What changed in XanMod Kernel from 6 to 7

13 releases numbered after 6.18.49-xanmod1 up to and including 7.2.3-xanmod1, stable releases only. 6.18.49-xanmod1 and 7.2.3-xanmod1 are the newest stable releases of 6 and 7 we track; this page follows them as new ones ship.

224 changes across 13 releases · 37 landed on more than one version

Added 17

7.2.0-xanmod1

  • Add sysctl to disallow unprivileged CLONE_NEWUSER by default
  • Enable overrides for missing ACS capabilities in PCI
  • Export file_close_fd() for use by modules
  • Allow __wake_up_pollfree() to be used from GPL modules
  • Add debug mask file for binder_alloc
  • Convert binder into a module
  • Expose controller board power in sysfs for Steam Deck
  • Add MFD core driver for Steam Deck
  • Add support for Steam Deck LED
  • Add support for max battery level and rate in Steam Deck hwmon
  • Add driver for Steam Deck's EC sensors
  • Add driver for Steam Deck extcon
  • Add xt_FLOWOFFLOAD target for netfilter
  • Add netfilter nf_tables fullcone support
  • Add sysctl to skip tcp collapse processing when receive buffer is full

7.1.8-xanmod1

  • media: chips-media: wave5: Support CBP profile

7.1.5-xanmod1

  • Add cancel helper for async requests in firmware_loader
Changed 30

7.2.3-xanmod1

  • usb: core: Strengthen error handling in hub_hub_status()also in7.1.13-xanmod1
  • usb: core: Add lock to usb_wakeup_notification()also in7.1.13-xanmod1
  • crypto: krb5: use kfree_sensitive() for derived key buffersalso in7.1.13-xanmod1

7.1.13-xanmod1

  • crypto: qcom-rng: Allow zero as a random number

7.1.10-xanmod1

  • Set GT rp min frequency as 1.2GHz default for BMG/CRI in drm/xe

7.2.0-xanmod1

  • Update TCP 'bbr' congestion control module to BBRv3also in7.1.5-xanmod1
  • Disable workqueues for crypto ops in dm-crypt
  • Use call_rcu when detaching client in input/evdev
  • Initialize ata before graphics
  • Improve rwsem spin performance
  • Enable stateless firmware loading
  • Accept connections in LIFO order for cache efficiency in sched/wait
  • Add working set protection for anon and clean file pages
  • Add 500Hz timer interrupt kernel config option
  • Set wbt_default_latency_nsec() to 2msec
  • Set rq_affinity to force complete I/O requests on same CPU
  • Disable front_merges by default in block/mq-deadline
  • Increase write priority in block/mq-deadline to improve responsiveness
  • Set scheduler tunable latencies to unscaled

7.1.8-xanmod1

  • drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse]
  • drm/xe: Set TTM device beneficial_order to 9 (2M)
  • drm/xe: Separate early xe_device initialization
  • drm/xe: Move xe->info.devid|revid initialization
  • drm/xe: Move xe->info.force_execlist initialization
  • drm/xe: Drop unused param from xe_device_create()
  • usb: typec: ucsi: split connector lock classes

7.1.6-xanmod1

  • net: mana: Optimize irq affinity for low vcpu configs

7.1.5-xanmod1

  • Wait for pre-firmware load in usb: atm: ueagle-atm .disconnect()
  • Remove function entry/exit debug messages from usb: atm: ueagle-atm
  • Use dev_dbg() for 'device found' message in usb: atm: ueagle-atm
Fixed 166

7.2.3-xanmod1

  • usb: usbfs: fix use-after-free of usb_device in usbdev_release()also in7.1.13-xanmod1
  • wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skbalso in7.1.13-xanmod1
  • USB: c67x00: fix use-after-free in c67x00_add_iso_urb()also in7.1.13-xanmod1
  • USB: serial: option: fix slab OOB read in interrupt URB callbackalso in7.1.13-xanmod1
  • ALSA: usb-audio: Complete cleanup after system-resume errorsalso in7.1.13-xanmod1
  • ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()also in7.1.13-xanmod1
  • ALSA: usb-audio: Fix sample rates for PreSonus AudioBox USBalso in7.1.13-xanmod1
  • KVM: s390: vsie: zero stale crypto bitsalso in7.1.13-xanmod1
  • crypto: mxs-dcp: fix source scatterlist length accessalso in7.1.13-xanmod1
  • crypto: iaa: fall back to software for multi-entry scatterlistsalso in7.1.13-xanmod1
  • crypto: qce: fix CCM AAD buffer underallocationalso in7.1.13-xanmod1
  • crypto: atmel-tdes: use scatterlist length before DMA mappingalso in7.1.13-xanmod1

7.2.1-xanmod1

  • ptp: vmclock: prevent read-only mappings from becoming writablealso in7.1.11-xanmod1
  • futex: Fix might_sleep() warning in futex_pivot_pending()
  • Bluetooth: hci_aml: validate firmware segment lengthsalso in7.1.11-xanmod1
  • Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255also in7.1.11-xanmod1
  • Bluetooth: ISO: zero the sockaddr before returning it in getnamealso in7.1.11-xanmod1
  • Bluetooth: ISO: do not force BT_LISTEN after a failed BIG syncalso in7.1.11-xanmod1
  • Bluetooth: hci_sync: Fix accept list UAF during suspendalso in7.1.11-xanmod1
  • Bluetooth: hci_event: validate LE Set CIG Parameters responsealso in7.1.11-xanmod1
  • Bluetooth: hci_event: fix LE list UAF on resetalso in7.1.11-xanmod1
  • HID: input: read battery capacity from its actual report offsetalso in7.1.11-xanmod1
  • HID: hyperv: validate initial device info boundsalso in7.1.11-xanmod1
  • HID: uclogic: fix use-after-free of inrange_timer on removealso in7.1.11-xanmod1
  • HID: sensor: custom: Fix use-after-free in enable_sensoralso in7.1.11-xanmod1
  • HID: ft260: fix stack-use-after-return write in I2C read racealso in7.1.11-xanmod1
  • HID: core: fix number/pointer type confusion on long itemsalso in7.1.11-xanmod1
  • HID: rapoo: fix missing hid_is_usb() checkalso in7.1.11-xanmod1
  • HID: nintendo: stop device IO before hid_hw_stop on probe failurealso in7.1.11-xanmod1
  • HID: nintendo: register input device after capabilities are setalso in7.1.11-xanmod1
  • HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()also in7.1.11-xanmod1
  • HID: huawei: fix missing hid_is_usb() checkalso in7.1.11-xanmod1

7.1.11-xanmod1

  • futex: Avoid private hash use-after-free on final put

7.1.10-xanmod1

  • Enable headset mic on F+ FLAPTOP r
  • Fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms
  • Mark SPI virtio device ready before registering the controller
  • Fix infinite loop when scale is too large for display in drm/log
  • Fix out-of-bounds read on empty message length in drm/log
  • Fix division by zero when scale module parameter is 0 in drm/log
  • Fix bug in pc_adjust_freq_bounds() in drm/xe
  • Check managed mutex initialization errors in drm/xe/oa
  • Fix sync entry leak on OA config emit failure in drm/xe/oa
  • Add termination on resume in drm/xe/pxp
  • Fix NULL pointer dereference in ar_context_release in firewire ohci
  • Fix tunnel and session refcount leak on seq_file release in l2tp
  • Reject dev-bound BPF programs bound to a different device in cls_bpf
  • Skip unmapped range in aie2_populate_range() in accel/amdxdna
  • Fix port_id extraction from SRC TAG in am65-cpsw-nuss
  • Don't call an unset readable_reg callback in regmap sdw-mbq
  • Define NR_CPUS to 1 on m68k
  • Reject allocations through dead ancestor pid namespaces
  • Skip hash tables in u32_bind_class() in cls_u32

7.1.9-xanmod1

  • thunderbolt: Fix bandwidth group reservation indexing
  • thunderbolt: Bound the DROM dual link port number before indexing sw->ports
  • sctp: clear new_transport when removing a peer
  • sctp: fix use-after-free of cached ASCONF chunk
  • sctp: keep chunk->transport in step with the list it is queued on
  • scsi: scsi_debug: Negate wrapped memcmp() result
  • bpf, sockmap: Fix sk_redir use-after-free in send verdict
  • fsverity: Fix silent truncation in bpf_get_fsverity_digest()
  • fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions
  • mm/filemap: __filemap_add_folio() restore index before retrying
  • ima: Instantiate file_truncate and path_truncate hooks
  • sched_ext: Take cgroup_lock() first in scx_cgroup_lock()
  • sched/psi: Create the psimon kthread outside of cgroup_mutex
  • sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
  • fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()
  • fs,fsverity: remove check for fsverity being enabled in setattr_prepare()
  • ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
  • ipv6: fix Route Information option length validation
  • mm/ptdump: always stabilise against page table freeing using init_mm
  • mm/page_table_check: skip special zero mappings

7.1.8-xanmod1

  • usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path
  • drm/amd/display: Exit idle optimizations before programming
  • drm/amd/display: check GRPH_FLIP status before sending event
  • drm/xe: Wait on external BO kernel fences in exec IOCTL
  • usb: typec: ucsi: Fix race condition and ordering in port unregistration
  • drm/xe/rtp: Ensure locking/ref counting for OA whitelists
  • drm/vmwgfx: validate external BO copy bounds for both stride paths
  • drm/vmwgfx: enforce cursor size limits for MOB cursors
  • drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure
  • drm/amdkfd: hold event_mutex while checkpointing CRIU events
  • drm/amdkfd: fix QID bit leak in pqm_create_queue()

7.1.6-xanmod1

  • cifs: fix time_last_write stamp placement in setattr/truncate paths
  • KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug
  • bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline()
  • mm/sparse-vmemmap: fix DAX vmemmap accounting with optimization
  • xfs: don't replace the wrong part of the cow fork
  • fuse-uring: fix race between registration and connection abortion
  • audit: fix recursive locking deadlock in audit_dupe_exe()
  • drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources
  • ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL
  • drm/amdgpu: fix aperture mapping leak
  • drm/amdgpu: reject mapping a reserved doorbell to a new queue
  • drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
  • drm/amdgpu: fix resource leak on ACP reset timeout
  • drm/amdgpu: Fix kernel panic during driver load failure
  • drm/amdgpu: fix division by zero with invalid uvd dimensions
  • vxlan: mdb: Fix source list corruption on a failed replace

7.1.5-xanmod1

  • Prevent UAF caused by non-leader exec() race in posix-cpu-timers
  • Fix Color Manager (3DLUT, Shaper, Blend) in drm/amd/display
  • Fix implicit declaration of brelse() in exfat
  • Validate session type before performing operation in liveupdate
  • Add newly added RTGs to the free pool in xfs growfs
  • Use opener credentials for FSCTL mutations in ksmbd
  • Fix path resolution in ksmbd_vfs_kern_path_create
  • Fix use-after-free in l2cap_sock_new_connection_cb() in Bluetooth L2CAP
  • Fix cyclic locking warning on netdev unregister in Bluetooth 6lowpan
  • Cache secctx size before release zeroes it in binder
  • Cancel async firmware request at unbind in ALSA: hda/tas2781
  • Update offsets for 2i2 Gen 4 firmware 2417 in ALSA: scarlett2
  • Fix stale or zero output when reading raw values in iio: hid-sensor-rotation
  • Fix listxattr handling of corrupted xattr entries in f2fs

7.1.4-xanmod1

  • xfs: use rtrefcount btree cursor in xchk_xref_is_rt_cow_staging
  • xfs: write the rg superblock when fixing it
  • xfs: fix off-by-one error when calling xchk_xref_has_rt_owner
  • xfs: don't zap bmbt forks if they are MAXLEVELS tall
  • xfs: fully check the parent handle when it points to the rootdir
  • xfs: clamp timestamp nanoseconds correctly
  • xfs: handle non-inode owners for rtrmap record checking
  • xfs: set xfarray killable sort correctly
  • xfs: use the rt version of the cow staging checker
  • xfs: grab rtrmap btree when checking rgsuper
  • xfs: don't wrap around quota ids in dqiterate
  • xfs: resample the data fork mapping after cycling ILOCK
  • xfs: fail recovery on a committed log item with no regions
  • xfs: fix null pointer dereference in tracepoint
  • smb: client: reject overlapping data areas in SMB2 responses
  • Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev
  • timekeeping: Register default clocksource before taking tk_core.lock
  • fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref
  • fuse-uring: make a fuse_req on SQE commit only findable after memcpy
  • fuse-uring: Avoid queue->stopped races and set/read that value under lock

7.1.3-xanmod1

  • apparmor: advertise the tcp fast open fix is applied
  • net/tcp-ao: fix use-after-free of key in del_async path
  • ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
  • NFS: Prevent resource leak in nfs_alloc_server()
  • NFSv4: clear exception state on successful mkdir retry
  • NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
  • NFSv4/flexfiles: reject zero filehandle version count
  • nfsd: reset write verifier on deferred writeback errors
  • nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
  • nfsd: fix dead ACL conflict guard in nfsd4_create
  • nfsd: check get_user() return when reading princhashlen
  • nfsd: fix posix_acl leak and ignored error in nfsd4_create_file
  • nfsd: fix inverted cp_ttl check in async copy reaper
  • nfsd: fix posix_acl leak on SETACL decode failure
  • NFSD: Fix SECINFO_NO_NAME decode error cleanup
  • nfsd: release layout stid on setlease failure
  • i2c: core: fix adapter registration race
  • fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
  • fbdev: modedb: fix a possible UAF in fb_find_mode()
  • fbdev: omap2: fix use-after-free in omapfb_mmap

7.1.2-xanmod1

  • virtiofs: fix UAF on submount umount
  • media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
  • ksmbd: reject non-VALID session in compound request branch
  • drivers/base/memory: set mem->altmap after successful device registration
  • serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
  • serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero
  • vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write
  • iio: adc: ti-ads1298: add bounds check to pga_settings index
  • iio: light: veml6075: add bounds check to veml6075_it_ms index
  • agp/amd64: Fix broken error propagation in agp_amd64_probe()
  • Revert NFSD: Defer sub-object cleanup in export put callbacks
  • fuse: re-lock request before replacing page cache folio
  • io_uring/net: Avoid msghdr on op_connect/op_bind async data
Removed 7

7.2.3-xanmod1

  • USB: serial: spcp8x5: drop broken carrier detect supportalso in7.1.13-xanmod1
  • crypto: qce: Remove unsafe/deprecated algorithmsalso in7.1.13-xanmod1
  • crypto: sun8i-ss: Remove crypto_rng interface
  • crypto: sun8i-ce: Remove crypto_rng interface

7.1.13-xanmod1

  • crypto: qcom-rng: Remove crypto_rng interface

7.1.5-xanmod1

  • Remove crypto_rng interface from crypto: xilinx-trng

7.1.2-xanmod1

  • crypto: qat - remove unused character device and IOCTLs
Security 4

7.1.8-xanmod1

  • drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE

7.1.6-xanmod1

  • ksmbd: validate ACE size against SID sub-authorities
  • ksmbd: bound DACL dedup walk to copied ACEs
  • ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl

Original release notes, newest first

The list above is our reading of these notes; the originals from XanMod are here, one fold per release.

7.2.3-xanmod1
  • 3b1e0e296cd6 Linux 7.2.3-xanmod1
  • a981f4bbb87f Merge tag 'v7.2.3' into 7.2
  • 58e7295cfeca Linux 7.2.3
  • 47a7f98fbb50 usb: usbfs: fix use-after-free of usb_device in usbdev_release()
  • e5e8fc11a7ac wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb
  • f24dcc61bd0e USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
  • 3720311fa519 USB: serial: spcp8x5: drop broken carrier detect support
  • d762aef4eba3 USB: serial: option: fix slab OOB read in interrupt URB callback
  • d1f643b1c025 ALSA: usb-audio: Complete cleanup after system-resume errors
  • 1074c2306901 ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
  • 8bf1cdb6d05c ALSA: usb-audio: Fix sample rates for PreSonus AudioBox USB
  • b471594da637 usb: core: Strengthen error handling in hub_hub_status()
  • 7c48aa0c1e79 usb: core: Add lock to usb_wakeup_notification()
  • 29b4f7bc2991 KVM: s390: vsie: zero stale crypto bits
  • 8cbd1539e00d crypto: qce - Remove unsafe/deprecated algorithms
  • 6ef9a4afb52c crypto: mxs-dcp - fix source scatterlist length access
  • 516a830e2f47 crypto: iaa - fall back to software for multi-entry scatterlists
  • 4839f4c21f9c crypto: qce - fix CCM AAD buffer underallocation
  • a1bf79365794 crypto: krb5 - use kfree_sensitive() for derived key buffers
  • 0dd2f638877a crypto: atmel-tdes - use scatterlist length before DMA mapping
  • 8ab58786b4c6 crypto: sun8i-ss - Remove crypto_rng interface
  • 1017f987c5f0 crypto: sun8i-ce - Remove crypto_rng interface
  • 3c7101cfc52e crypto: qcom-rng - Allow zero as a random number
  • 669d940351ed crypto: qcom-rng - Remove crypto_rng interface
  • b1d62624a13c crypto: qcom-rng - Enable clock in hwrng case
  • 1f9f877b1ef1 crypto: virtio - bound the akcipher result length
  • 8b9a857fcf32 kunit: irq: Continue increasing hrtimer interval for longer
  • 9b74e5633687 mm/swap: reject swapon() on filesystem-level encrypted files
  • 68de7f3a38ac netfilter: nf_tables: don't queue packet path object notifications
  • fbfa5944d221 netfilter: nft_set_pipapo_avx2: add missing vzeroupper
  • 4bbc76ee1b21 vxlan: keep the last remote linked during FDB flush
  • 2b46baa591d0 batman-adv: reject unrepresentable multicast TVLV offsets
  • f4be3b391265 ipv6: seg6: clear IPv4 control block on IPIP decapsulation
  • 550d00aa5819 net/packet: defer vmalloc TX_RING free until skbs finish
  • a29f3b884ba5 vlan: fix skb_under_panic and races when toggling HW VLAN offload
  • 57f94d3f4dee net: bridge: mcast: fix use-after-free of a master VLAN's multicast context
  • 3921c573d1ca xfrm: bound nat keepalive state collection
  • be19d20e53a2 xfrm: fix xfrm_state_construct() auth-trunc leak
  • 46640c814f25 xfrm: ah6: validate routing header segments_left
  • a9fa05b7a124 xfrm: avoid lock inversion in nat keepalive work
  • 943d95233b8b xfrm: drop ESP-in-TCP packets with no ingress device
  • 31cf23493619 tcp: clamp route advmss to TCP_MIN_MSS
  • 54b41ad14da9 xfrm: espintcp: fix UAF during close
  • 713ed6ce111e net: advertise TCP MSS from the configured MTU, not the learned PMTU
  • 2857dcbd03cf net/tcp-ao: fix use-after-free of current_key on reconnect to another peer
  • d17e88b6b60f tcp: fix AO info use-after-free in tcp_ao_connect_init()
  • a742178889f9 net/tcp: fix TCP-AO key deletion in VRFs
  • 1e995498d297 gtp: serialize PDP context updates
  • 7e1208c13561 tls: device: fix out-of-bounds write in tls_append_frag()
  • 60e5acbffcd4 KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if CONFIG_KVM_AMD_SEV=y
  • 6d989a0e2df2 KVM: SEV: Mark vCPU RUNNABLE after AP_CREATE, even if VMSA is unusable
  • 68a34115a423 KVM: SEV: Extract loading of guest-provided VMSA to a separate helper
  • 7813da74c6d3 KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests
  • c79c113b299b KVM: SEV: Drop FOLL_WRITE for encrypted region registration
  • 97f6402f5950 KVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts
  • eaa96a8458f5 usb: gadget: f_tcm: keep port count until LUN teardown completes
  • c6e90336ed7d usb: usbtest: disable dynamic ID support
  • e981474d7bf1 fuse: fix invalidate lock leak on open O_TRUNC DAX failure
  • e8457ebfd77a fuse: fix invalidate lock leak on setattr writeback failure
  • 715cb86e33cd fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free
  • a1bb359c443d fuse: publish io-uring queues with release semantics
  • dd9c835709f4 fuse: fix missing barrier when checking io-uring readiness
  • 26fbe4bc3ef3 fuse: fix race between interrupt and resend
  • 57881714412d xhci: dbgtty: Fix unregister on tty_alloc_driver() failure
  • 0e469b94fbba xhci: dbgtty: Fix unregister on tty_register_driver() failure
  • 0b31744f70c5 usb: xhci: bail out of setup if the controller is inaccessible
  • ed3c2adb57b5 usb: xhci: Handle USB3 port events when there is one roothub
  • 87dbc3fa08fc usb: xhci: Handle bogus TRB pointers in Missed Service Error events
  • aa323ccbc0a5 accessibility: speakup: unregister tty ldisc on later init failures
  • 5b2d5447730d fpga: dfl: fme: add error handling
  • 5b4be35d0228 selftests/bpf: Fix test_maps sockmap failure
  • 6e4cf2815587 nvme-tcp: fix usage of page_frag_cache
  • d219e7a8eed3 RDMA/rxe: Fix OOB in free_rd_atomic_resources()
  • 60dfd47929cd RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
  • 52c36105f76e Linux 7.2.2
  • da857e448322 inet: frags: strip GSO state from fragments before reassembly

View originalPermalink

7.1.13-xanmod1
  • b553b3542801 Linux 7.1.13-xanmod1
  • 43ca95d8926c Merge tag 'v7.1.13' into 7.1
  • 81d3924095fd Linux 7.1.13
  • 7f0278e474c4 usb: usbfs: fix use-after-free of usb_device in usbdev_release()
  • 8d481f935889 wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb
  • 7983daa15998 USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
  • 6bfa6c003d16 USB: serial: spcp8x5: drop broken carrier detect support
  • a72a13c83a65 USB: serial: option: fix slab OOB read in interrupt URB callback
  • 6c94877b6bab ALSA: usb-audio: Complete cleanup after system-resume errors
  • 7f00dbddb51f ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
  • b7c47225d4e2 ALSA: usb-audio: Fix sample rates for PreSonus AudioBox USB
  • 3a607bf79f86 usb: core: Strengthen error handling in hub_hub_status()
  • 960ca456faf6 usb: core: Add lock to usb_wakeup_notification()
  • d4bcd2df6d0d KVM: s390: vsie: zero stale crypto bits
  • 14f8bdfc7ac9 crypto: qce - Remove unsafe/deprecated algorithms
  • 0e9edb108a63 crypto: mxs-dcp - fix source scatterlist length access
  • cec32be0dcbf crypto: iaa - fall back to software for multi-entry scatterlists
  • 46a84efe2dba crypto: qce - fix CCM AAD buffer underallocation
  • 91b96dc9cc25 crypto: krb5 - use kfree_sensitive() for derived key buffers
  • cd4dd09c3d2d crypto: atmel-tdes - use scatterlist length before DMA mapping
  • 143c74034a1c crypto: qcom-rng - Allow zero as a random number
  • 843e2bdaf8de crypto: qcom-rng - Remove crypto_rng interface
  • c3f6dd7ee8b2 crypto: qcom-rng - Enable clock in hwrng case
  • 3fda114a42f1 crypto: virtio - bound the akcipher result length
  • 4df26c3684a0 kunit: irq: Continue increasing hrtimer interval for longer
  • 1b0303ff6ec4 mm/swap: reject swapon() on filesystem-level encrypted files
  • e97e2d6d0b15 netfilter: nf_tables: don't queue packet path object notifications
  • d1893ebc5c85 netfilter: nft_set_pipapo_avx2: add missing vzeroupper
  • 8ba68fd6cdd1 vxlan: keep the last remote linked during FDB flush
  • 1b466746fe10 batman-adv: reject unrepresentable multicast TVLV offsets
  • bf1c1151560d ipv6: seg6: clear IPv4 control block on IPIP decapsulation
  • 0189dce07db2 net/packet: defer vmalloc TX_RING free until skbs finish
  • 3f4752996735 net: bridge: mcast: fix use-after-free of a master VLAN's multicast context
  • 505ac032a97c xfrm: bound nat keepalive state collection
  • 37426395cb90 xfrm: fix xfrm_state_construct() auth-trunc leak
  • 0bf11081ad37 xfrm: ah6: validate routing header segments_left
  • 89ef3a2e1e46 xfrm: avoid lock inversion in nat keepalive work
  • 7911e0236616 xfrm: drop ESP-in-TCP packets with no ingress device
  • 6b8c20bf6192 tcp: clamp route advmss to TCP_MIN_MSS
  • eb3bbf29c723 xfrm: espintcp: fix UAF during close
  • f19186bb71d0 net: advertise TCP MSS from the configured MTU, not the learned PMTU
  • e54ad693eddb net/tcp-ao: fix use-after-free of current_key on reconnect to another peer
  • 284d7fd0eec8 tcp: fix AO info use-after-free in tcp_ao_connect_init()
  • 38a28d5053a4 net/tcp: fix TCP-AO key deletion in VRFs
  • 6df4f05bc299 gtp: serialize PDP context updates
  • cd7e875b8959 tls: device: fix out-of-bounds write in tls_append_frag()
  • 8ee84f9b64fd KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if CONFIG_KVM_AMD_SEV=y
  • 9e2de3ee5720 KVM: SEV: Mark vCPU RUNNABLE after AP_CREATE, even if VMSA is unusable
  • 66c01137350b KVM: SEV: Extract loading of guest-provided VMSA to a separate helper
  • f24ff526fe1b KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests
  • 1c0bc4321d29 KVM: SEV: Drop FOLL_WRITE for encrypted region registration
  • bbd6aa311a9f usb: gadget: f_tcm: keep port count until LUN teardown completes
  • d2e0f9c96551 usb: usbtest: disable dynamic ID support
  • 1d3e701cda2f fuse: fix invalidate lock leak on open O_TRUNC DAX failure
  • dd278d954c0e fuse: fix invalidate lock leak on setattr writeback failure
  • e15f8bcaa5fa xhci: dbgtty: Fix unregister on tty_alloc_driver() failure
  • 33ed35ca6294 xhci: dbgtty: Fix unregister on tty_register_driver() failure
  • bf84c6b02649 usb: xhci: bail out of setup if the controller is inaccessible
  • ff4f51d0fe5a usb: xhci: Handle USB3 port events when there is one roothub
  • 766a3c7dddd9 usb: xhci: Handle bogus TRB pointers in Missed Service Error events
  • 6d39dff1705e accessibility: speakup: unregister tty ldisc on later init failures
  • b6c9ac95dc36 fpga: dfl: fme: add error handling
  • 0f23bfff6033 ext4: zero out whole block for clean edges in WRITE_ZEROES
  • 6cfbf7dea8a8 ext4: track partial-zero outcome per edge in ext4_zero_partial_blocks()
  • 2335e7f2cf44 ext4: write back partial-zeroed edges in WRITE_ZEROES
  • 3cc1c2d5fbd0 ext4: move partial block zeroing earlier in ext4_zero_range()
  • 7e9ff031a5bc ext4: protect WRITE_ZEROES written extents with orphan list
  • 41fab074d4a1 ext4: export converted block count from ext4_convert_unwritten_extents()
  • 30a5b97813db selinux: switch two allocations to use kzalloc_objs()
  • cd998a10d6c9 selinux: require a class's permission values to cover its permission count
  • a7f3d4f22d92 selinux: reject a permission value exceeding the class permission count
  • f1e4513e8f06 selinux: more strict policy parsing
  • 4b53bfa7cb19 selinux: use u16 for security classes
  • 6d810f75a312 Revert "selinux: reject a permission value exceeding the class permission count"
  • 0a9750263ffa nvme-tcp: fix usage of page_frag_cache
  • ec8fcaf354c1 KVM: x86/mmu: Check write tracking in all address spaces
  • 4e5f753e8c28 RDMA/rxe: Fix OOB in free_rd_atomic_resources()
  • d4cd32eb8bd2 RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
  • b66529dc933e bpf: reject overlarge global subprog argument sizes
  • badc4fe5a9c1 Linux 7.1.12
  • 69b73b74d9eb inet: frags: strip GSO state from fragments before reassembly

View originalPermalink

7.2.1-xanmod1
  • 87d7e154ade4 Linux 7.2.1-xanmod1
  • 2112ca3bf8a8 Merge tag 'v7.2.1' into 7.2
  • 458fbaaefba2 Linux 7.2.1
  • 2e596e7814ba ptp: vmclock: prevent read-only mappings from becoming writable
  • 33b959876913 futex: Fix might_sleep() warning in futex_pivot_pending()
  • 2763b8bcb504 Bluetooth: hci_aml: validate firmware segment lengths
  • 6e1c44878aa3 Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255
  • 190b719b787e Bluetooth: ISO: zero the sockaddr before returning it in getname
  • 9f59f461dcae Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync
  • 29c59212a507 Bluetooth: hci_sync: Fix accept list UAF during suspend
  • 6fc540e835dd Bluetooth: hci_event: validate LE Set CIG Parameters response
  • 25b05e3ce31d Bluetooth: hci_event: fix LE list UAF on reset
  • bf05f17b8439 HID: input: read battery capacity from its actual report offset
  • c894143c508a HID: hyperv: validate initial device info bounds
  • f13d0a00204b HID: uclogic: fix use-after-free of inrange_timer on remove
  • 7bb79a3cf45e HID: sensor: custom: Fix use-after-free in enable_sensor
  • 77832d8f1c81 HID: ft260: fix stack-use-after-return write in I2C read race
  • e542edada3f7 HID: core: fix number/pointer type confusion on long items
  • 49b6fd28fbcc HID: rapoo: fix missing hid_is_usb() check
  • 2e0d98dc8a6d HID: nintendo: stop device IO before hid_hw_stop on probe failure
  • 27dc4b8eadac HID: nintendo: register input device after capabilities are set
  • 34725ed4719d HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
  • 9acc2463991c HID: huawei: fix missing hid_is_usb() check
  • ee883906cf66 HID: asus: fix missing hid_is_usb() check
  • ea081b443551 net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
  • 86b63adfa5e1 HID: pidff: fix OOB write when hid->inputs is empty
  • cbcc0e8dea49 HID: core: fix OOB read of field->usage in hid_set_field()
  • 2ef16934e069 HID: magicmouse: do not keep a stale msc->input if no input is claimed
  • 753786a7e6f9 HID: magicmouse: re-enable multitouch after reset-resume
  • d095de37f78c HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
  • 8384a2e1a9ab HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C
  • 56a7b6a6880d nvmet: pci-epf: put CQ ref on create_cq mapping failure
  • cede8d285257 nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work()
  • 9b770e40bc00 nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations
  • d895e66628f9 nvmet-tcp: bound SGL data length before allocating command buffers
  • 94334ea92f4d nvmet-fc: fix invalid free in LS IOD error path
  • 1d6837d98bf9 nvmet-auth: zero the AUTH_RECEIVE response buffer
  • 3256d648211e dmaengine: fsl-edma: Add error handling for devm_kasprintf
  • b233e7836d98 mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()
  • 73a187384a8c ipv6: fix use-after-free in ip6_finish_output2()
  • c8a74adccaf0 ipv4: reject undersized MTUs in ip_do_fragment()
  • 7b079b904691 nfc: nci: free destination parameters when closing a connection
  • d6f743d3d388 nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
  • 129032c0616d nfc: nci: fix out-of-bounds write in nci_target_auto_activated()
  • f5c534b53f8c nfc: nci: add data_len bound checks to activation parameter extractors
  • f33cecf69095 nfc: st21nfca: validate ATR_REQ length against the received frame
  • e95beff58b38 nfc: pn533: purge fragmented skbs during cleanup
  • d3d90243393c nfc: llcp: reject PDUs shorter than the LLCP header
  • 875285a165fd nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
  • 0cfbdb0e13ab nfc: llcp: bound the connect_sn TLV walk to the skb
  • 953963b9ac5e nfc: microread: validate target discovery payload lengths
  • 1aa3fc769b0c nfc: fdp: bound the device-reported read length and fix an skb leak
  • 31aa28ed732f nfc: digital: clamp SENSF_RES length to the destination buffer
  • 4d00a39c6762 xfs: restore nofs context unconditionally in xfs_trans_roll
  • c35da2bac6f7 xfs: validate attr entry pointer before field access
  • 2207f26ce715 ext4: fix incorrect function call when initializing s_resgid
  • e27bae352158 ext4: don't enable DAX on new encrypted files
  • 759830cde824 ext4: propagate errors from fast commit range replay
  • 29c2844d67c5 ext4: avoid tail write_begin walk for uptodate folios
  • f2c382914901 ext4: clear error before retrying inode xattr space fallback
  • fbcfb75c20d7 nilfs2: reject invalid block index in GC ioctl
  • dbd4aea175ad ext4: stop retrying saturated xattr cache entries
  • f8c9a3ec36b4 kcov: fix data corruption and race conditions on PREEMPT_RT
  • a04b3afd4f02 null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows
  • 50f0cbec45b0 ocfs2: fix missing metadata reservation for large xattrs
  • 40b6ccf68731 io_uring: defer eventfd signaling when queued from a wakeup handler
  • 771f6258c068 io_uring/uring_cmd: don't skip completion for a synchronous multishot cmd
  • 3267d7c8ba51 io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec()
  • 1bc9d45ebb81 io_uring/io-wq: fix worker accounting when canceling creation callbacks
  • 7068d3587a64 io_uring/cmd: fix iovec leak when the async cmd is not recycled
  • 690b721b9595 ALSA: dummy: Check card index validity at probe
  • cd4f44ede070 io_uring/futex: only mark private futex waits as inflight
  • d6d24b858b63 io_uring/futex: don't mark futex wake requests as inflight
  • c4b4972d8edc futex: Fix race on the initial mm->futex.phash.ref allocation
  • 25408c62ed4e futex: Avoid private hash use-after-free on final put
  • d7944cee62ec futex/pi: Plug private futex exec() race
  • 72fd9cbbe0cf futex: Sanitize and document task_struct::futex::state transitions
  • 43b148d796aa futex/pi: Reject cross-mm private futex owners
  • 123d664ac98d nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()
  • 2ded89ca77fa rndis_host: add overflow check in rndis_rx_fixup()
  • ecd2f83a4ddc ALSA: scarlett2: Use a private URB for the notification endpoint
  • 6db3c1d7e287 ALSA: FCP: Use a private URB for the notification endpoint
  • ffe6d379be20 iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages
  • 5994617e09ee iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown
  • b405c2f96ae2 Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept
  • 0916948026f6 PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems

View originalPermalink

7.1.11-xanmod1
  • 15d529e612cf Linux 7.1.11-xanmod1
  • 11c2a2475860 Merge tag 'v7.1.11' into 7.1
  • 843fd19fe9a2 Linux 7.1.11
  • 2496e1418271 ptp: vmclock: prevent read-only mappings from becoming writable
  • 12cd315a7b6a futex: Avoid private hash use-after-free on final put
  • 6c7025346290 Bluetooth: hci_aml: validate firmware segment lengths
  • 0bd0195ce257 Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255
  • 9069be87c67f Bluetooth: ISO: zero the sockaddr before returning it in getname
  • 2941716c753a Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync
  • 95bb57bc11a9 Bluetooth: hci_sync: Fix accept list UAF during suspend
  • d83ecb7b9610 Bluetooth: hci_event: validate LE Set CIG Parameters response
  • b55e83a4ba31 Bluetooth: hci_event: fix LE list UAF on reset
  • b81edc5df6b6 HID: input: read battery capacity from its actual report offset
  • 2529737763cb HID: hyperv: validate initial device info bounds
  • f1b3ca063805 HID: uclogic: fix use-after-free of inrange_timer on remove
  • c0757f106105 HID: sensor: custom: Fix use-after-free in enable_sensor
  • d7ffbdc07667 HID: ft260: fix stack-use-after-return write in I2C read race
  • e60159f5ea60 HID: core: fix number/pointer type confusion on long items
  • 99ed3febafe0 HID: rapoo: fix missing hid_is_usb() check
  • 13a3edf96568 HID: nintendo: stop device IO before hid_hw_stop on probe failure
  • a9fc7547f911 HID: nintendo: register input device after capabilities are set
  • d4cabd4089ad HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
  • 66805454c01f HID: huawei: fix missing hid_is_usb() check
  • 1ddc2f5913be HID: asus: fix missing hid_is_usb() check
  • 36e6dc9f9cae futex: Fix might_sleep() warning in futex_pivot_pending()
  • ff252ed45c82 futex: Fix race on the initial mm->futex.phash.ref allocation
  • 19b4be0717fa futex: Fix race in futex_pivot_pending() during private hash resize
  • 0478bc6bf197 futex/pi: Plug private futex exec() race
  • 19702d0396ee futex: Sanitize and document task_struct::futex::state transitions
  • f7fb3e077526 futex/pi: Reject cross-mm private futex owners
  • f3868046e8e2 net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
  • d416eeb7d016 HID: pidff: fix OOB write when hid->inputs is empty
  • 5215ea00a747 HID: core: fix OOB read of field->usage in hid_set_field()
  • 0bf253e9ac99 HID: magicmouse: do not keep a stale msc->input if no input is claimed
  • a8bdd9e22a84 HID: magicmouse: re-enable multitouch after reset-resume
  • a33a596d3ad8 HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
  • dcc8cf9414d1 HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C
  • 6c290915a03f mptcp: pm: fix memory leak from alloc-during-teardown race
  • ab8bae2403a7 mptcp: pm: uniform announced addresses helpers
  • 2c5fca4da0a5 mptcp: pm: rename add_entry structure to add_addr
  • 480560491a72 drm/amdgpu: Allocate coredump ring buffers per ring
  • 4e9b4dee0777 drm/amdgpu: fix recursive ww_mutex acquire in amdgpu_devcoredump_format
  • 26135631ed8e fbdev: serialize mode sysfs access with lock_fb_info()
  • 07f7e46833f7 fbdev: Wrap user-invoked calls to fb_set_var() in helper
  • b5f97fae2503 nvmet: pci-epf: put CQ ref on create_cq mapping failure
  • 1ed1eeaef55c nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work()
  • 7fd6da0f2893 nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations
  • 14dbe37681a6 nvmet-tcp: bound SGL data length before allocating command buffers
  • bb9489f0dce5 nvmet-fc: fix invalid free in LS IOD error path
  • 2dcc9226203d nvmet-auth: zero the AUTH_RECEIVE response buffer
  • 7494a167b958 dmaengine: fsl-edma: Add error handling for devm_kasprintf
  • df5c9816986b mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()
  • 99219c82804f ipv6: fix use-after-free in ip6_finish_output2()
  • 3556beb8ca86 ipv4: reject undersized MTUs in ip_do_fragment()
  • 7eae53335dba nfc: nci: free destination parameters when closing a connection
  • 5bd00c0e1470 nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
  • d7083f41c21b nfc: nci: fix out-of-bounds write in nci_target_auto_activated()
  • cf9d44be50b9 nfc: nci: add data_len bound checks to activation parameter extractors
  • 304f5b414f40 nfc: st21nfca: validate ATR_REQ length against the received frame
  • e7ed2ea5590f nfc: pn533: purge fragmented skbs during cleanup
  • ae5f20f5842f nfc: llcp: reject PDUs shorter than the LLCP header
  • e84cdfdc4a6c nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
  • 22e5177ba119 nfc: llcp: bound the connect_sn TLV walk to the skb
  • dabfa26a208e nfc: microread: validate target discovery payload lengths
  • e5eec121f2c3 nfc: fdp: bound the device-reported read length and fix an skb leak
  • a1ef9bddfbb3 nfc: digital: clamp SENSF_RES length to the destination buffer
  • c457e2c845cc drm/xe: Fix DPT allocation paths.
  • f2db6d8f09e7 drm/i915: Introduce struct intel_fb_pin_params
  • be01fcca9deb drm/i915: Track fence region ID in plane state
  • 504f06fab58e drm/i915/pin: s/dev_priv/i915/ and drop struct drm_device usage
  • b09198cf90cc xfs: restore nofs context unconditionally in xfs_trans_roll
  • 9f92e749fc08 xfs: validate attr entry pointer before field access
  • f09c28b8a212 ext4: fix incorrect function call when initializing s_resgid
  • 3392391b363a ext4: don't enable DAX on new encrypted files
  • 25cb98ef87c0 ext4: propagate errors from fast commit range replay
  • a11dedb18cd0 ext4: avoid tail write_begin walk for uptodate folios
  • 23171304c2ee ext4: clear error before retrying inode xattr space fallback
  • ec6ddf271dfa nilfs2: reject invalid block index in GC ioctl
  • 55ee6533c1db ext4: stop retrying saturated xattr cache entries
  • 22670d1552fe kcov: fix data corruption and race conditions on PREEMPT_RT
  • e7f9b40517f0 null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows
  • a3ccb57086dd ocfs2: fix missing metadata reservation for large xattrs
  • b6bb334b0e93 io_uring: defer eventfd signaling when queued from a wakeup handler
  • 2c937b7488d9 io_uring/uring_cmd: don't skip completion for a synchronous multishot cmd
  • 6b308c37fbeb io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec()
  • 0b0ba5369c26 io_uring/io-wq: fix worker accounting when canceling creation callbacks
  • b290de4d16d7 io_uring/cmd: fix iovec leak when the async cmd is not recycled
  • 3dba0e92e189 ALSA: dummy: Check card index validity at probe
  • 4849afbf11f4 io_uring/futex: only mark private futex waits as inflight
  • b64ad7cedce7 io_uring/futex: don't mark futex wake requests as inflight
  • 2bc1e33ff6a5 nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()
  • be7dc3650f79 rndis_host: add overflow check in rndis_rx_fixup()
  • 04df0232a697 ALSA: scarlett2: Use a private URB for the notification endpoint
  • 5da21a434171 ALSA: FCP: Use a private URB for the notification endpoint
  • d9635e2507dc iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages
  • a94309bb99ea iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown
  • 355bfd57ca4c Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept
  • a199293f3038 PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
  • 0fcf72d06689 xfs: rtsummary scrub should treat rtbitmap corruption errors as an xref error
  • e07800c65537 xfs: add a xchk_ip_set_corrupt helper
  • 56407a61a8bb xfs: don't livelock in scrub on a circular unlinked list
  • 1b744c1bd41f xfs: hoist per-bucket unlinked list check to helper

