6.18.38-rt-xanmod1
Fixed 20
- Advertise the tcp fast open fix is applied in apparmor
- Fix use-after-free of key in del_async path in net/tcp-ao
- Unregister 8250 port if clk_notifier_register() fails in serial 8250_dw
- Fix out-of-bounds read in smb_check_perm_dacl() in ksmbd
- Prevent resource leak in nfs_alloc_server() in NFS
- Clear exception state on successful mkdir retry in NFSv4
- Reject zero-length r_addr in nfs4_decode_mp_ds_addr in NFSv4/pNFS
- Reject zero filehandle version count in NFSv4/flexfiles
- Reset write verifier on deferred writeback errors in nfsd
- Avoid leaking pre-allocated openowner on unconfirmed retry race in nfsd
- Check get_user() return when reading princhashlen in nfsd
- Fix inverted cp_ttl check in async copy reaper in nfsd
- Fix posix_acl leak on SETACL decode failure in nfsd
- Fix SECINFO_NO_NAME decode error cleanup in NFSD
- Fix adapter registration race in i2c core
- Fix misaligned fields in the 1920x1080-60 mode in fbdev modedb
- Fix a possible UAF in fb_find_mode() in fbdev modedb
- Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var in fbdev
- Fix use-after-free in linkstation_poweroff_init() in power reset linkstation-poweroff
- Fix page overflow in sev_dbg_crypt() for ENCRYPT path in KVM SVM
- 4b8d52e3d233 Linux 6.18.38-rt-xanmod1
- 0b987ae8e20a Merge branch '6.18' into 6.18-rt
- e67923a55781 Linux 6.18.38-xanmod1
- 82e2790add06 Merge tag 'v6.18.38' into 6.18
- e46dc0adfe39 Linux 6.18.38
- 92c63a5ef3c7 apparmor: advertise the tcp fast open fix is applied
- e77fbefd1269 net/tcp-ao: fix use-after-free of key in del_async path
- 3d205fe80f21 serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
- 7627ff8c4f99 ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
- 62c26720121b NFS: Prevent resource leak in nfs_alloc_server()
- 6919eb549e8f NFSv4: clear exception state on successful mkdir retry
- 012d37a568bf NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
- d8c90c7cc061 NFSv4/flexfiles: reject zero filehandle version count
- 4367afc119c5 nfsd: reset write verifier on deferred writeback errors
- 017a6150106b nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
- 0f28337f54cf nfsd: check get_user() return when reading princhashlen
- dba7da4835de nfsd: fix inverted cp_ttl check in async copy reaper
- 136b416593f1 nfsd: fix posix_acl leak on SETACL decode failure
- c8a24effd96d NFSD: Fix SECINFO_NO_NAME decode error cleanup
- 6a946038f2a5 i2c: core: fix adapter registration race
- fc6aa9bdbae6 fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
- 4d418cf8daf5 fbdev: modedb: fix a possible UAF in fb_find_mode()
- eea16b6f805c fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
- 7643e5622994 riscv: kfence: Call mark_new_valid_map() for kfence_unprotect()
- 3b33dbb43e21 riscv: mm: Extract helper mark_new_valid_map()
- 2205275be9be power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()
- 720949ed666f KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
- e36095d8d922 KVM: x86: hyper-v: Bound the bank index when querying sparse banks
- f9b57a0015c2 MIPS: smp: report dying CPU to RCU in stop_this_cpu()
- 6dbe9443d9f5 9p: avoid putting oldfid in p9_client_walk() error path
- 4cd57ebee395 ocfs2: reject oversized group bitmap descriptors
- 104d10021239 rpmsg: char: Fix use-after-free on probe error path
- 369496d885b4 fpga: region: fix use-after-free in child_regions_with_firmware()
- b3a3831b2eb8 irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove
- 200e7637f4d6 pNFS: Fix use-after-free in pnfs_update_layout()
- 90e254f18b8c LoongArch: Report dying CPU to RCU in stop_this_cpu()
- e18769616fd5 tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
- 5e5b7f2ef854 blk-cgroup: fix UAF in __blkcg_rstat_flush()
- 5a84398101bf hdlc_ppp: sync per-proto timers before freeing hdlc state
- e91df6d27344 pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()
- b85ef03f726b gfs2: fix use-after-free in gfs2_qd_dealloc
- 8d8507a45766 crypto: nx - fix nx_crypto_ctx_exit argument
- 5da9b1a87ec7 KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()
- 18587f983161 KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
- adfacfbaeae2 exfat: fix potential use-after-free in exfat_find_dir_entry()
- 6e61fc2e06e4 MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
- 65bd0c0afb0e bpf: use kvfree() for replaced sysctl write buffer
- 3804e6de30ae block: Avoid mounting the bdev pseudo-filesystem in userspace
- db2c5b9fb908 f2fs: keep atomic write retry from zeroing original data
- 20190e498057 f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
- ff83de56882c f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
- 888d94cc9afb f2fs: fix to round down start offset of fallocate for pin file
- 77f216ff9ce5 f2fs: validate compress cache inode only when enabled
- 8aad54746c25 f2fs: validate orphan inode entry count
- 1e48fefac682 f2fs: pass correct iostat type for single node writes
- 1de92789ce31 wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
- b0b07e04f0c7 wifi: iwlwifi: mld: fix race condition in PTP removal
- df626f284cb9 wifi: iwlwifi: mvm: fix race condition in PTP removal
- 200d58c851b8 wifi: rtw88: usb: fix memory leaks on USB write failures
- 73d427d271f7 wifi: rtw88: increase TX report timeout to fix race condition
- 0aeb4d3ff6ce wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor
- 40aa3c2b0cb8 wifi: ath11k: fix warning when unbinding
- a7cdc384c9c5 wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer
- 7e25b5e22c1f wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S
- ec1c9e896255 userfaultfd: ensure mremap_userfaultfd_fail() releases mmap_changing
- 7216ce8cb12f keys: Pin request_key_auth payload in instantiate paths
- b11c1fa32667 KEYS: fix overflow in keyctl_pkey_params_get_2()
- 49d893b9cbcf gcov: use atomic counter updates to fix concurrent access crashes
- 2b7ec7278609 err.h: use __always_inline on all error pointer helpers
- 1fcca1260c6e KVM: arm64: Omit tag sync on stage-2 mappings of the zero page
- 97e1044e79c5 block: invalidate cached plug timestamp after task switch
- 99e6c712cc30 kernel/fork: clear PF_BLOCK_TS in copy_process()
- 0d35f9f194a8 fbdev: fix use-after-free in store_modes()
- 81371dbd2360 NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR
- c3ca2631073b apparmor: fix use-after-free in rawdata dedup loop
- 4a69b83045d3 apparmor: mediate the implicit connect of TCP fast open sendmsg
- 1697957eb097 net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
- 1acdd14c0990 net: skmsg: preserve sg.copy across SG transforms
- bd968bdd568b mac802154: llsec: add skb_cow_data() before in-place crypto
- 0cfa78c05066 af_unix: Set gc_in_progress to true in unix_gc().
- 3c499851753a wifi: mt76: add wcid publish check in mt76_sta_add
- 5e658b9245a5 ntfs3: reject direct userspace writes to reserved $LX* xattrs
- 77798d7be6ef ipv4: account for fraggap on the paged allocation path
- 6374fb9edf72 ipv6: account for fraggap on the paged allocation path
- 565ab66005b1 batman-adv: tvlv: avoid race of cifsnotfound handler state
- 4cc9f7711bb8 batman-adv: tvlv: enforce 2-byte alignment
- 04e1a6557fbf batman-adv: dat: prevent false sharing between VLANs
- 3f82fc92cf52 batman-adv: tt: track roam count per VID
- 3470d583fc65 batman-adv: tt: don't merge change entries with different VIDs
- af5a069805f6 batman-adv: tp_meter: handle overlapping packets
- d511c72a83dd batman-adv: tp_meter: prevent parallel modifications of last_recv
- 1dafdd0794be batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE
- 2233787658db batman-adv: tp_meter: restrict number of unacked list entries
- 3d4548c96d6f batman-adv: v: prevent OGM aggregation on disabled hardif
- 44ae137a2ace batman-adv: frag: avoid underflow of TTL
- 116e94025f0f batman-adv: frag: ensure fragment is writable before modifying TTL
- 0473ae882624 batman-adv: fix (m|b)cast csum after decrementing TTL
- 49bf27fcd7ee batman-adv: ensure bcast is writable before modifying TTL
- 646b68639c06 batman-adv: gw: don't deselect gateway with active hardif
- 95a061f587b7 batman-adv: tp_meter: initialize last_recv_time during init
- 75612c100a9e batman-adv: prevent ELP transmission interval underflow
- 43733e5b525f batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE
- 23d085bd6308 batman-adv: tp_meter: add only finished tp_vars to lists
- b8bf8400e50c batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection
- 1db02f3e315d batman-adv: tp_meter: fix fast recovery precondition
- 7d2a44bc6bbe batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
- 8e77fe0414f5 batman-adv: tp_meter: avoid window underflow
- 7cb88d91d5f9 batman-adv: tp_meter: initialize dec_cwnd explicitly
- 696c4cae872c batman-adv: tp_meter: initialize dup_acks explicitly
- 1c5a1268418e batman-adv: tp_meter: keep unacked list in ascending ordered
- e055e74b80eb lockd: fix TEST handling when not all permissions are available.
