linux-hwe-6.8 (6.8.0-136.136~22.04.1) jammy; urgency=medium
* jammy/linux-hwe-6.8: 6.8.0-136.136~22.04.1 -proposed tracker (LP: #2158961)
* Packaging resync (LP: #1786013)
- [Packaging] debian.hwe-6.8/dkms-versions -- update from kernel-versions
(main/2026.06.22)
* Add intel-speed-select to linux-tools-$(uname -r) (LP: #2131077)
- [Packaging] debian.hwe-6.8/control.stub.in -- sync from master
2026.06.22
[ Ubuntu: 6.8.0-136.136 ]
* noble/linux: 6.8.0-136.136 -proposed tracker (LP: #2158930)
* ext4: writeback causes kernel oops when low on space (LP: #2158377)
- ext4: get rid of ppath in get_ext_path()
* mount08 from ubuntu_ltp_syscalls failed - TFAIL: mount(/proc/139835/fd/4)
succeeded (LP: #2137199)
- proc: proc_readfd() -> proc_fd_iterate()
- proc: proc_readfdinfo() -> proc_fdinfo_iterate()
- proc: add proc_splice_unmountable()
- proc: block mounting on top of /proc/<pid>/map_files/*
- proc: block mounting on top of /proc/<pid>/fd/*
- proc: block mounting on top of /proc/<pid>/fdinfo/*
* Add intel-speed-select to linux-tools-$(uname -r) (LP: #2131077)
- [Packaging] Add intel-speed-select to linux-tools
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956)
- blk-cgroup: wait for blkcg cleanup before initializing new disk
- fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START
- drbd: Balance RCU calls in drbd_adm_dump_devices()
- loop: fix partition scan race between udev and loop_reread_partitions()
- nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty()
- blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current()
- pstore/ram: fix resource leak when ioremap() fails
- ACPI: x86: cmos_rtc: Clean up address space handler driver
- ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver
- devres: fix missing node debug info in devm_krealloc()
- thermal/drivers/spear: Fix error condition for reading st,thermal-flags
- debugfs: check for NULL pointer in debugfs_create_str()
- debugfs: fix placement of EXPORT_SYMBOL_GPL for debugfs_create_str()
- s390/cio: convert sprintf()/snprintf() to sysfs_emit()
- s390/cio: use generic driver_override infrastructure
- irqchip/irq-pic32-evic: Address warning related to wrong printf()
formatter
- hrtimers: Update the return type of enqueue_hrtimer()
- hrtimer: Avoid pointless reprogramming in __hrtimer_start_range_ns()
- hrtimer: Reduce trace noise in hrtimer_start()
- locking: Fix rwlock support in <linux/spinlock_up.h>
- firmware: dmi: Correct an indexing error in dmi.h
- wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt()
- wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished
irq_prepare_bcn_tasklet
- bpf: Add CHECKSUM_COMPLETE to bpf test progs
- bpf: test_run: Fix the null pointer dereference issue in
bpf_lwt_xmit_push_encap
- dpaa2: add independent dependencies for FSL_DPAA2_SWITCH
- [Config] Adjust CONFIG_FSL_DPAA2_SWITCH
- dpaa2: compile dpaa2 even CONFIG_FSL_DPAA2_ETH=n
- s390/bpf: Zero-extend bpf prog return values and kfunc arguments
- params: Replace __modinit with __init_or_module
- module: Fix freeing of charp module parameters when CONFIG_SYSFS=n
- wifi: mt76: mt7921: Reset ampdu_state state in case of failure in
mt76_connac2_tx_check_aggr()
- wifi: mt76: mt7615: fix use_cts_prot support
- wifi: mt76: mt7915: fix use_cts_prot support
- wifi: mt76: mt7996: fix FCS error flag check in RX descriptor
- arm64: cpufeature: Make PMUVer and PerfMon unsigned
- wifi: mt76: mt7996: fix struct mt7996_mcu_uni_event
- wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work()
- bpf, devmap: Remove unnecessary if check in for loop
- bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path
- wifi: rtw89: phy: fix uninitialized variable access in
rtw89_phy_cfo_set_crystal_cap()
- r8152: fix incorrect register write to USB_UPHY_XTAL
- powerpc/crash: fix backup region offset update to elfcorehdr
- selftests/powerpc: Re-order *FLAGS to follow lib.mk
- selftests/powerpc: Suppress -Wmaybe-uninitialized with GCC 15
- macvlan: annotate data-races around port->bc_queue_len_used
- bpf: Fix stale offload->prog pointer after constant blinding
- wifi: brcmfmac: Fix error pointer dereference
- bpf: Drop task_to_inode and inet_conn_established from lsm sleepable
hooks
- ACPI: AGDI: fix missing newline in error message
- arm64: kexec: Remove duplicate allocation for trans_pgd
- net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
- net: bcmgenet: add bcmgenet_has_* helpers
- net: bcmgenet: move DESC_INDEX flow to ring 0
- net: bcmgenet: support reclaiming unsent Tx packets
- net: bcmgenet: switch to use 64bit statistics
- net: bcmgenet: fix racing timeout handler
- netfilter: xt_socket: enable defrag after all other checks
- netfilter: nft_fwd_netdev: check ttl/hl before forwarding
- bpf: Fix RCU stall in bpf_fd_array_map_clear()
- 6pack: propagage new tty types
- net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf
- net/rds: Optimize rds_ib_laddr_check
- net/rds: Restrict use of RDS/IB to the initial network namespace
- bpf: Fix OOB in pcpu_init_value
- ppp: require CAP_NET_ADMIN in target netns for unattached ioctls
- net: ipa: Fix programming of QTIME_TIMESTAMP_CFG
- net: ipa: Fix decoding EV_PER_EE for IPA v5.0+
- dt-bindings: net: dsa: nxp,sja1105: make spi-cpol optional for sja1110
- net/mlx5e: Fix features not applied during netdev registration
- net/mlx5e: IPsec, fix ASO poll timeout with read_poll_timeout_atomic()
- bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb
- Bluetooth: L2CAP: Fix printing wrong information if SDU length exceeds
MTU
- Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER
- Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp
- net: phy: move at803x PHY driver to dedicated directory
- net: phy: qcom: at803x: Use the correct bit to disable extended next
page
- sctp: fix missing encap_port propagation for GSO fragments
- net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master
- drm/komeda: fix integer overflow in AFBC framebuffer size check
- drm/sun4i: backend: fix error pointer dereference
- ASoC: sti: Return errors from regmap_field_alloc()
- ASoC: sti: use managed regmap_field allocations
- dm cache: fix null-deref with concurrent writes in passthrough mode
- dm cache: fix write path cache coherency in passthrough mode
- dm cache: fix write hang in passthrough mode
- dm cache policy smq: fix missing locks in invalidating cache blocks
- dm cache: fix concurrent write failure in passthrough mode
- dm cache: support shrinking the origin device
- dm cache: fix dirty mapping checking in passthrough mode switching
- platform/chrome: chromeos_tbmc: Drop wakeup source on remove
- dm cache metadata: fix memory leak on metadata abort retry
- dm log: fix out-of-bounds write due to region_count overflow
- drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier
in atomic_enable()
- drm/bridge: cadence: cdns-mhdp8546-core: Add mode_valid hook to
drm_bridge_funcs
- drm/bridge: cadence: cdns-mhdp8546-core: Handle HDCP state in bridge
atomic check
- spi: fsl-qspi: Use reinit_completion() for repeated operations
- drm/sun4i: Fix resource leaks
- drm/amdgpu: Add default case in DVI mode validation
- dm init: ensure device probing has finished in dm-mod.waitfor=
- fbdev: matroxfb: Mark variable with __maybe_unused to avoid W=1 build
break
- crypto: atmel - Use unregister_{aeads,ahashes,skciphers}
- crypto: atmel-aes - guard unregister on error in atmel_aes_register_algs
- padata: Remove cpu online check from cpu add and removal
- padata: Put CPU offline callback in ONLINE section to allow failure
- drm/amdgpu/gfx10: look at the right prop for gfx queue priority
- spi: hisi-kunpeng: prevent infinite while() loop in hisi_spi_flush_fifo
- drm/msm/dpu: fix mismatch between power and frequency
- drm/msm/dsi: add the missing parameter description
- drm/msm/dsi: rename MSM8998 DSI version from V2_2_0 to V2_0_0
- drm/panel: sharp-ls043t1le01: make use of prepare_prev_first
- drm/panel: simple: Correct G190EAN01 prepare timing
- ALSA: core: Validate compress device numbers without dynamic minors
- drm/amd/pm/ci: Use highest MCLK on CI when MCLK DPM is disabled
- drm/amd/pm/ci: Disable MCLK DPM on problematic CI ASICs
- drm/amd/pm/smu7: Fix SMU7 voltage dependency on display clock
- drm/amd/pm/ci: Fix powertune defaults for Hawaii 0x67B0
- drm/amd/pm/ci: Clear EnabledForActivity field for memory levels
- drm/amd/pm/ci: Fill DW8 fields from SMC
- drm/amd/pm/smu7: Add SCLK cap for quirky Hawaii board
- ALSA: hda/realtek: fix code style (ERROR: else should follow close brace
'}')
- ASoC: SOF: Intel: hda: Place check before dereference
- drm/msm/a6xx: Fix HLSQ register dumping
- drm/msm/shrinker: Fix can_block() logic
- drm/msm/a6xx: Use barriers while updating HFI Q headers
- pmdomain: ti: omap_prm: Fix a reference leak on device node
- pmdomain: imx: scu-pd: Fix device_node reference leak during ->probe()
- ASoC: fsl_micfil: Add access property for "VAD Detected"
- ASoC: fsl_micfil: Fix event generation in hwvad_put_enable()
- ASoC: fsl_micfil: Fix event generation in hwvad_put_init_mode()
- ASoC: fsl_micfil: Fix event generation in micfil_put_dc_remover_state()
- ASoC: fsl_micfil: Fix event generation in micfil_quality_set()
- ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_arc_mode_put()
- ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_mode_put()
- ASoC: fsl_easrc: Check the variable range in fsl_easrc_iec958_put_bits()
- ASoC: fsl_easrc: Fix value type in fsl_easrc_iec958_get_bits()
- ASoC: fsl_easrc: Change the type for iec958 channel status controls
- ASoC: qcom: qdsp6: topology: check widget type before accessing data
- crypto: qat - use swab32 macro
- ASoC: rsnd: Fix potential out-of-bounds access of component_dais[]
- PCI: Enable AtomicOps only if Root Port supports them
- PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found
- selftests/mm: skip migration tests if NUMA is unavailable
- Documentation: fix a hugetlbfs reservation statement
- selftest: memcg: skip memcg_sock test if address family not supported
- ALSA: scarlett2: Add missing sentinel initializer field
- ASoC: SOF: compress: return the configured codec from get_params
- PCI: tegra194: Fix polling delay for L2 state
- PCI: tegra194: Increase LTSSM poll time on surprise link down
- PCI: tegra194: Disable LTSSM after transition to Detect on surprise link
down
- PCI: tegra194: Rename 'root_bus' to 'root_port_bus' in
tegra_pcie_downstream_dev_to_D0()
- PCI: tegra194: Don't force the device into the D0 state before L2
- PCI: tegra194: Disable PERST# IRQ only in Endpoint mode
- PCI: tegra194: Use devm_gpiod_get_optional() to parse "nvidia,refclk-
select"
- PCI: tegra194: Disable direct speed change for Endpoint mode
- PCI: tegra194: Allow system suspend when the Endpoint link is not up
- PCI: tegra194: Use DWC IP core version
- PCI: dwc: Apply ECRC workaround to DesignWare 5.00a as well
- spi: mtk-snfi: unregister ECC engine on probe failure and remove()
callback
- ALSA: sc6000: Use standard print API
- ALSA: sc6000: Keep the programmed board state in card-private data
- dm cache: fix missing return in invalidate_committed's error path
- crypto: jitterentropy - replace long-held spinlock with mutex
- gfs2: Call unlock_new_inode before d_instantiate
- ktest: Avoid undef warning when WARNINGS_FILE is unset
- ktest: Honor empty per-test option overrides
