{"cves":["CVE-2025-10263","CVE-2025-21807","CVE-2025-23131","CVE-2025-38525","CVE-2025-39729","CVE-2025-39936","CVE-2025-68299","CVE-2025-68768","CVE-2026-23247","CVE-2026-31419","CVE-2026-31732","CVE-2026-43010","CVE-2026-43116","CVE-2026-43197","CVE-2026-43216","CVE-2026-43303","CVE-2026-45850","CVE-2026-45897","CVE-2026-45901","CVE-2026-45907","CVE-2026-45944","CVE-2026-46054","CVE-2026-46093","CVE-2026-46252","CVE-2026-52908","CVE-2026-52909","CVE-2026-52910","CVE-2026-52917","CVE-2026-52923","CVE-2026-52924","CVE-2026-52927","CVE-2026-52929","CVE-2026-52930","CVE-2026-52934","CVE-2026-52942","CVE-2026-52946","CVE-2026-52947","CVE-2026-52948","CVE-2026-52975","CVE-2026-52995","CVE-2026-53005","CVE-2026-53078","CVE-2026-53090","CVE-2026-53101","CVE-2026-53131","CVE-2026-53132","CVE-2026-53134","CVE-2026-53135","CVE-2026-53136","CVE-2026-53137","CVE-2026-53138","CVE-2026-53142","CVE-2026-53143","CVE-2026-53144","CVE-2026-53146","CVE-2026-53147","CVE-2026-53148","CVE-2026-53149","CVE-2026-53150","CVE-2026-53151","CVE-2026-53154","CVE-2026-53156","CVE-2026-53167","CVE-2026-53168","CVE-2026-53175","CVE-2026-53176","CVE-2026-53177","CVE-2026-53180","CVE-2026-53181","CVE-2026-53182","CVE-2026-53183","CVE-2026-53184","CVE-2026-53185","CVE-2026-53186","CVE-2026-53189","CVE-2026-53190","CVE-2026-53191","CVE-2026-53192","CVE-2026-53193","CVE-2026-53194","CVE-2026-53195","CVE-2026-53196","CVE-2026-53199","CVE-2026-53207","CVE-2026-53208","CVE-2026-53209","CVE-2026-53210","CVE-2026-53212","CVE-2026-53213","CVE-2026-53214","CVE-2026-53215","CVE-2026-53216","CVE-2026-53217","CVE-2026-53218","CVE-2026-53219","CVE-2026-53220","CVE-2026-53221","CVE-2026-53223","CVE-2026-53225","CVE-2026-53226","CVE-2026-53227","CVE-2026-53228","CVE-2026-53229","CVE-2026-53230","CVE-2026-53232","CVE-2026-53233","CVE-2026-53235","CVE-2026-53236","CVE-2026-53237","CVE-2026-53238","CVE-2026-53239","CVE-2026-53241","CVE-2026-53245","CVE-2026-53249","CVE-2026-53251","CVE-2026-53252","CVE-2026-53253","CVE-2026-53254","CVE-2026-53255","CVE-2026-53256","CVE-2026-53260","CVE-2026-53261","CVE-2026-53262","CVE-2026-53263","CVE-2026-53264","CVE-2026-53266","CVE-2026-53267","CVE-2026-53268","CVE-2026-53269","CVE-2026-53270","CVE-2026-53272","CVE-2026-53273","CVE-2026-53275","CVE-2026-53325","CVE-2026-53328","CVE-2026-53329","CVE-2026-53337","CVE-2026-53341","CVE-2026-53345","CVE-2026-53347","CVE-2026-53349","CVE-2026-53350","CVE-2026-53352","CVE-2026-53353","CVE-2026-53354","CVE-2026-53356","CVE-2026-53358","CVE-2026-53360","CVE-2026-53361","CVE-2026-53364","CVE-2026-53365","CVE-2026-53381","CVE-2026-53384","CVE-2026-53385","CVE-2026-53388","CVE-2026-53391","CVE-2026-53392","CVE-2026-53393","CVE-2026-53394","CVE-2026-53397","CVE-2026-53398","CVE-2026-53399","CVE-2026-53400","CVE-2026-53402","CVE-2026-53403","CVE-2026-63794","CVE-2026-63795","CVE-2026-63796","CVE-2026-63800","CVE-2026-63801","CVE-2026-63802","CVE-2026-63803","CVE-2026-63804","CVE-2026-63806","CVE-2026-63807","CVE-2026-63808","CVE-2026-63809","CVE-2026-63810","CVE-2026-63821","CVE-2026-63822","CVE-2026-63823","CVE-2026-63824","CVE-2026-63826","CVE-2026-63829","CVE-2026-63830","CVE-2026-63831","CVE-2026-63834","CVE-2026-63835","CVE-2026-63836","CVE-2026-63867","CVE-2026-63868","CVE-2026-63869","CVE-2026-63870","CVE-2026-63871","CVE-2026-63875","CVE-2026-63881","CVE-2026-63882","CVE-2026-63884","CVE-2026-63891","CVE-2026-63892","CVE-2026-63893","CVE-2026-63897","CVE-2026-63898","CVE-2026-63899","CVE-2026-63900","CVE-2026-63901","CVE-2026-63902","CVE-2026-63903","CVE-2026-63904","CVE-2026-63908","CVE-2026-63912","CVE-2026-63913","CVE-2026-63914","CVE-2026-63916","CVE-2026-63917","CVE-2026-63918","CVE-2026-63919","CVE-2026-63920","CVE-2026-63921","CVE-2026-63922","CVE-2026-63924","CVE-2026-63925","CVE-2026-63926","CVE-2026-63927","CVE-2026-63928","CVE-2026-63929","CVE-2026-63937","CVE-2026-63938","CVE-2026-63939","CVE-2026-63940","CVE-2026-63942","CVE-2026-63944","CVE-2026-63945","CVE-2026-63946","CVE-2026-63947","CVE-2026-63948","CVE-2026-63949","CVE-2026-63952","CVE-2026-63956","CVE-2026-63957","CVE-2026-63958","CVE-2026-63961","CVE-2026-63962","CVE-2026-63963","CVE-2026-63968","CVE-2026-63969","CVE-2026-63970","CVE-2026-63971","CVE-2026-63973","CVE-2026-63974","CVE-2026-63975","CVE-2026-63976","CVE-2026-63978","CVE-2026-63980","CVE-2026-63981","CVE-2026-63982","CVE-2026-63983","CVE-2026-63984","CVE-2026-63985","CVE-2026-63987","CVE-2026-63990","CVE-2026-63992","CVE-2026-63993","CVE-2026-63994","CVE-2026-63995","CVE-2026-63996","CVE-2026-63997","CVE-2026-64000","CVE-2026-64002","CVE-2026-64003","CVE-2026-64007","CVE-2026-64009","CVE-2026-64012","CVE-2026-64014","CVE-2026-64090","CVE-2026-64091","CVE-2026-64093","CVE-2026-64094","CVE-2026-64095","CVE-2026-64122","CVE-2026-64123","CVE-2026-64131","CVE-2026-64187","CVE-2026-64189","CVE-2026-64191","CVE-2026-64192","CVE-2026-64205","CVE-2026-64206","CVE-2026-64227","CVE-2026-64235","CVE-2026-64237","CVE-2026-64239","CVE-2026-64241","CVE-2026-64244","CVE-2026-64245","CVE-2026-64247","CVE-2026-64251","CVE-2026-64253","CVE-2026-64256","CVE-2026-64257","CVE-2026-64265","CVE-2026-64266","CVE-2026-64270","CVE-2026-64271","CVE-2026-64272","CVE-2026-64275","CVE-2026-64276","CVE-2026-64279","CVE-2026-64284","CVE-2026-64286","CVE-2026-64287","CVE-2026-64289","CVE-2026-64294","CVE-2026-64296","CVE-2026-64298","CVE-2026-64299","CVE-2026-64304","CVE-2026-64305","CVE-2026-64306","CVE-2026-64307","CVE-2026-64308","CVE-2026-64309","CVE-2026-64310","CVE-2026-64312","CVE-2026-64313","CVE-2026-64317","CVE-2026-64319","CVE-2026-64320","CVE-2026-64321","CVE-2026-64322","CVE-2026-64323","CVE-2026-64324","CVE-2026-64326","CVE-2026-64330","CVE-2026-64332","CVE-2026-64333","CVE-2026-64334","CVE-2026-64335","CVE-2026-64336","CVE-2026-64338","CVE-2026-64340","CVE-2026-64341","CVE-2026-64342","CVE-2026-64343","CVE-2026-64344","CVE-2026-64348","CVE-2026-64351","CVE-2026-64352","CVE-2026-64354","CVE-2026-64355","CVE-2026-64357","CVE-2026-64362","CVE-2026-64363","CVE-2026-64364","CVE-2026-64365","CVE-2026-64368","CVE-2026-64370","CVE-2026-64371","CVE-2026-64372","CVE-2026-64373","CVE-2026-64374","CVE-2026-64375","CVE-2026-64376","CVE-2026-64378","CVE-2026-64379","CVE-2026-64380","CVE-2026-64381","CVE-2026-64382","CVE-2026-64383","CVE-2026-64384","CVE-2026-64385","CVE-2026-64386","CVE-2026-64387","CVE-2026-64401","CVE-2026-64403","CVE-2026-64404","CVE-2026-64405","CVE-2026-64406","CVE-2026-64408","CVE-2026-64411","CVE-2026-64412","CVE-2026-64413","CVE-2026-64414","CVE-2026-64415","CVE-2026-64416","CVE-2026-64418","CVE-2026-64420","CVE-2026-64422","CVE-2026-64423","CVE-2026-64424","CVE-2026-64425","CVE-2026-64427","CVE-2026-64433","CVE-2026-64434","CVE-2026-64435","CVE-2026-64436","CVE-2026-64438","CVE-2026-64448","CVE-2026-64450","CVE-2026-64452","CVE-2026-64455","CVE-2026-64456","CVE-2026-64457","CVE-2026-64458","CVE-2026-64461","CVE-2026-64465","CVE-2026-64470","CVE-2026-64471","CVE-2026-64472","CVE-2026-64473","CVE-2026-64474","CVE-2026-64475","CVE-2026-64476","CVE-2026-64477","CVE-2026-64478","CVE-2026-64479","CVE-2026-64480","CVE-2026-64481","CVE-2026-64484","CVE-2026-64486","CVE-2026-64487","CVE-2026-64489","CVE-2026-64490","CVE-2026-64496","CVE-2026-64503","CVE-2026-64504","CVE-2026-64508","CVE-2026-64510","CVE-2026-64511","CVE-2026-64512","CVE-2026-64514","CVE-2026-64523","CVE-2026-64524","CVE-2026-64527","CVE-2026-64528","CVE-2026-64529","CVE-2026-64530","CVE-2026-64531","CVE-2026-64534","CVE-2026-64535","CVE-2026-64538","CVE-2026-64539","CVE-2026-64540","CVE-2026-64542","CVE-2026-64543","CVE-2026-64544","CVE-2026-64545","CVE-2026-64546","CVE-2026-64547","CVE-2026-64548","CVE-2026-64549","CVE-2026-64551","CVE-2026-64552","CVE-2026-64553","CVE-2026-64554","CVE-2026-64555","CVE-2026-64556","CVE-2026-64557","CVE-2026-64560","CVE-2026-64561","CVE-2026-64562","CVE-2026-64563","CVE-2026-64564","CVE-2026-64567","CVE-2026-64568","CVE-2026-64569","CVE-2026-64570","CVE-2026-64571","CVE-2026-64572","CVE-2026-64574","CVE-2026-64575","CVE-2026-64576","CVE-2026-64577","CVE-2026-64579","CVE-2026-64580","CVE-2026-64582","CVE-2026-64586","CVE-2026-64589","CVE-2026-64593","CVE-2026-64597","CVE-2026-64598","CVE-2026-64599","CVE-2026-64600","CVE-2026-64603","CVE-2026-64604","CVE-2026-68085","CVE-2026-68091","CVE-2026-68092","CVE-2026-68093","CVE-2026-68096","CVE-2026-68102","CVE-2026-68106","CVE-2026-68107","CVE-2026-68108","CVE-2026-68110","CVE-2026-68111","CVE-2026-68112","CVE-2026-68113","CVE-2026-68115","CVE-2026-68116","CVE-2026-68117","CVE-2026-68118","CVE-2026-68119","CVE-2026-68121","CVE-2026-68123","CVE-2026-68125","CVE-2026-68126","CVE-2026-68128","CVE-2026-68129","CVE-2026-68131","CVE-2026-68133","CVE-2026-68136","CVE-2026-68138","CVE-2026-68139","CVE-2026-68142","CVE-2026-68143","CVE-2026-68145","CVE-2026-68146","CVE-2026-68148","CVE-2026-68149","CVE-2026-68153","CVE-2026-68154","CVE-2026-68155","CVE-2026-68156","CVE-2026-68157","CVE-2026-68158","CVE-2026-68160","CVE-2026-68161","CVE-2026-68162","CVE-2026-68164","CVE-2026-68165","CVE-2026-68166","CVE-2026-68169","CVE-2026-68180","CVE-2026-68181","CVE-2026-68184","CVE-2026-68186","CVE-2026-68187","CVE-2026-68188","CVE-2026-68189","CVE-2026-68192","CVE-2026-68193","CVE-2026-68194","CVE-2026-68197","CVE-2026-68198","CVE-2026-68199","CVE-2026-68200","CVE-2026-68201","CVE-2026-68202","CVE-2026-68205","CVE-2026-68206","CVE-2026-68212","CVE-2026-68213","CVE-2026-68214","CVE-2026-68216","CVE-2026-68217","CVE-2026-68218","CVE-2026-68226","CVE-2026-68227","CVE-2026-68234","CVE-2026-68235","CVE-2026-68236","CVE-2026-68243","CVE-2026-68244","CVE-2026-68245","CVE-2026-68246","CVE-2026-68247","CVE-2026-68248","CVE-2026-68249","CVE-2026-68250","CVE-2026-68251","CVE-2026-68252","CVE-2026-68253","CVE-2026-68254","CVE-2026-68255","CVE-2026-68256","CVE-2026-68257","CVE-2026-68259","CVE-2026-68264","CVE-2026-68266","CVE-2026-68267","CVE-2026-68269","CVE-2026-68271","CVE-2026-68272","CVE-2026-68273","CVE-2026-68276","CVE-2026-68277","CVE-2026-68278","CVE-2026-68279","CVE-2026-68284","CVE-2026-68293","CVE-2026-68294","CVE-2026-68296","CVE-2026-68297","CVE-2026-68299","CVE-2026-68300","CVE-2026-68301","CVE-2026-68304","CVE-2026-68307","CVE-2026-68309","CVE-2026-68310","CVE-2026-68311","CVE-2026-68313","CVE-2026-68315","CVE-2026-68317","CVE-2026-68318","CVE-2026-68319","CVE-2026-68320","CVE-2026-68325","CVE-2026-68326","CVE-2026-68328","CVE-2026-68329","CVE-2026-68336","CVE-2026-68338","CVE-2026-68339","CVE-2026-68343","CVE-2026-68344","CVE-2026-68346","CVE-2026-68348","CVE-2026-68349","CVE-2026-68350","CVE-2026-68351","CVE-2026-68352","CVE-2026-68353","CVE-2026-68355","CVE-2026-68362","CVE-2026-68363","CVE-2026-68365","CVE-2026-68372","CVE-2026-68373","CVE-2026-68374","CVE-2026-68376","CVE-2026-68377","CVE-2026-68378","CVE-2026-68386","CVE-2026-68388","CVE-2026-68391","CVE-2026-68392","CVE-2026-68394","CVE-2026-68398","CVE-2026-68402","CVE-2026-68403","CVE-2026-68405","CVE-2026-68406","CVE-2026-68407","CVE-2026-68408","CVE-2026-68410","CVE-2026-68411","CVE-2026-68413","CVE-2026-68414","CVE-2026-68416","CVE-2026-68419","CVE-2026-68422","CVE-2026-68425","CVE-2026-68427","CVE-2026-68428","CVE-2026-68429","CVE-2026-68430","CVE-2026-68432","CVE-2026-68433","CVE-2026-68434","CVE-2026-68439","CVE-2026-68442","CVE-2026-68444","CVE-2026-68445","CVE-2026-68446","CVE-2026-68450","CVE-2026-68456","CVE-2026-68461","CVE-2026-68469","CVE-2026-68475","CVE-2026-68476","CVE-2026-68477","CVE-2026-68479","CVE-2026-68480","CVE-2026-72004","CVE-2026-72005","CVE-2026-72010","CVE-2026-72012","CVE-2026-72014","CVE-2026-72015","CVE-2026-72017","CVE-2026-72019","CVE-2026-72020","CVE-2026-72021","CVE-2026-72024","CVE-2026-72027","CVE-2026-72029","CVE-2026-72030","CVE-2026-72032","CVE-2026-72034","CVE-2026-72035","CVE-2026-72036","CVE-2026-72037","CVE-2026-72039","CVE-2026-72040","CVE-2026-72045","CVE-2026-72046","CVE-2026-72049","CVE-2026-72051","CVE-2026-72052","CVE-2026-72053","CVE-2026-72054","CVE-2026-72055","CVE-2026-72056","CVE-2026-72057","CVE-2026-72059","CVE-2026-72061","CVE-2026-72063","CVE-2026-72065","CVE-2026-72066","CVE-2026-72067","CVE-2026-72068","CVE-2026-72070","CVE-2026-72083","CVE-2026-72084","CVE-2026-72085","CVE-2026-72086","CVE-2026-72087","CVE-2026-72088","CVE-2026-72096","CVE-2026-72099","CVE-2026-72100","CVE-2026-72101","CVE-2026-72102","CVE-2026-72103","CVE-2026-72105","CVE-2026-72106","CVE-2026-72107","CVE-2026-72108","CVE-2026-72110","CVE-2026-72111","CVE-2026-72113","CVE-2026-72114","CVE-2026-72115","CVE-2026-72116","CVE-2026-72117","CVE-2026-72118","CVE-2026-72119","CVE-2026-72120","CVE-2026-72121","CVE-2026-72122","CVE-2026-72123","CVE-2026-72124","CVE-2026-72125","CVE-2026-72126","CVE-2026-72127","CVE-2026-72129","CVE-2026-72130","CVE-2026-72132","CVE-2026-72135","CVE-2026-72136","CVE-2026-72138","CVE-2026-72144","CVE-2026-72151","CVE-2026-72152","CVE-2026-72155","CVE-2026-72157","CVE-2026-72159","CVE-2026-72160","CVE-2026-72161","CVE-2026-72163","CVE-2026-72164","CVE-2026-72165","CVE-2026-72166","CVE-2026-72170","CVE-2026-72172","CVE-2026-72174","CVE-2026-72175","CVE-2026-72176","CVE-2026-72177","CVE-2026-72178","CVE-2026-72182","CVE-2026-72183","CVE-2026-72212","CVE-2026-72213","CVE-2026-72217","CVE-2026-72218","CVE-2026-72219","CVE-2026-72221","CVE-2026-72222","CVE-2026-72223","CVE-2026-72224","CVE-2026-72225","CVE-2026-72226","CVE-2026-72227","CVE-2026-72228","CVE-2026-72229","CVE-2026-72230","CVE-2026-72231","CVE-2026-72232","CVE-2026-72233","CVE-2026-72234","CVE-2026-72235","CVE-2026-72237","CVE-2026-72240","CVE-2026-72241","CVE-2026-72242","CVE-2026-72243","CVE-2026-72245","CVE-2026-72247","CVE-2026-72250","CVE-2026-72251","CVE-2026-72252","CVE-2026-72253","CVE-2026-72254","CVE-2026-72255","CVE-2026-72256","CVE-2026-72261","CVE-2026-72262","CVE-2026-72265","CVE-2026-72266","CVE-2026-72272","CVE-2026-72273","CVE-2026-72280","CVE-2026-72282","CVE-2026-72284","CVE-2026-72286","CVE-2026-72289","CVE-2026-72297","CVE-2026-72298","CVE-2026-72299","CVE-2026-72300","CVE-2026-72301","CVE-2026-72302","CVE-2026-72304","CVE-2026-72305","CVE-2026-72306","CVE-2026-72307","CVE-2026-72308","CVE-2026-72310","CVE-2026-72314","CVE-2026-72316","CVE-2026-72317","CVE-2026-72318","CVE-2026-72319","CVE-2026-72320","CVE-2026-72322","CVE-2026-72323","CVE-2026-72324","CVE-2026-72325","CVE-2026-72326","CVE-2026-72330","CVE-2026-72333","CVE-2026-72335","CVE-2026-72336","CVE-2026-72338","CVE-2026-72339","CVE-2026-72342","CVE-2026-72343","CVE-2026-72347","CVE-2026-72348","CVE-2026-72349","CVE-2026-72350","CVE-2026-72351","CVE-2026-72356","CVE-2026-72360","CVE-2026-72361","CVE-2026-72362","CVE-2026-72364","CVE-2026-72371","CVE-2026-72372","CVE-2026-72373","CVE-2026-72374","CVE-2026-72376","CVE-2026-72378","CVE-2026-72379","CVE-2026-72389","CVE-2026-72390","CVE-2026-72392","CVE-2026-72395","CVE-2026-72396","CVE-2026-72400","CVE-2026-72405","CVE-2026-72406","CVE-2026-72409","CVE-2026-72416","CVE-2026-72418","CVE-2026-72419","CVE-2026-72420","CVE-2026-72421","CVE-2026-72425","CVE-2026-72427","CVE-2026-72428","CVE-2026-72430","CVE-2026-72433","CVE-2026-72434","CVE-2026-72435","CVE-2026-72436","CVE-2026-72437","CVE-2026-72441","CVE-2026-72443","CVE-2026-72444","CVE-2026-72447","CVE-2026-72449","CVE-2026-72450","CVE-2026-72451","CVE-2026-72452","CVE-2026-72464","CVE-2026-72465","CVE-2026-72466","CVE-2026-72467","CVE-2026-72468","CVE-2026-72469","CVE-2026-72472","CVE-2026-72473","CVE-2026-72476","CVE-2026-72481","CVE-2026-72487","CVE-2026-72491","CVE-2026-72502","CVE-2026-74255","CVE-2026-74256","CVE-2026-74259","CVE-2026-74263","CVE-2026-74265","CVE-2026-74267","CVE-2026-74270","CVE-2026-74271","CVE-2026-74278","CVE-2026-74279","CVE-2026-74281","CVE-2026-74282","CVE-2026-74283","CVE-2026-74284","CVE-2026-74287","CVE-2026-74288","CVE-2026-74290","CVE-2026-74296","CVE-2026-74297","CVE-2026-74300","CVE-2026-74302","CVE-2026-74305","CVE-2026-74306","CVE-2026-74307","CVE-2026-74308","CVE-2026-74310","CVE-2026-74312","CVE-2026-74313","CVE-2026-74316","CVE-2026-74318","CVE-2026-74320","CVE-2026-74321","CVE-2026-74327","CVE-2026-74329","CVE-2026-74330","CVE-2026-74331","CVE-2026-74332","CVE-2026-74339","CVE-2026-74340","CVE-2026-74341","CVE-2026-74346","CVE-2026-74348","CVE-2026-74349","CVE-2026-74351","CVE-2026-74352","CVE-2026-74353","CVE-2026-74356","CVE-2026-74359","CVE-2026-74362","CVE-2026-74363","CVE-2026-74365","CVE-2026-74376","CVE-2026-74377","CVE-2026-74378","CVE-2026-74379","CVE-2026-74380","CVE-2026-74381","CVE-2026-74382","CVE-2026-74384","CVE-2026-74386","CVE-2026-74387","CVE-2026-74390","CVE-2026-74391","CVE-2026-74393","CVE-2026-74394","CVE-2026-74395","CVE-2026-74397","CVE-2026-74398","CVE-2026-74399","CVE-2026-74401","CVE-2026-74404","CVE-2026-74406","CVE-2026-74408","CVE-2026-74410","CVE-2026-74411","CVE-2026-74416","CVE-2026-74417","CVE-2026-74424","CVE-2026-74425","CVE-2026-74426","CVE-2026-74427","CVE-2026-74432","CVE-2026-74435","CVE-2026-74436","CVE-2026-74439","CVE-2026-74440","CVE-2026-74441","CVE-2026-74442","CVE-2026-74443","CVE-2026-74444","CVE-2026-74445","CVE-2026-74446","CVE-2026-74447","CVE-2026-74448","CVE-2026-74453","CVE-2026-74454","CVE-2026-74455","CVE-2026-74456","CVE-2026-74457","CVE-2026-74458","CVE-2026-74460","CVE-2026-74464","CVE-2026-74465","CVE-2026-74469","CVE-2026-74470","CVE-2026-74471","CVE-2026-74472","CVE-2026-74473","CVE-2026-74475","CVE-2026-74476","CVE-2026-74479","CVE-2026-74480","CVE-2026-74481","CVE-2026-74482","CVE-2026-74484","CVE-2026-74485","CVE-2026-74486","CVE-2026-74487","CVE-2026-74488","CVE-2026-74490","CVE-2026-74492","CVE-2026-74495","CVE-2026-74497","CVE-2026-74498","CVE-2026-74499","CVE-2026-74500","CVE-2026-74501","CVE-2026-74502","CVE-2026-74503","CVE-2026-74504","CVE-2026-74505","CVE-2026-74507","CVE-2026-74508","CVE-2026-74509","CVE-2026-74510","CVE-2026-74512","CVE-2026-74516","CVE-2026-74517","CVE-2026-74518","CVE-2026-74519","CVE-2026-74523","CVE-2026-74531","CVE-2026-74532","CVE-2026-74535","CVE-2026-74536","CVE-2026-74540","CVE-2026-74541","CVE-2026-74543","CVE-2026-74546","CVE-2026-74547","CVE-2026-74548","CVE-2026-74549","CVE-2026-74550","CVE-2026-74552","CVE-2026-74553","CVE-2026-74555","CVE-2026-74556","CVE-2026-74557","CVE-2026-74564","CVE-2026-74565","CVE-2026-74566","CVE-2026-74567","CVE-2026-74569","CVE-2026-74572","CVE-2026-74574","CVE-2026-74575","CVE-2026-74577","CVE-2026-74579","CVE-2026-74580","CVE-2026-74581","CVE-2026-74582","CVE-2026-74583","CVE-2026-74584","CVE-2026-74585","CVE-2026-74586","CVE-2026-74587","CVE-2026-74588","CVE-2026-74589","CVE-2026-74590","CVE-2026-74592","CVE-2026-74594","CVE-2026-74595","CVE-2026-74597","CVE-2026-74598","CVE-2026-74603","CVE-2026-74604","CVE-2026-74606","CVE-2026-74607","CVE-2026-74608","CVE-2026-74609","CVE-2026-74610","CVE-2026-74612","CVE-2026-74613","CVE-2026-74614","CVE-2026-74615","CVE-2026-74616","CVE-2026-74618","CVE-2026-74619","CVE-2026-74620","CVE-2026-74621","CVE-2026-74622","CVE-2026-74623","CVE-2026-74624","CVE-2026-74625","CVE-2026-74630","CVE-2026-74632","CVE-2026-74634","CVE-2026-74635","CVE-2026-74636","CVE-2026-74641","CVE-2026-74642","CVE-2026-74644","CVE-2026-74654","CVE-2026-74656","CVE-2026-74657","CVE-2026-74658","CVE-2026-74660","CVE-2026-74661","CVE-2026-74663","CVE-2026-74664","CVE-2026-74665","CVE-2026-74666","CVE-2026-74667","CVE-2026-74668","CVE-2026-74669","CVE-2026-74670","CVE-2026-74671","CVE-2026-74673","CVE-2026-74675","CVE-2026-74676","CVE-2026-74677","CVE-2026-74678","CVE-2026-74680","CVE-2026-74682","CVE-2026-74683","CVE-2026-74684","CVE-2026-74688","CVE-2026-74689","CVE-2026-74691","CVE-2026-74696","CVE-2026-74700","CVE-2026-74701","CVE-2026-74704","CVE-2026-74705","CVE-2026-74710","CVE-2026-74712","CVE-2026-74714","CVE-2026-74717","CVE-2026-74718","CVE-2026-74720","CVE-2026-74722","CVE-2026-74724","CVE-2026-74725","CVE-2026-74726","CVE-2026-74730","CVE-2026-74732","CVE-2026-80590"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[6.12.0-206.104.3.3]\n- inet: frags: strip GSO state from fragments before reassembly (Xinyang Ge)  [Orabug: 39974840]  {CVE-2026-80590}\n\n[6.12.0-206.104.3.2]\n- KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs (Weiming Shi)  [Orabug: 39931938]  {CVE-2026-74517}\n- tcp: challenge ACK for non-exact RST in SYN-RECEIVED (Yuxiang Yang)  [Orabug: 39931929]  {CVE-2026-68118}\n- tcp: reorganize tcp_sock_write_txrx group for variables later (Chia-Yu Chang)  [Orabug: 39931929]\n- tcp: fast path functions later (Ilpo Jarvinen)  [Orabug: 39931929]\n- tcp: Pass flags to __tcp_send_ack (Ilpo Jarvinen)  [Orabug: 39931929]\n- mm/damon/ops-common: putback folios on invalid migrate nid (liyouhong)  [Orabug: 39931902]  {CVE-2026-74644}\n- KVM: SVM: Serialize accesses to the owner and mirror list with separate lock (Paolo Bonzini)  [Orabug: 39931893]  {CVE-2026-74607}\n- binfmt_misc: restore write access when removing an entry (Christian Brauner)  [Orabug: 39931874]  {CVE-2026-74487}\n- binfmt_misc: use exe_file_deny_write_access() for the interpreter clone (Christian Brauner)  [Orabug: 39931874] {CVE-2026-74486}\n- fs: don't block write during exec on pre-content watched files (Amir Goldstein)  [Orabug: 39931874]\n- fsnotify: opt-in for permission events at file open time (Amir Goldstein)  [Orabug: 39931874]\n- fsnotify, lsm: Decouple fsnotify from lsm (Song Liu)  [Orabug: 39931874]\n- net: pktgen: fix proc entry use-after-free (Chengfeng Ye)  [Orabug: 39931868]  {CVE-2026-74479}\n- net: pktgen: fix code style (WARNING: Block comments) (Peter Seiderer)  [Orabug: 39931868]\n- userfaultfd: prevent registration of special VMAs (Mike Rapoport (Microsoft))  [Orabug: 39931866]  {CVE-2026-68166}\n- mm/khugepaged: guard is_zero_pfn() calls with pte_present() (Lance Yang)  [Orabug: 39931866]\n- net/sched: serialize qdisc_rtab_list against concurrent get/put (Aldo Ariel Panzardo)  [Orabug: 39931864]  {CVE-2026-68138}\n- octeontx2-vf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)  [Orabug: 39924423]\n- Revert 'octeontx2-vf: clear stale mailbox IRQ state before request_irq()' (Saeed Mirzamohammadi)  [Orabug: 39924423]\n- octeontx2-pf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)  [Orabug: 39924423]\n- Revert 'octeontx2-pf: clear stale mailbox IRQ state before request_irq()' (Saeed Mirzamohammadi)  [Orabug: 39924423]\n- erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms (Gao Xiang)\n- m68k: Define NR_CPUS to 1 (Uwe Kleine-Konig)\n- drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini (Pierre-Eric Pelloux-Prayer)\n- drm/amdgpu: remove unused function parameter (Yunxiang Li)\n- drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE (Nathan Lucas)\n\n[6.12.0-206.100.3.1]\n- LTS version: v6.12.104 (Saeed Mirzamohammadi)\n- bpf: tcp: fix double sock release on batch realloc (Xiang Mei (Microsoft))\n- thunderbolt: Fix bandwidth group reservation indexing (Xu Rao) {CVE-2026-80736}\n- thunderbolt: Bound the DROM dual link port number before indexing sw-ports (Bryam Vargas) {CVE-2026-74585}\n- sctp: clear new_transport when removing a peer (Qing Ming) {CVE-2026-74586}\n- sctp: fix use-after-free of cached ASCONF chunk (Yuxiang Yang) {CVE-2026-74587}\n- sctp: keep chunk-transport in step with the list it is queued on (Baul Lee) {CVE-2026-74588}\n- scsi: scsi_debug: Negate wrapped memcmp() result (Xu Rao)\n- bpf, sockmap: Fix sk_redir use-after-free in send verdict (Chengfeng Ye) {CVE-2026-74589}\n- fsverity: Fix silent truncation in bpf_get_fsverity_digest() (Eric Biggers)\n- fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions (Eric Biggers) {CVE-2026-74590}\n- ima: Instantiate file_truncate and path_truncate hooks (Mimi Zohar) {CVE-2026-74592}\n- sched/psi: Shut down rtpoll_timer in psi_cgroup_free() (Tejun Heo) {CVE-2026-74594}\n- fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() (Zhan Xusheng) {CVE-2026-74595}\n- ip6_tunnel: clear skb2-cb[] in ip6ip6_err() (Zhiling Zou) {CVE-2026-74597}\n- ipv6: fix Route Information option length validation (Yuejie Shi) {CVE-2026-74598}\n- ptp: ocp: Fix board ID over-read (Ahmad Byagowi) {CVE-2026-74603}\n- Revert 'thermal/drivers/hwmon: Cleanup coding style a bit' (Rafael J. Wysocki) {CVE-2026-74604}\n- eventfs: Fix use-after-free in eventfs_remove_rec() (Shuangpeng Bai) {CVE-2026-74606}\n- KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (Sean Christopherson) {CVE-2026-80726}\n- smb: client: Fix use-after-free in cifs_try_adding_channels() (Shuangpeng Bai) {CVE-2026-74608}\n- tipc: read le-link under the node lock in tipc_node_link_down() (Jun Yang) {CVE-2026-74609}\n- tls: don't leave a full plaintext sk_msg ring unpushed (chanyoung) {CVE-2026-74610}\n- vhost: reset the vring metadata cache on vring reconfiguration (Jun Yang) {CVE-2026-74580}\n- veth: fix skb length accounting after XDP frag adjustment (Sun Jian) {CVE-2026-74612}\n- vsock/virtio: avoid refilling the RX queue after teardown (Weiming Shi) {CVE-2026-74613}\n- vsock/virtio: read virtqueues under worker locks (Weiming Shi) {CVE-2026-74614}\n- vxlan: do not arm the ageing timer on a device that is down (Baul Lee) {CVE-2026-74615}\n- xdp: reject clones that overrun skb_shared_info tailroom (Zhiling Zou) {CVE-2026-74616}\n- Revert 'drm/amdgpu: fix aperture mapping leak' (Asad Kamal) {CVE-2026-80728}\n- binfmt_misc: don't warn when the mount is completed from another user namespace (Christian Brauner) {CVE-2026-74618}\n- ovl: don't warn when the mount is completed from another user namespace (Christian Brauner) {CVE-2026-74619}\n- net/sched: act_gact, act_police: range check the fallback control action (Hyunjung Ko) {CVE-2026-74620}\n- net/sched: act_ct: fix sk_buff leak when the header checks reject a packet (Hyunjung Ko) {CVE-2026-74621}\n- net: atlantic: free RX pages of consumed but not refilled buffers (Yangyu Chen) {CVE-2026-74622}\n- net: atlantic: free stranded TX buffers on ring deinit (Yangyu Chen) {CVE-2026-74623}\n- netfilter: nf_conntrack: defer invalid log until after unlock (Zihan Xi) {CVE-2026-74624}\n- netfilter: bridge: release template ct on non-IP path (Zhiling Zou) {CVE-2026-74625}\n- ipv6: prevent in6_dev_get() from resurrecting inet6_dev (Kyle Zeng) {CVE-2026-74630}\n- net: smc: fix splice entry lifetime imbalance in smc_rx_splice (Daming Li) {CVE-2026-74631}\n- mm/huge_memory: fix huge_zero_pfn race (Lorenzo Stoakes (ARM))\n- ring-buffer: Prevent subbuf order change when resizing is disabled (Vincent Donnefort) {CVE-2026-74634}\n- fbdev: bitblit: bound-check glyph index in bit_cursor() (Rik van Riel) {CVE-2026-74635}\n- tracing: Fix race between update_event_fields and, event_define_fields (Michael Wu) {CVE-2026-74636}\n- ALSA: usx2y: bound the hwdep mmap fault offset (Baul Lee) {CVE-2026-74641}\n- ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (Takashi Iwai) {CVE-2026-74642}\n- ring-buffer: Fix crash passing ERR_PTR to kthread_stop() (Hui Su) {CVE-2026-80730}\n- misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (Eddie Lin)\n- misc: fastrpc: take fl-lock when moving mmaps on interrupted invoke (Junrui Luo) {CVE-2026-74646}\n- misc: fastrpc: Remove buffer from list prior to unmap operation (Ekansh Gupta) {CVE-2026-74647}\n- misc: fastrpc: fix channel ctx ref leak when session alloc fails (Anandu Krishnan E)\n- staging: rtl8723bs: validate monitor transmit frame lengths (Mariano Baragiola) {CVE-2026-74648}\n- staging: rtl8723bs: fix missing shared-key auth challenge length check (Panagiotis Petrakopoulos) {CVE-2026-74649}\n- staging: rtl8723bs: fix OOB read in WMM_param_handler() (Muhammad Bilal) {CVE-2026-74650}\n- staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (Muhammad Bilal) {CVE-2026-74651}\n- serial: 8250_dma: Clear stale RX state on shutdown (Cunhao Lu) {CVE-2026-74654}\n- serial: qcom-geni: fix TX DMA buffer flush (Jan Sebastian Gotte) {CVE-2026-74655}\n- nvmem: layouts: Add fixed-layout driver (Mathieu Dubois-Briand)\n- mei: pull kvfree out of spinlock (Alexander Usyskin)\n- ipv4: fix use-after-free in fib_nhc_update_mtu() (Chengfeng Ye) {CVE-2026-74656}\n- ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops (Zihan Xi) {CVE-2026-74657}\n- selftests/bpf: Adapt sockmap update error handling (Michal Luczaj)\n- selftests/bpf: Ensure UDP sockets are bound (Michal Luczaj)\n- pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP (Claudiu Beznea)\n- kunit/fortify: Add back 'volatile' for sizeof() constants (Kees Cook)\n- kunit/fortify: Replace 'volatile' with OPTIMIZER_HIDE_VAR() (Kees Cook)\n- futex: Prevent robust futex exit race some more (Keno Fischer) {CVE-2026-74658}\n- crypto: ccp - Abort doing SEV INIT if SNP INIT fails (Ashish Kalra)\n- crypto: ccp - Fix checks for SNP_VLEK_LOAD input buffer length (Michael Roth)\n- KVM: SVM: Add support to initialize SEV/SNP functionality in KVM (Ashish Kalra)\n- crypto: ccp - Add new SEV/SNP platform shutdown API (Ashish Kalra)\n- dt-bindings: crypto: qcom,ice: Fix missing power-domain and iface clk (Harshal Dev)\n- block: Reorder the request allocation code in blk_mq_submit_bio() (Bart Van Assche)\n- KVM: s390: pci: Fix aisb calculation (Matthew Rosato)\n- KVM: s390: pci: Fix resource leak on IRQ registration failure (Farhan Ali)\n- KVM: s390: pci: Fix missing error codes and memory unaccounting (Farhan Ali)\n- KVM: s390: pci: Fix memory accounting for pinned/unpinned pages (Farhan Ali) {CVE-2026-74514}\n- net: bridge: mrp: fix uninitialised bytes on the wire (Baul Lee) {CVE-2026-74659}\n- netfilter: ebt_nflog: pin the NFLOG backend (Chengfeng Ye) {CVE-2026-74660}\n- mac802154: fix netdev use-after-free in beacon worker (Zihan Xi) {CVE-2026-74661}\n- net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header (Qihang Tang) {CVE-2026-80731}\n- net: octeontx2-pf: Fix UB in shift operation (Sergey V. Frolov)\n- net/sched: reject overly deep qdisc hierarchies (Zijie Huang) {CVE-2026-74663}\n- net: openvswitch: reallocate update replies for mismatched IDs (Zhiling Zou) {CVE-2026-74664}\n- net: fix skb length accounting after generic XDP frag adjustment (Sun Jian) {CVE-2026-74665}\n- packet: synchronize pressure clearing with ring reconfiguration (Zihan Xi) {CVE-2026-74666}\n- net/packet: reset the MAC header on the packet-socket transmit path (Doruk Tan Ozturk) {CVE-2026-74667}\n- packet: use consistent hard_header_len in TX_RING send path (Qihang Tang) {CVE-2026-74668}\n- packet: use consistent hard_header_len in non-ring send paths (Qihang Tang) {CVE-2026-74582}\n- ipvs: clear IPv4 options after rebasing tunnel ICMP errors (Kyle Zeng) {CVE-2026-74669}\n- ipvs: properly update the overload flag on dest edit (Julian Anastasov)\n- ipvs: add totalconns for dest (Julian Anastasov)\n- ipvs: stop estimator after disabled calc phase (Zhiling Zou) {CVE-2026-74670}\n- ima: fix out-of-bounds read in xattr_verify() (Lincoln Wallace) {CVE-2026-74671}\n- Input: evdev - fix information leak in evdev_pass_values() (Dmitry Torokhov) {CVE-2026-74673}\n- vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (Joshua Rogers) {CVE-2026-74675}\n- vt: add permission check for KDSKBMETA ioctl (Joshua Rogers) {CVE-2026-74676}\n- net: usb: ipheth: fix carrier_work UAF on disconnect (Doruk Tan Ozturk) {CVE-2026-74677}\n- net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (Yi Cong) {CVE-2026-74678}\n- usb: gadget: f_ncm: Use unsigned int for ndp_index (Sonali Pradhan) {CVE-2026-74679}\n- usb: cdnsp: fix incorrect endian conversions for APB timeout register (Pawel Laszczak)\n- thunderbolt: icm: Preserve USB4 proxy data-valid bit (Xu Rao)\n- usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (Aleksandr Nogikh) {CVE-2026-74680}\n- ALSA: usb-audio: fix OOB write on Type II inbound URBs (Baul Lee) {CVE-2026-74682}\n- Input: evdev - sanitize event type index when fetching event masks (Dmitry Torokhov) {CVE-2026-74683}\n- swapfile: call cond_resched() before locking si-lock (Guillaume Morin)\n- mtd: spinand: repeat reading in regular mode if continuous reading fails (Mikhail Kshevetskiy)\n- mtd: spinand: try a regular dirmap if creating a dirmap for continuous reading fails (Mikhail Kshevetskiy)\n- mtd: spinand: fix direct mapping creation sizes (Mikhail Kshevetskiy)\n- spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (Larisa Grigore)\n- net: fec: do not release NULL pages when RX buffer allocation fails (Mehmet Fide)\n- hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt (Guenter Roeck)\n- hwmon: (ltc4282) Clamp negative current limits (Guenter Roeck) {CVE-2026-74685}\n- hwmon: (ltc4282) Avoid overflow in maximum power calculation (Guenter Roeck)\n- hwmon: (ads7828) Fix external VREF regulator handling (Qingshuang Fu)\n- hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (Wilken Gottwalt)\n- tls: don't abort the connection on signal-interrupted sends (Maximilian Immanuel Brandtner)\n- sctp: clear control chunk transport if it is being removed (Xin Long) {CVE-2026-74688}\n- net/atm: fix slab-out-of-bounds read in vcc_setsockopt() (Eric Dumazet) {CVE-2026-74689}\n- ata: pata_sl82c105: fix bridge revision use-after-free (Hongyan Xu) {CVE-2026-80732}\n- net: thunderbolt: Tear down DMA paths before stopping the rings (Fan XinRan) {CVE-2026-74691}\n- net/smc: fix TOCTOU race between smc_listen_out() and listener close (Sidraya Jayagond) {CVE-2026-74692}\n- net: remove WARN_ON_ONCE() from sk_mc_loop() (Eric Dumazet) {CVE-2026-80733}\n- net: prestera: validate firmware header length (Pengpeng Hou) {CVE-2026-74693}\n- net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (Henry Martin) {CVE-2026-74694}\n- tcp: fix TFO max_qlen accounting across reuseport migration (Jiayuan Chen) {CVE-2026-74696}\n- sctp: fix addip_serial increment on ASCONF_ACK allocation failure (Qing Luo)\n- bnxt_en: Fix PTP PPS setting bug (Keegan Freyhof)\n- bnxt_en: Refresh VNIC default ring on queue restart if needed (Shravya KN)\n- bnxt_en: Determine and store default RX ring in vnic structure (Shravya KN)\n- bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss() (Shravya KN)\n- selftests/ftrace: refactor eprobes test to fix argument checks (Martin Kaiser)\n- hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (Guenter Roeck)\n- hwmon: (nzxt-smart2) Check return value of init_device() in probe (Qingshuang Fu)\n- net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers (Jamal Hadi Salim) {CVE-2026-74700}\n- net/openvswitch: check Ethernet header length in key_extract() (Cen Zhang (Microsoft))\n- net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter (Toke Hoiland-Jorgensen) {CVE-2026-74704}\n- udp: fix potential use-after-free in tunnel segmentation (Xuanqiang Luo) {CVE-2026-74705}\n- xsk: require at least 16 bytes of TX metadata (Stanislav Fomichev) {CVE-2026-74710}\n- tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss() (Nathan Gao)\n- vdpa/mlx5: Fix buffer length in create_direct_keys() (Christian Borntraeger) {CVE-2026-74712}\n- vhost/vdpa: reject overflowing PA map page counts on 32-bit (Yousef Alhouseen)\n- bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() (Jose Fernandez (Anthropic))\n- bpf: tcp: Avoid socket skips and repeats during iteration (Jordan Rife)\n- bpf: tcp: Use bpf_tcp_iter_batch_item for bpf_tcp_iter_state batch items (Jordan Rife)\n- bpf: tcp: Get rid of st_bucket_done (Jordan Rife)\n- bpf: tcp: Make sure iter-batch always contains a full bucket snapshot (Jordan Rife)\n- bpf: tcp: Make mem flags configurable through bpf_iter_tcp_realloc_batch (Jordan Rife)\n- counter: microchip-tcb-capture: Fix DT channel validation (Babanpreet Singh)\n- net/mlx5: fw_tracer, return NULL on create error (Michael Guralnik) {CVE-2026-74717}\n- devlink: fix net namespace reference leak in reload (Or Har-Toov) {CVE-2026-74718}\n- net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete (Jiawen Liu)\n- net/sched: cls_route: fix fastmap use-after-free on filter (Jamal Hadi Salim) {CVE-2026-74583}\n- net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() (Mahanta Jambigi) {CVE-2026-74719}\n- bpf: Preserve pointer state for commuted arithmetic (Yiyang Chen) {CVE-2026-74720}\n- btrfs: fix memory leak in btrfs_do_encoded_write() (Dmitry Antipov) {CVE-2026-74722}\n- watchdog: bd96801_wdt: Fix timeout for enabled WDG (Matti Vaittinen)\n- ipvs: return the csum validation for forward hook (Julian Anastasov)\n- ipvs: avoid out-of-bounds write in ip_vs_nat_icmp (Julian Anastasov) {CVE-2026-74724}\n- netfilter: ipset: switch ext_size to atomic64_t (Jozsef Kadlecsik)\n- pds_core: cancel pending PCI reset work on AER recovery (Nikhil P. Rao)\n- pds_core: keep the health thread stopped during reset (Nikhil P. Rao)\n- net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock (Shay Drory) {CVE-2026-80739}\n- enic: fix tx_hang_reset use-after-free on device removal (Satish Kharat) {CVE-2026-74725}\n- bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor (Xiang Mei (Microsoft))\n- Revert 'net: thunderbolt: Enable end-to-end flow control also in transmit' (Fan Ye)\n- net: hns3: fix speed configuration residue after driver reload (Jijie Shao)\n- drm/bridge: ps8640: propagate AUX transfer register errors (Pengpeng Hou)\n- ARM: dts: BCM5301X: fix PCIe controller 2 second interrupt (Rosen Penev)\n- ARM: npcm: Fix OF node refcount leaks in SMP setup (Yuho Choi)\n- arm64: dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer (Daniel Drake)\n- NFS: Pin the 'struct