{"cves":["CVE-2022-50073","CVE-2025-10263","CVE-2026-31657","CVE-2026-46331","CVE-2026-52943","CVE-2026-53359"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[5.15.0-322.203.3.2]\n- KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (Sean Christopherson)  [Orabug: 39673886] \n- KVM: x86: Fix shadow paging use-after-free due to unexpected role (Paolo Bonzini)  [Orabug: 39673886] \n- KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (Sean Christopherson)  [Orabug: 39673886] \n- KVM: x86/mmu: pull call to drop_large_spte() into __link_shadow_page() (Paolo Bonzini)  [Orabug: 39673886] \n- KVM: x86/mmu: Always pass 0 for @quadrant when gptes are 8 bytes (Paolo Bonzini)  [Orabug: 39673886] \n- KVM: x86/mmu: Derive shadow MMU page role from parent (Paolo Bonzini)  [Orabug: 39673886] \n- KVM: x86/mmu: Stop passing 'direct' to mmu_alloc_root() (David Matlack)  [Orabug: 39673886] \n- KVM: x86/mmu: Use a bool for direct (David Matlack)  [Orabug: 39673886] \n- net/sched: act_pedit: free pedit keys on bail from offset check (Pedro Tammela)  [Orabug: 39668793] \n- net/sched: fix pedit partial COW leading to page cache corruption (Rajat Gupta)  [Orabug: 39668793]  {CVE-2026-46331}\n- net/sched: act_pedit: rate limit datapath messages (Pedro Tammela)  [Orabug: 39668793] \n- net/sched: act_pedit: check static offsets a priori (Pedro Tammela)  [Orabug: 39668793]\n\n[5.15.0-322.203.3.1]\n- net: skbuff: fix missing zerocopy reference in pskb_carve helpers (Minh Nguyen)  [Orabug: 39648952]  {CVE-2026-52943}\n\n[5.15.0-322.203.3]\n- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland)  [Orabug: 39548689]  {CVE-2025-10263}\n- arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland)  [Orabug: 39548689]\n- ARM: uek: Disable CONFIG_NVIDIA_CARMEL_CNP_ERRATUM (Boris Ostrovsky)  [Orabug: 39548689]\n- arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland)  [Orabug: 39548689]\n- arm64: cputype: Add C1-Premium definitions (Mark Rutland)  [Orabug: 39548689]\n- arm64: cputype: Add C1-Ultra definitions (Mark Rutland)  [Orabug: 39548689]\n- net/rds: Make 'rds_send_xmit' fairer (Gerd Rausch)  [Orabug: 39532945]\n- net/rds: Schedule rds_send_worker if there's more work to do (Gerd Rausch)  [Orabug: 39532945]\n- Revert 'rds: Change return code from rds_send_xmit() when lock is taken' (Gerd Rausch)  [Orabug: 39532945]\n- Revert 'Reapply 'rds: ib: Make sure receives are posted before connection is up'' (Gerd Rausch)  [Orabug: 39532945]\n- Revert 'rds: ib: Make sure a QP in INIT state is transitioned to ERR' (Gerd Rausch)  [Orabug: 39532945]\n- net: tap: NULL pointer derefence in dev_parse_header_protocol when skb-dev is null (Cezar Bulinaru)  [Orabug: 39526881]  {CVE-2022-50073}\n- mmc: dwcmshc_bf3_hw_reset: Log eMMC reset calls (Satyansh Shukla)  [Orabug: 39333650]\n- arm64: dts: pensando: drop elba penfw firmware node (Tom Saeger)  [Orabug: 39522954]\n- batman-adv: hold claim backbone gateways by reference (Haoze Xie)  [Orabug: 39262374]  {CVE-2026-31657}\n- rds: Drop rds conn in connect worker if not in down state. (Rohit Nair)  [Orabug: 39179363]\n\n[5.15.0-322.203.2]\n- LTS version: v5.15.203 (Vijayendra Suman)\n- io_uring/poll: correctly handle io_poll_add() return value on update (Jens Axboe)\n- ksmbd: Fix dangling pointer in krb_authenticate (Sean Heelan)\n- ksmbd: Fix refcount leak when invalid session is found on session lookup (Namjae Jeon)\n- Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ (Luiz Augusto von Dentz)\n- i2c: cp2615: fix serial string NULL-deref at probe (Johan Hovold)\n- i2c: cp2615: replace deprecated strncpy with strscpy (Justin Stitt)\n- ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() (Namjae Jeon)\n- ksmbd: fix potencial OOB in get_file_all_info() for compound requests (Namjae Jeon)\n- tracing: Fix potential deadlock in cpu hotplug with osnoise (Luo Haiyang)\n- x86/cpu: Enable FSGSBASE early in cpu_init_exception_handling() (Nikunj A Dadhania)\n- mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (Jinjiang Tu)\n- scsi: target: tcm_loop: Drain commands in target_reset handler (Josef Bacik)\n- net: macb: Move devm_{free,request}_irq() out of spin lock area (Kevin Hao)\n- dmaengine: sh: rz-dmac: Protect the driver specific lists (Claudiu Beznea)\n- dmaengine: sh: rz-dmac: Move CHCTRL updates under spinlock (Claudiu Beznea)\n- xfs: save ailp before dropping the AIL lock in push callbacks (Yuto Ohnuki)\n- ext4: fix use-after-free in update_super_work when racing with umount (Jiayuan Chen)\n- ext4: fix the might_sleep() warnings in kvfree() (Zqiang)\n- ext4: publish jinode after initialization (Li Chen)\n- usb: gadget: uvc: fix NULL pointer dereference during unbind race (Jimmy Hu)\n- usb: gadget: u_ether: Fix race between gether_disconnect and eth_stop (Kuen-Han Tsai)\n- usb: gadget: f_hid: move list and spinlock inits from bind to alloc (Michael Zimmermann)\n- net: rfkill: prevent unlimited numbers of rfkill events from being created (Greg Kroah-Hartman)\n- seg6: separate dst_cache for input and output paths in seg6 lwtunnel (Andrea Mayer)\n- Revert 'mptcp: add needs_id for netlink appending addr' (Matthieu Baerts (NGI0))\n- xen/privcmd: unregister xenstore notifier on module exit (GuoHan Zhao)\n- netlink: add nla be16/32 types to minlen array (Florian Westphal)\n- rxrpc: Fix key/keyring checks in setsockopt(RXRPC_SECURITY_KEY/KEYRING) (David Howells)\n- rxrpc: fix reference count leak in rxrpc_server_keyring() (Luxiao Xu)\n- net: stmmac: fix integer underflow in chain mode (Tyllis Xu)\n- net: qualcomm: qca_uart: report the consumed byte on RX skb allocation failure (Pengpeng Hou)\n- mmc: vub300: fix NULL-deref on disconnect (Johan Hovold)\n- drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (Sebastian Brzezinka)\n- net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (David Carlier)\n- net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (Muhammad Alifa Ramdhan)\n- batman-adv: reject oversized global TT response buffers (Ruide Cao)\n- nfc: pn533: allocate rx skb before consuming bytes (Pengpeng Hou)\n- arm64: dts: hisilicon: hi3798cv200: Add missing dma-ranges (Shawn Guo)\n- arm64: dts: hisilicon: poplar: Correct