c31f6 Bluetooth: ISO: ensure no dangling hcon references in iso_conn
  • 82e982f54f96 Bluetooth: ISO: avoid deadlocks in iso_sock_timeout
  • e76a0ae6542a Bluetooth: ISO: fix leaking sk after socket release
  • 4e9b5e8669b3 Bluetooth: ISO: hold sk properly in iso_conn_ready
  • 09a69828ae59 Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release
  • cde36776cfe6 Bluetooth: ISO: Fix not updating BIS sender source address
  • dfce8d30fc5b Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis()
  • 1fc2132950c2 Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos
  • e8e9cff6d80e Bluetooth: ISO: lock sk in iso_connect_ind
  • 3120664aa333 Bluetooth: ISO: Fix data-race on iso_pi(sk) in socket and HCI event paths
  • f1f167991a68 Bluetooth: HCI: Add initial support for PAST
  • 72d5bb1d77d7 Bluetooth: ISO: lock sk in iso_sock_getname
  • 58e3c5289ad2 Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp
  • 63c0f396a18b Bluetooth: ISO: clear iso_data always when detaching conn from hcon
  • 4e1f45de5b31 ice: suppress DPLL errors during reset recovery
  • 6ebbf198e76c idpf: Fix mailbox IRQ name leak on request failure
  • d44081c61dc9 idpf: adjust TxQ ring count minimum
  • ae7120102e1b hwmon: (pmbus) Fix return value from pmbus_update_byte_data()
  • 276f1f180f55 net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller
  • 2c148a31ca01 netfs: release readahead folios on iterator preparation failure
  • 291ebecdf315 netfs: handle single writeback rolling buffer allocation failure
  • 627826ef4208 netfs: clear PG_private_2 on copy-to-cache append failure
  • b558e07708d8 wifi: mac80211: validate individual TWT params before driver setup
  • f82a2ded3d7a net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister()
  • acbf711a2066 powerpc/boot: Fix treeboot-akebono CPU node lookup check
  • b407b98cf665 powerpc/boot: Fix treeboot-currituck CPU node lookup check
  • 3d24f2e5641b powerpc/boot: Fix simpleboot CPU node lookup check
  • db986098f308 rtase: fix double free of multi-frag skb on DMA map failure
  • 5a6b0ccb8b01 hwmon: (adt7470) Fix PWM auto temp state array and bounds check
  • 96ad57d31763 hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read
  • ddd689bd7226 hwmon: (adt7470) Use cached PWM frequency value
  • 1d6b54dbe885 hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks
  • d5d4034bb6f6 hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read()
  • 82d65f7ef11e hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread
  • 3e06ff0c79ea hwmon: (adt7470) Fix cache updated before hardware write on I2C error
  • 28548ecc2b45 hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors
  • ae20a8a4de06 forcedeth: fix UAF of txrx_stats in nv_remove
  • 2e0c6761c055 net: bridge: mrp: fix Option TLV length in MRP_Test frames
  • 1b722740ac5c hwmon: (nct6775-core) Prevent access to unsupported weight registers
  • 5ec5f00fc606 net: do not send ICMP/NDISC Redirects when peer allocation fails
  • 2332d35aaf20 hwmon: (nzxt-smart2) DMA-align output buffer
  • 075fce376cf8 hwmon: (lm90) Only report alarms if driver is ready
  • c498adfd4c3e hwmon: (sht3x) Fix unaligned accesses
  • 08aee6d45eef hwmon: (ltc4282) Fix reading the minimum alarm voltage
  • b60e8486c04d hwmon: (ina2xx) Fix various overflow issues
  • e627f4ad9eea hwmon: (ina2xx) Shift INA234 shunt and current registers
  • fdfde077e025 hwmon: (ina2xx) Add support for INA234
  • 8da94361f9ae hwmon: (ina2xx) Make it easier to add more devices
  • a42d727dae57 hwmon: (nct6775-core) Fix number of temperature registers for NCT6116
  • e28d478c003d spi: spi-cadence: Move TX FIFO full busy-wait into FIFO
  • d3337eefab62 spi: spi-cadence: supports transmission with bits_per_word of 16 and 32
  • fcc3d77fef02 ASoC: tas2781: Use correct calibration data for SINEGAIN2 register
  • b2851429afc5 smb: client: fix buffer leaks in SMB1 read and write
  • 9e24b47ef81d scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race
  • 72815741715b scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer
  • 3ef209ca0b4b scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer
  • 8e0996418590 pinctrl-amd: Don't clear S4 wake bits at probe
  • ceb00cb87a22 xsk: drain continuation descs after overflow in xsk_build_skb()
  • 411554cb868b xsk: use a smaller new lock for shared pool case
  • 05e283466b86 xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx
  • 814c5b159003 selftests/net/af_unix: test listen() rejects wrong socket states
  • 643ec3e24a49 selftest: af_unix: Create its own .gitignore.
  • 0372a5219112 selftests: af_unix: Add tests for ECONNRESET and EOF semantics
  • 5c170577049f af_unix: fix listen() succeeding on sockets in the wrong state
  • b1d480fce05f rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()
  • f6787fdffcae rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled
  • 4147866087fb ASoC: SDCA: Ensure that Control Range is large enough for header
  • 16b553c46e34 netfilter: nft_payload: fix mask build for partial field offload
  • e6f4b4b40db8 ipvs: do not mangle ICMP replies for non-first fragments
  • ce96c40a049b ipvs: fix places with wrong packet offsets
  • 00eb23829fd0 ipvs: fix the checksum validations
  • d186f77d18bd netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
  • 63ba12b664a2 netfilter: nf_tables: make nft_object rhltable per table
  • adf1a3ba27ad assoc_array: trim the final shortcut word using the current chunk end
  • 3d9f16c0b643 keys: make keyring key-chunk byte order agree with keyring_diff_objects()
  • e9417d21a22a keys: fix out-of-bounds read in keyring_get_key_chunk()
  • 6469ad300508 KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type
  • 31d491f9da94 KVM: arm64: Reject guest_memfd memslots when the VM has MTE
  • db1c4a8e9080 mshv: Fix sleeping under spinlock in mshv_portid_alloc
  • a920ead0bc2f mshv: Fix duplicate GSI detection for GSI 0
  • b215cb70e14c Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation
  • d397787dbc4b Drivers: hv: Allocate the paravisor SynIC pages when required
  • 74d20e3cf88e Drivers: hv: Rename fields for SynIC message and event pages
  • 82cdbb6155a2 arch/x86: mshyperv: Discover Confidential VMBus availability
  • 6e70eba930a2 drm/mediatek: Check CRTC state before freeing
  • f74554e67ccf netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()
  • ec81ecd2ac09 phy: zynqmp: fix runtime PM leak on probe allocation failure
  • 86fb88ac8c91 phy: zynqmp: fix clock error handling in xpsgtr_phy_init()
  • dff474e723ed btrfs: raid56: fix an incorrect csum skip during scrub
  • 4d4ef6627304 btrfs: zoned: reset meta_write_pointer on zone reset
  • deddd28fd83c btrfs: zoned: fix deadlock between metadata writeback and transaction commit
  • 762561c43859 btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag
  • cfa7e2734877 of: reserved_mem: prevent OOB when too many dynamic regions are defined
  • f5edba9bc69d ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup
  • 3cbfb9b886dc ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup
  • 3fd94b9ffe99 phy: qcom: m31-eusb2: Fix return value of init call
  • 9355f526c821 ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources()
  • a0f288ebe6d8 ata: sata_mv: accept 1 or 2 resources in platform probe
  • 8229a5388854 selftests/seccomp: Fix pointer type mismatch build error
  • 99dc2c143dfc selftests/lkdtm: rename STACKLEAK_ERASING to KSTACK_ERASE
  • 094145989b31 gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe()
  • 3808bab5d95a iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE
  • 0679c0c189d2 dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open()
  • 9086b488f273 dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA
  • 2ef9bb422dd6 pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151
  • 3e55d2809547 pinctrl: qcom: Unconditionally mark gpio as wakeup enable
  • 54a62153c765 thunderbolt: Prevent XDomain delayed work use-after-free on disconnect
  • d01e88d421a6 mm/slab: prevent unbounded recursion in free path with new kmalloc type
  • 3e957c9b160c lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled()
  • 98f57011e6cd HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report
  • bc3bba4656ad HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write
  • df0f33293c0a HID: logitech-dj: Standardise hid_report_enum variable nomenclature
  • 302eb8765132 ALSA: hda/realtek: add quirk for HP Dragonfly Folio G3 2-in-1
  • e8362523fd1b drm/gpusvm: publish dpagemap early to avoid device mapping leak on error
  • a5cdd2407dd8 net: mpls: initialize rtm_tos in mpls_getroute()
  • 85b94a74a0b8 netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge()
  • 9bb3714e0998 kunit: tool: Terminate kernel under test on SIGINT
  • d36086cd1826 kunit: tool: skip stty when stdin is not a tty
  • 285641eb82f0 netfilter: nf_conntrack_expect: restore helper propagation via expectation
  • 7b923c78b50d Linux 6.18.43
  • bfe7f9993467 x86/bugs: Make Safe-RET robust against interrupt injection
View originalPermalink
How 6.18.44-xanmod1 went

7.1.6-xanmod1

Changed 1
  • net: mana: Optimize irq affinity for low vcpu configs
Fixed 16
  • cifs: fix time_last_write stamp placement in setattr/truncate paths
  • KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug
  • bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline()
  • mm/sparse-vmemmap: fix DAX vmemmap accounting with optimization
  • xfs: don't replace the wrong part of the cow fork
  • fuse-uring: fix race between registration and connection abortion
Security 3
  • ksmbd: validate ACE size against SID sub-authorities
  • ksmbd: bound DACL dedup walk to copied ACEs
  • ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl

From XanMod Kernel

  • 6db734bb161f Linux 7.1.6-xanmod1
  • ba65783d88c0 Merge tag 'v7.1.6' into 7.1
  • 2609d60e2f6d Linux 7.1.6
  • 96f1a2309bd4 cifs: consolidate time_last_write stamp into _cifsFileInfo_put()
  • edfc6bf57524 cifs: fix time_last_write stamp placement in setattr/truncate paths
  • 6b542d116ace KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug
  • a86ceb3291ec selftests: drv-net: so_txtime: relax variance bounds
  • ea2e0c28609a selftests: drv-net: cope with slow env in so_txtime.py test
  • 97c09c9f5739 sched_ext: Preserve rq tracking across local DSQ dispatch
  • 046899bcfc2d sched_ext: Move shared helpers from ext.c into internal.h and cid.h
  • 1e37f12b040e bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline()
  • 18c946a3b7b0 bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c
  • 63ba393d279c net: mana: Optimize irq affinity for low vcpu configs
  • 760c47bce6f5 mm/sparse-vmemmap: fix DAX vmemmap accounting with optimization
  • 9ea8940dec3d mm/sparse-vmemmap: pass @pgmap argument to memory deactivation paths
  • 390187672abf SUNRPC: Return an error from xdr_buf_to_bvec() on overflow
  • ee055a047290 SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists
  • 8fe8da8edc45 xfs: don't replace the wrong part of the cow fork
  • 2cd945492bc5 fuse-uring: fix race between registration and connection abortion
  • 3b601938314c audit: fix recursive locking deadlock in audit_dupe_exe()
  • ea5ded52bd08 audit: use 'unsigned int' instead of 'unsigned'
  • e528ff627fde drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources
  • 61fd3559199f ksmbd: validate ACE size against SID sub-authorities
  • a0ebdaa79e10 ksmbd: bound DACL dedup walk to copied ACEs
  • bc90144ce8bb ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL
  • 5acbd3012fd4 ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
  • a75b4f3fe9cd selftests: drv-net: add missing kconfig for psp.py
  • be354ea7261c drm/amdgpu: fix check in amdgpu_hmm_invalidate_gfx
  • caf4f872eec3 drm/amd/pm: fix smu13 power limit range calculation
  • f5988b5c300a drm/amdgpu: fix aperture mapping leak
  • 1050d258c7c5 drm/amdgpu: reject mapping a reserved doorbell to a new queue
  • 930a5dc3df4a drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
  • 92789e28b08f drm/amdgpu: fix resource leak on ACP reset timeout
  • 5bc93f907bad drm/amdgpu: Fix kernel panic during driver load failure
  • be725ab23aa4 drm/amdgpu: fix division by zero with invalid uvd dimensions
  • afdff9103818 drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()
  • c309626bf91f drm/amdgpu/vcn4: avoid rereading IB param length
  • 00c311a13d22 drm/amdgpu/vce: fix integer overflow in image size
  • 253b1401862b drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON()
  • cbe3b293d0ee drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()
  • 6423b44b2e0b drm/amdgpu/mes11: set doorbell offset for suspending userq
  • 301f39acf779 drm/amdgpu/jpeg: fix jpeg_v5_0_1_is_idle detection
  • 6b4e19378d94 drm/amdgpu/jpeg: fix jpeg_v4_0_3_is_idle detection
  • 43768ad42b8f drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()
  • ac89ea915e8b drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()
  • db85aa861b82 drm/amdgpu/gfx8: drop unecessary BUG_ON()
  • 81597685c0d7 drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()
  • 4fbcd92047ff drm/amdgpu/gfx12: fix EOP interrupt routing for KQ and userq
  • 51f67bd8a71a drm/amdgpu/gfx11: fix EOP interrupt routing for KQ and userq
  • 1c27e889fa16 drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON()
  • 2929a932b0d7 drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()
  • 69a2c5be437b drm/amd/pm: make pp_features read-only when scpm is enabled
  • 1c2a60c187ec drm/amd/pm: fix amdgpu_pm_info power display units
  • 9423c88cde9a watchdog: s32g_wdt: remove incorrect options in watchdog_info struct
  • 54a3c27b357d vxlan: mdb: Fix source list corruption on a failed replace
  • 23b44803112a vsock/virtio: collapse receive queue under memory pressure
  • f9596b156661 tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
  • 22cec809b048 tcp: challenge ACK for non-exact RST in SYN-RECEIVED
  • a859b280441f tcp: initialize standalone TCP-AO response padding
  • 0f54f5048615 rtase: Workaround for TX hang caused by hardware packet parsing
  • bed4caecd723 pppoe: reload header pointer after dev_hard_header()
  • ee6c5b5194f1 ovpn: hold peer before scheduling keepalive work
  • f08f39c1f43f ovpn: fix peer refcount leak in TCP error paths
  • ea85dbcbe8d4 openvswitch: fix GSO userspace truncation underflow
  • 06a6b606129c mctp: serial: handle zero-length frames to prevent rx buffer overflow
  • e09e0301d616 mac802154: llsec: reject frames shorter than the authentication tag
  • 5f303f622f6b mac802154: hold an interface reference across the scan worker
  • c6a13ae00dab ila: reload IPv6 header after pskb_may_pull in checksum adjust
  • 33dc0dfb480e ice: use READ_ONCE() to access cached PHC time
  • 33cc15aaf249 ice: reject out-of-range ptype in ice_parser_profile_init
  • 689b9f588d2d gve: fix Rx queue stall on alloc failure
  • b62c510f5980 ksmbd: validate minimum PDU size for transform requests
  • 0ff12308c8a6 ksmbd: defer destroy_previous_session() until after NTLM authentication
  • 6e4d2eeccfb9 smb: client: handle STATUS_STOPPED_ON_SYMLINK responses without a symlink target
  • b1a613669332 rbd: Reset positive result codes to zero in object map update path
  • 4c483644d1a7 super: fix emergency thaw deadlock on frozen block devices
  • 14fceda28069 ice: fix PTP Call Trace during PTP release
  • 545a7fdbc110 ptp: ptp_s390: Add missing facility check
  • 6d828e3a353c s390/ptff: Export ptff_function_mask[]
  • 21231d8c6ca4 proc: Fix broken error paths for namespace links
  • 7479c6e8235c net: qrtr: ns: Raise node count limit to 512
  • 6bbdf8744de3 net: pcs: xpcs: fix SGMII state reading
  • a0f247d63489 net: hip04: fix RX buffer leak on build_skb failure
  • fc0c0f7a207f net: gro: fix double aggregation of flush-marked skbs
  • 9aabda553184 net/x25: fix use-after-free in x25_kill_by_neigh()
  • fb29e1b41052 net/sched: serialize qdisc_rtab_list against concurrent get/put
  • a60c81f168c9 net/mlx5e: Use sender devcom for MPV master-up
  • f579582c03ed net/iucv: fix use-after-free of a severed iucv_path
  • 0e857185591f net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
  • 95f45e20f1b2 geneve: require CAP_NET_ADMIN in the device netns for changelink
  • 0e37bbd6d617 net: slip: serialize receive against buffer reallocation
  • e8ad0d311e22 vxlan: require CAP_NET_ADMIN in the device netns for changelink
  • 25e3641beb51 phonet: pep: fix use-after-free in pep_get_sb()
  • d0bba984703d net: stmmac: intel: skip SerDes reconfig when rate is unchanged
  • 9b243e2f1756 mm/slab: fix a memory leak due to bootstrapping sheaves twice
  • 0b7f04a0abb4 mm/slub: fix lost local objects when bulk remote free batch fills
  • db57cc63a6e5 iommu/vt-d: Disallow SVA if page walk is not coherent
  • c5b6a48a8a71 iomap: fix out-of-bounds bitmap_set() with zero-length range
  • 579b0f5c528c io_uring/rw: fix missing ERESTARTSYS conversion in read paths
  • e807c9193d94 ftrace: Add global mutex to serialize trace_parser access
  • bc2d630296e0 fscrypt: Avoid dynamic allocation in fscrypt_get_devices()
  • 466f187b501a fscrypt: Add missing superblock check in find_or_insert_direct_key()
  • ca03a7984a34 fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
  • 64017df6e61a fs/super: fix emergency thaw double-unlock of s_umount
  • 69ecc199880b binfmt_elf_fdpic: only honour the first PT_INTERP
  • d2cba2e7a513 ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP
  • e01f47367a63 ASoC: fsl: imx-card: Skip sysclk reset for active DAIs in shutdown
  • 006340cf0688 amt: fix use-after-free in AMT delayed works
  • b9fedda2f628 libceph: remove debugfs files before client teardown
  • 70998f91030e libceph: reject zero bucket types in crush_decode
  • 3b249546f59c libceph: Reject monmaps advertising zero monitors
  • 5ecfcd5c0586 libceph: refresh auth->authorizer_buf{,_len} after authorizer update
  • db9cc9fd9660 libceph: guard missing CRUSH type name lookup
  • a54be593d0b7 libceph: fix two unsafe bare decodes in decode_lockers()
  • bee4b5b53e7b libceph: Fix multiplication overflow in decode_new_up_state_weight()
  • e36663145abd libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
  • 0d934c934ec7 libceph: bound get_version reply decode to front len
  • 0ce001e7fdf7 ceph: fix writeback_count leak in write_folio_nounlock()
  • f3247851d63e ceph: fix refcount leak in ceph_readdir()
  • 71893c342a26 ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
  • 37ff9794be48 sctp: close UDP tunnel sockets during netns teardown
  • a50e73488e0b sctp: avoid auth_enable sysctl UAF during netns teardown
  • d136b29bf91d sctp: don't free the ASCONF's own transport in DEL-IP processing
  • 7375e2699582 mm/huge_memory: set PG_has_hwpoisoned only after new folio head is established
  • ab6209f4b48a mm/page_vma_mapped: fix device-private PMD handling
  • a4b3a8dcc3d0 mm/memory-failure: trace: change memory_failure_event to ras subsystem
  • 02542f35129d mm/kmemleak: fix checksum computation for per-cpu objects
  • e33adf96afb5 mm/damon/core: disallow overlapping input ranges for damon_set_regions()
  • f4145cec7005 m68k: avoid -Wunused-but-set-parameter in clear_user_page()
  • 43aaddd0fa92 mm/damon/core: validate ranges in damon_set_regions()
  • 0c26202b157f userfaultfd: prevent registration of special VMAs
  • 31a62e4ad663 btrfs: do not try compression for data reloc inodes
  • bfdfc7782ada afs: Fix afs_edit_dir_remove() to get, not find, block 0
  • c019163e9382 selftests: mptcp: userspace_pm: fix undefined variable port
  • 40dde4b5d982 mptcp: pm: userspace: fix use-after-free in get_local_id
  • fb3f056a9416 mptcp: only set DATA_FIN when a mapping is present
  • 625fc6060864 mptcp: fix stale skb->sk reference on subflow close
  • cb9d3163ef38 mptcp: fix BUILD_BUG_ON on legacy ARM config
  • d6d2261e3475 mptcp: decrement subflows counter on failed passive join
  • 4cf89c430acc Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates"
  • e59c2476ef75 arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates
  • f3530aec2656 arm64: make huge_ptep_get handled unaligned addresses
  • 5b50f9fd58be tracing/remotes: Fix page_va[] access before counter update in trace_remote_alloc_buffer()
  • b174d40adda6 tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err()
  • 02d6f022c7ff tracing/probes: Fix potential underflow in LEN_OR_ZERO macro
  • 1ddf73ad334f tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args()
  • 1e8d254cb586 tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match()
  • 8f188dd11a1c ublk: wait on ublk_dev_ready() instead of ub->completion
  • 9899a6af1c5e tracing: Propagate errors from remote event bulk updates
  • be94a3a77e7e tracing: perf: Fix stale head for perf syscall tracing
  • 43a23dfe0024 tracing: Fix union collision of module and refcnt for dynamic events
  • cb459fec4f7b tracing: Fix resource leak on mmiotrace trace_pipe close
  • 724cd84b0546 tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
  • 57027f360231 tracing: Fix context switch counter truncation
  • 159fdc3e01dc tracing: Delay module ref count for "enable_event" trigger
  • 9e9a82d00c3d misc: nsm: pin the module while the device is open
  • f318f5a872cb misc: nsm: only unlock nsm_dev on post-lock error paths
  • c3a28f9cb824 intel_th: fix MSC output device reference leak
  • 7cf79e8d682f mei: bus: access mei_device under device_lock on cleanup
  • e089aa3f09ce selftests: ntsync: correct CONFIG_NTSYNC name
  • 8cbad52ccfa6 serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms
  • 863230250dd5 serial: sc16is7xx: implement gpio get_direction() callback
  • f5f663469ad2 uio_hv_generic: Bind to FCopy device by default
  • 5d059ce0e6a2 comedi: comedi_parport: deal with premature interrupt
  • 6ed367bbbf4d x86/boot/compressed: Disable jump tables
  • b5ed54a37ad5 firmware: stratix10-svc: handle NO_RESPONSE in async poll
  • 7b14f42c7460 firmware: stratix10-svc: fix teardown order in remove to prevent race
  • 8e93a083456d firmware: stratix10-svc: fix memory leaks and list corruption bugs
  • 4169d9fb92f3 rhashtable: clear stale iter->p on table restart
  • f3e2715a1500 cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
  • 496bc868d906 LoongArch: Retrieve CPU package ID from PPTT when available
  • 881e9f3c4e11 LoongArch: Move jump_label_init() before parse_early_param()
  • a30a69678fca LoongArch: Increase TASK_STRUCT_OFFSET up to 2040 for 32BIT
  • eca63bd15580 LoongArch: Fix oops during single-step debugging
  • 3cfc4bd63574 LoongArch: Fix build errors due to wrong instructions for 32BIT
  • 7a54e0cbaad4 LoongArch: Fix address space mismatch in kexec command line lookup
  • 2d342c8b79c1 objtool/rust: add one more noreturn Rust function for Rust 1.99.0
  • fd661e6c1f64 rust: allow clippy::unwrap_or_default globally
  • a73bcfeacd67 rust: allow suspicious_runtime_symbol_definitions lint for Rust >= 1.98
  • d7c36d58f16d rust: device: avoid trailing ; in printing macros
  • 132fc107b973 rust: time: fix as_micros_ceil() to round correctly for negative Delta
  • 9be9bb59f485 rust_binder: only print failure if error has source
  • 95e27b4ba4e5 platform/loongarch: laptop: Explicitly reset bl_powered state when suspend
  • 5ccc99d58f94 binfmt_misc: set have_execfd only once the interpreter is opened
  • 55fa2c7f2b15 exec: fix unsigned loop counter wrap in transfer_args_to_stack()
  • 98bc68194e37 Bluetooth: RFCOMM: Fix session UAF in set_termios
  • fe13adc258df Bluetooth: hci_sync: Protect UUID list traversal
  • 5968fd6c3f68 staging: rtl8723bs: fix inverted HT40 secondary channel offset
  • 23c31f107b4f staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()
  • 17a4298f7794 wifi: ath12k: fix NULL pointer dereference in rhash table destroy
  • 65ee82c5ee84 wifi: ath11k: fix refcount leak in ath11k_ahb_fw_resources_init()
  • a1734263befc wifi: brcmfmac: set F2 blocksize to 256 for BCM43752
  • 0ca80328df23 wifi: brcmfmac: make release_scratchbuffers idempotent
  • 177a25be1195 wifi: brcmfmac: drain bus_reset work on device removal
  • 03d3291c4b37 wifi: mt76: restrict NPU/PPE active checks to MMIO devices
  • 9677e86a5f7d wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses
  • 24475d2ddc8d wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
  • b2ab73b8123c wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
  • 8ccdf8c8de87 wifi: wilc1000: validate assoc response length before subtracting header
  • cca4398aa305 wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper
  • a3313111b5d9 wifi: ath6kl: fix use-after-free in aggr_reset_state()
  • cec0a487cf38 wifi: ath6kl: fix OOB access from firmware ADDBA window size
  • c1078130a4cd ALSA: timer: don't re-enter an instance callback that is still running
  • 2b2989977868 ALSA: timer: drain a slave's callback before its master detaches it
  • 089b8985a299 ALSA: hda: codecs: hdmi: disable keep-alive before audio format change
  • 31a6163e301d ALSA: seq: close a re-opened queue timer in the destructor
  • f7ba6fa309d4 ALSA: hda/realtek: Fix speakers on Lunnen Ground 14
  • 1a0e99470a0b media: vpif_capture: fix OF node reference imbalance
  • 6d51ad8f1c50 media: vivid: fix cleanup bugs in vivid_init()
  • daf2d92669b4 media: vivid: check for vb2_is_busy() when toggling caps
  • 90204e98c016 media: vivid: add vivid_update_reduced_fps()
  • dd29c4abad00 media: vimc: fix reference leak on failed device registration
  • 260346526b8e media: vidtv: fix reference leak on failed device registration
  • b9b02035b129 media: verisilicon: Export only needed pixels formats
  • 941bf408c5e5 media: vb2: use ssize_t for vb2_read/vb2_write
  • f7b3a27e35a3 media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely
  • 067887ff93fd media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()
  • b01df98a6669 media: v4l2-ctrls: validate HEVC active reference counts
  • ccf9c59704f8 media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete()
  • cd2bcc565619 media: uapi: rkisp: Correct name version enum
  • fcbbaf9cb972 media: ti: vpe: unwind v4l2 device registration on probe error
  • abfaa1b2670c media: ti: vpe: Fix the error code of devm_request_irq()
  • 956879b173c2 media: ti: vpe: Fix the error code of devm_kzalloc() in vip_probe_slice()
  • 6171b55640da media: ti: vpe: Fix fwnode_handle leak in vip_probe_complete()
  • b83120604a39 media: tegra-video: vi: fix invalid u32 return value in format lookup
  • 7dd27810eea0 media: synopsys: hdmirx: Fix HPD lane hold time
  • 668face37fdb media: sun4i-csi: Return queued buffers on start_streaming() failure
  • 4b7ee504969e media: stm32: dcmi: unregister notifier on probe failure
  • 624af2d4b5e9 media: stm32-dcmipp: Return queued buffers on start_streaming() failure
  • 1731dd61b6c0 media: saa7134: Fix a possible memory leak in saa7134_video_init1
  • 18aa963948b7 media: rzv2h-ivc: Wait for frame end in stop_streaming
  • a6709ee3c922 media: rzg2l-cru: Skip ICnMC configuration when ICnSVC is used
  • fc0b18782aab media: rtl2832_sdr: Return queued buffers on start_streaming() failure
  • 90d781711418 media: rtl2832: fix use-after-free in rtl2832_remove()
  • 730c235d7d2c media: radio-si476x: Unregister v4l2_device on probe failure
  • 9ce597c8bdb4 media: qcom: camss: Fix RDI streaming for CSID 340
  • 0495a46a30af media: qcom: camss: Fix RDI streaming for CSID GEN3
  • e0d11cb8b54c media: qcom: camss: Fix RDI streaming for CSID GEN2
  • ea87d4242723 media: qcom: camss: Fix RDI streaming for CSID 680
  • a4f8f629983f media: pwc: Return queued buffers on start_streaming() failure
  • 5d4812668b03 media: pwc: Drain fill_buf on start_streaming() failure
  • 0c2b4c45fce0 media: pci: dm1105: Free allocated workqueue
  • 26edee412cbe media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding
  • 75cdfaa7c908 media: nxp: imx8-isi: Fix potential out-of-bounds issues
  • fe127ea278b9 media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path
  • 9ac81a2bbf70 media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure
  • 9c5ddbabc31f media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe
  • 65ddc021d39d media: nuvoton: npcm-video: fix memory leaks in probe and remove
  • 410398f06c28 media: nuvoton: npcm-video: fix error handling in npcm_video_init()
  • 3673cb0a5711 media: msi2500: Return queued buffers on start_streaming() failure
  • 99f3527bd1a2 media: meson: vdec: Fix memory leak in error path of vdec_open
  • cbe66053094f media: marvell-cam: fix missing pci_disable_device() on remove
  • 3adde045236a media: mali-c55: Power-off the peripheral in remove()
  • 65d442427584 media: mali-c55: Fix possible ERR_PTR in enable_streams
  • f83262ac4437 media: mali-c55: Disable pm_runtime on probe error
  • f9879931b492 media: mali-c55: Add missing of_reserved_mem_device_release()
  • 49cdf03d95e7 media: iris: Fix use IRQF_NO_AUTOEN when requesting the IRQ
  • 54b70e8e682f media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges
  • 739e289bfb6d media: imx219: Fix maximum frame length in lines
  • eb2f934646ae media: i2c: alvium: fix critical pointer access in alvium_ctrl_init
  • e1a6465500b0 media: dw9719: Add back the I²C device id table
  • ff3c670a1de3 media: cx23885: add ioremap return check and cleanup
  • e797e252bfb3 media: cx231xx: fix devres lifetime
  • d681227ce43b media: chips-media: wave5: Move src_buf Removal to finish_encode
  • e53112c2de88 media: cedrus: skip invalid H.264 reference list entries
  • 4c2237c1f8c8 media: cedrus: Fix missing cleanup in error path
  • 578cb3701dd3 media: cedrus: clean up media device on probe failure
  • e94851429828 media: cec: seco: unregister adapter on IR probe failure
  • 578cff91d0b5 media: aspeed: fix missing of_reserved_mem_device_release() on probe failure
  • 32cbe5474e74 media: amlogic-c3: Add validations for ae and awb config
  • 170fcc945bc0 media: airspy: Return queued buffers on start_streaming() failure
  • eeaa0c5feb91 drm/v3d: Reach the GMP through the hub registers on V3D 7.x
  • adf0542659c7 drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict
  • b7fd42da6cb3 drm/gpusvm: Zero HMM PFNs before scanning ranges
  • 921d6acd5761 drm/ttm/pool: back up at native page order
  • 296f4c78f8da drm/pagemap: Guard HPAGE_PMD_ORDER use with CONFIG_ARCH_ENABLE_THP_MIGRATION
  • fe168ef1d232 drm/vc4: Prevent shader BO mappings from becoming writable
  • 6910ccaf4167 drm/vmwgfx: Validate vmw_surface_metadata::array_size
  • 095f1a2502eb drm/pagemap: Clear driver-provided PFNs from migration PFN array
  • c58088a8e744 drm/amd/display: Fix missing DCE check in dm_gpureset_toggle_interrupts()
  • bac4c1a9af69 drm/vc4: Shut down BO cache timer before teardown
  • 57c85f13a3df drm/amd/display: Fix flip-done timeouts on mode1 reset
  • 55440dd29e74 drm/amdgpu: always emit the job vm fence
  • 7d088935c72c drm/amdgpu: Print vmid, pasid and more task info in devcoredump
  • 9743f6001327 drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
  • 50d8e10bf867 drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge
  • 1191285ecb42 drm/amd/display: Fix backlight max_brightness to match exported range
  • 3665fc7f93f1 drm/amd/display: Force PWM backlight on Lenovo Legion 5 15ARH05
  • ed2d86aef9fa drm/amd/display: dce100: skip non-DP stream encoders for DP MST
  • 9a5a582ad96a drm/amd/display: consolidate DCN vblank/flip handling onto vupdate_no_lock
  • 0676fecbb524 drm/amd/display: set new_stream to NULL after release
  • b2c51a7e5786 drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X)
  • 42e80ecdb188 drm/amd: Create a device link between APU display and XHCI devices
  • 3085ae8695e0 drm/amdgpu/userq: fix indefinite fence wait during GPU reset
  • 23131f1f930d drm/amdgpu: Fix VFCT bus number matching with soft filter
  • 9b7de3ee5d2c drm/amdgpu: Release VFCT ACPI table reference
  • f59825d834c0 drm/panthor: return error on truncated firmware
  • 9ddaabf38f7a drm/ttm: Account for NULL and handle pages in ttm_pool_backup
  • 72e4fca5529e drm/gpusvm: publish dpagemap early to avoid device mapping leak on error
  • 7475273d88d8 drm/virtio: Don't detach GEM from a non-created context
  • b5a62e022f42 drm/gfx10: Program DB_RING_CONTROL
  • 5ee1c5784157 drm/amd/pm: fix smu14 power limit range calculation
  • 9061fbf2230b drm/i915/mst: limit DP MST ESI service loop
  • edd4804f07b8 drm/i915/gt: Fix NULL deref on sched_engine alloc failure
  • 97f236379f06 drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU
  • 6cdbef8f60f3 drm/i915/gem: Do not leak siblings[] on proto context error
  • 28ebf07444b0 drm/amdgpu: trigger GPU recovery when userq destroy fails to unmap a hung queue
  • 5d5fb9124a2b drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()
  • 29b4939bd44c drm/amd/amdgpu: disable ASPM on VI if pcie dpm is disabled
  • 625f301e01bf drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()
  • 15fd21a9bba2 drm/amdgpu/soc24: reset dGPU if suspend got aborted
  • 8887b94d2fc9 drm/i915/bios: range check LFP Data Block panel_type2
  • 58b7e63ca0cd drm/i915: Return NULL on error in active_instance
  • 0027cb19b044 drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
  • 2051bbbfbd44 drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
  • 9df8a7f09e30 drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()
  • bcbd53d25da8 drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()
  • 1a07ac63ae5b drm/amdgpu: add the doorbell index input for suspending userq
  • 984085c5b535 drm/i915/hdcp: check streams[] bounds before overflow
  • 41747d37cf56 drm/i915/hdcp: require monotonically increasing seq_num_v
  • c726c8bbee51 drm/i915/vrr: require valid min/max vfreq for VRR
  • 375c1934ef01 drm/virtio: bound EDID block reads to the response buffer
  • fba211b078d6 Revert "drm/amd/display: Restore 5s vbl offdelay for NV3x+ DGPUs"
  • 58ea24dd9684 drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference
  • dbad70d40cad drm/amd/display: use kvzalloc to allocate struct dc
  • b1bd5c2b24f5 drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips
  • ee4efff4b65c drm/amd/display: set MSA MISC1 bit 6 when using VSC SDP for DCE 11.x
  • 000c405fa153 drm/amdkfd: free MQD managers on DQM init failures
  • 865532d54eb5 drm/amdkfd: fix 32-bit overflow in CWSR total size calculation
  • cc10a5839756 drm/amdkfd: Check bounds on CRIU restore queue type and mqd size
  • abeeb1947d81 drm/amdkfd: Check bounds in allocate_event_notification_slot
  • 72c7d449778d drm/amdkfd: Use kvcalloc to allocate arrays
  • 1874a9414cbc drm/amdkfd: Guard m->cp_hqd_eop_control setting by q->eop_ring_buffer_size
  • a0d87beb2660 drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size
  • 15f58d44c244 drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM
  • 401fbe3b6bbb drm/imagination: fix error checking of pvr_vm_context_lookup()
  • 09beaf4aec05 drm/imagination: Fix user array stride in pvr_set_uobj_array()
  • c1136d907fd0 drm/imagination: Fix double call to drm_sched_entity_fini()
  • a6bdbff8f6f5 drm/xe/madvise: Skip invalidation for purgeable state updates
  • 50b6a61d8834 drm/xe/nvm: fix writable override for CRI
  • 90e4fd331b98 drm/xe/pt: Reset current_op in xe_pt_update_ops_init()
  • c4affa4e8bc8 drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC
  • ba8c4cbb31c6 drm/xe: Hold a dma-buf reference for imported BOs
  • 481dc7df8f72 drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds
  • 1e6d07abbc0c drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists
  • 22ad3edd2cec drm/xe/oa: Fix offset alignment for MERT WHITELIST_OA_MERT_MMIO_TRG
  • 7445e1b85159 drm/xe: Return error on non-migratable faults requiring devmem
  • 513346701b1d drm/xe/display: skip FORCE_WC and vm_bound check for external dma-bufs
  • f302e5f3bd33 drm/radeon: fix r100_copy_blit for large BOs
  • 0bb004807da9 drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit()
  • af128ca139d6 drm/i915/mtl+: Enable PPS before PLL
  • c41a54619e95 drm/i915/gem: Add missing nospec on parallel submit slot
  • bcd40ea7788f drm/displayid: fix Tiled Display Topology ID size
  • 28e1cb89f02c drm/amdkfd: Use exclusive bounds for SVM split alignment checks
  • 76e5a52855d7 drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions
  • 983eb36d3b09 drm/sysfb: Return errno code from drm_sysfb_get_visible_size()
  • 9d58a811739a drm/sysfb: Avoid possible truncation with calculating visible size
  • ebbaf64d2635 drm/nouveau: fix reversed error cleanup order in ucopy functions
  • 24668ca3ec19 drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
  • 9f9c88eb298c drm/amdgpu: Fix context pstate override handling
  • c5bf18ff8f2a drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT
  • 73874c6d2539 drm/amdgpu/gfx9: Fix Ring and IB test fail after mode2
  • 9777453ce4f8 drm/amd/display: Restore periodic detection for DCN35
  • 34a7ed214c5e drm/xe: Add compact-PT and addr mask handling for page reclaim
  • a9a020f3c11e drm/xe/guc: Fix buffer overflow in steered register list allocation
  • e7a871390b77 drm/sysfb: Avoid truncating maximum stride
  • aed27dbfb8d6 drm/sysfb: Do not page-align visible size of the framebuffer
  • 9faf4c66edb6 drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO
  • efa292aebc8b drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older
  • bc78482db958 drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2)
  • 9cd9a983769a drm/amdgpu/gfx: fix cleaner shader IB buffer overflow
  • 51af46225f84 drm/amd/pm: re-enable MC access after PrepareMp1ForUnload on SMU V15 APUs
  • 1e9b961f9f45 drm/i915/cdclk: Fix up CDCLK_FREQ_DECIMAL without a full PLL re-enable
  • 68a624416d1d drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
  • 4ddf82c18ee4 drm/imagination: Fit paired fragment job in the correct CCCB
  • 560adcc7d401 drm/tegra: fbdev: Remove offset into framebuffer memory
  • a6366b551079 drm/dp/mst: fix buffer overflows in sideband chunk accumulation
  • e6ef5455b06c drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
  • ace55d80395c drm/exynos: fbdev: Remove offset into screen_buffer
  • 1f9c6b74e796 drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
  • a673171502e8 drm/imagination: Count paired job fence as dependency in prepare_job()
  • ba34d197ebf2 drm/rockchip: analogix_dp: Add missing error check for platform_get_resource()
  • 6d5ee0dab4f9 drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video()
  • 4f2352520faa drm/tidss: Fix missing drm_bridge_add() call
  • d2c08dab2738 drm: renesas: rzg2l_mipi_dsi: Move rzg2l_mipi_dsi_set_display_timing()
  • e299e35e86e2 drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay
  • b9c8a1400a3b tracing: Fix use-after-free freeing trigger private data
  • 752b1159ed5d bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
  • f1557e0a6473 LoongArch: BPF: Fix memory leak in bpf_jit_free()
  • 9aa7071185c7 pidfs: make pidfs_ino_lock static
  • d5e2cd2bc8ae drop_monitor: perform u64_stats updates under IRQ-disabled section
  • 4a9e30764e80 drop_monitor: fix size calculations for 64-bit attributes
  • 8fd6975d2aec net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD
  • a3829056ca98 bnge/bng_re: fix ring ID widths
  • fe9bf32bb18f tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()
  • ecdd0875e3bd net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets()
  • 9e9654a8eec1 mctp: check register_netdevice_notifier() error in mctp_device_init()
  • 794c503d9264 ptp: netc: explicitly clear TMR_OFF during initialization
  • 3aa13fe0c1bb rds: tcp: unregister sysctl before tearing down listen socket
  • f08bf5f3be66 ipv6: Change allocation flags to match rcu_read_lock section requirements
  • 9fbe22b7aff0 idpf: fix max_vport related crash on allocation error during init
  • d0a21604c6ab ice: prevent tstamp ring allocation for non-PF VSI types
  • c63314c08b34 ice: fix LAG recipe to profile association
  • bff901a9852f ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV
  • e3e59c37cdc2 net: ipv6: fix dif and sdif mismatch in raw6_icmp_error
  • 294bc4b6b1a3 octeontx2-pf: tc: fix egress ratelimiting
  • f8d1c4e69ecb net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation
  • d6169ed4e341 net/mlx5e: Report zero bandwidth for non-ETS traffic classes
  • 96041242efc3 net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule
  • 88b2a16ddac3 net/mlx5: Fix MCIA register buffer overflow on 32 dword reads
  • 74ab1e7c8b8e raw: annotate lockless match fields in raw_v4_match()
  • 659b9b4f194b net: qrtr: restrict socket creation to the initial network namespace
  • 716cb29dbed4 LoongArch: BPF: Zero-extend signed ALU32 div/mod results
  • a189b62fa601 hinic: remove unused ethtool RSS user configuration buffers
  • daf82730355d ppp: annotate data races in ppp_generic
  • ee5b419cad37 ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup
  • 6c4e18135cc0 octeontx2-vf: set TC flower flag on MCAM entry allocation
  • 9dfab50f0765 mpls: Set rt->rt_nhn just before returning from mpls_nh_build_multi().
  • 2bffe3790235 net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
  • c09df4d9e72e net: stmmac: enable the MAC on link up for all supported speeds
  • a99bc2eef774 net: stmmac: reset residual action in L3L4 filters on delete
  • e10ccddeec02 net: stmmac: fix l3l4 filter rejecting unsupported offload requests
  • bdcc15ec0ff7 net: stmmac: xgmac: fix l4 filter port overwrite on register update
  • 8a726e9585ff bpf: tcp: fix double sock release on batch realloc
  • ce20d589370d drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem
  • c1cda72f6ace tipc: fix u16 MTU truncation in media and bearer MTU validation
  • fa1063d14a3c iomap: fix incorrect did_zero setting in iomap_zero_iter()
  • 9606c6014328 iomap: correct the range of a partial dirty clear
  • 9ac92736030f drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create()
  • bb7abf112544 drm/xe/i2c: Allow per domain unique id
  • b28596baf87e vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
  • 83f5031f2a6a sctp: auth: verify auth requirement when auth_chunk is NULL
  • 84228811cc18 net: stmmac: dwmac4: mask interrupts when stopping DMA in suspend
  • 31f9cbd09b3c net: dpaa: fix mode setting
  • 282d220bae5f smp: Make CSD lock acquisition atomic for debug mode
  • 6455dbdbb34b smp: Avoid invalid per-CPU CSD lookup with CSD lock debug
  • ae995b8002d3 net: hsr: fix memory leak on slave unregistration by removing synced VLANs
  • 3e2ff8448333 net: bridge: vlan: fix vlan range dumps starting with pvid
  • 3741147a3d18 amt: make the head writable before rewriting the L2 header
  • 7f48e3ddad8e amt: re-read skb header pointers after every pull
  • 1f4a107439d2 ovl: check access to copy_file_range source with src mounter creds
  • 261f0a3f0ac0 drm/vc4: hvs/v3d: Fix null dereference in unbind
  • 304a470bbd62 drm/panel: fix unmet dependency bug for DRM_PANEL_HIMAX_HX83121A
  • ed537d090471 drm/panel: s6e3ha8: fix unmet dependency on DRM_DISPLAY_HELPER
  • 496373b64075 drm/panel: ilitek-ili9882t: fix unmet dependency for DRM_PANEL_ILITEK_ILI9882T
  • 90775605dd0f ovl: fix trusted xattr escape prefix matching
  • bd4fac033bb9 wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
  • 523ed2831ee5 drm/xe/vf: Add drm_dev guards when detaching CCS read/write buffers
  • 45c496756c6f wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()
  • 89d03bda560d wifi: mt76: mt7925: fix crash in reset link replay
  • e12575136e47 wifi: mt76: fix airoha_npu dependency tracking
  • 8bc7167e8a86 wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()
  • 856f1588a259 wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()
  • 8709c66e665a wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()
  • 6f99a5667c6c wifi: mt76: mt7915: guard HE capability lookups
  • d86883f7e8f0 wifi: mt76: mt7925: guard link STA in decap offload
  • b3fe7baffc0d ppp: annotate concurrent dev->stats accesses
  • 32390b3f06f2 cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths
  • 42737cf1c3c9 cifs: prevent readdir from changing file size due to stale directory metadata
  • b8f3b8efa5f9 tipc: fix infinite loop in __tipc_nl_compat_dumpit
  • 18506d726376 nexthop: initialize extack in nh_res_bucket_migrate()
  • cf45d748e437 gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
  • 700de4678d11 selftests: drv-net: convert so_txtime to drv-net
  • aa59787607db selftests: drv-net: increase timeout
  • e286e6145379 selftests: ovpn: increase timeout
  • 5d9e83ee4632 selftests: ovpn: add IPV6 and VETH configs
  • 20b69c478c28 selftests: openvswitch: add config file
  • 38c6b3e45ab3 selftests: af_unix: add USER_NS config
  • 8a8d80197576 tls: device: push pending open record on splice EOF
  • a40e83a34eaa net: mctp i3c: clean up notifier and buses if driver register fails
  • 00ae679cb21a sctp: validate stream count in sctp_process_strreset_inreq()
  • 02b0b8a14d87 accel: ethosu: Handle U85 internal chaining buffer
  • b4ae748f8e6c accel: ethosu: Fix element size accounting for cmd stream validation
  • 1d93c6abc147 pds_core: check for workqueue allocation failure
  • bdeab32a7a91 pds_core: fix auxiliary device add/del races
  • 6d8593349c13 pds_core: order completion reads after the ownership check
  • ac05919612b4 pds_core: yield the CPU while waiting for the adminq to drain
  • ecc7a7d7569e pds_core: fix use-after-free on workqueue during remove
  • 54f905821f26 pds_core: fix deadlock between reset thread and remove
  • b6ea3dda09eb sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
  • 4946dea23863 net: txgbe: fix FDIR filter leak on remove
  • 00d5707217b5 rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled
  • febcced69581 net: txgbe: fix heap overflow when reading module EEPROM
  • d70c81001df9 tipc: serialize udp bearer replicast list updates
  • cac4ebdb831c geneve: ensure the skb is writable before fixing its headers
  • c0816ecedf36 geneve: fix hint header definition wrt endianness
  • c35b19fc3446 net: Call net_enable_timestamp() before failure in sk_clone().
  • c95ef27acc2d soreuseport: Clear sk_reuseport_cb before failure in sk_clone().
  • 6582ba7af37d amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN
  • b2f176d58dc3 arm64/mm: Check the requested PFN range during memory removal
  • 1e477e4c5e53 arm64: Correct value returned by ESR_ELx_FSC_ADDRSZ_nL()
  • 950431062159 pds_core: reject component parameter in legacy firmware update
  • d036f2d44f58 wifi: mac80211: recalculate TIM when a station enters power save
  • 0e28ca1c3204 iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
  • 030a8e84f8f1 iommu/amd: Bound the early ACPI HID map
  • b6766d7ea43e wifi: mwifiex: bound uAP association event IEs to the event buffer
  • 539382822dbb wifi: mac80211: copy aggregation information
  • 0c6d1b9fbb64 vhost-net: fix TX stall when vhost owns virtio-net header
  • 2fe22d58b379 wan: wanxl: Only reset hardware after BAR mapping
  • a7dc30b6828c nfp: Check resource mutex allocation
  • 901a73523e09 wifi: mac80211: tear down new links on vif update error path
  • 02f8cefa2ad9 iommu/amd: Wait for completion instead of returning early in iommu_completion_wait()
  • 4c4d866a64f3 net: airoha: Fix DMA direction for NPU mailbox buffer
  • a3cecf169cc6 dpaa2-eth: put MAC endpoint device on disconnect
  • ad28c4f9e0ea net: airoha: Fix potential use-after-free in airoha_ppe_deinit()
  • c27694ff6748 dpaa2-switch: put MAC endpoint device on disconnect
  • 092b42cf3f60 rxrpc: fix io_thread race in rxrpc_wake_up_io_thread()
  • e66451163383 gtp: parse extension headers before reading inner protocol
  • 0f8690e38691 rds: drop incoming messages that cross network namespace boundaries
  • 738039ad21e2 bonding: fix devconf_all NULL dereference when IPv6 is disabled
  • c8fd74445e86 net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains
  • cabfacbd5af0 bpf: Reject redirect helpers without a bpf_net_context
  • a885387dae79 net/packet: avoid fanout hook re-registration after unregister
  • 44de1031f1e2 netlink: specs: rt-link: convert bridge port flag attributes to u8
  • 08102525f1f8 selftests/net: Fix tun IPv6 test addresses to avoid 6to4 range
  • 4aba40721f92 net: phy: marvell: fix return code
  • 24b0758193d7 Bluetooth: btusb: validate Realtek vendor event length
  • 4f95592e1a90 regulator: mt6358: use regmap helper to read fixed LDO calibration
  • b042e538e98b hwmon: occ: validate poll response sensor blocks
  • 6c85bc624b4c ovpn: use monotonic clock for peer keepalive timeouts
  • 4cdb209f12a8 ovpn: fix use after free in unlock_ovpn()
  • ebe4e94f4a4c selftests/net: ovpn: fix getaddrinfo memory leak in ovpn_parse_remote()
  • 016a50379d17 ovpn: avoid putting unrelated P2P peer on socket release
  • 5d03046a7c53 drm/i915/backlight: Remove DP_EDP_BACKLIGHT_AUX_ENABLE_CAP check for DPCD backlight
  • 9f88a99ed511 smb: client: validate DFS referral PathConsumed
  • 672973b49ea3 hwmon: (asus-ec-sensors) add missed handle for ENOMEM
  • 491690618b90 hwmon: (asus-ec-sensors) fix EC read intervals
  • 8e609af82aa8 hwmon: (asus-ec-sensors) fix looping over banks while reading from EC
  • 9b93a63b9087 hwmon: (pmbus/max34440) block unsupported VIN and IIN limit registers
  • 316f7140217f hwmon: (pmbus/max34440): add support adpm12250
  • aadc7e08a28a hwmon: Use named initializers for arrays of i2c_device_data
  • 734d1cb58d43 hwmon: Drop unused i2c driver_data
  • af3895e9e887 drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook()
  • 0cc0c4c14150 usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect
  • 66c87fc2d529 wifi: iwlwifi: mvm: fix read in wake packet notification handler
  • 2b348020375e wifi: iwlwifi: validate payload length in iwl_pnvm_complete_fn
  • 29e89a5cd8b4 wifi: iwlwifi: fix pointer arithmetic in iwl_add_mcc_to_tas_block_list
  • 5bfeaeeab72e wifi: iwlwifi: mvm: validate SAR GEO response payload size
  • df61ff97d279 ASoC: cs35l56: Use complete_all() to signal init_completion
  • babdfc580020 ASoC: cs35l56: Fix potential probe() deadlock
  • ca1f96334267 arm_mpam: guard MBWU state before adding it to garbage
  • 125c3fd6b816 arm_mpam: Fix MPAMCFG_MBW_PBM register setting
  • ddc0769e2187 arm_mpam: Fix software reset values of MPAMCFG_PRI
  • 8ba157866b0c ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI
  • d5dfdf43259a ALSA: hda: cs35l41: validate and free ACPI mute object
  • d90825206896 iommu/amd: Fix nested domain leak
  • e0c78cdf35af iommu/amd: Fix IRQ unsafe locking in gdom allocation
  • 10de317e64d5 ASoC: sun4i-codec: Set quirks.playback_only for H616 codec
  • e75ef37d83c9 ASoC: tas2781: bound firmware description string parsing
  • ae0629ff9ccb btrfs: free mapping node on duplicate reloc root insert
  • 0e465c63f103 btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps
  • b6ba206ffb74 btrfs: fix u32 to s64 type conversion in dirty_metadata_bytes accounting
  • 0ea3c4445811 btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8
  • 21f59906ea75 wifi: carl9170: fix buffer overflow in rx_stream failover path
  • 423c836f9348 wifi: carl9170: fix OOB read from off-by-two in TX status handler
  • cb7a38810cf2 wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
  • 94e1bfcefe82 wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
  • c38b0d5c6619 wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
  • f8160cf19f9e wifi: ath12k: Fix low MLO RX throughput on WCN7850
  • 2a5aa4e9b892 firewire: net: Fix fragmented datagram reassembly
  • c3d2d8940ec0 platform/x86: asus-wmi: temporarily revert to setting a charge limit
  • 1e7ceb5b0135 platform/x86/intel/vsec: free ACPI discovery data on early errors
  • 8d182aead59e platform/x86/intel/vsec: allocate res with intel_vsec_dev
  • a19e0f4b6360 wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET
  • ef290f9e99c6 wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET
  • 725c1c3a8c5d wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()
  • ea48d712d298 wifi: ath10k: fix skb leak on incomplete msdu during rx pop
  • 57c3f5bd5be0 watchdog: airoha: Prevent division by zero when clock frequency is zero
  • 7993d626983c watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
  • dc73b0dfeab8 hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop
  • 18d7c5238910 hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
  • 0842e9faab04 hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
  • 1a634f464d61 hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
  • bb25bd980f2d hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
  • 4abb4e284d88 wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin
  • 7c9046d92c4b wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
  • 98b7fc0d7ef6 watchdog: ni903x_wdt: Check ACPI_COMPANION() against NULL
  • 828ed58535f2 selftests/bpf: Keep verifier_map_ptr exercising ops pointer access
  • 5c350dced70b selftests/bpf: Adjust verifier_map_ptr for the map's excl field
  • 2ea73153240f usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits
  • 749a36657ca2 Revert "drm/amd/display: Add missing kdoc for ALLM parameters"
  • 845fc1e4dcf4 RISC-V: KVM: Serialize virtual interrupt pending state updates
  • abc360aac3df wifi: mwifiex: fix freeze for 60 seconds caused by request_firmware
  • 68c857b78dcc drm/amd/display: Add dp_skip_rbr flag for NUTMEG
  • f83c5af4742d drm/amd/display: Fix preferred link rate for NUTMEG
  • 95776812e6b8 drm/amd/display: Fix ISM dc_lock deadlock during suspend
  • 2d19fbfceb14 usb: typec: ucsi: Add duplicate detection to nvidia registration path
  • 244b028dc7be usb: typec: ucsi: Detect and skip duplicate altmodes from buggy firmware
  • c7dd73d83b8c USB: serial: option: add TDTECH MT5710-CN
  • 122f180bfc1f USB: serial: keyspan_pda: fix data loss on receive throttling
  • 1e47d8228b87 USB: serial: io_edgeport: cap received transmit credits
  • 4f411e8501d2 USB: serial: ftdi_sio: add support for E+H FXA291
  • c8510fbbea09 usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer
  • d4964a747171 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
  • 4c6c6a5588b9 usb: gadget: f_tcm: synchronize delayed set_alt with teardown
  • 41fd5f2fb002 usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
  • 5e0eb0c78013 USB: gadget: fsl-udc: fix dev_printk() device
  • 1351277e153c USB: gadget: fsl-udc: fix device name leak on probe failure
  • 0320f21345d2 USB: gadget: snps-udc: fix device name leak on probe failure
  • e41bbbbb1740 usb: gadget: printer: fix infinite loop in printer_read()
  • ac9a51d910bb usb: gadget: f_midi: cancel pending IN work before freeing the midi object
  • e24b33618231 usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
  • b4b0d3802697 usb: chipidea: fix usage_count leak when autosuspend_delay is negative
  • 2313f5e7028f USB: storage: add NO_ATA_1X quirk for Longmai USB Key
  • 6c525c851e59 usb: musb: omap2430: Do not put borrowed of_node in probe
  • e00109b5adf7 usb: core: port: Deattach Type-C connector on component unbind
  • f742d9c98b5c wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
  • ab82adf5e63b usb: core: sysfs: add lock to bos_descriptors_read()
  • 06db79411a28 mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
  • 48b913e3f115 selftests: netconsole: only restore MAC when it changed on resume
  • 4e1caa5fdd0d bnxt_en: Handle partially initialized auxiliary devices
  • 3aa40c3bccac sctp: fix auth_hmacs array size in struct sctp_cookie
  • 2791a501da50 net/sched: act_tunnel_key: Defer dst_release to RCU callback
  • 4b3e6b9fdaeb dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync()
  • 374742a961be tcp: fix TIME_WAIT socket reference leak on PSP policy failure
  • e8fadbffc19a accel/amdxdna: Fix use-after-free of mm_struct in job scheduler
  • 76b9ec20d22e drm/i915/selftests: Fix GT PM sort comparators
  • c7b6d61979b8 drm/i915/wm: clear the plane ddb_y entries on plane disable
  • ea128f06d2fb ksmbd: validate compound request size before reading StructureSize2
  • 14062c74e5b2 ksmbd: pin conn during async oplock break notification
  • 03d6f83979b0 drm/xe/guc: Hold device ref until queue teardown completes
  • 77fd62412431 drm/xe/guc: Keep scheduler timeline name alive
  • 5a09a0d17b6b drm/xe: Assign queue name in time for drm_sched_init
  • 82806d880eac drm/xe/wopcm: fix WOPCM size for LNL+
  • f2ebfd5cc87f drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves
  • b3ea85c3c73b can: j1939: fix lockless local-destination check
  • 82f8d6ab4561 riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus()
  • 898bb2814f38 s390/checksum: Fix csum_partial() without vector facility
  • d4bf73b962b7 drm/panthor: Check debugfs GEM lock initialization
  • 8692655da369 bpf, sockmap: Reject unhashed UDP sockets on sockmap update
  • 56e97b36a501 powerpc/vtime: Initialize starttime at boot for native accounting
  • 234b3ead3e8f powerpc/time: Prepare to stop elapsing in dynticks-idle
  • 21541c24563e powerpc/85xx: Add fsl,ifc to common device ids
  • 755bd5556e5f spi: cadence-quadspi: Fix indirect write timeout when DMA read mode is enabled
  • 57791aab1129 can: raw: add locking for raw flags bitfield
  • 5fcb8b8cb396 drm/i915/gt: use correct selftest config symbol
  • ae70dda83d45 riscv: Gate FUNCTION_ALIGNMENT_4B on DYNAMIC_FTRACE
  • a4a09e514283 smb/client: handle overlapping allocated ranges in fallocate
  • 3899db224f8a Bluetooth: mgmt: Translate HCI reason in Device Disconnected event
  • 2363a7576947 Bluetooth: hci_qca: Clear memdump state on invalid dump size
  • 8d892bec1dd1 Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups
  • ecdcb55ea1c0 Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
  • b11511006f9e Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
  • 38326774df61 Bluetooth: hci_sync: extend conn_hash lookup critical sections
  • b82802b5ab26 Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update
  • 4fcfb5b2c736 Bluetooth: qca: fix NVM tag length underflow in TLV parser
  • b84691ff8069 ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC
  • 31e55573edeb accel/ivpu: Fix wrong register read in LNL failure diagnostics
  • 29b916d3556b ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning
  • cfecc0c67619 ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts
  • 626aecafa69a ata: sata_dwc_460ex: use platform_get_irq()
  • 5d0797d6940b ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered
  • 24d7abda6a2a scsi: core: wake eh reliably when using scsi_schedule_eh
  • 5c54e9d4fcaf udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf()
  • 5595ea59cdf2 net/iucv: take a reference on the socket found in afiucv_hs_rcv()
  • b8d2ea75c76a ipv4: fib: free fib_alias with kfree_rcu() on insert error path
  • 06213c85d8c0 ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
  • 82e0c68e5ed4 sched_ext: Record an error on errno-only sub-enable failure
  • 4f265e2cacc6 cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq
  • 14b49b5ab299 bpf: Fix UAF in sock clone early bailouts
  • 3c746522a41f firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context
  • 4d8e4780e306 ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup
  • 52bdf1290894 sched_ext: Enable tick for finite slices on nohz_full
  • 47370430ac16 ASoC: cs42l43: Correct report for forced microphone jack
  • b26272b392ce erofs: relax sanity check for tail pclusters due to ztailpacking
  • 70affc74bc31 ASoC: amd: ps: replace bitwise OR with logical OR in IRQ return check
  • bd54a545a324 ASoC: amd: ps: fix wrong ACP version string in pci_request_regions()
  • 365ea356341d ASoC: amd: ps: disable MSI on resume in ACP PCI driver
  • 46d78faf2641 ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop
  • 8ef18f0ab3c0 firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation
  • 27abdaf0c5c8 firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()
  • ddf2773bcc8e wifi: cfg80211: bound element ID read when checking non-inheritance
  • c73c3fc1c7ca wifi: brcmfmac: initialize SDIO data work before cleanup
  • 6d6123fef5a4 wifi: cfg80211: use wiphy work for socket owner autodisconnect
  • 4b8abf43bf34 wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
  • 4e5cf3cf184c ASoC: amd: acp: Fix linker error with SDCA quirks
  • 429ac1c2fe81 wifi: mac80211: avoid non-S1G AID fallback for S1G assoc
  • 8f2dbeee540c wifi: cfg80211: reject empty PMSR peer lists
  • 49a8ae4df3a0 wifi: cfg80211: reject unsupported PMSR FTM location requests
  • 58320cb47df2 wifi: cfg80211: validate PMSR FTM preamble range
  • befabcc4170f wifi: cfg80211: validate PMSR measurement type data
  • f3f3bbab96b3 wifi: nl80211: constrain MBSSID TX link ID range
  • f7055ad71368 wifi: nl80211: validate nested MBSSID IE blobs
  • eb1f99a02f6d wifi: cfg80211: derive S1G beacon TSF from S1G fields
  • 6f919f29e9b7 wifi: nl80211: free RNR data on MBSSID mismatch
  • 0a77d9fb4d5c wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock
  • 9096e1f70141 wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
  • a03fceae0c65 wifi: mac80211: defer link RX stats percpu free to RCU
  • 644640cde2fb wifi: libertas: fix memory leak in helper_firmware_cb()
  • 1981fba71797 wifi: mac80211: fix fils_discovery double free on alloc failure
  • 0ace76e410d7 wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
  • 99dc05c75acc wifi: mac80211_hwsim: clamp virtio RX length before skb_put
  • 99d2e850c643 wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()
  • 7cbda50eebcd wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
  • b119c70b2477 wifi: cfg80211: cancel sched scan results work on unregister
  • d91b1fdc70c5 ALSA: usb-audio: Fix imbalance per-channel volume of sticky mixers
  • 4b2c349988f9 wifi: mac80211: allocate backup ieee80211_nan_sched_cfg off stack
  • 6aa3796d18a9 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
  • e078da1b4e11 xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()
  • ffd64e0717ef xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
  • c37a07923012 xfrm: clear mode callbacks after failed mode setup
  • bdd83f0a49a1 RDMA/irdma: Prevent overflows in memory contiguity checks
  • 1d73084f4451 selftests/alsa: Fix memory leak in find_controls error path
  • 820f983d6419 mtd: fix double free and WARN_ON in add_mtd_device() error paths
  • 52f9fcb19114 RDMA/siw: publish QP after initialization
  • 9f0fbf76d664 RDMA/hns: Fix potential integer overflow in mhop hem cleanup
  • 9d0201aefda6 RDMA/core: Fix memory leak in __ib_create_cq() on invalid cqe
  • 0d9fbcf79c72 RDMA/mana_ib: initialize err for empty send WR lists
  • a9f76f726007 RDMA/erdma: initialize ret for empty receive WR lists
  • 728211c815f6 RDMA/irdma: Prevent user-triggered null deref on QP create
  • 9b5012a9ca33 RDMA/irdma: Remove redundant legacy_mode checks
  • dbaa37e06091 RDMA/irdma: Prevent rereg_mr for non-mem regions
  • c73a1ddb21c5 RDMA/cma: Fix hardware address comparison length in netevent callback
  • 9333f4b6f448 xfrm: reject optional IPTFS templates in outbound policies
  • 96b678d08268 xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
  • 6cefed45a5be reset: spacemit: k3: fix USB2 ahb reset
  • e2f188cdbf83 sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx()
  • 12a42c610e44 firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
  • cb5a938ca0fe btrfs: fallback to transaction csum tree on a commit root csum miss
  • 7591d1727067 btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()
  • f9fef131fa3f btrfs: reject free space cache with more entries than pages
  • 0fb32ba4f74d mtd: nand: mtk-ecc: stop on ECC idle timeouts
  • 4aaba135ddf4 mtd: mtdswap: remove debugfs stats file on teardown
  • d36520e5da8b mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy()
  • 4d91d783f934 mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy_joins()
  • ad9c9ad3204f IB/mad: Drop unmatched RMPP responses before reassembly
  • bd2a4483a863 firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits
  • bbca7cc3b2b4 xfrm: fix stale skb->prev after async crypto steals a GSO segment
  • 0943e331500c xfrm: propagate -EINPROGRESS from validate_xmit_xfrm()
  • db2765d4bfc3 arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234
  • 19dd7326d1ad sched_ext: Annotate ksyncs with __rcu in alloc/free_kick_syncs()
  • b27634071289 Docs/admin-guide/cgroup-v2: fix memory.stat doc details
  • 1defa8fb132f arm64: tegra: Remove fallback compatible for GPCDMA
  • e8bfeafded96 xprtrdma: Clear receive-side ownership pointers on release
  • 9382304e25c6 crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin
  • b773faa32b0a gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
  • 43cfb20d62ff KVM: x86/mmu: Fix use-after-free on vendor module reload
  • 1dabef6e2065 KVM: nVMX: Hide shadow VMCS right after VMCLEAR
  • 6e9815aa51fc KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN
  • bce0d3c26e2c KVM: x86: Check for invalid/obsolete root after making MMU pages available
  • 29ca543ac55a seqlock: Allow UBSAN_ALIGNMENT to fail optimizing
  • 2e0b1d51de9e drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker
  • 1d412720a163 sched_ext: Skip ops.set_weight() for disabled tasks
  • 782e1042143d platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug
View originalPermalink
How 7.1.6-xanmod1 went

6.18.42-xanmod1

Fixed 19
  • KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug
  • gpu: Fix uninitialized buddy for built-in drivers
  • net: stmmac: fix dwmac4 transmit performance regression
  • net/mlx5e: Fix NULL pointer dereference in ioctl module EEPROM query
  • usb: gadget: f_tcm: synchronize delayed set_alt with teardown
  • rust: device: avoid trailing ; in printing macros

