elsa-2026-500248
oracle_linux[6.12.0-206.104.3.3] - inet: frags: strip GSO state from fragments before reassembly (Xinyang Ge) [Orabug: 39974840] {CVE-2026-80590} [6.12.0-206.104.3.2] - KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs (Weiming Shi) [Orabug: 39931938] {CVE-2026-74517} - tcp: challenge ACK for non-exact RST in SYN-RECEIVED (Yuxiang Yang) [Orabug: 39931929] {CVE-2026-68118} - tcp: reorganize tcp_sock_write_txrx group for variables later (Chia-Yu Chang) [Orabug: 39931929] - tcp: fast path functions later (Ilpo Jarvinen) [Orabug: 39931929] - tcp: Pass flags to __tcp_send_ack (Ilpo Jarvinen) [Orabug: 39931929] - mm/damon/ops-common: putback folios on invalid migrate nid (liyouhong) [Orabug: 39931902] {CVE-2026-74644} - KVM: SVM: Serialize accesses to the owner and mirror list with separate lock (Paolo Bonzini) [Orabug: 39931893] {CVE-2026-74607} - binfmt_misc: restore write access when removing an entry (Christian Brauner) [Orabug: 39931874] {CVE-2026-74487} - binfmt_misc: use exe_file_deny_write_access() for the interpreter clone (Christian Brauner) [Orabug: 39931874] {CVE-2026-74486} - fs: don't block write during exec on pre-content watched files (Amir Goldstein) [Orabug: 39931874] - fsnotify: opt-in for permission events at file open time (Amir Goldstein) [Orabug: 39931874] - fsnotify, lsm: Decouple fsnotify from lsm (Song Liu) [Orabug: 39931874] - net: pktgen: fix proc entry use-after-free (Chengfeng Ye) [Orabug: 39931868] {CVE-2026-74479} - net: pktgen: fix code style (WARNING: Block comments) (Peter Seiderer) [Orabug: 39931868] - userfaultfd: prevent registration of special VMAs (Mike Rapoport (Microsoft)) [Orabug: 39931866] {CVE-2026-68166} - mm/khugepaged: guard is_zero_pfn() calls with pte_present() (Lance Yang) [Orabug: 39931866] - net/sched: serialize qdisc_rtab_list against concurrent get/put (Aldo Ariel Panzardo) [Orabug: 39931864] {CVE-2026-68138} - octeontx2-vf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao) [Orabug: 39924423] - Revert 'octeontx2-vf: clear stale mailbox IRQ state before request_irq()' (Saeed Mirzamohammadi) [Orabug: 39924423] - octeontx2-pf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao) [Orabug: 39924423] - Revert 'octeontx2-pf: clear stale mailbox IRQ state before request_irq()' (Saeed Mirzamohammadi) [Orabug: 39924423] - erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms (Gao Xiang) - m68k: Define NR_CPUS to 1 (Uwe Kleine-Konig) - drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini (Pierre-Eric Pelloux-Prayer) - drm/amdgpu: remove unused function parameter (Yunxiang Li) - drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE (Nathan Lucas) [6.12.0-206.100.3.1] - LTS version: v6.12.104 (Saeed Mirzamohammadi) - bpf: tcp: fix double sock release on batch realloc (Xiang Mei (Microsoft)) - thunderbolt: Fix bandwidth group reservation indexing (Xu Rao) {CVE-2026-80736} - thunderbolt: Bound the DROM dual link port number before indexing sw-ports (Bryam Vargas) {CVE-2026-74585} - sctp: clear new_transport when removing a peer (Qing Ming) {CVE-2026-74586} - sctp: fix use-after-free of cached ASCONF chunk (Yuxiang Yang) {CVE-2026-74587} - sctp: keep chunk-transport in step with the list it is queued on (Baul Lee) {CVE-2026-74588} - scsi: scsi_debug: Negate wrapped memcmp() result (Xu Rao) - bpf, sockmap: Fix sk_redir use-after-free in send verdict (Chengfeng Ye) {CVE-2026-74589} - fsverity: Fix silent truncation in bpf_get_fsverity_digest() (Eric Biggers) - fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions (Eric Biggers) {CVE-2026-74590} - ima: Instantiate file_truncate and path_truncate hooks (Mimi Zohar) {CVE-2026-74592} - sched/psi: Shut down rtpoll_timer in psi_cgroup_free() (Tejun Heo) {CVE-2026-74594} - fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() (Zhan Xusheng) {CVE-2026-74595} - ip6_tunnel: clear skb2-cb[] in ip6ip6_err() (Zhiling Zou) {CVE-2026-74597} - ipv6: fix Route Information option length validation (Yuejie Shi) {CVE-2026-74598} - ptp: ocp: Fix board ID over-read (Ahmad Byagowi) {CVE-2026-74603} - Revert 'thermal/drivers/hwmon: Cleanup coding style a bit' (Rafael J. Wysocki) {CVE-2026-74604} - eventfs: Fix use-after-free in eventfs_remove_rec() (Shuangpeng Bai) {CVE-2026-74606} - KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (Sean Christopherson) {CVE-2026-80726} - smb: client: Fix use-after-free in cifs_try_adding_channels() (Shuangpeng Bai) {CVE-2026-74608} - tipc: read le-link under the node lock in tipc_node_link_down() (Jun Yang) {CVE-2026-74609} - tls: don't leave a full plaintext sk_msg ring unpushed (chanyoung) {CVE-2026-74610} - vhost: reset the vring metadata cache on vring reconfiguration (Jun Yang) {CVE-2026-74580} - veth: fix skb length accounting after XDP frag adjustment (Sun Jian) {CVE-2026-74612} - vsock/virtio: avoid refilling the RX queue after teardown (Weiming Shi) {CVE-2026-74613} - vsock/virtio: read virtqueues under worker locks (Weiming Shi) {CVE-2026-74614} - vxlan: do not arm the ageing timer on a device that is down (Baul Lee) {CVE-2026-74615} - xdp: reject clones that overrun skb_shared_info tailroom (Zhiling Zou) {CVE-2026-74616} - Revert 'drm/amdgpu: fix aperture mapping leak' (Asad Kamal) {CVE-2026-80728} - binfmt_misc: don't warn when the mount is completed from another user namespace (Christian Brauner) {CVE-2026-74618} - ovl: don't warn when the mount is completed from another user namespace (Christian Brauner) {CVE-2026-74619} - net/sched: act_gact, act_police: range check the fallback control action (Hyunjung Ko) {CVE-2026-74620} - net/sched: act_ct: fix sk_buff leak when the header checks reject a packet (Hyunjung Ko) {CVE-2026-74621} - net: atlantic: free RX pages of consumed but not refilled buffers (Yangyu Chen) {CVE-2026-74622} - net: atlantic: free stranded TX buffers on ring deinit (Yangyu Chen) {CVE-2026-74623} - netfilter: nf_conntrack: defer invalid log until after unlock (Zihan Xi) {CVE-2026-74624} - netfilter: bridge: release template ct on non-IP path (Zhiling Zou) {CVE-2026-74625} - ipv6: prevent in6_dev_get() from resurrecting inet6_dev (Kyle Zeng) {CVE-2026-74630} - net: smc: fix splice entry lifetime imbalance in smc_rx_splice (Daming Li) {CVE-2026-74631} - mm/huge_memory: fix huge_zero_pfn race (Lorenzo Stoakes (ARM)) - ring-buffer: Prevent subbuf order change when resizing is disabled (Vincent Donnefort) {CVE-2026-74634} - fbdev: bitblit: bound-check glyph index in bit_cursor() (Rik van Riel) {CVE-2026-74635} - tracing: Fix race between update_event_fields and, event_define_fields (Michael Wu) {CVE-2026-74636} - ALSA: usx2y: bound the hwdep mmap fault offset (Baul Lee) {CVE-2026-74641} - ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (Takashi Iwai) {CVE-2026-74642} - ring-buffer: Fix crash passing ERR_PTR to kthread_stop() (Hui Su) {CVE-2026-80730} - misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (Eddie Lin) - misc: fastrpc: take fl-lock when moving mmaps on interrupted invoke (Junrui Luo) {CVE-2026-74646} - misc: fastrpc: Remove buffer from list prior to unmap operation (Ekansh Gupta) {CVE-2026-74647} - misc: fastrpc: fix channel ctx ref leak when session alloc fails (Anandu Krishnan E) - staging: rtl8723bs: validate monitor transmit frame lengths (Mariano Baragiola) {CVE-2026-74648} - staging: rtl8723bs: fix missing shared-key auth challenge length check (Panagiotis Petrakopoulos) {CVE-2026-74649} - staging: rtl8723bs: fix OOB read in WMM_param_handler() (Muhammad Bilal) {CVE-2026-74650} - staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (Muhammad Bilal) {CVE-2026-74651} - serial: 8250_dma: Clear stale RX state on shutdown (Cunhao Lu) {CVE-2026-74654} - serial: qcom-geni: fix TX DMA buffer flush (Jan Sebastian Gotte) {CVE-2026-74655} - nvmem: layouts: Add fixed-layout driver (Mathieu Dubois-Briand) - mei: pull kvfree out of spinlock (Alexander Usyskin) - ipv4: fix use-after-free in fib_nhc_update_mtu() (Chengfeng Ye) {CVE-2026-74656} - ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops (Zihan Xi) {CVE-2026-74657} - selftests/bpf: Adapt sockmap update error handling (Michal Luczaj) - selftests/bpf: Ensure UDP sockets are bound (Michal Luczaj) - pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP (Claudiu Beznea) - kunit/fortify: Add back 'volatile' for sizeof() constants (Kees Cook) - kunit/fortify: Replace 'volatile' with OPTIMIZER_HIDE_VAR() (Kees Cook) - futex: Prevent robust futex exit race some more (Keno Fischer) {CVE-2026-74658} - crypto: ccp - Abort doing SEV INIT if SNP INIT fails (Ashish Kalra) - crypto: ccp - Fix checks for SNP_VLEK_LOAD input buffer length (Michael Roth) - KVM: SVM: Add support to initialize SEV/SNP functionality in KVM (Ashish Kalra) - crypto: ccp - Add new SEV/SNP platform shutdown API (Ashish Kalra) - dt-bindings: crypto: qcom,ice: Fix missing power-domain and iface clk (Harshal Dev) - block: Reorder the request allocation code in blk_mq_submit_bio() (Bart Van Assche) - KVM: s390: pci: Fix aisb calculation (Matthew Rosato) - KVM: s390: pci: Fix resource leak on IRQ registration failure (Farhan Ali) - KVM: s390: pci: Fix missing error codes and memory unaccounting (Farhan Ali) - KVM: s390: pci: Fix memory accounting for pinned/unpinned pages (Farhan Ali) {CVE-2026-74514} - net: bridge: mrp: fix uninitialised bytes on the wire (Baul Lee) {CVE-2026-74659} - netfilter: ebt_nflog: pin the NFLOG backend (Chengfeng Ye) {CVE-2026-74660} - mac802154: fix netdev use-after-free in beacon worker (Zihan Xi) {CVE-2026-74661} - net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header (Qihang Tang) {CVE-2026-80731} - net: octeontx2-pf: Fix UB in shift operation (Sergey V. Frolov) - net/sched: reject overly deep qdisc hierarchies (Zijie Huang) {CVE-2026-74663} - net: openvswitch: reallocate update replies for mismatched IDs (Zhiling Zou) {CVE-2026-74664} - net: fix skb length accounting after generic XDP frag adjustment (Sun Jian) {CVE-2026-74665} - packet: synchronize pressure clearing with ring reconfiguration (Zihan Xi) {CVE-2026-74666} - net/packet: reset the MAC header on the packet-socket transmit path (Doruk Tan Ozturk) {CVE-2026-74667} - packet: use consistent hard_header_len in TX_RING send path (Qihang Tang) {CVE-2026-74668} - packet: use consistent hard_header_len in non-ring send paths (Qihang Tang) {CVE-2026-74582} - ipvs: clear IPv4 options after rebasing tunnel ICMP errors (Kyle Zeng) {CVE-2026-74669} - ipvs: properly update the overload flag on dest edit (Julian Anastasov) - ipvs: add totalconns for dest (Julian Anastasov) - ipvs: stop estimator after disabled calc phase (Zhiling Zou) {CVE-2026-74670} - ima: fix out-of-bounds read in xattr_verify() (Lincoln Wallace) {CVE-2026-74671} - Input: evdev - fix information leak in evdev_pass_values() (Dmitry Torokhov) {CVE-2026-74673} - vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (Joshua Rogers) {CVE-2026-74675} - vt: add permission check for KDSKBMETA ioctl (Joshua Rogers) {CVE-2026-74676} - net: usb: ipheth: fix carrier_work UAF on disconnect (Doruk Tan Ozturk) {CVE-2026-74677} - net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (Yi Cong) {CVE-2026-74678} - usb: gadget: f_ncm: Use unsigned int for ndp_index (Sonali Pradhan) {CVE-2026-74679} - usb: cdnsp: fix incorrect endian conversions for APB timeout register (Pawel Laszczak) - thunderbolt: icm: Preserve USB4 proxy data-valid bit (Xu Rao) - usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (Aleksandr Nogikh) {CVE-2026-74680} - ALSA: usb-audio: fix OOB write on Type II inbound URBs (Baul Lee) {CVE-2026-74682} - Input: evdev - sanitize event type index when fetching event masks (Dmitry Torokhov) {CVE-2026-74683} - swapfile: call cond_resched() before locking si-lock (Guillaume Morin) - mtd: spinand: repeat reading in regular mode if continuous reading fails (Mikhail Kshevetskiy) - mtd: spinand: try a regular dirmap if creating a dirmap for continuous reading fails (Mikhail Kshevetskiy) - mtd: spinand: fix direct mapping creation sizes (Mikhail Kshevetskiy) - spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (Larisa Grigore) - net: fec: do not release NULL pages when RX buffer allocation fails (Mehmet Fide) - hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt (Guenter Roeck) - hwmon: (ltc4282) Clamp negative current limits (Guenter Roeck) {CVE-2026-74685} - hwmon: (ltc4282) Avoid overflow in maximum power calculation (Guenter Roeck) - hwmon: (ads7828) Fix external VREF regulator handling (Qingshuang Fu) - hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (Wilken Gottwalt) - tls: don't abort the connection on signal-interrupted sends (Maximilian Immanuel Brandtner) - sctp: clear control chunk transport if it is being removed (Xin Long) {CVE-2026-74688} - net/atm: fix slab-out-of-bounds read in vcc_setsockopt() (Eric Dumazet) {CVE-2026-74689} - ata: pata_sl82c105: fix bridge revision use-after-free (Hongyan Xu) {CVE-2026-80732} - net: thunderbolt: Tear down DMA paths before stopping the rings (Fan XinRan) {CVE-2026-74691} - net/smc: fix TOCTOU race between smc_listen_out() and listener close (Sidraya Jayagond) {CVE-2026-74692} - net: remove WARN_ON_ONCE() from sk_mc_loop() (Eric Dumazet) {CVE-2026-80733} - net: prestera: validate firmware header length (Pengpeng Hou) {CVE-2026-74693} - net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (Henry Martin) {CVE-2026-74694} - tcp: fix TFO max_qlen accounting across reuseport migration (Jiayuan Chen) {CVE-2026-74696} - sctp: fix addip_serial increment on ASCONF_ACK allocation failure (Qing Luo) - bnxt_en: Fix PTP PPS setting bug (Keegan Freyhof) - bnxt_en: Refresh VNIC default ring on queue restart if needed (Shravya KN) - bnxt_en: Determine and store default RX ring in vnic structure (Shravya KN) - bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss() (Shravya KN) - selftests/ftrace: refactor eprobes test to fix argument checks (Martin Kaiser) - hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (Guenter Roeck) - hwmon: (nzxt-smart2) Check return value of init_device() in probe (Qingshuang Fu) - net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers (Jamal Hadi Salim) {CVE-2026-74700} - net/openvswitch: check Ethernet header length in key_extract() (Cen Zhang (Microsoft)) - net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter (Toke Hoiland-Jorgensen) {CVE-2026-74704} - udp: fix potential use-after-free in tunnel segmentation (Xuanqiang Luo) {CVE-2026-74705} - xsk: require at least 16 bytes of TX metadata (Stanislav Fomichev) {CVE-2026-74710} - tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss() (Nathan Gao) - vdpa/mlx5: Fix buffer length in create_direct_keys() (Christian Borntraeger) {CVE-2026-74712} - vhost/vdpa: reject overflowing PA map page counts on 32-bit (Yousef Alhouseen) - bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() (Jose Fernandez (Anthropic)) - bpf: tcp: Avoid socket skips and repeats during iteration (Jordan Rife) - bpf: tcp: Use bpf_tcp_iter_batch_item for bpf_tcp_iter_state batch items (Jordan Rife) - bpf: tcp: Get rid of st_bucket_done (Jordan Rife) - bpf: tcp: Make sure iter-batch always contains a full bucket snapshot (Jordan Rife) - bpf: tcp: Make mem flags configurable through bpf_iter_tcp_realloc_batch (Jordan Rife) - counter: microchip-tcb-capture: Fix DT channel validation (Babanpreet Singh) - net/mlx5: fw_tracer, return NULL on create error (Michael Guralnik) {CVE-2026-74717} - devlink: fix net namespace reference leak in reload (Or Har-Toov) {CVE-2026-74718} - net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete (Jiawen Liu) - net/sched: cls_route: fix fastmap use-after-free on filter (Jamal Hadi Salim) {CVE-2026-74583} - net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() (Mahanta Jambigi) {CVE-2026-74719} - bpf: Preserve pointer state for commuted arithmetic (Yiyang Chen) {CVE-2026-74720} - btrfs: fix memory leak in btrfs_do_encoded_write() (Dmitry Antipov) {CVE-2026-74722} - watchdog: bd96801_wdt: Fix timeout for enabled WDG (Matti Vaittinen) - ipvs: return the csum validation for forward hook (Julian Anastasov) - ipvs: avoid out-of-bounds write in ip_vs_nat_icmp (Julian Anastasov) {CVE-2026-74724} - netfilter: ipset: switch ext_size to atomic64_t (Jozsef Kadlecsik) - pds_core: cancel pending PCI reset work on AER recovery (Nikhil P. Rao) - pds_core: keep the health thread stopped during reset (Nikhil P. Rao) - net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock (Shay Drory) {CVE-2026-80739} - enic: fix tx_hang_reset use-after-free on device removal (Satish Kharat) {CVE-2026-74725} - bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor (Xiang Mei (Microsoft)) - Revert 'net: thunderbolt: Enable end-to-end flow control also in transmit' (Fan Ye) - net: hns3: fix speed configuration residue after driver reload (Jijie Shao) - drm/bridge: ps8640: propagate AUX transfer register errors (Pengpeng Hou) - ARM: dts: BCM5301X: fix PCIe controller 2 second interrupt (Rosen Penev) - ARM: npcm: Fix OF node refcount leaks in SMP setup (Yuho Choi) - arm64: dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer (Daniel Drake) - NFS: Pin the 'struct nfs_server' during a FREE_STATEID call (Anna Schumaker) {CVE-2026-74730} - s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() (Harald Freudenberger) {CVE-2026-80708} - drm/amd/display: Check for tg ops in dce110_set_avmute (Ray Wu) {CVE-2026-74732} - drm/amd/display: Add AV mute wait frames to dce110_set_avmute (Ray Wu) - selftests/bpf: Fail unbound UDP on sockmap update (Michal Luczaj) - mount: honour SB_NOUSER in the new mount API (Al Viro) - LTS version: v6.12.103 (Saeed Mirzamohammadi) - drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info (Thomas Zimmermann) - drm/fb-helper: Fix a locking bug in an error path (Bart Van Assche) - usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path (Andrei Kuchynski) - can: isotp: fix timer drain order, wakeup handling and tx_gen ordering (Oliver Hartkopp) - can: use skb hash instead of private variable in headroom (Oliver Hartkopp) - rxrpc: Fix irq-disabled in local_bh_enable() (David Howells) {CVE-2025-38525} - rxrpc: Manage RTT per-call rather than per-peer (David Howells) - rxrpc: Fix the calculation and use of RTO (David Howells) - rxrpc: Adjust the rxrpc_rtt_rx tracepoint (David Howells) - rxrpc: Generate rtt_min (David Howells) - drm/xe/pt: Reset current_op in xe_pt_update_ops_init() (Zongyao Bai) {CVE-2026-68264} - drm/xe: Stub out new pagefault layer (Matthew Brost) - drm/i915/hdcp: check streams[] bounds before overflow (Jani Nikula) {CVE-2026-68253} - drm/i915/hdcp: Skip inactive MST connectors when building stream list (Suraj Kandpal) - drm/i915/hdcp: require monotonically increasing seq_num_v (Jani Nikula) - drm/i915/hdcp: Move to using intel_display in intel_hdcp (Suraj Kandpal) - drm/xe: Hold a dma-buf reference for imported BOs (Nitin Gote) {CVE-2026-68266} - drm/xe: Rename ___xe_bo_create_locked() (Thomas Hellstrom) - drm/i915/vrr: require valid min/max vfreq for VRR (Jani Nikula) {CVE-2026-68254} - drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() (Ville Syrjala) - drm/xe: Wait on external BO kernel fences in exec IOCTL (Matthew Brost) {CVE-2026-74440} - drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse] (Thomas Hellstrom) - drm/tegra: fbdev: Remove offset into framebuffer memory (Thomas Zimmermann) - drm/fb-helper: Allocate and release fb_info in single place (Thomas Zimmermann) - drm/amdgpu/gfx: fix cleaner shader IB buffer overflow (Asad Kamal) {CVE-2026-68276} - drm/amdgpu: give each kernel job a unique id (Pierre-Eric Pelloux-Prayer) - drm/sched: Store the drm client_id in drm_sched_fence (Pierre-Eric Pelloux-Prayer) - drm/amdgpu: Fix context pstate override handling (Tvrtko Ursulin) {CVE-2026-68273} - drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions (Timur Kristof) - mm/kmemleak: fix checksum computation for per-cpu objects (Breno Leitao) - kmemleak: iommu/iova: fix transient kmemleak false positive (Catalin Marinas) - mptcp: pm: userspace: fix use-after-free in get_local_id (Geliang Tang) {CVE-2026-68169} - mptcp: pm: use addr entry for get_local_id (Geliang Tang) - mptcp: add mptcp_userspace_pm_lookup_addr helper (Geliang Tang) - mptcp: pm: avoid code duplication to lookup endp (Geliang Tang) - ALSA: hda: codecs: hdmi: disable keep-alive before audio format change (Kai Vehmanen) - wifi: brcmfmac: set F2 blocksize to 256 for BCM43752 (LiangCheng Wang) - wifi: brcmfmac: fix 43752 SDIO FWVID incorrectly labelled as Cypress (CYW) (Gokul Sivakumar) - wifi: ath6kl: fix use-after-free in aggr_reset_state() (Daniel Hodges) {CVE-2026-68198} - wifi: brcmfmac: drain bus_reset work on device removal (Fan Wu) {CVE-2026-64586} - media: uapi: rkisp: Correct name version enum (Niklas Soderlund) - media: chips-media: wave5: Support CBP profile (Jackson Lee) - media: imx219: Fix maximum frame length in lines (Sakari Ailus) - media: i2c: imx219: Rename VTS to FRM_LENGTH (Jai Luthra) - usb: typec: ucsi: Fix race condition and ordering in port unregistration (Andrei Kuchynski) {CVE-2026-74441} - usb: typec: ucsi: split connector lock classes (Sergey Senozhatsky) - usb: gadget: f_tcm: synchronize delayed set_alt with teardown (Cen Zhang) {CVE-2026-68367} - gpio: pch: use raw_spinlock_t for the register lock (Junjie Cao) {CVE-2026-74468} - lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled() (Harry Yoo (Oracle)) - mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (Kiryl Shutsemau (Meta)) - fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes (Kiryl Shutsemau (Meta)) - mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() (Kiryl Shutsemau (Meta)) - drm/xe/rtp: Ensure locking/ref counting for OA whitelists (Ashutosh Dixit) - drm/xe/oa: (De-)whitelist OA registers on OA stream open/release (Ashutosh Dixit) - drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt (Ashutosh Dixit) - drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs (Ashutosh Dixit) - drm/xe/rtp: Save OA nonpriv registers to register save/restore lists (Ashutosh Dixit) - drm/xe/rtp: Generalize whitelist_apply_to_hwe (Ashutosh Dixit) - drm/xe/rtp: Keep track of non-OA nonpriv slots (Ashutosh Dixit) - drm/xe/rtp: Maintain OA whitelists separately (Ashutosh Dixit) - drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (Ashutosh Dixit) {CVE-2026-68267} - drm/xe: Apply whitelist to engine save-restore (Lucas De Marchi) - drm/xe: Introduce xe_gt_dbg_printer() (Michal Wajdeczko) - drm/xe/rtp: Refactor OAG MMIO trigger register whitelisting (Ashutosh Dixit) - Bluetooth: ISO: fix CONNECTED - CLOSED transition on shutdown/release (Pauli Virtanen) - of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails (Wandun Chen) {CVE-2026-74352} - ata: ahci: Make ahci_ignore_port() handle empty mask_port_map (Niklas Cassel) - ata: libahci_platform: Do not set mask_port_map when not needed (Damien Le Moal) - HID: logitech-dj: Fix maxfield check in DJ short report validation (HyeongJun An) {CVE-2026-64427} - spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX (Jun Guo) - drm/vmwgfx: validate external BO copy bounds for both stride paths (Zack Rusin) {CVE-2026-80700} - drm/vmwgfx: use check_add_overflow for shader size+offset bound (Zack Rusin) - drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure (Zack Rusin) {CVE-2026-74442} - drm/vmwgfx: bound DMA command body size against suffix pointer (Zack Rusin) {CVE-2026-74443} - drm/vmwgfx: validate DRAW_PRIMITIVES header size before division (Zack Rusin) {CVE-2026-74444} - drm/vmwgfx: drop dma_buf reference on foreign-fd prime import (Zack Rusin) - drm/vmwgfx: reject DX_BIND_QUERY without a DX context (Zack Rusin) {CVE-2026-74445} - drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size (Zack Rusin) {CVE-2026-80702} - drm/amdkfd: hold event_mutex while checkpointing CRIU events (William Palacek) {CVE-2026-74446} - drm/amdkfd: Handle invalid event type in CRIU event restore (David Francis) - drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment (William Palacek) {CVE-2026-74447} - drm/amdkfd: fix QID bit leak in pqm_create_queue() (Vladimir Marioukhine) {CVE-2026-74448} - drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (Gang Ba) {CVE-2026-80703} - drm/amd/display: use proper context for logging (Jiri Slaby (SUSE)) - drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames (Ray Wu) - drm/amdgpu: cap GTT size to physical RAM on APUs (Harkirat Gill) - drm/amdgpu: restore UMD profile pstate after runtime resume (Candice Li) - drm/mediatek: ovl_adaptor: balance component registrations (Myeonghun Pak) - drm/panthor: validate firmware interface structure sizes (Osama Abdelkader) {CVE-2026-74451} - drm/panthor: reject firmware sections with oversized data (Osama Abdelkader) {CVE-2026-74452} - drm/vc4: Zero the tile state data array before each BIN job (Maira Canal) {CVE-2026-74453} - drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size (Jose Maria Casanova Crespo) {CVE-2026-74454} - drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs (Alexander Kaplan) - can: ctucanfd: mark error-active controller status valid (Avi Weiss) - can: ctucanfd: handle bus error interrupts (Avi Weiss) - can: ctucanfd: unmap BAR0 using base address (Avi Weiss) - can: ctucanfd: use self-test mode for PRESUME_ACK (Avi Weiss) - can: ctucanfd: add missing MODULE_DEVICE_TABLE() (Pengpeng Hou) - can: peak_usb: validate uCAN receive record lengths (Pengpeng Hou) {CVE-2026-74455} - can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error (Maoyi Xie) {CVE-2026-74456} - can: peak_usb: add bounds check for USB channel index (James Gao) {CVE-2026-74457} - can: softing: fw_parse(): validate firmware record spans (Pengpeng Hou) {CVE-2026-80706} - can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents (Pengpeng Hou) {CVE-2026-74458} - can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() (Abdun Nihaal) - can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (Tetsuo Handa) - can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer (Oleksij Rempel) {CVE-2026-80707} - can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure (Marc Kleine-Budde) - can: ems_usb: validate CPC message lengths (Pengpeng Hou) {CVE-2026-74460} - can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured (Lucas Martins Alves) - i2c: imx: Cancel hrtimer before clearing slave pointer (Liem) {CVE-2026-74461} - i2c: imx: Fix slave registration race and error handling (Liem) {CVE-2026-80678} - i2c: iproc: reset bus after timeout if START_BUSY is stuck (Jonas Gorski) - i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock (H. Nikolaus Schaller) {CVE-2026-74463} - ice: fix memory leak in ice_lbtest_prepare_rings() (Dawei Feng) - ice: wait for reset completion in ice_resume() (Aaron Ma) - net: openvswitch: fix skb leak on flow key update failure during ct (Ilya Maximets) {CVE-2026-74464} - net: openvswitch: fix skb leak on flow key update failure during recirculation (Ilya Maximets) - net: openvswitch: fix potential UAF on meter attach failure (Ilya Maximets) {CVE-2026-74465} - phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB (Nava kishore Manne) - phy: zynqmp: use read-modify-write for SERDES scrambler bypass (Nava kishore Manne) - phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask (Nava kishore Manne) - s390/zcrypt: Validate length for CCA ECC private key requests (Holger Dengler) {CVE-2026-68451} - s390/zcrypt: Validate length for CCA AES cipher key requests (Holger Dengler) {CVE-2026-68452} - s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs (Harald Freudenberger) {CVE-2026-80709} - s390/dasd: Fix undersized format-check buffer (Stefan Haberland) {CVE-2026-80710} - s390/dasd: Fix potential NULL pointer dereference (Jan Hoppner) {CVE-2026-80679} - s390/qeth: Check CAP_NET_ADMIN for private ioctls (Aswin Karuvally) {CVE-2026-74467} - s390/pci: Fix s390_pci_mmio_write syscall error return without MIO (Niklas Schnelle) - power: supply: max17040: handle missing status supplier (Jianing Li) {CVE-2026-80711} - power: supply: bq25890: fix the -10 C NTC lookup entry (Xu Rao) - cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized (Zhongqiu Han) - cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() (Abdun Nihaal) - gpio: pca953x: fix cache_only and IRQ state on restore_context() failure (bui duc phuc) - i2c: amd-mp2: Unregister callback on adapter add failure (Myeonghun Pak) {CVE-2026-80680} - hwmon: (pmbus/core) notify on the hwmon device, not the i2c client (Vincent Jardin) - hwmon: (npcm750-pwm-fan): stop fan timer on device detach (Hongyan Xu) - sctp: prevent peer transport count overflow (Asim Viladi Oglu Manizada) {CVE-2026-74469} - sctp: reject stale cookies with mismatched verification tags (Yuxiang Yang) - scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write (Ibrahim Hashimov) {CVE-2026-74470} - selftests/clone3: fix wild pointer access of getline due to missing init (Chris Gellermann) - selftests/mm: fix potential wild pointer access of getline due to missing init (Chris Gellermann) - spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure (Vijaya Krishna Nivarthi) - tracing/filters: Fix false positive match in regex_match_full() (Masami Hiramatsu (Google)) - tracing: Check return value of __register_event() in trace_module_add_events() (Masami Hiramatsu (Google)) - ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() (Ming Lei) {CVE-2026-74472} - vxlan: use pskb_network_may_pull() in route_shortcircuit() (Eric Dumazet) {CVE-2026-74473} - vxlan: use neigh_ha_snapshot() in route_shortcircuit() (Eric Dumazet) {CVE-2026-74475} - vxlan: unclone skb head before modifying eth header in route_shortcircuit() (Eric Dumazet) - vxlan: re-fetch eth header after route_shortcircuit() (Eric Dumazet) {CVE-2026-80681} - veth: convert frag_list skbs before running XDP (Matt Fleming) {CVE-2026-74476} - um: vector: fix use-after-free in vector_mmsg_rx() (Michael Bommarito) {CVE-2026-74478} - powerpc/ps3: Fix map failure path in dma_ioc0_map_pages() (Thorsten Blum) - net: ipv6: clear suppressed fib6 rule result (Zhiling Zou) {CVE-2026-74581} - net: bridge: stop fast-leave after deleting a port group (Zhiling Zou) {CVE-2026-74480} - mm: memcg: initialize *locked in memcg1_oom_prepare() stub (Breno Leitao) - mm/page_reporting: use system_freezable_wq to fix UAF during suspend (Link Lin) {CVE-2026-74481} - binfmt_misc: don't let an 'F' entry pin its own instance (Christian Brauner) {CVE-2026-74484} - binfmt_misc: reject a flag character as the field delimiter (Christian Brauner) {CVE-2026-74485} - wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (Zhao Li) {CVE-2026-74488} - tipc: avoid use-after-free in poll trace queue dumps (Zihan Xi) {CVE-2026-74490} - netfilter: ipset: do not update comments from kernel-side hash adds (David Lee) {CVE-2026-74492} - net/smc: fix socket use-after-free during link group termination (Xuanqiang Luo) {CVE-2026-74493} - ipvs: do not propagate one-packet flag to synced conns (Zhiling Zou) {CVE-2026-80714} - igbvf: Fix leak in TX DMA error cleanup (Matt Vollrath) {CVE-2026-74495} - e1000: fix memory leak in e1000_probe() (Dawei Feng) - dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ (Md Sadre Alam) - ALSA: usb-audio: Clamp frame size in implicit-feedback mode (Sonali Pradhan) {CVE-2026-74497} - ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set (Sonali Pradhan) {CVE-2026-74498} - ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() (Baul Lee) {CVE-2026-74499} - ALSA: usb-audio: fix stack info leak in RME Digiface status (Baul Lee) {CVE-2026-74500} - ALSA: usb-audio: fix use-after-free in ump_to_endpoint() (Baul Lee) {CVE-2026-74501} - ata: libata-sata: fix ata_scsi_lpm_supported() iteration (Niklas Cassel) - ata: libata-eh: Increase STANDBY IMMEDIATE timeout (Matt Vollrath) - ASoC: tas2562: fix broken entries in the volume lookup table (Haidar Lee) - ASoC: tas2562: fix DVC coefficient write order (Haidar Lee) - ALSA: ump: fix double free of out_cvts on rawmidi error (Baul Lee) {CVE-2026-74502} - ALSA: seq: Fix division by zero in initialize_timer() (Norbert Szetei) {CVE-2026-74504} - ALSA: pcm: wake linked drain waiters on unlink (Norbert Szetei) {CVE-2026-80716} - ALSA: lx6464es: fix period byte count for 16-bit streams (Xu Rao) - ALSA: 6fire: Fix UAF at error handling during probe (Takashi Iwai) {CVE-2026-74505} - bpf: lwt: Fix dst reference leak on reroute failure (Xuanqiang Luo) - Bluetooth: HIDP: validate numbered report payloads (Sangho Lee) {CVE-2026-74507} - Bluetooth: HIDP: reject frames without a transaction header (Sangho Lee) {CVE-2026-74508} - Bluetooth: hci_sync: Fix advertising data UAFs (Chengfeng Ye) {CVE-2026-74509} - Bluetooth: mgmt: fix UAF in pair command cancellation (Zihan Xi) {CVE-2026-74510} - Bluetooth: mgmt: fix pending command UAF in EIR updates (Zihan Xi) {CVE-2026-74511} - Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() (Greg Kroah-Hartman) - Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req() (Greg Kroah-Hartman) - audit: fix potential use-after-free in audit_del_rule() (Luxiao Xu) {CVE-2026-74512} - audit: fix potential integer overflow in audit_log_n_string() (Zhan Xusheng) - sctp: validate Adaptation Indication parameter length (Charles Vosburgh) {CVE-2026-80717} - KVM: s390: pci: Validate AIBV and AISB before pinning guest pages (Farhan Ali) - KVM: s390: pci: Fix NULL dereference on AIBV allocation failure (Farhan Ali) {CVE-2026-80684} - KVM: s390: pci: Reject adapter interrupt forwarding if already enabled (Farhan Ali) {CVE-2026-74515} - KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (Sean Christopherson) {CVE-2026-74516} - tracing/probes: Reject in meta argument expansion (Raushan Patel) - mm/vmstat: fold stranded per-cpu node stats when a node comes online (Gregory Price) - mm/hugetlb: fix list corruption in allocate_file_region_entries() (Xiangfeng Cai) {CVE-2026-74518} - mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() (Zi Yan) {CVE-2026-80718} - fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes (Kiryl Shutsemau (Meta)) - mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE (Kefeng Wang) {CVE-2026-80686} - fortify: Disable -Wstringop-overread in tests (Nathan Chancellor) - pinctrl: bm1880: add missing select GENERIC_PINCONF (Benjamin Boortz) - erofs: cap LZMA stream pool size (Michael Bommarito) - pinctrl: devicetree: don't free uninitialized dev_name on error path (Karl Mehltretter) {CVE-2026-74519} - pinctrl: microchip-sgpio: add missing select REGMAP_MMIO (Benjamin Boortz) - rhashtable: clear stale iter-p on table restart (Cen Zhang (Microsoft)) - ksmbd: fix use-after-free in __close_file_table_ids() (Namjae Jeon) {CVE-2026-74522} - ksmbd: return success for deferred final close (Namjae Jeon) - qede: sync udp_tunnel ports outside qede_lock in the recovery path (Denis V. Lunev) {CVE-2026-74523} - net: libwx: fix FDIR ATR queue mismatch for software VLAN packets (Jiawen Wu) - net: dsa: mt7530: error out on failed reads in MT7531 PHY polling (Daniel Golle) - net: dsa: mt7530: check bus-read() errors in the MDIO regmap backend (Daniel Golle) - riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove (Karl Mehltretter) {CVE-2026-74524} - accel/qaic: use sizeof(*trans_hdr) for transaction length check (Muhammad Bilal) - tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions (Masami Hiramatsu (Google)) - tracing/mmiotrace: Remove reference to unused per CPU data pointer (Steven Rostedt) - tracing: Remove TRACE_EVENT_FL_FILTERED logic (Zheng Yejian) - tracing/mmiotrace: Reset dropped_count in mmio_reset_data() (Masami Hiramatsu (Google)) - can: isotp: check register_netdevice_notifier() error in module init (Minhong He) - net: sxgbe: check descriptor ring allocation failures (Chenguang Zhao) - net: sxgbe: free TX rings on RX allocation failure (Chenguang Zhao) {CVE-2026-74525} - scsi: target: Clear cmd_cnt when initial counter enrollment fails (Leon Romanovsky) - scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req (Benjamin Block) - scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE (TanZheng) {CVE-2026-80691} - net: phylink: put link_gpio if phylink_create fails (Christian Marangi) - Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync (Pauli Virtanen) - Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (Pauli Virtanen) {CVE-2026-74531} - Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (Pauli Virtanen) - Bluetooth: btintel: Validate length before parsing diagnostics TLV (Zijun Hu) {CVE-2026-74532} - Bluetooth: ISO: avoid deadlocks in iso_sock_timeout (Pauli Virtanen) {CVE-2026-74535} - Bluetooth: ISO: fix leaking sk after socket release (Pauli Virtanen) {CVE-2026-74536} - Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis() (Pauli Virtanen) - Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos (Pauli Virtanen) - Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp (Jiale Yao) {CVE-2026-74540} - Bluetooth: ISO: clear iso_data always when detaching conn from hcon (Pauli Virtanen) {CVE-2026-74541} - idpf: Fix mailbox IRQ name leak on request failure (Yuho Choi) - idpf: adjust TxQ ring count minimum (Joshua Hay) - hwmon: (pmbus) Fix return value from pmbus_update_byte_data() (Guenter Roeck) - net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller (Chenguang Zhao) {CVE-2026-80694} - net: ethernet: mtk_eth_soc: add consts for irq index (Frank Wunderlich) - net: ethernet: mtk_eth_soc: support named IRQs (Frank Wunderlich) - wifi: mac80211: validate individual TWT params before driver setup (Zhao Li) {CVE-2026-80722} - net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister() (Eric Dumazet) {CVE-2026-74543} - powerpc/boot: Fix treeboot-akebono CPU node lookup check (Thorsten Blum) - powerpc/boot: Fix treeboot-currituck CPU node lookup check (Thorsten Blum) - powerpc/boot: Fix simpleboot CPU node lookup check (Thorsten Blum) - rtase: fix double free of multi-frag skb on DMA map failure (Yun Lu) {CVE-2026-74545} - hwmon: (adt7470) Fix PWM auto temp state array and bounds check (Luiz Angelo Daros de Luca) - hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read (Luiz Angelo Daros de Luca) {CVE-2026-74546} - hwmon: (adt7470) Use cached PWM frequency value (Luiz Angelo Daros de Luca) - hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks (Luiz Angelo Daros de Luca) - hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() (Luiz Angelo Daros de Luca) - hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread (Luiz Angelo Daros de Luca) {CVE-2026-74547} - hwmon: (adt7470) Fix cache updated before hardware write on I2C error (Luiz Angelo Daros de Luca) - hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors (Luiz Angelo Daros de Luca) - forcedeth: fix UAF of txrx_stats in nv_remove (Chenguang Zhao) {CVE-2026-74548} - net: bridge: mrp: fix Option TLV length in MRP_Test frames (David Corvaglia) - hwmon: (nct6775-core) Prevent access to unsupported weight registers (Guenter Roeck) {CVE-2026-74549} - net: do not send ICMP/NDISC Redirects when peer allocation fails (Eric Dumazet) {CVE-2026-74550} - hwmon: (nzxt-smart2) DMA-align output buffer (Guenter Roeck) {CVE-2026-74551} - hwmon: (lm90) Only report alarms if driver is ready (Guenter Roeck) {CVE-2026-74552} - hwmon: (sht3x) Fix unaligned accesses (Guenter Roeck) {CVE-2026-80695} - hwmon: (ltc4282) Fix reading the minimum alarm voltage (Guenter Roeck) {CVE-2026-80696} - hwmon: (ina2xx) Fix various overflow issues (Guenter Roeck) - hwmon: (ina2xx) Shift INA234 shunt and current registers (Jonas Rebmann) - hwmon: (ina2xx) Add support for INA234 (Ian Ray) - hwmon: (ina2xx) Make it easier to add more devices (Ian Ray) - hwmon: (ina226) Add support for SY24655 (Wenliang Yan) - hwmon: (ina2xx) Add support for INA260 (Guenter Roeck) - hwmon: (ina2xx) Add support for has_alerts configuration flag (Guenter Roeck) - hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 (Guenter Roeck) {CVE-2026-74553} - spi: spi-cadence: Move TX FIFO full busy-wait into FIFO (Srikanth Boyapally) - spi: spi-cadence: supports transmission with bits_per_word of 16 and 32 (Jun Guo) - smb: client: fix buffer leaks in SMB1 read and write (Dawei Feng) - scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race (Xingui Yang) {CVE-2026-74555} - scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (HyeongJun An) {CVE-2026-74556} - scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer (HyeongJun An) {CVE-2026-74557} - pinctrl-amd: Don't clear S4 wake bits at probe (Mario Limonciello) - netfilter: nft_payload: fix mask build for partial field offload (Xiang Mei (Microsoft)) - ipvs: do not mangle ICMP replies for non-first fragments (Julian Anastasov) - ipvs: fix places with wrong packet offsets (Julian Anastasov) - ipvs: fix the checksum validations (Julian Anastasov) - netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH (Pablo Neira Ayuso) {CVE-2026-74564} - netfilter: nf_tables: make nft_object rhltable per table (Pablo Neira Ayuso) {CVE-2026-74565} - assoc_array: trim the final shortcut word using the current chunk end (Michael Bommarito) - keys: make keyring key-chunk byte order agree with keyring_diff_objects() (Michael Bommarito) {CVE-2026-74566} - keys: fix out-of-bounds read in keyring_get_key_chunk() (Michael Bommarito) {CVE-2026-74567} - KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type (Fabrice Derepas) - Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation (Sebastian Andrzej Siewior) - drm/mediatek: Check CRTC state before freeing (Ruoyu Wang) - netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (Xiang Mei) {CVE-2026-74569} - phy: zynqmp: fix runtime PM leak on probe allocation failure (Radhey Shyam Pandey) - phy: zynqmp: fix clock error handling in xpsgtr_phy_init() (Radhey Shyam Pandey) - phy-zynqmp: Postpone getting clock rate until actually needed (Mike Looijmans) - btrfs: zoned: fix deadlock between metadata writeback and transaction commit (Johannes Thumshirn) {CVE-2026-74572} - btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag (Qu Wenruo) - of: reserved_mem: prevent OOB when too many dynamic regions are defined (Sang-Heon Jeon) {CVE-2026-80723} - of: reserved_mem: Add code to dynamically allocate reserved_mem array (Oreoluwa Babatunde) - ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare) - ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare) - ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources() (Radhey Shyam Pandey) - ahci: Introduce ahci_ignore_port() helper (Damien Le Moal) - ata: libahci_platform: support non-consecutive port numbers (Josua Mayer) - ata: sata_mv: accept 1 or 2 resources in platform probe (Rosen Penev) - gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe() (Abdun Nihaal) - dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() (Yuho Choi) {CVE-2026-74574} - dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA (Hongling Zeng) - pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 (Konrad Dybcio) - pinctrl: qcom: Unconditionally mark gpio as wakeup enable (Sneh Mankad) - thunderbolt: Prevent XDomain delayed work use-after-free on disconnect (Michael Bommarito) {CVE-2026-74575} - netconsole: avoid OOB reads, msg is not nul-terminated (Jakub Kicinski) {CVE-2026-43197} - bpf: Reset register bounds before narrowing retval range in check_mem_access() (Tristan Madani) {CVE-2026-72111} - HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (Benjamin Tissoires) - HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (Lee Jones) - HID: logitech-dj: Standardise hid_report_enum variable nomenclature (Lee Jones) - net: mpls: initialize rtm_tos in mpls_getroute() (Yehyeong Lee) {CVE-2026-74577} - netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge() (Lorenzo Bianconi) - um: Preserve errno within signal handler (Tiwei Bie) - kunit: tool: skip stty when stdin is not a tty (Shuvam Pandey) - kunit: tool: Terminate kernel under test on SIGINT (David Gow) - um: Set parent death signal for userspace process (Benjamin Berg) - um: Set parent-death signal for write_sigio thread/process (Tiwei Bie) - um: Set parent-death signal for ubd io thread/process (Tiwei Bie) - um: Use os_set_pdeathsig helper in winch thread/process (Tiwei Bie) - um: Set parent death signal for winch thread/process (Benjamin Berg) - um: Add os_set_pdeathsig helper function (Tiwei Bie) - LTS version: v6.12.102 (Saeed Mirzamohammadi) - LTS version: v6.12.101 (Saeed Mirzamohammadi) - KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug (Nikunj A Dadhania) {CVE-2026-68093} - afs: Fix uninit var in afs_alloc_anon_key() (David Howells) - Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() (Pavitra Jha) {CVE-2026-53364} - Bluetooth: hci_conn: Fix not cleaning up PA_LINK connections (Luiz Augusto von Dentz) - Bluetooth: hci_conn: Fix not cleaning up Broadcaster/Broadcast Source (Luiz Augusto von Dentz) - Bluetooth: hci_conn: Fix running bis_cleanup for hci_conn-type PA_LINK (Luiz Augusto von Dentz) - afs: handle CB.InitCallBackState3 requests without a server record (Nan Li) {CVE-2026-74425} - afs: Fix delayed allocation of a cell's anonymous key (David Howells) {CVE-2025-68299} - dpll: fix clock quality level reporting (Ivan Vecera) - afs: Set vllist to NULL if addr parsing fails (Edward Adam Davis) - net: ethernet: Remove accidental duplication in Kconfig file (Lukas Bulwahn) - wifi: nl80211: fix nl80211_start_radar_detection return value (Nicolas Escande) - rxrpc: Fix locking issues with the peer record hash (David Howells) - rxrpc: Disable IRQ, not BH, to take the lock for -attend_link (David Howells) - gpu: Fix uninitialized buddy for built-in drivers (Koen Koning) - net/mlx5e: Fix NULL pointer dereference in ioctl module EEPROM query (Gal Pressman) - usb: musb: omap2430: Do not put borrowed of_node in probe (Guangshuo Li) {CVE-2026-68371} - usb: musb: omap2430: clean up probe error handling (Johan Hovold) - USB: gadget: fsl-udc: fix dev_printk() device (Johan Hovold) - USB: gadget: Use str_enable_disable-like helpers (Krzysztof Kozlowski) - net: ipa: fix SMEM state handle leaks in SMP2P init (Haoxiang Li) - net: macb: drop in-flight Tx SKBs on close (Theo Lebrun) {CVE-2026-72017} - fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list (Reinette Chatre) {CVE-2026-72015} - ata: libata-core: Reject an invalid concurrent positioning ranges count (Bryam Vargas) {CVE-2026-72030} - octeontx2-pf: fix SQB pointer leak on init failure (Dawei Feng) {CVE-2026-72023} - net/mlx5: HWS, fix matcher leak on resize target setup failure (Dawei Feng) {CVE-2026-72032} - ipmi: fix refcount leak in i_ipmi_request() (Wentao Liang) {CVE-2026-72040} - bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline() (Breno Leitao) - bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c (Breno Leitao) - octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (Junrui Luo) {CVE-2026-72045} - gpio: mt7621: avoid corruption of shared interrupt trigger state (Sergio Paracuellos) {CVE-2026-72062} - gve: fix header buffer corruption with header-split and HW-GRO (Ankit Garg) {CVE-2026-72046} - net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) {CVE-2026-72051} - net: mana: Validate the packet length reported by the NIC (Dexuan Cui) {CVE-2026-72065} - locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (Thomas Gleixner) {CVE-2026-72069} - wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() (Maoyi Xie) {CVE-2026-72070} - dm: avoid leaking the caller's thread keyring via the table device file (Ingo Blechschmidt) {CVE-2026-72103} - cred: add scoped_with_kernel_creds() (Christian Brauner) - cred: add kernel_cred() helper (Christian Brauner) - cleanup: fix scoped_class() (Christian Brauner) - cleanup: add a scoped version of CLASS() (Christian Brauner) - dm-integrity: fix leaking uninitialized kernel memory (Mikulas Patocka) {CVE-2026-72101} - block: remove redundant GD_NEED_PART_SCAN in add_disk_final() (Connor Williamson) - block: add helper add_disk_final() (Ming Lei) - ovl: use linked upper dentry in copy-up tmpfile (Souvik Banerjee) - nvmet-auth: reject short AUTH_RECEIVE buffers (Michael Bommarito) {CVE-2026-72130} - nvmet: Introduce nvmet_req_transfer_len() (Damien Le Moal) - tcp: Decrement tcp_md5_needed static branch (Dmitry Safonov) - tcp: defer md5sig_info kfree past RCU grace period in tcp_connect (Michael Bommarito) {CVE-2026-72139} - xfrm: nat_keepalive: avoid double free on send error (Qianyu Luo) {CVE-2026-72137} - xfrm: Use nested-BH locking for nat_keepalive_sk_ipv[46] (Sebastian Andrzej Siewior) - i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (Vincent Jardin) - i2c: imx: separate atomic, dma and non-dma use case (Stefan Eichenberger) - dmaengine: dw-edma-pcie: Reject devices without driver data (Koichiro Den) {CVE-2026-72147} - dmaengine: dw-edma: Fix confusing cleanup.h syntax (Krzysztof Kozlowski) - dma: dw-edma: Fix build warning in dw_edma_pcie_probe() (Abinash Singh) - mm/sparse-vmemmap: fix DAX vmemmap accounting with optimization (Muchun Song) - mm: prepare to move subsection_map_init() to mm/sparse-vmemmap.c (David Hildenbrand (Arm)) - mtd: maps: vmu-flash: fix fault in unaligned fixup (Florian Fuchs) {CVE-2026-72168} - mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages (Muchun Song) - landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path (Bryam Vargas) {CVE-2026-72183} - landlock: Prepare to use credential instead of domain for fowner (Mickael Salaun) - mm/sparse-vmemmap: fix vmemmap accounting underflow (Muchun Song) - mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch (Deepanshu Kartikey) {CVE-2026-72213} - remoteproc: xlnx: Check remote core state (Tanmay Shah) - SUNRPC: Return an error from xdr_buf_to_bvec() on overflow (Chuck Lever) - SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists (Chuck Lever) - sunrpc: allocate a separate bvec array for socket sends (Jeff Layton) - NFSD: pass nfsd_file to nfsd_iter_read() (Mike Snitzer) - gpu/buddy: bail out of try_harder when alignment cannot be honoured (Arunpravin Paneer Selvam) {CVE-2026-72244} - gpu: Move DRM buddy allocator one level up (part two) (Joel Fernandes) - netfilter: nft_fib: reject fib expression on the netdev egress hook (Theodor Arsenij Larionov-Trichkine) {CVE-2026-72254} - netfilter: nf_tables: remove register tracking infrastructure (Florian Westphal) - netfilter: nf_tables: Remove unused nft_reduce_is_readonly() (Yue Haibing) - netfilter: bitwise: rename some boolean operation functions (Jeremy Sowden) - netfilter: nf_conntrack_sip: validate skb_dst() before accessing it (Pablo Neira Ayuso) {CVE-2026-72253} - netfilter: nf_conntrack_sip: remove net variable shadowing (Florian Westphal) - ASoC: mediatek: mt8183: Check runtime resume during probe (Cassio Gabriel) - ASoC: mediatek: mt8183-afe-pcm: use local dev pointer in driver callbacks (Chen-Yu Tsai) - ASoC: mediatek: mt8183-afe-pcm: Support 32 bit DMA addresses (Chen-Yu Tsai) - ASoC: mediatek: mt8183-afe-pcm: Shorten memif_data table using macros (Chen-Yu Tsai) - ASoC: mediatek: mt8192: Check runtime resume during probe (Cassio Gabriel) {CVE-2026-72260} - ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable (Tang Bin) - arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers (Abel Vesa) - arm64: dts: qcom: correct RBR opp entry (Dmitry Baryshkov) - octeontx2-pf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao) - octeontx2-vf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao) - VDUSE: avoid leaking information to userspace (Jason Wang) {CVE-2026-72305} - vduse: take out allocations from vduse_dev_alloc_coherent (Eugenio Perez) - vduse: remove unused vaddr parameter of vduse_domain_free_coherent (Eugenio Perez) - vduse: Use fixed 4KB bounce pages for non-4KB page size (Sheng Zhao) - tipc: restrict socket queue dumps in enqueue tracepoints (Li Xiasong) {CVE-2026-72299} - rxrpc: Fix socket notification race (David Howells) - rxrpc: Fix notification vs call-release vs recvmsg (David Howells) - rxrpc: Use irq-disabling spinlocks between app and I/O thread (David Howells) - rxrpc: Don't need barrier for -tx_bottom and -acks_hard_ack (David Howells) - rxrpc: Fix CPU time starvation in I/O thread (David Howells) - fbcon: Use correct type for vc_resize() return value (Jiacheng Yu) - fbcon: Rename struct fbcon_ops to struct fbcon_par (Thomas Zimmermann) - xfs: don't replace the wrong part of the cow fork (Darrick J. Wong) - xfs: factor out xfs_attr3_leaf_init (Long Li) - rxrpc: serialize kernel accept preallocation with socket teardown (Li Daming) {CVE-2026-74436} - rxrpc: Pull out certain app callback funcs into an ops table (David Howells) - ALSA: hda: Fix cached processing coefficient verbs (Xu Rao) - ALSA: hda: conexant: Remove mic bias threshold override (Zhang Heng) - i2c: i801: fix hardware state machine corruption in error path (Mingyu Wang) {CVE-2026-64205} - audit: fix recursive locking deadlock in audit_dupe_exe() (Ricardo Robaina) {CVE-2026-68096} - audit: use 'unsigned int' instead of 'unsigned' (Ricardo Robaina) - audit: widen ino fields to u64 (Jeff Layton) - VFS/audit: introduce kern_path_parent() for audit (NeilBrown) - i2c: davinci: Unregister cpufreq notifier on probe failure (Haoxiang Li) - fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() (Sebastian Alba Vives) {CVE-2026-64280} - iommufd: Avoid partial fault group delivery in iommufd_fault_fops_read() (Nicolin Chen) - iommufd: Break the loop on failure in iommufd_fault_fops_read() (Nicolin Chen) {CVE-2026-64290} - iommufd: Reject invalid read count in iommufd_fault_fops_read() (Nicolin Chen) - mm/damon/core: disallow overlapping input ranges for damon_set_regions() (SJ Park) {CVE-2026-68164} - mm/damon/core: validate ranges in damon_set_regions() (SJ Park) {CVE-2026-68165} - rust: allow suspicious_runtime_symbol_definitions lint for Rust = 1.98 (Miguel Ojeda) - gve: fix Rx queue stall on alloc failure (Eddie Phillips) {CVE-2026-68129} - net: pcs: xpcs: fix SGMII state reading (Coia Prant) - io_uring/rw: fix missing ERESTARTSYS conversion in read paths (Yitang Yang) - drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources (Harry Wentland) - ksmbd: validate ACE size against SID sub-authorities (Namjae Jeon) {CVE-2026-68097} - ksmbd: bound DACL dedup walk to copied ACEs (Namjae Jeon) {CVE-2026-68098} - bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (Jiayuan Chen) {CVE-2026-53078} - drm/amdgpu: fix aperture mapping leak (Asad Kamal) - drm/amdgpu: invoke pm_genpd_remove() before freeing genpd (Ce Sun) {CVE-2026-68104} - drm/amdgpu: fix division by zero with invalid uvd dimensions (Boyuan Zhang) {CVE-2026-68106} - drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (Luca Coelho) {CVE-2026-68429} - drm/amdgpu/vcn4: avoid rereading IB param length (Boyuan Zhang) {CVE-2026-68107} - drm/amdgpu/vce: fix integer overflow in image size (Boyuan Zhang) {CVE-2026-68108} - drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68110} - drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68111} - drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68112} - drm/amdgpu/gfx8: drop unecessary BUG_ON() (Alex Deucher) {CVE-2026-68430} - drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68113} - drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68246} - drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68115} - drm/amd/pm: make pp_features read-only when scpm is enabled (Yang Wang) - drm/amd/pm: fix amdgpu_pm_info power display units (Yang Wang) - vxlan: mdb: Fix source list corruption on a failed replace (James Raphael Tiovalen) {CVE-2026-68116} - tipc: clear sock-sk on the failed-insert path in tipc_sk_create() (Daehyeon Ko) {CVE-2026-68117} - tcp: initialize standalone TCP-AO response padding (Yizhou Zhao) {CVE-2026-68119} - rtase: Workaround for TX hang caused by hardware packet parsing (Justin Lai) {CVE-2026-68120} - pppoe: reload header pointer after dev_hard_header() (Asim Viladi Oglu Manizada) {CVE-2026-68121} - openvswitch: fix GSO userspace truncation underflow (Kyle Zeng) {CVE-2026-68123} - mctp: serial: handle zero-length frames to prevent rx buffer overflow (Doruk Tan Ozturk) {CVE-2026-68124} - mac802154: llsec: reject frames shorter than the authentication tag (Doruk Tan Ozturk) {CVE-2026-68125} - mac802154: hold an interface reference across the scan worker (Ibrahim Hashimov) {CVE-2026-68126} - ila: reload IPv6 header after pskb_may_pull in checksum adjust (Michael Bommarito) {CVE-2026-68127} - ice: use READ_ONCE() to access cached PHC time (Sergey Temerkhanov) - ice: reject out-of-range ptype in ice_parser_profile_init (Aleksandr Loktionov) {CVE-2026-68128} - ksmbd: defer destroy_previous_session() until after NTLM authentication (James Montgomery) {CVE-2026-68130} - rbd: Reset positive result codes to zero in object map update path (Raphael Zimmer) {CVE-2026-68131} - ice: fix PTP Call Trace during PTP release (Paul Greenwalt) {CVE-2026-68133} - net: hip04: fix RX buffer leak on build_skb failure (Fan Wu) {CVE-2026-68135} - net: gro: fix double aggregation of flush-marked skbs (Shiming Cheng) {CVE-2026-68136} - net/x25: fix use-after-free in x25_kill_by_neigh() (David Lee) {CVE-2026-68137} - net/mlx5e: Use sender devcom for MPV master-up (Manjunath Patil) {CVE-2026-68139} - net/iucv: fix use-after-free of a severed iucv_path (Bryam Vargas) {CVE-2026-68140} - net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() (Hidayath Khan) {CVE-2026-68141} - geneve: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk) {CVE-2026-68142} - net: slip: serialize receive against buffer reallocation (Sungmin Kang) {CVE-2026-68143} - vxlan: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk) {CVE-2026-68432} - phonet: pep: fix use-after-free in pep_get_sb() (Breno Leitao) {CVE-2026-68144} - iommu/vt-d: Disallow SVA if page walk is not coherent (Lu Baolu) - iomap: fix out-of-bounds bitmap_set() with zero-length range (Zhang Yi) {CVE-2026-68145} - ftrace: Add global mutex to serialize trace_parser access (Tengda Wu) {CVE-2026-68146} - fscrypt: Add missing superblock check in find_or_insert_direct_key() (Eric Biggers) {CVE-2026-68148} - fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (Amir Goldstein) {CVE-2026-68149} - binfmt_elf_fdpic: only honour the first PT_INTERP (Christian Brauner) {CVE-2026-68151} - ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP (Chancel Liu) - amt: fix use-after-free in AMT delayed works (Shihuang Liu) {CVE-2026-68152} - libceph: remove debugfs files before client teardown (Douya Le) {CVE-2026-68153} - libceph: reject zero bucket types in crush_decode (Douya Le) {CVE-2026-68154} - libceph: Reject monmaps advertising zero monitors (Raphael Zimmer) {CVE-2026-68155} - libceph: refresh auth-authorizer_buf{,_len} after authorizer update (Shuangpeng Bai) {CVE-2026-68156} - libceph: guard missing CRUSH type name lookup (Zhao Zhang) {CVE-2026-68157} - libceph: Fix multiplication overflow in decode_new_up_state_weight() (Raphael Zimmer) {CVE-2026-68158} - libceph: bound get_version reply decode to front len (Douya Le) {CVE-2026-68433} - ceph: fix refcount leak in ceph_readdir() (WenTao Liang) - ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (Bryam Vargas) {CVE-2026-68160} - sctp: close UDP tunnel sockets during netns teardown (Zhiling Zou) {CVE-2026-68161} - sctp: avoid auth_enable sysctl UAF during netns teardown (Zhiling Zou) {CVE-2026-68162} - sctp: don't free the ASCONF's own transport in DEL-IP processing (Jun Yang) {CVE-2026-64564} - mptcp: only set DATA_FIN when a mapping is present (Michael Bommarito) - mptcp: decrement subflows counter on failed passive join (Chenguang Zhao) - Revert 'arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates' (Will Deacon) - arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates (Will Deacon) - tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() (Masami Hiramatsu (Google)) - tracing/probes: Fix potential underflow in LEN_OR_ZERO macro (Masami Hiramatsu (Google)) - tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args() (Masami Hiramatsu (Google)) - tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() (Masami Hiramatsu (Google)) - tracing: Fix resource leak on mmiotrace trace_pipe close (deepakraog) {CVE-2026-68175} - tracing: Fix mmiotrace possible NULL dereferencing of hiter-dev (Steven Rostedt) {CVE-2026-68176} - misc: nsm: pin the module while the device is open (Xu Rao) {CVE-2026-68178} - misc: nsm: only unlock nsm_dev on post-lock error paths (Runyu Xiao) {CVE-2026-68179} - intel_th: fix MSC output device reference leak (Guangshuo Li) {CVE-2026-68180} - mei: bus: access mei_device under device_lock on cleanup (Alexander Usyskin) {CVE-2026-68181} - serial: sc16is7xx: implement gpio get_direction() callback (Hugo Villeneuve) - uio_hv_generic: Bind to FCopy device by default (Ben Hutchings) - comedi: comedi_parport: deal with premature interrupt (Ian Abbott) {CVE-2026-68182} - x86/boot/compressed: Disable jump tables (Nathan Chancellor) - firmware: stratix10-svc: fix memory leaks and list corruption bugs (Tze Yee Ng) {CVE-2026-68183} - cdrom: fix stack out-of-bounds read in CDROMVOLCTRL (Xu Rao) {CVE-2026-68184} - LoongArch: Retrieve CPU package ID from PPTT when available (Rong Bao) - LoongArch: Move jump_label_init() before parse_early_param() (Kanglong Wang) {CVE-2026-68185} - LoongArch: Fix oops during single-step debugging (Haoran Jiang) - objtool/rust: add one more noreturn Rust function for Rust 1.99.0 (Miguel Ojeda) - rust: allow clippy::unwrap_or_default globally (Alexandre Courbot) - platform/loongarch: laptop: Explicitly reset bl_powered state when suspend (Zixing Liu) - binfmt_misc: set have_execfd only once the interpreter is opened (Christian Brauner) {CVE-2026-68186} - exec: fix unsigned loop counter wrap in transfer_args_to_stack() (Christian Brauner) {CVE-2026-68187} - Bluetooth: RFCOMM: Fix session UAF in set_termios (Chengfeng Ye) {CVE-2026-68188} - Bluetooth: hci_sync: Protect UUID list traversal (Chengfeng Ye) {CVE-2026-68189} - staging: rtl8723bs: fix inverted HT40 secondary channel offset (MinJea Kim) - staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() (Moksh Panicker) {CVE-2026-68190} - wifi: brcmfmac: make release_scratchbuffers idempotent (Fan Wu) {CVE-2026-68192} - wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Devin Wittmayer) {CVE-2026-68193} - wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses (Devin Wittmayer) {CVE-2026-68194} - wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses (Devin Wittmayer) {CVE-2026-68195} - wifi: wilc1000: validate assoc response length before subtracting header (Huihui Huang) {CVE-2026-68196} - wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper (Doruk Tan Ozturk) {CVE-2026-68197} - wifi: ath6kl: fix OOB access from firmware ADDBA window size (Tristan Madani) {CVE-2026-68199} - ALSA: timer: don't re-enter an instance callback that is still running (Norbert Szetei) {CVE-2026-68200} - ALSA: timer: drain a slave's callback before its master detaches it (Norbert Szetei) {CVE-2026-68201} - ALSA: seq: close a re-opened queue timer in the destructor (Norbert Szetei) {CVE-2026-68202} - media: vpif_capture: fix OF node reference imbalance (Johan Hovold) - media: vivid: fix cleanup bugs in vivid_init() (Guangshuo Li) {CVE-2026-68203} - media: vivid: check for vb2_is_busy() when toggling caps (Hans Verkuil) {CVE-2026-68204} - media: vivid: add vivid_update_reduced_fps() (Hans Verkuil) - media: vimc: fix reference leak on failed device registration (Guangshuo Li) - media: vidtv: fix reference leak on failed device registration (Guangshuo Li) - media: vb2: use ssize_t for vb2_read/vb2_write (Zile Xiong) - media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely (Sakari Ailus) - media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (Mirela Rabulea) {CVE-2026-68205} - media: v4l2-ctrls: validate HEVC active reference counts (Pengpeng Hou) {CVE-2026-68206} - media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() (Sergey Shtylyov) - media: ti: vpe: unwind v4l2 device registration on probe error (Myeonghun Pak) {CVE-2026-68207} - media: tegra-video: vi: fix invalid u32 return value in format lookup (Hungyu Lin) - media: sun4i-csi: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68209} - media: stm32: dcmi: unregister notifier on probe failure (Myeonghun Pak) {CVE-2026-68210} - media: saa7134: Fix a possible memory leak in saa7134_video_init1 (Ma Ke) {CVE-2026-68212} - media: rtl2832_sdr: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68213} - media: rtl2832: fix use-after-free in rtl2832_remove() (Deepanshu Kartikey) {CVE-2026-68214} - media: radio-si476x: Unregister v4l2_device on probe failure (Myeonghun Pak) {CVE-2026-68215} - media: qcom: camss: Fix RDI streaming for CSID GEN2 (Bryan O'Donoghue) - media: pwc: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68216} - media: pwc: Drain fill_buf on start_streaming() failure (Valery Borovsky) {CVE-2026-68217} - media: pci: dm1105: Free allocated workqueue (Krzysztof Kozlowski) {CVE-2026-68218} - media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding (Guoniu Zhou) - media: nxp: imx8-isi: Fix potential out-of-bounds issues (Guoniu Zhou) {CVE-2026-68219} - media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path (Xiaolei Wang) - media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure (Xiaolei Wang) - media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe (Xiaolei Wang) {CVE-2026-68220} - media: nuvoton: npcm-video: fix memory leaks in probe and remove (David Carlier) {CVE-2026-68221} - media: nuvoton: npcm-video: fix error handling in npcm_video_init() (David Carlier) - media: msi2500: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68222} - media: meson: vdec: Fix memory leak in error path of vdec_open (Anand Moon) {CVE-2026-68223} - media: marvell-cam: fix missing pci_disable_device() on remove (Guangshuo Li) - media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges (Marco Nenciarini) - media: i2c: alvium: fix critical pointer access in alvium_ctrl_init (Martin Hecht) {CVE-2026-68225} - media: cx23885: add ioremap return check and cleanup (Wang Jun) {CVE-2026-68226} - media: cx231xx: fix devres lifetime (Johan Hovold) {CVE-2026-68227} - media: chips-media: wave5: Move src_buf Removal to finish_encode (Brandon Brnich) {CVE-2026-68228} - media: cedrus: skip invalid H.264 reference list entries (Pengpeng Hou) {CVE-2026-68229} - media: cedrus: Fix missing cleanup in error path (Samuel Holland) - media: cedrus: clean up media device on probe failure (Myeonghun Pak) - media: cec: seco: unregister adapter on IR probe failure (Myeonghun Pak) - media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (David Carlier) - media: airspy: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68231} - drm/vc4: Prevent shader BO mappings from becoming writable (Linmao Li) {CVE-2026-68445} - drm/vmwgfx: Validate vmw_surface_metadata::array_size (Ian Forbes) {CVE-2026-68446} - drm/amdgpu: fix bo-pin leaking in amdgpu_bo_create_reserved (Zhu Lingshan) {CVE-2026-68234} - drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge (Mario Limonciello) - drm/amd/display: dce100: skip non-DP stream encoders for DP MST (Andriy Korud) {CVE-2026-68235} - drm/amd/display: set new_stream to NULL after release (WenTao Liang) {CVE-2026-68236} - drm/amdgpu: Fix VFCT bus number matching with soft filter (Mario Limonciello) - drm/panthor: return error on truncated firmware (Osama Abdelkader) - drm/gfx10: Program DB_RING_CONTROL (Alex Deucher) - drm/amd/pm: fix smu14 power limit range calculation (Yang Wang) - drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (Joonas Lahtinen) {CVE-2026-68243} - drm/i915/gem: Do not leak siblings[] on proto context error (Joonas Lahtinen) {CVE-2026-68244} - drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() (Shahyan Soltani) {CVE-2026-68245} - drm/i915/bios: range check LFP Data Block panel_type2 (Jani Nikula) {CVE-2026-68247} - drm/i915: Return NULL on error in active_instance (Joonas Lahtinen) {CVE-2026-68248} - drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68249} - drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68250} - drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68251} - drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68252} - drm/virtio: bound EDID block reads to the response buffer (Bryam Vargas) {CVE-2026-68255} - drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (WenTao Liang) {CVE-2026-68256} - drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (Thomas Zimmermann) - drm/amdkfd: fix 32-bit overflow in CWSR total size calculation (Yongqiang Sun) {CVE-2026-68257} - drm/amdkfd: Check bounds in allocate_event_notification_slot (David Francis) {CVE-2026-68259} - drm/amdkfd: Use kvcalloc to allocate arrays (David Francis) - drm/imagination: acquire vm_ctx-lock before mapping memory to GPU VM (Icenowy Zheng) {CVE-2026-68260} - drm/imagination: fix error checking of pvr_vm_context_lookup() (Luigi Santivetti) {CVE-2026-68261} - drm/imagination: Fix user array stride in pvr_set_uobj_array() (Shuvam Pandey) {CVE-2026-68262} - drm/imagination: Fix double call to drm_sched_entity_fini() (Brajesh Gupta) {CVE-2026-68263} - drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds (Matthew Brost) - drm/radeon: fix r100_copy_blit for