PCIe reset GPIO polarity (Shawn Guo)\n- wifi: brcmsmac: Fix dma_free_coherent() size (Thomas Fourier)\n- tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (Oleh Konko)\n- netfilter: nft_ct: fix use-after-free in timeout object destroy (Tuan Do)\n- apparmor: fix race between freeing data and fs accessing it (John Johansen)\n- apparmor: fix race on rawdata dereference (John Johansen)\n- apparmor: fix differential encoding verification (John Johansen)\n- apparmor: fix unprivileged local user can do privileged policy management (John Johansen)\n- apparmor: Fix double free of ns_name in aa_replace_profiles() (John Johansen)\n- apparmor: fix missing bounds check on DEFAULT table in verify_dfa() (Massimiliano Pellizzer)\n- apparmor: fix side-effect bug in match_char() macro usage (Massimiliano Pellizzer)\n- apparmor: fix: limit the number of levels of policy namespaces (John Johansen)\n- apparmor: replace recursive profile removal with iterative approach (Massimiliano Pellizzer)\n- apparmor: fix memory leak in verify_header (Massimiliano Pellizzer)\n- apparmor: validate DFA start states are in bounds in unpack_pdb (Massimiliano Pellizzer)\n- iio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xfer (Nuno Sa)\n- gpiolib: cdev: fix uninitialised kfifo (Kent Gibson)\n- media: uvcvideo: Use heuristic to find stream entity (Ricardo Ribalda)\n- media: uvcvideo: Mark invalid entities with id UVC_INVALID_ENTITY_ID (Thadeu Lima de Souza Cascardo)\n- Input: uinput - take event lock when submitting FF request 'event' (Dmitry Torokhov)\n- Input: uinput - fix circular locking dependency with ff-core (Mikhail Gavrilov)\n- mptcp: fix slab-use-after-free in __inet_lookup_established (Jiayuan Chen)\n- xfrm_user: fix info leak in build_report() (Greg Kroah-Hartman)\n- wifi: rt2x00usb: fix devres lifetime (Johan Hovold)\n- lib/crypto: chacha: Zeroize permuted_state before it leaves scope (Eric Biggers)\n- wifi: virt_wifi: remove SET_NETDEV_DEV to avoid use-after-free (Alexander Popov)\n- io_uring/tctx: work around xa_store() allocation error issue (Jens Axboe)\n- usb: gadget: f_uac1_legacy: validate control request size (Taegu Ha)\n- usb: gadget: f_rndis: Protect RNDIS options with mutex (Kuen-Han Tsai)\n- usb: gadget: f_subset: Fix unbalanced refcnt in geth_free (Kuen-Han Tsai)\n- staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser (Navaneeth K)\n- smb: client: Fix refcount leak for cifs_sb_tlink (Shuhao Fu)\n- net: mctp: Don't access ifa_index when missing (Matt Johnston)\n- fbcon: Set fb_display[i]-mode to NULL when the mode is released (Quanmin Yan)\n- can: gs_usb: gs_usb_receive_bulk_callback(): fix error message (Marc Kleine-Budde)\n- can: gs_usb: gs_usb_receive_bulk_callback(): unanchor URL on usb_submit_urb() error (Marc Kleine-Budde)\n- can: gs_usb: gs_usb_receive_bulk_callback(): fix URB memory leak (Marc Kleine-Budde)\n- usb: gadget: dummy_hcd: fix premature URB completion when ZLP follows partial transfer (Sebastian Urban)\n- USB: dummy-hcd: Fix interrupt synchronization error (Alan Stern)\n- USB: dummy-hcd: Fix locking/synchronization error (Alan Stern)\n- thunderbolt: Fix property read in nhi_wake_supported() (Konrad Dybcio)\n- net: ftgmac100: fix ring allocation unwind on open failure (Yufan Chen)\n- vxlan: validate ND option lengths in vxlan_na_create (Yang Yang)\n- netfilter: ipset: drop logically empty buckets in mtype_del (Yifan Wu)\n- comedi: me4000: Fix potential overrun of firmware buffer (Ian Abbott)\n- comedi: me_daq: Fix potential overrun of firmware buffer (Ian Abbott)\n- comedi: ni_atmio16d: Fix invalid clean-up after failed attach (Ian Abbott)\n- comedi: Reinit dev-spinlock between attachments to low-level drivers (Ian Abbott)\n- comedi: dt2815: add hardware detection to prevent crash (Deepanshu Kartikey)\n- cdc-acm: new quirk for EPSON HMD (Oliver Neukum)\n- bridge: br_nd_send: validate ND option lengths (Yang Yang)\n- phy: renesas: rcar-gen3-usb2: Assert PLL reset on PHY power off (Claudiu Beznea)\n- phy: renesas: rcar-gen3-usb2: Lock around hardware registers and driver data (Claudiu Beznea)\n- phy: renesas: rcar-gen3-usb2: Move IRQ request in probe (Claudiu Beznea)\n- phy: renesas: rcar-gen3-usb2: Fix role detection on unbind/bind (Claudiu Beznea)\n- usb: cdns3: gadget: fix state inconsistency on gadget init failure (Yongchao Wu)\n- usb: cdns3: gadget: fix NULL pointer dereference in ep_queue (Yongchao Wu)\n- usb: dwc2: gadget: Fix spin_lock/unlock mismatch in dwc2_hsotg_udc_stop() (Juno Choi)\n- usb: ehci-brcm: fix sleep during atomic (Justin Chen)\n- usb: usbtmc: Flush anchored URBs in usbtmc_release (Heitor Alves de Siqueira)\n- usb: ulpi: fix double free in ulpi_register_interface() error path (Guangshuo Li)\n- usb: quirks: add DELAY_INIT quirk for another Silicon Motion flash drive (Miao Li)\n- iio: gyro: mpu3050: Fix out-of-sequence free_irq() (Ethan Tidmore)\n- iio: gyro: mpu3050: Move iio_device_register() to correct location (Ethan Tidmore)\n- iio: gyro: mpu3050: Fix irq resource leak (Ethan Tidmore)\n- iio: gyro: mpu3050: Fix incorrect free_irq() variable (Ethan Tidmore)\n- iio: imu: st_lsm6dsx: Set FIFO ODR for accelerometer and gyroscope only (Francesco Lavra)\n- iio: light: vcnl4035: fix scan buffer on big-endian (David Lechner)\n- iio: dac: ad5770r: fix error return in ad5770r_read_raw() (Antoniu Miclaus)\n- Input: xpad - add support for Razer Wolverine V3 Pro (Zoltan Illes)\n- Input: i8042 - add TUXEDO InfinityBook Max 16 Gen10 AMD to i8042 quirk table (Christoffer Sandberg)\n- Input: synaptics-rmi4 - fix a locking bug in an error path (Bart Van Assche)\n- USB: core: add NO_LPM quirk for Razer Kiyo Pro webcam (JP Hein)\n- USB: serial: option: add support for Rolling Wireless RW135R-GL (Wanquan Zhong)\n- USB: serial: io_edgeport: add support for Blackbox IC135A (Frej Drejhammar)\n- drm/ast: dp501: Fix initialization of SCU2C (Thomas Zimmermann)\n- hwmon: (occ) Fix division by zero in occ_show_power_1() (Sanman Pradhan)\n- MIPS: Fix the GCC version check for __multi3' workaround (Maciej W. Rozycki)\n- Bluetooth: SMP: force responder MITM requirements before building the pairing response (Oleh Konko)\n- Bluetooth: SMP: derive