View originalPermalink

7.1.10-xanmod1
  • 0f1ac59df670 Linux 7.1.10-xanmod1
  • fc11d50c4815 Merge tag 'v7.1.10' into 7.1
  • 8d4e6356173a Linux 7.1.10
  • 93f4d99b7e06 ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r
  • d31639e0dd88 erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms
  • f07ab9771db5 spi: virtio: mark device ready before registering the controller
  • 50ca4dbbaf3e drm/log: Fix infinite loop when scale is too large for display
  • 16bcea56f420 drm/log: Fix out-of-bounds read on empty message length
  • 71ba3938cd57 drm/log: Fix division by zero when scale module parameter is 0
  • 1eea17a9184c drm/xe: Fix a bug in pc_adjust_freq_bounds()
  • e75b29f1d31c drm/xe: Set GT rp min frequency as 1.2GHz default for BMG/CRI
  • b3991da6ea98 drm/xe/oa: Check managed mutex initialization errors
  • 027150e24e17 drm/xe/oa: Fix sync entry leak on OA config emit failure
  • 24026a295e03 drm/xe/pxp: add termination on resume
  • 7d228ba43279 firewire: ohci: fix NULL pointer dereference in ar_context_release
  • ebe2774e9564 l2tp: fix tunnel and session refcount leak on seq_file release
  • 5685bbbd3cbf net/sched: cls_bpf: reject dev-bound programs bound to a different device
  • 499227ca8edc accel/amdxdna: Skip unmapped range in aie2_populate_range()
  • 914e0100df34 net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG
  • 5bd8e897ecf5 regmap: sdw-mbq: don't call an unset readable_reg callback
  • eb5ad008574d m68k: Define NR_CPUS to 1
  • d7c413bd421c pid: reject allocations through dead ancestor pid namespaces
  • e71f8e9ed6f3 net/sched: cls_u32: skip hash tables in u32_bind_class()
  • 6b70886ebc42 net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain
  • f09ac5682f1b af_packet: Don't send zero-byte data in tpacket_snd().
  • cc90447a7f79 regmap: sdw-mbq: Fix swap of timeout and retry times
  • 09e4c486348e ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers
  • 4b177911eb9f net/tls: Fail tls_sw_splice_read() after a failed async decrypt
  • 0ab482b2195e net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling
  • 88b79ac89ecc net: tap: fix wrong transport_header when sending VLAN-tagged frame
  • 6386a6ffa2ef net: packet: fix wrong transport_header when sending VLAN-tagged frame
  • fa8ceaae52d3 net: phy: realtek: fix EEE advertisement write on the internal PHY MMD path
  • 29633de25773 tcp: fix icsk_ack.ato bitfield overflow
  • 90bb11fb29d3 veth: fix queue index used to wake the peer txq in veth_poll
  • bc9a00fb78e3 macvlan: inherit needed_headroom and needed_tailroom from lowerdev
  • 5c2ca77212eb ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
  • 8b1118fc5a5d eth: bnxt: avoid deadlock when canceling IRQ affinity notifier
  • ae2e1c26082c eth: bnxt: decrease indent in bnxt_request_irq()
  • 2a64e5e75879 eth: bnxt: keep the aRFS rmap updated when TPH is enabled
  • 5f451cdb3f4e eth: bnxt: cancel IRQ notifier before freeing affinity mask
  • 0c60f26caca4 netfilter: ipset: let destroy callbacks adjust ext mem size
  • b88250102549 netfilter: ipset: fix list type element drift bug
  • d16b71231e65 netfilter: flowtable: publish GC-visible tuple last
  • c23620a0fa5b netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path
  • 5365f012451f ipvs: revalidate ihl to prevent out-of-bounds access
  • 24ffcb1e1688 netfilter: ipset: fix refcount race between list:set GC and swap
  • 8bfb93a35c9f tick: Include ktime.h and jiffies.h in linux/tick.h
  • f5bde482b242 ASoC: tas2781: fix clang build error for goto bypassing cleanup variable
  • 1eee6a92739a gpio: ml-ioh: share the register lock across channels
  • 8bbf4405050b rseq: Prevent hard lockup on granted time slice extension
  • 0f77ed5ee919 ovpn: defer key slot crypto freeing to workqueue
  • bbe81f40582d ovpn: run deferred work on a module-owned workqueue
  • e697e30f3dd2 riscv: lib: Fix ZBB strnlen reading past count boundary
  • 0663d1df8d28 ALSA: usb-audio: Fix mixer regression on SteelSeries Arctis Nova 5
  • 88619b117be1 sctp: validate cookie AUTH state before use
  • 7ce010275c53 perf: Reject exited events as group leaders
  • e83eed1bea14 scsi: core: pair EH runtime PM get and put
  • fe98491cb322 riscv: ftrace: Fix ftrace_modify_call failure on kprobed functions
  • 4b0de8be288f ovpn: finish crypto callback cleanup before peer release
  • acf32a5dff08 ovpn: fix NULL dereference when killing missing key
  • e3702470ced9 af_unix: Unlink scc_entry in unix_del_edge().
  • 92a959405383 regulator: fp9931: Fix VPOS/VNEG voltage selector table
  • d9daaca68ab9 gpiolib: Check gc->get_direction() before calling gpiod_get_direction()
  • 413be75118d1 rhashtable: fix false-positive lockdep splat on rhltable destruction
  • c6237834d999 crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req()
  • 3b8a9543801b crypto: ccm - Set rfc4309 maxauthsize from child
  • 487aa5391f91 arm64: tegra: Add EL2 virtual timer interrupt for Tegra194
  • bb81b608db63 clk: spacemit: k3: set hdma clock as critical
  • 294fd02f48c5 clk: spacemit: k3: fix USB2 bus clock
  • 94bf4fe0e463 optee: ffa: Add NULL check in optee_ffa_lend_protmem
  • 9114f72b9161 clk: qcom: dispcc-eliza: Fix disp_cc_mdss_mdp_clk_src RCG stall on Eliza EVK
  • 574498e56024 ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup
  • b0b98763cedb net: expect instance lock in netdev_queue_get_dma_dev()
  • 1be781e450c5 net: rename netdev_ops_assert_locked()
  • ca91e0cc8087 drm/amdkfd: Add bounds check for CRAT subtype length
  • 75db927187a1 drm/mediatek: mtk_dsi: Enable HS clock only at pre-enable
  • 6bd8d6b4eb51 drm/mediatek: Convert legacy DRM logging to drm_* helpers in mtk_dsi.c
  • c37a0461c0d0 ASoC: tas2562: Validate values for volume writes
  • 9e55fe24c548 ceph: fix hanging __ceph_get_caps() with stale mds_wanted
  • b6a098961307 ceph: avoid fs reclaim while using current->journal_info
  • 605cbdb7ed21 xfs: check v5 superblock features early
  • ff350e672534 xfs: check xfarray iteration errors when committing unlinked inode lists
  • 233557b7b1ed xfs: don't ignore runtime errors in xrep_iunlink_reload_next
  • 36a31b12540c xfs: don't swallow dquot recovery verification errors
  • 03c9c9116e6d xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN
  • 96246a3200d3 xfs: avoid UAF on sc->tempip in xrep_tempfile_create
  • 73ce20d9b6a9 xfs: don't return EFSCORRUPTED when scrubbing corrupt parent pointers
  • 23690064f235 xfs: fix another iunlink infinite loop bug in online fsck
  • 8ce03692a6b5 xfs: fix allocated inodes that show up in the unlinked list
  • a6cfd0e4bb1e xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair
  • 70714b154842 xfs: don't zap the attr fork on repair when there are queued pptr updates
  • 08bed2b67d2e xfs: fix ilock leak on error in xfs_dq_get_next_id
  • 8a5bb14cd964 xfs: load next_agino from the correct xfarray in xrep_iunlink_relink_prev
  • 2773bf5156d5 xfs: nlink scrub must take IOLOCK before determining ILOCK state
  • a3ce762bdb5d xfs: pass runtime errors from xrep_iunlink_mark_ondisk_rec up to callers
  • ca6085790659 xfs: set the prev pointer when reinserting an inode on the unlinked list
  • c57590447157 xfs: don't double-lock when deleting a self-referential directory
  • e753d3b5b21b xfs: only check mergeability of bnobt records
  • a68b492357e3 xfs: zero i_nlink before repair puts inode on unlinked list
  • b51051f7dc53 xfs: fix transaction block reservation in xrep_rtbitmap
  • 5faabb37dd60 xfs: check cowextsize in xrep_inode_cowextsize
  • c82c1279c90a xfs: clear zapped attr fork state when bmap repair finds no attr fork
  • ccad4a3b96eb xfs: mark nonzero sb_gquotino as corrupt on metadir filesystems
  • edaf5b6bd625 xfs: bounds-check buffer log item's dirty bitmap
  • ccebfc309441 xfs: fix off-by-one in rtrefcount btree root level validation
  • 61c5165f02de xfs: propagate errors from xfs_rtginode_load
  • e3ee74d6dbbe drm/amdgpu: disallow multiple FENCE chunks in one submit
  • 5cbd8af02b0b drm/amdgpu: Fix UVD decode image min size calculation
  • ff4361816b6b drm/amdgpu: Fix UVD dpb min size calculation for H264
  • 4530aa81c907 drm/amdgpu: Fix UVD min buffer sizes
  • de67fd77ff18 drm/amdgpu: Implement insert_end for VCE 3
  • 17fbb996c05f drm/amdgpu: Reject UVD message with dimensions above 4096
  • 80f0b53860d0 drm/amdgpu: validate GEM_CREATE domain combinations
  • 544f760f36d4 drm/amdgpu: check ASPM on the dGPU host link
  • 9213b2febc37 drm/amdgpu: fix missing check in vm_flush()
  • 33bd5194ea61 drm/amdgpu: fix nbif 6.3.1 l1 low power not functional
  • 476d259f285f drm/amdgpu: Prefer default discovery offset
  • 0acdf1a575f5 drm/amdgpu: Reject UVD message with invalid number of h265 refs
  • 2f41881e73f4 drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE
  • dacea1e4de8e drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix
  • 4a6bc92fac30 drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank()
  • 2db92a56b000 s390/zcrypt: Pad trailing CCA or EP11 message with zeros
  • db21b2cf6dd0 s390/zcrypt: Improve EP11 CPRB domain handling with ASN.1 parsing
  • 2976b9d2e716 s390/zcrypt: Improve EP11 CPRB length and overflow checks
  • 50fe5133dcb4 s390/zcrypt: Improve CCA CPRB length and overflow checks
  • 14d41e383241 s390/zcrypt: Fix CPRB memory allocation in zcrypt misc code
  • c76c4ee72bfc s390/vfio_ccw: Implement a crw lock
  • 83a73fdeff38 s390/vfio_ccw: Calculate idal length based on idaw type
  • 2a5ac0c0f1f7 s390/vfio_ccw: Selectively expand io_mutex
  • 56100baa0eb7 s390/vfio_ccw: Move cp cleanup out of not operational
  • d5d096cd9369 s390/vfio_ccw: Fix out of bounds check on CCW array
  • fc59e9482117 s390/vfio_ccw: Ensure first IDAW remains constant
  • 988d9b5be3c2 s390/vfio_ccw: Ensure index for read/write regions are within range
  • 77f5e888d2e6 s390/vfio_ccw: Cancel existing workqueues
  • 4ee94790490a s390/vfio_ccw: Limit the number of channel program segments
  • 4699b54fada1 s390/vfio_ccw: Free all memory if cp_init() fails
  • 6a06a99b9c60 drm/radeon: fix autosuspend cleanup during teardown
  • e4aff0f8bc31 drm/xe/guc_ads: use uncached mapping for UM queue BO
  • 02bc8cf239a7 drm/xe/guc_ads: allocate UM queues in VRAM on dGFX
  • 7b1ebb987d13 drm/xe/guc_ads: allocate UM queues in a separate BO
  • 4db2b608e5f3 drm/xe: Fix xe_device_probe() failure
  • dea635bd1317 drm/xe: Order ring writes before ring tail updates
  • a5805f9e24d6 riscv: hwprobe: Register unaligned probes before usermode
  • f1478e8d5334 pmdomain: mediatek: Fix mt8183 hang on boot
  • db368164383c mmc: loongson2: Fix sg iteration in data reorder functions
  • f72bb95732bc drm/connector/hdmi: Fix out of bounds memory read
  • 7599a73ff66d mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition
  • 0e1c00199394 pmdomains: mediatek: Avoid setting RTFF's CLK_DIS before NRESTORE
  • 3c6c28b9bee7 mmc: sdhci: make tuning_err a signed int
  • 10bf2d7261d7 pmdomain: mediatek: fix remaining %pOF after of_node_put()
  • ce508a334e9c mmc: sdhci: unmap the bounce buffer before device release
  • 4a0c11683a8f mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit
  • 3497102117e8 libceph: tolerate addrvecs with multiple entries of the same type
  • 7130d94846da libceph: fix OOB read in decode_watchers() via missing bounds check
  • a9e1d197953f ceph: fix MDS random selection readiness predicate
  • e009c5f0ad63 libceph: Avoid using invalid osd indices from primary_temp
  • daeaa22a37dd Input: sur40 - fix V4L error path cleanup
  • beb9b0bd6e6e Input: sur40 - fix input device registration ordering
  • 212fc482ddd7 openrisc: signal: do not restore privileged SR bits on sigreturn
  • 7e65a89124c1 ftrace: Fix off-by-one fentry site disable in ftrace_free_mem()
  • bd75a42cea7e ftrace: Protect direct_functions in update_ftrace_direct_mod
  • 35f8e0989985 ftrace: Protect direct_functions in update_ftrace_direct_del
  • 5ac91943ee59 ftrace: Protect direct_functions in ftrace_find_rec_direct
  • de4eec0dfde8 pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev()
  • 51c8d238fe72 libceph: fix multiple unsafe decodes in decode_locker()
  • cdefce49feed pmdomain: arm: Fix -EINVAL from scmi_pd_set_perf_state() on state 0
  • 10505f28146f pmdomain: qcom: rpmhpd: Add missing MXC and MMCX power domains for Eliza
  • 0559b86611c3 gpio: ml-ioh: use raw_spinlock_t for the register lock
  • 44ec5936ba15 gve: fix zero-length skb frag with header-split
  • 8021105545c1 selftests/ftrace: Convert ELF entry point to file offset in uprobe test
  • 24bef4918f6a gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind
  • fa9b991bf678 gve: fix NULL dereference due to missing ptp adjfine
  • 4e88b4fda482 crypto: qce - fix error path in devm_qce_register_algs
  • 61b20fba32d6 crypto: starfive - use scatterlist length before DMA mapping
  • 51c5503554c8 Input: hynitron_cstxxx - validate touch count and finger IDs
  • 9bbd3682f8a3 Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue
  • ddd9a53faf3b Input: synaptics-rmi4 - block s_input when F54 queue is busy
  • b7b9a8b1c303 Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer
  • 88c8174d7290 Input: synaptics-rmi4 - zero report size on F54 work error
  • ed98ce338f9a powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak
  • 6a4643f7eabe powerpc/pseries: lparcfg - fix kbuf[] underflow
  • 2e509ef60ee4 Input: byd - synchronize timer deletion before freeing private data
  • 84e5cb517f44 Input: iforce - validate input packet lengths
  • 594b79d024e5 Input: atkbd - skip deactivate for HONOR ZQC-P
  • da1ecf638cd8 Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard
  • 62e25677d144 Input: psxpad-spi - set driver data before use
  • 1842e4712681 Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet
  • a81cafe3c3c2 Input: synaptics-rmi4 - fix F55 transmitter electrode count typo
  • 360fc573e6cf powerpc/pseries: pci - logic bug
  • d38554602a0b Input: cs40l50-vibra - validate custom data from user space
  • a3da1fa14797 Input: xpad - add support for ZENAIM LEVERLESS
  • 2deef1c38c2c ASoC: SOF: topology: Use acpi mach from the machine driver
  • 0306873bbb3a drm/amdgpu/gmc12.1: fix MMHUB0 check in pasid tlb flush
  • d4ffb51b9f02 drm/amdgpu/gmc12.1: implement tlb inv semaphore
  • 1c73854a53bb drm/amdgpu: fix aperture iounmap skipped on device removal
  • a4d52348157e drm/amdgpu: fix JPEG v4.0.5 queue reset failure in DPG mode
  • 09ad1526c2ef drm/amdgpu: fix JPEG v5.0.0 queue reset failure in DPG mode
  • c79ec4aa250b drm/amdgpu: fix JPEG v5.3.0 queue reset failure in DPG mode
  • 9381d8ae3e31 drm/amdgpu: Use virtual alloc during coredump
  • fb0eb608570e drm/radeon: restore hardware polling in fence_is_signaled to fix performance regression
  • 34c5b3eca369 drm/amd: Disable DP audio spread spectrum for Cyan Skillfish
  • 91731dec60e9 drm/amdgpu/userq: serialize queue map against GPU reset
  • a4443c272578 drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12
  • 07fe270ec07c drm/amdgpu: reject oversized IBs with per-ring packet limits
  • 5d222b657f02 drm/panthor: skip zero-sized firmware sections
  • 7110b7b794a2 fbdev: core: Fix pointer desynchronization in fb_io_read()
  • ce7fef961c63 fbdev: clear fb_info->mode before deleting a videomode
  • 873a1aa15c31 fbdev: bound mode sysfs output to the sysfs buffer
  • 7bcdde412e6c ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses
  • 4fbbbb17edb4 ASoC: cs35l41: sort the register default table
  • 2b12126944d7 ASoC: cs35l45: sort the register default table
  • b3f8a818796b ASoC: cs4265: sort the register default table
  • 6b512a5330ef ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout
  • d48691e70d4a ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked()
  • 12803e89a1e5 drm/shmem_helper: Check VMA boundaries for PMD mappings
  • 3ee3c26ceee5 ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses
  • 2f578062a5f1 microblaze: restore the page alignment of swapper_pg_dir
  • 75fb3151513d s390/qeth: validate user buffer length in SNMP and ARP query ioctls
  • 72b4a0c51a4b mptcp: fastopen: only mark MPTFO subflows with SYN data
  • 5099027f98b2 mptcp: pm: fix data race in add_addr timer callback
  • 27ed642a4e7e mptcp: options: reset DSS fields in case of unexpected size
  • 6bab90729215 mptcp: avoid combining some incoming suboptions
  • e5791c03854b selftests: mptcp: join: mark tests with data corruption as failed
  • 8277f48a06d3 mptcp: reclaim forward-allocated memory on RX path errors
  • d81bda85d95f selinux: reject a permission value exceeding the class permission count
  • d8a10899ea3c selinux: reject an unclaimed class value in security_get_classes()
  • 219c96de5d9b selinux: do not cancel a policy conversion that never started
  • 1b995966c3ae selinux: reject a class permission count below its inherited common
  • ed901e88aa3f selinux: require every boolean value to be defined
  • 93d620519d71 block: stop the timeout timer when releasing a never added disk

View originalPermalink

7.2.0-xanmod1
  • 275555fa1bf1 Linux 7.2.0-xanmod1
  • 29d92d1b92fb XANMOD: .gitlab-ci: Add gitlab-ci.yml file
  • f67bfad06094 XANMOD: Add GPLv2 license file
  • 020afb98da2e sysctl: add sysctl to disallow unprivileged CLONE_NEWUSER by default
  • 84598b0cf5c4 PCI: Enable overrides for missing ACS capabilities
  • a4c71e364327 file: export file_close_fd() instead of close_fd_get_file()
  • 049ff525581a wait: allow to use __wake_up_pollfree() from GPL modules
  • d72d6bc52918 binder: give binder_alloc its own debug mask file
  • 2b656afd62ec binder: turn into module
  • 8cba03efea37 mfd: steamdeck: Expose controller board power in sysfs
  • 53f4492f17e1 mfd: Add MFD core driver for Steam Deck
  • 92b109106b84 leds: steamdeck: Add support for Steam Deck LED
  • 4d95534fadd3 hwmon: steamdeck-hwmon: Add support for max battery level/rate
  • 824ae407514e hwmon: Add driver for Steam Deck's EC sensors
  • 8e799663139b extcon: Add driver for Steam Deck
  • 3b4d00f3a7bb netfilter: add xt_FLOWOFFLOAD target
  • 04edf698d915 netfilter: Add netfilter nf_tables fullcone support
  • 2bc6b0895f5c tcp: Add a sysctl to skip tcp collapse processing when the receive buffer is full
  • d50171100f3c tcp_bbr: v3: update TCP 'bbr' congestion control module to BBRv3
  • 9c594ca6d407 ZEN: dm-crypt: Disable workqueues for crypto ops
  • c1f19aa98e54 ZEN: input/evdev: Use call_rcu when detaching client
  • 66b54cff5cba drivers: initialize ata before graphics
  • 1c4833ae5add locking: rwsem: spin faster
  • dce6a5fdd743 firmware: Enable stateless firmware loading
  • 7c6a92846009 sched/wait: Do accept() in LIFO order for cache efficiency
  • 80af49bc67fa mm: Add working set protection for anon and clean file pages
  • 36d9622e03e8 XANMOD: Makefile: Move x86 instruction set selection to kernel-wide build
  • 4bc30ce6728f x86/kconfig: more x86-64 ISA levels and uarches
  • 231777ac25f3 XANMOD: x86/build: Prevent generating avx2 floating-point code
  • 0283427a0a31 XANMOD: scripts/setlocalversion: Move localversion* files to the end
  • 517afee9bc92 XANMOD: scripts/setlocalversion: remove '+' tag for git repo short version
  • f2ef9a46d11b XANMOD: lib/kconfig.debug: disable default SYMBOLIC_ERRNAME and DEBUG_BUGVERBOSE
  • ccc0f7ec88e3 XANMOD: cpufreq: tunes ondemand and conservative governor for performance
  • 5b4df09b709a XANMOD: mm/vmscan: Reduce amount of swapping
  • ed2a9eca2135 XANMOD: mm: Raise max_map_count default value
  • 7ac91c5588e7 XANMOD: vfs: Decrease rate at which vfs caches are reclaimed
  • 0988dbc5822a XANMOD: kconfig: add 500Hz timer interrupt kernel config option
  • 89d0ae046966 XANMOD: blk-wbt: Set wbt_default_latency_nsec() to 2msec
  • bae2948f36c9 XANMOD: block: Set rq_affinity to force complete I/O requests on same CPU
  • fd699380cd6a XANMOD: block/mq-deadline: Disable front_merges by default
  • 3868ed8dbd88 XANMOD: block/mq-deadline: Increase write priority to improve responsiveness
  • b746821c0765 XANMOD: fair: Set scheduler tunable latencies to unscaled
  • 19e5ebe24766 kbuild: Re-add .config file required to sign external modules
  • c9d752c21d51 XANMOD: kbuild: deb-pkg: Create -dbg when make DEB_DEBUG_PKG=1
  • 1d39a03d3382 XANMOD: kbuild: Add SMS-based software pipelining flags
  • 3b40b2850e79 XANMOD: kbuild: Add LLVM polyhedral loop optimizer flags
  • dd21db2d9881 XANMOD: x86/build: Add more CFLAGS optimizations
  • 8d3ae59288f1 Linux 7.2

View originalPermalink

7.1.9-xanmod1
  • 762461b8ceec Linux 7.1.9-xanmod1
  • 75350514d3f8 Merge tag 'v7.1.9' into 7.1
  • ffc82ed66531 Linux 7.1.9
  • 0a8c9ed4f166 thunderbolt: Fix bandwidth group reservation indexing
  • f32c3a9a77cf thunderbolt: Bound the DROM dual link port number before indexing sw->ports
  • 163847552a57 sctp: clear new_transport when removing a peer
  • d949992bc3f0 sctp: fix use-after-free of cached ASCONF chunk
  • 5ccf35ef0ed6 sctp: keep chunk->transport in step with the list it is queued on
  • 65a740633570 scsi: scsi_debug: Negate wrapped memcmp() result
  • 1cec526cf0a2 bpf, sockmap: Fix sk_redir use-after-free in send verdict
  • 911d5c32a54c fsverity: Fix silent truncation in bpf_get_fsverity_digest()
  • 5bd63cad9df4 fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions
  • 267ecd2eb775 mm/filemap: __filemap_add_folio() restore index before retrying
  • 0baed1fa2184 ima: Instantiate file_truncate and path_truncate hooks
  • a054c9ffa9b7 sched_ext: Take cgroup_lock() first in scx_cgroup_lock()
  • d217d851f0a2 sched/psi: Create the psimon kthread outside of cgroup_mutex
  • 611e7821c4f8 sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
  • 98516ba8b817 fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()
  • 2d2b2ed7bdcc fs,fsverity: remove check for fsverity being enabled in setattr_prepare()
  • fbf40faa0414 ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
  • da64ed1f346b ipv6: fix Route Information option length validation
  • 4adc4c9a9a43 mm/ptdump: always stabilise against page table freeing using init_mm
  • b726eb3c94d2 mm/page_table_check: skip special zero mappings
  • 5e6e2a18c20e ring-buffer: Use current_context for safe per-CPU buffer swap
  • 3b3e0a6ee5bb ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer()
  • f8d7e5751267 ptp: ocp: Fix board ID over-read
  • 2004172036ec Revert "thermal: hwmon: Register a hwmon device for each thermal zone"
  • 6b446d335ba1 Revert "thermal/drivers/hwmon: Cleanup coding style a bit"
  • c4d0c93d2469 ring-buffer: Prevent resizing of persistent ring buffer
  • 004f7232e497 eventfs: Use children field for rcu head and add memory barriers
  • 74bb1eaf72d1 eventfs: Fix use-after-free in eventfs_remove_rec()
  • 9f7760a2e962 KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page
  • d728baba0f20 KVM: SVM: Serialize accesses to the owner and mirror list with separate lock
  • 79748c9f9b2f smb: client: fix SMB1 TRANS2 multi-response truncation in SendReceive()
  • 1305eadc6a7d smb: client: Fix use-after-free in cifs_try_adding_channels()
  • 5558a8312452 tipc: read le->link under the node lock in tipc_node_link_down()
  • 3c5f8f2aa57c tls: don't leave a full plaintext sk_msg ring unpushed
  • 3c837266a734 tls: rx: restore msg_iter before TLS 1.3 optimistic retry
  • b70ebe0bba25 vhost: reset the vring metadata cache on vring reconfiguration
  • 3205b0652a37 veth: fix skb length accounting after XDP frag adjustment
  • e82a5faea2e3 vsock/virtio: avoid refilling the RX queue after teardown
  • 1cecb4202afd vsock/virtio: read virtqueues under worker locks
  • 6b4119af5449 vxlan: do not arm the ageing timer on a device that is down
  • f463b6f4957c xdp: reject clones that overrun skb_shared_info tailroom
  • 4f4cba3947d2 x86/mce: Set up the polling timer before CMCI discovery
  • da6acd11d2f2 x86/CPU: Add a tlbi= cmdline switch
  • eb0a9fabb924 arm64: remove redundant concurrent ptdump UAF mitigation
  • 2926031acba1 dibs: initialise dibs->lock in dibs_dev_alloc()
  • 496846a94111 Revert "drm/amdgpu: fix aperture mapping leak"
  • 047f927f54c6 binfmt_misc: don't warn when the mount is completed from another user namespace
  • 42d99fcd8006 ovl: don't warn when the mount is completed from another user namespace
  • 2e8df8c91903 net/sched: act_gact, act_police: range check the fallback control action
  • 439d3e404f9d net/sched: act_ct: fix sk_buff leak when the header checks reject a packet
  • 24d87dc28ddd net: atlantic: free RX pages of consumed but not refilled buffers
  • dd633280de7f net: atlantic: free stranded TX buffers on ring deinit
  • c0224327b7cb netfilter: nf_conntrack: defer invalid log until after unlock
  • 7cff440d7026 netfilter: bridge: release template ct on non-IP path
  • 755fd7843f30 NTB: ntb_netdev: Preserve RX queue depth on allocation failure
  • ed08011ae0be net: devmem: prevent net-iov / page mixing
  • e92c7e2b41d1 net/x25: fix use-after-free of the socket by its timers
  • 7a1df20a8d2c net/dibs: Correct freeing of dmb_clientid_arr
  • 14e812ab41df ipv6: prevent in6_dev_get() from resurrecting inet6_dev
  • 4515c78f4d9f net: smc: fix splice entry lifetime imbalance in smc_rx_splice
  • aa03d76252cc net: phy: mediatek: fix TX blink masks using the RX bits
  • ab7e4b407c7f mm/huge_memory: fix huge_zero_pfn race
  • d858f7c9fc51 mm/huge_memory: initialise workingset state before folio split
  • ad4e9dd5fec7 tracing: Fix NULL pointer dereference in module event cache removal
  • 7568e9e717e7 ring-buffer: Prevent subbuf order change when resizing is disabled
  • 9ea879862e66 fbdev: bitblit: bound-check glyph index in bit_cursor()
  • f128740f39ab tracing: Fix race between update_event_fields and, event_define_fields
  • 1e7abfeb23c1 perf/core: Fix group leader use-after-free after sibling detach
  • c22a45817b9c drm/v3d: Serialize the scheduler timeout handlers
  • a5548ce91659 ALSA: us144mkii: re-anchor capture URBs on resubmission
  • 0582952cd6cc ALSA: hda/tas2781: fix ACPI reference handling
  • bb61dc2ae590 ALSA: FCP: fix OOB write in fcp_meter_ctl_get()
  • 5bf5ccddf00b ALSA: usx2y: bound the hwdep mmap fault offset
  • f9d492a39ebe ALSA: usb: Fix UAF at delayed release of MIDI2 EPs
  • 91e4538952a9 mm/damon: adjust isolated pages stat for DAMOS_MIGRATE_{HOT,COLD}
  • 684f271210be samples/damon/mtier: error out for zero quota goal target values
  • cfef454862b7 mm/damon/ops-common: putback folios on invalid migrate nid
  • e7e5e5e0dfe2 mm/damon/lru_sort: error out for >10000 active_mem_bp
  • 3ea2fd344d93 ring-buffer: Fix crash passing ERR_PTR to kthread_stop()
  • eaef442fe68c misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free
  • efd02f8d1a74 misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke
  • 0beaa9bd7eb1 misc: fastrpc: Remove buffer from list prior to unmap operation
  • 03a9cea00b39 misc: fastrpc: fix channel ctx ref leak when session alloc fails
  • 60c1c757fd4f misc: fastrpc: Fix initial memory allocation for Audio PD memory pool
  • bd88f6289b7e staging: rtl8723bs: validate monitor transmit frame lengths
  • 6235b5156b48 staging: rtl8723bs: fix missing shared-key auth challenge length check
  • e429c6dfd5d2 staging: rtl8723bs: fix OOB read in WMM_param_handler()
  • 01ab275f8f3e staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()
  • fdfb46c38724 serial: amba-pl011: synchronize DMA teardown
  • e57f0aa5c35b serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ
  • b49a43ebace1 serial: amba-pl011: fix indefinite RS485 post-send delay
  • 7795e8abedc8 serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx
  • e7e3cc6709ca serial: 8250_dma: Clear stale RX state on shutdown
  • b449429e9e78 serial: sc16is7xx: enable THRI before filling TX FIFO
  • b1801c0d40f6 serial: qcom-geni: fix TX DMA buffer flush
  • 5f1d56be1e9c rust_binder: do not query current thread for all ioctls
  • 1149ce318c2b nvmem: layouts: Add fixed-layout driver
  • d11b12dcdce9 nvmem: apple-spmi-nvmem: wrap regmap calls to satisfy CFI
  • d88678d3fcb0 mei: pull kvfree out of spinlock
  • ed503eaad62f ipv4: fix use-after-free in fib_nhc_update_mtu()
  • 9b22f13524fa ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops
  • 1dd48303931b selftests/bpf: Adapt sockmap update error handling
  • 8cf744abef6a selftests/bpf: Ensure UDP sockets are bound
  • 781d944ca910 Bluetooth: btusb: Add TP-Link UB600 for Realtek 8761BUV
  • d5977f4f995e Bluetooth: btrtl: fix RTL8761B/BU broken LE extended scan
  • e828321f9cfa selftests/xsk: account reclaimed invalid Tx descriptors
  • 6d419a03249c selftests/xsk: fix too-many-frags multi-buffer Tx test
  • 7cf710e70f9b futex: Prevent robust futex exit race some more
  • 86e48e822111 Revert "drm/amd/display: Fix backlight max_brightness to match exported range"
  • e08665218040 net: bridge: mrp: fix uninitialised bytes on the wire
  • e2ab7e878bdb netfilter: ebt_nflog: pin the NFLOG backend
  • ef365e8f9c24 igc: fix netdev not re-attached after resume if interface is down
  • 9d067e581597 mac802154: fix netdev use-after-free in beacon worker
  • 928128865e43 inet: frags: publish queues before arming timer
  • fc902f52a022 net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header
  • 3010b7f13647 net: octeontx2-pf: Fix UB in shift operation
  • e2d658c64278 net/sched: reject overly deep qdisc hierarchies
  • 20751193d83b net: openvswitch: reallocate update replies for mismatched IDs
  • ea1ccd6d1c63 net: fix skb length accounting after generic XDP frag adjustment
  • a08196c3cc10 packet: synchronize pressure clearing with ring reconfiguration
  • fdd4d7d52358 net/packet: reset the MAC header on the packet-socket transmit path
  • d48ea5c9c4c3 packet: use consistent hard_header_len in TX_RING send path
  • b06b6fce6d7d packet: use consistent hard_header_len in non-ring send paths
  • 384b4dae1427 ipvs: clear IPv4 options after rebasing tunnel ICMP errors
  • ad8439a21081 ipvs: separate destination availability state
  • bc1286dca5a4 ipvs: properly update the overload flag on dest edit
  • 7c3fdb37de14 ipvs: add totalconns for dest
  • 2335dedc1922 ipvs: stop estimator after disabled calc phase
  • dd04114af0d4 ima: fix out-of-bounds read in xattr_verify()
  • 3cc26c8907db mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF
  • 7e55ca1080f0 Input: evdev - fix information leak in evdev_pass_values()
  • 0b8ff21cbda8 mm: fix incorrect flush address in direct page table reclaim
  • cc4a1a2ce0c5 vt: stabilize tty reference in kbd_keycode with tty_port_tty_get
  • 7bf32337a710 vt: add permission check for KDSKBMETA ioctl
  • fdbf547d91bf usbnet: cap max_mtu for drivers without bind callback
  • 48303f3ae0fa net: usb: ipheth: fix carrier_work UAF on disconnect
  • 4039cd807a5a net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()
  • fc9e54e22845 usb: gadget: f_ncm: Use unsigned int for ndp_index
  • 4364486f249c usb: cdnsp: fix incorrect endian conversions for APB timeout register
  • 4e9b490e555e thunderbolt: icm: Preserve USB4 proxy data-valid bit
  • 0b1ea726c987 usb: xhci: use BIT_ULL for CRCR bits to fix incorrect 64bit mask
  • 0af047703dbe usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
  • 9ad0164f78b6 usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg
  • 7436fb2bed66 usb: quirks: Add ShanWan gamepad to quirk list
  • 015e71a1b565 usb: core: Add quirk for 255-bytes initial config read
  • d3ed4e6321bb ALSA: usb-audio: fix OOB write on Type II inbound URBs
  • 810e1883d481 Input: evdev - sanitize event type index when fetching event masks
  • 164c31ee252e net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp()
  • 4870189064dd ALSA: usb-audio: Fix sticky mixer regressions on M-Audio Fast Track Ultra
  • e732c3b62465 hwmon: (corsair-psu) serialize debugfs access against hwmon
  • 50401a9ac8ef hwmon: Support guard() and scoped_guard for subsystem locks
  • c1ab527775e0 hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt
  • 046e56b53c09 hwmon: (ltc4282) Clamp negative current limits
  • 87a58da555f3 hwmon: (ltc4282) Avoid overflow in maximum power calculation
  • 1d43e4ce054b hwmon: (ads7828) Fix external VREF regulator handling
  • e81580057e98 hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination
  • f54667b0c162 rqspinlock: Reset tail when preserving queue on deadlock
  • b7949b0a7d99 watchdog: at91sam9_wdt: prevent timer rearm during teardown
  • 8a4713fe08b0 tls: don't abort the connection on signal-interrupted sends
  • 4d6b9cac6df5 sctp: clear control chunk transport if it is being removed
  • 2c5988c7349c net/atm: fix slab-out-of-bounds read in vcc_setsockopt()
  • 774394d27930 s390/ism: Fix UAF of sba and ieq during ism_dev_exit()
  • a294c0aa5741 bnge: Fix resource leak in bnge_init_nic() error path
  • 56fd78c8c820 ata: pata_sl82c105: fix bridge revision use-after-free
  • 9a482b2b117e net: thunderbolt: Tear down DMA paths before stopping the rings
  • 764b422116d7 net: qrtr: ns: Raise lookup limit to 128
  • ff5bcd804b5b net/smc: fix TOCTOU race between smc_listen_out() and listener close
  • 0d75f2c1d076 net: remove WARN_ON_ONCE() from sk_mc_loop()
  • 7fa8a12296d8 net: prestera: validate firmware header length
  • 3a60b5af75ab net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length
  • 538e67e8c788 netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()
  • d974618b2097 tcp: fix TFO max_qlen accounting across reuseport migration
  • 23f682083aa3 bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie
  • 9e61709d8dc8 sctp: fix addip_serial increment on ASCONF_ACK allocation failure
  • 39d56ee7db0b bnxt_en: Fix PTP PPS setting bug
  • c1962ab4645a bnxt_en: Disable EOP for TPA on all chips to prevent data corruption
  • 04550ca58622 bnxt_en: Refresh VNIC default ring on queue restart if needed
  • a6b1bf29ec40 bnxt_en: Determine and store default RX ring in vnic structure
  • 2daf5903b946 bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss()
  • d2897717cd22 net/mlx5e: fix BQL reset on SQ re-activation
  • 41661a81be9b bnge: use int for bnge_fix_rings_count() return value
  • 937f785910ce net: stmmac: resume PHY before hardware setup when opening the interface
  • 6db775482108 selftests/ftrace: refactor eprobes test to fix argument checks
  • eeaddd910841 hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations
  • c36f2c22ffdf hwmon: (nzxt-smart2) Check return value of init_device() in probe
  • 961d25b77dd0 drm/xe/uc: Apply RCS/CCS yield policy to SR-IOV VFs
  • 410596743958 drm/xe: Fix memory leak in exec_queue_set_hang_replay_state()
  • a81f9c44d87f net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers
  • 9b8cfbb58b85 net/openvswitch: check Ethernet header length in key_extract()
  • 9a3eb77a612f vhost-scsi: reject feature changes after endpoint
  • f8fe3f8d342d vhost-scsi: Validate T10 PI scatterlist counts
  • a1ae353d8355 net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter
  • 588d4a6795d9 udp: fix potential use-after-free in tunnel segmentation
  • 83ef2f3cab7f bnge: Fix NULL pointer dereference in aux device release
  • 0cc7aa6e0d19 xsk: validate metadata when processing requests
  • 7806d4885c53 xsk: move xsk_tx_metadata_request() to xdp_sock_drv.h
  • bc63d47611c0 xsk: validate launch-time metadata size
  • eb4c613d4ebc xsk: clear metadata pointer when no timestamp is requested
  • 8948aab6c349 xsk: pass TX metadata pointer by reference
  • cfb9d2976b27 xsk: require at least 16 bytes of TX metadata
  • b478ff6edf58 bnxt: fix memory leak in bnxt_queue_mem_alloc error cases
  • d01923852e52 tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss()
  • 0b121de89a99 hwmon: (pmbus) Fix type confusion in notification logic
  • 5112365c6820 hwmon: (pmbus/core) Avoid race condition during probe
  • 6c8a9f7bc003 vdpa/mlx5: Fix buffer length in create_direct_keys()
  • bb9122ba4dc4 vhost/vdpa: reject overflowing PA map page counts on 32-bit
  • ae128dd19040 vhost_iotlb: bound map allocation in add_range
  • 95dc716ca52b ALSA: usb-audio: Add QUIRK_FLAG_MIXER_GET_CUR_BROKEN for Logitech PRO X 2 LIGHTSPEED
  • e3668bb2d152 ALSA: usb-audio: Add QUIRK_FLAG_MIXER_GET_CUR_BROKEN
  • 97e74d3e45d6 bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()
  • 99eb9bb12adb counter: microchip-tcb-capture: Fix DT channel validation
  • e5e060eb63d1 bpf: Fix netns reference imbalance in conntrack kfuncs
  • 13339132d89d accel/amdxdna: Fix locally exploitable BUG_ON in amdxdna_insert_pages()
  • 4aafa600d93e net/mlx5: fw_tracer, return NULL on create error
  • eda60c85b4f4 devlink: fix net namespace reference leak in reload
  • 49053a39815f net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete
  • ae9aff870252 net/sched: cls_route: fix fastmap use-after-free on filter
  • bfc336a9fbbf net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()
  • d90e72e5e0f9 bpf: Propagate untrusted pointer state in commuted arithmetic
  • eaffa1495e4f bpf: Preserve pointer state for commuted arithmetic
  • 1501e4d07c6f accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages()
  • 0d2624967117 btrfs: initialize inode mapping flags for cached inodes
  • 60b50ceba624 btrfs: fix memory leak in btrfs_do_encoded_write()
  • fc50b475ad27 btrfs: lzo: reject inline extents without valid headers
  • ffa355d5dff3 btrfs: lzo: add error message for invalid headers
  • ba3e2d9584a4 watchdog: bd96801_wdt: Fix timeout for enabled WDG
  • 369faf64ccbc ipvs: return the csum validation for forward hook
  • 243d0187ec4c ipvs: avoid out-of-bounds write in ip_vs_nat_icmp
  • 3d450788dc04 netfilter: ipset: switch ext_size to atomic64_t
  • 14328d1ecdda pds_core: cancel pending PCI reset work on AER recovery
  • 8530ea7ac96c pds_core: keep the health thread stopped during reset
  • 7165fe321c61 net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock
  • 4f3464fc6c1f enic: fix tx_hang_reset use-after-free on device removal
  • 257c4a3a34d8 bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor
  • e18f8d166a7c Revert "net: thunderbolt: Enable end-to-end flow control also in transmit"
  • fe450066628e net: hns3: fix speed configuration residue after driver reload
  • a272a3d3129d drm/bridge: ps8640: propagate AUX transfer register errors
  • e71780593647 ovpn: fix incorrect use of rcu_access_pointer()
  • af82e1375513 ovpn: ensure TCP vars are initialized first
  • ac5cce2e9557 ovpn: disable IPv4 redirects on MP interfaces
  • 844616a78baa ovpn: hash floated peer by transport identity only
  • 21a2eda3fcc6 ovpn: zero-initialize sockaddr before learning a floated endpoint
  • 43a31142e1d2 ovpn: ensure socket is owned by ovpn before deref sk_user_data
  • 4bc1c83a2e04 ovpn: rehash peer in by_transp_addr table on CMD_PEER_SET
  • 667454802987 ovpn: skip rehash for peers already removed from by_id
  • 8730ac05b2c5 ARM: dts: BCM5301X: fix PCIe controller 2 second interrupt
  • 147ebe15f955 ovpn: add missing rtnl_link_ops->get_size callback
  • f5d2914f93c2 pinctrl: qcom: ipq806x: mark pci reset as a GPIO pin function
  • 617724534a83 pinctrl: qcom: ipq806x: mark gpio as a GPIO pin function
  • 576b1c202fa0 selftests/sched_ext: Handle sleeping task affinity changes in numa test
  • 5edc5e1df6c0 ARM: npcm: Fix OF node refcount leaks in SMP setup
  • 3aa0c1d23ee1 xfs: handle NULL b_addr in xfs_buf_free
  • 131ab677b033 soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read
  • d2c8160da4e5 arm64: dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer
  • b77bd3f067a0 NFS: Decrement refcounts if allocating nfs_free_stateid_data fails
  • 80ed3d762628 NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
  • 517b1e4fe28b sched_ext: Don't enable non-ext tasks in the sub-sched task loops
  • 6428093a4a98 sched_ext: Skip sub-disable teardown for never-linked sub-schedulers
  • 592bc5000d6b sched_ext: Reject setting disallow from init_task outside the enable path
  • de6f2b6c8d22 arm64: dts: qcom: sdm850-lenovo-yoga-c630: lower PSCI cluster idle
  • 0a234a9a5c1e arm64: dts: qcom: sm8650: Fix IPA IMEM slice
  • 1d724dc6193c arm64: dts: qcom: monaco: Add default GIC address cells
  • d15ef483c54d arm64: dts: qcom: purwa: Fix GPU IOMMU property
  • 04d06aa023e3 arm64: dts: qcom: glymur: fix QUP serial engine IRQs
  • f7b52b18c04d arm64: dts: qcom: glymur: fix PCIe SMMU interrupts
  • 5edbb409b0bc drm/amd/display: Check for tg ops in dce110_set_avmute
  • 9d64e8854f5e drm/amd/display: Add AV mute wait frames to dce110_set_avmute
  • e6a2f5f845f5 gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock
  • 7fd0235c438c selftests/bpf: Add tests for sleepable tracepoint programs
  • 070d4ce6776f selftests/bpf: Fail unbound UDP on sockmap update
  • 300bb214c938 mount: honour SB_NOUSER in the new mount API
  • 62e211a80cfd XANMOD: Add GPLv2 license file

