{
  "cves": [
    "CVE-2024-50022",
    "CVE-2025-22058",
    "CVE-2025-23143",
    "CVE-2025-39883",
    "CVE-2025-39885",
    "CVE-2025-39911",
    "CVE-2025-39913",
    "CVE-2025-39923",
    "CVE-2025-39945",
    "CVE-2025-39953",
    "CVE-2025-39955",
    "CVE-2025-39967",
    "CVE-2025-39968",
    "CVE-2025-39969",
    "CVE-2025-39970",
    "CVE-2025-39971",
    "CVE-2025-39972",
    "CVE-2025-39973",
    "CVE-2025-39993",
    "CVE-2025-39994",
    "CVE-2025-39995",
    "CVE-2025-39996",
    "CVE-2025-39998",
    "CVE-2025-40001",
    "CVE-2025-40006",
    "CVE-2025-40011",
    "CVE-2025-40018",
    "CVE-2025-40019",
    "CVE-2025-40020",
    "CVE-2025-40026",
    "CVE-2025-40027",
    "CVE-2025-40030",
    "CVE-2025-40035",
    "CVE-2025-40042",
    "CVE-2025-40044",
    "CVE-2025-40048",
    "CVE-2025-40049",
    "CVE-2025-40055",
    "CVE-2025-40070",
    "CVE-2025-40078",
    "CVE-2025-40081",
    "CVE-2025-40087",
    "CVE-2025-40105",
    "CVE-2025-40111",
    "CVE-2025-40115",
    "CVE-2025-40118",
    "CVE-2025-40125",
    "CVE-2025-40134",
    "CVE-2025-40140",
    "CVE-2025-40153",
    "CVE-2025-40167",
    "CVE-2025-40173",
    "CVE-2025-40178",
    "CVE-2025-40186",
    "CVE-2025-40187",
    "CVE-2025-40190",
    "CVE-2025-40194",
    "CVE-2025-40197",
    "CVE-2025-40198",
    "CVE-2025-40200",
    "CVE-2025-40204",
    "CVE-2025-40205",
    "CVE-2025-40219",
    "CVE-2025-40233",
    "CVE-2025-40240"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[5.4.17-2136.350.3.1]\n- Reapply 'cpuidle: menu: Avoid discarding useful information' (Harshvardhan Jha)  [Orabug: 38744458] \n- fbcon: fix integer overflow in font allocation (Samasth Norway Ananda)  [Orabug: 38744453]\n\n[5.4.17-2136.350.3]\n- net/rds: Fix rs_recv_pending counting issue (Gerd Rausch) [Orabug: 38506370]\n\n[5.4.17-2136.350.2]\n- LTS tag: v5.4.301 (Alok Tiwari)\n- net: rtnetlink: fix module reference count leak issue in rtnetlink_rcv_msg (Zhengchao Shao)\n- media: s5p-mfc: remove an unused/uninitialized variable (Arnd Bergmann)\n- NFSD: Fix last write offset handling in layoutcommit (Sergey Bashirov)\n- NFSD: Minor cleanup in layoutcommit processing (Sergey Bashirov)\n- padata: Reset next CPU when reorder sequence wraps around (Xiao Liang)\n- KEYS: trusted_tpm1: Compare HMAC values in constant time (Eric Biggers)\n- NFSD: Define a proc_layoutcommit for the FlexFiles layout type (Chuck Lever) [Orabug: 38601819] {CVE-2025-40087}\n- vfs: Don't leak disconnected dentries on umount (Jan Kara) [Orabug: 38601924] {CVE-2025-40105}\n- jbd2: ensure that all ongoing I/O complete before freeing blocks (Zhang Yi)\n- ext4: detect invalid INLINE_DATA + EXTENTS flag combination (Deepanshu Kartikey) [Orabug: 38649223] {CVE-2025-40167}\n- drm/amdgpu: use atomic functions with memory barriers for vm fault info (Gui-Dong Han)\n- ext4: avoid potential buffer over-read in parse_apply_sb_mount_options() (Theodore Ts'O) [Orabug: 38649412] {CVE-2025-40198}\n- spi: cadence-quadspi: Flush posted register writes before DAC access (Pratyush Yadav)\n- spi: cadence-quadspi: Flush posted register writes before INDAC access (Pratyush Yadav)\n- memory: samsung: exynos-srom: Fix of_iomap leak in exynos_srom_probe (Zhen Ni)\n- memory: samsung: exynos-srom: Correct alignment (Krzysztof Kozlowski)\n- arm64: errata: Apply workarounds for Neoverse-V3AE (Mark Rutland)\n- arm64: cputype: Add Neoverse-V3AE definitions (Mark Rutland)\n- comedi: fix divide-by-zero in comedi_buf_munge() (Deepanshu Kartikey)\n- binder: remove 'invalid inc weak' check (Alice Ryhl)\n- xhci: dbc: enable back DbC in resume if it was enabled before suspend (Mathias Nyman)\n- usb/core/quirks: Add Huawei ME906S to wakeup quirk (Tim Guttzeit)\n- USB: serial: option: add Telit FN920C04 ECM compositions (Li Qingwu)\n- USB: serial: option: add Quectel RG255C (Reinhard Speyerer)\n- USB: serial: option: add UNISOC UIS7720 (Renjun Wang)\n- net: ravb: Ensure memory write completes before ringing TX doorbell (Lad Prabhakar)\n- net: usb: rtl8150: Fix frame padding (Michal Pecio)\n- ocfs2: clear extent cache after moving/defragmenting extents (Deepanshu Kartikey) [Orabug: 38730547] {CVE-2025-40233}\n- MIPS: Malta: Fix keyboard resource preventing i8042 driver from registering (Maciej W. Rozycki)\n- Revert 'cpuidle: menu: Avoid discarding useful information' (Rafael J. Wysocki)\n- net: bonding: fix possible peer notify event loss or dup issue (Tonghao Zhang)\n- sctp: avoid NULL dereference when chunk data buffer is missing (Alexey Simakov) [Orabug: 38730567] {CVE-2025-40240}\n- arm64, mm: avoid always making PTE dirty in pte_mkwrite() (Huang, Ying)\n- net: enetc: correct the value of ENETC_RXB_TRUESIZE (Wei Fang)\n- rtnetlink: Allow deleting FDB entries in user namespace (Johannes Wiesboeck)\n- net: rtnetlink: add NLM_F_BULK support to rtnl_fdb_del (Nikolay Aleksandrov)\n- net: add ndo_fdb_del_bulk (Nikolay Aleksandrov)\n- net: rtnetlink: add bulk delete support flag (Nikolay Aleksandrov)\n- net: netlink: add NLM_F_BULK delete request modifier (Nikolay Aleksandrov)\n- net: rtnetlink: use BIT for flag values (Nikolay Aleksandrov)\n- net: rtnetlink: add helper to extract msg type's kind (Nikolay Aleksandrov)\n- net: rtnetlink: add msg kind names (Nikolay Aleksandrov)\n- net: rtnetlink: remove redundant assignment to variable err (Colin Ian King)\n- m68k: bitops: Fix find_*_bit() signatures (Geert Uytterhoeven)\n- hfsplus: return EIO when type of hidden directory mismatch in hfsplus_fill_super() (Yangtao Li)\n- hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits() (Viacheslav Dubeyko)\n- dlm: check for defined force value in dlm_lockspace_release (Alexander Aring)\n- hfsplus: fix KMSAN uninit-value issue in hfsplus_delete_cat() (Viacheslav Dubeyko)\n- hfs: validate record offset in hfsplus_bmap_alloc (Yang Chenzhi)\n- hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent() (Viacheslav Dubeyko)\n- hfs: make proper initalization of struct hfs_find_data (Viacheslav Dubeyko)\n- hfs: clear offset and space out of valid records in b-tree node (Viacheslav Dubeyko)\n- exec: Fix incorrect type for ret (Xichao Zhao)\n- hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp() (Viacheslav Dubeyko)\n- ALSA: firewire: amdtp-stream: fix enum kernel-doc warnings (Randy Dunlap)\n- sched/fair: Fix pelt lost idle time detection (Vincent Guittot)\n- sched/balancing: Rename newidle_balance() = sched_balance_newidle() (Ingo Molnar)\n- sched/fair: Trivial correction of the newidle_balance() comment (Barry Song)\n- sched: Make newidle_balance() static again (Chen Yu)\n- tls: don't rely on tx_work during send() (Sabrina Dubroca)\n- tls: always set record_type in tls_process_cmsg (Sabrina Dubroca)\n- tg3: prevent use of uninitialized remote_adv and local_adv variables (Alexey Simakov)\n- tcp: fix tcp_tso_should_defer() vs large RTT (Eric Dumazet)\n- amd-xgbe: Avoid spurious link down messages during interface toggle (Raju Rangoju)\n- net/ip6_tunnel: Prevent perpetual tunnel growth (Dmitry Safonov) [Orabug: 38649261] {CVE-2025-40173}\n- net: dlink: handle dma_map_single() failure properly (Moon Yeounsu)\n- net: dl2k: switch from 'pci_' to 'dma_' API (Christophe Jaillet)\n- media: pci: ivtv: Add missing check after DMA map (Thomas Fourier)\n- media: pci/ivtv: switch from 'pci_' to 'dma_' API (Christophe Jaillet)\n- xen/events: Update virq_to_irq on migration (Jason Andryuk)\n- media: lirc: Fix error handling in lirc_register() (Ma Ke)\n- media: rc: Directly use ida_free() (Keliu)\n- drm/exynos: exynos7_drm_decon: remove ctx-suspended (Kaustabh Chakraborty)\n- btrfs: avoid potential out-of-bounds in btrfs_encode_fh() (Anderson Nascimento) [Orabug: 38649463] {CVE-2025-40205}\n- pwm: berlin: Fix wrong register in suspend/resume (Jisheng Zhang)\n- media: cx18: Add missing check after DMA map (Thomas Fourier)\n- xen/events: Cleanup find_virq() return codes (Jason Andryuk)\n- cramfs: Verify inode mode when loading from disk (Tetsuo Handa)\n- fs: Add 'initramfs_options' to set initramfs mount options (Lichen Liu)\n- pid: Add a judgment for ns null in pid_nr_ns (Gaoxiang17) [Orabug: 38649276] {CVE-2025-40178}\n- minixfs: Verify inode mode when loading from disk (Tetsuo Handa)\n- tracing: Fix race condition in kprobe initialization causing NULL pointer dereference (Yuan Chen) [Orabug: 38592033] {CVE-2025-40042}\n- dm: fix NULL pointer dereference in __dm_suspend() (Zheng Qixing) [Orabug: 38649057] {CVE-2025-40134}\n- mfd: intel_soc_pmic_chtdc_ti: Set use_single_read regmap_config flag (Hans de Goede)\n- mfd: intel_soc_pmic_chtdc_ti: Drop unneeded assignment for cache_type (Andy Shevchenko)\n- mfd: intel_soc_pmic_chtdc_ti: Fix invalid regmap-config max_register value (Hans de Goede)\n- Squashfs: reject negative file sizes in squashfs_read_inode() (Phillip Lougher) [Orabug: 38649425] {CVE-2025-40200}\n- Squashfs: add additional inode sanity checking (Phillip Lougher)\n- media: mc: Clear minor number before put device (Edward Adam Davis) [Orabug: 38649399] {CVE-2025-40197}\n- mfd: vexpress-sysreg: Check the return value of devm_gpiochip_add_data() (Bartosz Golaszewski)\n- fs: udf: fix OOB read in lengthAllocDescs handling (Larshin Sergey) [Orabug: 38592048] {CVE-2025-40044}\n- KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (Sean Christopherson) [Orabug: 38591959] {CVE-2025-40026}\n- net/9p: fix double req put in p9_fd_cancelled (Nalivayko Sergey) [Orabug: 38591965] {CVE-2025-40027}\n- ext4: guard against EA inode refcount underflow in xattr update (Ahmet Eray Karadag) [Orabug: 38649330] {CVE-2025-40190}\n- ext4: correctly handle queries for metadata mappings (Ojaswin Mujoo)\n- ext4: increase i_disksize to offset + len in ext4_update_disksize_before_punch() (Yongjian Sun)\n- nfsd: nfserr_jukebox in nlm_fopen should lead to a retry (Olga Kornievskaia)\n- x86/umip: Fix decoding of register forms of 0F 01 (SGDT