elsa-2025-28049

oracle_linux
Description

[5.4.17-2136.350.3.1] - Reapply 'cpuidle: menu: Avoid discarding useful information' (Harshvardhan Jha) [Orabug: 38744458] - fbcon: fix integer overflow in font allocation (Samasth Norway Ananda) [Orabug: 38744453] [5.4.17-2136.350.3] - net/rds: Fix rs_recv_pending counting issue (Gerd Rausch) [Orabug: 38506370] [5.4.17-2136.350.2] - LTS tag: v5.4.301 (Alok Tiwari) - net: rtnetlink: fix module reference count leak issue in rtnetlink_rcv_msg (Zhengchao Shao) - media: s5p-mfc: remove an unused/uninitialized variable (Arnd Bergmann) - NFSD: Fix last write offset handling in layoutcommit (Sergey Bashirov) - NFSD: Minor cleanup in layoutcommit processing (Sergey Bashirov) - padata: Reset next CPU when reorder sequence wraps around (Xiao Liang) - KEYS: trusted_tpm1: Compare HMAC values in constant time (Eric Biggers) - NFSD: Define a proc_layoutcommit for the FlexFiles layout type (Chuck Lever) [Orabug: 38601819] {CVE-2025-40087} - vfs: Don't leak disconnected dentries on umount (Jan Kara) [Orabug: 38601924] {CVE-2025-40105} - jbd2: ensure that all ongoing I/O complete before freeing blocks (Zhang Yi) - ext4: detect invalid INLINE_DATA + EXTENTS flag combination (Deepanshu Kartikey) [Orabug: 38649223] {CVE-2025-40167} - drm/amdgpu: use atomic functions with memory barriers for vm fault info (Gui-Dong Han) - ext4: avoid potential buffer over-read in parse_apply_sb_mount_options() (Theodore Ts'O) [Orabug: 38649412] {CVE-2025-40198} - spi: cadence-quadspi: Flush posted register writes before DAC access (Pratyush Yadav) - spi: cadence-quadspi: Flush posted register writes before INDAC access (Pratyush Yadav) - memory: samsung: exynos-srom: Fix of_iomap leak in exynos_srom_probe (Zhen Ni) - memory: samsung: exynos-srom: Correct alignment (Krzysztof Kozlowski) - arm64: errata: Apply workarounds for Neoverse-V3AE (Mark Rutland) - arm64: cputype: Add Neoverse-V3AE definitions (Mark Rutland) - comedi: fix divide-by-zero in comedi_buf_munge() (Deepanshu Kartikey) - binder: remove 'invalid inc weak' check (Alice Ryhl) - xhci: dbc: enable back DbC in resume if it was enabled before suspend (Mathias Nyman) - usb/core/quirks: Add Huawei ME906S to wakeup quirk (Tim Guttzeit) - USB: serial: option: add Telit FN920C04 ECM compositions (Li Qingwu) - USB: serial: option: add Quectel RG255C (Reinhard Speyerer) - USB: serial: option: add UNISOC UIS7720 (Renjun Wang) - net: ravb: Ensure memory write completes before ringing TX doorbell (Lad Prabhakar) - net: usb: rtl8150: Fix frame padding (Michal Pecio) - ocfs2: clear extent cache after moving/defragmenting extents (Deepanshu Kartikey) [Orabug: 38730547] {CVE-2025-40233} - MIPS: Malta: Fix keyboard resource preventing i8042 driver from registering (Maciej W. Rozycki) - Revert 'cpuidle: menu: Avoid discarding useful information' (Rafael J. Wysocki) - net: bonding: fix possible peer notify event loss or dup issue (Tonghao Zhang) - sctp: avoid NULL dereference when chunk data buffer is missing (Alexey Simakov) [Orabug: 38730567] {CVE-2025-40240} - arm64, mm: avoid always making PTE dirty in pte_mkwrite() (Huang, Ying) - net: enetc: correct the value of ENETC_RXB_TRUESIZE (Wei Fang) - rtnetlink: Allow deleting FDB entries in user namespace (Johannes Wiesboeck) - net: rtnetlink: add NLM_F_BULK support to rtnl_fdb_del (Nikolay Aleksandrov) - net: add ndo_fdb_del_bulk (Nikolay Aleksandrov) - net: rtnetlink: add bulk delete support flag (Nikolay Aleksandrov) - net: netlink: add NLM_F_BULK delete request modifier (Nikolay Aleksandrov) - net: rtnetlink: use BIT for flag values (Nikolay Aleksandrov) - net: rtnetlink: add helper to extract msg type's kind (Nikolay Aleksandrov) - net: rtnetlink: add msg kind names (Nikolay Aleksandrov) - net: rtnetlink: remove redundant assignment to variable err (Colin Ian King) - m68k: bitops: Fix find_*_bit() signatures (Geert Uytterhoeven) - hfsplus: return EIO when type of hidden directory mismatch in hfsplus_fill_super() (Yangtao Li) - hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits() (Viacheslav Dubeyko) - dlm: check for defined force value in dlm_lockspace_release (Alexander Aring) - hfsplus: fix KMSAN uninit-value issue in hfsplus_delete_cat() (Viacheslav Dubeyko) - hfs: validate record offset in hfsplus_bmap_alloc (Yang Chenzhi) - hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent() (Viacheslav Dubeyko) - hfs: make proper initalization of struct hfs_find_data (Viacheslav Dubeyko) - hfs: clear offset and space out of valid records in b-tree node (Viacheslav Dubeyko) - exec: Fix incorrect type for ret (Xichao Zhao) - hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp() (Viacheslav Dubeyko) - ALSA: firewire: amdtp-stream: fix enum kernel-doc warnings (Randy Dunlap) - sched/fair: Fix pelt lost idle time detection (Vincent Guittot) - sched/balancing: Rename newidle_balance() = sched_balance_newidle() (Ingo Molnar) - sched/fair: Trivial correction of the newidle_balance() comment (Barry Song) - sched: Make newidle_balance() static again (Chen Yu) - tls: don't rely on tx_work during send() (Sabrina Dubroca) - tls: always set record_type in tls_process_cmsg (Sabrina Dubroca) - tg3: prevent use of uninitialized remote_adv and local_adv variables (Alexey Simakov) - tcp: fix tcp_tso_should_defer() vs large RTT (Eric Dumazet) - amd-xgbe: Avoid spurious link down messages during interface toggle (Raju Rangoju) - net/ip6_tunnel: Prevent perpetual tunnel growth (Dmitry Safonov) [Orabug: 38649261] {CVE-2025-40173} - net: dlink: handle dma_map_single() failure properly (Moon Yeounsu) - net: dl2k: switch from 'pci_' to 'dma_' API (Christophe Jaillet) - media: pci: ivtv: Add missing check after DMA map (Thomas Fourier) - media: pci/ivtv: switch from 'pci_' to 'dma_' API (Christophe Jaillet) - xen/events: Update virq_to_irq on migration (Jason Andryuk) - media: lirc: Fix error handling in lirc_register() (Ma Ke) - media: rc: Directly use ida_free() (Keliu) - drm/exynos: exynos7_drm_decon: remove ctx-suspended (Kaustabh Chakraborty) - btrfs: avoid potential out-of-bounds in btrfs_encode_fh() (Anderson Nascimento) [Orabug: 38649463] {CVE-2025-40205} - pwm: berlin: Fix wrong register in suspend/resume (Jisheng Zhang) - media: cx18: Add missing check after DMA map (Thomas Fourier) - xen/events: Cleanup find_virq() return codes (Jason Andryuk) - cramfs: Verify inode mode when loading from disk (Tetsuo Handa) - fs: Add 'initramfs_options' to set initramfs mount options (Lichen Liu) - pid: Add a judgment for ns null in pid_nr_ns (Gaoxiang17) [Orabug: 38649276] {CVE-2025-40178} - minixfs: Verify inode mode when loading from disk (Tetsuo Handa) - tracing: Fix race condition in kprobe initialization causing NULL pointer dereference (Yuan Chen) [Orabug: 38592033] {CVE-2025-40042} - dm: fix NULL pointer dereference in __dm_suspend() (Zheng Qixing) [Orabug: 38649057] {CVE-2025-40134} - mfd: intel_soc_pmic_chtdc_ti: Set use_single_read regmap_config flag (Hans de Goede) - mfd: intel_soc_pmic_chtdc_ti: Drop unneeded assignment for cache_type (Andy Shevchenko) - mfd: intel_soc_pmic_chtdc_ti: Fix invalid regmap-config max_register value (Hans de Goede) - Squashfs: reject negative file sizes in squashfs_read_inode() (Phillip Lougher) [Orabug: 38649425] {CVE-2025-40200} - Squashfs: add additional inode sanity checking (Phillip Lougher) - media: mc: Clear minor number before put device (Edward Adam Davis) [Orabug: 38649399] {CVE-2025-40197} - mfd: vexpress-sysreg: Check the return value of devm_gpiochip_add_data() (Bartosz Golaszewski) - fs: udf: fix OOB read in lengthAllocDescs handling (Larshin Sergey) [Orabug: 38592048] {CVE-2025-40044} - KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (Sean Christopherson) [Orabug: 38591959] {CVE-2025-40026} - net/9p: fix double req put in p9_fd_cancelled (Nalivayko Sergey) [Orabug: 38591965] {CVE-2025-40027} - ext4: guard against EA inode refcount underflow in xattr update (Ahmet Eray Karadag) [Orabug: 38649330] {CVE-2025-40190} - ext4: correctly handle queries for metadata mappings (Ojaswin Mujoo) - ext4: increase i_disksize to offset + len in ext4_update_disksize_before_punch() (Yongjian Sun) - nfsd: nfserr_jukebox in nlm_fopen should lead to a retry (Olga Kornievskaia) - x86/umip: Fix decoding of register forms of 0F 01 (SGDT and SIDT aliases) (Sean Christopherson) - x86/umip: Check that the instruction opcode is at least two bytes (Sean Christopherson) - PCI: keystone: Use devm_request_irq() to free 'ks-pcie-error-irq' on exit (Siddharth Vadapalli) - PCI/AER: Fix missing uevent on recovery when a reset is requested (Niklas Schnelle) - PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV (Niklas Schnelle) [Orabug: 38730513] {CVE-2025-40219} - rseq/selftests: Use weak symbol reference, not definition, to link with glibc (Sean Christopherson) - rtc: interface: Fix long-standing race when setting alarm (Esben Haabendal) - rtc: interface: Ensure alarm irq is enabled when UIE is enabled (Esben Haabendal) - mmc: core: SPI mode remove cmd7 (Rex Chen) - mtd: rawnand: fsmc: Default to autodetect buswidth (Linus Walleij) - sparc: fix error handling in scan_one_device() (Ma Ke) - sparc64: fix hugetlb for sun4u (Anthony Yznaga) - sctp: Fix MAC comparison to be constant-time (Eric Biggers) [Orabug: 38649451] {CVE-2025-40204} - scsi: hpsa: Fix potential memory leak in hpsa_big_passthru_ioctl() (Thorsten Blum) - parisc: don't reference obsolete termio struct for TC* constants (Sam James) - lib/genalloc: fix device leak in of_gen_pool_get() (Johan Hovold) - iio: frequency: adf4350: Fix prescaler usage. (Michael Hennerich) - iio: dac: ad5421: use int type to store negative error codes (Rong Qianfeng) - iio: dac: ad5360: use int type to store negative error codes (Rong Qianfeng) - crypto: atmel - Fix dma_unmap_sg() direction (Thomas Fourier) - cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request() (Rafael J. Wysocki) [Orabug: 38649367] {CVE-2025-40194} - drm/nouveau: fix bad ret code in nouveau_bo_move_prep (Shuhao Fu) - media: i2c: mt9v111: fix incorrect type for ret (Rong Qianfeng) - firmware: meson_sm: fix device leak at probe (Johan Hovold) - xen/manage: Fix suspend error path (Lukas Wunner) - arm64: dts: qcom: msm8916: Add missing MDSS reset (Stephan Gerhold) - ACPI: debug: fix signedness issues in read/write helpers (Amir Mohammad Jahangirzad) - ACPI: TAD: Add missing sysfs_remove_group() for ACPI_TAD_RT (Daniel Tang) - tpm_tis: Fix incorrect arguments in tpm_tis_probe_irq_single (Gunnar Kudrjavets) - tpm, tpm_tis: Claim locality before writing interrupt registers (Lino Sanfilippo) - crypto: essiv - Check ssize for decryption and in-place encryption (Herbert Xu) [Orabug: 38581456,38705546] {CVE-2025-40019} - mailbox: zynqmp-ipi: Remove dev.parent check in zynqmp_ipi_free_mboxes (Harini T) - mailbox: zynqmp-ipi: Remove redundant mbox_controller_unregister() call (Harini T) - tools build: Align warning options with perf (Leo Yan) - net: fsl_pq_mdio: Fix device node reference leak in fsl_pq_mdio_probe (Erick Karanja) - tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request(). (Kuniyuki Iwashima) [Orabug: 38649579] {CVE-2025-40186} - net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce() (Alexandr Sapozhnikov) [Orabug: 38649313] {CVE-2025-40187} - drm/vmwgfx: Fix Use-after-free in validation (Ian Forbes) [Orabug: 38643546] {CVE-2025-40111} - net/mlx4: prevent potential use after free in mlx4_en_do_uc_filter() (Dan Carpenter) - scsi: mvsas: Fix use-after-free bugs in mvs_work_queue (Duoming Zhou) [Orabug: 38557654] {CVE-2025-40001} - scsi: mvsas: Use sas_task_find_rq() for tagging (John Garry) - scsi: mvsas: Delete mvs_tag_init() (John Garry) - scsi: libsas: Add sas_task_find_rq() (John Garry) - clk: nxp: Fix pll0 rate check condition in LPC18xx CGU driver (Alok Tiwari) - clk: nxp: lpc18xx-cgu: convert from round_rate() to determine_rate() (Brian Masney) - perf session: Fix handling when buffer exceeds 2 GiB (Leo Yan) - rtc: x1205: Fix Xicor X1205 vendor prefix (Rob Herring) - perf util: Fix compression checks returning -1 as bool (Yunseong Kim) - iio: frequency: adf4350: Fix ADF4350_REG3_12BIT_CLKDIV_MODE (Michael Hennerich) - clocksource/drivers/clps711x: Fix resource leaks in error paths (Zhen Ni) - pinctrl: check the return value of pinmux_ops::get_function_name() (Bartosz Golaszewski) [Orabug: 38591981] {CVE-2025-40030} - Input: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak (Zhen Ni) [Orabug: 38592002] {CVE-2025-40035} - mm: hugetlb: avoid soft lockup when mprotect to large memory area (Yang Shi) [Orabug: 38649150] {CVE-2025-40153} - uio_hv_generic: Let userspace take care of interrupt mask (Naman Jain) [Orabug: 38592067] {CVE-2025-40048} - Squashfs: fix uninit-value in squashfs_get_parent (Phillip Lougher) [Orabug: 38592077] {CVE-2025-40049} - net: ena: return 0 in ena_get_rxfh_key_size() when RSS hash key is not configurable (Kohei Enju) - nfp: fix RSS hash key size when RSS is not supported (Kohei Enju) - drivers/base/node: fix double free in register_one_node() (Donet Tom) - ocfs2: fix double free in user_cluster_connect() (Dan Carpenter) [Orabug: 38592110] {CVE-2025-40055} - net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast (I Viswanath) [Orabug: 38649096] {CVE-2025-40140} - RDMA/siw: Always report immediate post SQ errors (Bernard Metzler) - usb: vhci-hcd: Prevent suspending virtually attached devices (Cristian Ciocaltea) - scsi: mpt3sas: Fix crash in transport port remove by using ioc_info() (Ranjan Kumar) [Orabug: 38648982] {CVE-2025-40115} - ipvs: Defer ip_vs_ftp unregister during netns cleanup (Slavin Liu) [Orabug: 38581446] {CVE-2025-40018} - NFSv4.1: fix backchannel max_resp_sz verification check (Anthony Iliopoulos) - remoteproc: qcom: q6v5: Avoid disabling handover IRQ twice (Stephan Gerhold) - sparc: fix accurate exception reporting in copy_{from,to}_user for M7 (Michael Karcher) - sparc: fix accurate exception reporting in copy_to_user for Niagara 4 (Michael Karcher) - sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara (Michael Karcher) - sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC III (Michael Karcher) - sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC (Michael Karcher) - IB/sa: Fix sa_local_svc_timeout_ms read race (Vlad Dumitrescu) - RDMA/core: Resolve MAC of next-hop device without ARP support (Parav Pandit) - wifi: mt76: fix potential memory leak in mt76_wmac_probe() (Abdun Nihaal) - drivers/base/node: handle error properly in register_one_node() (Donet Tom) - watchdog: mpc8xxx_wdt: Reload the watchdog timer when enabling the watchdog (Christophe Leroy) - netfilter: ipset: Remove unused htable_bits in macro ahash_region (Zhen Ni) - iio: consumers: Fix offset handling in iio_convert_raw_to_processed() (Hans de Goede) - ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping (Takashi Iwai) - ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping (Takashi Iwai) - ASoC: Intel: bytcht_es8316: Fix invalid quirk input mapping (Takashi Iwai) - pps: fix warning in pps_register_cdev when register device fail (Wang Liang) [Orabug: 38592170] {CVE-2025-40070} - misc: genwqe: Fix incorrect cmd field being reported in error (Colin Ian King) - usb: gadget: configfs: Correctly set use_os_string at bind (William Wu) - usb: phy: twl6030: Fix incorrect type for ret (Xichao Zhao) - tcp: fix __tcp_close() to only send RST when required (Eric Dumazet) - PCI: tegra: Fix devm_kcalloc() argument order for port-phys allocation (Alok Tiwari) - wifi: mwifiex: send world regulatory domain to driver (Stefan Kerkmann) - ALSA: lx_core: use int type to store negative error codes (Rong Qianfeng) - media: rj54n1cb0c: Fix memleak in rj54n1_probe() (Zhang Shurong) - scsi: myrs: Fix dma_alloc_coherent() error check (Thomas Fourier) - scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod (Niklas Cassel) [Orabug: 38649567] {CVE-2025-40118} - serial: max310x: Add error checking in probe() (Dan Carpenter) - usb: host: max3421-hcd: Fix error pointer dereference in probe cleanup (Dan Carpenter) - drm/radeon/r600_cs: clean up of dead code in r600_cs (Brahmajit Das) - i2c: designware: Add disabling clocks when probe fails (Kunihiko Hayashi) - i2c: mediatek: fix potential incorrect use of I2C_MASTER_WRRD (Leilk Liu) - bpf: Explicitly check accesses to bpf_sock_addr (Paul Chaignon) [Orabug: 38592205] {CVE-2025-40078} - selftests: watchdog: skip ping loop if WDIOF_KEEPALIVEPING not supported (Akhilesh Patil) - pwm: tiehrpwm: Fix corner case in clock divisor calculation (Uwe Kleine-Konig) - block: use int to store blk_stack_limits() return value (Rong Qianfeng) - blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx (Li Nan) [Orabug: 38649026] {CVE-2025-40125} - pinctrl: meson-gxl: add missing i2c_d pinmux (Da Xue) - soc: qcom: rpmh-rsc: Unconditionally clear _TRIGGER bit for TCS (Sneh Mankad) - ACPI: processor: idle: Fix memory leak when register cpuidle device failed (Huisong Li) - regmap: Remove superfluous check for !config in __regmap_init() (Geert Uytterhoeven) - x86/vdso: Fix output operand size of RDPID (Uros Bizjak) - perf: arm_spe: Prevent overflow in PERF_IDX2OFF() (Leo Yan) [Orabug: 38592223] {CVE-2025-40081} - driver core/PM: Set power.no_callbacks along with power.no_pm (Rafael J. Wysocki) - staging: axis-fifo: flush RX FIFO on read errors (Ovidiu Panait) - staging: axis-fifo: fix maximum TX packet length check (Ovidiu Panait) - perf subcmd: avoid crash in exclude_cmds when excludes is empty (Hupu) - dm-integrity: limit MAX_TAG_SIZE to 255 (Mikulas Patocka) - wifi: rtlwifi: rtl8192cu: Don't claim USB ID 07b8:8188 (Bitterblue Smith) - USB: serial: option: add SIMCom 8230C compositions (Xiaowei Li) - media: rc: fix races with imon_disconnect() (Larshin Sergey) [Orabug: 38548027] {CVE-2025-39993} - media: imon: grab lock earlier in imon_ir_change_protocol() (Tetsuo Handa) - media: imon: reorganize serialization (Tetsuo Handa) - media: rc: Add support for another iMON 0xffdc device (Flavius Georgescu) - media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe (Duoming Zhou) [Orabug: 38548044] {CVE-2025-39995} - media: tuner: xc5000: Fix use-after-free in xc5000_release (Duoming Zhou) [Orabug: 38548037] {CVE-2025-39994} - media: tunner: xc5000: Refactor firmware load (Ricardo Ribalda) - udp: Fix memory accounting leak. (Kuniyuki Iwashima) [Orabug: 37844325] {CVE-2025-22058} - media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove (Duoming Zhou) [Orabug: 38548051] {CVE-2025-39996} - scsi: target: target_core_configfs: Add length check to avoid buffer overflow (Wang Haoran) [Orabug: 38548059] {CVE-2025-39998} - LTS tag: v5.4.300 (Alok Tiwari) - KVM: SVM: Sync TPR from LAPIC into VMCB::V_TPR even if AVIC is active (Maciej S. Szmigiero) - mm/hugetlb: fix folio is still mapped when deleted (Tu Jinjiang) [Orabug: 38560482] {CVE-2025-40006} - i40e: add mask to apply valid bits for itr_idx (Lukasz Czapnik) - i40e: fix validation of VF state in get resources (Lukasz Czapnik) [Orabug: 38547929] {CVE-2025-39969} - i40e: fix idx validation in config queues msg (Lukasz Czapnik) [Orabug: 38547938] {CVE-2025-39971} - i40e: add validation for ring_len param (Lukasz Czapnik) [Orabug: 38547952,38604168,38604171] {CVE-2025-39973} - i40e: increase max descriptors for XL710 (Justin Bronder) - mm/migrate_device: don't add folio to be freed to LRU in migrate_device_finalize() (David