What’s New

XanMod Kernel 7.1.5-xanmod1

7.1.5-xanmod1
Added 1
  • Add cancel helper for async requests in firmware_loader
Changed 4
  • Update TCP 'bbr' congestion control module to BBRv3
  • Wait for pre-firmware load in usb: atm: ueagle-atm .disconnect()
  • Remove function entry/exit debug messages from usb: atm: ueagle-atm
  • Use dev_dbg() for 'device found' message in usb: atm: ueagle-atm
Fixed 14
  • Prevent UAF caused by non-leader exec() race in posix-cpu-timers
  • Fix Color Manager (3DLUT, Shaper, Blend) in drm/amd/display
  • Fix implicit declaration of brelse() in exfat
  • Validate session type before performing operation in liveupdate
  • Add newly added RTGs to the free pool in xfs growfs
  • Use opener credentials for FSCTL mutations in ksmbd
Removed 1
  • Remove crypto_rng interface from crypto: xilinx-trng
  • 2fb7a627a9c6 Linux 7.1.5-xanmod1
  • 022aeb4a9152 tcp_bbr: v3: update TCP 'bbr' congestion control module to BBRv3 [v7.1.5+]
  • c50e105d5af1 Merge tag 'v7.1.5' into 7.1
  • 8392dcae53e5 Revert "tcp_bbr: v3: update TCP 'bbr' congestion control module to BBRv3"
  • 155b42bec9cb Linux 7.1.5
  • 872380f930c9 Revert "gpib: cb7210: Fix region leak when request_irq fails"
  • ad1cafa1bdaa posix-cpu-timers: Prevent UAF caused by non-leader exec() race
  • 60325bf5e2c1 posix-timers: Expand timer_[re]arm() callbacks with a boolean return value
  • 5638dbfe9cf1 drm/amd/display: Fix Color Manager (3DLUT, Shaper, Blend)
  • 570967e9c615 iomap: consolidate bio submission
  • e2f0122bd566 exfat: fix implicit declaration of brelse()
  • 8e4e884f1bef exfat: add data_start_bytes and exfat_cluster_to_phys_bytes() helper
  • 390f1d72a478 exfat: add balloc parameter to exfat_map_cluster() for iomap support
  • 69b31ef6f853 exfat: replace unsafe macros with static inline functions
  • 9634db561e15 crypto: xilinx-trng - Remove crypto_rng interface
  • 3dc8a46d08a8 liveupdate: validate session type before performing operation
  • ddcdac47e1f2 usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()
  • 53430a3768b5 usb: atm: ueagle-atm: remove function entry/exit debug messages
  • 10cfea5091f0 usb: atm: ueagle-atm: use dev_dbg() for 'device found' message
  • 28f19c97eab4 xfs: add newly added RTGs to the free pool in growfs
  • 615104cd66f8 xfs: factor out a xfs_zone_mark_free helper
  • cfb2c6f71d61 ksmbd: use opener credentials for FSCTL mutations
  • cba4ee1092b3 smb: move compression definitions into common/fscc.h
  • 98185b3025be ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
  • 733e76e74e40 Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()
  • a2a2f68c42e0 Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister
  • 4257f45ee1fd binder: cache secctx size before release zeroes it
  • 3f54f2310de0 binder: Use LIST_HEAD() to initialize on stack list head
  • da9e3be9cf31 ALSA: hda/tas2781: Cancel async firmware request at unbind
  • cd992747d717 firmware_loader: Add cancel helper for async requests
  • ac1328962db1 ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417
  • 53e3dcfa74b3 ALSA: scarlett2: Allow selecting config_set by firmware version
  • b80d60249686 iio: hid-sensor-rotation: Fix stale or zero output when reading raw values
  • 3c0dbfecd859 f2fs: fix listxattr handling of corrupted xattr entries
  • aa807064473a f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs()
  • cf8b5937b7b2 f2fs: fix potential deadlock in f2fs_balance_fs()
  • c81e2af41de6 device property: initialize the remaining fields of fwnode_handle in fwnode_init()
  • db20589d7b24 samples/damon/mtier: fail early if address range parameters are invalid
  • 810c9ae71dad mm/damon/core: trace esz at first setup
  • 314bd592085c bpf: Reject negative const offsets for buffer pointers
  • a419421281fb mmc: sdhci-esdhc-imx: fix resume error handling
  • 89b63cd133fe mmc: sdhci-esdhc-imx: make non-fatal errors non-blocking in suspend
  • 6355749aebf6 mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend
  • 9bf4ee05a110 mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt
  • bb72b2398c05 mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore
  • 24300decd8bd mmc: sdhci-esdhc-imx: restore DLL override for DDR modes on resume
  • 48188934d5d2 mmc: sdhci-esdhc-imx: remove unnecessary mmc_card_wake_sdio_irq check for tuning save/restore
  • 657e0acce5b8 mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe() method
  • f59d0244d90b mmc: mmc_test: Fix __counted_by handling after kzalloc_flex() conversion
  • 0e93010b52bb mmc: block: fix RPMB device unregister ordering
  • cb2031f8b226 mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout
  • 791fc00d116e mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout
  • 1773c6e292b0 mtd: rawnand: fsl_ifc: return errors for failed page reads
  • c2e1d3392956 mmc: vub300: defer reset until cmd_mutex is unlocked
  • 09e044192a42 mtd: mchp23k256: use SPI match data for chip caps
  • 9fc23fc52fc9 mtd: onenand: samsung: report DMA completion timeouts
  • 0e65079d28e5 mtd: virt-concat: free duplicate generated name
  • 6126e12bf8c8 wifi: mwifiex: fix permanently busy scans after multiple roam iterations
  • 625fc704b19c wifi: mac80211: validate extension-frame layout before RX
  • 179d9be632d8 wifi: mac80211: free ack status frame on TX header build failure
  • 2b1589fd9a07 wifi: ieee80211: validate MLE common info length
  • 3b0505e43da8 wifi: cfg80211: validate EHT MLE before MLD ID read
  • d5c234774a82 powerpc/uaccess: correct check for CONFIG_PPC_E500 in mask_user_address()
  • 4efa313b1592 powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()
  • d826d3e04c5b reset: sunxi: fix memory region leak on ioremap failure
  • 68176d47421f reset: imx7: Correct polarity of MIPI CSI resets on i.MX8MQ
  • ad1e14710b36 ipvs: reload ip header after head reallocation
  • 905d7a363ade ipvs: fix more places with wrong ipv6 transport offsets
  • 47f0c7d856c6 memstick: ms_block: reject a card that reports too many blocks
  • 492cf7778a55 macsec: fix promiscuity refcount leak in macsec_dev_open()
  • 3cc37687227b llc: fix SAP refcount leak when creating incoming sockets
  • 5c1e8f56d84c crypto: aes - Fix conditions for selecting MAC dependencies
  • f1ca750c0510 Bluetooth: btrtl: validate firmware patch bounds
  • 1b41cbe05b18 net: openvswitch: reject oversized nested action attrs
  • b7f5bd59ed1c regulator: ltc3676: Fix incorrect IRQSTAT bit offsets
  • c8874e338d51 arch/riscv: vdso: remove CFI landing pad from rt_sigreturn
  • 73a7bdf06dbd riscv: vdso: Do not use LTO for the vDSO
  • 185bb156c427 wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
  • a7584f261e64 wifi: mac80211: fix memory leak in ieee80211_register_hw()
  • 564e3fce81eb wifi: mwifiex: fix roaming to different channel in host_mlme mode
  • 56994852d704 wifi: rt2x00: avoid full teardown before work setup in probe
  • 6eb4cf2fa899 net/mlx5: free mlx5_st_idx_data on final dealloc
  • 0b24b11ecda4 powerpc/pseries: fix memory leak on krealloc failure in papr_init
  • cc5c99b606ff mmc: sdhci-esdhc-imx: restore pinctrl before restoring ios timing on resume
  • 90dfffc360df selftests/landlock: Fix screwed up pointers in the scoped_signal_test
  • 19a1785250c7 selftests/landlock: Skip scoped_signal subtest with MSG_OOB if not available
  • 4907f4c2d98b pmdomain: imx: Fix i.MX8MP VC8000E power up sequence
  • 331ee3bc4edf pmdomain: imx: Fix i.MX8MP power notifier
  • 36c2d7728540 pmdomain: mediatek: Fix possible nullptr KP in HWV cleanup/on-check
  • 4ba6d7166750 pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI
  • c17f06d8a085 cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed
  • f45c8d3818da selftests/rseq: Fix a building error for riscv arch
  • 28673209eeea s390/mm: Fix type mismatch in get_align_mask().
  • 83fe36f81200 s390/diag: Add missing array_index_nospec() call to memtop_get_page_count()
  • dd0160a08423 tracing/osnoise: Call synchronize_rcu() when unregistering
  • d5b2752a17ef riscv: Prevent NULL pointer dereference in machine_kexec_prepare()
  • 648d4317326e drbd: reject data replies with an out-of-range payload size
  • f713d7a7e0f2 ata: libata-core: Allow capacity transition to zero for locked drives
  • f723ea50a96d ata: libata-core: Skip HPA resize for locked drives
  • f7628eea9212 fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
  • fa5c7c313018 fs/resctrl: Free mon_data structures on rdt_get_tree() failure
  • 901a489d89ee cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable()
  • c3f200efb454 arm64: smp: Fix hot-unplug tearing by forcing unregistration
  • f50d87f97527 amdkfd: properly free secondary context id
  • 109241d98804 net: macb: drop in-flight Tx SKBs on close
  • 94fe0ab01b48 dibs: loopback: validate offset and size in move_data()
  • c39087ad0b97 macsec: don't read an unset MAC header in macsec_encrypt()
  • 6335ab62d5fc ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
  • e5d0bb887166 ipvs: use parsed transport offset in SCTP state lookup
  • 21a537606fe3 llc: fix SAP refcount leak in llc_ui_autobind()
  • 680d9dcbf428 selftests: net: make busywait timeout clock portable
  • 23d917acd9c9 octeontx2-pf: fix SQB pointer leak on init failure
  • d8b5b66388a5 mac802154: remove interfaces with RCU list deletion
  • ae5347f3db17 s390/monwriter: Reject buffer reuse with different data length
  • b321a046d771 irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure
  • 23afc3786acf mm/compaction: handle free_pages_prepare() properly in compaction_free()
  • 91b4d76dd07f riscv: probes: save original sp in rethook trampoline
  • b770fcfcdced hwmon: (asus_atk0110) Check package count before accessing element
  • 3034e5d67ea6 net: ipa: fix SMEM state handle leaks in SMP2P init
  • 77f0023f22f6 net: wwan: iosm: bound device offsets in the MUX downlink decoder
  • d43efd1b5d97 ata: libata-core: Reject an invalid concurrent positioning ranges count
  • 7ba60286ed14 ata: pata_pxa: Fix DMA channel leak on probe error
  • 299739909c48 ata: libata-core: Add NOLPM quirk for PNY CS900 1TB SSD
  • ae0265f0a95a net/mlx5: HWS, fix matcher leak on resize target setup failure
  • e3d325c0bdb7 orangefs: keep the readdir entry size 64-bit in fill_from_part()
  • aac98ec816b0 tracing/probes: Fix double addition of offset for @+FOFFSET
  • 4a97d08d4ace hwmon: (max1619) add missing 'select REGMAP' to Kconfig
  • 6ee183d89261 fhandle: reject detached mounts in capable_wrt_mount()
  • 2dcebbd1ad2e net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked
  • fffeb2ab5eeb net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked
  • b99e890e6b32 net: lan743x: Initialize eth_syslock spinlock before use
  • ca096be8de31 fsl/fman: Free init resources on KeyGen failure in fman_init()
  • 7ee43ec8e677 hwmon: (occ) unregister sysfs devices outside occ lock
  • 8519e89c7f4d ACPI: TAD: Check AC wake capability before enabling wakeup
  • 4140c516473a net: liquidio: fix BAR resource leak on PF number failure
  • 1f11a29a3c80 hwmon: (w83793) remove vrm sysfs file on probe failure
  • 8a604fe15d03 hwmon: (w83627hf) remove VID sysfs files on error and remove
  • a3020a389cb1 rtc: mpfs: fix counter upload completion condition
  • a36b9528b071 fscrypt: Replace mk_users keyring with simple list
  • 03f1725f91e8 rtc: renesas-rtca3: Fix PIE clear polling condition in alarm setup error path
  • 356077547b1a bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()
  • 0fd23994ec8c ipmi: fix refcount leak in i_ipmi_request()
  • a338ce41bc93 espintcp: use sk_msg_free_partial to fix partial send
  • 7be349d4fcc5 ipmi: Fix user refcount underflow in event delivery
  • e483da960892 LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()
  • 7bcce38cbebd LoongArch: Fix nr passing in set_direct_map_valid_noflush()
  • c97d44a5bdf9 pwm: rzg2l-gpt: Fix period_ticks type from u32 to u64
  • c270eaa919f6 riscv: vdso: Always declare vdso_start symbols
  • fe08be92f2b6 KVM: arm64: Fix propagation of TLBI level in kvm_pgtable_stage2_relax_perms()
  • d1d73a3a37b7 netfilter: nfnetlink_cthelper: cap to maximum number of expectation per master on updates
  • 835a2f9d9f17 drm/xe/userptr: Stub notifier_lock helpers when DRM_GPUSVM=n
  • 1b31e160430c ACPICA: Define acpi_ut_safe_strncpy() as strscpy_pad() alias
  • 227dd2eeab0f net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants
  • fcc621f5b25d platform/x86/amd/pmc: Avoid logging "(null)" for DMI values
  • 744da2443f40 netfilter: nfnetlink_cthelper: cap to maximum number of expectation per master
  • 9a7f7b55d7d0 ksmbd: fix stack buffer overflow in multichannel session-key copy
  • 59da37fee81a octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF
  • 9f8e7f59b0c2 gve: fix header buffer corruption with header-split and HW-GRO
  • d8ce67fa6a5e ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit
  • 7e3630fbb6aa ieee802154: ca8210: fix cas_ctl leak on spi_async failure
  • 2953ec261bcf ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation
  • 638324805895 ieee802154: admin-gate legacy LLSEC dump operations
  • d0c880c9f405 octeontx2-af: Free BPID bitmap on setup failure