- 671ec2eabb87 Revert "PCI: qcom: Advertise Hotplug Slot Capability with no Command Completion support"
- d84470219839 selinux: fix overlayfs mmap() and mprotect() access checks
- 5dfcb15974e7 lsm: add backing_file LSM hooks
- 5e470998a23e KVM: x86: Fix shadow paging use-after-free due to unexpected role
- 6e2cd08aa3e8 Linux 6.18.37-xanmod1
- 0d25ba9b7110 Merge tag 'v6.18.37' into 6.18
- 0c503cf3dde2 Linux 6.18.37
- 71003a32bef5 mm: do not copy page tables unnecessarily for VM_UFFD_WP
- 2abfd3ffbd94 virtiofs: fix UAF on submount umount
- f965cf22dda7 media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
- 7cad3ceaf679 ksmbd: reject non-VALID session in compound request branch
- 6c25bf4e44a2 drivers/base/memory: set mem->altmap after successful device registration
- 50b72074c5e8 serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero
- 7cc3dd79777f vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write
- b8ebf008696d crypto: qat - remove unused character device and IOCTLs
- d08d82d83ed4 iio: adc: ti-ads1298: add bounds check to pga_settings index
- 0a89002737ee iio: light: veml6075: add bounds check to veml6075_it_ms index
- 76db05493184 net: net_failover: Fix the deadlock in slave register
- c5b3871b567c net: export netif_open for self_test usage
- cc1494fd6c65 testing/selftests/mm: add soft-dirty merge self-test
- f563ce913a83 mm: propagate VM_SOFTDIRTY on merge
- b836839c1fd9 mm: set the VM_MAYBE_GUARD flag on guard region install
- 3d6cb2ed06f7 mm: introduce copy-on-fork VMAs and make VM_MAYBE_GUARD one
- 05cdec24a858 mm: implement sticky VMA flags
- a093c80a1f13 mm: update vma_modify_flags() to handle residual flags, document
- bdeadba74337 mm: add atomic VMA flags and set VM_MAYBE_GUARD as such
- efce8a486bff mm: introduce VM_MAYBE_GUARD and make visible in /proc/$pid/smaps
- 0de7db2eb27e sctp: disable BH before calling udp_tunnel_xmit_skb()
- eee6be6ab637 firmware: samsung: acpm: Fix cross-thread RX length corruption
- 02ac3ba41628 Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs
- 072bbd2846d1 hv: utils: handle and propagate errors in kvp_register
- bde74af8d446 regulator: core: fix locking in regulator_resolve_supply() error path
- 9477cbc5107a rose: don't free fd-owned sockets when reaping in the heartbeat
- 395b6573b389 rose: clear neighbour pointer in rose_kill_by_device()
- 9e8fc2195f8b rose: cancel neighbour timers in rose_neigh_put() before freeing
- c31a0fa15a4b rose: drop CALL_REQUEST in loopback timer when device is not running
- 74cbe94c913a rose: release netdev ref and destroy orphaned incoming sockets
- c794d35f73a7 rose: fix netdev double-hold in rose_make_new()
- ce27bcdd857a rose: disconnect orphaned STATE_2 sockets when device is gone
- ab849a6972c9 rose: set SOCK_DESTROY in rose_kill_by_device() for prompt cleanup
- c98cc00c2d3b rose: fix notifier unregistered too early in rose_exit()
- 19139026dc1c rose: fix netdev double-hold in rose_rx_call_request()
- 1d94857c11d6 rose: guard rose_neigh_put() against NULL in timer expiry
- 270ef709257e rose: clear neighbour pointer after rose_neigh_put() in state machines
- 940f39e15332 rose: fix race between loopback timer and module removal
- fe8cbcc3e79d rose: hold loopback neighbour reference across timer callback
- 7dac298524b4 rose: fix dev_put() leak in rose_loopback_timer()
- 19b3691ec940 ACPI: scan: Use async schedule function in acpi_scan_clear_dep_fn()
- 53483a9f4ee9 agp/amd64: Fix broken error propagation in agp_amd64_probe()
- 8b17adf6d4fb net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
- 5f4d2bd028eb i2c: stub: Reject I2C block transfers with invalid length
- e2b143df2900 RDMA/bnxt_re: zero shared page before exposing to userspace
- 44b8b03a9fb5 debugobjects: Dont call fill_pool() in early boot hardirq context
- 3a408cae608d debugobjects: Do not fill_pool() if pi_blocked_on
- 9cd2087cd702 debugobjects: Use LD_WAIT_CONFIG instead of LD_WAIT_SLEEP
- a460935022f5 debugobjects: Allow to refill the pool before SYSTEM_SCHEDULING
- 95f9eb19d5e6 Revert "NFSD: Defer sub-object cleanup in export put callbacks"
- af2892249d98 fuse: re-lock request before replacing page cache folio
- 29706ac73f93 net: stmmac: fix stm32 (and potentially others) resume regression
- b6099150949f io_uring/net: Avoid msghdr on op_connect/op_bind async data
- e5609e8d8cac Linux 6.18.36-xanmod1
- a240262f0bf0 Merge tag 'v6.18.36' into 6.18
- 275d294b2b24 Linux 6.18.36
- 5d634afb8b83 netfilter: require Ethernet MAC header before using eth_hdr()
- bf7a9cacd95e cfi: Include uaccess.h for get_kernel_nofault()
- f455405e3207 vsock/virtio: fix skb overhead overflow on 32-bit builds
- 36a0faaa4e3d block: fix handling of dead zone write plugs
- 7b569b3a2f29 arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU
- 99abe00c605e arm64: errata: Mitigate TLBI errata on NVIDIA Olympus CPU
- d4fd42822040 arm64: errata: Mitigate TLBI errata on various Arm CPUs
- 8097f93f9b77 arm64: cputype: Add C1-Premium definitions
- e9ea7cb17677 arm64: cputype: Add C1-Ultra definitions
- eca6743b148a vsock/virtio: fix skb overhead accounting to preserve full buf_alloc
- 9bdc637fde66 vsock/virtio: fix potential unbounded skb queue
- cdce1e797add ipvs: skip ipv6 extension headers for csum checks
- afd35fec9297 RDMA/umem: Fix truncation for block sizes >= 4G
- cd26d54bfbc2 RDMA: Move DMA block iterator logic into dedicated files
- ebf22feff492 RDMA/umem: fix kernel-doc warnings
- 84d8f58cf28a netfilter: nft_fib: fix stale stack leak via the OIFNAME register
- 2904e985a291 RDMA: During rereg_mr ensure that REREG_ACCESS is compatible
- f58efaf9fcf7 RDMA/umem: Add helpers for umem dmabuf revoke lock
- 5f3286ca5fbb RDMA/umem: Move umem dmabuf revoke logic into helper function
- ceddd32231dd RDMA/umem: Add ib_umem_dmabuf_get_pinned_and_lock helper
- 0ffcad63b19a sched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task()
- 37c059d4d92f wifi: mac80211: tests: mark HT check strict
- 4dac39a4db14 wifi: mac80211: skip ieee80211_verify_sta_ht_mcs_support check in non-strict mode
- 17faa39ba980 driver core: reject devices with unregistered buses
- 20a93e397abe fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
- e09689286385 drm/amd/display: Use krealloc_array() in dal_vector_reserve()
- 454d3b3d499c drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()
- bb6f705b73b5 drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
- c000da79df78 drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs
- 3f32d52ec604 drm/amd/display: Clamp VBIOS HDMI retimer register count to array size
- 1906064d50d1 drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
- 0e56f460bddb drm/amd/display: Bound VBIOS record-chain walk loops
- 57607fe55e6d drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range
- 932642791cb1 drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2
- 8979ded4d899 drm/amd/pm: fix smu13 power limit default/cap calculation
- 39b5397bf8de drm/amdgpu: set noretry=1 as default for GFX 10.1.x (Navi10/12/14)
- fcd51a085e9a drm/amdgpu: restart the CS if some parts of the VM are still invalidated
- 68455b117258 drm/amdgpu: fix waiting for all submissions for userptrs
- 9655b56b6de9 drm/v3d: Skip CSD when it has zeroed workgroups
- 90b629269088 drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups
- 3e1947573140 drm/v3d: Fix global performance monitor reference counting
- 11e9bdf8824b drm/v3d: Wait for pending L2T flush before cleaning caches
- 4c10fd55187a drm/xe: Clear pending_disable before signaling suspend fence
- 0f68ddfaaebf drm/xe/display: fix oops in suspend/shutdown without display
- d3efcadfe3ee drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
- 72e259a32084 drm/amdkfd: fix NULL dereference in get_queue_ids()
- c0639ede2f24 drm/gem: Try to fix change_handle ioctl, attempt 4
- 9f0d45d509b4 slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock
- 8f4b371f4939 slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD
- 5204cd22c1c7 slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership
- dd8e1025a84e slimbus: qcom-ngd-ctrl: Initialize controller resources in controller
- 24ec89123fc9 slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd
- 3bb2ac834ed3 slimbus: qcom-ngd-ctrl: Fix probe error path ordering
- d6cb003e4661 slimbus: qcom-ngd-ctrl: Fix up platform_driver registration
- 6890bd2451a9 slimbus: qcom-ngd-ctrl: fix OF node refcount
- b5daa920f44c thunderbolt: Limit XDomain response copy to actual frame size
- 46da5c3ea011 thunderbolt: Validate XDomain request packet size before type cast
- fcbd0cdab928 thunderbolt: Clamp XDomain response data copy to allocation size
- 60ba62174607 thunderbolt: Bound root directory content to block size
- 2e0ddac549eb thunderbolt: Reject zero-length property entries in validator
- d5ea0b3e261f sctp: stream: fully roll back denied add-stream state
- 78c4f964b2f9 sctp: diag: reject stale associations in dump_one path
- 566c4c1244de rxrpc: Fix the ACK parser to extract the SACK table for parsing
- 1bf84f4013fa rtase: Reset TX subqueue when clearing TX ring
- 54f9cdcd7311 rtase: Avoid sleeping in get_stats64()
- ddcf84b25af0 pmdomain: ti_sci: add wakeup constraint to parent devices of wakeup source
- 0d11992d1898 pmdomain: imx: fix OF node refcount
- 0aecf3c7b8f8 mmc: sdhci: add signal voltage switch in sdhci_resume_host
- 535ff092b686 mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC
- 2f72d36f8acc mmc: litex_mmc: Set mandatory idle clocks before CMD0
- 7f8007be13e6 mmc: dw_mmc-rockchip: Add missing private data for very old controllers
- c677b13671dc mmc: core: Fix host controller programming for fixed driver type
- a8f91ddf67f6 mm/mincore: handle non-swap entries before !CONFIG_SWAP guard
- c19ff4351214 mm/list_lru: drain before clearing xarray entry on reparent
- c72469ac0f27 mm/hugetlb: restore reservation on error in hugetlb folio copy paths
- ecc24f0a8a30 mm/hugetlb: avoid false positive lockdep assertion
- 66bc00ea37fa mm/damon/reclaim: handle ctx allocation failure
- 6d48f1565939 mm/damon/lru_sort: handle ctx allocation failure
- d83390b21a02 mm/cma_debug: fix invalid accesses for inactive CMA areas
- 52078596dce1 mm/cma: fix reserved page leak on activation failure
- d5d37b7b72a9 io_uring/wait: fix min_timeout behavior
- c888d5198ffc io_uring/kbuf: don't truncate end buffer for bundles
- 3fdcca838f97 pinctrl: mcp23s08: Read spi-present-mask as u8 not u32
- e646b86b3b48 octeontx2-af: fix memory leak in rvu_setup_hw_resources()
- 4a4d21f531cc nvmem: layouts: onie-tlv: fix hang on unknown types
- cb85ef5a227b nvmem: core: fix use-after-free bugs in error paths
- bef389a210e7 net: sfp: initialize i2c_block_size at adapter configure time
- 1d4ec754ee38 net: rds: clear i_sends on setup unwind
- 52b8f5ef82c8 net: phonet: free phonet_device after RCU grace period
- 4a73cacb5586 net: mv643xx: fix OF node refcount
- bcb8fad90f27 net: bonding: fix NULL pointer dereference in bond_do_ioctl()
- 01f7d4b50458 net: airoha: Add NULL check for of_reserved_mem_lookup() in airoha_qdma_init_hfwd_queues()
- e0df4d9c0909 net/mlx5: Reorder completion before putting command entry in cmd_work_handler
- 0a46c7a5646d firmware: samsung: acpm: Fix mailbox channel leak on probe error
- d5de9cb5355d misc: fastrpc: Fix NULL pointer dereference in rpmsg callback
- 53e06f8a3c2b misc: fastrpc: fix DMA address corruption due to find_vma misuse
- 992f121796b7 misc: fastrpc: fix use-after-free race in fastrpc_map_create
- 5278ccd357e0 misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context
- 89bd8215e25a memcg: use round-robin victim selection in refill_stock
- a388e3dfaf95 locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
- db752ebfdaf2 ipc/shm: serialize orphan cleanup with shm_nattch updates
- ab61c990a87d iommu/dma: Do not try to iommu_map a 0 length region in swiotlb
- f35a368fee8a Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard
- a3dff1e1a554 Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK)
- 7f59e4f72a78 i2c: tegra: Fix NOIRQ suspend/resume
- 6018d73137cd i2c: stm32f7: fix timing computation ignoring i2c-analog-filter
- a162a260c8c4 i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()
- 9fa82cf393ba i2c: imx: fix clock and pinctrl state inconsistency in runtime PM
- b39f30c0a72f i2c: imx-lpi2c: fix resource leaks switching to devm_dma_request_chan()
- 16f8e17184b3 futex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock
- 56763afa0134 fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
- 12df4cfa738a fuse: reject fuse_notify() pagecache ops on directories
- 57a9c085be07 fs/qnx6: fix pointer arithmetic in directory iteration
- 2990f143ec86 pidfd: refuse access to tasks that have started exiting harder
- 89b909e97045 inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
- df422fd273c9 IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
- 32138633e51e fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh()
- 3884976f8744 bnxt_en: Fix NULL pointer dereference
- 6f72b902c34d ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write
- 735dabdf2156 staging: rtl8723bs: fix buffer over-read in rtw_update_protection
- 1d6c2062b77b timers/migration: Fix livelock in tmigr_handle_remote_up()
- ba9ad6015937 vsock/vmci: fix sk_ack_backlog leak on failed handshake
- 265c07c09c83 wifi: nl80211: reject oversized EMA RNR lists
- ac2000be0cbe wifi: iwlwifi: pcie: simplify the resume flow if fast resume is not used
- fcfdff42e841 xfs: fix rtgroup cleanup in CoW fork repair
- d84ed2f9718e xfs: fix error returns in CoW fork repair
- 9f21885c11ba mptcp: add-addr: always drop other suboptions
- 6ea1134f1b5f selftests: mptcp: add test for extra_subflows underflow on userspace PM
- 7bbc11437a20 mptcp: sockopt: set sockopt on all subflows
- f591cbc088c9 mptcp: sockopt: check timestamping ret value
- c0c152fc4ae6 mptcp: pm: fix extra_subflows underflow on userspace PM subflow creation
- 653245266913 mptcp: allow subflow rcv wnd to shrink
- 3b8cbba7c0ed mptcp: close TOCTOU race while computing rcv_wnd