and SIDT aliases) (Sean Christopherson)\n- x86/umip: Check that the instruction opcode is at least two bytes (Sean Christopherson)\n- PCI: keystone: Use devm_request_irq() to free 'ks-pcie-error-irq' on exit (Siddharth Vadapalli)\n- PCI/AER: Fix missing uevent on recovery when a reset is requested (Niklas Schnelle)\n- PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV (Niklas Schnelle) [Orabug: 38730513] {CVE-2025-40219}\n- rseq/selftests: Use weak symbol reference, not definition, to link with glibc (Sean Christopherson)\n- rtc: interface: Fix long-standing race when setting alarm (Esben Haabendal)\n- rtc: interface: Ensure alarm irq is enabled when UIE is enabled (Esben Haabendal)\n- mmc: core: SPI mode remove cmd7 (Rex Chen)\n- mtd: rawnand: fsmc: Default to autodetect buswidth (Linus Walleij)\n- sparc: fix error handling in scan_one_device() (Ma Ke)\n- sparc64: fix hugetlb for sun4u (Anthony Yznaga)\n- sctp: Fix MAC comparison to be constant-time (Eric Biggers) [Orabug: 38649451] {CVE-2025-40204}\n- scsi: hpsa: Fix potential memory leak in hpsa_big_passthru_ioctl() (Thorsten Blum)\n- parisc: don't reference obsolete termio struct for TC* constants (Sam James)\n- lib/genalloc: fix device leak in of_gen_pool_get() (Johan Hovold)\n- iio: frequency: adf4350: Fix prescaler usage. (Michael Hennerich)\n- iio: dac: ad5421: use int type to store negative error codes (Rong Qianfeng)\n- iio: dac: ad5360: use int type to store negative error codes (Rong Qianfeng)\n- crypto: atmel - Fix dma_unmap_sg() direction (Thomas Fourier)\n- cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request() (Rafael J. Wysocki) [Orabug: 38649367] {CVE-2025-40194}\n- drm/nouveau: fix bad ret code in nouveau_bo_move_prep (Shuhao Fu)\n- media: i2c: mt9v111: fix incorrect type for ret (Rong Qianfeng)\n- firmware: meson_sm: fix device leak at probe (Johan Hovold)\n- xen/manage: Fix suspend error path (Lukas Wunner)\n- arm64: dts: qcom: msm8916: Add missing MDSS reset (Stephan Gerhold)\n- ACPI: debug: fix signedness issues in read/write helpers (Amir Mohammad Jahangirzad)\n- ACPI: TAD: Add missing sysfs_remove_group() for ACPI_TAD_RT (Daniel Tang)\n- tpm_tis: Fix incorrect arguments in tpm_tis_probe_irq_single (Gunnar Kudrjavets)\n- tpm, tpm_tis: Claim locality before writing interrupt registers (Lino Sanfilippo)\n- crypto: essiv - Check ssize for decryption and in-place encryption (Herbert Xu) [Orabug: 38581456,38705546] {CVE-2025-40019}\n- mailbox: zynqmp-ipi: Remove dev.parent check in zynqmp_ipi_free_mboxes (Harini T)\n- mailbox: zynqmp-ipi: Remove redundant mbox_controller_unregister() call (Harini T)\n- tools build: Align warning options with perf (Leo Yan)\n- net: fsl_pq_mdio: Fix device node reference leak in fsl_pq_mdio_probe (Erick Karanja)\n- tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request(). (Kuniyuki Iwashima) [Orabug: 38649579] {CVE-2025-40186}\n- net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce() (Alexandr Sapozhnikov) [Orabug: 38649313] {CVE-2025-40187}\n- drm/vmwgfx: Fix Use-after-free in validation (Ian Forbes) [Orabug: 38643546] {CVE-2025-40111}\n- net/mlx4: prevent potential use after free in mlx4_en_do_uc_filter() (Dan Carpenter)\n- scsi: mvsas: Fix use-after-free bugs in mvs_work_queue (Duoming Zhou) [Orabug: 38557654] {CVE-2025-40001}\n- scsi: mvsas: Use sas_task_find_rq() for tagging (John Garry)\n- scsi: mvsas: Delete mvs_tag_init() (John Garry)\n- scsi: libsas: Add sas_task_find_rq() (John Garry)\n- clk: nxp: Fix pll0 rate check condition in LPC18xx CGU driver (Alok Tiwari)\n- clk: nxp: lpc18xx-cgu: convert from round_rate() to determine_rate() (Brian Masney)\n- perf session: Fix handling when buffer exceeds 2 GiB (Leo Yan)\n- rtc: x1205: Fix Xicor X1205 vendor prefix (Rob Herring)\n- perf util: Fix compression checks returning -1 as bool (Yunseong Kim)\n- iio: frequency: adf4350: Fix ADF4350_REG3_12BIT_CLKDIV_MODE (Michael Hennerich)\n- clocksource/drivers/clps711x: Fix resource leaks in error paths (Zhen Ni)\n- pinctrl: check the return value of pinmux_ops::get_function_name() (Bartosz Golaszewski) [Orabug: 38591981] {CVE-2025-40030}\n- Input: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak (Zhen Ni) [Orabug: 38592002] {CVE-2025-40035}\n- mm: hugetlb: avoid soft lockup when mprotect to large memory area (Yang Shi) [Orabug: 38649150] {CVE-2025-40153}\n- uio_hv_generic: Let userspace take care of interrupt mask (Naman Jain) [Orabug: 38592067] {CVE-2025-40048}\n- Squashfs: fix uninit-value in squashfs_get_parent (Phillip Lougher) [Orabug: 38592077] {CVE-2025-40049}\n- net: ena: return 0 in ena_get_rxfh_key_size() when RSS hash key is not configurable (Kohei Enju)\n- nfp: fix RSS hash key size when RSS is not supported (Kohei Enju)\n- drivers/base/node: fix double free in register_one_node() (Donet Tom)\n- ocfs2: fix double free in user_cluster_connect() (Dan Carpenter) [Orabug: 38592110] {CVE-2025-40055}\n- net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast (I Viswanath) [Orabug: 38649096] {CVE-2025-40140}\n- RDMA/siw: Always report immediate post SQ errors (Bernard Metzler)\n- usb: vhci-hcd: Prevent suspending virtually attached devices (Cristian Ciocaltea)\n- scsi: mpt3sas: Fix crash in transport port remove by using ioc_info() (Ranjan Kumar) [Orabug: 38648982] {CVE-2025-40115}\n- ipvs: Defer ip_vs_ftp unregister during netns cleanup (Slavin Liu) [Orabug: 38581446] {CVE-2025-40018}\n- NFSv4.1: fix backchannel max_resp_sz verification check (Anthony Iliopoulos)\n- remoteproc: qcom: q6v5: Avoid disabling handover IRQ twice (Stephan Gerhold)\n- sparc: fix accurate exception reporting in copy_{from,to}_user for M7 (Michael Karcher)\n- sparc: fix accurate exception reporting in copy_to_user for Niagara 4 (Michael Karcher)\n- sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara (Michael Karcher)\n- sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC III (Michael Karcher)\n- sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC (Michael Karcher)\n- IB/sa: Fix sa_local_svc_timeout_ms read race (Vlad Dumitrescu)\n- RDMA/core: Resolve MAC of next-hop device without ARP support (Parav Pandit)\n- wifi: mt76: fix potential memory leak in mt76_wmac_probe() (Abdun Nihaal)\n- drivers/base/node: handle error properly in register_one_node() (Donet Tom)\n- watchdog: mpc8xxx_wdt: Reload the watchdog timer when enabling the watchdog (Christophe Leroy)\n- netfilter: ipset: Remove unused htable_bits in macro ahash_region (Zhen Ni)\n- iio: consumers: Fix offset handling in iio_convert_raw_to_processed() (Hans de Goede)\n- ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping (Takashi Iwai)\n- ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping (Takashi Iwai)\n- ASoC: Intel: bytcht_es8316: Fix invalid quirk input mapping (Takashi Iwai)\n- pps: fix warning in pps_register_cdev when register device fail (Wang Liang) [Orabug: 38592170] {CVE-2025-40070}\n- misc: genwqe: Fix incorrect cmd field being reported in error (Colin Ian King)\n- usb: gadget: configfs: Correctly set use_os_string at bind (William Wu)\n- usb: phy: twl6030: Fix incorrect type for ret (Xichao Zhao)\n- tcp: fix __tcp_close() to only send RST when required (Eric Dumazet)\n- PCI: tegra: Fix devm_kcalloc() argument order for port-phys allocation (Alok Tiwari)\n- wifi: mwifiex: send world regulatory domain to driver (Stefan Kerkmann)\n- ALSA: lx_core: use int type to store negative error codes (Rong Qianfeng)\n- media: rj54n1cb0c: Fix memleak in rj54n1_probe() (Zhang Shurong)\n- scsi: myrs: Fix dma_alloc_coherent() error check (Thomas Fourier)\n- scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod (Niklas Cassel) [Orabug: 38649567] {CVE-2025-40118}\n- serial: max310x: Add error checking in probe() (Dan Carpenter)\n- usb: host: max3421-hcd: Fix error pointer dereference in probe cleanup (Dan Carpenter)\n- drm/radeon/r600_cs: clean up of dead code in r600_cs (Brahmajit Das)\n- i2c: designware: Add disabling clocks when probe fails (Kunihiko Hayashi)\n- i2c: mediatek: fix potential incorrect use of I2C_MASTER_WRRD (Leilk Liu)\n- bpf: Explicitly check accesses to bpf_sock_addr (Paul Chaignon) [Orabug: 38592205] {CVE-2025-40078}\n- selftests: watchdog: skip ping loop if WDIOF_KEEPALIVEPING not supported (Akhilesh Patil)\n- pwm: tiehrpwm: Fix corner case in clock divisor calculation (Uwe Kleine-Konig)\n- block: use int to store blk_stack_limits() return value (Rong Qianfeng)\n- blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx (Li Nan) [Orabug: 38649026] {CVE-2025-40125}\n- pinctrl: meson-gxl: add missing i2c_d pinmux (Da Xue)\n- soc: qcom: rpmh-rsc: Unconditionally clear _TRIGGER bit for TCS (Sneh Mankad)\n- ACPI: processor: idle: Fix memory leak when register cpuidle device failed (Huisong Li)\n- regmap: Remove superfluous check for !config in __regmap_init() (Geert Uytterhoeven)\n- x86/vdso: Fix output operand size of RDPID (Uros Bizjak)\n- perf: arm_spe: Prevent overflow in PERF_IDX2OFF() (Leo Yan) [Orabug: 38592223] {CVE-2025-40081}\n- driver core/PM: Set power.no_callbacks along with power.no_pm (Rafael J. Wysocki)\n- staging: axis-fifo: flush RX FIFO on read errors (Ovidiu Panait)\n- staging: axis-fifo: fix maximum TX packet length check (Ovidiu Panait)\n- perf subcmd: avoid crash in exclude_cmds when excludes is empty (Hupu)\n- dm-integrity: limit MAX_TAG_SIZE to 255 (Mikulas Patocka)\n- wifi: rtlwifi: rtl8192cu: Don't claim USB ID 07b8:8188 (Bitterblue Smith)\n- USB: serial: option: add SIMCom 8230C compositions (Xiaowei Li)\n- media: rc: fix races with imon_disconnect() (Larshin Sergey) [Orabug: 38548027] {CVE-2025-39993}\n- media: imon: grab lock earlier in imon_ir_change_protocol() (Tetsuo Handa)\n- media: imon: reorganize serialization (Tetsuo Handa)\n- media: rc: Add support for another iMON 0xffdc device (Flavius Georgescu)\n- media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe (Duoming Zhou) [Orabug: 38548044] {CVE-2025-39995}\n- media: tuner: xc5000: Fix use-after-free in xc5000_release (Duoming Zhou) [Orabug: 38548037] {CVE-2025-39994}\n- media: tunner: xc5000: Refactor firmware load (Ricardo Ribalda)\n- udp: Fix memory accounting leak. (Kuniyuki Iwashima) [Orabug: 37844325] {CVE-2025-22058}\n- media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove (Duoming Zhou) [Orabug: 38548051] {CVE-2025-39996}\n- scsi: target: target_core_configfs: Add length check to avoid buffer overflow (Wang Haoran) [Orabug: 38548059] {CVE-2025-39998}\n- LTS tag: v5.4.300 (Alok Tiwari)\n- KVM: SVM: Sync TPR from LAPIC into VMCB::V_TPR even if AVIC is active (Maciej S. Szmigiero)\n- mm/hugetlb: fix folio is still mapped when deleted (Tu Jinjiang) [Orabug: 38560482] {CVE-2025-40006}\n- i40e: add mask to apply valid bits for itr_idx (Lukasz Czapnik)\n- i40e: fix validation of VF state in get resources (Lukasz Czapnik) [Orabug: 38547929] {CVE-2025-39969}\n- i40e: fix idx validation in config queues msg (Lukasz Czapnik) [Orabug: 38547938] {CVE-2025-39971}\n- i40e: add validation for ring_len param (Lukasz Czapnik) [Orabug: 38547952,38604168,38604171] {CVE-2025-39973}\n- i40e: increase max descriptors for XL710 (Justin Bronder)\n- mm/migrate_device: don't add folio to be freed to LRU in migrate_device_finalize() (David Hildenbrand)\n- fbcon: Fix OOB access in font allocation (Thomas Zimmermann)\n- fbcon: fix integer overflow in fbcon_do_set_font (Samasth Norway Ananda) [Orabug: 38547913] {CVE-2025-39967}\n- i40e: add max boundary check for VF filters (Lukasz Czapnik) [Orabug: 38547923] {CVE-2025-39968}\n- i40e: fix input validation logic for action_meta (Lukasz Czapnik) [Orabug: 38547933] {CVE-2025-39970}\n- i40e: fix idx validation in i40e_validate_queue_map (Lukasz Czapnik) [Orabug: 38547946] {CVE-2025-39972}\n- drm/gma500: Fix null dereference in hdmi teardown (Zabelin Nikita) [Orabug: 38560496] {CVE-2025-40011}\n- can: peak_usb: fix shift-out-of-bounds issue (Stephane Grosjean) [Orabug: 38581463] {CVE-2025-40020}\n- can: mcba_usb: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol)\n- can: sun4i_can: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol)\n- can: hi311x: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol)\n- can: rcar_can: rcar_can_resume(): fix s2ram with PSCI (Geert Uytterhoeven)\n- IB/mlx5: Fix obj_type mismatch for SRQ event subscriptions (Or Har-Toov)\n- usb: core: Add 0x prefix to quirks debug output (Jiayi Li)\n- ALSA: usb-audio: Fix build with CONFIG_INPUT=n (Takashi Iwai)\n- ALSA: usb-audio: Convert comma to semicolon (Chen Ni)\n- ALSA: usb-audio: Add mixer quirk for Sony DualSense PS5 (Cristian Ciocaltea)\n- ALSA: usb-audio: Remove unneeded wmb() in mixer_quirks (Cristian Ciocaltea)\n- ALSA: usb-audio: Simplify NULL comparison in mixer_quirks (Cristian Ciocaltea)\n- ALSA: usb-audio: Avoid multiple assignments in mixer_quirks (Cristian Ciocaltea)\n- ALSA: usb-audio: Fix block comments in mixer_quirks (Cristian Ciocaltea)\n- net: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer (Hans de Goede)\n- net: rfkill: gpio: add DT support (Philipp Zabel)\n- serial: sc16is7xx: fix bug in flow control levels init (Hugo Villeneuve)\n- USB: gadget: dummy-hcd: Fix locking bug in RT-enabled kernels (Alan Stern)\n- usb: gadget: dummy_hcd: remove usage of list iterator past the loop body (Jakob Koschel)\n- ASoC: SOF: Intel: hda-stream: Fix incorrect variable used in error message (Colin Ian King)\n- ASoC: wm8974: Correct PLL rate rounding (Charles Keepax)\n- ASoC: wm8940: Correct typo in control name (Charles Keepax)\n- mmc: mvsdio: Fix dma_unmap_sg() nents value (Thomas Fourier)\n- nilfs2: fix CFI failure when accessing /sys/fs/nilfs2/features/* (Nathan Chancellor)\n- cnic: Fix use-after-free bugs in cnic_delete_task (Duoming Zhou) [Orabug: 38503849] {CVE-2025-39945}\n- net: liquidio: fix overflow in octeon_init_instr_queue() (Alexey Nepomnyashih)\n- tcp: Clear tcp_sk(sk)-fastopen_rsk in tcp_disconnect(). (Kuniyuki Iwashima) [Orabug: 38526388] {CVE-2025-39955}\n- i40e: remove redundant memory barrier when cleaning Tx descs (Maciej Fijalkowski)\n- net: natsemi: fix rx_dropped double accounting on netif_rx() failure (Moon Yeounsu)\n- cgroup: split cgroup_destroy_wq into 3 workqueues (Chen Ridong) [Orabug: 38503892] {CVE-2025-39953}\n- pcmcia: omap_cf: Mark driver struct with __refdata to prevent section mismatch (Geert Uytterhoeven)\n- wifi: mac80211: fix incorrect type for ret (Liao Yuanhong)\n- ALSA: firewire-motu: drop EPOLLOUT from poll return values as write is not supported (Takashi Sakamoto)\n- mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory (Miaohe Lin) [Orabug: 38461848] {CVE-2025-39883}\n- phy: ti-pipe3: fix device leak at unbind (Johan Hovold)\n- dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees (Stephan Gerhold) [Orabug: 38494822] {CVE-2025-39923}\n- dmaengine: ti: edma: Fix memory allocation size for queue_priority_map (Anders Roxell)\n- can: j1939: j1939_local_ecu_get(): undo increment when j1939_local_ecu_get() fails (Tetsuo Handa)\n- can: j1939: j1939_sk_bind(): call j1939_priv_put() immediately when j1939_local_ecu_get() failed (Tetsuo Handa)\n- i40e: fix IRQ freeing in i40e_vsi_request_irq_msix error path (Michal Schmidt) [Orabug: 38494787] {CVE-2025-39911}\n- i40e: Use irq_update_affinity_hint() (Nitesh Narayan Lal)\n- genirq: Provide new interfaces for affinity hints (Thomas Gleixner)\n- genirq: Export affinity setter for modules (Thomas Gleixner)\n- genirq/affinity: Add irq_update_affinity_desc() (John Garry)\n- igb: fix link test skipping when interface is admin down (Kohei Enju)\n- net: fec: Fix possible NPD in fec_enet_phy_reset_after_clk_enable() (Stefan Wahren)\n- USB: serial: option: add Telit Cinterion LE910C4-WWX new compositions (Fabio Porcedda)\n- USB: serial: option: add Telit Cinterion FN990A w/audio compositions (Fabio Porcedda)\n- tty: hvc_console: Call hvc_kick in hvc_write unconditionally (Fabian Vogt)\n- mtd: nand: raw: atmel: Respect tAR, tCLR in read setup timing (Alexander Sverdlin)\n- mtd: nand: raw: atmel: Fix comment in timings preparation (Alexander Dahl)\n- mtd: rawnand: stm32_fmc2: avoid overlapping mappings on ECC buffer (Christophe Kerello)\n- mm/khugepaged: fix the address passed to notifier on testing young (Wei Yang)\n- fuse: prevent overflow in copy_file_range return value (Miklos Szeredi)\n- fuse: check if copy_file_range() returns larger than requested size (Miklos Szeredi)\n- mtd: rawnand: stm32_fmc2: fix ECC overwrite (Christophe Kerello)\n- ocfs2: fix recursive semaphore deadlock in fiemap call (Mark Tinguely) [Orabug: 38461859] {CVE-2025-39885}\n- EDAC/altera: Delete an inappropriate dma_free_coherent() call (Salah Triki)\n- tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock-cork. (Kuniyuki Iwashima) [Orabug: 38494797] {CVE-2025-39913}\n- net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod. (Kuniyuki Iwashima) [Orabug: 37901604] {CVE-2025-23143}\n\n[5.4.17-2136.350.1]\n- device-dax: correct pgoff align in dax_set_mapping() (Kun(Llfl)) [Orabug: 37206404] {CVE-2024-50022}\n\n[5.4.17-2136.349.3]\n- Revert 'net/mlx5e: Update and set Xon/Xoff upon MTU set' (Jakub Kicinski) [Orabug: 38545204]\n- KVM: x86: Take irqfds.lock when adding/deleting IRQ bypass producer (Sean Christopherson) [Orabug: 38494247]\n- rds: Free all frags when rds_ib_recv_cache_put() fails (Hans Westgaard Ry) [Orabug: 38492234]\n\n[5.4.17-2136.349.2]\n- bpf/bpf_get,set_sockopt: add option to set TCP-BPF sock ops flags (Alan Maguire) [Orabug: 36699199]\n\n[5.4.17-2136.349.1]\n- NFSv4: Don't clear capabilities that won't be reset (Trond Myklebust)\n- power: supply: bq27xxx: restrict no-battery detection to bq27000 (H. Nikolaus Schaller)\n- power: supply: bq27xxx: fix error return in case of no bq27000 hdq battery (H. Nikolaus Schaller)\n- usb: hub: Fix flushing of delayed work used for post resume purposes (Mathias Nyman)\n- soc: qcom: mdt_loader: Deal with zero e_shentsize (Bjorn Andersson)\n- Revert 'net/mlx5e: Update and set Xon/Xoff upon port speed set' (Tariq Toukan)\n- LTS tag: v5.4.299 (Alok Tiwari)\n- scsi: lpfc: Fix buffer free/clear order in deferred receive path (John Evans) [Orabug: 38456754] {CVE-2025-39841}\n- dmaengine: mediatek: Fix a flag reuse error in mtk_cqdma_tx_status() (Qiu-Ji Chen)\n- cifs: fix integer overflow in match_server() (Roman Smirnov)\n- spi: spi-fsl-lpspi: Reset FIFO and disable module on transfer abort (Larisa Grigore)\n- spi: spi-fsl-lpspi: Set correct chip-select polarity bit (Larisa Grigore)\n- spi: spi-fsl-lpspi: Fix transmissions when using CONT (Larisa Grigore)\n- pcmcia: Add error handling for add_interval() in do_validate_mem() (Xu Wang)\n- ALSA: hda/hdmi: Add pin fix for another HP EliteDesk 800 G4 model (Takashi Iwai)\n- randstruct: gcc-plugin: Fix attribute addition (Kees Cook)\n- randstruct: gcc-plugin: Remove bogus void member (Kees Cook)\n- vmxnet3: update MTU after device quiesce (Ronak Doshi)\n- net: dsa: microchip: linearize skb for tail-tagging switches (Jakob Unterwurzacher)\n- net: dsa: microchip: update tag_ksz masks for KSZ9477 family (Pieter Van Trappen)\n- dmaengine: mediatek: Fix a possible deadlock error in mtk_cqdma_tx_status() (Qiu-Ji Chen)\n- ALSA: hda/realtek - Add new HP ZBook laptop with micmute led fixup (Chris Chiu)\n- gpio: pca953x: fix IRQ storm on system wake up (Emanuele Ghidoli)\n- iio: light: opt3001: fix deadlock due to concurrent flag access (Luca Ceresoli) [Orabug: 37977028] {CVE-2025-37968}\n- iio: chemical: pms7003: use aligned_s64 for timestamp (David Lechner)\n- cpufreq/sched: Explicitly synchronize limits_changed flag handling (Rafael J. Wysocki)\n- mm/slub: avoid accessing metadata when pointer is invalid in object_err() (Li Qiong) [Orabug: 38494761] {CVE-2025-39902}\n- mm/khugepaged: fix -anon_vma