View originalPermalink

7.1.8-xanmod1
  • a8992243188e Linux 7.1.8-xanmod1
  • 5dea5c12fecb Merge tag 'v7.1.8' into 7.1
  • 25c76bea853d Linux 7.1.8
  • bed97cd6f0ea usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path
  • 971962e96618 drm/amd/display: Exit idle optimizations before programming
  • be5c6ca1924a drm/amd/display: check GRPH_FLIP status before sending event
  • c1a029cb1aeb media: chips-media: wave5: Support CBP profile
  • 5d363d00bc97 drm/xe: Wait on external BO kernel fences in exec IOCTL
  • 1366bf0496c2 drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse]
  • 3e891bfe08b4 drm/xe: Set TTM device beneficial_order to 9 (2M)
  • 15dfb66b557a drm/xe: Separate early xe_device initialization
  • 805dcf380590 drm/xe: Move xe->info.devid|revid initialization
  • d4c139fe4548 drm/xe: Move xe->info.force_execlist initialization
  • f571c2616e58 drm/xe: Drop unused param from xe_device_create()
  • bc7a0f721123 usb: typec: ucsi: Fix race condition and ordering in port unregistration
  • 30df04e2d569 usb: typec: ucsi: split connector lock classes
  • 2c55034e53c5 drm/xe/rtp: Ensure locking/ref counting for OA whitelists
  • 3be72ad315db drm/xe/oa: (De-)whitelist OA registers on OA stream open/release
  • 43114690b12f drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt
  • e8d1f040eb15 drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs
  • ddcc9e4a8ebe drm/xe/rtp: Save OA nonpriv registers to register save/restore lists
  • 339bc3ab303e drm/xe/rtp: Generalize whitelist_apply_to_hwe
  • cc6b3f0c82b2 drm/xe/rtp: Keep track of non-OA nonpriv slots
  • 16449f284fa4 drm/xe/rtp: Maintain OA whitelists separately
  • 5e4a2d15637a drm/vmwgfx: validate external BO copy bounds for both stride paths
  • 5c725901908e drm/vmwgfx: use check_add_overflow for shader size+offset bound
  • 9109b7935b9c drm/vmwgfx: enforce cursor size limits for MOB cursors
  • 0ee0532f1d40 drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure
  • 9759da60e38d drm/vmwgfx: bound DMA command body size against suffix pointer
  • c77cf8edae2b drm/vmwgfx: validate DRAW_PRIMITIVES header size before division
  • 4df39eb99bb4 drm/vmwgfx: drop dma_buf reference on foreign-fd prime import
  • bacbdc0be793 drm/vmwgfx: take fman->lock around fence list mutation in fifo_down
  • 2c10e2271a08 drm/vmwgfx: clamp dirty-page range with min, not max
  • 6b1eb0b63cc1 drm/vmwgfx: reject DX_BIND_QUERY without a DX context
  • 3b2bb16a5b62 drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size
  • bed80be08c0b drm/amdkfd: hold event_mutex while checkpointing CRIU events
  • 46c6041c7b02 drm/amdkfd: Handle invalid event type in CRIU event restore
  • 7c54bd225d83 drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment
  • 7c35bf94150d drm/amdkfd: fix QID bit leak in pqm_create_queue()
  • 4070909ac042 drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE
  • f556bc844cc4 drm/amd/display: use proper context for logging
  • 1c0b90e44768 drm/amd/display: Silence link_dpms I2C retimer failures
  • 3fc61f526ffa drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames
  • 1f93537881fd drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero viewport
  • 062cfd6c678f drm/amd/display: check if dml21_add_phantom_plane() is successful
  • 221d2766fefa drm/amd/pm: use milliwatts for GPU power sensors
  • dfc5d288c7c9 drm/amd/pm: hide pp_table sysfs on APUs
  • b628f2c6feb3 drm/amd/pm: fix pptable use-after-free
  • 219eed1a041e drm/amd/pm: fix torn gpu metrics reads
  • 30e7e004bef7 drm/amdgpu: cap GTT size to physical RAM on APUs
  • 3529c9b1e4e7 drm/amdgpu: restore UMD profile pstate after runtime resume
  • a0062a4653e4 drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini
  • 4296fd8fe37a drm/mediatek: ovl_adaptor: balance component registrations
  • 2faeaaf28f92 drm/mediatek: mtk_hdmi: Fix DDC adapter double put in v2
  • ca41d9f3a215 drm/panthor: validate firmware interface structure sizes
  • 7f4674d986c1 drm/panthor: reject firmware sections with oversized data
  • f32aeba8e9ef drm/bridge: display-connector: Fix I2C adapter resource leak
  • a75c8f365e20 drm/vc4: Zero the tile state data array before each BIN job
  • 1e33ca7f44be drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size
  • f3d2397f5309 drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs
  • e49fa5a495af can: ctucanfd: mark error-active controller status valid
  • 5bdcb17d788b can: ctucanfd: handle bus error interrupts
  • 02170ecf8e2d can: ctucanfd: unmap BAR0 using base address
  • 8e4eadb4b770 can: ctucanfd: use self-test mode for PRESUME_ACK
  • 731ed47772a5 can: ctucanfd: add missing MODULE_DEVICE_TABLE()
  • d9c115948c3d can: peak_usb: validate uCAN receive record lengths
  • dfb17bf04a76 can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error
  • 0149fdb50a30 can: peak_usb: add bounds check for USB channel index
  • 808ed899dcf8 can: softing: fw_parse(): validate firmware record spans
  • 0e36a43dcdd4 can: rcar_canfd: change the initializing flow for clocks and resets
  • 21f0465fd86d can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents
  • 195e70e83a09 can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams()
  • 6fbf77ca59c9 can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking
  • d5b3613c7d69 can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer
  • 35c62ac98d06 can: isotp: fix timer drain order, wakeup handling and tx_gen ordering
  • 4976c9cf4186 can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure
  • 19c6c8c6cd5d can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure
  • df3ac2a672a5 can: ems_usb: validate CPC message lengths
  • 2ded503449ce can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured
  • dab4762ee7f3 i2c: imx: Cancel hrtimer before clearing slave pointer
  • 614ca6594e30 i2c: imx: Fix slave registration race and error handling
  • ec8e15e3e5c7 i2c: imx: mark I2C adapter when hardware is powered down
  • 83d48e4bf8a1 i2c: iproc: reset bus after timeout if START_BUSY is stuck
  • aa1944b52d64 i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock
  • 100f7fdc1398 i2c: qcom-cci: drop custom suspend/resume and rely on runtime PM helpers
  • f7f0b514ac66 i2c: spacemit: request IRQ after controller initialization
  • 85dc667f4aeb ice: fix memory leak in ice_lbtest_prepare_rings()
  • 5be4386042bb ice: fix VF interrupts cleanup
  • 2ee7feff7bfa ice: wait for reset completion in ice_resume()
  • 393f3c72600a net: openvswitch: fix skb leak on flow key update failure during ct
  • 378e341b29f9 net: openvswitch: fix skb leak on flow key update failure during recirculation
  • 431a295d93f7 net: openvswitch: fix potential UAF on meter attach failure
  • fa7da1efed83 phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB
  • 68c49df14c95 phy: zynqmp: use read-modify-write for SERDES scrambler bypass
  • 7e7b9c0dca77 phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask
  • 8fa3e9435a13 s390/zcrypt: Validate length for CCA ECC private key requests
  • 3859f630b674 s390/zcrypt: Validate length for CCA AES cipher key requests
  • ebfbb9ac7adb s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()
  • 3b2abee2a678 s390/zcrypt: Fix buffer over-read in cca_cipher2protkey
  • 82b62eda68ab s390/zcrypt: Close speculative mem read possibility
  • 1223477ca88e s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs
  • 87f3389cd392 s390/dasd: Fix undersized format-check buffer
  • 96b8e09b0953 s390/dasd: Fix potential NULL pointer dereference
  • 93a0a846ec59 s390/qeth: Check CAP_NET_ADMIN for private ioctls
  • e355752a94d9 s390/pci: Fix s390_pci_mmio_write syscall error return without MIO
  • ee2ea0c452ed power: supply: max17040: handle missing status supplier
  • 57694663d658 power: supply: macsmc: Support macOS 27 SMC firmware
  • 8a1b4b8a451e power: supply: bq25890: fix the -10 C NTC lookup entry
  • b6814d55ccd4 cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized
  • 8e787961a5dc cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init()
  • 304b5281191b cpufreq: cppc: Sanitize lockless policy limit snapshots
  • 3513f3931c57 cifs: add fscache_resize_cookie() to cifs_setsize()
  • c0a4ec89fc26 gpio: pch: use raw_spinlock_t for the register lock
  • a97d774fb738 gpio: pca953x: fix cache_only and IRQ state on restore_context() failure
  • a5012358afb6 gpiolib: tolerate gpio-hogs lacking a hogging state
  • 8bf719659406 i2c: amd-mp2: Unregister callback on adapter add failure
  • 705e87e35e54 hwmon: (pmbus/core) notify on the hwmon device, not the i2c client
  • 8583336d9e52 hwmon: (npcm750-pwm-fan): stop fan timer on device detach
  • 6201cd1d70f1 sctp: prevent peer transport count overflow
  • 35c279113498 sctp: reject stale cookies with mismatched verification tags
  • cad7ab03b989 scsi: ufs: dt-bindings: Add missing mcq reg for qcom,sa8255p-ufshc
  • d6e6da6bc3b5 scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
  • 73e4cf572507 scsi: libsas: terminate deferred commands on time out
  • e1d8f92f9603 selftests/clone3: fix wild pointer access of getline due to missing init
  • d7bd560e06ae selftests/mm: fix potential wild pointer access of getline due to missing init
  • 89fe0bddd429 spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure
  • 3ba021079ef2 spi: spi-qpic-snand: write the feature value before executing SET_FEATURE
  • 83c756f3f7a5 tracing/filters: Fix false positive match in regex_match_full()
  • 000765dcdc3e tracing: Check return value of __register_event() in trace_module_add_events()
  • 127033b79383 ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()
  • 4f3f96e771a2 vxlan: use pskb_network_may_pull() in route_shortcircuit()
  • 7076a34b6e33 vxlan: use pskb_network_may_pull() for transmit path header pulls
  • 05f2987f73da vxlan: use neigh_ha_snapshot() in route_shortcircuit()
  • e50da7442910 vxlan: unclone skb head before modifying eth header in route_shortcircuit()
  • c9dceac9e1c7 vxlan: re-fetch eth header after route_shortcircuit()
  • f9c1fff857e9 veth: convert frag_list skbs before running XDP
  • 06c275a6c0a9 uprobes: Fix NULL pointer dereference in hprobe_expire()
  • 804b681002ea um: vector: fix use-after-free in vector_mmsg_rx()
  • 95f05c1c0450 powerpc/ps3: Fix map failure path in dma_ioc0_map_pages()
  • 11ad86830a78 riscv/mm: use physical alignment for vmemmap_start_pfn
  • b006a5404470 net: pktgen: fix proc entry use-after-free
  • a341c091ca0b net: ipv6: clear suppressed fib6 rule result
  • 4c57056ca6aa net: bridge: stop fast-leave after deleting a port group
  • 2097e1ddf3a6 mm: memcg: initialize *locked in memcg1_oom_prepare() stub
  • faf439b5fa7b mm/page_reporting: use system_freezable_wq to fix UAF during suspend
  • d640efe94d86 mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios
  • fcef9325afee io_uring: preserve task restrictions across exec
  • ce5b96f9656d io_uring/net: initialize mshot_len for send
  • 87a4eb9bbb34 binfmt_misc: don't leak the user namespace when the mount fails
  • 098e92fe0f1b binfmt_misc: don't let an 'F' entry pin its own instance
  • 9a2d87db3898 binfmt_misc: reject a flag character as the field delimiter
  • f0edbaf487e4 binfmt_misc: use exe_file_deny_write_access() for the interpreter clone
  • 3b522487a3a9 binfmt_misc: restore write access when removing an entry
  • 5a21ab03829c wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames
  • 09fc36eec784 wifi: mac80211: fix tid_tx use-after-free on BA session stop
  • 882af7b84f97 x86/CPU/AMD: Carve out a Zen5 models range
  • ac2f787980fd tipc: avoid use-after-free in poll trace queue dumps
  • f448d2e9e938 PCI: imx6: Keep i.MX6 Root Port MSI/MSI-X Capabilities with iMSI-RX to work around hardware bug
  • eddd0159a876 of/address: Fix NULL bus dereference in of_pci_range_parser_one()
  • 77dbb248a5cc netfilter: ipset: do not update comments from kernel-side hash adds
  • f0541a775d04 net/smc: fix socket use-after-free during link group termination
  • b12378f6d1bb mshv: fix hv_input_get_system_property struct
  • 7e02cb30e8a1 ksmbd: reject repeated SMB2 NEGOTIATE requests
  • e7acfc990c29 ipvs: do not propagate one-packet flag to synced conns
  • 9a2b637aef4e igc: remove napi_synchronize() in igc_down()
  • df07003b5a6c igbvf: Fix leak in TX DMA error cleanup
  • a28d8903bfe7 fou: Fix use-after-free in fou_create()
  • 378768dbce47 e1000: fix memory leak in e1000_probe()
  • 5ccf1b76c239 dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+
  • 53f0aa37eb94 ALSA: usb-audio: Clamp frame size in implicit-feedback mode
  • bd65b7191683 ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set
  • 2b7a0f330dd9 ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
  • 98dbfbb38e29 ALSA: usb-audio: fix stack info leak in RME Digiface status
  • ae388c0e1bf7 ALSA: usb-audio: fix use-after-free in ump_to_endpoint()
  • 3164ce8ca109 ata: libata-scsi: schedule deferred atapi command
  • 5f19cc10afaa ata: libata-scsi: terminate deferred commands on time out
  • 1d8e0ff6eab8 ata: libata-sata: fix ata_scsi_lpm_supported() iteration
  • 410f7290dc15 ata: libata-eh: Increase STANDBY IMMEDIATE timeout
  • a4c7ae006ff5 ASoC: tas2562: fix broken entries in the volume lookup table
  • 97d20ff1ab70 ASoC: tas2562: fix DVC coefficient write order
  • 7e65b396192f ASoC: fsl_easrc: fix m2m_init error path to use goto instead of bare return
  • 637f7b361f10 ASoC: fsl_asrc: fix m2m_init error path to use goto instead of bare return
  • c57001f55f97 ALSA: ump: fix double free of out_cvts on rawmidi error
  • 0c561fab5099 ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes
  • 42c6543ff27e ALSA: seq: Fix division by zero in initialize_timer()
  • db09bc4ab19c ALSA: pcm: wake linked drain waiters on unlink
  • 1863097b1713 ALSA: lx6464es: fix period byte count for 16-bit streams
  • 61ddb594dba5 ALSA: hda/realtek: Add quirk for TongFang X6SP45xU
  • 630c8d6a93cb ALSA: 6fire: Fix UAF at error handling during probe
  • daaa726b14fc afs: Fix UAF when sending a message
  • cb20530c81eb afs: Fix afs_fs_fetch_data() to subtract transferred from len
  • 616a3b534e32 afs: Fix afs_fs_fetch_data() to set call->async
  • 8f0a7004755b bpf: lwt: Fix dst reference leak on reroute failure
  • 9c841f59e10b Bluetooth: HIDP: validate numbered report payloads
  • 854194494a6f Bluetooth: HIDP: reject frames without a transaction header
  • b16ebdbebd2d Bluetooth: hci_sync: Fix advertising data UAFs
  • 51be7280980f Bluetooth: mgmt: fix UAF in pair command cancellation
  • 8fe627192fa5 Bluetooth: SCO: give the socket its own sco_conn reference
  • 35464ff81816 Bluetooth: mgmt: fix pending command UAF in EIR updates
  • d9de4bd6bdf4 Bluetooth: btmtk: Fix short read errors in btmtk_usb_reg_read()
  • 1023e4524625 Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read()
  • 0fdd312c1396 Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req()
  • 5b8f46864f06 audit: fix potential use-after-free in audit_del_rule()
  • e18946575480 audit: fix potential integer overflow in audit_log_n_string()
  • bfa28cf99eb4 sctp: validate Adaptation Indication parameter length
  • 48c073f88c93 dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister
  • fbfe683f8b1a KVM: s390: pci: Validate AIBV and AISB before pinning guest pages
  • d1a103dc9016 KVM: s390: pci: Fix NULL dereference on AIBV allocation failure
  • 6a3339023e08 KVM: s390: pci: Fix resource leak on IRQ registration failure
  • 239d8c02c839 KVM: s390: pci: Fix missing error codes and memory unaccounting
  • e3f732e086e4 KVM: s390: pci: Fix memory accounting for pinned/unpinned pages
  • 591952b63a9f KVM: s390: pci: Reject adapter interrupt forwarding if already enabled
  • 89f9e8398e79 KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active
  • 2451c2f95c78 KVM: VMX: add memory clobber to asm for VMX instructions
  • c56baa99c5f4 tracing/fprobe: Roll back on enable_trace_fprobe() failure
  • cad531c857f4 tracing/probes: Reject $arg0 in meta argument expansion
  • ed56a6b58222 KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs
  • e2036b052a19 mm/vmstat: fold stranded per-cpu node stats when a node comes online
  • 43d3c86b1e80 userfaultfd: wait on source PMD during UFFDIO_MOVE
  • ac1bb7fd4508 mm/hugetlb: fix list corruption in allocate_file_region_entries()
  • 5c7fc39bf19a mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()
  • f7e22bcbec1a fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes
  • e20086c3be6e fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes
  • 45f6333ef56c selftest: fix headers in fclog.c
  • c64932457120 mm/util: don't read __page_2 for order-1 folios in snapshot_page()
  • 42f30fa5481a mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE
  • bcd83664c1c5 ocfs2: fix boundary check in ocfs2_check_dir_entry() to use buffer offset
  • c6e484fecc4d btrfs: zoned: fix missing chunk metadata reservation
  • afe9f6f9b6be lib: test_hmm: use device devt for coherent device range selection
  • 8ddfd1c1302d fortify: Disable -Wstringop-overread in tests
  • 8612c37c7e06 pinctrl: bm1880: add missing select GENERIC_PINCONF
  • e52da169b8c0 erofs: cap LZMA stream pool size
  • 6fedc49478be btrfs: raid56: fix scrub read assembly submitting no reads
  • 9d00a5ac7cd3 pinctrl: devicetree: don't free uninitialized dev_name on error path
  • f49b37761f24 pinctrl: microchip-sgpio: add missing select REGMAP_MMIO
  • 2fa11c60c9c0 mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()
  • fceb6b7f3dde mm: mglru: fix stale batch updates after memcg reparenting
  • 51b4c3743ab2 ACPI: CPPC: Check all controls for fast switching
  • 3edc387ba188 kbuild: Stop modifying $(objtree)/Makefile when building oot-kmods oos
  • 4e74a3692364 iommu/iommufd: Fix IOPF group ownership UAF
  • 8eb077025279 iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace
  • 41e615bc0e95 iommufd: Reject DMABUF pages from the access pin path
  • 0827a1ce6572 iommufd/viommu: Publish a vDEVICE only after vdevice_init() succeeds
  • ca9e49e1c893 iommufd/viommu: Release the igroup lock on the vdevice_size error path
  • 6f9fe8087bf1 ring-buffer: Fix subbuf_ids memory leak in rb_allocate_cpu_buffer() error path
  • bfc58bfd2415 mshv: Publish VP to pt_vp_array before installing the file descriptor
  • eba2bf5daa79 mshv: Order pt_vp_array publish against irqfd assertion path
  • 3fb8a6e89abe mshv: Fix missing error code on VP allocation failure
  • 363a6500ff31 mshv: Fix level-triggered check on uninitialized data
  • 4529a41a675b mshv: Fix race in mshv_irqfd_deassign
  • 4a869be56e9f iomap: add a separate bio_set for iomap_split_ioend
  • d53536329982 ksmbd: use memcmp() to compare ClientGUIDs
  • cffbdc86393b ksmbd: fix use-after-free in __close_file_table_ids()
  • a52601f2e2b4 ksmbd: return success for deferred final close
  • 54382aa779da drm/i915/hdmi: Poll for 200 msec for TMDS_Scrambler_Status
  • 6f1ef8170d3d qede: sync udp_tunnel ports outside qede_lock in the recovery path
  • bd2fc7a71dd2 spi: spi-nxp-fspi: add per-SoC SDR/DTR clock rate limits for all supported SoCs
  • 3ab00c9fd420 sched/deadline: Use revised wakeup rule only for running dl_server
  • aeddda24726c octeontx2-pf: Set correct sequence for carrier off and tx queue stop
  • 7416702c30ac net: libwx: fix FDIR ATR queue mismatch for software VLAN packets
  • 8486038decc6 ptp: netc: fix potential interrupt storm caused by incorrect unbind order
  • bc8ccdc869d5 net: mana: Return error code from mana_create_rxq()
  • 690ecb7bdfab net: mana: Create separate EQs for each vPort
  • 11b83d56d5f5 net: stmmac: Fix E2E delay mechanism
  • 0f30be7f2922 net: dsa: mt7530: error out on failed reads in MT7531 PHY polling
  • f3fc89593ef7 net: dsa: mt7530: error out on failed reads in ATC/VTCR command polling
  • fdefb3409f1c net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend
  • 9474b1eead40 riscv: vdso: Only try to install vDSO when present
  • 5cbcd7e4a18a ipv6: release fib6_null_entry on subtree failure
  • e0d8d33bac3b ring-buffer: Fix reader page read offset for remote buffers
  • 1bb0ef8069ef riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove
  • e9b98da3355e accel/qaic: use sizeof(*trans_hdr) for transaction length check
  • 25f228e6ac57 riscv: drop __init from vec_check_unaligned_access_speed_all_cpus
  • 60234845142f tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions
  • d9d771a6e503 tracing/mmiotrace: Reset dropped_count in mmio_reset_data()
  • ac61f5b01dfe fprobe: Fix module reference count leak on error in register_fprobe()
  • b641bfb518a3 drm/xe/pt: check no-DMA huge-pte cases before DMA segment test
  • fdffacb12279 drm/i915/dp: Ignore the sink's DSC max FRL rate without a PCON DSC encoder
  • ffa229d67de5 can: isotp: check register_netdevice_notifier() error in module init
  • 64442a301711 net: sxgbe: check descriptor ring allocation failures
  • f2e5bb9fb710 net: sxgbe: free TX rings on RX allocation failure
  • a29db0c7f695 scsi: ufs: core: Initialize hba->rpmbs list in ufshcd
  • df817b19dac7 scsi: mpi3mr: Fix potential deadlock in mpi3mr_fault_uevent_emit
  • d3c6b0f48f12 octeontx2-af: Block VFs from clobbering special CGX PKIND state
  • b21a2571f530 octeontx2: cn20k: Coordinate default rules with NIX LF lifecycle
  • bb0894e1eef6 scsi: target: Clear cmd_cnt when initial counter enrollment fails
  • deff324a327b scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req
  • 80aae06187d8 scsi: ufs: core: Revert "Delegate the interrupt service routine to a threaded IRQ handler"
  • 9265806bd1f9 scsi: ufs: core: Cancel RTC work in active-active suspend
  • f15bcf9a99b1 scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE
  • 4dc5361dd284 net: phylink: put link_gpio if phylink_create fails
  • f0bc7e69ba1b x86/boot: Add volatile, clobbers and zero-length test in memcmp()
  • 3f2ce63fe551 Bluetooth: hci_sync: remove unnecessary hci_conn_get in create_conn_sync
  • 236e5387cb09 Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync
  • e6792adef614 Bluetooth: hci_sync: hold conn in hci_past_sync() callback
  • c53c70ec289e Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback
  • 2d91e6244b69 Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback
  • 9a77f296aff4 Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks
  • fa812cfa81aa Bluetooth: hci_conn: hold conn reference in abort_conn_sync()
  • 6ec9c3dc5230 Bluetooth: btintel: Validate length before parsing diagnostics TLV
  • 876a3e94c70d Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero
  • 8208b4939afb Bluetooth: ISO: fix refcounting of iso_conn
  • cdce8af9291d Bluetooth: ISO: ensure no dangling hcon references in iso_conn
  • 3c3d5f85db80 Bluetooth: ISO: avoid deadlocks in iso_sock_timeout
  • e30e5ca63c8f Bluetooth: ISO: fix leaking sk after socket release
  • 1308d72903d7 Bluetooth: ISO: hold sk properly in iso_conn_ready
  • 171e71a6d661 Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis()
  • c46c7a22c496 Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos
  • 9bee7e476534 Bluetooth: ISO: lock sk in iso_connect_ind
  • 202670e6602e Bluetooth: ISO: lock sk in iso_sock_getname
  • b7dbf53fb3ca Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release
  • 09f447accc25 Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp
  • 69a4a7b162b3 Bluetooth: ISO: clear iso_data always when detaching conn from hcon
  • 4d0644bd7821 ice: suppress DPLL errors during reset recovery
  • b7f2c666fae8 idpf: Fix mailbox IRQ name leak on request failure
  • 372f458eef99 idpf: adjust TxQ ring count minimum
  • 41bb8748124d idpf: bound interrupt-vector register fill to the allocated array
  • 95599c050359 hwmon: (pmbus) Fix return value from pmbus_update_byte_data()
  • 7eb46318d539 net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller
  • 3f6d7f8a5416 netfs: Fix folio_queue ENOMEM in writeback by adding a mempool
  • 935e7b74bb23 netfs: release readahead folios on iterator preparation failure
  • e65e0c057664 netfs: handle single writeback rolling buffer allocation failure
  • 614b7f4bfcf6 netfs: clear PG_private_2 on copy-to-cache append failure
  • 47fb04c3826e wifi: mac80211: validate individual TWT params before driver setup
  • b322532a4b77 net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister()
  • 313cb9ffc410 net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds
  • c7116f38131d powerpc/boot: Fix treeboot-akebono CPU node lookup check
  • fe85d44d2c08 powerpc/boot: Fix treeboot-currituck CPU node lookup check
  • be2471a5af6d powerpc/boot: Fix simpleboot CPU node lookup check
  • f7bf8803e39c ethtool: Embed FEC hist ranges as buffer in struct
  • de691dc3227b rtase: fix double free of multi-frag skb on DMA map failure
  • 3a1c578d8539 hwmon: (adt7470) Fix PWM auto temp state array and bounds check
  • 76963b04b2d1 hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read
  • fe3c8c93d02d hwmon: (adt7470) Use cached PWM frequency value
  • c48557dc66c1 hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks
  • c6540a03838b hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read()
  • 5ea299c3aa42 hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread
  • 8a9492c467d6 hwmon: (adt7470) Fix cache updated before hardware write on I2C error
  • c8ee73e540f3 hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors
  • 201e05aa531e forcedeth: fix UAF of txrx_stats in nv_remove
  • 693ebff3e777 ASoC: sophgo: return 1 on volume change in cv1800b_adc_volume_set()
  • fec7c738e0f7 net: bridge: mrp: fix Option TLV length in MRP_Test frames
  • 4ad2972ef0e1 hwmon: (nct6775-core) Prevent access to unsupported weight registers
  • 828f6670d110 net: do not send ICMP/NDISC Redirects when peer allocation fails
  • 6a2dbce5da2d hwmon: (nzxt-smart2) DMA-align output buffer
  • f0b791a00651 hwmon: (lm90) Only report alarms if driver is ready
  • 1fb41650bc3e hwmon: (sht3x) Fix unaligned accesses
  • a0668ac20fea hwmon: (ltc4282) Fix reading the minimum alarm voltage
  • e9374bbeb8b7 hwmon: (ina2xx) Fix various overflow issues
  • a7f47f5246cd hwmon: (nct6775-core) Fix number of temperature registers for NCT6116
  • 8e89cc882f0a spi: spi-cadence: Move TX FIFO full busy-wait into FIFO
  • c0c99275cce5 ASoC: tas2781: Use correct calibration data for SINEGAIN2 register
  • 234b5cb81e6f wifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup()
  • 9703abd39ef0 ACPI: CPPC: Skip writes to unsupported performance controls
  • fbfa371a2fb3 gpio: gpio-by-pinctrl: Apply initial value in direction output wrapper
  • 3879657c4ffd erofs: ensure valid f_path for page cache sharing
  • f6145794f17a erofs: remove fscache backend entirely
  • fce6cd6f9845 erofs: clean up erofs_ishare_fill_inode()
  • b3e97ba24110 smb: client: fix buffer leaks in SMB1 read and write
  • b9c44a140620 scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race
  • b0aa3e8e2ab4 scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer
  • 1f07a897d43c scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer
  • a7c855969b1a pinctrl-amd: Don't clear S4 wake bits at probe
  • 3bb9cbcd944b net/sched: sch_cake: skip clearing unused tins during rate adjustment
  • e7ce2bad0c33 xsk: reclaim invalid Tx descriptors in ZC batch path
  • be1b85613ca7 xsk: provide sufficient space in pool->tx_descs
  • 5e94d74e4f3b xsk: drain continuation descs after overflow in xsk_build_skb()
  • a0528ab6af62 xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx
  • b0d8ecdac394 selftests/net/af_unix: test listen() rejects wrong socket states
  • 6c88d205c732 af_unix: fix listen() succeeding on sockets in the wrong state
  • 44f53e4331a3 nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush
  • bb2b072c619c nexthop: take nh->lock for f6i_list walks in replace check and notify
  • 8398bc477d3c rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()
  • 6a4d9d37c1c0 ASoC: SDCA: Ensure that Control Range is large enough for header
  • fe5c53a95297 ASoC: SDCA: Make UMP message size check more robust
  • 3712e66064a2 ASoC: SDCA: Always free firmware in FDL path
  • 5c595f2ef60a ASoC: SDCA: Correct pointer passed to devm_acpi_table_put
  • 630295d5bba1 netfilter: nft_payload: fix mask build for partial field offload
  • da286d421b9a ipvs: clear the nfct flag under lock
  • 92600ca75fda ipvs: do not mangle ICMP replies for non-first fragments
  • 79c1254f3dbd ipvs: fix places with wrong packet offsets
  • 5558a85add07 ipvs: fix the checksum validations
  • 06a76334243c netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
  • 7d4789b58761 netfilter: nf_tables: make nft_object rhltable per table
  • eec19d7c90cb ipvs: adjust double hashing when fwd method changes
  • 24053cfe4d50 assoc_array: trim the final shortcut word using the current chunk end
  • 7e5397a3fed0 keys: make keyring key-chunk byte order agree with keyring_diff_objects()
  • 8dba33c1e779 keys: fix out-of-bounds read in keyring_get_key_chunk()
  • b16272fe8916 KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type
  • 92e2c891a06b KVM: arm64: Reject guest_memfd memslots when the VM has MTE
  • c71729aab77d KVM: arm64: Add missing hyp_enter when trapping sysreg
  • 4c51944735f1 KVM: arm64: Fix hyp_trace_desc allocation size in hyp_trace_load()
  • c9a590838b73 KVM: arm64: Fix potential leak in hyp_trace_buffer_alloc_bpages_backing
  • 67baa93486bc KVM: arm64: Fix hyp_trace clock disabling
  • 72aea30c76d3 KVM: arm64: vgic: Mitigate potential LPI registration failure
  • 292e80a159aa KVM: arm64: vgic: Fix race between LPI release and re-registration
  • 668120335b89 mshv: Fix sleeping under spinlock in mshv_portid_alloc
  • c34ac583c2fa mshv: Fix duplicate GSI detection for GSI 0
  • 35dbc4cc58ce Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation
  • ccfb70d92a52 mshv_vtl: fix fd leak in mshv_ioctl_create_vtl()
  • 068f84c542b3 drm/mediatek: Check CRTC state before freeing
  • 8501ca88419a netfilter: nf_conntrack_expect: add and use nf_ct_expect_related_pair()
  • 5b361672720c selftests: netfilter: nft_flowtable.sh: fix offload counter verification for tunnel tests
  • ef5e2c6555d2 netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()
  • a6b6d16a5e1c phy: zynqmp: fix runtime PM leak on probe allocation failure
  • efea649f214f phy: zynqmp: fix clock error handling in xpsgtr_phy_init()
  • e8c5c80a20c7 rtla/timerlat_top: Fix on-threshold actions firing on signal
  • ed0d2e33fab5 ntfs: drop stale page-cache when shrinking a non-resident attr
  • 57e7b8bf7b02 ntfs: harden runlist realloc size calculations
  • 0e9dbc6d1f0d btrfs: zoned: skip fully truncated ordered extents at zone finish
  • 20f6badf1c2a btrfs: raid56: fix an incorrect csum skip during scrub
  • 076349e4c8d1 btrfs: skip global block reserve accounting for rescue mounts
  • b0c33c0628c5 btrfs: warn about extent buffer that can not be released
  • 920fe5b8317c btrfs: zoned: reset meta_write_pointer on zone reset
  • 75859a7cd77c btrfs: zoned: fix deadlock between metadata writeback and transaction commit
  • ec7959ecbfb0 btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag
  • de8ccbd6bf4e of: reserved_mem: prevent OOB when too many dynamic regions are defined
  • 0cd45057cd4b ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup
  • 4f385927d295 ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup
  • 5815ae160add phy: qcom: m31-eusb2: Fix return value of init call
  • 35ede850a936 ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources()
  • 99417b0dd4db ata: sata_mv: accept 1 or 2 resources in platform probe
  • 4180b67aeb8f ntfs: preserve RECALL_ON_OPEN on WSL special-file reparse points
  • 321c437d5c9c selftests/seccomp: Fix pointer type mismatch build error
  • 1dcffb3ecf54 selftests/lkdtm: rename STACKLEAK_ERASING to KSTACK_ERASE
  • 96c25ed04aa7 gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe()
  • 0acbc621341a iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE
  • 6e26a41c4c1a dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open()
  • c93a9f652b73 dmaengine: idxd: fix double free of wq, engine, and group structs
  • d4ba6aa65fcd dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA
  • dffcf5d44213 pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151
  • 85997b1c6a2e pinctrl: qcom: Unconditionally mark gpio as wakeup enable
  • 4087bf79d2a8 dmaengine: switchtec-dma: fix FIELD_GET misuse when programming SE threshold
  • f78f08b38a7f KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context
  • 2aa2cde2cc79 thunderbolt: Prevent XDomain delayed work use-after-free on disconnect
  • bd3fb6b74a49 ALSA: hda/realtek: Add quirk for HP Dragonfly Folio G3 2-in-1 (103c:8a05)
  • ebefca49e4c6 mm/slab: prevent unbounded recursion in free path with new kmalloc type
  • 2e048fda7bc7 lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled()
  • 4349e4dd25b2 mm/slab: decouple SLAB_NO_SHEAVES from SLAB_NO_OBJ_EXT
  • 2dc2fffc704a net: mpls: initialize rtm_tos in mpls_getroute()
  • c7ba9d6de43e Linux 7.1.7
  • 61649a2d61cb x86/bugs: Make Safe-RET robust against interrupt injection