  • d4bcc202a353 net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink
  • c38c8b0db3c6 net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
  • d49edcc65e0a net: ipip: require CAP_NET_ADMIN in the device netns for changelink
  • 88b33ee458a6 net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
  • f97e93ebf2f9 net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
  • 11f68ebc6891 net: ena: clean up XDP TX queues when regular TX setup fails
  • 6fed707239c4 selftests: net: fix file owner for broadcast_ether_dst test
  • f7f45ceb855d net/sched: act_ct: preserve tc_skb_cb across defragmentation
  • 91850f582783 net: ixp4xx_hss: fix duplicate HDLC netdev allocation
  • 0c0a8c782148 net: wwan: t7xx: destroy DMA pool on CLDMA late init failure
  • b3763f7e22ec net: ethernet: ti: icssg: guard PA stat lookups
  • 99ae3248b33d net: sit: require CAP_NET_ADMIN in the device netns for changelink
  • f4170f45c251 gpios: palmas: add .get_direction() op
  • a60a40c9ba30 gpio: mt7621: avoid corruption of shared interrupt trigger state
  • b90f24527723 gpio-f7188x: Add support for NCT6126D version B
  • 422a0567cd1b gpio: mt7621: be sure IRQ domain is created before exposing GPIO chips
  • 628c63f96f45 gpio: tegra: do not call pinctrl for GPIO direction
  • e187f6fbc8d6 gpio: mt7621: more robust management of IRQ domain teardown
  • bc650dd5ce64 net: mana: Sync page pool RX frags for CPU
  • 282c5214ca4e net: mana: Validate the packet length reported by the NIC
  • 631d53102da9 cpu: hotplug: Bound hotplug states sysfs output
  • 9f7dc355f62c cpu: hotplug: Preserve per instance callback errors
  • f563358661ea selftests/ftrace: Drop invalid top-level local in test_ownership
  • 571e1f10b599 posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()
  • 83f9fb561c1c locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
  • bcf7968cb97c wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
  • 05b24f68f78f tracing/user_events: Fix use-after-free in user_event_mm_dup()
  • 088873af1359 net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete
  • 618cf6b13950 mmc: vub300: fix use-after-free on probe failure
  • f4cf878dcc4f Input: ims-pcu - fix type confusion in CDC union descriptor parsing
  • 025955847e15 Input: ims-pcu - fix race condition in reset_device sysfs callback
  • bbbe31486cf2 Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing
  • f97bfc1a0766 Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging
  • e555f00621bd Input: ims-pcu - fix logic error in packet reset
  • 47a9889a9325 Input: ims-pcu - fix firmware leak in async update
  • 40693fcc88bc Input: ims-pcu - fix DMA mapping violation in line setup
  • f3c63aecca90 Input: ims-pcu - add response length checks
  • cbfa059dfb48 Input: ims-pcu - validate control endpoint type
  • 8c3095c43291 Input: ims-pcu - release data interface on disconnect
  • 73e6687be0c1 Input: ims-pcu - only expose sysfs attributes on control interface
  • bf0b58ba489d Input: ims-pcu - fix use-after-free and double-free in disconnect
  • 7d330a1d6633 fs/resctrl: Fix use-after-free during unmount
  • 94cbfed19124 scsi: elx: efct: Fix I/O leak on unsupported additional CDB
  • 747eaead2db2 scsi: elx: efct: Fix refcount leak in efct_hw_io_abort()
  • ef2ee18fec92 scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
  • 555a89846ed8 scsi: target: Bound PR-OUT TransportID parsing to the received buffer
  • 1e97c404e449 scsi: xen: scsiback: Free unsubmitted command instead of double-putting it
  • 1357fb32d42a scsi: xen: scsiback: Free the command tag on the TMR submit-failure path
  • 3cbabbf1722e scsi: sg: Report request-table problems when any status is set
  • 0ce5a37f7ddf scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()
  • 782e1bf48672 scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path
  • 6920e62be4c9 accel/ivpu: Reject firmware log with size smaller than header
  • 216e43d93dd4 accel/amdxdna: Use caller client for debug BO sync
  • fff6509d976f accel/amdxdna: reject user command submission without a command BO
  • f7d08603c87b accel/amdxdna: reject command submission on devices without a submit op
  • 5da885c39baa accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap()
  • 15ecfdf0ef6f dma-buf: dma-fence: Fix potential NULL pointer dereference
  • 562d5e6f9b99 dma-fence: use correct callback in dma_fence_timeline_name()
  • e2d9a2ea178a dma-fence: Make dma_fence_dedup_array() robust against 0-count input
  • 752e214b2c6f dm-verity: make error counter atomic
  • e96df7fdbec9 dm-verity: increase sprintf buffer size
  • 81f41d989a32 dm-verity: fix a possible NULL pointer dereference
  • 414650265267 dm-verity: avoid double increment of &use_bh_wq_enabled
  • f7990c2b0f08 dm-verity: fix buffer overflow in FEC calculation
  • 829476c06496 dm-integrity: don't increment hash_offset twice
  • 3d1afaa07462 dm-integrity: fix a bug if the bio is out of limits
  • 8f0af8493009 dm-integrity: fix leaking uninitialized kernel memory
  • 7d8ed7cb844d dm_early_create: fix freeing used table on dm_resume failure
  • f00105be6a59 dm: avoid leaking the caller's thread keyring via the table device file
  • 750b23d4935b dm-stats: fix merge accounting
  • f3441b3bf519 dm-stats: fix dm_jiffies_to_msec64
  • 0cbe13fe5403 dm-pcache: reject option groups without values
  • 79feb87ab239 dm-log: fix a bitset_size overflow on 32bit machines
  • df50c24c6447 dm-ioctl: fix a possible overflow in list_version_get_info
  • 53477ce5ef90 dm-bufio: fix wrong count calculation in dm_bufio_issue_discard
  • bafe3e720cda dm era: fix out-of-bounds memory access for non-zero start sector
  • 9f1a0d27586c dm thin metadata: fix metadata snapshot consistency on commit failure
  • 0562bd39d361 dm thin metadata: fix superblock refcount leak on snapshot shadow failure
  • 17f113e7b622 net: sparx5: unregister blocking notifier on init failure
  • d4cc255f35d5 block: fix IORING_URING_CMD_REISSUE flags check in blkdev_uring_cmd
  • c0f10f43ffa5 block: fix race in blk_time_get_ns() returning 0
  • 02f8ad12545c block: remove redundant GD_NEED_PART_SCAN in add_disk_final()
  • fe1d9121b4b7 selftests/bpf: Cover negative buffer pointer offsets
  • 28ce7bcf8a29 bpf: Add missing access_ok call to copy_user_syms
  • 43f0005f81b8 bpf,fork: wipe ->bpf_storage before bailouts that access it
  • 5a55f9aecc08 bpf: Reset register bounds before narrowing retval range in check_mem_access()
  • 0639ea767fe0 io_uring/bpf-ops: reject re-registration of an already-bound ops
  • 04d23061bbf1 can: bcm: add missing device refcount for CAN filter removal
  • 59bfddea6415 can: bcm: validate frame length in bcm_rx_setup() for RTR replies
  • b6317022b685 can: bcm: track a single source interface for ANYDEV timeout/throttle ops
  • b31d0933509c can: bcm: fix stale rx/tx ops after device removal
  • c312b750bb5a can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()
  • df47f07cdc80 can: bcm: fix CAN frame rx/tx statistics
  • 337f966c0066 can: bcm: extend bcm_tx_lock usage for data and timer updates
  • 30f7bb922cb7 can: bcm: add missing rcu list annotations and operations
  • fc9f5ee1b073 can: bcm: add locking when updating filter and timer values
  • b9c6ac6fb4e0 can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure
  • ce2d4b121fb7 can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF
  • 4f1fdf1a1c31 can: isotp: serialize TX state transitions under so->rx_lock
  • e442b62ba5a7 can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER
  • b8278ff60518 can: isotp: use unconditional synchronize_rcu() in isotp_release()
  • 5832c55b3c82 can: esd_usb: kill anchored URBs before freeing netdevs
  • 046380f3e111 ovl: use linked upper dentry in copy-up tmpfile
  • fd750b694f1f netdev-genl: report NAPI thread PID in the caller's pid namespace
  • fcef60ed5f71 nvmet: fix refcount leak in nvmet_sq_create()
  • 98bcdfa61915 nvmet-rdma: handle inline data with a nonzero offset
  • bc111698b46e nvmet-auth: reject short AUTH_RECEIVE buffers
  • b7d9aaedf024 nvme-apple: Prevent shared tags across queues on Apple A11
  • a192b6c149c6 NFS: Charge unstable writes by request size, not folio size
  • bbd6b2ea966c sctp: validate STALE_COOKIE cause length before reading staleness
  • 077a7bc1c32d spi: uniphier: Fix completion initialization order before devm_request_irq()
  • 40dee2d3e999 spi: imx: reconfigure for PIO when DMA cannot be started
  • 91376c61a5fd time: Fix off-by-one in compat settimeofday() usec validation
  • 947b773caaa5 tpm: Make the TPM character devices non-seekable
  • 98fa6e42fd51 tpm: fix event_size output in tpm1_binary_bios_measurements_show
  • 3ba2b2ef7d6a xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink
  • b4e9dcf4143e xfrm: use compat translator only for u64 alignment mismatch
  • a8a7e6a9ff8a xfrm: nat_keepalive: avoid double free on send error
  • 6883269a3236 xen/gntdev: fix error handling in ioctl
  • 2510434307a2 ufs: core: tracing: Do not dereference pointers in TP_printk()
  • f48d3ae9d320 tcp: Decrement tcp_md5_needed static branch
  • da48b9bf1eb9 tcp: defer md5sig_info kfree past RCU grace period in tcp_connect
  • b7ef06d010c9 ice: fix ice_init_link() error return preventing probe
  • 35176f104612 i2c: spacemit: fix spurious IRQ handling returning IRQ_HANDLED
  • fb267770bf82 i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource()
  • bbc08be46f00 i2c: mediatek: fix WRRD for SoCs without auto_restart option
  • 56ddfc18ea8f i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ)
  • 60ed00d46616 i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
  • c9a0f2bff2cb hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig
  • b9f07a4ec6e3 hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig
  • a0d8e415ebf3 ksmbd: fix integer overflow in set_file_allocation_info()
  • c32f565f3291 smb: client: use kvzalloc() for megabyte buffer in simple fallocate
  • 0bf6482919b9 pkey: Move keytype check from pkey api to handler
  • 301bb780d1b9 platform/x86/amd/pmc: Don't log during intermediate wakeups
  • d53314ae31fd platform/x86/amd/pmc: Add delay_suspend module parameter
  • 675592e86e81 platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops
  • 3002e2dda621 platform/x86/amd/pmc: Check for intermediate wakeup in function
  • 2a42f651cce9 platform/x86: ISST: Restore SST-PP control to all domains
  • 14812174d720 platform/x86: hp-wmi: Add support for Omen 16-ap0xxx (8E35)
  • 4676e81d55ab platform/x86: hp-wmi: Add support for Omen 16-ap0xxx (8D26)
  • b351e082711d platform/x86: dell-laptop: fix missing cleanups in init error path
  • 2137f2154290 platform/x86/intel/tpmi: use cleanup helpers in mem_write()
  • 07ae600bd353 dmaengine: sh: rz-dmac: Move interrupt request after everything is set up
  • 044f7b3252d4 dmaengine: dw-edma-pcie: Reject devices without driver data
  • 070b92cbb82a dmaengine: sh: rz-dmac: Fix incorrect NULL check for list_first_entry()
  • 1553ca96e9df dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK
  • 6e37e9e230c7 dmaengine: tegra: Fix burst size calculation
  • 7d3ce3bd23c0 sunrpc: fix uninitialized xprt_create_args structure
  • 493333f16792 tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt
  • 4bb3e1bc142d tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat()
  • 711cbcb464d2 tpm: restore timeout for key creation commands
  • e5be5d452d5f irqchip/crossbar: Use correct index in crossbar_domain_free()
  • c267911b4226 taskstats: retain dead thread stats in TGID queries
  • f4599793240d mtd: maps: vmu-flash: fix NULL pointer dereference in initialization
  • 57740658042d openrisc: Fix jump_label smp syncing
  • a145b47e22fd mtd: rawnand: Pause continuous reads at block boundaries
  • 007e28b2916d mtd: spi-nor: spansion: use die erase for multi-die devices only
  • 12d4d6922115 mtd: spi-nor: swp: Improve locking user experience
  • 614aa0491c7a s390/pkey: Check length in pkey_pckmo handler implementation
  • 7e7e03848c91 s390/pkey: Check length in PKEY_VERIFYPROTK ioctl
  • 3da8eaf5469e fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header()
  • fe6b606fbf0c net: thunderbolt: Fix frags[] overflow by bounding frame_count
  • 4f6542b14288 bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path
  • e0578493c950 bus: mhi: host: pci_generic: Fix the physical function check
  • f3df5386e3bb fpga: dfl: add bounds check in dfh_get_param_size()
  • 3bfeb436d4be ocfs2: reject non-inline dinodes with i_size and zero i_clusters
  • 60ceecda550e ocfs2: reject dinodes whose i_rdev disagrees with the file type
  • b858f2d57cfc ocfs2: reject dinodes with non-canonical i_mode type
  • 63921f790234 ocfs2: add journal NULL check in ocfs2_checkpoint_inode()
  • 858aa4965ffa ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec
  • 253ed993e0b3 ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits
  • 4d1953d3aeb4 ocfs2: avoid moving extents to occupied clusters
  • 8f575fc17360 mtd: rawnand: fix condition in 'nand_select_target()'
  • 823886a1b089 net/9p: fix infinite loop in p9_client_rpc on fatal signal
