{"cves":["CVE-2024-14027","CVE-2024-58096","CVE-2024-58097","CVE-2025-10263","CVE-2025-21709","CVE-2025-21717","CVE-2025-21882","CVE-2025-22116","CVE-2025-38426","CVE-2025-38431","CVE-2025-38584","CVE-2025-39764","CVE-2025-39816","CVE-2025-39832","CVE-2025-39858","CVE-2025-39979","CVE-2025-40135","CVE-2025-40147","CVE-2025-40219","CVE-2025-54518","CVE-2025-68209","CVE-2025-68239","CVE-2025-68333","CVE-2025-68334","CVE-2025-68351","CVE-2025-68358","CVE-2025-68725","CVE-2025-68736","CVE-2025-68737","CVE-2025-71152","CVE-2025-71161","CVE-2025-71197","CVE-2025-71222","CVE-2025-71224","CVE-2025-71225","CVE-2025-71229","CVE-2025-71231","CVE-2025-71232","CVE-2025-71234","CVE-2025-71235","CVE-2025-71236","CVE-2025-71238","CVE-2025-71268","CVE-2025-71269","CVE-2025-71273","CVE-2025-71274","CVE-2025-71286","CVE-2025-71294","CVE-2025-71295","CVE-2025-71297","CVE-2025-71305","CVE-2026-22981","CVE-2026-22985","CVE-2026-22986","CVE-2026-22993","CVE-2026-23004","CVE-2026-23057","CVE-2026-23058","CVE-2026-23059","CVE-2026-23060","CVE-2026-23061","CVE-2026-23062","CVE-2026-23069","CVE-2026-23071","CVE-2026-23072","CVE-2026-23073","CVE-2026-23074","CVE-2026-23076","CVE-2026-23078","CVE-2026-23082","CVE-2026-23083","CVE-2026-23084","CVE-2026-23085","CVE-2026-23086","CVE-2026-23087","CVE-2026-23088","CVE-2026-23089","CVE-2026-23091","CVE-2026-23095","CVE-2026-23097","CVE-2026-23099","CVE-2026-23100","CVE-2026-23101","CVE-2026-23103","CVE-2026-23104","CVE-2026-23105","CVE-2026-23107","CVE-2026-23108","CVE-2026-23110","CVE-2026-23111","CVE-2026-23112","CVE-2026-23113","CVE-2026-23119","CVE-2026-23120","CVE-2026-23123","CVE-2026-23124","CVE-2026-23125","CVE-2026-23126","CVE-2026-23128","CVE-2026-23129","CVE-2026-23131","CVE-2026-23133","CVE-2026-23138","CVE-2026-23146","CVE-2026-23148","CVE-2026-23151","CVE-2026-23154","CVE-2026-23155","CVE-2026-23156","CVE-2026-23157","CVE-2026-23159","CVE-2026-23161","CVE-2026-23163","CVE-2026-23164","CVE-2026-23166","CVE-2026-23168","CVE-2026-23173","CVE-2026-23177","CVE-2026-23178","CVE-2026-23179","CVE-2026-23188","CVE-2026-23189","CVE-2026-23190","CVE-2026-23191","CVE-2026-23193","CVE-2026-23198","CVE-2026-23199","CVE-2026-23200","CVE-2026-23201","CVE-2026-23202","CVE-2026-23204","CVE-2026-23205","CVE-2026-23207","CVE-2026-23209","CVE-2026-23210","CVE-2026-23212","CVE-2026-23213","CVE-2026-23214","CVE-2026-23215","CVE-2026-23216","CVE-2026-23219","CVE-2026-23223","CVE-2026-23229","CVE-2026-23230","CVE-2026-23231","CVE-2026-23237","CVE-2026-23240","CVE-2026-23243","CVE-2026-23244","CVE-2026-23245","CVE-2026-23246","CVE-2026-23249","CVE-2026-23250","CVE-2026-23251","CVE-2026-23252","CVE-2026-23253","CVE-2026-23254","CVE-2026-23255","CVE-2026-23260","CVE-2026-23261","CVE-2026-23262","CVE-2026-23264","CVE-2026-23266","CVE-2026-23270","CVE-2026-23271","CVE-2026-23273","CVE-2026-23274","CVE-2026-23276","CVE-2026-23277","CVE-2026-23278","CVE-2026-23279","CVE-2026-23281","CVE-2026-23285","CVE-2026-23286","CVE-2026-23289","CVE-2026-23290","CVE-2026-23292","CVE-2026-23293","CVE-2026-23296","CVE-2026-23297","CVE-2026-23300","CVE-2026-23302","CVE-2026-23303","CVE-2026-23304","CVE-2026-23306","CVE-2026-23307","CVE-2026-23309","CVE-2026-23310","CVE-2026-23312","CVE-2026-23313","CVE-2026-23315","CVE-2026-23316","CVE-2026-23317","CVE-2026-23318","CVE-2026-23319","CVE-2026-23321","CVE-2026-23335","CVE-2026-23336","CVE-2026-23340","CVE-2026-23343","CVE-2026-23351","CVE-2026-23352","CVE-2026-23354","CVE-2026-23356","CVE-2026-23357","CVE-2026-23359","CVE-2026-23360","CVE-2026-23362","CVE-2026-23365","CVE-2026-23367","CVE-2026-23368","CVE-2026-23369","CVE-2026-23370","CVE-2026-23373","CVE-2026-23374","CVE-2026-23375","CVE-2026-23379","CVE-2026-23380","CVE-2026-23381","CVE-2026-23382","CVE-2026-23383","CVE-2026-23386","CVE-2026-23388","CVE-2026-23389","CVE-2026-23390","CVE-2026-23391","CVE-2026-23392","CVE-2026-23395","CVE-2026-23396","CVE-2026-23397","CVE-2026-23398","CVE-2026-23399","CVE-2026-23401","CVE-2026-23412","CVE-2026-23413","CVE-2026-23414","CVE-2026-23417","CVE-2026-23420","CVE-2026-23434","CVE-2026-23438","CVE-2026-23439","CVE-2026-23440","CVE-2026-23441","CVE-2026-23442","CVE-2026-23443","CVE-2026-23444","CVE-2026-23445","CVE-2026-23447","CVE-2026-23448","CVE-2026-23449","CVE-2026-23452","CVE-2026-23454","CVE-2026-23455","CVE-2026-23456","CVE-2026-23457","CVE-2026-23458","CVE-2026-23461","CVE-2026-23462","CVE-2026-23465","CVE-2026-23468","CVE-2026-23473","CVE-2026-23474","CVE-2026-23475","CVE-2026-31389","CVE-2026-31392","CVE-2026-31393","CVE-2026-31394","CVE-2026-31396","CVE-2026-31399","CVE-2026-31400","CVE-2026-31402","CVE-2026-31403","CVE-2026-31405","CVE-2026-31406","CVE-2026-31407","CVE-2026-31408","CVE-2026-31411","CVE-2026-31413","CVE-2026-31414","CVE-2026-31415","CVE-2026-31416","CVE-2026-31418","CVE-2026-31419","CVE-2026-31421","CVE-2026-31422","CVE-2026-31423","CVE-2026-31424","CVE-2026-31426","CVE-2026-31427","CVE-2026-31428","CVE-2026-31429","CVE-2026-31430","CVE-2026-31431","CVE-2026-31434","CVE-2026-31436","CVE-2026-31438","CVE-2026-31440","CVE-2026-31441","CVE-2026-31446","CVE-2026-31447","CVE-2026-31448","CVE-2026-31449","CVE-2026-31450","CVE-2026-31451","CVE-2026-31452","CVE-2026-31453","CVE-2026-31454","CVE-2026-31455","CVE-2026-31456","CVE-2026-31458","CVE-2026-31462","CVE-2026-31466","CVE-2026-31467","CVE-2026-31469","CVE-2026-31470","CVE-2026-31473","CVE-2026-31474","CVE-2026-31479","CVE-2026-31480","CVE-2026-31487","CVE-2026-31488","CVE-2026-31489","CVE-2026-31492","CVE-2026-31494","CVE-2026-31495","CVE-2026-31496","CVE-2026-31497","CVE-2026-31498","CVE-2026-31500","CVE-2026-31503","CVE-2026-31504","CVE-2026-31505","CVE-2026-31506","CVE-2026-31508","CVE-2026-31510","CVE-2026-31511","CVE-2026-31512","CVE-2026-31513","CVE-2026-31514","CVE-2026-31515","CVE-2026-31516","CVE-2026-31518","CVE-2026-31519","CVE-2026-31520","CVE-2026-31521","CVE-2026-31522","CVE-2026-31523","CVE-2026-31524","CVE-2026-31525","CVE-2026-31527","CVE-2026-31528","CVE-2026-31530","CVE-2026-31531","CVE-2026-31532","CVE-2026-31533","CVE-2026-31540","CVE-2026-31542","CVE-2026-31546","CVE-2026-31548","CVE-2026-31550","CVE-2026-31551","CVE-2026-31552","CVE-2026-31554","CVE-2026-31555","CVE-2026-31556","CVE-2026-31557","CVE-2026-31561","CVE-2026-31563","CVE-2026-31565","CVE-2026-31566","CVE-2026-31570","CVE-2026-31575","CVE-2026-31578","CVE-2026-31580","CVE-2026-31581","CVE-2026-31583","CVE-2026-31586","CVE-2026-31588","CVE-2026-31590","CVE-2026-31593","CVE-2026-31596","CVE-2026-31597","CVE-2026-31598","CVE-2026-31602","CVE-2026-31604","CVE-2026-31607","CVE-2026-31614","CVE-2026-31624","CVE-2026-31625","CVE-2026-31628","CVE-2026-31634","CVE-2026-31638","CVE-2026-31639","CVE-2026-31642","CVE-2026-31647","CVE-2026-31648","CVE-2026-31649","CVE-2026-31651","CVE-2026-31656","CVE-2026-31657","CVE-2026-31658","CVE-2026-31659","CVE-2026-31661","CVE-2026-31662","CVE-2026-31664","CVE-2026-31665","CVE-2026-31666","CVE-2026-31667","CVE-2026-31668","CVE-2026-31669","CVE-2026-31670","CVE-2026-31671","CVE-2026-31672","CVE-2026-31673","CVE-2026-31674","CVE-2026-31675","CVE-2026-31676","CVE-2026-31677","CVE-2026-31678","CVE-2026-31679","CVE-2026-31680","CVE-2026-31681","CVE-2026-31682","CVE-2026-31683","CVE-2026-31684","CVE-2026-31685","CVE-2026-31688","CVE-2026-31689","CVE-2026-31693","CVE-2026-31694","CVE-2026-31696","CVE-2026-31697","CVE-2026-31698","CVE-2026-31699","CVE-2026-31700","CVE-2026-31701","CVE-2026-31708","CVE-2026-31709","CVE-2026-31729","CVE-2026-31731","CVE-2026-31733","CVE-2026-31738","CVE-2026-31752","CVE-2026-31758","CVE-2026-31759","CVE-2026-31761","CVE-2026-31762","CVE-2026-31763","CVE-2026-31765","CVE-2026-31767","CVE-2026-31772","CVE-2026-31773","CVE-2026-31774","CVE-2026-31776","CVE-2026-31778","CVE-2026-31779","CVE-2026-31781","CVE-2026-31786","CVE-2026-31787","CVE-2026-31788","CVE-2026-43012","CVE-2026-43013","CVE-2026-43014","CVE-2026-43015","CVE-2026-43016","CVE-2026-43017","CVE-2026-43018","CVE-2026-43019","CVE-2026-43020","CVE-2026-43023","CVE-2026-43024","CVE-2026-43025","CVE-2026-43026","CVE-2026-43027","CVE-2026-43028","CVE-2026-43030","CVE-2026-43033","CVE-2026-43035","CVE-2026-43036","CVE-2026-43037","CVE-2026-43038","CVE-2026-43040","CVE-2026-43041","CVE-2026-43043","CVE-2026-43046","CVE-2026-43047","CVE-2026-43049","CVE-2026-43050","CVE-2026-43051","CVE-2026-43052","CVE-2026-43054","CVE-2026-43056","CVE-2026-43057","CVE-2026-43059","CVE-2026-43060","CVE-2026-43061","CVE-2026-43062","CVE-2026-43063","CVE-2026-43064","CVE-2026-43065","CVE-2026-43066","CVE-2026-43068","CVE-2026-43069","CVE-2026-43071","CVE-2026-43072","CVE-2026-43073","CVE-2026-43074","CVE-2026-43075","CVE-2026-43076","CVE-2026-43077","CVE-2026-43078","CVE-2026-43079","CVE-2026-43080","CVE-2026-43084","CVE-2026-43085","CVE-2026-43086","CVE-2026-43089","CVE-2026-43090","CVE-2026-43091","CVE-2026-43092","CVE-2026-43093","CVE-2026-43094","CVE-2026-43099","CVE-2026-43104","CVE-2026-43105","CVE-2026-43107","CVE-2026-43110","CVE-2026-43111","CVE-2026-43112","CVE-2026-43113","CVE-2026-43114","CVE-2026-43117","CVE-2026-43119","CVE-2026-43120","CVE-2026-43123","CVE-2026-43124","CVE-2026-43125","CVE-2026-43126","CVE-2026-43128","CVE-2026-43129","CVE-2026-43130","CVE-2026-43132","CVE-2026-43133","CVE-2026-43134","CVE-2026-43135","CVE-2026-43136","CVE-2026-43137","CVE-2026-43139","CVE-2026-43140","CVE-2026-43143","CVE-2026-43147","CVE-2026-43150","CVE-2026-43152","CVE-2026-43153","CVE-2026-43156","CVE-2026-43158","CVE-2026-43161","CVE-2026-43163","CVE-2026-43167","CVE-2026-43168","CVE-2026-43169","CVE-2026-43170","CVE-2026-43171","CVE-2026-43177","CVE-2026-43178","CVE-2026-43180","CVE-2026-43186","CVE-2026-43187","CVE-2026-43189","CVE-2026-43190","CVE-2026-43194","CVE-2026-43199","CVE-2026-43201","CVE-2026-43206","CVE-2026-43210","CVE-2026-43211","CVE-2026-43214","CVE-2026-43215","CVE-2026-43218","CVE-2026-43220","CVE-2026-43223","CVE-2026-43231","CVE-2026-43233","CVE-2026-43238","CVE-2026-43239","CVE-2026-43243","CVE-2026-43246","CVE-2026-43248","CVE-2026-43251","CVE-2026-43252","CVE-2026-43253","CVE-2026-43255","CVE-2026-43257","CVE-2026-43260","CVE-2026-43261","CVE-2026-43262","CVE-2026-43264","CVE-2026-43265","CVE-2026-43266","CVE-2026-43271","CVE-2026-43273","CVE-2026-43275","CVE-2026-43277","CVE-2026-43278","CVE-2026-43279","CVE-2026-43281","CVE-2026-43284","CVE-2026-43287","CVE-2026-43288","CVE-2026-43289","CVE-2026-43292","CVE-2026-43304","CVE-2026-43306","CVE-2026-43313","CVE-2026-43314","CVE-2026-43315","CVE-2026-43316","CVE-2026-43318","CVE-2026-43319","CVE-2026-43320","CVE-2026-43328","CVE-2026-43329","CVE-2026-43332","CVE-2026-43333","CVE-2026-43334","CVE-2026-43336","CVE-2026-43338","CVE-2026-43339","CVE-2026-43341","CVE-2026-43350","CVE-2026-43357","CVE-2026-43359","CVE-2026-43360","CVE-2026-43361","CVE-2026-43362","CVE-2026-43363","CVE-2026-43365","CVE-2026-43366","CVE-2026-43368","CVE-2026-43370","CVE-2026-43371","CVE-2026-43374","CVE-2026-43381","CVE-2026-43382","CVE-2026-43383","CVE-2026-43392","CVE-2026-43393","CVE-2026-43394","CVE-2026-43395","CVE-2026-43397","CVE-2026-43403","CVE-2026-43405","CVE-2026-43406","CVE-2026-43407","CVE-2026-43408","CVE-2026-43409","CVE-2026-43411","CVE-2026-43413","CVE-2026-43415","CVE-2026-43419","CVE-2026-43420","CVE-2026-43425","CVE-2026-43427","CVE-2026-43428","CVE-2026-43429","CVE-2026-43430","CVE-2026-43432","CVE-2026-43436","CVE-2026-43437","CVE-2026-43438","CVE-2026-43439","CVE-2026-43441","CVE-2026-43444","CVE-2026-43445","CVE-2026-43448","CVE-2026-43449","CVE-2026-43450","CVE-2026-43451","CVE-2026-43452","CVE-2026-43453","CVE-2026-43456","CVE-2026-43459","CVE-2026-43466","CVE-2026-43468","CVE-2026-43469","CVE-2026-43470","CVE-2026-43471","CVE-2026-43472","CVE-2026-43473","CVE-2026-43475","CVE-2026-43482","CVE-2026-43483","CVE-2026-43484","CVE-2026-43486","CVE-2026-43487","CVE-2026-43488","CVE-2026-43491","CVE-2026-43493","CVE-2026-43499","CVE-2026-43500","CVE-2026-43501","CVE-2026-43503","CVE-2026-45847","CVE-2026-45851","CVE-2026-45852","CVE-2026-45853","CVE-2026-45855","CVE-2026-45856","CVE-2026-45857","CVE-2026-45858","CVE-2026-45859","CVE-2026-45860","CVE-2026-45861","CVE-2026-45862","CVE-2026-45868","CVE-2026-45870","CVE-2026-45871","CVE-2026-45872","CVE-2026-45873","CVE-2026-45877","CVE-2026-45878","CVE-2026-45886","CVE-2026-45888","CVE-2026-45890","CVE-2026-45892","CVE-2026-45894","CVE-2026-45895","CVE-2026-45898","CVE-2026-45899","CVE-2026-45905","CVE-2026-45910","CVE-2026-45912","CVE-2026-45913","CVE-2026-45914","CVE-2026-45915","CVE-2026-45916","CVE-2026-45917","CVE-2026-45919","CVE-2026-45920","CVE-2026-45922","CVE-2026-45923","CVE-2026-45925","CVE-2026-45933","CVE-2026-45941","CVE-2026-45942","CVE-2026-45943","CVE-2026-45947","CVE-2026-45948","CVE-2026-45949","CVE-2026-45957","CVE-2026-45962","CVE-2026-45964","CVE-2026-45968","CVE-2026-45970","CVE-2026-45972","CVE-2026-45973","CVE-2026-45974","CVE-2026-45976","CVE-2026-45982","CVE-2026-45983","CVE-2026-45984","CVE-2026-45985","CVE-2026-45987","CVE-2026-45988","CVE-2026-45992","CVE-2026-45997","CVE-2026-45998","CVE-2026-46000","CVE-2026-46002","CVE-2026-46003","CVE-2026-46004","CVE-2026-46005","CVE-2026-46006","CVE-2026-46015","CVE-2026-46018","CVE-2026-46021","CVE-2026-46023","CVE-2026-46024","CVE-2026-46026","CVE-2026-46028","CVE-2026-46033","CVE-2026-46037","CVE-2026-46038","CVE-2026-46040","CVE-2026-46043","CVE-2026-46046","CVE-2026-46047","CVE-2026-46048","CVE-2026-46049","CVE-2026-46050","CVE-2026-46051","CVE-2026-46052","CVE-2026-46056","CVE-2026-46061","CVE-2026-46069","CVE-2026-46070","CVE-2026-46076","CVE-2026-46078","CVE-2026-46079","CVE-2026-46080","CVE-2026-46082","CVE-2026-46083","CVE-2026-46084","CVE-2026-46085","CVE-2026-46086","CVE-2026-46088","CVE-2026-46089","CVE-2026-46091","CVE-2026-46092","CVE-2026-46094","CVE-2026-46099","CVE-2026-46101","CVE-2026-46102","CVE-2026-46109","CVE-2026-46165","CVE-2026-46242","CVE-2026-46243","CVE-2026-46300","CVE-2026-46331","CVE-2026-46333","CVE-2026-52943","CVE-2026-53359"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[6.12.0-204.92.4.2]\n- KVM: x86: Fix shadow paging use-after-free due to unexpected role (Paolo Bonzini)  [Orabug: 39673880] \n- net/sched: fix pedit partial COW leading to page cache corruption (Rajat Gupta)   {CVE-2026-46331}\n- net_sched: act_pedit: use RCU in tcf_pedit_dump() (Eric Dumazet)  [Orabug: 39668752] \n- eventpoll: fix ep_remove struct eventpoll / struct file UAF (Christian Brauner)  [Orabug: 39668743]  {CVE-2026-46242}\n- eventpoll: move epi_fget() up (Christian Brauner)  [Orabug: 39668743] \n- eventpoll: rename ep_remove_safe() back to ep_remove() (Christian Brauner)  [Orabug: 39668743] \n- eventpoll: drop vestigial __ prefix from ep_remove_{file,epi}() (Christian Brauner)  [Orabug: 39668743] \n- eventpoll: kill __ep_remove() (Christian Brauner)  [Orabug: 39668743] \n- eventpoll: split __ep_remove() (Christian Brauner)  [Orabug: 39668743] \n- eventpoll: use hlist_is_singular_node() in __ep_remove() (Christian Brauner)  [Orabug: 39668743]\n\n[6.12.0-204.92.4.1]\n- net: skbuff: fix missing zerocopy reference in pskb_carve helpers (Minh Nguyen)  [Orabug: 39656679]  {CVE-2026-52943}\n- md: fix array_state=clear sysfs deadlock (Yu Kuai)  [Orabug: 39656688]\n- md: fix return value of mddev_trylock (Xiao Ni)  [Orabug: 39656688]\n- md: avoid repeated calls to del_gendisk (Xiao Ni)  [Orabug: 39656688]\n- md: delete mddev kobj before deleting gendisk kobj (Xiao Ni)  [Orabug: 39656688]\n- md: add legacy_async_del_gendisk mode (Xiao Ni)  [Orabug: 39656688]\n- md: fix create on open mddev lifetime regression (Yu Kuai)  [Orabug: 39656688]\n- md: Don't clear MD_CLOSING until mddev is freed (Xiao Ni)  [Orabug: 39656688]\n- md: call del_gendisk in control path (Xiao Ni)  [Orabug: 39656688]\n\n[6.12.0-204.92.4]\n- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland)  [Orabug: 39548792]  {CVE-2025-10263}\n- arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland)  [Orabug: 39548792]\n- arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland)  [Orabug: 39548792]\n- arm64: cputype: Add C1-Premium definitions (Mark Rutland)  [Orabug: 39548792]\n- arm64: cputype: Add C1-Ultra definitions (Mark Rutland)  [Orabug: 39548792]\n- net/rds: Make 'rds_send_xmit' fairer (Gerd Rausch)  [Orabug: 38144694]\n- net/rds: Schedule rds_send_worker if there's more work to do (Gerd Rausch)  [Orabug: 38144694]\n- Revert 'rds: Change return code from rds_send_xmit() when lock is taken' (Gerd Rausch)  [Orabug: 38144694]\n- vfio/type1: optimize vfio_unpin_pages_remote() (Li Zhe)  [Orabug: 39058056]\n- vfio/type1: introduce a new member has_rsvd for struct vfio_dma (Li Zhe)  [Orabug: 39058056]\n- vfio/type1: batch vfio_find_vpfn() in function vfio_unpin_pages_remote() (Li Zhe)  [Orabug: 39058056]\n- vfio/type1: optimize vfio_pin_pages_remote() (Li Zhe)  [Orabug: 39058056]\n- mm: introduce num_pages_contiguous() (Li Zhe)  [Orabug: 39058056]\n- vfio/type1: Use mapping page mask for pfnmaps (Alex Williamson)  [Orabug: 39058056]\n- mm: Provide address mask in struct follow_pfnmap_args (Alex Williamson)  [Orabug: 39058056]\n- vfio/type1: Use consistent types for page counts (Alex Williamson)  [Orabug: 39058056]\n- vfio/type1: Use vfio_batch for vaddr_get_pfns() (Alex Williamson)  [Orabug: 39058056]\n- vfio/type1: Convert all vaddr_get_pfns() callers to use vfio_batch (Alex Williamson)  [Orabug: 39058056]\n- vfio/type1: Catch zero from pin_user_pages_remote() (Alex Williamson)  [Orabug: 39058056]\n- rds: Drop rds conn in connect worker if not in down state. (Rohit Nair)  [Orabug: 39179362]\n- mmc: dwcmshc_bf3_hw_reset: Log eMMC reset calls (Satyansh Shukla)  [Orabug: 39341694]\n- net: lan743x: rename chip_rev to fpga_rev (Thangaraj Samynathan)  [Orabug: 39369482]\n- net: lan743x: fix SGMII detection on PCI1xxxx B0+ during warm reset (Thangaraj Samynathan)  [Orabug: 39369482]\n- net: microchip: lan743x: add ethtool nway_reset support (Nicolai Buchwitz)  [Orabug: 39369482]\n- net: lan743x: implement ndo_hwtstamp_get() (Vladimir