- edaf0c955ace mptcp: fix retransmission loop when csum is enabled
- 95f27fcda681 arm64: mm: call pagetable dtor when freeing hot-removed page tables
- 517720913bd3 ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow
- da295adc9dab ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O
- 6243a363ec90 ARM: socfpga: Fix OF node refcount leak in SMP setup
- 6822eed69572 udp: clear skb->dev before running a sockmap verdict
- c96786d6ff1a zram: fix use-after-free in zram_bvec_write_partial()
- f92a285db7ff RDMA/srp: bound SRP_RSP sense copy by the received length
- bd5e818be796 RDMA/core: Validate cpu_id against nr_cpu_ids in DMAH alloc
- 96b6e98ff12d RDMA/core: Validate the passed in fops for ib_get_ucaps()
- e99807bdcd20 mm/huge_memory: update file PUD counter before folio_put()
- cb5230b6d8a0 mm/damon/ops-common: call folio_test_lru() after folio_get()
- 5f5b604e1e6b mm/huge_memory: update file PMD counter before folio_put()
- edabfe80e34e drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info()
- 8348567a6afb drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()
- 0bbc9481f970 io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries
- 3d39da65b5c4 ALSA: timer: Fix UAF at snd_timer_user_params()
- f46093dd2296 ALSA: timer: Forcibly close timer instances at closing
- 372f33ebed74 USB: serial: kl5kusb105: fix bulk-out buffer overflow
- 85bd2b3afa0a USB: serial: option: add usb-id for Dell Wireless DW5826e-m
- 294692d3296e USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
- f96cf7bf9fbf USB: serial: io_ti: fix heap overflow in get_manuf_info()
- a13ca53e47e5 xfrm: iptfs: fix ABBA deadlock in iptfs_destroy_state()
- dd66f7f6e360 xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()
- f9b38a8fbfa0 xfrm: espintcp: do not reuse an in-progress partial send
- 14d2eee0193a ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL
- 0b38870d81ab hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf
- 32d4c5d328a3 drm/i915/gem: Fix phys BO pread/pwrite with offset
- 0b79bcff7210 KVM: arm64: Restore POR_EL0 access to host EL0
- 196f1ee137eb KVM: SEV: Decouple the need to sync the GHCB SA from the need to free the SA
- 343e95c8ecc4 KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
- 0864bdde152e mshv: add a missing padding field
- 8bcbedce9bfa mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation
- a0a4600b396b rust: kasan/kbuild: fix rustc-option when cross-compiling
- d0f25a1755f2 rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES
- 5037b2ee1a17 ARM: Do not select HAVE_RUST when KASAN is enabled
- 00875811f372 rust: x86: support Rust >= 1.98.0 target spec
- 592be0dc491d tracing/probes: Point the error offset correctly for eprobe argument error
- 09df291fdf96 tracing: Fix CFI violation in probestub being called by tprobes
- 45cb105b8642 accel/ivpu: Fix signed integer truncation in IPC receive
- fa598556ecef accel/ivpu: Add buffer overflow check in MS get_info_ioctl
- 8ec70c0dbdf0 accel/ivpu: Add bounds checks for firmware log indices
- dd77a83915b0 mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison
- cc160ce08540 soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get()
- dedc92b96dc1 Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
- dafc9f57140e Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
- c10c9c48b290 tee: shm: fix shm leak in register_shm_helper()
- 07acb9798477 netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register
- 941d7394efda netfilter: nft_tunnel: fix use-after-free on object destroy
- e83fc4c28226 accel/amdxdna: Fix mm_struct reference leak in aie2_populate_range()
- 361e97d81331 drm/xe: fix refcount leak in xe_range_fence_insert()
- 02f5e4db57c0 drm/vc4: fix krealloc() memory leak
- 19a6a00ff50c drm/virtio: Fix driver removal with disabled KMS
- dda720b2928d drm/i915/edp: Check supported link rates DPCD read
- 489f6d759fa4 clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration time
- 3a4fc3617b7e clk: samsung: gs101: Fix missing USI7_USI DIV clock in peric0_clk_regs
- 656939c67595 clk: qcom: x1e80100-dispcc: Stop disp_cc_mdss_mdp_clk_src from getting parked
- f34689e7a0b3 KVM: VMX: Update SVI during runtime APICv activation
- 07d9a0870a17 ipv6: Fix a potential NPD in cleanup_prefix_route()
- 2c98343c9b23 net: txgbe: initialize module info buffer
- 19a4d2aace1d net: txgbe: rename the SFP related
- 9157060fed92 net: txgbe: support CR modules for AML devices
- 7649ba2b1291 net: txgbe: optimize the flow to setup PHY for AML devices
- af08fe9ba091 net: mvpp2: build skb from XDP-adjusted data on XDP_PASS
- 8a2126c5afe8 net: mvpp2: refill RX buffers before XDP or skb use
- 910617a4e67d net: mvpp2: limit XDP frame size to the RX buffer
- a13199fa224e net: mvpp2: sync RX data at the hardware packet offset
- 78069a6d8bc8 netfilter: nft_exthdr: fix register tracking for F_PRESENT flag
- af1b7699466f netfilter: nf_log: validate MAC header was set before dumping it
- 08a3e218064d netfilter: x_tables: avoid leaking percpu counter pointers
- 9d017671dcfc netfilter: nf_conntrack: destroy stale expectfn expectations on unregister
- 4beffcd726e2 netfilter: revalidate bridge ports
- 865e94f6d8a5 spi: rzv2h-rspi: Fix SPDR read access width for 16-bit RX
- 5ae8a38169fc rds: mark snapshot pages dirty in rds_info_getsockopt()
- 2abfb19bbb81 ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
- 5fd1fa5a4254 tun: zero the whole vnet header in tun_put_user()
- dcf458120add net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
- 3dde4fb941fa net: guard timestamp cmsgs to real error queue skbs
- 7560afb8cdda sctp: validate embedded INIT chunk and address list lengths in cookie
- ecf8904067dc ip6_vti: set netns_immutable on the fallback device.
- f76a8b323e28 sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
- d23d53355300 ASoC: SOF: amd: fix for ipc flags check
- 6c75ee4d1d40 net: mctp: usb: don't fail mctp_usb_rx_queue on a deferred submission
- 9c46f3ee1837 net: mctp: usb: fix race between urb completion and rx_retry cancellation
- bace7b99bfa5 gpio: rockchip: fix generic IRQ chip leak on remove
- 5d4bca5cbb69 gpio: zynq: fix runtime PM leak on remove
- c838ffc154cb r8152: handle the return value of usb_reset_device()
- ecc55aad3390 net: openvswitch: fix possible kfree_skb of ERR_PTR
- 2fa49b2715e1 ipv6: sit: reload inner IPv6 header after GSO offloads
- 289c06418ed9 net/mlx5: Use effective affinity mask for IRQ selection
- 2789b74ae1f4 net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure
- 0f807764bb12 net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list
- ab269990ed58 net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove
- 3a254779c169 net: phy: clean the sfp upstream if phy probing fails
- c299321bc623 netdev: fix double-free in netdev_nl_bind_rx_doit()
- c09c2e236eef net: ibm: emac: Fix use-after-free during device removal
- 8b0541231091 net/mlx4: avoid GCC 10 __bad_copy_from() false positive
- 0cde3a004119 net: add pskb_may_pull() to skb_gro_receive_list()
- ede69b8f6670 tcp: restrict SO_ATTACH_FILTER to priv users
- 12e579b88962 ASoC: wm_adsp: Fix NULL dereference when removing firmware controls
- 6136c1474db8 gpio: mvebu: fix NULL pointer dereference in suspend/resume
- 0c4bb32ad7fd netlabel: validate unlabeled address and mask attribute lengths
- 972c106f5d01 bnge: fix context mem iteration
- 6b8baf42b1b7 net: ena: PHC: Add missing barrier
- 640edc281d2f idpf: fix mailbox capability for set device clock time
- 6bdbe6f43ecf ice: fix missing priority callbacks for U.FL DPLL pins
- b5316e2b8614 xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()
- 5513dcb378f9 dma-debug: fix physical address retrieval in debug_dma_sync_sg_for_device
- 4ee4d628c4d9 dma-mapping: direct: fix missing mapping for THRU_HOST_BRIDGE segments
- 8d9a79fbf517 xfrm: iptfs: fix use-after-free on first_skb in __input_process_payload
- e27c17346628 tap: free page on error paths in tap_get_user_xdp()
- 0c03692e2372 verification/rvgen: Fix ltl2k writing True as a literal
- 43ad0a0da486 verification/rvgen: Fix options shared among commands
- 73590b4cfd05 tools/rv: Fix cleanup after failed trace setup
- fd1923910bbf tools/rv: Fix substring match when listing container monitors
- 2122d68f0864 tools/rv: Fix substring match bug in monitor name search
- 618193aba6fe tools/rv: Ensure monitor name and desc are NUL-terminated
- 65046b0d853d cpufreq/amd-pstate: drop stale @epp_cached kdoc
- 63a9f6012f45 spi: cadence-quadspi: fix unclocked access on unbind
- 6671a46144f8 ALSA: seq: dummy: fix UMP event stack overread
- cd98837db15f ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
- 6b71956c25f9 time: Fix off-by-one in settimeofday() usec validation
- ed0ad6574126 hyperv: Clean up and fix the guest ID comment in hvgdk.h
- 8c046f36222c signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()
- 6dc6e5b5c32e selftests: harness: fix pidfd leak in __wait_for_test
- 752e22ecf4df drm/hyperv: During panic do VMBus unload after frame buffer is flushed
- b0f77f76231b Drivers: hv: vmbus: Provide option to skip VMBus unload on panic
- 1639df1a9844 Drivers: hv: VMBus protocol version 6.0
- a6207349e703 sctp: purge outqueue on stale COOKIE-ECHO handling
- 42446ca0f357 net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr
- 285b0842f2e0 ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit()
- 3b7ee029b556 vxlan: vnifilter: fix spurious notification on VNI update
- 8e4d1188bad7 vxlan: vnifilter: send notification on VNI add
- eb676fb14427 octeontx2-af: npc: Fix CPT channel mask in npc_install_flow
- cc272185c9a9 sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
- b198ed4e5258 net/sched: fix pedit partial COW leading to page cache corruption
- e634408d2b0c net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown
- 6f829e2c17a5 net: airoha: Fix use-after-free in metadata dst teardown
- 9a263bbd1ec0 ptp: vclock: Switch from RCU to SRCU
- a4f3fd651692 ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
- 91106d0348a5 af_unix: Fix inq_len update problem in partial read
- f010cf9aea01 octeontx2-af: Fix initialization of mcam's entry2target_pffunc field
- ddf930f28be6 octeontx2-pf: Fix NDC sync operation errors
- 0dfe05b93843 xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata()
- 58d810354de1 Bluetooth: MGMT: Fix backward compatibility with userspace
- 446a17b1b509 Bluetooth: SCO: Fix data-race on sco_pi fields in sco_connect
- ab84fd7779a2 Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls
- 33d677d2e371 Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync
- ce4b4cac3c57 Bluetooth: fix memory leak in error path of hci_alloc_dev()
- c893e17d2809 Bluetooth: bnep: reject short frames before parsing
- 7f5367f1ad9b Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling
- 3eabc6d47a0a Bluetooth: RFCOMM: validate skb length in MCC handlers
- 1a3c8ffbb469 Bluetooth: MGMT: validate advertising TLV before type checks
- 8802413ce631 Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
- fb8db813eba2 wifi: fix leak if split 6 GHz scanning fails
- 15be7e9fdbff ipv6: anycast: insert aca into global hash under idev->lock
- 23bf7d5c250b net: fec: fix pinctrl default state restore order on resume
- 76244b33640b net: lan743x: permit VLAN-tagged packets up to configured MTU
- 04e22fefac1a net: garp: fix unsigned integer underflow in garp_pdu_parse_attr
- 66a46e22396f hsr: Remove WARN_ONCE() in hsr_addr_is_self().
- 07f13816be5a net: Annotate sk->sk_write_space() for UDP SOCKMAP.
- 83810d51d699 pcnet32: stop holding device spin lock during napi_complete_done
- 9b40c59bab08 wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap
- e3f6ba5f8cf3 drm/imx: Fix three kernel-doc warnings in dcss-scaler.c
- 927f96861f93 devlink: Release nested relation on devlink free
- e251d4cdfc72 l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()
- c32f30ef5e66 6lowpan: fix off-by-one in multicast context address compression
- b60e9391142e net/sched: act_api: use RCU with deferred freeing for action lifecycle
- 42ff6774ecd9 dm cache policy smq: check allocation under invalidate lock
- b18675263db1 netfilter: bridge: make ebt_snat ARP rewrite writable
- f071b0bf0781 netfilter: nft_ct: bail out on template ct in get eval
- 9e5da2379f96 netfilter: conntrack_irc: fix possible out-of-bounds read
- aaf80701dc2f netfilter: synproxy: add mutex to guard hook reference counting
- 25918720ba97 ipvs: clear the svc scheduler ptr early on edit
- cdaf13260c99 netfilter: xt_NFQUEUE: prefer raw_smp_processor_id
- e735dbd489e3 ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers
- 9dca67624721 wifi: iwlwifi: mvm: don't support the reset handshake for old firmwares
- 00bf6868df65 erofs: fix use-after-free on sbi->sync_decompress
- 50fd261b1ec4 erofs: tidy up synchronous decompression
- 8db2fabb5ecd tee: qcomtee: add missing va_end in early return qcomtee_object_user_init()
- ac7eca1ae4e5 tee: fix tee_ioctl_object_invoke_arg padding
- 633db9a1991a soc: qcom: ice: Return -ENODEV if the ICE platform device is not found
- 40fc6ed12f91 ARM: dts: microchip: sam9x7: fix GMAC clock configuration
- 9cb93ec617fb arm64: dts: qcom: x1-dell-thena: remove i2c20 (battery SMBus) and reserve its pins
- a171bc68e9af soc: qcom: ice: Allow explicit votes on 'iface' clock for ICE
- d5b57bb314d7 tee: optee: prevent use-after-free when the client exits before the supplicant
- dcd90f42a33e net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS
- 4203806f700b ipv6: mcast: Fix use-after-free when processing MLD queries
- ffbcf31f032e i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl
- 97706097f9b8 KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation
- 9e767af5f109 ARM: fix branch predictor hardening
- 05e22564a4f9 ARM: fix hash_name() fault
- 8bdb574b2176 ARM: allow __do_kernel_fault() to report execution of memory faults
- 22e26df355af ARM: group is_permission_fault() with is_translation_fault()
- 87dfb977bdb6 bpf: Free reuseport cBPF prog after RCU grace period.