large BOs (Pavel Ondracka) - drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (Wentao Liang) - drm/i915/gem: Add missing nospec on parallel submit slot (Joonas Lahtinen) {CVE-2026-68269} - drm/displayid: fix Tiled Display Topology ID size (Jani Nikula) - drm/nouveau: fix reversed error cleanup order in ucopy functions (Junrui Luo) {CVE-2026-68271} - drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (Mario Limonciello) {CVE-2026-68272} - drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (Timur Kristof) - drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older (Timur Kristof) - drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2) (Timur Kristof) - drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (Ashutosh Desai) {CVE-2026-68277} - drm/imagination: Fit paired fragment job in the correct CCCB (Alessio Belle) {CVE-2026-68437} - drm/dp/mst: fix buffer overflows in sideband chunk accumulation (Ashutosh Desai) {CVE-2026-68278} - drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (Ashutosh Desai) {CVE-2026-68279} - drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (Vitor Soares) {CVE-2026-68280} - drm/imagination: Count paired job fence as dependency in prepare_job() (Alessio Belle) {CVE-2026-68281} - drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (Sergey Shtylyov) - drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (Biju Das) - bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (Chengfeng Ye) {CVE-2026-68284} - ice: fix LAG recipe to profile association (Marcin Szycik) - ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV (Vincent Chen) - net: ipv6: fix dif and sdif mismatch in raw6_icmp_error (Li RongQing) - net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation (Alexei Lazar) - net/mlx5e: Report zero bandwidth for non-ETS traffic classes (Alexei Lazar) - net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule (Yael Chemla) - net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (Gal Pressman) {CVE-2026-68293} - net/mlx5: Refactor EEPROM query error handling to return status separately (Gal Pressman) - net: qrtr: restrict socket creation to the initial network namespace (Aldo Ariel Panzardo) {CVE-2026-68294} - hinic: remove unused ethtool RSS user configuration buffers (Chenguang Zhao) - ppp: annotate data races in ppp_generic (Eric Dumazet) - ppp: enable TX scatter-gather (Qingfang Deng) - ppp: convert to percpu netstats (Qingfang Deng) - ppp: use IFF_NO_QUEUE in virtual interfaces (Qingfang Deng) - ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup (Eric Dumazet) - net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM (Yun Zhou) {CVE-2026-68296} - net: stmmac: enable the MAC on link up for all supported speeds (vadik likholetov) - net: stmmac: reset residual action in L3L4 filters on delete (Nazim Amirul) - net: stmmac: fix l3l4 filter rejecting unsupported offload requests (Nazim Amirul) - drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem (Jose Exposito) - tipc: fix u16 MTU truncation in media and bearer MTU validation (Cen Zhang (Microsoft)) - iomap: correct the range of a partial dirty clear (Zhang Yi) - vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (Harshaka Narayana) {CVE-2026-68299} - sctp: auth: verify auth requirement when auth_chunk is NULL (Qing Luo) {CVE-2026-68300} - net: dpaa: fix mode setting (Michael Walle) - net: hsr: fix memory leak on slave unregistration by removing synced VLANs (Eric Dumazet) {CVE-2026-68301} - net: bridge: vlan: fix vlan range dumps starting with pvid (Nikolay Aleksandrov) - amt: make the head writable before rewriting the L2 header (Michael Bommarito) - amt: re-read skb header pointers after every pull (Michael Bommarito) {CVE-2026-68302} - ovl: fix trusted xattr escape prefix matching (Yichong Chen) - wifi: brcmfmac: fix 802.1X-SHA256 call trace warning (Shelley Yang) {CVE-2026-68304} - wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() (Lorenzo Bianconi) {CVE-2026-68306} - wifi: mt76: mt7925: fix crash in reset link replay (Sean Wang) {CVE-2026-68307} - wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() (Lorenzo Bianconi) {CVE-2026-68308} - wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv() (Lorenzo Bianconi) {CVE-2026-68439} - wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() (Lorenzo Bianconi) {CVE-2026-68309} - wifi: mt76: mt7915: guard HE capability lookups (Ruoyu Wang) {CVE-2026-68310} - wifi: mt76: mt7925: guard link STA in decap offload (Guangshuo Li) {CVE-2026-68311} - tipc: fix infinite loop in __tipc_nl_compat_dumpit (Helen Koike) {CVE-2026-68313} - nexthop: initialize extack in nh_res_bucket_migrate() (Xiang Mei (Microsoft)) - gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (Xiang Mei (Microsoft)) - selftests: openvswitch: add config file (Matthieu Baerts (NGI0)) - selftests: af_unix: add USER_NS config (Matthieu Baerts (NGI0)) - tls: device: push pending open record on splice EOF (Rishikesh Jethwani) - net: mctp i3c: clean up notifier and buses if driver register fails (Myeonghun Pak) {CVE-2026-68314} - sctp: validate stream count in sctp_process_strreset_inreq() (Cen Zhang (Microsoft)) - pds_core: check for workqueue allocation failure (Nikhil P. Rao) - pds_core: fix auxiliary device add/del races (Nikhil P. Rao) {CVE-2026-68317} - pds_core: order completion reads after the ownership check (Nikhil P. Rao) - pds_core: yield the CPU while waiting for the adminq to drain (Nikhil P. Rao) - pds_core: fix use-after-free on workqueue during remove (Nikhil P. Rao) {CVE-2026-68318} - pds_core: fix deadlock between reset thread and remove (Nikhil P. Rao) {CVE-2026-68319} - sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (HanQuan) {CVE-2026-68320} - net: txgbe: fix FDIR filter leak on remove (Chenguang Zhao) {CVE-2026-68321} - amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN (Prashanth Kumar KR) - pds_core: reject component parameter in legacy firmware update (Nikhil P. Rao) - wifi: mac80211: recalculate TIM when a station enters power save (Andrew Pope) - iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (Li RongQing) {CVE-2026-68324} - iommu/amd: Bound the early ACPI HID map (Pengpeng Hou) {CVE-2026-68325} - wifi: mwifiex: bound uAP association event IEs to the event buffer (HE WEI (???)) - wan: wanxl: Only reset hardware after BAR mapping (Ruoyu Wang) {CVE-2026-68327} - nfp: Check resource mutex allocation (Ruoyu Wang) {CVE-2026-68328} - wifi: mac80211: tear down new links on vif update error path (Xiang Mei) {CVE-2026-64574} - iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (Guanghui Feng) {CVE-2026-68329} - dpaa2-eth: put MAC endpoint device on disconnect (Guangshuo Li) {CVE-2026-68331} - dpaa2-switch: put MAC endpoint device on disconnect (Guangshuo Li) {CVE-2026-68333} - gtp: parse extension headers before reading inner protocol (Zhixing Chen) - bonding: fix devconf_all NULL dereference when IPv6 is disabled (Zhaolong Zhang) {CVE-2026-68336} - net/packet: avoid fanout hook re-registration after unregister (David Lee) {CVE-2026-68338} - netlink: specs: rt-link: convert bridge port flag attributes to u8 (Danielle Ratson) - Bluetooth: btusb: validate Realtek vendor event length (Pengpeng Hou) {CVE-2026-68339} - regulator: mt6358: use regmap helper to read fixed LDO calibration (Daniel Golle) - hwmon: occ: validate poll response sensor blocks (Pengpeng Hou) {CVE-2026-68340} - smb: client: validate DFS referral PathConsumed (Yichong Chen) {CVE-2026-68343} - hwmon: (asus-ec-sensors) add missed handle for ENOMEM (Eugene Shalygin) - hwmon: (asus-ec-sensors) fix EC read intervals (Eugene Shalygin) - hwmon: (asus-ec-sensors) fix looping over banks while reading from EC (Eugene Shalygin) - drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook() (Mostafa Saleh) - wifi: iwlwifi: mvm: fix read in wake packet notification handler (Shahar Tzarfati) - wifi: iwlwifi: mvm: validate SAR GEO response payload size (Pagadala Yesu Anjaneyulu) - ASoC: cs35l56: Use complete_all() to signal init_completion (Richard Fitzgerald) - ASoC: cs35l56: Fix potential probe() deadlock (Richard Fitzgerald) - ASoC: cs35l56: Don't use devres to unregister component (Richard Fitzgerald) - ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI (Shengjiu Wang) - ALSA: hda: cs35l41: validate and free ACPI mute object (Guangshuo Li) {CVE-2026-68346} - ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state() (Denis Arefev) - ASoC: tas2781: bound firmware description string parsing (Pengpeng Hou) {CVE-2026-68348} - btrfs: free mapping node on duplicate reloc root insert (Guanghui Yang) {CVE-2026-68450} - btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps (Leo Martins) {CVE-2026-68442} - btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8 (You-Kai Zheng) - wifi: carl9170: fix buffer overflow in rx_stream failover path (Tristan Madani) {CVE-2026-68349} - wifi: carl9170: fix OOB read from off-by-two in TX status handler (Tristan Madani) {CVE-2026-68350} - wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read (Tristan Madani) {CVE-2026-68351} - wifi: ath6kl: fix OOB read from firmware IE lengths in connect event (Tristan Madani) {CVE-2026-68352} - wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler (Tristan Madani) {CVE-2026-68353} - firewire: net: Fix fragmented datagram reassembly (Ruoyu Wang) {CVE-2026-68354} - wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (Manivannan Sadhasivam) - wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (Manivannan Sadhasivam) - wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() (Dmitry Morgun) {CVE-2026-68355} - watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() (Tzung-Bi Shih) {CVE-2026-68357} - hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop (Guenter Roeck) {CVE-2026-68358} - hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop (Guenter Roeck) {CVE-2026-68359} - hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop (Guenter Roeck) {CVE-2026-68443} - hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop (Guenter Roeck) {CVE-2026-68360} - hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop (Edward Adam Davis) {CVE-2026-68361} - wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin (Gaole Zhang) {CVE-2026-68362} - wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (Cheng Yongkang) {CVE-2026-68363} - usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits (Xincheng Zhang) - RISC-V: KVM: Serialize virtual interrupt pending state updates (Xie Bo) - crypto: rsa-pkcs1pad: Don't WARN on an empty digest (Doruk Tan Ozturk) - USB: serial: option: add TDTECH MT5710-CN (Chukun Pan) - USB: serial: keyspan_pda: fix data loss on receive throttling (Johan Hovold) - USB: serial: io_edgeport: cap received transmit credits (Sunho Park) {CVE-2026-68365} - USB: serial: ftdi_sio: add support for E+H FXA291 (Tim Pambor) - usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer (Muhammad Bilal) {CVE-2026-68366} - usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown (Fan Wu) {CVE-2026-64583} - usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() (Sonali Pradhan) {CVE-2026-68368} - USB: gadget: fsl-udc: fix device name leak on probe failure (Johan Hovold) - USB: gadget: snps-udc: fix device name leak on probe failure (Johan Hovold) - usb: gadget: printer: fix infinite loop in printer_read() (Melbin K Mathew) {CVE-2026-68369} - usb: gadget: f_midi: cancel pending IN work before freeing the midi object (Fan Wu) {CVE-2026-64584} - usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback (Jinchao Wang) {CVE-2026-68370} - usb: chipidea: fix usage_count leak when autosuspend_delay is negative (Xu Yang) - USB: storage: add NO_ATA_1X quirk for Longmai USB Key (Huang Wei) - usb: core: port: Deattach Type-C connector on component unbind (Chia-Lin Kao (AceLan)) - wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() (Huihui Huang) {CVE-2026-68373} - usb: core: sysfs: add lock to bos_descriptors_read() (Griffin Kroah-Hartman) {CVE-2026-68374} - mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (Weiming Shi) {CVE-2026-64569} - sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) {CVE-2026-68376} - net/sched: act_tunnel_key: Defer dst_release to RCU callback (Jamal Hadi Salim) {CVE-2026-68377} - drm/i915/selftests: Fix GT PM sort comparators (Emre Cecanpunar) - ksmbd: validate compound request size before reading StructureSize2 (Xiang Mei (Microsoft)) - ksmbd: pin conn during async oplock break notification (Qihang) {CVE-2026-68381} - smb: move some duplicate definitions to common/cifsglob.h (ZhangGuoDong) - drm/xe/wopcm: fix WOPCM size for LNL+ (Daniele Ceraolo Spurio) - can: j1939: fix lockless local-destination check (Shuhao Fu) - riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus() (Mark Harris) - s390/checksum: Fix csum_partial() without vector facility (Vasily Gorbik) {CVE-2026-68385} - bpf, sockmap: Reject unhashed UDP sockets on sockmap update (Michal Luczaj) {CVE-2026-68386} - powerpc/vtime: Initialize starttime at boot for native accounting (Shrikanth Hegde) - powerpc/time: Prepare to stop elapsing in dynticks-idle (Frederic Weisbecker) - powerpc/85xx: Add fsl,ifc to common device ids (Rosen Penev) - drm/i915/gt: use correct selftest config symbol (Pengpeng Hou) - smb/client: handle overlapping allocated ranges in fallocate (Huiwen He) {CVE-2026-68388} - Bluetooth: hci_qca: Clear memdump state on invalid dump size (Ruoyu Wang) {CVE-2026-68389} - Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (Pauli Virtanen) {CVE-2026-68391} - Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync (Pauli Virtanen) {CVE-2026-68392} - Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update (Cen Zhang) {CVE-2026-68394} - Bluetooth: qca: fix NVM tag length underflow in TLV parser (Xiang Mei) {CVE-2026-64573} - ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (Takashi Iwai) - accel/ivpu: Fix wrong register read in LNL failure diagnostics (Karol Wachowski) - ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning (Rosen Penev) {CVE-2026-68449} - ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts (Rosen Penev) - ata: sata_dwc_460ex: use platform_get_irq() (Rosen Penev) - ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered (Rosen Penev) {CVE-2026-68395} - net/iucv: take a reference on the socket found in afiucv_hs_rcv() (Bryam Vargas) {CVE-2026-68397} - ipv4: fib: free fib_alias with kfree_rcu() on insert error path (Weiming Shi) {CVE-2026-64572} - ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (Norbert Szetei) {CVE-2026-68398} - cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq (Rafael J. Wysocki) - firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context (Pushpendra Singh) - ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (Uday Khare) - ASoC: cs42l43: Correct report for forced microphone jack (Charles Keepax) - ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() (Vijendar Mukunda) - ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (Christian Hewitt) - wifi: cfg80211: bound element ID read when checking non-inheritance (HE WEI (???)) - wifi: brcmfmac: initialize SDIO data work before cleanup (Runyu Xiao) {CVE-2026-68403} - wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (Cen Zhang) {CVE-2026-68405} - wifi: cfg80211: reject unsupported PMSR FTM location requests (Zhao Li) - wifi: cfg80211: validate PMSR FTM preamble range (Zhao Li) {CVE-2026-68406} - wifi: cfg80211: validate PMSR measurement type data (Zhao Li) - wifi: nl80211: validate nested MBSSID IE blobs (Zhao Li) - wifi: cfg80211: derive S1G beacon TSF from S1G fields (Zhao Li) - wifi: nl80211: free RNR data on MBSSID mismatch (Zhao Li) {CVE-2026-68407} - wifi: p54: validate RX frame length in p54_rx_eeprom_readback() (Xiang Mei) {CVE-2026-64571} - wifi: libertas: fix memory leak in helper_firmware_cb() (Dawei Feng) {CVE-2026-68410} - wifi: mac80211: fix fils_discovery double free on alloc failure (Xiang Mei) {CVE-2026-64570} - wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure (Xiang Mei) {CVE-2026-64568} - wifi: mac80211_hwsim: clamp virtio RX length before skb_put (Bryam Vargas) {CVE-2026-68411} - wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (Abdun Nihaal) {CVE-2026-68413} - wifi: cfg80211: cancel sched scan results work on unregister (Cen Zhang) {CVE-2026-68414} - xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert (Xiang Mei (Microsoft)) - xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() (Xiang Mei (Microsoft)) - RDMA/irdma: Prevent overflows in memory contiguity checks (Aleksandrova Alyona) - selftests/alsa: Fix memory leak in find_controls error path (Malaya Kumar Rout) - mtd: fix double free and WARN_ON in add_mtd_device() error paths (Xue Lei) {CVE-2026-68416} - RDMA/siw: publish QP after initialization (Ruoyu Wang) {CVE-2026-68417} - RDMA/hns: Fix potential integer overflow in mhop hem cleanup (Danila Chernetsov) - RDMA/erdma: initialize ret for empty receive WR lists (Ruoyu Wang) - RDMA/irdma: Prevent rereg_mr for non-mem regions (Jacob Moroni) {CVE-2026-68419} - RDMA/umem: Add pinned revocable dmabuf import interface (Jacob Moroni) - RDMA/cma: Fix hardware address comparison length in netevent callback (Or Gerlitz) - firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (Unnathi Chalicheemala) {CVE-2026-68444} - btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (Filipe Manana) {CVE-2026-68422} - btrfs: reject free space cache with more entries than pages (Xiang Mei) {CVE-2026-64567} - mtd: nand: mtk-ecc: stop on ECC idle timeouts (Pengpeng Hou) - mtd: mtdswap: remove debugfs stats file on teardown (Pengpeng Hou) - IB/mad: Drop unmatched RMPP responses before reassembly (Michael Bommarito) {CVE-2026-68425} - arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234 (Sumit Gupta) - soc: qcom: ice: Allow explicit votes on 'iface' clock for ICE (Harshal Dev) - Input: ims-pcu - fix logic error in packet reset (Dmitry Torokhov) - Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (Seungjin Bae) {CVE-2026-64565} - xprtrdma: Clear receive-side ownership pointers on release (Chuck Lever) - crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin (Mikko Perttunen) - gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings (Mikko Perttunen) {CVE-2026-68427} - dmaengine: sh: rz-dmac: Move interrupt request after everything is set up (Claudiu Beznea) {CVE-2026-72146} - can: isotp: serialize TX state transitions under so-rx_lock (Oliver Hartkopp) {CVE-2026-72124} - can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER (Oliver Hartkopp) {CVE-2026-72125} - can: bcm: track a single source interface for ANYDEV timeout/throttle ops (Oliver Hartkopp) {CVE-2026-72115} - can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() (Oliver Hartkopp) {CVE-2026-72117} - can: bcm: fix stale rx/tx ops after device removal (Oliver Hartkopp) {CVE-2026-72116} - can: bcm: add missing device refcount for CAN filter removal (Oliver Hartkopp) {CVE-2026-72113} - can: bcm: validate frame length in bcm_rx_setup() for RTR replies (Oliver Hartkopp) {CVE-2026-72114} - can: bcm: extend bcm_tx_lock usage for data and timer updates (Oliver Hartkopp) {CVE-2026-72119} - can: bcm: fix CAN frame rx/tx statistics (Oliver Hartkopp) {CVE-2026-72118} - can: bcm: add locking when updating filter and timer values (Oliver Hartkopp) {CVE-2026-72121} - KVM: x86/mmu: Fix use-after-free on vendor module reload (Phil Rosenthal) {CVE-2026-68428} - KVM: nVMX: Hide shadow VMCS right after VMCLEAR (Hyunwoo Kim) {CVE-2026-64562} - KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN (Venkatesh Srinivas) - seqlock: Allow UBSAN_ALIGNMENT to fail optimizing (Heiko Carstens) - seqlock: Allow KASAN to fail optimizing (Peter Zijlstra) - seqlock: Cure some more scoped_seqlock() optimization fails (Peter Zijlstra) - fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race (Kiryl Shutsemau) {CVE-2026-72175} - drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker (Ryosuke Yasuoka) - netfilter: nf_tables: revert commit_mutex usage in reset path (Brian Witte) {CVE-2026-45901} - netfilter: nft_quota: use atomic64_xchg for reset (Brian Witte) - netfilter: nft_counter: serialize reset with spinlock (Brian Witte) {CVE-2026-45897} - selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs (Daniel Borkmann) - bpf: Fix ld_{abs,ind} failure path analysis in subprogs (Daniel Borkmann) {CVE-2026-53090} - net: airoha: Move airoha_eth driver in a dedicated folder (Lorenzo Bianconi) - platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug (Guixiong Wei) [6.12.0-206.100.3] - can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure (Guangshuo Li) {CVE-2026-74459} - ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes (Norbert Szetei) {CVE-2026-74503} - sched/deadline: Use revised wakeup rule only for running dl_server (Gabriele Monaco) - scsi: ufs: core: Cancel RTC work in active-active suspend (Guangshuo Li) - net: airoha: Fix register index for Tx-fwd counter configuration (Wayen Yan) - netfilter: nf_conntrack_expect: restore helper propagation via expectation (Pablo Neira Ayuso) - Enable Time slice extension (Prakash Sangappa) [Orabug: 39047408] - rseq: Increase struct rseq size to match mainline linux (Prakash Sangappa) [Orabug: 39047408] - selftests/rseq: Make registration flexible for legacy and optimized mode (Thomas Gleixner) [Orabug: 39047408] - selftests/rseq: Skip tests if time slice extensions are not available (Thomas Gleixner) [Orabug: 39047408] - rseq: Don't advertise time slice extensions if disabled (Thomas Gleixner) [Orabug: 39047408] - selftests/rseq: Add rseq slice histogram script (Peter Zijlstra) [Orabug: 39047408] - rseq: Lower default slice extension (Peter Zijlstra) [Orabug: 39047408] - rseq: Move slice_ext_nsec to debugfs (Peter Zijlstra) [Orabug: 39047408] - rseq: Allow registering RSEQ with slice extension (Peter Zijlstra) [Orabug: 39047408] - selftests/rseq: Implement time slice extension test (Thomas Gleixner) [Orabug: 39047408] - entry: Hook up rseq time slice extension (Thomas Gleixner) [Orabug: 39047408] - rseq: Implement rseq_grant_slice_extension() (Thomas Gleixner) [Orabug: 39047408] - rseq: Reset slice extension when scheduled (Thomas Gleixner) [Orabug: 39047408] - rseq: Implement time slice extension enforcement timer (Prakash Sangappa) [Orabug: 39047408] - rseq: Implement syscall entry work for time slice extensions (Thomas Gleixner) [Orabug: 39047408] - rseq: Implement sys_rseq_slice_yield() (Thomas Gleixner) [Orabug: 39047408] - rseq: Add prctl() to enable time slice extensions (Thomas Gleixner) [Orabug: 39047408] - rseq: Add statistics for time slice extensions (Thomas Gleixner) [Orabug: 39047408] - rseq: Provide static branch for runtime debugging (Thomas Gleixner) [Orabug: 39047408] - rseq: Expose lightweight statistics in debugfs (Thomas Gleixner) [Orabug: 39047408] - rseq: Provide static branch for time slice extensions (Thomas Gleixner) [Orabug: 39047408] - rseq: Add fields and constants for time slice extension (Prakash Sangappa) [Orabug: 39047408] - Revert 'Sched: Scheduler time slice extension' (Prakash Sangappa) [Orabug: 39047408] - Revert 'Sched: Add scheduler stat for cpu time slice extension' (Prakash Sangappa) [Orabug: 39047408] - Revert 'Scheduler extension change under Oracle Extensions and modify enum value' (Prakash Sangappa) [Orabug: 39047408] - net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover (Matt Fleming) [Orabug: 39203117,39870622] {CVE-2026-64122} - net/mlx5e: Fix deadlocks between devlink and netdev instance locks (Cosmin Ratiu) [Orabug: 39203117,39870450] {CVE-2026-45907} - net/mlx5: HWS, ignore flow level for multi-dest table (Yevgeny Kliteynik) [Orabug: 39203117] - net/mlx5: Prevent flow steering mode changes in switchdev mode (Moshe Shemesh) [Orabug: 39203117] - net/mlx5: HWS, Fix pattern destruction in mlx5hws_pat_get_pattern error path (Lama Kayal) [Orabug: 39203117] - net/mlx5: HWS, Fix memory leak in hws_action_get_shared_stc_nic error flow (Lama Kayal) [Orabug: 39203117] - net/mlx5: HWS, Fix memory leak in hws_pool_buddy_init error path (Lama Kayal) [Orabug: 39203117] - selftests: drv-net: hds: restore hds settings (Jakub Kicinski) [Orabug: 39203117] - net/mlx5: Restore missing scheduling node cleanup on vport enable failure (Carolina Jubran) [Orabug: 39203117] - net/mlx5: Fix QoS reference leak in vport enable error path (Carolina Jubran) [Orabug: 39203117] - net/mlx5: Destroy vport QoS element when no configuration remains (Carolina Jubran) [Orabug: 39203117] - net/mlx5e: Preserve tc-bw during parent changes (Carolina Jubran) [Orabug: 39203117] - net/mlx5: Remove default QoS group and attach vports directly to root TSAR (Carolina Jubran) [Orabug: 39203117] - net/mlx5: HWS, Fix table creation UID (Alex Vesker) [Orabug: 39203117] - net/mlx5: HWS, don't rehash on every kind of insertion failure (Yevgeny Kliteynik) [Orabug: 39203117] - selftests: drv-net: wait for carrier (Jakub Kicinski) [Orabug: 39203117] - netdevsim: Fix wild pointer access in nsim_queue_free(). (Kuniyuki Iwashima) [Orabug: 39203117] - vfio/pci: Do vf_token checks for VFIO_DEVICE_BIND_IOMMUFD (Jason Gunthorpe) [Orabug: 39203117] - net/mlx5e: Expose TIS via devlink tx reporter diagnose (Feng Liu) [Orabug: 39203117] - net/mlx5e: Fix potential deadlock by deferring RX timeout recovery (Shahar Shitrit) [Orabug: 39203117] - selftests: drv-net: Make command requirements explicit (Gal Pressman) [Orabug: 39203117] - net/mlx5: Fix build -Wframe-larger-than warnings (Zhu Yanjun) [Orabug: 39203117] - mlx5: access -pp through netmem_desc instead of page (Byungchul Park) [Orabug: 39203117] - netdevsim: access -pp through netmem_desc instead of page (Byungchul Park) [Orabug: 39203117] - netmem, mlx4: access -pp_ref_count through netmem_desc instead of page (Byungchul Park) [Orabug: 39203117] - netmem: use netmem_desc instead of page to access -pp in __netmem_get_pp() (Byungchul Park) [Orabug: 39203117] - netmem: introduce struct netmem_desc mirroring struct page (Byungchul Park) [Orabug: 39203117] - netdevsim: add fw_update_flash_chunk_time_ms debugfs knobs (Jiri Pirko) [Orabug: 39203117] - devlink: Fix excessive stack usage in rate TC bandwidth parsing (Carolina Jubran) [Orabug: 39203117] - RDMA/mlx5: Refactor optional counters steering code (Patrisious Haddad) [Orabug: 39203117] - RDMA/mlx5: Add DMAH object support (Yishai Hadas) [Orabug: 39203117] - RDMA/core: Introduce a DMAH object and its alloc/free APIs (Yishai Hadas) [Orabug: 39203117] - IB/core: Add UVERBS_METHOD_REG_MR on the MR object (Yishai Hadas) [Orabug: 39203117] - net/mlx5: Add support for device steering tag (Yishai Hadas) [Orabug: 39203117] - net/mlx5: Expose IFC bits for TPH (Yishai Hadas) [Orabug: 39203117] - PCI/TPH: Expose pcie_tph_get_st_table_size() (Yishai Hadas) [Orabug: 39203117] - net/mlx5e: Remove duplicate mkey from SHAMPO header (Lama Kayal) [Orabug: 39203117] - net/mlx5e: SHAMPO, Remove mlx5e_shampo_get_log_hd_entry_size() (Lama Kayal) [Orabug: 39203117] - net/mlx5e: SHAMPO, Cleanup reservation size formula (Lama Kayal) [Orabug: 39203117] - selftests: drv-net: Test XDP_PASS/DROP support (Mohsin Bashir) [Orabug: 39203117] - net: netdevsim: hook in XDP handling (Jakub Kicinski) [Orabug: 39203117] - RDMA/mlx5: Fix incorrect MKEY masking (Leon Romanovsky) [Orabug: 39203117] - RDMA/mlx5: Fix returned type from _mlx5r_umr_zap_mkey() (Leon Romanovsky) [Orabug: 39203117] - net/mlx5: Expose cable_length field in PFCC register (Oren Sidi) [Orabug: 39203117] - net/mlx5: Add IFC bits to support RSS for IPSec offload (Jianbo Liu) [Orabug: 39203117] - net/mlx5e: fix kdoc warning on eswitch.h (Moshe Shemesh) [Orabug: 39203117] - net/mlx5: HWS, Enable IPSec hardware offload in legacy mode (Lama Kayal) [Orabug: 39203117] - net/mlx5: Fix an IS_ERR() vs NULL bug in esw_qos_move_node() (Dan Carpenter) [Orabug: 39203117] - netdevsim: remove redundant branch (Dennis Chen) [Orabug: 39203117] - selftests: net: prevent Python from buffering the output (Jakub Kicinski) [Orabug: 39203117] - netlink: specs: define input-xfrm enum in the spec (Jakub Kicinski) [Orabug: 39203117] - net/mlx5e: TX, Fix dma unmapping for devmem tx (Dragos Tatulea) [Orabug: 39203117] - RDMA/mlx5: remove redundant check on err on return expression (Colin Ian King) [Orabug: 39203117] - net/mlx5e: Add device PCIe congestion ethtool stats (Dragos Tatulea) [Orabug: 39203117] - net/mlx5e: Create/destroy PCIe Congestion Event object (Dragos Tatulea) [Orabug: 39203117] - selftests: net: add netpoll basic functionality test (Breno Leitao) [Orabug: 39203117] - selftests: drv-net: add helper/wrapper for bpftrace (Jakub Kicinski) [Orabug: 39203117] - netdevsim: implement peer queue flow control (Breno Leitao) [Orabug: 39203117] - RDMA/uverbs: Add a common way to create CQ with umem (Michael Margolin) [Orabug: 39203117] - net/mlx5: Expose disciplined_fr_counter through HCA capabilities in mlx5_ifc (Carolina Jubran) [Orabug: 39203117] - RDMA/mlx5: Optimize DMABUF mkey page size (Edward Srouji) [Orabug: 39203117] - RDMA/mlx5: Align mkc page size capability check to PRM (Michael Guralnik) [Orabug: 39203117] - net/mlx5: Expose HCA capability bits for mkey max page size (Michael Guralnik) [Orabug: 39203117] - net: netdevsim: Support setting dev-perm_addr on port creation (Toke Hoiland-Jorgensen) [Orabug: 39203117] - selftests: drv-net: Add bpftool util (Mohsin Bashir) [Orabug: 39203117] - net/mlx5e: RX, Remove unnecessary RQT redirects (Tariq Toukan) [Orabug: 39203117] - net/mlx5: Warn when write combining is not supported (Maor Gottlieb) [Orabug: 39203117] - net/mlx5e: Replace recursive VLAN push handling with an iterative loop (Gal Pressman) [Orabug: 39203117] - net/mlx5e: CT: extract a memcmp from a spinlock section (Cosmin Ratiu) [Orabug: 39203117] - net/mlx5e: Remove unused VLAN insertion logic in TX path (Carolina Jubran) [Orabug: 39203117] - eth: mlx5: migrate to the *_rxfh_context ops (Jakub Kicinski) [Orabug: 39203117] - net/mlx5: Fix spelling mistake 'disabliing' - 'disabling' (Colin Ian King) [Orabug: 39203117] - net/mlx5: Add HWS as secondary steering mode (Moshe Shemesh) [Orabug: 39203117] - net/mlx5: HWS, Shrink empty matchers (Yevgeny Kliteynik) [Orabug: 39203117] - net/mlx5: HWS, Refactor rule skip logic (Vlad Dogaru) [Orabug: 39203117] - net/mlx5: HWS, remove incorrect comment (Yevgeny Kliteynik) [Orabug: 39203117] - net/mlx5: HWS, remove unused create_dest_array parameter (Vlad Dogaru) [Orabug: 39203117] - netmem: use _Generic to cover const casting for page_to_netmem() (Byungchul Park) [Orabug: 39203117] - page_pool: rename __page_pool_alloc_pages_slow() to __page_pool_alloc_netmems_slow() (Byungchul Park) [Orabug: 39203117] - page_pool: rename __page_pool_release_page_dma() to __page_pool_release_netmem_dma() (Byungchul Park) [Orabug: 39203117] - page_pool: rename page_pool_return_page() to page_pool_return_netmem() (Byungchul Park) [Orabug: 39203117] - mlxbf_gige: emit messages during open and probe failures (David Thompson) [Orabug: 39203117] - selftests: drv-net: Add test for devlink-rate traffic class bandwidth distribution (Carolina Jubran) [Orabug: 39203117] - net/mlx5: Manage TC arbiter nodes and implement full support for tc-bw (Carolina Jubran) [Orabug: 39203117] - net/mlx5: Add traffic class scheduling support for vport QoS (Carolina Jubran) [Orabug: 39203117] - net/mlx5: Add support for setting tc-bw on nodes (Carolina Jubran) [Orabug: 39203117] - net/mlx5: Add no-op implementation for setting tc-bw on rate objects (Carolina Jubran) [Orabug: 39203117] - selftest: netdevsim: Add devlink rate tc-bw test (Carolina Jubran) [Orabug: 39203117] - devlink: Extend devlink rate API with traffic classes bandwidth management (Carolina Jubran) [Orabug: 39203117] - netlink: introduce type-checking attribute iteration for nlmsg (Carolina Jubran) [Orabug: 39203117] - net/mlx5: fs, fix RDMA TRANSPORT init cleanup flow (Patrisious Haddad) [Orabug: 39203117] - RDMA/mlx5: Check CAP_NET_RAW in user namespace for devx create (Parav Pandit) [Orabug: 39203117] - time/timecounter: Fix the lie that struct cyclecounter is const (Greg Kroah-Hartman) [Orabug: 39203117] - RDMA/mlx5: Check CAP_NET_RAW in user namespace for anchor create (Parav Pandit) [Orabug: 39203117] - RDMA/mlx5: Check CAP_NET_RAW in user namespace for flow create (Parav Pandit) [Orabug: 39203117] - RDMA/uverbs: Check CAP_NET_RAW in user namespace for flow create (Parav Pandit) [Orabug: 39203117] - net/mlx5e: Fix error handling in RQ memory model registration (Wangfushuai) [Orabug: 39203117] - selftests: forwarding: lib: Split setup_wait() (Petr Machata) [Orabug: 39203117] - RDMA/ipoib: Use parent rdma device net namespace (Mark Bloch) [Orabug: 39203117] - RDMA/mlx5: Allocate IB device with net namespace supplied from core dev (Mark Bloch) [Orabug: 39203117] - RDMA/core: Extend RDMA device registration to be net namespace aware (Mark Bloch) [Orabug: 39203117] - netlink: specs: ethtool: replace underscores with dashes in names (Jakub Kicinski) [Orabug: 39203117] - net/mlx5: Add IFC bits for PCIe Congestion Event object (Dragos Tatulea) [Orabug: 39203117] - net/mlx5: Small refactor for general object capabilities (Dragos Tatulea) [Orabug: 39203117] - RDMA/mlx5: Add multiple priorities support to RDMA TRANSPORT userspace tables (Patrisious Haddad) [Orabug: 39203117] - net/mlx5: fs, add multiple prios to RDMA TRANSPORT steering domain (Patrisious Haddad) [Orabug: 39203117] - RDMA/mlx5: Support driver APIs pre_destroy_cq and post_destroy_cq (Mark Zhang) [Orabug: 39203117] - RDMA/core: Add driver APIs pre_destroy_cq() and post_destroy_cq() (Mark Zhang) [Orabug: 39203117] - mmc: sdhci-of-dwcmshc: Drop the use of sdhci_pltfm_free() (Binbin Zhou) [Orabug: 39203117] - selftests: drv-net: import things in lib one by one (Jakub Kicinski) [Orabug: 39203117] - netdevsim: fix UaF when counting Tx stats (Jakub Kicinski) [Orabug: 39203117] - eth: mlx5: migrate to new RXFH callbacks (Jakub Kicinski) [Orabug: 39203117] - netdevsim: account dropped packet length in stats on queue free (Breno Leitao) [Orabug: 39203117] - net: add dev_dstats_rx_dropped_add() helper (Breno Leitao) [Orabug: 39203117] - netdevsim: collect statistics at RX side (Breno Leitao) [Orabug: 39203117] - netdevsim: migrate to dstats stats collection (Breno Leitao) [Orabug: 39203117] - net/mlx4_en: Remove the redundant NULL check for the 'my_ets' object (Andrey Vatoropin) [Orabug: 39203117] - netdevsim: remove udp_ports_sleep (Stanislav Fomichev) [Orabug: 39203117] - net/mlx4e: Don't redefine IB_MTU_XXX enum (Mark Zhang) [Orabug: 39203117] - pinctrl: Constify static 'pinctrl_desc' (Krzysztof Kozlowski) [Orabug: 39203117] - pinctrl: Constify