Oltean)  [Orabug: 39369482]\n- net: lan743x: convert to ndo_hwtstamp_set() (Vladimir Oltean)  [Orabug: 39369482]\n- net: lan743x: use netdev in lan743x_phylink_mac_link_down() (Russell King (Oracle))  [Orabug: 39369482]\n- net/rds: Add parentheses around conditional operator (Gerd Rausch)  [Orabug: 39399490]\n- uek-rpm: avoid final module link in early FIPS symvers pass (Sherry Yang)  [Orabug: 39454846]\n- net/ethernet/pensando: Add out-of-tree network drivers (Joseph Dobosenski)  [Orabug: 39479413]\n- ima: kexec: move IMA log copy from kexec load to execute (Steven Chen)  [Orabug: 39517375]\n- ima: kexec: skip IMA segment validation after kexec soft reboot (Steven Chen)  [Orabug: 39517375]\n- rxrpc: Fix RESPONSE packet verification to extract skb to a linear buffer (David Howells)\n- rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg (David Howells)\n- drm/amd/pm/si: Disregard vblank time when no displays are connected (Timur Kristof)\n- USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (Wanquan Zhong)\n- ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops (Ali Ganiyev)\n- USB: cdc-acm: Fix bit overlap and move quirk definitions to header (Wentao Guan)\n- media: rc: igorplugusb: fix control request setup packet (Henri A)\n- media: rc: ttusbir: fix inverted error logic (Oliver Neukum)\n- media: rc: fix race between unregister and urb/irq callbacks (Sean Young)\n- nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems (Carl Lee)\n- bcache: fix uninitialized closure object (Mingzhe Zou)\n- xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit (Usama Arif)\n- net/sched: cls_fw: fix NULL dereference of 'old' filters before change() (Davide Caratti)\n- LTS version: v6.12.92 (Saeed Mirzamohammadi)\n- security/keys: fix missed RCU read section on lookup (Linus Torvalds)\n- landlock: Fix TCP handling of short AF_UNSPEC addresses (Matthieu Buffet)\n- LoongArch: kprobes: Fix handling of fatal unrecoverable recursions (Tiezhu Yang)\n- net: gro: don't merge zcopy skbs (Sabrina Dubroca)\n- pds_core: ensure null-termination for firmware version strings (Nikhil P. Rao)\n- net: mana: validate rx_req_idx to prevent out-of-bounds array access (Aditya Garg)\n- octeontx2-af: npc: Fix allmulticast skip logic for LBK and SDP VFs (Ratheesh Kannoth)\n- drm/xe/oa: Fix exec_queue leak on width check in stream open (Shuicheng Lin)\n- ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (Richard Fitzgerald)\n- gpio: cdev: check if uAPI v2 config attributes are correctly zeroed (Bartosz Golaszewski)\n- gpiolib: cdev: use !mem_is_zero() instead of memchr_inv(s, 0, n) (Andy Shevchenko)\n- bpf, skmsg: fix verdict sk_data_ready racing with ktls rx (Xingwang Xiang)\n- net: ag71xx: check error for platform_get_irq (Rosen Penev)\n- Bluetooth: btmtk: fix urb-setup_packet leak in error paths (Jiajia Liu)\n- tracing: Avoid NULL return from hist_field_name() on truncation (David Carlier)\n- ALSA: seq: Serialize UMP output teardown with event_input (Zhang Cen)\n- wifi: mac80211: fix MLE defragmentation (Johannes Berg)\n- pds_core: fix debugfs_lookup dentry leak and error handling (Nikhil P. Rao)\n- pds_core: fix error handling in pdsc_devcmd_wait (Nikhil P. Rao)\n- bridge: mcast: Fix a possible use-after-free when removing a bridge port (Ido Schimmel)\n- net: bridge: Flush multicast groups when snooping is disabled (Petr Machata)\n- RDMA/rtrs: Fix use-after-free in path file creation cleanup (Guangshuo Li)\n- platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki)\n- platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki)\n- platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (Rafael J. Wysocki)\n- platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki)\n- platform/surface: aggregator_registry: omit battery  AC nodes on Surface Laptop 7 (Oliver White)\n- net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (Erni Sri Satya Vennela)\n- net: dsa: mt7530: preserve VLAN tags on trapped link-local frames (Daniel Golle)\n- net: dsa: mt7530: fix FDB entries not aging out with short timeout (Daniel Golle)\n- kbuild: pacman-pkg: make 'rc' releases adhere to pacman versioning scheme (Viktor Jagerskupper)\n- drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (Ankit Nautiyal)\n- ice: ptp: serialize E825 PHY timer start with PTP lock (Grzegorz Nitka)\n- wifi: ath11k: fix peer resolution on rx path when peer_id=0 (Matthew Leach)\n- drm/xe/pf: Fix CFI failure in debugfs access (Mohanram Meenakshisundaram)\n- drm/xe/vf: Fix signature of print functions (Michal Wajdeczko)\n- drm/xe/gsc: Fix double-free of managed BO in error path (Shuicheng Lin)\n- drm/msm/snapshot: fix dumping of the unaligned regions (Dmitry Baryshkov)\n- spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (Felix Gu)\n- btrfs: fix squota accounting during enable generation (Boris Burkov)\n- io_uring/net: punt IORING_OP_BIND async if it needs file create (Jens Axboe)\n- ALSA: scarlett2: Add missing error check when initialise Autogain Status (Robertus Diawan Chris)\n- scsi: sd: Fix return code handling in sd_spinup_disk() (Mike Christie)\n- net/mlx5: Do not restore destination-less TC rules (Jeroen Massar)\n- tls: Preserve sk_err across recvmsg() when data has been copied (Chuck Lever)\n- x86/xen: Fix xen_e820_swap_entry_with_ram() (Juergen Gross)\n- net: phy: DP83TC811: add reading of abilities (Sven Schuchmann)\n- net: tls: prevent chain-after-chain in plain text SG (Jakub Kicinski)\n- net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (Jakub Kicinski)\n- net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (Xiang Mei)\n- powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() (Sayali Patil)\n- drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN (Mikko Perttunen)\n- drm/msm/dsi: don't dump registers past the mapped region (Dmitry Baryshkov)\n- ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics (Chenguang Zhao)\n- net/smc: avoid NULL deref of conn-lnk in smc_msg_event tracepoint (Xiang Mei)\n- accel/qaic: Add overflow check to remap_pfn_range during mmap (Zack McKevitt)\n- block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() (Sungwoo Kim)\n- blk-integrity: enable p2p source and destination (Keith Busch)\n- blk-integrity: use simpler alignment check (Keith Busch)\n- block: drop direction param from bio_integrity_copy_user() (Caleb Sander Mateos)\n- HID: quirks: really enable the intended work around for appledisplay (Lukas Bulwahn)\n- block: recompute nr_integrity_segments in blk_insert_cloned_request (Casey Chen)\n- block: don't overwrite bip_vcnt in bio_integrity_copy_user() (David Carlier)\n- wifi: ath10k: skip WMI and beacon transmission when device is wedged (Kang Yang)\n- wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (Nicolas Escande)\n- wifi: ath11k: fix error path leaks in some WMI WOW calls (Nicolas Escande)\n- net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference (Ethan Nelson-Moore)\n- net: ethernet: cortina: Carry over frag counter (Linus Walleij)\n- net: ethernet: cortina: Drop half-assembled SKB (Andreas Haarmann-Thiemann)\n- net: ethernet: cortina: Make RX SKB per-port (Linus Walleij)\n- netfs: Fix folio-private handling in netfs_perform_write() (David Howells)\n- netfs: Remove unnecessary references to pages (Matthew Wilcox (Oracle))\n- netfs: Fix a few minor bugs in netfs_page_mkwrite() (Matthew Wilcox (Oracle))\n- netfs: Fix partial invalidation of streaming-write folio (David Howells)\n- netfs: Fix early put of sink folio in netfs_read_gaps() (David Howells)\n- netfs: Fix write streaming disablement if fd open O_RDWR (David Howells)\n- netfs: Fix potential deadlock in write-through mode (David Howells)\n- netfs: Fix streaming write being overwritten (David Howells)\n- netfs: Defer the emission of trace_netfs_folio() (David Howells)\n- netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone (David Howells)\n- netfs: Fix overrun check in netfs_extract_user_iter() (David Howells)\n- netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call (Viacheslav Dubeyko)\n- powerpc: fix dead default for GUEST_STATE_BUFFER_TEST (Julian Braha)\n- tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key(). (Kuniyuki Iwashima)\n- zonefs: handle integer overflow in zonefs_fname_to_fno (Johannes Thumshirn)\n- irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT (Jiayuan Chen)\n- nsfs: fix wrong error code returned for pidns ioctls (Zhihao Cheng)\n- ublk: reject max_sectors smaller than PAGE_SECTORS in parameter validation (Ming Lei)\n- irqchip/ath79-cpu: Remove unused function (Rosen Penev)\n- NFSD: Fix infinite loop in layout state revocation (Chuck Lever)\n- phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access (Gabor Juhos)\n- net: lan966x: avoid unregistering netdev on register failure (Myeonghun Pak)\n- ice: fix locking in ice_dcb_rebuild() (Bart Van Assche)\n- ice: fix setting RSS VSI hash for E830 (Marcin Szycik)\n- tcp: Fix imbalanced icsk_accept_queue count. (Kuniyuki Iwashima)\n- test_kprobes: clear kprobes between test runs (Martin Kaiser)\n- kprobes: skip non-symbol addresses in kprobe_add_ksym_blacklist() (Jianpeng Chang)\n- netfilter: x_tables: unregister the templates first (Florian Westphal)\n- ALSA: hda: cs35l41: Put ACPI device on missing physical node (Shuhao Fu)\n- ALSA: hda: cs35l56: Put ACPI device after setting companion (Shuhao Fu)\n- ARM: integrator: Fix early initialization (Guenter Roeck)\n- firmware: arm_ffa: Fix sched-recv callback partition lookup (Sudeep Holla)\n- firmware: arm_ffa: Align RxTx buffer size before mapping (Sudeep Holla)\n- pinctrl: qcom: Fix wakeirq map by removing disconnected irqs for sm8150 (Maulik Shah)\n- kunit: config: KUNIT_DEBUGFS should depend on DEBUG_FS (David Gow)\n- kunit: config: Enable KUNIT_DEBUGFS by default (David Gow)\n- riscv: mm: Fixup no5lvl failure when vaddr is invalid (Guo Ren (Alibaba DAMO Academy))\n- firmware: arm_ffa: Unregister bus notifier on teardown for FF-A v1.0 (Sudeep Holla)\n- firmware: arm_ffa: Allow multiple UUIDs per partition to register SRI callback (Sudeep Holla)\n- firmware: arm_ffa: Remove unnecessary declaration of ffa_partitions_cleanup() (Sudeep Holla)\n- firmware: arm_ffa: Unregister the FF-A devices when cleaning up the partitions (Sudeep Holla)\n- firmware: arm_ffa: Refactor addition of partition information into XArray (Viresh Kumar)\n- firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (Sudeep Holla)\n- firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (Sudeep Holla)\n- firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (Sudeep Holla)\n- HID: uclogic: Fix regression of input name assignment (Takashi Iwai)\n- pinctrl: renesas: rzg2l: Fix incorrect PUPD register offset for high pins during suspend/resume (Biju Das)\n- ARM: dts: renesas: rskrza1: Drop superfluous cells (Marek Vasut)\n- ARM: dts: renesas: genmai: Drop superfluous cells (Marek Vasut)\n- hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (Abdurrahman Hussain)\n- hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (Abdurrahman Hussain)\n- hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (Abdurrahman Hussain)\n- hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (Abdurrahman Hussain)\n- hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (Abdurrahman Hussain)\n- hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (Abdurrahman Hussain)\n- hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (Abdurrahman Hussain)\n- hwmon: (pmbus/adm1266) reject implausible blackbox record_count (Abdurrahman Hussain)\n- hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (Abdurrahman Hussain)\n- batman-adv: tt: fix negative tt_buff_len (Sven Eckelmann)\n- batman-adv: tt: fix negative last_changeset_len (Sven Eckelmann)\n- batman-adv: tp_meter: fix race condition in send error reporting (Sven Eckelmann)\n- batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown (Sven Eckelmann)\n- batman-adv: tp_meter: avoid use of uninit sender vars (Sven Eckelmann)\n- batman-adv: bla: fix report_work leak on backbone_gw purge (Sven Eckelmann)\n- batman-adv: frag: disallow unicast fragment in fragment (Sven Eckelmann)\n- batman-adv: fix tp_meter counter underflow during shutdown (Luxiao Xu)\n- batman-adv: fix fragment reassembly length accounting (Ruide Cao)\n- batman-adv: dat: handle forward allocation error (Sven Eckelmann)\n- batman-adv: clear current gateway during teardown (Ruijie Li)\n- batman-adv: mcast: fix use-after-free in orig_node RCU release (Sven Eckelmann)\n- drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (Harry Wentland)\n- drm/amd/display: Validate GPIO pin LUT table size before iterating (Harry Wentland)\n- drm/amd/display: Fix integer overflow in bios_get_image() (Harry Wentland)\n- drm/bridge: megachips: remove bridge when irq request fails (Osama Abdelkader)\n- drm/bridge: it66121: acquire reset GPIO in probe (Julien Chauveau)\n- drm/amdgpu/vpe: Force collaborate sync after TRAP (Alan Liu)\n- drm/virtio: use uninterruptible resv lock for plane updates (Deepanshu Kartikey)\n- device property: set fwnode-secondary to NULL in fwnode_init() (Bartosz Golaszewski)\n- LoongArch: Remove unused code to avoid build warning (Huacai Chen)\n- RDMA/siw: Reject MPA FPDU length underflow before signed receive math (Michael Bommarito)\n- spi: ti-qspi: fix use-after-free after DMA setup failure (Johan Hovold)\n- spi: sprd: fix error pointer deref after DMA setup failure (Johan Hovold)\n- spi: ep93xx: fix error pointer deref after DMA setup failure (Johan Hovold)\n- scsi: isci: Fix use-after-free in device removal path (Michael Bommarito)\n- phy: tegra: xusb: Fix per-pad high-speed termination calibration (Wayne Chang)\n- spi: qup: fix error pointer deref after DMA setup failure (Johan Hovold)\n- drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (Osama Abdelkader)\n- riscv: kvm: return SBI_ERR_FAILURE for pmu_snapshot_set_shmem() when OOM (Osama Abdelkader)\n- KVM: arm64: vgic: Free private_irqs when init fails after allocation (Michael Bommarito)\n- KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (Michael Bommarito)\n- arm64: probes: Handle probes on hinted conditional branch instructions (Vladimir Murzin)\n- tracing: Do not call map-ops-elt_free() if elt_alloc() fails (Masami Hiramatsu (Google))\n- wifi: mac80211: consume only present negotiated TTLM maps (Michael Bommarito)\n- af_unix: Fix UAF read of tail-len in unix_stream_data_wait() (Jann Horn)\n- wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (John Walker)\n- ice: restore PTP Rx timestamp config after ethtool set-channels (Grzegorz Nitka)\n- ice: fix setting promisc mode while adding VID filter (Marcin Szycik)\n- octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (Sam Daly)\n- lsm: hold cred_guard_mutex for lsm_set_self_attr() (Stephen Smalley)\n- rbd: eliminate a race in lock_dwork draining on unmap (Ilya Dryomov)\n- ixgbevf: fix use-after-free in VEPA multicast source pruning (Michael Bommarito)\n- ipv4: raw: reject IP_HDRINCL packets with ihl  5 (Michael Bommarito)\n- wifi: ath11k: clear shared SRNG pointer state on restart (Kyle Farnung)\n- vsock/virtio: reset connection on receiving queue overflow (Stefano Garzarella)\n- vsock/vmci: fix UAF when peer resets connection during handshake (Minh Nguyen)\n- ipv6: ioam: add NULL check for idev in ipv6_hop_ioam() (Justin Iurman)\n- ring-buffer: Fix reporting of missed events in iterator (Steven Rostedt)\n- qed: fix double free in qed_cxt_tables_alloc() (Dawei Feng)\n- l2tp: use list_del_rcu in l2tp_session_unhash (Michael Bommarito)\n- fs/ntfs3: handle attr_set_size() errors when truncating files (Konstantin Komarov)\n- cgroup/cpuset: Reset DL migration state on can_attach() failure (Guopeng Zhang)\n- sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path (Tejun Heo)\n- sched_ext: Fix missing warning in scx_set_task_state() default case (Samuele Mariotti)\n- netfilter: nft_inner: Fix IPv6 inner_thoff desync (Yizhou Zhao)\n- netfilter: ipset: stop hash:* range iteration at end (Nan Li)\n- netfilter: nf_queue: hold bridge skb-dev while queued (Haoze Xie)\n- netfilter: ip6t_hbh: reject oversized option lists (Zhengchuan Liang)\n- net: pse-pd: fix sign on -ENOENT check in of_load_pse_pis() (Jonas Jelonek)\n- net: ifb: report ethtool stats over num_tx_queues (Michael Bommarito)\n- net: bcmgenet: keep RBUF EEE/PM disabled (Nicolai Buchwitz)\n- phonet/pep: disable BH around forwarded sk_receive_skb() (Zijing Yin)\n- Bluetooth: serialize accept_q access (Jiexun Wang)\n- Bluetooth: MGMT: validate Add Extended Advertising Data length (Michael Bommarito)\n- Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (Michael Bommarito)\n- Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (Mingyu Wang)\n- Bluetooth: bnep: Fix UAF read of dev-name (Jann Horn)\n- Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (David Carlier)\n- Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (Safa Karakus)\n- net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (Abdun Nihaal)\n- selftests/mm: run_vmtests.sh: fix destructive tests invocation (Luiz Capitulino)\n- mm/memory_hotplug: fix memory block reference leak on remove (Muchun Song)\n- ipv6: ioam: refresh hdr pointer before ioam6_event() (Justin Iurman)\n- drivers/base/memory: fix memory block reference leak in poison accounting (Muchun Song)\n- io_uring/waitid: clear waitid info before copying it to userspace (Heechan Kang)\n- efi: Allocate runtime workqueue before ACPI init (Ard Biesheuvel)\n- ALSA: asihpi: Fix potential OOB array access at reading cache (Takashi Iwai)\n- ALSA: pcm: Don't setup bogus iov_iter for silencing (Takashi Iwai)\n- ALSA: ua101: Reject too-short USB descriptors (Cassio Gabriel)\n- hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (Abdurrahman Hussain)\n- smb/server: promote S_DEL_ON_CLS to S_DEL_PENDING when close (ChenXiaoSong)\n- smb: client: use data_len for SMB2 READ encrypted folioq copy (Jeremy Erazo)\n- smb: client: require net admin for CIFS SWN netlink (Michael