elsa-2026-500249

oracle_linux
Description

[5.15.0-324.217.5.2] - inet: frags: strip GSO state from fragments before reassembly (Xinyang Ge) [Orabug: 39974835] {CVE-2026-80590} [5.15.0-324.217.5.1] - crypto: qat: restore misc workqueue lifecycle (Manjunath Patil) [Orabug: 39937535] - LTS version: v5.15.217 (Vijayendra Suman) - ring-buffer: Use current_context for safe per-CPU buffer swap (Tengda Wu) - ring-buffer: Remove jump to out label in ring_buffer_swap_cpu() (Steven Rostedt) - jiffies: Cast to unsigned long in secs_to_jiffies() conversion (Easwar Hariharan) - drm/virtio: Unlock reservations on dma_resv_reserve_fences() error (Dmitry Osipenko) - drm/vmwgfx: Reserve fence slots on buffer objects in cotables (Zack Rusin) - udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf() (Robert Mader) - binfmt_misc: use exe_file_deny_write_access() for the interpreter clone (Christian Brauner) - net/x25: fix use-after-free of the socket by its timers (Baul Lee) - net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG (Siddharth Vadapalli) - af_packet: Don't send zero-byte data in tpacket_snd(). (Eric Dumazet) - ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (Rosen Penev) - net: packet: fix wrong transport_header when sending VLAN-tagged frame (Wei Fang) - netfilter: ipset: fix list type element drift bug (Florian Westphal) - netfilter: flowtable: publish GC-visible tuple last (Jeremy Jean) - netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path (Alexey Velichayshiy) - netfilter: ipset: fix refcount race between list:set GC and swap (Xiang Mei (Microsoft)) - crypto: ccm - Set rfc4309 maxauthsize from child (Herbert Xu) - arm64: tegra: Add EL2 virtual timer interrupt for Tegra194 (Jon Hunter) - net: smc: fix splice entry lifetime imbalance in smc_rx_splice (Daming Li) - net/smc: rdma write inline if qp has sufficient inline space (Guangguan Wang) - net: atlantic: free stranded TX buffers on ring deinit (Yangyu Chen) - net/sched: act_ct: fix sk_buff leak when the header checks reject a packet (Hyunjung Ko) - openvswitch: move key and ovs_cb update out of handle_fragments (Xin Long) - net: sched: use skb_ip_totlen and iph_totlen (Xin Long) - openvswitch: use skb_ip_totlen in conntrack (Xin Long) - net: add a couple of helpers for iph tot_len (Xin Long) - mm/ptdump: always stabilise against page table freeing using init_mm (Lorenzo Stoakes (ARM)) - sched/psi: Shut down rtpoll_timer in psi_cgroup_free() (Tejun Heo) - drm/amd/pm: fix torn gpu metrics reads (Yang Wang) - ice: wait for reset completion in ice_resume() (Aaron Ma) - jiffies: Define secs_to_jiffies() (Easwar Hariharan) - can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure (Marc Kleine-Budde) - i2c: iproc: reset bus after timeout if START_BUSY is stuck (Jonas Gorski) - i2c: bcm-iproc: remove printout on handled timeouts (Wolfram Sang) - i2c: imx: Fix slave registration race and error handling (Liem) - binfmt_misc: restore write access when removing an entry (Christian Brauner) - fs: don't block write during exec on pre-content watched files (Amir Goldstein) - fsnotify: opt-in for permission events at file open time (Amir Goldstein) - ice: fix memory leak in ice_lbtest_prepare_rings() (Dawei Feng) - scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write (Ibrahim Hashimov) - scsi: scsi_debug: Rename zone type constants (Damien Le Moal) - scsi: sd: sd_zbc: Return early in sd_zbc_check_zoned_characteristics() (Damien Le Moal) - scsi: sd: sd_zbc: Introduce struct zoned_disk_info (Bart Van Assche) - scsi: sd: sd_zbc: Use logical blocks as unit when querying zones (Damien Le Moal) - scsi: sd: sd_zbc: Improve source code documentation (Bart Van Assche) - net: pktgen: fix proc entry use-after-free (Chengfeng Ye) - net: pktgen: fix code style (WARNING: Block comments) (Peter Seiderer) - igc: remove napi_synchronize() in igc_down() (David Carlier) - wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() (Maoyi Xie) - ksmbd: reject repeated SMB2 NEGOTIATE requests (Namjae Jeon) - ksmbd: conn lock to serialize smb2 negotiate (Namjae Jeon) - mm/vmstat: fold stranded per-cpu node stats when a node comes online (Gregory Price) - ksmbd: validate minimum PDU size for transform requests (Namjae Jeon) - smb/server: fix minimum SMB2 PDU size (ChenXiaoSong) - smb/server: fix minimum SMB1 PDU size (ChenXiaoSong) - ksmbd: rename smb2_get_msg to smb_get_msg (Namjae Jeon) - super: fix emergency thaw deadlock on frozen block devices (Christian Brauner) - ftrace: Add global mutex to serialize trace_parser access (Tengda Wu) - net/sched: serialize qdisc_rtab_list against concurrent get/put (Aldo Ariel Panzardo) - ksmbd: defer destroy_previous_session() until after NTLM authentication (James Montgomery) - libceph: fix two unsafe bare decodes in decode_lockers() (Pavitra Jha) - ceph: fix hanging __ceph_get_caps() with stale mds_wanted (Max Kellermann) - ceph: print cluster fsid and client global_id in all debug logs (Xiubo Li) - ceph: rename _to_client() to _to_fs_client() (Xiubo Li) - libceph: add doutc and *_client debug macros support (Xiubo Li) - libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (Xiang Mei) - libceph: Amend checking to fix make W=1 build breakage (Andy Shevchenko) - ceph: avoid fs reclaim while using current-journal_info (Max Kellermann) - sctp: avoid auth_enable sysctl UAF during netns teardown (Zhiling Zou) - mptcp: decrement subflows counter on failed passive join (Chenguang Zhao) - mptcp: fix subflow accounting on close (Paolo Abeni) - mptcp: cleanup MPJ subflow list handling (Paolo Abeni) - serial: sc16is7xx: implement gpio get_direction() callback (Hugo Villeneuve) - serial: sc16is7xx: fix regression with GPIO configuration (Hugo Villeneuve) - serial: sc16is7xx: remove obsolete out_thread label (Hugo Villeneuve) - serial: sc16is7xx: Fill in rs485_supported (Ilpo Jarvinen) - sc16is7xx: Properly resume TX after stop (Tomasz Mon) - wifi: brcmfmac: set F2 blocksize to 256 for BCM43752 (LiangCheng Wang) - wifi: brcmfmac: fix 43752 SDIO FWVID incorrectly labelled as Cypress (CYW) (Gokul Sivakumar) - serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (Jiangshan Yi) - serial: 8250_mid: Remove unneeded test for -setup() presence (Andy Shevchenko) - wifi: brcmfmac: drain bus_reset work on device removal (Fan Wu) - ALSA: seq: close a re-opened queue timer in the destructor (Norbert Szetei) - media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (Mirela Rabulea) - media: v4l: async: Set owner for async sub-devices (Sakari Ailus) - wifi: ath6kl: fix use-after-free in aggr_reset_state() (Daniel Hodges) - media: imx219: Fix maximum frame length in lines (Sakari Ailus) - media: i2c: imx219: Rename VTS to FRM_LENGTH (Jai Luthra) - media: i2c: imx219: Correct the minimum vblanking value (David Plowman) - media: i2c: imx219: Drop IMX219_VTS_* macros (Laurent Pinchart) - media: marvell-cam: fix missing pci_disable_device() on remove (Guangshuo Li) - drm/i915/hdcp: require monotonically increasing seq_num_v (Jani Nikula) - drm/i915/hdcp: check streams[] bounds before overflow (Jani Nikula) - drm/i915/vrr: require valid min/max vfreq for VRR (Jani Nikula) - media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (David Carlier) - drm/virtio: bound EDID block reads to the response buffer (Bryam Vargas) - drm/virtio: Return proper error codes instead of -1 (Dmitry Osipenko) - drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (Timur Kristof) - drm/tegra: fbdev: Remove offset into framebuffer memory (Thomas Zimmermann) - drm/displayid: fix Tiled Display Topology ID size (Jani Nikula) - drm/virtio: use uninterruptible resv lock for plane updates (Deepanshu Kartikey) - dma-buf/drivers: make reserving a shared slot mandatory v4 (Christian Konig) - drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (Ashutosh Desai) - drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (Ashutosh Desai) - usb: gadget: f_tcm: synchronize delayed set_alt with teardown (Cen Zhang) - drm/dp/mst: fix buffer overflows in sideband chunk accumulation (Ashutosh Desai) - fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list (Reinette Chatre) - octeontx2-pf: fix SQB pointer leak on init failure (Dawei Feng) - net: ipa: fix SMEM state handle leaks in SMP2P init (Haoxiang Li) - espintcp: use sk_msg_free_partial to fix partial send (Sabrina Dubroca) - bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline() (Breno Leitao) - bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c (Breno Leitao) - bootconfig: do not put quotes on cmdline items unless necessary (Rasmus Villemoes) - net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Bryam Vargas) - net/sched: taprio: avoid calling child-ops-dequeue(child) twice (Vladimir Oltean) - gpio: tegra: do not call pinctrl for GPIO direction (Runyu Xiao) - treewide: rename pinctrl_gpio_direction_output_new() (Bartosz Golaszewski) - octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (Junrui Luo) - net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) - net: mana: Validate the packet length reported by the NIC (Dexuan Cui) - net/sched: act_ct: preserve tc_skb_cb across defragmentation (Zihan Xi) - net: ixp4xx_hss: fix duplicate HDLC netdev allocation (Haoxiang Li) - net: ipip: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) - net: Add helper function to parse netlink msg of ip_tunnel_encap (Liu Jian) - locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (Thomas Gleixner) - mmc: vub300: fix use-after-free on probe failure (Guangshuo Li) - mmc: vub300: rename probe error labels (Johan Hovold) - mmc: vub300: fix use-after-free on disconnect (Johan Hovold) - Input: ims-pcu - fix firmware leak in async update (Dmitry Torokhov) - firmware_loader: introduce __free() cleanup hanler (Dmitry Torokhov) - dm-verity: make error counter atomic (Mikulas Patocka) - dm-integrity: don't increment hash_offset twice (Mikulas Patocka) - scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() (Abdun Nihaal) - ovl: use linked upper dentry in copy-up tmpfile (Souvik Banerjee) - bpf,fork: wipe -bpf_storage before bailouts that access it (Jann Horn) - thunderbolt: Prevent XDomain delayed work use-after-free on disconnect (Michael Bommarito) - thunderbolt: Remove XDomain from the bus without holding tb-lock (Mika Westerberg) - thunderbolt: Remove service debugfs entries during unregister (Mika Westerberg) - thunderbolt: Keep XDomain reference during the lifetime of a service (Mika Westerberg) - thunderbolt: Update property.c function documentation (Alan Borzeszkowski) - thunderbolt: Remove usage of the deprecated ida_simple_xx() API (Christophe JAILLET) - can: esd_usb: kill anchored URBs before freeing netdevs (Fan Wu) - can/esd_usb2: Rename esd_usb2.c to esd_usb.c (Frank Jungclaus) - i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (Vincent Jardin) - i2c: imx: separate atomic, dma and non-dma use case (Stefan Eichenberger) - ksmbd: fix integer overflow in set_file_allocation_info() (Ibrahim Hashimov) - tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (Jarkko Sakkinen) - smb: client: use kvzalloc() for megabyte buffer in simple fallocate (Fredric Cover) - taskstats: retain dead thread stats in TGID queries (Yiyang Chen) - taskstats: fill_stats_for_tgid: use for_each_thread() (Oleg Nesterov) - dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (Frank Li) - dmaengine: dw-edma: Detach the private data and chip info structures (Frank Li) - dmaengine: dw-edma: Remove unused irq field in struct dw_edma_chip (Frank Li) - mtd: spi-nor: swp: Improve locking user experience (Miquel Raynal) - mtd: spi-nor: Fix spi_nor_try_unlock_all() (Michael Walle) - net: thunderbolt: Fix frags[] overflow by bounding frame_count (Maoyi Xie) - mtd: maps: vmu-flash: fix fault in unaligned fixup (Florian Fuchs) - 9p: skip nlink update in cacheless mode to fix WARN_ON (Breno Leitao) - ntfs3: validate split-point offset in indx_insert_into_buffer (Michael Bommarito) - fs/ntfs3: Undo critial modificatins to keep directory consistency (Konstantin Komarov) - fs/ntfs3: Make ntfs_update_mftmirr return void (Pavel Skripkin) - selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() (Tristan Madani) - lsm: infrastructure management of the sock security (Casey Schaufler) - lsm: use default hook return value in call_int_hook() (Ondrej Mosnacek) - remoteproc: qcom: Fix leak when custom dump_segments addition fails (Wasim Nazir) - remoteproc: qcom: pas: Adjust the phys addr wrt the mem region (Yogesh Lal) - remoteproc: qcom: fix sparse warnings (Mukesh Ojha) - remoteproc: qcom: replace kstrdup with kstrndup (Mukesh Ojha) - netfilter: nft_set_pipapo: don't leak bad clone into future transaction (Florian Westphal) - netfilter: nft_set_pipapo: move cloning of match info to insert/removal path (Florian Westphal) - netfilter: nft_set_pipapo: prepare pipapo_get helper for on-demand clone (Florian Westphal) - netfilter: nft_set_pipapo: merge deactivate helper into caller (Florian Westphal) - netfilter: nft_set_pipapo: prepare walk function for on-demand clone (Florian Westphal) - netfilter: nft_set_pipapo: make pipapo_clone helper return NULL (Florian Westphal) - netfilter: nf_conntrack_sip: validate skb_dst() before accessing it (Pablo Neira Ayuso) - netfilter: nf_conntrack_sip: remove net variable shadowing (Florian Westphal) - netfilter: nft_set_pipapo: move prove_locking helper around (Florian Westphal) - netfilter: nft_set_pipapo: use GFP_KERNEL for insertions (Florian Westphal) - ASoC: mediatek: mt8192: Check runtime resume during probe (Cassio Gabriel) - ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable (Tang Bin) - ASoC: mediatek: Use common mtk_afe_pcm_platform with common probe cb (AngeloGioacchino Del Regno) - ASoC: mediatek: mt8192-afe-pcm: Simplify with dev_err_probe() (AngeloGioacchino Del Regno) - ASoC: mediatek: mt8192-afe-pcm: Convert to devm_pm_runtime_enable() (AngeloGioacchino Del Regno) - netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst (Haoze Xie) - ipv4: adopt dst_dev, skb_dst_dev and skb_dst_dev_net[_rcu] (Eric Dumazet) - net: dst: add four helpers to annotate data-races around dst-dev (Eric Dumazet) - net: dst: annotate data-races around dst-output (Eric Dumazet) - net: dst: annotate data-races around dst-input (Eric Dumazet) - tcp: convert to dev_net_rcu() (Eric Dumazet) - ASoC: mediatek: mt8183: Check runtime resume during probe (Cassio Gabriel) - octeontx2-vf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao) - octeontx2-pf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao) - octeontx2: Annotate mmio regions as __iomem (Subbaraya Sundeep) - octeontx2-af: Fix APR entry mapping based on APR_LMT_CFG (Geetha sowjanya) - VDUSE: avoid leaking information to userspace (Jason Wang) - vduse: take out allocations from vduse_dev_alloc_coherent (Eugenio Perez) - vduse: remove unused vaddr parameter of vduse_domain_free_coherent (Eugenio Perez) - vduse: Use fixed 4KB bounce pages for non-4KB page size (Sheng Zhao) - mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (Wentao Liang) - tipc: restrict socket queue dumps in enqueue tracepoints (Li Xiasong) - fbcon: Use correct type for vc_resize() return value (Jiacheng Yu) - fbcon: Rename struct fbcon_ops to struct fbcon_par (Thomas Zimmermann) - rxrpc: serialize kernel accept preallocation with socket teardown (Li Daming) - serial: max310x: implement gpio_chip::get_direction() (Tapio Reijonen) - serial: max310x: replace bare use of 'unsigned' with 'unsigned int' (checkpatch) (Hugo Villeneuve) - ALSA: hda: Fix cached processing coefficient verbs (Xu Rao) - audit: fix recursive locking deadlock in audit_dupe_exe() (Ricardo Robaina) - audit: use 'unsigned int' instead of 'unsigned' (Ricardo Robaina) - audit: widen ino fields to u64 (Jeff Layton) - VFS/audit: introduce kern_path_parent() for audit (NeilBrown) - ALSA: hda: conexant: Remove mic bias threshold override (Zhang Heng) - Input: mms114 - reject an oversized device packet size (Bryam Vargas) - i2c: davinci: Unregister cpufreq notifier on probe failure (Haoxiang Li) - Input: mms114 - fix touch indexing for MMS134S and MMS136 (Dmitry Torokhov) - fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() (Sebastian Alba Vives) - dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning (Mikhail Gavrilov) - udmabuf: Do not create malformed scatterlists (Jason Gunthorpe) - bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (Matt Bobrowski) - iommu/amd: Don't split flush for amd_iommu_domain_flush_all() (Weinan Liu) - mm: do file ownership checks with the proper mount idmap (Pedro Falcato) - net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (Xiang Mei) - xfs: check v5 superblock features early (Christoph Hellwig) - xfs: fix ilock leak on error in xfs_dq_get_next_id (Long Li) - drm/amdgpu: Fix UVD decode image min size calculation (David Rosca) - drm/amdgpu: Implement insert_end for VCE 3 (David Rosca) - drm/amdgpu: Reject UVD message with dimensions above 4096 (David Rosca) - drm/amdgpu: validate GEM_CREATE domain combinations (Candice Li) - drm/amdgpu: Reject UVD message with invalid number of h265 refs (David Rosca) - s390/vfio_ccw: Fix out of bounds check on CCW array (Eric Farman) - drm/radeon: fix autosuspend cleanup during teardown (Guangshuo Li) - mmc: sdhci: make tuning_err a signed int (Haibo Chen) - mmc: sdhci: unmap the bounce buffer before device release (Myeonghun Pak) - mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (Zhan Xusheng) - libceph: tolerate addrvecs with multiple entries of the same type (Kefu Chai) - ceph: fix MDS random selection readiness predicate (Yiming Zhu) - libceph: Avoid using invalid osd indices from primary_temp (Raphael Zimmer) - Input: sur40 - fix V4L error path cleanup (Dmitry Torokhov) - Input: sur40 - fix input device registration ordering (Dmitry Torokhov) - openrisc: signal: do not restore privileged SR bits on sigreturn (Ali Ahmet Memis) - ftrace: Fix off-by-one fentry site disable in ftrace_free_mem() (Josh Poimboeuf) - libceph: fix multiple unsafe decodes in decode_locker() (Pavitra Jha) - crypto: qce - fix error path in devm_qce_register_algs (Thorsten Blum) - Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (Dmitry Torokhov) - Input: synaptics-rmi4 - block s_input when F54 queue is busy (Dmitry Torokhov) - Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (Bryam Vargas) - Input: synaptics-rmi4 - zero report size on F54 work error (Dmitry Torokhov) - powerpc/pseries: lparcfg - fix kbuf[] underflow (George Wilson) - Input: iforce - validate input packet lengths (Pengpeng Hou) - Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (Zhefu Zhang) - Input: psxpad-spi - set driver data before use (Linmao Li) - Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (Richard Davies) - Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (Dmitry Torokhov) - powerpc/pseries: pci - logic bug (George Wilson) - ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (Dawid Wrobel) - ASoC: cs4265: sort the register default table (Peter Ujfalusi) - s390/qeth: validate user buffer length in SNMP and ARP query ioctls (Hidayath Khan) - mptcp: options: reset DSS fields in case of unexpected size (Matthieu Baerts (NGI0)) - selinux: do not cancel a policy conversion that never started (Bryam Vargas) - selinux: reject a class permission count below its inherited common (Bryam Vargas) - selinux: require every boolean value to be defined (Bryam Vargas) - ipvs: separate destination availability state (Yizhou Zhao) - fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() (Zhan Xusheng) - media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization (Jiasheng Jiang) - media: mtk-vcodec: potential null pointer deference in SCP (Fullway Wang) - f2fs: fix UAF issue in f2fs_merge_page_bio() (Chao Yu) - LTS version: v5.15.216 (Vijayendra Suman) - thunderbolt: Bound the DROM dual link port number before indexing sw-ports (Bryam Vargas) - sctp: clear new_transport when removing a peer (Qing Ming) - sctp: fix use-after-free of cached ASCONF chunk (Yuxiang Yang) - sctp: keep chunk-transport in step with the list it is queued on (Baul Lee) - scsi: scsi_debug: Negate wrapped memcmp() result (Xu Rao) - bpf, sockmap: Fix sk_redir use-after-free in send verdict (Chengfeng Ye) - ip6_tunnel: clear skb2-cb[] in ip6ip6_err() (Zhiling Zou) - ipv6: fix Route Information option length validation (Yuejie Shi) - Revert 'thermal/drivers/hwmon: Cleanup coding style a bit' (Rafael J. Wysocki) - tipc: read le-link under the node lock in tipc_node_link_down() (Jun Yang) - vhost: reset the vring metadata cache on vring reconfiguration (Jun Yang) - vsock/virtio: avoid refilling the RX queue after teardown (Weiming Shi) - vsock/virtio: read virtqueues under worker locks (Weiming Shi) - vxlan: do not arm the ageing timer on a device that is down (Baul Lee) - xdp: reject clones that overrun skb_shared_info tailroom (Zhiling Zou) - net/sched: act_gact, act_police: range check the fallback control action (Hyunjung Ko) - net: atlantic: free RX pages of consumed but not refilled buffers (Yangyu Chen) - netfilter: bridge: release template ct on non-IP path (Zhiling Zou) - ipv6: prevent in6_dev_get() from resurrecting inet6_dev (Kyle Zeng) - fbdev: bitblit: bound-check glyph index in bit_cursor() (Rik van Riel) - tracing: Fix race between update_event_fields and, event_define_fields (Michael Wu) - ALSA: usx2y: bound the hwdep mmap fault offset (Baul Lee) - misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (Eddie Lin) - misc: fastrpc: fix channel ctx ref leak when session alloc fails (Anandu Krishnan E) - staging: rtl8723bs: validate monitor transmit frame lengths (Mariano Baragiola) - staging: rtl8723bs: fix missing shared-key auth challenge length check (Panagiotis Petrakopoulos) - staging: rtl8723bs: fix OOB read in WMM_param_handler() (Muhammad Bilal) - staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (Muhammad Bilal) - serial: 8250_dma: Clear stale RX state on shutdown (Cunhao Lu) - ipv4: fix use-after-free in fib_nhc_update_mtu() (Chengfeng Ye) - ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops (Zihan Xi) - fscrypt: Replace mk_users keyring with simple list (Eric Biggers) - pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP (Claudiu Beznea) - futex: Prevent robust futex exit race some more (Keno Fischer) - Bluetooth: 6lowpan: Fix using chan-conn as indication to no remote netdev (Luiz Augusto von Dentz) - Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (Marco Elver) - Input: evdev - fix information leak in evdev_pass_values() (Dmitry Torokhov) - vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (Joshua Rogers) - vt: add permission check for KDSKBMETA ioctl (Joshua Rogers) - net: bridge: mrp: fix uninitialised bytes on the wire (Baul Lee) - netfilter: ebt_nflog: pin the NFLOG backend (Chengfeng Ye) - net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header (Qihang Tang) - net: octeontx2-pf: Fix UB in shift operation (Sergey V. Frolov) - net: openvswitch: reallocate update replies for mismatched IDs (Zhiling Zou) - net/packet: reset the MAC header on the packet-socket transmit path (Doruk Tan Ozturk) - ipvs: clear IPv4 options after rebasing tunnel ICMP errors (Kyle Zeng) - ipvs: properly update the overload flag on dest edit (Julian Anastasov) - ipvs: add totalconns for dest (Julian Anastasov) - ima: fix out-of-bounds read in xattr_verify() (Lincoln Wallace) - usb: gadget: f_ncm: Use unsigned int for ndp_index (Sonali Pradhan) - usb: cdnsp: fix incorrect endian conversions for APB timeout register (Pawel Laszczak) - thunderbolt: icm: Preserve USB4 proxy data-valid bit (Xu Rao) - usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (Aleksandr Nogikh) - ALSA: usb-audio: fix OOB write on Type II inbound URBs (Baul Lee) - Input: evdev - sanitize event type index when fetching event masks (Dmitry Torokhov) - spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (Larisa Grigore) - hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (Wilken Gottwalt) - tls: don't abort the connection on signal-interrupted sends (Maximilian Immanuel Brandtner) - sctp: clear control chunk transport if it is being removed (Xin Long) - ata: pata_sl82c105: fix bridge revision use-after-free (Hongyan Xu) - net: thunderbolt: Tear down DMA paths before stopping the rings (Fan XinRan) - net: qrtr: ns: Raise lookup limit to 128 (Lukasz Patron) - net/smc: fix TOCTOU race between smc_listen_out() and listener close (Sidraya Jayagond) - net: remove WARN_ON_ONCE() from sk_mc_loop() (Eric Dumazet) - net: prestera: validate firmware header length (Pengpeng Hou) - net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (Henry Martin) - tcp: fix TFO max_qlen accounting across reuseport migration (Jiayuan Chen) - sctp: fix addip_serial increment on ASCONF_ACK allocation failure (Qing Luo) - bnxt_en: Fix PTP PPS setting bug (Keegan Freyhof) - bnxt_en: Disable EOP for TPA on all chips to prevent data corruption (Michael Chan) - bnxt_en: Do not set EOP on RX AGG BDs on 5760X chips (Michael Chan) - selftests/ftrace: refactor eprobes test to fix argument checks (Martin Kaiser) - selftests/ftrace: Add test case for GRP/ only input (Linyu Yuan) - net/openvswitch: check Ethernet header length in key_extract() (Cen Zhang (Microsoft)) - net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter (Toke Hoiland-Jorgensen) - udp: fix potential use-after-free in tunnel segmentation (Xuanqiang Luo) - vhost/vdpa: reject overflowing PA map page counts on 32-bit (Yousef Alhouseen) - counter: microchip-tcb-capture: Fix DT channel validation (Babanpreet Singh) - net/mlx5: fw_tracer, return NULL on create error (Michael Guralnik) - net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete (Jiawen Liu) - net/sched: cls_route: fix fastmap use-after-free on filter (Jamal Hadi Salim) - net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() (Mahanta Jambigi) - bpf: Preserve pointer state for commuted arithmetic (Yiyang Chen) - bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor (Xiang Mei (Microsoft)) - ARM: npcm: Fix OF node refcount leaks in SMP setup (Yuho Choi) - NFS: Pin the 'struct nfs_server' during a FREE_STATEID call (Anna Schumaker) - nfs4: take a reference on the nfs_client when running FREE_STATEID (Scott Mayhew) - s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() (Harald Freudenberger) - mount: honour SB_NOUSER in the new mount API (Al Viro) - gpio: pch: use raw_spinlock_t for the register lock (Junjie Cao) - firmware: stratix10-svc: fix memory leaks and list corruption bugs (Tze Yee Ng) - net: openvswitch: fix skb leak on flow key update failure during recirculation (Ilya Maximets) - mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (Kiryl Shutsemau (Meta)) - HID: logitech-dj: Fix maxfield check in DJ short report validation (HyeongJun An) - drm/vmwgfx: bound DMA command body size against suffix pointer (Zack Rusin) - drm/vmwgfx: validate DRAW_PRIMITIVES header size before division (Zack Rusin) - drm/amdgpu: cap GTT size to physical RAM on APUs (Harkirat Gill) - drm/amdgpu: restore UMD profile pstate after runtime resume (Candice Li) - drm/vc4: Zero the tile state data array before each BIN job (Maira Canal) - can: peak_usb: validate uCAN receive record lengths (Pengpeng Hou) - can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error (Maoyi Xie) - can: peak_usb: add bounds check for USB channel index (James Gao) - can: softing: fw_parse(): validate firmware record spans (Pengpeng Hou) - can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents (Pengpeng Hou) - can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() (Abdun Nihaal) - can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer (Oleksij Rempel) - can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure (Guangshuo Li) - can: ems_usb: validate CPC message lengths (Pengpeng Hou) - can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured (Lucas Martins Alves) - i2c: imx: Cancel hrtimer before clearing slave pointer (Liem) - i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock (H. Nikolaus Schaller) - net: openvswitch: fix skb leak on flow key update failure during ct (Ilya Maximets) - net: openvswitch: fix potential UAF on meter attach failure (Ilya Maximets) - phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB (Nava kishore Manne) - phy: zynqmp: use read-modify-write for SERDES scrambler bypass (Nava kishore Manne) - phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask (Nava kishore Manne) - s390/zcrypt: Validate length for CCA ECC private key requests (Holger Dengler) - s390/zcrypt: Validate length for CCA AES cipher key requests (Holger Dengler) - s390/dasd: Fix potential NULL pointer dereference (Jan Hoppner) - s390/qeth: Check CAP_NET_ADMIN for private ioctls (Aswin Karuvally) - cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() (Abdun Nihaal) - i2c: amd-mp2: Unregister callback on adapter add failure (Myeonghun Pak) - hwmon: (npcm750-pwm-fan): stop fan timer on device detach (Hongyan Xu) - sctp: prevent peer transport count overflow (Asim Viladi Oglu Manizada) - sctp: reject stale cookies with mismatched verification tags (Yuxiang Yang) - selftests/clone3: fix wild pointer access of getline due to missing init (Chris Gellermann) - tracing/filters: Fix false positive match in regex_match_full() (Masami Hiramatsu (Google)) - tracing: Check return value of __register_event() in trace_module_add_events() (Masami Hiramatsu (Google)) - vxlan: use pskb_network_may_pull() in route_shortcircuit() (Eric Dumazet) - vxlan: use neigh_ha_snapshot() in route_shortcircuit() (Eric Dumazet) - vxlan: unclone skb head before modifying eth header in route_shortcircuit() (Eric Dumazet) - vxlan: re-fetch eth header after route_shortcircuit() (Eric Dumazet) - um: vector: fix use-after-free in vector_mmsg_rx() (Michael Bommarito) - powerpc/ps3: Fix map failure path in dma_ioc0_map_pages() (Thorsten Blum) - net: ipv6: clear suppressed fib6 rule result (Zhiling Zou) - net: bridge: stop fast-leave after deleting a port group (Zhiling Zou) - mm/page_reporting: use system_freezable_wq to fix UAF during suspend (Link Lin) - binfmt_misc: reject a flag character as the field delimiter (Christian Brauner) - wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (Zhao Li) - tipc: avoid use-after-free in poll trace queue dumps (Zihan Xi) - netfilter: ipset: do not update comments from kernel-side hash adds (David Lee) - net/smc: fix socket use-after-free during link group termination (Xuanqiang Luo) - ipvs: do not propagate one-packet flag to synced conns (Zhiling Zou) - igbvf: Fix leak in TX DMA error cleanup (Matt Vollrath) - e1000: fix memory leak in e1000_probe() (Dawei Feng) - dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ (Md Sadre Alam) - ALSA: usb-audio: Clamp frame size in implicit-feedback mode (Sonali Pradhan) - ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set (Sonali Pradhan) - ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() (Baul Lee) - ASoC: tas2562: fix broken entries in the volume lookup table (Haidar Lee) - ASoC: tas2562: fix DVC coefficient write order (Haidar Lee) - ALSA: pcm: wake linked drain waiters on unlink (Norbert Szetei) - ALSA: lx6464es: fix period byte count for 16-bit streams (Xu Rao) - ALSA: 6fire: Fix UAF at error handling during probe (Takashi Iwai) - bpf: lwt: Fix dst reference leak on reroute failure (Xuanqiang Luo) - Bluetooth: HIDP: validate numbered report payloads (Sangho Lee) - Bluetooth: HIDP: reject frames without a transaction header (Sangho Lee) - audit: fix potential use-after-free in audit_del_rule() (Luxiao Xu) - audit: fix potential integer overflow in audit_log_n_string() (Zhan Xusheng) - sctp: validate Adaptation Indication parameter length (Charles Vosburgh) - mm/hugetlb: fix list corruption in allocate_file_region_entries() (Xiangfeng Cai) - mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() (Zi Yan) - pinctrl: bm1880: add missing select GENERIC_PINCONF (Benjamin Boortz) - pinctrl: devicetree: don't free uninitialized dev_name on error path (Karl Mehltretter) - rhashtable: clear stale iter-p on table restart (Cen Zhang (Microsoft)) - qede: sync udp_tunnel ports outside qede_lock in the recovery path (Denis V. Lunev) - octeontx2-pf: Set correct sequence for carrier off and tx queue stop (Suman Ghosh) - tracing/mmiotrace: Reset dropped_count in mmio_reset_data() (Masami Hiramatsu (Google)) - can: isotp: check register_netdevice_notifier() error in module init (Minhong He) - net: sxgbe: check descriptor ring allocation failures (Chenguang Zhao) - net: sxgbe: free TX rings on RX allocation failure (Chenguang Zhao) - scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req (Benjamin Block) - net: phylink: put link_gpio if phylink_create fails (Christian Marangi) - Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp (Jiale Yao) - hwmon: (pmbus) Fix return value from pmbus_update_byte_data() (Guenter Roeck) - wifi: mac80211: validate individual TWT params before driver setup (Zhao Li) - powerpc/boot: Fix treeboot-akebono CPU node lookup check (Thorsten Blum) - powerpc/boot: Fix treeboot-currituck CPU node lookup check (Thorsten Blum) - powerpc/boot: Fix simpleboot CPU node lookup check (Thorsten Blum) - hwmon: (adt7470) Fix PWM auto temp state array and bounds check (Luiz Angelo Daros de Luca) - hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read (Luiz Angelo Daros de Luca) - hwmon: (adt7470) Use cached PWM frequency value (Luiz Angelo