nfs_server' during a FREE_STATEID call (Anna Schumaker) {CVE-2026-74730}\n- s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() (Harald Freudenberger) {CVE-2026-80708}\n- drm/amd/display: Check for tg ops in dce110_set_avmute (Ray Wu) {CVE-2026-74732}\n- drm/amd/display: Add AV mute wait frames to dce110_set_avmute (Ray Wu)\n- selftests/bpf: Fail unbound UDP on sockmap update (Michal Luczaj)\n- mount: honour SB_NOUSER in the new mount API (Al Viro)\n- LTS version: v6.12.103 (Saeed Mirzamohammadi)\n- drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info (Thomas Zimmermann)\n- drm/fb-helper: Fix a locking bug in an error path (Bart Van Assche)\n- usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path (Andrei Kuchynski)\n- can: isotp: fix timer drain order, wakeup handling and tx_gen ordering (Oliver Hartkopp)\n- can: use skb hash instead of private variable in headroom (Oliver Hartkopp)\n- rxrpc: Fix irq-disabled in local_bh_enable() (David Howells) {CVE-2025-38525}\n- rxrpc: Manage RTT per-call rather than per-peer (David Howells)\n- rxrpc: Fix the calculation and use of RTO (David Howells)\n- rxrpc: Adjust the rxrpc_rtt_rx tracepoint (David Howells)\n- rxrpc: Generate rtt_min (David Howells)\n- drm/xe/pt: Reset current_op in xe_pt_update_ops_init() (Zongyao Bai) {CVE-2026-68264}\n- drm/xe: Stub out new pagefault layer (Matthew Brost)\n- drm/i915/hdcp: check streams[] bounds before overflow (Jani Nikula) {CVE-2026-68253}\n- drm/i915/hdcp: Skip inactive MST connectors when building stream list (Suraj Kandpal)\n- drm/i915/hdcp: require monotonically increasing seq_num_v (Jani Nikula)\n- drm/i915/hdcp: Move to using intel_display in intel_hdcp (Suraj Kandpal)\n- drm/xe: Hold a dma-buf reference for imported BOs (Nitin Gote) {CVE-2026-68266}\n- drm/xe: Rename ___xe_bo_create_locked() (Thomas Hellstrom)\n- drm/i915/vrr: require valid min/max vfreq for VRR (Jani Nikula) {CVE-2026-68254}\n- drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() (Ville Syrjala)\n- drm/xe: Wait on external BO kernel fences in exec IOCTL (Matthew Brost) {CVE-2026-74440}\n- drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse] (Thomas Hellstrom)\n- drm/tegra: fbdev: Remove offset into framebuffer memory (Thomas Zimmermann)\n- drm/fb-helper: Allocate and release fb_info in single place (Thomas Zimmermann)\n- drm/amdgpu/gfx: fix cleaner shader IB buffer overflow (Asad Kamal) {CVE-2026-68276}\n- drm/amdgpu: give each kernel job a unique id (Pierre-Eric Pelloux-Prayer)\n- drm/sched: Store the drm client_id in drm_sched_fence (Pierre-Eric Pelloux-Prayer)\n- drm/amdgpu: Fix context pstate override handling (Tvrtko Ursulin) {CVE-2026-68273}\n- drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions (Timur Kristof)\n- mm/kmemleak: fix checksum computation for per-cpu objects (Breno Leitao)\n- kmemleak: iommu/iova: fix transient kmemleak false positive (Catalin Marinas)\n- mptcp: pm: userspace: fix use-after-free in get_local_id (Geliang Tang) {CVE-2026-68169}\n- mptcp: pm: use addr entry for get_local_id (Geliang Tang)\n- mptcp: add mptcp_userspace_pm_lookup_addr helper (Geliang Tang)\n- mptcp: pm: avoid code duplication to lookup endp (Geliang Tang)\n- ALSA: hda: codecs: hdmi: disable keep-alive before audio format change (Kai Vehmanen)\n- wifi: brcmfmac: set F2 blocksize to 256 for BCM43752 (LiangCheng Wang)\n- wifi: brcmfmac: fix 43752 SDIO FWVID incorrectly labelled as Cypress (CYW) (Gokul Sivakumar)\n- wifi: ath6kl: fix use-after-free in aggr_reset_state() (Daniel Hodges) {CVE-2026-68198}\n- wifi: brcmfmac: drain bus_reset work on device removal (Fan Wu) {CVE-2026-64586}\n- media: uapi: rkisp: Correct name version enum (Niklas Soderlund)\n- media: chips-media: wave5: Support CBP profile (Jackson Lee)\n- media: imx219: Fix maximum frame length in lines (Sakari Ailus)\n- media: i2c: imx219: Rename VTS to FRM_LENGTH (Jai Luthra)\n- usb: typec: ucsi: Fix race condition and ordering in port unregistration (Andrei Kuchynski) {CVE-2026-74441}\n- usb: typec: ucsi: split connector lock classes (Sergey Senozhatsky)\n- usb: gadget: f_tcm: synchronize delayed set_alt with teardown (Cen Zhang) {CVE-2026-68367}\n- gpio: pch: use raw_spinlock_t for the register lock (Junjie Cao) {CVE-2026-74468}\n- lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled() (Harry Yoo (Oracle))\n- mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (Kiryl Shutsemau (Meta))\n- fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes (Kiryl Shutsemau (Meta))\n- mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() (Kiryl Shutsemau (Meta))\n- drm/xe/rtp: Ensure locking/ref counting for OA whitelists (Ashutosh Dixit)\n- drm/xe/oa: (De-)whitelist OA registers on OA stream open/release (Ashutosh Dixit)\n- drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt (Ashutosh Dixit)\n- drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs (Ashutosh Dixit)\n- drm/xe/rtp: Save OA nonpriv registers to register save/restore lists (Ashutosh Dixit)\n- drm/xe/rtp: Generalize whitelist_apply_to_hwe (Ashutosh Dixit)\n- drm/xe/rtp: Keep track of non-OA nonpriv slots (Ashutosh Dixit)\n- drm/xe/rtp: Maintain OA whitelists separately (Ashutosh Dixit)\n- drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (Ashutosh Dixit) {CVE-2026-68267}\n- drm/xe: Apply whitelist to engine save-restore (Lucas De Marchi)\n- drm/xe: Introduce xe_gt_dbg_printer() (Michal Wajdeczko)\n- drm/xe/rtp: Refactor OAG MMIO trigger register whitelisting (Ashutosh Dixit)\n- Bluetooth: ISO: fix CONNECTED - CLOSED transition on shutdown/release (Pauli Virtanen)\n- of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails (Wandun Chen) {CVE-2026-74352}\n- ata: ahci: Make ahci_ignore_port() handle empty mask_port_map (Niklas Cassel)\n- ata: libahci_platform: Do not set mask_port_map when not needed (Damien Le Moal)\n- HID: logitech-dj: Fix maxfield check in DJ short report validation (HyeongJun An) {CVE-2026-64427}\n- spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX (Jun Guo)\n- drm/vmwgfx: validate external BO copy bounds for both stride paths (Zack Rusin) {CVE-2026-80700}\n- drm/vmwgfx: use check_add_overflow for shader size+offset bound (Zack Rusin)\n- drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure (Zack Rusin) {CVE-2026-74442}\n- drm/vmwgfx: bound DMA command body size against suffix pointer (Zack Rusin) {CVE-2026-74443}\n- drm/vmwgfx: validate DRAW_PRIMITIVES header size before division (Zack Rusin) {CVE-2026-74444}\n- drm/vmwgfx: drop dma_buf reference on foreign-fd prime import (Zack Rusin)\n- drm/vmwgfx: reject DX_BIND_QUERY without a DX context (Zack Rusin) {CVE-2026-74445}\n- drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size (Zack Rusin) {CVE-2026-80702}\n- drm/amdkfd: hold event_mutex while checkpointing CRIU events (William Palacek) {CVE-2026-74446}\n- drm/amdkfd: Handle invalid event type in CRIU event restore (David Francis)\n- drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment (William Palacek) {CVE-2026-74447}\n- drm/amdkfd: fix QID bit leak in pqm_create_queue() (Vladimir Marioukhine) {CVE-2026-74448}\n- drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (Gang Ba) {CVE-2026-80703}\n- drm/amd/display: use proper context for logging (Jiri Slaby (SUSE))\n- drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames (Ray Wu)\n- drm/amdgpu: cap GTT size to physical RAM on APUs (Harkirat Gill)\n- drm/amdgpu: restore UMD profile pstate after runtime resume (Candice Li)\n- drm/mediatek: ovl_adaptor: balance component registrations (Myeonghun Pak)\n- drm/panthor: validate firmware interface structure sizes (Osama Abdelkader) {CVE-2026-74451}\n- drm/panthor: reject firmware sections with oversized data (Osama Abdelkader) {CVE-2026-74452}\n- drm/vc4: Zero the tile state data array before each BIN job (Maira Canal) {CVE-2026-74453}\n- drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size (Jose Maria Casanova Crespo) {CVE-2026-74454}\n- drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs (Alexander Kaplan)\n- can: ctucanfd: mark error-active controller status valid (Avi Weiss)\n- can: ctucanfd: handle bus error interrupts (Avi Weiss)\n- can: ctucanfd: unmap BAR0 using base address (Avi Weiss)\n- can: ctucanfd: use self-test mode for PRESUME_ACK (Avi Weiss)\n- can: ctucanfd: add missing MODULE_DEVICE_TABLE() (Pengpeng Hou)\n- can: peak_usb: validate uCAN receive record lengths (Pengpeng Hou) {CVE-2026-74455}\n- can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error (Maoyi Xie) {CVE-2026-74456}\n- can: peak_usb: add bounds check for USB channel index (James Gao) {CVE-2026-74457}\n- can: softing: fw_parse(): validate firmware record spans (Pengpeng Hou) {CVE-2026-80706}\n- can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents (Pengpeng Hou) {CVE-2026-74458}\n- can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() (Abdun Nihaal)\n- can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (Tetsuo Handa)\n- can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer (Oleksij Rempel) {CVE-2026-80707}\n- can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure (Marc Kleine-Budde)\n- can: ems_usb: validate CPC message lengths (Pengpeng Hou) {CVE-2026-74460}\n- can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured (Lucas Martins Alves)\n- i2c: imx: Cancel hrtimer before clearing slave pointer (Liem) {CVE-2026-74461}\n- i2c: imx: Fix slave registration race and error handling (Liem) {CVE-2026-80678}\n- i2c: iproc: reset bus after timeout if START_BUSY is stuck (Jonas Gorski)\n- i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock (H. Nikolaus Schaller) {CVE-2026-74463}\n- ice: fix memory leak in ice_lbtest_prepare_rings() (Dawei Feng)\n- ice: wait for reset completion in ice_resume() (Aaron Ma)\n- net: openvswitch: fix skb leak on flow key update failure during ct (Ilya Maximets) {CVE-2026-74464}\n- net: openvswitch: fix skb leak on flow key update failure during recirculation (Ilya Maximets)\n- net: openvswitch: fix potential UAF on meter attach failure (Ilya Maximets) {CVE-2026-74465}\n- phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB (Nava kishore Manne)\n- phy: zynqmp: use read-modify-write for SERDES scrambler bypass (Nava kishore Manne)\n- phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask (Nava kishore Manne)\n- s390/zcrypt: Validate length for CCA ECC private key requests (Holger Dengler) {CVE-2026-68451}\n- s390/zcrypt: Validate length for CCA AES cipher key requests (Holger Dengler) {CVE-2026-68452}\n- s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs (Harald Freudenberger) {CVE-2026-80709}\n- s390/dasd: Fix undersized format-check buffer (Stefan Haberland) {CVE-2026-80710}\n- s390/dasd: Fix potential NULL pointer dereference (Jan Hoppner) {CVE-2026-80679}\n- s390/qeth: Check CAP_NET_ADMIN for private ioctls (Aswin Karuvally) {CVE-2026-74467}\n- s390/pci: Fix s390_pci_mmio_write syscall error return without MIO (Niklas Schnelle)\n- power: supply: max17040: handle missing status supplier (Jianing Li) {CVE-2026-80711}\n- power: supply: bq25890: fix the -10 C NTC lookup entry (Xu Rao)\n- cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized (Zhongqiu Han)\n- cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() (Abdun Nihaal)\n- gpio: pca953x: fix cache_only and IRQ state on restore_context() failure (bui duc phuc)\n- i2c: amd-mp2: Unregister callback on adapter add failure (Myeonghun Pak) {CVE-2026-80680}\n- hwmon: (pmbus/core) notify on the hwmon device, not the i2c client (Vincent Jardin)\n- hwmon: (npcm750-pwm-fan): stop fan timer on device detach (Hongyan Xu)\n- sctp: prevent peer transport count overflow (Asim Viladi Oglu Manizada) {CVE-2026-74469}\n- sctp: reject stale cookies with mismatched verification tags (Yuxiang Yang)\n- scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write (Ibrahim Hashimov) {CVE-2026-74470}\n- selftests/clone3: fix wild pointer access of getline due to missing init (Chris Gellermann)\n- selftests/mm: fix potential wild pointer access of getline due to missing init (Chris Gellermann)\n- spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure (Vijaya Krishna Nivarthi)\n- tracing/filters: Fix false positive match in regex_match_full() (Masami Hiramatsu (Google))\n- tracing: Check return value of __register_event() in trace_module_add_events() (Masami Hiramatsu (Google))\n- ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() (Ming Lei) {CVE-2026-74472}\n- vxlan: use pskb_network_may_pull() in route_shortcircuit() (Eric Dumazet) {CVE-2026-74473}\n- vxlan: use neigh_ha_snapshot() in route_shortcircuit() (Eric Dumazet) {CVE-2026-74475}\n- vxlan: unclone skb head before modifying eth header in route_shortcircuit() (Eric Dumazet)\n- vxlan: re-fetch eth header after route_shortcircuit() (Eric Dumazet) {CVE-2026-80681}\n- veth: convert frag_list skbs before running XDP (Matt Fleming) {CVE-2026-74476}\n- um: vector: fix use-after-free in vector_mmsg_rx() (Michael Bommarito) {CVE-2026-74478}\n- powerpc/ps3: Fix map failure path in dma_ioc0_map_pages() (Thorsten Blum)\n- net: ipv6: clear suppressed fib6 rule result (Zhiling Zou) {CVE-2026-74581}\n- net: bridge: stop fast-leave after deleting a port group (Zhiling Zou) {CVE-2026-74480}\n- mm: memcg: initialize *locked in memcg1_oom_prepare() stub (Breno Leitao)\n- mm/page_reporting: use system_freezable_wq to fix UAF during suspend (Link Lin) {CVE-2026-74481}\n- binfmt_misc: don't let an 'F' entry pin its own instance (Christian Brauner) {CVE-2026-74484}\n- binfmt_misc: reject a flag character as the field delimiter (Christian Brauner) {CVE-2026-74485}\n- wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (Zhao Li) {CVE-2026-74488}\n- tipc: avoid use-after-free in poll trace queue dumps (Zihan Xi) {CVE-2026-74490}\n- netfilter: ipset: do not update comments from kernel-side hash adds (David Lee) {CVE-2026-74492}\n- net/smc: fix socket use-after-free during link group termination (Xuanqiang Luo) {CVE-2026-74493}\n- ipvs: do not propagate one-packet flag to synced conns (Zhiling Zou) {CVE-2026-80714}\n- igbvf: Fix leak in TX DMA error cleanup (Matt Vollrath) {CVE-2026-74495}\n- e1000: fix memory leak in e1000_probe() (Dawei Feng)\n- dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ (Md Sadre Alam)\n- ALSA: usb-audio: Clamp frame size in implicit-feedback mode (Sonali Pradhan) {CVE-2026-74497}\n- ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set (Sonali Pradhan) {CVE-2026-74498}\n- ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() (Baul Lee) {CVE-2026-74499}\n- ALSA: usb-audio: fix stack info leak in RME Digiface status (Baul Lee) {CVE-2026-74500}\n- ALSA: usb-audio: fix use-after-free in ump_to_endpoint() (Baul Lee) {CVE-2026-74501}\n- ata: libata-sata: fix ata_scsi_lpm_supported() iteration (Niklas Cassel)\n- ata: libata-eh: Increase STANDBY IMMEDIATE timeout (Matt Vollrath)\n- ASoC: tas2562: fix broken entries in the volume lookup table (Haidar Lee)\n- ASoC: tas2562: fix DVC coefficient write order (Haidar Lee)\n- ALSA: ump: fix double free of out_cvts on rawmidi error (Baul Lee) {CVE-2026-74502}\n- ALSA: seq: Fix division by zero in initialize_timer() (Norbert Szetei) {CVE-2026-74504}\n- ALSA: pcm: wake linked drain waiters on unlink (Norbert Szetei) {CVE-2026-80716}\n- ALSA: lx6464es: fix period byte count for 16-bit streams (Xu Rao)\n- ALSA: 6fire: Fix UAF at error handling during probe (Takashi Iwai) {CVE-2026-74505}\n- bpf: lwt: Fix dst reference leak on reroute failure (Xuanqiang Luo)\n- Bluetooth: HIDP: validate numbered report payloads (Sangho Lee) {CVE-2026-74507}\n- Bluetooth: HIDP: reject frames without a transaction header (Sangho Lee) {CVE-2026-74508}\n- Bluetooth: hci_sync: Fix advertising data UAFs (Chengfeng Ye) {CVE-2026-74509}\n- Bluetooth: mgmt: fix UAF in pair command cancellation (Zihan Xi) {CVE-2026-74510}\n- Bluetooth: mgmt: fix pending command UAF in EIR updates (Zihan Xi) {CVE-2026-74511}\n- Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() (Greg Kroah-Hartman)\n- Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req() (Greg Kroah-Hartman)\n- audit: fix potential use-after-free in audit_del_rule() (Luxiao Xu) {CVE-2026-74512}\n- audit: fix potential integer overflow in audit_log_n_string() (Zhan Xusheng)\n- sctp: validate Adaptation Indication parameter length (Charles Vosburgh) {CVE-2026-80717}\n- KVM: s390: pci: Validate AIBV and AISB before pinning guest pages (Farhan Ali)\n- KVM: s390: pci: Fix NULL dereference on AIBV allocation failure (Farhan Ali) {CVE-2026-80684}\n- KVM: s390: pci: Reject adapter interrupt forwarding if already enabled (Farhan Ali) {CVE-2026-74515}\n- KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (Sean Christopherson) {CVE-2026-74516}\n- tracing/probes: Reject  in meta argument expansion (Raushan Patel)\n- mm/vmstat: fold stranded per-cpu node stats when a node comes online (Gregory Price)\n- mm/hugetlb: fix list corruption in allocate_file_region_entries() (Xiangfeng Cai) {CVE-2026-74518}\n- mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() (Zi Yan) {CVE-2026-80718}\n- fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes (Kiryl Shutsemau (Meta))\n- mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE (Kefeng Wang) {CVE-2026-80686}\n- fortify: Disable -Wstringop-overread in tests (Nathan Chancellor)\n- pinctrl: bm1880: add missing select GENERIC_PINCONF (Benjamin Boortz)\n- erofs: cap LZMA stream pool size (Michael Bommarito)\n- pinctrl: devicetree: don't free uninitialized dev_name on error path (Karl Mehltretter) {CVE-2026-74519}\n- pinctrl: microchip-sgpio: add missing select REGMAP_MMIO (Benjamin Boortz)\n- rhashtable: clear stale iter-p on table restart (Cen Zhang (Microsoft))\n- ksmbd: fix use-after-free in __close_file_table_ids() (Namjae Jeon) {CVE-2026-74522}\n- ksmbd: return success for deferred final close (Namjae Jeon)\n- qede: sync udp_tunnel ports outside qede_lock in the recovery path (Denis V. Lunev) {CVE-2026-74523}\n- net: libwx: fix FDIR ATR queue mismatch for software VLAN packets (Jiawen Wu)\n- net: dsa: mt7530: error out on failed reads in MT7531 PHY polling (Daniel Golle)\n- net: dsa: mt7530: check bus-read() errors in the MDIO regmap backend (Daniel Golle)\n- riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove (Karl Mehltretter) {CVE-2026-74524}\n- accel/qaic: use sizeof(*trans_hdr) for transaction length check (Muhammad Bilal)\n- tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions (Masami Hiramatsu (Google))\n- tracing/mmiotrace: Remove reference to unused per CPU data pointer (Steven Rostedt)\n- tracing: Remove TRACE_EVENT_FL_FILTERED logic (Zheng Yejian)\n- tracing/mmiotrace: Reset dropped_count in mmio_reset_data() (Masami Hiramatsu (Google))\n- can: isotp: check register_netdevice_notifier() error in module init (Minhong He)\n- net: sxgbe: check descriptor ring allocation failures (Chenguang Zhao)\n- net: sxgbe: free TX rings on RX allocation failure (Chenguang Zhao) {CVE-2026-74525}\n- scsi: target: Clear cmd_cnt when initial counter enrollment fails (Leon Romanovsky)\n- scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req (Benjamin Block)\n- scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE (TanZheng) {CVE-2026-80691}\n- net: phylink: put link_gpio if phylink_create fails (Christian Marangi)\n- Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync (Pauli Virtanen)\n- Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (Pauli Virtanen) {CVE-2026-74531}\n- Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (Pauli Virtanen)\n- Bluetooth: btintel: Validate length before parsing diagnostics TLV (Zijun Hu) {CVE-2026-74532}\n- Bluetooth: ISO: avoid deadlocks in iso_sock_timeout (Pauli Virtanen) {CVE-2026-74535}\n- Bluetooth: ISO: fix leaking sk after socket release (Pauli Virtanen) {CVE-2026-74536}\n- Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis() (Pauli Virtanen)\n- Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos (Pauli Virtanen)\n- Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp (Jiale Yao) {CVE-2026-74540}\n- Bluetooth: ISO: clear iso_data always when detaching conn from hcon (Pauli Virtanen) {CVE-2026-74541}\n- idpf: Fix mailbox IRQ name leak on request failure (Yuho Choi)\n- idpf: adjust TxQ ring count minimum (Joshua Hay)\n- hwmon: (pmbus) Fix return value from pmbus_update_byte_data() (Guenter Roeck)\n- net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller (Chenguang Zhao) {CVE-2026-80694}\n- net: ethernet: mtk_eth_soc: add consts for irq index (Frank Wunderlich)\n- net: ethernet: mtk_eth_soc: support named IRQs (Frank Wunderlich)\n- wifi: mac80211: validate individual TWT params before driver setup (Zhao Li) {CVE-2026-80722}\n- net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister() (Eric Dumazet) {CVE-2026-74543}\n- powerpc/boot: Fix treeboot-akebono CPU node lookup check (Thorsten Blum)\n- powerpc/boot: Fix treeboot-currituck CPU node lookup check (Thorsten Blum)\n- powerpc/boot: Fix simpleboot CPU node lookup check (Thorsten Blum)\n- rtase: fix double free of multi-frag skb on DMA map failure (Yun Lu) {CVE-2026-74545}\n- hwmon: (adt7470) Fix PWM auto temp state array and bounds check (Luiz Angelo Daros de Luca)\n- hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read (Luiz Angelo Daros de Luca) {CVE-2026-74546}\n- hwmon: (adt7470) Use cached PWM frequency value (Luiz Angelo Daros de Luca)\n- hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks (Luiz Angelo Daros de Luca)\n- hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() (Luiz Angelo Daros de Luca)\n- hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread (Luiz Angelo Daros de Luca) {CVE-2026-74547}\n- hwmon: (adt7470) Fix cache updated before hardware write on I2C error (Luiz Angelo Daros de Luca)\n- hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors (Luiz Angelo Daros de Luca)\n- forcedeth: fix UAF of txrx_stats in nv_remove (Chenguang Zhao) {CVE-2026-74548}\n- net: bridge: mrp: fix Option TLV length in MRP_Test frames (David Corvaglia)\n- hwmon: (nct6775-core) Prevent access to unsupported weight registers (Guenter Roeck) {CVE-2026-74549}\n- net: do not send ICMP/NDISC Redirects when peer allocation fails (Eric Dumazet) {CVE-2026-74550}\n- hwmon: (nzxt-smart2) DMA-align output buffer (Guenter Roeck) {CVE-2026-74551}\n- hwmon: (lm90) Only report alarms if driver is ready (Guenter Roeck) {CVE-2026-74552}\n- hwmon: (sht3x) Fix unaligned accesses (Guenter Roeck) {CVE-2026-80695}\n- hwmon: (ltc4282) Fix reading the minimum alarm voltage (Guenter Roeck) {CVE-2026-80696}\n- hwmon: (ina2xx) Fix various overflow issues (Guenter Roeck)\n- hwmon: (ina2xx) Shift INA234 shunt and current registers (Jonas Rebmann)\n- hwmon: (ina2xx) Add support for INA234 (Ian Ray)\n- hwmon: (ina2xx) Make it easier to add more devices (Ian Ray)\n- hwmon: (ina226) Add support for SY24655 (Wenliang Yan)\n- hwmon: (ina2xx) Add support for INA260 (Guenter Roeck)\n- hwmon: (ina2xx) Add support for has_alerts configuration flag (Guenter Roeck)\n- hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 (Guenter Roeck) {CVE-2026-74553}\n- spi: spi-cadence: Move TX FIFO full busy-wait into FIFO (Srikanth Boyapally)\n- spi: spi-cadence: supports transmission with bits_per_word of 16 and 32 (Jun Guo)\n- smb: client: fix buffer leaks in SMB1 read and write (Dawei Feng)\n- scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race (Xingui Yang) {CVE-2026-74555}\n- scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (HyeongJun An) {CVE-2026-74556}\n- scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer (HyeongJun An) {CVE-2026-74557}\n- pinctrl-amd: Don't clear S4 wake bits at probe (Mario Limonciello)\n- netfilter: nft_payload: fix mask build for partial field offload (Xiang Mei (Microsoft))\n- ipvs: do not mangle ICMP replies for non-first fragments (Julian Anastasov)\n- ipvs: fix places with wrong packet offsets (Julian Anastasov)\n- ipvs: fix the checksum validations (Julian Anastasov)\n- netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH (Pablo Neira Ayuso) {CVE-2026-74564}\n- netfilter: nf_tables: make nft_object rhltable per table (Pablo Neira Ayuso) {CVE-2026-74565}\n- assoc_array: trim the final shortcut word using the current chunk end (Michael Bommarito)\n- keys: make keyring key-chunk byte order agree with keyring_diff_objects() (Michael Bommarito) {CVE-2026-74566}\n- keys: fix out-of-bounds read in keyring_get_key_chunk() (Michael Bommarito) {CVE-2026-74567}\n- KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type (Fabrice Derepas)\n- Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation (Sebastian Andrzej Siewior)\n- drm/mediatek: Check CRTC state before freeing (Ruoyu Wang)\n- netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (Xiang Mei) {CVE-2026-74569}\n- phy: zynqmp: fix runtime PM leak on probe allocation failure (Radhey Shyam Pandey)\n- phy: zynqmp: fix clock error handling in xpsgtr_phy_init() (Radhey Shyam Pandey)\n- phy-zynqmp: Postpone getting clock rate until actually needed (Mike Looijmans)\n- btrfs: zoned: fix deadlock between metadata writeback and transaction commit (Johannes Thumshirn) {CVE-2026-74572}\n- btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag (Qu Wenruo)\n- of: reserved_mem: prevent OOB when too many dynamic regions are defined (Sang-Heon Jeon) {CVE-2026-80723}\n- of: reserved_mem: Add code to dynamically allocate reserved_mem array (Oreoluwa Babatunde)\n- ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare)\n- ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare)\n- ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources() (Radhey Shyam Pandey)\n- ahci: Introduce ahci_ignore_port() helper (Damien Le Moal)\n- ata: libahci_platform: support non-consecutive port numbers (Josua Mayer)\n- ata: sata_mv: accept 1 or 2 resources in platform probe (Rosen Penev)\n- gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe() (Abdun Nihaal)\n- dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() (Yuho Choi) {CVE-2026-74574}\n- dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA (Hongling Zeng)\n- pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 (Konrad Dybcio)\n- pinctrl: qcom: Unconditionally mark gpio as wakeup enable (Sneh Mankad)\n- thunderbolt: Prevent XDomain delayed work use-after-free on disconnect (Michael Bommarito) {CVE-2026-74575}\n- netconsole: avoid OOB reads, msg is not nul-terminated (Jakub Kicinski) {CVE-2026-43197}\n- bpf: Reset register bounds before narrowing retval range in check_mem_access() (Tristan Madani) {CVE-2026-72111}\n- HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (Benjamin Tissoires)\n- HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (Lee Jones)\n- HID: logitech-dj: Standardise hid_report_enum variable nomenclature (Lee Jones)\n- net: mpls: initialize rtm_tos in mpls_getroute() (Yehyeong Lee) {CVE-2026-74577}\n- netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge() (Lorenzo Bianconi)\n- um: Preserve errno within signal handler (Tiwei Bie)\n- kunit: tool: skip stty when stdin is not a tty (Shuvam Pandey)\n- kunit: tool: Terminate kernel under test on SIGINT (David Gow)\n- um: Set parent death signal for userspace process (Benjamin Berg)\n- um: Set parent-death signal for write_sigio thread/process (Tiwei Bie)\n- um: Set parent-death signal for ubd io thread/process (Tiwei Bie)\n- um: Use os_set_pdeathsig helper in winch thread/process (Tiwei Bie)\n- um: Set parent death signal for winch thread/process (Benjamin Berg)\n- um: Add os_set_pdeathsig helper function (Tiwei Bie)\n- LTS version: v6.12.102 (Saeed Mirzamohammadi)\n- LTS version: v6.12.101 (Saeed Mirzamohammadi)\n- KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug (Nikunj A Dadhania) {CVE-2026-68093}\n- afs: Fix uninit var in afs_alloc_anon_key() (David Howells)\n- Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() (Pavitra Jha) {CVE-2026-53364}\n- Bluetooth: hci_conn: Fix not cleaning up PA_LINK connections (Luiz Augusto von Dentz)\n- Bluetooth: hci_conn: Fix not cleaning up Broadcaster/Broadcast Source (Luiz Augusto von Dentz)\n- Bluetooth: hci_conn: Fix running bis_cleanup for hci_conn-type PA_LINK (Luiz Augusto von Dentz)\n- afs: handle CB.InitCallBackState3 requests without a server record (Nan Li) {CVE-2026-74425}\n- afs: Fix delayed allocation of a cell's anonymous key (David Howells) {CVE-2025-68299}\n- dpll: fix clock quality level reporting (Ivan Vecera)\n- afs: Set vllist to NULL if addr parsing fails (Edward Adam Davis)\n- net: ethernet: Remove accidental duplication in Kconfig file (Lukas Bulwahn)\n- wifi: nl80211: fix nl80211_start_radar_detection return value (Nicolas Escande)\n- rxrpc: Fix locking issues with the peer record hash (David Howells)\n- rxrpc: Disable IRQ, not BH, to take the lock for -attend_link (David Howells)\n- gpu: Fix uninitialized buddy for built-in drivers (Koen Koning)\n- net/mlx5e: Fix NULL pointer dereference in ioctl module EEPROM query (Gal Pressman)\n- usb: musb: omap2430: Do not put borrowed of_node in probe (Guangshuo Li) {CVE-2026-68371}\n- usb: musb: omap2430: clean up probe error handling (Johan Hovold)\n- USB: gadget: fsl-udc: fix dev_printk() device (Johan Hovold)\n- USB: gadget: Use str_enable_disable-like helpers (Krzysztof Kozlowski)\n- net: ipa: fix SMEM state handle leaks in SMP2P init (Haoxiang Li)\n- net: macb: drop in-flight Tx SKBs on close (Theo Lebrun) {CVE-2026-72017}\n- fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list (Reinette Chatre) {CVE-2026-72015}\n- ata: libata-core: Reject an invalid concurrent positioning ranges count (Bryam Vargas) {CVE-2026-72030}\n- octeontx2-pf: fix SQB pointer leak on init failure (Dawei Feng) {CVE-2026-72023}\n- net/mlx5: HWS, fix matcher leak on resize target setup failure (Dawei Feng) {CVE-2026-72032}\n- ipmi: fix refcount leak in i_ipmi_request() (Wentao Liang) {CVE-2026-72040}\n- bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline() (Breno Leitao)\n- bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c (Breno Leitao)\n- octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (Junrui Luo) {CVE-2026-72045}\n- gpio: mt7621: avoid corruption of shared interrupt trigger state (Sergio Paracuellos) {CVE-2026-72062}\n- gve: fix header buffer corruption with header-split and HW-GRO (Ankit Garg) {CVE-2026-72046}\n- net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) {CVE-2026-72051}\n- net: mana: Validate the packet length reported by the NIC (Dexuan Cui) {CVE-2026-72065}\n- locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (Thomas Gleixner) {CVE-2026-72069}\n- wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() (Maoyi Xie) {CVE-2026-72070}\n- dm: avoid leaking the caller's thread keyring via the table device file (Ingo Blechschmidt) {CVE-2026-72103}\n- cred: add scoped_with_kernel_creds() (Christian Brauner)\n- cred: add kernel_cred() helper (Christian Brauner)\n- cleanup: fix scoped_class() (Christian Brauner)\n- cleanup: add a scoped version of CLASS() (Christian Brauner)\n- dm-integrity: fix leaking uninitialized kernel memory (Mikulas Patocka) {CVE-2026-72101}\n- block: remove redundant GD_NEED_PART_SCAN in add_disk_final() (Connor Williamson)\n- block: add helper add_disk_final() (Ming Lei)\n- ovl: use linked upper dentry in copy-up tmpfile (Souvik Banerjee)\n- nvmet-auth: reject short AUTH_RECEIVE buffers (Michael Bommarito) {CVE-2026-72130}\n- nvmet: Introduce nvmet_req_transfer_len() (Damien Le Moal)\n- tcp: Decrement tcp_md5_needed static branch (Dmitry Safonov)\n- tcp: defer md5sig_info kfree past RCU grace period in tcp_connect (Michael Bommarito) {CVE-2026-72139}\n- xfrm: nat_keepalive: avoid double free on send error (Qianyu Luo) {CVE-2026-72137}\n- xfrm: Use nested-BH locking for nat_keepalive_sk_ipv[46] (Sebastian Andrzej Siewior)\n- i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (Vincent Jardin)\n- i2c: imx: separate atomic, dma and non-dma use case (Stefan Eichenberger)\n- dmaengine: dw-edma-pcie: Reject devices without driver data (Koichiro Den) {CVE-2026-72147}\n- dmaengine: dw-edma: Fix confusing cleanup.h syntax (Krzysztof Kozlowski)\n- dma: dw-edma: Fix build warning in dw_edma_pcie_probe() (Abinash Singh)\n- mm/sparse-vmemmap: fix DAX vmemmap accounting with optimization (Muchun Song)\n- mm: prepare to move subsection_map_init() to mm/sparse-vmemmap.c (David Hildenbrand (Arm))\n- mtd: maps: vmu-flash: fix fault in unaligned fixup (Florian Fuchs) {CVE-2026-72168}\n- mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages (Muchun Song)\n- landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path (Bryam Vargas) {CVE-2026-72183}\n- landlock: Prepare to use credential instead of domain for fowner (Mickael Salaun)\n- mm/sparse-vmemmap: fix vmemmap accounting underflow (Muchun Song)\n- mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch (Deepanshu Kartikey) {CVE-2026-72213}\n- remoteproc: xlnx: Check remote core state (Tanmay Shah)\n- SUNRPC: Return an error from xdr_buf_to_bvec() on overflow (Chuck Lever)\n- SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists (Chuck Lever)\n- sunrpc: allocate a separate bvec array for socket sends (Jeff Layton)\n- NFSD: pass nfsd_file to nfsd_iter_read() (Mike Snitzer)\n- gpu/buddy: bail out of try_harder when alignment cannot be honoured (Arunpravin Paneer Selvam) {CVE-2026-72244}\n- gpu: Move DRM buddy allocator one level up (part two) (Joel Fernandes)\n- netfilter: nft_fib: reject fib expression on the netdev egress hook (Theodor Arsenij Larionov-Trichkine) {CVE-2026-72254}\n- netfilter: nf_tables: remove register tracking infrastructure (Florian Westphal)\n- netfilter: nf_tables: Remove unused nft_reduce_is_readonly() (Yue Haibing)\n- netfilter: bitwise: rename some boolean operation functions (Jeremy Sowden)\n- netfilter: nf_conntrack_sip: validate skb_dst() before accessing it (Pablo Neira Ayuso) {CVE-2026-72253}\n- netfilter: nf_conntrack_sip: remove net variable shadowing (Florian Westphal)\n- ASoC: mediatek: mt8183: Check runtime resume during probe (Cassio Gabriel)\n- ASoC: mediatek: mt8183-afe-pcm: use local dev pointer in driver callbacks (Chen-Yu Tsai)\n- ASoC: mediatek: mt8183-afe-pcm: Support 32 bit DMA addresses (Chen-Yu Tsai)\n- ASoC: mediatek: mt8183-afe-pcm: Shorten memif_data table using macros (Chen-Yu Tsai)\n- ASoC: mediatek: mt8192: Check runtime resume during probe (Cassio Gabriel) {CVE-2026-72260}\n- ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable (Tang Bin)\n- arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers (Abel Vesa)\n- arm64: dts: qcom: correct RBR opp entry (Dmitry Baryshkov)\n- octeontx2-pf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)\n- octeontx2-vf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)\n- VDUSE: avoid leaking information to userspace (Jason Wang) {CVE-2026-72305}\n- vduse: take out allocations from vduse_dev_alloc_coherent (Eugenio Perez)\n- vduse: remove unused vaddr parameter of vduse_domain_free_coherent (Eugenio Perez)\n- vduse: Use fixed 4KB bounce pages for non-4KB page size (Sheng Zhao)\n- tipc: restrict socket queue dumps in enqueue tracepoints (Li Xiasong) {CVE-2026-72299}\n- rxrpc: Fix socket notification race (David Howells)\n- rxrpc: Fix notification vs call-release vs recvmsg (David Howells)\n- rxrpc: Use irq-disabling spinlocks between app and I/O thread (David Howells)\n- rxrpc: Don't need barrier for -tx_bottom and -acks_hard_ack (David Howells)\n- rxrpc: Fix CPU time starvation in I/O thread (David Howells)\n- fbcon: Use correct type for vc_resize() return value (Jiacheng Yu)\n- fbcon: Rename struct fbcon_ops to struct fbcon_par (Thomas Zimmermann)\n- xfs: don't replace the wrong part of the cow fork (Darrick J. Wong)\n- xfs: factor out xfs_attr3_leaf_init (Long Li)\n- rxrpc: serialize kernel accept preallocation with socket teardown (Li Daming) {CVE-2026-74436}\n- rxrpc: Pull out certain app callback funcs into an ops table (David Howells)\n- ALSA: hda: Fix cached processing coefficient verbs (Xu Rao)\n- ALSA: hda: conexant: Remove mic bias threshold override (Zhang Heng)\n- i2c: i801: fix hardware state machine corruption in error path (Mingyu Wang) {CVE-2026-64205}\n- audit: fix recursive locking deadlock in audit_dupe_exe() (Ricardo Robaina) {CVE-2026-68096}\n- audit: use 'unsigned int' instead of 'unsigned' (Ricardo Robaina)\n- audit: widen ino fields to u64 (Jeff Layton)\n- VFS/audit: introduce kern_path_parent() for audit (NeilBrown)\n- i2c: davinci: Unregister cpufreq notifier on probe failure (Haoxiang Li)\n- fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() (Sebastian Alba Vives) {CVE-2026-64280}\n- iommufd: Avoid partial fault group delivery in iommufd_fault_fops_read() (Nicolin Chen)\n- iommufd: Break the loop on failure in iommufd_fault_fops_read() (Nicolin Chen) {CVE-2026-64290}\n- iommufd: Reject invalid read count in iommufd_fault_fops_read() (Nicolin Chen)\n- mm/damon/core: disallow overlapping input ranges for damon_set_regions() (SJ Park) {CVE-2026-68164}\n- mm/damon/core: validate ranges in damon_set_regions() (SJ Park) {CVE-2026-68165}\n- rust: allow suspicious_runtime_symbol_definitions lint for Rust = 1.98 (Miguel Ojeda)\n- gve: fix Rx queue stall on alloc failure (Eddie Phillips) {CVE-2026-68129}\n- net: pcs: xpcs: fix SGMII state reading (Coia Prant)\n- io_uring/rw: fix missing ERESTARTSYS conversion in read paths (Yitang Yang)\n- drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources (Harry Wentland)\n- ksmbd: validate ACE size against SID sub-authorities (Namjae Jeon) {CVE-2026-68097}\n- ksmbd: bound DACL dedup walk to copied ACEs (Namjae Jeon) {CVE-2026-68098}\n- bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (Jiayuan Chen) {CVE-2026-53078}\n- drm/amdgpu: fix aperture mapping leak (Asad Kamal)\n- drm/amdgpu: invoke pm_genpd_remove() before freeing genpd (Ce Sun) {CVE-2026-68104}\n- drm/amdgpu: fix division by zero with invalid uvd dimensions (Boyuan Zhang) {CVE-2026-68106}\n- drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (Luca Coelho) {CVE-2026-68429}\n- drm/amdgpu/vcn4: avoid rereading IB param length (Boyuan Zhang) {CVE-2026-68107}\n- drm/amdgpu/vce: fix integer overflow in image size (Boyuan Zhang) {CVE-2026-68108}\n- drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68110}\n- drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68111}\n- drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68112}\n- drm/amdgpu/gfx8: drop unecessary BUG_ON() (Alex Deucher) {CVE-2026-68430}\n- drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68113}\n- drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68246}\n- drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68115}\n- drm/amd/pm: make pp_features read-only when scpm is enabled (Yang Wang)\n- drm/amd/pm: fix amdgpu_pm_info power display units (Yang Wang)\n- vxlan: mdb: Fix source list corruption on a failed replace (James Raphael Tiovalen) {CVE-2026-68116}\n- tipc: clear sock-sk on the failed-insert path in tipc_sk_create() (Daehyeon Ko) {CVE-2026-68117}\n- tcp: initialize standalone TCP-AO response padding (Yizhou Zhao) {CVE-2026-68119}\n- rtase: Workaround for TX hang caused by hardware packet parsing (Justin Lai) {CVE-2026-68120}\n- pppoe: reload header pointer after dev_hard_header() (Asim Viladi Oglu Manizada) {CVE-2026-68121}\n- openvswitch: fix GSO userspace truncation underflow (Kyle Zeng) {CVE-2026-68123}\n- mctp: serial: handle zero-length frames to prevent rx buffer overflow (Doruk Tan Ozturk) {CVE-2026-68124}\n- mac802154: llsec: reject frames shorter than the authentication tag (Doruk Tan Ozturk) {CVE-2026-68125}\n- mac802154: hold an interface reference across the scan worker (Ibrahim Hashimov) {CVE-2026-68126}\n- ila: reload IPv6 header after pskb_may_pull in checksum adjust (Michael Bommarito) {CVE-2026-68127}\n- ice: use READ_ONCE() to access cached PHC time (Sergey Temerkhanov)\n- ice: reject out-of-range ptype in ice_parser_profile_init (Aleksandr Loktionov) {CVE-2026-68128}\n- ksmbd: defer destroy_previous_session() until after NTLM authentication (James Montgomery) {CVE-2026-68130}\n- rbd: Reset positive result codes to zero in object map update path (Raphael Zimmer) {CVE-2026-68131}\n- ice: fix PTP Call Trace during PTP release (Paul Greenwalt) {CVE-2026-68133}\n- net: hip04: fix RX buffer leak on build_skb failure (Fan Wu) {CVE-2026-68135}\n- net: gro: fix double aggregation of flush-marked skbs (Shiming Cheng) {CVE-2026-68136}\n- net/x25: fix use-after-free in x25_kill_by_neigh() (David Lee) {CVE-2026-68137}\n- net/mlx5e: Use sender devcom for MPV master-up (Manjunath Patil) {CVE-2026-68139}\n- net/iucv: fix use-after-free of a severed iucv_path (Bryam Vargas) {CVE-2026-68140}\n- net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() (Hidayath Khan) {CVE-2026-68141}\n- geneve: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk) {CVE-2026-68142}\n- net: slip: serialize receive against buffer reallocation (Sungmin Kang) {CVE-2026-68143}\n- vxlan: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk) {CVE-2026-68432}\n- phonet: pep: fix use-after-free in pep_get_sb() (Breno Leitao) {CVE-2026-68144}\n- iommu/vt-d: Disallow SVA if page walk is not coherent (Lu Baolu)\n- iomap: fix out-of-bounds bitmap_set() with zero-length range (Zhang Yi) {CVE-2026-68145}\n- ftrace: Add global mutex to serialize trace_parser access (Tengda Wu) {CVE-2026-68146}\n- fscrypt: Add missing superblock check in find_or_insert_direct_key() (Eric Biggers) {CVE-2026-68148}\n- fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (Amir Goldstein) {CVE-2026-68149}\n- binfmt_elf_fdpic: only honour the first PT_INTERP (Christian Brauner) {CVE-2026-68151}\n- ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP (Chancel Liu)\n- amt: fix use-after-free in AMT delayed works (Shihuang Liu) {CVE-2026-68152}\n- libceph: remove debugfs files before client teardown (Douya Le) {CVE-2026-68153}\n- libceph: reject zero bucket types in crush_decode (Douya Le) {CVE-2026-68154}\n- libceph: Reject monmaps advertising zero monitors (Raphael Zimmer) {CVE-2026-68155}\n- libceph: refresh auth-authorizer_buf{,_len} after authorizer update (Shuangpeng Bai) {CVE-2026-68156}\n- libceph: guard missing CRUSH type name lookup (Zhao Zhang) {CVE-2026-68157}\n- libceph: Fix multiplication overflow in decode_new_up_state_weight() (Raphael Zimmer) {CVE-2026-68158}\n- libceph: bound get_version reply decode to front len (Douya Le) {CVE-2026-68433}\n- ceph: fix refcount leak in ceph_readdir() (WenTao Liang)\n- ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (Bryam Vargas) {CVE-2026-68160}\n- sctp: close UDP tunnel sockets during netns teardown (Zhiling Zou) {CVE-2026-68161}\n- sctp: avoid auth_enable sysctl UAF during netns teardown (Zhiling Zou) {CVE-2026-68162}\n- sctp: don't free the ASCONF's own transport in DEL-IP processing (Jun Yang) {CVE-2026-64564}\n- mptcp: only set DATA_FIN when a mapping is present (Michael Bommarito)\n- mptcp: decrement subflows counter on failed passive join (Chenguang Zhao)\n- Revert 'arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates' (Will Deacon)\n- arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates (Will Deacon)\n- tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() (Masami Hiramatsu (Google))\n- tracing/probes: Fix potential underflow in LEN_OR_ZERO macro (Masami Hiramatsu (Google))\n- tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args() (Masami Hiramatsu (Google))\n- tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() (Masami Hiramatsu (Google))\n- tracing: Fix resource leak on mmiotrace trace_pipe close (deepakraog) {CVE-2026-68175}\n- tracing: Fix mmiotrace possible NULL dereferencing of hiter-dev (Steven Rostedt) {CVE-2026-68176}\n- misc: nsm: pin the module while the device is open (Xu Rao) {CVE-2026-68178}\n- misc: nsm: only unlock nsm_dev on post-lock error paths (Runyu Xiao) {CVE-2026-68179}\n- intel_th: fix MSC output device reference leak (Guangshuo Li) {CVE-2026-68180}\n- mei: bus: access mei_device under device_lock on cleanup (Alexander Usyskin) {CVE-2026-68181}\n- serial: sc16is7xx: implement gpio get_direction() callback (Hugo Villeneuve)\n- uio_hv_generic: Bind to FCopy device by default (Ben Hutchings)\n- comedi: comedi_parport: deal with premature interrupt (Ian Abbott) {CVE-2026-68182}\n- x86/boot/compressed: Disable jump tables (Nathan Chancellor)\n- firmware: stratix10-svc: fix memory leaks and list corruption bugs (Tze Yee Ng) {CVE-2026-68183}\n- cdrom: fix stack out-of-bounds read in CDROMVOLCTRL (Xu Rao) {CVE-2026-68184}\n- LoongArch: Retrieve CPU package ID from PPTT when available (Rong Bao)\n- LoongArch: Move jump_label_init() before parse_early_param() (Kanglong Wang) {CVE-2026-68185}\n- LoongArch: Fix oops during single-step debugging (Haoran Jiang)\n- objtool/rust: add one more noreturn Rust function for Rust 1.99.0 (Miguel Ojeda)\n- rust: allow clippy::unwrap_or_default globally (Alexandre Courbot)\n- platform/loongarch: laptop: Explicitly reset bl_powered state when suspend (Zixing Liu)\n- binfmt_misc: set have_execfd only once the interpreter is opened (Christian Brauner) {CVE-2026-68186}\n- exec: fix unsigned loop counter wrap in transfer_args_to_stack() (Christian Brauner) {CVE-2026-68187}\n- Bluetooth: RFCOMM: Fix session UAF in set_termios (Chengfeng Ye) {CVE-2026-68188}\n- Bluetooth: hci_sync: Protect UUID list traversal (Chengfeng Ye) {CVE-2026-68189}\n- staging: rtl8723bs: fix inverted HT40 secondary channel offset (MinJea Kim)\n- staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() (Moksh Panicker) {CVE-2026-68190}\n- wifi: brcmfmac: make release_scratchbuffers idempotent (Fan Wu) {CVE-2026-68192}\n- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Devin Wittmayer) {CVE-2026-68193}\n- wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses (Devin Wittmayer) {CVE-2026-68194}\n- wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses (Devin Wittmayer) {CVE-2026-68195}\n- wifi: wilc1000: validate assoc response length before subtracting header (Huihui Huang) {CVE-2026-68196}\n- wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper (Doruk Tan Ozturk) {CVE-2026-68197}\n- wifi: ath6kl: fix OOB access from firmware ADDBA window size (Tristan Madani) {CVE-2026-68199}\n- ALSA: timer: don't re-enter an instance callback that is still running (Norbert Szetei) {CVE-2026-68200}\n- ALSA: timer: drain a slave's callback before its master detaches it (Norbert Szetei) {CVE-2026-68201}\n- ALSA: seq: close a re-opened queue timer in the destructor (Norbert Szetei) {CVE-2026-68202}\n- media: vpif_capture: fix OF node reference imbalance (Johan Hovold)\n- media: vivid: fix cleanup bugs in vivid_init() (Guangshuo Li) {CVE-2026-68203}\n- media: vivid: check for vb2_is_busy() when toggling caps (Hans Verkuil) {CVE-2026-68204}\n- media: vivid: add vivid_update_reduced_fps() (Hans Verkuil)\n- media: vimc: fix reference leak on failed device registration (Guangshuo Li)\n- media: vidtv: fix reference leak on failed device registration (Guangshuo Li)\n- media: vb2: use ssize_t for vb2_read/vb2_write (Zile Xiong)\n- media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely (Sakari Ailus)\n- media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (Mirela Rabulea) {CVE-2026-68205}\n- media: v4l2-ctrls: validate HEVC active reference counts (Pengpeng Hou) {CVE-2026-68206}\n- media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() (Sergey Shtylyov)\n- media: ti: vpe: unwind v4l2 device registration on probe error (Myeonghun Pak) {CVE-2026-68207}\n- media: tegra-video: vi: fix invalid u32 return value in format lookup (Hungyu Lin)\n- media: sun4i-csi: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68209}\n- media: stm32: dcmi: unregister notifier on probe failure (Myeonghun Pak) {CVE-2026-68210}\n- media: saa7134: Fix a possible memory leak in saa7134_video_init1 (Ma Ke) {CVE-2026-68212}\n- media: rtl2832_sdr: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68213}\n- media: rtl2832: fix use-after-free in rtl2832_remove() (Deepanshu Kartikey) {CVE-2026-68214}\n- media: radio-si476x: Unregister v4l2_device on probe failure (Myeonghun Pak) {CVE-2026-68215}\n- media: qcom: camss: Fix RDI streaming for CSID GEN2 (Bryan O'Donoghue)\n- media: pwc: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68216}\n- media: pwc: Drain fill_buf on start_streaming() failure (Valery Borovsky) {CVE-2026-68217}\n- media: pci: dm1105: Free allocated workqueue (Krzysztof Kozlowski) {CVE-2026-68218}\n- media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding (Guoniu Zhou)\n- media: nxp: imx8-isi: Fix potential out-of-bounds issues (Guoniu Zhou) {CVE-2026-68219}\n- media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path (Xiaolei Wang)\n- media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure (Xiaolei Wang)\n- media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe (Xiaolei Wang) {CVE-2026-68220}\n- media: nuvoton: npcm-video: fix memory leaks in probe and remove (David Carlier) {CVE-2026-68221}\n- media: nuvoton: npcm-video: fix error handling in npcm_video_init() (David Carlier)\n- media: msi2500: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68222}\n- media: meson: vdec: Fix memory leak in error path of vdec_open (Anand Moon) {CVE-2026-68223}\n- media: marvell-cam: fix missing pci_disable_device() on remove (Guangshuo Li)\n- media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges (Marco Nenciarini)\n- media: i2c: alvium: fix critical pointer access in alvium_ctrl_init (Martin Hecht) {CVE-2026-68225}\n- media: cx23885: add ioremap return check and cleanup (Wang Jun) {CVE-2026-68226}\n- media: cx231xx: fix devres lifetime (Johan Hovold) {CVE-2026-68227}\n- media: chips-media: wave5: Move src_buf Removal to finish_encode (Brandon Brnich) {CVE-2026-68228}\n- media: cedrus: skip invalid H.264 reference list entries (Pengpeng Hou) {CVE-2026-68229}\n- media: cedrus: Fix missing cleanup in error path (Samuel Holland)\n- media: cedrus: clean up media device on probe failure (Myeonghun Pak)\n- media: cec: seco: unregister adapter on IR probe failure (Myeonghun Pak)\n- media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (David Carlier)\n- media: airspy: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68231}\n- drm/vc4: Prevent shader BO mappings from becoming writable (Linmao Li) {CVE-2026-68445}\n- drm/vmwgfx: Validate vmw_surface_metadata::array_size (Ian Forbes) {CVE-2026-68446}\n- drm/amdgpu: fix bo-pin leaking in amdgpu_bo_create_reserved (Zhu Lingshan) {CVE-2026-68234}\n- drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge (Mario Limonciello)\n- drm/amd/display: dce100: skip non-DP stream encoders for DP MST (Andriy Korud) {CVE-2026-68235}\n- drm/amd/display: set new_stream to NULL after release (WenTao Liang) {CVE-2026-68236}\n- drm/amdgpu: Fix VFCT bus number matching with soft filter (Mario Limonciello)\n- drm/panthor: return error on truncated firmware (Osama Abdelkader)\n- drm/gfx10: Program DB_RING_CONTROL (Alex Deucher)\n- drm/amd/pm: fix smu14 power limit range calculation (Yang Wang)\n- drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (Joonas Lahtinen) {CVE-2026-68243}\n- drm/i915/gem: Do not leak siblings[] on proto context error (Joonas Lahtinen) {CVE-2026-68244}\n- drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() (Shahyan Soltani) {CVE-2026-68245}\n- drm/i915/bios: range check LFP Data Block panel_type2 (Jani Nikula) {CVE-2026-68247}\n- drm/i915: Return NULL on error in active_instance (Joonas Lahtinen) {CVE-2026-68248}\n- drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68249}\n- drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68250}\n- drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68251}\n- drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68252}\n- drm/virtio: bound EDID block reads to the response buffer (Bryam Vargas) {CVE-2026-68255}\n- drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (WenTao Liang) {CVE-2026-68256}\n- drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (Thomas Zimmermann)\n- drm/amdkfd: fix 32-bit overflow in CWSR total size calculation (Yongqiang Sun) {CVE-2026-68257}\n- drm/amdkfd: Check bounds in allocate_event_notification_slot (David Francis) {CVE-2026-68259}\n- drm/amdkfd: Use kvcalloc to allocate arrays (David Francis)\n- drm/imagination: acquire vm_ctx-lock before mapping memory to GPU VM (Icenowy Zheng) {CVE-2026-68260}\n- drm/imagination: fix error checking of pvr_vm_context_lookup() (Luigi Santivetti) {CVE-2026-68261}\n- drm/imagination: Fix user array stride in pvr_set_uobj_array() (Shuvam Pandey) {CVE-2026-68262}\n- drm/imagination: Fix double call to drm_sched_entity_fini() (Brajesh Gupta) {CVE-2026-68263}\n- drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds (Matthew Brost)\n- drm/radeon: fix r100_copy_blit for large BOs (Pavel Ondracka)\n- drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (Wentao Liang)\n- drm/i915/gem: Add missing nospec on parallel submit slot (Joonas Lahtinen) {CVE-2026-68269}\n- drm/displayid: fix Tiled Display Topology ID size (Jani Nikula)\n- drm/nouveau: fix reversed error cleanup order in ucopy functions (Junrui Luo) {CVE-2026-68271}\n- drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (Mario Limonciello) {CVE-2026-68272}\n- drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (Timur Kristof)\n- drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older (Timur Kristof)\n- drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2) (Timur Kristof)\n- drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (Ashutosh Desai) {CVE-2026-68277}\n- drm/imagination: Fit paired fragment job in the correct CCCB (Alessio Belle) {CVE-2026-68437}\n- drm/dp/mst: fix buffer overflows in sideband chunk accumulation (Ashutosh Desai) {CVE-2026-68278}\n- drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (Ashutosh Desai) {CVE-2026-68279}\n- drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (Vitor Soares) {CVE-2026-68280}\n- drm/imagination: Count paired job fence as dependency in prepare_job() (Alessio Belle) {CVE-2026-68281}\n- drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (Sergey Shtylyov)\n- drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (Biju Das)\n- bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (Chengfeng Ye) {CVE-2026-68284}\n- ice: fix LAG recipe to profile association (Marcin Szycik)\n- ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV (Vincent Chen)\n- net: ipv6: fix dif and sdif mismatch in raw6_icmp_error (Li RongQing)\n- net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation (Alexei Lazar)\n- net/mlx5e: Report zero bandwidth for non-ETS traffic classes (Alexei Lazar)\n- net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule (Yael Chemla)\n- net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (Gal Pressman) {CVE-2026-68293}\n- net/mlx5: Refactor EEPROM query error handling to return status separately (Gal Pressman)\n- net: qrtr: restrict socket creation to the initial network namespace (Aldo Ariel Panzardo) {CVE-2026-68294}\n- hinic: remove unused ethtool RSS user configuration buffers (Chenguang Zhao)\n- ppp: annotate data races in ppp_generic (Eric Dumazet)\n- ppp: enable TX scatter-gather (Qingfang Deng)\n- ppp: convert to percpu netstats (Qingfang Deng)\n- ppp: use IFF_NO_QUEUE in virtual interfaces (Qingfang Deng)\n- ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup (Eric Dumazet)\n- net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM (Yun Zhou) {CVE-2026-68296}\n- net: stmmac: enable the MAC on link up for all supported speeds (vadik likholetov)\n- net: stmmac: reset residual action in L3L4 filters on delete (Nazim Amirul)\n- net: stmmac: fix l3l4 filter rejecting unsupported offload requests (Nazim Amirul)\n- drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem (Jose