  • 3c44f6c62f65 mtd: rawnand: pl353: fix probe resource allocation
  • 20869525a283 ocfs2: use kzalloc for quota recovery bitmap allocation
  • 455519f6b70f mtd: maps: vmu-flash: fix fault in unaligned fixup
  • 9f457beb601d openrisc: Add full instruction cache invalidate functions
  • c8f8e61332ba scsi: sas: Skip opt_sectors when DMA reports no real optimization hint
  • 9fefab759f59 kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES
  • d52d4c9ac716 scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished()
  • 8c1b23d83008 power: supply: bq257xx: Fix VSYSMIN clamping logic
  • 8faccac11e13 9p: skip nlink update in cacheless mode to fix WARN_ON
  • bdcdfc246465 mtd: slram: remove failed entries from the device list
  • 3afd3929fbc7 kcov: use WRITE_ONCE() for selftest mode stores
  • b91e27bce37c mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE
  • 1712a7fa1339 powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors
  • 8e7709aaed66 fs/proc: fix KPF_KSM reported for all anonymous pages
  • b09d5ad00338 proc: only bump parent nlink when registering directories
  • 319caaca072a fs/proc/task_mmu: do not warn on seeing non-migration pmd entry
  • 5ac8f1c56ba1 fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry()
  • 18b8a9700610 fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()
  • 6b7f774b8882 fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race
  • 6b6b5d7c2c95 mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error
  • ee59df7a886a mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs()
  • 837f619f1d98 mm/damon/core: always put unsuccessfully committed target pids
  • 36e4843fe39e riscv: cacheinfo: Fix node reference leak in populate_cache_leaves
  • 2611f7521c6c mm/huge_memory: preserve pmd_swp_uffd_wp on device-private PMD downgrade
  • a1dd41d00c57 mips: sched: Fix CPUMASK_OFFSTACK memory corruption
  • 4d46e07b23d8 selftests/landlock: Test SCOPE_SIGNAL on the SIGIO/fowner pgid path
  • e8631b883338 power: supply: charger-manager: fix refcount leak in is_full_charged()
  • 04916f7dc6d3 landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path
  • 7d7f72cb21a8 ntfs: fix hole runlist memory leak in insert range error path
  • b397b1238a21 ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock()
  • 8f313e92522a ntfs: make system files immutable to prevent corruption
  • 5a5f877c5df7 ntfs: avoid self-deadlock during inode eviction
  • 83f396d881c4 ntfs: sanitize MFT references returned from ntfs_lookup_inode_by_name()
  • d5379035355c ntfs: fail attrlist updates when the superblock is inactive
  • b3d09502b80d ntfs: fix mrec_lock ABBA deadlock in rename
  • a93980141253 ntfs3: fix out-of-bounds read in decompress_lznt
  • 1758a564b6eb ntfs3: validate split-point offset in indx_insert_into_buffer
  • d240f5f9d036 ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head
  • d313416280d4 ntfs3: cap RESTART_TABLE free-chain walker at rt->used
  • 36feda687afe fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}
  • fdf50c788e09 fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
  • 32b9f8733feb fs/ntfs3: validate lcns_follow in log_replay conversion
  • a89c66674283 fs/ntfs3: bound attr_off in UpdateResidentValue against data_off
  • 49c86dae0c0c fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass
  • 554700c65d39 fs/ntfs3: bound DeleteIndexEntryAllocation memmove length
  • 007977325021 fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename
  • b54c9beb90e5 ntfs: reject non-resident records for resident-only attributes
  • bfb01dd319b6 ntfs: validate resident index root values on lookup
  • 18fe978d265b ntfs: validate resident volume name values on lookup
  • 82510cb5c658 ntfs: do not replace volume name after lookup errors
  • 7fb64788812d ntfs: detect mapping-pairs LCN accumulator overflow
  • e2b95d3adb55 ntfs: validate index entries on reading
  • 40ee64e633e5 ntfs: avoid heap allocation for free-cluster readahead state
  • a9cafa8c780f ntfs: only alias volume $UpCase to default on exact match
  • d7773b7af1d2 ntfs: reinit search context before volume information lookup
  • f831ab09d521 ntfs: skip extent mft records in writeback to prevent deadlock
  • b06730c6af58 ntfs: centalize $INDEX_ROOT header validation
  • 0527a81e85ee ntfs: update index root allocated size before shrink
  • aca3d383a23c ntfs: free volume-wide resources on fill_super failure
  • 34a49b3e94a5 ntfs: validate index block header more strictly
  • ceb49c372501 ntfs: not change 0-byte $DATA attribute to non-resident
  • d9d9925de1d8 ntfs: add bounds check before accessing EA entries
  • e4c36dfac57a ntfs: validate attribute values on lookup
  • 353a79fb76bf ntfs: Add WQ_PERCPU to alloc_workqueue users
  • bfe835e535fe ntfs: fix off-by-one in mapping pairs decoding bounds checks
  • 7d702aee1589 ntfs: fix incorrect size of symbolic link
  • 38d444271604 ntfs: grow index root value before reparent header update
  • 57094929cf09 mm/damon/core: make charge_addr_from aware of end-address exclusivity
  • 2f9e3ec17c3d mm/memory_hotplug: fix incorrect altmap passing in error path
  • b785f2bd9496 mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch
  • fc3f0eef426f power: supply: max17042: fix OF node reference imbalance
  • b56a5cbf8f1f power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak
  • b03e62112c9d mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages
  • 3ae86630b94f MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf()
  • 35521e4ec762 MIPS: ip22-gio: fix device reference leak in probe
  • b04bbb89ca3a MIPS: ip22-gio: fix kfree() of static object
  • a018c9b8805c MIPS: ip22-gio: fix gio device memory leak
  • 25bec992181d mm/sparse-vmemmap: fix vmemmap accounting underflow
  • f80fafe24f72 remoteproc: xlnx: Check remote core state
  • e5b1aaa74118 remoteproc: qcom: Fix leak when custom dump_segments addition fails
  • 98414b42530a SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
  • 3a5c55a19cad lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure
  • 3f2dc01b9cb5 lockd: Plug nlm_file leak when nlm_do_fopen() fails
  • 31ba490c02d4 sunrpc: harden rq_procinfo lifecycle to prevent double-free
  • a4f878e8ecd7 sunrpc: wait for in-flight TLS handshake callback when cancel loses race
  • 083e9c2ec7e8 sunrpc: pin svc_xprt across the asynchronous TLS handshake callback
  • c49df5f1e193 pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP
  • ba59b96d8d21 nvdimm/btt: Free arena sub-allocations on discover_arenas() error path
  • 7e49684d90fa nvdimm/btt: Free arenas on btt_init() error paths
  • a58fc10adf50 jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit()
  • fc5eb0962a5e cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size
  • 0ec5c7f03ecf backlight: ktd2801: Enable BL_CORE_SUSPENDRESUME
  • 089ea1e2faf4 mfd: tps6586x: Fix OF node refcount
  • da743704c647 cifs: invalidate cfid on unlink/rename/rmdir
  • 6222b4436865 batman-adv: tt: prevent TVLV OOB check overflow
  • 7d1a877670bc batman-adv: mcast: avoid OOB read of num_dests header
  • 777a88256d6f batman-adv: frag: fix primary_if leak on failed linearization
  • 5a82c5580988 batman-adv: clean untagged VLAN on netdev registration failure
  • 080478388175 batman-adv: frag: free unfragmentable packet
  • ae8355b24abe batman-adv: fix VLAN priority offset
  • aba1cf21954e batman-adv: tt: avoid request storms during pending request
  • 64fd0b0dbb52 batman-adv: dat: fix tie-break for candidate selection
  • dbeb4145d977 batman-adv: ensure minimal ethernet header on TX
  • 4407ff3af469 batman-adv: dat: ensure accessible eth_hdr proto field
  • f4fb97ecf677 batman-adv: bla: reacquire gw address after skb realloc
  • 059a70e1d12d batman-adv: dat: acquire ARP hw source only after skb realloc
  • 9a7b72487981 batman-adv: access unicast_ttvn skb->data only after skb realloc
  • b031fc97e199 batman-adv: retrieve ethhdr after potential skb realloc on RX
  • 916dac5f2944 batman-adv: gw: acquire ethernet header only after skb realloc
  • f79dff8c721b s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()
  • cabcfbc069d8 cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF()
  • a18afd69408c cpufreq: schedutil: Fix uncleared need_freq_update on the .adjust_perf() path
  • fb3b76b5ad2e perf/x86/amd/lbr: Fix kernel address leakage
  • 2e706be56f41 perf/x86/amd/brs: Fix kernel address leakage
  • 64193ed819db x86/boot: Reject too long acpi_rsdp= values
  • 4dad7e870c7e x86/boot: Validate console=uart8250 baud rate to fix early boot hang
  • e5158ff53fdf x86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN"
  • 8a2a0b911cd6 x86/video: Only fall back to vga_default_device() without screen info
  • e8adac69d1bd tools/power/x86/intel-speed-select: Harden daemon pidfile open
  • 2ff8156fd500 mfd: sm501: Fix reference leak on failed device registration
  • 263ccdd627ca leds: uleds: Fix potential buffer overread
  • c9a691350e28 selinux: fix incorrect execmem checks on overlayfs
  • 37d642b37ccd selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()
  • 646ebbc5f2ff selinux: check connect-related permissions on TCP Fast Open
  • fe11d6ce19b2 soc: fsl: qe: panic on ioremap() failure in qe_reset()
  • 9b3325f5a9fb soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy
  • 419d7d930649 gpu/buddy: bail out of try_harder when alignment cannot be honoured
  • 8559b1501f77 gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path
  • 392d033fd372 netfilter: flowtable: use correct direction to set up tunnel route
  • 4ac981a8b7ce netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
  • ec88fa71c820 netfilter: xt_nat: reject unsupported target families
  • 4301ae9ce3d4 netfilter: ecache: fix inverted time_after() check
  • b7a1626c28ba netfilter: xt_physdev: masks are not c-strings
  • 6ff07ac5405b netfilter: nf_conncount: fix zone comparison in tuple dedup
  • 0880c4ed122d netfilter: flowtable: support IPIP tunnel with direct xmit
  • ecb78fbb03d3 netfilter: flowtable: use dst in this direction when pushing IPIP header
  • 00bdce2fda7e netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag
  • 0e76e3e886cc netfilter: nf_nat_sip: reload possible stale data pointer
  • e74f9680e1b6 netfilter: nft_set_pipapo: don't leak bad clone into future transaction
  • b843a96252f6 netfilter: nf_conntrack_sip: validate skb_dst() before accessing it
  • f68305267ebd netfilter: nft_fib: reject fib expression on the netdev egress hook
  • 47b3af24de5f netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst
  • 5b2d4f001001 netfilter: xt_cluster: reject template conntracks in hash match
  • 29e06c8f616c netfilter: nfnl_cthelper: apply per-class values when updating policies
  • eeef3b81f449 netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
  • 214af790e3a3 ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback
  • 03009465312c ASoC: mediatek: mt8183: Release reserved memory on cleanup
  • 80506fcac597 ASoC: mediatek: mt8183: Check runtime resume during probe
  • 4c9df23e121f ASoC: mediatek: mt8192: Release reserved memory on cleanup
  • f6e424835cc0 ASoC: mediatek: mt8192: Check runtime resume during probe
  • 2a591bf6fd41 ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control
  • f4933e1d11b9 ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
  • 6ed7787c43ec ASoC: SOF: topology: fix memory leak in snd_sof_load_topology
  • 2efd9797331a fbdev: tridentfb: fix potential memory leak in trident_pci_probe()
  • ed3b3eb21244 fbdev: nvidia: fix potential memory leak in nvidiafb_probe()
  • 7b96ce9f8e47 fbdev: vesafb: fix memory leak in vesafb_probe()
  • dae8f6ddc35c fbdev: carminefb: fix potential memory leak in alloc_carmine_fb()
  • 2fd16a94bea5 fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe()
  • aa387a3e5180 fbdev: uvesafb: fix potential memory leak in uvesafb_probe()
  • 56964e803915 fbdev: s3fb: fix potential memory leak in s3_pci_probe()
  • 2ede8fa70823 fbdev: i740fb: fix potential memory leak in i740fb_probe()
  • 1b1b43342fbf fbdev: radeon: fix potential memory leak in radeonfb_pci_register()
  • 5276e3f75ddb fbdev: efifb: fix memory leak in efifb_probe()
  • f6a1ac55e6ca fbdev: sm712: Fix operator precedence in big_swap macro
  • 9a94b8553185 fbdev: hecubafb: fix potential memory leak in hecubafb_probe()
  • e818c397548c fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe()
  • a889978ec44f fbdev: metronomefb: fix potential memory leak in metronomefb_probe()
  • bc00e0e376ee KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory
  • 0a5dd8cf4d58 KVM: arm64: nv: Re-translate VNCR before injecting abort
  • 53804b683957 KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN
  • d35defbdfcb1 KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR
  • dd3b237eb778 KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
  • 29227821e232 KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions
  • 7deadbc5dab5 KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2
  • a805ab1914ea KVM: arm64: Ensure level is always initialized when relaxing perms
  • 34d8d7242c52 KVM: arm64: account pKVM reclaim against the VM mm