Daros de Luca) - hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks (Luiz Angelo Daros de Luca) - hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() (Luiz Angelo Daros de Luca) - hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread (Luiz Angelo Daros de Luca) - hwmon: (adt7470) Fix cache updated before hardware write on I2C error (Luiz Angelo Daros de Luca) - hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors (Luiz Angelo Daros de Luca) - forcedeth: fix UAF of txrx_stats in nv_remove (Chenguang Zhao) - net: bridge: mrp: fix Option TLV length in MRP_Test frames (David Corvaglia) - hwmon: (nct6775-core) Prevent access to unsupported weight registers (Guenter Roeck) - smb: client: fix buffer leaks in SMB1 read and write (Dawei Feng) - scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (HyeongJun An) - scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer (HyeongJun An) - netfilter: nft_payload: fix mask build for partial field offload (Xiang Mei (Microsoft)) - netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH (Pablo Neira Ayuso) - assoc_array: trim the final shortcut word using the current chunk end (Michael Bommarito) - keys: make keyring key-chunk byte order agree with keyring_diff_objects() (Michael Bommarito) - keys: fix out-of-bounds read in keyring_get_key_chunk() (Michael Bommarito) - drm/mediatek: Check CRTC state before freeing (Ruoyu Wang) - netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (Xiang Mei) - phy: zynqmp: fix runtime PM leak on probe allocation failure (Radhey Shyam Pandey) - phy: zynqmp: fix clock error handling in xpsgtr_phy_init() (Radhey Shyam Pandey) - phy-zynqmp: Postpone getting clock rate until actually needed (Mike Looijmans) - phy: zynqmp: Allow variation in refclk rate (Sean Anderson) - ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare) - ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare) - dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA (Hongling Zeng) - tls: separate no-async decryption request handling from async (Sabrina Dubroca) - net: qrtr: ns: Raise node count limit to 512 (Youssef Samir) - net: qrtr: ns: Limit the maximum server registration per node (Manivannan Sadhasivam) - HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (Benjamin Tissoires) - HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (Lee Jones) - HID: logitech-dj: Standardise hid_report_enum variable nomenclature (Lee Jones) - gve: fix Rx queue stall on alloc failure (Eddie Phillips) - media: uvcvideo: Fix sequence number when no EOF (Ricardo Ribalda) - media: uvcvideo: Implement dual stream quirk to fix loss of usb packets (Isaac Scott) - net: mpls: initialize rtm_tos in mpls_getroute() (Yehyeong Lee) - raw: fix a typo in raw_icmp_error() (Eric Dumazet) - raw: remove unused variables from raw6_icmp_error() (Eric Dumazet) - openvswitch: fix GSO userspace truncation underflow (Kyle Zeng) - wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses (Devin Wittmayer) - tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (Weiming Shi) - drm/amdgpu: invoke pm_genpd_remove() before freeing genpd (Ce Sun) - drm/amdgpu: fix division by zero with invalid uvd dimensions (Boyuan Zhang) - drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (Alex Deucher) - drm/amdgpu/gfx8: drop unecessary BUG_ON() (Alex Deucher) - drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() (Alex Deucher) - tipc: clear sock-sk on the failed-insert path in tipc_sk_create() (Daehyeon Ko) - pppoe: reload header pointer after dev_hard_header() (Asim Viladi Oglu Manizada) - mac802154: llsec: reject frames shorter than the authentication tag (Doruk Tan Ozturk) - ila: reload IPv6 header after pskb_may_pull in checksum adjust (Michael Bommarito) - ice: use READ_ONCE() to access cached PHC time (Sergey Temerkhanov) - rbd: Reset positive result codes to zero in object map update path (Raphael Zimmer) - proc: Fix broken error paths for namespace links (Jann Horn) - net: hip04: fix RX buffer leak on build_skb failure (Fan Wu) - net/x25: fix use-after-free in x25_kill_by_neigh() (David Lee) - net/iucv: fix use-after-free of a severed iucv_path (Bryam Vargas) - net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() (Hidayath Khan) - geneve: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk) - net: slip: serialize receive against buffer reallocation (Sungmin Kang) - vxlan: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk) - phonet: pep: fix use-after-free in pep_get_sb() (Breno Leitao) - iommu/vt-d: Disallow SVA if page walk is not coherent (Lu Baolu) - binfmt_elf_fdpic: only honour the first PT_INTERP (Christian Brauner) - libceph: remove debugfs files before client teardown (Douya Le) - libceph: reject zero bucket types in crush_decode (Douya Le) - libceph: Reject monmaps advertising zero monitors (Raphael Zimmer) - libceph: refresh auth-authorizer_buf{,_len} after authorizer update (Shuangpeng Bai) - libceph: guard missing CRUSH type name lookup (Zhao Zhang) - libceph: Fix multiplication overflow in decode_new_up_state_weight() (Raphael Zimmer) - libceph: bound get_version reply decode to front len (Douya Le) - ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (Bryam Vargas) - mptcp: only set DATA_FIN when a mapping is present (Michael Bommarito) - Revert 'arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates' (Will Deacon) - arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates (Will Deacon) - tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() (Masami Hiramatsu (Google)) - tracing/probes: Fix potential underflow in LEN_OR_ZERO macro (Masami Hiramatsu (Google)) - tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args() (Masami Hiramatsu (Google)) - tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() (Masami Hiramatsu (Google)) - tracing: Fix resource leak on mmiotrace trace_pipe close (deepakraog) - tracing: Fix mmiotrace possible NULL dereferencing of hiter-dev (Steven Rostedt) - intel_th: fix MSC output device reference leak (Guangshuo Li) - comedi: comedi_parport: deal with premature interrupt (Ian Abbott) - x86/boot/compressed: Disable jump tables (Nathan Chancellor) - cdrom: fix stack out-of-bounds read in CDROMVOLCTRL (Xu Rao) - binfmt_misc: set have_execfd only once the interpreter is opened (Christian Brauner) - exec: fix unsigned loop counter wrap in transfer_args_to_stack() (Christian Brauner) - Bluetooth: RFCOMM: Fix session UAF in set_termios (Chengfeng Ye) - staging: rtl8723bs: fix inverted HT40 secondary channel offset (MinJea Kim) - staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() (Moksh Panicker) - wifi: brcmfmac: make release_scratchbuffers idempotent (Fan Wu) - wifi: wilc1000: validate assoc response length before subtracting header (Huihui Huang) - wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper (Doruk Tan Ozturk) - wifi: ath6kl: fix OOB access from firmware ADDBA window size (Tristan Madani) - media: vivid: check for vb2_is_busy() when toggling caps (Hans Verkuil) - media: vimc: fix reference leak on failed device registration (Guangshuo Li) - media: vidtv: fix reference leak on failed device registration (Guangshuo Li) - media: vb2: use ssize_t for vb2_read/vb2_write (Zile Xiong) - media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() (Sergey Shtylyov) - media: tegra-video: vi: fix invalid u32 return value in format lookup (Hungyu Lin) - media: sun4i-csi: Return queued buffers on start_streaming() failure (Valery Borovsky) - media: saa7134: Fix a possible memory leak in saa7134_video_init1 (Ma Ke) - media: rtl2832_sdr: Return queued buffers on start_streaming() failure (Valery Borovsky) - media: rtl2832: fix use-after-free in rtl2832_remove() (Deepanshu Kartikey) - media: radio-si476x: Unregister v4l2_device on probe failure (Myeonghun Pak) - media: pwc: Return queued buffers on start_streaming() failure (Valery Borovsky) - media: pwc: Drain fill_buf on start_streaming() failure (Valery Borovsky) - media: pci: dm1105: Free allocated workqueue (Krzysztof Kozlowski) - media: msi2500: Return queued buffers on start_streaming() failure (Valery Borovsky) - media: meson: vdec: Fix memory leak in error path of vdec_open (Anand Moon) - media: cx23885: add ioremap return check and cleanup (Wang Jun) - media: cx231xx: fix devres lifetime (Johan Hovold) - media: cedrus: skip invalid H.264 reference list entries (Pengpeng Hou) - media: cedrus: Fix missing cleanup in error path (Samuel Holland) - media: cedrus: clean up media device on probe failure (Myeonghun Pak) - media: cec: seco: unregister adapter on IR probe failure (Myeonghun Pak) - media: airspy: Return queued buffers on start_streaming() failure (Valery Borovsky) - drm/vmwgfx: Validate vmw_surface_metadata::array_size (Ian Forbes) - drm/amdgpu: fix bo-pin leaking in amdgpu_bo_create_reserved (Zhu Lingshan) - drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) (Timur Kristof) - drm/amdgpu: Fix VFCT bus number matching with soft filter (Mario Limonciello) - drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (Joonas Lahtinen) - drm/i915/gem: Do not leak siblings[] on proto context error (Joonas Lahtinen) - drm/i915: Return NULL on error in active_instance (Joonas Lahtinen) - drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() (Alex Deucher) - drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() (Alex Deucher) - drm/radeon: fix r100_copy_blit for large BOs (Pavel Ondracka) - drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (Wentao Liang) - drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (Sergey Shtylyov) - can: bcm: track a single source interface for ANYDEV timeout/throttle ops (Oliver Hartkopp) - can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() (Oliver Hartkopp) - can: bcm: fix stale rx/tx ops after device removal (Oliver Hartkopp) - can: bcm: add missing device refcount for CAN filter removal (Oliver Hartkopp) - can: bcm: validate frame length in bcm_rx_setup() for RTR replies (Oliver Hartkopp) - can: bcm: extend bcm_tx_lock usage for data and timer updates (Oliver Hartkopp) - can: bcm: fix CAN frame rx/tx statistics (Oliver Hartkopp) - can: bcm: add locking when updating filter and timer values (Oliver Hartkopp) - can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (Lee Jones) - bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (Chengfeng Ye) - net: ipv6: fix dif and sdif mismatch in raw6_icmp_error (Li RongQing) - raw: use more conventional iterators (Eric Dumazet) - net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation (Alexei Lazar) - net/mlx5e: Report zero bandwidth for non-ETS traffic classes (Alexei Lazar) - net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule (Yael Chemla) - net: qrtr: restrict socket creation to the initial network namespace (Aldo Ariel Panzardo) - hinic: remove unused ethtool RSS user configuration buffers (Chenguang Zhao) - ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup (Eric Dumazet) - octeontx2-vf: set TC flower flag on MCAM entry allocation (Suman Ghosh) - net: stmmac: reset residual action in L3L4 filters on delete (Nazim Amirul) - net: stmmac: fix l3l4 filter rejecting unsupported offload requests (Nazim Amirul) - net: stmmac: add tc flower filter for EtherType matching (Ong Boon Leong) - tipc: fix u16 MTU truncation in media and bearer MTU validation (Cen Zhang (Microsoft)) - vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (Harshaka Narayana) - sctp: auth: verify auth requirement when auth_chunk is NULL (Qing Luo) - net: hsr: fix memory leak on slave unregistration by removing synced VLANs (Eric Dumazet) - net: bridge: vlan: fix vlan range dumps starting with pvid (Nikolay Aleksandrov) - wifi: brcmfmac: fix 802.1X-SHA256 call trace warning (Shelley Yang) - wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() (Lorenzo Bianconi) - tipc: fix infinite loop in __tipc_nl_compat_dumpit (Helen Koike) - nexthop: initialize extack in nh_res_bucket_migrate() (Xiang Mei (Microsoft)) - sctp: validate stream count in sctp_process_strreset_inreq() (Cen Zhang (Microsoft)) - sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (HanQuan) - amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN (Prashanth Kumar KR) - wifi: mac80211: recalculate TIM when a station enters power save (Andrew Pope) - iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (Li RongQing) - iommu/amd: Bound the early ACPI HID map (Pengpeng Hou) - wifi: mwifiex: bound uAP association event IEs to the event buffer (HE WEI (???)) - wan: wanxl: Only reset hardware after BAR mapping (Ruoyu Wang) - nfp: Check resource mutex allocation (Ruoyu Wang) - dpaa2-eth: put MAC endpoint device on disconnect (Guangshuo Li) - net: dpaa2-eth: assign priv-mac after dpaa2_mac_connect() call (Vladimir Oltean) - dpaa2-switch: put MAC endpoint device on disconnect (Guangshuo Li) - net/packet: avoid fanout hook re-registration after unregister (David Lee) - hwmon: occ: validate poll response sensor blocks (Pengpeng Hou) - hwmon: (occ) Delay hwmon registration until user request (Eddie James) - hwmon: (occ) Add sysfs entries for additional extended status bits (Eddie James) - hwmon: (occ) Add sysfs entry for OCC mode (Eddie James) - hwmon: (occ) Add sysfs entry for IPS (Idle Power Saver) status (Eddie James) - usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect (Diego Fernando Mancera Gomez) - ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI (Shengjiu Wang) - ASoC: bt-sco: fix bt-sco-pcm-wb dai widget don't connect to the endpoint (Jiaxin Yu) - btrfs: free mapping node on duplicate reloc root insert (Guanghui Yang) - wifi: carl9170: fix buffer overflow in rx_stream failover path (Tristan Madani) - wifi: carl9170: fix OOB read from off-by-two in TX status handler (Tristan Madani) - wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read (Tristan Madani) - wifi: ath6kl: fix OOB read from firmware IE lengths in connect event (Tristan Madani) - wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler (Tristan Madani) - firewire: net: Fix fragmented datagram reassembly (Ruoyu Wang) - wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() (Dmitry Morgun) - watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() (Tzung-Bi Shih) - hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop (Guenter Roeck) - hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop (Edward Adam Davis) - wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (Cheng Yongkang) - usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits (Xincheng Zhang) - bpf: Fix ld_{abs,ind} failure path analysis in subprogs (Daniel Borkmann) - Revert 'drm/amd/display: Add missing kdoc for ALLM parameters' (Sasha Levin) - crypto: rsa-pkcs1pad: Don't WARN on an empty digest (Doruk Tan Ozturk) - USB: serial: option: add TDTECH MT5710-CN (Chukun Pan) - USB: serial: keyspan_pda: fix data loss on receive throttling (Johan Hovold) - USB: serial: io_edgeport: cap received transmit credits (Sunho Park) - USB: serial: ftdi_sio: add support for E+H FXA291 (Tim Pambor) - usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer (Muhammad Bilal) - usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown (Fan Wu) - usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() (Sonali Pradhan) - USB: gadget: fsl-udc: fix device name leak on probe failure (Johan Hovold) - USB: gadget: snps-udc: fix device name leak on probe failure (Johan Hovold) - usb: gadget: printer: fix infinite loop in printer_read() (Melbin K Mathew) - usb: gadget: f_midi: cancel pending IN work before freeing the midi object (Fan Wu) - usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback (Jinchao Wang) - usb: chipidea: fix usage_count leak when autosuspend_delay is negative (Xu Yang) - USB: storage: add NO_ATA_1X quirk for Longmai USB Key (Huang Wei) - wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() (Huihui Huang) - mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (Weiming Shi) - sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) - net/sched: act_tunnel_key: Defer dst_release to RCU callback (Jamal Hadi Salim) - drm/i915/selftests: Fix GT PM sort comparators (Emre Cecanpunar) - ksmbd: validate compound request size before reading StructureSize2 (Xiang Mei (Microsoft)) - can: j1939: fix lockless local-destination check (Shuhao Fu) - powerpc/vtime: Initialize starttime at boot for native accounting (Shrikanth Hegde) - powerpc/time: Prepare to stop elapsing in dynticks-idle (Frederic Weisbecker) - sched/vtime: Get rid of generic vtime_task_switch() implementation (Alexander Gordeev) - powerpc: remove the last remnants of cputime_t (Nicholas Piggin) - powerpc/time: Fix sparse warnings (He Ying) - drm/i915/gt: use correct selftest config symbol (Pengpeng Hou) - smb/client: handle overlapping allocated ranges in fallocate (Huiwen He) - Bluetooth: qca: fix NVM tag length underflow in TLV parser (Xiang Mei) - ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (Takashi Iwai) - ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning (Rosen Penev) - ata: sata_dwc_460ex: remove variable num_processed (Colin Ian King) - ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts (Rosen Penev) - ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered (Rosen Penev) - net/iucv: take a reference on the socket found in afiucv_hs_rcv() (Bryam Vargas) - ipv4: fib: free fib_alias with kfree_rcu() on insert error path (Weiming Shi) - ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (Norbert Szetei) - firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context (Pushpendra Singh) - ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (Uday Khare) - ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (Christian Hewitt) - wifi: cfg80211: bound element ID read when checking non-inheritance (HE WEI (???)) - wifi: brcmfmac: initialize SDIO data work before cleanup (Runyu Xiao) - wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (Cen Zhang) - wifi: cfg80211: reject unsupported PMSR FTM location requests (Zhao Li) - wifi: cfg80211: validate PMSR FTM preamble range (Zhao Li) - wifi: cfg80211: validate PMSR measurement type data (Zhao Li) - wifi: p54: validate RX frame length in p54_rx_eeprom_readback() (Xiang Mei) - wifi: libertas: fix memory leak in helper_firmware_cb() (Dawei Feng) - wifi: mac80211_hwsim: clamp virtio RX length before skb_put (Bryam Vargas) - wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (Abdun Nihaal) - wifi: cfg80211: cancel sched scan results work on unregister (Cen Zhang) - xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert (Xiang Mei (Microsoft)) - RDMA/irdma: Prevent overflows in memory contiguity checks (Aleksandrova Alyona) - RDMA/siw: publish QP after initialization (Ruoyu Wang) - RDMA/siw: Only check attrs-cap.max_send_wr in siw_create_qp (Guoqing Jiang) - RDMA/hns: Fix potential integer overflow in mhop hem cleanup (Danila Chernetsov) - firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (Unnathi Chalicheemala) - btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (Filipe Manana) - btrfs: reject free space cache with more entries than pages (Xiang Mei) - mtd: nand: mtk-ecc: stop on ECC idle timeouts (Pengpeng Hou) - mtd: mtdswap: remove debugfs stats file on teardown (Pengpeng Hou) - IB/mad: Drop unmatched RMPP responses before reassembly (Michael Bommarito) - KVM: VMX: Make vmread_error_trampoline() uncallable from C code (Sean Christopherson) - Input: ims-pcu - fix logic error in packet reset (Dmitry Torokhov) - Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (Seungjin Bae) - dmaengine: sh: rz-dmac: Move interrupt request after everything is set up (Claudiu Beznea) - can: isotp: serialize TX state transitions under so-rx_lock (Oliver Hartkopp) - can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER (Oliver Hartkopp) - KVM: x86/mmu: Fix use-after-free on vendor module reload (Phil Rosenthal) - KVM: nVMX: Hide shadow VMCS right after VMCLEAR (Hyunwoo Kim) - macsec: don't read an unset MAC header in macsec_encrypt() (Daehyeon Ko) - futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (Sebastian Andrzej Siewior) - nvmet-tcp: Fix potential UAF when ddgst mismatch (Sagi Grimberg) [5.15.0-324.213.5] - Revert 'rseq: Introduce feature size and alignment ELF auxiliary vector entries' (Prakash Sangappa) [Orabug: 39874250] [5.15.0-324.213.4] - Enable Time slice extension (Prakash Sangappa) [Orabug: 39047421] - rseq: Increase struct rseq size to match mainline linux (Prakash Sangappa) [Orabug: 39047421] - rseq: Introduce extensible rseq ABI (Prakash Sangappa) [Orabug: 39047421] - rseq: Introduce feature size and alignment ELF auxiliary vector entries (Mathieu Desnoyers) [Orabug: 39047421] - Update AT_VA_RESERVATION number (Prakash Sangappa) [Orabug: 39047421] - selftests/rseq: Make registration flexible for legacy and optimized mode (Thomas Gleixner) [Orabug: 39047421] - selftests/rseq: Skip tests if time slice extensions are not available (Thomas Gleixner) [Orabug: 39047421] - rseq: Don't advertise time slice extensions if disabled (Thomas Gleixner) [Orabug: 39047421] - selftests/rseq: Add rseq slice histogram script (Peter Zijlstra) [Orabug: 39047421] - rseq: Lower default slice extension (Peter Zijlstra) [Orabug: 39047421] - rseq: Move slice_ext_nsec to debugfs (Peter Zijlstra) [Orabug: 39047421] - rseq: Allow registering RSEQ with slice extension (Peter Zijlstra) [Orabug: 39047421] - selftests/rseq: Implement time slice extension test (Thomas Gleixner) [Orabug: 39047421] - entry: Hook up rseq time slice extension (Thomas Gleixner) [Orabug: 39047421] - rseq: Implement rseq_grant_slice_extension() (Thomas Gleixner) [Orabug: 39047421] - rseq: Reset slice extension when scheduled (Thomas Gleixner) [Orabug: 39047421] - rseq: Implement time slice extension enforcement timer (Prakash Sangappa) [Orabug: 39047421] - rseq: Implement syscall entry work for time slice extensions (Thomas Gleixner) [Orabug: 39047421] - rseq: Implement sys_rseq_slice_yield() (Thomas Gleixner) [Orabug: 39047421] - rseq: Add prctl() to enable time slice extensions (Thomas Gleixner) [Orabug: 39047421] - rseq: Add statistics for time slice extensions (Thomas Gleixner) [Orabug: 39047421] - rseq: Provide static branch for runtime debugging (Thomas Gleixner) [Orabug: 39047421] - rseq: Expose lightweight statistics in debugfs (Thomas Gleixner) [Orabug: 39047421] - rseq: Provide static branch for time slice extensions (Thomas Gleixner) [Orabug: 39047421] - rseq: Add fields and constants for time slice extension (Thomas Gleixner) [Orabug: 39047421] - sched/fair: Disable affine wakeups at NUMA domain levels on Exadata (Daniel Jordan) [Orabug: 38770281] - drivers/soc/pensando/penfw: Added attest_meas and get cert_chain to penfw_util (Rahshekh) [Orabug: 39818086] - drivers/soc/pensando/penfw_sysfs: fix bl31_show vers buffer size (Rahshekh) [Orabug: 39818086] - mmc: core: Use HPI to interrupt lengthy cache flush (#494) (Brad Larson) [Orabug: 39818086] - xen/ovmapi: terminate values passed to xenbus_write (Joe Jin) [Orabug: 39851069] - xen/ovmapi: free queued events on release (Joe Jin) [Orabug: 39851069] - xen/ovmapi: prevent duplicate app registration (Joe Jin) [Orabug: 39851069] - xen/ovmapi: avoid raw user pointer access in get_next_event (Joe Jin) [Orabug: 39851069] - xen/ovmapi: reject oversized posted event payloads (Joe Jin) [Orabug: 39851069] - IB/rxe: use rxe_drop_ref to release rxe_pd (Wengang Wang) [Orabug: 39831970] - IB/uverbs: enhance authorization checks for ib_uverbs_share_pd() (Wengang Wang) [Orabug: 39831970] - net/rds: restrict RDS_INFO dumps to caller netns (Praveen Kumar Kannoju) [Orabug: 39832021] - rds: tcp: fix uninit-value in __inet_bind (Tabrez Ahmed) [Orabug: 39668599] - rds: tcp: cleanup if kmem_cache_alloc fails in rds_tcp_conn_alloc() (Sowmini Varadhan) [Orabug: 39668599] - Revert 'x86/alternatives: Add alt_instr.flags' (Harshit Mogalapalli) [Orabug: 39864327] - KVM: x86/mmu: Stop needlessly making MMU pages available for TDP MMU faults (David Matlack) [Orabug: 39830590] {CVE-2026-64561} - KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Sean Christopherson) [Orabug: 39830590,39832946] {CVE-2026-64561} - KVM: x86/mmu: Rename __direct_map() to direct_map() (David Matlack) [Orabug: 39830590] {CVE-2026-64561} - KVM: x86/mmu: Split out TDP MMU page fault handling (David Matlack) [Orabug: 39830590] {CVE-2026-64561} - KVM: Rename mmu_notifier_* to mmu_invalidate_* (Chao Peng) [Orabug: 39830590] {CVE-2026-64561} - KVM: x86/mmu: Document the 'rules' for using host_pfn_mapping_level() (Sean Christopherson) [Orabug: 39830590] {CVE-2026-64561} - KVM: x86/mmu: Rename pte_list_{destroy,remove}() to show they zap SPTEs (Sean Christopherson) [Orabug: 39830590] {CVE-2026-64561} - KVM: x86/mmu: Directly 'destroy' PTE list when recycling rmaps (Sean Christopherson) [Orabug: 39830590] {CVE-2026-64561} - x86/bugs: Make Safe-RET robust against interrupt injection (Borislav Petkov) [Orabug: 39784615,39853775] {CVE-2026-68480} - x86/alternatives: Disable interrupts and sync when optimizing NOPs in place (Thomas Gleixner) [Orabug: 39784615] {CVE-2026-68480} - x86/alternative: Support relocations in alternatives (Peter Zijlstra) [Orabug: 39784615] {CVE-2026-68480} - x86/alternative: Make debug-alternative selective (Peter Zijlstra) [Orabug: 39784615] {CVE-2026-68480} - x86/alternatives: Add alt_instr.flags (Borislav Petkov) [Orabug: 39784615] {CVE-2026-68480} - x86/asm: Provide ALTERNATIVE_3 (Peter Zijlstra) [Orabug: 39784615] {CVE-2026-68480} [5.15.0-324.213.3] - LTS version: v5.15.213 (Vijayendra Suman) - posix-cpu-timers: Prevent UAF caused by non-leader exec() race (Thomas Gleixner) [Orabug: 39807438] {CVE-2026-64560} - LTS version: v5.15.212 (Vijayendra Suman) - perf/x86/amd/core: Always use the NMI latency mitigation (Sandipan Das) - ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (Hyeongjun An) [Orabug: 39853280] {CVE-2026-64479} - iio: imu: inv_icm42600: fix timestamp clock period by using lower value (Jean-Baptiste Maneyrol) - ALSA: seq: Check UMP support for midi_version change (Takashi Iwai) - ALSA: seq: Skip event type filtering for UMP events (Takashi Iwai) - iio: invensense: fix odr switching to same value (Jean-Baptiste Maneyrol) - iio: imu: inv_mpu6050: fix frequency setting when chip is off (Jean-Baptiste Maneyrol) - ALSA: seq: Avoid confusion of aligned read size (Takashi Iwai) - Bluetooth: L2CAP: Fix regressions caused by reusing ident (Luiz Augusto von Dentz) - KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers (Marc Zyngier) - posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu() (Zhan Xusheng) - regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() (Xu Wang) - audit: fix potential integer overflow in audit_log_n_hex() (Ricardo Robaina) - audit: add audit_log_nf_skb helper function (Ricardo Robaina) - btrfs: fix incorrect buffered IO fallback for append direct writes (Qu Wenruo) - crypto: qat - validate RSA CRT component lengths (Giovanni Cabiddu) [Orabug: 39785885] {CVE-2026-64304} - btrfs: fix false IO failure after falling back to buffered write (Qu Wenruo) - crypto: qat - fix restarting state leak on allocation failure (Ahsan Atta) - btrfs: do not trim a device which is not writeable (Qu Wenruo) [Orabug: 39843586] {CVE-2026-64593} - usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile (Neill Kapron) - crypto: atmel-sha204a - drop hwrng quality reduction for ATSHA204A (Thorsten Blum) - crypto: atmel - Drop explicit initialization of struct i2c_device_id::driver_data to 0 (Uwe Kleine-Konig) - crypto: atmel-sha204a - Mark OF related data as maybe unused (Krzysztof Kozlowski) - usb: gadget: f_fs: initialize reset_work at allocation time (Tyler Baker) - usb: typec: tcpm: Fix VDM type for Enter Mode commands (Andy Yan) - usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect() (Mauricio Faria de Oliveira) - usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (Fan Wu) - gpio: pca953x: Make platform teardown callback return void (Uwe Kleine-Konig) - leds: lm3601x: Improve error reporting for problems during .remove() (Uwe Kleine-Konig) - leds: lm3697: Remove duplicated error reporting in .remove() (Uwe Kleine-Konig) - drm/i2c/sil164: Drop no-op remove function (Uwe Kleine-Konig) - usb: iowarrior: remove inherent race with minor number (Oliver Neukum) - bpf: Allow LPM map access from sleepable BPF programs (Vlad Poenaru) [Orabug: 39786046] {CVE-2026-64352} - bpf: Consistently use bpf_rcu_lock_held() everywhere (Andrii Nakryiko) - bpf: Convert lpm_trie.c to rqspinlock (Kumar Kartikeya Dwivedi) - bpf: Reject fragmented frames in devmap (Zhao Zhang) [Orabug: 39786052] {CVE-2026-64355} - hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length (Tristan Madani) - hfs/hfsplus: prevent getting negative values of offset/length (Viacheslav Dubeyko) - xfs: use null daddr for unset first bad log block (Yousef Alhouseen) - xfs: Remove dead code (Jiapeng Chong) - xfs: Remove redundant assignment of mp (Jiapeng Chong) - serial: 8250_mid: Disable DMA for selected platforms (Andy Shevchenko) - serial: 8250_mid: Remove 8250_pci usage (Ilpo Jarvinen) - HID: appleir: fix UAF on pending key_up_timer in remove() (Manish Khadka) [Orabug: 39786074] {CVE-2026-64363} - treewide: Switch/rename to timer_delete[_sync]() (Thomas Gleixner) - proc: protect ptrace_may_access() with exec_update_lock (part 1) (Jann Horn) [Orabug: 39786095] {CVE-2026-64371} - HID: multitouch: fix out-of-bounds bit access on mt_io_flags (Trung Nguyen) [Orabug: 39786078] {CVE-2026-64364} - HID: add haptics page defines (Angela Czubak) - proc: protect ptrace_may_access() with exec_update_lock (FD links) (Jann Horn) [Orabug: 39786112] {CVE-2026-64375} - proc: rename proc_setattr to proc_nochmod_setattr (Christoph Hellwig) - proc: Move fdinfo PTRACE_MODE_READ check into the inode .permission operation (Tyler Hicks) - proc: use generic setattr() for /proc//net (Thomas Weissschuh) - X.509: Fix validation of ASN.1 certificate header (Lukas Wunner) - ksmbd: track the connection owning a byte-range lock (Namjae Jeon) - ksmbd: centralize ksmbd_conn final release to plug transport leak (Daemyung Kang) - ksmbd: destroy async_ida in ksmbd_conn_free() (Daemyung Kang) - ksmbd: fix mechToken leak when SPNEGO decode fails after token alloc (Greg Kroah-Hartman) - ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger (Namjae Jeon) - smb: client: harden POSIX SID length parsing (Zihan Xi) [Orabug: 39786128] {CVE-2026-64380} - smb: client: use unaligned reads in parse_posix_ctxt() (Zihan Xi) - smb: client: mask server-provided mode to 07777 in modefromsid (Norbert Manthey) [Orabug: 39786124] {CVE-2026-64379} - smb: client: resolve SWN tcon from live registrations (Michael Bommarito) [Orabug: 39786200] {CVE-2026-64401} - cifs: Add tracing for the cifs_tcon struct refcounting (David Howells) - smb: client: Fix next buffer leak in receive_encrypted_standard() (Haoxiang Li) [Orabug: 39786131] {CVE-2026-64381} - Bluetooth: L2CAP: cancel pending_rx_work before taking conn-lock (Runyu Xiao) [Orabug: 39760901] {CVE-2026-64206} - Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (Hyunwoo Kim) - Bluetooth: L2CAP: Fix not tracking outstanding TX ident (Luiz Augusto von Dentz) - netfilter: ebtables: zero chainstack array (Florian Westphal) [Orabug: 39786232] {CVE-2026-64413} - netfilter: ebtables: Use vmalloc_array() to improve code (Rong Qianfeng) - gpio: sch: use raw_spinlock_t in the irq startup path (Runyu Xiao) - gpio: sch: use new GPIO line value setter callbacks (Bartosz Golaszewski) - coresight: etb10: restore atomic_t for shared reading state (Runyu Xiao) - PCI: Skip Resizable BAR restore on read error (Marco Nenciarini) - PCI: Move Resizable BAR code to rebar.c (Ilpo Jarvinen) - PCI: Add kerneldoc for pci_resize_resource() (Ilpo Jarvinen) - PCI: Fix restoring BARs on BAR resize rollback path (Ilpo Jarvinen) - PCI: Free saved list without holding pci_bus_sem (Ilpo Jarvinen) - PCI: Prevent resource tree corruption when BAR resize fails (Ilpo Jarvinen) - staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() (Alexandru Hossu) [Orabug: 39786307] {CVE-2026-64441} - staging: rtl8723bs: fix spaces around binary operators (Nikolay Kulikov) - staging: rtl8723bs: core: move constants to right side in comparison (William Hansen-Baird) - staging: rtl8723bs: remove redundant braces in if statements (Sevinj Aghayeva) - staging: rtl8723bs: Remove redundant else branches. (Sevinj Aghayeva) - PCI: mediatek: Fix IRQ domain leak when port fails to enable (Manivannan Sadhasivam) [Orabug: 39786366] {CVE-2026-64461} - PCI: mediatek: Convert bool to single quirks entry and bitmap (Christian Marangi) - PCI: controller: Use dev_fwnode() instead of of_fwnode_handle() (Jiri Slaby) - staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie() (Alexandru Hossu) [Orabug: 39786327] {CVE-2026-64446} - staging: rtl8723bs: Fix space issues (Franziska Naepelt) - staging: rtl8723bs: Fix indentation issues (Franziska Naepelt) - PCI: imx6: Fix IMX6SX_GPR12_PCIE_TEST_POWERDOWN handling (Richard Zhu) - smb: client: restrict implied bcc[0] exemption to responses without data area (Shoichiro Miyamoto) [Orabug: 39786332] {CVE-2026-64448} - cifs: remove unused server parameter from calc_smb_size() (Enzo Matsumiya) - smb2: small refactor in smb2_check_message() (Enzo Matsumiya) - cifs: remove check of list iterator against head past the loop body (Jakob Koschel) - cifs: Create a new shared file holding smb2 pdu definitions (Ronnie Sahlberg) - PCI: altera: Fix resource