From XanMod Kernel

  • 054f69ce6232 Linux 6.18.42-xanmod1
  • 764d67d28fa6 Merge tag 'v6.18.42' into 6.18
  • 856a9b51680c Linux 6.18.42
  • 0f33b1c457c2 KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug
  • 846ed916cfa0 gpu: Fix uninitialized buddy for built-in drivers
  • bcb29986bbba net: stmmac: fix dwmac4 transmit performance regression
  • a0d1a11b90a5 net/mlx5e: Fix NULL pointer dereference in ioctl module EEPROM query
  • f282242906c1 usb: gadget: f_tcm: synchronize delayed set_alt with teardown
  • aeebcfa8237c rust: device: avoid trailing ; in printing macros
  • e94e820df37d rust: allow suspicious_runtime_symbol_definitions lint for Rust >= 1.98
  • 6ce0db97fb37 mm/damon/core: disallow overlapping input ranges for damon_set_regions()
  • 4b6f1d6d5d07 mm/damon/core: validate ranges in damon_set_regions()
  • deead12d2e65 i3c: mipi-i3c-hci: Fix handling of shared IRQs during early initialization
  • 811b581fae65 i3c: mipi-i3c-hci: Fix Hot-Join NACK
  • 4fd5b33faf09 pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI
  • c389893bb403 pmdomain: imx93-blk-ctrl: convert to devm_* only
  • dc8347f263b2 net: ipa: fix SMEM state handle leaks in SMP2P init
  • 4c1e8ccd8655 ata: libata-core: Reject an invalid concurrent positioning ranges count
  • 9466dc5e377f bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline()
  • a88c2a70ea0a bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c
  • c73b8795b45f octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF
  • 4467fa514482 octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify
  • ae5ae3d5bfaa net: mana: Optimize irq affinity for low vcpu configs
  • 6d13eaa13341 net: mana: Validate the packet length reported by the NIC
  • 7b7bb07efe41 fs/resctrl: Fix use-after-free during unmount
  • d48cf914c739 fs/resctrl: Move RMID initialization to first mount
  • 682d3c2cd20e fs/resctrl: Move allocation/free of closid_num_dirty_rmid[]
  • 8c5925f0fa12 x86,fs/resctrl: Rename some L3 specific functions
  • 696c34a1964f x86,fs/resctrl: Rename struct rdt_mon_domain and rdt_hw_mon_domain
  • ad4ea2a169a4 fs/resctrl: Split L3 dependent parts out of __mon_event_count()
  • 5b82af744e06 mmc: vub300: fix use-after-free on probe failure
  • 73d397ab54f2 mmc: vub300: rename probe error labels
  • 8ced1d242c34 dm: avoid leaking the caller's thread keyring via the table device file
  • dd73cc92a55d cred: add kernel_cred() helper
  • af7a4c2caa7a accel/amdxdna: reject command submission on devices without a submit op
  • 62dae36be7a6 ovl: use linked upper dentry in copy-up tmpfile
  • 043acb00e4ed dmaengine: dw-edma-pcie: Reject devices without driver data
  • 277a035cda47 dmaengine: dw-edma: Fix confusing cleanup.h syntax
  • 19360c25135f mtd: maps: vmu-flash: fix fault in unaligned fixup
  • b8271be34bce kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES
  • 3d561f46fa78 mm/sparse-vmemmap: fix vmemmap accounting underflow
  • 8af652cd9946 remoteproc: xlnx: Check remote core state
  • 6fc1919a6f2e cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size
  • 89b2ae039d18 cxl/pci: Remove CXL VH handling in CONFIG_PCIEAER_CXL conditional blocks from core/pci.c
  • eeab77506992 cxl/pci: Remove unnecessary CXL RCH handling helper functions
  • a64661dccb2e cxl/pci: Remove unnecessary CXL Endpoint handling helper functions
  • 5d964cb2b7bc SUNRPC: Return an error from xdr_buf_to_bvec() on overflow
  • b50b2cb87e7a SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists
  • a112b91dd634 sunrpc: allocate a separate bvec array for socket sends
  • 3120f21df3fb NFSD: pass nfsd_file to nfsd_iter_read()
  • 6876f767b049 pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP
  • 7185c5262435 gpu/buddy: bail out of try_harder when alignment cannot be honoured
  • 9634fd144cdc drm: drop lib from header search path.
  • 65677f7a20c4 gpu: Move DRM buddy allocator one level up (part two)
  • 09755dc62b02 netfilter: nf_conntrack_sip: validate skb_dst() before accessing it
  • a1a94a00b884 netfilter: nf_conntrack_sip: remove net variable shadowing
  • d01c913febea netfilter: nft_fib: reject fib expression on the netdev egress hook
  • beeda5bf7857 netfilter: nf_tables: remove register tracking infrastructure
  • 1de827e24d0a arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers
  • 0d810ff7a6f6 arm64: dts: qcom: correct RBR opp entry
  • 690fb82c4122 VDUSE: avoid leaking information to userspace
  • 7764e9c727d5 vduse: take out allocations from vduse_dev_alloc_coherent
  • db5c554b36d5 vduse: remove unused vaddr parameter of vduse_domain_free_coherent
  • 82e48ad2a132 vduse: return internal vq group struct as map token
  • b1f38c3ec620 xfs: don't replace the wrong part of the cow fork
  • 3bca70235a70 fuse-uring: fix race between registration and connection abortion
  • 40879c39d674 audit: fix recursive locking deadlock in audit_dupe_exe()
  • 91b64f0be416 audit: use 'unsigned int' instead of 'unsigned'
  • eef6914f2b45 audit: widen ino fields to u64
  • c5772ced573e landlock: Account all audit data allocations to user space
  • a95b62759f3b landlock: Fix formatting
  • 682a0066dde0 drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources
  • 81ea8e822185 fscrypt: Avoid dynamic allocation in fscrypt_get_devices()
  • 337022d9dfac ksmbd: validate ACE size against SID sub-authorities
  • f1eba60db813 ksmbd: bound DACL dedup walk to copied ACEs
  • 847ecd4eb3c1 ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL
  • b6d3cc6a5244 ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
  • 17e6b8c4319f net: qrtr: ns: Raise node count limit to 512
  • 7dd26adf7e7d ublk: wait on ublk_dev_ready() instead of ub->completion
  • 5a15eaa50f92 drm/xe/uapi: Reject coh_none PAT index for CPU_ADDR_MIRROR
  • 5488d3a69d20 dm-verity: fix buffer overflow in FEC calculation
  • 3f31bde63f9a dm-verity-fec: replace {MAX,MIN}_RSN with {MIN,MAX}_ROOTS
  • d47281b9a447 dm-verity-fec: fix reading parity bytes split across blocks (take 3)
  • a556189c0675 dm-verity-fec: fix the size of dm_verity_fec_io::erasures
  • 22400725de07 bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops
  • 15a7cb71a574 drm/amdgpu: fix check in amdgpu_hmm_invalidate_gfx
  • ab7b40c638e0 drm/amd/pm: fix smu13 power limit range calculation
  • 6405c4e75b3b drm/amdgpu: fix aperture mapping leak
  • 08fee493e026 drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
  • 68eab5a64ddb drm/amdgpu: fix resource leak on ACP reset timeout
  • ffb33d466a68 drm/amdgpu: fix division by zero with invalid uvd dimensions
  • 8c6d84a54823 drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()
  • bd868c077f67 drm/amdgpu/vcn4: avoid rereading IB param length
  • 7eebef042c12 drm/amdgpu/vce: fix integer overflow in image size
  • f7e9eeaccca5 drm/amdgpu/soc24: reset dGPU if suspend got aborted
  • dc3f5da1ba8e drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()
  • 76c977d396f1 drm/amdgpu/jpeg: fix jpeg_v5_0_1_is_idle detection
  • 058373af5955 drm/amdgpu/jpeg: fix jpeg_v4_0_3_is_idle detection
  • 042c047e8bc9 drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()
  • 05aea3344c42 drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()
  • f70bd5235d9e drm/amdgpu/gfx8: drop unecessary BUG_ON()
  • 987bedd3ea89 drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()
  • dfd9bf09fd8f drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()
  • 7e22de67e545 drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()
  • e75f71143b68 drm/amd/pm: make pp_features read-only when scpm is enabled
  • ada47af5c215 drm/amd/pm: fix amdgpu_pm_info power display units
  • 7b263cf1dd4c watchdog: s32g_wdt: remove incorrect options in watchdog_info struct
  • 79370b573e92 vxlan: mdb: Fix source list corruption on a failed replace
  • f60bac115d8d vsock/virtio: collapse receive queue under memory pressure
  • 5f5a41a48dbf tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
  • 234f9ffbd9b2 tcp: challenge ACK for non-exact RST in SYN-RECEIVED
  • fadaff3f66e1 tcp: initialize standalone TCP-AO response padding
  • 4a4f3aa6af20 rtase: Workaround for TX hang caused by hardware packet parsing
  • 6866abf59976 pppoe: reload header pointer after dev_hard_header()
  • 460b9f0609d2 ovpn: hold peer before scheduling keepalive work
  • b08526bf0bbf ovpn: fix peer refcount leak in TCP error paths
  • 100a23b1613e openvswitch: fix GSO userspace truncation underflow
  • f80ba170d7b3 mctp: serial: handle zero-length frames to prevent rx buffer overflow
  • f20dedce0429 mac802154: llsec: reject frames shorter than the authentication tag
  • 59c1d5463b7b mac802154: hold an interface reference across the scan worker
  • 472aba2603ca ila: reload IPv6 header after pskb_may_pull in checksum adjust
  • 919d0accf260 ice: use READ_ONCE() to access cached PHC time
  • 5e496f2b615c ice: reject out-of-range ptype in ice_parser_profile_init
  • 91e0249f3ef6 gve: fix Rx queue stall on alloc failure
  • 18705cace061 ksmbd: defer destroy_previous_session() until after NTLM authentication
  • 6098b55f6a0c smb: client: handle STATUS_STOPPED_ON_SYMLINK responses without a symlink target
  • 34f2a2f32af5 rbd: Reset positive result codes to zero in object map update path
  • 63d78b546eef super: fix emergency thaw deadlock on frozen block devices
  • e4406cbdd915 ice: fix PTP Call Trace during PTP release
  • b3efb4744abf ptp: ptp_s390: Add missing facility check
  • 9a8a247f0f17 s390/ptff: Export ptff_function_mask[]
  • 4afc58ea75b9 proc: Fix broken error paths for namespace links
  • 4056cc19071a net: pcs: xpcs: fix SGMII state reading
  • 80d977f280b4 net: hip04: fix RX buffer leak on build_skb failure
  • a4dfd46cc8f0 net: gro: fix double aggregation of flush-marked skbs
  • ec6d91a1bf2e net/x25: fix use-after-free in x25_kill_by_neigh()
  • 40f9a124ebbe net/mlx5e: Use sender devcom for MPV master-up
  • 900cd6d8119b net/iucv: fix use-after-free of a severed iucv_path
  • 33736ff5e7c9 net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
  • f8c498585d2a geneve: require CAP_NET_ADMIN in the device netns for changelink
  • 5d07b178bef5 net: slip: serialize receive against buffer reallocation
  • 730c7e5fea7f vxlan: require CAP_NET_ADMIN in the device netns for changelink
  • a48a889b60f7 phonet: pep: fix use-after-free in pep_get_sb()
  • 03157872da5e net: stmmac: intel: skip SerDes reconfig when rate is unchanged
  • 1b44a5f584bf iommu/vt-d: Disallow SVA if page walk is not coherent
  • 7037e7bdcd26 iomap: fix out-of-bounds bitmap_set() with zero-length range
  • f139498c5ebd io_uring/rw: fix missing ERESTARTSYS conversion in read paths
  • 65bf73bee1a4 ftrace: Add global mutex to serialize trace_parser access
  • 95376fe9c145 fscrypt: Add missing superblock check in find_or_insert_direct_key()
  • a019b074903b fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
  • c78e38745ff1 fs/super: fix emergency thaw double-unlock of s_umount
  • 89b9121c3b01 binfmt_elf_fdpic: only honour the first PT_INTERP
  • d309f8b52b34 ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP
  • c4d77740eca2 ASoC: fsl: imx-card: Skip sysclk reset for active DAIs in shutdown
  • 1a644db2cf59 amt: fix use-after-free in AMT delayed works
  • 8f5a3abc54ba libceph: remove debugfs files before client teardown
  • 3b2f1937f5fc libceph: reject zero bucket types in crush_decode
  • e67e8b694872 libceph: Reject monmaps advertising zero monitors
  • 0060ec912292 libceph: refresh auth->authorizer_buf{,_len} after authorizer update
  • 4716a64b7cc2 libceph: guard missing CRUSH type name lookup
  • 1732d89dfcd7 libceph: Fix multiplication overflow in decode_new_up_state_weight()
  • 4e7ebfaa0d14 libceph: bound get_version reply decode to front len
  • 7d03e08b763f ceph: fix writeback_count leak in write_folio_nounlock()
  • a7c2dfa610a1 ceph: fix refcount leak in ceph_readdir()
  • a4228b93706f ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
  • 3bf0e349cbb4 sctp: close UDP tunnel sockets during netns teardown
  • be6aae9d1b91 sctp: avoid auth_enable sysctl UAF during netns teardown
  • 85aca407c560 sctp: don't free the ASCONF's own transport in DEL-IP processing
  • 3db217a4c2bd mm/huge_memory: set PG_has_hwpoisoned only after new folio head is established
  • ac7a6f61f56f mm/kmemleak: fix checksum computation for per-cpu objects
  • f2b293359924 afs: Fix afs_edit_dir_remove() to get, not find, block 0
  • d64f6c02495f mptcp: pm: userspace: fix use-after-free in get_local_id
  • 6cd3c3d63155 mptcp: only set DATA_FIN when a mapping is present
  • 6c936b5ad557 mptcp: decrement subflows counter on failed passive join
  • 35c4b274d4cc Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates"
  • 64ab0964c7db arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates
  • 9cd4b1a52eff arm64: make huge_ptep_get handled unaligned addresses
  • 9025946adec9 tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err()
  • 3b3be8653c59 tracing/probes: Fix potential underflow in LEN_OR_ZERO macro
  • 949ac1aeb37b tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args()
  • 6b5098d74581 tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match()
  • b6a4575f2292 tracing: Fix union collision of module and refcnt for dynamic events
  • cf5a82bef623 tracing: Fix resource leak on mmiotrace trace_pipe close
  • 8464427e1c17 tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
  • 1f2e7cd0ff97 tracing: Fix context switch counter truncation
  • 1da310b94504 misc: nsm: pin the module while the device is open
  • 8f068342096b misc: nsm: only unlock nsm_dev on post-lock error paths
  • caba30eb8bd3 intel_th: fix MSC output device reference leak
  • 59dd34854202 mei: bus: access mei_device under device_lock on cleanup
  • 511887235727 selftests: ntsync: correct CONFIG_NTSYNC name
  • b2a3eeb57ba2 serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms
  • 4fae473b856b serial: sc16is7xx: implement gpio get_direction() callback
  • 635be8b097f0 uio_hv_generic: Bind to FCopy device by default
  • cf26dd2d8415 comedi: comedi_parport: deal with premature interrupt
  • 9bb71b59e0aa x86/boot/compressed: Disable jump tables
  • 4f2db41a09eb firmware: stratix10-svc: fix memory leaks and list corruption bugs
  • 3ff7c1dbf722 rhashtable: clear stale iter->p on table restart
  • d43c5c0c9355 cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
  • 4427a33faabb LoongArch: Retrieve CPU package ID from PPTT when available
  • 38b025fcdc45 LoongArch: Move jump_label_init() before parse_early_param()
  • 6ab0abb5a2e0 LoongArch: Fix oops during single-step debugging
  • a94d6726ec86 LoongArch: Fix address space mismatch in kexec command line lookup
  • c404b1f30b25 objtool/rust: add one more noreturn Rust function for Rust 1.99.0
  • 8ccfb3b315a0 rust: allow clippy::unwrap_or_default globally
  • 6db0c42c87c4 rust: time: fix as_micros_ceil() to round correctly for negative Delta
  • 12be1d75e9b2 rust_binder: only print failure if error has source
  • cc3bbff10b1a platform/loongarch: laptop: Explicitly reset bl_powered state when suspend
  • 1cd4e9b7967d binfmt_misc: set have_execfd only once the interpreter is opened
  • 2bc6bf70d410 exec: fix unsigned loop counter wrap in transfer_args_to_stack()
  • 780b04d09c94 Bluetooth: RFCOMM: Fix session UAF in set_termios
  • a42f5536ea9c Bluetooth: hci_sync: Protect UUID list traversal
  • 91eff666c907 staging: rtl8723bs: fix inverted HT40 secondary channel offset
  • 875479f18835 staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()
  • 0dbaff14fd6a wifi: ath11k: fix refcount leak in ath11k_ahb_fw_resources_init()
  • efe9de178e4b wifi: brcmfmac: set F2 blocksize to 256 for BCM43752
  • 044fca8f45ba wifi: brcmfmac: make release_scratchbuffers idempotent
  • 9cb72f67e150 wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses
  • 263816e92e8d wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
  • ab4d213393e8 wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
  • e511e93abd6e wifi: wilc1000: validate assoc response length before subtracting header
  • 9375a4ea4121 wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper
  • 18965470d41e wifi: ath6kl: fix use-after-free in aggr_reset_state()
  • 58c6c8dc2e02 wifi: ath6kl: fix OOB access from firmware ADDBA window size
  • 1395327a9661 ALSA: timer: don't re-enter an instance callback that is still running
  • 426c0ff1c433 ALSA: timer: drain a slave's callback before its master detaches it
  • 3bc4de57fc7d ALSA: hda: codecs: hdmi: disable keep-alive before audio format change
  • 6a10025c7fd0 ALSA: seq: close a re-opened queue timer in the destructor
  • 2ec8f95a08fe ALSA: hda/realtek: Fix speakers on Lunnen Ground 14
  • 4091b216d11b media: vpif_capture: fix OF node reference imbalance
  • 1349af7f87df media: vivid: fix cleanup bugs in vivid_init()
  • 492c97cb50fe media: vivid: check for vb2_is_busy() when toggling caps
  • 26e7a8ac286f media: vivid: add vivid_update_reduced_fps()
  • 3780ad381071 media: vimc: fix reference leak on failed device registration
  • 86ece01fba2d media: vidtv: fix reference leak on failed device registration
  • 16ae8c166e78 media: verisilicon: Export only needed pixels formats
  • b88c929188e3 media: vb2: use ssize_t for vb2_read/vb2_write
  • 072a883061a4 media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely
  • cf9732fd6c4f media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()
  • 3068ab802fc9 media: v4l2-ctrls: validate HEVC active reference counts
  • 836cfffb2ddb media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete()
  • 7e6521dd747e media: ti: vpe: unwind v4l2 device registration on probe error
  • 127fc44e8325 media: tegra-video: vi: fix invalid u32 return value in format lookup
  • 118c2f5d1d36 media: synopsys: hdmirx: Fix HPD lane hold time
  • b5184b3f0e9d media: sun4i-csi: Return queued buffers on start_streaming() failure
  • 931abe1deb65 media: stm32: dcmi: unregister notifier on probe failure
  • ed342a86bb2f media: stm32-dcmipp: Return queued buffers on start_streaming() failure
  • b7936e8cbec1 media: saa7134: Fix a possible memory leak in saa7134_video_init1
  • a7a141e4e93c media: rzg2l-cru: Skip ICnMC configuration when ICnSVC is used
  • 894e83509c66 media: rtl2832_sdr: Return queued buffers on start_streaming() failure
  • 2c71bda6edc6 media: rtl2832: fix use-after-free in rtl2832_remove()
  • 64cb15878b35 media: radio-si476x: Unregister v4l2_device on probe failure
  • a58d01a0ed39 media: qcom: camss: Fix RDI streaming for CSID GEN3
  • c39a1d9fde82 media: qcom: camss: Fix RDI streaming for CSID GEN2
  • 4e451100b35e media: qcom: camss: Fix RDI streaming for CSID 680
  • cb16b79a2be2 media: pwc: Return queued buffers on start_streaming() failure
  • 9afd605dcd96 media: pwc: Drain fill_buf on start_streaming() failure
  • 08ddfd628a2d media: pci: dm1105: Free allocated workqueue
  • 4e077bcb5e1f media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding
  • 28ae75dba701 media: nxp: imx8-isi: Fix potential out-of-bounds issues
  • 659a7cea0be8 media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path
  • 4702afbd56f1 media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure
  • 9e61258fbc3c media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe
  • 181a0aeefd56 media: nuvoton: npcm-video: fix memory leaks in probe and remove
  • 2147acb948a9 media: nuvoton: npcm-video: fix error handling in npcm_video_init()
  • 264b5380c4f8 media: msi2500: Return queued buffers on start_streaming() failure
  • 1391b75bf011 media: meson: vdec: Fix memory leak in error path of vdec_open
  • 18e3b838e09d media: marvell-cam: fix missing pci_disable_device() on remove
  • cf48e9db8565 media: iris: Fix use IRQF_NO_AUTOEN when requesting the IRQ
  • d56044558a75 media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges
  • 00a98fb2a6fb media: imx219: Fix maximum frame length in lines
  • 7337c88205ed media: i2c: alvium: fix critical pointer access in alvium_ctrl_init
  • c68c4ce72feb media: cx23885: add ioremap return check and cleanup
  • f468b7ee5d63 media: cx231xx: fix devres lifetime
  • f24ca8b53fe1 media: chips-media: wave5: Move src_buf Removal to finish_encode
  • 9924cb548ee7 media: cedrus: skip invalid H.264 reference list entries
  • 000e51afb606 media: cedrus: Fix missing cleanup in error path
  • 73504935e436 media: cedrus: clean up media device on probe failure
  • 6efe665356ec media: cec: seco: unregister adapter on IR probe failure
  • 0459a4304cff media: aspeed: fix missing of_reserved_mem_device_release() on probe failure
  • 391fe3e36e59 media: amlogic-c3: Add validations for ae and awb config
  • 73bd27798653 media: airspy: Return queued buffers on start_streaming() failure
  • a096a6aba601 drm/v3d: Reach the GMP through the hub registers on V3D 7.x
  • a2212fef8e18 drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict
  • 6deaa3172018 drm/vc4: Prevent shader BO mappings from becoming writable
  • b1379f0c42b8 drm/vmwgfx: Validate vmw_surface_metadata::array_size
  • 2b85e19792be drm/amd/display: Fix missing DCE check in dm_gpureset_toggle_interrupts()
  • a38f2724eb93 drm/vc4: Shut down BO cache timer before teardown
  • ee44ea4f7e30 drm/amd/display: Fix flip-done timeouts on mode1 reset
  • ba7b6444097a drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
  • fd2de80f28a0 drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge
  • 490ceacd2162 drm/amd/display: Fix backlight max_brightness to match exported range
  • 9c0432044d34 drm/amd/display: Force PWM backlight on Lenovo Legion 5 15ARH05
  • 51ea665c30c4 drm/amd/display: dce100: skip non-DP stream encoders for DP MST
  • 0b9fa4272e24 drm/amd/display: consolidate DCN vblank/flip handling onto vupdate_no_lock
  • 679f23f0a360 drm/amd/display: set new_stream to NULL after release
  • 123692ebc1ea drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X)
  • d8dc3a9e815d drm/amdgpu: Fix VFCT bus number matching with soft filter
  • 312278b30919 drm/amdgpu: Release VFCT ACPI table reference
  • e64b2f1e826a drm/panthor: return error on truncated firmware
  • 22aa7fb4e7d0 drm/ttm: Account for NULL and handle pages in ttm_pool_backup
  • b2d8b66c6739 drm/virtio: Don't detach GEM from a non-created context
  • a4a1866d50c4 drm/gfx10: Program DB_RING_CONTROL
  • e163c5a0946d drm/amd/pm: fix smu14 power limit range calculation
  • e3bcd3bf7eec drm/i915/mst: limit DP MST ESI service loop
  • 726f27bca93e drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU
  • 37951ce1567c drm/i915/gem: Do not leak siblings[] on proto context error
  • 1173190412fb drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()
  • 5df5a59c32b4 drm/amd/amdgpu: disable ASPM on VI if pcie dpm is disabled
  • 8b2da44446f9 drm/i915/bios: range check LFP Data Block panel_type2
  • cbec6a57959a drm/i915: Return NULL on error in active_instance
  • d20b5c139b29 drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
  • 09da54636bac drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
  • 51fd52087165 drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()
  • 4c0948332536 drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()
  • 3d2ef8d38949 drm/i915/hdcp: check streams[] bounds before overflow
  • 1f876bd8adc7 drm/i915/hdcp: require monotonically increasing seq_num_v
  • 35be0e2c6862 drm/virtio: bound EDID block reads to the response buffer
  • 4ee77643e619 drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference
  • 8a77ccf9cb99 drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips
  • abce3276c57e drm/amdkfd: fix 32-bit overflow in CWSR total size calculation
  • fd1691ec6270 drm/amdkfd: Check bounds on CRIU restore queue type and mqd size
  • 50319efb865f drm/amdkfd: Check bounds in allocate_event_notification_slot
  • 14a631dca9df drm/amdkfd: Use kvcalloc to allocate arrays
  • 6253bb56bb2e drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM
  • c45fafa69fe3 drm/imagination: fix error checking of pvr_vm_context_lookup()
  • b983a35dad37 drm/imagination: Fix user array stride in pvr_set_uobj_array()
  • c88fdbf3da26 drm/imagination: Fix double call to drm_sched_entity_fini()
  • c1954c66662d drm/xe: Hold a dma-buf reference for imported BOs
  • 038d0b80ab77 drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds
  • 90a8a938e0ca drm/xe: Return error on non-migratable faults requiring devmem
  • 3e1f909556aa drm/radeon: fix r100_copy_blit for large BOs
  • fbb9effc8168 drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit()
  • 45db277b2e1e drm/i915/gem: Add missing nospec on parallel submit slot
  • 748d425e53c3 drm/displayid: fix Tiled Display Topology ID size
  • 5452eb5c1663 drm/sysfb: Return errno code from drm_sysfb_get_visible_size()
  • 154795885e8f drm/sysfb: Avoid possible truncation with calculating visible size
  • 4e109faa9ea2 drm/nouveau: fix reversed error cleanup order in ucopy functions
  • 315d2e5741a8 drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
  • 3fb10ec43c25 drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT
  • 9c2b01508831 drm/amdgpu/gfx9: Fix Ring and IB test fail after mode2
  • f835eda74cf6 drm/sysfb: Avoid truncating maximum stride
  • 7daefc6d5195 drm/sysfb: Do not page-align visible size of the framebuffer
  • ddba17b3dfa0 drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO
  • d068a2f53afc drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older
  • b3a01cda0ae1 drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2)
  • e28420e36542 drm/amdgpu/gfx: fix cleaner shader IB buffer overflow
  • d5c70523cafa drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
  • e2c29d51c0f6 drm/imagination: Fit paired fragment job in the correct CCCB
  • 1e5827839ad0 drm/dp/mst: fix buffer overflows in sideband chunk accumulation
  • 533d9e2bede4 drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
  • c0384d6872f4 drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
  • 943fa73ea0ef drm/imagination: Count paired job fence as dependency in prepare_job()
  • 6ab29a868357 drm/rockchip: analogix_dp: Add missing error check for platform_get_resource()
  • 50cd8a7e98dd drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video()
  • 86ab4d93b3d4 drm/tidss: Fix missing drm_bridge_add() call
  • 300a2d970a53 drm: renesas: rzg2l_mipi_dsi: Move rzg2l_mipi_dsi_set_display_timing()
  • aa8ad3e0d1fe drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay
  • 786d690257ec bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
  • 3a924139cf52 net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets()
  • 391a23c50385 mctp: check register_netdevice_notifier() error in mctp_device_init()
  • 74ecebfbf155 ptp: netc: explicitly clear TMR_OFF during initialization
  • 16df2d154ec8 rds: tcp: unregister sysctl before tearing down listen socket
  • 1db34097998c ipv6: Change allocation flags to match rcu_read_lock section requirements
  • 684d4d0bda95 ice: prevent tstamp ring allocation for non-PF VSI types
  • a32604e8d9e2 ice: fix LAG recipe to profile association
  • 3a8134546767 ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV
  • 5d54d603cf3e net: ipv6: fix dif and sdif mismatch in raw6_icmp_error
  • e60e6009d3ba octeontx2-pf: tc: fix egress ratelimiting
  • d612754a515c net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation
  • a7e430349fc5 net/mlx5e: Report zero bandwidth for non-ETS traffic classes
  • cdddc8188db4 net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule
  • 87b39a8c875c net/mlx5: Fix MCIA register buffer overflow on 32 dword reads
  • 5f2ef3d53d37 net/mlx5: Refactor EEPROM query error handling to return status separately
  • 953d47cfe529 raw: annotate lockless match fields in raw_v4_match()
  • 8150c48fb978 net: qrtr: restrict socket creation to the initial network namespace
  • 0d57d43d7c4c hinic: remove unused ethtool RSS user configuration buffers
  • 8fc45a2a7cc2 ppp: annotate data races in ppp_generic
  • 19fe119dfa93 ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup
  • e037a41938c6 octeontx2-vf: set TC flower flag on MCAM entry allocation
  • 15a1c5f2ed2e net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
  • 55515c1b1285 net: stmmac: enable the MAC on link up for all supported speeds
  • 1bcb737fb884 net: stmmac: reset residual action in L3L4 filters on delete
  • 370dde2b70e5 net: stmmac: fix l3l4 filter rejecting unsupported offload requests
  • 55d2a8d184e2 net: stmmac: xgmac: fix l4 filter port overwrite on register update
  • 40413da85036 net: stmmac: cores: remove many xxx_SHIFT definitions
  • 4a3eea468a04 net: stmmac: socfpga: Add hardware supported cross-timestamp
  • 01d45e6b2c50 net: stmmac: socfpga: Enable TBS support for Agilex5
  • dac8c2ab943a net: stmmac: socfpga: Agilex5 EMAC platform configuration
  • d67136a931e5 net: stmmac: remove xstats.pcs_* members
  • 9f27c4f0ae35 bpf: tcp: fix double sock release on batch realloc
  • b43bb9ab6003 drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem
  • 1b8fb5a20508 tipc: fix u16 MTU truncation in media and bearer MTU validation
  • c8e4b2a567ef iomap: correct the range of a partial dirty clear
  • 279339aa8bdc drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create()
  • d18d9b2c29a1 drm/xe/i2c: Allow per domain unique id
  • 4fdb0f162ccd vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
  • 18957373920c sctp: auth: verify auth requirement when auth_chunk is NULL
  • ae0ec759865e net: dpaa: fix mode setting
  • b5ded444621b net: hsr: fix memory leak on slave unregistration by removing synced VLANs
  • 17bb59682b8e net: bridge: vlan: fix vlan range dumps starting with pvid
  • 0a347ca1d6a2 amt: make the head writable before rewriting the L2 header
  • ca0e8b661957 amt: re-read skb header pointers after every pull
  • 9ec22c8113d8 ovl: check access to copy_file_range source with src mounter creds
  • 31f5f7c959c3 ovl: port ovl_copyfile() to cred guard
  • cde234a493f6 ovl: add override_creds cleanup guard extension for overlayfs
  • 35f0b504394e cred: add scoped_with_kernel_creds()
  • 3139b806923b drm/panel: s6e3ha8: fix unmet dependency on DRM_DISPLAY_HELPER
  • 790da254031c ovl: fix trusted xattr escape prefix matching
  • 00ebbf030d8c wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
  • d5628f39fccc wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()
  • 95b0cf02731c wifi: mt76: mt7925: fix crash in reset link replay
  • d14238523ca4 wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()
  • 313343ab8cab wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()
  • c058786b09cf wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()
  • 871549814eb4 wifi: mt76: mt7915: guard HE capability lookups
  • f1ee53e08fdd wifi: mt76: mt7925: guard link STA in decap offload
  • cc4d2f8b984c ppp: annotate concurrent dev->stats accesses
  • b52ff80948d1 ppp: don't store tx skb in the fastpath
  • cb9d3e0b5569 ppp: enable TX scatter-gather
  • e740e90ca8e7 tipc: fix infinite loop in __tipc_nl_compat_dumpit
  • d536bf205c71 nexthop: initialize extack in nh_res_bucket_migrate()
  • 961e9b1e3344 gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
  • 023c5e0d0294 selftests: drv-net: increase timeout
  • fa065685c8a9 selftests: ovpn: increase timeout
  • e2b3d426c7ee selftests: ovpn: add IPV6 and VETH configs
  • 69eab5c4d9aa selftests: openvswitch: add config file
  • 340c389fd3d5 selftests: af_unix: add USER_NS config
  • fbd91910c502 tls: device: push pending open record on splice EOF
  • a8bd8c109da5 net: mctp i3c: clean up notifier and buses if driver register fails
  • 1a10fe1aa9c0 sctp: validate stream count in sctp_process_strreset_inreq()
  • c984a4184f81 pds_core: check for workqueue allocation failure
  • cf0ed2ba202f pds_core: fix auxiliary device add/del races
  • 0e87fe52b560 pds_core: order completion reads after the ownership check
  • 3a831f40e88d pds_core: yield the CPU while waiting for the adminq to drain
  • 9e0f80fac50a pds_core: fix use-after-free on workqueue during remove
  • 19ef775c91c6 pds_core: fix deadlock between reset thread and remove
  • 11092d79eb2b sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
  • 2d34421bfa26 net: txgbe: fix FDIR filter leak on remove
  • 245bfe72a5ad net: Call net_enable_timestamp() before failure in sk_clone().
  • 412279292331 soreuseport: Clear sk_reuseport_cb before failure in sk_clone().
  • f97d19928768 amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN
  • e695cb9becbb arm64: Correct value returned by ESR_ELx_FSC_ADDRSZ_nL()
  • f5b8b8ccf9a4 pds_core: reject component parameter in legacy firmware update
  • b5fcd1da0562 wifi: mac80211: recalculate TIM when a station enters power save
  • d06fea9b85f0 iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
  • e5ebe8544df1 iommu/amd: Bound the early ACPI HID map
  • d21464d93f8b wifi: mwifiex: bound uAP association event IEs to the event buffer
  • a0980682d84d vhost-net: fix TX stall when vhost owns virtio-net header
  • 59cbe6cfa0fa wan: wanxl: Only reset hardware after BAR mapping
  • 3b1d4fc3b73e nfp: Check resource mutex allocation
  • 0f7eaeb950ad wifi: mac80211: tear down new links on vif update error path
  • d053eb7e09e1 iommu/amd: Wait for completion instead of returning early in iommu_completion_wait()
  • 76fc5604308a net: airoha: Fix DMA direction for NPU mailbox buffer
  • f112df0744e2 dpaa2-eth: put MAC endpoint device on disconnect
  • 46e3bed4b071 net: airoha: Fix potential use-after-free in airoha_ppe_deinit()
  • 26ac2d360234 dpaa2-switch: put MAC endpoint device on disconnect
  • c9165e199f56 rxrpc: fix io_thread race in rxrpc_wake_up_io_thread()
  • b78547914bee gtp: parse extension headers before reading inner protocol
  • 959104253314 rds: drop incoming messages that cross network namespace boundaries
  • 992dce02bdab bonding: fix devconf_all NULL dereference when IPv6 is disabled
  • 1bc55c29cd85 net/packet: avoid fanout hook re-registration after unregister
  • 9f4f75df77c8 netlink: specs: rt-link: convert bridge port flag attributes to u8
  • 4264dbc84ca0 net: phy: marvell: fix return code
  • 8881daaafadb Bluetooth: btusb: validate Realtek vendor event length
  • 9d208de7a8f6 regulator: mt6358: use regmap helper to read fixed LDO calibration
  • 538d862cc0db hwmon: occ: validate poll response sensor blocks
  • 2f0f66199894 ovpn: use monotonic clock for peer keepalive timeouts
  • 5b96227c0e8b ovpn: fix use after free in unlock_ovpn()
  • 47cd68e050a6 selftests/net: ovpn: fix getaddrinfo memory leak in ovpn_parse_remote()
  • c5bf6b39be23 ovpn: avoid putting unrelated P2P peer on socket release
  • 2fdd6d196c65 smb: client: validate DFS referral PathConsumed
  • d6959dd79088 hwmon: (asus-ec-sensors) add missed handle for ENOMEM
  • dd6f730be95b hwmon: (asus-ec-sensors) fix EC read intervals
  • 22e449c1dd54 hwmon: (asus-ec-sensors) fix looping over banks while reading from EC
  • d5913f97b5b6 drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook()
  • d0a57f19fe28 usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect
  • 2d5dec517b53 wifi: iwlwifi: mvm: fix read in wake packet notification handler
  • eae7fdf7d446 wifi: iwlwifi: validate payload length in iwl_pnvm_complete_fn
  • 70a6de303c9b wifi: iwlwifi: fix pointer arithmetic in iwl_add_mcc_to_tas_block_list
  • a076b0c457c7 wifi: iwlwifi: mvm: validate SAR GEO response payload size
  • cdf895bfd803 ASoC: cs35l56: Use complete_all() to signal init_completion
  • 3c26e8bb14cc ASoC: cs35l56: Fix potential probe() deadlock
  • 1ddb3e0e502a ASoC: cs35l56: Don't use devres to unregister component
  • 9153fa1ee99b ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI
  • 08433c71f159 ALSA: hda: cs35l41: validate and free ACPI mute object
  • eca9fcf9f5d8 ASoC: sun4i-codec: Set quirks.playback_only for H616 codec
  • 41ae2b7d37c3 ASoC: tas2781: bound firmware description string parsing
  • 797dc567146c btrfs: free mapping node on duplicate reloc root insert
  • 9304713b70e7 btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps
  • 39f196f64bd3 btrfs: fix u32 to s64 type conversion in dirty_metadata_bytes accounting
  • f49ff44831d5 btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8
  • 450382984335 wifi: carl9170: fix buffer overflow in rx_stream failover path
  • fab6ff91d5b8 wifi: carl9170: fix OOB read from off-by-two in TX status handler
  • 9aee949c68dc wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
  • 33b5342d2080 wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
  • eb636fbc4431 wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
  • 0177e578d7a8 firewire: net: Fix fragmented datagram reassembly
  • 51516fda914c wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET
  • 9a9b0ea72d8b wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET
  • a154ca3c441a wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()
  • 8681e5addf71 watchdog: airoha: Prevent division by zero when clock frequency is zero
  • 7d1658b066de watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
  • 305c23993e43 hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop
  • 205cff797a94 hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
  • f36e12cc8cfe hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
  • 56d2deb64483 hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
  • ec477af3a7e8 hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
  • e5394605f9a9 wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin
  • 48a69cedde73 wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
  • 593072aae7fc selftests/bpf: Keep verifier_map_ptr exercising ops pointer access
  • 938bcf99f53e selftests/bpf: Adjust verifier_map_ptr for the map's excl field
  • fe7892d46921 usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits
  • 958624d63860 Revert "drm/amd/display: Add missing kdoc for ALLM parameters"
  • 03eb7a809947 RISC-V: KVM: Serialize virtual interrupt pending state updates
  • 731acda5ba77 wifi: mwifiex: fix freeze for 60 seconds caused by request_firmware
  • 0905b3ce1deb usb: typec: ucsi: Add duplicate detection to nvidia registration path
  • fe8cde072293 usb: typec: ucsi: Detect and skip duplicate altmodes from buggy firmware
  • 67d2626827e3 USB: serial: option: add TDTECH MT5710-CN
  • 601f75671b8f USB: serial: keyspan_pda: fix data loss on receive throttling
  • cbe00048b69d USB: serial: io_edgeport: cap received transmit credits
  • c1611c6744e3 USB: serial: ftdi_sio: add support for E+H FXA291
  • 1f03658f3e9b usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer
  • dcf3e2f16443 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
  • 40c706a0224b usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
  • 12b3edca90d4 USB: gadget: fsl-udc: fix dev_printk() device
  • 66956a5a4258 USB: gadget: fsl-udc: fix device name leak on probe failure
  • e5ecfb776752 USB: gadget: snps-udc: fix device name leak on probe failure
  • 4cde0b38cc0c usb: gadget: printer: fix infinite loop in printer_read()
  • f45089eaad0a usb: gadget: f_midi: cancel pending IN work before freeing the midi object
  • e239ea91b481 usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
  • ace1a0adfc78 usb: chipidea: fix usage_count leak when autosuspend_delay is negative
  • 8eca14198c20 USB: storage: add NO_ATA_1X quirk for Longmai USB Key
  • 0950ac52426b usb: musb: omap2430: Do not put borrowed of_node in probe
  • 7714fb896ed3 usb: core: port: Deattach Type-C connector on component unbind
  • fb1b50ab6992 wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
  • 217774e143d7 usb: core: sysfs: add lock to bos_descriptors_read()
  • 5f6e7b32bd1f mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
  • a8d20ba0ab51 sctp: fix auth_hmacs array size in struct sctp_cookie
  • fed1b1ddab41 net/sched: act_tunnel_key: Defer dst_release to RCU callback
  • 51c2fcc4cd2e dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync()
  • e666af5dcc90 tcp: fix TIME_WAIT socket reference leak on PSP policy failure
  • 6875ee2bef48 accel/amdxdna: Fix use-after-free of mm_struct in job scheduler
  • f6b522033bc8 drm/i915/selftests: Fix GT PM sort comparators
  • c23abdb922c3 drm/i915/wm: clear the plane ddb_y entries on plane disable
  • f0e337e7db67 ksmbd: validate compound request size before reading StructureSize2
  • 6ecb252efa0b ksmbd: pin conn during async oplock break notification
  • 5e5f298d0af6 drm/xe/wopcm: fix WOPCM size for LNL+
  • 35ba43b54111 drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves
  • c1b19d855626 drm/xe/vf: Shadow buffer management for CCS read/write operations
  • bf293b5bcff4 drm/xe/sa: Shadow buffer support in the sub-allocator pool
  • 65129a03a801 drm/xe: Allow the caller to pass guc_buf_cache size
  • cfb66ad4aa8e can: j1939: fix lockless local-destination check
  • 3f398d45f3c7 riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus()
  • 1d9a2f01b3c4 s390/checksum: Fix csum_partial() without vector facility
  • 5b06cf93341f drm/panthor: Check debugfs GEM lock initialization
  • 250474c69bc3 bpf, sockmap: Reject unhashed UDP sockets on sockmap update
  • c3e61df6fabc powerpc/vtime: Initialize starttime at boot for native accounting
  • 5c3a1cede86f powerpc/time: Prepare to stop elapsing in dynticks-idle
  • c1bbd0a6906b powerpc/85xx: Add fsl,ifc to common device ids
  • 00ba4bf87982 can: raw: add locking for raw flags bitfield
  • 479425744b21 drm/i915/gt: use correct selftest config symbol
  • 7e08ab7a061b smb/client: handle overlapping allocated ranges in fallocate
  • cefb44c367b2 Bluetooth: hci_qca: Clear memdump state on invalid dump size
  • d5b3b484b62b Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
  • ca58ad287bfc Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
  • 83b7e67698d0 Bluetooth: hci_sync: extend conn_hash lookup critical sections
  • 57059ff14d81 Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update
  • a087ed960fce Bluetooth: qca: fix NVM tag length underflow in TLV parser
  • f4e23e661a25 ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC
  • b133f007ba02 accel/ivpu: Fix wrong register read in LNL failure diagnostics
  • 1842d45f461a ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning
  • d28920db5696 ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts
  • 678d874e6ae1 ata: sata_dwc_460ex: use platform_get_irq()
  • daa80b422ed9 ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered
  • c7a150912372 scsi: core: wake eh reliably when using scsi_schedule_eh
  • 2c77ed279c4b udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf()
  • c75a950e7735 net/iucv: take a reference on the socket found in afiucv_hs_rcv()
  • cb8be318b443 ipv4: fib: free fib_alias with kfree_rcu() on insert error path
  • c9574b8a8ede ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
  • 88f87cb4b52e cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq
  • 640a33e77f91 firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context
  • fb343716fad4 ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup
  • 7f2cb99eaf53 ASoC: cs42l43: Correct report for forced microphone jack
  • 9f393d816043 ASoC: amd: ps: replace bitwise OR with logical OR in IRQ return check
  • 3b2d32f52815 ASoC: amd: ps: fix wrong ACP version string in pci_request_regions()
  • f33ad19e3e3d ASoC: amd: ps: disable MSI on resume in ACP PCI driver
  • 4801f6690f98 ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop
  • b39b08e6bee8 firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation
  • cf5708c9d78c firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()
  • 11ac7a5e75f5 wifi: cfg80211: bound element ID read when checking non-inheritance
  • 5c342437ea44 wifi: brcmfmac: initialize SDIO data work before cleanup
  • a424985c3ef2 wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
  • 44eda4a8d1dc wifi: mac80211: avoid non-S1G AID fallback for S1G assoc
  • fbaa8c31ef94 wifi: cfg80211: reject unsupported PMSR FTM location requests
  • cfbda103aeae wifi: cfg80211: validate PMSR FTM preamble range
  • 0caf6416bfbb wifi: cfg80211: validate PMSR measurement type data
  • 0b6efde0ed97 wifi: nl80211: constrain MBSSID TX link ID range
  • f8c547e543e1 wifi: nl80211: validate nested MBSSID IE blobs
  • f649dc9c5e65 wifi: cfg80211: derive S1G beacon TSF from S1G fields
  • fb052a6e2fa8 wifi: nl80211: free RNR data on MBSSID mismatch
  • 133684982dd0 wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock
  • d38f5d868a0a wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
  • 2aa1789880fa wifi: mac80211: defer link RX stats percpu free to RCU
  • 6cda91bbb8dc wifi: libertas: fix memory leak in helper_firmware_cb()
  • 5baaa1042f71 wifi: mac80211: fix fils_discovery double free on alloc failure
  • d62b55b7c7dc wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
  • 6dc76371a9a3 wifi: mac80211_hwsim: clamp virtio RX length before skb_put
  • e67dc2b8d5ac wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()
  • f442e581a889 wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
  • 9293574ac208 wifi: cfg80211: cancel sched scan results work on unregister
  • 7acc5ed2f336 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
  • ff636d7b7cba xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()
  • d8aaf06b29f5 xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
  • 9845a35986a6 xfrm: clear mode callbacks after failed mode setup
  • 9e632a70f204 RDMA/irdma: Prevent overflows in memory contiguity checks
  • 124382a2a975 selftests/alsa: Fix memory leak in find_controls error path
  • f98ae09c727d mtd: fix double free and WARN_ON in add_mtd_device() error paths
  • fcc9d50022bc RDMA/siw: publish QP after initialization
  • e221dde026af RDMA/hns: Fix potential integer overflow in mhop hem cleanup
  • d842ef03d914 RDMA/mana_ib: initialize err for empty send WR lists
  • 14e519f93a48 RDMA/erdma: initialize ret for empty receive WR lists
  • ec675b4cdfd3 RDMA/irdma: Prevent user-triggered null deref on QP create
  • 1cd56258fe1a RDMA/irdma: Remove redundant legacy_mode checks
  • ca1c29f05274 RDMA/irdma: Prevent rereg_mr for non-mem regions
  • dbb945b80a3a RDMA/umem: Add pinned revocable dmabuf import interface
  • c4ef25de94d7 RDMA/cma: Fix hardware address comparison length in netevent callback
  • d7fc6f351c47 xfrm: reject optional IPTFS templates in outbound policies
  • 2907e9d0f05b sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx()
  • 57acd5192833 sched/ext: Avoid null ptr traversal when ->put_prev_task() is called with NULL next
  • 996c5c19d5b5 firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
  • 8edc92525178 btrfs: fallback to transaction csum tree on a commit root csum miss
  • a84ca16ce07e btrfs: use bool type for btrfs_path members used as booleans
  • 60a23d4ea169 btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()
  • 5e1b2ca6b349 btrfs: reject free space cache with more entries than pages
  • 0ac9c7d9ccfd mtd: nand: mtk-ecc: stop on ECC idle timeouts
  • fdb53a9b2607 mtd: mtdswap: remove debugfs stats file on teardown
  • 98d2d468b4fa IB/mad: Drop unmatched RMPP responses before reassembly
  • 59114e0ff6e3 firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits
  • 33e1b0d25ca0 xfrm: fix stale skb->prev after async crypto steals a GSO segment
  • eae16fbc7ce2 xfrm: propagate -EINPROGRESS from validate_xmit_xfrm()
  • 23bbb9eafec7 net: plumb drop reasons to __dev_queue_xmit()
  • 4cc4d6fb08e7 net: dropreason: add SKB_DROP_REASON_RECURSION_LIMIT
  • 4c22b4e3ff50 arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234
  • 0b9858484d09 arm64: tegra: Remove fallback compatible for GPCDMA
  • 903f2edc0477 fuse: fix writeback array overflow when max_pages is one
  • afe9cda0862a Input: ims-pcu - fix logic error in packet reset
  • d03a740e087d Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
  • 6cbed4be9a6c xprtrdma: Clear receive-side ownership pointers on release
  • 0892b427c4b8 crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin
  • 5f4de3c717d3 gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
  • ec9f66c91bff dmaengine: sh: rz-dmac: Move interrupt request after everything is set up
  • eca8b44d51fc can: bcm: track a single source interface for ANYDEV timeout/throttle ops
  • 136de17f3863 can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()
  • 6be3e1fedf03 can: bcm: fix stale rx/tx ops after device removal
  • b024c21c9066 can: bcm: add missing device refcount for CAN filter removal
  • deb6a697cce3 can: bcm: validate frame length in bcm_rx_setup() for RTR replies
  • bd46f55dec60 can: bcm: extend bcm_tx_lock usage for data and timer updates
  • 8104bcdb2612 can: bcm: fix CAN frame rx/tx statistics
  • 19b1994069dd can: bcm: add locking when updating filter and timer values
  • ec9daa8fd1b6 KVM: x86/mmu: Fix use-after-free on vendor module reload
  • 8001d2ce9d9b KVM: nVMX: Hide shadow VMCS right after VMCLEAR
  • dd50ad7935d5 KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN
  • f3477a6a4164 KVM: x86: Check for invalid/obsolete root after making MMU pages available
  • 865dfe76c150 seqlock: Allow UBSAN_ALIGNMENT to fail optimizing
  • 3958b1aeef43 seqlock: Allow KASAN to fail optimizing
  • ec46baf83082 seqlock: Cure some more scoped_seqlock() optimization fails
  • 8e39ed92d7c5 fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race
  • 89890a5fcefa drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker
  • f6410d18c1e2 netfilter: nf_tables: revert commit_mutex usage in reset path
  • 0c8a9022f4c5 netfilter: nft_quota: use atomic64_xchg for reset
  • cd968dcdec6a netfilter: nft_counter: serialize reset with spinlock
  • 55904f1a4689 selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs
  • ce01a4e5cfac bpf: Fix ld_{abs,ind} failure path analysis in subprogs
  • bffc0b27e457 platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug
View originalPermalink
How 6.18.42-xanmod1 went

6.18.41-rt-xanmod1

Changed 1
  • Expand timer_[re]arm() callbacks with a boolean return value
Fixed 19
  • Prevent UAF caused by non-leader exec() race in posix-cpu-timers
  • Avoid repeated requests to allocate WC pages in RDMA/bnxt_re
  • Initialize dpi variable to zero in RDMA/bnxt_re
  • Fix durable reconnect double-bind race in ksmbd_reopen_durable_fd
  • Handle multiple address spaces in perf callchain
  • Fix scoped_seqlock_read kernel-doc in seqlock