View originalPermalink

7.1.6-xanmod1
  • 6db734bb161f Linux 7.1.6-xanmod1
  • ba65783d88c0 Merge tag 'v7.1.6' into 7.1
  • 2609d60e2f6d Linux 7.1.6
  • 96f1a2309bd4 cifs: consolidate time_last_write stamp into _cifsFileInfo_put()
  • edfc6bf57524 cifs: fix time_last_write stamp placement in setattr/truncate paths
  • 6b542d116ace KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug
  • a86ceb3291ec selftests: drv-net: so_txtime: relax variance bounds
  • ea2e0c28609a selftests: drv-net: cope with slow env in so_txtime.py test
  • 97c09c9f5739 sched_ext: Preserve rq tracking across local DSQ dispatch
  • 046899bcfc2d sched_ext: Move shared helpers from ext.c into internal.h and cid.h
  • 1e37f12b040e bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline()
  • 18c946a3b7b0 bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c
  • 63ba393d279c net: mana: Optimize irq affinity for low vcpu configs
  • 760c47bce6f5 mm/sparse-vmemmap: fix DAX vmemmap accounting with optimization
  • 9ea8940dec3d mm/sparse-vmemmap: pass @pgmap argument to memory deactivation paths
  • 390187672abf SUNRPC: Return an error from xdr_buf_to_bvec() on overflow
  • ee055a047290 SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists
  • 8fe8da8edc45 xfs: don't replace the wrong part of the cow fork
  • 2cd945492bc5 fuse-uring: fix race between registration and connection abortion
  • 3b601938314c audit: fix recursive locking deadlock in audit_dupe_exe()
  • ea5ded52bd08 audit: use 'unsigned int' instead of 'unsigned'
  • e528ff627fde drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources
  • 61fd3559199f ksmbd: validate ACE size against SID sub-authorities
  • a0ebdaa79e10 ksmbd: bound DACL dedup walk to copied ACEs
  • bc90144ce8bb ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL
  • 5acbd3012fd4 ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
  • a75b4f3fe9cd selftests: drv-net: add missing kconfig for psp.py
  • be354ea7261c drm/amdgpu: fix check in amdgpu_hmm_invalidate_gfx
  • caf4f872eec3 drm/amd/pm: fix smu13 power limit range calculation
  • f5988b5c300a drm/amdgpu: fix aperture mapping leak
  • 1050d258c7c5 drm/amdgpu: reject mapping a reserved doorbell to a new queue
  • 930a5dc3df4a drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
  • 92789e28b08f drm/amdgpu: fix resource leak on ACP reset timeout
  • 5bc93f907bad drm/amdgpu: Fix kernel panic during driver load failure
  • be725ab23aa4 drm/amdgpu: fix division by zero with invalid uvd dimensions
  • afdff9103818 drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()
  • c309626bf91f drm/amdgpu/vcn4: avoid rereading IB param length
  • 00c311a13d22 drm/amdgpu/vce: fix integer overflow in image size
  • 253b1401862b drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON()
  • cbe3b293d0ee drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()
  • 6423b44b2e0b drm/amdgpu/mes11: set doorbell offset for suspending userq
  • 301f39acf779 drm/amdgpu/jpeg: fix jpeg_v5_0_1_is_idle detection
  • 6b4e19378d94 drm/amdgpu/jpeg: fix jpeg_v4_0_3_is_idle detection
  • 43768ad42b8f drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()
  • ac89ea915e8b drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()
  • db85aa861b82 drm/amdgpu/gfx8: drop unecessary BUG_ON()
  • 81597685c0d7 drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()
  • 4fbcd92047ff drm/amdgpu/gfx12: fix EOP interrupt routing for KQ and userq
  • 51f67bd8a71a drm/amdgpu/gfx11: fix EOP interrupt routing for KQ and userq
  • 1c27e889fa16 drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON()
  • 2929a932b0d7 drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()
  • 69a2c5be437b drm/amd/pm: make pp_features read-only when scpm is enabled
  • 1c2a60c187ec drm/amd/pm: fix amdgpu_pm_info power display units
  • 9423c88cde9a watchdog: s32g_wdt: remove incorrect options in watchdog_info struct
  • 54a3c27b357d vxlan: mdb: Fix source list corruption on a failed replace
  • 23b44803112a vsock/virtio: collapse receive queue under memory pressure
  • f9596b156661 tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
  • 22cec809b048 tcp: challenge ACK for non-exact RST in SYN-RECEIVED
  • a859b280441f tcp: initialize standalone TCP-AO response padding
  • 0f54f5048615 rtase: Workaround for TX hang caused by hardware packet parsing
  • bed4caecd723 pppoe: reload header pointer after dev_hard_header()
  • ee6c5b5194f1 ovpn: hold peer before scheduling keepalive work
  • f08f39c1f43f ovpn: fix peer refcount leak in TCP error paths
  • ea85dbcbe8d4 openvswitch: fix GSO userspace truncation underflow
  • 06a6b606129c mctp: serial: handle zero-length frames to prevent rx buffer overflow
  • e09e0301d616 mac802154: llsec: reject frames shorter than the authentication tag
  • 5f303f622f6b mac802154: hold an interface reference across the scan worker
  • c6a13ae00dab ila: reload IPv6 header after pskb_may_pull in checksum adjust
  • 33dc0dfb480e ice: use READ_ONCE() to access cached PHC time
  • 33cc15aaf249 ice: reject out-of-range ptype in ice_parser_profile_init
  • 689b9f588d2d gve: fix Rx queue stall on alloc failure
  • b62c510f5980 ksmbd: validate minimum PDU size for transform requests
  • 0ff12308c8a6 ksmbd: defer destroy_previous_session() until after NTLM authentication
  • 6e4d2eeccfb9 smb: client: handle STATUS_STOPPED_ON_SYMLINK responses without a symlink target
  • b1a613669332 rbd: Reset positive result codes to zero in object map update path
  • 4c483644d1a7 super: fix emergency thaw deadlock on frozen block devices
  • 14fceda28069 ice: fix PTP Call Trace during PTP release
  • 545a7fdbc110 ptp: ptp_s390: Add missing facility check
  • 6d828e3a353c s390/ptff: Export ptff_function_mask[]
  • 21231d8c6ca4 proc: Fix broken error paths for namespace links
  • 7479c6e8235c net: qrtr: ns: Raise node count limit to 512
  • 6bbdf8744de3 net: pcs: xpcs: fix SGMII state reading
  • a0f247d63489 net: hip04: fix RX buffer leak on build_skb failure
  • fc0c0f7a207f net: gro: fix double aggregation of flush-marked skbs
  • 9aabda553184 net/x25: fix use-after-free in x25_kill_by_neigh()
  • fb29e1b41052 net/sched: serialize qdisc_rtab_list against concurrent get/put
  • a60c81f168c9 net/mlx5e: Use sender devcom for MPV master-up
  • f579582c03ed net/iucv: fix use-after-free of a severed iucv_path
  • 0e857185591f net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
  • 95f45e20f1b2 geneve: require CAP_NET_ADMIN in the device netns for changelink
  • 0e37bbd6d617 net: slip: serialize receive against buffer reallocation
  • e8ad0d311e22 vxlan: require CAP_NET_ADMIN in the device netns for changelink
  • 25e3641beb51 phonet: pep: fix use-after-free in pep_get_sb()
  • d0bba984703d net: stmmac: intel: skip SerDes reconfig when rate is unchanged
  • 9b243e2f1756 mm/slab: fix a memory leak due to bootstrapping sheaves twice
  • 0b7f04a0abb4 mm/slub: fix lost local objects when bulk remote free batch fills
  • db57cc63a6e5 iommu/vt-d: Disallow SVA if page walk is not coherent
  • c5b6a48a8a71 iomap: fix out-of-bounds bitmap_set() with zero-length range
  • 579b0f5c528c io_uring/rw: fix missing ERESTARTSYS conversion in read paths
  • e807c9193d94 ftrace: Add global mutex to serialize trace_parser access
  • bc2d630296e0 fscrypt: Avoid dynamic allocation in fscrypt_get_devices()
  • 466f187b501a fscrypt: Add missing superblock check in find_or_insert_direct_key()
  • ca03a7984a34 fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
  • 64017df6e61a fs/super: fix emergency thaw double-unlock of s_umount
  • 69ecc199880b binfmt_elf_fdpic: only honour the first PT_INTERP
  • d2cba2e7a513 ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP
  • e01f47367a63 ASoC: fsl: imx-card: Skip sysclk reset for active DAIs in shutdown
  • 006340cf0688 amt: fix use-after-free in AMT delayed works
  • b9fedda2f628 libceph: remove debugfs files before client teardown
  • 70998f91030e libceph: reject zero bucket types in crush_decode
  • 3b249546f59c libceph: Reject monmaps advertising zero monitors
  • 5ecfcd5c0586 libceph: refresh auth->authorizer_buf{,_len} after authorizer update
  • db9cc9fd9660 libceph: guard missing CRUSH type name lookup
  • a54be593d0b7 libceph: fix two unsafe bare decodes in decode_lockers()
  • bee4b5b53e7b libceph: Fix multiplication overflow in decode_new_up_state_weight()
  • e36663145abd libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
  • 0d934c934ec7 libceph: bound get_version reply decode to front len
  • 0ce001e7fdf7 ceph: fix writeback_count leak in write_folio_nounlock()
  • f3247851d63e ceph: fix refcount leak in ceph_readdir()
  • 71893c342a26 ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
  • 37ff9794be48 sctp: close UDP tunnel sockets during netns teardown
  • a50e73488e0b sctp: avoid auth_enable sysctl UAF during netns teardown
  • d136b29bf91d sctp: don't free the ASCONF's own transport in DEL-IP processing
  • 7375e2699582 mm/huge_memory: set PG_has_hwpoisoned only after new folio head is established
  • ab6209f4b48a mm/page_vma_mapped: fix device-private PMD handling
  • a4b3a8dcc3d0 mm/memory-failure: trace: change memory_failure_event to ras subsystem
  • 02542f35129d mm/kmemleak: fix checksum computation for per-cpu objects
  • e33adf96afb5 mm/damon/core: disallow overlapping input ranges for damon_set_regions()
  • f4145cec7005 m68k: avoid -Wunused-but-set-parameter in clear_user_page()
  • 43aaddd0fa92 mm/damon/core: validate ranges in damon_set_regions()
  • 0c26202b157f userfaultfd: prevent registration of special VMAs
  • 31a62e4ad663 btrfs: do not try compression for data reloc inodes
  • bfdfc7782ada afs: Fix afs_edit_dir_remove() to get, not find, block 0
  • c019163e9382 selftests: mptcp: userspace_pm: fix undefined variable port
  • 40dde4b5d982 mptcp: pm: userspace: fix use-after-free in get_local_id
  • fb3f056a9416 mptcp: only set DATA_FIN when a mapping is present
  • 625fc6060864 mptcp: fix stale skb->sk reference on subflow close
  • cb9d3163ef38 mptcp: fix BUILD_BUG_ON on legacy ARM config
  • d6d2261e3475 mptcp: decrement subflows counter on failed passive join
  • 4cf89c430acc Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates"
  • e59c2476ef75 arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates
  • f3530aec2656 arm64: make huge_ptep_get handled unaligned addresses
  • 5b50f9fd58be tracing/remotes: Fix page_va[] access before counter update in trace_remote_alloc_buffer()
  • b174d40adda6 tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err()
  • 02d6f022c7ff tracing/probes: Fix potential underflow in LEN_OR_ZERO macro
  • 1ddf73ad334f tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args()
  • 1e8d254cb586 tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match()
  • 8f188dd11a1c ublk: wait on ublk_dev_ready() instead of ub->completion
  • 9899a6af1c5e tracing: Propagate errors from remote event bulk updates
  • be94a3a77e7e tracing: perf: Fix stale head for perf syscall tracing
  • 43a23dfe0024 tracing: Fix union collision of module and refcnt for dynamic events
  • cb459fec4f7b tracing: Fix resource leak on mmiotrace trace_pipe close
  • 724cd84b0546 tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
  • 57027f360231 tracing: Fix context switch counter truncation
  • 159fdc3e01dc tracing: Delay module ref count for "enable_event" trigger
  • 9e9a82d00c3d misc: nsm: pin the module while the device is open
  • f318f5a872cb misc: nsm: only unlock nsm_dev on post-lock error paths
  • c3a28f9cb824 intel_th: fix MSC output device reference leak
  • 7cf79e8d682f mei: bus: access mei_device under device_lock on cleanup
  • e089aa3f09ce selftests: ntsync: correct CONFIG_NTSYNC name
  • 8cbad52ccfa6 serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms
  • 863230250dd5 serial: sc16is7xx: implement gpio get_direction() callback
  • f5f663469ad2 uio_hv_generic: Bind to FCopy device by default
  • 5d059ce0e6a2 comedi: comedi_parport: deal with premature interrupt
  • 6ed367bbbf4d x86/boot/compressed: Disable jump tables
  • b5ed54a37ad5 firmware: stratix10-svc: handle NO_RESPONSE in async poll
  • 7b14f42c7460 firmware: stratix10-svc: fix teardown order in remove to prevent race
  • 8e93a083456d firmware: stratix10-svc: fix memory leaks and list corruption bugs
  • 4169d9fb92f3 rhashtable: clear stale iter->p on table restart
  • f3e2715a1500 cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
  • 496bc868d906 LoongArch: Retrieve CPU package ID from PPTT when available
  • 881e9f3c4e11 LoongArch: Move jump_label_init() before parse_early_param()
  • a30a69678fca LoongArch: Increase TASK_STRUCT_OFFSET up to 2040 for 32BIT
  • eca63bd15580 LoongArch: Fix oops during single-step debugging
  • 3cfc4bd63574 LoongArch: Fix build errors due to wrong instructions for 32BIT
  • 7a54e0cbaad4 LoongArch: Fix address space mismatch in kexec command line lookup
  • 2d342c8b79c1 objtool/rust: add one more noreturn Rust function for Rust 1.99.0
  • fd661e6c1f64 rust: allow clippy::unwrap_or_default globally
  • a73bcfeacd67 rust: allow suspicious_runtime_symbol_definitions lint for Rust >= 1.98
  • d7c36d58f16d rust: device: avoid trailing ; in printing macros
  • 132fc107b973 rust: time: fix as_micros_ceil() to round correctly for negative Delta
  • 9be9bb59f485 rust_binder: only print failure if error has source
  • 95e27b4ba4e5 platform/loongarch: laptop: Explicitly reset bl_powered state when suspend
  • 5ccc99d58f94 binfmt_misc: set have_execfd only once the interpreter is opened
  • 55fa2c7f2b15 exec: fix unsigned loop counter wrap in transfer_args_to_stack()
  • 98bc68194e37 Bluetooth: RFCOMM: Fix session UAF in set_termios
  • fe13adc258df Bluetooth: hci_sync: Protect UUID list traversal
  • 5968fd6c3f68 staging: rtl8723bs: fix inverted HT40 secondary channel offset
  • 23c31f107b4f staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()
  • 17a4298f7794 wifi: ath12k: fix NULL pointer dereference in rhash table destroy
  • 65ee82c5ee84 wifi: ath11k: fix refcount leak in ath11k_ahb_fw_resources_init()
  • a1734263befc wifi: brcmfmac: set F2 blocksize to 256 for BCM43752
  • 0ca80328df23 wifi: brcmfmac: make release_scratchbuffers idempotent
  • 177a25be1195 wifi: brcmfmac: drain bus_reset work on device removal
  • 03d3291c4b37 wifi: mt76: restrict NPU/PPE active checks to MMIO devices
  • 9677e86a5f7d wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses
  • 24475d2ddc8d wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
  • b2ab73b8123c wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
  • 8ccdf8c8de87 wifi: wilc1000: validate assoc response length before subtracting header
  • cca4398aa305 wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper
  • a3313111b5d9 wifi: ath6kl: fix use-after-free in aggr_reset_state()
  • cec0a487cf38 wifi: ath6kl: fix OOB access from firmware ADDBA window size
  • c1078130a4cd ALSA: timer: don't re-enter an instance callback that is still running
  • 2b2989977868 ALSA: timer: drain a slave's callback before its master detaches it
  • 089b8985a299 ALSA: hda: codecs: hdmi: disable keep-alive before audio format change
  • 31a6163e301d ALSA: seq: close a re-opened queue timer in the destructor
  • f7ba6fa309d4 ALSA: hda/realtek: Fix speakers on Lunnen Ground 14
  • 1a0e99470a0b media: vpif_capture: fix OF node reference imbalance
  • 6d51ad8f1c50 media: vivid: fix cleanup bugs in vivid_init()
  • daf2d92669b4 media: vivid: check for vb2_is_busy() when toggling caps
  • 90204e98c016 media: vivid: add vivid_update_reduced_fps()
  • dd29c4abad00 media: vimc: fix reference leak on failed device registration
  • 260346526b8e media: vidtv: fix reference leak on failed device registration
  • b9b02035b129 media: verisilicon: Export only needed pixels formats
  • 941bf408c5e5 media: vb2: use ssize_t for vb2_read/vb2_write
  • f7b3a27e35a3 media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely
  • 067887ff93fd media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()
  • b01df98a6669 media: v4l2-ctrls: validate HEVC active reference counts
  • ccf9c59704f8 media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete()
  • cd2bcc565619 media: uapi: rkisp: Correct name version enum
  • fcbbaf9cb972 media: ti: vpe: unwind v4l2 device registration on probe error
  • abfaa1b2670c media: ti: vpe: Fix the error code of devm_request_irq()
  • 956879b173c2 media: ti: vpe: Fix the error code of devm_kzalloc() in vip_probe_slice()
  • 6171b55640da media: ti: vpe: Fix fwnode_handle leak in vip_probe_complete()
  • b83120604a39 media: tegra-video: vi: fix invalid u32 return value in format lookup
  • 7dd27810eea0 media: synopsys: hdmirx: Fix HPD lane hold time
  • 668face37fdb media: sun4i-csi: Return queued buffers on start_streaming() failure
  • 4b7ee504969e media: stm32: dcmi: unregister notifier on probe failure
  • 624af2d4b5e9 media: stm32-dcmipp: Return queued buffers on start_streaming() failure
  • 1731dd61b6c0 media: saa7134: Fix a possible memory leak in saa7134_video_init1
  • 18aa963948b7 media: rzv2h-ivc: Wait for frame end in stop_streaming
  • a6709ee3c922 media: rzg2l-cru: Skip ICnMC configuration when ICnSVC is used
  • fc0b18782aab media: rtl2832_sdr: Return queued buffers on start_streaming() failure
  • 90d781711418 media: rtl2832: fix use-after-free in rtl2832_remove()
  • 730c235d7d2c media: radio-si476x: Unregister v4l2_device on probe failure
  • 9ce597c8bdb4 media: qcom: camss: Fix RDI streaming for CSID 340
  • 0495a46a30af media: qcom: camss: Fix RDI streaming for CSID GEN3
  • e0d11cb8b54c media: qcom: camss: Fix RDI streaming for CSID GEN2
  • ea87d4242723 media: qcom: camss: Fix RDI streaming for CSID 680
  • a4f8f629983f media: pwc: Return queued buffers on start_streaming() failure
  • 5d4812668b03 media: pwc: Drain fill_buf on start_streaming() failure
  • 0c2b4c45fce0 media: pci: dm1105: Free allocated workqueue
  • 26edee412cbe media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding
  • 75cdfaa7c908 media: nxp: imx8-isi: Fix potential out-of-bounds issues
  • fe127ea278b9 media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path
  • 9ac81a2bbf70 media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure
  • 9c5ddbabc31f media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe
  • 65ddc021d39d media: nuvoton: npcm-video: fix memory leaks in probe and remove
  • 410398f06c28 media: nuvoton: npcm-video: fix error handling in npcm_video_init()
  • 3673cb0a5711 media: msi2500: Return queued buffers on start_streaming() failure
  • 99f3527bd1a2 media: meson: vdec: Fix memory leak in error path of vdec_open
  • cbe66053094f media: marvell-cam: fix missing pci_disable_device() on remove
  • 3adde045236a media: mali-c55: Power-off the peripheral in remove()
  • 65d442427584 media: mali-c55: Fix possible ERR_PTR in enable_streams
  • f83262ac4437 media: mali-c55: Disable pm_runtime on probe error
  • f9879931b492 media: mali-c55: Add missing of_reserved_mem_device_release()
  • 49cdf03d95e7 media: iris: Fix use IRQF_NO_AUTOEN when requesting the IRQ
  • 54b70e8e682f media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges
  • 739e289bfb6d media: imx219: Fix maximum frame length in lines
  • eb2f934646ae media: i2c: alvium: fix critical pointer access in alvium_ctrl_init
  • e1a6465500b0 media: dw9719: Add back the I²C device id table
  • ff3c670a1de3 media: cx23885: add ioremap return check and cleanup
  • e797e252bfb3 media: cx231xx: fix devres lifetime
  • d681227ce43b media: chips-media: wave5: Move src_buf Removal to finish_encode
  • e53112c2de88 media: cedrus: skip invalid H.264 reference list entries
  • 4c2237c1f8c8 media: cedrus: Fix missing cleanup in error path
  • 578cb3701dd3 media: cedrus: clean up media device on probe failure
  • e94851429828 media: cec: seco: unregister adapter on IR probe failure
  • 578cff91d0b5 media: aspeed: fix missing of_reserved_mem_device_release() on probe failure
  • 32cbe5474e74 media: amlogic-c3: Add validations for ae and awb config
  • 170fcc945bc0 media: airspy: Return queued buffers on start_streaming() failure
  • eeaa0c5feb91 drm/v3d: Reach the GMP through the hub registers on V3D 7.x
  • adf0542659c7 drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict
  • b7fd42da6cb3 drm/gpusvm: Zero HMM PFNs before scanning ranges
  • 921d6acd5761 drm/ttm/pool: back up at native page order
  • 296f4c78f8da drm/pagemap: Guard HPAGE_PMD_ORDER use with CONFIG_ARCH_ENABLE_THP_MIGRATION
  • fe168ef1d232 drm/vc4: Prevent shader BO mappings from becoming writable
  • 6910ccaf4167 drm/vmwgfx: Validate vmw_surface_metadata::array_size
  • 095f1a2502eb drm/pagemap: Clear driver-provided PFNs from migration PFN array
  • c58088a8e744 drm/amd/display: Fix missing DCE check in dm_gpureset_toggle_interrupts()
  • bac4c1a9af69 drm/vc4: Shut down BO cache timer before teardown
  • 57c85f13a3df drm/amd/display: Fix flip-done timeouts on mode1 reset
  • 55440dd29e74 drm/amdgpu: always emit the job vm fence
  • 7d088935c72c drm/amdgpu: Print vmid, pasid and more task info in devcoredump
  • 9743f6001327 drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
  • 50d8e10bf867 drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge
  • 1191285ecb42 drm/amd/display: Fix backlight max_brightness to match exported range
  • 3665fc7f93f1 drm/amd/display: Force PWM backlight on Lenovo Legion 5 15ARH05
  • ed2d86aef9fa drm/amd/display: dce100: skip non-DP stream encoders for DP MST
  • 9a5a582ad96a drm/amd/display: consolidate DCN vblank/flip handling onto vupdate_no_lock
  • 0676fecbb524 drm/amd/display: set new_stream to NULL after release
  • b2c51a7e5786 drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X)
  • 42e80ecdb188 drm/amd: Create a device link between APU display and XHCI devices
  • 3085ae8695e0 drm/amdgpu/userq: fix indefinite fence wait during GPU reset
  • 23131f1f930d drm/amdgpu: Fix VFCT bus number matching with soft filter
  • 9b7de3ee5d2c drm/amdgpu: Release VFCT ACPI table reference
  • f59825d834c0 drm/panthor: return error on truncated firmware
  • 9ddaabf38f7a drm/ttm: Account for NULL and handle pages in ttm_pool_backup
  • 72e4fca5529e drm/gpusvm: publish dpagemap early to avoid device mapping leak on error
  • 7475273d88d8 drm/virtio: Don't detach GEM from a non-created context
  • b5a62e022f42 drm/gfx10: Program DB_RING_CONTROL
  • 5ee1c5784157 drm/amd/pm: fix smu14 power limit range calculation
  • 9061fbf2230b drm/i915/mst: limit DP MST ESI service loop
  • edd4804f07b8 drm/i915/gt: Fix NULL deref on sched_engine alloc failure
  • 97f236379f06 drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU
  • 6cdbef8f60f3 drm/i915/gem: Do not leak siblings[] on proto context error
  • 28ebf07444b0 drm/amdgpu: trigger GPU recovery when userq destroy fails to unmap a hung queue
  • 5d5fb9124a2b drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()
  • 29b4939bd44c drm/amd/amdgpu: disable ASPM on VI if pcie dpm is disabled
  • 625f301e01bf drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()
  • 15fd21a9bba2 drm/amdgpu/soc24: reset dGPU if suspend got aborted
  • 8887b94d2fc9 drm/i915/bios: range check LFP Data Block panel_type2
  • 58b7e63ca0cd drm/i915: Return NULL on error in active_instance
  • 0027cb19b044 drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
  • 2051bbbfbd44 drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
  • 9df8a7f09e30 drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()
  • bcbd53d25da8 drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()
  • 1a07ac63ae5b drm/amdgpu: add the doorbell index input for suspending userq
  • 984085c5b535 drm/i915/hdcp: check streams[] bounds before overflow
  • 41747d37cf56 drm/i915/hdcp: require monotonically increasing seq_num_v
  • c726c8bbee51 drm/i915/vrr: require valid min/max vfreq for VRR
  • 375c1934ef01 drm/virtio: bound EDID block reads to the response buffer
  • fba211b078d6 Revert "drm/amd/display: Restore 5s vbl offdelay for NV3x+ DGPUs"
  • 58ea24dd9684 drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference
  • dbad70d40cad drm/amd/display: use kvzalloc to allocate struct dc
  • b1bd5c2b24f5 drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips
  • ee4efff4b65c drm/amd/display: set MSA MISC1 bit 6 when using VSC SDP for DCE 11.x
  • 000c405fa153 drm/amdkfd: free MQD managers on DQM init failures
  • 865532d54eb5 drm/amdkfd: fix 32-bit overflow in CWSR total size calculation
  • cc10a5839756 drm/amdkfd: Check bounds on CRIU restore queue type and mqd size
  • abeeb1947d81 drm/amdkfd: Check bounds in allocate_event_notification_slot
  • 72c7d449778d drm/amdkfd: Use kvcalloc to allocate arrays
  • 1874a9414cbc drm/amdkfd: Guard m->cp_hqd_eop_control setting by q->eop_ring_buffer_size
  • a0d87beb2660 drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size
  • 15f58d44c244 drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM
  • 401fbe3b6bbb drm/imagination: fix error checking of pvr_vm_context_lookup()
  • 09beaf4aec05 drm/imagination: Fix user array stride in pvr_set_uobj_array()
  • c1136d907fd0 drm/imagination: Fix double call to drm_sched_entity_fini()
  • a6bdbff8f6f5 drm/xe/madvise: Skip invalidation for purgeable state updates
  • 50b6a61d8834 drm/xe/nvm: fix writable override for CRI
  • 90e4fd331b98 drm/xe/pt: Reset current_op in xe_pt_update_ops_init()
  • c4affa4e8bc8 drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC
  • ba8c4cbb31c6 drm/xe: Hold a dma-buf reference for imported BOs
  • 481dc7df8f72 drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds
  • 1e6d07abbc0c drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists
  • 22ad3edd2cec drm/xe/oa: Fix offset alignment for MERT WHITELIST_OA_MERT_MMIO_TRG
  • 7445e1b85159 drm/xe: Return error on non-migratable faults requiring devmem
  • 513346701b1d drm/xe/display: skip FORCE_WC and vm_bound check for external dma-bufs
  • f302e5f3bd33 drm/radeon: fix r100_copy_blit for large BOs
  • 0bb004807da9 drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit()
  • af128ca139d6 drm/i915/mtl+: Enable PPS before PLL
  • c41a54619e95 drm/i915/gem: Add missing nospec on parallel submit slot
  • bcd40ea7788f drm/displayid: fix Tiled Display Topology ID size
  • 28e1cb89f02c drm/amdkfd: Use exclusive bounds for SVM split alignment checks
  • 76e5a52855d7 drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions
  • 983eb36d3b09 drm/sysfb: Return errno code from drm_sysfb_get_visible_size()
  • 9d58a811739a drm/sysfb: Avoid possible truncation with calculating visible size
  • ebbaf64d2635 drm/nouveau: fix reversed error cleanup order in ucopy functions
  • 24668ca3ec19 drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
  • 9f9c88eb298c drm/amdgpu: Fix context pstate override handling
  • c5bf18ff8f2a drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT
  • 73874c6d2539 drm/amdgpu/gfx9: Fix Ring and IB test fail after mode2
  • 9777453ce4f8 drm/amd/display: Restore periodic detection for DCN35
  • 34a7ed214c5e drm/xe: Add compact-PT and addr mask handling for page reclaim
  • a9a020f3c11e drm/xe/guc: Fix buffer overflow in steered register list allocation
  • e7a871390b77 drm/sysfb: Avoid truncating maximum stride
  • aed27dbfb8d6 drm/sysfb: Do not page-align visible size of the framebuffer
  • 9faf4c66edb6 drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO
  • efa292aebc8b drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older
  • bc78482db958 drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2)
  • 9cd9a983769a drm/amdgpu/gfx: fix cleaner shader IB buffer overflow
  • 51af46225f84 drm/amd/pm: re-enable MC access after PrepareMp1ForUnload on SMU V15 APUs
  • 1e9b961f9f45 drm/i915/cdclk: Fix up CDCLK_FREQ_DECIMAL without a full PLL re-enable
  • 68a624416d1d drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
  • 4ddf82c18ee4 drm/imagination: Fit paired fragment job in the correct CCCB
  • 560adcc7d401 drm/tegra: fbdev: Remove offset into framebuffer memory
  • a6366b551079 drm/dp/mst: fix buffer overflows in sideband chunk accumulation
  • e6ef5455b06c drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
  • ace55d80395c drm/exynos: fbdev: Remove offset into screen_buffer
  • 1f9c6b74e796 drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
  • a673171502e8 drm/imagination: Count paired job fence as dependency in prepare_job()
  • ba34d197ebf2 drm/rockchip: analogix_dp: Add missing error check for platform_get_resource()
  • 6d5ee0dab4f9 drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video()
  • 4f2352520faa drm/tidss: Fix missing drm_bridge_add() call
  • d2c08dab2738 drm: renesas: rzg2l_mipi_dsi: Move rzg2l_mipi_dsi_set_display_timing()
  • e299e35e86e2 drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay
  • b9c8a1400a3b tracing: Fix use-after-free freeing trigger private data
  • 752b1159ed5d bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
  • f1557e0a6473 LoongArch: BPF: Fix memory leak in bpf_jit_free()
  • 9aa7071185c7 pidfs: make pidfs_ino_lock static
  • d5e2cd2bc8ae drop_monitor: perform u64_stats updates under IRQ-disabled section
  • 4a9e30764e80 drop_monitor: fix size calculations for 64-bit attributes
  • 8fd6975d2aec net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD
  • a3829056ca98 bnge/bng_re: fix ring ID widths
  • fe9bf32bb18f tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()
  • ecdd0875e3bd net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets()
  • 9e9654a8eec1 mctp: check register_netdevice_notifier() error in mctp_device_init()
  • 794c503d9264 ptp: netc: explicitly clear TMR_OFF during initialization
  • 3aa13fe0c1bb rds: tcp: unregister sysctl before tearing down listen socket
  • f08bf5f3be66 ipv6: Change allocation flags to match rcu_read_lock section requirements
  • 9fbe22b7aff0 idpf: fix max_vport related crash on allocation error during init
  • d0a21604c6ab ice: prevent tstamp ring allocation for non-PF VSI types
  • c63314c08b34 ice: fix LAG recipe to profile association
  • bff901a9852f ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV
  • e3e59c37cdc2 net: ipv6: fix dif and sdif mismatch in raw6_icmp_error
  • 294bc4b6b1a3 octeontx2-pf: tc: fix egress ratelimiting
  • f8d1c4e69ecb net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation
  • d6169ed4e341 net/mlx5e: Report zero bandwidth for non-ETS traffic classes
  • 96041242efc3 net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule
  • 88b2a16ddac3 net/mlx5: Fix MCIA register buffer overflow on 32 dword reads
  • 74ab1e7c8b8e raw: annotate lockless match fields in raw_v4_match()
  • 659b9b4f194b net: qrtr: restrict socket creation to the initial network namespace
  • 716cb29dbed4 LoongArch: BPF: Zero-extend signed ALU32 div/mod results
  • a189b62fa601 hinic: remove unused ethtool RSS user configuration buffers
  • daf82730355d ppp: annotate data races in ppp_generic
  • ee5b419cad37 ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup
  • 6c4e18135cc0 octeontx2-vf: set TC flower flag on MCAM entry allocation
  • 9dfab50f0765 mpls: Set rt->rt_nhn just before returning from mpls_nh_build_multi().
  • 2bffe3790235 net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
  • c09df4d9e72e net: stmmac: enable the MAC on link up for all supported speeds
  • a99bc2eef774 net: stmmac: reset residual action in L3L4 filters on delete
  • e10ccddeec02 net: stmmac: fix l3l4 filter rejecting unsupported offload requests
  • bdcc15ec0ff7 net: stmmac: xgmac: fix l4 filter port overwrite on register update
  • 8a726e9585ff bpf: tcp: fix double sock release on batch realloc
  • ce20d589370d drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem
  • c1cda72f6ace tipc: fix u16 MTU truncation in media and bearer MTU validation
  • fa1063d14a3c iomap: fix incorrect did_zero setting in iomap_zero_iter()
  • 9606c6014328 iomap: correct the range of a partial dirty clear
  • 9ac92736030f drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create()
  • bb7abf112544 drm/xe/i2c: Allow per domain unique id
  • b28596baf87e vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
  • 83f5031f2a6a sctp: auth: verify auth requirement when auth_chunk is NULL
  • 84228811cc18 net: stmmac: dwmac4: mask interrupts when stopping DMA in suspend
  • 31f9cbd09b3c net: dpaa: fix mode setting
  • 282d220bae5f smp: Make CSD lock acquisition atomic for debug mode
  • 6455dbdbb34b smp: Avoid invalid per-CPU CSD lookup with CSD lock debug
  • ae995b8002d3 net: hsr: fix memory leak on slave unregistration by removing synced VLANs
  • 3e2ff8448333 net: bridge: vlan: fix vlan range dumps starting with pvid
  • 3741147a3d18 amt: make the head writable before rewriting the L2 header
  • 7f48e3ddad8e amt: re-read skb header pointers after every pull
  • 1f4a107439d2 ovl: check access to copy_file_range source with src mounter creds
  • 261f0a3f0ac0 drm/vc4: hvs/v3d: Fix null dereference in unbind
  • 304a470bbd62 drm/panel: fix unmet dependency bug for DRM_PANEL_HIMAX_HX83121A
  • ed537d090471 drm/panel: s6e3ha8: fix unmet dependency on DRM_DISPLAY_HELPER
  • 496373b64075 drm/panel: ilitek-ili9882t: fix unmet dependency for DRM_PANEL_ILITEK_ILI9882T
  • 90775605dd0f ovl: fix trusted xattr escape prefix matching
  • bd4fac033bb9 wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
  • 523ed2831ee5 drm/xe/vf: Add drm_dev guards when detaching CCS read/write buffers
  • 45c496756c6f wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()
  • 89d03bda560d wifi: mt76: mt7925: fix crash in reset link replay
  • e12575136e47 wifi: mt76: fix airoha_npu dependency tracking
  • 8bc7167e8a86 wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()
  • 856f1588a259 wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()
  • 8709c66e665a wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()
  • 6f99a5667c6c wifi: mt76: mt7915: guard HE capability lookups
  • d86883f7e8f0 wifi: mt76: mt7925: guard link STA in decap offload
  • b3fe7baffc0d ppp: annotate concurrent dev->stats accesses
  • 32390b3f06f2 cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths
  • 42737cf1c3c9 cifs: prevent readdir from changing file size due to stale directory metadata
  • b8f3b8efa5f9 tipc: fix infinite loop in __tipc_nl_compat_dumpit
  • 18506d726376 nexthop: initialize extack in nh_res_bucket_migrate()
  • cf45d748e437 gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
  • 700de4678d11 selftests: drv-net: convert so_txtime to drv-net
  • aa59787607db selftests: drv-net: increase timeout
  • e286e6145379 selftests: ovpn: increase timeout
  • 5d9e83ee4632 selftests: ovpn: add IPV6 and VETH configs
  • 20b69c478c28 selftests: openvswitch: add config file
  • 38c6b3e45ab3 selftests: af_unix: add USER_NS config
  • 8a8d80197576 tls: device: push pending open record on splice EOF
  • a40e83a34eaa net: mctp i3c: clean up notifier and buses if driver register fails
  • 00ae679cb21a sctp: validate stream count in sctp_process_strreset_inreq()
  • 02b0b8a14d87 accel: ethosu: Handle U85 internal chaining buffer
  • b4ae748f8e6c accel: ethosu: Fix element size accounting for cmd stream validation
  • 1d93c6abc147 pds_core: check for workqueue allocation failure
  • bdeab32a7a91 pds_core: fix auxiliary device add/del races
  • 6d8593349c13 pds_core: order completion reads after the ownership check
  • ac05919612b4 pds_core: yield the CPU while waiting for the adminq to drain
  • ecc7a7d7569e pds_core: fix use-after-free on workqueue during remove
  • 54f905821f26 pds_core: fix deadlock between reset thread and remove
  • b6ea3dda09eb sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
  • 4946dea23863 net: txgbe: fix FDIR filter leak on remove
  • 00d5707217b5 rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled
  • febcced69581 net: txgbe: fix heap overflow when reading module EEPROM
  • d70c81001df9 tipc: serialize udp bearer replicast list updates
  • cac4ebdb831c geneve: ensure the skb is writable before fixing its headers
  • c0816ecedf36 geneve: fix hint header definition wrt endianness
  • c35b19fc3446 net: Call net_enable_timestamp() before failure in sk_clone().
  • c95ef27acc2d soreuseport: Clear sk_reuseport_cb before failure in sk_clone().
  • 6582ba7af37d amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN
  • b2f176d58dc3 arm64/mm: Check the requested PFN range during memory removal
  • 1e477e4c5e53 arm64: Correct value returned by ESR_ELx_FSC_ADDRSZ_nL()
  • 950431062159 pds_core: reject component parameter in legacy firmware update
  • d036f2d44f58 wifi: mac80211: recalculate TIM when a station enters power save
  • 0e28ca1c3204 iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
  • 030a8e84f8f1 iommu/amd: Bound the early ACPI HID map
  • b6766d7ea43e wifi: mwifiex: bound uAP association event IEs to the event buffer
  • 539382822dbb wifi: mac80211: copy aggregation information
  • 0c6d1b9fbb64 vhost-net: fix TX stall when vhost owns virtio-net header
  • 2fe22d58b379 wan: wanxl: Only reset hardware after BAR mapping
  • a7dc30b6828c nfp: Check resource mutex allocation
  • 901a73523e09 wifi: mac80211: tear down new links on vif update error path
  • 02f8cefa2ad9 iommu/amd: Wait for completion instead of returning early in iommu_completion_wait()
  • 4c4d866a64f3 net: airoha: Fix DMA direction for NPU mailbox buffer
  • a3cecf169cc6 dpaa2-eth: put MAC endpoint device on disconnect
  • ad28c4f9e0ea net: airoha: Fix potential use-after-free in airoha_ppe_deinit()
  • c27694ff6748 dpaa2-switch: put MAC endpoint device on disconnect
  • 092b42cf3f60 rxrpc: fix io_thread race in rxrpc_wake_up_io_thread()
  • e66451163383 gtp: parse extension headers before reading inner protocol
  • 0f8690e38691 rds: drop incoming messages that cross network namespace boundaries
  • 738039ad21e2 bonding: fix devconf_all NULL dereference when IPv6 is disabled
  • c8fd74445e86 net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains
  • cabfacbd5af0 bpf: Reject redirect helpers without a bpf_net_context
  • a885387dae79 net/packet: avoid fanout hook re-registration after unregister
  • 44de1031f1e2 netlink: specs: rt-link: convert bridge port flag attributes to u8
  • 08102525f1f8 selftests/net: Fix tun IPv6 test addresses to avoid 6to4 range
  • 4aba40721f92 net: phy: marvell: fix return code
  • 24b0758193d7 Bluetooth: btusb: validate Realtek vendor event length
  • 4f95592e1a90 regulator: mt6358: use regmap helper to read fixed LDO calibration
  • b042e538e98b hwmon: occ: validate poll response sensor blocks
  • 6c85bc624b4c ovpn: use monotonic clock for peer keepalive timeouts
  • 4cdb209f12a8 ovpn: fix use after free in unlock_ovpn()
  • ebe4e94f4a4c selftests/net: ovpn: fix getaddrinfo memory leak in ovpn_parse_remote()
  • 016a50379d17 ovpn: avoid putting unrelated P2P peer on socket release
  • 5d03046a7c53 drm/i915/backlight: Remove DP_EDP_BACKLIGHT_AUX_ENABLE_CAP check for DPCD backlight
  • 9f88a99ed511 smb: client: validate DFS referral PathConsumed
  • 672973b49ea3 hwmon: (asus-ec-sensors) add missed handle for ENOMEM
  • 491690618b90 hwmon: (asus-ec-sensors) fix EC read intervals
  • 8e609af82aa8 hwmon: (asus-ec-sensors) fix looping over banks while reading from EC
  • 9b93a63b9087 hwmon: (pmbus/max34440) block unsupported VIN and IIN limit registers
  • 316f7140217f hwmon: (pmbus/max34440): add support adpm12250
  • aadc7e08a28a hwmon: Use named initializers for arrays of i2c_device_data
  • 734d1cb58d43 hwmon: Drop unused i2c driver_data
  • af3895e9e887 drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook()
  • 0cc0c4c14150 usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect
  • 66c87fc2d529 wifi: iwlwifi: mvm: fix read in wake packet notification handler
  • 2b348020375e wifi: iwlwifi: validate payload length in iwl_pnvm_complete_fn
  • 29e89a5cd8b4 wifi: iwlwifi: fix pointer arithmetic in iwl_add_mcc_to_tas_block_list
  • 5bfeaeeab72e wifi: iwlwifi: mvm: validate SAR GEO response payload size
  • df61ff97d279 ASoC: cs35l56: Use complete_all() to signal init_completion
  • babdfc580020 ASoC: cs35l56: Fix potential probe() deadlock
  • ca1f96334267 arm_mpam: guard MBWU state before adding it to garbage
  • 125c3fd6b816 arm_mpam: Fix MPAMCFG_MBW_PBM register setting
  • ddc0769e2187 arm_mpam: Fix software reset values of MPAMCFG_PRI
  • 8ba157866b0c ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI
  • d5dfdf43259a ALSA: hda: cs35l41: validate and free ACPI mute object
  • d90825206896 iommu/amd: Fix nested domain leak
  • e0c78cdf35af iommu/amd: Fix IRQ unsafe locking in gdom allocation
  • 10de317e64d5 ASoC: sun4i-codec: Set quirks.playback_only for H616 codec
  • e75ef37d83c9 ASoC: tas2781: bound firmware description string parsing
  • ae0629ff9ccb btrfs: free mapping node on duplicate reloc root insert
  • 0e465c63f103 btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps
  • b6ba206ffb74 btrfs: fix u32 to s64 type conversion in dirty_metadata_bytes accounting
  • 0ea3c4445811 btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8
  • 21f59906ea75 wifi: carl9170: fix buffer overflow in rx_stream failover path
  • 423c836f9348 wifi: carl9170: fix OOB read from off-by-two in TX status handler
  • cb7a38810cf2 wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
  • 94e1bfcefe82 wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
  • c38b0d5c6619 wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
  • f8160cf19f9e wifi: ath12k: Fix low MLO RX throughput on WCN7850
  • 2a5aa4e9b892 firewire: net: Fix fragmented datagram reassembly
  • c3d2d8940ec0 platform/x86: asus-wmi: temporarily revert to setting a charge limit
  • 1e7ceb5b0135 platform/x86/intel/vsec: free ACPI discovery data on early errors
  • 8d182aead59e platform/x86/intel/vsec: allocate res with intel_vsec_dev
  • a19e0f4b6360 wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET
  • ef290f9e99c6 wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET
  • 725c1c3a8c5d wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()
  • ea48d712d298 wifi: ath10k: fix skb leak on incomplete msdu during rx pop
  • 57c3f5bd5be0 watchdog: airoha: Prevent division by zero when clock frequency is zero
  • 7993d626983c watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
  • dc73b0dfeab8 hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop
  • 18d7c5238910 hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
  • 0842e9faab04 hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
  • 1a634f464d61 hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
  • bb25bd980f2d hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
  • 4abb4e284d88 wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin
  • 7c9046d92c4b wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
  • 98b7fc0d7ef6 watchdog: ni903x_wdt: Check ACPI_COMPANION() against NULL
  • 828ed58535f2 selftests/bpf: Keep verifier_map_ptr exercising ops pointer access
  • 5c350dced70b selftests/bpf: Adjust verifier_map_ptr for the map's excl field
  • 2ea73153240f usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits
  • 749a36657ca2 Revert "drm/amd/display: Add missing kdoc for ALLM parameters"
  • 845fc1e4dcf4 RISC-V: KVM: Serialize virtual interrupt pending state updates
  • abc360aac3df wifi: mwifiex: fix freeze for 60 seconds caused by request_firmware
  • 68c857b78dcc drm/amd/display: Add dp_skip_rbr flag for NUTMEG
  • f83c5af4742d drm/amd/display: Fix preferred link rate for NUTMEG
  • 95776812e6b8 drm/amd/display: Fix ISM dc_lock deadlock during suspend
  • 2d19fbfceb14 usb: typec: ucsi: Add duplicate detection to nvidia registration path
  • 244b028dc7be usb: typec: ucsi: Detect and skip duplicate altmodes from buggy firmware
  • c7dd73d83b8c USB: serial: option: add TDTECH MT5710-CN
  • 122f180bfc1f USB: serial: keyspan_pda: fix data loss on receive throttling
  • 1e47d8228b87 USB: serial: io_edgeport: cap received transmit credits
  • 4f411e8501d2 USB: serial: ftdi_sio: add support for E+H FXA291
  • c8510fbbea09 usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer
  • d4964a747171 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
  • 4c6c6a5588b9 usb: gadget: f_tcm: synchronize delayed set_alt with teardown
  • 41fd5f2fb002 usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
  • 5e0eb0c78013 USB: gadget: fsl-udc: fix dev_printk() device
  • 1351277e153c USB: gadget: fsl-udc: fix device name leak on probe failure
  • 0320f21345d2 USB: gadget: snps-udc: fix device name leak on probe failure
  • e41bbbbb1740 usb: gadget: printer: fix infinite loop in printer_read()
  • ac9a51d910bb usb: gadget: f_midi: cancel pending IN work before freeing the midi object
  • e24b33618231 usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
  • b4b0d3802697 usb: chipidea: fix usage_count leak when autosuspend_delay is negative
  • 2313f5e7028f USB: storage: add NO_ATA_1X quirk for Longmai USB Key
  • 6c525c851e59 usb: musb: omap2430: Do not put borrowed of_node in probe
  • e00109b5adf7 usb: core: port: Deattach Type-C connector on component unbind
  • f742d9c98b5c wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
  • ab82adf5e63b usb: core: sysfs: add lock to bos_descriptors_read()
  • 06db79411a28 mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
  • 48b913e3f115 selftests: netconsole: only restore MAC when it changed on resume
  • 4e1caa5fdd0d bnxt_en: Handle partially initialized auxiliary devices
  • 3aa40c3bccac sctp: fix auth_hmacs array size in struct sctp_cookie
  • 2791a501da50 net/sched: act_tunnel_key: Defer dst_release to RCU callback
  • 4b3e6b9fdaeb dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync()
  • 374742a961be tcp: fix TIME_WAIT socket reference leak on PSP policy failure
  • e8fadbffc19a accel/amdxdna: Fix use-after-free of mm_struct in job scheduler
  • 76b9ec20d22e drm/i915/selftests: Fix GT PM sort comparators
  • c7b6d61979b8 drm/i915/wm: clear the plane ddb_y entries on plane disable
  • ea128f06d2fb ksmbd: validate compound request size before reading StructureSize2
  • 14062c74e5b2 ksmbd: pin conn during async oplock break notification
  • 03d6f83979b0 drm/xe/guc: Hold device ref until queue teardown completes
  • 77fd62412431 drm/xe/guc: Keep scheduler timeline name alive
  • 5a09a0d17b6b drm/xe: Assign queue name in time for drm_sched_init
  • 82806d880eac drm/xe/wopcm: fix WOPCM size for LNL+
  • f2ebfd5cc87f drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves
  • b3ea85c3c73b can: j1939: fix lockless local-destination check
  • 82f8d6ab4561 riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus()
  • 898bb2814f38 s390/checksum: Fix csum_partial() without vector facility
  • d4bf73b962b7 drm/panthor: Check debugfs GEM lock initialization
  • 8692655da369 bpf, sockmap: Reject unhashed UDP sockets on sockmap update
  • 56e97b36a501 powerpc/vtime: Initialize starttime at boot for native accounting
  • 234b3ead3e8f powerpc/time: Prepare to stop elapsing in dynticks-idle
  • 21541c24563e powerpc/85xx: Add fsl,ifc to common device ids
  • 755bd5556e5f spi: cadence-quadspi: Fix indirect write timeout when DMA read mode is enabled
  • 57791aab1129 can: raw: add locking for raw flags bitfield
  • 5fcb8b8cb396 drm/i915/gt: use correct selftest config symbol
  • ae70dda83d45 riscv: Gate FUNCTION_ALIGNMENT_4B on DYNAMIC_FTRACE
  • a4a09e514283 smb/client: handle overlapping allocated ranges in fallocate
  • 3899db224f8a Bluetooth: mgmt: Translate HCI reason in Device Disconnected event
  • 2363a7576947 Bluetooth: hci_qca: Clear memdump state on invalid dump size
  • 8d892bec1dd1 Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups
  • ecdcb55ea1c0 Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
  • b11511006f9e Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
  • 38326774df61 Bluetooth: hci_sync: extend conn_hash lookup critical sections
  • b82802b5ab26 Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update
  • 4fcfb5b2c736 Bluetooth: qca: fix NVM tag length underflow in TLV parser
  • b84691ff8069 ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC
  • 31e55573edeb accel/ivpu: Fix wrong register read in LNL failure diagnostics
  • 29b916d3556b ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning
  • cfecc0c67619 ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts
  • 626aecafa69a ata: sata_dwc_460ex: use platform_get_irq()
  • 5d0797d6940b ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered
  • 24d7abda6a2a scsi: core: wake eh reliably when using scsi_schedule_eh
  • 5c54e9d4fcaf udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf()
  • 5595ea59cdf2 net/iucv: take a reference on the socket found in afiucv_hs_rcv()
  • b8d2ea75c76a ipv4: fib: free fib_alias with kfree_rcu() on insert error path
  • 06213c85d8c0 ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
  • 82e0c68e5ed4 sched_ext: Record an error on errno-only sub-enable failure
  • 4f265e2cacc6 cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq
  • 14b49b5ab299 bpf: Fix UAF in sock clone early bailouts
  • 3c746522a41f firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context
  • 4d8e4780e306 ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup
  • 52bdf1290894 sched_ext: Enable tick for finite slices on nohz_full
  • 47370430ac16 ASoC: cs42l43: Correct report for forced microphone jack
  • b26272b392ce erofs: relax sanity check for tail pclusters due to ztailpacking
  • 70affc74bc31 ASoC: amd: ps: replace bitwise OR with logical OR in IRQ return check
  • bd54a545a324 ASoC: amd: ps: fix wrong ACP version string in pci_request_regions()
  • 365ea356341d ASoC: amd: ps: disable MSI on resume in ACP PCI driver
  • 46d78faf2641 ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop
  • 8ef18f0ab3c0 firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation
  • 27abdaf0c5c8 firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()
  • ddf2773bcc8e wifi: cfg80211: bound element ID read when checking non-inheritance
  • c73c3fc1c7ca wifi: brcmfmac: initialize SDIO data work before cleanup
  • 6d6123fef5a4 wifi: cfg80211: use wiphy work for socket owner autodisconnect
  • 4b8abf43bf34 wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
  • 4e5cf3cf184c ASoC: amd: acp: Fix linker error with SDCA quirks
  • 429ac1c2fe81 wifi: mac80211: avoid non-S1G AID fallback for S1G assoc
  • 8f2dbeee540c wifi: cfg80211: reject empty PMSR peer lists
  • 49a8ae4df3a0 wifi: cfg80211: reject unsupported PMSR FTM location requests
  • 58320cb47df2 wifi: cfg80211: validate PMSR FTM preamble range
  • befabcc4170f wifi: cfg80211: validate PMSR measurement type data
  • f3f3bbab96b3 wifi: nl80211: constrain MBSSID TX link ID range
  • f7055ad71368 wifi: nl80211: validate nested MBSSID IE blobs
  • eb1f99a02f6d wifi: cfg80211: derive S1G beacon TSF from S1G fields
  • 6f919f29e9b7 wifi: nl80211: free RNR data on MBSSID mismatch
  • 0a77d9fb4d5c wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock
  • 9096e1f70141 wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
  • a03fceae0c65 wifi: mac80211: defer link RX stats percpu free to RCU
  • 644640cde2fb wifi: libertas: fix memory leak in helper_firmware_cb()
  • 1981fba71797 wifi: mac80211: fix fils_discovery double free on alloc failure
  • 0ace76e410d7 wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
  • 99dc05c75acc wifi: mac80211_hwsim: clamp virtio RX length before skb_put
  • 99d2e850c643 wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()
  • 7cbda50eebcd wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
  • b119c70b2477 wifi: cfg80211: cancel sched scan results work on unregister
  • d91b1fdc70c5 ALSA: usb-audio: Fix imbalance per-channel volume of sticky mixers
  • 4b2c349988f9 wifi: mac80211: allocate backup ieee80211_nan_sched_cfg off stack
  • 6aa3796d18a9 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
  • e078da1b4e11 xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()
  • ffd64e0717ef xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
  • c37a07923012 xfrm: clear mode callbacks after failed mode setup
  • bdd83f0a49a1 RDMA/irdma: Prevent overflows in memory contiguity checks
  • 1d73084f4451 selftests/alsa: Fix memory leak in find_controls error path
  • 820f983d6419 mtd: fix double free and WARN_ON in add_mtd_device() error paths
  • 52f9fcb19114 RDMA/siw: publish QP after initialization
  • 9f0fbf76d664 RDMA/hns: Fix potential integer overflow in mhop hem cleanup
  • 9d0201aefda6 RDMA/core: Fix memory leak in __ib_create_cq() on invalid cqe
  • 0d9fbcf79c72 RDMA/mana_ib: initialize err for empty send WR lists
  • a9f76f726007 RDMA/erdma: initialize ret for empty receive WR lists
  • 728211c815f6 RDMA/irdma: Prevent user-triggered null deref on QP create
  • 9b5012a9ca33 RDMA/irdma: Remove redundant legacy_mode checks
  • dbaa37e06091 RDMA/irdma: Prevent rereg_mr for non-mem regions
  • c73a1ddb21c5 RDMA/cma: Fix hardware address comparison length in netevent callback
  • 9333f4b6f448 xfrm: reject optional IPTFS templates in outbound policies
  • 96b678d08268 xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
  • 6cefed45a5be reset: spacemit: k3: fix USB2 ahb reset
  • e2f188cdbf83 sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx()
  • 12a42c610e44 firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
  • cb5a938ca0fe btrfs: fallback to transaction csum tree on a commit root csum miss
  • 7591d1727067 btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()
  • f9fef131fa3f btrfs: reject free space cache with more entries than pages
  • 0fb32ba4f74d mtd: nand: mtk-ecc: stop on ECC idle timeouts
  • 4aaba135ddf4 mtd: mtdswap: remove debugfs stats file on teardown
  • d36520e5da8b mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy()
  • 4d91d783f934 mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy_joins()
  • ad9c9ad3204f IB/mad: Drop unmatched RMPP responses before reassembly
  • bd2a4483a863 firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits
  • bbca7cc3b2b4 xfrm: fix stale skb->prev after async crypto steals a GSO segment
  • 0943e331500c xfrm: propagate -EINPROGRESS from validate_xmit_xfrm()
  • db2765d4bfc3 arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234
  • 19dd7326d1ad sched_ext: Annotate ksyncs with __rcu in alloc/free_kick_syncs()
  • b27634071289 Docs/admin-guide/cgroup-v2: fix memory.stat doc details
  • 1defa8fb132f arm64: tegra: Remove fallback compatible for GPCDMA
  • e8bfeafded96 xprtrdma: Clear receive-side ownership pointers on release
  • 9382304e25c6 crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin
  • b773faa32b0a gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
  • 43cfb20d62ff KVM: x86/mmu: Fix use-after-free on vendor module reload
  • 1dabef6e2065 KVM: nVMX: Hide shadow VMCS right after VMCLEAR
  • 6e9815aa51fc KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN
  • bce0d3c26e2c KVM: x86: Check for invalid/obsolete root after making MMU pages available
  • 29ca543ac55a seqlock: Allow UBSAN_ALIGNMENT to fail optimizing
  • 2e0b1d51de9e drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker
  • 1d412720a163 sched_ext: Skip ops.set_weight() for disabled tasks
  • 782e1042143d platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug

View originalPermalink

7.1.5-xanmod1
  • 2fb7a627a9c6 Linux 7.1.5-xanmod1
  • 022aeb4a9152 tcp_bbr: v3: update TCP 'bbr' congestion control module to BBRv3 [v7.1.5+]
  • c50e105d5af1 Merge tag 'v7.1.5' into 7.1
  • 8392dcae53e5 Revert "tcp_bbr: v3: update TCP 'bbr' congestion control module to BBRv3"
  • 155b42bec9cb Linux 7.1.5
  • 872380f930c9 Revert "gpib: cb7210: Fix region leak when request_irq fails"
  • ad1cafa1bdaa posix-cpu-timers: Prevent UAF caused by non-leader exec() race
  • 60325bf5e2c1 posix-timers: Expand timer_[re]arm() callbacks with a boolean return value
  • 5638dbfe9cf1 drm/amd/display: Fix Color Manager (3DLUT, Shaper, Blend)
  • 570967e9c615 iomap: consolidate bio submission
  • e2f0122bd566 exfat: fix implicit declaration of brelse()
  • 8e4e884f1bef exfat: add data_start_bytes and exfat_cluster_to_phys_bytes() helper
  • 390f1d72a478 exfat: add balloc parameter to exfat_map_cluster() for iomap support
  • 69b31ef6f853 exfat: replace unsafe macros with static inline functions
  • 9634db561e15 crypto: xilinx-trng - Remove crypto_rng interface
  • 3dc8a46d08a8 liveupdate: validate session type before performing operation
  • ddcdac47e1f2 usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()
  • 53430a3768b5 usb: atm: ueagle-atm: remove function entry/exit debug messages
  • 10cfea5091f0 usb: atm: ueagle-atm: use dev_dbg() for 'device found' message
  • 28f19c97eab4 xfs: add newly added RTGs to the free pool in growfs
  • 615104cd66f8 xfs: factor out a xfs_zone_mark_free helper
  • cfb2c6f71d61 ksmbd: use opener credentials for FSCTL mutations
  • cba4ee1092b3 smb: move compression definitions into common/fscc.h
  • 98185b3025be ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
  • 733e76e74e40 Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()
  • a2a2f68c42e0 Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister
  • 4257f45ee1fd binder: cache secctx size before release zeroes it
  • 3f54f2310de0 binder: Use LIST_HEAD() to initialize on stack list head
  • da9e3be9cf31 ALSA: hda/tas2781: Cancel async firmware request at unbind
  • cd992747d717 firmware_loader: Add cancel helper for async requests
  • ac1328962db1 ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417
  • 53e3dcfa74b3 ALSA: scarlett2: Allow selecting config_set by firmware version
  • b80d60249686 iio: hid-sensor-rotation: Fix stale or zero output when reading raw values
  • 3c0dbfecd859 f2fs: fix listxattr handling of corrupted xattr entries
  • aa807064473a f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs()
  • cf8b5937b7b2 f2fs: fix potential deadlock in f2fs_balance_fs()
  • c81e2af41de6 device property: initialize the remaining fields of fwnode_handle in fwnode_init()
  • db20589d7b24 samples/damon/mtier: fail early if address range parameters are invalid
  • 810c9ae71dad mm/damon/core: trace esz at first setup
  • 314bd592085c bpf: Reject negative const offsets for buffer pointers
  • a419421281fb mmc: sdhci-esdhc-imx: fix resume error handling
  • 89b63cd133fe mmc: sdhci-esdhc-imx: make non-fatal errors non-blocking in suspend
  • 6355749aebf6 mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend
  • 9bf4ee05a110 mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt
  • bb72b2398c05 mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore
  • 24300decd8bd mmc: sdhci-esdhc-imx: restore DLL override for DDR modes on resume
  • 48188934d5d2 mmc: sdhci-esdhc-imx: remove unnecessary mmc_card_wake_sdio_irq check for tuning save/restore
  • 657e0acce5b8 mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe() method
  • f59d0244d90b mmc: mmc_test: Fix __counted_by handling after kzalloc_flex() conversion
  • 0e93010b52bb mmc: block: fix RPMB device unregister ordering
  • cb2031f8b226 mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout
  • 791fc00d116e mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout
  • 1773c6e292b0 mtd: rawnand: fsl_ifc: return errors for failed page reads
  • c2e1d3392956 mmc: vub300: defer reset until cmd_mutex is unlocked
  • 09e044192a42 mtd: mchp23k256: use SPI match data for chip caps
  • 9fc23fc52fc9 mtd: onenand: samsung: report DMA completion timeouts
  • 0e65079d28e5 mtd: virt-concat: free duplicate generated name
  • 6126e12bf8c8 wifi: mwifiex: fix permanently busy scans after multiple roam iterations
  • 625fc704b19c wifi: mac80211: validate extension-frame layout before RX
  • 179d9be632d8 wifi: mac80211: free ack status frame on TX header build failure
  • 2b1589fd9a07 wifi: ieee80211: validate MLE common info length
  • 3b0505e43da8 wifi: cfg80211: validate EHT MLE before MLD ID read
  • d5c234774a82 powerpc/uaccess: correct check for CONFIG_PPC_E500 in mask_user_address()
  • 4efa313b1592 powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()
  • d826d3e04c5b reset: sunxi: fix memory region leak on ioremap failure
  • 68176d47421f reset: imx7: Correct polarity of MIPI CSI resets on i.MX8MQ
  • ad1e14710b36 ipvs: reload ip header after head reallocation
  • 905d7a363ade ipvs: fix more places with wrong ipv6 transport offsets
  • 47f0c7d856c6 memstick: ms_block: reject a card that reports too many blocks
  • 492cf7778a55 macsec: fix promiscuity refcount leak in macsec_dev_open()
  • 3cc37687227b llc: fix SAP refcount leak when creating incoming sockets
  • 5c1e8f56d84c crypto: aes - Fix conditions for selecting MAC dependencies
  • f1ca750c0510 Bluetooth: btrtl: validate firmware patch bounds
  • 1b41cbe05b18 net: openvswitch: reject oversized nested action attrs
  • b7f5bd59ed1c regulator: ltc3676: Fix incorrect IRQSTAT bit offsets
  • c8874e338d51 arch/riscv: vdso: remove CFI landing pad from rt_sigreturn
  • 73a7bdf06dbd riscv: vdso: Do not use LTO for the vDSO
  • 185bb156c427 wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
  • a7584f261e64 wifi: mac80211: fix memory leak in ieee80211_register_hw()
  • 564e3fce81eb wifi: mwifiex: fix roaming to different channel in host_mlme mode
  • 56994852d704 wifi: rt2x00: avoid full teardown before work setup in probe
  • 6eb4cf2fa899 net/mlx5: free mlx5_st_idx_data on final dealloc
  • 0b24b11ecda4 powerpc/pseries: fix memory leak on krealloc failure in papr_init
  • cc5c99b606ff mmc: sdhci-esdhc-imx: restore pinctrl before restoring ios timing on resume
  • 90dfffc360df selftests/landlock: Fix screwed up pointers in the scoped_signal_test
  • 19a1785250c7 selftests/landlock: Skip scoped_signal subtest with MSG_OOB if not available
  • 4907f4c2d98b pmdomain: imx: Fix i.MX8MP VC8000E power up sequence
  • 331ee3bc4edf pmdomain: imx: Fix i.MX8MP power notifier
  • 36c2d7728540 pmdomain: mediatek: Fix possible nullptr KP in HWV cleanup/on-check
  • 4ba6d7166750 pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI
  • c17f06d8a085 cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed
  • f45c8d3818da selftests/rseq: Fix a building error for riscv arch
  • 28673209eeea s390/mm: Fix type mismatch in get_align_mask().
  • 83fe36f81200 s390/diag: Add missing array_index_nospec() call to memtop_get_page_count()
  • dd0160a08423 tracing/osnoise: Call synchronize_rcu() when unregistering
  • d5b2752a17ef riscv: Prevent NULL pointer dereference in machine_kexec_prepare()
  • 648d4317326e drbd: reject data replies with an out-of-range payload size
  • f713d7a7e0f2 ata: libata-core: Allow capacity transition to zero for locked drives
  • f723ea50a96d ata: libata-core: Skip HPA resize for locked drives
  • f7628eea9212 fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
  • fa5c7c313018 fs/resctrl: Free mon_data structures on rdt_get_tree() failure
  • 901a489d89ee cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable()
  • c3f200efb454 arm64: smp: Fix hot-unplug tearing by forcing unregistration
  • f50d87f97527 amdkfd: properly free secondary context id
  • 109241d98804 net: macb: drop in-flight Tx SKBs on close
  • 94fe0ab01b48 dibs: loopback: validate offset and size in move_data()
  • c39087ad0b97 macsec: don't read an unset MAC header in macsec_encrypt()
  • 6335ab62d5fc ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
  • e5d0bb887166 ipvs: use parsed transport offset in SCTP state lookup
  • 21a537606fe3 llc: fix SAP refcount leak in llc_ui_autobind()
  • 680d9dcbf428 selftests: net: make busywait timeout clock portable
  • 23d917acd9c9 octeontx2-pf: fix SQB pointer leak on init failure
  • d8b5b66388a5 mac802154: remove interfaces with RCU list deletion
  • ae5347f3db17 s390/monwriter: Reject buffer reuse with different data length
  • b321a046d771 irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure
  • 23afc3786acf mm/compaction: handle free_pages_prepare() properly in compaction_free()
  • 91b4d76dd07f riscv: probes: save original sp in rethook trampoline
  • b770fcfcdced hwmon: (asus_atk0110) Check package count before accessing element
  • 3034e5d67ea6 net: ipa: fix SMEM state handle leaks in SMP2P init
  • 77f0023f22f6 net: wwan: iosm: bound device offsets in the MUX downlink decoder
  • d43efd1b5d97 ata: libata-core: Reject an invalid concurrent positioning ranges count
  • 7ba60286ed14 ata: pata_pxa: Fix DMA channel leak on probe error
  • 299739909c48 ata: libata-core: Add NOLPM quirk for PNY CS900 1TB SSD
  • ae0265f0a95a net/mlx5: HWS, fix matcher leak on resize target setup failure
  • e3d325c0bdb7 orangefs: keep the readdir entry size 64-bit in fill_from_part()
  • aac98ec816b0 tracing/probes: Fix double addition of offset for @+FOFFSET
  • 4a97d08d4ace hwmon: (max1619) add missing 'select REGMAP' to Kconfig
  • 6ee183d89261 fhandle: reject detached mounts in capable_wrt_mount()
  • 2dcebbd1ad2e net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked
  • fffeb2ab5eeb net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked
  • b99e890e6b32 net: lan743x: Initialize eth_syslock spinlock before use
  • ca096be8de31 fsl/fman: Free init resources on KeyGen failure in fman_init()
  • 7ee43ec8e677 hwmon: (occ) unregister sysfs devices outside occ lock
  • 8519e89c7f4d ACPI: TAD: Check AC wake capability before enabling wakeup
  • 4140c516473a net: liquidio: fix BAR resource leak on PF number failure
  • 1f11a29a3c80 hwmon: (w83793) remove vrm sysfs file on probe failure
  • 8a604fe15d03 hwmon: (w83627hf) remove VID sysfs files on error and remove
  • a3020a389cb1 rtc: mpfs: fix counter upload completion condition
  • a36b9528b071 fscrypt: Replace mk_users keyring with simple list
  • 03f1725f91e8 rtc: renesas-rtca3: Fix PIE clear polling condition in alarm setup error path
  • 356077547b1a bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()
  • 0fd23994ec8c ipmi: fix refcount leak in i_ipmi_request()
  • a338ce41bc93 espintcp: use sk_msg_free_partial to fix partial send
  • 7be349d4fcc5 ipmi: Fix user refcount underflow in event delivery
  • e483da960892 LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()
  • 7bcce38cbebd LoongArch: Fix nr passing in set_direct_map_valid_noflush()
  • c97d44a5bdf9 pwm: rzg2l-gpt: Fix period_ticks type from u32 to u64
  • c270eaa919f6 riscv: vdso: Always declare vdso_start symbols
  • fe08be92f2b6 KVM: arm64: Fix propagation of TLBI level in kvm_pgtable_stage2_relax_perms()
  • d1d73a3a37b7 netfilter: nfnetlink_cthelper: cap to maximum number of expectation per master on updates
  • 835a2f9d9f17 drm/xe/userptr: Stub notifier_lock helpers when DRM_GPUSVM=n
  • 1b31e160430c ACPICA: Define acpi_ut_safe_strncpy() as strscpy_pad() alias
  • 227dd2eeab0f net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants
  • fcc621f5b25d platform/x86/amd/pmc: Avoid logging "(null)" for DMI values
  • 744da2443f40 netfilter: nfnetlink_cthelper: cap to maximum number of expectation per master
  • 9a7f7b55d7d0 ksmbd: fix stack buffer overflow in multichannel session-key copy
  • 59da37fee81a octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF
  • 9f8e7f59b0c2 gve: fix header buffer corruption with header-split and HW-GRO
  • d8ce67fa6a5e ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit
  • 7e3630fbb6aa ieee802154: ca8210: fix cas_ctl leak on spi_async failure
  • 2953ec261bcf ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation
  • 638324805895 ieee802154: admin-gate legacy LLSEC dump operations
  • d0c880c9f405 octeontx2-af: Free BPID bitmap on setup failure
  • d4bcc202a353 net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink
  • c38c8b0db3c6 net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
  • d49edcc65e0a net: ipip: require CAP_NET_ADMIN in the device netns for changelink
  • 88b33ee458a6 net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
  • f97e93ebf2f9 net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
  • 11f68ebc6891 net: ena: clean up XDP TX queues when regular TX setup fails
  • 6fed707239c4 selftests: net: fix file owner for broadcast_ether_dst test
  • f7f45ceb855d net/sched: act_ct: preserve tc_skb_cb across defragmentation
  • 91850f582783 net: ixp4xx_hss: fix duplicate HDLC netdev allocation
  • 0c0a8c782148 net: wwan: t7xx: destroy DMA pool on CLDMA late init failure
  • b3763f7e22ec net: ethernet: ti: icssg: guard PA stat lookups
  • 99ae3248b33d net: sit: require CAP_NET_ADMIN in the device netns for changelink
  • f4170f45c251 gpios: palmas: add .get_direction() op
  • a60a40c9ba30 gpio: mt7621: avoid corruption of shared interrupt trigger state
  • b90f24527723 gpio-f7188x: Add support for NCT6126D version B
  • 422a0567cd1b gpio: mt7621: be sure IRQ domain is created before exposing GPIO chips
  • 628c63f96f45 gpio: tegra: do not call pinctrl for GPIO direction
  • e187f6fbc8d6 gpio: mt7621: more robust management of IRQ domain teardown
  • bc650dd5ce64 net: mana: Sync page pool RX frags for CPU
  • 282c5214ca4e net: mana: Validate the packet length reported by the NIC
  • 631d53102da9 cpu: hotplug: Bound hotplug states sysfs output
  • 9f7dc355f62c cpu: hotplug: Preserve per instance callback errors
  • f563358661ea selftests/ftrace: Drop invalid top-level local in test_ownership
  • 571e1f10b599 posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()
  • 83f9fb561c1c locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
  • bcf7968cb97c wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
  • 05b24f68f78f tracing/user_events: Fix use-after-free in user_event_mm_dup()
  • 088873af1359 net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete
  • 618cf6b13950 mmc: vub300: fix use-after-free on probe failure
  • f4cf878dcc4f Input: ims-pcu - fix type confusion in CDC union descriptor parsing
  • 025955847e15 Input: ims-pcu - fix race condition in reset_device sysfs callback
  • bbbe31486cf2 Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing
  • f97bfc1a0766 Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging
  • e555f00621bd Input: ims-pcu - fix logic error in packet reset
  • 47a9889a9325 Input: ims-pcu - fix firmware leak in async update
  • 40693fcc88bc Input: ims-pcu - fix DMA mapping violation in line setup
  • f3c63aecca90 Input: ims-pcu - add response length checks
  • cbfa059dfb48 Input: ims-pcu - validate control endpoint type
  • 8c3095c43291 Input: ims-pcu - release data interface on disconnect
  • 73e6687be0c1 Input: ims-pcu - only expose sysfs attributes on control interface
  • bf0b58ba489d Input: ims-pcu - fix use-after-free and double-free in disconnect
  • 7d330a1d6633 fs/resctrl: Fix use-after-free during unmount
  • 94cbfed19124 scsi: elx: efct: Fix I/O leak on unsupported additional CDB
  • 747eaead2db2 scsi: elx: efct: Fix refcount leak in efct_hw_io_abort()
  • ef2ee18fec92 scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
  • 555a89846ed8 scsi: target: Bound PR-OUT TransportID parsing to the received buffer
  • 1e97c404e449 scsi: xen: scsiback: Free unsubmitted command instead of double-putting it
  • 1357fb32d42a scsi: xen: scsiback: Free the command tag on the TMR submit-failure path
  • 3cbabbf1722e scsi: sg: Report request-table problems when any status is set
  • 0ce5a37f7ddf scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()
  • 782e1bf48672 scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path
  • 6920e62be4c9 accel/ivpu: Reject firmware log with size smaller than header
  • 216e43d93dd4 accel/amdxdna: Use caller client for debug BO sync
  • fff6509d976f accel/amdxdna: reject user command submission without a command BO
  • f7d08603c87b accel/amdxdna: reject command submission on devices without a submit op
  • 5da885c39baa accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap()
  • 15ecfdf0ef6f dma-buf: dma-fence: Fix potential NULL pointer dereference
  • 562d5e6f9b99 dma-fence: use correct callback in dma_fence_timeline_name()
  • e2d9a2ea178a dma-fence: Make dma_fence_dedup_array() robust against 0-count input
  • 752e214b2c6f dm-verity: make error counter atomic
  • e96df7fdbec9 dm-verity: increase sprintf buffer size
  • 81f41d989a32 dm-verity: fix a possible NULL pointer dereference
  • 414650265267 dm-verity: avoid double increment of &use_bh_wq_enabled
  • f7990c2b0f08 dm-verity: fix buffer overflow in FEC calculation
  • 829476c06496 dm-integrity: don't increment hash_offset twice
  • 3d1afaa07462 dm-integrity: fix a bug if the bio is out of limits
  • 8f0af8493009 dm-integrity: fix leaking uninitialized kernel memory
  • 7d8ed7cb844d dm_early_create: fix freeing used table on dm_resume failure
  • f00105be6a59 dm: avoid leaking the caller's thread keyring via the table device file
  • 750b23d4935b dm-stats: fix merge accounting
  • f3441b3bf519 dm-stats: fix dm_jiffies_to_msec64
  • 0cbe13fe5403 dm-pcache: reject option groups without values
  • 79feb87ab239 dm-log: fix a bitset_size overflow on 32bit machines
  • df50c24c6447 dm-ioctl: fix a possible overflow in list_version_get_info
  • 53477ce5ef90 dm-bufio: fix wrong count calculation in dm_bufio_issue_discard
  • bafe3e720cda dm era: fix out-of-bounds memory access for non-zero start sector
  • 9f1a0d27586c dm thin metadata: fix metadata snapshot consistency on commit failure
  • 0562bd39d361 dm thin metadata: fix superblock refcount leak on snapshot shadow failure
  • 17f113e7b622 net: sparx5: unregister blocking notifier on init failure
  • d4cc255f35d5 block: fix IORING_URING_CMD_REISSUE flags check in blkdev_uring_cmd
  • c0f10f43ffa5 block: fix race in blk_time_get_ns() returning 0
  • 02f8ad12545c block: remove redundant GD_NEED_PART_SCAN in add_disk_final()
  • fe1d9121b4b7 selftests/bpf: Cover negative buffer pointer offsets
  • 28ce7bcf8a29 bpf: Add missing access_ok call to copy_user_syms
  • 43f0005f81b8 bpf,fork: wipe ->bpf_storage before bailouts that access it
  • 5a55f9aecc08 bpf: Reset register bounds before narrowing retval range in check_mem_access()
  • 0639ea767fe0 io_uring/bpf-ops: reject re-registration of an already-bound ops
  • 04d23061bbf1 can: bcm: add missing device refcount for CAN filter removal
  • 59bfddea6415 can: bcm: validate frame length in bcm_rx_setup() for RTR replies
  • b6317022b685 can: bcm: track a single source interface for ANYDEV timeout/throttle ops
  • b31d0933509c can: bcm: fix stale rx/tx ops after device removal
  • c312b750bb5a can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()
  • df47f07cdc80 can: bcm: fix CAN frame rx/tx statistics
  • 337f966c0066 can: bcm: extend bcm_tx_lock usage for data and timer updates
  • 30f7bb922cb7 can: bcm: add missing rcu list annotations and operations
  • fc9f5ee1b073 can: bcm: add locking when updating filter and timer values
  • b9c6ac6fb4e0 can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure
  • ce2d4b121fb7 can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF
  • 4f1fdf1a1c31 can: isotp: serialize TX state transitions under so->rx_lock
  • e442b62ba5a7 can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER
  • b8278ff60518 can: isotp: use unconditional synchronize_rcu() in isotp_release()
  • 5832c55b3c82 can: esd_usb: kill anchored URBs before freeing netdevs
  • 046380f3e111 ovl: use linked upper dentry in copy-up tmpfile
  • fd750b694f1f netdev-genl: report NAPI thread PID in the caller's pid namespace
  • fcef60ed5f71 nvmet: fix refcount leak in nvmet_sq_create()
  • 98bcdfa61915 nvmet-rdma: handle inline data with a nonzero offset
  • bc111698b46e nvmet-auth: reject short AUTH_RECEIVE buffers
  • b7d9aaedf024 nvme-apple: Prevent shared tags across queues on Apple A11
  • a192b6c149c6 NFS: Charge unstable writes by request size, not folio size
  • bbd6b2ea966c sctp: validate STALE_COOKIE cause length before reading staleness
  • 077a7bc1c32d spi: uniphier: Fix completion initialization order before devm_request_irq()
  • 40dee2d3e999 spi: imx: reconfigure for PIO when DMA cannot be started
  • 91376c61a5fd time: Fix off-by-one in compat settimeofday() usec validation
  • 947b773caaa5 tpm: Make the TPM character devices non-seekable
  • 98fa6e42fd51 tpm: fix event_size output in tpm1_binary_bios_measurements_show
  • 3ba2b2ef7d6a xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink
  • b4e9dcf4143e xfrm: use compat translator only for u64 alignment mismatch
  • a8a7e6a9ff8a xfrm: nat_keepalive: avoid double free on send error
  • 6883269a3236 xen/gntdev: fix error handling in ioctl
  • 2510434307a2 ufs: core: tracing: Do not dereference pointers in TP_printk()
  • f48d3ae9d320 tcp: Decrement tcp_md5_needed static branch
  • da48b9bf1eb9 tcp: defer md5sig_info kfree past RCU grace period in tcp_connect
  • b7ef06d010c9 ice: fix ice_init_link() error return preventing probe
  • 35176f104612 i2c: spacemit: fix spurious IRQ handling returning IRQ_HANDLED
  • fb267770bf82 i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource()
  • bbc08be46f00 i2c: mediatek: fix WRRD for SoCs without auto_restart option
  • 56ddfc18ea8f i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ)
  • 60ed00d46616 i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
  • c9a0f2bff2cb hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig
  • b9f07a4ec6e3 hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig
  • a0d8e415ebf3 ksmbd: fix integer overflow in set_file_allocation_info()
  • c32f565f3291 smb: client: use kvzalloc() for megabyte buffer in simple fallocate
  • 0bf6482919b9 pkey: Move keytype check from pkey api to handler
  • 301bb780d1b9 platform/x86/amd/pmc: Don't log during intermediate wakeups
  • d53314ae31fd platform/x86/amd/pmc: Add delay_suspend module parameter
  • 675592e86e81 platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops
  • 3002e2dda621 platform/x86/amd/pmc: Check for intermediate wakeup in function
  • 2a42f651cce9 platform/x86: ISST: Restore SST-PP control to all domains
  • 14812174d720 platform/x86: hp-wmi: Add support for Omen 16-ap0xxx (8E35)
  • 4676e81d55ab platform/x86: hp-wmi: Add support for Omen 16-ap0xxx (8D26)
  • b351e082711d platform/x86: dell-laptop: fix missing cleanups in init error path
  • 2137f2154290 platform/x86/intel/tpmi: use cleanup helpers in mem_write()
  • 07ae600bd353 dmaengine: sh: rz-dmac: Move interrupt request after everything is set up
  • 044f7b3252d4 dmaengine: dw-edma-pcie: Reject devices without driver data
  • 070b92cbb82a dmaengine: sh: rz-dmac: Fix incorrect NULL check for list_first_entry()
  • 1553ca96e9df dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK
  • 6e37e9e230c7 dmaengine: tegra: Fix burst size calculation
  • 7d3ce3bd23c0 sunrpc: fix uninitialized xprt_create_args structure
  • 493333f16792 tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt
  • 4bb3e1bc142d tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat()
  • 711cbcb464d2 tpm: restore timeout for key creation commands
  • e5be5d452d5f irqchip/crossbar: Use correct index in crossbar_domain_free()
  • c267911b4226 taskstats: retain dead thread stats in TGID queries
  • f4599793240d mtd: maps: vmu-flash: fix NULL pointer dereference in initialization
  • 57740658042d openrisc: Fix jump_label smp syncing
  • a145b47e22fd mtd: rawnand: Pause continuous reads at block boundaries
  • 007e28b2916d mtd: spi-nor: spansion: use die erase for multi-die devices only
  • 12d4d6922115 mtd: spi-nor: swp: Improve locking user experience
  • 614aa0491c7a s390/pkey: Check length in pkey_pckmo handler implementation
  • 7e7e03848c91 s390/pkey: Check length in PKEY_VERIFYPROTK ioctl
  • 3da8eaf5469e fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header()
  • fe6b606fbf0c net: thunderbolt: Fix frags[] overflow by bounding frame_count
  • 4f6542b14288 bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path
  • e0578493c950 bus: mhi: host: pci_generic: Fix the physical function check
  • f3df5386e3bb fpga: dfl: add bounds check in dfh_get_param_size()
  • 3bfeb436d4be ocfs2: reject non-inline dinodes with i_size and zero i_clusters
  • 60ceecda550e ocfs2: reject dinodes whose i_rdev disagrees with the file type
  • b858f2d57cfc ocfs2: reject dinodes with non-canonical i_mode type
  • 63921f790234 ocfs2: add journal NULL check in ocfs2_checkpoint_inode()
  • 858aa4965ffa ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec
  • 253ed993e0b3 ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits
  • 4d1953d3aeb4 ocfs2: avoid moving extents to occupied clusters
  • 8f575fc17360 mtd: rawnand: fix condition in 'nand_select_target()'
  • 823886a1b089 net/9p: fix infinite loop in p9_client_rpc on fatal signal
  • 3c44f6c62f65 mtd: rawnand: pl353: fix probe resource allocation
  • 20869525a283 ocfs2: use kzalloc for quota recovery bitmap allocation
  • 455519f6b70f mtd: maps: vmu-flash: fix fault in unaligned fixup
  • 9f457beb601d openrisc: Add full instruction cache invalidate functions
  • c8f8e61332ba scsi: sas: Skip opt_sectors when DMA reports no real optimization hint
  • 9fefab759f59 kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES
  • d52d4c9ac716 scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished()
  • 8c1b23d83008 power: supply: bq257xx: Fix VSYSMIN clamping logic
  • 8faccac11e13 9p: skip nlink update in cacheless mode to fix WARN_ON
  • bdcdfc246465 mtd: slram: remove failed entries from the device list
  • 3afd3929fbc7 kcov: use WRITE_ONCE() for selftest mode stores
  • b91e27bce37c mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE
  • 1712a7fa1339 powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors
  • 8e7709aaed66 fs/proc: fix KPF_KSM reported for all anonymous pages
  • b09d5ad00338 proc: only bump parent nlink when registering directories
  • 319caaca072a fs/proc/task_mmu: do not warn on seeing non-migration pmd entry
  • 5ac8f1c56ba1 fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry()
  • 18b8a9700610 fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()
  • 6b7f774b8882 fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race
  • 6b6b5d7c2c95 mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error
  • ee59df7a886a mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs()
  • 837f619f1d98 mm/damon/core: always put unsuccessfully committed target pids
  • 36e4843fe39e riscv: cacheinfo: Fix node reference leak in populate_cache_leaves
  • 2611f7521c6c mm/huge_memory: preserve pmd_swp_uffd_wp on device-private PMD downgrade
  • a1dd41d00c57 mips: sched: Fix CPUMASK_OFFSTACK memory corruption
  • 4d46e07b23d8 selftests/landlock: Test SCOPE_SIGNAL on the SIGIO/fowner pgid path
  • e8631b883338 power: supply: charger-manager: fix refcount leak in is_full_charged()
  • 04916f7dc6d3 landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path
  • 7d7f72cb21a8 ntfs: fix hole runlist memory leak in insert range error path
  • b397b1238a21 ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock()
  • 8f313e92522a ntfs: make system files immutable to prevent corruption
  • 5a5f877c5df7 ntfs: avoid self-deadlock during inode eviction
  • 83f396d881c4 ntfs: sanitize MFT references returned from ntfs_lookup_inode_by_name()
  • d5379035355c ntfs: fail attrlist updates when the superblock is inactive
  • b3d09502b80d ntfs: fix mrec_lock ABBA deadlock in rename
  • a93980141253 ntfs3: fix out-of-bounds read in decompress_lznt
  • 1758a564b6eb ntfs3: validate split-point offset in indx_insert_into_buffer
  • d240f5f9d036 ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head
  • d313416280d4 ntfs3: cap RESTART_TABLE free-chain walker at rt->used
  • 36feda687afe fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}
  • fdf50c788e09 fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
  • 32b9f8733feb fs/ntfs3: validate lcns_follow in log_replay conversion
  • a89c66674283 fs/ntfs3: bound attr_off in UpdateResidentValue against data_off
  • 49c86dae0c0c fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass
  • 554700c65d39 fs/ntfs3: bound DeleteIndexEntryAllocation memmove length
  • 007977325021 fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename
  • b54c9beb90e5 ntfs: reject non-resident records for resident-only attributes
  • bfb01dd319b6 ntfs: validate resident index root values on lookup
  • 18fe978d265b ntfs: validate resident volume name values on lookup
  • 82510cb5c658 ntfs: do not replace volume name after lookup errors
  • 7fb64788812d ntfs: detect mapping-pairs LCN accumulator overflow
  • e2b95d3adb55 ntfs: validate index entries on reading
  • 40ee64e633e5 ntfs: avoid heap allocation for free-cluster readahead state
  • a9cafa8c780f ntfs: only alias volume $UpCase to default on exact match
  • d7773b7af1d2 ntfs: reinit search context before volume information lookup
  • f831ab09d521 ntfs: skip extent mft records in writeback to prevent deadlock
  • b06730c6af58 ntfs: centalize $INDEX_ROOT header validation
  • 0527a81e85ee ntfs: update index root allocated size before shrink
  • aca3d383a23c ntfs: free volume-wide resources on fill_super failure
  • 34a49b3e94a5 ntfs: validate index block header more strictly
  • ceb49c372501 ntfs: not change 0-byte $DATA attribute to non-resident
  • d9d9925de1d8 ntfs: add bounds check before accessing EA entries
  • e4c36dfac57a ntfs: validate attribute values on lookup
  • 353a79fb76bf ntfs: Add WQ_PERCPU to alloc_workqueue users
  • bfe835e535fe ntfs: fix off-by-one in mapping pairs decoding bounds checks
  • 7d702aee1589 ntfs: fix incorrect size of symbolic link
  • 38d444271604 ntfs: grow index root value before reparent header update
  • 57094929cf09 mm/damon/core: make charge_addr_from aware of end-address exclusivity
  • 2f9e3ec17c3d mm/memory_hotplug: fix incorrect altmap passing in error path
  • b785f2bd9496 mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch
  • fc3f0eef426f power: supply: max17042: fix OF node reference imbalance
  • b56a5cbf8f1f power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak
  • b03e62112c9d mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages
  • 3ae86630b94f MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf()
  • 35521e4ec762 MIPS: ip22-gio: fix device reference leak in probe
  • b04bbb89ca3a MIPS: ip22-gio: fix kfree() of static object
  • a018c9b8805c MIPS: ip22-gio: fix gio device memory leak
  • 25bec992181d mm/sparse-vmemmap: fix vmemmap accounting underflow
  • f80fafe24f72 remoteproc: xlnx: Check remote core state
  • e5b1aaa74118 remoteproc: qcom: Fix leak when custom dump_segments addition fails
  • 98414b42530a SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
  • 3a5c55a19cad lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure
  • 3f2dc01b9cb5 lockd: Plug nlm_file leak when nlm_do_fopen() fails
  • 31ba490c02d4 sunrpc: harden rq_procinfo lifecycle to prevent double-free
  • a4f878e8ecd7 sunrpc: wait for in-flight TLS handshake callback when cancel loses race
  • 083e9c2ec7e8 sunrpc: pin svc_xprt across the asynchronous TLS handshake callback
  • c49df5f1e193 pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP
  • ba59b96d8d21 nvdimm/btt: Free arena sub-allocations on discover_arenas() error path
  • 7e49684d90fa nvdimm/btt: Free arenas on btt_init() error paths
  • a58fc10adf50 jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit()
  • fc5eb0962a5e cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size
  • 0ec5c7f03ecf backlight: ktd2801: Enable BL_CORE_SUSPENDRESUME
  • 089ea1e2faf4 mfd: tps6586x: Fix OF node refcount
  • da743704c647 cifs: invalidate cfid on unlink/rename/rmdir
  • 6222b4436865 batman-adv: tt: prevent TVLV OOB check overflow
  • 7d1a877670bc batman-adv: mcast: avoid OOB read of num_dests header
  • 777a88256d6f batman-adv: frag: fix primary_if leak on failed linearization
  • 5a82c5580988 batman-adv: clean untagged VLAN on netdev registration failure
  • 080478388175 batman-adv: frag: free unfragmentable packet
  • ae8355b24abe batman-adv: fix VLAN priority offset
  • aba1cf21954e batman-adv: tt: avoid request storms during pending request
  • 64fd0b0dbb52 batman-adv: dat: fix tie-break for candidate selection
  • dbeb4145d977 batman-adv: ensure minimal ethernet header on TX
  • 4407ff3af469 batman-adv: dat: ensure accessible eth_hdr proto field
  • f4fb97ecf677 batman-adv: bla: reacquire gw address after skb realloc
  • 059a70e1d12d batman-adv: dat: acquire ARP hw source only after skb realloc
  • 9a7b72487981 batman-adv: access unicast_ttvn skb->data only after skb realloc
  • b031fc97e199 batman-adv: retrieve ethhdr after potential skb realloc on RX
  • 916dac5f2944 batman-adv: gw: acquire ethernet header only after skb realloc
  • f79dff8c721b s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()
  • cabcfbc069d8 cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF()
  • a18afd69408c cpufreq: schedutil: Fix uncleared need_freq_update on the .adjust_perf() path