Bommarito)\n- ksmbd: validate SID in parent security descriptor during ACL inheritance (Junyi Liu)\n- ksmbd: fix null pointer dereference in compare_guid_key() (Jeremy Laratro)\n- mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break() (SeongJae Park)\n- sysfs: don't remove existing directory on update failure (Greg Kroah-Hartman)\n- hwmon: (pmbus/core) Protect regulator operations with mutex (Guenter Roeck)\n- Revert 'ice: Remove jumbo_remove step from TX path' (Sasha Levin)\n- Revert 'ice: fix double-free of tx_buf skb' (Sasha Levin)\n- perf parse-events: Expose/rename config_term_name (Ian Rogers)\n- drm/imagination: Synchronize interrupts before suspending the GPU (Alessio Belle)\n- af_unix: Give up GC if MSG_PEEK intervened. (Kuniyuki Iwashima)\n- ksmbd: close durable scavenger races against m_fp_list lookups (DaeMyung Kang)\n- Revert 'x86/vdso: Fix output operand size of RDPID' (Sasha Levin)\n- spi: spi-dw-dma: fix print error log when wait finish transaction (Vladimir Yakovlev)\n- bridge: mrp: reject zero test interval to avoid OOM panic (Xiang Mei)\n- Revert 'perf tool_pmu: Factor tool events into their own PMU' (Sasha Levin)\n- Revert 'perf python: Add parse_events function' (Sasha Levin)\n- Revert 'perf tool_pmu: Fix aggregation on duration_time' (Sasha Levin)\n- Revert 'perf cgroup: Update metric leader in evlist__expand_cgroup' (Sasha Levin)\n- s390/debug: Reject zero-length input before trimming a newline (Pengpeng Hou)\n- drm/xe/hdcp: Add NULL check for media_gt in intel_hdcp_gsc_check_status() (Gustavo Sousa)\n- ksmbd: validate owner of durable handle on reconnect (Namjae Jeon)\n- mptcp: pm: ADD_ADDR rtx: free sk if last (Matthieu Baerts (NGI0))\n- mptcp: pm: ADD_ADDR rtx: always decrease sk refcount (Matthieu Baerts (NGI0))\n- mptcp: pm: ADD_ADDR rtx: allow ID 0 (Matthieu Baerts (NGI0))\n- mptcp: sync the msk-sndbuf at accept() time (Gang Yan)\n- LTS version: v6.12.91 (Saeed Mirzamohammadi)\n- netfs: Fix potential uninitialised var in netfs_extract_user_iter() (David Howells)\n- mptcp: pm: ADD_ADDR rtx: resched blocked ADD_ADDR quicker (Matthieu Baerts (NGI0))\n- mptcp: pm: ADD_ADDR rtx: fix potential data-race (Matthieu Baerts (NGI0))\n- mptcp: pm: kernel: correctly retransmit ADD_ADDR ID 0 (Matthieu Baerts (NGI0))\n- spi: sifive: fix controller deregistration (Johan Hovold)\n- spi: sifive: Simplify clock handling with devm_clk_get_enabled() (Pei Xiao)\n- f2fs: fix false alarm of lockdep on cp_global_sem lock (Chao Yu)\n- f2fs: fix incorrect file address mapping when inline inode is unwritten (Yongpeng Yang)\n- mptcp: fix rx timestamp corruption on fastopen (Paolo Abeni)\n- mptcp: drop __mptcp_fastopen_gen_msk_ackseq() (Paolo Abeni)\n- mptcp: pm: prio: skip closed subflows (Matthieu Baerts (NGI0))\n- sched_ext: Guard scx_dsq_move() against NULL kit-dsq after failed iter_new (Tejun Heo)\n- RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (Jason Gunthorpe)\n- btrfs: do not mark inode incompressible after inline attempt fails (Qu Wenruo)\n- smb: client: Use FullSessionKey for AES-256 encryption key derivation (Piyush Sachdeva)\n- btrfs: fix missing last_unlink_trans update when removing a directory (Filipe Manana)\n- btrfs: use btrfs inodes in btrfs_rmdir() to avoid so much usage of BTRFS_I() (Filipe Manana)\n- btrfs: use inode already stored in local variable at btrfs_rmdir() (Filipe Manana)\n- drm/v3d: Reject empty multisync extension to prevent infinite loop (Ashutosh Desai)\n- eventfs: Use list_add_tail_rcu() for SRCU-protected children list (David Carlier)\n- iommufd: Fix return value of iommufd_fault_fops_write() (Zhenzhong Duan)\n- drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (Johan Hovold)\n- drm/gma500/oaktrail_lvds: fix hang on init failure (Johan Hovold)\n- drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (Johan Hovold)\n- drm/xe/dma-buf: handle empty bo and UAF races (Matthew Auld)\n- drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (Gyeyoung Baek)\n- drm/i915: skip __i915_request_skip() for already signaled requests (Sebastian Brzezinka)\n- iommu/vt-d: Disable DMAR for Intel Q35 IGFX (Naval Alcala)\n- libceph: handle rbtree insertion error in decode_choose_args() (Raphael Zimmer)\n- libceph: Fix potential out-of-bounds access in crush_decode() (Raphael Zimmer)\n- libceph: Fix potential null-ptr-deref in decode_choose_args() (Raphael Zimmer)\n- libceph: Fix potential out-of-bounds access in osdmap_decode() (Raphael Zimmer)\n- irqchip/riscv-imsic: Clear interrupt move state during CPU offlining (Yong-Xuan Wang)\n- netfs: fix error handling in netfs_extract_user_iter() (Paulo Alcantara)\n- powerpc/warp: Fix error handling in pika_dtm_thread (Ma Ke)\n- io-wq: check that the predecessor is hashed in io_wq_remove_pending() (Nicholas Carlini)\n- ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size (Viacheslav Dubeyko)\n- ceph: fix a buffer leak in __ceph_setxattr() (Viacheslav Dubeyko)\n- ALSA: usb-audio: Bound MIDI endpoint descriptor scans (Cassio Gabriel)\n- ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (Cassio Gabriel)\n- drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (Chaitanya Kumar Borah)\n- drm/loongson: Use managed KMS polling (Myeonghun Pak)\n- smb/client: fix possible infinite loop and oob read in symlink_data() (Ye Bin)\n- Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (Pauli Virtanen)\n- netfilter: nf_tables: unconditionally bump set-nelems before insertion (Pablo Neira Ayuso)\n- KVM: x86: Fix Xen hypercall tracepoint argument assignment (Qiang Ma)\n- KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic (Junrui Luo)\n- KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (Aaron Sacks)\n- audit: enforce AUDIT_LOCKED for AUDIT_TRIM and AUDIT_MAKE_EQUIV (Sergio Correia)\n- net: atlantic: preserve PCI wake-from-D3 on shutdown when WOL enabled (Zoran Ilievski)\n- netfilter: nft_ct: fix missing expect put in obj eval (Li Xiasong)\n- Revert 'ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn' (Mario Limonciello)\n- audit: fix incorrect inheritable capability in CAPSET records (Sergio Correia)\n- netfilter: nf_conntrack_sip: get helper before allocating expectation (Li Xiasong)\n- workqueue: Fix wq-cpu_pwq leak in alloc_and_link_pwqs() WQ_UNBOUND path (Breno Leitao)\n- i40e: Cleanup PTP pins on probe failure (Matt Vollrath)\n- crypto: af_alg - Cap AEAD AD length to 0x80000000 (Herbert Xu)\n- page_pool: fix incorrect mp_ops error handling (Mina Almasry)\n- netpoll: pass buffer size to egress_dev() to avoid MAC truncation (Breno Leitao)\n- netpoll: Extract IPv6 address retrieval function (Breno Leitao)\n- net/sched: sch_pie: annotate more data-races in pie_dump_stats() (Eric Dumazet)\n- perf tool_pmu: Fix aggregation on duration_time (Ian Rogers)\n- iommu/amd: Put list_add/del(dev_data) back under the domain-lock (Jason Gunthorpe)\n- iommu/amd: Reorder attach device code (Vasant Hegde)\n- net: bcmgenet: fix leaking free_bds (Justin Chen)\n- net: bcmgenet: Initialize u64 stats seq counter (Ryo Takakura)\n- PCI: Initialize temporary device in new_id_store() (Samiullah Khawaja)\n- ntfs: -d_compare() must not block (Al Viro)\n- LoongArch: KVM: Compile switch.S directly into the kernel (Xianglai Li)\n- smb: client: fix OOB reads parsing symlink error response (Greg Kroah-Hartman)\n- smb: client: correctly handle ErrorContextData as a flexible array (Liang Jie)\n- arm64: Reserve an extra page for early kernel mapping (Zhaoyang Huang)\n- net/sched: cls_flower: revert unintended changes (Paolo Abeni)\n- sfc: fix error code in efx_devlink_info_running_versions() (Dan Carpenter)\n- net: tls: fix strparser anchor skb leak on offload RX setup failure (Jakub Kicinski)\n- ice: fix NULL pointer dereference in ice_reset_all_vfs() (Petr Oros)\n- iavf: add VIRTCHNL_OP_ADD_VLAN to success completion handler (Petr Oros)\n- iavf: wait for PF confirmation before removing VLAN filters (Petr Oros)\n- iavf: stop removing VLAN filters from PF on interface down (Petr Oros)\n- iavf: rename IAVF_VLAN_IS_NEW to IAVF_VLAN_ADDING (Petr Oros)\n- page_pool: fix memory-provider leak in page_pool_create_percpu() error path (Hasan Basbunar)\n- net: page_pool: create hooks for custom memory providers (Pavel Begunkov)\n- page_pool: Set dma_sync to false for devmem memory provider (Samiullah Khawaja)\n- drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (Shuicheng Lin)\n- drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (Shuicheng Lin)\n- drm/xe/debugfs: Correct printing of register whitelist ranges (Matt Roper)\n- drm/amd/display: Read EDID from VBIOS embedded panel info (Timur Kristof)\n- drm/amd/display: Allow DCE link encoder without AUX registers (Timur Kristof)\n- futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (Sebastian Andrzej Siewior)\n- ALSA: hda: cs35l56: Fix uninitialized value in cs35l56_hda_read_acpi() (Richard Fitzgerald)\n- ALSA: hda/conexant: Fix missing error check for jack detection (wangdicheng)\n- ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (wangdicheng)\n- netconsole: propagate device name truncation in dev_name_store() (Breno Leitao)\n- net/sched: sch_cake: annotate data-races in cake_dump_stats() (V) (Eric Dumazet)\n- bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (Weiming Shi)\n- sctp: discard stale INIT after handshake completion (Xin Long)\n- netfilter: skip recording stale or retransmitted INIT (Xin Long)\n- ASoC: codecs: ab8500: Fix casting of private data (Christian A. Ehrhardt)\n- drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (Yinjie Yao)\n- drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (Yinjie Yao)\n- drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (Yinjie Yao)\n- drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (Yinjie Yao)\n- drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (Yinjie Yao)\n- drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (Yinjie Yao)\n- drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (Yinjie Yao)\n- drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (Yinjie Yao)\n- drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (Yinjie Yao)\n- drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (Yinjie Yao)\n- drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (Yinjie Yao)\n- drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (Yinjie Yao)\n- drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (Yinjie Yao)\n- net: phy: dp83869: fix setting CLK_O_SEL field. (Heiko Schocher)\n- net: mctp i2c: check length before marking flow active (William A. Kennington III)\n- sched/fair: Clear rel_deadline when initializing forked entities (Zicheng Qu)\n- ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (Takashi Iwai)\n- netpoll: fix IPv6 local-address corruption (Breno Leitao)\n- netpoll: extract IPv4 address retrieval into helper function (Breno Leitao)\n- netpoll: Extract carrier wait function (Breno Leitao)\n- netconsole: allow selection of egress interface via MAC address (Uday Shankar)\n- net, treewide: define and use MAC_ADDR_STR_LEN (Uday Shankar)\n- tcp: make probe0 timer handle expired user timeout (Altan Hacigumus)\n- neigh: let neigh_xmit take skb ownership (Florian Westphal)\n- net/sched: taprio: fix NULL pointer dereference in class dump (Weiming Shi)\n- NFC: trf7970a: Ignore antenna noise when checking for RF field (Paul Geurts)\n- net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (Morduan Zang)\n- net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (Zhan Jun)\n- vrf: Fix a potential NPD when removing a port from a VRF (Ido Schimmel)\n- net/sched: sch_fq_pie: annotate data-races in fq_pie_dump_stats() (Eric Dumazet)\n- net/sched: sch_choke: annotate data-races in choke_dump_stats() (Eric Dumazet)\n- net/sched: netem: check for negative latency and jitter (Stephen Hemminger)\n- net/sched: netem: fix slot delay calculation overflow (Stephen Hemminger)\n- net/sched: netem: validate slot configuration (Stephen Hemminger)\n- net/sched: netem: only reseed PRNG when seed is explicitly provided (Stephen Hemminger)\n- net/sched: netem: fix queue limit check to include reordered packets (Stephen Hemminger)\n- net/sched: netem: fix probability gaps in 4-state loss model (Stephen Hemminger)\n- netdevsim: zero initialize struct iphdr in dummy sk_buff (Nikola Z. Ivanov)\n- cdrom, scsi: sr: propagate read-only status to block layer via set_disk_ro() (Daan De Meyer)\n- drm/sysfb: ofdrm: fix PCI device reference leaks (Yuho Choi)\n- spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (John Madieu)\n- ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (Guilherme G. Piccoli)\n- netfilter: nf_conntrack_sip: don't use simple_strtoul (Florian Westphal)\n- netfilter: xt_policy: fix strict mode inbound policy matching (Jiexun Wang)\n- drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (Timur Kristof)\n- drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (Timur Kristof)\n- drm/amdgpu: fix spelling typos (Alexandre Demers)\n- drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (Christian Konig)\n- drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (Timur Kristof)\n- nvme-pci: fix missed admin queue sq doorbell write (Keith Busch)\n- netfilter: arp_tables: fix IEEE1394 ARP payload parsing (Pablo Neira Ayuso)\n- nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (Maurizio Lombardi)\n- tracing: branch: Fix inverted check on stat tracer registration (Breno Leitao)\n- cgroup: Increment nr_dying_subsys_* from rmdir context (Petr Malat)\n- btrfs: fix double-decrement of bytes_may_use in submit_one_async_extent() (Mark Harmstone)\n- fsnotify: fix inode reference leak in fsnotify_recalc_mask() (Amir Goldstein)\n- mailbox: mailbox-test: make data_ready a per-instance variable (Wolfram Sang)\n- mailbox: mailbox-test: initialize struct earlier (Wolfram Sang)\n- mailbox: mailbox-test: don't free the reused channel (Wolfram Sang)\n- mailbox: add sanity check for channel array (Wolfram Sang)\n- cgroup/rdma: fix integer overflow in rdmacg_try_charge() (cuitao)\n- mailbox: mailbox-test: free channels on probe error (Wolfram Sang)\n- mailbox: mtk-cmdq: Fix CURR and END addr for task insert case (Jason-JH Lin)\n- fbdev: offb: fix PCI device reference leak on probe failure (Yuho Choi)\n- kbuild: builddeb - avoid recompiles for non-cross-compiles (Mathias Krause)\n- rtc: abx80x: Disable alarm feature if no interrupt attached (Anthony Pighin (Nokia))\n- fs/adfs: validate nzones in adfs_validate_bblk() (Bae Yeonju)\n- vhost_net: fix sleeping with preempt-disabled in vhost_net_busy_poll() (Kohei Enju)\n- tipc: fix double-free in tipc_buf_append() (Lee Jones)\n- nfp: fix swapped arguments in nfp_encode_basic_qdr() calls (Alexey Kodanev)\n- virtio_net: sync rss_trailer.max_tx_vq on queue_pairs change via VQ_PAIRS_SET (Brett Creeley)\n- virtio_net: Use new RSS config structs (Akihiko Odaki)\n- virtio_net: Fix endian with virtio_net_ctrl_rss (Akihiko Odaki)\n- virtio_net: Split struct virtio_net_rss_config (Akihiko Odaki)\n- net: airoha: Move ndesc initialization at end of airoha_qdma_init_rx_queue() (Lorenzo Bianconi)\n- net: dsa: realtek: rtl8365mb: fix mode mask calculation (Mieczyslaw Nalewaj)\n- net/sched: sch_sfb: annotate data-races in sfb_dump_stats() (Eric Dumazet)\n- net/sched: sch_red: annotate data-races in red_dump_stats() (Eric Dumazet)\n- net/sched: sch_fq_codel: remove data-races from fq_codel_dump_stats() (Eric Dumazet)\n- net/sched: sch_pie: annotate data-races in pie_dump_stats() (Eric Dumazet)\n- net_sched: sch_hhf: annotate data-races in hhf_dump_stats() (Eric Dumazet)\n- ice: fix ice_ptp_read_tx_hwtstamp_status_eth56g (Jacob Keller)\n- ice: fix timestamp interrupt configuration for E825C (Grzegorz Nitka)\n- ksmbd: scope conn-binding slowpath to bound sessions only (Hyunwoo Kim)\n- ksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open (DaeMyung Kang)\n- ksmbd: destroy async_ida in ksmbd_conn_free() (DaeMyung Kang)\n- ksmbd: destroy tree_conn_ida in ksmbd_session_destroy() (DaeMyung Kang)\n- pwm: atmel-tcb: Cache clock rates and mark chip as atomic (Sangyun Kim)\n- arm64: dts: meson-gxl-p230: fix ethernet PHY interrupt number (Jun Yan)\n- slip: bound decode() reads against the compressed packet length (Weiming Shi)\n- slip: reject VJ receive packets on instances with no rstate array (Weiming Shi)\n- netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check (Fernando Fernandez Mancera)\n- netfilter: nfnetlink_osf: fix out-of-bounds read on option matching (Fernando Fernandez Mancera)\n- ipvs: fix MTU check for GSO packets in tunnel mode (Yingnan Zhang)\n- netfilter: xtables: restrict several matches to inet family (Pablo Neira Ayuso)\n- netfilter: conntrack: remove sprintf usage (Florian Westphal)\n- netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (Xiang Mei)\n- netfilter: nft_osf: restrict it to ipv4 (Pablo Neira Ayuso)\n- openvswitch: cap upcall PID array size and pre-size vport replies (Weiming Shi)\n- net/mlx5: Fix HCA caps leak on notifier init failure (Prathamesh Deshpande)\n- pppoe: drop PFC frames (Qingfang Deng)\n- sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks (Michael Bommarito)\n- ipv6: fix possible UAF in icmpv6_rcv() (Eric Dumazet)\n- e1000e: Unroll PTP in probe error handling (Matt Vollrath)\n- i40e: don't advertise IFF_SUPP_NOFCS (Kohei Enju)\n- ice: fix ICE_AQ_LINK_SPEED_M for 200G (Paul Greenwalt)\n- ice: fix double-free of tx_buf skb (Michal Schmidt)\n- ice: Remove jumbo_remove step from TX path (Alice Mikityanska)\n- ice: update PCS latency settings for E825 10G/25Gb modes (Grzegorz Nitka)\n- tcp: annotate data-races around tp-plb_rehash (Eric Dumazet)\n- tcp: annotate data-races around (tp-write_seq - tp-snd_nxt) (Eric Dumazet)\n- tcp: annotate data-races around tp-dsack_dups (Eric Dumazet)\n- tcp: annotate data-races around tp-bytes_retrans (Eric Dumazet)\n- tcp: annotate data-races around tp-bytes_sent (Eric Dumazet)\n- tcp: add data-race annotations for TCP_NLA_SNDQ_SIZE (Eric Dumazet)\n- tcp: add data-race annotations