From XanMod Kernel

  • 93ee63dfc0db Linux 6.18.41-rt-xanmod1
  • 3e27e81ebc48 Merge branch '6.18' into 6.18-rt
  • 929ca27d531b Linux 6.18.41-xanmod1
  • 1c784dbe2a35 Merge tag 'v6.18.41' into 6.18
  • 2fe596715f84 Linux 6.18.41
  • 6a7ecc25abe6 posix-cpu-timers: Prevent UAF caused by non-leader exec() race
  • 9f7268928ac0 posix-timers: Expand timer_[re]arm() callbacks with a boolean return value
  • 44db62f5aa97 Linux 6.18.40-xanmod1
  • 8b49b49d26aa Merge tag 'v6.18.40' into 6.18
  • 221fc2f4d0ed Linux 6.18.40
  • 478c4d24193f RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
  • b87cbd4d198a RDMA/bnxt_re: Initialize dpi variable to zero
  • 81e6faa5b640 ksmbd: fix durable reconnect double-bind race in ksmbd_reopen_durable_fd
  • 1badb6866482 perf callchain: Handle multiple address spaces
  • 275eb3993094 seqlock: fix scoped_seqlock_read kernel-doc
  • 453cb79a1564 perf inject: With --convert-callchain ignore the dummy event for dwarf stacks
  • 2764d031efd6 PCI: Fix Resizable BAR restore order
  • 2fb74141ec54 PCI: Fix BAR resize rollback path overwriting ret
  • 7425e7d82cb9 perf symbol: Fix ENOENT case for filename__read_build_id
  • a888f3d5970f pinctrl: airoha: fix pinctrl function mismatch issue
  • 267fdd9b6530 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
  • 779480ea7955 iommufd: Move vevent memory allocation outside spinlock
  • 73b5d5cb1f5a iommufd: Propagate allocation failure in iommufd_veventq_deliver_fetch()
  • ea7a76d7d614 KVM: arm64: nv: Re-translate VNCR before injecting abort
  • 459adfc6cd35 KVM: arm64: Deduplicate ASID retrieval code
  • 9d360fb820a3 samples/damon/mtier: fail early if address range parameters are invalid
  • ec976851ad93 mm/damon/core: trace esz at first setup
  • 3b91c35961fa mm/damon/core: always put unsuccessfully committed target pids
  • ba37cd4d8a75 KVM: arm64: Fix propagation of TLBI level in kvm_pgtable_stage2_relax_perms()
  • 19d9996435db KVM: arm64: Ensure level is always initialized when relaxing perms
  • c3a3d3986719 btrfs: fix incorrect buffered IO fallback for append direct writes
  • 998ee7f01ecf btrfs: fix false IO failure after falling back to buffered write
  • a4497a122e27 crypto: qat - fix restarting state leak on allocation failure
  • 6c78081d047c btrfs: remove folio parameter from ordered io related functions
  • 1a648c50a505 btrfs: replace for_each_set_bit() with for_each_set_bitmap()
  • 99d4ae3fbb5b btrfs: concentrate the error handling of submit_one_sector()
  • 382fd8004cc6 crypto: atmel-sha204a - fail on hwrng registration error in probe path
  • 952db4b985c7 usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile
  • 69faa3779250 usb: gadget: f_fs: initialize reset_work at allocation time
  • 8a2fdbf92cdc functionfs: use spinlock for FFS_DEACTIVATED/FFS_CLOSING transitions
  • 5fb0b09180a0 functionfs: switch to simple_remove_by_name()
  • 4744f07f6bb7 functionfs: don't bother with ffs->ref in ffs_data_{opened,closed}()
  • 901c036cf625 functionfs: don't abuse ffs_data_closed() on fs shutdown
  • c3e686025210 new helper: simple_remove_by_name()
  • 509b51327320 usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()
  • b78826a65799 usb: atm: ueagle-atm: remove function entry/exit debug messages
  • 6e5ef54b884f usb: atm: ueagle-atm: use dev_dbg() for 'device found' message
  • 41a4e80d5af0 usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()
  • e534790c4c27 usb: dwc3: Support USB3340x ULPI PHY high-speed negotiation.
  • bce232923aa9 xfs: use bio_reuse in the zone GC code
  • adadb181ad42 xfs: only log freed extents for the current RTG in zoned growfs
  • 47c0e0743302 xfs: add a xfs_groups_to_rfsbs helper
  • 57454944737f bpf: Allow LPM map access from sleepable BPF programs
  • 8fccaeeb9e9c bpf: Consistently use bpf_rcu_lock_held() everywhere
  • 0b92ad64d6e4 bpf: Keep dynamic inner array lookups nullable
  • c447be8d88c3 bpf: Introduce struct bpf_map_desc in verifier
  • dccb3c557879 bpf: Consistently use reg_state() for register access in the verifier
  • 60eed4467429 xfs: initialize iomap->flags earlier in xfs_bmbt_to_iomap
  • 607217f7ad41 hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length
  • 7676ea09beb5 hfs/hfsplus: prevent getting negative values of offset/length
  • f9b4b03ccc9c proc: protect ptrace_may_access() with exec_update_lock (part 1)
  • 07bf18dc63f7 seqlock: Change do_task_stat() to use scoped_seqlock_read()
  • c897fd63762e seqlock: Introduce scoped_seqlock_read()
  • 497c6bae5167 proc: protect ptrace_may_access() with exec_update_lock (FD links)
  • 903d78e5aca7 proc: rename proc_setattr to proc_nochmod_setattr
  • b56400364aed ksmbd: validate NTLMv2 response before updating session key
  • 74c2f0ffb81c ksmbd: Use HMAC-MD5 library for NTLMv2
  • 51c5f7e84cfe ksmbd: Use HMAC-SHA256 library for message signing and key generation
  • bd27d9504d20 ksmbd: Use SHA-512 library for SMB3.1.1 preauth hash
  • 427faaa52b0b ksmbd: track the connection owning a byte-range lock
  • 6a37bc484f12 ksmbd: centralize ksmbd_conn final release to plug transport leak
  • c7c884a1305a ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
  • e205f3e7e8c3 ksmbd: use opener credentials for FSCTL mutations
  • 90a93fb3230c cifs: SMB1 split: Add some #includes
  • ff943e1f3d31 cifs: SMB1 split: Rename cifstransport.c
  • 36da806f7fba Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()
  • 6d0eeebe22ba Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister
  • ef382a6baf0a media: nxp: imx8-isi: Fix use-after-free on remove
  • 4278953ff0cd media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code
  • 49cd5ac6de8d crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()
  • 4b51ee8a40fe staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()
  • 5d76bc296bb5 staging: rtl8723bs: fix spaces around binary operators
  • 48323ebaeeee staging: rtl8723bs: core: move constants to right side in comparison
  • 73cc54326de4 PCI: Skip Resizable BAR restore on read error
  • f33837a75447 PCI: Move Resizable BAR code to rebar.c
  • 2242c75b6328 PCI: Add kerneldoc for pci_resize_resource()
  • 4b5322f0002a PCI: Fix restoring BARs on BAR resize rollback path
  • c18646165f21 PCI: Free saved list without holding pci_bus_sem
  • 534f20cdddc3 PCI: Try BAR resize even when no window was released
  • dbb1d8507dd9 PCI: Change pci_dev variable from 'bridge' to 'dev'
  • 0d1c263e6fd7 PCI/IOV: Adjust ->barsz[] when changing BAR size
  • 0dfad346c293 PCI: imx6: Configure REF_USE_PAD before PHY reset for i.MX95
  • e53d54b92f0c PCI: imx6: Fix reference clock source selection for i.MX95
  • 1228926e1e4d binder: cache secctx size before release zeroes it
  • 79ac87bb1a4c binder: Use LIST_HEAD() to initialize on stack list head
  • 7ed120b1a007 vfio/mlx5: Fix racy bitfields and tighten struct layout
  • f8272331da87 ALSA: hda/tas2781: Cancel async firmware request at unbind
  • 6438d0707087 firmware_loader: Add cancel helper for async requests
  • 1ed7ff33cfc8 ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417
  • ad5c5bdb0f58 ALSA: scarlett2: Allow selecting config_set by firmware version
  • 2745574697ee iio: hid-sensor-rotation: Fix stale or zero output when reading raw values
  • 7f680924c5c2 ACPI: NFIT: core: Fix possible deadlock and missing notifications
  • cf5f93228e7a ACPI: NFIT: core: Use devm_acpi_install_notify_handler()
  • d57d2aae87b2 ACPI: bus: Introduce devm_acpi_install_notify_handler()
  • 34f4d0e4e506 ACPI: driver: Check ACPI_COMPANION() against NULL during probe
  • 3b2628f7682a ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup
  • 83f29da85dc9 crypto: xilinx-trng - Remove crypto_rng interface
  • f84c0bae0e8d mmc: sdhci-esdhc-imx: fix resume error handling
  • 174dc8103ab7 mmc: sdhci-esdhc-imx: make non-fatal errors non-blocking in suspend
  • 5b8f11cbe8ad mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend
  • 4f96903e2fd2 mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt
  • aa276aa6cbfb mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore
  • 52990f6b5752 mmc: sdhci-esdhc-imx: restore DLL override for DDR modes on resume
  • eefcd3ca245c mmc: sdhci-esdhc-imx: remove unnecessary mmc_card_wake_sdio_irq check for tuning save/restore
  • c02237966c19 mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe() method
  • 8d94498cc445 mmc: block: fix RPMB device unregister ordering
  • cf7258f57d18 mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout
  • 4b5de4007e5b mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout
  • de2bc884d887 mtd: rawnand: fsl_ifc: return errors for failed page reads
  • bf9848a22a8e mmc: vub300: defer reset until cmd_mutex is unlocked
  • 04ebd3766861 mtd: mchp23k256: use SPI match data for chip caps
  • ac2d9f6b4f90 mtd: onenand: samsung: report DMA completion timeouts
  • a59cfa165aee wifi: mwifiex: fix permanently busy scans after multiple roam iterations
  • b8df3a993f69 wifi: mac80211: free ack status frame on TX header build failure
  • 90576bd6921a wifi: ieee80211: validate MLE common info length
  • 584657c5fc58 wifi: cfg80211: validate EHT MLE before MLD ID read
  • 3c1e92f75e11 powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()
  • 82753ac86cb3 reset: sunxi: fix memory region leak on ioremap failure
  • 3fb7edd2018b ipvs: reload ip header after head reallocation
  • d4ec18f48ce7 ipvs: fix more places with wrong ipv6 transport offsets
  • 39151f0708c8 memstick: ms_block: reject a card that reports too many blocks
  • a75d2b5249e3 macsec: fix promiscuity refcount leak in macsec_dev_open()
  • fd701fc0d065 llc: fix SAP refcount leak when creating incoming sockets
  • 6744ab60dfac Bluetooth: btrtl: validate firmware patch bounds
  • dbd14f736be0 net: openvswitch: reject oversized nested action attrs
  • 6926d13865aa regulator: ltc3676: Fix incorrect IRQSTAT bit offsets
  • 688bd4c6144d riscv: vdso: Do not use LTO for the vDSO
  • 55b26abb1fa1 wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
  • bdc0b8bfdc14 wifi: mac80211: fix memory leak in ieee80211_register_hw()
  • 65446b85595a wifi: mwifiex: fix roaming to different channel in host_mlme mode
  • 816559409e34 wifi: rt2x00: avoid full teardown before work setup in probe
  • 262da8b6ea03 net/mlx5: free mlx5_st_idx_data on final dealloc
  • 9b8df4da2cf7 powerpc/pseries: fix memory leak on krealloc failure in papr_init
  • afa0db5322c5 mmc: sdhci-esdhc-imx: restore pinctrl before restoring ios timing on resume
  • d94160a5d1ac selftests/landlock: Fix screwed up pointers in the scoped_signal_test
  • ba481c0b5376 selftests/landlock: Skip scoped_signal subtest with MSG_OOB if not available
  • 4ff3960f3527 pmdomain: imx: Fix i.MX8MP VC8000E power up sequence
  • 9a0464fcfae4 pmdomain: imx: Fix i.MX8MP power notifier
  • c844b7d9a958 cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed
  • 8131a91fe2de selftests/rseq: Fix a building error for riscv arch
  • 3dfec7490f3a s390/mm: Fix type mismatch in get_align_mask().
  • c6b4d454865a s390/diag: Add missing array_index_nospec() call to memtop_get_page_count()
  • fad36954b295 tracing/osnoise: Call synchronize_rcu() when unregistering
  • eadd0c2c76ae riscv: Prevent NULL pointer dereference in machine_kexec_prepare()
  • 38cc4867540a drbd: reject data replies with an out-of-range payload size
  • 91ec52dd2a5d ata: libata-core: Allow capacity transition to zero for locked drives
  • 7a9a69641b68 ata: libata-core: Skip HPA resize for locked drives
  • 52007bfdce53 fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
  • 1155a9d0a2e0 fs/resctrl: Free mon_data structures on rdt_get_tree() failure
  • ccdf1770a4ba cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable()
  • 5f5783c7806f arm64: smp: Fix hot-unplug tearing by forcing unregistration
  • 26b131b2d5b5 net: macb: drop in-flight Tx SKBs on close
  • b2f426a9a228 dibs: loopback: validate offset and size in move_data()
  • 2cf10d042562 macsec: don't read an unset MAC header in macsec_encrypt()
  • 83fb4c2c5344 ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
  • 247d055504dc ipvs: use parsed transport offset in SCTP state lookup
  • 61a7ff4a6200 llc: fix SAP refcount leak in llc_ui_autobind()
  • 685fb410d90e selftests: net: make busywait timeout clock portable
  • 5df30f05db96 octeontx2-pf: fix SQB pointer leak on init failure
  • 77caf2d6eba7 mac802154: remove interfaces with RCU list deletion
  • f0745496f7c1 s390/monwriter: Reject buffer reuse with different data length
  • a5a367756926 irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure
  • 018d7ad26cb8 mm/compaction: handle free_pages_prepare() properly in compaction_free()
  • 2faf0198168d riscv: probes: save original sp in rethook trampoline
  • d8d4fa0c4f81 hwmon: (asus_atk0110) Check package count before accessing element
  • 07f5eb6d268a net: wwan: iosm: bound device offsets in the MUX downlink decoder
  • 1286a4156333 ata: pata_pxa: Fix DMA channel leak on probe error
  • 1dce4f4bb3c1 net/mlx5: HWS, fix matcher leak on resize target setup failure
  • 82fc886e244c orangefs: keep the readdir entry size 64-bit in fill_from_part()
  • 2c76c01a505c tracing/probes: Fix double addition of offset for @+FOFFSET
  • b4427ee3667c hwmon: (max1619) add missing 'select REGMAP' to Kconfig
  • 6c52226072a3 fhandle: reject detached mounts in capable_wrt_mount()
  • e2b7ee61989f net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked
  • 5889064919a1 net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked
  • 99a6f37b113c net: lan743x: Initialize eth_syslock spinlock before use
  • ac58088d70b8 fsl/fman: Free init resources on KeyGen failure in fman_init()
  • f0aad157576d hwmon: (occ) unregister sysfs devices outside occ lock
  • 715cce38424f net: liquidio: fix BAR resource leak on PF number failure
  • 664480021f6a hwmon: (w83793) remove vrm sysfs file on probe failure
  • c6c990f7208c hwmon: (w83627hf) remove VID sysfs files on error and remove
  • 8dc6c7e8c967 rtc: mpfs: fix counter upload completion condition
  • 6e21d1253ef1 rtc: renesas-rtca3: Fix PIE clear polling condition in alarm setup error path
  • 6c98ccdb9a09 bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()
  • f5c506596302 ipmi: fix refcount leak in i_ipmi_request()
  • a66d45e0ce6d espintcp: use sk_msg_free_partial to fix partial send
  • ddbb6e3dc9bb ipmi: Fix user refcount underflow in event delivery
  • a65f49b6f7ec LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()
  • 20ac8131f8c9 LoongArch: Fix nr passing in set_direct_map_valid_noflush()
  • 612cda6630f2 pwm: rzg2l-gpt: Fix period_ticks type from u32 to u64
  • 4b73889941b9 selftests/bpf: Add simple strscpy() implementation
  • da7f17c2d5bb KVM: TDX: Account all non-transient page allocations for per-TD structures
  • d0cc2c74060b drm/xe/userptr: Stub notifier_lock helpers when DRM_GPUSVM=n
  • 6cec36c795c0 net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants
  • 55da782eb454 platform/x86/amd/pmc: Avoid logging "(null)" for DMI values
  • 35267819b250 gve: fix header buffer corruption with header-split and HW-GRO
  • 2059c28bd725 ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit
  • cb5cca1d2a90 ieee802154: ca8210: fix cas_ctl leak on spi_async failure
  • 314f21c9dd0d ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation
  • 1905ebabe638 ieee802154: admin-gate legacy LLSEC dump operations
  • 19c148cb82d1 octeontx2-af: Free BPID bitmap on setup failure
  • 234cd54fc500 net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink
  • 03d8843b143e net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
  • 68cadc3698c7 net: ipip: require CAP_NET_ADMIN in the device netns for changelink
  • 9571af2eec80 net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
  • 0b2f9c908f93 net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
  • 6596baf80411 net: ena: clean up XDP TX queues when regular TX setup fails
  • ab625256882e selftests: net: fix file owner for broadcast_ether_dst test
  • b3d835407846 net/sched: act_ct: preserve tc_skb_cb across defragmentation
  • 3f85fcd520aa net: ixp4xx_hss: fix duplicate HDLC netdev allocation
  • e89b8829693e net: wwan: t7xx: destroy DMA pool on CLDMA late init failure
  • 121c5f31c3fb net: ethernet: ti: icssg: guard PA stat lookups
  • 3118e97dae53 net: sit: require CAP_NET_ADMIN in the device netns for changelink
  • 5d7bd8790309 gpios: palmas: add .get_direction() op
  • d3b9026ef78d gpio: mt7621: avoid corruption of shared interrupt trigger state
  • 4e16bc75c750 gpio-f7188x: Add support for NCT6126D version B
  • b6e040b5143c gpio: mt7621: be sure IRQ domain is created before exposing GPIO chips
  • ac761e66708d gpio: tegra: do not call pinctrl for GPIO direction
  • 0630f2c3c16c gpio: mt7621: more robust management of IRQ domain teardown
  • 6cb15b81ff54 cpu: hotplug: Bound hotplug states sysfs output
  • f77117530fc3 cpu: hotplug: Preserve per instance callback errors
  • afd147e59b32 selftests/ftrace: Drop invalid top-level local in test_ownership
  • ea6a188ee805 posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()
  • 633cadbc0b83 locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
  • fcff712d0e3d wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
  • b33ac2d39953 tracing/user_events: Fix use-after-free in user_event_mm_dup()
  • ed3cc4218070 net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete
  • 0e8115a7ed9a Input: ims-pcu - fix type confusion in CDC union descriptor parsing
  • f516cba88bf9 Input: ims-pcu - fix race condition in reset_device sysfs callback
  • 383934c249a9 Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing
  • 9c964fc9507a Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging
  • 99c428d7ef64 Input: ims-pcu - fix firmware leak in async update
  • 05ac85da1219 Input: ims-pcu - fix DMA mapping violation in line setup
  • f28c5cabb2df Input: ims-pcu - add response length checks
  • c8d3d83f2eaa Input: ims-pcu - validate control endpoint type
  • 6329d1af316a Input: ims-pcu - release data interface on disconnect
  • 87e2f89dea07 Input: ims-pcu - only expose sysfs attributes on control interface
  • 6aacc18004b1 Input: ims-pcu - fix use-after-free and double-free in disconnect
  • df87532e9212 scsi: elx: efct: Fix I/O leak on unsupported additional CDB
  • 9b871369cbb4 scsi: elx: efct: Fix refcount leak in efct_hw_io_abort()
  • cb7bdae7fba4 scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
  • 004ccd2d3b4a scsi: target: Bound PR-OUT TransportID parsing to the received buffer
  • f1516c56ac54 scsi: xen: scsiback: Free unsubmitted command instead of double-putting it
  • 255fb7b0cdc9 scsi: xen: scsiback: Free the command tag on the TMR submit-failure path
  • d0a8a6660d58 scsi: sg: Report request-table problems when any status is set
  • ed0849797782 scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()
  • d495b403d5b3 scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path
  • 257321a1c036 accel/ivpu: Reject firmware log with size smaller than header
  • 4e370b528962 accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap()
  • 7aa8f3dba534 dma-fence: Make dma_fence_dedup_array() robust against 0-count input
  • 089e05b644d5 dm-verity: make error counter atomic
  • c8d743bb0e98 dm-verity: increase sprintf buffer size
  • f15eaa3801f2 dm-verity: fix a possible NULL pointer dereference
  • 2a0858cba1da dm-verity: avoid double increment of &use_bh_wq_enabled
  • 5dfd80426352 dm-integrity: don't increment hash_offset twice
  • aa5113e7155f dm-integrity: fix a bug if the bio is out of limits
  • 0c4e9bb1d410 dm-integrity: fix leaking uninitialized kernel memory
  • 92e3c93d60be dm_early_create: fix freeing used table on dm_resume failure
  • ee458c3c1834 dm-stats: fix merge accounting
  • 461d36b5ddaf dm-stats: fix dm_jiffies_to_msec64
  • 1247615aadb7 dm-pcache: reject option groups without values
  • e0b0163a6575 dm-log: fix a bitset_size overflow on 32bit machines
  • d61c12573ed9 dm-ioctl: fix a possible overflow in list_version_get_info
  • 021dab70eb37 dm-bufio: fix wrong count calculation in dm_bufio_issue_discard
  • 1fcb5e29dd7a dm era: fix out-of-bounds memory access for non-zero start sector
  • 7f76245960a3 dm thin metadata: fix metadata snapshot consistency on commit failure
  • ac2136dc4441 dm thin metadata: fix superblock refcount leak on snapshot shadow failure
  • 8a3c44a00317 net: sparx5: unregister blocking notifier on init failure
  • ffd17a393921 block: fix IORING_URING_CMD_REISSUE flags check in blkdev_uring_cmd
  • 2977b5fe401c block: fix race in blk_time_get_ns() returning 0
  • af382ffca93e block: remove redundant GD_NEED_PART_SCAN in add_disk_final()
  • 0b6252afcd19 bpf: Add missing access_ok call to copy_user_syms
  • c4f626ddf235 bpf,fork: wipe ->bpf_storage before bailouts that access it
  • 0993dc5fc619 bpf: Reset register bounds before narrowing retval range in check_mem_access()
  • b06a4a397ac8 can: bcm: add missing rcu list annotations and operations
  • 35f0ac19efb1 can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure
  • cd830e0bc25e can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF
  • 37beb16e08ca can: isotp: serialize TX state transitions under so->rx_lock
  • 7bef39ba76eb can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER
  • b88a51130877 can: isotp: use unconditional synchronize_rcu() in isotp_release()
  • 765ba1c91823 can: esd_usb: kill anchored URBs before freeing netdevs
  • 5e4c8e08ce95 netdev-genl: report NAPI thread PID in the caller's pid namespace
  • 26355295ce21 nvmet: fix refcount leak in nvmet_sq_create()
  • 2944113ad5fb nvmet-rdma: handle inline data with a nonzero offset
  • 2eaa3ad45014 nvmet-auth: reject short AUTH_RECEIVE buffers
  • 59cef6abc924 nvme-apple: Prevent shared tags across queues on Apple A11
  • 0ffc032294a2 NFS: Charge unstable writes by request size, not folio size
  • ebe0a55d954f sctp: validate STALE_COOKIE cause length before reading staleness
  • d44b828eb551 spi: uniphier: Fix completion initialization order before devm_request_irq()
  • 9b092f9e6b34 time: Fix off-by-one in compat settimeofday() usec validation
  • ada4b9a5087e tpm: Make the TPM character devices non-seekable
  • 95bdf3950d66 tpm: fix event_size output in tpm1_binary_bios_measurements_show
  • 8ca2a19a987a xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink
  • e0f688ccb20f xfrm: use compat translator only for u64 alignment mismatch
  • 5b0c4c916f20 xfrm: nat_keepalive: avoid double free on send error
  • 16d3ccdabb8d xen/gntdev: fix error handling in ioctl
  • e497fef9ad7e ufs: core: tracing: Do not dereference pointers in TP_printk()
  • 0ced34b4bbc0 tcp: Decrement tcp_md5_needed static branch
  • 33a1bee41362 tcp: defer md5sig_info kfree past RCU grace period in tcp_connect
  • bccae122dab8 ice: fix ice_init_link() error return preventing probe
  • 8bd84316bbaf i2c: spacemit: fix spurious IRQ handling returning IRQ_HANDLED
  • e6a395a71f46 i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource()
  • 2f3f471a448a i2c: mediatek: fix WRRD for SoCs without auto_restart option
  • 5d3240f42a66 i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ)
  • 6d2c973926d0 i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
  • 500716a007b2 hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig
  • 1dcd7565e590 hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig
  • 3cd6f93f3d59 ksmbd: fix integer overflow in set_file_allocation_info()
  • 6cc151835736 smb: client: use kvzalloc() for megabyte buffer in simple fallocate
  • fe623f9515bb pkey: Move keytype check from pkey api to handler
  • eafc5aca7156 platform/x86/amd/pmc: Don't log during intermediate wakeups
  • e628d9169f9e platform/x86/amd/pmc: Add delay_suspend module parameter
  • 27d16a19ae74 platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops
  • d8bc45c4c1a4 platform/x86/amd/pmc: Check for intermediate wakeup in function
  • cea03d67db3a platform/x86: ISST: Restore SST-PP control to all domains
  • 1e41ca4a7fba platform/x86: dell-laptop: fix missing cleanups in init error path
  • ddbc4a8a4fe2 dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK
  • 7926c1e4be86 dmaengine: tegra: Fix burst size calculation
  • 933654508b2b sunrpc: fix uninitialized xprt_create_args structure
  • 934d1cd40e28 tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt
  • ba33b4f9d342 tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat()
  • 781f28bd982c tpm: restore timeout for key creation commands
  • 36ca587f55a2 irqchip/crossbar: Use correct index in crossbar_domain_free()
  • 0d078152fcab taskstats: retain dead thread stats in TGID queries
  • 9ac007affa77 mtd: maps: vmu-flash: fix NULL pointer dereference in initialization
  • 3fac46068fe4 openrisc: Fix jump_label smp syncing
  • ff7bcc9d71bf mtd: rawnand: Pause continuous reads at block boundaries
  • 0fd20c1905ab mtd: spi-nor: spansion: use die erase for multi-die devices only
  • c0806df5cf80 mtd: spi-nor: swp: Improve locking user experience
  • 433e5e70cdc1 s390/pkey: Check length in pkey_pckmo handler implementation
  • 693bf91d4db1 s390/pkey: Check length in PKEY_VERIFYPROTK ioctl
  • c9ef79e34bc1 fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header()
  • e5824d5b841d net: thunderbolt: Fix frags[] overflow by bounding frame_count
  • fc74244e0cc2 bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path
  • 3ebe0ee6527e bus: mhi: host: pci_generic: Fix the physical function check
  • 012683accbb7 fpga: dfl: add bounds check in dfh_get_param_size()
  • 2174c68f623b ocfs2: reject non-inline dinodes with i_size and zero i_clusters
  • 5e512d370a01 ocfs2: reject dinodes whose i_rdev disagrees with the file type
  • 4db3b6a2a8ec ocfs2: reject dinodes with non-canonical i_mode type
  • 499714de42ab ocfs2: add journal NULL check in ocfs2_checkpoint_inode()
  • 671889c553ea ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec
  • bd73971fad89 ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits
  • d5d5a21fb33c ocfs2: avoid moving extents to occupied clusters
  • 4bbfcf9c7e46 mtd: rawnand: fix condition in 'nand_select_target()'
  • a8874c34c4a9 net/9p: fix infinite loop in p9_client_rpc on fatal signal
  • ace3a0c839f3 mtd: rawnand: pl353: fix probe resource allocation
  • b6337e3687d3 ocfs2: use kzalloc for quota recovery bitmap allocation
  • bf53557a96d4 openrisc: Add full instruction cache invalidate functions
  • 8d263bae573d scsi: sas: Skip opt_sectors when DMA reports no real optimization hint
  • 83405848e403 scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished()
  • a7bbf83dfebd power: supply: bq257xx: Fix VSYSMIN clamping logic
  • 8d610017c992 9p: skip nlink update in cacheless mode to fix WARN_ON
  • d8dcbbfa0d69 mtd: slram: remove failed entries from the device list
  • 4e4beef747c6 kcov: use WRITE_ONCE() for selftest mode stores
  • da5234df0941 mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE
  • 749e2051da3b powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors
  • 07ed8b178548 fs/proc: fix KPF_KSM reported for all anonymous pages
  • b6a6fb6803d5 proc: only bump parent nlink when registering directories
  • 4d67bdef35c3 fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry()
  • 43b987ed35be fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()
  • 40a04601a3f6 mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error
  • f18c561eb9c5 mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs()
  • f322955d9a1c riscv: cacheinfo: Fix node reference leak in populate_cache_leaves
  • 1caee6e084a9 mips: sched: Fix CPUMASK_OFFSTACK memory corruption
  • bd2e9be9ebb6 selftests/landlock: Test SCOPE_SIGNAL on the SIGIO/fowner pgid path
  • 193e6471e985 power: supply: charger-manager: fix refcount leak in is_full_charged()
  • 1f18aac26372 landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path
  • ff05a98150eb ntfs3: fix out-of-bounds read in decompress_lznt
  • f3624cc06919 ntfs3: validate split-point offset in indx_insert_into_buffer
  • aaa1f956c0fc ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head
  • 0fad25687d4d ntfs3: cap RESTART_TABLE free-chain walker at rt->used
  • be306b8d9143 fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}
  • 908c9243ba30 fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
  • 7adb38279812 fs/ntfs3: validate lcns_follow in log_replay conversion
  • 50b5e83384e7 fs/ntfs3: bound attr_off in UpdateResidentValue against data_off
  • d240cd98f5f7 fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass
  • 09fddd52c1b0 fs/ntfs3: bound DeleteIndexEntryAllocation memmove length
  • ccd6b7079873 fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename
  • 640627f07c79 mm/damon/core: make charge_addr_from aware of end-address exclusivity
  • 722e6c54bde6 mm/memory_hotplug: fix incorrect altmap passing in error path
  • 1697d253f51c mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch
  • 9227b387eee5 power: supply: max17042: fix OF node reference imbalance
  • a3d81de44123 power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak
  • a39d281f207b mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages
  • d3fd2d358df0 MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf()
  • 11a3bc25f2c3 MIPS: ip22-gio: fix device reference leak in probe
  • 2c551f14f55e MIPS: ip22-gio: fix kfree() of static object
  • 620a37ea7d62 MIPS: ip22-gio: fix gio device memory leak
  • 51aad3d89a2d remoteproc: qcom: Fix leak when custom dump_segments addition fails
  • 69e18135e2a0 SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
  • 46d59ff42182 lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure
  • 1161c4b5bd00 lockd: Plug nlm_file leak when nlm_do_fopen() fails
  • 66014ab165cb sunrpc: harden rq_procinfo lifecycle to prevent double-free
  • 65b23bec1fca sunrpc: wait for in-flight TLS handshake callback when cancel loses race
  • 3f9ee75a97a7 sunrpc: pin svc_xprt across the asynchronous TLS handshake callback
  • 30d490bb2c4c nvdimm/btt: Free arena sub-allocations on discover_arenas() error path
  • f4ca396bdd60 nvdimm/btt: Free arenas on btt_init() error paths
  • 78955fdce8ff jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit()
  • 7199c78c3a3e Bluetooth: SCO: hold sk properly in sco_conn_ready
  • 77eb0cf57009 Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready
  • 96dd35f1942c HID: playstation: validate num_touch_reports in DualShock 4 reports
  • 88ba84546850 mfd: tps6586x: Fix OF node refcount
  • d8e2f3e1bc20 cifs: invalidate cfid on unlink/rename/rmdir
  • 3256c05d5a9d batman-adv: tt: prevent TVLV OOB check overflow
  • d2b657c9653f batman-adv: mcast: avoid OOB read of num_dests header
  • a90f4fff9025 batman-adv: frag: fix primary_if leak on failed linearization
  • c945f6007e78 batman-adv: clean untagged VLAN on netdev registration failure
  • 8f54162e07d3 batman-adv: frag: free unfragmentable packet
  • 2c989ab8e205 batman-adv: fix VLAN priority offset
  • 6a65ac8a81e9 batman-adv: tt: avoid request storms during pending request
  • ee878decf9e5 batman-adv: dat: fix tie-break for candidate selection
  • 9e16b6751a82 batman-adv: ensure minimal ethernet header on TX
  • 8f76277d0217 batman-adv: dat: ensure accessible eth_hdr proto field
  • e5e18886aadd batman-adv: bla: reacquire gw address after skb realloc
  • 3b4c70c40f2e batman-adv: dat: acquire ARP hw source only after skb realloc
  • b8afcf799b2c batman-adv: access unicast_ttvn skb->data only after skb realloc
  • 85a71a81854e batman-adv: retrieve ethhdr after potential skb realloc on RX
  • e6b43acd34b2 batman-adv: gw: acquire ethernet header only after skb realloc
  • fa1ebae4206e s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()
  • 8514585aa955 cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF()
  • 221ee479a49f cpufreq: schedutil: Fix uncleared need_freq_update on the .adjust_perf() path
  • 5ab0eba9c881 perf/x86/amd/lbr: Fix kernel address leakage
  • 046f6244da9b perf/x86/amd/brs: Fix kernel address leakage
  • 394e2bdf7594 x86/boot: Reject too long acpi_rsdp= values
  • f7c67c97b37c x86/boot: Validate console=uart8250 baud rate to fix early boot hang
  • 1a1d6e3ef6cf x86/video: Only fall back to vga_default_device() without screen info
  • 19ffeb30fdfc tools/power/x86/intel-speed-select: Harden daemon pidfile open
  • 16a42c88c466 mfd: sm501: Fix reference leak on failed device registration
  • 6dd51d84a950 leds: uleds: Fix potential buffer overread
  • 3a134c3fb5f0 selinux: fix incorrect execmem checks on overlayfs
  • d61a80b17254 selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()
  • fc633a598206 selinux: check connect-related permissions on TCP Fast Open
  • e9cdf741ffcb soc: fsl: qe: panic on ioremap() failure in qe_reset()
  • c6854d9f4e1b soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy
  • c4d6442ac3ed gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path
  • 1c4f67c89fd2 netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
  • 679ced28a9dc netfilter: xt_nat: reject unsupported target families
  • b2dbbedfa935 netfilter: ecache: fix inverted time_after() check
  • 3cd9a5792cbe netfilter: nf_conncount: fix zone comparison in tuple dedup
  • a58230f3a7c4 netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag
  • 2bcf2c5052fb netfilter: nf_nat_sip: reload possible stale data pointer
  • 02b6b0e892ae netfilter: nft_set_pipapo: don't leak bad clone into future transaction
  • 0ca505346c5e netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst
  • 07f9ddbf5e79 netfilter: xt_cluster: reject template conntracks in hash match
  • a1b672a3b537 netfilter: nfnl_cthelper: apply per-class values when updating policies
  • aff589556ed7 netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
  • ca028334343a ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback
  • e42d8322b67f ASoC: mediatek: mt8183: Release reserved memory on cleanup
  • 4b068759d308 ASoC: mediatek: mt8183: Check runtime resume during probe
  • 51c367230e30 ASoC: mediatek: mt8192: Release reserved memory on cleanup
  • e0f276f1918a ASoC: mediatek: mt8192: Check runtime resume during probe
  • d3abaedf6a58 ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control
  • 121577383b5c ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
  • 4ebe2c3a7db6 fbdev: tridentfb: fix potential memory leak in trident_pci_probe()
  • 009a8514745b fbdev: nvidia: fix potential memory leak in nvidiafb_probe()
  • 58bc18e03481 fbdev: vesafb: fix memory leak in vesafb_probe()
  • d81860691e4c fbdev: carminefb: fix potential memory leak in alloc_carmine_fb()
  • e1ca9b8559e0 fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe()
  • 12fe6a56506e fbdev: uvesafb: fix potential memory leak in uvesafb_probe()
  • ad54698255a4 fbdev: s3fb: fix potential memory leak in s3_pci_probe()
  • 146b708bc75f fbdev: i740fb: fix potential memory leak in i740fb_probe()
  • c2c795a320e7 fbdev: radeon: fix potential memory leak in radeonfb_pci_register()
  • febb5b4f67ac fbdev: efifb: fix memory leak in efifb_probe()
  • 9423e1f10527 fbdev: sm712: Fix operator precedence in big_swap macro
  • d684ce2db92b fbdev: hecubafb: fix potential memory leak in hecubafb_probe()
  • e8c9aae8c950 fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe()
  • 6854cf33dddb fbdev: metronomefb: fix potential memory leak in metronomefb_probe()
  • d5436e18e4fc KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory
  • 4ead4def0465 KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN
  • 5c50db5bcbb9 KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR
  • 884b44256041 KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
  • 09f35145f3a4 KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions
  • 5000bcae71c8 KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2
  • 7099e7148f81 KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers
  • 7996013b8568 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state
  • d1379888cc42 KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails
  • 97542f15dc4c KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
  • ba06690b28be KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs
  • df72596278b0 KVM: s390: pci: Fix handling of AIF enable without AISB
  • d19dca8194eb KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling
  • 79fdd2aa774e KVM: arm64: vgic: Check the interrupt is still ours before migrating it
  • 5fb75c527295 KVM: s390: pci: Fix GISC refcount leak on AIF enable failure
  • 9f8eaef40e95 powerpc/pseries/Kconfig: Enable CONFIG_VPA_PMU to be used with KVM
  • 33d79ad6eced LoongArch: KVM: Return full old CSR value from kvm_emu_xchg_csr()
  • f3efcef6648b LoongArch: KVM: Fix FPU register width with user access API
  • 45f2e6505fcf LoongArch: KVM: Check the return values for put_user()
  • efe27b19a15c LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt()
  • 199b570d7fca LoongArch: KVM: Validate irqchip index in irqfd routing
  • 1ee200a1764f ARM: dts: stm32: stm32mp15x-mecio1-io: Move expander gpio-line-names to board files
  • f550bf32b9a0 ARM: dts: stm32: stm32mp15x-mecio1-io: Fix expander gpio line typo
  • 7da4d1a6b740 ARM: dts: stm32: stm32mp15x-mecio1-io: Move gpio-line-names to board files
  • 804821b69b2d ARM: dts: stm32: stm32mp15x-mecio1-io: Fix GPIO names typo
  • c632a27f35cf arm64: dts: imx8ulp-evk: Correct Type-C int GPIO flags
  • bd938c985ab3 ARM: dts: stm32: stm32mp15x-mecio1-io: Enable internal ADC reference
  • ead9f10428c7 arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc
  • a98bda2305f3 ARM: dts: stm32: stm32mp15x-mecio1-io: Move divergent mecio1 ADC channels to board files
  • 4fd52ac541ce ARM: dts: stm32: stm32mp15x-mecio1-io: Fix ADC sampling times
  • 68f9773754f0 arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Ringneck
  • e2e3fb995175 arm64: dts: qcom: sdm630: describe adsp_mem region properly
  • 508e55e81870 ARM: dts: imx6ul-var-som: fix warning for non-existent dc-supply property
  • e8dc96a42571 arm64: dts: s32g3: Fix SWT8 watchdog address
  • 89edae416141 arm64: fpsimd: Fix type mismatch in sve_{save,load}_state()
  • 5526d1997aea net: ife: require ETH_HLEN to be pullable in ife_decode()
  • 908391d801b2 octeontx2-vf: clear stale mailbox IRQ state before request_irq()
  • eebf439aa7a1 octeontx2-pf: clear stale mailbox IRQ state before request_irq()
  • e62adb157c2e net: atm: reject out-of-range traffic classes in QoS validation
  • 22100a8f73d4 net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
  • 61a55fa24a5d tipc: restrict socket queue dumps in enqueue tracepoints
  • d34deef34c99 ASoC: SOF: topology: validate vendor array size before parsing
  • 0c4fbdaca225 ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get
  • 711d912b1876 ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
  • fb4293173db2 ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put
  • d8715b5a8fdb vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter
  • 3a2b47d1b4b3 mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()
  • 2d8b3c3e1299 mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()
  • b65e46eed9e5 idpf: add padding to PTP virtchnl structures
  • 1627e7d5c9b0 smb: client: fix overflow in passthrough ioctl bounds check
  • 327595e7c34e drm/xe: remove duplicate <kunit/test-bug.h> include
  • 3de77d2f34c2 octeontx2-af: fix VF bringup affecting PF promiscuous state
  • ee3f7566bcf3 net/mlx5: Fix L3 tunnel entropy refcount leak
  • 1550b07bca2b selftests/net: fix EVP_MD_CTX leak in tcp_mmap
  • 346e2d666a29 regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK
  • 14e03ecd3b1b dm era: fix NULL pointer dereference in metadata_open()
  • 5b0427ba582d SUNRPC: pin upper rpc_clnt across the TLS connect_worker
  • 13965a7b190f SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED
  • b784cd1c24d8 cifs: validate DFS referral string offsets
  • df0e3e70f699 s390/zcrypt: Remove the empty file
  • 8f48cfe65740 ipvs: ensure inner headers in ICMP errors are in headroom
  • 7510451a58c2 ipvs: fix PMTU for GUE/GRE tunnel ICMP errors
  • d73f4249776d ipvs: use parsed transport offset in TCP state lookup
  • d340e351a0a7 ipvs: pass parsed transport offset to state handlers
  • 238c612357b5 netfilter: nft_lookup: fix catchall element handling with inverted lookups
  • f60ec3058a85 ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer()
  • 27506827a01f ipv4: igmp: annotate data-races around timer-related fields
  • d269eb67d2e5 ipv4: igmp: annotate data-races around im->users
  • 9ce741c22df4 ipv6: mcast: Fix potential UAF in MLD delayed work
  • 75e984fe0cb9 ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
  • 3bfcce441c55 gpio: mvebu: free generic chips on unbind
  • 7cc438c99bba perf/x86/amd/core: Avoid enabling BRS from the SVM reload path
  • 9579d625171a octeontx2-pf: check DMAC extraction support before filtering
  • 7aa0e64fea77 net/sched: cake: reject overhead values that underflow length
  • 72119397cdff net: mdio: select REGMAP_MMIO instead of depending on it
  • 762116dfa728 drm/v3d: Reject invalid indirect BO handle in indirect CSD setup
  • 267809e2c56f accel/amdxdna: Fix potential amdxdna_umap lifetime race
  • 1cd434ac1c22 tracing: Make tracepoint_printk static as not exported
  • 5e15cf51982f gpio: dwapb: Defer clock gating until noirq
  • 6c736c5ccf4a gpio: dwapb: reduce allocation to single kzalloc
  • d7b5497e0e45 gpio: dwapb: Use modern PM macros
  • a3010b732d62 net: usb: lan78xx: disable VLAN filter in promiscuous mode
  • e8a4c9fc437b net/tls: Consume empty data records in tls_sw_read_sock()
  • b3eeb586f94c accel/amdxdna: Use unsigned long for nr_pages in amdxdna_hmm_register()
  • ec5e96aee75d ring-buffer: Fix event length with forced 8-byte alignment
  • 0c602cb8f148 Bluetooth: L2CAP: fix tx ident leak for commands without a response
  • bfc9e7be289d Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
  • b69b1ab121fe Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length
  • da4d8eea0c5f Bluetooth: sco: Fix a race condition in sco_sock_timeout()
  • dfc8373893b1 Bluetooth: MGMT: Fix adv monitor add failure cleanup
  • 23a83bac3356 Bluetooth: 6lowpan: hold L2CAP conn across debugfs control
  • 026c236f0eef amt: fix size calculation in amt_get_size()
  • 3bfb96d9bc6a net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
  • 6f9b23eb92a8 net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload
  • 1b12612c367e net: qualcomm: rmnet: validate MAP frame length before ingress parsing
  • b066420e57f3 qede: fix off-by-one in BD ring consumption on build_skb failure
  • 1e71a40d1015 net: microchip: vcap: fix races on the shared Super VCAP block
  • 5c7e3755abf6 net/mlx5e: Fix publication race for priv->channel_stats[]
  • 60fddda7207d net/mlx5e: Fix HV VHCA stats agent registration race
  • 420aabb32da4 net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation
  • 6a802de97a8b net/mlx5: LAG, MPESW, Fix missing complete() on devcom error
  • 4eef84b09a38 netfilter: xt_connmark: reject invalid shift parameters
  • b29b67c729de netfilter: nft_set_rbtree: get command skips end element with open interval
  • 3d441be2b1c5 netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
  • e702f6dd5d21 netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()
  • a597a722fb71 netfilter: xt_u32: reject invalid shift counts
  • 4a4a1d41c6e9 gue: validate REMCSUM private option length
  • b153cfe84b13 net: usb: net1080: validate packet_len before pad-byte access in rx_fixup
  • 66f57dc92aeb arm64/sysreg: Fix BWE field encoding in ID_AA64DFR2_EL1
  • a6185c21d551 selftests/hid: Cover hid_bpf_get_data() size overflow
  • 91ac1d7fd51e selftests/hid: Load only requested struct_ops maps
  • 61a959b82f1a HID: bpf: Fix hid_bpf_get_data() range check
  • 4c65c3d9f660 arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range()
  • dd395744e4ed HID: core: Fix OOB read in hid_get_report for numbered reports
  • d354e523c6f7 HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait()
  • 793b55c3f36f ata: libata-scsi: limit simulated SCSI command copy to response length
  • 232a2f2fce9b ata: sata_gemini: unwind clocks on IDE pinctrl errors
  • 86652704a7fd cifs: Fix missing credit release on failure in cifs_issue_read()
  • c9170c83b0e0 uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline
  • 2265b2b1c5aa x86/uprobes: Keep shadow stack in sync for emulated CALLs
  • adc7dda728ca drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays
  • a0a56b4480a0 drm/xe/hw_engine: Fix double-free of managed BO in error path
  • f9a9abd7bbda drm/xe/userptr: Hold notifier_lock for write on inject test path
  • 78b1074966d2 drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()
  • a9b89752c272 netfs: Fix folio state after ENOMEM whilst under writeback iteration
  • 1bb33d959aab netfs: Fix writeback error handling
  • 7838131e296d netfs: Fix writethrough to use collection offload
  • 8ab75e445c16 netfs: Fix netfs_create_write_req() to handle async cache object creation
  • 1f38f65bf965 iomap: guard io_size EOF trim against concurrent truncate underflow
  • 08b214547066 ovl: fix comment about locking order
  • abe3536a4bed minix: avoid overflow in bitmap block count calculation
  • ce6aced2e855 afs: Fix unchecked-length string display in debug statement
  • 158c5a0b1dfc afs: Fix the volume AFS_VOLUME_RM_TREE is set on
  • 657449e5581a afs: Fix premature cell exposure through /afs
  • 2ffb70a8a019 afs: Fix lack of locking around modifications of net->cells_dyn_ino
  • 8afb1a787a28 afs: Fix vllist leak
  • 5492799ec5d2 afs: Fix missing NULL pointer check in afs_break_some_callbacks()
  • 0acbc09d2aca afs: Fix callback service message parsers to pass through -EAGAIN
  • 63d3f283858f afs: Fix reinitialisation of the inode, in particular ->lock_work
  • 5ea289ca751c afs: Fix misplaced inc of net->cells_outstanding
  • b5bc1e5d5ce5 afs: Fix bulk lookup malfunction due to change in dir_emit() API
  • 083a0ddc9cd4 afs: Remove erroneous seq |= 1 in volume lookup loop
  • 6eb0d929202a afs: use kvfree() to free memory allocated by kvcalloc()
  • aa24cec5b347 afs: Fix double netfs initialisation in afs_root_iget()
  • 8530206911fd afs: Fix error code in afs_extract_vl_addrs()
  • a2038514e693 fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid
  • 374fd8122421 net/sched: hhf: clear heavy-hitter state on reset
  • fba8e250ce5f net/sched: dualpi2: clear stale classification on filter miss
  • a203f2c3892b pinctrl: meson: restore non-sleeping GPIO access
  • 47120164c63d gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe
  • 5a5ac2852cd3 ksmbd: fix use-after-free of fp->owner.name in durable handle owner check
  • d020e7f27bf6 ksmbd: reject undersized DACLs before parsing ACEs
  • 6b1304ce6cff net/sched: act_bpf: use rcu_dereference_bh() to read the filter
  • a03387e1f625 selftests: drv-net: tso: don't touch dangerous feature bits
  • df9ffdceac05 cxgb4: Fix decode strings dump for T6 adapters
  • 124440df267d virtio_net: disable cb when NAPI is busy-polled
  • a8323fb2ab6c sctp: fix addr_wq_timer race in sctp_free_addr_wq()
  • 4e8d498d32b6 irqchip/ts4800: Fix missing chained handler cleanup on remove
  • c5d75800539b irqchip/gic-v3-its: Fix OF node reference leak
  • f0069a262bd4 tracing/probes: Make the $ prefix mandatory for comm access
  • 62988204162f tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry()
  • 898cb5a7c415 tracing: eprobe: read the complete FILTER_PTR_STRING pointer
  • e0881f5cc4d7 tracing/events: Fix to check the simple_tsk_fn creation
  • f148f86c65b8 tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg
  • 3b51d6f07a19 tracing/eprobes: Allow use of BTF names to dereference pointers
  • acbf1ecc22f3 drm/panthor: Interrupt group start/resumption if group_bind_locked() fails
  • a9d098b346db drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced
  • 1497a438ea34 drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick()
  • dd0b2976b7c0 drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom()
  • b4b3458ef88d bridge: stp: Fix a potential use-after-free when deleting a bridge
  • 9b7d05cbaa60 net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF
  • ef940e042f32 net: gianfar: dispose irq mappings on probe failure and device removal
  • 58ba00999898 net: libwx: fix VMDQ mask for 1-queue mode
  • 86d379fcf1b7 net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy
  • 0a7d9c7c5f1f usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()
  • d8a01d27873e ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump
  • 83df3e2594cd eth: fbnic: don't cache shinfo across skb realloc
  • 898ca04b096b hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero
  • 489291b6b569 hwmon: (pmbus) Fix passing events to regulator core
  • 36554592e2f5 hwmon: adm1275: Prevent reading uninitialized stack
  • 1797eb92f0b3 ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280
  • f14c3926fee3 ASoC: codecs: lpass-va-macro: add SM6115 compatible
  • 3d3638fe9213 MIPS: mm: Add check for highmem before removing memory block
  • 4e9f4ca9dc73 MIPS: DEC: Ensure RTC platform device deregistration upon failure
  • bca3100f5502 sctp: add INIT verification after cookie unpacking
  • ad6215d76b64 sctp: fix SCTP_RESET_STREAMS stream list length limit
  • 1681cc7974a6 net: enetc: check the number of BDs needed for xdp_frame
  • b17751a2ebc4 qede: fix out-of-bounds check for cqe->len_list[]
  • 8dba7a94a269 seg6: validate SRH length before reading fixed fields
  • 8d501b141154 net: pse-pd: scope pse_control regulator handle to kref lifetime
  • e94d53a9ac22 gpio: htc-egpio: use managed gpiochip registration
  • f4af803269cc gpio: mvebu: fail probe if gpiochip registration fails
  • 46dee20d30b7 riscv: Fix 32-bit call_on_irq_stack() frame pointer ABI
  • 8e0b7f94fb39 ACPI: RIMT: Only defer the IOMMU configuration in init stage
  • 776f70bafd45 spi: sh-msiof: abort transfers when reset times out
  • d6cd34d17b95 tracing: probes: fix typo in a log message
  • f28d7b5f1578 ALSA: FCP: Fix NULL pointer dereference in interface lookup
  • d990a01b853e net: hns3: differentiate autoneg default values between copper and fiber
  • 2d149a20275a net: hns3: fix permanent link down deadlock after reset
  • 92d05883ef33 net: hns3: refactor MAC autoneg and speed configuration
  • 43a6c6fb6ec5 net: hns3: unify copper port ksettings configuration path
  • de051b146022 selftests: tls: size splice_short pipe by page size
  • 6727f580cf46 dt-bindings: net: renesas,ether: Drop example "ethernet-phy-ieee802.3-c22" fallback
  • 9075efb9b2c1 net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync
  • c1e7286d0531 ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count
  • 7a7c7263bbbc LoongArch: BPF: Fix off-by-one error in tail call
  • ed295077a221 LoongArch: BPF: Fix outdated tail call comments
  • 0a8a729481c8 LoongArch: Move struct kimage forward declaration before use
  • 2f3c0895fb20 net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove
  • b15a3cc68e24 net: sungem: fix probe error cleanup
  • b84dd48f9da1 net: mvneta: re-enable percpu interrupt on resume
  • e0ac054416bf octeontx2-af: Validate NIX maximum LFs correctly
  • 9dc3cf8a3590 net: phy: realtek: Clear MDIO_AN_10GBT_CTRL_ADV10G bit
  • 0c11a1da41a6 net: dsa: realtek: fix memory leak in rtl8366rb_setup_led()
  • a69ccea6d7eb rtc: cmos: unregister HPET IRQ handler on probe failure
  • 5fd1f0512748 rtc: ds1307: Fix off-by-one issue with wday for rx8130
  • d0bfd7004a87 smb/client: preserve errors from smb2_set_sparse()
  • 5b6165d7ec38 ACPI: processor_idle: Mark LPI enter functions as __cpuidle
  • ea43e7a231aa thermal: testing: zone: Flush work items during cleanup
  • 4e62be1490d2 eth: fbnic: fix ordering of heartbeat vs ownership
  • 123b559aa6bb ipv6: fix missing notification for ignore_routes_with_linkdown
  • 419017dd2dda ipv6: fix state corruption during proxy_ndp sysctl restart
  • ae58dbf1d78d ipv6: fix error handling in disable_policy sysctl
  • 2bf70e0306f8 ipv6: fix error handling in forwarding sysctl
  • b060606bc7e4 ipv6: fix error handling in ignore_routes_with_linkdown sysctl
  • 56c26538f0e5 ipv6: fix error handling in disable_ipv6 sysctl
  • 2140c2f3f2e7 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
  • ff127c0aa527 net: usb: lan78xx: restore VLAN and hash filters after link up
  • a9e6707322ef veth: fix NAPI leak in XDP enable error path
  • 410629528067 net: dsa: sja1105: round up PTP perout pin duration
  • 7557df1b60f2 net: do not acquire dev->tx_global_lock in netdev_watchdog_up()
  • 03b743586a24 net, bpf: check master for NULL in xdp_master_redirect()
  • a0904f7d2703 alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs
  • 94defb18ac79 alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
  • 04117aea9bc1 NTB: epf: Fix doorbell bitmask and IRQ vector handling
  • 56ec2a08d27b NTB: epf: Report 0-based doorbell vector via ntb_db_event()
  • d2a41c85beb5 NTB: epf: Make db_valid_mask cover only real doorbell bits
  • 60a6689b9a5d gpio: davinci: fix IRQ domain leak on devm_kzalloc failure
  • 33e1875d6b5b netfilter: nft_compat: ebtables emulation must reject non-bridge targets
  • d3e9a7e2ce9d netfilter: nft_synproxy: stop bypassing the priv->info snapshot
  • 329f2626ee5c netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
  • a73e7ac3f3b6 netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()
  • 49fa1be621dd bpf: Disable xfrm_decode_session hook attachment
  • 4d919c9b7709 md/raid5: avoid R5_Overlap races while breaking stripe batches
  • 3db13f82ba31 md/raid5: use stripe state snapshot in break_stripe_batch_list()
  • 828fad4fd418 ipv4: fib: Don't ignore error route in local/main tables.
  • 630ce3806b70 eth: bnxt: improve the timing of stats
  • c0057e5f762b eth: bnxt: rename ring_err_stats -> ring_drv_stats
  • 33168db149d0 eth: bnxt: gather and report HW-GRO stats
  • b0d0eb13a044 ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().
  • 77bb0bbfcc4e ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE
  • 1f6a4aec0d36 rtc: msc313: fix NULL deref in shared IRQ handler at probe
  • 68115a7a336f i40e: Fix i40e_debug() to use struct i40e_hw argument
  • de80d04b13de ice: dpll: fix memory leak in ice_dpll_init_info error paths
  • eaffdd113f56 ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info
  • 854065a75e37 rtc: isl1208: Balance enable_irq_wake() with disable_irq_wake() on cleanup
  • 4cc632fe63df ice: call netif_keep_dst() once when entering switchdev mode
  • 04c082b7dc5b ice: fix AQ error code comparison in ice_set_pauseparam()
  • dd6d8e4412f8 ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs()
  • 9415a94cf622 PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0
  • e1e7c72a2301 PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0
  • 9cc0f8e63e8c drm/edid: fix OOB read in drm_parse_tiled_block()
  • 5e4c4ab99abc gpiolib: initialize return value in gpiochip_set_multiple()
  • 7550becf3301 power: sequencing: fix ABBA deadlock in pwrseq_device_unregister()
  • 9697db03e010 bpf: Fix effective prog array index with BPF_F_PREORDER
  • 3bdfa0e435f3 bpf: zero-initialize the fib lookup flow struct
  • b05337635be3 bpftool: Fix vmlinux BTF leak in cgroup commands
  • 68b41e68a622 bpf: Fix stack slot index in nospec checks
  • aa33b44f70bf rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231
  • 56e5f8a409f8 rtc: abx80x: fix the RTC_VL_CLR clearing all status flags
  • 93f95538b611 dpaa2-switch: do not accept VLAN uppers while bridged
  • ea24f911ead8 ipv6: ioam: fix type confusion of dst_entry
  • a6450f7cfae5 ipv6: ndisc: fix NULL deref in accept_untracked_na()
  • 2066e692ec7a net: airoha: Fix skb->priority underflow in airoha_dev_select_queue()
  • 1d51aff78f07 net/sched: act_ct: fix nf_connlabels leak on two error paths
  • a103cdb0681e net: emac: Fix NULL pointer dereference in emac_probe
  • 2855ec137a22 octeontx2-pf: mcs: Fix mcs resources free on PF shutdown
  • da603b606ceb octeontx2-pf: Clear stats of all resources when freeing resources
  • 5636f0f3bd99 octeontx2-af: mcs: Fix unsupported secy stats read
  • ceef83f0eaf9 net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths
  • a0c5fdeb5fa2 tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
  • 5dda4f164a63 net: marvell: prestera: initialize err in prestera_port_sfp_bind
  • 9200c8149910 selftests/mm: fix exclusive_cow test fork() handling
  • 55fc2f99d097 selftests/mm: allow PUD-level entries in compound testcase of hmm tests
  • c8add1d06512 selftests/mm: clarify alternate unmapping in compaction_test
  • 0caa28e97894 selftests/mm: skip uffd-stress test when nr_pages_per_cpu is zero
  • 471b62966c78 selftests/mm: ensure destination is hugetlb-backed in hugetlb-mremap
  • 9dbfd514148d selftest/mm: register existing mapping with userfaultfd in hugetlb-mremap
  • a8673dbd3d4a selftests/mm: free dynamically allocated PMD-sized buffers in split_huge_page_test
  • 31b28910abe3 selftests/mm: size tmpfs according to PMD page size in split_huge_page_test
  • fff7d3ea3a4c selftests/mm: fix cgroup task placement and drop memory.current checks in hugetlb_reparenting_test.sh
  • 8c65c58868ec selftests/mm: fix hugetlb pathname construction in hugetlb_reparenting_test.sh
  • 58cd8ff69e33 selftests/mm: restore default nr_hugepages value via exit trap in hugetlb_reparenting_test.sh
  • b805de2abfa3 selftests/mm: restore default nr_hugepages value via exit trap in charge_reserved_hugetlb.sh
  • 37e3e8a2c3bf alloc_tag: fix use-after-free in /proc/allocinfo after module unload
  • 502b3ae43f79 irqchip/crossbar: Fix parent domain resource leak
  • 002ebbcc8414 mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx()
  • 7e23965d44f0 netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak
  • d32e4301a0e5 netfilter: nf_reject: skip iphdr options when looking for icmp header
  • 8e935c51b65d netfilter: nft_flow_offload: zero device address for non-ether case
  • 4c61d28634fb netfilter: flowtable: move path discovery infrastructure to its own file
  • 13c6ba6e0f21 netfilter: nft_meta_bridge: add validate callback for get operations
  • 5baa149abb41 netfilter: nft_payload: reject offsets exceeding 65535 bytes
  • 12088da6add5 netfilter: ipset: make sure gc is properly stopped
  • 8087bb360a93 netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
  • c4d257734e91 netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types
  • a0afd353c2f7 netfilter: ipset: annotate "pos" for concurrent readers/writers
  • 7228cc8ff626 netfilter: ipset: Fix data race between add and dump in all hash types
  • 6d92dbd73d19 md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry
  • 2c5384c40a4c md/raid1: honor REQ_NOWAIT when waiting for behind writes
  • 119903c32083 md: merge mddev serialize_policy into mddev_flags
  • 2e414af05a7c md: merge mddev faillast_dev into mddev_flags
  • 9408c233a5bb md: merge mddev has_superblock into mddev_flags
  • 5464ee644237 mac802154: Prevent overwrite return code in mac802154_perform_association()
  • de3bd9809af7 ieee802154: fix kernel-infoleak in dgram_recvmsg()
  • d22e278cd067 ieee802154: Remove WARN_ON() in cfg802154_pernet_exit()
  • f4860dd988b1 ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns()
  • 5d17ebdf6c23 ieee802154: Restore initial state on failed device_rename() in cfg802154_switch_netns()
  • 3b40ebc19ad0 ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone()
  • 45465b0e0135 ACPI: resource: Amend kernel-doc style
  • 7ae67f0e1c16 thermal: intel: Fix dangling resources on thermal_throttle_online() failure
  • 679fd0bf4f8a arm64/hw_breakpoint: reject unaligned watchpoints that would truncate BAS
  • 4c16176fc11a ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints
  • a762b9865f49 selftests: vlan_bridge_binding: Fix flaky operational state check
  • c6d3bcb0f934 flow_dissector: check device type before reading ETH_ADDRS
  • 68af74ad696c net: macb: add TX stall timeout callback to recover from lost TSTART write
  • 112b5eff24e0 net: airoha: fix foe_check_time allocation size
  • 5ffb2b4987cc devlink: Fix parent ref leak on tc-bw failure
  • 02c884d9aaca devlink: Fix parent ref leak in devl_rate_node_create()
  • 0dafdaaf8684 dpaa2-switch: fix VLAN upper check not rejecting bridge join
  • c7fc9adf4e00 virtio-net: fix len check in receive_big()
  • 0d95587d662a spi: rpc-if: Use correct device for hardware reinitialization on resume
  • f37f2f804796 PCI: iproc: Restore .map_irq() for the platform bus driver
  • 53c23d56b46b ALSA: usb-audio: qcom: clear opened when stream enable fails
  • 25a867aa5e67 ALSA: usb-audio: qcom: reject stream disable with no active interface
  • 207bb4ce8fe7 sctp: hold socket lock when dumping endpoints in sctp_diag
  • a6cfb924ad74 net: psample: fix info leak in PSAMPLE_ATTR_DATA
  • 3d45d40b872a octeontx2-pf: Fix leak of SQ timestamp buffer on teardown
  • 290ad0a54891 drm/amdgpu: initialize irq.lock spinlock earlier
  • 96ac562a9ea3 drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm
  • 211bb9d8f17c drm/amd/display: Fix mem_type change detection for async flips
  • 0e27d92f69b8 drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free
  • 7bcd4ef375fa ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode
  • ca297485271c perf dso: Set standard errno on decompression failure
  • 05b11debdffe perf bpf: Validate array presence before casting BPF prog info pointers
  • c8cb4a92eda6 perf cs-etm: Bounds-check CPU in cs_etm__get_queue()
  • b389a5b215e3 perf cs-etm: Require full global header in auxtrace_info size check
  • c13532ff67fa perf cs-etm: Validate num_cpu before metadata allocation
  • 87d23f25b5e9 perf machine: Use snprintf() for guestmount path construction
  • 6d99379c58f7 xfrm: validate selector family and prefixlen during match
  • 7248ae02a945 xfrm: annotate data-races around xfrm_policy_count[] and xfrm_policy_default[]
  • a1a3360a0c44 xfrm: Fix xfrm state cache insertion race
  • 1467ca02ddac ALSA: usb-audio: qcom: Free sideband sg_table objects
  • 507a7b07f3fa i3c: master: Add missing runtime PM get in dev_nack_retry_count_store()
  • 34cd92141a02 i3c: master: Update dev_nack_retry_count under maintenance lock
  • 95028569589f spi: dw: fix wrong BAUDR setting after resume
  • 355e51eeffc6 drm/xe: Fix wa_oob codegen recipe for external module builds
  • 2024940522ef drm/i915: clear CRTC color blob pointers after dropping refs
  • 1348bf64c197 gpio: mlxbf3: fail probe if gpiochip registration fails
  • 7d3532a0b11a perf cs-etm: Reject CPU IDs that would overflow signed comparison
  • a56f29ad8aac perf: Remove redundant kernel.h include
  • f8898d2eb71a perf bpf: Bounds-check array offsets in bpil_offs_to_addr()
  • cafd80d81f08 perf bpf: Reject oversized BPF metadata events that truncate header.size
  • 1935d213aeb2 perf bpf: Validate func_info_rec_size and sub_id in synthesize_bpf_prog_name()
  • aea30b437ebd perf sched: Replace (void*)1 sentinel with proper runtime allocation
  • bc27041e8971 perf hwmon: Fix fd check to accept fd 0 in hwmon_pmu__describe_items()
  • 661f60a8a5cf perf tools: Use snprintf() for root_dir path construction
  • 5d080b7324f0 perf dso: Set error code when open() fails on uncompressed fallback path
  • debfcd673a6d perf dso: Fix heap overflow in dso__get_filename() on decompressed path
  • 95bf4dbcd502 perf tools: Fix uninitialized pathname on uncompressed fallback in filename__decompress()
  • fa870f951793 perf tools: Add O_CLOEXEC to open() calls in DSO and ELF code
  • 3ae7947101b9 perf tools: Don't read build-ids from non-regular files
  • 2c19e40753ec perf symbols: Break infinite loop on zero-filled notes in sysfs__read_build_id()
  • 137eabe3c18f perf symbols: Validate p_filesz before use in filename__read_build_id()
  • ca3393e258f6 perf symbols: Fix bswap copy-paste error for 32-bit ELF p_filesz
  • f231387f3d2b sparc: led: avoid trimming a newline from empty writes
  • 17955f1995bf accel/ivpu: fix HWS command queue leak on registration failure
  • 85873b1bd366 apparmor: fix label can not be immediately before a declaration
  • 38d3d33bf42c i3c: master: Prevent reuse of dynamic address on device add failure
  • c4f2afcdc547 i3c: master: Defer new-device registration out of DAA caller context
  • 3891c061341f i3c: master: Ensure Hot-Join operations are stopped on shutdown
  • 57490b302b98 i3c: master: Consolidate Hot-Join DAA work in the core
  • 0bd450d40f87 i3c: master: Move rstdaa error suppression
  • fd32e8d4a293 i3c: master: Add i3c_master_do_daa_ext() for post-hibernation address recovery
  • b07a318afca1 i3c: master: Introduce optional Runtime PM support
  • 882ee831366a i3c: master: Replace WARN_ON() with dev_err() in i3c_dev_free_ibi_locked()
  • de2106d99b87 i3c: add sysfs entry and attribute for Device NACK Retry count
  • 0d66830f302f i3c: master: Make hot-join workqueue freezable to block hot-join during suspend
  • eb9db96a5deb i3c: master: add WQ_PERCPU to alloc_workqueue users
  • 45bbc1e1fe62 i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring
  • d22ab94261c7 i3c: mipi-i3c-hci: Switch PIO data allocation to devm_kzalloc()
  • 973fda38b124 i3c: mipi-i3c-hci: Allow for Multi-Bus Instances
  • 5625b8767ce3 i3c: mipi-i3c-hci: Quieten initialization messages
  • 2791dd42d41e apparmor: fix uninitialised pointer passed to audit_log_untrustedstring()
  • fdf610a9a9e7 apparmor: don't audit files pointing to aa_null.dentry
  • b58d240883df apparmor: put secmark label after secid lookup
  • 66a6c61369d4 apparmor: aa_getprocattr free procattr leak on format failure
  • 22dc9433d458 apparmor: fail policy unpack on accept2 allocation failure
  • 3b918f6f5239 apparmor: Fix return in ns_mkdir_op
  • 566d1ef98a71 apparmor: remove or add symlinks to rawdata according to export_binary
  • fbfdb5a94a48 apparmor: fix NULL pointer dereference in unpack_pdb
  • 57b1bd4486d5 apparmor: fix potential UAF in aa_replace_profiles
  • b427061ca498 apparmor: grab ns lock and refresh when looking up changehat child profiles
  • 9111f76e8dc8 apparmor: fix rawdata_f_data implicit flex array
  • ae02e603c0b3 apparmor: aa_label_alloc use aa_label_free on alloc failure
  • d82160132345 apparmor: check label build before no_new_privs test
  • ad965f36d298 security/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref()
  • 045dbe89ac31 apparmor: fix refcount leak when updating the sk_ctx
  • d8ea44f6090c apparmor: fix race in unix socket mediation when peer_path is used
  • ef488d7429d2 apparmor: fix shadowing of plabel that prevents cache from being updated
  • f79519f63605 Revert "PCI/MSI: Unmap MSI-X region on error"
  • 514b84b1bf30 PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability
  • 11016555d751 phy: freescale: phy-fsl-imx8qm-lvds-phy: Fix missing pm_runtime_disable() on probe error path
  • 872f9a63a108 PCI: mediatek: Use actual physical address instead of virt_to_phys()
  • f77c490c45d4 PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port()
  • 9ca0a78a5d56 dt-bindings: phy: sc8280xp-qmp-pcie: Disallow bifurcation register on Purwa
  • f1f5f8d334e9 perf symbols: Add bounds checks to read_build_id() note iteration in minimal build
  • cc6cd3fe8b8b perf symbols: Add bounds checks to elf_read_build_id() note iteration
  • a3e758e74122 perf bpf: Fix metadata leak in perf_env__add_bpf_info() on duplicate insert
  • f593775fecf5 perf bpf: Fix map data leak in bpf_metadata_create() on alloc failure
  • bafb6bfb346f perf bpf: Add NULL check for btf__type_by_id() in synthesize_bpf_prog_name()
  • fe4d8ad2e96f tools lib api: Fix mount_overload() snprintf truncation and toupper range
  • b0385203a09f tools lib api: Fix filename__write_int() writing uninitialized stack data
  • 41b3a9231045 perf tools: Use snprintf() in dso__read_running_kernel_build_id()
  • fbaf9bdfc091 perf hwmon: Guard label read against empty or failed reads
  • d34b42ee0c74 perf symbols: Bounds-check descsz in sysfs__read_build_id() GNU fallback
  • bc2fc12ce6e4 perf hwmon: Fix parse_hwmon_filename() strlcpy buffer overflow
  • f830bb8d221f perf hwmon: Use scnprintf() in hwmon_pmu__for_each_event()
  • 76dfa13a0acb perf hwmon: Fix off-by-one null termination on sysfs reads
  • 56b17c84394f perf tools: Fix thread__set_comm_from_proc() on empty comm file
  • f2e5262589d9 perf intel-pt: Fix snprintf size tracking bug in insn decoder
  • 45e7900e1555 perf symbols: Bounds-check .gnu_debuglink section data
  • 4f883ab5bc7b perf symbols: Fix signed overflow in sysfs__read_build_id() size check
  • 490473192ac2 tools lib api: Fix missing null termination in filename__read_int/ull()
  • 09962b811ef1 perf pmu: Fix perf_pmu__parse_scale/unit() OOB access on empty sysfs file
  • a6eec54329b4 perf pmu: Fix pmu_id() heap underwrite on empty identifier file
  • e274dfa05904 perf cs-etm: Queue context packets for frontend
  • fa9eb50ddfea perf s390: Fix TEXTREL in Python extension by compiling as PIC
  • b5a0a4a564d2 xprtrdma: Return sendctx slot after Send preparation failure
  • 007b4da2f38d xprtrdma: Repost Receive buffers for malformed replies
  • 469b22376ee7 xprtrdma: Sanitize the reply credit grant after parsing
  • d7a2870dde3b xprtrdma: Fix bcall rep leak and unbounded peek
  • 345652531400 xprtrdma: Resize reply buffers before reposting receives
  • 47b3dc59e09e xprtrdma: Document and assert reply-handler invariants
  • 7471e66373a4 xprtrdma: Check frwr_wp_create() during connect
  • 28743571c17b xprtrdma: Initialize re_id before removal registration
  • d0479c2b1297 xprtrdma: Fix ep kref imbalance on ADDR_CHANGE
  • 6d52921f4702 perf hists: Fix snprintf() in hists__scnprintf_title() UID filter path
  • 56ad33189ed5 perf bpf: Use scnprintf() in snprintf_hex() and synthesize_bpf_prog_name()
  • c32fe40b0c74 perf sched: Fix idle-hist callchain display using wrong rb_first variant
  • 77051ef66e4a perf sched: Bounds-check prio before test_bit() in timehist
  • 2e0dd50e5a4d PCI: rcar-host: Remove unused LIST_HEAD(res)
  • b9e8406651dc perf tools: Use perf_env__get_cpu_topology() in machine__resolve()
  • 504028f561b1 perf tools: Use scnprintf() in cpu_map__snprint() to prevent overflow
  • 2a8244988316 perf tools: Fix get_max_num() size_t underflow on empty sysfs file
  • 3f4476a089a6 platform/x86/intel/vsec: Restore BAR fallback for header walk
  • d6565e08166c platform/x86/intel/vsec: Return real error codes from registration path
  • 4df30a4dc0e9 platform/x86/intel/vsec: Switch exported helpers from pci_dev to device
  • 817ab332d37c platform/x86/intel/vsec: Decouple add/link helpers from PCI
  • e6523bcafeb6 platform/x86/intel/vsec: correct kernel-doc comments
  • c0d97519c9df platform/x86:intel/pmc: Relocate lpm_req_guid to pmc_reg_map
  • b95e1facc5b7 platform/x86:intel/pmc: Rename PMC index variable to pmc_idx
  • 3e86797c0699 platform/x86:intel/pmc: Add support for multiple DMU GUIDs
  • 4f129fc6f756 fs/ntfs3: resize log->one_page_buf when adopting on-disk page size
  • d3491b23bc20 PCI: meson: Add missing remove callback
  • a5c0ba31eef9 PCI: meson: Propagate devm_add_action_or_reset() failure
  • f0aaa198e068 pwm: rzg2l-gpt: Add missing newlines to dev_err_probe() messages
  • a57692ad365f PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro
  • f161ef7b0dd2 nfs: use nfsi->rwsem to protect traversal of the file lock list
  • a6f147b23e36 NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write
  • a70375f0b793 NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors
  • b694c7de94bc nfs: keep PG_UPTODATE clear after read errors in page groups
  • f84949dd1784 NFSv4/pnfs: defer return_range callbacks until after inode unlock
  • 53442c7d0c88 xprtrdma: Decouple req recycling from RPC completion
  • becc90a04780 xprtrdma: Use sendctx DMA state for Send signaling
  • e7ae0883c8c8 xprtrdma: Post receive buffers after RPC completion
  • f043dd58fbd7 xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot
  • b7bc8e7f09ae xprtrdma: Avoid 250 ms delay on backlog wakeup
  • 44b73b4b7eff pNFS/filelayout: fix cheking if a layout is striped
  • f3f21b94cf98 sunrpc: Fix error handling in rpc_sysfs_xprt_switch_add_xprt_store()
  • e8dc126e8039 clk: qcom: a53: Corrected frequency multiplier for 1152MHz
  • c0e6bb2b0408 dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor
  • 9f1ef67c041e dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc
  • 329ec20a8609 dmaengine: Fix possible use after free
  • 7d49f0ddaf5a dmaengine: qcom: gpi: set DMA_PRIVATE capability
  • 8e2c460a8f0e mshv: add bounds check on vp_index in mshv_intercept_isr()
  • eaf937b501fd clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks
  • 032692e4525a dt-bindings: clock: qcom: Add X1P42100 camera clock controller
  • c7c8bab87d0d perf tools: Fix int16_t truncation of max_cpu_num in set_max_cpu_num()
  • e16012f8f63d perf timechart: Fix cpu2y() OOB read on untrusted CPU index
  • 330219fe8523 perf c2c: Fix use-after-free in he__get_c2c_hists() error path
  • 01564c1a260f perf stat: Introduce perf_env__get_cpu_topology() to guard NULL env->cpu
  • c05ba5b57505 perf mmap: Fix NULL deref in aio cleanup on alloc failure
  • c4406dbe5d8f perf sched: Replace BUG_ON and add NULL checks in replay event helpers
  • b1f768363271 perf sched: Use thread__put() in free_idle_threads()
  • 1517402d0a81 perf sched: Clean up idle_threads entry on init failure
  • d6b586bb8f48 perf c2c: Bounds-check CPU IDs in setup_nodes() topology loop
  • 2f9f7224e769 perf c2c: Bounds-check CPU and node IDs before bitmap and array access
  • 278e30717c35 perf stat: Bounds-check CPU index in topology aggregation callbacks
  • 21a9b87ada08 perf mmap: Guard cpu__get_node() return in aio_bind()
  • 652cea73b7b7 perf sched: Fix register_pid() overflow, strcpy, and BUG_ON
  • 068e9b6a07bc perf sched: Cap max_cpu at MAX_CPUS in timehist sample processing
  • 1d25a8418c89 perf tools: Add bounds check to cpu__get_node()
  • 89489a31f444 perf sched: Fix thread reference leak in latency_switch_event
  • ea486d61b166 perf tools: Guard test_bit from out-of-bounds sample CPU
  • 18961e0f8966 perf annotate: Fix crashes on empty annotate windows
  • 93f3e84fc74e perf: Fix off-by-one stack buffer overflow in kallsyms__parse()
  • d78b16d07814 dt-bindings: dma: nvidia,tegra186-gpc-dma: Make reset optional
  • a498063f95bd dmaengine: imx-sdma: Refine spba bus searching in probe
  • da4058382315 thunderbolt: debugfs: Fix margining error counter buffer leak
  • 038a0f01dda5 drm/amd/display: Add missing kdoc for ALLM parameters
  • c5388a957cf1 fs/ntfs3: fix mount failure on 64K page-size kernels
  • a31893206588 fs/ntfs3: add bounds check to run_get_highest_vcn()
  • 097fcf945d93 HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter
  • 26fa946925a0 clk: at91: keep securam node alive while mapping it
  • 0147c544cbc6 iio: tcs3472: power down chip on probe failure
  • 1cddef80a180 iio: accel: mma8452: handle I2C read error(s) in mma8452_read()
  • 9ac3675bf875 iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling
  • 3d5767211952 iio: magnetometer: ak8975: fix potential kernel stack memory leak
  • 6ec473b36034 iio: light: si1133: prevent race condition on timeout
  • f835b69fbeae iio: light: si1133: reset counter to prevent race condition
  • fd6b65ade119 perf header: Sanity check HEADER_EVENT_DESC attr.size before swap
  • be62602fe079 PCI: qcom: Disable ASPM L0s for SA8775P
  • de93ef83f99e powerpc tools perf: Initialize error code in auxtrace_record_init function
  • 96c8f732cadf clk: renesas: rzg2l: Rename iterator in for_each_mod_clock() to avoid shadowing
  • fdee9f207a48 gpib: fix double decrement of descriptor_busy in command_ioctl()
  • 3d5e4cc0d9dc char: tlclk: fix use-after-free in tlclk_cleanup()
  • d72ece584c44 gpib: Fix inappropriate ioctl error return
  • 92f8b1d83383 perf test amd ibs: Fix incorrect kernel version check
  • 2b2b1613b734 usb: host: max3421: Reject hub port requests for non-existent ports
  • 02d03c61e8a7 usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
  • 43078449ad62 staging: most: video: avoid double free on video register failure
  • 45652323ce74 perf inject: Add --convert-callchain option
  • 28ebd287a7fa perf build-id: Fix off-by-one bug when printing kernel/module build-id
  • fc5ce5606db5 PCI: dwc: Fix signedness bug in fault injection test code
  • 7d881615fb63 mailbox: mtk-adsp: fix UAF during device teardown
  • 91353d63bbf6 mailbox: mpfs: fix check for syscon presence in mpfs_mbox_inbox_isr()
  • e6bc4e127707 coresight: Fix source not disabled on idr_alloc_u32 failure
  • 67d0475e78b3 soundwire: intel_ace2x: release bpt_stream when close it
  • 5732869c70d4 clk: at91: sam9x7: Fix gmac_gclk clock definition
  • f28906e7e32f perf pmu: Skip test on Arm64 when #slots is zero
  • 210c202c0576 phy: phy-can-transceiver: Check driver match and driver data against NULL
  • 226feccaac81 clk: qcom: cmnpll: Account for reference clock divider
  • 6abdf27fbcfb coresight: fix missing error code when trace ID is invalid
  • 5bb87456dcd6 bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
  • 601a9b2e3b2f rust: alloc: fix assert in Vec::reserve doc test
  • b773c7161cea PCI: loongson: Do not ignore downstream devices on external bridges
  • e1b79f77336d perf sched: Add missing mmap2 handler in timehist
  • c788955b4a14 platform/x86: xo15-ebook: Fix wakeup source and GPE handling
  • 2ce4d93768d2 x86/platform/olpc: xo15: Drop wakeup source on driver removal
  • 1d495446ec7a PCI: Check ROM header and data structure addr before accessing
  • 78f264c0cb2a PCI: Introduce named defines for PCI ROM
  • 10021c2d3306 PCI/ASPM: Don't reconfigure ASPM entering low-power state
  • 48dde5c56426 coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore
  • 65d87f28daec coresight: ete: Always save state on power down
  • 1ac8f4c112aa coresight: etm4x: Remove the state_needs_restore flag
  • a454f61747c9 soundwire: fix bug in sdw_add_element_group_count found by syzkaller
  • d3896c944338 soundwire: don't program SDW_SCP_BUSCLOCK_SCALE on a unattached Peripheral
  • c3ca7c6741af coresight: cti: Fix DT filter signals silently ignored
  • fb940466fd4d perf debuginfo: Fix libdw API contract violations
  • bb3d592c7d6c staging: nvec: fix use-after-free in nvec_rx_completed()
  • 466c7f87de52 i3c: master: svc: Fix missed IBI after false SLVSTART on NPCM845
  • db2d8b6525bd gpiolib: acpi: Only trigger ActiveBoth interrupts on boot
  • 02e2dadd62ea eventpoll: Fix epoll_wait() report false negative
  • f938bc8fde51 eventpoll: rename epi->next and txlist for clarity
  • 430dac191905 eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers
  • d8f88803152f eventpoll: extract ep_deliver_event() from ep_send_events()
  • 4fd51f413d7b eventpoll: split ep_insert() into alloc + register stages
  • 25e85dc040a6 eventpoll: rename attach_epitem() to ep_attach_file()
  • baebd892f8a2 eventpoll: expand top-of-file overview / locking doc
  • f04166c8677a eventpoll: rename ep_remove_safe() back to ep_remove()
  • 13bf9879b778 net/9p: fix race condition on rdma->state in trans_rdma.c
  • 9c1c120471a6 9p: avoid returning ERR_PTR(0) from mkdir operations
  • ae1f3460833d ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write
  • d35e4032f16d mfd: cs42l43: Sanity check firmware size
  • 706fe1ce4f3a mfd: rsmu: Fix page register setup
  • 35d3d6ff2bc1 ksmbd: fix use-after-free in same_client_has_lease()
  • aa0c43c13c0b RDMA/bnxt_re: Fail DBR related page allocation UAPIs if the feature is disabled
  • 0fe155aa844e RDMA/bnxt_re: Move the UAPI methods to a dedicated file
  • 95d46a8d3ba9 RDMA/bnxt_re: Avoid displaying the kernel pointer
  • 104a7ff382a5 RDMA/bnxt_re: Free SRQ toggle page after firmware teardown
  • 5a48dd5150d7 ionic: Fix check in ionic_get_link_ext_stats
  • 4c55003566c0 net: ethernet: oa_tc6: Remove FCS size in RX frame
  • 93e133b9193c net: airoha: Fix always-true condition in PPE1 queue reservation loop
  • d774cdbda663 tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)
  • 0d8a12d71431 tipc: fix UAF in tipc_l2_send_msg()
  • db1616263a2c KEYS: Use acquire when reading state in keyring search
  • 66919a6d72b9 powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus
  • 527cd14a416f powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down
  • 73711688479d powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del
  • 92f38fe85198 MIPS: mm: Fix out-of-bounds write in maar_res_walk()
  • fe09dd288722 bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check
  • 81567d2b3f4d sockmap: Fix use-after-free in udp_bpf_recvmsg()
  • 073d95725269 net: remove addr_len argument of recvmsg() handlers
  • 4e40056bb5c8 bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
  • 264d6a79c96e udf: fix nls leak on udf_fill_super() failure
  • 5e8627b7a7b7 bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket
  • e80307776924 selftests/bpf: Initialize operation name before use
  • 9f32d4c2de85 selftests/bpf: Fix typo in verify_umulti_link_info
  • 74badb5e2b00 smb/client: always return a value for FS_IOC_GETFLAGS
  • 21303c4a2b72 cifs: remove all cifs files before kill super
  • 7a59146cb9ad ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait()
  • 87d1eaffeec4 netfilter: nf_conncount: callers must hold rcu read lock
  • 98a965cb1e76 ALSA: seq: avoid stale FIFO cells during resize
  • 287d506d4e08 ALSA: seq: oss: Serialize readq reset state with q->lock
  • f01fb6138f8e kcm: use WRITE_ONCE() when changing lower socket callbacks
  • 4d48c08a0bf6 net: airoha: Fix debugfs new-tuple display for IPv4 ROUTE entries
  • dcac6e4221f3 net: airoha: Fix register index for Tx-fwd counter configuration
  • 36edab340a06 net: bcmgenet: Use weighted round-robin TX DMA arbitration
  • b91b241a4eef landlock: Fix unmarked concurrent access to socket family
  • 1bb02353e79f dpll: balance create/delete notifications in _dpll_pin(un)register
  • 77a1ea975c87 dpll: guard sync-pair removal on full pin unregister
  • 8008ef973f01 dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister()
  • 6564ce3a2f9c dpll: send delete notification before unregister in on-pin rollback
  • f1e1c6eb8248 dpll: fix stale iteration in dpll_pin_on_pin_unregister()
  • 20575400fc1b dpll: Enhance and consolidate reference counting logic
  • ebe4bd3560a7 dpll: Support dynamic pin index allocation
  • f7aebaee2961 net: wwan: t7xx: check skb_clone in control TX
  • 34bd255dba32 net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show()
  • 1d072cc3ba43 octeontx2-af: npc: Fix size of entry2cntr_map
  • 417bd36a085d bpf: Fix setting retval to -EPERM for cgroup hooks not returning errno
  • 3d90b15fb191 net/mlx5: Check max_macs devlink param value against max capability
  • 8d5f4be13488 bpf: Run generic devmap egress prog on private skb
  • 450e48271827 net/sched: sch_dualpi2: Add missing module alias
  • 6d585d0dc674 net: ethernet: mtk_wed: fix loading WO firmware for MT7986
  • 446fe8ce699c net: watchdog: fix refcount tracking races
  • 697db22a9dcc net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check
  • 62ce489acb42 net: mana: initialize gdma queue id to INVALID_QUEUE_ID
  • bd851b10daee net/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
  • 755108bb7a50 net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
  • 0500af8630c3 net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
  • a05d638b6074 virtio_net: do not allow tunnel csum offload for non GSO packets
  • ce311bd2e365 tcp: clear sock_ops cb flags before force-closing a child socket
  • 67cec2f1eb9e handshake: Require admin permission for DONE command
  • d0503357653e power: supply: core: fix supplied_from allocations
  • 7f4aa81f5bb2 ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO
  • 0c22c0092435 iommu: Avoid copying the user array twice in the full-array copy helper
  • 1c9246a199e1 spi: xilinx: use FIFO occupancy register to determine buffer size
  • dae23c545eb5 ALSA: seq: Fix kernel heap address leak in bounce_error_event()
  • 1749fef4bda0 ALSA: usb-audio: qcom: Guard sideband endpoint removal
  • 2ba237315193 crypto: rng - Free default RNG on module exit
  • fb4d57b83356 crypto: cavium/cpt - fix DMA cleanup using wrong loop index
  • 5f99a396f706 crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
  • 4941205f5fa3 cxl/test: Add check after kzalloc() memory in alloc_mock_res()
  • a27481516d32 cxl/test: Unregister cxl_acpi in cxl_test_init() error path
  • 7e401233f9bb tipc: reject inverted service ranges from peer bindings
  • 3cfa3d8e0dc1 tipc: prevent snt_unacked underflow on CONN_ACK
  • cebaefe1aceb tipc: require net admin for TIPCv2 netlink mutators
  • 66dbb13eeb2f net/sched: sch_hfsc: Don't make class passive twice
  • 51a1d9836acc net: pfcp: allocate per-cpu tstats for PFCP netdevs
  • ed8605c6f39b sctp: validate embedded address parameter length
  • a090880c1f54 bridge: cfm: reject invalid CCM interval at configuration time
  • bb4a5b3c91af net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().
  • 0a8b5b74f0e6 net/sched: cls_flow: Dont expose folded kernel pointers
  • 10e05634ddc1 net: dsa: qca8k: fix led devicename when using external mdio bus
  • e098c9c6477d ASoC: tegra: tegra210_ahub: Validate written enum value
  • 0f1510e84d7b ASoC: fsl: fsl_audmix: Validate written enum values
  • 9131e4b023e0 ASoC: codecs: hdac_hdmi: Validate written enum value
  • cb527e063a32 ASoC: SOF: Intel: hda-sdw-bpt: select SND_SOF_SOF_HDA_SDW_BPT properly
  • d3ff718c0c71 RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one
  • 4b87a2497276 RDMA/mlx5: Fix undefined shift of user RQ WQE size
  • 1bc1487f7a7f RDMA/mlx5: Remove raw RSS QP restrack tracking
  • f704db4b0318 RDMA/mlx5: Remove DCT restrack tracking
  • 3a1687e0506b fs: efs: remove unneeded debug prints
  • 7e694ac97591 Bluetooth: vhci: validate devcoredump state before side effects
  • ec4d352747a6 Bluetooth: hci: validate codec capability element length
  • 7f206a8d8d82 Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path
  • a0fd1086a57b Bluetooth: hci_core: Fix UAF in hci_unregister_dev()
  • e8815ae9dcdc Bluetooth: hci_event: fix simultaneous discovery stuck in FINDING
  • f1b4df9c260c Bluetooth: eir: Fix stack OOB write when prepending the Flags AD
  • e284bb94ad45 Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device
  • c86c861c64b5 s390/process: Fix kernel thread function pointer type
  • 0eab19ab9cb1 ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset()
  • c83255f3cf22 arm64: dts: allwinner: a523: Add missing GPIO interrupt
  • ad6963c3bb45 pinctrl: airoha: an7581: fix misprint in gpio19 pinconf
  • 5985ddfd3e83 pinctrl: airoha: an7581: add missed gpio32 pin group
  • db3cd694ded4 pinctrl: airoha: generalize pins/group/function/confs handling
  • 0234e8fc296e pinctrl: sunxi: a523: Remove unneeded IRQ remuxing flag
  • 46fbafe3d2d5 bpf: Tighten cgroup storage cookie checks for prog arrays
  • d416dcefdbac vfio/qat: fix f_pos race in qat_vf_resume_write()
  • 1201dbb26050 of: cpu: add check in __of_find_n_match_cpu_property()
  • d2acea4f4747 cxl/test: Zero out LSA backing memory to avoid leaking to user
  • 42a9a76f314e cxl/test: Fix integer overflow in mock LSA bounds checks
  • 91ad3088ee1b selftests/bpf: Fix bpf_iter/task_vma test
  • f00f5c0dd553 ext4: fix kernel BUG in ext4_write_inline_data_end
  • c998a09c7144 bonding: 3ad: fix mux port state on oper down
  • f0ada4846d11 bonding: 3ad: fix carrier when no usable slaves
  • cb20a9b50efe bonding: 3ad: add lacp_strict configuration knob
  • 47636f0a70b3 netlink: specs: rt-link: missed broadcast-neigh
  • 6b2c271d2c39 tools: missed broadcast_neigh if_link uapi header
  • 484b3b9aa798 ext4: fix ERR_PTR(0) in ext4_mkdir()
  • 88cb304c0be0 ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails
  • 8b55e7ec116c ASoC: cs35l56: Fix missing calls to wm_adsp2_remove()
  • 3ef0cfa77a3d vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
  • 54556d539438 vdpa/octeon_ep: Fix PF->VF mailbox data address calculation
  • 86e0b37738de tools/virtio: check mmap return value in vringh_test
  • 321c73baf54d vhost/net: complete zerocopy ubufs only once
  • 646614dcb160 vduse: Requeue failed read to send_list head
  • f9d922023445 virtio_console: read size from config space during device init
  • 79366023aa89 virtio: rtc: tear down old virtqueues before restore
  • 1f5f94c6c6b2 vhost/vdpa: validate virtqueue index in mmap and fault paths
  • a2d0a57538fd vduse: hold vduse_lock across IDR lookup in open path
  • 3d56f3fb201f ASoC: codecs: aw88261: fix incorrect masks for boost regs
  • ecb9be4fc8be spi: meson-spifc: fix runtime PM leak on remove
  • da6f86ff4f2d NFSD: Handle layout stid in nfsd4_drop_revoked_stid()
  • 37e85be551c4 IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified
  • e6d83f877d5a ASoC: sma1307: Fix uevent string leaks in fault worker
  • 701ea71c17c9 igc: skip RX timestamp header for frame preemption verification
  • 2aa37c8ef109 btrfs: fix deadlock cloning inline extent when using flushoncommit
  • f85410ebf20b btrfs: annotate lockless read of defrag_bytes in should_nocow()
  • 18285888cb41 btrfs: zoned: always set max_active_zones for zoned devices
  • 943f5917c53c Revert "btrfs: fix the file offset calculation inside btrfs_decompress_buf2page()"
  • ba641829c11c btrfs: zoned: don't account data relocation space-info in statfs free space
  • bd5e90b0f5a0 hwmon: (it87) Clamp negative values to zero in set_fan()
  • ebb579c5c0f0 vfs: add FS_USERNS_DELEGATABLE flag and set it for NFS
  • de590cdf7efe fbdev: sm501fb: Fix buffer errors in OF binding code
  • 0678fed27def wifi: ath12k: enable IEEE80211_VHT_EXT_NSS_BW_CAPABLE when NSS ratio is reported
  • 47e5302722e0 gpio: mt7621: fix interrupt banks mapping on gpio chips
  • 90a9c909c5b7 ALSA: aloop: Drop superfluous break
  • 3b15d02be05e btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
  • 7ec839c7c0bc wifi: mt76: mt7996: fix potential tx_retries underflow
  • ad12fdaaed16 wifi: mt76: mt7925: fix potential tx_retries underflow
  • 3b6e6fefa57f wifi: mt76: mt7921: fix potential tx_retries underflow
  • 6b8e35685c18 wifi: mt76: mt7915: fix potential tx_retries underflow
  • 6356a829a1ed wifi: mt76: fix argument to ieee80211_is_first_frag()
  • 42f34c478fcd wifi: mt76: mt7996: limit work in set_bitrate_mask
  • 1a399103cacc wifi: mt76: mt7996: fix reading zeroed info->control.flags after mt76_tx_status_skb_add()
  • dfb27e5dd9e4 wifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write_txwi_80211()
  • 06e65d6cf804 wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb()
  • c386e90a7ce8 wifi: mt76: mt7925: validate skb length in testmode query
  • 856fa6a21586 wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX
  • a10e4959a73b wifi: mt76: mt7925: keep TX BA state in the primary WCID
  • b8bf7c221b36 wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links
  • bd3b91ff1300 wifi: mt76: mt7996: add missing max_remain_on_channel_duration
  • c7a83899203e wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link
  • 3f0ea6d14fa4 wifi: mt76: mt7925: clean up DMA on probe failure
  • ce9d5a021cfc ARM: configs: Drop duplicated CONFIG_EXT4_FS
  • c788617705c3 sched/fair: Fix cpu_util runnable_avg arithmetic
  • a2e8b5264f92 hwspinlock: qcom: avoid uninitialized struct members
  • bbd664b7c77f vmalloc: fix NULL pointer dereference in is_vm_area_hugepages()
  • 648a3960e366 pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39
  • 44cff0737127 pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39
  • f775e7bda9a4 scsi: target: Remove tcm_loop target reset handling
  • c2bd9fdb448d scsi: target: Fix hexadecimal CHAP_I handling
  • 0404baeb9e43 pinctrl: qcom: Fix resolving register base address from device node
  • 298821692d44 watchdog: unregister PM notifier on watchdog unregister
  • 637ef4961470 configfs: fix lockless traversals of ->s_children
  • f25d6e4ec4c2 firmware_loader: Fix recursive lock in device_cache_fw_images()
  • 9e82497138ab ASoC: amd: acp-sdw-sof: Bound DAI link iteration
  • 1279bdab5fa1 ASoC: amd: acp-sdw-legacy: Bound DAI link iteration
  • e8d89baf9217 spi: ep93xx: fix double-free of zeropage on DMA setup failure
  • e123f0ab02d0 IB/mlx5: Don't mangle the mr->pd inside the rereg callback
  • fd284b12810e IB/mlx5: Pull the pdn out of the depths of the umr machinery
  • 8119fe468b01 IB/mlx5: Remove unused mkc bits in mlx5r_umr_update_mr_page_shift()
  • d4f84bfa089f IB/mlx5: Properly support implicit ODP rereg_mr
  • f5657d399b7e IB/mlx5: Don't take the rereg_mr fallback without a new translation
  • c213b71a2d41 btrfs: don't force DIO writes to be serialized
  • 920dcf1cb8da thermal: testing: reject missing command arguments
  • dde04550fd6f cpufreq: Documentation: fix conservative governor freq_step description
  • 6cb635ad1006 ACPI: IPMI: Fix message kref handling on dead device
  • b7474f4432dd bpf: Fix NULL pointer dereference in bpf_task_from_vpid()
  • 84932636d020 powerpc/8xx: implement get_direction() in cpm1
  • 8daa1a64711e kunit:tool: Don't write to stdout when it should be disabled
  • 8b0510cc3a4a bpf: Fix NMI/tracepoint re-entry deadlock on lru locks
  • 74ac1ce1f4af ALSA: seq: Clear variable event pointer on read
  • c04e0cde2fa3 riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe
  • 834d4cc067fa riscv: cpu_ops: Change return value type of cpu_is_stopped() to bool
  • 4b2b6bc7f5eb ALSA: seq: Fix partial userptr event expansion
  • af8f0ea1f0a3 wifi: wcn36xx: fix OOB read from short trigger BA firmware response
  • f03782f7f41f wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication
  • 1b5d8a248c3a wifi: wcn36xx: fix heap overflow from oversized firmware HAL response
  • 495e7e832c67 bpf: Update transport_header when encapsulating UDP tunnel in lwt
  • efe57b72196a bpf: Check tail zero of bpf_prog_info
  • 58513d6d1241 bpf: Check tail zero of bpf_map_info
  • 2eb39de4962f bpf: Clear rb node linkage when freeing bpf_rb_root
  • f6183983ce1f RDMA/siw: Fix endpoint/socket association handling
  • 04255bda8d79 arm64: dts: imx8mp-kontron: Fix GPIO for display power switch
  • e6ab22200e44 arm64: dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as well
  • f3ef944c5599 arm64: dts: lx2162a-clearfog: use rev2 SoC dtsi
  • b5087fc4ef1f arm64: dts: imx95: Correct PCIe outbound address space configuration
  • ab4b5a07e1c1 arm64: dts: imx8mp-kontron: Reduce EERAM SPI clock frequency
  • f9173e0fc026 RDMA/irdma: Initialize iwmr->access during MR registration
  • 54cab78df037 RDMA/irdma: Fix OOB read during CQ MR registration
  • 844a1ae78e22 ALSA: hda: fix Kconfig dependency of HD Audio PCI
  • 47831b503ecb IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path()
  • fe5414d6b399 RDMA/hfi1: Open-code rvt_set_ibdev_name()
  • 77b4bfc1ce32 netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp
  • d53eecbca16f netfilter: conntrack: revert ct extension genid infrastructure
  • e6665d36b37b x86/cpu: Remove obsolete aperfmperf_get_khz() declaration
  • dd0d22fdae4c ALSA: usb-audio: qcom: Initialize offload control return value
  • 8ebc31b86dcc netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock
  • 5c9c67cf7a3d netfilter: synproxy: fix unaligned memory access in timestamp adjustment
  • b171119082ba netfilter: synproxy: adjust duplicate timestamp options
  • 4dbb71c046f7 netfilter: synproxy: drop packets if timestamp adjustment fails
  • dce1e3cf735d netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags
  • 7b819a84f1d5 netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures
  • c3ebf67cf8a9 ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release()
  • a087b2d3411e ocfs2/dlm: require a ref for locking_state debugfs open
  • 3fa7139b5f42 ocfs2: reject FITRIM ranges shorter than a cluster
  • 0e389fc290c3 ocfs2: fix buffer head management in ocfs2_read_blocks()
  • 3fe2d0d21c8a lib: kunit_iov_iter: repeatedly call alloc_pages_bulk()
  • bb44a7690a4d ocfs2: rebase copied fsdlm LVB pointers in locking_state
  • 9af58d10d0d8 of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails
  • 9a030fcb4b19 drm/amdkfd: always resume_all after suspend_all
  • b8d15e85596a cxl/fwctl: Fix __fortify_panic
  • b64120d54278 xfrm: fix NAT-related field inheritance in SA migration
  • ac9e29b191a0 perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains
  • 58cbb1c2aadf perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems
  • 4e18e9361aab perf/x86/amd/core: Always use the NMI latency mitigation
  • f5102e0fc3c6 iommu/vt-d: Fix RB-tree corruption in probe error path
  • 7f229d27bf27 vhost: fix vhost_get_avail_idx for a non empty ring
  • 73f9f54d7174 bpftool: Use libbpf error code for flow dissector query
  • 4beed798daf4 drm/amdgpu: set sub_block_index for mca ras sub-blocks
  • e82d515092a0 ext4: fix fast commit wait/wake bit mapping on 64-bit
  • 8cbd587e8cdb lockdep/selftests: Restore sched_rt_mutex state on PREEMPT_RT
  • 8d5ed4810e47 lockdep/selftests: Restore migrate_disable() state on PREEMPT_RT
  • c3b073a209a9 configfs_lookup(): don't leave ->s_dentry dangling on failure
  • 778bb4939d45 riscv: dts: sophgo: sg2042: use hex for CPU unit address
  • efe71fbced52 riscv: dts: sophgo: sg2044: use hex for CPU unit address
  • 5a1168ba0a95 lib/test_meminit: use && for bools
  • 377758884852 tick/sched: Fix TOCTOU in nohz idle time fetch
  • 5cf2c85b1231 bpf: Reject exclusive maps for bpf_map_elem iterators
  • 0830287cc6cb driver core: Use system_percpu_wq instead of system_wq
  • 5e406928404d nvme: fix FDP fdpcidx bounds check
  • 36bdda0c86d5 sched: restore timer_slack_ns when resetting RT policy on fork
  • ffa974b2f50a ext2: fix ignored return value of generic_write_sync()
  • 8d763babb2a2 mm/fake-numa: fix under-allocation detection in uniform split
  • 61f197297282 bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs
  • d81370c6c4f5 scsi: ufs: Fix wrong value printed in unexpected UPIU response case
  • 846052542cfa scsi: pm8001: Fix error code in non_fatal_log_show()
  • 0de14eae6de8 libbpf: Skip max_entries override on signed loaders
  • abe383999640 libbpf: Skip initial_value override on signed loaders
  • b6862b6a25c6 libbpf: Reject non-exclusive metadata maps in the signed loader
  • 3a0f73d27a8d bpf: Reject exclusive maps as inner maps in map-in-map
  • 91ca9eab008b scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans"
  • 5c53406098b5 nvdimm/btt: Handle preemption in BTT lane acquisition
  • d292b30e1b74 x86/cpu: Keep the PROCESSOR_SELECT menu together
  • 901802925ebe ARM: imx31: Fix IIM mapping leak in revision check
  • 617a5a67ce01 ata: libata: Fix ata_exec_internal()
  • cfcea221db93 wifi: ath12k: fix NULL deref in change_sta_links for unready link
  • eb9b89baf308 wifi: ath12k: fix incorrect HT/VHT/HE/EHT MCS reporting in monitor mode
  • adf0eb748d21 HID: wiimote: Fix table layout and whitespace errors
  • 2d642797dd1c ARM: imx3: Fix CCM node reference leak
  • f0742d09eb6b NFSD: Fix delegation reference leak in nfsd4_revoke_states
  • 9e565962d999 ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble
  • 8ec64276ecd2 spi: atmel: fix DMA channel and bounce buffer leaks
  • ab4d04bf8b2f ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback
  • 803087a16a4e libbpf: Skip endianness swap when loader generation failed
  • f3389fbaff1a libbpf: Skip hash computation when loader generation failed
  • a441c0794ac2 selftests/bpf: add verification for BPF_PROG_QUERY attr size boundaries
  • a7131340d0f9 bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat
  • 5ac9e793ba25 raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path
  • b7313f23ea5a md/raid10: reset read_slot when reusing r10bio for discard
  • e04e384274f8 rpmsg: use generic driver_override infrastructure
  • 0e2f0833556c Drivers: hv: vmbus: use generic driver_override infrastructure
  • d2cf52ba2803 cdx: use generic driver_override infrastructure
  • b41923dbf676 amba: use generic driver_override infrastructure
  • ff4e38a37ba5 media: qcom: venus: relax encoder frame/blur step size on v6
  • bc7c166cc101 media: qcom: venus: relax encoder frame/blur dimension steps on v4
  • ffe754288750 media: qcom: venus: drop extra padding in NV12 raw size calculation
  • f8f48c851a0d Revert "media: venus: hfi_platform: Correct supported codecs for sc7280"

View originalPermalink
How 6.18.41-rt-xanmod1 went

6.18.41-xanmod1

Changed 1
  • Expand timer_[re]arm() callbacks with a boolean return value in posix-timers
Fixed 1
  • Prevent UAF caused by non-leader exec() race in posix-cpu-timers

From XanMod Kernel

  • 929ca27d531b Linux 6.18.41-xanmod1
  • 1c784dbe2a35 Merge tag 'v6.18.41' into 6.18
  • 2fe596715f84 Linux 6.18.41
  • 6a7ecc25abe6 posix-cpu-timers: Prevent UAF caused by non-leader exec() race
  • 9f7268928ac0 posix-timers: Expand timer_[re]arm() callbacks with a boolean return value
View originalPermalink
How 6.18.41-xanmod1 went

7.1.5-xanmod1

Added 1
  • Add cancel helper for async requests in firmware_loader
Changed 4
  • Update TCP 'bbr' congestion control module to BBRv3
  • Wait for pre-firmware load in usb: atm: ueagle-atm .disconnect()
  • Remove function entry/exit debug messages from usb: atm: ueagle-atm
  • Use dev_dbg() for 'device found' message in usb: atm: ueagle-atm
Fixed 14
  • Prevent UAF caused by non-leader exec() race in posix-cpu-timers
  • Fix Color Manager (3DLUT, Shaper, Blend) in drm/amd/display
  • Fix implicit declaration of brelse() in exfat
  • Validate session type before performing operation in liveupdate
  • Add newly added RTGs to the free pool in xfs growfs
  • Use opener credentials for FSCTL mutations in ksmbd
Removed 1
  • Remove crypto_rng interface from crypto: xilinx-trng

