{
  "cves": [
    "CVE-2024-36350",
    "CVE-2024-36357",
    "CVE-2024-49929",
    "CVE-2024-57976",
    "CVE-2024-58091",
    "CVE-2025-21879",
    "CVE-2025-21942",
    "CVE-2025-22112",
    "CVE-2025-22115",
    "CVE-2025-22119",
    "CVE-2025-23137",
    "CVE-2025-23155",
    "CVE-2025-37984",
    "CVE-2025-38067",
    "CVE-2025-38083",
    "CVE-2025-38084",
    "CVE-2025-38085",
    "CVE-2025-38086",
    "CVE-2025-38087",
    "CVE-2025-38090",
    "CVE-2025-38091",
    "CVE-2025-38094",
    "CVE-2025-38095",
    "CVE-2025-38096",
    "CVE-2025-38097",
    "CVE-2025-38098",
    "CVE-2025-38099",
    "CVE-2025-38100",
    "CVE-2025-38101",
    "CVE-2025-38102",
    "CVE-2025-38103",
    "CVE-2025-38104",
    "CVE-2025-38106",
    "CVE-2025-38107",
    "CVE-2025-38108",
    "CVE-2025-38109",
    "CVE-2025-38110",
    "CVE-2025-38111",
    "CVE-2025-38112",
    "CVE-2025-38113",
    "CVE-2025-38115",
    "CVE-2025-38117",
    "CVE-2025-38118",
    "CVE-2025-38119",
    "CVE-2025-38120",
    "CVE-2025-38122",
    "CVE-2025-38124",
    "CVE-2025-38125",
    "CVE-2025-38126",
    "CVE-2025-38127",
    "CVE-2025-38129",
    "CVE-2025-38134",
    "CVE-2025-38141",
    "CVE-2025-38146",
    "CVE-2025-38147",
    "CVE-2025-38148",
    "CVE-2025-38149",
    "CVE-2025-38151",
    "CVE-2025-38154",
    "CVE-2025-38155",
    "CVE-2025-38157",
    "CVE-2025-38159",
    "CVE-2025-38160",
    "CVE-2025-38161",
    "CVE-2025-38162",
    "CVE-2025-38165",
    "CVE-2025-38166",
    "CVE-2025-38169",
    "CVE-2025-38170",
    "CVE-2025-38174",
    "CVE-2025-38177",
    "CVE-2025-38179",
    "CVE-2025-38180",
    "CVE-2025-38181",
    "CVE-2025-38184",
    "CVE-2025-38185",
    "CVE-2025-38186",
    "CVE-2025-38188",
    "CVE-2025-38190",
    "CVE-2025-38192",
    "CVE-2025-38193",
    "CVE-2025-38194",
    "CVE-2025-38197",
    "CVE-2025-38198",
    "CVE-2025-38200",
    "CVE-2025-38201",
    "CVE-2025-38202",
    "CVE-2025-38208",
    "CVE-2025-38210",
    "CVE-2025-38211",
    "CVE-2025-38212",
    "CVE-2025-38214",
    "CVE-2025-38215",
    "CVE-2025-38216",
    "CVE-2025-38217",
    "CVE-2025-38220",
    "CVE-2025-38222",
    "CVE-2025-38223",
    "CVE-2025-38229",
    "CVE-2025-38231",
    "CVE-2025-38232",
    "CVE-2025-38236",
    "CVE-2025-38238",
    "CVE-2025-38239",
    "CVE-2025-38242",
    "CVE-2025-38243",
    "CVE-2025-38244",
    "CVE-2025-38245",
    "CVE-2025-38246",
    "CVE-2025-38249",
    "CVE-2025-38250",
    "CVE-2025-38251",
    "CVE-2025-38253",
    "CVE-2025-38255",
    "CVE-2025-38256",
    "CVE-2025-38258",
    "CVE-2025-38260",
    "CVE-2025-38263",
    "CVE-2025-38264",
    "CVE-2025-38265",
    "CVE-2025-38267",
    "CVE-2025-38268",
    "CVE-2025-38269",
    "CVE-2025-38270",
    "CVE-2025-38273",
    "CVE-2025-38279",
    "CVE-2025-38280",
    "CVE-2025-38282",
    "CVE-2025-38285",
    "CVE-2025-38288",
    "CVE-2025-38289",
    "CVE-2025-38293",
    "CVE-2025-38298",
    "CVE-2025-38302",
    "CVE-2025-38303",
    "CVE-2025-38304",
    "CVE-2025-38305",
    "CVE-2025-38307",
    "CVE-2025-38310",
    "CVE-2025-38312",
    "CVE-2025-38315",
    "CVE-2025-38319",
    "CVE-2025-38320",
    "CVE-2025-38321",
    "CVE-2025-38323",
    "CVE-2025-38324",
    "CVE-2025-38326",
    "CVE-2025-38328",
    "CVE-2025-38332",
    "CVE-2025-38334",
    "CVE-2025-38336",
    "CVE-2025-38337",
    "CVE-2025-38338",
    "CVE-2025-38342",
    "CVE-2025-38344",
    "CVE-2025-38345",
    "CVE-2025-38346",
    "CVE-2025-38348",
    "CVE-2025-38349",
    "CVE-2025-38350",
    "CVE-2025-38352",
    "CVE-2025-38354",
    "CVE-2025-38360",
    "CVE-2025-38361",
    "CVE-2025-38362",
    "CVE-2025-38363",
    "CVE-2025-38364",
    "CVE-2025-38365",
    "CVE-2025-38369",
    "CVE-2025-38372",
    "CVE-2025-38373",
    "CVE-2025-38374",
    "CVE-2025-38375",
    "CVE-2025-38379",
    "CVE-2025-38380",
    "CVE-2025-38382",
    "CVE-2025-38383",
    "CVE-2025-38385",
    "CVE-2025-38386",
    "CVE-2025-38387",
    "CVE-2025-38389",
    "CVE-2025-38391",
    "CVE-2025-38392",
    "CVE-2025-38393",
    "CVE-2025-38395",
    "CVE-2025-38396",
    "CVE-2025-38399",
    "CVE-2025-38400",
    "CVE-2025-38402",
    "CVE-2025-38403",
    "CVE-2025-38404",
    "CVE-2025-38405",
    "CVE-2025-38406",
    "CVE-2025-38409",
    "CVE-2025-38410",
    "CVE-2025-38412",
    "CVE-2025-38413",
    "CVE-2025-38415",
    "CVE-2025-38417",
    "CVE-2025-38418",
    "CVE-2025-38419",
    "CVE-2025-38420",
    "CVE-2025-38424",
    "CVE-2025-38425",
    "CVE-2025-38427",
    "CVE-2025-38430",
    "CVE-2025-38436",
    "CVE-2025-38438",
    "CVE-2025-38439",
    "CVE-2025-38440",
    "CVE-2025-38441",
    "CVE-2025-38443",
    "CVE-2025-38444",
    "CVE-2025-38445",
    "CVE-2025-38449",
    "CVE-2025-38451",
    "CVE-2025-38455",
    "CVE-2025-38456",
    "CVE-2025-38457",
    "CVE-2025-38458",
    "CVE-2025-38459",
    "CVE-2025-38460",
    "CVE-2025-38461",
    "CVE-2025-38462",
    "CVE-2025-38463",
    "CVE-2025-38464",
    "CVE-2025-38465",
    "CVE-2025-38466",
    "CVE-2025-38467",
    "CVE-2025-38468",
    "CVE-2025-38470",
    "CVE-2025-38471",
    "CVE-2025-38472",
    "CVE-2025-38473",
    "CVE-2025-38474",
    "CVE-2025-38477",
    "CVE-2025-38488",
    "CVE-2025-38491",
    "CVE-2025-38493",
    "CVE-2025-38494",
    "CVE-2025-38495",
    "CVE-2025-38496",
    "CVE-2025-38498",
    "CVE-2025-38499",
    "CVE-2025-38503",
    "CVE-2025-38505",
    "CVE-2025-38506",
    "CVE-2025-38512",
    "CVE-2025-38513",
    "CVE-2025-38515",
    "CVE-2025-38516",
    "CVE-2025-38520",
    "CVE-2025-38523",
    "CVE-2025-38526",
    "CVE-2025-38527",
    "CVE-2025-38528",
    "CVE-2025-38531",
    "CVE-2025-38535",
    "CVE-2025-38537",
    "CVE-2025-38539",
    "CVE-2025-38540",
    "CVE-2025-38543",
    "CVE-2025-38546",
    "CVE-2025-38547",
    "CVE-2025-38549",
    "CVE-2025-38550",
    "CVE-2025-38551",
    "CVE-2025-38552"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[6.12.0-103.40.4.1.el10uek]\n- netlink: avoid infinite retry looping in netlink_unicast() (Fedor Pchelkin)  [Orabug: 38361037]\n\n[6.12.0-103.40.4.el10uek]\n- rds: Fix NULL ptr deref in xas_start (Hakon Bugge) [Orabug: 38169301]\n- KVM: x86: use array_index_nospec with indices that come from guest (Thijs Raymakers) [Orabug: 38325898]\n\n[6.12.0-103.40.3.el10uek]\n- enic: get max rq  wq entries supported by hw, 16K queues (Satish Kharat) [Orabug: 38058289]\n- enic: cleanup of enic wq request completion path (Satish Kharat) [Orabug: 38058289]\n- enic: added enic_wq.c and enic_wq.h (Satish Kharat) [Orabug: 38058289]\n- enic: remove unused function cq_enet_wq_desc_dec (Satish Kharat) [Orabug: 38058289]\n- enic: enable rq extended cq support (Satish Kharat) [Orabug: 38058289]\n- enic: enic rq extended cq defines (Satish Kharat) [Orabug: 38058289]\n- enic: enic rq code reorg (Satish Kharat) [Orabug: 38058289]\n- enic: Move function from header file to c file (Satish Kharat) [Orabug: 38058289]\n- enic: add dependency on Page Pool (John Daley) [Orabug: 38058289]\n- enic: remove copybreak tunable (John Daley) [Orabug: 38058289]\n- enic: Use the Page Pool API for RX (John Daley) [Orabug: 38058289]\n- enic: Simplify RX handler function (John Daley) [Orabug: 38058289]\n- enic: Move RX functions to their own file (John Daley) [Orabug: 38058289]\n- enic: Fix typo in comment in table indexed by link speed (John Daley) [Orabug: 38058289]\n- enic: Obtain the Link speed only after the link comes up (John Daley) [Orabug: 38058289]\n- enic: Move RX coalescing set function (John Daley) [Orabug: 38058289]\n- enic: Move kdump check into enic_adjust_resources() (Nelson Escobar) [Orabug: 38058289]\n- enic: Move enic resource adjustments to separate function (Nelson Escobar) [Orabug: 38058289]\n- enic: Adjust used MSI-X wq/rq/cq/interrupt resources in a more robust way (Nelson Escobar) [Orabug: 38058289]\n- enic: Allocate arrays in enic struct based on VIC config (Nelson Escobar) [Orabug: 38058289]\n- enic: Save resource counts we read from HW (Nelson Escobar) [Orabug: 38058289]\n- enic: Make MSI-X I/O interrupts come after the other required ones (Nelson Escobar) [Orabug: 38058289]\n- enic: Create enic_wq/rq structures to bundle per wq/rq data (Nelson Escobar) [Orabug: 38058289]\n- RDMA/mlx5: Fix HW counters query for non-representor devices (Patrisious Haddad) [Orabug: 38161799]\n- RDMA/mlx5: Fix CC counters query for MPV (Patrisious Haddad) [Orabug: 38161799]\n- Revert 'RDMA/mlx5: Fix CC counters query for MPV' (Qing Huang) [Orabug: 38161799]\n- block: use chunk_sectors when evaluating stacked atomic write limits (John Garry) [Orabug: 38279050]\n- dm-stripe: limit chunk_sectors to the stripe size (John Garry) [Orabug: 38279050]\n- md/raid10: set chunk_sectors limit (John Garry) [Orabug: 38279050]\n- md/raid0: set chunk_sectors limit (John Garry) [Orabug: 38279050]\n- block: sanitize chunk_sectors for atomic write limits (John Garry) [Orabug: 38279050]\n- ilog2: add max_pow_of_two_factor() (John Garry) [Orabug: 38279050]\n- net/mlx5: E-Switch, Fix switching to switchdev mode in MPV (Patrisious Haddad) [Orabug: 38281424]\n- net/mlx5: E-Switch, Fix switching to switchdev mode with IB device disabled (Patrisious Haddad) [Orabug: 38281424]\n- net/mlx5: E-switch, refactor eswitch mode change (Patrisious Haddad) [Orabug: 38281424]\n\n[6.12.0-103.40.2.el10uek]\n- arm64: sysreg: Drag linux/kconfig.h to work around vdso build issue (Marc Zyngier) [Orabug: 38194015]\n- arm64: errata: Work around AmpereOne's erratum AC04_CPU_23 (D Scott Phillips) [Orabug: 38194015]\n- scsi: fnic: Set appropriate logging level for log message (Karan Tilak Kumar) [Orabug: 38226429]\n- scsi: fnic: Add and improve logs in FDMI and FDMI ABTS paths (Karan Tilak Kumar) [Orabug: 38226429]\n- scsi: fnic: Turn off FDMI ACTIVE flags on link down (Karan Tilak Kumar) [Orabug: 38226429]\n- scsi: fnic: Fix crash in fnic_wq_cmpl_handler when FDMI times out (Karan Tilak Kumar) [Orabug: 38175020,38226429] {CVE-2025-38238}\n- fnic: treewide: Switch/rename to timer_delete[_sync]() (Thomas Gleixner) [Orabug: 38226429]\n- LTS version: v6.12.40 (Jack Vogel)\n- KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (Manuel Andreas) [Orabug: 38254220] {CVE-2025-38469}\n- iommu/vt-d: Fix misplaced domain_attached assignment (Bbaa)\n- smb: client: let smbd_post_send_iter() respect the peers max_send_size and transmit all data (Stefan Metzmacher)\n- drm/xe: Move page fault init after topology init (Matthew Brost)\n- drm/xe/mocs: Initialize MOCS index early (Balasubramani Vivekanandan)\n- sched,freezer: Remove unnecessary warning in __thaw_task (Chen Ridong)\n- i2c: omap: fix deprecated of_property_read_bool() use (Johan Hovold)\n- i2c: omap: Handle omap_i2c_init() errors in omap_i2c_probe() (Christophe Jaillet)\n- i2c: omap: Fix an error handling path in omap_i2c_probe() (Christophe Jaillet)\n- i2c: omap: Add support for setting mux (Jayesh Choudhary)\n- selftests/bpf: Set test path for token/obj_priv_implicit_token_envvar (Ihor Solodrai)\n- rust: use #[used(compiler)] to fix build and modpost with Rust = 1.89.0 (Miguel Ojeda)\n- net: libwx: fix multicast packets received count (Jiawen Wu)\n- usb: dwc3: qcom: Don't leave BCR asserted (Krishna Kurapati)\n- usb: hub: Don't try to recover devices lost during warm reset. (Mathias Nyman)\n- usb: hub: Fix flushing of delayed work used for post resume purposes (Mathias Nyman)\n- usb: hub: Fix flushing and scheduling of delayed work that tunes runtime pm (Mathias Nyman)\n- usb: hub: fix detection of high tier USB3 devices behind suspended hubs (Mathias Nyman)\n- btrfs: fix block group refcount race in btrfs_create_pending_block_groups() (Boris Burkov) [Orabug: 37844509] {CVE-2025-22115}\n- clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns (Al Viro) [Orabug: 38310005] {CVE-2025-38499}\n- efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths (Breno Leitao) [Orabug: 38324320] {CVE-2025-38549}\n- libbpf: Fix handling of BPF arena relocations (Andrii Nakryiko)\n- drm/mediatek: only announce AFBC if really supported (Icenowy Zheng)\n- drm/mediatek: Add wait_event_timeout when disabling plane (Jason-JH Lin)\n- Revert 'cgroup_freezer: cgroup_freezing: Check if not frozen' (Chen Ridong)\n- rxrpc: Fix transmission of an abort in response to an abort (David Howells)\n- rxrpc: Fix recv-recv race of completed call (David Howells) [Orabug: 38324205] {CVE-2025-38524}\n- net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree (William Liu) [Orabug: 38254212] {CVE-2025-38468}\n- net: bridge: Do not offload IGMP/MLD messages (Joseph Huang)\n- net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime (Dong Chenchen) [Orabug: 38254223] {CVE-2025-38470}\n- tls: always refresh the queue when reading sock (Jakub Kicinski) [Orabug: 38254232] {CVE-2025-38471}\n- virtio-net: fix recursived rtnl_lock() during probe() (Zigit Zo) [Orabug: 38324329] {CVE-2025-38551}\n- hv_netvsc: Set VF priv_flags to IFF_NO_ADDRCONF before open to prevent IPv6 addrconf (Li Tian)\n- Bluetooth: L2CAP: Fix attempting to adjust outgoing MTU (Luiz Augusto von Dentz)\n- drm/xe/pf: Prepare to stop SR-IOV support prior GT reset (Michal Wajdeczko)\n- drm/xe/pf: Move VFs reprovisioning to worker (Michal Wajdeczko)\n- drm/xe/pf: Sanitize VF scratch registers on FLR (Michal Wajdeczko)\n- netfilter: nf_conntrack: fix crash due to removal of uninitialised entry (Florian Westphal) [Orabug: 38254235] {CVE-2025-38472}\n- net: fix segmentation after TCP/UDP fraglist GRO (Felix Fietkau)\n- ipv6: mcast: Delay put pmc-idev in mld_del_delrec() (Yue Haibing) [Orabug: 38324325] {CVE-2025-38550}\n- net/mlx5: Correctly set gso_size when LRO is used (Christoph Paasch)\n- Bluetooth: btusb: QCA: Fix downloading wrong NVM for WCN6855 GF variant without board ID (Zijun Hu)\n- Bluetooth: hci_core: add missing braces when using macro parameters (Christian Eggers)\n- Bluetooth: SMP: Fix using HCI_ERROR_REMOTE_USER_TERM on timeout (Luiz Augusto von Dentz)\n- Bluetooth: SMP: If an unallowed command is received consider it a failure (Luiz Augusto von Dentz)\n- Bluetooth: hci_sync: fix connectable extended advertising when using static random address (Alessandro Gasbarroni)\n- Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb() (Kuniyuki Iwashima) [Orabug: 38254239] {CVE-2025-38473}\n- riscv: traps_misaligned: properly sign extend value in misaligned load handler (Andreas Schwab)\n- riscv: Enable interrupt during exception handling (Nam Cao)\n- loop: use kiocb helpers to fix lockdep warning (Ming Lei)\n- usb: net: sierra: check for no status endpoint (Oliver Neukum) [Orabug: 38254247] {CVE-2025-38474}\n- ice: check correct pointer in fwlog debugfs (Michal Swiatkowski)\n- ice: add NULL check in eswitch lag check (Dave Ertman) [Orabug: 38324213] {CVE-2025-38526}\n- hwmon: (corsair-cpro) Validate the