legacy responder STK authentication from MITM state (Oleh Konko)\n- ALSA: ctxfi: Fix missing SPDIFI1 index handling (Takashi Iwai)\n- ALSA: caiaq: fix stack out-of-bounds read in init_card (Berk Cem Goksel)\n- USB: serial: option: add MeiG Smart SRM825WN (Ernestas Kulik)\n- wifi: wilc1000: fix u8 overflow in SSID scan buffer size calculation (Yasuaki Torimaru)\n- drm/ioc32: stop speculation on the drm_compat_ioctl path (Greg Kroah-Hartman)\n- riscv: kgdb: fix several debug register assignment bugs (Paul Walmsley)\n- hwmon: (occ) Fix missing newline in occ_show_extended() (Sanman Pradhan)\n- hwmon: (tps53679) Fix device ID comparison and printing in tps53676_identify() (Sanman Pradhan)\n- hwmon: (pxe1610) Check return value of page-select write in probe (Sanman Pradhan)\n- bpf: reject direct access to nullable PTR_TO_BUF pointers (Qi Tang)\n- ipv6: avoid overflows in ip6_datagram_send_ctl() (Eric Dumazet)\n- net/sched: cls_flow: fix NULL pointer dereference on shared blocks (Xiang Mei)\n- net/sched: cls_fw: fix NULL pointer dereference on shared blocks (Xiang Mei)\n- net/x25: Fix overflow when accumulating packets (Martin Schiller)\n- net/x25: Fix potential double free of skb (Martin Schiller)\n- net/mlx5: Avoid 'No data available' when FW version queries fail (Saeed Mahameed)\n- net: macb: properly unregister fixed rate clocks (Fedor Pchelkin)\n- net: macb: fix clk handling on PCI glue driver removal (Fedor Pchelkin)\n- Bluetooth: MGMT: validate LTK enc_size on load (Keenan Dong)\n- netfilter: nf_tables: reject immediate NF_QUEUE verdict (Pablo Neira Ayuso)\n- netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP (Pablo Neira Ayuso)\n- netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (Qi Tang)\n- netfilter: nf_conntrack_helper: pass helper to expect cleanup (Qi Tang)\n- netfilter: ipset: use nla_strcmp for IPSET_ATTR_NAME attr (Florian Westphal)\n- netfilter: x_tables: ensure names are nul-terminated (Florian Westphal)\n- netfilter: nfnetlink_log: account for netlink header size (Florian Westphal)\n- netfilter: flowtable: strictly check for maximum number of actions (Pablo Neira Ayuso)\n- net: ipv6: flowlabel: defer exclusive option free until RCU teardown (Zhengchuan Liang)\n- bpf: Fix regsafe() for pointers to packet (Alexei Starovoitov)\n- net: xilinx: axienet: Correct BD length masks to match AXIDMA IP spec (Suraj Gupta)\n- NFC: pn533: bound the UART receive buffer (Pengpeng Hou)\n- net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (Yochai Eisenrich)\n- ipv6: prevent possible UaF in addrconf_permanent_addr() (Paolo Abeni)\n- net/sched: sch_hfsc: fix divide-by-zero in rtsc_min() (Xiang Mei)\n- bridge: br_nd_send: linearize skb before parsing ND options (Yang Yang)\n- ip6_tunnel: clear skb2-cb[] in ip4ip6_err() (Eric Dumazet)\n- ipv6: icmp: clear skb2-cb[] in ip6_err_gen_icmpv6_unreach() (Eric Dumazet)\n- tg3: Fix race for querying speed/duplex (Thomas Bogendoerfer)\n- net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak (Yochai Eisenrich)\n- net: qrtr: replace qrtr_tx_flow radix_tree with xarray to fix memory leak (Jiayuan Chen)\n- crypto: af-alg - fix NULL pointer dereference in scatterwalk (Norbert Szetei)\n- dt-bindings: auxdisplay: ht16k33: Use unevaluatedProperties to fix common property warning (Frank Li)\n- btrfs: reject root items with drop_progress and zero drop_level (ZhengYuan Huang)\n- HID: multitouch: Check to ensure report responses match the request (Lee Jones)\n- objtool: Fix Clang jump table detection (Josh Poimboeuf)\n- btrfs: don't take device_list_mutex when querying zone info (Johannes Thumshirn)\n- atm: lec: fix use-after-free in sock_def_readable() (Deepanshu Kartikey)\n- HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (Benoit Sevens)\n- futex: Clear stale exiting pointer in futex_lock_pi() retry path (Davidlohr Bueso)\n- dmaengine: xilinx_dma: Fix reset related timeout with two-channel AXIDMA (Tomi Valkeinen)\n- dmaengine: xilinx_dma: Program interrupt delay timeout (Radhey Shyam Pandey)\n- dmaengine: idxd: Fix freeing the allocated ida too late (Vinicius Costa Gomes)\n- btrfs: fix lost error when running device stats on multiple devices fs (Filipe Manana)\n- btrfs: fix super block offset in error message in btrfs_validate_super() (Mark Harmstone)\n- dmaengine: xilinx: xilinx_dma: Fix unmasked residue subtraction (Marek Vasut)\n- dmaengine: xilinx: xilinx_dma: Fix residue calculation for cyclic DMA (Marek Vasut)\n- dmaengine: xilinx: xilinx_dma: Fix dma_device directions (Marek Vasut)\n- phy: ti: j721e-wiz: Fix device node reference leak in wiz_get_lane_phy_types() (Felix Gu)\n- ext4: always drain queued discard work in ext4_mb_release() (Theodore Ts'o)\n- ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (Baokun Li)\n- ext4: reject mount if bigalloc with s_first_data_block != 0 (Helen Koike)\n- ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (Ye Bin)\n- ext4: make recently_deleted() properly work with lazy itable initialization (Jan Kara)\n- ext4: convert inline data to extents when truncate exceeds inline size (Deepanshu Kartikey)\n- xfs: stop reclaim before pushing AIL during unmount (Yuto Ohnuki)\n- jbd2: gracefully abort on checkpointing state corruptions (Milos Nikic)\n- scsi: ses: Handle positive SCSI error from ses_recv_diag() (Greg Kroah-Hartman)\n- scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (Tyllis Xu)\n- alarmtimer: Fix argument order in alarm_timer_forward() (Zhan Xusheng)\n- erofs: add GFP_NOIO in the bio completion if needed (Jiucheng Xu)\n- virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false (xietangxin)\n- media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex (Yuchan Nam)\n- cpufreq: conservative: Reset requested_freq on limits change (Viresh Kumar)\n- can: gw: fix OOB heap access in cgw_csum_crc8_rel() (Ali Norouzi)\n- s390/barrier: Make array_index_mask_nospec() __always_inline (Vasily Gorbik)\n- s390/syscalls: Add spectre boundary for syscall dispatch table (Greg Kroah-Hartman)\n- spi: spi-fsl-lpspi: fix teardown order issue (UAF) (Marc Kleine-Budde)\n- ASoC: adau1372: Fix clock leak on PLL lock failure (Jihed Chaibi)\n- ASoC: adau1372: Fix