From XanMod Kernel

  • 2fb7a627a9c6 Linux 7.1.5-xanmod1
  • 022aeb4a9152 tcp_bbr: v3: update TCP 'bbr' congestion control module to BBRv3 [v7.1.5+]
  • c50e105d5af1 Merge tag 'v7.1.5' into 7.1
  • 8392dcae53e5 Revert "tcp_bbr: v3: update TCP 'bbr' congestion control module to BBRv3"
  • 155b42bec9cb Linux 7.1.5
  • 872380f930c9 Revert "gpib: cb7210: Fix region leak when request_irq fails"
  • ad1cafa1bdaa posix-cpu-timers: Prevent UAF caused by non-leader exec() race
  • 60325bf5e2c1 posix-timers: Expand timer_[re]arm() callbacks with a boolean return value
  • 5638dbfe9cf1 drm/amd/display: Fix Color Manager (3DLUT, Shaper, Blend)
  • 570967e9c615 iomap: consolidate bio submission
  • e2f0122bd566 exfat: fix implicit declaration of brelse()
  • 8e4e884f1bef exfat: add data_start_bytes and exfat_cluster_to_phys_bytes() helper
  • 390f1d72a478 exfat: add balloc parameter to exfat_map_cluster() for iomap support
  • 69b31ef6f853 exfat: replace unsafe macros with static inline functions
  • 9634db561e15 crypto: xilinx-trng - Remove crypto_rng interface
  • 3dc8a46d08a8 liveupdate: validate session type before performing operation
  • ddcdac47e1f2 usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()
  • 53430a3768b5 usb: atm: ueagle-atm: remove function entry/exit debug messages
  • 10cfea5091f0 usb: atm: ueagle-atm: use dev_dbg() for 'device found' message
  • 28f19c97eab4 xfs: add newly added RTGs to the free pool in growfs
  • 615104cd66f8 xfs: factor out a xfs_zone_mark_free helper
  • cfb2c6f71d61 ksmbd: use opener credentials for FSCTL mutations
  • cba4ee1092b3 smb: move compression definitions into common/fscc.h
  • 98185b3025be ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
  • 733e76e74e40 Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()
  • a2a2f68c42e0 Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister
  • 4257f45ee1fd binder: cache secctx size before release zeroes it
  • 3f54f2310de0 binder: Use LIST_HEAD() to initialize on stack list head
  • da9e3be9cf31 ALSA: hda/tas2781: Cancel async firmware request at unbind
  • cd992747d717 firmware_loader: Add cancel helper for async requests
  • ac1328962db1 ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417
  • 53e3dcfa74b3 ALSA: scarlett2: Allow selecting config_set by firmware version
  • b80d60249686 iio: hid-sensor-rotation: Fix stale or zero output when reading raw values
  • 3c0dbfecd859 f2fs: fix listxattr handling of corrupted xattr entries
  • aa807064473a f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs()
  • cf8b5937b7b2 f2fs: fix potential deadlock in f2fs_balance_fs()
  • c81e2af41de6 device property: initialize the remaining fields of fwnode_handle in fwnode_init()
  • db20589d7b24 samples/damon/mtier: fail early if address range parameters are invalid
  • 810c9ae71dad mm/damon/core: trace esz at first setup
  • 314bd592085c bpf: Reject negative const offsets for buffer pointers
  • a419421281fb mmc: sdhci-esdhc-imx: fix resume error handling
  • 89b63cd133fe mmc: sdhci-esdhc-imx: make non-fatal errors non-blocking in suspend
  • 6355749aebf6 mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend
  • 9bf4ee05a110 mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt
  • bb72b2398c05 mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore
  • 24300decd8bd mmc: sdhci-esdhc-imx: restore DLL override for DDR modes on resume
  • 48188934d5d2 mmc: sdhci-esdhc-imx: remove unnecessary mmc_card_wake_sdio_irq check for tuning save/restore
  • 657e0acce5b8 mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe() method
  • f59d0244d90b mmc: mmc_test: Fix __counted_by handling after kzalloc_flex() conversion
  • 0e93010b52bb mmc: block: fix RPMB device unregister ordering
  • cb2031f8b226 mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout
  • 791fc00d116e mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout
  • 1773c6e292b0 mtd: rawnand: fsl_ifc: return errors for failed page reads
  • c2e1d3392956 mmc: vub300: defer reset until cmd_mutex is unlocked
  • 09e044192a42 mtd: mchp23k256: use SPI match data for chip caps
  • 9fc23fc52fc9 mtd: onenand: samsung: report DMA completion timeouts
  • 0e65079d28e5 mtd: virt-concat: free duplicate generated name
  • 6126e12bf8c8 wifi: mwifiex: fix permanently busy scans after multiple roam iterations
  • 625fc704b19c wifi: mac80211: validate extension-frame layout before RX
  • 179d9be632d8 wifi: mac80211: free ack status frame on TX header build failure
  • 2b1589fd9a07 wifi: ieee80211: validate MLE common info length
  • 3b0505e43da8 wifi: cfg80211: validate EHT MLE before MLD ID read
  • d5c234774a82 powerpc/uaccess: correct check for CONFIG_PPC_E500 in mask_user_address()
  • 4efa313b1592 powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()
  • d826d3e04c5b reset: sunxi: fix memory region leak on ioremap failure
  • 68176d47421f reset: imx7: Correct polarity of MIPI CSI resets on i.MX8MQ
  • ad1e14710b36 ipvs: reload ip header after head reallocation
  • 905d7a363ade ipvs: fix more places with wrong ipv6 transport offsets
  • 47f0c7d856c6 memstick: ms_block: reject a card that reports too many blocks
  • 492cf7778a55 macsec: fix promiscuity refcount leak in macsec_dev_open()
  • 3cc37687227b llc: fix SAP refcount leak when creating incoming sockets
  • 5c1e8f56d84c crypto: aes - Fix conditions for selecting MAC dependencies
  • f1ca750c0510 Bluetooth: btrtl: validate firmware patch bounds
  • 1b41cbe05b18 net: openvswitch: reject oversized nested action attrs
  • b7f5bd59ed1c regulator: ltc3676: Fix incorrect IRQSTAT bit offsets
  • c8874e338d51 arch/riscv: vdso: remove CFI landing pad from rt_sigreturn
  • 73a7bdf06dbd riscv: vdso: Do not use LTO for the vDSO
  • 185bb156c427 wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
  • a7584f261e64 wifi: mac80211: fix memory leak in ieee80211_register_hw()
  • 564e3fce81eb wifi: mwifiex: fix roaming to different channel in host_mlme mode
  • 56994852d704 wifi: rt2x00: avoid full teardown before work setup in probe
  • 6eb4cf2fa899 net/mlx5: free mlx5_st_idx_data on final dealloc
  • 0b24b11ecda4 powerpc/pseries: fix memory leak on krealloc failure in papr_init
  • cc5c99b606ff mmc: sdhci-esdhc-imx: restore pinctrl before restoring ios timing on resume
  • 90dfffc360df selftests/landlock: Fix screwed up pointers in the scoped_signal_test
  • 19a1785250c7 selftests/landlock: Skip scoped_signal subtest with MSG_OOB if not available
  • 4907f4c2d98b pmdomain: imx: Fix i.MX8MP VC8000E power up sequence
  • 331ee3bc4edf pmdomain: imx: Fix i.MX8MP power notifier
  • 36c2d7728540 pmdomain: mediatek: Fix possible nullptr KP in HWV cleanup/on-check
  • 4ba6d7166750 pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI
  • c17f06d8a085 cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed
  • f45c8d3818da selftests/rseq: Fix a building error for riscv arch
  • 28673209eeea s390/mm: Fix type mismatch in get_align_mask().
  • 83fe36f81200 s390/diag: Add missing array_index_nospec() call to memtop_get_page_count()
  • dd0160a08423 tracing/osnoise: Call synchronize_rcu() when unregistering
  • d5b2752a17ef riscv: Prevent NULL pointer dereference in machine_kexec_prepare()
  • 648d4317326e drbd: reject data replies with an out-of-range payload size
  • f713d7a7e0f2 ata: libata-core: Allow capacity transition to zero for locked drives
  • f723ea50a96d ata: libata-core: Skip HPA resize for locked drives
  • f7628eea9212 fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
  • fa5c7c313018 fs/resctrl: Free mon_data structures on rdt_get_tree() failure
  • 901a489d89ee cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable()
  • c3f200efb454 arm64: smp: Fix hot-unplug tearing by forcing unregistration
  • f50d87f97527 amdkfd: properly free secondary context id
  • 109241d98804 net: macb: drop in-flight Tx SKBs on close
  • 94fe0ab01b48 dibs: loopback: validate offset and size in move_data()
  • c39087ad0b97 macsec: don't read an unset MAC header in macsec_encrypt()
  • 6335ab62d5fc ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
  • e5d0bb887166 ipvs: use parsed transport offset in SCTP state lookup
  • 21a537606fe3 llc: fix SAP refcount leak in llc_ui_autobind()
  • 680d9dcbf428 selftests: net: make busywait timeout clock portable
  • 23d917acd9c9 octeontx2-pf: fix SQB pointer leak on init failure
  • d8b5b66388a5 mac802154: remove interfaces with RCU list deletion
  • ae5347f3db17 s390/monwriter: Reject buffer reuse with different data length
  • b321a046d771 irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure
  • 23afc3786acf mm/compaction: handle free_pages_prepare() properly in compaction_free()
  • 91b4d76dd07f riscv: probes: save original sp in rethook trampoline
  • b770fcfcdced hwmon: (asus_atk0110) Check package count before accessing element
  • 3034e5d67ea6 net: ipa: fix SMEM state handle leaks in SMP2P init
  • 77f0023f22f6 net: wwan: iosm: bound device offsets in the MUX downlink decoder
  • d43efd1b5d97 ata: libata-core: Reject an invalid concurrent positioning ranges count
  • 7ba60286ed14 ata: pata_pxa: Fix DMA channel leak on probe error
  • 299739909c48 ata: libata-core: Add NOLPM quirk for PNY CS900 1TB SSD
  • ae0265f0a95a net/mlx5: HWS, fix matcher leak on resize target setup failure
  • e3d325c0bdb7 orangefs: keep the readdir entry size 64-bit in fill_from_part()
  • aac98ec816b0 tracing/probes: Fix double addition of offset for @+FOFFSET
  • 4a97d08d4ace hwmon: (max1619) add missing 'select REGMAP' to Kconfig
  • 6ee183d89261 fhandle: reject detached mounts in capable_wrt_mount()
  • 2dcebbd1ad2e net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked
  • fffeb2ab5eeb net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked
  • b99e890e6b32 net: lan743x: Initialize eth_syslock spinlock before use
  • ca096be8de31 fsl/fman: Free init resources on KeyGen failure in fman_init()
  • 7ee43ec8e677 hwmon: (occ) unregister sysfs devices outside occ lock
  • 8519e89c7f4d ACPI: TAD: Check AC wake capability before enabling wakeup
  • 4140c516473a net: liquidio: fix BAR resource leak on PF number failure
  • 1f11a29a3c80 hwmon: (w83793) remove vrm sysfs file on probe failure
  • 8a604fe15d03 hwmon: (w83627hf) remove VID sysfs files on error and remove
  • a3020a389cb1 rtc: mpfs: fix counter upload completion condition
  • a36b9528b071 fscrypt: Replace mk_users keyring with simple list
  • 03f1725f91e8 rtc: renesas-rtca3: Fix PIE clear polling condition in alarm setup error path
  • 356077547b1a bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()
  • 0fd23994ec8c ipmi: fix refcount leak in i_ipmi_request()
  • a338ce41bc93 espintcp: use sk_msg_free_partial to fix partial send
  • 7be349d4fcc5 ipmi: Fix user refcount underflow in event delivery
  • e483da960892 LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()
  • 7bcce38cbebd LoongArch: Fix nr passing in set_direct_map_valid_noflush()
  • c97d44a5bdf9 pwm: rzg2l-gpt: Fix period_ticks type from u32 to u64
  • c270eaa919f6 riscv: vdso: Always declare vdso_start symbols
  • fe08be92f2b6 KVM: arm64: Fix propagation of TLBI level in kvm_pgtable_stage2_relax_perms()
  • d1d73a3a37b7 netfilter: nfnetlink_cthelper: cap to maximum number of expectation per master on updates
  • 835a2f9d9f17 drm/xe/userptr: Stub notifier_lock helpers when DRM_GPUSVM=n
  • 1b31e160430c ACPICA: Define acpi_ut_safe_strncpy() as strscpy_pad() alias
  • 227dd2eeab0f net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants
  • fcc621f5b25d platform/x86/amd/pmc: Avoid logging "(null)" for DMI values
  • 744da2443f40 netfilter: nfnetlink_cthelper: cap to maximum number of expectation per master
  • 9a7f7b55d7d0 ksmbd: fix stack buffer overflow in multichannel session-key copy
  • 59da37fee81a octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF
  • 9f8e7f59b0c2 gve: fix header buffer corruption with header-split and HW-GRO
  • d8ce67fa6a5e ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit
  • 7e3630fbb6aa ieee802154: ca8210: fix cas_ctl leak on spi_async failure
  • 2953ec261bcf ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation
  • 638324805895 ieee802154: admin-gate legacy LLSEC dump operations
  • d0c880c9f405 octeontx2-af: Free BPID bitmap on setup failure
  • d4bcc202a353 net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink
  • c38c8b0db3c6 net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
  • d49edcc65e0a net: ipip: require CAP_NET_ADMIN in the device netns for changelink
  • 88b33ee458a6 net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
  • f97e93ebf2f9 net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
  • 11f68ebc6891 net: ena: clean up XDP TX queues when regular TX setup fails
  • 6fed707239c4 selftests: net: fix file owner for broadcast_ether_dst test
  • f7f45ceb855d net/sched: act_ct: preserve tc_skb_cb across defragmentation
  • 91850f582783 net: ixp4xx_hss: fix duplicate HDLC netdev allocation
  • 0c0a8c782148 net: wwan: t7xx: destroy DMA pool on CLDMA late init failure
  • b3763f7e22ec net: ethernet: ti: icssg: guard PA stat lookups
  • 99ae3248b33d net: sit: require CAP_NET_ADMIN in the device netns for changelink
  • f4170f45c251 gpios: palmas: add .get_direction() op
  • a60a40c9ba30 gpio: mt7621: avoid corruption of shared interrupt trigger state
  • b90f24527723 gpio-f7188x: Add support for NCT6126D version B
  • 422a0567cd1b gpio: mt7621: be sure IRQ domain is created before exposing GPIO chips
  • 628c63f96f45 gpio: tegra: do not call pinctrl for GPIO direction
  • e187f6fbc8d6 gpio: mt7621: more robust management of IRQ domain teardown
  • bc650dd5ce64 net: mana: Sync page pool RX frags for CPU
  • 282c5214ca4e net: mana: Validate the packet length reported by the NIC
  • 631d53102da9 cpu: hotplug: Bound hotplug states sysfs output
  • 9f7dc355f62c cpu: hotplug: Preserve per instance callback errors
  • f563358661ea selftests/ftrace: Drop invalid top-level local in test_ownership
  • 571e1f10b599 posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()
  • 83f9fb561c1c locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
  • bcf7968cb97c wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
  • 05b24f68f78f tracing/user_events: Fix use-after-free in user_event_mm_dup()
  • 088873af1359 net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete
  • 618cf6b13950 mmc: vub300: fix use-after-free on probe failure
  • f4cf878dcc4f Input: ims-pcu - fix type confusion in CDC union descriptor parsing
  • 025955847e15 Input: ims-pcu - fix race condition in reset_device sysfs callback
  • bbbe31486cf2 Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing
  • f97bfc1a0766 Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging
  • e555f00621bd Input: ims-pcu - fix logic error in packet reset
  • 47a9889a9325 Input: ims-pcu - fix firmware leak in async update
  • 40693fcc88bc Input: ims-pcu - fix DMA mapping violation in line setup
  • f3c63aecca90 Input: ims-pcu - add response length checks
  • cbfa059dfb48 Input: ims-pcu - validate control endpoint type
  • 8c3095c43291 Input: ims-pcu - release data interface on disconnect
  • 73e6687be0c1 Input: ims-pcu - only expose sysfs attributes on control interface
  • bf0b58ba489d Input: ims-pcu - fix use-after-free and double-free in disconnect
  • 7d330a1d6633 fs/resctrl: Fix use-after-free during unmount
  • 94cbfed19124 scsi: elx: efct: Fix I/O leak on unsupported additional CDB
  • 747eaead2db2 scsi: elx: efct: Fix refcount leak in efct_hw_io_abort()
  • ef2ee18fec92 scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
  • 555a89846ed8 scsi: target: Bound PR-OUT TransportID parsing to the received buffer
  • 1e97c404e449 scsi: xen: scsiback: Free unsubmitted command instead of double-putting it
  • 1357fb32d42a scsi: xen: scsiback: Free the command tag on the TMR submit-failure path
  • 3cbabbf1722e scsi: sg: Report request-table problems when any status is set
  • 0ce5a37f7ddf scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()
  • 782e1bf48672 scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path
  • 6920e62be4c9 accel/ivpu: Reject firmware log with size smaller than header
  • 216e43d93dd4 accel/amdxdna: Use caller client for debug BO sync
  • fff6509d976f accel/amdxdna: reject user command submission without a command BO
  • f7d08603c87b accel/amdxdna: reject command submission on devices without a submit op
  • 5da885c39baa accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap()
  • 15ecfdf0ef6f dma-buf: dma-fence: Fix potential NULL pointer dereference
  • 562d5e6f9b99 dma-fence: use correct callback in dma_fence_timeline_name()
  • e2d9a2ea178a dma-fence: Make dma_fence_dedup_array() robust against 0-count input
  • 752e214b2c6f dm-verity: make error counter atomic
  • e96df7fdbec9 dm-verity: increase sprintf buffer size
  • 81f41d989a32 dm-verity: fix a possible NULL pointer dereference
  • 414650265267 dm-verity: avoid double increment of &use_bh_wq_enabled
  • f7990c2b0f08 dm-verity: fix buffer overflow in FEC calculation
  • 829476c06496 dm-integrity: don't increment hash_offset twice
  • 3d1afaa07462 dm-integrity: fix a bug if the bio is out of limits
  • 8f0af8493009 dm-integrity: fix leaking uninitialized kernel memory
  • 7d8ed7cb844d dm_early_create: fix freeing used table on dm_resume failure
  • f00105be6a59 dm: avoid leaking the caller's thread keyring via the table device file
  • 750b23d4935b dm-stats: fix merge accounting
  • f3441b3bf519 dm-stats: fix dm_jiffies_to_msec64
  • 0cbe13fe5403 dm-pcache: reject option groups without values
  • 79feb87ab239 dm-log: fix a bitset_size overflow on 32bit machines
  • df50c24c6447 dm-ioctl: fix a possible overflow in list_version_get_info
  • 53477ce5ef90 dm-bufio: fix wrong count calculation in dm_bufio_issue_discard
  • bafe3e720cda dm era: fix out-of-bounds memory access for non-zero start sector
  • 9f1a0d27586c dm thin metadata: fix metadata snapshot consistency on commit failure
  • 0562bd39d361 dm thin metadata: fix superblock refcount leak on snapshot shadow failure
  • 17f113e7b622 net: sparx5: unregister blocking notifier on init failure
  • d4cc255f35d5 block: fix IORING_URING_CMD_REISSUE flags check in blkdev_uring_cmd
  • c0f10f43ffa5 block: fix race in blk_time_get_ns() returning 0
  • 02f8ad12545c block: remove redundant GD_NEED_PART_SCAN in add_disk_final()
  • fe1d9121b4b7 selftests/bpf: Cover negative buffer pointer offsets
  • 28ce7bcf8a29 bpf: Add missing access_ok call to copy_user_syms
  • 43f0005f81b8 bpf,fork: wipe ->bpf_storage before bailouts that access it
  • 5a55f9aecc08 bpf: Reset register bounds before narrowing retval range in check_mem_access()
  • 0639ea767fe0 io_uring/bpf-ops: reject re-registration of an already-bound ops
  • 04d23061bbf1 can: bcm: add missing device refcount for CAN filter removal
  • 59bfddea6415 can: bcm: validate frame length in bcm_rx_setup() for RTR replies
  • b6317022b685 can: bcm: track a single source interface for ANYDEV timeout/throttle ops
  • b31d0933509c can: bcm: fix stale rx/tx ops after device removal
  • c312b750bb5a can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()
  • df47f07cdc80 can: bcm: fix CAN frame rx/tx statistics
  • 337f966c0066 can: bcm: extend bcm_tx_lock usage for data and timer updates
  • 30f7bb922cb7 can: bcm: add missing rcu list annotations and operations
  • fc9f5ee1b073 can: bcm: add locking when updating filter and timer values
  • b9c6ac6fb4e0 can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure
  • ce2d4b121fb7 can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF
  • 4f1fdf1a1c31 can: isotp: serialize TX state transitions under so->rx_lock
  • e442b62ba5a7 can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER
  • b8278ff60518 can: isotp: use unconditional synchronize_rcu() in isotp_release()
  • 5832c55b3c82 can: esd_usb: kill anchored URBs before freeing netdevs
  • 046380f3e111 ovl: use linked upper dentry in copy-up tmpfile
  • fd750b694f1f netdev-genl: report NAPI thread PID in the caller's pid namespace
  • fcef60ed5f71 nvmet: fix refcount leak in nvmet_sq_create()
  • 98bcdfa61915 nvmet-rdma: handle inline data with a nonzero offset
  • bc111698b46e nvmet-auth: reject short AUTH_RECEIVE buffers
  • b7d9aaedf024 nvme-apple: Prevent shared tags across queues on Apple A11
  • a192b6c149c6 NFS: Charge unstable writes by request size, not folio size
  • bbd6b2ea966c sctp: validate STALE_COOKIE cause length before reading staleness
  • 077a7bc1c32d spi: uniphier: Fix completion initialization order before devm_request_irq()
  • 40dee2d3e999 spi: imx: reconfigure for PIO when DMA cannot be started
  • 91376c61a5fd time: Fix off-by-one in compat settimeofday() usec validation
  • 947b773caaa5 tpm: Make the TPM character devices non-seekable
  • 98fa6e42fd51 tpm: fix event_size output in tpm1_binary_bios_measurements_show
  • 3ba2b2ef7d6a xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink
  • b4e9dcf4143e xfrm: use compat translator only for u64 alignment mismatch
  • a8a7e6a9ff8a xfrm: nat_keepalive: avoid double free on send error
  • 6883269a3236 xen/gntdev: fix error handling in ioctl
  • 2510434307a2 ufs: core: tracing: Do not dereference pointers in TP_printk()
  • f48d3ae9d320 tcp: Decrement tcp_md5_needed static branch
  • da48b9bf1eb9 tcp: defer md5sig_info kfree past RCU grace period in tcp_connect
  • b7ef06d010c9 ice: fix ice_init_link() error return preventing probe
  • 35176f104612 i2c: spacemit: fix spurious IRQ handling returning IRQ_HANDLED
  • fb267770bf82 i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource()
  • bbc08be46f00 i2c: mediatek: fix WRRD for SoCs without auto_restart option
  • 56ddfc18ea8f i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ)
  • 60ed00d46616 i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
  • c9a0f2bff2cb hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig
  • b9f07a4ec6e3 hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig
  • a0d8e415ebf3 ksmbd: fix integer overflow in set_file_allocation_info()
  • c32f565f3291 smb: client: use kvzalloc() for megabyte buffer in simple fallocate
  • 0bf6482919b9 pkey: Move keytype check from pkey api to handler
  • 301bb780d1b9 platform/x86/amd/pmc: Don't log during intermediate wakeups
  • d53314ae31fd platform/x86/amd/pmc: Add delay_suspend module parameter
  • 675592e86e81 platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops
  • 3002e2dda621 platform/x86/amd/pmc: Check for intermediate wakeup in function
  • 2a42f651cce9 platform/x86: ISST: Restore SST-PP control to all domains
  • 14812174d720 platform/x86: hp-wmi: Add support for Omen 16-ap0xxx (8E35)
  • 4676e81d55ab platform/x86: hp-wmi: Add support for Omen 16-ap0xxx (8D26)
  • b351e082711d platform/x86: dell-laptop: fix missing cleanups in init error path
  • 2137f2154290 platform/x86/intel/tpmi: use cleanup helpers in mem_write()
  • 07ae600bd353 dmaengine: sh: rz-dmac: Move interrupt request after everything is set up
  • 044f7b3252d4 dmaengine: dw-edma-pcie: Reject devices without driver data
  • 070b92cbb82a dmaengine: sh: rz-dmac: Fix incorrect NULL check for list_first_entry()
  • 1553ca96e9df dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK
  • 6e37e9e230c7 dmaengine: tegra: Fix burst size calculation
  • 7d3ce3bd23c0 sunrpc: fix uninitialized xprt_create_args structure
  • 493333f16792 tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt
  • 4bb3e1bc142d tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat()
  • 711cbcb464d2 tpm: restore timeout for key creation commands
  • e5be5d452d5f irqchip/crossbar: Use correct index in crossbar_domain_free()
  • c267911b4226 taskstats: retain dead thread stats in TGID queries
  • f4599793240d mtd: maps: vmu-flash: fix NULL pointer dereference in initialization
  • 57740658042d openrisc: Fix jump_label smp syncing
  • a145b47e22fd mtd: rawnand: Pause continuous reads at block boundaries
  • 007e28b2916d mtd: spi-nor: spansion: use die erase for multi-die devices only
  • 12d4d6922115 mtd: spi-nor: swp: Improve locking user experience
  • 614aa0491c7a s390/pkey: Check length in pkey_pckmo handler implementation
  • 7e7e03848c91 s390/pkey: Check length in PKEY_VERIFYPROTK ioctl
  • 3da8eaf5469e fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header()
  • fe6b606fbf0c net: thunderbolt: Fix frags[] overflow by bounding frame_count
  • 4f6542b14288 bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path
  • e0578493c950 bus: mhi: host: pci_generic: Fix the physical function check
  • f3df5386e3bb fpga: dfl: add bounds check in dfh_get_param_size()
  • 3bfeb436d4be ocfs2: reject non-inline dinodes with i_size and zero i_clusters
  • 60ceecda550e ocfs2: reject dinodes whose i_rdev disagrees with the file type
  • b858f2d57cfc ocfs2: reject dinodes with non-canonical i_mode type
  • 63921f790234 ocfs2: add journal NULL check in ocfs2_checkpoint_inode()
  • 858aa4965ffa ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec
  • 253ed993e0b3 ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits
  • 4d1953d3aeb4 ocfs2: avoid moving extents to occupied clusters
  • 8f575fc17360 mtd: rawnand: fix condition in 'nand_select_target()'
  • 823886a1b089 net/9p: fix infinite loop in p9_client_rpc on fatal signal
  • 3c44f6c62f65 mtd: rawnand: pl353: fix probe resource allocation
  • 20869525a283 ocfs2: use kzalloc for quota recovery bitmap allocation
  • 455519f6b70f mtd: maps: vmu-flash: fix fault in unaligned fixup
  • 9f457beb601d openrisc: Add full instruction cache invalidate functions
  • c8f8e61332ba scsi: sas: Skip opt_sectors when DMA reports no real optimization hint
  • 9fefab759f59 kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES
  • d52d4c9ac716 scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished()
  • 8c1b23d83008 power: supply: bq257xx: Fix VSYSMIN clamping logic
  • 8faccac11e13 9p: skip nlink update in cacheless mode to fix WARN_ON
  • bdcdfc246465 mtd: slram: remove failed entries from the device list
  • 3afd3929fbc7 kcov: use WRITE_ONCE() for selftest mode stores
  • b91e27bce37c mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE
  • 1712a7fa1339 powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors
  • 8e7709aaed66 fs/proc: fix KPF_KSM reported for all anonymous pages
  • b09d5ad00338 proc: only bump parent nlink when registering directories
  • 319caaca072a fs/proc/task_mmu: do not warn on seeing non-migration pmd entry
  • 5ac8f1c56ba1 fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry()
  • 18b8a9700610 fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()
  • 6b7f774b8882 fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race
  • 6b6b5d7c2c95 mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error
  • ee59df7a886a mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs()
  • 837f619f1d98 mm/damon/core: always put unsuccessfully committed target pids
  • 36e4843fe39e riscv: cacheinfo: Fix node reference leak in populate_cache_leaves
  • 2611f7521c6c mm/huge_memory: preserve pmd_swp_uffd_wp on device-private PMD downgrade
  • a1dd41d00c57 mips: sched: Fix CPUMASK_OFFSTACK memory corruption
  • 4d46e07b23d8 selftests/landlock: Test SCOPE_SIGNAL on the SIGIO/fowner pgid path
  • e8631b883338 power: supply: charger-manager: fix refcount leak in is_full_charged()
  • 04916f7dc6d3 landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path
  • 7d7f72cb21a8 ntfs: fix hole runlist memory leak in insert range error path
  • b397b1238a21 ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock()
  • 8f313e92522a ntfs: make system files immutable to prevent corruption
  • 5a5f877c5df7 ntfs: avoid self-deadlock during inode eviction
  • 83f396d881c4 ntfs: sanitize MFT references returned from ntfs_lookup_inode_by_name()
  • d5379035355c ntfs: fail attrlist updates when the superblock is inactive
  • b3d09502b80d ntfs: fix mrec_lock ABBA deadlock in rename
  • a93980141253 ntfs3: fix out-of-bounds read in decompress_lznt
  • 1758a564b6eb ntfs3: validate split-point offset in indx_insert_into_buffer
  • d240f5f9d036 ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head
  • d313416280d4 ntfs3: cap RESTART_TABLE free-chain walker at rt->used
  • 36feda687afe fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}
  • fdf50c788e09 fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
  • 32b9f8733feb fs/ntfs3: validate lcns_follow in log_replay conversion
  • a89c66674283 fs/ntfs3: bound attr_off in UpdateResidentValue against data_off
  • 49c86dae0c0c fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass
  • 554700c65d39 fs/ntfs3: bound DeleteIndexEntryAllocation memmove length
  • 007977325021 fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename
  • b54c9beb90e5 ntfs: reject non-resident records for resident-only attributes
  • bfb01dd319b6 ntfs: validate resident index root values on lookup
  • 18fe978d265b ntfs: validate resident volume name values on lookup
  • 82510cb5c658 ntfs: do not replace volume name after lookup errors
  • 7fb64788812d ntfs: detect mapping-pairs LCN accumulator overflow
  • e2b95d3adb55 ntfs: validate index entries on reading
  • 40ee64e633e5 ntfs: avoid heap allocation for free-cluster readahead state
  • a9cafa8c780f ntfs: only alias volume $UpCase to default on exact match
  • d7773b7af1d2 ntfs: reinit search context before volume information lookup
  • f831ab09d521 ntfs: skip extent mft records in writeback to prevent deadlock
  • b06730c6af58 ntfs: centalize $INDEX_ROOT header validation
  • 0527a81e85ee ntfs: update index root allocated size before shrink
  • aca3d383a23c ntfs: free volume-wide resources on fill_super failure
  • 34a49b3e94a5 ntfs: validate index block header more strictly
  • ceb49c372501 ntfs: not change 0-byte $DATA attribute to non-resident
  • d9d9925de1d8 ntfs: add bounds check before accessing EA entries
  • e4c36dfac57a ntfs: validate attribute values on lookup
  • 353a79fb76bf ntfs: Add WQ_PERCPU to alloc_workqueue users
  • bfe835e535fe ntfs: fix off-by-one in mapping pairs decoding bounds checks
  • 7d702aee1589 ntfs: fix incorrect size of symbolic link
  • 38d444271604 ntfs: grow index root value before reparent header update
  • 57094929cf09 mm/damon/core: make charge_addr_from aware of end-address exclusivity
  • 2f9e3ec17c3d mm/memory_hotplug: fix incorrect altmap passing in error path
  • b785f2bd9496 mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch
  • fc3f0eef426f power: supply: max17042: fix OF node reference imbalance
  • b56a5cbf8f1f power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak
  • b03e62112c9d mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages
  • 3ae86630b94f MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf()
  • 35521e4ec762 MIPS: ip22-gio: fix device reference leak in probe
  • b04bbb89ca3a MIPS: ip22-gio: fix kfree() of static object
  • a018c9b8805c MIPS: ip22-gio: fix gio device memory leak
  • 25bec992181d mm/sparse-vmemmap: fix vmemmap accounting underflow
  • f80fafe24f72 remoteproc: xlnx: Check remote core state
  • e5b1aaa74118 remoteproc: qcom: Fix leak when custom dump_segments addition fails
  • 98414b42530a SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
  • 3a5c55a19cad lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure
  • 3f2dc01b9cb5 lockd: Plug nlm_file leak when nlm_do_fopen() fails
  • 31ba490c02d4 sunrpc: harden rq_procinfo lifecycle to prevent double-free
  • a4f878e8ecd7 sunrpc: wait for in-flight TLS handshake callback when cancel loses race
  • 083e9c2ec7e8 sunrpc: pin svc_xprt across the asynchronous TLS handshake callback
  • c49df5f1e193 pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP
  • ba59b96d8d21 nvdimm/btt: Free arena sub-allocations on discover_arenas() error path
  • 7e49684d90fa nvdimm/btt: Free arenas on btt_init() error paths
  • a58fc10adf50 jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit()
  • fc5eb0962a5e cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size
  • 0ec5c7f03ecf backlight: ktd2801: Enable BL_CORE_SUSPENDRESUME
  • 089ea1e2faf4 mfd: tps6586x: Fix OF node refcount
  • da743704c647 cifs: invalidate cfid on unlink/rename/rmdir
  • 6222b4436865 batman-adv: tt: prevent TVLV OOB check overflow
  • 7d1a877670bc batman-adv: mcast: avoid OOB read of num_dests header
  • 777a88256d6f batman-adv: frag: fix primary_if leak on failed linearization
  • 5a82c5580988 batman-adv: clean untagged VLAN on netdev registration failure
  • 080478388175 batman-adv: frag: free unfragmentable packet
  • ae8355b24abe batman-adv: fix VLAN priority offset
  • aba1cf21954e batman-adv: tt: avoid request storms during pending request
  • 64fd0b0dbb52 batman-adv: dat: fix tie-break for candidate selection
  • dbeb4145d977 batman-adv: ensure minimal ethernet header on TX
  • 4407ff3af469 batman-adv: dat: ensure accessible eth_hdr proto field
  • f4fb97ecf677 batman-adv: bla: reacquire gw address after skb realloc
  • 059a70e1d12d batman-adv: dat: acquire ARP hw source only after skb realloc
  • 9a7b72487981 batman-adv: access unicast_ttvn skb->data only after skb realloc
  • b031fc97e199 batman-adv: retrieve ethhdr after potential skb realloc on RX
  • 916dac5f2944 batman-adv: gw: acquire ethernet header only after skb realloc
  • f79dff8c721b s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()
  • cabcfbc069d8 cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF()
  • a18afd69408c cpufreq: schedutil: Fix uncleared need_freq_update on the .adjust_perf() path
  • fb3b76b5ad2e perf/x86/amd/lbr: Fix kernel address leakage
  • 2e706be56f41 perf/x86/amd/brs: Fix kernel address leakage
  • 64193ed819db x86/boot: Reject too long acpi_rsdp= values
  • 4dad7e870c7e x86/boot: Validate console=uart8250 baud rate to fix early boot hang
  • e5158ff53fdf x86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN"
  • 8a2a0b911cd6 x86/video: Only fall back to vga_default_device() without screen info
  • e8adac69d1bd tools/power/x86/intel-speed-select: Harden daemon pidfile open
  • 2ff8156fd500 mfd: sm501: Fix reference leak on failed device registration
  • 263ccdd627ca leds: uleds: Fix potential buffer overread
  • c9a691350e28 selinux: fix incorrect execmem checks on overlayfs
  • 37d642b37ccd selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()
  • 646ebbc5f2ff selinux: check connect-related permissions on TCP Fast Open
  • fe11d6ce19b2 soc: fsl: qe: panic on ioremap() failure in qe_reset()
  • 9b3325f5a9fb soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy
  • 419d7d930649 gpu/buddy: bail out of try_harder when alignment cannot be honoured
  • 8559b1501f77 gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path
  • 392d033fd372 netfilter: flowtable: use correct direction to set up tunnel route
  • 4ac981a8b7ce netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
  • ec88fa71c820 netfilter: xt_nat: reject unsupported target families
  • 4301ae9ce3d4 netfilter: ecache: fix inverted time_after() check
  • b7a1626c28ba netfilter: xt_physdev: masks are not c-strings
  • 6ff07ac5405b netfilter: nf_conncount: fix zone comparison in tuple dedup
  • 0880c4ed122d netfilter: flowtable: support IPIP tunnel with direct xmit
  • ecb78fbb03d3 netfilter: flowtable: use dst in this direction when pushing IPIP header
  • 00bdce2fda7e netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag
  • 0e76e3e886cc netfilter: nf_nat_sip: reload possible stale data pointer
  • e74f9680e1b6 netfilter: nft_set_pipapo: don't leak bad clone into future transaction
  • b843a96252f6 netfilter: nf_conntrack_sip: validate skb_dst() before accessing it
  • f68305267ebd netfilter: nft_fib: reject fib expression on the netdev egress hook
  • 47b3af24de5f netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst
  • 5b2d4f001001 netfilter: xt_cluster: reject template conntracks in hash match
  • 29e06c8f616c netfilter: nfnl_cthelper: apply per-class values when updating policies
  • eeef3b81f449 netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
  • 214af790e3a3 ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback
  • 03009465312c ASoC: mediatek: mt8183: Release reserved memory on cleanup
  • 80506fcac597 ASoC: mediatek: mt8183: Check runtime resume during probe
  • 4c9df23e121f ASoC: mediatek: mt8192: Release reserved memory on cleanup
  • f6e424835cc0 ASoC: mediatek: mt8192: Check runtime resume during probe
  • 2a591bf6fd41 ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control
  • f4933e1d11b9 ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
  • 6ed7787c43ec ASoC: SOF: topology: fix memory leak in snd_sof_load_topology
  • 2efd9797331a fbdev: tridentfb: fix potential memory leak in trident_pci_probe()
  • ed3b3eb21244 fbdev: nvidia: fix potential memory leak in nvidiafb_probe()
  • 7b96ce9f8e47 fbdev: vesafb: fix memory leak in vesafb_probe()
  • dae8f6ddc35c fbdev: carminefb: fix potential memory leak in alloc_carmine_fb()
  • 2fd16a94bea5 fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe()
  • aa387a3e5180 fbdev: uvesafb: fix potential memory leak in uvesafb_probe()
  • 56964e803915 fbdev: s3fb: fix potential memory leak in s3_pci_probe()
  • 2ede8fa70823 fbdev: i740fb: fix potential memory leak in i740fb_probe()
  • 1b1b43342fbf fbdev: radeon: fix potential memory leak in radeonfb_pci_register()
  • 5276e3f75ddb fbdev: efifb: fix memory leak in efifb_probe()
  • f6a1ac55e6ca fbdev: sm712: Fix operator precedence in big_swap macro
  • 9a94b8553185 fbdev: hecubafb: fix potential memory leak in hecubafb_probe()
  • e818c397548c fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe()
  • a889978ec44f fbdev: metronomefb: fix potential memory leak in metronomefb_probe()
  • bc00e0e376ee KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory
  • 0a5dd8cf4d58 KVM: arm64: nv: Re-translate VNCR before injecting abort
  • 53804b683957 KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN
  • d35defbdfcb1 KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR
  • dd3b237eb778 KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
  • 29227821e232 KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions
  • 7deadbc5dab5 KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2
  • a805ab1914ea KVM: arm64: Ensure level is always initialized when relaxing perms
  • 34d8d7242c52 KVM: arm64: account pKVM reclaim against the VM mm
  • 0cbae0e296d2 KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers
  • 2c87a087c206 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state
  • d5560b6569cd KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails
  • 32bdca80aa81 KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
  • d6b5aba65e99 KVM: TDX: Reject concurrent change to CPUID entry count
  • d2f9df3b615c KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs
  • 124a3769c437 KVM: s390: pci: Fix handling of AIF enable without AISB
  • 7d066368f72e KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal" checks
  • b1a89d12d35a KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling
  • 0658b09cba7f KVM: arm64: vgic: Check the interrupt is still ours before migrating it
  • adce12bb0e0d KVM: s390: pci: Fix GISC refcount leak on AIF enable failure
  • a2e7bbc91cf6 powerpc/pseries/Kconfig: Enable CONFIG_VPA_PMU to be used with KVM
  • ce587046baac KVM: s390: Fix unlikely race in try_get_locked_pte()
  • a4a19941ccb2 KVM: s390: Initialize KVM_S390_GET_CMMA_BITS memory
  • 5fc9690db3bf KVM: s390: vsie: Use mmu cache to allocate rmap
  • eeeb9bc71831 KVM: s390: Silence potential warnings in _gmap_crstep_xchg_atomic()
  • 0c3d4ca328e6 KVM: s390: vsie: Add missing radix_tree_preload() in _gaccess_shadow_fault()
  • bcc6b684fcf6 KVM: s390: vsie: Fix allocation of struct vsie_rmap
  • ac3366245221 LoongArch: KVM: Return full old CSR value from kvm_emu_xchg_csr()
  • 31e99851ee99 LoongArch: KVM: Fix FPU register width with user access API
  • 5c827b66a626 LoongArch: KVM: Check the return values for put_user()
  • d4574547e04a LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt()
  • 8b3e188d19e4 LoongArch: KVM: Validate irqchip index in irqfd routing
  • 81f5b85a5fb0 ARM: dts: stm32: stm32mp15x-mecio1-io: Move expander gpio-line-names to board files
  • 7b5e3c15eee1 ARM: dts: stm32: stm32mp15x-mecio1-io: Fix expander gpio line typo
  • d735c64a1462 ARM: dts: stm32: stm32mp15x-mecio1-io: Move gpio-line-names to board files
  • e61543c0aa5a arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers
  • fc58177cca3b ARM: dts: stm32: stm32mp15x-mecio1-io: Fix GPIO names typo
  • 73e14c8bf53c arm64: dts: imx8ulp-evk: Correct Type-C int GPIO flags
  • 520de5e79dda ARM: dts: stm32: stm32mp15x-mecio1-io: Enable internal ADC reference
  • 0623e082e99a arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc
  • ba13b141ddb5 ARM: dts: stm32: stm32mp15x-mecio1-io: Move divergent mecio1 ADC channels to board files
  • d09c701a531c ARM: dts: stm32: stm32mp15x-mecio1-io: Fix ADC sampling times
  • 12cabe872172 arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Ringneck
  • b5ab9ada87e8 arm64: dts: qcom: sdm630: describe adsp_mem region properly
  • 17b7ab1d26b3 ARM: dts: imx6ul-var-som: fix warning for non-existent dc-supply property
  • 7cc51bb053f6 arm64: dts: renesas: ironhide: Describe inline ECC carveouts
  • 7b71b69719eb arm64: dts: s32g3: Fix SWT8 watchdog address
  • 9b6a94b187f4 arm64: fpsimd: Fix type mismatch in sve_{save,load}_state()
  • b69ad768cd4a net: ife: require ETH_HLEN to be pullable in ife_decode()
  • 463d417a905d octeontx2-vf: clear stale mailbox IRQ state before request_irq()
  • 1ffc164c4744 octeontx2-pf: clear stale mailbox IRQ state before request_irq()
  • 806b7b6edc84 net: atm: reject out-of-range traffic classes in QoS validation
  • 7f72c285f6d3 net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
  • 6acbbe54215d tipc: restrict socket queue dumps in enqueue tracepoints
  • 201b60c4d155 ASoC: SOF: topology: validate vendor array size before parsing
  • 92f90917413b ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get
  • 312c7d2ebe69 ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
  • c29f5b449889 ASoC: SOF: ipc4-control: Validate notification payload size
  • 038406abde0d ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put
  • 00335df9da20 VDUSE: avoid leaking information to userspace
  • 8062ff9d366c vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter
  • 8adebf07b46d mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()
  • cab468c3c03f mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()
  • 708df5274cee idpf: add padding to PTP virtchnl structures
  • 21710f27d55e ring-buffer: Allow sparse CPU masks in ring_buffer_desc()
  • 57e566db78fc tracing/remotes: Fix struct_len in trace_remote_alloc_buffer()
  • 81a7b7ddb07e tracing/remotes: Fix leak in trace_remote_alloc_buffer() error path
  • c25212f274a5 drm/imagination: make pvr_fw_trace_init_mask_ops static
  • 1a638c55f2db smb: client: fix overflow in passthrough ioctl bounds check
  • bf126747e7bf drm/xe: free madvise VMA array on L2 flush failure
  • c69369057b30 drm/xe: remove duplicate <kunit/test-bug.h> include
  • 3cf83432e056 octeontx2-af: fix VF bringup affecting PF promiscuous state
  • 2ae146bcfcc1 ethtool: rss: Fix hfunc and input_xfrm parsing on big endian
  • 7b2fbdafc6de net/mlx5: Fix L3 tunnel entropy refcount leak
  • ddd5ab921fdd selftests/net: fix EVP_MD_CTX leak in tcp_mmap
  • 7d84acf641af drm/fb-helper: Only consider active CRTCs for vblank sync
  • 153d1b8b5bc3 regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK
  • f0eac9c3c371 smb: client: fix busy dentry warning on unmount after DIO
  • b69ea153d30c dm era: fix NULL pointer dereference in metadata_open()
  • d49f6d098ed4 SUNRPC: pin upper rpc_clnt across the TLS connect_worker
  • 9359aac4999e SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED
  • c37abc99bb3d cifs: validate DFS referral string offsets
  • b0640acace25 s390/zcrypt: Remove the empty file
  • 92185d6f7819 ipvs: ensure inner headers in ICMP errors are in headroom
  • f0f35153de83 ipvs: fix PMTU for GUE/GRE tunnel ICMP errors
  • c2ee845e292c ipvs: use parsed transport offset in TCP state lookup
  • 568720055fbd ipvs: pass parsed transport offset to state handlers
  • ef0c7d4b04a0 netfilter: nft_lookup: fix catchall element handling with inverted lookups
  • 95128dc74425 ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer()
  • 1fcabcba272d ipv4: igmp: annotate data-races around timer-related fields
  • 16e5b2dbea49 ipv4: igmp: annotate data-races around im->users
  • 0458ba1cda83 ipv6: mcast: Fix potential UAF in MLD delayed work
  • 8d4394ffa405 ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
  • d73e4d790db6 gpio: mvebu: free generic chips on unbind
  • 46d0fd8535ed perf/x86/amd/core: Avoid enabling BRS from the SVM reload path
  • 543c66cea0e2 octeontx2-pf: check DMAC extraction support before filtering
  • f1e7807df5bf net/sched: cake: reject overhead values that underflow length
  • e3d1ca7882a5 net: mdio: select REGMAP_MMIO instead of depending on it
  • 3861bae3ffe4 selftests: gpio: add gpio-cdev-uaf to .gitignore
  • 5d65dade4d84 drm/v3d: Reject invalid indirect BO handle in indirect CSD setup
  • 91e8109ecffb accel/amdxdna: Fix potential amdxdna_umap lifetime race
  • 6cb18e712feb tracing: Make tracepoint_printk static as not exported
  • 170c008d3f49 drm: Guard DRM_CLIENT_CAP_PLANE_COLOR_PIPELINE
  • 82202fc724f4 gpio: dwapb: Defer clock gating until noirq
  • 8aede22b6a69 net: usb: lan78xx: disable VLAN filter in promiscuous mode
  • 81acef3a247f net/liquidio: drop cached VF pci_dev LUT
  • 40824fc26ad3 net: rnpgbe: fix mailbox endianness and remove pointer casts
  • ebc295ce3436 net/tls: Consume empty data records in tls_sw_read_sock()
  • bea20225c67f accel/amdxdna: Fix VMA access race
  • cf10c506fdbe accel/amdxdna: Use unsigned long for nr_pages in amdxdna_hmm_register()
  • 2d8eeb0578ae accel/amdxdna: Prevent PM resume deadlock in hwctx_sync_debug_bo()
  • 3a63a11897c7 ring-buffer: Fix event length with forced 8-byte alignment
  • d0a2b0c81f11 Bluetooth: L2CAP: fix tx ident leak for commands without a response
  • a8e169d30877 Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
  • 058d0d087a27 Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length
  • 990e65eb9387 Bluetooth: ISO: fix malformed ISO_END/CONT handling
  • 1f9375f55ead Bluetooth: btintel_pcie: Refactor FLR to use device_reprobe()
  • c36895aa1122 Bluetooth: btintel_pcie: Separate coredump work from RX work
  • fb6fc74cc10f Bluetooth: btintel_pcie: Add support for smart trigger dump
  • 4ff5778e8ee3 Bluetooth: btintel_pcie: Support Product level reset
  • a50da115b588 Bluetooth: sco: Fix a race condition in sco_sock_timeout()
  • dbd935a9e056 Bluetooth: MGMT: Fix adv monitor add failure cleanup
  • 32c48c7f6cc8 Bluetooth: 6lowpan: hold L2CAP conn across debugfs control
  • feb3fc2c38ed Bluetooth: 6lowpan: avoid untracked enable work
  • b601c031d4fa drm/i915/ltphy: Fix SSC Enablement bit in PORT_CLOCK_CTL
  • 0b98a503ed1e gpio: shared: make the voting mechanism adaptable
  • 8d12d1fede47 smb: client: preserve leading slash for POSIX absolute symlink targets
  • a1f2ada2e4d3 ksmbd: fix multichannel binding and enforce channel limit
  • 5a632f2f207e amt: fix size calculation in amt_get_size()
  • ce5aa8084329 net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
  • 8e49cd891bda net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload
  • 231a8a4b76cb net: qualcomm: rmnet: validate MAP frame length before ingress parsing
  • 982d6d6bc059 qede: fix off-by-one in BD ring consumption on build_skb failure
  • 952928564cc5 net: microchip: vcap: fix races on the shared Super VCAP block
  • 815515ec68f5 net/mlx5e: Fix publication race for priv->channel_stats[]
  • f5677797b094 net/mlx5e: Fix HV VHCA stats agent registration race
  • abc4c56427f1 net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation
  • 98fc2deffcf1 drm/bridge: analogix_dp: Fix PE/VS value shift mismatch during link training
  • 5a95aa0198af net/mlx5e: TC, skip peer flow cleanup when LAG seq is unavailable
  • 4d720c6c60e1 net/mlx5: LAG, MPESW, Fix missing complete() on devcom error
  • 40cc06bf7147 net/mlx5: LAG, Fix off-by-one in single-FDB error rollback
  • fd2ef924a56f net/mlx5: LAG, extend shared FDB API with group_id filter
  • d14f2dbf727c net/mlx5: LAG, prepare for SD device integration
  • 5092213b9a31 net/mlx5: LAG, replace peer count check with direct peer lookup
  • 3b8b364f97f4 net/mlx5: LAG, factor out shared FDB code into dedicated file
  • 7ac37a167cc6 net/mlx5: Lag, avoid LAG and representor lock cycles
  • db9e44e0ed63 net/mlx5: E-Switch, add representor lifecycle lock
  • 25d4c0948300 net/mlx5: Lag: refactor representor reload handling
  • 6f2cb20d8e28 platform/x86: bitland-mifs-wmi: Fix NULL pointer dereference during suspend/resume
  • 230173cc6105 netfilter: xt_connmark: reject invalid shift parameters
  • 94427ca35943 netfilter: nft_set_rbtree: get command skips end element with open interval
  • d5e39e5eb6b3 netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
  • 905a927b2e6f netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()
  • 00d034fe8230 netfilter: xt_u32: reject invalid shift counts
  • f618cbe9b24c gue: validate REMCSUM private option length
  • ea866cab12db net: usb: net1080: validate packet_len before pad-byte access in rx_fixup
  • 9d343a4889e5 arm64/sysreg: Fix BWE field encoding in ID_AA64DFR2_EL1
  • 79b33d9f1d9c selftests/hid: Cover hid_bpf_get_data() size overflow
  • b56f874e49e6 selftests/hid: Load only requested struct_ops maps
  • f81bc5a709dc HID: bpf: Fix hid_bpf_get_data() range check
  • 3dd3e43f17cd ntfs: avoid stale runlist element dereference in fallocate
  • 6706e332151b iio: dac: mcp47feb02: Fix passing uninitialized vref1_uV for no Vref1 case
  • 9a1479b05bd9 arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range()
  • 67a863ceb348 arm64: Avoid eager DVMSync reclaim batches with C1-Pro SME erratum
  • f7e8117e42b2 HID: core: Fix OOB read in hid_get_report for numbered reports
  • ef649703dce0 HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait()
  • 9a2e36963a3f ntfs: avoid stale runlist element dereference in MFT writeback
  • be47c0472506 netfs: Fix barriering when walking subrequest list
  • 9da2e4275e64 ata: libata-scsi: limit simulated SCSI command copy to response length
  • 35cb43b721c0 ata: sata_gemini: unwind clocks on IDE pinctrl errors
  • 3a303f985c6b cifs: Fix missing credit release on failure in cifs_issue_read()
  • 1acddd3e22dd uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline
  • fa8fd23e3a87 x86/uprobes: Keep shadow stack in sync for emulated CALLs
  • 2b6b3f98d0e9 drm/xe/pt: prevent invalid cursor access for purged BOs
  • 5ff2212f0e07 drm/xe: fix NPD in bo_meminfo()
  • a4208d8032ab drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays
  • 23ee91355e31 drm/xe/hw_engine: Fix double-free of managed BO in error path
  • f1a1909f36b7 drm/xe/userptr: Drop bogus static from finish in force_invalidate
  • ab9ea5c943c7 drm/xe/userptr: Hold notifier_lock for write on inject test path
  • 159f9aa8d2e0 drm/imagination: Fix returned size for DRM_IOCTL_PVR_DEV_QUERY
  • d94b9922b2ae drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()
  • 1a4421c7a561 netfs: Fix folio state after ENOMEM whilst under writeback iteration
  • 89df9c158a25 netfs: Fix writeback error handling
  • 0348e3fa0dfb netfs: Fix writethrough to use collection offload
  • 68fb8a93a34b cachefiles: Fix file burial to take lock when unsetting S_KERNEL_FILE
  • 1188a9846fad netfs: Fix netfs_create_write_req() to handle async cache object creation
  • 7f7780abb4c0 iomap: guard io_size EOF trim against concurrent truncate underflow
  • 3c181e6ff1f4 ovl: fix comment about locking order
  • 26757dac1517 cachefiles: Fix double unlock in nomem_d_alloc error path
  • 8a29e60e2176 minix: avoid overflow in bitmap block count calculation
  • 27ddd3442fc6 iomap: release pages on atomic dio size mismatch
  • 89ec425b454e afs: Fix unchecked-length string display in debug statement
  • d0c8ad418b47 afs: Fix the volume AFS_VOLUME_RM_TREE is set on
  • c9a0b9e5f3d4 afs: Fix premature cell exposure through /afs
  • e94f92fd56c5 afs: Fix lack of locking around modifications of net->cells_dyn_ino
  • 91d8f8e5fd34 afs: Fix vllist leak
  • 9cabf1c86948 afs: Fix leak of ungot volume
  • 1bdbc50e2d41 afs: Use scoped_seqlock_read() rather than manually doing seqlock stuff
  • e3e59ff22a0d afs: Fix missing NULL pointer check in afs_break_some_callbacks()
  • f14dd036fad3 afs: Fix callback service message parsers to pass through -EAGAIN
  • ebfd13c0367a afs: Fix reinitialisation of the inode, in particular ->lock_work
  • 654a546c34f3 afs: Fix misplaced inc of net->cells_outstanding
  • 552d3c0f184a afs: Fix bulk lookup malfunction due to change in dir_emit() API
  • ca9f19505077 afs: Remove erroneous seq |= 1 in volume lookup loop
  • 84e4b9232a32 afs: use kvfree() to free memory allocated by kvcalloc()
  • 6d52ff4c866e afs: Fix directory inode initialisation order
  • 9d6b0f6d437e afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints
  • 462eada939f2 afs: Fix double netfs initialisation in afs_root_iget()
  • bdcd80ff1293 afs: Fix error code in afs_extract_vl_addrs()
  • 47e434da476b fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid
  • fc9332533a58 net/sched: hhf: clear heavy-hitter state on reset
  • d25cdea6226c net/sched: dualpi2: clear stale classification on filter miss
  • d1297a9e2fd6 xen/pvcalls: bound backend response req_id before indexing rsp[]
  • feba85c0eeda pinctrl: meson: restore non-sleeping GPIO access
  • 2ef42bd9a8b7 gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe
  • ed98719be413 ksmbd: fix use-after-free of fp->owner.name in durable handle owner check
  • 15a9e9b8f7f5 ksmbd: reject undersized DACLs before parsing ACEs
  • b0933dede95d net/sched: act_bpf: use rcu_dereference_bh() to read the filter
  • 24e63c47668a selftests: drv-net: tso: don't touch dangerous feature bits
  • 9717091371d7 cxgb4: Fix decode strings dump for T6 adapters
  • 13741bad74d4 virtio_net: disable cb when NAPI is busy-polled
  • c3e5cac47519 sctp: fix addr_wq_timer race in sctp_free_addr_wq()
  • ac39628cb3ef spi: rzv2h-rspi: Fix DMA transfer error handling for signal interruption
  • 9ed0dca2aa05 irqchip/ts4800: Fix missing chained handler cleanup on remove
  • 5459f4f32a8e irqchip/gic-v3-its: Fix OF node reference leak
  • 57e1f2cd6a0e tracing/probes: Make the $ prefix mandatory for comm access
  • d655cca1c6e6 tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry()
  • f4461db8eb8e tracing: eprobe: read the complete FILTER_PTR_STRING pointer
  • 10a33029e1cf tracing/events: Fix to check the simple_tsk_fn creation
  • 8a662d8c05e2 tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg
  • 9acf6f34eb48 tracing/eprobes: Allow use of BTF names to dereference pointers
  • 2c88ad0d06c6 drm/panthor: Interrupt group start/resumption if group_bind_locked() fails
  • 893ed1a7c837 drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced
  • 50556bfe1d6c drm/panthor: Fix panthor_pwr_unplug()
  • 1352cd192e5b drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick()
  • 361adc5343e9 drm/panthor: Fix theoretical IOMEM access in suspended state
  • 1c942c3c5179 drm/panthor: Store IRQ register base iomem pointer in panthor_irq
  • 34eb9945a075 drm/panthor: Split register definitions by components
  • 85c6f80499e6 drm/panthor: Pass an iomem pointer to GPU register access helpers
  • 053522ba6158 drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom()
  • 752a08cfeeea drm/panthor: Keep the reset work disabled until everything is initialized
  • 2946aa6c97ac drm/panthor: Always use the IRQ-safe variant when acquiring the fence lock
  • 8a277a20258d gpio: shared-proxy: always serialize with a sleeping mutex
  • 40cbfa3a28e0 bridge: stp: Fix a potential use-after-free when deleting a bridge
  • b26aa9d99353 net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF
  • b637d6b72661 net: gianfar: dispose irq mappings on probe failure and device removal
  • 14b4cb78c332 net: libwx: fix VMDQ mask for 1-queue mode
  • 2381bf3f484e net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy
  • 3ef79fa3860e usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()
  • 110ccbd28c94 ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump
  • 21f304c2aae4 eth: fbnic: don't cache shinfo across skb realloc
  • fb8a5afe6f1f hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero
  • b0ff6b6ae9c5 hwmon: (pmbus) Fix passing events to regulator core
  • 93b96e723bdc hwmon: adm1275: Prevent reading uninitialized stack
  • 65e7e2b8d71b accel/amdxdna: Fix iommu domain lifetime race during device removal
  • 5bd0d4764039 hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid()
  • 492d0c8f78d4 ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280
  • f3ed74540244 MIPS: mm: Add check for highmem before removing memory block
  • 3aca736e177f MIPS: DEC: Ensure RTC platform device deregistration upon failure
  • 062bcbf8d1f1 sctp: add INIT verification after cookie unpacking
  • f7776052bb23 sctp: fix SCTP_RESET_STREAMS stream list length limit
  • d22829101ab6 net: enetc: check the number of BDs needed for xdp_frame
  • 6d46ab395803 qede: fix out-of-bounds check for cqe->len_list[]
  • c9961336aa5f seg6: validate SRH length before reading fixed fields
  • e1fc4b00b96d net: pse-pd: scope pse_control regulator handle to kref lifetime
  • 151db2b54744 gpio: htc-egpio: use managed gpiochip registration
  • 537e75aeb9cc gpio: mvebu: fail probe if gpiochip registration fails
  • d8df91756890 bpf: Fix insn_aux_data leak on verifier err_free_env path
  • 1c53d16b174d bpf: Mask pseudo pointer values in verifier logs
  • 5c907c11615f riscv: Fix 32-bit call_on_irq_stack() frame pointer ABI
  • d1a22906727b ACPI: RIMT: Only defer the IOMMU configuration in init stage
  • c637ec6a4592 spi: sh-msiof: abort transfers when reset times out
  • b2fa801be46d tracing: probes: fix typo in a log message
  • 3ab06151ffcb ALSA: FCP: Fix NULL pointer dereference in interface lookup
  • b4c34415b82b net: hns3: differentiate autoneg default values between copper and fiber
  • 783dcef78cb0 net: hns3: fix permanent link down deadlock after reset
  • 99f6a07add50 net: hns3: refactor MAC autoneg and speed configuration
  • ac04c2c833dd net: hns3: unify copper port ksettings configuration path
  • 9715ea1ceab7 selftests: tls: size splice_short pipe by page size
  • 522d1d950b9e tipc: avoid busy looping in tipc_exit_net()
  • 1c8393eefa3c tipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy()
  • 46d8d5b02f89 tipc: Store struct sock in struct udp_bearer.
  • 80e9adfed05d udp_tunnel: Pass struct sock to setup_udp_tunnel_sock().
  • ea0eb61029e0 udp_tunnel: Pass struct sock to udp_tunnel_sock_release().
  • cd37bcb67f90 net: enetc: fix potential divide-by-zero when num_vsi is zero
  • 2542ce01d811 dt-bindings: net: renesas,ether: Drop example "ethernet-phy-ieee802.3-c22" fallback
  • 54292b167466 net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync
  • c5fafece300c ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count
  • 0ddb9dcabf0b LoongArch: BPF: Fix off-by-one error in tail call
  • 09068613dd0d LoongArch: BPF: Fix outdated tail call comments
  • ee79d03aafb5 LoongArch: Move struct kimage forward declaration before use
  • fe0669928f27 net: stmmac: dwmac-spacemit: Fix wrong irq definition
  • a77abd7a3490 net: stmmac: dwmac-spacemit: Fix wrong phy interface definition
  • c3e27e4ee524 net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove
  • bc49e8746584 net: sungem: fix probe error cleanup
  • fb42560afec5 tools: ynl: build archives with $(AR)
  • e2087447f562 geneve: validate inner network offset in geneve_gro_complete()
  • 49c2e7c0a699 geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
  • 5bdb33ff6e58 net: mvneta: re-enable percpu interrupt on resume
  • 0fd234bc1264 octeontx2-af: fix CGX debugfs RVU AF PCI reference leaks
  • b1f6381acf9d octeontx2-af: Validate NIX maximum LFs correctly
  • ba933c5f3568 net: phy: realtek: Clear MDIO_AN_10GBT_CTRL_ADV10G bit
  • 7d47925c2c64 net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0
  • cf52622fbc27 net: dsa: mxl862xx: fix use-after-free of DSA ports in crc_err_work
  • 245c6c8a2958 net: dsa: mxl862xx: avoid unaligned 16-bit access in api_wrap
  • c21f7ee511ae net: dsa: realtek: fix memory leak in rtl8366rb_setup_led()
  • a427cfa41796 rtc: cmos: unregister HPET IRQ handler on probe failure
  • 5904fd94f919 rtc: ds1307: Fix off-by-one issue with wday for rx8130
  • cddbfbc71085 smb/client: preserve errors from smb2_set_sparse()
  • 8bbe4dd79645 ACPI: processor_idle: Mark LPI enter functions as __cpuidle
  • 42d4fc933280 ACPICA: Unbreak tools build after switching over to strscpy_pad()
  • 156af6606f36 thermal: testing: zone: Flush work items during cleanup
  • fda07c8e4b54 s390/mm: Fix handling of _PAGE_UNUSED pte bit
  • ca2dbee8fea6 eth: fbnic: fix ordering of heartbeat vs ownership
  • 7a368c754a96 ipv6: fix missing notification for ignore_routes_with_linkdown
  • b91ac71fc2a2 ipv6: fix state corruption during proxy_ndp sysctl restart
  • 764ac02cbd3b ipv6: fix error handling in disable_policy sysctl
  • 420e895fb41d ipv6: fix error handling in forwarding sysctl
  • a39ff02a241c ipv6: fix error handling in ignore_routes_with_linkdown sysctl
  • e28bada56f4f ipv6: fix error handling in disable_ipv6 sysctl
  • 94f55994e19e sctp: fix err_chunk memory leaks in INIT handling
  • e28aedab9488 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
  • 19eec11f3ab5 net: lwtunnel: Drop skb metadata before LWT encapsulation
  • cc27e4514e6e net: usb: lan78xx: restore VLAN and hash filters after link up
  • 4bd2e5dbe623 veth: fix NAPI leak in XDP enable error path
  • 20d4a9dea55b net: ti: icssg: Fix XSK zero copy TX during application wakeup
  • 09efce96c909 net: dsa: sja1105: round up PTP perout pin duration
  • a3d0c8b437ef net: do not acquire dev->tx_global_lock in netdev_watchdog_up()
  • 89c103d702b2 net, bpf: check master for NULL in xdp_master_redirect()
  • 752b781b0c0a Docs/driver-api/uio-howto: document mmap_prepare callback
  • c19faa40b37d alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs
  • 257b55dc3d18 alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
  • 75d7a27c506e NTB: epf: Fix doorbell bitmask and IRQ vector handling
  • bfe11cd91ab0 NTB: epf: Report 0-based doorbell vector via ntb_db_event()
  • 583a4a19eefc NTB: epf: Make db_valid_mask cover only real doorbell bits
  • 9787c2d17111 PCI: endpoint: pci-epf-vntb: Exclude reserved slots from db_valid_mask
  • 9e105f6a14fb ASoC: rt5575: Use __le32 for SPI burst write address
  • 33387bf9bb61 ASoC: SDCA: Validate written enum value in ge_put_enum_double()
  • 0ae6e70edc33 cpuidle: Allow exit latency to exceed target residency
  • c239f2d879ab netfilter: nf_conntrack_helper: cap maximum number of expectation at helper registration
  • e3b7789be80d netfilter: nft_ct: expectation timeouts are passed in milliseconds
  • f32e644fe365 netfilter: nf_conntrack_expect: run expectation eviction with no helper
  • 3401ab813d27 netfilter: nf_conntrack_expect: store master_tuple in expectation
  • 7ec786f4230c netfilter: nf_conntrack_expect: use conntrack GC to reap expectations
  • 743209358ff8 netfilter: conntrack: check NULL when retrieving ct extension
  • ae568b6f16e0 netfilter: nf_conntrack_pptp: move GRE specific cleanup to GRE tracker
  • a1572284b14e netfilter: nf_conntrack_helper: dynamically allocate struct nf_conntrack_helper
  • 40c14ce49963 gpio: davinci: fix IRQ domain leak on devm_kzalloc failure
  • c129b0185e70 netfilter: nft_compat: ebtables emulation must reject non-bridge targets
  • 2f71ca368ffd netfilter: nft_synproxy: stop bypassing the priv->info snapshot
  • 025a41e76b51 netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()
  • be52572c6d55 netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
  • eb14aba91163 netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()
  • 1bb3b6a5c3c5 bpf: Disable xfrm_decode_session hook attachment
  • d684b72dfbd3 md/raid5: avoid R5_Overlap races while breaking stripe batches
  • 4465211d195d md/raid5: use stripe state snapshot in break_stripe_batch_list()
  • a668fa160247 ipv4: fib: Don't ignore error route in local/main tables.
  • c5bd84c6cd77 eth: bnxt: improve the timing of stats
  • 6428634f7a0b ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().
  • 1c89da3baa2b ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE
  • 03ae998ae623 selftests/bpf: Cover small conntrack opts error writes
  • dd74c8020384 bpf: Guard conntrack opts error writes
  • bb3e624808c9 rtc: msc313: fix NULL deref in shared IRQ handler at probe
  • 5f2cfe30af5a e1000e: Reconfigure PLL clock gate timeout and re-enable K1 on Meteor Lake
  • 939756efe505 i40e: Fix i40e_debug() to use struct i40e_hw argument
  • 40c68e35e700 ice: dpll: fix memory leak in ice_dpll_init_info error paths
  • 17c0a9db05e3 ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info
  • 19ec35b79913 rtc: isl1208: Balance enable_irq_wake() with disable_irq_wake() on cleanup
  • 6c70914ab629 ice: call netif_keep_dst() once when entering switchdev mode
  • 4f13a0a479b5 ice: fix AQ error code comparison in ice_set_pauseparam()
  • b1fc5bafbc5f ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs()
  • 0f9278b22cda bpf: Preserve pointer spill metadata during half-slot cleanup
  • 233170ad54d3 PCI: endpoint: pci-epf-vntb: Report 0-based doorbell vector via ntb_db_event()
  • 93a85a6aca19 PCI: endpoint: pci-epf-vntb: Defer pci_epc_raise_irq() out of atomic context
  • 528cfbcc47bb PCI: endpoint: pci-epf-vntb: Document legacy MSI doorbell offset
  • a58543f1e1cc PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0
  • 750dd7546de3 PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0
  • 937f77a79636 ASoC: cs530x: Fix expected MCLK rates for CS5302/4/8
  • 50456f445fee erofs: handle 48-bit blocks_hi for compressed inodes
  • 4137e1ecec9c drm/edid: fix OOB read in drm_parse_tiled_block()
  • 6558811274c8 gpiolib: initialize return value in gpiochip_set_multiple()
  • 7dba66caf98e power: sequencing: fix ABBA deadlock in pwrseq_device_unregister()
  • b584f107ab90 bpf: Fix effective prog array index with BPF_F_PREORDER
  • d977b2aff9f7 bpf: Fix BPF_PROG_ASSOC_STRUCT_OPS last field check
  • 8b996c555575 bpf: zero-initialize the fib lookup flow struct
  • 7faf89ed5b4c bpftool: Fix vmlinux BTF leak in cgroup commands
  • 89cf4d0c71a2 bpf: Fix partial copy of non-linear test_run output
  • db8f1dcf5950 bpf: Fix stack slot index in nospec checks
  • 9242939dd6d9 rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231
  • fc4f78e8f034 rtc: abx80x: fix the RTC_VL_CLR clearing all status flags
  • 84ac7a0f9562 dpaa2-switch: do not accept VLAN uppers while bridged
  • 5a3b2ee1e96d ipv6: ioam: fix type confusion of dst_entry
  • 63d1c23764de ipv6: ndisc: fix NULL deref in accept_untracked_na()
  • f4d7d8fdcc59 net: airoha: Fix skb->priority underflow in airoha_dev_select_queue()
  • 0c3d8fc87e10 net/sched: act_ct: fix nf_connlabels leak on two error paths
  • 44068b6863fb net: emac: Fix NULL pointer dereference in emac_probe
  • d0ab67f7e7cf octeontx2-pf: mcs: Fix mcs resources free on PF shutdown
  • e7f1311e7ef3 octeontx2-pf: Clear stats of all resources when freeing resources
  • a56fd8449de8 octeontx2-af: mcs: Fix unsupported secy stats read
  • e129d1a4c2ba octeontx2-af: npc: cn20k: fix NPC defrag
  • c36cecf9903f net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths
  • 7ce31739fe88 net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone
  • b65289e1c3f3 tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
  • 31d486562062 net: marvell: prestera: initialize err in prestera_port_sfp_bind
  • 8c439591f703 selftests/mm: fix exclusive_cow test fork() handling
  • 214ba4596887 selftests/mm: remove hardcoded THP sizing assumptions in hmm tests
  • 679642fa56d5 selftests/mm: allow PUD-level entries in compound testcase of hmm tests
  • 0481f4bad161 selftests/mm: clarify alternate unmapping in compaction_test
  • 2a018e29ac5f selftests/mm: move hwpoison setup into run_test() and silence modprobe output for memory-failure category
  • 835ef922f3ba selftests/mm: run_vmtests.sh: free memory if available memory is low
  • de72caed5077 selftests/mm: skip uffd-stress test when nr_pages_per_cpu is zero
  • e186a9ac7af4 selftests/mm: ensure destination is hugetlb-backed in hugetlb-mremap
  • e0f39f7671a9 selftest/mm: register existing mapping with userfaultfd in hugetlb-mremap
  • 7c0ba2376d40 selftests/mm: free dynamically allocated PMD-sized buffers in split_huge_page_test
  • 5b136718617a selftests/mm: size tmpfs according to PMD page size in split_huge_page_test
  • aef0f2059a97 selftests/mm: fix cgroup task placement and drop memory.current checks in hugetlb_reparenting_test.sh
  • 4a1e9beaff98 selftests/mm: fix hugetlb pathname construction in hugetlb_reparenting_test.sh
  • 95f64f30431e selftests/mm: restore default nr_hugepages value via exit trap in hugetlb_reparenting_test.sh
  • 65a7bc39d4a2 selftests/mm: fix hugetlb pathname construction in charge_reserved_hugetlb.sh
  • 83d9d5f63cc9 selftests/mm: restore default nr_hugepages value via exit trap in charge_reserved_hugetlb.sh
  • 008ceffd4404 alloc_tag: fix use-after-free in /proc/allocinfo after module unload
  • 810779623104 irqchip/crossbar: Fix parent domain resource leak
  • 74b19383580d mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx()
  • c041d2be785f tpm_crb: Check ACPI_COMPANION() against NULL during probe
  • 4dce8bf588a8 netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak
  • a259780ddf1d netfilter: nf_reject: skip iphdr options when looking for icmp header
  • a75f7745dc8f netfilter: nft_flow_offload: zero device address for non-ether case
  • c3167c9c6433 netfilter: nft_meta_bridge: add validate callback for get operations
  • 94daa48ea7b6 netfilter: nft_payload: reject offsets exceeding 65535 bytes
  • c78bd5195a59 netfilter: ipset: make sure gc is properly stopped
  • 93a775fd67f3 netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
  • 7efd8a1c96c7 netfilter: ipset: Don't use test_bit() in lockless RCU readers in bitmap types
  • 3219d74e4536 netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types
  • c6e635429584 md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry
  • 937c3e44ecaf md/raid1: honor REQ_NOWAIT when waiting for behind writes
  • d1324b41dabd md/raid10: fix writes_pending and barrier reference leaks on discard failures
  • f94031c94eae md/raid10: fix writes_pending leak on write request failures
  • bffbbfcbd939 md/raid1: fix writes_pending and barrier reference leaks on write failures
  • 4fe0635fe604 mac802154: Prevent overwrite return code in mac802154_perform_association()
  • f14802465f59 ieee802154: fix kernel-infoleak in dgram_recvmsg()
  • 4c3717546878 ieee802154: Remove WARN_ON() in cfg802154_pernet_exit()
  • 6fcba77571c5 ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns()
  • 8a4eae78287a ieee802154: Restore initial state on failed device_rename() in cfg802154_switch_netns()
  • 315e1efc3f16 ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone()
  • 8dcf676092ff ACPI: resource: Amend kernel-doc style
  • 172e690bab7a thermal: intel: Fix dangling resources on thermal_throttle_online() failure
  • 02f1d4b40eb4 arm64/hw_breakpoint: reject unaligned watchpoints that would truncate BAS
  • fde42e9f5c59 arm64: static_call: include asm/insns.h
  • 7f8d816a9aa2 netfilter: flowtable: fix and simplify IP6IP6 tunnel handling
  • 68286258698e ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints
  • d9ac4239157e eth: fbnic: take netif_addr_lock_bh() around rx mode address programming
  • 41b70eff0392 selftests: vlan_bridge_binding: Fix flaky operational state check
  • 0b17f320893a netconsole: don't drop the last byte of a full-sized message
  • 825de39f0c35 flow_dissector: check device type before reading ETH_ADDRS
  • 9acbcb89190a net: macb: add TX stall timeout callback to recover from lost TSTART write
  • 9f7cd1e26d2f net: airoha: fix foe_check_time allocation size
  • f5adcb9245ae devlink: Fix parent ref leak on tc-bw failure
  • 21f7e96cf164 devlink: Fix parent ref leak in devl_rate_node_create()
  • dbb6321c2977 dpaa2-switch: fix VLAN upper check not rejecting bridge join
  • e6b8463b7d79 virtio-net: fix len check in receive_big()
  • d654af91739a spi: rpc-if: Use correct device for hardware reinitialization on resume
  • aa80fca32cf7 PCI: iproc: Restore .map_irq() for the platform bus driver
  • ec6fb1ecada8 ALSA: usb-audio: qcom: clear opened when stream enable fails
  • a22356d1f731 ALSA: usb-audio: qcom: reject stream disable with no active interface
  • f09a245f33e5 sctp: hold socket lock when dumping endpoints in sctp_diag
  • 794a0d8bdbb3 net: psample: fix info leak in PSAMPLE_ATTR_DATA
  • e19d38d397d4 octeontx2-af: npc: Log successful MCAM drop-on-non-hit install at debug level
  • 452ec5058ea4 octeontx2-pf: Fix leak of SQ timestamp buffer on teardown
  • 043ed6924c63 selftests/ftrace: Fix trace_marker_raw test on 64K page kernels
  • e5c6debdad28 net: ethernet: mtk_eth_soc: fix supported_interface set after phylink_create
  • bc88744dc556 drm/amdgpu: initialize irq.lock spinlock earlier
  • e33a3bd5cb8d drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm
  • db803223edc4 drm/amd/display: Fix mem_type change detection for async flips
  • db70b4a08211 drm/amd/display: Skip PHY SSC reduction on some 8K panels
  • 7f20ce7b2bcf drm/amdgpu: initialize iter.start in amdgpu_devcoredump_format
  • 1d12ae8b079e drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free
  • e2ab48e8591d ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode
  • 77961e12ea16 perf dso: Set standard errno on decompression failure
  • aa967ae8b256 perf bpf: Validate array presence before casting BPF prog info pointers
  • bfc764f9de65 perf c2c: Fix hist entry and format list leaks in c2c_he_free()
  • 502ee1fe757a perf c2c: Free format list entries when c2c_hists__init() fails
  • 79b92b298b5c perf cs-etm: Bounds-check CPU in cs_etm__get_queue()
  • 2d5a695a9d19 perf cs-etm: Require full global header in auxtrace_info size check
  • f22dbfb71c3d perf cs-etm: Validate num_cpu before metadata allocation
  • 7c7245321599 perf machine: Use snprintf() for guestmount path construction
  • 5a03a2ee17e8 xfrm: validate selector family and prefixlen during match
  • 7394a276f869 xfrm: annotate data-races around xfrm_policy_count[] and xfrm_policy_default[]
  • 041859fd55c8 xfrm: Fix xfrm state cache insertion race
  • f83ef148a94b ALSA: usb-audio: qcom: Free sideband sg_table objects
  • 9104559db16b erofs: call erofs_exit_ishare() before rcu_barrier()
  • a6b17b34aedc i3c: master: Add missing runtime PM get in dev_nack_retry_count_store()
  • b5d5cfea4f23 i3c: master: Update dev_nack_retry_count under maintenance lock
  • 7f29c063c53f spi: dw: fix wrong BAUDR setting after resume
  • a5c5676ad3b0 drm/xe: Fix wa_oob codegen recipe for external module builds
  • ac554ad94361 drm/i915: clear CRTC color blob pointers after dropping refs
  • 9f171aa115ec regcache: Do not overwrite error code when finalizing cache after error
  • e06ad4356915 gpio: mlxbf3: fail probe if gpiochip registration fails
  • 99ab295d8025 perf cs-etm: Reject CPU IDs that would overflow signed comparison
  • 6d2aa8dfea1f perf c2c: Free format list entries when releasing c2c hist entries
  • 62a11653847f perf bpf: Bounds-check array offsets in bpil_offs_to_addr()
  • f9ec0eda83ea perf bpf: Reject oversized BPF metadata events that truncate header.size
  • 3fe6751a0697 perf bpf: Validate func_info_rec_size and sub_id in synthesize_bpf_prog_name()
  • eaab676863cb perf sched: Replace (void*)1 sentinel with proper runtime allocation
  • dd8e455fd91e perf hwmon: Fix fd check to accept fd 0 in hwmon_pmu__describe_items()
  • 97584371d5d8 perf tools: Use snprintf() for root_dir path construction
  • 2367ebcd0d4b perf dso: Set error code when open() fails on uncompressed fallback path
  • c5dcbd5cf007 perf dso: Fix heap overflow in dso__get_filename() on decompressed path
  • df77307da9da perf symbols: Break infinite loop on zero-filled notes in sysfs__read_build_id()
  • 6172d92a7f15 perf symbols: Validate p_filesz before use in filename__read_build_id()
  • 1ce03f1d990e perf symbols: Fix bswap copy-paste error for 32-bit ELF p_filesz
  • a06241a08631 perf maps: Add maps__mutate_mapping
  • abbdd94e6a10 sparc: led: avoid trimming a newline from empty writes
  • f55b1ff89938 accel/ivpu: fix HWS command queue leak on registration failure
  • 30521e7ec4d8 apparmor: fix label can not be immediately before a declaration
  • 4b0c34521747 i3c: master: Prevent reuse of dynamic address on device add failure
  • 8f851cab401c i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev()
  • 50eabb91d2de i3c: master: Defer new-device registration out of DAA caller context
  • fef9bdaa0df0 i3c: master: Ensure Hot-Join operations are stopped on shutdown
  • 08b33dfd457b i3c: master: Consolidate Hot-Join DAA work in the core
  • 21cf9175b370 i3c: master: Serialize i3c_set_hotjoin() with the maintenance lock
  • af6df5d50607 i3c: master: Make hot-join workqueue freezable to block hot-join during suspend
  • 88116f41086a i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring
  • 49a230c2aea4 i3c: mipi-i3c-hci: Fix suspend behavior when bus disable falls back to software reset
  • 4238195ed989 apparmor: Fix inverted comparison in cache_hold_inc()
  • a5c79d44ef19 apparmor: fix uninitialised pointer passed to audit_log_untrustedstring()
  • 3f172fbbe357 apparmor: don't audit files pointing to aa_null.dentry
  • 859ba6c7fc6e apparmor: put secmark label after secid lookup
  • b1abb5340737 apparmor: aa_getprocattr free procattr leak on format failure
  • de91788aa6b8 apparmor: remove unnecessary goto and associated label
  • 393809a05cfb apparmor: release exe file resources on path failure
  • 106e909e12ba apparmor: fail policy unpack on accept2 allocation failure
  • bd30d91f9f22 apparmor: Fix return in ns_mkdir_op
  • 2118a9f7a7ed apparmor: remove or add symlinks to rawdata according to export_binary
  • 73d86ca950b8 apparmor: fix NULL pointer dereference in unpack_pdb
  • dd5f1202f45a apparmor: fix potential UAF in aa_replace_profiles
  • 67ee65ec1a3e apparmor: grab ns lock and refresh when looking up changehat child profiles
  • 4a2c4f2b45dc apparmor: fix rawdata_f_data implicit flex array
  • 6d9147917424 apparmor: aa_label_alloc use aa_label_free on alloc failure
  • ec926b2a351e apparmor: check label build before no_new_privs test
  • 25b262492539 security/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref()
  • b8642f147898 apparmor: fix refcount leak when updating the sk_ctx
  • d680472db988 apparmor: fix race in unix socket mediation when peer_path is used
  • ec95dec9ae2c apparmor: fix shadowing of plabel that prevents cache from being updated
  • 3691a82be209 Revert "PCI/MSI: Unmap MSI-X region on error"
  • 91fbf0de91bc Documentation: ABI: sysfs-class-reboot-mode-reboot_modes: fix doc warnings
  • 375e1defdeb8 sparc: Avoid -Wunused-but-set-parameter in clear_user_page()
  • 63a300151999 xfrm: Fix dev use-after-free in xfrm async resumption
  • 855870e8c59b PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability
  • 972052764672 phy: freescale: phy-fsl-imx8qm-lvds-phy: Fix missing pm_runtime_disable() on probe error path
  • d31244d1732e phy: freescale: phy-fsl-imx8qm-lvds-phy: Use synchronous PM runtime put in reset
  • 393f0bb61545 PCI: mediatek: Use actual physical address instead of virt_to_phys()
  • f66b4e65c4cc dt-bindings: phy: sc8280xp-qmp-pcie: Disallow bifurcation register on Purwa
  • e30fa32cd078 dt-bindings: dma: snps,dw-axi-dmac: Add fallback compatible for CV1800B
  • 65a406f5bbd9 perf symbols: Add bounds checks to read_build_id() note iteration in minimal build
  • e525be3207ed perf symbols: Add bounds checks to elf_read_build_id() note iteration
  • 802257fbe4ea perf bpf: Fix metadata leak in perf_env__add_bpf_info() on duplicate insert
  • 7e841b7b1014 perf bpf: Fix map data leak in bpf_metadata_create() on alloc failure
  • 77373bfa2564 perf bpf: Add NULL check for btf__type_by_id() in synthesize_bpf_prog_name()
  • df7d723d66bd tools lib api: Fix mount_overload() snprintf truncation and toupper range
  • 62adda4bb1b8 tools lib api: Fix filename__write_int() writing uninitialized stack data
  • 908bc5238979 perf tools: Use snprintf() in dso__read_running_kernel_build_id()
  • 1577822e1fa1 perf hwmon: Guard label read against empty or failed reads
  • 2bfaa207732a perf tools: Fix uninitialized pathname on uncompressed fallback in filename__decompress()
  • a11731df15af perf symbols: Bounds-check descsz in sysfs__read_build_id() GNU fallback
  • 354a61c752ea perf hwmon: Fix parse_hwmon_filename() strlcpy buffer overflow
  • f99e250f8085 perf hwmon: Use scnprintf() in hwmon_pmu__for_each_event()
  • 4c7ed5f4ff36 perf hwmon: Fix off-by-one null termination on sysfs reads
  • 6290c0c0fb2b perf tools: Fix thread__set_comm_from_proc() on empty comm file
  • 8532c1725abb perf intel-pt: Fix snprintf size tracking bug in insn decoder
  • 5e5b4cfffb4a perf tools: Use mkostemp() for O_CLOEXEC on temporary files
  • 51d3124590bc perf symbols: Bounds-check .gnu_debuglink section data
  • 519b4ad15b2c perf symbols: Fix signed overflow in sysfs__read_build_id() size check
  • b4333af83c12 tools lib api: Fix missing null termination in filename__read_int/ull()
  • a407a5177cd1 perf pmu: Fix perf_pmu__parse_scale/unit() OOB access on empty sysfs file
  • 1202ebd3a9b4 perf pmu: Fix pmu_id() heap underwrite on empty identifier file
  • 4d72f46d420f perf cs-etm: Queue context packets for frontend
  • c091fe7073b0 perf data convert json: Fix addr_location leak on time-filtered samples
  • d625d9b320c2 perf s390: Fix TEXTREL in Python extension by compiling as PIC
  • 31298d37687b xprtrdma: Return sendctx slot after Send preparation failure
  • d7c531ab477a xprtrdma: Repost Receive buffers for malformed replies
  • 33db78b1b24f xprtrdma: Sanitize the reply credit grant after parsing
  • 118a16a18c59 xprtrdma: Fix bcall rep leak and unbounded peek
  • 69c956c1b67d xprtrdma: Resize reply buffers before reposting receives
  • 96da53e7d6f9 xprtrdma: Document and assert reply-handler invariants
  • ef3b79edf14b xprtrdma: Check frwr_wp_create() during connect
  • 264ccd787191 xprtrdma: Initialize re_id before removal registration
  • ffc077905397 xprtrdma: Fix ep kref imbalance on ADDR_CHANGE
  • f025990647c8 perf tools: Use scnprintf() in build_id__snprintf() and hwmon read_events()
  • a6d9b8184656 perf hists: Fix snprintf() in hists__scnprintf_title() UID filter path
  • 5f3b8ff3f632 perf bpf: Use scnprintf() in snprintf_hex() and synthesize_bpf_prog_name()
  • 01d67b6f44ed perf tools: Add O_CLOEXEC to open() calls in DSO and ELF code
  • a757d523741d perf sched: Fix idle-hist callchain display using wrong rb_first variant
  • 23af74f538b7 perf sched: Bounds-check prio before test_bit() in timehist
  • 2c0461f5393b PCI: rcar-host: Remove unused LIST_HEAD(res)
  • 027c177da2b5 perf tools: NULL bitmap pointers after bitmap_free()
  • eb266a14c16a perf tools: Use perf_env__get_cpu_topology() in machine__resolve()
  • 36d2c15a33ec perf tools: Use scnprintf() in cpu_map__snprint() to prevent overflow
  • 678bb88bb977 perf tools: Fix get_max_num() size_t underflow on empty sysfs file
  • 962c7a1f8f1e platform/x86/intel/vsec: Restore BAR fallback for header walk
  • c99444f6dfca fs/ntfs3: resize log->one_page_buf when adopting on-disk page size
  • 7ae7e98b7143 fs/ntfs3: prevent potential lcn remains uninitialized
  • b052df3a5953 virtio: add missing kernel-doc for map and vmap members
  • a2cc03ee5d34 lockd: Correct kernel-doc status descriptions for NLMv4 GRANTED
  • ec52cdcbf23f PCI: meson: Add missing remove callback
  • 221972a90c56 PCI: meson: Propagate devm_add_action_or_reset() failure
  • f966db2568c4 pwm: rzg2l-gpt: Add missing newlines to dev_err_probe() messages
  • fa7ce7dfbd2d PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro
  • e68035178e65 nfs: use nfsi->rwsem to protect traversal of the file lock list
  • 51e5adebef61 NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write
  • 0fe1ac2bda64 NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors
  • 7471673936d1 nfs: keep PG_UPTODATE clear after read errors in page groups
  • 72c578ca2f9e NFSv4/pnfs: defer return_range callbacks until after inode unlock
  • 8203f760a72b xprtrdma: Decouple req recycling from RPC completion
  • 7c42bc9cb7d3 xprtrdma: Use sendctx DMA state for Send signaling
  • fa977d37765b pNFS/filelayout: fix cheking if a layout is striped
  • f0dfbca47b9e sunrpc: Fix error handling in rpc_sysfs_xprt_switch_add_xprt_store()
  • e2414f2a3f12 clk: qcom: a53: Corrected frequency multiplier for 1152MHz
  • 65e82fa24965 dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor
  • f055829151ee dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc
  • 0bc191050c32 dmaengine: Fix possible use after free
  • c1a2159c1100 dmaengine: qcom: gpi: set DMA_PRIVATE capability
  • fb372cbccab6 mshv: add bounds check on vp_index in mshv_intercept_isr()
  • 89acfa8ad3af docs: memfd_preservation: fix rendering of ABI documentation
  • 2ce2a2e19b62 clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks
  • ca461a2a7390 dt-bindings: clock: qcom: Add X1P42100 camera clock controller
  • a0c08cdaf63a perf sched: Free callchain nodes in idle thread cleanup
  • 5e7c076511bf perf tools: Fix int16_t truncation of max_cpu_num in set_max_cpu_num()
  • cb47a3546f52 perf timechart: Fix cpu2y() OOB read on untrusted CPU index
  • 231acb6d0e14 perf c2c: Fix use-after-free in he__get_c2c_hists() error path
  • 423c520416d7 perf stat: Introduce perf_env__get_cpu_topology() to guard NULL env->cpu
  • 6cfa75ce9a82 perf mmap: Fix NULL deref in aio cleanup on alloc failure
  • f09f7be6bba1 perf sched: Replace BUG_ON and add NULL checks in replay event helpers
  • 6380a4f550dc perf sched: Use thread__put() in free_idle_threads()
  • 1f0a529864d8 perf sched: Fix thread reference leak in idle hist processing
  • 3ba9b69aef73 perf sched: Use is_idle_sample() for idle thread runtime cast guard
  • 340b08cfa751 perf sched: Clean up idle_threads entry on init failure
  • 4884cfb0d36d perf c2c: Bounds-check CPU IDs in setup_nodes() topology loop
  • 937be22cf6d2 perf c2c: Bounds-check CPU and node IDs before bitmap and array access
  • 9cbb9f3e532e perf stat: Bounds-check CPU index in topology aggregation callbacks
  • 5257dfb9619c perf mmap: Guard cpu__get_node() return in aio_bind()
  • 5ea1dcc9418c perf sched: Fix register_pid() overflow, strcpy, and BUG_ON
  • 68b6157d2c62 perf sched: Cap max_cpu at MAX_CPUS in timehist sample processing
  • 380ad7297fa0 perf sched: Fix thread reference leaks in timehist_get_thread()
  • 6587c61570f4 perf tools: Add bounds check to cpu__get_node()
  • bd027a461624 perf tools: Guard remaining test_bit calls from OOB sample CPU
  • e94a56aac6b4 perf sched: Fix comp_cpus heap overflow with cross-machine recordings
  • 70d31bdd3789 perf sched: Fix NULL dereference in latency_runtime_event
  • bbaa0a0441d2 perf sched: Replace BUG_ON on invalid CPU with graceful skip
  • a4ec6bf24145 perf sample: Add file_offset field to struct perf_sample
  • b189fce8d2ac perf sched: Fix thread reference leak in latency_switch_event
  • d88a630bacfa perf tools: Guard test_bit from out-of-bounds sample CPU
  • 885bd036cbdf perf annotate: Fix crashes on empty annotate windows
  • 25b1f78ef352 perf: Fix off-by-one stack buffer overflow in kallsyms__parse()
  • 4442e8c8f20f dt-bindings: dma: nvidia,tegra186-gpc-dma: Make reset optional
  • 4e8f512e2b8f dmaengine: imx-sdma: Refine spba bus searching in probe
  • 3ea71aa629a7 thunderbolt: debugfs: Fix margining error counter buffer leak
  • 994a42b890ce drm/amd/display: Add missing kdoc for ALLM parameters
  • 668791009a21 fs/ntfs3: fix mount failure on 64K page-size kernels
  • bc95e2f61192 ntfs3: avoid another -Wmaybe-uninitialized warning
  • 3cd2212012c0 ntfs3: Allocate iomap inline_data using alloc_page
  • ff825bf0521f fs/ntfs3: call _ntfs_bad_inode() when failing to rename
  • 1f6111ad30d2 fs/ntfs3: fix wrong LCN in run_remove_range() when splitting a run
  • 41081202eb82 fs/ntfs3: add bounds check to run_get_highest_vcn()
  • 3dcdf8ddb509 clk: spacemit: k3: Fix PCIe clock register offset
  • 0b4739fc72db clk: spacemit: k3: Switch to pll2_d6 as parent for PCIe clock
  • d823ab4592b3 docs: changes.rst: restore pahole 1.26 minimum (regressed by sort)
  • 83d87cbfa3aa HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter
  • b7ef2eb23936 clk: at91: keep securam node alive while mapping it
  • 8c00cabb1982 iio: tcs3472: power down chip on probe failure
  • f3d413e701c5 iio: accel: mma8452: handle I2C read error(s) in mma8452_read()
  • 3c374d33f133 iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling
  • fb27ebf81136 iio: magnetometer: ak8975: fix potential kernel stack memory leak
  • 7f167853ef3c iio: light: si1133: prevent race condition on timeout
  • 2413ede67e39 iio: light: si1133: reset counter to prevent race condition
  • 8e8b52ad5ab5 perf header: Validate bitmap size before allocating in do_read_bitmap()
  • ea63c57eb2f1 perf header: Sanity check HEADER_EVENT_DESC attr.size before swap
  • 27ca3f615c1a timers/migration: Update stale @online doc to @available
  • d61e42f63a00 PCI: qcom: Disable ASPM L0s for SA8775P
  • c764d5092b92 powerpc tools perf: Initialize error code in auxtrace_record_init function
  • 0e1db8dc4623 docs: threat-model: add missing closing parenthesis
  • 789d1b0e1118 clk: renesas: rzg2l: Rename iterator in for_each_mod_clock() to avoid shadowing
  • f15a545f7518 gpib: cb7210: Fix region leak when request_irq fails
  • 8b5f1d295dda gpib: fix double decrement of descriptor_busy in command_ioctl()
  • a41f0fbd77ae sonypi: Check ACPI_COMPANION() against NULL at probe time
  • 99a34d028293 hpet: Check ACPI_COMPANION() against NULL at probe time
  • 42223445607a char: tlclk: fix use-after-free in tlclk_cleanup()
  • 49489a18afa5 gpib: Fix inappropriate ioctl error return
  • ecdd8af41197 perf test amd ibs: Fix incorrect kernel version check
  • 684a58dd845e usb: host: max3421: Reject hub port requests for non-existent ports
  • 4da073d57176 usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
  • 7fc162453cfb staging: most: video: avoid double free on video register failure
  • b1493c42183f perf inject: Fix itrace branch stack synthesis
  • 034182b63108 perf event: Fix size of synthesized sample with branch stacks
  • 7e374ac7702b perf build-id: Fix off-by-one bug when printing kernel/module build-id
  • 8b54808fcced clk: microchip: mpfs-ccc: fix peripheral driver registration failures after oob fix
  • b670ac2731dd platform/x86: classmate-laptop: Address memory leaks on driver removal
  • ce5633204a4b PCI: mediatek-gen3: Fix incorrectly skipped pwrctrl error message
  • e31173a19466 PCI: dwc: Fix signedness bug in fault injection test code
  • 8ca9adc80588 coresight: platform: defer connection counter increment until alloc succeeds
  • f344f6ae8517 PCI/pwrctrl: Lock device when calling device_is_bound()
  • ac8a86dcaf59 mailbox: don't free the channel if the startup callback failed
  • 25d6ea6c76e1 mailbox: mtk-adsp: fix UAF during device teardown
  • 8ceeb0541978 mailbox: mpfs: fix check for syscon presence in mpfs_mbox_inbox_isr()
  • 80cf6501acb9 PCI: mediatek-gen3: Do full device power down on removal
  • 8c1dac9c05d4 coresight: Handle helper enable failure properly
  • c37f87151990 coresight: Fix source not disabled on idr_alloc_u32 failure
  • 81ed540159ef soundwire: intel_ace2x: release bpt_stream when close it
  • abdfdb8e6220 iio: light: acpi-als: Check ACPI_COMPANION() against NULL
  • 14622b111e4e clk: at91: sam9x7: Fix gmac_gclk clock definition
  • 8a7a8ac82791 perf pmu: Skip test on Arm64 when #slots is zero
  • 03dda04f2f76 perf unwind: Refactor get_entries to allow dynamic libdw/libunwind selection
  • 9810f833df66 perf pmu-events AMD: Switch l2_itlb_misses to bp_l1_tlb_miss_l2_tlb_miss.all
  • cb329b1fa702 phy: phy-can-transceiver: Check driver match and driver data against NULL
  • 0ba6fd199192 PCI: qcom: Set max OPP before DBI access during resume
  • 72a7bfee9fe8 PCI: dwc: Apply ECRC workaround for DesignWare cores prior to 5.10a
  • f478709f7be8 dt-bindings: clock: qcom,sm6125-dispcc: reference qcom,gcc.yaml
  • 6c7f2108af20 clk: qcom: cmnpll: Account for reference clock divider
  • d1da8fcb8802 coresight: fix missing error code when trace ID is invalid
  • adec0b0df4e2 bus: mhi: ep: Add missing state_lock protection for mhi_state access
  • e30fa2246972 bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
  • 34b2a1076dd7 rust: alloc: fix assert in Vec::reserve doc test
  • 1f95260a8237 PCI: loongson: Do not ignore downstream devices on external bridges
  • f62ffd973b07 PCI: intel-gw: Add .start_link() callback
  • b2dd40f1d15e PCI: intel-gw: Enable clock before PHY init
  • 28c35ea3515f PCI: intel-gw: Move interrupt enable to own function
  • fc9d6f815871 perf tool: Fix missing schedstat delegates and dont_split_sample_group in delegate_tool
  • 6ed3cea56b77 perf sched: Add missing mmap2 handler in timehist
  • f05c3b4c9cc0 platform/x86: xo15-ebook: Fix wakeup source and GPE handling
  • df6d71c9a818 x86/platform/olpc: xo15: Drop wakeup source on driver removal
  • 721ad5b72448 PCI: Check ROM header and data structure addr before accessing
  • 4e82818ead50 PCI: Introduce named defines for PCI ROM
  • d50ba5e4642c PCI/ASPM: Don't reconfigure ASPM entering low-power state
  • 12007c55d9c0 coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore
  • 293dacd5b6a9 coresight: ete: Always save state on power down
  • 9d802907fc2a coresight: tmc: Fix overflow when calculating is bigger than 2GiB
  • e483a406a23a soundwire: fix bug in sdw_add_element_group_count found by syzkaller
  • f0481e6bcc5d soundwire: don't program SDW_SCP_BUSCLOCK_SCALE on a unattached Peripheral
  • fbd5d3168740 coresight: cti: Fix DT filter signals silently ignored
  • 2830eedfcc7d perf callchain: Handle multiple address spaces
  • ffddd64eae0b perf debuginfo: Fix libdw API contract violations
  • 2a86103b44af perf annotate-data: Fix libdw API contract violations
  • 881af00c02c0 perf probe-finder: Fix libdw API contract violations
  • d739d9f4525b perf libdw: Fix libdw API contract violations and memory leaks
  • e542c8800bbc perf srcline: Introduce inline_node__clear_frames()
  • eb0062b3e76d perf dwarf-aux: Fix libdw API contract violations
  • 23ec342a8fa6 perf dwarf-aux: Fix libdw segmentation fault in cu_walk_functions_at
  • 5de04caa46b6 staging: nvec: fix use-after-free in nvec_rx_completed()
  • fde2296f87b7 staging: rtl8723bs: fix stainfo check in rtw_aes_decrypt
  • 697af8745d5c i3c: master: svc: Fix missed IBI after false SLVSTART on NPCM845
  • b0194db10032 gpiolib: acpi: Only trigger ActiveBoth interrupts on boot
  • 4791b91daeb1 eventpoll: Fix epoll_wait() report false negative
  • 8679e9e06876 eventpoll: rename epi->next and txlist for clarity
  • b698ee9abf40 eventpoll: expand top-of-file overview / locking doc
  • 0c44866f4a23 9p: Add missing read barrier in virtio zero-copy path
  • ebbcbe5c0db2 net/9p: fix race condition on rdma->state in trans_rdma.c
  • fdc9043cfd50 9p: avoid returning ERR_PTR(0) from mkdir operations
  • f3dd1e534e9d ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write
  • 17d79248b4f3 mfd: cs42l43: Sanity check firmware size
  • afb1a5af6dd9 mfd: rsmu: Fix page register setup
  • e18ffb7541de mfd: bd72720: Drop BUCK11 ID
  • 0ff82a9cf931 ksmbd: fix use-after-free in same_client_has_lease()
  • 2fface6e0bbd net: serialize netif_running() check in enqueue_to_backlog()
  • bde37aed0724 RDMA/irdma: Replace waitqueue and flag with completion
  • bc4caea7a82b RDMA/hns: Fix memory leak of bonding resources
  • 967099102562 RDMA/bnxt_re: Reject GET_TOGGLE_MEM when toggle page was not allocated
  • 03c9a2fba68e RDMA/bnxt_re: Fail DBR related page allocation UAPIs if the feature is disabled
  • da406b8b49c1 RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
  • 303f6fef95df RDMA/bnxt_re: Proper rollback if the ioremap fails
  • a59d815cbe66 RDMA/bnxt_re: Add a max slot check for SQ
  • a65b5258b14c RDMA/bnxt_re: Enable app allocated QPs
  • 6eceb09df972 RDMA/bnxt_re: Support doorbells for app allocated QPs
  • 2234acd1d1d2 RDMA/bnxt_re: Enhance dbr usecnt logic in doorbell uapis
  • 3169824fd8f4 RDMA/bnxt_re: Update msn table size for app allocated QPs
  • 7605fd8bbf4d RDMA/bnxt_re: Refactor bnxt_re_init_user_qp()
  • 0c403e078676 RDMA/bnxt_re: Avoid displaying the kernel pointer
  • b193854675ec RDMA/bnxt_re: Free CQ toggle page after firmware teardown
  • 0adcd67f3d6f RDMA/bnxt_re: Free SRQ toggle page after firmware teardown
  • 3d00b375853f RDMA/bnxt_re: Initialize dpi variable to zero
  • 5126f099295c ionic: Fix check in ionic_get_link_ext_stats
  • d01d4cfc806a net: ethernet: oa_tc6: Remove FCS size in RX frame
  • 785e3765bf9a net: ti: icssg: Use undirected TX tag for XDP zero copy in HSR offload mode
  • 40a91dcc6260 net: ti: icssg: Use undirected TX tag for native XDP in HSR offload mode
  • b478a6ffda4e net: ti: icssg-prueth: Fix AF_XDP fill ring alloc and wakeup condition
  • ad262d2b96be net: airoha: Fix always-true condition in PPE1 queue reservation loop
  • a210791f3334 tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)
  • 35e0297a93c3 tipc: fix UAF in tipc_l2_send_msg()
  • d2fb2ef76008 KEYS: Use acquire when reading state in keyring search
  • c893bfb0d696 powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus
  • e4e69cee0b01 powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down
  • b504fd953664 powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del
  • 038f068cced8 MIPS: mm: Fix out-of-bounds write in maar_res_walk()
  • e09f7bd72739 bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check
  • 39d44ed6904b sockmap: Fix use-after-free in udp_bpf_recvmsg()
  • bd004716ba75 bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
  • 478c7f68ef25 udf: fix nls leak on udf_fill_super() failure
  • c12e3c9e5224 bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket
  • e68343ee3c13 selftests/bpf: Initialize operation name before use
  • 85100de4f473 selftests/bpf: Fix typo in verify_umulti_link_info
  • c6d51ad36490 bpf: Guard __get_user acesss with access_ok for uprobe_multi data
  • 590d696f846a btrfs: Drop WQ_PERCPU from ordered_flags in btrfs_init_workqueues()
  • 2bc610c9db5d smb/client: always return a value for FS_IOC_GETFLAGS
  • 7839f1817a0c cifs: remove all cifs files before kill super
  • 018b3c8248f5 smb: client: fix conflicting option validation for new mount API
  • b8ca5fcc3182 ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait()
  • 1e8ff78520d9 geneve: Fix off-by-one comparing with GRO_LEGACY_MAX_SIZE
  • edf234f71fb3 netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them
  • db50e2d289b6 netfilter: nf_conncount: callers must hold rcu read lock
  • 1c4c35fb68d5 ALSA: seq: avoid stale FIFO cells during resize
  • 43e10709b1ba ALSA: seq: oss: Serialize readq reset state with q->lock
  • 9684fff87124 kcm: use WRITE_ONCE() when changing lower socket callbacks
  • 6b638db5ec06 net: airoha: Fix debugfs new-tuple display for IPv4 ROUTE entries
  • 2ac37fca3052 net: airoha: Fix register index for Tx-fwd counter configuration
  • be55f99a0b08 octeontx2-af: fix NPC mailbox codes in mbox.h
  • 6be4da4f5a16 net: bcmgenet: Use weighted round-robin TX DMA arbitration
  • d0de5037dce5 landlock: Fix unmarked concurrent access to socket family
  • 467ae77921ad dpll: balance create/delete notifications in _dpll_pin(un)register
  • 8c48e6581c43 dpll: guard sync-pair removal on full pin unregister
  • dc37a9a94954 dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister()
  • 0ea6703cb3dc dpll: send delete notification before unregister in on-pin rollback
  • 75a52d107203 dpll: fix stale iteration in dpll_pin_on_pin_unregister()
  • 4c1b25d85f4c net: wwan: t7xx: check skb_clone in control TX