leaks on probe failure (Mahesh Vaidya) - vfio/pci: Release the VGA arbiter client on register_device() failure (Alex Williamson) [Orabug: 39786409] {CVE-2026-64475} - ALSA: aoa: check snd_ctl_new1() return value (Zhao Dongdong) - iio: common: st_sensors: honour channel endianness in read_axis_data (Herman van Hazendonk) - bitops: make BYTES_TO_BITS() treewide-available (Alexander Lobakin) - iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading (Jean-Baptiste Maneyrol) - iio: imu: inv_icm42600: stabilized timestamp in interrupt (Jean-Baptiste Maneyrol) - iio: invensense: fix timestamp glitches when switching frequency (Jean-Baptiste Maneyrol) - iio: invensense: remove redundant initialization of variable period (Colin Ian King) - iio: imu: inv_mpu6050: use the common inv_sensors timestamp module (Jean-Baptiste Maneyrol) - iio: make invensense timestamp module generic (Jean-Baptiste Maneyrol) - iio: move inv_icm42600 timestamp module in common (Jean-Baptiste Maneyrol) - iio: imu: inv_icm42600: make timestamp module chip independent (Jean-Baptiste Maneyrol) - iio: hid-sensor-rotation: Fix stale or zero output when reading raw values (Zhang Lixu) - iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ (Runyu Xiao) - ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup (Rafael J. Wysocki) [Orabug: 39786502] {CVE-2026-64510} - ACPI: CPPC: Suppress UBSAN warning caused by field misuse (Jeremy Linton) [Orabug: 39786508] {CVE-2026-64512} - mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout (Pengpeng Hou) - mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout (Pengpeng Hou) - mtd: rawnand: fsl_ifc: return errors for failed page reads (Pengpeng Hou) - mmc: vub300: defer reset until cmd_mutex is unlocked (Runyu Xiao) - mtd: mchp23k256: use SPI match data for chip caps (Pengpeng Hou) - mtd: onenand: samsung: report DMA completion timeouts (Pengpeng Hou) - wifi: mwifiex: fix permanently busy scans after multiple roam iterations (Rafael Beims) - wifi: mac80211: free ack status frame on TX header build failure (Zhiling Zou) - powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access() (Junrui Luo) - reset: sunxi: fix memory region leak on ioremap failure (Zhao Dongdong) - ipvs: fix more places with wrong ipv6 transport offsets (Julian Anastasov) - memstick: ms_block: reject a card that reports too many blocks (Maoyi Xie) - macsec: fix promiscuity refcount leak in macsec_dev_open() (James Raphael Tiovalen) - llc: fix SAP refcount leak when creating incoming sockets (Luoxuanqiang) - Bluetooth: btrtl: validate firmware patch bounds (Laxman Acharya Padhya) - net: openvswitch: reject oversized nested action attrs (Asim Viladi Oglu Manizada) [Orabug: 39789564,39816016,39819143] {CVE-2026-64531} - regulator: ltc3676: Fix incorrect IRQSTAT bit offsets (Abhishek Ojha) - wifi: mac80211: fix memory leak in ieee80211_register_hw() (Dawei Feng) - wifi: rt2x00: avoid full teardown before work setup in probe (Runyu Xiao) - cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed (Farhad Alemi) - riscv: Prevent NULL pointer dereference in machine_kexec_prepare() (Tao Liu) - drbd: reject data replies with an out-of-range payload size (Michael Bommarito) - ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (Yizhou Zhao) - ipvs: use parsed transport offset in SCTP state lookup (Yizhou Zhao) - llc: fix SAP refcount leak in llc_ui_autobind() (Shuangpeng Bai) - mac802154: remove interfaces with RCU list deletion (Yousef Alhouseen) - s390/monwriter: Reject buffer reuse with different data length (Gerald Schaefer) - hwmon: (asus_atk0110) Check package count before accessing element (Hyeongjun An) - ata: pata_pxa: Fix DMA channel leak on probe error (Xu Wang) - orangefs: keep the readdir entry size 64-bit in fill_from_part() (Bryam Vargas) - tracing/probes: Fix double addition of offset for @+FOFFSET (Masami Hiramatsu) - net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Bryam Vargas) - fsl/fman: Free init resources on KeyGen failure in fman_init() (Haoxiang Li) - net: liquidio: fix BAR resource leak on PF number failure (Haoxiang Li) - hwmon: (w83793) remove vrm sysfs file on probe failure (Pengpeng Hou) - hwmon: (w83627hf) remove VID sysfs files on error and remove (Pengpeng Hou) - bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp() (Abdun Nihaal) - batman-adv: clean untagged VLAN on netdev registration failure (Sven Eckelmann) - batman-adv: ensure minimal ethernet header on TX (Sven Eckelmann) - batman-adv: retrieve ethhdr after potential skb realloc on RX (Sven Eckelmann) - nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (Shivam Kumar) [Orabug: 39789573] {CVE-2026-64534} - ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit (Shitalkumar Gandhi) - ieee802154: ca8210: fix cas_ctl leak on spi_async failure (Shitalkumar Gandhi) - ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation (Michael Bommarito) - ieee802154: admin-gate legacy LLSEC dump operations (Michael Bommarito) - net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) - net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) - net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) - net: ena: clean up XDP TX queues when regular TX setup fails (Dawei Feng) - net: sit: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) - gpios: palmas: add .get_direction() op (Andreas Kemnade) - cpu: hotplug: Bound hotplug states sysfs output (Bradley Morgan) - cpu: hotplug: Preserve per instance callback errors (Bradley Morgan) - Input: ims-pcu - fix type confusion in CDC union descriptor parsing (Dmitry Torokhov) - Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing (Dmitry Torokhov) - Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging (Dmitry Torokhov) - Input: ims-pcu - fix DMA mapping violation in line setup (Dmitry Torokhov) - Input: ims-pcu - add response length checks (Dmitry Torokhov) - Input: ims-pcu - validate control endpoint type (Dmitry Torokhov) - Input: ims-pcu - release data interface on disconnect (Dmitry Torokhov) - Input: ims-pcu - fix use-after-free and double-free in disconnect (Dmitry Torokhov) - scsi: elx: efct: Fix I/O leak on unsupported additional CDB (Haoxiang Li) - scsi: elx: efct: Fix refcount leak in efct_hw_io_abort() (Xu Wang) - scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (Bryam Vargas) - scsi: target: Bound PR-OUT TransportID parsing to the received buffer (Bryam Vargas) - scsi: xen: scsiback: Free unsubmitted command instead of double-putting it (Michael Bommarito) - scsi: xen: scsiback: Free the command tag on the TMR submit-failure path (Michael Bommarito) - scsi: sg: Report request-table problems when any status is set (Xu Rao) - scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path (Haoxiang Li) - dm-verity: increase sprintf buffer size (Mikulas Patocka) - dm_early_create: fix freeing used table on dm_resume failure (Mikulas Patocka) - dm-stats: fix merge accounting (Mikulas Patocka) - dm-stats: fix dm_jiffies_to_msec64 (Mikulas Patocka) - dm-log: fix a bitset_size overflow on 32bit machines (Benjamin Marzinski) - dm-bufio: fix wrong count calculation in dm_bufio_issue_discard (Mikulas Patocka) - dm era: fix out-of-bounds memory access for non-zero start sector (Samuel Moelius) - dm thin metadata: fix metadata snapshot consistency on commit failure (Ming-Hung Tsai) - dm thin metadata: fix superblock refcount leak on snapshot shadow failure (Genjian Zhang) - net: sparx5: unregister blocking notifier on init failure (Haoxiang Li) - can: bcm: add missing rcu list annotations and operations (Oliver Hartkopp) - can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure (Oliver Hartkopp) - can: isotp: use unconditional synchronize_rcu() in isotp_release() (Oliver Hartkopp) - nvmet-rdma: handle inline data with a nonzero offset (Bryam Vargas) - sctp: validate STALE_COOKIE cause length before reading staleness (Weiming Shi) [Orabug: 39794431] {CVE-2026-64551} - spi: uniphier: Fix completion initialization order before devm_request_irq() (Kunihiko Hayashi) - time: Fix off-by-one in compat settimeofday() usec validation (Wang Yan) - tpm: Make the TPM character devices non-seekable (Jaewon Yang) - tpm: fix event_size output in tpm1_binary_bios_measurements_show (Thorsten Blum) - xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) - xfrm: use compat translator only for u64 alignment mismatch (Sanman Pradhan) - xen/gntdev: fix error handling in ioctl (Xu Wang) - i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() (Luoxuanqiang) - i2c: mediatek: fix WRRD for SoCs without auto_restart option (Roman Vivchar) - hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (Joshua Crofts) - irqchip/crossbar: Use correct index in crossbar_domain_free() (Bhargav Joshi) - mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (Florian Fuchs) - ocfs2: reject non-inline dinodes with i_size and zero i_clusters (Michael Bommarito) - ocfs2: reject dinodes whose i_rdev disagrees with the file type (Michael Bommarito) - ocfs2: reject dinodes with non-canonical i_mode type (Michael Bommarito) - ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits (Ian Bridges) - ocfs2: avoid moving extents to occupied clusters (Kyle Zeng) - mtd: rawnand: fix condition in 'nand_select_target()' (Arseniy Krasnov) - net/9p: fix infinite loop in p9_client_rpc on fatal signal (Vasiliy Kovalev) - mtd: rawnand: pl353: fix probe resource allocation (Bastien Curutchet) - ocfs2: use kzalloc for quota recovery bitmap allocation (Tristan Madani) - scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished() (Martin Wilck) - mtd: slram: remove failed entries from the device list (Ruoyu Wang) - proc: only bump parent nlink when registering directories (Krzysztof Wilczynski) - mips: sched: Fix CPUMASK_OFFSTACK memory corruption (Aaron Tomlin) - power: supply: charger-manager: fix refcount leak in is_full_charged() (Xu Wang) - ntfs3: fix out-of-bounds read in decompress_lznt (Tristan Madani) - ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head (Michael Bommarito) - ntfs3: cap RESTART_TABLE free-chain walker at rt-used (Michael Bommarito) - fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} (Michael Bommarito) - fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow (Michael Bommarito) - fs/ntfs3: validate lcns_follow in log_replay conversion (Konstantin Komarov) - fs/ntfs3: bound attr_off in UpdateResidentValue against data_off (Konstantin Komarov) - fs/ntfs3: bound DeleteIndexEntryAllocation memmove length (Konstantin Komarov) - fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename (Zhan Xusheng) - MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf() (Maciej W. Rozycki) - MIPS: ip22-gio: fix device reference leak in probe (Johan Hovold) - MIPS: ip22-gio: fix kfree() of static object (Johan Hovold) - MIPS: ip22-gio: fix gio device memory leak (Johan Hovold) - lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure (Chuck Lever) - lockd: Plug nlm_file leak when nlm_do_fopen() fails (Chuck Lever) - nvdimm/btt: Free arena sub-allocations on discover_arenas() error path (Abdun Nihaal) - nvdimm/btt: Free arenas on btt_init() error paths (Abdun Nihaal) - jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() (Junrui Luo) - Bluetooth: SCO: hold sk properly in sco_conn_ready (Pauli Virtanen) - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (Pauli Virtanen) - mfd: tps6586x: Fix OF node refcount (Bartosz Golaszewski) - batman-adv: tt: prevent TVLV OOB check overflow (Sven Eckelmann) - batman-adv: frag: fix primary_if leak on failed linearization (Sven Eckelmann) - batman-adv: frag: free unfragmentable packet (Sven Eckelmann) - batman-adv: fix VLAN priority offset (Sven Eckelmann) - batman-adv: tt: avoid request storms during pending request (Sven Eckelmann) - batman-adv: dat: fix tie-break for candidate selection (Sven Eckelmann) - batman-adv: dat: ensure accessible eth_hdr proto field (Sven Eckelmann) - batman-adv: bla: reacquire gw address after skb realloc (Sven Eckelmann) - batman-adv: dat: acquire ARP hw source only after skb realloc (Sven Eckelmann) - batman-adv: access unicast_ttvn skb-data only after skb realloc (Sven Eckelmann) - batman-adv: gw: acquire ethernet header only after skb realloc (Sven Eckelmann) - x86/boot: Reject too long acpi_rsdp= values (Thorsten Blum) - x86/boot: Validate console=uart8250 baud rate to fix early boot hang (Thorsten Blum) - mfd: sm501: Fix reference leak on failed device registration (Guangshuo Li) - leds: uleds: Fix potential buffer overread (Armin Wolf) - soc: fsl: qe: panic on ioremap() failure in qe_reset() (Wang Jun) - soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (Siddharth Vadapalli) - gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path (Guangshuo Li) - netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (Xiang Mei) [Orabug: 39794442] {CVE-2026-64554} - netfilter: xt_nat: reject unsupported target families (Wyatt Feng) - netfilter: nf_conncount: fix zone comparison in tuple dedup (Yizhou Zhao) - netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag (Xiang Mei) - netfilter: nf_nat_sip: reload possible stale data pointer (Florian Westphal) - netfilter: xt_cluster: reject template conntracks in hash match (Wyatt Feng) - netfilter: nfnl_cthelper: apply per-class values when updating policies (David Carlier) - netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read (Muhammad Bilal) - fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (Abdun Nihaal) - fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (Abdun Nihaal) - fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() (Abdun Nihaal) - fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (Abdun Nihaal) - fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (Abdun Nihaal) - fbdev: s3fb: fix potential memory leak in s3_pci_probe() (Abdun Nihaal) - fbdev: i740fb: fix potential memory leak in i740fb_probe() (Abdun Nihaal) - fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (Abdun Nihaal) - fbdev: sm712: Fix operator precedence in big_swap macro (Li Rongqing) - fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (Abdun Nihaal) - fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (Abdun Nihaal) - fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (Abdun Nihaal) - KVM: arm64: vgic: Check the interrupt is still ours before migrating it (Hyunwoo Kim) - arm64: dts: qcom: sdm630: describe adsp_mem region properly (Nickolay Goppen) - net: ife: require ETH_HLEN to be pullable in ife_decode() (Yong Wang) - net: atm: reject out-of-range traffic classes in QoS validation (Zhengchuan Liang) - net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() (Michael Bommarito) - vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter (Zhang Tianci) - mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (Xu Wang) - smb: client: fix overflow in passthrough ioctl bounds check (Guangshuo Li) - net/mlx5: Fix L3 tunnel entropy refcount leak (Li Rongqing) - regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (Timur Tabi) - regulator: core: Make regulator_lock_two() logic easier to follow (Douglas Anderson) - dm era: fix NULL pointer dereference in metadata_open() (Cao Guanghui) - ipvs: ensure inner headers in ICMP errors are in headroom (Julian Anastasov) - ipvs: fix PMTU for GUE/GRE tunnel ICMP errors (Yizhou Zhao) - ipvs: use parsed transport offset in TCP state lookup (Yizhou Zhao) - ipvs: pass parsed transport offset to state handlers (Yizhou Zhao) - ipv6: mcast: Fix potential UAF in MLD delayed work (Eric Dumazet) - ipv6: mcast: Replace locking comments with lockdep annotations. (Kuniyuki Iwashima) - octeontx2-pf: check DMAC extraction support before filtering (Suman Ghosh) - net/sched: cake: reject overhead values that underflow length (Samuel Moelius) - net: usb: lan78xx: disable VLAN filter in promiscuous mode (Enrico Pozzobon) - ring-buffer: Fix event length with forced 8-byte alignment (Hui Wang) - Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (Weiming Shi) [Orabug: 39794421] {CVE-2026-64549} - Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (Pauli Virtanen) - net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (Xiang Mei) - net: qualcomm: rmnet: validate MAP frame length before ingress parsing (Xiang Mei) - net: qualcomm: rmnet: add tx packets aggregation (Daniele Palmas) - qede: fix off-by-one in BD ring consumption on build_skb failure (Shigeru Yoshida) - netfilter: xt_connmark: reject invalid shift parameters (Wyatt Feng) - netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop (Zhixing Chen) - netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt() (Feng Wu) - netfilter: xt_u32: reject invalid shift counts (Wyatt Feng) - gue: validate REMCSUM private option length (Qihang) - net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (Xiang Mei) [Orabug: 39794412] {CVE-2026-64547} - arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range() (Anshuman Khandual) - HID: core: Fix OOB read in hid_get_report for numbered reports (Lee Jones) - HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (Georgiy Osokin) - ata: sata_gemini: unwind clocks on IDE pinctrl errors (Myeonghun Pak) - afs: Fix unchecked-length string display in debug statement (David Howells) - afs: Fix the volume AFS_VOLUME_RM_TREE is set on (David Howells) - afs: Fix vllist leak (David Howells) - afs: Fix callback service message parsers to pass through -EAGAIN (David Howells) - afs: Fix error code in afs_extract_vl_addrs() (Dan Carpenter) - net/sched: hhf: clear heavy-hitter state on reset (Samuel Moelius) - gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (Vladimir Zapolskiy) - net/sched: act_bpf: use rcu_dereference_bh() to read the filter (Sechang Lim) - cxgb4: Fix decode strings dump for T6 adapters (Gleb Markov) - virtio_net: disable cb when NAPI is busy-polled (Longjun Tang) - irqchip/gic-v3-its: Fix OF node reference leak (Yuho Choi) - tracing: eprobe: read the complete FILTER_PTR_STRING pointer (Martin Kaiser) - tracing/events: Fix to check the simple_tsk_fn creation (Masami Hiramatsu) - bridge: stp: Fix a potential use-after-free when deleting a bridge (Ido Schimmel) - net: gianfar: dispose irq mappings on probe failure and device removal (Rosen Penev) - usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (Xiang Mei) [Orabug: 39794387] {CVE-2026-64540} - ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump (Pengfei Zhang) - ipv6: remove RTNL protection from inet6_dump_fib() (Eric Dumazet) - inet: allow ip_valid_fib_dump_req() to be called with RTNL or RCU (Eric Dumazet) - rtnetlink: add RTNL_FLAG_DUMP_UNLOCKED flag (Eric Dumazet) - rtnetlink: change nlk-cb_mutex role (Eric Dumazet) - hwmon: adm1275: Prevent reading uninitialized stack (Matti Vaittinen) - qede: fix out-of-bounds check for cqe-len_list[] (Matvey Kovalev) - seg6: validate SRH length before reading fixed fields (Nuoqi Gui) - gpio: htc-egpio: use managed gpiochip registration (Pengpeng Hou) - gpio: mvebu: fail probe if gpiochip registration fails (Pengpeng Hou) - spi: sh-msiof: abort transfers when reset times out (Pengpeng Hou) - tracing: probes: fix typo in a log message (Martin Kaiser) - net: sungem: fix probe error cleanup (Ruoyu Wang) - net: mvneta: re-enable percpu interrupt on resume (Yun Zhou) - rtc: cmos: unregister HPET IRQ handler on probe failure (Haoxiang Li) - rtc: ds1307: Fix off-by-one issue with wday for rx8130 (Fredrik M Olsson) - smb/client: preserve errors from smb2_set_sparse() (Huiwen He) - ipv6: fix error handling in disable_policy sysctl (Fernando Fernandez Mancera) - ipv6: fix error handling in forwarding sysctl (Fernando Fernandez Mancera) - ipv6: fix error handling in ignore_routes_with_linkdown sysctl (Fernando Fernandez Mancera) - ipv6: fix error handling in disable_ipv6 sysctl (Fernando Fernandez Mancera) - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (Jamal Hadi Salim) [Orabug: 39787017] {CVE-2026-64530} - veth: fix NAPI leak in XDP enable error path (Eric Dumazet) - net: dsa: sja1105: round up PTP perout pin duration (Aleksandrova Alyona) - net, bpf: check master for NULL in xdp_master_redirect() (Xiang Mei) [Orabug: 39794405] {CVE-2026-64545} - alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs (Krzysztof Wilczynski) - alpha/PCI: Add security_locked_down() check to pci_mmap_resource() (Krzysztof Wilczynski) - NTB: epf: Make db_valid_mask cover only real doorbell bits (Koichiro Den) - netfilter: nft_synproxy: stop bypassing the priv-info snapshot (Runyu Xiao) - netfilter: nf_conncount: prevent connlimit drops for early confirmed ct (Fernando Fernandez Mancera) - ipv4: fib: Don't ignore error route in local/main tables. (Kuniyuki Iwashima) - ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). (Xiang Mei) [Orabug: 39794379] {CVE-2026-64538} - ksmbd: fix use-after-free of conn-preauth_info in concurrent SMB2 NEGOTIATE (Gil Portnoy) - PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0 (Manivannan Sadhasivam) - PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0 (Manivannan Sadhasivam) - drm/edid: fix OOB read in drm_parse_tiled_block() (Xiang Mei) [Orabug: 39794408] {CVE-2026-64546} - bpf: zero-initialize the fib lookup flow struct (Avinash Duduskar) - bpf: Fix stack slot index in nospec checks (Nuoqi Gui) - rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (Ronan Dalton) - rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (Antoni Pokusinski) - selftests/mm: fix exclusive_cow test fork() handling (Aboorva Devarajan) - selftests/mm: allow PUD-level entries in compound testcase of hmm tests (Sayali Patil) - selftests/mm: clarify alternate unmapping in compaction_test (Sayali Patil) - irqchip/crossbar: Fix parent domain resource leak (Bhargav Joshi) - netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak (Florian Westphal) - netfilter: nf_reject: skip iphdr options when looking for icmp header (Florian Westphal) - netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() (Jozsef Kadlecsik) - ieee802154: fix kernel-infoleak in dgram_recvmsg() (Aleksandr Nogikh) - ieee802154: Remove WARN_ON() in cfg802154_pernet_exit() (Ivan Abramov) - ACPI: resource: Amend kernel-doc style (Andy Shevchenko) - thermal: intel: Fix dangling resources on thermal_throttle_online() failure (Ricardo Neri) - arm64/hw_breakpoint: reject unaligned watchpoints that would truncate BAS (Breno Leitao) - dpaa2-switch: fix VLAN upper check not rejecting bridge join (Ioana Ciornei) - sctp: hold socket lock when dumping endpoints in sctp_diag (Xin Long) - net: psample: fix info leak in PSAMPLE_ATTR_DATA (Jakub Kicinski) [Orabug: 39794438] {CVE-2026-64553} - octeontx2-pf: Fix leak of SQ timestamp buffer on teardown (Ratheesh Kannoth) - xfrm: validate selector family and prefixlen during match (Eric Dumazet) - sparc: led: avoid trimming a newline from empty writes (Pengpeng Hou) - apparmor: fix label can not be immediately before a declaration (John Johansen) - i3c: master: Prevent reuse of dynamic address on device add failure (Adrian Hunter) - apparmor: put secmark label after secid lookup (Zygmunt Krynicki) - apparmor: aa_getprocattr free procattr leak on format failure (Zygmunt Krynicki) - apparmor: fix potential UAF in aa_replace_profiles (Maxime Belair) - apparmor: grab ns lock and refresh when looking up changehat child profiles (Ryan Lee) - apparmor: aa_label_alloc use aa_label_free on alloc failure (Zygmunt Krynicki) - apparmor: check label build before no_new_privs test (Ruoyu Wang) - PCI: mediatek: Use actual physical address instead of virt_to_phys() (Manivannan Sadhasivam) - PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port() (Ryder Lee) - tools lib api: Fix mount_overload() snprintf truncation and toupper range (Arnaldo Carvalho de Melo) - tools lib api: Fix filename__write_int() writing uninitialized stack data (Arnaldo Carvalho de Melo) - tools lib api: Fix missing null termination in filename__read_int/ull() (Arnaldo Carvalho de Melo) - xprtrdma: Fix bcall rep leak and unbounded peek (Chris Mason) - PCI: rcar-host: Remove unused LIST_HEAD(res) (Lad Prabhakar) - PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro (Li Rongqing) - NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write (Mike Snitzer) - NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors (Mike Snitzer) - NFSv4/pnfs: defer return_range callbacks until after inode unlock (Dai Ngo) - pNFS/filelayout: fix cheking if a layout is striped (Sagi Grimberg) - clk: qcom: a53: Corrected frequency multiplier for 1152MHz (Phillip Varney) - dmaengine: Fix possible use after free (Nuno Sa) - dmaengine: qcom: gpi: set DMA_PRIVATE capability (Icenowy Zheng) - drm/amd/display: Add missing kdoc for ALLM parameters (Srinivasan Shanmugam) - HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (Rosen Penev) - iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (Sanjay Chitroda) - iio: magnetometer: ak8975: fix potential kernel stack memory leak (Joshua Crofts) - iio: light: si1133: prevent race condition on timeout (Joshua Crofts) - iio: light: si1133: reset counter to prevent race condition (Joshua Crofts) - char: tlclk: fix use-after-free in tlclk_cleanup() (James Kim) - usb: host: max3421: Reject hub port requests for non-existent ports (Seungjin Bae) - usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (Seungjin Bae) - staging: most: video: avoid double free on video register failure (Guangshuo Li) - phy: phy-can-transceiver: Check driver match and driver data against NULL (Andy Shevchenko) - platform/x86: xo15-ebook: Fix wakeup source and GPE handling (Rafael J. Wysocki) - x86/platform/olpc: xo15: Drop wakeup source on driver removal (Rafael J. Wysocki) - coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore (Leo Yan) - coresight: cti: Fix DT filter signals silently ignored (Yingchao Deng) - staging: nvec: fix use-after-free in nvec_rx_completed() (Alexandru Hossu) - net/9p: fix race condition on rdma-state in trans_rdma.c (Yizhou Zhao) - ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write (Aleksandr Nogikh) - ksmbd: fix use-after-free in same_client_has_lease() (Guangshuo Li) - tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (Eric Dumazet) - tipc: fix UAF in tipc_l2_send_msg() (Eric Dumazet) - KEYS: Use acquire when reading state in keyring search (Gui-Dong Han) - powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus (Aboorva Devarajan) - powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down (Aboorva Devarajan) - powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del (Aboorva Devarajan) - MIPS: mm: Fix out-of-bounds write in maar_res_walk() (Yadan Fan) - bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check (Sechang Lim) - bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (Weiming Shi) [Orabug: 39794417] {CVE-2026-64548} - smb/client: always return a value for FS_IOC_GETFLAGS (Huiwen He) - netfilter: nf_conncount: callers must hold rcu read lock (Florian Westphal) - kcm: use WRITE_ONCE() when changing lower socket callbacks (Runyu Xiao) - bpf: Run generic devmap egress prog on private skb (Sun Jian) - net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (Aditya Garg) - net: mana: initialize gdma queue id to INVALID_QUEUE_ID (Aditya Garg) - net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen (Victor Nogueira) - net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen (Victor Nogueira) - ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (Guangshuo Li) - spi: xilinx: use FIFO occupancy register to determine buffer size (Lars Poschel) - crypto: rng - Free default RNG on module exit (Herbert Xu) - crypto: cavium/cpt - fix DMA cleanup using wrong loop index (Felix Gu) - crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (Felix Gu) - tipc: reject inverted service ranges from peer bindings (Michael Bommarito) - tipc: prevent snt_unacked underflow on CONN_ACK (Michael Bommarito) - tipc: require net admin for TIPCv2 netlink mutators (Michael Bommarito) - net/sched: sch_hfsc: Don't make class passive twice (Victor Nogueira) - sctp: validate embedded address parameter length (Xin Long) - bridge: cfm: reject invalid CCM interval at configuration time (Xiang Mei) - net: fib_rules: Don't dump dying fib_rule in fib_rules_dump(). (Kuniyuki Iwashima) - ASoC: tegra: tegra210_ahub: Validate written enum value (Hyeongjun An) - ASoC: fsl: fsl_audmix: Validate written enum values (Hyeongjun An) - ASoC: codecs: hdac_hdmi: Validate written enum value (Hyeongjun An) - RDMA/mlx5: Fix undefined shift of user RQ WQE size (Maher Sanalla) - RDMA/mlx5: Remove raw RSS QP restrack tracking (Patrisious Haddad) - fs: efs: remove unneeded debug prints (Maxwell Doose) - s390/process: Fix kernel thread function pointer type (Heiko Carstens) - bpf: Tighten cgroup storage cookie checks for prog arrays (Daniel Borkmann) - selftests/bpf: Fix bpf_iter/task_vma test (Yonghong Song) - bonding: 3ad: fix mux port state on oper down (Louis Scalbert) - tools/virtio: check mmap return value in vringh_test (Longlong Yan) - vduse: Requeue failed read to send_list head (Zhang Tianci) - vhost/vdpa: validate virtqueue index in mmap and fault paths (Qihang) - vduse: hold vduse_lock across IDR lookup in open path (Qihang) - IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified (Jason Gunthorpe) - fbdev: sm501fb: Fix buffer errors in OF binding code (David Laight) - btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (Filipe Manana) - hwspinlock: qcom: avoid uninitialized struct members (Wolfram Sang) - vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() (Hui Zhu) - pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (Luca Leonardo Scorcia) - pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (Luca Leonardo Scorcia) - watchdog: unregister PM notifier on watchdog unregister (Yuho Choi) - configfs: fix lockless traversals of -s_children (Al Viro) - firmware_loader: Fix recursive lock in device_cache_fw_images() (Dmitry Vyukov) - spi: ep93xx: fix double-free of zeropage on DMA setup failure (Felix Gu) - IB/mlx5: Properly support implicit ODP rereg_mr (Jason Gunthorpe) - IB/mlx5: Don't take the rereg_mr fallback without a new translation (Jason Gunthorpe) - cpufreq: Documentation: fix conservative governor freq_step description (Pengjie Zhang) - ACPI: IPMI: Fix message kref handling on dead device (Yuho Choi) - ALSA: seq: Clear variable event pointer on read (Kyle Zeng) - ALSA: seq: Add UMP support (Takashi Iwai) - ALSA: seq: Introduce SNDRV_SEQ_IOCTL_USER_PVERSION ioctl (Takashi Iwai) - riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe (Rui Qi) - wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (Tristan Madani) - bpf: Update transport_header when encapsulating UDP tunnel in lwt (Leon Hwang) - RDMA/irdma: Fix OOB read during CQ MR registration (Jacob Moroni) - IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path() (Jason Gunthorpe) - netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp (Pablo Neira Ayuso) - netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock (Fernando Fernandez Mancera) - netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures (Fernando Fernandez Mancera) - ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release() (Joseph Qi) - ocfs2/dlm: require a ref for locking_state debugfs open (Zhang Cen) - ocfs2: reject FITRIM ranges shorter than a cluster (Zhang Cen) - ocfs2: fix buffer head management in ocfs2_read_blocks() (Dmitry Antipov) - ocfs2: rebase copied fsdlm LVB pointers in locking_state (Zhang Cen) - bpftool: Use libbpf error code for flow dissector query (Woojin Ji) - configfs_lookup(): don't leave -s_dentry dangling on failure (Al Viro) - lib/test_meminit: use for bools (Alexander Potapenko) - mm/fake-numa: fix under-allocation detection in uniform split (Sang-Heon Jeon) - bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs (Deepanshu Kartikey) - scsi: pm8001: Fix error code in non_fatal_log_show() (Dan Carpenter) - scsi: Revert 'scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans' (Martin Wilck) - ARM: imx31: Fix IIM mapping leak in revision check (Yuho Choi) - ARM: imx3: Fix CCM node reference leak (Yuho Choi) - ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback (Zhang Yi) - md/raid10: reset read_slot when reusing r10bio for discard (Chen Cheng) - media: qcom: venus: relax encoder frame/blur step size on v6 (Renjiang Han) - media: qcom: venus: relax encoder frame/blur dimension steps on v4 (Renjiang Han) - media: qcom: venus: drop extra padding in NV12 raw size calculation (Renjiang Han) - EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info (Zhoumin) - drm/msm/dp: Fix the ISR_* enum values (Jessica Zhang) - drm/msm/dp: fix HPD state status bit shift value (Jessica Zhang) - crypto: hisilicon/qm - disable error report before flr (Weili Qian) - ocfs2: kill osb-system_file_mutex lock (Tetsuo Handa) - ocfs2: don't BUG_ON an invalid journal dinode (Zhengyuan Huang) - rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() (Dan Carpenter) - dax/kmem: account for partial discontiguous resource upon removal (Davidlohr Bueso) - libbpf: Fix UAF in strset__add_str() (Carlos Llamas) - drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (Timur Tabi) - drm/tegra: Fix iommu_map_sgtable() return value check (Mikko Perttunen) - drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (Felix Gu) - net/sched: cls_bpf: prevent unbounded recursion in offload rollback (Jiayuan Chen) - ipv6: guard against possible NULL deref in __in6_dev_stats_get() (Eric Dumazet) - workqueue: drop