Hildenbrand) - fbcon: Fix OOB access in font allocation (Thomas Zimmermann) - fbcon: fix integer overflow in fbcon_do_set_font (Samasth Norway Ananda) [Orabug: 38547913] {CVE-2025-39967} - i40e: add max boundary check for VF filters (Lukasz Czapnik) [Orabug: 38547923] {CVE-2025-39968} - i40e: fix input validation logic for action_meta (Lukasz Czapnik) [Orabug: 38547933] {CVE-2025-39970} - i40e: fix idx validation in i40e_validate_queue_map (Lukasz Czapnik) [Orabug: 38547946] {CVE-2025-39972} - drm/gma500: Fix null dereference in hdmi teardown (Zabelin Nikita) [Orabug: 38560496] {CVE-2025-40011} - can: peak_usb: fix shift-out-of-bounds issue (Stephane Grosjean) [Orabug: 38581463] {CVE-2025-40020} - can: mcba_usb: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol) - can: sun4i_can: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol) - can: hi311x: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol) - can: rcar_can: rcar_can_resume(): fix s2ram with PSCI (Geert Uytterhoeven) - IB/mlx5: Fix obj_type mismatch for SRQ event subscriptions (Or Har-Toov) - usb: core: Add 0x prefix to quirks debug output (Jiayi Li) - ALSA: usb-audio: Fix build with CONFIG_INPUT=n (Takashi Iwai) - ALSA: usb-audio: Convert comma to semicolon (Chen Ni) - ALSA: usb-audio: Add mixer quirk for Sony DualSense PS5 (Cristian Ciocaltea) - ALSA: usb-audio: Remove unneeded wmb() in mixer_quirks (Cristian Ciocaltea) - ALSA: usb-audio: Simplify NULL comparison in mixer_quirks (Cristian Ciocaltea) - ALSA: usb-audio: Avoid multiple assignments in mixer_quirks (Cristian Ciocaltea) - ALSA: usb-audio: Fix block comments in mixer_quirks (Cristian Ciocaltea) - net: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer (Hans de Goede) - net: rfkill: gpio: add DT support (Philipp Zabel) - serial: sc16is7xx: fix bug in flow control levels init (Hugo Villeneuve) - USB: gadget: dummy-hcd: Fix locking bug in RT-enabled kernels (Alan Stern) - usb: gadget: dummy_hcd: remove usage of list iterator past the loop body (Jakob Koschel) - ASoC: SOF: Intel: hda-stream: Fix incorrect variable used in error message (Colin Ian King) - ASoC: wm8974: Correct PLL rate rounding (Charles Keepax) - ASoC: wm8940: Correct typo in control name (Charles Keepax) - mmc: mvsdio: Fix dma_unmap_sg() nents value (Thomas Fourier) - nilfs2: fix CFI failure when accessing /sys/fs/nilfs2/features/* (Nathan Chancellor) - cnic: Fix use-after-free bugs in cnic_delete_task (Duoming Zhou) [Orabug: 38503849] {CVE-2025-39945} - net: liquidio: fix overflow in octeon_init_instr_queue() (Alexey Nepomnyashih) - tcp: Clear tcp_sk(sk)-fastopen_rsk in tcp_disconnect(). (Kuniyuki Iwashima) [Orabug: 38526388] {CVE-2025-39955} - i40e: remove redundant memory barrier when cleaning Tx descs (Maciej Fijalkowski) - net: natsemi: fix rx_dropped double accounting on netif_rx() failure (Moon Yeounsu) - cgroup: split cgroup_destroy_wq into 3 workqueues (Chen Ridong) [Orabug: 38503892] {CVE-2025-39953} - pcmcia: omap_cf: Mark driver struct with __refdata to prevent section mismatch (Geert Uytterhoeven) - wifi: mac80211: fix incorrect type for ret (Liao Yuanhong) - ALSA: firewire-motu: drop EPOLLOUT from poll return values as write is not supported (Takashi Sakamoto) - mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory (Miaohe Lin) [Orabug: 38461848] {CVE-2025-39883} - phy: ti-pipe3: fix device leak at unbind (Johan Hovold) - dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees (Stephan Gerhold) [Orabug: 38494822] {CVE-2025-39923} - dmaengine: ti: edma: Fix memory allocation size for queue_priority_map (Anders Roxell) - can: j1939: j1939_local_ecu_get(): undo increment when j1939_local_ecu_get() fails (Tetsuo Handa) - can: j1939: j1939_sk_bind(): call j1939_priv_put() immediately when j1939_local_ecu_get() failed (Tetsuo Handa) - i40e: fix IRQ freeing in i40e_vsi_request_irq_msix error path (Michal Schmidt) [Orabug: 38494787] {CVE-2025-39911} - i40e: Use irq_update_affinity_hint() (Nitesh Narayan Lal) - genirq: Provide new interfaces for affinity hints (Thomas Gleixner) - genirq: Export affinity setter for modules (Thomas Gleixner) - genirq/affinity: Add irq_update_affinity_desc() (John Garry) - igb: fix link test skipping when interface is admin down (Kohei Enju) - net: fec: Fix possible NPD in fec_enet_phy_reset_after_clk_enable() (Stefan Wahren) - USB: serial: option: add Telit Cinterion LE910C4-WWX new compositions (Fabio Porcedda) - USB: serial: option: add Telit Cinterion FN990A w/audio compositions (Fabio Porcedda) - tty: hvc_console: Call hvc_kick in hvc_write unconditionally (Fabian Vogt) - mtd: nand: raw: atmel: Respect tAR, tCLR in read setup timing (Alexander Sverdlin) - mtd: nand: raw: atmel: Fix comment in timings preparation (Alexander Dahl) - mtd: rawnand: stm32_fmc2: avoid overlapping mappings on ECC buffer (Christophe Kerello) - mm/khugepaged: fix the address passed to notifier on testing young (Wei Yang) - fuse: prevent overflow in copy_file_range return value (Miklos Szeredi) - fuse: check if copy_file_range() returns larger than requested size (Miklos Szeredi) - mtd: rawnand: stm32_fmc2: fix ECC overwrite (Christophe Kerello) - ocfs2: fix recursive semaphore deadlock in fiemap call (Mark Tinguely) [Orabug: 38461859] {CVE-2025-39885} - EDAC/altera: Delete an inappropriate dma_free_coherent() call (Salah Triki) - tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock-cork. (Kuniyuki Iwashima) [Orabug: 38494797] {CVE-2025-39913} - net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod. (Kuniyuki Iwashima) [Orabug: 37901604] {CVE-2025-23143} [5.4.17-2136.350.1] - device-dax: correct pgoff align in dax_set_mapping() (Kun(Llfl)) [Orabug: 37206404] {CVE-2024-50022} [5.4.17-2136.349.3] - Revert 'net/mlx5e: Update and set Xon/Xoff upon MTU set' (Jakub Kicinski) [Orabug: 38545204] - KVM: x86: Take irqfds.lock when adding/deleting IRQ bypass producer (Sean Christopherson) [Orabug: 38494247] - rds: Free all frags when rds_ib_recv_cache_put() fails (Hans Westgaard Ry) [Orabug: 38492234] [5.4.17-2136.349.2] - bpf/bpf_get,set_sockopt: add option to set TCP-BPF sock ops flags (Alan Maguire) [Orabug: 36699199] [5.4.17-2136.349.1] - NFSv4: Don't clear capabilities that won't be reset (Trond Myklebust) - power: supply: bq27xxx: restrict no-battery detection to bq27000 (H. Nikolaus Schaller) - power: supply: bq27xxx: fix error return in case of no bq27000 hdq battery (H. Nikolaus Schaller) - usb: hub: Fix flushing of delayed work used for post resume purposes (Mathias Nyman) - soc: qcom: mdt_loader: Deal with zero e_shentsize (Bjorn Andersson) - Revert 'net/mlx5e: Update and set Xon/Xoff upon port speed set' (Tariq Toukan) - LTS tag: v5.4.299 (Alok Tiwari) - scsi: lpfc: Fix buffer free/clear order in deferred receive path (John Evans) [Orabug: 38456754] {CVE-2025-39841} - dmaengine: mediatek: Fix a flag reuse error in mtk_cqdma_tx_status() (Qiu-Ji Chen) - cifs: fix integer overflow in match_server() (Roman Smirnov) - spi: spi-fsl-lpspi: Reset FIFO and disable module on transfer abort (Larisa Grigore) - spi: spi-fsl-lpspi: Set correct chip-select polarity bit (Larisa Grigore) - spi: spi-fsl-lpspi: Fix transmissions when using CONT (Larisa Grigore) - pcmcia: Add error handling for add_interval() in do_validate_mem() (Xu Wang) - ALSA: hda/hdmi: Add pin fix for another HP EliteDesk 800 G4 model (Takashi Iwai) - randstruct: gcc-plugin: Fix attribute addition (Kees Cook) - randstruct: gcc-plugin: Remove bogus void member (Kees Cook) - vmxnet3: update MTU after device quiesce (Ronak Doshi) - net: dsa: microchip: linearize skb for tail-tagging switches (Jakob Unterwurzacher) - net: dsa: microchip: update tag_ksz masks for KSZ9477 family (Pieter Van Trappen) - dmaengine: mediatek: Fix a possible deadlock error in mtk_cqdma_tx_status() (Qiu-Ji Chen) - ALSA: hda/realtek - Add new HP ZBook laptop with micmute led fixup (Chris Chiu) - gpio: pca953x: fix IRQ storm on system wake up (Emanuele Ghidoli) - iio: light: opt3001: fix deadlock due to concurrent flag access (Luca Ceresoli) [Orabug: 37977028] {CVE-2025-37968} - iio: chemical: pms7003: use aligned_s64 for timestamp (David Lechner) - cpufreq/sched: Explicitly synchronize limits_changed flag handling (Rafael J. Wysocki) - mm/slub: avoid accessing metadata when pointer is invalid in object_err() (Li Qiong) [Orabug: 38494761] {CVE-2025-39902} - mm/khugepaged: fix -anon_vma race (Jann Horn) - e1000e: fix heap overflow in e1000_set_eeprom (Vitaly Lifshits) - batman-adv: fix OOB read/write in network-coding decode (Stanislav Fort) - drm/amdgpu: drop hw access in non-DC audio fini (Alex Deucher) - wifi: mwifiex: Initialize the chan_stats array to zero (Rong Qianfeng) [Orabug: 38494723] {CVE-2025-39891} - pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region() (Ma Ke) - ALSA: usb-audio: Add mute TLV for playback volumes on some devices (Cryolitia Pukngae) - ppp: fix memory leak in pad_compress_skb (Qingfang Deng) [Orabug: 38456781] {CVE-2025-39847} - net: atm: fix memory leak in atm_register_sysfs when device_register fail (Wang Liang) - ax25: properly unshare skbs in ax25_kiss_rcv() (Eric Dumazet) - ipv4: Fix NULL vs error pointer check in inet_blackhole_dev_init() (Dan Carpenter) - net: thunder_bgx: add a missing of_node_put (Rosen Penev) - wifi: libertas: cap SSID len in lbs_associate() (Dan Carpenter) - wifi: cw1200: cap SSID length in cw1200_do_join() (Dan Carpenter) - net: ethernet: mtk_eth_soc: fix tx vlan tag for llc packets (Felix Fietkau) - i40e: Fix potential invalid access when MAC list is empty (Zhen Ni) [Orabug: 38456814] {CVE-2025-39853} - icmp: fix icmp_ndo_send address translation for reply direction (Fabian Blase) - mISDN: Fix memory leak in dsp_hwec_enable() (Miaoqian Lin) - xirc2ps_cs: fix register access when enabling FullDuplex (Alok Tiwari) - Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen() (Kuniyuki Iwashima) [Orabug: 38456834] {CVE-2025-39860} - netfilter: conntrack: helper: Replace -EEXIST by -EBUSY (Phil Sutter) - wifi: cfg80211: fix use-after-free in cmp_bss() (Dmitry Antipov) [Orabug: 38456860] {CVE-2025-39864} - powerpc: boot: Remove leading zero in label in udelay() (Nathan Chancellor) [5.4.17-2136.348.3] - hugetlbfs: take read_lock on i_mmap for PMD sharing (Waiman Long) [Orabug: 38459576] - kallsyms: add module_kallsyms_on_each_symbol_locked (Julian Pidancet) [Orabug: 38418686] - kallsyms: export module_kallsyms_on_each_symbol (Julian Pidancet) [Orabug: 38418686] [5.4.17-2136.348.2] - uek-rpm: Move ifb module to nano modules (Harshit Mogalapalli) [Orabug: 38443798] - clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns (Al Viro) [Orabug: 38310007,38453918] {CVE-2025-38499} - x86/vmscape: Warn when STIBP is disabled with SMT (Pawan Gupta) [Orabug: 38424094] - x86/bugs: Move cpu_bugs_smt_update() down (Pawan Gupta) [Orabug: 38424094] - x86/vmscape: Enable the mitigation (Pawan Gupta) [Orabug: 38424094] - x86/vmscape: Add conditional IBPB mitigation (Pawan Gupta) [Orabug: 38424094] - x86/vmscape: Add old Intel CPUs to affected list (Pawan Gupta) [Orabug: 38424094] - x86/vmscape: Enumerate VMSCAPE bug (Pawan Gupta) [Orabug: 38424094] - Documentation/hw-vuln: Add VMSCAPE documentation (Pawan Gupta) [Orabug: 38424094] [5.4.17-2136.348.1] - LTS tag: v5.4.298 (Sherry Yang) - Revert 'drm/dp: Change AUX DPCD probe address from DPCD_REV to LANE0_1_STATUS' (Imre Deak) - net: usb: qmi_wwan: add Telit Cinterion LE910C4-WWX new compositions (Fabio Porcedda) - Revert 'drm/amdgpu: fix incorrect vm flags to map bo' (Alex Deucher) [Orabug: 38343661] - HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() (Minjong Kim) [Orabug: 38440228] {CVE-2025-39808} - HID: wacom: Add a new Art Pen 2 (Ping Cheng) - HID: asus: fix UAF via HID_CLAIMED_INPUT validation (Qasim Ijaz) [Orabug: 38440310] {CVE-2025-39824} - efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare (Li Nan) [Orabug: 38440277] {CVE-2025-39817} - sctp: initialize more fields in sctp_v6_from_sk() (Eric Dumazet) [Orabug: 38440251] {CVE-2025-39812} - net: stmmac: xgmac: Do not enable RX FIFO Overflow interrupts (Rohan G Thomas) - net/mlx5e: Set local Xoff after FW update (Alexei Lazar) - net/mlx5e: Update and set Xon/Xoff upon port speed set (Alexei Lazar) - net/mlx5e: Update and set Xon/Xoff upon MTU set (Alexei Lazar) - net: dlink: fix multicast stats being counted incorrectly (Moon Yeounsu) - atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control(). (Kuniyuki Iwashima) [Orabug: 38440347] {CVE-2025-39828} - net/atm: remove the atmdev_ops {get, set}sockopt methods (Christoph Hellwig) - Bluetooth: hci_event: Detect if HCI_EV_NUM_COMP_PKTS is unbalanced (Luiz Augusto von Dentz) - powerpc/kvm: Fix ifdef to remove build warning (Madhavan Srinivasan) - net: ipv4: fix regression in local-broadcast routes (Oscar Maes) [Orabug: 38343661] - vhost/net: Protect ubufs with rcu read lock in vhost_net_ubuf_put() (Nikolay Kuratov) - scsi: core: sysfs: Correct sysfs attributes access rights (Damien Le Moal) - ftrace: Fix potential warning in trace_printk_seq during ftrace_dump (Tengda Wu) [Orabug: 38440259] {CVE-2025-39813} - pinctrl: STMFX: add missing HAS_IOMEM dependency (Randy Dunlap) - LTS tag: v5.4.297 (Sherry Yang) - alloc_fdtable(): change calling conventions. (Al Viro) - s390/hypfs: Enable limited access during lockdown (Peter Oberparleiter) - s390/hypfs: Avoid unnecessary ioctl registration in debugfs (Peter Oberparleiter) - ALSA: usb-audio: Use correct sub-type for UAC3 feature unit validation (Takashi Iwai) - net/sched: Remove unnecessary WARNING condition for empty child qdisc in htb_activate (William Liu) - net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit (William Liu) - ixgbe: xsk: resolve the negative overflow of budget in ixgbe_xmit_zc (Jason Xing) - ipv6: sr: validate HMAC algorithm ID in seg6_hmac_info_add (Heminhong) - ALSA: usb-audio: Fix size validation in convert_chmap_v3() (Dan Carpenter) [Orabug: 38343661] - scsi: qla4xxx: Prevent a potential error pointer dereference (Dan Carpenter) [Orabug: 38401514] {CVE-2025-39676} - usb: xhci: Fix slot_id resource race conflict (Weitao Wang) - nfs: fix UAF in direct writes (Josef Bacik) [Orabug: 36596831] {CVE-2024-26958} - NFS: Fix up commit deadlocks (Trond Myklebust) - cifs: Fix UAF in cifs_demultiplex_thread() (Zhang Xiaoxu) - Bluetooth: fix use-after-free in device_for_each_child() (Dmitry Antipov) [Orabug: 37433654] {CVE-2024-53237} - act_mirred: use the backlog for nested calls to mirred ingress (Davide Caratti) [Orabug: 34882838] {CVE: CVE-2022-4269} - net/sched: act_mirred: better wording on protection against excessive stack growth (Davide Caratti) - net/sched: act_mirred: refactor the handle of xmit (Wenxu) - selftests: forwarding: tc_actions.sh: add matchall mirror test (Jiri Pirko) - net: sched: don't expose action qstats to skb_tc_reinsert() (Vlad Buslov) - net: sched: extract qstats update code into functions (Vlad Buslov) - net: sched: extract bstats update code into function (Vlad Buslov) - net: sched: extract common action counters update code into function (Vlad Buslov) - mm: perform the mapping_map_writable() check after call_mmap() (Lorenzo Stoakes) - mm: update memfd seal write check to include F_SEAL_WRITE (Lorenzo Stoakes) - mm: drop the assumption that VM_SHARED always implies writable (Lorenzo Stoakes) - codel: remove sch-q.qlen check before qdisc_tree_reduce_backlog() (Cong Wang) [Orabug: 37908492] {CVE-2025-37798} - sch_qfq: make qfq_qlen_notify() idempotent (Cong Wang) - sch_hfsc: make hfsc_qlen_notify() idempotent (Cong Wang) [Orabug: 38158396] {CVE-2025-38177} - sch_drr: make drr_qlen_notify() idempotent (Cong Wang) - btrfs: populate otime when logging an inode item (Qu Wenruo) - media: venus: hfi: explicitly release IRQ during teardown (Jorge Ramirez-Ortiz) - f2fs: fix to avoid out-of-boundary access in dnode page (Chao Yu) - media: venus: protect against spurious interrupts during probe (Jorge Ramirez-Ortiz) - media: qcom: camss: cleanup media device allocated resource on error path (Vladimir Zapolskiy) - media: venus: vdec: Clamp param smaller than 1fps and bigger than 240. (Ricardo Ribalda) - drm/dp: Change AUX DPCD probe address from DPCD_REV to LANE0_1_STATUS (Imre Deak) - pwm: mediatek: Fix duty and period setting (Uwe Kleine-Konig) - pwm: mediatek: Handle hardware enable and clock enable separately (Uwe Kleine-Konig) - pwm: mediatek: Implement .apply() callback (Uwe Kleine-Konig) - media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt() (Gui-Dong Han) [Orabug: 38401677] {CVE-2025-39713} - media: v4l2-ctrls: Don't reset handler's error in v4l2_ctrl_handler_free() (Sakari Ailus) - media: v4l2-ctrls: always copy the controls on completion (Hans Verkuil) - ata: Fix SATA_MOBILE_LPM_POLICY description in Kconfig (Damien Le Moal) - soc: qcom: mdt_loader: Ensure we don't read past the ELF header (Bjorn Andersson) [Orabug: 38423524] {CVE-2025-39787} - rtc: ds1307: handle oscillator stop flag (OSF) for ds1341 (Meagan Lloyd) - usb: musb: omap2430: fix device leak at unbind (Johan Hovold) - NFS: Fix the setting of capabilities when automounting a new filesystem (Trond Myklebust) [Orabug: 38429211] {CVE-2025-39798} - NFS: Fix up handling of outstanding layoutcommit in nfs_update_inode() (Trond Myklebust) - NFSv4: Fix nfs4_bitmap_copy_adjust() (Trond Myklebust) - usb: typec: fusb302: cache PD RX state (Sebastian Reichel) - cdc-acm: fix race between initial clearing halt and open (Oliver Neukum) - USB: cdc-acm: do not log successful probe on later errors (Johan Hovold) - mm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock (Breno Leitao) - mm/kmemleak: turn kmemleak_lock and object-lock to raw_spinlock_t (He Zhe) - ALSA: scarlett2: Add retry on -EPROTO from scarlett2_usb_tx() (Geoffrey D. Bennett) - x86/fpu: Delay instruction pointer fixup until after warning (Dave Hansen) - mm/hmm: move pmd_to_hmm_pfn_flags() to the respective #ifdeffery (Andy Shevchenko) - nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() (Jeff Layton) [Orabug: 38395081,38501612] {CVE-2025-38724} - pmdomain: governor: Consider CPU latency tolerance from pm_domain_cpu_gov (Maulik Shah) - tracing: Add down_write(trace_event_sem) when adding trace event (Steven Rostedt) [Orabug: 38324271] {CVE-2025-38539} - usb: hub: Don't try to recover devices lost during warm reset. (Mathias Nyman) - usb: hub: avoid warm port reset during USB3 disconnect (Mathias Nyman) - x86/mce/amd: Add default names for MCA banks and blocks (Yazen Ghannam) - iio: hid-sensor-prox: Fix incorrect OFFSET calculation (Zhang Lixu) - f2fs: fix to do sanity check on ino and xnid (Chao Yu) - mm/zsmalloc: do not pass __GFP_MOVABLE if CONFIG_COMPACTION=n (Harry Yoo) - mm/zsmalloc.c: convert to use kmem_cache_zalloc in cache_alloc_zspage() (Miaohe Lin) - drm/sched: Remove optimization that causes hang when killing dependent jobs (Lin Cao) - ice: Fix a null pointer dereference in ice_copy_and_init_pkg() (Haoxiang Li) [Orabug: 38351930] {CVE-2025-38664} - net: usbnet: Fix the wrong netif_carrier_on() call (Ammar Faizi) - net: usbnet: Avoid potential RCU stall on LINK_CHANGE event (John Ernberg) - PCI/ACPI: Fix runtime PM ref imbalance on Hot-Plug Capable ports (Lukas Wunner) - ACPI: processor: idle: Check acpi_fetch_acpi_dev() return value (Li Zhong) - comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large (Ian Abbott) - comedi: Fix initialization of data for