View originalPermalink
How 7.1.5-xanmod1 went

6.18.40-xanmod1

Fixed 20
  • RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
  • RDMA/bnxt_re: Initialize dpi variable to zero
  • ksmbd: fix durable reconnect double-bind race in ksmbd_reopen_durable_fd
  • perf callchain: Handle multiple address spaces
  • seqlock: fix scoped_seqlock_read kernel-doc
  • perf inject: With --convert-callchain ignore the dummy event for dwarf stacks

From XanMod Kernel

  • 44db62f5aa97 Linux 6.18.40-xanmod1
  • 8b49b49d26aa Merge tag 'v6.18.40' into 6.18
  • 221fc2f4d0ed Linux 6.18.40
  • 478c4d24193f RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
  • b87cbd4d198a RDMA/bnxt_re: Initialize dpi variable to zero
  • 81e6faa5b640 ksmbd: fix durable reconnect double-bind race in ksmbd_reopen_durable_fd
  • 1badb6866482 perf callchain: Handle multiple address spaces
  • 275eb3993094 seqlock: fix scoped_seqlock_read kernel-doc
  • 453cb79a1564 perf inject: With --convert-callchain ignore the dummy event for dwarf stacks
  • 2764d031efd6 PCI: Fix Resizable BAR restore order
  • 2fb74141ec54 PCI: Fix BAR resize rollback path overwriting ret
  • 7425e7d82cb9 perf symbol: Fix ENOENT case for filename__read_build_id
  • a888f3d5970f pinctrl: airoha: fix pinctrl function mismatch issue
  • 267fdd9b6530 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
  • 779480ea7955 iommufd: Move vevent memory allocation outside spinlock
  • 73b5d5cb1f5a iommufd: Propagate allocation failure in iommufd_veventq_deliver_fetch()
  • ea7a76d7d614 KVM: arm64: nv: Re-translate VNCR before injecting abort
  • 459adfc6cd35 KVM: arm64: Deduplicate ASID retrieval code
  • 9d360fb820a3 samples/damon/mtier: fail early if address range parameters are invalid
  • ec976851ad93 mm/damon/core: trace esz at first setup
  • 3b91c35961fa mm/damon/core: always put unsuccessfully committed target pids
  • ba37cd4d8a75 KVM: arm64: Fix propagation of TLBI level in kvm_pgtable_stage2_relax_perms()
  • 19d9996435db KVM: arm64: Ensure level is always initialized when relaxing perms
  • c3a3d3986719 btrfs: fix incorrect buffered IO fallback for append direct writes
  • 998ee7f01ecf btrfs: fix false IO failure after falling back to buffered write
  • a4497a122e27 crypto: qat - fix restarting state leak on allocation failure
  • 6c78081d047c btrfs: remove folio parameter from ordered io related functions
  • 1a648c50a505 btrfs: replace for_each_set_bit() with for_each_set_bitmap()
  • 99d4ae3fbb5b btrfs: concentrate the error handling of submit_one_sector()
  • 382fd8004cc6 crypto: atmel-sha204a - fail on hwrng registration error in probe path
  • 952db4b985c7 usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile
  • 69faa3779250 usb: gadget: f_fs: initialize reset_work at allocation time
  • 8a2fdbf92cdc functionfs: use spinlock for FFS_DEACTIVATED/FFS_CLOSING transitions
  • 5fb0b09180a0 functionfs: switch to simple_remove_by_name()
  • 4744f07f6bb7 functionfs: don't bother with ffs->ref in ffs_data_{opened,closed}()
  • 901c036cf625 functionfs: don't abuse ffs_data_closed() on fs shutdown
  • c3e686025210 new helper: simple_remove_by_name()
  • 509b51327320 usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()
  • b78826a65799 usb: atm: ueagle-atm: remove function entry/exit debug messages
  • 6e5ef54b884f usb: atm: ueagle-atm: use dev_dbg() for 'device found' message
  • 41a4e80d5af0 usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()
  • e534790c4c27 usb: dwc3: Support USB3340x ULPI PHY high-speed negotiation.
  • bce232923aa9 xfs: use bio_reuse in the zone GC code
  • adadb181ad42 xfs: only log freed extents for the current RTG in zoned growfs
  • 47c0e0743302 xfs: add a xfs_groups_to_rfsbs helper
  • 57454944737f bpf: Allow LPM map access from sleepable BPF programs
  • 8fccaeeb9e9c bpf: Consistently use bpf_rcu_lock_held() everywhere
  • 0b92ad64d6e4 bpf: Keep dynamic inner array lookups nullable
  • c447be8d88c3 bpf: Introduce struct bpf_map_desc in verifier
  • dccb3c557879 bpf: Consistently use reg_state() for register access in the verifier
  • 60eed4467429 xfs: initialize iomap->flags earlier in xfs_bmbt_to_iomap
  • 607217f7ad41 hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length
  • 7676ea09beb5 hfs/hfsplus: prevent getting negative values of offset/length
  • f9b4b03ccc9c proc: protect ptrace_may_access() with exec_update_lock (part 1)
  • 07bf18dc63f7 seqlock: Change do_task_stat() to use scoped_seqlock_read()
  • c897fd63762e seqlock: Introduce scoped_seqlock_read()
  • 497c6bae5167 proc: protect ptrace_may_access() with exec_update_lock (FD links)
  • 903d78e5aca7 proc: rename proc_setattr to proc_nochmod_setattr
  • b56400364aed ksmbd: validate NTLMv2 response before updating session key
  • 74c2f0ffb81c ksmbd: Use HMAC-MD5 library for NTLMv2
  • 51c5f7e84cfe ksmbd: Use HMAC-SHA256 library for message signing and key generation
  • bd27d9504d20 ksmbd: Use SHA-512 library for SMB3.1.1 preauth hash
  • 427faaa52b0b ksmbd: track the connection owning a byte-range lock
  • 6a37bc484f12 ksmbd: centralize ksmbd_conn final release to plug transport leak
  • c7c884a1305a ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
  • e205f3e7e8c3 ksmbd: use opener credentials for FSCTL mutations
  • 90a93fb3230c cifs: SMB1 split: Add some #includes
  • ff943e1f3d31 cifs: SMB1 split: Rename cifstransport.c
  • 36da806f7fba Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()
  • 6d0eeebe22ba Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister
  • ef382a6baf0a media: nxp: imx8-isi: Fix use-after-free on remove
  • 4278953ff0cd media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code
  • 49cd5ac6de8d crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()
  • 4b51ee8a40fe staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()
  • 5d76bc296bb5 staging: rtl8723bs: fix spaces around binary operators
  • 48323ebaeeee staging: rtl8723bs: core: move constants to right side in comparison
  • 73cc54326de4 PCI: Skip Resizable BAR restore on read error
  • f33837a75447 PCI: Move Resizable BAR code to rebar.c
  • 2242c75b6328 PCI: Add kerneldoc for pci_resize_resource()
  • 4b5322f0002a PCI: Fix restoring BARs on BAR resize rollback path
  • c18646165f21 PCI: Free saved list without holding pci_bus_sem
  • 534f20cdddc3 PCI: Try BAR resize even when no window was released
  • dbb1d8507dd9 PCI: Change pci_dev variable from 'bridge' to 'dev'
  • 0d1c263e6fd7 PCI/IOV: Adjust ->barsz[] when changing BAR size
  • 0dfad346c293 PCI: imx6: Configure REF_USE_PAD before PHY reset for i.MX95
  • e53d54b92f0c PCI: imx6: Fix reference clock source selection for i.MX95
  • 1228926e1e4d binder: cache secctx size before release zeroes it
  • 79ac87bb1a4c binder: Use LIST_HEAD() to initialize on stack list head
  • 7ed120b1a007 vfio/mlx5: Fix racy bitfields and tighten struct layout
  • f8272331da87 ALSA: hda/tas2781: Cancel async firmware request at unbind
  • 6438d0707087 firmware_loader: Add cancel helper for async requests
  • 1ed7ff33cfc8 ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417
  • ad5c5bdb0f58 ALSA: scarlett2: Allow selecting config_set by firmware version
  • 2745574697ee iio: hid-sensor-rotation: Fix stale or zero output when reading raw values
  • 7f680924c5c2 ACPI: NFIT: core: Fix possible deadlock and missing notifications
  • cf5f93228e7a ACPI: NFIT: core: Use devm_acpi_install_notify_handler()
  • d57d2aae87b2 ACPI: bus: Introduce devm_acpi_install_notify_handler()
  • 34f4d0e4e506 ACPI: driver: Check ACPI_COMPANION() against NULL during probe
  • 3b2628f7682a ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup
  • 83f29da85dc9 crypto: xilinx-trng - Remove crypto_rng interface
  • f84c0bae0e8d mmc: sdhci-esdhc-imx: fix resume error handling
  • 174dc8103ab7 mmc: sdhci-esdhc-imx: make non-fatal errors non-blocking in suspend
  • 5b8f11cbe8ad mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend
  • 4f96903e2fd2 mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt
  • aa276aa6cbfb mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore
  • 52990f6b5752 mmc: sdhci-esdhc-imx: restore DLL override for DDR modes on resume
  • eefcd3ca245c mmc: sdhci-esdhc-imx: remove unnecessary mmc_card_wake_sdio_irq check for tuning save/restore
  • c02237966c19 mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe() method
  • 8d94498cc445 mmc: block: fix RPMB device unregister ordering
  • cf7258f57d18 mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout
  • 4b5de4007e5b mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout
  • de2bc884d887 mtd: rawnand: fsl_ifc: return errors for failed page reads
  • bf9848a22a8e mmc: vub300: defer reset until cmd_mutex is unlocked
  • 04ebd3766861 mtd: mchp23k256: use SPI match data for chip caps
  • ac2d9f6b4f90 mtd: onenand: samsung: report DMA completion timeouts
  • a59cfa165aee wifi: mwifiex: fix permanently busy scans after multiple roam iterations
  • b8df3a993f69 wifi: mac80211: free ack status frame on TX header build failure
  • 90576bd6921a wifi: ieee80211: validate MLE common info length
  • 584657c5fc58 wifi: cfg80211: validate EHT MLE before MLD ID read
  • 3c1e92f75e11 powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()
  • 82753ac86cb3 reset: sunxi: fix memory region leak on ioremap failure
  • 3fb7edd2018b ipvs: reload ip header after head reallocation
  • d4ec18f48ce7 ipvs: fix more places with wrong ipv6 transport offsets
  • 39151f0708c8 memstick: ms_block: reject a card that reports too many blocks
  • a75d2b5249e3 macsec: fix promiscuity refcount leak in macsec_dev_open()
  • fd701fc0d065 llc: fix SAP refcount leak when creating incoming sockets
  • 6744ab60dfac Bluetooth: btrtl: validate firmware patch bounds
  • dbd14f736be0 net: openvswitch: reject oversized nested action attrs
  • 6926d13865aa regulator: ltc3676: Fix incorrect IRQSTAT bit offsets
  • 688bd4c6144d riscv: vdso: Do not use LTO for the vDSO
  • 55b26abb1fa1 wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
  • bdc0b8bfdc14 wifi: mac80211: fix memory leak in ieee80211_register_hw()
  • 65446b85595a wifi: mwifiex: fix roaming to different channel in host_mlme mode
  • 816559409e34 wifi: rt2x00: avoid full teardown before work setup in probe
  • 262da8b6ea03 net/mlx5: free mlx5_st_idx_data on final dealloc
  • 9b8df4da2cf7 powerpc/pseries: fix memory leak on krealloc failure in papr_init
  • afa0db5322c5 mmc: sdhci-esdhc-imx: restore pinctrl before restoring ios timing on resume
  • d94160a5d1ac selftests/landlock: Fix screwed up pointers in the scoped_signal_test
  • ba481c0b5376 selftests/landlock: Skip scoped_signal subtest with MSG_OOB if not available
  • 4ff3960f3527 pmdomain: imx: Fix i.MX8MP VC8000E power up sequence
  • 9a0464fcfae4 pmdomain: imx: Fix i.MX8MP power notifier
  • c844b7d9a958 cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed
  • 8131a91fe2de selftests/rseq: Fix a building error for riscv arch
  • 3dfec7490f3a s390/mm: Fix type mismatch in get_align_mask().
  • c6b4d454865a s390/diag: Add missing array_index_nospec() call to memtop_get_page_count()
  • fad36954b295 tracing/osnoise: Call synchronize_rcu() when unregistering
  • eadd0c2c76ae riscv: Prevent NULL pointer dereference in machine_kexec_prepare()
  • 38cc4867540a drbd: reject data replies with an out-of-range payload size
  • 91ec52dd2a5d ata: libata-core: Allow capacity transition to zero for locked drives
  • 7a9a69641b68 ata: libata-core: Skip HPA resize for locked drives
  • 52007bfdce53 fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
  • 1155a9d0a2e0 fs/resctrl: Free mon_data structures on rdt_get_tree() failure
  • ccdf1770a4ba cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable()
  • 5f5783c7806f arm64: smp: Fix hot-unplug tearing by forcing unregistration
  • 26b131b2d5b5 net: macb: drop in-flight Tx SKBs on close
  • b2f426a9a228 dibs: loopback: validate offset and size in move_data()
  • 2cf10d042562 macsec: don't read an unset MAC header in macsec_encrypt()
  • 83fb4c2c5344 ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
  • 247d055504dc ipvs: use parsed transport offset in SCTP state lookup
  • 61a7ff4a6200 llc: fix SAP refcount leak in llc_ui_autobind()
  • 685fb410d90e selftests: net: make busywait timeout clock portable
  • 5df30f05db96 octeontx2-pf: fix SQB pointer leak on init failure
  • 77caf2d6eba7 mac802154: remove interfaces with RCU list deletion
  • f0745496f7c1 s390/monwriter: Reject buffer reuse with different data length
  • a5a367756926 irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure
  • 018d7ad26cb8 mm/compaction: handle free_pages_prepare() properly in compaction_free()
  • 2faf0198168d riscv: probes: save original sp in rethook trampoline
  • d8d4fa0c4f81 hwmon: (asus_atk0110) Check package count before accessing element
  • 07f5eb6d268a net: wwan: iosm: bound device offsets in the MUX downlink decoder
  • 1286a4156333 ata: pata_pxa: Fix DMA channel leak on probe error
  • 1dce4f4bb3c1 net/mlx5: HWS, fix matcher leak on resize target setup failure
  • 82fc886e244c orangefs: keep the readdir entry size 64-bit in fill_from_part()
  • 2c76c01a505c tracing/probes: Fix double addition of offset for @+FOFFSET
  • b4427ee3667c hwmon: (max1619) add missing 'select REGMAP' to Kconfig
  • 6c52226072a3 fhandle: reject detached mounts in capable_wrt_mount()
  • e2b7ee61989f net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked
  • 5889064919a1 net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked
  • 99a6f37b113c net: lan743x: Initialize eth_syslock spinlock before use
  • ac58088d70b8 fsl/fman: Free init resources on KeyGen failure in fman_init()
  • f0aad157576d hwmon: (occ) unregister sysfs devices outside occ lock
  • 715cce38424f net: liquidio: fix BAR resource leak on PF number failure
  • 664480021f6a hwmon: (w83793) remove vrm sysfs file on probe failure
  • c6c990f7208c hwmon: (w83627hf) remove VID sysfs files on error and remove
  • 8dc6c7e8c967 rtc: mpfs: fix counter upload completion condition
  • 6e21d1253ef1 rtc: renesas-rtca3: Fix PIE clear polling condition in alarm setup error path
  • 6c98ccdb9a09 bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()
  • f5c506596302 ipmi: fix refcount leak in i_ipmi_request()
  • a66d45e0ce6d espintcp: use sk_msg_free_partial to fix partial send
  • ddbb6e3dc9bb ipmi: Fix user refcount underflow in event delivery
  • a65f49b6f7ec LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()
  • 20ac8131f8c9 LoongArch: Fix nr passing in set_direct_map_valid_noflush()
  • 612cda6630f2 pwm: rzg2l-gpt: Fix period_ticks type from u32 to u64
  • 4b73889941b9 selftests/bpf: Add simple strscpy() implementation
  • da7f17c2d5bb KVM: TDX: Account all non-transient page allocations for per-TD structures
  • d0cc2c74060b drm/xe/userptr: Stub notifier_lock helpers when DRM_GPUSVM=n
  • 6cec36c795c0 net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants
  • 55da782eb454 platform/x86/amd/pmc: Avoid logging "(null)" for DMI values
  • 35267819b250 gve: fix header buffer corruption with header-split and HW-GRO
  • 2059c28bd725 ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit
  • cb5cca1d2a90 ieee802154: ca8210: fix cas_ctl leak on spi_async failure
  • 314f21c9dd0d ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation
  • 1905ebabe638 ieee802154: admin-gate legacy LLSEC dump operations
  • 19c148cb82d1 octeontx2-af: Free BPID bitmap on setup failure
  • 234cd54fc500 net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink
  • 03d8843b143e net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
  • 68cadc3698c7 net: ipip: require CAP_NET_ADMIN in the device netns for changelink
  • 9571af2eec80 net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
  • 0b2f9c908f93 net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
  • 6596baf80411 net: ena: clean up XDP TX queues when regular TX setup fails
  • ab625256882e selftests: net: fix file owner for broadcast_ether_dst test
  • b3d835407846 net/sched: act_ct: preserve tc_skb_cb across defragmentation
  • 3f85fcd520aa net: ixp4xx_hss: fix duplicate HDLC netdev allocation
  • e89b8829693e net: wwan: t7xx: destroy DMA pool on CLDMA late init failure
  • 121c5f31c3fb net: ethernet: ti: icssg: guard PA stat lookups
  • 3118e97dae53 net: sit: require CAP_NET_ADMIN in the device netns for changelink
  • 5d7bd8790309 gpios: palmas: add .get_direction() op
  • d3b9026ef78d gpio: mt7621: avoid corruption of shared interrupt trigger state
  • 4e16bc75c750 gpio-f7188x: Add support for NCT6126D version B
  • b6e040b5143c gpio: mt7621: be sure IRQ domain is created before exposing GPIO chips
  • ac761e66708d gpio: tegra: do not call pinctrl for GPIO direction
  • 0630f2c3c16c gpio: mt7621: more robust management of IRQ domain teardown
  • 6cb15b81ff54 cpu: hotplug: Bound hotplug states sysfs output
  • f77117530fc3 cpu: hotplug: Preserve per instance callback errors
  • afd147e59b32 selftests/ftrace: Drop invalid top-level local in test_ownership
  • ea6a188ee805 posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()
  • 633cadbc0b83 locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
  • fcff712d0e3d wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
  • b33ac2d39953 tracing/user_events: Fix use-after-free in user_event_mm_dup()
  • ed3cc4218070 net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete
  • 0e8115a7ed9a Input: ims-pcu - fix type confusion in CDC union descriptor parsing
  • f516cba88bf9 Input: ims-pcu - fix race condition in reset_device sysfs callback
  • 383934c249a9 Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing
  • 9c964fc9507a Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging
  • 99c428d7ef64 Input: ims-pcu - fix firmware leak in async update
  • 05ac85da1219 Input: ims-pcu - fix DMA mapping violation in line setup
  • f28c5cabb2df Input: ims-pcu - add response length checks
  • c8d3d83f2eaa Input: ims-pcu - validate control endpoint type
  • 6329d1af316a Input: ims-pcu - release data interface on disconnect
  • 87e2f89dea07 Input: ims-pcu - only expose sysfs attributes on control interface
  • 6aacc18004b1 Input: ims-pcu - fix use-after-free and double-free in disconnect
  • df87532e9212 scsi: elx: efct: Fix I/O leak on unsupported additional CDB
  • 9b871369cbb4 scsi: elx: efct: Fix refcount leak in efct_hw_io_abort()
  • cb7bdae7fba4 scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
  • 004ccd2d3b4a scsi: target: Bound PR-OUT TransportID parsing to the received buffer
  • f1516c56ac54 scsi: xen: scsiback: Free unsubmitted command instead of double-putting it
  • 255fb7b0cdc9 scsi: xen: scsiback: Free the command tag on the TMR submit-failure path
  • d0a8a6660d58 scsi: sg: Report request-table problems when any status is set
  • ed0849797782 scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()
  • d495b403d5b3 scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path
  • 257321a1c036 accel/ivpu: Reject firmware log with size smaller than header
  • 4e370b528962 accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap()
  • 7aa8f3dba534 dma-fence: Make dma_fence_dedup_array() robust against 0-count input
  • 089e05b644d5 dm-verity: make error counter atomic
  • c8d743bb0e98 dm-verity: increase sprintf buffer size
  • f15eaa3801f2 dm-verity: fix a possible NULL pointer dereference
  • 2a0858cba1da dm-verity: avoid double increment of &use_bh_wq_enabled
  • 5dfd80426352 dm-integrity: don't increment hash_offset twice
  • aa5113e7155f dm-integrity: fix a bug if the bio is out of limits
  • 0c4e9bb1d410 dm-integrity: fix leaking uninitialized kernel memory
  • 92e3c93d60be dm_early_create: fix freeing used table on dm_resume failure
  • ee458c3c1834 dm-stats: fix merge accounting
  • 461d36b5ddaf dm-stats: fix dm_jiffies_to_msec64
  • 1247615aadb7 dm-pcache: reject option groups without values
  • e0b0163a6575 dm-log: fix a bitset_size overflow on 32bit machines
  • d61c12573ed9 dm-ioctl: fix a possible overflow in list_version_get_info
  • 021dab70eb37 dm-bufio: fix wrong count calculation in dm_bufio_issue_discard
  • 1fcb5e29dd7a dm era: fix out-of-bounds memory access for non-zero start sector
  • 7f76245960a3 dm thin metadata: fix metadata snapshot consistency on commit failure
  • ac2136dc4441 dm thin metadata: fix superblock refcount leak on snapshot shadow failure
  • 8a3c44a00317 net: sparx5: unregister blocking notifier on init failure
  • ffd17a393921 block: fix IORING_URING_CMD_REISSUE flags check in blkdev_uring_cmd
  • 2977b5fe401c block: fix race in blk_time_get_ns() returning 0
  • af382ffca93e block: remove redundant GD_NEED_PART_SCAN in add_disk_final()
  • 0b6252afcd19 bpf: Add missing access_ok call to copy_user_syms
  • c4f626ddf235 bpf,fork: wipe ->bpf_storage before bailouts that access it
  • 0993dc5fc619 bpf: Reset register bounds before narrowing retval range in check_mem_access()
  • b06a4a397ac8 can: bcm: add missing rcu list annotations and operations
  • 35f0ac19efb1 can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure
  • cd830e0bc25e can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF
  • 37beb16e08ca can: isotp: serialize TX state transitions under so->rx_lock
  • 7bef39ba76eb can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER
  • b88a51130877 can: isotp: use unconditional synchronize_rcu() in isotp_release()
  • 765ba1c91823 can: esd_usb: kill anchored URBs before freeing netdevs
  • 5e4c8e08ce95 netdev-genl: report NAPI thread PID in the caller's pid namespace
  • 26355295ce21 nvmet: fix refcount leak in nvmet_sq_create()
  • 2944113ad5fb nvmet-rdma: handle inline data with a nonzero offset
  • 2eaa3ad45014 nvmet-auth: reject short AUTH_RECEIVE buffers
  • 59cef6abc924 nvme-apple: Prevent shared tags across queues on Apple A11
  • 0ffc032294a2 NFS: Charge unstable writes by request size, not folio size
  • ebe0a55d954f sctp: validate STALE_COOKIE cause length before reading staleness
  • d44b828eb551 spi: uniphier: Fix completion initialization order before devm_request_irq()
  • 9b092f9e6b34 time: Fix off-by-one in compat settimeofday() usec validation
  • ada4b9a5087e tpm: Make the TPM character devices non-seekable
  • 95bdf3950d66 tpm: fix event_size output in tpm1_binary_bios_measurements_show
  • 8ca2a19a987a xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink
  • e0f688ccb20f xfrm: use compat translator only for u64 alignment mismatch
  • 5b0c4c916f20 xfrm: nat_keepalive: avoid double free on send error
  • 16d3ccdabb8d xen/gntdev: fix error handling in ioctl
  • e497fef9ad7e ufs: core: tracing: Do not dereference pointers in TP_printk()
  • 0ced34b4bbc0 tcp: Decrement tcp_md5_needed static branch
  • 33a1bee41362 tcp: defer md5sig_info kfree past RCU grace period in tcp_connect
  • bccae122dab8 ice: fix ice_init_link() error return preventing probe
  • 8bd84316bbaf i2c: spacemit: fix spurious IRQ handling returning IRQ_HANDLED
  • e6a395a71f46 i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource()
  • 2f3f471a448a i2c: mediatek: fix WRRD for SoCs without auto_restart option
  • 5d3240f42a66 i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ)
  • 6d2c973926d0 i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
  • 500716a007b2 hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig
  • 1dcd7565e590 hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig
  • 3cd6f93f3d59 ksmbd: fix integer overflow in set_file_allocation_info()
  • 6cc151835736 smb: client: use kvzalloc() for megabyte buffer in simple fallocate
  • fe623f9515bb pkey: Move keytype check from pkey api to handler
  • eafc5aca7156 platform/x86/amd/pmc: Don't log during intermediate wakeups
  • e628d9169f9e platform/x86/amd/pmc: Add delay_suspend module parameter
  • 27d16a19ae74 platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops
  • d8bc45c4c1a4 platform/x86/amd/pmc: Check for intermediate wakeup in function
  • cea03d67db3a platform/x86: ISST: Restore SST-PP control to all domains
  • 1e41ca4a7fba platform/x86: dell-laptop: fix missing cleanups in init error path
  • ddbc4a8a4fe2 dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK
  • 7926c1e4be86 dmaengine: tegra: Fix burst size calculation
  • 933654508b2b sunrpc: fix uninitialized xprt_create_args structure
  • 934d1cd40e28 tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt
  • ba33b4f9d342 tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat()
  • 781f28bd982c tpm: restore timeout for key creation commands
  • 36ca587f55a2 irqchip/crossbar: Use correct index in crossbar_domain_free()
  • 0d078152fcab taskstats: retain dead thread stats in TGID queries
  • 9ac007affa77 mtd: maps: vmu-flash: fix NULL pointer dereference in initialization
  • 3fac46068fe4 openrisc: Fix jump_label smp syncing
  • ff7bcc9d71bf mtd: rawnand: Pause continuous reads at block boundaries
  • 0fd20c1905ab mtd: spi-nor: spansion: use die erase for multi-die devices only
  • c0806df5cf80 mtd: spi-nor: swp: Improve locking user experience
  • 433e5e70cdc1 s390/pkey: Check length in pkey_pckmo handler implementation
  • 693bf91d4db1 s390/pkey: Check length in PKEY_VERIFYPROTK ioctl
  • c9ef79e34bc1 fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header()
  • e5824d5b841d net: thunderbolt: Fix frags[] overflow by bounding frame_count
  • fc74244e0cc2 bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path
  • 3ebe0ee6527e bus: mhi: host: pci_generic: Fix the physical function check
  • 012683accbb7 fpga: dfl: add bounds check in dfh_get_param_size()
  • 2174c68f623b ocfs2: reject non-inline dinodes with i_size and zero i_clusters
  • 5e512d370a01 ocfs2: reject dinodes whose i_rdev disagrees with the file type
  • 4db3b6a2a8ec ocfs2: reject dinodes with non-canonical i_mode type
  • 499714de42ab ocfs2: add journal NULL check in ocfs2_checkpoint_inode()
  • 671889c553ea ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec
  • bd73971fad89 ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits
  • d5d5a21fb33c ocfs2: avoid moving extents to occupied clusters
  • 4bbfcf9c7e46 mtd: rawnand: fix condition in 'nand_select_target()'
  • a8874c34c4a9 net/9p: fix infinite loop in p9_client_rpc on fatal signal
  • ace3a0c839f3 mtd: rawnand: pl353: fix probe resource allocation
  • b6337e3687d3 ocfs2: use kzalloc for quota recovery bitmap allocation
  • bf53557a96d4 openrisc: Add full instruction cache invalidate functions
  • 8d263bae573d scsi: sas: Skip opt_sectors when DMA reports no real optimization hint
  • 83405848e403 scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished()
  • a7bbf83dfebd power: supply: bq257xx: Fix VSYSMIN clamping logic
  • 8d610017c992 9p: skip nlink update in cacheless mode to fix WARN_ON
  • d8dcbbfa0d69 mtd: slram: remove failed entries from the device list
  • 4e4beef747c6 kcov: use WRITE_ONCE() for selftest mode stores
  • da5234df0941 mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE
  • 749e2051da3b powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors
  • 07ed8b178548 fs/proc: fix KPF_KSM reported for all anonymous pages
  • b6a6fb6803d5 proc: only bump parent nlink when registering directories
  • 4d67bdef35c3 fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry()
  • 43b987ed35be fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()
  • 40a04601a3f6 mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error
  • f18c561eb9c5 mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs()
  • f322955d9a1c riscv: cacheinfo: Fix node reference leak in populate_cache_leaves
  • 1caee6e084a9 mips: sched: Fix CPUMASK_OFFSTACK memory corruption
  • bd2e9be9ebb6 selftests/landlock: Test SCOPE_SIGNAL on the SIGIO/fowner pgid path
  • 193e6471e985 power: supply: charger-manager: fix refcount leak in is_full_charged()
  • 1f18aac26372 landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path
  • ff05a98150eb ntfs3: fix out-of-bounds read in decompress_lznt
  • f3624cc06919 ntfs3: validate split-point offset in indx_insert_into_buffer
  • aaa1f956c0fc ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head
  • 0fad25687d4d ntfs3: cap RESTART_TABLE free-chain walker at rt->used
  • be306b8d9143 fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}
  • 908c9243ba30 fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
  • 7adb38279812 fs/ntfs3: validate lcns_follow in log_replay conversion
  • 50b5e83384e7 fs/ntfs3: bound attr_off in UpdateResidentValue against data_off
  • d240cd98f5f7 fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass
  • 09fddd52c1b0 fs/ntfs3: bound DeleteIndexEntryAllocation memmove length
  • ccd6b7079873 fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename
  • 640627f07c79 mm/damon/core: make charge_addr_from aware of end-address exclusivity
  • 722e6c54bde6 mm/memory_hotplug: fix incorrect altmap passing in error path
  • 1697d253f51c mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch
  • 9227b387eee5 power: supply: max17042: fix OF node reference imbalance
  • a3d81de44123 power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak
  • a39d281f207b mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages
  • d3fd2d358df0 MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf()
  • 11a3bc25f2c3 MIPS: ip22-gio: fix device reference leak in probe
  • 2c551f14f55e MIPS: ip22-gio: fix kfree() of static object
  • 620a37ea7d62 MIPS: ip22-gio: fix gio device memory leak
  • 51aad3d89a2d remoteproc: qcom: Fix leak when custom dump_segments addition fails
  • 69e18135e2a0 SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
  • 46d59ff42182 lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure
  • 1161c4b5bd00 lockd: Plug nlm_file leak when nlm_do_fopen() fails
  • 66014ab165cb sunrpc: harden rq_procinfo lifecycle to prevent double-free
  • 65b23bec1fca sunrpc: wait for in-flight TLS handshake callback when cancel loses race
  • 3f9ee75a97a7 sunrpc: pin svc_xprt across the asynchronous TLS handshake callback
  • 30d490bb2c4c nvdimm/btt: Free arena sub-allocations on discover_arenas() error path
  • f4ca396bdd60 nvdimm/btt: Free arenas on btt_init() error paths
  • 78955fdce8ff jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit()
  • 7199c78c3a3e Bluetooth: SCO: hold sk properly in sco_conn_ready
  • 77eb0cf57009 Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready
  • 96dd35f1942c HID: playstation: validate num_touch_reports in DualShock 4 reports
  • 88ba84546850 mfd: tps6586x: Fix OF node refcount
  • d8e2f3e1bc20 cifs: invalidate cfid on unlink/rename/rmdir
  • 3256c05d5a9d batman-adv: tt: prevent TVLV OOB check overflow
  • d2b657c9653f batman-adv: mcast: avoid OOB read of num_dests header
  • a90f4fff9025 batman-adv: frag: fix primary_if leak on failed linearization
  • c945f6007e78 batman-adv: clean untagged VLAN on netdev registration failure
  • 8f54162e07d3 batman-adv: frag: free unfragmentable packet
  • 2c989ab8e205 batman-adv: fix VLAN priority offset
  • 6a65ac8a81e9 batman-adv: tt: avoid request storms during pending request
  • ee878decf9e5 batman-adv: dat: fix tie-break for candidate selection
  • 9e16b6751a82 batman-adv: ensure minimal ethernet header on TX
  • 8f76277d0217 batman-adv: dat: ensure accessible eth_hdr proto field
  • e5e18886aadd batman-adv: bla: reacquire gw address after skb realloc
  • 3b4c70c40f2e batman-adv: dat: acquire ARP hw source only after skb realloc
  • b8afcf799b2c batman-adv: access unicast_ttvn skb->data only after skb realloc
  • 85a71a81854e batman-adv: retrieve ethhdr after potential skb realloc on RX
  • e6b43acd34b2 batman-adv: gw: acquire ethernet header only after skb realloc
  • fa1ebae4206e s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()
  • 8514585aa955 cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF()
  • 221ee479a49f cpufreq: schedutil: Fix uncleared need_freq_update on the .adjust_perf() path
  • 5ab0eba9c881 perf/x86/amd/lbr: Fix kernel address leakage
  • 046f6244da9b perf/x86/amd/brs: Fix kernel address leakage
  • 394e2bdf7594 x86/boot: Reject too long acpi_rsdp= values
  • f7c67c97b37c x86/boot: Validate console=uart8250 baud rate to fix early boot hang
  • 1a1d6e3ef6cf x86/video: Only fall back to vga_default_device() without screen info
  • 19ffeb30fdfc tools/power/x86/intel-speed-select: Harden daemon pidfile open
  • 16a42c88c466 mfd: sm501: Fix reference leak on failed device registration
  • 6dd51d84a950 leds: uleds: Fix potential buffer overread
  • 3a134c3fb5f0 selinux: fix incorrect execmem checks on overlayfs
  • d61a80b17254 selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()
  • fc633a598206 selinux: check connect-related permissions on TCP Fast Open
  • e9cdf741ffcb soc: fsl: qe: panic on ioremap() failure in qe_reset()
  • c6854d9f4e1b soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy
  • c4d6442ac3ed gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path
  • 1c4f67c89fd2 netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
  • 679ced28a9dc netfilter: xt_nat: reject unsupported target families
  • b2dbbedfa935 netfilter: ecache: fix inverted time_after() check
  • 3cd9a5792cbe netfilter: nf_conncount: fix zone comparison in tuple dedup
  • a58230f3a7c4 netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag
  • 2bcf2c5052fb netfilter: nf_nat_sip: reload possible stale data pointer
  • 02b6b0e892ae netfilter: nft_set_pipapo: don't leak bad clone into future transaction
  • 0ca505346c5e netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst
  • 07f9ddbf5e79 netfilter: xt_cluster: reject template conntracks in hash match
  • a1b672a3b537 netfilter: nfnl_cthelper: apply per-class values when updating policies
  • aff589556ed7 netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
  • ca028334343a ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback
  • e42d8322b67f ASoC: mediatek: mt8183: Release reserved memory on cleanup
  • 4b068759d308 ASoC: mediatek: mt8183: Check runtime resume during probe
  • 51c367230e30 ASoC: mediatek: mt8192: Release reserved memory on cleanup
  • e0f276f1918a ASoC: mediatek: mt8192: Check runtime resume during probe
  • d3abaedf6a58 ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control
  • 121577383b5c ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
  • 4ebe2c3a7db6 fbdev: tridentfb: fix potential memory leak in trident_pci_probe()
  • 009a8514745b fbdev: nvidia: fix potential memory leak in nvidiafb_probe()
  • 58bc18e03481 fbdev: vesafb: fix memory leak in vesafb_probe()
  • d81860691e4c fbdev: carminefb: fix potential memory leak in alloc_carmine_fb()
  • e1ca9b8559e0 fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe()
  • 12fe6a56506e fbdev: uvesafb: fix potential memory leak in uvesafb_probe()
  • ad54698255a4 fbdev: s3fb: fix potential memory leak in s3_pci_probe()
  • 146b708bc75f fbdev: i740fb: fix potential memory leak in i740fb_probe()
  • c2c795a320e7 fbdev: radeon: fix potential memory leak in radeonfb_pci_register()
  • febb5b4f67ac fbdev: efifb: fix memory leak in efifb_probe()
  • 9423e1f10527 fbdev: sm712: Fix operator precedence in big_swap macro
  • d684ce2db92b fbdev: hecubafb: fix potential memory leak in hecubafb_probe()
  • e8c9aae8c950 fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe()
  • 6854cf33dddb fbdev: metronomefb: fix potential memory leak in metronomefb_probe()
  • d5436e18e4fc KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory
  • 4ead4def0465 KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN
  • 5c50db5bcbb9 KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR
  • 884b44256041 KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
  • 09f35145f3a4 KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions
  • 5000bcae71c8 KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2
  • 7099e7148f81 KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers
  • 7996013b8568 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state
  • d1379888cc42 KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails
  • 97542f15dc4c KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
  • ba06690b28be KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs
  • df72596278b0 KVM: s390: pci: Fix handling of AIF enable without AISB
  • d19dca8194eb KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling
  • 79fdd2aa774e KVM: arm64: vgic: Check the interrupt is still ours before migrating it
  • 5fb75c527295 KVM: s390: pci: Fix GISC refcount leak on AIF enable failure
  • 9f8eaef40e95 powerpc/pseries/Kconfig: Enable CONFIG_VPA_PMU to be used with KVM
  • 33d79ad6eced LoongArch: KVM: Return full old CSR value from kvm_emu_xchg_csr()
  • f3efcef6648b LoongArch: KVM: Fix FPU register width with user access API
  • 45f2e6505fcf LoongArch: KVM: Check the return values for put_user()
  • efe27b19a15c LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt()
  • 199b570d7fca LoongArch: KVM: Validate irqchip index in irqfd routing
  • 1ee200a1764f ARM: dts: stm32: stm32mp15x-mecio1-io: Move expander gpio-line-names to board files
  • f550bf32b9a0 ARM: dts: stm32: stm32mp15x-mecio1-io: Fix expander gpio line typo
  • 7da4d1a6b740 ARM: dts: stm32: stm32mp15x-mecio1-io: Move gpio-line-names to board files
  • 804821b69b2d ARM: dts: stm32: stm32mp15x-mecio1-io: Fix GPIO names typo
  • c632a27f35cf arm64: dts: imx8ulp-evk: Correct Type-C int GPIO flags
  • bd938c985ab3 ARM: dts: stm32: stm32mp15x-mecio1-io: Enable internal ADC reference
  • ead9f10428c7 arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc
  • a98bda2305f3 ARM: dts: stm32: stm32mp15x-mecio1-io: Move divergent mecio1 ADC channels to board files
  • 4fd52ac541ce ARM: dts: stm32: stm32mp15x-mecio1-io: Fix ADC sampling times
  • 68f9773754f0 arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Ringneck
  • e2e3fb995175 arm64: dts: qcom: sdm630: describe adsp_mem region properly
  • 508e55e81870 ARM: dts: imx6ul-var-som: fix warning for non-existent dc-supply property
  • e8dc96a42571 arm64: dts: s32g3: Fix SWT8 watchdog address
  • 89edae416141 arm64: fpsimd: Fix type mismatch in sve_{save,load}_state()
  • 5526d1997aea net: ife: require ETH_HLEN to be pullable in ife_decode()
  • 908391d801b2 octeontx2-vf: clear stale mailbox IRQ state before request_irq()
  • eebf439aa7a1 octeontx2-pf: clear stale mailbox IRQ state before request_irq()
  • e62adb157c2e net: atm: reject out-of-range traffic classes in QoS validation
  • 22100a8f73d4 net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
  • 61a55fa24a5d tipc: restrict socket queue dumps in enqueue tracepoints
  • d34deef34c99 ASoC: SOF: topology: validate vendor array size before parsing
  • 0c4fbdaca225 ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get
  • 711d912b1876 ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
  • fb4293173db2 ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put
  • d8715b5a8fdb vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter
  • 3a2b47d1b4b3 mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()
  • 2d8b3c3e1299 mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()
  • b65e46eed9e5 idpf: add padding to PTP virtchnl structures
  • 1627e7d5c9b0 smb: client: fix overflow in passthrough ioctl bounds check
  • 327595e7c34e drm/xe: remove duplicate <kunit/test-bug.h> include
  • 3de77d2f34c2 octeontx2-af: fix VF bringup affecting PF promiscuous state
  • ee3f7566bcf3 net/mlx5: Fix L3 tunnel entropy refcount leak
  • 1550b07bca2b selftests/net: fix EVP_MD_CTX leak in tcp_mmap
  • 346e2d666a29 regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK
  • 14e03ecd3b1b dm era: fix NULL pointer dereference in metadata_open()
  • 5b0427ba582d SUNRPC: pin upper rpc_clnt across the TLS connect_worker
  • 13965a7b190f SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED
  • b784cd1c24d8 cifs: validate DFS referral string offsets
  • df0e3e70f699 s390/zcrypt: Remove the empty file
  • 8f48cfe65740 ipvs: ensure inner headers in ICMP errors are in headroom
  • 7510451a58c2 ipvs: fix PMTU for GUE/GRE tunnel ICMP errors
  • d73f4249776d ipvs: use parsed transport offset in TCP state lookup
  • d340e351a0a7 ipvs: pass parsed transport offset to state handlers
  • 238c612357b5 netfilter: nft_lookup: fix catchall element handling with inverted lookups
  • f60ec3058a85 ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer()
  • 27506827a01f ipv4: igmp: annotate data-races around timer-related fields
  • d269eb67d2e5 ipv4: igmp: annotate data-races around im->users
  • 9ce741c22df4 ipv6: mcast: Fix potential UAF in MLD delayed work
  • 75e984fe0cb9 ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
  • 3bfcce441c55 gpio: mvebu: free generic chips on unbind
  • 7cc438c99bba perf/x86/amd/core: Avoid enabling BRS from the SVM reload path
  • 9579d625171a octeontx2-pf: check DMAC extraction support before filtering
  • 7aa0e64fea77 net/sched: cake: reject overhead values that underflow length
  • 72119397cdff net: mdio: select REGMAP_MMIO instead of depending on it
  • 762116dfa728 drm/v3d: Reject invalid indirect BO handle in indirect CSD setup
  • 267809e2c56f accel/amdxdna: Fix potential amdxdna_umap lifetime race
  • 1cd434ac1c22 tracing: Make tracepoint_printk static as not exported
  • 5e15cf51982f gpio: dwapb: Defer clock gating until noirq
  • 6c736c5ccf4a gpio: dwapb: reduce allocation to single kzalloc
  • d7b5497e0e45 gpio: dwapb: Use modern PM macros
  • a3010b732d62 net: usb: lan78xx: disable VLAN filter in promiscuous mode
  • e8a4c9fc437b net/tls: Consume empty data records in tls_sw_read_sock()
  • b3eeb586f94c accel/amdxdna: Use unsigned long for nr_pages in amdxdna_hmm_register()
  • ec5e96aee75d ring-buffer: Fix event length with forced 8-byte alignment
  • 0c602cb8f148 Bluetooth: L2CAP: fix tx ident leak for commands without a response
  • bfc9e7be289d Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
  • b69b1ab121fe Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length
  • da4d8eea0c5f Bluetooth: sco: Fix a race condition in sco_sock_timeout()
  • dfc8373893b1 Bluetooth: MGMT: Fix adv monitor add failure cleanup
  • 23a83bac3356 Bluetooth: 6lowpan: hold L2CAP conn across debugfs control
  • 026c236f0eef amt: fix size calculation in amt_get_size()
  • 3bfb96d9bc6a net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
  • 6f9b23eb92a8 net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload
  • 1b12612c367e net: qualcomm: rmnet: validate MAP frame length before ingress parsing
  • b066420e57f3 qede: fix off-by-one in BD ring consumption on build_skb failure
  • 1e71a40d1015 net: microchip: vcap: fix races on the shared Super VCAP block
  • 5c7e3755abf6 net/mlx5e: Fix publication race for priv->channel_stats[]
  • 60fddda7207d net/mlx5e: Fix HV VHCA stats agent registration race
  • 420aabb32da4 net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation
  • 6a802de97a8b net/mlx5: LAG, MPESW, Fix missing complete() on devcom error
  • 4eef84b09a38 netfilter: xt_connmark: reject invalid shift parameters
  • b29b67c729de netfilter: nft_set_rbtree: get command skips end element with open interval
  • 3d441be2b1c5 netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
  • e702f6dd5d21 netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()
  • a597a722fb71 netfilter: xt_u32: reject invalid shift counts
  • 4a4a1d41c6e9 gue: validate REMCSUM private option length
  • b153cfe84b13 net: usb: net1080: validate packet_len before pad-byte access in rx_fixup
  • 66f57dc92aeb arm64/sysreg: Fix BWE field encoding in ID_AA64DFR2_EL1
  • a6185c21d551 selftests/hid: Cover hid_bpf_get_data() size overflow
  • 91ac1d7fd51e selftests/hid: Load only requested struct_ops maps
  • 61a959b82f1a HID: bpf: Fix hid_bpf_get_data() range check
  • 4c65c3d9f660 arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range()
  • dd395744e4ed HID: core: Fix OOB read in hid_get_report for numbered reports
  • d354e523c6f7 HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait()
  • 793b55c3f36f ata: libata-scsi: limit simulated SCSI command copy to response length
  • 232a2f2fce9b ata: sata_gemini: unwind clocks on IDE pinctrl errors
  • 86652704a7fd cifs: Fix missing credit release on failure in cifs_issue_read()
  • c9170c83b0e0 uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline
  • 2265b2b1c5aa x86/uprobes: Keep shadow stack in sync for emulated CALLs
  • adc7dda728ca drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays
  • a0a56b4480a0 drm/xe/hw_engine: Fix double-free of managed BO in error path
  • f9a9abd7bbda drm/xe/userptr: Hold notifier_lock for write on inject test path
  • 78b1074966d2 drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()
  • a9b89752c272 netfs: Fix folio state after ENOMEM whilst under writeback iteration
  • 1bb33d959aab netfs: Fix writeback error handling
  • 7838131e296d netfs: Fix writethrough to use collection offload
  • 8ab75e445c16 netfs: Fix netfs_create_write_req() to handle async cache object creation
  • 1f38f65bf965 iomap: guard io_size EOF trim against concurrent truncate underflow
  • 08b214547066 ovl: fix comment about locking order
  • abe3536a4bed minix: avoid overflow in bitmap block count calculation
  • ce6aced2e855 afs: Fix unchecked-length string display in debug statement
  • 158c5a0b1dfc afs: Fix the volume AFS_VOLUME_RM_TREE is set on
  • 657449e5581a afs: Fix premature cell exposure through /afs
  • 2ffb70a8a019 afs: Fix lack of locking around modifications of net->cells_dyn_ino
  • 8afb1a787a28 afs: Fix vllist leak
  • 5492799ec5d2 afs: Fix missing NULL pointer check in afs_break_some_callbacks()
  • 0acbc09d2aca afs: Fix callback service message parsers to pass through -EAGAIN
  • 63d3f283858f afs: Fix reinitialisation of the inode, in particular ->lock_work
  • 5ea289ca751c afs: Fix misplaced inc of net->cells_outstanding
  • b5bc1e5d5ce5 afs: Fix bulk lookup malfunction due to change in dir_emit() API
  • 083a0ddc9cd4 afs: Remove erroneous seq |= 1 in volume lookup loop
  • 6eb0d929202a afs: use kvfree() to free memory allocated by kvcalloc()
  • aa24cec5b347 afs: Fix double netfs initialisation in afs_root_iget()
  • 8530206911fd afs: Fix error code in afs_extract_vl_addrs()
  • a2038514e693 fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid
  • 374fd8122421 net/sched: hhf: clear heavy-hitter state on reset
  • fba8e250ce5f net/sched: dualpi2: clear stale classification on filter miss
  • a203f2c3892b pinctrl: meson: restore non-sleeping GPIO access
  • 47120164c63d gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe
  • 5a5ac2852cd3 ksmbd: fix use-after-free of fp->owner.name in durable handle owner check
  • d020e7f27bf6 ksmbd: reject undersized DACLs before parsing ACEs
  • 6b1304ce6cff net/sched: act_bpf: use rcu_dereference_bh() to read the filter
  • a03387e1f625 selftests: drv-net: tso: don't touch dangerous feature bits
  • df9ffdceac05 cxgb4: Fix decode strings dump for T6 adapters
  • 124440df267d virtio_net: disable cb when NAPI is busy-polled
  • a8323fb2ab6c sctp: fix addr_wq_timer race in sctp_free_addr_wq()
  • 4e8d498d32b6 irqchip/ts4800: Fix missing chained handler cleanup on remove
  • c5d75800539b irqchip/gic-v3-its: Fix OF node reference leak
  • f0069a262bd4 tracing/probes: Make the $ prefix mandatory for comm access
  • 62988204162f tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry()
  • 898cb5a7c415 tracing: eprobe: read the complete FILTER_PTR_STRING pointer
  • e0881f5cc4d7 tracing/events: Fix to check the simple_tsk_fn creation
  • f148f86c65b8 tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg
  • 3b51d6f07a19 tracing/eprobes: Allow use of BTF names to dereference pointers
  • acbf1ecc22f3 drm/panthor: Interrupt group start/resumption if group_bind_locked() fails
  • a9d098b346db drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced
  • 1497a438ea34 drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick()
  • dd0b2976b7c0 drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom()
  • b4b3458ef88d bridge: stp: Fix a potential use-after-free when deleting a bridge
  • 9b7d05cbaa60 net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF
  • ef940e042f32 net: gianfar: dispose irq mappings on probe failure and device removal
  • 58ba00999898 net: libwx: fix VMDQ mask for 1-queue mode
  • 86d379fcf1b7 net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy
  • 0a7d9c7c5f1f usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()
  • d8a01d27873e ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump
  • 83df3e2594cd eth: fbnic: don't cache shinfo across skb realloc
  • 898ca04b096b hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero
  • 489291b6b569 hwmon: (pmbus) Fix passing events to regulator core
  • 36554592e2f5 hwmon: adm1275: Prevent reading uninitialized stack
  • 1797eb92f0b3 ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280
  • f14c3926fee3 ASoC: codecs: lpass-va-macro: add SM6115 compatible
  • 3d3638fe9213 MIPS: mm: Add check for highmem before removing memory block
  • 4e9f4ca9dc73 MIPS: DEC: Ensure RTC platform device deregistration upon failure
  • bca3100f5502 sctp: add INIT verification after cookie unpacking
  • ad6215d76b64 sctp: fix SCTP_RESET_STREAMS stream list length limit
  • 1681cc7974a6 net: enetc: check the number of BDs needed for xdp_frame
  • b17751a2ebc4 qede: fix out-of-bounds check for cqe->len_list[]
  • 8dba7a94a269 seg6: validate SRH length before reading fixed fields
  • 8d501b141154 net: pse-pd: scope pse_control regulator handle to kref lifetime
  • e94d53a9ac22 gpio: htc-egpio: use managed gpiochip registration
  • f4af803269cc gpio: mvebu: fail probe if gpiochip registration fails
  • 46dee20d30b7 riscv: Fix 32-bit call_on_irq_stack() frame pointer ABI
  • 8e0b7f94fb39 ACPI: RIMT: Only defer the IOMMU configuration in init stage
  • 776f70bafd45 spi: sh-msiof: abort transfers when reset times out
  • d6cd34d17b95 tracing: probes: fix typo in a log message
  • f28d7b5f1578 ALSA: FCP: Fix NULL pointer dereference in interface lookup
  • d990a01b853e net: hns3: differentiate autoneg default values between copper and fiber
  • 2d149a20275a net: hns3: fix permanent link down deadlock after reset
  • 92d05883ef33 net: hns3: refactor MAC autoneg and speed configuration
  • 43a6c6fb6ec5 net: hns3: unify copper port ksettings configuration path
  • de051b146022 selftests: tls: size splice_short pipe by page size
  • 6727f580cf46 dt-bindings: net: renesas,ether: Drop example "ethernet-phy-ieee802.3-c22" fallback
  • 9075efb9b2c1 net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync
  • c1e7286d0531 ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count
  • 7a7c7263bbbc LoongArch: BPF: Fix off-by-one error in tail call
  • ed295077a221 LoongArch: BPF: Fix outdated tail call comments
  • 0a8a729481c8 LoongArch: Move struct kimage forward declaration before use
  • 2f3c0895fb20 net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove
  • b15a3cc68e24 net: sungem: fix probe error cleanup
  • b84dd48f9da1 net: mvneta: re-enable percpu interrupt on resume
  • e0ac054416bf octeontx2-af: Validate NIX maximum LFs correctly
  • 9dc3cf8a3590 net: phy: realtek: Clear MDIO_AN_10GBT_CTRL_ADV10G bit
  • 0c11a1da41a6 net: dsa: realtek: fix memory leak in rtl8366rb_setup_led()
  • a69ccea6d7eb rtc: cmos: unregister HPET IRQ handler on probe failure
  • 5fd1f0512748 rtc: ds1307: Fix off-by-one issue with wday for rx8130
  • d0bfd7004a87 smb/client: preserve errors from smb2_set_sparse()
  • 5b6165d7ec38 ACPI: processor_idle: Mark LPI enter functions as __cpuidle
  • ea43e7a231aa thermal: testing: zone: Flush work items during cleanup
  • 4e62be1490d2 eth: fbnic: fix ordering of heartbeat vs ownership
  • 123b559aa6bb ipv6: fix missing notification for ignore_routes_with_linkdown
  • 419017dd2dda ipv6: fix state corruption during proxy_ndp sysctl restart
  • ae58dbf1d78d ipv6: fix error handling in disable_policy sysctl
  • 2bf70e0306f8 ipv6: fix error handling in forwarding sysctl
  • b060606bc7e4 ipv6: fix error handling in ignore_routes_with_linkdown sysctl
  • 56c26538f0e5 ipv6: fix error handling in disable_ipv6 sysctl
  • 2140c2f3f2e7 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
  • ff127c0aa527 net: usb: lan78xx: restore VLAN and hash filters after link up
  • a9e6707322ef veth: fix NAPI leak in XDP enable error path
  • 410629528067 net: dsa: sja1105: round up PTP perout pin duration
  • 7557df1b60f2 net: do not acquire dev->tx_global_lock in netdev_watchdog_up()
  • 03b743586a24 net, bpf: check master for NULL in xdp_master_redirect()
  • a0904f7d2703 alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs
  • 94defb18ac79 alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
  • 04117aea9bc1 NTB: epf: Fix doorbell bitmask and IRQ vector handling
  • 56ec2a08d27b NTB: epf: Report 0-based doorbell vector via ntb_db_event()
  • d2a41c85beb5 NTB: epf: Make db_valid_mask cover only real doorbell bits
  • 60a6689b9a5d gpio: davinci: fix IRQ domain leak on devm_kzalloc failure
  • 33e1875d6b5b netfilter: nft_compat: ebtables emulation must reject non-bridge targets
  • d3e9a7e2ce9d netfilter: nft_synproxy: stop bypassing the priv->info snapshot
  • 329f2626ee5c netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
  • a73e7ac3f3b6 netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()
  • 49fa1be621dd bpf: Disable xfrm_decode_session hook attachment
  • 4d919c9b7709 md/raid5: avoid R5_Overlap races while breaking stripe batches
  • 3db13f82ba31 md/raid5: use stripe state snapshot in break_stripe_batch_list()
  • 828fad4fd418 ipv4: fib: Don't ignore error route in local/main tables.
  • 630ce3806b70 eth: bnxt: improve the timing of stats
  • c0057e5f762b eth: bnxt: rename ring_err_stats -> ring_drv_stats
  • 33168db149d0 eth: bnxt: gather and report HW-GRO stats
  • b0d0eb13a044 ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().
  • 77bb0bbfcc4e ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE
  • 1f6a4aec0d36 rtc: msc313: fix NULL deref in shared IRQ handler at probe
  • 68115a7a336f i40e: Fix i40e_debug() to use struct i40e_hw argument
  • de80d04b13de ice: dpll: fix memory leak in ice_dpll_init_info error paths
  • eaffdd113f56 ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info
  • 854065a75e37 rtc: isl1208: Balance enable_irq_wake() with disable_irq_wake() on cleanup
  • 4cc632fe63df ice: call netif_keep_dst() once when entering switchdev mode
  • 04c082b7dc5b ice: fix AQ error code comparison in ice_set_pauseparam()
  • dd6d8e4412f8 ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs()
  • 9415a94cf622 PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0
  • e1e7c72a2301 PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0
  • 9cc0f8e63e8c drm/edid: fix OOB read in drm_parse_tiled_block()
  • 5e4c4ab99abc gpiolib: initialize return value in gpiochip_set_multiple()
  • 7550becf3301 power: sequencing: fix ABBA deadlock in pwrseq_device_unregister()
  • 9697db03e010 bpf: Fix effective prog array index with BPF_F_PREORDER
  • 3bdfa0e435f3 bpf: zero-initialize the fib lookup flow struct
  • b05337635be3 bpftool: Fix vmlinux BTF leak in cgroup commands
  • 68b41e68a622 bpf: Fix stack slot index in nospec checks
  • aa33b44f70bf rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231
  • 56e5f8a409f8 rtc: abx80x: fix the RTC_VL_CLR clearing all status flags
  • 93f95538b611 dpaa2-switch: do not accept VLAN uppers while bridged
  • ea24f911ead8 ipv6: ioam: fix type confusion of dst_entry
  • a6450f7cfae5 ipv6: ndisc: fix NULL deref in accept_untracked_na()
  • 2066e692ec7a net: airoha: Fix skb->priority underflow in airoha_dev_select_queue()
  • 1d51aff78f07 net/sched: act_ct: fix nf_connlabels leak on two error paths
  • a103cdb0681e net: emac: Fix NULL pointer dereference in emac_probe
  • 2855ec137a22 octeontx2-pf: mcs: Fix mcs resources free on PF shutdown
  • da603b606ceb octeontx2-pf: Clear stats of all resources when freeing resources
  • 5636f0f3bd99 octeontx2-af: mcs: Fix unsupported secy stats read
  • ceef83f0eaf9 net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths
  • a0c5fdeb5fa2 tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
  • 5dda4f164a63 net: marvell: prestera: initialize err in prestera_port_sfp_bind
  • 9200c8149910 selftests/mm: fix exclusive_cow test fork() handling
  • 55fc2f99d097 selftests/mm: allow PUD-level entries in compound testcase of hmm tests
  • c8add1d06512 selftests/mm: clarify alternate unmapping in compaction_test
  • 0caa28e97894 selftests/mm: skip uffd-stress test when nr_pages_per_cpu is zero
  • 471b62966c78 selftests/mm: ensure destination is hugetlb-backed in hugetlb-mremap
  • 9dbfd514148d selftest/mm: register existing mapping with userfaultfd in hugetlb-mremap
  • a8673dbd3d4a selftests/mm: free dynamically allocated PMD-sized buffers in split_huge_page_test
  • 31b28910abe3 selftests/mm: size tmpfs according to PMD page size in split_huge_page_test
  • fff7d3ea3a4c selftests/mm: fix cgroup task placement and drop memory.current checks in hugetlb_reparenting_test.sh
  • 8c65c58868ec selftests/mm: fix hugetlb pathname construction in hugetlb_reparenting_test.sh
  • 58cd8ff69e33 selftests/mm: restore default nr_hugepages value via exit trap in hugetlb_reparenting_test.sh
  • b805de2abfa3 selftests/mm: restore default nr_hugepages value via exit trap in charge_reserved_hugetlb.sh
  • 37e3e8a2c3bf alloc_tag: fix use-after-free in /proc/allocinfo after module unload
  • 502b3ae43f79 irqchip/crossbar: Fix parent domain resource leak
  • 002ebbcc8414 mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx()
  • 7e23965d44f0 netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak
  • d32e4301a0e5 netfilter: nf_reject: skip iphdr options when looking for icmp header
  • 8e935c51b65d netfilter: nft_flow_offload: zero device address for non-ether case
  • 4c61d28634fb netfilter: flowtable: move path discovery infrastructure to its own file
  • 13c6ba6e0f21 netfilter: nft_meta_bridge: add validate callback for get operations
  • 5baa149abb41 netfilter: nft_payload: reject offsets exceeding 65535 bytes
  • 12088da6add5 netfilter: ipset: make sure gc is properly stopped
  • 8087bb360a93 netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
  • c4d257734e91 netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types
  • a0afd353c2f7 netfilter: ipset: annotate "pos" for concurrent readers/writers
  • 7228cc8ff626 netfilter: ipset: Fix data race between add and dump in all hash types
  • 6d92dbd73d19 md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry
  • 2c5384c40a4c md/raid1: honor REQ_NOWAIT when waiting for behind writes
  • 119903c32083 md: merge mddev serialize_policy into mddev_flags
  • 2e414af05a7c md: merge mddev faillast_dev into mddev_flags
  • 9408c233a5bb md: merge mddev has_superblock into mddev_flags
  • 5464ee644237 mac802154: Prevent overwrite return code in mac802154_perform_association()
  • de3bd9809af7 ieee802154: fix kernel-infoleak in dgram_recvmsg()
  • d22e278cd067 ieee802154: Remove WARN_ON() in cfg802154_pernet_exit()
  • f4860dd988b1 ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns()
  • 5d17ebdf6c23 ieee802154: Restore initial state on failed device_rename() in cfg802154_switch_netns()
  • 3b40ebc19ad0 ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone()
  • 45465b0e0135 ACPI: resource: Amend kernel-doc style
  • 7ae67f0e1c16 thermal: intel: Fix dangling resources on thermal_throttle_online() failure
  • 679fd0bf4f8a arm64/hw_breakpoint: reject unaligned watchpoints that would truncate BAS
  • 4c16176fc11a ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints
  • a762b9865f49 selftests: vlan_bridge_binding: Fix flaky operational state check
  • c6d3bcb0f934 flow_dissector: check device type before reading ETH_ADDRS
  • 68af74ad696c net: macb: add TX stall timeout callback to recover from lost TSTART write
  • 112b5eff24e0 net: airoha: fix foe_check_time allocation size
  • 5ffb2b4987cc devlink: Fix parent ref leak on tc-bw failure
  • 02c884d9aaca devlink: Fix parent ref leak in devl_rate_node_create()
  • 0dafdaaf8684 dpaa2-switch: fix VLAN upper check not rejecting bridge join
  • c7fc9adf4e00 virtio-net: fix len check in receive_big()
  • 0d95587d662a spi: rpc-if: Use correct device for hardware reinitialization on resume
  • f37f2f804796 PCI: iproc: Restore .map_irq() for the platform bus driver
  • 53c23d56b46b ALSA: usb-audio: qcom: clear opened when stream enable fails
  • 25a867aa5e67 ALSA: usb-audio: qcom: reject stream disable with no active interface
  • 207bb4ce8fe7 sctp: hold socket lock when dumping endpoints in sctp_diag
  • a6cfb924ad74 net: psample: fix info leak in PSAMPLE_ATTR_DATA
  • 3d45d40b872a octeontx2-pf: Fix leak of SQ timestamp buffer on teardown
  • 290ad0a54891 drm/amdgpu: initialize irq.lock spinlock earlier
  • 96ac562a9ea3 drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm
  • 211bb9d8f17c drm/amd/display: Fix mem_type change detection for async flips
  • 0e27d92f69b8 drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free
  • 7bcd4ef375fa ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode
  • ca297485271c perf dso: Set standard errno on decompression failure
  • 05b11debdffe perf bpf: Validate array presence before casting BPF prog info pointers
  • c8cb4a92eda6 perf cs-etm: Bounds-check CPU in cs_etm__get_queue()
  • b389a5b215e3 perf cs-etm: Require full global header in auxtrace_info size check
  • c13532ff67fa perf cs-etm: Validate num_cpu before metadata allocation
  • 87d23f25b5e9 perf machine: Use snprintf() for guestmount path construction
  • 6d99379c58f7 xfrm: validate selector family and prefixlen during match
  • 7248ae02a945 xfrm: annotate data-races around xfrm_policy_count[] and xfrm_policy_default[]
  • a1a3360a0c44 xfrm: Fix xfrm state cache insertion race
  • 1467ca02ddac ALSA: usb-audio: qcom: Free sideband sg_table objects
  • 507a7b07f3fa i3c: master: Add missing runtime PM get in dev_nack_retry_count_store()
  • 34cd92141a02 i3c: master: Update dev_nack_retry_count under maintenance lock
  • 95028569589f spi: dw: fix wrong BAUDR setting after resume
  • 355e51eeffc6 drm/xe: Fix wa_oob codegen recipe for external module builds
  • 2024940522ef drm/i915: clear CRTC color blob pointers after dropping refs
  • 1348bf64c197 gpio: mlxbf3: fail probe if gpiochip registration fails
  • 7d3532a0b11a perf cs-etm: Reject CPU IDs that would overflow signed comparison
  • a56f29ad8aac perf: Remove redundant kernel.h include
  • f8898d2eb71a perf bpf: Bounds-check array offsets in bpil_offs_to_addr()
  • cafd80d81f08 perf bpf: Reject oversized BPF metadata events that truncate header.size
  • 1935d213aeb2 perf bpf: Validate func_info_rec_size and sub_id in synthesize_bpf_prog_name()
  • aea30b437ebd perf sched: Replace (void*)1 sentinel with proper runtime allocation
  • bc27041e8971 perf hwmon: Fix fd check to accept fd 0 in hwmon_pmu__describe_items()
  • 661f60a8a5cf perf tools: Use snprintf() for root_dir path construction
  • 5d080b7324f0 perf dso: Set error code when open() fails on uncompressed fallback path
  • debfcd673a6d perf dso: Fix heap overflow in dso__get_filename() on decompressed path
  • 95bf4dbcd502 perf tools: Fix uninitialized pathname on uncompressed fallback in filename__decompress()
  • fa870f951793 perf tools: Add O_CLOEXEC to open() calls in DSO and ELF code
  • 3ae7947101b9 perf tools: Don't read build-ids from non-regular files
  • 2c19e40753ec perf symbols: Break infinite loop on zero-filled notes in sysfs__read_build_id()
  • 137eabe3c18f perf symbols: Validate p_filesz before use in filename__read_build_id()
  • ca3393e258f6 perf symbols: Fix bswap copy-paste error for 32-bit ELF p_filesz
  • f231387f3d2b sparc: led: avoid trimming a newline from empty writes
  • 17955f1995bf accel/ivpu: fix HWS command queue leak on registration failure
  • 85873b1bd366 apparmor: fix label can not be immediately before a declaration
  • 38d3d33bf42c i3c: master: Prevent reuse of dynamic address on device add failure
  • c4f2afcdc547 i3c: master: Defer new-device registration out of DAA caller context
  • 3891c061341f i3c: master: Ensure Hot-Join operations are stopped on shutdown
  • 57490b302b98 i3c: master: Consolidate Hot-Join DAA work in the core
  • 0bd450d40f87 i3c: master: Move rstdaa error suppression
  • fd32e8d4a293 i3c: master: Add i3c_master_do_daa_ext() for post-hibernation address recovery
  • b07a318afca1 i3c: master: Introduce optional Runtime PM support
  • 882ee831366a i3c: master: Replace WARN_ON() with dev_err() in i3c_dev_free_ibi_locked()
  • de2106d99b87 i3c: add sysfs entry and attribute for Device NACK Retry count
  • 0d66830f302f i3c: master: Make hot-join workqueue freezable to block hot-join during suspend
  • eb9db96a5deb i3c: master: add WQ_PERCPU to alloc_workqueue users
  • 45bbc1e1fe62 i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring
  • d22ab94261c7 i3c: mipi-i3c-hci: Switch PIO data allocation to devm_kzalloc()
  • 973fda38b124 i3c: mipi-i3c-hci: Allow for Multi-Bus Instances
  • 5625b8767ce3 i3c: mipi-i3c-hci: Quieten initialization messages
  • 2791dd42d41e apparmor: fix uninitialised pointer passed to audit_log_untrustedstring()
  • fdf610a9a9e7 apparmor: don't audit files pointing to aa_null.dentry
  • b58d240883df apparmor: put secmark label after secid lookup
  • 66a6c61369d4 apparmor: aa_getprocattr free procattr leak on format failure
  • 22dc9433d458 apparmor: fail policy unpack on accept2 allocation failure
  • 3b918f6f5239 apparmor: Fix return in ns_mkdir_op
  • 566d1ef98a71 apparmor: remove or add symlinks to rawdata according to export_binary
  • fbfdb5a94a48 apparmor: fix NULL pointer dereference in unpack_pdb
  • 57b1bd4486d5 apparmor: fix potential UAF in aa_replace_profiles
  • b427061ca498 apparmor: grab ns lock and refresh when looking up changehat child profiles
  • 9111f76e8dc8 apparmor: fix rawdata_f_data implicit flex array
  • ae02e603c0b3 apparmor: aa_label_alloc use aa_label_free on alloc failure
  • d82160132345 apparmor: check label build before no_new_privs test
  • ad965f36d298 security/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref()
  • 045dbe89ac31 apparmor: fix refcount leak when updating the sk_ctx
  • d8ea44f6090c apparmor: fix race in unix socket mediation when peer_path is used
  • ef488d7429d2 apparmor: fix shadowing of plabel that prevents cache from being updated
  • f79519f63605 Revert "PCI/MSI: Unmap MSI-X region on error"
  • 514b84b1bf30 PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability
  • 11016555d751 phy: freescale: phy-fsl-imx8qm-lvds-phy: Fix missing pm_runtime_disable() on probe error path
  • 872f9a63a108 PCI: mediatek: Use actual physical address instead of virt_to_phys()
  • f77c490c45d4 PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port()
  • 9ca0a78a5d56 dt-bindings: phy: sc8280xp-qmp-pcie: Disallow bifurcation register on Purwa
  • f1f5f8d334e9 perf symbols: Add bounds checks to read_build_id() note iteration in minimal build
  • cc6cd3fe8b8b perf symbols: Add bounds checks to elf_read_build_id() note iteration
  • a3e758e74122 perf bpf: Fix metadata leak in perf_env__add_bpf_info() on duplicate insert
  • f593775fecf5 perf bpf: Fix map data leak in bpf_metadata_create() on alloc failure
  • bafb6bfb346f perf bpf: Add NULL check for btf__type_by_id() in synthesize_bpf_prog_name()
  • fe4d8ad2e96f tools lib api: Fix mount_overload() snprintf truncation and toupper range
  • b0385203a09f tools lib api: Fix filename__write_int() writing uninitialized stack data
  • 41b3a9231045 perf tools: Use snprintf() in dso__read_running_kernel_build_id()
  • fbaf9bdfc091 perf hwmon: Guard label read against empty or failed reads
  • d34b42ee0c74 perf symbols: Bounds-check descsz in sysfs__read_build_id() GNU fallback
  • bc2fc12ce6e4 perf hwmon: Fix parse_hwmon_filename() strlcpy buffer overflow
  • f830bb8d221f perf hwmon: Use scnprintf() in hwmon_pmu__for_each_event()
  • 76dfa13a0acb perf hwmon: Fix off-by-one null termination on sysfs reads
  • 56b17c84394f perf tools: Fix thread__set_comm_from_proc() on empty comm file
  • f2e5262589d9 perf intel-pt: Fix snprintf size tracking bug in insn decoder
  • 45e7900e1555 perf symbols: Bounds-check .gnu_debuglink section data
  • 4f883ab5bc7b perf symbols: Fix signed overflow in sysfs__read_build_id() size check
  • 490473192ac2 tools lib api: Fix missing null termination in filename__read_int/ull()
  • 09962b811ef1 perf pmu: Fix perf_pmu__parse_scale/unit() OOB access on empty sysfs file
  • a6eec54329b4 perf pmu: Fix pmu_id() heap underwrite on empty identifier file
  • e274dfa05904 perf cs-etm: Queue context packets for frontend
  • fa9eb50ddfea perf s390: Fix TEXTREL in Python extension by compiling as PIC
  • b5a0a4a564d2 xprtrdma: Return sendctx slot after Send preparation failure
  • 007b4da2f38d xprtrdma: Repost Receive buffers for malformed replies
  • 469b22376ee7 xprtrdma: Sanitize the reply credit grant after parsing
  • d7a2870dde3b xprtrdma: Fix bcall rep leak and unbounded peek
  • 345652531400 xprtrdma: Resize reply buffers before reposting receives
  • 47b3dc59e09e xprtrdma: Document and assert reply-handler invariants
  • 7471e66373a4 xprtrdma: Check frwr_wp_create() during connect
  • 28743571c17b xprtrdma: Initialize re_id before removal registration
  • d0479c2b1297 xprtrdma: Fix ep kref imbalance on ADDR_CHANGE
  • 6d52921f4702 perf hists: Fix snprintf() in hists__scnprintf_title() UID filter path
  • 56ad33189ed5 perf bpf: Use scnprintf() in snprintf_hex() and synthesize_bpf_prog_name()
  • c32fe40b0c74 perf sched: Fix idle-hist callchain display using wrong rb_first variant
  • 77051ef66e4a perf sched: Bounds-check prio before test_bit() in timehist
  • 2e0dd50e5a4d PCI: rcar-host: Remove unused LIST_HEAD(res)
  • b9e8406651dc perf tools: Use perf_env__get_cpu_topology() in machine__resolve()
  • 504028f561b1 perf tools: Use scnprintf() in cpu_map__snprint() to prevent overflow
  • 2a8244988316 perf tools: Fix get_max_num() size_t underflow on empty sysfs file
  • 3f4476a089a6 platform/x86/intel/vsec: Restore BAR fallback for header walk
  • d6565e08166c platform/x86/intel/vsec: Return real error codes from registration path
  • 4df30a4dc0e9 platform/x86/intel/vsec: Switch exported helpers from pci_dev to device
  • 817ab332d37c platform/x86/intel/vsec: Decouple add/link helpers from PCI
  • e6523bcafeb6 platform/x86/intel/vsec: correct kernel-doc comments
  • c0d97519c9df platform/x86:intel/pmc: Relocate lpm_req_guid to pmc_reg_map
  • b95e1facc5b7 platform/x86:intel/pmc: Rename PMC index variable to pmc_idx
  • 3e86797c0699 platform/x86:intel/pmc: Add support for multiple DMU GUIDs
  • 4f129fc6f756 fs/ntfs3: resize log->one_page_buf when adopting on-disk page size
  • d3491b23bc20 PCI: meson: Add missing remove callback
  • a5c0ba31eef9 PCI: meson: Propagate devm_add_action_or_reset() failure
  • f0aaa198e068 pwm: rzg2l-gpt: Add missing newlines to dev_err_probe() messages
  • a57692ad365f PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro
  • f161ef7b0dd2 nfs: use nfsi->rwsem to protect traversal of the file lock list
  • a6f147b23e36 NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write
  • a70375f0b793 NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors
  • b694c7de94bc nfs: keep PG_UPTODATE clear after read errors in page groups
  • f84949dd1784 NFSv4/pnfs: defer return_range callbacks until after inode unlock
  • 53442c7d0c88 xprtrdma: Decouple req recycling from RPC completion
  • becc90a04780 xprtrdma: Use sendctx DMA state for Send signaling
  • e7ae0883c8c8 xprtrdma: Post receive buffers after RPC completion
  • f043dd58fbd7 xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot
  • b7bc8e7f09ae xprtrdma: Avoid 250 ms delay on backlog wakeup
  • 44b73b4b7eff pNFS/filelayout: fix cheking if a layout is striped
  • f3f21b94cf98 sunrpc: Fix error handling in rpc_sysfs_xprt_switch_add_xprt_store()
  • e8dc126e8039 clk: qcom: a53: Corrected frequency multiplier for 1152MHz
  • c0e6bb2b0408 dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor
  • 9f1ef67c041e dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc
  • 329ec20a8609 dmaengine: Fix possible use after free
  • 7d49f0ddaf5a dmaengine: qcom: gpi: set DMA_PRIVATE capability
  • 8e2c460a8f0e mshv: add bounds check on vp_index in mshv_intercept_isr()
  • eaf937b501fd clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks
  • 032692e4525a dt-bindings: clock: qcom: Add X1P42100 camera clock controller
  • c7c8bab87d0d perf tools: Fix int16_t truncation of max_cpu_num in set_max_cpu_num()
  • e16012f8f63d perf timechart: Fix cpu2y() OOB read on untrusted CPU index
  • 330219fe8523 perf c2c: Fix use-after-free in he__get_c2c_hists() error path
  • 01564c1a260f perf stat: Introduce perf_env__get_cpu_topology() to guard NULL env->cpu
  • c05ba5b57505 perf mmap: Fix NULL deref in aio cleanup on alloc failure
  • c4406dbe5d8f perf sched: Replace BUG_ON and add NULL checks in replay event helpers
  • b1f768363271 perf sched: Use thread__put() in free_idle_threads()
  • 1517402d0a81 perf sched: Clean up idle_threads entry on init failure
  • d6b586bb8f48 perf c2c: Bounds-check CPU IDs in setup_nodes() topology loop
  • 2f9f7224e769 perf c2c: Bounds-check CPU and node IDs before bitmap and array access
  • 278e30717c35 perf stat: Bounds-check CPU index in topology aggregation callbacks
  • 21a9b87ada08 perf mmap: Guard cpu__get_node() return in aio_bind()
  • 652cea73b7b7 perf sched: Fix register_pid() overflow, strcpy, and BUG_ON
  • 068e9b6a07bc perf sched: Cap max_cpu at MAX_CPUS in timehist sample processing
  • 1d25a8418c89 perf tools: Add bounds check to cpu__get_node()
  • 89489a31f444 perf sched: Fix thread reference leak in latency_switch_event
  • ea486d61b166 perf tools: Guard test_bit from out-of-bounds sample CPU
  • 18961e0f8966 perf annotate: Fix crashes on empty annotate windows
  • 93f3e84fc74e perf: Fix off-by-one stack buffer overflow in kallsyms__parse()
  • d78b16d07814 dt-bindings: dma: nvidia,tegra186-gpc-dma: Make reset optional
  • a498063f95bd dmaengine: imx-sdma: Refine spba bus searching in probe
  • da4058382315 thunderbolt: debugfs: Fix margining error counter buffer leak
  • 038a0f01dda5 drm/amd/display: Add missing kdoc for ALLM parameters
  • c5388a957cf1 fs/ntfs3: fix mount failure on 64K page-size kernels
  • a31893206588 fs/ntfs3: add bounds check to run_get_highest_vcn()
  • 097fcf945d93 HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter
  • 26fa946925a0 clk: at91: keep securam node alive while mapping it
  • 0147c544cbc6 iio: tcs3472: power down chip on probe failure
  • 1cddef80a180 iio: accel: mma8452: handle I2C read error(s) in mma8452_read()
  • 9ac3675bf875 iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling
  • 3d5767211952 iio: magnetometer: ak8975: fix potential kernel stack memory leak
  • 6ec473b36034 iio: light: si1133: prevent race condition on timeout
  • f835b69fbeae iio: light: si1133: reset counter to prevent race condition
  • fd6b65ade119 perf header: Sanity check HEADER_EVENT_DESC attr.size before swap
  • be62602fe079 PCI: qcom: Disable ASPM L0s for SA8775P
  • de93ef83f99e powerpc tools perf: Initialize error code in auxtrace_record_init function
  • 96c8f732cadf clk: renesas: rzg2l: Rename iterator in for_each_mod_clock() to avoid shadowing
  • fdee9f207a48 gpib: fix double decrement of descriptor_busy in command_ioctl()
  • 3d5e4cc0d9dc char: tlclk: fix use-after-free in tlclk_cleanup()
  • d72ece584c44 gpib: Fix inappropriate ioctl error return
  • 92f8b1d83383 perf test amd ibs: Fix incorrect kernel version check
  • 2b2b1613b734 usb: host: max3421: Reject hub port requests for non-existent ports
  • 02d03c61e8a7 usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
  • 43078449ad62 staging: most: video: avoid double free on video register failure
  • 45652323ce74 perf inject: Add --convert-callchain option
  • 28ebd287a7fa perf build-id: Fix off-by-one bug when printing kernel/module build-id
  • fc5ce5606db5 PCI: dwc: Fix signedness bug in fault injection test code
  • 7d881615fb63 mailbox: mtk-adsp: fix UAF during device teardown
  • 91353d63bbf6 mailbox: mpfs: fix check for syscon presence in mpfs_mbox_inbox_isr()
  • e6bc4e127707 coresight: Fix source not disabled on idr_alloc_u32 failure
  • 67d0475e78b3 soundwire: intel_ace2x: release bpt_stream when close it
  • 5732869c70d4 clk: at91: sam9x7: Fix gmac_gclk clock definition
  • f28906e7e32f perf pmu: Skip test on Arm64 when #slots is zero
  • 210c202c0576 phy: phy-can-transceiver: Check driver match and driver data against NULL
  • 226feccaac81 clk: qcom: cmnpll: Account for reference clock divider
  • 6abdf27fbcfb coresight: fix missing error code when trace ID is invalid
  • 5bb87456dcd6 bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
  • 601a9b2e3b2f rust: alloc: fix assert in Vec::reserve doc test
  • b773c7161cea PCI: loongson: Do not ignore downstream devices on external bridges
  • e1b79f77336d perf sched: Add missing mmap2 handler in timehist
  • c788955b4a14 platform/x86: xo15-ebook: Fix wakeup source and GPE handling
  • 2ce4d93768d2 x86/platform/olpc: xo15: Drop wakeup source on driver removal
  • 1d495446ec7a PCI: Check ROM header and data structure addr before accessing
  • 78f264c0cb2a PCI: Introduce named defines for PCI ROM
  • 10021c2d3306 PCI/ASPM: Don't reconfigure ASPM entering low-power state
  • 48dde5c56426 coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore
  • 65d87f28daec coresight: ete: Always save state on power down
  • 1ac8f4c112aa coresight: etm4x: Remove the state_needs_restore flag
  • a454f61747c9 soundwire: fix bug in sdw_add_element_group_count found by syzkaller
  • d3896c944338 soundwire: don't program SDW_SCP_BUSCLOCK_SCALE on a unattached Peripheral
  • c3ca7c6741af coresight: cti: Fix DT filter signals silently ignored
  • fb940466fd4d perf debuginfo: Fix libdw API contract violations
  • bb3d592c7d6c staging: nvec: fix use-after-free in nvec_rx_completed()
  • 466c7f87de52 i3c: master: svc: Fix missed IBI after false SLVSTART on NPCM845
  • db2d8b6525bd gpiolib: acpi: Only trigger ActiveBoth interrupts on boot
  • 02e2dadd62ea eventpoll: Fix epoll_wait() report false negative
  • f938bc8fde51 eventpoll: rename epi->next and txlist for clarity
  • 430dac191905 eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers
  • d8f88803152f eventpoll: extract ep_deliver_event() from ep_send_events()
  • 4fd51f413d7b eventpoll: split ep_insert() into alloc + register stages
  • 25e85dc040a6 eventpoll: rename attach_epitem() to ep_attach_file()
  • baebd892f8a2 eventpoll: expand top-of-file overview / locking doc
  • f04166c8677a eventpoll: rename ep_remove_safe() back to ep_remove()
  • 13bf9879b778 net/9p: fix race condition on rdma->state in trans_rdma.c
  • 9c1c120471a6 9p: avoid returning ERR_PTR(0) from mkdir operations
  • ae1f3460833d ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write
  • d35e4032f16d mfd: cs42l43: Sanity check firmware size
  • 706fe1ce4f3a mfd: rsmu: Fix page register setup
  • 35d3d6ff2bc1 ksmbd: fix use-after-free in same_client_has_lease()
  • aa0c43c13c0b RDMA/bnxt_re: Fail DBR related page allocation UAPIs if the feature is disabled
  • 0fe155aa844e RDMA/bnxt_re: Move the UAPI methods to a dedicated file
  • 95d46a8d3ba9 RDMA/bnxt_re: Avoid displaying the kernel pointer
  • 104a7ff382a5 RDMA/bnxt_re: Free SRQ toggle page after firmware teardown
  • 5a48dd5150d7 ionic: Fix check in ionic_get_link_ext_stats
  • 4c55003566c0 net: ethernet: oa_tc6: Remove FCS size in RX frame
  • 93e133b9193c net: airoha: Fix always-true condition in PPE1 queue reservation loop
  • d774cdbda663 tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)
  • 0d8a12d71431 tipc: fix UAF in tipc_l2_send_msg()
  • db1616263a2c KEYS: Use acquire when reading state in keyring search
  • 66919a6d72b9 powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus
  • 527cd14a416f powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down
  • 73711688479d powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del
  • 92f38fe85198 MIPS: mm: Fix out-of-bounds write in maar_res_walk()
  • fe09dd288722 bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check
  • 81567d2b3f4d sockmap: Fix use-after-free in udp_bpf_recvmsg()
  • 073d95725269 net: remove addr_len argument of recvmsg() handlers
  • 4e40056bb5c8 bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
  • 264d6a79c96e udf: fix nls leak on udf_fill_super() failure
  • 5e8627b7a7b7 bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket
  • e80307776924 selftests/bpf: Initialize operation name before use
  • 9f32d4c2de85 selftests/bpf: Fix typo in verify_umulti_link_info
  • 74badb5e2b00 smb/client: always return a value for FS_IOC_GETFLAGS
  • 21303c4a2b72 cifs: remove all cifs files before kill super
  • 7a59146cb9ad ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait()
  • 87d1eaffeec4 netfilter: nf_conncount: callers must hold rcu read lock
  • 98a965cb1e76 ALSA: seq: avoid stale FIFO cells during resize
  • 287d506d4e08 ALSA: seq: oss: Serialize readq reset state with q->lock
  • f01fb6138f8e kcm: use WRITE_ONCE() when changing lower socket callbacks
  • 4d48c08a0bf6 net: airoha: Fix debugfs new-tuple display for IPv4 ROUTE entries
  • dcac6e4221f3 net: airoha: Fix register index for Tx-fwd counter configuration
  • 36edab340a06 net: bcmgenet: Use weighted round-robin TX DMA arbitration
  • b91b241a4eef landlock: Fix unmarked concurrent access to socket family
  • 1bb02353e79f dpll: balance create/delete notifications in _dpll_pin(un)register
  • 77a1ea975c87 dpll: guard sync-pair removal on full pin unregister
  • 8008ef973f01 dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister()
  • 6564ce3a2f9c dpll: send delete notification before unregister in on-pin rollback
  • f1e1c6eb8248 dpll: fix stale iteration in dpll_pin_on_pin_unregister()
  • 20575400fc1b dpll: Enhance and consolidate reference counting logic
  • ebe4bd3560a7 dpll: Support dynamic pin index allocation
  • f7aebaee2961 net: wwan: t7xx: check skb_clone in control TX
  • 34bd255dba32 net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show()
  • 1d072cc3ba43 octeontx2-af: npc: Fix size of entry2cntr_map
  • 417bd36a085d bpf: Fix setting retval to -EPERM for cgroup hooks not returning errno
  • 3d90b15fb191 net/mlx5: Check max_macs devlink param value against max capability
  • 8d5f4be13488 bpf: Run generic devmap egress prog on private skb
  • 450e48271827 net/sched: sch_dualpi2: Add missing module alias
  • 6d585d0dc674 net: ethernet: mtk_wed: fix loading WO firmware for MT7986
  • 446fe8ce699c net: watchdog: fix refcount tracking races
  • 697db22a9dcc net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check
  • 62ce489acb42 net: mana: initialize gdma queue id to INVALID_QUEUE_ID
  • bd851b10daee net/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
  • 755108bb7a50 net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
  • 0500af8630c3 net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
  • a05d638b6074 virtio_net: do not allow tunnel csum offload for non GSO packets
  • ce311bd2e365 tcp: clear sock_ops cb flags before force-closing a child socket
  • 67cec2f1eb9e handshake: Require admin permission for DONE command
  • d0503357653e power: supply: core: fix supplied_from allocations
  • 7f4aa81f5bb2 ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO
  • 0c22c0092435 iommu: Avoid copying the user array twice in the full-array copy helper
  • 1c9246a199e1 spi: xilinx: use FIFO occupancy register to determine buffer size
  • dae23c545eb5 ALSA: seq: Fix kernel heap address leak in bounce_error_event()
  • 1749fef4bda0 ALSA: usb-audio: qcom: Guard sideband endpoint removal
  • 2ba237315193 crypto: rng - Free default RNG on module exit
  • fb4d57b83356 crypto: cavium/cpt - fix DMA cleanup using wrong loop index
  • 5f99a396f706 crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
  • 4941205f5fa3 cxl/test: Add check after kzalloc() memory in alloc_mock_res()
  • a27481516d32 cxl/test: Unregister cxl_acpi in cxl_test_init() error path
  • 7e401233f9bb tipc: reject inverted service ranges from peer bindings
  • 3cfa3d8e0dc1 tipc: prevent snt_unacked underflow on CONN_ACK
  • cebaefe1aceb tipc: require net admin for TIPCv2 netlink mutators
  • 66dbb13eeb2f net/sched: sch_hfsc: Don't make class passive twice
  • 51a1d9836acc net: pfcp: allocate per-cpu tstats for PFCP netdevs
  • ed8605c6f39b sctp: validate embedded address parameter length
  • a090880c1f54 bridge: cfm: reject invalid CCM interval at configuration time
  • bb4a5b3c91af net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().
  • 0a8b5b74f0e6 net/sched: cls_flow: Dont expose folded kernel pointers
  • 10e05634ddc1 net: dsa: qca8k: fix led devicename when using external mdio bus
  • e098c9c6477d ASoC: tegra: tegra210_ahub: Validate written enum value
  • 0f1510e84d7b ASoC: fsl: fsl_audmix: Validate written enum values
  • 9131e4b023e0 ASoC: codecs: hdac_hdmi: Validate written enum value
  • cb527e063a32 ASoC: SOF: Intel: hda-sdw-bpt: select SND_SOF_SOF_HDA_SDW_BPT properly
  • d3ff718c0c71 RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one
  • 4b87a2497276 RDMA/mlx5: Fix undefined shift of user RQ WQE size
  • 1bc1487f7a7f RDMA/mlx5: Remove raw RSS QP restrack tracking
  • f704db4b0318 RDMA/mlx5: Remove DCT restrack tracking
  • 3a1687e0506b fs: efs: remove unneeded debug prints
  • 7e694ac97591 Bluetooth: vhci: validate devcoredump state before side effects
  • ec4d352747a6 Bluetooth: hci: validate codec capability element length
  • 7f206a8d8d82 Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path
  • a0fd1086a57b Bluetooth: hci_core: Fix UAF in hci_unregister_dev()
  • e8815ae9dcdc Bluetooth: hci_event: fix simultaneous discovery stuck in FINDING
  • f1b4df9c260c Bluetooth: eir: Fix stack OOB write when prepending the Flags AD
  • e284bb94ad45 Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device
  • c86c861c64b5 s390/process: Fix kernel thread function pointer type
  • 0eab19ab9cb1 ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset()
  • c83255f3cf22 arm64: dts: allwinner: a523: Add missing GPIO interrupt
  • ad6963c3bb45 pinctrl: airoha: an7581: fix misprint in gpio19 pinconf
  • 5985ddfd3e83 pinctrl: airoha: an7581: add missed gpio32 pin group
  • db3cd694ded4 pinctrl: airoha: generalize pins/group/function/confs handling
  • 0234e8fc296e pinctrl: sunxi: a523: Remove unneeded IRQ remuxing flag
  • 46fbafe3d2d5 bpf: Tighten cgroup storage cookie checks for prog arrays
  • d416dcefdbac vfio/qat: fix f_pos race in qat_vf_resume_write()
  • 1201dbb26050 of: cpu: add check in __of_find_n_match_cpu_property()
  • d2acea4f4747 cxl/test: Zero out LSA backing memory to avoid leaking to user
  • 42a9a76f314e cxl/test: Fix integer overflow in mock LSA bounds checks
  • 91ad3088ee1b selftests/bpf: Fix bpf_iter/task_vma test
  • f00f5c0dd553 ext4: fix kernel BUG in ext4_write_inline_data_end
  • c998a09c7144 bonding: 3ad: fix mux port state on oper down
  • f0ada4846d11 bonding: 3ad: fix carrier when no usable slaves
  • cb20a9b50efe bonding: 3ad: add lacp_strict configuration knob
  • 47636f0a70b3 netlink: specs: rt-link: missed broadcast-neigh
  • 6b2c271d2c39 tools: missed broadcast_neigh if_link uapi header
  • 484b3b9aa798 ext4: fix ERR_PTR(0) in ext4_mkdir()
  • 88cb304c0be0 ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails
  • 8b55e7ec116c ASoC: cs35l56: Fix missing calls to wm_adsp2_remove()
  • 3ef0cfa77a3d vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
  • 54556d539438 vdpa/octeon_ep: Fix PF->VF mailbox data address calculation
  • 86e0b37738de tools/virtio: check mmap return value in vringh_test
  • 321c73baf54d vhost/net: complete zerocopy ubufs only once
  • 646614dcb160 vduse: Requeue failed read to send_list head
  • f9d922023445 virtio_console: read size from config space during device init
  • 79366023aa89 virtio: rtc: tear down old virtqueues before restore
  • 1f5f94c6c6b2 vhost/vdpa: validate virtqueue index in mmap and fault paths
  • a2d0a57538fd vduse: hold vduse_lock across IDR lookup in open path
  • 3d56f3fb201f ASoC: codecs: aw88261: fix incorrect masks for boost regs
  • ecb9be4fc8be spi: meson-spifc: fix runtime PM leak on remove
  • da6f86ff4f2d NFSD: Handle layout stid in nfsd4_drop_revoked_stid()
  • 37e85be551c4 IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified
  • e6d83f877d5a ASoC: sma1307: Fix uevent string leaks in fault worker
  • 701ea71c17c9 igc: skip RX timestamp header for frame preemption verification
  • 2aa37c8ef109 btrfs: fix deadlock cloning inline extent when using flushoncommit
  • f85410ebf20b btrfs: annotate lockless read of defrag_bytes in should_nocow()
  • 18285888cb41 btrfs: zoned: always set max_active_zones for zoned devices
  • 943f5917c53c Revert "btrfs: fix the file offset calculation inside btrfs_decompress_buf2page()"
  • ba641829c11c btrfs: zoned: don't account data relocation space-info in statfs free space
  • bd5e90b0f5a0 hwmon: (it87) Clamp negative values to zero in set_fan()
  • ebb579c5c0f0 vfs: add FS_USERNS_DELEGATABLE flag and set it for NFS
  • de590cdf7efe fbdev: sm501fb: Fix buffer errors in OF binding code
  • 0678fed27def wifi: ath12k: enable IEEE80211_VHT_EXT_NSS_BW_CAPABLE when NSS ratio is reported
  • 47e5302722e0 gpio: mt7621: fix interrupt banks mapping on gpio chips
  • 90a9c909c5b7 ALSA: aloop: Drop superfluous break
  • 3b15d02be05e btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
  • 7ec839c7c0bc wifi: mt76: mt7996: fix potential tx_retries underflow
  • ad12fdaaed16 wifi: mt76: mt7925: fix potential tx_retries underflow
  • 3b6e6fefa57f wifi: mt76: mt7921: fix potential tx_retries underflow
  • 6b8e35685c18 wifi: mt76: mt7915: fix potential tx_retries underflow
  • 6356a829a1ed wifi: mt76: fix argument to ieee80211_is_first_frag()
  • 42f34c478fcd wifi: mt76: mt7996: limit work in set_bitrate_mask
  • 1a399103cacc wifi: mt76: mt7996: fix reading zeroed info->control.flags after mt76_tx_status_skb_add()
  • dfb27e5dd9e4 wifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write_txwi_80211()
  • 06e65d6cf804 wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb()
  • c386e90a7ce8 wifi: mt76: mt7925: validate skb length in testmode query
  • 856fa6a21586 wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX
  • a10e4959a73b wifi: mt76: mt7925: keep TX BA state in the primary WCID
  • b8bf7c221b36 wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links
  • bd3b91ff1300 wifi: mt76: mt7996: add missing max_remain_on_channel_duration
  • c7a83899203e wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link
  • 3f0ea6d14fa4 wifi: mt76: mt7925: clean up DMA on probe failure
  • ce9d5a021cfc ARM: configs: Drop duplicated CONFIG_EXT4_FS
  • c788617705c3 sched/fair: Fix cpu_util runnable_avg arithmetic
  • a2e8b5264f92 hwspinlock: qcom: avoid uninitialized struct members
  • bbd664b7c77f vmalloc: fix NULL pointer dereference in is_vm_area_hugepages()
  • 648a3960e366 pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39
  • 44cff0737127 pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39
  • f775e7bda9a4 scsi: target: Remove tcm_loop target reset handling
  • c2bd9fdb448d scsi: target: Fix hexadecimal CHAP_I handling
  • 0404baeb9e43 pinctrl: qcom: Fix resolving register base address from device node
  • 298821692d44 watchdog: unregister PM notifier on watchdog unregister
  • 637ef4961470 configfs: fix lockless traversals of ->s_children
  • f25d6e4ec4c2 firmware_loader: Fix recursive lock in device_cache_fw_images()
  • 9e82497138ab ASoC: amd: acp-sdw-sof: Bound DAI link iteration
  • 1279bdab5fa1 ASoC: amd: acp-sdw-legacy: Bound DAI link iteration
  • e8d89baf9217 spi: ep93xx: fix double-free of zeropage on DMA setup failure
  • e123f0ab02d0 IB/mlx5: Don't mangle the mr->pd inside the rereg callback
  • fd284b12810e IB/mlx5: Pull the pdn out of the depths of the umr machinery
  • 8119fe468b01 IB/mlx5: Remove unused mkc bits in mlx5r_umr_update_mr_page_shift()
  • d4f84bfa089f IB/mlx5: Properly support implicit ODP rereg_mr
  • f5657d399b7e IB/mlx5: Don't take the rereg_mr fallback without a new translation
  • c213b71a2d41 btrfs: don't force DIO writes to be serialized
  • 920dcf1cb8da thermal: testing: reject missing command arguments
  • dde04550fd6f cpufreq: Documentation: fix conservative governor freq_step description
  • 6cb635ad1006 ACPI: IPMI: Fix message kref handling on dead device
  • b7474f4432dd bpf: Fix NULL pointer dereference in bpf_task_from_vpid()
  • 84932636d020 powerpc/8xx: implement get_direction() in cpm1
  • 8daa1a64711e kunit:tool: Don't write to stdout when it should be disabled
  • 8b0510cc3a4a bpf: Fix NMI/tracepoint re-entry deadlock on lru locks
  • 74ac1ce1f4af ALSA: seq: Clear variable event pointer on read
  • c04e0cde2fa3 riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe
  • 834d4cc067fa riscv: cpu_ops: Change return value type of cpu_is_stopped() to bool
  • 4b2b6bc7f5eb ALSA: seq: Fix partial userptr event expansion
  • af8f0ea1f0a3 wifi: wcn36xx: fix OOB read from short trigger BA firmware response
  • f03782f7f41f wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication
  • 1b5d8a248c3a wifi: wcn36xx: fix heap overflow from oversized firmware HAL response
  • 495e7e832c67 bpf: Update transport_header when encapsulating UDP tunnel in lwt
  • efe57b72196a bpf: Check tail zero of bpf_prog_info
  • 58513d6d1241 bpf: Check tail zero of bpf_map_info
  • 2eb39de4962f bpf: Clear rb node linkage when freeing bpf_rb_root
  • f6183983ce1f RDMA/siw: Fix endpoint/socket association handling
  • 04255bda8d79 arm64: dts: imx8mp-kontron: Fix GPIO for display power switch
  • e6ab22200e44 arm64: dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as well
  • f3ef944c5599 arm64: dts: lx2162a-clearfog: use rev2 SoC dtsi
  • b5087fc4ef1f arm64: dts: imx95: Correct PCIe outbound address space configuration
  • ab4b5a07e1c1 arm64: dts: imx8mp-kontron: Reduce EERAM SPI clock frequency
  • f9173e0fc026 RDMA/irdma: Initialize iwmr->access during MR registration
  • 54cab78df037 RDMA/irdma: Fix OOB read during CQ MR registration
  • 844a1ae78e22 ALSA: hda: fix Kconfig dependency of HD Audio PCI
  • 47831b503ecb IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path()
  • fe5414d6b399 RDMA/hfi1: Open-code rvt_set_ibdev_name()
  • 77b4bfc1ce32 netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp
  • d53eecbca16f netfilter: conntrack: revert ct extension genid infrastructure
  • e6665d36b37b x86/cpu: Remove obsolete aperfmperf_get_khz() declaration
  • dd0d22fdae4c ALSA: usb-audio: qcom: Initialize offload control return value
  • 8ebc31b86dcc netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock
  • 5c9c67cf7a3d netfilter: synproxy: fix unaligned memory access in timestamp adjustment
  • b171119082ba netfilter: synproxy: adjust duplicate timestamp options
  • 4dbb71c046f7 netfilter: synproxy: drop packets if timestamp adjustment fails
  • dce1e3cf735d netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags
  • 7b819a84f1d5 netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures
  • c3ebf67cf8a9 ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release()
  • a087b2d3411e ocfs2/dlm: require a ref for locking_state debugfs open
  • 3fa7139b5f42 ocfs2: reject FITRIM ranges shorter than a cluster
  • 0e389fc290c3 ocfs2: fix buffer head management in ocfs2_read_blocks()
  • 3fe2d0d21c8a lib: kunit_iov_iter: repeatedly call alloc_pages_bulk()
  • bb44a7690a4d ocfs2: rebase copied fsdlm LVB pointers in locking_state
  • 9af58d10d0d8 of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails
  • 9a030fcb4b19 drm/amdkfd: always resume_all after suspend_all
  • b8d15e85596a cxl/fwctl: Fix __fortify_panic
  • b64120d54278 xfrm: fix NAT-related field inheritance in SA migration
  • ac9e29b191a0 perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains
  • 58cbb1c2aadf perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems
  • 4e18e9361aab perf/x86/amd/core: Always use the NMI latency mitigation
  • f5102e0fc3c6 iommu/vt-d: Fix RB-tree corruption in probe error path
  • 7f229d27bf27 vhost: fix vhost_get_avail_idx for a non empty ring
  • 73f9f54d7174 bpftool: Use libbpf error code for flow dissector query
  • 4beed798daf4 drm/amdgpu: set sub_block_index for mca ras sub-blocks
  • e82d515092a0 ext4: fix fast commit wait/wake bit mapping on 64-bit
  • 8cbd587e8cdb lockdep/selftests: Restore sched_rt_mutex state on PREEMPT_RT
  • 8d5ed4810e47 lockdep/selftests: Restore migrate_disable() state on PREEMPT_RT
  • c3b073a209a9 configfs_lookup(): don't leave ->s_dentry dangling on failure
  • 778bb4939d45 riscv: dts: sophgo: sg2042: use hex for CPU unit address
  • efe71fbced52 riscv: dts: sophgo: sg2044: use hex for CPU unit address
  • 5a1168ba0a95 lib/test_meminit: use && for bools
  • 377758884852 tick/sched: Fix TOCTOU in nohz idle time fetch
  • 5cf2c85b1231 bpf: Reject exclusive maps for bpf_map_elem iterators
  • 0830287cc6cb driver core: Use system_percpu_wq instead of system_wq
  • 5e406928404d nvme: fix FDP fdpcidx bounds check
  • 36bdda0c86d5 sched: restore timer_slack_ns when resetting RT policy on fork
  • ffa974b2f50a ext2: fix ignored return value of generic_write_sync()
  • 8d763babb2a2 mm/fake-numa: fix under-allocation detection in uniform split
  • 61f197297282 bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs
  • d81370c6c4f5 scsi: ufs: Fix wrong value printed in unexpected UPIU response case
  • 846052542cfa scsi: pm8001: Fix error code in non_fatal_log_show()
  • 0de14eae6de8 libbpf: Skip max_entries override on signed loaders
  • abe383999640 libbpf: Skip initial_value override on signed loaders
  • b6862b6a25c6 libbpf: Reject non-exclusive metadata maps in the signed loader
  • 3a0f73d27a8d bpf: Reject exclusive maps as inner maps in map-in-map
  • 91ca9eab008b scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans"
  • 5c53406098b5 nvdimm/btt: Handle preemption in BTT lane acquisition
  • d292b30e1b74 x86/cpu: Keep the PROCESSOR_SELECT menu together
  • 901802925ebe ARM: imx31: Fix IIM mapping leak in revision check
  • 617a5a67ce01 ata: libata: Fix ata_exec_internal()
  • cfcea221db93 wifi: ath12k: fix NULL deref in change_sta_links for unready link
  • eb9b89baf308 wifi: ath12k: fix incorrect HT/VHT/HE/EHT MCS reporting in monitor mode
  • adf0eb748d21 HID: wiimote: Fix table layout and whitespace errors
  • 2d642797dd1c ARM: imx3: Fix CCM node reference leak
  • f0742d09eb6b NFSD: Fix delegation reference leak in nfsd4_revoke_states
  • 9e565962d999 ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble
  • 8ec64276ecd2 spi: atmel: fix DMA channel and bounce buffer leaks
  • ab4d04bf8b2f ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback
  • 803087a16a4e libbpf: Skip endianness swap when loader generation failed
  • f3389fbaff1a libbpf: Skip hash computation when loader generation failed
  • a441c0794ac2 selftests/bpf: add verification for BPF_PROG_QUERY attr size boundaries
  • a7131340d0f9 bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat
  • 5ac9e793ba25 raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path
  • b7313f23ea5a md/raid10: reset read_slot when reusing r10bio for discard
  • e04e384274f8 rpmsg: use generic driver_override infrastructure
  • 0e2f0833556c Drivers: hv: vmbus: use generic driver_override infrastructure
  • d2cf52ba2803 cdx: use generic driver_override infrastructure
  • b41923dbf676 amba: use generic driver_override infrastructure
  • ff4e38a37ba5 media: qcom: venus: relax encoder frame/blur step size on v6
  • bc7c166cc101 media: qcom: venus: relax encoder frame/blur dimension steps on v4
  • ffe754288750 media: qcom: venus: drop extra padding in NV12 raw size calculation
  • f8f48c851a0d Revert "media: venus: hfi_platform: Correct supported codecs for sc7280"
  • 5420eebf3b3c RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path
  • 02558c86b6b7 RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe
  • 4779f435627b RDMA/umem: Add ib_umem_is_contiguous() stub for !CONFIG_INFINIBAND_USER_MEM
  • bae436a78a05 arm64: dts: st: Fix SAI addresses on stm32mp251
  • 5da012c605fd EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info