unchecked clk_prepare_enable() return value (Jihed Chaibi)\n- sysctl: fix uninitialized variable in proc_do_large_bitmap (Marc Buerg)\n- hwmon: (adm1177) fix sysfs ABI violation and current unit conversion (Sanman Pradhan)\n- ACPI: EC: Fix ECDT probe ordering issues (Hans de Goede)\n- ACPI: EC: Fix EC address space handler unregistration (Hans de Goede)\n- ACPICA: Allow address_space_handler Install and _REG execution as 2 separate steps (Hans de Goede)\n- ACPICA: include/acpi/acpixf.h: Fix indentation (Hans de Goede)\n- ASoC: Intel: catpt: Fix the device initialization (Cezary Rojewski)\n- drm/i915/gmbus: fix spurious timeout on 512-byte burst reads (Samasth Norway Ananda)\n- x86/efi: efi_unmap_boot_services: fix calculation of ranges_to_free size (Mike Rapoport (Microsoft))\n- scsi: scsi_transport_sas: Fix the maximum channel scanning issue (Yihang Li)\n- RDMA/irdma: Return EINVAL for invalid arp index error (Tatyana Nikolova)\n- RDMA/irdma: Fix deadlock during netdev reset with active connections (Anil Samal)\n- RDMA/irdma: Remove reset check from irdma_modify_qp_to_err() (Tatyana Nikolova)\n- RDMA/irdma: Clean up unnecessary dereference of event-cm_node (Ivan Barrera)\n- RDMA/irdma: Remove a NOP wait_event() in irdma_modify_qp_roce() (Tatyana Nikolova)\n- RDMA/irdma: Update ibqp state to error if QP is already in error state (Tatyana Nikolova)\n- RDMA/rw: Fall back to direct SGE on MR pool exhaustion (Chuck Lever)\n- regmap: Synchronize cache for the page selector (Andy Shevchenko)\n- net: macb: use the current queue number for stats (Paolo Valerio)\n- netfilter: ctnetlink: use netlink policy range checks (David Carlier)\n- netlink: allow be16 and be32 types in all uint policy checks (Florian Westphal)\n- netlink: introduce bigendian integer types (Florian Westphal)\n- netfilter: nft_payload: reject out-of-range attributes via policy (Florian Westphal)\n- netlink: introduce NLA_POLICY_MAX_BE (Florian Westphal)\n- netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp (Weiming Shi)\n- netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (Ren Wei)\n- netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD (Weiming Shi)\n- Bluetooth: btusb: clamp SCO altsetting table indices (Pengpeng Hou)\n- Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite loop (Hyunwoo Kim)\n- dma-mapping: add missing inline for dma_free_attrs (Miguel Ojeda)\n- net: enetc: fix the output issue of 'ethtool --show-ring' (Wei Fang)\n- net: fix fanout UAF in packet_release() via NETDEV_UP race (Yochai Eisenrich)\n- platform/olpc: olpc-xo175-ec: Fix overflow error message to print inlen (Alok Tiwari)\n- rtnetlink: count IFLA_INFO_SLAVE_KIND in if_nlmsg_size (Sabrina Dubroca)\n- net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (Qi Tang)\n- openvswitch: validate MPLS set/set_masked payload length (Yang Yang)\n- nfc: nci: fix circular locking dependency in nci_close_device (Jakub Kicinski)\n- ionic: fix persistent MAC address override on PF (Mohammad Heib)\n- pinctrl: mediatek: common: Fix probe failure for devices without EINT (Luca Leonardo Scorcia)\n- Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb (Helen Koike)\n- Bluetooth: hci_ll: Fix firmware leak on error path (Anas Iqbal)\n- Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (Hyunwoo Kim)\n- Bluetooth: L2CAP: Validate PDU length before reading SDU length in l2cap_ecred_data_rcv() (Hyunwoo Kim)\n- can: statistics: add missing atomic access in hot path (Oliver Hartkopp)\n- af_key: validate families in pfkey_send_migrate() (Eric Dumazet)\n- esp: fix skb leak with espintcp and async crypto (Sabrina Dubroca)\n- xfrm: Fix the usage of skb-sk (Steffen Klassert)\n- xfrm: call xdo_dev_state_delete during state update (Sabrina Dubroca)\n- ALSA: hda/realtek: Add headset jack quirk for Thinkpad X390 (Uzair Mughal)\n- dma-buf: Include ioctl.h in UAPI header (Isaac J. Manjarres)\n- ASoC: fsl_easrc: Fix event generation in fsl_easrc_iec958_put_bits() (Mark Brown)\n- ASoC: fsl_easrc: Fix event generation in fsl_easrc_iec958_set_reg() (Mark Brown)\n- module: Fix kernel panic when a symbol st_shndx is out of bounds (Ihor Solodrai)\n- HID: mcp2221: cancel last I2C command on read error (Romain Sioen)\n- net: usb: r8152: add TRENDnet TUC-ET2G (Valentin Spreckels)\n- HID: magicmouse: avoid memory leak in magicmouse_report_fixup() (Gunther Noack)\n- HID: magicmouse: fix battery reporting for Apple Magic Trackpad 2 (Julius Lehmann)\n- nvme-pci: ensure we're polling a polled queue (Keith Busch)\n- platform/x86: touchscreen_dmi: Add quirk for y-inverted Goodix touchscreen on SUPI S10 (Hans de Goede)\n- platform/x86: intel-hid: Enable 5-button array on ThinkPad X1 Fold 16 Gen 1 (Leif Skunberg)\n- nvme-pci: cap queue creation to used queues (Keith Busch)\n- platform/x86: intel-hid: Add Dell 14 Plus 2-in-1 to dmi_vgbs_allow_list (Peter Metz)\n- HID: asus: avoid memory leak in asus_report_fixup() (Gunther Noack)\n- bpf: Release module BTF IDR before module unload (Kumar Kartikeya Dwivedi)\n- sh: platform_early: remove pdev-driver_override check (Danilo Krummrich)\n- xen/privcmd: add boot control for restricted usage in domU (Juergen Gross)\n- xen/privcmd: restrict usage in unprivileged domU (Juergen Gross)\n- netfilter: nft_set_pipapo: split gc into unlink and reclaim phase (Florian Westphal)\n- netfilter: nf_tables: de-constify set commit ops function argument (Florian Westphal)\n- tools/bootconfig: fix fd leak in load_xbc_file() on fstat failure (Josh Law)\n- lib/bootconfig: check xbc_init_node() return in override path (Josh Law)\n- drm/i915/gt: Check set_default_submission() before deferencing (Rahul Bukte)\n- ksmbd: fix use-after-free of share_conf in compound request (Hyunwoo Kim)\n- mtd: rawnand: brcmnand: skip DMA during panic write (Kamal Dasu)\n- mtd: rawnand: serialize lock/unlock against other NAND operations (Kamal Dasu)\n- i2c: fsi: Fix a potential leak in fsi_i2c_probe() (Christophe JAILLET)\n- hwmon: (pmbus/isl68137) Fix unchecked return value and use sysfs_emit() (Sanman Pradhan)\n- icmp: fix NULL pointer dereference in icmp_tag_validation() (Weiming Shi)\n- net: dsa: bcm_sf2: fix missing clk_disable_unprepare() in