Exposito)\n- tipc: fix u16 MTU truncation in media and bearer MTU validation (Cen Zhang (Microsoft))\n- iomap: correct the range of a partial dirty clear (Zhang Yi)\n- vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (Harshaka Narayana) {CVE-2026-68299}\n- sctp: auth: verify auth requirement when auth_chunk is NULL (Qing Luo) {CVE-2026-68300}\n- net: dpaa: fix mode setting (Michael Walle)\n- net: hsr: fix memory leak on slave unregistration by removing synced VLANs (Eric Dumazet) {CVE-2026-68301}\n- net: bridge: vlan: fix vlan range dumps starting with pvid (Nikolay Aleksandrov)\n- amt: make the head writable before rewriting the L2 header (Michael Bommarito)\n- amt: re-read skb header pointers after every pull (Michael Bommarito) {CVE-2026-68302}\n- ovl: fix trusted xattr escape prefix matching (Yichong Chen)\n- wifi: brcmfmac: fix 802.1X-SHA256 call trace warning (Shelley Yang) {CVE-2026-68304}\n- wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() (Lorenzo Bianconi) {CVE-2026-68306}\n- wifi: mt76: mt7925: fix crash in reset link replay (Sean Wang) {CVE-2026-68307}\n- wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() (Lorenzo Bianconi) {CVE-2026-68308}\n- wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv() (Lorenzo Bianconi) {CVE-2026-68439}\n- wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() (Lorenzo Bianconi) {CVE-2026-68309}\n- wifi: mt76: mt7915: guard HE capability lookups (Ruoyu Wang) {CVE-2026-68310}\n- wifi: mt76: mt7925: guard link STA in decap offload (Guangshuo Li) {CVE-2026-68311}\n- tipc: fix infinite loop in __tipc_nl_compat_dumpit (Helen Koike) {CVE-2026-68313}\n- nexthop: initialize extack in nh_res_bucket_migrate() (Xiang Mei (Microsoft))\n- gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (Xiang Mei (Microsoft))\n- selftests: openvswitch: add config file (Matthieu Baerts (NGI0))\n- selftests: af_unix: add USER_NS config (Matthieu Baerts (NGI0))\n- tls: device: push pending open record on splice EOF (Rishikesh Jethwani)\n- net: mctp i3c: clean up notifier and buses if driver register fails (Myeonghun Pak) {CVE-2026-68314}\n- sctp: validate stream count in sctp_process_strreset_inreq() (Cen Zhang (Microsoft))\n- pds_core: check for workqueue allocation failure (Nikhil P. Rao)\n- pds_core: fix auxiliary device add/del races (Nikhil P. Rao) {CVE-2026-68317}\n- pds_core: order completion reads after the ownership check (Nikhil P. Rao)\n- pds_core: yield the CPU while waiting for the adminq to drain (Nikhil P. Rao)\n- pds_core: fix use-after-free on workqueue during remove (Nikhil P. Rao) {CVE-2026-68318}\n- pds_core: fix deadlock between reset thread and remove (Nikhil P. Rao) {CVE-2026-68319}\n- sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (HanQuan) {CVE-2026-68320}\n- net: txgbe: fix FDIR filter leak on remove (Chenguang Zhao) {CVE-2026-68321}\n- amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN (Prashanth Kumar KR)\n- pds_core: reject component parameter in legacy firmware update (Nikhil P. Rao)\n- wifi: mac80211: recalculate TIM when a station enters power save (Andrew Pope)\n- iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (Li RongQing) {CVE-2026-68324}\n- iommu/amd: Bound the early ACPI HID map (Pengpeng Hou) {CVE-2026-68325}\n- wifi: mwifiex: bound uAP association event IEs to the event buffer (HE WEI (???))\n- wan: wanxl: Only reset hardware after BAR mapping (Ruoyu Wang) {CVE-2026-68327}\n- nfp: Check resource mutex allocation (Ruoyu Wang) {CVE-2026-68328}\n- wifi: mac80211: tear down new links on vif update error path (Xiang Mei) {CVE-2026-64574}\n- iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (Guanghui Feng) {CVE-2026-68329}\n- dpaa2-eth: put MAC endpoint device on disconnect (Guangshuo Li) {CVE-2026-68331}\n- dpaa2-switch: put MAC endpoint device on disconnect (Guangshuo Li) {CVE-2026-68333}\n- gtp: parse extension headers before reading inner protocol (Zhixing Chen)\n- bonding: fix devconf_all NULL dereference when IPv6 is disabled (Zhaolong Zhang) {CVE-2026-68336}\n- net/packet: avoid fanout hook re-registration after unregister (David Lee) {CVE-2026-68338}\n- netlink: specs: rt-link: convert bridge port flag attributes to u8 (Danielle Ratson)\n- Bluetooth: btusb: validate Realtek vendor event length (Pengpeng Hou) {CVE-2026-68339}\n- regulator: mt6358: use regmap helper to read fixed LDO calibration (Daniel Golle)\n- hwmon: occ: validate poll response sensor blocks (Pengpeng Hou) {CVE-2026-68340}\n- smb: client: validate DFS referral PathConsumed (Yichong Chen) {CVE-2026-68343}\n- hwmon: (asus-ec-sensors) add missed handle for ENOMEM (Eugene Shalygin)\n- hwmon: (asus-ec-sensors) fix EC read intervals (Eugene Shalygin)\n- hwmon: (asus-ec-sensors) fix looping over banks while reading from EC (Eugene Shalygin)\n- drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook() (Mostafa Saleh)\n- wifi: iwlwifi: mvm: fix read in wake packet notification handler (Shahar Tzarfati)\n- wifi: iwlwifi: mvm: validate SAR GEO response payload size (Pagadala Yesu Anjaneyulu)\n- ASoC: cs35l56: Use complete_all() to signal init_completion (Richard Fitzgerald)\n- ASoC: cs35l56: Fix potential probe() deadlock (Richard Fitzgerald)\n- ASoC: cs35l56: Don't use devres to unregister component (Richard Fitzgerald)\n- ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI (Shengjiu Wang)\n- ALSA: hda: cs35l41: validate and free ACPI mute object (Guangshuo Li) {CVE-2026-68346}\n- ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state() (Denis Arefev)\n- ASoC: tas2781: bound firmware description string parsing (Pengpeng Hou) {CVE-2026-68348}\n- btrfs: free mapping node on duplicate reloc root insert (Guanghui Yang) {CVE-2026-68450}\n- btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps (Leo Martins) {CVE-2026-68442}\n- btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8 (You-Kai Zheng)\n- wifi: carl9170: fix buffer overflow in rx_stream failover path (Tristan Madani) {CVE-2026-68349}\n- wifi: carl9170: fix OOB read from off-by-two in TX status handler (Tristan Madani) {CVE-2026-68350}\n- wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read (Tristan Madani) {CVE-2026-68351}\n- wifi: ath6kl: fix OOB read from firmware IE lengths in connect event (Tristan Madani) {CVE-2026-68352}\n- wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler (Tristan Madani) {CVE-2026-68353}\n- firewire: net: Fix fragmented datagram reassembly (Ruoyu Wang) {CVE-2026-68354}\n- wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (Manivannan Sadhasivam)\n- wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (Manivannan Sadhasivam)\n- wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() (Dmitry Morgun) {CVE-2026-68355}\n- watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() (Tzung-Bi Shih) {CVE-2026-68357}\n- hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop (Guenter Roeck) {CVE-2026-68358}\n- hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop (Guenter Roeck) {CVE-2026-68359}\n- hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop (Guenter Roeck) {CVE-2026-68443}\n- hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop (Guenter Roeck) {CVE-2026-68360}\n- hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop (Edward Adam Davis) {CVE-2026-68361}\n- wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin (Gaole Zhang) {CVE-2026-68362}\n- wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (Cheng Yongkang) {CVE-2026-68363}\n- usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits (Xincheng Zhang)\n- RISC-V: KVM: Serialize virtual interrupt pending state updates (Xie Bo)\n- crypto: rsa-pkcs1pad: Don't WARN on an empty digest (Doruk Tan Ozturk)\n- USB: serial: option: add TDTECH MT5710-CN (Chukun Pan)\n- USB: serial: keyspan_pda: fix data loss on receive throttling (Johan Hovold)\n- USB: serial: io_edgeport: cap received transmit credits (Sunho Park) {CVE-2026-68365}\n- USB: serial: ftdi_sio: add support for E+H FXA291 (Tim Pambor)\n- usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer (Muhammad Bilal) {CVE-2026-68366}\n- usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown (Fan Wu) {CVE-2026-64583}\n- usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() (Sonali Pradhan) {CVE-2026-68368}\n- USB: gadget: fsl-udc: fix device name leak on probe failure (Johan Hovold)\n- USB: gadget: snps-udc: fix device name leak on probe failure (Johan Hovold)\n- usb: gadget: printer: fix infinite loop in printer_read() (Melbin K Mathew) {CVE-2026-68369}\n- usb: gadget: f_midi: cancel pending IN work before freeing the midi object (Fan Wu) {CVE-2026-64584}\n- usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback (Jinchao Wang) {CVE-2026-68370}\n- usb: chipidea: fix usage_count leak when autosuspend_delay is negative (Xu Yang)\n- USB: storage: add NO_ATA_1X quirk for Longmai USB Key (Huang Wei)\n- usb: core: port: Deattach Type-C connector on component unbind (Chia-Lin Kao (AceLan))\n- wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() (Huihui Huang) {CVE-2026-68373}\n- usb: core: sysfs: add lock to bos_descriptors_read() (Griffin Kroah-Hartman) {CVE-2026-68374}\n- mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (Weiming Shi) {CVE-2026-64569}\n- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) {CVE-2026-68376}\n- net/sched: act_tunnel_key: Defer dst_release to RCU callback (Jamal Hadi Salim) {CVE-2026-68377}\n- drm/i915/selftests: Fix GT PM sort comparators (Emre Cecanpunar)\n- ksmbd: validate compound request size before reading StructureSize2 (Xiang Mei (Microsoft))\n- ksmbd: pin conn during async oplock break notification (Qihang) {CVE-2026-68381}\n- smb: move some duplicate definitions to common/cifsglob.h (ZhangGuoDong)\n- drm/xe/wopcm: fix WOPCM size for LNL+ (Daniele Ceraolo Spurio)\n- can: j1939: fix lockless local-destination check (Shuhao Fu)\n- riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus() (Mark Harris)\n- s390/checksum: Fix csum_partial() without vector facility (Vasily Gorbik) {CVE-2026-68385}\n- bpf, sockmap: Reject unhashed UDP sockets on sockmap update (Michal Luczaj) {CVE-2026-68386}\n- powerpc/vtime: Initialize starttime at boot for native accounting (Shrikanth Hegde)\n- powerpc/time: Prepare to stop elapsing in dynticks-idle (Frederic Weisbecker)\n- powerpc/85xx: Add fsl,ifc to common device ids (Rosen Penev)\n- drm/i915/gt: use correct selftest config symbol (Pengpeng Hou)\n- smb/client: handle overlapping allocated ranges in fallocate (Huiwen He) {CVE-2026-68388}\n- Bluetooth: hci_qca: Clear memdump state on invalid dump size (Ruoyu Wang) {CVE-2026-68389}\n- Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (Pauli Virtanen) {CVE-2026-68391}\n- Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync (Pauli Virtanen) {CVE-2026-68392}\n- Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update (Cen Zhang) {CVE-2026-68394}\n- Bluetooth: qca: fix NVM tag length underflow in TLV parser (Xiang Mei) {CVE-2026-64573}\n- ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (Takashi Iwai)\n- accel/ivpu: Fix wrong register read in LNL failure diagnostics (Karol Wachowski)\n- ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning (Rosen Penev) {CVE-2026-68449}\n- ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts (Rosen Penev)\n- ata: sata_dwc_460ex: use platform_get_irq() (Rosen Penev)\n- ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered (Rosen Penev) {CVE-2026-68395}\n- net/iucv: take a reference on the socket found in afiucv_hs_rcv() (Bryam Vargas) {CVE-2026-68397}\n- ipv4: fib: free fib_alias with kfree_rcu() on insert error path (Weiming Shi) {CVE-2026-64572}\n- ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (Norbert Szetei) {CVE-2026-68398}\n- cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq (Rafael J. Wysocki)\n- firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context (Pushpendra Singh)\n- ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (Uday Khare)\n- ASoC: cs42l43: Correct report for forced microphone jack (Charles Keepax)\n- ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() (Vijendar Mukunda)\n- ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (Christian Hewitt)\n- wifi: cfg80211: bound element ID read when checking non-inheritance (HE WEI (???))\n- wifi: brcmfmac: initialize SDIO data work before cleanup (Runyu Xiao) {CVE-2026-68403}\n- wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (Cen Zhang) {CVE-2026-68405}\n- wifi: cfg80211: reject unsupported PMSR FTM location requests (Zhao Li)\n- wifi: cfg80211: validate PMSR FTM preamble range (Zhao Li) {CVE-2026-68406}\n- wifi: cfg80211: validate PMSR measurement type data (Zhao Li)\n- wifi: nl80211: validate nested MBSSID IE blobs (Zhao Li)\n- wifi: cfg80211: derive S1G beacon TSF from S1G fields (Zhao Li)\n- wifi: nl80211: free RNR data on MBSSID mismatch (Zhao Li) {CVE-2026-68407}\n- wifi: p54: validate RX frame length in p54_rx_eeprom_readback() (Xiang Mei) {CVE-2026-64571}\n- wifi: libertas: fix memory leak in helper_firmware_cb() (Dawei Feng) {CVE-2026-68410}\n- wifi: mac80211: fix fils_discovery double free on alloc failure (Xiang Mei) {CVE-2026-64570}\n- wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure (Xiang Mei) {CVE-2026-64568}\n- wifi: mac80211_hwsim: clamp virtio RX length before skb_put (Bryam Vargas) {CVE-2026-68411}\n- wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (Abdun Nihaal) {CVE-2026-68413}\n- wifi: cfg80211: cancel sched scan results work on unregister (Cen Zhang) {CVE-2026-68414}\n- xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert (Xiang Mei (Microsoft))\n- xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() (Xiang Mei (Microsoft))\n- RDMA/irdma: Prevent overflows in memory contiguity checks (Aleksandrova Alyona)\n- selftests/alsa: Fix memory leak in find_controls error path (Malaya Kumar Rout)\n- mtd: fix double free and WARN_ON in add_mtd_device() error paths (Xue Lei) {CVE-2026-68416}\n- RDMA/siw: publish QP after initialization (Ruoyu Wang) {CVE-2026-68417}\n- RDMA/hns: Fix potential integer overflow in mhop hem cleanup (Danila Chernetsov)\n- RDMA/erdma: initialize ret for empty receive WR lists (Ruoyu Wang)\n- RDMA/irdma: Prevent rereg_mr for non-mem regions (Jacob Moroni) {CVE-2026-68419}\n- RDMA/umem: Add pinned revocable dmabuf import interface (Jacob Moroni)\n- RDMA/cma: Fix hardware address comparison length in netevent callback (Or Gerlitz)\n- firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (Unnathi Chalicheemala) {CVE-2026-68444}\n- btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (Filipe Manana) {CVE-2026-68422}\n- btrfs: reject free space cache with more entries than pages (Xiang Mei) {CVE-2026-64567}\n- mtd: nand: mtk-ecc: stop on ECC idle timeouts (Pengpeng Hou)\n- mtd: mtdswap: remove debugfs stats file on teardown (Pengpeng Hou)\n- IB/mad: Drop unmatched RMPP responses before reassembly (Michael Bommarito) {CVE-2026-68425}\n- arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234 (Sumit Gupta)\n- soc: qcom: ice: Allow explicit votes on 'iface' clock for ICE (Harshal Dev)\n- Input: ims-pcu - fix logic error in packet reset (Dmitry Torokhov)\n- Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (Seungjin Bae) {CVE-2026-64565}\n- xprtrdma: Clear receive-side ownership pointers on release (Chuck Lever)\n- crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin (Mikko Perttunen)\n- gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings (Mikko Perttunen) {CVE-2026-68427}\n- dmaengine: sh: rz-dmac: Move interrupt request after everything is set up (Claudiu Beznea) {CVE-2026-72146}\n- can: isotp: serialize TX state transitions under so-rx_lock (Oliver Hartkopp) {CVE-2026-72124}\n- can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER (Oliver Hartkopp) {CVE-2026-72125}\n- can: bcm: track a single source interface for ANYDEV timeout/throttle ops (Oliver Hartkopp) {CVE-2026-72115}\n- can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() (Oliver Hartkopp) {CVE-2026-72117}\n- can: bcm: fix stale rx/tx ops after device removal (Oliver Hartkopp) {CVE-2026-72116}\n- can: bcm: add missing device refcount for CAN filter removal (Oliver Hartkopp) {CVE-2026-72113}\n- can: bcm: validate frame length in bcm_rx_setup() for RTR replies (Oliver Hartkopp) {CVE-2026-72114}\n- can: bcm: extend bcm_tx_lock usage for data and timer updates (Oliver Hartkopp) {CVE-2026-72119}\n- can: bcm: fix CAN frame rx/tx statistics (Oliver Hartkopp) {CVE-2026-72118}\n- can: bcm: add locking when updating filter and timer values (Oliver Hartkopp) {CVE-2026-72121}\n- KVM: x86/mmu: Fix use-after-free on vendor module reload (Phil Rosenthal) {CVE-2026-68428}\n- KVM: nVMX: Hide shadow VMCS right after VMCLEAR (Hyunwoo Kim) {CVE-2026-64562}\n- KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN (Venkatesh Srinivas)\n- seqlock: Allow UBSAN_ALIGNMENT to fail optimizing (Heiko Carstens)\n- seqlock: Allow KASAN to fail optimizing (Peter Zijlstra)\n- seqlock: Cure some more scoped_seqlock() optimization fails (Peter Zijlstra)\n- fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race (Kiryl Shutsemau) {CVE-2026-72175}\n- drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker (Ryosuke Yasuoka)\n- netfilter: nf_tables: revert commit_mutex usage in reset path (Brian Witte) {CVE-2026-45901}\n- netfilter: nft_quota: use atomic64_xchg for reset (Brian Witte)\n- netfilter: nft_counter: serialize reset with spinlock (Brian Witte) {CVE-2026-45897}\n- selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs (Daniel Borkmann)\n- bpf: Fix ld_{abs,ind} failure path analysis in subprogs (Daniel Borkmann) {CVE-2026-53090}\n- net: airoha: Move airoha_eth driver in a dedicated folder (Lorenzo Bianconi)\n- platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug (Guixiong Wei)\n\n[6.12.0-206.100.3]\n- can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure (Guangshuo Li) {CVE-2026-74459}\n- ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes (Norbert Szetei) {CVE-2026-74503}\n- sched/deadline: Use revised wakeup rule only for running dl_server (Gabriele Monaco)\n- scsi: ufs: core: Cancel RTC work in active-active suspend (Guangshuo Li)\n- net: airoha: Fix register index for Tx-fwd counter configuration (Wayen Yan)\n- netfilter: nf_conntrack_expect: restore helper propagation via expectation (Pablo Neira Ayuso)\n- Enable Time slice extension (Prakash Sangappa) [Orabug: 39047408]\n- rseq: Increase struct rseq size to match mainline linux (Prakash Sangappa) [Orabug: 39047408]\n- selftests/rseq: Make registration flexible for legacy and optimized mode (Thomas Gleixner) [Orabug: 