- ktest: Run POST_KTEST hooks on failure and cancellation
- quota: Fix race of dquot_scan_active() with quota deactivation
- gfs2: add some missing log locking
- gfs2: prevent NULL pointer dereference during unmount
- efi/capsule-loader: fix incorrect sizeof in phys array reallocation
- ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine
- ARM: dts: mediatek: mt7623: fix efuse fallback compatible
- memory: tegra124-emc: Fix dll_change check
- memory: tegra30-emc: Fix dll_change check
- arm64: dts: imx8-apalis: Fix LEDs name collision
- arm64: dts: imx8mp-evk: Enable pull select bit for PCIe regulator GPIO
(M.2 W_DISABLE1)
- iommufd: vfio compatibility extension check for noiommu mode
- arm64: dts: mediatek: mt6795: Fix gpio-ranges pin count
- arm64: dts: mediatek: mt7986a: Fix gpio-ranges pin count
- arm64: dts: qcom: msm8953-xiaomi-vince: correct wled ovp value
- arm64: dts: qcom: msm8953-xiaomi-daisy: fix backlight
- soc: qcom: ocmem: make the core clock optional
- soc: qcom: ocmem: use scoped device node handling to simplify error
paths
- soc: qcom: ocmem: register reasons for probe deferrals
- soc: qcom: ocmem: return -EPROBE_DEFER is ocmem is not available
- arm64: dts: qcom: sm8450: Fix GIC_ITS range length
- arm64: dts: qcom: sm8550: Fix GIC_ITS range length
- arm64: dts: qcom: sm8550: Fix xo clock supply of platform SD host
controller
- arm64: dts: qcom: sm8450: Enable UHS-I SDR50 and SDR104 SD card modes
- arm64: dts: qcom: sm8550: Enable UHS-I SDR50 and SDR104 SD card modes
- arm64: dts: qcom: sm7225-fairphone-fp4: Fix conflicting bias pinctrl
- arm64: dts: qcom: sdm845-xiaomi-beryllium: Mark l1a regulator as powered
during boot
- arm64: dts: imx8qxp-mek: switch Type-C connector power-role to dual
- soc/tegra: cbb: Set ERD on resume for err interrupt
- unshare: fix nsproxy leak in ksys_unshare() on set_cred_ucounts()
failure
- ocfs2/dlm: validate qr_numregions in dlm_match_regions()
- ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison
- soc: qcom: llcc: fix v1 SB syndrome register offset
- soc: qcom: aoss: compare against normalized cooling state
- arm64: dts: qcom: sm8250: Add missing CPU7 3.09GHz OPP
- ARM: OMAP1: Fix DEBUG_LL and earlyprintk on OMAP16XX
- arm64/xor: fix conflicting attributes for xor_block_template
- ARM: dts: imx27-eukrea: replace interrupts with interrupts-extended
- ocfs2: fix listxattr handling when the buffer is full
- ocfs2: validate bg_bits during freefrag scan
- ocfs2: validate group add input before caching
- dmaengine: dw-axi-dmac: Remove unnecessary return statement from void
function
- soundwire: bus: demote UNATTACHED state warnings to dev_dbg()
- dmaengine: mxs-dma: Fix missing return value from
of_dma_controller_register()
- soundwire: cadence: Clear message complete before signaling waiting
thread
- tracing: Rebuild full_name on each hist_field_name() call
- ima: check return value of crypto_shash_final() in boot aggregate
- HID: asus: make asus_resume adhere to linux kernel coding standards
- HID: asus: do not abort probe when not necessary
- mtd: physmap_of_gemini: Fix disabled pinctrl state check
- dt-bindings: interrupt-controller: arm,gic-v3: Fix EPPI range
- mtd: spi-nor: core: correct the op.dummy.nbytes when check read
operations
- mtd: spi-nor: sfdp: introduce smpt_read_dummy fixup hook
- mtd: spi-nor: sfdp: introduce smpt_map_id fixup hook
- mtd: spi-nor: update spi_nor_fixups::post_sfdp() documentation
- mtd: spi-nor: swp: check SR_TB flag when getting tb_mask
- mtd: parsers: ofpart: call of_node_put() only in ofpart_fail path
- mtd: parsers: ofpart: call of_node_get() for dedicated subpartitions
- mtd: rawnand: sunxi: fix sunxi_nfc_hw_ecc_read_extra_oob
- HID: usbhid: fix deadlock in hid_post_reset()
- bpf, arm64: Fix off-by-one in check_imm signed range check
- bpf, sockmap: Fix af_unix iter deadlock
- bpf, sockmap: Fix af_unix null-ptr-deref in proto update
- bpf, sockmap: Take state lock for af_unix iter
- bpf: Fix precedence bug in convert_bpf_ld_abs alignment check
- bpf: Fix NULL deref in map_kptr_match_type for scalar regs
- bpf: allow UTF-8 literals in bpf_bprintf_prepare()
- bpf, arm32: Reject BPF-to-BPF calls and callbacks in the JIT
- pinctrl: pinctrl-pic32: Fix resource leak
- pinctrl: cy8c95x0: remove duplicate error message
- pinctrl: cy8c95x0: Unify messages with help of dev_err_probe()
- pinctrl: cy8c95x0: Avoid returning positive values to user space
- perf branch: Avoid incrementing NULL
- perf: tools: cs-etm: Fix print issue for Coresight debug in ETE/TRBE
trace
- pinctrl: abx500: Fix type of 'argument' variable
- perf lock: Fix option value type in parse_max_stack
- perf expr: Return -EINVAL for syntax error in expr__find_ids()
- ipmi: ssif_bmc: fix missing check for copy_to_user() partial failure
- ipmi: ssif_bmc: fix message desynchronization after truncated response
- ipmi: ssif_bmc: change log level to dbg in irq callback
- perf util: Kill die() prototype, dead for a long time
- i3c: mipi-i3c-hci: fix IBI payload length calculation for final status
- dev_printk: add new dev_err_probe() helpers
- backlight: sky81452-backlight: Check return value of
devm_gpiod_get_optional() in sky81452_bl_parse_dt()
- platform/surface: surfacepro3_button: Drop wakeup source on remove
- leds: lgm-sso: Remove duplicate assignments for priv->mmap
- tty: hvc_iucv: fix off-by-one in number of supported devices
- platform/x86: panasonic-laptop: Fix OPTD notifier registration and
cleanup
- mfd: mc13xxx-core: Fix memory leak in mc13xxx_add_subdevice_pdata()
- nfs/blocklayout: Fix compilation error (`make W=1`) in
bl_write_pagelist()
- fs/ntfs3: terminate the cached volume label after UTF-8 conversion