- b0ffe362d9f8 Linux 6.18.35-rt-xanmod1
- a42985600ae2 Merge branch '6.18' into 6.18-rt
- da2d87f71ae2 Linux 6.18.35-xanmod1
- f718432d2e3a Merge tag 'v6.18.35' into 6.18
- acb7cf4c1184 Linux 6.18.35
- 918450ad6010 KVM: arm64: Reassign nested_mmus array behind mmu_lock
- 2bbc395e81bd KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry
- adc6fc240a61 tools: ynl: add scope qualifier for definitions
- f54b30f3316a usb: core: Fix SuperSpeed root hub wMaxPacketSize
- 830c8a9b467e thunderbolt: property: Cap recursion depth in __tb_property_parse_dir()
- 21bfa15a89d8 drm/i915/psr: Use DC_OFF wake reference to block DC6 on vblank enable
- 00869f2320dc mailbox: Fix NULL message support in mbox_send_message()
- 5372f6f10b0a xhci: tegra: Fix ghost USB device on dual-role port unplug
- 58b2c0f096b3 net: phy: micrel: fix LAN8814 QSGMII soft reset
- 972ea882d4bf mm/slub: hold cpus_read_lock around flush_rcu_sheaves_on_cache()
- 56857385f313 hwmon: (pmbus/adm1266) serialize GPIO PMBus accesses with pmbus_lock
- 6b94f9f5fe28 hwmon: (pmbus/adm1266) serialize sequencer_state debugfs read with pmbus_lock
- 192516d72774 hwmon: (pmbus) Add support for guarded PMBus lock
- d8fdf33d6fcf USB: serial: mct_u232: fix memory corruption with small endpoint
- 062dcc0b324a USB: serial: digi_acceleport: fix memory corruption with small endpoints
- 284105c40fc3 USB: serial: cypress_m8: fix memory corruption with small endpoint
- c73c62a4bd52 usb: dwc3: xilinx: fix error handling in zynqmp init error paths
- 9327252e0462 xfrm: iptfs: reset runtime state when cloning SAs
- bb50838a2a06 cpufreq: intel_pstate: Use correct scaling factor on Raptor Lake-E
- 7cb2daed3509 cpufreq: intel_pstate: Add and use hybrid_get_cpu_type()
- 8f72a2509163 mptcp: reset rcv wnd on disconnect
- 82e742b9d2cc mptcp: cleanup fallback dummy mapping generation
- 0d9b9d7dbef9 octeontx2-pf: avoid double free of pool->stack on AQ init failure
- fe93e907b1af arm64: tlb: Flush walk cache when unsharing PMD tables
- bb37498a99e4 mptcp: do not drop partial packets
- a84164847b1e mptcp: borrow forward memory from subflow
- c67f986fc02c mptcp: handle first subflow closing consistently
- 134c517dfa63 net: devmem: reject dma-buf bind with non-page-aligned size or SG length
- b2beed6ad149 selftests: mptcp: drop nanoseconds width specifier
- c5e7d4865292 Bluetooth: hci_qca: Convert timeout from jiffies to ms
- 8264178afb5c Bluetooth: hci_qca: Migrate to serdev specific shutdown function
- 0acba63d7d46 serdev: Provide a bustype shutdown function
- 8bf7dbb741dd rxrpc: Fix RESPONSE packet verification to extract skb to a linear buffer
- 46cb765e2e5a rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg
- fed725cace3a x86/mm: Disable broadcast TLB flush when PCID is disabled
- 81181a39bde9 platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error recovery
- 1730c91a8b9a platform/x86/intel/vsec: Make driver_data info const
- 4b0e87f9b50f platform/x86/intel/vsec: Refactor base_addr handling
- 71b88acec0a7 serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq()
- 7f8b194ed720 serial: 8250: dispatch SysRq character in serial8250_handle_irq()
- 5f2172d799f3 serial: core: introduce guard(uart_port_lock_check_sysrq_irqsave)
- 237dc8c08de3 serial: zs: Convert to use a platform device
- 81984447eac4 serial: zs: Switch to using channel reset
- b1ceeaef4fbc serial: zs: Fix bootconsole handover lockup
- 2ff0401ffdda serial: dz: Convert to use a platform device
- 2c5b693d918c serial: dz: Fix bootconsole handover lockup
- 24b7be239b0b serial: dz: Fix bootconsole message clobbering at chip reset
- f059b4c493df drm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO
- fa372f4e8aef drm/amdgpu: fix calling VM invalidation in amdgpu_hmm_invalidate_gfx
- 1eb86334e391 drm/amdgpu: fix lock leak on ENOMEM in AMDGPU_GEM_OP_GET_MAPPING_INFO
- 275396bf71c4 drm/amdkfd: Check for pdd drm file first in CRIU restore path
- 5cf4a41aa0d7 drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger
- 2f9c3c161692 drm/amdkfd: fix NULL pointer bug in svm_range_set_attr
- 348e01e64a87 serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma
- 8e39badab090 serial: zs: Fix swapped RI/DSR modem line transition counting
- 10ddd1a320e1 serial: sh-sci: fix memory region release in error path
- 654f45a8569f serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ
- 78d0d6f69bd6 serial: qcom-geni: fix UART_RX_PAR_EN bit position
- 9a91692fae5c serial: altera_jtaguart: handle uart_add_one_port() failures
- ffa7dce35b64 drm/amd/pm/si: Disregard vblank time when no displays are connected
- c9ae7e7e3bc9 drm/i915: Fix potential UAF in TTM object purge
- fed64e47a32f drm/i915/psr: Block DC states on vblank enable when Panel Replay supported
- 0dfa42cfe4db drm/gem: fix race between change_handle and handle_delete
- 164dc7bf1760 drm/hyperv: validate VMBus packet size in receive callback
- 9c698b2c43c2 drm/hyperv: validate resolution_count and fix WIN8 fallback
- 4a3a19c98a82 scsi: target: iscsi: Validate CHAP_R length before base64 decode
- 594a40360012 scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf
- 89c81d1228c0 scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()
- 35461d237441 scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32
- 14dd80a20a72 scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker
- d548179adcc8 thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow
- 31b98e503ecc thunderbolt: property: Reject u32 wrap in tb_property_entry_valid()
- c7d421123b98 usb: gadget: f_fs: serialize DMABUF cancel against request completion
- 607730a41477 usb: gadget: f_fs: copy only received bytes on short ep0 read
- 5933063935e8 usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports
- f8f5a8f48c7c usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling
- f928630f450b usb: gadget: f_hid: fix device reference leak in hidg_alloc()
- e6f8be12f030 usb: gadget: net2280: Fix double free in probe error path
- caec0145e597 usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind
- f06bcaba2970 USB: serial: mct_u232: fix missing interrupt-in transfer sanity check
- 6c0cf56f00f2 USB: serial: mxuport: fix memory corruption with small endpoint
- ea2b792330b4 USB: serial: keyspan: fix missing indat transfer sanity check
- ae03453f2c80 USB: serial: cypress_m8: validate interrupt packet headers
- 22823a319fb2 USB: serial: belkin_sa: validate interrupt status length
- f7c3fcd63405 USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL
- 38ba1a464c0d USB: serial: option: add MeiG SRM813Q
- 62fbc1396108 usb: typec: ucsi: Don't update power_supply on power role change if not connected
- d62d97c9c8c2 usb: typec: ucsi: Check if power role change actually happened before handling
- f34effb0b545 usb: typec: tcpm: improve handling of DISCOVER_MODES failures
- 02d9d8b79e18 usb: typec: tipd: Fix error code in tps6598x_probe()
- a90139ff1eba usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize
- 75f6d3da2cc6 usb: usbtmc: check URB actual_length for interrupt-IN notifications
- 88d459e5b5a4 usbip: vudc: Fix use after free bug in vudc_remove due to race condition
- 5b78d8b9a832 usb: storage: Add quirks for PNY Elite Portable SSD
- 94b05aec1985 USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers
- 69f9f2b30af0 usb: musb: omap2430: Fix use-after-free in omap2430_probe()
- 3bc65566331a usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval
- 7118304b1a77 usb: chipidea: core: convert ci_role_switch to local variable
- 9fd48937046e tty: serial: samsung: Remove redundant port lock acquisition in rx helpers
- 66f8bfea055b tty: serial: pch_uart: add check for dma_alloc_coherent()
- b4bebb6e0a44 counter: Fix refcount leak in counter_alloc() error path
- c7e670cb2538 comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest()
- 269f5be6a6e4 comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest()
- fdb74898d91d Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490
- 7f95f4792c0d Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem
- 639fa8af506e misc: rp1: Send IACK on IRQ activate to fix kdump/kexec
- 94215d55b094 ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops
- 6617ee91062b Input: xpad - add support for ASUS ROG RAIKIRI II
- 3d63b8077f5b Input: xpad - add "Nova 2 Lite" from GameSir
- 2ffd8b0dd448 ALSA: hda/realtek: Fix speaker output on ASUS ROG Strix G615LP
- c093468aea82 xfrm: esp: restore combined single-frag length gate
- c4609fff0665 ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks
- 35be14ea8298 ASoC: qcom: q6asm-dai: close stream only when running
- b98ab51c45c5 netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check
- b9027ff112b6 ALSA: firewire-motu: Protect register DSP event queue positions
- befcb15c1f05 ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417
- aa0c7e59192b xfrm: ah: use skb_to_full_sk in async output callbacks
- dc6dcba80d72 xfrm: ipcomp: Free destination pages on acomp errors
- 448bb92ca101 xfrm: route MIGRATE notifications to caller's netns
- 22d41b176b99 nfc: hci: fix out-of-bounds read in HCP header parsing
- 8b1f4f618fd8 iommu, debugobjects: avoid gcc-16.1 section mismatch warnings
- b8338111e141 HID: wacom: Fix OOB write in wacom_hid_set_device_mode()
- 59139473a7a7 spi: spi-mem: avoid mutating op template in spi_mem_supports_op()
- 96a4713ae041 net: skbuff: fix missing zerocopy reference in pskb_carve helpers
- fc32be9ac278 ip6: vti: Use ip6_tnl.net in vti6_changelink().
- 947013fd7c8c l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname
- 9f7ebb45a83a xfrm: input: hold netns during deferred transport reinjection
- a35daeabb433 ipv6: validate extension header length before copying to cmsg
- 853f6ea482df ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().