size of the received input buffer (Marius Zachmann) [Orabug: 38324317] {CVE-2025-38548}\n- selftests: net: increase inter-packet timeout in udpgro.sh (Paolo Abeni)\n- can: tcan4x5x: fix reset gpio usage during probe (Brett Werling)\n- can: tcan4x5x: add option for selecting nWKRQ voltage (Sean Nyekjaer)\n- wifi: cfg80211: remove scan request n_channels counted_by (Johannes Berg)\n- nvmet-tcp: fix callback lock for TLS handshake (Maurizio Lombardi)\n- nvme: fix misaccounting of nvme-mpath inflight I/O (Yu Kuai)\n- net: phy: Don't register LEDs for genphy (Sean Anderson) [Orabug: 38324260] {CVE-2025-38537}\n- smc: Fix various oops due to inet_sock type confusion. (Kuniyuki Iwashima) [Orabug: 38254256] {CVE-2025-38475}\n- nvme: fix endianness of command word prints in nvme_log_err_passthru() (John Garry)\n- nvme: fix inconsistent RCU list manipulation in nvme_ns_add_to_ctrl_list() (Zheng Qixing)\n- fix a leak in fcntl_dirnotify() (Al Viro)\n- smb: client: fix use-after-free in cifs_oplock_break (Wang Zhaolong) [Orabug: 38324216] {CVE-2025-38527}\n- rpl: Fix use-after-free in rpl_do_srh_inline(). (Kuniyuki Iwashima) [Orabug: 38254259] {CVE-2025-38476}\n- net/sched: sch_qfq: Fix race condition on qfq_aggregate (Xiang Mei) [Orabug: 38254264] {CVE-2025-38477}\n- block: fix kobject leak in blk_unregister_queue (Ming Lei)\n- net: emaclite: Fix missing pointer increment in aligned_read() (Alok Tiwari)\n- cachefiles: Fix the incorrect return value in __cachefiles_write() (Zizhi Wo)\n- selftests/sched_ext: Fix exit selftest hang on UP (Andrea Righi)\n- bpf: Reject %p% format string in bprintf-like helpers (Paul Chaignon) [Orabug: 38324225] {CVE-2025-38528}\n- arm64: dts: imx95: Correct the DMA interrupter number of pcie0_ep (Richard Zhu)\n- soundwire: amd: fix for clearing command status register (Vijendar Mukunda)\n- soundwire: amd: fix for handling slave alerts after link is down (Vijendar Mukunda)\n- arm64: dts: rockchip: Add cd-gpios for sdcard detect on Cool Pi 4B (Andy Yan)\n- arm64: dts: rockchip: Add cd-gpios for sdcard detect on Cool Pi CM5 (Andy Yan)\n- comedi: Fix initialization of data for instructions that write to subdevice (Ian Abbott) [Orabug: 38254270] {CVE-2025-38478}\n- comedi: Fix use of uninitialized data in insn_rw_emulate_bits() (Ian Abbott) [Orabug: 38254276] {CVE-2025-38480}\n- comedi: Fix some signed shift left operations (Ian Abbott)\n- comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large (Ian Abbott) [Orabug: 38254283] {CVE-2025-38481}\n- comedi: das6402: Fix bit shift out of bounds (Ian Abbott) [Orabug: 38254291] {CVE-2025-38482}\n- comedi: das16m1: Fix bit shift out of bounds (Ian Abbott) [Orabug: 38254299] {CVE-2025-38483}\n- comedi: aio_iiro_16: Fix bit shift out of bounds (Ian Abbott) [Orabug: 38324229] {CVE-2025-38529}\n- comedi: pcl812: Fix bit shift out of bounds (Ian Abbott) [Orabug: 38324236] {CVE-2025-38530}\n- iio: common: st_sensors: Fix use of uninitialize device structs (Maud Spierings) [Orabug: 38324242] {CVE-2025-38531}\n- iio: backend: fix out-of-bound write (Markus Burri) [Orabug: 38254383] {CVE-2025-38484}\n- iio: adc: stm32-adc: Fix race in installing chained IRQ handler (Chen Ni)\n- iio: adc: max1363: Reorder mode_list[] entries (Fabio Estevam)\n- iio: adc: max1363: Fix MAX1363_4X_CHANS/MAX1363_8X_CHANS[] (Fabio Estevam)\n- iio: adc: axp20x_adc: Add missing sentinel to AXP717 ADC channel maps (Chen-Yu Tsai) [Orabug: 38324314] {CVE-2025-38547}\n- iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush (Sean Nyekjaer) [Orabug: 38254306] {CVE-2025-38485}\n- soc: aspeed: lpc-snoop: Don't disable channels that aren't enabled (Andrew Jeffery)\n- soc: aspeed: lpc-snoop: Cleanup resources in stack-order (Andrew Jeffery)\n- smb: client: fix use-after-free in crypt_message when using async crypto (Wang Zhaolong) [Orabug: 38254322] {CVE-2025-38488}\n- s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again (Ilya Leoshkevich) [Orabug: 38254325] {CVE-2025-38489}\n- pmdomain: governor: Consider CPU latency tolerance from pm_domain_cpu_gov (Maulik Shah)\n- net: libwx: properly reset Rx ring descriptor (Jiawen Wu) [Orabug: 38324251] {CVE-2025-38532}\n- net: libwx: fix the using of Rx buffer DMA (Jiawen Wu) [Orabug: 38324253] {CVE-2025-38533}\n- net: libwx: remove duplicate page_pool_put_full_page() (Jiawen Wu) [Orabug: 38254327] {CVE-2025-38490}\n- net: stmmac: intel: populate entire system_counterval_t in get_time_fn() callback (Markus Blochl)\n- mmc: sdhci_am654: Workaround for Errata i2312 (Judith Mendez)\n- mmc: sdhci-pci: Quirk for broken command queuing on Intel GLK-based Positivo models (Edson Juliano Drosdeck)\n- mmc: bcm2835: Fix dma_unmap_sg() nents value (Thomas Fourier)\n- memstick: core: Zero initialize id_reg in h_memstick_read_dev_id() (Nathan Chancellor)\n- isofs: Verify inode mode when loading from disk (Jan Kara)\n- dmaengine: nbpfaxi: Fix memory corruption in probe() (Dan Carpenter) [Orabug: 38324262] {CVE-2025-38538}\n- cpuidle: psci: Fix cpuhotplug routine with PREEMPT_RT=y (Daniel Lezcano)\n- Bluetooth: btintel: Check if controller is ISO capable on btintel_classify_pkt_type (Luiz Augusto von Dentz)\n- af_packet: fix soft lockup issue caused by tpacket_snd() (Yun Lu)\n- af_packet: fix the SO_SNDTIMEO constraint not effective on tpacked_snd() (Yun Lu)\n- arm64: dts: rockchip: use cs-gpios for spi1 on ringneck (Jakob Unterwurzacher)\n- arm64: dts: imx8mp-venice-gw73xx: fix TPM SPI frequency (Tim Harvey)\n- arm64: dts: imx8mp-venice-gw72xx: fix TPM SPI frequency (Tim Harvey)\n- arm64: dts: imx8mp-venice-gw71xx: fix TPM SPI frequency (Tim Harvey)\n- arm64: dts: freescale: imx8mm-verdin: Keep LDO5 always on (Francesco Dolcini)\n- arm64: dts: add big-endian property back into watchdog node (Meng Li)\n- arm64: dts: imx8mp-venice-gw74xx: fix TPM SPI frequency (Tim Harvey)\n- net/mlx5: Update the list of the PCI supported devices (Maor Gottlieb)\n- phonet/pep: Move call to pn_skb_get_dst_sockaddr() earlier in pep_sock_accept() (Nathan Chancellor)\n- mptcp: reset fallback status gracefully at disconnect() time (Paolo Abeni)\n- mptcp: plug races between subflow fail and subflow creation (Paolo Abeni) [Orabug: 38324332] {CVE-2025-38552}\n- mptcp: make fallback action and fallback decision atomic (Paolo Abeni) [Orabug: 38254329] {CVE-2025-38491}\n- io_uring/poll: fix POLLERR handling (Pavel Begunkov)\n- ALSA: hda/realtek: Add quirk for ASUS ROG Strix G712LWS (Takashi Iwai)\n- ALSA: hda/realtek - Fix mute LED for HP Victus 16-r0xxx (Edip Hazuri)\n- drm/amd/display: Free memory allocation (Clayton King)\n- drm/amd/display: Disable CRTC degamma LUT for DCN401 (Melissa Wen)\n- drm/amdgpu: Increase reset counter only on success (Lijo Lazar)\n- drm/amdgpu/gfx8: reset compute ring wptr on the GPU on resume (Eeli Haapalainen)\n- objtool/rust: add one more noreturn Rust function for Rust 1.89.0 (Miguel Ojeda)\n- tracing/osnoise: Fix crash in timerlat_dump_stack() (Tomas Glozar) [Orabug: 38254335] {CVE-2025-38493}\n- tracing: Add down_write(trace_event_sem) when adding trace event (Steven Rostedt) [Orabug: 38324268] {CVE-2025-38539}\n- tracing/probes: Avoid using params uninitialized in parse_btf_arg() (Nathan Chancellor)\n- HID: core: do not bypass hid_hw_raw_request (Benjamin Tissoires) [Orabug: 38254338] {CVE-2025-38494}\n- HID: core: ensure __hid_request reserves the report ID as the first byte (Benjamin Tissoires)\n- HID: core: ensure