View originalPermalink
How 6.18.40-xanmod1 went

7.1.4-xanmod1

Fixed 20
  • xfs: use rtrefcount btree cursor in xchk_xref_is_rt_cow_staging
  • xfs: write the rg superblock when fixing it
  • xfs: fix off-by-one error when calling xchk_xref_has_rt_owner
  • xfs: don't zap bmbt forks if they are MAXLEVELS tall
  • xfs: fully check the parent handle when it points to the rootdir
  • xfs: clamp timestamp nanoseconds correctly

From XanMod Kernel

  • 967cc061f0dc Linux 7.1.4-xanmod1
  • d3dc120f721d Merge tag 'v7.1.4' into 7.1
  • 7a5cef0db479 Linux 7.1.4
  • 63940a3adc7d xfs: use rtrefcount btree cursor in xchk_xref_is_rt_cow_staging
  • 5394c215efde xfs: write the rg superblock when fixing it
  • 4d281a74eed8 xfs: fix off-by-one error when calling xchk_xref_has_rt_owner
  • 19fa8bc0df48 xfs: don't zap bmbt forks if they are MAXLEVELS tall
  • 704a6ba079f0 xfs: fully check the parent handle when it points to the rootdir
  • cb1f92cb29cc xfs: clamp timestamp nanoseconds correctly
  • b7e9edbed705 xfs: handle non-inode owners for rtrmap record checking
  • 261c7a32f637 xfs: set xfarray killable sort correctly
  • 5da68d6c927a xfs: use the rt version of the cow staging checker
  • b19e5b47424b xfs: grab rtrmap btree when checking rgsuper
  • 2b14fe1e0924 xfs: don't wrap around quota ids in dqiterate
  • 44f891bc0889 xfs: resample the data fork mapping after cycling ILOCK
  • cccbabeb9a18 xfs: fail recovery on a committed log item with no regions
  • 0bc4d4a97302 xfs: fix null pointer dereference in tracepoint
  • 57cba95f0e97 smb: client: reject overlapping data areas in SMB2 responses
  • 25e2ac320c3d Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev
  • 07e454687b13 timekeeping: Register default clocksource before taking tk_core.lock
  • ae8f855a28e0 ALSA: doc: usb-audio: Add doc for QUIRK_FLAG_IFB_SILENCE_ON_EMPTY
  • 0a7f33010c0e fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref
  • a635f427d57e fuse-uring: make a fuse_req on SQE commit only findable after memcpy
  • 4021a3a79eee fuse-uring: Avoid queue->stopped races and set/read that value under lock
  • 95d7f50aff2a fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues
  • 4f45f276d5b4 fuse-uring: end fuse_req on io-uring cancel task work
  • e8afc85acdf3 fuse-uring: fix moving cancelled entry to ent_in_userspace list
  • d01a09b442cb fuse-uring: fix data races on ring->ready
  • fe604c08d874 fuse-uring: fix EFAULT clobber in fuse_uring_commit
  • 893479015cb6 fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req
  • 1ec674d3d0ed fuse: don't block in fuse_get_dev() for non-sync_init case
  • 1f3f4060e656 fuse: fix io-uring background queue dispatch on request completion
  • 65a1c2551f7e fuse: re-lock request before returning from fuse_ref_folio()
  • 779b7f1fcdee fuse: do not use start_removing_noperm()
  • 81b1045c401c fuse: fix device node leak in cuse_process_init_reply()
  • a37a64ebc9d7 Revert "fuse: fix conversion of fuse_reverse_inval_entry() to start_removing()"
  • c78c4b242299 fuse: avoid 32-bit prune notification count wrap
  • 7ddcbd4dd85f fuse: back uncached readdir buffers with pages
  • 75c93cd3c421 RDMA/siw: bound Read Response placement to the RREAD length
  • 020700a2fdc4 RDMA/core: Fix broadcast address falsely detected as local
  • da3e44add94b RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
  • 2ffcdbfd1431 Input: maplecontrol - set driver data before registering input device
  • 79e6fd106356 Input: maplemouse - set driver data before registering input device
  • 2351e841951c Input: maple_keyb - set driver data before registering input device
  • d5ab7e52e86e Input: mms114 - fix multi-touch slot corruption
  • 2914e243ec9e Input: maplemouse - fix NULL pointer dereference in open()
  • b75371bc87ae Input: gscps2 - advance receive buffer write index
  • f3d5e77b27fd Input: mms114 - reject an oversized device packet size
  • a8d87184576c Input: touchwin - reset the packet index on every complete packet
  • 2691b68f9b03 Input: ads7846 - don't use scratch for tx_buf when clearing register
  • a747c4eb0265 Input: mms114 - fix touch indexing for MMS134S and MMS136
  • a40250f97c31 Input: iforce - bound the device-reported force-feedback effect index
  • 2a6766869012 Input: goodix - clamp the device-reported contact count
  • 6bac57d8fe2a Input: elan_i2c - prevent division by zero and arithmetic underflow
  • bfe622efecd4 Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
  • 64fb0e1161cc Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count
  • 43d61346c040 Input: synaptics-rmi4 - unregister function handlers on physical driver registration failure
  • 00904687b9c5 i2c: i801: fix hardware state machine corruption in error path
  • 5800647d19d3 i2c: imx-lpi2c: mark I2C adapter when hardware is powered down
  • 1f0ab044e106 i2c: stm32f7: truncate clock period instead of rounding it
  • cb037e697da0 i2c: davinci: Unregister cpufreq notifier on probe failure
  • d8c97bde8224 i2c: mpc: Fix timeout calculations
  • 35dbd1f1f603 i2c: core: fix adapter deregistration race
  • 036d554f532b i2c: core: fix adapter debugfs creation
  • 76402d37a5de i2c: core: fix adapter probe deferral loop
  • 034e30742811 i2c: core: fix NULL-deref on adapter registration failure
  • 3d760ca230b0 i2c: core: fix irq domain leak on adapter registration failure
  • fb2c0eab51ae fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
  • 284d5ba931a5 Revert "svcrdma: Use contiguous pages for RDMA Read sink buffers"
  • 40eedc4253db svcrdma: wake sq waiters when the transport closes
  • 0449a6583c0e dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning
  • 18bd476ef4a1 udmabuf: fix DMA direction mismatch in release_udmabuf()
  • cd1067ccc0db KVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier
  • f3a98d5881b9 KVM: guest_memfd: Treat memslot binding offset+size as unsigned values
  • f2ca2b532621 KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits
  • bf27cd2d58a4 KVM: TDX: Account all non-transient page allocations for per-TD structures
  • f0a47e6cb035 KVM: VMX: Handle bad values on proxied writes to LBR MSRs
  • aa41338ee2db KVM: SEV: Don't terminate SNP VMs on #VMGEXIT without a registered GHCB
  • 77eab9571f6d KVM: VMX: Refresh GUEST_PENDING_DBG_EXCEPTIONS.BS on all injected #DBs
  • dda5ce3fdf89 KVM: SVM: Only disable x2AVIC WRMSR interception for MSRs that are accelerated
  • a3487d5926dd KVM: SVM: Disable x2AVIC RDMSR interception for MSRs KVM actually supports
  • 256034648b9e KVM: x86: Add dedicated API for getting mask of accelerated x2APIC MSRs
  • dcdb476f5fc5 KVM: SEV: Pin source page for write when adding CPUID data for SNP guest
  • d4f4d61715d1 KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
  • 7fca3fcef81c KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU
  • 60e51a62170a LoongArch: KVM: Add missing slots_lock for device register/unregister
  • 5fd30133af86 KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB
  • 5c22e38cfb73 selftests/landlock: Increase default audit socket timeout
  • 395135628ad5 selftests/landlock: Filter dealloc records in audit_count_records()
  • 7621e00a4059 landlock: Account all audit data allocations to user space
  • c02f2a0ae1c1 selftests/landlock: Explicitly disable audit in teardowns
  • 0254cef9bf18 landlock: Set audit_net.sk for socket access checks
  • fe85607ceffc audit: fix removal of dangling executable rules
  • 2c6381d90898 iommufd: Set upper bounds on cache invalidation entry_num and entry_len
  • 0714e5a4c83e iommufd: Avoid partial fault group delivery in iommufd_fault_fops_read()
  • f66c16b17550 iommufd: Break the loop on failure in iommufd_fault_fops_read()
  • 76c05bd8f634 iommufd: Reject invalid read count in iommufd_fault_fops_read()
  • db4e1a1e9f13 iommufd: Propagate allocation failure in iommufd_veventq_deliver_fetch()
  • f682c833f7d5 iommufd: Reject invalid read count in iommufd_veventq_fops_read()
  • 7a860d6f260e iommufd: Rewind header length in done if iommufd_veventq_fops_read() fails
  • e7b5e5565274 iommufd: Set veventq_depth upper bound
  • 6c5fc40200cd iommufd: Move vevent memory allocation outside spinlock
  • f9f08e46b9e3 iommufd: Fix data_len byte-count vs element-count mismatch
  • 0cdbb97a4dbd iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read
  • ff189754fc34 iommu/amd: Don't split flush for amd_iommu_domain_flush_all()
  • 477f8dec3b5a iommu/vt-d: Avoid WARNING in sva unbind path
  • c76b8abce575 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
  • 49af4044ed98 nouveau/vmm: fix another SPT/LPT race
  • f250db8ea6e9 selftests/mm: fix ksft_process_madv.sh test category
  • 913324904ce9 selftests/mm: pagemap_ioctl: use the correct page size for transact_test()
  • 04ba248d02d9 mm: do file ownership checks with the proper mount idmap
  • 377b1cd6bbcf mm: page_ext: add count limit to page_ext_iter_next to prevent invalid PFN access
  • fceca62a095e selftests: mm: fix and speedup "droppable" test
  • 246f0713360a mm: fix mmap errno value when MAP_DROPPABLE is not supported
  • 9adedf9c885c lib/test_hmm: use kvfree() to free kvcalloc() allocations
  • ede985ff4b56 riscv: mm: Unconditionally sfence.vma for spurious fault
  • bc773b8b4c81 riscv: mm: Define DIRECT_MAP_PHYSMEM_END
  • 84ab222021c2 NTB: epf: Fix request_irq() unwind in ntb_epf_init_isr()
  • c8e041c68c0b exfat: bound uniname advance in exfat_find_dir_entry()
  • 5bfa2814528d exfat: preserve benign secondary entries during rename and move
  • c4c82cdfdf8a vt: fix spurious modifier in CSI/cursor key sequences
  • e7da02659c22 module: decompress: check return value of module_extend_max_pages()
  • 8e0a22bc728e rqspinlock: Fix order in raw_res_spin_(un)lock_irq to allow schedule
  • e36501b7d4ab NFSv4: include MAY_WRITE in open permission mask for O_TRUNC
  • 80a7608376e5 audit: fix potential integer overflow in audit_log_n_hex()
  • e5d5f3bd053a tracing: Prevent out-of-bounds read in glob matching
  • 792118d05f01 selftests/liveupdate: add test cases for LIVEUPDATE_IOCTL_CREATE_SESSION calls with invalid length
  • c04873ea85d9 liveupdate: reject LIVEUPDATE_IOCTL_CREATE_SESSION with invalid name length
  • 0cff05bd2186 perf/aux: Fix page UAF in map_range()
  • 5fd2dbeded54 i2c: core: fix hang on adapter registration failure
  • a935b64548fc regulator: scmi: fix of_node refcount leak in scmi_regulator_probe()
  • 3e6e9f17f583 watchdog: apple: Add "apple,t8103-wdt" compatible
  • 7057fcf3a6d3 EDAC/i10nm: Don't fail probing if ADXL is missing
  • 03f6ecbc446c x86/mm: Fix freeing of PMD-sized vmemmap pages
  • 9d000bdd250d spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
  • 507c13781101 spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync()
  • 02d9dac2b843 arm64: fpsimd: Fix type mismatch in sme_{save,load}_state()
  • 4519290ed20d crypto: talitos/hash - fix SEC2 64k - 1 ahash request limitation
  • 1691f2c4a4f2 crypto: talitos/hash - remove useless wrapper
  • a4ffe8e7bdfe crypto: talitos/hash - rename first_desc/last_desc to first_request/last_request
  • ab3b0f3e4e72 crypto: talitos/hash - drop workqueue mechanism for SEC1
  • 96a8955d7020 crypto: talitos/hash - use descriptor chaining for SEC1 instead of workqueue
  • a0cf230cb4df crypto: talitos/hash - prepare SEC1 descriptor chaining, remove additional descriptor
  • 0f21d65f4381 crypto: talitos - move code in current_desc_hdr() into a standalone function
  • 873e34c46cb7 crypto: talitos - move dma mapping code in talitos_submit() into a standalone dma_map_request() function
  • ec6669f1c162 crypto: talitos - move dma unmapping code in flush_channel() into a standalone dma_unmap_request() function
  • b624dcd2fda9 crypto: talitos - add chaining of arbitrary number of descriptor for the SEC1
  • 9d4ea20a402d crypto: talitos - use dma_sync_single_for_cpu() before reading descriptor header
  • abf9a568013c crypto: qat - factor out AER reset helpers
  • ce42224487c5 crypto: qat - validate RSA CRT component lengths
  • 8e8391469a92 crypto: qat - skip restart for down devices
  • 0dbcecea740d crypto: qat - protect service table iterations with service_lock
  • 425f1260ecb9 crypto: qat - notify fatal error before AER reset preparation
  • 6f52fe576ac6 crypto: qat - keep VFs enabled during reset
  • 4515bf525c96 crypto: qat - handle sysfs-triggered reset callbacks
  • 59c0901db2b7 crypto: qat - fix restarting state leak on allocation failure
  • c98aed00e65a crypto: qat - centralize bus master enable
  • d5c0a6f8dc7e crypto: drbg - Fix the fips_enabled priority boost
  • 044aaaba99e1 crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels
  • 59a27cf2d01a crypto: drbg - Fix ineffective sanity check
  • d9f4acde5ae9 crypto: drbg - Fix misaligned writes in CTR_DRBG and HASH_DRBG
  • a9e886f73dd7 crypto: drbg - Fix returning success on failure in CTR_DRBG
  • 20f548cdac94 crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG)
  • 8836801847b9 crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD)
  • 67ed191b4c8b crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)
  • d51207735e7c crypto: ccp - Do not initialize SNP for SEV ioctls
  • 43de8b9f01b7 crypto: loongson - Remove broken and unused loongson-rng
  • 0927083d5e3e crypto: loongson - Select CRYPTO_RNG
  • 855240d4d243 crypto: tegra - fix refcount leak in tegra_se_host1x_submit()
  • 83fa1397d585 crypto: pcrypt - restore callback for non-parallel fallback
  • 98a771d340bd crypto: hisi-trng - Remove crypto_rng interface
  • ebaae7c4251c crypto: ecc - Fix carry overflow in vli multiplication
  • a856bc7d0fbb crypto: crypto4xx - Remove insecure and unused rng_alg
  • e74df53b36cd crypto: chacha20poly1305 - validate poly1305 template argument
  • 59057f5d4e9a crypto: caam - use print_hex_dump_devel to guard key hex dumps again
  • 8cf5fb050312 crypto: caam - use print_hex_dump_devel to guard key hex dumps
  • d9dbf9a484cb crypto: af_alg - Remove zero-copy support from skcipher and aead
  • 9830725078c8 isofs: bound Rock Ridge symlink components to the SL record
  • b8df7f486a46 btrfs: fix incorrect buffered IO fallback for append direct writes
  • 44f37ee92fdc partitions: aix: bound the pp_count scan to the ppe array
  • b4af31b898a9 btrfs: do not trim a device which is not writeable
  • 5d444a2a06d0 btrfs: check and set EXTENT_DELALLOC_NEW before clearing EXTENT_DELALLOC
  • caa71b3a43ea nvmet-auth: validate reply message payload bounds against transfer length
  • 05645271751e btrfs: fix false IO failure after falling back to buffered write
  • a29b316b9bbf nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
  • 16898de2ca35 nvme-multipath: set BIO_REMAPPED on bios remapped to per-path namespace disks
  • f815869f926c dm-ioctl: report an error if a device has no table
  • 0d3d19f78595 block: partitions: fix of_node refcount leak in of_partition()
  • 5828517d17ed nvme: target: rdma: fix ndev refcount leak on queue connect
  • 1c0462532916 crypto: atmel-sha204a - fail on hwrng registration error in probe path
  • 5c925be839d8 crypto: atmel-sha204a - drop hwrng quality reduction for ATSHA204A
  • 68896ba8ccb8 hwrng: jh7110 - fix refcount leak in starfive_trng_read()
  • 7f7774b9da0e udf: validate sparing table length as an entry count, not a byte count
  • 74580fdf0229 udf: validate VAT header length against the VAT inode size
  • be87de7789a8 udf: validate free block extents against the partition length
  • 77e7b127472a wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon
  • aa4c4a931576 block: skip sync_blockdev() on surprise removal in bdev_mark_dead()
  • dfecbb9ee08d usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile
  • f99f32ea9aa9 usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks
  • 0cae3d610942 usb: gadget: f_fs: Fix DMA fence leak
  • ba1867999dbc usb: gadget: f_fs: initialize reset_work at allocation time
  • 3aeed2451603 usb: typec: ucsi: cancel pending work on system suspend
  • dbb500bad021 usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove
  • f1736bb63f74 usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode
  • 42ac1cc7de06 usb: typec: ucsi: Invert DisplayPort role assignment
  • 313ca06e7e22 usb: typec: tcpm: Validate SVID index in svdm_consume_modes()
  • 20f38be1d262 usb: typec: tcpm: Fix VDM type for Enter Mode commands
  • 9a95bf88c6e4 usb: typec: ps883x: Fix DP+USB3 configuration
  • 14457cb92258 usb: typec: class: drop PD lookup reference
  • 575cb72b5ed0 usb: typec: anx7411: use devm_pm_runtime_enable()
  • 0443e4416aa1 usbip: vudc: fix NULL deref in vep_dequeue()
  • ddc4619707af usbip: tools: support SuperSpeedPlus devices
  • e9b316d99a5c USB: usb-storage: ene_ub6250: restore media-ready check
  • e5493c9a98ff USB: ulpi: fix memory leak on registration failure
  • a3a13fdc5310 USB: serial: digi_acceleport: fix write buffer corruption
  • 79bc131df0e5 USB: serial: digi_acceleport: fix hard lockup on disconnect
  • 92fa3e1a4984 USB: serial: digi_acceleport: fix broken rx after throttle
  • 6c8ccd8db36e USB: serial: option: add Telit Cinterion FE990D50 compositions
  • d4b12b6b395e USB: serial: keyspan_pda: fix information leak
  • 835b0596d4c9 usb: mtu3: unmap request DMA on queue failure
  • 48dd0b2ec9f2 USB: misc: uss720: unregister parport on probe failure
  • fc1b546973c1 usb: misc: usbio: bound bulk IN response length to the received transfer
  • 88bf7b68ac90 USB: storage: include US_FL_NO_SAME in quirks mask
  • e4271a74bf99 usb: sl811-hcd: disable controller wakeup on remove
  • 9ba62966461a USB: legousbtower: fix use-after-free on disconnect race
  • 452c5d97ba38 USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD
  • 71590982700f USB: iowarrior: fix use-after-free on disconnect race
  • e4596816984e USB: iowarrior: fix use-after-free on disconnect
  • a3e794136ab5 USB: ldusb: fix use-after-free on disconnect race
  • e88cff5fbaa6 USB: idmouse: fix use-after-free on disconnect race
  • 7f1f24c36793 usb: gadget: f_printer: take kref only for successful open
  • 54fa390aae39 usb: gadget: udc: Fix use-after-free in gadget_match_driver
  • fcb21bf74764 usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler
  • 4bb88aee6b86 usb: free iso schedules on failed submit
  • f4f5219c06d4 usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume()
  • 4349e487a114 usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()
  • effc5f7942b4 USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub
  • 963075c4da0c usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()
  • 35179684907c usb: cdc_acm: Add quirk for Uniden BC125AT scanner
  • 0aa71f258810 Revert "usb: typec: mux: avoid duplicated mux switches"
  • 51e65f1d7845 net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()
  • bd6ad9a6b304 bpf: Allow LPM map access from sleepable BPF programs
  • d57db0d97505 bpf: Keep dynamic inner array lookups nullable
  • ff77d013b737 bpf: Validate BTF repeated field counts before expansion
  • ee7099359f96 bpf: Restore sysctl new-value from 1 to 0
  • 51d07c12ca41 bpf: Reject fragmented frames in devmap
  • 06a2e6dbaa26 xfs: fix memory leak in xfs_dqinode_metadir_create()
  • 4707344b0d36 xfs: fix exchmaps reservation limit check
  • 60db12509ec0 xfs: fix pointer arithmetic error on 32-bit systems
  • cbcb09dacb71 xfs: fix unreachable BIGTIME check in dquot flush validation
  • ed16544d0d8b xfs: initialize iomap->flags earlier in xfs_bmbt_to_iomap
  • ce03e51a24c1 xfs: only log freed extents for the current RTG in zoned growfs
  • 4693131bee05 xfs: pass back updated nb from xfs_growfs_compute_deltas
  • d108043cc04e xfs: release dquot buffer after dqflush failure
  • 33c2c9d717f6 xfs: use null daddr for unset first bad log block
  • 9690e8a34263 serial: 8250_mid: Disable DMA for selected platforms
  • 4c4b4af4a9f2 media: mtk-jpeg: cancel workqueue on release for supported platforms only
  • d26aef771b4f nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers
  • d5b45bad75cd hfs/hfsplus: zero-initialize buffer in hfs_bnode_read
  • c25d3c931a63 hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length
  • d36e69c8c0c8 HID: sensor-hub: Add sensor_hub_input_attr_read_values() for multi-byte reads
  • 8131f4226688 HID: lg-g15: cancel pending work on remove to fix a use-after-free
  • 6b0838e86da8 HID: appleir: fix UAF on pending key_up_timer in remove()
  • 6493ebf9489e HID: multitouch: fix out-of-bounds bit access on mt_io_flags
  • df3d8aa1a939 HID: letsketch: fix UAF on inrange_timer at driver unbind
  • 27c4dad1b791 HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush()
  • 57bdd10ad50d HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert
  • 3e7761f7bf9f HID: hid-lenovo-go: cancel cfg_setup work in hid_go_cfg_remove()
  • 48218df04220 HID: pidff: Use correct effect type in effect update
  • e2cc711a9df3 HID: wacom: stop hardware after post-start probe failures
  • cfc0d283d931 HID: uhid: convert to hid_safe_input_report()
  • 835fcc865556 HID: hid-goodix-spi: validate report size to prevent stack buffer overflow
  • 493f261c0772 tools/mm/slabinfo: fix total_objects attribute name
  • 27c83f667575 tools/mm/slabinfo: Fix trace disable logic inversion
  • 0d18ccef142f mm/slab: do not limit zeroing to orig_size when only red zoning is enabled
  • d33dc0d5824c X.509: Fix validation of ASN.1 certificate header
  • 942dfe844229 perf/arm-cmn: Fix DVM node events
  • c94806905e02 s390: Revert support for DCACHE_WORD_ACCESS
  • c67b06370ade clocksource/drivers/timer-tegra186: Fix support for multiple watchdog instances
  • 75b478096c6b time/jiffies: Register jiffies clocksource before usage
  • 8f06363446c5 posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path
  • c1cfd63326f5 proc: protect ptrace_may_access() with exec_update_lock (part 1)
  • 0e3c739a2f6f cpufreq: pcc: fix use-after-free and double free in _OSC evaluation
  • a0106b41f9a7 cpufreq: Fix hotplug-suspend race during reboot
  • a18f80bf5359 sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT
  • e0d0adc3d204 cpufreq: intel_pstate: Sync policy->cur during CPU offline
  • a5f5f5053f98 perf/x86/intel/uncore: Defer ADL global PMON enable to enable_box()
  • dfd1894cb64c proc: protect ptrace_may_access() with exec_update_lock (FD links)
  • 8e931557b317 libfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo()
  • 15432f19562f firmware_loader: fix device reference leak in firmware_upload_register()
  • 9de568ef6cdf cpufreq: qcom-cpufreq-hw: Fix possible double free
  • 625b014f922c OPP: of: Fix potential memory leak in opp_parse_supplies()
  • 53eeaf4d6306 writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs()
  • eedf142d994e smb/server: do not require delete access for non-replacing links
  • f80add1bfb34 smb: client: mask server-provided mode to 07777 in modefromsid
  • fc25bbc893f6 smb: client: fix atime clamp check in read completion
  • 46a84715a015 smb: client: harden POSIX SID length parsing
  • 52f9c9dafefc smb: client: use unaligned reads in parse_posix_ctxt()
  • 927d4805aea0 smb: client: Fix next buffer leak in receive_encrypted_standard()
  • b18ed621dbfc smb: client: fix double-free in SMB2_close() replay
  • ff2d30927bc3 smb: client: fix double-free in SMB2_open() replay
  • 013a9a3da46c smb: client: fix double-free in SMB2_flush() replay
  • 901891513951 smb: client: fix change notify replay double-free
  • fc65ffb4ef1b smb: client: fix double-free in SMB2_ioctl() replay
  • 89234773e834 smb: client: fix query_info() replay double-free
  • 3317a5d015fc smb: client: fix query directory replay double-free
  • 550cfb8a8118 smb/client: fix chown/chgrp with SMB3 POSIX Extensions
  • 89ca7756d556 ksmbd: validate NTLMv2 response before updating session key
  • 5fecc15a30cb ksmbd: track the connection owning a byte-range lock
  • 52a56cf53ec8 ksmbd: use opener credentials for ADS I/O
  • 4b7059974549 ksmbd: use opener credentials for delete-on-close
  • 3bed9974fdf8 ksmbd: add per-handle permission check to FILE_LINK_INFORMATION
  • 5bc2aa358b57 ksmbd: enforce FILE_READ_ATTRIBUTES on SMB_FIND_FILE_POSIX_INFORMATION
  • 8cc9ec711f52 ksmbd: run set info with opener credentials
  • aae600cdaffc ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY
  • a10942af2783 ksmbd: require source read access for duplicate extents
  • 5c75275c0fc9 ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation
  • fd22b039a5a0 ksmbd: serialize QUERY_DIRECTORY requests per file
  • deffa929086d ksmbd: add a permission check for FSCTL_SET_ZERO_DATA
  • c917e4522d25 ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE
  • 8c9a4f1327eb ksmbd: prevent path traversal bypass by restricting caseless retry
  • a1cc432cb0b0 smb/client: Fix error code in smb2_aead_req_alloc()
  • 0700f946659d smb: client: resolve SWN tcon from live registrations
  • daf6246ab988 coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()
  • 6b47bdaacfd0 Bluetooth: L2CAP: validate option length before reading conf opt value
  • e96fbac8d3a7 Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
  • 01afd198c2c2 Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync()
  • 714d861d35d9 Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled
  • b42cb640a049 Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()
  • 50c662bdcd51 Bluetooth: fix UAF in bt_accept_dequeue()
  • 49bcb39e3a04 Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3()
  • 563a85730471 Bluetooth: bnep: pin L2CAP connection during netdev registration
  • 0f0a83e26a9c Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()
  • 9efe838c1313 netfilter: flowtable: IPIP tunnel hardware offload is not yet support
  • 419835f1bd5f netfilter: flowtable: fix offloaded ct timeout never being extended
  • b6183b1b88a7 netfilter: ebtables: terminate table name before find_table_lock()
  • 7b217960e88b netfilter: ebtables: module names must be null-terminated
  • 5ee856e4208a netfilter: ebtables: zero chainstack array
  • 57056be3ec12 netfilter: handle unreadable frags
  • 02f8a0a1da2e netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump
  • 2a55fdf9f746 mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup
  • 6a4196d19f47 mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host
  • b9beed2322f3 mm: shrinker: fix NULL pointer dereference in debugfs
  • 284c267f013e mm: shrinker: fix shrinker_info teardown race with expansion
  • 86237e56091e mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()
  • fc030c5b116f mfd: cros_ec: Delay dev_set_drvdata() until probe success
  • c12a5b226135 media: nxp: imx8-isi: Fix use-after-free on remove
  • a094ac95d3b6 net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes
  • f91883031e5a ipv4: igmp: remove multicast group from hash table on device destruction
  • 5ed09a108d93 netpoll: fix a use-after-free on shutdown path
  • f254713ac539 io_uring/rw: preserve partial result for iopoll
  • ab85765cbe32 io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item
  • 7267717f3578 io_uring/nop: fix file reference leak with IOSQE_FIXED_FILE
  • 7a89ad762fad HID: logitech-dj: Fix maxfield check in DJ short report validation
  • 41cad91a09d6 gpio: sch: use raw_spinlock_t in the irq startup path
  • 5c3c9ec1172a gpio: eic-sprd: use raw_spinlock_t in the irq startup path
  • 6350df503897 NTB: epf: Avoid calling pci_irq_vector() from hardirq context
  • e2018628301a ntfs: avoid calling post_write_mst_fixup() for invalid index_block
  • f433acc85b86 fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns
  • 1f4f02b336c3 debugobjects: Plug race against a concurrent OOM disable
  • 2edd162cbd4a coresight: etb10: restore atomic_t for shared reading state
  • 9531014c60c8 Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete
  • 50c38d9f42a5 Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
  • c5186201fa70 audit: Fix data races of skb_queue_len() readers on audit_queue
  • cea34abc94b0 net: af_key: initialize alg_key_len for IPComp states
  • 12c36c99655f ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL
  • 6e92b28cd74f crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()
  • 2b7bd6dccff1 crypto: krb5 - filter out async aead implementations at alloc
  • 6dda8406d8a3 crypto: amlogic - avoid double cleanup in meson_crypto_probe()
  • 225b6d3fc7e9 staging: rtl8723bs: fix OOB write in HT_caps_handler()
  • 729c4e72563b staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()
  • 4380b3860d88 staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop
  • 402f13ec9594 staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()
  • b5cc2f999927 staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop
  • 7e7741c8315e staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop
  • d90b9f39f375 staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()
  • 138cd190efd5 staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()
  • 35f4dbec7380 staging: rtl8723bs: don't drop short TX frames in _rtw_pktfile_read()
  • 837c1f965542 staging: media: ipu7: fix double-free and use-after-free in error paths
  • 7c973c5113e3 staging: media: atomisp: reduce load_primary_binaries() stack usage
  • 753e684fa55f media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe
  • c6cda17e9854 staging: vme_user: fix location monitor leak in tsi148 bridge
  • 157bcfc7955c staging: vme_user: fix location monitor leak in fake bridge
  • 6e9d10f62773 smb: client: restrict implied bcc[0] exemption to responses without data area
  • 1b495fa0d492 staging: vme_user: bound slave read/write to the kern_buf size
  • f333b6851bdf tipc: fix out-of-bounds read in broadcast Gap ACK blocks
  • 69f17ac132a3 tracing: Fix NULL pointer dereference in func_set_flag()
  • b713aa0cc344 6lowpan: fix NHC entry use-after-free on error path
  • 1947b6411460 usb: misc: usbio: fix disconnect UAF in client teardown
  • 642e04f5c292 usb: dwc3: run gadget disconnect from sleepable suspend context
  • 8f50613bff22 USB: chaoskey: Fix slab-use-after-free in chaoskey_release()
  • 92d5736a6204 hwrng: virtio: clamp device-reported used.len at copy_data()
  • 378493da2980 virtio-mmio: fix device release warning on module unload
  • 64a4c0befa77 virtio_pci: fix vq info pointer lookup via wrong index
  • e8ee198bbc04 netfilter: ipset: fix race between dump and ip_set_list resize
  • 76e415ea88d2 mm/damon/ops-common: handle extreme intervals in damon_hot_score()
  • 4caf12c778fe tcp: restore RCU grace period in tcp_ao_destroy_sock
  • 55fd485e66d0 PCI/IOV: Skip VF Resizable BAR restore on read error
  • 7908ddb6f8b3 PCI: Skip Resizable BAR restore on read error
  • 67a8b1d876d5 PCI: qcom: Initialize DWC MSI lock for firmware-managed ECAM hosts
  • df77314b3bed PCI: mediatek: Fix IRQ domain leak when port fails to enable
  • 6a2363bf9eae PCI: imx6: Assert ref_clk_en after reference clock stabilizes on i.MX95
  • edefa5f4b701 PCI: imx6: Fix IMX6SX_GPR12_PCIE_TEST_POWERDOWN handling
  • 76143cbb18dc PCI: imx6: Configure REF_USE_PAD before PHY reset for i.MX95
  • 7707ac040967 PCI: host-common: Request bus reassignment when not probe-only
  • 669c4f387600 PCI: Always lift 2.5GT/s restriction in PCIe failed link retraining
  • 6864c789b570 PCI: altera: Fix resource leaks on probe failure
  • ff396bab155f PCI: altera: Do not dispose parent IRQ mapping
  • bc29e49364ea PCI: loongson: Override PCIe bridge supported speeds for Loongson-3C6000 series
  • 1d3f464bb158 riscv: dts: sophgo: Add dma-coherent to SG2042 PCIe controllers
  • 569f18a83eed usb: typec: tcpci_rt1711h: unregister TCPCI port with devres
  • a3eaf82ff842 xhci: sideband: fix ring sg table pages leak
  • 93cd037da94f usb: xhci: Fix sleep in atomic context in xhci_free_streams()
  • 0644da3621dd rust_binder: clear freeze listener on node removal
  • 59fbe6b20456 rust_binder: synchronize Rust Binder stats with freeze commands
  • ad6af5c32dac rust_binder: reject context manager self-transaction
  • 3ffc336432da rust_binder: fix BINDER_GET_EXTENDED_ERROR
  • 74920b1b4e47 rust_binder: use a u64 stride when cleaning up the offsets array
  • 0f15f0f6ca5d binder: fix UAF in binder_free_transaction()
  • ef5439ba5b9a binder: fix UAF in binder_thread_release()
  • 087a305e025c Bluetooth: btusb: fix wakeup source leak on probe failure
  • 838c917a2f16 Bluetooth: btusb: fix use-after-free on marvell probe failure
  • da7d7758fe88 Bluetooth: btusb: fix use-after-free on registration failure
  • c028dfa0a3c7 Bluetooth: btusb: Add USB ID 2c4e:0128 for Mercusys MA60XNB
  • 39d163627b51 vfio/mlx5: Fix racy bitfields and tighten struct layout
  • a5df401dc84f vfio: Remove device debugfs before releasing devres
  • a3a8afa2f6e7 vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc
  • ad0f12d2dfc2 vfio/pci: Fix racy bitfields and tighten struct layout
  • 278a5659c391 vfio/pci: Release the VGA arbiter client on register_device() failure
  • 062b820290bc vfio/pci: Latch disable_idle_d3 per device
  • 2bdb4c96287d vfio/pci: Use a private flag to prevent power state change with VFs
  • 58c5ec23b1a2 x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled
  • c4fe3d9551ea ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes
  • 3314c5af8a13 ALSA: usb-audio: Update Babyface Pro control caches only after successful writes
  • 4e01d542e910 ALSA: usb-audio: Roll back quirk control caches on write errors
  • 14dfb2abae01 ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks
  • edf3ce5a72ca ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put()
  • 4246dd043b7a ALSA: usb-audio: avoid kobject path lookup in DualSense match
  • 344b64d4d411 ALSA: usb-audio: add IFB_SILENCE_ON_EMPTY quirk for Behringer Flow 8
  • ab1db6491242 ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission
  • 6ded42615fa1 ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()
  • 38a7cc46370a ALSA: ice1712: check snd_ctl_new1() return value
  • 17f31b904e8c ALSA: hda/realtek: Fix noisy mic for Clevo V6xxAW
  • 8bbba4ab5e6d ALSA: hda/hdmi: Use 'AC_PINSENSE_ELDV' to detect pinsense for Loongson
  • 0056958bf308 ALSA: hda/hdmi: Add force-connect quirk for HP EliteDesk 800 G5 Mini
  • d6a40a4d083e ALSA: hda/cs35l41: Fix firmware load work teardown
  • 465075c68351 ALSA: gus: check snd_ctl_new1() return value
  • 31a01b70bb90 ALSA: firewire: isight: bound the sample count to the packet payload
  • aeeeae9c1a51 ALSA: FCP: Add Focusrite ISA C8X support
  • 1949163dee39 ALSA: es1938: check snd_ctl_new1() return value
  • 426a9947a38d ALSA: compress: Fix task creation error unwind
  • 67e9ea92cd59 ALSA: cmipci: check snd_ctl_new1() return value
  • 0680413f2f10 ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser
  • e47f2a341adb ALSA: aoa: check snd_ctl_new1() return value
  • 18ec7d7785be ALSA: ymfpci: check snd_ctl_new1() return value
  • 21584672fd69 ALSA: virtio: Validate control metadata from the device
  • 6f3c7e552fd8 ALSA: virtio: Add missing 384 kHz PCM rate mapping
  • 27161c68d5e7 ALSA: usx2y: us144mkii: fix work UAF on disconnect
  • d90f868f56a1 iio: temperature: tmp006: use devm_iio_trigger_register
  • d8274d1a79af iio: temperature: ltc2983: Fix reinit_completion() called after conversion start
  • e52f7939a41c iio: temperature: ltc2983: Fix n_wires default bypassing rotation check
  • f87b86a7fd9e iio: temperature: Build mlx90635 with CONFIG_MLX90635
  • 1c8150ee8f2f iio: resolver: ad2s1210: notify trigger and clear state on fault read error
  • 769e819e6925 iio: proximity: vl53l0x: notify trigger and clear IRQ on error paths
  • 46e69d3dd429 iio: pressure: mpl115: fix runtime PM leak on read error
  • 9990e06016af iio: pressure: bmp280: zero-init bmp580 trigger handler buffer
  • 0adca7d78b7b iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call
  • 8a383705c455 iio: light: veml6030: fix channel type when pushing events
  • 9f45d437ce24 iio: light: tsl2591: return actual error from probe IRQ failure
  • 56447eeab51e iio: light: opt3001: fix missing state reset on timeout
  • 2ebaea7f3089 iio: light: gp2ap002: fix runtime PM leak on read error
  • a82b89a35692 iio: light: al3320a: read both ALS ADC registers again
  • 2b42c313b941 iio: light: al3320a: add missing REGMAP_I2C to Kconfig
  • e297afa1845f iio: light: al3010: read both ALS ADC registers again
  • 78451f43e3f4 iio: light: al3010: fix incorrect scale for the highest gain range
  • acd4946b583a iio: light: al3010: add missing REGMAP_I2C to Kconfig
  • c2d8c2696b8c iio: light: al3000a: add missing REGMAP_I2C to Kconfig
  • 4f49fef6179d iio: imu: st_lsm6dsx: deselect shub page before reading whoami
  • 2e2595765dcb iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading
  • 9fdc477b652a iio: imu: inv_icm42600: fix timestamp clock period by using lower value
  • 65f1f81e7521 iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ
  • 9f5690f2dc54 iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ
  • a11bc637375e iio: gyro: bmg160: wait full startup time after mode change at probe
  • 6c8675468862 iio: gyro: bmg160: bail out when bandwidth/filter is not in table
  • f187dc5a4c48 iio: event: Fix event FIFO reset race
  • b03fb2f8c6fc iio: dac: ad3552r-hs: fix uninitialized data ni ad3552r_hs_write_data_source()
  • 89fbd3e32dff iio: core: fix uninitialized data in debugfs
  • 20a5fee40c3d iio: common: st_sensors: honour channel endianness in read_axis_data
  • d49ff54b2784 iio: chemical: scd30: Cleanup initializations and fix sign-extension bug
  • fb8e18f8ca72 iio: buffer: hw-consumer: free scan_mask on buffer release
  • 33b29764f6c4 iio: backend: fix uninitialized data in debugfs
  • 84552fdcef8f iio: adc: ti-ads124s08: Return reset GPIO lookup errors
  • 6537f0810018 iio: adc: ti-ads1119: fix PM reference leak in buffer preenable
  • eb5b07c9d0ec iio: adc: spear: Initialize completion before requesting IRQ
  • af885d419b4d iio: adc: nxp-sar-adc: Fix the delay calculation in nxp_sar_adc_wait_for()
  • 2f18c5551aa9 iio: adc: lpc32xx: Initialize completion before requesting IRQ
  • f1de829ee87a iio: adc: ad_sigma_delta: fix CS held asserted and state leaks
  • 3bceb26dfaf7 iio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices
  • 73a92d5e3d78 iio: adc: ad7779: add missing 'select IIO_TRIGGERED_BUFFER' to Kconfig
  • f75a12808cd3 iio: adc: ad7768-1: Select GPIOLIB
  • e3f3fcf011e7 iio: adc: ad7380: select REGMAP
  • 5d32dd6338c8 iio: adc: ad4062: add GPIOLIB dependency
  • 13a91e8631cf iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error
  • 35a3cd8fd65e iio: accel: bmc150: clamp the device-reported FIFO frame count
  • 9facd79028a7 usb: gadget: function: rndis: add length check for header
  • b09716040f3f usb: gadget: function: rndis: add length check to response query
  • 994994cfadaf wifi: rtw89: correct drop logic for malformed AMPDU frames
  • 29d3f527bc1a bpf: Prefer dirty packs for eBPF allocations
  • 3448efcb18ae bpf: Prefer packs that won't trigger an IBPB flush on allocation
  • 80a96785fe42 bpf: Skip redundant IBPB in pack allocator
  • 7ff3b159b8b7 bpf: Restrict JIT predictor flush to cBPF
  • 52440e15d962 x86/bugs: Enable IBPB flush on BPF JIT allocation
  • 7a6c171c6a1a bpf: Support for hardening against JIT spraying
  • 06ccef0434e9 perf/core: Detach event groups during remove_on_exec
  • 007f071b2c39 futex/requeue: Revert "Prevent NULL pointer dereference in remove_waiter() on self-deadlock""
  • 89592176b718 rust: Kbuild: set frame-pointer llvm module flag for CONFIG_FRAME_POINTER
  • c781009975c5 rust: doctest: fix incorrect pattern in replacement
  • 6822a2685b4d rust: block: fix GenDisk cleanup paths
  • afa40a464072 rust: pci: use 'static lifetime for PCI BAR resource names
  • 1b1cac9887ec rust: kasan: KASAN+RUST requires clang
  • 3f096fb8647b rust: cpufreq: clean new clippy::map_or_identity lint for Rust 1.98.0
  • fbe9f0ff0b5b LoongArch: Add PIO for early access before ACPI PCI root register
  • eace3b3e729d platform/x86: intel-hid: Protect ACPI notify handler against recursion
  • 7d69235bdc58 ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup
  • 873576e585da ACPI: NFIT: core: Fix possible NULL pointer dereference
  • dc066bd13c86 ACPI: CPPC: Suppress UBSAN warning caused by field misuse
  • 8c8e8ac22ee1 KVM: x86: Unconditionally recompute CR8 intercept on PPR update
  • db8407b9fd06 KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode
  • 3db1ef139956 KVM: x86: Move update_cr8_intercept() to lapic.c
  • 3b3ca5d3a28e perf trace beauty fcntl: Fix build with older kernel headers
  • 7d45ca69164e slab: recognize @GFP parameter as optional in kernel-doc
  • 2dfe9f5c91d0 mm/khugepaged: write all dirty file folios when collapsing
  • 806586e33891 net/sched: dualpi2: fix GSO backlog accounting
  • 710183888174 userfaultfd: gate must_wait writability check on pte_present()
  • 6537884e9cf2 rust: str: clean unused import for Rust >= 1.98
  • 77ddefb1aeda rust: str: use the "kernel vertical" imports style
View originalPermalink
How 7.1.4-xanmod1 went

6.18.39-xanmod1

Fixed 19
  • xfs: use rtrefcount btree cursor in xchk_xref_is_rt_cow_staging
  • xfs: write the rg superblock when fixing it
  • xfs: fix off-by-one error when calling xchk_xref_has_rt_owner
  • xfs: don't zap bmbt forks if they are MAXLEVELS tall
  • xfs: fully check the parent handle when it points to the rootdir
  • xfs: clamp timestamp nanoseconds correctly
Security 1
  • smb: client: reject overlapping data areas in SMB2 responses