race (Jann Horn)\n- e1000e: fix heap overflow in e1000_set_eeprom (Vitaly Lifshits)\n- batman-adv: fix OOB read/write in network-coding decode (Stanislav Fort)\n- drm/amdgpu: drop hw access in non-DC audio fini (Alex Deucher)\n- wifi: mwifiex: Initialize the chan_stats array to zero (Rong Qianfeng) [Orabug: 38494723] {CVE-2025-39891}\n- pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region() (Ma Ke)\n- ALSA: usb-audio: Add mute TLV for playback volumes on some devices (Cryolitia Pukngae)\n- ppp: fix memory leak in pad_compress_skb (Qingfang Deng) [Orabug: 38456781] {CVE-2025-39847}\n- net: atm: fix memory leak in atm_register_sysfs when device_register fail (Wang Liang)\n- ax25: properly unshare skbs in ax25_kiss_rcv() (Eric Dumazet)\n- ipv4: Fix NULL vs error pointer check in inet_blackhole_dev_init() (Dan Carpenter)\n- net: thunder_bgx: add a missing of_node_put (Rosen Penev)\n- wifi: libertas: cap SSID len in lbs_associate() (Dan Carpenter)\n- wifi: cw1200: cap SSID length in cw1200_do_join() (Dan Carpenter)\n- net: ethernet: mtk_eth_soc: fix tx vlan tag for llc packets (Felix Fietkau)\n- i40e: Fix potential invalid access when MAC list is empty (Zhen Ni) [Orabug: 38456814] {CVE-2025-39853}\n- icmp: fix icmp_ndo_send address translation for reply direction (Fabian Blase)\n- mISDN: Fix memory leak in dsp_hwec_enable() (Miaoqian Lin)\n- xirc2ps_cs: fix register access when enabling FullDuplex (Alok Tiwari)\n- Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen() (Kuniyuki Iwashima) [Orabug: 38456834] {CVE-2025-39860}\n- netfilter: conntrack: helper: Replace -EEXIST by -EBUSY (Phil Sutter)\n- wifi: cfg80211: fix use-after-free in cmp_bss() (Dmitry Antipov) [Orabug: 38456860] {CVE-2025-39864}\n- powerpc: boot: Remove leading zero in label in udelay() (Nathan Chancellor)\n\n[5.4.17-2136.348.3]\n- hugetlbfs: take read_lock on i_mmap for PMD sharing (Waiman Long) [Orabug: 38459576]\n- kallsyms: add module_kallsyms_on_each_symbol_locked (Julian Pidancet) [Orabug: 38418686]\n- kallsyms: export module_kallsyms_on_each_symbol (Julian Pidancet) [Orabug: 38418686]\n\n[5.4.17-2136.348.2]\n- uek-rpm: Move ifb module to nano modules (Harshit Mogalapalli) [Orabug: 38443798]\n- clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns (Al Viro) [Orabug: 38310007,38453918] {CVE-2025-38499}\n- x86/vmscape: Warn when STIBP is disabled with SMT (Pawan Gupta) [Orabug: 38424094]\n- x86/bugs: Move cpu_bugs_smt_update() down (Pawan Gupta) [Orabug: 38424094]\n- x86/vmscape: Enable the mitigation (Pawan Gupta) [Orabug: 38424094]\n- x86/vmscape: Add conditional IBPB mitigation (Pawan Gupta) [Orabug: 38424094]\n- x86/vmscape: Add old Intel CPUs to affected list (Pawan Gupta) [Orabug: 38424094]\n- x86/vmscape: Enumerate VMSCAPE bug (Pawan Gupta) [Orabug: 38424094]\n- Documentation/hw-vuln: Add VMSCAPE documentation (Pawan Gupta) [Orabug: 38424094]\n\n[5.4.17-2136.348.1]\n- LTS tag: v5.4.298 (Sherry Yang)\n- Revert 'drm/dp: Change AUX DPCD probe address from DPCD_REV to LANE0_1_STATUS' (Imre Deak)\n- net: usb: qmi_wwan: add Telit Cinterion LE910C4-WWX new compositions (Fabio Porcedda)\n- Revert 'drm/amdgpu: fix incorrect vm flags to map bo' (Alex Deucher) [Orabug: 38343661]\n- HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() (Minjong Kim) [Orabug: 38440228] {CVE-2025-39808}\n- HID: wacom: Add a new Art Pen 2 (Ping Cheng)\n- HID: asus: fix UAF via HID_CLAIMED_INPUT validation (Qasim Ijaz) [Orabug: 38440310] {CVE-2025-39824}\n- efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare (Li Nan) [Orabug: 38440277] {CVE-2025-39817}\n- sctp: initialize more fields in sctp_v6_from_sk() (Eric Dumazet) [Orabug: 38440251] {CVE-2025-39812}\n- net: stmmac: xgmac: Do not enable RX FIFO Overflow interrupts (Rohan G Thomas)\n- net/mlx5e: Set local Xoff after FW update (Alexei Lazar)\n- net/mlx5e: Update and set Xon/Xoff upon port speed set (Alexei Lazar)\n- net/mlx5e: Update and set Xon/Xoff upon MTU set (Alexei Lazar)\n- net: dlink: fix multicast stats being counted incorrectly (Moon Yeounsu)\n- atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control(). (Kuniyuki Iwashima) [Orabug: 38440347] {CVE-2025-39828}\n- net/atm: remove the atmdev_ops {get, set}sockopt methods (Christoph Hellwig)\n- Bluetooth: hci_event: Detect if HCI_EV_NUM_COMP_PKTS is unbalanced (Luiz Augusto von Dentz)\n- powerpc/kvm: Fix ifdef to remove build warning (Madhavan Srinivasan)\n- net: ipv4: fix regression in local-broadcast routes (Oscar Maes) [Orabug: 38343661]\n- vhost/net: Protect ubufs with rcu read lock in vhost_net_ubuf_put() (Nikolay Kuratov)\n- scsi: core: sysfs: Correct sysfs attributes access rights (Damien Le Moal)\n- ftrace: Fix potential warning in trace_printk_seq during ftrace_dump (Tengda Wu) [Orabug: 38440259] {CVE-2025-39813}\n- pinctrl: STMFX: add missing HAS_IOMEM dependency (Randy Dunlap)\n- LTS tag: v5.4.297 (Sherry Yang)\n- alloc_fdtable(): change calling conventions. (Al Viro)\n- s390/hypfs: Enable limited access during lockdown (Peter Oberparleiter)\n- s390/hypfs: Avoid unnecessary ioctl registration in debugfs (Peter Oberparleiter)\n- ALSA: usb-audio: Use correct sub-type for UAC3 feature unit validation (Takashi Iwai)\n- net/sched: Remove unnecessary WARNING condition for empty child qdisc in htb_activate (William Liu)\n- net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit (William Liu)\n- ixgbe: xsk: resolve the negative overflow of budget in ixgbe_xmit_zc (Jason Xing)\n- ipv6: sr: validate HMAC algorithm ID in seg6_hmac_info_add (Heminhong)\n- ALSA: usb-audio: Fix size validation in convert_chmap_v3() (Dan Carpenter) [Orabug: 38343661]\n- scsi: qla4xxx: Prevent a potential error pointer dereference (Dan Carpenter) [Orabug: 38401514] {CVE-2025-39676}\n- usb: xhci: Fix slot_id resource race conflict (Weitao Wang)\n- nfs: fix UAF in direct writes (Josef Bacik) [Orabug: 36596831] {CVE-2024-26958}\n- NFS: Fix up commit deadlocks (Trond Myklebust)\n- cifs: Fix UAF in cifs_demultiplex_thread() (Zhang Xiaoxu)\n- Bluetooth: fix use-after-free in device_for_each_child() (Dmitry Antipov) [Orabug: 37433654] {CVE-2024-53237}\n- act_mirred: use the backlog for nested calls to mirred ingress (Davide Caratti) [Orabug: 34882838] {CVE: CVE-2022-4269}\n- net/sched: act_mirred: better wording on protection against excessive stack growth (Davide Caratti)\n- net/sched: act_mirred: refactor the handle of xmit (Wenxu)\n- selftests: forwarding: tc_actions.sh: add matchall mirror test (Jiri Pirko)\n- net: sched: don't expose action qstats to skb_tc_reinsert() (Vlad Buslov)\n- net: sched: extract qstats update code into functions (Vlad Buslov)\n- net: sched: extract bstats update code into function (Vlad Buslov)\n- net: sched: extract common action counters update code into function (Vlad Buslov)\n- mm: perform the mapping_map_writable() check after call_mmap() (Lorenzo Stoakes)\n- mm: update memfd seal write check to include F_SEAL_WRITE (Lorenzo Stoakes)\n- mm: drop the assumption that VM_SHARED always implies writable (Lorenzo Stoakes)\n- codel: remove sch-q.qlen check before qdisc_tree_reduce_backlog() (Cong Wang) [Orabug: 37908492] {CVE-2025-37798}\n- sch_qfq: make qfq_qlen_notify() idempotent (Cong Wang)\n- sch_hfsc: make hfsc_qlen_notify() idempotent (Cong Wang) [Orabug: 38158396] {CVE-2025-38177}\n- sch_drr: make drr_qlen_notify() idempotent (Cong Wang)\n- btrfs: populate otime when logging an inode item (Qu Wenruo)\n- media: venus: hfi: explicitly release IRQ during teardown (Jorge Ramirez-Ortiz)\n- f2fs: fix to avoid out-of-boundary access in dnode page (Chao Yu)\n- media: venus: protect against spurious interrupts during probe (Jorge Ramirez-Ortiz)\n- media: qcom: camss: cleanup media device allocated resource on error path (Vladimir Zapolskiy)\n- media: venus: vdec: Clamp param smaller than 1fps and bigger than 240. (Ricardo Ribalda)\n- drm/dp: Change AUX DPCD probe address from DPCD_REV to LANE0_1_STATUS (Imre Deak)\n- pwm: mediatek: Fix duty and period setting (Uwe Kleine-Konig)\n- pwm: mediatek: Handle hardware enable and clock enable separately (Uwe Kleine-Konig)\n- pwm: mediatek: Implement .apply() callback (Uwe Kleine-Konig)\n- media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt() (Gui-Dong Han) [Orabug: 38401677] {CVE-2025-39713}\n- media: v4l2-ctrls: Don't reset handler's error in v4l2_ctrl_handler_free() (Sakari Ailus)\n- media: v4l2-ctrls: always copy the controls on completion (Hans Verkuil)\n- ata: Fix SATA_MOBILE_LPM_POLICY description in Kconfig (Damien Le Moal)\n- soc: qcom: mdt_loader: Ensure we don't read past the ELF header (Bjorn Andersson) [Orabug: 38423524] {CVE-2025-39787}\n- rtc: ds1307: handle oscillator stop flag (OSF) for ds1341 (Meagan Lloyd)\n- usb: musb: omap2430: fix device leak at unbind (Johan Hovold)\n- NFS: Fix the setting of capabilities when automounting a new filesystem (Trond Myklebust) [Orabug: 38429211] {CVE-2025-39798}\n- NFS: Fix up handling of outstanding layoutcommit in nfs_update_inode() (Trond Myklebust)\n- NFSv4: Fix nfs4_bitmap_copy_adjust() (Trond Myklebust)\n- usb: typec: fusb302: cache PD RX state (Sebastian Reichel)\n- cdc-acm: fix race between initial clearing halt and open (Oliver Neukum)\n- USB: cdc-acm: do not log successful probe on later errors (Johan Hovold)\n- mm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock (Breno Leitao)\n- mm/kmemleak: turn kmemleak_lock and object-lock to raw_spinlock_t (He Zhe)\n- ALSA: scarlett2: Add retry on -EPROTO from scarlett2_usb_tx() (Geoffrey D. Bennett)\n- x86/fpu: Delay instruction pointer fixup until after warning (Dave Hansen)\n- mm/hmm: move pmd_to_hmm_pfn_flags() to the respective #ifdeffery (Andy Shevchenko)\n- nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() (Jeff Layton) [Orabug: 38395081,38501612] {CVE-2025-38724}\n- pmdomain: governor: Consider CPU latency tolerance from