around tp-data_segs_out and tp-total_retrans (Eric Dumazet)\n- net/sched: taprio: fix use-after-free in advance_sched() on schedule switch (Vinicius Costa Gomes)\n- nexthop: fix IPv6 route referencing IPv4 nexthop (Jiayuan Chen)\n- net/sched: sch_cake: fix NAT destination port not being updated in cake_update_flowkeys (Dudu Lu)\n- macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF (Dudu Lu)\n- net/sched: act_mirred: fix wrong device for mac_header_xmit check in tcf_blockcast_redir (Dudu Lu)\n- arm64: dts: marvell: armada-37xx: use 'usb2-phy' in USB3 controller's phy-names (Gabor Juhos)\n- arm64: dts: imx8mm-tqma8mqml: Correct PAD settings for PMIC_nINT (Peng Fan)\n- arm64: dts: imx8mn-tqma8mqnl: Correct PAD settings for PMIC_nINT (Peng Fan)\n- arm64: dts: imx8mm-emtop-som: Correct PAD settings for PMIC_nINT (Peng Fan)\n- PCMCIA: Fix garbled log messages for KERN_CONT (Rene Rebe)\n- arm64: dts: imx8mp-data-modul-edm-sbc: Correct PAD settings for PMIC_nINT (Peng Fan)\n- arm64: dts: imx8mp-dhcom-som: Correct PAD settings for PMIC_nINT (Peng Fan)\n- arm64: dts: imx8mp-icore-mx8mp: Correct PAD settings for PMIC_nINT (Peng Fan)\n- arm64: dts: imx8mp-navqp: Correct PAD settings for PMIC_nINT (Peng Fan)\n- arm64: dts: imx8mp-debix-som-a: Correct PAD settings for PMIC_nINT (Peng Fan)\n- arm64: dts: imx8mp-debix-model-a: Correct PAD settings for PMIC_nINT (Peng Fan)\n- erofs: unify lcn as u64 for 32-bit platforms (Gao Xiang)\n- erofs: avoid infinite loops due to corrupted subpage compact indexes (Gao Xiang)\n- erofs: do sanity check on m-type in z_erofs_load_compact_lcluster() (Chao Yu)\n- erofs: add encoded extent on-disk definition (Gao Xiang)\n- crypto: ccp - copy IV using skcipher ivsize (Paul Moses)\n- crypto: sa2ul - Fix AEAD fallback algorithm names (T Pratham)\n- drm/i915/wm: Verify the correct plane DDB entry (Ville Syrjala)\n- drm/i915: Relocate the SKL wm sanitation code (Ville Syrjala)\n- f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show() (Yongpeng Yang)\n- clk: visconti: pll: initialize clk_init_data to zero (Brian Masney)\n- clk: qcom: gcc-x1e80100: Keep GCC USB QTB clock always ON (Jagadeesh Kona)\n- lib/hexdump: print_hex_dump_bytes() calls print_hex_dump_debug() (Geert Uytterhoeven)\n- clk: qcom: dispcc-sc7180: Add missing MDSS resets (Konrad Dybcio)\n- dt-bindings: clock: qcom,dispcc-sc7180: Define MDSS resets (Konrad Dybcio)\n- clk: xgene: Fix mapping leak in xgene_pllclk_init() (Geert Uytterhoeven)\n- clk: qoriq: avoid format string warning (Arnd Bergmann)\n- x86/um: fix vDSO installation (Thomas Weissschuh)\n- x86/um/vdso: Drop VDSO64-y from Makefile (Thomas Weissschuh)\n- clk: imx8mq: Correct the CSI PHY sels (Sebastian Krzyszkowiak)\n- clk: imx: imx6q: Fix device node reference leak in of_assigned_ldb_sels() (Felix Gu)\n- clk: imx: imx6q: Fix device node reference leak in pll6_bypassed() (Felix Gu)\n- clk: qcom: dispcc-sm8250: Enable parents for pixel clocks (Val Packett)\n- clk: qcom: dispcc-sm8250: Use shared ops on the mdss vsync clk (Val Packett)\n- clk: qcom: gcc-sc8180x: Use retention for PCIe power domains (Val Packett)\n- clk: qcom: gcc-sc8180x: Use retention for USB power domains (Val Packett)\n- clk: qcom: gcc-sc8180x: Add missing GDSCs (Val Packett)\n- dt-bindings: clock: qcom,gcc-sc8180x: Add missing GDSCs (Val Packett)\n- scsi: target: core: Fix integer overflow in UNMAP bounds check (Junrui Luo)\n- clk: qcom: dispcc-sm4450: Fix DSI byte clock rate setting (Konrad Dybcio)\n- clk: qcom: dispcc-sc8280xp: remove CLK_SET_RATE_PARENT from byte_div_clk_src dividers (White Lewis)\n- scsi: sg: Resolve soft lockup issue when opening /dev/sgX (Yang Erkun)\n- scsi: sg: Fix sysctl sg-big-buff register during sg_init() (Yang Erkun)\n- clk: qcom: dispcc-sm8450: use RCG2 ops for DPTX1 AUX clock source (Dmitry Baryshkov)\n- RDMA/core: Prefer NLA_NUL_STRING (Florian Westphal)\n- platform/x86: dell-wmi-sysman: bound enumeration string aggregation (Pengpeng Hou)\n- platform/x86: dell_rbu: avoid uninit value usage in packet_size_write() (Fedor Pchelkin)\n- fs/ntfs3: terminate the cached volume label after UTF-8 conversion (Pengpeng Hou)\n- tty: serial: ip22zilog: Fix section mispatch warning (Thomas Bogendoerfer)\n- platform/x86: asus-wmi: fix screenpad brightness range (Denis Benato)\n- platform/x86: asus-wmi: adjust screenpad power/brightness handling (Denis Benato)\n- nfs/blocklayout: Fix compilation error (make W=1) in bl_write_pagelist() (Andy Shevchenko)\n- mfd: mc13xxx-core: Fix memory leak in mc13xxx_add_subdevice_pdata() (Abdun Nihaal)\n- platform/x86: panasonic-laptop: Fix OPTD notifier registration and cleanup (Rafael J. Wysocki)\n- tty: hvc_iucv: fix off-by-one in number of supported devices (Randy Dunlap)\n- leds: lgm-sso: Remove duplicate assignments for priv-mmap (Chen Ni)\n- platform/surface: surfacepro3_button: Drop wakeup source on remove (Rafael J. Wysocki)\n- backlight: sky81452-backlight: Check return value of devm_gpiod_get_optional() in sky81452_bl_parse_dt() (Chen Ni)\n- i3c: mipi-i3c-hci: fix IBI payload length calculation for final status (Billy Tsai)\n- i3c: dw: Fix memory leak in dw_i3c_master_i3c_xfers() (Felix Gu)\n- i3c: master: dw-i3c: Fix missing reset assertion in remove() callback (Felix Gu)\n- reset: Add devres helpers to request pre-deasserted reset controls (Philipp Zabel)\n- reset: replace boolean parameters with flags parameter (Philipp Zabel)\n- perf util: Kill die() prototype, dead for a long time (Arnaldo Carvalho de Melo)\n- perf maps: Fix copy_from that can break sorted by name order (Ian Rogers)\n- perf cgroup: Update metric leader in evlist__expand_cgroup (Ian Rogers)\n- perf python: Add parse_events function (Ian Rogers)\n- perf tool_pmu: Factor tool events into their own PMU (Ian Rogers)\n- perf evsel: Add alternate_hw_config and use in evsel__match (Ian Rogers)\n- ipmi: ssif_bmc: change log level to dbg in irq callback (Jian Zhang)\n- ipmi: ssif_bmc: fix message desynchronization after truncated response (Jian Zhang)\n- ipmi: ssif_bmc: fix missing check for copy_to_user() partial failure (Jian Zhang)\n- perf expr: Return -EINVAL for syntax error in expr__find_ids() (Leo Yan)\n- perf tools: Fix module symbol resolution for non-zero .text sh_addr (Chuck Lever)\n- perf stat: Fix opt-value type for parse_cache_level (Ian Rogers)\n- perf lock: Fix option value type in parse_max_stack (Ian Rogers)\n- pinctrl: renesas: rzg2l: Fix save/restore of {IOLH,IEN,PUPD,SMT} registers (Biju Das)\n- pinctrl: abx500: Fix type of 'argument' variable (Yu-Chun Lin)\n- pinctrl: realtek: Fix function signature for config argument (Yu-Chun Lin)\n- perf: tools: cs-etm: Fix print issue for Coresight debug in ETE/TRBE trace (Mike Leach)\n- perf branch: Avoid incrementing NULL (Ian Rogers)\n- pinctrl: cy8c95x0: Avoid returning positive values to user space (Andy Shevchenko)\n- pinctrl: cy8c95x0: Unify messages with help of dev_err_probe() (Andy Shevchenko)\n- pinctrl: cy8c95x0: remove duplicate error message (Andy Shevchenko)\n- pinctrl: pinctrl-pic32: Fix resource leak (Ethan Tidmore)\n- bpf, arm32: Reject BPF-to-BPF calls and callbacks in the JIT (Puranjay Mohan)\n- bpf: Validate node_id in arena_alloc_pages() (Puranjay Mohan)\n- bpf: allow UTF-8 literals in bpf_bprintf_prepare() (Yihan Ding)\n- bpf: Fix NULL deref in map_kptr_match_type for scalar regs (Mykyta Yatsenko)\n- bpf: Fix precedence bug in convert_bpf_ld_abs alignment check (Daniel Borkmann)\n- bpf, sockmap: Take state lock for af_unix iter (Michal Luczaj)\n- bpf, sockmap: Fix af_unix null-ptr-deref in proto update (Michal Luczaj)\n- bpf, sockmap: Fix af_unix iter deadlock (Michal Luczaj)\n- bpf, arm64: Fix off-by-one in check_imm signed range check (Daniel Borkmann)\n- ext4: fix possible null-ptr-deref in mbt_kunit_exit() (Ye Bin)\n- HID: usbhid: fix deadlock in hid_post_reset() (Oliver Neukum)\n- mtd: rawnand: sunxi: fix sunxi_nfc_hw_ecc_read_extra_oob (Richard Genoud)\n- cxl/pci: Check memdev driver binding status in cxl_reset_done() (Li Ming)\n- mtd: parsers: ofpart: call of_node_put() only in ofpart_fail path (Cosmin Tanislav)\n- mtd: spi-nor: swp: check SR_TB flag when getting tb_mask (Shiji Yang)\n- mtd: spi-nor: update spi_nor_fixups::post_sfdp() documentation (Jonas Gorski)\n- mtd: spi-nor: sfdp: introduce smpt_map_id fixup hook (Takahiro Kuwano)\n- mtd: spi-nor: sfdp: introduce smpt_read_dummy fixup hook (Takahiro Kuwano)\n- mtd: spi-nor: core: correct the op.dummy.nbytes when check read operations (Haibo Chen)\n- dt-bindings: interrupt-controller: arm,gic-v3: Fix EPPI range (Geert Uytterhoeven)\n- ima_fs: Correctly create securityfs files for unsupported hash algos (Dmitry Safonov)\n- ima_fs: get rid of lookup-by-dentry stuff (Al Viro)\n- ima_fs: don't bother with removal of files in directory we'll be removing (Al Viro)\n- mtd: physmap_of_gemini: Fix disabled pinctrl state check (Chen Ni)\n- HID: asus: do not abort probe when not necessary (Denis Benato)\n- HID: asus: make asus_resume adhere to linux kernel coding standards (Denis Benato)\n- ima: check return value of crypto_shash_final() in boot aggregate (Daniel Hodges)\n- remoteproc: xlnx: Fix sram property parsing (Tim Michals)\n- hte: tegra194: remove Kconfig dependency on Tegra194 SoC (Francesco Lavra)\n- tracing: Rebuild full_name on each hist_field_name() call (Pengpeng Hou)\n- soundwire: cadence: Clear message complete before signaling waiting thread (Richard Fitzgerald)\n- dmaengine: mxs-dma: Fix missing return value from of_dma_controller_register() (Frank Li)\n- soundwire: bus: demote UNATTACHED state warnings to dev_dbg() (Cole Leavitt)\n- dmaengine: dw-axi-dmac: Remove unnecessary return statement from void function (Khairul Anuar Romli)\n- ocfs2: validate group add input before caching (ZhengYuan Huang)\n- ocfs2: validate bg_bits during freefrag scan (ZhengYuan Huang)\n- ocfs2: fix listxattr handling when the buffer is full (ZhengYuan Huang)\n- firmware: arm_ffa: Use the correct buffer size during RXTX_MAP (Sebastian Ene)\n- ARM: dts: imx27-eukrea: replace interrupts with interrupts-extended (Frank Li)\n- arm64/xor: fix conflicting attributes for xor_block_template (Christoph Hellwig)\n- ARM: OMAP1: Fix DEBUG_LL and earlyprintk on OMAP16XX (Aaro Koskinen)\n- arm64: dts: qcom: sm8250: Add missing CPU7 3.09GHz OPP (Alexander Koskovich)\n- soc: qcom: aoss: compare against normalized cooling state (Alok Tiwari)\n- soc: qcom: llcc: fix v1 SB syndrome register offset (Alok Tiwari)\n- ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (Junrui Luo)\n- ocfs2/dlm: validate qr_numregions in dlm_match_regions() (Junrui Luo)\n- unshare: fix nsproxy leak in ksys_unshare() on set_cred_ucounts() failure (Michal Grzedzicki)\n- soc/tegra: cbb: Set ERD on resume for err interrupt (Sumit Gupta)\n- arm64: dts: imx8qxp-mek: switch Type-C connector power-role to dual (Xu Yang)\n- arm64: dts: imx8qm-mek: switch Type-C connector power-role to dual (Xu Yang)\n- arm64: dts: lx2160a: complete pinmux for rcwsr12 configuration word (Josua Mayer)\n- arm64: dts: lx2160a: change zeros to hexadecimal in pinmux nodes (Josua Mayer)\n- arm64: dts: lx2160a: add sda gpio references for i2c bus recovery (Josua Mayer)\n- arm64: dts: lx2160a: rename pinmux nodes for readability (Josua Mayer)\n- arm64: dts: lx2160a: remove duplicate pinmux nodes (Josua Mayer)\n- arm64: dts: lx2160a: change i2c0 (iic1) pinmux mask to one bit (Josua Mayer)\n- arm64: dts: freescale: imx8mp-tqma8mpql-mba8mp-ras314: fix UART1 RTS/CTS muxing (Nora Schiffer)\n- arm64: dts: ti: k3-am62-verdin: Fix SPI_1 GPIO CS pinctrl label (Francesco Dolcini)\n- arm64: dts: ti: k3-am62-lp-sk: Enable internal pulls for MMC0 data pins (Judith Mendez)\n- arm64: dts: ti: k3-am62p5-sk: Disable MMC1 internal pulls on data pins (Judith Mendez)\n- arm64: dts: qcom: sdm845-xiaomi-beryllium: Mark l1a regulator as powered during boot (David Heidelberg)\n- arm64: dts: qcom: sm7225-fairphone-fp4: Fix conflicting bias pinctrl (Luca Weiss)\n- arm64: dts: qcom: sm8650: Enable UHS-I SDR50 and SDR104 SD card modes (Vladimir Zapolskiy)\n- arm64: dts: qcom: sm8550: Enable UHS-I SDR50 and SDR104 SD card modes (Vladimir Zapolskiy)\n- arm64: dts: qcom: sm8450: Enable UHS-I SDR50 and SDR104 SD card modes (Vladimir Zapolskiy)\n- arm64: dts: qcom: sm8650: Fix xo clock supply of SD host controller (Vladimir Zapolskiy)\n- arm64: dts: qcom: sm8550: Fix xo clock supply of platform SD host controller (Vladimir Zapolskiy)\n- arm64: dts: qcom: sm8650: Fix GIC_ITS range length (Konrad Dybcio)\n- arm64: dts: qcom: sm8550: Fix GIC_ITS range length (Konrad Dybcio)\n- arm64: dts: qcom: sm8450: Fix GIC_ITS range length (Konrad Dybcio)\n- bus: rifsc: fix RIF configuration check for peripherals (Gatien Chevallier)\n- soc: qcom: ocmem: return -EPROBE_DEFER is ocmem is not available (Dmitry Baryshkov)\n- soc: qcom: ocmem: register reasons for probe deferrals (Dmitry Baryshkov)\n- soc: qcom: ocmem: make the core clock optional (Dmitry Baryshkov)\n- arm64: dts: rockchip: Correct Joystick Axes on Gameforce Ace (Chris Morgan)\n- arm64: dts: rockchip: Correct Fan Supply for Gameforce Ace (Chris Morgan)\n- arm64: dts: rockchip: Fix Bluetooth stability on LCKFB TaiShan Pi (Ming Wang)\n- arm64: dts: qcom: msm8953-xiaomi-daisy: fix backlight (Barnabas Czeman)\n- arm64: dts: qcom: msm8953-xiaomi-vince: correct wled ovp value (Barnabas Czeman)\n- arm64: dts: mediatek: mt7986a: Fix gpio-ranges pin count (Akari Tsuyukusa)\n- arm64: dts: mediatek: mt7981b: Fix gpio-ranges pin count (Akari Tsuyukusa)\n- arm64: dts: mediatek: mt6795: Fix gpio-ranges pin count (Akari Tsuyukusa)\n- iommufd: vfio compatibility extension check for noiommu mode (Jacob Pan)\n- arm64: dts: imx8mp-evk: Enable pull select bit for PCIe regulator GPIO (M.2 W_DISABLE1) (Sherry Sun)\n- arm64: dts: rockchip: Make Jaguar PCIe-refclk pin use pull-up config (Heiko Stuebner)\n- arm64: dts: imx8-apalis: Fix LEDs name collision (Francesco Dolcini)\n- memory: tegra30-emc: Fix dll_change check (Mikko Perttunen)\n- memory: tegra124-emc: Fix dll_change check (Mikko Perttunen)\n- ARM: dts: mediatek: mt7623: fix efuse fallback compatible (Rafal Milecki)\n- arm64: dts: mediatek: mt8365: Describe infracfg-nao as a pure syscon (Nicolas F. R. A. Prado)\n- ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine (Joshua Klinesmith)\n- efi/capsule-loader: fix incorrect sizeof in phys array reallocation (Thomas Huth)\n- gfs2: prevent NULL pointer dereference during unmount (Andreas Gruenbacher)\n- gfs2: add some missing log locking (Andreas Gruenbacher)\n- quota: Fix race of dquot_scan_active() with quota deactivation (Jan Kara)\n- ktest: Run POST_KTEST hooks on failure and cancellation (Ricardo B. Marliere)\n- ktest: Honor empty per-test option overrides (Ricardo B. Marliere)\n- ktest: Avoid undef warning when WARNINGS_FILE is unset (Ricardo B. Marliere)\n- fanotify: call fanotify_events_supported() before path_permission() and security_path_notify() (Ondrej Mosnacek)\n- fdget(), trivial conversions (Al Viro)\n- net/socket.c: switch to CLASS(fd) (Al Viro)\n- gfs2: Call unlock_new_inode before d_instantiate (Andreas Gruenbacher)\n- ALSA: hda/realtek - fixed speaker no sound update (Kailang Yang)\n- crypto: jitterentropy - replace long-held spinlock with mutex (Haixin Xu)\n- dm cache: fix missing return in invalidate_committed's error path (Ming-Hung Tsai)\n- ALSA: sc6000: Keep the programmed board state in card-private data (Cassio Gabriel)\n- spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback (Pei Xiao)\n- PCI: tegra194: Fix CBB timeout caused by DBI access before core power-on (Manikanta Maddireddy)\n- PCI: dwc: Apply ECRC workaround to DesignWare 5.00a as well (Manikanta Maddireddy)\n- PCI: tegra194: Use DWC IP core version (Manikanta Maddireddy)\n- PCI: tegra194: Free up Endpoint resources during remove() (Vidya Sagar)\n- PCI: tegra194: Allow system suspend when the Endpoint link is not up (Vidya Sagar)\n- PCI: tegra194: Set LTR message request before PCIe link up in Endpoint mode (Vidya Sagar)\n- PCI: tegra194: Disable direct speed change for Endpoint mode (Vidya Sagar)\n- PCI: tegra194: Use devm_gpiod_get_optional() to parse 'nvidia,refclk-select' (Vidya Sagar)\n- PCI: tegra194: Disable PERST# IRQ only in Endpoint mode (Manikanta Maddireddy)\n- PCI: tegra194: Don't force the device into the D0 state before L2 (Vidya Sagar)\n- PCI: tegra194: Rename 'root_bus' to 'root_port_bus' in tegra_pcie_downstream_dev_to_D0() (Manivannan Sadhasivam)\n- PCI: tegra194: Disable LTSSM after transition to Detect on surprise link down (Manikanta Maddireddy)\n- PCI: tegra194: Increase LTSSM poll time on surprise link down (Manikanta Maddireddy)\n- PCI: tegra194: Fix polling delay for L2 state (Vidya Sagar)\n- PCI/NPEM: Set LED_HW_PLUGGABLE for hotplug-capable ports (Richard Cheng)\n- ASoC: SOF: compress: return the configured codec from get_params (Cassio Gabriel)\n- ALSA: scarlett2: Add missing sentinel initializer field (Panagiotis Petrakopoulos)\n- selftest: memcg: skip memcg_sock test if address family not supported (Waiman Long)\n- Documentation: fix a hugetlbfs reservation statement (Jane Chu)\n- selftests/mm: skip migration tests if NUMA is unavailable (AnishMulay)\n- PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found (Chen-Yu Tsai)\n- PCI: Enable AtomicOps only if Root Port supports them (Gerd Bayer)\n- ASoC: rsnd: Fix potential out-of-bounds access of component_dais[] (Denis Rastyogin)\n- crypto: qat - use swab32 macro (Giovanni Cabiddu)\n- crypto: qat - fix type mismatch in RAS sysfs show functions (Giovanni Cabiddu)\n- crypto: qat - disable 420xx AE cluster when lead engine is fused off (Ahsan Atta)\n- crypto: qat - disable 4xxx AE cluster when lead engine is fused off (Ahsan Atta)\n- crypto: qat - introduce fuse array (Suman Kumar Chakraborty)\n- ASoC: qcom: qdsp6: topology: check widget type before accessing data (Srinivas Kandagatla)\n- iommu/amd: Fix clone_alias() to use the original device's devid (Vasant Hegde)\n- iommu/amd: Convert