pointers to 'pinctrl_desc' (Krzysztof Kozlowski) [Orabug: 39203117] - pinctrl: amd: Constify pointers to 'pinctrl_desc' (Krzysztof Kozlowski) [Orabug: 39203117] - net/mlx5e: Add TX support for netmems (Dragos Tatulea) [Orabug: 39203117] - net/mlx5e: Support ethtool tcp-data-split settings (Saeed Mahameed) [Orabug: 39203117] - net/mlx5e: Implement queue mgmt ops and single channel swap (Saeed Mahameed) [Orabug: 39203117] - net/mlx5e: Add support for UNREADABLE netmem page pools (Saeed Mahameed) [Orabug: 39203117] - net/mlx5e: Convert over to netmem (Saeed Mahameed) [Orabug: 39203117] - net/mlx5e: SHAMPO: Separate pool for headers (Saeed Mahameed) [Orabug: 39203117] - net/mlx5e: SHAMPO: Improve hw gro capability checking (Saeed Mahameed) [Orabug: 39203117] - net/mlx5e: SHAMPO: Remove redundant params (Saeed Mahameed) [Orabug: 39203117] - net/mlx5e: SHAMPO: Reorganize mlx5_rq_shampo_alloc (Saeed Mahameed) [Orabug: 39203117] - page_pool: Add page_pool_dev_alloc_netmems helper (Dragos Tatulea) [Orabug: 39203117] - net: Add skb_can_coalesce for netmem (Dragos Tatulea) [Orabug: 39203117] - net: Allow const args for of page_to_netmem() (Dragos Tatulea) [Orabug: 39203117] - selftests: forwarding: Add a test for verifying VXLAN MC underlay (Petr Machata) [Orabug: 39203117] - netmem: fix netmem comments (Mina Almasry) [Orabug: 39203117] - selftests: net: add netconsole test for cmdline configuration (Breno Leitao) [Orabug: 39203117] - net: ethtool: add dedicated callbacks for getting and setting rxfh fields (Jakub Kicinski) [Orabug: 39203117] - net: ethtool: require drivers to opt into the per-RSS ctx RXFH (Jakub Kicinski) [Orabug: 39203117] - net: ethtool: remove the duplicated handling from rxfh and rxnfc (Jakub Kicinski) [Orabug: 39203117] - net: ethtool: copy the rxfh flow handling (Jakub Kicinski) [Orabug: 39203117] - net: ethtool: Don't check if RSS context exists in case of context 0 (Gal Pressman) [Orabug: 39203117] - net/mlx5: Expose serial numbers in devlink info (Jiri Pirko) [Orabug: 39203117] - selftests: netconsole: Add support for basic netconsole target format (Breno Leitao) [Orabug: 39203117] - selftests: netconsole: Do not exit from inside the validation function (Breno Leitao) [Orabug: 39203117] - page_pool: fix ugly page_pool formatting (Mina Almasry) [Orabug: 39203117] - net/mlx5e: Convert mlx5 netdevs to instance locking (Cosmin Ratiu) [Orabug: 39203117] - net: Add support for providing the PTP hardware source in tsinfo (Kory Maincent) [Orabug: 39203117] - selftests: drv-net: Fix 'envirnoments' to 'environments' (Sumanth Gavini) [Orabug: 39203117] - net: enable driver support for netmem TX (Mina Almasry) [Orabug: 39203117] - net: add get_netmem/put_netmem support (Mina Almasry) [Orabug: 39203117] - netmem: add niov-type attribute to distinguish different net_iov types (Mina Almasry) [Orabug: 39203117] - selftests: drv-net: ping: make sure the ping test restores checksum offload (Jakub Kicinski) [Orabug: 39203117] - ethtool: Block setting of symmetric RSS when non-symmetric rx-flow-hash is requested (Gal Pressman) [Orabug: 39203117] - pinctrl: mediatek: airoha: use new GPIO line value setter callbacks (Bartosz Golaszewski) [Orabug: 39203117] - selftests: net-drv: remove the nic_performance and nic_link_layer tests (Jakub Kicinski) [Orabug: 39203117] - devlink: define enum for attr types of dynamic attributes (Jiri Pirko) [Orabug: 39203117] - selftests: net: exit cleanly on SIGTERM / timeout (Jakub Kicinski) [Orabug: 39203117] - selftests: drv: net: add version indicator (Mohsin Bashir) [Orabug: 39203117] - selftests: drv: net: avoid skipping tests (Mohsin Bashir) [Orabug: 39203117] - selftests: drv: net: fix test failure on ipv6 sys (Mohsin Bashir) [Orabug: 39203117] - selftests: drv-net: rss_input_xfrm: Check test prerequisites before running (Gal Pressman) [Orabug: 39203117] - selftests: net: add a virtio_net deadlock selftest (Bui Quang Minh) [Orabug: 39203117] - selftests: net: move xdp_helper to net/lib (Bui Quang Minh) [Orabug: 39203117] - selftests: drv-net: Test that NAPI ID is non-zero (Joe Damato) [Orabug: 39203117] - pinctrl: airoha: fix wrong PHY LED mapping and PHY2 LED defines (Christian Marangi) [Orabug: 39203117] - netlink: specs: rename rtnetlink specs in accordance with family name (Jakub Kicinski) [Orabug: 39203117] - pinctrl: amd: Add an LPS0 check() callback (Mario Limonciello) [Orabug: 39203117] - selftests: drv-net: test random value for hds-thresh (Taehee Yoo) [Orabug: 39203117] - selftests: net: use Path helpers in ping (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: replace the rpath helper with Path objects (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: use defer in the ping test (Jakub Kicinski) [Orabug: 39203117] - net: skbuff: Remove unused skb_add_data() (Yue Haibing) [Orabug: 39203117] - selftests: drv-net: fix merge conflicts resolution (Matthieu Baerts) [Orabug: 39203117] - selftests: drv-net: add xdp cases for ping.py (Taehee Yoo) [Orabug: 39203117] - selftests: drv-net: use env.rpath in the HDS test (Jakub Kicinski) [Orabug: 39203117] - selftests: net: report output format as TAP 13 in Python tests (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: add tests for napi IRQ affinity notifiers (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net-hw: Add a test for symmetric RSS hash (Gal Pressman) [Orabug: 39203117] - selftests: drv-net: Make rand_port() get a port more reliably (Gal Pressman) [Orabug: 39203117] - selftests: drv-net: test XDP, HDS auto and the ioctl path (Jakub Kicinski) [Orabug: 39203117] - net: ethtool: fix ioctl confusing drivers about desired HDS user config (Jakub Kicinski) [Orabug: 39203117] - netlink: specs: Add FIB rule DSCP mask attribute (Ido Schimmel) [Orabug: 39203117] - selftests: net: Add python context manager for netns entering (Xiao Liang) [Orabug: 39203117] - selftests: drv-net: rename queues check_xdp to check_xsk (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: improve the use of ksft helpers in XSK queue test (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: add a way to wait for a local process (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: probe for AF_XDP sockets more explicitly (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: add missing new line in xdp_helper (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: use cfg.rpath() in netlink xsk attr test (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: add a warning for bkg + shell + terminate (Jakub Kicinski) [Orabug: 39203117] - net: ngbe: Add support for 1PPS and TOD (Jiawen Wu) [Orabug: 39203117] - net: wangxun: Add periodic checks for overflow and errors (Jiawen Wu) [Orabug: 39203117] - net: wangxun: Add support for PTP clock (Jiawen Wu) [Orabug: 39203117] - selftests: drv-net: add a simple TSO test (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: store addresses in dict indexed by ipver (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: get detailed interface info (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: resolve remote interface name (Jakub Kicinski) [Orabug: 39203117] - netlink: specs: Add FIB rule port mask attributes (Ido Schimmel) [Orabug: 39203117] - net: move stale comment about ntuple validation (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: Test queue xsk attribute (Joe Damato) [Orabug: 39203117] - io_uring/zcrx: add selftest (David Wei) [Orabug: 39203117] - selftests/net: Add selftest for IPv4 RTM_GETMULTICAST support (Yuyang Huang) [Orabug: 39203117] - selftests: drv-net: add helper for path resolution (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: factor out a DrvEnv base class (Jakub Kicinski) [Orabug: 39203117] - net: ethtool: prevent flow steering to RSS contexts which don't exist (Jakub Kicinski) [Orabug: 39203117] - netconsole: selftest: test for sysdata CPU (Breno Leitao) [Orabug: 39203117] - netconsole: selftest: Add test for fragmented messages (Breno Leitao) [Orabug: 39203117] - net: provide pending ring configuration in net_device (Jakub Kicinski) [Orabug: 39203117] - net: ethtool: store netdev in a temp variable in ethnl_default_set_doit() (Jakub Kicinski) [Orabug: 39203117] - net: move HDS config from ethtool state (Jakub Kicinski) [Orabug: 39203117] - selftest: net-drv: hds: add test for HDS feature (Taehee Yoo) [Orabug: 39203117] - netdevsim: add HDS feature (Taehee Yoo) [Orabug: 39203117] - bnxt_en: add support for hds-thresh ethtool command (Taehee Yoo) [Orabug: 39203117] - bnxt_en: add support for tcp-data-split ethtool command (Taehee Yoo) [Orabug: 39203117] - bnxt_en: add support for rx-copybreak ethtool command (Taehee Yoo) [Orabug: 39203117] - net: ethtool: add ring parameter filtering (Taehee Yoo) [Orabug: 39203117] - net: devmem: add ring parameter filtering (Taehee Yoo) [Orabug: 39203117] - net: ethtool: add support for configuring hds-thresh (Taehee Yoo) [Orabug: 39203117] - netconsole: selftest: verify userdata entry limit (Breno Leitao) [Orabug: 39203117] - netconsole: selftest: Split the helpers from the selftest (Breno Leitao) [Orabug: 39203117] - tools: ynl: move python code to separate sub-directory (Jan Stancek) [Orabug: 39203117] - netdevsim: add debugfs-triggered queue reset (Jakub Kicinski) [Orabug: 39203117] - netdev: define NETDEV_INTERNAL (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: test drivers sleeping in ndo_get_stats64 (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: assume stats refresh is 0 if no ethtool -c support (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: test empty queue and NAPI responses in netlink (Jakub Kicinski) [Orabug: 39203117] - page_pool: add page_pool_dev_alloc_netmem() (Alexander Lobakin) [Orabug: 39203117] - net: Document netmem driver support (Mina Almasry) [Orabug: 39203117] - netlink: specs: Add FIB rule flow label attributes (Ido Schimmel) [Orabug: 39203117] - selftests: net-drv: stats: sanity check netlink dumps (Jakub Kicinski) [Orabug: 39203117] - selftests: net-drv: queues: sanity check netlink dumps (Jakub Kicinski) [Orabug: 39203117] - selftests: net: support setting recv_size in YNL (Jakub Kicinski) [Orabug: 39203117] - net: ethtool: Add support for tsconfig command to get/set hwtstamp config (Kory Maincent) [Orabug: 39203117] - net: ethtool: tsinfo: Enhance tsinfo to support several hwtstamp by net topology (Kory Maincent) [Orabug: 39203117] - net: Add the possibility to support a selected hwtstamp in netdevice (Kory Maincent) [Orabug: 39203117] - net: Make net_hwtstamp_validate accessible (Kory Maincent) [Orabug: 39203117] - net: Make dev_get_hwtstamp_phylib accessible (Kory Maincent) [Orabug: 39203117] - page_pool: allow mixing PPs within one bulk (Alexander Lobakin) [Orabug: 39203117] - vrf: Make pcpu_dstats update functions available to other modules. (Guillaume Nault) [Orabug: 39203117] - page_pool: make page_pool_put_page_bulk() handle array of netmems (Alexander Lobakin) [Orabug: 39203117] - netmem: add a couple of page helper wrappers (Alexander Lobakin) [Orabug: 39203117] - xsk: allow attaching XSk pool via xdp_rxq_info_reg_mem_model() (Alexander Lobakin) [Orabug: 39203117] - xdp, xsk: constify read-only arguments of some static inline helpers (Alexander Lobakin) [Orabug: 39203117] - ethtool: regenerate uapi header from the spec (Stanislav Fomichev) [Orabug: 39203117] - ethtool: remove the comments that are not gonna be generated (Stanislav Fomichev) [Orabug: 39203117] - ethtool: separate definitions that are gonna be generated (Stanislav Fomichev) [Orabug: 39203117] - ynl: add missing pieces to ethtool spec to better match uapi header (Stanislav Fomichev) [Orabug: 39203117] - selftests: fix nested double quotes in f-string (David Wei) [Orabug: 39203117] - selftests: nic_performance: Add selftest for performance of NIC driver (Mohan Prasad J) [Orabug: 39203117] - selftests: nic_link_layer: Add selftest case for speed and duplex states (Mohan Prasad J) [Orabug: 39203117] - selftests: nic_link_layer: Add link layer selftest for NIC driver (Mohan Prasad J) [Orabug: 39203117] - pinctrl: airoha: Use unsigned long for bit search (Kees Cook) [Orabug: 39203117] - net: netconsole: selftests: Check if netdevsim is available (Breno Leitao) [Orabug: 39203117] - docs: networking: Describe irq suspension (Joe Damato) [Orabug: 39203117] - selftests: ncdevmem: Add automated test (Stanislav Fomichev) [Orabug: 39203117] - selftests: ncdevmem: Move ncdevmem under drivers/net/hw (Stanislav Fomichev) [Orabug: 39203117] - selftests: ncdevmem: Use YNL to enable TCP header split (Stanislav Fomichev) [Orabug: 39203117] - selftests: ncdevmem: Properly reset flow steering (Stanislav Fomichev) [Orabug: 39203117] - selftests: ncdevmem: Remove default arguments (Stanislav Fomichev) [Orabug: 39203117] - netlink: specs: Add a spec for FIB rule management (Donald Hunter) [Orabug: 39203117] - netlink: specs: Add a spec for neighbor tables in rtnetlink (Donald Hunter) [Orabug: 39203117] - net: netconsole: selftests: Add userdata validation (Breno Leitao) [Orabug: 39203117] - net: netconsole: selftests: Change the IP subnet (Breno Leitao) [Orabug: 39203117] - pinctrl: airoha: Add support for EN7581 SoC (Lorenzo Bianconi) [Orabug: 39203117] - Documentation: networking: Add missing PHY_GET command in the message list (Kory Maincent) [Orabug: 39203117] - netlink: specs: Add missing phy-ntf command to ethtool spec (Kory Maincent) [Orabug: 39203117] - selftests: net: lib: Introduce deferred commands (Petr Machata) [Orabug: 39203117] - ethtool: rss: prevent rss ctx deletion when in use (Daniel Zahka) [Orabug: 39203117] - selftests: net: move EXTRA_CLEAN of libynl.a into ynl.mk (Jakub Kicinski) [Orabug: 39203117] - selftests: net: rebuild YNL if dependencies changed (Jakub Kicinski) [Orabug: 39203117] - selftests: drv-net: add missing trailing backslash (Jakub Kicinski) [Orabug: 39203117] - pinctrl: amd: Fix two small typos (Marc Ferland) [Orabug: 39203117] - pinctrl: Switch back to struct platform_driver::remove() (Uwe Kleine-Konig) [Orabug: 39203117] - pinctrl: qcom: add the tlmm driver for QCS615 platform (Lijuan Gao) [Orabug: 39203117] - net: tap: set skb-dev before parsing virtio net header in tap_get_user_xdp() (Dongli Zhang) [Orabug: 39558732] {CVE-2026-74684} - uek-rpm: enable Nexthop SONiC drivers for ONOS (Vijay Kumar) [Orabug: 39597630] - platform: nexthop-sonic: add SONiC platform drivers (Vijay Kumar) [Orabug: 39597630] - uek-rpm/modules.yaml.S.onos: Package PDDF platform drivers (Darren Kenny) [Orabug: 39597630] - uek-rpm/config-x86_64-onos: Enable PDDF platform driver configs (Vijay Kumar) [Orabug: 39597630] - platform: Port SONiC PDDF drivers (Test Com) [Orabug: 39597630] - rds: tcp: fix uninit-value in __inet_bind (Tabrez Ahmed) [Orabug: 39668598] - rds: tcp: cleanup if kmem_cache_alloc fails in rds_tcp_conn_alloc() (Sowmini Varadhan) [Orabug: 39668598] - eeprom: optoe: set clientdata before publishing sysfs files (Vijay Kumar) [Orabug: 39721366] - eeprom: optoe: remove eeprom bin file on sysfs_create_group failure (Vijay Kumar) [Orabug: 39721366] - eeprom: optoe: fix heap OOB write from stale writebuf sizing (Vijay Kumar) [Orabug: 39721366] - arista-sonic: raven-fan-driver: read fan ID pins at correct offsets (Vijay Kumar) [Orabug: 39721366] - arista-sonic: scd: check parse result in scd_set_debug (Vijay Kumar) [Orabug: 39721366] - arista-sonic: scd: restrict /proc/scd to root-only read (Vijay Kumar) [Orabug: 39721366] - arista-sonic: fan-cpld: don't hold cpld-lock across work cancel on remove (Vijay Kumar) [Orabug: 39721366] - arista-sonic: minke-fan-cpld: fix uninitialised cpld deref in probe error path (Vijay Kumar) [Orabug: 39721366] - arista-sonic: tmp468: fix out-of-bounds read of names[] in probe (Vijay Kumar) [Orabug: 39721366] - arista-sonic: scd-mdio: fix mdiobus_free(NULL) and mii_bus leak on error (Vijay Kumar) [Orabug: 39721366] - arista-sonic: scd: enforce register offset bound instead of advisory ASSERT (Vijay Kumar) [Orabug: 39721366] - arista-sonic: scd: overflow-safe range check in scd_lpc_mmap_resource (Vijay Kumar) [Orabug: 39721366] - arista-sonic: rook-fan-cpld: only unregister LEDs that were registered (Vijay Kumar) [Orabug: 39721366] - arista-sonic: minke-fan-cpld: unregister slot_count LEDs, not fan_count (Vijay Kumar) [Orabug: 39721366] - arista-sonic: scd: fix SPI controller devdata UAF and invalid kfree (Vijay Kumar) [Orabug: 39721366] - arista-sonic: scd: don't panic on over-long xcvr attribute name (Vijay Kumar) [Orabug: 39721366] - arista-sonic: scd: remove partial xcvr sysfs attrs before freeing on error (Vijay Kumar) [Orabug: 39721366] - arista-sonic: scd: init master-list before the master-add error path (Vijay Kumar) [Orabug: 39721366] - arista-sonic: scd: use strscpy for LED name to guarantee NUL termination (Vijay Kumar) [Orabug: 39721366] - arista-sonic: scd: bound fan_count against speed_*_steps[] arrays (Vijay Kumar) [Orabug: 39721366] - arista-sonic: scd: bound derived MMIO offsets in master/port add paths (Vijay Kumar) [Orabug: 39721366] - arista-sonic: scd: fix user-controlled format string in gpio/reset add (Vijay Kumar) [Orabug: 39721366] - src: handle ioremap error in raven-fan-driver (Arista-Hpandya) [Orabug: 39721366] - Replace sprintf with sysfs_emit in sysfs show callbacks (Arista-Hpandya) [Orabug: 39721366] - scd: add sysfs knob to control watchdog panic (Mohan Yelugoti) [Orabug: 39721366] - scd: update scd driver to EOS latest (Mohan Yelugoti) [Orabug: 39721366] - platform: remove old tricolor LED handling (Justin Oliver) [Orabug: 39721366] - scd: add bus_speed attribute to i2c buses (Samuel Angebault) [Orabug: 39721366] - Modify arista-drivers for arm64 compilation. (Vivek Kumar Verma) [Orabug: 39721366] - minke-fan-cpld: seperate slot and fan initialization in cpld_init (Arista-Hpandya) [Orabug: 39721366] - x86/bugs: Make Safe-RET robust against interrupt injection (Borislav Petkov) [Orabug: 39784619,39853774] {CVE-2026-68480} - net/rds: harden rds_rm_size (Manjunath Patil) [Orabug: 39812332] - KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Sean Christopherson) [Orabug: 39830589,39832725,39832878,39844799] {CVE-2026-64561} - net/rds: remove cached rds_sock-rs_conn and rs_conn_path (Sharath Srinivasan) [Orabug: 39832353] - Revert 'rds: cong: Make rds_cong_wait an array to reduce lock contention' (Sharath Srinivasan) [Orabug: 39832353] [6.12.0-206.100.2] - afs: Fix lack of locking around modifications of net-cells_dyn_ino (David Howells) {CVE-2026-72372} - afs: Fix dynamic lookup to fail on cell lookup failure (David Howells) - afs: Simplify cell record handling (David Howells) - afs: Fix afs_server ref accounting (David Howells) - afs: Use the per-peer app data provided by rxrpc (David Howells) - rxrpc: Allow the app to store private data on peer structs (David Howells) - afs: Drop the net parameter from afs_unuse_cell() (David Howells) - afs: Make afs_lookup_cell() take a trace note (David Howells) - afs: Improve server refcount/active count tracing (David Howells) - Bluetooth: hci_core: Fix not accounting for BIS/CIS/PA links separately (Luiz Augusto von Dentz) - Bluetooth: Add PA_LINK to distinguish BIG sync and PA sync connections (Yang Li) - net: qrtr: ns: Raise node count limit to 512 (Youssef Samir) - drm/amd/pm: fix smu13 power limit range calculation (Yang Wang) - ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL (Guan Wentao) {CVE-2026-68099} - ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl (Haofeng Li) {CVE-2026-68100} - vsock/virtio: collapse receive queue under memory pressure (Stefano Garzarella) - proc: Fix broken error paths for namespace links (Jann Horn) - serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (Jiangshan Yi) [Orabug: 39868564] {CVE-2026-68434} - drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) (Timur Kristof) - Revert 'drm/amd/display: Add missing kdoc for ALLM parameters' (Sasha Levin) - usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect (Diego Fernando Mancera Gomez) [Orabug: 39860411] {CVE-2026-68344} - net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets() (Lorenzo Bianconi) - udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf() (Robert Mader) - wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (Peddolla Harshavardhan Reddy) [Orabug: 39860409] {CVE-2026-68408} - wifi: cfg80211: define and use wiphy guard (Johannes Berg) - wifi: cfg80211: pass net_device to .set_monitor_channel (Felix Fietkau) - firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits (Seth Forshee) - Revert 'arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc' (Sasha Levin) - net: airoha: Fix skb-priority underflow in airoha_dev_select_queue() (Wayen Yan) - LTS version: v6.12.100 (Sherry Yang) - posix-cpu-timers: Prevent UAF caused by non-leader exec() race (Thomas Gleixner) [Orabug: 39807437] {CVE-2026-64560} - LTS version: v6.12.99 (Sherry Yang) - mm: refactor mm_access() to not return NULL (Lorenzo Stoakes) - LTS version: v6.12.98 (Sherry Yang) - ext4: fix fd leak in EXT4_IOC_MOVE_EXT cross-sb validation (Yun Zhou) - LTS version: v6.12.97 (Sherry Yang) - selftests/bpf: Add simple strscpy() implementation (Ihor Solodrai) - tools/testing: add linux/args.h header and fix radix, VMA tests (Lorenzo Stoakes) - dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() (Ivan Vecera) [Orabug: 39860212] {CVE-2026-68378} - Bluetooth: L2CAP: fix tx ident leak for commands without a response (Stig Hornang) {CVE-2026-72333} - Bluetooth: 6lowpan: Fix using chan-conn as indication to no remote netdev (Luiz Augusto von Dentz) - Bluetooth: L2CAP: Fix regressions caused by reusing ident (Luiz Augusto von Dentz) - crypto: ccp - Fix leaking the same page twice (Guenter Roeck) - ice: drop udp_tunnel_get_rx_info() call from ndo_open() (Mohammad Heib) - i40e: drop udp_tunnel_get_rx_info() call from i40e_open() (Mohammad Heib) - crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked() (Borislav Petkov) [Orabug: 39838809] {CVE-2025-39936} - Bluetooth: hci_sync: Fix attempting to send HCI_Disconnect to BIS handle (Luiz Augusto von Dentz) - Bluetooth: hci_core: Remove check of BDADDR_ANY in hci_conn_hash_lookup_big_state (Luiz Augusto von Dentz) - udp_tunnel: fix deadlock in udp_tunnel_nic_set_port_priv() (Paolo Abeni) - crypto: ccp - Fix SNP panic notifier unregistration (Ashish Kalra) - crypto: ccp - Fix dereferencing uninitialized error pointer (Ashish Kalra) [Orabug: 39838818] {CVE-2025-39729} - crypto: ccp - Fix __sev_snp_shutdown_locked (Ashish Kalra) - afs: Fix afs_dynroot_readdir() to not use the RCU read lock (David Howells) - afs: Fix afs_atcell_get_link() to check if ws_cell is unset first (David Howells) - net: airoha: Fix channel configuration for ETS Qdisc (Lorenzo Bianconi) - rtnetlink: Make per-netns RTNL dereference helpers to macro. (Kuniyuki Iwashima) - ksmbd: fix durable reconnect double-bind race in ksmbd_reopen_durable_fd (Gil Portnoy) - seqlock: fix scoped_seqlock_read kernel-doc (Randy Dunlap) - dibs: loopback: validate offset and size in move_data() (Dust Li) {CVE-2026-72018} - perf/x86/amd/brs: Fix kernel address leakage (Sandipan Das) {CVE-2026-72237} ...
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
No references available.
No linked vulnerabilities found.
{
"cves": [
"CVE-2025-10263",
"CVE-2025-21807",
"CVE-2025-23131",
"CVE-2025-38525",
"CVE-2025-39729",
"CVE-2025-39936",
"CVE-2025-68299",
"CVE-2025-68768",
"CVE-2026-23247",
"CVE-2026-31419",
"CVE-2026-31732",
"CVE-2026-43010",
"CVE-2026-43116",
"CVE-2026-43197",
"CVE-2026-43216",
"CVE-2026-43303",
"CVE-2026-45850",
"CVE-2026-45897",
"CVE-2026-45901",
"CVE-2026-45907",
"CVE-2026-45944",
"CVE-2026-46054",
"CVE-2026-46093",
"CVE-2026-46252",
"CVE-2026-52908",
"CVE-2026-52909",
"CVE-2026-52910",
"CVE-2026-52917",
"CVE-2026-52923",
"CVE-2026-52924",
"CVE-2026-52927",
"CVE-2026-52929",
"CVE-2026-52930",
"CVE-2026-52934",
"CVE-2026-52942",
"CVE-2026-52946",
"CVE-2026-52947",
"CVE-2026-52948",
"CVE-2026-52975",
"CVE-2026-52995",
"CVE-2026-53005",
"CVE-2026-53078",
"CVE-2026-53090",
"CVE-2026-53101",
"CVE-2026-53131",
"CVE-2026-53132",
"CVE-2026-53134",
"CVE-2026-53135",
"CVE-2026-53136",
"CVE-2026-53137",
"CVE-2026-53138",
"CVE-2026-53142",
"CVE-2026-53143",
"CVE-2026-53144",
"CVE-2026-53146",
"CVE-2026-53147",
"CVE-2026-53148",
"CVE-2026-53149",
"CVE-2026-53150",
"CVE-2026-53151",
"CVE-2026-53154",
"CVE-2026-53156",
"CVE-2026-53167",
"CVE-2026-53168",
"CVE-2026-53175",
"CVE-2026-53176",
"CVE-2026-53177",
"CVE-2026-53180",
"CVE-2026-53181",
"CVE-2026-53182",
"CVE-2026-53183",
"CVE-2026-53184",
"CVE-2026-53185",
"CVE-2026-53186",
"CVE-2026-53189",
"CVE-2026-53190",
"CVE-2026-53191",
"CVE-2026-53192",
"CVE-2026-53193",
"CVE-2026-53194",
"CVE-2026-53195",
"CVE-2026-53196",
"CVE-2026-53199",
"CVE-2026-53207",
"CVE-2026-53208",
"CVE-2026-53209",
"CVE-2026-53210",
"CVE-2026-53212",
"CVE-2026-53213",
"CVE-2026-53214",
"CVE-2026-53215",
"CVE-2026-53216",
"CVE-2026-53217",
"CVE-2026-53218",
"CVE-2026-53219",
"CVE-2026-53220",
"CVE-2026-53221",
"CVE-2026-53223",
"CVE-2026-53225",
"CVE-2026-53226",
"CVE-2026-53227",
"CVE-2026-53228",
"CVE-2026-53229",
"CVE-2026-53230",
"CVE-2026-53232",
"CVE-2026-53233",
"CVE-2026-53235",
"CVE-2026-53236",
"CVE-2026-53237",
"CVE-2026-53238",
"CVE-2026-53239",
"CVE-2026-53241",
"CVE-2026-53245",
"CVE-2026-53249",
"CVE-2026-53251",
"CVE-2026-53252",
"CVE-2026-53253",
"CVE-2026-53254",
"CVE-2026-53255",
"CVE-2026-53256",
"CVE-2026-53260",
"CVE-2026-53261",
"CVE-2026-53262",
"CVE-2026-53263",
"CVE-2026-53264",
"CVE-2026-53266",
"CVE-2026-53267",
"CVE-2026-53268",
"CVE-2026-53269",
"CVE-2026-53270",
"CVE-2026-53272",
"CVE-2026-53273",
"CVE-2026-53275",
"CVE-2026-53325",
"CVE-2026-53328",
"CVE-2026-53329",
"CVE-2026-53337",
"CVE-2026-53341",
"CVE-2026-53345",
"CVE-2026-53347",
"CVE-2026-53349",
"CVE-2026-53350",
"CVE-2026-53352",
"CVE-2026-53353",
"CVE-2026-53354",
"CVE-2026-53356",
"CVE-2026-53358",
"CVE-2026-53360",
"CVE-2026-53361",
"CVE-2026-53364",
"CVE-2026-53365",
"CVE-2026-53381",
"CVE-2026-53384",
"CVE-2026-53385",
"CVE-2026-53388",
"CVE-2026-53391",
"CVE-2026-53392",
"CVE-2026-53393",
"CVE-2026-53394",
"CVE-2026-53397",
"CVE-2026-53398",
"CVE-2026-53399",
"CVE-2026-53400",
"CVE-2026-53402",
"CVE-2026-53403",
"CVE-2026-63794",
"CVE-2026-63795",
"CVE-2026-63796",
"CVE-2026-63800",
"CVE-2026-63801",
"CVE-2026-63802",
"CVE-2026-63803",
"CVE-2026-63804",
"CVE-2026-63806",
"CVE-2026-63807",
"CVE-2026-63808",
"CVE-2026-63809",
"CVE-2026-63810",
"CVE-2026-63821",
"CVE-2026-63822",
"CVE-2026-63823",
"CVE-2026-63824",
"CVE-2026-63826",
"CVE-2026-63829",
"CVE-2026-63830",
"CVE-2026-63831",
"CVE-2026-63834",
"CVE-2026-63835",
"CVE-2026-63836",
"CVE-2026-63867",
"CVE-2026-63868",
"CVE-2026-63869",
"CVE-2026-63870",
"CVE-2026-63871",
"CVE-2026-63875",
"CVE-2026-63881",
"CVE-2026-63882",
"CVE-2026-63884",
"CVE-2026-63891",
"CVE-2026-63892",
"CVE-2026-63893",
"CVE-2026-63897",
"CVE-2026-63898",
"CVE-2026-63899",
"CVE-2026-63900",
"CVE-2026-63901",
"CVE-2026-63902",
"CVE-2026-63903",
"CVE-2026-63904",
"CVE-2026-63908",
"CVE-2026-63912",
"CVE-2026-63913",
"CVE-2026-63914",
"CVE-2026-63916",
"CVE-2026-63917",
"CVE-2026-63918",
"CVE-2026-63919",
"CVE-2026-63920",
"CVE-2026-63921",
"CVE-2026-63922",
"CVE-2026-63924",
"CVE-2026-63925",
"CVE-2026-63926",
"CVE-2026-63927",
"CVE-2026-63928",
"CVE-2026-63929",
"CVE-2026-63937",
"CVE-2026-63938",
"CVE-2026-63939",
"CVE-2026-63940",
"CVE-2026-63942",
"CVE-2026-63944",
"CVE-2026-63945",
"CVE-2026-63946",
"CVE-2026-63947",
"CVE-2026-63948",
"CVE-2026-63949",
"CVE-2026-63952",
"CVE-2026-63956",
"CVE-2026-63957",
"CVE-2026-63958",
"CVE-2026-63961",
"CVE-2026-63962",
"CVE-2026-63963",
"CVE-2026-63968",
"CVE-2026-63969",
"CVE-2026-63970",
"CVE-2026-63971",
"CVE-2026-63973",
"CVE-2026-63974",
"CVE-2026-63975",
"CVE-2026-63976",
"CVE-2026-63978",
"CVE-2026-63980",
"CVE-2026-63981",
"CVE-2026-63982",
"CVE-2026-63983",
"CVE-2026-63984",
"CVE-2026-63985",
"CVE-2026-63987",
"CVE-2026-63990",
"CVE-2026-63992",
"CVE-2026-63993",
"CVE-2026-63994",
"CVE-2026-63995",
"CVE-2026-63996",
"CVE-2026-63997",
"CVE-2026-64000",
"CVE-2026-64002",
"CVE-2026-64003",
"CVE-2026-64007",
"CVE-2026-64009",
"CVE-2026-64012",
"CVE-2026-64014",
"CVE-2026-64090",
"CVE-2026-64091",
"CVE-2026-64093",
"CVE-2026-64094",
"CVE-2026-64095",
"CVE-2026-64122",
"CVE-2026-64123",
"CVE-2026-64131",
"CVE-2026-64187",
"CVE-2026-64189",
"CVE-2026-64191",
"CVE-2026-64192",
"CVE-2026-64205",
"CVE-2026-64206",
"CVE-2026-64227",
"CVE-2026-64235",
"CVE-2026-64237",
"CVE-2026-64239",
"CVE-2026-64241",
"CVE-2026-64244",
"CVE-2026-64245",
"CVE-2026-64247",
"CVE-2026-64251",
"CVE-2026-64253",
"CVE-2026-64256",
"CVE-2026-64257",
"CVE-2026-64265",
"CVE-2026-64266",
"CVE-2026-64270",
"CVE-2026-64271",
"CVE-2026-64272",
"CVE-2026-64275",
"CVE-2026-64276",
"CVE-2026-64279",
"CVE-2026-64284",
"CVE-2026-64286",
"CVE-2026-64287",
"CVE-2026-64289",
"CVE-2026-64294",
"CVE-2026-64296",
"CVE-2026-64298",
"CVE-2026-64299",
"CVE-2026-64304",
"CVE-2026-64305",
"CVE-2026-64306",
"CVE-2026-64307",
"CVE-2026-64308",
"CVE-2026-64309",
"CVE-2026-64310",
"CVE-2026-64312",
"CVE-2026-64313",
"CVE-2026-64317",
"CVE-2026-64319",
"CVE-2026-64320",
"CVE-2026-64321",
"CVE-2026-64322",
"CVE-2026-64323",
"CVE-2026-64324",
"CVE-2026-64326",
"CVE-2026-64330",
"CVE-2026-64332",
"CVE-2026-64333",
"CVE-2026-64334",
"CVE-2026-64335",
"CVE-2026-64336",
"CVE-2026-64338",
"CVE-2026-64340",
"CVE-2026-64341",
"CVE-2026-64342",
"CVE-2026-64343",
"CVE-2026-64344",
"CVE-2026-64348",
"CVE-2026-64351",
"CVE-2026-64352",
"CVE-2026-64354",
"CVE-2026-64355",
"CVE-2026-64357",
"CVE-2026-64362",
"CVE-2026-64363",
"CVE-2026-64364",
"CVE-2026-64365",
"CVE-2026-64368",
"CVE-2026-64370",
"CVE-2026-64371",
"CVE-2026-64372",
"CVE-2026-64373",
"CVE-2026-64374",
"CVE-2026-64375",
"CVE-2026-64376",
"CVE-2026-64378",
"CVE-2026-64379",
"CVE-2026-64380",
"CVE-2026-64381",
"CVE-2026-64382",
"CVE-2026-64383",
"CVE-2026-64384",
"CVE-2026-64385",
"CVE-2026-64386",
"CVE-2026-64387",
"CVE-2026-64401",
"CVE-2026-64403",
"CVE-2026-64404",
"CVE-2026-64405",
"CVE-2026-64406",
"CVE-2026-64408",
"CVE-2026-64411",
"CVE-2026-64412",
"CVE-2026-64413",
"CVE-2026-64414",
"CVE-2026-64415",
"CVE-2026-64416",
"CVE-2026-64418",
"CVE-2026-64420",
"CVE-2026-64422",
"CVE-2026-64423",
"CVE-2026-64424",
"CVE-2026-64425",
"CVE-2026-64427",
"CVE-2026-64433",
"CVE-2026-64434",
"CVE-2026-64435",
"CVE-2026-64436",
"CVE-2026-64438",
"CVE-2026-64448",
"CVE-2026-64450",
"CVE-2026-64452",
"CVE-2026-64455",
"CVE-2026-64456",
"CVE-2026-64457",
"CVE-2026-64458",
"CVE-2026-64461",
"CVE-2026-64465",
"CVE-2026-64470",
"CVE-2026-64471",
"CVE-2026-64472",
"CVE-2026-64473",
"CVE-2026-64474",
"CVE-2026-64475",
"CVE-2026-64476",
"CVE-2026-64477",
"CVE-2026-64478",
"CVE-2026-64479",
"CVE-2026-64480",
"CVE-2026-64481",
"CVE-2026-64484",
"CVE-2026-64486",
"CVE-2026-64487",
"CVE-2026-64489",
"CVE-2026-64490",
"CVE-2026-64496",
"CVE-2026-64503",
"CVE-2026-64504",
"CVE-2026-64508",
"CVE-2026-64510",
"CVE-2026-64511",
"CVE-2026-64512",
"CVE-2026-64514",
"CVE-2026-64523",
"CVE-2026-64524",
"CVE-2026-64527",
"CVE-2026-64528",
"CVE-2026-64529",
"CVE-2026-64530",
"CVE-2026-64531",
"CVE-2026-64534",
"CVE-2026-64535",
"CVE-2026-64538",
"CVE-2026-64539",
"CVE-2026-64540",
"CVE-2026-64542",
"CVE-2026-64543",
"CVE-2026-64544",
"CVE-2026-64545",
"CVE-2026-64546",
"CVE-2026-64547",
"CVE-2026-64548",
"CVE-2026-64549",
"CVE-2026-64551",
"CVE-2026-64552",
"CVE-2026-64553",
"CVE-2026-64554",
"CVE-2026-64555",
"CVE-2026-64556",
"CVE-2026-64557",
"CVE-2026-64560",
"CVE-2026-64561",
"CVE-2026-64562",
"CVE-2026-64563",
"CVE-2026-64564",
"CVE-2026-64567",
"CVE-2026-64568",
"CVE-2026-64569",
"CVE-2026-64570",
"CVE-2026-64571",
"CVE-2026-64572",
"CVE-2026-64574",
"CVE-2026-64575",
"CVE-2026-64576",
"CVE-2026-64577",
"CVE-2026-64579",
"CVE-2026-64580",
"CVE-2026-64582",
"CVE-2026-64586",
"CVE-2026-64589",
"CVE-2026-64593",
"CVE-2026-64597",
"CVE-2026-64598",
"CVE-2026-64599",
"CVE-2026-64600",
"CVE-2026-64603",
"CVE-2026-64604",
"CVE-2026-68085",
"CVE-2026-68091",
"CVE-2026-68092",
"CVE-2026-68093",
"CVE-2026-68096",
"CVE-2026-68102",
"CVE-2026-68106",
"CVE-2026-68107",
"CVE-2026-68108",
"CVE-2026-68110",
"CVE-2026-68111",
"CVE-2026-68112",
"CVE-2026-68113",
"CVE-2026-68115",
"CVE-2026-68116",
"CVE-2026-68117",
"CVE-2026-68118",
"CVE-2026-68119",
"CVE-2026-68121",
"CVE-2026-68123",
"CVE-2026-68125",
"CVE-2026-68126",
"CVE-2026-68128",
"CVE-2026-68129",
"CVE-2026-68131",
"CVE-2026-68133",
"CVE-2026-68136",
"CVE-2026-68138",
"CVE-2026-68139",
"CVE-2026-68142",
"CVE-2026-68143",
"CVE-2026-68145",
"CVE-2026-68146",
"CVE-2026-68148",
"CVE-2026-68149",
"CVE-2026-68153",
"CVE-2026-68154",
"CVE-2026-68155",
"CVE-2026-68156",
"CVE-2026-68157",
"CVE-2026-68158",
"CVE-2026-68160",
"CVE-2026-68161",
"CVE-2026-68162",
"CVE-2026-68164",
"CVE-2026-68165",
"CVE-2026-68166",
"CVE-2026-68169",
"CVE-2026-68180",
"CVE-2026-68181",
"CVE-2026-68184",
"CVE-2026-68186",
"CVE-2026-68187",
"CVE-2026-68188",
"CVE-2026-68189",
"CVE-2026-68192",
"CVE-2026-68193",
"CVE-2026-68194",
"CVE-2026-68197",
"CVE-2026-68198",
"CVE-2026-68199",
"CVE-2026-68200",
"CVE-2026-68201",
"CVE-2026-68202",
"CVE-2026-68205",
"CVE-2026-68206",
"CVE-2026-68212",
"CVE-2026-68213",
"CVE-2026-68214",
"CVE-2026-68216",
"CVE-2026-68217",
"CVE-2026-68218",
"CVE-2026-68226",
"CVE-2026-68227",
"CVE-2026-68234",
"CVE-2026-68235",
"CVE-2026-68236",
"CVE-2026-68243",
"CVE-2026-68244",
"CVE-2026-68245",
"CVE-2026-68246",
"CVE-2026-68247",
"CVE-2026-68248",
"CVE-2026-68249",
"CVE-2026-68250",
"CVE-2026-68251",
"CVE-2026-68252",
"CVE-2026-68253",
"CVE-2026-68254",
"CVE-2026-68255",
"CVE-2026-68256",
"CVE-2026-68257",
"CVE-2026-68259",
"CVE-2026-68264",
"CVE-2026-68266",
"CVE-2026-68267",
"CVE-2026-68269",
"CVE-2026-68271",
"CVE-2026-68272",
"CVE-2026-68273",
"CVE-2026-68276",
"CVE-2026-68277",
"CVE-2026-68278",
"CVE-2026-68279",
"CVE-2026-68284",
"CVE-2026-68293",
"CVE-2026-68294",
"CVE-2026-68296",
"CVE-2026-68297",
"CVE-2026-68299",
"CVE-2026-68300",
"CVE-2026-68301",
"CVE-2026-68304",
"CVE-2026-68307",
"CVE-2026-68309",
"CVE-2026-68310",
"CVE-2026-68311",
"CVE-2026-68313",
"CVE-2026-68315",
"CVE-2026-68317",
"CVE-2026-68318",
"CVE-2026-68319",
"CVE-2026-68320",
"CVE-2026-68325",
"CVE-2026-68326",
"CVE-2026-68328",
"CVE-2026-68329",
"CVE-2026-68336",
"CVE-2026-68338",
"CVE-2026-68339",
"CVE-2026-68343",
"CVE-2026-68344",
"CVE-2026-68346",
"CVE-2026-68348",
"CVE-2026-68349",
"CVE-2026-68350",
"CVE-2026-68351",
"CVE-2026-68352",
"CVE-2026-68353",
"CVE-2026-68355",
"CVE-2026-68362",
"CVE-2026-68363",
"CVE-2026-68365",
"CVE-2026-68372",
"CVE-2026-68373",
"CVE-2026-68374",
"CVE-2026-68376",
"CVE-2026-68377",
"CVE-2026-68378",
"CVE-2026-68386",
"CVE-2026-68388",