From XanMod Kernel

  • 27e97e554390 Linux 6.18.39-xanmod1
  • a4b496b054d4 Merge tag 'v6.18.39' into 6.18
  • f89c296854b7 Linux 6.18.39
  • 06b1729436ef xfs: use rtrefcount btree cursor in xchk_xref_is_rt_cow_staging
  • 457a93a233bd xfs: write the rg superblock when fixing it
  • e696ef088f55 xfs: fix off-by-one error when calling xchk_xref_has_rt_owner
  • 6403ef9a81e6 xfs: don't zap bmbt forks if they are MAXLEVELS tall
  • 1ea0868a477b xfs: fully check the parent handle when it points to the rootdir
  • c9662ffd62c4 xfs: clamp timestamp nanoseconds correctly
  • 424be21ed8cd xfs: handle non-inode owners for rtrmap record checking
  • d399b026a6b3 xfs: set xfarray killable sort correctly
  • 08b191ae6465 xfs: use the rt version of the cow staging checker
  • 104584477883 xfs: grab rtrmap btree when checking rgsuper
  • d1c4c40599c3 xfs: don't wrap around quota ids in dqiterate
  • 206c09b04dc5 xfs: resample the data fork mapping after cycling ILOCK
  • d98f22d2e11e xfs: fail recovery on a committed log item with no regions
  • dca861f2cc9e xfs: fix null pointer dereference in tracepoint
  • fdafa1e68dc7 smb: client: reject overlapping data areas in SMB2 responses
  • 1991d49433e9 Revert "f2fs: remove non-uptodate folio from the page cache in move_data_block"
  • 1c56c4651935 Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev
  • e697df336662 timekeeping: Register default clocksource before taking tk_core.lock
  • 9e04055ab5fc usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks
  • 75e1d2787005 sched/fair: Only update stats for allowed CPUs when looking for dst group
  • 0b466cf1b96e fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref
  • e1711479e906 fuse-uring: make a fuse_req on SQE commit only findable after memcpy
  • 39c8e925b207 fuse-uring: Avoid queue->stopped races and set/read that value under lock
  • 23a356e0bd96 fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues
  • bb476ef8e102 fuse-uring: end fuse_req on io-uring cancel task work
  • 50f3e03db823 fuse-uring: fix moving cancelled entry to ent_in_userspace list
  • b156bb996697 fuse-uring: fix data races on ring->ready
  • 0483fffdeeb3 fuse-uring: fix EFAULT clobber in fuse_uring_commit
  • 7366e6f4d2b4 fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req
  • 096cb2e58a6d fuse: fix io-uring background queue dispatch on request completion
  • be353caffa86 fuse: re-lock request before returning from fuse_ref_folio()
  • e6620208bdd3 fuse: fix device node leak in cuse_process_init_reply()
  • 6e2d84fdeac0 fuse: avoid 32-bit prune notification count wrap
  • 69cfae58b9a3 fuse: back uncached readdir buffers with pages
  • 423a78ff7928 RDMA/siw: bound Read Response placement to the RREAD length
  • ab45808c141a RDMA/core: Fix broadcast address falsely detected as local
  • 5a45d0aa1fa5 RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
  • 95de76f6ad47 Input: maplecontrol - set driver data before registering input device
  • 9376c744bea2 Input: maplemouse - set driver data before registering input device
  • 699e3abac02d Input: maple_keyb - set driver data before registering input device
  • d7f66fbab5d2 Input: mms114 - fix multi-touch slot corruption
  • 1b4cb75f254f Input: maplemouse - fix NULL pointer dereference in open()
  • 37fbe63bccf2 Input: gscps2 - advance receive buffer write index
  • 8301c3353053 Input: mms114 - reject an oversized device packet size
  • 3e6f007b43e2 Input: touchwin - reset the packet index on every complete packet
  • 05dee4007cf3 Input: ads7846 - don't use scratch for tx_buf when clearing register
  • 75b12874b417 Input: mms114 - fix touch indexing for MMS134S and MMS136
  • 70019779325f Input: iforce - bound the device-reported force-feedback effect index
  • 3b3230346015 Input: goodix - clamp the device-reported contact count
  • 01e0317c256c Input: elan_i2c - prevent division by zero and arithmetic underflow
  • e849c6f51e68 Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
  • 8db211aed837 Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count
  • 11f275f01c46 Input: synaptics-rmi4 - unregister function handlers on physical driver registration failure
  • bb5133a7d5f3 i2c: i801: fix hardware state machine corruption in error path
  • b2523f26979e i2c: imx-lpi2c: mark I2C adapter when hardware is powered down
  • 369635fbcf7f i2c: stm32f7: truncate clock period instead of rounding it
  • b65667ec5e9a i2c: davinci: Unregister cpufreq notifier on probe failure
  • 56945871123e i2c: mpc: Fix timeout calculations
  • b6d2af6fe9c1 i2c: core: fix adapter deregistration race
  • 71b7da959031 i2c: core: fix adapter debugfs creation
  • 0345994d6476 i2c: core: fix adapter probe deferral loop
  • 3351c5e77749 i2c: core: fix NULL-deref on adapter registration failure
  • 9ec02cc9a04e i2c: core: fix irq domain leak on adapter registration failure
  • 59070040fd12 fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
  • 34696563461c dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning
  • f8e1dc70efe4 udmabuf: fix DMA direction mismatch in release_udmabuf()
  • 0c93681aea0a KVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier
  • 4ad73ef0e796 KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits
  • ab253cf6e111 KVM: VMX: Handle bad values on proxied writes to LBR MSRs
  • eeb456eb3556 KVM: VMX: Refresh GUEST_PENDING_DBG_EXCEPTIONS.BS on all injected #DBs
  • 35f3ea7e49a3 KVM: SVM: Only disable x2AVIC WRMSR interception for MSRs that are accelerated
  • 7949aa38e109 KVM: SVM: Disable x2AVIC RDMSR interception for MSRs KVM actually supports
  • 4b200e0c9c33 KVM: x86: Add dedicated API for getting mask of accelerated x2APIC MSRs
  • 6bea2f8becdb KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
  • 2d710d4fcd2c LoongArch: KVM: Add missing slots_lock for device register/unregister
  • 7c73a269a880 KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB
  • b51a7439c166 selftests/landlock: Filter dealloc records in audit_count_records()
  • 859fef2c3d40 landlock: Set audit_net.sk for socket access checks
  • e4427c19554b audit: fix removal of dangling executable rules
  • 32ca4aed2a66 iommufd: Set upper bounds on cache invalidation entry_num and entry_len
  • 67daea4c0935 iommufd: Avoid partial fault group delivery in iommufd_fault_fops_read()
  • 5539da127d03 iommufd: Break the loop on failure in iommufd_fault_fops_read()
  • f2dbe1dba01e iommufd: Reject invalid read count in iommufd_fault_fops_read()
  • f549a749b625 iommufd: Reject invalid read count in iommufd_veventq_fops_read()
  • 64011399d881 iommufd: Rewind header length in done if iommufd_veventq_fops_read() fails
  • f565297edf31 iommufd: Set veventq_depth upper bound
  • 5c5f1b5184f7 iommufd: Fix data_len byte-count vs element-count mismatch
  • 04a177f91160 iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read
  • 50612ce318b1 iommu/amd: Don't split flush for amd_iommu_domain_flush_all()
  • bb354384f40b iommu/vt-d: Avoid WARNING in sva unbind path
  • 037ec8353711 crypto: loongson - Remove broken and unused loongson-rng
  • 6bbe2000d9f9 selftests/mm: pagemap_ioctl: use the correct page size for transact_test()
  • 5c942ad7df75 mm: do file ownership checks with the proper mount idmap
  • 8dcaa0f87a88 mm: page_ext: add count limit to page_ext_iter_next to prevent invalid PFN access
  • 785ebd42b8b5 selftests: mm: fix and speedup "droppable" test
  • 279c2fa73112 mm: fix mmap errno value when MAP_DROPPABLE is not supported
  • 4d730cab96e6 riscv: mm: Unconditionally sfence.vma for spurious fault
  • 90405c8822c5 riscv: mm: Define DIRECT_MAP_PHYSMEM_END
  • 1c8889e0db01 NTB: epf: Fix request_irq() unwind in ntb_epf_init_isr()
  • 33c0b96d7e16 exfat: bound uniname advance in exfat_find_dir_entry()
  • a82e170637e0 module: decompress: check return value of module_extend_max_pages()
  • b88373330250 rqspinlock: Fix order in raw_res_spin_(un)lock_irq to allow schedule
  • a937e92c1d00 NFSv4: include MAY_WRITE in open permission mask for O_TRUNC
  • 75ca99875aa4 audit: fix potential integer overflow in audit_log_n_hex()
  • 2dad64a97e1d tracing: Prevent out-of-bounds read in glob matching
  • c8b7e113f7b6 perf/aux: Fix page UAF in map_range()
  • af6048e91305 i2c: core: fix hang on adapter registration failure
  • 22cb337370e6 regulator: scmi: fix of_node refcount leak in scmi_regulator_probe()
  • 6b01ed165d29 watchdog: apple: Add "apple,t8103-wdt" compatible
  • f4dd5621a6ee EDAC/i10nm: Don't fail probing if ADXL is missing
  • add1e4112e00 x86/mm: Fix freeing of PMD-sized vmemmap pages
  • 808033d80d5c spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
  • 18d6048b1b1b spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync()
  • 75422f5e5022 arm64: fpsimd: Fix type mismatch in sme_{save,load}_state()
  • 93f000e89976 crypto: talitos/hash - fix SEC2 64k - 1 ahash request limitation
  • fda9cb9b7191 crypto: talitos/hash - remove useless wrapper
  • 99cc3f5511d8 crypto: talitos/hash - rename first_desc/last_desc to first_request/last_request
  • b960edc92c81 crypto: talitos/hash - drop workqueue mechanism for SEC1
  • 042730207a99 crypto: talitos/hash - use descriptor chaining for SEC1 instead of workqueue
  • 40a2e90acdb1 crypto: talitos/hash - prepare SEC1 descriptor chaining, remove additional descriptor
  • a8decb89920a crypto: talitos - move code in current_desc_hdr() into a standalone function
  • aea8cfbd60da crypto: talitos - move dma mapping code in talitos_submit() into a standalone dma_map_request() function
  • 3fa1846f75ed crypto: talitos - move dma unmapping code in flush_channel() into a standalone dma_unmap_request() function
  • 664e7f16e74f crypto: talitos - add chaining of arbitrary number of descriptor for the SEC1
  • f52aa95e3cae crypto: talitos - use dma_sync_single_for_cpu() before reading descriptor header
  • 7584c92f7244 crypto: qat - factor out AER reset helpers
  • 6fb62b767f3e crypto: qat - validate RSA CRT component lengths
  • fabf364ef9db crypto: qat - skip restart for down devices
  • c3c5925791cf crypto: qat - protect service table iterations with service_lock
  • e310e8dc8ce7 crypto: qat - notify fatal error before AER reset preparation
  • 45b65a21edbe crypto: qat - keep VFs enabled during reset
  • 33cfc0ce28ac crypto: qat - handle sysfs-triggered reset callbacks
  • 050bded706ee crypto: qat - centralize bus master enable
  • 5337b5cd3608 crypto: drbg - Fix the fips_enabled priority boost
  • 53d38b93cadc crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels
  • 23b8b188cb32 crypto: drbg - Fix returning success on failure in CTR_DRBG
  • 441ea32cf275 crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG)
  • 92567ed9306d crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD)
  • 7a361c74bb12 crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)
  • 9e983d0a74a6 crypto: ccp - Do not initialize SNP for SEV ioctls
  • 53b8fb85f332 crypto: loongson - Select CRYPTO_RNG
  • cc4e42b3ee9f crypto: tegra - fix refcount leak in tegra_se_host1x_submit()
  • c4bd2f4c35b0 crypto: pcrypt - restore callback for non-parallel fallback
  • ee6a2a25665c crypto: hisi-trng - Remove crypto_rng interface
  • 774ddddf5eb2 crypto: ecc - Fix carry overflow in vli multiplication
  • ac667f9f18c6 crypto: crypto4xx - Remove insecure and unused rng_alg
  • 0016d3c21c6a crypto: chacha20poly1305 - validate poly1305 template argument
  • d0b8cafd529b crypto: caam - use print_hex_dump_devel to guard key hex dumps again
  • 6f7b8e0321f3 crypto: caam - use print_hex_dump_devel to guard key hex dumps
  • 7465ed1524ac crypto: af_alg - Remove zero-copy support from skcipher and aead
  • b5699642640d isofs: bound Rock Ridge symlink components to the SL record
  • ce93228e2193 partitions: aix: bound the pp_count scan to the ppe array
  • 7a6452180299 btrfs: do not trim a device which is not writeable
  • 0912b98151ee btrfs: check and set EXTENT_DELALLOC_NEW before clearing EXTENT_DELALLOC
  • 6d7649c1231d nvmet-auth: validate reply message payload bounds against transfer length
  • 56c021a08692 nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
  • 7a69463e9ad2 nvme-multipath: set BIO_REMAPPED on bios remapped to per-path namespace disks
  • 13f2f5defb4d dm-ioctl: report an error if a device has no table
  • 427c82497e26 block: partitions: fix of_node refcount leak in of_partition()
  • a8803c4f0ac3 nvme: target: rdma: fix ndev refcount leak on queue connect
  • d161d47aba31 crypto: atmel-sha204a - drop hwrng quality reduction for ATSHA204A
  • c60932d6f837 hwrng: jh7110 - fix refcount leak in starfive_trng_read()
  • 04f4599a9efb udf: validate sparing table length as an entry count, not a byte count
  • e610fb113cdf udf: validate VAT header length against the VAT inode size
  • 335202ab25b0 udf: validate free block extents against the partition length
  • d944b8add331 bpf: Prefer dirty packs for eBPF allocations
  • 0229944ba792 bpf: Prefer packs that won't trigger an IBPB flush on allocation
  • f1f36bf9bb11 bpf: Skip redundant IBPB in pack allocator
  • 666fc2e6e4d0 bpf: Restrict JIT predictor flush to cBPF
  • 8a4c8af9ae67 x86/bugs: Enable IBPB flush on BPF JIT allocation
  • 8ff183ee4d8c bpf: Support for hardening against JIT spraying
  • bd818dcf4783 rust_binder: fix BINDER_GET_EXTENDED_ERROR
  • e5049526a7aa rust_binder: introduce TransactionInfo
  • be1567992417 x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled
  • b7b2d2ccdbc4 mm: shmem: fix potential livelock issue for shmem direct swapin
  • 9818bcae3c0c block: skip sync_blockdev() on surprise removal in bdev_mark_dead()
  • e086c16962a1 usb: gadget: f_fs: Fix DMA fence leak
  • b45be66ed47d usb: typec: ucsi: cancel pending work on system suspend
  • f5c772b76bbd usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove
  • b1dfdff51a86 usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode
  • 8c00aec752ce usb: typec: ucsi: Invert DisplayPort role assignment
  • 3e1b1ac47e81 usb: typec: tcpm: Validate SVID index in svdm_consume_modes()
  • 0bc177820bd3 usb: typec: tcpm: Fix VDM type for Enter Mode commands
  • bf6aa6c0ce0d usb: typec: class: drop PD lookup reference
  • 1126f1110b86 usb: typec: anx7411: use devm_pm_runtime_enable()
  • 347b59e9f967 usbip: vudc: fix NULL deref in vep_dequeue()
  • 6c7e8e251437 usbip: tools: support SuperSpeedPlus devices
  • 2d84c8376f7a USB: usb-storage: ene_ub6250: restore media-ready check
  • 1967a7f0cd5c USB: ulpi: fix memory leak on registration failure
  • 1243f1207900 USB: serial: digi_acceleport: fix write buffer corruption
  • 2b7dc482f859 USB: serial: digi_acceleport: fix hard lockup on disconnect
  • eab394781e93 USB: serial: digi_acceleport: fix broken rx after throttle
  • 4b147eb6ae6e USB: serial: option: add Telit Cinterion FE990D50 compositions
  • cf6ca0aefae0 USB: serial: keyspan_pda: fix information leak
  • 8c29d9cfab1c usb: mtu3: unmap request DMA on queue failure
  • 729b68a5bad7 USB: misc: uss720: unregister parport on probe failure
  • 48394f94211c usb: misc: usbio: bound bulk IN response length to the received transfer
  • 964d572b6c00 USB: storage: include US_FL_NO_SAME in quirks mask
  • e0886775952e usb: sl811-hcd: disable controller wakeup on remove
  • 766738ecf2b8 USB: legousbtower: fix use-after-free on disconnect race
  • 6af28345cbf8 USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD
  • b748f97aff33 USB: iowarrior: fix use-after-free on disconnect
  • 2107a4fc8ff1 USB: ldusb: fix use-after-free on disconnect race
  • 54c2b7356b4a USB: idmouse: fix use-after-free on disconnect race
  • 8a5eba992c86 usb: gadget: f_printer: take kref only for successful open
  • b52476a83d9e usb: gadget: udc: Fix use-after-free in gadget_match_driver
  • 01feaf024f29 usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler
  • 6bc17a78a056 usb: free iso schedules on failed submit
  • 0bbab8882a31 usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume()
  • 4b0779207e36 USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub
  • c00826e87bb7 usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()
  • e22f044b0b20 usb: cdc_acm: Add quirk for Uniden BC125AT scanner
  • e24eb271061d net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()
  • cd407de2ef5d bpf: Validate BTF repeated field counts before expansion
  • d94ab0e91d3f bpf: Restore sysctl new-value from 1 to 0
  • a9bb2d9c798c bpf: Reject fragmented frames in devmap
  • c3d3d2212c29 xfs: fix memory leak in xfs_dqinode_metadir_create()
  • a62ef2d13d6e xfs: fix exchmaps reservation limit check
  • 55e4d8413fb5 xfs: fix pointer arithmetic error on 32-bit systems
  • dd8d0665cdab xfs: fix unreachable BIGTIME check in dquot flush validation
  • 936618643591 xfs: release dquot buffer after dqflush failure
  • 200794d0354c xfs: use null daddr for unset first bad log block
  • 1cd54e217c6e serial: 8250_mid: Disable DMA for selected platforms
  • 973408ceab14 media: mtk-jpeg: cancel workqueue on release for supported platforms only
  • 223463c488b0 nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers
  • f3461b84a486 hfs/hfsplus: zero-initialize buffer in hfs_bnode_read
  • c63bc6308da7 HID: sensor-hub: Add sensor_hub_input_attr_read_values() for multi-byte reads
  • 4d0d51bc12d2 HID: lg-g15: cancel pending work on remove to fix a use-after-free
  • b363d964ca82 HID: appleir: fix UAF on pending key_up_timer in remove()
  • 37daa8c96bd5 HID: multitouch: fix out-of-bounds bit access on mt_io_flags
  • 3eca1a8165b5 HID: letsketch: fix UAF on inrange_timer at driver unbind
  • bbe1e55629bf HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush()
  • ca899a926c11 HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert
  • cb90a01e478c HID: pidff: Use correct effect type in effect update
  • 416095e9a603 HID: wacom: stop hardware after post-start probe failures
  • 7ce2c7dd28ab HID: uhid: convert to hid_safe_input_report()
  • dae1d000ddfd HID: hid-goodix-spi: validate report size to prevent stack buffer overflow
  • abf07f5c3584 tools/mm/slabinfo: fix total_objects attribute name
  • e0eec7497bcc tools/mm/slabinfo: Fix trace disable logic inversion
  • 2382971aaaef mm/slab: do not limit zeroing to orig_size when only red zoning is enabled
  • 18d90dc05d98 X.509: Fix validation of ASN.1 certificate header
  • 28390912740a perf/arm-cmn: Fix DVM node events
  • be79d285bea7 s390: Revert support for DCACHE_WORD_ACCESS
  • 2421a7b24f9c clocksource/drivers/timer-tegra186: Fix support for multiple watchdog instances
  • cd25e9819620 time/jiffies: Register jiffies clocksource before usage
  • 7776f9226e99 posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path
  • 6ba6f6783be2 cpufreq: pcc: fix use-after-free and double free in _OSC evaluation
  • 6e175c00c62d cpufreq: Fix hotplug-suspend race during reboot
  • 4bd0da48fbc1 sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT
  • f77e55baeeb8 cpufreq: intel_pstate: Sync policy->cur during CPU offline
  • 59626d0d2921 perf/x86/intel/uncore: Defer ADL global PMON enable to enable_box()
  • b9d45d328fcd libfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo()
  • 92f41769e5fd firmware_loader: fix device reference leak in firmware_upload_register()
  • e90496133280 cpufreq: qcom-cpufreq-hw: Fix possible double free
  • a277489337c7 OPP: of: Fix potential memory leak in opp_parse_supplies()
  • 685fc15a4108 writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs()
  • c6c484a7d5bf smb: client: mask server-provided mode to 07777 in modefromsid
  • 157c67a657a7 smb: client: fix atime clamp check in read completion
  • 86c5d470f5d4 smb: client: harden POSIX SID length parsing
  • 3d89ae65ef78 smb: client: use unaligned reads in parse_posix_ctxt()
  • 297243e365fc smb: client: Fix next buffer leak in receive_encrypted_standard()
  • d15d83125007 smb: client: fix double-free in SMB2_close() replay
  • 14498ff5ce0f smb: client: fix double-free in SMB2_open() replay
  • 3407240cde13 smb: client: fix double-free in SMB2_flush() replay
  • 52af1975f0df smb: client: fix change notify replay double-free
  • 276c8efbc49f smb: client: fix double-free in SMB2_ioctl() replay
  • f1add4acb656 smb: client: fix query_info() replay double-free
  • 00b0fa425941 smb: client: fix query directory replay double-free
  • 2b4592cea214 ksmbd: use opener credentials for ADS I/O
  • e72c15085b6d ksmbd: use opener credentials for delete-on-close
  • df501c0f320b ksmbd: add per-handle permission check to FILE_LINK_INFORMATION
  • 2ca82bfff49c ksmbd: enforce FILE_READ_ATTRIBUTES on SMB_FIND_FILE_POSIX_INFORMATION
  • 20ee516a6298 ksmbd: run set info with opener credentials
  • f56535db508e ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY
  • db231af84286 ksmbd: require source read access for duplicate extents
  • 5aa1cb01155f ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation
  • a1d5d31cad59 ksmbd: serialize QUERY_DIRECTORY requests per file
  • 57f2042fd87d ksmbd: add a permission check for FSCTL_SET_ZERO_DATA
  • baae7b39673e ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE
  • a187883cc1dc smb/client: Fix error code in smb2_aead_req_alloc()
  • 91b8a58c6ac1 smb: client: resolve SWN tcon from live registrations
  • 661a019ac041 coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()
  • 08fad5d5a26c fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked()
  • 6dd58c56ab86 fs/ntfs3: zero-fill folios beyond i_valid in ntfs_read_folio()
  • 764e6f76fdbd fs/ntfs3: fsync files by syncing parent inodes
  • 38cbb1feebcf fs/ntfs3: rename ni_readpage_cmpr into ni_read_folio_cmpr
  • 471800787054 iommu/vt-d: Fix race condition during PASID entry replacement
  • 73abbaf91aa3 Bluetooth: L2CAP: validate option length before reading conf opt value
  • d5616beb3355 Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
  • b84eeb7636d6 Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync()
  • b9dd39cf1667 Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled
  • 61701912c58a Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()
  • 26168db1ce5a Bluetooth: fix UAF in bt_accept_dequeue()
  • 2a68a7730892 Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3()
  • a6b22dbd8092 Bluetooth: bnep: pin L2CAP connection during netdev registration
  • 0039bdde36b2 Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()
  • 81a5971cbe18 netfilter: flowtable: fix offloaded ct timeout never being extended
  • 6fe8d3cecd20 netfilter: ebtables: terminate table name before find_table_lock()
  • 13a5f532e3a4 netfilter: ebtables: module names must be null-terminated
  • 9f74d28e903f netfilter: ebtables: zero chainstack array
  • fc5bfe63bacf netfilter: handle unreadable frags
  • a8f03a379328 netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump
  • 69c0e6246575 mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup
  • b415c00bf23d mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host
  • 006467ab9326 mm: shrinker: fix NULL pointer dereference in debugfs
  • 6465ff3ce651 mm: shrinker: fix shrinker_info teardown race with expansion
  • 560e21e8ccff mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()
  • b5f41d5bf08e mfd: cros_ec: Delay dev_set_drvdata() until probe success
  • bbae351c0f32 net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes
  • 2ca18df1c261 ipv4: igmp: remove multicast group from hash table on device destruction
  • a33f37f8d079 netpoll: fix a use-after-free on shutdown path
  • f090acf881a2 io_uring/rw: preserve partial result for iopoll
  • 1636d85dc139 io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item
  • 722869fcff59 io_uring/nop: fix file reference leak with IOSQE_FIXED_FILE
  • 4508366ab7dd gpio: sch: use raw_spinlock_t in the irq startup path
  • 4750909a40da gpio: eic-sprd: use raw_spinlock_t in the irq startup path
  • f71e8d987506 NTB: epf: Avoid calling pci_irq_vector() from hardirq context
  • cf28fc165846 fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns
  • c00164c9e7fa debugobjects: Plug race against a concurrent OOM disable
  • cbb684ef39e9 coresight: etb10: restore atomic_t for shared reading state
  • b346efa825b5 Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete
  • d3b739db5dc6 Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
  • fe997a84a385 audit: Fix data races of skb_queue_len() readers on audit_queue
  • e8417353cbd0 net: af_key: initialize alg_key_len for IPComp states
  • 94083db75193 ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL
  • ef6feb77e2d9 crypto: krb5 - filter out async aead implementations at alloc
  • 84a00be9b736 crypto: amlogic - avoid double cleanup in meson_crypto_probe()
  • 6f91621fc450 staging: rtl8723bs: fix OOB write in HT_caps_handler()
  • a6105ea8ca6e staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop
  • c38d16b1ffac staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()
  • 69f174a0673b staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop
  • 04f612dc0342 staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop
  • 64ec4192d9c1 staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()
  • b9c4bf133c3c staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()
  • b5ddc7257bee staging: media: ipu7: fix double-free and use-after-free in error paths
  • 1ca4f310c6b1 staging: media: atomisp: reduce load_primary_binaries() stack usage
  • b4ba13dafa13 media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe
  • e3ceafa6d8ee staging: vme_user: fix location monitor leak in tsi148 bridge
  • a92148631397 staging: vme_user: fix location monitor leak in fake bridge
  • ceb875a375de smb: client: restrict implied bcc[0] exemption to responses without data area
  • e99f2df433c6 staging: vme_user: bound slave read/write to the kern_buf size
  • 2de42e268174 tipc: fix out-of-bounds read in broadcast Gap ACK blocks
  • 0beccbcf50de 6lowpan: fix NHC entry use-after-free on error path
  • c40090f8d19b usb: misc: usbio: fix disconnect UAF in client teardown
  • c4e232bd07fe usb: dwc3: run gadget disconnect from sleepable suspend context
  • 2a52d55c86a4 USB: chaoskey: Fix slab-use-after-free in chaoskey_release()
  • 285e17c44e38 hwrng: virtio: clamp device-reported used.len at copy_data()
  • 65e93ec592f5 virtio-mmio: fix device release warning on module unload
  • 075bc3c779e1 virtio_pci: fix vq info pointer lookup via wrong index
  • 81d54c766337 netfilter: ipset: fix race between dump and ip_set_list resize
  • 9c8f31eaae61 mm/damon/ops-common: handle extreme intervals in damon_hot_score()
  • 657646c08c94 tcp: restore RCU grace period in tcp_ao_destroy_sock
  • b77524621250 PCI/IOV: Skip VF Resizable BAR restore on read error
  • 1115680bca1d PCI: qcom: Initialize DWC MSI lock for firmware-managed ECAM hosts
  • 6e6a529d6f77 PCI: mediatek: Fix IRQ domain leak when port fails to enable
  • 69416a530867 PCI: imx6: Fix IMX6SX_GPR12_PCIE_TEST_POWERDOWN handling
  • 1d2e66a4bc0d PCI: host-common: Request bus reassignment when not probe-only
  • 9c698af5c2a1 PCI: Always lift 2.5GT/s restriction in PCIe failed link retraining
  • 09c43b7b7d29 PCI: altera: Fix resource leaks on probe failure
  • 5e42a981887d PCI: altera: Do not dispose parent IRQ mapping
  • d666c5aec822 PCI: loongson: Override PCIe bridge supported speeds for Loongson-3C6000 series
  • e5406c8fb71c usb: typec: tcpci_rt1711h: unregister TCPCI port with devres
  • 99d00a9e35e3 xhci: sideband: fix ring sg table pages leak
  • f90586129cf9 usb: xhci: Fix sleep in atomic context in xhci_free_streams()
  • 91b27f8172cd rust_binder: clear freeze listener on node removal
  • 281335996ab2 rust_binder: synchronize Rust Binder stats with freeze commands
  • 08e21d86d272 rust_binder: reject context manager self-transaction
  • 89b8cc948dce rust_binder: use a u64 stride when cleaning up the offsets array
  • 328ccf32acb8 binder: fix UAF in binder_free_transaction()
  • ea02df466df6 binder: fix UAF in binder_thread_release()
  • 17a2d3f90345 Bluetooth: btusb: fix wakeup source leak on probe failure
  • a7e941a39571 Bluetooth: btusb: fix use-after-free on marvell probe failure
  • 8db0ce3de783 Bluetooth: btusb: fix use-after-free on registration failure
  • 79f9e221ddde Bluetooth: btusb: Add USB ID 2c4e:0128 for Mercusys MA60XNB
  • a53109ffb6b5 vfio: Remove device debugfs before releasing devres
  • 7f2d6b31089e vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc
  • ba96666d991e vfio/pci: Fix racy bitfields and tighten struct layout
  • 52adb2dff7ce vfio/pci: Release the VGA arbiter client on register_device() failure
  • f6c67cf0051f vfio/pci: Latch disable_idle_d3 per device
  • a385d3435a7a vfio/pci: Use a private flag to prevent power state change with VFs
  • afc90150551d ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes
  • 54c448e4f26a ALSA: usb-audio: Update Babyface Pro control caches only after successful writes
  • f3e8a6cca15b ALSA: usb-audio: Roll back quirk control caches on write errors
  • 3061b6c11445 ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks
  • bfd28b07541e ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put()
  • a263eb12cbe2 ALSA: usb-audio: avoid kobject path lookup in DualSense match
  • 16f14f55141d ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission
  • 651ba82fe2a1 ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()
  • 71b87108ad93 ALSA: ice1712: check snd_ctl_new1() return value
  • 04dd21018057 ALSA: hda/realtek: Fix noisy mic for Clevo V6xxAW
  • 1933e6ee136b ALSA: hda/hdmi: Use 'AC_PINSENSE_ELDV' to detect pinsense for Loongson
  • 4dd2552e559b ALSA: hda/hdmi: Add force-connect quirk for HP EliteDesk 800 G5 Mini
  • ce0a903d0591 ALSA: hda/cs35l41: Fix firmware load work teardown
  • 5e74e5e8cb7c ALSA: gus: check snd_ctl_new1() return value
  • 8e48a29813df ALSA: firewire: isight: bound the sample count to the packet payload
  • db25755e7629 ALSA: FCP: Add Focusrite ISA C8X support
  • 9e53e99b6fa3 ALSA: es1938: check snd_ctl_new1() return value
  • b27a75d42044 ALSA: compress: Fix task creation error unwind
  • af2b009b773b ALSA: cmipci: check snd_ctl_new1() return value
  • a5fd3122283b ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser
  • fd786466889e ALSA: aoa: check snd_ctl_new1() return value
  • f6538a318947 ALSA: ymfpci: check snd_ctl_new1() return value
  • 5da9742de22d ALSA: virtio: Validate control metadata from the device
  • df0fe53a7104 ALSA: virtio: Add missing 384 kHz PCM rate mapping
  • c071df05bcda ALSA: usx2y: us144mkii: fix work UAF on disconnect
  • a4f8491da956 iio: temperature: tmp006: use devm_iio_trigger_register
  • 62a0d75bedd4 iio: temperature: ltc2983: Fix reinit_completion() called after conversion start
  • e16258913be6 iio: temperature: ltc2983: Fix n_wires default bypassing rotation check
  • b50344ab202f iio: temperature: Build mlx90635 with CONFIG_MLX90635
  • 7d4d60f7c054 iio: resolver: ad2s1210: notify trigger and clear state on fault read error
  • c6ca87c7bbb3 iio: proximity: vl53l0x: notify trigger and clear IRQ on error paths
  • b3f1af4ba8e9 iio: pressure: mpl115: fix runtime PM leak on read error
  • e2d5b9673bf7 iio: pressure: bmp280: zero-init bmp580 trigger handler buffer
  • f829d6c32f31 iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call
  • 0975e013179d iio: light: veml6030: fix channel type when pushing events
  • ef6c2a521454 iio: light: tsl2591: return actual error from probe IRQ failure
  • 9d421c2827ea iio: light: opt3001: fix missing state reset on timeout
  • 0c655d067ac6 iio: light: gp2ap002: fix runtime PM leak on read error
  • a60bf629a760 iio: light: al3320a: read both ALS ADC registers again
  • a1dafc918d79 iio: light: al3320a: add missing REGMAP_I2C to Kconfig
  • a00d471cf358 iio: light: al3010: read both ALS ADC registers again
  • cd278561640c iio: light: al3010: fix incorrect scale for the highest gain range
  • 9fb4ff07d97e iio: light: al3010: add missing REGMAP_I2C to Kconfig
  • 6afb69bb969e iio: light: al3000a: add missing REGMAP_I2C to Kconfig
  • 482b24660ec3 iio: imu: st_lsm6dsx: deselect shub page before reading whoami
  • 76e12a71ac05 iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading
  • 34656a59322e iio: imu: inv_icm42600: fix timestamp clock period by using lower value
  • 052281922828 iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ
  • bdafd53ae671 iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ
  • 001527e2382e iio: gyro: bmg160: wait full startup time after mode change at probe
  • 7bbf02b63961 iio: gyro: bmg160: bail out when bandwidth/filter is not in table
  • 9edefd4c56be iio: event: Fix event FIFO reset race
  • 2358da87315d iio: dac: ad3552r-hs: fix uninitialized data ni ad3552r_hs_write_data_source()
  • e166a8cfb28a iio: core: fix uninitialized data in debugfs
  • b947bde73461 iio: common: st_sensors: honour channel endianness in read_axis_data
  • 82accdd57404 iio: chemical: scd30: Cleanup initializations and fix sign-extension bug
  • c28835b8618e iio: backend: fix uninitialized data in debugfs
  • 0f30e68dd6c1 iio: adc: ti-ads124s08: Return reset GPIO lookup errors
  • ffb2195921c3 iio: adc: ti-ads1119: fix PM reference leak in buffer preenable
  • bbfebae473ac iio: adc: spear: Initialize completion before requesting IRQ
  • 9e2e8b8cdfd3 iio: adc: lpc32xx: Initialize completion before requesting IRQ
  • c313bb7c3885 iio: adc: ad_sigma_delta: fix CS held asserted and state leaks
  • 3394e0b33284 iio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices
  • 46e93fcbe7c2 iio: adc: ad7779: add missing 'select IIO_TRIGGERED_BUFFER' to Kconfig
  • 24a9514b606e iio: adc: ad7768-1: Select GPIOLIB
  • e6ade81631d7 iio: adc: ad7380: select REGMAP
  • 6293211d1426 iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error
  • 3e766526827a iio: accel: bmc150: clamp the device-reported FIFO frame count
  • 7515a6d4a9e9 usb: gadget: function: rndis: add length check for header
  • e01e7814b422 usb: gadget: function: rndis: add length check to response query
  • 9d1dc507b99c fscrypt: Replace mk_users keyring with simple list
  • 85f8b440a09b fscrypt: Fix key setup in edge case with multiple data unit sizes
  • 20133754d46f rust: kasan: KASAN+RUST requires clang
  • a2d5d3ee7b6e perf/core: Detach event groups during remove_on_exec
  • 94396fd93226 futex/requeue: Revert "Prevent NULL pointer dereference in remove_waiter() on self-deadlock""
  • 1cc8f512cd90 rust: Kbuild: set frame-pointer llvm module flag for CONFIG_FRAME_POINTER
  • 70fe1ac8647b rust: doctest: fix incorrect pattern in replacement
  • e7636f26f770 rust: block: fix GenDisk cleanup paths
  • c1dd0b107100 rust: cpufreq: clean new clippy::map_or_identity lint for Rust 1.98.0
  • 30d5d4eef35a LoongArch: Add PIO for early access before ACPI PCI root register
  • 86df6499dfd2 platform/x86: intel-hid: Protect ACPI notify handler against recursion
  • 452945662fd8 ACPI: NFIT: core: Fix possible NULL pointer dereference
  • f29dc6132d49 ACPI: CPPC: Suppress UBSAN warning caused by field misuse
  • ff9c4c642888 KVM: x86: Unconditionally recompute CR8 intercept on PPR update
  • 3dcfb04dd43b KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode
  • 0d0187a46b16 KVM: x86: Move update_cr8_intercept() to lapic.c
  • 9baa2833e6bc perf trace beauty fcntl: Fix build with older kernel headers
  • 47e4c6e06e78 slab: recognize @GFP parameter as optional in kernel-doc
  • 1776f29327a1 default_gfp(): avoid using the "newfangled" VA_OPT trick
  • 50c26b461b8e add default_gfp() helper macro and use it in the new *alloc_obj() helpers
  • 2dca62902eb3 slab: Introduce kmalloc_flex() and family
  • 1c2672781b1b mm/khugepaged: write all dirty file folios when collapsing
  • 2539f67b7546 nfsd: change nfs4_client_to_reclaim() to allocate data
  • 05e48af3bf58 nfsd: move name lookup out of nfsd4_list_rec_dir()
  • c4b70c1512b8 net/sched: dualpi2: fix GSO backlog accounting
  • 076b1aa65f77 fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
  • 406c28af7512 f2fs: fix to do sanity check on f2fs_get_node_folio_ra()
  • 3f42fbd3c891 f2fs: detect more inconsistent cases in sanity_check_node_footer()
  • ed87e57558dc f2fs: optimize trace_f2fs_write_checkpoint with enums
  • 8dbc4c568682 f2fs: introduce f2fs_schedule_timeout()
  • 599d7d82eeec f2fs: use memalloc_retry_wait() as much as possible
  • ec9f79c8d5b2 f2fs: fix listxattr handling of corrupted xattr entries
  • 89479a27fa4e f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs()
  • 998536c96b6a f2fs: fix potential deadlock in f2fs_balance_fs()
  • 4ce2d52f680c f2fs: bound i_inline_xattr_size for non-inline-xattr inodes
  • a499f77c0605 f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
  • 5a4d3968cf82 f2fs: remove non-uptodate folio from the page cache in move_data_block
  • 9c86a1f930bb device property: initialize the remaining fields of fwnode_handle in fwnode_init()
  • 60d696a037ee userfaultfd: gate must_wait writability check on pte_present()
  • 3436a7dd067c rust: str: clean unused import for Rust >= 1.98
  • 3603500c868a rust: str: use the "kernel vertical" imports style
  • 8dee7c278f1c nfsd: release layout stid on setlease failure
  • 6f88ca186a98 nfsd: update mtime/ctime on COPY in presence of delegated attributes
  • 7c702bb4f8d8 nfsd: update mtime/ctime on CLONE in presense of delegated attributes
  • 501543207378 bpf, arm64: Reject out-of-range B.cond targets
View originalPermalink
How 6.18.39-xanmod1 went

7.1.3-xanmod1

Fixed 20
  • apparmor: advertise the tcp fast open fix is applied
  • net/tcp-ao: fix use-after-free of key in del_async path
  • ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
  • NFS: Prevent resource leak in nfs_alloc_server()
  • NFSv4: clear exception state on successful mkdir retry
  • NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr

From XanMod Kernel

  • ece066880fc5 Linux 7.1.3-xanmod1
  • 2ddd8fb98217 Merge tag 'v7.1.3' into 7.1
  • 199c9959d3a9 Linux 7.1.3
  • 5b872b77bd35 apparmor: advertise the tcp fast open fix is applied
  • 7ddc29a094d9 net/tcp-ao: fix use-after-free of key in del_async path
  • e36e35660adb ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
  • 65b1bb5d24e5 NFS: Prevent resource leak in nfs_alloc_server()
  • a2c8befd06a4 NFSv4: clear exception state on successful mkdir retry
  • 30aae62e50b4 NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
  • 2131ed64b767 NFSv4/flexfiles: reject zero filehandle version count
  • b027cca33c97 nfsd: reset write verifier on deferred writeback errors
  • a10bf67fe064 nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
  • 8371cc5c0a2c nfsd: fix dead ACL conflict guard in nfsd4_create
  • ff3ecd17db74 nfsd: check get_user() return when reading princhashlen
  • 18cf006a08ba nfsd: fix posix_acl leak and ignored error in nfsd4_create_file
  • 80866c84137e nfsd: fix inverted cp_ttl check in async copy reaper
  • a5b42c1e4ff2 nfsd: fix posix_acl leak on SETACL decode failure
  • 46eb17d45be6 NFSD: Fix SECINFO_NO_NAME decode error cleanup
  • 83c2b7797742 nfsd: release layout stid on setlease failure
  • a4c8094bbf4c i2c: core: fix adapter registration race
  • 7e58653d4352 fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
  • 13b6f0cdd5cd fbdev: modedb: fix a possible UAF in fb_find_mode()
  • 6eb6ebcc8590 fbdev: omap2: fix use-after-free in omapfb_mmap
  • 39815715cbcf fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
  • 88913059c77e fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
  • acd744019460 ntfs: serialize volume label accesses
  • 7f7a9d6cb0ed riscv: kfence: Call mark_new_valid_map() for kfence_unprotect()
  • d6d6051fd15a riscv: mm: Extract helper mark_new_valid_map()
  • d109e72f3fbc power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()
  • 2753a097d1fe KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
  • f636cf6a1e7b KVM: x86: hyper-v: Bound the bank index when querying sparse banks
  • 9fef09df42df MIPS: smp: report dying CPU to RCU in stop_this_cpu()
  • a7656d368265 9p: avoid putting oldfid in p9_client_walk() error path
  • 99c21e726324 ocfs2: reject oversized group bitmap descriptors
  • ff268cd9ccbc rpmsg: char: Fix use-after-free on probe error path
  • 5e098e40e8ba fpga: region: fix use-after-free in child_regions_with_firmware()
  • 0405a65e4ebd irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove
  • 8d32856fb72b sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path
  • 9645aaf689af pNFS: Fix use-after-free in pnfs_update_layout()
  • 0833b2b84c2f LoongArch: Report dying CPU to RCU in stop_this_cpu()
  • 1eea5e1820a2 tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
  • afebe44facc4 blk-cgroup: fix UAF in __blkcg_rstat_flush()
  • a594debfd4e7 hdlc_ppp: sync per-proto timers before freeing hdlc state
  • 73569a44fca2 pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()
  • 9d0d5ba20cad gfs2: fix use-after-free in gfs2_qd_dealloc
  • 833033e6e55a crypto: nx - fix nx_crypto_ctx_exit argument
  • 5c87b4737468 KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()
  • b2ae3245ea44 KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
  • 708b97e79294 exfat: fix potential use-after-free in exfat_find_dir_entry()
  • 07c245bc39f9 MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
  • 70df4de46577 bpf: use kvfree() for replaced sysctl write buffer
  • 717f721eb67d block: Avoid mounting the bdev pseudo-filesystem in userspace
  • a92332f32a8d f2fs: read COW data with the original inode during atomic write
  • d52dbbcad61d f2fs: keep atomic write retry from zeroing original data
  • edf12cbeeeab f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
  • 6e035dae4415 Revert "f2fs: remove non-uptodate folio from the page cache in move_data_block"
  • 5d8a39649947 f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
  • 16bc237ce3c4 f2fs: bound i_inline_xattr_size for non-inline-xattr inodes
  • 536c7e7482e0 f2fs: fix to round down start offset of fallocate for pin file
  • a805fec35c20 f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
  • 0969926d987b f2fs: validate compress cache inode only when enabled
  • 2e12381d4495 f2fs: validate orphan inode entry count
  • 0cc21c1ffe15 f2fs: fix to do sanity check on f2fs_get_node_folio_ra()
  • f5b8b3dd6e85 f2fs: reject setattr size changes on large folio files
  • 8a2d8a34ef0b f2fs: pass correct iostat type for single node writes
  • 48c92559e7b6 f2fs: fix missing read bio submission on large folio error
  • fe7f339f63c9 wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
  • 9579781cd16d wifi: iwlwifi: mld: fix race condition in PTP removal
  • 032e49805099 wifi: iwlwifi: mvm: fix race condition in PTP removal
  • 8206d173d18e wifi: rtw88: usb: fix memory leaks on USB write failures
  • a68c04f4ee6a wifi: rtw88: increase TX report timeout to fix race condition
  • 2a42951e935f wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor
  • 4b75e6180f46 wifi: rtl8xxxu: Detect the maximum supported channel width
  • 051f954b9447 wifi: ath11k: fix warning when unbinding
  • 84139c1ab368 wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer
  • f10e6d5a35c4 wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S
  • 5db89515fc28 userfaultfd: build __VMA_UFFD_FLAGS from config-gated masks
  • 19ad7bfbd7f8 userfaultfd: ensure mremap_userfaultfd_fail() releases mmap_changing
  • 83c0a1cb296d keys: Pin request_key_auth payload in instantiate paths
  • 670fc6a311ed KEYS: fix overflow in keyctl_pkey_params_get_2()
  • 5b959c1dbb45 gcov: use atomic counter updates to fix concurrent access crashes
  • 450ee7ff510a err.h: use __always_inline on all error pointer helpers
  • 8ead17358119 KVM: arm64: Omit tag sync on stage-2 mappings of the zero page
  • dcb7416212e6 block: invalidate cached plug timestamp after task switch
  • 77bba61a20f1 kernel/fork: clear PF_BLOCK_TS in copy_process()
  • 43e40c7a7b26 fscrypt: Fix key setup in edge case with multiple data unit sizes
  • 70f1e000b88c fbdev: fix use-after-free in store_modes()
  • 9764a786ba98 NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR
  • 5e34fa9f6f7c apparmor: fix use-after-free in rawdata dedup loop
  • 45ebb934ea50 apparmor: mediate the implicit connect of TCP fast open sendmsg
  • cbad530277b5 PCI/P2PDMA: Add Intel QAT, DSA, IAA devices to whitelist
  • 47b5d3d50660 net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
  • 21ed9540a8e1 net: skmsg: preserve sg.copy across SG transforms
  • 86d531337ea1 mac802154: llsec: add skb_cow_data() before in-place crypto
  • 55e014aaec65 wifi: mt76: add wcid publish check in mt76_sta_add
  • 293a84fa40b3 ntfs3: reject direct userspace writes to reserved $LX* xattrs
  • c04d9ece23de ipv4: account for fraggap on the paged allocation path
  • e9eacf19281e ipv6: account for fraggap on the paged allocation path
  • d25df4f62eea batman-adv: tvlv: avoid race of cifsnotfound handler state
  • 56910cfd3116 batman-adv: tvlv: enforce 2-byte alignment
  • 3e4555177235 batman-adv: dat: prevent false sharing between VLANs
  • f91d579a085b batman-adv: tt: track roam count per VID
  • 6ae315914113 batman-adv: tt: don't merge change entries with different VIDs
  • 39aadfa35160 batman-adv: tp_meter: handle overlapping packets
  • aa9fe4cb1acb batman-adv: tp_meter: prevent parallel modifications of last_recv
  • 7c5f5f680dfc batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE
  • 1fb8762600a3 batman-adv: tp_meter: restrict number of unacked list entries
  • 86ab6b6fb5b8 batman-adv: v: prevent OGM aggregation on disabled hardif
  • 5d8e32165427 batman-adv: frag: avoid underflow of TTL
  • cc97b6311190 batman-adv: frag: ensure fragment is writable before modifying TTL
  • 09927ad14a5d batman-adv: fix (m|b)cast csum after decrementing TTL
  • 4f121f393811 batman-adv: ensure bcast is writable before modifying TTL
  • c14d3619a1f7 batman-adv: gw: don't deselect gateway with active hardif
  • 26ac02e6ae5d batman-adv: tp_meter: initialize last_recv_time during init
  • b4284cac3095 batman-adv: prevent ELP transmission interval underflow
  • 7f58e114c1f3 batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE
  • bafe4928d321 batman-adv: tp_meter: add only finished tp_vars to lists
  • 1d8b344e8dfc batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection
  • 47ca1ecb85b9 batman-adv: tp_meter: fix fast recovery precondition
  • 585616dab0aa batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
  • f1be6ca7c183 batman-adv: tp_meter: avoid window underflow
  • fa54b5d133cd batman-adv: tp_meter: initialize dec_cwnd explicitly
  • fd46e54c0601 batman-adv: tp_meter: initialize dup_acks explicitly
  • d7f6ffe69078 batman-adv: tp_meter: keep unacked list in ascending ordered
  • 1ae7d5a6db6c KVM: x86: Fix shadow paging use-after-free due to unexpected role
View originalPermalink
How 7.1.3-xanmod1 went

6.18.38-rt-xanmod1

Fixed 20
  • Advertise the tcp fast open fix is applied in apparmor
  • Fix use-after-free of key in del_async path in net/tcp-ao
  • Unregister 8250 port if clk_notifier_register() fails in serial 8250_dw
  • Fix out-of-bounds read in smb_check_perm_dacl() in ksmbd
  • Prevent resource leak in nfs_alloc_server() in NFS
  • Clear exception state on successful mkdir retry in NFSv4