spurious '*' from print_worker_info() fn declaration (Breno Leitao) - nvme-multipath: fix flex array size in struct nvme_ns_head (Nilay Shroff) - mtd: spi-nor: Drop duplicate Kconfig dependency (Miquel Raynal) - mips: n64: add __iomem for writel call (Rosen Penev) - mips: ralink: mt7621: add missing __iomem (Rosen Penev) - MIPS: DEC: Remove do_IRQ() call indirection (Maciej W. Rozycki) - MIPS: Fix big-endian stack argument fetching in o32 wrapper (Maciej W. Rozycki) - PM: sleep: Use complete() in device_pm_sleep_init() (Jiakai Xu) - RDMA/hns: Fix warning in poll cq direct mode (Wenglianfa) - IB/mlx4: Fix refcount leak in add_port() error path (Guangshuo Li) - RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (Jacob Moroni) - bus: sunxi-rsb: Always check register address validity (Samuel Holland) - pwm: imx27: Fix variable truncation in .apply() (Ronaldo Nunez) - cpufreq: conservative: Simplify frequency limit handling (Lifeng Zheng) - cpufreq: Documentation: fix sampling_down_factor range (Pengjie Zhang) - device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id() (Stepan Ionichev) - firmware: arm_scmi: Fix OOB in scmi_power_name_get() (Geert Uytterhoeven) - media: rockchip: rga: fix too small buffer size (Sven Puschel) - net/sched: sch_drr: annotate data-races around cl-deficit (Eric Dumazet) - sysfs: clamp show() return value in sysfs_kf_read() (Greg Kroah-Hartman) - firmware: arm_scmi: Read sensor config as 32-bit value (Sudeep Holla) - media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() (Zilin Guan) - RDMA/srpt: fix integer overflow in immediate data length check (Sara Venkatesh) - RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (Prathamesh Deshpande) - RDMA/hns: Fix arithmetic overflow in calc_hem_config() (Alexander Chesnokov) - ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD (Linmao Li) - net/sched: sch_htb: annotate data-races (I) (Eric Dumazet) - net/sched: sch_htb: do not change sch-flags in htb_dump() (Eric Dumazet) - crypto: ccp - Treat zero-length cert chain as query for blob lengths (Sean Christopherson) - net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats() (Eric Dumazet) - thermal: hwmon: Fix critical temperature attribute removal (Rafael J. Wysocki) - evm: terminate and bound the evm_xattrs read buffer (Pengpeng Hou) - drm/hisilicon/hibmc: use clock to look up the PLL value (Lin He) - drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (Lin He) - clk: scmi: Fix clock rate rounding (Cristian Marussi) - iommu/amd: Fix a stale comment about which legacy mode is user visible (Sean Christopherson) - crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (Weiming Shi) [Orabug: 39794401] {CVE-2026-64544} - crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (Thorsten Blum) - crypto: atmel-sha204a - fix blocking and non-blocking rng logic (Lothar Rubusch) - pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path (Felix Gu) - media: cedrus: Fix failure to clean up hardware on probe failure (Samuel Holland) - watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (Felix Gu) - watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (Gao Yingjie) - ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint (Jihed Chaibi) - wifi: ath9k: fix OOB access from firmware tx status queue ID (Tristan Madani) - kconfig: fix potential NULL pointer dereference in conf_askvalue (Xingjing Deng) - wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (Tristan Madani) - driver core: use READ_ONCE() for dev-driver in dev_has_sync_state() (Danilo Krummrich) - drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (Yuho Choi) - drm/tidss: Drop extra drm_mode_config_reset() call (Tomi Valkeinen) - fbcon: fix NULL pointer dereference for a console without vc_data (Ian Bridges) - afs: Fix further netns teardown to cancel the preallocation charger (David Howells) - afs: fix NULL pointer dereference in afs_get_tree() (Matvey Kovalev) - afs: Fix netns teardown to cancel the preallocation charger (David Howells) - serial: 8250_omap: clear rx_running on zero-length DMA completes (Matthias Feser) - serial: msm: Disable DMA for kernel console UART (Stephan Gerhold) - dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties (Chen-Yu Tsai) - media: uvcvideo: Fix buffer sequence in frame gaps (Ricardo Ribalda) - media: uvcvideo: Avoid partial metadata buffers (Ricardo Ribalda) - crypto: hisi-trng - Remove crypto_rng interface (Eric Biggers) - crypto: crypto4xx - Remove insecure and unused rng_alg (Eric Biggers) - crypto: crypto4xx - Remove ahash-related code (Herbert Xu) - crypto: sun4i-ss - Remove insecure and unused rng_alg (Eric Biggers) - crypto: af_alg - Remove zero-copy support from skcipher and aead (Eric Biggers) - net: dsa: tag_ksz: do not rely on skb_mac_header() in TX paths (Vladimir Oltean) - tools/mm/slabinfo: fix total_objects attribute name (Chenyichong) - crypto: algif_skcipher - force synchronous processing on trees without ctx-state (Muhammet Kaan Kilinc) - sched/fair: Only update stats for allowed CPUs when looking for dst group (Adam Li) - xfs: fail recovery on a committed log item with no regions (Weiming Shi) [Orabug: 39760871] {CVE-2026-64187} - fuse: re-lock request before returning from fuse_ref_folio() (Joanne Koong) [Orabug: 39785786] {CVE-2026-64266} - fuse: fix device node leak in cuse_process_init_reply() (Alberto Ruiz) - RDMA/siw: bound Read Response placement to the RREAD length (Michael Bommarito) - RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg (Zhenhao Wan) - Input: maplecontrol - set driver data before registering input device (Dmitry Torokhov) - Input: maplemouse - set driver data before registering input device (Dmitry Torokhov) - Input: maple_keyb - set driver data before registering input device (Dmitry Torokhov) - Input: mms114 - fix multi-touch slot corruption (Dmitry Torokhov) - Input: maplemouse - fix NULL pointer dereference in open() (Florian Fuchs) - Input: touchwin - reset the packet index on every complete packet (Bryam Vargas) [Orabug: 39785802] {CVE-2026-64271} - Input: iforce - bound the device-reported force-feedback effect index (Bryam Vargas) - Input: goodix - clamp the device-reported contact count (Bryam Vargas) - Input: elan_i2c - prevent division by zero and arithmetic underflow (Ranjan Kumar) [Orabug: 39785819] {CVE-2026-64275} - Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (Bryam Vargas) [Orabug: 39785823] {CVE-2026-64276} - Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (Bryam Vargas) - Input: synaptics-rmi4 - unregister function handlers on physical driver registration failure (Haoxiang Li) - i2c: stm32f7: truncate clock period instead of rounding it (Guillermo Rodriguez) - i2c: core: fix adapter deregistration race (Johan Hovold) [Orabug: 39785831] {CVE-2026-64279} - udmabuf: fix DMA direction mismatch in release_udmabuf() (Mikhail Gavrilov) - KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (Sean Christopherson) [Orabug: 39843616] {CVE-2026-64604} - NTB: epf: Fix request_irq() unwind in ntb_epf_init_isr() (Koichiro Den) - exfat: bound uniname advance in exfat_find_dir_entry() (Bryam Vargas) [Orabug: 39785863] {CVE-2026-64296} - NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (Benjamin Coddington) [Orabug: 39785868] {CVE-2026-64298} - tracing: Prevent out-of-bounds read in glob matching (Huihui Huang) [Orabug: 39785872] {CVE-2026-64299} - spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (Carlos Song) - spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (Carlos Song) - crypto: talitos - use dma_sync_single_for_cpu() before reading descriptor header (Paul Louvel) - crypto: drbg - Fix the fips_enabled priority boost (Eric Biggers) - crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (Eric Biggers) - crypto: drbg - Fix returning success on failure in CTR_DRBG (Eric Biggers) [Orabug: 39785893] {CVE-2026-64306} - crypto: pcrypt - restore callback for non-parallel fallback (Ruijie Li) [Orabug: 39785906] {CVE-2026-64312} - crypto: ecc - Fix carry overflow in vli multiplication (Anastasia Tishchenko) [Orabug: 39785910] {CVE-2026-64313} - crypto: caam - use print_hex_dump_devel to guard key hex dumps again (Thorsten Blum) - crypto: caam - use print_hex_dump_devel to guard key hex dumps (Thorsten Blum) - isofs: bound Rock Ridge symlink components to the SL record (Bryam Vargas) [Orabug: 39785923] {CVE-2026-64317} - partitions: aix: bound the pp_count scan to the ppe array (Bryam Vargas) - nvme-multipath: set BIO_REMAPPED on bios remapped to per-path namespace disks (Igor Achkinazi) - dm-ioctl: report an error if a device has no table (Mikulas Patocka) - udf: validate sparing table length as an entry count, not a byte count (Bryam Vargas) [Orabug: 39785940] {CVE-2026-64322} - udf: validate VAT header length against the VAT inode size (Bryam Vargas) [Orabug: 39785944] {CVE-2026-64323} - udf: validate free block extents against the partition length (Michael Bommarito) [Orabug: 39785948] {CVE-2026-64324} - iio: temperature: ltc2983: Fix n_wires default bypassing rotation check (Liviu Stan) - usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (Madhu M) - usb: typec: ucsi: Invert DisplayPort role assignment (Andrei Kuchynski) - usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (Badhri Jagan Sridharan) [Orabug: 39785963] {CVE-2026-64330} - usbip: vudc: fix NULL deref in vep_dequeue() (Sam Day) [Orabug: 39785967] {CVE-2026-64331} - usbip: tools: support SuperSpeedPlus devices (Chenyichong) - USB: usb-storage: ene_ub6250: restore media-ready check (Xu Rao) - USB: ulpi: fix memory leak on registration failure (Johan Hovold) [Orabug: 39785971] {CVE-2026-64332} - USB: serial: digi_acceleport: fix write buffer corruption (Johan Hovold) [Orabug: 39785975] {CVE-2026-64333} - USB: serial: digi_acceleport: fix hard lockup on disconnect (Johan Hovold) [Orabug: 39785979] {CVE-2026-64334} - USB: serial: digi_acceleport: fix broken rx after throttle (Johan Hovold) [Orabug: 39785983] {CVE-2026-64335} - USB: serial: option: add Telit Cinterion FE990D50 compositions (Fabio Porcedda) - USB: serial: keyspan_pda: fix information leak (Johan Hovold) [Orabug: 39785987] {CVE-2026-64336} - usb: mtu3: unmap request DMA on queue failure (Haoxiang Li) - USB: misc: uss720: unregister parport on probe failure (Myeonghun Pak) [Orabug: 39785994] {CVE-2026-64338} - USB: storage: include US_FL_NO_SAME in quirks mask (Xu Rao) - usb: sl811-hcd: disable controller wakeup on remove (Myeonghun Pak) - USB: legousbtower: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39785999] {CVE-2026-64340} - USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD (Erich E. Hoover) - USB: iowarrior: fix use-after-free on disconnect (Johan Hovold) [Orabug: 39786007] {CVE-2026-64342} - USB: ldusb: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39786012] {CVE-2026-64343} - USB: idmouse: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39786017] {CVE-2026-64344} - usb: gadget: udc: Fix use-after-free in gadget_match_driver (Jimmy Hu) [Orabug: 39786026] {CVE-2026-64346} - usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (Maoyi Xie) [Orabug: 39786030] {CVE-2026-64347} - usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (Xu Wang) - USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub (Rodrigo Lugathe Da Conceicao Alves) - usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (Haoxiang Li) - usb: cdc_acm: Add quirk for Uniden BC125AT scanner (Jared Baldridge) - net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() (Maoyi Xie) [Orabug: 39786042] {CVE-2026-64351} - xfs: fix unreachable BIGTIME check in dquot flush validation (Alexey Nepomnyashih) - nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers (Deepanshu Kartikey) - hfs/hfsplus: zero-initialize buffer in hfs_bnode_read (Tristan Madani) - HID: sensor-hub: Add sensor_hub_input_attr_read_values() for multi-byte reads (Srinivas Pandruvada) - HID: lg-g15: cancel pending work on remove to fix a use-after-free (Maoyi Xie) [Orabug: 39786071] {CVE-2026-64362} - HID: wacom: stop hardware after post-start probe failures (Myeonghun Pak) [Orabug: 39859299] {CVE-2026-68091} - posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path (Xu Wang) [Orabug: 39786091] {CVE-2026-64370} - cpufreq: pcc: fix use-after-free and double free in _OSC evaluation (Yuho Choi) [Orabug: 39786100] {CVE-2026-64372} - cpufreq: Fix hotplug-suspend race during reboot (Tianxiang Chen) [Orabug: 39786104] {CVE-2026-64373} - sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT (Steven Rostedt) [Orabug: 39786108] {CVE-2026-64374} - cpufreq: intel_pstate: Sync policy-cur during CPU offline (Wangfushuai) - net: Drop the lock in skb_may_tx_timestamp() (Sebastian Andrzej Siewior) [Orabug: 39331701] {CVE-2026-43216} - Bluetooth: L2CAP: validate option length before reading conf opt value (Muhammad Bilal) [Orabug: 39786205] {CVE-2026-64403} - Bluetooth: fix UAF in bt_accept_dequeue() (Yousef Alhouseen) [Orabug: 39786578] {CVE-2026-64406} - Bluetooth: bnep: pin L2CAP connection during netdev registration (Yousef Alhouseen) [Orabug: 39786217] {CVE-2026-64408} - netfilter: ebtables: terminate table name before find_table_lock() (Xiang Mei) [Orabug: 39786224] {CVE-2026-64411} - netfilter: ebtables: module names must be null-terminated (Florian Westphal) [Orabug: 39786228] {CVE-2026-64412} - mfd: cros_ec: Delay dev_set_drvdata() until probe success (Andrei Kuchynski) [Orabug: 39786248] {CVE-2026-64420} - net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes (Wyatt Feng) [Orabug: 39786254] {CVE-2026-64422} - ipv4: igmp: remove multicast group from hash table on device destruction (Yuyang Huang) [Orabug: 39786259] {CVE-2026-64423} - io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item (Runyu Xiao) [Orabug: 39786574] {CVE-2026-64425} - gpio: eic-sprd: use raw_spinlock_t in the irq startup path (Runyu Xiao) - NTB: epf: Avoid calling pci_irq_vector() from hardirq context (Koichiro Den) - fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns (Yunpeng Tian) - debugobjects: Plug race against a concurrent OOM disable (Thomas Gleixner) - audit: Fix data races of skb_queue_len() readers on audit_queue (Chi Wang) [Orabug: 39786289] {CVE-2026-64435} - net: af_key: initialize alg_key_len for IPComp states (Zijing Yin) [Orabug: 39786293] {CVE-2026-64436} - crypto: amlogic - avoid double cleanup in meson_crypto_probe() (Dawei Feng) [Orabug: 39843604] {CVE-2026-64599} - staging: rtl8723bs: fix OOB write in HT_caps_handler() (Alexandru Hossu) [Orabug: 39786303] {CVE-2026-64440} - staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (Alexandru Hossu) [Orabug: 39789581] {CVE-2026-64536} - staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (Alexandru Hossu) [Orabug: 39786311] {CVE-2026-64442} - staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (Alexandru Hossu) [Orabug: 39786315] {CVE-2026-64443} - staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (Alexandru Hossu) [Orabug: 39786319] {CVE-2026-64444} - staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (Alexandru Hossu) [Orabug: 39786323] {CVE-2026-64445} - staging: media: atomisp: reduce load_primary_binaries() stack usage (Arnd Bergmann) - media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe (Ricardo Ribalda) - tipc: fix out-of-bounds read in broadcast Gap ACK blocks (Samuel Page) [Orabug: 39786340] {CVE-2026-64450} - 6lowpan: fix NHC entry use-after-free on error path (Yizhou Zhao) [Orabug: 39786344] {CVE-2026-64452} - usb: dwc3: run gadget disconnect from sleepable suspend context (Runyu Xiao) [Orabug: 39786349] {CVE-2026-64454} - USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (Alan Stern) [Orabug: 39786352] {CVE-2026-64455} - hwrng: virtio: clamp device-reported used.len at copy_data() (Michael Bommarito) [Orabug: 39786356] {CVE-2026-64456} - virtio-mmio: fix device release warning on module unload (Johan Hovold) - netfilter: ipset: fix race between dump and ip_set_list resize (Xiang Mei) [Orabug: 39760883] {CVE-2026-64189} - PCI: host-common: Request bus reassignment when not probe-only (Ratheesh Kannoth) - PCI: altera: Do not dispose parent IRQ mapping (Mahesh Vaidya) - usb: xhci: Fix sleep in atomic context in xhci_free_streams() (Lianqin Hu) [Orabug: 39786379] {CVE-2026-64465} - binder: fix UAF in binder_free_transaction() (Carlos Llamas) - binder: fix UAF in binder_thread_release() (Carlos Llamas) - Bluetooth: btusb: fix wakeup source leak on probe failure (Johan Hovold) - Bluetooth: btusb: fix use-after-free on marvell probe failure (Johan Hovold) [Orabug: 39786393] {CVE-2026-64470} - Bluetooth: btusb: fix use-after-free on registration failure (Johan Hovold) [Orabug: 39786397] {CVE-2026-64471} - ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (Cassio Gabriel) - ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (Cassio Gabriel) - ALSA: usb-audio: Roll back quirk control caches on write errors (Cassio Gabriel) - ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (Cassio Gabriel) - ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (Cassio Gabriel) - ALSA: usb-audio: avoid kobject path lookup in DualSense match (Darvell Long) [Orabug: 39786416] {CVE-2026-64478} - ALSA: firewire: isight: bound the sample count to the packet payload (Maoyi Xie) [Orabug: 39786428] {CVE-2026-64483} - ALSA: es1938: check snd_ctl_new1() return value (Zhao Dongdong) [Orabug: 39786432] {CVE-2026-64484} - ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (Maoyi Xie) [Orabug: 39786439] {CVE-2026-64487} - ALSA: virtio: Add missing 384 kHz PCM rate mapping (Cassio Gabriel) - iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (Liviu Stan) - iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (Andy Shevchenko) - iio: light: veml6030: fix channel type when pushing events (Javier Carrasco) - iio: light: tsl2591: return actual error from probe IRQ failure (Stepan Ionichev) - iio: light: opt3001: fix missing state reset on timeout (Joshua Crofts) - iio: light: gp2ap002: fix runtime PM leak on read error (Biren Pandya) - iio: light: al3010: fix incorrect scale for the highest gain range (Vidhu Sarwal) - iio: imu: st_lsm6dsx: deselect shub page before reading whoami (Andreas Kempe) - iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (Runyu Xiao) - iio: gyro: bmg160: wait full startup time after mode change at probe (Stepan Ionichev) - iio: gyro: bmg160: bail out when bandwidth/filter is not in table (Stepan Ionichev) - iio: event: Fix event FIFO reset race (Lars-Peter Clausen) [Orabug: 39786462] {CVE-2026-64496} - iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (Maxwell Doose) - iio: adc: ti-ads124s08: Return reset GPIO lookup errors (Pengpeng Hou) - iio: adc: spear: Initialize completion before requesting IRQ (Maxwell Doose) - iio: adc: lpc32xx: Initialize completion before requesting IRQ (Maxwell Doose) - iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (Biren Pandya) [Orabug: 39786478] {CVE-2026-64503} - iio: accel: bmc150: clamp the device-reported FIFO frame count (Bryam Vargas) [Orabug: 39786482] {CVE-2026-64504} - usb: gadget: function: rndis: add length check for header (Griffin Kroah-Hartman) - usb: gadget: function: rndis: add length check to response query (Griffin Kroah-Hartman) - ksmbd: fix out-of-bounds read in smb_check_perm_dacl() (Hem Parekh) - NFSv4/flexfiles: reject zero filehandle version count (Michael Bommarito) [Orabug: 39753894] {CVE-2026-53392} - fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() (Mingyu Wang) [Orabug: 39753924] {CVE-2026-53402} - i2c: core: fix adapter registration race (Johan Hovold) [Orabug: 39753916] {CVE-2026-53400} - i2c: core: fix adapter debugfs creation (Johan Hovold) - i2c: core: fix NULL-deref on adapter registration failure (Johan Hovold) - i2c: core: fix hang on adapter registration failure (Johan Hovold) - i2c: core: fix irq domain leak on adapter registration failure (Johan Hovold) - block: Avoid mounting the bdev pseudo-filesystem in userspace (Denis Arefev) [Orabug: 39753985] {CVE-2026-63810} - f2fs: fix listxattr handling of corrupted xattr entries (Keshav Verma) - f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs() (Chao Yu) - f2fs: fix potential deadlock in f2fs_balance_fs() (Ruipeng Qi) - f2fs: bound i_inline_xattr_size for non-inline-xattr inodes (Bryam Vargas) - f2fs: validate orphan inode entry count (Wenjie Qi) - device property: initialize the remaining fields of fwnode_handle in fwnode_init() (Bartosz Golaszewski) - f2fs: fix to round down start offset of fallocate for pin file (Sunmin Jeong) - f2fs: adjust zone capacity when considering valid block count (Jaegeuk Kim) - f2fs: validate compress cache inode only when enabled (Wenjie Qi) - f2fs: fix to detect corrupted meta ino (Chao Yu) - apparmor: mediate the implicit connect of TCP fast open sendmsg (Bryam Vargas) - net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) [Orabug: 39754045] {CVE-2026-63829} - apparmor: fix use-after-free in rawdata dedup loop (Ruslan Valiyev) - net: skmsg: preserve sg.copy across SG transforms (Yiming Qian) [Orabug: 39754049] {CVE-2026-63830} - skmsg: convert struct sk_msg_sg::copy to a bitmap (Eric Dumazet) - netfilter: nf_tables: restore set elements when delete set fails (Pablo Neira Ayuso) [Orabug: 36598010] {CVE-2024-27012} - KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (Sean Christopherson) [Orabug: 39753972] {CVE-2026-63806} - nfsd: change nfs4_client_to_reclaim() to allocate data (Neil Brown) - nfsd: move name lookup out of nfsd4_list_rec_dir() (Neilbrown) - slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd (Bjorn Andersson) - slimbus: Convert to platform remove callback returning void (Uwe Kleine-Konig) - slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership (Bjorn Andersson) - slimbus: qcom-ngd-ctrl: Fix probe error path ordering (Bjorn Andersson) - slimbus: qcom-ngd-ctrl: Fix up platform_driver registration (Bjorn Andersson) - dma-buf: remove unused dma-fence-unwrap.c (stable/linux-5.15.y only) (Tudor Ambarus) - net/sched: act_pedit: use NLA_POLICY for parsing 'ex' keys (Pedro Tammela) - clk: imx: Add check for kcalloc (Jiasheng Jiang) - userfaultfd: gate must_wait writability check on pte_present() (Kiryl Shutsemau) [Orabug: 39786515] {CVE-2026-64514} - nfsd: reset write verifier on deferred writeback errors (Jeff Layton) [Orabug: 39753898] {CVE-2026-53393} - nfsd: release layout stid on setlease failure (Chris Mason) [Orabug: 39753912] {CVE-2026-53399} - nfc: llcp: protect nfc_llcp_sock_unlink() calls (Krzysztof Kozlowski) - nvmet-tcp: fix race between ICReq handling and queue teardown (Chaitanya Kulkarni) [Orabug: 39460310] {CVE-2026-46135} [5.15.0-324.211.2] - net: tap: set skb-dev before parsing virtio net header in tap_get_user_xdp() (Dongli Zhang) [Orabug: 39558744] {CVE-2026-74684} - ACPI: resource: Always use MADT override IRQ settings for all legacy non i8042 IRQs (Hans de Goede) [Orabug: 39801953] - net/rds: harden rds_rm_size (Manjunath Patil) [Orabug: 39812533] - net/rds: Add parentheses around conditional operator (Gerd Rausch) [Orabug: 39844638] - net/rds: remove cached rds_sock-rs_conn and rs_conn_path (Sharath Srinivasan) [Orabug: 39832354] - Revert 'rds: cong: Make rds_cong_wait an array to reduce lock contention' (Sharath Srinivasan) [Orabug: 39832354] - rds: Prevent kernel-infoleak in rds_notify_queue_get() (Peilin Ye) [Orabug: 39772650] - rds: do not leak kernel memory to user land (Eric Dumazet) [Orabug: 39772650] - net/rds: zero per-item info buffer before handing it to visitors (Michael Bommarito) [Orabug: 39621715,39638197] {CVE-2026-52995} - x86/sev: Evict cache lines during SNP memory validation (Tom Lendacky) [Orabug: 38334919] {CVE-2025-38560} - Revert: uek-rpm: cnic: Trim the SNIC config for a faster boot (Kan Liang) [Orabug: 39825570] - Revert: uek-rpm: cnic: Clean up the elba/SNIC config with make olddefconfig (Kan Liang) [Orabug: 39825570] - rds: ib: move gc_count reset before free_percpu (Manjunath Patil) [Orabug: 39818509] - rds: fix lfstack_pop_all sequence reset (Manjunath Patil) [Orabug: 39818509] - drm/amdkfd: fix invalid GTT pointer in DQM cleanup (Imran Khan) [Orabug: 39605741] - xfs: resample the data fork mapping after cycling ILOCK (Darrick Wong) [Orabug: 39776791] {CVE-2026-64600} [5.15.0-324.211.1] - signal: Fix use-after-free of wait_chldexit (Aruna Ramakrishna) [Orabug: 39800301] - mstflint_access: Update driver code to v4.36.0-1 from Github (Mark Haywood) [Orabug: 38074279] - mstflint_access: Update driver code to v4.35.0-1 from Github (Mark Haywood) [Orabug: 38074279] - mstflint_access: Update driver code to v4.34.0-1 from Github (Itay Avraham) [Orabug: 38074279] - mstflint_access: Update driver code to v4.33.0-1 from Github (Itay Avraham) [Orabug: 38074279] - mstflint_access: Update driver code to v4.32.0-1 from Github (Tzafrir Cohen) [Orabug: 38074279] - mstflint_access: Update driver code to v4.31.0-1 from Github (Mark Haywood) [Orabug: 38074279] - mstflint_access: Update driver code to v4.28.0-1 from Github (Itay Avraham) [Orabug: 38074279] - mstflint_access: Update driver code to v4.26.0-1 from Github (Markus Theil) [Orabug: 38074279] - mstflint_access: Update driver code to v4.25.0-1 from Github (Mark Haywood) [Orabug: 38074279] - mstflint_access: Update driver code to v4.24.0-1 from Github (Chris Moore) [Orabug: 38074279] - mstflint_access: Update driver code to v4.21.0-1 from Github (Mark Haywood) [Orabug: 38074279] - mm/filemap: make filemap_fault() to retry fault after collapse_file() (Jane Chu) [Orabug: 39778847] - PM: hibernate: Fix backwards snapshot_test condition for test_resume mode (Jeremy Tang) [Orabug: 39766052] - PM: hibernate: Do not get block device exclusively in test_resume mode (Chen Yu) [Orabug: 39766052] - PM: hibernate: Turn snapshot_test into global variable (Chen Yu) [Orabug: 39766052] - PM: hibernate: fix load_image_and_restore() error path (Ye Bin) [Orabug: 39766052] - arm64: mm: Add PTE_DIRTY back to PAGE_KERNEL* to fix kexec/hibernation (Catalin Marinas) [Orabug: 39750197] ...

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2024-27012",
    "CVE-2024-58240",
    "CVE-2025-38560",
    "CVE-2026-43216",
    "CVE-2026-43491",
    "CVE-2026-46135",
    "CVE-2026-52995",
    "CVE-2026-53090",
    "CVE-2026-53392",
    "CVE-2026-53393",
    "CVE-2026-53399",
    "CVE-2026-53400",
    "CVE-2026-53402",
    "CVE-2026-63806",
    "CVE-2026-63810",
    "CVE-2026-63829",
    "CVE-2026-63830",
    "CVE-2026-64098",
    "CVE-2026-64187",
    "CVE-2026-64189",
    "CVE-2026-64192",
    "CVE-2026-64206",
    "CVE-2026-64266",
    "CVE-2026-64270",
    "CVE-2026-64271",
    "CVE-2026-64272",
    "CVE-2026-64275",
    "CVE-2026-64276",
    "CVE-2026-64279",
    "CVE-2026-64294",
    "CVE-2026-64296",
    "CVE-2026-64298",
    "CVE-2026-64299",
    "CVE-2026-64304",
    "CVE-2026-64306",
    "CVE-2026-64312",
    "CVE-2026-64313",
    "CVE-2026-64317",
    "CVE-2026-64322",
    "CVE-2026-64323",
    "CVE-2026-64324",
    "CVE-2026-64330",
    "CVE-2026-64331",
    "CVE-2026-64332",
    "CVE-2026-64333",
    "CVE-2026-64334",
    "CVE-2026-64335",
    "CVE-2026-64336",
    "CVE-2026-64338",
    "CVE-2026-64340",
    "CVE-2026-64342",
    "CVE-2026-64343",
    "CVE-2026-64344",
    "CVE-2026-64346",
    "CVE-2026-64347",
    "CVE-2026-64351",
    "CVE-2026-64352",
    "CVE-2026-64355",
    "CVE-2026-64362",
    "CVE-2026-64363",
    "CVE-2026-64364",
    "CVE-2026-64370",
    "CVE-2026-64371",
    "CVE-2026-64372",
    "CVE-2026-64373",
    "CVE-2026-64374",
    "CVE-2026-64375",
    "CVE-2026-64379",
    "CVE-2026-64380",
    "CVE-2026-64381",
    "CVE-2026-64401",
    "CVE-2026-64403",
    "CVE-2026-64406",
    "CVE-2026-64408",
    "CVE-2026-64411",
    "CVE-2026-64412",
    "CVE-2026-64413",
    "CVE-2026-64420",
    "CVE-2026-64422",
    "CVE-2026-64423",
    "CVE-2026-64425",
    "CVE-2026-64427",
    "CVE-2026-64434",
    "CVE-2026-64435",
    "CVE-2026-64436",
    "CVE-2026-64440",
    "CVE-2026-64441",
    "CVE-2026-64442",
    "CVE-2026-64443",
    "CVE-2026-64444",
    "CVE-2026-64445",
    "CVE-2026-64446",
    "CVE-2026-64448",
    "CVE-2026-64450",
    "CVE-2026-64452",
    "CVE-2026-64454",
    "CVE-2026-64455",
    "CVE-2026-64456",
    "CVE-2026-64461",
    "CVE-2026-64465",
    "CVE-2026-64470",
    "CVE-2026-64471",
    "CVE-2026-64475",
    "CVE-2026-64478",
    "CVE-2026-64479",
    "CVE-2026-64483",
    "CVE-2026-64484",
    "CVE-2026-64487",
    "CVE-2026-64496",
    "CVE-2026-64503",
    "CVE-2026-64504",
    "CVE-2026-64510",
    "CVE-2026-64512",
    "CVE-2026-64514",
    "CVE-2026-64530",
    "CVE-2026-64531",
    "CVE-2026-64534",
    "CVE-2026-64535",
    "CVE-2026-64536",
    "CVE-2026-64538",
    "CVE-2026-64540",
    "CVE-2026-64543",
    "CVE-2026-64544",
    "CVE-2026-64545",
    "CVE-2026-64546",
    "CVE-2026-64547",
    "CVE-2026-64548",
    "CVE-2026-64549",
    "CVE-2026-64551",
    "CVE-2026-64553",
    "CVE-2026-64554",
    "CVE-2026-64560",
    "CVE-2026-64561",
    "CVE-2026-64562",
    "CVE-2026-64563",
    "CVE-2026-64567",
    "CVE-2026-64569",
    "CVE-2026-64571",
    "CVE-2026-64572",
    "CVE-2026-64576",
    "CVE-2026-64579",
    "CVE-2026-64586",
    "CVE-2026-64593",
    "CVE-2026-64599",
    "CVE-2026-64600",
    "CVE-2026-64604",
    "CVE-2026-68082",
    "CVE-2026-68091",
    "CVE-2026-68096",
    "CVE-2026-68104",
    "CVE-2026-68106",
    "CVE-2026-68111",
    "CVE-2026-68115",
    "CVE-2026-68117",
    "CVE-2026-68121",
    "CVE-2026-68123",
    "CVE-2026-68125",
    "CVE-2026-68129",
    "CVE-2026-68131",
    "CVE-2026-68132",
    "CVE-2026-68138",
    "CVE-2026-68142",
    "CVE-2026-68143",
    "CVE-2026-68144",
    "CVE-2026-68146",
    "CVE-2026-68153",
    "CVE-2026-68154",
    "CVE-2026-68155",
    "CVE-2026-68156",
    "CVE-2026-68157",
    "CVE-2026-68158",
    "CVE-2026-68159",
    "CVE-2026-68160",
    "CVE-2026-68162",
    "CVE-2026-68180",
    "CVE-2026-68184",
    "CVE-2026-68186",
    "CVE-2026-68187",
    "CVE-2026-68188",
    "CVE-2026-68190",
    "CVE-2026-68192",
    "CVE-2026-68197",
    "CVE-2026-68198",
    "CVE-2026-68199",
    "CVE-2026-68202",
    "CVE-2026-68205",
    "CVE-2026-68212",
    "CVE-2026-68213",
    "CVE-2026-68214",
    "CVE-2026-68216",
    "CVE-2026-68217",
    "CVE-2026-68218",
    "CVE-2026-68226",
    "CVE-2026-68227",
    "CVE-2026-68234",
    "CVE-2026-68243",
    "CVE-2026-68244",
    "CVE-2026-68248",
    "CVE-2026-68249",
    "CVE-2026-68250",
    "CVE-2026-68253",
    "CVE-2026-68254",
    "CVE-2026-68255",
    "CVE-2026-68284",
    "CVE-2026-68294",
    "CVE-2026-68297",
    "CVE-2026-68299",
    "CVE-2026-68300",
    "CVE-2026-68301",
    "CVE-2026-68304",
    "CVE-2026-68309",
    "CVE-2026-68313",
    "CVE-2026-68315",
    "CVE-2026-68320",
    "CVE-2026-68325",
    "CVE-2026-68326",
    "CVE-2026-68328",
    "CVE-2026-68338",
    "CVE-2026-68344",
    "CVE-2026-68349",
    "CVE-2026-68350",
    "CVE-2026-68351",
    "CVE-2026-68352",
    "CVE-2026-68353",
    "CVE-2026-68354",
    "CVE-2026-68355",
    "CVE-2026-68363",
    "CVE-2026-68365",
    "CVE-2026-68367",
    "CVE-2026-68368",
    "CVE-2026-68373",
    "CVE-2026-68376",
    "CVE-2026-68377",
    "CVE-2026-68398",
    "CVE-2026-68402",
    "CVE-2026-68403",
    "CVE-2026-68405",
    "CVE-2026-68406",
    "CVE-2026-68410",
    "CVE-2026-68413",
    "CVE-2026-68414",
    "CVE-2026-68422",
    "CVE-2026-68425",
    "CVE-2026-68428",
    "CVE-2026-68430",
    "CVE-2026-68432",
    "CVE-2026-68433",
    "CVE-2026-68434",
    "CVE-2026-68444",
    "CVE-2026-68446",
    "CVE-2026-68450",
    "CVE-2026-68456",
    "CVE-2026-68461",
    "CVE-2026-68469",
    "CVE-2026-68475",
    "CVE-2026-68477",
    "CVE-2026-68479",
    "CVE-2026-68480",
    "CVE-2026-72004",
    "CVE-2026-72005",
    "CVE-2026-72010",
    "CVE-2026-72014",
    "CVE-2026-72015",
    "CVE-2026-72019",
    "CVE-2026-72020",
    "CVE-2026-72021",
    "CVE-2026-72024",
    "CVE-2026-72035",
    "CVE-2026-72036",
    "CVE-2026-72039",
    "CVE-2026-72045",
    "CVE-2026-72049",
    "CVE-2026-72051",
    "CVE-2026-72052",
    "CVE-2026-72053",
    "CVE-2026-72054",
    "CVE-2026-72055",
    "CVE-2026-72056",
    "CVE-2026-72057",
    "CVE-2026-72061",
    "CVE-2026-72063",
    "CVE-2026-72065",
    "CVE-2026-72066",
    "CVE-2026-72067",
    "CVE-2026-72068",
    "CVE-2026-72070",
    "CVE-2026-72073",
    "CVE-2026-72083",
    "CVE-2026-72084",
    "CVE-2026-72085",
    "CVE-2026-72086",
    "CVE-2026-72087",
    "CVE-2026-72088",
    "CVE-2026-72096",
    "CVE-2026-72099",
    "CVE-2026-72102",
    "CVE-2026-72105",
    "CVE-2026-72107",
    "CVE-2026-72108",
    "CVE-2026-72110",
    "CVE-2026-72113",
    "CVE-2026-72114",
    "CVE-2026-72115",
    "CVE-2026-72116",
    "CVE-2026-72117",
    "CVE-2026-72118",
    "CVE-2026-72119",
    "CVE-2026-72120",
    "CVE-2026-72121",
    "CVE-2026-72122",
    "CVE-2026-72123",
    "CVE-2026-72124",
    "CVE-2026-72125",
    "CVE-2026-72126",
    "CVE-2026-72129",
    "CVE-2026-72135",
    "CVE-2026-72136",
    "CVE-2026-72138",
    "CVE-2026-72142",
    "CVE-2026-72152",
    "CVE-2026-72155",
    "CVE-2026-72159",
    "CVE-2026-72160",
    "CVE-2026-72163",
    "CVE-2026-72164",
    "CVE-2026-72165",
    "CVE-2026-72166",
    "CVE-2026-72170",
    "CVE-2026-72182",
    "CVE-2026-72218",
    "CVE-2026-72219",
    "CVE-2026-72223",
    "CVE-2026-72224",
    "CVE-2026-72225",
    "CVE-2026-72226",
    "CVE-2026-72228",
    "CVE-2026-72229",
    "CVE-2026-72230",
    "CVE-2026-72231",