the allocated report buffer can contain the reserved report ID (Benjamin Tissoires) [Orabug: 38254346] {CVE-2025-38495}\n- dm-bufio: fix sched in atomic context (Sheng Yong) [Orabug: 38254353] {CVE-2025-38496}\n- spi: Add check for 8-bit transfer with 8 IO mode support (Cheng Ming Lin)\n- pch_uart: Fix dma_sync_sg_for_device() nents value (Thomas Fourier)\n- Input: xpad - set correct controller type for Acer NGR200 (Nilton Perim Neto)\n- nvmem: layouts: u-boot-env: remove crc32 endianness conversion (Michael C. Pratt)\n- nvmem: imx-ocotp: fix MAC address byte length (Steffen Batz)\n- Revert 'staging: vchiq_arm: Create keep-alive thread during probe' (Stefan Wahren)\n- thunderbolt: Fix bit masking in tb_dp_port_set_hops() (Alok Tiwari)\n- thunderbolt: Fix wake on connect at runtime (Mario Limonciello)\n- i2c: stm32f7: unmap DMA mapped buffer (Clement Le Goffic)\n- i2c: stm32: fix the device used for the DMA map (Clement Le Goffic)\n- usb: gadget: configfs: Fix OOB read on empty string write (Xinyu Liu) [Orabug: 38254356] {CVE-2025-38497}\n- usb: dwc2: gadget: Fix enter to hibernation for UTMI+ PHY (Minas Harutyunyan)\n- usb: musb: fix gadget state on disconnect (Drew Hamilton)\n- USB: serial: ftdi_sio: add support for NDI EMGUIDE GEMINI (Ryan Mann)\n- USB: serial: option: add Foxconn T99W640 (Slark Xiao)\n- USB: serial: option: add Telit Cinterion FE910C04 (ECM) composition (Fabio Porcedda)\n- phy: tegra: xusb: Disable periodic tracking on Tegra234 (Haotien Hsu)\n- phy: tegra: xusb: Decouple CYA_TRK_CODE_UPDATE_ON_IDLE from trk_hw_mode (Wayne Chang)\n- phy: tegra: xusb: Fix unbalanced regulator disable in UTMI PHY mode (Wayne Chang) [Orabug: 38324256] {CVE-2025-38535}\n- LTS version: v6.12.39 (Jack Vogel)\n- KVM: SVM: Set synthesized TSA CPUID flags (Borislav Petkov)\n- rseq: Fix segfault on registration when rseq_cs is non-zero (Michael Jeanson) [Orabug: 38095070] {CVE-2025-38067}\n- crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP() (Lukas Wunner) [Orabug: 37977089] {CVE-2025-37984}\n- arm64: Filter out SME hwcaps when FEAT_SME isn't implemented (Mark Brown)\n- ksmbd: fix potential use-after-free in oplock/lease break ack (Namjae Jeon) [Orabug: 38254080] {CVE-2025-38437}\n- kasan: remove kasan_find_vm_area() to prevent possible deadlock (Levi Yun) [Orabug: 38324146] {CVE-2025-38510}\n- net: wangxun: revert the adjustment of the IRQ vector sequence (Jiawen Wu)\n- erofs: fix rare pcluster memory leak after unmounting (Gao Xiang)\n- selftests/bpf: adapt one more case in test_lru_map to the new target_free (Willem de Bruijn)\n- HID: nintendo: avoid bluetooth suspend/resume stalls (Daniel J. Ogorchock) [Orabug: 38324137] {CVE-2025-38507}\n- HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras (Chia-Lin Kao) [Orabug: 38324277] {CVE-2025-38540}\n- HID: Add IGNORE quirk for SMARTLINKTECHNOLOGY (Zhang Heng)\n- riscv: vdso: Exclude .rodata from the PT_DYNAMIC segment (Fangrui Song)\n- bpf: Adjust free target to avoid global starvation of LRU map (Willem de Bruijn)\n- vt: add missing notification when switching back to text mode (Nicolas Pitre)\n- btrfs: fix assertion when building free space tree (Filipe Manana) [Orabug: 38324119] {CVE-2025-38503}\n- net: mana: Record doorbell physical address in PF mode (Long Li)\n- HID: lenovo: Add support for ThinkPad X1 Tablet Thin Keyboard Gen2 (Akira Inoue)\n- driver: bluetooth: hci_qca:fix unable to load the BT driver (Shuai Zhang)\n- net: usb: qmi_wwan: add SIMCom 8230C composition (Xiaowei Li)\n- ALSA: hda/realtek: Add quirks for some Clevo laptops (Tim Crawford)\n- ALSA: hda/realtek - Enable mute LED on HP Pavilion Laptop 15-eg100 (Yasmin Fitzgerald)\n- ASoC: amd: yc: add quirk for Acer Nitro ANV15-41 internal mic (Yuzuru)\n- io_uring: make fallocate be hashed work (Fengnan Chang)\n- ALSA: hda/realtek: Add mic-mute LED setup for ASUS UM5606 (Takashi Iwai)\n- ASoC: SOF: Intel: hda: Use devm_kstrdup() to avoid memleak. (Tamura Dai) [Orabug: 38254084] {CVE-2025-38438}\n- um: vector: Reduce stack usage in vector_eth_configure() (Tiwei Bie)\n- atm: idt77252: Add missing dma_map_error() (Thomas Fourier)\n- ublk: sanity check add_dev input for underflow (Ronnie Sahlberg)\n- bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT (Somnath Kotur) [Orabug: 38254088] {CVE-2025-38439}\n- bnxt_en: Fix DCB ETS validation (Shravya Kn)\n- net: ll_temac: Fix missing tx_pending check in ethtools_set_ringparam() (Alok Tiwari)\n- net/mlx5e: Add new prio for promiscuous mode (Jianbo Liu)\n- net/mlx5e: Fix race between DIM disable and net_dim() (Carolina Jubran) [Orabug: 38254092] {CVE-2025-38440}\n- can: m_can: m_can_handle_lost_msg(): downgrade msg lost in rx message to debug level (Sean Nyekjaer)\n- drm/xe/pm: Correct comment of xe_pm_set_vram_threshold() (Shuicheng Lin)\n- selftests: net: lib: fix shift count out of range (Hangbin Liu)\n- selftests: net: lib: Move logging from forwarding/lib.sh here (Petr Machata)\n- net: phy: microchip: limit 100M workaround to link-down events on LAN88xx (Oleksij Rempel)\n- net: phy: microchip: Use genphy_soft_reset() to purge stale LPA bits (Oleksij Rempel)\n- ibmvnic: Fix hardcoded NUM_RX_STATS/NUM_TX_STATS with dynamic sizeof (Mingming Cao)\n- net: appletalk: Fix device refcount leak in atrtr_create() (Kito Xu) [Orabug: 38324288] {CVE-2025-38542}\n- netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() (Eric Dumazet) [Orabug: 38254094] {CVE-2025-38441}\n- erofs: fix to add missing tracepoint in erofs_readahead() (Chao Yu)\n- erofs: refine readahead tracepoint (Gao Xiang)\n- erofs: tidy up zdata.c (Gao Xiang)\n- erofs: get rid of z_erofs_next_pcluster_t (Gao Xiang)\n- erofs: free pclusters if no cached folio is attached (Chunhai Guo)\n- drm/xe/pf: Clear all LMTT pages on alloc (Michal Wajdeczko) [Orabug: 38324148] {CVE-2025-38511}\n- nbd: fix uaf in nbd_genl_connect() error path (Zheng Qixing) [Orabug: 38254100] {CVE-2025-38443}\n- wifi: mt76: mt7925: Fix null-ptr-deref in mt7925_thermal_init() (Henry Martin) [Orabug: 38324286] {CVE-2025-38541}\n- drm/nouveau/gsp: fix potential leak of memory used during acpi init (Ben Skeggs)\n- wifi: rt2x00: fix remove callback type mismatch (Felix Fietkau)\n- wifi: mac80211: fix non-transmitted BSSID profile search (Johannes Berg)\n- wifi: mac80211: correctly identify S1G short beacon (Lachlan Hodges)\n- raid10: cleanup memleak at raid10_make_request (Nigel Croxon) [Orabug: 38254103] {CVE-2025-38444}\n- md/raid1: Fix stack memory use after return in raid1_reshape (Wang Jinchao) [Orabug: 38254107] {CVE-2025-38445}\n- drm/tegra: nvdec: Fix dma_alloc_coherent error check (Mikko Perttunen) [Orabug: 38324294] {CVE-2025-38543}\n- wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev() (Daniil Dulov) [Orabug: 38324159] {CVE-2025-38513}\n- wifi: cfg80211: fix S1G beacon head validation in nl80211 (Lachlan Hodges)\n- netfs: Fix ref leak on inserted extra subreq in write retry (David Howells)\n- netlink: make sure we allow at least one dump skb (Jakub Kicinski)\n- netlink: Fix rmem check in netlink_broadcast_deliver(). (Kuniyuki Iwashima)\n- ASoC: Intel: sof-function-topology-lib: Print out the unsupported dmic count (Peter Ujfalusi)\n- erofs: address D-cache aliasing (Gao Xiang)\n- erofs: fix to add missing tracepoint in erofs_read_folio() (Chao Yu)\n- ksmbd: fix a mount write count leak in ksmbd_vfs_kern_path_locked() (Al Viro)\n- smb: server: make use of