- 751db1b802a0 ipv6: exthdrs: refresh nh after handling HAO option
- 90983f841dfa ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params
- c512e1c819df ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()
- 6d00f5c7e5ff macsec: fix replay protection at XPN lower-PN wrap
- 5e1902866796 bpf: sockmap: fix tail fragment offset in bpf_msg_push_data
- e4892b1ecd73 wireguard: send: append trailer after expanding head
- d59cc66b7027 x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines
- 3f43865cb64d i2c: davinci: fix division by zero on missing clock-frequency
- bf769358419e Input: elan_i2c - validate firmware size before use
- 84ea928ed584 usb: dwc2: Fix use after free in debug code
- 94c92f9c886c usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles
- 459c4fa089f7 usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure
- b2723bd468c5 usb: cdns3: gadget: fix request skipping after clearing halt
- 0fee0ccac29e USB: serial: omninet: fix memory corruption with small endpoint
- 3412a95afaa5 iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf()
- a3763ae33476 iio: buffer: hw-consumer: fix use-after-free in error path
- 390254cf509b iio: light: cm3323: fix reg_conf not being initialized correctly
- 5e4d34092a5e iio: chemical: scd30: fix division by zero in write_raw
- a5a05410cb34 iio: chemical: mhz19b: reject oversized serial replies
- cbd2d7e6bd4f iio: Fix iio_multiply_value use in iio_read_channel_processed_scale
- 8d4daa614440 iio: light: veml6070: Fix resource leak in probe error path
- ae01ec83841d iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL
- aefc19ca3dd3 iio: temperature: tsys01: fix broken PROM checksum validation
- 04a4d9822210 iio: ssp_sensors: cancel delayed work_refresh on remove
- aaf9d640e9ae iio: gyro: adis16260: fix division by zero in write_raw
- 15a0b3f33ffb iio: gyro: itg3200: fix i2c read into the wrong stack location
- 5cb8cede8baf iio: adc: ad4695: Fix call ordering in offload buffer postenable
- 7155e7fce429 iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw
- 944082fdb028 iio: adc: mt6359: fix unchecked return value in mt6358_read_imp
- 991d359faa95 iio: dac: ad5686: fix powerdown control on dual-channel devices
- 31de336a2c0d iio: dac: ad5686: acquire lock when doing powerdown control
- f541c9a1eb89 iio: dac: ad5686: fix input raw value check
- 69f7d101976c iio: dac: ad5686: fix ref bit initialization for single-channel parts
- 684bfd655b80 iio: dac: max5821: fix return value check in powerdown sync
- 88c9dd5170e0 iio: dac: ad3530r: Fix AD3531/AD3531R powerdown mode strings
- 2ce5ca7824a1 iio: adc: npcm: fix unbalanced clk_disable_unprepare()
- 0ee771fff32e iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux
- bb1b43e8a7ed Disable -Wattribute-alias for clang-23 and newer
- bbd989d6fd36 KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc()
- b1dfaa6f7a95 KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer
- 75c8d1d72912 KVM: SEV: Check PSC request indices against the actual size of the buffer
- 9f0a9e780f02 KVM: SEV: Compute the correct max length of the in-GHCB scratch area
- 5300aedbee56 KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0
- e4ab26f81a63 KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests
- 2254972d4d69 KVM: SEV: Ignore Port I/O requests of length '0'
- c9b4198fbc6e KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use
- ec62e8480e82 KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC
- b1fc4a83dd44 KVM: arm64: PMU: Preserve AArch32 counter low bits
- 625153b917bc USB: cdc-acm: Fix bit overlap and move quirk definitions to header
- 667599e71832 rust_binder: avoid calling pending_oneway_finished() on TF_UPDATE_TXN
- f2f2671e32c5 rust_binder: Avoid holding lock when dropping delivered_death
- 74d6aae1df45 parport: Fix race between port and client registration
- 9749db57233b Input: xpad - fix out-of-bounds access for Share button
- d9019210c8c3 Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync
- 2b7651f58670 Bluetooth: hci_qca: Use 100 ms SSR delay for rampatch and NVM loading
- e6b78019664d Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate()
- bc08c15746f2 Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock
- c318aa51830a Bluetooth: ISO: fix UAF in iso_recv_frame
- 6348dfed5b0f Bluetooth: HIDP: fix missing length checks in hidp_input_report()
- e8a5baff5be2 Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn
- 859d3ace791e Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()
- 388051f7389a smb: client: fix uninitialized variable in smb2_writev_callback
- 197476b12601 auxdisplay: line-display: fix OOB read on zero-length message_store()
- 0fcc34d0d8fe mm/rmap: initialize nr_pages to 1 at loop start in try_to_unmap_one
- 0995d1f79aed memfd: deny writeable mappings when implying SEAL_WRITE
- f1f0cdca932b mm: memcontrol: propagate NMI slab stats to memcg vmstats
- a3cc795129e5 ipc: limit next_id allocation to the valid ID range
- 0ba6c05156d9 mm/damon/sysfs-schemes: delete tried region in regions_rmdirs()
- 0886c6f257fe hpfs: fix a crash if hpfs_map_dnode_bitmap fails
- 4064a30381fa Bluetooth: btusb: Allow firmware re-download when version matches
- 6728e80c9d29 HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse
- 8735a28f2dcd Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free()
- f33b5a61673b media: rc: igorplugusb: fix control request setup packet
- f793b67d41e5 USB: serial: safe_serial: fix memory corruption with small endpoint
- 0edd1e21587b usb: typec: ucsi: validate connector number in ucsi_connector_change()
- 9b496e3371c0 usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
- e94933dc41b8 usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer()
- b10eff5abe6a usb: typec: altmodes/displayport: validate count before reading Status Update VDO
- 052dbef45cb3 usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO
- 4505f33dab56 usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()
- f9d787fbe831 usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers
- a38ed87818b2 usb: typec: ucsi: ccg: reject firmware images without a ':' record header
- a58400f58f82 iio: pressure: bmp280: fix stack leak in bmp580 trigger handler
- ce582b22dd2f iio: imu: adis16550: fix stack leak in trigger handler
- e6bb3a49c5f9 iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer
- 278b0df1f736 phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X
- 487393023feb drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used
- c058cf6b84c1 drm/i915/psr: Read Intel DPCD workaround register
- dd4cbab2a446 drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register
- 600ad63124de s390/cio: Restore GFP_DMA for CHSC allocation
- 0171e01de47a Revert "x86/fpu: Refine and simplify the magic number check during signal return"
- ff0ca46b13b9 smb: client: validate the whole DACL before rewriting it in cifsacl
- efacf63ed087 media: rc: ttusbir: fix inverted error logic
- e250b672d40a media: rc: fix race between unregister and urb/irq callbacks
- 814be4a0924b net: skbuff: fix pskb_carve leaking zcopy pages
- ab9a10969a90 ipv6: fix possible infinite loop in fib6_select_path()
- dc36a04621dc ipv6: fix possible infinite loop in rt6_fill_node()
- b62e2b2b4a50 vsock/virtio: bind uarg before filling zerocopy skb
- 68667ee4c7da sctp: fix race between sctp_wait_for_connect and peeloff
- c4152b4e28b3 net: mana: Skip redundant detach on already-detached port
- da87896f34e0 net: mana: Add NULL guards in teardown path to prevent panic on attach failure
- 7f945f7f10f4 gpio: rockchip: teardown bugs and resource leaks
- e2fabb984bfd gpio: rockchip: convert bank->clk to devm_clk_get_enabled()
- 5d43c71fa8e1 gpio: virtuser: Fix uninitialized data bug in gpio_virtuser_direction_do_write()
- b6cdbb681ce1 gpio: adnp: fix flow control regression caused by scoped_guard()
- ae2eac5e9cfe Bluetooth: hci_sync: Reset device counters in hci_dev_close_sync()
- 47330cc875b3 Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close
- 41e29548b5e8 Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp
- f39049304ba6 Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success
- 1d4dcfe60fe1 net/handshake: Pass negative errno through handshake_complete()
- 25b2fcdea6f6 nvme-tcp: store negative errno in queue->tls_err
- 0866569fc36a net/handshake: Use spin_lock_bh for hn_lock
- c35064294eca net: hibmcge: disable Relaxed Ordering to fix RX packet corruption
- 7f97b8352ce5 net/sched: Revert "net/sched: Restrict conditions for adding duplicating netems to qdisc tree"
- 6fe1cb312038 ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()
- fd0de51c54fa ethtool: eeprom: add more safeties to EEPROM Netlink fallback
- c944cab3df82 ethtool: eeprom: add missing ethnl_ops_begin() / _complete() during fallback
- 3e656023a649 ethtool: strset: fix header attribute index in ethnl_req_get_phydev()
- 2008f9bb1ede ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure
- ab94e0d6664d ethtool: tsinfo: fix uninitialized stats on the by-PHC path
- d02342d9bb4f ethtool: tsconfig: fix missing ethnl_ops_complete()
- 912f8b23bc4b ethtool: pse-pd: fix missing ethnl_ops_complete()
- 49455e27838a ethtool: linkstate: fix unbalanced ethnl_ops_complete() on PHY lookup error
- d11c98484485 ethtool: tsconfig: fix reply error handling
- 0c02c190bcd9 ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES
- e976e3f2f200 bridge: Fix sleep in atomic context in sysfs path
- c9c2e609e839 bridge: Fix sleep in atomic context in netlink path
- 9ea8a648d912 bonding: refuse to enslave CAN devices
- e673889a35a5 Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt()
- 75cf24709037 drm/xe: Restore IDLEDLY regiter on engine reset
- 164dcbec9632 ASoC: codecs: simple-mux: Fix enum control bounds check
- de9eb0b44fa9 ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE
- 43368636c663 tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()
- 5303925e3605 vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
- 6dff77899b9e tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmpv6
- 2a8c9994406b cxl/test: Update mock dev array before calling platform_device_add()
- 41d2dc766bf8 ethtool: cmis: validate fw->size against start_cmd_payload_size
- 0696709e951b ethtool: cmis: validate start_cmd_payload_size from module
- 0cbce444db75 ethtool: cmis: fix u16-to-u8 truncation of msleep_pre_rpl
- 4d42fb88ec61 ethtool: cmis: require exact CDB reply length
- e1dd697094f1 ethtool: module: fix cleanup if socket used for flashing multiple devices
- 9e70c8efb0ca ethtool: module: check fw_flash_in_progress under rtnl_lock
- 9f5108f5ee27 ethtool: module: avoid racy updates to dev->ethtool bitfield
- 61848c83b913 ethtool: module: avoid leaking a netdev ref on module flash errors
- d9defbf8b62b ethtool: module: call ethnl_ops_complete() on module flash errors
- 7877d8fbbec2 ethtool: rss: avoid device context leak on reply-build failure
- 7ddc3b3ddee8 ethtool: rss: fix hkey leak when indir_size is 0
- 33d05c22d6f2 ethtool: rss: fix indir_table and hkey leak on get_rxfh failure
- 39c01c405063 ethtool: rss: fix falsely ignoring indir table updates
- 6a775ec73210 ethtool: rss: add missing errno on RSS context delete
- f23e4d7324b8 ethtool: rss: avoid modifying the RSS context response
- 48fd840a26d3 net: Avoid checksumming unreadable skb tail on trim
- 03e9405c518c net: team: fix NULL pointer dereference in team_xmit during mode change
- c2af23b48f93 net: team: Rename port_disabled team mode op to port_tx_disabled
- a20e6ae5f05e net: team: Remove unused team_mode_op, port_enabled
- f2e077e8979f gpio: mxc: fix irq_high handling
- fbd0662f9c9a net: hsr: fix potential OOB access in supervision frame handling
- 2a15a03e58b0 net/mlx5: HWS: Reject unsupported remove-header action
- f0ac76e3d55e ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors
- e13922bb97b4 ALSA: pcm: oss: Fix setup list UAF on proc write error
- a7f4eefb6e14 ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table()
- 475f2b37a78f scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues
- 981736924338 net/iucv: fix locking in .getsockopt
- 55cba6b883b4 net/smc: Do not re-initialize smc hashtables
- bcd0d19db3e6 net: netlink: don't set nsid on local notifications
- ca5e36629641 net: netlink: fix sending unassigned nsid after assigned one
- ef3b3ea864d0 vsock: keep poll shutdown state consistent
- aa308e9dbb9a tun: free page on build_skb failure in tun_xdp_one()
- 37a1c268c2c8 tun: free page on short-frame rejection in tun_xdp_one()
- 96bea2a7baac netfilter: nf_tables: fix dst corruption in same register operation
- bf8e8eac7ede netfilter: ebtables: fix OOB read in compat_mtw_from_user
- 052468b1c93b netfilter: xt_cpu: prefer raw_smp_processor_id
- f0fea2b6d545 netfilter: synproxy: refresh tcphdr after skb_ensure_writable
- 18abd88d19ea accel/rocket: fix UAF via dangling GEM handle in create_bo
- 45564a16a24f kunit: fix use-after-free in debugfs when using kunit.filter
- e1b8a53834dc HID: remove duplicate hid_warn_ratelimited definition
- bebc7dc0fb4b tools/bootconfig: Fix buf leaks in apply_xbc
- b4702049417f nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems
- 82ac903e0b51 xfrm: Check for underflow in xfrm_state_mtu
- 650bdd8fdfab nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()
- 912ebc49d440 nfc: llcp: Fix use-after-free in llcp_sock_release()
- 8b733ee4aecd bcache: fix uninitialized closure object
- dbc560858da8 net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked
- 91cc13978ab0 xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit
- 54ed418de62a net: mctp: ensure our nlmsg responses are initialised
- 41845bc5bb64 net/sched: cls_fw: fix NULL dereference of "old" filters before change()
- 0ca809ea8e03 Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size
- 599f0b059dab Linux 6.18.34-xanmod1
- a17ef3eb3ae0 Merge tag 'v6.18.34' into 6.18
- 18ad16ce4a6b Linux 6.18.34
- 50bb3435a5e6 security/keys: fix missed RCU read section on lookup
- 239172639075 drm/msm: Restore second parameter name in purge() and evict()
- 306ba9d0e5aa LoongArch: kprobes: Fix handling of fatal unrecoverable recursions
- a1a39f227c80 ksmbd: fix durable reconnect error path file lifetime
- 6836f694126e io_uring/nop: pass all errors to userspace
- e334cbf3388f net: gro: don't merge zcopy skbs
- 8129611d4ede pds_core: ensure null-termination for firmware version strings
- d1d76bbb6d7a net: airoha: Disable GDM2 forwarding before configuring GDM2 loopback
- 719007c3492f tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR
- fa627a5eaa83 net: mana: validate rx_req_idx to prevent out-of-bounds array access
- bc0020490f88 octeontx2-af: npc: Fix allmulticast skip logic for LBK and SDP VFs
- 76dd50b7888d selftests: net: Fix checksums in xdp_native
- 04ef7592eaad drm/xe/oa: Fix exec_queue leak on width check in stream open
- db86ac6d8daf ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove()
- decacc6308c5 gpio: aggregator: lock device when calling device_is_bound()
- 3e657619cf72 gpio: aggregator: remove the software node when deactivating the aggregator
- 80d94cf1773a gpio: aggregator: stop using dev-sync-probe
- ea28b286649b gpio: aggregator: fix a potential use-after-free
- 4669f84adcb1 gpio: cdev: check if uAPI v2 config attributes are correctly zeroed
- e47f7060eaf6 tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction
- 1861d369efd6 bpf, skmsg: fix verdict sk_data_ready racing with ktls rx
- 26f1d4522060 net: ag71xx: check error for platform_get_irq
- 585f9f6aef5c crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks
- 2417df5e7bb4 net: shaper: rework the VALID marking (again)
- 5a2c2aa139c8 net: shaper: annotate the data races
- b5bd4249e430 net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA
- a0f5268c77eb Bluetooth: btmtk: fix urb->setup_packet leak in error paths
- c7860b6a6d2d Bluetooth: btintel_pcie: Fix incorrect MAC access programming
- d6c8b3ebdcdb tracing: Avoid NULL return from hist_field_name() on truncation
- 8bf00d3ac425 cgroup: rstat: relax NMI guard after switch to try_cmpxchg
- 3aab4a58d23f ALSA: seq: Serialize UMP output teardown with event_input
- 95c82d498d74 wifi: wilc1000: fix dma_buffer leak on bus acquire failure
- 55c479aae99b wifi: mac80211: fix MLE defragmentation
- 2d8379834800 wifi: mac80211: bounds-check link_id in ieee80211_ml_epcs
- 425d32d6288d erofs: fix managed cache race for unaligned extents
- 91d13e92b983 pds_core: fix debugfs_lookup dentry leak and error handling
- 784dd2bdc622 pds_core: fix error handling in pdsc_devcmd_wait
- ce23832071af net: airoha: Fix NPU RX DMA descriptor bits
- 0c277d203684 net: phy: honor eee_disabled_modes in phy_advertise_eee_all()
- bd731994cff1 net: phy: honor eee_disabled_modes in phy_support_eee()
- a9224862d597 bridge: mcast: Fix a possible use-after-free when removing a bridge port
- 981aea209977 net: bridge: Flush multicast groups when snooping is disabled
- eae62c5451e6 RDMA/rtrs: Fix use-after-free in path file creation cleanup
- 8c63698737b4 RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port
- d5b11e15ee67 ASoC: soc-utils: Add missing va_end in snd_soc_ret()
- 09deb063eecf platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL
- f6dfd64bfd9b platform/x86: intel-hid: Check ACPI_HANDLE() against NULL
- ed864a7b881c platform/x86: hp_accel: Check ACPI_COMPANION() against NULL
- 7ea5aad8d351 platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL
- 098419a4b062 platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7
- 09ec063d87c2 net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer
- f71fc35b5e45 net: dsa: mt7530: preserve VLAN tags on trapped link-local frames
- 89bed786f231 net: dsa: mt7530: fix FDB entries not aging out with short timeout
- f1739debda62 kbuild: pacman-pkg: make "rc" releases adhere to pacman versioning scheme
- ad8e3d096fa1 drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP
- 1f83545f432d igc: set tx buffer type for SMD frames
- 89964ddb322a ice: ptp: use primary NAC semaphore on E825
- 0010296879df ice: ptp: serialize E825 PHY timer start with PTP lock
- 6a01413a4e8f cgroup/rstat: validate cpu before css_rstat_cpu() access
- 83b8a0f72ecc drm/mediatek: mtk_hdmi_ddc: Fix non-static global variable
- 8ea34da68964 drm/mediatek: mtk_cec: Fix non-static global variable
- 926a08cf19be wifi: ath11k: fix peer resolution on rx path when peer_id=0
- 6c9e9272bc37 drm/xe/pf: Fix CFI failure in debugfs access
- dc26e00860a1 drm/xe/vf: Fix signature of print functions
- 2c890e71ae26 drm/xe/gsc: Fix double-free of managed BO in error path
- 181e67bc11c5 dma-mapping: move dma_map_resource() sanity check into debug code
- 3a74aaad0473 wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it
- 9e360e610a73 wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled
- bed1fc32e0eb hwmon: (lm90) Add lock protection to lm90_alert
- c98107817b0f hwmon: (lm90) Stop work before releasing hwmon device
- cdd1aaf0ee96 drm/msm/snapshot: fix dumping of the unaligned regions
- 0c9e4d9484cc ALSA: hda/realtek: Use ALC287_FIXUP_TXNW2781_I2C for ASUS Strix Gxx5
- df19b6af1716 netfilter: nft_inner: release local_lock before re-enabling softirqs
- 0fa225896f4b spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache()
- fecfed41da73 ASoC: amd: acp-sdw-legacy: check CPU DAI name before logging
- 7e91d3a1a98a btrfs: fix squota accounting during enable generation
- ca56ffdb017b btrfs: check for subvolume before deleting squota qgroup
- b422609291f6 btrfs: relax squota parent qgroup deletion rule
- 22d558df51d9 btrfs: check squota parent usage on membership change
- a1296bb9f44a btrfs: remaining BTRFS_PATH_AUTO_FREE conversions
- 76ad957a72c7 btrfs: don't search back for dir inode item in INO_LOOKUP_USER
- 16141bef6fb1 btrfs: use the key format macros when printing keys
- 35f69e993d00 btrfs: add macros to facilitate printing of keys
- 76b995bc57bd vsock/virtio: fix zerocopy completion for multi-skb sends
- 782693eb53f8 io_uring/net: punt IORING_OP_BIND async if it needs file create
- c53cac053d62 ALSA: scarlett2: Add missing error check when initialise Autogain Status
- 1ddf678bb75b ASoC: codecs: fs210x: fix possible buffer overflow
- 36de63965464 scsi: sd: Fix return code handling in sd_spinup_disk()
- b4dc0056397f net/mlx5: Do not restore destination-less TC rules
- 81c8a9f75a42 tls: Preserve sk_err across recvmsg() when data has been copied
- 1370acb8bc39 ovpn: disable BHs when updating device stats
- f7808b7ddcf2 x86/xen: Fix xen_e820_swap_entry_with_ram()
- 2378d25675da gcc-plugins: Always define CONST_CAST_GIMPLE and CONST_CAST_TREE
- 097d62df3831 ovpn: fix race between deleting interface and adding new peer
- 8298834912d7 ovpn: respect peer refcount in CMD_NEW_PEER error path
- e5460eb7238c ovpn: tcp - use cached peer pointer in ovpn_tcp_close()
- 2bc34520ce5c net: phy: DP83TC811: add reading of abilities
- af855f4c966a net: tls: prevent chain-after-chain in plain text SG
- eca989eab4b2 net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring
- afa9036b8c99 net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot
- 6dcd072a5ae3 powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise()
- f4e37f3df436 drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN
- eea43d5ed450 drm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx
- 3a7b59d2385d Documentation: intel_pstate: Fix description of asymmetric packing with SMT
- 3ad2d8be6e4d x86/mce: Restore MCA polling interval halving
- 15dba511d569 selftests: ublk: cap nthreads to kernel's actual nr_hw_queues
- ff58e5ef1b46 drm/msm/dpu: don't mix devm and drmm functions
- a184aec79013 drm/msm/dsi: don't dump registers past the mapped region
- d235f8f7b264 ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics
- d2ea0b8aef87 net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint
- 97a8e89cdef3 accel/qaic: Add overflow check to remap_pfn_range during mmap
- 76410790f149 block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()
- 086695145000 HID: quirks: really enable the intended work around for appledisplay
- 0943f81e1b31 block: recompute nr_integrity_segments in blk_insert_cloned_request
- 0d48654af4d1 block: don't overwrite bip_vcnt in bio_integrity_copy_user()
- a52486394493 net: shaper: reject QUEUE scope handle with missing id
- 77ec90d41c59 net: shaper: enforce singleton NETDEV scope with id 0
- d7c2bbbaa2c4 net: shaper: fix undersized reply skb allocation in GROUP command
- f817ce8d1943 net: shaper: set ret to -ENOMEM when genlmsg_new() fails in group_doit
- 5098b223f0f0 net: shaper: reject duplicate leaves in GROUP request
- d6128451c591 net: shaper: fix trivial ordering issue in net_shaper_commit()
- d947e6685ff4 net: shaper: flip the polarity of the valid flag
- e1b429d8e712 wifi: ath10k: skip WMI and beacon transmission when device is wedged
- d94127d04017 wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm()
- acde4692afcd wifi: ath11k: fix error path leaks in some WMI WOW calls
- 9bc70fe995da net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference
- c373b34877af net: ethernet: cortina: Carry over frag counter
- 3cd05250a2df net: ethernet: cortina: Drop half-assembled SKB
- cfd62907f3cd net: ethernet: cortina: Make RX SKB per-port
- 77bb293049d6 netfs, afs: Fix write skipping in dir/link writepages
- f17b9121bb99 netfs: Fix netfs_read_folio() to wait on writeback
- 551b5c71ee31 netfs: Fix folio->private handling in netfs_perform_write()
- 3d9601c029b9 netfs: Fix partial invalidation of streaming-write folio
- 6080fa3ecfbb netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()
- 22ae28aae436 netfs: Fix leak of request in netfs_write_begin() error handling
- d4f4bc87c765 netfs: Fix early put of sink folio in netfs_read_gaps()
- 616578e40dcb netfs: Fix write streaming disablement if fd open O_RDWR
- 0b18cd70ebab netfs: Fix read-gaps to remove netfs_folio from filled folio
- 003aa0dd26c9 netfs: Fix potential deadlock in write-through mode
- ef9b521212e4 netfs: Fix streaming write being overwritten
- 185ded4112cd netfs: Defer the emission of trace_netfs_folio()
- fb6ec883b48b netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone
- afeb32d9bf9a netfs: Fix overrun check in netfs_extract_user_iter()
- b63971238beb netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call
- 884c4c4f35e5 netfs: Fix netfs_read_to_pagecache() to pause on subreq failure
- 5366199be46f netfs: Fix cancellation of a DIO and single read subrequests
- 9c6f23cf3a07 powerpc: fix dead default for GUEST_STATE_BUFFER_TEST
- 822bb1614ec4 powerpc: 82xx: fix uninitialized pointers with free attribute
- aed60070ed7b ASoC: SOF: amd: Fix error code handling in psp_send_cmd()
- 510db031ba6e tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key().
- eba8af785fde zonefs: handle integer overflow in zonefs_fname_to_fno
- 9525e3a6fbb1 nvme-pci: fix use-after-free in nvme_free_host_mem()
- fea4b46f84c5 nvme: fix bio leak on mapping failure
- 18c0456ea261 irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT
- 06ee55f78fbe nsfs: fix wrong error code returned for pidns ioctls
- d168a71fc1d6 ublk: reject max_sectors smaller than PAGE_SECTORS in parameter validation
- 617a2564d863 irqchip/ath79-cpu: Remove unused function
- ace6b3e033c6 fs: Fix return in jfs_mkdir and orangefs_mkdir
- e37ea2c6f17f fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap
- 56b4cfcf1518 fprobe: Fix unregister_fprobe() to wait for RCU grace period
- 36dc0cea30db ASoC: sdw_utils: Add quirk to ignore RT721 CODEC_MIC
- 5afefecfe054 ASoC: sdw_utils: Add quirk to ignore RT712 CODEC_MIC
- fe59ae27d734 NFSD: Fix infinite loop in layout state revocation
- e9405f704127 phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access
- 994358adc098 net: ti: icssm-prueth: fix eth_ports_node leak in probe
- 7df3e1dfee53 net: lan966x: avoid unregistering netdev on register failure
- d91a9a049698 ice: fix locking in ice_dcb_rebuild()
- 34ad3c782644 ice: fix setting RSS VSI hash for E830
- eb5991d4c8ba idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()
- a248793f00ab net: shaper: Reject reparenting of existing nodes
- bfe08fe5624b net: napi: Avoid gro timer misfiring at end of busypoll
- 77e7818eb347 tcp: Fix imbalanced icsk_accept_queue count.