instructions that write to subdevice (Ian Abbott) - kbuild: Add KBUILD_CPPFLAGS to as-option invocation (Nathan Chancellor) - kbuild: add to KBUILD_CPPFLAGS (Masahiro Yamada) - kbuild: Add CLANG_FLAGS to as-instr (Nathan Chancellor) - mips: Include KBUILD_CPPFLAGS in CHECKFLAGS invocation (Nathan Chancellor) - kbuild: Update assembler calls to use proper flags and language target (Nick Desaulniers) - ARM: 9448/1: Use an absolute path to unified.h in KBUILD_AFLAGS (Nathan Chancellor) - usb: dwc3: Ignore late xferNotReady event to prevent halt timeout (Kuen-Han Tsai) - USB: storage: Ignore driver CD mode for Realtek multi-mode Wi-Fi dongles (Zenm Chen) - usb: storage: realtek_cr: Use correct byte order for bcs-Residue (Thorsten Blum) - USB: storage: Add unusual-devs entry for Novatek NTK96550-based camera (Mael Guerin) - usb: quirks: Add DELAY_INIT quick for another SanDisk 3.2Gen1 Flash Drive (Miao Li) - iio: proximity: isl29501: fix buffered read on big-endian systems (David Lechner) - ftrace: Also allocate and copy hash for reading of filter files (Steven Rostedt) [Orabug: 38401581] {CVE-2025-39689} - fpga: zynq_fpga: Fix the wrong usage of dma_map_sgtable() (Xu Yilun) - use uniform permission checks for all mount propagation changes (Al Viro) - move_mount: allow to add a mount into an existing group (Pavel Tikhomirov) - fs/buffer: fix use-after-free when call bh_read() helper (Ye Bin) [Orabug: 38401587] {CVE-2025-39691} - drm/amd/display: Find first CRTC and its line time in dce110_fill_display_configs (Timur Kristof) - drm/amd/display: Fix fractional fb divider in set_pixel_clock_v3 (Timur Kristof) - memstick: Fix deadlock by moving removing flag earlier (Jiayi Li) - media: venus: Add a check for packet size after reading from shared memory (Vedang Nagar) - media: ov2659: Fix memory leaks in ov2659_probe() (Zhang Shurong) - media: usbtv: Lock resolution while streaming (Ludwig Disterhof) [Orabug: 38401684] {CVE-2025-39714} - media: imx: fix a potential memory leak in imx_media_csc_scaler_device_init() (Haoxiang Li) - media: gspca: Add bounds checking to firmware parser (Dan Carpenter) - soc/tegra: pmc: Ensure power-domains are in a known state (Jonathan Hunter) - jbd2: prevent softlockup in jbd2_log_do_checkpoint() (Baokun Li) [Orabug: 38423509] {CVE-2025-39782} - PCI: endpoint: Fix configfs group removal on driver teardown (Damien Le Moal) - PCI: endpoint: Fix configfs group list head handling (Damien Le Moal) - mtd: rawnand: fsmc: Add missing check after DMA map (Thomas Fourier) - pwm: imx-tpm: Reset counter if CMOD is 0 (Laurentiu Mihalcea) - wifi: brcmsmac: Remove const from tbl_ptr parameter in wlc_lcnphy_common_read_table() (Nathan Chancellor) - zynq_fpga: use sgtable-based scatterlist wrappers (Marek Szyprowski) - ata: libata-scsi: Fix ata_to_sense_error() status handling (Damien Le Moal) - ext4: fix reserved gdt blocks handling in fsmap (Ojaswin Mujoo) - ext4: fix fsmap end of range reporting with bigalloc (Ojaswin Mujoo) - ext4: check fast symlink for ea_inode correctly (Andreas Dilger) - vt: defkeymap: Map keycodes above 127 to K_HOLE (Myrrh Periwinkle) - vt: keyboard: Don't process Unicode characters in K_OFF mode (Myrrh Periwinkle) - usb: dwc3: meson-g12a: fix device leaks at unbind (Johan Hovold) - usb: gadget: udc: renesas_usb3: fix device leak at unbind (Johan Hovold) - usb: atm: cxacru: Merge cxacru_upload_firmware() into cxacru_heavy_init() (Nathan Chancellor) - m68k: Fix lost column on framebuffer debug console (Finn Thain) - cpufreq: armada-8k: Fix off by one in armada_8k_cpufreq_free_table() (Dan Carpenter) - serial: 8250: fix panic due to PSLVERR (Yunhui Cui) [Orabug: 38401729] {CVE-2025-39724} - media: uvcvideo: Do not mark valid metadata as invalid (Ricardo Ribalda) - media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() (Youngjun Lee) [Orabug: 38394816] {CVE-2025-38680} - mm/kmemleak: avoid soft lockup in __kmemleak_do_cleanup() (Waiman Long) - parisc: Makefile: fix a typo in palo.conf (Randy Dunlap) - btrfs: fix log tree replay failure due to file with 0 links and extents (Filipe Manana) - thunderbolt: Fix copy+paste error in match_service_id() (Eric Biggers) - comedi: fix race between polling and detaching (Ian Abbott) - misc: rtsx: usb: Ensure mmc child device is active when card is present (Ricky Wu) - drm/amdgpu: fix incorrect vm flags to map bo (Jack Xiao) - scsi: lpfc: Remove redundant assignment to avoid memory leak (Jiasheng Jiang) - rtc: ds1307: remove clear of oscillator stop flag (OSF) in probe (Meagan Lloyd) - pNFS: Fix uninited ptr deref in block/scsi layout (Sergey Bashirov) [Orabug: 38394867] {CVE-2025-38691} - pNFS: Handle RPC size limit for layoutcommits (Sergey Bashirov) - pNFS: Fix disk addr range check in block/scsi layout (Sergey Bashirov) - pNFS: Fix stripe mapping in block/scsi layout (Sergey Bashirov) - net: phy: smsc: add proper reset flags for LAN8710A (Csaba Buday) - ipmi: Fix strcpy source and destination the same (Corey Minyard) - kconfig: lxdialog: fix 'space' to (de)select options (Yann E. MORIN) - kconfig: gconf: fix potential memory leak in renderer_edited() (Masahiro Yamada) - kconfig: gconf: avoid hardcoding model2 in on_treeview2_cursor_changed() (Masahiro Yamada) - ipmi: Use dev_warn_ratelimited() for incorrect message warnings (Breno Leitao) - scsi: aacraid: Stop using PCI_IRQ_AFFINITY (John Garry) - scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans (Ranjan Kumar) - kconfig: nconf: Ensure null termination where strncpy is used (Shankari Anand) - kconfig: lxdialog: replace strcpy() with strncpy() in inputbox.c (Suchit Karunakaran) - i3c: don't fail if GETHDRCAP is unsupported (Wolfram Sang) - PCI: pnv_php: Work around switches with broken presence detection (Timothy Pearson) - i3c: add missing include to internal header (Wolfram Sang) - media: uvcvideo: Fix bandwidth issue for Alcor camera (Chenchangcheng) - media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar (Alex Guo) [Orabug: 38394880] {CVE-2025-38693} - media: dvb-frontends: dib7090p: fix null-ptr-deref in dib7090p_rw_on_apb() (Alex Guo) [Orabug: 38394887] {CVE-2025-38694} - media: usb: hdpvr: disable zero-length read messages (Wolfram Sang) - media: tc358743: Increase FIFO trigger level to 374 (Dave Stevenson) - media: tc358743: Return an appropriate colorspace from tc358743_set_fmt (Dave Stevenson) - media: tc358743: Check I2C succeeded during probe (Dave Stevenson) - pinctrl: stm32: Manage irq affinity settings (Cheick Traore) - scsi: mpt3sas: Correctly handle ATA device errors (Damien Le Moal) - scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure (Justin Tee) [Orabug: 38394894] {CVE-2025-38695} - RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask() (Yury Norov) [Orabug: 38423286] {CVE-2025-39742} - MIPS: Don't crash in stack_top() for tasks without ABI or vDSO (Thomas Weissschuh) - jfs: upper bound check of tree index in dbAllocAG (Arnaud Lecomte) - jfs: Regular file corruption check (Edward Adam Davis) - jfs: truncate good inode pages when hard link is 0 (Lizhi Xu) - scsi: bfa: Double-free fix (Jackysliu) [Orabug: 38394925] {CVE-2025-38699} - MIPS: vpe-mt: add missing prototypes for vpe_{alloc,start,stop,free} (Shiji Yang) - watchdog: dw_wdt: Fix default timeout (Sebastian Reichel) - fs/orangefs: use snprintf() instead of sprintf() (Amir Mohammad Jahangirzad) - scsi: libiscsi: Initialize iscsi_conn-dd_data only if memory is allocated (Showrya M N) [Orabug: 38394931] {CVE-2025-38700} - ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr (Theodore Ts'O) [Orabug: 38394937] {CVE-2025-38701} - cifs: Fix calling CIFSFindFirst() for root path without msearch (Pali Rohar) - vhost: fail early when __vhost_add_used() fails (Jason Wang) - net: dsa: b53: fix IP_MULTICAST_CTRL on BCM5325 (Alvaro Fernandez Rojas) - uapi: in6: restore visibility of most IPv6 socket options (Jakub Kicinski) - net: ncsi: Fix buffer overflow in fetching version id (Hari Kalavakunta) - net: dsa: b53: prevent SWITCH_CTRL access on BCM5325 (Alvaro Fernandez Rojas) - net: dsa: b53: fix b53_imp_vlan_setup for BCM5325 (Alvaro Fernandez Rojas) - net: vlan: Replace BUG() with WARN_ON_ONCE() in vlan_dev_* stubs (Gal Pressman) - wifi: iwlegacy: Check rate_idx range after addition (Stanislaw Gruszka) - netmem: fix skb_frag_address_safe with unreadable skbs (Mina Almasry) - wifi: rtlwifi: fix possible skb memory leak in _rtl_pci_rx_interrupt(). (Thomas Fourier) - wifi: iwlwifi: fw: Fix possible memory leak in iwl_fw_dbg_collect (Anjaneyulu) - wifi: iwlwifi: dvm: fix potential overflow in rs_fill_link_cmd() (Rand Deeb) - net: fec: allow disable coalescing (Jonas Rebmann) - (powerpc/512) Fix possible dma_unmap_single() on uninitialized pointer (Thomas Fourier) - s390/stp: Remove udelay from stp_sync_clock() (Sven Schnelle) - wifi: iwlwifi: mvm: fix scan request validation (Avraham Stern) - net: thunderx: Fix format-truncation warning in bgx_acpi_match_id() (Alok Tiwari) - net: ipv4: fix incorrect MTU in broadcast routes (Oscar Maes) - wifi: cfg80211: Fix interface type validation (Ilan Peer) - rcu: Protect -defer_qs_iw_pending from data race (Paul E. McKenney) [Orabug: 38423341] {CVE-2025-39749} - net: ag71xx: Add missing check after DMA map (Thomas Fourier) - et131x: Add missing check after DMA map (Thomas Fourier) - be2net: Use correct byte order and format string for TCP seq and ack_seq (Alok Tiwari) - s390/time: Use monotonic clock in get_cycles() (Sven Schnelle) - wifi: cfg80211: reject HTC bit for management frames (Johannes Berg) - ktest.pl: Prevent recursion of default variable options (Steven Rostedt) - ASoC: codecs: rt5640: Retry DEVICE_ID verification (Xinxin Wan) - ALSA: usb-audio: Avoid precedence issues in mixer_quirks macros (Cristian Ciocaltea) - ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control (Lucy Thrun) - platform/x86: thinkpad_acpi: Handle KCOV __init vs inline mismatches (Kees Cook) - pm: cpupower: Fix the snapshot-order of tsc,mperf, clock in mperf_stop() (Gautham R. Shenoy) - usb: core: usb_submit_urb: downgrade type check (Oliver Neukum) - ALSA: intel8x0: Fix incorrect codec index usage in mixer for ICH4 (Alok Tiwari) - ASoC: hdac_hdmi: Rate limit logging on connection and disconnection (Mark Brown) - mmc: rtsx_usb_sdmmc: Fix error-path in sd_set_power_mode() (Ulf Hansson) - ACPI: APEI: GHES: add TAINT_MACHINE_CHECK on GHES panic path (Breno Leitao) - ACPI: processor: fix acpi_object initialization (Sebastian Ott) - PM: sleep: console: Fix the black screen issue (Tuhaowen) - thermal: sysfs: Return ENODATA instead of EAGAIN for reads (Hsin-Te Yuan) - PM: runtime: Clear power.needs_force_resume in pm_runtime_reinit() (Rafael J. Wysocki) - selftests: tracing: Use mutex_unlock for testing glob filter (Masami Hiramatsu) - ARM: tegra: Use I/O memcpy to write to IRAM (Aaron Kling) - gpio: tps65912: check the return value of regmap_update_bits() (Bartosz Golaszewski) - ASoC: soc-dapm: set bias_level if snd_soc_dapm_set_bias_level() was successed (Kuninori Morimoto) - ARM: rockchip: fix kernel hang during smp initialization (Alexander Kochetkov) - cpufreq: Exit governor when failed to start old governor (Lifeng Zheng) - usb: xhci: Avoid showing errors during surprise removal (Mario Limonciello) - usb: xhci: Set avg_trb_len = 8 for EP0 during Address Device Command (Jay Chen) - usb: xhci: Avoid showing warnings for dying controller (Mario Limonciello) - selftests/futex: Define SYS_futex on 32-bit architectures with 64-bit time_t (Cynthia Huang) - usb: xhci: print xhci-xhc_state when queue_command failed (Su Hui) - securityfs: don't pin dentries twice, once is enough... (Al Viro) - hfs: fix not erasing deleted b-tree node issue (Viacheslav Dubeyko) - drbd: add missing kref_get in handle_write_conflicts (Sarah Newman) [Orabug: 38394995] {CVE-2025-38708} - udf: Verify partition map count (Jan Kara) - arm64: Handle KCOV __init vs inline mismatches (Kees Cook) - hfsplus: don't use BUG_ON() in hfsplus_create_attributes_file() (Tetsuo Handa) - hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() (Viacheslav Dubeyko) - hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read() (Viacheslav Dubeyko) - hfs: fix slab-out-of-bounds in hfs_bnode_read() (Viacheslav Dubeyko) - sctp: linearize cloned gso packets in sctp_rcv (Xin Long) [Orabug: 38395059] {CVE-2025-38718} - netfilter: ctnetlink: fix refcount leak on table dump (Florian Westphal) [Orabug: 38395068] {CVE-2025-38721} - udp: also consider secpath when evaluating ipsec use for checksumming (Sabrina Dubroca) - ACPI: processor: perflib: Move problematic pr-performance check (Rafael J. Wysocki) - ACPI: processor: perflib: Fix initial _PPC limit application (Jiayi Li) - Documentation: ACPI: Fix parent device references (Andy Shevchenko) - fs: Prevent file descriptor table allocations exceeding INT_MAX (Sasha Levin) [Orabug: 38423397] {CVE-2025-39756} - sunvdc: Balance device refcount in vdc_port_mpgroup_check (Ma Ke) - NFSD: detect mismatch of file handle and delegation stateid in OPEN op (Dai Ngo) - net: dpaa: fix device leak when querying time stamp info (Johan Hovold) - net: gianfar: fix device leak when querying time stamp info (Johan Hovold) - netlink: avoid infinite retry looping in netlink_unicast() (Fedor Pchelkin) [Orabug: 38401319] {CVE-2025-38727} - ALSA: usb-audio: Validate UAC3 cluster segment descriptors (Takashi Iwai) [Orabug: 38423407] {CVE-2025-39757} - ALSA: usb-audio: Validate UAC3 power domain descriptors, too (Takashi Iwai) [Orabug: 38395101] {CVE-2025-38729} - io_uring: don't use int for ABI (Pavel Begunkov) - usb: gadget : fix use-after-free in composite_dev_cleanup() (Taoxue) [Orabug: 38334898] {CVE-2025-38555} - MIPS: mm: tlb-r4k: Uniquify TLB entries on init (Jiaxun Yang) - USB: serial: option: add Foxconn T99W709 (Slark Xiao) - vsock: Do not allow binding to VMADDR_PORT_ANY (Budimir Markovic) [Orabug: 38351771,38453914] {CVE-2025-38618} - net/packet: fix a race in packet_set_ring() and packet_notifier() (Quang Le) [Orabug: 38351764] {CVE-2025-38617} - perf/core: Prevent VMA split of buffer mappings (Thomas Gleixner) [Orabug: 38334948] {CVE-2025-38563} - perf/core: Exit early on perf_mmap() fail (Thomas Gleixner) [Orabug: 38334959] {CVE-2025-38565} - perf/core: Don't leak AUX buffer refcount on allocation failure (Thomas Gleixner) - pptp: fix pptp_xmit() error path (Eric Dumazet) - smb: client: let recv_done() cleanup before notifying the callers. (Stefan Metzmacher) - benet: fix BUG when creating VFs (Michal Schmidt) [Orabug: 38334976] {CVE-2025-38569} - net: drop UFO packets in udp_rcv_segment() (Wang Liang) [Orabug: 38351786] {CVE-2025-38622} - ipv6: reject malicious packets in ipv6_gso_segment() (Eric Dumazet) [Orabug: 38334988] {CVE-2025-38572} - pptp: ensure minimal skb length in pptp_xmit() (Eric Dumazet) [Orabug: 38335004] {CVE-2025-38574} - netpoll: prevent hanging NAPI when netcons gets enabled (Jakub Kicinski) - NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() (Trond Myklebust) [Orabug: 38401745] {CVE-2025-39730} - pci/hotplug/pnv-php: Wrap warnings in macro (Frederic Barrat) - pci/hotplug/pnv-php: Improve error msg on power state change failure (Frederic Barrat) - usb: chipidea: udc: fix sleeping function called from invalid context (Peter Chen) - f2fs: fix to avoid out-of-boundary access in devs.path (Chao Yu) - f2fs: fix to avoid panic in f2fs_evict_inode (Chao Yu) - f2fs: fix to avoid UAF in f2fs_sync_inode_meta() (Chao Yu) - rtc: pcf8563: fix incorrect maximum clock rate handling (Brian Masney) - rtc: hym8563: fix incorrect maximum clock rate handling (Brian Masney) - rtc: ds1307: fix incorrect maximum clock rate handling (Brian Masney) - module: Restore the moduleparam prefix length check (Petr Pavlu) - bpf: Check flow_dissector ctx accesses are aligned (Paul Chaignon) - mtd: rawnand: atmel: set pmecc data setup time (Balamanikandan Gunasundar) - mtd: rawnand: atmel: Fix dma_mapping_error() address (Thomas Fourier) - jfs: fix metapage reference count leak in dbAllocCtl (Zheng Yu) - fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref (Chenyuan Yang) - crypto: qat - fix seq_file position update in adf_ring_next() (Giovanni Cabiddu) - dmaengine: nbpfaxi: Add missing check after DMA map (Thomas Fourier) - dmaengine: mv_xor: Fix missing check after DMA map and missing unmap (Thomas Fourier) - fs/orangefs: Allow 2 more characters in do_c_string() (Dan Carpenter) - soundwire: stream: restore params when prepare ports fail (Bard Liao) - crypto: img-hash - Fix dma_unmap_sg() nents value (Thomas Fourier) - hwrng: mtk - handle devm_pm_runtime_enable errors (Ovidiu Panait) - watchdog: ziirave_wdt: check record length in ziirave_firm_verify() (Dan Carpenter) - scsi: isci: Fix dma_unmap_sg() nents value (Thomas Fourier) - scsi: mvsas: Fix dma_unmap_sg() nents value (Thomas Fourier) - scsi: ibmvscsi_tgt: Fix dma_unmap_sg() nents value (Thomas Fourier) - clk: sunxi-ng: v3s: Fix de clock definition (Paul Kocialkowski) - perf tests bp_account: Fix leaked file descriptor (Leo Yan) - crypto: ccp - Fix crash when rebind ccp device for ccp.ko (Mengbiao Xiong) - pinctrl: sunxi: Fix memory leak on krealloc failure (Yuan Chen) - power: supply: max14577: Handle NULL pdata when CONFIG_OF is not set (Charles Han) - clk: davinci: Add NULL check in davinci_lpsc_clk_register() (Henry Martin) - mtd: fix possible integer overflow in erase_xfer() (Ivan Stepchenko) - crypto: marvell/cesa - Fix engine load inaccuracy (Herbert Xu) - PCI: rockchip-host: Fix 'Unexpected Completion' log message (Hans Zhang) - vrf: Drop existing dst reference in vrf_ip6_input_dst (Stanislav Fomichev) - selftests: rtnetlink.sh: remove esp4_offload after test (Xiumei Mu) - netfilter: xt_nfacct: don't assume acct name is null-terminated (Florian Westphal) [Orabug: 38351854] {CVE-2025-38639} - can: kvaser_usb: Assign netdev.dev_port based on device channel index (Jimmy Assarsson) - can: kvaser_pciefd: Store device channel index (Jimmy Assarsson) - wifi: brcmfmac: fix P2P discovery failure in P2P peer due to missing P2P IE (Gokul Sivakumar) - Reapply 'wifi: mac80211: Update skb's control block key in ieee80211_tx_dequeue()' (Remi Pommarel) - mwl8k: Add missing check after DMA map (Thomas Fourier) - wifi: rtl8xxxu: Fix RX skb size for aggregation disabled (Martin Kaistra) - net/sched: Restrict conditions for adding duplicating netems to qdisc tree (William Liu) [Orabug: 38331466] {CVE-2025-38553} - arch: powerpc: defconfig: Drop obsolete CONFIG_NET_CLS_TCINDEX (Johan Korsnes) - drm/amd/pm/powerplay/hwmgr/smu_helper: fix order of mask and value (Fedor Pchelkin) - m68k: Don't unregister boot console needlessly (Finn Thain) - tcp: fix tcp_ofo_queue() to avoid including too much DUP SACK range (Xin Guo) - iwlwifi: Add missing check for alloc_ordered_workqueue (Jiasheng Jiang) [Orabug: 38335110] {CVE-2025-38602} - wifi: iwlwifi: Fix memory leak in iwl_mvm_init() (Xiu Jianfeng) - wifi: rtl818x: Kill URBs before clearing tx status queue (Daniil Dulov) [Orabug: 38335120] {CVE-2025-38604} - caif: reduce stack size, again (Arnd Bergmann) - bpftool: Fix memory leak in dump_xx_nlmsg on realloc failure (Yuan Chen) - bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls (Jiayuan Chen) [Orabug: 38335131] {CVE-2025-38608} - staging: nvec: Fix incorrect null termination of battery manufacturer (Alok Tiwari) - samples: mei: Fix building on musl libc (Brahmajit Das) - cpufreq: Init policy-rwsem before it may be possibly used (Lifeng Zheng) - ARM: dts: imx6ul-kontron-bl-common: Fix RTS polarity for RS485 interface (Annette Kobou) - usb: early: xhci-dbc: Fix early_ioremap leak (Lucas De Marchi) - Revert 'vmci: Prevent the dispatching of uninitialized payloads' (Greg Kroah-Hartman) - pps: fix poll support (Denis Osterland-Heim) - vmci: Prevent the dispatching of uninitialized payloads (Lizhi Xu) - staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc() (Abdun Nihaal) [Orabug: 38335153] {CVE-2025-38612} - ARM: dts: vfxxx: Correctly use two tuples for timer address (Krzysztof Kozlowski) - hfsplus: remove mutex_lock check in hfsplus_free_extents (Yangtao Li) - ASoC: Intel: fix SND_SOC_SOF dependencies (Arnd Bergmann) - ethernet: intel: fix building with large NR_CPUS (Arnd Bergmann) - usb: phy: mxs: disconnect line when USB charger is attached (Xu Yang) - usb: chipidea: add USB PHY event (Xu Yang) - usb: chipidea: introduce CI_HDRC_CONTROLLER_VBUS_EVENT glue layer use (Peter Chen) - usb: chipidea: udc: protect usb interrupt enable (Li Jun) - usb: chipidea: udc: add new API ci_hdrc_gadget_connect (Peter Chen) - ALSA: hda: Add missing NVIDIA HDA codec IDs (Daniel Dadap) - comedi: comedi_test: Fix possible deletion of uninitialized timers (Ian Abbott) - nilfs2: reject invalid file types when reading inodes (Ryusuke Konishi) - i2c: qup: jump out of the loop in case of timeout (Yang Xiwen) [Orabug: 38351994] {CVE-2025-38671} - net/sched: sch_qfq: Avoid triggering might_sleep in atomic context in qfq_delete_class (Xiang Mei) - net: appletalk: Fix use-after-free in AARP proxy probe (Kito Xu) - net: appletalk: fix kerneldoc warnings (Andrew Lunn) - RDMA/core: Rate limit GID cache warning messages (Maor Gottlieb) - regulator: core: fix NULL dereference on unbind due to stale coupling data (Alessandro Carminati) [Orabug: 38351978] {CVE-2025-38668} - usb: hub: Fix flushing and scheduling of delayed work that tunes runtime pm (Mathias Nyman) - usb: hub: fix detection of high tier USB3 devices behind suspended hubs (Mathias Nyman) - net_sched: sch_sfq: reject invalid perturb period (Eric Dumazet) [Orabug: 38158477] {CVE-2025-38193} - power: supply: bq24190: Fix use after free bug in bq24190_remove due to race condition (Zheng Wang) - power: supply: bq24190_charger: using pm_runtime_resume_and_get instead of pm_runtime_get_sync (Minghao Chi) - power: supply: bq24190_charger: Fix runtime PM imbalance on error (Dinghao Liu) - xhci: Disable stream for xHC controller with XHCI_BROKEN_STREAMS (Hongyu Xie) - virtio-net: ensure the received length does not exceed allocated size (Bui Quang Minh) [Orabug: 38253834] {CVE-2025-38375} - ASoC: fsl_sai: Force a software reset when starting in consumer mode (Arun Raghavan) - usb: dwc3: qcom: Don't leave BCR asserted (Krishna Kurapati) - usb: musb: fix gadget state on disconnect (Drew Hamilton) - net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree (William Liu) [Orabug: 38254214] {CVE-2025-38468} - net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime (Dong Chenchen) [Orabug: 38254225] {CVE-2025-38470} - Bluetooth: L2CAP: Fix attempting to adjust outgoing MTU (Luiz Augusto von Dentz) - Bluetooth: SMP: Fix using HCI_ERROR_REMOTE_USER_TERM on timeout (Luiz Augusto von Dentz) - Bluetooth: SMP: If an unallowed command is received consider it a failure (Luiz Augusto von Dentz) - Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb() (Kuniyuki Iwashima) [Orabug: 38254241] {CVE-2025-38473} - usb: net: sierra: check for no status endpoint (Oliver Neukum) [Orabug: 38254249] {CVE-2025-38474} - net/sched: sch_qfq: Fix race condition on qfq_aggregate (Xiang Mei) [Orabug: 38254266] {CVE-2025-38477} - net: emaclite: Fix missing pointer increment in aligned_read() (Alok Tiwari) - comedi: Fix use of uninitialized data in insn_rw_emulate_bits() (Ian Abbott) - comedi: Fix some signed shift left operations (Ian Abbott) - comedi: das6402: Fix bit shift out of bounds (Ian Abbott) - comedi: das16m1: Fix bit shift out of bounds (Ian Abbott) - comedi: aio_iiro_16: Fix bit shift out of bounds (Ian Abbott) - comedi: pcl812: Fix bit shift out of bounds (Ian Abbott) - iio: adc: stm32-adc: Fix race in installing chained IRQ handler (Chen Ni) - iio: adc: max1363: Reorder mode_list[] entries (Fabio Estevam) - iio: adc: max1363: Fix MAX1363_4X_CHANS/MAX1363_8X_CHANS[] (Fabio Estevam) - soc: aspeed: lpc-snoop: Don't disable channels that aren't enabled (Andrew Jeffery) - soc: aspeed: lpc-snoop: Cleanup resources in stack-order (Andrew Jeffery) - mmc: sdhci_am654: Workaround for Errata i2312 (Judith Mendez) - mmc: sdhci-pci: Quirk for broken command queuing on Intel GLK-based Positivo models (Edson Juliano Drosdeck) - mmc: bcm2835: Fix dma_unmap_sg() nents value (Thomas Fourier) - memstick: core: Zero initialize id_reg in h_memstick_read_dev_id() (Nathan Chancellor) - isofs: Verify inode mode when loading from disk (Jan Kara) - dmaengine: nbpfaxi: Fix memory corruption in probe() (Dan Carpenter) - af_packet: fix soft lockup issue caused by tpacket_snd() (Yun Lu) - af_packet: fix the SO_SNDTIMEO constraint not effective on tpacked_snd() (Yun Lu) - phonet/pep: Move call to pn_skb_get_dst_sockaddr() earlier in pep_sock_accept() (Nathan Chancellor) - HID: core: do not bypass hid_hw_raw_request (Benjamin Tissoires) [Orabug: 38254340,38453904] {CVE-2025-38494} - HID: core: ensure __hid_request reserves the report ID as the first byte (Benjamin Tissoires) - HID: core: ensure the allocated report buffer can contain the reserved report ID (Benjamin Tissoires) [Orabug: 38254348,38453908] {CVE-2025-38495} - pch_uart: Fix dma_sync_sg_for_device() nents value (Thomas Fourier) - Input: xpad - set correct controller type for Acer NGR200 (Nilton Perim Neto) - i2c: stm32: fix the device used for the DMA map (Clement Le Goffic) - usb: gadget: configfs: Fix OOB read on empty string write (Xinyu Liu) [Orabug: 38254358] {CVE-2025-38497} - USB: serial: ftdi_sio: add support for NDI EMGUIDE GEMINI (Ryan Mann) - USB: serial: option: add Foxconn T99W640 (Slark Xiao) - USB: serial: option: add Telit Cinterion FE910C04 (ECM) composition (Fabio Porcedda) - LTS tag: v5.4.296 (Sherry Yang) - x86/mm: Disable hugetlb page table sharing on 32-bit (Jann Horn) - Input: atkbd - do not skip atkbd_deactivate() when skipping ATKBD_CMD_GETID (Hans de Goede) - HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras (Chia-Lin Kao) [Orabug: 38324280] {CVE-2025-38540} - HID: Add IGNORE quirk for SMARTLINKTECHNOLOGY (Zhang Heng) - vt: add missing notification when switching back to text mode (Nicolas Pitre) - net: usb: qmi_wwan: add SIMCom 8230C composition (Xiaowei Li) - atm: idt77252: Add missing dma_map_error() (Thomas Fourier) - bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT (Somnath Kotur) [Orabug: 38254090] {CVE-2025-38439} - bnxt_en: Fix DCB ETS validation (Shravya Kn) - can: m_can: m_can_handle_lost_msg(): downgrade msg lost in rx message to debug level (Sean Nyekjaer) - net: phy: microchip: limit 100M workaround to link-down events on LAN88xx (Oleksij Rempel) - net: appletalk: Fix device refcount leak in atrtr_create() (Kito Xu) - md/raid1: Fix stack memory use after return in raid1_reshape (Wang Jinchao) [Orabug: 38254109] {CVE-2025-38445} - wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev() (Daniil Dulov) [Orabug: 38324161] {CVE-2025-38513} - dma-buf: fix timeout handling in dma_resv_wait_timeout v2 (Christian Konig) - Input: xpad - support Acer NGR 200 Controller (Nilton Perim Neto) - Input: xpad - add VID for Turtle Beach controllers (Vicki Pfau) - Input: xpad - add support for Amazon Game Controller (Matt Reynolds) - NFSv4/flexfiles: Fix handling of NFS level errors in I/O (Trond Myklebust) - flexfiles/pNFS: update stats on NFS4ERR_DELAY for v4.1 DSes (Tigran Mkrtchyan) - RDMA/mlx5: Fix vport loopback for MPV device (Patrisious Haddad) - netlink: Fix rmem check in netlink_broadcast_deliver(). (Kuniyuki Iwashima) - netlink: make sure we allow at least one dump skb (Jakub Kicinski) - Revert 'ACPI: battery: negate current when discharging' (Rafael J. Wysocki) - usb: gadget: u_serial: Fix race condition in TTY wakeup (Kuen-Han Tsai) [Orabug: 38254118] {CVE-2025-38448} - drm/sched: Increment job count before swapping tail spsc queue (Matthew Brost) [Orabug: 38324180] {CVE-2025-38515} - pinctrl: qcom: msm: mark certain pins as invalid for interrupts (Bartosz Golaszewski) [Orabug: 38324186] {CVE-2025-38516} - x86/mce: Make sure CMCI banks are cleared during shutdown on Intel (Jp Kobryn) - x86/mce: Don't remove sysfs if thresholding sysfs init fails (Yazen Ghannam) - x86/mce/amd: Fix threshold limit reset (Yazen Ghannam) - rxrpc: Fix oops due to non-existence of prealloc backlog struct (David Howells) - net/sched: Abort __tc_modify_qdisc if parent class does not exist (Victor Nogueira) [Orabug: 38254147] {CVE-2025-38457} - atm: clip: Fix NULL pointer dereference in vcc_sendmsg() (Yue Haibing) [Orabug: 38254153] {CVE-2025-38458} - atm: clip: Fix infinite recursive call of clip_push(). (Kuniyuki Iwashima) [Orabug: 38254161] {CVE-2025-38459} - atm: clip: Fix memory leak of struct clip_vcc. (Kuniyuki Iwashima) [Orabug: 38324309] {CVE-2025-38546} - atm: clip: Fix potential null-ptr-deref in to_atmarpd(). (Kuniyuki Iwashima) [Orabug: 38254167] {CVE-2025-38460} - tipc: Fix use-after-free in tipc_conn_close(). (Kuniyuki Iwashima) [Orabug: 38254181] {CVE-2025-38464} - netlink: Fix wraparounds of sk-sk_rmem_alloc. (Kuniyuki Iwashima) [Orabug: 38254188] {CVE-2025-38465} - fix proc_sys_compare() handling of in-lookup dentries (Al Viro) - proc: Clear the pieces of proc_inode that proc_evict_inode cares about (Eric W. Biederman) - drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling (Kaustabh Chakraborty) [Orabug: 38254203] {CVE-2025-38467} - staging: rtl8723bs: Avoid memset() in aes_cipher() and aes_decipher() (Nathan Chancellor) - media: uvcvideo: Rollback non processed entities on error (Ricardo Ribalda) - media: uvcvideo: Send control events for partial succeeds (Ricardo Ribalda) - media: uvcvideo: Return the number of processed controls (Ricardo Ribalda) - ACPI: PAD: fix crash in exit_round_robin() (Seiji Nishikawa) [Orabug: 37206006] {CVE-2024-49935} - usb: typec: displayport: Fix potential deadlock (Andrei Kuchynski) [Orabug: 38401436] {CVE-2025-38404} - Logitech C-270 even more broken (Oliver Neukum) - rose: fix dangling neighbour pointers in rose_rt_device_down() (Kohei Enju) - net: rose: Fix fall-through warnings for Clang (Gustavo A R Silva) - drm/i915/gt: Fix timeline left held on VMA alloc error (Janusz Krzysztofik) [Orabug: 38253887] {CVE-2025-38389} - drm/i915/selftests: Change mock_request() to return error pointers (Dan Carpenter) - spi: spi-fsl-dspi: Clear completion counter before initiating transfer (James Clark) - spi: spi-fsl-dspi: Fix interrupt-less DMA mode taking an XSPI code path (Vladimir Oltean) - spi: spi-fsl-dspi: Rename fifo_{read,write} and {tx,cmd}_fifo_write (Vladimir Oltean) - dpaa2-eth: fix xdp_rxq_info leak (Wangfushuai) - ethernet: atl1: Add missing DMA mapping error checks and count errors (Thomas Fourier) - btrfs: use btrfs_record_snapshot_destroy() during rmdir (Filipe Manana) - btrfs: propagate last_unlink_trans earlier when doing a rmdir (Filipe Manana) - RDMA/mlx5: Fix CC counters query for MPV (Patrisious Haddad) - RDMA/core: Create and destroy counters in the ib_core (Leon Romanovsky) - scsi: ufs: core: Fix spelling of a sysfs attribute name (Bart Van Assche) - drm/v3d: Disable interrupts before resetting the GPU (Maira Canal) - mtk-sd: reset host-mrq on prepare_data() error (Sergey Senozhatsky) - mtk-sd: Prevent memory corruption from DMA map failure (Masami Hiramatsu) - mmc: mediatek: use data instead of mrq parameter from msdc_{un}prepare_data() (Yue Hu) - regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods (Manivannan Sadhasivam) [Orabug: 38253907] {CVE-2025-38395} - regulator: gpio: Add input_supply support in gpio_regulator_config (Jerome Neanne) - ACPICA: Refuse to evaluate a method if arguments are missing (Rafael J. Wysocki) [Orabug: 38253875] {CVE-2025-38386} - wifi: ath6kl: remove WARN on bad firmware input (Johannes Berg) [Orabug: 38253946] {CVE-2025-38406} - wifi: mac80211: drop invalid source address OCB frames (Johannes Berg) - powerpc: Fix struct termio related ioctl macros (Madhavan Srinivasan) - ata: pata_cs5536: fix build on 32-bit UML (Johannes Berg) - ALSA: sb: Force to disable DMAs once when DMA mode is changed (Takashi Iwai) - nui: Fix dma_mapping_error() check (Thomas Fourier) - enic: fix incorrect MTU comparison in enic_change_mtu() (Alok Tiwari) - amd-xgbe: align CL37 AN sequence as per databook (Raju Rangoju) - lib: test_objagg: Set error message in check_expect_hints_stats() (Dan Carpenter) - drm/exynos: fimd: Guard display clock control with runtime PM calls (Marek Szyprowski) - btrfs: fix missing error handling when searching for inode refs during log replay (Filipe Manana) - scsi: qla4xxx: Fix missing DMA mapping error in qla4xxx_alloc_pdu() (Thomas Fourier) - nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init() fails. (Kuniyuki Iwashima) [Orabug: 38253923] {CVE-2025-38400} - RDMA/mlx5: Initialize obj_event-obj_sub_list before xa_insert (Mark Zhang) [Orabug: 38253881] {CVE-2025-38387} - platform/mellanox: mlxbf-tmfifo: fix vring_desc.len assignment (David Thompson) - mtk-sd: Fix a pagefault in dma_unmap_sg() for not prepared data (Masami Hiramatsu) - usb: typec: altmodes/displayport: do not index invalid pin_assignments (Rd Babiera) [Orabug: 38253894] {CVE-2025-38391} - mmc: sdhci: Add a helper function for dump register in dynamic debug mode (Victor Shih) - vsock/vmci: Clear the vmci transport packet properly when initializing it (Harshavardhana S A) [Orabug: 38253937] {CVE-2025-38403} - btrfs: don't abort filesystem when attempting to snapshot deleted subvolume (Omar Sandoval) [Orabug: 36530119] {CVE-2024-26644} - arm64: Restrict pagetable teardown to avoid false warning (Dev Jain) - s390: Add '-std=gnu11' to decompressor and purgatory CFLAGS (Nathan Chancellor) - drm/bridge: cdns-dsi: Check return value when getting default PHY config (Aradhya Bhatia) - drm/bridge: cdns-dsi: Fix connecting to next bridge (Aradhya Bhatia) - drm/bridge: cdns-dsi: Fix the clock variable for mode_valid() (Aradhya Bhatia) - drm/tegra: Assign plane type before registration (Thierry Reding) - HID: wacom: fix kobject reference count leak (Qasim Ijaz) - HID: wacom: fix memory leak on sysfs attribute creation failure (Qasim Ijaz) - HID: wacom: fix memory leak on kobject creation failure (Qasim Ijaz) - dm-raid: fix variable in journal device check (Heinz Mauelshagen) - Bluetooth: L2CAP: Fix L2CAP MTU negotiation (Frederic Danis) - atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister(). (Kuniyuki Iwashima) [Orabug: 38175045] {CVE-2025-38245} - net: enetc: Correct endianness handling in _enetc_rd_reg64 (Simon Horman) - um: ubd: Add missing error check in start_io_thread() (Tiwei Bie) - vsock/uapi: fix linux/vm_sockets.h userspace compilation errors (Stefano Garzarella) - wifi: mac80211: fix beacon interval calculation overflow (Lachlan Hodges) - attach_recursive_mnt(): do not lock the covering tree when sliding something under it (Al Viro) - ALSA: usb-audio: Fix out-of-bounds read in snd_usb_get_audioformat_uac3() (Youngjun Lee) [Orabug: 38175065] {CVE-2025-38249} - i2c: robotfuzz-osif: disable zero-length read messages (Wolfram Sang) - i2c: tiny-usb: disable zero-length read messages (Wolfram Sang) - RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction (Shin'Ichiro Kawasaki) [Orabug: 38158592] {CVE-2025-38211} - RDMA/core: Use refcount_t instead of atomic_t on refcount of iwcm_id_private (Weihang Li) - media: vivid: Change the siize of the composing (Denis Arefev) - media: omap3isp: use sgtable-based scatterlist wrappers (Marek Szyprowski) - media: cxusb: no longer judge rbuf when the write fails (Edward Adam Davis) [Orabug: 38158692] {CVE-2025-38229} - media: cxusb: use dev_dbg() rather than hand-rolled debug (Sean Young) - jfs: validate AG parameters in dbMount() to prevent crashes (Vasiliy Kovalev) - fs/jfs: consolidate sanity checking in dbMount (Dave Kleikamp) - ASoC: meson: meson-card-utils: use of_property_present() for DT parsing (Martin Blumenstingl) - of: Add of_property_present() helper (Rob Herring) - of: property: define of_property_read_u{8,16,32,64}_array() unconditionally (Michael Walle) - kbuild: hdrcheck: fix cross build with clang (Arnd Bergmann) - kbuild: add --target to correctly cross-compile UAPI headers with Clang (Masahiro Yamada) - bpfilter: match bit size of bpfilter_umh to that of the kernel (Masahiro Yamada) - kbuild: use -MMD instead of -MD to exclude system headers from dependency (Masahiro Yamada) - VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify (Ma Wupeng) [Orabug: 38152869] {CVE-2025-38102} - VMCI: check context-notify_page after call to get_user_pages_fast() to avoid GPF (George Kennedy) - ovl: Check for NULL d_inode() in ovl_dentry_upper() (Kees Cook) - ceph: fix possible integer overflow in ceph_zero_objects() (Dmitry Kandybka) - ALSA: hda: Ignore unsol events for cards being shut down (Cezary Rojewski) - usb: typec: displayport: Receive DP Status Update NAK request exit dp altmode (Jos Wang) - usb: cdc-wdm: avoid setting WDM_READ for ZLP-s (Robert Hodaszi) - usb: Add checks for snprintf() calls in usb_alloc_dev() (Andy Shevchenko) - tty: serial: uartlite: register uart driver in init (Jakub Lewalski) - usb: potential integer overflow in usbg_make_tpg() (Chen Yufeng) - iio: pressure: zpa2326: Use aligned_s64 for the timestamp (Jonathan Cameron) - md/md-bitmap: fix dm-raid max_write_behind setting (Yu Kuai) - dmaengine: xilinx_dma: Set dma_device directions (Thomas Gessler) - mfd: max14577: Fix wakeup source leaks on device unbind (Krzysztof Kozlowski) - mailbox: Not protect module_put with spin_lock_irqsave (Peng Fan) - cifs: Fix cifs_query_path_info() for Windows NT servers (Pali Rohar)

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2024-50022",
    "CVE-2025-22058",
    "CVE-2025-23143",
    "CVE-2025-39883",
    "CVE-2025-39885",
    "CVE-2025-39911",
    "CVE-2025-39913",
    "CVE-2025-39923",
    "CVE-2025-39945",
    "CVE-2025-39953",
    "CVE-2025-39955",
    "CVE-2025-39967",
    "CVE-2025-39968",
    "CVE-2025-39969",
    "CVE-2025-39970",
    "CVE-2025-39971",
    "CVE-2025-39972",
    "CVE-2025-39973",
    "CVE-2025-39993",
    "CVE-2025-39994",
    "CVE-2025-39995",
    "CVE-2025-39996",
    "CVE-2025-39998",
    "CVE-2025-40001",
    "CVE-2025-40006",
    "CVE-2025-40011",
    "CVE-2025-40018",
    "CVE-2025-40019",
    "CVE-2025-40020",
    "CVE-2025-40026",
    "CVE-2025-40027",
    "CVE-2025-40030",
    "CVE-2025-40035",
    "CVE-2025-40042",
    "CVE-2025-40044",
    "CVE-2025-40048",
    "CVE-2025-40049",
    "CVE-2025-40055",
    "CVE-2025-40070",
    "CVE-2025-40078",
    "CVE-2025-40081",
    "CVE-2025-40087",
    "CVE-2025-40105",
    "CVE-2025-40111",
    "CVE-2025-40115",
    "CVE-2025-40118",
    "CVE-2025-40125",
    "CVE-2025-40134",
    "CVE-2025-40140",
    "CVE-2025-40153",
    "CVE-2025-40167",
    "CVE-2025-40173",
    "CVE-2025-40178",
    "CVE-2025-40186",
    "CVE-2025-40187",
    "CVE-2025-40190",
    "CVE-2025-40194",
    "CVE-2025-40197",
    "CVE-2025-40198",
    "CVE-2025-40200",