dev_data lock from spinlock to mutex (Vasant Hegde)\n- iommu/amd: Rearrange attach device code (Vasant Hegde)\n- iommu/amd: Reduce domain lock scope in attach device path (Vasant Hegde)\n- iommu/amd: Do not detach devices in domain free path (Vasant Hegde)\n- iommu/amd: xarray to track protection_domain-iommu list (Vasant Hegde)\n- iommu/amd: Remove protection_domain.dev_cnt variable (Vasant Hegde)\n- ASoC: fsl_easrc: Change the type for iec958 channel status controls (Shengjiu Wang)\n- ASoC: fsl_easrc: Fix value type in fsl_easrc_iec958_get_bits() (Shengjiu Wang)\n- ASoC: fsl_easrc: Check the variable range in fsl_easrc_iec958_put_bits() (Shengjiu Wang)\n- ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_mode_put() (Shengjiu Wang)\n- ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_arc_mode_put() (Shengjiu Wang)\n- ASoC: fsl_micfil: Fix event generation in micfil_quality_set() (Shengjiu Wang)\n- ASoC: fsl_micfil: Fix event generation in micfil_put_dc_remover_state() (Shengjiu Wang)\n- ASoC: fsl_micfil: Fix event generation in hwvad_put_init_mode() (Shengjiu Wang)\n- ASoC: fsl_micfil: Fix event generation in hwvad_put_enable() (Shengjiu Wang)\n- ASoC: fsl_micfil: Add access property for 'VAD Detected' (Shengjiu Wang)\n- PM: domains: De-constify fields in struct dev_pm_domain_attach_data (Dmitry Baryshkov)\n- pmdomain: imx: scu-pd: Fix device_node reference leak during -probe() (Felix Gu)\n- pmdomain: ti: omap_prm: Fix a reference leak on device node (Felix Gu)\n- drm/msm/a6xx: Use barriers while updating HFI Q headers (Akhil P Oommen)\n- drm/msm/a6xx: Fix dumping A650+ debugbus blocks (Connor Abbott)\n- drm/msm/shrinker: Fix can_block() logic (Rob Clark)\n- drm/msm/a6xx: Fix HLSQ register dumping (Rob Clark)\n- ASoC: SOF: Intel: hda: Place check before dereference (Ethan Tidmore)\n- ALSA: hda/realtek: fix code style (ERROR: else should follow close brace '}') (Lei Huang)\n- hwmon: (aspeed-g6-pwm-tach): remove redundant driver remove callback (Billy Tsai)\n- hwmon: Switch back to struct platform_driver::remove() (Uwe Kleine-Konig)\n- drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (Timur Kristof)\n- drm/amdgpu: update the handle ptr in early_init (Sunil Khatri)\n- drm/amdgpu: update the handle ptr in dump_ip_state (Sunil Khatri)\n- drm/amdgpu: add amdgpu_device reference in ip block (Sunil Khatri)\n- drm/amd/pm/smu7: Add SCLK cap for quirky Hawaii board (Timur Kristof)\n- drm/amd/pm/ci: Fill DW8 fields from SMC (Timur Kristof)\n- drm/amd/pm/ci: Clear EnabledForActivity field for memory levels (Timur Kristof)\n- drm/amd/pm/ci: Fix powertune defaults for Hawaii 0x67B0 (Timur Kristof)\n- drm/amd/pm/smu7: Fix SMU7 voltage dependency on display clock (Timur Kristof)\n- drm/amd/pm/ci: Disable MCLK DPM on problematic CI ASICs (Timur Kristof)\n- drm/amd/pm/ci: Use highest MCLK on CI when MCLK DPM is disabled (Timur Kristof)\n- ALSA: core: Validate compress device numbers without dynamic minors (Cassio Gabriel)\n- PCI: qcom: Advertise Hotplug Slot Capability with no Command Completion support (Krishna Chaitanya Chundru)\n- drm/panel: simple: Correct G190EAN01 prepare timing (Sebastian Reichel)\n- drm/panel: sharp-ls043t1le01: make use of prepare_prev_first (Dmitry Baryshkov)\n- drm/msm/dsi: rename MSM8998 DSI version from V2_2_0 to V2_0_0 (Alexander Koskovich)\n- drm/msm/dpu: fix mismatch between power and frequency (Yuanjie Yang)\n- iommu/tegra241-cmdqv: Set supports_cmd op in tegra241_vcmdq_hw_init() (Nicolin Chen)\n- drm/imagination: Switch reset_reason fields from enum to u32 (Alexandru Dadu)\n- spi: hisi-kunpeng: prevent infinite while() loop in hisi_spi_flush_fifo (Pei Xiao)\n- drm/amdgpu/gfx11: look at the right prop for gfx queue priority (Alex Deucher)\n- drm/amdgpu/gfx10: look at the right prop for gfx queue priority (Alex Deucher)\n- PCI: dwc: rcar-gen4: Change EPC BAR alignment to 4K as per the documentation (Koichiro Den)\n- padata: Remove cpu online check from cpu add and removal (Chuyi Zhou)\n- crypto: atmel-aes - guard unregister on error in atmel_aes_register_algs (Thorsten Blum)\n- crypto: atmel - Use unregister_{aeads,ahashes,skciphers} (Thorsten Blum)\n- crypto: tegra - Disable softirqs before finalizing request (Herbert Xu)\n- crypto: tegra - Reserve keyslots to allocate dynamically (Akhil R)\n- crypto: tegra - Transfer HASH init function to crypto engine (Akhil R)\n- crypto: tegra - finalize crypto req on error (Akhil R)\n- fbdev: matroxfb: Mark variable with __maybe_unused to avoid W=1 build break (Andy Shevchenko)\n- dm init: ensure device probing has finished in dm-mod.waitfor= (Guillaume Gonnet)\n- drm/amdgpu: Add default case in DVI mode validation (Srinivasan Shanmugam)\n- drm/sun4i: Fix resource leaks (Ethan Tidmore)\n- drm/v3d: Handle error from drm_sched_entity_init() (Maira Canal)\n- selftests/sched_ext: Add missing error check for exit__load() (David Carlier)\n- media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (Vladimir Zapolskiy)\n- media: i2c: og01a1b: Replace client-dev usage (Laurent Pinchart)\n- spi: fsl-qspi: Use reinit_completion() for repeated operations (Felix Gu)\n- spi: nxp-fspi: Use reinit_completion() for repeated operations (Felix Gu)\n- spi: spi-nxp-fspi: enable runtime pm for fspi (Haibo Chen)\n- drm/bridge: cadence: cdns-mhdp8546-core: Handle HDCP state in bridge atomic check (Harikrishna Shenoy)\n- drm/bridge: cadence: cdns-mhdp8546-core: Add mode_valid hook to drm_bridge_funcs (Jayesh Choudhary)\n- drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable() (Jayesh Choudhary)\n- dm log: fix out-of-bounds write due to region_count overflow (Junrui Luo)\n- dm cache metadata: fix memory leak on metadata abort retry (Ming-Hung Tsai)\n- PCI: dwc: Perform cleanup in the error path of dw_pcie_resume_noirq() (Manivannan Sadhasivam)\n- PCI: dwc: Invoke post_init in dw_pcie_resume_noirq() (Richard Zhu)\n- PCI: dwc: ep: Fix MSI-X Table Size configuration in dw_pcie_ep_set_msix() (Aksh Garg)\n- PCI: endpoint: Align pci_epc_set_msix(), pci_epc_ops::set_msix() nr_irqs encoding (Niklas Cassel)\n- platform/chrome: chromeos_tbmc: Drop wakeup source on remove (Rafael J. Wysocki)\n- dm cache: fix dirty mapping checking in passthrough mode switching (Ming-Hung Tsai)\n- dm cache: support shrinking the origin device (Ming-Hung Tsai)\n- dm cache: fix concurrent write failure in passthrough mode (Ming-Hung Tsai)\n- dm cache policy smq: fix missing locks in invalidating cache blocks (Ming-Hung Tsai)\n- dm cache: fix write hang in passthrough mode (Ming-Hung Tsai)\n- dm cache: fix write path cache coherency in passthrough mode (Ming-Hung Tsai)\n- dm cache: fix null-deref with concurrent writes in passthrough mode (Ming-Hung Tsai)\n- ASoC: sti: use managed regmap_field allocations (Sander Vanheule)\n- ASoC: sti: Return errors from regmap_field_alloc() (Sander Vanheule)\n- drm/sun4i: backend: fix error pointer dereference (Ethan Tidmore)\n- ASoC: soc-compress: use function to clear symmetric params (Kuninori Morimoto)\n- ASoC: add symmetric_ prefix for dai-rate/channels/sample_bits (Kuninori Morimoto)\n- ASoC: SOF: ipc3: Use standard dev_dbg API (Daniel Baluta)\n- drm/komeda: fix integer overflow in AFBC framebuffer size check (Alexander Konyukhov)\n- net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master (Jiayuan Chen)\n- sctp: fix missing encap_port propagation for GSO fragments (Xin Long)\n- tcp: Don't set treq-req_usec_ts in cookie_tcp_reqsk_init(). (Kuniyuki Iwashima)\n- udp: Force compute_score to always inline (Gabriel Krisman Bertazi)\n- ipv6: udp: fix typos in comments (Alok Tiwari)\n- ipv4: udp: fix typos in comments (Alok Tiwari)\n- net: phy: qcom: at803x: Use the correct bit to disable extended next page (Maxime Chevallier)\n- Bluetooth: SCO: check for codecs-num_codecs == 1 before assigning to sco_pi(sk)-codec (Stefan Metzmacher)\n- Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (Dudu Lu)\n- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (Pauli Virtanen)\n- Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error (Jonathan Rissanen)\n- bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb (Sun Jian)\n- net/mlx5e: IPsec, fix ASO poll timeout with read_poll_timeout_atomic() (Gal Pressman)\n- net/mlx5e: Fix features not applied during netdev registration (Gal Pressman)\n- net: phy: fix a return path in get_phy_c45_ids() (Charles Perry)\n- dt-bindings: net: dsa: nxp,sja1105: make spi-cpol optional for sja1110 (Josua Mayer)\n- net: ipa: Fix decoding EV_PER_EE for IPA v5.0+ (Luca Weiss)\n- net: ipa: Fix programming of QTIME_TIMESTAMP_CFG (Luca Weiss)\n- ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (Taegu Ha)\n- bpf: Fix OOB in pcpu_init_value (Lang Xu)\n- bpf: Allow instructions with arena source and non-arena dest registers (Emil Tsalapatis)\n- selftests: netfilter: nft_tproxy.sh: adjust to socat changes (Florian Westphal)\n- net/sched: act_ct: Only release RCU read lock after ct_ft (Jamal Hadi Salim)\n- selftests/bpf: fix __jited_unpriv tag name (Eduard Zingerman)\n- bpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars (Daniel Borkmann)\n- bpf: Relax scalar id equivalence for state pruning (Puranjay Mohan)\n- net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf (Mashiro Chen)\n- bpf: Fix RCU stall in bpf_fd_array_map_clear() (Sechang Lim)\n- bpf: return VMA snapshot from task_vma iterator (Puranjay Mohan)\n- bpf: switch task_vma iterator from mmap_lock to per-VMA locks (Puranjay Mohan)\n- bpf: fix mm lifecycle in open-coded task_vma iterator (Puranjay Mohan)\n- netfilter: nft_fwd_netdev: check ttl/hl before forwarding (Florian Westphal)\n- netfilter: xt_socket: enable defrag after all other checks (Florian Westphal)\n- eth: fbnic: Use wake instead of start (Mohsin Bashir)\n- net: bcmgenet: fix racing timeout handler (Justin Chen)\n- net: bcmgenet: switch to use 64bit statistics (Zak Kemble)\n- net: bcmgenet: support reclaiming unsent Tx packets (Doug Berger)\n- net: bcmgenet: move DESC_INDEX flow to ring 0 (Doug Berger)\n- net: bcmgenet: add bcmgenet_has_* helpers (Doug Berger)\n- net: bcmgenet: fix off-by-one in bcmgenet_put_txcb (Justin Chen)\n- arm64: kexec: Remove duplicate allocation for trans_pgd (Wang Wensheng)\n- ACPI: AGDI: fix missing newline in error message (Haoyu Lu)\n- wifi: ath10k: fix station lookup failure during disconnect (Baochen Qiang)\n- bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() (Weiming Shi)\n- bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (Jiayuan Chen)\n- wifi: mac80211: handle VHT EXT NSS in ieee80211_determine_our_sta_mode() (Nicolas Escande)\n- wifi: brcmfmac: Fix error pointer dereference (Ethan Tidmore)\n- bpf: Fix stale offload-prog pointer after constant blinding (MingTao Huang)\n- bpf: fix end-of-list detection in cgroup_storage_get_next_key() (Weiming Shi)\n- macvlan: annotate data-races around port-bc_queue_len_used (Eric Dumazet)\n- selftests/powerpc: Suppress -Wmaybe-uninitialized with GCC 15 (Amit Machhiwal)\n- powerpc/crash: Update backup region offset in elfcorehdr on memory hotplug (Sourabh Jain)\n- powerpc/crash: fix backup region offset update to elfcorehdr (Sourabh Jain)\n- r8152: fix incorrect register write to USB_UPHY_XTAL (Chih Kai Hsu)\n- wifi: rtw89: phy: fix uninitialized variable access in rtw89_phy_cfo_set_crystal_cap() (Alexey Velichayshiy)\n- bpf,arc_jit: Fix missing newline in pr_err messages (haoyu.lu)\n- bpf: Fix variable length stack write over spilled pointers (Alexei Starovoitov)\n- bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (David Carlier)\n- wifi: mt76: mt7921: fix 6GHz regulatory update on connection (Michael Lo)\n- wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work() (Duoming Zhou)\n- wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work() (Duoming Zhou)\n- wifi: mt76: mt7996: fix struct mt7996_mcu_uni_event (StanleyYP Wang)\n- arm64: cpufeature: Make PMUVer and PerfMon unsigned (James Clark)\n- wifi: mt76: mt7921: Place upper limit on station AID (Rory Little)\n- wifi: mt76: mt7996: fix FCS error flag check in RX descriptor (Alok Tiwari)\n- wifi: mt76: mt7925: prevent NULL vif dereference in mt7925_mac_write_txwi (Ming Yen Hsieh)\n- wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_tx_check_aggr() (Ming Yen Hsieh)\n- wifi: mt76: mt7915: fix use_cts_prot support (Ryder Lee)\n- wifi: mt76: mt7615: fix use_cts_prot support (Ryder Lee)\n- wifi: mt76: mt7925: Fix incorrect MLO mode in firmware control (Leon Yen)\n- wifi: mt76: mt7921: Reset ampdu_state state in case of failure in mt76_connac2_tx_check_aggr() (Sean Wang)\n- module: Fix freeing of charp module parameters when CONFIG_SYSFS=n (Petr Pavlu)\n- params: Replace __modinit with __init_or_module (Petr Pavlu)\n- s390/bpf: Zero-extend bpf prog return values and kfunc arguments (Ilya Leoshkevich)\n- dpaa2: compile dpaa2 even CONFIG_FSL_DPAA2_ETH=n (Cai Xinchen)\n- dpaa2: add independent dependencies for FSL_DPAA2_SWITCH (Cai Xinchen)\n- bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap (Feng Yang)\n- wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet (Duoming Zhou)\n- wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt() (Zilin Guan)\n- firmware: dmi: Correct an indexing error in dmi.h (Mario Limonciello (AMD))\n(Bart Van Assche)\n- sparc64: vdso: Link with -z noexecstack (Thomas Weissschuh)\n- sparc/vdso: Always reject undefined references during linking (Thomas Weissschuh)\n- hrtimer: Reduce trace noise in hrtimer_start() (Thomas Gleixner)\n- hrtimer: Avoid pointless reprogramming in __hrtimer_start_range_ns() (Peter Zijlstra)\n- hrtimers: Update the return type of enqueue_hrtimer() (Richard Clark)\n- irqchip/irq-pic32-evic: Address warning related to wrong printf() formatter (Brian Masney)\n- bus: fsl-mc: use generic driver_override infrastructure (Danilo Krummrich)\n- s390/cio: use generic driver_override infrastructure (Danilo Krummrich)\n- platform/wmi: use generic driver_override infrastructure (Danilo Krummrich)\n- PCI: use generic driver_override infrastructure (Danilo Krummrich)\n- soundwire: debugfs: initialize firmware_file to empty string (Gui-Dong Han)\n- debugfs: fix placement of EXPORT_SYMBOL_GPL for debugfs_create_str() (Gui-Dong Han)\n- debugfs: check for NULL pointer in debugfs_create_str() (Gui-Dong Han)\n- thermal/drivers/spear: Fix error condition for reading st,thermal-flags (Gopi Krishna Menon)\n- devres: fix missing node debug info in devm_krealloc() (Danilo Krummrich)\n- ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (Rafael J. Wysocki)\n- ACPI: x86: cmos_rtc: Clean up address space handler driver (Rafael J. Wysocki)\n- btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (Filipe Manana)\n- btrfs: pass struct btrfs_inode to clone_copy_inline_extent() (David Sterba)\n- md: wake raid456 reshape waiters before suspend (Yu Kuai)\n- pstore/ram: fix resource leak when ioremap() fails (Cole Leavitt)\n- blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() (Jackie Liu)\n- nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty() (Deepanshu Kartikey)\n- loop: fix partition scan race between udev and loop_reread_partitions() (Daan De Meyer)\n- drbd: Balance RCU calls in drbd_adm_dump_devices() (Bart Van Assche)\n- md/raid1: fix the comparing region of interval tree (Xiao Ni)\n- fs/mbcache: cancel shrink work before destroying the cache (HyungJung Joo)\n- fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START (HyungJung Joo)\n- blk-cgroup: wait for blkcg cleanup before initializing new disk (Ming Lei)\n- io_uring/kbuf: use mem_is_zero() (Pavel Begunkov)\n- LTS version: v6.12.90 (Saeed Mirzamohammadi)\n- drm/amdgpu/vcn4: Avoid overflow on msg bound check (Benjamin Cheng)\n- drm/amdgpu/vcn3: Avoid overflow on msg bound check (Benjamin Cheng)\n- vsock/virtio: fix accept queue count leak on transport mismatch (Dudu Lu)\n- vsock/virtio: fix empty payload in tap skb for non-linear buffers (Stefano Garzarella)\n- vsock/virtio: fix length and offset in tap skb for split packets (Stefano Garzarella)\n- vsock: fix buffer size clamping order (Norbert Szetei)\n- batman-adv: tp_meter: fix tp_num leak on kmalloc failure (Sven Eckelmann)\n- batman-adv: stop tp_meter sessions during mesh teardown (Jiexun Wang)\n- tracing/probes: Limit size of event probe to 3K (Steven Rostedt)\n- btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (Yochai Eisenrich)\n- btrfs: fix double free in create_space_info_sub_group() error path (Guangshuo Li)\n- btrfs: remove fs_info argument from btrfs_sysfs_add_space_info_type() (Filipe Manana)\n- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() (Siwei Zhang)\n- io_uring/kbuf: support min length left for incremental buffers (Martin Michaelis)\n- bonding: fix use-after-free due to enslave fail after slave array update (Nikolay Aleksandrov)\n- rust: allow clippy::collapsible_if globally (Miguel Ojeda)\n- rust: allow clippy::collapsible_match globally (Miguel Ojeda)\n- mm/damon/reclaim: detect and use fresh enabled and kdamond_pid values (SeongJae Park)\n- mm/damon/lru_sort: detect and use fresh enabled and kdamond_pid values (SeongJae Park)\n- mm/damon/core: implement damon_kdamond_pid() (SeongJae Park)\n- mm/damon/core: disallow time-quota setting zero esz (SeongJae Park)\n- rust: pin-init: fix incorrect accessor reference lifetime (Gary Guo)\n- fbcon: Avoid OOB font access if console rotation fails (Thomas Zimmermann)\n- tracefs: Fix default permissions not being applied on initial mount (David Carlier)\n- block: fix zone write plug removal (Damien Le Moal)\n- block: reorganize struct blk_zone_wplug (Damien Le Moal)\n- block: cleanup blkdev_report_zones() (Damien Le Moal)\n- mm/hugetlb_cma: round up per_node before logging it (Sang-Heon Jeon)\n- spi: uniphier: fix controller deregistration (Johan Hovold)\n- spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (Pei Xiao)\n- spi: tegra114: fix controller deregistration (Johan Hovold)\n- spi: tegra20-sflash: fix controller deregistration (Johan Hovold)\n- spi: zynq-qspi: fix controller