    "CVE-2026-72232",
    "CVE-2026-72233",
    "CVE-2026-72234",
    "CVE-2026-72235",
    "CVE-2026-72240",
    "CVE-2026-72241",
    "CVE-2026-72242",
    "CVE-2026-72245",
    "CVE-2026-72247",
    "CVE-2026-72250",
    "CVE-2026-72251",
    "CVE-2026-72252",
    "CVE-2026-72253",
    "CVE-2026-72255",
    "CVE-2026-72256",
    "CVE-2026-72265",
    "CVE-2026-72272",
    "CVE-2026-72282",
    "CVE-2026-72289",
    "CVE-2026-72297",
    "CVE-2026-72298",
    "CVE-2026-72299",
    "CVE-2026-72305",
    "CVE-2026-72306",
    "CVE-2026-72310",
    "CVE-2026-72314",
    "CVE-2026-72316",
    "CVE-2026-72319",
    "CVE-2026-72322",
    "CVE-2026-72326",
    "CVE-2026-72339",
    "CVE-2026-72347",
    "CVE-2026-72348",
    "CVE-2026-72349",
    "CVE-2026-72350",
    "CVE-2026-72351",
    "CVE-2026-72389",
    "CVE-2026-72392",
    "CVE-2026-72396",
    "CVE-2026-72400",
    "CVE-2026-72406",
    "CVE-2026-72409",
    "CVE-2026-72418",
    "CVE-2026-72421",
    "CVE-2026-72428",
    "CVE-2026-72433",
    "CVE-2026-72435",
    "CVE-2026-72441",
    "CVE-2026-72447",
    "CVE-2026-72450",
    "CVE-2026-72466",
    "CVE-2026-72476",
    "CVE-2026-72481",
    "CVE-2026-72491",
    "CVE-2026-72502",
    "CVE-2026-74255",
    "CVE-2026-74256",
    "CVE-2026-74265",
    "CVE-2026-74267",
    "CVE-2026-74279",
    "CVE-2026-74281",
    "CVE-2026-74282",
    "CVE-2026-74283",
    "CVE-2026-74284",
    "CVE-2026-74287",
    "CVE-2026-74288",
    "CVE-2026-74295",
    "CVE-2026-74297",
    "CVE-2026-74305",
    "CVE-2026-74312",
    "CVE-2026-74313",
    "CVE-2026-74320",
    "CVE-2026-74321",
    "CVE-2026-74327",
    "CVE-2026-74329",
    "CVE-2026-74330",
    "CVE-2026-74331",
    "CVE-2026-74339",
    "CVE-2026-74340",
    "CVE-2026-74346",
    "CVE-2026-74348",
    "CVE-2026-74349",
    "CVE-2026-74351",
    "CVE-2026-74359",
    "CVE-2026-74363",
    "CVE-2026-74376",
    "CVE-2026-74379",
    "CVE-2026-74382",
    "CVE-2026-74384",
    "CVE-2026-74390",
    "CVE-2026-74394",
    "CVE-2026-74395",
    "CVE-2026-74398",
    "CVE-2026-74399",
    "CVE-2026-74408",
    "CVE-2026-74410",
    "CVE-2026-74416",
    "CVE-2026-74424",
    "CVE-2026-74443",
    "CVE-2026-74444",
    "CVE-2026-74453",
    "CVE-2026-74455",
    "CVE-2026-74456",
    "CVE-2026-74457",
    "CVE-2026-74458",
    "CVE-2026-74460",
    "CVE-2026-74461",
    "CVE-2026-74464",
    "CVE-2026-74465",
    "CVE-2026-74469",
    "CVE-2026-74470",
    "CVE-2026-74471",
    "CVE-2026-74473",
    "CVE-2026-74475",
    "CVE-2026-74479",
    "CVE-2026-74480",
    "CVE-2026-74481",
    "CVE-2026-74482",
    "CVE-2026-74485",
    "CVE-2026-74486",
    "CVE-2026-74487",
    "CVE-2026-74488",
    "CVE-2026-74490",
    "CVE-2026-74492",
    "CVE-2026-74495",
    "CVE-2026-74497",
    "CVE-2026-74498",
    "CVE-2026-74499",
    "CVE-2026-74505",
    "CVE-2026-74507",
    "CVE-2026-74508",
    "CVE-2026-74512",
    "CVE-2026-74517",
    "CVE-2026-74518",
    "CVE-2026-74519",
    "CVE-2026-74523",
    "CVE-2026-74540",
    "CVE-2026-74546",
    "CVE-2026-74547",
    "CVE-2026-74548",
    "CVE-2026-74556",
    "CVE-2026-74557",
    "CVE-2026-74564",
    "CVE-2026-74566",
    "CVE-2026-74567",
    "CVE-2026-74569",
    "CVE-2026-74575",
    "CVE-2026-74577",
    "CVE-2026-74579",
    "CVE-2026-74580",
    "CVE-2026-74581",
    "CVE-2026-74583",
    "CVE-2026-74585",
    "CVE-2026-74586",
    "CVE-2026-74587",
    "CVE-2026-74588",
    "CVE-2026-74589",
    "CVE-2026-74594",
    "CVE-2026-74595",
    "CVE-2026-74597",
    "CVE-2026-74598",
    "CVE-2026-74599",
    "CVE-2026-74601",
    "CVE-2026-74604",
    "CVE-2026-74609",
    "CVE-2026-74613",
    "CVE-2026-74614",
    "CVE-2026-74615",
    "CVE-2026-74616",
    "CVE-2026-74620",
    "CVE-2026-74621",
    "CVE-2026-74622",
    "CVE-2026-74623",
    "CVE-2026-74625",
    "CVE-2026-74630",
    "CVE-2026-74635",
    "CVE-2026-74636",
    "CVE-2026-74641",
    "CVE-2026-74648",
    "CVE-2026-74649",
    "CVE-2026-74650",
    "CVE-2026-74651",
    "CVE-2026-74654",
    "CVE-2026-74656",
    "CVE-2026-74657",
    "CVE-2026-74658",
    "CVE-2026-74660",
    "CVE-2026-74664",
    "CVE-2026-74667",
    "CVE-2026-74669",
    "CVE-2026-74671",
    "CVE-2026-74673",
    "CVE-2026-74675",
    "CVE-2026-74676",
    "CVE-2026-74679",
    "CVE-2026-74680",
    "CVE-2026-74682",
    "CVE-2026-74683",
    "CVE-2026-74684",
    "CVE-2026-74688",
    "CVE-2026-74696",
    "CVE-2026-74697",
    "CVE-2026-74701",
    "CVE-2026-74704",
    "CVE-2026-74705",
    "CVE-2026-74717",
    "CVE-2026-74720",
    "CVE-2026-74726",
    "CVE-2026-74730",
    "CVE-2026-74746",
    "CVE-2026-74748",
    "CVE-2026-80527",
    "CVE-2026-80528",
    "CVE-2026-80534",
    "CVE-2026-80540",
    "CVE-2026-80541",
    "CVE-2026-80558",
    "CVE-2026-80561",
    "CVE-2026-80574",
    "CVE-2026-80586",
    "CVE-2026-80590",
    "CVE-2026-80593",
    "CVE-2026-80599",
    "CVE-2026-80601",
    "CVE-2026-80603",
    "CVE-2026-80604",
    "CVE-2026-80605",
    "CVE-2026-80609",
    "CVE-2026-80613",
    "CVE-2026-80622",
    "CVE-2026-80630",
    "CVE-2026-80644",
    "CVE-2026-80646",
    "CVE-2026-80652",
    "CVE-2026-80659",
    "CVE-2026-80664",
    "CVE-2026-80677",
    "CVE-2026-80678",
    "CVE-2026-80681",
    "CVE-2026-80706",
    "CVE-2026-80707",
    "CVE-2026-80714",
    "CVE-2026-80715",
    "CVE-2026-80716",
    "CVE-2026-80717",
    "CVE-2026-80722",
    "CVE-2026-80731",
    "CVE-2026-80733",
    "CVE-2026-80742",
    "CVE-2026-80744",
    "CVE-2026-80754",
    "CVE-2026-80756",
    "CVE-2026-80757"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[5.15.0-324.217.5.2]\n- inet: frags: strip GSO state from fragments before reassembly (Xinyang Ge)  [Orabug: 39974835]  {CVE-2026-80590}\n\n[5.15.0-324.217.5.1]\n- crypto: qat: restore misc workqueue lifecycle (Manjunath Patil)  [Orabug: 39937535]\n- LTS version: v5.15.217 (Vijayendra Suman)\n- ring-buffer: Use current_context for safe per-CPU buffer swap (Tengda Wu)\n- ring-buffer: Remove jump to out label in ring_buffer_swap_cpu() (Steven Rostedt)\n- jiffies: Cast to unsigned long in secs_to_jiffies() conversion (Easwar Hariharan)\n- drm/virtio: Unlock reservations on dma_resv_reserve_fences() error (Dmitry Osipenko)\n- drm/vmwgfx: Reserve fence slots on buffer objects in cotables (Zack Rusin)\n- udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf() (Robert Mader)\n- binfmt_misc: use exe_file_deny_write_access() for the interpreter clone (Christian Brauner)\n- net/x25: fix use-after-free of the socket by its timers (Baul Lee)\n- net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG (Siddharth Vadapalli)\n- af_packet: Don't send zero-byte data in tpacket_snd(). (Eric Dumazet)\n- ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (Rosen Penev)\n- net: packet: fix wrong transport_header when sending VLAN-tagged frame (Wei Fang)\n- netfilter: ipset: fix list type element drift bug (Florian Westphal)\n- netfilter: flowtable: publish GC-visible tuple last (Jeremy Jean)\n- netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path (Alexey Velichayshiy)\n- netfilter: ipset: fix refcount race between list:set GC and swap (Xiang Mei (Microsoft))\n- crypto: ccm - Set rfc4309 maxauthsize from child (Herbert Xu)\n- arm64: tegra: Add EL2 virtual timer interrupt for Tegra194 (Jon Hunter)\n- net: smc: fix splice entry lifetime imbalance in smc_rx_splice (Daming Li)\n- net/smc: rdma write inline if qp has sufficient inline space (Guangguan Wang)\n- net: atlantic: free stranded TX buffers on ring deinit (Yangyu Chen)\n- net/sched: act_ct: fix sk_buff leak when the header checks reject a packet (Hyunjung Ko)\n- openvswitch: move key and ovs_cb update out of handle_fragments (Xin Long)\n- net: sched: use skb_ip_totlen and iph_totlen (Xin Long)\n- openvswitch: use skb_ip_totlen in conntrack (Xin Long)\n- net: add a couple of helpers for iph tot_len (Xin Long)\n- mm/ptdump: always stabilise against page table freeing using init_mm (Lorenzo Stoakes (ARM))\n- sched/psi: Shut down rtpoll_timer in psi_cgroup_free() (Tejun Heo)\n- drm/amd/pm: fix torn gpu metrics reads (Yang Wang)\n- ice: wait for reset completion in ice_resume() (Aaron Ma)\n- jiffies: Define secs_to_jiffies() (Easwar Hariharan)\n- can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure (Marc Kleine-Budde)\n- i2c: iproc: reset bus after timeout if START_BUSY is stuck (Jonas Gorski)\n- i2c: bcm-iproc: remove printout on handled timeouts (Wolfram Sang)\n- i2c: imx: Fix slave registration race and error handling (Liem)\n- binfmt_misc: restore write access when removing an entry (Christian Brauner)\n- fs: don't block write during exec on pre-content watched files (Amir Goldstein)\n- fsnotify: opt-in for permission events at file open time (Amir Goldstein)\n- ice: fix memory leak in ice_lbtest_prepare_rings() (Dawei Feng)\n- scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write (Ibrahim Hashimov)\n- scsi: scsi_debug: Rename zone type constants (Damien Le Moal)\n- scsi: sd: sd_zbc: Return early in sd_zbc_check_zoned_characteristics() (Damien Le Moal)\n- scsi: sd: sd_zbc: Introduce struct zoned_disk_info (Bart Van Assche)\n- scsi: sd: sd_zbc: Use logical blocks as unit when querying zones (Damien Le Moal)\n- scsi: sd: sd_zbc: Improve source code documentation (Bart Van Assche)\n- net: pktgen: fix proc entry use-after-free (Chengfeng Ye)\n- net: pktgen: fix code style (WARNING: Block comments) (Peter Seiderer)\n- igc: remove napi_synchronize() in igc_down() (David Carlier)\n- wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() (Maoyi Xie)\n- ksmbd: reject repeated SMB2 NEGOTIATE requests (Namjae Jeon)\n- ksmbd: conn lock to serialize smb2 negotiate (Namjae Jeon)\n- mm/vmstat: fold stranded per-cpu node stats when a node comes online (Gregory Price)\n- ksmbd: validate minimum PDU size for transform requests (Namjae Jeon)\n- smb/server: fix minimum SMB2 PDU size (ChenXiaoSong)\n- smb/server: fix minimum SMB1 PDU size (ChenXiaoSong)\n- ksmbd: rename smb2_get_msg to smb_get_msg (Namjae Jeon)\n- super: fix emergency thaw deadlock on frozen block devices (Christian Brauner)\n- ftrace: Add global mutex to serialize trace_parser access (Tengda Wu)\n- net/sched: serialize qdisc_rtab_list against concurrent get/put (Aldo Ariel Panzardo)\n- ksmbd: defer destroy_previous_session() until after NTLM authentication (James Montgomery)\n- libceph: fix two unsafe bare decodes in decode_lockers() (Pavitra Jha)\n- ceph: fix hanging __ceph_get_caps() with stale mds_wanted (Max Kellermann)\n- ceph: print cluster fsid and client global_id in all debug logs (Xiubo Li)\n- ceph: rename _to_client() to _to_fs_client() (Xiubo Li)\n- libceph: add doutc and *_client debug macros support (Xiubo Li)\n- libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (Xiang Mei)\n- libceph: Amend checking to fix make W=1 build breakage (Andy Shevchenko)\n- ceph: avoid fs reclaim while using current-journal_info (Max Kellermann)\n- sctp: avoid auth_enable sysctl UAF during netns teardown (Zhiling Zou)\n- mptcp: decrement subflows counter on failed passive join (Chenguang Zhao)\n- mptcp: fix subflow accounting on close (Paolo Abeni)\n- mptcp: cleanup MPJ subflow list handling (Paolo Abeni)\n- serial: sc16is7xx: implement gpio get_direction() callback (Hugo Villeneuve)\n- serial: sc16is7xx: fix regression with GPIO configuration (Hugo Villeneuve)\n- serial: sc16is7xx: remove obsolete out_thread label (Hugo Villeneuve)\n- serial: sc16is7xx: Fill in rs485_supported (Ilpo Jarvinen)\n- sc16is7xx: Properly resume TX after stop (Tomasz Mon)\n- wifi: brcmfmac: set F2 blocksize to 256 for BCM43752 (LiangCheng Wang)\n- wifi: brcmfmac: fix 43752 SDIO FWVID incorrectly labelled as Cypress (CYW) (Gokul Sivakumar)\n- serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (Jiangshan Yi)\n- serial: 8250_mid: Remove unneeded test for -setup() presence (Andy Shevchenko)\n- wifi: brcmfmac: drain bus_reset work on device removal (Fan Wu)\n- ALSA: seq: close a re-opened queue timer in the destructor (Norbert Szetei)\n- media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (Mirela Rabulea)\n- media: v4l: async: Set owner for async sub-devices (Sakari Ailus)\n- wifi: ath6kl: fix use-after-free in aggr_reset_state() (Daniel Hodges)\n- media: imx219: Fix maximum frame length in lines (Sakari Ailus)\n- media: i2c: imx219: Rename VTS to FRM_LENGTH (Jai Luthra)\n- media: i2c: imx219: Correct the minimum vblanking value (David Plowman)\n- media: i2c: imx219: Drop IMX219_VTS_* macros (Laurent Pinchart)\n- media: marvell-cam: fix missing pci_disable_device() on remove (Guangshuo Li)\n- drm/i915/hdcp: require monotonically increasing seq_num_v (Jani Nikula)\n- drm/i915/hdcp: check streams[] bounds before overflow (Jani Nikula)\n- drm/i915/vrr: require valid min/max vfreq for VRR (Jani Nikula)\n- media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (David Carlier)\n- drm/virtio: bound EDID block reads to the response buffer (Bryam Vargas)\n- drm/virtio: Return proper error codes instead of -1 (Dmitry Osipenko)\n- drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (Timur Kristof)\n- drm/tegra: fbdev: Remove offset into framebuffer memory (Thomas Zimmermann)\n- drm/displayid: fix Tiled Display Topology ID size (Jani Nikula)\n- drm/virtio: use uninterruptible resv lock for plane updates (Deepanshu Kartikey)\n- dma-buf/drivers: make reserving a shared slot mandatory v4 (Christian Konig)\n- drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (Ashutosh Desai)\n- drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (Ashutosh Desai)\n- usb: gadget: f_tcm: synchronize delayed set_alt with teardown (Cen Zhang)\n- drm/dp/mst: fix buffer overflows in sideband chunk accumulation (Ashutosh Desai)\n- fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list (Reinette Chatre)\n- octeontx2-pf: fix SQB pointer leak on init failure (Dawei Feng)\n- net: ipa: fix SMEM state handle leaks in SMP2P init (Haoxiang Li)\n- espintcp: use sk_msg_free_partial to fix partial send (Sabrina Dubroca)\n- bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline() (Breno Leitao)\n- bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c (Breno Leitao)\n- bootconfig: do not put quotes on cmdline items unless necessary (Rasmus Villemoes)\n- net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Bryam Vargas)\n- net/sched: taprio: avoid calling child-ops-dequeue(child) twice (Vladimir Oltean)\n- gpio: tegra: do not call pinctrl for GPIO direction (Runyu Xiao)\n- treewide: rename pinctrl_gpio_direction_output_new() (Bartosz Golaszewski)\n- octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (Junrui Luo)\n- net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)\n- net: mana: Validate the packet length reported by the NIC (Dexuan Cui)\n- net/sched: act_ct: preserve tc_skb_cb across defragmentation (Zihan Xi)\n- net: ixp4xx_hss: fix duplicate HDLC netdev allocation (Haoxiang Li)\n- net: ipip: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)\n- net: Add helper function to parse netlink msg of ip_tunnel_encap (Liu Jian)\n- locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (Thomas Gleixner)\n- mmc: vub300: fix use-after-free on probe failure (Guangshuo Li)\n- mmc: vub300: rename probe error labels (Johan Hovold)\n- mmc: vub300: fix use-after-free on disconnect (Johan Hovold)\n- Input: ims-pcu - fix firmware leak in async update (Dmitry Torokhov)\n- firmware_loader: introduce __free() cleanup hanler (Dmitry Torokhov)\n- dm-verity: make error counter atomic (Mikulas Patocka)\n- dm-integrity: don't increment hash_offset twice (Mikulas Patocka)\n- scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() (Abdun Nihaal)\n- ovl: use linked upper dentry in copy-up tmpfile (Souvik Banerjee)\n- bpf,fork: wipe -bpf_storage before bailouts that access it (Jann Horn)\n- thunderbolt: Prevent XDomain delayed work use-after-free on disconnect (Michael Bommarito)\n- thunderbolt: Remove XDomain from the bus without holding tb-lock (Mika Westerberg)\n- thunderbolt: Remove service debugfs entries during unregister (Mika Westerberg)\n- thunderbolt: Keep XDomain reference during the lifetime of a service (Mika Westerberg)\n- thunderbolt: Update property.c function documentation (Alan Borzeszkowski)\n- thunderbolt: Remove usage of the deprecated ida_simple_xx() API (Christophe JAILLET)\n- can: esd_usb: kill anchored URBs before freeing netdevs (Fan Wu)\n- can/esd_usb2: Rename esd_usb2.c to esd_usb.c (Frank Jungclaus)\n- i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (Vincent Jardin)\n- i2c: imx: separate atomic, dma and non-dma use case (Stefan Eichenberger)\n- ksmbd: fix integer overflow in set_file_allocation_info() (Ibrahim Hashimov)\n- tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (Jarkko Sakkinen)\n- smb: client: use kvzalloc() for megabyte buffer in simple fallocate (Fredric Cover)\n- taskstats: retain dead thread stats in TGID queries (Yiyang Chen)\n- taskstats: fill_stats_for_tgid: use for_each_thread() (Oleg Nesterov)\n- dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (Frank Li)\n- dmaengine: dw-edma: Detach the private data and chip info structures (Frank Li)\n- dmaengine: dw-edma: Remove unused irq field in struct dw_edma_chip (Frank Li)\n- mtd: spi-nor: swp: Improve locking user experience (Miquel Raynal)\n- mtd: spi-nor: Fix spi_nor_try_unlock_all() (Michael Walle)\n- net: thunderbolt: Fix frags[] overflow by bounding frame_count (Maoyi Xie)\n- mtd: maps: vmu-flash: fix fault in unaligned fixup (Florian Fuchs)\n- 9p: skip nlink update in cacheless mode to fix WARN_ON (Breno Leitao)\n- ntfs3: validate split-point offset in indx_insert_into_buffer (Michael Bommarito)\n- fs/ntfs3: Undo critial modificatins to keep directory consistency (Konstantin Komarov)\n- fs/ntfs3: Make ntfs_update_mftmirr return void (Pavel Skripkin)\n- selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() (Tristan Madani)\n- lsm: infrastructure management of the sock security (Casey Schaufler)\n- lsm: use default hook return value in call_int_hook() (Ondrej Mosnacek)\n- remoteproc: qcom: Fix leak when custom dump_segments addition fails (Wasim Nazir)\n- remoteproc: qcom: pas: Adjust the phys addr wrt the mem region (Yogesh Lal)\n- remoteproc: qcom: fix sparse warnings (Mukesh Ojha)\n- remoteproc: qcom: replace kstrdup with kstrndup (Mukesh Ojha)\n- netfilter: nft_set_pipapo: don't leak bad clone into future transaction (Florian Westphal)\n- netfilter: nft_set_pipapo: move cloning of match info to insert/removal path (Florian Westphal)\n- netfilter: nft_set_pipapo: prepare pipapo_get helper for on-demand clone (Florian Westphal)\n- netfilter: nft_set_pipapo: merge deactivate helper into caller (Florian Westphal)\n- netfilter: nft_set_pipapo: prepare walk function for on-demand clone (Florian Westphal)\n- netfilter: nft_set_pipapo: make pipapo_clone helper return NULL (Florian Westphal)\n- netfilter: nf_conntrack_sip: validate skb_dst() before accessing it (Pablo Neira Ayuso)\n- netfilter: nf_conntrack_sip: remove net variable shadowing (Florian Westphal)\n- netfilter: nft_set_pipapo: move prove_locking helper around (Florian Westphal)\n- netfilter: nft_set_pipapo: use GFP_KERNEL for insertions (Florian Westphal)\n- ASoC: mediatek: mt8192: Check runtime resume during probe (Cassio Gabriel)\n- ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable (Tang Bin)\n- ASoC: mediatek: Use common mtk_afe_pcm_platform with common probe cb (AngeloGioacchino Del Regno)\n- ASoC: mediatek: mt8192-afe-pcm: Simplify with dev_err_probe() (AngeloGioacchino Del Regno)\n- ASoC: mediatek: mt8192-afe-pcm: Convert to devm_pm_runtime_enable() (AngeloGioacchino Del Regno)\n- netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst (Haoze Xie)\n- ipv4: adopt dst_dev, skb_dst_dev and skb_dst_dev_net[_rcu] (Eric Dumazet)\n- net: dst: add four helpers to annotate data-races around dst-dev (Eric Dumazet)\n- net: dst: annotate data-races around dst-output (Eric Dumazet)\n- net: dst: annotate data-races around dst-input (Eric Dumazet)\n- tcp: convert to dev_net_rcu() (Eric Dumazet)\n- ASoC: mediatek: mt8183: Check runtime resume during probe (Cassio Gabriel)\n- octeontx2-vf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)\n- octeontx2-pf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)\n- octeontx2: Annotate mmio regions as __iomem (Subbaraya Sundeep)\n- octeontx2-af: Fix APR entry mapping based on APR_LMT_CFG (Geetha sowjanya)\n- VDUSE: avoid leaking information to userspace (Jason Wang)\n- vduse: take out allocations from vduse_dev_alloc_coherent (Eugenio Perez)\n- vduse: remove unused vaddr parameter of vduse_domain_free_coherent (Eugenio Perez)\n- vduse: Use fixed 4KB bounce pages for non-4KB page size (Sheng Zhao)\n- mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (Wentao Liang)\n- tipc: restrict socket queue dumps in enqueue tracepoints (Li Xiasong)\n- fbcon: Use correct type for vc_resize() return value (Jiacheng Yu)\n- fbcon: Rename struct fbcon_ops to struct fbcon_par (Thomas Zimmermann)\n- rxrpc: serialize kernel accept preallocation with socket teardown (Li Daming)\n- serial: max310x: implement gpio_chip::get_direction() (Tapio Reijonen)\n- serial: max310x: replace bare use of 'unsigned' with 'unsigned int' (checkpatch) (Hugo Villeneuve)\n- ALSA: hda: Fix cached processing coefficient verbs (Xu Rao)\n- audit: fix recursive locking deadlock in audit_dupe_exe() (Ricardo Robaina)\n- audit: use 'unsigned int' instead of 'unsigned' (Ricardo Robaina)\n- audit: widen ino fields to u64 (Jeff Layton)\n- VFS/audit: introduce kern_path_parent() for audit (NeilBrown)\n- ALSA: hda: conexant: Remove mic bias threshold override (Zhang Heng)\n- Input: mms114 - reject an oversized device packet size (Bryam Vargas)\n- i2c: davinci: Unregister cpufreq notifier on probe failure (Haoxiang Li)\n- Input: mms114 - fix touch indexing for MMS134S and MMS136 (Dmitry Torokhov)\n- fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() (Sebastian Alba Vives)\n- dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning (Mikhail Gavrilov)\n- udmabuf: Do not create malformed scatterlists (Jason Gunthorpe)\n- bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (Matt Bobrowski)\n- iommu/amd: Don't split flush for amd_iommu_domain_flush_all() (Weinan Liu)\n- mm: do file ownership checks with the proper mount idmap (Pedro Falcato)\n- net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (Xiang Mei)\n- xfs: check v5 superblock features early (Christoph Hellwig)\n- xfs: fix ilock leak on error in xfs_dq_get_next_id (Long Li)\n- drm/amdgpu: Fix UVD decode image min size calculation (David Rosca)\n- drm/amdgpu: Implement insert_end for VCE 3 (David Rosca)\n- drm/amdgpu: Reject UVD message with dimensions above 4096 (David Rosca)\n- drm/amdgpu: validate GEM_CREATE domain combinations (Candice Li)\n- drm/amdgpu: Reject UVD message with invalid number of h265 refs (David Rosca)\n- s390/vfio_ccw: Fix out of bounds check on CCW array (Eric Farman)\n- drm/radeon: fix autosuspend cleanup during teardown (Guangshuo Li)\n- mmc: sdhci: make tuning_err a signed int (Haibo Chen)\n- mmc: sdhci: unmap the bounce buffer before device release (Myeonghun Pak)\n- mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (Zhan Xusheng)\n- libceph: tolerate addrvecs with multiple entries of the same type (Kefu Chai)\n- ceph: fix MDS random selection readiness predicate (Yiming Zhu)\n- libceph: Avoid using invalid osd indices from primary_temp (Raphael Zimmer)\n- Input: sur40 - fix V4L error path cleanup (Dmitry Torokhov)\n- Input: sur40 - fix input device registration ordering (Dmitry Torokhov)\n- openrisc: signal: do not restore privileged SR bits on sigreturn (Ali Ahmet Memis)\n- ftrace: Fix off-by-one fentry site disable in ftrace_free_mem() (Josh Poimboeuf)\n- libceph: fix multiple unsafe decodes in decode_locker() (Pavitra Jha)\n- crypto: qce - fix error path in devm_qce_register_algs (Thorsten Blum)\n- Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (Dmitry Torokhov)\n- Input: synaptics-rmi4 - block s_input when F54 queue is busy (Dmitry Torokhov)\n- Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (Bryam Vargas)\n- Input: synaptics-rmi4 - zero report size on F54 work error (Dmitry Torokhov)\n- powerpc/pseries: lparcfg - fix kbuf[] underflow (George Wilson)\n- Input: iforce - validate input packet lengths (Pengpeng Hou)\n- Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (Zhefu Zhang)\n- Input: psxpad-spi - set driver data before use (Linmao Li)\n- Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (Richard Davies)\n- Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (Dmitry Torokhov)\n- powerpc/pseries: pci - logic bug (George Wilson)\n- ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (Dawid Wrobel)\n- ASoC: cs4265: sort the register default table (Peter Ujfalusi)\n- s390/qeth: validate user buffer length in SNMP and ARP query ioctls (Hidayath Khan)\n- mptcp: options: reset DSS fields in case of unexpected size (Matthieu Baerts (NGI0))\n- selinux: do not cancel a policy conversion that never started (Bryam Vargas)\n- selinux: reject a class permission count below its inherited common (Bryam Vargas)\n- selinux: require every boolean value to be defined (Bryam Vargas)\n- ipvs: separate destination availability state (Yizhou Zhao)\n- fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() (Zhan Xusheng)\n- media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization (Jiasheng Jiang)\n- media: mtk-vcodec: potential null pointer deference in SCP (Fullway Wang)\n- f2fs: fix UAF issue in f2fs_merge_page_bio() (Chao Yu)\n- LTS version: v5.15.216 (Vijayendra Suman)\n- thunderbolt: Bound the DROM dual link port number before indexing sw-ports (Bryam Vargas)\n- sctp: clear new_transport when removing a peer (Qing Ming)\n- sctp: fix use-after-free of cached ASCONF chunk (Yuxiang Yang)\n- sctp: keep chunk-transport in step with the list it is queued on (Baul Lee)\n- scsi: scsi_debug: Negate wrapped memcmp() result (Xu Rao)\n- bpf, sockmap: Fix sk_redir use-after-free in send verdict (Chengfeng Ye)\n- ip6_tunnel: clear skb2-cb[] in ip6ip6_err() (Zhiling Zou)\n- ipv6: fix Route Information option length validation (Yuejie Shi)\n- Revert 'thermal/drivers/hwmon: Cleanup coding style a bit' (Rafael J. Wysocki)\n- tipc: read le-link under the node lock in tipc_node_link_down() (Jun Yang)\n- vhost: reset the vring metadata cache on vring reconfiguration (Jun Yang)\n- vsock/virtio: avoid refilling the RX queue after teardown (Weiming Shi)\n- vsock/virtio: read virtqueues under worker locks (Weiming Shi)\n- vxlan: do not arm the ageing timer on a device that is down (Baul Lee)\n- xdp: reject clones that overrun skb_shared_info tailroom (Zhiling Zou)\n- net/sched: act_gact, act_police: range check the fallback control action (Hyunjung Ko)\n- net: atlantic: free RX pages of consumed but not refilled buffers (Yangyu Chen)\n- netfilter: bridge: release template ct on non-IP path (Zhiling Zou)\n- ipv6: prevent in6_dev_get() from resurrecting inet6_dev (Kyle Zeng)\n- fbdev: bitblit: bound-check glyph index in bit_cursor() (Rik van Riel)\n- tracing: Fix race between update_event_fields and, event_define_fields (Michael Wu)\n- ALSA: usx2y: bound the hwdep mmap fault offset (Baul Lee)\n- misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (Eddie Lin)\n- misc: fastrpc: fix channel ctx ref leak when session alloc fails (Anandu Krishnan E)\n- staging: rtl8723bs: validate monitor transmit frame lengths (Mariano Baragiola)\n- staging: rtl8723bs: fix missing shared-key auth challenge length check (Panagiotis Petrakopoulos)\n- staging: rtl8723bs: fix OOB read in WMM_param_handler() (Muhammad Bilal)\n- staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (Muhammad Bilal)\n- serial: 8250_dma: Clear stale RX state on shutdown (Cunhao Lu)\n- ipv4: fix use-after-free in fib_nhc_update_mtu() (Chengfeng Ye)\n- ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops (Zihan Xi)\n- fscrypt: Replace mk_users keyring with simple list (Eric Biggers)\n- pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP (Claudiu Beznea)\n- futex: Prevent robust futex exit race some more (Keno Fischer)\n- Bluetooth: 6lowpan: Fix using chan-conn as indication to no remote netdev (Luiz Augusto von Dentz)\n- Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (Marco Elver)\n- Input: evdev - fix information leak in evdev_pass_values() (Dmitry Torokhov)\n- vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (Joshua Rogers)\n- vt: add permission check for KDSKBMETA ioctl (Joshua Rogers)\n- net: bridge: mrp: fix uninitialised bytes on the wire (Baul Lee)\n- netfilter: ebt_nflog: pin the NFLOG backend (Chengfeng Ye)\n- net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header (Qihang Tang)\n- net: octeontx2-pf: Fix UB in shift operation (Sergey V. Frolov)\n- net: openvswitch: reallocate update replies for mismatched IDs (Zhiling Zou)\n- net/packet: reset the MAC header on the packet-socket transmit path (Doruk Tan Ozturk)\n- ipvs: clear IPv4 options after rebasing tunnel ICMP errors (Kyle Zeng)\n- ipvs: properly update the overload flag on dest edit (Julian Anastasov)\n- ipvs: add totalconns for dest (Julian Anastasov)\n- ima: fix out-of-bounds read in xattr_verify() (Lincoln Wallace)\n- usb: gadget: f_ncm: Use unsigned int for ndp_index (Sonali Pradhan)\n- usb: cdnsp: fix incorrect endian conversions for APB timeout register (Pawel Laszczak)\n- thunderbolt: icm: Preserve USB4 proxy data-valid bit (Xu Rao)\n- usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (Aleksandr Nogikh)\n- ALSA: usb-audio: fix OOB write on Type II inbound URBs (Baul Lee)\n- Input: evdev - sanitize event type index when fetching event masks (Dmitry Torokhov)\n- spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (Larisa Grigore)\n- hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (Wilken Gottwalt)\n- tls: don't abort the connection on signal-interrupted sends (Maximilian Immanuel Brandtner)\n- sctp: clear control chunk transport if it is being removed (Xin Long)\n- ata: pata_sl82c105: fix bridge revision use-after-free (Hongyan Xu)\n- net: thunderbolt: Tear down DMA paths before stopping the rings (Fan XinRan)\n- net: qrtr: ns: Raise lookup limit to 128 (Lukasz Patron)\n- net/smc: fix TOCTOU race between smc_listen_out() and listener close (Sidraya Jayagond)\n- net: remove WARN_ON_ONCE() from sk_mc_loop() (Eric Dumazet)\n- net: prestera: validate firmware header length (Pengpeng Hou)\n- net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (Henry Martin)\n- tcp: fix TFO max_qlen accounting across reuseport migration (Jiayuan Chen)\n- sctp: fix addip_serial increment on ASCONF_ACK allocation failure (Qing Luo)\n- bnxt_en: Fix PTP PPS setting bug (Keegan Freyhof)\n- bnxt_en: Disable EOP for TPA on all chips to prevent data corruption (Michael Chan)\n- bnxt_en: Do not set EOP on RX AGG BDs on 5760X chips (Michael Chan)\n- selftests/ftrace: refactor eprobes test to fix argument checks (Martin Kaiser)\n- selftests/ftrace: Add test case for GRP/ only input (Linyu Yuan)\n- net/openvswitch: check Ethernet header length in key_extract() (Cen Zhang (Microsoft))\n- net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter (Toke Hoiland-Jorgensen)\n- udp: fix potential use-after-free in tunnel segmentation (Xuanqiang Luo)\n- vhost/vdpa: reject overflowing PA map page counts on 32-bit (Yousef Alhouseen)\n- counter: microchip-tcb-capture: Fix DT channel validation (Babanpreet Singh)\n- net/mlx5: fw_tracer, return NULL on create error (Michael Guralnik)\n- net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete (Jiawen Liu)\n- net/sched: cls_route: fix fastmap use-after-free on filter (Jamal Hadi Salim)\n- net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() (Mahanta Jambigi)\n- bpf: Preserve pointer state for commuted arithmetic (Yiyang Chen)\n- bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor (Xiang Mei (Microsoft))\n- ARM: npcm: Fix OF node refcount leaks in SMP setup (Yuho Choi)\n- NFS: Pin the 'struct nfs_server' during a FREE_STATEID call (Anna Schumaker)\n- nfs4: take a reference on the nfs_client when running FREE_STATEID (Scott Mayhew)\n- s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() (Harald Freudenberger)\n- mount: honour SB_NOUSER in the new mount API (Al Viro)\n- gpio: pch: use raw_spinlock_t for the register lock (Junjie Cao)\n- firmware: stratix10-svc: fix memory leaks and list corruption bugs (Tze Yee Ng)\n- net: openvswitch: fix skb leak on flow key update failure during recirculation (Ilya Maximets)\n- mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (Kiryl Shutsemau (Meta))\n- HID: logitech-dj: Fix maxfield check in DJ short report validation (HyeongJun An)\n- drm/vmwgfx: bound DMA command body size against suffix pointer (Zack Rusin)\n- drm/vmwgfx: validate DRAW_PRIMITIVES header size before division (Zack Rusin)\n- drm/amdgpu: cap GTT size to physical RAM on APUs (Harkirat Gill)\n- drm/amdgpu: restore UMD profile pstate after runtime resume (Candice Li)\n- drm/vc4: Zero the tile state data array before each BIN job (Maira Canal)\n- can: peak_usb: validate uCAN receive record lengths (Pengpeng Hou)\n- can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error (Maoyi Xie)\n- can: peak_usb: add bounds check for USB channel index (James Gao)\n- can: softing: fw_parse(): validate firmware record spans (Pengpeng Hou)\n- can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents (Pengpeng Hou)\n- can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() (Abdun Nihaal)\n- can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer (Oleksij Rempel)\n- can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure (Guangshuo Li)\n- can: ems_usb: validate CPC message lengths (Pengpeng Hou)\n- can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured (Lucas Martins Alves)\n- i2c: imx: Cancel hrtimer before clearing slave pointer (Liem)\n- i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock (H. Nikolaus Schaller)\n- net: openvswitch: fix skb leak on flow key update failure during ct (Ilya Maximets)\n- net: openvswitch: fix potential UAF on meter attach failure (Ilya Maximets)\n- phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB (Nava kishore Manne)\n- phy: zynqmp: use read-modify-write for SERDES scrambler bypass (Nava kishore Manne)\n- phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask (Nava kishore Manne)\n- s390/zcrypt: Validate length for CCA ECC private key requests (Holger Dengler)\n- s390/zcrypt: Validate length for CCA AES cipher key requests (Holger Dengler)\n- s390/dasd: Fix potential NULL pointer dereference (Jan Hoppner)\n- s390/qeth: Check CAP_NET_ADMIN for private ioctls (Aswin Karuvally)\n- cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() (Abdun Nihaal)\n- i2c: amd-mp2: Unregister callback on adapter add failure (Myeonghun Pak)\n- hwmon: (npcm750-pwm-fan): stop fan timer on device detach (Hongyan Xu)\n- sctp: prevent peer transport count overflow (Asim Viladi Oglu Manizada)\n- sctp: reject stale cookies with mismatched verification tags (Yuxiang Yang)\n- selftests/clone3: fix wild pointer access of getline due to missing init (Chris Gellermann)\n- tracing/filters: Fix false positive match in regex_match_full() (Masami Hiramatsu (Google))\n- tracing: Check return value of __register_event() in trace_module_add_events() (Masami Hiramatsu (Google))\n- vxlan: use pskb_network_may_pull() in route_shortcircuit() (Eric Dumazet)\n- vxlan: use neigh_ha_snapshot() in route_shortcircuit() (Eric Dumazet)\n- vxlan: unclone skb head before modifying eth header in route_shortcircuit() (Eric Dumazet)\n- vxlan: re-fetch eth header after route_shortcircuit() (Eric Dumazet)\n- um: vector: fix use-after-free in vector_mmsg_rx() (Michael Bommarito)\n- powerpc/ps3: Fix map failure path in dma_ioc0_map_pages() (Thorsten Blum)\n- net: ipv6: clear suppressed fib6 rule result (Zhiling Zou)\n- net: bridge: stop fast-leave after deleting a port group (Zhiling Zou)\n- mm/page_reporting: use system_freezable_wq to fix UAF during suspend (Link Lin)\n- binfmt_misc: reject a flag character as the field delimiter (Christian Brauner)\n- wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (Zhao Li)\n- tipc: avoid use-after-free in poll trace queue dumps (Zihan Xi)\n- netfilter: ipset: do not update comments from kernel-side hash adds (David Lee)\n- net/smc: fix socket use-after-free during link group termination (Xuanqiang Luo)\n- ipvs: do not propagate one-packet flag to synced conns (Zhiling Zou)\n- igbvf: Fix leak in TX DMA error cleanup (Matt Vollrath)\n- e1000: fix memory leak in e1000_probe() (Dawei Feng)\n- dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ (Md Sadre Alam)\n- ALSA: usb-audio: Clamp frame size in implicit-feedback mode (Sonali Pradhan)\n- ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set (Sonali Pradhan)\n- ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() (Baul Lee)\n- ASoC: tas2562: fix broken entries in the volume lookup table (Haidar Lee)\n- ASoC: tas2562: fix DVC coefficient write order (Haidar Lee)\n- ALSA: pcm: wake linked drain waiters on unlink (Norbert Szetei)\n- ALSA: lx6464es: fix period byte count for 16-bit streams (Xu Rao)\n- ALSA: 6fire: Fix UAF at error handling during probe (Takashi Iwai)\n- bpf: lwt: Fix dst reference leak on reroute failure (Xuanqiang Luo)\n- Bluetooth: HIDP: validate numbered report payloads (Sangho Lee)\n- Bluetooth: HIDP: reject frames without a transaction header (Sangho Lee)\n- audit: fix potential use-after-free in audit_del_rule() (Luxiao Xu)\n- audit: fix potential integer overflow in audit_log_n_string() (Zhan Xusheng)\n- sctp: validate Adaptation Indication parameter length (Charles Vosburgh)\n- mm/hugetlb: fix list corruption in allocate_file_region_entries() (Xiangfeng Cai)\n- mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() (Zi Yan)\n- pinctrl: bm1880: add missing select GENERIC_PINCONF (Benjamin Boortz)\n- pinctrl: devicetree: don't free uninitialized dev_name on error path (Karl Mehltretter)\n- rhashtable: clear stale iter-p on table restart (Cen Zhang (Microsoft))\n- qede: sync udp_tunnel ports outside qede_lock in the recovery path (Denis V. Lunev)\n- octeontx2-pf: Set correct sequence for carrier off and tx queue stop (Suman Ghosh)\n- tracing/mmiotrace: Reset dropped_count in mmio_reset_data() (Masami Hiramatsu (Google))\n- can: isotp: check register_netdevice_notifier() error in module init (Minhong He)\n- net: sxgbe: check descriptor ring allocation failures (Chenguang Zhao)\n- net: sxgbe: free TX rings on RX allocation failure (Chenguang Zhao)\n- scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req (Benjamin Block)\n- net: phylink: put link_gpio if phylink_create fails (Christian Marangi)\n- Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp (Jiale Yao)\n- hwmon: (pmbus) Fix return value from pmbus_update_byte_data() (Guenter Roeck)\n- wifi: mac80211: validate individual TWT params before driver setup (Zhao Li)\n- powerpc/boot: Fix treeboot-akebono CPU node lookup check (Thorsten Blum)\n- powerpc/boot: Fix treeboot-currituck CPU node lookup check (Thorsten Blum)\n- powerpc/boot: Fix simpleboot CPU node lookup check (Thorsten Blum)\n- hwmon: (adt7470) Fix PWM auto temp state array and bounds check (Luiz Angelo Daros de Luca)\n- hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read (Luiz Angelo Daros de Luca)\n- hwmon: (adt7470) Use cached PWM frequency value (Luiz Angelo Daros de Luca)\n- hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks (Luiz Angelo Daros de Luca)\n- hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() (Luiz Angelo Daros de Luca)\n- hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread (Luiz Angelo Daros de Luca)\n- hwmon: (adt7470) Fix cache updated before hardware write on I2C error (Luiz Angelo Daros de Luca)\n- hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors (Luiz Angelo Daros de Luca)\n- forcedeth: fix UAF of txrx_stats in nv_remove (Chenguang Zhao)\n- net: bridge: mrp: fix Option TLV length in MRP_Test frames (David Corvaglia)\n- hwmon: (nct6775-core) Prevent access to unsupported weight registers (Guenter Roeck)\n- smb: client: fix buffer leaks in SMB1 read and write (Dawei Feng)\n- scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (HyeongJun An)\n- scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer (HyeongJun An)\n- netfilter: nft_payload: fix mask build for partial field offload (Xiang Mei (Microsoft))\n- netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH (Pablo Neira Ayuso)\n- assoc_array: trim the final shortcut word using the current chunk end (Michael Bommarito)\n- keys: make keyring key-chunk byte order agree with keyring_diff_objects() (Michael Bommarito)\n- keys: fix out-of-bounds read in keyring_get_key_chunk() (Michael Bommarito)\n- drm/mediatek: Check CRTC state before freeing (Ruoyu Wang)\n- netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (Xiang Mei)\n- phy: zynqmp: fix runtime PM leak on probe allocation failure (Radhey Shyam Pandey)\n- phy: zynqmp: fix clock error handling in xpsgtr_phy_init() (Radhey Shyam Pandey)\n- phy-zynqmp: Postpone getting clock rate until actually needed (Mike Looijmans)\n- phy: zynqmp: Allow variation in refclk rate (Sean Anderson)\n- ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare)\n- ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare)\n- dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA (Hongling Zeng)\n- tls: separate no-async decryption request handling from async (Sabrina Dubroca)\n- net: qrtr: ns: Raise node count limit to 512 (Youssef Samir)\n- net: qrtr: ns: Limit the maximum server registration per node (Manivannan Sadhasivam)\n- HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (Benjamin Tissoires)\n- HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (Lee Jones)\n- HID: logitech-dj: Standardise hid_report_enum variable nomenclature (Lee Jones)\n- gve: fix Rx queue stall on alloc failure (Eddie Phillips)\n- media: uvcvideo: Fix sequence number when no EOF (Ricardo Ribalda)\n- media: uvcvideo: Implement dual stream quirk to fix loss of usb packets (Isaac Scott)\n- net: mpls: initialize rtm_tos in mpls_getroute() (Yehyeong Lee)\n- raw: fix a typo in raw_icmp_error() (Eric Dumazet)\n- raw: remove unused variables from raw6_icmp_error() (Eric Dumazet)\n- openvswitch: fix GSO userspace truncation underflow (Kyle Zeng)\n- wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses (Devin Wittmayer)\n- tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (Weiming Shi)\n- drm/amdgpu: invoke pm_genpd_remove() before freeing genpd (Ce Sun)\n- drm/amdgpu: fix division by zero with invalid uvd dimensions (Boyuan Zhang)\n- drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (Alex Deucher)\n- drm/amdgpu/gfx8: drop unecessary BUG_ON() (Alex Deucher)\n- drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() (Alex Deucher)\n- tipc: clear sock-sk on the failed-insert path in tipc_sk_create() (Daehyeon Ko)\n- pppoe: reload header pointer after dev_hard_header() (Asim Viladi Oglu Manizada)\n- mac802154: llsec: reject frames shorter than the authentication tag (Doruk Tan Ozturk)\n- ila: reload IPv6 header after pskb_may_pull in checksum adjust (Michael Bommarito)\n- ice: use READ_ONCE() to access cached PHC time (Sergey Temerkhanov)\n- rbd: Reset positive result codes to zero in object map update path (Raphael Zimmer)\n- proc: Fix broken error paths for namespace links (Jann Horn)\n- net: hip04: fix RX buffer leak on build_skb failure (Fan Wu)\n- net/x25: fix use-after-free in x25_kill_by_neigh() (David Lee)\n- net/iucv: fix use-after-free of a severed iucv_path (Bryam Vargas)\n- net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() (Hidayath Khan)\n- geneve: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk)\n- net: slip: serialize receive against buffer reallocation (Sungmin Kang)\n- vxlan: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk)\n- phonet: pep: fix use-after-free in pep_get_sb() (Breno Leitao)\n- iommu/vt-d: Disallow SVA if page walk is not coherent (Lu Baolu)\n- binfmt_elf_fdpic: only honour the first PT_INTERP (Christian Brauner)\n- libceph: remove debugfs files before client teardown (Douya Le)\n- libceph: reject zero bucket types in crush_decode (Douya Le)\n- libceph: Reject monmaps advertising zero monitors (Raphael Zimmer)\n- libceph: refresh auth-authorizer_buf{,_len} after authorizer update (Shuangpeng Bai)\n- libceph: guard missing CRUSH type name lookup (Zhao Zhang)\n- libceph: Fix multiplication overflow in decode_new_up_state_weight() (Raphael Zimmer)\n- libceph: bound get_version reply decode to front len (Douya Le)\n- ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (Bryam Vargas)\n- mptcp: only set DATA_FIN when a mapping is present (Michael Bommarito)\n- Revert 'arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates' (Will Deacon)\n- arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates (Will Deacon)\n- tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() (Masami Hiramatsu (Google))\n- tracing/probes: Fix potential underflow in LEN_OR_ZERO macro (Masami Hiramatsu (Google))\n- tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args() (Masami Hiramatsu (Google))\n- tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() (Masami Hiramatsu (Google))\n- tracing: Fix resource leak on mmiotrace trace_pipe close (deepakraog)\n- tracing: Fix mmiotrace possible NULL dereferencing of hiter-dev (Steven Rostedt)\n- intel_th: fix MSC output device reference leak (Guangshuo Li)\n- comedi: comedi_parport: deal with premature interrupt (Ian Abbott)\n- x86/boot/compressed: Disable jump tables (Nathan Chancellor)\n- cdrom: fix stack out-of-bounds read in CDROMVOLCTRL (Xu Rao)\n- binfmt_misc: set have_execfd only once the interpreter is opened (Christian Brauner)\n- exec: fix unsigned loop counter wrap in transfer_args_to_stack() (Christian Brauner)\n- Bluetooth: RFCOMM: Fix session UAF in set_termios (Chengfeng Ye)\n- staging: rtl8723bs: fix inverted HT40 secondary channel offset (MinJea Kim)\n- staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() (Moksh Panicker)\n- wifi: brcmfmac: make release_scratchbuffers idempotent (Fan Wu)\n- wifi: wilc1000: validate assoc response length before subtracting header (Huihui Huang)\n- wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper (Doruk Tan Ozturk)\n- wifi: ath6kl: fix OOB access from firmware ADDBA window size (Tristan Madani)\n- media: vivid: check for vb2_is_busy() when toggling caps (Hans Verkuil)\n- media: vimc: fix reference leak on failed device registration (Guangshuo Li)\n- media: vidtv: fix reference leak on failed device registration (Guangshuo Li)\n- media: vb2: use ssize_t for vb2_read/vb2_write (Zile Xiong)\n- media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() (Sergey Shtylyov)\n- media: tegra-video: vi: fix invalid u32 return value in format lookup (Hungyu Lin)\n- media: sun4i-csi: Return queued buffers on start_streaming() failure (Valery Borovsky)\n- media: saa7134: Fix a possible memory leak in saa7134_video_init1 (Ma Ke)\n- media: rtl2832_sdr: Return queued buffers on start_streaming() failure (Valery Borovsky)\n- media: rtl2832: fix use-after-free in rtl2832_remove() (Deepanshu Kartikey)\n- media: radio-si476x: Unregister v4l2_device on probe failure (Myeonghun Pak)\n- media: pwc: Return queued buffers on start_streaming() failure (Valery Borovsky)\n- media: pwc: Drain fill_buf on start_streaming() failure (Valery Borovsky)\n- media: pci: dm1105: Free allocated workqueue (Krzysztof Kozlowski)\n- media: msi2500: Return queued buffers on start_streaming() failure (Valery Borovsky)\n- media: meson: vdec: Fix memory leak in error path of vdec_open (Anand Moon)\n- media: cx23885: add ioremap return check and cleanup (Wang Jun)\n- media: cx231xx: fix devres lifetime (Johan Hovold)\n- media: cedrus: skip invalid H.264 reference list entries (Pengpeng Hou)\n- media: cedrus: Fix missing cleanup in error path (Samuel Holland)\n- media: cedrus: clean up media device on probe failure (Myeonghun Pak)\n- media: cec: seco: unregister adapter on IR probe failure (Myeonghun Pak)\n- media: airspy: Return queued buffers on start_streaming() failure (Valery Borovsky)\n- drm/vmwgfx: Validate vmw_surface_metadata::array_size (Ian Forbes)\n- drm/amdgpu: fix bo-pin leaking in amdgpu_bo_create_reserved (Zhu Lingshan)\n- drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) (Timur Kristof)\n- drm/amdgpu: Fix VFCT bus number matching with soft filter (Mario Limonciello)\n- drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (Joonas Lahtinen)\n- drm/i915/gem: Do not leak siblings[] on proto context error (Joonas Lahtinen)\n- drm/i915: Return NULL on error in active_instance (Joonas Lahtinen)\n- drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() (Alex Deucher)\n- drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() (Alex Deucher)\n- drm/radeon: fix r100_copy_blit for large BOs (Pavel Ondracka)\n- drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (Wentao Liang)\n- drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (Sergey Shtylyov)\n- can: bcm: track a single source interface for ANYDEV timeout/throttle ops (Oliver Hartkopp)\n- can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() (Oliver Hartkopp)\n- can: bcm: fix stale rx/tx ops after device removal (Oliver Hartkopp)\n- can: bcm: add missing device refcount for CAN filter removal (Oliver Hartkopp)\n- can: bcm: validate frame length in bcm_rx_setup() for RTR replies (Oliver Hartkopp)\n- can: bcm: extend bcm_tx_lock usage for data and timer updates (Oliver Hartkopp)\n- can: bcm: fix CAN frame rx/tx statistics (Oliver Hartkopp)\n- can: bcm: add locking when updating filter and timer values (Oliver Hartkopp)\n- can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (Lee Jones)\n- bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (Chengfeng Ye)\n- net: ipv6: fix dif and sdif mismatch in raw6_icmp_error (Li RongQing)\n- raw: use more conventional iterators (Eric Dumazet)\n- net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation (Alexei Lazar)\n- net/mlx5e: Report zero bandwidth for non-ETS traffic classes (Alexei Lazar)\n- net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule (Yael Chemla)\n- net: qrtr: restrict socket creation to the initial network namespace (Aldo Ariel Panzardo)\n- hinic: remove unused ethtool RSS user configuration buffers (Chenguang Zhao)\n- ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup (Eric Dumazet)\n- octeontx2-vf: set TC flower flag on MCAM entry allocation (Suman Ghosh)\n- net: stmmac: reset residual action in L3L4 filters on delete (Nazim Amirul)\n- net: stmmac: fix l3l4 filter rejecting unsupported offload requests (Nazim Amirul)\n- net: stmmac: add tc flower filter for EtherType matching (Ong Boon Leong)\n- tipc: fix u16 MTU truncation in media and bearer MTU validation (Cen Zhang (Microsoft))\n- vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (Harshaka Narayana)\n- sctp: auth: verify auth requirement when auth_chunk is NULL (Qing Luo)\n- net: hsr: fix memory leak on slave unregistration by removing synced VLANs (Eric Dumazet)\n- net: bridge: vlan: fix vlan range dumps starting with pvid (Nikolay Aleksandrov)\n- wifi: brcmfmac: fix 802.1X-SHA256 call trace warning (Shelley Yang)\n- wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() (Lorenzo Bianconi)\n- tipc: fix infinite loop in __tipc_nl_compat_dumpit (Helen Koike)\n- nexthop: initialize extack in nh_res_bucket_migrate() (Xiang Mei (Microsoft))\n- sctp: validate stream count in sctp_process_strreset_inreq() (Cen Zhang (Microsoft))\n- sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (HanQuan)\n- amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN (Prashanth Kumar KR)\n- wifi: mac80211: recalculate TIM when a station enters power save (Andrew Pope)\n- iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (Li RongQing)\n- iommu/amd: Bound the early ACPI HID map (Pengpeng Hou)\n- wifi: mwifiex: bound uAP association event IEs to the event buffer (HE WEI (???))\n- wan: wanxl: Only reset hardware after BAR mapping (Ruoyu Wang)\n- nfp: Check resource mutex allocation (Ruoyu Wang)\n- dpaa2-eth: put MAC endpoint device on disconnect (Guangshuo Li)\n- net: dpaa2-eth: assign priv-mac after dpaa2_mac_connect() call (Vladimir Oltean)\n- dpaa2-switch: put MAC endpoint device on disconnect (Guangshuo Li)\n- net/packet: avoid fanout hook re-registration after unregister (David Lee)\n- hwmon: occ: validate poll response sensor blocks (Pengpeng Hou)\n- hwmon: (occ) Delay hwmon registration until user request (Eddie James)\n- hwmon: (occ) Add sysfs entries for additional extended status bits (Eddie James)\n- hwmon: (occ) Add sysfs entry for OCC mode (Eddie James)\n- hwmon: (occ) Add sysfs entry for IPS (Idle Power Saver) status (Eddie James)\n- usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect (Diego Fernando Mancera Gomez)\n- ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI (Shengjiu Wang)\n- ASoC: bt-sco: fix bt-sco-pcm-wb dai widget don't connect to the endpoint (Jiaxin Yu)\n- btrfs: free mapping node on duplicate reloc root insert (Guanghui Yang)\n- wifi: carl9170: fix buffer overflow in rx_stream failover path (Tristan Madani)\n- wifi: carl9170: fix OOB read from off-by-two in TX status handler (Tristan Madani)\n- wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read (Tristan Madani)\n- wifi: ath6kl: fix OOB read from firmware IE lengths in connect event (Tristan Madani)\n- wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler (Tristan Madani)\n- firewire: net: Fix fragmented datagram reassembly (Ruoyu Wang)\n- wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() (Dmitry Morgun)\n- watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() (Tzung-Bi Shih)\n- hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop (Guenter Roeck)\n- hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop (Edward Adam Davis)\n- wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (Cheng Yongkang)\n- usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits (Xincheng Zhang)\n- bpf: Fix ld_{abs,ind} failure path analysis in subprogs (Daniel Borkmann)\n- Revert 'drm/amd/display: Add missing kdoc for ALLM parameters' (Sasha Levin)\n- crypto: rsa-pkcs1pad: Don't WARN on an empty digest (Doruk Tan Ozturk)\n- USB: serial: option: add TDTECH MT5710-CN (Chukun Pan)\n- USB: serial: keyspan_pda: fix data loss on receive throttling (Johan Hovold)\n- USB: serial: io_edgeport: cap received transmit credits (Sunho Park)\n- USB: serial: ftdi_sio: add support for E+H FXA291 (Tim Pambor)\n- usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer (Muhammad Bilal)\n- usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown (Fan Wu)\n- usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() (Sonali Pradhan)\n- USB: gadget: fsl-udc: fix device name leak on probe failure (Johan Hovold)\n- USB: gadget: snps-udc: fix device name leak on probe failure (Johan Hovold)\n- usb: gadget: printer: fix infinite loop in printer_read() (Melbin K Mathew)\n- usb: gadget: f_midi: cancel pending IN work before freeing the midi object (Fan Wu)\n- usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback (Jinchao Wang)\n- usb: chipidea: fix usage_count leak when autosuspend_delay is negative (Xu Yang)\n- USB: storage: add NO_ATA_1X quirk for Longmai USB Key (Huang Wei)\n- wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() (Huihui Huang)\n- mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (Weiming Shi)\n- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long)\n- net/sched: act_tunnel_key: Defer dst_release to RCU callback (Jamal Hadi Salim)\n- drm/i915/selftests: Fix GT PM sort comparators (Emre Cecanpunar)\n- ksmbd: validate compound request size before reading StructureSize2 (Xiang Mei (Microsoft))\n- can: j1939: fix lockless local-destination check (Shuhao Fu)\n- powerpc/vtime: Initialize starttime at boot for native accounting (Shrikanth Hegde)\n- powerpc/time: Prepare to stop elapsing in dynticks-idle (Frederic Weisbecker)\n- sched/vtime: Get rid of generic vtime_task_switch() implementation (Alexander Gordeev)\n- powerpc: remove the last remnants of cputime_t (Nicholas Piggin)\n- powerpc/time: Fix sparse warnings (He Ying)\n- drm/i915/gt: use correct selftest config symbol (Pengpeng Hou)\n- smb/client: handle overlapping allocated ranges in fallocate (Huiwen He)\n- Bluetooth: qca: fix NVM tag length underflow in TLV parser (Xiang Mei)\n- ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (Takashi Iwai)\n- ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning (Rosen Penev)\n- ata: sata_dwc_460ex: remove variable num_processed (Colin Ian King)\n- ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts (Rosen Penev)\n- ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered (Rosen Penev)\n- net/iucv: take a reference on the socket found in afiucv_hs_rcv() (Bryam Vargas)\n- ipv4: fib: free fib_alias with kfree_rcu() on insert error path (Weiming Shi)\n- ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (Norbert Szetei)\n- firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context (Pushpendra Singh)\n- ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (Uday Khare)\n- ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (Christian Hewitt)\n- wifi: cfg80211: bound element ID read when checking non-inheritance (HE WEI (???))\n- wifi: brcmfmac: initialize SDIO data work before cleanup (Runyu Xiao)\n- wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (Cen Zhang)\n- wifi: cfg80211: reject unsupported PMSR FTM location requests (Zhao Li)\n- wifi: cfg80211: validate PMSR FTM preamble range (Zhao Li)\n- wifi: cfg80211: validate PMSR measurement type data (Zhao Li)\n- wifi: p54: validate RX frame length in p54_rx_eeprom_readback() (Xiang Mei)\n- wifi: libertas: fix memory leak in helper_firmware_cb() (Dawei Feng)\n- wifi: mac80211_hwsim: clamp virtio RX length before skb_put (Bryam Vargas)\n- wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (Abdun Nihaal)\n- wifi: cfg80211: cancel sched scan results work on unregister (Cen Zhang)\n- xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert (Xiang Mei (Microsoft))\n- RDMA/irdma: Prevent overflows in memory contiguity checks (Aleksandrova Alyona)\n- RDMA/siw: publish QP after initialization (Ruoyu Wang)\n- RDMA/siw: Only check attrs-cap.max_send_wr in siw_create_qp (Guoqing Jiang)\n- RDMA/hns: Fix potential integer overflow in mhop hem cleanup (Danila Chernetsov)\n- firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (Unnathi Chalicheemala)\n- btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (Filipe Manana)\n- btrfs: reject free space cache with more entries than pages (Xiang Mei)\n- mtd: nand: mtk-ecc: stop on ECC idle timeouts (Pengpeng Hou)\n- mtd: mtdswap: remove debugfs stats file on teardown (Pengpeng Hou)\n- IB/mad: Drop unmatched RMPP responses before reassembly (Michael Bommarito)\n- KVM: VMX: Make vmread_error_trampoline() uncallable from C code (Sean Christopherson)\n- Input: ims-pcu - fix logic error in packet reset (Dmitry Torokhov)\n- Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (Seungjin Bae)\n- dmaengine: sh: rz-dmac: Move interrupt request after everything is set up (Claudiu Beznea)\n- can: isotp: serialize TX state transitions under so-rx_lock (Oliver Hartkopp)\n- can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER (Oliver Hartkopp)\n- KVM: x86/mmu: Fix use-after-free on vendor module reload (Phil Rosenthal)\n- KVM: nVMX: Hide shadow VMCS right after VMCLEAR (Hyunwoo Kim)\n- macsec: don't read an unset MAC header in macsec_encrypt() (Daehyeon Ko)\n- futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (Sebastian Andrzej Siewior)\n- nvmet-tcp: Fix potential UAF when ddgst mismatch (Sagi Grimberg)\n\n[5.15.0-324.213.5]\n- Revert 'rseq: Introduce feature size and alignment ELF auxiliary vector entries' (Prakash Sangappa) [Orabug: 39874250]\n\n[5.15.0-324.213.4]\n- Enable Time slice extension (Prakash Sangappa) [Orabug: 39047421]\n- rseq: Increase struct rseq size to match mainline linux (Prakash Sangappa) [Orabug: 39047421]\n- rseq: Introduce extensible rseq ABI (Prakash Sangappa) [Orabug: 39047421]\n- rseq: Introduce feature size and alignment ELF auxiliary vector entries (Mathieu Desnoyers) [Orabug: 39047421]\n- Update AT_VA_RESERVATION number (Prakash Sangappa) [Orabug: 39047421]\n- selftests/rseq: Make registration flexible for legacy and optimized mode (Thomas Gleixner) [Orabug: 39047421]\n- selftests/rseq: Skip tests if time slice extensions are not available (Thomas Gleixner) [Orabug: 39047421]\n- rseq: Don't advertise time slice extensions if disabled (Thomas Gleixner) [Orabug: 39047421]\n- selftests/rseq: Add rseq slice histogram script (Peter Zijlstra) [Orabug: 39047421]\n- rseq: Lower default slice extension (Peter Zijlstra) [Orabug: 39047421]\n- rseq: Move slice_ext_nsec to debugfs (Peter Zijlstra) [Orabug: 39047421]\n- rseq: Allow registering RSEQ with slice extension (Peter Zijlstra) [Orabug: 39047421]\n- selftests/rseq: Implement time slice extension test (Thomas Gleixner) [Orabug: 39047421]\n- entry: Hook up rseq time slice extension (Thomas Gleixner) [Orabug: 39047421]\n- rseq: Implement rseq_grant_slice_extension() (Thomas Gleixner) [Orabug: 39047421]\n- rseq: Reset slice extension when scheduled (Thomas Gleixner) [Orabug: 39047421]\n- rseq: Implement time slice extension enforcement timer (Prakash Sangappa) [Orabug: 39047421]\n- rseq: Implement syscall entry work for time slice extensions (Thomas Gleixner) [Orabug: 39047421]\n- rseq: Implement sys_rseq_slice_yield() (Thomas Gleixner) [Orabug: 39047421]\n- rseq: Add prctl() to enable time slice extensions (Thomas Gleixner) [Orabug: 39047421]\n- rseq: Add statistics for time slice extensions (Thomas Gleixner) [Orabug: 39047421]\n- rseq: Provide static branch for runtime debugging (Thomas Gleixner) [Orabug: 39047421]\n- rseq: Expose lightweight statistics in debugfs (Thomas Gleixner) [Orabug: 39047421]\n- rseq: Provide static branch for time slice extensions (Thomas Gleixner) [Orabug: 39047421]\n- rseq: Add fields and constants for time slice extension (Thomas Gleixner) [Orabug: 39047421]\n- sched/fair: Disable affine wakeups at NUMA domain levels on Exadata (Daniel Jordan) [Orabug: 38770281]\n- drivers/soc/pensando/penfw: Added attest_meas and get cert_chain to penfw_util (Rahshekh) [Orabug: 39818086]\n- drivers/soc/pensando/penfw_sysfs: fix bl31_show vers buffer size (Rahshekh) [Orabug: 39818086]\n- mmc: core: Use HPI to interrupt lengthy cache flush (#494) (Brad Larson) [Orabug: 39818086]\n- xen/ovmapi: terminate values passed to xenbus_write (Joe Jin) [Orabug: 39851069]\n- xen/ovmapi: free queued events on release (Joe Jin) [Orabug: 39851069]\n- xen/ovmapi: prevent duplicate app registration (Joe Jin) [Orabug: 39851069]\n- xen/ovmapi: avoid raw user pointer access in get_next_event (Joe Jin) [Orabug: 39851069]\n- xen/ovmapi: reject oversized posted event payloads (Joe Jin) [Orabug: 39851069]\n- IB/rxe: use rxe_drop_ref to release rxe_pd (Wengang Wang) [Orabug: 39831970]\n- IB/uverbs: enhance authorization checks for ib_uverbs_share_pd() (Wengang Wang) [Orabug: 39831970]\n- net/rds: restrict RDS_INFO dumps to caller netns (Praveen Kumar Kannoju) [Orabug: 39832021]\n- rds: tcp: fix uninit-value in __inet_bind (Tabrez Ahmed) [Orabug: 39668599]\n- rds: tcp: cleanup if kmem_cache_alloc fails in rds_tcp_conn_alloc() (Sowmini Varadhan) [Orabug: 39668599]\n- Revert 'x86/alternatives: Add alt_instr.flags' (Harshit Mogalapalli) [Orabug: 39864327]\n- KVM: x86/mmu: Stop needlessly making MMU pages available for TDP MMU faults (David Matlack) [Orabug: 39830590] {CVE-2026-64561}\n- KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Sean Christopherson) [Orabug: 39830590,39832946] {CVE-2026-64561}\n- KVM: x86/mmu: Rename __direct_map() to direct_map() (David Matlack) [Orabug: 39830590] {CVE-2026-64561}\n- KVM: x86/mmu: Split out TDP MMU page fault handling (David Matlack) [Orabug: 39830590] {CVE-2026-64561}\n- KVM: Rename mmu_notifier_* to mmu_invalidate_* (Chao Peng) [Orabug: 39830590] {CVE-2026-64561}\n- KVM: x86/mmu: Document the 'rules' for using host_pfn_mapping_level() (Sean Christopherson) [Orabug: 39830590] {CVE-2026-64561}\n- KVM: x86/mmu: Rename pte_list_{destroy,remove}() to show they zap SPTEs (Sean Christopherson) [Orabug: 39830590] {CVE-2026-64561}\n- KVM: x86/mmu: Directly 'destroy' PTE list when recycling rmaps (Sean Christopherson) [Orabug: 39830590] {CVE-2026-64561}\n- x86/bugs: Make Safe-RET robust against interrupt injection (Borislav Petkov) [Orabug: 39784615,39853775] {CVE-2026-68480}\n- x86/alternatives: Disable interrupts and sync when optimizing NOPs in place (Thomas Gleixner) [Orabug: 39784615] {CVE-2026-68480}\n- x86/alternative: Support relocations in alternatives (Peter Zijlstra) [Orabug: 39784615] {CVE-2026-68480}\n- x86/alternative: Make debug-alternative selective (Peter Zijlstra) [Orabug: 39784615] {CVE-2026-68480}\n- x86/alternatives: Add alt_instr.flags (Borislav Petkov) [Orabug: 39784615] {CVE-2026-68480}\n- x86/asm: Provide ALTERNATIVE_3 (Peter Zijlstra) [Orabug: 39784615] {CVE-2026-68480}\n\n[5.15.0-324.213.3]\n- LTS version: v5.15.213 (Vijayendra Suman)\n- posix-cpu-timers: Prevent UAF caused by non-leader exec() race (Thomas Gleixner) [Orabug: 39807438] {CVE-2026-64560}\n- LTS version: v5.15.212 (Vijayendra Suman)\n- perf/x86/amd/core: Always use the NMI latency mitigation (Sandipan Das)\n- ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (Hyeongjun An) [Orabug: 39853280] {CVE-2026-64479}\n- iio: imu: inv_icm42600: fix timestamp clock period by using lower value (Jean-Baptiste Maneyrol)\n- ALSA: seq: Check UMP support for midi_version change (Takashi Iwai)\n- ALSA: seq: Skip event type filtering for UMP events (Takashi Iwai)\n- iio: invensense: fix odr switching to same value (Jean-Baptiste Maneyrol)\n- iio: imu: inv_mpu6050: fix frequency setting when chip is off (Jean-Baptiste Maneyrol)\n- ALSA: seq: Avoid confusion of aligned read size (Takashi Iwai)\n- Bluetooth: L2CAP: Fix regressions caused by reusing ident (Luiz Augusto von Dentz)\n- KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers (Marc Zyngier)\n- posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu() (Zhan Xusheng)\n- regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() (Xu Wang)\n- audit: fix potential integer overflow in audit_log_n_hex() (Ricardo Robaina)\n- audit: add audit_log_nf_skb helper function (Ricardo Robaina)\n- btrfs: fix incorrect buffered IO fallback for append direct writes (Qu Wenruo)\n- crypto: qat - validate RSA CRT component lengths (Giovanni Cabiddu) [Orabug: 39785885] {CVE-2026-64304}\n- btrfs: fix false IO failure after falling back to buffered write (Qu Wenruo)\n- crypto: qat - fix restarting state leak on