pm_domain_cpu_gov (Maulik Shah)\n- tracing: Add down_write(trace_event_sem) when adding trace event (Steven Rostedt) [Orabug: 38324271] {CVE-2025-38539}\n- usb: hub: Don't try to recover devices lost during warm reset. (Mathias Nyman)\n- usb: hub: avoid warm port reset during USB3 disconnect (Mathias Nyman)\n- x86/mce/amd: Add default names for MCA banks and blocks (Yazen Ghannam)\n- iio: hid-sensor-prox: Fix incorrect OFFSET calculation (Zhang Lixu)\n- f2fs: fix to do sanity check on ino and xnid (Chao Yu)\n- mm/zsmalloc: do not pass __GFP_MOVABLE if CONFIG_COMPACTION=n (Harry Yoo)\n- mm/zsmalloc.c: convert to use kmem_cache_zalloc in cache_alloc_zspage() (Miaohe Lin)\n- drm/sched: Remove optimization that causes hang when killing dependent jobs (Lin Cao)\n- ice: Fix a null pointer dereference in ice_copy_and_init_pkg() (Haoxiang Li) [Orabug: 38351930] {CVE-2025-38664}\n- net: usbnet: Fix the wrong netif_carrier_on() call (Ammar Faizi)\n- net: usbnet: Avoid potential RCU stall on LINK_CHANGE event (John Ernberg)\n- PCI/ACPI: Fix runtime PM ref imbalance on Hot-Plug Capable ports (Lukas Wunner)\n- ACPI: processor: idle: Check acpi_fetch_acpi_dev() return value (Li Zhong)\n- comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large (Ian Abbott)\n- comedi: Fix initialization of data for instructions that write to subdevice (Ian Abbott)\n- kbuild: Add KBUILD_CPPFLAGS to as-option invocation (Nathan Chancellor)\n- kbuild: add  to KBUILD_CPPFLAGS (Masahiro Yamada)\n- kbuild: Add CLANG_FLAGS to as-instr (Nathan Chancellor)\n- mips: Include KBUILD_CPPFLAGS in CHECKFLAGS invocation (Nathan Chancellor)\n- kbuild: Update assembler calls to use proper flags and language target (Nick Desaulniers)\n- ARM: 9448/1: Use an absolute path to unified.h in KBUILD_AFLAGS (Nathan Chancellor)\n- usb: dwc3: Ignore late xferNotReady event to prevent halt timeout (Kuen-Han Tsai)\n- USB: storage: Ignore driver CD mode for Realtek multi-mode Wi-Fi dongles (Zenm Chen)\n- usb: storage: realtek_cr: Use correct byte order for bcs-Residue (Thorsten Blum)\n- USB: storage: Add unusual-devs entry for Novatek NTK96550-based camera (Mael Guerin)\n- usb: quirks: Add DELAY_INIT quick for another SanDisk 3.2Gen1 Flash Drive (Miao Li)\n- iio: proximity: isl29501: fix buffered read on big-endian systems (David Lechner)\n- ftrace: Also allocate and copy hash for reading of filter files (Steven Rostedt) [Orabug: 38401581] {CVE-2025-39689}\n- fpga: zynq_fpga: Fix the wrong usage of dma_map_sgtable() (Xu Yilun)\n- use uniform permission checks for all mount propagation changes (Al Viro)\n- move_mount: allow to add a mount into an existing group (Pavel Tikhomirov)\n- fs/buffer: fix use-after-free when call bh_read() helper (Ye Bin) [Orabug: 38401587] {CVE-2025-39691}\n- drm/amd/display: Find first CRTC and its line time in dce110_fill_display_configs (Timur Kristof)\n- drm/amd/display: Fix fractional fb divider in set_pixel_clock_v3 (Timur Kristof)\n- memstick: Fix deadlock by moving removing flag earlier (Jiayi Li)\n- media: venus: Add a check for packet size after reading from shared memory (Vedang Nagar)\n- media: ov2659: Fix memory leaks in ov2659_probe() (Zhang Shurong)\n- media: usbtv: Lock resolution while streaming (Ludwig Disterhof) [Orabug: 38401684] {CVE-2025-39714}\n- media: imx: fix a potential memory leak in imx_media_csc_scaler_device_init() (Haoxiang Li)\n- media: gspca: Add bounds checking to firmware parser (Dan Carpenter)\n- soc/tegra: pmc: Ensure power-domains are in a known state (Jonathan Hunter)\n- jbd2: prevent softlockup in jbd2_log_do_checkpoint() (Baokun Li) [Orabug: 38423509] {CVE-2025-39782}\n- PCI: endpoint: Fix configfs group removal on driver teardown (Damien Le Moal)\n- PCI: endpoint: Fix configfs group list head handling (Damien Le Moal)\n- mtd: rawnand: fsmc: Add missing check after DMA map (Thomas Fourier)\n- pwm: imx-tpm: Reset counter if CMOD is 0 (Laurentiu Mihalcea)\n- wifi: brcmsmac: Remove const from tbl_ptr parameter in wlc_lcnphy_common_read_table() (Nathan Chancellor)\n- zynq_fpga: use sgtable-based scatterlist wrappers (Marek Szyprowski)\n- ata: libata-scsi: Fix ata_to_sense_error() status handling (Damien Le Moal)\n- ext4: fix reserved gdt blocks handling in fsmap (Ojaswin Mujoo)\n- ext4: fix fsmap end of range reporting with bigalloc (Ojaswin Mujoo)\n- ext4: check fast symlink for ea_inode correctly (Andreas Dilger)\n- vt: defkeymap: Map keycodes above 127 to K_HOLE (Myrrh Periwinkle)\n- vt: keyboard: Don't process Unicode characters in K_OFF mode (Myrrh Periwinkle)\n- usb: dwc3: meson-g12a: fix device leaks at unbind (Johan Hovold)\n- usb: gadget: udc: renesas_usb3: fix device leak at unbind (Johan Hovold)\n- usb: atm: cxacru: Merge cxacru_upload_firmware() into cxacru_heavy_init() (Nathan Chancellor)\n- m68k: Fix lost column on framebuffer debug console (Finn Thain)\n- cpufreq: armada-8k: Fix off by one in armada_8k_cpufreq_free_table() (Dan Carpenter)\n- serial: 8250: fix panic due to PSLVERR (Yunhui Cui) [Orabug: 38401729] {CVE-2025-39724}\n- media: uvcvideo: Do not mark valid metadata as invalid (Ricardo Ribalda)\n- media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() (Youngjun Lee) [Orabug: 38394816] {CVE-2025-38680}\n- mm/kmemleak: avoid soft lockup in __kmemleak_do_cleanup() (Waiman Long)\n- parisc: Makefile: fix a typo in palo.conf (Randy Dunlap)\n- btrfs: fix log tree replay failure due to file with 0 links and extents (Filipe Manana)\n- thunderbolt: Fix copy+paste error in match_service_id() (Eric Biggers)\n- comedi: fix race between polling and detaching (Ian Abbott)\n- misc: rtsx: usb: Ensure mmc child device is active when card is present (Ricky Wu)\n- drm/amdgpu: fix incorrect vm flags to map bo (Jack Xiao)\n- scsi: lpfc: Remove redundant assignment to avoid memory leak (Jiasheng Jiang)\n- rtc: ds1307: remove clear of oscillator stop flag (OSF) in probe (Meagan Lloyd)\n- pNFS: Fix uninited ptr deref in block/scsi layout (Sergey Bashirov) [Orabug: 38394867] {CVE-2025-38691}\n- pNFS: Handle RPC size limit for layoutcommits (Sergey Bashirov)\n- pNFS: Fix disk addr range check in block/scsi layout (Sergey Bashirov)\n- pNFS: Fix stripe mapping in block/scsi layout (Sergey Bashirov)\n- net: phy: smsc: add proper reset flags for LAN8710A (Csaba Buday)\n- ipmi: Fix strcpy source and destination the same (Corey Minyard)\n- kconfig: lxdialog: fix 'space' to (de)select options (Yann E. MORIN)\n- kconfig: gconf: fix potential memory leak in renderer_edited() (Masahiro Yamada)\n- kconfig: gconf: avoid hardcoding model2 in on_treeview2_cursor_changed() (Masahiro Yamada)\n- ipmi: Use dev_warn_ratelimited() for incorrect message warnings (Breno Leitao)\n- scsi: aacraid: Stop using PCI_IRQ_AFFINITY (John Garry)\n- scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans (Ranjan Kumar)\n- kconfig: nconf: Ensure null termination where strncpy is used (Shankari Anand)\n- kconfig: lxdialog: replace strcpy() with strncpy() in inputbox.c (Suchit Karunakaran)\n- i3c: don't fail if GETHDRCAP is unsupported (Wolfram Sang)\n- PCI: pnv_php: Work around switches with broken presence detection (Timothy Pearson)\n- i3c: add missing include to internal header (Wolfram Sang)\n- media: uvcvideo: Fix bandwidth issue for Alcor camera (Chenchangcheng)\n- media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar (Alex Guo) [Orabug: 38394880] {CVE-2025-38693}\n- media: dvb-frontends: dib7090p: fix null-ptr-deref in dib7090p_rw_on_apb() (Alex Guo) [Orabug: 38394887] {CVE-2025-38694}\n- media: usb: hdpvr: disable zero-length read messages (Wolfram Sang)\n- media: tc358743: Increase FIFO trigger level to 374 (Dave Stevenson)\n- media: tc358743: Return an appropriate colorspace from tc358743_set_fmt (Dave Stevenson)\n- media: tc358743: Check I2C succeeded during probe (Dave Stevenson)\n- pinctrl: stm32: Manage irq affinity settings (Cheick Traore)\n- scsi: mpt3sas: Correctly handle ATA device errors (Damien Le Moal)\n- scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure (Justin Tee) [Orabug: 38394894] {CVE-2025-38695}\n- RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask() (Yury Norov) [Orabug: 38423286] {CVE-2025-39742}\n- MIPS: Don't crash in stack_top() for tasks without ABI or vDSO (Thomas Weissschuh)\n- jfs: upper bound check of tree index in dbAllocAG (Arnaud Lecomte)\n- jfs: Regular file corruption check (Edward Adam Davis)\n- jfs: truncate good inode pages when hard link is 0 (Lizhi Xu)\n- scsi: bfa: Double-free fix (Jackysliu) [Orabug: 38394925] {CVE-2025-38699}\n- MIPS: vpe-mt: add missing prototypes for vpe_{alloc,start,stop,free} (Shiji Yang)\n- watchdog: dw_wdt: Fix default timeout (Sebastian Reichel)\n- fs/orangefs: use snprintf() instead of sprintf() (Amir Mohammad Jahangirzad)\n- scsi: libiscsi: Initialize iscsi_conn-dd_data only if memory is allocated (Showrya M N) [Orabug: 38394931] {CVE-2025-38700}\n- ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr (Theodore Ts'O) [Orabug: 38394937] {CVE-2025-38701}\n- cifs: Fix calling CIFSFindFirst() for root path without msearch (Pali Rohar)\n- vhost: fail early when __vhost_add_used() fails (Jason Wang)\n- net: dsa: b53: fix IP_MULTICAST_CTRL on BCM5325 (Alvaro Fernandez Rojas)\n- uapi: in6: restore visibility of most IPv6 socket options (Jakub Kicinski)\n- net: ncsi: Fix buffer overflow in fetching version id (Hari Kalavakunta)\n- net: dsa: b53: prevent SWITCH_CTRL access on BCM5325 (Alvaro Fernandez Rojas)\n- net: dsa: b53: fix b53_imp_vlan_setup for BCM5325 (Alvaro Fernandez Rojas)\n- net: vlan: Replace BUG() with WARN_ON_ONCE() in vlan_dev_* stubs (Gal Pressman)\n- wifi: iwlegacy: Check rate_idx range after addition (Stanislaw Gruszka)\n- netmem: fix skb_frag_address_safe with unreadable skbs (Mina Almasry)\n- wifi: rtlwifi: fix possible skb memory leak in _rtl_pci_rx_interrupt(). (Thomas Fourier)\n- wifi: iwlwifi: fw: Fix