  • fb3b76b5ad2e perf/x86/amd/lbr: Fix kernel address leakage
  • 2e706be56f41 perf/x86/amd/brs: Fix kernel address leakage
  • 64193ed819db x86/boot: Reject too long acpi_rsdp= values
  • 4dad7e870c7e x86/boot: Validate console=uart8250 baud rate to fix early boot hang
  • e5158ff53fdf x86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN"
  • 8a2a0b911cd6 x86/video: Only fall back to vga_default_device() without screen info
  • e8adac69d1bd tools/power/x86/intel-speed-select: Harden daemon pidfile open
  • 2ff8156fd500 mfd: sm501: Fix reference leak on failed device registration
  • 263ccdd627ca leds: uleds: Fix potential buffer overread
  • c9a691350e28 selinux: fix incorrect execmem checks on overlayfs
  • 37d642b37ccd selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()
  • 646ebbc5f2ff selinux: check connect-related permissions on TCP Fast Open
  • fe11d6ce19b2 soc: fsl: qe: panic on ioremap() failure in qe_reset()
  • 9b3325f5a9fb soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy
  • 419d7d930649 gpu/buddy: bail out of try_harder when alignment cannot be honoured
  • 8559b1501f77 gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path
  • 392d033fd372 netfilter: flowtable: use correct direction to set up tunnel route
  • 4ac981a8b7ce netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
  • ec88fa71c820 netfilter: xt_nat: reject unsupported target families
  • 4301ae9ce3d4 netfilter: ecache: fix inverted time_after() check
  • b7a1626c28ba netfilter: xt_physdev: masks are not c-strings
  • 6ff07ac5405b netfilter: nf_conncount: fix zone comparison in tuple dedup
  • 0880c4ed122d netfilter: flowtable: support IPIP tunnel with direct xmit
  • ecb78fbb03d3 netfilter: flowtable: use dst in this direction when pushing IPIP header
  • 00bdce2fda7e netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag
  • 0e76e3e886cc netfilter: nf_nat_sip: reload possible stale data pointer
  • e74f9680e1b6 netfilter: nft_set_pipapo: don't leak bad clone into future transaction
  • b843a96252f6 netfilter: nf_conntrack_sip: validate skb_dst() before accessing it
  • f68305267ebd netfilter: nft_fib: reject fib expression on the netdev egress hook
  • 47b3af24de5f netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst
  • 5b2d4f001001 netfilter: xt_cluster: reject template conntracks in hash match
  • 29e06c8f616c netfilter: nfnl_cthelper: apply per-class values when updating policies
  • eeef3b81f449 netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
  • 214af790e3a3 ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback
  • 03009465312c ASoC: mediatek: mt8183: Release reserved memory on cleanup
  • 80506fcac597 ASoC: mediatek: mt8183: Check runtime resume during probe
  • 4c9df23e121f ASoC: mediatek: mt8192: Release reserved memory on cleanup
  • f6e424835cc0 ASoC: mediatek: mt8192: Check runtime resume during probe
  • 2a591bf6fd41 ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control
  • f4933e1d11b9 ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
  • 6ed7787c43ec ASoC: SOF: topology: fix memory leak in snd_sof_load_topology
  • 2efd9797331a fbdev: tridentfb: fix potential memory leak in trident_pci_probe()
  • ed3b3eb21244 fbdev: nvidia: fix potential memory leak in nvidiafb_probe()
  • 7b96ce9f8e47 fbdev: vesafb: fix memory leak in vesafb_probe()
  • dae8f6ddc35c fbdev: carminefb: fix potential memory leak in alloc_carmine_fb()
  • 2fd16a94bea5 fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe()
  • aa387a3e5180 fbdev: uvesafb: fix potential memory leak in uvesafb_probe()
  • 56964e803915 fbdev: s3fb: fix potential memory leak in s3_pci_probe()
  • 2ede8fa70823 fbdev: i740fb: fix potential memory leak in i740fb_probe()
  • 1b1b43342fbf fbdev: radeon: fix potential memory leak in radeonfb_pci_register()
  • 5276e3f75ddb fbdev: efifb: fix memory leak in efifb_probe()
  • f6a1ac55e6ca fbdev: sm712: Fix operator precedence in big_swap macro
  • 9a94b8553185 fbdev: hecubafb: fix potential memory leak in hecubafb_probe()
  • e818c397548c fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe()
  • a889978ec44f fbdev: metronomefb: fix potential memory leak in metronomefb_probe()
  • bc00e0e376ee KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory
  • 0a5dd8cf4d58 KVM: arm64: nv: Re-translate VNCR before injecting abort
  • 53804b683957 KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN
  • d35defbdfcb1 KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR
  • dd3b237eb778 KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
  • 29227821e232 KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions
  • 7deadbc5dab5 KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2
  • a805ab1914ea KVM: arm64: Ensure level is always initialized when relaxing perms
  • 34d8d7242c52 KVM: arm64: account pKVM reclaim against the VM mm
  • 0cbae0e296d2 KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers
  • 2c87a087c206 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state
  • d5560b6569cd KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails
  • 32bdca80aa81 KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
  • d6b5aba65e99 KVM: TDX: Reject concurrent change to CPUID entry count
  • d2f9df3b615c KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs
  • 124a3769c437 KVM: s390: pci: Fix handling of AIF enable without AISB
  • 7d066368f72e KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal" checks
  • b1a89d12d35a KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling
  • 0658b09cba7f KVM: arm64: vgic: Check the interrupt is still ours before migrating it
  • adce12bb0e0d KVM: s390: pci: Fix GISC refcount leak on AIF enable failure
  • a2e7bbc91cf6 powerpc/pseries/Kconfig: Enable CONFIG_VPA_PMU to be used with KVM
  • ce587046baac KVM: s390: Fix unlikely race in try_get_locked_pte()
  • a4a19941ccb2 KVM: s390: Initialize KVM_S390_GET_CMMA_BITS memory
  • 5fc9690db3bf KVM: s390: vsie: Use mmu cache to allocate rmap
  • eeeb9bc71831 KVM: s390: Silence potential warnings in _gmap_crstep_xchg_atomic()
  • 0c3d4ca328e6 KVM: s390: vsie: Add missing radix_tree_preload() in _gaccess_shadow_fault()
  • bcc6b684fcf6 KVM: s390: vsie: Fix allocation of struct vsie_rmap
  • ac3366245221 LoongArch: KVM: Return full old CSR value from kvm_emu_xchg_csr()
  • 31e99851ee99 LoongArch: KVM: Fix FPU register width with user access API
  • 5c827b66a626 LoongArch: KVM: Check the return values for put_user()
  • d4574547e04a LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt()
  • 8b3e188d19e4 LoongArch: KVM: Validate irqchip index in irqfd routing
  • 81f5b85a5fb0 ARM: dts: stm32: stm32mp15x-mecio1-io: Move expander gpio-line-names to board files
  • 7b5e3c15eee1 ARM: dts: stm32: stm32mp15x-mecio1-io: Fix expander gpio line typo
  • d735c64a1462 ARM: dts: stm32: stm32mp15x-mecio1-io: Move gpio-line-names to board files
  • e61543c0aa5a arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers
  • fc58177cca3b ARM: dts: stm32: stm32mp15x-mecio1-io: Fix GPIO names typo
  • 73e14c8bf53c arm64: dts: imx8ulp-evk: Correct Type-C int GPIO flags
  • 520de5e79dda ARM: dts: stm32: stm32mp15x-mecio1-io: Enable internal ADC reference
  • 0623e082e99a arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc
  • ba13b141ddb5 ARM: dts: stm32: stm32mp15x-mecio1-io: Move divergent mecio1 ADC channels to board files
  • d09c701a531c ARM: dts: stm32: stm32mp15x-mecio1-io: Fix ADC sampling times
  • 12cabe872172 arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Ringneck
  • b5ab9ada87e8 arm64: dts: qcom: sdm630: describe adsp_mem region properly
  • 17b7ab1d26b3 ARM: dts: imx6ul-var-som: fix warning for non-existent dc-supply property
  • 7cc51bb053f6 arm64: dts: renesas: ironhide: Describe inline ECC carveouts
  • 7b71b69719eb arm64: dts: s32g3: Fix SWT8 watchdog address
  • 9b6a94b187f4 arm64: fpsimd: Fix type mismatch in sve_{save,load}_state()
  • b69ad768cd4a net: ife: require ETH_HLEN to be pullable in ife_decode()
  • 463d417a905d octeontx2-vf: clear stale mailbox IRQ state before request_irq()
  • 1ffc164c4744 octeontx2-pf: clear stale mailbox IRQ state before request_irq()
  • 806b7b6edc84 net: atm: reject out-of-range traffic classes in QoS validation
  • 7f72c285f6d3 net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
  • 6acbbe54215d tipc: restrict socket queue dumps in enqueue tracepoints
  • 201b60c4d155 ASoC: SOF: topology: validate vendor array size before parsing
  • 92f90917413b ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get
  • 312c7d2ebe69 ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
  • c29f5b449889 ASoC: SOF: ipc4-control: Validate notification payload size
  • 038406abde0d ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put
  • 00335df9da20 VDUSE: avoid leaking information to userspace
  • 8062ff9d366c vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter
  • 8adebf07b46d mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()
  • cab468c3c03f mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()
  • 708df5274cee idpf: add padding to PTP virtchnl structures
  • 21710f27d55e ring-buffer: Allow sparse CPU masks in ring_buffer_desc()
  • 57e566db78fc tracing/remotes: Fix struct_len in trace_remote_alloc_buffer()
  • 81a7b7ddb07e tracing/remotes: Fix leak in trace_remote_alloc_buffer() error path
  • c25212f274a5 drm/imagination: make pvr_fw_trace_init_mask_ops static
  • 1a638c55f2db smb: client: fix overflow in passthrough ioctl bounds check
  • bf126747e7bf drm/xe: free madvise VMA array on L2 flush failure
  • c69369057b30 drm/xe: remove duplicate <kunit/test-bug.h> include
  • 3cf83432e056 octeontx2-af: fix VF bringup affecting PF promiscuous state
  • 2ae146bcfcc1 ethtool: rss: Fix hfunc and input_xfrm parsing on big endian
  • 7b2fbdafc6de net/mlx5: Fix L3 tunnel entropy refcount leak
  • ddd5ab921fdd selftests/net: fix EVP_MD_CTX leak in tcp_mmap
  • 7d84acf641af drm/fb-helper: Only consider active CRTCs for vblank sync
  • 153d1b8b5bc3 regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK
  • f0eac9c3c371 smb: client: fix busy dentry warning on unmount after DIO
  • b69ea153d30c dm era: fix NULL pointer dereference in metadata_open()
  • d49f6d098ed4 SUNRPC: pin upper rpc_clnt across the TLS connect_worker
  • 9359aac4999e SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED
  • c37abc99bb3d cifs: validate DFS referral string offsets
  • b0640acace25 s390/zcrypt: Remove the empty file
  • 92185d6f7819 ipvs: ensure inner headers in ICMP errors are in headroom
  • f0f35153de83 ipvs: fix PMTU for GUE/GRE tunnel ICMP errors
  • c2ee845e292c ipvs: use parsed transport offset in TCP state lookup
  • 568720055fbd ipvs: pass parsed transport offset to state handlers
  • ef0c7d4b04a0 netfilter: nft_lookup: fix catchall element handling with inverted lookups
  • 95128dc74425 ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer()
  • 1fcabcba272d ipv4: igmp: annotate data-races around timer-related fields
  • 16e5b2dbea49 ipv4: igmp: annotate data-races around im->users
  • 0458ba1cda83 ipv6: mcast: Fix potential UAF in MLD delayed work
  • 8d4394ffa405 ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
  • d73e4d790db6 gpio: mvebu: free generic chips on unbind
  • 46d0fd8535ed perf/x86/amd/core: Avoid enabling BRS from the SVM reload path
  • 543c66cea0e2 octeontx2-pf: check DMAC extraction support before filtering
  • f1e7807df5bf net/sched: cake: reject overhead values that underflow length
  • e3d1ca7882a5 net: mdio: select REGMAP_MMIO instead of depending on it
  • 3861bae3ffe4 selftests: gpio: add gpio-cdev-uaf to .gitignore
  • 5d65dade4d84 drm/v3d: Reject invalid indirect BO handle in indirect CSD setup
  • 91e8109ecffb accel/amdxdna: Fix potential amdxdna_umap lifetime race
  • 6cb18e712feb tracing: Make tracepoint_printk static as not exported
  • 170c008d3f49 drm: Guard DRM_CLIENT_CAP_PLANE_COLOR_PIPELINE
  • 82202fc724f4 gpio: dwapb: Defer clock gating until noirq
  • 8aede22b6a69 net: usb: lan78xx: disable VLAN filter in promiscuous mode
  • 81acef3a247f net/liquidio: drop cached VF pci_dev LUT
  • 40824fc26ad3 net: rnpgbe: fix mailbox endianness and remove pointer casts
  • ebc295ce3436 net/tls: Consume empty data records in tls_sw_read_sock()
  • bea20225c67f accel/amdxdna: Fix VMA access race
  • cf10c506fdbe accel/amdxdna: Use unsigned long for nr_pages in amdxdna_hmm_register()
  • 2d8eeb0578ae accel/amdxdna: Prevent PM resume deadlock in hwctx_sync_debug_bo()
  • 3a63a11897c7 ring-buffer: Fix event length with forced 8-byte alignment
  • d0a2b0c81f11 Bluetooth: L2CAP: fix tx ident leak for commands without a response
  • a8e169d30877 Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
  • 058d0d087a27 Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length
  • 990e65eb9387 Bluetooth: ISO: fix malformed ISO_END/CONT handling
  • 1f9375f55ead Bluetooth: btintel_pcie: Refactor FLR to use device_reprobe()
  • c36895aa1122 Bluetooth: btintel_pcie: Separate coredump work from RX work
  • fb6fc74cc10f Bluetooth: btintel_pcie: Add support for smart trigger dump
  • 4ff5778e8ee3 Bluetooth: btintel_pcie: Support Product level reset
  • a50da115b588 Bluetooth: sco: Fix a race condition in sco_sock_timeout()
  • dbd935a9e056 Bluetooth: MGMT: Fix adv monitor add failure cleanup
  • 32c48c7f6cc8 Bluetooth: 6lowpan: hold L2CAP conn across debugfs control
  • feb3fc2c38ed Bluetooth: 6lowpan: avoid untracked enable work
  • b601c031d4fa drm/i915/ltphy: Fix SSC Enablement bit in PORT_CLOCK_CTL
  • 0b98a503ed1e gpio: shared: make the voting mechanism adaptable
  • 8d12d1fede47 smb: client: preserve leading slash for POSIX absolute symlink targets
  • a1f2ada2e4d3 ksmbd: fix multichannel binding and enforce channel limit
  • 5a632f2f207e amt: fix size calculation in amt_get_size()
  • ce5aa8084329 net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
  • 8e49cd891bda net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload
  • 231a8a4b76cb net: qualcomm: rmnet: validate MAP frame length before ingress parsing
  • 982d6d6bc059 qede: fix off-by-one in BD ring consumption on build_skb failure
  • 952928564cc5 net: microchip: vcap: fix races on the shared Super VCAP block
  • 815515ec68f5 net/mlx5e: Fix publication race for priv->channel_stats[]
  • f5677797b094 net/mlx5e: Fix HV VHCA stats agent registration race
  • abc4c56427f1 net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation
  • 98fc2deffcf1 drm/bridge: analogix_dp: Fix PE/VS value shift mismatch during link training
  • 5a95aa0198af net/mlx5e: TC, skip peer flow cleanup when LAG seq is unavailable
  • 4d720c6c60e1 net/mlx5: LAG, MPESW, Fix missing complete() on devcom error
  • 40cc06bf7147 net/mlx5: LAG, Fix off-by-one in single-FDB error rollback
  • fd2ef924a56f net/mlx5: LAG, extend shared FDB API with group_id filter
  • d14f2dbf727c net/mlx5: LAG, prepare for SD device integration
  • 5092213b9a31 net/mlx5: LAG, replace peer count check with direct peer lookup
  • 3b8b364f97f4 net/mlx5: LAG, factor out shared FDB code into dedicated file
  • 7ac37a167cc6 net/mlx5: Lag, avoid LAG and representor lock cycles
  • db9e44e0ed63 net/mlx5: E-Switch, add representor lifecycle lock
  • 25d4c0948300 net/mlx5: Lag: refactor representor reload handling
  • 6f2cb20d8e28 platform/x86: bitland-mifs-wmi: Fix NULL pointer dereference during suspend/resume
  • 230173cc6105 netfilter: xt_connmark: reject invalid shift parameters
  • 94427ca35943 netfilter: nft_set_rbtree: get command skips end element with open interval
  • d5e39e5eb6b3 netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
  • 905a927b2e6f netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()
  • 00d034fe8230 netfilter: xt_u32: reject invalid shift counts
  • f618cbe9b24c gue: validate REMCSUM private option length
  • ea866cab12db net: usb: net1080: validate packet_len before pad-byte access in rx_fixup
  • 9d343a4889e5 arm64/sysreg: Fix BWE field encoding in ID_AA64DFR2_EL1
  • 79b33d9f1d9c selftests/hid: Cover hid_bpf_get_data() size overflow
  • b56f874e49e6 selftests/hid: Load only requested struct_ops maps
  • f81bc5a709dc HID: bpf: Fix hid_bpf_get_data() range check
  • 3dd3e43f17cd ntfs: avoid stale runlist element dereference in fallocate
  • 6706e332151b iio: dac: mcp47feb02: Fix passing uninitialized vref1_uV for no Vref1 case
  • 9a1479b05bd9 arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range()
  • 67a863ceb348 arm64: Avoid eager DVMSync reclaim batches with C1-Pro SME erratum
  • f7e8117e42b2 HID: core: Fix OOB read in hid_get_report for numbered reports
  • ef649703dce0 HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait()
  • 9a2e36963a3f ntfs: avoid stale runlist element dereference in MFT writeback
  • be47c0472506 netfs: Fix barriering when walking subrequest list
  • 9da2e4275e64 ata: libata-scsi: limit simulated SCSI command copy to response length
  • 35cb43b721c0 ata: sata_gemini: unwind clocks on IDE pinctrl errors
  • 3a303f985c6b cifs: Fix missing credit release on failure in cifs_issue_read()
  • 1acddd3e22dd uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline
  • fa8fd23e3a87 x86/uprobes: Keep shadow stack in sync for emulated CALLs
  • 2b6b3f98d0e9 drm/xe/pt: prevent invalid cursor access for purged BOs
  • 5ff2212f0e07 drm/xe: fix NPD in bo_meminfo()
  • a4208d8032ab drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays
  • 23ee91355e31 drm/xe/hw_engine: Fix double-free of managed BO in error path
  • f1a1909f36b7 drm/xe/userptr: Drop bogus static from finish in force_invalidate
  • ab9ea5c943c7 drm/xe/userptr: Hold notifier_lock for write on inject test path
  • 159f9aa8d2e0 drm/imagination: Fix returned size for DRM_IOCTL_PVR_DEV_QUERY
  • d94b9922b2ae drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()
  • 1a4421c7a561 netfs: Fix folio state after ENOMEM whilst under writeback iteration
  • 89df9c158a25 netfs: Fix writeback error handling
  • 0348e3fa0dfb netfs: Fix writethrough to use collection offload
  • 68fb8a93a34b cachefiles: Fix file burial to take lock when unsetting S_KERNEL_FILE
  • 1188a9846fad netfs: Fix netfs_create_write_req() to handle async cache object creation
  • 7f7780abb4c0 iomap: guard io_size EOF trim against concurrent truncate underflow
  • 3c181e6ff1f4 ovl: fix comment about locking order
  • 26757dac1517 cachefiles: Fix double unlock in nomem_d_alloc error path
  • 8a29e60e2176 minix: avoid overflow in bitmap block count calculation
  • 27ddd3442fc6 iomap: release pages on atomic dio size mismatch
  • 89ec425b454e afs: Fix unchecked-length string display in debug statement
  • d0c8ad418b47 afs: Fix the volume AFS_VOLUME_RM_TREE is set on
  • c9a0b9e5f3d4 afs: Fix premature cell exposure through /afs
  • e94f92fd56c5 afs: Fix lack of locking around modifications of net->cells_dyn_ino
  • 91d8f8e5fd34 afs: Fix vllist leak
  • 9cabf1c86948 afs: Fix leak of ungot volume
  • 1bdbc50e2d41 afs: Use scoped_seqlock_read() rather than manually doing seqlock stuff
  • e3e59ff22a0d afs: Fix missing NULL pointer check in afs_break_some_callbacks()
  • f14dd036fad3 afs: Fix callback service message parsers to pass through -EAGAIN
  • ebfd13c0367a afs: Fix reinitialisation of the inode, in particular ->lock_work
  • 654a546c34f3 afs: Fix misplaced inc of net->cells_outstanding
  • 552d3c0f184a afs: Fix bulk lookup malfunction due to change in dir_emit() API
  • ca9f19505077 afs: Remove erroneous seq |= 1 in volume lookup loop
  • 84e4b9232a32 afs: use kvfree() to free memory allocated by kvcalloc()
  • 6d52ff4c866e afs: Fix directory inode initialisation order
  • 9d6b0f6d437e afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints
  • 462eada939f2 afs: Fix double netfs initialisation in afs_root_iget()
  • bdcd80ff1293 afs: Fix error code in afs_extract_vl_addrs()
  • 47e434da476b fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid
  • fc9332533a58 net/sched: hhf: clear heavy-hitter state on reset
  • d25cdea6226c net/sched: dualpi2: clear stale classification on filter miss
  • d1297a9e2fd6 xen/pvcalls: bound backend response req_id before indexing rsp[]
  • feba85c0eeda pinctrl: meson: restore non-sleeping GPIO access
  • 2ef42bd9a8b7 gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe
  • ed98719be413 ksmbd: fix use-after-free of fp->owner.name in durable handle owner check
  • 15a9e9b8f7f5 ksmbd: reject undersized DACLs before parsing ACEs
  • b0933dede95d net/sched: act_bpf: use rcu_dereference_bh() to read the filter
  • 24e63c47668a selftests: drv-net: tso: don't touch dangerous feature bits
  • 9717091371d7 cxgb4: Fix decode strings dump for T6 adapters
  • 13741bad74d4 virtio_net: disable cb when NAPI is busy-polled
  • c3e5cac47519 sctp: fix addr_wq_timer race in sctp_free_addr_wq()
  • ac39628cb3ef spi: rzv2h-rspi: Fix DMA transfer error handling for signal interruption
  • 9ed0dca2aa05 irqchip/ts4800: Fix missing chained handler cleanup on remove
  • 5459f4f32a8e irqchip/gic-v3-its: Fix OF node reference leak
  • 57e1f2cd6a0e tracing/probes: Make the $ prefix mandatory for comm access
  • d655cca1c6e6 tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry()
  • f4461db8eb8e tracing: eprobe: read the complete FILTER_PTR_STRING pointer
  • 10a33029e1cf tracing/events: Fix to check the simple_tsk_fn creation
  • 8a662d8c05e2 tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg
  • 9acf6f34eb48 tracing/eprobes: Allow use of BTF names to dereference pointers
  • 2c88ad0d06c6 drm/panthor: Interrupt group start/resumption if group_bind_locked() fails
  • 893ed1a7c837 drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced
  • 50556bfe1d6c drm/panthor: Fix panthor_pwr_unplug()
  • 1352cd192e5b drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick()
  • 361adc5343e9 drm/panthor: Fix theoretical IOMEM access in suspended state
  • 1c942c3c5179 drm/panthor: Store IRQ register base iomem pointer in panthor_irq
  • 34eb9945a075 drm/panthor: Split register definitions by components
  • 85c6f80499e6 drm/panthor: Pass an iomem pointer to GPU register access helpers
  • 053522ba6158 drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom()
  • 752a08cfeeea drm/panthor: Keep the reset work disabled until everything is initialized
  • 2946aa6c97ac drm/panthor: Always use the IRQ-safe variant when acquiring the fence lock
  • 8a277a20258d gpio: shared-proxy: always serialize with a sleeping mutex
  • 40cbfa3a28e0 bridge: stp: Fix a potential use-after-free when deleting a bridge
  • b26aa9d99353 net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF
  • b637d6b72661 net: gianfar: dispose irq mappings on probe failure and device removal
  • 14b4cb78c332 net: libwx: fix VMDQ mask for 1-queue mode
  • 2381bf3f484e net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy
  • 3ef79fa3860e usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()
  • 110ccbd28c94 ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump
  • 21f304c2aae4 eth: fbnic: don't cache shinfo across skb realloc
  • fb8a5afe6f1f hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero
  • b0ff6b6ae9c5 hwmon: (pmbus) Fix passing events to regulator core
  • 93b96e723bdc hwmon: adm1275: Prevent reading uninitialized stack
  • 65e7e2b8d71b accel/amdxdna: Fix iommu domain lifetime race during device removal
  • 5bd0d4764039 hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid()
  • 492d0c8f78d4 ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280
  • f3ed74540244 MIPS: mm: Add check for highmem before removing memory block
  • 3aca736e177f MIPS: DEC: Ensure RTC platform device deregistration upon failure
  • 062bcbf8d1f1 sctp: add INIT verification after cookie unpacking
  • f7776052bb23 sctp: fix SCTP_RESET_STREAMS stream list length limit
  • d22829101ab6 net: enetc: check the number of BDs needed for xdp_frame
  • 6d46ab395803 qede: fix out-of-bounds check for cqe->len_list[]
  • c9961336aa5f seg6: validate SRH length before reading fixed fields
  • e1fc4b00b96d net: pse-pd: scope pse_control regulator handle to kref lifetime
  • 151db2b54744 gpio: htc-egpio: use managed gpiochip registration
  • 537e75aeb9cc gpio: mvebu: fail probe if gpiochip registration fails
  • d8df91756890 bpf: Fix insn_aux_data leak on verifier err_free_env path
  • 1c53d16b174d bpf: Mask pseudo pointer values in verifier logs
  • 5c907c11615f riscv: Fix 32-bit call_on_irq_stack() frame pointer ABI
  • d1a22906727b ACPI: RIMT: Only defer the IOMMU configuration in init stage
  • c637ec6a4592 spi: sh-msiof: abort transfers when reset times out
  • b2fa801be46d tracing: probes: fix typo in a log message
  • 3ab06151ffcb ALSA: FCP: Fix NULL pointer dereference in interface lookup
  • b4c34415b82b net: hns3: differentiate autoneg default values between copper and fiber
  • 783dcef78cb0 net: hns3: fix permanent link down deadlock after reset
  • 99f6a07add50 net: hns3: refactor MAC autoneg and speed configuration
  • ac04c2c833dd net: hns3: unify copper port ksettings configuration path
  • 9715ea1ceab7 selftests: tls: size splice_short pipe by page size
  • 522d1d950b9e tipc: avoid busy looping in tipc_exit_net()
  • 1c8393eefa3c tipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy()
  • 46d8d5b02f89 tipc: Store struct sock in struct udp_bearer.
  • 80e9adfed05d udp_tunnel: Pass struct sock to setup_udp_tunnel_sock().
  • ea0eb61029e0 udp_tunnel: Pass struct sock to udp_tunnel_sock_release().
  • cd37bcb67f90 net: enetc: fix potential divide-by-zero when num_vsi is zero
  • 2542ce01d811 dt-bindings: net: renesas,ether: Drop example "ethernet-phy-ieee802.3-c22" fallback
  • 54292b167466 net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync
  • c5fafece300c ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count
  • 0ddb9dcabf0b LoongArch: BPF: Fix off-by-one error in tail call
  • 09068613dd0d LoongArch: BPF: Fix outdated tail call comments
  • ee79d03aafb5 LoongArch: Move struct kimage forward declaration before use
  • fe0669928f27 net: stmmac: dwmac-spacemit: Fix wrong irq definition
  • a77abd7a3490 net: stmmac: dwmac-spacemit: Fix wrong phy interface definition
  • c3e27e4ee524 net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove
  • bc49e8746584 net: sungem: fix probe error cleanup
  • fb42560afec5 tools: ynl: build archives with $(AR)
  • e2087447f562 geneve: validate inner network offset in geneve_gro_complete()
  • 49c2e7c0a699 geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
  • 5bdb33ff6e58 net: mvneta: re-enable percpu interrupt on resume
  • 0fd234bc1264 octeontx2-af: fix CGX debugfs RVU AF PCI reference leaks
  • b1f6381acf9d octeontx2-af: Validate NIX maximum LFs correctly
  • ba933c5f3568 net: phy: realtek: Clear MDIO_AN_10GBT_CTRL_ADV10G bit
  • 7d47925c2c64 net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0
  • cf52622fbc27 net: dsa: mxl862xx: fix use-after-free of DSA ports in crc_err_work
  • 245c6c8a2958 net: dsa: mxl862xx: avoid unaligned 16-bit access in api_wrap
  • c21f7ee511ae net: dsa: realtek: fix memory leak in rtl8366rb_setup_led()
  • a427cfa41796 rtc: cmos: unregister HPET IRQ handler on probe failure
  • 5904fd94f919 rtc: ds1307: Fix off-by-one issue with wday for rx8130
  • cddbfbc71085 smb/client: preserve errors from smb2_set_sparse()
  • 8bbe4dd79645 ACPI: processor_idle: Mark LPI enter functions as __cpuidle
  • 42d4fc933280 ACPICA: Unbreak tools build after switching over to strscpy_pad()
  • 156af6606f36 thermal: testing: zone: Flush work items during cleanup
  • fda07c8e4b54 s390/mm: Fix handling of _PAGE_UNUSED pte bit
  • ca2dbee8fea6 eth: fbnic: fix ordering of heartbeat vs ownership
  • 7a368c754a96 ipv6: fix missing notification for ignore_routes_with_linkdown
  • b91ac71fc2a2 ipv6: fix state corruption during proxy_ndp sysctl restart
  • 764ac02cbd3b ipv6: fix error handling in disable_policy sysctl
  • 420e895fb41d ipv6: fix error handling in forwarding sysctl
  • a39ff02a241c ipv6: fix error handling in ignore_routes_with_linkdown sysctl
  • e28bada56f4f ipv6: fix error handling in disable_ipv6 sysctl
  • 94f55994e19e sctp: fix err_chunk memory leaks in INIT handling
  • e28aedab9488 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
  • 19eec11f3ab5 net: lwtunnel: Drop skb metadata before LWT encapsulation
  • cc27e4514e6e net: usb: lan78xx: restore VLAN and hash filters after link up
  • 4bd2e5dbe623 veth: fix NAPI leak in XDP enable error path
  • 20d4a9dea55b net: ti: icssg: Fix XSK zero copy TX during application wakeup
  • 09efce96c909 net: dsa: sja1105: round up PTP perout pin duration
  • a3d0c8b437ef net: do not acquire dev->tx_global_lock in netdev_watchdog_up()
  • 89c103d702b2 net, bpf: check master for NULL in xdp_master_redirect()
  • 752b781b0c0a Docs/driver-api/uio-howto: document mmap_prepare callback
  • c19faa40b37d alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs
  • 257b55dc3d18 alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
  • 75d7a27c506e NTB: epf: Fix doorbell bitmask and IRQ vector handling
  • bfe11cd91ab0 NTB: epf: Report 0-based doorbell vector via ntb_db_event()
  • 583a4a19eefc NTB: epf: Make db_valid_mask cover only real doorbell bits
  • 9787c2d17111 PCI: endpoint: pci-epf-vntb: Exclude reserved slots from db_valid_mask
  • 9e105f6a14fb ASoC: rt5575: Use __le32 for SPI burst write address
  • 33387bf9bb61 ASoC: SDCA: Validate written enum value in ge_put_enum_double()
  • 0ae6e70edc33 cpuidle: Allow exit latency to exceed target residency
  • c239f2d879ab netfilter: nf_conntrack_helper: cap maximum number of expectation at helper registration
  • e3b7789be80d netfilter: nft_ct: expectation timeouts are passed in milliseconds
  • f32e644fe365 netfilter: nf_conntrack_expect: run expectation eviction with no helper
  • 3401ab813d27 netfilter: nf_conntrack_expect: store master_tuple in expectation
  • 7ec786f4230c netfilter: nf_conntrack_expect: use conntrack GC to reap expectations
  • 743209358ff8 netfilter: conntrack: check NULL when retrieving ct extension
  • ae568b6f16e0 netfilter: nf_conntrack_pptp: move GRE specific cleanup to GRE tracker
  • a1572284b14e netfilter: nf_conntrack_helper: dynamically allocate struct nf_conntrack_helper
  • 40c14ce49963 gpio: davinci: fix IRQ domain leak on devm_kzalloc failure
  • c129b0185e70 netfilter: nft_compat: ebtables emulation must reject non-bridge targets
  • 2f71ca368ffd netfilter: nft_synproxy: stop bypassing the priv->info snapshot
  • 025a41e76b51 netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()
  • be52572c6d55 netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
  • eb14aba91163 netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()
  • 1bb3b6a5c3c5 bpf: Disable xfrm_decode_session hook attachment
  • d684b72dfbd3 md/raid5: avoid R5_Overlap races while breaking stripe batches
  • 4465211d195d md/raid5: use stripe state snapshot in break_stripe_batch_list()
  • a668fa160247 ipv4: fib: Don't ignore error route in local/main tables.
  • c5bd84c6cd77 eth: bnxt: improve the timing of stats
  • 6428634f7a0b ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().
  • 1c89da3baa2b ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE
  • 03ae998ae623 selftests/bpf: Cover small conntrack opts error writes
  • dd74c8020384 bpf: Guard conntrack opts error writes
  • bb3e624808c9 rtc: msc313: fix NULL deref in shared IRQ handler at probe
  • 5f2cfe30af5a e1000e: Reconfigure PLL clock gate timeout and re-enable K1 on Meteor Lake
  • 939756efe505 i40e: Fix i40e_debug() to use struct i40e_hw argument
  • 40c68e35e700 ice: dpll: fix memory leak in ice_dpll_init_info error paths
  • 17c0a9db05e3 ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info
  • 19ec35b79913 rtc: isl1208: Balance enable_irq_wake() with disable_irq_wake() on cleanup
  • 6c70914ab629 ice: call netif_keep_dst() once when entering switchdev mode
  • 4f13a0a479b5 ice: fix AQ error code comparison in ice_set_pauseparam()
  • b1fc5bafbc5f ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs()
  • 0f9278b22cda bpf: Preserve pointer spill metadata during half-slot cleanup
  • 233170ad54d3 PCI: endpoint: pci-epf-vntb: Report 0-based doorbell vector via ntb_db_event()
  • 93a85a6aca19 PCI: endpoint: pci-epf-vntb: Defer pci_epc_raise_irq() out of atomic context
  • 528cfbcc47bb PCI: endpoint: pci-epf-vntb: Document legacy MSI doorbell offset
  • a58543f1e1cc PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0
  • 750dd7546de3 PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0
  • 937f77a79636 ASoC: cs530x: Fix expected MCLK rates for CS5302/4/8
  • 50456f445fee erofs: handle 48-bit blocks_hi for compressed inodes
  • 4137e1ecec9c drm/edid: fix OOB read in drm_parse_tiled_block()
  • 6558811274c8 gpiolib: initialize return value in gpiochip_set_multiple()
  • 7dba66caf98e power: sequencing: fix ABBA deadlock in pwrseq_device_unregister()
  • b584f107ab90 bpf: Fix effective prog array index with BPF_F_PREORDER
  • d977b2aff9f7 bpf: Fix BPF_PROG_ASSOC_STRUCT_OPS last field check
  • 8b996c555575 bpf: zero-initialize the fib lookup flow struct
  • 7faf89ed5b4c bpftool: Fix vmlinux BTF leak in cgroup commands
  • 89cf4d0c71a2 bpf: Fix partial copy of non-linear test_run output
  • db8f1dcf5950 bpf: Fix stack slot index in nospec checks
  • 9242939dd6d9 rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231
  • fc4f78e8f034 rtc: abx80x: fix the RTC_VL_CLR clearing all status flags