- platform/x86: dell_rbu: avoid uninit value usage in packet_size_write()
- platform/x86: dell-wmi-sysman: bound enumeration string aggregation
- RDMA/core: Prefer NLA_NUL_STRING
- clk: qcom: dispcc-sm8450: use RCG2 ops for DPTX1 AUX clock source
- scsi: sg: Make sg_sysfs_class constant
- scsi: sg: Fix sysctl sg-big-buff register during sg_init()
- scsi: sg: Resolve soft lockup issue when opening /dev/sgX
- clk: qcom: dispcc-sc8280xp: remove CLK_SET_RATE_PARENT from
byte_div_clk_src dividers
- scsi: target: core: Fix integer overflow in UNMAP bounds check
- dt-bindings: clock: qcom,gcc-sc8180x: Add missing GDSCs
- clk: qcom: gcc-sc8180x: Add missing GDSCs
- clk: qcom: gcc-sc8180x: Use retention for USB power domains
- clk: qcom: gcc-sc8180x: Use retention for PCIe power domains
- clk: qcom: dispcc-sm8250: Use shared ops on the mdss vsync clk
- clk: qcom: dispcc-sm8250: Enable parents for pixel clocks
- clk: imx: imx6q: Fix device node reference leak in pll6_bypassed()
- clk: imx: imx6q: Fix device node reference leak in
of_assigned_ldb_sels()
- clk: imx8mq: Correct the CSI PHY sels
- clk: qoriq: avoid format string warning
- clk: xgene: Fix mapping leak in xgene_pllclk_init()
- dt-bindings: clock: qcom,dispcc-sc7180: Define MDSS resets
- clk: qcom: dispcc-sc7180: Add missing MDSS resets
- lib/hexdump: print_hex_dump_bytes() calls print_hex_dump_debug()
- clk: visconti: pll: initialize clk_init_data to zero
- f2fs: Use sysfs_emit_at() to simplify code
- f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show()
- drm/i915: Extract intel_dbuf_mdclk_cdclk_ratio_update()
- drm/i915: Loop over all active pipes in intel_mbus_dbox_update
- drm/i915/wm: Verify the correct plane DDB entry
- crypto: sa2ul - Fix AEAD fallback algorithm names
- crypto: ccp - copy IV using skcipher ivsize
- arm64: dts: imx8mp-debix-model-a: Correct PAD settings for PMIC_nINT
- arm64: dts: imx8mp-debix-som-a: Correct PAD settings for PMIC_nINT
- arm64: dts: imx8mp-icore-mx8mp: Correct PAD settings for PMIC_nINT
- arm64: dts: imx8mp-dhcom-som: Correct PAD settings for PMIC_nINT
- arm64: dts: imx8mp-data-modul-edm-sbc: Correct PAD settings for
PMIC_nINT
- PCMCIA: Fix garbled log messages for KERN_CONT
- arm64: dts: imx8mm-emtop-som: Correct PAD settings for PMIC_nINT
- arm64: dts: imx8mn-tqma8mqnl: Correct PAD settings for PMIC_nINT
- arm64: dts: imx8mm-tqma8mqml: Correct PAD settings for PMIC_nINT
- macvlan: fix macvlan_get_size() not reserving space for
IFLA_MACVLAN_BC_CUTOFF
- net/sched: sch_cake: fix NAT destination port not being updated in
cake_update_flowkeys
- nexthop: fix IPv6 route referencing IPv4 nexthop
- net/sched: taprio: fix use-after-free in advance_sched() on schedule
switch
- tcp: add data-race annotations around tp->data_segs_out and
tp->total_retrans
- tcp: annotate data-races around tp->bytes_sent
- tcp: annotate data-races around tp->bytes_retrans
- tcp: annotate data-races around tp->dsack_dups
- tcp: annotate data-races around (tp->write_seq - tp->snd_nxt)
- tcp: annotate data-races around tp->plb_rehash
- i40e: don't advertise IFF_SUPP_NOFCS
- e1000e: Unroll PTP in probe error handling
- ipv6: fix possible UAF in icmpv6_rcv()
- sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks
- pppoe: drop PFC frames
- netfilter: nft_osf: restrict it to ipv4
- netfilter: conntrack: remove sprintf usage
- netfilter: xtables: restrict several matches to inet family
- ipvs: fix MTU check for GSO packets in tunnel mode
- netfilter: nfnetlink_osf: fix out-of-bounds read on option matching
- netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check
- arm64: dts: meson-gxl-p230: fix ethernet PHY interrupt number
- ksmbd: destroy tree_conn_ida in ksmbd_session_destroy()
- ksmbd: Use struct_size() to improve smb_direct_rdma_xmit()
- ksmbd: add support for supplementary groups
- ksmbd: destroy async_ida in ksmbd_conn_free()
- ksmbd: scope conn->binding slowpath to bound sessions only
- net/rds: zero per-item info buffer before handing it to visitors
- net_sched: sch_hhf: annotate data-races in hhf_dump_stats()
- net/sched: sch_pie: annotate data-races in pie_dump_stats()
- net/sched: sch_fq_codel: remove data-races from fq_codel_dump_stats()
- net/sched: sch_red: annotate data-races in red_dump_stats()
- net/sched: sch_sfb: annotate data-races in sfb_dump_stats()
- net: dsa: realtek: rtl8365mb: fix mode mask calculation
- nfp: fix swapped arguments in nfp_encode_basic_qdr() calls
- tipc: fix double-free in tipc_buf_append()
- vhost_net: fix sleeping with preempt-disabled in vhost_net_busy_poll()
- fs/adfs: validate nzones in adfs_validate_bblk()
- rtc: abx80x: Disable alarm feature if no interrupt attached
- fbdev: offb: fix PCI device reference leak on probe failure
- mailbox: mailbox-test: free channels on probe error
- cgroup/rdma: fix integer overflow in rdmacg_try_charge()
- mailbox: add sanity check for channel array
- mailbox: mailbox-test: don't free the reused channel
- mailbox: mailbox-test: initialize struct earlier
- mailbox: mailbox-test: make data_ready a per-instance variable
- btrfs: fix double-decrement of bytes_may_use in
submit_one_async_extent()
- tracing: branch: Fix inverted check on stat tracer registration
- nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers
- nvme-pci: fix missed admin queue sq doorbell write
- drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG
- drm/amdgpu: fix spelling typos
- drm/amdgpu/uvd3.1: Don't validate the firmware when already validated
- drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2)
- netfilter: xt_policy: fix strict mode inbound policy matching
- netfilter: nf_conntrack_sip: don't use simple_strtoul
- spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ
- drm/sysfb: ofdrm: fix PCI device reference leaks
- cdrom, scsi: sr: propagate read-only status to block layer via
set_disk_ro()
- netdevsim: zero initialize struct iphdr in dummy sk_buff
- net/sched: netem: fix probability gaps in 4-state loss model
- net/sched: netem: fix queue limit check to include reordered packets
- net/sched: netem: only reseed PRNG when seed is explicitly provided
- net/sched: netem: validate slot configuration
- net/sched: netem: fix slot delay calculation overflow
- net/sched: netem: check for negative latency and jitter
- net/sched: sch_choke: annotate data-races in choke_dump_stats()
- net/sched: sch_fq_pie: annotate data-races in fq_pie_dump_stats()
- vrf: Fix a potential NPD when removing a port from a VRF
- net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()
- net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit
- NFC: trf7970a: Ignore antenna noise when checking for RF field
- neighbour: add RCU protection to neigh_tables[]
- neigh: let neigh_xmit take skb ownership
- ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams
- net: mctp i2c: check length before marking flow active
- net: phy: dp83869: fix setting CLK_O_SEL field.
- drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings
- drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings
- drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings
- drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring
- drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring
- drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring
- drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring
- drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring
- drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring
- ASoC: codecs: ab8500: Fix casting of private data
- netfilter: skip recording stale or retransmitted INIT
- sctp: discard stale INIT after handshake completion
- net/sched: sch_cake: annotate data-races in cake_dump_stats() (V)
- net: netconsole: move newline trimming to function
- netconsole: propagate device name truncation in dev_name_store()
- ALSA: hda/conexant: fix some typos
- ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87
- ALSA: hda/conexant: Fix missing error check for jack detection
- futex: Prevent lockup in requeue-PI during signal/ timeout wakeup
- drm/amd/display: Allow DCE link encoder without AUX registers
- drm/amd/display: Read EDID from VBIOS embedded panel info
- bonding: 802.3ad replace MAC_ADDRESS_EQUAL with __agg_has_partner
- net: bonding: add broadcast_neighbor option for 802.3ad
- bonding: add support for per-port LACP actor priority
- bonding: print churn state via netlink
- bonding: 3ad: implement proper RCU rules for port->aggregator
- iavf: rename IAVF_VLAN_IS_NEW to IAVF_VLAN_ADDING
- iavf: stop removing VLAN filters from PF on interface down
- iavf: wait for PF confirmation before removing VLAN filters
- iavf: add VIRTCHNL_OP_ADD_VLAN to success completion handler
- ice: fix NULL pointer dereference in ice_reset_all_vfs()
- net: tls: fix strparser anchor skb leak on offload RX setup failure
- sfc: fix error code in efx_devlink_info_running_versions()
- net/sched: cls_flower: revert unintended changes
- smb: client: correctly handle ErrorContextData as a flexible array
- net: bcmgenet: Initialize u64 stats seq counter
- net: bcmgenet: fix leaking free_bds
- net/sched: sch_pie: annotate more data-races in pie_dump_stats()
- netconsole: avoid out-of-bounds access on empty string in trim_newline()
- bonding: fix NULL pointer dereference in actor_port_prio setting
- crypto: af_alg - Cap AEAD AD length to 0x80000000
- i40e: Cleanup PTP pins on probe failure
- workqueue: Fix wq->cpu_pwq leak in alloc_and_link_pwqs() WQ_UNBOUND path
- netfilter: nf_conntrack_sip: get helper before allocating expectation
- audit: fix incorrect inheritable capability in CAPSET records
- netfilter: nft_ct: fix missing expect put in obj eval
- net: atlantic: preserve PCI wake-from-D3 on shutdown when WOL enabled
- audit: enforce AUDIT_LOCKED for AUDIT_TRIM and AUDIT_MAKE_EQUIV
- KVM: Reject wrapped offset in kvm_reset_dirty_gfn()
- KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer
arithmetic
- KVM: x86: Fix Xen hypercall tracepoint argument assignment
- ASoC: SOF: Intel: hda-dai: remove dspless special case
- ASoC: SOF: Intel: hda-dai: add support for dspless mode beyond HDAudio
- smb/client: fix possible infinite loop and oob read in symlink_data()
- drm/i915/dp: Fix VSC dynamic range signaling for RGB formats
- ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans
- ALSA: usb-audio: Bound MIDI endpoint descriptor scans
- ceph: fix a buffer leak in __ceph_setxattr()
- powerpc/warp: Fix error handling in pika_dtm_thread
- netfs: fix error handling in netfs_extract_user_iter()
- libceph: Fix potential out-of-bounds access in osdmap_decode()
- libceph: Fix potential null-ptr-deref in decode_choose_args()
- libceph: Fix potential out-of-bounds access in crush_decode()
- libceph: handle rbtree insertion error in decode_choose_args()
- iommu/vt-d: Disable DMAR for Intel Q35 IGFX
- drm/i915: skip __i915_request_skip() for already signaled requests
- drm/panfrost: Fix wait_bo ioctl leaking positive return from
dma_resv_wait_timeout()
- drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup
- drm/gma500/oaktrail_lvds: fix hang on init failure
- drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init
- eventfs: Use list_add_tail_rcu() for SRCU-protected children list
- smb: client: Use FullSessionKey for AES-256 encryption key derivation