possible memory leak in iwl_fw_dbg_collect (Anjaneyulu)\n- wifi: iwlwifi: dvm: fix potential overflow in rs_fill_link_cmd() (Rand Deeb)\n- net: fec: allow disable coalescing (Jonas Rebmann)\n- (powerpc/512) Fix possible dma_unmap_single() on uninitialized pointer (Thomas Fourier)\n- s390/stp: Remove udelay from stp_sync_clock() (Sven Schnelle)\n- wifi: iwlwifi: mvm: fix scan request validation (Avraham Stern)\n- net: thunderx: Fix format-truncation warning in bgx_acpi_match_id() (Alok Tiwari)\n- net: ipv4: fix incorrect MTU in broadcast routes (Oscar Maes)\n- wifi: cfg80211: Fix interface type validation (Ilan Peer)\n- rcu: Protect -defer_qs_iw_pending from data race (Paul E. McKenney) [Orabug: 38423341] {CVE-2025-39749}\n- net: ag71xx: Add missing check after DMA map (Thomas Fourier)\n- et131x: Add missing check after DMA map (Thomas Fourier)\n- be2net: Use correct byte order and format string for TCP seq and ack_seq (Alok Tiwari)\n- s390/time: Use monotonic clock in get_cycles() (Sven Schnelle)\n- wifi: cfg80211: reject HTC bit for management frames (Johannes Berg)\n- ktest.pl: Prevent recursion of default variable options (Steven Rostedt)\n- ASoC: codecs: rt5640: Retry DEVICE_ID verification (Xinxin Wan)\n- ALSA: usb-audio: Avoid precedence issues in mixer_quirks macros (Cristian Ciocaltea)\n- ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control (Lucy Thrun)\n- platform/x86: thinkpad_acpi: Handle KCOV __init vs inline mismatches (Kees Cook)\n- pm: cpupower: Fix the snapshot-order of tsc,mperf, clock in mperf_stop() (Gautham R. Shenoy)\n- usb: core: usb_submit_urb: downgrade type check (Oliver Neukum)\n- ALSA: intel8x0: Fix incorrect codec index usage in mixer for ICH4 (Alok Tiwari)\n- ASoC: hdac_hdmi: Rate limit logging on connection and disconnection (Mark Brown)\n- mmc: rtsx_usb_sdmmc: Fix error-path in sd_set_power_mode() (Ulf Hansson)\n- ACPI: APEI: GHES: add TAINT_MACHINE_CHECK on GHES panic path (Breno Leitao)\n- ACPI: processor: fix acpi_object initialization (Sebastian Ott)\n- PM: sleep: console: Fix the black screen issue (Tuhaowen)\n- thermal: sysfs: Return ENODATA instead of EAGAIN for reads (Hsin-Te Yuan)\n- PM: runtime: Clear power.needs_force_resume in pm_runtime_reinit() (Rafael J. Wysocki)\n- selftests: tracing: Use mutex_unlock for testing glob filter (Masami Hiramatsu)\n- ARM: tegra: Use I/O memcpy to write to IRAM (Aaron Kling)\n- gpio: tps65912: check the return value of regmap_update_bits() (Bartosz Golaszewski)\n- ASoC: soc-dapm: set bias_level if snd_soc_dapm_set_bias_level() was successed (Kuninori Morimoto)\n- ARM: rockchip: fix kernel hang during smp initialization (Alexander Kochetkov)\n- cpufreq: Exit governor when failed to start old governor (Lifeng Zheng)\n- usb: xhci: Avoid showing errors during surprise removal (Mario Limonciello)\n- usb: xhci: Set avg_trb_len = 8 for EP0 during Address Device Command (Jay Chen)\n- usb: xhci: Avoid showing warnings for dying controller (Mario Limonciello)\n- selftests/futex: Define SYS_futex on 32-bit architectures with 64-bit time_t (Cynthia Huang)\n- usb: xhci: print xhci-xhc_state when queue_command failed (Su Hui)\n- securityfs: don't pin dentries twice, once is enough... (Al Viro)\n- hfs: fix not erasing deleted b-tree node issue (Viacheslav Dubeyko)\n- drbd: add missing kref_get in handle_write_conflicts (Sarah Newman) [Orabug: 38394995] {CVE-2025-38708}\n- udf: Verify partition map count (Jan Kara)\n- arm64: Handle KCOV __init vs inline mismatches (Kees Cook)\n- hfsplus: don't use BUG_ON() in hfsplus_create_attributes_file() (Tetsuo Handa)\n- hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() (Viacheslav Dubeyko)\n- hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read() (Viacheslav Dubeyko)\n- hfs: fix slab-out-of-bounds in hfs_bnode_read() (Viacheslav Dubeyko)\n- sctp: linearize cloned gso packets in sctp_rcv (Xin Long) [Orabug: 38395059] {CVE-2025-38718}\n- netfilter: ctnetlink: fix refcount leak on table dump (Florian Westphal) [Orabug: 38395068] {CVE-2025-38721}\n- udp: also consider secpath when evaluating ipsec use for checksumming (Sabrina Dubroca)\n- ACPI: processor: perflib: Move problematic pr-performance check (Rafael J. Wysocki)\n- ACPI: processor: perflib: Fix initial _PPC limit application (Jiayi Li)\n- Documentation: ACPI: Fix parent device references (Andy Shevchenko)\n- fs: Prevent file descriptor table allocations exceeding INT_MAX (Sasha Levin) [Orabug: 38423397] {CVE-2025-39756}\n- sunvdc: Balance device refcount in vdc_port_mpgroup_check (Ma Ke)\n- NFSD: detect mismatch of file handle and delegation stateid in OPEN op (Dai Ngo)\n- net: dpaa: fix device leak when querying time stamp info (Johan Hovold)\n- net: gianfar: fix device leak when querying time stamp info (Johan Hovold)\n- netlink: avoid infinite retry looping in netlink_unicast() (Fedor Pchelkin) [Orabug: 38401319] {CVE-2025-38727}\n- ALSA: usb-audio: Validate UAC3 cluster segment descriptors (Takashi Iwai) [Orabug: 38423407] {CVE-2025-39757}\n- ALSA: usb-audio: Validate UAC3 power domain descriptors, too (Takashi Iwai) [Orabug: 38395101] {CVE-2025-38729}\n- io_uring: don't use int for ABI (Pavel Begunkov)\n- usb: gadget : fix use-after-free in composite_dev_cleanup() (Taoxue) [Orabug: 38334898] {CVE-2025-38555}\n- MIPS: mm: tlb-r4k: Uniquify TLB entries on init (Jiaxun Yang)\n- USB: serial: option: add Foxconn T99W709 (Slark Xiao)\n- vsock: Do not allow binding to VMADDR_PORT_ANY (Budimir Markovic) [Orabug: 38351771,38453914] {CVE-2025-38618}\n- net/packet: fix a race in packet_set_ring() and packet_notifier() (Quang Le) [Orabug: 38351764] {CVE-2025-38617}\n- perf/core: Prevent VMA split of buffer mappings (Thomas Gleixner) [Orabug: 38334948] {CVE-2025-38563}\n- perf/core: Exit early on perf_mmap() fail (Thomas Gleixner) [Orabug: 38334959] {CVE-2025-38565}\n- perf/core: Don't leak AUX buffer refcount on allocation failure (Thomas Gleixner)\n- pptp: fix pptp_xmit() error path (Eric Dumazet)\n- smb: client: let recv_done() cleanup before notifying the callers. (Stefan Metzmacher)\n- benet: fix BUG when creating VFs (Michal Schmidt) [Orabug: 38334976] {CVE-2025-38569}\n- net: drop UFO packets in udp_rcv_segment() (Wang Liang) [Orabug: 38351786] {CVE-2025-38622}\n- ipv6: reject malicious packets in ipv6_gso_segment() (Eric Dumazet) [Orabug: 38334988] {CVE-2025-38572}\n- pptp: ensure minimal skb length in pptp_xmit() (Eric Dumazet) [Orabug: 38335004] {CVE-2025-38574}\n- netpoll: prevent hanging NAPI when netcons gets enabled (Jakub Kicinski)\n- NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() (Trond Myklebust) [Orabug: 38401745] {CVE-2025-39730}\n- pci/hotplug/pnv-php: Wrap warnings in macro (Frederic Barrat)\n- pci/hotplug/pnv-php: Improve error msg on power state change failure (Frederic Barrat)\n- usb: chipidea: udc: fix sleeping function called from invalid context (Peter Chen)\n- f2fs: fix to avoid out-of-boundary access in devs.path (Chao Yu)\n- f2fs: fix to avoid panic in f2fs_evict_inode (Chao Yu)\n- f2fs: fix to avoid UAF in f2fs_sync_inode_meta() (Chao Yu)\n- rtc: pcf8563: fix incorrect maximum clock rate handling (Brian Masney)\n- rtc: hym8563: fix incorrect maximum clock rate handling (Brian Masney)\n- rtc: ds1307: fix incorrect maximum clock rate handling (Brian Masney)\n- module: Restore the moduleparam prefix length check (Petr Pavlu)\n- bpf: Check flow_dissector ctx accesses are aligned (Paul Chaignon)\n- mtd: rawnand: atmel: set pmecc data setup time (Balamanikandan Gunasundar)\n- mtd: rawnand: atmel: Fix dma_mapping_error() address (Thomas Fourier)\n- jfs: fix metapage reference count leak in dbAllocCtl (Zheng Yu)\n- fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref (Chenyuan Yang)\n- crypto: qat - fix seq_file position update in adf_ring_next() (Giovanni Cabiddu)\n- dmaengine: nbpfaxi: Add missing check after DMA map (Thomas Fourier)\n- dmaengine: mv_xor: Fix missing check after DMA map and missing unmap (Thomas Fourier)\n- fs/orangefs: Allow 2 more characters in do_c_string() (Dan Carpenter)\n- soundwire: stream: restore params when prepare ports fail (Bard Liao)\n- crypto: img-hash - Fix dma_unmap_sg() nents value (Thomas Fourier)\n- hwrng: mtk - handle devm_pm_runtime_enable errors (Ovidiu Panait)\n- watchdog: ziirave_wdt: check record length in ziirave_firm_verify() (Dan Carpenter)\n- scsi: isci: Fix dma_unmap_sg() nents value (Thomas Fourier)\n- scsi: mvsas: Fix dma_unmap_sg() nents value (Thomas Fourier)\n- scsi: ibmvscsi_tgt: Fix dma_unmap_sg() nents value (Thomas Fourier)\n- clk: sunxi-ng: v3s: Fix de clock definition (Paul Kocialkowski)\n- perf tests bp_account: Fix leaked file descriptor (Leo Yan)\n- crypto: ccp - Fix crash when rebind ccp device for ccp.ko (Mengbiao Xiong)\n- pinctrl: sunxi: Fix memory leak on krealloc failure (Yuan Chen)\n- power: supply: max14577: Handle NULL pdata when CONFIG_OF is not set (Charles Han)\n- clk: davinci: Add NULL check in davinci_lpsc_clk_register() (Henry Martin)\n- mtd: fix possible integer overflow in erase_xfer() (Ivan Stepchenko)\n- crypto: marvell/cesa - Fix engine load inaccuracy (Herbert Xu)\n- PCI: rockchip-host: Fix 'Unexpected Completion' log message (Hans Zhang)\n- vrf: Drop existing dst reference in vrf_ip6_input_dst (Stanislav Fomichev)\n- selftests: rtnetlink.sh: remove esp4_offload after test (Xiumei Mu)\n- netfilter: xt_nfacct: don't assume acct name is null-terminated (Florian Westphal) [Orabug: 38351854] {CVE-2025-38639}\n- can: kvaser_usb: Assign netdev.dev_port based on device channel index (Jimmy Assarsson)\n- can: kvaser_pciefd: Store device channel index (Jimmy Assarsson)\n- wifi: brcmfmac: fix P2P discovery failure in P2P peer due to missing P2P IE (Gokul Sivakumar)\n- Reapply 'wifi: mac80211: Update skb's control block key in ieee80211_tx_dequeue()' (Remi Pommarel)\n- mwl8k: Add missing check after DMA map (Thomas Fourier)\n- wifi: rtl8xxxu: Fix RX skb size for aggregation disabled (Martin Kaistra)\n- net/sched: Restrict conditions for adding duplicating netems to qdisc tree (William Liu) [Orabug: 38331466] {CVE-2025-38553}\n- arch: powerpc: defconfig: Drop obsolete CONFIG_NET_CLS_TCINDEX (Johan Korsnes)\n- drm/amd/pm/powerplay/hwmgr/smu_helper: fix order of mask and value (Fedor Pchelkin)\n- m68k: Don't unregister boot console needlessly (Finn Thain)\n- tcp: fix tcp_ofo_queue() to avoid including too much DUP SACK range (Xin Guo)\n- iwlwifi: Add missing check for alloc_ordered_workqueue (Jiasheng Jiang) [Orabug: 38335110] {CVE-2025-38602}\n- wifi: iwlwifi: Fix memory leak in iwl_mvm_init() (Xiu Jianfeng)\n- wifi: rtl818x: Kill URBs before clearing tx status queue (Daniil Dulov) [Orabug: 38335120] {CVE-2025-38604}\n- caif: reduce stack size, again (Arnd Bergmann)\n- bpftool: Fix memory leak in dump_xx_nlmsg on realloc failure (Yuan Chen)\n- bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls (Jiayuan Chen) [Orabug: 38335131] {CVE-2025-38608}\n- staging: nvec: Fix incorrect null termination of battery manufacturer (Alok Tiwari)\n- samples: mei: Fix building on musl libc (Brahmajit Das)\n- cpufreq: Init policy-rwsem before it may be possibly used (Lifeng Zheng)\n- ARM: dts: imx6ul-kontron-bl-common: Fix RTS polarity for RS485 interface (Annette Kobou)\n- usb: early: xhci-dbc: Fix early_ioremap leak (Lucas De Marchi)\n- Revert 'vmci: Prevent the dispatching of uninitialized payloads' (Greg Kroah-Hartman)\n- pps: fix poll support (Denis Osterland-Heim)\n- vmci: Prevent the dispatching of uninitialized payloads (Lizhi Xu)\n- staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc() (Abdun Nihaal) [Orabug: 38335153] {CVE-2025-38612}\n- ARM: dts: vfxxx: Correctly use two tuples for timer address (Krzysztof Kozlowski)\n- hfsplus: remove mutex_lock check in hfsplus_free_extents (Yangtao Li)\n- ASoC: Intel: fix SND_SOC_SOF dependencies (Arnd Bergmann)\n- ethernet: intel: fix building with large NR_CPUS (Arnd Bergmann)\n- usb: phy: mxs: disconnect line when USB charger is attached (Xu Yang)\n- usb: chipidea: add USB PHY event (Xu Yang)\n- usb: chipidea: introduce CI_HDRC_CONTROLLER_VBUS_EVENT glue layer use (Peter Chen)\n- usb: chipidea: udc: protect usb interrupt enable (Li Jun)\n- usb: chipidea: udc: add new API ci_hdrc_gadget_connect (Peter Chen)\n- ALSA: hda: Add missing NVIDIA HDA codec IDs (Daniel Dadap)\n- comedi: comedi_test: Fix possible deletion of uninitialized timers (Ian Abbott)\n- nilfs2: reject invalid file types when reading inodes (Ryusuke Konishi)\n- i2c: qup: jump out of the loop in case of timeout (Yang Xiwen) [Orabug: 38351994] {CVE-2025-38671}\n- net/sched: sch_qfq: Avoid triggering might_sleep in atomic context in qfq_delete_class (Xiang Mei)\n- net: appletalk: Fix use-after-free in AARP proxy probe (Kito Xu)\n- net: appletalk: fix kerneldoc warnings (Andrew Lunn)\n- RDMA/core: Rate limit GID cache warning messages (Maor Gottlieb)\n- regulator: core: fix NULL dereference on unbind due to stale coupling data (Alessandro Carminati) [Orabug: 38351978] {CVE-2025-38668}\n- usb: hub: Fix flushing and scheduling of delayed work that tunes runtime pm (Mathias Nyman)\n- usb: hub: fix detection of high tier USB3 devices behind suspended hubs (Mathias Nyman)\n- net_sched: sch_sfq: reject invalid perturb period (Eric Dumazet) [Orabug: 38158477] {CVE-2025-38193}\n- power: supply: bq24190: Fix use after free bug in bq24190_remove due to race condition (Zheng Wang)\n- power: supply: bq24190_charger: using pm_runtime_resume_and_get instead of pm_runtime_get_sync (Minghao Chi)\n- power: supply: bq24190_charger: Fix runtime PM imbalance on error (Dinghao Liu)\n- xhci: Disable stream for xHC controller with XHCI_BROKEN_STREAMS (Hongyu Xie)\n- virtio-net: ensure the received length does not exceed allocated size (Bui Quang Minh) [Orabug: 38253834] {CVE-2025-38375}\n- ASoC: fsl_sai: Force a software reset when starting in consumer mode (Arun Raghavan)\n- usb: dwc3: qcom: Don't leave BCR asserted (Krishna Kurapati)\n- usb: musb: fix gadget state on disconnect (Drew Hamilton)\n- net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree (William Liu) [Orabug: 38254214] {CVE-2025-38468}\n- net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime (Dong Chenchen) [Orabug: 38254225] {CVE-2025-38470}\n- Bluetooth: L2CAP: Fix attempting to adjust outgoing MTU (Luiz Augusto von Dentz)\n- Bluetooth: SMP: Fix using HCI_ERROR_REMOTE_USER_TERM on timeout (Luiz Augusto von Dentz)\n- Bluetooth: SMP: If an unallowed command is received consider it a failure (Luiz Augusto von Dentz)\n- Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb() (Kuniyuki Iwashima) [Orabug: 38254241] {CVE-2025-38473}\n- usb: net: sierra: check for no status endpoint (Oliver Neukum) [Orabug: 38254249] {CVE-2025-38474}\n- net/sched: sch_qfq: Fix race condition on qfq_aggregate (Xiang Mei) [Orabug: 38254266] {CVE-2025-38477}\n- net: emaclite: Fix missing pointer increment in aligned_read() (Alok Tiwari)\n- comedi: Fix use of uninitialized data in insn_rw_emulate_bits() (Ian Abbott)\n- comedi: Fix some signed shift left operations (Ian Abbott)\n- comedi: das6402: Fix bit shift out of bounds (Ian Abbott)\n- comedi: das16m1: Fix bit shift out of bounds (Ian Abbott)\n- comedi: aio_iiro_16: Fix bit shift out of bounds (Ian Abbott)\n- comedi: pcl812: Fix bit shift out of bounds (Ian Abbott)\n- iio: adc: stm32-adc: Fix race in installing chained IRQ handler (Chen Ni)\n- iio: adc: max1363: Reorder mode_list[] entries (Fabio Estevam)\n- iio: adc: max1363: Fix MAX1363_4X_CHANS/MAX1363_8X_CHANS[] (Fabio Estevam)\n- soc: aspeed: lpc-snoop: Don't disable channels that aren't enabled (Andrew Jeffery)\n- soc: aspeed: lpc-snoop: Cleanup resources in stack-order (Andrew Jeffery)\n- mmc: sdhci_am654: Workaround for Errata i2312 (Judith Mendez)\n- mmc: sdhci-pci: Quirk for broken command queuing on Intel GLK-based Positivo models (Edson Juliano Drosdeck)\n- mmc: bcm2835: Fix dma_unmap_sg() nents value (Thomas Fourier)\n- memstick: core: Zero initialize id_reg in h_memstick_read_dev_id() (Nathan Chancellor)\n- isofs: Verify inode mode when loading from disk (Jan Kara)\n- dmaengine: nbpfaxi: Fix memory corruption in probe() (Dan Carpenter)\n- af_packet: fix soft lockup issue caused by tpacket_snd() (Yun Lu)\n- af_packet: fix the SO_SNDTIMEO constraint not effective on tpacked_snd() (Yun Lu)\n- phonet/pep: Move call to pn_skb_get_dst_sockaddr() earlier in pep_sock_accept() (Nathan Chancellor)\n- HID: core: do not bypass hid_hw_raw_request (Benjamin Tissoires) [Orabug: 38254340,38453904] {CVE-2025-38494}\n- HID: core: ensure __hid_request reserves the report ID as the first byte (Benjamin Tissoires)\n- HID: core: ensure the allocated report buffer can contain the reserved report ID (Benjamin Tissoires) [Orabug: 38254348,38453908] {CVE-2025-38495}\n- pch_uart: Fix dma_sync_sg_for_device() nents value (Thomas Fourier)\n- Input: xpad - set correct controller type for Acer NGR200 (Nilton Perim Neto)\n- i2c: stm32: fix the device used for the DMA map (Clement Le Goffic)\n- usb: gadget: configfs: Fix OOB read on empty string write (Xinyu Liu) [Orabug: 38254358] {CVE-2025-38497}\n- USB: serial: ftdi_sio: add support for NDI EMGUIDE GEMINI (Ryan Mann)\n- USB: serial: option: add Foxconn T99W640 (Slark Xiao)\n- USB: serial: option: add Telit Cinterion FE910C04 (ECM) composition (Fabio Porcedda)\n- LTS tag: v5.4.296 (Sherry Yang)\n- x86/mm: Disable hugetlb page table sharing on 32-bit (Jann Horn)\n- Input: atkbd - do not skip atkbd_deactivate() when skipping ATKBD_CMD_GETID (Hans de Goede)\n- HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras (Chia-Lin Kao) [Orabug: 38324280] {CVE-2025-38540}\n- HID: Add IGNORE quirk for SMARTLINKTECHNOLOGY (Zhang Heng)\n- vt: add missing notification when switching back to text mode (Nicolas Pitre)\n- net: usb: qmi_wwan: add SIMCom 8230C composition (Xiaowei Li)\n- atm: idt77252: Add missing dma_map_error() (Thomas Fourier)\n- bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT (Somnath Kotur) [Orabug: 38254090] {CVE-2025-38439}\n- bnxt_en: Fix DCB ETS validation (Shravya Kn)\n- can: m_can: m_can_handle_lost_msg(): downgrade msg lost in rx message to debug level (Sean Nyekjaer)\n- net: phy: microchip: limit 100M workaround to link-down events on LAN88xx (Oleksij Rempel)\n- net: appletalk: Fix device refcount leak in atrtr_create() (Kito Xu)\n- md/raid1: Fix stack memory use after return in raid1_reshape (Wang Jinchao) [Orabug: 38254109] {CVE-2025-38445}\n- wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev() (Daniil Dulov) [Orabug: 38324161] {CVE-2025-38513}\n- dma-buf: fix timeout handling in dma_resv_wait_timeout v2 (Christian Konig)\n- Input: xpad - support Acer NGR 200 Controller (Nilton Perim Neto)\n- Input: xpad - add VID for Turtle Beach controllers (Vicki Pfau)\n- Input: xpad - add support for Amazon Game Controller (Matt Reynolds)\n- NFSv4/flexfiles: Fix handling of NFS level errors in I/O (Trond Myklebust)\n- flexfiles/pNFS: update stats on NFS4ERR_DELAY for v4.1 DSes (Tigran Mkrtchyan)\n- RDMA/mlx5: Fix vport loopback for MPV device (Patrisious Haddad)\n- netlink: Fix rmem check in netlink_broadcast_deliver(). (Kuniyuki Iwashima)\n- netlink: make sure we allow at least one dump skb (Jakub Kicinski)\n- Revert 'ACPI: battery: negate current when discharging' (Rafael J. Wysocki)\n- usb: gadget: u_serial: Fix race condition in TTY wakeup (Kuen-Han Tsai) [Orabug: 38254118] {CVE-2025-38448}\n- drm/sched: Increment job count before swapping tail spsc queue (Matthew Brost) [Orabug: 38324180] {CVE-2025-38515}\n- pinctrl: qcom: msm: mark certain pins as invalid for interrupts (Bartosz Golaszewski) [Orabug: 38324186] {CVE-2025-38516}\n- x86/mce: Make sure CMCI banks are cleared during shutdown on Intel (Jp