  • 84ac7a0f9562 dpaa2-switch: do not accept VLAN uppers while bridged
  • 5a3b2ee1e96d ipv6: ioam: fix type confusion of dst_entry
  • 63d1c23764de ipv6: ndisc: fix NULL deref in accept_untracked_na()
  • f4d7d8fdcc59 net: airoha: Fix skb->priority underflow in airoha_dev_select_queue()
  • 0c3d8fc87e10 net/sched: act_ct: fix nf_connlabels leak on two error paths
  • 44068b6863fb net: emac: Fix NULL pointer dereference in emac_probe
  • d0ab67f7e7cf octeontx2-pf: mcs: Fix mcs resources free on PF shutdown
  • e7f1311e7ef3 octeontx2-pf: Clear stats of all resources when freeing resources
  • a56fd8449de8 octeontx2-af: mcs: Fix unsupported secy stats read
  • e129d1a4c2ba octeontx2-af: npc: cn20k: fix NPC defrag
  • c36cecf9903f net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths
  • 7ce31739fe88 net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone
  • b65289e1c3f3 tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
  • 31d486562062 net: marvell: prestera: initialize err in prestera_port_sfp_bind
  • 8c439591f703 selftests/mm: fix exclusive_cow test fork() handling
  • 214ba4596887 selftests/mm: remove hardcoded THP sizing assumptions in hmm tests
  • 679642fa56d5 selftests/mm: allow PUD-level entries in compound testcase of hmm tests
  • 0481f4bad161 selftests/mm: clarify alternate unmapping in compaction_test
  • 2a018e29ac5f selftests/mm: move hwpoison setup into run_test() and silence modprobe output for memory-failure category
  • 835ef922f3ba selftests/mm: run_vmtests.sh: free memory if available memory is low
  • de72caed5077 selftests/mm: skip uffd-stress test when nr_pages_per_cpu is zero
  • e186a9ac7af4 selftests/mm: ensure destination is hugetlb-backed in hugetlb-mremap
  • e0f39f7671a9 selftest/mm: register existing mapping with userfaultfd in hugetlb-mremap
  • 7c0ba2376d40 selftests/mm: free dynamically allocated PMD-sized buffers in split_huge_page_test
  • 5b136718617a selftests/mm: size tmpfs according to PMD page size in split_huge_page_test
  • aef0f2059a97 selftests/mm: fix cgroup task placement and drop memory.current checks in hugetlb_reparenting_test.sh
  • 4a1e9beaff98 selftests/mm: fix hugetlb pathname construction in hugetlb_reparenting_test.sh
  • 95f64f30431e selftests/mm: restore default nr_hugepages value via exit trap in hugetlb_reparenting_test.sh
  • 65a7bc39d4a2 selftests/mm: fix hugetlb pathname construction in charge_reserved_hugetlb.sh
  • 83d9d5f63cc9 selftests/mm: restore default nr_hugepages value via exit trap in charge_reserved_hugetlb.sh
  • 008ceffd4404 alloc_tag: fix use-after-free in /proc/allocinfo after module unload
  • 810779623104 irqchip/crossbar: Fix parent domain resource leak
  • 74b19383580d mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx()
  • c041d2be785f tpm_crb: Check ACPI_COMPANION() against NULL during probe
  • 4dce8bf588a8 netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak
  • a259780ddf1d netfilter: nf_reject: skip iphdr options when looking for icmp header
  • a75f7745dc8f netfilter: nft_flow_offload: zero device address for non-ether case
  • c3167c9c6433 netfilter: nft_meta_bridge: add validate callback for get operations
  • 94daa48ea7b6 netfilter: nft_payload: reject offsets exceeding 65535 bytes
  • c78bd5195a59 netfilter: ipset: make sure gc is properly stopped
  • 93a775fd67f3 netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
  • 7efd8a1c96c7 netfilter: ipset: Don't use test_bit() in lockless RCU readers in bitmap types
  • 3219d74e4536 netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types
  • c6e635429584 md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry
  • 937c3e44ecaf md/raid1: honor REQ_NOWAIT when waiting for behind writes
  • d1324b41dabd md/raid10: fix writes_pending and barrier reference leaks on discard failures
  • f94031c94eae md/raid10: fix writes_pending leak on write request failures
  • bffbbfcbd939 md/raid1: fix writes_pending and barrier reference leaks on write failures
  • 4fe0635fe604 mac802154: Prevent overwrite return code in mac802154_perform_association()
  • f14802465f59 ieee802154: fix kernel-infoleak in dgram_recvmsg()
  • 4c3717546878 ieee802154: Remove WARN_ON() in cfg802154_pernet_exit()
  • 6fcba77571c5 ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns()
  • 8a4eae78287a ieee802154: Restore initial state on failed device_rename() in cfg802154_switch_netns()
  • 315e1efc3f16 ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone()
  • 8dcf676092ff ACPI: resource: Amend kernel-doc style
  • 172e690bab7a thermal: intel: Fix dangling resources on thermal_throttle_online() failure
  • 02f1d4b40eb4 arm64/hw_breakpoint: reject unaligned watchpoints that would truncate BAS
  • fde42e9f5c59 arm64: static_call: include asm/insns.h
  • 7f8d816a9aa2 netfilter: flowtable: fix and simplify IP6IP6 tunnel handling
  • 68286258698e ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints
  • d9ac4239157e eth: fbnic: take netif_addr_lock_bh() around rx mode address programming
  • 41b70eff0392 selftests: vlan_bridge_binding: Fix flaky operational state check
  • 0b17f320893a netconsole: don't drop the last byte of a full-sized message
  • 825de39f0c35 flow_dissector: check device type before reading ETH_ADDRS
  • 9acbcb89190a net: macb: add TX stall timeout callback to recover from lost TSTART write
  • 9f7cd1e26d2f net: airoha: fix foe_check_time allocation size
  • f5adcb9245ae devlink: Fix parent ref leak on tc-bw failure
  • 21f7e96cf164 devlink: Fix parent ref leak in devl_rate_node_create()
  • dbb6321c2977 dpaa2-switch: fix VLAN upper check not rejecting bridge join
  • e6b8463b7d79 virtio-net: fix len check in receive_big()
  • d654af91739a spi: rpc-if: Use correct device for hardware reinitialization on resume
  • aa80fca32cf7 PCI: iproc: Restore .map_irq() for the platform bus driver
  • ec6fb1ecada8 ALSA: usb-audio: qcom: clear opened when stream enable fails
  • a22356d1f731 ALSA: usb-audio: qcom: reject stream disable with no active interface
  • f09a245f33e5 sctp: hold socket lock when dumping endpoints in sctp_diag
  • 794a0d8bdbb3 net: psample: fix info leak in PSAMPLE_ATTR_DATA
  • e19d38d397d4 octeontx2-af: npc: Log successful MCAM drop-on-non-hit install at debug level
  • 452ec5058ea4 octeontx2-pf: Fix leak of SQ timestamp buffer on teardown
  • 043ed6924c63 selftests/ftrace: Fix trace_marker_raw test on 64K page kernels
  • e5c6debdad28 net: ethernet: mtk_eth_soc: fix supported_interface set after phylink_create
  • bc88744dc556 drm/amdgpu: initialize irq.lock spinlock earlier
  • e33a3bd5cb8d drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm
  • db803223edc4 drm/amd/display: Fix mem_type change detection for async flips
  • db70b4a08211 drm/amd/display: Skip PHY SSC reduction on some 8K panels
  • 7f20ce7b2bcf drm/amdgpu: initialize iter.start in amdgpu_devcoredump_format
  • 1d12ae8b079e drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free
  • e2ab48e8591d ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode
  • 77961e12ea16 perf dso: Set standard errno on decompression failure
  • aa967ae8b256 perf bpf: Validate array presence before casting BPF prog info pointers
  • bfc764f9de65 perf c2c: Fix hist entry and format list leaks in c2c_he_free()
  • 502ee1fe757a perf c2c: Free format list entries when c2c_hists__init() fails
  • 79b92b298b5c perf cs-etm: Bounds-check CPU in cs_etm__get_queue()
  • 2d5a695a9d19 perf cs-etm: Require full global header in auxtrace_info size check
  • f22dbfb71c3d perf cs-etm: Validate num_cpu before metadata allocation
  • 7c7245321599 perf machine: Use snprintf() for guestmount path construction
  • 5a03a2ee17e8 xfrm: validate selector family and prefixlen during match
  • 7394a276f869 xfrm: annotate data-races around xfrm_policy_count[] and xfrm_policy_default[]
  • 041859fd55c8 xfrm: Fix xfrm state cache insertion race
  • f83ef148a94b ALSA: usb-audio: qcom: Free sideband sg_table objects
  • 9104559db16b erofs: call erofs_exit_ishare() before rcu_barrier()
  • a6b17b34aedc i3c: master: Add missing runtime PM get in dev_nack_retry_count_store()
  • b5d5cfea4f23 i3c: master: Update dev_nack_retry_count under maintenance lock
  • 7f29c063c53f spi: dw: fix wrong BAUDR setting after resume
  • a5c5676ad3b0 drm/xe: Fix wa_oob codegen recipe for external module builds
  • ac554ad94361 drm/i915: clear CRTC color blob pointers after dropping refs
  • 9f171aa115ec regcache: Do not overwrite error code when finalizing cache after error
  • e06ad4356915 gpio: mlxbf3: fail probe if gpiochip registration fails
  • 99ab295d8025 perf cs-etm: Reject CPU IDs that would overflow signed comparison
  • 6d2aa8dfea1f perf c2c: Free format list entries when releasing c2c hist entries
  • 62a11653847f perf bpf: Bounds-check array offsets in bpil_offs_to_addr()
  • f9ec0eda83ea perf bpf: Reject oversized BPF metadata events that truncate header.size
  • 3fe6751a0697 perf bpf: Validate func_info_rec_size and sub_id in synthesize_bpf_prog_name()
  • eaab676863cb perf sched: Replace (void*)1 sentinel with proper runtime allocation
  • dd8e455fd91e perf hwmon: Fix fd check to accept fd 0 in hwmon_pmu__describe_items()
  • 97584371d5d8 perf tools: Use snprintf() for root_dir path construction
  • 2367ebcd0d4b perf dso: Set error code when open() fails on uncompressed fallback path
  • c5dcbd5cf007 perf dso: Fix heap overflow in dso__get_filename() on decompressed path
  • df77307da9da perf symbols: Break infinite loop on zero-filled notes in sysfs__read_build_id()
  • 6172d92a7f15 perf symbols: Validate p_filesz before use in filename__read_build_id()
  • 1ce03f1d990e perf symbols: Fix bswap copy-paste error for 32-bit ELF p_filesz
  • a06241a08631 perf maps: Add maps__mutate_mapping
  • abbdd94e6a10 sparc: led: avoid trimming a newline from empty writes
  • f55b1ff89938 accel/ivpu: fix HWS command queue leak on registration failure
  • 30521e7ec4d8 apparmor: fix label can not be immediately before a declaration
  • 4b0c34521747 i3c: master: Prevent reuse of dynamic address on device add failure
  • 8f851cab401c i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev()
  • 50eabb91d2de i3c: master: Defer new-device registration out of DAA caller context
  • fef9bdaa0df0 i3c: master: Ensure Hot-Join operations are stopped on shutdown
  • 08b33dfd457b i3c: master: Consolidate Hot-Join DAA work in the core
  • 21cf9175b370 i3c: master: Serialize i3c_set_hotjoin() with the maintenance lock
  • af6df5d50607 i3c: master: Make hot-join workqueue freezable to block hot-join during suspend
  • 88116f41086a i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring
  • 49a230c2aea4 i3c: mipi-i3c-hci: Fix suspend behavior when bus disable falls back to software reset
  • 4238195ed989 apparmor: Fix inverted comparison in cache_hold_inc()
  • a5c79d44ef19 apparmor: fix uninitialised pointer passed to audit_log_untrustedstring()
  • 3f172fbbe357 apparmor: don't audit files pointing to aa_null.dentry
  • 859ba6c7fc6e apparmor: put secmark label after secid lookup
  • b1abb5340737 apparmor: aa_getprocattr free procattr leak on format failure
  • de91788aa6b8 apparmor: remove unnecessary goto and associated label
  • 393809a05cfb apparmor: release exe file resources on path failure
  • 106e909e12ba apparmor: fail policy unpack on accept2 allocation failure
  • bd30d91f9f22 apparmor: Fix return in ns_mkdir_op
  • 2118a9f7a7ed apparmor: remove or add symlinks to rawdata according to export_binary
  • 73d86ca950b8 apparmor: fix NULL pointer dereference in unpack_pdb
  • dd5f1202f45a apparmor: fix potential UAF in aa_replace_profiles
  • 67ee65ec1a3e apparmor: grab ns lock and refresh when looking up changehat child profiles
  • 4a2c4f2b45dc apparmor: fix rawdata_f_data implicit flex array
  • 6d9147917424 apparmor: aa_label_alloc use aa_label_free on alloc failure
  • ec926b2a351e apparmor: check label build before no_new_privs test
  • 25b262492539 security/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref()
  • b8642f147898 apparmor: fix refcount leak when updating the sk_ctx
  • d680472db988 apparmor: fix race in unix socket mediation when peer_path is used
  • ec95dec9ae2c apparmor: fix shadowing of plabel that prevents cache from being updated
  • 3691a82be209 Revert "PCI/MSI: Unmap MSI-X region on error"
  • 91fbf0de91bc Documentation: ABI: sysfs-class-reboot-mode-reboot_modes: fix doc warnings
  • 375e1defdeb8 sparc: Avoid -Wunused-but-set-parameter in clear_user_page()
  • 63a300151999 xfrm: Fix dev use-after-free in xfrm async resumption
  • 855870e8c59b PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability
  • 972052764672 phy: freescale: phy-fsl-imx8qm-lvds-phy: Fix missing pm_runtime_disable() on probe error path
  • d31244d1732e phy: freescale: phy-fsl-imx8qm-lvds-phy: Use synchronous PM runtime put in reset
  • 393f0bb61545 PCI: mediatek: Use actual physical address instead of virt_to_phys()
  • f66b4e65c4cc dt-bindings: phy: sc8280xp-qmp-pcie: Disallow bifurcation register on Purwa
  • e30fa32cd078 dt-bindings: dma: snps,dw-axi-dmac: Add fallback compatible for CV1800B
  • 65a406f5bbd9 perf symbols: Add bounds checks to read_build_id() note iteration in minimal build
  • e525be3207ed perf symbols: Add bounds checks to elf_read_build_id() note iteration
  • 802257fbe4ea perf bpf: Fix metadata leak in perf_env__add_bpf_info() on duplicate insert
  • 7e841b7b1014 perf bpf: Fix map data leak in bpf_metadata_create() on alloc failure
  • 77373bfa2564 perf bpf: Add NULL check for btf__type_by_id() in synthesize_bpf_prog_name()
  • df7d723d66bd tools lib api: Fix mount_overload() snprintf truncation and toupper range
  • 62adda4bb1b8 tools lib api: Fix filename__write_int() writing uninitialized stack data
  • 908bc5238979 perf tools: Use snprintf() in dso__read_running_kernel_build_id()
  • 1577822e1fa1 perf hwmon: Guard label read against empty or failed reads
  • 2bfaa207732a perf tools: Fix uninitialized pathname on uncompressed fallback in filename__decompress()
  • a11731df15af perf symbols: Bounds-check descsz in sysfs__read_build_id() GNU fallback
  • 354a61c752ea perf hwmon: Fix parse_hwmon_filename() strlcpy buffer overflow
  • f99e250f8085 perf hwmon: Use scnprintf() in hwmon_pmu__for_each_event()
  • 4c7ed5f4ff36 perf hwmon: Fix off-by-one null termination on sysfs reads
  • 6290c0c0fb2b perf tools: Fix thread__set_comm_from_proc() on empty comm file
  • 8532c1725abb perf intel-pt: Fix snprintf size tracking bug in insn decoder
  • 5e5b4cfffb4a perf tools: Use mkostemp() for O_CLOEXEC on temporary files
  • 51d3124590bc perf symbols: Bounds-check .gnu_debuglink section data
  • 519b4ad15b2c perf symbols: Fix signed overflow in sysfs__read_build_id() size check
  • b4333af83c12 tools lib api: Fix missing null termination in filename__read_int/ull()
  • a407a5177cd1 perf pmu: Fix perf_pmu__parse_scale/unit() OOB access on empty sysfs file
  • 1202ebd3a9b4 perf pmu: Fix pmu_id() heap underwrite on empty identifier file
  • 4d72f46d420f perf cs-etm: Queue context packets for frontend
  • c091fe7073b0 perf data convert json: Fix addr_location leak on time-filtered samples
  • d625d9b320c2 perf s390: Fix TEXTREL in Python extension by compiling as PIC
  • 31298d37687b xprtrdma: Return sendctx slot after Send preparation failure
  • d7c531ab477a xprtrdma: Repost Receive buffers for malformed replies
  • 33db78b1b24f xprtrdma: Sanitize the reply credit grant after parsing
  • 118a16a18c59 xprtrdma: Fix bcall rep leak and unbounded peek
  • 69c956c1b67d xprtrdma: Resize reply buffers before reposting receives
  • 96da53e7d6f9 xprtrdma: Document and assert reply-handler invariants
  • ef3b79edf14b xprtrdma: Check frwr_wp_create() during connect
  • 264ccd787191 xprtrdma: Initialize re_id before removal registration
  • ffc077905397 xprtrdma: Fix ep kref imbalance on ADDR_CHANGE
  • f025990647c8 perf tools: Use scnprintf() in build_id__snprintf() and hwmon read_events()
  • a6d9b8184656 perf hists: Fix snprintf() in hists__scnprintf_title() UID filter path
  • 5f3b8ff3f632 perf bpf: Use scnprintf() in snprintf_hex() and synthesize_bpf_prog_name()
  • 01d67b6f44ed perf tools: Add O_CLOEXEC to open() calls in DSO and ELF code
  • a757d523741d perf sched: Fix idle-hist callchain display using wrong rb_first variant
  • 23af74f538b7 perf sched: Bounds-check prio before test_bit() in timehist
  • 2c0461f5393b PCI: rcar-host: Remove unused LIST_HEAD(res)
  • 027c177da2b5 perf tools: NULL bitmap pointers after bitmap_free()
  • eb266a14c16a perf tools: Use perf_env__get_cpu_topology() in machine__resolve()
  • 36d2c15a33ec perf tools: Use scnprintf() in cpu_map__snprint() to prevent overflow
  • 678bb88bb977 perf tools: Fix get_max_num() size_t underflow on empty sysfs file
  • 962c7a1f8f1e platform/x86/intel/vsec: Restore BAR fallback for header walk
  • c99444f6dfca fs/ntfs3: resize log->one_page_buf when adopting on-disk page size
  • 7ae7e98b7143 fs/ntfs3: prevent potential lcn remains uninitialized
  • b052df3a5953 virtio: add missing kernel-doc for map and vmap members
  • a2cc03ee5d34 lockd: Correct kernel-doc status descriptions for NLMv4 GRANTED
  • ec52cdcbf23f PCI: meson: Add missing remove callback
  • 221972a90c56 PCI: meson: Propagate devm_add_action_or_reset() failure
  • f966db2568c4 pwm: rzg2l-gpt: Add missing newlines to dev_err_probe() messages
  • fa7ce7dfbd2d PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro
  • e68035178e65 nfs: use nfsi->rwsem to protect traversal of the file lock list
  • 51e5adebef61 NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write
  • 0fe1ac2bda64 NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors
  • 7471673936d1 nfs: keep PG_UPTODATE clear after read errors in page groups
  • 72c578ca2f9e NFSv4/pnfs: defer return_range callbacks until after inode unlock
  • 8203f760a72b xprtrdma: Decouple req recycling from RPC completion
  • 7c42bc9cb7d3 xprtrdma: Use sendctx DMA state for Send signaling
  • fa977d37765b pNFS/filelayout: fix cheking if a layout is striped
  • f0dfbca47b9e sunrpc: Fix error handling in rpc_sysfs_xprt_switch_add_xprt_store()
  • e2414f2a3f12 clk: qcom: a53: Corrected frequency multiplier for 1152MHz
  • 65e82fa24965 dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor
  • f055829151ee dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc
  • 0bc191050c32 dmaengine: Fix possible use after free
  • c1a2159c1100 dmaengine: qcom: gpi: set DMA_PRIVATE capability
  • fb372cbccab6 mshv: add bounds check on vp_index in mshv_intercept_isr()
  • 89acfa8ad3af docs: memfd_preservation: fix rendering of ABI documentation
  • 2ce2a2e19b62 clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks
  • ca461a2a7390 dt-bindings: clock: qcom: Add X1P42100 camera clock controller
  • a0c08cdaf63a perf sched: Free callchain nodes in idle thread cleanup
  • 5e7c076511bf perf tools: Fix int16_t truncation of max_cpu_num in set_max_cpu_num()
  • cb47a3546f52 perf timechart: Fix cpu2y() OOB read on untrusted CPU index
  • 231acb6d0e14 perf c2c: Fix use-after-free in he__get_c2c_hists() error path
  • 423c520416d7 perf stat: Introduce perf_env__get_cpu_topology() to guard NULL env->cpu
  • 6cfa75ce9a82 perf mmap: Fix NULL deref in aio cleanup on alloc failure
  • f09f7be6bba1 perf sched: Replace BUG_ON and add NULL checks in replay event helpers
  • 6380a4f550dc perf sched: Use thread__put() in free_idle_threads()
  • 1f0a529864d8 perf sched: Fix thread reference leak in idle hist processing
  • 3ba9b69aef73 perf sched: Use is_idle_sample() for idle thread runtime cast guard
  • 340b08cfa751 perf sched: Clean up idle_threads entry on init failure
  • 4884cfb0d36d perf c2c: Bounds-check CPU IDs in setup_nodes() topology loop
  • 937be22cf6d2 perf c2c: Bounds-check CPU and node IDs before bitmap and array access
  • 9cbb9f3e532e perf stat: Bounds-check CPU index in topology aggregation callbacks
  • 5257dfb9619c perf mmap: Guard cpu__get_node() return in aio_bind()
  • 5ea1dcc9418c perf sched: Fix register_pid() overflow, strcpy, and BUG_ON
  • 68b6157d2c62 perf sched: Cap max_cpu at MAX_CPUS in timehist sample processing
  • 380ad7297fa0 perf sched: Fix thread reference leaks in timehist_get_thread()
  • 6587c61570f4 perf tools: Add bounds check to cpu__get_node()
  • bd027a461624 perf tools: Guard remaining test_bit calls from OOB sample CPU
  • e94a56aac6b4 perf sched: Fix comp_cpus heap overflow with cross-machine recordings
  • 70d31bdd3789 perf sched: Fix NULL dereference in latency_runtime_event
  • bbaa0a0441d2 perf sched: Replace BUG_ON on invalid CPU with graceful skip
  • a4ec6bf24145 perf sample: Add file_offset field to struct perf_sample
  • b189fce8d2ac perf sched: Fix thread reference leak in latency_switch_event
  • d88a630bacfa perf tools: Guard test_bit from out-of-bounds sample CPU
  • 885bd036cbdf perf annotate: Fix crashes on empty annotate windows
  • 25b1f78ef352 perf: Fix off-by-one stack buffer overflow in kallsyms__parse()
  • 4442e8c8f20f dt-bindings: dma: nvidia,tegra186-gpc-dma: Make reset optional
  • 4e8f512e2b8f dmaengine: imx-sdma: Refine spba bus searching in probe
  • 3ea71aa629a7 thunderbolt: debugfs: Fix margining error counter buffer leak
  • 994a42b890ce drm/amd/display: Add missing kdoc for ALLM parameters
  • 668791009a21 fs/ntfs3: fix mount failure on 64K page-size kernels
  • bc95e2f61192 ntfs3: avoid another -Wmaybe-uninitialized warning
  • 3cd2212012c0 ntfs3: Allocate iomap inline_data using alloc_page
  • ff825bf0521f fs/ntfs3: call _ntfs_bad_inode() when failing to rename
  • 1f6111ad30d2 fs/ntfs3: fix wrong LCN in run_remove_range() when splitting a run
  • 41081202eb82 fs/ntfs3: add bounds check to run_get_highest_vcn()
  • 3dcdf8ddb509 clk: spacemit: k3: Fix PCIe clock register offset
  • 0b4739fc72db clk: spacemit: k3: Switch to pll2_d6 as parent for PCIe clock
  • d823ab4592b3 docs: changes.rst: restore pahole 1.26 minimum (regressed by sort)
  • 83d87cbfa3aa HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter
  • b7ef2eb23936 clk: at91: keep securam node alive while mapping it
  • 8c00cabb1982 iio: tcs3472: power down chip on probe failure
  • f3d413e701c5 iio: accel: mma8452: handle I2C read error(s) in mma8452_read()
  • 3c374d33f133 iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling
  • fb27ebf81136 iio: magnetometer: ak8975: fix potential kernel stack memory leak
  • 7f167853ef3c iio: light: si1133: prevent race condition on timeout
  • 2413ede67e39 iio: light: si1133: reset counter to prevent race condition
  • 8e8b52ad5ab5 perf header: Validate bitmap size before allocating in do_read_bitmap()
  • ea63c57eb2f1 perf header: Sanity check HEADER_EVENT_DESC attr.size before swap
  • 27ca3f615c1a timers/migration: Update stale @online doc to @available
  • d61e42f63a00 PCI: qcom: Disable ASPM L0s for SA8775P
  • c764d5092b92 powerpc tools perf: Initialize error code in auxtrace_record_init function
  • 0e1db8dc4623 docs: threat-model: add missing closing parenthesis
  • 789d1b0e1118 clk: renesas: rzg2l: Rename iterator in for_each_mod_clock() to avoid shadowing
  • f15a545f7518 gpib: cb7210: Fix region leak when request_irq fails
  • 8b5f1d295dda gpib: fix double decrement of descriptor_busy in command_ioctl()
  • a41f0fbd77ae sonypi: Check ACPI_COMPANION() against NULL at probe time
  • 99a34d028293 hpet: Check ACPI_COMPANION() against NULL at probe time
  • 42223445607a char: tlclk: fix use-after-free in tlclk_cleanup()
  • 49489a18afa5 gpib: Fix inappropriate ioctl error return
  • ecdd8af41197 perf test amd ibs: Fix incorrect kernel version check
  • 684a58dd845e usb: host: max3421: Reject hub port requests for non-existent ports
  • 4da073d57176 usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
  • 7fc162453cfb staging: most: video: avoid double free on video register failure
  • b1493c42183f perf inject: Fix itrace branch stack synthesis
  • 034182b63108 perf event: Fix size of synthesized sample with branch stacks
  • 7e374ac7702b perf build-id: Fix off-by-one bug when printing kernel/module build-id
  • 8b54808fcced clk: microchip: mpfs-ccc: fix peripheral driver registration failures after oob fix
  • b670ac2731dd platform/x86: classmate-laptop: Address memory leaks on driver removal
  • ce5633204a4b PCI: mediatek-gen3: Fix incorrectly skipped pwrctrl error message
  • e31173a19466 PCI: dwc: Fix signedness bug in fault injection test code
  • 8ca9adc80588 coresight: platform: defer connection counter increment until alloc succeeds
  • f344f6ae8517 PCI/pwrctrl: Lock device when calling device_is_bound()
  • ac8a86dcaf59 mailbox: don't free the channel if the startup callback failed
  • 25d6ea6c76e1 mailbox: mtk-adsp: fix UAF during device teardown
  • 8ceeb0541978 mailbox: mpfs: fix check for syscon presence in mpfs_mbox_inbox_isr()
  • 80cf6501acb9 PCI: mediatek-gen3: Do full device power down on removal
  • 8c1dac9c05d4 coresight: Handle helper enable failure properly
  • c37f87151990 coresight: Fix source not disabled on idr_alloc_u32 failure
  • 81ed540159ef soundwire: intel_ace2x: release bpt_stream when close it
  • abdfdb8e6220 iio: light: acpi-als: Check ACPI_COMPANION() against NULL
  • 14622b111e4e clk: at91: sam9x7: Fix gmac_gclk clock definition
  • 8a7a8ac82791 perf pmu: Skip test on Arm64 when #slots is zero
  • 03dda04f2f76 perf unwind: Refactor get_entries to allow dynamic libdw/libunwind selection
  • 9810f833df66 perf pmu-events AMD: Switch l2_itlb_misses to bp_l1_tlb_miss_l2_tlb_miss.all
  • cb329b1fa702 phy: phy-can-transceiver: Check driver match and driver data against NULL
  • 0ba6fd199192 PCI: qcom: Set max OPP before DBI access during resume
  • 72a7bfee9fe8 PCI: dwc: Apply ECRC workaround for DesignWare cores prior to 5.10a
  • f478709f7be8 dt-bindings: clock: qcom,sm6125-dispcc: reference qcom,gcc.yaml
  • 6c7f2108af20 clk: qcom: cmnpll: Account for reference clock divider
  • d1da8fcb8802 coresight: fix missing error code when trace ID is invalid
  • adec0b0df4e2 bus: mhi: ep: Add missing state_lock protection for mhi_state access
  • e30fa2246972 bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
  • 34b2a1076dd7 rust: alloc: fix assert in Vec::reserve doc test
  • 1f95260a8237 PCI: loongson: Do not ignore downstream devices on external bridges
  • f62ffd973b07 PCI: intel-gw: Add .start_link() callback
  • b2dd40f1d15e PCI: intel-gw: Enable clock before PHY init
  • 28c35ea3515f PCI: intel-gw: Move interrupt enable to own function
  • fc9d6f815871 perf tool: Fix missing schedstat delegates and dont_split_sample_group in delegate_tool
  • 6ed3cea56b77 perf sched: Add missing mmap2 handler in timehist
  • f05c3b4c9cc0 platform/x86: xo15-ebook: Fix wakeup source and GPE handling
  • df6d71c9a818 x86/platform/olpc: xo15: Drop wakeup source on driver removal
  • 721ad5b72448 PCI: Check ROM header and data structure addr before accessing
  • 4e82818ead50 PCI: Introduce named defines for PCI ROM
  • d50ba5e4642c PCI/ASPM: Don't reconfigure ASPM entering low-power state
  • 12007c55d9c0 coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore
  • 293dacd5b6a9 coresight: ete: Always save state on power down
  • 9d802907fc2a coresight: tmc: Fix overflow when calculating is bigger than 2GiB
  • e483a406a23a soundwire: fix bug in sdw_add_element_group_count found by syzkaller
  • f0481e6bcc5d soundwire: don't program SDW_SCP_BUSCLOCK_SCALE on a unattached Peripheral
  • fbd5d3168740 coresight: cti: Fix DT filter signals silently ignored
  • 2830eedfcc7d perf callchain: Handle multiple address spaces
  • ffddd64eae0b perf debuginfo: Fix libdw API contract violations
  • 2a86103b44af perf annotate-data: Fix libdw API contract violations
  • 881af00c02c0 perf probe-finder: Fix libdw API contract violations
  • d739d9f4525b perf libdw: Fix libdw API contract violations and memory leaks
  • e542c8800bbc perf srcline: Introduce inline_node__clear_frames()
  • eb0062b3e76d perf dwarf-aux: Fix libdw API contract violations
  • 23ec342a8fa6 perf dwarf-aux: Fix libdw segmentation fault in cu_walk_functions_at
  • 5de04caa46b6 staging: nvec: fix use-after-free in nvec_rx_completed()
  • fde2296f87b7 staging: rtl8723bs: fix stainfo check in rtw_aes_decrypt
  • 697af8745d5c i3c: master: svc: Fix missed IBI after false SLVSTART on NPCM845
  • b0194db10032 gpiolib: acpi: Only trigger ActiveBoth interrupts on boot
  • 4791b91daeb1 eventpoll: Fix epoll_wait() report false negative
  • 8679e9e06876 eventpoll: rename epi->next and txlist for clarity
  • b698ee9abf40 eventpoll: expand top-of-file overview / locking doc
  • 0c44866f4a23 9p: Add missing read barrier in virtio zero-copy path
  • ebbcbe5c0db2 net/9p: fix race condition on rdma->state in trans_rdma.c
  • fdc9043cfd50 9p: avoid returning ERR_PTR(0) from mkdir operations
  • f3dd1e534e9d ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write
  • 17d79248b4f3 mfd: cs42l43: Sanity check firmware size
  • afb1a5af6dd9 mfd: rsmu: Fix page register setup
  • e18ffb7541de mfd: bd72720: Drop BUCK11 ID
  • 0ff82a9cf931 ksmbd: fix use-after-free in same_client_has_lease()
  • 2fface6e0bbd net: serialize netif_running() check in enqueue_to_backlog()
  • bde37aed0724 RDMA/irdma: Replace waitqueue and flag with completion
  • bc4caea7a82b RDMA/hns: Fix memory leak of bonding resources
  • 967099102562 RDMA/bnxt_re: Reject GET_TOGGLE_MEM when toggle page was not allocated
  • 03c9a2fba68e RDMA/bnxt_re: Fail DBR related page allocation UAPIs if the feature is disabled
  • da406b8b49c1 RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
  • 303f6fef95df RDMA/bnxt_re: Proper rollback if the ioremap fails
  • a59d815cbe66 RDMA/bnxt_re: Add a max slot check for SQ
  • a65b5258b14c RDMA/bnxt_re: Enable app allocated QPs
  • 6eceb09df972 RDMA/bnxt_re: Support doorbells for app allocated QPs
  • 2234acd1d1d2 RDMA/bnxt_re: Enhance dbr usecnt logic in doorbell uapis
  • 3169824fd8f4 RDMA/bnxt_re: Update msn table size for app allocated QPs
  • 7605fd8bbf4d RDMA/bnxt_re: Refactor bnxt_re_init_user_qp()
  • 0c403e078676 RDMA/bnxt_re: Avoid displaying the kernel pointer
  • b193854675ec RDMA/bnxt_re: Free CQ toggle page after firmware teardown
  • 0adcd67f3d6f RDMA/bnxt_re: Free SRQ toggle page after firmware teardown
  • 3d00b375853f RDMA/bnxt_re: Initialize dpi variable to zero
  • 5126f099295c ionic: Fix check in ionic_get_link_ext_stats
  • d01d4cfc806a net: ethernet: oa_tc6: Remove FCS size in RX frame
  • 785e3765bf9a net: ti: icssg: Use undirected TX tag for XDP zero copy in HSR offload mode
  • 40a91dcc6260 net: ti: icssg: Use undirected TX tag for native XDP in HSR offload mode
  • b478a6ffda4e net: ti: icssg-prueth: Fix AF_XDP fill ring alloc and wakeup condition
  • ad262d2b96be net: airoha: Fix always-true condition in PPE1 queue reservation loop
  • a210791f3334 tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)
  • 35e0297a93c3 tipc: fix UAF in tipc_l2_send_msg()
  • d2fb2ef76008 KEYS: Use acquire when reading state in keyring search
  • c893bfb0d696 powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus
  • e4e69cee0b01 powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down
  • b504fd953664 powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del
  • 038f068cced8 MIPS: mm: Fix out-of-bounds write in maar_res_walk()
  • e09f7bd72739 bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check
  • 39d44ed6904b sockmap: Fix use-after-free in udp_bpf_recvmsg()
  • bd004716ba75 bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
  • 478c7f68ef25 udf: fix nls leak on udf_fill_super() failure
  • c12e3c9e5224 bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket
  • e68343ee3c13 selftests/bpf: Initialize operation name before use
  • 85100de4f473 selftests/bpf: Fix typo in verify_umulti_link_info
  • c6d51ad36490 bpf: Guard __get_user acesss with access_ok for uprobe_multi data
  • 590d696f846a btrfs: Drop WQ_PERCPU from ordered_flags in btrfs_init_workqueues()
  • 2bc610c9db5d smb/client: always return a value for FS_IOC_GETFLAGS
  • 7839f1817a0c cifs: remove all cifs files before kill super
  • 018b3c8248f5 smb: client: fix conflicting option validation for new mount API
  • b8ca5fcc3182 ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait()
  • 1e8ff78520d9 geneve: Fix off-by-one comparing with GRO_LEGACY_MAX_SIZE
  • edf234f71fb3 netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them
  • db50e2d289b6 netfilter: nf_conncount: callers must hold rcu read lock
  • 1c4c35fb68d5 ALSA: seq: avoid stale FIFO cells during resize
  • 43e10709b1ba ALSA: seq: oss: Serialize readq reset state with q->lock
  • 9684fff87124 kcm: use WRITE_ONCE() when changing lower socket callbacks
  • 6b638db5ec06 net: airoha: Fix debugfs new-tuple display for IPv4 ROUTE entries
  • 2ac37fca3052 net: airoha: Fix register index for Tx-fwd counter configuration
  • be55f99a0b08 octeontx2-af: fix NPC mailbox codes in mbox.h
  • 6be4da4f5a16 net: bcmgenet: Use weighted round-robin TX DMA arbitration
  • d0de5037dce5 landlock: Fix unmarked concurrent access to socket family
  • 467ae77921ad dpll: balance create/delete notifications in _dpll_pin(un)register
  • 8c48e6581c43 dpll: guard sync-pair removal on full pin unregister
  • dc37a9a94954 dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister()
  • 0ea6703cb3dc dpll: send delete notification before unregister in on-pin rollback
  • 75a52d107203 dpll: fix stale iteration in dpll_pin_on_pin_unregister()
  • 4c1b25d85f4c net: wwan: t7xx: check skb_clone in control TX