39047408]\n- selftests/rseq: Skip tests if time slice extensions are not available (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Don't advertise time slice extensions if disabled (Thomas Gleixner) [Orabug: 39047408]\n- selftests/rseq: Add rseq slice histogram script (Peter Zijlstra) [Orabug: 39047408]\n- rseq: Lower default slice extension (Peter Zijlstra) [Orabug: 39047408]\n- rseq: Move slice_ext_nsec to debugfs (Peter Zijlstra) [Orabug: 39047408]\n- rseq: Allow registering RSEQ with slice extension (Peter Zijlstra) [Orabug: 39047408]\n- selftests/rseq: Implement time slice extension test (Thomas Gleixner) [Orabug: 39047408]\n- entry: Hook up rseq time slice extension (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Implement rseq_grant_slice_extension() (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Reset slice extension when scheduled (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Implement time slice extension enforcement timer (Prakash Sangappa) [Orabug: 39047408]\n- rseq: Implement syscall entry work for time slice extensions (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Implement sys_rseq_slice_yield() (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Add prctl() to enable time slice extensions (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Add statistics for time slice extensions (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Provide static branch for runtime debugging (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Expose lightweight statistics in debugfs (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Provide static branch for time slice extensions (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Add fields and constants for time slice extension (Prakash Sangappa) [Orabug: 39047408]\n- Revert 'Sched: Scheduler time slice extension' (Prakash Sangappa) [Orabug: 39047408]\n- Revert 'Sched: Add scheduler stat for cpu time slice extension' (Prakash Sangappa) [Orabug: 39047408]\n- Revert 'Scheduler extension change under Oracle Extensions and modify enum value' (Prakash Sangappa) [Orabug: 39047408]\n- net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover (Matt Fleming) [Orabug: 39203117,39870622] {CVE-2026-64122}\n- net/mlx5e: Fix deadlocks between devlink and netdev instance locks (Cosmin Ratiu) [Orabug: 39203117,39870450] {CVE-2026-45907}\n- net/mlx5: HWS, ignore flow level for multi-dest table (Yevgeny Kliteynik) [Orabug: 39203117]\n- net/mlx5: Prevent flow steering mode changes in switchdev mode (Moshe Shemesh) [Orabug: 39203117]\n- net/mlx5: HWS, Fix pattern destruction in mlx5hws_pat_get_pattern error path (Lama Kayal) [Orabug: 39203117]\n- net/mlx5: HWS, Fix memory leak in hws_action_get_shared_stc_nic error flow (Lama Kayal) [Orabug: 39203117]\n- net/mlx5: HWS, Fix memory leak in hws_pool_buddy_init error path (Lama Kayal) [Orabug: 39203117]\n- selftests: drv-net: hds: restore hds settings (Jakub Kicinski) [Orabug: 39203117]\n- net/mlx5: Restore missing scheduling node cleanup on vport enable failure (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: Fix QoS reference leak in vport enable error path (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: Destroy vport QoS element when no configuration remains (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5e: Preserve tc-bw during parent changes (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: Remove default QoS group and attach vports directly to root TSAR (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: HWS, Fix table creation UID (Alex Vesker) [Orabug: 39203117]\n- net/mlx5: HWS, don't rehash on every kind of insertion failure (Yevgeny Kliteynik) [Orabug: 39203117]\n- selftests: drv-net: wait for carrier (Jakub Kicinski) [Orabug: 39203117]\n- netdevsim: Fix wild pointer access in nsim_queue_free(). (Kuniyuki Iwashima) [Orabug: 39203117]\n- vfio/pci: Do vf_token checks for VFIO_DEVICE_BIND_IOMMUFD (Jason Gunthorpe) [Orabug: 39203117]\n- net/mlx5e: Expose TIS via devlink tx reporter diagnose (Feng Liu) [Orabug: 39203117]\n- net/mlx5e: Fix potential deadlock by deferring RX timeout recovery (Shahar Shitrit) [Orabug: 39203117]\n- selftests: drv-net: Make command requirements explicit (Gal Pressman) [Orabug: 39203117]\n- net/mlx5: Fix build -Wframe-larger-than warnings (Zhu Yanjun) [Orabug: 39203117]\n- mlx5: access -pp through netmem_desc instead of page (Byungchul Park) [Orabug: 39203117]\n- netdevsim: access -pp through netmem_desc instead of page (Byungchul Park) [Orabug: 39203117]\n- netmem, mlx4: access -pp_ref_count through netmem_desc instead of page (Byungchul Park) [Orabug: 39203117]\n- netmem: use netmem_desc instead of page to access -pp in __netmem_get_pp() (Byungchul Park) [Orabug: 39203117]\n- netmem: introduce struct netmem_desc mirroring struct page (Byungchul Park) [Orabug: 39203117]\n- netdevsim: add fw_update_flash_chunk_time_ms debugfs knobs (Jiri Pirko) [Orabug: 39203117]\n- devlink: Fix excessive stack usage in rate TC bandwidth parsing (Carolina Jubran) [Orabug: 39203117]\n- RDMA/mlx5: Refactor optional counters steering code (Patrisious Haddad) [Orabug: 39203117]\n- RDMA/mlx5: Add DMAH object support (Yishai Hadas) [Orabug: 39203117]\n- RDMA/core: Introduce a DMAH object and its alloc/free APIs (Yishai Hadas) [Orabug: 39203117]\n- IB/core: Add UVERBS_METHOD_REG_MR on the MR object (Yishai Hadas) [Orabug: 39203117]\n- net/mlx5: Add support for device steering tag (Yishai Hadas) [Orabug: 39203117]\n- net/mlx5: Expose IFC bits for TPH (Yishai Hadas) [Orabug: 39203117]\n- PCI/TPH: Expose pcie_tph_get_st_table_size() (Yishai Hadas) [Orabug: 39203117]\n- net/mlx5e: Remove duplicate mkey from SHAMPO header (Lama Kayal) [Orabug: 39203117]\n- net/mlx5e: SHAMPO, Remove mlx5e_shampo_get_log_hd_entry_size() (Lama Kayal) [Orabug: 39203117]\n- net/mlx5e: SHAMPO, Cleanup reservation size formula (Lama Kayal) [Orabug: 39203117]\n- selftests: drv-net: Test XDP_PASS/DROP support (Mohsin Bashir) [Orabug: 39203117]\n- net: netdevsim: hook in XDP handling (Jakub Kicinski) [Orabug: 39203117]\n- RDMA/mlx5: Fix incorrect MKEY masking (Leon Romanovsky) [Orabug: 39203117]\n- RDMA/mlx5: Fix returned type from _mlx5r_umr_zap_mkey() (Leon Romanovsky) [Orabug: 39203117]\n- net/mlx5: Expose cable_length field in PFCC register (Oren Sidi) [Orabug: 39203117]\n- net/mlx5: Add IFC bits to support RSS for IPSec offload (Jianbo Liu) [Orabug: 39203117]\n- net/mlx5e: fix kdoc warning on eswitch.h (Moshe Shemesh) [Orabug: 39203117]\n- net/mlx5: HWS, Enable IPSec hardware offload in legacy mode (Lama Kayal) [Orabug: 39203117]\n- net/mlx5: Fix an IS_ERR() vs NULL bug in esw_qos_move_node() (Dan Carpenter) [Orabug: 39203117]\n- netdevsim: remove redundant branch (Dennis Chen) [Orabug: 39203117]\n- selftests: net: prevent Python from buffering the output (Jakub Kicinski) [Orabug: 39203117]\n- netlink: specs: define input-xfrm enum in the spec (Jakub Kicinski) [Orabug: 39203117]\n- net/mlx5e: TX, Fix dma unmapping for devmem tx (Dragos Tatulea) [Orabug: 39203117]\n- RDMA/mlx5: remove redundant check on err on return expression (Colin Ian King) [Orabug: 39203117]\n- net/mlx5e: Add device PCIe congestion ethtool stats (Dragos Tatulea) [Orabug: 39203117]\n- net/mlx5e: Create/destroy PCIe Congestion Event object (Dragos Tatulea) [Orabug: 39203117]\n- selftests: net: add netpoll basic functionality test (Breno Leitao) [Orabug: 39203117]\n- selftests: drv-net: add helper/wrapper for bpftrace (Jakub Kicinski) [Orabug: 39203117]\n- netdevsim: implement peer queue flow control (Breno Leitao) [Orabug: 39203117]\n- RDMA/uverbs: Add a common way to create CQ with umem (Michael Margolin) [Orabug: 39203117]\n- net/mlx5: Expose disciplined_fr_counter through HCA capabilities in mlx5_ifc (Carolina Jubran) [Orabug: 39203117]\n- RDMA/mlx5: Optimize DMABUF mkey page size (Edward Srouji) [Orabug: 39203117]\n- RDMA/mlx5: Align mkc page size capability check to PRM (Michael Guralnik) [Orabug: 39203117]\n- net/mlx5: Expose HCA capability bits for mkey max page size (Michael Guralnik) [Orabug: 39203117]\n- net: netdevsim: Support setting dev-perm_addr on port creation (Toke Hoiland-Jorgensen) [Orabug: 39203117]\n- selftests: drv-net: Add bpftool util (Mohsin Bashir) [Orabug: 39203117]\n- net/mlx5e: RX, Remove unnecessary RQT redirects (Tariq Toukan) [Orabug: 39203117]\n- net/mlx5: Warn when write combining is not supported (Maor Gottlieb) [Orabug: 39203117]\n- net/mlx5e: Replace recursive VLAN push handling with an iterative loop (Gal Pressman) [Orabug: 39203117]\n- net/mlx5e: CT: extract a memcmp from a spinlock section (Cosmin Ratiu) [Orabug: 39203117]\n- net/mlx5e: Remove unused VLAN insertion logic in TX path (Carolina Jubran) [Orabug: 39203117]\n- eth: mlx5: migrate to the *_rxfh_context ops (Jakub Kicinski) [Orabug: 39203117]\n- net/mlx5: Fix spelling mistake 'disabliing' - 'disabling' (Colin Ian King) [Orabug: 39203117]\n- net/mlx5: Add HWS as secondary steering mode (Moshe Shemesh) [Orabug: 39203117]\n- net/mlx5: HWS, Shrink empty matchers (Yevgeny Kliteynik) [Orabug: 39203117]\n- net/mlx5: HWS, Refactor rule skip logic (Vlad Dogaru) [Orabug: 39203117]\n- net/mlx5: HWS, remove incorrect comment (Yevgeny Kliteynik) [Orabug: 39203117]\n- net/mlx5: HWS, remove unused create_dest_array parameter (Vlad Dogaru) [Orabug: 39203117]\n- netmem: use _Generic to cover const casting for page_to_netmem() (Byungchul Park) [Orabug: 39203117]\n- page_pool: rename __page_pool_alloc_pages_slow() to __page_pool_alloc_netmems_slow() (Byungchul Park) [Orabug: 39203117]\n- page_pool: rename __page_pool_release_page_dma() to __page_pool_release_netmem_dma() (Byungchul Park) [Orabug: 39203117]\n- page_pool: rename page_pool_return_page() to page_pool_return_netmem() (Byungchul Park) [Orabug: 39203117]\n- mlxbf_gige: emit messages during open and probe failures (David Thompson) [Orabug: 39203117]\n- selftests: drv-net: Add test for devlink-rate traffic class bandwidth distribution (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: Manage TC arbiter nodes and implement full support for tc-bw (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: Add traffic class scheduling support for vport QoS (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: Add support for setting tc-bw on nodes (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: Add no-op implementation for setting tc-bw on rate objects (Carolina Jubran) [Orabug: 39203117]\n- selftest: netdevsim: Add devlink rate tc-bw test (Carolina Jubran) [Orabug: 39203117]\n- devlink: Extend devlink rate API with traffic classes bandwidth management (Carolina Jubran) [Orabug: 39203117]\n- netlink: introduce type-checking attribute iteration for nlmsg (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: fs, fix RDMA TRANSPORT init cleanup flow (Patrisious Haddad) [Orabug: 39203117]\n- RDMA/mlx5: Check CAP_NET_RAW in user namespace for devx create (Parav Pandit) [Orabug: 39203117]\n- time/timecounter: Fix the lie that struct cyclecounter is const (Greg Kroah-Hartman) [Orabug: 39203117]\n- RDMA/mlx5: Check CAP_NET_RAW in user namespace for anchor create (Parav Pandit) [Orabug: 39203117]\n- RDMA/mlx5: Check CAP_NET_RAW in user namespace for flow create (Parav Pandit) [Orabug: 39203117]\n- RDMA/uverbs: Check CAP_NET_RAW in user namespace for flow create (Parav Pandit) [Orabug: 39203117]\n- net/mlx5e: Fix error handling in RQ memory model registration (Wangfushuai) [Orabug: 39203117]\n- selftests: forwarding: lib: Split setup_wait() (Petr Machata) [Orabug: 39203117]\n- RDMA/ipoib: Use parent rdma device net namespace (Mark Bloch) [Orabug: 39203117]\n- RDMA/mlx5: Allocate IB device with net namespace supplied from core dev (Mark Bloch) [Orabug: 39203117]\n- RDMA/core: Extend RDMA device registration to be net namespace aware (Mark Bloch) [Orabug: 39203117]\n- netlink: specs: ethtool: replace underscores with dashes in names (Jakub Kicinski) [Orabug: 39203117]\n- net/mlx5: Add IFC bits for PCIe Congestion Event object (Dragos Tatulea) [Orabug: 39203117]\n- net/mlx5: Small refactor for general object capabilities (Dragos Tatulea) [Orabug: 39203117]\n- RDMA/mlx5: Add multiple priorities support to RDMA TRANSPORT userspace tables (Patrisious Haddad) [Orabug: 39203117]\n- net/mlx5: fs, add multiple prios to RDMA TRANSPORT steering domain (Patrisious Haddad) [Orabug: 39203117]\n- RDMA/mlx5: Support driver APIs pre_destroy_cq and post_destroy_cq (Mark Zhang) [Orabug: 39203117]\n- RDMA/core: Add driver APIs pre_destroy_cq() and post_destroy_cq() (Mark Zhang) [Orabug: 39203117]\n- mmc: sdhci-of-dwcmshc: Drop the use of sdhci_pltfm_free() (Binbin Zhou) [Orabug: 39203117]\n- selftests: drv-net: import things in lib one by one (Jakub Kicinski) [Orabug: 39203117]\n- netdevsim: fix UaF when counting Tx stats (Jakub Kicinski) [Orabug: 39203117]\n- eth: mlx5: migrate to new RXFH callbacks (Jakub Kicinski) [Orabug: 39203117]\n- netdevsim: account dropped packet length in stats on queue free (Breno Leitao) [Orabug: 39203117]\n- net: add dev_dstats_rx_dropped_add() helper (Breno Leitao) [Orabug: 39203117]\n- netdevsim: collect statistics at RX side (Breno Leitao) [Orabug: 39203117]\n- netdevsim: migrate to dstats stats collection (Breno Leitao) [Orabug: 39203117]\n- net/mlx4_en: Remove the redundant NULL check for the 'my_ets' object (Andrey Vatoropin) [Orabug: 39203117]\n- netdevsim: remove udp_ports_sleep (Stanislav Fomichev) [Orabug: 39203117]\n- net/mlx4e: Don't redefine IB_MTU_XXX enum (Mark Zhang) [Orabug: 39203117]\n- pinctrl: Constify static 'pinctrl_desc' (Krzysztof Kozlowski) [Orabug: 39203117]\n- pinctrl: Constify pointers to 'pinctrl_desc' (Krzysztof Kozlowski) [Orabug: 39203117]\n- pinctrl: amd: Constify pointers to 'pinctrl_desc' (Krzysztof Kozlowski) [Orabug: 39203117]\n- net/mlx5e: Add TX support for netmems (Dragos Tatulea) [Orabug: 39203117]\n- net/mlx5e: Support ethtool tcp-data-split settings (Saeed Mahameed) [Orabug: 39203117]\n- net/mlx5e: Implement queue mgmt ops and single channel swap (Saeed Mahameed) [Orabug: 39203117]\n- net/mlx5e: Add support for UNREADABLE netmem page pools (Saeed Mahameed) [Orabug: 39203117]\n- net/mlx5e: Convert over to netmem (Saeed Mahameed) [Orabug: 39203117]\n- net/mlx5e: SHAMPO: Separate pool for headers (Saeed Mahameed) [Orabug: 39203117]\n- net/mlx5e: SHAMPO: Improve hw gro capability checking (Saeed Mahameed) [Orabug: 39203117]\n- net/mlx5e: SHAMPO: Remove redundant params (Saeed Mahameed) [Orabug: 39203117]\n- net/mlx5e: SHAMPO: Reorganize mlx5_rq_shampo_alloc (Saeed Mahameed) [Orabug: 39203117]\n- page_pool: Add page_pool_dev_alloc_netmems helper (Dragos Tatulea) [Orabug: 39203117]\n- net: Add skb_can_coalesce for netmem (Dragos Tatulea) [Orabug: 39203117]\n- net: Allow const args for of page_to_netmem() (Dragos Tatulea) [Orabug: 39203117]\n- selftests: forwarding: Add a test for verifying VXLAN MC underlay (Petr Machata) [Orabug: 39203117]\n- netmem: fix netmem comments (Mina Almasry) [Orabug: 39203117]\n- selftests: net: add netconsole test for cmdline configuration (Breno Leitao) [Orabug: 39203117]\n- net: ethtool: add dedicated callbacks for getting and setting rxfh fields (Jakub Kicinski) [Orabug: 39203117]\n- net: ethtool: require drivers to opt into the per-RSS ctx RXFH (Jakub Kicinski) [Orabug: 39203117]\n- net: ethtool: remove the duplicated handling from rxfh and rxnfc (Jakub Kicinski) [Orabug: 39203117]\n- net: ethtool: copy the rxfh flow handling (Jakub Kicinski) [Orabug: 39203117]\n- net: ethtool: Don't check if RSS context exists in case of context 0 (Gal Pressman) [Orabug: 39203117]\n- net/mlx5: Expose serial numbers in devlink info (Jiri Pirko) [Orabug: 39203117]\n- selftests: netconsole: Add support for basic netconsole target format (Breno Leitao) [Orabug: 39203117]\n- selftests: netconsole: Do not exit from inside the validation function (Breno Leitao) [Orabug: 39203117]\n- page_pool: fix ugly page_pool formatting (Mina Almasry) [Orabug: 39203117]\n- net/mlx5e: Convert mlx5 netdevs to instance locking (Cosmin Ratiu) [Orabug: 39203117]\n- net: Add support for providing the PTP hardware source in tsinfo (Kory Maincent) [Orabug: 39203117]\n- selftests: drv-net: Fix 'envirnoments' to 'environments' (Sumanth Gavini) [Orabug: 39203117]\n- net: enable driver support for netmem TX (Mina Almasry) [Orabug: 39203117]\n- net: add get_netmem/put_netmem support (Mina Almasry) [Orabug: 39203117]\n- netmem: add niov-type attribute to distinguish different net_iov types (Mina Almasry) [Orabug: 39203117]\n- selftests: drv-net: ping: make sure the ping test restores checksum offload (Jakub Kicinski) [Orabug: 39203117]\n- ethtool: Block setting of symmetric RSS when non-symmetric rx-flow-hash is requested (Gal Pressman) [Orabug: 39203117]\n- pinctrl: mediatek: airoha: use new GPIO line value setter callbacks (Bartosz Golaszewski) [Orabug: 39203117]\n- selftests: net-drv: remove the nic_performance and nic_link_layer tests (Jakub Kicinski) [Orabug: 39203117]\n- devlink: define enum for attr types of dynamic attributes (Jiri Pirko) [Orabug: 39203117]\n- selftests: net: exit cleanly on SIGTERM / timeout (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv: net: add version indicator (Mohsin Bashir) [Orabug: 39203117]\n- selftests: drv: net: avoid skipping tests (Mohsin Bashir) [Orabug: 39203117]\n- selftests: drv: net: fix test failure on ipv6 sys (Mohsin Bashir) [Orabug: 39203117]\n- selftests: drv-net: rss_input_xfrm: Check test prerequisites before running (Gal Pressman) [Orabug: 39203117]\n- selftests: net: add a virtio_net deadlock selftest (Bui Quang Minh) [Orabug: 39203117]\n- selftests: net: move xdp_helper to net/lib (Bui Quang Minh) [Orabug: 39203117]\n- selftests: drv-net: Test that NAPI ID is non-zero (Joe Damato) [Orabug: 39203117]\n- pinctrl: airoha: fix wrong PHY LED mapping and PHY2 LED defines (Christian Marangi) [Orabug: 39203117]\n- netlink: specs: rename rtnetlink specs in accordance with family name (Jakub Kicinski) [Orabug: 39203117]\n- pinctrl: amd: Add an LPS0 check() callback (Mario Limonciello) [Orabug: 39203117]\n- selftests: drv-net: test random value for hds-thresh (Taehee Yoo) [Orabug: 39203117]\n- selftests: net: use Path helpers in ping (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: replace the rpath helper with Path objects (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: use defer in the ping test (Jakub Kicinski) [Orabug: 39203117]\n- net: skbuff: Remove unused skb_add_data() (Yue Haibing) [Orabug: 39203117]\n- selftests: drv-net: fix merge conflicts resolution (Matthieu Baerts) [Orabug: 39203117]\n- selftests: drv-net: add xdp cases for ping.py (Taehee