deregistration (Johan Hovold)\n- spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (Pei Xiao)\n- Bluetooth: hci_conn: fix potential UAF in create_big_sync (David Carlier)\n- ALSA: seq: Fix UMP group 16 filtering (Cassio Gabriel)\n- ALSA: seq: Notify client and port info changes (Takashi Iwai)\n- ALSA: hda: cs35l56: Propagate ASP TX source control errors (Cassio Gabriel)\n- usb: dwc3: Move GUID programming after PHY initialization (Selvarasu Ganesan)\n- usb: typec: tcpm: reset internal port states on soft reset AMS (Amit Sunil Dhamne)\n- batman-adv: bla: put backbone reference on failed claim hash insert (Sven Eckelmann)\n- batman-adv: bla: only purge non-released claims (Sven Eckelmann)\n- batman-adv: bla: prevent use-after-free when deleting claims (Sven Eckelmann)\n- batman-adv: stop caching unowned originator pointers in BAT IV (Jiexun Wang)\n- batman-adv: reject new tp_meter sessions during teardown (Jiexun Wang)\n- batman-adv: fix integer overflow on buff_pos (Lyes Bourennani)\n- sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (Ben Morris)\n- arm64: dts: ti: k3-am62a7-sk: Fix pin name in comment from M19 to N22 (Siddharth Vadapalli)\n- drm/amdgpu/pm: align Hawaii mclk workaround with radeon (Alex Deucher)\n- drm/amdgpu/pm: add missing revision check for CI (Alex Deucher)\n- drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (John B. Moore)\n- drm/amdkfd: Make all TLB-flushes heavy-weight (Felix Kuehling)\n- drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (Icenowy Zheng)\n- drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (John B. Moore)\n- drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (Icenowy Zheng)\n- drm/exynos: remove bridge when component_add fails (Osama Abdelkader)\n- drm/amdgpu: zero-initialize GART table on allocation (Philip Yang)\n- drm/radeon: add missing revision check for CI (Alex Deucher)\n- drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (Shuicheng Lin)\n- drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (Shuicheng Lin)\n- drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (Shuicheng Lin)\n- drm/amdkfd: validate SVM ioctl nattr against buffer size (Alysa Liu)\n- drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (Ashutosh Desai)\n- drm/amd/display: Change dither policy for 10 bpc output back to dithering (Mario Kleiner)\n- drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (Benjamin Cheng)\n- drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (Benjamin Cheng)\n- drm/amdgpu/vce: Prevent partial address patches (Benjamin Cheng)\n- drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (Benjamin Cheng)\n- drm/amdgpu: Add bounds checking to ib_{get,set}_value (Benjamin Cheng)\n- drm/amdkfd: Add upper bound check for num_of_nodes (Alysa Liu)\n- drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (Yang Wang)\n- drm/amdgpu: gate VM CPU HDP flush on reset lock (Chenglei Xie)\n- drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count. (Ramalingeswara Reddy, Kanala)\n- drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (Amir Shetaia)\n- drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata() (Yasuaki Torimaru)\n- spi: cadence: fix unclocked access on unbind (Johan Hovold)\n- spi: cadence: fix controller deregistration (Johan Hovold)\n- spi: mpc52xx: fix use-after-free on unbind (Johan Hovold)\n- spi: mpc52xx: fix controller deregistration (Johan Hovold)\n- spi: mpc52xx: fix use-after-free on registration failure (Johan Hovold)\n- spi: orion: fix clock imbalance on registration failure (Johan Hovold)\n- spi: orion: fix runtime pm leak on unbind (Johan Hovold)\n- spi: orion: fix controller deregistration (Johan Hovold)\n- spi: mxic: fix controller deregistration (Johan Hovold)\n- spi: imx: fix runtime pm leak on probe deferral (Johan Hovold)\n- spi: img-spfi: fix controller deregistration (Johan Hovold)\n- spi: rspi: fix controller deregistration (Johan Hovold)\n- spi: sprd: fix controller deregistration (Johan Hovold)\n- spi: pic32-sqi: fix controller deregistration (Johan Hovold)\n- spi: npcm-pspi: fix controller deregistration (Johan Hovold)\n- spi: coldfire-qspi: fix controller deregistration (Johan Hovold)\n- spi: bcmbca-hsspi: fix controller deregistration (Johan Hovold)\n- spi: fsl: fix controller deregistration (Johan Hovold)\n- spi: sh-hspi: fix controller deregistration (Johan Hovold)\n- spi: pl022: fix controller deregistration (Johan Hovold)\n- spi: mtk-nor: fix controller deregistration (Johan Hovold)\n- spi: pic32: fix controller deregistration (Johan Hovold)\n- spi: omap2-mcspi: fix controller deregistration (Johan Hovold)\n- spi: fsl-espi: fix controller deregistration (Johan Hovold)\n- spi: s3c64xx: fix controller deregistration (Johan Hovold)\n- spi: dln2: fix controller deregistration (Johan Hovold)\n- spi: mxs: fix controller deregistration (Johan Hovold)\n- media: omap3isp: drop the use count of v4l2 pipeline (Haoxiang Li)\n- media: i2c: ov08d10: fix image vertical start setting (Matthias Fend)\n- media: staging: imx: request mbus_config in csi_start (Michael Tretter)\n- media: i2c: imx412: Assert reset GPIO during probe (Wenmeng Liu)\n- media: dib8000: avoid division by 0 in dib8000_set_dds() (Sergey Shtylyov)\n- media: pci: zoran: fix potential memory leak in zoran_probe() (Abdun Nihaal)\n- vsock/virtio: fix MSG_PEEK ignoring skb offset when calculating bytes to copy (Luigi Leonardi)\n- platform/x86: hp-wmi: Ignore backlight and FnLock events (Krishna Chomal)\n- spi: aspeed-smc: fix controller deregistration (Johan Hovold)\n- media: saa7164: add ioremap return checks and cleanups (Wang Jun)\n- spi: at91-usart: fix controller deregistration (Johan Hovold)\n- spi: qup: fix controller deregistration (Johan Hovold)\n- spi: meson-spicc: fix controller deregistration (Johan Hovold)\n- spi: lantiq-ssc: fix controller deregistration (Johan Hovold)\n- regulator: bd9571mwv: fix OF node reference imbalance (Johan Hovold)\n- regulator: act8945a: fix OF node reference imbalance (Johan Hovold)\n- media: i2c: imx283: Fix hang when going from large to small resolution (Jai Luthra)\n- media: intel/ipu6: fix error pointer dereference (Ethan Tidmore)\n- media: videobuf2: Set vma_flags in vb2_dma_sg_mmap (Janne Grunau)\n- regulator: rk808: fix OF node reference imbalance (Johan Hovold)\n- media: i2c: imx283: Enter full standby when stopping streaming (Jai Luthra)\n- media: rc: streamzap: Error handling in probe (Oliver Neukum)\n- media: rc: xbox_remote: heed DMA restrictions (Oliver Neukum)\n- regulator: max77650: fix OF node reference imbalance (Johan Hovold)\n- spi: st-ssc4: fix controller deregistration (Johan Hovold)\n- regulator: mt6357: fix OF node reference imbalance (Johan Hovold)\n- staging: media: atomisp: Disallow all private IOCTLs (Sakari Ailus)\n- arm64: dts: lx2160a-cex7/lx2162a-sr-som: fix usd-cd  gpio pinmux (Josua Mayer)\n- spi: atmel: fix controller deregistration (Johan Hovold)\n- spi: bcm63xx: fix controller deregistration (Johan Hovold)\n- media: chips-media: wave5: add missing spinlock protection for handle_dynamic_resolution_change() (Ziyi Guo)\n- media: chips-media: wave5: add missing spinlock protection for send_eos_event() (Ziyi Guo)\n- media: chips-media: wave5: fix a potential memory leak in wave5_vdi_init() (Haoxiang Li)\n- media: i2c: ov8856: free control handler on error in ov8856_init_controls() (Alexander Koskovich)\n- media: nxp: imx8-isi: Reduce minimum queued buffers from 2 to 0 (Guoniu Zhou)\n- media: uvcvideo: Enable VB2_DMABUF for metadata stream (Ricardo Ribalda)\n- HID: playstation: Clamp num_touch_reports (T.J. Mercier)\n- LTS version: v6.12.89 (Saeed Mirzamohammadi)\n- LTS version: v6.12.88 (Saeed Mirzamohammadi)\n- ksmbd: validate inherited ACE SID length (Shota Zaizen)\n- KVM: arm64: Wake-up from WFI when iqrchip is in userspace (Marc Zyngier)\n- tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() (David Carlier)\n- wifi: mt76: mt7925: fix incorrect TLV length in CLC command (Quan Zhou)\n- net: stmmac: Prevent NULL deref when RX memory exhausted (Sam Edwards)\n- net: stmmac: rename STMMAC_GET_ENTRY() - STMMAC_NEXT_ENTRY() (Russell King (Oracle))\n- net: stmmac: avoid shadowing global buf_sz (Russell King (Oracle))\n- ALSA: aloop: Fix peer runtime UAF during format-change stop (Cassio Gabriel)\n- crypto: caam - guard HMAC key hex dumps in hash_digest_key (Thorsten Blum)\n- printk: add print_hex_dump_devel() (Thorsten Blum)\n- erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() (Junrui Luo)\n- erofs: tidy up z_erofs_lz4_handle_overlap() (Gao Xiang)\n- erofs: move {in,out}pages into struct z_erofs_decompress_req (Gao Xiang)\n- crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx (Thorsten Blum)\n- hfsplus: fix held lock freed on hfsplus_fill_super() (Zilin Guan)\n- hfsplus: fix uninit-value by validating catalog record size (Deepanshu Kartikey)\n- mtd: spinand: winbond: Declare the QE bit on W25NxxJW (Miquel Raynal)\n- udf: fix partition descriptor append bookkeeping (Seohyeon Maeng)\n- mmc: core: Optimize time for secure erase/trim for some Kingston eMMCs (Luke Wang)\n- octeon_ep_vf: add NULL check for napi_build_skb() (David Carlier)\n- hwmon: (powerz) Avoid cacheline sharing for DMA buffer (Thomas Weissschuh)\n- dma-mapping: add __dma_from_device_group_begin()/end() (Michael S. Tsirkin)\n- dma-mapping: drop unneeded includes from dma-mapping.h (Christoph Hellwig)\n- fs: prepare for adding LSM blob to backing_file (Amir Goldstein)\n- fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info (Thomas Zimmermann)\n- bpf: Fix use-after-free in arena_vm_close on fork (Alexei Starovoitov)\n- LoongArch: Use per-root-bridge PCIH flag to skip mem resource fixup (Huacai Chen)\n- LoongArch: KVM: Use kvm_set_pte() in kvm_flush_pte() (Tao Cui)\n- LoongArch: KVM: Move unconditional delay into timer clear scenery (Bibo Mao)\n- LoongArch: KVM: Fix HW timer interrupt lost when inject interrupt by software (Bibo Mao)\n- LoongArch: KVM: Fix 'unreliable stack' for kvm_exc_entry (Xianglai Li)\n- LoongArch: KVM: Cap KVM_CAP_NR_VCPUS by KVM_CAP_MAX_VCPUS (Qiang Ma)\n- KVM: arm64: Fix initialisation order in __pkvm_init_finalise() (Quentin Perret)\n- KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (David Woodhouse)\n- f2fs: fix uninitialized kobject put in f2fs_init_sysfs() (Guangshuo Li)\n- f2fs: fix node_cnt race between extent node destroy and writeback (Yongpeng Yang)\n- f2fs: fix incorrect multidevice info in trace_f2fs_map_blocks() (Yongpeng Yang)\n- f2fs: fix fiemap boundary handling when read extent cache is incomplete (Yongpeng Yang)\n- f2fs: add READ_ONCE() for i_blocks in f2fs_update_inode() (Cen Zhang)\n- mptcp: fix scheduling with atomic in timestamp sockopt (Gang Yan)\n- mptcp: sockopt: set timestamp flags on subflow socket, not msk (Gang Yan)\n- mptcp: use MPTCP_RST_EMPTCP for ACK HMAC validation failure (Shardul Bankar)\n- mptcp: use MPJoinSynAckHMacFailure for SynAck HMAC failure (Shardul Bankar)\n- mptcp: fastclose msk when linger time is 0 (Matthieu Baerts (NGI0))\n- selftests: mptcp: pm: restrict 'unknown' check to pm_nl_ctl (Matthieu Baerts (NGI0))\n- selftests: mptcp: check output: catch cmd errors (Matthieu Baerts (NGI0))\n- RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (Jason Gunthorpe)\n- RDMA/rxe: Reject unknown opcodes before ICRC processing (Michael Bommarito)\n- RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (Michael Bommarito)\n- RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() (Jason Gunthorpe)\n- RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (Junrui Luo)\n- RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (Jason Gunthorpe)\n- RDMA/mana: Validate rx_hash_key_len (Jason Gunthorpe)\n- RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss() (Jason Gunthorpe)\n- RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() (Jason Gunthorpe)\n- power: supply: max17042: avoid overflow when determining health (Andre Draszik)\n- PCI/ASPM: Fix pci_clear_and_set_config_dword() usage (Lukas Wunner)\n- PCI/AER: Stop ruling out unbound devices as error source (Lukas Wunner)\n- PCI/AER: Clear only error bits in PCIe Device Status (Shuai Xue)\n- PCI: Update saved_config_space upon resource assignment (Lukas Wunner)\n- mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock (SeongJae Park)\n- KVM: x86: check for nEPT/nNPT in slow flush hypercalls (Paolo Bonzini)\n- smb: client: validate dacloffset before building DACL pointers (Michael Bommarito)\n- smb: client: use kzalloc to zero-initialize security descriptor buffer (Bjoern Doebel)\n- smb/client: fix out-of-bounds read in symlink_data() (Zisen Ye)\n- smb/client: fix out-of-bounds read in smb2_compound_op() (Zisen Ye)\n- s390/debug: Reject zero-length input in debug_input_flush_fn() (Vasily Gorbik)\n- RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (Jason Gunthorpe)\n- pmdomain: core: Fix detach procedure for virtual devices in genpd (Ulf Hansson)\n- nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free (Chaitanya Kulkarni)\n- nvmet-tcp: fix race between ICReq handling and queue teardown (Chaitanya Kulkarni)\n- nvme-apple: drop invalid put of admin queue reference count (Fedor Pchelkin)\n- md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (Junrui Luo)\n- libceph: Fix slab-out-of-bounds access in auth message processing (Raphael Zimmer)\n- lib/scatterlist: fix temp buffer in extract_user_to_sg() (Christian A. Ehrhardt)\n- lib/scatterlist: fix length calculations in extract_kvec_to_sg (Christian A. Ehrhardt)\n- lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (Lukas Wunner)\n- iommu/arm-smmu-v3: Add a missing dma_wmb() for hitless STE update (Nicolin Chen)\n- isofs: validate block number from NFS file handle in isofs_export_iget (Michael Bommarito)\n- isofs: validate Rock Ridge CE continuation extent against volume size (Michael Bommarito)\n- dm-verity-fec: correctly reject too-small hash devices (Eric Biggers)\n- dm-verity-fec: correctly reject too-small FEC devices (Eric Biggers)\n- eventfs: Hold eventfs_mutex and SRCU when remount walks events (David Carlier)\n- dm: fix a buffer overflow in ioctl processing (Mikulas Patocka)\n- dm: don't report warning when doing deferred remove (Mikulas Patocka)\n- dm-thin: fix metadata refcount underflow (Mikulas Patocka)\n- btrfs: fix double free in create_space_info() error path (Guangshuo Li)\n- ASoC: qcom: q6apm: remove child devices when apm is removed (Srinivas Kandagatla)\n- ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens (Srinivas Kandagatla)\n- ASoC: qcom: q6apm-dai: reset queue ptr on trigger stop (Srinivas Kandagatla)\n- ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (Cassio Gabriel)\n- ASoC: fsl_easrc: fix comment typo (Joseph Salisbury)\n- ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (Tommaso Soncin)\n- cpuidle: powerpc: avoid double clear when breaking snooze (Shrikanth Hegde)\n- clk: microchip: mpfs-ccc: fix out of bounds access during output registration (Conor Dooley)\n- clk: imx: imx8-acm: fix flags for acm clocks (Stefan Eichenberger)\n- spi: topcliff-pch: fix use-after-free on unbind (Johan Hovold)\n- spi: topcliff-pch: fix controller deregistration (Johan Hovold)\n- thermal/drivers/sprd: Fix raw temperature clamping in sprd_thm_rawdata_to_temp (Thorsten Blum)\n- thermal/drivers/sprd: Fix temperature clamping in sprd_thm_temp_to_rawdata (Thorsten Blum)\n- thermal: core: Free thermal zone ID later during removal (Rafael J. Wysocki)\n- udf: reject descriptors with oversized CRC length (Michael Bommarito)\n- spi: microchip-core-qspi: fix controller deregistration (Johan Hovold)\n- ice: fix double free in ice_sf_eth_activate() error path (Guangshuo Li)\n- ibmveth: Disable GSO for packets with small MSS (Mingming Cao)\n- hv_sock: fix ARM64 support (Hamza Mahfooz)\n- gpio: of: clear OF_POPULATED on hog nodes in remove path (Bartosz Golaszewski)\n- extcon: ptn5150: handle pending IRQ events during system resume (Xu Yang)\n- cifs: change_conf needs to be called for session setup (Shyam Prasad N)\n- cifs: abort open_cached_dir if we don't request leases (Shyam Prasad N)\n- block: add pgmap check to biovec_phys_mergeable (Naman Jain)\n- af_unix: Reject SIOCATMARK on non-stream sockets (Jiexun Wang)\n- hwmon: (corsair-psu) Close HID device on probe errors (Myeonghun Pak)\n- clk: rk808: fix OF node reference imbalance (Johan Hovold)\n- hwmon: (ltc2992) Fix u32 overflow in power read path (Sanman Pradhan)\n- hwmon: (ltc2992) Clamp threshold writes to hardware range (Sanman Pradhan)\n- parisc: Fix IRQ leak in LASI driver (Hongling Zeng)\n- net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (Pavitra Jha)\n- ip6_gre: Use cached t-net in ip6erspan_changelink(). (Maoyi Xie)\n- net: libwx: fix VF illegal register access (Jiawen Wu)\n- sound: ua101: fix division by zero at probe (SeungJu Cheon)\n- net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo (Kai Zen)\n- mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (Tudor Ambarus)\n- KVM: arm64: Fix kvm_vcpu_initialized() macro parameter (Fuad Tabba)\n- fanotify: fix false positive on permission events (Miklos Szeredi)\n- staging: vme_user: fix root device leak on init failure (Johan Hovold)\n- spi: s3c64xx: fix NULL-deref on driver unbind (Johan Hovold)\n- spi: zynqmp-gqspi: fix controller deregistration (Johan Hovold)\n- spi: sun6i: fix controller deregistration (Johan Hovold)\n- spi: ti-qspi: fix controller deregistration (Johan Hovold)\n- spi: sun4i: fix controller deregistration (Johan Hovold)\n- spi: syncuacer: fix controller deregistration (Johan Hovold)\n- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (Siwei Zhang)\n- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (Siwei Zhang)\n- Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (Luiz Augusto von Dentz)\n- Bluetooth: btmtk: validate WMT event SKB length before struct access (Tristan Madani)\n- Bluetooth: virtio_bt: validate rx pkt_type header length (Michael Bommarito)\n- Bluetooth: virtio_bt: clamp rx length before