- btrfs: use inode already stored in local variable at btrfs_rmdir()
- btrfs: use btrfs inodes in btrfs_rmdir() to avoid so much usage of
BTRFS_I()
- mptcp: drop __mptcp_fastopen_gen_msk_ackseq()
- mptcp: fix rx timestamp corruption on fastopen
- mptcp: pm: prio: skip closed subflows
- mptcp: pm: kernel: correctly retransmit ADD_ADDR ID 0
- f2fs: fix incorrect file address mapping when inline inode is unwritten
- f2fs: fix false alarm of lockdep on cp_global_sem lock
- spi: sifive: Simplify clock handling with devm_clk_get_enabled()
- spi: sifive: fix controller deregistration
- mptcp: pm: ADD_ADDR rtx: resched blocked ADD_ADDR quicker
- netfs: Fix potential uninitialised var in netfs_extract_user_iter()
- io_uring/kbuf: use mem_is_zero()
- md/raid1: fix the comparing region of interval tree
- md: wake raid456 reshape waiters before suspend
- btrfs: pass struct btrfs_inode to clone_copy_inline_extent()
- btrfs: fix deadlock between reflink and transaction commit when using
flushoncommit
- bus: fsl-mc: use generic driver_override infrastructure
- sparc/vdso: Always reject undefined references during linking
- sparc64: vdso: Link with -z noexecstack
- wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work()
- wifi: mt76: mt7921: fix 6GHz regulatory update on connection
- bpf: Fix variable length stack write over spilled pointers
- wifi: ath10k: fix station lookup failure during disconnect
- bpf: fix mm lifecycle in open-coded task_vma iterator
- bpf: switch task_vma iterator from mmap_lock to per-VMA locks
- bpf: return VMA snapshot from task_vma iterator
- Bluetooth: SCO: check for codecs->num_codecs == 1 before assigning to
sco_pi(sk)->codec
- ipv4: udp: fix typos in comments
- ipv6: udp: fix typos in comments
- udp: Force compute_score to always inline
- PCI: endpoint: Align pci_epc_set_msix(), pci_epc_ops::set_msix() nr_irqs
encoding
- PCI: dwc: ep: Fix MSI-X Table Size configuration in
dw_pcie_ep_set_msix()
- PCI: dwc: Invoke post_init in dw_pcie_resume_noirq()
- PCI: dwc: Perform cleanup in the error path of dw_pcie_resume_noirq()
- spi: spi-nxp-fspi: remove the goto in probe
- spi: spi-nxp-fspi: enable runtime pm for fspi
- spi: nxp-fspi: Use reinit_completion() for repeated operations
- drm/v3d: Handle error from drm_sched_entity_init()
- PCI: dwc: rcar-gen4: Change EPC BAR alignment to 4K as per the
documentation
- drm/imagination: Switch reset_reason fields from enum to u32
- drm/msm/dsi: fix bits_per_pclk
- drm/msm/dsi: fix hdisplay calculation for CMD mode panel
- PCI: qcom: Advertise Hotplug Slot Capability with no Command Completion
support
- drm/msm/a6xx: Fix dumping A650+ debugbus blocks
- crypto: qat - introduce fuse array
- crypto: qat - disable 4xxx AE cluster when lead engine is fused off
- crypto: qat - disable 420xx AE cluster when lead engine is fused off
- crypto: qat - fix type mismatch in RAS sysfs show functions
- PCI: tegra194: Set LTR message request before PCIe link up in Endpoint
mode
- PCI: tegra194: Free up Endpoint resources during remove()
- arm64: dts: mediatek: mt8365: Describe infracfg-nao as a pure syscon
- arm64: dts: qcom: sm8650: Fix GIC_ITS range length
- arm64: dts: qcom: sm8650: Fix xo clock supply of SD host controller
- arm64: dts: qcom: sm8650: Enable UHS-I SDR50 and SDR104 SD card modes
- arm64: dts: ti: k3-am62p5-sk: Disable MMC1 internal pulls on data pins
- arm64: dts: ti: k3-am62-lp-sk: Enable internal pulls for MMC0 data pins
- arm64: dts: ti: k3-am62-verdin: Fix SPI_1 GPIO CS pinctrl label
- hte: tegra194: remove Kconfig dependency on Tegra194 SoC
- [Config] Adjust CONFIG_HTE_TEGRA194
- cxl/pci: Check memdev driver binding status in cxl_reset_done()
- ext4: fix possible null-ptr-deref in mbt_kunit_exit()
- pinctrl: realtek: Fix function signature for config argument
- perf maps: Fix copy_from that can break sorted by name order
- platform/x86: asus-wmi: adjust screenpad power/brightness handling
- platform/x86: asus-wmi: fix screenpad brightness range
- tty: serial: ip22zilog: Fix section mispatch warning
- clk: qcom: gcc-x1e80100: Keep GCC USB QTB clock always ON
- erofs: unify lcn as u64 for 32-bit platforms
- net/sched: act_mirred: fix wrong device for mac_header_xmit check in
tcf_blockcast_redir
- tcp: add data-race annotations for TCP_NLA_SNDQ_SIZE
- ice: fix ICE_AQ_LINK_SPEED_M for 200G
- net/mlx5: Fix HCA caps leak on notifier init failure
- pwm: atmel-tcb: Cache clock rates and mark chip as atomic
- mailbox: mtk-cmdq: Fix CURR and END addr for task insert case
- fsnotify: fix inode reference leak in fsnotify_recalc_mask()
- drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM
- ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED
- tcp: make probe0 timer handle expired user timeout
- drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring
- drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring
- ALSA: hda: cs35l56: Fix uninitialized value in cs35l56_hda_read_acpi()
- drm/xe/debugfs: Correct printing of register whitelist ranges
- drm/xe/gsc: Fix BO leak on error in query_compatibility_version()
- PCI: Initialize temporary device in new_id_store()
- ata: libata-scsi: fix requeue of deferred ATA PASS-THROUGH commands
- drm/loongson: Use managed KMS polling
- ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size
- drm/xe/dma-buf: handle empty bo and UAF races
- btrfs: do not mark inode incompressible after inline attempt fails
- tracing: Avoid NULL return from hist_field_name() on truncation
- Upstream stable to v6.6.141, v6.12.91
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-46117
- RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-46137