Yoo) [Orabug: 39203117]\n- selftests: drv-net: use env.rpath in the HDS test (Jakub Kicinski) [Orabug: 39203117]\n- selftests: net: report output format as TAP 13 in Python tests (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: add tests for napi IRQ affinity notifiers (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net-hw: Add a test for symmetric RSS hash (Gal Pressman) [Orabug: 39203117]\n- selftests: drv-net: Make rand_port() get a port more reliably (Gal Pressman) [Orabug: 39203117]\n- selftests: drv-net: test XDP, HDS auto and the ioctl path (Jakub Kicinski) [Orabug: 39203117]\n- net: ethtool: fix ioctl confusing drivers about desired HDS user config (Jakub Kicinski) [Orabug: 39203117]\n- netlink: specs: Add FIB rule DSCP mask attribute (Ido Schimmel) [Orabug: 39203117]\n- selftests: net: Add python context manager for netns entering (Xiao Liang) [Orabug: 39203117]\n- selftests: drv-net: rename queues check_xdp to check_xsk (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: improve the use of ksft helpers in XSK queue test (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: add a way to wait for a local process (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: probe for AF_XDP sockets more explicitly (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: add missing new line in xdp_helper (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: use cfg.rpath() in netlink xsk attr test (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: add a warning for bkg + shell + terminate (Jakub Kicinski) [Orabug: 39203117]\n- net: ngbe: Add support for 1PPS and TOD (Jiawen Wu) [Orabug: 39203117]\n- net: wangxun: Add periodic checks for overflow and errors (Jiawen Wu) [Orabug: 39203117]\n- net: wangxun: Add support for PTP clock (Jiawen Wu) [Orabug: 39203117]\n- selftests: drv-net: add a simple TSO test (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: store addresses in dict indexed by ipver (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: get detailed interface info (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: resolve remote interface name (Jakub Kicinski) [Orabug: 39203117]\n- netlink: specs: Add FIB rule port mask attributes (Ido Schimmel) [Orabug: 39203117]\n- net: move stale comment about ntuple validation (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: Test queue xsk attribute (Joe Damato) [Orabug: 39203117]\n- io_uring/zcrx: add selftest (David Wei) [Orabug: 39203117]\n- selftests/net: Add selftest for IPv4 RTM_GETMULTICAST support (Yuyang Huang) [Orabug: 39203117]\n- selftests: drv-net: add helper for path resolution (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: factor out a DrvEnv base class (Jakub Kicinski) [Orabug: 39203117]\n- net: ethtool: prevent flow steering to RSS contexts which don't exist (Jakub Kicinski) [Orabug: 39203117]\n- netconsole: selftest: test for sysdata CPU (Breno Leitao) [Orabug: 39203117]\n- netconsole: selftest: Add test for fragmented messages (Breno Leitao) [Orabug: 39203117]\n- net: provide pending ring configuration in net_device (Jakub Kicinski) [Orabug: 39203117]\n- net: ethtool: store netdev in a temp variable in ethnl_default_set_doit() (Jakub Kicinski) [Orabug: 39203117]\n- net: move HDS config from ethtool state (Jakub Kicinski) [Orabug: 39203117]\n- selftest: net-drv: hds: add test for HDS feature (Taehee Yoo) [Orabug: 39203117]\n- netdevsim: add HDS feature (Taehee Yoo) [Orabug: 39203117]\n- bnxt_en: add support for hds-thresh ethtool command (Taehee Yoo) [Orabug: 39203117]\n- bnxt_en: add support for tcp-data-split ethtool command (Taehee Yoo) [Orabug: 39203117]\n- bnxt_en: add support for rx-copybreak ethtool command (Taehee Yoo) [Orabug: 39203117]\n- net: ethtool: add ring parameter filtering (Taehee Yoo) [Orabug: 39203117]\n- net: devmem: add ring parameter filtering (Taehee Yoo) [Orabug: 39203117]\n- net: ethtool: add support for configuring hds-thresh (Taehee Yoo) [Orabug: 39203117]\n- netconsole: selftest: verify userdata entry limit (Breno Leitao) [Orabug: 39203117]\n- netconsole: selftest: Split the helpers from the selftest (Breno Leitao) [Orabug: 39203117]\n- tools: ynl: move python code to separate sub-directory (Jan Stancek) [Orabug: 39203117]\n- netdevsim: add debugfs-triggered queue reset (Jakub Kicinski) [Orabug: 39203117]\n- netdev: define NETDEV_INTERNAL (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: test drivers sleeping in ndo_get_stats64 (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: assume stats refresh is 0 if no ethtool -c support (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: test empty queue and NAPI responses in netlink (Jakub Kicinski) [Orabug: 39203117]\n- page_pool: add page_pool_dev_alloc_netmem() (Alexander Lobakin) [Orabug: 39203117]\n- net: Document netmem driver support (Mina Almasry) [Orabug: 39203117]\n- netlink: specs: Add FIB rule flow label attributes (Ido Schimmel) [Orabug: 39203117]\n- selftests: net-drv: stats: sanity check netlink dumps (Jakub Kicinski) [Orabug: 39203117]\n- selftests: net-drv: queues: sanity check netlink dumps (Jakub Kicinski) [Orabug: 39203117]\n- selftests: net: support setting recv_size in YNL (Jakub Kicinski) [Orabug: 39203117]\n- net: ethtool: Add support for tsconfig command to get/set hwtstamp config (Kory Maincent) [Orabug: 39203117]\n- net: ethtool: tsinfo: Enhance tsinfo to support several hwtstamp by net topology (Kory Maincent) [Orabug: 39203117]\n- net: Add the possibility to support a selected hwtstamp in netdevice (Kory Maincent) [Orabug: 39203117]\n- net: Make net_hwtstamp_validate accessible (Kory Maincent) [Orabug: 39203117]\n- net: Make dev_get_hwtstamp_phylib accessible (Kory Maincent) [Orabug: 39203117]\n- page_pool: allow mixing PPs within one bulk (Alexander Lobakin) [Orabug: 39203117]\n- vrf: Make pcpu_dstats update functions available to other modules. (Guillaume Nault) [Orabug: 39203117]\n- page_pool: make page_pool_put_page_bulk() handle array of netmems (Alexander Lobakin) [Orabug: 39203117]\n- netmem: add a couple of page helper wrappers (Alexander Lobakin) [Orabug: 39203117]\n- xsk: allow attaching XSk pool via xdp_rxq_info_reg_mem_model() (Alexander Lobakin) [Orabug: 39203117]\n- xdp, xsk: constify read-only arguments of some static inline helpers (Alexander Lobakin) [Orabug: 39203117]\n- ethtool: regenerate uapi header from the spec (Stanislav Fomichev) [Orabug: 39203117]\n- ethtool: remove the comments that are not gonna be generated (Stanislav Fomichev) [Orabug: 39203117]\n- ethtool: separate definitions that are gonna be generated (Stanislav Fomichev) [Orabug: 39203117]\n- ynl: add missing pieces to ethtool spec to better match uapi header (Stanislav Fomichev) [Orabug: 39203117]\n- selftests: fix nested double quotes in f-string (David Wei) [Orabug: 39203117]\n- selftests: nic_performance: Add selftest for performance of NIC driver (Mohan Prasad J) [Orabug: 39203117]\n- selftests: nic_link_layer: Add selftest case for speed and duplex states (Mohan Prasad J) [Orabug: 39203117]\n- selftests: nic_link_layer: Add link layer selftest for NIC driver (Mohan Prasad J) [Orabug: 39203117]\n- pinctrl: airoha: Use unsigned long for bit search (Kees Cook) [Orabug: 39203117]\n- net: netconsole: selftests: Check if netdevsim is available (Breno Leitao) [Orabug: 39203117]\n- docs: networking: Describe irq suspension (Joe Damato) [Orabug: 39203117]\n- selftests: ncdevmem: Add automated test (Stanislav Fomichev) [Orabug: 39203117]\n- selftests: ncdevmem: Move ncdevmem under drivers/net/hw (Stanislav Fomichev) [Orabug: 39203117]\n- selftests: ncdevmem: Use YNL to enable TCP header split (Stanislav Fomichev) [Orabug: 39203117]\n- selftests: ncdevmem: Properly reset flow steering (Stanislav Fomichev) [Orabug: 39203117]\n- selftests: ncdevmem: Remove default arguments (Stanislav Fomichev) [Orabug: 39203117]\n- netlink: specs: Add a spec for FIB rule management (Donald Hunter) [Orabug: 39203117]\n- netlink: specs: Add a spec for neighbor tables in rtnetlink (Donald Hunter) [Orabug: 39203117]\n- net: netconsole: selftests: Add userdata validation (Breno Leitao) [Orabug: 39203117]\n- net: netconsole: selftests: Change the IP subnet (Breno Leitao) [Orabug: 39203117]\n- pinctrl: airoha: Add support for EN7581 SoC (Lorenzo Bianconi) [Orabug: 39203117]\n- Documentation: networking: Add missing PHY_GET command in the message list (Kory Maincent) [Orabug: 39203117]\n- netlink: specs: Add missing phy-ntf command to ethtool spec (Kory Maincent) [Orabug: 39203117]\n- selftests: net: lib: Introduce deferred commands (Petr Machata) [Orabug: 39203117]\n- ethtool: rss: prevent rss ctx deletion when in use (Daniel Zahka) [Orabug: 39203117]\n- selftests: net: move EXTRA_CLEAN of libynl.a into ynl.mk (Jakub Kicinski) [Orabug: 39203117]\n- selftests: net: rebuild YNL if dependencies changed (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: add missing trailing backslash (Jakub Kicinski) [Orabug: 39203117]\n- pinctrl: amd: Fix two small typos (Marc Ferland) [Orabug: 39203117]\n- pinctrl: Switch back to struct platform_driver::remove() (Uwe Kleine-Konig) [Orabug: 39203117]\n- pinctrl: qcom: add the tlmm driver for QCS615 platform (Lijuan Gao) [Orabug: 39203117]\n- net: tap: set skb-dev before parsing virtio net header in tap_get_user_xdp() (Dongli Zhang) [Orabug: 39558732] {CVE-2026-74684}\n- uek-rpm: enable Nexthop SONiC drivers for ONOS (Vijay Kumar) [Orabug: 39597630]\n- platform: nexthop-sonic: add SONiC platform drivers (Vijay Kumar) [Orabug: 39597630]\n- uek-rpm/modules.yaml.S.onos: Package PDDF platform drivers (Darren Kenny) [Orabug: 39597630]\n- uek-rpm/config-x86_64-onos: Enable PDDF platform driver configs (Vijay Kumar) [Orabug: 39597630]\n- platform: Port SONiC PDDF drivers (Test Com) [Orabug: 39597630]\n- rds: tcp: fix uninit-value in __inet_bind (Tabrez Ahmed) [Orabug: 39668598]\n- rds: tcp: cleanup if kmem_cache_alloc fails in rds_tcp_conn_alloc() (Sowmini Varadhan) [Orabug: 39668598]\n- eeprom: optoe: set clientdata before publishing sysfs files (Vijay Kumar) [Orabug: 39721366]\n- eeprom: optoe: remove eeprom bin file on sysfs_create_group failure (Vijay Kumar) [Orabug: 39721366]\n- eeprom: optoe: fix heap OOB write from stale writebuf sizing (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: raven-fan-driver: read fan ID pins at correct offsets (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: check parse result in scd_set_debug (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: restrict /proc/scd to root-only read (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: fan-cpld: don't hold cpld-lock across work cancel on remove (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: minke-fan-cpld: fix uninitialised cpld deref in probe error path (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: tmp468: fix out-of-bounds read of names[] in probe (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd-mdio: fix mdiobus_free(NULL) and mii_bus leak on error (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: enforce register offset bound instead of advisory ASSERT (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: overflow-safe range check in scd_lpc_mmap_resource (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: rook-fan-cpld: only unregister LEDs that were registered (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: minke-fan-cpld: unregister slot_count LEDs, not fan_count (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: fix SPI controller devdata UAF and invalid kfree (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: don't panic on over-long xcvr attribute name (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: remove partial xcvr sysfs attrs before freeing on error (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: init master-list before the master-add error path (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: use strscpy for LED name to guarantee NUL termination (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: bound fan_count against speed_*_steps[] arrays (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: bound derived MMIO offsets in master/port add paths (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: fix user-controlled format string in gpio/reset add (Vijay Kumar) [Orabug: 39721366]\n- src: handle ioremap error in raven-fan-driver (Arista-Hpandya) [Orabug: 39721366]\n- Replace sprintf with sysfs_emit in sysfs show callbacks (Arista-Hpandya) [Orabug: 39721366]\n- scd: add sysfs knob to control watchdog panic (Mohan Yelugoti) [Orabug: 39721366]\n- scd: update scd driver to EOS latest (Mohan Yelugoti) [Orabug: 39721366]\n- platform: remove old tricolor LED handling (Justin Oliver) [Orabug: 39721366]\n- scd: add bus_speed attribute to i2c buses (Samuel Angebault) [Orabug: 39721366]\n- Modify arista-drivers for arm64 compilation. (Vivek Kumar Verma) [Orabug: 39721366]\n- minke-fan-cpld: seperate slot and fan initialization in cpld_init (Arista-Hpandya) [Orabug: 39721366]\n- x86/bugs: Make Safe-RET robust against interrupt injection (Borislav Petkov) [Orabug: 39784619,39853774] {CVE-2026-68480}\n- net/rds: harden rds_rm_size (Manjunath Patil) [Orabug: 39812332]\n- KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Sean Christopherson) [Orabug: 39830589,39832725,39832878,39844799] {CVE-2026-64561}\n- net/rds: remove cached rds_sock-rs_conn and rs_conn_path (Sharath Srinivasan) [Orabug: 39832353]\n- Revert 'rds: cong: Make rds_cong_wait an array to reduce lock contention' (Sharath Srinivasan) [Orabug: 39832353]\n\n[6.12.0-206.100.2]\n- afs: Fix lack of locking around modifications of net-cells_dyn_ino (David Howells) {CVE-2026-72372}\n- afs: Fix dynamic lookup to fail on cell lookup failure (David Howells)\n- afs: Simplify cell record handling (David Howells)\n- afs: Fix afs_server ref accounting (David Howells)\n- afs: Use the per-peer app data provided by rxrpc (David Howells)\n- rxrpc: Allow the app to store private data on peer structs (David Howells)\n- afs: Drop the net parameter from afs_unuse_cell() (David Howells)\n- afs: Make afs_lookup_cell() take a trace note (David Howells)\n- afs: Improve server refcount/active count tracing (David Howells)\n- Bluetooth: hci_core: Fix not accounting for BIS/CIS/PA links separately (Luiz Augusto von Dentz)\n- Bluetooth: Add PA_LINK to distinguish BIG sync and PA sync connections (Yang Li)\n- net: qrtr: ns: Raise node count limit to 512 (Youssef Samir)\n- drm/amd/pm: fix smu13 power limit range calculation (Yang Wang)\n- ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL (Guan Wentao) {CVE-2026-68099}\n- ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl (Haofeng Li) {CVE-2026-68100}\n- vsock/virtio: collapse receive queue under memory pressure (Stefano Garzarella)\n- proc: Fix broken error paths for namespace links (Jann Horn)\n- serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (Jiangshan Yi) [Orabug: 39868564] {CVE-2026-68434}\n- drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) (Timur Kristof)\n- Revert 'drm/amd/display: Add missing kdoc for ALLM parameters' (Sasha Levin)\n- usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect (Diego Fernando Mancera Gomez) [Orabug: 39860411] {CVE-2026-68344}\n- net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets() (Lorenzo Bianconi)\n- udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf() (Robert Mader)\n- wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (Peddolla Harshavardhan Reddy) [Orabug: 39860409] {CVE-2026-68408}\n- wifi: cfg80211: define and use wiphy guard (Johannes Berg)\n- wifi: cfg80211: pass net_device to .set_monitor_channel (Felix Fietkau)\n- firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits (Seth Forshee)\n- Revert 'arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc' (Sasha Levin)\n- net: airoha: Fix skb-priority underflow in airoha_dev_select_queue() (Wayen Yan)\n- LTS version: v6.12.100 (Sherry Yang)\n- posix-cpu-timers: Prevent UAF caused by non-leader exec() race (Thomas Gleixner) [Orabug: 39807437] {CVE-2026-64560}\n- LTS version: v6.12.99 (Sherry Yang)\n- mm: refactor mm_access() to not return NULL (Lorenzo Stoakes)\n- LTS version: v6.12.98 (Sherry Yang)\n- ext4: fix fd leak in EXT4_IOC_MOVE_EXT cross-sb validation (Yun Zhou)\n- LTS version: v6.12.97 (Sherry Yang)\n- selftests/bpf: Add simple strscpy() implementation (Ihor Solodrai)\n- tools/testing: add linux/args.h header and fix radix, VMA tests (Lorenzo Stoakes)\n- dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() (Ivan Vecera) [Orabug: 39860212] {CVE-2026-68378}\n- Bluetooth: L2CAP: fix tx ident leak for commands without a response (Stig Hornang) {CVE-2026-72333}\n- Bluetooth: 6lowpan: Fix using chan-conn as indication to no remote netdev (Luiz Augusto von Dentz)\n- Bluetooth: L2CAP: Fix regressions caused by reusing ident (Luiz Augusto von Dentz)\n- crypto: ccp - Fix leaking the same page twice (Guenter Roeck)\n- ice: drop udp_tunnel_get_rx_info() call from ndo_open() (Mohammad Heib)\n- i40e: drop udp_tunnel_get_rx_info() call from i40e_open() (Mohammad Heib)\n- crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked() (Borislav Petkov) [Orabug: 39838809] {CVE-2025-39936}\n- Bluetooth: hci_sync: Fix attempting to send HCI_Disconnect to BIS handle (Luiz Augusto von Dentz)\n- Bluetooth: hci_core: Remove check of BDADDR_ANY in hci_conn_hash_lookup_big_state (Luiz Augusto von Dentz)\n- udp_tunnel: fix deadlock in udp_tunnel_nic_set_port_priv() (Paolo Abeni)\n- crypto: ccp - Fix SNP panic notifier unregistration (Ashish Kalra)\n- crypto: ccp - Fix dereferencing uninitialized error pointer (Ashish Kalra) [Orabug: 39838818] {CVE-2025-39729}\n- crypto: ccp - Fix __sev_snp_shutdown_locked (Ashish Kalra)\n- afs: Fix afs_dynroot_readdir() to not use the RCU read lock (David Howells)\n- afs: Fix afs_atcell_get_link() to check if ws_cell is unset first (David Howells)\n- net: airoha: Fix channel configuration for ETS Qdisc (Lorenzo Bianconi)\n- rtnetlink: Make per-netns RTNL dereference helpers to macro. (Kuniyuki Iwashima)\n- ksmbd: fix durable reconnect double-bind race in ksmbd_reopen_durable_fd (Gil Portnoy)\n- seqlock: fix scoped_seqlock_read kernel-doc (Randy Dunlap)\n- dibs: loopback: validate offset and size in move_data() (Dust Li) {CVE-2026-72018}\n- perf/x86/amd/brs: Fix kernel address leakage (Sandipan Das) {CVE-2026-72237}\n...","id":"ELSA-2026-500248","ovalId":"oval:com.oracle.elsa:def:2026500248","source":"oracle_linux","title":"ELSA-2026-500248: Unbreakable Enterprise kernel security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-500248.html"}