skb_put (Michael Bommarito)\n- LoongArch: KVM: Fix missing EMULATE_FAIL in kvm_emu_mmio_read() (Tao Cui)\n- selinux: prune /sys/fs/selinux/disable (Stephen Smalley)\n- selinux: shrink critical section in sel_write_load() (Stephen Smalley)\n- selinux: don't reserve xattr slot when we won't fill it (David Windsor)\n- xfrm: ah: account for ESN high bits in async callbacks (Michael Bommarito)\n- ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (Yilin Zhu)\n- xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (Michal Kosiorek)\n- xfrm: provide message size for XFRM_MSG_MAPPING (Ruijie Li)\n- powerpc/kdump: fix KASAN sanitization flag for core_.o (Sourabh Jain)\n- ALSA: firewire-tascam: Do not drop unread control events (Cassio Gabriel)\n- ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (Takashi Iwai)\n- USB: serial: option: add Telit Cinterion LE910Cx compositions (Fabio Porcedda)\n- USB: omap_udc: DMA: Don't enable burst 4 mode (Aaro Koskinen)\n- ALSA: usb-audio: Fix UAC3 cluster descriptor size check (Cassio Gabriel)\n- ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (Takashi Iwai)\n- ALSA: usb-audio: midi2: Restart output URBs on resume (Cassio Gabriel)\n- usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (Greg Kroah-Hartman)\n- usb: usblp: fix heap leak in IEEE 1284 device ID via short response (Greg Kroah-Hartman)\n- wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (Marek Szyprowski)\n- wifi: b43: enforce bounds check on firmware key index in b43_rx() (Tristan Madani)\n- wifi: mac80211: remove station if connection prep fails (Johannes Berg)\n- wifi: ath5k: do not access array OOB (Jiri Slaby (SUSE))\n- wifi: mac80211: use safe list iteration in radar detect work (Benjamin Berg)\n- wifi: rsi: fix kthread lifetime race between self-exit and external-stop (Jeongjun Park)\n- wifi: mac80211: drop stray 'static' from fast-RX rx_result (Catherine)\n- wifi: b43legacy: enforce bounds check on firmware key index in RX path (Tristan Madani)\n- wifi: mt76: mt7921: fix ROC abort flow interruption in mt7921_roc_work (Quan Zhou)\n- wifi: mt76: mt7921: fix a potential clc buffer length underflow (Leon Yen)\n- wifi: mt76: mt7925: fix incorrect length field in txpower command (Ming Yen Hsieh)\n- wifi: mt76: mt7925: fix AMPDU state handling in mt7925_tx_check_aggr (Quan Zhou)\n- exit: prevent preemption of oopsing TASK_DEAD task (Jann Horn)\n- Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (Hyunwoo Kim)\n- net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Jamal Hadi Salim)\n- KVM: SVM: check validity of VMCB controls when returning from SMM (Paolo Bonzini)\n- net: af_key: zero aligned sockaddr tail in PF_KEY exports (Zhengchuan Liang)\n- net: txgbe: fix RTNL assertion warning when remove module (Jiawen Wu)\n- flow_dissector: do not dissect PPPoE PFC frames (Qingfang Deng)\n- KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (Sean Christopherson)\n- x86/shstk: Prevent deadlock during shstk sigreturn (Rick Edgecombe)\n- x86: shadow stacks: proper error handling for mmap lock (Linus Torvalds)\n- mm: convert mm_lock_seq to a proper seqcount (Suren Baghdasaryan)\n- ksmbd: rewrite stop_sessions() with restartable iteration (DaeMyung Kang)\n- spi: rockchip: fix controller deregistration (Johan Hovold)\n- ASoC: SOF: Don't allow pointer operations on unconfigured streams (Mark Brown)\n- iommufd: Fix a race with concurrent allocation and unmap (Sina Hassani)\n- ACPI: video: force native backlight on HP OMEN 16 (8A44) (Shivam Kalra)\n- ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (Jan Schar)\n- ACPI: scan: Use acpi_dev_put() in object add error paths (Guangshuo Li)\n- fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free (Rajat Gupta)\n- ipmi:si: Return state to normal if message allocation fails (Corey Minyard)\n- ipmi: Check event message buffer response for bad data (Corey Minyard)\n- ipmi: Add limits to event and receive message requests (Corey Minyard)\n- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (Greg Kroah-Hartman)\n\n[6.12.0-204.87.3]\n- btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (Filipe Manana)\n- cifs: Fix busy dentry used after unmounting (Zhihao Cheng)\n- smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (Henrique Carvalho)\n- net/mlx5e: Trigger neighbor resolution for unresolved destinations (Jianbo Liu)\n- net/mlx5e: Use ip6_dst_lookup instead of ipv6_dst_lookup_flow for MAC init (Jianbo Liu)\n- x86/fgraph: Fix return_to_handler regs.rsp value (Jiri Olsa)\n- tracing: Fix the bug where bpf_get_stackid returns -EFAULT on the ARM64 (Feng Yang)\n- iommu/vt-d: Draining PRQ in sva unbind path when FPD bit set (Lu Baolu)\n- ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow (Ferry Meng)\n- arm64: Kconfig: Remove selecting replaced HAVE_FUNCTION_GRAPH_RETVAL (Lukas Bulwahn)\n- riscv: fgraph: Fix stack layout to match __arch_ftrace_regs argument of ftrace_return_to_handler (Pu Lehui)\n- riscv: fgraph: Select HAVE_FUNCTION_GRAPH_TRACER depends on HAVE_DYNAMIC_FTRACE_WITH_ARGS (Pu Lehui)\n- ata: libata-scsi: do not needlessly defer commands when using PMP with FBS (Niklas Cassel)\n- ata: libata-scsi: do not use the deferred QC feature on PMPs with CBS (Niklas Cassel)\n- ata: libata-scsi: do not use the deferred QC feature for ATA_DEFER_PORT (Niklas Cassel)\n- ata: libata-scsi: improve readability of ata_scsi_qc_issue() (Niklas Cassel)\n- ata: libata-scsi: fix requeue of deferred ATA PASS-THROUGH commands (Igor Pylypiv)\n- mtd: parsers: ofpart: call of_node_get() for dedicated subpartitions (Cosmin Tanislav)\n- arm64/scs: Fix potential sign extension issue of advance_loc4 (Wentao Guan)\n- net: airoha: Add missing RX_CPU_IDX() configuration in airoha_qdma_cleanup_rx_queue() (Lorenzo Bianconi)\n- net: airoha: Implement BQL support (Lorenzo Bianconi)\n- Bluetooth: L2CAP: Fix printing wrong information if SDU length exceeds MTU (Luiz Augusto von Dentz)\n- drm/msm/dsi: fix hdisplay calculation for CMD mode panel (Pengyu Luo)\n- drm/msm/dsi: fix bits_per_pclk (Pengyu Luo)\n- drm/msm/dsi: add the missing parameter description (Pengyu Luo)\n- ALSA: core: Serialize deferred fasync state checks (Cassio Gabriel)\n- ALSA: misc: Use guard() for spin locks (Takashi Iwai)\n- drm/i915/psr: Init variable to avoid early exit from et alignment loop (Jouni Hogander)\n- LoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang() (Wentao Guan)\n- gtp: disable BH before calling udp_tunnel_xmit_skb() (David Carlier)\n- openvswitch: vport: fix self-deadlock on release of tunnel ports (Ilya Maximets) {CVE-2026-46165}\n- LoongArch: Fix SYM_SIGFUNC_START definition for 32BIT (Huacai Chen)\n- iommu/amd: serialize sequence allocation under concurrent TLB invalidations (Ankit Soni) {CVE-2026-43220}\n- iommu/amd: Use atomic64_inc_return() in iommu.c (Uros Bizjak)\n- usb: ulpi: fix memory leak on ulpi_register() error paths (Felix Gu) {CVE-2026-46109}\n- ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (Jinjie Ruan)\n- scsi: target: iscsi: Validate CHAP_R length before base64 decode (Alexandru Hossu)  [Orabug: 39445550]\n- scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (Michael Bommarito)  [Orabug: 39445550]\n- scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (Michael Bommarito)  [Orabug: 39445550]\n- scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (Michael Bommarito)  [Orabug: 39445550]\n- scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (Michael Bommarito)  [Orabug: 39445550]\n- arm64: io: Fix ioremap_encrypted() argument type (Vijay Kumar)  [Orabug: 39387242]\n- uek-rpm/config-aarch64: Enable Vera firmware and memory attribute support (Vijay Kumar)  [Orabug: 39387242]\n- NVIDIA: VR: SAUCE: arm64: Add workaround to convert MT_NORMAL_NC to Device-nGnRE (Shanker Donthineni)  [Orabug: 39387242]\n- NVIDIA: VR: SAUCE: firmware: smccc: lfa: fix work item re-initialization race (Nirmoy Das)  [Orabug: 39387242]\n- NVIDIA: VR: SAUCE: firmware: smccc: lfa: handle LFA_BUSY and improve SMC retry pacing (Vedashree Vidwans)  [Orabug: 39387242]\n- NVIDIA: VR: CCA: SAUCE: arm_pmu: Provide a mechanism for disabling the physical IRQ (Steven Price)  [Orabug: 39387242]\n- NVIDIA: VR: SAUCE: firmware: smccc: register as platform driver (Vedashree Vidwans)  [Orabug: 39387242]\n- NVIDIA: VR: SAUCE: firmware: smccc: add timeout, touch wdt (Vedashree Vidwans)  [Orabug: 39387242]\n- NVIDIA: VR: SAUCE: firmware: smccc: add support for Live Firmware Activation (LFA) (Salman Nabi)  [Orabug: 39387242]\n- NVIDIA: VR: SAUCE: iommu/arm-smmu-v3: Allow ATS to be always on (Nicolin Chen)  [Orabug: 39387242]\n- NVIDIA: VR: SAUCE: PCI: Allow ATS to be always on for non-CXL NVIDIA GPUs (Nicolin Chen)  [Orabug: 39387242]\n- NVIDIA: VR: SAUCE: PCI: Allow ATS to be always on for CXL.cache capable devices (Nicolin Chen)  [Orabug: 39387242]\n- NVIDIA: VR: SAUCE: soc/tegra: pmc: Add PMC support for Tegra410 (Kartik Rajput)  [Orabug: 39387242]\n- soc/tegra: pmc: Add Tegra264 support (Thierry Reding)  [Orabug: 39387242]\n- NVIDIA: VR: SAUCE: soc/tegra: misc: Use SMCCC to get chipid (Kartik Rajput)  [Orabug: 39387242]\n- tun: free page on build_skb failure in tun_xdp_one() (Weiming Shi)  [Orabug: 39429137]\n- tap: free page on error paths in tap_get_user_xdp() (Weiming Shi)  [Orabug: 39429137]\n- tun: free page on short-frame rejection in tun_xdp_one() (Weiming Shi)  [Orabug: 39429137]\n- uek-rpm: disable kABI size checks in debug configs (Saeed Mirzamohammadi)  [Orabug: 39442662]\n- smb: client: reject userspace cifs.spnego descriptions (Asim Viladi Oglu Manizada)  [Orabug: 39463671] {CVE-2026-46243}\n\n[6.12.0-204.87.2]\n- Reapply 'x86/kexec: add a sanity check on previous kernel's ima kexec buffer' (Harshit Mogalapalli) [Orabug: 39419018]\n- net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim) [Orabug: 39368826,39441323] {CVE-2026-43503,CVE-2026-46300}\n- net: skbuff: preserve shared-frag marker during coalescing (William Bowling) [Orabug: 39368826] {CVE-2026-46300}\n- LTS version: v6.12.87 (Sherry Yang)\n- LTS version: v6.12.86 (Sherry Yang)\n- netfilter: reject zero shift in nft_bitwise (Kai Ma) [Orabug: 39452464] {CVE-2026-46101}\n- net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (Andrea Mayer) [Orabug: 39452457] {CVE-2026-46099}\n- ALSA: caiaq: fix usb_dev refcount leak on probe failure (Deepanshu Kartikey) [Orabug: 39452739] {CVE-2026-46048}\n- drm/amdgpu: fix zero-size GDS range init on RDNA4 (Arjan van de Ven)\n- ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (Greg Kroah-Hartman) [Orabug: 39426003] {CVE-2026-43501}\n- ALSA: caiaq: Don't abort when no input device is available (Takashi Iwai)\n- ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (Takashi Iwai) [Orabug: 39452746] {CVE-2026-45992}\n- net: bonding: fix use-after-free in bond_xmit_broadcast() (Xiang Mei) [Orabug: 39205989] {CVE-2026-31419}\n- crypto: authencesn - reject short ahash digests during instance creation (Yucheng Lu) [Orabug: 39452231] {CVE-2026-46033}\n- mm: prevent droppable mappings from being locked (Anthony Yznaga)\n- spi: fix resource leaks on device setup failure (Johan Hovold) [Orabug: 39452400] {CVE-2026-46083}\n- net: qrtr: ns: Limit the total number of nodes (Manivannan Sadhasivam) [Orabug: 39452123] {CVE-2026-46003}\n- net: mctp: fix don't require received header reserved bits to be zero (Yuanzhaoming)\n- net: bridge: use a stable FDB dst snapshot in RCU readers (Zhengchuan Liang) [Orabug: 39452411] {CVE-2026-46086}\n- net: qrtr: ns: Limit the maximum number of lookups (Manivannan Sadhasivam) [Orabug: 39452207] {CVE-2026-46026}\n- net: qrtr: ns: Limit the maximum server registration per node (Manivannan Sadhasivam) [Orabug: 39410851] {CVE-2026-43491}\n- iio: frequency: admv1013: fix NULL pointer dereference on str (Antoniu Miclaus)\n- iio: frequency: admv1013: add dev variable (Antoniu Miclaus)\n- block: relax pgmap check in bio_add_page for compatible zone device pages (Naman Jain)\n- RDMA/mana_ib: Disable RX steering on RSS QP destroy (Long Li) [Orabug: 39452406] {CVE-2026-46084}\n- media: rc: igorplugusb: heed coherency rules (Oliver Neukum) [Orabug: 39452432] {CVE-2026-46091}\n- ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (Thorsten Blum)\n- media: rc: ttusbir: respect DMA coherency rules (Oliver Neukum)\n- mm/zsmalloc: copy KMSAN metadata in zs_page_migrate() (Shigeru Yoshida)\n- ALSA: aoa: i2sbus: clear stale prepared state (Cassio Gabriel)\n- ALSA: aoa: Use guard() for mutex locks (Takashi Iwai)\n- mm: migrate: requeue destination folio on deferred split queue (Usama Arif)\n- mm/migrate: move movable_ops page handling out of move_to_new_folio() (David Hildenbrand)\n- mm/migrate: factor out movable_ops page handling into migrate_movable_ops_page() (David Hildenbrand)\n- wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (Daniel Hodges) [Orabug: 39452343] {CVE-2026-46069}\n- wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (Sean Wang)\n- wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (Sean Wang)\n- thermal: core: Fix thermal zone governor cleanup issues (Rafael J. Wysocki) [Orabug: 39452186] {CVE-2026-46021}\n- ksmbd: reset rcount per connection in ksmbd_conn_wait_idle_sess_id() (Daemyung Kang)\n- ksmbd: replace connection list with hash table (Namjae Jeon)\n- ksmbd: use msleep instaed of schedule_timeout_interruptible() (Namjae Jeon)\n- f2fs: fix to do sanity check on dcc-discard_cmd_cnt conditionally (Chao Yu)\n- lib: test_hmm: evict device pages on file close to avoid use-after-free (Alistair Popple)\n- f2fs: fix UAF caused by decrementing sbi-nr_pages[] in f2fs_write_end_io() (Yongpeng Yang)\n- smb: client: validate the whole DACL before rewriting it in cifsacl (Michael Bommarito) [Orabug: 39300611] {CVE-2026-31709}\n- seg6: fix seg6 lwtunnel output redirect for L2 reduced encap mode (Andrea Mayer)\n- scsi: sd: fix missing put_disk() when device_add(disk_dev) fails (Yang Xiuwei) [Orabug: 39452100] {CVE-2026-45997}\n- rtmutex: Use waiter::task instead of current in remove_waiter() (Keenan Dong) [Orabug: 39425998] {CVE-2026-43499}\n- ntfs3: fix integer overflow in run_unpack() volume boundary check (Tobi Gaertner)\n- ntfs3: add buffer boundary checks to run_unpack() (Tobi Gaertner)\n- ktest: Fix the month in the name of the failure directory (Steven Rostedt)\n- ceph: only d_add() negative dentries when they are unhashed (Max Kellermann) [Orabug: 39452291] {CVE-2026-46052}\n- dm mirror: fix integer overflow in create_dirty_log() (Junrui Luo) [Orabug: 39452196] {CVE-2026-46023}\n- crypto: nx - Fix packed layout in struct nx842_crypto_header (Gustavo A R Silva)\n- crypto: atmel-sha204a - Fix uninitialized data access on OTP read error (Thorsten Blum)\n- crypto: atmel-sha204a - Fix potential UAF and memory leak in remove path (Thorsten Blum)\n- crypto: atmel-sha204a - Fix error codes in OTP reads (Thorsten Blum)\n- crypto: atmel-tdes - fix DMA sync direction (Thorsten Blum)\n- crypto: ccree - fix a memory leak in cc_mac_digest() (Haoxiang Li)\n- crypto: hisilicon - Fix dma_unmap_single() direction (Thomas Fourier)\n- crypto: atmel-ecc - Release client on allocation failure (Thorsten Blum)\n- crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup (Thorsten Blum)\n- crypto: arm64/aes - Fix 32-bit aes_mac_update() arg treated as 64-bit (Eric Biggers)\n- can: ucan: fix devres lifetime (Johan Hovold)\n- bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (Qiang Yu)\n- Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (Shuvam Pandey) [Orabug: 39452304] {CVE-2026-46056}\n- apparmor: use target task's context in apparmor_getprocattr() (Cengiz Can)\n- mfd: core: Preserve OF node when ACPI handle is present (Brian Mak)\n- taskstats: set version in TGID exit notifications (Yiyang Chen)\n- tcp: call sk_data_ready() after listener migration (Zhenzhong Wu) [Orabug: 39452159] {CVE-2026-46015}\n- wifi: rtl8xxxu: fix potential use of uninitialized value (Yi Cong)\n- x86/cpu: Disable FRED when PTI is forced on (Dave Hansen)\n- inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails (Chia-Ming Chang) [Orabug: 39452250] {CVE-2026-46040}\n- HID: apple: ensure the keyboard backlight is off if suspending (Aditya Garg)\n- check-uapi: link into shared objects (Arnd Bergmann)\n- md/raid5: validate payload size before accessing journal metadata (Junrui Luo) [Orabug: 39452349] {CVE-2026-46070}\n- md/raid5: fix soft lockup in retry_aligned_read() (Chia-Ming Chang) [Orabug: 39452287] {CVE-2026-46051}\n- amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (David (Ming Qiang) Wu)\n- mtd: spi-nor: sst: Fix write enable before AAI sequence (Sanjaikumar V S)\n- ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (Sohei Koyama) [Orabug: 39452269] {CVE-2026-46046}\n- ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access (Deepanshu Kartikey) [Orabug: 39452442] {CVE-2026-46094}\n- perf annotate: Use jump__delete when freeing LoongArch jumps (Rong Bao)\n- io_uring/poll: fix multishot recv missing EOF on wakeup race (Jens Axboe) {CVE-2026-23473}\n- KVM: nSVM: Always intercept VMMCALL when L2 is active (Sean Christopherson)\n- KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (Kevin Cheng) [Orabug: 39452372] {CVE-2026-46076}\n- KVM: nSVM: Add missing consistency check for nCR3 validity (Yosry Ahmed)\n- KVM: nSVM: Add missing consistency check for EFER, CR0, CR4, and CS (Yosry Ahmed)\n- KVM: nSVM: Clear tracking of L1-L2 NMI and soft IRQ on nested #VMEXIT (Yosry Ahmed)\n- KVM: nSVM: Clear EVENTINJ fields in vmcb12 on nested #VMEXIT (Yosry Ahmed)\n- KVM: nSVM: Clear GIF on nested #VMEXIT(INVALID) (Yosry Ahmed)\n- KVM: nSVM: Always inject a #GP if mapping VMCB12 fails on nested VMRUN (Yosry Ahmed)\n- KVM: nSVM: Use vcpu-arch.cr2 when updating vmcb12 on nested #VMEXIT (Yosry Ahmed)\n- KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (Yosry Ahmed)\n- KVM: SVM: Explicitly mark vmcb01 dirty after modifying VMCB intercepts (Sean Christopherson)\n- KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (Kevin Cheng) [Orabug: 