From XanMod Kernel

  • 4b8d52e3d233 Linux 6.18.38-rt-xanmod1
  • 0b987ae8e20a Merge branch '6.18' into 6.18-rt
  • e67923a55781 Linux 6.18.38-xanmod1
  • 82e2790add06 Merge tag 'v6.18.38' into 6.18
  • e46dc0adfe39 Linux 6.18.38
  • 92c63a5ef3c7 apparmor: advertise the tcp fast open fix is applied
  • e77fbefd1269 net/tcp-ao: fix use-after-free of key in del_async path
  • 3d205fe80f21 serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
  • 7627ff8c4f99 ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
  • 62c26720121b NFS: Prevent resource leak in nfs_alloc_server()
  • 6919eb549e8f NFSv4: clear exception state on successful mkdir retry
  • 012d37a568bf NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
  • d8c90c7cc061 NFSv4/flexfiles: reject zero filehandle version count
  • 4367afc119c5 nfsd: reset write verifier on deferred writeback errors
  • 017a6150106b nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
  • 0f28337f54cf nfsd: check get_user() return when reading princhashlen
  • dba7da4835de nfsd: fix inverted cp_ttl check in async copy reaper
  • 136b416593f1 nfsd: fix posix_acl leak on SETACL decode failure
  • c8a24effd96d NFSD: Fix SECINFO_NO_NAME decode error cleanup
  • 6a946038f2a5 i2c: core: fix adapter registration race
  • fc6aa9bdbae6 fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
  • 4d418cf8daf5 fbdev: modedb: fix a possible UAF in fb_find_mode()
  • eea16b6f805c fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
  • 7643e5622994 riscv: kfence: Call mark_new_valid_map() for kfence_unprotect()
  • 3b33dbb43e21 riscv: mm: Extract helper mark_new_valid_map()
  • 2205275be9be power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()
  • 720949ed666f KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
  • e36095d8d922 KVM: x86: hyper-v: Bound the bank index when querying sparse banks
  • f9b57a0015c2 MIPS: smp: report dying CPU to RCU in stop_this_cpu()
  • 6dbe9443d9f5 9p: avoid putting oldfid in p9_client_walk() error path
  • 4cd57ebee395 ocfs2: reject oversized group bitmap descriptors
  • 104d10021239 rpmsg: char: Fix use-after-free on probe error path
  • 369496d885b4 fpga: region: fix use-after-free in child_regions_with_firmware()
  • b3a3831b2eb8 irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove
  • 200e7637f4d6 pNFS: Fix use-after-free in pnfs_update_layout()
  • 90e254f18b8c LoongArch: Report dying CPU to RCU in stop_this_cpu()
  • e18769616fd5 tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
  • 5e5b7f2ef854 blk-cgroup: fix UAF in __blkcg_rstat_flush()
  • 5a84398101bf hdlc_ppp: sync per-proto timers before freeing hdlc state
  • e91df6d27344 pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()
  • b85ef03f726b gfs2: fix use-after-free in gfs2_qd_dealloc
  • 8d8507a45766 crypto: nx - fix nx_crypto_ctx_exit argument
  • 5da9b1a87ec7 KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()
  • 18587f983161 KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
  • adfacfbaeae2 exfat: fix potential use-after-free in exfat_find_dir_entry()
  • 6e61fc2e06e4 MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
  • 65bd0c0afb0e bpf: use kvfree() for replaced sysctl write buffer
  • 3804e6de30ae block: Avoid mounting the bdev pseudo-filesystem in userspace
  • db2c5b9fb908 f2fs: keep atomic write retry from zeroing original data
  • 20190e498057 f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
  • ff83de56882c f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
  • 888d94cc9afb f2fs: fix to round down start offset of fallocate for pin file
  • 77f216ff9ce5 f2fs: validate compress cache inode only when enabled
  • 8aad54746c25 f2fs: validate orphan inode entry count
  • 1e48fefac682 f2fs: pass correct iostat type for single node writes
  • 1de92789ce31 wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
  • b0b07e04f0c7 wifi: iwlwifi: mld: fix race condition in PTP removal
  • df626f284cb9 wifi: iwlwifi: mvm: fix race condition in PTP removal
  • 200d58c851b8 wifi: rtw88: usb: fix memory leaks on USB write failures
  • 73d427d271f7 wifi: rtw88: increase TX report timeout to fix race condition
  • 0aeb4d3ff6ce wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor
  • 40aa3c2b0cb8 wifi: ath11k: fix warning when unbinding
  • a7cdc384c9c5 wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer
  • 7e25b5e22c1f wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S
  • ec1c9e896255 userfaultfd: ensure mremap_userfaultfd_fail() releases mmap_changing
  • 7216ce8cb12f keys: Pin request_key_auth payload in instantiate paths
  • b11c1fa32667 KEYS: fix overflow in keyctl_pkey_params_get_2()
  • 49d893b9cbcf gcov: use atomic counter updates to fix concurrent access crashes
  • 2b7ec7278609 err.h: use __always_inline on all error pointer helpers
  • 1fcca1260c6e KVM: arm64: Omit tag sync on stage-2 mappings of the zero page
  • 97e1044e79c5 block: invalidate cached plug timestamp after task switch
  • 99e6c712cc30 kernel/fork: clear PF_BLOCK_TS in copy_process()
  • 0d35f9f194a8 fbdev: fix use-after-free in store_modes()
  • 81371dbd2360 NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR
  • c3ca2631073b apparmor: fix use-after-free in rawdata dedup loop
  • 4a69b83045d3 apparmor: mediate the implicit connect of TCP fast open sendmsg
  • 1697957eb097 net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
  • 1acdd14c0990 net: skmsg: preserve sg.copy across SG transforms
  • bd968bdd568b mac802154: llsec: add skb_cow_data() before in-place crypto
  • 0cfa78c05066 af_unix: Set gc_in_progress to true in unix_gc().
  • 3c499851753a wifi: mt76: add wcid publish check in mt76_sta_add
  • 5e658b9245a5 ntfs3: reject direct userspace writes to reserved $LX* xattrs
  • 77798d7be6ef ipv4: account for fraggap on the paged allocation path
  • 6374fb9edf72 ipv6: account for fraggap on the paged allocation path
  • 565ab66005b1 batman-adv: tvlv: avoid race of cifsnotfound handler state
  • 4cc9f7711bb8 batman-adv: tvlv: enforce 2-byte alignment
  • 04e1a6557fbf batman-adv: dat: prevent false sharing between VLANs
  • 3f82fc92cf52 batman-adv: tt: track roam count per VID
  • 3470d583fc65 batman-adv: tt: don't merge change entries with different VIDs
  • af5a069805f6 batman-adv: tp_meter: handle overlapping packets
  • d511c72a83dd batman-adv: tp_meter: prevent parallel modifications of last_recv
  • 1dafdd0794be batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE
  • 2233787658db batman-adv: tp_meter: restrict number of unacked list entries
  • 3d4548c96d6f batman-adv: v: prevent OGM aggregation on disabled hardif
  • 44ae137a2ace batman-adv: frag: avoid underflow of TTL
  • 116e94025f0f batman-adv: frag: ensure fragment is writable before modifying TTL
  • 0473ae882624 batman-adv: fix (m|b)cast csum after decrementing TTL
  • 49bf27fcd7ee batman-adv: ensure bcast is writable before modifying TTL
  • 646b68639c06 batman-adv: gw: don't deselect gateway with active hardif
  • 95a061f587b7 batman-adv: tp_meter: initialize last_recv_time during init
  • 75612c100a9e batman-adv: prevent ELP transmission interval underflow
  • 43733e5b525f batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE
  • 23d085bd6308 batman-adv: tp_meter: add only finished tp_vars to lists
  • b8bf8400e50c batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection
  • 1db02f3e315d batman-adv: tp_meter: fix fast recovery precondition
  • 7d2a44bc6bbe batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
  • 8e77fe0414f5 batman-adv: tp_meter: avoid window underflow
  • 7cb88d91d5f9 batman-adv: tp_meter: initialize dec_cwnd explicitly
  • 696c4cae872c batman-adv: tp_meter: initialize dup_acks explicitly
  • 1c5a1268418e batman-adv: tp_meter: keep unacked list in ascending ordered
  • e055e74b80eb lockd: fix TEST handling when not all permissions are available.
  • 671ec2eabb87 Revert "PCI: qcom: Advertise Hotplug Slot Capability with no Command Completion support"
  • d84470219839 selinux: fix overlayfs mmap() and mprotect() access checks
  • 5dfcb15974e7 lsm: add backing_file LSM hooks
  • 5e470998a23e KVM: x86: Fix shadow paging use-after-free due to unexpected role
  • 6e2cd08aa3e8 Linux 6.18.37-xanmod1
  • 0d25ba9b7110 Merge tag 'v6.18.37' into 6.18
  • 0c503cf3dde2 Linux 6.18.37
  • 71003a32bef5 mm: do not copy page tables unnecessarily for VM_UFFD_WP
  • 2abfd3ffbd94 virtiofs: fix UAF on submount umount
  • f965cf22dda7 media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
  • 7cad3ceaf679 ksmbd: reject non-VALID session in compound request branch
  • 6c25bf4e44a2 drivers/base/memory: set mem->altmap after successful device registration
  • 50b72074c5e8 serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero
  • 7cc3dd79777f vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write
  • b8ebf008696d crypto: qat - remove unused character device and IOCTLs
  • d08d82d83ed4 iio: adc: ti-ads1298: add bounds check to pga_settings index
  • 0a89002737ee iio: light: veml6075: add bounds check to veml6075_it_ms index
  • 76db05493184 net: net_failover: Fix the deadlock in slave register
  • c5b3871b567c net: export netif_open for self_test usage
  • cc1494fd6c65 testing/selftests/mm: add soft-dirty merge self-test
  • f563ce913a83 mm: propagate VM_SOFTDIRTY on merge
  • b836839c1fd9 mm: set the VM_MAYBE_GUARD flag on guard region install
  • 3d6cb2ed06f7 mm: introduce copy-on-fork VMAs and make VM_MAYBE_GUARD one
  • 05cdec24a858 mm: implement sticky VMA flags
  • a093c80a1f13 mm: update vma_modify_flags() to handle residual flags, document
  • bdeadba74337 mm: add atomic VMA flags and set VM_MAYBE_GUARD as such
  • efce8a486bff mm: introduce VM_MAYBE_GUARD and make visible in /proc/$pid/smaps
  • 0de7db2eb27e sctp: disable BH before calling udp_tunnel_xmit_skb()
  • eee6be6ab637 firmware: samsung: acpm: Fix cross-thread RX length corruption
  • 02ac3ba41628 Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs
  • 072bbd2846d1 hv: utils: handle and propagate errors in kvp_register
  • bde74af8d446 regulator: core: fix locking in regulator_resolve_supply() error path
  • 9477cbc5107a rose: don't free fd-owned sockets when reaping in the heartbeat
  • 395b6573b389 rose: clear neighbour pointer in rose_kill_by_device()
  • 9e8fc2195f8b rose: cancel neighbour timers in rose_neigh_put() before freeing
  • c31a0fa15a4b rose: drop CALL_REQUEST in loopback timer when device is not running
  • 74cbe94c913a rose: release netdev ref and destroy orphaned incoming sockets
  • c794d35f73a7 rose: fix netdev double-hold in rose_make_new()
  • ce27bcdd857a rose: disconnect orphaned STATE_2 sockets when device is gone
  • ab849a6972c9 rose: set SOCK_DESTROY in rose_kill_by_device() for prompt cleanup
  • c98cc00c2d3b rose: fix notifier unregistered too early in rose_exit()
  • 19139026dc1c rose: fix netdev double-hold in rose_rx_call_request()
  • 1d94857c11d6 rose: guard rose_neigh_put() against NULL in timer expiry
  • 270ef709257e rose: clear neighbour pointer after rose_neigh_put() in state machines
  • 940f39e15332 rose: fix race between loopback timer and module removal
  • fe8cbcc3e79d rose: hold loopback neighbour reference across timer callback
  • 7dac298524b4 rose: fix dev_put() leak in rose_loopback_timer()
  • 19b3691ec940 ACPI: scan: Use async schedule function in acpi_scan_clear_dep_fn()
  • 53483a9f4ee9 agp/amd64: Fix broken error propagation in agp_amd64_probe()
  • 8b17adf6d4fb net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
  • 5f4d2bd028eb i2c: stub: Reject I2C block transfers with invalid length
  • e2b143df2900 RDMA/bnxt_re: zero shared page before exposing to userspace
  • 44b8b03a9fb5 debugobjects: Dont call fill_pool() in early boot hardirq context
  • 3a408cae608d debugobjects: Do not fill_pool() if pi_blocked_on
  • 9cd2087cd702 debugobjects: Use LD_WAIT_CONFIG instead of LD_WAIT_SLEEP
  • a460935022f5 debugobjects: Allow to refill the pool before SYSTEM_SCHEDULING
  • 95f9eb19d5e6 Revert "NFSD: Defer sub-object cleanup in export put callbacks"
  • af2892249d98 fuse: re-lock request before replacing page cache folio
  • 29706ac73f93 net: stmmac: fix stm32 (and potentially others) resume regression
  • b6099150949f io_uring/net: Avoid msghdr on op_connect/op_bind async data
  • e5609e8d8cac Linux 6.18.36-xanmod1
  • a240262f0bf0 Merge tag 'v6.18.36' into 6.18
  • 275d294b2b24 Linux 6.18.36
  • 5d634afb8b83 netfilter: require Ethernet MAC header before using eth_hdr()
  • bf7a9cacd95e cfi: Include uaccess.h for get_kernel_nofault()
  • f455405e3207 vsock/virtio: fix skb overhead overflow on 32-bit builds
  • 36a0faaa4e3d block: fix handling of dead zone write plugs
  • 7b569b3a2f29 arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU
  • 99abe00c605e arm64: errata: Mitigate TLBI errata on NVIDIA Olympus CPU
  • d4fd42822040 arm64: errata: Mitigate TLBI errata on various Arm CPUs
  • 8097f93f9b77 arm64: cputype: Add C1-Premium definitions
  • e9ea7cb17677 arm64: cputype: Add C1-Ultra definitions
  • eca6743b148a vsock/virtio: fix skb overhead accounting to preserve full buf_alloc
  • 9bdc637fde66 vsock/virtio: fix potential unbounded skb queue
  • cdce1e797add ipvs: skip ipv6 extension headers for csum checks
  • afd35fec9297 RDMA/umem: Fix truncation for block sizes >= 4G
  • cd26d54bfbc2 RDMA: Move DMA block iterator logic into dedicated files
  • ebf22feff492 RDMA/umem: fix kernel-doc warnings
  • 84d8f58cf28a netfilter: nft_fib: fix stale stack leak via the OIFNAME register
  • 2904e985a291 RDMA: During rereg_mr ensure that REREG_ACCESS is compatible
  • f58efaf9fcf7 RDMA/umem: Add helpers for umem dmabuf revoke lock
  • 5f3286ca5fbb RDMA/umem: Move umem dmabuf revoke logic into helper function
  • ceddd32231dd RDMA/umem: Add ib_umem_dmabuf_get_pinned_and_lock helper
  • 0ffcad63b19a sched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task()
  • 37c059d4d92f wifi: mac80211: tests: mark HT check strict
  • 4dac39a4db14 wifi: mac80211: skip ieee80211_verify_sta_ht_mcs_support check in non-strict mode
  • 17faa39ba980 driver core: reject devices with unregistered buses
  • 20a93e397abe fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
  • e09689286385 drm/amd/display: Use krealloc_array() in dal_vector_reserve()
  • 454d3b3d499c drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()
  • bb6f705b73b5 drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
  • c000da79df78 drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs
  • 3f32d52ec604 drm/amd/display: Clamp VBIOS HDMI retimer register count to array size
  • 1906064d50d1 drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
  • 0e56f460bddb drm/amd/display: Bound VBIOS record-chain walk loops
  • 57607fe55e6d drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range
  • 932642791cb1 drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2
  • 8979ded4d899 drm/amd/pm: fix smu13 power limit default/cap calculation
  • 39b5397bf8de drm/amdgpu: set noretry=1 as default for GFX 10.1.x (Navi10/12/14)
  • fcd51a085e9a drm/amdgpu: restart the CS if some parts of the VM are still invalidated
  • 68455b117258 drm/amdgpu: fix waiting for all submissions for userptrs
  • 9655b56b6de9 drm/v3d: Skip CSD when it has zeroed workgroups
  • 90b629269088 drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups
  • 3e1947573140 drm/v3d: Fix global performance monitor reference counting
  • 11e9bdf8824b drm/v3d: Wait for pending L2T flush before cleaning caches
  • 4c10fd55187a drm/xe: Clear pending_disable before signaling suspend fence
  • 0f68ddfaaebf drm/xe/display: fix oops in suspend/shutdown without display
  • d3efcadfe3ee drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
  • 72e259a32084 drm/amdkfd: fix NULL dereference in get_queue_ids()
  • c0639ede2f24 drm/gem: Try to fix change_handle ioctl, attempt 4
  • 9f0d45d509b4 slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock
  • 8f4b371f4939 slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD
  • 5204cd22c1c7 slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership
  • dd8e1025a84e slimbus: qcom-ngd-ctrl: Initialize controller resources in controller
  • 24ec89123fc9 slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd
  • 3bb2ac834ed3 slimbus: qcom-ngd-ctrl: Fix probe error path ordering
  • d6cb003e4661 slimbus: qcom-ngd-ctrl: Fix up platform_driver registration
  • 6890bd2451a9 slimbus: qcom-ngd-ctrl: fix OF node refcount
  • b5daa920f44c thunderbolt: Limit XDomain response copy to actual frame size
  • 46da5c3ea011 thunderbolt: Validate XDomain request packet size before type cast
  • fcbd0cdab928 thunderbolt: Clamp XDomain response data copy to allocation size
  • 60ba62174607 thunderbolt: Bound root directory content to block size
  • 2e0ddac549eb thunderbolt: Reject zero-length property entries in validator
  • d5ea0b3e261f sctp: stream: fully roll back denied add-stream state
  • 78c4f964b2f9 sctp: diag: reject stale associations in dump_one path
  • 566c4c1244de rxrpc: Fix the ACK parser to extract the SACK table for parsing
  • 1bf84f4013fa rtase: Reset TX subqueue when clearing TX ring
  • 54f9cdcd7311 rtase: Avoid sleeping in get_stats64()
  • ddcf84b25af0 pmdomain: ti_sci: add wakeup constraint to parent devices of wakeup source
  • 0d11992d1898 pmdomain: imx: fix OF node refcount
  • 0aecf3c7b8f8 mmc: sdhci: add signal voltage switch in sdhci_resume_host
  • 535ff092b686 mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC
  • 2f72d36f8acc mmc: litex_mmc: Set mandatory idle clocks before CMD0
  • 7f8007be13e6 mmc: dw_mmc-rockchip: Add missing private data for very old controllers
  • c677b13671dc mmc: core: Fix host controller programming for fixed driver type
  • a8f91ddf67f6 mm/mincore: handle non-swap entries before !CONFIG_SWAP guard
  • c19ff4351214 mm/list_lru: drain before clearing xarray entry on reparent
  • c72469ac0f27 mm/hugetlb: restore reservation on error in hugetlb folio copy paths
  • ecc24f0a8a30 mm/hugetlb: avoid false positive lockdep assertion
  • 66bc00ea37fa mm/damon/reclaim: handle ctx allocation failure
  • 6d48f1565939 mm/damon/lru_sort: handle ctx allocation failure
  • d83390b21a02 mm/cma_debug: fix invalid accesses for inactive CMA areas
  • 52078596dce1 mm/cma: fix reserved page leak on activation failure
  • d5d37b7b72a9 io_uring/wait: fix min_timeout behavior
  • c888d5198ffc io_uring/kbuf: don't truncate end buffer for bundles
  • 3fdcca838f97 pinctrl: mcp23s08: Read spi-present-mask as u8 not u32
  • e646b86b3b48 octeontx2-af: fix memory leak in rvu_setup_hw_resources()
  • 4a4d21f531cc nvmem: layouts: onie-tlv: fix hang on unknown types
  • cb85ef5a227b nvmem: core: fix use-after-free bugs in error paths
  • bef389a210e7 net: sfp: initialize i2c_block_size at adapter configure time
  • 1d4ec754ee38 net: rds: clear i_sends on setup unwind
  • 52b8f5ef82c8 net: phonet: free phonet_device after RCU grace period
  • 4a73cacb5586 net: mv643xx: fix OF node refcount
  • bcb8fad90f27 net: bonding: fix NULL pointer dereference in bond_do_ioctl()
  • 01f7d4b50458 net: airoha: Add NULL check for of_reserved_mem_lookup() in airoha_qdma_init_hfwd_queues()
  • e0df4d9c0909 net/mlx5: Reorder completion before putting command entry in cmd_work_handler
  • 0a46c7a5646d firmware: samsung: acpm: Fix mailbox channel leak on probe error
  • d5de9cb5355d misc: fastrpc: Fix NULL pointer dereference in rpmsg callback
  • 53e06f8a3c2b misc: fastrpc: fix DMA address corruption due to find_vma misuse
  • 992f121796b7 misc: fastrpc: fix use-after-free race in fastrpc_map_create
  • 5278ccd357e0 misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context
  • 89bd8215e25a memcg: use round-robin victim selection in refill_stock
  • a388e3dfaf95 locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
  • db752ebfdaf2 ipc/shm: serialize orphan cleanup with shm_nattch updates
  • ab61c990a87d iommu/dma: Do not try to iommu_map a 0 length region in swiotlb
  • f35a368fee8a Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard
  • a3dff1e1a554 Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK)
  • 7f59e4f72a78 i2c: tegra: Fix NOIRQ suspend/resume
  • 6018d73137cd i2c: stm32f7: fix timing computation ignoring i2c-analog-filter
  • a162a260c8c4 i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()
  • 9fa82cf393ba i2c: imx: fix clock and pinctrl state inconsistency in runtime PM
  • b39f30c0a72f i2c: imx-lpi2c: fix resource leaks switching to devm_dma_request_chan()
  • 16f8e17184b3 futex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock
  • 56763afa0134 fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
  • 12df4cfa738a fuse: reject fuse_notify() pagecache ops on directories
  • 57a9c085be07 fs/qnx6: fix pointer arithmetic in directory iteration
  • 2990f143ec86 pidfd: refuse access to tasks that have started exiting harder
  • 89b909e97045 inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
  • df422fd273c9 IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
  • 32138633e51e fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh()
  • 3884976f8744 bnxt_en: Fix NULL pointer dereference
  • 6f72b902c34d ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write
  • 735dabdf2156 staging: rtl8723bs: fix buffer over-read in rtw_update_protection
  • 1d6c2062b77b timers/migration: Fix livelock in tmigr_handle_remote_up()
  • ba9ad6015937 vsock/vmci: fix sk_ack_backlog leak on failed handshake
  • 265c07c09c83 wifi: nl80211: reject oversized EMA RNR lists
  • ac2000be0cbe wifi: iwlwifi: pcie: simplify the resume flow if fast resume is not used
  • fcfdff42e841 xfs: fix rtgroup cleanup in CoW fork repair
  • d84ed2f9718e xfs: fix error returns in CoW fork repair
  • 9f21885c11ba mptcp: add-addr: always drop other suboptions
  • 6ea1134f1b5f selftests: mptcp: add test for extra_subflows underflow on userspace PM
  • 7bbc11437a20 mptcp: sockopt: set sockopt on all subflows
  • f591cbc088c9 mptcp: sockopt: check timestamping ret value
  • c0c152fc4ae6 mptcp: pm: fix extra_subflows underflow on userspace PM subflow creation
  • 653245266913 mptcp: allow subflow rcv wnd to shrink
  • 3b8cbba7c0ed mptcp: close TOCTOU race while computing rcv_wnd
  • edaf0c955ace mptcp: fix retransmission loop when csum is enabled
  • 95f27fcda681 arm64: mm: call pagetable dtor when freeing hot-removed page tables
  • 517720913bd3 ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow
  • da295adc9dab ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O
  • 6243a363ec90 ARM: socfpga: Fix OF node refcount leak in SMP setup
  • 6822eed69572 udp: clear skb->dev before running a sockmap verdict
  • c96786d6ff1a zram: fix use-after-free in zram_bvec_write_partial()
  • f92a285db7ff RDMA/srp: bound SRP_RSP sense copy by the received length
  • bd5e818be796 RDMA/core: Validate cpu_id against nr_cpu_ids in DMAH alloc
  • 96b6e98ff12d RDMA/core: Validate the passed in fops for ib_get_ucaps()
  • e99807bdcd20 mm/huge_memory: update file PUD counter before folio_put()
  • cb5230b6d8a0 mm/damon/ops-common: call folio_test_lru() after folio_get()
  • 5f5b604e1e6b mm/huge_memory: update file PMD counter before folio_put()
  • edabfe80e34e drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info()
  • 8348567a6afb drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()
  • 0bbc9481f970 io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries
  • 3d39da65b5c4 ALSA: timer: Fix UAF at snd_timer_user_params()
  • f46093dd2296 ALSA: timer: Forcibly close timer instances at closing
  • 372f33ebed74 USB: serial: kl5kusb105: fix bulk-out buffer overflow
  • 85bd2b3afa0a USB: serial: option: add usb-id for Dell Wireless DW5826e-m
  • 294692d3296e USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
  • f96cf7bf9fbf USB: serial: io_ti: fix heap overflow in get_manuf_info()
  • a13ca53e47e5 xfrm: iptfs: fix ABBA deadlock in iptfs_destroy_state()
  • dd66f7f6e360 xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()
  • f9b38a8fbfa0 xfrm: espintcp: do not reuse an in-progress partial send
  • 14d2eee0193a ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL
  • 0b38870d81ab hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf
  • 32d4c5d328a3 drm/i915/gem: Fix phys BO pread/pwrite with offset
  • 0b79bcff7210 KVM: arm64: Restore POR_EL0 access to host EL0
  • 196f1ee137eb KVM: SEV: Decouple the need to sync the GHCB SA from the need to free the SA
  • 343e95c8ecc4 KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
  • 0864bdde152e mshv: add a missing padding field
  • 8bcbedce9bfa mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation
  • a0a4600b396b rust: kasan/kbuild: fix rustc-option when cross-compiling
  • d0f25a1755f2 rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES
  • 5037b2ee1a17 ARM: Do not select HAVE_RUST when KASAN is enabled
  • 00875811f372 rust: x86: support Rust >= 1.98.0 target spec
  • 592be0dc491d tracing/probes: Point the error offset correctly for eprobe argument error
  • 09df291fdf96 tracing: Fix CFI violation in probestub being called by tprobes
  • 45cb105b8642 accel/ivpu: Fix signed integer truncation in IPC receive
  • fa598556ecef accel/ivpu: Add buffer overflow check in MS get_info_ioctl
  • 8ec70c0dbdf0 accel/ivpu: Add bounds checks for firmware log indices
  • dd77a83915b0 mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison
  • cc160ce08540 soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get()
  • dedc92b96dc1 Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
  • dafc9f57140e Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
  • c10c9c48b290 tee: shm: fix shm leak in register_shm_helper()
  • 07acb9798477 netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register
  • 941d7394efda netfilter: nft_tunnel: fix use-after-free on object destroy
  • e83fc4c28226 accel/amdxdna: Fix mm_struct reference leak in aie2_populate_range()
  • 361e97d81331 drm/xe: fix refcount leak in xe_range_fence_insert()
  • 02f5e4db57c0 drm/vc4: fix krealloc() memory leak
  • 19a6a00ff50c drm/virtio: Fix driver removal with disabled KMS
  • dda720b2928d drm/i915/edp: Check supported link rates DPCD read
  • 489f6d759fa4 clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration time
  • 3a4fc3617b7e clk: samsung: gs101: Fix missing USI7_USI DIV clock in peric0_clk_regs
  • 656939c67595 clk: qcom: x1e80100-dispcc: Stop disp_cc_mdss_mdp_clk_src from getting parked
  • f34689e7a0b3 KVM: VMX: Update SVI during runtime APICv activation
  • 07d9a0870a17 ipv6: Fix a potential NPD in cleanup_prefix_route()
  • 2c98343c9b23 net: txgbe: initialize module info buffer
  • 19a4d2aace1d net: txgbe: rename the SFP related
  • 9157060fed92 net: txgbe: support CR modules for AML devices
  • 7649ba2b1291 net: txgbe: optimize the flow to setup PHY for AML devices
  • af08fe9ba091 net: mvpp2: build skb from XDP-adjusted data on XDP_PASS
  • 8a2126c5afe8 net: mvpp2: refill RX buffers before XDP or skb use
  • 910617a4e67d net: mvpp2: limit XDP frame size to the RX buffer
  • a13199fa224e net: mvpp2: sync RX data at the hardware packet offset
  • 78069a6d8bc8 netfilter: nft_exthdr: fix register tracking for F_PRESENT flag
  • af1b7699466f netfilter: nf_log: validate MAC header was set before dumping it
  • 08a3e218064d netfilter: x_tables: avoid leaking percpu counter pointers
  • 9d017671dcfc netfilter: nf_conntrack: destroy stale expectfn expectations on unregister
  • 4beffcd726e2 netfilter: revalidate bridge ports
  • 865e94f6d8a5 spi: rzv2h-rspi: Fix SPDR read access width for 16-bit RX
  • 5ae8a38169fc rds: mark snapshot pages dirty in rds_info_getsockopt()
  • 2abfb19bbb81 ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
  • 5fd1fa5a4254 tun: zero the whole vnet header in tun_put_user()
  • dcf458120add net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
  • 3dde4fb941fa net: guard timestamp cmsgs to real error queue skbs
  • 7560afb8cdda sctp: validate embedded INIT chunk and address list lengths in cookie
  • ecf8904067dc ip6_vti: set netns_immutable on the fallback device.
  • f76a8b323e28 sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
  • d23d53355300 ASoC: SOF: amd: fix for ipc flags check
  • 6c75ee4d1d40 net: mctp: usb: don't fail mctp_usb_rx_queue on a deferred submission
  • 9c46f3ee1837 net: mctp: usb: fix race between urb completion and rx_retry cancellation
  • bace7b99bfa5 gpio: rockchip: fix generic IRQ chip leak on remove
  • 5d4bca5cbb69 gpio: zynq: fix runtime PM leak on remove
  • c838ffc154cb r8152: handle the return value of usb_reset_device()
  • ecc55aad3390 net: openvswitch: fix possible kfree_skb of ERR_PTR
  • 2fa49b2715e1 ipv6: sit: reload inner IPv6 header after GSO offloads
  • 289c06418ed9 net/mlx5: Use effective affinity mask for IRQ selection
  • 2789b74ae1f4 net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure
  • 0f807764bb12 net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list
  • ab269990ed58 net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove
  • 3a254779c169 net: phy: clean the sfp upstream if phy probing fails
  • c299321bc623 netdev: fix double-free in netdev_nl_bind_rx_doit()
  • c09c2e236eef net: ibm: emac: Fix use-after-free during device removal
  • 8b0541231091 net/mlx4: avoid GCC 10 __bad_copy_from() false positive
  • 0cde3a004119 net: add pskb_may_pull() to skb_gro_receive_list()
  • ede69b8f6670 tcp: restrict SO_ATTACH_FILTER to priv users
  • 12e579b88962 ASoC: wm_adsp: Fix NULL dereference when removing firmware controls
  • 6136c1474db8 gpio: mvebu: fix NULL pointer dereference in suspend/resume
  • 0c4bb32ad7fd netlabel: validate unlabeled address and mask attribute lengths
  • 972c106f5d01 bnge: fix context mem iteration
  • 6b8baf42b1b7 net: ena: PHC: Add missing barrier
  • 640edc281d2f idpf: fix mailbox capability for set device clock time
  • 6bdbe6f43ecf ice: fix missing priority callbacks for U.FL DPLL pins
  • b5316e2b8614 xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()
  • 5513dcb378f9 dma-debug: fix physical address retrieval in debug_dma_sync_sg_for_device
  • 4ee4d628c4d9 dma-mapping: direct: fix missing mapping for THRU_HOST_BRIDGE segments
  • 8d9a79fbf517 xfrm: iptfs: fix use-after-free on first_skb in __input_process_payload
  • e27c17346628 tap: free page on error paths in tap_get_user_xdp()
  • 0c03692e2372 verification/rvgen: Fix ltl2k writing True as a literal
  • 43ad0a0da486 verification/rvgen: Fix options shared among commands
  • 73590b4cfd05 tools/rv: Fix cleanup after failed trace setup
  • fd1923910bbf tools/rv: Fix substring match when listing container monitors
  • 2122d68f0864 tools/rv: Fix substring match bug in monitor name search
  • 618193aba6fe tools/rv: Ensure monitor name and desc are NUL-terminated
  • 65046b0d853d cpufreq/amd-pstate: drop stale @epp_cached kdoc
  • 63a9f6012f45 spi: cadence-quadspi: fix unclocked access on unbind
  • 6671a46144f8 ALSA: seq: dummy: fix UMP event stack overread
  • cd98837db15f ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
  • 6b71956c25f9 time: Fix off-by-one in settimeofday() usec validation
  • ed0ad6574126 hyperv: Clean up and fix the guest ID comment in hvgdk.h
  • 8c046f36222c signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()
  • 6dc6e5b5c32e selftests: harness: fix pidfd leak in __wait_for_test
  • 752e22ecf4df drm/hyperv: During panic do VMBus unload after frame buffer is flushed
  • b0f77f76231b Drivers: hv: vmbus: Provide option to skip VMBus unload on panic
  • 1639df1a9844 Drivers: hv: VMBus protocol version 6.0
  • a6207349e703 sctp: purge outqueue on stale COOKIE-ECHO handling
  • 42446ca0f357 net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr
  • 285b0842f2e0 ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit()
  • 3b7ee029b556 vxlan: vnifilter: fix spurious notification on VNI update
  • 8e4d1188bad7 vxlan: vnifilter: send notification on VNI add
  • eb676fb14427 octeontx2-af: npc: Fix CPT channel mask in npc_install_flow
  • cc272185c9a9 sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
  • b198ed4e5258 net/sched: fix pedit partial COW leading to page cache corruption
  • e634408d2b0c net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown
  • 6f829e2c17a5 net: airoha: Fix use-after-free in metadata dst teardown
  • 9a263bbd1ec0 ptp: vclock: Switch from RCU to SRCU
  • a4f3fd651692 ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
  • 91106d0348a5 af_unix: Fix inq_len update problem in partial read
  • f010cf9aea01 octeontx2-af: Fix initialization of mcam's entry2target_pffunc field
  • ddf930f28be6 octeontx2-pf: Fix NDC sync operation errors
  • 0dfe05b93843 xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata()
  • 58d810354de1 Bluetooth: MGMT: Fix backward compatibility with userspace
  • 446a17b1b509 Bluetooth: SCO: Fix data-race on sco_pi fields in sco_connect
  • ab84fd7779a2 Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls
  • 33d677d2e371 Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync
  • ce4b4cac3c57 Bluetooth: fix memory leak in error path of hci_alloc_dev()
  • c893e17d2809 Bluetooth: bnep: reject short frames before parsing
  • 7f5367f1ad9b Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling
  • 3eabc6d47a0a Bluetooth: RFCOMM: validate skb length in MCC handlers
  • 1a3c8ffbb469 Bluetooth: MGMT: validate advertising TLV before type checks
  • 8802413ce631 Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
  • fb8db813eba2 wifi: fix leak if split 6 GHz scanning fails
  • 15be7e9fdbff ipv6: anycast: insert aca into global hash under idev->lock
  • 23bf7d5c250b net: fec: fix pinctrl default state restore order on resume
  • 76244b33640b net: lan743x: permit VLAN-tagged packets up to configured MTU
  • 04e22fefac1a net: garp: fix unsigned integer underflow in garp_pdu_parse_attr
  • 66a46e22396f hsr: Remove WARN_ONCE() in hsr_addr_is_self().
  • 07f13816be5a net: Annotate sk->sk_write_space() for UDP SOCKMAP.
  • 83810d51d699 pcnet32: stop holding device spin lock during napi_complete_done
  • 9b40c59bab08 wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap
  • e3f6ba5f8cf3 drm/imx: Fix three kernel-doc warnings in dcss-scaler.c
  • 927f96861f93 devlink: Release nested relation on devlink free
  • e251d4cdfc72 l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()
  • c32f30ef5e66 6lowpan: fix off-by-one in multicast context address compression
  • b60e9391142e net/sched: act_api: use RCU with deferred freeing for action lifecycle
  • 42ff6774ecd9 dm cache policy smq: check allocation under invalidate lock
  • b18675263db1 netfilter: bridge: make ebt_snat ARP rewrite writable
  • f071b0bf0781 netfilter: nft_ct: bail out on template ct in get eval
  • 9e5da2379f96 netfilter: conntrack_irc: fix possible out-of-bounds read
  • aaf80701dc2f netfilter: synproxy: add mutex to guard hook reference counting
  • 25918720ba97 ipvs: clear the svc scheduler ptr early on edit
  • cdaf13260c99 netfilter: xt_NFQUEUE: prefer raw_smp_processor_id
  • e735dbd489e3 ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers
  • 9dca67624721 wifi: iwlwifi: mvm: don't support the reset handshake for old firmwares
  • 00bf6868df65 erofs: fix use-after-free on sbi->sync_decompress
  • 50fd261b1ec4 erofs: tidy up synchronous decompression
  • 8db2fabb5ecd tee: qcomtee: add missing va_end in early return qcomtee_object_user_init()
  • ac7eca1ae4e5 tee: fix tee_ioctl_object_invoke_arg padding
  • 633db9a1991a soc: qcom: ice: Return -ENODEV if the ICE platform device is not found
  • 40fc6ed12f91 ARM: dts: microchip: sam9x7: fix GMAC clock configuration
  • 9cb93ec617fb arm64: dts: qcom: x1-dell-thena: remove i2c20 (battery SMBus) and reserve its pins
  • a171bc68e9af soc: qcom: ice: Allow explicit votes on 'iface' clock for ICE
  • d5b57bb314d7 tee: optee: prevent use-after-free when the client exits before the supplicant
  • dcd90f42a33e net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS
  • 4203806f700b ipv6: mcast: Fix use-after-free when processing MLD queries
  • ffbcf31f032e i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl
  • 97706097f9b8 KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation
  • 9e767af5f109 ARM: fix branch predictor hardening
  • 05e22564a4f9 ARM: fix hash_name() fault
  • 8bdb574b2176 ARM: allow __do_kernel_fault() to report execution of memory faults
  • 22e26df355af ARM: group is_permission_fault() with is_translation_fault()
  • 87dfb977bdb6 bpf: Free reuseport cBPF prog after RCU grace period.
  • b0ffe362d9f8 Linux 6.18.35-rt-xanmod1
  • a42985600ae2 Merge branch '6.18' into 6.18-rt
  • da2d87f71ae2 Linux 6.18.35-xanmod1
  • f718432d2e3a Merge tag 'v6.18.35' into 6.18
  • acb7cf4c1184 Linux 6.18.35
  • 918450ad6010 KVM: arm64: Reassign nested_mmus array behind mmu_lock
  • 2bbc395e81bd KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry
  • adc6fc240a61 tools: ynl: add scope qualifier for definitions
  • f54b30f3316a usb: core: Fix SuperSpeed root hub wMaxPacketSize
  • 830c8a9b467e thunderbolt: property: Cap recursion depth in __tb_property_parse_dir()
  • 21bfa15a89d8 drm/i915/psr: Use DC_OFF wake reference to block DC6 on vblank enable
  • 00869f2320dc mailbox: Fix NULL message support in mbox_send_message()
  • 5372f6f10b0a xhci: tegra: Fix ghost USB device on dual-role port unplug
  • 58b2c0f096b3 net: phy: micrel: fix LAN8814 QSGMII soft reset
  • 972ea882d4bf mm/slub: hold cpus_read_lock around flush_rcu_sheaves_on_cache()
  • 56857385f313 hwmon: (pmbus/adm1266) serialize GPIO PMBus accesses with pmbus_lock
  • 6b94f9f5fe28 hwmon: (pmbus/adm1266) serialize sequencer_state debugfs read with pmbus_lock
  • 192516d72774 hwmon: (pmbus) Add support for guarded PMBus lock
  • d8fdf33d6fcf USB: serial: mct_u232: fix memory corruption with small endpoint
  • 062dcc0b324a USB: serial: digi_acceleport: fix memory corruption with small endpoints
  • 284105c40fc3 USB: serial: cypress_m8: fix memory corruption with small endpoint
  • c73c62a4bd52 usb: dwc3: xilinx: fix error handling in zynqmp init error paths
  • 9327252e0462 xfrm: iptfs: reset runtime state when cloning SAs
  • bb50838a2a06 cpufreq: intel_pstate: Use correct scaling factor on Raptor Lake-E
  • 7cb2daed3509 cpufreq: intel_pstate: Add and use hybrid_get_cpu_type()
  • 8f72a2509163 mptcp: reset rcv wnd on disconnect
  • 82e742b9d2cc mptcp: cleanup fallback dummy mapping generation
  • 0d9b9d7dbef9 octeontx2-pf: avoid double free of pool->stack on AQ init failure
  • fe93e907b1af arm64: tlb: Flush walk cache when unsharing PMD tables
  • bb37498a99e4 mptcp: do not drop partial packets
  • a84164847b1e mptcp: borrow forward memory from subflow
  • c67f986fc02c mptcp: handle first subflow closing consistently
  • 134c517dfa63 net: devmem: reject dma-buf bind with non-page-aligned size or SG length
  • b2beed6ad149 selftests: mptcp: drop nanoseconds width specifier
  • c5e7d4865292 Bluetooth: hci_qca: Convert timeout from jiffies to ms
  • 8264178afb5c Bluetooth: hci_qca: Migrate to serdev specific shutdown function
  • 0acba63d7d46 serdev: Provide a bustype shutdown function
  • 8bf7dbb741dd rxrpc: Fix RESPONSE packet verification to extract skb to a linear buffer
  • 46cb765e2e5a rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg
  • fed725cace3a x86/mm: Disable broadcast TLB flush when PCID is disabled
  • 81181a39bde9 platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error recovery
  • 1730c91a8b9a platform/x86/intel/vsec: Make driver_data info const
  • 4b0e87f9b50f platform/x86/intel/vsec: Refactor base_addr handling
  • 71b88acec0a7 serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq()
  • 7f8b194ed720 serial: 8250: dispatch SysRq character in serial8250_handle_irq()
  • 5f2172d799f3 serial: core: introduce guard(uart_port_lock_check_sysrq_irqsave)
  • 237dc8c08de3 serial: zs: Convert to use a platform device
  • 81984447eac4 serial: zs: Switch to using channel reset
  • b1ceeaef4fbc serial: zs: Fix bootconsole handover lockup
  • 2ff0401ffdda serial: dz: Convert to use a platform device
  • 2c5b693d918c serial: dz: Fix bootconsole handover lockup
  • 24b7be239b0b serial: dz: Fix bootconsole message clobbering at chip reset
  • f059b4c493df drm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO
  • fa372f4e8aef drm/amdgpu: fix calling VM invalidation in amdgpu_hmm_invalidate_gfx
  • 1eb86334e391 drm/amdgpu: fix lock leak on ENOMEM in AMDGPU_GEM_OP_GET_MAPPING_INFO
  • 275396bf71c4 drm/amdkfd: Check for pdd drm file first in CRIU restore path
  • 5cf4a41aa0d7 drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger
  • 2f9c3c161692 drm/amdkfd: fix NULL pointer bug in svm_range_set_attr
  • 348e01e64a87 serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma
  • 8e39badab090 serial: zs: Fix swapped RI/DSR modem line transition counting
  • 10ddd1a320e1 serial: sh-sci: fix memory region release in error path
  • 654f45a8569f serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ
  • 78d0d6f69bd6 serial: qcom-geni: fix UART_RX_PAR_EN bit position
  • 9a91692fae5c serial: altera_jtaguart: handle uart_add_one_port() failures
  • ffa7dce35b64 drm/amd/pm/si: Disregard vblank time when no displays are connected
  • c9ae7e7e3bc9 drm/i915: Fix potential UAF in TTM object purge
  • fed64e47a32f drm/i915/psr: Block DC states on vblank enable when Panel Replay supported
  • 0dfa42cfe4db drm/gem: fix race between change_handle and handle_delete
  • 164dc7bf1760 drm/hyperv: validate VMBus packet size in receive callback
  • 9c698b2c43c2 drm/hyperv: validate resolution_count and fix WIN8 fallback
  • 4a3a19c98a82 scsi: target: iscsi: Validate CHAP_R length before base64 decode
  • 594a40360012 scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf
  • 89c81d1228c0 scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()
  • 35461d237441 scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32
  • 14dd80a20a72 scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker
  • d548179adcc8 thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow
  • 31b98e503ecc thunderbolt: property: Reject u32 wrap in tb_property_entry_valid()
  • c7d421123b98 usb: gadget: f_fs: serialize DMABUF cancel against request completion
  • 607730a41477 usb: gadget: f_fs: copy only received bytes on short ep0 read
  • 5933063935e8 usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports
  • f8f5a8f48c7c usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling
  • f928630f450b usb: gadget: f_hid: fix device reference leak in hidg_alloc()
  • e6f8be12f030 usb: gadget: net2280: Fix double free in probe error path
  • caec0145e597 usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind
  • f06bcaba2970 USB: serial: mct_u232: fix missing interrupt-in transfer sanity check
  • 6c0cf56f00f2 USB: serial: mxuport: fix memory corruption with small endpoint
  • ea2b792330b4 USB: serial: keyspan: fix missing indat transfer sanity check
  • ae03453f2c80 USB: serial: cypress_m8: validate interrupt packet headers
  • 22823a319fb2 USB: serial: belkin_sa: validate interrupt status length
  • f7c3fcd63405 USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL
  • 38ba1a464c0d USB: serial: option: add MeiG SRM813Q
  • 62fbc1396108 usb: typec: ucsi: Don't update power_supply on power role change if not connected
  • d62d97c9c8c2 usb: typec: ucsi: Check if power role change actually happened before handling
  • f34effb0b545 usb: typec: tcpm: improve handling of DISCOVER_MODES failures
  • 02d9d8b79e18 usb: typec: tipd: Fix error code in tps6598x_probe()
  • a90139ff1eba usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize
  • 75f6d3da2cc6 usb: usbtmc: check URB actual_length for interrupt-IN notifications
  • 88d459e5b5a4 usbip: vudc: Fix use after free bug in vudc_remove due to race condition
  • 5b78d8b9a832 usb: storage: Add quirks for PNY Elite Portable SSD
  • 94b05aec1985 USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers
  • 69f9f2b30af0 usb: musb: omap2430: Fix use-after-free in omap2430_probe()
  • 3bc65566331a usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval
  • 7118304b1a77 usb: chipidea: core: convert ci_role_switch to local variable
  • 9fd48937046e tty: serial: samsung: Remove redundant port lock acquisition in rx helpers
  • 66f8bfea055b tty: serial: pch_uart: add check for dma_alloc_coherent()
  • b4bebb6e0a44 counter: Fix refcount leak in counter_alloc() error path
  • c7e670cb2538 comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest()
  • 269f5be6a6e4 comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest()
  • fdb74898d91d Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490
  • 7f95f4792c0d Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem
  • 639fa8af506e misc: rp1: Send IACK on IRQ activate to fix kdump/kexec
  • 94215d55b094 ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops
  • 6617ee91062b Input: xpad - add support for ASUS ROG RAIKIRI II
  • 3d63b8077f5b Input: xpad - add "Nova 2 Lite" from GameSir
  • 2ffd8b0dd448 ALSA: hda/realtek: Fix speaker output on ASUS ROG Strix G615LP
  • c093468aea82 xfrm: esp: restore combined single-frag length gate
  • c4609fff0665 ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks
  • 35be14ea8298 ASoC: qcom: q6asm-dai: close stream only when running
  • b98ab51c45c5 netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check
  • b9027ff112b6 ALSA: firewire-motu: Protect register DSP event queue positions
  • befcb15c1f05 ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417
  • aa0c7e59192b xfrm: ah: use skb_to_full_sk in async output callbacks
  • dc6dcba80d72 xfrm: ipcomp: Free destination pages on acomp errors
  • 448bb92ca101 xfrm: route MIGRATE notifications to caller's netns
  • 22d41b176b99 nfc: hci: fix out-of-bounds read in HCP header parsing
  • 8b1f4f618fd8 iommu, debugobjects: avoid gcc-16.1 section mismatch warnings
  • b8338111e141 HID: wacom: Fix OOB write in wacom_hid_set_device_mode()
  • 59139473a7a7 spi: spi-mem: avoid mutating op template in spi_mem_supports_op()
  • 96a4713ae041 net: skbuff: fix missing zerocopy reference in pskb_carve helpers
  • fc32be9ac278 ip6: vti: Use ip6_tnl.net in vti6_changelink().
  • 947013fd7c8c l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname
  • 9f7ebb45a83a xfrm: input: hold netns during deferred transport reinjection
  • a35daeabb433 ipv6: validate extension header length before copying to cmsg
  • 853f6ea482df ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().
  • 751db1b802a0 ipv6: exthdrs: refresh nh after handling HAO option
  • 90983f841dfa ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params
  • c512e1c819df ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()
  • 6d00f5c7e5ff macsec: fix replay protection at XPN lower-PN wrap
  • 5e1902866796 bpf: sockmap: fix tail fragment offset in bpf_msg_push_data
  • e4892b1ecd73 wireguard: send: append trailer after expanding head
  • d59cc66b7027 x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines
  • 3f43865cb64d i2c: davinci: fix division by zero on missing clock-frequency
  • bf769358419e Input: elan_i2c - validate firmware size before use
  • 84ea928ed584 usb: dwc2: Fix use after free in debug code
  • 94c92f9c886c usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles
  • 459c4fa089f7 usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure
  • b2723bd468c5 usb: cdns3: gadget: fix request skipping after clearing halt
  • 0fee0ccac29e USB: serial: omninet: fix memory corruption with small endpoint
  • 3412a95afaa5 iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf()
  • a3763ae33476 iio: buffer: hw-consumer: fix use-after-free in error path
  • 390254cf509b iio: light: cm3323: fix reg_conf not being initialized correctly
  • 5e4d34092a5e iio: chemical: scd30: fix division by zero in write_raw
  • a5a05410cb34 iio: chemical: mhz19b: reject oversized serial replies
  • cbd2d7e6bd4f iio: Fix iio_multiply_value use in iio_read_channel_processed_scale
  • 8d4daa614440 iio: light: veml6070: Fix resource leak in probe error path
  • ae01ec83841d iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL
  • aefc19ca3dd3 iio: temperature: tsys01: fix broken PROM checksum validation
  • 04a4d9822210 iio: ssp_sensors: cancel delayed work_refresh on remove
  • aaf9d640e9ae iio: gyro: adis16260: fix division by zero in write_raw
  • 15a0b3f33ffb iio: gyro: itg3200: fix i2c read into the wrong stack location
  • 5cb8cede8baf iio: adc: ad4695: Fix call ordering in offload buffer postenable
  • 7155e7fce429 iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw
  • 944082fdb028 iio: adc: mt6359: fix unchecked return value in mt6358_read_imp
  • 991d359faa95 iio: dac: ad5686: fix powerdown control on dual-channel devices
  • 31de336a2c0d iio: dac: ad5686: acquire lock when doing powerdown control
  • f541c9a1eb89 iio: dac: ad5686: fix input raw value check
  • 69f7d101976c iio: dac: ad5686: fix ref bit initialization for single-channel parts
  • 684bfd655b80 iio: dac: max5821: fix return value check in powerdown sync
  • 88c9dd5170e0 iio: dac: ad3530r: Fix AD3531/AD3531R powerdown mode strings
  • 2ce5ca7824a1 iio: adc: npcm: fix unbalanced clk_disable_unprepare()
  • 0ee771fff32e iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux
  • bb1b43e8a7ed Disable -Wattribute-alias for clang-23 and newer
  • bbd989d6fd36 KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc()
  • b1dfaa6f7a95 KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer
  • 75c8d1d72912 KVM: SEV: Check PSC request indices against the actual size of the buffer
  • 9f0a9e780f02 KVM: SEV: Compute the correct max length of the in-GHCB scratch area
  • 5300aedbee56 KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0
  • e4ab26f81a63 KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests
  • 2254972d4d69 KVM: SEV: Ignore Port I/O requests of length '0'
  • c9b4198fbc6e KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use
  • ec62e8480e82 KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC
  • b1fc4a83dd44 KVM: arm64: PMU: Preserve AArch32 counter low bits
  • 625153b917bc USB: cdc-acm: Fix bit overlap and move quirk definitions to header
  • 667599e71832 rust_binder: avoid calling pending_oneway_finished() on TF_UPDATE_TXN
  • f2f2671e32c5 rust_binder: Avoid holding lock when dropping delivered_death
  • 74d6aae1df45 parport: Fix race between port and client registration
  • 9749db57233b Input: xpad - fix out-of-bounds access for Share button
  • d9019210c8c3 Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync
  • 2b7651f58670 Bluetooth: hci_qca: Use 100 ms SSR delay for rampatch and NVM loading
  • e6b78019664d Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate()
  • bc08c15746f2 Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock
  • c318aa51830a Bluetooth: ISO: fix UAF in iso_recv_frame
  • 6348dfed5b0f Bluetooth: HIDP: fix missing length checks in hidp_input_report()
  • e8a5baff5be2 Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn
  • 859d3ace791e Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()
  • 388051f7389a smb: client: fix uninitialized variable in smb2_writev_callback
  • 197476b12601 auxdisplay: line-display: fix OOB read on zero-length message_store()
  • 0fcc34d0d8fe mm/rmap: initialize nr_pages to 1 at loop start in try_to_unmap_one
  • 0995d1f79aed memfd: deny writeable mappings when implying SEAL_WRITE
  • f1f0cdca932b mm: memcontrol: propagate NMI slab stats to memcg vmstats
  • a3cc795129e5 ipc: limit next_id allocation to the valid ID range
  • 0ba6c05156d9 mm/damon/sysfs-schemes: delete tried region in regions_rmdirs()
  • 0886c6f257fe hpfs: fix a crash if hpfs_map_dnode_bitmap fails
  • 4064a30381fa Bluetooth: btusb: Allow firmware re-download when version matches
  • 6728e80c9d29 HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse
  • 8735a28f2dcd Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free()
  • f33b5a61673b media: rc: igorplugusb: fix control request setup packet
  • f793b67d41e5 USB: serial: safe_serial: fix memory corruption with small endpoint
  • 0edd1e21587b usb: typec: ucsi: validate connector number in ucsi_connector_change()
  • 9b496e3371c0 usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
  • e94933dc41b8 usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer()
  • b10eff5abe6a usb: typec: altmodes/displayport: validate count before reading Status Update VDO
  • 052dbef45cb3 usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO
  • 4505f33dab56 usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()
  • f9d787fbe831 usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers
  • a38ed87818b2 usb: typec: ucsi: ccg: reject firmware images without a ':' record header
  • a58400f58f82 iio: pressure: bmp280: fix stack leak in bmp580 trigger handler
  • ce582b22dd2f iio: imu: adis16550: fix stack leak in trigger handler
  • e6bb3a49c5f9 iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer
  • 278b0df1f736 phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X
  • 487393023feb drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used
  • c058cf6b84c1 drm/i915/psr: Read Intel DPCD workaround register
  • dd4cbab2a446 drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register
  • 600ad63124de s390/cio: Restore GFP_DMA for CHSC allocation
  • 0171e01de47a Revert "x86/fpu: Refine and simplify the magic number check during signal return"
  • ff0ca46b13b9 smb: client: validate the whole DACL before rewriting it in cifsacl
  • efacf63ed087 media: rc: ttusbir: fix inverted error logic
  • e250b672d40a media: rc: fix race between unregister and urb/irq callbacks
  • 814be4a0924b net: skbuff: fix pskb_carve leaking zcopy pages
  • ab9a10969a90 ipv6: fix possible infinite loop in fib6_select_path()
  • dc36a04621dc ipv6: fix possible infinite loop in rt6_fill_node()
  • b62e2b2b4a50 vsock/virtio: bind uarg before filling zerocopy skb
  • 68667ee4c7da sctp: fix race between sctp_wait_for_connect and peeloff
  • c4152b4e28b3 net: mana: Skip redundant detach on already-detached port
  • da87896f34e0 net: mana: Add NULL guards in teardown path to prevent panic on attach failure
  • 7f945f7f10f4 gpio: rockchip: teardown bugs and resource leaks
  • e2fabb984bfd gpio: rockchip: convert bank->clk to devm_clk_get_enabled()
  • 5d43c71fa8e1 gpio: virtuser: Fix uninitialized data bug in gpio_virtuser_direction_do_write()
  • b6cdbb681ce1 gpio: adnp: fix flow control regression caused by scoped_guard()
  • ae2eac5e9cfe Bluetooth: hci_sync: Reset device counters in hci_dev_close_sync()
  • 47330cc875b3 Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close
  • 41e29548b5e8 Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp
  • f39049304ba6 Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success
  • 1d4dcfe60fe1 net/handshake: Pass negative errno through handshake_complete()
  • 25b2fcdea6f6 nvme-tcp: store negative errno in queue->tls_err
  • 0866569fc36a net/handshake: Use spin_lock_bh for hn_lock
  • c35064294eca net: hibmcge: disable Relaxed Ordering to fix RX packet corruption
  • 7f97b8352ce5 net/sched: Revert "net/sched: Restrict conditions for adding duplicating netems to qdisc tree"
  • 6fe1cb312038 ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()
  • fd0de51c54fa ethtool: eeprom: add more safeties to EEPROM Netlink fallback
  • c944cab3df82 ethtool: eeprom: add missing ethnl_ops_begin() / _complete() during fallback
  • 3e656023a649 ethtool: strset: fix header attribute index in ethnl_req_get_phydev()
  • 2008f9bb1ede ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure
  • ab94e0d6664d ethtool: tsinfo: fix uninitialized stats on the by-PHC path
  • d02342d9bb4f ethtool: tsconfig: fix missing ethnl_ops_complete()
  • 912f8b23bc4b ethtool: pse-pd: fix missing ethnl_ops_complete()
  • 49455e27838a ethtool: linkstate: fix unbalanced ethnl_ops_complete() on PHY lookup error
  • d11c98484485 ethtool: tsconfig: fix reply error handling
  • 0c02c190bcd9 ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES
  • e976e3f2f200 bridge: Fix sleep in atomic context in sysfs path
  • c9c2e609e839 bridge: Fix sleep in atomic context in netlink path
  • 9ea8a648d912 bonding: refuse to enslave CAN devices
  • e673889a35a5 Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt()
  • 75cf24709037 drm/xe: Restore IDLEDLY regiter on engine reset
  • 164dcbec9632 ASoC: codecs: simple-mux: Fix enum control bounds check
  • de9eb0b44fa9 ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE
  • 43368636c663 tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()
  • 5303925e3605 vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
  • 6dff77899b9e tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmpv6
  • 2a8c9994406b cxl/test: Update mock dev array before calling platform_device_add()
  • 41d2dc766bf8 ethtool: cmis: validate fw->size against start_cmd_payload_size
  • 0696709e951b ethtool: cmis: validate start_cmd_payload_size from module
  • 0cbce444db75 ethtool: cmis: fix u16-to-u8 truncation of msleep_pre_rpl
  • 4d42fb88ec61 ethtool: cmis: require exact CDB reply length
  • e1dd697094f1 ethtool: module: fix cleanup if socket used for flashing multiple devices
  • 9e70c8efb0ca ethtool: module: check fw_flash_in_progress under rtnl_lock
  • 9f5108f5ee27 ethtool: module: avoid racy updates to dev->ethtool bitfield
  • 61848c83b913 ethtool: module: avoid leaking a netdev ref on module flash errors
  • d9defbf8b62b ethtool: module: call ethnl_ops_complete() on module flash errors
  • 7877d8fbbec2 ethtool: rss: avoid device context leak on reply-build failure
  • 7ddc3b3ddee8 ethtool: rss: fix hkey leak when indir_size is 0
  • 33d05c22d6f2 ethtool: rss: fix indir_table and hkey leak on get_rxfh failure
  • 39c01c405063 ethtool: rss: fix falsely ignoring indir table updates
  • 6a775ec73210 ethtool: rss: add missing errno on RSS context delete
  • f23e4d7324b8 ethtool: rss: avoid modifying the RSS context response
  • 48fd840a26d3 net: Avoid checksumming unreadable skb tail on trim
  • 03e9405c518c net: team: fix NULL pointer dereference in team_xmit during mode change
  • c2af23b48f93 net: team: Rename port_disabled team mode op to port_tx_disabled
  • a20e6ae5f05e net: team: Remove unused team_mode_op, port_enabled
  • f2e077e8979f gpio: mxc: fix irq_high handling
  • fbd0662f9c9a net: hsr: fix potential OOB access in supervision frame handling
  • 2a15a03e58b0 net/mlx5: HWS: Reject unsupported remove-header action
  • f0ac76e3d55e ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors
  • e13922bb97b4 ALSA: pcm: oss: Fix setup list UAF on proc write error
  • a7f4eefb6e14 ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table()
  • 475f2b37a78f scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues
  • 981736924338 net/iucv: fix locking in .getsockopt
  • 55cba6b883b4 net/smc: Do not re-initialize smc hashtables
  • bcd0d19db3e6 net: netlink: don't set nsid on local notifications
  • ca5e36629641 net: netlink: fix sending unassigned nsid after assigned one
  • ef3b3ea864d0 vsock: keep poll shutdown state consistent
  • aa308e9dbb9a tun: free page on build_skb failure in tun_xdp_one()
  • 37a1c268c2c8 tun: free page on short-frame rejection in tun_xdp_one()
  • 96bea2a7baac netfilter: nf_tables: fix dst corruption in same register operation
  • bf8e8eac7ede netfilter: ebtables: fix OOB read in compat_mtw_from_user
  • 052468b1c93b netfilter: xt_cpu: prefer raw_smp_processor_id
  • f0fea2b6d545 netfilter: synproxy: refresh tcphdr after skb_ensure_writable
  • 18abd88d19ea accel/rocket: fix UAF via dangling GEM handle in create_bo
  • 45564a16a24f kunit: fix use-after-free in debugfs when using kunit.filter
  • e1b8a53834dc HID: remove duplicate hid_warn_ratelimited definition
  • bebc7dc0fb4b tools/bootconfig: Fix buf leaks in apply_xbc
  • b4702049417f nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems
  • 82ac903e0b51 xfrm: Check for underflow in xfrm_state_mtu
  • 650bdd8fdfab nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()
  • 912ebc49d440 nfc: llcp: Fix use-after-free in llcp_sock_release()
  • 8b733ee4aecd bcache: fix uninitialized closure object
  • dbc560858da8 net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked
  • 91cc13978ab0 xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit
  • 54ed418de62a net: mctp: ensure our nlmsg responses are initialised
  • 41845bc5bb64 net/sched: cls_fw: fix NULL dereference of "old" filters before change()
  • 0ca809ea8e03 Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size
  • 599f0b059dab Linux 6.18.34-xanmod1
  • a17ef3eb3ae0 Merge tag 'v6.18.34' into 6.18
  • 18ad16ce4a6b Linux 6.18.34
  • 50bb3435a5e6 security/keys: fix missed RCU read section on lookup
  • 239172639075 drm/msm: Restore second parameter name in purge() and evict()
  • 306ba9d0e5aa LoongArch: kprobes: Fix handling of fatal unrecoverable recursions
  • a1a39f227c80 ksmbd: fix durable reconnect error path file lifetime
  • 6836f694126e io_uring/nop: pass all errors to userspace
  • e334cbf3388f net: gro: don't merge zcopy skbs
  • 8129611d4ede pds_core: ensure null-termination for firmware version strings
  • d1d76bbb6d7a net: airoha: Disable GDM2 forwarding before configuring GDM2 loopback
  • 719007c3492f tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR
  • fa627a5eaa83 net: mana: validate rx_req_idx to prevent out-of-bounds array access
  • bc0020490f88 octeontx2-af: npc: Fix allmulticast skip logic for LBK and SDP VFs
  • 76dd50b7888d selftests: net: Fix checksums in xdp_native
  • 04ef7592eaad drm/xe/oa: Fix exec_queue leak on width check in stream open
  • db86ac6d8daf ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove()
  • decacc6308c5 gpio: aggregator: lock device when calling device_is_bound()
  • 3e657619cf72 gpio: aggregator: remove the software node when deactivating the aggregator
  • 80d94cf1773a gpio: aggregator: stop using dev-sync-probe
  • ea28b286649b gpio: aggregator: fix a potential use-after-free
  • 4669f84adcb1 gpio: cdev: check if uAPI v2 config attributes are correctly zeroed
  • e47f7060eaf6 tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction
  • 1861d369efd6 bpf, skmsg: fix verdict sk_data_ready racing with ktls rx
  • 26f1d4522060 net: ag71xx: check error for platform_get_irq
  • 585f9f6aef5c crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks
  • 2417df5e7bb4 net: shaper: rework the VALID marking (again)
  • 5a2c2aa139c8 net: shaper: annotate the data races
  • b5bd4249e430 net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA
  • a0f5268c77eb Bluetooth: btmtk: fix urb->setup_packet leak in error paths
  • c7860b6a6d2d Bluetooth: btintel_pcie: Fix incorrect MAC access programming
  • d6c8b3ebdcdb tracing: Avoid NULL return from hist_field_name() on truncation
  • 8bf00d3ac425 cgroup: rstat: relax NMI guard after switch to try_cmpxchg
  • 3aab4a58d23f ALSA: seq: Serialize UMP output teardown with event_input
  • 95c82d498d74 wifi: wilc1000: fix dma_buffer leak on bus acquire failure
  • 55c479aae99b wifi: mac80211: fix MLE defragmentation
  • 2d8379834800 wifi: mac80211: bounds-check link_id in ieee80211_ml_epcs
  • 425d32d6288d erofs: fix managed cache race for unaligned extents
  • 91d13e92b983 pds_core: fix debugfs_lookup dentry leak and error handling
  • 784dd2bdc622 pds_core: fix error handling in pdsc_devcmd_wait
  • ce23832071af net: airoha: Fix NPU RX DMA descriptor bits
  • 0c277d203684 net: phy: honor eee_disabled_modes in phy_advertise_eee_all()
  • bd731994cff1 net: phy: honor eee_disabled_modes in phy_support_eee()
  • a9224862d597 bridge: mcast: Fix a possible use-after-free when removing a bridge port
  • 981aea209977 net: bridge: Flush multicast groups when snooping is disabled
  • eae62c5451e6 RDMA/rtrs: Fix use-after-free in path file creation cleanup
  • 8c63698737b4 RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port
  • d5b11e15ee67 ASoC: soc-utils: Add missing va_end in snd_soc_ret()
  • 09deb063eecf platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL
  • f6dfd64bfd9b platform/x86: intel-hid: Check ACPI_HANDLE() against NULL
  • ed864a7b881c platform/x86: hp_accel: Check ACPI_COMPANION() against NULL
  • 7ea5aad8d351 platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL
  • 098419a4b062 platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7
  • 09ec063d87c2 net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer
  • f71fc35b5e45 net: dsa: mt7530: preserve VLAN tags on trapped link-local frames
  • 89bed786f231 net: dsa: mt7530: fix FDB entries not aging out with short timeout
  • f1739debda62 kbuild: pacman-pkg: make "rc" releases adhere to pacman versioning scheme
  • ad8e3d096fa1 drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP
  • 1f83545f432d igc: set tx buffer type for SMD frames
  • 89964ddb322a ice: ptp: use primary NAC semaphore on E825
  • 0010296879df ice: ptp: serialize E825 PHY timer start with PTP lock
  • 6a01413a4e8f cgroup/rstat: validate cpu before css_rstat_cpu() access
  • 83b8a0f72ecc drm/mediatek: mtk_hdmi_ddc: Fix non-static global variable
  • 8ea34da68964 drm/mediatek: mtk_cec: Fix non-static global variable
  • 926a08cf19be wifi: ath11k: fix peer resolution on rx path when peer_id=0
  • 6c9e9272bc37 drm/xe/pf: Fix CFI failure in debugfs access
  • dc26e00860a1 drm/xe/vf: Fix signature of print functions
  • 2c890e71ae26 drm/xe/gsc: Fix double-free of managed BO in error path
  • 181e67bc11c5 dma-mapping: move dma_map_resource() sanity check into debug code
  • 3a74aaad0473 wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it
  • 9e360e610a73 wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled
  • bed1fc32e0eb hwmon: (lm90) Add lock protection to lm90_alert
  • c98107817b0f hwmon: (lm90) Stop work before releasing hwmon device
  • cdd1aaf0ee96 drm/msm/snapshot: fix dumping of the unaligned regions
  • 0c9e4d9484cc ALSA: hda/realtek: Use ALC287_FIXUP_TXNW2781_I2C for ASUS Strix Gxx5
  • df19b6af1716 netfilter: nft_inner: release local_lock before re-enabling softirqs
  • 0fa225896f4b spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache()
  • fecfed41da73 ASoC: amd: acp-sdw-legacy: check CPU DAI name before logging
  • 7e91d3a1a98a btrfs: fix squota accounting during enable generation
  • ca56ffdb017b btrfs: check for subvolume before deleting squota qgroup
  • b422609291f6 btrfs: relax squota parent qgroup deletion rule
  • 22d558df51d9 btrfs: check squota parent usage on membership change
  • a1296bb9f44a btrfs: remaining BTRFS_PATH_AUTO_FREE conversions
  • 76ad957a72c7 btrfs: don't search back for dir inode item in INO_LOOKUP_USER
  • 16141bef6fb1 btrfs: use the key format macros when printing keys
  • 35f69e993d00 btrfs: add macros to facilitate printing of keys
  • 76b995bc57bd vsock/virtio: fix zerocopy completion for multi-skb sends
  • 782693eb53f8 io_uring/net: punt IORING_OP_BIND async if it needs file create
  • c53cac053d62 ALSA: scarlett2: Add missing error check when initialise Autogain Status
  • 1ddf678bb75b ASoC: codecs: fs210x: fix possible buffer overflow
  • 36de63965464 scsi: sd: Fix return code handling in sd_spinup_disk()
  • b4dc0056397f net/mlx5: Do not restore destination-less TC rules
  • 81c8a9f75a42 tls: Preserve sk_err across recvmsg() when data has been copied
  • 1370acb8bc39 ovpn: disable BHs when updating device stats
  • f7808b7ddcf2 x86/xen: Fix xen_e820_swap_entry_with_ram()
  • 2378d25675da gcc-plugins: Always define CONST_CAST_GIMPLE and CONST_CAST_TREE
  • 097d62df3831 ovpn: fix race between deleting interface and adding new peer
  • 8298834912d7 ovpn: respect peer refcount in CMD_NEW_PEER error path
  • e5460eb7238c ovpn: tcp - use cached peer pointer in ovpn_tcp_close()
  • 2bc34520ce5c net: phy: DP83TC811: add reading of abilities
  • af855f4c966a net: tls: prevent chain-after-chain in plain text SG
  • eca989eab4b2 net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring
  • afa9036b8c99 net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot
  • 6dcd072a5ae3 powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise()
  • f4e37f3df436 drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN
  • eea43d5ed450 drm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx
  • 3a7b59d2385d Documentation: intel_pstate: Fix description of asymmetric packing with SMT
  • 3ad2d8be6e4d x86/mce: Restore MCA polling interval halving
  • 15dba511d569 selftests: ublk: cap nthreads to kernel's actual nr_hw_queues
  • ff58e5ef1b46 drm/msm/dpu: don't mix devm and drmm functions
  • a184aec79013 drm/msm/dsi: don't dump registers past the mapped region
  • d235f8f7b264 ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics
  • d2ea0b8aef87 net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint
  • 97a8e89cdef3 accel/qaic: Add overflow check to remap_pfn_range during mmap
  • 76410790f149 block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()
  • 086695145000 HID: quirks: really enable the intended work around for appledisplay
  • 0943f81e1b31 block: recompute nr_integrity_segments in blk_insert_cloned_request
  • 0d48654af4d1 block: don't overwrite bip_vcnt in bio_integrity_copy_user()
  • a52486394493 net: shaper: reject QUEUE scope handle with missing id
  • 77ec90d41c59 net: shaper: enforce singleton NETDEV scope with id 0
  • d7c2bbbaa2c4 net: shaper: fix undersized reply skb allocation in GROUP command
  • f817ce8d1943 net: shaper: set ret to -ENOMEM when genlmsg_new() fails in group_doit
  • 5098b223f0f0 net: shaper: reject duplicate leaves in GROUP request
  • d6128451c591 net: shaper: fix trivial ordering issue in net_shaper_commit()
  • d947e6685ff4 net: shaper: flip the polarity of the valid flag
  • e1b429d8e712 wifi: ath10k: skip WMI and beacon transmission when device is wedged
  • d94127d04017 wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm()
  • acde4692afcd wifi: ath11k: fix error path leaks in some WMI WOW calls
  • 9bc70fe995da net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference
  • c373b34877af net: ethernet: cortina: Carry over frag counter
  • 3cd05250a2df net: ethernet: cortina: Drop half-assembled SKB
  • cfd62907f3cd net: ethernet: cortina: Make RX SKB per-port
  • 77bb293049d6 netfs, afs: Fix write skipping in dir/link writepages
  • f17b9121bb99 netfs: Fix netfs_read_folio() to wait on writeback
  • 551b5c71ee31 netfs: Fix folio->private handling in netfs_perform_write()
  • 3d9601c029b9 netfs: Fix partial invalidation of streaming-write folio
  • 6080fa3ecfbb netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()
  • 22ae28aae436 netfs: Fix leak of request in netfs_write_begin() error handling
  • d4f4bc87c765 netfs: Fix early put of sink folio in netfs_read_gaps()
  • 616578e40dcb netfs: Fix write streaming disablement if fd open O_RDWR
  • 0b18cd70ebab netfs: Fix read-gaps to remove netfs_folio from filled folio
  • 003aa0dd26c9 netfs: Fix potential deadlock in write-through mode
  • ef9b521212e4 netfs: Fix streaming write being overwritten
  • 185ded4112cd netfs: Defer the emission of trace_netfs_folio()
  • fb6ec883b48b netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone
  • afeb32d9bf9a netfs: Fix overrun check in netfs_extract_user_iter()
  • b63971238beb netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call
  • 884c4c4f35e5 netfs: Fix netfs_read_to_pagecache() to pause on subreq failure
  • 5366199be46f netfs: Fix cancellation of a DIO and single read subrequests
  • 9c6f23cf3a07 powerpc: fix dead default for GUEST_STATE_BUFFER_TEST
  • 822bb1614ec4 powerpc: 82xx: fix uninitialized pointers with free attribute
  • aed60070ed7b ASoC: SOF: amd: Fix error code handling in psp_send_cmd()
  • 510db031ba6e tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key().
  • eba8af785fde zonefs: handle integer overflow in zonefs_fname_to_fno
  • 9525e3a6fbb1 nvme-pci: fix use-after-free in nvme_free_host_mem()
  • fea4b46f84c5 nvme: fix bio leak on mapping failure
  • 18c0456ea261 irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT
  • 06ee55f78fbe nsfs: fix wrong error code returned for pidns ioctls
  • d168a71fc1d6 ublk: reject max_sectors smaller than PAGE_SECTORS in parameter validation
  • 617a2564d863 irqchip/ath79-cpu: Remove unused function
  • ace6b3e033c6 fs: Fix return in jfs_mkdir and orangefs_mkdir
  • e37ea2c6f17f fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap
  • 56b4cfcf1518 fprobe: Fix unregister_fprobe() to wait for RCU grace period
  • 36dc0cea30db ASoC: sdw_utils: Add quirk to ignore RT721 CODEC_MIC
  • 5afefecfe054 ASoC: sdw_utils: Add quirk to ignore RT712 CODEC_MIC
  • fe59ae27d734 NFSD: Fix infinite loop in layout state revocation
  • e9405f704127 phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access
  • 994358adc098 net: ti: icssm-prueth: fix eth_ports_node leak in probe
  • 7df3e1dfee53 net: lan966x: avoid unregistering netdev on register failure
  • d91a9a049698 ice: fix locking in ice_dcb_rebuild()
  • 34ad3c782644 ice: fix setting RSS VSI hash for E830
  • eb5991d4c8ba idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()
  • a248793f00ab net: shaper: Reject reparenting of existing nodes
  • bfe08fe5624b net: napi: Avoid gro timer misfiring at end of busypoll
  • 77e7818eb347 tcp: Fix imbalanced icsk_accept_queue count.
  • 1c24cf1fd67f test_kprobes: clear kprobes between test runs
  • ae8a5c6b0316 kprobes: skip non-symbol addresses in kprobe_add_ksym_blacklist()
  • c647e2a21bbb netfilter: bridge: eb_tables: close module init race
  • 524b6337277a netfilter: x_tables: close dangling table module init race
  • cc989ef1c044 netfilter: ebtables: close dangling table module init race
  • 739d5dac7b2d netfilter: ebtables: move to two-stage removal scheme
  • 86ee5bc9c0f0 netfilter: x_tables: add and use xtables_unregister_table_exit
  • 89ebafe7910d netfilter: x_tables: add and use xt_unregister_table_pre_exit
  • a9b2f73f6ba7 netfilter: x_tables: unregister the templates first
  • c32a7e0e3c73 btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()
  • 373f65b448ed ALSA: hda: cs35l41: Put ACPI device on missing physical node
  • fecae8b1fb2d ALSA: hda: cs35l56: Put ACPI device after setting companion
  • e984dc22e2c2 ARM: integrator: Fix early initialization
  • 9e472874c954 firmware: arm_ffa: Fix sched-recv callback partition lookup
  • d1e38551fade firmware: arm_ffa: Snapshot notifier callbacks under lock
  • 419cef661ae8 firmware: arm_ffa: Align RxTx buffer size before mapping
  • 3c51d99449dc firmware: arm_ffa: Validate framework notification message layout
  • 0a5dbac5ef53 firmware: arm_ffa: Keep framework RX release under lock
  • f39bc7ebe75e firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies
  • fd2b01637e56 pinctrl: qcom: Fix wakeirq map by removing disconnected irqs for sm8150
  • 3f4d82780001 kunit: config: KUNIT_DEBUGFS should depend on DEBUG_FS
  • 91e4446b35f6 kunit: config: Enable KUNIT_DEBUGFS by default
  • 96b8b9d0dead riscv: mm: Fixup no5lvl failure when vaddr is invalid
  • f3216d930c0f riscv: errata: Fix bitwise vs logical AND in MIPS errata patching
  • 1aa01b46fe3b firmware: arm_ffa: Unregister bus notifier on teardown for FF-A v1.0
  • 07907b897bb7 firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue
  • 1418765d28ab firmware: arm_ffa: Skip free_pages on RX buffer alloc failure
  • 820245d86ce5 firmware: arm_ffa: Check for NULL FF-A ID table while driver registration
  • 4894847fcec1 HID: uclogic: Fix regression of input name assignment
  • e912d5dc0096 HID: intel-thc-hid: Intel-quickspi: Fix some error codes
  • 1fce9dcb3a66 pinctrl: qcom: Fix GPIO to PDC wake irq map for qcs615
  • e917713f0134 pinctrl: meson: amlogic-a4: fix deadlock issue
  • 8d1c6b603327 pinctrl: renesas: rzg2l: Fix SMT register cache handling
  • c4cfa8ee7737 pinctrl: renesas: rzg2l: Fix incorrect PUPD register offset for high pins during suspend/resume
  • a7fee1322683 ARM: dts: renesas: rskrza1: Drop superfluous cells
  • d27b29e474a6 ARM: dts: renesas: genmai: Drop superfluous cells
  • 00aca89f5e34 pinctrl: qcom: ipq4019: mark gpio as a GPIO pin function
  • eb3cd9bb5904 hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors
  • dd12c6dbe2ac hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe()
  • a203125c0e81 hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe()
  • b2998ae90331 hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple
  • fa7ca363069a hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR
  • 97a9cf2a8217 hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer
  • 2279c342d94e hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer
  • 75c862adf3d3 hwmon: (pmbus/adm1266) reject implausible blackbox record_count
  • e9b8f85daebf hwmon: (pmbus/adm1266) seed timestamp from the real-time clock
  • e37dbe150515 batman-adv: tt: prevent TVLV entry number overflow
  • 730de8733dd9 batman-adv: tt: fix negative tt_buff_len
  • 179eb62506a0 batman-adv: tt: fix negative last_changeset_len
  • b93ca6012712 batman-adv: tt: avoid empty VLAN responses
  • 7cac9c9ef4b7 batman-adv: tt: reject oversized local TVLV buffers
  • 4cc85aec8d3c batman-adv: tt: fix TOCTOU race for reported vlans
  • 2d2d365d0b9d batman-adv: tp_meter: avoid role confusion in tp_list
  • 72d670d7a492 batman-adv: tp_meter: fix race condition in send error reporting
  • b285bc0a97f4 batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown
  • 770bf0a35f06 batman-adv: tp_meter: directly shut down timer on cleanup
  • dc2ae5fbd2da batman-adv: tp_meter: avoid use of uninit sender vars
  • 6921a7683ae9 batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface
  • 45384612f296 batman-adv: bla: avoid double decrement of bla.num_requests
  • c6de1a5a9c40 batman-adv: bla: fix report_work leak on backbone_gw purge
  • 5895ad21c705 batman-adv: frag: disallow unicast fragment in fragment
  • 90ae3eae06b7 batman-adv: fix tp_meter counter underflow during shutdown
  • 3eb8bcb82339 batman-adv: fix fragment reassembly length accounting
  • 9cceea8eeba7 batman-adv: dat: handle forward allocation error
  • ae7aeb0ce3c0 batman-adv: clear current gateway during teardown
  • 8a3707653ab6 batman-adv: mcast: fix use-after-free in orig_node RCU release
  • ca3ff3d2a0af batman-adv: iv: recover OGM scheduling after forward packet error
  • ede47988ac56 batman-adv: tvlv: reject oversized TVLV packets
  • 23d4ce84df4d batman-adv: tvlv: abort OGM send on tvlv append failure
  • 1be1e99cbd5b batman-adv: v: stop OGMv2 on disabled interface
  • 1ecde19bfce6 drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async
  • 7ca695b31222 drm/amd/display: Validate GPIO pin LUT table size before iterating
  • 6bbd703ea1c1 drm/amd/display: Fix integer overflow in bios_get_image()
  • d35563813296 drm/bridge: megachips: remove bridge when irq request fails
  • 95306db11956 drm/bridge: it66121: acquire reset GPIO in probe
  • 3ed448c1dc78 drm/amdgpu/vpe: Force collaborate sync after TRAP
  • 8fadd01cf461 drm/virtio: use uninterruptible resv lock for plane updates
  • 35671087a272 drm/v3d: Release indirect CSD GEM reference on CPU job free
  • 0f8efc45740b drm/v3d: Fix use-after-free of CPU job query arrays on error path
  • 942968260e61 drm/msm: Fix shrinker deadlock
  • 508fd8ab158a device property: set fwnode->secondary to NULL in fwnode_init()
  • 22d9b9739b8e LoongArch: Remove unused code to avoid build warning
  • f27a3b9aadfb LoongArch: kprobes: Use larch_insn_text_copy() to patch instructions
  • 9e3f18883a98 fwctl: pds: Validate RPC input size before parsing
  • 1012896f4225 RDMA/siw: Reject MPA FPDU length underflow before signed receive math
  • d7a076fb596c spi: ti-qspi: fix use-after-free after DMA setup failure
  • be409d2bbe9c spi: sprd: fix error pointer deref after DMA setup failure
  • 8e027db9fa31 spi: ep93xx: fix error pointer deref after DMA setup failure
  • b9ff86310062 scsi: isci: Fix use-after-free in device removal path
  • 78a369a065f1 phy: qcom-qmp-ufs: Fix kaanapali PHY PLL lock failure after SM8650 G4 fix
  • 58f4a7bd8d73 phy: tegra: xusb: Fix per-pad high-speed termination calibration
  • a1f50f5aaa69 phy: exynos5-usbdrd: fix USB 2.0 HS PHY tuning values for Exynos7870
  • 4bb4764f2c51 spi: qup: fix error pointer deref after DMA setup failure
  • ecdf21536c6d drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe
  • bee400ad4f42 virt: sev-guest: Explicitly leak pages in unknown state
  • 4f087193b5ff riscv: kvm: return SBI_ERR_FAILURE for pmu_event_info() when OOM
  • 77071943c752 riscv: kvm: return SBI_ERR_FAILURE for pmu_snapshot_set_shmem() when OOM
  • 94ade38f317e KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235)
  • 7023900b4988 KVM: arm64: vgic: Free private_irqs when init fails after allocation
  • 0680f5119265 KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits
  • 240373425e2d arm64: probes: Handle probes on hinted conditional branch instructions
  • 798183376d9d tracing: Do not call map->ops->elt_free() if elt_alloc() fails
  • 5e7d9d0805e5 cifs: Fix busy dentry used after unmounting
  • 2dd9304727c7 wifi: mac80211: consume only present negotiated TTLM maps
  • acdff9907478 af_unix: Fix UAF read of tail->len in unix_stream_data_wait()
  • 6cfae4914439 wifi: cfg80211: advance loop vars in cfg80211_merge_profile()
  • 50884c2afd7a ice: restore PTP Rx timestamp config after ethtool set-channels
  • 0b9431b972a0 ice: fix setting promisc mode while adding VID filter
  • 9c9d00d81b41 ice: fix locking around wait_event_interruptible_locked_irq
  • f1bafd35f11b igc: fix potential skb leak in igc_fpe_xmit_smd_frame()
  • 8864b664d044 octeontx2-pf: fix double free in rvu_rep_rsrc_init()
  • 47a4cf2229be octeontx2-af: CGX: add bounds check to cgx_speed_mbps index
  • 5b906f31e977 lsm: hold cred_guard_mutex for lsm_set_self_attr()
  • 9dcd4f5c99b4 rbd: eliminate a race in lock_dwork draining on unmap
  • dfef79e09ed2 ixgbevf: fix use-after-free in VEPA multicast source pruning
  • 7725cd3b4717 ipv4: raw: reject IP_HDRINCL packets with ihl < 5
  • dc31c6947652 wifi: iwlwifi: mld: stop TX during firmware restart
  • 6fe92651b44f wifi: iwlwifi: mvm: fix driver-set TX rates on old devices
  • 614cacec60fe wifi: ath11k: clear shared SRNG pointer state on restart
  • a3529032afe2 ice: fix VF queue configuration with low MTU values
  • c618cf8926c0 vsock/virtio: reset connection on receiving queue overflow
  • 440447699c68 vsock/vmci: fix UAF when peer resets connection during handshake
  • 29b643351012 mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient
  • abdd03229414 ipv6: ioam: add NULL check for idev in ipv6_hop_ioam()
  • 2bc60c175568 ring-buffer: Flush and stop persistent ring buffer on panic
  • 610ff6bc2f44 ring-buffer: Fix reporting of missed events in iterator
  • 0e47fc1c9181 qed: fix double free in qed_cxt_tables_alloc()
  • e0c3dd7b30cc l2tp: use list_del_rcu in l2tp_session_unhash
  • d73dcd1520d6 fs/ntfs3: handle attr_set_size() errors when truncating files
  • 358692462555 net: ethtool: phy: avoid NULL deref when PHY driver is unbound
  • 61f53c1e58d6 net: ethtool: fix NULL pointer dereference in phy_reply_size
  • 752ea4a105e6 cgroup/cpuset: Reset DL migration state on can_attach() failure
  • 1aed73795392 tracing/fprobe: Check the same type fprobe on table as the unregistered one
  • f0ad68d2f0ad tracing/fprobe: Avoid kcalloc() in rcu_read_lock section
  • bb92f356d2b7 tracing: fprobe: use ftrace if CONFIG_DYNAMIC_FTRACE_WITH_ARGS
  • 52cc572c9565 tracing: fprobe: Remove unused local variable
  • 45c7c4e3db8b sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path
  • 6e73ec10b2a3 sched_ext: Fix missing warning in scx_set_task_state() default case
  • 689bbf48c1f4 netfilter: nft_inner: Fix IPv6 inner_thoff desync
  • 952e988163c2 netfilter: ipset: stop hash:* range iteration at end
  • 15d464265120 netfilter: nf_queue: hold bridge skb->dev while queued
  • 57b0ac5e1b46 netfilter: ip6t_hbh: reject oversized option lists
  • dac025c4e8f9 net: pse-pd: fix sign on -ENOENT check in of_load_pse_pis()
  • f8a5a76b4a68 net: ifb: report ethtool stats over num_tx_queues
  • 1604a2d68414 net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover
  • 49eff79967fd net: phy: skip EEE advertisement write when autoneg is disabled
  • 3d4ef05266ab net: bcmgenet: keep RBUF EEE/PM disabled
  • 84bc87beb4cd phonet/pep: disable BH around forwarded sk_receive_skb()
  • 8b4c412e001b Bluetooth: serialize accept_q access
  • f1febe93ef07 Bluetooth: MGMT: validate Add Extended Advertising Data length
  • 051922ab709c Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer
  • 192cb0f1ca70 Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths
  • 5506aec79513 Bluetooth: bnep: Fix UAF read of dev->name
  • 61f2410a96de Bluetooth: ISO: drop ISO_END frames received without prior ISO_START
  • added1213395 Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()
  • ffb6dbb49c96 net: wwan: iosm: fix potential memory leaks in ipc_imem_init()
  • 0fa24311bd42 selftests/mm: run_vmtests.sh: fix destructive tests invocation
  • 738d18f1da35 mm/page_alloc: fix initialization of tags of the huge zero folio with init_on_free
  • 09ce923071e7 mm/memory_hotplug: fix memory block reference leak on remove
  • 62153767e8fc mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_special()
  • 2fff0cdd9422 mm/memory: fix spurious warning when unmapping device-private/exclusive pages
  • 24de676da63c ipv6: ioam: refresh hdr pointer before ioam6_event()
  • 24840b3139d7 drivers/base/memory: fix memory block reference leak in poison accounting
  • b737c6612c60 io_uring/waitid: clear waitid info before copying it to userspace
  • 5fb947ddae55 spi: amd: Set correct bus number in ACPI probe path
  • c32a1fbe0f9a efi: Allocate runtime workqueue before ACPI init
  • fcbd0a5fd812 ALSA: scarlett2: Allow flash writes ending at segment boundary
  • 61c5017c64e2 ALSA: asihpi: Fix potential OOB array access at reading cache
  • feff0251386a ALSA: pcm: Don't setup bogus iov_iter for silencing
  • cba8dab72e9b ALSA: ua101: Reject too-short USB descriptors
  • ca560f7566df hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX
  • 9803e75c9813 smb/server: promote S_DEL_ON_CLS to S_DEL_PENDING when close
  • d65104a4a815 smb: client: use data_len for SMB2 READ encrypted folioq copy
  • bf4ebdb19ff9 smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
  • a8d17d22db59 smb: client: require net admin for CIFS SWN netlink
  • 6827647fd2dc regulator: tps65219: fix irq_data.rdev not being assigned
  • 18d8db24b0a5 ksmbd: validate SID in parent security descriptor during ACL inheritance
  • 0e198f09cb2a ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow
  • cd5c1b75d2f4 ksmbd: fix null pointer dereference in compare_guid_key()
  • 302e02f9ba49 mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break()
  • 48fa96538bd2 sysfs: don't remove existing directory on update failure
  • 141ffb83abe9 drm/vblank: Fix kernel docs for vblank timer
  • ed39ecd3a96c drm/atomic: Increase timeout in drm_atomic_helper_wait_for_vblanks()
  • a0582cc92398 drm/vkms: Convert to DRM's vblank timer
  • 60918357456d drm/vblank: Add CRTC helpers for simple use cases
  • fa4b91eea433 drm/vblank: Add vblank timer
  • 18a08b87db71 Revert "ice: Remove jumbo_remove step from TX path"
  • 523cd0ea0324 Revert "ice: fix double-free of tx_buf skb"
  • 515de0a3b6c1 ata: libata-scsi: do not needlessly defer commands when using PMP with FBS
  • 4e6eada8de38 ata: libata-scsi: do not use the deferred QC feature on PMPs with CBS
  • f207ebd5656e ata: libata-scsi: do not use the deferred QC feature for ATA_DEFER_PORT
  • 62ee00c1042c ata: libata-scsi: improve readability of ata_scsi_qc_issue()
  • 9d11e4b1db1c mfd: bcm2835-pm: Add support for BCM2712
  • ed915823d469 arm64: dts: broadcom: bcm2712: Add watchdog DT node
  • 375d5a17dc8d dt-bindings: soc: bcm: Add bcm2712 compatible
  • 91f89c1d83e8 smb: client: reject userspace cifs.spnego descriptions
  • 5da69a65b282 ksmbd: close durable scavenger races against m_fp_list lookups
  • aae4a47073b1 spi: spi-dw-dma: fix print error log when wait finish transaction
  • e8ec80430bfa bridge: mrp: reject zero test interval to avoid OOM panic
  • 0638bf16b7a7 sched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting
  • 3f0543bdf446 sched: Employ sched_change guards
  • dc184ac2f0ba cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed()
  • da3d241c5b92 fuse: fix uninit-value in fuse_dentry_revalidate()
  • 488d2c76bd9f iommu/amd: Remove latent out-of-bounds access in IOMMU debugfs
  • b9a4184271b9 iommu/amd: Fix illegal cap/mmio access in IOMMU debugfs
  • 814326e86e92 drm/xe/hdcp: Add NULL check for media_gt in intel_hdcp_gsc_check_status()
  • e469a636f608 Linux 6.18.33-xanmod1
  • b1dc0d89228b tcp_bbr: v3: update TCP 'bbr' congestion control module to BBRv3 [v6.18.33+]
  • bddb6a8ebea6 Merge tag 'v6.18.33' into 6.18
  • ac95f57c40f3 Revert "tcp_bbr: v3: update TCP 'bbr' congestion control module to BBRv3 [v6.18.14+]"
  • 83657f418961 Linux 6.18.33
  • 664736cc1f95 netfs: Fix potential uninitialised var in netfs_extract_user_iter()
  • e9a23ec9461e selftests/bpf: Remove test_access_variable_array
  • ff375cc75f91 net: skbuff: propagate shared-frag marker through frag-transfer helpers
  • 3bd9e113d500 net: skbuff: preserve shared-frag marker during coalescing
  • 640e37f58f99 net/rds: reset op_nents when zerocopy page pin fails
  • 6bf4253af814 spi: sifive: fix controller deregistration
  • 27fcf3dd04df spi: sifive: Simplify clock handling with devm_clk_get_enabled()
  • fac9cfad2f90 f2fs: fix false alarm of lockdep on cp_global_sem lock
  • a4a0340d20ab sched_ext: Pass held rq to SCX_CALL_OP() for core_sched_before
  • 255c3998dae8 sched_ext: Guard scx_dsq_move() against NULL kit->dsq after failed iter_new
  • a3c44e77f379 perf/x86/intel: Disable PMI for self-reloaded ACR events
  • b6437e6f8f3d btrfs: do not mark inode incompressible after inline attempt fails
  • 2647b8fe2f1f smb: client: Use FullSessionKey for AES-256 encryption key derivation
  • 244575d0c695 eventfs: Use list_add_tail_rcu() for SRCU-protected children list
  • 4fa42a249e8c drm/v3d: Reject empty multisync extension to prevent infinite loop
  • 4e003e2fb6d3 drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init
  • ab9256936b58 drm/gma500/oaktrail_lvds: fix hang on init failure
  • 6d835a99474c drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup
  • 9a34b94832c3 drm/ttm: Convert -EAGAIN from dmem_cgroup_try_charge to -ENOSPC
  • 39fdac6be02e drm/xe/dma-buf: fix UAF with retry loop
  • 20a99ea1e2fd drm/xe/dma-buf: handle empty bo and UAF races
  • c76273c3eba9 drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout()
  • 65a3a1cf29eb drm/i915: skip __i915_request_skip() for already signaled requests
  • 9022cb9ac0c2 iommu/vt-d: Avoid NULL pointer dereference or refcount corruption
  • 88397fad7914 iommu/vt-d: Fix oops due to out of scope access
  • 637b7ce89e54 iommu/vt-d: Disable DMAR for Intel Q35 IGFX
  • 4d2b37abda95 libceph: handle rbtree insertion error in decode_choose_args()
  • 0f3604cbe4df libceph: Fix potential out-of-bounds access in crush_decode()
  • f2f95e6d4b97 libceph: Fix potential null-ptr-deref in decode_choose_args()
  • 48df98d12b15 libceph: Fix potential out-of-bounds access in osdmap_decode()
  • 0de5cb2d61d0 irqchip/gic-v5: Allocate ITS parent LPIs as a range
  • 2cbd4abe413e irqchip/gic-v5: Support range allocation for LPIs
  • e6550b17cc0e irqchip/gic-v5: Move LPI allocation into the LPI domain
  • 84ff9ae64d9b irqchip/meson-gpio: Use the correct register in meson_s4_gpio_irq_set_type()
  • 5b0756b6b757 irqchip/riscv-imsic: Clear interrupt move state during CPU offlining
  • 42558732af4a nfsd: fix file change detection in CB_GETATTR
  • fc6db1e47c55 netfs: fix error handling in netfs_extract_user_iter()
  • 1a78bea6a5e9 powerpc/warp: Fix error handling in pika_dtm_thread
  • 3f6fb0211b39 virt: sev-guest: Do not use host-controlled page order in cleanup path
  • 690b7ca1f9b3 xfs: fix memory leak on error in xfs_alloc_zone_info()
  • b0bd7a850e1f x86/kexec: Push kjump return address even for non-kjump kexec
  • f0a0f01787ec iommu/amd: Bounds-check devid in __rlookup_amd_iommu()
  • 252c5051dba9 io-wq: check that the predecessor is hashed in io_wq_remove_pending()
  • d5bd8b4e39cf ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size
  • 3fa13ceefbc5 ceph: fix a buffer leak in __ceph_setxattr()
  • 9ebb7eba1237 btrfs: only release the dirty pages io tree after successful writes
  • d7b2de5d9862 ALSA: usb-audio: qcom: Check offload mapping failures
  • 09141583bd97 ALSA: usb-audio: Bound MIDI endpoint descriptor scans
  • f9c184a83574 ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans
  • 651760f57fe0 ALSA: hda/realtek: Add quirk for Samsung Galaxy Book5 360 headphone
  • a424946e00f2 ALSA: hda/realtek: Add mute LED quirk for HP Pavilion Laptop 16-ag0xxx
  • d3e03c25d520 accel/rocket: Fix prep_bo ioctl leaking positive return from dma_resv_wait_timeout()
  • 9b718ebe0e97 platform/x86: lenovo-wmi-other: Fix tunable_attr_01 struct members
  • b6c0f545c8f9 platform/x86: lenovo-wmi-helpers: Move gamezone enums to wmi-helpers
  • 1b2dca1f9b5a platform/x86: intel: Move debugfs register before creating devices
  • d25b863e2dff drm/i915/dp: Fix VSC dynamic range signaling for RGB formats
  • 318b995cffcf drm: Replace old pointer to new idr
  • d31c6b334215 drm/loongson: Use managed KMS polling
  • 97a05b0ae9ea smb/client: fix possible infinite loop and oob read in symlink_data()
  • 0ea9d6e036be nvme-apple: Reset q->sq_tail during queue init
  • 527cb4a55155 Bluetooth: btmtk: accept too short WMT FUNC_CTRL events
  • 151cfe527f0a media: staging: imx: configure src_mux in csi_start
  • 7c96f2e5b6fb ata: libata-scsi: fix requeue of deferred ATA PASS-THROUGH commands
  • d92229dfa3f9 fuse: avoid 0x10 fault in fuse_readahead when max_pages == 0
  • 3ab135238832 HID: core: Fix size_t specifier in hid_report_raw_event()
  • 301338b8edad HID: core: introduce hid_safe_input_report()
  • 509c26050650 HID: pass the buffer size to hid_report_raw_event
  • 8adc988e9f20 KVM: x86: Fix Xen hypercall tracepoint argument assignment
  • b22a2da8792a KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic
  • 0d419c23bb11 KVM: Reject wrapped offset in kvm_reset_dirty_gfn()
  • d9017d233258 audit: enforce AUDIT_LOCKED for AUDIT_TRIM and AUDIT_MAKE_EQUIV
  • e029cbd8c06d net: atlantic: preserve PCI wake-from-D3 on shutdown when WOL enabled
  • 1dced0725e2f netfilter: nft_ct: fix missing expect put in obj eval
  • a9f76de38ba3 Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn"
  • 722b91d5086a idpf: fix double free and use-after-free in aux device error paths
  • c4a8998aafb8 cgroup/dmem: Return -ENOMEM on failed pool preallocation
  • bddf59818ae5 net: ena: PHC: Check return code before setting timestamp output
  • e35f3550c5b4 audit: fix incorrect inheritable capability in CAPSET records
  • 430b05f6c918 netfilter: nf_conntrack_sip: get helper before allocating expectation
  • 95e8ae9af2a6 net: ena: PHC: Fix potential use-after-free in get_timestamp
  • 10addc25fa17 workqueue: Fix wq->cpu_pwq leak in alloc_and_link_pwqs() WQ_UNBOUND path
  • f43240068791 i40e: Cleanup PTP pins on probe failure
  • a1c5672faf8e crypto: af_alg - Cap AEAD AD length to 0x80000000
  • b4e1c03b876c sched/fair: Revert force wakeup preemption
  • ec4f6da3373d sched/fair: Fix wakeup_preempt_fair() for not waking up task
  • ce8ac8432fd7 net: mana: Init gf_stats_work before potential error paths in probe
  • 45d6c6c10b8b net: mana: Fix use-after-free in reset service rescan path
  • 80c025618524 net: airoha: Fix VIP configuration for AN7583 SoC
  • 81a2a3607866 net: airoha: Use gdm port enum value whenever possible
  • 106581064439 net: airoha: Remove code duplication in airoha_regs.h
  • db9af8a2efad net/sched: sch_pie: annotate more data-races in pie_dump_stats()
  • 90619fdedfb9 net: airoha: Move ndesc initialization at end of airoha_qdma_init_tx()
  • 7645ead02939 net: airoha: Move entries to queue head in case of DMA mapping failure in airoha_dev_xmit()
  • 95fdee73c39c rtla: Fix parse_cpu_set() bug introduced by strtoi()
  • 26b4ea23f511 net: airoha: Fix a copy and paste bug in probe()
  • dbbd60129f79 bpf: Fix sync_linked_regs regarding BPF_ADD_CONST32 zext propagation
  • 22f72b1dccfe PCI: Initialize temporary device in new_id_store()
  • 735439394dde Revert "papr-hvpipe: convert papr_hvpipe_dev_create_handle() to FD_PREPARE()"
  • d66dc9505935 Revert "pseries/papr-hvpipe: Fix race with interrupt handler"
  • 1dcd36420af2 futex: Drop CLONE_THREAD requirement for private default hash alloc
  • dcb89deed40b arm64: Reserve an extra page for early kernel mapping
  • b9d854388988 kselftest/arm64: Include <asm/ptrace.h> for user_gcs definition
  • 5704a90c0970 net/sched: cls_flower: revert unintended changes
  • 3f4a3f740c23 sfc: fix error code in efx_devlink_info_running_versions()
  • 9c54e76f8d6e net: tls: fix strparser anchor skb leak on offload RX setup failure
  • f5c5692a61f7 ice: add dpll peer notification for paired SMA and U.FL pins
  • f5f1b59bdb12 dpll: export __dpll_pin_change_ntf() for use under dpll_lock
  • 47e53940451c dpll: Add notifier chain for dpll events
  • 8bcfd78bbc32 dpll: Allow associating dpll pin with a firmware node
  • a723643ee055 ice: fix missing dpll notifications for SW pins
  • 3b3aab57e33f ice: fix SMA and U.FL pin state changes affecting paired pin
  • 0c56810ce1ba ice: fix missing SMA pin initialization in DPLL subsystem
  • c3cad2ae8088 ice: fix infinite recursion in ice_cfg_tx_topo via ice_init_dev_hw
  • 1e9185b13ce5 ice: fix NULL pointer dereference in ice_reset_all_vfs()
  • b166453d8d01 iavf: add VIRTCHNL_OP_ADD_VLAN to success completion handler
  • e469b1ff3319 iavf: wait for PF confirmation before removing VLAN filters
  • b0173c36977c iavf: stop removing VLAN filters from PF on interface down
  • 033fa40dff77 iavf: rename IAVF_VLAN_IS_NEW to IAVF_VLAN_ADDING
  • 864577384d72 page_pool: fix memory-provider leak in page_pool_create_percpu() error path
  • c169c5837525 bonding: 3ad: implement proper RCU rules for port->aggregator
  • f2edb41645bf bonding: print churn state via netlink
  • c1e0b5eccdf0 net: airoha: Do not return err in ndo_stop() callback
  • aaad53a55812 net: airoha: fix BQL imbalance in TX path
  • d1469eb93af7 drm/xe/gsc: Fix BO leak on error in query_compatibility_version()
  • bebce43f34b5 drm/xe/eustall: Fix drm_dev_put called before stream disable in close
  • 753b149d5a43 drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl()
  • 2d8656c27ff6 drm/xe/debugfs: Correct printing of register whitelist ranges
  • 8b85ffe52052 drm/amd/display: Read EDID from VBIOS embedded panel info
  • 07822f1d9bdb drm/amd/display: Allow constructing DCE8 link encoder without DDC
  • e0f874f209d4 drm/amd/display: Allow constructing DCE6 link encoder without DDC
  • 9b84d67ce8c9 drm/amd/display: Allow DCE link encoder without AUX registers
  • 69a7cfc66405 futex: Prevent lockup in requeue-PI during signal/ timeout wakeup
  • 24c22c644ea5 ALSA: hda/tas2781: Fix incorrect bit update for non-book-zero or book 0 pages >1
  • 7e6f7ac79abe ALSA: hda: cs35l56: Fix uninitialized value in cs35l56_hda_read_acpi()
  • f837c7b85143 ALSA: hda/conexant: Fix missing error check for jack detection
  • 47984e9db9ca netconsole: propagate device name truncation in dev_name_store()
  • b19a6804d498 net/sched: sch_cake: annotate data-races in cake_dump_stats() (V)
  • cd0401593b2d net/sched: sch_cake: annotate data-races in cake_dump_stats() (III)
  • 74a02921c48f bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst()

View originalPermalink
How 6.18.38-rt-xanmod1 went

6.18.38-xanmod1

Fixed 20
  • AppArmor: advertise the TCP fast open fix is applied
  • Fix use-after-free of key in TCP-AO del_async path
  • Serial 8250_dw: unregister 8250 port if clk_notifier_register() fails
  • ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
  • NFS: prevent resource leak in nfs_alloc_server()
  • NFSv4: clear exception state on successful mkdir retry

From XanMod Kernel

  • e67923a55781 Linux 6.18.38-xanmod1
  • 82e2790add06 Merge tag 'v6.18.38' into 6.18
  • e46dc0adfe39 Linux 6.18.38
  • 92c63a5ef3c7 apparmor: advertise the tcp fast open fix is applied
  • e77fbefd1269 net/tcp-ao: fix use-after-free of key in del_async path
  • 3d205fe80f21 serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
  • 7627ff8c4f99 ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
  • 62c26720121b NFS: Prevent resource leak in nfs_alloc_server()
  • 6919eb549e8f NFSv4: clear exception state on successful mkdir retry
  • 012d37a568bf NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
  • d8c90c7cc061 NFSv4/flexfiles: reject zero filehandle version count
  • 4367afc119c5 nfsd: reset write verifier on deferred writeback errors
  • 017a6150106b nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
  • 0f28337f54cf nfsd: check get_user() return when reading princhashlen
  • dba7da4835de nfsd: fix inverted cp_ttl check in async copy reaper
  • 136b416593f1 nfsd: fix posix_acl leak on SETACL decode failure
  • c8a24effd96d NFSD: Fix SECINFO_NO_NAME decode error cleanup
  • 6a946038f2a5 i2c: core: fix adapter registration race
  • fc6aa9bdbae6 fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
  • 4d418cf8daf5 fbdev: modedb: fix a possible UAF in fb_find_mode()
  • eea16b6f805c fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
  • 7643e5622994 riscv: kfence: Call mark_new_valid_map() for kfence_unprotect()
  • 3b33dbb43e21 riscv: mm: Extract helper mark_new_valid_map()
  • 2205275be9be power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()
  • 720949ed666f KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
  • e36095d8d922 KVM: x86: hyper-v: Bound the bank index when querying sparse banks
  • f9b57a0015c2 MIPS: smp: report dying CPU to RCU in stop_this_cpu()
  • 6dbe9443d9f5 9p: avoid putting oldfid in p9_client_walk() error path
  • 4cd57ebee395 ocfs2: reject oversized group bitmap descriptors
  • 104d10021239 rpmsg: char: Fix use-after-free on probe error path
  • 369496d885b4 fpga: region: fix use-after-free in child_regions_with_firmware()
  • b3a3831b2eb8 irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove
  • 200e7637f4d6 pNFS: Fix use-after-free in pnfs_update_layout()
  • 90e254f18b8c LoongArch: Report dying CPU to RCU in stop_this_cpu()
  • e18769616fd5 tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
  • 5e5b7f2ef854 blk-cgroup: fix UAF in __blkcg_rstat_flush()
  • 5a84398101bf hdlc_ppp: sync per-proto timers before freeing hdlc state
  • e91df6d27344 pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()
  • b85ef03f726b gfs2: fix use-after-free in gfs2_qd_dealloc
  • 8d8507a45766 crypto: nx - fix nx_crypto_ctx_exit argument
  • 5da9b1a87ec7 KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()
  • 18587f983161 KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
  • adfacfbaeae2 exfat: fix potential use-after-free in exfat_find_dir_entry()
  • 6e61fc2e06e4 MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
  • 65bd0c0afb0e bpf: use kvfree() for replaced sysctl write buffer
  • 3804e6de30ae block: Avoid mounting the bdev pseudo-filesystem in userspace
  • db2c5b9fb908 f2fs: keep atomic write retry from zeroing original data
  • 20190e498057 f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
  • ff83de56882c f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
  • 888d94cc9afb f2fs: fix to round down start offset of fallocate for pin file
  • 77f216ff9ce5 f2fs: validate compress cache inode only when enabled
  • 8aad54746c25 f2fs: validate orphan inode entry count
  • 1e48fefac682 f2fs: pass correct iostat type for single node writes
  • 1de92789ce31 wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
  • b0b07e04f0c7 wifi: iwlwifi: mld: fix race condition in PTP removal
  • df626f284cb9 wifi: iwlwifi: mvm: fix race condition in PTP removal
  • 200d58c851b8 wifi: rtw88: usb: fix memory leaks on USB write failures
  • 73d427d271f7 wifi: rtw88: increase TX report timeout to fix race condition
  • 0aeb4d3ff6ce wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor
  • 40aa3c2b0cb8 wifi: ath11k: fix warning when unbinding
  • a7cdc384c9c5 wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer
  • 7e25b5e22c1f wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S
  • ec1c9e896255 userfaultfd: ensure mremap_userfaultfd_fail() releases mmap_changing
  • 7216ce8cb12f keys: Pin request_key_auth payload in instantiate paths
  • b11c1fa32667 KEYS: fix overflow in keyctl_pkey_params_get_2()
  • 49d893b9cbcf gcov: use atomic counter updates to fix concurrent access crashes
  • 2b7ec7278609 err.h: use __always_inline on all error pointer helpers
  • 1fcca1260c6e KVM: arm64: Omit tag sync on stage-2 mappings of the zero page
  • 97e1044e79c5 block: invalidate cached plug timestamp after task switch
  • 99e6c712cc30 kernel/fork: clear PF_BLOCK_TS in copy_process()
  • 0d35f9f194a8 fbdev: fix use-after-free in store_modes()
  • 81371dbd2360 NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR
  • c3ca2631073b apparmor: fix use-after-free in rawdata dedup loop
  • 4a69b83045d3 apparmor: mediate the implicit connect of TCP fast open sendmsg
  • 1697957eb097 net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
  • 1acdd14c0990 net: skmsg: preserve sg.copy across SG transforms
  • bd968bdd568b mac802154: llsec: add skb_cow_data() before in-place crypto
  • 0cfa78c05066 af_unix: Set gc_in_progress to true in unix_gc().
  • 3c499851753a wifi: mt76: add wcid publish check in mt76_sta_add
  • 5e658b9245a5 ntfs3: reject direct userspace writes to reserved $LX* xattrs
  • 77798d7be6ef ipv4: account for fraggap on the paged allocation path
  • 6374fb9edf72 ipv6: account for fraggap on the paged allocation path
  • 565ab66005b1 batman-adv: tvlv: avoid race of cifsnotfound handler state
  • 4cc9f7711bb8 batman-adv: tvlv: enforce 2-byte alignment
  • 04e1a6557fbf batman-adv: dat: prevent false sharing between VLANs
  • 3f82fc92cf52 batman-adv: tt: track roam count per VID
  • 3470d583fc65 batman-adv: tt: don't merge change entries with different VIDs
  • af5a069805f6 batman-adv: tp_meter: handle overlapping packets
  • d511c72a83dd batman-adv: tp_meter: prevent parallel modifications of last_recv
  • 1dafdd0794be batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE
  • 2233787658db batman-adv: tp_meter: restrict number of unacked list entries
  • 3d4548c96d6f batman-adv: v: prevent OGM aggregation on disabled hardif
  • 44ae137a2ace batman-adv: frag: avoid underflow of TTL
  • 116e94025f0f batman-adv: frag: ensure fragment is writable before modifying TTL
  • 0473ae882624 batman-adv: fix (m|b)cast csum after decrementing TTL
  • 49bf27fcd7ee batman-adv: ensure bcast is writable before modifying TTL
  • 646b68639c06 batman-adv: gw: don't deselect gateway with active hardif
  • 95a061f587b7 batman-adv: tp_meter: initialize last_recv_time during init
  • 75612c100a9e batman-adv: prevent ELP transmission interval underflow
  • 43733e5b525f batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE
  • 23d085bd6308 batman-adv: tp_meter: add only finished tp_vars to lists
  • b8bf8400e50c batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection
  • 1db02f3e315d batman-adv: tp_meter: fix fast recovery precondition
  • 7d2a44bc6bbe batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
  • 8e77fe0414f5 batman-adv: tp_meter: avoid window underflow
  • 7cb88d91d5f9 batman-adv: tp_meter: initialize dec_cwnd explicitly
  • 696c4cae872c batman-adv: tp_meter: initialize dup_acks explicitly
  • 1c5a1268418e batman-adv: tp_meter: keep unacked list in ascending ordered
  • e055e74b80eb lockd: fix TEST handling when not all permissions are available.
  • 671ec2eabb87 Revert "PCI: qcom: Advertise Hotplug Slot Capability with no Command Completion support"
  • d84470219839 selinux: fix overlayfs mmap() and mprotect() access checks
  • 5dfcb15974e7 lsm: add backing_file LSM hooks
  • 5e470998a23e KVM: x86: Fix shadow paging use-after-free due to unexpected role
View originalPermalink
How 6.18.38-xanmod1 went

7.1.2-xanmod1

Fixed 13
  • virtiofs: fix UAF on submount umount
  • media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
  • ksmbd: reject non-VALID session in compound request branch
  • drivers/base/memory: set mem->altmap after successful device registration
  • serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
  • serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero
Removed 1
  • crypto: qat - remove unused character device and IOCTLs

From XanMod Kernel

  • 74edfbf88678 Linux 7.1.2-xanmod1
  • 963a4a40216b Merge tag 'v7.1.2' into 7.1
  • 03e2778d1f11 Linux 7.1.2
  • e09412a714bc virtiofs: fix UAF on submount umount
  • 232e4b313ea3 media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
  • 5f983b864d3d ksmbd: reject non-VALID session in compound request branch
  • 059ac6252a63 drivers/base/memory: set mem->altmap after successful device registration
  • 778b9dda4b24 serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
  • ee6754f583a9 serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero
  • 09a43e81279b vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write
  • 3ae49dd04dbb crypto: qat - remove unused character device and IOCTLs
  • abd776ded3e2 iio: adc: ti-ads1298: add bounds check to pga_settings index
  • e545936e06f1 iio: light: veml6075: add bounds check to veml6075_it_ms index
  • cefe535a60a2 agp/amd64: Fix broken error propagation in agp_amd64_probe()
  • 613257f91906 Revert "NFSD: Defer sub-object cleanup in export put callbacks"
  • e28db6ac4792 fuse: re-lock request before replacing page cache folio
  • 7e00cafa33b5 io_uring/net: Avoid msghdr on op_connect/op_bind async data
View originalPermalink
How 7.1.2-xanmod1 went
View all

Discussion