"CVE-2026-68391",
"CVE-2026-68392",
"CVE-2026-68394",
"CVE-2026-68398",
"CVE-2026-68402",
"CVE-2026-68403",
"CVE-2026-68405",
"CVE-2026-68406",
"CVE-2026-68407",
"CVE-2026-68408",
"CVE-2026-68410",
"CVE-2026-68411",
"CVE-2026-68413",
"CVE-2026-68414",
"CVE-2026-68416",
"CVE-2026-68419",
"CVE-2026-68422",
"CVE-2026-68425",
"CVE-2026-68427",
"CVE-2026-68428",
"CVE-2026-68429",
"CVE-2026-68430",
"CVE-2026-68432",
"CVE-2026-68433",
"CVE-2026-68434",
"CVE-2026-68439",
"CVE-2026-68442",
"CVE-2026-68444",
"CVE-2026-68445",
"CVE-2026-68446",
"CVE-2026-68450",
"CVE-2026-68456",
"CVE-2026-68461",
"CVE-2026-68469",
"CVE-2026-68475",
"CVE-2026-68476",
"CVE-2026-68477",
"CVE-2026-68479",
"CVE-2026-68480",
"CVE-2026-72004",
"CVE-2026-72005",
"CVE-2026-72010",
"CVE-2026-72012",
"CVE-2026-72014",
"CVE-2026-72015",
"CVE-2026-72017",
"CVE-2026-72019",
"CVE-2026-72020",
"CVE-2026-72021",
"CVE-2026-72024",
"CVE-2026-72027",
"CVE-2026-72029",
"CVE-2026-72030",
"CVE-2026-72032",
"CVE-2026-72034",
"CVE-2026-72035",
"CVE-2026-72036",
"CVE-2026-72037",
"CVE-2026-72039",
"CVE-2026-72040",
"CVE-2026-72045",
"CVE-2026-72046",
"CVE-2026-72049",
"CVE-2026-72051",
"CVE-2026-72052",
"CVE-2026-72053",
"CVE-2026-72054",
"CVE-2026-72055",
"CVE-2026-72056",
"CVE-2026-72057",
"CVE-2026-72059",
"CVE-2026-72061",
"CVE-2026-72063",
"CVE-2026-72065",
"CVE-2026-72066",
"CVE-2026-72067",
"CVE-2026-72068",
"CVE-2026-72070",
"CVE-2026-72083",
"CVE-2026-72084",
"CVE-2026-72085",
"CVE-2026-72086",
"CVE-2026-72087",
"CVE-2026-72088",
"CVE-2026-72096",
"CVE-2026-72099",
"CVE-2026-72100",
"CVE-2026-72101",
"CVE-2026-72102",
"CVE-2026-72103",
"CVE-2026-72105",
"CVE-2026-72106",
"CVE-2026-72107",
"CVE-2026-72108",
"CVE-2026-72110",
"CVE-2026-72111",
"CVE-2026-72113",
"CVE-2026-72114",
"CVE-2026-72115",
"CVE-2026-72116",
"CVE-2026-72117",
"CVE-2026-72118",
"CVE-2026-72119",
"CVE-2026-72120",
"CVE-2026-72121",
"CVE-2026-72122",
"CVE-2026-72123",
"CVE-2026-72124",
"CVE-2026-72125",
"CVE-2026-72126",
"CVE-2026-72127",
"CVE-2026-72129",
"CVE-2026-72130",
"CVE-2026-72132",
"CVE-2026-72135",
"CVE-2026-72136",
"CVE-2026-72138",
"CVE-2026-72144",
"CVE-2026-72151",
"CVE-2026-72152",
"CVE-2026-72155",
"CVE-2026-72157",
"CVE-2026-72159",
"CVE-2026-72160",
"CVE-2026-72161",
"CVE-2026-72163",
"CVE-2026-72164",
"CVE-2026-72165",
"CVE-2026-72166",
"CVE-2026-72170",
"CVE-2026-72172",
"CVE-2026-72174",
"CVE-2026-72175",
"CVE-2026-72176",
"CVE-2026-72177",
"CVE-2026-72178",
"CVE-2026-72182",
"CVE-2026-72183",
"CVE-2026-72212",
"CVE-2026-72213",
"CVE-2026-72217",
"CVE-2026-72218",
"CVE-2026-72219",
"CVE-2026-72221",
"CVE-2026-72222",
"CVE-2026-72223",
"CVE-2026-72224",
"CVE-2026-72225",
"CVE-2026-72226",
"CVE-2026-72227",
"CVE-2026-72228",
"CVE-2026-72229",
"CVE-2026-72230",
"CVE-2026-72231",
"CVE-2026-72232",
"CVE-2026-72233",
"CVE-2026-72234",
"CVE-2026-72235",
"CVE-2026-72237",
"CVE-2026-72240",
"CVE-2026-72241",
"CVE-2026-72242",
"CVE-2026-72243",
"CVE-2026-72245",
"CVE-2026-72247",
"CVE-2026-72250",
"CVE-2026-72251",
"CVE-2026-72252",
"CVE-2026-72253",
"CVE-2026-72254",
"CVE-2026-72255",
"CVE-2026-72256",
"CVE-2026-72261",
"CVE-2026-72262",
"CVE-2026-72265",
"CVE-2026-72266",
"CVE-2026-72272",
"CVE-2026-72273",
"CVE-2026-72280",
"CVE-2026-72282",
"CVE-2026-72284",
"CVE-2026-72286",
"CVE-2026-72289",
"CVE-2026-72297",
"CVE-2026-72298",
"CVE-2026-72299",
"CVE-2026-72300",
"CVE-2026-72301",
"CVE-2026-72302",
"CVE-2026-72304",
"CVE-2026-72305",
"CVE-2026-72306",
"CVE-2026-72307",
"CVE-2026-72308",
"CVE-2026-72310",
"CVE-2026-72314",
"CVE-2026-72316",
"CVE-2026-72317",
"CVE-2026-72318",
"CVE-2026-72319",
"CVE-2026-72320",
"CVE-2026-72322",
"CVE-2026-72323",
"CVE-2026-72324",
"CVE-2026-72325",
"CVE-2026-72326",
"CVE-2026-72330",
"CVE-2026-72333",
"CVE-2026-72335",
"CVE-2026-72336",
"CVE-2026-72338",
"CVE-2026-72339",
"CVE-2026-72342",
"CVE-2026-72343",
"CVE-2026-72347",
"CVE-2026-72348",
"CVE-2026-72349",
"CVE-2026-72350",
"CVE-2026-72351",
"CVE-2026-72356",
"CVE-2026-72360",
"CVE-2026-72361",
"CVE-2026-72362",
"CVE-2026-72364",
"CVE-2026-72371",
"CVE-2026-72372",
"CVE-2026-72373",
"CVE-2026-72374",
"CVE-2026-72376",
"CVE-2026-72378",
"CVE-2026-72379",
"CVE-2026-72389",
"CVE-2026-72390",
"CVE-2026-72392",
"CVE-2026-72395",
"CVE-2026-72396",
"CVE-2026-72400",
"CVE-2026-72405",
"CVE-2026-72406",
"CVE-2026-72409",
"CVE-2026-72416",
"CVE-2026-72418",
"CVE-2026-72419",
"CVE-2026-72420",
"CVE-2026-72421",
"CVE-2026-72425",
"CVE-2026-72427",
"CVE-2026-72428",
"CVE-2026-72430",
"CVE-2026-72433",
"CVE-2026-72434",
"CVE-2026-72435",
"CVE-2026-72436",
"CVE-2026-72437",
"CVE-2026-72441",
"CVE-2026-72443",
"CVE-2026-72444",
"CVE-2026-72447",
"CVE-2026-72449",
"CVE-2026-72450",
"CVE-2026-72451",
"CVE-2026-72452",
"CVE-2026-72464",
"CVE-2026-72465",
"CVE-2026-72466",
"CVE-2026-72467",
"CVE-2026-72468",
"CVE-2026-72469",
"CVE-2026-72472",
"CVE-2026-72473",
"CVE-2026-72476",
"CVE-2026-72481",
"CVE-2026-72487",
"CVE-2026-72491",
"CVE-2026-72502",
"CVE-2026-74255",
"CVE-2026-74256",
"CVE-2026-74259",
"CVE-2026-74263",
"CVE-2026-74265",
"CVE-2026-74267",
"CVE-2026-74270",
"CVE-2026-74271",
"CVE-2026-74278",
"CVE-2026-74279",
"CVE-2026-74281",
"CVE-2026-74282",
"CVE-2026-74283",
"CVE-2026-74284",
"CVE-2026-74287",
"CVE-2026-74288",
"CVE-2026-74290",
"CVE-2026-74296",
"CVE-2026-74297",
"CVE-2026-74300",
"CVE-2026-74302",
"CVE-2026-74305",
"CVE-2026-74306",
"CVE-2026-74307",
"CVE-2026-74308",
"CVE-2026-74310",
"CVE-2026-74312",
"CVE-2026-74313",
"CVE-2026-74316",
"CVE-2026-74318",
"CVE-2026-74320",
"CVE-2026-74321",
"CVE-2026-74327",
"CVE-2026-74329",
"CVE-2026-74330",
"CVE-2026-74331",
"CVE-2026-74332",
"CVE-2026-74339",
"CVE-2026-74340",
"CVE-2026-74341",
"CVE-2026-74346",
"CVE-2026-74348",
"CVE-2026-74349",
"CVE-2026-74351",
"CVE-2026-74352",
"CVE-2026-74353",
"CVE-2026-74356",
"CVE-2026-74359",
"CVE-2026-74362",
"CVE-2026-74363",
"CVE-2026-74365",
"CVE-2026-74376",
"CVE-2026-74377",
"CVE-2026-74378",
"CVE-2026-74379",
"CVE-2026-74380",
"CVE-2026-74381",
"CVE-2026-74382",
"CVE-2026-74384",
"CVE-2026-74386",
"CVE-2026-74387",
"CVE-2026-74390",
"CVE-2026-74391",
"CVE-2026-74393",
"CVE-2026-74394",
"CVE-2026-74395",
"CVE-2026-74397",
"CVE-2026-74398",
"CVE-2026-74399",
"CVE-2026-74401",
"CVE-2026-74404",
"CVE-2026-74406",
"CVE-2026-74408",
"CVE-2026-74410",
"CVE-2026-74411",
"CVE-2026-74416",
"CVE-2026-74417",
"CVE-2026-74424",
"CVE-2026-74425",
"CVE-2026-74426",
"CVE-2026-74427",
"CVE-2026-74432",
"CVE-2026-74435",
"CVE-2026-74436",
"CVE-2026-74439",
"CVE-2026-74440",
"CVE-2026-74441",
"CVE-2026-74442",
"CVE-2026-74443",
"CVE-2026-74444",
"CVE-2026-74445",
"CVE-2026-74446",
"CVE-2026-74447",
"CVE-2026-74448",
"CVE-2026-74453",
"CVE-2026-74454",
"CVE-2026-74455",
"CVE-2026-74456",
"CVE-2026-74457",
"CVE-2026-74458",
"CVE-2026-74460",
"CVE-2026-74464",
"CVE-2026-74465",
"CVE-2026-74469",
"CVE-2026-74470",
"CVE-2026-74471",
"CVE-2026-74472",
"CVE-2026-74473",
"CVE-2026-74475",
"CVE-2026-74476",
"CVE-2026-74479",
"CVE-2026-74480",
"CVE-2026-74481",
"CVE-2026-74482",
"CVE-2026-74484",
"CVE-2026-74485",
"CVE-2026-74486",
"CVE-2026-74487",
"CVE-2026-74488",
"CVE-2026-74490",
"CVE-2026-74492",
"CVE-2026-74495",
"CVE-2026-74497",
"CVE-2026-74498",
"CVE-2026-74499",
"CVE-2026-74500",
"CVE-2026-74501",
"CVE-2026-74502",
"CVE-2026-74503",
"CVE-2026-74504",
"CVE-2026-74505",
"CVE-2026-74507",
"CVE-2026-74508",
"CVE-2026-74509",
"CVE-2026-74510",
"CVE-2026-74512",
"CVE-2026-74516",
"CVE-2026-74517",
"CVE-2026-74518",
"CVE-2026-74519",
"CVE-2026-74523",
"CVE-2026-74531",
"CVE-2026-74532",
"CVE-2026-74535",
"CVE-2026-74536",
"CVE-2026-74540",
"CVE-2026-74541",
"CVE-2026-74543",
"CVE-2026-74546",
"CVE-2026-74547",
"CVE-2026-74548",
"CVE-2026-74549",
"CVE-2026-74550",
"CVE-2026-74552",
"CVE-2026-74553",
"CVE-2026-74555",
"CVE-2026-74556",
"CVE-2026-74557",
"CVE-2026-74564",
"CVE-2026-74565",
"CVE-2026-74566",
"CVE-2026-74567",
"CVE-2026-74569",
"CVE-2026-74572",
"CVE-2026-74574",
"CVE-2026-74575",
"CVE-2026-74577",
"CVE-2026-74579",
"CVE-2026-74580",
"CVE-2026-74581",
"CVE-2026-74582",
"CVE-2026-74583",
"CVE-2026-74584",
"CVE-2026-74585",
"CVE-2026-74586",
"CVE-2026-74587",
"CVE-2026-74588",
"CVE-2026-74589",
"CVE-2026-74590",
"CVE-2026-74592",
"CVE-2026-74594",
"CVE-2026-74595",
"CVE-2026-74597",
"CVE-2026-74598",
"CVE-2026-74603",
"CVE-2026-74604",
"CVE-2026-74606",
"CVE-2026-74607",
"CVE-2026-74608",
"CVE-2026-74609",
"CVE-2026-74610",
"CVE-2026-74612",
"CVE-2026-74613",
"CVE-2026-74614",
"CVE-2026-74615",
"CVE-2026-74616",
"CVE-2026-74618",
"CVE-2026-74619",
"CVE-2026-74620",
"CVE-2026-74621",
"CVE-2026-74622",
"CVE-2026-74623",
"CVE-2026-74624",
"CVE-2026-74625",
"CVE-2026-74630",
"CVE-2026-74632",
"CVE-2026-74634",
"CVE-2026-74635",
"CVE-2026-74636",
"CVE-2026-74641",
"CVE-2026-74642",
"CVE-2026-74644",
"CVE-2026-74654",
"CVE-2026-74656",
"CVE-2026-74657",
"CVE-2026-74658",
"CVE-2026-74660",
"CVE-2026-74661",
"CVE-2026-74663",
"CVE-2026-74664",
"CVE-2026-74665",
"CVE-2026-74666",
"CVE-2026-74667",
"CVE-2026-74668",
"CVE-2026-74669",
"CVE-2026-74670",
"CVE-2026-74671",
"CVE-2026-74673",
"CVE-2026-74675",
"CVE-2026-74676",
"CVE-2026-74677",
"CVE-2026-74678",
"CVE-2026-74680",
"CVE-2026-74682",
"CVE-2026-74683",
"CVE-2026-74684",
"CVE-2026-74688",
"CVE-2026-74689",
"CVE-2026-74691",
"CVE-2026-74696",
"CVE-2026-74700",
"CVE-2026-74701",
"CVE-2026-74704",
"CVE-2026-74705",
"CVE-2026-74710",
"CVE-2026-74712",
"CVE-2026-74714",
"CVE-2026-74717",
"CVE-2026-74718",
"CVE-2026-74720",
"CVE-2026-74722",
"CVE-2026-74724",
"CVE-2026-74725",
"CVE-2026-74726",
"CVE-2026-74730",
"CVE-2026-74732",
"CVE-2026-80590"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "[6.12.0-206.104.3.3]\n- inet: frags: strip GSO state from fragments before reassembly (Xinyang Ge) [Orabug: 39974840] {CVE-2026-80590}\n\n[6.12.0-206.104.3.2]\n- KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs (Weiming Shi) [Orabug: 39931938] {CVE-2026-74517}\n- tcp: challenge ACK for non-exact RST in SYN-RECEIVED (Yuxiang Yang) [Orabug: 39931929] {CVE-2026-68118}\n- tcp: reorganize tcp_sock_write_txrx group for variables later (Chia-Yu Chang) [Orabug: 39931929]\n- tcp: fast path functions later (Ilpo Jarvinen) [Orabug: 39931929]\n- tcp: Pass flags to __tcp_send_ack (Ilpo Jarvinen) [Orabug: 39931929]\n- mm/damon/ops-common: putback folios on invalid migrate nid (liyouhong) [Orabug: 39931902] {CVE-2026-74644}\n- KVM: SVM: Serialize accesses to the owner and mirror list with separate lock (Paolo Bonzini) [Orabug: 39931893] {CVE-2026-74607}\n- binfmt_misc: restore write access when removing an entry (Christian Brauner) [Orabug: 39931874] {CVE-2026-74487}\n- binfmt_misc: use exe_file_deny_write_access() for the interpreter clone (Christian Brauner) [Orabug: 39931874] {CVE-2026-74486}\n- fs: don't block write during exec on pre-content watched files (Amir Goldstein) [Orabug: 39931874]\n- fsnotify: opt-in for permission events at file open time (Amir Goldstein) [Orabug: 39931874]\n- fsnotify, lsm: Decouple fsnotify from lsm (Song Liu) [Orabug: 39931874]\n- net: pktgen: fix proc entry use-after-free (Chengfeng Ye) [Orabug: 39931868] {CVE-2026-74479}\n- net: pktgen: fix code style (WARNING: Block comments) (Peter Seiderer) [Orabug: 39931868]\n- userfaultfd: prevent registration of special VMAs (Mike Rapoport (Microsoft)) [Orabug: 39931866] {CVE-2026-68166}\n- mm/khugepaged: guard is_zero_pfn() calls with pte_present() (Lance Yang) [Orabug: 39931866]\n- net/sched: serialize qdisc_rtab_list against concurrent get/put (Aldo Ariel Panzardo) [Orabug: 39931864] {CVE-2026-68138}\n- octeontx2-vf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao) [Orabug: 39924423]\n- Revert 'octeontx2-vf: clear stale mailbox IRQ state before request_irq()' (Saeed Mirzamohammadi) [Orabug: 39924423]\n- octeontx2-pf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao) [Orabug: 39924423]\n- Revert 'octeontx2-pf: clear stale mailbox IRQ state before request_irq()' (Saeed Mirzamohammadi) [Orabug: 39924423]\n- erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms (Gao Xiang)\n- m68k: Define NR_CPUS to 1 (Uwe Kleine-Konig)\n- drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini (Pierre-Eric Pelloux-Prayer)\n- drm/amdgpu: remove unused function parameter (Yunxiang Li)\n- drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE (Nathan Lucas)\n\n[6.12.0-206.100.3.1]\n- LTS version: v6.12.104 (Saeed Mirzamohammadi)\n- bpf: tcp: fix double sock release on batch realloc (Xiang Mei (Microsoft))\n- thunderbolt: Fix bandwidth group reservation indexing (Xu Rao) {CVE-2026-80736}\n- thunderbolt: Bound the DROM dual link port number before indexing sw-ports (Bryam Vargas) {CVE-2026-74585}\n- sctp: clear new_transport when removing a peer (Qing Ming) {CVE-2026-74586}\n- sctp: fix use-after-free of cached ASCONF chunk (Yuxiang Yang) {CVE-2026-74587}\n- sctp: keep chunk-transport in step with the list it is queued on (Baul Lee) {CVE-2026-74588}\n- scsi: scsi_debug: Negate wrapped memcmp() result (Xu Rao)\n- bpf, sockmap: Fix sk_redir use-after-free in send verdict (Chengfeng Ye) {CVE-2026-74589}\n- fsverity: Fix silent truncation in bpf_get_fsverity_digest() (Eric Biggers)\n- fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions (Eric Biggers) {CVE-2026-74590}\n- ima: Instantiate file_truncate and path_truncate hooks (Mimi Zohar) {CVE-2026-74592}\n- sched/psi: Shut down rtpoll_timer in psi_cgroup_free() (Tejun Heo) {CVE-2026-74594}\n- fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() (Zhan Xusheng) {CVE-2026-74595}\n- ip6_tunnel: clear skb2-cb[] in ip6ip6_err() (Zhiling Zou) {CVE-2026-74597}\n- ipv6: fix Route Information option length validation (Yuejie Shi) {CVE-2026-74598}\n- ptp: ocp: Fix board ID over-read (Ahmad Byagowi) {CVE-2026-74603}\n- Revert 'thermal/drivers/hwmon: Cleanup coding style a bit' (Rafael J. Wysocki) {CVE-2026-74604}\n- eventfs: Fix use-after-free in eventfs_remove_rec() (Shuangpeng Bai) {CVE-2026-74606}\n- KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (Sean Christopherson) {CVE-2026-80726}\n- smb: client: Fix use-after-free in cifs_try_adding_channels() (Shuangpeng Bai) {CVE-2026-74608}\n- tipc: read le-link under the node lock in tipc_node_link_down() (Jun Yang) {CVE-2026-74609}\n- tls: don't leave a full plaintext sk_msg ring unpushed (chanyoung) {CVE-2026-74610}\n- vhost: reset the vring metadata cache on vring reconfiguration (Jun Yang) {CVE-2026-74580}\n- veth: fix skb length accounting after XDP frag adjustment (Sun Jian) {CVE-2026-74612}\n- vsock/virtio: avoid refilling the RX queue after teardown (Weiming Shi) {CVE-2026-74613}\n- vsock/virtio: read virtqueues under worker locks (Weiming Shi) {CVE-2026-74614}\n- vxlan: do not arm the ageing timer on a device that is down (Baul Lee) {CVE-2026-74615}\n- xdp: reject clones that overrun skb_shared_info tailroom (Zhiling Zou) {CVE-2026-74616}\n- Revert 'drm/amdgpu: fix aperture mapping leak' (Asad Kamal) {CVE-2026-80728}\n- binfmt_misc: don't warn when the mount is completed from another user namespace (Christian Brauner) {CVE-2026-74618}\n- ovl: don't warn when the mount is completed from another user namespace (Christian Brauner) {CVE-2026-74619}\n- net/sched: act_gact, act_police: range check the fallback control action (Hyunjung Ko) {CVE-2026-74620}\n- net/sched: act_ct: fix sk_buff leak when the header checks reject a packet (Hyunjung Ko) {CVE-2026-74621}\n- net: atlantic: free RX pages of consumed but not refilled buffers (Yangyu Chen) {CVE-2026-74622}\n- net: atlantic: free stranded TX buffers on ring deinit (Yangyu Chen) {CVE-2026-74623}\n- netfilter: nf_conntrack: defer invalid log until after unlock (Zihan Xi) {CVE-2026-74624}\n- netfilter: bridge: release template ct on non-IP path (Zhiling Zou) {CVE-2026-74625}\n- ipv6: prevent in6_dev_get() from resurrecting inet6_dev (Kyle Zeng) {CVE-2026-74630}\n- net: smc: fix splice entry lifetime imbalance in smc_rx_splice (Daming Li) {CVE-2026-74631}\n- mm/huge_memory: fix huge_zero_pfn race (Lorenzo Stoakes (ARM))\n- ring-buffer: Prevent subbuf order change when resizing is disabled (Vincent Donnefort) {CVE-2026-74634}\n- fbdev: bitblit: bound-check glyph index in bit_cursor() (Rik van Riel) {CVE-2026-74635}\n- tracing: Fix race between update_event_fields and, event_define_fields (Michael Wu) {CVE-2026-74636}\n- ALSA: usx2y: bound the hwdep mmap fault offset (Baul Lee) {CVE-2026-74641}\n- ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (Takashi Iwai) {CVE-2026-74642}\n- ring-buffer: Fix crash passing ERR_PTR to kthread_stop() (Hui Su) {CVE-2026-80730}\n- misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (Eddie Lin)\n- misc: fastrpc: take fl-lock when moving mmaps on interrupted invoke (Junrui Luo) {CVE-2026-74646}\n- misc: fastrpc: Remove buffer from list prior to unmap operation (Ekansh Gupta) {CVE-2026-74647}\n- misc: fastrpc: fix channel ctx ref leak when session alloc fails (Anandu Krishnan E)\n- staging: rtl8723bs: validate monitor transmit frame lengths (Mariano Baragiola) {CVE-2026-74648}\n- staging: rtl8723bs: fix missing shared-key auth challenge length check (Panagiotis Petrakopoulos) {CVE-2026-74649}\n- staging: rtl8723bs: fix OOB read in WMM_param_handler() (Muhammad Bilal) {CVE-2026-74650}\n- staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (Muhammad Bilal) {CVE-2026-74651}\n- serial: 8250_dma: Clear stale RX state on shutdown (Cunhao Lu) {CVE-2026-74654}\n- serial: qcom-geni: fix TX DMA buffer flush (Jan Sebastian Gotte) {CVE-2026-74655}\n- nvmem: layouts: Add fixed-layout driver (Mathieu Dubois-Briand)\n- mei: pull kvfree out of spinlock (Alexander Usyskin)\n- ipv4: fix use-after-free in fib_nhc_update_mtu() (Chengfeng Ye) {CVE-2026-74656}\n- ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops (Zihan Xi) {CVE-2026-74657}\n- selftests/bpf: Adapt sockmap update error handling (Michal Luczaj)\n- selftests/bpf: Ensure UDP sockets are bound (Michal Luczaj)\n- pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP (Claudiu Beznea)\n- kunit/fortify: Add back 'volatile' for sizeof() constants (Kees Cook)\n- kunit/fortify: Replace 'volatile' with OPTIMIZER_HIDE_VAR() (Kees Cook)\n- futex: Prevent robust futex exit race some more (Keno Fischer) {CVE-2026-74658}\n- crypto: ccp - Abort doing SEV INIT if SNP INIT fails (Ashish Kalra)\n- crypto: ccp - Fix checks for SNP_VLEK_LOAD input buffer length (Michael Roth)\n- KVM: SVM: Add support to initialize SEV/SNP functionality in KVM (Ashish Kalra)\n- crypto: ccp - Add new SEV/SNP platform shutdown API (Ashish Kalra)\n- dt-bindings: crypto: qcom,ice: Fix missing power-domain and iface clk (Harshal Dev)\n- block: Reorder the request allocation code in blk_mq_submit_bio() (Bart Van Assche)\n- KVM: s390: pci: Fix aisb calculation (Matthew Rosato)\n- KVM: s390: pci: Fix resource leak on IRQ registration failure (Farhan Ali)\n- KVM: s390: pci: Fix missing error codes and memory unaccounting (Farhan Ali)\n- KVM: s390: pci: Fix memory accounting for pinned/unpinned pages (Farhan Ali) {CVE-2026-74514}\n- net: bridge: mrp: fix uninitialised bytes on the wire (Baul Lee) {CVE-2026-74659}\n- netfilter: ebt_nflog: pin the NFLOG backend (Chengfeng Ye) {CVE-2026-74660}\n- mac802154: fix netdev use-after-free in beacon worker (Zihan Xi) {CVE-2026-74661}\n- net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header (Qihang Tang) {CVE-2026-80731}\n- net: octeontx2-pf: Fix UB in shift operation (Sergey V. Frolov)\n- net/sched: reject overly deep qdisc hierarchies (Zijie Huang) {CVE-2026-74663}\n- net: openvswitch: reallocate update replies for mismatched IDs (Zhiling Zou) {CVE-2026-74664}\n- net: fix skb length accounting after generic XDP frag adjustment (Sun Jian) {CVE-2026-74665}\n- packet: synchronize pressure clearing with ring reconfiguration (Zihan Xi) {CVE-2026-74666}\n- net/packet: reset the MAC header on the packet-socket transmit path (Doruk Tan Ozturk) {CVE-2026-74667}\n- packet: use consistent hard_header_len in TX_RING send path (Qihang Tang) {CVE-2026-74668}\n- packet: use consistent hard_header_len in non-ring send paths (Qihang Tang) {CVE-2026-74582}\n- ipvs: clear IPv4 options after rebasing tunnel ICMP errors (Kyle Zeng) {CVE-2026-74669}\n- ipvs: properly update the overload flag on dest edit (Julian Anastasov)\n- ipvs: add totalconns for dest (Julian Anastasov)\n- ipvs: stop estimator after disabled calc phase (Zhiling Zou) {CVE-2026-74670}\n- ima: fix out-of-bounds read in xattr_verify() (Lincoln Wallace) {CVE-2026-74671}\n- Input: evdev - fix information leak in evdev_pass_values() (Dmitry Torokhov) {CVE-2026-74673}\n- vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (Joshua Rogers) {CVE-2026-74675}\n- vt: add permission check for KDSKBMETA ioctl (Joshua Rogers) {CVE-2026-74676}\n- net: usb: ipheth: fix carrier_work UAF on disconnect (Doruk Tan Ozturk) {CVE-2026-74677}\n- net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (Yi Cong) {CVE-2026-74678}\n- usb: gadget: f_ncm: Use unsigned int for ndp_index (Sonali Pradhan) {CVE-2026-74679}\n- usb: cdnsp: fix incorrect endian conversions for APB timeout register (Pawel Laszczak)\n- thunderbolt: icm: Preserve USB4 proxy data-valid bit (Xu Rao)\n- usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (Aleksandr Nogikh) {CVE-2026-74680}\n- ALSA: usb-audio: fix OOB write on Type II inbound URBs (Baul Lee) {CVE-2026-74682}\n- Input: evdev - sanitize event type index when fetching event masks (Dmitry Torokhov) {CVE-2026-74683}\n- swapfile: call cond_resched() before locking si-lock (Guillaume Morin)\n- mtd: spinand: repeat reading in regular mode if continuous reading fails (Mikhail Kshevetskiy)\n- mtd: spinand: try a regular dirmap if creating a dirmap for continuous reading fails (Mikhail Kshevetskiy)\n- mtd: spinand: fix direct mapping creation sizes (Mikhail Kshevetskiy)\n- spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (Larisa Grigore)\n- net: fec: do not release NULL pages when RX buffer allocation fails (Mehmet Fide)\n- hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt (Guenter Roeck)\n- hwmon: (ltc4282) Clamp negative current limits (Guenter Roeck) {CVE-2026-74685}\n- hwmon: (ltc4282) Avoid overflow in maximum power calculation (Guenter Roeck)\n- hwmon: (ads7828) Fix external VREF regulator handling (Qingshuang Fu)\n- hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (Wilken Gottwalt)\n- tls: don't abort the connection on signal-interrupted sends (Maximilian Immanuel Brandtner)\n- sctp: clear control chunk transport if it is being removed (Xin Long) {CVE-2026-74688}\n- net/atm: fix slab-out-of-bounds read in vcc_setsockopt() (Eric Dumazet) {CVE-2026-74689}\n- ata: pata_sl82c105: fix bridge revision use-after-free (Hongyan Xu) {CVE-2026-80732}\n- net: thunderbolt: Tear down DMA paths before stopping the rings (Fan XinRan) {CVE-2026-74691}\n- net/smc: fix TOCTOU race between smc_listen_out() and listener close (Sidraya Jayagond) {CVE-2026-74692}\n- net: remove WARN_ON_ONCE() from sk_mc_loop() (Eric Dumazet) {CVE-2026-80733}\n- net: prestera: validate firmware header length (Pengpeng Hou) {CVE-2026-74693}\n- net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (Henry Martin) {CVE-2026-74694}\n- tcp: fix TFO max_qlen accounting across reuseport migration (Jiayuan Chen) {CVE-2026-74696}\n- sctp: fix addip_serial increment on ASCONF_ACK allocation failure (Qing Luo)\n- bnxt_en: Fix PTP PPS setting bug (Keegan Freyhof)\n- bnxt_en: Refresh VNIC default ring on queue restart if needed (Shravya KN)\n- bnxt_en: Determine and store default RX ring in vnic structure (Shravya KN)\n- bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss() (Shravya KN)\n- selftests/ftrace: refactor eprobes test to fix argument checks (Martin Kaiser)\n- hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (Guenter Roeck)\n- hwmon: (nzxt-smart2) Check return value of init_device() in probe (Qingshuang Fu)\n- net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers (Jamal Hadi Salim) {CVE-2026-74700}\n- net/openvswitch: check Ethernet header length in key_extract() (Cen Zhang (Microsoft))\n- net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter (Toke Hoiland-Jorgensen) {CVE-2026-74704}\n- udp: fix potential use-after-free in tunnel segmentation (Xuanqiang Luo) {CVE-2026-74705}\n- xsk: require at least 16 bytes of TX metadata (Stanislav Fomichev) {CVE-2026-74710}\n- tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss() (Nathan Gao)\n- vdpa/mlx5: Fix buffer length in create_direct_keys() (Christian Borntraeger) {CVE-2026-74712}\n- vhost/vdpa: reject overflowing PA map page counts on 32-bit (Yousef Alhouseen)\n- bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() (Jose Fernandez (Anthropic))\n- bpf: tcp: Avoid socket skips and repeats during iteration (Jordan Rife)\n- bpf: tcp: Use bpf_tcp_iter_batch_item for bpf_tcp_iter_state batch items (Jordan Rife)\n- bpf: tcp: Get rid of st_bucket_done (Jordan Rife)\n- bpf: tcp: Make sure iter-batch always contains a full bucket snapshot (Jordan Rife)\n- bpf: tcp: Make mem flags configurable through bpf_iter_tcp_realloc_batch (Jordan Rife)\n- counter: microchip-tcb-capture: Fix DT channel validation (Babanpreet Singh)\n- net/mlx5: fw_tracer, return NULL on create error (Michael Guralnik) {CVE-2026-74717}\n- devlink: fix net namespace reference leak in reload (Or Har-Toov) {CVE-2026-74718}\n- net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete (Jiawen Liu)\n- net/sched: cls_route: fix fastmap use-after-free on filter (Jamal Hadi Salim) {CVE-2026-74583}\n- net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() (Mahanta Jambigi) {CVE-2026-74719}\n- bpf: Preserve pointer state for commuted arithmetic (Yiyang Chen) {CVE-2026-74720}\n- btrfs: fix memory leak in btrfs_do_encoded_write() (Dmitry Antipov) {CVE-2026-74722}\n- watchdog: bd96801_wdt: Fix timeout for enabled WDG (Matti Vaittinen)\n- ipvs: return the csum validation for forward hook (Julian Anastasov)\n- ipvs: avoid out-of-bounds write in ip_vs_nat_icmp (Julian Anastasov) {CVE-2026-74724}\n- netfilter: ipset: switch ext_size to atomic64_t (Jozsef Kadlecsik)\n- pds_core: cancel pending PCI reset work on AER recovery (Nikhil P. Rao)\n- pds_core: keep the health thread stopped during reset (Nikhil P. Rao)\n- net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock (Shay Drory) {CVE-2026-80739}\n- enic: fix tx_hang_reset use-after-free on device removal (Satish Kharat) {CVE-2026-74725}\n- bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor (Xiang Mei (Microsoft))\n- Revert 'net: thunderbolt: Enable end-to-end flow control also in transmit' (Fan Ye)\n- net: hns3: fix speed configuration residue after driver reload (Jijie Shao)\n- drm/bridge: ps8640: propagate AUX transfer register errors (Pengpeng Hou)\n- ARM: dts: BCM5301X: fix PCIe controller 2 second interrupt (Rosen Penev)\n- ARM: npcm: Fix OF node refcount leaks in SMP setup (Yuho Choi)\n- arm64: dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer (Daniel Drake)\n- NFS: Pin the 'struct nfs_server' during a FREE_STATEID call (Anna Schumaker) {CVE-2026-74730}\n- s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() (Harald Freudenberger) {CVE-2026-80708}\n- drm/amd/display: Check for tg ops in dce110_set_avmute (Ray Wu) {CVE-2026-74732}\n- drm/amd/display: Add AV mute wait frames to dce110_set_avmute (Ray Wu)\n- selftests/bpf: Fail unbound UDP on sockmap update (Michal Luczaj)\n- mount: honour SB_NOUSER in the new mount API (Al Viro)\n- LTS version: v6.12.103 (Saeed Mirzamohammadi)\n- drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info (Thomas Zimmermann)\n- drm/fb-helper: Fix a locking bug in an error path (Bart Van Assche)\n- usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path (Andrei Kuchynski)\n- can: isotp: fix timer drain order, wakeup handling and tx_gen ordering (Oliver Hartkopp)\n- can: use skb hash instead of private variable in headroom (Oliver Hartkopp)\n- rxrpc: Fix irq-disabled in local_bh_enable() (David Howells) {CVE-2025-38525}\n- rxrpc: Manage RTT per-call rather than per-peer (David Howells)\n- rxrpc: Fix the calculation and use of RTO (David Howells)\n- rxrpc: Adjust the rxrpc_rtt_rx tracepoint (David Howells)\n- rxrpc: Generate rtt_min (David Howells)\n- drm/xe/pt: Reset current_op in xe_pt_update_ops_init() (Zongyao Bai) {CVE-2026-68264}\n- drm/xe: Stub out new pagefault layer (Matthew Brost)\n- drm/i915/hdcp: check streams[] bounds before overflow (Jani Nikula) {CVE-2026-68253}\n- drm/i915/hdcp: Skip inactive MST connectors when building stream list (Suraj Kandpal)\n- drm/i915/hdcp: require monotonically increasing seq_num_v (Jani Nikula)\n- drm/i915/hdcp: Move to using intel_display in intel_hdcp (Suraj Kandpal)\n- drm/xe: Hold a dma-buf reference for imported BOs (Nitin Gote) {CVE-2026-68266}\n- drm/xe: Rename ___xe_bo_create_locked() (Thomas Hellstrom)\n- drm/i915/vrr: require valid min/max vfreq for VRR (Jani Nikula) {CVE-2026-68254}\n- drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() (Ville Syrjala)\n- drm/xe: Wait on external BO kernel fences in exec IOCTL (Matthew Brost) {CVE-2026-74440}\n- drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse] (Thomas Hellstrom)\n- drm/tegra: fbdev: Remove offset into framebuffer memory (Thomas Zimmermann)\n- drm/fb-helper: Allocate and release fb_info in single place (Thomas Zimmermann)\n- drm/amdgpu/gfx: fix cleaner shader IB buffer overflow (Asad Kamal) {CVE-2026-68276}\n- drm/amdgpu: give each kernel job a unique id (Pierre-Eric Pelloux-Prayer)\n- drm/sched: Store the drm client_id in drm_sched_fence (Pierre-Eric Pelloux-Prayer)\n- drm/amdgpu: Fix context pstate override handling (Tvrtko Ursulin) {CVE-2026-68273}\n- drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions (Timur Kristof)\n- mm/kmemleak: fix checksum computation for per-cpu objects (Breno Leitao)\n- kmemleak: iommu/iova: fix transient kmemleak false positive (Catalin Marinas)\n- mptcp: pm: userspace: fix use-after-free in get_local_id (Geliang Tang) {CVE-2026-68169}\n- mptcp: pm: use addr entry for get_local_id (Geliang Tang)\n- mptcp: add mptcp_userspace_pm_lookup_addr helper (Geliang Tang)\n- mptcp: pm: avoid code duplication to lookup endp (Geliang Tang)\n- ALSA: hda: codecs: hdmi: disable keep-alive before audio format change (Kai Vehmanen)\n- wifi: brcmfmac: set F2 blocksize to 256 for BCM43752 (LiangCheng Wang)\n- wifi: brcmfmac: fix 43752 SDIO FWVID incorrectly labelled as Cypress (CYW) (Gokul Sivakumar)\n- wifi: ath6kl: fix use-after-free in aggr_reset_state() (Daniel Hodges) {CVE-2026-68198}\n- wifi: brcmfmac: drain bus_reset work on device removal (Fan Wu) {CVE-2026-64586}\n- media: uapi: rkisp: Correct name version enum (Niklas Soderlund)\n- media: chips-media: wave5: Support CBP profile (Jackson Lee)\n- media: imx219: Fix maximum frame length in lines (Sakari Ailus)\n- media: i2c: imx219: Rename VTS to FRM_LENGTH (Jai Luthra)\n- usb: typec: ucsi: Fix race condition and ordering in port unregistration (Andrei Kuchynski) {CVE-2026-74441}\n- usb: typec: ucsi: split connector lock classes (Sergey Senozhatsky)\n- usb: gadget: f_tcm: synchronize delayed set_alt with teardown (Cen Zhang) {CVE-2026-68367}\n- gpio: pch: use raw_spinlock_t for the register lock (Junjie Cao) {CVE-2026-74468}\n- lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled() (Harry Yoo (Oracle))\n- mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (Kiryl Shutsemau (Meta))\n- fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes (Kiryl Shutsemau (Meta))\n- mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() (Kiryl Shutsemau (Meta))\n- drm/xe/rtp: Ensure locking/ref counting for OA whitelists (Ashutosh Dixit)\n- drm/xe/oa: (De-)whitelist OA registers on OA stream open/release (Ashutosh Dixit)\n- drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt (Ashutosh Dixit)\n- drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs (Ashutosh Dixit)\n- drm/xe/rtp: Save OA nonpriv registers to register save/restore lists (Ashutosh Dixit)\n- drm/xe/rtp: Generalize whitelist_apply_to_hwe (Ashutosh Dixit)\n- drm/xe/rtp: Keep track of non-OA nonpriv slots (Ashutosh Dixit)\n- drm/xe/rtp: Maintain OA whitelists separately (Ashutosh Dixit)\n- drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (Ashutosh Dixit) {CVE-2026-68267}\n- drm/xe: Apply whitelist to engine save-restore (Lucas De Marchi)\n- drm/xe: Introduce xe_gt_dbg_printer() (Michal Wajdeczko)\n- drm/xe/rtp: Refactor OAG MMIO trigger register whitelisting (Ashutosh Dixit)\n- Bluetooth: ISO: fix CONNECTED - CLOSED transition on shutdown/release (Pauli Virtanen)\n- of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails (Wandun Chen) {CVE-2026-74352}\n- ata: ahci: Make ahci_ignore_port() handle empty mask_port_map (Niklas Cassel)\n- ata: libahci_platform: Do not set mask_port_map when not needed (Damien Le Moal)\n- HID: logitech-dj: Fix maxfield check in DJ short report validation (HyeongJun An) {CVE-2026-64427}\n- spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX (Jun Guo)\n- drm/vmwgfx: validate external BO copy bounds for both stride paths (Zack Rusin) {CVE-2026-80700}\n- drm/vmwgfx: use check_add_overflow for shader size+offset bound (Zack Rusin)\n- drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure (Zack Rusin) {CVE-2026-74442}\n- drm/vmwgfx: bound DMA command body size against suffix pointer (Zack Rusin) {CVE-2026-74443}\n- drm/vmwgfx: validate DRAW_PRIMITIVES header size before division (Zack Rusin) {CVE-2026-74444}\n- drm/vmwgfx: drop dma_buf reference on foreign-fd prime import (Zack Rusin)\n- drm/vmwgfx: reject DX_BIND_QUERY without a DX context (Zack Rusin) {CVE-2026-74445}\n- drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size (Zack Rusin) {CVE-2026-80702}\n- drm/amdkfd: hold event_mutex while checkpointing CRIU events (William Palacek) {CVE-2026-74446}\n- drm/amdkfd: Handle invalid event type in CRIU event restore (David Francis)\n- drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment (William Palacek) {CVE-2026-74447}\n- drm/amdkfd: fix QID bit leak in pqm_create_queue() (Vladimir Marioukhine) {CVE-2026-74448}\n- drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (Gang Ba) {CVE-2026-80703}\n- drm/amd/display: use proper context for logging (Jiri Slaby (SUSE))\n- drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames (Ray Wu)\n- drm/amdgpu: cap GTT size to physical RAM on APUs (Harkirat Gill)\n- drm/amdgpu: restore UMD profile pstate after runtime resume (Candice Li)\n- drm/mediatek: ovl_adaptor: balance component registrations (Myeonghun Pak)\n- drm/panthor: validate firmware interface structure sizes (Osama Abdelkader) {CVE-2026-74451}\n- drm/panthor: reject firmware sections with oversized data (Osama Abdelkader) {CVE-2026-74452}\n- drm/vc4: Zero the tile state data array before each BIN job (Maira Canal) {CVE-2026-74453}\n- drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size (Jose Maria Casanova Crespo) {CVE-2026-74454}\n- drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs (Alexander Kaplan)\n- can: ctucanfd: mark error-active controller status valid (Avi Weiss)\n- can: ctucanfd: handle bus error interrupts (Avi Weiss)\n- can: ctucanfd: unmap BAR0 using base address (Avi Weiss)\n- can: ctucanfd: use self-test mode for PRESUME_ACK (Avi Weiss)\n- can: ctucanfd: add missing MODULE_DEVICE_TABLE() (Pengpeng Hou)\n- can: peak_usb: validate uCAN receive record lengths (Pengpeng Hou) {CVE-2026-74455}\n- can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error (Maoyi Xie) {CVE-2026-74456}\n- can: peak_usb: add bounds check for USB channel index (James Gao) {CVE-2026-74457}\n- can: softing: fw_parse(): validate firmware record spans (Pengpeng Hou) {CVE-2026-80706}\n- can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents (Pengpeng Hou) {CVE-2026-74458}\n- can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() (Abdun Nihaal)\n- can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (Tetsuo Handa)\n- can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer (Oleksij Rempel) {CVE-2026-80707}\n- can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure (Marc Kleine-Budde)\n- can: ems_usb: validate CPC message lengths (Pengpeng Hou) {CVE-2026-74460}\n- can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured (Lucas Martins Alves)\n- i2c: imx: Cancel hrtimer before clearing slave pointer (Liem) {CVE-2026-74461}\n- i2c: imx: Fix slave registration race and error handling (Liem) {CVE-2026-80678}\n- i2c: iproc: reset bus after timeout if START_BUSY is stuck (Jonas Gorski)\n- i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock (H. Nikolaus Schaller) {CVE-2026-74463}\n- ice: fix memory leak in ice_lbtest_prepare_rings() (Dawei Feng)\n- ice: wait for reset completion in ice_resume() (Aaron Ma)\n- net: openvswitch: fix skb leak on flow key update failure during ct (Ilya Maximets) {CVE-2026-74464}\n- net: openvswitch: fix skb leak on flow key update failure during recirculation (Ilya Maximets)\n- net: openvswitch: fix potential UAF on meter attach failure (Ilya Maximets) {CVE-2026-74465}\n- phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB (Nava kishore Manne)\n- phy: zynqmp: use read-modify-write for SERDES scrambler bypass (Nava kishore Manne)\n- phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask (Nava kishore Manne)\n- s390/zcrypt: Validate length for CCA ECC private key requests (Holger Dengler) {CVE-2026-68451}\n- s390/zcrypt: Validate length for CCA AES cipher key requests (Holger Dengler) {CVE-2026-68452}\n- s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs (Harald Freudenberger) {CVE-2026-80709}\n- s390/dasd: Fix undersized format-check buffer (Stefan Haberland) {CVE-2026-80710}\n- s390/dasd: Fix potential NULL pointer dereference (Jan Hoppner) {CVE-2026-80679}\n- s390/qeth: Check CAP_NET_ADMIN for private ioctls (Aswin Karuvally) {CVE-2026-74467}\n- s390/pci: Fix s390_pci_mmio_write syscall error return without MIO (Niklas Schnelle)\n- power: supply: max17040: handle missing status supplier (Jianing Li) {CVE-2026-80711}\n- power: supply: bq25890: fix the -10 C NTC lookup entry (Xu Rao)\n- cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized (Zhongqiu Han)\n- cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() (Abdun Nihaal)\n- gpio: pca953x: fix cache_only and IRQ state on restore_context() failure (bui duc phuc)\n- i2c: amd-mp2: Unregister callback on adapter add failure (Myeonghun Pak) {CVE-2026-80680}\n- hwmon: (pmbus/core) notify on the hwmon device, not the i2c client (Vincent Jardin)\n- hwmon: (npcm750-pwm-fan): stop fan timer on device detach (Hongyan Xu)\n- sctp: prevent peer transport count overflow (Asim Viladi Oglu Manizada) {CVE-2026-74469}\n- sctp: reject stale cookies with mismatched verification tags (Yuxiang Yang)\n- scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write (Ibrahim Hashimov) {CVE-2026-74470}\n- selftests/clone3: fix wild pointer access of getline due to missing init (Chris Gellermann)\n- selftests/mm: fix potential wild pointer access of getline due to missing init (Chris Gellermann)\n- spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure (Vijaya Krishna Nivarthi)\n- tracing/filters: Fix false positive match in regex_match_full() (Masami Hiramatsu (Google))\n- tracing: Check return value of __register_event() in trace_module_add_events() (Masami Hiramatsu (Google))\n- ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() (Ming Lei) {CVE-2026-74472}\n- vxlan: use pskb_network_may_pull() in route_shortcircuit() (Eric Dumazet) {CVE-2026-74473}\n- vxlan: use neigh_ha_snapshot() in route_shortcircuit() (Eric Dumazet) {CVE-2026-74475}\n- vxlan: unclone skb head before modifying eth header in route_shortcircuit() (Eric Dumazet)\n- vxlan: re-fetch eth header after route_shortcircuit() (Eric Dumazet) {CVE-2026-80681}\n- veth: convert frag_list skbs before running XDP (Matt Fleming) {CVE-2026-74476}\n- um: vector: fix use-after-free in vector_mmsg_rx() (Michael Bommarito) {CVE-2026-74478}\n- powerpc/ps3: Fix map failure path in dma_ioc0_map_pages() (Thorsten Blum)\n- net: ipv6: clear suppressed fib6 rule result (Zhiling Zou) {CVE-2026-74581}\n- net: bridge: stop fast-leave after deleting a port group (Zhiling Zou) {CVE-2026-74480}\n- mm: memcg: initialize *locked in memcg1_oom_prepare() stub (Breno Leitao)\n- mm/page_reporting: use system_freezable_wq to fix UAF during suspend (Link Lin) {CVE-2026-74481}\n- binfmt_misc: don't let an 'F' entry pin its own instance (Christian Brauner) {CVE-2026-74484}\n- binfmt_misc: reject a flag character as the field delimiter (Christian Brauner) {CVE-2026-74485}\n- wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (Zhao Li) {CVE-2026-74488}\n- tipc: avoid use-after-free in poll trace queue dumps (Zihan Xi) {CVE-2026-74490}\n- netfilter: ipset: do not update comments from kernel-side hash adds (David Lee) {CVE-2026-74492}\n- net/smc: fix socket use-after-free during link group termination (Xuanqiang Luo) {CVE-2026-74493}\n- ipvs: do not propagate one-packet flag to synced conns (Zhiling Zou) {CVE-2026-80714}\n- igbvf: Fix leak in TX DMA error cleanup (Matt Vollrath) {CVE-2026-74495}\n- e1000: fix memory leak in e1000_probe() (Dawei Feng)\n- dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ (Md Sadre Alam)\n- ALSA: usb-audio: Clamp frame size in implicit-feedback mode (Sonali Pradhan) {CVE-2026-74497}\n- ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set (Sonali Pradhan) {CVE-2026-74498}\n- ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() (Baul Lee) {CVE-2026-74499}\n- ALSA: usb-audio: fix stack info leak in RME Digiface status (Baul Lee) {CVE-2026-74500}\n- ALSA: usb-audio: fix use-after-free in ump_to_endpoint() (Baul Lee) {CVE-2026-74501}\n- ata: libata-sata: fix ata_scsi_lpm_supported() iteration (Niklas Cassel)\n- ata: libata-eh: Increase STANDBY IMMEDIATE timeout (Matt Vollrath)\n- ASoC: tas2562: fix broken entries in the volume lookup table (Haidar Lee)\n- ASoC: tas2562: fix DVC coefficient write order (Haidar Lee)\n- ALSA: ump: fix double free of out_cvts on rawmidi error (Baul Lee) {CVE-2026-74502}\n- ALSA: seq: Fix division by zero in initialize_timer() (Norbert Szetei) {CVE-2026-74504}\n- ALSA: pcm: wake linked drain waiters on unlink (Norbert Szetei) {CVE-2026-80716}\n- ALSA: lx6464es: fix period byte count for 16-bit streams (Xu Rao)\n- ALSA: 6fire: Fix UAF at error handling during probe (Takashi Iwai) {CVE-2026-74505}\n- bpf: lwt: Fix dst reference leak on reroute failure (Xuanqiang Luo)\n- Bluetooth: HIDP: validate numbered report payloads (Sangho Lee) {CVE-2026-74507}\n- Bluetooth: HIDP: reject frames without a transaction header (Sangho Lee) {CVE-2026-74508}\n- Bluetooth: hci_sync: Fix advertising data UAFs (Chengfeng Ye) {CVE-2026-74509}\n- Bluetooth: mgmt: fix UAF in pair command cancellation (Zihan Xi) {CVE-2026-74510}\n- Bluetooth: mgmt: fix pending command UAF in EIR updates (Zihan Xi) {CVE-2026-74511}\n- Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() (Greg Kroah-Hartman)\n- Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req() (Greg Kroah-Hartman)\n- audit: fix potential use-after-free in audit_del_rule() (Luxiao Xu) {CVE-2026-74512}\n- audit: fix potential integer overflow in audit_log_n_string() (Zhan Xusheng)\n- sctp: validate Adaptation Indication parameter length (Charles Vosburgh) {CVE-2026-80717}\n- KVM: s390: pci: Validate AIBV and AISB before pinning guest pages (Farhan Ali)\n- KVM: s390: pci: Fix NULL dereference on AIBV allocation failure (Farhan Ali) {CVE-2026-80684}\n- KVM: s390: pci: Reject adapter interrupt forwarding if already enabled (Farhan Ali) {CVE-2026-74515}\n- KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (Sean Christopherson) {CVE-2026-74516}\n- tracing/probes: Reject in meta argument expansion (Raushan Patel)\n- mm/vmstat: fold stranded per-cpu node stats when a node comes online (Gregory Price)\n- mm/hugetlb: fix list corruption in allocate_file_region_entries() (Xiangfeng Cai) {CVE-2026-74518}\n- mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() (Zi Yan) {CVE-2026-80718}\n- fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes (Kiryl Shutsemau (Meta))\n- mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE (Kefeng Wang) {CVE-2026-80686}\n- fortify: Disable -Wstringop-overread in tests (Nathan Chancellor)\n- pinctrl: bm1880: add missing select GENERIC_PINCONF (Benjamin Boortz)\n- erofs: cap LZMA stream pool size (Michael Bommarito)\n- pinctrl: devicetree: don't free uninitialized dev_name on error path (Karl Mehltretter) {CVE-2026-74519}\n- pinctrl: microchip-sgpio: add missing select REGMAP_MMIO (Benjamin Boortz)\n- rhashtable: clear stale iter-p on table restart (Cen Zhang (Microsoft))\n- ksmbd: fix use-after-free in __close_file_table_ids() (Namjae Jeon) {CVE-2026-74522}\n- ksmbd: return success for deferred final close (Namjae Jeon)\n- qede: sync udp_tunnel ports outside qede_lock in the recovery path (Denis V. Lunev) {CVE-2026-74523}\n- net: libwx: fix FDIR ATR queue mismatch for software VLAN packets (Jiawen Wu)\n- net: dsa: mt7530: error out on failed reads in MT7531 PHY polling (Daniel Golle)\n- net: dsa: mt7530: check bus-read() errors in the MDIO regmap backend (Daniel Golle)\n- riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove (Karl Mehltretter) {CVE-2026-74524}\n- accel/qaic: use sizeof(*trans_hdr) for transaction length check (Muhammad Bilal)\n- tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions (Masami Hiramatsu (Google))\n- tracing/mmiotrace: Remove reference to unused per CPU data pointer (Steven Rostedt)\n- tracing: Remove TRACE_EVENT_FL_FILTERED logic (Zheng Yejian)\n- tracing/mmiotrace: Reset dropped_count in mmio_reset_data() (Masami Hiramatsu (Google))\n- can: isotp: check register_netdevice_notifier() error in module init (Minhong He)\n- net: sxgbe: check descriptor ring allocation failures (Chenguang Zhao)\n- net: sxgbe: free TX rings on RX allocation failure (Chenguang Zhao) {CVE-2026-74525}\n- scsi: target: Clear cmd_cnt when initial counter enrollment fails (Leon Romanovsky)\n- scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req (Benjamin Block)\n- scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE (TanZheng) {CVE-2026-80691}\n- net: phylink: put link_gpio if phylink_create fails (Christian Marangi)\n- Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync (Pauli Virtanen)\n- Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (Pauli Virtanen) {CVE-2026-74531}\n- Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (Pauli Virtanen)\n- Bluetooth: btintel: Validate length before parsing diagnostics TLV (Zijun Hu) {CVE-2026-74532}\n- Bluetooth: ISO: avoid deadlocks in iso_sock_timeout (Pauli Virtanen) {CVE-2026-74535}\n- Bluetooth: ISO: fix leaking sk after socket release (Pauli Virtanen) {CVE-2026-74536}\n- Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis() (Pauli Virtanen)\n- Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos (Pauli Virtanen)\n- Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp (Jiale Yao) {CVE-2026-74540}\n- Bluetooth: ISO: clear iso_data always when detaching conn from hcon (Pauli Virtanen) {CVE-2026-74541}\n- idpf: Fix mailbox IRQ name leak on request failure (Yuho Choi)\n- idpf: adjust TxQ ring count minimum (Joshua Hay)\n- hwmon: (pmbus) Fix return value from pmbus_update_byte_data() (Guenter Roeck)\n- net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller (Chenguang Zhao) {CVE-2026-80694}\n- net: ethernet: mtk_eth_soc: add consts for irq index (Frank Wunderlich)\n- net: ethernet: mtk_eth_soc: support named IRQs (Frank Wunderlich)\n- wifi: mac80211: validate individual TWT params before driver setup (Zhao Li) {CVE-2026-80722}\n- net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister() (Eric Dumazet) {CVE-2026-74543}\n- powerpc/boot: Fix treeboot-akebono CPU node lookup check (Thorsten Blum)\n- powerpc/boot: Fix treeboot-currituck CPU node lookup check (Thorsten Blum)\n- powerpc/boot: Fix simpleboot CPU node lookup check (Thorsten Blum)\n- rtase: fix double free of multi-frag skb on DMA map failure (Yun Lu) {CVE-2026-74545}\n- hwmon: (adt7470) Fix PWM auto temp state array and bounds check (Luiz Angelo Daros de Luca)\n- hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read (Luiz Angelo Daros de Luca) {CVE-2026-74546}\n- hwmon: (adt7470) Use cached PWM frequency value (Luiz Angelo Daros de Luca)\n- hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks (Luiz Angelo Daros de Luca)\n- hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() (Luiz Angelo Daros de Luca)\n- hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread (Luiz Angelo Daros de Luca) {CVE-2026-74547}\n- hwmon: (adt7470) Fix cache updated before hardware write on I2C error (Luiz Angelo Daros de Luca)\n- hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors (Luiz Angelo Daros de Luca)\n- forcedeth: fix UAF of txrx_stats in nv_remove (Chenguang Zhao) {CVE-2026-74548}\n- net: bridge: mrp: fix Option TLV length in MRP_Test frames (David Corvaglia)\n- hwmon: (nct6775-core) Prevent access to unsupported weight registers (Guenter Roeck) {CVE-2026-74549}\n- net: do not send ICMP/NDISC Redirects when peer allocation fails (Eric Dumazet) {CVE-2026-74550}\n- hwmon: (nzxt-smart2) DMA-align output buffer (Guenter Roeck) {CVE-2026-74551}\n- hwmon: (lm90) Only report alarms if driver is ready (Guenter Roeck) {CVE-2026-74552}\n- hwmon: (sht3x) Fix unaligned accesses (Guenter Roeck) {CVE-2026-80695}\n- hwmon: (ltc4282) Fix reading the minimum alarm voltage (Guenter Roeck) {CVE-2026-80696}\n- hwmon: (ina2xx) Fix various overflow issues (Guenter Roeck)\n- hwmon: (ina2xx) Shift INA234 shunt and current registers (Jonas Rebmann)\n- hwmon: (ina2xx) Add support for INA234 (Ian Ray)\n- hwmon: (ina2xx) Make it easier to add more devices (Ian Ray)\n- hwmon: (ina226) Add support for SY24655 (Wenliang Yan)\n- hwmon: (ina2xx) Add support for INA260 (Guenter Roeck)\n- hwmon: (ina2xx) Add support for has_alerts configuration flag (Guenter Roeck)\n- hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 (Guenter Roeck) {CVE-2026-74553}\n- spi: spi-cadence: Move TX FIFO full busy-wait into FIFO (Srikanth Boyapally)\n- spi: spi-cadence: supports transmission with bits_per_word of 16 and 32 (Jun Guo)\n- smb: client: fix buffer leaks in SMB1 read and write (Dawei Feng)\n- scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race (Xingui Yang) {CVE-2026-74555}\n- scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (HyeongJun An) {CVE-2026-74556}\n- scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer (HyeongJun An) {CVE-2026-74557}\n- pinctrl-amd: Don't clear S4 wake bits at probe (Mario Limonciello)\n- netfilter: nft_payload: fix mask build for partial field offload (Xiang Mei (Microsoft))\n- ipvs: do not mangle ICMP replies for non-first fragments (Julian Anastasov)\n- ipvs: fix places with wrong packet offsets (Julian Anastasov)\n- ipvs: fix the checksum validations (Julian Anastasov)\n- netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH (Pablo Neira Ayuso) {CVE-2026-74564}\n- netfilter: nf_tables: make nft_object rhltable per table (Pablo Neira Ayuso) {CVE-2026-74565}\n- assoc_array: trim the final shortcut word using the current chunk end (Michael Bommarito)\n- keys: make keyring key-chunk byte order agree with keyring_diff_objects() (Michael Bommarito) {CVE-2026-74566}\n- keys: fix out-of-bounds read in keyring_get_key_chunk() (Michael Bommarito) {CVE-2026-74567}\n- KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type (Fabrice Derepas)\n- Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation (Sebastian Andrzej Siewior)\n- drm/mediatek: Check CRTC state before freeing (Ruoyu Wang)\n- netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (Xiang Mei) {CVE-2026-74569}\n- phy: zynqmp: fix runtime PM leak on probe allocation failure (Radhey Shyam Pandey)\n- phy: zynqmp: fix clock error handling in xpsgtr_phy_init() (Radhey Shyam Pandey)\n- phy-zynqmp: Postpone getting clock rate until actually needed (Mike Looijmans)\n- btrfs: zoned: fix deadlock between metadata writeback and transaction commit (Johannes Thumshirn) {CVE-2026-74572}\n- btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag (Qu Wenruo)\n- of: reserved_mem: prevent OOB when too many dynamic regions are defined (Sang-Heon Jeon) {CVE-2026-80723}\n- of: reserved_mem: Add code to dynamically allocate reserved_mem array (Oreoluwa Babatunde)\n- ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare)\n- ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare)\n- ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources() (Radhey Shyam Pandey)\n- ahci: Introduce ahci_ignore_port() helper (Damien Le Moal)\n- ata: libahci_platform: support non-consecutive port numbers (Josua Mayer)\n- ata: sata_mv: accept 1 or 2 resources in platform probe (Rosen Penev)\n- gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe() (Abdun Nihaal)\n- dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() (Yuho Choi) {CVE-2026-74574}\n- dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA (Hongling Zeng)\n- pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 (Konrad Dybcio)\n- pinctrl: qcom: Unconditionally mark gpio as wakeup enable (Sneh Mankad)\n- thunderbolt: Prevent XDomain delayed work use-after-free on disconnect (Michael Bommarito) {CVE-2026-74575}\n- netconsole: avoid OOB reads, msg is not nul-terminated (Jakub Kicinski) {CVE-2026-43197}\n- bpf: Reset register bounds before narrowing retval range in check_mem_access() (Tristan Madani) {CVE-2026-72111}\n- HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (Benjamin Tissoires)\n- HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (Lee Jones)\n- HID: logitech-dj: Standardise hid_report_enum variable nomenclature (Lee Jones)\n- net: mpls: initialize rtm_tos in mpls_getroute() (Yehyeong Lee) {CVE-2026-74577}\n- netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge() (Lorenzo Bianconi)\n- um: Preserve errno within signal handler (Tiwei Bie)\n- kunit: tool: skip stty when stdin is not a tty (Shuvam Pandey)\n- kunit: tool: Terminate kernel under test on SIGINT (David Gow)\n- um: Set parent death signal for userspace process (Benjamin Berg)\n- um: Set parent-death signal for write_sigio thread/process (Tiwei Bie)\n- um: Set parent-death signal for ubd io thread/process (Tiwei Bie)\n- um: Use os_set_pdeathsig helper in winch thread/process (Tiwei Bie)\n- um: Set parent death signal for winch thread/process (Benjamin Berg)\n- um: Add os_set_pdeathsig helper function (Tiwei Bie)\n- LTS version: v6.12.102 (Saeed Mirzamohammadi)\n- LTS version: v6.12.101 (Saeed Mirzamohammadi)\n- KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug (Nikunj A Dadhania) {CVE-2026-68093}\n- afs: Fix uninit var in afs_alloc_anon_key() (David Howells)\n- Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() (Pavitra Jha) {CVE-2026-53364}\n- Bluetooth: hci_conn: Fix not cleaning up PA_LINK connections (Luiz Augusto von Dentz)\n- Bluetooth: hci_conn: Fix not cleaning up Broadcaster/Broadcast Source (Luiz Augusto von Dentz)\n- Bluetooth: hci_conn: Fix running bis_cleanup for hci_conn-type PA_LINK (Luiz Augusto von Dentz)\n- afs: handle CB.InitCallBackState3 requests without a server record (Nan Li) {CVE-2026-74425}\n- afs: Fix delayed allocation of a cell's anonymous key (David Howells) {CVE-2025-68299}\n- dpll: fix clock quality level reporting (Ivan Vecera)\n- afs: Set vllist to NULL if addr parsing fails (Edward Adam Davis)\n- net: ethernet: Remove accidental duplication in Kconfig file (Lukas Bulwahn)\n- wifi: nl80211: fix nl80211_start_radar_detection return value (Nicolas Escande)\n- rxrpc: Fix locking issues with the peer record hash (David Howells)\n- rxrpc: Disable IRQ, not BH, to take the lock for -attend_link (David Howells)\n- gpu: Fix uninitialized buddy for built-in drivers (Koen Koning)\n- net/mlx5e: Fix NULL pointer dereference in ioctl module EEPROM query (Gal Pressman)\n- usb: musb: omap2430: Do not put borrowed of_node in probe (Guangshuo Li) {CVE-2026-68371}\n- usb: musb: omap2430: clean up probe error handling (Johan Hovold)\n- USB: gadget: fsl-udc: fix dev_printk() device (Johan Hovold)\n- USB: gadget: Use str_enable_disable-like helpers (Krzysztof Kozlowski)\n- net: ipa: fix SMEM state handle leaks in SMP2P init (Haoxiang Li)\n- net: macb: drop in-flight Tx SKBs on close (Theo Lebrun) {CVE-2026-72017}\n- fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list (Reinette Chatre) {CVE-2026-72015}\n- ata: libata-core: Reject an invalid concurrent positioning ranges count (Bryam Vargas) {CVE-2026-72030}\n- octeontx2-pf: fix SQB pointer leak on init failure (Dawei Feng) {CVE-2026-72023}\n- net/mlx5: HWS, fix matcher leak on resize target setup failure (Dawei Feng) {CVE-2026-72032}\n- ipmi: fix refcount leak in i_ipmi_request() (Wentao Liang) {CVE-2026-72040}\n- bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline() (Breno Leitao)\n- bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c (Breno Leitao)\n- octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (Junrui Luo) {CVE-2026-72045}\n- gpio: mt7621: avoid corruption of shared interrupt trigger state (Sergio Paracuellos) {CVE-2026-72062}\n- gve: fix header buffer corruption with header-split and HW-GRO (Ankit Garg) {CVE-2026-72046}\n- net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) {CVE-2026-72051}\n- net: mana: Validate the packet length reported by the NIC (Dexuan Cui) {CVE-2026-72065}\n- locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (Thomas Gleixner) {CVE-2026-72069}\n- wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() (Maoyi Xie) {CVE-2026-72070}\n- dm: avoid leaking the caller's thread keyring via the table device file (Ingo Blechschmidt) {CVE-2026-72103}\n- cred: add scoped_with_kernel_creds() (Christian Brauner)\n- cred: add kernel_cred() helper (Christian Brauner)\n- cleanup: fix scoped_class() (Christian Brauner)\n- cleanup: add a scoped version of CLASS() (Christian Brauner)\n- dm-integrity: fix leaking uninitialized kernel memory (Mikulas Patocka) {CVE-2026-72101}\n- block: remove redundant GD_NEED_PART_SCAN in add_disk_final() (Connor Williamson)\n- block: add helper add_disk_final() (Ming Lei)\n- ovl: use linked upper dentry in copy-up tmpfile (Souvik Banerjee)\n- nvmet-auth: reject short AUTH_RECEIVE buffers (Michael Bommarito) {CVE-2026-72130}\n- nvmet: Introduce nvmet_req_transfer_len() (Damien Le Moal)\n- tcp: Decrement tcp_md5_needed static branch (Dmitry Safonov)\n- tcp: defer md5sig_info kfree past RCU grace period in tcp_connect (Michael Bommarito) {CVE-2026-72139}\n- xfrm: nat_keepalive: avoid double free on send error (Qianyu Luo) {CVE-2026-72137}\n- xfrm: Use nested-BH locking for nat_keepalive_sk_ipv[46] (Sebastian Andrzej Siewior)\n- i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (Vincent Jardin)\n- i2c: imx: separate atomic, dma and non-dma use case (Stefan Eichenberger)\n- dmaengine: dw-edma-pcie: Reject devices without driver data (Koichiro Den) {CVE-2026-72147}\n- dmaengine: dw-edma: Fix confusing cleanup.h syntax (Krzysztof Kozlowski)\n- dma: dw-edma: Fix build warning in dw_edma_pcie_probe() (Abinash Singh)\n- mm/sparse-vmemmap: fix DAX vmemmap accounting with optimization (Muchun Song)\n- mm: prepare to move subsection_map_init() to mm/sparse-vmemmap.c (David Hildenbrand (Arm))\n- mtd: maps: vmu-flash: fix fault in unaligned fixup (Florian Fuchs) {CVE-2026-72168}\n- mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages (Muchun Song)\n- landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path (Bryam Vargas) {CVE-2026-72183}\n- landlock: Prepare to use credential instead of domain for fowner (Mickael Salaun)\n- mm/sparse-vmemmap: fix vmemmap accounting underflow (Muchun Song)\n- mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch (Deepanshu Kartikey) {CVE-2026-72213}\n- remoteproc: xlnx: Check remote core state (Tanmay Shah)\n- SUNRPC: Return an error from xdr_buf_to_bvec() on overflow (Chuck Lever)\n- SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists (Chuck Lever)\n- sunrpc: allocate a separate bvec array for socket sends (Jeff Layton)\n- NFSD: pass nfsd_file to nfsd_iter_read() (Mike Snitzer)\n- gpu/buddy: bail out of try_harder when alignment cannot be honoured (Arunpravin Paneer Selvam) {CVE-2026-72244}\n- gpu: Move DRM buddy allocator one level up (part two) (Joel Fernandes)\n- netfilter: nft_fib: reject fib expression on the netdev egress hook (Theodor Arsenij Larionov-Trichkine) {CVE-2026-72254}\n- netfilter: nf_tables: remove register tracking infrastructure (Florian Westphal)\n- netfilter: nf_tables: Remove unused nft_reduce_is_readonly() (Yue Haibing)\n- netfilter: bitwise: rename some boolean operation functions (Jeremy Sowden)\n- netfilter: nf_conntrack_sip: validate skb_dst() before accessing it (Pablo Neira Ayuso) {CVE-2026-72253}\n- netfilter: nf_conntrack_sip: remove net variable shadowing (Florian Westphal)\n- ASoC: mediatek: mt8183: Check runtime resume during probe (Cassio Gabriel)\n- ASoC: mediatek: mt8183-afe-pcm: use local dev pointer in driver callbacks (Chen-Yu Tsai)\n- ASoC: mediatek: mt8183-afe-pcm: Support 32 bit DMA addresses (Chen-Yu Tsai)\n- ASoC: mediatek: mt8183-afe-pcm: Shorten memif_data table using macros (Chen-Yu Tsai)\n- ASoC: mediatek: mt8192: Check runtime resume during probe (Cassio Gabriel) {CVE-2026-72260}\n- ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable (Tang Bin)\n- arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers (Abel Vesa)\n- arm64: dts: qcom: correct RBR opp entry (Dmitry Baryshkov)\n- octeontx2-pf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)\n- octeontx2-vf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)\n- VDUSE: avoid leaking information to userspace (Jason Wang) {CVE-2026-72305}\n- vduse: take out allocations from vduse_dev_alloc_coherent (Eugenio Perez)\n- vduse: remove unused vaddr parameter of vduse_domain_free_coherent (Eugenio Perez)\n- vduse: Use fixed 4KB bounce pages for non-4KB page size (Sheng Zhao)\n- tipc: restrict socket queue dumps in enqueue tracepoints (Li Xiasong) {CVE-2026-72299}\n- rxrpc: Fix socket notification race (David Howells)\n- rxrpc: Fix notification vs call-release vs recvmsg (David Howells)\n- rxrpc: Use irq-disabling spinlocks between app and I/O thread (David Howells)\n- rxrpc: Don't need barrier for -tx_bottom and -acks_hard_ack (David Howells)\n- rxrpc: Fix CPU time starvation in I/O thread (David Howells)\n- fbcon: Use correct type for vc_resize() return value (Jiacheng Yu)\n- fbcon: Rename struct fbcon_ops to struct fbcon_par (Thomas Zimmermann)\n- xfs: don't replace the wrong part of the cow fork (Darrick J. Wong)\n- xfs: factor out xfs_attr3_leaf_init (Long Li)\n- rxrpc: serialize kernel accept preallocation with socket teardown (Li Daming) {CVE-2026-74436}\n- rxrpc: Pull out certain app callback funcs into an ops table (David Howells)\n- ALSA: hda: Fix cached processing coefficient verbs (Xu Rao)\n- ALSA: hda: conexant: Remove mic bias threshold override (Zhang Heng)\n- i2c: i801: fix hardware state machine corruption in error path (Mingyu Wang) {CVE-2026-64205}\n- audit: fix recursive locking deadlock in audit_dupe_exe() (Ricardo Robaina) {CVE-2026-68096}\n- audit: use 'unsigned int' instead of 'unsigned' (Ricardo Robaina)\n- audit: widen ino fields to u64 (Jeff Layton)\n- VFS/audit: introduce kern_path_parent() for audit (NeilBrown)\n- i2c: davinci: Unregister cpufreq notifier on probe failure (Haoxiang Li)\n- fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() (Sebastian Alba Vives) {CVE-2026-64280}\n- iommufd: Avoid partial fault group delivery in iommufd_fault_fops_read() (Nicolin Chen)\n- iommufd: Break the loop on failure in iommufd_fault_fops_read() (Nicolin Chen) {CVE-2026-64290}\n- iommufd: Reject invalid read count in iommufd_fault_fops_read() (Nicolin Chen)\n- mm/damon/core: disallow overlapping input ranges for damon_set_regions() (SJ Park) {CVE-2026-68164}\n- mm/damon/core: validate ranges in damon_set_regions() (SJ Park) {CVE-2026-68165}\n- rust: allow suspicious_runtime_symbol_definitions lint for Rust = 1.98 (Miguel Ojeda)\n- gve: fix Rx queue stall on alloc failure (Eddie Phillips) {CVE-2026-68129}\n- net: pcs: xpcs: fix SGMII state reading (Coia Prant)\n- io_uring/rw: fix missing ERESTARTSYS conversion in read paths (Yitang Yang)\n- drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources (Harry Wentland)\n- ksmbd: validate ACE size against SID sub-authorities (Namjae Jeon) {CVE-2026-68097}\n- ksmbd: bound DACL dedup walk to copied ACEs (Namjae Jeon) {CVE-2026-68098}\n- bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (Jiayuan Chen) {CVE-2026-53078}\n- drm/amdgpu: fix aperture mapping leak (Asad Kamal)\n- drm/amdgpu: invoke pm_genpd_remove() before freeing genpd (Ce Sun) {CVE-2026-68104}\n- drm/amdgpu: fix division by zero with invalid uvd dimensions (Boyuan Zhang) {CVE-2026-68106}\n- drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (Luca Coelho) {CVE-2026-68429}\n- drm/amdgpu/vcn4: avoid rereading IB param length (Boyuan Zhang) {CVE-2026-68107}\n- drm/amdgpu/vce: fix integer overflow in image size (Boyuan Zhang) {CVE-2026-68108}\n- drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68110}\n- drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68111}\n- drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68112}\n- drm/amdgpu/gfx8: drop unecessary BUG_ON() (Alex Deucher) {CVE-2026-68430}\n- drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68113}\n- drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68246}\n- drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68115}\n- drm/amd/pm: make pp_features read-only when scpm is enabled (Yang Wang)\n- drm/amd/pm: fix amdgpu_pm_info power display units (Yang Wang)\n- vxlan: mdb: Fix source list corruption on a failed replace (James Raphael Tiovalen) {CVE-2026-68116}\n- tipc: clear sock-sk on the failed-insert path in tipc_sk_create() (Daehyeon Ko) {CVE-2026-68117}\n- tcp: initialize standalone TCP-AO response padding (Yizhou Zhao) {CVE-2026-68119}\n- rtase: Workaround for TX hang caused by hardware packet parsing (Justin Lai) {CVE-2026-68120}\n- pppoe: reload header pointer after dev_hard_header() (Asim Viladi Oglu Manizada) {CVE-2026-68121}\n- openvswitch: fix GSO userspace truncation underflow (Kyle Zeng) {CVE-2026-68123}\n- mctp: serial: handle zero-length frames to prevent rx buffer overflow (Doruk Tan Ozturk) {CVE-2026-68124}\n- mac802154: llsec: reject frames shorter than the authentication tag (Doruk Tan Ozturk) {CVE-2026-68125}\n- mac802154: hold an interface reference across the scan worker (Ibrahim Hashimov) {CVE-2026-68126}\n- ila: reload IPv6 header after pskb_may_pull in checksum adjust (Michael Bommarito) {CVE-2026-68127}\n- ice: use READ_ONCE() to access cached PHC time (Sergey Temerkhanov)\n- ice: reject out-of-range ptype in ice_parser_profile_init (Aleksandr Loktionov) {CVE-2026-68128}\n- ksmbd: defer destroy_previous_session() until after NTLM authentication (James Montgomery) {CVE-2026-68130}\n- rbd: Reset positive result codes to zero in object map update path (Raphael Zimmer) {CVE-2026-68131}\n- ice: fix PTP Call Trace during PTP release (Paul Greenwalt) {CVE-2026-68133}\n- net: hip04: fix RX buffer leak on build_skb failure (Fan Wu) {CVE-2026-68135}\n- net: gro: fix double aggregation of flush-marked skbs (Shiming Cheng) {CVE-2026-68136}\n- net/x25: fix use-after-free in x25_kill_by_neigh() (David Lee) {CVE-2026-68137}\n- net/mlx5e: Use sender devcom for MPV master-up (Manjunath Patil) {CVE-2026-68139}\n- net/iucv: fix use-after-free of a severed iucv_path (Bryam Vargas) {CVE-2026-68140}\n- net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() (Hidayath Khan) {CVE-2026-68141}\n- geneve: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk) {CVE-2026-68142}\n- net: slip: serialize receive against buffer reallocation (Sungmin Kang) {CVE-2026-68143}\n- vxlan: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk) {CVE-2026-68432}\n- phonet: pep: fix use-after-free in pep_get_sb() (Breno Leitao) {CVE-2026-68144}\n- iommu/vt-d: Disallow SVA if page walk is not coherent (Lu Baolu)\n- iomap: fix out-of-bounds bitmap_set() with zero-length range (Zhang Yi) {CVE-2026-68145}\n- ftrace: Add global mutex to serialize trace_parser access (Tengda Wu) {CVE-2026-68146}\n- fscrypt: Add missing superblock check in find_or_insert_direct_key() (Eric Biggers) {CVE-2026-68148}\n- fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (Amir Goldstein) {CVE-2026-68149}\n- binfmt_elf_fdpic: only honour the first PT_INTERP (Christian Brauner) {CVE-2026-68151}\n- ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP (Chancel Liu)\n- amt: fix use-after-free in AMT delayed works (Shihuang Liu) {CVE-2026-68152}\n- libceph: remove debugfs files before client teardown (Douya Le) {CVE-2026-68153}\n- libceph: reject zero bucket types in crush_decode (Douya Le) {CVE-2026-68154}\n- libceph: Reject monmaps advertising zero monitors (Raphael Zimmer) {CVE-2026-68155}\n- libceph: refresh auth-authorizer_buf{,_len} after authorizer update (Shuangpeng Bai) {CVE-2026-68156}\n- libceph: guard missing CRUSH type name lookup (Zhao Zhang) {CVE-2026-68157}\n- libceph: Fix multiplication overflow in decode_new_up_state_weight() (Raphael Zimmer) {CVE-2026-68158}\n- libceph: bound get_version reply decode to front len (Douya Le) {CVE-2026-68433}\n- ceph: fix refcount leak in ceph_readdir() (WenTao Liang)\n- ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (Bryam Vargas) {CVE-2026-68160}\n- sctp: close UDP tunnel sockets during netns teardown (Zhiling Zou) {CVE-2026-68161}\n- sctp: avoid auth_enable sysctl UAF during netns teardown (Zhiling Zou) {CVE-2026-68162}\n- sctp: don't free the ASCONF's own transport in DEL-IP processing (Jun Yang) {CVE-2026-64564}\n- mptcp: only set DATA_FIN when a mapping is present (Michael Bommarito)\n- mptcp: decrement subflows counter on failed passive join (Chenguang Zhao)\n- Revert 'arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates' (Will Deacon)\n- arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates (Will Deacon)\n- tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() (Masami Hiramatsu (Google))\n- tracing/probes: Fix potential underflow in LEN_OR_ZERO macro (Masami Hiramatsu (Google))\n- tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args() (Masami Hiramatsu (Google))\n- tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() (Masami Hiramatsu (Google))\n- tracing: Fix resource leak on mmiotrace trace_pipe close (deepakraog) {CVE-2026-68175}\n- tracing: Fix mmiotrace possible NULL dereferencing of hiter-dev (Steven Rostedt) {CVE-2026-68176}\n- misc: nsm: pin the module while the device is open (Xu Rao) {CVE-2026-68178}\n- misc: nsm: only unlock nsm_dev on post-lock error paths (Runyu Xiao) {CVE-2026-68179}\n- intel_th: fix MSC output device reference leak (Guangshuo Li) {CVE-2026-68180}\n- mei: bus: access mei_device under device_lock on cleanup (Alexander Usyskin) {CVE-2026-68181}\n- serial: sc16is7xx: implement gpio get_direction() callback (Hugo Villeneuve)\n- uio_hv_generic: Bind to FCopy device by default (Ben Hutchings)\n- comedi: comedi_parport: deal with premature interrupt (Ian Abbott) {CVE-2026-68182}\n- x86/boot/compressed: Disable jump tables (Nathan Chancellor)\n- firmware: stratix10-svc: fix memory leaks and list corruption bugs (Tze Yee Ng) {CVE-2026-68183}\n- cdrom: fix stack out-of-bounds read in CDROMVOLCTRL (Xu Rao) {CVE-2026-68184}\n- LoongArch: Retrieve CPU package ID from PPTT when available (Rong Bao)\n- LoongArch: Move jump_label_init() before parse_early_param() (Kanglong Wang) {CVE-2026-68185}\n- LoongArch: Fix oops during single-step debugging (Haoran Jiang)\n- objtool/rust: add one more noreturn Rust function for Rust 1.99.0 (Miguel Ojeda)\n- rust: allow clippy::unwrap_or_default globally (Alexandre Courbot)\n- platform/loongarch: laptop: Explicitly reset bl_powered state when suspend (Zixing Liu)\n- binfmt_misc: set have_execfd only once the interpreter is opened (Christian Brauner) {CVE-2026-68186}\n- exec: fix unsigned loop counter wrap in transfer_args_to_stack() (Christian Brauner) {CVE-2026-68187}\n- Bluetooth: RFCOMM: Fix session UAF in set_termios (Chengfeng Ye) {CVE-2026-68188}\n- Bluetooth: hci_sync: Protect UUID list traversal (Chengfeng Ye) {CVE-2026-68189}\n- staging: rtl8723bs: fix inverted HT40 secondary channel offset (MinJea Kim)\n- staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() (Moksh Panicker) {CVE-2026-68190}\n- wifi: brcmfmac: make release_scratchbuffers idempotent (Fan Wu) {CVE-2026-68192}\n- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Devin Wittmayer) {CVE-2026-68193}\n- wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses (Devin Wittmayer) {CVE-2026-68194}\n- wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses (Devin Wittmayer) {CVE-2026-68195}\n- wifi: wilc1000: validate assoc response length before subtracting header (Huihui Huang) {CVE-2026-68196}\n- wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper (Doruk Tan Ozturk) {CVE-2026-68197}\n- wifi: ath6kl: fix OOB access from firmware ADDBA window size (Tristan Madani) {CVE-2026-68199}\n- ALSA: timer: don't re-enter an instance callback that is still running (Norbert Szetei) {CVE-2026-68200}\n- ALSA: timer: drain a slave's callback before its master detaches it (Norbert Szetei) {CVE-2026-68201}\n- ALSA: seq: close a re-opened queue timer in the destructor (Norbert Szetei) {CVE-2026-68202}\n- media: vpif_capture: fix OF node reference imbalance (Johan Hovold)\n- media: vivid: fix cleanup bugs in vivid_init() (Guangshuo Li) {CVE-2026-68203}\n- media: vivid: check for vb2_is_busy() when toggling caps (Hans Verkuil) {CVE-2026-68204}\n- media: vivid: add vivid_update_reduced_fps() (Hans Verkuil)\n- media: vimc: fix reference leak on failed device registration (Guangshuo Li)\n- media: vidtv: fix reference leak on failed device registration (Guangshuo Li)\n- media: vb2: use ssize_t for vb2_read/vb2_write (Zile Xiong)\n- media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely (Sakari Ailus)\n- media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (Mirela Rabulea) {CVE-2026-68205}\n- media: v4l2-ctrls: validate HEVC active reference counts (Pengpeng Hou) {CVE-2026-68206}\n- media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() (Sergey Shtylyov)\n- media: ti: vpe: unwind v4l2 device registration on probe error (Myeonghun Pak) {CVE-2026-68207}\n- media: tegra-video: vi: fix invalid u32 return value in format lookup (Hungyu Lin)\n- media: sun4i-csi: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68209}\n- media: stm32: dcmi: unregister notifier on probe failure (Myeonghun Pak) {CVE-2026-68210}\n- media: saa7134: Fix a possible memory leak in saa7134_video_init1 (Ma Ke) {CVE-2026-68212}\n- media: rtl2832_sdr: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68213}\n- media: rtl2832: fix use-after-free in rtl2832_remove() (Deepanshu Kartikey) {CVE-2026-68214}\n- media: radio-si476x: Unregister v4l2_device on probe failure (Myeonghun Pak) {CVE-2026-68215}\n- media: qcom: camss: Fix RDI streaming for CSID GEN2 (Bryan O'Donoghue)\n- media: pwc: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68216}\n- media: pwc: Drain fill_buf on start_streaming() failure (Valery Borovsky) {CVE-2026-68217}\n- media: pci: dm1105: Free allocated workqueue (Krzysztof Kozlowski) {CVE-2026-68218}\n- media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding (Guoniu Zhou)\n- media: nxp: imx8-isi: Fix potential out-of-bounds issues (Guoniu Zhou) {CVE-2026-68219}\n- media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path (Xiaolei Wang)\n- media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure (Xiaolei Wang)\n- media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe (Xiaolei Wang) {CVE-2026-68220}\n- media: nuvoton: npcm-video: fix memory leaks in probe and remove (David Carlier) {CVE-2026-68221}\n- media: nuvoton: npcm-video: fix error handling in npcm_video_init() (David Carlier)\n- media: msi2500: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68222}\n- media: meson: vdec: Fix memory leak in error path of vdec_open (Anand Moon) {CVE-2026-68223}\n- media: marvell-cam: fix missing pci_disable_device() on remove (Guangshuo Li)\n- media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges (Marco Nenciarini)\n- media: i2c: alvium: fix critical pointer access in alvium_ctrl_init (Martin Hecht) {CVE-2026-68225}\n- media: cx23885: add ioremap return check and cleanup (Wang Jun) {CVE-2026-68226}\n- media: cx231xx: fix devres lifetime (Johan Hovold) {CVE-2026-68227}\n- media: chips-media: wave5: Move src_buf Removal to finish_encode (Brandon Brnich) {CVE-2026-68228}\n- media: cedrus: skip invalid H.264 reference list entries (Pengpeng Hou) {CVE-2026-68229}\n- media: cedrus: Fix missing cleanup in error path (Samuel Holland)\n- media: cedrus: clean up media device on probe failure (Myeonghun Pak)\n- media: cec: seco: unregister adapter on IR probe failure (Myeonghun Pak)\n- media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (David Carlier)\n- media: airspy: Return queued buffers on start_streaming() failure (Valery Borovsky) {CVE-2026-68231}\n- drm/vc4: Prevent shader BO mappings from becoming writable (Linmao Li) {CVE-2026-68445}\n- drm/vmwgfx: Validate vmw_surface_metadata::array_size (Ian Forbes) {CVE-2026-68446}\n- drm/amdgpu: fix bo-pin leaking in amdgpu_bo_create_reserved (Zhu Lingshan) {CVE-2026-68234}\n- drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge (Mario Limonciello)\n- drm/amd/display: dce100: skip non-DP stream encoders for DP MST (Andriy Korud) {CVE-2026-68235}\n- drm/amd/display: set new_stream to NULL after release (WenTao Liang) {CVE-2026-68236}\n- drm/amdgpu: Fix VFCT bus number matching with soft filter (Mario Limonciello)\n- drm/panthor: return error on truncated firmware (Osama Abdelkader)\n- drm/gfx10: Program DB_RING_CONTROL (Alex Deucher)\n- drm/amd/pm: fix smu14 power limit range calculation (Yang Wang)\n- drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (Joonas Lahtinen) {CVE-2026-68243}\n- drm/i915/gem: Do not leak siblings[] on proto context error (Joonas Lahtinen) {CVE-2026-68244}\n- drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() (Shahyan Soltani) {CVE-2026-68245}\n- drm/i915/bios: range check LFP Data Block panel_type2 (Jani Nikula) {CVE-2026-68247}\n- drm/i915: Return NULL on error in active_instance (Joonas Lahtinen) {CVE-2026-68248}\n- drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68249}\n- drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68250}\n- drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68251}\n- drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() (Alex Deucher) {CVE-2026-68252}\n- drm/virtio: bound EDID block reads to the response buffer (Bryam Vargas) {CVE-2026-68255}\n- drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (WenTao Liang) {CVE-2026-68256}\n- drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (Thomas Zimmermann)\n- drm/amdkfd: fix 32-bit overflow in CWSR total size calculation (Yongqiang Sun) {CVE-2026-68257}\n- drm/amdkfd: Check bounds in allocate_event_notification_slot (David Francis) {CVE-2026-68259}\n- drm/amdkfd: Use kvcalloc to allocate arrays (David Francis)\n- drm/imagination: acquire vm_ctx-lock before mapping memory to GPU VM (Icenowy Zheng) {CVE-2026-68260}\n- drm/imagination: fix error checking of pvr_vm_context_lookup() (Luigi Santivetti) {CVE-2026-68261}\n- drm/imagination: Fix user array stride in pvr_set_uobj_array() (Shuvam Pandey) {CVE-2026-68262}\n- drm/imagination: Fix double call to drm_sched_entity_fini() (Brajesh Gupta) {CVE-2026-68263}\n- drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds (Matthew Brost)\n- drm/radeon: fix r100_copy_blit for large BOs (Pavel Ondracka)\n- drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (Wentao Liang)\n- drm/i915/gem: Add missing nospec on parallel submit slot (Joonas Lahtinen) {CVE-2026-68269}\n- drm/displayid: fix Tiled Display Topology ID size (Jani Nikula)\n- drm/nouveau: fix reversed error cleanup order in ucopy functions (Junrui Luo) {CVE-2026-68271}\n- drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (Mario Limonciello) {CVE-2026-68272}\n- drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (Timur Kristof)\n- drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older (Timur Kristof)\n- drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2) (Timur Kristof)\n- drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (Ashutosh Desai) {CVE-2026-68277}\n- drm/imagination: Fit paired fragment job in the correct CCCB (Alessio Belle) {CVE-2026-68437}\n- drm/dp/mst: fix buffer overflows in sideband chunk accumulation (Ashutosh Desai) {CVE-2026-68278}\n- drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (Ashutosh Desai) {CVE-2026-68279}\n- drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (Vitor Soares) {CVE-2026-68280}\n- drm/imagination: Count paired job fence as dependency in prepare_job() (Alessio Belle) {CVE-2026-68281}\n- drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (Sergey Shtylyov)\n- drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (Biju Das)\n- bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (Chengfeng Ye) {CVE-2026-68284}\n- ice: fix LAG recipe to profile association (Marcin Szycik)\n- ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV (Vincent Chen)\n- net: ipv6: fix dif and sdif mismatch in raw6_icmp_error (Li RongQing)\n- net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation (Alexei Lazar)\n- net/mlx5e: Report zero bandwidth for non-ETS traffic classes (Alexei Lazar)\n- net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule (Yael Chemla)\n- net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (Gal Pressman) {CVE-2026-68293}\n- net/mlx5: Refactor EEPROM query error handling to return status separately (Gal Pressman)\n- net: qrtr: restrict socket creation to the initial network namespace (Aldo Ariel Panzardo) {CVE-2026-68294}\n- hinic: remove unused ethtool RSS user configuration buffers (Chenguang Zhao)\n- ppp: annotate data races in ppp_generic (Eric Dumazet)\n- ppp: enable TX scatter-gather (Qingfang Deng)\n- ppp: convert to percpu netstats (Qingfang Deng)\n- ppp: use IFF_NO_QUEUE in virtual interfaces (Qingfang Deng)\n- ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup (Eric Dumazet)\n- net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM (Yun Zhou) {CVE-2026-68296}\n- net: stmmac: enable the MAC on link up for all supported speeds (vadik likholetov)\n- net: stmmac: reset residual action in L3L4 filters on delete (Nazim Amirul)\n- net: stmmac: fix l3l4 filter rejecting unsupported offload requests (Nazim Amirul)\n- drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem (Jose Exposito)\n- tipc: fix u16 MTU truncation in media and bearer MTU validation (Cen Zhang (Microsoft))\n- iomap: correct the range of a partial dirty clear (Zhang Yi)\n- vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (Harshaka Narayana) {CVE-2026-68299}\n- sctp: auth: verify auth requirement when auth_chunk is NULL (Qing Luo) {CVE-2026-68300}\n- net: dpaa: fix mode setting (Michael Walle)\n- net: hsr: fix memory leak on slave unregistration by removing synced VLANs (Eric Dumazet) {CVE-2026-68301}\n- net: bridge: vlan: fix vlan range dumps starting with pvid (Nikolay Aleksandrov)\n- amt: make the head writable before rewriting the L2 header (Michael Bommarito)\n- amt: re-read skb header pointers after every pull (Michael Bommarito) {CVE-2026-68302}\n- ovl: fix trusted xattr escape prefix matching (Yichong Chen)\n- wifi: brcmfmac: fix 802.1X-SHA256 call trace warning (Shelley Yang) {CVE-2026-68304}\n- wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() (Lorenzo Bianconi) {CVE-2026-68306}\n- wifi: mt76: mt7925: fix crash in reset link replay (Sean Wang) {CVE-2026-68307}\n- wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() (Lorenzo Bianconi) {CVE-2026-68308}\n- wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv() (Lorenzo Bianconi) {CVE-2026-68439}\n- wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() (Lorenzo Bianconi) {CVE-2026-68309}\n- wifi: mt76: mt7915: guard HE capability lookups (Ruoyu Wang) {CVE-2026-68310}\n- wifi: mt76: mt7925: guard link STA in decap offload (Guangshuo Li) {CVE-2026-68311}\n- tipc: fix infinite loop in __tipc_nl_compat_dumpit (Helen Koike) {CVE-2026-68313}\n- nexthop: initialize extack in nh_res_bucket_migrate() (Xiang Mei (Microsoft))\n- gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (Xiang Mei (Microsoft))\n- selftests: openvswitch: add config file (Matthieu Baerts (NGI0))\n- selftests: af_unix: add USER_NS config (Matthieu Baerts (NGI0))\n- tls: device: push pending open record on splice EOF (Rishikesh Jethwani)\n- net: mctp i3c: clean up notifier and buses if driver register fails (Myeonghun Pak) {CVE-2026-68314}\n- sctp: validate stream count in sctp_process_strreset_inreq() (Cen Zhang (Microsoft))\n- pds_core: check for workqueue allocation failure (Nikhil P. Rao)\n- pds_core: fix auxiliary device add/del races (Nikhil P. Rao) {CVE-2026-68317}\n- pds_core: order completion reads after the ownership check (Nikhil P. Rao)\n- pds_core: yield the CPU while waiting for the adminq to drain (Nikhil P. Rao)\n- pds_core: fix use-after-free on workqueue during remove (Nikhil P. Rao) {CVE-2026-68318}\n- pds_core: fix deadlock between reset thread and remove (Nikhil P. Rao) {CVE-2026-68319}\n- sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (HanQuan) {CVE-2026-68320}\n- net: txgbe: fix FDIR filter leak on remove (Chenguang Zhao) {CVE-2026-68321}\n- amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN (Prashanth Kumar KR)\n- pds_core: reject component parameter in legacy firmware update (Nikhil P. Rao)\n- wifi: mac80211: recalculate TIM when a station enters power save (Andrew Pope)\n- iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (Li RongQing) {CVE-2026-68324}\n- iommu/amd: Bound the early ACPI HID map (Pengpeng Hou) {CVE-2026-68325}\n- wifi: mwifiex: bound uAP association event IEs to the event buffer (HE WEI (???))\n- wan: wanxl: Only reset hardware after BAR mapping (Ruoyu Wang) {CVE-2026-68327}\n- nfp: Check resource mutex allocation (Ruoyu Wang) {CVE-2026-68328}\n- wifi: mac80211: tear down new links on vif update error path (Xiang Mei) {CVE-2026-64574}\n- iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (Guanghui Feng) {CVE-2026-68329}\n- dpaa2-eth: put MAC endpoint device on disconnect (Guangshuo Li) {CVE-2026-68331}\n- dpaa2-switch: put MAC endpoint device on disconnect (Guangshuo Li) {CVE-2026-68333}\n- gtp: parse extension headers before reading inner protocol (Zhixing Chen)\n- bonding: fix devconf_all NULL dereference when IPv6 is disabled (Zhaolong Zhang) {CVE-2026-68336}\n- net/packet: avoid fanout hook re-registration after unregister (David Lee) {CVE-2026-68338}\n- netlink: specs: rt-link: convert bridge port flag attributes to u8 (Danielle Ratson)\n- Bluetooth: btusb: validate Realtek vendor event length (Pengpeng Hou) {CVE-2026-68339}\n- regulator: mt6358: use regmap helper to read fixed LDO calibration (Daniel Golle)\n- hwmon: occ: validate poll response sensor blocks (Pengpeng Hou) {CVE-2026-68340}\n- smb: client: validate DFS referral PathConsumed (Yichong Chen) {CVE-2026-68343}\n- hwmon: (asus-ec-sensors) add missed handle for ENOMEM (Eugene Shalygin)\n- hwmon: (asus-ec-sensors) fix EC read intervals (Eugene Shalygin)\n- hwmon: (asus-ec-sensors) fix looping over banks while reading from EC (Eugene Shalygin)\n- drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook() (Mostafa Saleh)\n- wifi: iwlwifi: mvm: fix read in wake packet notification handler (Shahar Tzarfati)\n- wifi: iwlwifi: mvm: validate SAR GEO response payload size (Pagadala Yesu Anjaneyulu)\n- ASoC: cs35l56: Use complete_all() to signal init_completion (Richard Fitzgerald)\n- ASoC: cs35l56: Fix potential probe() deadlock (Richard Fitzgerald)\n- ASoC: cs35l56: Don't use devres to unregister component (Richard Fitzgerald)\n- ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI (Shengjiu Wang)\n- ALSA: hda: cs35l41: validate and free ACPI mute object (Guangshuo Li) {CVE-2026-68346}\n- ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state() (Denis Arefev)\n- ASoC: tas2781: bound firmware description string parsing (Pengpeng Hou) {CVE-2026-68348}\n- btrfs: free mapping node on duplicate reloc root insert (Guanghui Yang) {CVE-2026-68450}\n- btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps (Leo Martins) {CVE-2026-68442}\n- btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8 (You-Kai Zheng)\n- wifi: carl9170: fix buffer overflow in rx_stream failover path (Tristan Madani) {CVE-2026-68349}\n- wifi: carl9170: fix OOB read from off-by-two in TX status handler (Tristan Madani) {CVE-2026-68350}\n- wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read (Tristan Madani) {CVE-2026-68351}\n- wifi: ath6kl: fix OOB read from firmware IE lengths in connect event (Tristan Madani) {CVE-2026-68352}\n- wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler (Tristan Madani) {CVE-2026-68353}\n- firewire: net: Fix fragmented datagram reassembly (Ruoyu Wang) {CVE-2026-68354}\n- wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (Manivannan Sadhasivam)\n- wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (Manivannan Sadhasivam)\n- wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() (Dmitry Morgun) {CVE-2026-68355}\n- watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() (Tzung-Bi Shih) {CVE-2026-68357}\n- hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop (Guenter Roeck) {CVE-2026-68358}\n- hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop (Guenter Roeck) {CVE-2026-68359}\n- hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop (Guenter Roeck) {CVE-2026-68443}\n- hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop (Guenter Roeck) {CVE-2026-68360}\n- hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop (Edward Adam Davis) {CVE-2026-68361}\n- wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin (Gaole Zhang) {CVE-2026-68362}\n- wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (Cheng Yongkang) {CVE-2026-68363}\n- usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits (Xincheng Zhang)\n- RISC-V: KVM: Serialize virtual interrupt pending state updates (Xie Bo)\n- crypto: rsa-pkcs1pad: Don't WARN on an empty digest (Doruk Tan Ozturk)\n- USB: serial: option: add TDTECH MT5710-CN (Chukun Pan)\n- USB: serial: keyspan_pda: fix data loss on receive throttling (Johan Hovold)\n- USB: serial: io_edgeport: cap received transmit credits (Sunho Park) {CVE-2026-68365}\n- USB: serial: ftdi_sio: add support for E+H FXA291 (Tim Pambor)\n- usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer (Muhammad Bilal) {CVE-2026-68366}\n- usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown (Fan Wu) {CVE-2026-64583}\n- usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() (Sonali Pradhan) {CVE-2026-68368}\n- USB: gadget: fsl-udc: fix device name leak on probe failure (Johan Hovold)\n- USB: gadget: snps-udc: fix device name leak on probe failure (Johan Hovold)\n- usb: gadget: printer: fix infinite loop in printer_read() (Melbin K Mathew) {CVE-2026-68369}\n- usb: gadget: f_midi: cancel pending IN work before freeing the midi object (Fan Wu) {CVE-2026-64584}\n- usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback (Jinchao Wang) {CVE-2026-68370}\n- usb: chipidea: fix usage_count leak when autosuspend_delay is negative (Xu Yang)\n- USB: storage: add NO_ATA_1X quirk for Longmai USB Key (Huang Wei)\n- usb: core: port: Deattach Type-C connector on component unbind (Chia-Lin Kao (AceLan))\n- wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() (Huihui Huang) {CVE-2026-68373}\n- usb: core: sysfs: add lock to bos_descriptors_read() (Griffin Kroah-Hartman) {CVE-2026-68374}\n- mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (Weiming Shi) {CVE-2026-64569}\n- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) {CVE-2026-68376}\n- net/sched: act_tunnel_key: Defer dst_release to RCU callback (Jamal Hadi Salim) {CVE-2026-68377}\n- drm/i915/selftests: Fix GT PM sort comparators (Emre Cecanpunar)\n- ksmbd: validate compound request size before reading StructureSize2 (Xiang Mei (Microsoft))\n- ksmbd: pin conn during async oplock break notification (Qihang) {CVE-2026-68381}\n- smb: move some duplicate definitions to common/cifsglob.h (ZhangGuoDong)\n- drm/xe/wopcm: fix WOPCM size for LNL+ (Daniele Ceraolo Spurio)\n- can: j1939: fix lockless local-destination check (Shuhao Fu)\n- riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus() (Mark Harris)\n- s390/checksum: Fix csum_partial() without vector facility (Vasily Gorbik) {CVE-2026-68385}\n- bpf, sockmap: Reject unhashed UDP sockets on sockmap update (Michal Luczaj) {CVE-2026-68386}\n- powerpc/vtime: Initialize starttime at boot for native accounting (Shrikanth Hegde)\n- powerpc/time: Prepare to stop elapsing in dynticks-idle (Frederic Weisbecker)\n- powerpc/85xx: Add fsl,ifc to common device ids (Rosen Penev)\n- drm/i915/gt: use correct selftest config symbol (Pengpeng Hou)\n- smb/client: handle overlapping allocated ranges in fallocate (Huiwen He) {CVE-2026-68388}\n- Bluetooth: hci_qca: Clear memdump state on invalid dump size (Ruoyu Wang) {CVE-2026-68389}\n- Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (Pauli Virtanen) {CVE-2026-68391}\n- Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync (Pauli Virtanen) {CVE-2026-68392}\n- Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update (Cen Zhang) {CVE-2026-68394}\n- Bluetooth: qca: fix NVM tag length underflow in TLV parser (Xiang Mei) {CVE-2026-64573}\n- ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (Takashi Iwai)\n- accel/ivpu: Fix wrong register read in LNL failure diagnostics (Karol Wachowski)\n- ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning (Rosen Penev) {CVE-2026-68449}\n- ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts (Rosen Penev)\n- ata: sata_dwc_460ex: use platform_get_irq() (Rosen Penev)\n- ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered (Rosen Penev) {CVE-2026-68395}\n- net/iucv: take a reference on the socket found in afiucv_hs_rcv() (Bryam Vargas) {CVE-2026-68397}\n- ipv4: fib: free fib_alias with kfree_rcu() on insert error path (Weiming Shi) {CVE-2026-64572}\n- ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (Norbert Szetei) {CVE-2026-68398}\n- cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq (Rafael J. Wysocki)\n- firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context (Pushpendra Singh)\n- ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (Uday Khare)\n- ASoC: cs42l43: Correct report for forced microphone jack (Charles Keepax)\n- ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() (Vijendar Mukunda)\n- ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (Christian Hewitt)\n- wifi: cfg80211: bound element ID read when checking non-inheritance (HE WEI (???))\n- wifi: brcmfmac: initialize SDIO data work before cleanup (Runyu Xiao) {CVE-2026-68403}\n- wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (Cen Zhang) {CVE-2026-68405}\n- wifi: cfg80211: reject unsupported PMSR FTM location requests (Zhao Li)\n- wifi: cfg80211: validate PMSR FTM preamble range (Zhao Li) {CVE-2026-68406}\n- wifi: cfg80211: validate PMSR measurement type data (Zhao Li)\n- wifi: nl80211: validate nested MBSSID IE blobs (Zhao Li)\n- wifi: cfg80211: derive S1G beacon TSF from S1G fields (Zhao Li)\n- wifi: nl80211: free RNR data on MBSSID mismatch (Zhao Li) {CVE-2026-68407}\n- wifi: p54: validate RX frame length in p54_rx_eeprom_readback() (Xiang Mei) {CVE-2026-64571}\n- wifi: libertas: fix memory leak in helper_firmware_cb() (Dawei Feng) {CVE-2026-68410}\n- wifi: mac80211: fix fils_discovery double free on alloc failure (Xiang Mei) {CVE-2026-64570}\n- wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure (Xiang Mei) {CVE-2026-64568}\n- wifi: mac80211_hwsim: clamp virtio RX length before skb_put (Bryam Vargas) {CVE-2026-68411}\n- wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (Abdun Nihaal) {CVE-2026-68413}\n- wifi: cfg80211: cancel sched scan results work on unregister (Cen Zhang) {CVE-2026-68414}\n- xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert (Xiang Mei (Microsoft))\n- xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() (Xiang Mei (Microsoft))\n- RDMA/irdma: Prevent overflows in memory contiguity checks (Aleksandrova Alyona)\n- selftests/alsa: Fix memory leak in find_controls error path (Malaya Kumar Rout)\n- mtd: fix double free and WARN_ON in add_mtd_device() error paths (Xue Lei) {CVE-2026-68416}\n- RDMA/siw: publish QP after initialization (Ruoyu Wang) {CVE-2026-68417}\n- RDMA/hns: Fix potential integer overflow in mhop hem cleanup (Danila Chernetsov)\n- RDMA/erdma: initialize ret for empty receive WR lists (Ruoyu Wang)\n- RDMA/irdma: Prevent rereg_mr for non-mem regions (Jacob Moroni) {CVE-2026-68419}\n- RDMA/umem: Add pinned revocable dmabuf import interface (Jacob Moroni)\n- RDMA/cma: Fix hardware address comparison length in netevent callback (Or Gerlitz)\n- firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (Unnathi Chalicheemala) {CVE-2026-68444}\n- btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (Filipe Manana) {CVE-2026-68422}\n- btrfs: reject free space cache with more entries than pages (Xiang Mei) {CVE-2026-64567}\n- mtd: nand: mtk-ecc: stop on ECC idle timeouts (Pengpeng Hou)\n- mtd: mtdswap: remove debugfs stats file on teardown (Pengpeng Hou)\n- IB/mad: Drop unmatched RMPP responses before reassembly (Michael Bommarito) {CVE-2026-68425}\n- arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234 (Sumit Gupta)\n- soc: qcom: ice: Allow explicit votes on 'iface' clock for ICE (Harshal Dev)\n- Input: ims-pcu - fix logic error in packet reset (Dmitry Torokhov)\n- Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (Seungjin Bae) {CVE-2026-64565}\n- xprtrdma: Clear receive-side ownership pointers on release (Chuck Lever)\n- crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin (Mikko Perttunen)\n- gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings (Mikko Perttunen) {CVE-2026-68427}\n- dmaengine: sh: rz-dmac: Move interrupt request after everything is set up (Claudiu Beznea) {CVE-2026-72146}\n- can: isotp: serialize TX state transitions under so-rx_lock (Oliver Hartkopp) {CVE-2026-72124}\n- can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER (Oliver Hartkopp) {CVE-2026-72125}\n- can: bcm: track a single source interface for ANYDEV timeout/throttle ops (Oliver Hartkopp) {CVE-2026-72115}\n- can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() (Oliver Hartkopp) {CVE-2026-72117}\n- can: bcm: fix stale rx/tx ops after device removal (Oliver Hartkopp) {CVE-2026-72116}\n- can: bcm: add missing device refcount for CAN filter removal (Oliver Hartkopp) {CVE-2026-72113}\n- can: bcm: validate frame length in bcm_rx_setup() for RTR replies (Oliver Hartkopp) {CVE-2026-72114}\n- can: bcm: extend bcm_tx_lock usage for data and timer updates (Oliver Hartkopp) {CVE-2026-72119}\n- can: bcm: fix CAN frame rx/tx statistics (Oliver Hartkopp) {CVE-2026-72118}\n- can: bcm: add locking when updating filter and timer values (Oliver Hartkopp) {CVE-2026-72121}\n- KVM: x86/mmu: Fix use-after-free on vendor module reload (Phil Rosenthal) {CVE-2026-68428}\n- KVM: nVMX: Hide shadow VMCS right after VMCLEAR (Hyunwoo Kim) {CVE-2026-64562}\n- KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN (Venkatesh Srinivas)\n- seqlock: Allow UBSAN_ALIGNMENT to fail optimizing (Heiko Carstens)\n- seqlock: Allow KASAN to fail optimizing (Peter Zijlstra)\n- seqlock: Cure some more scoped_seqlock() optimization fails (Peter Zijlstra)\n- fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race (Kiryl Shutsemau) {CVE-2026-72175}\n- drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker (Ryosuke Yasuoka)\n- netfilter: nf_tables: revert commit_mutex usage in reset path (Brian Witte) {CVE-2026-45901}\n- netfilter: nft_quota: use atomic64_xchg for reset (Brian Witte)\n- netfilter: nft_counter: serialize reset with spinlock (Brian Witte) {CVE-2026-45897}\n- selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs (Daniel Borkmann)\n- bpf: Fix ld_{abs,ind} failure path analysis in subprogs (Daniel Borkmann) {CVE-2026-53090}\n- net: airoha: Move airoha_eth driver in a dedicated folder (Lorenzo Bianconi)\n- platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug (Guixiong Wei)\n\n[6.12.0-206.100.3]\n- can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure (Guangshuo Li) {CVE-2026-74459}\n- ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes (Norbert Szetei) {CVE-2026-74503}\n- sched/deadline: Use revised wakeup rule only for running dl_server (Gabriele Monaco)\n- scsi: ufs: core: Cancel RTC work in active-active suspend (Guangshuo Li)\n- net: airoha: Fix register index for Tx-fwd counter configuration (Wayen Yan)\n- netfilter: nf_conntrack_expect: restore helper propagation via expectation (Pablo Neira Ayuso)\n- Enable Time slice extension (Prakash Sangappa) [Orabug: 39047408]\n- rseq: Increase struct rseq size to match mainline linux (Prakash Sangappa) [Orabug: 39047408]\n- selftests/rseq: Make registration flexible for legacy and optimized mode (Thomas Gleixner) [Orabug: 39047408]\n- selftests/rseq: Skip tests if time slice extensions are not available (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Don't advertise time slice extensions if disabled (Thomas Gleixner) [Orabug: 39047408]\n- selftests/rseq: Add rseq slice histogram script (Peter Zijlstra) [Orabug: 39047408]\n- rseq: Lower default slice extension (Peter Zijlstra) [Orabug: 39047408]\n- rseq: Move slice_ext_nsec to debugfs (Peter Zijlstra) [Orabug: 39047408]\n- rseq: Allow registering RSEQ with slice extension (Peter Zijlstra) [Orabug: 39047408]\n- selftests/rseq: Implement time slice extension test (Thomas Gleixner) [Orabug: 39047408]\n- entry: Hook up rseq time slice extension (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Implement rseq_grant_slice_extension() (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Reset slice extension when scheduled (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Implement time slice extension enforcement timer (Prakash Sangappa) [Orabug: 39047408]\n- rseq: Implement syscall entry work for time slice extensions (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Implement sys_rseq_slice_yield() (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Add prctl() to enable time slice extensions (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Add statistics for time slice extensions (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Provide static branch for runtime debugging (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Expose lightweight statistics in debugfs (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Provide static branch for time slice extensions (Thomas Gleixner) [Orabug: 39047408]\n- rseq: Add fields and constants for time slice extension (Prakash Sangappa) [Orabug: 39047408]\n- Revert 'Sched: Scheduler time slice extension' (Prakash Sangappa) [Orabug: 39047408]\n- Revert 'Sched: Add scheduler stat for cpu time slice extension' (Prakash Sangappa) [Orabug: 39047408]\n- Revert 'Scheduler extension change under Oracle Extensions and modify enum value' (Prakash Sangappa) [Orabug: 39047408]\n- net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover (Matt Fleming) [Orabug: 39203117,39870622] {CVE-2026-64122}\n- net/mlx5e: Fix deadlocks between devlink and netdev instance locks (Cosmin Ratiu) [Orabug: 39203117,39870450] {CVE-2026-45907}\n- net/mlx5: HWS, ignore flow level for multi-dest table (Yevgeny Kliteynik) [Orabug: 39203117]\n- net/mlx5: Prevent flow steering mode changes in switchdev mode (Moshe Shemesh) [Orabug: 39203117]\n- net/mlx5: HWS, Fix