Kobryn)\n- x86/mce: Don't remove sysfs if thresholding sysfs init fails (Yazen Ghannam)\n- x86/mce/amd: Fix threshold limit reset (Yazen Ghannam)\n- rxrpc: Fix oops due to non-existence of prealloc backlog struct (David Howells)\n- net/sched: Abort __tc_modify_qdisc if parent class does not exist (Victor Nogueira) [Orabug: 38254147] {CVE-2025-38457}\n- atm: clip: Fix NULL pointer dereference in vcc_sendmsg() (Yue Haibing) [Orabug: 38254153] {CVE-2025-38458}\n- atm: clip: Fix infinite recursive call of clip_push(). (Kuniyuki Iwashima) [Orabug: 38254161] {CVE-2025-38459}\n- atm: clip: Fix memory leak of struct clip_vcc. (Kuniyuki Iwashima) [Orabug: 38324309] {CVE-2025-38546}\n- atm: clip: Fix potential null-ptr-deref in to_atmarpd(). (Kuniyuki Iwashima) [Orabug: 38254167] {CVE-2025-38460}\n- tipc: Fix use-after-free in tipc_conn_close(). (Kuniyuki Iwashima) [Orabug: 38254181] {CVE-2025-38464}\n- netlink: Fix wraparounds of sk-sk_rmem_alloc. (Kuniyuki Iwashima) [Orabug: 38254188] {CVE-2025-38465}\n- fix proc_sys_compare() handling of in-lookup dentries (Al Viro)\n- proc: Clear the pieces of proc_inode that proc_evict_inode cares about (Eric W. Biederman)\n- drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling (Kaustabh Chakraborty) [Orabug: 38254203] {CVE-2025-38467}\n- staging: rtl8723bs: Avoid memset() in aes_cipher() and aes_decipher() (Nathan Chancellor)\n- media: uvcvideo: Rollback non processed entities on error (Ricardo Ribalda)\n- media: uvcvideo: Send control events for partial succeeds (Ricardo Ribalda)\n- media: uvcvideo: Return the number of processed controls (Ricardo Ribalda)\n- ACPI: PAD: fix crash in exit_round_robin() (Seiji Nishikawa) [Orabug: 37206006] {CVE-2024-49935}\n- usb: typec: displayport: Fix potential deadlock (Andrei Kuchynski) [Orabug: 38401436] {CVE-2025-38404}\n- Logitech C-270 even more broken (Oliver Neukum)\n- rose: fix dangling neighbour pointers in rose_rt_device_down() (Kohei Enju)\n- net: rose: Fix fall-through warnings for Clang (Gustavo A R Silva)\n- drm/i915/gt: Fix timeline left held on VMA alloc error (Janusz Krzysztofik) [Orabug: 38253887] {CVE-2025-38389}\n- drm/i915/selftests: Change mock_request() to return error pointers (Dan Carpenter)\n- spi: spi-fsl-dspi: Clear completion counter before initiating transfer (James Clark)\n- spi: spi-fsl-dspi: Fix interrupt-less DMA mode taking an XSPI code path (Vladimir Oltean)\n- spi: spi-fsl-dspi: Rename fifo_{read,write} and {tx,cmd}_fifo_write (Vladimir Oltean)\n- dpaa2-eth: fix xdp_rxq_info leak (Wangfushuai)\n- ethernet: atl1: Add missing DMA mapping error checks and count errors (Thomas Fourier)\n- btrfs: use btrfs_record_snapshot_destroy() during rmdir (Filipe Manana)\n- btrfs: propagate last_unlink_trans earlier when doing a rmdir (Filipe Manana)\n- RDMA/mlx5: Fix CC counters query for MPV (Patrisious Haddad)\n- RDMA/core: Create and destroy counters in the ib_core (Leon Romanovsky)\n- scsi: ufs: core: Fix spelling of a sysfs attribute name (Bart Van Assche)\n- drm/v3d: Disable interrupts before resetting the GPU (Maira Canal)\n- mtk-sd: reset host-mrq on prepare_data() error (Sergey Senozhatsky)\n- mtk-sd: Prevent memory corruption from DMA map failure (Masami Hiramatsu)\n- mmc: mediatek: use data instead of mrq parameter from msdc_{un}prepare_data() (Yue Hu)\n- regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods (Manivannan Sadhasivam) [Orabug: 38253907] {CVE-2025-38395}\n- regulator: gpio: Add input_supply support in gpio_regulator_config (Jerome Neanne)\n- ACPICA: Refuse to evaluate a method if arguments are missing (Rafael J. Wysocki) [Orabug: 38253875] {CVE-2025-38386}\n- wifi: ath6kl: remove WARN on bad firmware input (Johannes Berg) [Orabug: 38253946] {CVE-2025-38406}\n- wifi: mac80211: drop invalid source address OCB frames (Johannes Berg)\n- powerpc: Fix struct termio related ioctl macros (Madhavan Srinivasan)\n- ata: pata_cs5536: fix build on 32-bit UML (Johannes Berg)\n- ALSA: sb: Force to disable DMAs once when DMA mode is changed (Takashi Iwai)\n- nui: Fix dma_mapping_error() check (Thomas Fourier)\n- enic: fix incorrect MTU comparison in enic_change_mtu() (Alok Tiwari)\n- amd-xgbe: align CL37 AN sequence as per databook (Raju Rangoju)\n- lib: test_objagg: Set error message in check_expect_hints_stats() (Dan Carpenter)\n- drm/exynos: fimd: Guard display clock control with runtime PM calls (Marek Szyprowski)\n- btrfs: fix missing error handling when searching for inode refs during log replay (Filipe Manana)\n- scsi: qla4xxx: Fix missing DMA mapping error in qla4xxx_alloc_pdu() (Thomas Fourier)\n- nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init() fails. (Kuniyuki Iwashima) [Orabug: 38253923] {CVE-2025-38400}\n- RDMA/mlx5: Initialize obj_event-obj_sub_list before xa_insert (Mark Zhang) [Orabug: 38253881] {CVE-2025-38387}\n- platform/mellanox: mlxbf-tmfifo: fix vring_desc.len assignment (David Thompson)\n- mtk-sd: Fix a pagefault in dma_unmap_sg() for not prepared data (Masami Hiramatsu)\n- usb: typec: altmodes/displayport: do not index invalid pin_assignments (Rd Babiera) [Orabug: 38253894] {CVE-2025-38391}\n- mmc: sdhci: Add a helper function for dump register in dynamic debug mode (Victor Shih)\n- vsock/vmci: Clear the vmci transport packet properly when initializing it (Harshavardhana S A) [Orabug: 38253937] {CVE-2025-38403}\n- btrfs: don't abort filesystem when attempting to snapshot deleted subvolume (Omar Sandoval) [Orabug: 36530119] {CVE-2024-26644}\n- arm64: Restrict pagetable teardown to avoid false warning (Dev Jain)\n- s390: Add '-std=gnu11' to decompressor and purgatory CFLAGS (Nathan Chancellor)\n- drm/bridge: cdns-dsi: Check return value when getting default PHY config (Aradhya Bhatia)\n- drm/bridge: cdns-dsi: Fix connecting to next bridge (Aradhya Bhatia)\n- drm/bridge: cdns-dsi: Fix the clock variable for mode_valid() (Aradhya Bhatia)\n- drm/tegra: Assign plane type before registration (Thierry Reding)\n- HID: wacom: fix kobject reference count leak (Qasim Ijaz)\n- HID: wacom: fix memory leak on sysfs attribute creation failure (Qasim Ijaz)\n- HID: wacom: fix memory leak on kobject creation failure (Qasim Ijaz)\n- dm-raid: fix variable in journal device check (Heinz Mauelshagen)\n- Bluetooth: L2CAP: Fix L2CAP MTU negotiation (Frederic Danis)\n- atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister(). (Kuniyuki Iwashima) [Orabug: 38175045] {CVE-2025-38245}\n- net: enetc: Correct endianness handling in _enetc_rd_reg64 (Simon Horman)\n- um: ubd: Add missing error check in start_io_thread() (Tiwei Bie)\n- vsock/uapi: fix linux/vm_sockets.h userspace compilation errors (Stefano Garzarella)\n- wifi: mac80211: fix beacon interval calculation overflow (Lachlan Hodges)\n- attach_recursive_mnt(): do not lock the covering tree when sliding something under it (Al Viro)\n- ALSA: usb-audio: Fix out-of-bounds read in snd_usb_get_audioformat_uac3() (Youngjun Lee) [Orabug: 38175065] {CVE-2025-38249}\n- i2c: robotfuzz-osif: disable zero-length read messages (Wolfram Sang)\n- i2c: tiny-usb: disable zero-length read messages (Wolfram Sang)\n- RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction (Shin'Ichiro Kawasaki) [Orabug: 38158592] {CVE-2025-38211}\n- RDMA/core: Use refcount_t instead of atomic_t on refcount of iwcm_id_private (Weihang Li)\n- media: vivid: Change the siize of the composing (Denis Arefev)\n- media: omap3isp: use sgtable-based scatterlist wrappers (Marek Szyprowski)\n- media: cxusb: no longer judge rbuf when the write fails (Edward Adam Davis) [Orabug: 38158692] {CVE-2025-38229}\n- media: cxusb: use dev_dbg() rather than hand-rolled debug (Sean Young)\n- jfs: validate AG parameters in dbMount() to prevent crashes (Vasiliy Kovalev)\n- fs/jfs: consolidate sanity checking in dbMount (Dave Kleikamp)\n- ASoC: meson: meson-card-utils: use of_property_present() for DT parsing (Martin Blumenstingl)\n- of: Add of_property_present() helper (Rob Herring)\n- of: property: define of_property_read_u{8,16,32,64}_array() unconditionally (Michael Walle)\n- kbuild: hdrcheck: fix cross build with clang (Arnd Bergmann)\n- kbuild: add --target to correctly cross-compile UAPI headers with Clang (Masahiro Yamada)\n- bpfilter: match bit size of bpfilter_umh to that of the kernel (Masahiro Yamada)\n- kbuild: use -MMD instead of -MD to exclude system headers from dependency (Masahiro Yamada)\n- VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify (Ma Wupeng) [Orabug: 38152869] {CVE-2025-38102}\n- VMCI: check context-notify_page after call to get_user_pages_fast() to avoid GPF (George Kennedy)\n- ovl: Check for NULL d_inode() in ovl_dentry_upper() (Kees Cook)\n- ceph: fix possible integer overflow in ceph_zero_objects() (Dmitry Kandybka)\n- ALSA: hda: Ignore unsol events for cards being shut down (Cezary Rojewski)\n- usb: typec: displayport: Receive DP Status Update NAK request exit dp altmode (Jos Wang)\n- usb: cdc-wdm: avoid setting WDM_READ for ZLP-s (Robert Hodaszi)\n- usb: Add checks for snprintf() calls in usb_alloc_dev() (Andy Shevchenko)\n- tty: serial: uartlite: register uart driver in init (Jakub Lewalski)\n- usb: potential integer overflow in usbg_make_tpg() (Chen Yufeng)\n- iio: pressure: zpa2326: Use aligned_s64 for the timestamp (Jonathan Cameron)\n- md/md-bitmap: fix dm-raid max_write_behind setting (Yu Kuai)\n- dmaengine: xilinx_dma: Set dma_device directions (Thomas Gessler)\n- mfd: max14577: Fix wakeup source leaks on device unbind (Krzysztof Kozlowski)\n- mailbox: Not protect module_put with spin_lock_irqsave (Peng Fan)\n- cifs: Fix cifs_query_path_info() for Windows NT servers (Pali Rohar)",
  "id": "ELSA-2025-28049",
  "ovalId": "oval:com.oracle.elsa:def:202528049",
  "source": "oracle_linux",
  "title": "ELSA-2025-28049: Unbreakable Enterprise kernel security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2025-28049.html"
}