rdma_destroy_qp() (Stefan Metzmacher)\n- clk: scmi: Handle case where child clocks are initialized before their parents (Sascha Hauer)\n- x86/mm: Disable hugetlb page table sharing on 32-bit (Jann Horn)\n- x86/rdrand: Disable RDSEED on AMD Cyan Skillfish (Mikhail Paulyshka)\n- clk: imx: Fix an out-of-bounds access in dispmix_csr_clk_dev_data (Xiaolei Wang) [Orabug: 38254112] {CVE-2025-38446}\n- rust: init: allow dead_code warnings for Rust = 1.89.0 (Miguel Ojeda)\n- lib/alloc_tag: do not acquire non-existent lock in alloc_tag_top_users() (Harry Yoo) [Orabug: 38324192] {CVE-2025-38517}\n- mm/vmalloc: leave lazy MMU mode on PTE mapping error (Alexander Gordeev)\n- scripts/gdb: fix interrupts.py after maple tree conversion (Florian Fainelli)\n- scripts/gdb: de-reference per-CPU MCE interrupts (Florian Fainelli)\n- scripts/gdb: fix interrupts display after MCP on x86 (Florian Fainelli)\n- mm: fix the inaccurate memory statistics issue for users (Baolin Wang)\n- maple_tree: fix mt_destroy_walk() on root leaf node (Wei Yang)\n- kallsyms: fix build without execinfo (Achill Gilgenast)\n- Revert 'PCI/ACPI: Fix allocated memory release on error in pci_acpi_scan_root()' (Zhe Qiao)\n- Revert 'ACPI: battery: negate current when discharging' (Rafael J. Wysocki)\n- drm/xe: Allocate PF queue size on pow2 boundary (Matthew Brost)\n- drm/framebuffer: Acquire internal references on GEM handles (Thomas Zimmermann)\n- Revert 'usb: gadget: u_serial: Add null pointer check in gs_start_io' (Kuen-Han Tsai)\n- usb: gadget: u_serial: Fix race condition in TTY wakeup (Kuen-Han Tsai) [Orabug: 38254116] {CVE-2025-38448}\n- Revert 'drm/xe/xe2: Enable Indirect Ring State support for Xe2' (Matthew Brost)\n- drm/xe/bmg: fix compressed VRAM handling (Matthew Auld)\n- drm/gem: Fix race in drm_gem_handle_create_tail() (Simona Vetter)\n- drm/ttm: fix error handling in ttm_buffer_object_transfer (Christian Konig)\n- drm/sched: Increment job count before swapping tail spsc queue (Matthew Brost) [Orabug: 38324178] {CVE-2025-38515}\n- drm/gem: Acquire references on GEM handles for framebuffers (Thomas Zimmermann) [Orabug: 38254122] {CVE-2025-38449}\n- drm/amdkfd: Don't call mmput from MMU notifier callback (Philip Yang) [Orabug: 38324196] {CVE-2025-38520}\n- drm/imagination: Fix kernel crash when hard resetting the GPU (Alessio Belle) [Orabug: 38324199] {CVE-2025-38521}\n- wifi: mt76: mt7925: fix invalid array index in ssid assignment during hw scan (Michael Lo)\n- wifi: mt76: mt7925: fix the wrong config for tx interrupt (Ming Yen Hsieh)\n- wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_sta_set_decap_offload() (Deren Wu) [Orabug: 38254130] {CVE-2025-38450}\n- wifi: mt76: mt7921: prevent decap offload config before STA initialization (Deren Wu)\n- wifi: mwifiex: discard erroneous disassoc frames on STA interface (Vitor Soares) [Orabug: 38324132] {CVE-2025-38505}\n- wifi: prevent A-MSDU attacks in mesh networks (Mathy Vanhoef) [Orabug: 38324151] {CVE-2025-38512}\n- pwm: mediatek: Ensure to disable clocks in error path (Uwe Kleine-Konig)\n- pwm: Fix invalid state detection (Uwe Kleine-Konig)\n- pinctrl: qcom: msm: mark certain pins as invalid for interrupts (Bartosz Golaszewski) [Orabug: 38324184] {CVE-2025-38516}\n- net: ethernet: rtsn: Fix a null pointer dereference in rtsn_probe() (Haoxiang Li) [Orabug: 38254133] {CVE-2025-38452}\n- gre: Fix IPv6 multicast route creation. (Guillaume Nault)\n- ASoC: fsl_sai: Force a software reset when starting in consumer mode (Arun Raghavan)\n- ALSA: ad1816a: Fix potential NULL pointer deref in snd_card_ad1816a_pnp() (Thorsten Blum) [Orabug: 38254137] {CVE-2025-38454}\n- KVM: Allow CPU to reschedule while setting per-page memory attributes (Liam Merwick) [Orabug: 38324134] {CVE-2025-38506}\n- KVM: SVM: Reject SEV{-ES} intra host migration if vCPU creation is in-flight (Sean Christopherson) [Orabug: 38254139] {CVE-2025-38455}\n- KVM: SVM: Add missing member in SNP_LAUNCH_START command structure (Nikunj A Dadhania)\n- KVM: x86/xen: Allow 'out of range' event channel ports in IRQ routing table. (David Woodhouse)\n- x86/mce: Make sure CMCI banks are cleared during shutdown on Intel (Jp Kobryn)\n- x86/mce: Ensure user polling settings are honored when restarting timer (Yazen Ghannam)\n- x86/mce: Don't remove sysfs if thresholding sysfs init fails (Yazen Ghannam)\n- x86/mce/amd: Fix threshold limit reset (Yazen Ghannam)\n- x86/mce/amd: Add default names for MCA banks and blocks (Yazen Ghannam)\n- ipmi:msghandler: Fix potential memory corruption in ipmi_create_user() (Dan Carpenter) [Orabug: 38254142] {CVE-2025-38456}\n- rxrpc: Fix oops due to non-existence of prealloc backlog struct (David Howells) [Orabug: 38324168] {CVE-2025-38514}\n- rxrpc: Fix bug due to prealloc collision (David Howells) [Orabug: 38324296] {CVE-2025-38544}\n- net/sched: Abort __tc_modify_qdisc if parent class does not exist (Victor Nogueira) [Orabug: 38254145] {CVE-2025-38457}\n- net: ethernet: ti: am65-cpsw-nuss: Fix skb size by accounting for skb_shared_info (Chintan Vankar) [Orabug: 38324304] {CVE-2025-38545}\n- atm: clip: Fix NULL pointer dereference in vcc_sendmsg() (Yue Haibing) [Orabug: 38254151] {CVE-2025-38458}\n- atm: clip: Fix infinite recursive call of clip_push(). (Kuniyuki Iwashima) [Orabug: 38254159] {CVE-2025-38459}\n- atm: clip: Fix memory leak of struct clip_vcc. (Kuniyuki Iwashima) [Orabug: 38324307] {CVE-2025-38546}\n- atm: clip: Fix potential null-ptr-deref in to_atmarpd(). (Kuniyuki Iwashima) [Orabug: 38254165] {CVE-2025-38460}\n- net: phy: smsc: Fix link failure in forced mode with Auto-MDIX (Oleksij Rempel)\n- net: phy: smsc: Force predictable MDI-X state on LAN87xx (Oleksij Rempel)\n- net: phy: smsc: Fix Auto-MDIX configuration when disabled by strap (Oleksij Rempel)\n- net: stmmac: Fix interrupt handling for level-triggered mode in DWC_XGMAC2 (Ericchan)\n- vsock: Fix IOCTL_VM_SOCKETS_GET_LOCAL_CID to check also transport_local (Michal Luczaj)\n- vsock: Fix transport_* TOCTOU (Michal Luczaj) [Orabug: 38254171] {CVE-2025-38461}\n- vsock: Fix transport_{g2h,h2g} TOCTOU (Michal Luczaj) [Orabug: 38254174] {CVE-2025-38462}\n- tcp: Correct signedness in skb remaining space calculation (Jiayuan Chen) [Orabug: 38254177] {CVE-2025-38463}\n- tipc: Fix use-after-free in tipc_conn_close(). (Kuniyuki Iwashima) [Orabug: 38254179] {CVE-2025-38464}\n- vsock: fix vsock_proto declaration (Stefano Garzarella)\n- netlink: Fix wraparounds of sk-sk_rmem_alloc. (Kuniyuki Iwashima) [Orabug: 38254186] {CVE-2025-38465}\n- net: phy: qcom: qca808x: Fix WoL issue by utilizing at8031_set_wol() (Luo Jie)\n- net: phy: qcom: move the WoL function to shared library (Luo Jie)\n- arm64: poe: Handle spurious Overlay faults (Kevin Brodsky)\n- bnxt_en: eliminate the compile warning in bnxt_request_irq due to CONFIG_RFS_ACCEL (Jason Xing)\n- sched/deadline: Fix dl_server runtime calculation formula (Kuyo Chang)\n- fix proc_sys_compare() handling of in-lookup dentries (Al Viro)\n- pinctrl: amd: Clear GPIO debounce for suspend (Mario Limonciello)\n- Bluetooth: hci_event: Fix not marking Broadcast Sink BIS as connected (Luiz Augusto von Dentz)\n- Bluetooth: hci_sync: Fix not disabling advertising instance (Luiz Augusto von Dentz)\n- ASoC: cs35l56: probe() should fail if the device ID is not recognized (Richard Fitzgerald)\n- perf: Revert to requiring CAP_SYS_ADMIN for uprobes (Peter Zijlstra) [Orabug: 38254195] {CVE-2025-38466}\n- sched/core: Fix migrate_swap() vs. hotplug (Peter Zijlstra)\n- irqchip/irq-msi-lib: Select CONFIG_GENERIC_MSI_IRQ (Nam Cao)\n- perf/core: Fix the WARN_ON_ONCE is out of lock protected region (Luo Gengkun)\n- ASoC: Intel: soc-acpi: arl: Correct order of cs42l43 matches (Charles Keepax)\n- ASoC: Intel: soc-acpi-intel-arl-match: set get_function_tplg_files ops (Bard Liao)\n- ASoC: Intel: add sof_sdw_get_tplg_files ops (Bard Liao)\n- ASoC: soc-acpi: add get_function_tplg_files ops (Bard Liao)\n- ASoC: Intel: soc-acpi: arl: Add match entries for new cs42l43 laptops (Simon Trimmer)\n- ASoC: Intel: soc-acpi: arl: Correct naming of a cs35l56 address struct (Simon Trimmer)\n- ASoC: Intel: SND_SOC_INTEL_SOF_BOARD_HELPERS select SND_SOC_ACPI_INTEL_MATCH (Bard Liao)\n- ASoC: fsl_asrc: use internal measured ratio for non-ideal ratio mode (Shengjiu Wang)\n- drm/amdgpu: Replace Mutex with Spinlock for RLCG register access to avoid Priority Inversion in SRIOV (Srinivasan Shanmugam) [Orabug: 37855415] {CVE-2025-38104}\n- crypto: s390/sha - Fix uninitialized variable in SHA-1 and SHA-2 (Eric Biggers)\n- drm/amdgpu/ip_discovery: add missing ip_discovery fw (Flora Cui)\n- drm/amdgpu/discovery: use specific ip_discovery.bin for legacy asics (Flora Cui)\n- drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling (Kaustabh Chakraborty) [Orabug: 38254201] {CVE-2025-38467}\n- eventpoll: don't decrement ep refcount while still holding the ep mutex (Linus Torvalds) [Orabug: 38209551] {CVE-2025-38349}\n- LTS version: v6.12.38 (Jack Vogel)\n- x86/CPU/AMD: Properly check the TSA microcode (Borislav Petkov)\n- LTS version: v6.12.37 (Jack Vogel)\n- x86/process: Move the buffer clearing before MONITOR (Borislav Petkov)\n- x86/microcode/AMD: Add TSA microcode SHAs (Borislav Petkov)\n- KVM: SVM: Advertise TSA CPUID bits to guests (Borislav Petkov)\n- x86/bugs: Add a Transient Scheduler Attacks mitigation (Borislav Petkov) [Orabug: 38023239,38129827] {CVE-2024-36350,CVE-2024-36357}\n- x86/bugs: Rename MDS machinery to something more generic (Borislav Petkov) [Orabug: 38023239,38129827] {CVE-2024-36350,CVE-2024-36357}\n- x86/idle: Remove MFENCEs for X86_BUG_CLFLUSH_MONITOR in mwait_idle_with_hints() and prefer_mwait_c1_over_halt() (Andrew Cooper) [Orabug: 38264060]\n- Revert 'x86/bugs: Rename MDS machinery to something more generic' (Boris Ostrovsky) [Orabug: 38264060]\n- Revert 'x86/bugs: Add a Transient Scheduler Attacks mitigation' (Boris Ostrovsky) [Orabug: 38264060]\n- Revert 'KVM: SVM: Advertize TSA CPUID bits to guests' (Boris Ostrovsky) [Orabug: 38264060]\n- Revert 'x86/process: Move the buffer clearing before MONITOR' (Boris Ostrovsky) [Orabug: 38264060]\n- Revert 'Add Zen34 clients' (Boris Ostrovsky) [Orabug: 38264060]\n- Revert 'x86/idle: Remove MFENCEs for X86_BUG_CLFLUSH_MONITOR in mwait_idle_with_hints() and prefer_mwait_c1_over_halt()' (Boris Ostrovsky) [Orabug: 38264060]\n- mm: userfaultfd: fix race of userfaultfd_move and swap cache (Kairui Song) [Orabug: 38175034] {CVE-2025-38242}\n- mm/vmalloc: fix data race in show_numa_info() (Jeongjun Park) [Orabug: 38253860] {CVE-2025-38383}\n- powerpc/kernel: Fix ppc_save_regs inclusion in build (Madhavan Srinivasan)\n- usb: typec: displayport: Fix potential deadlock (Andrei Kuchynski) [Orabug: 38254393] {CVE-2025-38404}\n- platform/x86: think-lmi: Fix sysfs group cleanup (Kurt Borja)\n- platform/x86: think-lmi: Fix kobject cleanup (Kurt Borja)\n- platform/x86: think-lmi: Create ksets consecutively (Kurt Borja)\n- riscv: cpu_ops_sbi: Use static array for boot_data (Vivian Wang) [Orabug: 38253953] {CVE-2025-38407}\n- powercap: intel_rapl: Do not change CLAMPING bit if ENABLE bit cannot be changed (Zhang Rui)\n- iommu/rockchip: prevent iommus dead loop when two masters share one IOMMU (Simon Xue)\n- optee: ffa: fix sleep in atomic context (Jens Wiklander) [Orabug: 38253830] {CVE-2025-38374}\n- Logitech C-270 even more broken (Oliver Neukum)\n- i2c/designware: Fix an initialization issue (Michael J. Ruhl) [Orabug: 38253849] {CVE-2025-38380}\n- dma-buf: fix timeout handling in dma_resv_wait_timeout v2 (Christian Konig)\n- cifs: all initializations for tcon should happen in tcon_info_alloc (Shyam Prasad N)\n- smb: client: fix readdir returning wrong type with POSIX extensions (Philipp Kerling)\n- usb: acpi: fix device link removal (Krogerus Heikki)\n- usb: chipidea: udc: disconnect/reconnect from host when do suspend/resume (Xu Yang) [Orabug: 38253838] {CVE-2025-38376}\n- usb: dwc3: Abort suspend on soft disconnect failure (Kuen-Han Tsai)\n- usb: cdnsp: Fix issue with CV Bad Descriptor test (Pawel Laszczak)\n- usb: cdnsp: do not disable slot for disabled slot (Peter Chen)\n- Input: iqs7222 - explicitly define number of external channels (Jeff Labundy)\n- Input: xpad - support Acer NGR 200 Controller (Nilton Perim Neto)\n- xhci: Disable stream for xHC controller with XHCI_BROKEN_STREAMS (Hongyu Xie)\n- xhci: dbc: Flush queued requests before stopping dbc (Mathias Nyman)\n- xhci: dbctty: disable ECHO flag by default (Lukasz Bartosik)\n- usb: xhci: quirk for data loss in ISOC transfers (Raju Rangoju)\n- Revert 'usb: xhci: Implement xhci_handshake_check_state() helper' (Roy Luo)\n- usb: xhci: Skip xhci_reset in xhci_resume if xhci is being removed (Roy Luo)\n- NFSv4/flexfiles: Fix handling of NFS level errors in I/O (Trond Myklebust)\n- drm/xe: Allow dropping kunit dependency as built-in (Harry Austen)\n- drm/xe/bmg: Update Wa_22019338487 (Vinay Belgaumkar)\n- IB/mlx5: Fix potential deadlock in MR deregistration (Or Har-Toov) [Orabug: 38253826] {CVE-2025-38373}\n- RDMA/mlx5: Fix cache entry update on dereg error (Michael Guralnik)\n- fs: export anon_inode_make_secure_inode() and fix secretmem LSM bypass (Shivank Garg) [Orabug: 38253909] {CVE-2025-38396}\n- module: Provide EXPORT_SYMBOL_GPL_FOR_MODULES() helper (Peter Zijlstra)\n- add a string-to-qstr constructor (Al Viro)\n- rcu: Return early if callback is not specified (Uladzislau Rezki)\n- mtd: spinand: fix memory leak of ECC engine conf (Pablo Martin-Gomez) [Orabug: 38253862] {CVE-2025-38384}\n- ACPICA: Refuse to evaluate a method if arguments are missing (Rafael J. Wysocki) [Orabug: 38253873] {CVE-2025-38386}\n- wifi: ath6kl: remove WARN on bad firmware input (Johannes Berg) [Orabug: 38253944] {CVE-2025-38406}\n- wifi: mac80211: drop invalid source address OCB frames (Johannes Berg)\n- aoe: defer rexmit timer downdev work to workqueue (Justin Sanders)\n- scsi: target: Fix NULL pointer dereference in core_scsi3_decode_spec_i_port() (Maurizio Lombardi) [Orabug: 38253913] {CVE-2025-38399}\n- regulator: fan53555: add enable_time support and soft-start times (Heiko Stuebner)\n- ASoC: amd: yc: update quirk data for HP Victus (Raven Black)\n- powerpc: Fix struct termio related ioctl macros (Madhavan Srinivasan)\n- genirq/irq_sim: Initialize work context pointers properly (Gyeyoung Baek) [Orabug: 38253955] {CVE-2025-38408}\n- platform/x86/amd/pmc: Add PCSpecialist Lafite Pro V 14M to 8042 quirks list (Mario Limonciello)\n- ASoC: amd: yc: Add quirk for MSI Bravo 17 D7VF internal mic (Gabriel Santese)\n- ata: pata_cs5536: fix build on 32-bit UML (Johannes Berg)\n- ata: libata-acpi: Do not assume 40 wire cable if no devices are enabled (Tasos Sahanidis)\n- ALSA: sb: Force to disable DMAs once when DMA mode is changed (Takashi Iwai)\n- ALSA: sb: Don't allow changing the DMA mode during operations (Takashi Iwai)\n- drm/msm: Fix another leak in the submit error path (Rob Clark) [Orabug: 38253959] {CVE-2025-38409}\n- drm/msm: Fix a fence leak in submit error path (Rob Clark) [Orabug: 38253966] {CVE-2025-38410}\n- scsi: lpfc: Restore clearing of NLP_UNREG_INP in ndlp-nlp_flag (Ewan D. Milne)\n- sched_ext: Make scx_group_set_weight() always update tg-scx.weight (Tejun Heo)\n- drm/amdgpu/mes: add missing locking in helper functions (Alex Deucher)\n- arm64: dts: qcom: x1e80100-crd: mark l12b and l15b always-on (Johan Hovold)\n- drm/amd/display: Add more checks for DSC / HUBP ONO guarantees (Nicholas Kazlauskas) [Orabug: 38253787] {CVE-2025-38360}\n- drm/amdgpu: add kicker fws loading for gfx11/smu13/psp13 (Frank Min)\n- drm/i915/dp_mst: Work around Thunderbolt sink disconnect after SINK_COUNT_ESI read (Imre Deak)\n- drm/amdgpu: VCN v5_0_1 to prevent FW checking RB during DPG pause (Sonny Jiang)\n- drm/simpledrm: Do not upcast in release helpers (Thomas Zimmermann)\n- selinux: change security_compute_sid to return the ssid or tsid on match (Stephen Smalley)\n- drm/xe/guc: Explicitly exit CT safe mode on unwind (Michal Wajdeczko) [Orabug: 38253775] {CVE-2025-38356}\n- drm/xe/guc: Dead CT helper (John Harrison)\n- drm/xe: Replace double space with single space after comma (Gote, Nitin R)\n- drm/xe: move DPT l2 flush to a more sensible place (Matthew Auld)\n- drm/xe: Allow bo mapping on multiple ggtts (Niranjana Vishwanathapura)\n- drm/xe: add interface to request physical alignment for buffer objects (Juha-Pekka Heikkila)\n- drm/xe: Move DSB l2 flush to a more sensible place (Maarten Lankhorst)\n- drm/xe: Fix DSB buffer coherency (Maarten Lankhorst)\n- mfd: exynos-lpass: Fix another error handling path in exynos_lpass_probe() (Christophe Jaillet)\n- netfs: Fix oops in write-retry from mis-resetting the subreq iterator (David Howells) [Orabug: 38153033] {CVE-2025-38139}\n- remoteproc: k3-r5: Refactor sequential core power up/down operations (Beleswar Padhi)\n- remoteproc: k3-r5: Use devm_rproc_add() helper (Beleswar Padhi)\n- remoteproc: k3-r5: Use devm_ioremap_wc() helper (Beleswar Padhi)\n- remoteproc: k3-r5: Use devm_kcalloc() helper (Beleswar Padhi)\n- remoteproc: k3-r5: Add devm action to release reserved memory (Beleswar Padhi)\n- remoteproc: k3: Call of_node_put(rmem_np) only once in three functions (Markus Elfring)\n- ubsan: integer-overflow: depend on BROKEN to keep this out of CI (Kees Cook)\n- arm64: dts: qcom: sm8650: add the missing l2 cache node (Pengyu Luo)\n- arm64: dts: renesas: white-hawk-single: Improve Ethernet TSN description (Geert Uytterhoeven)\n- arm64: dts: renesas: Factor out White Hawk Single board support (Geert Uytterhoeven)\n- arm64: dts: renesas: Use interrupts-extended for Ethernet PHYs (Geert Uytterhoeven)\n- arm64: dts: qcom: sm8650: Fix domain-idle-state for CPU2 (Luca Weiss)\n- arm64: dts: qcom: sm8650: change labels to lower-case (Krzysztof Kozlowski)\n- bpf: Do not include stack ptr register in precision backtracking bookkeeping (Yonghong Song) [Orabug: 38180467] {CVE-2025-38279}\n- bpf: use common instruction history across all states (Andrii Nakryiko)\n- hisi_acc_vfio_pci: bugfix the problem of uninstalling driver (Longfang Liu)\n- hisi_acc_vfio_pci: bugfix cache write-back issue (Longfang Liu)\n- scsi: lpfc: Avoid potential ndlp use-after-free in dev_loss_tmo_callbk (Justin Tee) [Orabug: 38180503] {CVE-2025-38289}\n- f2fs: zone: fix to calculate first_zoned_segno correctly (Chao Yu)\n- f2fs: zone: introduce first_zoned_segno in f2fs_sb_info (Chao Yu)\n- f2fs: decrease spare area for pinned files for zoned devices (Daeho Jeong)\n- iommu: ipmmu-vmsa: avoid Wformat-security warning (Arnd Bergmann)\n- RDMA/rxe: Fix 'trying to register non-static key in rxe_qp_do_cleanup' bug (Zhu Yanjun)\n- wifi: ath12k: fix wrong handling of CCMP256 and GCMP ciphers (Rameshkumar Sundaram)\n- wifi: ath12k: Handle error cases during extended skb allocation (P Praneesh)\n- wifi: ath12k: fix skb_ext_desc leak in ath12k_dp_tx() error path (Nicolas Escande)\n- bonding: Mark active offloaded xfrm_states (Cosmin Ratiu)\n- ACPI: thermal: Execute _SCP before reading trip points (Armin Wolf)\n- ACPI: thermal: Fix stale comment regarding trip points (Xueqin Luo)\n- ASoC: tas2764: Reinit cache on part reset (Martin Poviser)\n- ASoC: tas2764: Extend driver to SN012776 (Martin Poviser)\n- gfs2: Don't start unnecessary transactions during log flush (Andreas Gruenbacher)\n- gfs2: Move gfs2_trans_add_databufs (Andreas Gruenbacher)\n- sched/fair: Fixup wake_up_sync() vs DELAYED_DEQUEUE (Xuewen Yan)\n- sched/fair: Add new cfs_rq.h_nr_runnable (Vincent Guittot)\n- sched/fair: Rename h_nr_running into h_nr_queued (Vincent Guittot)\n- btrfs: fix wrong start offset for delalloc space release during mmap write (Filipe Manana)\n- btrfs: prepare btrfs_page_mkwrite() for large folios (Qu Wenruo)\n- gfs2: deallocate inodes in gfs2_create_inode (Andreas Gruenbacher)\n- gfs2: Move GIF_ALLOC_FAILED check out of gfs2_ea_dealloc (Andreas Gruenbacher)\n- gfs2: Move gfs2_dinode_dealloc (Andreas Gruenbacher)\n- gfs2: Replace GIF_DEFER_DELETE with GLF_DEFER_DELETE (Andreas Gruenbacher)\n- gfs2: Add GLF_PENDING_REPLY flag (Andreas Gruenbacher)\n- gfs2: Decode missing glock flags in tracepoints (Andreas Gruenbacher)\n- gfs2: Prevent inode creation race (Andreas Gruenbacher)\n- gfs2: Rename dinode_demise to evict_behavior (Andreas Gruenbacher)\n- gfs2: Rename GIF_{DEFERRED - DEFER}_DELETE (Andreas Gruenbacher)\n- gfs2: Initialize gl_no_formal_ino earlier (Andreas Gruenbacher)\n- kunit: qemu_configs: Disable faulting tests on 32-bit SPARC (David Gow)\n- kunit: qemu_configs: sparc: Explicitly enable CONFIG_SPARC32=y (Thomas Weissschuh)\n- kunit: qemu_configs: sparc: use Zilog console (Thomas Weissschuh)\n- crypto: zynqmp-sha - Add locking (Herbert Xu)\n- spinlock: extend guard with spinlock_bh variants (Christian Marangi)\n- crypto: iaa - Do not clobber req-base.data (Herbert Xu)\n- crypto: iaa - Remove dst_null support (Herbert Xu)\n- arm64: dts: rockchip: fix internal USB hub instability on RK3399 Puma (Lukasz Czechowski)\n- smb: client: fix race condition in negotiate timeout by using more precise timing (Wang Zhaolong)\n- amd-xgbe: do not double read link status (Raju Rangoju)\n- net/sched: Always pass notifications when child class becomes empty (Lion Ackermann) [Orabug: 38217337] {CVE-2025-38350}\n- nui: Fix dma_mapping_error() check (Thomas Fourier)\n- rose: fix dangling neighbour pointers in rose_rt_device_down() (Kohei Enju) [Orabug: 38253840] {CVE-2025-38377}\n- enic: fix incorrect MTU comparison in enic_change_mtu() (Alok Tiwari)\n- amd-xgbe: align CL37 AN sequence as per databook (Raju Rangoju)\n- lib: test_objagg: Set error message in check_expect_hints_stats() (Dan Carpenter)\n- netfs: Fix i_size updating (David Howells)\n- smb: client: set missing retry flag in cifs_writev_callback() (Paulo Alcantara)\n- smb: client: set missing retry flag in cifs_readv_callback() (Paulo Alcantara)\n- smb: client: set missing retry flag in smb2_writev_callback() (Paulo Alcantara)\n- igc: disable L1.2 PCI-E link substate to avoid performance issue (Vitaly Lifshits)\n- idpf: convert control queue mutex to a spinlock (Ahmed Zaki) [Orabug: 38253897] {CVE-2025-38392}\n- idpf: return 0 size for RSS key if not supported (Michal Swiatkowski) [Orabug: 38253932] {CVE-2025-38402}\n- drm/i915/gsc: mei interrupt top half should be in irq