- mptcp: pm: ADD_ADDR rtx: fix potential data-race
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-46160
- btrfs: fix missing last_unlink_trans update when removing a directory
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-46314
- drm/v3d: Reject empty multisync extension to prevent infinite loop
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-46274
- io-wq: check that the predecessor is hashed in io_wq_remove_pending()
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-31707
- ksmbd: validate response sizes in ipc_validate_msg()
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-46068
- crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-31613
- smb: client: fix OOB reads parsing symlink error response
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-43245
- ntfs: ->d_compare() must not block
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-45846
- bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst()
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-45845
- net/sched: taprio: fix NULL pointer dereference in class dump
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-45844
- netfilter: arp_tables: fix IEEE1394 ARP payload parsing
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-45843
- slip: bound decode() reads against the compressed packet length
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-45842
- slip: reject VJ receive packets on instances with no rstate array
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-45841
- netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-45840
- openvswitch: cap upcall PID array size and pre-size vport replies
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-46319
- net/sched: act_ct: Only release RCU read lock after ct_ft
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-45839
- bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec()
* Noble update: upstream stable patchset 2026-06-16 (LP: #2156956) //
CVE-2026-45838
- bpf: fix end-of-list detection in cgroup_storage_get_next_key()
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619)
- regset: use kvzalloc() for regset_get_alloc()
- selftests/bpf: validate fake register spill/fill precision backtracking
logic
- exit: Sleep at TASK_IDLE when waiting for application core dump
- media: uvcvideo: Enable VB2_DMABUF for metadata stream
- media: i2c: ov8856: free control handler on error in
ov8856_init_controls()
- spi: bcm63xx: fix controller deregistration
- spi: atmel: fix controller deregistration
- regulator: mt6357: fix OF node reference imbalance
- regulator: max77650: fix OF node reference imbalance
- media: rc: streamzap: Error handling in probe
- regulator: rk808: fix OF node reference imbalance
- regulator: act8945a: fix OF node reference imbalance
- regulator: bd9571mwv: fix OF node reference imbalance
- spi: lantiq-ssc: fix controller deregistration
- spi: qup: fix controller deregistration
- spi: at91-usart: fix controller deregistration
- platform/x86: hp-wmi: Ignore backlight and FnLock events
- media: pci: zoran: fix potential memory leak in zoran_probe()
- media: dib8000: avoid division by 0 in dib8000_set_dds()
- media: i2c: imx412: Assert reset GPIO during probe
- media: staging: imx: request mbus_config in csi_start
- media: i2c: ov08d10: fix image vertical start setting
- media: omap3isp: drop the use count of v4l2 pipeline
- spi: dln2: fix controller deregistration
- spi: s3c64xx: fix controller deregistration
- spi: fsl-espi: fix controller deregistration
- spi: omap2-mcspi: fix controller deregistration
- spi: mtk-nor: fix controller deregistration
- spi: sh-hspi: fix controller deregistration
- spi: bcmbca-hsspi: fix controller deregistration
- spi: coldfire-qspi: fix controller deregistration
- spi: sprd: fix controller deregistration
- spi: img-spfi: fix controller deregistration
- spi: imx: fix runtime pm leak on probe deferral
- spi: orion: fix runtime pm leak on unbind
- spi: orion: fix clock imbalance on registration failure
- spi: cadence: fix controller deregistration
- spi: cadence: fix unclocked access on unbind
- drm/amdkfd: Add upper bound check for num_of_nodes
- drm/amdgpu/vce: Prevent partial address patches
- drm/radeon: add missing revision check for CI
- drm/amdgpu: zero-initialize GART table on allocation
- drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ
- drm/amdgpu/pm: add missing revision check for CI
- drm/amdgpu/pm: align Hawaii mclk workaround with radeon
- ipmi:ssif: Fix a shutdown race
- ALSA: hda: cs35l56: Propagate ASP TX source control errors
- ALSA: misc: Use guard() for spin locks
- ALSA: core: Serialize deferred fasync state checks
- ALSA: seq: Notify client and port info changes
- ALSA: seq: Fix UMP group 16 filtering
- spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled()
- spi: zynq-qspi: fix controller deregistration
- spi: tegra114: fix controller deregistration
- spi: tegra20-sflash: fix controller deregistration
- spi: uniphier: Simplify clock handling with devm_clk_get_enabled()
- spi: uniphier: fix controller deregistration
- mm/hugetlb_cma: round up per_node before logging it
- mm/damon/core: disallow time-quota setting zero esz
- mm/damon/core: implement damon_kdamond_pid()
- mm/damon/lru_sort: detect and use fresh enabled and kdamond_pid values
- usb: typec: tcpm: reset internal port states on soft reset AMS
- mm/damon/reclaim: detect and use fresh enabled and kdamond_pid values
- mtd: spi-nor: sst: Factor out common write operation to
`sst_nor_write_data()`
- pwm: imx-tpm: Count the number of enabled channels in probe
- batman-adv: tp_meter: fix tp_num leak on kmalloc failure
- tracing/probes: Limit size of event probe to 3K
