# XanMod Kernel 6.18.47-rt-xanmod1 - Product: XanMod Kernel (https://whatsnew.fyi/product/xanmod) - Vendor: XanMod - Date: 2026-08-27 - Version: 6.18.47-rt-xanmod1 - Original notes: https://gitlab.com/xanmod/linux/-/releases/6.18.47-rt-xanmod1 - Permalink: https://whatsnew.fyi/product/xanmod/releases/6.18.47-rt-xanmod1 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **fixed** — Fix GRO BIG TCP aggregation validation to properly check criteria - **fixed** — Prevent ptp vmclock read-only mappings from becoming writable - **fixed** — Fix private hash use-after-free on final put in futex - **fixed** — Validate Bluetooth firmware segment lengths in hci_aml - **fixed** — Reject HCI_CMD_SYNC with params_len above 255 in Bluetooth MGMT - **fixed** — Zero the sockaddr before returning it in Bluetooth ISO getname - **fixed** — Stop forcing BT_LISTEN after failed BIG sync in Bluetooth ISO - **fixed** — Fix accept list UAF during suspend in Bluetooth hci_sync - **fixed** — Validate LE Set CIG Parameters response in Bluetooth hci_event - **fixed** — Fix LE list UAF on reset in Bluetooth hci_event - **fixed** — Validate initial device info bounds in HID hyperv - **fixed** — Fix use-after-free of inrange_timer on remove in HID uclogic - **fixed** — Fix use-after-free in enable_sensor in HID sensor custom - **fixed** — Fix number/pointer type confusion on long items in HID core - **fixed** — Stop device IO before hid_hw_stop on probe failure in HID nintendo - **fixed** — Register input device after capabilities are set in HID nintendo - **fixed** — Fix out-of-bounds read in joycon_ctlr_read_handler in HID nintendo - **fixed** — Fix might_sleep() warning in futex_pivot_pending() - **fixed** — Fix race on initial mm->futex.phash.ref allocation in futex - **fixed** — Plug private futex exec() race in futex/pi - 782e1ccebdad Linux 6.18.47-rt-xanmod1 - 48fc777af830 Merge branch '6.18' into 6.18-rt - b260538251f0 Linux 6.18.47-xanmod1 - 3cefea4ac89f Merge tag 'v6.18.47' into 6.18 - 7519e95095c9 Linux 6.18.47 - 3ce832e2bd43 net: gro: properly validate BIG TCP aggregation criteria - 5b4f2bec7bea ptp: vmclock: prevent read-only mappings from becoming writable - dba60d26e9dd futex: Avoid private hash use-after-free on final put - e1534d49a7b8 Bluetooth: hci_aml: validate firmware segment lengths - b7d9edcf9fe6 Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 - 1f6d1f2611af Bluetooth: ISO: zero the sockaddr before returning it in getname - 753af97d8d42 Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync - fe93a697a7a9 Bluetooth: hci_sync: Fix accept list UAF during suspend - e3f82e8f2a59 Bluetooth: hci_event: validate LE Set CIG Parameters response - 39a3afb91be3 Bluetooth: hci_event: fix LE list UAF on reset - 608f8fd8c0f7 HID: hyperv: validate initial device info bounds - 849e537160bb HID: uclogic: fix use-after-free of inrange_timer on remove - 8406d4b69d48 HID: sensor: custom: Fix use-after-free in enable_sensor - 1fa1591efd41 HID: core: fix number/pointer type confusion on long items - 5efcd7bbfaae HID: nintendo: stop device IO before hid_hw_stop on probe failure - 268679f50138 HID: nintendo: register input device after capabilities are set - 51cfd1adbe7a HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() - 942b89f7824f futex: Fix might_sleep() warning in futex_pivot_pending() - 86d12b34bafc futex: Fix race on the initial mm->futex.phash.ref allocation - fdf538b2e696 futex/pi: Plug private futex exec() race - 4da67def9efe futex: Sanitize and document task_struct::futex::state transitions - 2b92e5562653 futex/pi: Reject cross-mm private futex owners - f303f6a4c909 Input: atkbd - skip deactivate for HONOR ZQC-P - 936ea65543da Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard - 0ea8f0645401 xfrm: fix sk_dst_cache double-free in xfrm_user_policy() - 39fc615e355b net/ionic: avoid OOB TX partner lookup for hwstamp RXQ - 4529c03c3da8 HID: pidff: fix OOB write when hid->inputs is empty - 9a1d7c5f0d82 HID: core: fix OOB read of field->usage in hid_set_field() - ace7fc4d3879 HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID - 15b60ade825c HID: magicmouse: do not keep a stale msc->input if no input is claimed - 62ec3c591ee8 HID: magicmouse: re-enable multitouch after reset-resume - 02a88f8308ae HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C - b6baab796d11 ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses - 9fe5eebb664e mptcp: pm: fix memory leak from alloc-during-teardown race - 6fa2064761ec mptcp: pm: uniform announced addresses helpers - 714c6d11acea mptcp: pm: rename add_entry structure to add_addr - defc59e74c1b mptcp: pm: use for_each_subflow helper - f31650243c1a nvmet: pci-epf: put CQ ref on create_cq mapping failure - 20be486d1c22 nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work() - 9c95f7e66c62 nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations - 6d27199ebe8c nvmet-tcp: bound SGL data length before allocating command buffers - 8bce9cd08aae nvmet-fc: fix invalid free in LS IOD error path - b26189d28442 nvmet-auth: zero the AUTH_RECEIVE response buffer - 23a475ff24d2 dmaengine: fsl-edma: Add error handling for devm_kasprintf - 364edaedf412 mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf() - 3dc98e5fe82d ipv6: fix use-after-free in ip6_finish_output2() - d9d1a676b033 ipv4: reject undersized MTUs in ip_do_fragment() - f03415030579 drm/xe: Fix DPT allocation paths. - 20892d2923e4 nfc: nci: free destination parameters when closing a connection - 0d4b5cfab689 nfc: nci: fix uninit-value in the RF discover/activated NTF handlers - 2f08dbce3b37 nfc: nci: fix out-of-bounds write in nci_target_auto_activated() - 9620a91f8d64 nfc: nci: add data_len bound checks to activation parameter extracto _[Truncated at 4000 characters — full notes: https://gitlab.com/xanmod/linux/-/releases/6.18.47-rt-xanmod1]_