oracle-2026500163
oracle_linux[5.15.0-323.211.3.3] - Revert 'x86/alternatives: Add alt_instr.flags' (Harshit Mogalapalli) [Orabug: 39853924] [5.15.0-323.211.3.2] - ACPI: resource: Always use MADT override IRQ settings for all legacy non i8042 IRQs (Hans de Goede) [Orabug: 39848333] - KVM: x86/mmu: Stop needlessly making MMU pages available for TDP MMU faults (David Matlack) [Orabug: 39848194] - KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Sean Christopherson) [Orabug: 39848194] {CVE-2026-64561} - KVM: x86/mmu: Rename __direct_map() to direct_map() (David Matlack) [Orabug: 39848194] - KVM: x86/mmu: Split out TDP MMU page fault handling (David Matlack) [Orabug: 39848194] - KVM: Rename mmu_notifier_* to mmu_invalidate_* (Chao Peng) [Orabug: 39848194] - KVM: x86/mmu: Document the 'rules' for using host_pfn_mapping_level() (Sean Christopherson) [Orabug: 39848194] - KVM: x86/mmu: Rename pte_list_{destroy,remove}() to show they zap SPTEs (Sean Christopherson) [Orabug: 39848194] - KVM: x86/mmu: Directly 'destroy' PTE list when recycling rmaps (Sean Christopherson) [Orabug: 39848194] - x86/bugs: Make Safe-RET robust against interrupt injection (Borislav Petkov (AMD)) [Orabug: 39849605] {CVE-2026-68480} - x86/alternatives: Disable interrupts and sync when optimizing NOPs in place (Thomas Gleixner) [Orabug: 39849605] - x86/alternative: Support relocations in alternatives (Peter Zijlstra) [Orabug: 39849605] - x86/alternative: Make debug-alternative selective (Peter Zijlstra) [Orabug: 39849605] - x86/alternatives: Add alt_instr.flags (Borislav Petkov (AMD)) [Orabug: 39849605] - x86/asm: Provide ALTERNATIVE_3 (Peter Zijlstra) [Orabug: 39849605] - net: tap: set skb-dev before parsing virtio net header in tap_get_user_xdp() (Dongli Zhang) [Orabug: 39848314] [5.15.0-323.211.3.1] - net: openvswitch: reject oversized nested action attrs (Asim Viladi Oglu Manizada) [Orabug: 39816016] {CVE-2026-64531} - xfs: resample the data fork mapping after cycling ILOCK (Darrick J. Wong) [Orabug: 39816098] {CVE-2026-64600} [5.15.0-323.211.3] - LTS version: v5.15.211 (Vijayendra Suman) - dlm: prevent NPD when writing a positive value to event_done (Thadeu Lima de Souza Cascardo) [Orabug: 37844553] {CVE-2025-23131} - crypto: qat - remove unused character device and IOCTLs (Giovanni Cabiddu) [Orabug: 39786549] {CVE-2026-64529} - crypto: qat - Return pointer directly in adf_ctl_alloc_resources (Herbert Xu) - crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (Thorsten Blum) - Documentation: ioctl-number: Extend 'Include File' column width (Bagas Sanjaya) - ksmbd: reject non-VALID session in compound request branch (Gil Portnoy) - fuse: re-lock request before replacing page cache folio (Joanne Koong) [Orabug: 39753883] {CVE-2026-53388} - net: phonet: free phonet_device after RCU grace period (Santosh Kalluri) [Orabug: 39637380] {CVE-2026-53157} - phonet: Pass net and ifindex to phonet_address_notify(). (Kuniyuki Iwashima) - phonet: Pass ifindex to fill_addr(). (Kuniyuki Iwashima) - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (Dexuan Cui) - misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (Mukesh Ojha) - misc: fastrpc: Add dma_mask to fastrpc_channel_ctx (Abel Vesa) - hv: utils: handle and propagate errors in kvp_register (Thorsten Blum) - mptcp: fix missing wakeups in edge scenarios (Paolo Abeni) - NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (Michael Bommarito) [Orabug: 39753890] {CVE-2026-53391} - nfsd: check get_user() return when reading princhashlen (Dominik Wozniak) - nfsd: fix posix_acl leak on SETACL decode failure (Jeff Layton) [Orabug: 39753905] {CVE-2026-53397} - NFSD: Fix SECINFO_NO_NAME decode error cleanup (Guannan Wang) [Orabug: 39753909] {CVE-2026-53398} - fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (Steffen Persvold) - fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (Ian Bridges) [Orabug: 39753928] {CVE-2026-53403} - power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (Xu Wang) - KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (Ashutosh Desai) [Orabug: 39753936] {CVE-2026-63794} - ocfs2: reject oversized group bitmap descriptors (Zhang Cen) [Orabug: 39753942] {CVE-2026-63796} - fpga: region: fix use-after-free in child_regions_with_firmware() (Xu Wang) - irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove (Qingshuang Fu) - pNFS: Fix use-after-free in pnfs_update_layout() (Xu Wang) [Orabug: 39753953] {CVE-2026-63800} - tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Doruk Tan Ozturk) [Orabug: 39753957] {CVE-2026-63801} - hdlc_ppp: sync per-proto timers before freeing hdlc state (Fan Wu) [Orabug: 39753963] {CVE-2026-63803} - exfat: fix potential use-after-free in exfat_find_dir_entry() (Michael Bommarito) [Orabug: 39753979] {CVE-2026-63808} - MIPS: DEC: Prevent initial console buffer from landing in XKPHYS (Maciej W. Rozycki) - bpf: use kvfree() for replaced sysctl write buffer (Dawei Feng) [Orabug: 39753982] {CVE-2026-63809} - f2fs: validate ACL entry sizes in f2fs_acl_from_disk() (Zhang Cen) - wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (Bitterblue Smith) - wifi: ath11k: fix warning when unbinding (Jose Ignacio Tornos Martinez) [Orabug: 39754021] {CVE-2026-63822} - wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (Zenm Chen) - keys: Pin request_key_auth payload in instantiate paths (Shaomin Chen) [Orabug: 39754024] {CVE-2026-63823} - KEYS: fix overflow in keyctl_pkey_params_get_2() (Jarkko Sakkinen) [Orabug: 39754028] {CVE-2026-63824} - mac802154: llsec: add skb_cow_data() before in-place crypto (Doruk Tan Ozturk) [Orabug: 39754053] {CVE-2026-63831} - crypto: af_alg - Set merge to zero early in af_alg_sendmsg (Herbert Xu) [Orabug: 38503789] {CVE-2025-39931} - ext4: add bounds check for inline data length in ext4_read_inline_page (Yuto Ohnuki) - ntfs3: reject direct userspace writes to reserved * xattrs (Konstantin Komarov) - ring-buffer: Remove ring_buffer_read_prepare_sync() (Bjoern Doebel) - batman-adv: tvlv: avoid race of cifsnotfound handler state (Sven Eckelmann) - batman-adv: tvlv: enforce 2-byte alignment (Sven Eckelmann) - batman-adv: dat: prevent false sharing between VLANs (Sven Eckelmann) - batman-adv: tt: track roam count per VID (Sven Eckelmann) - batman-adv: tt: don't merge change entries with different VIDs (Sven Eckelmann) - batman-adv: tp_meter: handle overlapping packets (Sven Eckelmann) - batman-adv: tp_meter: prevent parallel modifications of last_recv (Sven Eckelmann) - batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE (Sven Eckelmann) - batman-adv: tp_meter: restrict number of unacked list entries (Sven Eckelmann) [Orabug: 39754066] {CVE-2026-63834} - batman-adv: v: prevent OGM aggregation on disabled hardif (Sven Eckelmann) [Orabug: 39754070] {CVE-2026-63835} - batman-adv: frag: avoid underflow of TTL (Sven Eckelmann) - batman-adv: frag: ensure fragment is writable before modifying TTL (Sven Eckelmann) - batman-adv: fix (m|b)cast csum after decrementing TTL (Sven Eckelmann) - batman-adv: ensure bcast is writable before modifying TTL (Sven Eckelmann) - batman-adv: tp_meter: initialize last_recv_time during init (Sven Eckelmann) - batman-adv: prevent ELP transmission interval underflow (Sven Eckelmann) - batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (Sven Eckelmann) - batman-adv: tp_meter: add only finished tp_vars to lists (Sven Eckelmann) - batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (Sven Eckelmann) - batman-adv: tp_meter: fix fast recovery precondition (Sven Eckelmann) - batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (Sven Eckelmann) [Orabug: 39754076] {CVE-2026-63836} - batman-adv: tp_meter: avoid window underflow (Sven Eckelmann) - batman-adv: tp_meter: initialize dec_cwnd explicitly (Sven Eckelmann) - batman-adv: tp_meter: initialize dup_acks explicitly (Sven Eckelmann) - batman-adv: tp_meter: keep unacked list in ascending ordered (Sven Eckelmann) - kselftest/arm64: signal: Skip SVE signal test if not enough VLs supported (Yijia Wang) - Revert 'ptp: add testptp mask test' (Petr Machata) - Revert 'selftest/ptp: update ptp selftest to exercise the gettimex options' (Petr Machata) - virtiofs: fix UAF on submount umount (Miklos Szeredi) [Orabug: 39753856] {CVE-2026-53381} - media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (Ruslan Valiyev) - vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (Yi Yang) [Orabug: 39753871] {CVE-2026-53385} - regulator: core: fix locking in regulator_resolve_supply() error path (Andre Draszik) [Orabug: 39489558] {CVE-2026-46252} - af_unix: Reject SIOCATMARK on non-stream sockets (Jiexun Wang) [Orabug: 39619334] {CVE-2026-52928} - xhci: fix memory leak regression when freeing xhci vdev devices depth first (Mathias Nyman) - agp/amd64: Fix broken error propagation in agp_amd64_probe() (Mingyu Wang) [Orabug: 39662073] {CVE-2026-53325} - net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (Weiming Shi) - i2c: stub: Reject I2C block transfers with invalid length (Weiming Shi) [Orabug: 39760892] {CVE-2026-64191} - RDMA/bnxt_re: zero shared page before exposing to userspace (Lord Ulf Henrik Holmberg) - iio: light: bh1780: fix PM runtime leak on error path (Antoniu Miclaus) - batman-adv: tt: prevent TVLV entry number overflow (Sven Eckelmann) - batman-adv: tt: reject oversized local TVLV buffers (Sven Eckelmann) - drm/v3d: Skip CSD when it has zeroed workgroups (Maira Canal) - drm/v3d: Store the active job inside the queue's state (Maira Canal) - ip6_vti: set netns_immutable on the fallback device. (Eric Dumazet) [Orabug: 39589885] {CVE-2026-52909} - drm/amd/display: Bound VBIOS record-chain walk loops (Harry Wentland) [Orabug: 39637312] {CVE-2026-53138} - fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (Jann Horn) [Orabug: 39637410] {CVE-2026-53167} - LTS version: v5.15.210 (Vijayendra Suman) - netfilter: require Ethernet MAC header before using eth_hdr() (Zhengchuan Liang) [Orabug: 39637279] {CVE-2026-53131} - batman-adv: tp_meter: avoid role confusion in tp_list (Sven Eckelmann) - batman-adv: tp_meter: fix race condition in send error reporting (Sven Eckelmann) - ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops (Ali Ganiyev) - Bluetooth: MGMT: Fix backward compatibility with userspace (Luiz Augusto von Dentz) - media: rc: igorplugusb: fix control request setup packet (Henri A) [Orabug: 39785220] {CVE-2026-64240} - batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown (Sven Eckelmann) [Orabug: 39784982] {CVE-2026-64092} - media: rc: ttusbir: fix inverted error logic (Oliver Neukum) - apparmor: validate default DFA states are in bounds (Ben Hutchings) - fbdev: vt8500lcdfb: Fix dma_free_coherent() cpu_addr parameter (Ben Hutchings) - mptcp: close TOCTOU race while computing rcv_wnd (Paolo Abeni) [Orabug: 39754146] {CVE-2026-63867} - arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU (Will Deacon) - arm64: errata: Mitigate TLBI errata on NVIDIA Olympus CPU (Shanker Donthineni) - arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39674327] {CVE-2026-53354} - arm64: cputype: Add NVIDIA Olympus definitions (Shanker Donthineni) - selinux: enable genfscon labeling for securityfs (Christian Gottsche) - ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (Aaron Erhardt) - ksmbd: Compare MACs in constant time (Eric Biggers) - net/ipv6: ioam6: prevent schema length wraparound in trace fill (Pengpeng Hou) [Orabug: 39343685] {CVE-2026-43341} - batman-adv: tp_meter: fix tp_num leak on kmalloc failure (Sven Eckelmann) - batman-adv: stop tp_meter sessions during mesh teardown (Jiexun Wang) [Orabug: 39460622] {CVE-2026-46208} - blk-cgroup: Fix NULL deref caused by blkg_policy_data being installed before init (Tejun Heo) - ipvs: skip ipv6 extension headers for csum checks (Julian Anastasov) [Orabug: 39451541] {CVE-2026-45850} - mm/huge_memory: update file PMD counter before folio_put() (Yin Tirui) [Orabug: 39637477] {CVE-2026-53189} - RDMA/umem: Fix truncation for block sizes = 4G (Jason Gunthorpe) - RDMA: Move DMA block iterator logic into dedicated files (Leon Romanovsky) - RDMA/umem: fix kernel-doc warnings (Randy Dunlap) - hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf (Anton Leontev) [Orabug: 39637516] {CVE-2026-53199} - netfilter: nft_fib: fix stale stack leak via the OIFNAME register (Davide Ornaghi) [Orabug: 39637292] {CVE-2026-53134} - serial: qcom-geni: fix UART_RX_PAR_EN bit position (Prasanna S) - tty: serial: qcom-geni-serial: align #define values (Bartosz Golaszewski) - tty: serial: qcom-geni-serial: remove unused symbols (Bartosz Golaszewski) - serial: altera_jtaguart: handle uart_add_one_port() failures (Myeonghun Pak) - serial: altera_jtaguart: Use platform_get_irq_optional() to get the interrupt (Lad Prabhakar) - drm/hyperv: validate resolution_count and fix WIN8 fallback (Berkant Koc) [Orabug: 39786537] {CVE-2026-64524} - drm/hyperv: Remove support for Hyper-V 2008 and 2008R2/Win7 (Michael Kelley) - usb: typec: ucsi: Check if power role change actually happened before handling (Myrrh Periwinkle) - thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (Michael Bommarito) [Orabug: 39754211] {CVE-2026-63891} - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (Guangshuo Li) - usb: gadget: f_hid: tidy error handling in hidg_alloc (John Keeping) - usb: dwc3: xilinx: fix error handling in zynqmp init error paths (Radhey Shyam Pandey) - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (Tudor Ambarus) [Orabug: 39786545] {CVE-2026-64528} - tty: serial: samsung: use u32 for register interactions (Tudor Ambarus) - serial: samsung_tty: Use port lock wrappers (Thomas Gleixner) - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (Peter Chen) - iio: dac: ad5686: fix ref bit initialization for single-channel parts (Rodrigo Alencar) - iio: chemical: scd30: fix division by zero in write_raw (Antoniu Miclaus) - iio: chemical: scd30: Use guard(mutex) to allow early returns (Jonathan Cameron) - iio: gyro: adis16260: fix division by zero in write_raw (Antoniu Miclaus) - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (Siwei Zhang) [Orabug: 39681273] {CVE-2026-53358} - phy: tegra: xusb: Fix per-pad high-speed termination calibration (Wayne Chang) - phy: tegra: xusb: Disable trk clk when not in use (Wayne Chang) - arm64: tlb: Flush walk cache when unsharing PMD tables (Zeng Heng) [Orabug: 39755010] {CVE-2026-63875} - spi: qup: fix error pointer deref after DMA setup failure (Johan Hovold) [Orabug: 39754942] {CVE-2026-64170} - spi: qup: switch to use modern name (Yang Yingliang) - octeontx2-pf: avoid double free of pool-stack on AQ init failure (Dawei Feng) - octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (Sam Daly) - mptcp: do not drop partial packets (Shardul Bankar) - selftests: mptcp: drop nanoseconds width specifier (Matthieu Baerts) - mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient (Li Xiasong) - use less confusing names for iov_iter direction initializers (Al Viro) - ipv6: ioam: add NULL check for idev in ipv6_hop_ioam() (Justin Iurman) [Orabug: 39754825] {CVE-2026-64116} - ipv6/addrconf: annotate data-races around devconf fields (II) (Eric Dumazet) - ice: fix VF queue configuration with low MTU values (Jose Ignacio Tornos Martinez) - net: hsr: defer node table free until after RCU readers (Michael Bommarito) [Orabug: 39754840] {CVE-2026-64123} - Bluetooth: serialize accept_q access (Jiexun Wang) [Orabug: 39619283] {CVE-2026-52918} - Bluetooth: Init sk_peer_* on bt_sock_alloc (Luiz Augusto von Dentz) - Bluetooth: Consolidate code around sk_alloc into a helper function (Luiz Augusto von Dentz) - qed: fix double free in qed_cxt_tables_alloc() (Dawei Feng) [Orabug: 39754830] {CVE-2026-64118} - Bluetooth: MGMT: validate Add Extended Advertising Data length (Michael Bommarito) [Orabug: 39754849] {CVE-2026-64126} - Bluetooth: hci_sync: Make use of hci_cmd_sync_queue set 2 (Luiz Augusto von Dentz) - Bluetooth: hci_qca: Convert timeout from jiffies to ms (Shuai Zhang) - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (Safa Karakus) [Orabug: 39681270] {CVE-2026-53357} - smb: client: require net admin for CIFS SWN netlink (Michael Bommarito) - genetlink: Use internal flags for multicast groups (Ido Schimmel) - spi: lantiq-ssc: fix controller deregistration (Johan Hovold) - spi: st-ssc4: fix controller deregistration (Johan Hovold) - f2fs: fix false alarm of lockdep on cp_global_sem lock (Chao Yu) - f2fs: fix incorrect file address mapping when inline inode is unwritten (Yongpeng Yang) - mptcp: pm: ADD_ADDR rtx: resched blocked ADD_ADDR quicker (Matthieu Baerts) - mptcp: pm: ADD_ADDR rtx: fix potential data-race (Matthieu Baerts) [Orabug: 39460320] {CVE-2026-46137} - mptcp: pm: prio: skip closed subflows (Matthieu Baerts) - smb: client: Use FullSessionKey for AES-256 encryption key derivation (Piyush Sachdeva) - btrfs: fix missing last_unlink_trans update when removing a directory (Filipe Manana) [Orabug: 39460410] {CVE-2026-46160} - smb: client: validate dacloffset before building DACL pointers (Michael Bommarito) - pmdomain: core: Fix detach procedure for virtual devices in genpd (Ulf Hansson) [Orabug: 39524579] {CVE-2026-46292} - tracing/probes: Limit size of event probe to 3K (Steven Rostedt) - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (Yochai Eisenrich) [Orabug: 39460405] {CVE-2026-46159} - spi: topcliff-pch: fix controller deregistration (Johan Hovold) - spi: topcliff-pch: Convert to platform remove callback returning void (Uwe Kleine-Konig) - fbcon: Avoid OOB font access if console rotation fails (Thomas Zimmermann) [Orabug: 39460548] {CVE-2026-46191} - mm/hugetlb_cma: round up per_node before logging it (Sang-Heon Jeon) - spi: uniphier: fix controller deregistration (Johan Hovold) - spi: tegra20-sflash: fix controller deregistration (Johan Hovold) - spi: tegra114: fix controller deregistration (Johan Hovold) - spi: sun6i: fix controller deregistration (Johan Hovold) - spi: zynq-qspi: fix controller deregistration (Johan Hovold) - spi: ti-qspi: fix controller deregistration (Johan Hovold) - spi: spi-ti-qspi: Convert to platform remove callback returning void (Uwe Kleine-Konig) - spi: sun4i: fix controller deregistration (Johan Hovold) - spi: syncuacer: fix controller deregistration (Johan Hovold) - xfrm: ah: account for ESN high bits in async callbacks (Michael Bommarito) [Orabug: 39460554] {CVE-2026-46193} - net: ipv6: stop checking crypto_ahash_alignmask (Eric Biggers) - net: ipv4: stop checking crypto_ahash_alignmask (Eric Biggers) - usb: dwc3: Move GUID programming after PHY initialization (Selvarasu Ganesan) - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (Marek Szyprowski) [Orabug: 39460504] {CVE-2026-46180} - usb: typec: tcpm: reset internal port states on soft reset AMS (Amit Sunil Dhamne) - smb: client: validate the whole DACL before rewriting it in cifsacl (Michael Bommarito) - tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() (David Carlier) [Orabug: 39460568] {CVE-2026-46196} - crypto: caam - guard HMAC key hex dumps in hash_digest_key (Thorsten Blum) - printk: add print_hex_dump_devel() (Thorsten Blum) - ALSA: aloop: Fix peer runtime UAF during format-change stop (Cassio Gabriel) [Orabug: 39452424] {CVE-2026-46090} - ceph: only d_add() negative dentries when they are unhashed (Max Kellermann) [Orabug: 39452292] {CVE-2026-46052} - erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() (Junrui Luo) - can: ucan: fix devres lifetime (Johan Hovold) - can: ucan: fix typos in comments (Julia Lawall) - Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (Shuvam Pandey) [Orabug: 39452305] {CVE-2026-46056} - hfsplus: fix held lock freed on hfsplus_fill_super() (Zilin Guan) - hfsplus: fix uninit-value by validating catalog record size (Deepanshu Kartikey) - udf: fix partition descriptor append bookkeeping (Seohyeon Maeng) [Orabug: 39452078] {CVE-2026-45991} - mtd: spi-nor: sst: Fix write enable before AAI sequence (Sanjaikumar V S) - mmc: sdhci-of-dwcmshc: Disable clock before DLL configuration (Shawn Lin) - randomize_kstack: Maintain kstack_offset per task (Ryan Roberts) - fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info (Thomas Zimmermann) [Orabug: 39452332] {CVE-2026-46065} - net: bridge: use a stable FDB dst snapshot in RCU readers (Zhengchuan Liang) [Orabug: 39452412] {CVE-2026-46086} - net: qrtr: ns: Limit the total number of nodes (Manivannan Sadhasivam) [Orabug: 39452124] {CVE-2026-46003} - net: mctp: fix don't require received header reserved bits to be zero (Yuanzhaoming) - net: qrtr: ns: Free the node during ctrl_cmd_bye() (Manivannan Sadhasivam) [Orabug: 39452247] {CVE-2026-46038} - net: qrtr: ns: Change servers radix tree to xarray (Vignesh Viswanathan) - net: qrtr: ns: Limit the maximum number of lookups (Manivannan Sadhasivam) [Orabug: 39452208] {CVE-2026-46026} - ALSA: core: Fix potential data race at fasync handling (Takashi Iwai) - sched: Use u64 for bandwidth ratio calculations (Joseph Salisbury) - media: rc: igorplugusb: heed coherency rules (Oliver Neukum) [Orabug: 39452433] {CVE-2026-46091} - erofs: fix the out-of-bounds nameoff handling for trailing dirents (Gao Xiang) - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (Thorsten Blum) - media: rc: ttusbir: respect DMA coherency rules (Oliver Neukum) - ALSA: aoa: i2sbus: clear stale prepared state (Cassio Gabriel) - ALSA: aoa: Use guard() for mutex locks (Takashi Iwai) - wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (Daniel Hodges) [Orabug: 39452344] {CVE-2026-46069} - thermal: core: Fix thermal zone governor cleanup issues (Rafael J. Wysocki) [Orabug: 39452187] {CVE-2026-46021} - wifi: rtw88: check for PCI upstream bridge existence (Fedor Pchelkin) [Orabug: 39452438] {CVE-2026-46092} - rtw88: 8821ce: Disable PCIe ASPM L1 for 8821CE using chip ID (Jimmy Hon) - arm64/mm: Enable batched TLB flush in unmap_hotplug_range() (Anshuman Khandual) - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (Bingquan Chen) [Orabug: 39300581] {CVE-2026-31700} - ksmbd: require minimum ACE size in smb_check_perm_dacl() (Michael Bommarito) - smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path (Michael Bommarito) - smb: client: require a full NFS mode SID before reading mode bits (Michael Bommarito) - smb: server: fix max_connections off-by-one in tcp accept path (Daemyung Kang) - smb: server: fix active_num_conn leak on transport allocation failure (Michael Bommarito) - f2fs: fix UAF caused by decrementing sbi-nr_pages[] in f2fs_write_end_io() (Yongpeng Yang) - f2fs: fix to do sanity check on dcc-discard_cmd_cnt conditionally (Chao Yu) - lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (Lukas Wunner) - net/tcp-md5: Fix MAC comparison to be constant-time (Eric Biggers) [Orabug: 39343806] {CVE-2026-43383} - io_uring/poll: fix signed comparison in io_poll_get_ownership() (Longxuan Yu) [Orabug: 39619351] {CVE-2026-52933} - mm/damon/ops-common: call folio_test_lru() after folio_get() (Seongjae Park) - fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (Mingyu Wang) [Orabug: 39655978] {CVE-2026-52946} - drm/amd/display: Use krealloc_array() in dal_vector_reserve() (Harry Wentland) [Orabug: 39674253] {CVE-2026-53329} - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (Harry Wentland) [Orabug: 39637296] {CVE-2026-53135} - drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (Harry Wentland) [Orabug: 39637301] {CVE-2026-53136} - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (Harry Wentland) - slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl-lock (Bjorn Andersson) - thunderbolt: Limit XDomain response copy to actual frame size (Michael Bommarito) [Orabug: 39637337] {CVE-2026-53146} - thunderbolt: Clamp XDomain response data copy to allocation size (Michael Bommarito) [Orabug: 39637346] {CVE-2026-53148} - thunderbolt: Bound root directory content to block size (Michael Bommarito) [Orabug: 39637351] {CVE-2026-53149} - thunderbolt: Reject zero-length property entries in validator (Michael Bommarito) [Orabug: 39637356] {CVE-2026-53150} - sctp: stream: fully roll back denied add-stream state (Wyatt Feng) [Orabug: 39619338] {CVE-2026-52929} - sctp: diag: reject stale associations in dump_one path (Zhao Zhang) [Orabug: 39619278] {CVE-2026-52917} - mmc: sdhci: add signal voltage switch in sdhci_resume_host (Jisheng Zhang) - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (Lad Prabhakar) - mmc: core: Fix host controller programming for fixed driver type (Kamal Dasu) - net: mv643xx: fix OF node refcount (Bartosz Golaszewski) - net: bonding: fix NULL pointer dereference in bond_do_ioctl() (Zhaojinming) [Orabug: 39674284] {CVE-2026-53337} - misc: fastrpc: fix DMA address corruption due to find_vma misuse (Junrui Luo) - misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (Anandu Krishnan E) - ipc/shm: serialize orphan cleanup with shm_nattch updates (Yilin Zhu) [Orabug: 39619342] {CVE-2026-52930} - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (Cryolitia Pukngae) - Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (Zeyu Wang) - i2c: tegra: Fix NOIRQ suspend/resume (Akhil R) - i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (Guillermo Rodriguez) - i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (Vladimir Zapolskiy) - fuse: reject fuse_notify() pagecache ops on directories (Jann Horn) [Orabug: 39637414] {CVE-2026-53168} - pidfd: refuse access to tasks that have started exiting harder (Christian Brauner) - IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (Michael Bommarito) [Orabug: 39637428] {CVE-2026-53176} - bnxt_en: Fix NULL pointer dereference (Kyle Meyer) [Orabug: 39637432] {CVE-2026-53177} - vsock/vmci: fix sk_ack_backlog leak on failed handshake (Raf Dickson) [Orabug: 39637447] {CVE-2026-53181} - mptcp: sockopt: check timestamping ret value (Matthieu Baerts) - mptcp: fix retransmission loop when csum is enabled (Paolo Abeni) - ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O (Karl Mehltretter) - ARM: socfpga: Fix OF node refcount leak in SMP setup (Yuho Choi) - RDMA/srp: bound SRP_RSP sense copy by the received length (Michael Bommarito) [Orabug: 39637467] {CVE-2026-53186} - drm/amd/display: Reject gpio_bitshift = 32 in bios_parser_get_gpio_pin_info() (Harry Wentland) - ALSA: timer: Fix UAF at snd_timer_user_params() (Takashi Iwai) [Orabug: 39637489] {CVE-2026-53192} - USB: serial: kl5kusb105: fix bulk-out buffer overflow (Hyeongjun An) [Orabug: 39637496] {CVE-2026-53194} - USB: serial: option: add usb-id for Dell Wireless DW5826e-m (Jack Wu) - USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (Adrian Korwel) [Orabug: 39637502] {CVE-2026-53195} - USB: serial: io_ti: fix heap overflow in get_manuf_info() (Adrian Korwel) [Orabug: 39637506] {CVE-2026-53196} - xfrm: espintcp: do not reuse an in-progress partial send (Wyatt Feng) - drm/i915/gem: Fix phys BO pread/pwrite with offset (Joonas Lahtinen) [Orabug: 39674335] {CVE-2026-53356} - Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (Michael Bommarito) [Orabug: 39637545] {CVE-2026-53208} - netfilter: nft_tunnel: fix use-after-free on object destroy (Tristan Madani) [Orabug: 39637555] {CVE-2026-53212} - drm/vc4: fix krealloc() memory leak (Alexander A. Klimov) [Orabug: 39637561] {CVE-2026-53213} - net: mvpp2: build skb from XDP-adjusted data on XDP_PASS (Til Kaiser) - net: mvpp2: refill RX buffers before XDP or skb use (Til Kaiser) [Orabug: 39637568] {CVE-2026-53215} - net: mvpp2: Add metadata support for xdp mode (Lorenzo Bianconi) - net: mvpp2: limit XDP frame size to the RX buffer (Til Kaiser) [Orabug: 39637571] {CVE-2026-53216} - net: mvpp2: sync RX data at the hardware packet offset (Til Kaiser) [Orabug: 39637575] {CVE-2026-53217} - netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (Florian Westphal) [Orabug: 39637578] {CVE-2026-53218} - netfilter: nf_log: validate MAC header was set before dumping it (Xiang Mei) [Orabug: 39619384] {CVE-2026-52942} - netfilter: x_tables: avoid leaking percpu counter pointers (Kyle Zeng) [Orabug: 39637582] {CVE-2026-53219} - ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() (Eric Dumazet) [Orabug: 39637592] {CVE-2026-53221} - net: guard timestamp cmsgs to real error queue skbs (Kyle Zeng) [Orabug: 39637599] {CVE-2026-53223} - sctp: fix uninit-value in __sctp_rcv_asconf_lookup() (Michael Bommarito) [Orabug: 39637609] {CVE-2026-53225} - net: openvswitch: fix possible kfree_skb of ERR_PTR (Adrian Moreno) [Orabug: 39637618] {CVE-2026-53227} - ipv6: sit: reload inner IPv6 header after GSO offloads (Kyle Zeng) [Orabug: 39637622] {CVE-2026-53228} - net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Mingyu Wang) [Orabug: 39621562] {CVE-2026-52947} - netlabel: validate