- 1c24cf1fd67f test_kprobes: clear kprobes between test runs
- ae8a5c6b0316 kprobes: skip non-symbol addresses in kprobe_add_ksym_blacklist()
- c647e2a21bbb netfilter: bridge: eb_tables: close module init race
- 524b6337277a netfilter: x_tables: close dangling table module init race
- cc989ef1c044 netfilter: ebtables: close dangling table module init race
- 739d5dac7b2d netfilter: ebtables: move to two-stage removal scheme
- 86ee5bc9c0f0 netfilter: x_tables: add and use xtables_unregister_table_exit
- 89ebafe7910d netfilter: x_tables: add and use xt_unregister_table_pre_exit
- a9b2f73f6ba7 netfilter: x_tables: unregister the templates first
- c32a7e0e3c73 btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()
- 373f65b448ed ALSA: hda: cs35l41: Put ACPI device on missing physical node
- fecae8b1fb2d ALSA: hda: cs35l56: Put ACPI device after setting companion
- e984dc22e2c2 ARM: integrator: Fix early initialization
- 9e472874c954 firmware: arm_ffa: Fix sched-recv callback partition lookup
- d1e38551fade firmware: arm_ffa: Snapshot notifier callbacks under lock
- 419cef661ae8 firmware: arm_ffa: Align RxTx buffer size before mapping
- 3c51d99449dc firmware: arm_ffa: Validate framework notification message layout
- 0a5dbac5ef53 firmware: arm_ffa: Keep framework RX release under lock
- f39bc7ebe75e firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies
- fd2b01637e56 pinctrl: qcom: Fix wakeirq map by removing disconnected irqs for sm8150
- 3f4d82780001 kunit: config: KUNIT_DEBUGFS should depend on DEBUG_FS
- 91e4446b35f6 kunit: config: Enable KUNIT_DEBUGFS by default
- 96b8b9d0dead riscv: mm: Fixup no5lvl failure when vaddr is invalid
- f3216d930c0f riscv: errata: Fix bitwise vs logical AND in MIPS errata patching
- 1aa01b46fe3b firmware: arm_ffa: Unregister bus notifier on teardown for FF-A v1.0
- 07907b897bb7 firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue
- 1418765d28ab firmware: arm_ffa: Skip free_pages on RX buffer alloc failure
- 820245d86ce5 firmware: arm_ffa: Check for NULL FF-A ID table while driver registration
- 4894847fcec1 HID: uclogic: Fix regression of input name assignment
- e912d5dc0096 HID: intel-thc-hid: Intel-quickspi: Fix some error codes
- 1fce9dcb3a66 pinctrl: qcom: Fix GPIO to PDC wake irq map for qcs615
- e917713f0134 pinctrl: meson: amlogic-a4: fix deadlock issue
- 8d1c6b603327 pinctrl: renesas: rzg2l: Fix SMT register cache handling
- c4cfa8ee7737 pinctrl: renesas: rzg2l: Fix incorrect PUPD register offset for high pins during suspend/resume
- a7fee1322683 ARM: dts: renesas: rskrza1: Drop superfluous cells
- d27b29e474a6 ARM: dts: renesas: genmai: Drop superfluous cells
- 00aca89f5e34 pinctrl: qcom: ipq4019: mark gpio as a GPIO pin function
- eb3cd9bb5904 hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors
- dd12c6dbe2ac hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe()
- a203125c0e81 hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe()
- b2998ae90331 hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple
- fa7ca363069a hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR
- 97a9cf2a8217 hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer
- 2279c342d94e hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer
- 75c862adf3d3 hwmon: (pmbus/adm1266) reject implausible blackbox record_count
- e9b8f85daebf hwmon: (pmbus/adm1266) seed timestamp from the real-time clock
- e37dbe150515 batman-adv: tt: prevent TVLV entry number overflow
- 730de8733dd9 batman-adv: tt: fix negative tt_buff_len
- 179eb62506a0 batman-adv: tt: fix negative last_changeset_len
- b93ca6012712 batman-adv: tt: avoid empty VLAN responses
- 7cac9c9ef4b7 batman-adv: tt: reject oversized local TVLV buffers
- 4cc85aec8d3c batman-adv: tt: fix TOCTOU race for reported vlans
- 2d2d365d0b9d batman-adv: tp_meter: avoid role confusion in tp_list
- 72d670d7a492 batman-adv: tp_meter: fix race condition in send error reporting
- b285bc0a97f4 batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown
- 770bf0a35f06 batman-adv: tp_meter: directly shut down timer on cleanup
- dc2ae5fbd2da batman-adv: tp_meter: avoid use of uninit sender vars
- 6921a7683ae9 batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface
- 45384612f296 batman-adv: bla: avoid double decrement of bla.num_requests
- c6de1a5a9c40 batman-adv: bla: fix report_work leak on backbone_gw purge
- 5895ad21c705 batman-adv: frag: disallow unicast fragment in fragment
- 90ae3eae06b7 batman-adv: fix tp_meter counter underflow during shutdown
- 3eb8bcb82339 batman-adv: fix fragment reassembly length accounting
- 9cceea8eeba7 batman-adv: dat: handle forward allocation error
- ae7aeb0ce3c0 batman-adv: clear current gateway during teardown
- 8a3707653ab6 batman-adv: mcast: fix use-after-free in orig_node RCU release
- ca3ff3d2a0af batman-adv: iv: recover OGM scheduling after forward packet error
- ede47988ac56 batman-adv: tvlv: reject oversized TVLV packets
- 23d4ce84df4d batman-adv: tvlv: abort OGM send on tvlv append failure
- 1be1e99cbd5b batman-adv: v: stop OGMv2 on disabled interface
- 1ecde19bfce6 drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async
- 7ca695b31222 drm/amd/display: Validate GPIO pin LUT table size before iterating
- 6bbd703ea1c1 drm/amd/display: Fix integer overflow in bios_get_image()
- d35563813296 drm/bridge: megachips: remove bridge when irq request fails
- 95306db11956 drm/bridge: it66121: acquire reset GPIO in probe
- 3ed448c1dc78 drm/amdgpu/vpe: Force collaborate sync after TRAP
- 8fadd01cf461 drm/virtio: use uninterruptible resv lock for plane updates
- 35671087a272 drm/v3d: Release indirect CSD GEM reference on CPU job free
- 0f8efc45740b drm/v3d: Fix use-after-free of CPU job query arrays on error path
- 942968260e61 drm/msm: Fix shrinker deadlock
- 508fd8ab158a device property: set fwnode->secondary to NULL in fwnode_init()
- 22d9b9739b8e LoongArch: Remove unused code to avoid build warning
- f27a3b9aadfb LoongArch: kprobes: Use larch_insn_text_copy() to patch instructions
- 9e3f18883a98 fwctl: pds: Validate RPC input size before parsing
- 1012896f4225 RDMA/siw: Reject MPA FPDU length underflow before signed receive math
- d7a076fb596c spi: ti-qspi: fix use-after-free after DMA setup failure
- be409d2bbe9c spi: sprd: fix error pointer deref after DMA setup failure
- 8e027db9fa31 spi: ep93xx: fix error pointer deref after DMA setup failure
- b9ff86310062 scsi: isci: Fix use-after-free in device removal path
- 78a369a065f1 phy: qcom-qmp-ufs: Fix kaanapali PHY PLL lock failure after SM8650 G4 fix
- 58f4a7bd8d73 phy: tegra: xusb: Fix per-pad high-speed termination calibration
- a1f50f5aaa69 phy: exynos5-usbdrd: fix USB 2.0 HS PHY tuning values for Exynos7870
- 4bb4764f2c51 spi: qup: fix error pointer deref after DMA setup failure
- ecdf21536c6d drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe
- bee400ad4f42 virt: sev-guest: Explicitly leak pages in unknown state
- 4f087193b5ff riscv: kvm: return SBI_ERR_FAILURE for pmu_event_info() when OOM
- 77071943c752 riscv: kvm: return SBI_ERR_FAILURE for pmu_snapshot_set_shmem() when OOM
- 94ade38f317e KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235)
- 7023900b4988 KVM: arm64: vgic: Free private_irqs when init fails after allocation
- 0680f5119265 KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits
- 240373425e2d arm64: probes: Handle probes on hinted conditional branch instructions
- 798183376d9d tracing: Do not call map->ops->elt_free() if elt_alloc() fails
- 5e7d9d0805e5 cifs: Fix busy dentry used after unmounting
- 2dd9304727c7 wifi: mac80211: consume only present negotiated TTLM maps
- acdff9907478 af_unix: Fix UAF read of tail->len in unix_stream_data_wait()
- 6cfae4914439 wifi: cfg80211: advance loop vars in cfg80211_merge_profile()
- 50884c2afd7a ice: restore PTP Rx timestamp config after ethtool set-channels
- 0b9431b972a0 ice: fix setting promisc mode while adding VID filter
- 9c9d00d81b41 ice: fix locking around wait_event_interruptible_locked_irq
- f1bafd35f11b igc: fix potential skb leak in igc_fpe_xmit_smd_frame()
- 8864b664d044 octeontx2-pf: fix double free in rvu_rep_rsrc_init()
- 47a4cf2229be octeontx2-af: CGX: add bounds check to cgx_speed_mbps index
- 5b906f31e977 lsm: hold cred_guard_mutex for lsm_set_self_attr()
- 9dcd4f5c99b4 rbd: eliminate a race in lock_dwork draining on unmap
- dfef79e09ed2 ixgbevf: fix use-after-free in VEPA multicast source pruning
- 7725cd3b4717 ipv4: raw: reject IP_HDRINCL packets with ihl < 5
- dc31c6947652 wifi: iwlwifi: mld: stop TX during firmware restart
- 6fe92651b44f wifi: iwlwifi: mvm: fix driver-set TX rates on old devices
- 614cacec60fe wifi: ath11k: clear shared SRNG pointer state on restart
- a3529032afe2 ice: fix VF queue configuration with low MTU values
- c618cf8926c0 vsock/virtio: reset connection on receiving queue overflow
- 440447699c68 vsock/vmci: fix UAF when peer resets connection during handshake
- 29b643351012 mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient
- abdd03229414 ipv6: ioam: add NULL check for idev in ipv6_hop_ioam()
- 2bc60c175568 ring-buffer: Flush and stop persistent ring buffer on panic
- 610ff6bc2f44 ring-buffer: Fix reporting of missed events in iterator
- 0e47fc1c9181 qed: fix double free in qed_cxt_tables_alloc()
- e0c3dd7b30cc l2tp: use list_del_rcu in l2tp_session_unhash
- d73dcd1520d6 fs/ntfs3: handle attr_set_size() errors when truncating files
- 358692462555 net: ethtool: phy: avoid NULL deref when PHY driver is unbound
- 61f53c1e58d6 net: ethtool: fix NULL pointer dereference in phy_reply_size
- 752ea4a105e6 cgroup/cpuset: Reset DL migration state on can_attach() failure
- 1aed73795392 tracing/fprobe: Check the same type fprobe on table as the unregistered one
- f0ad68d2f0ad tracing/fprobe: Avoid kcalloc() in rcu_read_lock section
- bb92f356d2b7 tracing: fprobe: use ftrace if CONFIG_DYNAMIC_FTRACE_WITH_ARGS
- 52cc572c9565 tracing: fprobe: Remove unused local variable
- 45c7c4e3db8b sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path
- 6e73ec10b2a3 sched_ext: Fix missing warning in scx_set_task_state() default case
- 689bbf48c1f4 netfilter: nft_inner: Fix IPv6 inner_thoff desync
- 952e988163c2 netfilter: ipset: stop hash:* range iteration at end
- 15d464265120 netfilter: nf_queue: hold bridge skb->dev while queued
- 57b0ac5e1b46 netfilter: ip6t_hbh: reject oversized option lists
- dac025c4e8f9 net: pse-pd: fix sign on -ENOENT check in of_load_pse_pis()
- f8a5a76b4a68 net: ifb: report ethtool stats over num_tx_queues
- 1604a2d68414 net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover
- 49eff79967fd net: phy: skip EEE advertisement write when autoneg is disabled
- 3d4ef05266ab net: bcmgenet: keep RBUF EEE/PM disabled
- 84bc87beb4cd phonet/pep: disable BH around forwarded sk_receive_skb()
- 8b4c412e001b Bluetooth: serialize accept_q access
- f1febe93ef07 Bluetooth: MGMT: validate Add Extended Advertising Data length
- 051922ab709c Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer
- 192cb0f1ca70 Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths
- 5506aec79513 Bluetooth: bnep: Fix UAF read of dev->name
- 61f2410a96de Bluetooth: ISO: drop ISO_END frames received without prior ISO_START
- added1213395 Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()
- ffb6dbb49c96 net: wwan: iosm: fix potential memory leaks in ipc_imem_init()
- 0fa24311bd42 selftests/mm: run_vmtests.sh: fix destructive tests invocation
- 738d18f1da35 mm/page_alloc: fix initialization of tags of the huge zero folio with init_on_free
- 09ce923071e7 mm/memory_hotplug: fix memory block reference leak on remove
- 62153767e8fc mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_special()
- 2fff0cdd9422 mm/memory: fix spurious warning when unmapping device-private/exclusive pages
- 24de676da63c ipv6: ioam: refresh hdr pointer before ioam6_event()
- 24840b3139d7 drivers/base/memory: fix memory block reference leak in poison accounting
- b737c6612c60 io_uring/waitid: clear waitid info before copying it to userspace
- 5fb947ddae55 spi: amd: Set correct bus number in ACPI probe path
- c32a1fbe0f9a efi: Allocate runtime workqueue before ACPI init
- fcbd0a5fd812 ALSA: scarlett2: Allow flash writes ending at segment boundary
- 61c5017c64e2 ALSA: asihpi: Fix potential OOB array access at reading cache
- feff0251386a ALSA: pcm: Don't setup bogus iov_iter for silencing
- cba8dab72e9b ALSA: ua101: Reject too-short USB descriptors
- ca560f7566df hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX
- 9803e75c9813 smb/server: promote S_DEL_ON_CLS to S_DEL_PENDING when close
- d65104a4a815 smb: client: use data_len for SMB2 READ encrypted folioq copy
- bf4ebdb19ff9 smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
- a8d17d22db59 smb: client: require net admin for CIFS SWN netlink
- 6827647fd2dc regulator: tps65219: fix irq_data.rdev not being assigned