39452394] {CVE-2026-46082}\n- KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (Yosry Ahmed) [Orabug: 39452061] {CVE-2026-45987}\n- KVM: nSVM: Sync NextRIP to cached vmcb12 after VMRUN of L2 (Yosry Ahmed)\n- KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (Yosry Ahmed)\n- KVM: x86: Defer non-architectural deliver of exception payload to userspace read (Sean Christopherson)\n- userfaultfd: allow registration of ranges below mmap_min_addr (Denis M. Karpov)\n- mm/damon/core: use time_in_range_open() for damos quota window start (Seongjae Park)\n- rtc: ntxec: fix OF node reference imbalance (Johan Hovold)\n- tpm: tpm_tis: stop transmit if retries are exhausted (Jacqueline Wong)\n- tpm: tpm_tis: add error logging for data transfer (Jacqueline Wong)\n- tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (Gunnar Kudrjavets)\n- tpm: Fix auth session leak in tpm2_get_random() error path (Gunnar Kudrjavets)\n- pwm: imx-tpm: Count the number of enabled channels in probe (Viorel Suman)\n- crypto: talitos - rename first/last to first_desc/last_desc (Paul Louvel)\n- crypto: talitos - fix SEC1 32k ahash request limitation (Paul Louvel)\n- firmware: google: framebuffer: Do not unregister platform device (Thomas Zimmermann)\n- xfs: fix a resource leak in xfs_alloc_buftarg() (Haoxiang Li) [Orabug: 39452131] {CVE-2026-46005}\n- arm64: dts: ti: am62-verdin: Enable pullup for eMMC data pins (Francesco Dolcini)\n- mmc: sdhci-of-dwcmshc: Disable clock before DLL configuration (Shawn Lin)\n- mmc: block: use single block write in retry (Bin Liu)\n- randomize_kstack: Maintain kstack_offset per task (Ryan Roberts)\n- hwmon: (pt5161l) Fix bugs in pt5161l_read_block_data() (Sanman Pradhan)\n- power: supply: axp288_charger: Do not cancel work before initializing it (Krzysztof Kozlowski)\n- LoongArch: Show CPU vulnerabilites correctly (Huacai Chen)\n- tpm: avoid -Wunused-but-set-variable (Arnd Bergmann)\n- extract-cert: Wrap key_pass with '#ifdef USE_PKCS11_ENGINE' (Nathan Chancellor)\n- libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (Raphael Zimmer) [Orabug: 39452201] {CVE-2026-46024}\n- ipv4: icmp: validate reply type before using icmp_pointers (Ruide Cao) [Orabug: 39452243] {CVE-2026-46037}\n- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (Hkbinbin) [Orabug: 39452259] {CVE-2026-46043}\n- drm/arcpgu: fix device node leak (Luca Ceresoli)\n- net: ks8851: Avoid excess softirq scheduling (Marek Vasut)\n- netconsole: avoid out-of-bounds access on empty string in trim_newline() (Breno Leitao)\n- net: ks8851: Reinstate disabling of BHs around IRQ handler (Marek Vasut)\n- net/smc: avoid early lgr access in smc_clc_wait_msg (Ruijie Li)\n- net: txgbe: fix firmware version check (Jiawen Wu)\n- net: qrtr: ns: Free the node during ctrl_cmd_bye() (Manivannan Sadhasivam) [Orabug: 39452246] {CVE-2026-46038}\n- arm64: dts: marvell: uDPU: add ethernet aliases (Robert Marko)\n- tools/accounting: handle truncated taskstats netlink messages (Yiyang Chen)\n- rxrpc: Fix rxkad crypto unalignment handling (David Howells) [Orabug: 39452728] {CVE-2026-46085}\n- rxrpc: Fix memory leaks in rxkad_verify_response() (David Howells)\n- iio: adc: ad7768-1: fix one-shot mode data acquisition (Jonathan Santos)\n- ALSA: pcmtest: Fix resource leaks in module init error paths (Cassio Gabriel)\n- ALSA: pcmtest: fix reference leak on failed device registration (Guangshuo Li)\n- ALSA: 6fire: Fix input volume change detection (Cassio Gabriel)\n- ALSA: caiaq: Handle probe errors properly (Takashi Iwai) [Orabug: 39452126] {CVE-2026-46004}\n- ALSA: caiaq: Fix control_put() result and cache rollback (Cassio Gabriel)\n- ALSA: core: Fix potential data race at fasync handling (Takashi Iwai)\n- io_uring/poll: ensure EPOLL_ONESHOT is propagated for EPOLL_URING_WAKE (Jens Axboe)\n- io_uring/poll: fix signed comparison in io_poll_get_ownership() (Longxuan Yu)\n- iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (David Lechner)\n- io_uring/timeout: check unused sqe fields (Pavel Begunkov)\n- block: fix zone write plugs refcount handling in disk_zone_wplug_schedule_bio_work() (Damien Le Moal)\n- rbd: fix null-ptr-deref when device_add_disk() fails (Dawei Feng) [Orabug: 39452385] {CVE-2026-46079}\n- selftests/landlock: Fix format warning for __u64 in net_test (Mickael Salaun)\n- selftests/mqueue: Fix incorrectly named file (Simon Liebold)\n- sched: Use u64 for bandwidth ratio calculations (Joseph Salisbury)\n- remoteproc: xlnx: Only access buffer information if IPI is buffered (Ben Levinsky)\n- parisc: _llseek syscall is only available for 32-bit userspace (Helge Deller)\n- nvme: respect NVME_QUIRK_DISABLE_WRITE_ZEROES when wzsl is set (Robert Beckett)\n- nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (Robert Beckett)\n- mtd: docg3: fix use-after-free in docg3_release() (James Kim)\n- mfd: stpmic1: Attempt system shutdown twice in case PMIC is confused (Marek Vasut)\n- md/raid10: fix deadlock with check operation and nowait requests (Josh Hunt) [Orabug: 39452284] {CVE-2026-46050}\n- jbd2: fix deadlock in jbd2_journal_cancel_revoke() (Zhang Yi) [Orabug: 39452318] {CVE-2026-46061}\n- erofs: fix the out-of-bounds nameoff handling for trailing dirents (Gao Xiang) [Orabug: 39452380] {CVE-2026-46078}\n- ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (Cassio Gabriel)\n- ALSA: ctxfi: Add fallback to default RSR for S/PDIF (Harin Lee) [Orabug: 39452280] {CVE-2026-46049}\n- ALSA: aoa: i2sbus: fix OF node lifetime handling (Cassio Gabriel)\n- ext2: reject inodes with zero i_nlink and valid mode in ext2_iget() (Vasiliy Kovalev) [Orabug: 39452119] {CVE-2026-46002}\n- net: qrtr: ns: Fix use-after-free in driver remove() (Manivannan Sadhasivam) [Orabug: 39452274] {CVE-2026-46047}\n- media: i2c: imx219: Check return value of devm_gpiod_get_optional() in imx219_probe() (Chen Ni)\n- lib/ts_kmp: fix integer overflow in pattern length calculation (Josh Law)\n- PCI: epf-mhi: Return 0, not remaining timeout, when eDMA ops complete (Daniel Hodges)\n- Revert 'ALSA: usb: Increase volume range that triggers a warning' (Rongrong)\n- PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown (Koichiro Den)\n- crypto: atmel-sha204a - Fix OTP sysfs read and error handling (Thorsten Blum)\n- media: mtk-jpeg: fix use-after-free in release path due to uncancelled work (Fan Wu)\n- net: strparser: fix skb_head leak in strp_abort_strp() (Luxiao Xu) [Orabug: 39452468] {CVE-2026-46102}\n- net: caif: clear client service pointer on teardown (Zhengchuan Liang)\n- ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names() (Ziqing Chen) [Orabug: 39452416] {CVE-2026-46088}\n- media: amphion: Fix race between m2m job_abort and device_run (Ming Qian)\n- hwmon: (powerz) Fix missing usb_kill_urb() on signal interrupt (Sanman Pradhan)\n- of: unittest: fix use-after-free in testdrv_probe() (Xu Wang)\n- of: unittest: fix use-after-free in of_unittest_changeset() (Xu Wang)\n- crypto: pcrypt - Fix handling of MAY_BACKLOG requests (Herbert Xu) [Orabug: 39410863] {CVE-2026-43493}\n- mm/memory_hotplug: fix hwpoisoned large folio handling in do_migrate_range() (Tu Jinjiang)\n- spi: ch341: fix memory leaks on probe failures (Johan Hovold)\n- spi: imx: fix use-after-free on unbind (Johan Hovold)\n- um: drivers: call kernel_strrchr() explicitly in cow_user.c (Michael Bommarito)\n- vfio/cdx: Fix NULL pointer dereference in interrupt trigger path (Prasanna Kumar T S M)\n- vfio/cdx: Serialize VFIO_DEVICE_SET_IRQS with a per-device mutex (Alex Williamson)\n- wifi: rtw88: check for PCI upstream bridge existence (Fedor Pchelkin) [Orabug: 39452437] {CVE-2026-46092}\n- zram: do not forget to endio for partial discard requests (Sergey Senozhatsky) [Orabug: 39452420] {CVE-2026-46089}\n- ocfs2: split transactions in dio completion to avoid credit exhaustion (Heming Zhao) [Orabug: 39452388] {CVE-2026-46080}\n- device property: Make modifications of fwnode 'flags' thread safe (Douglas Anderson)\n- drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (Jesse Zhang) [Orabug: 39167551] {CVE-2026-23468}\n- drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array (Tvrtko Ursulin)\n- rust: init: fix clippy::undocumented_unsafe_blocks warnings (Miguel Ojeda)\n- padata: Remove comment for reorder_work (Herbert Xu)\n- padata: Fix pd UAF once and for all (Herbert Xu) [Orabug: 38335055] {CVE-2025-38584}\n- arm64/mm: Enable batched TLB flush in unmap_hotplug_range() (Anshuman Khandual)\n- firmware: google: framebuffer: Do not mark framebuffer as busy (Thomas Zimmermann)\n- kbuild: rust: allow clippy::uninlined_format_args (Miguel Ojeda)\n- drm/nouveau: fix nvkm_device leak on aperture removal failure (David Carlier)\n- ibmasm: fix heap over-read in ibmasm_send_i2o_message() (Tyllis Xu)\n- ibmasm: fix OOB reads in command_file_write due to missing size checks (Tyllis Xu)\n- misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt() (Tyllis Xu)\n- greybus: gb-beagleplay: fix sleep in atomic context in hdlc_tx_frames() (Weigang He)\n- greybus: gb-beagleplay: bound bootloader receive buffering (Pengpeng Hou)\n- leds: qcom-lpg: Check for array overflow when selecting the high resolution (Greg Kroah-Hartman)\n- drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (Greg Kroah-Hartman) [Orabug: 39452133] {CVE-2026-46006}\n- LoongArch: Add spectre boundry for syscall dispatch table (Greg Kroah-Hartman)\n- ALSA: usb-audio: Evaluate packsize caps at the right place (Takashi Iwai)\n- usb: chipidea: core: allow ci_irq_handler() handle both ID and VBUS change (Xu Yang)\n- usb: chipidea: otg: not wait vbus drop if use role_switch (Xu Yang)\n- usb: xhci: Make usb_host_endpoint.hcpriv survive endpoint_disable() (Michal Pecio)\n- ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (Cassio Gabriel)\n- ALSA: usb-audio: Avoid false E-MU sample-rate notifications (Cassio Gabriel)\n- ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (Cassio Gabriel) [Orabug: 39452170] {CVE-2026-46018}\n- LTS version: v6.12.85 (Sherry Yang)\n- Buffer overflow in drivers/xen/sys-hypervisor.c (Juergen Gross) [Orabug: 39305898] {CVE-2026-31786}\n- xen/privcmd: fix double free via VMA splitting (Juergen Gross) [Orabug: 39305908] {CVE-2026-31787}\n- LTS version: v6.12.84 (Sherry Yang)\n- rxrpc: Fix missing validation of ticket length in non-XDR key preparsing (Anderson Nascimento) [Orabug: 39300563] {CVE-2026-31696}\n- crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (Sean Christopherson) {CVE-2026-31697}\n- crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (Sean Christopherson) {CVE-2026-31698}\n- crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (Sean Christopherson) {CVE-2026-31699}\n- net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (Bingquan Chen) {CVE-2026-31700}\n- ALSA: caiaq: take a reference on the USB device in create_card() (Berk Cem Goksel) [Orabug: 39300586] {CVE-2026-31701}\n- ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (Cryolitia Pukngae)\n- f2fs: fix use-after-free of sbi in f2fs_compress_write_end_io() (George Saad)\n- ksmbd: use check_add_overflow() to prevent u16 DACL size overflow (Tristan Madani)\n- ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment (Tristan Madani)\n- ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl() (Michael Bommarito)\n- ksmbd: validate response sizes in ipc_validate_msg() (Michael Bommarito)\n- smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path (Michael Bommarito) [Orabug: 39300607] {CVE-2026-31708}\n- smb: client: require a full NFS mode SID before reading mode bits (Michael Bommarito) [Orabug: 39343707] {CVE-2026-43350}\n- smb: server: fix max_connections off-by-one in tcp accept path (Daemyung Kang)\n- smb: server: fix active_num_conn leak on transport allocation failure (Michael Bommarito)\n- ksmbd: require minimum ACE size in smb_check_perm_dacl() (Michael Bommarito)\n- fuse: quiet down complaints in fuse_conn_limit_write (Darrick J. Wong)\n- fuse: Check for large folio with SPLICE_F_MOVE (Bernd Schubert)\n- fuse: reject oversized dirents in page cache (Samuel Page) [Orabug: 39300556] {CVE-2026-31694}\n- f2fs: fix to avoid memory leak in f2fs_rename() (Chao Yu)\n- fs/ntfs3: validate rec-used in journal-replay file record check (Greg Kroah-Hartman)\n- scripts/dtc: Remove unused dts_version in dtc-lexer.l (Nathan Chancellor)\n- ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger (Namjae Jeon)\n- mm/pagewalk: fix race between concurrent split and refault (Max Boone) [Orabug: 39250782] {CVE-2026-31456}\n- scripts: generate_rust_analyzer.py: define scripts (Tamir Duberstein)\n- drm/amdgpu: replace PASID IDR with XArray (Mikhail Gavrilov)\n- net: ethernet: mtk_eth_soc: initialize PPE per-tag-layer MTU registers (Daniel Golle)\n- rust: warn on bindgen  0.69.5 and libclang = 19.1 (Miguel Ojeda)\n- wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (Felix Fietkau) [Orabug: 39167472] {CVE-2026-23444}\n- ima: do not copy measurement list to kdump kernel (Steven Chen)\n- ima: verify if the segment size has changed (Steven Chen)\n- PCI: endpoint: pci-epf-vntb: Remove duplicate resource teardown (Koichiro Den)\n- mm/userfaultfd: fix hugetlb fault mutex hash calculation (Jianhui Zhou) [Orabug: 39273453] {CVE-2026-31575}\n- LTS version: v6.12.83 (Sherry Yang)\n- ipv6: add NULL checks for idev in SRv6 paths (Heminhong) [Orabug: 39167467] {CVE-2026-23442}\n- PCI: Fix placement of pci_save_state() in pci_bus_add_device() (Lukas Wunner)\n- rxrpc: Fix key quota calculation for multitoken keys (David Howells)\n- ocfs2: fix out-of-bounds write in ocfs2_write_end_inline (Joseph Qi) [Orabug: 39331090] {CVE-2026-43075}\n- ocfs2: validate inline data i_size during inode read (Deepanshu Kartikey) [Orabug: 39331097] {CVE-2026-43076}\n- ocfs2: add inline inode consistency check to ocfs2_validate_inode_block() (Dmitry Antipov)\n- media: hackrf: fix to not free memory after the device is registered in hackrf_probe() (Jeongjun Park)\n- media: vidtv: fix pass-by-value structs causing MSAN warnings (Abd-Alrhman Masalkhi)\n- nilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map (Deepanshu Kartikey)\n- media: as102: fix to not free memory after the device is registered in as102_usb_probe() (Jeongjun Park) [Orabug: 39273467] {CVE-2026-31578}\n- bcache: fix cached_dev.sb_bio use-after-free and crash (Mingzhe Zou) [Orabug: 39273481] {CVE-2026-31580}\n- ALSA: 6fire: fix use-after-free on disconnect (Berk Cem Goksel) [Orabug: 39273486] {CVE-2026-31581}\n- hwmon: (powerz) Fix use-after-free on USB disconnect (Sanman Pradhan)\n- media: em28xx: fix use-after-free in em28xx_v4l2_open() (Abhishek Kumar) [Orabug: 39273493] {CVE-2026-31583}\n- media: mediatek: vcodec: fix use-after-free in encoder release path (Fan Wu)\n- media: vidtv: fix nfeeds state corruption on start_streaming failure (Ruslan Valiyev)\n- mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (Breno Leitao) [Orabug: 39273507] {CVE-2026-31586}\n- mm/kasan: fix double free for kasan pXds (Ritesh Harjani)\n- ASoC: qcom: q6apm: move component registration to unmanaged version (Srinivas Kandagatla)\n- KVM: x86: Use scratch field in MMIO fragment to hold small write values (Sean Christopherson) [Orabug: 39273521] {CVE-2026-31588}\n- x86-64/arm64/powerpc: clean up and rename __copy_from_user_flushcache (Linus Torvalds)\n- x86: rename and clean up __copy_from_user_inatomic_nocache() (Linus Torvalds)\n- x86-64: rename misleadingly named '__copy_user_nocache()' function (Linus Torvalds) [Orabug: 39323162] {CVE-2026-43073}\n- checkpatch: add support for Assisted-by tag (Sasha Levin)\n- KVM: x86: Use __DECLARE_FLEX_ARRAY() for UAPI structures with VLAs (David Woodhouse)\n- KVM: Remove subtle 'struct kvm_stats_desc' pseudo-overlay (Sean Christopherson)\n- kernel: be more careful about dup_mmap() failures and uprobe registering (Liam R. Howlett) {CVE-2025-21709}\n- net: sched: fix TCF_LAYER_TRANSPORT handling in tcf_get_base_ptr() (Eric Dumazet)\n- gpiolib: fix race condition for gdev-srcu (Pawel Narewski) [Orabug: 38887677] {CVE-2026-22986}\n- gpiolib: unify two loops initializing GPIO descriptors (Bartosz Golaszewski)\n- KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (Sean Christopherson) [Orabug: 39273529] {CVE-2026-31590}\n- KVM: SEV: Disallow LAUNCH_FINISH if vCPUs are actively being created (Sean Christopherson)\n- KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU (Sean Christopherson) [Orabug: 39273553] {CVE-2026-31593}\n- PCI: endpoint: pci-epf-vntb: Stop cmd_handler work in epf_ntb_epc_cleanup (Koichiro Den)\n- ocfs2: handle invalid dinode in ocfs2_group_extend (Zhengyuan Huang) [Orabug: 39273569] {CVE-2026-31596}\n- ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY (Tejas Bharambe) [Orabug: 39273578] {CVE-2026-31597}\n- ocfs2: fix possible deadlock between unlink and dio_end_io_write (Joseph Qi) [Orabug: 39273586] {CVE-2026-31598}\n- media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections (Ruslan Valiyev)\n- dcache: Limit the minimal number of bucket to two (Zhihao Cheng) [Orabug: 39323133] {CVE-2026-43071}\n- ALSA: ctxfi: Limit PTP to a single page (Harin Lee) [Orabug: 39273608] {CVE-2026-31602}\n- Docs/admin-guide/mm/damon/reclaim: warn commit_inputs vs param updates race (Seongjae Park)\n- USB: serial: option: add Telit Cinterion FN990A MBIM composition (Fabio Porcedda)\n- staging: sm750fb: fix division by zero in ps_to_hz() (Junrui Luo)\n- wifi: rtw88: fix device leak on probe failure (Johan Hovold) [Orabug: 39273620] {CVE-2026-31604}\n- scripts: generate_rust_analyzer.py: avoid FD leak (Tamir Duberstein)\n- fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (Greg Kroah-Hartman)\n- usb: port: add delay after usb_hub_set_port_power() (Xu Yang)\n- usb: gadget: f_hid: don't call cdev_init while cdev in use (Michael Zimmermann)\n...","id":"ELSA-2026-50372","ovalId":"oval:com.oracle.elsa:def:202650372","source":"oracle_linux","title":"ELSA-2026-50372: Unbreakable Enterprise kernel security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-50372.html"}