unlabeled address and mask attribute lengths (Chenguang Zhao) [Orabug: 39637662] {CVE-2026-53238} - xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (Sanghyun Park) [Orabug: 39637666] {CVE-2026-53239} - arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (Mark Rutland) - KVM: arm64: Remove VPIPT I-cache handling (Marc Zyngier) - nfsd: don't ignore the return code of svc_proc_register() (Jeff Layton) [Orabug: 37844165] {CVE-2025-22026} - fs/ntfs3: Return error for inconsistent extended attributes (Edward Lo) - ext4: validate p_idx bounds in ext4_ext_correct_indexes (Tejas Bharambe) [Orabug: 39250744] {CVE-2026-31449} - time: Fix off-by-one in settimeofday() usec validation (Naveen Kumar Chaudhary) - signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() (Aleksandr Nogikh) [Orabug: 39674319] {CVE-2026-53352} - sctp: purge outqueue on stale COOKIE-ECHO handling (Xin Long) [Orabug: 39619311] {CVE-2026-52924} - net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (Yizhou Zhao) [Orabug: 39637680] {CVE-2026-53245} - ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() (Eric Dumazet) [Orabug: 39754155] {CVE-2026-63870} - ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (Eric Dumazet) [Orabug: 39637694] {CVE-2026-53249} - Bluetooth: fix memory leak in error path of hci_alloc_dev() (Bharath Reddy) [Orabug: 39785002] {CVE-2026-53252} - Bluetooth: bnep: reject short frames before parsing (Zhang Cen) [Orabug: 39637706] {CVE-2026-53253} - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (Dudu Lu) - Bluetooth: RFCOMM: validate skb length in MCC handlers (Seungju Cheon) [Orabug: 39637711] {CVE-2026-53254} - Bluetooth: MGMT: validate advertising TLV before type checks (Zhang Cen) [Orabug: 39637716] {CVE-2026-53255} - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (Zhang Cen) [Orabug: 39637720] {CVE-2026-53256} - net: lan743x: permit VLAN-tagged packets up to configured MTU (David Thompson) - net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (Yizhou Zhao) [Orabug: 39754149] {CVE-2026-63868} - pcnet32: stop holding device spin lock during napi_complete_done (Oscar Maes) - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (Yicong Hui) - 6lowpan: fix off-by-one in multicast context address compression (Yizhou Zhao) [Orabug: 39637741] {CVE-2026-53263} - net/sched: act_api: use RCU with deferred freeing for action lifecycle (Jamal Hadi Salim) [Orabug: 39637748] {CVE-2026-53264} - dm cache policy smq: check allocation under invalidate lock (Guangshuo Li) [Orabug: 39784967] {CVE-2026-53265} - netfilter: bridge: make ebt_snat ARP rewrite writable (Yiming Qian) [Orabug: 39637753] {CVE-2026-53266} - netfilter: conntrack_irc: fix possible out-of-bounds read (Florian Westphal) [Orabug: 39637763] {CVE-2026-53268} - netfilter: synproxy: add mutex to guard hook reference counting (Fernando Fernandez Mancera) [Orabug: 39637768] {CVE-2026-53269} - ipvs: clear the svc scheduler ptr early on edit (Julian Anastasov) [Orabug: 39637772] {CVE-2026-53270} - netfilter: xt_NFQUEUE: prefer raw_smp_processor_id (Fernando Fernandez Mancera) - tee: optee: prevent use-after-free when the client exits before the supplicant (Amirreza Zarrabi) [Orabug: 39637782] {CVE-2026-53273} - ipv6: mcast: Fix use-after-free when processing MLD queries (Ido Schimmel) [Orabug: 39637790] {CVE-2026-53275} - i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (Mingyu Wang) [Orabug: 39621568] {CVE-2026-52948} - Disable -Wattribute-alias for clang-23 and newer (Nathan Chancellor) - compiler-clang.h: Add __diag infrastructure for clang (Nathan Chancellor) - USB: serial: mct_u232: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754236] {CVE-2026-63898} - bpf: Free reuseport cBPF prog after RCU grace period. (Kuniyuki Iwashima) [Orabug: 39589889] {CVE-2026-52910} - usb: core: Fix SuperSpeed root hub wMaxPacketSize (Michal Pecio) - serial: dz: Fix bootconsole handover lockup (Maciej W. Rozycki) - xhci: tegra: Fix ghost USB device on dual-role port unplug (Wei-Cheng Chen) - USB: serial: digi_acceleport: fix memory corruption with small endpoints (Johan Hovold) [Orabug: 39754248] {CVE-2026-63901} - HID: core: Fix size_t specifier in hid_report_raw_event() (Nathan Chancellor) - HID: pass the buffer size to hid_report_raw_event (Benjamin Tissoires) - HID: core: Add printk_ratelimited variants to hid_warn() etc (Vicki Pfau) - USB: serial: cypress_m8: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754408] {CVE-2026-63956} - serial: zs: Switch to using channel reset (Maciej W. Rozycki) - serial: zs: Fix bootconsole handover lockup (Maciej W. Rozycki) - serial: dz: Fix bootconsole message clobbering at chip reset (Maciej W. Rozycki) - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (Shitalkumar Gandhi) - serial: zs: Fix swapped RI/DSR modem line transition counting (Maciej W. Rozycki) - serial: sh-sci: fix memory region release in error path (Hongling Zeng) - drm/hyperv: validate VMBus packet size in receive callback (Berkant Koc) [Orabug: 39786542] {CVE-2026-64527} - thunderbolt: property: Reject dir_len 4 to prevent size_t underflow (Michael Bommarito) [Orabug: 39754216] {CVE-2026-63892} - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (Michael Bommarito) [Orabug: 39754220] {CVE-2026-63893} - usb: gadget: f_fs: copy only received bytes on short ep0 read (Michael Bommarito) - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (Seungjin Bae) - usb: gadget: net2280: Fix double free in probe error path (Guangshuo Li) - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (Johan Hovold) [Orabug: 39754232] {CVE-2026-63897} - USB: serial: mxuport: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754240] {CVE-2026-63899} - USB: serial: keyspan: fix missing indat transfer sanity check (Johan Hovold) [Orabug: 39754244] {CVE-2026-63900} - USB: serial: cypress_m8: validate interrupt packet headers (Zhang Cen) [Orabug: 39754252] {CVE-2026-63902} - USB: serial: belkin_sa: validate interrupt status length (Zhang Cen) [Orabug: 39754256] {CVE-2026-63903} - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (Wanquan Zhong) - USB: serial: option: add MeiG SRM813Q (Jan Volckaert) - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (Heitor Alves de Siqueira) - usb: usbtmc: check URB actual_length for interrupt-IN notifications (Heitor Alves de Siqueira) [Orabug: 39754260] {CVE-2026-63904} - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (Michael Bommarito) [Orabug: 39754264] {CVE-2026-63905} - usb: storage: Add quirks for PNY Elite Portable SSD (Sam Burkels) - USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (Stephen J. Fuhry) - usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (Michal Pecio) - usb: chipidea: core: convert ci_role_switch to local variable (Xu Yang) - tty: serial: pch_uart: add check for dma_alloc_coherent() (Zhaoyang Yu) - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (Ian Abbott) - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (Ian Abbott) - Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (Nicolas Bazaes) - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (Dmitry Torokhov) [Orabug: 39754271] {CVE-2026-63908} - xfrm: esp: restore combined single-frag length gate (Jingguo Tan) [Orabug: 39754278] {CVE-2026-63912} - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (Srinivas Kandagatla) - ASoC: qcom: q6asm-dai: close stream only when running (Srinivas Kandagatla) - netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check (Hamza Mahfooz) [Orabug: 39754282] {CVE-2026-63913} - xfrm: ah: use skb_to_full_sk in async output callbacks (Michael Bommarito) - xfrm: route MIGRATE notifications to caller's netns (Maoyi Xie) [Orabug: 39754286] {CVE-2026-63914} - nfc: hci: fix out-of-bounds read in HCP header parsing (Ashutosh Desai) - iommu, debugobjects: avoid gcc-16.1 section mismatch warnings (Arnd Bergmann) - HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (Lee Jones) [Orabug: 39754294] {CVE-2026-63916} - ip6: vti: Use ip6_tnl.net in vti6_changelink(). (Kuniyuki Iwashima) [Orabug: 39754298] {CVE-2026-63917} - xfrm: input: hold netns during deferred transport reinjection (Zhengchuan Liang) [Orabug: 39754304] {CVE-2026-63919} - ipv6: validate extension header length before copying to cmsg (Qi Tang) [Orabug: 39754307] {CVE-2026-63920} - ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). (Maoyi Xie) [Orabug: 39754311] {CVE-2026-63921} - ipv6: exthdrs: refresh nh after handling HAO option (Zhengchuan Liang) [Orabug: 39754315] {CVE-2026-63922} - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (Srinivas Kandagatla) - ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() (Justin Iurman) [Orabug: 39754322] {CVE-2026-63924} - macsec: fix replay protection at XPN lower-PN wrap (Junrui Luo) [Orabug: 39754326] {CVE-2026-63925} - bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (Yuqi Xu) [Orabug: 39754329] {CVE-2026-63926} - Input: elan_i2c - validate firmware size before use (Dmitry Torokhov) [Orabug: 39785158] {CVE-2026-64237} - usb: dwc2: Fix use after free in debug code (Dan Carpenter) [Orabug: 39754333] {CVE-2026-63927} - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (Peter Chen) - usb: cdns3: gadget: fix request skipping after clearing halt (Yongchao Wu) - USB: serial: omninet: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754337] {CVE-2026-63928} - iio: buffer: hw-consumer: fix use-after-free in error path (Felix Gu) - iio: light: cm3323: fix reg_conf not being initialized correctly (Aldo Conte) - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (Advait Dhamorikar) - iio: temperature: tsys01: fix broken PROM checksum validation (Salah Triki) - iio: ssp_sensors: cancel delayed work_refresh on remove (Sanjay Chitroda) - iio: gyro: itg3200: fix i2c read into the wrong stack location (David Carlier) - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (Salah Triki) - wireguard: send: append trailer after expanding head (Jason A. Donenfeld) - iio: dac: ad5686: fix input raw value check (Rodrigo Alencar) - iio: dac: max5821: fix return value check in powerdown sync (Salah Triki) - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (Christofer Jonason) - parport: Fix race between port and client registration (Ben Hutchings) [Orabug: 39754375] {CVE-2026-63942} - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (Muhammad Bilal) [Orabug: 39754387] {CVE-2026-63947} - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (Siwei Zhang) [Orabug: 39754391] {CVE-2026-63948} - ipc: limit next_id allocation to the valid ID range (Linpu Yu) [Orabug: 39619307] {CVE-2026-52923} - hpfs: fix a crash if hpfs_map_dnode_bitmap fails (Mikulas Patocka) - Bluetooth: btusb: Allow firmware re-download when version matches (Shuai Zhang) - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (Thomas Fourier) - USB: serial: safe_serial: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754412] {CVE-2026-63957} - usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (Greg Kroah-Hartman) - usb: typec: altmodes/displayport: validate count before reading Status Update VDO (Greg Kroah-Hartman) [Orabug: 39754428] {CVE-2026-63961} - usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (Greg Kroah-Hartman) - usb: typec: ucsi: ccg: reject firmware images without a ':' record header (Greg Kroah-Hartman) - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (Greg Kroah-Hartman) - smb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path (Stefan Metzmacher) - phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X (Horatiu Vultur) - phy: mscc: Use PHY_ID_MATCH_VENDOR to minimize PHY ID table (Harini Katakam) - RDMA/rxe: Fix double free in rxe_srq_from_init (Jiasheng Jiang) [Orabug: 39451551] {CVE-2026-45852} - Revert 'RDMA/rxe: Fix double free in rxe_srq_from_init' (Ben Hutchings) - drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used (Jouni Hogander) - drm/dp: Add eDP 1.5 bit definition (Suraj Kandpal) - drm/i915/psr: Read Intel DPCD workaround register (Jouni Hogander) - drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (Jouni Hogander) - wifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work (Duoming Zhou) [Orabug: 38456849] {CVE-2025-39863} - batman-adv: bla: avoid double decrement of bla.num_requests (Sven Eckelmann) [Orabug: 39754761] {CVE-2026-64095} - batman-adv: tt: avoid empty VLAN responses (Sven Eckelmann) [Orabug: 39754744] {CVE-2026-64090} - batman-adv: tt: fix TOCTOU race for reported vlans (Sven Eckelmann) [Orabug: 39754748] {CVE-2026-64091} - batman-adv: iv: recover OGM scheduling after forward packet error (Sven Eckelmann) - batman-adv: tvlv: reject oversized TVLV packets (Sven Eckelmann) [Orabug: 39619357] {CVE-2026-52934} - batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface (Sven Eckelmann) [Orabug: 39754757] {CVE-2026-64094} - batman-adv: tvlv: abort OGM send on tvlv append failure (Sven Eckelmann) - batman-adv: v: stop OGMv2 on disabled interface (Sven Eckelmann) - sctp: fix race between sctp_wait_for_connect and peeloff (Zhenghang Xiao) [Orabug: 39754456] {CVE-2026-63971} - gpio: rockchip: convert bank-clk to devm_clk_get_enabled() (Marco Scardovi) - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (Luiz Augusto von Dentz) [Orabug: 39754468] {CVE-2026-63975} - Bluetooth: l2cap: clear chan-ident on ECRED reconfiguration success (Zhenghang Xiao) [Orabug: 39754471] {CVE-2026-63976} - ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (Rahul Chandelkar) [Orabug: 39754489] {CVE-2026-63984} - ethtool: eeprom: add more safeties to EEPROM Netlink fallback (Jakub Kicinski) [Orabug: 39754492] {CVE-2026-63985} - bonding: refuse to enslave CAN devices (Oliver Hartkopp) [Orabug: 39754502] {CVE-2026-63990} - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (Zhao Dongdong) - ASoC: codecs: simple-mux: Fix enum control bounds check (Cassio Gabriel) - tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (Eric Dumazet) [Orabug: 39754510] {CVE-2026-63992} - vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() (Eric Dumazet) [Orabug: 39754513] {CVE-2026-63993} - tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() (Eric Dumazet) [Orabug: 39754516] {CVE-2026-63994} - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (Cassio Gabriel) - ipv4: free net-ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (Eric Dumazet) [Orabug: 39754536] {CVE-2026-64002} - net/iucv: fix locking in .getsockopt (Breno Leitao) - net/smc: Do not re-initialize smc hashtables (Alexandra Winter) - net: netlink: don't set nsid on local notifications (Ilya Maximets) - net: netlink: fix sending unassigned nsid after assigned one (Ilya Maximets) - netfilter: ebtables: fix OOB read in compat_mtw_from_user (Florian Westphal) [Orabug: 39619329] {CVE-2026-52927} - netfilter: xt_cpu: prefer raw_smp_processor_id (Florian Westphal) - netfilter: synproxy: refresh tcphdr after skb_ensure_writable (Chris Mason) [Orabug: 39754553] {CVE-2026-64007} - nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems (Carl Lee) - xfrm: Check for underflow in xfrm_state_mtu (David Ahern) [Orabug: 39754558] {CVE-2026-64009} - nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (Lee Jones) - nfc: llcp: Fix use-after-free in llcp_sock_release() (Lee Jones) - net: cpsw_new: Fix potential unregister of netdev that has not been registered yet (Kevin Hao) - dmaengine: idxd: Fix not releasing workqueue on .release() (Vinicius Costa Gomes) [Orabug: 39323060] {CVE-2026-43064} - drm: Remove plane hsub/vsub alignment requirement for core helpers (Carlos Eduardo Gallo Filho) - net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Victor Nogueira) [Orabug: 39754570] {CVE-2026-64012} - net: mctp: ensure our nlmsg responses are initialised (Jeremy Kerr) - net/sched: cls_fw: fix NULL dereference of 'old' filters before change() (Davide Caratti) [Orabug: 39622011] {CVE-2026-53080} - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (Greg Kroah-Hartman) [Orabug: 39754575] {CVE-2026-64014} - LTS version: v5.15.209 (Samasth Norway Ananda) - net: mana: validate rx_req_idx to prevent out-of-bounds array access (Aditya Garg) [Orabug: 39754586] {CVE-2026-64018} - gpio: cdev: check if uAPI v2 config attributes are correctly zeroed (Bartosz Golaszewski) - gpiolib: cdev: use !mem_is_zero() instead of memchr_inv(s, 0, n) (Andy Shevchenko) - string: add mem_is_zero() helper to check if memory area is all zeros (Jani Nikula) - net: ag71xx: check error for platform_get_irq (Rosen Penev) - tracing: Avoid NULL return from hist_field_name() on truncation (David Carlier) [Orabug: 39784962] {CVE-2026-64028} - bridge: mcast: Fix a possible use-after-free when removing a bridge port (Ido Schimmel) [Orabug: 39754613] {CVE-2026-64032} - net: bridge: Flush multicast groups when snooping is disabled (Petr Machata) - RDMA/rtrs: Fix use-after-free in path file creation cleanup (Guangshuo Li) - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki) - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki) - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (Rafael J. Wysocki) - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki) - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (Erni Sri Satya Vennela) [Orabug: 39754619] {CVE-2026-64034} - net: dsa: mt7530: preserve VLAN tags on trapped link-local frames (Daniel Golle) - net: dsa: mt7530: rename mt753x_bpdu_port_fw enum to mt753x_to_cpu_fw (Arinc Unal) - net: dsa: mt7530: fix FDB entries not aging out with short timeout (Daniel Golle) - net: dsa: mt7530: sync driver-specific behavior of MT7531 variants (Daniel Golle) - drm/msm/snapshot: fix dumping of the unaligned regions (Dmitry Baryshkov) [Orabug: 39754629] {CVE-2026-64039} - net: tls: prevent chain-after-chain in plain text SG (Jakub Kicinski) [Orabug: 39754638] {CVE-2026-64046} - net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (Jakub Kicinski) [Orabug: 39754642] {CVE-2026-64047} - drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN (Mikko Perttunen) [Orabug: 39754904] {CVE-2026-64153} - ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics (Chenguang Zhao) - HID: quirks: really enable the intended work around for appledisplay (Lukas Bulwahn) - wifi: ath11k: fix error path leaks in some WMI WOW calls (Nicolas Escande) [Orabug: 39754909] {CVE-2026-64155} - net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference (Ethan Nelson-Moore) - net: ethernet: cortina: Carry over frag counter (Linus Walleij) - net: ethernet: cortina: Drop half-assembled SKB (Andreas Haarmann-Thiemann) - net: ethernet: cortina: Make RX SKB per-port (Linus Walleij) - irqchip/ath79-cpu: Remove unused function (Rosen Penev) - phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access (Gabor Juhos) - ice: fix locking in ice_dcb_rebuild() (Bart Van Assche) - tcp: Fix imbalanced icsk_accept_queue count. (Kuniyuki Iwashima) - netfilter: x_tables: unregister the templates first (Florian Westphal) - ARM: integrator: Fix early initialization (Guenter Roeck) - kunit: config: KUNIT_DEBUGFS should depend on DEBUG_FS (David Gow) - kunit: config: Enable KUNIT_DEBUGFS by default (David Gow) - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (Sudeep Holla) - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (Sudeep Holla) [Orabug: 39754932] {CVE-2026-64166} - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (Abdurrahman Hussain) - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (Abdurrahman Hussain) - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (Abdurrahman Hussain) - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (Abdurrahman Hussain) - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (Abdurrahman Hussain) - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (Abdurrahman Hussain) - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (Abdurrahman Hussain) - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (Abdurrahman Hussain) - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (Abdurrahman Hussain) - batman-adv: tt: fix negative tt_buff_len (Sven Eckelmann) [Orabug: 39754734] {CVE-2026-64088} - batman-adv: tt: fix negative last_changeset_len (Sven Eckelmann) [Orabug: 39754740] {CVE-2026-64089} - batman-adv: tp_meter: avoid use of uninit sender vars (Sven Eckelmann) [Orabug: 39619346] {CVE-2026-52931} - batman-adv: bla: fix report_work leak on backbone_gw purge (Sven Eckelmann) [Orabug: 39785109] {CVE-2026-64218} - batman-adv: frag: disallow unicast fragment in fragment (Sven Eckelmann) [Orabug: 39619274] {CVE-2026-52916} - batman-adv: fix tp_meter counter underflow during shutdown (Luxiao Xu) [Orabug: 39619287] {CVE-2026-52919} - batman-adv: fix fragment reassembly length accounting (Ruide Cao) [Orabug: 39619266] {CVE-2026-52914} - batman-adv: dat: handle forward allocation error (Sven Eckelmann) - batman-adv: clear current gateway during teardown (Ruijie Li) [Orabug: 39619323] {CVE-2026-52926} - batman-adv: mcast: fix use-after-free in orig_node RCU release (Sven Eckelmann) [Orabug: 39754765] {CVE-2026-64096} - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (Harry Wentland) [Orabug: 39785113] {CVE-2026-64219} - drm/amd/display: Fix integer overflow in bios_get_image() (Harry Wentland) - drm/bridge: megachips: remove bridge when irq request fails (Osama Abdelkader) - drm/bridge: it66121: acquire reset GPIO in probe (Julien Chauveau) - device property: set fwnode-secondary to NULL in fwnode_init() (Bartosz Golaszewski) [Orabug: 39785117] {CVE-2026-64220} - RDMA/siw: Reject MPA FPDU length underflow before signed receive math (Michael Bommarito) - spi: ti-qspi: fix use-after-free after DMA setup failure (Johan Hovold) - spi: sprd: fix error pointer deref after DMA setup failure (Johan Hovold) - scsi: isci: Fix use-after-free in device removal path (Michael Bommarito) [Orabug: 39754786] {CVE-2026-64103} - tracing: Do not call map-ops-elt_free() if elt_alloc() fails (Masami Hiramatsu) [Orabug: 39754948] {CVE-2026-64173} - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (John Walker) [Orabug: 39754952] {CVE-2026-64174} - ixgbevf: fix use-after-free in VEPA multicast source pruning (Michael Bommarito) [Orabug: 39754812] {CVE-2026-64113} - ipv4: raw: reject IP_HDRINCL packets with ihl 5 (Michael Bommarito) [Orabug: 39754817] {CVE-2026-64114} - wifi: ath11k: clear shared SRNG pointer state on restart (Kyle Farnung) - vsock/vmci: fix UAF when peer resets connection during handshake (Minh Nguyen) [Orabug: 39754821] {CVE-2026-64115} - ring-buffer: Fix reporting of missed events in iterator (Steven Rostedt) - netfilter: ipset: stop hash:* range iteration at end (Nan Li) [Orabug: 39619299] {CVE-2026-52921} - netfilter: nf_queue: hold bridge skb-dev while queued (Haoze Xie) [Orabug: 39619255] {CVE-2026-52912} - netfilter: ip6t_hbh: reject oversized option lists (Zhengchuan Liang) [Orabug: 39619270] {CVE-2026-52915} - net: bcmgenet: keep RBUF EEE/PM disabled (Nicolai Buchwitz) [Orabug: 39754845] {CVE-2026-64125} - phonet/pep: disable BH around forwarded sk_receive_skb() (Zijing Yin) [Orabug: 39754963] {CVE-2026-64177} - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (Mingyu Wang) [Orabug: 39523054] {CVE-2026-46275} - Bluetooth: bnep: Fix UAF read of dev-name (Jann Horn) [Orabug: 39754967] {CVE-2026-64178} - net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (Abdun Nihaal) - ALSA: asihpi: Fix potential OOB array access at reading cache (Takashi Iwai) [Orabug: 39754862] {CVE-2026-64133} - ALSA: ua101: Reject too-short USB descriptors (Cassio Gabriel) - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (Abdurrahman Hussain) - sysfs: don't remove existing directory on update failure (Greg Kroah-Hartman) [Orabug: 39754983] {CVE-2026-64185} - Revert 's390/cio: Fix device lifecycle handling in css_alloc_subchannel()' (Sasha Levin) - KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses (Sean Christopherson) [Orabug: 37901590] {CVE-2025-23141} - wifi: mac80211: check tdls flag in ieee80211_tdls_oper (Deepanshu Kartikey) [Orabug: 39300982] {CVE-2026-43052} - net: dsa: sja1105: fix kasan out-of-bounds warning in sja1105_table_delete_entry() (Vladimir Oltean) - Revert 'x86/vdso: Fix output operand size of RDPID' (Sasha Levin) - s390/debug: Reject zero-length input before trimming a newline (Pengpeng Hou) - io_uring: prevent opcode speculation (Pavel Begunkov) [Orabug: 37702113] {CVE-2025-21863} - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (Nicholas Carlini) [Orabug: 39523050] {CVE-2026-46274} - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (Johan Hovold) - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (Gyeyoung Baek) - drm/i915: skip __i915_request_skip() for already signaled requests (Sebastian Brzezinka) - iommu/vt-d: Disable DMAR for Intel Q35 IGFX (Naval Alcala) - libceph: handle rbtree insertion error in decode_choose_args() (Raphael Zimmer) [Orabug: 39621580] {CVE-2026-52954} - libceph: Fix potential out-of-bounds access in crush_decode() (Raphael Zimmer) [Orabug: 39621584] {CVE-2026-52955} - libceph: Fix potential null-ptr-deref in decode_choose_args() (Raphael Zimmer) [Orabug: 39621592] {CVE-2026-52957} - libceph: Fix potential out-of-bounds access in osdmap_decode() (Raphael Zimmer) [Orabug: 39621596] {CVE-2026-52958} - powerpc/warp: Fix error handling in pika_dtm_thread (Ma Ke) - ceph: fix a buffer leak in __ceph_setxattr() (Viacheslav Dubeyko) [Orabug: 39621609] {CVE-2026-52962} - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (Cassio Gabriel) [Orabug: 39621613] {CVE-2026-52963} - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (Chaitanya Kumar Borah) - KVM: x86: Fix Xen hypercall tracepoint argument assignment (Maqiang) - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (Aaron Sacks) [Orabug: 39621628] {CVE-2026-52969} - audit: enforce AUDIT_LOCKED for AUDIT_TRIM and AUDIT_MAKE_EQUIV (Sergio Correia) - net: atlantic: preserve PCI wake-from-D3 on shutdown when WOL enabled (Zoran Ilievski) - netfilter: nft_ct: fix missing expect put in obj eval (Li Xiasong) [Orabug: 39621633] {CVE-2026-52970} - audit: fix incorrect inheritable capability in CAPSET records (Sergio Correia) [Orabug: 39653209] {CVE-2026-53287} - i40e: Cleanup PTP pins on probe failure (Matt Vollrath) - crypto: af_alg - Cap AEAD AD length to 0x80000000 (Herbert Xu) [Orabug: 39655982] {CVE-2026-52972} - net/sched: sch_pie: annotate more data-races in pie_dump_stats() (Eric Dumazet) - flow_dissector: Do not count vlan tags inside tunnel payload (Qingqing Yang) - flow_dissector: do not dissect PPPoE PFC frames (Qingfang Deng) [Orabug: 39524619] {CVE-2026-46306} - btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (Filipe Manana) [Orabug: 39784984] {CVE-2026-64164} - drm/amd/display: Read EDID from VBIOS embedded panel info (Timur Kristof) - drm/amd/display: Allow DCE link encoder without AUX registers (Timur Kristof) - ALSA: hda/conexant: Fix missing error check for jack detection (Wangdicheng) [Orabug: 39653220] {CVE-2026-53291} - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (Wangdicheng) - ALSA: hda/conexant: fix some typos (Oldherl Oh) - ALSA: hda/conexant: add a new hda codec SN6140 (Bo Liu) - net/sched: sch_cake: annotate data-races in cake_dump_stats() (V) (Eric Dumazet) - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (Weiming Shi) [Orabug: 39451517] {CVE-2026-45846} - ipv6: rename and move ip6_dst_lookup_tunnel() (Beniamino Galvani) - ipv4: add new arguments to udp_tunnel_dst_lookup() (Beniamino Galvani) - ipv4: remove 'proto' argument from udp_tunnel_dst_lookup() (Beniamino Galvani) - ipv4: rename and move ip_route_output_tunnel() (Beniamino Galvani) - sctp: discard stale INIT after handshake completion (Xin Long) - netfilter: skip recording stale or retransmitted INIT (Xin Long) - ASoC: codecs: ab8500: Fix casting of private data (Christian A. Ehrhardt) - net: phy: dp83869: fix setting CLK_O_SEL field. (Heiko Schocher) - NFC: trf7970a: Ignore antenna noise when checking for RF field (Paul Geurts) - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (Dandan Zhang) - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (Jun Zhan) [Orabug: 39621670] {CVE-2026-52982} - vrf: Fix a potential NPD when removing a port from a VRF (Ido Schimmel) [Orabug: 39619318] {CVE-2026-52925} - net/sched: sch_fq_pie: annotate data-races in fq_pie_dump_stats() (Eric Dumazet) - net/sched: sch_choke: annotate data-races in choke_dump_stats() (Eric Dumazet) - net: sched: choke: remove unused variables in struct choke_sched_data (Zhengchao Shao) - net/sched: netem: validate slot configuration (Stephen Hemminger) - net/sched: netem: fix queue limit check to include reordered packets (Stephen Hemminger) [Orabug: 39621677] {CVE-2026-52984} - net/sched: netem: fix