  • 0cbae0e296d2 KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers
  • 2c87a087c206 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state
  • d5560b6569cd KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails
  • 32bdca80aa81 KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
  • d6b5aba65e99 KVM: TDX: Reject concurrent change to CPUID entry count
  • d2f9df3b615c KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs
  • 124a3769c437 KVM: s390: pci: Fix handling of AIF enable without AISB
  • 7d066368f72e KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal" checks
  • b1a89d12d35a KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling
  • 0658b09cba7f KVM: arm64: vgic: Check the interrupt is still ours before migrating it
  • adce12bb0e0d KVM: s390: pci: Fix GISC refcount leak on AIF enable failure
  • a2e7bbc91cf6 powerpc/pseries/Kconfig: Enable CONFIG_VPA_PMU to be used with KVM
  • ce587046baac KVM: s390: Fix unlikely race in try_get_locked_pte()
  • a4a19941ccb2 KVM: s390: Initialize KVM_S390_GET_CMMA_BITS memory
  • 5fc9690db3bf KVM: s390: vsie: Use mmu cache to allocate rmap
  • eeeb9bc71831 KVM: s390: Silence potential warnings in _gmap_crstep_xchg_atomic()
  • 0c3d4ca328e6 KVM: s390: vsie: Add missing radix_tree_preload() in _gaccess_shadow_fault()
  • bcc6b684fcf6 KVM: s390: vsie: Fix allocation of struct vsie_rmap
  • ac3366245221 LoongArch: KVM: Return full old CSR value from kvm_emu_xchg_csr()
  • 31e99851ee99 LoongArch: KVM: Fix FPU register width with user access API
  • 5c827b66a626 LoongArch: KVM: Check the return values for put_user()
  • d4574547e04a LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt()
  • 8b3e188d19e4 LoongArch: KVM: Validate irqchip index in irqfd routing
  • 81f5b85a5fb0 ARM: dts: stm32: stm32mp15x-mecio1-io: Move expander gpio-line-names to board files
  • 7b5e3c15eee1 ARM: dts: stm32: stm32mp15x-mecio1-io: Fix expander gpio line typo
  • d735c64a1462 ARM: dts: stm32: stm32mp15x-mecio1-io: Move gpio-line-names to board files
  • e61543c0aa5a arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers
  • fc58177cca3b ARM: dts: stm32: stm32mp15x-mecio1-io: Fix GPIO names typo
  • 73e14c8bf53c arm64: dts: imx8ulp-evk: Correct Type-C int GPIO flags
  • 520de5e79dda ARM: dts: stm32: stm32mp15x-mecio1-io: Enable internal ADC reference
  • 0623e082e99a arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc
  • ba13b141ddb5 ARM: dts: stm32: stm32mp15x-mecio1-io: Move divergent mecio1 ADC channels to board files
  • d09c701a531c ARM: dts: stm32: stm32mp15x-mecio1-io: Fix ADC sampling times
  • 12cabe872172 arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Ringneck
  • b5ab9ada87e8 arm64: dts: qcom: sdm630: describe adsp_mem region properly
  • 17b7ab1d26b3 ARM: dts: imx6ul-var-som: fix warning for non-existent dc-supply property
  • 7cc51bb053f6 arm64: dts: renesas: ironhide: Describe inline ECC carveouts
  • 7b71b69719eb arm64: dts: s32g3: Fix SWT8 watchdog address
  • 9b6a94b187f4 arm64: fpsimd: Fix type mismatch in sve_{save,load}_state()
  • b69ad768cd4a net: ife: require ETH_HLEN to be pullable in ife_decode()
  • 463d417a905d octeontx2-vf: clear stale mailbox IRQ state before request_irq()
  • 1ffc164c4744 octeontx2-pf: clear stale mailbox IRQ state before request_irq()
  • 806b7b6edc84 net: atm: reject out-of-range traffic classes in QoS validation
  • 7f72c285f6d3 net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
  • 6acbbe54215d tipc: restrict socket queue dumps in enqueue tracepoints
  • 201b60c4d155 ASoC: SOF: topology: validate vendor array size before parsing
  • 92f90917413b ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get
  • 312c7d2ebe69 ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
  • c29f5b449889 ASoC: SOF: ipc4-control: Validate notification payload size
  • 038406abde0d ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put
  • 00335df9da20 VDUSE: avoid leaking information to userspace
  • 8062ff9d366c vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter
  • 8adebf07b46d mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()
  • cab468c3c03f mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()
  • 708df5274cee idpf: add padding to PTP virtchnl structures
  • 21710f27d55e ring-buffer: Allow sparse CPU masks in ring_buffer_desc()
  • 57e566db78fc tracing/remotes: Fix struct_len in trace_remote_alloc_buffer()
  • 81a7b7ddb07e tracing/remotes: Fix leak in trace_remote_alloc_buffer() error path
  • c25212f274a5 drm/imagination: make pvr_fw_trace_init_mask_ops static
  • 1a638c55f2db smb: client: fix overflow in passthrough ioctl bounds check
  • bf126747e7bf drm/xe: free madvise VMA array on L2 flush failure
  • c69369057b30 drm/xe: remove duplicate <kunit/test-bug.h> include
  • 3cf83432e056 octeontx2-af: fix VF bringup affecting PF promiscuous state
  • 2ae146bcfcc1 ethtool: rss: Fix hfunc and input_xfrm parsing on big endian
  • 7b2fbdafc6de net/mlx5: Fix L3 tunnel entropy refcount leak
  • ddd5ab921fdd selftests/net: fix EVP_MD_CTX leak in tcp_mmap
  • 7d84acf641af drm/fb-helper: Only consider active CRTCs for vblank sync
  • 153d1b8b5bc3 regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK
  • f0eac9c3c371 smb: client: fix busy dentry warning on unmount after DIO
  • b69ea153d30c dm era: fix NULL pointer dereference in metadata_open()
  • d49f6d098ed4 SUNRPC: pin upper rpc_clnt across the TLS connect_worker
  • 9359aac4999e SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED
  • c37abc99bb3d cifs: validate DFS referral string offsets
  • b0640acace25 s390/zcrypt: Remove the empty file
  • 92185d6f7819 ipvs: ensure inner headers in ICMP errors are in headroom
  • f0f35153de83 ipvs: fix PMTU for GUE/GRE tunnel ICMP errors
  • c2ee845e292c ipvs: use parsed transport offset in TCP state lookup
  • 568720055fbd ipvs: pass parsed transport offset to state handlers
  • ef0c7d4b04a0 netfilter: nft_lookup: fix catchall element handling with inverted lookups
  • 95128dc74425 ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer()
  • 1fcabcba272d ipv4: igmp: annotate data-races around timer-related fields
  • 16e5b2dbea49 ipv4: igmp: annotate data-races around im->users
  • 0458ba1cda83 ipv6: mcast: Fix potential UAF in MLD delayed work
  • 8d4394ffa405 ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
  • d73e4d790db6 gpio: mvebu: free generic chips on unbind
  • 46d0fd8535ed perf/x86/amd/core: Avoid enabling BRS from the SVM reload path
  • 543c66cea0e2 octeontx2-pf: check DMAC extraction support before filtering
  • f1e7807df5bf net/sched: cake: reject overhead values that underflow length
  • e3d1ca7882a5 net: mdio: select REGMAP_MMIO instead of depending on it
  • 3861bae3ffe4 selftests: gpio: add gpio-cdev-uaf to .gitignore
  • 5d65dade4d84 drm/v3d: Reject invalid indirect BO handle in indirect CSD setup
  • 91e8109ecffb accel/amdxdna: Fix potential amdxdna_umap lifetime race
  • 6cb18e712feb tracing: Make tracepoint_printk static as not exported
  • 170c008d3f49 drm: Guard DRM_CLIENT_CAP_PLANE_COLOR_PIPELINE
  • 82202fc724f4 gpio: dwapb: Defer clock gating until noirq
  • 8aede22b6a69 net: usb: lan78xx: disable VLAN filter in promiscuous mode
  • 81acef3a247f net/liquidio: drop cached VF pci_dev LUT
  • 40824fc26ad3 net: rnpgbe: fix mailbox endianness and remove pointer casts
  • ebc295ce3436 net/tls: Consume empty data records in tls_sw_read_sock()
  • bea20225c67f accel/amdxdna: Fix VMA access race
  • cf10c506fdbe accel/amdxdna: Use unsigned long for nr_pages in amdxdna_hmm_register()
  • 2d8eeb0578ae accel/amdxdna: Prevent PM resume deadlock in hwctx_sync_debug_bo()
  • 3a63a11897c7 ring-buffer: Fix event length with forced 8-byte alignment
  • d0a2b0c81f11 Bluetooth: L2CAP: fix tx ident leak for commands without a response
  • a8e169d30877 Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
  • 058d0d087a27 Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length
  • 990e65eb9387 Bluetooth: ISO: fix malformed ISO_END/CONT handling
  • 1f9375f55ead Bluetooth: btintel_pcie: Refactor FLR to use device_reprobe()
  • c36895aa1122 Bluetooth: btintel_pcie: Separate coredump work from RX work
  • fb6fc74cc10f Bluetooth: btintel_pcie: Add support for smart trigger dump
  • 4ff5778e8ee3 Bluetooth: btintel_pcie: Support Product level reset
  • a50da115b588 Bluetooth: sco: Fix a race condition in sco_sock_timeout()
  • dbd935a9e056 Bluetooth: MGMT: Fix adv monitor add failure cleanup
  • 32c48c7f6cc8 Bluetooth: 6lowpan: hold L2CAP conn across debugfs control
  • feb3fc2c38ed Bluetooth: 6lowpan: avoid untracked enable work
  • b601c031d4fa drm/i915/ltphy: Fix SSC Enablement bit in PORT_CLOCK_CTL
  • 0b98a503ed1e gpio: shared: make the voting mechanism adaptable
  • 8d12d1fede47 smb: client: preserve leading slash for POSIX absolute symlink targets
  • a1f2ada2e4d3 ksmbd: fix multichannel binding and enforce channel limit
  • 5a632f2f207e amt: fix size calculation in amt_get_size()
  • ce5aa8084329 net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
  • 8e49cd891bda net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload
  • 231a8a4b76cb net: qualcomm: rmnet: validate MAP frame length before ingress parsing
  • 982d6d6bc059 qede: fix off-by-one in BD ring consumption on build_skb failure
  • 952928564cc5 net: microchip: vcap: fix races on the shared Super VCAP block
  • 815515ec68f5 net/mlx5e: Fix publication race for priv->channel_stats[]
  • f5677797b094 net/mlx5e: Fix HV VHCA stats agent registration race
  • abc4c56427f1 net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation
  • 98fc2deffcf1 drm/bridge: analogix_dp: Fix PE/VS value shift mismatch during link training
  • 5a95aa0198af net/mlx5e: TC, skip peer flow cleanup when LAG seq is unavailable
  • 4d720c6c60e1 net/mlx5: LAG, MPESW, Fix missing complete() on devcom error
  • 40cc06bf7147 net/mlx5: LAG, Fix off-by-one in single-FDB error rollback
  • fd2ef924a56f net/mlx5: LAG, extend shared FDB API with group_id filter
  • d14f2dbf727c net/mlx5: LAG, prepare for SD device integration
  • 5092213b9a31 net/mlx5: LAG, replace peer count check with direct peer lookup
  • 3b8b364f97f4 net/mlx5: LAG, factor out shared FDB code into dedicated file
  • 7ac37a167cc6 net/mlx5: Lag, avoid LAG and representor lock cycles
  • db9e44e0ed63 net/mlx5: E-Switch, add representor lifecycle lock
  • 25d4c0948300 net/mlx5: Lag: refactor representor reload handling
  • 6f2cb20d8e28 platform/x86: bitland-mifs-wmi: Fix NULL pointer dereference during suspend/resume
  • 230173cc6105 netfilter: xt_connmark: reject invalid shift parameters
  • 94427ca35943 netfilter: nft_set_rbtree: get command skips end element with open interval
  • d5e39e5eb6b3 netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
  • 905a927b2e6f netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()
  • 00d034fe8230 netfilter: xt_u32: reject invalid shift counts
  • f618cbe9b24c gue: validate REMCSUM private option length
  • ea866cab12db net: usb: net1080: validate packet_len before pad-byte access in rx_fixup
  • 9d343a4889e5 arm64/sysreg: Fix BWE field encoding in ID_AA64DFR2_EL1
  • 79b33d9f1d9c selftests/hid: Cover hid_bpf_get_data() size overflow
  • b56f874e49e6 selftests/hid: Load only requested struct_ops maps
  • f81bc5a709dc HID: bpf: Fix hid_bpf_get_data() range check
  • 3dd3e43f17cd ntfs: avoid stale runlist element dereference in fallocate
  • 6706e332151b iio: dac: mcp47feb02: Fix passing uninitialized vref1_uV for no Vref1 case
  • 9a1479b05bd9 arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range()
  • 67a863ceb348 arm64: Avoid eager DVMSync reclaim batches with C1-Pro SME erratum
  • f7e8117e42b2 HID: core: Fix OOB read in hid_get_report for numbered reports
  • ef649703dce0 HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait()
  • 9a2e36963a3f ntfs: avoid stale runlist element dereference in MFT writeback
  • be47c0472506 netfs: Fix barriering when walking subrequest list
  • 9da2e4275e64 ata: libata-scsi: limit simulated SCSI command copy to response length
  • 35cb43b721c0 ata: sata_gemini: unwind clocks on IDE pinctrl errors
  • 3a303f985c6b cifs: Fix missing credit release on failure in cifs_issue_read()
  • 1acddd3e22dd uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline
  • fa8fd23e3a87 x86/uprobes: Keep shadow stack in sync for emulated CALLs
  • 2b6b3f98d0e9 drm/xe/pt: prevent invalid cursor access for purged BOs
  • 5ff2212f0e07 drm/xe: fix NPD in bo_meminfo()
  • a4208d8032ab drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays
  • 23ee91355e31 drm/xe/hw_engine: Fix double-free of managed BO in error path
  • f1a1909f36b7 drm/xe/userptr: Drop bogus static from finish in force_invalidate
  • ab9ea5c943c7 drm/xe/userptr: Hold notifier_lock for write on inject test path
  • 159f9aa8d2e0 drm/imagination: Fix returned size for DRM_IOCTL_PVR_DEV_QUERY
  • d94b9922b2ae drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()
  • 1a4421c7a561 netfs: Fix folio state after ENOMEM whilst under writeback iteration