    "CVE-2025-40204",
    "CVE-2025-40205",
    "CVE-2025-40219",
    "CVE-2025-40233",
    "CVE-2025-40240"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[5.4.17-2136.350.3.1]\n- Reapply 'cpuidle: menu: Avoid discarding useful information' (Harshvardhan Jha)  [Orabug: 38744458] \n- fbcon: fix integer overflow in font allocation (Samasth Norway Ananda)  [Orabug: 38744453]\n\n[5.4.17-2136.350.3]\n- net/rds: Fix rs_recv_pending counting issue (Gerd Rausch) [Orabug: 38506370]\n\n[5.4.17-2136.350.2]\n- LTS tag: v5.4.301 (Alok Tiwari)\n- net: rtnetlink: fix module reference count leak issue in rtnetlink_rcv_msg (Zhengchao Shao)\n- media: s5p-mfc: remove an unused/uninitialized variable (Arnd Bergmann)\n- NFSD: Fix last write offset handling in layoutcommit (Sergey Bashirov)\n- NFSD: Minor cleanup in layoutcommit processing (Sergey Bashirov)\n- padata: Reset next CPU when reorder sequence wraps around (Xiao Liang)\n- KEYS: trusted_tpm1: Compare HMAC values in constant time (Eric Biggers)\n- NFSD: Define a proc_layoutcommit for the FlexFiles layout type (Chuck Lever) [Orabug: 38601819] {CVE-2025-40087}\n- vfs: Don't leak disconnected dentries on umount (Jan Kara) [Orabug: 38601924] {CVE-2025-40105}\n- jbd2: ensure that all ongoing I/O complete before freeing blocks (Zhang Yi)\n- ext4: detect invalid INLINE_DATA + EXTENTS flag combination (Deepanshu Kartikey) [Orabug: 38649223] {CVE-2025-40167}\n- drm/amdgpu: use atomic functions with memory barriers for vm fault info (Gui-Dong Han)\n- ext4: avoid potential buffer over-read in parse_apply_sb_mount_options() (Theodore Ts'O) [Orabug: 38649412] {CVE-2025-40198}\n- spi: cadence-quadspi: Flush posted register writes before DAC access (Pratyush Yadav)\n- spi: cadence-quadspi: Flush posted register writes before INDAC access (Pratyush Yadav)\n- memory: samsung: exynos-srom: Fix of_iomap leak in exynos_srom_probe (Zhen Ni)\n- memory: samsung: exynos-srom: Correct alignment (Krzysztof Kozlowski)\n- arm64: errata: Apply workarounds for Neoverse-V3AE (Mark Rutland)\n- arm64: cputype: Add Neoverse-V3AE definitions (Mark Rutland)\n- comedi: fix divide-by-zero in comedi_buf_munge() (Deepanshu Kartikey)\n- binder: remove 'invalid inc weak' check (Alice Ryhl)\n- xhci: dbc: enable back DbC in resume if it was enabled before suspend (Mathias Nyman)\n- usb/core/quirks: Add Huawei ME906S to wakeup quirk (Tim Guttzeit)\n- USB: serial: option: add Telit FN920C04 ECM compositions (Li Qingwu)\n- USB: serial: option: add Quectel RG255C (Reinhard Speyerer)\n- USB: serial: option: add UNISOC UIS7720 (Renjun Wang)\n- net: ravb: Ensure memory write completes before ringing TX doorbell (Lad Prabhakar)\n- net: usb: rtl8150: Fix frame padding (Michal Pecio)\n- ocfs2: clear extent cache after moving/defragmenting extents (Deepanshu Kartikey) [Orabug: 38730547] {CVE-2025-40233}\n- MIPS: Malta: Fix keyboard resource preventing i8042 driver from registering (Maciej W. Rozycki)\n- Revert 'cpuidle: menu: Avoid discarding useful information' (Rafael J. Wysocki)\n- net: bonding: fix possible peer notify event loss or dup issue (Tonghao Zhang)\n- sctp: avoid NULL dereference when chunk data buffer is missing (Alexey Simakov) [Orabug: 38730567] {CVE-2025-40240}\n- arm64, mm: avoid always making PTE dirty in pte_mkwrite() (Huang, Ying)\n- net: enetc: correct the value of ENETC_RXB_TRUESIZE (Wei Fang)\n- rtnetlink: Allow deleting FDB entries in user namespace (Johannes Wiesboeck)\n- net: rtnetlink: add NLM_F_BULK support to rtnl_fdb_del (Nikolay Aleksandrov)\n- net: add ndo_fdb_del_bulk (Nikolay Aleksandrov)\n- net: rtnetlink: add bulk delete support flag (Nikolay Aleksandrov)\n- net: netlink: add NLM_F_BULK delete request modifier (Nikolay Aleksandrov)\n- net: rtnetlink: use BIT for flag values (Nikolay Aleksandrov)\n- net: rtnetlink: add helper to extract msg type's kind (Nikolay Aleksandrov)\n- net: rtnetlink: add msg kind names (Nikolay Aleksandrov)\n- net: rtnetlink: remove redundant assignment to variable err (Colin Ian King)\n- m68k: bitops: Fix find_*_bit() signatures (Geert Uytterhoeven)\n- hfsplus: return EIO when type of hidden directory mismatch in hfsplus_fill_super() (Yangtao Li)\n- hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits() (Viacheslav Dubeyko)\n- dlm: check for defined force value in dlm_lockspace_release (Alexander Aring)\n- hfsplus: fix KMSAN uninit-value issue in hfsplus_delete_cat() (Viacheslav Dubeyko)\n- hfs: validate record offset in hfsplus_bmap_alloc (Yang Chenzhi)\n- hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent() (Viacheslav Dubeyko)\n- hfs: make proper initalization of struct hfs_find_data (Viacheslav Dubeyko)\n- hfs: clear offset and space out of valid records in b-tree node (Viacheslav Dubeyko)\n- exec: Fix incorrect type for ret (Xichao Zhao)\n- hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp() (Viacheslav Dubeyko)\n- ALSA: firewire: amdtp-stream: fix enum kernel-doc warnings (Randy Dunlap)\n- sched/fair: Fix pelt lost idle time detection (Vincent Guittot)\n- sched/balancing: Rename newidle_balance() = sched_balance_newidle() (Ingo Molnar)\n- sched/fair: Trivial correction of the newidle_balance() comment (Barry Song)\n- sched: Make newidle_balance() static again (Chen Yu)\n- tls: don't rely on tx_work during send() (Sabrina Dubroca)\n- tls: always set record_type in tls_process_cmsg (Sabrina Dubroca)\n- tg3: prevent use of uninitialized remote_adv and local_adv variables (Alexey Simakov)\n- tcp: fix tcp_tso_should_defer() vs large RTT (Eric Dumazet)\n- amd-xgbe: Avoid spurious link down messages during interface toggle (Raju Rangoju)\n- net/ip6_tunnel: Prevent perpetual tunnel growth (Dmitry Safonov) [Orabug: 38649261] {CVE-2025-40173}\n- net: dlink: handle dma_map_single() failure properly (Moon Yeounsu)\n- net: dl2k: switch from 'pci_' to 'dma_' API (Christophe Jaillet)\n- media: pci: ivtv: Add missing check after DMA map (Thomas Fourier)\n- media: pci/ivtv: switch from 'pci_' to 'dma_' API (Christophe Jaillet)\n- xen/events: Update virq_to_irq on migration (Jason Andryuk)\n- media: lirc: Fix error handling in lirc_register() (Ma Ke)\n- media: rc: Directly use ida_free() (Keliu)\n- drm/exynos: exynos7_drm_decon: remove ctx-suspended (Kaustabh Chakraborty)\n- btrfs: avoid potential out-of-bounds in btrfs_encode_fh() (Anderson Nascimento) [Orabug: 38649463] {CVE-2025-40205}\n- pwm: berlin: Fix wrong register in suspend/resume (Jisheng Zhang)\n- media: cx18: Add missing check after DMA map (Thomas Fourier)\n- xen/events: Cleanup find_virq() return codes (Jason Andryuk)\n- cramfs: Verify inode mode when loading from disk (Tetsuo Handa)\n- fs: Add 'initramfs_options' to set initramfs mount options (Lichen Liu)\n- pid: Add a judgment for ns null in pid_nr_ns (Gaoxiang17) [Orabug: 38649276] {CVE-2025-40178}\n- minixfs: Verify inode mode when loading from disk (Tetsuo Handa)\n- tracing: Fix race condition in kprobe initialization causing NULL pointer dereference (Yuan Chen) [Orabug: 38592033] {CVE-2025-40042}\n- dm: fix NULL pointer dereference in __dm_suspend() (Zheng Qixing) [Orabug: 38649057] {CVE-2025-40134}\n- mfd: intel_soc_pmic_chtdc_ti: Set use_single_read regmap_config flag (Hans de Goede)\n- mfd: intel_soc_pmic_chtdc_ti: Drop unneeded assignment for cache_type (Andy Shevchenko)\n- mfd: intel_soc_pmic_chtdc_ti: Fix invalid regmap-config max_register value (Hans de Goede)\n- Squashfs: reject negative file sizes in squashfs_read_inode() (Phillip Lougher) [Orabug: 38649425] {CVE-2025-40200}\n- Squashfs: add additional inode sanity checking (Phillip Lougher)\n- media: mc: Clear minor number before put device (Edward Adam Davis) [Orabug: 38649399] {CVE-2025-40197}\n- mfd: vexpress-sysreg: Check the return value of devm_gpiochip_add_data() (Bartosz Golaszewski)\n- fs: udf: fix OOB read in lengthAllocDescs handling (Larshin Sergey) [Orabug: 38592048] {CVE-2025-40044}\n- KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (Sean Christopherson) [Orabug: 38591959] {CVE-2025-40026}\n- net/9p: fix double req put in p9_fd_cancelled (Nalivayko Sergey) [Orabug: 38591965] {CVE-2025-40027}\n- ext4: guard against EA inode refcount underflow in xattr update (Ahmet Eray Karadag) [Orabug: 38649330] {CVE-2025-40190}\n- ext4: correctly handle queries for metadata mappings (Ojaswin Mujoo)\n- ext4: increase i_disksize to offset + len in ext4_update_disksize_before_punch() (Yongjian Sun)\n- nfsd: nfserr_jukebox in nlm_fopen should lead to a retry (Olga Kornievskaia)\n- x86/umip: Fix decoding of register forms of 0F 01 (SGDT and SIDT aliases) (Sean Christopherson)\n- x86/umip: Check that the instruction opcode is at least two bytes (Sean Christopherson)\n- PCI: keystone: Use devm_request_irq() to free 'ks-pcie-error-irq' on exit (Siddharth Vadapalli)\n- PCI/AER: Fix missing uevent on recovery when a reset is requested (Niklas Schnelle)\n- PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV (Niklas Schnelle) [Orabug: 38730513] {CVE-2025-40219}\n- rseq/selftests: Use weak symbol reference, not definition, to link with glibc (Sean Christopherson)\n- rtc: interface: Fix long-standing race when setting alarm (Esben Haabendal)\n- rtc: interface: Ensure alarm irq is enabled when UIE is enabled (Esben Haabendal)\n- mmc: core: SPI mode remove cmd7 (Rex Chen)\n- mtd: rawnand: fsmc: Default to autodetect buswidth (Linus Walleij)\n- sparc: fix error handling in scan_one_device() (Ma Ke)\n- sparc64: fix hugetlb for sun4u (Anthony Yznaga)\n- sctp: Fix MAC comparison to be constant-time (Eric Biggers) [Orabug: 38649451] {CVE-2025-40204}\n- scsi: hpsa: Fix potential memory leak in hpsa_big_passthru_ioctl() (Thorsten Blum)\n- parisc: don't reference obsolete termio struct for TC* constants (Sam James)\n- lib/genalloc: fix device leak in of_gen_pool_get() (Johan Hovold)\n- iio: frequency: adf4350: Fix prescaler usage. (Michael Hennerich)\n- iio: dac: ad5421: use int type to store negative error codes (Rong Qianfeng)\n- iio: dac: ad5360: use int type to store negative error codes (Rong Qianfeng)\n- crypto: atmel - Fix dma_unmap_sg() direction (Thomas Fourier)\n- cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request() (Rafael J. Wysocki) [Orabug: 38649367] {CVE-2025-40194}\n- drm/nouveau: fix bad ret code in nouveau_bo_move_prep (Shuhao Fu)\n- media: i2c: mt9v111: fix incorrect type for ret (Rong Qianfeng)\n- firmware: meson_sm: fix device leak at probe (Johan Hovold)\n- xen/manage: Fix suspend error path (Lukas Wunner)\n- arm64: dts: qcom: msm8916: Add missing MDSS reset (Stephan Gerhold)\n- ACPI: debug: fix signedness issues in read/write helpers (Amir Mohammad Jahangirzad)\n- ACPI: TAD: Add missing sysfs_remove_group() for ACPI_TAD_RT (Daniel Tang)\n- tpm_tis: Fix incorrect arguments in tpm_tis_probe_irq_single (Gunnar Kudrjavets)\n- tpm, tpm_tis: Claim locality before writing interrupt registers (Lino Sanfilippo)\n- crypto: essiv - Check ssize for decryption and in-place encryption (Herbert Xu) [Orabug: 38581456,38705546] {CVE-2025-40019}\n- mailbox: zynqmp-ipi: Remove dev.parent check in zynqmp_ipi_free_mboxes (Harini T)\n- mailbox: zynqmp-ipi: Remove redundant mbox_controller_unregister() call (Harini T)\n- tools build: Align warning options with perf (Leo Yan)\n- net: fsl_pq_mdio: Fix device node reference leak in fsl_pq_mdio_probe (Erick Karanja)\n- tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request(). (Kuniyuki Iwashima) [Orabug: 38649579] {CVE-2025-40186}\n- net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce() (Alexandr Sapozhnikov) [Orabug: 38649313] {CVE-2025-40187}\n- drm/vmwgfx: Fix Use-after-free in validation (Ian Forbes) [Orabug: 38643546] {CVE-2025-40111}\n- net/mlx4: prevent potential use after free in mlx4_en_do_uc_filter() (Dan Carpenter)\n- scsi: mvsas: Fix use-after-free bugs in mvs_work_queue (Duoming Zhou) [Orabug: 38557654] {CVE-2025-40001}\n- scsi: mvsas: Use sas_task_find_rq() for tagging (John Garry)\n- scsi: mvsas: Delete mvs_tag_init() (John Garry)\n- scsi: libsas: Add sas_task_find_rq() (John Garry)\n- clk: nxp: Fix pll0 rate check condition in LPC18xx CGU driver (Alok Tiwari)\n- clk: nxp: lpc18xx-cgu: convert from round_rate() to determine_rate() (Brian Masney)\n- perf session: Fix handling when buffer exceeds 2 GiB (Leo Yan)\n- rtc: x1205: Fix Xicor X1205 vendor prefix (Rob Herring)\n- perf util: Fix compression checks returning -1 as bool (Yunseong Kim)\n- iio: frequency: adf4350: Fix ADF4350_REG3_12BIT_CLKDIV_MODE (Michael Hennerich)\n- clocksource/drivers/clps711x: Fix resource leaks in error paths (Zhen Ni)\n- pinctrl: check the return value of pinmux_ops::get_function_name() (Bartosz Golaszewski) [Orabug: 38591981] {CVE-2025-40030}\n- Input: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak (Zhen Ni) [Orabug: 38592002] {CVE-2025-40035}\n- mm: hugetlb: avoid soft lockup when mprotect to large memory area (Yang Shi) [Orabug: 38649150] {CVE-2025-40153}\n- uio_hv_generic: Let userspace take care of interrupt mask (Naman Jain) [Orabug: 38592067] {CVE-2025-40048}\n- Squashfs: fix uninit-value in squashfs_get_parent (Phillip Lougher) [Orabug: 38592077] {CVE-2025-40049}\n- net: ena: return 0 in ena_get_rxfh_key_size() when RSS hash key is not configurable (Kohei Enju)\n- nfp: fix RSS hash key size when RSS is not supported (Kohei Enju)\n- drivers/base/node: fix double free in register_one_node() (Donet Tom)\n- ocfs2: fix double free in user_cluster_connect() (Dan Carpenter) [Orabug: 38592110] {CVE-2025-40055}\n- net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast (I Viswanath) [Orabug: 38649096] {CVE-2025-40140}\n- RDMA/siw: Always report immediate post SQ errors (Bernard Metzler)\n- usb: vhci-hcd: Prevent suspending virtually attached devices (Cristian Ciocaltea)\n- scsi: mpt3sas: Fix crash in transport port remove by using ioc_info() (Ranjan Kumar) [Orabug: 38648982] {CVE-2025-40115}\n- ipvs: Defer ip_vs_ftp unregister during netns cleanup (Slavin Liu) [Orabug: 38581446] {CVE-2025-40018}\n- NFSv4.1: fix backchannel max_resp_sz verification check (Anthony Iliopoulos)\n- remoteproc: qcom: q6v5: Avoid disabling handover IRQ twice (Stephan Gerhold)\n- sparc: fix accurate exception reporting in copy_{from,to}_user for M7 (Michael Karcher)\n- sparc: fix accurate exception reporting in copy_to_user for Niagara 4 (Michael Karcher)\n- sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara (Michael Karcher)\n- sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC III (Michael Karcher)\n- sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC (Michael Karcher)\n- IB/sa: Fix sa_local_svc_timeout_ms read race (Vlad Dumitrescu)\n- RDMA/core: Resolve MAC of next-hop device without ARP support (Parav Pandit)\n- wifi: mt76: fix potential memory leak in mt76_wmac_probe() (Abdun Nihaal)\n- drivers/base/node: handle error properly in register_one_node() (Donet Tom)\n- watchdog: mpc8xxx_wdt: Reload the watchdog timer when enabling the watchdog (Christophe Leroy)\n- netfilter: ipset: Remove unused htable_bits in macro ahash_region (Zhen Ni)\n- iio: consumers: Fix offset handling in iio_convert_raw_to_processed() (Hans de Goede)\n- ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping (Takashi Iwai)\n- ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping (Takashi Iwai)\n- ASoC: Intel: bytcht_es8316: Fix invalid quirk input mapping (Takashi Iwai)\n- pps: fix warning in pps_register_cdev when register device fail (Wang Liang) [Orabug: 38592170] {CVE-2025-40070}\n- misc: genwqe: Fix incorrect cmd field being reported in error (Colin Ian King)\n- usb: gadget: configfs: Correctly set use_os_string at bind (William Wu)\n- usb: phy: twl6030: Fix incorrect type for ret (Xichao Zhao)\n- tcp: fix __tcp_close() to only send RST when required (Eric Dumazet)\n- PCI: tegra: Fix devm_kcalloc() argument order for port-phys allocation (Alok Tiwari)\n- wifi: mwifiex: send world regulatory domain to driver (Stefan Kerkmann)\n- ALSA: lx_core: use int type to store negative error codes (Rong Qianfeng)\n- media: rj54n1cb0c: Fix memleak in rj54n1_probe() (Zhang Shurong)\n- scsi: myrs: Fix dma_alloc_coherent() error check (Thomas Fourier)\n- scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod (Niklas Cassel) [Orabug: 38649567] {CVE-2025-40118}\n- serial: max310x: Add error checking in probe() (Dan Carpenter)\n- usb: host: max3421-hcd: Fix error pointer dereference in probe cleanup (Dan Carpenter)\n- drm/radeon/r600_cs: clean up of dead code in r600_cs (Brahmajit Das)\n- i2c: designware: Add disabling clocks when probe fails (Kunihiko Hayashi)\n- i2c: mediatek: fix potential incorrect use of I2C_MASTER_WRRD (Leilk Liu)\n- bpf: Explicitly check accesses to bpf_sock_addr (Paul Chaignon) [Orabug: 38592205] {CVE-2025-40078}\n- selftests: watchdog: skip ping loop if WDIOF_KEEPALIVEPING not supported (Akhilesh Patil)\n- pwm: tiehrpwm: Fix corner case in clock divisor calculation (Uwe Kleine-Konig)\n- block: use int to store blk_stack_limits() return value (Rong Qianfeng)\n- blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx (Li Nan) [Orabug: 38649026] {CVE-2025-40125}\n- pinctrl: meson-gxl: add missing i2c_d pinmux (Da Xue)\n- soc: qcom: rpmh-rsc: Unconditionally clear _TRIGGER bit for TCS (Sneh Mankad)\n- ACPI: processor: idle: Fix memory leak when register cpuidle device failed (Huisong Li)\n- regmap: Remove superfluous check for !config in __regmap_init() (Geert Uytterhoeven)\n- x86/vdso: Fix output operand size of RDPID (Uros Bizjak)\n- perf: arm_spe: Prevent overflow in PERF_IDX2OFF() (Leo Yan) [Orabug: 38592223] {CVE-2025-40081}\n- driver core/PM: Set power.no_callbacks along with power.no_pm (Rafael J. Wysocki)\n- staging: axis-fifo: flush RX FIFO on read errors (Ovidiu Panait)\n- staging: axis-fifo: fix maximum TX packet length check (Ovidiu Panait)\n- perf subcmd: avoid crash in exclude_cmds when excludes is empty (Hupu)\n- dm-integrity: limit MAX_TAG_SIZE to 255 (Mikulas Patocka)\n- wifi: rtlwifi: rtl8192cu: Don't claim USB ID 07b8:8188 (Bitterblue Smith)\n- USB: serial: option: add SIMCom 8230C compositions (Xiaowei Li)\n- media: rc: fix races with imon_disconnect() (Larshin Sergey) [Orabug: 38548027] {CVE-2025-39993}\n- media: imon: grab lock earlier in imon_ir_change_protocol() (Tetsuo Handa)\n- media: imon: reorganize serialization (Tetsuo Handa)\n- media: rc: Add support for another iMON 0xffdc device (Flavius Georgescu)\n- media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe (Duoming Zhou) [Orabug: 38548044] {CVE-2025-39995}\n- media: tuner: xc5000: Fix use-after-free in xc5000_release (Duoming Zhou) [Orabug: 38548037] {CVE-2025-39994}\n- media: tunner: xc5000: Refactor firmware load (Ricardo Ribalda)\n- udp: Fix memory accounting leak. (Kuniyuki Iwashima) [Orabug: 37844325] {CVE-2025-22058}\n- media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove (Duoming Zhou) [Orabug: 38548051] {CVE-2025-39996}\n- scsi: target: target_core_configfs: Add length check to avoid buffer overflow (Wang Haoran) [Orabug: 38548059] {CVE-2025-39998}\n- LTS tag: v5.4.300 (Alok Tiwari)\n- KVM: SVM: Sync TPR from LAPIC into VMCB::V_TPR even if AVIC is active (Maciej S. Szmigiero)\n- mm/hugetlb: fix folio is still mapped when deleted (Tu Jinjiang) [Orabug: 38560482] {CVE-2025-40006}\n- i40e: add mask to apply valid bits for itr_idx (Lukasz Czapnik)\n- i40e: fix validation of VF state in get resources (Lukasz Czapnik) [Orabug: 38547929] {CVE-2025-39969}\n- i40e: fix idx validation in config queues msg (Lukasz Czapnik) [Orabug: 38547938] {CVE-2025-39971}\n- i40e: add validation for ring_len param (Lukasz Czapnik) [Orabug: 38547952,38604168,38604171] {CVE-2025-39973}\n- i40e: increase max descriptors for XL710 (Justin Bronder)\n- mm/migrate_device: don't add folio to be freed to LRU in migrate_device_finalize() (David Hildenbrand)\n- fbcon: Fix OOB access in font allocation (Thomas Zimmermann)\n- fbcon: fix integer overflow in fbcon_do_set_font (Samasth Norway Ananda) [Orabug: 38547913] {CVE-2025-39967}\n- i40e: add max boundary check for VF filters (Lukasz Czapnik) [Orabug: 38547923] {CVE-2025-39968}\n- i40e: fix input validation logic for action_meta (Lukasz Czapnik) [Orabug: 38547933] {CVE-2025-39970}\n- i40e: fix idx validation in i40e_validate_queue_map (Lukasz Czapnik) [Orabug: 38547946] {CVE-2025-39972}\n- drm/gma500: Fix null dereference in hdmi teardown (Zabelin Nikita) [Orabug: 38560496] {CVE-2025-40011}\n- can: peak_usb: fix shift-out-of-bounds issue (Stephane Grosjean) [Orabug: 38581463] {CVE-2025-40020}\n- can: mcba_usb: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol)\n- can: sun4i_can: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol)\n- can: hi311x: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol)\n- can: rcar_can: rcar_can_resume(): fix s2ram with PSCI (Geert Uytterhoeven)\n- IB/mlx5: Fix obj_type mismatch for SRQ event subscriptions (Or Har-Toov)\n- usb: core: Add 0x prefix to quirks debug output (Jiayi Li)\n- ALSA: usb-audio: Fix build with CONFIG_INPUT=n (Takashi Iwai)\n- ALSA: usb-audio: Convert comma to semicolon (Chen Ni)\n- ALSA: usb-audio: Add mixer quirk for Sony DualSense PS5 (Cristian Ciocaltea)\n- ALSA: usb-audio: Remove unneeded wmb() in mixer_quirks (Cristian Ciocaltea)\n- ALSA: usb-audio: Simplify NULL comparison in mixer_quirks (Cristian Ciocaltea)\n- ALSA: usb-audio: Avoid multiple assignments in mixer_quirks (Cristian Ciocaltea)\n- ALSA: usb-audio: Fix block comments in mixer_quirks (Cristian Ciocaltea)\n- net: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer (Hans de Goede)\n- net: rfkill: gpio: add DT support (Philipp Zabel)\n- serial: sc16is7xx: fix bug in flow control levels init (Hugo Villeneuve)\n- USB: gadget: dummy-hcd: Fix locking bug in RT-enabled kernels (Alan Stern)\n- usb: gadget: dummy_hcd: remove usage of list iterator past the loop body (Jakob Koschel)\n- ASoC: SOF: Intel: hda-stream: Fix incorrect variable used in error message (Colin Ian King)\n- ASoC: wm8974: Correct PLL rate rounding (Charles Keepax)\n- ASoC: wm8940: Correct typo in control name (Charles Keepax)\n- mmc: mvsdio: Fix dma_unmap_sg() nents value (Thomas Fourier)\n- nilfs2: fix CFI failure when accessing /sys/fs/nilfs2/features/* (Nathan Chancellor)\n- cnic: Fix use-after-free bugs in cnic_delete_task (Duoming Zhou) [Orabug: 38503849] {CVE-2025-39945}\n- net: liquidio: fix overflow in octeon_init_instr_queue() (Alexey Nepomnyashih)\n- tcp: Clear tcp_sk(sk)-fastopen_rsk in tcp_disconnect(). (Kuniyuki Iwashima) [Orabug: 38526388] {CVE-2025-39955}\n- i40e: remove redundant memory barrier when cleaning Tx descs (Maciej Fijalkowski)\n- net: natsemi: fix rx_dropped double accounting on netif_rx() failure (Moon Yeounsu)\n- cgroup: split cgroup_destroy_wq into 3 workqueues (Chen Ridong) [Orabug: 38503892] {CVE-2025-39953}\n- pcmcia: omap_cf: Mark driver struct with __refdata to prevent section mismatch (Geert Uytterhoeven)\n- wifi: mac80211: fix incorrect type for ret (Liao Yuanhong)\n- ALSA: firewire-motu: drop EPOLLOUT from poll return values as write is not supported (Takashi Sakamoto)\n- mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory (Miaohe Lin) [Orabug: 38461848] {CVE-2025-39883}\n- phy: ti-pipe3: fix device leak at unbind (Johan Hovold)\n- dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees (Stephan Gerhold) [Orabug: 38494822] {CVE-2025-39923}\n- dmaengine: ti: edma: Fix memory allocation size for queue_priority_map (Anders Roxell)\n- can: j1939: j1939_local_ecu_get(): undo increment when j1939_local_ecu_get() fails (Tetsuo Handa)\n- can: j1939: j1939_sk_bind(): call j1939_priv_put() immediately when j1939_local_ecu_get() failed (Tetsuo Handa)\n- i40e: fix IRQ freeing in i40e_vsi_request_irq_msix error path (Michal Schmidt) [Orabug: 38494787] {CVE-2025-39911}\n- i40e: Use irq_update_affinity_hint() (Nitesh Narayan Lal)\n- genirq: Provide new interfaces for affinity hints (Thomas Gleixner)\n- genirq: Export affinity setter for modules (Thomas Gleixner)\n- genirq/affinity: Add irq_update_affinity_desc() (John Garry)\n- igb: fix link test skipping when interface is admin down (Kohei Enju)\n- net: fec: Fix possible NPD in fec_enet_phy_reset_after_clk_enable() (Stefan Wahren)\n- USB: serial: option: add Telit Cinterion LE910C4-WWX new compositions (Fabio Porcedda)\n- USB: serial: option: add Telit Cinterion FN990A w/audio compositions (Fabio Porcedda)\n- tty: hvc_console: Call hvc_kick in hvc_write unconditionally (Fabian Vogt)\n- mtd: nand: raw: atmel: Respect tAR, tCLR in read setup timing (Alexander Sverdlin)\n- mtd: nand: raw: atmel: Fix comment in timings preparation (Alexander Dahl)\n- mtd: rawnand: stm32_fmc2: avoid overlapping mappings on ECC buffer (Christophe Kerello)\n- mm/khugepaged: fix the address passed to notifier on testing young (Wei Yang)\n- fuse: prevent overflow in copy_file_range return value (Miklos Szeredi)\n- fuse: check if copy_file_range() returns larger than requested size (Miklos Szeredi)\n- mtd: rawnand: stm32_fmc2: fix ECC overwrite (Christophe Kerello)\n- ocfs2: fix recursive semaphore deadlock in fiemap call (Mark Tinguely) [Orabug: 38461859] {CVE-2025-39885}\n- EDAC/altera: Delete an inappropriate dma_free_coherent() call (Salah Triki)\n- tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock-cork. (Kuniyuki Iwashima) [Orabug: 38494797] {CVE-2025-39913}\n- net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod. (Kuniyuki Iwashima) [Orabug: 37901604] {CVE-2025-23143}\n\n[5.4.17-2136.350.1]\n- device-dax: correct pgoff align in dax_set_mapping() (Kun(Llfl)) [Orabug: 37206404] {CVE-2024-50022}\n\n[5.4.17-2136.349.3]\n- Revert 'net/mlx5e: Update and set Xon/Xoff upon MTU set' (Jakub Kicinski) [Orabug: 38545204]\n- KVM: x86: Take irqfds.lock when adding/deleting IRQ bypass producer (Sean Christopherson) [Orabug: 38494247]\n- rds: Free all frags when rds_ib_recv_cache_put() fails (Hans Westgaard Ry) [Orabug: 38492234]\n\n[5.4.17-2136.349.2]\n- bpf/bpf_get,set_sockopt: add option to set TCP-BPF sock ops flags (Alan Maguire) [Orabug: 36699199]\n\n[5.4.17-2136.349.1]\n- NFSv4: Don't clear capabilities that won't be reset (Trond Myklebust)\n- power: supply: bq27xxx: restrict no-battery detection to bq27000 (H. Nikolaus Schaller)\n- power: supply: bq27xxx: fix error return in case of no bq27000 hdq battery (H. Nikolaus Schaller)\n- usb: hub: Fix flushing of delayed work used for post resume purposes (Mathias Nyman)\n- soc: qcom: mdt_loader: Deal with zero e_shentsize (Bjorn Andersson)\n- Revert 'net/mlx5e: Update and set Xon/Xoff upon port speed set' (Tariq Toukan)\n- LTS tag: v5.4.299 (Alok Tiwari)\n- scsi: lpfc: Fix buffer free/clear order in deferred receive path (John Evans) [Orabug: 38456754] {CVE-2025-39841}\n- dmaengine: mediatek: Fix a flag reuse error in mtk_cqdma_tx_status() (Qiu-Ji Chen)\n- cifs: fix integer overflow in match_server() (Roman Smirnov)\n- spi: spi-fsl-lpspi: Reset FIFO and disable module on transfer abort (Larisa Grigore)\n- spi: spi-fsl-lpspi: Set correct chip-select polarity bit (Larisa Grigore)\n- spi: spi-fsl-lpspi: Fix transmissions when using CONT (Larisa Grigore)\n- pcmcia: Add error handling for add_interval() in do_validate_mem() (Xu Wang)\n- ALSA: hda/hdmi: Add pin fix for another HP EliteDesk 800 G4 model (Takashi Iwai)\n- randstruct: gcc-plugin: Fix attribute addition (Kees Cook)\n- randstruct: gcc-plugin: Remove bogus void member (Kees Cook)\n- vmxnet3: update MTU after device quiesce (Ronak Doshi)\n- net: dsa: microchip: linearize skb for tail-tagging switches (Jakob Unterwurzacher)\n- net: dsa: microchip: update tag_ksz masks for KSZ9477 family (Pieter Van Trappen)\n- dmaengine: mediatek: Fix a possible deadlock error in mtk_cqdma_tx_status() (Qiu-Ji Chen)\n- ALSA: hda/realtek - Add new HP ZBook laptop with micmute led fixup (Chris Chiu)\n- gpio: pca953x: fix IRQ storm on system wake up (Emanuele Ghidoli)\n- iio: light: opt3001: fix deadlock due to concurrent flag access (Luca Ceresoli) [Orabug: 37977028] {CVE-2025-37968}\n- iio: chemical: pms7003: use aligned_s64 for timestamp (David Lechner)\n- cpufreq/sched: Explicitly synchronize limits_changed flag handling (Rafael J. Wysocki)\n- mm/slub: avoid accessing metadata when pointer is invalid in object_err() (Li Qiong) [Orabug: 38494761] {CVE-2025-39902}\n- mm/khugepaged: fix -anon_vma race (Jann Horn)\n- e1000e: fix heap overflow in e1000_set_eeprom (Vitaly Lifshits)\n- batman-adv: fix OOB read/write in network-coding decode (Stanislav Fort)\n- drm/amdgpu: drop hw access in non-DC audio fini (Alex Deucher)\n- wifi: mwifiex: Initialize the chan_stats array to zero (Rong Qianfeng) [Orabug: 38494723] {CVE-2025-39891}\n- pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region() (Ma Ke)\n- ALSA: usb-audio: Add mute TLV for playback volumes on some devices (Cryolitia Pukngae)\n- ppp: fix memory leak in pad_compress_skb (Qingfang Deng) [Orabug: 38456781] {CVE-2025-39847}\n- net: atm: fix memory leak in atm_register_sysfs when device_register fail (Wang Liang)\n- ax25: properly unshare skbs in ax25_kiss_rcv() (Eric Dumazet)\n- ipv4: Fix NULL vs error pointer check in inet_blackhole_dev_init() (Dan Carpenter)\n- net: thunder_bgx: add a missing of_node_put (Rosen Penev)\n- wifi: libertas: cap SSID len in lbs_associate() (Dan Carpenter)\n- wifi: cw1200: cap SSID length in cw1200_do_join() (Dan Carpenter)\n- net: ethernet: mtk_eth_soc: fix tx vlan tag for llc packets (Felix Fietkau)\n- i40e: Fix potential invalid access when MAC list is empty (Zhen Ni) [Orabug: 38456814] {CVE-2025-39853}\n- icmp: fix icmp_ndo_send address translation for reply direction (Fabian Blase)\n- mISDN: Fix memory leak in dsp_hwec_enable() (Miaoqian Lin)\n- xirc2ps_cs: fix register access when enabling FullDuplex (Alok Tiwari)\n- Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen() (Kuniyuki Iwashima) [Orabug: 38456834] {CVE-2025-39860}\n- netfilter: conntrack: helper: Replace -EEXIST by -EBUSY (Phil Sutter)\n- wifi: cfg80211: fix use-after-free in cmp_bss() (Dmitry Antipov) [Orabug: 38456860] {CVE-2025-39864}\n- powerpc: boot: Remove leading zero in label in udelay() (Nathan Chancellor)\n\n[5.4.17-2136.348.3]\n- hugetlbfs: take read_lock on i_mmap for PMD sharing (Waiman Long) [Orabug: 38459576]\n- kallsyms: add module_kallsyms_on_each_symbol_locked (Julian Pidancet) [Orabug: 38418686]\n- kallsyms: export module_kallsyms_on_each_symbol (Julian Pidancet) [Orabug: 38418686]\n\n[5.4.17-2136.348.2]\n- uek-rpm: Move ifb module to nano modules (Harshit Mogalapalli) [Orabug: 38443798]\n- clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns (Al Viro) [Orabug: 38310007,38453918] {CVE-2025-38499}\n- x86/vmscape: Warn when STIBP is disabled with SMT (Pawan Gupta) [Orabug: 38424094]\n- x86/bugs: Move cpu_bugs_smt_update() down (Pawan Gupta) [Orabug: 38424094]\n- x86/vmscape: Enable the mitigation (Pawan Gupta) [Orabug: 38424094]\n- x86/vmscape: Add conditional IBPB mitigation (Pawan Gupta) [Orabug: 38424094]\n- x86/vmscape: Add old Intel CPUs to affected list (Pawan Gupta) [Orabug: 38424094]\n- x86/vmscape: Enumerate VMSCAPE bug (Pawan Gupta) [Orabug: 38424094]\n- Documentation/hw-vuln: Add VMSCAPE documentation (Pawan Gupta) [Orabug: 38424094]\n\n[5.4.17-2136.348.1]\n- LTS tag: v5.4.298 (Sherry Yang)\n- Revert 'drm/dp: Change AUX DPCD probe address from DPCD_REV to LANE0_1_STATUS' (Imre Deak)\n- net: usb: qmi_wwan: add Telit Cinterion LE910C4-WWX new compositions (Fabio Porcedda)\n- Revert 'drm/amdgpu: fix incorrect vm flags to map bo' (Alex Deucher) [Orabug: 38343661]\n- HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() (Minjong Kim) [Orabug: 38440228] {CVE-2025-39808}\n- HID: wacom: Add a new Art Pen 2 (Ping Cheng)\n- HID: asus: fix UAF via HID_CLAIMED_INPUT validation (Qasim Ijaz) [Orabug: 38440310] {CVE-2025-39824}\n- efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare (Li Nan) [Orabug: 38440277] {CVE-2025-39817}\n- sctp: initialize more fields in sctp_v6_from_sk() (Eric Dumazet) [Orabug: 38440251] {CVE-2025-39812}\n- net: stmmac: xgmac: Do not enable RX FIFO Overflow interrupts (Rohan G Thomas)\n- net/mlx5e: Set local Xoff after FW update (Alexei Lazar)\n- net/mlx5e: Update and set Xon/Xoff upon port speed set (Alexei Lazar)\n- net/mlx5e: Update and set Xon/Xoff upon MTU set (Alexei Lazar)\n- net: dlink: fix multicast stats being counted incorrectly (Moon Yeounsu)\n- atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control(). (Kuniyuki Iwashima) [Orabug: 38440347] {CVE-2025-39828}\n- net/atm: remove the atmdev_ops {get, set}sockopt methods (Christoph Hellwig)\n- Bluetooth: hci_event: Detect if HCI_EV_NUM_COMP_PKTS is unbalanced (Luiz Augusto von Dentz)\n- powerpc/kvm: Fix ifdef to remove build warning (Madhavan Srinivasan)\n- net: ipv4: fix regression in local-broadcast routes (Oscar Maes) [Orabug: 38343661]\n- vhost/net: Protect ubufs with rcu read lock in vhost_net_ubuf_put() (Nikolay Kuratov)\n- scsi: core: sysfs: Correct sysfs attributes access rights (Damien Le Moal)\n- ftrace: Fix potential warning in trace_printk_seq during ftrace_dump (Tengda Wu) [Orabug: 38440259] {CVE-2025-39813}\n- pinctrl: STMFX: add missing HAS_IOMEM dependency (Randy Dunlap)\n- LTS tag: v5.4.297 (Sherry Yang)\n- alloc_fdtable(): change calling conventions. (Al Viro)\n- s390/hypfs: Enable limited access during lockdown (Peter Oberparleiter)\n- s390/hypfs: Avoid unnecessary ioctl registration in debugfs (Peter Oberparleiter)\n- ALSA: usb-audio: Use correct sub-type for UAC3 feature unit validation (Takashi Iwai)\n- net/sched: Remove unnecessary WARNING condition for empty child qdisc in htb_activate (William Liu)\n- net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit (William Liu)\n- ixgbe: xsk: resolve the negative overflow of budget in ixgbe_xmit_zc (Jason Xing)\n- ipv6: sr: validate HMAC algorithm ID in seg6_hmac_info_add (Heminhong)\n- ALSA: usb-audio: Fix size validation in convert_chmap_v3() (Dan Carpenter) [Orabug: 38343661]\n- scsi: qla4xxx: Prevent a potential error pointer dereference (Dan Carpenter) [Orabug: 38401514] {CVE-2025-39676}\n- usb: xhci: Fix slot_id resource race conflict (Weitao Wang)\n- nfs: fix UAF in direct writes (Josef Bacik) [Orabug: 36596831] {CVE-2024-26958}\n- NFS: Fix up commit deadlocks (Trond Myklebust)\n- cifs: Fix UAF in cifs_demultiplex_thread() (Zhang Xiaoxu)\n- Bluetooth: fix use-after-free in device_for_each_child() (Dmitry Antipov) [Orabug: 37433654] {CVE-2024-53237}\n- act_mirred: use the backlog for nested calls to mirred ingress (Davide Caratti) [Orabug: 34882838] {CVE: CVE-2022-4269}\n- net/sched: act_mirred: better wording on protection against excessive stack growth (Davide Caratti)\n- net/sched: act_mirred: refactor the handle of xmit (Wenxu)\n- selftests: forwarding: tc_actions.sh: add matchall mirror test (Jiri Pirko)\n- net: sched: don't expose action qstats to skb_tc_reinsert() (Vlad Buslov)\n- net: sched: extract qstats update code into functions (Vlad Buslov)\n- net: sched: extract bstats update code into function (Vlad Buslov)\n- net: sched: extract common action counters update code into function (Vlad Buslov)\n- mm: perform the mapping_map_writable() check after call_mmap() (Lorenzo Stoakes)\n- mm: update memfd seal write check to include F_SEAL_WRITE (Lorenzo Stoakes)\n- mm: drop the assumption that VM_SHARED always implies writable (Lorenzo Stoakes)\n- codel: remove sch-q.qlen check before qdisc_tree_reduce_backlog() (Cong Wang) [Orabug: 37908492] {CVE-2025-37798}\n- sch_qfq: make qfq_qlen_notify() idempotent (Cong Wang)\n- sch_hfsc: make hfsc_qlen_notify() idempotent (Cong Wang) [Orabug: 38158396] {CVE-2025-38177}\n- sch_drr: make drr_qlen_notify() idempotent (Cong Wang)\n- btrfs: populate otime when logging an inode item (Qu Wenruo)\n- media: venus: hfi: explicitly release IRQ during teardown (Jorge Ramirez-Ortiz)\n- f2fs: fix to avoid out-of-boundary access in dnode page (Chao Yu)\n- media: venus: protect against spurious interrupts during probe (Jorge Ramirez-Ortiz)\n- media: qcom: camss: cleanup media device allocated resource on error path (Vladimir Zapolskiy)\n- media: venus: vdec: Clamp param smaller than 1fps and bigger than 240. (Ricardo Ribalda)\n- drm/dp: Change AUX DPCD probe address from DPCD_REV to LANE0_1_STATUS (Imre Deak)\n- pwm: mediatek: Fix duty and period setting (Uwe Kleine-Konig)\n- pwm: mediatek: Handle hardware enable and clock enable separately (Uwe Kleine-Konig)\n- pwm: mediatek: Implement .apply() callback (Uwe Kleine-Konig)\n- media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt() (Gui-Dong Han) [Orabug: 38401677] {CVE-2025-39713}\n- media: v4l2-ctrls: Don't reset handler's error in v4l2_ctrl_handler_free() (Sakari Ailus)\n- media: v4l2-ctrls: always copy the controls on completion (Hans Verkuil)\n- ata: Fix SATA_MOBILE_LPM_POLICY description in Kconfig (Damien Le Moal)\n- soc: qcom: mdt_loader: Ensure we don't read past the ELF header (Bjorn Andersson) [Orabug: 38423524] {CVE-2025-39787}\n- rtc: ds1307: handle oscillator stop flag (OSF) for ds1341 (Meagan Lloyd)\n- usb: musb: omap2430: fix device leak at unbind (Johan Hovold)\n- NFS: Fix the setting of capabilities when automounting a new filesystem (Trond Myklebust) [Orabug: 38429211] {CVE-2025-39798}\n- NFS: Fix up handling of outstanding layoutcommit in nfs_update_inode() (Trond Myklebust)\n- NFSv4: Fix nfs4_bitmap_copy_adjust() (Trond Myklebust)\n- usb: typec: fusb302: cache PD RX state (Sebastian Reichel)\n- cdc-acm: fix race between initial clearing halt and open (Oliver Neukum)\n- USB: cdc-acm: do not log successful probe on later errors (Johan Hovold)\n- mm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock (Breno Leitao)\n- mm/kmemleak: turn kmemleak_lock and object-lock to raw_spinlock_t (He Zhe)\n- ALSA: scarlett2: Add retry on -EPROTO from scarlett2_usb_tx() (Geoffrey D. Bennett)\n- x86/fpu: Delay instruction pointer fixup until after warning (Dave Hansen)\n- mm/hmm: move pmd_to_hmm_pfn_flags() to the respective #ifdeffery (Andy Shevchenko)\n- nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() (Jeff Layton) [Orabug: 38395081,38501612] {CVE-2025-38724}\n- pmdomain: governor: Consider CPU latency tolerance from pm_domain_cpu_gov (Maulik Shah)\n- tracing: Add down_write(trace_event_sem) when adding trace event (Steven Rostedt) [Orabug: 38324271] {CVE-2025-38539}\n- usb: hub: Don't try to recover devices lost during warm reset. (Mathias Nyman)\n- usb: hub: avoid warm port reset during USB3 disconnect (Mathias Nyman)\n- x86/mce/amd: Add default names for MCA banks and blocks (Yazen Ghannam)\n- iio: hid-sensor-prox: Fix incorrect OFFSET calculation (Zhang Lixu)\n- f2fs: fix to do sanity check on ino and xnid (Chao Yu)\n- mm/zsmalloc: do not pass __GFP_MOVABLE if CONFIG_COMPACTION=n (Harry Yoo)\n- mm/zsmalloc.c: convert to use kmem_cache_zalloc in cache_alloc_zspage() (Miaohe Lin)\n- drm/sched: Remove optimization that causes hang when killing dependent jobs (Lin Cao)\n- ice: Fix a null pointer dereference in ice_copy_and_init_pkg() (Haoxiang Li) [Orabug: 38351930] {CVE-2025-38664}\n- net: usbnet: Fix the wrong netif_carrier_on() call (Ammar Faizi)\n- net: usbnet: Avoid potential RCU stall on LINK_CHANGE event (John Ernberg)\n- PCI/ACPI: Fix runtime PM ref imbalance on Hot-Plug Capable ports (Lukas Wunner)\n- ACPI: processor: idle: Check acpi_fetch_acpi_dev() return value (Li Zhong)\n- comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large (Ian Abbott)\n- comedi: Fix initialization of data for instructions that write to subdevice (Ian Abbott)\n- kbuild: Add KBUILD_CPPFLAGS to as-option invocation (Nathan Chancellor)\n- kbuild: add  to KBUILD_CPPFLAGS (Masahiro Yamada)\n- kbuild: Add CLANG_FLAGS to as-instr (Nathan Chancellor)\n- mips: Include KBUILD_CPPFLAGS in CHECKFLAGS invocation (Nathan Chancellor)\n- kbuild: Update assembler calls to use proper flags and language target (Nick Desaulniers)\n- ARM: 9448/1: Use an absolute path to unified.h in KBUILD_AFLAGS (Nathan Chancellor)\n- usb: dwc3: Ignore late xferNotReady event to prevent halt timeout (Kuen-Han Tsai)\n- USB: storage: Ignore driver CD mode for Realtek multi-mode Wi-Fi dongles (Zenm Chen)\n- usb: storage: realtek_cr: Use correct byte order for bcs-Residue (Thorsten Blum)\n- USB: storage: Add unusual-devs entry for Novatek NTK96550-based camera (Mael Guerin)\n- usb: quirks: Add DELAY_INIT quick for another SanDisk 3.2Gen1 Flash Drive (Miao Li)\n- iio: proximity: isl29501: fix buffered read on big-endian systems (David Lechner)\n- ftrace: Also allocate and copy hash for reading of filter files (Steven Rostedt) [Orabug: 38401581] {CVE-2025-39689}\n- fpga: zynq_fpga: Fix the wrong usage of dma_map_sgtable() (Xu Yilun)\n- use uniform permission checks for all mount propagation changes (Al Viro)\n- move_mount: allow to add a mount into an existing group (Pavel Tikhomirov)\n- fs/buffer: fix use-after-free when call bh_read() helper (Ye Bin) [Orabug: 38401587] {CVE-2025-39691}\n- drm/amd/display: Find first CRTC and its line time in dce110_fill_display_configs (Timur Kristof)\n- drm/amd/display: Fix fractional fb divider in set_pixel_clock_v3 (Timur Kristof)\n- memstick: Fix deadlock by moving removing flag earlier (Jiayi Li)\n- media: venus: Add a check for packet size after reading from shared memory (Vedang Nagar)\n- media: ov2659: Fix memory leaks in ov2659_probe() (Zhang Shurong)\n- media: usbtv: Lock resolution while streaming (Ludwig Disterhof) [Orabug: 38401684] {CVE-2025-39714}\n- media: imx: fix a potential memory leak in imx_media_csc_scaler_device_init() (Haoxiang Li)\n- media: gspca: Add bounds checking to firmware parser (Dan Carpenter)\n- soc/tegra: pmc: Ensure power-domains are in a known state (Jonathan Hunter)\n- jbd2: prevent softlockup in jbd2_log_do_checkpoint() (Baokun Li) [Orabug: 38423509] {CVE-2025-39782}\n- PCI: endpoint: Fix configfs group removal on driver teardown (Damien Le Moal)\n- PCI: endpoint: Fix configfs group list head handling (Damien Le Moal)\n- mtd: rawnand: fsmc: Add missing check after DMA map (Thomas Fourier)\n- pwm: imx-tpm: Reset counter if CMOD is 0 (Laurentiu Mihalcea)\n- wifi: brcmsmac: Remove const from tbl_ptr parameter in wlc_lcnphy_common_read_table() (Nathan Chancellor)\n- zynq_fpga: use sgtable-based scatterlist wrappers (Marek Szyprowski)\n- ata: libata-scsi: Fix ata_to_sense_error() status handling (Damien Le Moal)\n- ext4: fix reserved gdt blocks handling in fsmap (Ojaswin Mujoo)\n- ext4: fix fsmap end of range reporting with bigalloc (Ojaswin Mujoo)\n- ext4: check fast symlink for ea_inode correctly (Andreas Dilger)\n- vt: defkeymap: Map keycodes above 127 to K_HOLE (Myrrh Periwinkle)\n- vt: keyboard: Don't process Unicode characters in K_OFF mode (Myrrh Periwinkle)\n- usb: dwc3: meson-g12a: fix device leaks at unbind (Johan Hovold)\n- usb: gadget: udc: renesas_usb3: fix device leak at unbind (Johan Hovold)\n- usb: atm: cxacru: Merge cxacru_upload_firmware() into cxacru_heavy_init() (Nathan Chancellor)\n- m68k: Fix lost column on framebuffer debug console (Finn Thain)\n- cpufreq: armada-8k: Fix off by one in armada_8k_cpufreq_free_table() (Dan Carpenter)\n- serial: 8250: fix panic due to PSLVERR (Yunhui Cui) [Orabug: 38401729] {CVE-2025-39724}\n- media: uvcvideo: Do not mark valid metadata as invalid (Ricardo Ribalda)\n- media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() (Youngjun Lee) [Orabug: 38394816] {CVE-2025-38680}\n- mm/kmemleak: avoid soft lockup in __kmemleak_do_cleanup() (Waiman Long)\n- parisc: Makefile: fix a typo in palo.conf (Randy Dunlap)\n- btrfs: fix log tree replay failure due to file with 0 links and extents (Filipe Manana)\n- thunderbolt: Fix copy+paste error in match_service_id() (Eric Biggers)\n- comedi: fix race between polling and detaching (Ian Abbott)\n- misc: rtsx: usb: Ensure mmc child device is active when card is present (Ricky Wu)\n- drm/amdgpu: fix incorrect vm flags to map bo (Jack Xiao)\n- scsi: lpfc: Remove redundant assignment to avoid memory leak (Jiasheng Jiang)\n- rtc: ds1307: remove clear of oscillator stop flag (OSF) in probe (Meagan Lloyd)\n- pNFS: Fix uninited ptr deref in block/scsi layout (Sergey Bashirov) [Orabug: 38394867] {CVE-2025-38691}\n- pNFS: Handle RPC size limit for layoutcommits (Sergey Bashirov)\n- pNFS: Fix disk addr range check in block/scsi layout (Sergey Bashirov)\n- pNFS: Fix stripe mapping in block/scsi layout (Sergey Bashirov)\n- net: phy: smsc: add proper reset flags for LAN8710A (Csaba Buday)\n- ipmi: Fix strcpy source and destination the same (Corey Minyard)\n- kconfig: lxdialog: fix 'space' to (de)select options (Yann E. MORIN)\n- kconfig: gconf: fix potential memory leak in renderer_edited() (Masahiro Yamada)\n- kconfig: gconf: avoid hardcoding model2 in on_treeview2_cursor_changed() (Masahiro Yamada)\n- ipmi: Use dev_warn_ratelimited() for incorrect message warnings (Breno Leitao)\n- scsi: aacraid: Stop using PCI_IRQ_AFFINITY (John Garry)\n- scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans (Ranjan Kumar)\n- kconfig: nconf: Ensure null termination where strncpy is used (Shankari Anand)\n- kconfig: lxdialog: replace strcpy() with strncpy() in inputbox.c (Suchit Karunakaran)\n- i3c: don't fail if GETHDRCAP is unsupported (Wolfram Sang)\n- PCI: pnv_php: Work around switches with broken presence detection (Timothy Pearson)\n- i3c: add missing include to internal header (Wolfram Sang)\n- media: uvcvideo: Fix bandwidth issue for Alcor camera (Chenchangcheng)\n- media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar (Alex Guo) [Orabug: 38394880] {CVE-2025-38693}\n- media: dvb-frontends: dib7090p: fix null-ptr-deref in dib7090p_rw_on_apb() (Alex Guo) [Orabug: 38394887] {CVE-2025-38694}\n- media: usb: hdpvr: disable zero-length read messages (Wolfram Sang)\n- media: tc358743: Increase FIFO trigger level to 374 (Dave Stevenson)\n- media: tc358743: Return an appropriate colorspace from tc358743_set_fmt (Dave Stevenson)\n- media: tc358743: Check I2C succeeded during probe (Dave Stevenson)\n- pinctrl: stm32: Manage irq affinity settings (Cheick Traore)\n- scsi: mpt3sas: Correctly handle ATA device errors (Damien Le Moal)\n- scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure (Justin Tee) [Orabug: 38394894] {CVE-2025-38695}\n- RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask() (Yury Norov) [Orabug: 38423286] {CVE-2025-39742}\n- MIPS: Don't crash in stack_top() for tasks without ABI or vDSO (Thomas Weissschuh)\n- jfs: upper bound check of tree index in dbAllocAG (Arnaud Lecomte)\n- jfs: Regular file corruption check (Edward Adam Davis)\n- jfs: truncate good inode pages when hard link is 0 (Lizhi Xu)\n- scsi: bfa: Double-free fix (Jackysliu) [Orabug: 38394925] {CVE-2025-38699}\n- MIPS: vpe-mt: add missing prototypes for vpe_{alloc,start,stop,free} (Shiji Yang)\n- watchdog: dw_wdt: Fix default timeout (Sebastian Reichel)\n- fs/orangefs: use snprintf() instead of sprintf() (Amir Mohammad Jahangirzad)\n- scsi: libiscsi: Initialize iscsi_conn-dd_data only if memory is allocated (Showrya M N) [Orabug: 38394931] {CVE-2025-38700}\n- ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr (Theodore Ts'O) [Orabug: 38394937] {CVE-2025-38701}\n- cifs: Fix calling CIFSFindFirst() for root path without msearch (Pali Rohar)\n- vhost: fail early when __vhost_add_used() fails (Jason Wang)\n- net: dsa: b53: fix IP_MULTICAST_CTRL on BCM5325 (Alvaro Fernandez Rojas)\n- uapi: in6: restore visibility of most IPv6 socket options (Jakub Kicinski)\n- net: ncsi: Fix buffer overflow in fetching version id (Hari Kalavakunta)\n- net: dsa: b53: prevent SWITCH_CTRL access on BCM5325 (Alvaro Fernandez Rojas)\n- net: dsa: b53: fix b53_imp_vlan_setup for BCM5325 (Alvaro Fernandez Rojas)\n- net: vlan: Replace BUG() with WARN_ON_ONCE() in vlan_dev_* stubs (Gal Pressman)\n- wifi: iwlegacy: Check rate_idx range after addition (Stanislaw Gruszka)\n- netmem: fix skb_frag_address_safe with unreadable skbs (Mina Almasry)\n- wifi: rtlwifi: fix possible skb memory leak in _rtl_pci_rx_interrupt(). (Thomas Fourier)\n- wifi: iwlwifi: fw: Fix possible memory leak in iwl_fw_dbg_collect (Anjaneyulu)\n- wifi: iwlwifi: dvm: fix potential overflow in rs_fill_link_cmd() (Rand Deeb)\n- net: fec: allow disable coalescing (Jonas Rebmann)\n- (powerpc/512) Fix possible dma_unmap_single() on uninitialized pointer (Thomas Fourier)\n- s390/stp: Remove udelay from stp_sync_clock() (Sven Schnelle)\n- wifi: iwlwifi: mvm: fix scan request validation (Avraham Stern)\n- net: thunderx: Fix format-truncation warning in bgx_acpi_match_id() (Alok Tiwari)\n- net: ipv4: fix incorrect MTU in broadcast routes (Oscar Maes)\n- wifi: cfg80211: Fix interface type validation (Ilan Peer)\n- rcu: Protect -defer_qs_iw_pending from data race (Paul E. McKenney) [Orabug: 38423341] {CVE-2025-39749}\n- net: ag71xx: Add missing check after DMA map (Thomas Fourier)\n- et131x: Add missing check after DMA map (Thomas Fourier)\n- be2net: Use correct byte order and format string for TCP seq and ack_seq (Alok Tiwari)\n- s390/time: Use monotonic clock in get_cycles() (Sven Schnelle)\n- wifi: cfg80211: reject HTC bit for management frames (Johannes Berg)\n- ktest.pl: Prevent recursion of default variable options (Steven Rostedt)\n- ASoC: codecs: rt5640: Retry DEVICE_ID verification (Xinxin Wan)\n- ALSA: usb-audio: Avoid precedence issues in mixer_quirks macros (Cristian Ciocaltea)\n- ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control (Lucy Thrun)\n- platform/x86: thinkpad_acpi: Handle KCOV __init vs inline mismatches (Kees Cook)\n- pm: cpupower: Fix the snapshot-order of tsc,mperf, clock in mperf_stop() (Gautham R. Shenoy)\n- usb: core: usb_submit_urb: downgrade type check (Oliver Neukum)\n- ALSA: intel8x0: Fix incorrect codec index usage in mixer for ICH4 (Alok Tiwari)\n- ASoC: hdac_hdmi: Rate limit logging on connection and disconnection (Mark Brown)\n- mmc: rtsx_usb_sdmmc: Fix error-path in sd_set_power_mode() (Ulf Hansson)\n- ACPI: APEI: GHES: add TAINT_MACHINE_CHECK on GHES panic path (Breno Leitao)\n- ACPI: processor: fix acpi_object initialization (Sebastian Ott)\n- PM: sleep: console: Fix the black screen issue (Tuhaowen)\n- thermal: sysfs: Return ENODATA instead of EAGAIN for reads (Hsin-Te Yuan)\n- PM: runtime: Clear power.needs_force_resume in pm_runtime_reinit() (Rafael J. Wysocki)\n- selftests: tracing: Use mutex_unlock for testing glob filter (Masami Hiramatsu)\n- ARM: tegra: Use I/O memcpy to write to IRAM (Aaron Kling)\n- gpio: tps65912: check the return value of regmap_update_bits() (Bartosz Golaszewski)\n- ASoC: soc-dapm: set bias_level if snd_soc_dapm_set_bias_level() was successed (Kuninori Morimoto)\n- ARM: rockchip: fix kernel hang during smp initialization (Alexander Kochetkov)\n- cpufreq: Exit governor when failed to start old governor (Lifeng Zheng)\n- usb: xhci: Avoid showing errors during surprise removal (Mario Limonciello)\n- usb: xhci: Set avg_trb_len = 8 for EP0 during Address Device Command (Jay Chen)\n- usb: xhci: Avoid showing warnings for dying controller (Mario Limonciello)\n- selftests/futex: Define SYS_futex on 32-bit architectures with 64-bit time_t (Cynthia Huang)\n- usb: xhci: print xhci-xhc_state when queue_command failed (Su Hui)\n- securityfs: don't pin dentries twice, once is enough... (Al Viro)\n- hfs: fix not erasing deleted b-tree node issue (Viacheslav Dubeyko)\n- drbd: add missing kref_get in handle_write_conflicts (Sarah Newman) [Orabug: 38394995] {CVE-2025-38708}\n- udf: Verify partition map count (Jan Kara)\n- arm64: Handle KCOV __init vs inline mismatches (Kees Cook)\n- hfsplus: don't use BUG_ON() in hfsplus_create_attributes_file() (Tetsuo Handa)\n- hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() (Viacheslav Dubeyko)\n- hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read() (Viacheslav Dubeyko)\n- hfs: fix slab-out-of-bounds in hfs_bnode_read() (Viacheslav Dubeyko)\n- sctp: linearize cloned gso packets in sctp_rcv (Xin Long) [Orabug: 38395059] {CVE-2025-38718}\n- netfilter: ctnetlink: fix refcount leak on table dump (Florian Westphal) [Orabug: 38395068] {CVE-2025-38721}\n- udp: also consider secpath when evaluating ipsec use for checksumming (Sabrina Dubroca)\n- ACPI: processor: perflib: Move problematic pr-performance check (Rafael J. Wysocki)\n- ACPI: processor: perflib: Fix initial _PPC limit application (Jiayi Li)\n- Documentation: ACPI: Fix parent device references (Andy Shevchenko)\n- fs: Prevent file descriptor table allocations exceeding INT_MAX (Sasha Levin) [Orabug: 38423397] {CVE-2025-39756}\n- sunvdc: Balance device refcount in vdc_port_mpgroup_check (Ma Ke)\n- NFSD: detect mismatch of file handle and delegation stateid in OPEN op (Dai Ngo)\n- net: dpaa: fix device leak when querying time stamp info (Johan Hovold)\n- net: gianfar: fix device leak when querying time stamp info (Johan Hovold)\n- netlink: avoid infinite retry looping in netlink_unicast() (Fedor Pchelkin) [Orabug: 38401319] {CVE-2025-38727}\n- ALSA: usb-audio: Validate UAC3 cluster segment descriptors (Takashi Iwai) [Orabug: 38423407] {CVE-2025-39757}\n- ALSA: usb-audio: Validate UAC3 power domain descriptors, too (Takashi Iwai) [Orabug: 38395101] {CVE-2025-38729}\n- io_uring: don't use int for ABI (Pavel Begunkov)\n- usb: gadget : fix use-after-free in composite_dev_cleanup() (Taoxue) [Orabug: 38334898] {CVE-2025-38555}\n- MIPS: mm: tlb-r4k: Uniquify TLB entries on init (Jiaxun Yang)\n- USB: serial: option: add Foxconn T99W709 (Slark Xiao)\n- vsock: Do not allow binding to VMADDR_PORT_ANY (Budimir Markovic) [Orabug: 38351771,38453914] {CVE-2025-38618}\n- net/packet: fix a race in packet_set_ring() and packet_notifier() (Quang Le) [Orabug: 38351764] {CVE-2025-38617}\n- perf/core: Prevent VMA split of buffer mappings (Thomas Gleixner) [Orabug: 38334948] {CVE-2025-38563}\n- perf/core: Exit early on perf_mmap() fail (Thomas Gleixner) [Orabug: 38334959] {CVE-2025-38565}\n- perf/core: Don't leak AUX buffer refcount on allocation failure (Thomas Gleixner)\n- pptp: fix pptp_xmit() error path (Eric Dumazet)\n- smb: client: let recv_done() cleanup before notifying the callers. (Stefan Metzmacher)\n- benet: fix BUG when creating VFs (Michal Schmidt) [Orabug: 38334976] {CVE-2025-38569}\n- net: drop UFO packets in udp_rcv_segment() (Wang Liang) [Orabug: 38351786] {CVE-2025-38622}\n- ipv6: reject malicious packets in ipv6_gso_segment() (Eric Dumazet) [Orabug: 38334988] {CVE-2025-38572}\n- pptp: ensure minimal skb length in pptp_xmit() (Eric Dumazet) [Orabug: 38335004] {CVE-2025-38574}\n- netpoll: prevent hanging NAPI when netcons gets enabled (Jakub Kicinski)\n- NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() (Trond Myklebust) [Orabug: 38401745] {CVE-2025-39730}\n- pci/hotplug/pnv-php: Wrap warnings in macro (Frederic Barrat)\n- pci/hotplug/pnv-php: Improve error msg on power state change failure (Frederic Barrat)\n- usb: chipidea: udc: fix sleeping function called from invalid context (Peter Chen)\n- f2fs: fix to avoid out-of-boundary access in devs.path (Chao Yu)\n- f2fs: fix to avoid panic in f2fs_evict_inode (Chao Yu)\n- f2fs: fix to avoid UAF in f2fs_sync_inode_meta() (Chao Yu)\n- rtc: pcf8563: fix incorrect maximum clock rate handling (Brian Masney)\n- rtc: hym8563: fix incorrect maximum clock rate handling (Brian Masney)\n- rtc: ds1307: fix incorrect maximum clock rate handling (Brian Masney)\n- module: Restore the moduleparam prefix length check (Petr Pavlu)\n- bpf: Check flow_dissector ctx accesses are aligned (Paul Chaignon)\n- mtd: rawnand: atmel: set pmecc data setup time (Balamanikandan Gunasundar)\n- mtd: rawnand: atmel: Fix dma_mapping_error() address (Thomas Fourier)\n- jfs: fix metapage reference count leak in dbAllocCtl (Zheng Yu)\n- fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref (Chenyuan Yang)\n- crypto: qat - fix seq_file position update in adf_ring_next() (Giovanni Cabiddu)\n- dmaengine: nbpfaxi: Add missing check after DMA map (Thomas Fourier)\n- dmaengine: mv_xor: Fix missing check after DMA map and missing unmap (Thomas Fourier)\n- fs/orangefs: Allow 2 more characters in do_c_string() (Dan Carpenter)\n- soundwire: stream: restore params when prepare ports fail (Bard Liao)\n- crypto: img-hash - Fix dma_unmap_sg() nents value (Thomas Fourier)\n- hwrng: mtk - handle devm_pm_runtime_enable errors (Ovidiu Panait)\n- watchdog: ziirave_wdt: check record length in ziirave_firm_verify() (Dan Carpenter)\n- scsi: isci: Fix dma_unmap_sg() nents value (Thomas Fourier)\n- scsi: mvsas: Fix dma_unmap_sg() nents value (Thomas Fourier)\n- scsi: ibmvscsi_tgt: Fix dma_unmap_sg() nents value (Thomas Fourier)\n- clk: sunxi-ng: v3s: Fix de clock definition (Paul Kocialkowski)\n- perf tests bp_account: Fix leaked file descriptor (Leo Yan)\n- crypto: ccp - Fix crash when rebind ccp device for ccp.ko (Mengbiao Xiong)\n- pinctrl: sunxi: Fix memory leak on krealloc failure (Yuan Chen)\n- power: supply: max14577: Handle NULL pdata when CONFIG_OF is not set (Charles Han)\n- clk: davinci: Add NULL check in davinci_lpsc_clk_register() (Henry Martin)\n- mtd: fix possible integer overflow in erase_xfer() (Ivan Stepchenko)\n- crypto: marvell/cesa - Fix engine load inaccuracy (Herbert Xu)\n- PCI: rockchip-host: Fix 'Unexpected Completion' log message (Hans Zhang)\n- vrf: Drop existing dst reference in vrf_ip6_input_dst (Stanislav Fomichev)\n- selftests: rtnetlink.sh: remove esp4_offload after test (Xiumei Mu)\n- netfilter: xt_nfacct: don't assume acct name is null-terminated (Florian Westphal) [Orabug: 38351854] {CVE-2025-38639}\n- can: kvaser_usb: Assign netdev.dev_port based on device channel index (Jimmy Assarsson)\n- can: kvaser_pciefd: Store device channel index (Jimmy Assarsson)\n- wifi: brcmfmac: fix P2P discovery failure in P2P peer due to missing P2P IE (Gokul Sivakumar)\n- Reapply 'wifi: mac80211: Update skb's control block key in ieee80211_tx_dequeue()' (Remi Pommarel)\n- mwl8k: Add missing check after DMA map (Thomas Fourier)\n- wifi: rtl8xxxu: Fix RX skb size for aggregation disabled (Martin Kaistra)\n- net/sched: Restrict conditions for adding duplicating netems to qdisc tree (William Liu) [Orabug: 38331466] {CVE-2025-38553}\n- arch: powerpc: defconfig: Drop obsolete CONFIG_NET_CLS_TCINDEX (Johan Korsnes)\n- drm/amd/pm/powerplay/hwmgr/smu_helper: fix