probability gaps in 4-state loss model (Stephen Hemminger) - net: sched: sch_netem: Refactor code in 4-state loss generator (Harshit Mogalapalli) - netdevsim: zero initialize struct iphdr in dummy sk_buff (Nikola Z. Ivanov) [Orabug: 39621681] {CVE-2026-52985} - cdrom, scsi: sr: propagate read-only status to block layer via set_disk_ro() (Daan De Meyer) - scsi: sr: Add memory allocation failure handling for get_capabilities() (Enze Li) - netfilter: nf_conntrack_sip: don't use simple_strtoul (Florian Westphal) [Orabug: 39621685] {CVE-2026-52986} - netfilter: xt_policy: fix strict mode inbound policy matching (Jiexun Wang) [Orabug: 39619293] {CVE-2026-52920} - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (Timur Kristof) - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (Timur Kristof) - drm/amdgpu: fix spelling typos (Alexandre Demers) - netfilter: arp_tables: fix IEEE1394 ARP payload parsing (Pablo Neira Ayuso) [Orabug: 39451507] {CVE-2026-45844} - tracing: branch: Fix inverted check on stat tracer registration (Breno Leitao) - btrfs: fix double-decrement of bytes_may_use in submit_one_async_extent() (Mark Harmstone) - mailbox: mailbox-test: make data_ready a per-instance variable (Wolfram Sang) - mailbox: mailbox-test: initialize struct earlier (Wolfram Sang) - mailbox: mailbox-test: don't free the reused channel (Wolfram Sang) - mailbox: add sanity check for channel array (Wolfram Sang) [Orabug: 39653234] {CVE-2026-53295} - cgroup/rdma: fix integer overflow in rdmacg_try_charge() (Tao Cui) - mailbox: mailbox-test: free channels on probe error (Wolfram Sang) - fbdev: offb: fix PCI device reference leak on probe failure (Yuho Choi) - rtc: abx80x: Disable alarm feature if no interrupt attached (Anthony Pighin) - fs/adfs: validate nzones in adfs_validate_bblk() (Bae Yeonju) - vhost_net: fix sleeping with preempt-disabled in vhost_net_busy_poll() (Kohei Enju) - tipc: fix double-free in tipc_buf_append() (Lee Jones) [Orabug: 39621708] {CVE-2026-52993} - nfp: fix swapped arguments in nfp_encode_basic_qdr() calls (Alexey Kodanev) - net/sched: sch_sfb: annotate data-races in sfb_dump_stats() (Eric Dumazet) - net/sched: sch_red: annotate data-races in red_dump_stats() (Eric Dumazet) - net: sched: gred/red: remove unused variables in struct red_stats (Zhengchao Shao) - net/sched: sch_fq_codel: remove data-races from fq_codel_dump_stats() (Eric Dumazet) - net/sched: sch_pie: annotate data-races in pie_dump_stats() (Eric Dumazet) - net_sched: sch_hhf: annotate data-races in hhf_dump_stats() (Eric Dumazet) - ksmbd: scope conn-binding slowpath to bound sessions only (Hyunwoo Kim) - ksmbd: destroy tree_conn_ida in ksmbd_session_destroy() (Daemyung Kang) - arm64: dts: meson-gxl-p230: fix ethernet PHY interrupt number (Yan Jun) - slip: bound decode() reads against the compressed packet length (Weiming Shi) [Orabug: 39451500] {CVE-2026-45843} - slip: reject VJ receive packets on instances with no rstate array (Weiming Shi) [Orabug: 39451493] {CVE-2026-45842} - netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check (Fernando Fernandez Mancera) [Orabug: 39621724] {CVE-2026-52998} - netfilter: nfnetlink_osf: fix out-of-bounds read on option matching (Fernando Fernandez Mancera) [Orabug: 39621730] {CVE-2026-52999} - ipvs: fix MTU check for GSO packets in tunnel mode (Yingnan Zhang) - netfilter: xtables: restrict several matches to inet family (Pablo Neira Ayuso) [Orabug: 39621740] {CVE-2026-53001} - netfilter: conntrack: remove sprintf usage (Florian Westphal) [Orabug: 39621746] {CVE-2026-53002} - netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (Xiang Mei) [Orabug: 39451485] {CVE-2026-45841} - netfilter: nft_osf: restrict it to ipv4 (Pablo Neira Ayuso) - openvswitch: cap upcall PID array size and pre-size vport replies (Weiming Shi) [Orabug: 39451479] {CVE-2026-45840} - pppoe: drop PFC frames (Qingfang Deng) [Orabug: 39621751] {CVE-2026-53003} - flow_dissector: Add number of vlan tags dissector (Boris Sukholitko) - sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks (Michael Bommarito) [Orabug: 39621757] {CVE-2026-53004} - ipv6: fix possible UAF in icmpv6_rcv() (Eric Dumazet) [Orabug: 39621765] {CVE-2026-53006} - e1000e: Unroll PTP in probe error handling (Matt Vollrath) - i40e: don't advertise IFF_SUPP_NOFCS (Kohei Enju) - tcp: annotate data-races around (tp-write_seq - tp-snd_nxt) (Eric Dumazet) - net/sched: taprio: fix use-after-free in advance_sched() on schedule switch (Vinicius Costa Gomes) [Orabug: 39621780] {CVE-2026-53011} - net/sched: taprio: rename close_time to end_time (Vladimir Oltean) - net/sched: taprio: refactor one skb dequeue from TXQ to separate function (Vladimir Oltean) - net/sched: taprio: continue with other TXQs if one dequeue() failed (Vladimir Oltean) - net/sched: taprio: replace safety precautions with comments (Vladimir Oltean) - net/sched: taprio: stop going through private ops for dequeue and peek (Vladimir Oltean) - nexthop: fix IPv6 route referencing IPv4 nexthop (Jiayuan Chen) [Orabug: 39621784] {CVE-2026-53012} - net/sched: sch_cake: fix NAT destination port not being updated in cake_update_flowkeys (Dudu Lu) - PCMCIA: Fix garbled log messages for KERN_CONT (Rene Rebe) - crypto: ccp - copy IV using skcipher ivsize (Paul Moses) [Orabug: 39621796] {CVE-2026-53016} - crypto: sa2ul - Fix AEAD fallback algorithm names (T Pratham) - lib/hexdump: print_hex_dump_bytes() calls print_hex_dump_debug() (Geert Uytterhoeven) - clk: qcom: dispcc-sc7180: Add missing MDSS resets (Konrad Dybcio) - dt-bindings: clock: qcom,dispcc-sc7180: Define MDSS resets (Konrad Dybcio) - clk: xgene: Fix mapping leak in xgene_pllclk_init() (Geert Uytterhoeven) - clk: qoriq: avoid format string warning (Arnd Bergmann) - clk: imx8mq: Correct the CSI PHY sels (Sebastian Krzyszkowiak) - clk: imx: imx6q: Fix device node reference leak in of_assigned_ldb_sels() (Felix Gu) - clk: imx: imx6q: Fix device node reference leak in pll6_bypassed() (Felix Gu) - clk: qcom: dispcc-sm8250: Enable parents for pixel clocks (Val Packett) - clk: qcom: dispcc-sm8250: Use shared ops on the mdss vsync clk (Val Packett) - clk: qcom: gcc-sc8180x: Use retention for PCIe power domains (Val Packett) - clk: qcom: gcc-sc8180x: Use retention for USB power domains (Val Packett) - clk: qcom: gcc-sc8180x: Add missing GDSCs (Val Packett) - dt-bindings: clock: qcom,gcc-sc8180x: Add missing GDSCs (Val Packett) - scsi: target: core: Fix integer overflow in UNMAP bounds check (Junrui Luo) [Orabug: 39621811] {CVE-2026-53021} - scsi: sg: Resolve soft lockup issue when opening /dev/sgX (Yangerkun) [Orabug: 39653261] {CVE-2026-53304} - RDMA/core: Prefer NLA_NUL_STRING (Florian Westphal) [Orabug: 39754131] {CVE-2026-63860} - platform/x86: dell-wmi-sysman: bound enumeration string aggregation (Pengpeng Hou) [Orabug: 39621815] {CVE-2026-53022} - platform/x86: dell_rbu: avoid uninit value usage in packet_size_write() (Fedor Pchelkin) - fs/ntfs3: terminate the cached volume label after UTF-8 conversion (Pengpeng Hou) - nfs/blocklayout: Fix compilation error (make W=1) in bl_write_pagelist() (Andy Shevchenko) - mfd: mc13xxx-core: Fix memory leak in mc13xxx_add_subdevice_pdata() (Abdun Nihaal) - platform/x86: panasonic-laptop: Fix OPTD notifier registration and cleanup (Rafael J. Wysocki) - tty: hvc_iucv: fix off-by-one in number of supported devices (Randy Dunlap) - tty: hvc: remove HVC_IUCV_MAGIC (Ahelenia Ziemianska) - leds: lgm-sso: Remove duplicate assignments for priv-mmap (Chen Ni) - platform/surface: surfacepro3_button: Drop wakeup source on remove (Rafael J. Wysocki) - backlight: sky81452-backlight: Check return value of devm_gpiod_get_optional() in sky81452_bl_parse_dt() (Chen Ni) - dev_printk: add new dev_err_probe() helpers (Nuno Sa) - driver core: Move dev_err_probe() to where it belogs (Andy Shevchenko) - driver core: device.h: remove extern from function prototypes (Greg Kroah-Hartman) - i3c: mipi-i3c-hci: fix IBI payload length calculation for final status (Billy Tsai) - perf util: Kill die() prototype, dead for a long time (Arnaldo Carvalho de Melo) - perf expr: Return -EINVAL for syntax error in expr__find_ids() (Leo Yan) - pinctrl: abx500: Fix type of 'argument' variable (Yu-Chun Lin) - perf: tools: cs-etm: Fix print issue for Coresight debug in ETE/TRBE trace (Mike Leach) - perf branch: Avoid incrementing NULL (Ian Rogers) - pinctrl: pinctrl-pic32: Fix resource leak (Ethan Tidmore) - HID: usbhid: fix deadlock in hid_post_reset() (Oliver Neukum) [Orabug: 39621857] {CVE-2026-53037} - mtd: rawnand: sunxi: fix sunxi_nfc_hw_ecc_read_extra_oob (Richard Genoud) - mtd: parsers: ofpart: call of_node_get() for dedicated subpartitions (Cosmin Tanislav) - mtd: parsers: ofpart: call of_node_put() only in ofpart_fail path (Cosmin Tanislav) - mtd: spi-nor: swp: check SR_TB flag when getting tb_mask (Shiji Yang) - mtd: spi-nor: core: correct the op.dummy.nbytes when check read operations (Haibo Chen) - mtd: physmap_of_gemini: Fix disabled pinctrl state check (Chen Ni) - HID: asus: do not abort probe when not necessary (Denis Benato) - HID: asus: make asus_resume adhere to linux kernel coding standards (Denis Benato) - ima: check return value of crypto_shash_final() in boot aggregate (Daniel Hodges) - tracing: Rebuild full_name on each hist_field_name() call (Pengpeng Hou) - dmaengine: mxs-dma: Fix missing return value from of_dma_controller_register() (Frank Li) - dmaengine: dw-axi-dmac: Remove unnecessary return statement from void function (Khairul Anuar Romli) - ocfs2: validate group add input before caching (Zhengyuan Huang) [Orabug: 39621864] {CVE-2026-53039} - ocfs2: validate bg_bits during freefrag scan (Zhengyuan Huang) [Orabug: 39621868] {CVE-2026-53040} - ocfs2: fix listxattr handling when the buffer is full (Zhengyuan Huang) [Orabug: 39621872] {CVE-2026-53041} - soc: qcom: aoss: compare against normalized cooling state (Alok Tiwari) - ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (Junrui Luo) [Orabug: 39653274] {CVE-2026-53309} - ocfs2/dlm: validate qr_numregions in dlm_match_regions() (Junrui Luo) [Orabug: 39621878] {CVE-2026-53043} - unshare: fix nsproxy leak in ksys_unshare() on set_cred_ucounts() failure (Michal Grzedzicki) - arm64: dts: qcom: sdm845-xiaomi-beryllium: Mark l1a regulator as powered during boot (David Heidelberger) - soc: qcom: ocmem: return -EPROBE_DEFER is ocmem is not available (Dmitry Baryshkov) - soc: qcom: ocmem: register reasons for probe deferrals (Dmitry Baryshkov) - soc: qcom: ocmem: use scoped device node handling to simplify error paths (Krzysztof Kozlowski) - memory: tegra30-emc: Fix dll_change check (Mikko Perttunen) - memory: tegra124-emc: Fix dll_change check (Mikko Perttunen) - ARM: dts: mediatek: mt7623: fix efuse fallback compatible (Rafal Milecki) - ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine (Joshua Klinesmith) - efi/capsule-loader: fix incorrect sizeof in phys array reallocation (Thomas Huth) [Orabug: 39621893] {CVE-2026-53047} - gfs2: prevent NULL pointer dereference during unmount (Andreas Gruenbacher) [Orabug: 39621897] {CVE-2026-53048} - gfs2: add some missing log locking (Andreas Gruenbacher) [Orabug: 39621900] {CVE-2026-53049} - quota: Fix race of dquot_scan_active() with quota deactivation (Jan Kara) [Orabug: 39621904] {CVE-2026-53050} - ktest: Run POST_KTEST hooks on failure and cancellation (Ricardo B. Marliere) - ktest: Honor empty per-test option overrides (Ricardo B. Marliere) - ktest: Avoid undef warning when WARNINGS_FILE is unset (Ricardo B. Marliere) - ALSA: sc6000: Keep the programmed board state in card-private data (Cassio Gabriel) - ALSA: sc6000: Use standard print API (Takashi Iwai) - PCI: tegra194: Disable direct speed change for Endpoint mode (Vidya Sagar) - PCI: tegra194: Use devm_gpiod_get_optional() to parse 'nvidia,refclk-select' (Vidya Sagar) - PCI: tegra194: Disable LTSSM after transition to Detect on surprise link down (Manikanta Maddireddy) - PCI: tegra194: Increase LTSSM poll time on surprise link down (Manikanta Maddireddy) - PCI: tegra194: Fix polling delay for L2 state (Vidya Sagar) - PCI: Add PCIE_PME_TO_L2_TIMEOUT_US L2 ready timeout value (Frank Li) - selftest: memcg: skip memcg_sock test if address family not supported (Waiman Long) - Documentation: fix a hugetlbfs reservation statement (Jane Chu) - PCI: Enable AtomicOps only if Root Port supports them (Gerd Bayer) - ASoC: fsl_easrc: Change the type for iec958 channel status controls (Shengjiu Wang) - ASoC: fsl_easrc: Fix value type in fsl_easrc_iec958_get_bits() (Shengjiu Wang) - ASoC: fsl_easrc: Check the variable range in fsl_easrc_iec958_put_bits() (Shengjiu Wang) - ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_mode_put() (Shengjiu Wang) - ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_arc_mode_put() (Shengjiu Wang) - pmdomain: imx: scu-pd: Fix device_node reference leak during -probe() (Felix Gu) - pmdomain: ti: omap_prm: Fix a reference leak on device node (Felix Gu) - drm/msm/a6xx: Use barriers while updating HFI Q headers (Akhil P Oommen) - drm/msm/a6xx: Fix HLSQ register dumping (Rob Clark) - ALSA: hda/realtek: fix code style (ERROR: else should follow close brace '}') (Huanglei) - ALSA: hda/realtek: Whitespace fix (Luke D. Jones) - drm/amd/pm/smu7: Add SCLK cap for quirky Hawaii board (Timur Kristof) - drm/amd/pm/ci: Fill DW8 fields from SMC (Timur Kristof) - drm/amd/pm/ci: Clear EnabledForActivity field for memory levels (Timur Kristof) - drm/amd/pm/ci: Fix powertune defaults for Hawaii 0x67B0 (Timur Kristof) - drm/amd/pm/smu7: Fix SMU7 voltage dependency on display clock (Timur Kristof) - drm/amd/pm/ci: Disable MCLK DPM on problematic CI ASICs (Timur Kristof) - drm/amd/pm/ci: Use highest MCLK on CI when MCLK DPM is disabled (Timur Kristof) - ALSA: core: Validate compress device numbers without dynamic minors (Cassio Gabriel) - drm/panel: simple: Correct G190EAN01 prepare timing (Sebastian Reichel) - drm/msm/dsi: rename MSM8998 DSI version from V2_2_0 to V2_0_0 (Alexander Koskovich) - spi: hisi-kunpeng: prevent infinite while() loop in hisi_spi_flush_fifo (Pei Xiao) - fbdev: matroxfb: Mark variable with __maybe_unused to avoid W=1 build break (Andy Shevchenko) - dm init: ensure device probing has finished in dm-mod.waitfor= (Guillaume Gonnet) - drm/sun4i: Fix resource leaks (Ethan Tidmore) - spi: fsl-qspi: Use reinit_completion() for repeated operations (Felix Gu) - dm log: fix out-of-bounds write due to region_count overflow (Junrui Luo) [Orabug: 39621924] {CVE-2026-53059} - dm cache metadata: fix memory leak on metadata abort retry (Ming-Hung Tsai) [Orabug: 39621929] {CVE-2026-53060} - dm cache: fix dirty mapping checking in passthrough mode switching (Ming-Hung Tsai) [Orabug: 39621933] {CVE-2026-53061} - dm cache: support shrinking the origin device (Ming-Hung Tsai) - dm cache: fix concurrent write failure in passthrough mode (Ming-Hung Tsai) - dm cache policy smq: fix missing locks in invalidating cache blocks (Ming-Hung Tsai) [Orabug: 39621937] {CVE-2026-53062} - dm cache: fix write path cache coherency in passthrough mode (Ming-Hung Tsai) - dm cache: fix null-deref with concurrent writes in passthrough mode (Ming-Hung Tsai) [Orabug: 39621946] {CVE-2026-53064} - ASoC: sti: use managed regmap_field allocations (Sander Vanheule) - ASoC: sti: Return errors from regmap_field_alloc() (Sander Vanheule) - drm/komeda: fix integer overflow in AFBC framebuffer size check (Alexander Konyukhov) - net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master (Jiayuan Chen) [Orabug: 39621966] {CVE-2026-53069} - sctp: fix missing encap_port propagation for GSO fragments (Xin Long) - net: phy: qcom: at803x: Use the correct bit to disable extended next page (Maxime Chevallier) - Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (Dudu Lu) [Orabug: 39621973] {CVE-2026-53071} - Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (Pauli Virtanen) [Orabug: 39621976] {CVE-2026-53072} - Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error (Jonathan Rissanen) [Orabug: 39621980] {CVE-2026-53073} - Bluetooth: L2CAP: Fix printing wrong information if SDU length exceeds MTU (Luiz Augusto von Dentz) - bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb (Sun Jian) [Orabug: 39621984] {CVE-2026-53074} - ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (Taegu Ha) [Orabug: 39621987] {CVE-2026-53075} - net/sched: act_ct: Only release RCU read lock after ct_ft (Jamal Hadi Salim) [Orabug: 39531630] {CVE-2026-46319} - net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf (Mashiro Chen) - 6pack: propagage new tty types (Jiri Slaby) - netfilter: nft_fwd_netdev: check ttl/hl before forwarding (Florian Westphal) - netfilter: xt_socket: enable defrag after all other checks (Florian Westphal) - net: bcmgenet: fix off-by-one in bcmgenet_put_txcb (Justin Chen) [Orabug: 39622043] {CVE-2026-53088} - bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() (Weiming Shi) - bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (Jiayuan Chen) [Orabug: 39754142] {CVE-2026-63865} - bpf-lsm: Make bpf_lsm_userns_create() sleepable (Frederick Lawler) - wifi: brcmfmac: Fix error pointer dereference (Ethan Tidmore) [Orabug: 39622061] {CVE-2026-53093} - bpf: fix end-of-list detection in cgroup_storage_get_next_key() (Weiming Shi) [Orabug: 39451462] {CVE-2026-45838} - macvlan: annotate data-races around port-bc_queue_len_used (Eric Dumazet) - powerpc/crash: fix backup region offset update to elfcorehdr (Sourabh Jain) - r8152: fix incorrect register write to USB_UPHY_XTAL (Chih Kai Hsu) - bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (David Carlier) [Orabug: 39622069] {CVE-2026-53096} - bpf, devmap: Remove unnecessary if check in for loop (Thorsten Blum) - module: Fix freeing of charp module parameters when CONFIG_SYSFS=n (Petr Pavlu) - params: Replace __modinit with __init_or_module (Petr Pavlu) - kernel: globalize lookup_or_create_module_kobject() (Shyam Saini) - kernel: param: rename locate_module_kobject (Shyam Saini) - dpaa2: compile dpaa2 even CONFIG_FSL_DPAA2_ETH=n (Cai Xinchen) - dpaa2: add independent dependencies for FSL_DPAA2_SWITCH (Cai Xinchen) - wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet (Duoming Zhou) [Orabug: 39622109] {CVE-2026-53112} - wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt() (Zilin Guan) - firmware: dmi: Correct an indexing error in dmi.h (Mario Limonciello) (Bart Van Assche) - irqchip/irq-pic32-evic: Address warning related to wrong printf() formatter (Brian Masney) - debugfs: check for NULL pointer in debugfs_create_str() (Gui-Dong Han) - thermal/drivers/spear: Fix error condition for reading st,thermal-flags (Gopi Krishna Menon) - devres: fix missing node debug info in devm_krealloc() (Danilo Krummrich) - pstore/ram: fix resource leak when ioremap() fails (Cole Leavitt) - nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty() (Deepanshu Kartikey) - drbd: Balance RCU calls in drbd_adm_dump_devices() (Bart Van Assche) [Orabug: 39622158] {CVE-2026-53128} - fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START (Hyungjung Joo) - bcache: fix uninitialized closure object (Mingzhe Zou) - drm/amdgpu/vcn3: Avoid overflow on msg bound check (Benjamin Cheng) - vsock/virtio: fix accept queue count leak on transport mismatch (Dudu Lu) [Orabug: 39460646] {CVE-2026-46214} - vsock: fix buffer size clamping order (Norbert Szetei) [Orabug: 39460717] {CVE-2026-46234} - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() (Siwei Zhang) [Orabug: 39445785] {CVE-2026-45836} - batman-adv: bla: put backbone reference on failed claim hash insert (Sven Eckelmann) [Orabug: 39460707] {CVE-2026-46231} - batman-adv: bla: only purge non-released claims (Sven Eckelmann) [Orabug: 39460713] {CVE-2026-46233} - batman-adv: bla: prevent use-after-free when deleting claims (Sven Eckelmann) [Orabug: 39460640] {CVE-2026-46212} - batman-adv: stop caching unowned originator pointers in BAT IV (Jiexun Wang) [Orabug: 39460733] {CVE-2026-46238} - batman-adv: reject new tp_meter sessions during teardown (Jiexun Wang) [Orabug: 39460614] {CVE-2026-46206} - batman-adv: fix integer overflow on buff_pos (Lyes Bourennani) [Orabug: 39460580] {CVE-2026-46198} - sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (Ben Morris) [Orabug: 39460689] {CVE-2026-46227} - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (Alex Deucher) - drm/amdgpu/pm: add missing revision check for CI (Alex Deucher) - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (John B. Moore) [Orabug: 39460668] {CVE-2026-46220} - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (John B. Moore) - drm/radeon: add missing revision check for CI (Alex Deucher) - drm/amdkfd: validate SVM ioctl nattr against buffer size (Alysa Liu) [Orabug: 39460573] {CVE-2026-46197} - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (Ashutosh Desai) [Orabug: 39460627] {CVE-2026-46209} - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (Benjamin Cheng) [Orabug: 39460702] {CVE-2026-46230} - spi: mpc52xx: fix use-after-free on unbind (Johan Hovold) - spi: orion: fix clock imbalance on registration failure (Johan Hovold) - spi: imx: fix runtime pm leak on probe deferral (Johan Hovold) - spi: mtk-nor: fix controller deregistration (Johan Hovold) - media: i2c: imx412: Assert reset GPIO during probe (Wenmeng Liu) - media: dib8000: avoid division by 0 in dib8000_set_dds() (Sergey Shtylyov) - regulator: bd9571mwv: fix OF node reference imbalance (Johan Hovold) - regulator: act8945a: fix OF node reference imbalance (Johan Hovold) - media: rc: streamzap: Error handling in probe (Oliver Neukum) - media: rc: xbox_remote: heed DMA restrictions (Oliver Neukum) - regulator: max77650: fix OF node reference imbalance (Johan Hovold) - staging: media: atomisp: Disallow all private IOCTLs (Sakari Ailus) - media: i2c: ov8856: free control handler on error in ov8856_init_controls() (Alexander Koskovich) - media: uvcvideo: Enable VB2_DMABUF for metadata stream (Ricardo Ribalda) - platform/x86: hp-wmi: Ignore backlight and FnLock events (Krishna Chomal) - mptcp: fix scheduling with atomic in timestamp sockopt (Gang Yan) [Orabug: 39460450] {CVE-2026-46168} - mptcp: sockopt: set timestamp flags on subflow socket, not msk (Gang Yan) - mptcp: use MPTCP_RST_EMPTCP for ACK HMAC validation failure (Shardul Bankar) - mptcp: use MPJoinSynAckHMacFailure for SynAck HMAC failure (Shardul Bankar) - RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (Jason Gunthorpe) [Orabug: 39460540] {CVE-2026-46189} - RDMA/rxe: Reject unknown opcodes before ICRC processing (Michael Bommarito) [Orabug: 39460303] {CVE-2026-46133} - RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() (Jason Gunthorpe) [Orabug: 39460277] {CVE-2026-46127} - RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (Jason Gunthorpe) [Orabug: 39460496] {CVE-2026-46178} - power: supply: max17042: avoid overflow when determining health (Andre Draszik) - PCI/AER: Stop ruling out unbound devices as error source (Lukas Wunner) - PCI/AER: Clear only error bits in PCIe Device Status (Shuai Xue) - s390/debug: Reject zero-length input in debug_input_flush_fn() (Vasily Gorbik) - RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (Jason Gunthorpe) - nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free (Chaitanya Kulkarni) [Orabug: 39524613] {CVE-2026-46304} - md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (Junrui Luo) [Orabug: 39460415] {CVE-2026-46161} - libceph: Fix slab-out-of-bounds access in auth message processing (Raphael Zimmer) [Orabug: 39460244] {CVE-2026-46119} - isofs: validate block number from NFS file handle in isofs_export_iget (Michael Bommarito) [Orabug: 39460265] {CVE-2026-46124} - isofs: validate Rock Ridge CE continuation extent against volume size (Michael Bommarito) [Orabug: 39524609] {CVE-2026-46303} - dm-verity-fec: correctly reject too-small hash devices (Eric Biggers) - dm-verity-fec: correctly reject too-small FEC devices (Eric Biggers) - dm: fix a buffer overflow in ioctl processing (Mikulas Patocka) [Orabug: 39524585] {CVE-2026-46294} - dm: don't report warning when doing deferred remove (Mikulas Patocka) - dm-thin: fix metadata refcount underflow (Mikulas Patocka) [Orabug: 39460195] {CVE-2026-46107} - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (Cassio Gabriel) - ASoC: fsl_easrc: fix comment typo (Joseph Salisbury) - cpuidle: powerpc: avoid double clear when breaking snooze (Shrikanth Hegde) - spi: topcliff-pch: fix use-after-free on unbind (Johan Hovold) - thermal/drivers/sprd: Fix raw temperature clamping in sprd_thm_rawdata_to_temp (Thorsten Blum) - thermal/drivers/sprd: Fix temperature clamping in sprd_thm_temp_to_rawdata (Thorsten Blum) - udf: reject descriptors with oversized CRC length (Michael Bommarito) [Orabug: 39753576] {CVE-2026-53369} - ibmveth: Disable GSO for packets with small MSS (Mingming Cao) - hv_sock: fix ARM64 support (Hamza Mahfooz) - extcon: ptn5150: handle pending IRQ events during system resume (Xu Yang) - hwmon: (corsair-psu) Close HID device on probe errors (Myeonghun Pak) - hwmon: (ltc2992) Fix u32 overflow in power read path (Sanman Pradhan) - hwmon: (ltc2992) Clamp threshold writes to hardware range (Sanman Pradhan) - parisc: Fix IRQ leak in LASI driver (Hongling Zeng) - ip6_gre: Use cached t-net in ip6erspan_changelink(). (Maoyi Xie) [Orabug: 39460248] {CVE-2026-46120} - sound: ua101: fix division by zero at probe (Seungju Cheon) [Orabug: 39460519] {CVE-2026-46184} - net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo (Kai Aizen) [Orabug: 39460297] {CVE-2026-46132} - fanotify: fix false positive on permission events (Miklos Szeredi) [Orabug: 39460374] {CVE-2026-46150} - spi: zynqmp-gqspi: fix controller deregistration (Johan Hovold) - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (Siwei Zhang) [Orabug: 39445772] {CVE-2026-45834} - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (Siwei Zhang) [Orabug: 39445781] {CVE-2026-45835} - Bluetooth: virtio_bt: validate rx pkt_type header length (Michael Bommarito) - Bluetooth: virtio_bt: clamp rx length before skb_put (Michael Bommarito) - ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (Yilin Zhu) [Orabug: 39460469] {CVE-2026-46172} - xfrm: provide message size for XFRM_MSG_MAPPING (Ruijie Li) - ALSA: firewire-tascam: Do not drop unread control events (Cassio Gabriel) - usb: ulpi: fix memory leak on ulpi_register() error paths (Felix Gu) [Orabug: 39654820] {CVE-2026-46109} - USB: serial: option: add Telit Cinterion LE910Cx compositions (Fabio Porcedda) - USB: omap_udc: DMA: Don't enable burst 4 mode (Aaro Koskinen) - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (Cassio Gabriel) - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (Takashi Iwai) [Orabug: 39460352] {CVE-2026-46146} - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (Greg Kroah-Hartman) [Orabug: 39460438] {CVE-2026-46167} - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (Greg Kroah-Hartman) [Orabug: 39460379] {CVE-2026-46151} - wifi: b43: enforce bounds check on firmware key index in b43_rx() (Tristan Madani) [Orabug: 39460257] {CVE-2026-46122} - wifi: ath5k: do not access array OOB (Jiri Slaby) [Orabug: 39524622] {CVE-2026-46307} - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (Jeongjun Park) [Orabug: 39460532] {CVE-2026-46187} - wifi: b43legacy: enforce bounds check on firmware key index in RX path (Tristan Madani) [Orabug: 39460424] {CVE-2026-46163} - ipmi:ssif: NULL thread on error (Corey Minyard) - ipmi:ssif: Remove unnecessary indention (Corey Minyard) - ipmi:ssif: Clean up kthread on errors (Corey Minyard) [Orabug: 39452264] {CVE-2026-46044} - ipmi:ssif: Fix a shutdown race (Corey Minyard) - net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Jamal Hadi Salim) [Orabug: 39425987] {CVE-2026-43496} - octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_flows.c (Dipendra Khadka) - um: virt-pci: Fix build failure (Florian Fainelli) - spi: meson-spicc: Fix double-put in remove path (Felix Gu) [Orabug: 39250891] {CVE-2026-31489} - ksmbd: do not expire session on binding failure (Hyunwoo Kim) - spi: rockchip: fix controller deregistration (Johan Hovold) - ACPI: video: force native backlight on HP OMEN 16 (8A44) (Shivam Kalra) - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (Jinjie Ruan) - ACPI: scan: Use acpi_dev_put() in object add error paths (Guangshuo Li) - fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free (Rajat Gupta) - ipmi:si: Return state to normal if message allocation fails (Corey Minyard) [Orabug: 39460202] {CVE-2026-46108} - ipmi: Check event message buffer response for bad data (Corey Minyard) [Orabug: 39460284] {CVE-2026-46128} - ipmi: Add limits to event and receive message requests (Corey Minyard) [Orabug: 39460490] {CVE-2026-46177} - scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (Greg Kroah-Hartman) [Orabug: 39460368] {CVE-2026-46149} - netfilter: reject zero shift in nft_bitwise (Kai Ma) [Orabug: 39452465] {CVE-2026-46101} - net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (Andrea Mayer) [Orabug: 39452458] {CVE-2026-46099} - ALSA: caiaq: fix usb_dev refcount leak on probe failure (Deepanshu Kartikey) [Orabug: 39784983] {CVE-2026-46048} - drm/amdgpu: fix zero-size GDS range init on RDNA4 (Arjan van de Ven) [Orabug: 39524543] {CVE-2026-46276} - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (Greg Kroah-Hartman) [Orabug: 39426004] {CVE-2026-43501} - ALSA: caiaq: Don't abort when no input device is available (Takashi Iwai) - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (Takashi Iwai) - driver core: Add kernel-doc for DEV_FLAG_COUNT enum value (Douglas Anderson) - crypto: authencesn - reject short ahash digests during instance creation (Yucheng Lu) [Orabug: 39452232] {CVE-2026-46033} - seg6: fix seg6 lwtunnel output redirect for L2 reduced encap mode (Andrea Mayer) - ntfs3: fix integer overflow in run_unpack() volume boundary check (Tobi Gaertner) - ntfs3: add buffer boundary checks to run_unpack() (Tobi Gaertner) - ktest: Fix the month in the name of the failure directory (Steven Rostedt) - IB/core: Fix zero dmac race in neighbor resolution (Chen Zhao) - dm mirror: fix integer overflow in create_dirty_log() (Junrui Luo) [Orabug: 39452197] {CVE-2026-46023} - crypto: atmel-tdes - fix DMA sync direction (Thorsten Blum) - crypto: ccree - fix a memory leak in cc_mac_digest() (Haoxiang Li) - crypto: hisilicon - Fix dma_unmap_single() direction (Thomas Fourier) - crypto: atmel-ecc - Release client on allocation failure (Thorsten Blum) - crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup (Thorsten Blum) - crypto: arm64/aes - Fix 32-bit aes_mac_update() arg treated as 64-bit (Eric Biggers) - taskstats: set version in TGID exit notifications (Yiyang Chen) - tcp: call sk_data_ready() after listener migration (Zhenzhong Wu) [Orabug: 39452160] {CVE-2026-46015} - inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails (Chia-Ming Chang) [Orabug: 39452251] {CVE-2026-46040} - md/raid5: validate payload size before accessing journal metadata (Junrui Luo) [Orabug: 39452350] {CVE-2026-46070} - md/raid5: fix soft lockup in retry_aligned_read() (Chia-Ming Chang) [Orabug: 39452288] {CVE-2026-46051} - ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (Sohei Koyama) [Orabug: 39452270] {CVE-2026-46046} - mtd: docg3: fix use-after-free in docg3_release() (James Kim) - mtd: docg3: Convert to platform remove callback returning void (Uwe Kleine-Konig) - io_uring/poll: fix backport of io_poll_add() changes (Jens Axboe) - io_uring/poll: fix EPOLL_URING_WAKE sometimes not being honored (Jens Axboe) - KVM: nSVM: Add missing consistency check for nCR3 validity (Yosry Ahmed) - KVM: nSVM: Clear GIF on nested #VMEXIT(INVALID) (Yosry Ahmed) - KVM: nSVM: Always inject a #GP if mapping VMCB12 fails on nested VMRUN (Yosry Ahmed) - KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (Yosry Ahmed) - KVM: SVM: Explicitly mark vmcb01 dirty after modifying VMCB intercepts (Sean Christopherson) - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (Kevin Cheng) [Orabug: 39452395] {CVE-2026-46082} - KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (Yosry Ahmed) [Orabug: 39452062] {CVE-2026-45987} - KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (Yosry Ahmed) - userfaultfd: allow registration of ranges below mmap_min_addr (Denis M. Karpov) - rtc: ntxec: fix OF node reference imbalance (Johan Hovold) - tpm: tpm_tis: add error logging for data transfer (Jacqueline Wong) - mmc: block: use single block write in retry (Bin Liu) - power: supply: axp288_charger: Do not cancel work before initializing it (Krzysztof Kozlowski) - tpm: avoid -Wunused-but-set-variable (Arnd Bergmann) - libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (Raphael Zimmer) [Orabug: 39452202] {CVE-2026-46024} - ipv4: icmp: validate reply type before using icmp_pointers (Ruide Cao) [Orabug: 39452244] {CVE-2026-46037} - drm/arcpgu: fix device node leak (Luca Ceresoli) - net/smc: avoid early lgr access in smc_clc_wait_msg (Ruijie Li) - iio: adc: ad7768-1: fix one-shot mode data acquisition (Jonathan Santos) - ALSA: 6fire: Fix input volume change detection (Cassio Gabriel) - ALSA: caiaq: Handle probe errors properly (Takashi Iwai) [Orabug: 39452127] {CVE-2026-46004} - ALSA: caiaq: Fix control_put() result and cache rollback (Cassio Gabriel) - selftests/mqueue: Fix incorrectly named file (Simon Liebold) - parisc: _llseek syscall is only available for 32-bit userspace (Helge Deller) - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (Robert Beckett) - md/raid10: fix deadlock with check operation and nowait requests (Josh Hunt) [Orabug: 39452285] {CVE-2026-46050} - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (Cassio Gabriel) - ALSA: ctxfi: Add fallback to default RSR for S/PDIF (Harin Lee) [Orabug: 39452281] {CVE-2026-46049} - ALSA: aoa: i2sbus: fix OF node lifetime handling (Cassio Gabriel) - ext2: reject inodes with zero i_nlink and valid mode in ext2_iget() (Vasiliy Kovalev) [Orabug: 39452120] {CVE-2026-46002} - net: qrtr: ns: Fix use-after-free in driver remove() (Manivannan Sadhasivam) [Orabug: 39452275] {CVE-2026-46047} - media: i2c: imx219: Check return value of devm_gpiod_get_optional() in imx219_probe() (Chen Ni) - lib/ts_kmp: fix integer overflow in pattern length calculation (Josh Law) - Revert 'ALSA: usb: Increase volume range that triggers a warning' (Rongrong) - PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown (Koichiro Den) - net: strparser: fix skb_head leak in strp_abort_strp() (Luxiao Xu) [Orabug: 39452469] {CVE-2026-46102} - net: caif: clear client service pointer on teardown (Zhengchuan Liang) - ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names() (Ziqing Chen) [Orabug: 39452417] {CVE-2026-46088} - crypto: pcrypt - Fix handling of MAY_BACKLOG requests (Herbert Xu) [Orabug: 39410864] {CVE-2026-43493} - um: drivers: call kernel_strrchr() explicitly in cow_user.c (Michael Bommarito) - driver core: Don't let a device probe until it's ready (Douglas Anderson) - padata: Remove comment for reorder_work (Herbert Xu) - padata: Fix pd UAF once and for all (Herbert Xu) [Orabug: 38335056] {CVE-2025-38584} - ocfs2: split transactions in dio completion to avoid credit exhaustion (Heming Zhao) [Orabug: 39452389] {CVE-2026-46080} - device property: Make modifications of fwnode 'flags' thread safe (Douglas Anderson) - scsi: ufs: core: Fix use-after free in init error and remove paths (Andre Draszik) - firmware: google: framebuffer: Do not mark framebuffer as busy (Thomas Zimmermann) - ibmasm: fix heap over-read in ibmasm_send_i2o_message() (Tyllis Xu) - ibmasm: fix OOB reads in command_file_write due to missing size checks (Tyllis Xu) - misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt() (Tyllis Xu) - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (Greg Kroah-Hartman) [Orabug: 39452134] {CVE-2026-46006} - ALSA: usb-audio: Evaluate packsize caps at the right place (Takashi Iwai) - usb: xhci: Make usb_host_endpoint.hcpriv survive endpoint_disable() (Michal Pecio) - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (Cassio Gabriel) - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (Cassio Gabriel) - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (Cassio Gabriel) [Orabug: 39452171] {CVE-2026-46018} - ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free (Jeongjun Park) - tty: n_gsm: fix flow control handling in tx path (Daniel Starke) - rxrpc: Fix missing validation of ticket length in non-XDR key preparsing (Anderson Nascimento) - crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (Sean Christopherson) [Orabug: 39300568] {CVE-2026-31697} - crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (Sean Christopherson) [Orabug: 39300572] {CVE-2026-31698} - crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (Sean Christopherson) [Orabug: 39300576] {CVE-2026-31699} - ALSA: caiaq: take a reference on the USB device in create_card() (Berk Cem Goksel) [Orabug: 39300587] {CVE-2026-31701} - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (Cryolitia Pukngae) - fuse: quiet down complaints in fuse_conn_limit_write (Darrick J. Wong) - fuse: reject oversized dirents in page cache (Samuel Page) [Orabug: 39300557] {CVE-2026-31694} - fs/ntfs3: validate rec-used in journal-replay file record check (Greg Kroah-Hartman) - iommu: fix a reference count leak in iommu_sva_bind_device() (Vasant Karasulli) - rxrpc: Fix anonymous key handling (David Howells) - rxrpc: only handle RESPONSE during service challenge (Jie Wang) [Orabug: 39342679,39368252] - ksmbd: unset conn-binding on failed binding request (Namjae Jeon) - scripts/dtc: Remove unused dts_version in dtc-lexer.l (Nathan Chancellor) - Revert 'wifi: cfg80211: stop NAN and P2P in cfg80211_leave' (Guocai He) - drivers: base: Free devm resources when unregistering a device (David Gow) - cpufreq: Avoid a bad reference count on CPU node (Miquel Sabate Sola) [Orabug: 37206351] {CVE-2024-50012} - net: clear the dst when changing skb protocol (Jakub Kicinski) [Orabug: 38158471] {CVE-2025-38192} - fbdev: efifb: Register sysfs groups through driver core (Thomas Weissschuh) [Orabug: 37205941] {CVE-2024-49925} - md/md-bitmap: Synchronize bitmap_get_stats() with bitmap lifetime (Yu Kuai) [Orabug: 37649831] {CVE-2025-21712} - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (Guangshuo Li) [Orabug: 39343645] {CVE-2026-43328} - cpufreq: governor: Free dbs_data directly when gov-init() fails (Liao Chang) - rxrpc: Fix recvmsg() unconditional requeue (David Howells) - fs/ntfs3: Add more attributes checks in mi_enum_attr() (Konstantin Komarov) {CVE-2023-45896} - btrfs: lock the inode in shared mode before starting fiemap (Filipe Manana) - f2fs: fix to trigger foreground gc during f2fs_map_blocks() in lfs mode (Chao Yu) - can: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted URBs (Marc Kleine-Budde) [Orabug: 38773752] {CVE-2025-68307} - Bluetooth: af_bluetooth: Fix deadlock (Luiz Augusto von Dentz) [Orabug: 36544919] {CVE-2024-26886} - iio: imu: inv_icm42600: fix odr switch when turning buffer off (Jean-Baptiste Maneyrol) - pstore: inode: Only d_invalidate() is needed (Kees Cook) [Orabug: 36598300] {CVE-2024-27389} - f2fs: fix to wait on block writeback for post_read case (Chao Yu) - net: stmmac: fix TSO DMA API usage causing oops (Russell King) [Orabug: 37434619] {CVE-2024-56719} - drm/amdgpu: unmap and remove csa_va properly (Lang Yu) - binfmt_misc: restore write access before closing files opened by open_exec() (Zilin Guan) [Orabug: 38773485] {CVE-2025-68239} - gfs2: No more self recovery (Andreas Gruenbacher) [Orabug: 38351909] {CVE-2025-38659} - bpf: Do mark_chain_precision for ARG_CONST_ALLOC_SIZE_OR_ZERO (Kumar Kartikeya Dwivedi) - dlm: fix possible lkb_resource null dereference (Alexander Aring) [Orabug: 37472202] {CVE-2024-47809} - Bluetooth: hci_core: Fix use-after-free in vhci_flush() (Kuniyuki Iwashima) [Orabug: 38175068] {CVE-2025-38250} - mailbox: Prevent out-of-bounds access in of_mbox_index_xlate() (Joonwon Kang) - btrfs: do not strictly require dirty metadata threshold for metadata writepages (Qu Wenruo) [Orabug: 38970329] {CVE-2026-23157} - btrfs: send: check for inline extents in range_is_hole_in_parent() (Qu Wenruo) [Orabug: 38970284] {CVE-2026-23141} - x86/uprobes: Fix XOL allocation failure for 32-bit tasks (Oleg Nesterov) - spi: cadence-quadspi: Implement refcount to handle unbind during busy (Khairul Anuar Romli) - fs: dlm: fix use after free in midcomms commit (Alexander Aring) - dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue() (Guodong Xu) - net/sched: cls_u32: use skb_header_pointer_careful() (Eric Dumazet) [Orabug: 38970488] {CVE-2026-23204} - net: add skb_header_pointer_careful() helper (Eric Dumazet) - dm-verity: disable recursive forward error correction (Mikulas Patocka) [Orabug: 38887637] {CVE-2025-71161} - blk-mq: use quiesced elevator switch when reinitializing queues (Keith Busch) - wifi: iwlwifi: read txq-read_ptr under lock (Johannes Berg) [Orabug: 36683388] {CVE-2024-36922} - f2fs: fix null-ptr-deref in f2fs_submit_page_bio() (Ye Bin) - s390/xor: Fix xor_xc_2() inline assembly constraints (Heiko Carstens) - ALSA: control: Avoid WARN() for symlink errors (Takashi Iwai) [Orabug: 37434224] {CVE-2024-56657} - nvme: nvme-fc: Ensure -ioerr_work is cancelled in nvme_fc_delete_ctrl() (Jaskaran Singh) [Orabug: 38730673] {CVE-2025-40261} - Revert 'nvme: nvme-fc: Ensure -ioerr_work is cancelled in nvme_fc_delete_ctrl()' (Jaskaran Singh) - tty: n_gsm: fix deadlock and link starvation in outgoing data path (Daniel Starke) - MPTCP: fix lock class name family in pm_nl_create_listen_socket (Li Xiasong) - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (Breno Leitao) [Orabug: 39273511] {CVE-2026-31586} - ocfs2: fix possible deadlock between unlink and dio_end_io_write (Joseph Qi) [Orabug: 39273588] {CVE-2026-31598} - fs/ocfs2: fix comments mentioning i_mutex (Hongnan Li) - rxrpc: reject undecryptable rxkad response tickets (Yuqi Xu) - rxrpc: Fix call removal to use RCU safe deletion (David Howells) - rxrpc: Fix key quota calculation for multitoken keys (David Howells) - xfrm: clear trailing padding in build_polexpire() (Yasuaki Torimaru) [Orabug: 39262402] {CVE-2026-31664} - ocfs2: fix out-of-bounds write in ocfs2_write_end_inline (Joseph Qi) [Orabug: 39331093] {CVE-2026-43075} - ocfs2: validate inline data i_size during inode read (Deepanshu Kartikey) [Orabug: 39331098] {CVE-2026-43076} - ocfs2: add inline inode consistency check to ocfs2_validate_inode_block() (Dmitry Antipov) - arm64: dts: imx8mq-librem5: Bump BUCK1 suspend voltage up to 0.85V (Sebastian Krzyszkowiak) - Revert 'arm64: dts: imx8mq-librem5: Set the DVS voltages lower' (Sebastian Krzyszkowiak) - arm64: dts: imx8mq-librem5: Bump BUCK1 suspend voltage to 0.81V (Sebastian Krzyszkowiak) - arm64: dts: imx8mq-librem5: Set the DVS voltages lower (Sebastian Krzyszkowiak) - powerpc64/bpf: do not increment tailcall count when prog is NULL (Hari Bathini) - netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR (Florian Westphal) - PCI/ACPI: Restrict program_hpx_type2() to AER bits (Hakon Bugge) - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (Felix Fietkau) [Orabug: 39167473] {CVE-2026-23444} - gfs2: Validate i_depth for exhash directories (Andrew Price) [Orabug: 38395007] {CVE-2025-38710} - gfs2: Improve gfs2_consist_inode() usage (Andrew Price) - ipv6: add NULL checks for idev in SRv6 paths (Heminhong) [Orabug: 39167468] {CVE-2026-23442} - Revert 'net: ixp4xx_eth: convert to ndo_hwtstamp_get() and ndo_hwtstamp_set()' (Sasha Levin) - Revert 'net: ethernet: xscale: Check for PTP support properly' (Sasha Levin) - PCI: endpoint: pci-epf-vntb: Remove duplicate resource teardown (Koichiro Den) - media: hackrf: fix to not free memory after the device is registered in hackrf_probe() (Jeongjun Park) - media: vidtv: fix pass-by-value structs causing MSAN warnings (Abd-Alrhman Masalkhi) - nilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map (Deepanshu Kartikey) - media: as102: fix to not free memory after the device is registered in as102_usb_probe() (Jeongjun Park) [Orabug: 39273468] {CVE-2026-31578} - bcache: fix cached_dev.sb_bio use-after-free and crash (Mingzhe Zou) [Orabug: 39273482] {CVE-2026-31580} - ALSA: 6fire: fix use-after-free on disconnect (Berk Cem Goksel) [Orabug: 39273487] {CVE-2026-31581} - media: em28xx: fix use-after-free in em28xx_v4l2_open() (Abhishek Kumar) [Orabug: 39273494] {CVE-2026-31583} - media: vidtv: fix nfeeds state corruption on start_streaming failure (Ruslan Valiyev) - mm/kasan: fix double free for kasan pXds (Ritesh Harjani) - KVM: x86: Use scratch field in MMIO fragment to hold small write values (Sean Christopherson) [Orabug: 39273523] {CVE-2026-31588} - checkpatch: add support for Assisted-by tag (Sasha Levin) - rxrpc: proc: size address buffers for %pISpc output (Pengpeng Hou) - nf_tables: nft_dynset: fix possible stateful expression memleak in error path (Pablo Neira Ayuso) [Orabug: 39139840] {CVE-2026-23399} - smb: client: fix potential UAF in smb2_is_valid_oplock_break() (Paulo Alcantara) - fsl-mc: Use driver_set_override() instead of open-coding (Krzysztof Kozlowski) - KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (Sean Christopherson) [Orabug: 39273531] {CVE-2026-31590} - ocfs2: handle invalid dinode in ocfs2_group_extend (Zhengyuan Huang) [Orabug: 39273570] {CVE-2026-31596} - ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY (Tejas Bharambe) [Orabug: 39273579] {CVE-2026-31597} - media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections (Ruslan Valiyev) - ALSA: ctxfi: Limit PTP to a single page (Harin Lee) [Orabug: 39273609] {CVE-2026-31602} - USB: serial: option: add Telit Cinterion FN990A MBIM composition (Fabio Porcedda) - staging: sm750fb: fix division by zero in ps_to_hz() (Junrui Luo) - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (Greg Kroah-Hartman) - usb: storage: Expand range of matched versions for VL817 quirks entry (Daniel Brat) - usbip: validate number_of_packets in usbip_pack_ret_submit() (Nathan Rebello) [Orabug: 39273632] {CVE-2026-31607} - usb: gadget: renesas_usb3: validate endpoint index in standard request handlers (Greg Kroah-Hartman) - usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete() (Greg Kroah-Hartman) - usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb() (Greg Kroah-Hartman) [Orabug: 39273669] {CVE-2026-31617} - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (Greg Kroah-Hartman) - ALSA: fireworks: bound device-supplied status before string array lookup (Greg Kroah-Hartman) [Orabug: 39273681] {CVE-2026-31619} - NFC: digital: Bounds check NFC-A cascade depth in SDD response handler (Greg Kroah-Hartman) - net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete() (Greg Kroah-Hartman) [Orabug: 39273693] {CVE-2026-31623} - HID: core: clamp report_size in s32ton() to avoid undefined shift (Greg Kroah-Hartman) [Orabug: 39273697] {CVE-2026-31624} - HID: alps: fix NULL pointer dereference in alps_raw_event() (Greg Kroah-Hartman) [Orabug: 39273705] {CVE-2026-31625} - staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify() (Lin Yu Chen) [Orabug: 39273709] {CVE-2026-31626} - i2c: s3c24xx: check the size of the SMBUS message before using it (Greg Kroah-Hartman) - can: raw: fix ro-uniq use-after-free in raw_rcv() (Samuel Page) [Orabug: 39273447] {CVE-2026-31532} - nfc: llcp: add missing return after LLCP_CLOSED checks (Junxi Qian) - ALSA: usb-audio: Update for native DSD support quirks (Jussi Laako) - MIPS: mm: Rewrite TLB uniquification for the hidden bit feature (Maciej W. Rozycki) - MIPS: mm: Suppress TLB uniquification on EHINV hardware (Maciej W. Rozycki) - MIPS: Always record SEGBITS in cpu_data.vmbits (Maciej W. Rozycki) - mips: mm: Allocate tlb_vpn array atomically (Stefan Wiehler) - netfilter: conntrack: add missing netlink policy validations (Florian Westphal) [Orabug: 39171450] {CVE-2026-31407} - i3c: fix uninitialized variable use in i2c setup (Jamie Iles) - perf/x86/intel/uncore: Skip discovery table for offline dies (Zide Chen) [Orabug: 39331116] {CVE-2026-43079} - gpio: tegra: fix irq_release_resources calling enable instead of disable (Samasth Norway Ananda) - l2tp: Drop large packets with UDP encap (Alice Mikityanska) [Orabug: 39331125] {CVE-2026-43080} - af_unix: read UNIX_DIAG_VFS data under unix_state_lock (Jiexun Wang) [Orabug: 39263356] {CVE-2026-31673} - netfilter: ip6t_eui64: reject invalid MAC header for all packets (Zhengchuan Liang) [Orabug: 39263406] {CVE-2026-31685} - netfilter: xt_multiport: validate range encoding in checkentry (Ao Zhou) [Orabug: 39263388] {CVE-2026-31681} - netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (Xiang Mei) [Orabug: 39331145] {CVE-2026-43085} - xfrm_user: fix info leak in build_mapping() (Greg Kroah-Hartman) [Orabug: 39331163] {CVE-2026-43089} - xsk: tighten UMEM headroom validation to account for tailroom and min frame (Maciej Fijalkowski) [Orabug: 39331181] {CVE-2026-43093} - e1000: check return value of e1000_read_eeprom (Agalakov Daniil) - tracing/probe: reject non-closed empty immediate strings (Pengpeng Hou) - nfc: s3fwrn5: allocate rx skb before consuming bytes (Pengpeng Hou) - ipv4: icmp: fix null-ptr-deref in icmp_build_probe() (Yiqi Sun) [Orabug: 39331198] {CVE-2026-43099} - net: lapbether: handle NETDEV_PRE_TYPE_CHANGE (Eric Dumazet) - net: sched: act_csum: validate nested VLAN headers (Ruide Cao) [Orabug: 39263401] {CVE-2026-31684} - eventpoll: defer struct eventpoll free to RCU grace period (Nicholas Carlini) [Orabug: 39784990] {CVE-2026-43074} - epoll: use refcount to reduce ep_mutex contention (Paolo Abeni) - drm/vc4: Protect madv read in vc4_gem_object_mmap() with madv_lock (Maira Canal) - drm/vc4: Fix a memory leak in hang state error path (Maira Canal) [Orabug: 39331212] {CVE-2026-43104} - drm/vc4: Fix memory leak of BO array in hang state (Maira Canal) [Orabug: 39331216] {CVE-2026-43105} - PCI: hv: Set default NUMA node to 0 for devices without affinity info (Long Li) - arm64: dts: imx8mq: Set the correct gpu_ahb clock frequency (Sebastian Krzyszkowiak) - soc: aspeed: socinfo: Mask table entries for accurate SoC ID matching (Potin Lai) - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (Tomasz Merta) - wifi: brcmfmac: validate bsscfg indices in IF events (Pengpeng Hou) [Orabug: 39331238] {CVE-2026-43110} - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (Arthur Husband) - HID: roccat: fix use-after-free in roccat_report_event (Benoit Sevens) [Orabug: 39331244] {CVE-2026-43111} - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (Leo Vriska) - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (Andy Shevchenko) - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (Fredric Cover) - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (Phil Willoughby) - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (Kuninori Morimoto) - wifi: wl1251: validate packet IDs before indexing tx_frames (Pengpeng Hou) [Orabug: 39331254] {CVE-2026-43113} - netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (Florian Westphal) [Orabug: 39331263] {CVE-2026-43114} - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (Cesar Montoya) - btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() (Goldwyn Rodrigues) [Orabug: 39331280] {CVE-2026-43117} - can: mcp251x: add error handling for power enable in open and resume (Wenyuan Li) - ALSA: asihpi: avoid write overflow check warning (Arnd Bergmann) - LTS version: v5.15.208 (Samasth Norway Ananda) - LTS version: v5.15.207 (Samasth Norway Ananda) - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (Prathyushi Nangia) [Orabug: 39460476] {CVE-2026-46174} - x86/CPU/AMD: Add X86_FEATURE_ZEN1 (Borislav Petkov) - LTS version: v5.15.206 (Samasth Norway Ananda) - LTS version: v5.15.205 (Samasth Norway Ananda) - LTS version: v5.15.204 (Samasth Norway Ananda) - xen/privcmd: fix double free via VMA splitting (Juergen Gross) [Orabug: 39305911] {CVE-2026-31787} - Buffer overflow in drivers/xen/sys-hypervisor.c (Juergen Gross) [Orabug: 39305899] {CVE-2026-31786}
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
No references available.
No linked vulnerabilities found.
{
"cves": [
"CVE-2023-45896",
"CVE-2024-26886",
"CVE-2024-27389",
"CVE-2024-36922",
"CVE-2024-47809",
"CVE-2024-49925",
"CVE-2024-50012",
"CVE-2024-56657",
"CVE-2024-56719",
"CVE-2025-21712",
"CVE-2025-21863",
"CVE-2025-22026",
"CVE-2025-23131",
"CVE-2025-23141",
"CVE-2025-38192",
"CVE-2025-38250",
"CVE-2025-38584",
"CVE-2025-38659",
"CVE-2025-38710",
"CVE-2025-39863",
"CVE-2025-39931",
"CVE-2025-40261",
"CVE-2025-68239",
"CVE-2025-68307",
"CVE-2025-71161",
"CVE-2026-23141",
"CVE-2026-23157",
"CVE-2026-23204",
"CVE-2026-23399",
"CVE-2026-23440",
"CVE-2026-23441",
"CVE-2026-23442",
"CVE-2026-23444",
"CVE-2026-31407",
"CVE-2026-31449",
"CVE-2026-31489",
"CVE-2026-31532",
"CVE-2026-31578",
"CVE-2026-31580",
"CVE-2026-31581",
"CVE-2026-31583",
"CVE-2026-31586",
"CVE-2026-31588",
"CVE-2026-31590",
"CVE-2026-31596",
"CVE-2026-31597",
"CVE-2026-31598",
"CVE-2026-31602",
"CVE-2026-31607",
"CVE-2026-31617",
"CVE-2026-31619",
"CVE-2026-31623",
"CVE-2026-31624",
"CVE-2026-31625",
"CVE-2026-31626",
"CVE-2026-31664",
"CVE-2026-31673",
"CVE-2026-31681",
"CVE-2026-31684",
"CVE-2026-31685",
"CVE-2026-31694",
"CVE-2026-31697",
"CVE-2026-31698",
"CVE-2026-31699",
"CVE-2026-31700",
"CVE-2026-31701",
"CVE-2026-31786",
"CVE-2026-31787",
"CVE-2026-43052",
"CVE-2026-43064",
"CVE-2026-43074",
"CVE-2026-43075",
"CVE-2026-43076",
"CVE-2026-43079",
"CVE-2026-43080",
"CVE-2026-43085",
"CVE-2026-43089",
"CVE-2026-43093",
"CVE-2026-43099",
"CVE-2026-43104",
"CVE-2026-43105",
"CVE-2026-43110",
"CVE-2026-43111",
"CVE-2026-43113",
"CVE-2026-43114",
"CVE-2026-43117",
"CVE-2026-43328",
"CVE-2026-43341",
"CVE-2026-43383",
"CVE-2026-43493",
"CVE-2026-43496",
"CVE-2026-43499",
"CVE-2026-43501",
"CVE-2026-45834",
"CVE-2026-45835",
"CVE-2026-45836",
"CVE-2026-45838",
"CVE-2026-45840",
"CVE-2026-45841",
"CVE-2026-45842",
"CVE-2026-45843",
"CVE-2026-45844",
"CVE-2026-45846",
"CVE-2026-45850",
"CVE-2026-45852",
"CVE-2026-45987",
"CVE-2026-45991",
"CVE-2026-46002",
"CVE-2026-46003",
"CVE-2026-46004",
"CVE-2026-46006",
"CVE-2026-46015",
"CVE-2026-46018",
"CVE-2026-46021",
"CVE-2026-46023",
"CVE-2026-46024",
"CVE-2026-46026",
"CVE-2026-46033",
"CVE-2026-46037",
"CVE-2026-46038",
"CVE-2026-46040",
"CVE-2026-46043",
"CVE-2026-46044",
"CVE-2026-46046",
"CVE-2026-46047",
"CVE-2026-46048",
"CVE-2026-46049",
"CVE-2026-46050",
"CVE-2026-46051",
"CVE-2026-46052",
"CVE-2026-46056",
"CVE-2026-46065",
"CVE-2026-46069",
"CVE-2026-46070",
"CVE-2026-46080",
"CVE-2026-46082",
"CVE-2026-46086",
"CVE-2026-46088",
"CVE-2026-46090",
"CVE-2026-46091",
"CVE-2026-46092",
"CVE-2026-46099",
"CVE-2026-46101",
"CVE-2026-46102",
"CVE-2026-46107",
"CVE-2026-46108",
"CVE-2026-46109",
"CVE-2026-46113",
"CVE-2026-46116",
"CVE-2026-46119",
"CVE-2026-46120",
"CVE-2026-46122",
"CVE-2026-46124",
"CVE-2026-46127",
"CVE-2026-46128",
"CVE-2026-46132",
"CVE-2026-46133",
"CVE-2026-46137",
"CVE-2026-46146",
"CVE-2026-46149",
"CVE-2026-46150",
"CVE-2026-46151",
"CVE-2026-46159",
"CVE-2026-46160",
"CVE-2026-46161",
"CVE-2026-46163",
"CVE-2026-46167",
"CVE-2026-46168",
"CVE-2026-46172",
"CVE-2026-46174",
"CVE-2026-46177",
"CVE-2026-46178",
"CVE-2026-46180",
"CVE-2026-46184",
"CVE-2026-46187",
"CVE-2026-46189",
"CVE-2026-46191",
"CVE-2026-46193",
"CVE-2026-46196",
"CVE-2026-46197",
"CVE-2026-46198",
"CVE-2026-46206",
"CVE-2026-46208",
"CVE-2026-46209",
"CVE-2026-46212",
"CVE-2026-46214",
"CVE-2026-46220",
"CVE-2026-46227",
"CVE-2026-46230",
"CVE-2026-46231",
"CVE-2026-46233",
"CVE-2026-46234",
"CVE-2026-46238",
"CVE-2026-46252",
"CVE-2026-46274",
"CVE-2026-46275",
"CVE-2026-46276",
"CVE-2026-46292",
"CVE-2026-46294",
"CVE-2026-46303",
"CVE-2026-46304",
"CVE-2026-46306",
"CVE-2026-46307",
"CVE-2026-46319",
"CVE-2026-46331",
"CVE-2026-52909",
"CVE-2026-52910",
"CVE-2026-52912",
"CVE-2026-52914",
"CVE-2026-52915",
"CVE-2026-52916",
"CVE-2026-52917",
"CVE-2026-52918",
"CVE-2026-52919",
"CVE-2026-52920",
"CVE-2026-52921",
"CVE-2026-52923",
"CVE-2026-52924",
"CVE-2026-52925",
"CVE-2026-52926",
"CVE-2026-52927",
"CVE-2026-52928",
"CVE-2026-52929",
"CVE-2026-52930",
"CVE-2026-52931",
"CVE-2026-52933",
"CVE-2026-52934",
"CVE-2026-52942",
"CVE-2026-52943",
"CVE-2026-52946",
"CVE-2026-52947",
"CVE-2026-52948",
"CVE-2026-52954",
"CVE-2026-52955",
"CVE-2026-52957",
"CVE-2026-52958",
"CVE-2026-52962",
"CVE-2026-52963",
"CVE-2026-52969",
"CVE-2026-52970",
"CVE-2026-52972",
"CVE-2026-52982",
"CVE-2026-52984",
"CVE-2026-52985",
"CVE-2026-52986",
"CVE-2026-52993",
"CVE-2026-52998",
"CVE-2026-52999",
"CVE-2026-53001",
"CVE-2026-53002",
"CVE-2026-53003",
"CVE-2026-53004",
"CVE-2026-53006",
"CVE-2026-53011",
"CVE-2026-53012",
"CVE-2026-53016",
"CVE-2026-53021",
"CVE-2026-53022",
"CVE-2026-53037",
"CVE-2026-53039",
"CVE-2026-53040",
"CVE-2026-53041",
"CVE-2026-53043",
"CVE-2026-53047",
"CVE-2026-53048",
"CVE-2026-53049",
"CVE-2026-53050",
"CVE-2026-53059",
"CVE-2026-53060",
"CVE-2026-53061",
"CVE-2026-53062",
"CVE-2026-53064",
"CVE-2026-53069",
"CVE-2026-53071",
"CVE-2026-53072",
"CVE-2026-53073",
"CVE-2026-53074",
"CVE-2026-53075",
"CVE-2026-53080",
"CVE-2026-53088",
"CVE-2026-53093",
"CVE-2026-53096",
"CVE-2026-53112",
"CVE-2026-53128",
"CVE-2026-53131",
"CVE-2026-53134",
"CVE-2026-53135",