View originalPermalink

7.1.4-xanmod1
  • 967cc061f0dc Linux 7.1.4-xanmod1
  • d3dc120f721d Merge tag 'v7.1.4' into 7.1
  • 7a5cef0db479 Linux 7.1.4
  • 63940a3adc7d xfs: use rtrefcount btree cursor in xchk_xref_is_rt_cow_staging
  • 5394c215efde xfs: write the rg superblock when fixing it
  • 4d281a74eed8 xfs: fix off-by-one error when calling xchk_xref_has_rt_owner
  • 19fa8bc0df48 xfs: don't zap bmbt forks if they are MAXLEVELS tall
  • 704a6ba079f0 xfs: fully check the parent handle when it points to the rootdir
  • cb1f92cb29cc xfs: clamp timestamp nanoseconds correctly
  • b7e9edbed705 xfs: handle non-inode owners for rtrmap record checking
  • 261c7a32f637 xfs: set xfarray killable sort correctly
  • 5da68d6c927a xfs: use the rt version of the cow staging checker
  • b19e5b47424b xfs: grab rtrmap btree when checking rgsuper
  • 2b14fe1e0924 xfs: don't wrap around quota ids in dqiterate
  • 44f891bc0889 xfs: resample the data fork mapping after cycling ILOCK
  • cccbabeb9a18 xfs: fail recovery on a committed log item with no regions
  • 0bc4d4a97302 xfs: fix null pointer dereference in tracepoint
  • 57cba95f0e97 smb: client: reject overlapping data areas in SMB2 responses
  • 25e2ac320c3d Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev
  • 07e454687b13 timekeeping: Register default clocksource before taking tk_core.lock
  • ae8f855a28e0 ALSA: doc: usb-audio: Add doc for QUIRK_FLAG_IFB_SILENCE_ON_EMPTY
  • 0a7f33010c0e fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref
  • a635f427d57e fuse-uring: make a fuse_req on SQE commit only findable after memcpy
  • 4021a3a79eee fuse-uring: Avoid queue->stopped races and set/read that value under lock
  • 95d7f50aff2a fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues
  • 4f45f276d5b4 fuse-uring: end fuse_req on io-uring cancel task work
  • e8afc85acdf3 fuse-uring: fix moving cancelled entry to ent_in_userspace list
  • d01a09b442cb fuse-uring: fix data races on ring->ready
  • fe604c08d874 fuse-uring: fix EFAULT clobber in fuse_uring_commit
  • 893479015cb6 fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req
  • 1ec674d3d0ed fuse: don't block in fuse_get_dev() for non-sync_init case
  • 1f3f4060e656 fuse: fix io-uring background queue dispatch on request completion
  • 65a1c2551f7e fuse: re-lock request before returning from fuse_ref_folio()
  • 779b7f1fcdee fuse: do not use start_removing_noperm()
  • 81b1045c401c fuse: fix device node leak in cuse_process_init_reply()
  • a37a64ebc9d7 Revert "fuse: fix conversion of fuse_reverse_inval_entry() to start_removing()"
  • c78c4b242299 fuse: avoid 32-bit prune notification count wrap
  • 7ddcbd4dd85f fuse: back uncached readdir buffers with pages
  • 75c93cd3c421 RDMA/siw: bound Read Response placement to the RREAD length
  • 020700a2fdc4 RDMA/core: Fix broadcast address falsely detected as local
  • da3e44add94b RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
  • 2ffcdbfd1431 Input: maplecontrol - set driver data before registering input device
  • 79e6fd106356 Input: maplemouse - set driver data before registering input device
  • 2351e841951c Input: maple_keyb - set driver data before registering input device
  • d5ab7e52e86e Input: mms114 - fix multi-touch slot corruption
  • 2914e243ec9e Input: maplemouse - fix NULL pointer dereference in open()
  • b75371bc87ae Input: gscps2 - advance receive buffer write index
  • f3d5e77b27fd Input: mms114 - reject an oversized device packet size
  • a8d87184576c Input: touchwin - reset the packet index on every complete packet
  • 2691b68f9b03 Input: ads7846 - don't use scratch for tx_buf when clearing register
  • a747c4eb0265 Input: mms114 - fix touch indexing for MMS134S and MMS136
  • a40250f97c31 Input: iforce - bound the device-reported force-feedback effect index
  • 2a6766869012 Input: goodix - clamp the device-reported contact count
  • 6bac57d8fe2a Input: elan_i2c - prevent division by zero and arithmetic underflow
  • bfe622efecd4 Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
  • 64fb0e1161cc Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count
  • 43d61346c040 Input: synaptics-rmi4 - unregister function handlers on physical driver registration failure
  • 00904687b9c5 i2c: i801: fix hardware state machine corruption in error path
  • 5800647d19d3 i2c: imx-lpi2c: mark I2C adapter when hardware is powered down
  • 1f0ab044e106 i2c: stm32f7: truncate clock period instead of rounding it
  • cb037e697da0 i2c: davinci: Unregister cpufreq notifier on probe failure
  • d8c97bde8224 i2c: mpc: Fix timeout calculations
  • 35dbd1f1f603 i2c: core: fix adapter deregistration race
  • 036d554f532b i2c: core: fix adapter debugfs creation
  • 76402d37a5de i2c: core: fix adapter probe deferral loop
  • 034e30742811 i2c: core: fix NULL-deref on adapter registration failure
  • 3d760ca230b0 i2c: core: fix irq domain leak on adapter registration failure
  • fb2c0eab51ae fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
  • 284d5ba931a5 Revert "svcrdma: Use contiguous pages for RDMA Read sink buffers"
  • 40eedc4253db svcrdma: wake sq waiters when the transport closes
  • 0449a6583c0e dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning
  • 18bd476ef4a1 udmabuf: fix DMA direction mismatch in release_udmabuf()
  • cd1067ccc0db KVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier
  • f3a98d5881b9 KVM: guest_memfd: Treat memslot binding offset+size as unsigned values
  • f2ca2b532621 KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits
  • bf27cd2d58a4 KVM: TDX: Account all non-transient page allocations for per-TD structures
  • f0a47e6cb035 KVM: VMX: Handle bad values on proxied writes to LBR MSRs
  • aa41338ee2db KVM: SEV: Don't terminate SNP VMs on #VMGEXIT without a registered GHCB
  • 77eab9571f6d KVM: VMX: Refresh GUEST_PENDING_DBG_EXCEPTIONS.BS on all injected #DBs
  • dda5ce3fdf89 KVM: SVM: Only disable x2AVIC WRMSR interception for MSRs that are accelerated
  • a3487d5926dd KVM: SVM: Disable x2AVIC RDMSR interception for MSRs KVM actually supports
  • 256034648b9e KVM: x86: Add dedicated API for getting mask of accelerated x2APIC MSRs
  • dcdb476f5fc5 KVM: SEV: Pin source page for write when adding CPUID data for SNP guest
  • d4f4d61715d1 KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
  • 7fca3fcef81c KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU
  • 60e51a62170a LoongArch: KVM: Add missing slots_lock for device register/unregister
  • 5fd30133af86 KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB
  • 5c22e38cfb73 selftests/landlock: Increase default audit socket timeout
  • 395135628ad5 selftests/landlock: Filter dealloc records in audit_count_records()
  • 7621e00a4059 landlock: Account all audit data allocations to user space
  • c02f2a0ae1c1 selftests/landlock: Explicitly disable audit in teardowns
  • 0254cef9bf18 landlock: Set audit_net.sk for socket access checks
  • fe85607ceffc audit: fix removal of dangling executable rules
  • 2c6381d90898 iommufd: Set upper bounds on cache invalidation entry_num and entry_len
  • 0714e5a4c83e iommufd: Avoid partial fault group delivery in iommufd_fault_fops_read()
  • f66c16b17550 iommufd: Break the loop on failure in iommufd_fault_fops_read()
  • 76c05bd8f634 iommufd: Reject invalid read count in iommufd_fault_fops_read()
  • db4e1a1e9f13 iommufd: Propagate allocation failure in iommufd_veventq_deliver_fetch()
  • f682c833f7d5 iommufd: Reject invalid read count in iommufd_veventq_fops_read()
  • 7a860d6f260e iommufd: Rewind header length in done if iommufd_veventq_fops_read() fails
  • e7b5e5565274 iommufd: Set veventq_depth upper bound
  • 6c5fc40200cd iommufd: Move vevent memory allocation outside spinlock
  • f9f08e46b9e3 iommufd: Fix data_len byte-count vs element-count mismatch
  • 0cdbb97a4dbd iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read
  • ff189754fc34 iommu/amd: Don't split flush for amd_iommu_domain_flush_all()
  • 477f8dec3b5a iommu/vt-d: Avoid WARNING in sva unbind path
  • c76b8abce575 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
  • 49af4044ed98 nouveau/vmm: fix another SPT/LPT race
  • f250db8ea6e9 selftests/mm: fix ksft_process_madv.sh test category
  • 913324904ce9 selftests/mm: pagemap_ioctl: use the correct page size for transact_test()
  • 04ba248d02d9 mm: do file ownership checks with the proper mount idmap
  • 377b1cd6bbcf mm: page_ext: add count limit to page_ext_iter_next to prevent invalid PFN access
  • fceca62a095e selftests: mm: fix and speedup "droppable" test
  • 246f0713360a mm: fix mmap errno value when MAP_DROPPABLE is not supported
  • 9adedf9c885c lib/test_hmm: use kvfree() to free kvcalloc() allocations
  • ede985ff4b56 riscv: mm: Unconditionally sfence.vma for spurious fault
  • bc773b8b4c81 riscv: mm: Define DIRECT_MAP_PHYSMEM_END
  • 84ab222021c2 NTB: epf: Fix request_irq() unwind in ntb_epf_init_isr()
  • c8e041c68c0b exfat: bound uniname advance in exfat_find_dir_entry()
  • 5bfa2814528d exfat: preserve benign secondary entries during rename and move
  • c4c82cdfdf8a vt: fix spurious modifier in CSI/cursor key sequences
  • e7da02659c22 module: decompress: check return value of module_extend_max_pages()
  • 8e0a22bc728e rqspinlock: Fix order in raw_res_spin_(un)lock_irq to allow schedule
  • e36501b7d4ab NFSv4: include MAY_WRITE in open permission mask for O_TRUNC
  • 80a7608376e5 audit: fix potential integer overflow in audit_log_n_hex()
  • e5d5f3bd053a tracing: Prevent out-of-bounds read in glob matching
  • 792118d05f01 selftests/liveupdate: add test cases for LIVEUPDATE_IOCTL_CREATE_SESSION calls with invalid length
  • c04873ea85d9 liveupdate: reject LIVEUPDATE_IOCTL_CREATE_SESSION with invalid name length
  • 0cff05bd2186 perf/aux: Fix page UAF in map_range()
  • 5fd2dbeded54 i2c: core: fix hang on adapter registration failure
  • a935b64548fc regulator: scmi: fix of_node refcount leak in scmi_regulator_probe()
  • 3e6e9f17f583 watchdog: apple: Add "apple,t8103-wdt" compatible
  • 7057fcf3a6d3 EDAC/i10nm: Don't fail probing if ADXL is missing
  • 03f6ecbc446c x86/mm: Fix freeing of PMD-sized vmemmap pages
  • 9d000bdd250d spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
  • 507c13781101 spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync()
  • 02d9dac2b843 arm64: fpsimd: Fix type mismatch in sme_{save,load}_state()
  • 4519290ed20d crypto: talitos/hash - fix SEC2 64k - 1 ahash request limitation
  • 1691f2c4a4f2 crypto: talitos/hash - remove useless wrapper
  • a4ffe8e7bdfe crypto: talitos/hash - rename first_desc/last_desc to first_request/last_request
  • ab3b0f3e4e72 crypto: talitos/hash - drop workqueue mechanism for SEC1
  • 96a8955d7020 crypto: talitos/hash - use descriptor chaining for SEC1 instead of workqueue
  • a0cf230cb4df crypto: talitos/hash - prepare SEC1 descriptor chaining, remove additional descriptor
  • 0f21d65f4381 crypto: talitos - move code in current_desc_hdr() into a standalone function
  • 873e34c46cb7 crypto: talitos - move dma mapping code in talitos_submit() into a standalone dma_map_request() function
  • ec6669f1c162 crypto: talitos - move dma unmapping code in flush_channel() into a standalone dma_unmap_request() function
  • b624dcd2fda9 crypto: talitos - add chaining of arbitrary number of descriptor for the SEC1
  • 9d4ea20a402d crypto: talitos - use dma_sync_single_for_cpu() before reading descriptor header
  • abf9a568013c crypto: qat - factor out AER reset helpers
  • ce42224487c5 crypto: qat - validate RSA CRT component lengths
  • 8e8391469a92 crypto: qat - skip restart for down devices
  • 0dbcecea740d crypto: qat - protect service table iterations with service_lock
  • 425f1260ecb9 crypto: qat - notify fatal error before AER reset preparation
  • 6f52fe576ac6 crypto: qat - keep VFs enabled during reset
  • 4515bf525c96 crypto: qat - handle sysfs-triggered reset callbacks
  • 59c0901db2b7 crypto: qat - fix restarting state leak on allocation failure
  • c98aed00e65a crypto: qat - centralize bus master enable
  • d5c0a6f8dc7e crypto: drbg - Fix the fips_enabled priority boost
  • 044aaaba99e1 crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels
  • 59a27cf2d01a crypto: drbg - Fix ineffective sanity check
  • d9f4acde5ae9 crypto: drbg - Fix misaligned writes in CTR_DRBG and HASH_DRBG
  • a9e886f73dd7 crypto: drbg - Fix returning success on failure in CTR_DRBG
  • 20f548cdac94 crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG)
  • 8836801847b9 crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD)
  • 67ed191b4c8b crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)
  • d51207735e7c crypto: ccp - Do not initialize SNP for SEV ioctls
  • 43de8b9f01b7 crypto: loongson - Remove broken and unused loongson-rng
  • 0927083d5e3e crypto: loongson - Select CRYPTO_RNG
  • 855240d4d243 crypto: tegra - fix refcount leak in tegra_se_host1x_submit()
  • 83fa1397d585 crypto: pcrypt - restore callback for non-parallel fallback
  • 98a771d340bd crypto: hisi-trng - Remove crypto_rng interface
  • ebaae7c4251c crypto: ecc - Fix carry overflow in vli multiplication
  • a856bc7d0fbb crypto: crypto4xx - Remove insecure and unused rng_alg
  • e74df53b36cd crypto: chacha20poly1305 - validate poly1305 template argument
  • 59057f5d4e9a crypto: caam - use print_hex_dump_devel to guard key hex dumps again
  • 8cf5fb050312 crypto: caam - use print_hex_dump_devel to guard key hex dumps
  • d9dbf9a484cb crypto: af_alg - Remove zero-copy support from skcipher and aead
  • 9830725078c8 isofs: bound Rock Ridge symlink components to the SL record
  • b8df7f486a46 btrfs: fix incorrect buffered IO fallback for append direct writes
  • 44f37ee92fdc partitions: aix: bound the pp_count scan to the ppe array
  • b4af31b898a9 btrfs: do not trim a device which is not writeable
  • 5d444a2a06d0 btrfs: check and set EXTENT_DELALLOC_NEW before clearing EXTENT_DELALLOC
  • caa71b3a43ea nvmet-auth: validate reply message payload bounds against transfer length
  • 05645271751e btrfs: fix false IO failure after falling back to buffered write
  • a29b316b9bbf nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
  • 16898de2ca35 nvme-multipath: set BIO_REMAPPED on bios remapped to per-path namespace disks
  • f815869f926c dm-ioctl: report an error if a device has no table
  • 0d3d19f78595 block: partitions: fix of_node refcount leak in of_partition()
  • 5828517d17ed nvme: target: rdma: fix ndev refcount leak on queue connect
  • 1c0462532916 crypto: atmel-sha204a - fail on hwrng registration error in probe path
  • 5c925be839d8 crypto: atmel-sha204a - drop hwrng quality reduction for ATSHA204A
  • 68896ba8ccb8 hwrng: jh7110 - fix refcount leak in starfive_trng_read()
  • 7f7774b9da0e udf: validate sparing table length as an entry count, not a byte count
  • 74580fdf0229 udf: validate VAT header length against the VAT inode size
  • be87de7789a8 udf: validate free block extents against the partition length
  • 77e7b127472a wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon
  • aa4c4a931576 block: skip sync_blockdev() on surprise removal in bdev_mark_dead()
  • dfecbb9ee08d usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile
  • f99f32ea9aa9 usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks
  • 0cae3d610942 usb: gadget: f_fs: Fix DMA fence leak
  • ba1867999dbc usb: gadget: f_fs: initialize reset_work at allocation time
  • 3aeed2451603 usb: typec: ucsi: cancel pending work on system suspend
  • dbb500bad021 usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove
  • f1736bb63f74 usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode
  • 42ac1cc7de06 usb: typec: ucsi: Invert DisplayPort role assignment
  • 313ca06e7e22 usb: typec: tcpm: Validate SVID index in svdm_consume_modes()
  • 20f38be1d262 usb: typec: tcpm: Fix VDM type for Enter Mode commands
  • 9a95bf88c6e4 usb: typec: ps883x: Fix DP+USB3 configuration
  • 14457cb92258 usb: typec: class: drop PD lookup reference
  • 575cb72b5ed0 usb: typec: anx7411: use devm_pm_runtime_enable()
  • 0443e4416aa1 usbip: vudc: fix NULL deref in vep_dequeue()
  • ddc4619707af usbip: tools: support SuperSpeedPlus devices
  • e9b316d99a5c USB: usb-storage: ene_ub6250: restore media-ready check
  • e5493c9a98ff USB: ulpi: fix memory leak on registration failure
  • a3a13fdc5310 USB: serial: digi_acceleport: fix write buffer corruption
  • 79bc131df0e5 USB: serial: digi_acceleport: fix hard lockup on disconnect
  • 92fa3e1a4984 USB: serial: digi_acceleport: fix broken rx after throttle
  • 6c8ccd8db36e USB: serial: option: add Telit Cinterion FE990D50 compositions
  • d4b12b6b395e USB: serial: keyspan_pda: fix information leak
  • 835b0596d4c9 usb: mtu3: unmap request DMA on queue failure
  • 48dd0b2ec9f2 USB: misc: uss720: unregister parport on probe failure
  • fc1b546973c1 usb: misc: usbio: bound bulk IN response length to the received transfer
  • 88bf7b68ac90 USB: storage: include US_FL_NO_SAME in quirks mask
  • e4271a74bf99 usb: sl811-hcd: disable controller wakeup on remove
  • 9ba62966461a USB: legousbtower: fix use-after-free on disconnect race
  • 452c5d97ba38 USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD
  • 71590982700f USB: iowarrior: fix use-after-free on disconnect race
  • e4596816984e USB: iowarrior: fix use-after-free on disconnect
  • a3e794136ab5 USB: ldusb: fix use-after-free on disconnect race
  • e88cff5fbaa6 USB: idmouse: fix use-after-free on disconnect race
  • 7f1f24c36793 usb: gadget: f_printer: take kref only for successful open
  • 54fa390aae39 usb: gadget: udc: Fix use-after-free in gadget_match_driver
  • fcb21bf74764 usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler
  • 4bb88aee6b86 usb: free iso schedules on failed submit
  • f4f5219c06d4 usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume()
  • 4349e487a114 usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()
  • effc5f7942b4 USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub
  • 963075c4da0c usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()
  • 35179684907c usb: cdc_acm: Add quirk for Uniden BC125AT scanner
  • 0aa71f258810 Revert "usb: typec: mux: avoid duplicated mux switches"
  • 51e65f1d7845 net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()
  • bd6ad9a6b304 bpf: Allow LPM map access from sleepable BPF programs
  • d57db0d97505 bpf: Keep dynamic inner array lookups nullable
  • ff77d013b737 bpf: Validate BTF repeated field counts before expansion
  • ee7099359f96 bpf: Restore sysctl new-value from 1 to 0
  • 51d07c12ca41 bpf: Reject fragmented frames in devmap
  • 06a2e6dbaa26 xfs: fix memory leak in xfs_dqinode_metadir_create()
  • 4707344b0d36 xfs: fix exchmaps reservation limit check
  • 60db12509ec0 xfs: fix pointer arithmetic error on 32-bit systems
  • cbcb09dacb71 xfs: fix unreachable BIGTIME check in dquot flush validation
  • ed16544d0d8b xfs: initialize iomap->flags earlier in xfs_bmbt_to_iomap
  • ce03e51a24c1 xfs: only log freed extents for the current RTG in zoned growfs
  • 4693131bee05 xfs: pass back updated nb from xfs_growfs_compute_deltas
  • d108043cc04e xfs: release dquot buffer after dqflush failure
  • 33c2c9d717f6 xfs: use null daddr for unset first bad log block
  • 9690e8a34263 serial: 8250_mid: Disable DMA for selected platforms
  • 4c4b4af4a9f2 media: mtk-jpeg: cancel workqueue on release for supported platforms only
  • d26aef771b4f nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers
  • d5b45bad75cd hfs/hfsplus: zero-initialize buffer in hfs_bnode_read
  • c25d3c931a63 hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length
  • d36e69c8c0c8 HID: sensor-hub: Add sensor_hub_input_attr_read_values() for multi-byte reads
  • 8131f4226688 HID: lg-g15: cancel pending work on remove to fix a use-after-free
  • 6b0838e86da8 HID: appleir: fix UAF on pending key_up_timer in remove()
  • 6493ebf9489e HID: multitouch: fix out-of-bounds bit access on mt_io_flags
  • df3d8aa1a939 HID: letsketch: fix UAF on inrange_timer at driver unbind
  • 27c4dad1b791 HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush()
  • 57bdd10ad50d HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert
  • 3e7761f7bf9f HID: hid-lenovo-go: cancel cfg_setup work in hid_go_cfg_remove()
  • 48218df04220 HID: pidff: Use correct effect type in effect update
  • e2cc711a9df3 HID: wacom: stop hardware after post-start probe failures
  • cfc0d283d931 HID: uhid: convert to hid_safe_input_report()
  • 835fcc865556 HID: hid-goodix-spi: validate report size to prevent stack buffer overflow
  • 493f261c0772 tools/mm/slabinfo: fix total_objects attribute name
  • 27c83f667575 tools/mm/slabinfo: Fix trace disable logic inversion
  • 0d18ccef142f mm/slab: do not limit zeroing to orig_size when only red zoning is enabled
  • d33dc0d5824c X.509: Fix validation of ASN.1 certificate header
  • 942dfe844229 perf/arm-cmn: Fix DVM node events
  • c94806905e02 s390: Revert support for DCACHE_WORD_ACCESS
  • c67b06370ade clocksource/drivers/timer-tegra186: Fix support for multiple watchdog instances
  • 75b478096c6b time/jiffies: Register jiffies clocksource before usage
  • 8f06363446c5 posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path
  • c1cfd63326f5 proc: protect ptrace_may_access() with exec_update_lock (part 1)
  • 0e3c739a2f6f cpufreq: pcc: fix use-after-free and double free in _OSC evaluation
  • a0106b41f9a7 cpufreq: Fix hotplug-suspend race during reboot
  • a18f80bf5359 sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT
  • e0d0adc3d204 cpufreq: intel_pstate: Sync policy->cur during CPU offline
  • a5f5f5053f98 perf/x86/intel/uncore: Defer ADL global PMON enable to enable_box()
  • dfd1894cb64c proc: protect ptrace_may_access() with exec_update_lock (FD links)
  • 8e931557b317 libfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo()
  • 15432f19562f firmware_loader: fix device reference leak in firmware_upload_register()
  • 9de568ef6cdf cpufreq: qcom-cpufreq-hw: Fix possible double free
  • 625b014f922c OPP: of: Fix potential memory leak in opp_parse_supplies()
  • 53eeaf4d6306 writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs()
  • eedf142d994e smb/server: do not require delete access for non-replacing links
  • f80add1bfb34 smb: client: mask server-provided mode to 07777 in modefromsid
  • fc25bbc893f6 smb: client: fix atime clamp check in read completion
  • 46a84715a015 smb: client: harden POSIX SID length parsing
  • 52f9c9dafefc smb: client: use unaligned reads in parse_posix_ctxt()
  • 927d4805aea0 smb: client: Fix next buffer leak in receive_encrypted_standard()
  • b18ed621dbfc smb: client: fix double-free in SMB2_close() replay
  • ff2d30927bc3 smb: client: fix double-free in SMB2_open() replay
  • 013a9a3da46c smb: client: fix double-free in SMB2_flush() replay
  • 901891513951 smb: client: fix change notify replay double-free
  • fc65ffb4ef1b smb: client: fix double-free in SMB2_ioctl() replay
  • 89234773e834 smb: client: fix query_info() replay double-free
  • 3317a5d015fc smb: client: fix query directory replay double-free
  • 550cfb8a8118 smb/client: fix chown/chgrp with SMB3 POSIX Extensions
  • 89ca7756d556 ksmbd: validate NTLMv2 response before updating session key
  • 5fecc15a30cb ksmbd: track the connection owning a byte-range lock
  • 52a56cf53ec8 ksmbd: use opener credentials for ADS I/O
  • 4b7059974549 ksmbd: use opener credentials for delete-on-close
  • 3bed9974fdf8 ksmbd: add per-handle permission check to FILE_LINK_INFORMATION
  • 5bc2aa358b57 ksmbd: enforce FILE_READ_ATTRIBUTES on SMB_FIND_FILE_POSIX_INFORMATION
  • 8cc9ec711f52 ksmbd: run set info with opener credentials
  • aae600cdaffc ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY
  • a10942af2783 ksmbd: require source read access for duplicate extents
  • 5c75275c0fc9 ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation
  • fd22b039a5a0 ksmbd: serialize QUERY_DIRECTORY requests per file
  • deffa929086d ksmbd: add a permission check for FSCTL_SET_ZERO_DATA
  • c917e4522d25 ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE
  • 8c9a4f1327eb ksmbd: prevent path traversal bypass by restricting caseless retry
  • a1cc432cb0b0 smb/client: Fix error code in smb2_aead_req_alloc()
  • 0700f946659d smb: client: resolve SWN tcon from live registrations
  • daf6246ab988 coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()
  • 6b47bdaacfd0 Bluetooth: L2CAP: validate option length before reading conf opt value
  • e96fbac8d3a7 Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
  • 01afd198c2c2 Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync()
  • 714d861d35d9 Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled
  • b42cb640a049 Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()
  • 50c662bdcd51 Bluetooth: fix UAF in bt_accept_dequeue()
  • 49bcb39e3a04 Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3()
  • 563a85730471 Bluetooth: bnep: pin L2CAP connection during netdev registration
  • 0f0a83e26a9c Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()
  • 9efe838c1313 netfilter: flowtable: IPIP tunnel hardware offload is not yet support
  • 419835f1bd5f netfilter: flowtable: fix offloaded ct timeout never being extended
  • b6183b1b88a7 netfilter: ebtables: terminate table name before find_table_lock()
  • 7b217960e88b netfilter: ebtables: module names must be null-terminated
  • 5ee856e4208a netfilter: ebtables: zero chainstack array
  • 57056be3ec12 netfilter: handle unreadable frags
  • 02f8a0a1da2e netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump
  • 2a55fdf9f746 mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup
  • 6a4196d19f47 mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host
  • b9beed2322f3 mm: shrinker: fix NULL pointer dereference in debugfs
  • 284c267f013e mm: shrinker: fix shrinker_info teardown race with expansion
  • 86237e56091e mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()
  • fc030c5b116f mfd: cros_ec: Delay dev_set_drvdata() until probe success
  • c12a5b226135 media: nxp: imx8-isi: Fix use-after-free on remove
  • a094ac95d3b6 net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes
  • f91883031e5a ipv4: igmp: remove multicast group from hash table on device destruction
  • 5ed09a108d93 netpoll: fix a use-after-free on shutdown path
  • f254713ac539 io_uring/rw: preserve partial result for iopoll
  • ab85765cbe32 io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item
  • 7267717f3578 io_uring/nop: fix file reference leak with IOSQE_FIXED_FILE
  • 7a89ad762fad HID: logitech-dj: Fix maxfield check in DJ short report validation
  • 41cad91a09d6 gpio: sch: use raw_spinlock_t in the irq startup path
  • 5c3c9ec1172a gpio: eic-sprd: use raw_spinlock_t in the irq startup path
  • 6350df503897 NTB: epf: Avoid calling pci_irq_vector() from hardirq context
  • e2018628301a ntfs: avoid calling post_write_mst_fixup() for invalid index_block
  • f433acc85b86 fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns
  • 1f4f02b336c3 debugobjects: Plug race against a concurrent OOM disable
  • 2edd162cbd4a coresight: etb10: restore atomic_t for shared reading state
  • 9531014c60c8 Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete
  • 50c38d9f42a5 Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
  • c5186201fa70 audit: Fix data races of skb_queue_len() readers on audit_queue
  • cea34abc94b0 net: af_key: initialize alg_key_len for IPComp states
  • 12c36c99655f ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL
  • 6e92b28cd74f crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()
  • 2b7bd6dccff1 crypto: krb5 - filter out async aead implementations at alloc
  • 6dda8406d8a3 crypto: amlogic - avoid double cleanup in meson_crypto_probe()
  • 225b6d3fc7e9 staging: rtl8723bs: fix OOB write in HT_caps_handler()
  • 729c4e72563b staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()
  • 4380b3860d88 staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop
  • 402f13ec9594 staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()
  • b5cc2f999927 staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop
  • 7e7741c8315e staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop
  • d90b9f39f375 staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()
  • 138cd190efd5 staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()
  • 35f4dbec7380 staging: rtl8723bs: don't drop short TX frames in _rtw_pktfile_read()
  • 837c1f965542 staging: media: ipu7: fix double-free and use-after-free in error paths
  • 7c973c5113e3 staging: media: atomisp: reduce load_primary_binaries() stack usage
  • 753e684fa55f media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe
  • c6cda17e9854 staging: vme_user: fix location monitor leak in tsi148 bridge
  • 157bcfc7955c staging: vme_user: fix location monitor leak in fake bridge
  • 6e9d10f62773 smb: client: restrict implied bcc[0] exemption to responses without data area
  • 1b495fa0d492 staging: vme_user: bound slave read/write to the kern_buf size
  • f333b6851bdf tipc: fix out-of-bounds read in broadcast Gap ACK blocks
  • 69f17ac132a3 tracing: Fix NULL pointer dereference in func_set_flag()
  • b713aa0cc344 6lowpan: fix NHC entry use-after-free on error path
  • 1947b6411460 usb: misc: usbio: fix disconnect UAF in client teardown
  • 642e04f5c292 usb: dwc3: run gadget disconnect from sleepable suspend context
  • 8f50613bff22 USB: chaoskey: Fix slab-use-after-free in chaoskey_release()
  • 92d5736a6204 hwrng: virtio: clamp device-reported used.len at copy_data()
  • 378493da2980 virtio-mmio: fix device release warning on module unload
  • 64a4c0befa77 virtio_pci: fix vq info pointer lookup via wrong index
  • e8ee198bbc04 netfilter: ipset: fix race between dump and ip_set_list resize
  • 76e415ea88d2 mm/damon/ops-common: handle extreme intervals in damon_hot_score()
  • 4caf12c778fe tcp: restore RCU grace period in tcp_ao_destroy_sock
  • 55fd485e66d0 PCI/IOV: Skip VF Resizable BAR restore on read error
  • 7908ddb6f8b3 PCI: Skip Resizable BAR restore on read error
  • 67a8b1d876d5 PCI: qcom: Initialize DWC MSI lock for firmware-managed ECAM hosts
  • df77314b3bed PCI: mediatek: Fix IRQ domain leak when port fails to enable
  • 6a2363bf9eae PCI: imx6: Assert ref_clk_en after reference clock stabilizes on i.MX95
  • edefa5f4b701 PCI: imx6: Fix IMX6SX_GPR12_PCIE_TEST_POWERDOWN handling
  • 76143cbb18dc PCI: imx6: Configure REF_USE_PAD before PHY reset for i.MX95
  • 7707ac040967 PCI: host-common: Request bus reassignment when not probe-only
  • 669c4f387600 PCI: Always lift 2.5GT/s restriction in PCIe failed link retraining
  • 6864c789b570 PCI: altera: Fix resource leaks on probe failure
  • ff396bab155f PCI: altera: Do not dispose parent IRQ mapping
  • bc29e49364ea PCI: loongson: Override PCIe bridge supported speeds for Loongson-3C6000 series
  • 1d3f464bb158 riscv: dts: sophgo: Add dma-coherent to SG2042 PCIe controllers
  • 569f18a83eed usb: typec: tcpci_rt1711h: unregister TCPCI port with devres
  • a3eaf82ff842 xhci: sideband: fix ring sg table pages leak
  • 93cd037da94f usb: xhci: Fix sleep in atomic context in xhci_free_streams()
  • 0644da3621dd rust_binder: clear freeze listener on node removal
  • 59fbe6b20456 rust_binder: synchronize Rust Binder stats with freeze commands
  • ad6af5c32dac rust_binder: reject context manager self-transaction
  • 3ffc336432da rust_binder: fix BINDER_GET_EXTENDED_ERROR
  • 74920b1b4e47 rust_binder: use a u64 stride when cleaning up the offsets array
  • 0f15f0f6ca5d binder: fix UAF in binder_free_transaction()
  • ef5439ba5b9a binder: fix UAF in binder_thread_release()
  • 087a305e025c Bluetooth: btusb: fix wakeup source leak on probe failure
  • 838c917a2f16 Bluetooth: btusb: fix use-after-free on marvell probe failure
  • da7d7758fe88 Bluetooth: btusb: fix use-after-free on registration failure
  • c028dfa0a3c7 Bluetooth: btusb: Add USB ID 2c4e:0128 for Mercusys MA60XNB
  • 39d163627b51 vfio/mlx5: Fix racy bitfields and tighten struct layout
  • a5df401dc84f vfio: Remove device debugfs before releasing devres
  • a3a8afa2f6e7 vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc
  • ad0f12d2dfc2 vfio/pci: Fix racy bitfields and tighten struct layout
  • 278a5659c391 vfio/pci: Release the VGA arbiter client on register_device() failure
  • 062b820290bc vfio/pci: Latch disable_idle_d3 per device
  • 2bdb4c96287d vfio/pci: Use a private flag to prevent power state change with VFs
  • 58c5ec23b1a2 x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled
  • c4fe3d9551ea ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes
  • 3314c5af8a13 ALSA: usb-audio: Update Babyface Pro control caches only after successful writes
  • 4e01d542e910 ALSA: usb-audio: Roll back quirk control caches on write errors
  • 14dfb2abae01 ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks
  • edf3ce5a72ca ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put()
  • 4246dd043b7a ALSA: usb-audio: avoid kobject path lookup in DualSense match
  • 344b64d4d411 ALSA: usb-audio: add IFB_SILENCE_ON_EMPTY quirk for Behringer Flow 8
  • ab1db6491242 ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission
  • 6ded42615fa1 ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()
  • 38a7cc46370a ALSA: ice1712: check snd_ctl_new1() return value
  • 17f31b904e8c ALSA: hda/realtek: Fix noisy mic for Clevo V6xxAW
  • 8bbba4ab5e6d ALSA: hda/hdmi: Use 'AC_PINSENSE_ELDV' to detect pinsense for Loongson
  • 0056958bf308 ALSA: hda/hdmi: Add force-connect quirk for HP EliteDesk 800 G5 Mini
  • d6a40a4d083e ALSA: hda/cs35l41: Fix firmware load work teardown
  • 465075c68351 ALSA: gus: check snd_ctl_new1() return value
  • 31a01b70bb90 ALSA: firewire: isight: bound the sample count to the packet payload
  • aeeeae9c1a51 ALSA: FCP: Add Focusrite ISA C8X support
  • 1949163dee39 ALSA: es1938: check snd_ctl_new1() return value
  • 426a9947a38d ALSA: compress: Fix task creation error unwind
  • 67e9ea92cd59 ALSA: cmipci: check snd_ctl_new1() return value
  • 0680413f2f10 ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser
  • e47f2a341adb ALSA: aoa: check snd_ctl_new1() return value
  • 18ec7d7785be ALSA: ymfpci: check snd_ctl_new1() return value
  • 21584672fd69 ALSA: virtio: Validate control metadata from the device
  • 6f3c7e552fd8 ALSA: virtio: Add missing 384 kHz PCM rate mapping
  • 27161c68d5e7 ALSA: usx2y: us144mkii: fix work UAF on disconnect
  • d90f868f56a1 iio: temperature: tmp006: use devm_iio_trigger_register
  • d8274d1a79af iio: temperature: ltc2983: Fix reinit_completion() called after conversion start
  • e52f7939a41c iio: temperature: ltc2983: Fix n_wires default bypassing rotation check
  • f87b86a7fd9e iio: temperature: Build mlx90635 with CONFIG_MLX90635
  • 1c8150ee8f2f iio: resolver: ad2s1210: notify trigger and clear state on fault read error
  • 769e819e6925 iio: proximity: vl53l0x: notify trigger and clear IRQ on error paths
  • 46e69d3dd429 iio: pressure: mpl115: fix runtime PM leak on read error
  • 9990e06016af iio: pressure: bmp280: zero-init bmp580 trigger handler buffer
  • 0adca7d78b7b iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call
  • 8a383705c455 iio: light: veml6030: fix channel type when pushing events
  • 9f45d437ce24 iio: light: tsl2591: return actual error from probe IRQ failure
  • 56447eeab51e iio: light: opt3001: fix missing state reset on timeout
  • 2ebaea7f3089 iio: light: gp2ap002: fix runtime PM leak on read error
  • a82b89a35692 iio: light: al3320a: read both ALS ADC registers again
  • 2b42c313b941 iio: light: al3320a: add missing REGMAP_I2C to Kconfig
  • e297afa1845f iio: light: al3010: read both ALS ADC registers again
  • 78451f43e3f4 iio: light: al3010: fix incorrect scale for the highest gain range
  • acd4946b583a iio: light: al3010: add missing REGMAP_I2C to Kconfig
  • c2d8c2696b8c iio: light: al3000a: add missing REGMAP_I2C to Kconfig
  • 4f49fef6179d iio: imu: st_lsm6dsx: deselect shub page before reading whoami
  • 2e2595765dcb iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading
  • 9fdc477b652a iio: imu: inv_icm42600: fix timestamp clock period by using lower value
  • 65f1f81e7521 iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ
  • 9f5690f2dc54 iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ
  • a11bc637375e iio: gyro: bmg160: wait full startup time after mode change at probe
  • 6c8675468862 iio: gyro: bmg160: bail out when bandwidth/filter is not in table
  • f187dc5a4c48 iio: event: Fix event FIFO reset race
  • b03fb2f8c6fc iio: dac: ad3552r-hs: fix uninitialized data ni ad3552r_hs_write_data_source()
  • 89fbd3e32dff iio: core: fix uninitialized data in debugfs
  • 20a5fee40c3d iio: common: st_sensors: honour channel endianness in read_axis_data
  • d49ff54b2784 iio: chemical: scd30: Cleanup initializations and fix sign-extension bug
  • fb8e18f8ca72 iio: buffer: hw-consumer: free scan_mask on buffer release
  • 33b29764f6c4 iio: backend: fix uninitialized data in debugfs
  • 84552fdcef8f iio: adc: ti-ads124s08: Return reset GPIO lookup errors
  • 6537f0810018 iio: adc: ti-ads1119: fix PM reference leak in buffer preenable
  • eb5b07c9d0ec iio: adc: spear: Initialize completion before requesting IRQ
  • af885d419b4d iio: adc: nxp-sar-adc: Fix the delay calculation in nxp_sar_adc_wait_for()
  • 2f18c5551aa9 iio: adc: lpc32xx: Initialize completion before requesting IRQ
  • f1de829ee87a iio: adc: ad_sigma_delta: fix CS held asserted and state leaks
  • 3bceb26dfaf7 iio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices
  • 73a92d5e3d78 iio: adc: ad7779: add missing 'select IIO_TRIGGERED_BUFFER' to Kconfig
  • f75a12808cd3 iio: adc: ad7768-1: Select GPIOLIB
  • e3f3fcf011e7 iio: adc: ad7380: select REGMAP
  • 5d32dd6338c8 iio: adc: ad4062: add GPIOLIB dependency
  • 13a91e8631cf iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error
  • 35a3cd8fd65e iio: accel: bmc150: clamp the device-reported FIFO frame count
  • 9facd79028a7 usb: gadget: function: rndis: add length check for header
  • b09716040f3f usb: gadget: function: rndis: add length check to response query
  • 994994cfadaf wifi: rtw89: correct drop logic for malformed AMPDU frames
  • 29d3f527bc1a bpf: Prefer dirty packs for eBPF allocations
  • 3448efcb18ae bpf: Prefer packs that won't trigger an IBPB flush on allocation
  • 80a96785fe42 bpf: Skip redundant IBPB in pack allocator
  • 7ff3b159b8b7 bpf: Restrict JIT predictor flush to cBPF
  • 52440e15d962 x86/bugs: Enable IBPB flush on BPF JIT allocation
  • 7a6c171c6a1a bpf: Support for hardening against JIT spraying
  • 06ccef0434e9 perf/core: Detach event groups during remove_on_exec
  • 007f071b2c39 futex/requeue: Revert "Prevent NULL pointer dereference in remove_waiter() on self-deadlock""
  • 89592176b718 rust: Kbuild: set frame-pointer llvm module flag for CONFIG_FRAME_POINTER
  • c781009975c5 rust: doctest: fix incorrect pattern in replacement
  • 6822a2685b4d rust: block: fix GenDisk cleanup paths
  • afa40a464072 rust: pci: use 'static lifetime for PCI BAR resource names
  • 1b1cac9887ec rust: kasan: KASAN+RUST requires clang
  • 3f096fb8647b rust: cpufreq: clean new clippy::map_or_identity lint for Rust 1.98.0
  • fbe9f0ff0b5b LoongArch: Add PIO for early access before ACPI PCI root register
  • eace3b3e729d platform/x86: intel-hid: Protect ACPI notify handler against recursion
  • 7d69235bdc58 ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup
  • 873576e585da ACPI: NFIT: core: Fix possible NULL pointer dereference
  • dc066bd13c86 ACPI: CPPC: Suppress UBSAN warning caused by field misuse
  • 8c8e8ac22ee1 KVM: x86: Unconditionally recompute CR8 intercept on PPR update
  • db8407b9fd06 KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode
  • 3db1ef139956 KVM: x86: Move update_cr8_intercept() to lapic.c
  • 3b3ca5d3a28e perf trace beauty fcntl: Fix build with older kernel headers
  • 7d45ca69164e slab: recognize @GFP parameter as optional in kernel-doc
  • 2dfe9f5c91d0 mm/khugepaged: write all dirty file folios when collapsing
  • 806586e33891 net/sched: dualpi2: fix GSO backlog accounting
  • 710183888174 userfaultfd: gate must_wait writability check on pte_present()
  • 6537884e9cf2 rust: str: clean unused import for Rust >= 1.98
  • 77ddefb1aeda rust: str: use the "kernel vertical" imports style

View originalPermalink

7.1.3-xanmod1
  • ece066880fc5 Linux 7.1.3-xanmod1
  • 2ddd8fb98217 Merge tag 'v7.1.3' into 7.1
  • 199c9959d3a9 Linux 7.1.3
  • 5b872b77bd35 apparmor: advertise the tcp fast open fix is applied
  • 7ddc29a094d9 net/tcp-ao: fix use-after-free of key in del_async path
  • e36e35660adb ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
  • 65b1bb5d24e5 NFS: Prevent resource leak in nfs_alloc_server()
  • a2c8befd06a4 NFSv4: clear exception state on successful mkdir retry
  • 30aae62e50b4 NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
  • 2131ed64b767 NFSv4/flexfiles: reject zero filehandle version count
  • b027cca33c97 nfsd: reset write verifier on deferred writeback errors
  • a10bf67fe064 nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
  • 8371cc5c0a2c nfsd: fix dead ACL conflict guard in nfsd4_create
  • ff3ecd17db74 nfsd: check get_user() return when reading princhashlen
  • 18cf006a08ba nfsd: fix posix_acl leak and ignored error in nfsd4_create_file
  • 80866c84137e nfsd: fix inverted cp_ttl check in async copy reaper
  • a5b42c1e4ff2 nfsd: fix posix_acl leak on SETACL decode failure
  • 46eb17d45be6 NFSD: Fix SECINFO_NO_NAME decode error cleanup
  • 83c2b7797742 nfsd: release layout stid on setlease failure
  • a4c8094bbf4c i2c: core: fix adapter registration race
  • 7e58653d4352 fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
  • 13b6f0cdd5cd fbdev: modedb: fix a possible UAF in fb_find_mode()
  • 6eb6ebcc8590 fbdev: omap2: fix use-after-free in omapfb_mmap
  • 39815715cbcf fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
  • 88913059c77e fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
  • acd744019460 ntfs: serialize volume label accesses
  • 7f7a9d6cb0ed riscv: kfence: Call mark_new_valid_map() for kfence_unprotect()
  • d6d6051fd15a riscv: mm: Extract helper mark_new_valid_map()
  • d109e72f3fbc power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()
  • 2753a097d1fe KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
  • f636cf6a1e7b KVM: x86: hyper-v: Bound the bank index when querying sparse banks
  • 9fef09df42df MIPS: smp: report dying CPU to RCU in stop_this_cpu()
  • a7656d368265 9p: avoid putting oldfid in p9_client_walk() error path
  • 99c21e726324 ocfs2: reject oversized group bitmap descriptors
  • ff268cd9ccbc rpmsg: char: Fix use-after-free on probe error path
  • 5e098e40e8ba fpga: region: fix use-after-free in child_regions_with_firmware()
  • 0405a65e4ebd irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove
  • 8d32856fb72b sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path
  • 9645aaf689af pNFS: Fix use-after-free in pnfs_update_layout()
  • 0833b2b84c2f LoongArch: Report dying CPU to RCU in stop_this_cpu()
  • 1eea5e1820a2 tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
  • afebe44facc4 blk-cgroup: fix UAF in __blkcg_rstat_flush()
  • a594debfd4e7 hdlc_ppp: sync per-proto timers before freeing hdlc state
  • 73569a44fca2 pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()
  • 9d0d5ba20cad gfs2: fix use-after-free in gfs2_qd_dealloc
  • 833033e6e55a crypto: nx - fix nx_crypto_ctx_exit argument
  • 5c87b4737468 KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()
  • b2ae3245ea44 KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
  • 708b97e79294 exfat: fix potential use-after-free in exfat_find_dir_entry()
  • 07c245bc39f9 MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
  • 70df4de46577 bpf: use kvfree() for replaced sysctl write buffer
  • 717f721eb67d block: Avoid mounting the bdev pseudo-filesystem in userspace
  • a92332f32a8d f2fs: read COW data with the original inode during atomic write
  • d52dbbcad61d f2fs: keep atomic write retry from zeroing original data
  • edf12cbeeeab f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
  • 6e035dae4415 Revert "f2fs: remove non-uptodate folio from the page cache in move_data_block"
  • 5d8a39649947 f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
  • 16bc237ce3c4 f2fs: bound i_inline_xattr_size for non-inline-xattr inodes
  • 536c7e7482e0 f2fs: fix to round down start offset of fallocate for pin file
  • a805fec35c20 f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
  • 0969926d987b f2fs: validate compress cache inode only when enabled
  • 2e12381d4495 f2fs: validate orphan inode entry count
  • 0cc21c1ffe15 f2fs: fix to do sanity check on f2fs_get_node_folio_ra()
  • f5b8b3dd6e85 f2fs: reject setattr size changes on large folio files
  • 8a2d8a34ef0b f2fs: pass correct iostat type for single node writes
  • 48c92559e7b6 f2fs: fix missing read bio submission on large folio error
  • fe7f339f63c9 wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
  • 9579781cd16d wifi: iwlwifi: mld: fix race condition in PTP removal
  • 032e49805099 wifi: iwlwifi: mvm: fix race condition in PTP removal
  • 8206d173d18e wifi: rtw88: usb: fix memory leaks on USB write failures
  • a68c04f4ee6a wifi: rtw88: increase TX report timeout to fix race condition
  • 2a42951e935f wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor
  • 4b75e6180f46 wifi: rtl8xxxu: Detect the maximum supported channel width
  • 051f954b9447 wifi: ath11k: fix warning when unbinding
  • 84139c1ab368 wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer
  • f10e6d5a35c4 wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S
  • 5db89515fc28 userfaultfd: build __VMA_UFFD_FLAGS from config-gated masks
  • 19ad7bfbd7f8 userfaultfd: ensure mremap_userfaultfd_fail() releases mmap_changing
  • 83c0a1cb296d keys: Pin request_key_auth payload in instantiate paths
  • 670fc6a311ed KEYS: fix overflow in keyctl_pkey_params_get_2()
  • 5b959c1dbb45 gcov: use atomic counter updates to fix concurrent access crashes
  • 450ee7ff510a err.h: use __always_inline on all error pointer helpers
  • 8ead17358119 KVM: arm64: Omit tag sync on stage-2 mappings of the zero page
  • dcb7416212e6 block: invalidate cached plug timestamp after task switch
  • 77bba61a20f1 kernel/fork: clear PF_BLOCK_TS in copy_process()
  • 43e40c7a7b26 fscrypt: Fix key setup in edge case with multiple data unit sizes
  • 70f1e000b88c fbdev: fix use-after-free in store_modes()
  • 9764a786ba98 NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR
  • 5e34fa9f6f7c apparmor: fix use-after-free in rawdata dedup loop
  • 45ebb934ea50 apparmor: mediate the implicit connect of TCP fast open sendmsg
  • cbad530277b5 PCI/P2PDMA: Add Intel QAT, DSA, IAA devices to whitelist
  • 47b5d3d50660 net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
  • 21ed9540a8e1 net: skmsg: preserve sg.copy across SG transforms
  • 86d531337ea1 mac802154: llsec: add skb_cow_data() before in-place crypto
  • 55e014aaec65 wifi: mt76: add wcid publish check in mt76_sta_add
  • 293a84fa40b3 ntfs3: reject direct userspace writes to reserved $LX* xattrs
  • c04d9ece23de ipv4: account for fraggap on the paged allocation path
  • e9eacf19281e ipv6: account for fraggap on the paged allocation path
  • d25df4f62eea batman-adv: tvlv: avoid race of cifsnotfound handler state
  • 56910cfd3116 batman-adv: tvlv: enforce 2-byte alignment
  • 3e4555177235 batman-adv: dat: prevent false sharing between VLANs
  • f91d579a085b batman-adv: tt: track roam count per VID
  • 6ae315914113 batman-adv: tt: don't merge change entries with different VIDs
  • 39aadfa35160 batman-adv: tp_meter: handle overlapping packets
  • aa9fe4cb1acb batman-adv: tp_meter: prevent parallel modifications of last_recv
  • 7c5f5f680dfc batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE
  • 1fb8762600a3 batman-adv: tp_meter: restrict number of unacked list entries
  • 86ab6b6fb5b8 batman-adv: v: prevent OGM aggregation on disabled hardif
  • 5d8e32165427 batman-adv: frag: avoid underflow of TTL
  • cc97b6311190 batman-adv: frag: ensure fragment is writable before modifying TTL
  • 09927ad14a5d batman-adv: fix (m|b)cast csum after decrementing TTL
  • 4f121f393811 batman-adv: ensure bcast is writable before modifying TTL
  • c14d3619a1f7 batman-adv: gw: don't deselect gateway with active hardif
  • 26ac02e6ae5d batman-adv: tp_meter: initialize last_recv_time during init
  • b4284cac3095 batman-adv: prevent ELP transmission interval underflow
  • 7f58e114c1f3 batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE
  • bafe4928d321 batman-adv: tp_meter: add only finished tp_vars to lists
  • 1d8b344e8dfc batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection
  • 47ca1ecb85b9 batman-adv: tp_meter: fix fast recovery precondition
  • 585616dab0aa batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
  • f1be6ca7c183 batman-adv: tp_meter: avoid window underflow
  • fa54b5d133cd batman-adv: tp_meter: initialize dec_cwnd explicitly
  • fd46e54c0601 batman-adv: tp_meter: initialize dup_acks explicitly
  • d7f6ffe69078 batman-adv: tp_meter: keep unacked list in ascending ordered
  • 1ae7d5a6db6c KVM: x86: Fix shadow paging use-after-free due to unexpected role

View originalPermalink

7.1.2-xanmod1
  • 74edfbf88678 Linux 7.1.2-xanmod1
  • 963a4a40216b Merge tag 'v7.1.2' into 7.1
  • 03e2778d1f11 Linux 7.1.2
  • e09412a714bc virtiofs: fix UAF on submount umount
  • 232e4b313ea3 media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
  • 5f983b864d3d ksmbd: reject non-VALID session in compound request branch
  • 059ac6252a63 drivers/base/memory: set mem->altmap after successful device registration
  • 778b9dda4b24 serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
  • ee6754f583a9 serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero
  • 09a43e81279b vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write
  • 3ae49dd04dbb crypto: qat - remove unused character device and IOCTLs
  • abd776ded3e2 iio: adc: ti-ads1298: add bounds check to pga_settings index
  • e545936e06f1 iio: light: veml6075: add bounds check to veml6075_it_ms index
  • cefe535a60a2 agp/amd64: Fix broken error propagation in agp_amd64_probe()
  • 613257f91906 Revert "NFSD: Defer sub-object cleanup in export put callbacks"
  • e28db6ac4792 fuse: re-lock request before replacing page cache folio
  • 7e00cafa33b5 io_uring/net: Avoid msghdr on op_connect/op_bind async data

View originalPermalink