error paths (Anas Iqbal)\n- net: mvpp2: guard flow control update with global_tx_fc in buffer switching (Muhammad Hammad Ijaz)\n- nfnetlink_osf: validate individual option lengths in fingerprints (Weiming Shi)\n- net: bonding: fix NULL deref in bond_debug_rlb_hash_show (Xiang Mei)\n- udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n (Xiang Mei)\n- net: macb: fix uninitialized rx_fs_lock (Fedor Pchelkin)\n- wifi: mac80211: fix NULL deref in mesh_matches_local() (Xiang Mei)\n- igc: fix missing update of skb-tail in igc_xmit_frame() (Kohei Enju)\n- net: usb: aqc111: Do not perform PM inside suspend callback (Nikola Z. Ivanov)\n- net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() (Jiayuan Chen)\n- net/smc: Fix slab-out-of-bounds issue in fallback (Wen Gu)\n- net/smc: Only save the original clcsock callback functions (Wen Gu)\n- PM: runtime: Fix a race condition related to device removal (Bart Van Assche)\n- sched: idle: Consolidate the handling of two special cases (Rafael J. Wysocki)\n- net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown (Dipayaan Roy)\n- net: bcmgenet: increase WoL poll timeout (Justin Chen)\n- netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (Jenny Guanni Qu)\n- netfilter: xt_time: use unsigned int for monthday bit shift (Jenny Guanni Qu)\n- netfilter: xt_CT: drop pending enqueued packets on template removal (Pablo Neira Ayuso)\n- netfilter: nft_ct: drop pending enqueued packets on removal (Pablo Neira Ayuso)\n- netfilter: nft_ct: add seqadj extension for natted connections (Andrii Melnychenko)\n- netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case (Jenny Guanni Qu)\n- netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() (Lukas Johannes Moller)\n- netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() (Hyunwoo Kim)\n- netfilter: ctnetlink: remove refcounting in expectation dumpers (Florian Westphal)\n- net/rose: fix NULL pointer dereference in rose_transmit_link on reconnect (Jiayuan Chen)\n- Bluetooth: qca: fix ROM version reading on WCN3998 chips (Dmitry Baryshkov)\n- Bluetooth: HIDP: Fix possible UAF (Luiz Augusto von Dentz)\n- Bluetooth: SMP: make SM/PER/KDU/BI-04-C happy (Christian Eggers)\n- Bluetooth: LE L2CAP: Disconnect if sum of payload sizes exceed SDU (Christian Eggers)\n- Bluetooth: LE L2CAP: Disconnect if received packet's SDU exceeds IMTU (Christian Eggers)\n- firmware: arm_scpi: Fix device_node reference leak in probe path (Felix Gu)\n- of: Add cleanup.h based auto release via __free(device_node) markings (Jonathan Cameron)\n- wifi: mac80211: Fix static_branch_dec() underflow for aql_disable. (Kuniyuki Iwashima)\n- soc: fsl: qbman: fix race condition in qman_destroy_fq (Richard Genoud)\n- btrfs: tree-checker: fix misleading root drop_level error message (ZhengYuan Huang)\n- batman-adv: avoid OGM aggregation when skb tailroom is insufficient (Yang Yang)\n- pmdomain: bcm: bcm2835-power: Increase ASB control timeout (Maira Canal)\n- mptcp: pm: avoid sending RM_ADDR over same subflow (Matthieu Baerts (NGI0))\n- drm/amd/display: Use GFP_ATOMIC in dc_create_stream_for_sink (Natalie Vock)\n- net: phy: register phy led_triggers during probe to avoid AB-BA deadlock (Andrew Lunn)\n- smb: client: Don't log plaintext credentials in cifs_set_cifscreds (Thorsten Blum)\n- RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah() (Jason Gunthorpe)\n- wifi: cfg80211: cancel rfkill_block work in wiphy_unregister() (Daniil Dulov)\n- wifi: cfg80211: move scan done work to wiphy work (Johannes Berg)\n- wifi: libertas: fix use-after-free in lbs_free_adapter() (Daniel Hodges)\n- ext4: always allocate blocks only from groups inode can use (Jan Kara)\n- ksmbd: fix null pointer dereference error in generate_encryptionkey (Namjae Jeon)\n- ext4: fix dirtyclusters double decrement on fs shutdown (Brian Foster)\n- ext4: drop extent cache when splitting extent fails (Zhang Yi)\n- ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (Zhang Yi)\n- ksmbd: call ksmbd_vfs_kern_path_end_removing() on some error paths (Fedor Pchelkin)\n- drm/exynos: vidi: use ctx-lock to protect struct vidi_context member variables related to memory alloc/free (Jeongjun Park)\n- drm/exynos: vidi: fix to avoid directly dereferencing user pointer (Jeongjun Park)\n- drm/exynos: vidi: use priv-vidi_dev for ctx lookup in vidi_connection_ioctl() (Jeongjun Park)\n- net: Handle napi_schedule() calls from non-interrupt (Frederic Weisbecker)\n- net: stmmac: dwmac-loongson: Set clk_csr_i to 100-150MHz (Huacai Chen)\n- drm/radeon: apply state adjust rules to some additional HAINAN vairants (Alex Deucher)\n- serial: uartlite: fix PM runtime usage count underflow on probe (Maciej Andrzejewski ICEYE)\n- serial: 8250: Add late synchronize_irq() to shutdown to handle DW UART BUSY (Ilpo Jarvinen)\n- serial: 8250: Fix TX deadlock when using DMA (Raul E Rangel)\n- serial: 8250_pci: add support for the AX99100 (Martin Roukala (ne Peres))\n- iommu/vt-d: Fix intel iommu iotlb sync hardlockup and retry (Guanghui Feng)\n- mtd: Avoid boot crash in RedBoot partition table parser (Finn Thain)\n- mtd: rawnand: cadence: Fix error check for dma_alloc_coherent() in cadence_nand_init() (Chen Ni)\n- mtd: rawnand: pl353: make sure optimal timings are applied (Olivier Sobrie)\n- mmc: sdhci: fix timing selection for 1-bit bus width (Luke Wang)\n- mmc: sdhci-pci-gli: fix GL9750 DMA write corruption (Matthew Schwartz)\n- Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access (Lukas Johannes Moller)\n- Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp() (Lukas Johannes Moller)\n- net: macb: fix use-after-free access to PTP clock (Fedor Pchelkin)\n- NFC: nxp-nci: allow GPIOs to sleep (Ian Ray)\n- nvdimm/bus: Fix potential use after free in asynchronous initialization (Ira Weiny)\n- sunrpc: fix cache_request leak in cache_release (Jeff Layton)\n- driver: iio: add missing checks on iio_info's callback access (Julien Stephan)\n- io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop (Jens Axboe)\n- l2tp: do not use sock_hold() in pppol2tp_session_get_sock() (Eric Dumazet)\n- bpf: Forget ranges when refining tnum after JSET (Paul Chaignon)\n- i3c: mipi-i3c-hci: Add missing TID field to no-op command descriptor (Adrian Hunter)\n- i3c: mipi-i3c-hci: Restart DMA ring correctly after dequeue abort (Adrian Hunter)\n- i3c: mipi-i3c-hci: Use ETIMEDOUT instead of ETIME for timeout errors (Adrian Hunter)\n- iio: imu: inv_icm42600: fix odr switch to the same value (Jean-Baptiste Maneyrol)\n- iio: gyro: mpu3050-i2c: fix pm_runtime error handling (Antoniu Miclaus)\n- iio: gyro: mpu3050-core: fix pm_runtime error handling (Antoniu Miclaus)\n- iio: chemical: bme680: Fix measurement wait duration calculation (Chris Spencer)\n- iio: potentiometer: mcp4131: fix double application of wiper shift (Lukas Schmid)\n- iio: chemical: sps30_i2c: fix buffer size in sps30_i2c_read_meas() (Antoniu Miclaus)\n- iio: chemical: sps30_serial: fix buffer size in sps30_serial_read_meas() (Antoniu Miclaus)\n- iio: dac: ds4424: reject -128 RAW value (Oleksij Rempel)\n- btrfs: abort transaction on failure to update root in the received subvol ioctl (Filipe Manana)\n- lib/bootconfig: check bounds before writing in __xbc_open_brace() (Josh Law)\n- lib/bootconfig: fix snprintf truncation check in xbc_node_compose_key_after() (Josh Law)\n- x86/apic: Disable x2apic on resume if the kernel expects so (Shashank Balaji)\n- lib/bootconfig: fix off-by-one in xbc_verify_tree() unclosed brace error (Josh Law)\n- xfs: fix undersized l_iclog_roundoff values (Darrick J. Wong)\n- tracing: Fix trace_buf_size= cmdline parameter with sizes = 2G (Calvin Owens)\n- drm/amdgpu: Fix use-after-free race in VM acquire (Alysa Liu)\n- net: ethernet: arc: emac: quiesce interrupts before requesting IRQ (Fan Wu)\n- net: ncsi: fix skb leak in error paths (Jian Zhang)\n- parisc: Fix initial page table creation for boot (Helge Deller)\n- hwmon: (pmbus/q54sj108a2) fix stack overflow in debugfs read (Sanman Pradhan)\n- nouveau/dpcd: return EBUSY for aux xfer if the device is asleep (Dave Airlie)\n- parisc: Increase initial mapping to 64 MB with KALLSYMS (Helge Deller)\n- batman-adv: Avoid double-rtnl_lock ELP metric worker (Sven Eckelmann)\n- ice: fix retry for AQ command 0x06EE (Jakub Staniszewski)\n- net: mana: Ring doorbell at 4 CQ wraparounds (Long Li)\n- media: dvb-net: fix OOB access in ULE extension header tables (Ariel Silver)\n- staging: rtl8723bs: properly validate the data in rtw_get_ie_ex() (Greg Kroah-Hartman)\n- staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie (Luka Gejak)\n- irqchip/gic-v3-its: Limit number of per-device MSIs to the range the ITS supports (Marc Zyngier)\n- device property: Allow secondary lookup in fwnode_get_next_child_node() (Andy Shevchenko)\n- time/jiffies: Mark jiffies_64_to_clock_t() notrace (Steven Rostedt)\n- time: add kernel-doc in time.c (Randy Dunlap)\n- ceph: fix i_nlink underrun during async unlink (Max Kellermann)\n- libceph: admit message frames only in CEPH_CON_S_OPEN state (Ilya Dryomov)\n- libceph: Use u32 for non-negative values in ceph_monmap_decode() (Raphael Zimmer)\n- libceph: prevent potential out-of-bounds reads in process_message_header() (Ilya Dryomov)\n- libceph: reject preamble if control segment is empty (Ilya Dryomov)\n- libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (Raphael Zimmer)\n- tipc: fix divide-by-zero in tipc_sk_filter_connect() (Mehul Rao)\n- mmc: core: Avoid bitfield RMW for claim/retune flags (Penghe Geng)\n- mmc: mmci: Fix device_node reference leak in of_get_dml_pipe_index() (Felix Gu)\n- mm/tracing: rss_stat: ensure curr is false from kthread context (Kalesh Singh)\n- usb: image: mdc800: kill download URB on timeout (Ziyi Guo)\n- usb: mdc800: handle signal and read racing (Oliver Neukum)\n- usb: renesas_usbhs: fix use-after-free in ISR during device removal (Fan Wu)\n- usb: class: cdc-wdm: fix reordering issue in read code path (Oliver Neukum)\n- USB: core: Limit the length of unkillable synchronous timeouts (Alan Stern)\n- USB: usbtmc: Use usb_bulk_msg_killable() with user-specified timeouts (Alan Stern)\n- USB: usbcore: Introduce usb_bulk_msg_killable() (Alan Stern)\n- usb: cdc-acm: Restore CAP_BRK functionnality to CH343 (Marc Zyngier)\n- usb: core: don't power off roothub PHYs if phy_set_mode() fails (Gabor Juhos)\n- usb: misc: uss720: properly clean up reference in uss720_probe() (Greg Kroah-Hartman)\n- usb: yurex: fix race in probe (Oliver Neukum)\n- usb: xhci: Fix memory leak in xhci_disable_slot() (Zilin Guan)\n- usb/core/quirks: Add Huawei ME906S-device to wakeup quirk (Christoffer Sandberg)\n- net: usb: lan78xx: skip LTM configuration for LAN7850 (Oleksij Rempel)\n- net: usb: lan78xx: fix silent drop of packets with checksum errors (Oleksij Rempel)\n- cgroup: fix race between task migration and iteration (Qingye Zhao)\n- octeontx2-af: devlink: fix NIX RAS reporter recovery condition (Alok Tiwari)\n- ASoC: detect empty DMI strings (Casey Connolly)\n- ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition (Chen Ni)\n- ACPI: OSL: fix __iomem type on return from acpi_os_map_generic_address() (Ben Dooks)\n- e1000/e1000e: Fix leak in DMA error cleanup (Matt Vollrath)\n- i40e: fix src IP mask checks and memcpy argument names in cloud filter (Alok Tiwari)\n- nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (Sungwoo Kim)\n- regulator: pca9450: Correct interrupt type (Peng Fan)\n- regulator: pca9450: Make IRQ optional (Frieder Schrempf)\n- netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels (Yuan Tan)\n- netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (Hyunwoo Kim)\n- netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path (Hyunwoo Kim)\n- netfilter: x_tables: guard option walkers against 1-byte tail reads (David Dull)\n- netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop() (Jenny Guanni Qu)\n- can: hi311x: hi3110_open(): add check for hi3110_power_enable() return value (Wenyuan Li)\n- serial: caif: hold tty-link reference in ldisc_open and ser_release (Shuangpeng Bai)\n- ASoC: soc-core: flush delayed work before removing DAIs and widgets (matteo.cotifava)\n- ASoC: core: Do not call link_exit() on uninitialized rtd objects (Amadeusz Slawinski)\n- ASoC: core: Exit all links before removing their components (Cezary Rojewski)\n- ASoC: soc-core: accept