"CVE-2026-53136",
"CVE-2026-53138",
"CVE-2026-53146",
"CVE-2026-53148",
"CVE-2026-53149",
"CVE-2026-53150",
"CVE-2026-53157",
"CVE-2026-53163",
"CVE-2026-53167",
"CVE-2026-53168",
"CVE-2026-53176",
"CVE-2026-53177",
"CVE-2026-53181",
"CVE-2026-53186",
"CVE-2026-53189",
"CVE-2026-53192",
"CVE-2026-53194",
"CVE-2026-53195",
"CVE-2026-53196",
"CVE-2026-53199",
"CVE-2026-53208",
"CVE-2026-53212",
"CVE-2026-53213",
"CVE-2026-53215",
"CVE-2026-53216",
"CVE-2026-53217",
"CVE-2026-53218",
"CVE-2026-53219",
"CVE-2026-53221",
"CVE-2026-53223",
"CVE-2026-53225",
"CVE-2026-53227",
"CVE-2026-53228",
"CVE-2026-53238",
"CVE-2026-53239",
"CVE-2026-53245",
"CVE-2026-53249",
"CVE-2026-53252",
"CVE-2026-53253",
"CVE-2026-53254",
"CVE-2026-53255",
"CVE-2026-53256",
"CVE-2026-53263",
"CVE-2026-53264",
"CVE-2026-53265",
"CVE-2026-53266",
"CVE-2026-53268",
"CVE-2026-53269",
"CVE-2026-53270",
"CVE-2026-53273",
"CVE-2026-53275",
"CVE-2026-53287",
"CVE-2026-53291",
"CVE-2026-53295",
"CVE-2026-53304",
"CVE-2026-53309",
"CVE-2026-53325",
"CVE-2026-53329",
"CVE-2026-53337",
"CVE-2026-53352",
"CVE-2026-53354",
"CVE-2026-53356",
"CVE-2026-53357",
"CVE-2026-53358",
"CVE-2026-53359",
"CVE-2026-53369",
"CVE-2026-53381",
"CVE-2026-53385",
"CVE-2026-53388",
"CVE-2026-53391",
"CVE-2026-53397",
"CVE-2026-53398",
"CVE-2026-53403",
"CVE-2026-63794",
"CVE-2026-63796",
"CVE-2026-63800",
"CVE-2026-63801",
"CVE-2026-63803",
"CVE-2026-63807",
"CVE-2026-63808",
"CVE-2026-63809",
"CVE-2026-63822",
"CVE-2026-63823",
"CVE-2026-63824",
"CVE-2026-63831",
"CVE-2026-63834",
"CVE-2026-63835",
"CVE-2026-63836",
"CVE-2026-63860",
"CVE-2026-63865",
"CVE-2026-63867",
"CVE-2026-63868",
"CVE-2026-63870",
"CVE-2026-63875",
"CVE-2026-63891",
"CVE-2026-63892",
"CVE-2026-63893",
"CVE-2026-63897",
"CVE-2026-63898",
"CVE-2026-63899",
"CVE-2026-63900",
"CVE-2026-63901",
"CVE-2026-63902",
"CVE-2026-63903",
"CVE-2026-63904",
"CVE-2026-63905",
"CVE-2026-63908",
"CVE-2026-63912",
"CVE-2026-63913",
"CVE-2026-63914",
"CVE-2026-63916",
"CVE-2026-63917",
"CVE-2026-63919",
"CVE-2026-63920",
"CVE-2026-63921",
"CVE-2026-63922",
"CVE-2026-63924",
"CVE-2026-63925",
"CVE-2026-63926",
"CVE-2026-63927",
"CVE-2026-63928",
"CVE-2026-63942",
"CVE-2026-63947",
"CVE-2026-63948",
"CVE-2026-63956",
"CVE-2026-63957",
"CVE-2026-63961",
"CVE-2026-63971",
"CVE-2026-63975",
"CVE-2026-63976",
"CVE-2026-63984",
"CVE-2026-63985",
"CVE-2026-63990",
"CVE-2026-63992",
"CVE-2026-63993",
"CVE-2026-63994",
"CVE-2026-64002",
"CVE-2026-64007",
"CVE-2026-64009",
"CVE-2026-64012",
"CVE-2026-64014",
"CVE-2026-64018",
"CVE-2026-64028",
"CVE-2026-64032",
"CVE-2026-64034",
"CVE-2026-64039",
"CVE-2026-64046",
"CVE-2026-64047",
"CVE-2026-64088",
"CVE-2026-64089",
"CVE-2026-64090",
"CVE-2026-64091",
"CVE-2026-64092",
"CVE-2026-64094",
"CVE-2026-64095",
"CVE-2026-64096",
"CVE-2026-64103",
"CVE-2026-64113",
"CVE-2026-64114",
"CVE-2026-64115",
"CVE-2026-64116",
"CVE-2026-64118",
"CVE-2026-64123",
"CVE-2026-64125",
"CVE-2026-64126",
"CVE-2026-64133",
"CVE-2026-64153",
"CVE-2026-64155",
"CVE-2026-64164",
"CVE-2026-64166",
"CVE-2026-64170",
"CVE-2026-64173",
"CVE-2026-64174",
"CVE-2026-64177",
"CVE-2026-64178",
"CVE-2026-64185",
"CVE-2026-64191",
"CVE-2026-64218",
"CVE-2026-64219",
"CVE-2026-64220",
"CVE-2026-64237",
"CVE-2026-64240",
"CVE-2026-64524",
"CVE-2026-64527",
"CVE-2026-64528",
"CVE-2026-64529",
"CVE-2026-64531",
"CVE-2026-64561",
"CVE-2026-64600",
"CVE-2026-68480"
],
"cvss": 0.0,
"database_specific": {
"severity": "N/A"
},
"description": "[5.15.0-323.211.3.3]\n- Revert 'x86/alternatives: Add alt_instr.flags' (Harshit Mogalapalli) [Orabug: 39853924]\n\n[5.15.0-323.211.3.2]\n- ACPI: resource: Always use MADT override IRQ settings for all legacy non i8042 IRQs (Hans de Goede) [Orabug: 39848333]\n- KVM: x86/mmu: Stop needlessly making MMU pages available for TDP MMU faults (David Matlack) [Orabug: 39848194]\n- KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Sean Christopherson) [Orabug: 39848194] {CVE-2026-64561}\n- KVM: x86/mmu: Rename __direct_map() to direct_map() (David Matlack) [Orabug: 39848194]\n- KVM: x86/mmu: Split out TDP MMU page fault handling (David Matlack) [Orabug: 39848194]\n- KVM: Rename mmu_notifier_* to mmu_invalidate_* (Chao Peng) [Orabug: 39848194]\n- KVM: x86/mmu: Document the 'rules' for using host_pfn_mapping_level() (Sean Christopherson) [Orabug: 39848194]\n- KVM: x86/mmu: Rename pte_list_{destroy,remove}() to show they zap SPTEs (Sean Christopherson) [Orabug: 39848194]\n- KVM: x86/mmu: Directly 'destroy' PTE list when recycling rmaps (Sean Christopherson) [Orabug: 39848194]\n- x86/bugs: Make Safe-RET robust against interrupt injection (Borislav Petkov (AMD)) [Orabug: 39849605] {CVE-2026-68480}\n- x86/alternatives: Disable interrupts and sync when optimizing NOPs in place (Thomas Gleixner) [Orabug: 39849605]\n- x86/alternative: Support relocations in alternatives (Peter Zijlstra) [Orabug: 39849605]\n- x86/alternative: Make debug-alternative selective (Peter Zijlstra) [Orabug: 39849605]\n- x86/alternatives: Add alt_instr.flags (Borislav Petkov (AMD)) [Orabug: 39849605]\n- x86/asm: Provide ALTERNATIVE_3 (Peter Zijlstra) [Orabug: 39849605]\n- net: tap: set skb-dev before parsing virtio net header in tap_get_user_xdp() (Dongli Zhang) [Orabug: 39848314]\n\n[5.15.0-323.211.3.1]\n- net: openvswitch: reject oversized nested action attrs (Asim Viladi Oglu Manizada) [Orabug: 39816016] {CVE-2026-64531}\n- xfs: resample the data fork mapping after cycling ILOCK (Darrick J. Wong) [Orabug: 39816098] {CVE-2026-64600}\n\n[5.15.0-323.211.3]\n- LTS version: v5.15.211 (Vijayendra Suman)\n- dlm: prevent NPD when writing a positive value to event_done (Thadeu Lima de Souza Cascardo) [Orabug: 37844553] {CVE-2025-23131}\n- crypto: qat - remove unused character device and IOCTLs (Giovanni Cabiddu) [Orabug: 39786549] {CVE-2026-64529}\n- crypto: qat - Return pointer directly in adf_ctl_alloc_resources (Herbert Xu)\n- crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (Thorsten Blum)\n- Documentation: ioctl-number: Extend 'Include File' column width (Bagas Sanjaya)\n- ksmbd: reject non-VALID session in compound request branch (Gil Portnoy)\n- fuse: re-lock request before replacing page cache folio (Joanne Koong) [Orabug: 39753883] {CVE-2026-53388}\n- net: phonet: free phonet_device after RCU grace period (Santosh Kalluri) [Orabug: 39637380] {CVE-2026-53157}\n- phonet: Pass net and ifindex to phonet_address_notify(). (Kuniyuki Iwashima)\n- phonet: Pass ifindex to fill_addr(). (Kuniyuki Iwashima)\n- Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (Dexuan Cui)\n- misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (Mukesh Ojha)\n- misc: fastrpc: Add dma_mask to fastrpc_channel_ctx (Abel Vesa)\n- hv: utils: handle and propagate errors in kvp_register (Thorsten Blum)\n- mptcp: fix missing wakeups in edge scenarios (Paolo Abeni)\n- NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (Michael Bommarito) [Orabug: 39753890] {CVE-2026-53391}\n- nfsd: check get_user() return when reading princhashlen (Dominik Wozniak)\n- nfsd: fix posix_acl leak on SETACL decode failure (Jeff Layton) [Orabug: 39753905] {CVE-2026-53397}\n- NFSD: Fix SECINFO_NO_NAME decode error cleanup (Guannan Wang) [Orabug: 39753909] {CVE-2026-53398}\n- fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (Steffen Persvold)\n- fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (Ian Bridges) [Orabug: 39753928] {CVE-2026-53403}\n- power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (Xu Wang)\n- KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (Ashutosh Desai) [Orabug: 39753936] {CVE-2026-63794}\n- ocfs2: reject oversized group bitmap descriptors (Zhang Cen) [Orabug: 39753942] {CVE-2026-63796}\n- fpga: region: fix use-after-free in child_regions_with_firmware() (Xu Wang)\n- irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove (Qingshuang Fu)\n- pNFS: Fix use-after-free in pnfs_update_layout() (Xu Wang) [Orabug: 39753953] {CVE-2026-63800}\n- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Doruk Tan Ozturk) [Orabug: 39753957] {CVE-2026-63801}\n- hdlc_ppp: sync per-proto timers before freeing hdlc state (Fan Wu) [Orabug: 39753963] {CVE-2026-63803}\n- exfat: fix potential use-after-free in exfat_find_dir_entry() (Michael Bommarito) [Orabug: 39753979] {CVE-2026-63808}\n- MIPS: DEC: Prevent initial console buffer from landing in XKPHYS (Maciej W. Rozycki)\n- bpf: use kvfree() for replaced sysctl write buffer (Dawei Feng) [Orabug: 39753982] {CVE-2026-63809}\n- f2fs: validate ACL entry sizes in f2fs_acl_from_disk() (Zhang Cen)\n- wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (Bitterblue Smith)\n- wifi: ath11k: fix warning when unbinding (Jose Ignacio Tornos Martinez) [Orabug: 39754021] {CVE-2026-63822}\n- wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (Zenm Chen)\n- keys: Pin request_key_auth payload in instantiate paths (Shaomin Chen) [Orabug: 39754024] {CVE-2026-63823}\n- KEYS: fix overflow in keyctl_pkey_params_get_2() (Jarkko Sakkinen) [Orabug: 39754028] {CVE-2026-63824}\n- mac802154: llsec: add skb_cow_data() before in-place crypto (Doruk Tan Ozturk) [Orabug: 39754053] {CVE-2026-63831}\n- crypto: af_alg - Set merge to zero early in af_alg_sendmsg (Herbert Xu) [Orabug: 38503789] {CVE-2025-39931}\n- ext4: add bounds check for inline data length in ext4_read_inline_page (Yuto Ohnuki)\n- ntfs3: reject direct userspace writes to reserved * xattrs (Konstantin Komarov)\n- ring-buffer: Remove ring_buffer_read_prepare_sync() (Bjoern Doebel)\n- batman-adv: tvlv: avoid race of cifsnotfound handler state (Sven Eckelmann)\n- batman-adv: tvlv: enforce 2-byte alignment (Sven Eckelmann)\n- batman-adv: dat: prevent false sharing between VLANs (Sven Eckelmann)\n- batman-adv: tt: track roam count per VID (Sven Eckelmann)\n- batman-adv: tt: don't merge change entries with different VIDs (Sven Eckelmann)\n- batman-adv: tp_meter: handle overlapping packets (Sven Eckelmann)\n- batman-adv: tp_meter: prevent parallel modifications of last_recv (Sven Eckelmann)\n- batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE (Sven Eckelmann)\n- batman-adv: tp_meter: restrict number of unacked list entries (Sven Eckelmann) [Orabug: 39754066] {CVE-2026-63834}\n- batman-adv: v: prevent OGM aggregation on disabled hardif (Sven Eckelmann) [Orabug: 39754070] {CVE-2026-63835}\n- batman-adv: frag: avoid underflow of TTL (Sven Eckelmann)\n- batman-adv: frag: ensure fragment is writable before modifying TTL (Sven Eckelmann)\n- batman-adv: fix (m|b)cast csum after decrementing TTL (Sven Eckelmann)\n- batman-adv: ensure bcast is writable before modifying TTL (Sven Eckelmann)\n- batman-adv: tp_meter: initialize last_recv_time during init (Sven Eckelmann)\n- batman-adv: prevent ELP transmission interval underflow (Sven Eckelmann)\n- batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (Sven Eckelmann)\n- batman-adv: tp_meter: add only finished tp_vars to lists (Sven Eckelmann)\n- batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (Sven Eckelmann)\n- batman-adv: tp_meter: fix fast recovery precondition (Sven Eckelmann)\n- batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (Sven Eckelmann) [Orabug: 39754076] {CVE-2026-63836}\n- batman-adv: tp_meter: avoid window underflow (Sven Eckelmann)\n- batman-adv: tp_meter: initialize dec_cwnd explicitly (Sven Eckelmann)\n- batman-adv: tp_meter: initialize dup_acks explicitly (Sven Eckelmann)\n- batman-adv: tp_meter: keep unacked list in ascending ordered (Sven Eckelmann)\n- kselftest/arm64: signal: Skip SVE signal test if not enough VLs supported (Yijia Wang)\n- Revert 'ptp: add testptp mask test' (Petr Machata)\n- Revert 'selftest/ptp: update ptp selftest to exercise the gettimex options' (Petr Machata)\n- virtiofs: fix UAF on submount umount (Miklos Szeredi) [Orabug: 39753856] {CVE-2026-53381}\n- media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (Ruslan Valiyev)\n- vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (Yi Yang) [Orabug: 39753871] {CVE-2026-53385}\n- regulator: core: fix locking in regulator_resolve_supply() error path (Andre Draszik) [Orabug: 39489558] {CVE-2026-46252}\n- af_unix: Reject SIOCATMARK on non-stream sockets (Jiexun Wang) [Orabug: 39619334] {CVE-2026-52928}\n- xhci: fix memory leak regression when freeing xhci vdev devices depth first (Mathias Nyman)\n- agp/amd64: Fix broken error propagation in agp_amd64_probe() (Mingyu Wang) [Orabug: 39662073] {CVE-2026-53325}\n- net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (Weiming Shi)\n- i2c: stub: Reject I2C block transfers with invalid length (Weiming Shi) [Orabug: 39760892] {CVE-2026-64191}\n- RDMA/bnxt_re: zero shared page before exposing to userspace (Lord Ulf Henrik Holmberg)\n- iio: light: bh1780: fix PM runtime leak on error path (Antoniu Miclaus)\n- batman-adv: tt: prevent TVLV entry number overflow (Sven Eckelmann)\n- batman-adv: tt: reject oversized local TVLV buffers (Sven Eckelmann)\n- drm/v3d: Skip CSD when it has zeroed workgroups (Maira Canal)\n- drm/v3d: Store the active job inside the queue's state (Maira Canal)\n- ip6_vti: set netns_immutable on the fallback device. (Eric Dumazet) [Orabug: 39589885] {CVE-2026-52909}\n- drm/amd/display: Bound VBIOS record-chain walk loops (Harry Wentland) [Orabug: 39637312] {CVE-2026-53138}\n- fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (Jann Horn) [Orabug: 39637410] {CVE-2026-53167}\n- LTS version: v5.15.210 (Vijayendra Suman)\n- netfilter: require Ethernet MAC header before using eth_hdr() (Zhengchuan Liang) [Orabug: 39637279] {CVE-2026-53131}\n- batman-adv: tp_meter: avoid role confusion in tp_list (Sven Eckelmann)\n- batman-adv: tp_meter: fix race condition in send error reporting (Sven Eckelmann)\n- ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops (Ali Ganiyev)\n- Bluetooth: MGMT: Fix backward compatibility with userspace (Luiz Augusto von Dentz)\n- media: rc: igorplugusb: fix control request setup packet (Henri A) [Orabug: 39785220] {CVE-2026-64240}\n- batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown (Sven Eckelmann) [Orabug: 39784982] {CVE-2026-64092}\n- media: rc: ttusbir: fix inverted error logic (Oliver Neukum)\n- apparmor: validate default DFA states are in bounds (Ben Hutchings)\n- fbdev: vt8500lcdfb: Fix dma_free_coherent() cpu_addr parameter (Ben Hutchings)\n- mptcp: close TOCTOU race while computing rcv_wnd (Paolo Abeni) [Orabug: 39754146] {CVE-2026-63867}\n- arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU (Will Deacon)\n- arm64: errata: Mitigate TLBI errata on NVIDIA Olympus CPU (Shanker Donthineni)\n- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39674327] {CVE-2026-53354}\n- arm64: cputype: Add NVIDIA Olympus definitions (Shanker Donthineni)\n- selinux: enable genfscon labeling for securityfs (Christian Gottsche)\n- ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (Aaron Erhardt)\n- ksmbd: Compare MACs in constant time (Eric Biggers)\n- net/ipv6: ioam6: prevent schema length wraparound in trace fill (Pengpeng Hou) [Orabug: 39343685] {CVE-2026-43341}\n- batman-adv: tp_meter: fix tp_num leak on kmalloc failure (Sven Eckelmann)\n- batman-adv: stop tp_meter sessions during mesh teardown (Jiexun Wang) [Orabug: 39460622] {CVE-2026-46208}\n- blk-cgroup: Fix NULL deref caused by blkg_policy_data being installed before init (Tejun Heo)\n- ipvs: skip ipv6 extension headers for csum checks (Julian Anastasov) [Orabug: 39451541] {CVE-2026-45850}\n- mm/huge_memory: update file PMD counter before folio_put() (Yin Tirui) [Orabug: 39637477] {CVE-2026-53189}\n- RDMA/umem: Fix truncation for block sizes = 4G (Jason Gunthorpe)\n- RDMA: Move DMA block iterator logic into dedicated files (Leon Romanovsky)\n- RDMA/umem: fix kernel-doc warnings (Randy Dunlap)\n- hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf (Anton Leontev) [Orabug: 39637516] {CVE-2026-53199}\n- netfilter: nft_fib: fix stale stack leak via the OIFNAME register (Davide Ornaghi) [Orabug: 39637292] {CVE-2026-53134}\n- serial: qcom-geni: fix UART_RX_PAR_EN bit position (Prasanna S)\n- tty: serial: qcom-geni-serial: align #define values (Bartosz Golaszewski)\n- tty: serial: qcom-geni-serial: remove unused symbols (Bartosz Golaszewski)\n- serial: altera_jtaguart: handle uart_add_one_port() failures (Myeonghun Pak)\n- serial: altera_jtaguart: Use platform_get_irq_optional() to get the interrupt (Lad Prabhakar)\n- drm/hyperv: validate resolution_count and fix WIN8 fallback (Berkant Koc) [Orabug: 39786537] {CVE-2026-64524}\n- drm/hyperv: Remove support for Hyper-V 2008 and 2008R2/Win7 (Michael Kelley)\n- usb: typec: ucsi: Check if power role change actually happened before handling (Myrrh Periwinkle)\n- thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (Michael Bommarito) [Orabug: 39754211] {CVE-2026-63891}\n- usb: gadget: f_hid: fix device reference leak in hidg_alloc() (Guangshuo Li)\n- usb: gadget: f_hid: tidy error handling in hidg_alloc (John Keeping)\n- usb: dwc3: xilinx: fix error handling in zynqmp init error paths (Radhey Shyam Pandey)\n- tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (Tudor Ambarus) [Orabug: 39786545] {CVE-2026-64528}\n- tty: serial: samsung: use u32 for register interactions (Tudor Ambarus)\n- serial: samsung_tty: Use port lock wrappers (Thomas Gleixner)\n- usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (Peter Chen)\n- iio: dac: ad5686: fix ref bit initialization for single-channel parts (Rodrigo Alencar)\n- iio: chemical: scd30: fix division by zero in write_raw (Antoniu Miclaus)\n- iio: chemical: scd30: Use guard(mutex) to allow early returns (Jonathan Cameron)\n- iio: gyro: adis16260: fix division by zero in write_raw (Antoniu Miclaus)\n- Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (Siwei Zhang) [Orabug: 39681273] {CVE-2026-53358}\n- phy: tegra: xusb: Fix per-pad high-speed termination calibration (Wayne Chang)\n- phy: tegra: xusb: Disable trk clk when not in use (Wayne Chang)\n- arm64: tlb: Flush walk cache when unsharing PMD tables (Zeng Heng) [Orabug: 39755010] {CVE-2026-63875}\n- spi: qup: fix error pointer deref after DMA setup failure (Johan Hovold) [Orabug: 39754942] {CVE-2026-64170}\n- spi: qup: switch to use modern name (Yang Yingliang)\n- octeontx2-pf: avoid double free of pool-stack on AQ init failure (Dawei Feng)\n- octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (Sam Daly)\n- mptcp: do not drop partial packets (Shardul Bankar)\n- selftests: mptcp: drop nanoseconds width specifier (Matthieu Baerts)\n- mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient (Li Xiasong)\n- use less confusing names for iov_iter direction initializers (Al Viro)\n- ipv6: ioam: add NULL check for idev in ipv6_hop_ioam() (Justin Iurman) [Orabug: 39754825] {CVE-2026-64116}\n- ipv6/addrconf: annotate data-races around devconf fields (II) (Eric Dumazet)\n- ice: fix VF queue configuration with low MTU values (Jose Ignacio Tornos Martinez)\n- net: hsr: defer node table free until after RCU readers (Michael Bommarito) [Orabug: 39754840] {CVE-2026-64123}\n- Bluetooth: serialize accept_q access (Jiexun Wang) [Orabug: 39619283] {CVE-2026-52918}\n- Bluetooth: Init sk_peer_* on bt_sock_alloc (Luiz Augusto von Dentz)\n- Bluetooth: Consolidate code around sk_alloc into a helper function (Luiz Augusto von Dentz)\n- qed: fix double free in qed_cxt_tables_alloc() (Dawei Feng) [Orabug: 39754830] {CVE-2026-64118}\n- Bluetooth: MGMT: validate Add Extended Advertising Data length (Michael Bommarito) [Orabug: 39754849] {CVE-2026-64126}\n- Bluetooth: hci_sync: Make use of hci_cmd_sync_queue set 2 (Luiz Augusto von Dentz)\n- Bluetooth: hci_qca: Convert timeout from jiffies to ms (Shuai Zhang)\n- Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (Safa Karakus) [Orabug: 39681270] {CVE-2026-53357}\n- smb: client: require net admin for CIFS SWN netlink (Michael Bommarito)\n- genetlink: Use internal flags for multicast groups (Ido Schimmel)\n- spi: lantiq-ssc: fix controller deregistration (Johan Hovold)\n- spi: st-ssc4: fix controller deregistration (Johan Hovold)\n- f2fs: fix false alarm of lockdep on cp_global_sem lock (Chao Yu)\n- f2fs: fix incorrect file address mapping when inline inode is unwritten (Yongpeng Yang)\n- mptcp: pm: ADD_ADDR rtx: resched blocked ADD_ADDR quicker (Matthieu Baerts)\n- mptcp: pm: ADD_ADDR rtx: fix potential data-race (Matthieu Baerts) [Orabug: 39460320] {CVE-2026-46137}\n- mptcp: pm: prio: skip closed subflows (Matthieu Baerts)\n- smb: client: Use FullSessionKey for AES-256 encryption key derivation (Piyush Sachdeva)\n- btrfs: fix missing last_unlink_trans update when removing a directory (Filipe Manana) [Orabug: 39460410] {CVE-2026-46160}\n- smb: client: validate dacloffset before building DACL pointers (Michael Bommarito)\n- pmdomain: core: Fix detach procedure for virtual devices in genpd (Ulf Hansson) [Orabug: 39524579] {CVE-2026-46292}\n- tracing/probes: Limit size of event probe to 3K (Steven Rostedt)\n- btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (Yochai Eisenrich) [Orabug: 39460405] {CVE-2026-46159}\n- spi: topcliff-pch: fix controller deregistration (Johan Hovold)\n- spi: topcliff-pch: Convert to platform remove callback returning void (Uwe Kleine-Konig)\n- fbcon: Avoid OOB font access if console rotation fails (Thomas Zimmermann) [Orabug: 39460548] {CVE-2026-46191}\n- mm/hugetlb_cma: round up per_node before logging it (Sang-Heon Jeon)\n- spi: uniphier: fix controller deregistration (Johan Hovold)\n- spi: tegra20-sflash: fix controller deregistration (Johan Hovold)\n- spi: tegra114: fix controller deregistration (Johan Hovold)\n- spi: sun6i: fix controller deregistration (Johan Hovold)\n- spi: zynq-qspi: fix controller deregistration (Johan Hovold)\n- spi: ti-qspi: fix controller deregistration (Johan Hovold)\n- spi: spi-ti-qspi: Convert to platform remove callback returning void (Uwe Kleine-Konig)\n- spi: sun4i: fix controller deregistration (Johan Hovold)\n- spi: syncuacer: fix controller deregistration (Johan Hovold)\n- xfrm: ah: account for ESN high bits in async callbacks (Michael Bommarito) [Orabug: 39460554] {CVE-2026-46193}\n- net: ipv6: stop checking crypto_ahash_alignmask (Eric Biggers)\n- net: ipv4: stop checking crypto_ahash_alignmask (Eric Biggers)\n- usb: dwc3: Move GUID programming after PHY initialization (Selvarasu Ganesan)\n- wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (Marek Szyprowski) [Orabug: 39460504] {CVE-2026-46180}\n- usb: typec: tcpm: reset internal port states on soft reset AMS (Amit Sunil Dhamne)\n- smb: client: validate the whole DACL before rewriting it in cifsacl (Michael Bommarito)\n- tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() (David Carlier) [Orabug: 39460568] {CVE-2026-46196}\n- crypto: caam - guard HMAC key hex dumps in hash_digest_key (Thorsten Blum)\n- printk: add print_hex_dump_devel() (Thorsten Blum)\n- ALSA: aloop: Fix peer runtime UAF during format-change stop (Cassio Gabriel) [Orabug: 39452424] {CVE-2026-46090}\n- ceph: only d_add() negative dentries when they are unhashed (Max Kellermann) [Orabug: 39452292] {CVE-2026-46052}\n- erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() (Junrui Luo)\n- can: ucan: fix devres lifetime (Johan Hovold)\n- can: ucan: fix typos in comments (Julia Lawall)\n- Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (Shuvam Pandey) [Orabug: 39452305] {CVE-2026-46056}\n- hfsplus: fix held lock freed on hfsplus_fill_super() (Zilin Guan)\n- hfsplus: fix uninit-value by validating catalog record size (Deepanshu Kartikey)\n- udf: fix partition descriptor append bookkeeping (Seohyeon Maeng) [Orabug: 39452078] {CVE-2026-45991}\n- mtd: spi-nor: sst: Fix write enable before AAI sequence (Sanjaikumar V S)\n- mmc: sdhci-of-dwcmshc: Disable clock before DLL configuration (Shawn Lin)\n- randomize_kstack: Maintain kstack_offset per task (Ryan Roberts)\n- fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info (Thomas Zimmermann) [Orabug: 39452332] {CVE-2026-46065}\n- net: bridge: use a stable FDB dst snapshot in RCU readers (Zhengchuan Liang) [Orabug: 39452412] {CVE-2026-46086}\n- net: qrtr: ns: Limit the total number of nodes (Manivannan Sadhasivam) [Orabug: 39452124] {CVE-2026-46003}\n- net: mctp: fix don't require received header reserved bits to be zero (Yuanzhaoming)\n- net: qrtr: ns: Free the node during ctrl_cmd_bye() (Manivannan Sadhasivam) [Orabug: 39452247] {CVE-2026-46038}\n- net: qrtr: ns: Change servers radix tree to xarray (Vignesh Viswanathan)\n- net: qrtr: ns: Limit the maximum number of lookups (Manivannan Sadhasivam) [Orabug: 39452208] {CVE-2026-46026}\n- ALSA: core: Fix potential data race at fasync handling (Takashi Iwai)\n- sched: Use u64 for bandwidth ratio calculations (Joseph Salisbury)\n- media: rc: igorplugusb: heed coherency rules (Oliver Neukum) [Orabug: 39452433] {CVE-2026-46091}\n- erofs: fix the out-of-bounds nameoff handling for trailing dirents (Gao Xiang)\n- ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (Thorsten Blum)\n- media: rc: ttusbir: respect DMA coherency rules (Oliver Neukum)\n- ALSA: aoa: i2sbus: clear stale prepared state (Cassio Gabriel)\n- ALSA: aoa: Use guard() for mutex locks (Takashi Iwai)\n- wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (Daniel Hodges) [Orabug: 39452344] {CVE-2026-46069}\n- thermal: core: Fix thermal zone governor cleanup issues (Rafael J. Wysocki) [Orabug: 39452187] {CVE-2026-46021}\n- wifi: rtw88: check for PCI upstream bridge existence (Fedor Pchelkin) [Orabug: 39452438] {CVE-2026-46092}\n- rtw88: 8821ce: Disable PCIe ASPM L1 for 8821CE using chip ID (Jimmy Hon)\n- arm64/mm: Enable batched TLB flush in unmap_hotplug_range() (Anshuman Khandual)\n- net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (Bingquan Chen) [Orabug: 39300581] {CVE-2026-31700}\n- ksmbd: require minimum ACE size in smb_check_perm_dacl() (Michael Bommarito)\n- smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path (Michael Bommarito)\n- smb: client: require a full NFS mode SID before reading mode bits (Michael Bommarito)\n- smb: server: fix max_connections off-by-one in tcp accept path (Daemyung Kang)\n- smb: server: fix active_num_conn leak on transport allocation failure (Michael Bommarito)\n- f2fs: fix UAF caused by decrementing sbi-nr_pages[] in f2fs_write_end_io() (Yongpeng Yang)\n- f2fs: fix to do sanity check on dcc-discard_cmd_cnt conditionally (Chao Yu)\n- lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (Lukas Wunner)\n- net/tcp-md5: Fix MAC comparison to be constant-time (Eric Biggers) [Orabug: 39343806] {CVE-2026-43383}\n- io_uring/poll: fix signed comparison in io_poll_get_ownership() (Longxuan Yu) [Orabug: 39619351] {CVE-2026-52933}\n- mm/damon/ops-common: call folio_test_lru() after folio_get() (Seongjae Park)\n- fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (Mingyu Wang) [Orabug: 39655978] {CVE-2026-52946}\n- drm/amd/display: Use krealloc_array() in dal_vector_reserve() (Harry Wentland) [Orabug: 39674253] {CVE-2026-53329}\n- drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (Harry Wentland) [Orabug: 39637296] {CVE-2026-53135}\n- drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (Harry Wentland) [Orabug: 39637301] {CVE-2026-53136}\n- drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (Harry Wentland)\n- slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl-lock (Bjorn Andersson)\n- thunderbolt: Limit XDomain response copy to actual frame size (Michael Bommarito) [Orabug: 39637337] {CVE-2026-53146}\n- thunderbolt: Clamp XDomain response data copy to allocation size (Michael Bommarito) [Orabug: 39637346] {CVE-2026-53148}\n- thunderbolt: Bound root directory content to block size (Michael Bommarito) [Orabug: 39637351] {CVE-2026-53149}\n- thunderbolt: Reject zero-length property entries in validator (Michael Bommarito) [Orabug: 39637356] {CVE-2026-53150}\n- sctp: stream: fully roll back denied add-stream state (Wyatt Feng) [Orabug: 39619338] {CVE-2026-52929}\n- sctp: diag: reject stale associations in dump_one path (Zhao Zhang) [Orabug: 39619278] {CVE-2026-52917}\n- mmc: sdhci: add signal voltage switch in sdhci_resume_host (Jisheng Zhang)\n- mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (Lad Prabhakar)\n- mmc: core: Fix host controller programming for fixed driver type (Kamal Dasu)\n- net: mv643xx: fix OF node refcount (Bartosz Golaszewski)\n- net: bonding: fix NULL pointer dereference in bond_do_ioctl() (Zhaojinming) [Orabug: 39674284] {CVE-2026-53337}\n- misc: fastrpc: fix DMA address corruption due to find_vma misuse (Junrui Luo)\n- misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (Anandu Krishnan E)\n- ipc/shm: serialize orphan cleanup with shm_nattch updates (Yilin Zhu) [Orabug: 