order of mask and value (Fedor Pchelkin)\n- m68k: Don't unregister boot console needlessly (Finn Thain)\n- tcp: fix tcp_ofo_queue() to avoid including too much DUP SACK range (Xin Guo)\n- iwlwifi: Add missing check for alloc_ordered_workqueue (Jiasheng Jiang) [Orabug: 38335110] {CVE-2025-38602}\n- wifi: iwlwifi: Fix memory leak in iwl_mvm_init() (Xiu Jianfeng)\n- wifi: rtl818x: Kill URBs before clearing tx status queue (Daniil Dulov) [Orabug: 38335120] {CVE-2025-38604}\n- caif: reduce stack size, again (Arnd Bergmann)\n- bpftool: Fix memory leak in dump_xx_nlmsg on realloc failure (Yuan Chen)\n- bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls (Jiayuan Chen) [Orabug: 38335131] {CVE-2025-38608}\n- staging: nvec: Fix incorrect null termination of battery manufacturer (Alok Tiwari)\n- samples: mei: Fix building on musl libc (Brahmajit Das)\n- cpufreq: Init policy-rwsem before it may be possibly used (Lifeng Zheng)\n- ARM: dts: imx6ul-kontron-bl-common: Fix RTS polarity for RS485 interface (Annette Kobou)\n- usb: early: xhci-dbc: Fix early_ioremap leak (Lucas De Marchi)\n- Revert 'vmci: Prevent the dispatching of uninitialized payloads' (Greg Kroah-Hartman)\n- pps: fix poll support (Denis Osterland-Heim)\n- vmci: Prevent the dispatching of uninitialized payloads (Lizhi Xu)\n- staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc() (Abdun Nihaal) [Orabug: 38335153] {CVE-2025-38612}\n- ARM: dts: vfxxx: Correctly use two tuples for timer address (Krzysztof Kozlowski)\n- hfsplus: remove mutex_lock check in hfsplus_free_extents (Yangtao Li)\n- ASoC: Intel: fix SND_SOC_SOF dependencies (Arnd Bergmann)\n- ethernet: intel: fix building with large NR_CPUS (Arnd Bergmann)\n- usb: phy: mxs: disconnect line when USB charger is attached (Xu Yang)\n- usb: chipidea: add USB PHY event (Xu Yang)\n- usb: chipidea: introduce CI_HDRC_CONTROLLER_VBUS_EVENT glue layer use (Peter Chen)\n- usb: chipidea: udc: protect usb interrupt enable (Li Jun)\n- usb: chipidea: udc: add new API ci_hdrc_gadget_connect (Peter Chen)\n- ALSA: hda: Add missing NVIDIA HDA codec IDs (Daniel Dadap)\n- comedi: comedi_test: Fix possible deletion of uninitialized timers (Ian Abbott)\n- nilfs2: reject invalid file types when reading inodes (Ryusuke Konishi)\n- i2c: qup: jump out of the loop in case of timeout (Yang Xiwen) [Orabug: 38351994] {CVE-2025-38671}\n- net/sched: sch_qfq: Avoid triggering might_sleep in atomic context in qfq_delete_class (Xiang Mei)\n- net: appletalk: Fix use-after-free in AARP proxy probe (Kito Xu)\n- net: appletalk: fix kerneldoc warnings (Andrew Lunn)\n- RDMA/core: Rate limit GID cache warning messages (Maor Gottlieb)\n- regulator: core: fix NULL dereference on unbind due to stale coupling data (Alessandro Carminati) [Orabug: 38351978] {CVE-2025-38668}\n- usb: hub: Fix flushing and scheduling of delayed work that tunes runtime pm (Mathias Nyman)\n- usb: hub: fix detection of high tier USB3 devices behind suspended hubs (Mathias Nyman)\n- net_sched: sch_sfq: reject invalid perturb period (Eric Dumazet) [Orabug: 38158477] {CVE-2025-38193}\n- power: supply: bq24190: Fix use after free bug in bq24190_remove due to race condition (Zheng Wang)\n- power: supply: bq24190_charger: using pm_runtime_resume_and_get instead of pm_runtime_get_sync (Minghao Chi)\n- power: supply: bq24190_charger: Fix runtime PM imbalance on error (Dinghao Liu)\n- xhci: Disable stream for xHC controller with XHCI_BROKEN_STREAMS (Hongyu Xie)\n- virtio-net: ensure the received length does not exceed allocated size (Bui Quang Minh) [Orabug: 38253834] {CVE-2025-38375}\n- ASoC: fsl_sai: Force a software reset when starting in consumer mode (Arun Raghavan)\n- usb: dwc3: qcom: Don't leave BCR asserted (Krishna Kurapati)\n- usb: musb: fix gadget state on disconnect (Drew Hamilton)\n- net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree (William Liu) [Orabug: 38254214] {CVE-2025-38468}\n- net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime (Dong Chenchen) [Orabug: 38254225] {CVE-2025-38470}\n- Bluetooth: L2CAP: Fix attempting to adjust outgoing MTU (Luiz Augusto von Dentz)\n- Bluetooth: SMP: Fix using HCI_ERROR_REMOTE_USER_TERM on timeout (Luiz Augusto von Dentz)\n- Bluetooth: SMP: If an unallowed command is received consider it a failure (Luiz Augusto von Dentz)\n- Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb() (Kuniyuki Iwashima) [Orabug: 38254241] {CVE-2025-38473}\n- usb: net: sierra: check for no status endpoint (Oliver Neukum) [Orabug: 38254249] {CVE-2025-38474}\n- net/sched: sch_qfq: Fix race condition on qfq_aggregate (Xiang Mei) [Orabug: 38254266] {CVE-2025-38477}\n- net: emaclite: Fix missing pointer increment in aligned_read() (Alok Tiwari)\n- comedi: Fix use of uninitialized data in insn_rw_emulate_bits() (Ian Abbott)\n- comedi: Fix some signed shift left operations (Ian Abbott)\n- comedi: das6402: Fix bit shift out of bounds (Ian Abbott)\n- comedi: das16m1: Fix bit shift out of bounds (Ian Abbott)\n- comedi: aio_iiro_16: Fix bit shift out of bounds (Ian Abbott)\n- comedi: pcl812: Fix bit shift out of bounds (Ian Abbott)\n- iio: adc: stm32-adc: Fix race in installing chained IRQ handler (Chen Ni)\n- iio: adc: max1363: Reorder mode_list[] entries (Fabio Estevam)\n- iio: adc: max1363: Fix MAX1363_4X_CHANS/MAX1363_8X_CHANS[] (Fabio Estevam)\n- soc: aspeed: lpc-snoop: Don't disable channels that aren't enabled (Andrew Jeffery)\n- soc: aspeed: lpc-snoop: Cleanup resources in stack-order (Andrew Jeffery)\n- mmc: sdhci_am654: Workaround for Errata i2312 (Judith Mendez)\n- mmc: sdhci-pci: Quirk for broken command queuing on Intel GLK-based Positivo models (Edson Juliano Drosdeck)\n- mmc: bcm2835: Fix dma_unmap_sg() nents value (Thomas Fourier)\n- memstick: core: Zero initialize id_reg in h_memstick_read_dev_id() (Nathan Chancellor)\n- isofs: Verify inode mode when loading from disk (Jan Kara)\n- dmaengine: nbpfaxi: Fix memory corruption in probe() (Dan Carpenter)\n- af_packet: fix soft lockup issue caused by tpacket_snd() (Yun Lu)\n- af_packet: fix the SO_SNDTIMEO constraint not effective on tpacked_snd() (Yun Lu)\n- phonet/pep: Move call to pn_skb_get_dst_sockaddr() earlier in pep_sock_accept() (Nathan Chancellor)\n- HID: core: do not bypass hid_hw_raw_request (Benjamin Tissoires) [Orabug: 38254340,38453904] {CVE-2025-38494}\n- HID: core: ensure __hid_request reserves the report ID as the first byte (Benjamin Tissoires)\n- HID: core: ensure the allocated report buffer can contain the reserved report ID (Benjamin Tissoires) [Orabug: 38254348,38453908] {CVE-2025-38495}\n- pch_uart: Fix dma_sync_sg_for_device() nents value (Thomas Fourier)\n- Input: xpad - set correct controller type for Acer NGR200 (Nilton Perim Neto)\n- i2c: stm32: fix the device used for the DMA map (Clement Le Goffic)\n- usb: gadget: configfs: Fix OOB read on empty string write (Xinyu Liu) [Orabug: 38254358] {CVE-2025-38497}\n- USB: serial: ftdi_sio: add support for NDI EMGUIDE GEMINI (Ryan Mann)\n- USB: serial: option: add Foxconn T99W640 (Slark Xiao)\n- USB: serial: option: add Telit Cinterion FE910C04 (ECM) composition (Fabio Porcedda)\n- LTS tag: v5.4.296 (Sherry Yang)\n- x86/mm: Disable hugetlb page table sharing on 32-bit (Jann Horn)\n- Input: atkbd - do not skip atkbd_deactivate() when skipping ATKBD_CMD_GETID (Hans de Goede)\n- HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras (Chia-Lin Kao) [Orabug: 38324280] {CVE-2025-38540}\n- HID: Add IGNORE quirk for SMARTLINKTECHNOLOGY (Zhang Heng)\n- vt: add missing notification when switching back to text mode (Nicolas Pitre)\n- net: usb: qmi_wwan: add SIMCom 8230C composition (Xiaowei Li)\n- atm: idt77252: Add missing dma_map_error() (Thomas Fourier)\n- bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT (Somnath Kotur) [Orabug: 38254090] {CVE-2025-38439}\n- bnxt_en: Fix DCB ETS validation (Shravya Kn)\n- can: m_can: m_can_handle_lost_msg(): downgrade msg lost in rx message to debug level (Sean Nyekjaer)\n- net: phy: microchip: limit 100M workaround to link-down events on LAN88xx (Oleksij Rempel)\n- net: appletalk: Fix device refcount leak in atrtr_create() (Kito Xu)\n- md/raid1: Fix stack memory use after return in raid1_reshape (Wang Jinchao) [Orabug: 38254109] {CVE-2025-38445}\n- wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev() (Daniil Dulov) [Orabug: 38324161] {CVE-2025-38513}\n- dma-buf: fix timeout handling in dma_resv_wait_timeout v2 (Christian Konig)\n- Input: xpad - support Acer NGR 200 Controller (Nilton Perim Neto)\n- Input: xpad - add VID for Turtle Beach controllers (Vicki Pfau)\n- Input: xpad - add support for Amazon Game Controller (Matt Reynolds)\n- NFSv4/flexfiles: Fix handling of NFS level errors in I/O (Trond Myklebust)\n- flexfiles/pNFS: update stats on NFS4ERR_DELAY for v4.1 DSes (Tigran Mkrtchyan)\n- RDMA/mlx5: Fix vport loopback for MPV device (Patrisious Haddad)\n- netlink: Fix rmem check in netlink_broadcast_deliver(). (Kuniyuki Iwashima)\n- netlink: make sure we allow at least one dump skb (Jakub Kicinski)\n- Revert 'ACPI: battery: negate current when discharging' (Rafael J. Wysocki)\n- usb: gadget: u_serial: Fix race condition in TTY wakeup (Kuen-Han Tsai) [Orabug: 38254118] {CVE-2025-38448}\n- drm/sched: Increment job count before swapping tail spsc queue (Matthew Brost) [Orabug: 38324180] {CVE-2025-38515}\n- pinctrl: qcom: msm: mark certain pins as invalid for interrupts (Bartosz Golaszewski) [Orabug: 38324186] {CVE-2025-38516}\n- x86/mce: Make sure CMCI banks are cleared during shutdown on Intel (Jp Kobryn)\n- x86/mce: Don't remove sysfs if thresholding sysfs init fails (Yazen Ghannam)\n- x86/mce/amd: Fix threshold limit reset (Yazen Ghannam)\n- rxrpc: Fix oops due to non-existence of prealloc backlog struct (David Howells)\n- net/sched: Abort __tc_modify_qdisc if parent class does not exist (Victor Nogueira) [Orabug: 38254147] {CVE-2025-38457}\n- atm: clip: Fix NULL pointer dereference in vcc_sendmsg() (Yue Haibing) [Orabug: 38254153] {CVE-2025-38458}\n- atm: clip: Fix infinite recursive call of clip_push(). (Kuniyuki Iwashima) [Orabug: 38254161] {CVE-2025-38459}\n- atm: clip: Fix memory leak of struct clip_vcc. (Kuniyuki Iwashima) [Orabug: 38324309] {CVE-2025-38546}\n- atm: clip: Fix potential null-ptr-deref in to_atmarpd(). (Kuniyuki Iwashima) [Orabug: 38254167] {CVE-2025-38460}\n- tipc: Fix use-after-free in tipc_conn_close(). (Kuniyuki Iwashima) [Orabug: 38254181] {CVE-2025-38464}\n- netlink: Fix wraparounds of sk-sk_rmem_alloc. (Kuniyuki Iwashima) [Orabug: 38254188] {CVE-2025-38465}\n- fix proc_sys_compare() handling of in-lookup dentries (Al Viro)\n- proc: Clear the pieces of proc_inode that proc_evict_inode cares about (Eric W. Biederman)\n- drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling (Kaustabh Chakraborty) [Orabug: 38254203] {CVE-2025-38467}\n- staging: rtl8723bs: Avoid memset() in aes_cipher() and aes_decipher() (Nathan Chancellor)\n- media: uvcvideo: Rollback non processed entities on error (Ricardo Ribalda)\n- media: uvcvideo: Send control events for partial succeeds (Ricardo Ribalda)\n- media: uvcvideo: Return the number of processed controls (Ricardo Ribalda)\n- ACPI: PAD: fix crash in exit_round_robin() (Seiji Nishikawa) [Orabug: 37206006] {CVE-2024-49935}\n- usb: typec: displayport: Fix potential deadlock (Andrei Kuchynski) [Orabug: 38401436] {CVE-2025-38404}\n- Logitech C-270 even more broken (Oliver Neukum)\n- rose: fix dangling neighbour pointers in rose_rt_device_down() (Kohei Enju)\n- net: rose: Fix fall-through warnings for Clang (Gustavo A R Silva)\n- drm/i915/gt: Fix timeline left held on VMA alloc error (Janusz Krzysztofik) [Orabug: 38253887] {CVE-2025-38389}\n- drm/i915/selftests: Change mock_request() to return error pointers (Dan Carpenter)\n- spi: spi-fsl-dspi: Clear completion counter before initiating transfer (James Clark)\n- spi: spi-fsl-dspi: Fix interrupt-less DMA mode taking an XSPI code path (Vladimir Oltean)\n- spi: spi-fsl-dspi: Rename fifo_{read,write} and {tx,cmd}_fifo_write (Vladimir Oltean)\n- dpaa2-eth: fix xdp_rxq_info leak (Wangfushuai)\n- ethernet: atl1: Add missing DMA mapping error checks and count errors (Thomas Fourier)\n- btrfs: use btrfs_record_snapshot_destroy() during rmdir (Filipe Manana)\n- btrfs: propagate last_unlink_trans earlier when doing a rmdir (Filipe Manana)\n- RDMA/mlx5: Fix CC counters query for MPV (Patrisious Haddad)\n- RDMA/core: Create and destroy counters in the ib_core (Leon Romanovsky)\n- scsi: ufs: core: Fix spelling of a sysfs attribute name (Bart Van Assche)\n- drm/v3d: Disable interrupts before resetting the GPU (Maira Canal)\n- mtk-sd: reset host-mrq on prepare_data() error (Sergey Senozhatsky)\n- mtk-sd: Prevent memory corruption from DMA map failure (Masami Hiramatsu)\n- mmc: mediatek: use data instead of mrq parameter from msdc_{un}prepare_data() (Yue Hu)\n- regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods (Manivannan Sadhasivam) [Orabug: 38253907] {CVE-2025-38395}\n- regulator: gpio: Add input_supply support in gpio_regulator_config (Jerome Neanne)\n- ACPICA: Refuse to evaluate a method if arguments are missing (Rafael J. Wysocki) [Orabug: 38253875] {CVE-2025-38386}\n- wifi: ath6kl: remove WARN on bad firmware input (Johannes Berg) [Orabug: 38253946] {CVE-2025-38406}\n- wifi: mac80211: drop invalid source address OCB frames (Johannes Berg)\n- powerpc: Fix struct termio related ioctl macros (Madhavan Srinivasan)\n- ata: pata_cs5536: fix build on 32-bit UML (Johannes Berg)\n- ALSA: sb: Force to disable DMAs once when DMA mode is changed (Takashi Iwai)\n- nui: Fix dma_mapping_error() check (Thomas Fourier)\n- enic: fix incorrect MTU comparison in enic_change_mtu() (Alok Tiwari)\n- amd-xgbe: align CL37 AN sequence as per databook (Raju Rangoju)\n- lib: test_objagg: Set error message in check_expect_hints_stats() (Dan Carpenter)\n- drm/exynos: fimd: Guard display clock control with runtime PM calls (Marek Szyprowski)\n- btrfs: fix missing error handling when searching for inode refs during log replay (Filipe Manana)\n- scsi: qla4xxx: Fix missing DMA mapping error in qla4xxx_alloc_pdu() (Thomas Fourier)\n- nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init() fails. (Kuniyuki Iwashima) [Orabug: 38253923] {CVE-2025-38400}\n- RDMA/mlx5: Initialize obj_event-obj_sub_list before xa_insert (Mark Zhang) [Orabug: 38253881] {CVE-2025-38387}\n- platform/mellanox: mlxbf-tmfifo: fix vring_desc.len assignment (David Thompson)\n- mtk-sd: Fix a pagefault in dma_unmap_sg() for not prepared data (Masami Hiramatsu)\n- usb: typec: altmodes/displayport: do not index invalid pin_assignments (Rd Babiera) [Orabug: 38253894] {CVE-2025-38391}\n- mmc: sdhci: Add a helper function for dump register in dynamic debug mode (Victor Shih)\n- vsock/vmci: Clear the vmci transport packet properly when initializing it (Harshavardhana S A) [Orabug: 38253937] {CVE-2025-38403}\n- btrfs: don't abort filesystem when attempting to snapshot deleted subvolume (Omar Sandoval) [Orabug: 36530119] {CVE-2024-26644}\n- arm64: Restrict pagetable teardown to avoid false warning (Dev Jain)\n- s390: Add '-std=gnu11' to decompressor and purgatory CFLAGS (Nathan Chancellor)\n- drm/bridge: cdns-dsi: Check return value when getting default PHY config (Aradhya Bhatia)\n- drm/bridge: cdns-dsi: Fix connecting to next bridge (Aradhya Bhatia)\n- drm/bridge: cdns-dsi: Fix the clock variable for mode_valid() (Aradhya Bhatia)\n- drm/tegra: Assign plane type before registration (Thierry Reding)\n- HID: wacom: fix kobject reference count leak (Qasim Ijaz)\n- HID: wacom: fix memory leak on sysfs attribute creation failure (Qasim Ijaz)\n- HID: wacom: fix memory leak on kobject creation failure (Qasim Ijaz)\n- dm-raid: fix variable in journal device check (Heinz Mauelshagen)\n- Bluetooth: L2CAP: Fix L2CAP MTU negotiation (Frederic Danis)\n- atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister(). (Kuniyuki Iwashima) [Orabug: 38175045] {CVE-2025-38245}\n- net: enetc: Correct endianness handling in _enetc_rd_reg64 (Simon Horman)\n- um: ubd: Add missing error check in start_io_thread() (Tiwei Bie)\n- vsock/uapi: fix linux/vm_sockets.h userspace compilation errors (Stefano Garzarella)\n- wifi: mac80211: fix beacon interval calculation overflow (Lachlan Hodges)\n- attach_recursive_mnt(): do not lock the covering tree when sliding something under it (Al Viro)\n- ALSA: usb-audio: Fix out-of-bounds read in snd_usb_get_audioformat_uac3() (Youngjun Lee) [Orabug: 38175065] {CVE-2025-38249}\n- i2c: robotfuzz-osif: disable zero-length read messages (Wolfram Sang)\n- i2c: tiny-usb: disable zero-length read messages (Wolfram Sang)\n- RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction (Shin'Ichiro Kawasaki) [Orabug: 38158592] {CVE-2025-38211}\n- RDMA/core: Use refcount_t instead of atomic_t on refcount of iwcm_id_private (Weihang Li)\n- media: vivid: Change the siize of the composing (Denis Arefev)\n- media: omap3isp: use sgtable-based scatterlist wrappers (Marek Szyprowski)\n- media: cxusb: no longer judge rbuf when the write fails (Edward Adam Davis) [Orabug: 38158692] {CVE-2025-38229}\n- media: cxusb: use dev_dbg() rather than hand-rolled debug (Sean Young)\n- jfs: validate AG parameters in dbMount() to prevent crashes (Vasiliy Kovalev)\n- fs/jfs: consolidate sanity checking in dbMount (Dave Kleikamp)\n- ASoC: meson: meson-card-utils: use of_property_present() for DT parsing (Martin Blumenstingl)\n- of: Add of_property_present() helper (Rob Herring)\n- of: property: define of_property_read_u{8,16,32,64}_array() unconditionally (Michael Walle)\n- kbuild: hdrcheck: fix cross build with clang (Arnd Bergmann)\n- kbuild: add --target to correctly cross-compile UAPI headers with Clang (Masahiro Yamada)\n- bpfilter: match bit size of bpfilter_umh to that of the kernel (Masahiro Yamada)\n- kbuild: use -MMD instead of -MD to exclude system headers from dependency (Masahiro Yamada)\n- VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify (Ma Wupeng) [Orabug: 38152869] {CVE-2025-38102}\n- VMCI: check context-notify_page after call to get_user_pages_fast() to avoid GPF (George Kennedy)\n- ovl: Check for NULL d_inode() in ovl_dentry_upper() (Kees Cook)\n- ceph: fix possible integer overflow in ceph_zero_objects() (Dmitry Kandybka)\n- ALSA: hda: Ignore unsol events for cards being shut down (Cezary Rojewski)\n- usb: typec: displayport: Receive DP Status Update NAK request exit dp altmode (Jos Wang)\n- usb: cdc-wdm: avoid setting WDM_READ for ZLP-s (Robert Hodaszi)\n- usb: Add checks for snprintf() calls in usb_alloc_dev() (Andy Shevchenko)\n- tty: serial: uartlite: register uart driver in init (Jakub Lewalski)\n- usb: potential integer overflow in usbg_make_tpg() (Chen Yufeng)\n- iio: pressure: zpa2326: Use aligned_s64 for the timestamp (Jonathan Cameron)\n- md/md-bitmap: fix dm-raid max_write_behind setting (Yu Kuai)\n- dmaengine: xilinx_dma: Set dma_device directions (Thomas Gessler)\n- mfd: max14577: Fix wakeup source leaks on device unbind (Krzysztof Kozlowski)\n- mailbox: Not protect module_put with spin_lock_irqsave (Peng Fan)\n- cifs: Fix cifs_query_path_info() for Windows NT servers (Pali Rohar)",
  "id": "ELSA-2025-28049",
  "ovalId": "oval:com.oracle.elsa:def:202528049",
  "source": "oracle_linux",
  "title": "ELSA-2025-28049: Unbreakable Enterprise kernel security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2025-28049.html"
}
View JSON API Download JSON