allocation failure (Ahsan Atta)\n- btrfs: do not trim a device which is not writeable (Qu Wenruo) [Orabug: 39843586] {CVE-2026-64593}\n- usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile (Neill Kapron)\n- crypto: atmel-sha204a - drop hwrng quality reduction for ATSHA204A (Thorsten Blum)\n- crypto: atmel - Drop explicit initialization of struct i2c_device_id::driver_data to 0 (Uwe Kleine-Konig)\n- crypto: atmel-sha204a - Mark OF related data as maybe unused (Krzysztof Kozlowski)\n- usb: gadget: f_fs: initialize reset_work at allocation time (Tyler Baker)\n- usb: typec: tcpm: Fix VDM type for Enter Mode commands (Andy Yan)\n- usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect() (Mauricio Faria de Oliveira)\n- usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (Fan Wu)\n- gpio: pca953x: Make platform teardown callback return void (Uwe Kleine-Konig)\n- leds: lm3601x: Improve error reporting for problems during .remove() (Uwe Kleine-Konig)\n- leds: lm3697: Remove duplicated error reporting in .remove() (Uwe Kleine-Konig)\n- drm/i2c/sil164: Drop no-op remove function (Uwe Kleine-Konig)\n- usb: iowarrior: remove inherent race with minor number (Oliver Neukum)\n- bpf: Allow LPM map access from sleepable BPF programs (Vlad Poenaru) [Orabug: 39786046] {CVE-2026-64352}\n- bpf: Consistently use bpf_rcu_lock_held() everywhere (Andrii Nakryiko)\n- bpf: Convert lpm_trie.c to rqspinlock (Kumar Kartikeya Dwivedi)\n- bpf: Reject fragmented frames in devmap (Zhao Zhang) [Orabug: 39786052] {CVE-2026-64355}\n- hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length (Tristan Madani)\n- hfs/hfsplus: prevent getting negative values of offset/length (Viacheslav Dubeyko)\n- xfs: use null daddr for unset first bad log block (Yousef Alhouseen)\n- xfs: Remove dead code (Jiapeng Chong)\n- xfs: Remove redundant assignment of mp (Jiapeng Chong)\n- serial: 8250_mid: Disable DMA for selected platforms (Andy Shevchenko)\n- serial: 8250_mid: Remove 8250_pci usage (Ilpo Jarvinen)\n- HID: appleir: fix UAF on pending key_up_timer in remove() (Manish Khadka) [Orabug: 39786074] {CVE-2026-64363}\n- treewide: Switch/rename to timer_delete[_sync]() (Thomas Gleixner)\n- proc: protect ptrace_may_access() with exec_update_lock (part 1) (Jann Horn) [Orabug: 39786095] {CVE-2026-64371}\n- HID: multitouch: fix out-of-bounds bit access on mt_io_flags (Trung Nguyen) [Orabug: 39786078] {CVE-2026-64364}\n- HID: add haptics page defines (Angela Czubak)\n- proc: protect ptrace_may_access() with exec_update_lock (FD links) (Jann Horn) [Orabug: 39786112] {CVE-2026-64375}\n- proc: rename proc_setattr to proc_nochmod_setattr (Christoph Hellwig)\n- proc: Move fdinfo PTRACE_MODE_READ check into the inode .permission operation (Tyler Hicks)\n- proc: use generic setattr() for /proc//net (Thomas Weissschuh)\n- X.509: Fix validation of ASN.1 certificate header (Lukas Wunner)\n- ksmbd: track the connection owning a byte-range lock (Namjae Jeon)\n- ksmbd: centralize ksmbd_conn final release to plug transport leak (Daemyung Kang)\n- ksmbd: destroy async_ida in ksmbd_conn_free() (Daemyung Kang)\n- ksmbd: fix mechToken leak when SPNEGO decode fails after token alloc (Greg Kroah-Hartman)\n- ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger (Namjae Jeon)\n- smb: client: harden POSIX SID length parsing (Zihan Xi) [Orabug: 39786128] {CVE-2026-64380}\n- smb: client: use unaligned reads in parse_posix_ctxt() (Zihan Xi)\n- smb: client: mask server-provided mode to 07777 in modefromsid (Norbert Manthey) [Orabug: 39786124] {CVE-2026-64379}\n- smb: client: resolve SWN tcon from live registrations (Michael Bommarito) [Orabug: 39786200] {CVE-2026-64401}\n- cifs: Add tracing for the cifs_tcon struct refcounting (David Howells)\n- smb: client: Fix next buffer leak in receive_encrypted_standard() (Haoxiang Li) [Orabug: 39786131] {CVE-2026-64381}\n- Bluetooth: L2CAP: cancel pending_rx_work before taking conn-lock (Runyu Xiao) [Orabug: 39760901] {CVE-2026-64206}\n- Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (Hyunwoo Kim)\n- Bluetooth: L2CAP: Fix not tracking outstanding TX ident (Luiz Augusto von Dentz)\n- netfilter: ebtables: zero chainstack array (Florian Westphal) [Orabug: 39786232] {CVE-2026-64413}\n- netfilter: ebtables: Use vmalloc_array() to improve code (Rong Qianfeng)\n- gpio: sch: use raw_spinlock_t in the irq startup path (Runyu Xiao)\n- gpio: sch: use new GPIO line value setter callbacks (Bartosz Golaszewski)\n- coresight: etb10: restore atomic_t for shared reading state (Runyu Xiao)\n- PCI: Skip Resizable BAR restore on read error (Marco Nenciarini)\n- PCI: Move Resizable BAR code to rebar.c (Ilpo Jarvinen)\n- PCI: Add kerneldoc for pci_resize_resource() (Ilpo Jarvinen)\n- PCI: Fix restoring BARs on BAR resize rollback path (Ilpo Jarvinen)\n- PCI: Free saved list without holding pci_bus_sem (Ilpo Jarvinen)\n- PCI: Prevent resource tree corruption when BAR resize fails (Ilpo Jarvinen)\n- staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() (Alexandru Hossu) [Orabug: 39786307] {CVE-2026-64441}\n- staging: rtl8723bs: fix spaces around binary operators (Nikolay Kulikov)\n- staging: rtl8723bs: core: move constants to right side in comparison (William Hansen-Baird)\n- staging: rtl8723bs: remove redundant braces in if statements (Sevinj Aghayeva)\n- staging: rtl8723bs: Remove redundant else branches. (Sevinj Aghayeva)\n- PCI: mediatek: Fix IRQ domain leak when port fails to enable (Manivannan Sadhasivam) [Orabug: 39786366] {CVE-2026-64461}\n- PCI: mediatek: Convert bool to single quirks entry and bitmap (Christian Marangi)\n- PCI: controller: Use dev_fwnode() instead of of_fwnode_handle() (Jiri Slaby)\n- staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie() (Alexandru Hossu) [Orabug: 39786327] {CVE-2026-64446}\n- staging: rtl8723bs: Fix space issues (Franziska Naepelt)\n- staging: rtl8723bs: Fix indentation issues (Franziska Naepelt)\n- PCI: imx6: Fix IMX6SX_GPR12_PCIE_TEST_POWERDOWN handling (Richard Zhu)\n- smb: client: restrict implied bcc[0] exemption to responses without data area (Shoichiro Miyamoto) [Orabug: 39786332] {CVE-2026-64448}\n- cifs: remove unused server parameter from calc_smb_size() (Enzo Matsumiya)\n- smb2: small refactor in smb2_check_message() (Enzo Matsumiya)\n- cifs: remove check of list iterator against head past the loop body (Jakob Koschel)\n- cifs: Create a new shared file holding smb2 pdu definitions (Ronnie Sahlberg)\n- PCI: altera: Fix resource leaks on probe failure (Mahesh Vaidya)\n- vfio/pci: Release the VGA arbiter client on register_device() failure (Alex Williamson) [Orabug: 39786409] {CVE-2026-64475}\n- ALSA: aoa: check snd_ctl_new1() return value (Zhao Dongdong)\n- iio: common: st_sensors: honour channel endianness in read_axis_data (Herman van Hazendonk)\n- bitops: make BYTES_TO_BITS() treewide-available (Alexander Lobakin)\n- iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading (Jean-Baptiste Maneyrol)\n- iio: imu: inv_icm42600: stabilized timestamp in interrupt (Jean-Baptiste Maneyrol)\n- iio: invensense: fix timestamp glitches when switching frequency (Jean-Baptiste Maneyrol)\n- iio: invensense: remove redundant initialization of variable period (Colin Ian King)\n- iio: imu: inv_mpu6050: use the common inv_sensors timestamp module (Jean-Baptiste Maneyrol)\n- iio: make invensense timestamp module generic (Jean-Baptiste Maneyrol)\n- iio: move inv_icm42600 timestamp module in common (Jean-Baptiste Maneyrol)\n- iio: imu: inv_icm42600: make timestamp module chip independent (Jean-Baptiste Maneyrol)\n- iio: hid-sensor-rotation: Fix stale or zero output when reading raw values (Zhang Lixu)\n- iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ (Runyu Xiao)\n- ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup (Rafael J. Wysocki) [Orabug: 39786502] {CVE-2026-64510}\n- ACPI: CPPC: Suppress UBSAN warning caused by field misuse (Jeremy Linton) [Orabug: 39786508] {CVE-2026-64512}\n- mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout (Pengpeng Hou)\n- mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout (Pengpeng Hou)\n- mtd: rawnand: fsl_ifc: return errors for failed page reads (Pengpeng Hou)\n- mmc: vub300: defer reset until cmd_mutex is unlocked (Runyu Xiao)\n- mtd: mchp23k256: use SPI match data for chip caps (Pengpeng Hou)\n- mtd: onenand: samsung: report DMA completion timeouts (Pengpeng Hou)\n- wifi: mwifiex: fix permanently busy scans after multiple roam iterations (Rafael Beims)\n- wifi: mac80211: free ack status frame on TX header build failure (Zhiling Zou)\n- powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access() (Junrui Luo)\n- reset: sunxi: fix memory region leak on ioremap failure (Zhao Dongdong)\n- ipvs: fix more places with wrong ipv6 transport offsets (Julian Anastasov)\n- memstick: ms_block: reject a card that reports too many blocks (Maoyi Xie)\n- macsec: fix promiscuity refcount leak in macsec_dev_open() (James Raphael Tiovalen)\n- llc: fix SAP refcount leak when creating incoming sockets (Luoxuanqiang)\n- Bluetooth: btrtl: validate firmware patch bounds (Laxman Acharya Padhya)\n- net: openvswitch: reject oversized nested action attrs (Asim Viladi Oglu Manizada) [Orabug: 39789564,39816016,39819143] {CVE-2026-64531}\n- regulator: ltc3676: Fix incorrect IRQSTAT bit offsets (Abhishek Ojha)\n- wifi: mac80211: fix memory leak in ieee80211_register_hw() (Dawei Feng)\n- wifi: rt2x00: avoid full teardown before work setup in probe (Runyu Xiao)\n- cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed (Farhad Alemi)\n- riscv: Prevent NULL pointer dereference in machine_kexec_prepare() (Tao Liu)\n- drbd: reject data replies with an out-of-range payload size (Michael Bommarito)\n- ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (Yizhou Zhao)\n- ipvs: use parsed transport offset in SCTP state lookup (Yizhou Zhao)\n- llc: fix SAP refcount leak in llc_ui_autobind() (Shuangpeng Bai)\n- mac802154: remove interfaces with RCU list deletion (Yousef Alhouseen)\n- s390/monwriter: Reject buffer reuse with different data length (Gerald Schaefer)\n- hwmon: (asus_atk0110) Check package count before accessing element (Hyeongjun An)\n- ata: pata_pxa: Fix DMA channel leak on probe error (Xu Wang)\n- orangefs: keep the readdir entry size 64-bit in fill_from_part() (Bryam Vargas)\n- tracing/probes: Fix double addition of offset for @+FOFFSET (Masami Hiramatsu)\n- net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Bryam Vargas)\n- fsl/fman: Free init resources on KeyGen failure in fman_init() (Haoxiang Li)\n- net: liquidio: fix BAR resource leak on PF number failure (Haoxiang Li)\n- hwmon: (w83793) remove vrm sysfs file on probe failure (Pengpeng Hou)\n- hwmon: (w83627hf) remove VID sysfs files on error and remove (Pengpeng Hou)\n- bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp() (Abdun Nihaal)\n- batman-adv: clean untagged VLAN on netdev registration failure (Sven Eckelmann)\n- batman-adv: ensure minimal ethernet header on TX (Sven Eckelmann)\n- batman-adv: retrieve ethhdr after potential skb realloc on RX (Sven Eckelmann)\n- nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (Shivam Kumar) [Orabug: 39789573] {CVE-2026-64534}\n- ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit (Shitalkumar Gandhi)\n- ieee802154: ca8210: fix cas_ctl leak on spi_async failure (Shitalkumar Gandhi)\n- ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation (Michael Bommarito)\n- ieee802154: admin-gate legacy LLSEC dump operations (Michael Bommarito)\n- net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)\n- net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)\n- net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)\n- net: ena: clean up XDP TX queues when regular TX setup fails (Dawei Feng)\n- net: sit: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)\n- gpios: palmas: add .get_direction() op (Andreas Kemnade)\n- cpu: hotplug: Bound hotplug states sysfs output (Bradley Morgan)\n- cpu: hotplug: Preserve per instance callback errors (Bradley Morgan)\n- Input: ims-pcu - fix type confusion in CDC union descriptor parsing (Dmitry Torokhov)\n- Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing (Dmitry Torokhov)\n- Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging (Dmitry Torokhov)\n- Input: ims-pcu - fix DMA mapping violation in line setup (Dmitry Torokhov)\n- Input: ims-pcu - add response length checks (Dmitry Torokhov)\n- Input: ims-pcu - validate control endpoint type (Dmitry Torokhov)\n- Input: ims-pcu - release data interface on disconnect (Dmitry Torokhov)\n- Input: ims-pcu - fix use-after-free and double-free in disconnect (Dmitry Torokhov)\n- scsi: elx: efct: Fix I/O leak on unsupported additional CDB (Haoxiang Li)\n- scsi: elx: efct: Fix refcount leak in efct_hw_io_abort() (Xu Wang)\n- scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (Bryam Vargas)\n- scsi: target: Bound PR-OUT TransportID parsing to the received buffer (Bryam Vargas)\n- scsi: xen: scsiback: Free unsubmitted command instead of double-putting it (Michael Bommarito)\n- scsi: xen: scsiback: Free the command tag on the TMR submit-failure path (Michael Bommarito)\n- scsi: sg: Report request-table problems when any status is set (Xu Rao)\n- scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path (Haoxiang Li)\n- dm-verity: increase sprintf buffer size (Mikulas Patocka)\n- dm_early_create: fix freeing used table on dm_resume failure (Mikulas Patocka)\n- dm-stats: fix merge accounting (Mikulas Patocka)\n- dm-stats: fix dm_jiffies_to_msec64 (Mikulas Patocka)\n- dm-log: fix a bitset_size overflow on 32bit machines (Benjamin Marzinski)\n- dm-bufio: fix wrong count calculation in dm_bufio_issue_discard (Mikulas Patocka)\n- dm era: fix out-of-bounds memory access for non-zero start sector (Samuel Moelius)\n- dm thin metadata: fix metadata snapshot consistency on commit failure (Ming-Hung Tsai)\n- dm thin metadata: fix superblock refcount leak on snapshot shadow failure (Genjian Zhang)\n- net: sparx5: unregister blocking notifier on init failure (Haoxiang Li)\n- can: bcm: add missing rcu list annotations and operations (Oliver Hartkopp)\n- can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure (Oliver Hartkopp)\n- can: isotp: use unconditional synchronize_rcu() in isotp_release() (Oliver Hartkopp)\n- nvmet-rdma: handle inline data with a nonzero offset (Bryam Vargas)\n- sctp: validate STALE_COOKIE cause length before reading staleness (Weiming Shi) [Orabug: 39794431] {CVE-2026-64551}\n- spi: uniphier: Fix completion initialization order before devm_request_irq() (Kunihiko Hayashi)\n- time: Fix off-by-one in compat settimeofday() usec validation (Wang Yan)\n- tpm: Make the TPM character devices non-seekable (Jaewon Yang)\n- tpm: fix event_size output in tpm1_binary_bios_measurements_show (Thorsten Blum)\n- xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie)\n- xfrm: use compat translator only for u64 alignment mismatch (Sanman Pradhan)\n- xen/gntdev: fix error handling in ioctl (Xu Wang)\n- i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() (Luoxuanqiang)\n- i2c: mediatek: fix WRRD for SoCs without auto_restart option (Roman Vivchar)\n- hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (Joshua Crofts)\n- irqchip/crossbar: Use correct index in crossbar_domain_free() (Bhargav Joshi)\n- mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (Florian Fuchs)\n- ocfs2: reject non-inline dinodes with i_size and zero i_clusters (Michael Bommarito)\n- ocfs2: reject dinodes whose i_rdev disagrees with the file type (Michael Bommarito)\n- ocfs2: reject dinodes with non-canonical i_mode type (Michael Bommarito)\n- ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits (Ian Bridges)\n- ocfs2: avoid moving extents to occupied clusters (Kyle Zeng)\n- mtd: rawnand: fix condition in 'nand_select_target()' (Arseniy Krasnov)\n- net/9p: fix infinite loop in p9_client_rpc on fatal signal (Vasiliy Kovalev)\n- mtd: rawnand: pl353: fix probe resource allocation (Bastien Curutchet)\n- ocfs2: use kzalloc for quota recovery bitmap allocation (Tristan Madani)\n- scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished() (Martin Wilck)\n- mtd: slram: remove failed entries from the device list (Ruoyu Wang)\n- proc: only bump parent nlink when registering directories (Krzysztof Wilczynski)\n- mips: sched: Fix CPUMASK_OFFSTACK memory corruption (Aaron Tomlin)\n- power: supply: charger-manager: fix refcount leak in is_full_charged() (Xu Wang)\n- ntfs3: fix out-of-bounds read in decompress_lznt (Tristan Madani)\n- ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head (Michael Bommarito)\n- ntfs3: cap RESTART_TABLE free-chain walker at rt-used (Michael Bommarito)\n- fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} (Michael Bommarito)\n- fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow (Michael Bommarito)\n- fs/ntfs3: validate lcns_follow in log_replay conversion (Konstantin Komarov)\n- fs/ntfs3: bound attr_off in UpdateResidentValue against data_off (Konstantin Komarov)\n- fs/ntfs3: bound DeleteIndexEntryAllocation memmove length (Konstantin Komarov)\n- fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename (Zhan Xusheng)\n- MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf() (Maciej W. Rozycki)\n- MIPS: ip22-gio: fix device reference leak in probe (Johan Hovold)\n- MIPS: ip22-gio: fix kfree() of static object (Johan Hovold)\n- MIPS: ip22-gio: fix gio device memory leak (Johan Hovold)\n- lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure (Chuck Lever)\n- lockd: Plug nlm_file leak when nlm_do_fopen() fails (Chuck Lever)\n- nvdimm/btt: Free arena sub-allocations on discover_arenas() error path (Abdun Nihaal)\n- nvdimm/btt: Free arenas on btt_init() error paths (Abdun Nihaal)\n- jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() (Junrui Luo)\n- Bluetooth: SCO: hold sk properly in sco_conn_ready (Pauli Virtanen)\n- Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (Pauli Virtanen)\n- mfd: tps6586x: Fix OF node refcount (Bartosz Golaszewski)\n- batman-adv: tt: prevent TVLV OOB check overflow (Sven Eckelmann)\n- batman-adv: frag: fix primary_if leak on failed linearization (Sven Eckelmann)\n- batman-adv: frag: free unfragmentable packet (Sven Eckelmann)\n- batman-adv: fix VLAN priority offset (Sven Eckelmann)\n- batman-adv: tt: avoid request storms during pending request (Sven Eckelmann)\n- batman-adv: dat: fix tie-break for candidate selection (Sven Eckelmann)\n- batman-adv: dat: ensure accessible eth_hdr proto field (Sven Eckelmann)\n- batman-adv: bla: reacquire gw address after skb realloc (Sven Eckelmann)\n- batman-adv: dat: acquire ARP hw source only after skb realloc (Sven Eckelmann)\n- batman-adv: access unicast_ttvn skb-data only after skb realloc (Sven Eckelmann)\n- batman-adv: gw: acquire ethernet header only after skb realloc (Sven Eckelmann)\n- x86/boot: Reject too long acpi_rsdp= values (Thorsten Blum)\n- x86/boot: Validate console=uart8250 baud rate to fix early boot hang (Thorsten Blum)\n- mfd: sm501: Fix reference leak on failed device registration (Guangshuo Li)\n- leds: uleds: Fix potential buffer overread (Armin Wolf)\n- soc: fsl: qe: panic on ioremap() failure in qe_reset() (Wang Jun)\n- soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (Siddharth Vadapalli)\n- gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path (Guangshuo Li)\n- netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (Xiang Mei) [Orabug: 39794442] {CVE-2026-64554}\n- netfilter: xt_nat: reject unsupported target families (Wyatt Feng)\n- netfilter: nf_conncount: fix zone comparison in tuple dedup (Yizhou Zhao)\n- netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag (Xiang Mei)\n- netfilter: nf_nat_sip: reload possible stale data pointer (Florian Westphal)\n- netfilter: xt_cluster: reject template conntracks in hash match (Wyatt Feng)\n- netfilter: nfnl_cthelper: apply per-class values when updating policies (David Carlier)\n- netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read (Muhammad Bilal)\n- fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (Abdun Nihaal)\n- fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (Abdun Nihaal)\n- fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() (Abdun Nihaal)\n- fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (Abdun Nihaal)\n- fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (Abdun Nihaal)\n- fbdev: s3fb: fix potential memory leak in s3_pci_probe() (Abdun Nihaal)\n- fbdev: i740fb: fix potential memory leak in i740fb_probe() (Abdun Nihaal)\n- fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (Abdun Nihaal)\n- fbdev: sm712: Fix operator precedence in big_swap macro (Li Rongqing)\n- fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (Abdun Nihaal)\n- fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (Abdun Nihaal)\n- fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (Abdun Nihaal)\n- KVM: arm64: vgic: Check the interrupt is still ours before migrating it (Hyunwoo Kim)\n- arm64: dts: qcom: sdm630: describe adsp_mem region properly (Nickolay Goppen)\n- net: ife: require ETH_HLEN to be pullable in ife_decode() (Yong Wang)\n- net: atm: reject out-of-range traffic classes in QoS validation (Zhengchuan Liang)\n- net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() (Michael Bommarito)\n- vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter (Zhang Tianci)\n- mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (Xu Wang)\n- smb: client: fix overflow in passthrough ioctl bounds check (Guangshuo Li)\n- net/mlx5: Fix L3 tunnel entropy refcount leak (Li Rongqing)\n- regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (Timur Tabi)\n- regulator: core: Make regulator_lock_two() logic easier to follow (Douglas Anderson)\n- dm era: fix NULL pointer dereference in metadata_open() (Cao Guanghui)\n- ipvs: ensure inner headers in ICMP errors are in headroom (Julian Anastasov)\n- ipvs: fix PMTU for GUE/GRE tunnel ICMP errors (Yizhou Zhao)\n- ipvs: use parsed transport offset in TCP state lookup (Yizhou Zhao)\n- ipvs: pass parsed transport offset to state handlers (Yizhou Zhao)\n- ipv6: mcast: Fix potential UAF in MLD delayed work (Eric Dumazet)\n- ipv6: mcast: Replace locking comments with lockdep annotations. (Kuniyuki Iwashima)\n- octeontx2-pf: check DMAC extraction support before filtering (Suman Ghosh)\n- net/sched: cake: reject overhead values that underflow length (Samuel Moelius)\n- net: usb: lan78xx: disable VLAN filter in promiscuous mode (Enrico Pozzobon)\n- ring-buffer: Fix event length with forced 8-byte alignment (Hui Wang)\n- Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (Weiming Shi) [Orabug: 39794421] {CVE-2026-64549}\n- Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (Pauli Virtanen)\n- net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (Xiang Mei)\n- net: qualcomm: rmnet: validate MAP frame length before ingress parsing (Xiang Mei)\n- net: qualcomm: rmnet: add tx packets aggregation (Daniele Palmas)\n- qede: fix off-by-one in BD ring consumption on build_skb failure (Shigeru Yoshida)\n- netfilter: xt_connmark: reject invalid shift parameters (Wyatt Feng)\n- netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop (Zhixing Chen)\n- netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt() (Feng Wu)\n- netfilter: xt_u32: reject invalid shift counts (Wyatt Feng)\n- gue: validate REMCSUM private option length (Qihang)\n- net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (Xiang Mei) [Orabug: 39794412] {CVE-2026-64547}\n- arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range() (Anshuman Khandual)\n- HID: core: Fix OOB read in hid_get_report for numbered reports (Lee Jones)\n- HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (Georgiy Osokin)\n- ata: sata_gemini: unwind clocks on IDE pinctrl errors (Myeonghun Pak)\n- afs: Fix unchecked-length string display in debug statement (David Howells)\n- afs: Fix the volume AFS_VOLUME_RM_TREE is set on (David Howells)\n- afs: Fix vllist leak (David Howells)\n- afs: Fix callback service message parsers to pass through -EAGAIN (David Howells)\n- afs: Fix error code in afs_extract_vl_addrs() (Dan Carpenter)\n- net/sched: hhf: clear heavy-hitter state on reset (Samuel Moelius)\n- gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (Vladimir Zapolskiy)\n- net/sched: act_bpf: use rcu_dereference_bh() to read the filter (Sechang Lim)\n- cxgb4: Fix decode strings dump for T6 adapters (Gleb Markov)\n- virtio_net: disable cb when NAPI is busy-polled (Longjun Tang)\n- irqchip/gic-v3-its: Fix OF node reference leak (Yuho Choi)\n- tracing: eprobe: read the complete FILTER_PTR_STRING pointer (Martin Kaiser)\n- tracing/events: Fix to check the simple_tsk_fn creation (Masami Hiramatsu)\n- bridge: stp: Fix a potential use-after-free when deleting a bridge (Ido Schimmel)\n- net: gianfar: dispose irq mappings on probe failure and device removal (Rosen Penev)\n- usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (Xiang Mei) [Orabug: 39794387] {CVE-2026-64540}\n- ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump (Pengfei Zhang)\n- ipv6: remove RTNL protection from inet6_dump_fib() (Eric Dumazet)\n- inet: allow ip_valid_fib_dump_req() to be called with RTNL or RCU (Eric Dumazet)\n- rtnetlink: add RTNL_FLAG_DUMP_UNLOCKED flag (Eric Dumazet)\n- rtnetlink: change nlk-cb_mutex role (Eric Dumazet)\n- hwmon: adm1275: Prevent reading uninitialized stack (Matti Vaittinen)\n- qede: fix out-of-bounds check for cqe-len_list[] (Matvey Kovalev)\n- seg6: validate SRH length before reading fixed fields (Nuoqi Gui)\n- gpio: htc-egpio: use managed gpiochip registration (Pengpeng Hou)\n- gpio: mvebu: fail probe if gpiochip registration fails (Pengpeng Hou)\n- spi: sh-msiof: abort transfers when reset times out (Pengpeng Hou)\n- tracing: probes: fix typo in a log message (Martin Kaiser)\n- net: sungem: fix probe error cleanup (Ruoyu Wang)\n- net: mvneta: re-enable percpu interrupt on resume (Yun Zhou)\n- rtc: cmos: unregister HPET IRQ handler on probe failure (Haoxiang Li)\n- rtc: ds1307: Fix off-by-one issue with wday for rx8130 (Fredrik M Olsson)\n- smb/client: preserve errors from smb2_set_sparse() (Huiwen He)\n- ipv6: fix error handling in disable_policy sysctl (Fernando Fernandez Mancera)\n- ipv6: fix error handling in forwarding sysctl (Fernando Fernandez Mancera)\n- ipv6: fix error handling in ignore_routes_with_linkdown sysctl (Fernando Fernandez Mancera)\n- ipv6: fix error handling in disable_ipv6 sysctl (Fernando Fernandez Mancera)\n- net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (Jamal Hadi Salim) [Orabug: 39787017] {CVE-2026-64530}\n- veth: fix NAPI leak in XDP enable error path (Eric Dumazet)\n- net: dsa: sja1105: round up PTP perout pin duration (Aleksandrova Alyona)\n- net, bpf: check master for NULL in xdp_master_redirect() (Xiang Mei) [Orabug: 39794405] {CVE-2026-64545}\n- alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs (Krzysztof Wilczynski)\n- alpha/PCI: Add security_locked_down() check to pci_mmap_resource() (Krzysztof Wilczynski)\n- NTB: epf: Make db_valid_mask cover only real doorbell bits (Koichiro Den)\n- netfilter: nft_synproxy: stop bypassing the priv-info snapshot (Runyu Xiao)\n- netfilter: nf_conncount: prevent connlimit drops for early confirmed ct (Fernando Fernandez Mancera)\n- ipv4: fib: Don't ignore error route in local/main tables. (Kuniyuki Iwashima)\n- ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). (Xiang Mei) [Orabug: 39794379] {CVE-2026-64538}\n- ksmbd: fix use-after-free of conn-preauth_info in concurrent SMB2 NEGOTIATE (Gil Portnoy)\n- PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0 (Manivannan Sadhasivam)\n- PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0 (Manivannan Sadhasivam)\n- drm/edid: fix OOB read in drm_parse_tiled_block() (Xiang Mei) [Orabug: 39794408] {CVE-2026-64546}\n- bpf: zero-initialize the fib lookup flow struct (Avinash Duduskar)\n- bpf: Fix stack slot index in nospec checks (Nuoqi Gui)\n- rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (Ronan Dalton)\n- rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (Antoni Pokusinski)\n- selftests/mm: fix exclusive_cow test fork() handling (Aboorva Devarajan)\n- selftests/mm: allow PUD-level entries in compound testcase of hmm tests (Sayali Patil)\n- selftests/mm: clarify alternate unmapping in compaction_test (Sayali Patil)\n- irqchip/crossbar: Fix parent domain resource leak (Bhargav Joshi)\n- netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak (Florian Westphal)\n- netfilter: nf_reject: skip iphdr options when looking for icmp header (Florian Westphal)\n- netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() (Jozsef Kadlecsik)\n- ieee802154: fix kernel-infoleak in dgram_recvmsg() (Aleksandr Nogikh)\n- ieee802154: Remove WARN_ON() in cfg802154_pernet_exit() (Ivan Abramov)\n- ACPI: resource: Amend kernel-doc style (Andy Shevchenko)\n- thermal: intel: Fix dangling resources on thermal_throttle_online() failure (Ricardo Neri)\n- arm64/hw_breakpoint: reject unaligned watchpoints that would truncate BAS (Breno Leitao)\n- dpaa2-switch: fix VLAN upper check not rejecting bridge join (Ioana Ciornei)\n- sctp: hold socket lock when dumping endpoints in sctp_diag (Xin Long)\n- net: psample: fix info leak in PSAMPLE_ATTR_DATA (Jakub Kicinski) [Orabug: 39794438] {CVE-2026-64553}\n- octeontx2-pf: Fix leak of SQ timestamp buffer on teardown (Ratheesh Kannoth)\n- xfrm: validate selector family and prefixlen during match (Eric Dumazet)\n- sparc: led: avoid trimming a newline from empty writes (Pengpeng Hou)\n- apparmor: fix label can not be immediately before a declaration (John Johansen)\n- i3c: master: Prevent reuse of dynamic address on device add failure (Adrian Hunter)\n- apparmor: put secmark label after secid lookup (Zygmunt Krynicki)\n- apparmor: aa_getprocattr free procattr leak on format failure (Zygmunt Krynicki)\n- apparmor: fix potential UAF in aa_replace_profiles (Maxime Belair)\n- apparmor: grab ns lock and refresh when looking up changehat child profiles (Ryan Lee)\n- apparmor: aa_label_alloc use aa_label_free on alloc failure (Zygmunt Krynicki)\n- apparmor: check label build before no_new_privs test (Ruoyu Wang)\n- PCI: mediatek: Use actual physical address instead of virt_to_phys() (Manivannan Sadhasivam)\n- PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port() (Ryder Lee)\n- tools lib api: Fix mount_overload() snprintf truncation and toupper range (Arnaldo Carvalho de Melo)\n- tools lib api: Fix filename__write_int() writing uninitialized stack data (Arnaldo Carvalho de Melo)\n- tools lib api: Fix missing null termination in filename__read_int/ull() (Arnaldo Carvalho de Melo)\n- xprtrdma: Fix bcall rep leak and unbounded peek (Chris Mason)\n- PCI: rcar-host: Remove unused LIST_HEAD(res) (Lad Prabhakar)\n- PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro (Li Rongqing)\n- NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write (Mike Snitzer)\n- NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors (Mike Snitzer)\n- NFSv4/pnfs: defer return_range callbacks until after inode unlock (Dai Ngo)\n- pNFS/filelayout: fix cheking if a layout is striped (Sagi Grimberg)\n- clk: qcom: a53: Corrected frequency multiplier for 1152MHz (Phillip Varney)\n- dmaengine: Fix possible use after free (Nuno Sa)\n- dmaengine: qcom: gpi: set DMA_PRIVATE capability (Icenowy Zheng)\n- drm/amd/display: Add missing kdoc for ALLM parameters (Srinivasan Shanmugam)\n- HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (Rosen Penev)\n- iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (Sanjay Chitroda)\n- iio: magnetometer: ak8975: fix potential kernel stack memory leak (Joshua Crofts)\n- iio: light: si1133: prevent race condition on timeout (Joshua Crofts)\n- iio: light: si1133: reset counter to prevent race condition (Joshua Crofts)\n- char: tlclk: fix use-after-free in tlclk_cleanup() (James Kim)\n- usb: host: max3421: Reject hub port requests for non-existent ports (Seungjin Bae)\n- usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (Seungjin Bae)\n- staging: most: video: avoid double free on video register failure (Guangshuo Li)\n- phy: phy-can-transceiver: Check driver match and driver data against NULL (Andy Shevchenko)\n- platform/x86: xo15-ebook: Fix wakeup source and GPE handling (Rafael J. Wysocki)\n- x86/platform/olpc: xo15: Drop wakeup source on driver removal (Rafael J. Wysocki)\n- coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore (Leo Yan)\n- coresight: cti: Fix DT filter signals silently ignored (Yingchao Deng)\n- staging: nvec: fix use-after-free in nvec_rx_completed() (Alexandru Hossu)\n- net/9p: fix race condition on rdma-state in trans_rdma.c (Yizhou Zhao)\n- ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write (Aleksandr Nogikh)\n- ksmbd: fix use-after-free in same_client_has_lease() (Guangshuo Li)\n- tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (Eric Dumazet)\n- tipc: fix UAF in tipc_l2_send_msg() (Eric Dumazet)\n- KEYS: Use acquire when reading state in keyring search (Gui-Dong Han)\n- powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus (Aboorva Devarajan)\n- powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down (Aboorva Devarajan)\n- powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del (Aboorva Devarajan)\n- MIPS: mm: Fix out-of-bounds write in maar_res_walk() (Yadan Fan)\n- bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check (Sechang