39619342] {CVE-2026-52930}\n- Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (Cryolitia Pukngae)\n- Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (Zeyu Wang)\n- i2c: tegra: Fix NOIRQ suspend/resume (Akhil R)\n- i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (Guillermo Rodriguez)\n- i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (Vladimir Zapolskiy)\n- fuse: reject fuse_notify() pagecache ops on directories (Jann Horn) [Orabug: 39637414] {CVE-2026-53168}\n- pidfd: refuse access to tasks that have started exiting harder (Christian Brauner)\n- IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (Michael Bommarito) [Orabug: 39637428] {CVE-2026-53176}\n- bnxt_en: Fix NULL pointer dereference (Kyle Meyer) [Orabug: 39637432] {CVE-2026-53177}\n- vsock/vmci: fix sk_ack_backlog leak on failed handshake (Raf Dickson) [Orabug: 39637447] {CVE-2026-53181}\n- mptcp: sockopt: check timestamping ret value (Matthieu Baerts)\n- mptcp: fix retransmission loop when csum is enabled (Paolo Abeni)\n- ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O (Karl Mehltretter)\n- ARM: socfpga: Fix OF node refcount leak in SMP setup (Yuho Choi)\n- RDMA/srp: bound SRP_RSP sense copy by the received length (Michael Bommarito) [Orabug: 39637467] {CVE-2026-53186}\n- drm/amd/display: Reject gpio_bitshift = 32 in bios_parser_get_gpio_pin_info() (Harry Wentland)\n- ALSA: timer: Fix UAF at snd_timer_user_params() (Takashi Iwai) [Orabug: 39637489] {CVE-2026-53192}\n- USB: serial: kl5kusb105: fix bulk-out buffer overflow (Hyeongjun An) [Orabug: 39637496] {CVE-2026-53194}\n- USB: serial: option: add usb-id for Dell Wireless DW5826e-m (Jack Wu)\n- USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (Adrian Korwel) [Orabug: 39637502] {CVE-2026-53195}\n- USB: serial: io_ti: fix heap overflow in get_manuf_info() (Adrian Korwel) [Orabug: 39637506] {CVE-2026-53196}\n- xfrm: espintcp: do not reuse an in-progress partial send (Wyatt Feng)\n- drm/i915/gem: Fix phys BO pread/pwrite with offset (Joonas Lahtinen) [Orabug: 39674335] {CVE-2026-53356}\n- Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (Michael Bommarito) [Orabug: 39637545] {CVE-2026-53208}\n- netfilter: nft_tunnel: fix use-after-free on object destroy (Tristan Madani) [Orabug: 39637555] {CVE-2026-53212}\n- drm/vc4: fix krealloc() memory leak (Alexander A. Klimov) [Orabug: 39637561] {CVE-2026-53213}\n- net: mvpp2: build skb from XDP-adjusted data on XDP_PASS (Til Kaiser)\n- net: mvpp2: refill RX buffers before XDP or skb use (Til Kaiser) [Orabug: 39637568] {CVE-2026-53215}\n- net: mvpp2: Add metadata support for xdp mode (Lorenzo Bianconi)\n- net: mvpp2: limit XDP frame size to the RX buffer (Til Kaiser) [Orabug: 39637571] {CVE-2026-53216}\n- net: mvpp2: sync RX data at the hardware packet offset (Til Kaiser) [Orabug: 39637575] {CVE-2026-53217}\n- netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (Florian Westphal) [Orabug: 39637578] {CVE-2026-53218}\n- netfilter: nf_log: validate MAC header was set before dumping it (Xiang Mei) [Orabug: 39619384] {CVE-2026-52942}\n- netfilter: x_tables: avoid leaking percpu counter pointers (Kyle Zeng) [Orabug: 39637582] {CVE-2026-53219}\n- ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() (Eric Dumazet) [Orabug: 39637592] {CVE-2026-53221}\n- net: guard timestamp cmsgs to real error queue skbs (Kyle Zeng) [Orabug: 39637599] {CVE-2026-53223}\n- sctp: fix uninit-value in __sctp_rcv_asconf_lookup() (Michael Bommarito) [Orabug: 39637609] {CVE-2026-53225}\n- net: openvswitch: fix possible kfree_skb of ERR_PTR (Adrian Moreno) [Orabug: 39637618] {CVE-2026-53227}\n- ipv6: sit: reload inner IPv6 header after GSO offloads (Kyle Zeng) [Orabug: 39637622] {CVE-2026-53228}\n- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Mingyu Wang) [Orabug: 39621562] {CVE-2026-52947}\n- netlabel: validate unlabeled address and mask attribute lengths (Chenguang Zhao) [Orabug: 39637662] {CVE-2026-53238}\n- xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (Sanghyun Park) [Orabug: 39637666] {CVE-2026-53239}\n- arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (Mark Rutland)\n- KVM: arm64: Remove VPIPT I-cache handling (Marc Zyngier)\n- nfsd: don't ignore the return code of svc_proc_register() (Jeff Layton) [Orabug: 37844165] {CVE-2025-22026}\n- fs/ntfs3: Return error for inconsistent extended attributes (Edward Lo)\n- ext4: validate p_idx bounds in ext4_ext_correct_indexes (Tejas Bharambe) [Orabug: 39250744] {CVE-2026-31449}\n- time: Fix off-by-one in settimeofday() usec validation (Naveen Kumar Chaudhary)\n- signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() (Aleksandr Nogikh) [Orabug: 39674319] {CVE-2026-53352}\n- sctp: purge outqueue on stale COOKIE-ECHO handling (Xin Long) [Orabug: 39619311] {CVE-2026-52924}\n- net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (Yizhou Zhao) [Orabug: 39637680] {CVE-2026-53245}\n- ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() (Eric Dumazet) [Orabug: 39754155] {CVE-2026-63870}\n- ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (Eric Dumazet) [Orabug: 39637694] {CVE-2026-53249}\n- Bluetooth: fix memory leak in error path of hci_alloc_dev() (Bharath Reddy) [Orabug: 39785002] {CVE-2026-53252}\n- Bluetooth: bnep: reject short frames before parsing (Zhang Cen) [Orabug: 39637706] {CVE-2026-53253}\n- Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (Dudu Lu)\n- Bluetooth: RFCOMM: validate skb length in MCC handlers (Seungju Cheon) [Orabug: 39637711] {CVE-2026-53254}\n- Bluetooth: MGMT: validate advertising TLV before type checks (Zhang Cen) [Orabug: 39637716] {CVE-2026-53255}\n- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (Zhang Cen) [Orabug: 39637720] {CVE-2026-53256}\n- net: lan743x: permit VLAN-tagged packets up to configured MTU (David Thompson)\n- net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (Yizhou Zhao) [Orabug: 39754149] {CVE-2026-63868}\n- pcnet32: stop holding device spin lock during napi_complete_done (Oscar Maes)\n- drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (Yicong Hui)\n- 6lowpan: fix off-by-one in multicast context address compression (Yizhou Zhao) [Orabug: 39637741] {CVE-2026-53263}\n- net/sched: act_api: use RCU with deferred freeing for action lifecycle (Jamal Hadi Salim) [Orabug: 39637748] {CVE-2026-53264}\n- dm cache policy smq: check allocation under invalidate lock (Guangshuo Li) [Orabug: 39784967] {CVE-2026-53265}\n- netfilter: bridge: make ebt_snat ARP rewrite writable (Yiming Qian) [Orabug: 39637753] {CVE-2026-53266}\n- netfilter: conntrack_irc: fix possible out-of-bounds read (Florian Westphal) [Orabug: 39637763] {CVE-2026-53268}\n- netfilter: synproxy: add mutex to guard hook reference counting (Fernando Fernandez Mancera) [Orabug: 39637768] {CVE-2026-53269}\n- ipvs: clear the svc scheduler ptr early on edit (Julian Anastasov) [Orabug: 39637772] {CVE-2026-53270}\n- netfilter: xt_NFQUEUE: prefer raw_smp_processor_id (Fernando Fernandez Mancera)\n- tee: optee: prevent use-after-free when the client exits before the supplicant (Amirreza Zarrabi) [Orabug: 39637782] {CVE-2026-53273}\n- ipv6: mcast: Fix use-after-free when processing MLD queries (Ido Schimmel) [Orabug: 39637790] {CVE-2026-53275}\n- i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (Mingyu Wang) [Orabug: 39621568] {CVE-2026-52948}\n- Disable -Wattribute-alias for clang-23 and newer (Nathan Chancellor)\n- compiler-clang.h: Add __diag infrastructure for clang (Nathan Chancellor)\n- USB: serial: mct_u232: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754236] {CVE-2026-63898}\n- bpf: Free reuseport cBPF prog after RCU grace period. (Kuniyuki Iwashima) [Orabug: 39589889] {CVE-2026-52910}\n- usb: core: Fix SuperSpeed root hub wMaxPacketSize (Michal Pecio)\n- serial: dz: Fix bootconsole handover lockup (Maciej W. Rozycki)\n- xhci: tegra: Fix ghost USB device on dual-role port unplug (Wei-Cheng Chen)\n- USB: serial: digi_acceleport: fix memory corruption with small endpoints (Johan Hovold) [Orabug: 39754248] {CVE-2026-63901}\n- HID: core: Fix size_t specifier in hid_report_raw_event() (Nathan Chancellor)\n- HID: pass the buffer size to hid_report_raw_event (Benjamin Tissoires)\n- HID: core: Add printk_ratelimited variants to hid_warn() etc (Vicki Pfau)\n- USB: serial: cypress_m8: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754408] {CVE-2026-63956}\n- serial: zs: Switch to using channel reset (Maciej W. Rozycki)\n- serial: zs: Fix bootconsole handover lockup (Maciej W. Rozycki)\n- serial: dz: Fix bootconsole message clobbering at chip reset (Maciej W. Rozycki)\n- serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (Shitalkumar Gandhi)\n- serial: zs: Fix swapped RI/DSR modem line transition counting (Maciej W. Rozycki)\n- serial: sh-sci: fix memory region release in error path (Hongling Zeng)\n- drm/hyperv: validate VMBus packet size in receive callback (Berkant Koc) [Orabug: 39786542] {CVE-2026-64527}\n- thunderbolt: property: Reject dir_len 4 to prevent size_t underflow (Michael Bommarito) [Orabug: 39754216] {CVE-2026-63892}\n- thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (Michael Bommarito) [Orabug: 39754220] {CVE-2026-63893}\n- usb: gadget: f_fs: copy only received bytes on short ep0 read (Michael Bommarito)\n- usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (Seungjin Bae)\n- usb: gadget: net2280: Fix double free in probe error path (Guangshuo Li)\n- USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (Johan Hovold) [Orabug: 39754232] {CVE-2026-63897}\n- USB: serial: mxuport: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754240] {CVE-2026-63899}\n- USB: serial: keyspan: fix missing indat transfer sanity check (Johan Hovold) [Orabug: 39754244] {CVE-2026-63900}\n- USB: serial: cypress_m8: validate interrupt packet headers (Zhang Cen) [Orabug: 39754252] {CVE-2026-63902}\n- USB: serial: belkin_sa: validate interrupt status length (Zhang Cen) [Orabug: 39754256] {CVE-2026-63903}\n- USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (Wanquan Zhong)\n- USB: serial: option: add MeiG SRM813Q (Jan Volckaert)\n- usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (Heitor Alves de Siqueira)\n- usb: usbtmc: check URB actual_length for interrupt-IN notifications (Heitor Alves de Siqueira) [Orabug: 39754260] {CVE-2026-63904}\n- usbip: vudc: Fix use after free bug in vudc_remove due to race condition (Michael Bommarito) [Orabug: 39754264] {CVE-2026-63905}\n- usb: storage: Add quirks for PNY Elite Portable SSD (Sam Burkels)\n- USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (Stephen J. Fuhry)\n- usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (Michal Pecio)\n- usb: chipidea: core: convert ci_role_switch to local variable (Xu Yang)\n- tty: serial: pch_uart: add check for dma_alloc_coherent() (Zhaoyang Yu)\n- comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (Ian Abbott)\n- comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (Ian Abbott)\n- Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (Nicolas Bazaes)\n- Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (Dmitry Torokhov) [Orabug: 39754271] {CVE-2026-63908}\n- xfrm: esp: restore combined single-frag length gate (Jingguo Tan) [Orabug: 39754278] {CVE-2026-63912}\n- ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (Srinivas Kandagatla)\n- ASoC: qcom: q6asm-dai: close stream only when running (Srinivas Kandagatla)\n- netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check (Hamza Mahfooz) [Orabug: 39754282] {CVE-2026-63913}\n- xfrm: ah: use skb_to_full_sk in async output callbacks (Michael Bommarito)\n- xfrm: route MIGRATE notifications to caller's netns (Maoyi Xie) [Orabug: 39754286] {CVE-2026-63914}\n- nfc: hci: fix out-of-bounds read in HCP header parsing (Ashutosh Desai)\n- iommu, debugobjects: avoid gcc-16.1 section mismatch warnings (Arnd Bergmann)\n- HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (Lee Jones) [Orabug: 39754294] {CVE-2026-63916}\n- ip6: vti: Use ip6_tnl.net in vti6_changelink(). (Kuniyuki Iwashima) [Orabug: 39754298] {CVE-2026-63917}\n- xfrm: input: hold netns during deferred transport reinjection (Zhengchuan Liang) [Orabug: 39754304] {CVE-2026-63919}\n- ipv6: validate extension header length before copying to cmsg (Qi Tang) [Orabug: 39754307] {CVE-2026-63920}\n- ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). (Maoyi Xie) [Orabug: 39754311] {CVE-2026-63921}\n- ipv6: exthdrs: refresh nh after handling HAO option (Zhengchuan Liang) [Orabug: 39754315] {CVE-2026-63922}\n- ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (Srinivas Kandagatla)\n- ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() (Justin Iurman) [Orabug: 39754322] {CVE-2026-63924}\n- macsec: fix replay protection at XPN lower-PN wrap (Junrui Luo) [Orabug: 39754326] {CVE-2026-63925}\n- bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (Yuqi Xu) [Orabug: 39754329] {CVE-2026-63926}\n- Input: elan_i2c - validate firmware size before use (Dmitry Torokhov) [Orabug: 39785158] {CVE-2026-64237}\n- usb: dwc2: Fix use after free in debug code (Dan Carpenter) [Orabug: 39754333] {CVE-2026-63927}\n- usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (Peter Chen)\n- usb: cdns3: gadget: fix request skipping after clearing halt (Yongchao Wu)\n- USB: serial: omninet: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754337] {CVE-2026-63928}\n- iio: buffer: hw-consumer: fix use-after-free in error path (Felix Gu)\n- iio: light: cm3323: fix reg_conf not being initialized correctly (Aldo Conte)\n- iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (Advait Dhamorikar)\n- iio: temperature: tsys01: fix broken PROM checksum validation (Salah Triki)\n- iio: ssp_sensors: cancel delayed work_refresh on remove (Sanjay Chitroda)\n- iio: gyro: itg3200: fix i2c read into the wrong stack location (David Carlier)\n- iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (Salah Triki)\n- wireguard: send: append trailer after expanding head (Jason A. Donenfeld)\n- iio: dac: ad5686: fix input raw value check (Rodrigo Alencar)\n- iio: dac: max5821: fix return value check in powerdown sync (Salah Triki)\n- iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (Christofer Jonason)\n- parport: Fix race between port and client registration (Ben Hutchings) [Orabug: 39754375] {CVE-2026-63942}\n- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (Muhammad Bilal) [Orabug: 39754387] {CVE-2026-63947}\n- Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (Siwei Zhang) [Orabug: 39754391] {CVE-2026-63948}\n- ipc: limit next_id allocation to the valid ID range (Linpu Yu) [Orabug: 39619307] {CVE-2026-52923}\n- hpfs: fix a crash if hpfs_map_dnode_bitmap fails (Mikulas Patocka)\n- Bluetooth: btusb: Allow firmware re-download when version matches (Shuai Zhang)\n- Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (Thomas Fourier)\n- USB: serial: safe_serial: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754412] {CVE-2026-63957}\n- usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (Greg Kroah-Hartman)\n- usb: typec: altmodes/displayport: validate count before reading Status Update VDO (Greg Kroah-Hartman) [Orabug: 39754428] {CVE-2026-63961}\n- usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (Greg Kroah-Hartman)\n- usb: typec: ucsi: ccg: reject firmware images without a ':' record header (Greg Kroah-Hartman)\n- iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (Greg Kroah-Hartman)\n- smb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path (Stefan Metzmacher)\n- phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X (Horatiu Vultur)\n- phy: mscc: Use PHY_ID_MATCH_VENDOR to minimize PHY ID table (Harini Katakam)\n- RDMA/rxe: Fix double free in rxe_srq_from_init (Jiasheng Jiang) [Orabug: 39451551] {CVE-2026-45852}\n- Revert 'RDMA/rxe: Fix double free in rxe_srq_from_init' (Ben Hutchings)\n- drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used (Jouni Hogander)\n- drm/dp: Add eDP 1.5 bit definition (Suraj Kandpal)\n- drm/i915/psr: Read Intel DPCD workaround register (Jouni Hogander)\n- drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (Jouni Hogander)\n- wifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work (Duoming Zhou) [Orabug: 38456849] {CVE-2025-39863}\n- batman-adv: bla: avoid double decrement of bla.num_requests (Sven Eckelmann) [Orabug: 39754761] {CVE-2026-64095}\n- batman-adv: tt: avoid empty VLAN responses (Sven Eckelmann) [Orabug: 39754744] {CVE-2026-64090}\n- batman-adv: tt: fix TOCTOU race for reported vlans (Sven Eckelmann) [Orabug: 39754748] {CVE-2026-64091}\n- batman-adv: iv: recover OGM scheduling after forward packet error (Sven Eckelmann)\n- batman-adv: tvlv: reject oversized TVLV packets (Sven Eckelmann) [Orabug: 39619357] {CVE-2026-52934}\n- batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface (Sven Eckelmann) [Orabug: 39754757] {CVE-2026-64094}\n- batman-adv: tvlv: abort OGM send on tvlv append failure (Sven Eckelmann)\n- batman-adv: v: stop OGMv2 on disabled interface (Sven Eckelmann)\n- sctp: fix race between sctp_wait_for_connect and peeloff (Zhenghang Xiao) [Orabug: 39754456] {CVE-2026-63971}\n- gpio: rockchip: convert bank-clk to devm_clk_get_enabled() (Marco Scardovi)\n- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (Luiz Augusto von Dentz) [Orabug: 39754468] {CVE-2026-63975}\n- Bluetooth: l2cap: clear chan-ident on ECRED reconfiguration success (Zhenghang Xiao) [Orabug: 39754471] {CVE-2026-63976}\n- ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (Rahul Chandelkar) [Orabug: 39754489] {CVE-2026-63984}\n- ethtool: eeprom: add more safeties to EEPROM Netlink fallback (Jakub Kicinski) [Orabug: 39754492] {CVE-2026-63985}\n- bonding: refuse to enslave CAN devices (Oliver Hartkopp) [Orabug: 39754502] {CVE-2026-63990}\n- Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (Zhao Dongdong)\n- ASoC: codecs: simple-mux: Fix enum control bounds check (Cassio Gabriel)\n- tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (Eric Dumazet) [Orabug: 39754510] {CVE-2026-63992}\n- vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() (Eric Dumazet) [Orabug: 39754513] {CVE-2026-63993}\n- tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() (Eric Dumazet) [Orabug: 39754516] {CVE-2026-63994}\n- ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (Cassio Gabriel)\n- ipv4: free net-ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (Eric Dumazet) [Orabug: 39754536] {CVE-2026-64002}\n- net/iucv: fix locking in .getsockopt (Breno Leitao)\n- net/smc: Do not re-initialize smc hashtables (Alexandra Winter)\n- net: netlink: don't set nsid on local notifications (Ilya Maximets)\n- net: netlink: fix sending unassigned nsid after assigned one (Ilya Maximets)\n- netfilter: ebtables: fix OOB read in compat_mtw_from_user (Florian Westphal) [Orabug: 39619329] {CVE-2026-52927}\n- netfilter: xt_cpu: prefer raw_smp_processor_id (Florian Westphal)\n- netfilter: synproxy: refresh tcphdr after skb_ensure_writable (Chris Mason) [Orabug: 39754553] {CVE-2026-64007}\n- nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems (Carl Lee)\n- xfrm: Check for underflow in xfrm_state_mtu (David Ahern) [Orabug: 39754558] {CVE-2026-64009}\n- nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (Lee Jones)\n- nfc: llcp: Fix use-after-free in llcp_sock_release() (Lee Jones)\n- net: cpsw_new: Fix potential unregister of netdev that has not been registered yet (Kevin Hao)\n- dmaengine: idxd: Fix not releasing workqueue on .release() (Vinicius Costa Gomes) [Orabug: 39323060] {CVE-2026-43064}\n- drm: Remove plane hsub/vsub alignment requirement for core helpers (Carlos Eduardo Gallo Filho)\n- net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Victor Nogueira) [Orabug: 39754570] {CVE-2026-64012}\n- net: mctp: ensure our nlmsg responses are initialised (Jeremy Kerr)\n- net/sched: cls_fw: fix NULL dereference of 'old' filters before change() (Davide Caratti) [Orabug: 39622011] {CVE-2026-53080}\n- Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (Greg Kroah-Hartman) [Orabug: 39754575] {CVE-2026-64014}\n- LTS version: v5.15.209 (Samasth Norway Ananda)\n- net: mana: validate rx_req_idx to prevent out-of-bounds array access (Aditya Garg) [Orabug: 39754586] {CVE-2026-64018}\n- gpio: cdev: check if uAPI v2 config attributes are correctly zeroed (Bartosz Golaszewski)\n- gpiolib: cdev: use !mem_is_zero() instead of memchr_inv(s, 0, n) (Andy Shevchenko)\n- string: add mem_is_zero() helper to check if memory area is all zeros (Jani Nikula)\n- net: ag71xx: check error for platform_get_irq (Rosen Penev)\n- tracing: Avoid NULL return from hist_field_name() on truncation (David Carlier) [Orabug: 39784962] {CVE-2026-64028}\n- bridge: mcast: Fix a possible use-after-free when removing a bridge port (Ido Schimmel) [Orabug: 39754613] {CVE-2026-64032}\n- net: bridge: Flush multicast groups when snooping is disabled (Petr Machata)\n- RDMA/rtrs: Fix use-after-free in path file creation cleanup (Guangshuo Li)\n- platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki)\n- platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki)\n- platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (Rafael J. Wysocki)\n- platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (Rafael J. Wysocki)\n- net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (Erni Sri Satya Vennela) [Orabug: 39754619] {CVE-2026-64034}\n- net: dsa: mt7530: preserve VLAN tags on trapped link-local frames (Daniel Golle)\n- net: dsa: mt7530: rename mt753x_bpdu_port_fw enum to mt753x_to_cpu_fw (Arinc Unal)\n- net: dsa: mt7530: fix FDB entries not aging out with short timeout (Daniel Golle)\n- net: dsa: mt7530: sync driver-specific behavior of MT7531 variants (Daniel Golle)\n- drm/msm/snapshot: fix dumping of the unaligned regions (Dmitry Baryshkov) [Orabug: 39754629] {CVE-2026-64039}\n- net: tls: prevent chain-after-chain in plain text SG (Jakub Kicinski) [Orabug: 39754638] {CVE-2026-64046}\n- net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (Jakub Kicinski) [Orabug: 39754642] {CVE-2026-64047}\n- drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN (Mikko Perttunen) [Orabug: 39754904] {CVE-2026-64153}\n- ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics (Chenguang Zhao)\n- HID: quirks: really enable the intended work around for appledisplay (Lukas Bulwahn)\n- wifi: ath11k: fix error path leaks in some WMI WOW calls (Nicolas Escande) [Orabug: 39754909] {CVE-2026-64155}\n- net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference (Ethan Nelson-Moore)\n- net: ethernet: cortina: Carry over frag counter (Linus Walleij)\n- net: ethernet: cortina: Drop half-assembled SKB (Andreas Haarmann-Thiemann)\n- net: ethernet: cortina: Make RX SKB per-port (Linus Walleij)\n- irqchip/ath79-cpu: Remove unused function (Rosen Penev)\n- phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access (Gabor Juhos)\n- ice: fix locking in ice_dcb_rebuild() (Bart Van Assche)\n- tcp: Fix imbalanced icsk_accept_queue count. (Kuniyuki Iwashima)\n- netfilter: x_tables: unregister the templates first (Florian Westphal)\n- ARM: integrator: Fix early initialization (Guenter Roeck)\n- kunit: config: KUNIT_DEBUGFS should depend on DEBUG_FS (David Gow)\n- kunit: config: Enable KUNIT_DEBUGFS by default (David Gow)\n- firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (Sudeep Holla)\n- firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (Sudeep Holla) [Orabug: 39754932] {CVE-2026-64166}\n- hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (Abdurrahman Hussain)\n- hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (Abdurrahman Hussain)\n- hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (Abdurrahman Hussain)\n- hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (Abdurrahman Hussain)\n- hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (Abdurrahman Hussain)\n- hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (Abdurrahman Hussain)\n- hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (Abdurrahman Hussain)\n- hwmon: (pmbus/adm1266) reject implausible blackbox record_count (Abdurrahman Hussain)\n- hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (Abdurrahman Hussain)\n- batman-adv: tt: fix negative tt_buff_len (Sven Eckelmann) [Orabug: 39754734] {CVE-2026-64088}\n- batman-adv: tt: fix negative last_changeset_len (Sven Eckelmann) [Orabug: 39754740] {CVE-2026-64089}\n- batman-adv: tp_meter: avoid use of uninit sender vars (Sven Eckelmann) [Orabug: 39619346] {CVE-2026-52931}\n- batman-adv: bla: fix report_work leak on backbone_gw purge (Sven Eckelmann) [Orabug: 39785109] {CVE-2026-64218}\n- batman-adv: frag: disallow unicast fragment in fragment (Sven Eckelmann) [Orabug: 39619274] {CVE-2026-52916}\n- batman-adv: fix tp_meter counter underflow during shutdown (Luxiao Xu) [Orabug: 39619287] {CVE-2026-52919}\n- batman-adv: fix fragment reassembly length accounting (Ruide Cao) [Orabug: 39619266] {CVE-2026-52914}\n- batman-adv: dat: handle forward allocation error (Sven Eckelmann)\n- batman-adv: clear current gateway during teardown (Ruijie Li) [Orabug: 39619323] {CVE-2026-52926}\n- batman-adv: mcast: fix use-after-free in orig_node RCU release (Sven Eckelmann) [Orabug: 39754765] {CVE-2026-64096}\n- drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (Harry Wentland) [Orabug: 39785113] {CVE-2026-64219}\n- drm/amd/display: Fix integer overflow in bios_get_image() (Harry Wentland)\n- drm/bridge: megachips: remove bridge when irq request fails (Osama Abdelkader)\n- drm/bridge: it66121: acquire reset GPIO in probe (Julien Chauveau)\n- device property: set fwnode-secondary to NULL in fwnode_init() (Bartosz Golaszewski) [Orabug: 39785117] {CVE-2026-64220}\n- RDMA/siw: Reject MPA FPDU length underflow before signed receive math (Michael Bommarito)\n- spi: ti-qspi: fix use-after-free after DMA setup failure (Johan Hovold)\n- spi: sprd: fix error pointer deref after DMA setup failure (Johan Hovold)\n- scsi: isci: Fix use-after-free in device removal path (Michael Bommarito) [Orabug: 39754786] {CVE-2026-64103}\n- tracing: Do not call map-ops-elt_free() if elt_alloc() fails (Masami Hiramatsu) [Orabug: 39754948] {CVE-2026-64173}\n- wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (John Walker) [Orabug: 39754952] {CVE-2026-64174}\n- ixgbevf: fix use-after-free in VEPA multicast source pruning (Michael Bommarito) [Orabug: 39754812] {CVE-2026-64113}\n- ipv4: raw: reject IP_HDRINCL packets with ihl 5 (Michael Bommarito) [Orabug: 39754817] {CVE-2026-64114}\n- wifi: ath11k: clear shared SRNG pointer state on restart (Kyle Farnung)\n- vsock/vmci: fix UAF when peer resets connection during handshake (Minh Nguyen) [Orabug: 39754821] {CVE-2026-64115}\n- ring-buffer: Fix reporting of missed events in iterator (Steven Rostedt)\n- netfilter: ipset: stop hash:* range iteration at end (Nan Li) [Orabug: 39619299] {CVE-2026-52921}\n- netfilter: nf_queue: hold bridge skb-dev while queued (Haoze Xie) [Orabug: 39619255] {CVE-2026-52912}\n- netfilter: ip6t_hbh: reject oversized option lists (Zhengchuan Liang) [Orabug: 39619270] {CVE-2026-52915}\n- net: bcmgenet: keep RBUF EEE/PM disabled (Nicolai Buchwitz) [Orabug: 39754845] {CVE-2026-64125}\n- phonet/pep: disable BH around forwarded sk_receive_skb() (Zijing Yin) [Orabug: 39754963] {CVE-2026-64177}\n- Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (Mingyu Wang) [Orabug: 39523054] {CVE-2026-46275}\n- Bluetooth: bnep: Fix UAF read of dev-name (Jann Horn) [Orabug: 39754967] {CVE-2026-64178}\n- net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (Abdun Nihaal)\n- ALSA: asihpi: Fix potential OOB array access at reading cache (Takashi Iwai) [Orabug: 39754862] {CVE-2026-64133}\n- ALSA: ua101: Reject too-short USB descriptors (Cassio Gabriel)\n- hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (Abdurrahman Hussain)\n- sysfs: don't remove existing directory on update failure (Greg Kroah-Hartman) [Orabug: 39754983] {CVE-2026-64185}\n- Revert 's390/cio: Fix device lifecycle handling in css_alloc_subchannel()' (Sasha Levin)\n- KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses (Sean Christopherson) [Orabug: 37901590] {CVE-2025-23141}\n- wifi: mac80211: check tdls flag in ieee80211_tdls_oper (Deepanshu Kartikey) [Orabug: 39300982] {CVE-2026-43052}\n- net: dsa: sja1105: fix kasan out-of-bounds warning in sja1105_table_delete_entry() (Vladimir Oltean)\n- Revert 'x86/vdso: Fix output operand size of RDPID' (Sasha Levin)\n- s390/debug: Reject zero-length input before trimming a newline (Pengpeng Hou)\n- io_uring: prevent opcode speculation (Pavel Begunkov) [Orabug: 37702113] {CVE-2025-21863}\n- io-wq: check that the predecessor is hashed in io_wq_remove_pending() (Nicholas Carlini) [Orabug: 