zero format at snd_soc_runtime_set_dai_fmt() (Kuninori Morimoto)\n- ASoC: soc-core: drop delayed_work_pending() check before flush (matteo.cotifava)\n- net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit (Weiming Shi)\n- net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (Gal Pressman)\n- bonding: handle BOND_LINK_FAIL, BOND_LINK_BACK as valid link states (Hangbin Liu)\n- xprtrdma: Decrement re_receiving on the early exit paths (Eric Badger)\n- powerpc: 83xx: km83xx: Fix keymile vendor prefix (J. Neuschafer)\n- remoteproc: sysmon: Correct subsys_name_len type in QMI request (Bjorn Andersson)\n- powerpc/uaccess: Fix inline assembly for clang build on PPC32 (Christophe Leroy (CS GROUP))\n- ALSA: usb-audio: Check max frame size for implicit feedback mode, too (Takashi Iwai)\n- ALSA: usb-audio: Avoid implicit feedback mode on DIYINHK USB Audio 2.0 (Takashi Iwai)\n- scsi: ses: Fix devices attaching to different hosts (Tomas Henzl)\n- ACPI: OSI: Add DMI quirk for Acer Aspire One D255 (Sofia Schneider)\n- unshare: fix unshare_fs() handling (Al Viro)\n- scsi: mpi3mr: Add NULL checks when resetting request and reply queues (Ranjan Kumar)\n- ACPI: PM: Save NVS memory on Lenovo G70-35 (Piotr Mazek)\n- scsi: storvsc: Fix scheduling while atomic on PREEMPT_RT (Jan Kiszka)\n- net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks (Victor Nogueira)\n- net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop (Jiayuan Chen)\n- net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled (Fernando Fernandez Mancera)\n- net: stmmac: Fix error handling in VLAN add and delete paths (Ovidiu Panait)\n- nfc: rawsock: cancel tx_work before socket teardown (Jakub Kicinski)\n- nfc: nci: clear NCI_DATA_EXCHANGE before calling completion callback (Jakub Kicinski)\n- nfc: nci: free skb on nci_transceive early error paths (Jakub Kicinski)\n- net: nfc: nci: Fix zero-length proprietary notifications (Ian Ray)\n- net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs (Koichiro Den)\n- amd-xgbe: fix sleep while atomic on suspend/resume (Raju Rangoju)\n- ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu() (Jakub Kicinski)\n- xen/acpi-processor: fix _CST detection using undersized evaluation buffer (David Thomson)\n- indirect_call_wrapper: do not reevaluate function pointer (Eric Dumazet)\n- wifi: wlcore: Fix a locking bug (Bart Van Assche)\n- can: mcp251x: fix deadlock in error path of mcp251x_open (Alban Bedel)\n- can: bcm: fix locking for bcm_op runtime updates (Oliver Hartkopp)\n- atm: lec: fix null-ptr-deref in lec_arp_clear_vccs (Jiayuan Chen)\n- dpaa2-switch: do not clear any interrupts automatically (Ioana Ciornei)\n- net: dpaa2-switch: serialize changes to priv-mac with a mutex (Vladimir Oltean)\n- net: dpaa2-switch replace direct MAC access with dpaa2_switch_port_has_mac() (Vladimir Oltean)\n- net: dpaa2-switch: assign port_priv-mac after dpaa2_mac_connect() call (Vladimir Oltean)\n- net: dpaa2: replace dpaa2_mac_is_type_fixed() with dpaa2_mac_is_type_phy() (Vladimir Oltean)\n- net: ethernet: ti: am65-cpsw-nuss/cpsw-ale: Fix multicast entry handling in ALE table (Chintan Vankar)\n- platform/x86: thinkpad_acpi: Fix errors reading battery thresholds (Jonathan Teh)\n- selftests: mptcp: more stable simult_flows tests (Paolo Abeni)\n- drbd: fix 'LOGIC BUG' in drbd_al_begin_io_nonblock() (Lars Ellenberg)\n- Squashfs: check metadata block offset is within range (Phillip Lougher)\n- net/sched: ets: fix divide by zero in the offload path (Davide Caratti)\n- IB/mthca: Add missed mthca_unmap_user_db() for mthca_create_srq() (Jason Gunthorpe)\n- wifi: mac80211: fix NULL pointer dereference in mesh_rx_csa_frame() (Vahagn Vardanian)\n- wifi: radiotap: reject radiotap with unknown bits (Johannes Berg)\n- ALSA: usb-audio: Use correct version for UAC3 header validation (Jun Seo)\n- platform/x86: dell-wmi: Add audio/mic mute key codes (Kurt Borja)\n- platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data (Thorsten Blum)\n- x86/efi: defer freeing of boot services memory (Mike Rapoport (Microsoft))\n- HID: Add HID_CLAIMED_INPUT guards in raw_event callbacks missing them (Greg Kroah-Hartman)\n- can: usb: etas_es58x: correctly anchor the urb in the read bulk callback (Greg Kroah-Hartman)\n- can: ucan: Fix infinite loop from zero-length messages (Greg Kroah-Hartman)\n- can: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message (Greg Kroah-Hartman)\n- net: usb: pegasus: validate USB endpoints (Greg Kroah-Hartman)\n- net: usb: kalmia: validate USB endpoints (Greg Kroah-Hartman)\n- net: usb: kaweth: validate USB endpoints (Greg Kroah-Hartman)\n- nfc: pn533: properly drop the usb interface reference on disconnect (Greg Kroah-Hartman)\n- media: dvb-core: fix wrong reinitialization of ringbuffer on reopen (Jens Axboe)\n- eventpoll: Fix integer overflow in ep_loop_check_proc() (Jann Horn)\n- net: arcnet: com20020-pci: fix support for 2.5Mbit cards (Ethan Nelson-Moore)\n- ALSA: hda/conexant: Fix headphone jack handling on Acer Swift SF314 (Takashi Iwai)\n- fbcon: check return value of con2fb_acquire_newinfo() (Andrey Vatoropin)\n- fbcon: move more common code into fb_open() (Daniel Vetter)\n- fbcon: Extract fbcon_open/release helpers (Daniel Vetter)\n- fbcon: Use delayed work for cursor (Daniel Vetter)\n- ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths (Namjae Jeon)\n- ALSA: hda/conexant: Add quirk for HP ZBook Studio G4 (Takashi Iwai)\n- usb: cdns3: fix role switching during resume (Thomas Richard (TI))\n- usb: cdns3: call cdns_power_is_lost() only once in cdns_resume() (Theo Lebrun)\n- usb: cdns3: remove redundant if branch (Hongyu Xie)\n- clk: tegra: tegra124-emc: fix device leak on set_rate() (Johan Hovold)\n- mfd: omap-usb-host: Fix OF populate on driver rebind (Johan Hovold)\n- mfd: omap-usb-host: Convert to platform remove callback returning void (Uwe Kleine-Konig)\n- mfd: qcom-pm8xxx: Fix OF populate on driver rebind (Johan Hovold)\n- mfd: qcom-pm8xxx: Convert to platform remove callback returning void (Uwe Kleine-Konig)\n- mfd: qcom-pm8xxx: switch away from using chained IRQ handlers (Dmitry Baryshkov)\n- drm/tegra: dsi: fix device leak on probe (Johan