- 18d8db24b0a5 ksmbd: validate SID in parent security descriptor during ACL inheritance
- 0e198f09cb2a ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow
- cd5c1b75d2f4 ksmbd: fix null pointer dereference in compare_guid_key()
- 302e02f9ba49 mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break()
- 48fa96538bd2 sysfs: don't remove existing directory on update failure
- 141ffb83abe9 drm/vblank: Fix kernel docs for vblank timer
- ed39ecd3a96c drm/atomic: Increase timeout in drm_atomic_helper_wait_for_vblanks()
- a0582cc92398 drm/vkms: Convert to DRM's vblank timer
- 60918357456d drm/vblank: Add CRTC helpers for simple use cases
- fa4b91eea433 drm/vblank: Add vblank timer
- 18a08b87db71 Revert "ice: Remove jumbo_remove step from TX path"
- 523cd0ea0324 Revert "ice: fix double-free of tx_buf skb"
- 515de0a3b6c1 ata: libata-scsi: do not needlessly defer commands when using PMP with FBS
- 4e6eada8de38 ata: libata-scsi: do not use the deferred QC feature on PMPs with CBS
- f207ebd5656e ata: libata-scsi: do not use the deferred QC feature for ATA_DEFER_PORT
- 62ee00c1042c ata: libata-scsi: improve readability of ata_scsi_qc_issue()
- 9d11e4b1db1c mfd: bcm2835-pm: Add support for BCM2712
- ed915823d469 arm64: dts: broadcom: bcm2712: Add watchdog DT node
- 375d5a17dc8d dt-bindings: soc: bcm: Add bcm2712 compatible
- 91f89c1d83e8 smb: client: reject userspace cifs.spnego descriptions
- 5da69a65b282 ksmbd: close durable scavenger races against m_fp_list lookups
- aae4a47073b1 spi: spi-dw-dma: fix print error log when wait finish transaction
- e8ec80430bfa bridge: mrp: reject zero test interval to avoid OOM panic
- 0638bf16b7a7 sched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting
- 3f0543bdf446 sched: Employ sched_change guards
- dc184ac2f0ba cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed()
- da3d241c5b92 fuse: fix uninit-value in fuse_dentry_revalidate()
- 488d2c76bd9f iommu/amd: Remove latent out-of-bounds access in IOMMU debugfs
- b9a4184271b9 iommu/amd: Fix illegal cap/mmio access in IOMMU debugfs
- 814326e86e92 drm/xe/hdcp: Add NULL check for media_gt in intel_hdcp_gsc_check_status()
- e469a636f608 Linux 6.18.33-xanmod1
- b1dc0d89228b tcp_bbr: v3: update TCP 'bbr' congestion control module to BBRv3 [v6.18.33+]
- bddb6a8ebea6 Merge tag 'v6.18.33' into 6.18
- ac95f57c40f3 Revert "tcp_bbr: v3: update TCP 'bbr' congestion control module to BBRv3 [v6.18.14+]"
- 83657f418961 Linux 6.18.33
- 664736cc1f95 netfs: Fix potential uninitialised var in netfs_extract_user_iter()
- e9a23ec9461e selftests/bpf: Remove test_access_variable_array
- ff375cc75f91 net: skbuff: propagate shared-frag marker through frag-transfer helpers
- 3bd9e113d500 net: skbuff: preserve shared-frag marker during coalescing
- 640e37f58f99 net/rds: reset op_nents when zerocopy page pin fails
- 6bf4253af814 spi: sifive: fix controller deregistration
- 27fcf3dd04df spi: sifive: Simplify clock handling with devm_clk_get_enabled()
- fac9cfad2f90 f2fs: fix false alarm of lockdep on cp_global_sem lock
- a4a0340d20ab sched_ext: Pass held rq to SCX_CALL_OP() for core_sched_before
- 255c3998dae8 sched_ext: Guard scx_dsq_move() against NULL kit->dsq after failed iter_new
- a3c44e77f379 perf/x86/intel: Disable PMI for self-reloaded ACR events
- b6437e6f8f3d btrfs: do not mark inode incompressible after inline attempt fails
- 2647b8fe2f1f smb: client: Use FullSessionKey for AES-256 encryption key derivation
- 244575d0c695 eventfs: Use list_add_tail_rcu() for SRCU-protected children list
- 4fa42a249e8c drm/v3d: Reject empty multisync extension to prevent infinite loop
- 4e003e2fb6d3 drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init
- ab9256936b58 drm/gma500/oaktrail_lvds: fix hang on init failure
- 6d835a99474c drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup
- 9a34b94832c3 drm/ttm: Convert -EAGAIN from dmem_cgroup_try_charge to -ENOSPC
- 39fdac6be02e drm/xe/dma-buf: fix UAF with retry loop
- 20a99ea1e2fd drm/xe/dma-buf: handle empty bo and UAF races
- c76273c3eba9 drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout()
- 65a3a1cf29eb drm/i915: skip __i915_request_skip() for already signaled requests
- 9022cb9ac0c2 iommu/vt-d: Avoid NULL pointer dereference or refcount corruption
- 88397fad7914 iommu/vt-d: Fix oops due to out of scope access
- 637b7ce89e54 iommu/vt-d: Disable DMAR for Intel Q35 IGFX
- 4d2b37abda95 libceph: handle rbtree insertion error in decode_choose_args()
- 0f3604cbe4df libceph: Fix potential out-of-bounds access in crush_decode()
- f2f95e6d4b97 libceph: Fix potential null-ptr-deref in decode_choose_args()
- 48df98d12b15 libceph: Fix potential out-of-bounds access in osdmap_decode()
- 0de5cb2d61d0 irqchip/gic-v5: Allocate ITS parent LPIs as a range
- 2cbd4abe413e irqchip/gic-v5: Support range allocation for LPIs
- e6550b17cc0e irqchip/gic-v5: Move LPI allocation into the LPI domain
- 84ff9ae64d9b irqchip/meson-gpio: Use the correct register in meson_s4_gpio_irq_set_type()
- 5b0756b6b757 irqchip/riscv-imsic: Clear interrupt move state during CPU offlining
- 42558732af4a nfsd: fix file change detection in CB_GETATTR
- fc6db1e47c55 netfs: fix error handling in netfs_extract_user_iter()
- 1a78bea6a5e9 powerpc/warp: Fix error handling in pika_dtm_thread
- 3f6fb0211b39 virt: sev-guest: Do not use host-controlled page order in cleanup path
- 690b7ca1f9b3 xfs: fix memory leak on error in xfs_alloc_zone_info()
- b0bd7a850e1f x86/kexec: Push kjump return address even for non-kjump kexec
- f0a0f01787ec iommu/amd: Bounds-check devid in __rlookup_amd_iommu()
- 252c5051dba9 io-wq: check that the predecessor is hashed in io_wq_remove_pending()
- d5bd8b4e39cf ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size
- 3fa13ceefbc5 ceph: fix a buffer leak in __ceph_setxattr()
- 9ebb7eba1237 btrfs: only release the dirty pages io tree after successful writes
- d7b2de5d9862 ALSA: usb-audio: qcom: Check offload mapping failures
- 09141583bd97 ALSA: usb-audio: Bound MIDI endpoint descriptor scans
- f9c184a83574 ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans
- 651760f57fe0 ALSA: hda/realtek: Add quirk for Samsung Galaxy Book5 360 headphone
- a424946e00f2 ALSA: hda/realtek: Add mute LED quirk for HP Pavilion Laptop 16-ag0xxx
- d3e03c25d520 accel/rocket: Fix prep_bo ioctl leaking positive return from dma_resv_wait_timeout()
- 9b718ebe0e97 platform/x86: lenovo-wmi-other: Fix tunable_attr_01 struct members
- b6c0f545c8f9 platform/x86: lenovo-wmi-helpers: Move gamezone enums to wmi-helpers
- 1b2dca1f9b5a platform/x86: intel: Move debugfs register before creating devices
- d25b863e2dff drm/i915/dp: Fix VSC dynamic range signaling for RGB formats
- 318b995cffcf drm: Replace old pointer to new idr
- d31c6b334215 drm/loongson: Use managed KMS polling
- 97a05b0ae9ea smb/client: fix possible infinite loop and oob read in symlink_data()
- 0ea9d6e036be nvme-apple: Reset q->sq_tail during queue init
- 527cb4a55155 Bluetooth: btmtk: accept too short WMT FUNC_CTRL events
- 151cfe527f0a media: staging: imx: configure src_mux in csi_start
- 7c96f2e5b6fb ata: libata-scsi: fix requeue of deferred ATA PASS-THROUGH commands
- d92229dfa3f9 fuse: avoid 0x10 fault in fuse_readahead when max_pages == 0
- 3ab135238832 HID: core: Fix size_t specifier in hid_report_raw_event()
- 301338b8edad HID: core: introduce hid_safe_input_report()
- 509c26050650 HID: pass the buffer size to hid_report_raw_event
- 8adc988e9f20 KVM: x86: Fix Xen hypercall tracepoint argument assignment
- b22a2da8792a KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic
- 0d419c23bb11 KVM: Reject wrapped offset in kvm_reset_dirty_gfn()
- d9017d233258 audit: enforce AUDIT_LOCKED for AUDIT_TRIM and AUDIT_MAKE_EQUIV
- e029cbd8c06d net: atlantic: preserve PCI wake-from-D3 on shutdown when WOL enabled
- 1dced0725e2f netfilter: nft_ct: fix missing expect put in obj eval
- a9f76de38ba3 Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn"
- 722b91d5086a idpf: fix double free and use-after-free in aux device error paths
- c4a8998aafb8 cgroup/dmem: Return -ENOMEM on failed pool preallocation
- bddf59818ae5 net: ena: PHC: Check return code before setting timestamp output
- e35f3550c5b4 audit: fix incorrect inheritable capability in CAPSET records
- 430b05f6c918 netfilter: nf_conntrack_sip: get helper before allocating expectation
- 95e8ae9af2a6 net: ena: PHC: Fix potential use-after-free in get_timestamp
- 10addc25fa17 workqueue: Fix wq->cpu_pwq leak in alloc_and_link_pwqs() WQ_UNBOUND path
- f43240068791 i40e: Cleanup PTP pins on probe failure
- a1c5672faf8e crypto: af_alg - Cap AEAD AD length to 0x80000000
- b4e1c03b876c sched/fair: Revert force wakeup preemption
- ec4f6da3373d sched/fair: Fix wakeup_preempt_fair() for not waking up task
- ce8ac8432fd7 net: mana: Init gf_stats_work before potential error paths in probe
- 45d6c6c10b8b net: mana: Fix use-after-free in reset service rescan path
- 80c025618524 net: airoha: Fix VIP configuration for AN7583 SoC
- 81a2a3607866 net: airoha: Use gdm port enum value whenever possible
- 106581064439 net: airoha: Remove code duplication in airoha_regs.h
- db9af8a2efad net/sched: sch_pie: annotate more data-races in pie_dump_stats()
- 90619fdedfb9 net: airoha: Move ndesc initialization at end of airoha_qdma_init_tx()
- 7645ead02939 net: airoha: Move entries to queue head in case of DMA mapping failure in airoha_dev_xmit()
- 95fdee73c39c rtla: Fix parse_cpu_set() bug introduced by strtoi()
- 26b4ea23f511 net: airoha: Fix a copy and paste bug in probe()
- dbbd60129f79 bpf: Fix sync_linked_regs regarding BPF_ADD_CONST32 zext propagation
- 22f72b1dccfe PCI: Initialize temporary device in new_id_store()
- 735439394dde Revert "papr-hvpipe: convert papr_hvpipe_dev_create_handle() to FD_PREPARE()"
- d66dc9505935 Revert "pseries/papr-hvpipe: Fix race with interrupt handler"
- 1dcd36420af2 futex: Drop CLONE_THREAD requirement for private default hash alloc
- dcb89deed40b arm64: Reserve an extra page for early kernel mapping
- b9d854388988 kselftest/arm64: Include <asm/ptrace.h> for user_gcs definition
- 5704a90c0970 net/sched: cls_flower: revert unintended changes
- 3f4a3f740c23 sfc: fix error code in efx_devlink_info_running_versions()
- 9c54e76f8d6e net: tls: fix strparser anchor skb leak on offload RX setup failure
- f5c5692a61f7 ice: add dpll peer notification for paired SMA and U.FL pins
- f5f1b59bdb12 dpll: export __dpll_pin_change_ntf() for use under dpll_lock
- 47e53940451c dpll: Add notifier chain for dpll events
- 8bcfd78bbc32 dpll: Allow associating dpll pin with a firmware node
- a723643ee055 ice: fix missing dpll notifications for SW pins
- 3b3aab57e33f ice: fix SMA and U.FL pin state changes affecting paired pin
- 0c56810ce1ba ice: fix missing SMA pin initialization in DPLL subsystem
- c3cad2ae8088 ice: fix infinite recursion in ice_cfg_tx_topo via ice_init_dev_hw
- 1e9185b13ce5 ice: fix NULL pointer dereference in ice_reset_all_vfs()
- b166453d8d01 iavf: add VIRTCHNL_OP_ADD_VLAN to success completion handler
- e469b1ff3319 iavf: wait for PF confirmation before removing VLAN filters
- b0173c36977c iavf: stop removing VLAN filters from PF on interface down
- 033fa40dff77 iavf: rename IAVF_VLAN_IS_NEW to IAVF_VLAN_ADDING
- 864577384d72 page_pool: fix memory-provider leak in page_pool_create_percpu() error path
- c169c5837525 bonding: 3ad: implement proper RCU rules for port->aggregator
- f2edb41645bf bonding: print churn state via netlink
- c1e0b5eccdf0 net: airoha: Do not return err in ndo_stop() callback
- aaad53a55812 net: airoha: fix BQL imbalance in TX path
- d1469eb93af7 drm/xe/gsc: Fix BO leak on error in query_compatibility_version()
- bebce43f34b5 drm/xe/eustall: Fix drm_dev_put called before stream disable in close
- 753b149d5a43 drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl()
- 2d8656c27ff6 drm/xe/debugfs: Correct printing of register whitelist ranges
- 8b85ffe52052 drm/amd/display: Read EDID from VBIOS embedded panel info
- 07822f1d9bdb drm/amd/display: Allow constructing DCE8 link encoder without DDC
- e0f874f209d4 drm/amd/display: Allow constructing DCE6 link encoder without DDC
- 9b84d67ce8c9 drm/amd/display: Allow DCE link encoder without AUX registers
- 69a7cfc66405 futex: Prevent lockup in requeue-PI during signal/ timeout wakeup
- 24c22c644ea5 ALSA: hda/tas2781: Fix incorrect bit update for non-book-zero or book 0 pages >1
- 7e6f7ac79abe ALSA: hda: cs35l56: Fix uninitialized value in cs35l56_hda_read_acpi()
- f837c7b85143 ALSA: hda/conexant: Fix missing error check for jack detection
- 47984e9db9ca netconsole: propagate device name truncation in dev_name_store()
- b19a6804d498 net/sched: sch_cake: annotate data-races in cake_dump_stats() (V)
- cd0401593b2d net/sched: sch_cake: annotate data-races in cake_dump_stats() (III)
- 74a02921c48f bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst()
…