39523050] {CVE-2026-46274}\n- drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (Johan Hovold)\n- drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (Gyeyoung Baek)\n- drm/i915: skip __i915_request_skip() for already signaled requests (Sebastian Brzezinka)\n- iommu/vt-d: Disable DMAR for Intel Q35 IGFX (Naval Alcala)\n- libceph: handle rbtree insertion error in decode_choose_args() (Raphael Zimmer) [Orabug: 39621580] {CVE-2026-52954}\n- libceph: Fix potential out-of-bounds access in crush_decode() (Raphael Zimmer) [Orabug: 39621584] {CVE-2026-52955}\n- libceph: Fix potential null-ptr-deref in decode_choose_args() (Raphael Zimmer) [Orabug: 39621592] {CVE-2026-52957}\n- libceph: Fix potential out-of-bounds access in osdmap_decode() (Raphael Zimmer) [Orabug: 39621596] {CVE-2026-52958}\n- powerpc/warp: Fix error handling in pika_dtm_thread (Ma Ke)\n- ceph: fix a buffer leak in __ceph_setxattr() (Viacheslav Dubeyko) [Orabug: 39621609] {CVE-2026-52962}\n- ALSA: usb-audio: Bound MIDI endpoint descriptor scans (Cassio Gabriel) [Orabug: 39621613] {CVE-2026-52963}\n- drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (Chaitanya Kumar Borah)\n- KVM: x86: Fix Xen hypercall tracepoint argument assignment (Maqiang)\n- KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (Aaron Sacks) [Orabug: 39621628] {CVE-2026-52969}\n- audit: enforce AUDIT_LOCKED for AUDIT_TRIM and AUDIT_MAKE_EQUIV (Sergio Correia)\n- net: atlantic: preserve PCI wake-from-D3 on shutdown when WOL enabled (Zoran Ilievski)\n- netfilter: nft_ct: fix missing expect put in obj eval (Li Xiasong) [Orabug: 39621633] {CVE-2026-52970}\n- audit: fix incorrect inheritable capability in CAPSET records (Sergio Correia) [Orabug: 39653209] {CVE-2026-53287}\n- i40e: Cleanup PTP pins on probe failure (Matt Vollrath)\n- crypto: af_alg - Cap AEAD AD length to 0x80000000 (Herbert Xu) [Orabug: 39655982] {CVE-2026-52972}\n- net/sched: sch_pie: annotate more data-races in pie_dump_stats() (Eric Dumazet)\n- flow_dissector: Do not count vlan tags inside tunnel payload (Qingqing Yang)\n- flow_dissector: do not dissect PPPoE PFC frames (Qingfang Deng) [Orabug: 39524619] {CVE-2026-46306}\n- btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (Filipe Manana) [Orabug: 39784984] {CVE-2026-64164}\n- drm/amd/display: Read EDID from VBIOS embedded panel info (Timur Kristof)\n- drm/amd/display: Allow DCE link encoder without AUX registers (Timur Kristof)\n- ALSA: hda/conexant: Fix missing error check for jack detection (Wangdicheng) [Orabug: 39653220] {CVE-2026-53291}\n- ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (Wangdicheng)\n- ALSA: hda/conexant: fix some typos (Oldherl Oh)\n- ALSA: hda/conexant: add a new hda codec SN6140 (Bo Liu)\n- net/sched: sch_cake: annotate data-races in cake_dump_stats() (V) (Eric Dumazet)\n- bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (Weiming Shi) [Orabug: 39451517] {CVE-2026-45846}\n- ipv6: rename and move ip6_dst_lookup_tunnel() (Beniamino Galvani)\n- ipv4: add new arguments to udp_tunnel_dst_lookup() (Beniamino Galvani)\n- ipv4: remove 'proto' argument from udp_tunnel_dst_lookup() (Beniamino Galvani)\n- ipv4: rename and move ip_route_output_tunnel() (Beniamino Galvani)\n- sctp: discard stale INIT after handshake completion (Xin Long)\n- netfilter: skip recording stale or retransmitted INIT (Xin Long)\n- ASoC: codecs: ab8500: Fix casting of private data (Christian A. Ehrhardt)\n- net: phy: dp83869: fix setting CLK_O_SEL field. (Heiko Schocher)\n- NFC: trf7970a: Ignore antenna noise when checking for RF field (Paul Geurts)\n- net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (Dandan Zhang)\n- net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (Jun Zhan) [Orabug: 39621670] {CVE-2026-52982}\n- vrf: Fix a potential NPD when removing a port from a VRF (Ido Schimmel) [Orabug: 39619318] {CVE-2026-52925}\n- net/sched: sch_fq_pie: annotate data-races in fq_pie_dump_stats() (Eric Dumazet)\n- net/sched: sch_choke: annotate data-races in choke_dump_stats() (Eric Dumazet)\n- net: sched: choke: remove unused variables in struct choke_sched_data (Zhengchao Shao)\n- net/sched: netem: validate slot configuration (Stephen Hemminger)\n- net/sched: netem: fix queue limit check to include reordered packets (Stephen Hemminger) [Orabug: 39621677] {CVE-2026-52984}\n- net/sched: netem: fix probability gaps in 4-state loss model (Stephen Hemminger)\n- net: sched: sch_netem: Refactor code in 4-state loss generator (Harshit Mogalapalli)\n- netdevsim: zero initialize struct iphdr in dummy sk_buff (Nikola Z. Ivanov) [Orabug: 39621681] {CVE-2026-52985}\n- cdrom, scsi: sr: propagate read-only status to block layer via set_disk_ro() (Daan De Meyer)\n- scsi: sr: Add memory allocation failure handling for get_capabilities() (Enze Li)\n- netfilter: nf_conntrack_sip: don't use simple_strtoul (Florian Westphal) [Orabug: 39621685] {CVE-2026-52986}\n- netfilter: xt_policy: fix strict mode inbound policy matching (Jiexun Wang) [Orabug: 39619293] {CVE-2026-52920}\n- drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (Timur Kristof)\n- drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (Timur Kristof)\n- drm/amdgpu: fix spelling typos (Alexandre Demers)\n- netfilter: arp_tables: fix IEEE1394 ARP payload parsing (Pablo Neira Ayuso) [Orabug: 39451507] {CVE-2026-45844}\n- tracing: branch: Fix inverted check on stat tracer registration (Breno Leitao)\n- btrfs: fix double-decrement of bytes_may_use in submit_one_async_extent() (Mark Harmstone)\n- mailbox: mailbox-test: make data_ready a per-instance variable (Wolfram Sang)\n- mailbox: mailbox-test: initialize struct earlier (Wolfram Sang)\n- mailbox: mailbox-test: don't free the reused channel (Wolfram Sang)\n- mailbox: add sanity check for channel array (Wolfram Sang) [Orabug: 39653234] {CVE-2026-53295}\n- cgroup/rdma: fix integer overflow in rdmacg_try_charge() (Tao Cui)\n- mailbox: mailbox-test: free channels on probe error (Wolfram Sang)\n- fbdev: offb: fix PCI device reference leak on probe failure (Yuho Choi)\n- rtc: abx80x: Disable alarm feature if no interrupt attached (Anthony Pighin)\n- fs/adfs: validate nzones in adfs_validate_bblk() (Bae Yeonju)\n- vhost_net: fix sleeping with preempt-disabled in vhost_net_busy_poll() (Kohei Enju)\n- tipc: fix double-free in tipc_buf_append() (Lee Jones) [Orabug: 39621708] {CVE-2026-52993}\n- nfp: fix swapped arguments in nfp_encode_basic_qdr() calls (Alexey Kodanev)\n- net/sched: sch_sfb: annotate data-races in sfb_dump_stats() (Eric Dumazet)\n- net/sched: sch_red: annotate data-races in red_dump_stats() (Eric Dumazet)\n- net: sched: gred/red: remove unused variables in struct red_stats (Zhengchao Shao)\n- net/sched: sch_fq_codel: remove data-races from fq_codel_dump_stats() (Eric Dumazet)\n- net/sched: sch_pie: annotate data-races in pie_dump_stats() (Eric Dumazet)\n- net_sched: sch_hhf: annotate data-races in hhf_dump_stats() (Eric Dumazet)\n- ksmbd: scope conn-binding slowpath to bound sessions only (Hyunwoo Kim)\n- ksmbd: destroy tree_conn_ida in ksmbd_session_destroy() (Daemyung Kang)\n- arm64: dts: meson-gxl-p230: fix ethernet PHY interrupt number (Yan Jun)\n- slip: bound decode() reads against the compressed packet length (Weiming Shi) [Orabug: 39451500] {CVE-2026-45843}\n- slip: reject VJ receive packets on instances with no rstate array (Weiming Shi) [Orabug: 39451493] {CVE-2026-45842}\n- netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check (Fernando Fernandez Mancera) [Orabug: 39621724] {CVE-2026-52998}\n- netfilter: nfnetlink_osf: fix out-of-bounds read on option matching (Fernando Fernandez Mancera) [Orabug: 39621730] {CVE-2026-52999}\n- ipvs: fix MTU check for GSO packets in tunnel mode (Yingnan Zhang)\n- netfilter: xtables: restrict several matches to inet family (Pablo Neira Ayuso) [Orabug: 39621740] {CVE-2026-53001}\n- netfilter: conntrack: remove sprintf usage (Florian Westphal) [Orabug: 39621746] {CVE-2026-53002}\n- netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (Xiang Mei) [Orabug: 39451485] {CVE-2026-45841}\n- netfilter: nft_osf: restrict it to ipv4 (Pablo Neira Ayuso)\n- openvswitch: cap upcall PID array size and pre-size vport replies (Weiming Shi) [Orabug: 39451479] {CVE-2026-45840}\n- pppoe: drop PFC frames (Qingfang Deng) [Orabug: 39621751] {CVE-2026-53003}\n- flow_dissector: Add number of vlan tags dissector (Boris Sukholitko)\n- sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks (Michael Bommarito) [Orabug: 39621757] {CVE-2026-53004}\n- ipv6: fix possible UAF in icmpv6_rcv() (Eric Dumazet) [Orabug: 39621765] {CVE-2026-53006}\n- e1000e: Unroll PTP in probe error handling (Matt Vollrath)\n- i40e: don't advertise IFF_SUPP_NOFCS (Kohei Enju)\n- tcp: annotate data-races around (tp-write_seq - tp-snd_nxt) (Eric Dumazet)\n- net/sched: taprio: fix use-after-free in advance_sched() on schedule switch (Vinicius Costa Gomes) [Orabug: 39621780] {CVE-2026-53011}\n- net/sched: taprio: rename close_time to end_time (Vladimir Oltean)\n- net/sched: taprio: refactor one skb dequeue from TXQ to separate function (Vladimir Oltean)\n- net/sched: taprio: continue with other TXQs if one dequeue() failed (Vladimir Oltean)\n- net/sched: taprio: replace safety precautions with comments (Vladimir Oltean)\n- net/sched: taprio: stop going through private ops for dequeue and peek (Vladimir Oltean)\n- nexthop: fix IPv6 route referencing IPv4 nexthop (Jiayuan Chen) [Orabug: 39621784] {CVE-2026-53012}\n- net/sched: sch_cake: fix NAT destination port not being updated in cake_update_flowkeys (Dudu Lu)\n- PCMCIA: Fix garbled log messages for KERN_CONT (Rene Rebe)\n- crypto: ccp - copy IV using skcipher ivsize (Paul Moses) [Orabug: 39621796] {CVE-2026-53016}\n- crypto: sa2ul - Fix AEAD fallback algorithm names (T Pratham)\n- lib/hexdump: print_hex_dump_bytes() calls print_hex_dump_debug() (Geert Uytterhoeven)\n- clk: qcom: dispcc-sc7180: Add missing MDSS resets (Konrad Dybcio)\n- dt-bindings: clock: qcom,dispcc-sc7180: Define MDSS resets (Konrad Dybcio)\n- clk: xgene: Fix mapping leak in xgene_pllclk_init() (Geert Uytterhoeven)\n- clk: qoriq: avoid format string warning (Arnd Bergmann)\n- clk: imx8mq: Correct the CSI PHY sels (Sebastian Krzyszkowiak)\n- clk: imx: imx6q: Fix device node reference leak in of_assigned_ldb_sels() (Felix Gu)\n- clk: imx: imx6q: Fix device node reference leak in pll6_bypassed() (Felix Gu)\n- clk: qcom: dispcc-sm8250: Enable parents for pixel clocks (Val Packett)\n- clk: qcom: dispcc-sm8250: Use shared ops on the mdss vsync clk (Val Packett)\n- clk: qcom: gcc-sc8180x: Use retention for PCIe power domains (Val Packett)\n- clk: qcom: gcc-sc8180x: Use retention for USB power domains (Val Packett)\n- clk: qcom: gcc-sc8180x: Add missing GDSCs (Val Packett)\n- dt-bindings: clock: qcom,gcc-sc8180x: Add missing GDSCs (Val Packett)\n- scsi: target: core: Fix integer overflow in UNMAP bounds check (Junrui Luo) [Orabug: 39621811] {CVE-2026-53021}\n- scsi: sg: Resolve soft lockup issue when opening /dev/sgX (Yangerkun) [Orabug: 39653261] {CVE-2026-53304}\n- RDMA/core: Prefer NLA_NUL_STRING (Florian Westphal) [Orabug: 39754131] {CVE-2026-63860}\n- platform/x86: dell-wmi-sysman: bound enumeration string aggregation (Pengpeng Hou) [Orabug: 39621815] {CVE-2026-53022}\n- platform/x86: dell_rbu: avoid uninit value usage in packet_size_write() (Fedor Pchelkin)\n- fs/ntfs3: terminate the cached volume label after UTF-8 conversion (Pengpeng Hou)\n- nfs/blocklayout: Fix compilation error (make W=1) in bl_write_pagelist() (Andy Shevchenko)\n- mfd: mc13xxx-core: Fix memory leak in mc13xxx_add_subdevice_pdata() (Abdun Nihaal)\n- platform/x86: panasonic-laptop: Fix OPTD notifier registration and cleanup (Rafael J. Wysocki)\n- tty: hvc_iucv: fix off-by-one in number of supported devices (Randy Dunlap)\n- tty: hvc: remove HVC_IUCV_MAGIC (Ahelenia Ziemianska)\n- leds: lgm-sso: Remove duplicate assignments for priv-mmap (Chen Ni)\n- platform/surface: surfacepro3_button: Drop wakeup source on remove (Rafael J. Wysocki)\n- backlight: sky81452-backlight: Check return value of devm_gpiod_get_optional() in sky81452_bl_parse_dt() (Chen Ni)\n- dev_printk: add new dev_err_probe() helpers (Nuno Sa)\n- driver core: Move dev_err_probe() to where it belogs (Andy Shevchenko)\n- driver core: device.h: remove extern from function prototypes (Greg Kroah-Hartman)\n- i3c: mipi-i3c-hci: fix IBI payload length calculation for final status (Billy Tsai)\n- perf util: Kill die() prototype, dead for a long time (Arnaldo Carvalho de Melo)\n- perf expr: Return -EINVAL for syntax error in expr__find_ids() (Leo Yan)\n- pinctrl: abx500: Fix type of 'argument' variable (Yu-Chun Lin)\n- perf: tools: cs-etm: Fix print issue for Coresight debug in ETE/TRBE trace (Mike Leach)\n- perf branch: Avoid incrementing NULL (Ian Rogers)\n- pinctrl: pinctrl-pic32: Fix resource leak (Ethan Tidmore)\n- HID: usbhid: fix deadlock in hid_post_reset() (Oliver Neukum) [Orabug: 39621857] {CVE-2026-53037}\n- mtd: rawnand: sunxi: fix sunxi_nfc_hw_ecc_read_extra_oob (Richard Genoud)\n- mtd: parsers: ofpart: call of_node_get() for dedicated subpartitions (Cosmin Tanislav)\n- mtd: parsers: ofpart: call of_node_put() only in ofpart_fail path (Cosmin Tanislav)\n- mtd: spi-nor: swp: check SR_TB flag when getting tb_mask (Shiji Yang)\n- mtd: spi-nor: core: correct the op.dummy.nbytes when check read operations (Haibo Chen)\n- mtd: physmap_of_gemini: Fix disabled pinctrl state check (Chen Ni)\n- HID: asus: do not abort probe when not necessary (Denis Benato)\n- HID: asus: make asus_resume adhere to linux kernel coding standards (Denis Benato)\n- ima: check return value of crypto_shash_final() in boot aggregate (Daniel Hodges)\n- tracing: Rebuild full_name on each hist_field_name() call (Pengpeng Hou)\n- dmaengine: mxs-dma: Fix missing return value from of_dma_controller_register() (Frank Li)\n- dmaengine: dw-axi-dmac: Remove unnecessary return statement from void function (Khairul Anuar Romli)\n- ocfs2: validate group add input before caching (Zhengyuan Huang) [Orabug: 39621864] {CVE-2026-53039}\n- ocfs2: validate bg_bits during freefrag scan (Zhengyuan Huang) [Orabug: 39621868] {CVE-2026-53040}\n- ocfs2: fix listxattr handling when the buffer is full (Zhengyuan Huang) [Orabug: 39621872] {CVE-2026-53041}\n- soc: qcom: aoss: compare against normalized cooling state (Alok Tiwari)\n- ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (Junrui Luo) [Orabug: 39653274] {CVE-2026-53309}\n- ocfs2/dlm: validate qr_numregions in dlm_match_regions() (Junrui Luo) [Orabug: 39621878] {CVE-2026-53043}\n- unshare: fix nsproxy leak in ksys_unshare() on set_cred_ucounts() failure (Michal Grzedzicki)\n- arm64: dts: qcom: sdm845-xiaomi-beryllium: Mark l1a regulator as powered during boot (David Heidelberger)\n- soc: qcom: ocmem: return -EPROBE_DEFER is ocmem is not available (Dmitry Baryshkov)\n- soc: qcom: ocmem: register reasons for probe deferrals (Dmitry Baryshkov)\n- soc: qcom: ocmem: use scoped device node handling to simplify error paths (Krzysztof Kozlowski)\n- memory: tegra30-emc: Fix dll_change check (Mikko Perttunen)\n- memory: tegra124-emc: Fix dll_change check (Mikko Perttunen)\n- ARM: dts: mediatek: mt7623: fix efuse fallback compatible (Rafal Milecki)\n- ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine (Joshua Klinesmith)\n- efi/capsule-loader: fix incorrect sizeof in phys array reallocation (Thomas Huth) [Orabug: 39621893] {CVE-2026-53047}\n- gfs2: prevent NULL pointer dereference during unmount (Andreas Gruenbacher) [Orabug: 39621897] {CVE-2026-53048}\n- gfs2: add some missing log locking (Andreas Gruenbacher) [Orabug: 39621900] {CVE-2026-53049}\n- quota: Fix race of dquot_scan_active() with quota deactivation (Jan Kara) [Orabug: 39621904] {CVE-2026-53050}\n- ktest: Run POST_KTEST hooks on failure and cancellation (Ricardo B. Marliere)\n- ktest: Honor empty per-test option overrides (Ricardo B. Marliere)\n- ktest: Avoid undef warning when WARNINGS_FILE is unset (Ricardo B. Marliere)\n- ALSA: sc6000: Keep the programmed board state in card-private data (Cassio Gabriel)\n- ALSA: sc6000: Use standard print API (Takashi Iwai)\n- PCI: tegra194: Disable direct speed change for Endpoint mode (Vidya Sagar)\n- PCI: tegra194: Use devm_gpiod_get_optional() to parse 'nvidia,refclk-select' (Vidya Sagar)\n- PCI: tegra194: Disable LTSSM after transition to Detect on surprise link down (Manikanta Maddireddy)\n- PCI: tegra194: Increase LTSSM poll time on surprise link down (Manikanta Maddireddy)\n- PCI: tegra194: Fix polling delay for L2 state (Vidya Sagar)\n- PCI: Add PCIE_PME_TO_L2_TIMEOUT_US L2 ready timeout value (Frank Li)\n- selftest: memcg: skip memcg_sock test if address family not supported (Waiman Long)\n- Documentation: fix a hugetlbfs reservation statement (Jane Chu)\n- PCI: Enable AtomicOps only if Root Port supports them (Gerd Bayer)\n- ASoC: fsl_easrc: Change the type for iec958 channel status controls (Shengjiu Wang)\n- ASoC: fsl_easrc: Fix value type in fsl_easrc_iec958_get_bits() (Shengjiu Wang)\n- ASoC: fsl_easrc: Check the variable range in fsl_easrc_iec958_put_bits() (Shengjiu Wang)\n- ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_mode_put() (Shengjiu Wang)\n- ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_arc_mode_put() (Shengjiu Wang)\n- pmdomain: imx: scu-pd: Fix device_node reference leak during -probe() (Felix Gu)\n- pmdomain: ti: omap_prm: Fix a reference leak on device node (Felix Gu)\n- drm/msm/a6xx: Use barriers while updating HFI Q headers (Akhil P Oommen)\n- drm/msm/a6xx: Fix HLSQ register dumping (Rob Clark)\n- ALSA: hda/realtek: fix code style (ERROR: else should follow close brace '}') (Huanglei)\n- ALSA: hda/realtek: Whitespace fix (Luke D. Jones)\n- drm/amd/pm/smu7: Add SCLK cap for quirky Hawaii board (Timur Kristof)\n- drm/amd/pm/ci: Fill DW8 fields from SMC (Timur Kristof)\n- drm/amd/pm/ci: Clear EnabledForActivity field for memory levels (Timur Kristof)\n- drm/amd/pm/ci: Fix powertune defaults for Hawaii 0x67B0 (Timur Kristof)\n- drm/amd/pm/smu7: Fix SMU7 voltage dependency on display clock (Timur Kristof)\n- drm/amd/pm/ci: Disable MCLK DPM on problematic CI ASICs (Timur Kristof)\n- drm/amd/pm/ci: Use highest MCLK on CI when MCLK DPM is disabled (Timur Kristof)\n- ALSA: core: Validate compress device numbers without dynamic minors (Cassio Gabriel)\n- drm/panel: simple: Correct G190EAN01 prepare timing (Sebastian Reichel)\n- drm/msm/dsi: rename MSM8998 DSI version from V2_2_0 to V2_0_0 (Alexander Koskovich)\n- spi: hisi-kunpeng: prevent infinite while() loop in hisi_spi_flush_fifo (Pei Xiao)\n- fbdev: matroxfb: Mark variable with __maybe_unused to avoid W=1 build break (Andy Shevchenko)\n- dm init: ensure device probing has finished in dm-mod.waitfor= (Guillaume Gonnet)\n- drm/sun4i: Fix resource leaks (Ethan Tidmore)\n- spi: fsl-qspi: Use reinit_completion() for repeated operations (Felix Gu)\n- dm log: fix out-of-bounds write due to region_count overflow (Junrui Luo) [Orabug: 39621924] {CVE-2026-53059}\n- dm cache metadata: fix memory leak on metadata abort retry (Ming-Hung Tsai) [Orabug: 39621929] {CVE-2026-53060}\n- dm cache: fix dirty mapping checking in passthrough mode switching (Ming-Hung Tsai) [Orabug: 39621933] {CVE-2026-53061}\n- dm cache: support shrinking the origin device (Ming-Hung Tsai)\n- dm cache: fix concurrent write failure in passthrough mode (Ming-Hung Tsai)\n- dm cache policy smq: fix missing locks in invalidating cache blocks (Ming-Hung Tsai) [Orabug: 39621937] {CVE-2026-53062}\n- dm cache: fix write path cache coherency in passthrough mode (Ming-Hung Tsai)\n- dm cache: fix null-deref with concurrent writes in passthrough mode (Ming-Hung Tsai) [Orabug: 39621946] {CVE-2026-53064}\n- ASoC: sti: use managed regmap_field allocations (Sander Vanheule)\n- ASoC: sti: Return errors from regmap_field_alloc() (Sander Vanheule)\n- drm/komeda: fix integer overflow in AFBC framebuffer size check (Alexander Konyukhov)\n- net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master (Jiayuan Chen) [Orabug: 39621966] {CVE-2026-53069}\n- sctp: fix missing encap_port propagation for GSO fragments (Xin Long)\n- net: phy: qcom: at803x: Use the correct bit to disable extended next page (Maxime Chevallier)\n- Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (Dudu Lu) [Orabug: 39621973] {CVE-2026-53071}\n- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (Pauli Virtanen) [Orabug: 39621976] {CVE-2026-53072}\n- Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error (Jonathan Rissanen) [Orabug: 39621980] {CVE-2026-53073}\n- Bluetooth: L2CAP: Fix printing wrong information if SDU length exceeds MTU (Luiz Augusto von Dentz)\n- bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb (Sun Jian) [Orabug: 39621984] {CVE-2026-53074}\n- ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (Taegu Ha) [Orabug: 39621987] {CVE-2026-53075}\n- net/sched: act_ct: Only release RCU read lock after ct_ft (Jamal Hadi Salim) [Orabug: 39531630] {CVE-2026-46319}\n- net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf (Mashiro Chen)\n- 6pack: propagage new tty types (Jiri Slaby)\n- netfilter: nft_fwd_netdev: check ttl/hl before forwarding (Florian Westphal)\n- netfilter: xt_socket: enable defrag after all other checks (Florian Westphal)\n- net: bcmgenet: fix off-by-one in bcmgenet_put_txcb (Justin Chen) [Orabug: 39622043] {CVE-2026-53088}\n- bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() (Weiming Shi)\n- bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (Jiayuan Chen) [Orabug: 39754142] {CVE-2026-63865}\n- bpf-lsm: Make bpf_lsm_userns_create() sleepable (Frederick Lawler)\n- wifi: brcmfmac: Fix error pointer dereference (Ethan Tidmore) [Orabug: 39622061] {CVE-2026-53093}\n- bpf: fix end-of-list detection in cgroup_storage_get_next_key() (Weiming Shi) [Orabug: 39451462] {CVE-2026-45838}\n- macvlan: annotate data-races around port-bc_queue_len_used (Eric Dumazet)\n- powerpc/crash: fix backup region offset update to elfcorehdr (Sourabh Jain)\n- r8152: fix incorrect register write to USB_UPHY_XTAL (Chih Kai Hsu)\n- bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (David Carlier) [Orabug: 39622069] {CVE-2026-53096}\n- bpf, devmap: Remove unnecessary if check in for loop (Thorsten Blum)\n- module: Fix freeing of charp module parameters when CONFIG_SYSFS=n (Petr Pavlu)\n- params: Replace __modinit with __init_or_module (Petr Pavlu)\n- kernel: globalize lookup_or_create_module_kobject() (Shyam Saini)\n- kernel: param: rename locate_module_kobject (Shyam Saini)\n- dpaa2: compile dpaa2 even CONFIG_FSL_DPAA2_ETH=n (Cai Xinchen)\n- dpaa2: add independent dependencies for FSL_DPAA2_SWITCH (Cai Xinchen)\n- wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet (Duoming Zhou) [Orabug: 39622109] {CVE-2026-53112}\n- wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt() (Zilin Guan)\n- firmware: dmi: Correct an indexing error in dmi.h (Mario Limonciello) (Bart Van Assche)\n- irqchip/irq-pic32-evic: Address warning related to wrong printf() formatter (Brian Masney)\n- debugfs: check for NULL pointer in debugfs_create_str() (Gui-Dong Han)\n- thermal/drivers/spear: Fix error condition for reading st,thermal-flags (Gopi Krishna Menon)\n- devres: fix missing node debug info in devm_krealloc() (Danilo Krummrich)\n- pstore/ram: fix resource leak when ioremap() fails (Cole Leavitt)\n- nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty() (Deepanshu Kartikey)\n- drbd: Balance RCU calls in drbd_adm_dump_devices() (Bart Van Assche) [Orabug: 39622158] {CVE-2026-53128}\n- fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START (Hyungjung Joo)\n- bcache: fix uninitialized closure object (Mingzhe Zou)\n- drm/amdgpu/vcn3: Avoid overflow on msg bound check (Benjamin Cheng)\n- vsock/virtio: fix accept queue count leak on transport mismatch (Dudu Lu) [Orabug: 39460646] {CVE-2026-46214}\n- vsock: fix buffer size clamping order (Norbert Szetei) [Orabug: 39460717] {CVE-2026-46234}\n- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() (Siwei Zhang) [Orabug: 39445785] {CVE-2026-45836}\n- batman-adv: bla: put backbone reference on failed claim hash insert (Sven Eckelmann) [Orabug: 39460707] {CVE-2026-46231}\n- batman-adv: bla: only purge non-released claims (Sven Eckelmann) [Orabug: 39460713] {CVE-2026-46233}\n- batman-adv: bla: prevent use-after-free when deleting claims (Sven Eckelmann) [Orabug: 39460640] {CVE-2026-46212}\n- batman-adv: stop caching unowned originator pointers in BAT IV (Jiexun Wang) [Orabug: 39460733] {CVE-2026-46238}\n- batman-adv: reject new tp_meter sessions during teardown (Jiexun Wang) [Orabug: 39460614] {CVE-2026-46206}\n- batman-adv: fix integer overflow on buff_pos (Lyes Bourennani) [Orabug: 39460580] {CVE-2026-46198}\n- sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (Ben Morris) [Orabug: 39460689] {CVE-2026-46227}\n- drm/amdgpu/pm: align Hawaii mclk workaround with radeon (Alex Deucher)\n- drm/amdgpu/pm: add missing revision check for CI (Alex Deucher)\n- drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (John B. Moore) [Orabug: 39460668] {CVE-2026-46220}\n- drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (John B. Moore)\n- drm/radeon: add missing revision check for CI (Alex Deucher)\n- drm/amdkfd: validate SVM ioctl nattr against buffer size (Alysa Liu) [Orabug: 39460573] {CVE-2026-46197}\n- drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (Ashutosh Desai) [Orabug: 39460627] {CVE-2026-46209}\n- drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (Benjamin Cheng) [Orabug: 39460702] {CVE-2026-46230}\n- spi: mpc52xx: fix use-after-free on unbind (Johan Hovold)\n- spi: orion: fix clock imbalance on registration failure (Johan Hovold)\n- spi: imx: fix runtime pm leak on probe deferral (Johan Hovold)\n- spi: mtk-nor: fix controller deregistration (Johan Hovold)\n- media: i2c: imx412: Assert reset GPIO during probe (Wenmeng Liu)\n- media: dib8000: avoid division by 0 in dib8000_set_dds() (Sergey Shtylyov)\n- regulator: bd9571mwv: fix OF node reference imbalance (Johan Hovold)\n- regulator: act8945a: fix OF node reference imbalance (Johan Hovold)\n- media: rc: streamzap: Error handling in probe (Oliver Neukum)\n- media: rc: xbox_remote: heed DMA restrictions (Oliver Neukum)\n- regulator: max77650: fix OF node reference imbalance (Johan Hovold)\n- staging: media: atomisp: Disallow all private IOCTLs (Sakari Ailus)\n- media: i2c: ov8856: free control handler on error in ov8856_init_controls() (Alexander Koskovich)\n- media: uvcvideo: Enable VB2_DMABUF for metadata stream (Ricardo Ribalda)\n- platform/x86: hp-wmi: Ignore backlight and FnLock events (Krishna Chomal)\n- mptcp: fix scheduling with atomic in timestamp sockopt (Gang Yan) [Orabug: 39460450] {CVE-2026-46168}\n- mptcp: sockopt: set timestamp flags on subflow socket, not msk (Gang Yan)\n- mptcp: use MPTCP_RST_EMPTCP for ACK HMAC validation failure (Shardul Bankar)\n- mptcp: use MPJoinSynAckHMacFailure for SynAck HMAC failure (Shardul Bankar)\n- RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (Jason Gunthorpe) [Orabug: 39460540] {CVE-2026-46189}\n- RDMA/rxe: Reject unknown opcodes before ICRC processing (Michael Bommarito) [Orabug: 39460303] {CVE-2026-46133}\n- RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() (Jason Gunthorpe) [Orabug: 39460277] {CVE-2026-46127}\n- RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (Jason Gunthorpe) [Orabug: 39460496] {CVE-2026-46178}\n- power: supply: max17042: avoid overflow when determining health (Andre Draszik)\n- PCI/AER: Stop ruling out unbound devices as error source (Lukas Wunner)\n- PCI/AER: Clear only error bits in PCIe Device Status (Shuai Xue)\n- s390/debug: Reject zero-length input in debug_input_flush_fn() (Vasily Gorbik)\n- RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (Jason Gunthorpe)\n- nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free (Chaitanya Kulkarni) [Orabug: 39524613] {CVE-2026-46304}\n- md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (Junrui Luo) [Orabug: 39460415] {CVE-2026-46161}\n- libceph: Fix slab-out-of-bounds access in auth message processing (Raphael Zimmer) [Orabug: 39460244] {CVE-2026-46119}\n- isofs: validate block number from NFS file handle in isofs_export_iget (Michael Bommarito) [Orabug: 39460265] {CVE-2026-46124}\n- isofs: validate Rock Ridge CE continuation extent against volume size (Michael Bommarito) [Orabug: 39524609] {CVE-2026-46303}\n- dm-verity-fec: correctly reject too-small hash devices (Eric Biggers)\n- dm-verity-fec: correctly reject too-small FEC devices (Eric Biggers)\n- dm: fix a buffer overflow in ioctl processing (Mikulas Patocka) [Orabug: 39524585] {CVE-2026-46294}\n- dm: don't report warning when