disabled context (Junxiao Chang)\n- drm/i915/gt: Fix timeline left held on VMA alloc error (Janusz Krzysztofik) [Orabug: 38253885] {CVE-2025-38389}\n- net: usb: lan78xx: fix WARN in __netif_napi_del_locked on disconnect (Oleksij Rempel) [Orabug: 38253870] {CVE-2025-38385}\n- smb: client: fix warning when reconnecting channel (Paulo Alcantara) [Orabug: 38254386] {CVE-2025-38379}\n- drm/bridge: aux-hpd-bridge: fix assignment of the of_node (Dmitry Baryshkov)\n- platform/mellanox: mlxreg-lc: Fix logic error in power state check (Alok Tiwari)\n- platform/x86: dell-wmi-sysman: Fix class device unregistration (Kurt Borja)\n- platform/x86: dell-sysman: Directly use firmware_attributes_class (Thomas Weissschuh)\n- platform/x86: think-lmi: Fix class device unregistration (Kurt Borja)\n- platform/x86: think-lmi: Directly use firmware_attributes_class (Thomas Weissschuh)\n- platform/x86: firmware_attributes_class: Simplify API (Thomas Weissschuh)\n- platform/x86: firmware_attributes_class: Move include linux/device/class.h (Thomas Weissschuh)\n- platform/x86: hp-bioscfg: Fix class device unregistration (Kurt Borja)\n- platform/x86: hp-bioscfg: Directly use firmware_attributes_class (Thomas Weissschuh)\n- platform/x86: dell-wmi-sysman: Fix WMI data block retrieval in sysfs callbacks (Kurt Borja) [Orabug: 38253975] {CVE-2025-38412}\n- nvmet: fix memory leak of bio integrity (Dmitry Bogdanov) [Orabug: 38253942] {CVE-2025-38405}\n- nvme: Fix incorrect cdw15 value in passthru error logging (Alok Tiwari)\n- drm/i915/selftests: Change mock_request() to return error pointers (Dan Carpenter)\n- spi: spi-fsl-dspi: Clear completion counter before initiating transfer (James Clark)\n- drm/exynos: fimd: Guard display clock control with runtime PM calls (Marek Szyprowski)\n- dpaa2-eth: fix xdp_rxq_info leak (Wangfushuai)\n- ethernet: atl1: Add missing DMA mapping error checks and count errors (Thomas Fourier)\n- btrfs: use btrfs_record_snapshot_destroy() during rmdir (Filipe Manana)\n- btrfs: propagate last_unlink_trans earlier when doing a rmdir (Filipe Manana)\n- btrfs: record new subvolume in parent dir earlier to avoid dir logging races (Filipe Manana)\n- btrfs: fix inode lookup error handling during log replay (Filipe Manana)\n- btrfs: fix invalid inode pointer dereferences during log replay (Filipe Manana) [Orabug: 38288149] {CVE-2025-38243}\n- btrfs: return a btrfs_inode from read_one_inode() (Filipe Manana)\n- btrfs: return a btrfs_inode from btrfs_iget_logging() (Filipe Manana)\n- btrfs: fix iteration of extrefs during log replay (Filipe Manana) [Orabug: 38253858] {CVE-2025-38382}\n- btrfs: fix missing error handling when searching for inode refs during log replay (Filipe Manana)\n- Bluetooth: Prevent unintended pause by checking if advertising is active (Yang Li)\n- platform/mellanox: nvsw-sn2201: Fix bus number in adapter error message (Alok Tiwari)\n- platform/mellanox: mlxbf-pmc: Fix duplicate event ID for CACHE_DATA1 (Alok Tiwari)\n- RDMA/mlx5: Fix vport loopback for MPV device (Patrisious Haddad) [Orabug: 38118599]\n- scsi: ufs: core: Fix spelling of a sysfs attribute name (Bart Van Assche)\n- scsi: sd: Fix VPD page 0xb7 length check (Jackysliu)\n- scsi: qla4xxx: Fix missing DMA mapping error in qla4xxx_alloc_pdu() (Thomas Fourier)\n- scsi: qla2xxx: Fix DMA mapping test in qla24xx_get_port_database() (Thomas Fourier)\n- NFSv4/pNFS: Fix a race to wake on NFS_LAYOUT_DRAIN (Benjamin Coddington) [Orabug: 38253899] {CVE-2025-38393}\n- nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init() fails. (Kuniyuki Iwashima) [Orabug: 38253921] {CVE-2025-38400}\n- RDMA/mlx5: Initialize obj_event-obj_sub_list before xa_insert (Mark Zhang) [Orabug: 38253879] {CVE-2025-38387}\n- RDMA/mlx5: Fix unsafe xarray access in implicit ODP handling (Or Har-Toov) [Orabug: 38253824] {CVE-2025-38372}\n- platform/mellanox: mlxbf-tmfifo: fix vring_desc.len assignment (David Thompson)\n- arm64: dts: apple: t8103: Fix PCIe BCM4377 nodename (Janne Grunau)\n- firmware: arm_ffa: Replace mutex with rwlock to avoid sleep in atomic context (Sudeep Holla) [Orabug: 38253883] {CVE-2025-38388}\n- firmware: arm_ffa: Move memory allocation outside the mutex locking (Sudeep Holla)\n- firmware: arm_ffa: Fix memory leak by freeing notifier callback node (Sudeep Holla) [Orabug: 38253890] {CVE-2025-38390}\n- drm/v3d: Disable interrupts before resetting the GPU (Maira Canal) [Orabug: 38253819] {CVE-2025-38371}\n- mtk-sd: reset host-mrq on prepare_data() error (Sergey Senozhatsky)\n- mtk-sd: Prevent memory corruption from DMA map failure (Masami Hiramatsu) [Orabug: 38253926] {CVE-2025-38401}\n- mtk-sd: Fix a pagefault in dma_unmap_sg() for not prepared data (Masami Hiramatsu)\n- usb: typec: altmodes/displayport: do not index invalid pin_assignments (Rd Babiera) [Orabug: 38253892] {CVE-2025-38391}\n- Input: cs40l50-vibra - fix potential NULL dereference in cs40l50_upload_owt() (Yunshui) [Orabug: 38253852] {CVE-2025-38381}\n- regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods (Manivannan Sadhasivam) [Orabug: 38253905] {CVE-2025-38395}\n- iommufd/selftest: Fix iommufd_dirty_tracking with large hugepage sizes (Nicolin Chen)\n- Bluetooth: MGMT: mesh_send: check instances prior disabling advertising (Christian Eggers)\n- Bluetooth: MGMT: set_mesh: update LE scan interval and window (Christian Eggers)\n- Bluetooth: hci_sync: revert some mesh modifications (Christian Eggers)\n- Bluetooth: HCI: Set extended advertising data synchronously (Christian Eggers)\n- mmc: core: sd: Apply BROKEN_SD_DISCARD quirk earlier (Avri Altman)\n- Revert 'mmc: sdhci: Disable SD card clock before changing parameters' (Ulf Hansson)\n- mmc: sdhci: Add a helper function for dump register in dynamic debug mode (Victor Shih)\n- net: libwx: fix the incorrect display of the queue number (Jiawen Wu)\n- vsock/vmci: Clear the vmci transport packet properly when initializing it (Harshavardhana S A) [Orabug: 38253935] {CVE-2025-38403}\n- net: txgbe: request MISC IRQ in ndo_open (Jiawen Wu)\n- s390/pci: Do not try re-enabling load/store if device is disabled (Niklas Schnelle)\n- s390/pci: Fix stale function handles in error handling (Niklas Schnelle)\n- virtio-net: ensure the received length does not exceed allocated size (Bui Quang Minh) [Orabug: 38253832] {CVE-2025-38375}\n- virtio-net: xsk: rx: fix the frame's length check (Bui Quang Minh) [Orabug: 38253978] {CVE-2025-38413}\n- rtc: cmos: use spin_lock_irqsave in cmos_interrupt (Mateusz Jonczyk)\n- rtc: pcf2127: fix SPI command byte for PCF2131 (Elena Popa)\n- rtc: pcf2127: add missing semicolon after statement (Hugo Villeneuve)\n\n[6.12.0-103.36.1.el10uek]\n- rds: tcp: block BH in TCP callbacks (Eric Dumazet) [Orabug: 38233600]\n- mm: memcontrol: fix MM statistics during lruvec reparenting on MGLRU (Harry Yoo) [Orabug: 38002245]\n- memcg: add folio_memcg_charged() stub for !memcg (Kamalesh Babulal) [Orabug: 38002245]\n- mm: memcontrol: fix a build error on CONFIG_MEMCG=n (Harry Yoo) [Orabug: 38002245]\n- net/mlx5: Add poll-eq API to be used by ULP's (Praveen Kumar Kannoju) [Orabug: 38182399]\n- net/rds: poll eq during user-reset (Praveen Kumar Kannoju) [Orabug: 38189326]",
  "id": "ELSA-2025-20551",
  "ovalId": "oval:com.oracle.elsa:def:202520551",
  "source": "oracle_linux",
  "title": "ELSA-2025-20551: Unbreakable Enterprise kernel security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2025-20551.html"
}