  • 89df9c158a25 netfs: Fix writeback error handling
  • 0348e3fa0dfb netfs: Fix writethrough to use collection offload
  • 68fb8a93a34b cachefiles: Fix file burial to take lock when unsetting S_KERNEL_FILE
  • 1188a9846fad netfs: Fix netfs_create_write_req() to handle async cache object creation
  • 7f7780abb4c0 iomap: guard io_size EOF trim against concurrent truncate underflow
  • 3c181e6ff1f4 ovl: fix comment about locking order
  • 26757dac1517 cachefiles: Fix double unlock in nomem_d_alloc error path
  • 8a29e60e2176 minix: avoid overflow in bitmap block count calculation
  • 27ddd3442fc6 iomap: release pages on atomic dio size mismatch
  • 89ec425b454e afs: Fix unchecked-length string display in debug statement
  • d0c8ad418b47 afs: Fix the volume AFS_VOLUME_RM_TREE is set on
  • c9a0b9e5f3d4 afs: Fix premature cell exposure through /afs
  • e94f92fd56c5 afs: Fix lack of locking around modifications of net->cells_dyn_ino
  • 91d8f8e5fd34 afs: Fix vllist leak
  • 9cabf1c86948 afs: Fix leak of ungot volume
  • 1bdbc50e2d41 afs: Use scoped_seqlock_read() rather than manually doing seqlock stuff
  • e3e59ff22a0d afs: Fix missing NULL pointer check in afs_break_some_callbacks()
  • f14dd036fad3 afs: Fix callback service message parsers to pass through -EAGAIN
  • ebfd13c0367a afs: Fix reinitialisation of the inode, in particular ->lock_work
  • 654a546c34f3 afs: Fix misplaced inc of net->cells_outstanding
  • 552d3c0f184a afs: Fix bulk lookup malfunction due to change in dir_emit() API
  • ca9f19505077 afs: Remove erroneous seq |= 1 in volume lookup loop
  • 84e4b9232a32 afs: use kvfree() to free memory allocated by kvcalloc()
  • 6d52ff4c866e afs: Fix directory inode initialisation order
  • 9d6b0f6d437e afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints
  • 462eada939f2 afs: Fix double netfs initialisation in afs_root_iget()
  • bdcd80ff1293 afs: Fix error code in afs_extract_vl_addrs()
  • 47e434da476b fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid
  • fc9332533a58 net/sched: hhf: clear heavy-hitter state on reset
  • d25cdea6226c net/sched: dualpi2: clear stale classification on filter miss
  • d1297a9e2fd6 xen/pvcalls: bound backend response req_id before indexing rsp[]
  • feba85c0eeda pinctrl: meson: restore non-sleeping GPIO access
  • 2ef42bd9a8b7 gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe
  • ed98719be413 ksmbd: fix use-after-free of fp->owner.name in durable handle owner check
  • 15a9e9b8f7f5 ksmbd: reject undersized DACLs before parsing ACEs
  • b0933dede95d net/sched: act_bpf: use rcu_dereference_bh() to read the filter
  • 24e63c47668a selftests: drv-net: tso: don't touch dangerous feature bits
  • 9717091371d7 cxgb4: Fix decode strings dump for T6 adapters
  • 13741bad74d4 virtio_net: disable cb when NAPI is busy-polled
  • c3e5cac47519 sctp: fix addr_wq_timer race in sctp_free_addr_wq()
  • ac39628cb3ef spi: rzv2h-rspi: Fix DMA transfer error handling for signal interruption
  • 9ed0dca2aa05 irqchip/ts4800: Fix missing chained handler cleanup on remove
  • 5459f4f32a8e irqchip/gic-v3-its: Fix OF node reference leak
  • 57e1f2cd6a0e tracing/probes: Make the $ prefix mandatory for comm access
  • d655cca1c6e6 tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry()
  • f4461db8eb8e tracing: eprobe: read the complete FILTER_PTR_STRING pointer
  • 10a33029e1cf tracing/events: Fix to check the simple_tsk_fn creation
  • 8a662d8c05e2 tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg
  • 9acf6f34eb48 tracing/eprobes: Allow use of BTF names to dereference pointers
  • 2c88ad0d06c6 drm/panthor: Interrupt group start/resumption if group_bind_locked() fails
  • 893ed1a7c837 drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced
  • 50556bfe1d6c drm/panthor: Fix panthor_pwr_unplug()
  • 1352cd192e5b drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick()
  • 361adc5343e9 drm/panthor: Fix theoretical IOMEM access in suspended state
  • 1c942c3c5179 drm/panthor: Store IRQ register base iomem pointer in panthor_irq
  • 34eb9945a075 drm/panthor: Split register definitions by components
  • 85c6f80499e6 drm/panthor: Pass an iomem pointer to GPU register access helpers
  • 053522ba6158 drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom()
  • 752a08cfeeea drm/panthor: Keep the reset work disabled until everything is initialized
  • 2946aa6c97ac drm/panthor: Always use the IRQ-safe variant when acquiring the fence lock
  • 8a277a20258d gpio: shared-proxy: always serialize with a sleeping mutex
  • 40cbfa3a28e0 bridge: stp: Fix a potential use-after-free when deleting a bridge
  • b26aa9d99353 net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF
  • b637d6b72661 net: gianfar: dispose irq mappings on probe failure and device removal
  • 14b4cb78c332 net: libwx: fix VMDQ mask for 1-queue mode
  • 2381bf3f484e net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy
  • 3ef79fa3860e usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()
  • 110ccbd28c94 ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump
  • 21f304c2aae4 eth: fbnic: don't cache shinfo across skb realloc
  • fb8a5afe6f1f hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero
  • b0ff6b6ae9c5 hwmon: (pmbus) Fix passing events to regulator core
  • 93b96e723bdc hwmon: adm1275: Prevent reading uninitialized stack
  • 65e7e2b8d71b accel/amdxdna: Fix iommu domain lifetime race during device removal
  • 5bd0d4764039 hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid()
  • 492d0c8f78d4 ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280
  • f3ed74540244 MIPS: mm: Add check for highmem before removing memory block
  • 3aca736e177f MIPS: DEC: Ensure RTC platform device deregistration upon failure
  • 062bcbf8d1f1 sctp: add INIT verification after cookie unpacking
  • f7776052bb23 sctp: fix SCTP_RESET_STREAMS stream list length limit
  • d22829101ab6 net: enetc: check the number of BDs needed for xdp_frame
  • 6d46ab395803 qede: fix out-of-bounds check for cqe->len_list[]
  • c9961336aa5f seg6: validate SRH length before reading fixed fields
  • e1fc4b00b96d net: pse-pd: scope pse_control regulator handle to kref lifetime
  • 151db2b54744 gpio: htc-egpio: use managed gpiochip registration
  • 537e75aeb9cc gpio: mvebu: fail probe if gpiochip registration fails
  • d8df91756890 bpf: Fix insn_aux_data leak on verifier err_free_env path
  • 1c53d16b174d bpf: Mask pseudo pointer values in verifier logs
  • 5c907c11615f riscv: Fix 32-bit call_on_irq_stack() frame pointer ABI
  • d1a22906727b ACPI: RIMT: Only defer the IOMMU configuration in init stage
  • c637ec6a4592 spi: sh-msiof: abort transfers when reset times out
  • b2fa801be46d tracing: probes: fix typo in a log message
  • 3ab06151ffcb ALSA: FCP: Fix NULL pointer dereference in interface lookup
  • b4c34415b82b net: hns3: differentiate autoneg default values between copper and fiber
  • 783dcef78cb0 net: hns3: fix permanent link down deadlock after reset
  • 99f6a07add50 net: hns3: refactor MAC autoneg and speed configuration
  • ac04c2c833dd net: hns3: unify copper port ksettings configuration path
  • 9715ea1ceab7 selftests: tls: size splice_short pipe by page size
  • 522d1d950b9e tipc: avoid busy looping in tipc_exit_net()
  • 1c8393eefa3c tipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy()
  • 46d8d5b02f89 tipc: Store struct sock in struct udp_bearer.
  • 80e9adfed05d udp_tunnel: Pass struct sock to setup_udp_tunnel_sock().
  • ea0eb61029e0 udp_tunnel: Pass struct sock to udp_tunnel_sock_release().
  • cd37bcb67f90 net: enetc: fix potential divide-by-zero when num_vsi is zero
  • 2542ce01d811 dt-bindings: net: renesas,ether: Drop example "ethernet-phy-ieee802.3-c22" fallback
  • 54292b167466 net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync
  • c5fafece300c ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count
  • 0ddb9dcabf0b LoongArch: BPF: Fix off-by-one error in tail call
  • 09068613dd0d LoongArch: BPF: Fix outdated tail call comments
  • ee79d03aafb5 LoongArch: Move struct kimage forward declaration before use
  • fe0669928f27 net: stmmac: dwmac-spacemit: Fix wrong irq definition
  • a77abd7a3490 net: stmmac: dwmac-spacemit: Fix wrong phy interface definition
  • c3e27e4ee524 net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove
  • bc49e8746584 net: sungem: fix probe error cleanup
  • fb42560afec5 tools: ynl: build archives with $(AR)
  • e2087447f562 geneve: validate inner network offset in geneve_gro_complete()
  • 49c2e7c0a699 geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
  • 5bdb33ff6e58 net: mvneta: re-enable percpu interrupt on resume
  • 0fd234bc1264 octeontx2-af: fix CGX debugfs RVU AF PCI reference leaks
  • b1f6381acf9d octeontx2-af: Validate NIX maximum LFs correctly
  • ba933c5f3568 net: phy: realtek: Clear MDIO_AN_10GBT_CTRL_ADV10G bit
  • 7d47925c2c64 net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0
  • cf52622fbc27 net: dsa: mxl862xx: fix use-after-free of DSA ports in crc_err_work
  • 245c6c8a2958 net: dsa: mxl862xx: avoid unaligned 16-bit access in api_wrap
  • c21f7ee511ae net: dsa: realtek: fix memory leak in rtl8366rb_setup_led()
  • a427cfa41796 rtc: cmos: unregister HPET IRQ handler on probe failure
  • 5904fd94f919 rtc: ds1307: Fix off-by-one issue with wday for rx8130
  • cddbfbc71085 smb/client: preserve errors from smb2_set_sparse()
  • 8bbe4dd79645 ACPI: processor_idle: Mark LPI enter functions as __cpuidle
  • 42d4fc933280 ACPICA: Unbreak tools build after switching over to strscpy_pad()
  • 156af6606f36 thermal: testing: zone: Flush work items during cleanup
  • fda07c8e4b54 s390/mm: Fix handling of _PAGE_UNUSED pte bit
  • ca2dbee8fea6 eth: fbnic: fix ordering of heartbeat vs ownership
  • 7a368c754a96 ipv6: fix missing notification for ignore_routes_with_linkdown
  • b91ac71fc2a2 ipv6: fix state corruption during proxy_ndp sysctl restart
  • 764ac02cbd3b ipv6: fix error handling in disable_policy sysctl
  • 420e895fb41d ipv6: fix error handling in forwarding sysctl
  • a39ff02a241c ipv6: fix error handling in ignore_routes_with_linkdown sysctl
  • e28bada56f4f ipv6: fix error handling in disable_ipv6 sysctl
  • 94f55994e19e sctp: fix err_chunk memory leaks in INIT handling
  • e28aedab9488 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
  • 19eec11f3ab5 net: lwtunnel: Drop skb metadata before LWT encapsulation
  • cc27e4514e6e net: usb: lan78xx: restore VLAN and hash filters after link up
  • 4bd2e5dbe623 veth: fix NAPI leak in XDP enable error path
  • 20d4a9dea55b net: ti: icssg: Fix XSK zero copy TX during application wakeup
  • 09efce96c909 net: dsa: sja1105: round up PTP perout pin duration
  • a3d0c8b437ef net: do not acquire dev->tx_global_lock in netdev_watchdog_up()
  • 89c103d702b2 net, bpf: check master for NULL in xdp_master_redirect()
  • 752b781b0c0a Docs/driver-api/uio-howto: document mmap_prepare callback
  • c19faa40b37d alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs
  • 257b55dc3d18 alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
  • 75d7a27c506e NTB: epf: Fix doorbell bitmask and IRQ vector handling
  • bfe11cd91ab0 NTB: epf: Report 0-based doorbell vector via ntb_db_event()
  • 583a4a19eefc NTB: epf: Make db_valid_mask cover only real doorbell bits
  • 9787c2d17111 PCI: endpoint: pci-epf-vntb: Exclude reserved slots from db_valid_mask
  • 9e105f6a14fb ASoC: rt5575: Use __le32 for SPI burst write address
  • 33387bf9bb61 ASoC: SDCA: Validate written enum value in ge_put_enum_double()
  • 0ae6e70edc33 cpuidle: Allow exit latency to exceed target residency
  • c239f2d879ab netfilter: nf_conntrack_helper: cap maximum number of expectation at helper registration
  • e3b7789be80d netfilter: nft_ct: expectation timeouts are passed in milliseconds
  • f32e644fe365 netfilter: nf_conntrack_expect: run expectation eviction with no helper
  • 3401ab813d27 netfilter: nf_conntrack_expect: store master_tuple in expectation
  • 7ec786f4230c netfilter: nf_conntrack_expect: use conntrack GC to reap expectations
  • 743209358ff8 netfilter: conntrack: check NULL when retrieving ct extension
  • ae568b6f16e0 netfilter: nf_conntrack_pptp: move GRE specific cleanup to GRE tracker
  • a1572284b14e netfilter: nf_conntrack_helper: dynamically allocate struct nf_conntrack_helper
  • 40c14ce49963 gpio: davinci: fix IRQ domain leak on devm_kzalloc failure
  • c129b0185e70 netfilter: nft_compat: ebtables emulation must reject non-bridge targets
  • 2f71ca368ffd netfilter: nft_synproxy: stop bypassing the priv->info snapshot
  • 025a41e76b51 netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()
  • be52572c6d55 netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
  • eb14aba91163 netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()
  • 1bb3b6a5c3c5 bpf: Disable xfrm_decode_session hook attachment
  • d684b72dfbd3 md/raid5: avoid R5_Overlap races while breaking stripe batches
  • 4465211d195d md/raid5: use stripe state snapshot in break_stripe_batch_list()
  • a668fa160247 ipv4: fib: Don't ignore error route in local/main tables.