doing deferred remove (Mikulas Patocka)\n- dm-thin: fix metadata refcount underflow (Mikulas Patocka) [Orabug: 39460195] {CVE-2026-46107}\n- ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (Cassio Gabriel)\n- ASoC: fsl_easrc: fix comment typo (Joseph Salisbury)\n- cpuidle: powerpc: avoid double clear when breaking snooze (Shrikanth Hegde)\n- spi: topcliff-pch: fix use-after-free on unbind (Johan Hovold)\n- thermal/drivers/sprd: Fix raw temperature clamping in sprd_thm_rawdata_to_temp (Thorsten Blum)\n- thermal/drivers/sprd: Fix temperature clamping in sprd_thm_temp_to_rawdata (Thorsten Blum)\n- udf: reject descriptors with oversized CRC length (Michael Bommarito) [Orabug: 39753576] {CVE-2026-53369}\n- ibmveth: Disable GSO for packets with small MSS (Mingming Cao)\n- hv_sock: fix ARM64 support (Hamza Mahfooz)\n- extcon: ptn5150: handle pending IRQ events during system resume (Xu Yang)\n- hwmon: (corsair-psu) Close HID device on probe errors (Myeonghun Pak)\n- hwmon: (ltc2992) Fix u32 overflow in power read path (Sanman Pradhan)\n- hwmon: (ltc2992) Clamp threshold writes to hardware range (Sanman Pradhan)\n- parisc: Fix IRQ leak in LASI driver (Hongling Zeng)\n- ip6_gre: Use cached t-net in ip6erspan_changelink(). (Maoyi Xie) [Orabug: 39460248] {CVE-2026-46120}\n- sound: ua101: fix division by zero at probe (Seungju Cheon) [Orabug: 39460519] {CVE-2026-46184}\n- net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo (Kai Aizen) [Orabug: 39460297] {CVE-2026-46132}\n- fanotify: fix false positive on permission events (Miklos Szeredi) [Orabug: 39460374] {CVE-2026-46150}\n- spi: zynqmp-gqspi: fix controller deregistration (Johan Hovold)\n- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (Siwei Zhang) [Orabug: 39445772] {CVE-2026-45834}\n- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (Siwei Zhang) [Orabug: 39445781] {CVE-2026-45835}\n- Bluetooth: virtio_bt: validate rx pkt_type header length (Michael Bommarito)\n- Bluetooth: virtio_bt: clamp rx length before skb_put (Michael Bommarito)\n- ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (Yilin Zhu) [Orabug: 39460469] {CVE-2026-46172}\n- xfrm: provide message size for XFRM_MSG_MAPPING (Ruijie Li)\n- ALSA: firewire-tascam: Do not drop unread control events (Cassio Gabriel)\n- usb: ulpi: fix memory leak on ulpi_register() error paths (Felix Gu) [Orabug: 39654820] {CVE-2026-46109}\n- USB: serial: option: add Telit Cinterion LE910Cx compositions (Fabio Porcedda)\n- USB: omap_udc: DMA: Don't enable burst 4 mode (Aaro Koskinen)\n- ALSA: usb-audio: Fix UAC3 cluster descriptor size check (Cassio Gabriel)\n- ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (Takashi Iwai) [Orabug: 39460352] {CVE-2026-46146}\n- usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (Greg Kroah-Hartman) [Orabug: 39460438] {CVE-2026-46167}\n- usb: usblp: fix heap leak in IEEE 1284 device ID via short response (Greg Kroah-Hartman) [Orabug: 39460379] {CVE-2026-46151}\n- wifi: b43: enforce bounds check on firmware key index in b43_rx() (Tristan Madani) [Orabug: 39460257] {CVE-2026-46122}\n- wifi: ath5k: do not access array OOB (Jiri Slaby) [Orabug: 39524622] {CVE-2026-46307}\n- wifi: rsi: fix kthread lifetime race between self-exit and external-stop (Jeongjun Park) [Orabug: 39460532] {CVE-2026-46187}\n- wifi: b43legacy: enforce bounds check on firmware key index in RX path (Tristan Madani) [Orabug: 39460424] {CVE-2026-46163}\n- ipmi:ssif: NULL thread on error (Corey Minyard)\n- ipmi:ssif: Remove unnecessary indention (Corey Minyard)\n- ipmi:ssif: Clean up kthread on errors (Corey Minyard) [Orabug: 39452264] {CVE-2026-46044}\n- ipmi:ssif: Fix a shutdown race (Corey Minyard)\n- net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Jamal Hadi Salim) [Orabug: 39425987] {CVE-2026-43496}\n- octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_flows.c (Dipendra Khadka)\n- um: virt-pci: Fix build failure (Florian Fainelli)\n- spi: meson-spicc: Fix double-put in remove path (Felix Gu) [Orabug: 39250891] {CVE-2026-31489}\n- ksmbd: do not expire session on binding failure (Hyunwoo Kim)\n- spi: rockchip: fix controller deregistration (Johan Hovold)\n- ACPI: video: force native backlight on HP OMEN 16 (8A44) (Shivam Kalra)\n- ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (Jinjie Ruan)\n- ACPI: scan: Use acpi_dev_put() in object add error paths (Guangshuo Li)\n- fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free (Rajat Gupta)\n- ipmi:si: Return state to normal if message allocation fails (Corey Minyard) [Orabug: 39460202] {CVE-2026-46108}\n- ipmi: Check event message buffer response for bad data (Corey Minyard) [Orabug: 39460284] {CVE-2026-46128}\n- ipmi: Add limits to event and receive message requests (Corey Minyard) [Orabug: 39460490] {CVE-2026-46177}\n- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (Greg Kroah-Hartman) [Orabug: 39460368] {CVE-2026-46149}\n- netfilter: reject zero shift in nft_bitwise (Kai Ma) [Orabug: 39452465] {CVE-2026-46101}\n- net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (Andrea Mayer) [Orabug: 39452458] {CVE-2026-46099}\n- ALSA: caiaq: fix usb_dev refcount leak on probe failure (Deepanshu Kartikey) [Orabug: 39784983] {CVE-2026-46048}\n- drm/amdgpu: fix zero-size GDS range init on RDNA4 (Arjan van de Ven) [Orabug: 39524543] {CVE-2026-46276}\n- ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (Greg Kroah-Hartman) [Orabug: 39426004] {CVE-2026-43501}\n- ALSA: caiaq: Don't abort when no input device is available (Takashi Iwai)\n- ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (Takashi Iwai)\n- driver core: Add kernel-doc for DEV_FLAG_COUNT enum value (Douglas Anderson)\n- crypto: authencesn - reject short ahash digests during instance creation (Yucheng Lu) [Orabug: 39452232] {CVE-2026-46033}\n- seg6: fix seg6 lwtunnel output redirect for L2 reduced encap mode (Andrea Mayer)\n- ntfs3: fix integer overflow in run_unpack() volume boundary check (Tobi Gaertner)\n- ntfs3: add buffer boundary checks to run_unpack() (Tobi Gaertner)\n- ktest: Fix the month in the name of the failure directory (Steven Rostedt)\n- IB/core: Fix zero dmac race in neighbor resolution (Chen Zhao)\n- dm mirror: fix integer overflow in create_dirty_log() (Junrui Luo) [Orabug: 39452197] {CVE-2026-46023}\n- crypto: atmel-tdes - fix DMA sync direction (Thorsten Blum)\n- crypto: ccree - fix a memory leak in cc_mac_digest() (Haoxiang Li)\n- crypto: hisilicon - Fix dma_unmap_single() direction (Thomas Fourier)\n- crypto: atmel-ecc - Release client on allocation failure (Thorsten Blum)\n- crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup (Thorsten Blum)\n- crypto: arm64/aes - Fix 32-bit aes_mac_update() arg treated as 64-bit (Eric Biggers)\n- taskstats: set version in TGID exit notifications (Yiyang Chen)\n- tcp: call sk_data_ready() after listener migration (Zhenzhong Wu) [Orabug: 39452160] {CVE-2026-46015}\n- inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails (Chia-Ming Chang) [Orabug: 39452251] {CVE-2026-46040}\n- md/raid5: validate payload size before accessing journal metadata (Junrui Luo) [Orabug: 39452350] {CVE-2026-46070}\n- md/raid5: fix soft lockup in retry_aligned_read() (Chia-Ming Chang) [Orabug: 39452288] {CVE-2026-46051}\n- ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (Sohei Koyama) [Orabug: 39452270] {CVE-2026-46046}\n- mtd: docg3: fix use-after-free in docg3_release() (James Kim)\n- mtd: docg3: Convert to platform remove callback returning void (Uwe Kleine-Konig)\n- io_uring/poll: fix backport of io_poll_add() changes (Jens Axboe)\n- io_uring/poll: fix EPOLL_URING_WAKE sometimes not being honored (Jens Axboe)\n- KVM: nSVM: Add missing consistency check for nCR3 validity (Yosry Ahmed)\n- KVM: nSVM: Clear GIF on nested #VMEXIT(INVALID) (Yosry Ahmed)\n- KVM: nSVM: Always inject a #GP if mapping VMCB12 fails on nested VMRUN (Yosry Ahmed)\n- KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (Yosry Ahmed)\n- KVM: SVM: Explicitly mark vmcb01 dirty after modifying VMCB intercepts (Sean Christopherson)\n- KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (Kevin Cheng) [Orabug: 39452395] {CVE-2026-46082}\n- KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (Yosry Ahmed) [Orabug: 39452062] {CVE-2026-45987}\n- KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (Yosry Ahmed)\n- userfaultfd: allow registration of ranges below mmap_min_addr (Denis M. Karpov)\n- rtc: ntxec: fix OF node reference imbalance (Johan Hovold)\n- tpm: tpm_tis: add error logging for data transfer (Jacqueline Wong)\n- mmc: block: use single block write in retry (Bin Liu)\n- power: supply: axp288_charger: Do not cancel work before initializing it (Krzysztof Kozlowski)\n- tpm: avoid -Wunused-but-set-variable (Arnd Bergmann)\n- libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (Raphael Zimmer) [Orabug: 39452202] {CVE-2026-46024}\n- ipv4: icmp: validate reply type before using icmp_pointers (Ruide Cao) [Orabug: 39452244] {CVE-2026-46037}\n- drm/arcpgu: fix device node leak (Luca Ceresoli)\n- net/smc: avoid early lgr access in smc_clc_wait_msg (Ruijie Li)\n- iio: adc: ad7768-1: fix one-shot mode data acquisition (Jonathan Santos)\n- ALSA: 6fire: Fix input volume change detection (Cassio Gabriel)\n- ALSA: caiaq: Handle probe errors properly (Takashi Iwai) [Orabug: 39452127] {CVE-2026-46004}\n- ALSA: caiaq: Fix control_put() result and cache rollback (Cassio Gabriel)\n- selftests/mqueue: Fix incorrectly named file (Simon Liebold)\n- parisc: _llseek syscall is only available for 32-bit userspace (Helge Deller)\n- nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (Robert Beckett)\n- md/raid10: fix deadlock with check operation and nowait requests (Josh Hunt) [Orabug: 39452285] {CVE-2026-46050}\n- ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (Cassio Gabriel)\n- ALSA: ctxfi: Add fallback to default RSR for S/PDIF (Harin Lee) [Orabug: 39452281] {CVE-2026-46049}\n- ALSA: aoa: i2sbus: fix OF node lifetime handling (Cassio Gabriel)\n- ext2: reject inodes with zero i_nlink and valid mode in ext2_iget() (Vasiliy Kovalev) [Orabug: 39452120] {CVE-2026-46002}\n- net: qrtr: ns: Fix use-after-free in driver remove() (Manivannan Sadhasivam) [Orabug: 39452275] {CVE-2026-46047}\n- media: i2c: imx219: Check return value of devm_gpiod_get_optional() in imx219_probe() (Chen Ni)\n- lib/ts_kmp: fix integer overflow in pattern length calculation (Josh Law)\n- Revert 'ALSA: usb: Increase volume range that triggers a warning' (Rongrong)\n- PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown (Koichiro Den)\n- net: strparser: fix skb_head leak in strp_abort_strp() (Luxiao Xu) [Orabug: 39452469] {CVE-2026-46102}\n- net: caif: clear client service pointer on teardown (Zhengchuan Liang)\n- ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names() (Ziqing Chen) [Orabug: 39452417] {CVE-2026-46088}\n- crypto: pcrypt - Fix handling of MAY_BACKLOG requests (Herbert Xu) [Orabug: 39410864] {CVE-2026-43493}\n- um: drivers: call kernel_strrchr() explicitly in cow_user.c (Michael Bommarito)\n- driver core: Don't let a device probe until it's ready (Douglas Anderson)\n- padata: Remove comment for reorder_work (Herbert Xu)\n- padata: Fix pd UAF once and for all (Herbert Xu) [Orabug: 38335056] {CVE-2025-38584}\n- ocfs2: split transactions in dio completion to avoid credit exhaustion (Heming Zhao) [Orabug: 39452389] {CVE-2026-46080}\n- device property: Make modifications of fwnode 'flags' thread safe (Douglas Anderson)\n- scsi: ufs: core: Fix use-after free in init error and remove paths (Andre Draszik)\n- firmware: google: framebuffer: Do not mark framebuffer as busy (Thomas Zimmermann)\n- ibmasm: fix heap over-read in ibmasm_send_i2o_message() (Tyllis Xu)\n- ibmasm: fix OOB reads in command_file_write due to missing size checks (Tyllis Xu)\n- misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt() (Tyllis Xu)\n- drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (Greg Kroah-Hartman) [Orabug: 39452134] {CVE-2026-46006}\n- ALSA: usb-audio: Evaluate packsize caps at the right place (Takashi Iwai)\n- usb: xhci: Make usb_host_endpoint.hcpriv survive endpoint_disable() (Michal Pecio)\n- ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (Cassio Gabriel)\n- ALSA: usb-audio: Avoid false E-MU sample-rate notifications (Cassio Gabriel)\n- ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (Cassio Gabriel) [Orabug: 39452171] {CVE-2026-46018}\n- ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free (Jeongjun Park)\n- tty: n_gsm: fix flow control handling in tx path (Daniel Starke)\n- rxrpc: Fix missing validation of ticket length in non-XDR key preparsing (Anderson Nascimento)\n- crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (Sean Christopherson) [Orabug: 39300568] {CVE-2026-31697}\n- crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (Sean Christopherson) [Orabug: 39300572] {CVE-2026-31698}\n- crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (Sean Christopherson) [Orabug: 39300576] {CVE-2026-31699}\n- ALSA: caiaq: take a reference on the USB device in create_card() (Berk Cem Goksel) [Orabug: 39300587] {CVE-2026-31701}\n- ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (Cryolitia Pukngae)\n- fuse: quiet down complaints in fuse_conn_limit_write (Darrick J. Wong)\n- fuse: reject oversized dirents in page cache (Samuel Page) [Orabug: 39300557] {CVE-2026-31694}\n- fs/ntfs3: validate rec-used in journal-replay file record check (Greg Kroah-Hartman)\n- iommu: fix a reference count leak in iommu_sva_bind_device() (Vasant Karasulli)\n- rxrpc: Fix anonymous key handling (David Howells)\n- rxrpc: only handle RESPONSE during service challenge (Jie Wang) [Orabug: 39342679,39368252]\n- ksmbd: unset conn-binding on failed binding request (Namjae Jeon)\n- scripts/dtc: Remove unused dts_version in dtc-lexer.l (Nathan Chancellor)\n- Revert 'wifi: cfg80211: stop NAN and P2P in cfg80211_leave' (Guocai He)\n- drivers: base: Free devm resources when unregistering a device (David Gow)\n- cpufreq: Avoid a bad reference count on CPU node (Miquel Sabate Sola) [Orabug: 37206351] {CVE-2024-50012}\n- net: clear the dst when changing skb protocol (Jakub Kicinski) [Orabug: 38158471] {CVE-2025-38192}\n- fbdev: efifb: Register sysfs groups through driver core (Thomas Weissschuh) [Orabug: 37205941] {CVE-2024-49925}\n- md/md-bitmap: Synchronize bitmap_get_stats() with bitmap lifetime (Yu Kuai) [Orabug: 37649831] {CVE-2025-21712}\n- cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (Guangshuo Li) [Orabug: 39343645] {CVE-2026-43328}\n- cpufreq: governor: Free dbs_data directly when gov-init() fails (Liao Chang)\n- rxrpc: Fix recvmsg() unconditional requeue (David Howells)\n- fs/ntfs3: Add more attributes checks in mi_enum_attr() (Konstantin Komarov) {CVE-2023-45896}\n- btrfs: lock the inode in shared mode before starting fiemap (Filipe Manana)\n- f2fs: fix to trigger foreground gc during f2fs_map_blocks() in lfs mode (Chao Yu)\n- can: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted URBs (Marc Kleine-Budde) [Orabug: 38773752] {CVE-2025-68307}\n- Bluetooth: af_bluetooth: Fix deadlock (Luiz Augusto von Dentz) [Orabug: 36544919] {CVE-2024-26886}\n- iio: imu: inv_icm42600: fix odr switch when turning buffer off (Jean-Baptiste Maneyrol)\n- pstore: inode: Only d_invalidate() is needed (Kees Cook) [Orabug: 36598300] {CVE-2024-27389}\n- f2fs: fix to wait on block writeback for post_read case (Chao Yu)\n- net: stmmac: fix TSO DMA API usage causing oops (Russell King) [Orabug: 37434619] {CVE-2024-56719}\n- drm/amdgpu: unmap and remove csa_va properly (Lang Yu)\n- binfmt_misc: restore write access before closing files opened by open_exec() (Zilin Guan) [Orabug: 38773485] {CVE-2025-68239}\n- gfs2: No more self recovery (Andreas Gruenbacher) [Orabug: 38351909] {CVE-2025-38659}\n- bpf: Do mark_chain_precision for ARG_CONST_ALLOC_SIZE_OR_ZERO (Kumar Kartikeya Dwivedi)\n- dlm: fix possible lkb_resource null dereference (Alexander Aring) [Orabug: 37472202] {CVE-2024-47809}\n- Bluetooth: hci_core: Fix use-after-free in vhci_flush() (Kuniyuki Iwashima) [Orabug: 38175068] {CVE-2025-38250}\n- mailbox: Prevent out-of-bounds access in of_mbox_index_xlate() (Joonwon Kang)\n- btrfs: do not strictly require dirty metadata threshold for metadata writepages (Qu Wenruo) [Orabug: 38970329] {CVE-2026-23157}\n- btrfs: send: check for inline extents in range_is_hole_in_parent() (Qu Wenruo) [Orabug: 38970284] {CVE-2026-23141}\n- x86/uprobes: Fix XOL allocation failure for 32-bit tasks (Oleg Nesterov)\n- spi: cadence-quadspi: Implement refcount to handle unbind during busy (Khairul Anuar Romli)\n- fs: dlm: fix use after free in midcomms commit (Alexander Aring)\n- dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue() (Guodong Xu)\n- net/sched: cls_u32: use skb_header_pointer_careful() (Eric Dumazet) [Orabug: 38970488] {CVE-2026-23204}\n- net: add skb_header_pointer_careful() helper (Eric Dumazet)\n- dm-verity: disable recursive forward error correction (Mikulas Patocka) [Orabug: 38887637] {CVE-2025-71161}\n- blk-mq: use quiesced elevator switch when reinitializing queues (Keith Busch)\n- wifi: iwlwifi: read txq-read_ptr under lock (Johannes Berg) [Orabug: 36683388] {CVE-2024-36922}\n- f2fs: fix null-ptr-deref in f2fs_submit_page_bio() (Ye Bin)\n- s390/xor: Fix xor_xc_2() inline assembly constraints (Heiko Carstens)\n- ALSA: control: Avoid WARN() for symlink errors (Takashi Iwai) [Orabug: 37434224] {CVE-2024-56657}\n- nvme: nvme-fc: Ensure -ioerr_work is cancelled in nvme_fc_delete_ctrl() (Jaskaran Singh) [Orabug: 38730673] {CVE-2025-40261}\n- Revert 'nvme: nvme-fc: Ensure -ioerr_work is cancelled in nvme_fc_delete_ctrl()' (Jaskaran Singh)\n- tty: n_gsm: fix deadlock and link starvation in outgoing data path (Daniel Starke)\n- MPTCP: fix lock class name family in pm_nl_create_listen_socket (Li Xiasong)\n- mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (Breno Leitao) [Orabug: 39273511] {CVE-2026-31586}\n- ocfs2: fix possible deadlock between unlink and dio_end_io_write (Joseph Qi) [Orabug: 39273588] {CVE-2026-31598}\n- fs/ocfs2: fix comments mentioning i_mutex (Hongnan Li)\n- rxrpc: reject undecryptable rxkad response tickets (Yuqi Xu)\n- rxrpc: Fix call removal to use RCU safe deletion (David Howells)\n- rxrpc: Fix key quota calculation for multitoken keys (David Howells)\n- xfrm: clear trailing padding in build_polexpire() (Yasuaki Torimaru) [Orabug: 39262402] {CVE-2026-31664}\n- ocfs2: fix out-of-bounds write in ocfs2_write_end_inline (Joseph Qi) [Orabug: 39331093] {CVE-2026-43075}\n- ocfs2: validate inline data i_size during inode read (Deepanshu Kartikey) [Orabug: 39331098] {CVE-2026-43076}\n- ocfs2: add inline inode consistency check to ocfs2_validate_inode_block() (Dmitry Antipov)\n- arm64: dts: imx8mq-librem5: Bump BUCK1 suspend voltage up to 0.85V (Sebastian Krzyszkowiak)\n- Revert 'arm64: dts: imx8mq-librem5: Set the DVS voltages lower' (Sebastian Krzyszkowiak)\n- arm64: dts: imx8mq-librem5: Bump BUCK1 suspend voltage to 0.81V (Sebastian Krzyszkowiak)\n- arm64: dts: imx8mq-librem5: Set the DVS voltages lower (Sebastian Krzyszkowiak)\n- powerpc64/bpf: do not increment tailcall count when prog is NULL (Hari Bathini)\n- netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR (Florian Westphal)\n- PCI/ACPI: Restrict program_hpx_type2() to AER bits (Hakon Bugge)\n- wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (Felix Fietkau) [Orabug: 39167473] {CVE-2026-23444}\n- gfs2: Validate i_depth for exhash directories (Andrew Price) [Orabug: 38395007] {CVE-2025-38710}\n- gfs2: Improve gfs2_consist_inode() usage (Andrew Price)\n- ipv6: add NULL checks for idev in SRv6 paths (Heminhong) [Orabug: 39167468] {CVE-2026-23442}\n- Revert 'net: ixp4xx_eth: convert to ndo_hwtstamp_get() and ndo_hwtstamp_set()' (Sasha Levin)\n- Revert 'net: ethernet: xscale: Check for PTP support properly' (Sasha Levin)\n- PCI: endpoint: pci-epf-vntb: Remove duplicate resource teardown (Koichiro Den)\n- media: hackrf: fix to not free memory after the device is registered in hackrf_probe() (Jeongjun Park)\n- media: vidtv: fix pass-by-value structs causing MSAN warnings (Abd-Alrhman Masalkhi)\n- nilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map (Deepanshu Kartikey)\n- media: as102: fix to not free memory after the device is registered in as102_usb_probe() (Jeongjun Park) [Orabug: 39273468] {CVE-2026-31578}\n- bcache: fix cached_dev.sb_bio use-after-free and crash (Mingzhe Zou) [Orabug: 39273482] {CVE-2026-31580}\n- ALSA: 6fire: fix use-after-free on disconnect (Berk Cem Goksel) [Orabug: 39273487] {CVE-2026-31581}\n- media: em28xx: fix use-after-free in em28xx_v4l2_open() (Abhishek Kumar) [Orabug: 39273494] {CVE-2026-31583}\n- media: vidtv: fix nfeeds state corruption on start_streaming failure (Ruslan Valiyev)\n- mm/kasan: fix double free for kasan pXds (Ritesh Harjani)\n- KVM: x86: Use scratch field in MMIO fragment to hold small write values (Sean Christopherson) [Orabug: 39273523] {CVE-2026-31588}\n- checkpatch: add support for Assisted-by tag (Sasha Levin)\n- rxrpc: proc: size address buffers for %pISpc output (Pengpeng Hou)\n- nf_tables: nft_dynset: fix possible stateful expression memleak in error path (Pablo Neira Ayuso) [Orabug: 39139840] {CVE-2026-23399}\n- smb: client: fix potential UAF in smb2_is_valid_oplock_break() (Paulo Alcantara)\n- fsl-mc: Use driver_set_override() instead of open-coding (Krzysztof Kozlowski)\n- KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (Sean Christopherson) [Orabug: 39273531] {CVE-2026-31590}\n- ocfs2: handle invalid dinode in ocfs2_group_extend (Zhengyuan Huang) [Orabug: 39273570] {CVE-2026-31596}\n- ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY (Tejas Bharambe) [Orabug: 39273579] {CVE-2026-31597}\n- media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections (Ruslan Valiyev)\n- ALSA: ctxfi: Limit PTP to a single page (Harin Lee) [Orabug: 39273609] {CVE-2026-31602}\n- USB: serial: option: add Telit Cinterion FN990A MBIM composition (Fabio Porcedda)\n- staging: sm750fb: fix division by zero in ps_to_hz() (Junrui Luo)\n- fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (Greg Kroah-Hartman)\n- usb: storage: Expand range of matched versions for VL817 quirks entry (Daniel Brat)\n- usbip: validate number_of_packets in usbip_pack_ret_submit() (Nathan Rebello) [Orabug: 39273632] {CVE-2026-31607}\n- usb: gadget: renesas_usb3: validate endpoint index in standard request handlers (Greg Kroah-Hartman)\n- usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete() (Greg Kroah-Hartman)\n- usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb() (Greg Kroah-Hartman) [Orabug: 39273669] {CVE-2026-31617}\n- fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (Greg Kroah-Hartman)\n- ALSA: fireworks: bound device-supplied status before string array lookup (Greg Kroah-Hartman) [Orabug: 39273681] {CVE-2026-31619}\n- NFC: digital: Bounds check NFC-A cascade depth in SDD response handler (Greg Kroah-Hartman)\n- net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete() (Greg Kroah-Hartman) [Orabug: 39273693] {CVE-2026-31623}\n- HID: core: clamp report_size in s32ton() to avoid undefined shift (Greg Kroah-Hartman) [Orabug: 39273697] {CVE-2026-31624}\n- HID: alps: fix NULL pointer dereference in alps_raw_event() (Greg Kroah-Hartman) [Orabug: 39273705] {CVE-2026-31625}\n- staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify() (Lin Yu Chen) [Orabug: 39273709] {CVE-2026-31626}\n- i2c: s3c24xx: check the size of the SMBUS message before using it (Greg Kroah-Hartman)\n- can: raw: fix ro-uniq use-after-free in raw_rcv() (Samuel Page) [Orabug: 39273447] {CVE-2026-31532}\n- nfc: llcp: add missing return after LLCP_CLOSED checks (Junxi Qian)\n- ALSA: usb-audio: Update for native DSD support quirks (Jussi Laako)\n- MIPS: mm: Rewrite TLB uniquification for the hidden bit feature (Maciej W. Rozycki)\n- MIPS: mm: Suppress TLB uniquification on EHINV hardware (Maciej W. Rozycki)\n- MIPS: Always record SEGBITS in cpu_data.vmbits (Maciej W. Rozycki)\n- mips: mm: Allocate tlb_vpn array atomically (Stefan Wiehler)\n- netfilter: conntrack: add missing netlink policy validations (Florian Westphal) [Orabug: 39171450] {CVE-2026-31407}\n- i3c: fix uninitialized variable use in i2c setup (Jamie Iles)\n- perf/x86/intel/uncore: Skip discovery table for offline dies (Zide Chen) [Orabug: 39331116] {CVE-2026-43079}\n- gpio: tegra: fix irq_release_resources calling enable instead of disable (Samasth Norway Ananda)\n- l2tp: Drop large packets with UDP encap (Alice Mikityanska) [Orabug: 39331125] {CVE-2026-43080}\n- af_unix: read UNIX_DIAG_VFS data under unix_state_lock (Jiexun Wang) [Orabug: 39263356] {CVE-2026-31673}\n- netfilter: ip6t_eui64: reject invalid MAC header for all packets (Zhengchuan Liang) [Orabug: 39263406] {CVE-2026-31685}\n- netfilter: xt_multiport: validate range encoding in checkentry (Ao Zhou) [Orabug: 39263388] {CVE-2026-31681}\n- netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (Xiang Mei) [Orabug: 39331145] {CVE-2026-43085}\n- xfrm_user: fix info leak in build_mapping() (Greg Kroah-Hartman) [Orabug: 39331163] {CVE-2026-43089}\n- xsk: tighten UMEM headroom validation to account for tailroom and min frame (Maciej Fijalkowski) [Orabug: 39331181] {CVE-2026-43093}\n- e1000: check return value of e1000_read_eeprom (Agalakov Daniil)\n- tracing/probe: reject non-closed empty immediate strings (Pengpeng Hou)\n- nfc: s3fwrn5: allocate rx skb before consuming bytes (Pengpeng Hou)\n- ipv4: icmp: fix null-ptr-deref in icmp_build_probe() (Yiqi Sun) [Orabug: 39331198] {CVE-2026-43099}\n- net: lapbether: handle NETDEV_PRE_TYPE_CHANGE (Eric Dumazet)\n- net: sched: act_csum: validate nested VLAN headers (Ruide Cao) [Orabug: 39263401] {CVE-2026-31684}\n- eventpoll: defer struct eventpoll free to RCU grace period (Nicholas Carlini) [Orabug: 39784990] {CVE-2026-43074}\n- epoll: use refcount to reduce ep_mutex contention (Paolo Abeni)\n- drm/vc4: Protect madv read in vc4_gem_object_mmap() with madv_lock (Maira Canal)\n- drm/vc4: Fix a memory leak in hang state error path (Maira Canal) [Orabug: 39331212] {CVE-2026-43104}\n- drm/vc4: Fix memory leak of BO array in hang state (Maira Canal) [Orabug: 39331216] {CVE-2026-43105}\n- PCI: hv: Set default NUMA node to 0 for devices without affinity info (Long Li)\n- arm64: dts: imx8mq: Set the correct gpu_ahb clock frequency (Sebastian Krzyszkowiak)\n- soc: aspeed: socinfo: Mask table entries for accurate SoC ID matching (Potin Lai)\n- ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (Tomasz Merta)\n- wifi: brcmfmac: validate bsscfg indices in IF events (Pengpeng Hou) [Orabug: 39331238] {CVE-2026-43110}\n- ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (Arthur Husband)\n- HID: roccat: fix use-after-free in roccat_report_event (Benoit Sevens) [Orabug: 39331244] {CVE-2026-43111}\n- HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (Leo Vriska)\n- pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (Andy Shevchenko)\n- fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (Fredric Cover)\n- ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (Phil Willoughby)\n- ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (Kuninori Morimoto)\n- wifi: wl1251: validate packet IDs before indexing tx_frames (Pengpeng Hou) [Orabug: 39331254] {CVE-2026-43113}\n- netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (Florian Westphal) [Orabug: 39331263] {CVE-2026-43114}\n- ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (Cesar Montoya)\n- btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() (Goldwyn Rodrigues) [Orabug: 39331280] {CVE-2026-43117}\n- can: mcp251x: add error handling for power enable in open and resume (Wenyuan Li)\n- ALSA: asihpi: avoid write overflow check warning (Arnd Bergmann)\n- LTS version: v5.15.208 (Samasth Norway Ananda)\n- LTS version: v5.15.207 (Samasth Norway Ananda)\n- x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (Prathyushi Nangia) [Orabug: 39460476] {CVE-2026-46174}\n- x86/CPU/AMD: Add X86_FEATURE_ZEN1 (Borislav Petkov)\n- LTS version: v5.15.206 (Samasth Norway Ananda)\n- LTS version: v5.15.205 (Samasth Norway Ananda)\n- LTS version: v5.15.204 (Samasth Norway Ananda)\n- xen/privcmd: fix double free via VMA splitting (Juergen Gross) [Orabug: 39305911] {CVE-2026-31787}\n- Buffer overflow in drivers/xen/sys-hypervisor.c (Juergen Gross) [Orabug: 39305899] {CVE-2026-31786}",
"id": "ORACLE-2026500163",
"ovalId": "oval:com.oracle.elba:def:2026500163",
"source": "oracle_linux",
"title": "ELBA-2026-500163: Unbreakable Enterprise kernel bug fix update (NA)",
"url": "https://linux.oracle.com/security/oval/com.oracle.elsa-all.xml.bz2"
}