Lim)\n- bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (Weiming Shi) [Orabug: 39794417] {CVE-2026-64548}\n- smb/client: always return a value for FS_IOC_GETFLAGS (Huiwen He)\n- netfilter: nf_conncount: callers must hold rcu read lock (Florian Westphal)\n- kcm: use WRITE_ONCE() when changing lower socket callbacks (Runyu Xiao)\n- bpf: Run generic devmap egress prog on private skb (Sun Jian)\n- net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (Aditya Garg)\n- net: mana: initialize gdma queue id to INVALID_QUEUE_ID (Aditya Garg)\n- net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen (Victor Nogueira)\n- net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen (Victor Nogueira)\n- ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (Guangshuo Li)\n- spi: xilinx: use FIFO occupancy register to determine buffer size (Lars Poschel)\n- crypto: rng - Free default RNG on module exit (Herbert Xu)\n- crypto: cavium/cpt - fix DMA cleanup using wrong loop index (Felix Gu)\n- crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (Felix Gu)\n- tipc: reject inverted service ranges from peer bindings (Michael Bommarito)\n- tipc: prevent snt_unacked underflow on CONN_ACK (Michael Bommarito)\n- tipc: require net admin for TIPCv2 netlink mutators (Michael Bommarito)\n- net/sched: sch_hfsc: Don't make class passive twice (Victor Nogueira)\n- sctp: validate embedded address parameter length (Xin Long)\n- bridge: cfm: reject invalid CCM interval at configuration time (Xiang Mei)\n- net: fib_rules: Don't dump dying fib_rule in fib_rules_dump(). (Kuniyuki Iwashima)\n- ASoC: tegra: tegra210_ahub: Validate written enum value (Hyeongjun An)\n- ASoC: fsl: fsl_audmix: Validate written enum values (Hyeongjun An)\n- ASoC: codecs: hdac_hdmi: Validate written enum value (Hyeongjun An)\n- RDMA/mlx5: Fix undefined shift of user RQ WQE size (Maher Sanalla)\n- RDMA/mlx5: Remove raw RSS QP restrack tracking (Patrisious Haddad)\n- fs: efs: remove unneeded debug prints (Maxwell Doose)\n- s390/process: Fix kernel thread function pointer type (Heiko Carstens)\n- bpf: Tighten cgroup storage cookie checks for prog arrays (Daniel Borkmann)\n- selftests/bpf: Fix bpf_iter/task_vma test (Yonghong Song)\n- bonding: 3ad: fix mux port state on oper down (Louis Scalbert)\n- tools/virtio: check mmap return value in vringh_test (Longlong Yan)\n- vduse: Requeue failed read to send_list head (Zhang Tianci)\n- vhost/vdpa: validate virtqueue index in mmap and fault paths (Qihang)\n- vduse: hold vduse_lock across IDR lookup in open path (Qihang)\n- IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified (Jason Gunthorpe)\n- fbdev: sm501fb: Fix buffer errors in OF binding code (David Laight)\n- btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (Filipe Manana)\n- hwspinlock: qcom: avoid uninitialized struct members (Wolfram Sang)\n- vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() (Hui Zhu)\n- pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (Luca Leonardo Scorcia)\n- pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (Luca Leonardo Scorcia)\n- watchdog: unregister PM notifier on watchdog unregister (Yuho Choi)\n- configfs: fix lockless traversals of -s_children (Al Viro)\n- firmware_loader: Fix recursive lock in device_cache_fw_images() (Dmitry Vyukov)\n- spi: ep93xx: fix double-free of zeropage on DMA setup failure (Felix Gu)\n- IB/mlx5: Properly support implicit ODP rereg_mr (Jason Gunthorpe)\n- IB/mlx5: Don't take the rereg_mr fallback without a new translation (Jason Gunthorpe)\n- cpufreq: Documentation: fix conservative governor freq_step description (Pengjie Zhang)\n- ACPI: IPMI: Fix message kref handling on dead device (Yuho Choi)\n- ALSA: seq: Clear variable event pointer on read (Kyle Zeng)\n- ALSA: seq: Add UMP support (Takashi Iwai)\n- ALSA: seq: Introduce SNDRV_SEQ_IOCTL_USER_PVERSION ioctl (Takashi Iwai)\n- riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe (Rui Qi)\n- wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (Tristan Madani)\n- bpf: Update transport_header when encapsulating UDP tunnel in lwt (Leon Hwang)\n- RDMA/irdma: Fix OOB read during CQ MR registration (Jacob Moroni)\n- IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path() (Jason Gunthorpe)\n- netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp (Pablo Neira Ayuso)\n- netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock (Fernando Fernandez Mancera)\n- netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures (Fernando Fernandez Mancera)\n- ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release() (Joseph Qi)\n- ocfs2/dlm: require a ref for locking_state debugfs open (Zhang Cen)\n- ocfs2: reject FITRIM ranges shorter than a cluster (Zhang Cen)\n- ocfs2: fix buffer head management in ocfs2_read_blocks() (Dmitry Antipov)\n- ocfs2: rebase copied fsdlm LVB pointers in locking_state (Zhang Cen)\n- bpftool: Use libbpf error code for flow dissector query (Woojin Ji)\n- configfs_lookup(): don't leave -s_dentry dangling on failure (Al Viro)\n- lib/test_meminit: use  for bools (Alexander Potapenko)\n- mm/fake-numa: fix under-allocation detection in uniform split (Sang-Heon Jeon)\n- bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs (Deepanshu Kartikey)\n- scsi: pm8001: Fix error code in non_fatal_log_show() (Dan Carpenter)\n- scsi: Revert 'scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans' (Martin Wilck)\n- ARM: imx31: Fix IIM mapping leak in revision check (Yuho Choi)\n- ARM: imx3: Fix CCM node reference leak (Yuho Choi)\n- ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback (Zhang Yi)\n- md/raid10: reset read_slot when reusing r10bio for discard (Chen Cheng)\n- media: qcom: venus: relax encoder frame/blur step size on v6 (Renjiang Han)\n- media: qcom: venus: relax encoder frame/blur dimension steps on v4 (Renjiang Han)\n- media: qcom: venus: drop extra padding in NV12 raw size calculation (Renjiang Han)\n- EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info (Zhoumin)\n- drm/msm/dp: Fix the ISR_* enum values (Jessica Zhang)\n- drm/msm/dp: fix HPD state status bit shift value (Jessica Zhang)\n- crypto: hisilicon/qm - disable error report before flr (Weili Qian)\n- ocfs2: kill osb-system_file_mutex lock (Tetsuo Handa)\n- ocfs2: don't BUG_ON an invalid journal dinode (Zhengyuan Huang)\n- rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() (Dan Carpenter)\n- dax/kmem: account for partial discontiguous resource upon removal (Davidlohr Bueso)\n- libbpf: Fix UAF in strset__add_str() (Carlos Llamas)\n- drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (Timur Tabi)\n- drm/tegra: Fix iommu_map_sgtable() return value check (Mikko Perttunen)\n- drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (Felix Gu)\n- net/sched: cls_bpf: prevent unbounded recursion in offload rollback (Jiayuan Chen)\n- ipv6: guard against possible NULL deref in __in6_dev_stats_get() (Eric Dumazet)\n- workqueue: drop spurious '*' from print_worker_info() fn declaration (Breno Leitao)\n- nvme-multipath: fix flex array size in struct nvme_ns_head (Nilay Shroff)\n- mtd: spi-nor: Drop duplicate Kconfig dependency (Miquel Raynal)\n- mips: n64: add __iomem for writel call (Rosen Penev)\n- mips: ralink: mt7621: add missing __iomem (Rosen Penev)\n- MIPS: DEC: Remove do_IRQ() call indirection (Maciej W. Rozycki)\n- MIPS: Fix big-endian stack argument fetching in o32 wrapper (Maciej W. Rozycki)\n- PM: sleep: Use complete() in device_pm_sleep_init() (Jiakai Xu)\n- RDMA/hns: Fix warning in poll cq direct mode (Wenglianfa)\n- IB/mlx4: Fix refcount leak in add_port() error path (Guangshuo Li)\n- RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (Jacob Moroni)\n- bus: sunxi-rsb: Always check register address validity (Samuel Holland)\n- pwm: imx27: Fix variable truncation in .apply() (Ronaldo Nunez)\n- cpufreq: conservative: Simplify frequency limit handling (Lifeng Zheng)\n- cpufreq: Documentation: fix sampling_down_factor range (Pengjie Zhang)\n- device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id() (Stepan Ionichev)\n- firmware: arm_scmi: Fix OOB in scmi_power_name_get() (Geert Uytterhoeven)\n- media: rockchip: rga: fix too small buffer size (Sven Puschel)\n- net/sched: sch_drr: annotate data-races around cl-deficit (Eric Dumazet)\n- sysfs: clamp show() return value in sysfs_kf_read() (Greg Kroah-Hartman)\n- firmware: arm_scmi: Read sensor config as 32-bit value (Sudeep Holla)\n- media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() (Zilin Guan)\n- RDMA/srpt: fix integer overflow in immediate data length check (Sara Venkatesh)\n- RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (Prathamesh Deshpande)\n- RDMA/hns: Fix arithmetic overflow in calc_hem_config() (Alexander Chesnokov)\n- ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD (Linmao Li)\n- net/sched: sch_htb: annotate data-races (I) (Eric Dumazet)\n- net/sched: sch_htb: do not change sch-flags in htb_dump() (Eric Dumazet)\n- crypto: ccp - Treat zero-length cert chain as query for blob lengths (Sean Christopherson)\n- net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats() (Eric Dumazet)\n- thermal: hwmon: Fix critical temperature attribute removal (Rafael J. Wysocki)\n- evm: terminate and bound the evm_xattrs read buffer (Pengpeng Hou)\n- drm/hisilicon/hibmc: use clock to look up the PLL value (Lin He)\n- drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (Lin He)\n- clk: scmi: Fix clock rate rounding (Cristian Marussi)\n- iommu/amd: Fix a stale comment about which legacy mode is user visible (Sean Christopherson)\n- crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (Weiming Shi) [Orabug: 39794401] {CVE-2026-64544}\n- crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (Thorsten Blum)\n- crypto: atmel-sha204a - fix blocking and non-blocking rng logic (Lothar Rubusch)\n- pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path (Felix Gu)\n- media: cedrus: Fix failure to clean up hardware on probe failure (Samuel Holland)\n- watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (Felix Gu)\n- watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (Gao Yingjie)\n- ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint (Jihed Chaibi)\n- wifi: ath9k: fix OOB access from firmware tx status queue ID (Tristan Madani)\n- kconfig: fix potential NULL pointer dereference in conf_askvalue (Xingjing Deng)\n- wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (Tristan Madani)\n- driver core: use READ_ONCE() for dev-driver in dev_has_sync_state() (Danilo Krummrich)\n- drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (Yuho Choi)\n- drm/tidss: Drop extra drm_mode_config_reset() call (Tomi Valkeinen)\n- fbcon: fix NULL pointer dereference for a console without vc_data (Ian Bridges)\n- afs: Fix further netns teardown to cancel the preallocation charger (David Howells)\n- afs: fix NULL pointer dereference in afs_get_tree() (Matvey Kovalev)\n- afs: Fix netns teardown to cancel the preallocation charger (David Howells)\n- serial: 8250_omap: clear rx_running on zero-length DMA completes (Matthias Feser)\n- serial: msm: Disable DMA for kernel console UART (Stephan Gerhold)\n- dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties (Chen-Yu Tsai)\n- media: uvcvideo: Fix buffer sequence in frame gaps (Ricardo Ribalda)\n- media: uvcvideo: Avoid partial metadata buffers (Ricardo Ribalda)\n- crypto: hisi-trng - Remove crypto_rng interface (Eric Biggers)\n- crypto: crypto4xx - Remove insecure and unused rng_alg (Eric Biggers)\n- crypto: crypto4xx - Remove ahash-related code (Herbert Xu)\n- crypto: sun4i-ss - Remove insecure and unused rng_alg (Eric Biggers)\n- crypto: af_alg - Remove zero-copy support from skcipher and aead (Eric Biggers)\n- net: dsa: tag_ksz: do not rely on skb_mac_header() in TX paths (Vladimir Oltean)\n- tools/mm/slabinfo: fix total_objects attribute name (Chenyichong)\n- crypto: algif_skcipher - force synchronous processing on trees without ctx-state (Muhammet Kaan Kilinc)\n- sched/fair: Only update stats for allowed CPUs when looking for dst group (Adam Li)\n- xfs: fail recovery on a committed log item with no regions (Weiming Shi) [Orabug: 39760871] {CVE-2026-64187}\n- fuse: re-lock request before returning from fuse_ref_folio() (Joanne Koong) [Orabug: 39785786] {CVE-2026-64266}\n- fuse: fix device node leak in cuse_process_init_reply() (Alberto Ruiz)\n- RDMA/siw: bound Read Response placement to the RREAD length (Michael Bommarito)\n- RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg (Zhenhao Wan)\n- Input: maplecontrol - set driver data before registering input device (Dmitry Torokhov)\n- Input: maplemouse - set driver data before registering input device (Dmitry Torokhov)\n- Input: maple_keyb - set driver data before registering input device (Dmitry Torokhov)\n- Input: mms114 - fix multi-touch slot corruption (Dmitry Torokhov)\n- Input: maplemouse - fix NULL pointer dereference in open() (Florian Fuchs)\n- Input: touchwin - reset the packet index on every complete packet (Bryam Vargas) [Orabug: 39785802] {CVE-2026-64271}\n- Input: iforce - bound the device-reported force-feedback effect index (Bryam Vargas)\n- Input: goodix - clamp the device-reported contact count (Bryam Vargas)\n- Input: elan_i2c - prevent division by zero and arithmetic underflow (Ranjan Kumar) [Orabug: 39785819] {CVE-2026-64275}\n- Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (Bryam Vargas) [Orabug: 39785823] {CVE-2026-64276}\n- Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (Bryam Vargas)\n- Input: synaptics-rmi4 - unregister function handlers on physical driver registration failure (Haoxiang Li)\n- i2c: stm32f7: truncate clock period instead of rounding it (Guillermo Rodriguez)\n- i2c: core: fix adapter deregistration race (Johan Hovold) [Orabug: 39785831] {CVE-2026-64279}\n- udmabuf: fix DMA direction mismatch in release_udmabuf() (Mikhail Gavrilov)\n- KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (Sean Christopherson) [Orabug: 39843616] {CVE-2026-64604}\n- NTB: epf: Fix request_irq() unwind in ntb_epf_init_isr() (Koichiro Den)\n- exfat: bound uniname advance in exfat_find_dir_entry() (Bryam Vargas) [Orabug: 39785863] {CVE-2026-64296}\n- NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (Benjamin Coddington) [Orabug: 39785868] {CVE-2026-64298}\n- tracing: Prevent out-of-bounds read in glob matching (Huihui Huang) [Orabug: 39785872] {CVE-2026-64299}\n- spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (Carlos Song)\n- spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (Carlos Song)\n- crypto: talitos - use dma_sync_single_for_cpu() before reading descriptor header (Paul Louvel)\n- crypto: drbg - Fix the fips_enabled priority boost (Eric Biggers)\n- crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (Eric Biggers)\n- crypto: drbg - Fix returning success on failure in CTR_DRBG (Eric Biggers) [Orabug: 39785893] {CVE-2026-64306}\n- crypto: pcrypt - restore callback for non-parallel fallback (Ruijie Li) [Orabug: 39785906] {CVE-2026-64312}\n- crypto: ecc - Fix carry overflow in vli multiplication (Anastasia Tishchenko) [Orabug: 39785910] {CVE-2026-64313}\n- crypto: caam - use print_hex_dump_devel to guard key hex dumps again (Thorsten Blum)\n- crypto: caam - use print_hex_dump_devel to guard key hex dumps (Thorsten Blum)\n- isofs: bound Rock Ridge symlink components to the SL record (Bryam Vargas) [Orabug: 39785923] {CVE-2026-64317}\n- partitions: aix: bound the pp_count scan to the ppe array (Bryam Vargas)\n- nvme-multipath: set BIO_REMAPPED on bios remapped to per-path namespace disks (Igor Achkinazi)\n- dm-ioctl: report an error if a device has no table (Mikulas Patocka)\n- udf: validate sparing table length as an entry count, not a byte count (Bryam Vargas) [Orabug: 39785940] {CVE-2026-64322}\n- udf: validate VAT header length against the VAT inode size (Bryam Vargas) [Orabug: 39785944] {CVE-2026-64323}\n- udf: validate free block extents against the partition length (Michael Bommarito) [Orabug: 39785948] {CVE-2026-64324}\n- iio: temperature: ltc2983: Fix n_wires default bypassing rotation check (Liviu Stan)\n- usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (Madhu M)\n- usb: typec: ucsi: Invert DisplayPort role assignment (Andrei Kuchynski)\n- usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (Badhri Jagan Sridharan) [Orabug: 39785963] {CVE-2026-64330}\n- usbip: vudc: fix NULL deref in vep_dequeue() (Sam Day) [Orabug: 39785967] {CVE-2026-64331}\n- usbip: tools: support SuperSpeedPlus devices (Chenyichong)\n- USB: usb-storage: ene_ub6250: restore media-ready check (Xu Rao)\n- USB: ulpi: fix memory leak on registration failure (Johan Hovold) [Orabug: 39785971] {CVE-2026-64332}\n- USB: serial: digi_acceleport: fix write buffer corruption (Johan Hovold) [Orabug: 39785975] {CVE-2026-64333}\n- USB: serial: digi_acceleport: fix hard lockup on disconnect (Johan Hovold) [Orabug: 39785979] {CVE-2026-64334}\n- USB: serial: digi_acceleport: fix broken rx after throttle (Johan Hovold) [Orabug: 39785983] {CVE-2026-64335}\n- USB: serial: option: add Telit Cinterion FE990D50 compositions (Fabio Porcedda)\n- USB: serial: keyspan_pda: fix information leak (Johan Hovold) [Orabug: 39785987] {CVE-2026-64336}\n- usb: mtu3: unmap request DMA on queue failure (Haoxiang Li)\n- USB: misc: uss720: unregister parport on probe failure (Myeonghun Pak) [Orabug: 39785994] {CVE-2026-64338}\n- USB: storage: include US_FL_NO_SAME in quirks mask (Xu Rao)\n- usb: sl811-hcd: disable controller wakeup on remove (Myeonghun Pak)\n- USB: legousbtower: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39785999] {CVE-2026-64340}\n- USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD (Erich E. Hoover)\n- USB: iowarrior: fix use-after-free on disconnect (Johan Hovold) [Orabug: 39786007] {CVE-2026-64342}\n- USB: ldusb: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39786012] {CVE-2026-64343}\n- USB: idmouse: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39786017] {CVE-2026-64344}\n- usb: gadget: udc: Fix use-after-free in gadget_match_driver (Jimmy Hu) [Orabug: 39786026] {CVE-2026-64346}\n- usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (Maoyi Xie) [Orabug: 39786030] {CVE-2026-64347}\n- usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (Xu Wang)\n- USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub (Rodrigo Lugathe Da Conceicao Alves)\n- usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (Haoxiang Li)\n- usb: cdc_acm: Add quirk for Uniden BC125AT scanner (Jared Baldridge)\n- net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() (Maoyi Xie) [Orabug: 39786042] {CVE-2026-64351}\n- xfs: fix unreachable BIGTIME check in dquot flush validation (Alexey Nepomnyashih)\n- nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers (Deepanshu Kartikey)\n- hfs/hfsplus: zero-initialize buffer in hfs_bnode_read (Tristan Madani)\n- HID: sensor-hub: Add sensor_hub_input_attr_read_values() for multi-byte reads (Srinivas Pandruvada)\n- HID: lg-g15: cancel pending work on remove to fix a use-after-free (Maoyi Xie) [Orabug: 39786071] {CVE-2026-64362}\n- HID: wacom: stop hardware after post-start probe failures (Myeonghun Pak) [Orabug: 39859299] {CVE-2026-68091}\n- posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path (Xu Wang) [Orabug: 39786091] {CVE-2026-64370}\n- cpufreq: pcc: fix use-after-free and double free in _OSC evaluation (Yuho Choi) [Orabug: 39786100] {CVE-2026-64372}\n- cpufreq: Fix hotplug-suspend race during reboot (Tianxiang Chen) [Orabug: 39786104] {CVE-2026-64373}\n- sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT (Steven Rostedt) [Orabug: 39786108] {CVE-2026-64374}\n- cpufreq: intel_pstate: Sync policy-cur during CPU offline (Wangfushuai)\n- net: Drop the lock in skb_may_tx_timestamp() (Sebastian Andrzej Siewior) [Orabug: 39331701] {CVE-2026-43216}\n- Bluetooth: L2CAP: validate option length before reading conf opt value (Muhammad Bilal) [Orabug: 39786205] {CVE-2026-64403}\n- Bluetooth: fix UAF in bt_accept_dequeue() (Yousef Alhouseen) [Orabug: 39786578] {CVE-2026-64406}\n- Bluetooth: bnep: pin L2CAP connection during netdev registration (Yousef Alhouseen) [Orabug: 39786217] {CVE-2026-64408}\n- netfilter: ebtables: terminate table name before find_table_lock() (Xiang Mei) [Orabug: 39786224] {CVE-2026-64411}\n- netfilter: ebtables: module names must be null-terminated (Florian Westphal) [Orabug: 39786228] {CVE-2026-64412}\n- mfd: cros_ec: Delay dev_set_drvdata() until probe success (Andrei Kuchynski) [Orabug: 39786248] {CVE-2026-64420}\n- net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes (Wyatt Feng) [Orabug: 39786254] {CVE-2026-64422}\n- ipv4: igmp: remove multicast group from hash table on device destruction (Yuyang Huang) [Orabug: 39786259] {CVE-2026-64423}\n- io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item (Runyu Xiao) [Orabug: 39786574] {CVE-2026-64425}\n- gpio: eic-sprd: use raw_spinlock_t in the irq startup path (Runyu Xiao)\n- NTB: epf: Avoid calling pci_irq_vector() from hardirq context (Koichiro Den)\n- fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns (Yunpeng Tian)\n- debugobjects: Plug race against a concurrent OOM disable (Thomas Gleixner)\n- audit: Fix data races of skb_queue_len() readers on audit_queue (Chi Wang) [Orabug: 39786289] {CVE-2026-64435}\n- net: af_key: initialize alg_key_len for IPComp states (Zijing Yin) [Orabug: 39786293] {CVE-2026-64436}\n- crypto: amlogic - avoid double cleanup in meson_crypto_probe() (Dawei Feng) [Orabug: 39843604] {CVE-2026-64599}\n- staging: rtl8723bs: fix OOB write in HT_caps_handler() (Alexandru Hossu) [Orabug: 39786303] {CVE-2026-64440}\n- staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (Alexandru Hossu) [Orabug: 39789581] {CVE-2026-64536}\n- staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (Alexandru Hossu) [Orabug: 39786311] {CVE-2026-64442}\n- staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (Alexandru Hossu) [Orabug: 39786315] {CVE-2026-64443}\n- staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (Alexandru Hossu) [Orabug: 39786319] {CVE-2026-64444}\n- staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (Alexandru Hossu) [Orabug: 39786323] {CVE-2026-64445}\n- staging: media: atomisp: reduce load_primary_binaries() stack usage (Arnd Bergmann)\n- media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe (Ricardo Ribalda)\n- tipc: fix out-of-bounds read in broadcast Gap ACK blocks (Samuel Page) [Orabug: 39786340] {CVE-2026-64450}\n- 6lowpan: fix NHC entry use-after-free on error path (Yizhou Zhao) [Orabug: 39786344] {CVE-2026-64452}\n- usb: dwc3: run gadget disconnect from sleepable suspend context (Runyu Xiao) [Orabug: 39786349] {CVE-2026-64454}\n- USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (Alan Stern) [Orabug: 39786352] {CVE-2026-64455}\n- hwrng: virtio: clamp device-reported used.len at copy_data() (Michael Bommarito) [Orabug: 39786356] {CVE-2026-64456}\n- virtio-mmio: fix device release warning on module unload (Johan Hovold)\n- netfilter: ipset: fix race between dump and ip_set_list resize (Xiang Mei) [Orabug: 39760883] {CVE-2026-64189}\n- PCI: host-common: Request bus reassignment when not probe-only (Ratheesh Kannoth)\n- PCI: altera: Do not dispose parent IRQ mapping (Mahesh Vaidya)\n- usb: xhci: Fix sleep in atomic context in xhci_free_streams() (Lianqin Hu) [Orabug: 39786379] {CVE-2026-64465}\n- binder: fix UAF in binder_free_transaction() (Carlos Llamas)\n- binder: fix UAF in binder_thread_release() (Carlos Llamas)\n- Bluetooth: btusb: fix wakeup source leak on probe failure (Johan Hovold)\n- Bluetooth: btusb: fix use-after-free on marvell probe failure (Johan Hovold) [Orabug: 39786393] {CVE-2026-64470}\n- Bluetooth: btusb: fix use-after-free on registration failure (Johan Hovold) [Orabug: 39786397] {CVE-2026-64471}\n- ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (Cassio Gabriel)\n- ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (Cassio Gabriel)\n- ALSA: usb-audio: Roll back quirk control caches on write errors (Cassio Gabriel)\n- ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (Cassio Gabriel)\n- ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (Cassio Gabriel)\n- ALSA: usb-audio: avoid kobject path lookup in DualSense match (Darvell Long) [Orabug: 39786416] {CVE-2026-64478}\n- ALSA: firewire: isight: bound the sample count to the packet payload (Maoyi Xie) [Orabug: 39786428] {CVE-2026-64483}\n- ALSA: es1938: check snd_ctl_new1() return value (Zhao Dongdong) [Orabug: 39786432] {CVE-2026-64484}\n- ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (Maoyi Xie) [Orabug: 39786439] {CVE-2026-64487}\n- ALSA: virtio: Add missing 384 kHz PCM rate mapping (Cassio Gabriel)\n- iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (Liviu Stan)\n- iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (Andy Shevchenko)\n- iio: light: veml6030: fix channel type when pushing events (Javier Carrasco)\n- iio: light: tsl2591: return actual error from probe IRQ failure (Stepan Ionichev)\n- iio: light: opt3001: fix missing state reset on timeout (Joshua Crofts)\n- iio: light: gp2ap002: fix runtime PM leak on read error (Biren Pandya)\n- iio: light: al3010: fix incorrect scale for the highest gain range (Vidhu Sarwal)\n- iio: imu: st_lsm6dsx: deselect shub page before reading whoami (Andreas Kempe)\n- iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (Runyu Xiao)\n- iio: gyro: bmg160: wait full startup time after mode change at probe (Stepan Ionichev)\n- iio: gyro: bmg160: bail out when bandwidth/filter is not in table (Stepan Ionichev)\n- iio: event: Fix event FIFO reset race (Lars-Peter Clausen) [Orabug: 39786462] {CVE-2026-64496}\n- iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (Maxwell Doose)\n- iio: adc: ti-ads124s08: Return reset GPIO lookup errors (Pengpeng Hou)\n- iio: adc: spear: Initialize completion before requesting IRQ (Maxwell Doose)\n- iio: adc: lpc32xx: Initialize completion before requesting IRQ (Maxwell Doose)\n- iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (Biren Pandya) [Orabug: 39786478] {CVE-2026-64503}\n- iio: accel: bmc150: clamp the device-reported FIFO frame count (Bryam Vargas) [Orabug: 39786482] {CVE-2026-64504}\n- usb: gadget: function: rndis: add length check for header (Griffin Kroah-Hartman)\n- usb: gadget: function: rndis: add length check to response query (Griffin Kroah-Hartman)\n- ksmbd: fix out-of-bounds read in smb_check_perm_dacl() (Hem Parekh)\n- NFSv4/flexfiles: reject zero filehandle version count (Michael Bommarito) [Orabug: 39753894] {CVE-2026-53392}\n- fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() (Mingyu Wang) [Orabug: 39753924] {CVE-2026-53402}\n- i2c: core: fix adapter registration race (Johan Hovold) [Orabug: 39753916] {CVE-2026-53400}\n- i2c: core: fix adapter debugfs creation (Johan Hovold)\n- i2c: core: fix NULL-deref on adapter registration failure (Johan Hovold)\n- i2c: core: fix hang on adapter registration failure (Johan Hovold)\n- i2c: core: fix irq domain leak on adapter registration failure (Johan Hovold)\n- block: Avoid mounting the bdev pseudo-filesystem in userspace (Denis Arefev) [Orabug: 39753985] {CVE-2026-63810}\n- f2fs: fix listxattr handling of corrupted xattr entries (Keshav Verma)\n- f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs() (Chao Yu)\n- f2fs: fix potential deadlock in f2fs_balance_fs() (Ruipeng Qi)\n- f2fs: bound i_inline_xattr_size for non-inline-xattr inodes (Bryam Vargas)\n- f2fs: validate orphan inode entry count (Wenjie Qi)\n- device property: initialize the remaining fields of fwnode_handle in fwnode_init() (Bartosz Golaszewski)\n- f2fs: fix to round down start offset of fallocate for pin file (Sunmin Jeong)\n- f2fs: adjust zone capacity when considering valid block count (Jaegeuk Kim)\n- f2fs: validate compress cache inode only when enabled (Wenjie Qi)\n- f2fs: fix to detect corrupted meta ino (Chao Yu)\n- apparmor: mediate the implicit connect of TCP fast open sendmsg (Bryam Vargas)\n- net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) [Orabug: 39754045] {CVE-2026-63829}\n- apparmor: fix use-after-free in rawdata dedup loop (Ruslan Valiyev)\n- net: skmsg: preserve sg.copy across SG transforms (Yiming Qian) [Orabug: 39754049] {CVE-2026-63830}\n- skmsg: convert struct sk_msg_sg::copy to a bitmap (Eric Dumazet)\n- netfilter: nf_tables: restore set elements when delete set fails (Pablo Neira Ayuso) [Orabug: 36598010] {CVE-2024-27012}\n- KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (Sean Christopherson) [Orabug: 39753972] {CVE-2026-63806}\n- nfsd: change nfs4_client_to_reclaim() to allocate data (Neil Brown)\n- nfsd: move name lookup out of nfsd4_list_rec_dir() (Neilbrown)\n- slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd (Bjorn Andersson)\n- slimbus: Convert to platform remove callback returning void (Uwe Kleine-Konig)\n- slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership (Bjorn Andersson)\n- slimbus: qcom-ngd-ctrl: Fix probe error path ordering (Bjorn Andersson)\n- slimbus: qcom-ngd-ctrl: Fix up platform_driver registration (Bjorn Andersson)\n- dma-buf: remove unused dma-fence-unwrap.c (stable/linux-5.15.y only) (Tudor Ambarus)\n- net/sched: act_pedit: use NLA_POLICY for parsing 'ex' keys (Pedro Tammela)\n- clk: imx: Add check for kcalloc (Jiasheng Jiang)\n- userfaultfd: gate must_wait writability check on pte_present() (Kiryl Shutsemau) [Orabug: 39786515] {CVE-2026-64514}\n- nfsd: reset write verifier on deferred writeback errors (Jeff Layton) [Orabug: 39753898] {CVE-2026-53393}\n- nfsd: release layout stid on setlease failure (Chris Mason) [Orabug: 39753912] {CVE-2026-53399}\n- nfc: llcp: protect nfc_llcp_sock_unlink() calls (Krzysztof Kozlowski)\n- nvmet-tcp: fix race between ICReq handling and queue teardown (Chaitanya Kulkarni) [Orabug: 39460310] {CVE-2026-46135}\n\n[5.15.0-324.211.2]\n- net: tap: set skb-dev before parsing virtio net header in tap_get_user_xdp() (Dongli Zhang) [Orabug: 39558744] {CVE-2026-74684}\n- ACPI: resource: Always use MADT override IRQ settings for all legacy non i8042 IRQs (Hans de Goede) [Orabug: 39801953]\n- net/rds: harden rds_rm_size (Manjunath Patil) [Orabug: 39812533]\n- net/rds: Add parentheses around conditional operator (Gerd Rausch) [Orabug: 39844638]\n- net/rds: remove cached rds_sock-rs_conn and rs_conn_path (Sharath Srinivasan) [Orabug: 39832354]\n- Revert 'rds: cong: Make rds_cong_wait an array to reduce lock contention' (Sharath Srinivasan) [Orabug: 39832354]\n- rds: Prevent kernel-infoleak in rds_notify_queue_get() (Peilin Ye) [Orabug: 39772650]\n- rds: do not leak kernel memory to user land (Eric Dumazet) [Orabug: 39772650]\n- net/rds: zero per-item info buffer before handing it to visitors (Michael Bommarito) [Orabug: 39621715,39638197] {CVE-2026-52995}\n- x86/sev: Evict cache lines during SNP memory validation (Tom Lendacky) [Orabug: 38334919] {CVE-2025-38560}\n- Revert: uek-rpm: cnic: Trim the SNIC config for a faster boot (Kan Liang) [Orabug: 39825570]\n- Revert: uek-rpm: cnic: Clean up the elba/SNIC config with make olddefconfig (Kan Liang) [Orabug: 39825570]\n- rds: ib: move gc_count reset before free_percpu (Manjunath Patil) [Orabug: 39818509]\n- rds: fix lfstack_pop_all sequence reset (Manjunath Patil) [Orabug: 39818509]\n- drm/amdkfd: fix invalid GTT pointer in DQM cleanup (Imran Khan) [Orabug: 39605741]\n- xfs: resample the data fork mapping after cycling ILOCK (Darrick Wong) [Orabug: 39776791] {CVE-2026-64600}\n\n[5.15.0-324.211.1]\n- signal: Fix use-after-free of wait_chldexit (Aruna Ramakrishna) [Orabug: 39800301]\n- mstflint_access: Update driver code to v4.36.0-1 from Github (Mark Haywood) [Orabug: 38074279]\n- mstflint_access: Update driver code to v4.35.0-1 from Github (Mark Haywood) [Orabug: 38074279]\n- mstflint_access: Update driver code to v4.34.0-1 from Github (Itay Avraham) [Orabug: 38074279]\n- mstflint_access: Update driver code to v4.33.0-1 from Github (Itay Avraham) [Orabug: 38074279]\n- mstflint_access: Update driver code to v4.32.0-1 from Github (Tzafrir Cohen) [Orabug: 38074279]\n- mstflint_access: Update driver code to v4.31.0-1 from Github (Mark Haywood) [Orabug: 38074279]\n- mstflint_access: Update driver code to v4.28.0-1 from Github (Itay Avraham) [Orabug: 38074279]\n- mstflint_access: Update driver code to v4.26.0-1 from Github (Markus Theil) [Orabug: 38074279]\n- mstflint_access: Update driver code to v4.25.0-1 from Github (Mark Haywood) [Orabug: 38074279]\n- mstflint_access: Update driver code to v4.24.0-1 from Github (Chris Moore) [Orabug: 38074279]\n- mstflint_access: Update driver code to v4.21.0-1 from Github (Mark Haywood) [Orabug: 38074279]\n- mm/filemap: make filemap_fault() to retry fault after collapse_file() (Jane Chu) [Orabug: 39778847]\n- PM: hibernate: Fix backwards snapshot_test condition for test_resume mode (Jeremy Tang) [Orabug: 39766052]\n- PM: hibernate: Do not get block device exclusively in test_resume mode (Chen Yu) [Orabug: 39766052]\n- PM: hibernate: Turn snapshot_test into global variable (Chen Yu) [Orabug: 39766052]\n- PM: hibernate: fix load_image_and_restore() error path (Ye Bin) [Orabug: 39766052]\n- arm64: mm: Add PTE_DIRTY back to PAGE_KERNEL* to fix kexec/hibernation (Catalin Marinas) [Orabug: 39750197]\n...",
  "id": "ELSA-2026-500249",
  "ovalId": "oval:com.oracle.elsa:def:2026500249",
  "source": "oracle_linux",
  "title": "ELSA-2026-500249: Unbreakable Enterprise kernel security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-500249.html"
}
View JSON API Download JSON