  • c5bd84c6cd77 eth: bnxt: improve the timing of stats
  • 6428634f7a0b ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().
  • 1c89da3baa2b ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE
  • 03ae998ae623 selftests/bpf: Cover small conntrack opts error writes
  • dd74c8020384 bpf: Guard conntrack opts error writes
  • bb3e624808c9 rtc: msc313: fix NULL deref in shared IRQ handler at probe
  • 5f2cfe30af5a e1000e: Reconfigure PLL clock gate timeout and re-enable K1 on Meteor Lake
  • 939756efe505 i40e: Fix i40e_debug() to use struct i40e_hw argument
  • 40c68e35e700 ice: dpll: fix memory leak in ice_dpll_init_info error paths
  • 17c0a9db05e3 ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info
  • 19ec35b79913 rtc: isl1208: Balance enable_irq_wake() with disable_irq_wake() on cleanup
  • 6c70914ab629 ice: call netif_keep_dst() once when entering switchdev mode
  • 4f13a0a479b5 ice: fix AQ error code comparison in ice_set_pauseparam()
  • b1fc5bafbc5f ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs()
  • 0f9278b22cda bpf: Preserve pointer spill metadata during half-slot cleanup
  • 233170ad54d3 PCI: endpoint: pci-epf-vntb: Report 0-based doorbell vector via ntb_db_event()
  • 93a85a6aca19 PCI: endpoint: pci-epf-vntb: Defer pci_epc_raise_irq() out of atomic context
  • 528cfbcc47bb PCI: endpoint: pci-epf-vntb: Document legacy MSI doorbell offset
  • a58543f1e1cc PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0
  • 750dd7546de3 PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0
  • 937f77a79636 ASoC: cs530x: Fix expected MCLK rates for CS5302/4/8
  • 50456f445fee erofs: handle 48-bit blocks_hi for compressed inodes
  • 4137e1ecec9c drm/edid: fix OOB read in drm_parse_tiled_block()
  • 6558811274c8 gpiolib: initialize return value in gpiochip_set_multiple()
  • 7dba66caf98e power: sequencing: fix ABBA deadlock in pwrseq_device_unregister()
  • b584f107ab90 bpf: Fix effective prog array index with BPF_F_PREORDER
  • d977b2aff9f7 bpf: Fix BPF_PROG_ASSOC_STRUCT_OPS last field check
  • 8b996c555575 bpf: zero-initialize the fib lookup flow struct
  • 7faf89ed5b4c bpftool: Fix vmlinux BTF leak in cgroup commands
  • 89cf4d0c71a2 bpf: Fix partial copy of non-linear test_run output
  • db8f1dcf5950 bpf: Fix stack slot index in nospec checks
  • 9242939dd6d9 rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231
  • fc4f78e8f034 rtc: abx80x: fix the RTC_VL_CLR clearing all status flags
  • 84ac7a0f9562 dpaa2-switch: do not accept VLAN uppers while bridged
  • 5a3b2ee1e96d ipv6: ioam: fix type confusion of dst_entry
  • 63d1c23764de ipv6: ndisc: fix NULL deref in accept_untracked_na()
  • f4d7d8fdcc59 net: airoha: Fix skb->priority underflow in airoha_dev_select_queue()
  • 0c3d8fc87e10 net/sched: act_ct: fix nf_connlabels leak on two error paths
  • 44068b6863fb net: emac: Fix NULL pointer dereference in emac_probe
  • d0ab67f7e7cf octeontx2-pf: mcs: Fix mcs resources free on PF shutdown
  • e7f1311e7ef3 octeontx2-pf: Clear stats of all resources when freeing resources
  • a56fd8449de8 octeontx2-af: mcs: Fix unsupported secy stats read
  • e129d1a4c2ba octeontx2-af: npc: cn20k: fix NPC defrag
  • c36cecf9903f net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths
  • 7ce31739fe88 net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone
  • b65289e1c3f3 tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
  • 31d486562062 net: marvell: prestera: initialize err in prestera_port_sfp_bind
  • 8c439591f703 selftests/mm: fix exclusive_cow test fork() handling
  • 214ba4596887 selftests/mm: remove hardcoded THP sizing assumptions in hmm tests
  • 679642fa56d5 selftests/mm: allow PUD-level entries in compound testcase of hmm tests
  • 0481f4bad161 selftests/mm: clarify alternate unmapping in compaction_test
  • 2a018e29ac5f selftests/mm: move hwpoison setup into run_test() and silence modprobe output for memory-failure category
  • 835ef922f3ba selftests/mm: run_vmtests.sh: free memory if available memory is low
  • de72caed5077 selftests/mm: skip uffd-stress test when nr_pages_per_cpu is zero
  • e186a9ac7af4 selftests/mm: ensure destination is hugetlb-backed in hugetlb-mremap
  • e0f39f7671a9 selftest/mm: register existing mapping with userfaultfd in hugetlb-mremap
  • 7c0ba2376d40 selftests/mm: free dynamically allocated PMD-sized buffers in split_huge_page_test
  • 5b136718617a selftests/mm: size tmpfs according to PMD page size in split_huge_page_test
  • aef0f2059a97 selftests/mm: fix cgroup task placement and drop memory.current checks in hugetlb_reparenting_test.sh
  • 4a1e9beaff98 selftests/mm: fix hugetlb pathname construction in hugetlb_reparenting_test.sh
  • 95f64f30431e selftests/mm: restore default nr_hugepages value via exit trap in hugetlb_reparenting_test.sh
  • 65a7bc39d4a2 selftests/mm: fix hugetlb pathname construction in charge_reserved_hugetlb.sh
  • 83d9d5f63cc9 selftests/mm: restore default nr_hugepages value via exit trap in charge_reserved_hugetlb.sh
  • 008ceffd4404 alloc_tag: fix use-after-free in /proc/allocinfo after module unload
  • 810779623104 irqchip/crossbar: Fix parent domain resource leak
  • 74b19383580d mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx()
  • c041d2be785f tpm_crb: Check ACPI_COMPANION() against NULL during probe
  • 4dce8bf588a8 netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak
  • a259780ddf1d netfilter: nf_reject: skip iphdr options when looking for icmp header
  • a75f7745dc8f netfilter: nft_flow_offload: zero device address for non-ether case
  • c3167c9c6433 netfilter: nft_meta_bridge: add validate callback for get operations
  • 94daa48ea7b6 netfilter: nft_payload: reject offsets exceeding 65535 bytes
  • c78bd5195a59 netfilter: ipset: make sure gc is properly stopped
  • 93a775fd67f3 netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
  • 7efd8a1c96c7 netfilter: ipset: Don't use test_bit() in lockless RCU readers in bitmap types
  • 3219d74e4536 netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types
  • c6e635429584 md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry
  • 937c3e44ecaf md/raid1: honor REQ_NOWAIT when waiting for behind writes
  • d1324b41dabd md/raid10: fix writes_pending and barrier reference leaks on discard failures
  • f94031c94eae md/raid10: fix writes_pending leak on write request failures
  • bffbbfcbd939 md/raid1: fix writes_pending and barrier reference leaks on write failures
  • 4fe0635fe604 mac802154: Prevent overwrite return code in mac802154_perform_association()
  • f14802465f59 ieee802154: fix kernel-infoleak in dgram_recvmsg()
  • 4c3717546878 ieee802154: Remove WARN_ON() in cfg802154_pernet_exit()
  • 6fcba77571c5 ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns()
  • 8a4eae78287a ieee802154: Restore initial state on failed device_rename() in cfg802154_switch_netns()
  • 315e1efc3f16 ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone()
  • 8dcf676092ff ACPI: resource: Amend kernel-doc style
  • 172e690bab7a thermal: intel: Fix dangling resources on thermal_throttle_online() failure
  • 02f1d4b40eb4 arm64/hw_breakpoint: reject unaligned watchpoints that would truncate BAS
  • fde42e9f5c59 arm64: static_call: include asm/insns.h
  • 7f8d816a9aa2 netfilter: flowtable: fix and simplify IP6IP6 tunnel handling
  • 68286258698e ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints
  • d9ac4239157e eth: fbnic: take netif_addr_lock_bh() around rx mode address programming
  • 41b70eff0392 selftests: vlan_bridge_binding: Fix flaky operational state check
  • 0b17f320893a netconsole: don't drop the last byte of a full-sized message
  • 825de39f0c35 flow_dissector: check device type before reading ETH_ADDRS
  • 9acbcb89190a net: macb: add TX stall timeout callback to recover from lost TSTART write
  • 9f7cd1e26d2f net: airoha: fix foe_check_time allocation size
  • f5adcb9245ae devlink: Fix parent ref leak on tc-bw failure
  • 21f7e96cf164 devlink: Fix parent ref leak in devl_rate_node_create()
  • dbb6321c2977 dpaa2-switch: fix VLAN upper check not rejecting bridge join
  • e6b8463b7d79 virtio-net: fix len check in receive_big()
  • d654af91739a spi: rpc-if: Use correct device for hardware reinitialization on resume
  • aa80fca32cf7 PCI: iproc: Restore .map_irq() for the platform bus driver
  • ec6fb1ecada8 ALSA: usb-audio: qcom: clear opened when stream enable fails
  • a22356d1f731 ALSA: usb-audio: qcom: reject stream disable with no active interface
  • f09a245f33e5 sctp: hold socket lock when dumping endpoints in sctp_diag
  • 794a0d8bdbb3 net: psample: fix info leak in PSAMPLE_ATTR_DATA
  • e19d38d397d4 octeontx2-af: npc: Log successful MCAM drop-on-non-hit install at debug level
  • 452ec5058ea4 octeontx2-pf: Fix leak of SQ timestamp buffer on teardown
  • 043ed6924c63 selftests/ftrace: Fix trace_marker_raw test on 64K page kernels
  • e5c6debdad28 net: ethernet: mtk_eth_soc: fix supported_interface set after phylink_create
  • bc88744dc556 drm/amdgpu: initialize irq.lock spinlock earlier
  • e33a3bd5cb8d drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm
  • db803223edc4 drm/amd/display: Fix mem_type change detection for async flips
  • db70b4a08211 drm/amd/display: Skip PHY SSC reduction on some 8K panels
  • 7f20ce7b2bcf drm/amdgpu: initialize iter.start in amdgpu_devcoredump_format
  • 1d12ae8b079e drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free
  • e2ab48e8591d ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode
  • 77961e12ea16 perf dso: Set standard errno on decompression failure
  • aa967ae8b256 perf bpf: Validate array presence before casting BPF prog info pointers
  • bfc764f9de65 perf c2c: Fix hist entry and format list leaks in c2c_he_free()
  • 502ee1fe757a perf c2c: Free format list entries when c2c_hists__init() fails
  • 79b92b298b5c perf cs-etm: Bounds-check CPU in cs_etm__get_queue()
  • 2d5a695a9d19 perf cs-etm: Require full global header in auxtrace_info size check
  • f22dbfb71c3d perf cs-etm: Validate num_cpu before metadata allocation
  • 7c7245321599 perf machine: Use snprintf() for guestmount path construction
  • 5a03a2ee17e8 xfrm: validate selector family and prefixlen during match
  • 7394a276f869 xfrm: annotate data-races around xfrm_policy_count[] and xfrm_policy_default[]
  • 041859fd55c8 xfrm: Fix xfrm state cache insertion race
  • f83ef148a94b ALSA: usb-audio: qcom: Free sideband sg_table objects
  • 9104559db16b erofs: call erofs_exit_ishare() before rcu_barrier()
  • a6b17b34aedc i3c: master: Add missing runtime PM get in dev_nack_retry_count_store()
  • b5d5cfea4f23 i3c: master: Update dev_nack_retry_count under maintenance lock
  • 7f29c063c53f spi: dw: fix wrong BAUDR setting after resume
  • a5c5676ad3b0 drm/xe: Fix wa_oob codegen recipe for external module builds
  • ac554ad94361 drm/i915: clear CRTC color blob pointers after dropping refs
  • 9f171aa115ec regcache: Do not overwrite error code when finalizing cache after error
  • e06ad4356915 gpio: mlxbf3: fail probe if gpiochip registration fails
  • 99ab295d8025 perf cs-etm: Reject CPU IDs that would overflow signed comparison
  • 6d2aa8dfea1f perf c2c: Free format list entries when releasing c2c hist entries
  • 62a11653847f perf bpf: Bounds-check array offsets in bpil_offs_to_addr()
  • f9ec0eda83ea perf bpf: Reject oversized BPF metadata events that truncate header.size
  • 3fe6751a0697 perf bpf: Validate func_info_rec_size and sub_id in synthesize_bpf_prog_name()
  • eaab676863cb perf sched: Replace (void*)1 sentinel with proper runtime allocation
  • dd8e455fd91e perf hwmon: Fix fd check to accept fd 0 in hwmon_pmu__describe_items()
  • 97584371d5d8 perf tools: Use snprintf() for root_dir path construction
  • 2367ebcd0d4b perf dso: Set error code when open() fails on uncompressed fallback path
  • c5dcbd5cf007 perf dso: Fix heap overflow in dso__get_filename() on decompressed path
  • df77307da9da perf symbols: Break infinite loop on zero-filled notes in sysfs__read_build_id()