Hovold)\n- ata: libata-scsi: refactor ata_scsi_translate() (Damien Le Moal)\n- ata: libata: remove pointless VPRINTK() calls (Hannes Reinecke)\n- ata: libata-scsi: drop DPRINTK calls for cdb translation (Hannes Reinecke)\n- scsi: ata: Call scsi_done() directly (Bart Van Assche)\n- ARM: omap2: Fix reference count leaks in omap_control_init() (Wentao Liang)\n- ARM: OMAP2+: add missing of_node_put before break and return (Wang Qing)\n- memory: mtk-smi: fix device leak on larb probe (Johan Hovold)\n- memory: mtk-smi: Convert to platform remove callback returning void (Uwe Kleine-Konig)\n- bpf: Fix stack-out-of-bounds write in devmap (Kohei Enju)\n- btrfs: fix incorrect key offset in error message in check_dev_extent_item() (Mark Harmstone)\n- ALSA: usb-audio: Use inclusive terms (Takashi Iwai)\n- ALSA: usb-audio: Cap the packet size pre-calculations (Takashi Iwai)\n- scsi: ufs: core: Move link recovery for hibern8 exit failure to wl_resume (Peter Wang)\n- scsi: ufs: core: Always initialize the UIC done completion (Bart Van Assche)\n- scsi: lpfc: Properly set WC for DPP mapping (Mathias Krause)\n- ARM: clean up the memset64() C wrapper (Thomas Weissschuh)\n\n[5.15.0-322.202.1]\n- scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (Michael Bommarito)  [Orabug: 39446044]\n- scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (Michael Bommarito)  [Orabug: 39446044]\n- scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (Michael Bommarito)  [Orabug: 39446044]\n- scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (Michael Bommarito)  [Orabug: 39446044]\n- ima: process_measurement() needlessly takes inode_lock() on MAY_READ (Frederick Lawler)  [Orabug: 39390378]\n- net: sched: act_api: implement generic walker and search for tc action (Zhengchao Shao)  [Orabug: 39342047]\n- btrfs: reserve extra space for the free space tree (Josef Bacik)  [Orabug: 39281379]\n- btrfs: include the free space tree in the global rsv minimum calculation (Josef Bacik)  [Orabug: 39281379]\n\n[5.15.0-321.202.5]\n- Revert 'ip6_tunnel: Fix usage of skb_vlan_inet_prepare()' (Harshit Mogalapalli)  [Orabug: 39476647]\n- smb: client: reject userspace cifs.spnego descriptions (Asim Viladi Oglu Manizada)  [Orabug: 39463672]\n\n[5.15.0-321.202.4]\n- tun: free page on build_skb failure in tun_xdp_one() (Weiming Shi)  [Orabug: 39429143]\n- tap: free page on error paths in tap_get_user_xdp() (Weiming Shi)  [Orabug: 39429143]\n- tun: free page on short-frame rejection in tun_xdp_one() (Weiming Shi)  [Orabug: 39429143]\n\n[5.15.0-321.202.3]\n- net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim)  [Orabug: 39368827]  {CVE-2026-46300}\n- net: skbuff: preserve shared-frag marker during coalescing (William Bowling)  [Orabug: 39368827]\n- ptrace: slightly saner 'get_dumpable()' logic (Linus Torvalds)  [Orabug: 39384274]  {CVE-2026-46333}\n- mm/hugetlb: fix excessive IPI broadcasts when unsharing PMD tables using mmu_gather (David Hildenbrand (Red Hat))  [Orabug: 38474901]\n- Revert 'mm/hugetlb: add option to allows disabling CVE-2025-38085 mitigation' (Samasth Norway Ananda)  [Orabug: 38474901]\n- mm/rmap: fix two comments related to huge_pmd_unshare() (David Hildenbrand (Red Hat))  [Orabug: 38474901]\n- mm/hugetlb: fix two comments related to huge_pmd_unshare() (David Hildenbrand (Red Hat))  [Orabug: 38474901]\n- mm/hugetlb: fix hugetlb_pmd_shared() (David Hildenbrand (Red Hat))  [Orabug: 38474901]\n\n[5.15.0-321.202.2]\n- dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler (Guenter Roeck)\n- Revert 'arm64: dts: qcom: sdm845-oneplus: Mark l14a regulator as boot-on' (Sasha Levin)\n- ip6_tunnel: Fix usage of skb_vlan_inet_prepare() (Ben Hutchings)\n- hwmon: (max16065) Use READ/WRITE_ONCE to avoid compiler optimization induced race (Gui-Dong Han)\n- wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom (Guenter Roeck)\n- sched: idle: Make skipping governor callbacks more consistent (Rafael J. Wysocki)\n- nvmet-tcp: fix use-before-check of sg in bounds validation (Cengiz Can)\n- remoteproc: mediatek: Unprepare SCP clock during system suspend (Tzung-Bi Shih)\n- net: openvswitch: Avoid releasing netdev before teardown completes (Toke Hoiland-Jorgensen)\n- ACPI: processor: Fix previous acpi_processor_errata_piix4() fix (Rafael J. Wysocki)\n- net: hsr: fix VLAN add unwind on slave errors (Luka Gejak)\n- x86/CPU/AMD: Add a fix for AMD-SB-7052 (Prathyushi Nangia)  [Orabug: 39327141]  {CVE-2025-54518}\n- xfrm: esp: ipv4: fix up flags setting (Greg Kroah-Hartman)  [Orabug: 39342679]  {CVE-2026-43284}\n- xfrm: esp: avoid in-place decrypt on shared skb frags (Kuan-Ting Chen)  [Orabug: 39342679]  {CVE-2026-43284}\n- KVM: x86: disable preemption around the call to kvm_arch_vcpu_{un|}blocking (Maxim Levitsky)  [Orabug: 39334996]\n- KVM: Don't block+unblock when halt-polling is successful (Sean Christopherson)  [Orabug: 39334996]\n- nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (Jeff Layton)  [Orabug: 39167616]  {CVE-2026-31402}\n- net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks (Victor Nogueira)  [Orabug: 39103230]  {CVE-2026-23270}\n- exadata: tools: perf: update column to comm_nodigit (Stephen Brennan)  [Orabug: 39327019]\n- perf report: Add comm_nodigit sort key (Stephen Brennan)  [Orabug: 39327019]\n- Revert 'tools: perf: add comm_ignore_digit column' (Stephen Brennan)  [Orabug: 39327019]\n\n[5.15.0-321.202.1]\n- virtio-net: add cond_resched() to the command waiting loop (Jason Wang) [Orabug: 39291988]\n- virtio-net: convert rx mode setting to use workqueue (Jason Wang) [Orabug: 39291988]\n- x86: KVM: Add common feature flag for AMD's PSFD (Sean Christopherson) [Orabug: 35586248]\n- KVM: x86: Insert 'AMD' in KVM_X86_FEATURE_PSFD (Jim Mattson) [Orabug: 35586248]\n- KVM: x86: Expose Predictive Store Forwarding Disable (Babu Moger) [Orabug: 35586248]\n- i2c: designware: fix __i2c_dw_disable() in case master is holding SCL low (Yann Sionneau) [Orabug: 39174661]","id":"ELSA-2026-50373","ovalId":"oval:com.oracle.elsa:def:202650373","source":"oracle_linux","title":"ELSA-2026-50373: Unbreakable Enterprise kernel security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-50373.html"}