pattern destruction in mlx5hws_pat_get_pattern error path (Lama Kayal) [Orabug: 39203117]\n- net/mlx5: HWS, Fix memory leak in hws_action_get_shared_stc_nic error flow (Lama Kayal) [Orabug: 39203117]\n- net/mlx5: HWS, Fix memory leak in hws_pool_buddy_init error path (Lama Kayal) [Orabug: 39203117]\n- selftests: drv-net: hds: restore hds settings (Jakub Kicinski) [Orabug: 39203117]\n- net/mlx5: Restore missing scheduling node cleanup on vport enable failure (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: Fix QoS reference leak in vport enable error path (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: Destroy vport QoS element when no configuration remains (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5e: Preserve tc-bw during parent changes (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: Remove default QoS group and attach vports directly to root TSAR (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: HWS, Fix table creation UID (Alex Vesker) [Orabug: 39203117]\n- net/mlx5: HWS, don't rehash on every kind of insertion failure (Yevgeny Kliteynik) [Orabug: 39203117]\n- selftests: drv-net: wait for carrier (Jakub Kicinski) [Orabug: 39203117]\n- netdevsim: Fix wild pointer access in nsim_queue_free(). (Kuniyuki Iwashima) [Orabug: 39203117]\n- vfio/pci: Do vf_token checks for VFIO_DEVICE_BIND_IOMMUFD (Jason Gunthorpe) [Orabug: 39203117]\n- net/mlx5e: Expose TIS via devlink tx reporter diagnose (Feng Liu) [Orabug: 39203117]\n- net/mlx5e: Fix potential deadlock by deferring RX timeout recovery (Shahar Shitrit) [Orabug: 39203117]\n- selftests: drv-net: Make command requirements explicit (Gal Pressman) [Orabug: 39203117]\n- net/mlx5: Fix build -Wframe-larger-than warnings (Zhu Yanjun) [Orabug: 39203117]\n- mlx5: access -pp through netmem_desc instead of page (Byungchul Park) [Orabug: 39203117]\n- netdevsim: access -pp through netmem_desc instead of page (Byungchul Park) [Orabug: 39203117]\n- netmem, mlx4: access -pp_ref_count through netmem_desc instead of page (Byungchul Park) [Orabug: 39203117]\n- netmem: use netmem_desc instead of page to access -pp in __netmem_get_pp() (Byungchul Park) [Orabug: 39203117]\n- netmem: introduce struct netmem_desc mirroring struct page (Byungchul Park) [Orabug: 39203117]\n- netdevsim: add fw_update_flash_chunk_time_ms debugfs knobs (Jiri Pirko) [Orabug: 39203117]\n- devlink: Fix excessive stack usage in rate TC bandwidth parsing (Carolina Jubran) [Orabug: 39203117]\n- RDMA/mlx5: Refactor optional counters steering code (Patrisious Haddad) [Orabug: 39203117]\n- RDMA/mlx5: Add DMAH object support (Yishai Hadas) [Orabug: 39203117]\n- RDMA/core: Introduce a DMAH object and its alloc/free APIs (Yishai Hadas) [Orabug: 39203117]\n- IB/core: Add UVERBS_METHOD_REG_MR on the MR object (Yishai Hadas) [Orabug: 39203117]\n- net/mlx5: Add support for device steering tag (Yishai Hadas) [Orabug: 39203117]\n- net/mlx5: Expose IFC bits for TPH (Yishai Hadas) [Orabug: 39203117]\n- PCI/TPH: Expose pcie_tph_get_st_table_size() (Yishai Hadas) [Orabug: 39203117]\n- net/mlx5e: Remove duplicate mkey from SHAMPO header (Lama Kayal) [Orabug: 39203117]\n- net/mlx5e: SHAMPO, Remove mlx5e_shampo_get_log_hd_entry_size() (Lama Kayal) [Orabug: 39203117]\n- net/mlx5e: SHAMPO, Cleanup reservation size formula (Lama Kayal) [Orabug: 39203117]\n- selftests: drv-net: Test XDP_PASS/DROP support (Mohsin Bashir) [Orabug: 39203117]\n- net: netdevsim: hook in XDP handling (Jakub Kicinski) [Orabug: 39203117]\n- RDMA/mlx5: Fix incorrect MKEY masking (Leon Romanovsky) [Orabug: 39203117]\n- RDMA/mlx5: Fix returned type from _mlx5r_umr_zap_mkey() (Leon Romanovsky) [Orabug: 39203117]\n- net/mlx5: Expose cable_length field in PFCC register (Oren Sidi) [Orabug: 39203117]\n- net/mlx5: Add IFC bits to support RSS for IPSec offload (Jianbo Liu) [Orabug: 39203117]\n- net/mlx5e: fix kdoc warning on eswitch.h (Moshe Shemesh) [Orabug: 39203117]\n- net/mlx5: HWS, Enable IPSec hardware offload in legacy mode (Lama Kayal) [Orabug: 39203117]\n- net/mlx5: Fix an IS_ERR() vs NULL bug in esw_qos_move_node() (Dan Carpenter) [Orabug: 39203117]\n- netdevsim: remove redundant branch (Dennis Chen) [Orabug: 39203117]\n- selftests: net: prevent Python from buffering the output (Jakub Kicinski) [Orabug: 39203117]\n- netlink: specs: define input-xfrm enum in the spec (Jakub Kicinski) [Orabug: 39203117]\n- net/mlx5e: TX, Fix dma unmapping for devmem tx (Dragos Tatulea) [Orabug: 39203117]\n- RDMA/mlx5: remove redundant check on err on return expression (Colin Ian King) [Orabug: 39203117]\n- net/mlx5e: Add device PCIe congestion ethtool stats (Dragos Tatulea) [Orabug: 39203117]\n- net/mlx5e: Create/destroy PCIe Congestion Event object (Dragos Tatulea) [Orabug: 39203117]\n- selftests: net: add netpoll basic functionality test (Breno Leitao) [Orabug: 39203117]\n- selftests: drv-net: add helper/wrapper for bpftrace (Jakub Kicinski) [Orabug: 39203117]\n- netdevsim: implement peer queue flow control (Breno Leitao) [Orabug: 39203117]\n- RDMA/uverbs: Add a common way to create CQ with umem (Michael Margolin) [Orabug: 39203117]\n- net/mlx5: Expose disciplined_fr_counter through HCA capabilities in mlx5_ifc (Carolina Jubran) [Orabug: 39203117]\n- RDMA/mlx5: Optimize DMABUF mkey page size (Edward Srouji) [Orabug: 39203117]\n- RDMA/mlx5: Align mkc page size capability check to PRM (Michael Guralnik) [Orabug: 39203117]\n- net/mlx5: Expose HCA capability bits for mkey max page size (Michael Guralnik) [Orabug: 39203117]\n- net: netdevsim: Support setting dev-perm_addr on port creation (Toke Hoiland-Jorgensen) [Orabug: 39203117]\n- selftests: drv-net: Add bpftool util (Mohsin Bashir) [Orabug: 39203117]\n- net/mlx5e: RX, Remove unnecessary RQT redirects (Tariq Toukan) [Orabug: 39203117]\n- net/mlx5: Warn when write combining is not supported (Maor Gottlieb) [Orabug: 39203117]\n- net/mlx5e: Replace recursive VLAN push handling with an iterative loop (Gal Pressman) [Orabug: 39203117]\n- net/mlx5e: CT: extract a memcmp from a spinlock section (Cosmin Ratiu) [Orabug: 39203117]\n- net/mlx5e: Remove unused VLAN insertion logic in TX path (Carolina Jubran) [Orabug: 39203117]\n- eth: mlx5: migrate to the *_rxfh_context ops (Jakub Kicinski) [Orabug: 39203117]\n- net/mlx5: Fix spelling mistake 'disabliing' - 'disabling' (Colin Ian King) [Orabug: 39203117]\n- net/mlx5: Add HWS as secondary steering mode (Moshe Shemesh) [Orabug: 39203117]\n- net/mlx5: HWS, Shrink empty matchers (Yevgeny Kliteynik) [Orabug: 39203117]\n- net/mlx5: HWS, Refactor rule skip logic (Vlad Dogaru) [Orabug: 39203117]\n- net/mlx5: HWS, remove incorrect comment (Yevgeny Kliteynik) [Orabug: 39203117]\n- net/mlx5: HWS, remove unused create_dest_array parameter (Vlad Dogaru) [Orabug: 39203117]\n- netmem: use _Generic to cover const casting for page_to_netmem() (Byungchul Park) [Orabug: 39203117]\n- page_pool: rename __page_pool_alloc_pages_slow() to __page_pool_alloc_netmems_slow() (Byungchul Park) [Orabug: 39203117]\n- page_pool: rename __page_pool_release_page_dma() to __page_pool_release_netmem_dma() (Byungchul Park) [Orabug: 39203117]\n- page_pool: rename page_pool_return_page() to page_pool_return_netmem() (Byungchul Park) [Orabug: 39203117]\n- mlxbf_gige: emit messages during open and probe failures (David Thompson) [Orabug: 39203117]\n- selftests: drv-net: Add test for devlink-rate traffic class bandwidth distribution (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: Manage TC arbiter nodes and implement full support for tc-bw (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: Add traffic class scheduling support for vport QoS (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: Add support for setting tc-bw on nodes (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: Add no-op implementation for setting tc-bw on rate objects (Carolina Jubran) [Orabug: 39203117]\n- selftest: netdevsim: Add devlink rate tc-bw test (Carolina Jubran) [Orabug: 39203117]\n- devlink: Extend devlink rate API with traffic classes bandwidth management (Carolina Jubran) [Orabug: 39203117]\n- netlink: introduce type-checking attribute iteration for nlmsg (Carolina Jubran) [Orabug: 39203117]\n- net/mlx5: fs, fix RDMA TRANSPORT init cleanup flow (Patrisious Haddad) [Orabug: 39203117]\n- RDMA/mlx5: Check CAP_NET_RAW in user namespace for devx create (Parav Pandit) [Orabug: 39203117]\n- time/timecounter: Fix the lie that struct cyclecounter is const (Greg Kroah-Hartman) [Orabug: 39203117]\n- RDMA/mlx5: Check CAP_NET_RAW in user namespace for anchor create (Parav Pandit) [Orabug: 39203117]\n- RDMA/mlx5: Check CAP_NET_RAW in user namespace for flow create (Parav Pandit) [Orabug: 39203117]\n- RDMA/uverbs: Check CAP_NET_RAW in user namespace for flow create (Parav Pandit) [Orabug: 39203117]\n- net/mlx5e: Fix error handling in RQ memory model registration (Wangfushuai) [Orabug: 39203117]\n- selftests: forwarding: lib: Split setup_wait() (Petr Machata) [Orabug: 39203117]\n- RDMA/ipoib: Use parent rdma device net namespace (Mark Bloch) [Orabug: 39203117]\n- RDMA/mlx5: Allocate IB device with net namespace supplied from core dev (Mark Bloch) [Orabug: 39203117]\n- RDMA/core: Extend RDMA device registration to be net namespace aware (Mark Bloch) [Orabug: 39203117]\n- netlink: specs: ethtool: replace underscores with dashes in names (Jakub Kicinski) [Orabug: 39203117]\n- net/mlx5: Add IFC bits for PCIe Congestion Event object (Dragos Tatulea) [Orabug: 39203117]\n- net/mlx5: Small refactor for general object capabilities (Dragos Tatulea) [Orabug: 39203117]\n- RDMA/mlx5: Add multiple priorities support to RDMA TRANSPORT userspace tables (Patrisious Haddad) [Orabug: 39203117]\n- net/mlx5: fs, add multiple prios to RDMA TRANSPORT steering domain (Patrisious Haddad) [Orabug: 39203117]\n- RDMA/mlx5: Support driver APIs pre_destroy_cq and post_destroy_cq (Mark Zhang) [Orabug: 39203117]\n- RDMA/core: Add driver APIs pre_destroy_cq() and post_destroy_cq() (Mark Zhang) [Orabug: 39203117]\n- mmc: sdhci-of-dwcmshc: Drop the use of sdhci_pltfm_free() (Binbin Zhou) [Orabug: 39203117]\n- selftests: drv-net: import things in lib one by one (Jakub Kicinski) [Orabug: 39203117]\n- netdevsim: fix UaF when counting Tx stats (Jakub Kicinski) [Orabug: 39203117]\n- eth: mlx5: migrate to new RXFH callbacks (Jakub Kicinski) [Orabug: 39203117]\n- netdevsim: account dropped packet length in stats on queue free (Breno Leitao) [Orabug: 39203117]\n- net: add dev_dstats_rx_dropped_add() helper (Breno Leitao) [Orabug: 39203117]\n- netdevsim: collect statistics at RX side (Breno Leitao) [Orabug: 39203117]\n- netdevsim: migrate to dstats stats collection (Breno Leitao) [Orabug: 39203117]\n- net/mlx4_en: Remove the redundant NULL check for the 'my_ets' object (Andrey Vatoropin) [Orabug: 39203117]\n- netdevsim: remove udp_ports_sleep (Stanislav Fomichev) [Orabug: 39203117]\n- net/mlx4e: Don't redefine IB_MTU_XXX enum (Mark Zhang) [Orabug: 39203117]\n- pinctrl: Constify static 'pinctrl_desc' (Krzysztof Kozlowski) [Orabug: 39203117]\n- pinctrl: Constify pointers to 'pinctrl_desc' (Krzysztof Kozlowski) [Orabug: 39203117]\n- pinctrl: amd: Constify pointers to 'pinctrl_desc' (Krzysztof Kozlowski) [Orabug: 39203117]\n- net/mlx5e: Add TX support for netmems (Dragos Tatulea) [Orabug: 39203117]\n- net/mlx5e: Support ethtool tcp-data-split settings (Saeed Mahameed) [Orabug: 39203117]\n- net/mlx5e: Implement queue mgmt ops and single channel swap (Saeed Mahameed) [Orabug: 39203117]\n- net/mlx5e: Add support for UNREADABLE netmem page pools (Saeed Mahameed) [Orabug: 39203117]\n- net/mlx5e: Convert over to netmem (Saeed Mahameed) [Orabug: 39203117]\n- net/mlx5e: SHAMPO: Separate pool for headers (Saeed Mahameed) [Orabug: 39203117]\n- net/mlx5e: SHAMPO: Improve hw gro capability checking (Saeed Mahameed) [Orabug: 39203117]\n- net/mlx5e: SHAMPO: Remove redundant params (Saeed Mahameed) [Orabug: 39203117]\n- net/mlx5e: SHAMPO: Reorganize mlx5_rq_shampo_alloc (Saeed Mahameed) [Orabug: 39203117]\n- page_pool: Add page_pool_dev_alloc_netmems helper (Dragos Tatulea) [Orabug: 39203117]\n- net: Add skb_can_coalesce for netmem (Dragos Tatulea) [Orabug: 39203117]\n- net: Allow const args for of page_to_netmem() (Dragos Tatulea) [Orabug: 39203117]\n- selftests: forwarding: Add a test for verifying VXLAN MC underlay (Petr Machata) [Orabug: 39203117]\n- netmem: fix netmem comments (Mina Almasry) [Orabug: 39203117]\n- selftests: net: add netconsole test for cmdline configuration (Breno Leitao) [Orabug: 39203117]\n- net: ethtool: add dedicated callbacks for getting and setting rxfh fields (Jakub Kicinski) [Orabug: 39203117]\n- net: ethtool: require drivers to opt into the per-RSS ctx RXFH (Jakub Kicinski) [Orabug: 39203117]\n- net: ethtool: remove the duplicated handling from rxfh and rxnfc (Jakub Kicinski) [Orabug: 39203117]\n- net: ethtool: copy the rxfh flow handling (Jakub Kicinski) [Orabug: 39203117]\n- net: ethtool: Don't check if RSS context exists in case of context 0 (Gal Pressman) [Orabug: 39203117]\n- net/mlx5: Expose serial numbers in devlink info (Jiri Pirko) [Orabug: 39203117]\n- selftests: netconsole: Add support for basic netconsole target format (Breno Leitao) [Orabug: 39203117]\n- selftests: netconsole: Do not exit from inside the validation function (Breno Leitao) [Orabug: 39203117]\n- page_pool: fix ugly page_pool formatting (Mina Almasry) [Orabug: 39203117]\n- net/mlx5e: Convert mlx5 netdevs to instance locking (Cosmin Ratiu) [Orabug: 39203117]\n- net: Add support for providing the PTP hardware source in tsinfo (Kory Maincent) [Orabug: 39203117]\n- selftests: drv-net: Fix 'envirnoments' to 'environments' (Sumanth Gavini) [Orabug: 39203117]\n- net: enable driver support for netmem TX (Mina Almasry) [Orabug: 39203117]\n- net: add get_netmem/put_netmem support (Mina Almasry) [Orabug: 39203117]\n- netmem: add niov-type attribute to distinguish different net_iov types (Mina Almasry) [Orabug: 39203117]\n- selftests: drv-net: ping: make sure the ping test restores checksum offload (Jakub Kicinski) [Orabug: 39203117]\n- ethtool: Block setting of symmetric RSS when non-symmetric rx-flow-hash is requested (Gal Pressman) [Orabug: 39203117]\n- pinctrl: mediatek: airoha: use new GPIO line value setter callbacks (Bartosz Golaszewski) [Orabug: 39203117]\n- selftests: net-drv: remove the nic_performance and nic_link_layer tests (Jakub Kicinski) [Orabug: 39203117]\n- devlink: define enum for attr types of dynamic attributes (Jiri Pirko) [Orabug: 39203117]\n- selftests: net: exit cleanly on SIGTERM / timeout (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv: net: add version indicator (Mohsin Bashir) [Orabug: 39203117]\n- selftests: drv: net: avoid skipping tests (Mohsin Bashir) [Orabug: 39203117]\n- selftests: drv: net: fix test failure on ipv6 sys (Mohsin Bashir) [Orabug: 39203117]\n- selftests: drv-net: rss_input_xfrm: Check test prerequisites before running (Gal Pressman) [Orabug: 39203117]\n- selftests: net: add a virtio_net deadlock selftest (Bui Quang Minh) [Orabug: 39203117]\n- selftests: net: move xdp_helper to net/lib (Bui Quang Minh) [Orabug: 39203117]\n- selftests: drv-net: Test that NAPI ID is non-zero (Joe Damato) [Orabug: 39203117]\n- pinctrl: airoha: fix wrong PHY LED mapping and PHY2 LED defines (Christian Marangi) [Orabug: 39203117]\n- netlink: specs: rename rtnetlink specs in accordance with family name (Jakub Kicinski) [Orabug: 39203117]\n- pinctrl: amd: Add an LPS0 check() callback (Mario Limonciello) [Orabug: 39203117]\n- selftests: drv-net: test random value for hds-thresh (Taehee Yoo) [Orabug: 39203117]\n- selftests: net: use Path helpers in ping (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: replace the rpath helper with Path objects (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: use defer in the ping test (Jakub Kicinski) [Orabug: 39203117]\n- net: skbuff: Remove unused skb_add_data() (Yue Haibing) [Orabug: 39203117]\n- selftests: drv-net: fix merge conflicts resolution (Matthieu Baerts) [Orabug: 39203117]\n- selftests: drv-net: add xdp cases for ping.py (Taehee Yoo) [Orabug: 39203117]\n- selftests: drv-net: use env.rpath in the HDS test (Jakub Kicinski) [Orabug: 39203117]\n- selftests: net: report output format as TAP 13 in Python tests (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: add tests for napi IRQ affinity notifiers (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net-hw: Add a test for symmetric RSS hash (Gal Pressman) [Orabug: 39203117]\n- selftests: drv-net: Make rand_port() get a port more reliably (Gal Pressman) [Orabug: 39203117]\n- selftests: drv-net: test XDP, HDS auto and the ioctl path (Jakub Kicinski) [Orabug: 39203117]\n- net: ethtool: fix ioctl confusing drivers about desired HDS user config (Jakub Kicinski) [Orabug: 39203117]\n- netlink: specs: Add FIB rule DSCP mask attribute (Ido Schimmel) [Orabug: 39203117]\n- selftests: net: Add python context manager for netns entering (Xiao Liang) [Orabug: 39203117]\n- selftests: drv-net: rename queues check_xdp to check_xsk (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: improve the use of ksft helpers in XSK queue test (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: add a way to wait for a local process (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: probe for AF_XDP sockets more explicitly (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: add missing new line in xdp_helper (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: use cfg.rpath() in netlink xsk attr test (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: add a warning for bkg + shell + terminate (Jakub Kicinski) [Orabug: 39203117]\n- net: ngbe: Add support for 1PPS and TOD (Jiawen Wu) [Orabug: 39203117]\n- net: wangxun: Add periodic checks for overflow and errors (Jiawen Wu) [Orabug: 39203117]\n- net: wangxun: Add support for PTP clock (Jiawen Wu) [Orabug: 39203117]\n- selftests: drv-net: add a simple TSO test (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: store addresses in dict indexed by ipver (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: get detailed interface info (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: resolve remote interface name (Jakub Kicinski) [Orabug: 39203117]\n- netlink: specs: Add FIB rule port mask attributes (Ido Schimmel) [Orabug: 39203117]\n- net: move stale comment about ntuple validation (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: Test queue xsk attribute (Joe Damato) [Orabug: 39203117]\n- io_uring/zcrx: add selftest (David Wei) [Orabug: 39203117]\n- selftests/net: Add selftest for IPv4 RTM_GETMULTICAST support (Yuyang Huang) [Orabug: 39203117]\n- selftests: drv-net: add helper for path resolution (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: factor out a DrvEnv base class (Jakub Kicinski) [Orabug: 39203117]\n- net: ethtool: prevent flow steering to RSS contexts which don't exist (Jakub Kicinski) [Orabug: 39203117]\n- netconsole: selftest: test for sysdata CPU (Breno Leitao) [Orabug: 39203117]\n- netconsole: selftest: Add test for fragmented messages (Breno Leitao) [Orabug: 39203117]\n- net: provide pending ring configuration in net_device (Jakub Kicinski) [Orabug: 39203117]\n- net: ethtool: store netdev in a temp variable in ethnl_default_set_doit() (Jakub Kicinski) [Orabug: 39203117]\n- net: move HDS config from ethtool state (Jakub Kicinski) [Orabug: 39203117]\n- selftest: net-drv: hds: add test for HDS feature (Taehee Yoo) [Orabug: 39203117]\n- netdevsim: add HDS feature (Taehee Yoo) [Orabug: 39203117]\n- bnxt_en: add support for hds-thresh ethtool command (Taehee Yoo) [Orabug: 39203117]\n- bnxt_en: add support for tcp-data-split ethtool command (Taehee Yoo) [Orabug: 39203117]\n- bnxt_en: add support for rx-copybreak ethtool command (Taehee Yoo) [Orabug: 39203117]\n- net: ethtool: add ring parameter filtering (Taehee Yoo) [Orabug: 39203117]\n- net: devmem: add ring parameter filtering (Taehee Yoo) [Orabug: 39203117]\n- net: ethtool: add support for configuring hds-thresh (Taehee Yoo) [Orabug: 39203117]\n- netconsole: selftest: verify userdata entry limit (Breno Leitao) [Orabug: 39203117]\n- netconsole: selftest: Split the helpers from the selftest (Breno Leitao) [Orabug: 39203117]\n- tools: ynl: move python code to separate sub-directory (Jan Stancek) [Orabug: 39203117]\n- netdevsim: add debugfs-triggered queue reset (Jakub Kicinski) [Orabug: 39203117]\n- netdev: define NETDEV_INTERNAL (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: test drivers sleeping in ndo_get_stats64 (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: assume stats refresh is 0 if no ethtool -c support (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: test empty queue and NAPI responses in netlink (Jakub Kicinski) [Orabug: 39203117]\n- page_pool: add page_pool_dev_alloc_netmem() (Alexander Lobakin) [Orabug: 39203117]\n- net: Document netmem driver support (Mina Almasry) [Orabug: 39203117]\n- netlink: specs: Add FIB rule flow label attributes (Ido Schimmel) [Orabug: 39203117]\n- selftests: net-drv: stats: sanity check netlink dumps (Jakub Kicinski) [Orabug: 39203117]\n- selftests: net-drv: queues: sanity check netlink dumps (Jakub Kicinski) [Orabug: 39203117]\n- selftests: net: support setting recv_size in YNL (Jakub Kicinski) [Orabug: 39203117]\n- net: ethtool: Add support for tsconfig command to get/set hwtstamp config (Kory Maincent) [Orabug: 39203117]\n- net: ethtool: tsinfo: Enhance tsinfo to support several hwtstamp by net topology (Kory Maincent) [Orabug: 39203117]\n- net: Add the possibility to support a selected hwtstamp in netdevice (Kory Maincent) [Orabug: 39203117]\n- net: Make net_hwtstamp_validate accessible (Kory Maincent) [Orabug: 39203117]\n- net: Make dev_get_hwtstamp_phylib accessible (Kory Maincent) [Orabug: 39203117]\n- page_pool: allow mixing PPs within one bulk (Alexander Lobakin) [Orabug: 39203117]\n- vrf: Make pcpu_dstats update functions available to other modules. (Guillaume Nault) [Orabug: 39203117]\n- page_pool: make page_pool_put_page_bulk() handle array of netmems (Alexander Lobakin) [Orabug: 39203117]\n- netmem: add a couple of page helper wrappers (Alexander Lobakin) [Orabug: 39203117]\n- xsk: allow attaching XSk pool via xdp_rxq_info_reg_mem_model() (Alexander Lobakin) [Orabug: 39203117]\n- xdp, xsk: constify read-only arguments of some static inline helpers (Alexander Lobakin) [Orabug: 39203117]\n- ethtool: regenerate uapi header from the spec (Stanislav Fomichev) [Orabug: 39203117]\n- ethtool: remove the comments that are not gonna be generated (Stanislav Fomichev) [Orabug: 39203117]\n- ethtool: separate definitions that are gonna be generated (Stanislav Fomichev) [Orabug: 39203117]\n- ynl: add missing pieces to ethtool spec to better match uapi header (Stanislav Fomichev) [Orabug: 39203117]\n- selftests: fix nested double quotes in f-string (David Wei) [Orabug: 39203117]\n- selftests: nic_performance: Add selftest for performance of NIC driver (Mohan Prasad J) [Orabug: 39203117]\n- selftests: nic_link_layer: Add selftest case for speed and duplex states (Mohan Prasad J) [Orabug: 39203117]\n- selftests: nic_link_layer: Add link layer selftest for NIC driver (Mohan Prasad J) [Orabug: 39203117]\n- pinctrl: airoha: Use unsigned long for bit search (Kees Cook) [Orabug: 39203117]\n- net: netconsole: selftests: Check if netdevsim is available (Breno Leitao) [Orabug: 39203117]\n- docs: networking: Describe irq suspension (Joe Damato) [Orabug: 39203117]\n- selftests: ncdevmem: Add automated test (Stanislav Fomichev) [Orabug: 39203117]\n- selftests: ncdevmem: Move ncdevmem under drivers/net/hw (Stanislav Fomichev) [Orabug: 39203117]\n- selftests: ncdevmem: Use YNL to enable TCP header split (Stanislav Fomichev) [Orabug: 39203117]\n- selftests: ncdevmem: Properly reset flow steering (Stanislav Fomichev) [Orabug: 39203117]\n- selftests: ncdevmem: Remove default arguments (Stanislav Fomichev) [Orabug: 39203117]\n- netlink: specs: Add a spec for FIB rule management (Donald Hunter) [Orabug: 39203117]\n- netlink: specs: Add a spec for neighbor tables in rtnetlink (Donald Hunter) [Orabug: 39203117]\n- net: netconsole: selftests: Add userdata validation (Breno Leitao) [Orabug: 39203117]\n- net: netconsole: selftests: Change the IP subnet (Breno Leitao) [Orabug: 39203117]\n- pinctrl: airoha: Add support for EN7581 SoC (Lorenzo Bianconi) [Orabug: 39203117]\n- Documentation: networking: Add missing PHY_GET command in the message list (Kory Maincent) [Orabug: 39203117]\n- netlink: specs: Add missing phy-ntf command to ethtool spec (Kory Maincent) [Orabug: 39203117]\n- selftests: net: lib: Introduce deferred commands (Petr Machata) [Orabug: 39203117]\n- ethtool: rss: prevent rss ctx deletion when in use (Daniel Zahka) [Orabug: 39203117]\n- selftests: net: move EXTRA_CLEAN of libynl.a into ynl.mk (Jakub Kicinski) [Orabug: 39203117]\n- selftests: net: rebuild YNL if dependencies changed (Jakub Kicinski) [Orabug: 39203117]\n- selftests: drv-net: add missing trailing backslash (Jakub Kicinski) [Orabug: 39203117]\n- pinctrl: amd: Fix two small typos (Marc Ferland) [Orabug: 39203117]\n- pinctrl: Switch back to struct platform_driver::remove() (Uwe Kleine-Konig) [Orabug: 39203117]\n- pinctrl: qcom: add the tlmm driver for QCS615 platform (Lijuan Gao) [Orabug: 39203117]\n- net: tap: set skb-dev before parsing virtio net header in tap_get_user_xdp() (Dongli Zhang) [Orabug: 39558732] {CVE-2026-74684}\n- uek-rpm: enable Nexthop SONiC drivers for ONOS (Vijay Kumar) [Orabug: 39597630]\n- platform: nexthop-sonic: add SONiC platform drivers (Vijay Kumar) [Orabug: 39597630]\n- uek-rpm/modules.yaml.S.onos: Package PDDF platform drivers (Darren Kenny) [Orabug: 39597630]\n- uek-rpm/config-x86_64-onos: Enable PDDF platform driver configs (Vijay Kumar) [Orabug: 39597630]\n- platform: Port SONiC PDDF drivers (Test Com) [Orabug: 39597630]\n- rds: tcp: fix uninit-value in __inet_bind (Tabrez Ahmed) [Orabug: 39668598]\n- rds: tcp: cleanup if kmem_cache_alloc fails in rds_tcp_conn_alloc() (Sowmini Varadhan) [Orabug: 39668598]\n- eeprom: optoe: set clientdata before publishing sysfs files (Vijay Kumar) [Orabug: 39721366]\n- eeprom: optoe: remove eeprom bin file on sysfs_create_group failure (Vijay Kumar) [Orabug: 39721366]\n- eeprom: optoe: fix heap OOB write from stale writebuf sizing (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: raven-fan-driver: read fan ID pins at correct offsets (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: check parse result in scd_set_debug (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: restrict /proc/scd to root-only read (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: fan-cpld: don't hold cpld-lock across work cancel on remove (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: minke-fan-cpld: fix uninitialised cpld deref in probe error path (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: tmp468: fix out-of-bounds read of names[] in probe (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd-mdio: fix mdiobus_free(NULL) and mii_bus leak on error (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: enforce register offset bound instead of advisory ASSERT (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: overflow-safe range check in scd_lpc_mmap_resource (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: rook-fan-cpld: only unregister LEDs that were registered (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: minke-fan-cpld: unregister slot_count LEDs, not fan_count (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: fix SPI controller devdata UAF and invalid kfree (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: don't panic on over-long xcvr attribute name (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: remove partial xcvr sysfs attrs before freeing on error (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: init master-list before the master-add error path (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: use strscpy for LED name to guarantee NUL termination (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: bound fan_count against speed_*_steps[] arrays (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: bound derived MMIO offsets in master/port add paths (Vijay Kumar) [Orabug: 39721366]\n- arista-sonic: scd: fix user-controlled format string in gpio/reset add (Vijay Kumar) [Orabug: 39721366]\n- src: handle ioremap error in raven-fan-driver (Arista-Hpandya) [Orabug: 39721366]\n- Replace sprintf with sysfs_emit in sysfs show callbacks (Arista-Hpandya) [Orabug: 39721366]\n- scd: add sysfs knob to control watchdog panic (Mohan Yelugoti) [Orabug: 39721366]\n- scd: update scd driver to EOS latest (Mohan Yelugoti) [Orabug: 39721366]\n- platform: remove old tricolor LED handling (Justin Oliver) [Orabug: 39721366]\n- scd: add bus_speed attribute to i2c buses (Samuel Angebault) [Orabug: 39721366]\n- Modify arista-drivers for arm64 compilation. (Vivek Kumar Verma) [Orabug: 39721366]\n- minke-fan-cpld: seperate slot and fan initialization in cpld_init (Arista-Hpandya) [Orabug: 39721366]\n- x86/bugs: Make Safe-RET robust against interrupt injection (Borislav Petkov) [Orabug: 39784619,39853774] {CVE-2026-68480}\n- net/rds: harden rds_rm_size (Manjunath Patil) [Orabug: 39812332]\n- KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Sean Christopherson) [Orabug: 39830589,39832725,39832878,39844799] {CVE-2026-64561}\n- net/rds: remove cached rds_sock-rs_conn and rs_conn_path (Sharath Srinivasan) [Orabug: 39832353]\n- Revert 'rds: cong: Make rds_cong_wait an array to reduce lock contention' (Sharath Srinivasan) [Orabug: 39832353]\n\n[6.12.0-206.100.2]\n- afs: Fix lack of locking around modifications of net-cells_dyn_ino (David Howells) {CVE-2026-72372}\n- afs: Fix dynamic lookup to fail on cell lookup failure (David Howells)\n- afs: Simplify cell record handling (David Howells)\n- afs: Fix afs_server ref accounting (David Howells)\n- afs: Use the per-peer app data provided by rxrpc (David Howells)\n- rxrpc: Allow the app to store private data on peer structs (David Howells)\n- afs: Drop the net parameter from afs_unuse_cell() (David Howells)\n- afs: Make afs_lookup_cell() take a trace note (David Howells)\n- afs: Improve server refcount/active count tracing (David Howells)\n- Bluetooth: hci_core: Fix not accounting for BIS/CIS/PA links separately (Luiz Augusto von Dentz)\n- Bluetooth: Add PA_LINK to distinguish BIG sync and PA sync connections (Yang Li)\n- net: qrtr: ns: Raise node count limit to 512 (Youssef Samir)\n- drm/amd/pm: fix smu13 power limit range calculation (Yang Wang)\n- ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL (Guan Wentao) {CVE-2026-68099}\n- ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl (Haofeng Li) {CVE-2026-68100}\n- vsock/virtio: collapse receive queue under memory pressure (Stefano Garzarella)\n- proc: Fix broken error paths for namespace links (Jann Horn)\n- serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (Jiangshan Yi) [Orabug: 39868564] {CVE-2026-68434}\n- drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) (Timur Kristof)\n- Revert 'drm/amd/display: Add missing kdoc for ALLM parameters' (Sasha Levin)\n- usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect (Diego Fernando Mancera Gomez) [Orabug: 39860411] {CVE-2026-68344}\n- net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets() (Lorenzo Bianconi)\n- udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf() (Robert Mader)\n- wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (Peddolla Harshavardhan Reddy) [Orabug: 39860409] {CVE-2026-68408}\n- wifi: cfg80211: define and use wiphy guard (Johannes Berg)\n- wifi: cfg80211: pass net_device to .set_monitor_channel (Felix Fietkau)\n- firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits (Seth Forshee)\n- Revert 'arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc' (Sasha Levin)\n- net: airoha: Fix skb-priority underflow in airoha_dev_select_queue() (Wayen Yan)\n- LTS version: v6.12.100 (Sherry Yang)\n- posix-cpu-timers: Prevent UAF caused by non-leader exec() race (Thomas Gleixner) [Orabug: 39807437] {CVE-2026-64560}\n- LTS version: v6.12.99 (Sherry Yang)\n- mm: refactor mm_access() to not return NULL (Lorenzo Stoakes)\n- LTS version: v6.12.98 (Sherry Yang)\n- ext4: fix fd leak in EXT4_IOC_MOVE_EXT cross-sb validation (Yun Zhou)\n- LTS version: v6.12.97 (Sherry Yang)\n- selftests/bpf: Add simple strscpy() implementation (Ihor Solodrai)\n- tools/testing: add linux/args.h header and fix radix, VMA tests (Lorenzo Stoakes)\n- dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() (Ivan Vecera) [Orabug: 39860212] {CVE-2026-68378}\n- Bluetooth: L2CAP: fix tx ident leak for commands without a response (Stig Hornang) {CVE-2026-72333}\n- Bluetooth: 6lowpan: Fix using chan-conn as indication to no remote netdev (Luiz Augusto von Dentz)\n- Bluetooth: L2CAP: Fix regressions caused by reusing ident (Luiz Augusto von Dentz)\n- crypto: ccp - Fix leaking the same page twice (Guenter Roeck)\n- ice: drop udp_tunnel_get_rx_info() call from ndo_open() (Mohammad Heib)\n- i40e: drop udp_tunnel_get_rx_info() call from i40e_open() (Mohammad Heib)\n- crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked() (Borislav Petkov) [Orabug: 39838809] {CVE-2025-39936}\n- Bluetooth: hci_sync: Fix attempting to send HCI_Disconnect to BIS handle (Luiz Augusto von Dentz)\n- Bluetooth: hci_core: Remove check of BDADDR_ANY in hci_conn_hash_lookup_big_state (Luiz Augusto von Dentz)\n- udp_tunnel: fix deadlock in udp_tunnel_nic_set_port_priv() (Paolo Abeni)\n- crypto: ccp - Fix SNP panic notifier unregistration (Ashish Kalra)\n- crypto: ccp - Fix dereferencing uninitialized error pointer (Ashish Kalra) [Orabug: 39838818] {CVE-2025-39729}\n- crypto: ccp - Fix __sev_snp_shutdown_locked (Ashish Kalra)\n- afs: Fix afs_dynroot_readdir() to not use the RCU read lock (David Howells)\n- afs: Fix afs_atcell_get_link() to check if ws_cell is unset first (David Howells)\n- net: airoha: Fix channel configuration for ETS Qdisc (Lorenzo Bianconi)\n- rtnetlink: Make per-netns RTNL dereference helpers to macro. (Kuniyuki Iwashima)\n- ksmbd: fix durable reconnect double-bind race in ksmbd_reopen_durable_fd (Gil Portnoy)\n- seqlock: fix scoped_seqlock_read kernel-doc (Randy Dunlap)\n- dibs: loopback: validate offset and size in move_data() (Dust Li) {CVE-2026-72018}\n- perf/x86/amd/brs: Fix kernel address leakage (Sandipan Das) {CVE-2026-72237}\n...",
"id": "ELSA-2026-500248",
"ovalId": "oval:com.oracle.elsa:def:2026500248",
"source": "oracle_linux",
"title": "ELSA-2026-500248: Unbreakable Enterprise kernel security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2026-500248.html"
}