  • 6172d92a7f15 perf symbols: Validate p_filesz before use in filename__read_build_id()
  • 1ce03f1d990e perf symbols: Fix bswap copy-paste error for 32-bit ELF p_filesz
  • a06241a08631 perf maps: Add maps__mutate_mapping
  • abbdd94e6a10 sparc: led: avoid trimming a newline from empty writes
  • f55b1ff89938 accel/ivpu: fix HWS command queue leak on registration failure
  • 30521e7ec4d8 apparmor: fix label can not be immediately before a declaration
  • 4b0c34521747 i3c: master: Prevent reuse of dynamic address on device add failure
  • 8f851cab401c i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev()
  • 50eabb91d2de i3c: master: Defer new-device registration out of DAA caller context
  • fef9bdaa0df0 i3c: master: Ensure Hot-Join operations are stopped on shutdown
  • 08b33dfd457b i3c: master: Consolidate Hot-Join DAA work in the core
  • 21cf9175b370 i3c: master: Serialize i3c_set_hotjoin() with the maintenance lock
  • af6df5d50607 i3c: master: Make hot-join workqueue freezable to block hot-join during suspend
  • 88116f41086a i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring
  • 49a230c2aea4 i3c: mipi-i3c-hci: Fix suspend behavior when bus disable falls back to software reset
  • 4238195ed989 apparmor: Fix inverted comparison in cache_hold_inc()
  • a5c79d44ef19 apparmor: fix uninitialised pointer passed to audit_log_untrustedstring()
  • 3f172fbbe357 apparmor: don't audit files pointing to aa_null.dentry
  • 859ba6c7fc6e apparmor: put secmark label after secid lookup
  • b1abb5340737 apparmor: aa_getprocattr free procattr leak on format failure
  • de91788aa6b8 apparmor: remove unnecessary goto and associated label
  • 393809a05cfb apparmor: release exe file resources on path failure
  • 106e909e12ba apparmor: fail policy unpack on accept2 allocation failure
  • bd30d91f9f22 apparmor: Fix return in ns_mkdir_op
  • 2118a9f7a7ed apparmor: remove or add symlinks to rawdata according to export_binary
  • 73d86ca950b8 apparmor: fix NULL pointer dereference in unpack_pdb
  • dd5f1202f45a apparmor: fix potential UAF in aa_replace_profiles
  • 67ee65ec1a3e apparmor: grab ns lock and refresh when looking up changehat child profiles
  • 4a2c4f2b45dc apparmor: fix rawdata_f_data implicit flex array
  • 6d9147917424 apparmor: aa_label_alloc use aa_label_free on alloc failure
  • ec926b2a351e apparmor: check label build before no_new_privs test
  • 25b262492539 security/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref()
  • b8642f147898 apparmor: fix refcount leak when updating the sk_ctx
  • d680472db988 apparmor: fix race in unix socket mediation when peer_path is used
  • ec95dec9ae2c apparmor: fix shadowing of plabel that prevents cache from being updated
  • 3691a82be209 Revert "PCI/MSI: Unmap MSI-X region on error"
  • 91fbf0de91bc Documentation: ABI: sysfs-class-reboot-mode-reboot_modes: fix doc warnings
  • 375e1defdeb8 sparc: Avoid -Wunused-but-set-parameter in clear_user_page()
  • 63a300151999 xfrm: Fix dev use-after-free in xfrm async resumption
  • 855870e8c59b PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability
  • 972052764672 phy: freescale: phy-fsl-imx8qm-lvds-phy: Fix missing pm_runtime_disable() on probe error path
  • d31244d1732e phy: freescale: phy-fsl-imx8qm-lvds-phy: Use synchronous PM runtime put in reset
  • 393f0bb61545 PCI: mediatek: Use actual physical address instead of virt_to_phys()
  • f66b4e65c4cc dt-bindings: phy: sc8280xp-qmp-pcie: Disallow bifurcation register on Purwa
  • e30fa32cd078 dt-bindings: dma: snps,dw-axi-dmac: Add fallback compatible for CV1800B
  • 65a406f5bbd9 perf symbols: Add bounds checks to read_build_id() note iteration in minimal build
  • e525be3207ed perf symbols: Add bounds checks to elf_read_build_id() note iteration
  • 802257fbe4ea perf bpf: Fix metadata leak in perf_env__add_bpf_info() on duplicate insert
  • 7e841b7b1014 perf bpf: Fix map data leak in bpf_metadata_create() on alloc failure
  • 77373bfa2564 perf bpf: Add NULL check for btf__type_by_id() in synthesize_bpf_prog_name()
  • df7d723d66bd tools lib api: Fix mount_overload() snprintf truncation and toupper range
  • 62adda4bb1b8 tools lib api: Fix filename__write_int() writing uninitialized stack data
  • 908bc5238979 perf tools: Use snprintf() in dso__read_running_kernel_build_id()
  • 1577822e1fa1 perf hwmon: Guard label read against empty or failed reads
  • 2bfaa207732a perf tools: Fix uninitialized pathname on uncompressed fallback in filename__decompress()
  • a11731df15af perf symbols: Bounds-check descsz in sysfs__read_build_id() GNU fallback
  • 354a61c752ea perf hwmon: Fix parse_hwmon_filename() strlcpy buffer overflow
  • f99e250f8085 perf hwmon: Use scnprintf() in hwmon_pmu__for_each_event()
  • 4c7ed5f4ff36 perf hwmon: Fix off-by-one null termination on sysfs reads
  • 6290c0c0fb2b perf tools: Fix thread__set_comm_from_proc() on empty comm file
  • 8532c1725abb perf intel-pt: Fix snprintf size tracking bug in insn decoder
  • 5e5b4cfffb4a perf tools: Use mkostemp() for O_CLOEXEC on temporary files
  • 51d3124590bc perf symbols: Bounds-check .gnu_debuglink section data
  • 519b4ad15b2c perf symbols: Fix signed overflow in sysfs__read_build_id() size check
  • b4333af83c12 tools lib api: Fix missing null termination in filename__read_int/ull()
  • a407a5177cd1 perf pmu: Fix perf_pmu__parse_scale/unit() OOB access on empty sysfs file
  • 1202ebd3a9b4 perf pmu: Fix pmu_id() heap underwrite on empty identifier file
  • 4d72f46d420f perf cs-etm: Queue context packets for frontend
  • c091fe7073b0 perf data convert json: Fix addr_location leak on time-filtered samples
  • d625d9b320c2 perf s390: Fix TEXTREL in Python extension by compiling as PIC
  • 31298d37687b xprtrdma: Return sendctx slot after Send preparation failure
  • d7c531ab477a xprtrdma: Repost Receive buffers for malformed replies
  • 33db78b1b24f xprtrdma: Sanitize the reply credit grant after parsing
  • 118a16a18c59 xprtrdma: Fix bcall rep leak and unbounded peek
  • 69c956c1b67d xprtrdma: Resize reply buffers before reposting receives
  • 96da53e7d6f9 xprtrdma: Document and assert reply-handler invariants
  • ef3b79edf14b xprtrdma: Check frwr_wp_create() during connect
  • 264ccd787191 xprtrdma: Initialize re_id before removal registration
  • ffc077905397 xprtrdma: Fix ep kref imbalance on ADDR_CHANGE
  • f025990647c8 perf tools: Use scnprintf() in build_id__snprintf() and hwmon read_events()
  • a6d9b8184656 perf hists: Fix snprintf() in hists__scnprintf_title() UID filter path
  • 5f3b8ff3f632 perf bpf: Use scnprintf() in snprintf_hex() and synthesize_bpf_prog_name()
  • 01d67b6f44ed perf tools: Add O_CLOEXEC to open() calls in DSO and ELF code
  • a757d523741d perf sched: Fix idle-hist callchain display using wrong rb_first variant
  • 23af74f538b7 perf sched: Bounds-check prio before test_bit() in timehist
  • 2c0461f5393b PCI: rcar-host: Remove unused LIST_HEAD(res)
  • 027c177da2b5 perf tools: NULL bitmap pointers after bitmap_free()
  • eb266a14c16a perf tools: Use perf_env__get_cpu_topology() in machine__resolve()
  • 36d2c15a33ec perf tools: Use scnprintf() in cpu_map__snprint() to prevent overflow
  • 678bb88bb977 perf tools: Fix get_max_num() size_t underflow on empty sysfs file
  • 962c7a1f8f1e platform/x86/intel/vsec: Restore BAR fallback for header walk
  • c99444f6dfca fs/ntfs3: resize log->one_page_buf when adopting on-disk page size
  • 7ae7e98b7143 fs/ntfs3: prevent potential lcn remains uninitialized
  • b052df3a5953 virtio: add missing kernel-doc for map and vmap members
  • a2cc03ee5d34 lockd: Correct kernel-doc status descriptions for NLMv4 GRANTED
  • ec52cdcbf23f PCI: meson: Add missing remove callback
  • 221972a90c56 PCI: meson: Propagate devm_add_action_or_reset() failure
  • f966db2568c4 pwm: rzg2l-gpt: Add missing newlines to dev_err_probe() messages
  • fa7ce7dfbd2d PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro
  • e68035178e65 nfs: use nfsi->rwsem to protect traversal of the file lock list
  • 51e5adebef61 NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write
  • 0fe1ac2bda64 NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors
  • 7471673936d1 nfs: keep PG_UPTODATE clear after read errors in page groups
  • 72c578ca2f9e NFSv4/pnfs: defer return_range callbacks until after inode unlock
  • 8203f760a72b xprtrdma: Decouple req recycling from RPC completion
  • 7c42bc9cb7d3 xprtrdma: Use sendctx DMA state for Send signaling
  • fa977d37765b pNFS/filelayout: fix cheking if a layout is striped
  • f0dfbca47b9e sunrpc: Fix error handling in rpc_sysfs_xprt_switch_add_xprt_store()
  • e2414f2a3f12 clk: qcom: a53: Corrected frequency multiplier for 1152MHz
  • 65e82fa24965 dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor
  • f055829151ee dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc
  • 0bc191050c32 dmaengine: Fix possible use after free
  • c1a2159c1100 dmaengine: qcom: gpi: set DMA_PRIVATE capability
  • fb372cbccab6 mshv: add bounds check on vp_index in mshv_intercept_isr()
  • 89acfa8ad3af docs: memfd_preservation: fix rendering of ABI documentation
  • 2ce2a2e19b62 clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks
  • ca461a2a7390 dt-bindings: clock: qcom: Add X1P42100 camera clock controller
  • a0c08cdaf63a perf sched: Free callchain nodes in idle thread cleanup
  • 5e7c076511bf perf tools: Fix int16_t truncation of max_cpu_num in set_max_cpu_num()
  • cb47a3546f52 perf timechart: Fix cpu2y() OOB read on untrusted CPU index
  • 231acb6d0e14 perf c2c: Fix use-after-free in he__get_c2c_hists() error path
  • 423c520416d7 perf stat: Introduce perf_env__get_cpu_topology() to guard NULL env->cpu
  • 6cfa75ce9a82 perf mmap: Fix NULL deref in aio cleanup on alloc failure
  • f09f7be6bba1 perf sched: Replace BUG_ON and add NULL checks in replay event helpers
  • 6380a4f550dc perf sched: Use thread__put() in free_idle_threads()
  • 1f0a529864d8 perf sched: Fix thread reference leak in idle hist processing
  • 3ba9b69aef73 perf sched: Use is_idle_sample() for idle thread runtime cast guard
  • 340b08cfa751 perf sched: Clean up idle_threads entry on init failure
  • 4884cfb0d36d perf c2c: Bounds-check CPU IDs in setup_nodes() topology loop
  • 937be22cf6d2 perf c2c: Bounds-check CPU and node IDs before bitmap and array access
  • 9cbb9f3e532e perf stat: Bounds-check CPU index in topology aggregation callbacks
  • 5257dfb9619c perf mmap: Guard cpu__get_node() return in aio_bind()
  • 5ea1dcc9418c perf sched: Fix register_pid() overflow, strcpy, and BUG_ON
  • 68b6157d2c62 perf sched: Cap max_cpu at MAX_CPUS in timehist sample processing
  • 380ad7297fa0 perf sched: Fix thread reference leaks in timehist_get_thread()
  • 6587c61570f4 perf tools: Add bounds check to cpu__get_node()
  • bd027a461624 perf tools: Guard remaining test_bit calls from OOB sample CPU
  • e94a56aac6b4 perf sched: Fix comp_cpus heap overflow with cross-machine recordings
  • 70d31bdd3789 perf sched: Fix NULL dereference in latency_runtime_event
  • bbaa0a0441d2 perf sched: Replace BUG_ON on invalid CPU with graceful skip
  • a4ec6bf24145 perf sample: Add file_offset field to struct perf_sample
  • b189fce8d2ac perf sched: Fix thread reference leak in latency_switch_event
  • d88a630bacfa perf tools: Guard test_bit from out-of-bounds sample CPU
  • 885bd036cbdf perf annotate: Fix crashes on empty annotate windows
  • 25b1f78ef352 perf: Fix off-by-one stack buffer overflow in kallsyms__parse()
  • 4442e8c8f20f dt-bindings: dma: nvidia,tegra186-gpc-dma: Make reset optional
  • 4e8f512e2b8f dmaengine: imx-sdma: Refine spba bus searching in probe
  • 3ea71aa629a7 thunderbolt: debugfs: Fix margining error counter buffer leak
  • 994a42b890ce drm/amd/display: Add missing kdoc for ALLM parameters
  • 668791009a21 fs/ntfs3: fix mount failure on 64K page-size kernels
  • bc95e2f61192 ntfs3: avoid another -Wmaybe-uninitialized warning
  • 3cd2212012c0 ntfs3: Allocate iomap inline_data using alloc_page
  • ff825bf0521f fs/ntfs3: call _ntfs_bad_inode() when failing to rename
  • 1f6111ad30d2 fs/ntfs3: fix wrong LCN in run_remove_range() when splitting a run
  • 41081202eb82 fs/ntfs3: add bounds check to run_get_highest_vcn()
  • 3dcdf8ddb509 clk: spacemit: k3: Fix PCIe clock register offset
  • 0b4739fc72db clk: spacemit: k3: Switch to pll2_d6 as parent for PCIe clock
  • d823ab4592b3 docs: changes.rst: restore pahole 1.26 minimum (regressed by sort)
  • 83d87cbfa3aa HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter
  • b7ef2eb23936 clk: at91: keep securam node alive while mapping it
  • 8c00cabb1982 iio: tcs3472: power down chip on probe failure
  • f3d413e701c5 iio: accel: mma8452: handle I2C read error(s) in mma8452_read()
  • 3c374d33f133 iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling
  • fb27ebf81136 iio: magnetometer: ak8975: fix potential kernel stack memory leak
  • 7f167853ef3c iio: light: si1133: prevent race condition on timeout
  • 2413ede67e39 iio: light: si1133: reset counter to prevent race condition
  • 8e8b52ad5ab5 perf header: Validate bitmap size before allocating in do_read_bitmap()
  • ea63c57eb2f1 perf header: Sanity check HEADER_EVENT_DESC attr.size before swap
  • 27ca3f615c1a timers/migration: Update stale @online doc to @available
  • d61e42f63a00 PCI: qcom: Disable ASPM L0s for SA8775P
  • c764d5092b92 powerpc tools perf: Initialize error code in auxtrace_record_init function
  • 0e1db8dc4623 docs: threat-model: add missing closing parenthesis
  • 789d1b0e1118 clk: renesas: rzg2l: Rename iterator in for_each_mod_clock() to avoid shadowing
  • f15a545f7518 gpib: cb7210: Fix region leak when request_irq fails
  • 8b5f1d295dda gpib: fix double decrement of descriptor_busy in command_ioctl()
  • a41f0fbd77ae sonypi: Check ACPI_COMPANION() against NULL at probe time
  • 99a34d028293 hpet: Check ACPI_COMPANION() against NULL at probe time
  • 42223445607a char: tlclk: fix use-after-free in tlclk_cleanup()
  • 49489a18afa5 gpib: Fix inappropriate ioctl error return
  • ecdd8af41197 perf test amd ibs: Fix incorrect kernel version check
  • 684a58dd845e usb: host: max3421: Reject hub port requests for non-existent ports
  • 4da073d57176 usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
  • 7fc162453cfb staging: most: video: avoid double free on video register failure
  • b1493c42183f perf inject: Fix itrace branch stack synthesis
  • 034182b63108 perf event: Fix size of synthesized sample with branch stacks
  • 7e374ac7702b perf build-id: Fix off-by-one bug when printing kernel/module build-id
  • 8b54808fcced clk: microchip: mpfs-ccc: fix peripheral driver registration failures after oob fix
  • b670ac2731dd platform/x86: classmate-laptop: Address memory leaks on driver removal
  • ce5633204a4b PCI: mediatek-gen3: Fix incorrectly skipped pwrctrl error message
  • e31173a19466 PCI: dwc: Fix signedness bug in fault injection test code
  • 8ca9adc80588 coresight: platform: defer connection counter increment until alloc succeeds
  • f344f6ae8517 PCI/pwrctrl: Lock device when calling device_is_bound()
  • ac8a86dcaf59 mailbox: don't free the channel if the startup callback failed
  • 25d6ea6c76e1 mailbox: mtk-adsp: fix UAF during device teardown
  • 8ceeb0541978 mailbox: mpfs: fix check for syscon presence in mpfs_mbox_inbox_isr()
  • 80cf6501acb9 PCI: mediatek-gen3: Do full device power down on removal
  • 8c1dac9c05d4 coresight: Handle helper enable failure properly
  • c37f87151990 coresight: Fix source not disabled on idr_alloc_u32 failure
  • 81ed540159ef soundwire: intel_ace2x: release bpt_stream when close it
  • abdfdb8e6220 iio: light: acpi-als: Check ACPI_COMPANION() against NULL
  • 14622b111e4e clk: at91: sam9x7: Fix gmac_gclk clock definition
  • 8a7a8ac82791 perf pmu: Skip test on Arm64 when #slots is zero
  • 03dda04f2f76 perf unwind: Refactor get_entries to allow dynamic libdw/libunwind selection
  • 9810f833df66 perf pmu-events AMD: Switch l2_itlb_misses to bp_l1_tlb_miss_l2_tlb_miss.all
  • cb329b1fa702 phy: phy-can-transceiver: Check driver match and driver data against NULL
  • 0ba6fd199192 PCI: qcom: Set max OPP before DBI access during resume
  • 72a7bfee9fe8 PCI: dwc: Apply ECRC workaround for DesignWare cores prior to 5.10a
  • f478709f7be8 dt-bindings: clock: qcom,sm6125-dispcc: reference qcom,gcc.yaml
  • 6c7f2108af20 clk: qcom: cmnpll: Account for reference clock divider
  • d1da8fcb8802 coresight: fix missing error code when trace ID is invalid
  • adec0b0df4e2 bus: mhi: ep: Add missing state_lock protection for mhi_state access
  • e30fa2246972 bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
  • 34b2a1076dd7 rust: alloc: fix assert in Vec::reserve doc test
  • 1f95260a8237 PCI: loongson: Do not ignore downstream devices on external bridges
  • f62ffd973b07 PCI: intel-gw: Add .start_link() callback
  • b2dd40f1d15e PCI: intel-gw: Enable clock before PHY init
  • 28c35ea3515f PCI: intel-gw: Move interrupt enable to own function
  • fc9d6f815871 perf tool: Fix missing schedstat delegates and dont_split_sample_group in delegate_tool
  • 6ed3cea56b77 perf sched: Add missing mmap2 handler in timehist
  • f05c3b4c9cc0 platform/x86: xo15-ebook: Fix wakeup source and GPE handling
  • df6d71c9a818 x86/platform/olpc: xo15: Drop wakeup source on driver removal
  • 721ad5b72448 PCI: Check ROM header and data structure addr before accessing
  • 4e82818ead50 PCI: Introduce named defines for PCI ROM
  • d50ba5e4642c PCI/ASPM: Don't reconfigure ASPM entering low-power state
  • 12007c55d9c0 coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore
  • 293dacd5b6a9 coresight: ete: Always save state on power down
  • 9d802907fc2a coresight: tmc: Fix overflow when calculating is bigger than 2GiB
  • e483a406a23a soundwire: fix bug in sdw_add_element_group_count found by syzkaller
  • f0481e6bcc5d soundwire: don't program SDW_SCP_BUSCLOCK_SCALE on a unattached Peripheral
  • fbd5d3168740 coresight: cti: Fix DT filter signals silently ignored
  • 2830eedfcc7d perf callchain: Handle multiple address spaces
  • ffddd64eae0b perf debuginfo: Fix libdw API contract violations
  • 2a86103b44af perf annotate-data: Fix libdw API contract violations
  • 881af00c02c0 perf probe-finder: Fix libdw API contract violations
  • d739d9f4525b perf libdw: Fix libdw API contract violations and memory leaks
  • e542c8800bbc perf srcline: Introduce inline_node__clear_frames()
  • eb0062b3e76d perf dwarf-aux: Fix libdw API contract violations
  • 23ec342a8fa6 perf dwarf-aux: Fix libdw segmentation fault in cu_walk_functions_at
  • 5de04caa46b6 staging: nvec: fix use-after-free in nvec_rx_completed()
  • fde2296f87b7 staging: rtl8723bs: fix stainfo check in rtw_aes_decrypt
  • 697af8745d5c i3c: master: svc: Fix missed IBI after false SLVSTART on NPCM845
  • b0194db10032 gpiolib: acpi: Only trigger ActiveBoth interrupts on boot
  • 4791b91daeb1 eventpoll: Fix epoll_wait() report false negative
  • 8679e9e06876 eventpoll: rename epi->next and txlist for clarity
  • b698ee9abf40 eventpoll: expand top-of-file overview / locking doc
  • 0c44866f4a23 9p: Add missing read barrier in virtio zero-copy path
  • ebbcbe5c0db2 net/9p: fix race condition on rdma->state in trans_rdma.c
  • fdc9043cfd50 9p: avoid returning ERR_PTR(0) from mkdir operations
  • f3dd1e534e9d ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write
  • 17d79248b4f3 mfd: cs42l43: Sanity check firmware size
  • afb1a5af6dd9 mfd: rsmu: Fix page register setup
  • e18ffb7541de mfd: bd72720: Drop BUCK11 ID
  • 0ff82a9cf931 ksmbd: fix use-after-free in same_client_has_lease()
  • 2fface6e0bbd net: serialize netif_running() check in enqueue_to_backlog()
  • bde37aed0724 RDMA/irdma: Replace waitqueue and flag with completion
  • bc4caea7a82b RDMA/hns: Fix memory leak of bonding resources
  • 967099102562 RDMA/bnxt_re: Reject GET_TOGGLE_MEM when toggle page was not allocated
  • 03c9a2fba68e RDMA/bnxt_re: Fail DBR related page allocation UAPIs if the feature is disabled
  • da406b8b49c1 RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
  • 303f6fef95df RDMA/bnxt_re: Proper rollback if the ioremap fails
  • a59d815cbe66 RDMA/bnxt_re: Add a max slot check for SQ
  • a65b5258b14c RDMA/bnxt_re: Enable app allocated QPs
  • 6eceb09df972 RDMA/bnxt_re: Support doorbells for app allocated QPs
  • 2234acd1d1d2 RDMA/bnxt_re: Enhance dbr usecnt logic in doorbell uapis
  • 3169824fd8f4 RDMA/bnxt_re: Update msn table size for app allocated QPs
  • 7605fd8bbf4d RDMA/bnxt_re: Refactor bnxt_re_init_user_qp()
  • 0c403e078676 RDMA/bnxt_re: Avoid displaying the kernel pointer
  • b193854675ec RDMA/bnxt_re: Free CQ toggle page after firmware teardown
  • 0adcd67f3d6f RDMA/bnxt_re: Free SRQ toggle page after firmware teardown
  • 3d00b375853f RDMA/bnxt_re: Initialize dpi variable to zero
  • 5126f099295c ionic: Fix check in ionic_get_link_ext_stats
  • d01d4cfc806a net: ethernet: oa_tc6: Remove FCS size in RX frame
  • 785e3765bf9a net: ti: icssg: Use undirected TX tag for XDP zero copy in HSR offload mode
  • 40a91dcc6260 net: ti: icssg: Use undirected TX tag for native XDP in HSR offload mode
  • b478a6ffda4e net: ti: icssg-prueth: Fix AF_XDP fill ring alloc and wakeup condition
  • ad262d2b96be net: airoha: Fix always-true condition in PPE1 queue reservation loop
  • a210791f3334 tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)
  • 35e0297a93c3 tipc: fix UAF in tipc_l2_send_msg()
  • d2fb2ef76008 KEYS: Use acquire when reading state in keyring search
  • c893bfb0d696 powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus
  • e4e69cee0b01 powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down
  • b504fd953664 powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del
  • 038f068cced8 MIPS: mm: Fix out-of-bounds write in maar_res_walk()
  • e09f7bd72739 bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check
  • 39d44ed6904b sockmap: Fix use-after-free in udp_bpf_recvmsg()
  • bd004716ba75 bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
  • 478c7f68ef25 udf: fix nls leak on udf_fill_super() failure
  • c12e3c9e5224 bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket
  • e68343ee3c13 selftests/bpf: Initialize operation name before use
  • 85100de4f473 selftests/bpf: Fix typo in verify_umulti_link_info
  • c6d51ad36490 bpf: Guard __get_user acesss with access_ok for uprobe_multi data
  • 590d696f846a btrfs: Drop WQ_PERCPU from ordered_flags in btrfs_init_workqueues()
  • 2bc610c9db5d smb/client: always return a value for FS_IOC_GETFLAGS
  • 7839f1817a0c cifs: remove all cifs files before kill super
  • 018b3c8248f5 smb: client: fix conflicting option validation for new mount API
  • b8ca5fcc3182 ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait()
  • 1e8ff78520d9 geneve: Fix off-by-one comparing with GRO_LEGACY_MAX_SIZE
  • edf234f71fb3 netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them
  • db50e2d289b6 netfilter: nf_conncount: callers must hold rcu read lock
  • 1c4c35fb68d5 ALSA: seq: avoid stale FIFO cells during resize
  • 43e10709b1ba ALSA: seq: oss: Serialize readq reset state with q->lock
  • 9684fff87124 kcm: use WRITE_ONCE() when changing lower socket callbacks
  • 6b638db5ec06 net: airoha: Fix debugfs new-tuple display for IPv4 ROUTE entries
  • 2ac37fca3052 net: airoha: Fix register index for Tx-fwd counter configuration
  • be55f99a0b08 octeontx2-af: fix NPC mailbox codes in mbox.h
  • 6be4da4f5a16 net: bcmgenet: Use weighted round-robin TX DMA arbitration
  • d0de5037dce5 landlock: Fix unmarked concurrent access to socket family
  • 467ae77921ad dpll: balance create/delete notifications in _dpll_pin(un)register
  • 8c48e6581c43 dpll: guard sync-pair removal on full pin unregister
  • dc37a9a94954 dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister()
  • 0ea6703cb3dc dpll: send delete notification before unregister in on-pin rollback
  • 75a52d107203 dpll: fix stale iteration in dpll_pin_on_pin_unregister()
  • 4c1b25d85f4c net: wwan: t7xx: check skb_clone in control TX

View original

Discussion