- usb: dwc3: Move GUID programming after PHY initialization
- vsock/virtio: fix length and offset in tap skb for split packets
- drm/amdgpu/vcn3: Avoid overflow on msg bound check
- drm/amdgpu/vcn4: Avoid overflow on msg bound check
- mtd: spi-nor: sst: Fix SST write failure
- media: nxp: imx8-isi: Reduce minimum queued buffers from 2 to 0
- media: chips-media: wave5: fix a potential memory leak in
wave5_vdi_init()
- media: chips-media: wave5: add missing spinlock protection for
send_eos_event()
- media: chips-media: wave5: add missing spinlock protection for
handle_dynamic_resolution_change()
- spi: st-ssc4: fix controller deregistration
- spi: meson-spicc: fix controller deregistration
- spi: aspeed-smc: fix controller deregistration
- vsock/virtio: fix MSG_PEEK ignoring skb offset when calculating bytes to
copy
- spi: mxs: fix controller deregistration
- spi: pic32: fix controller deregistration
- spi: pl022: fix controller deregistration
- spi: npcm-pspi: fix controller deregistration
- spi: pic32-sqi: fix controller deregistration
- spi: mxic: fix controller deregistration
- spi: orion: fix controller deregistration
- drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count.
- drm/amdgpu: gate VM CPU HDP flush on reset lock
- drm/amd/display: Change dither policy for 10 bpc output back to
dithering
- drm/xe/bo: Fix bo leak on unaligned size validation in
xe_bo_init_locked()
- drm/exynos: remove bridge when component_add fails
- drm/amdkfd: Make all TLB-flushes heavy-weight
- btrfs: remove fs_info argument from btrfs_sysfs_add_space_info_type()
- Upstream stable to v6.6.140, v6.12.89, v6.12.90
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46207
- vsock/virtio: fix empty payload in tap skb for non-linear buffers
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46164
- btrfs: fix double free in create_space_info_sub_group() error path
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46201
- drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import()
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46211
- drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata()
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46200
- spi: mpc52xx: fix controller deregistration
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46241
- spi: mpc52xx: fix use-after-free on registration failure
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46214
- vsock/virtio: fix accept queue count leak on transport mismatch
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46234
- vsock: fix buffer size clamping order
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46159
- btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to
info-leak
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46208
- batman-adv: stop tp_meter sessions during mesh teardown
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-23171
- bonding: fix use-after-free due to enslave fail after slave array update
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-45836
- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb()
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46191
- fbcon: Avoid OOB font access if console rotation fails
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46111
- Bluetooth: hci_conn: fix potential UAF in create_big_sync
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-45999
- erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap()
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46044
- ipmi:ssif: Clean up kthread on errors
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46231
- batman-adv: bla: put backbone reference on failed claim hash insert
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46233
- batman-adv: bla: only purge non-released claims
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46212
- batman-adv: bla: prevent use-after-free when deleting claims
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46238
- batman-adv: stop caching unowned originator pointers in BAT IV
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46206
- batman-adv: reject new tp_meter sessions during teardown
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46198
- batman-adv: fix integer overflow on buff_pos
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46227
- sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in
SCTP_SENDALL
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46220
- drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46197
- drm/amdkfd: validate SVM ioctl nattr against buffer size
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46209
- drm/gem: Fix inconsistent plane dimension calculation in
drm_gem_fb_init_with_funcs()
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46230
- drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46199
- drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46204
- drm/amdgpu/vcn4: Prevent OOB reads when parsing IB
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46218
- drm/amdgpu: Add bounds checking to ib_{get,set}_value
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46229
- drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46219
- spi: mpc52xx: fix use-after-free on unbind
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46225
- spi: rspi: fix controller deregistration
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46226
- spi: fsl: fix controller deregistration
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46235
- media: saa7164: add ioremap return checks and cleanups
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46312
- media: videobuf2: Set vma_flags in vb2_dma_sg_mmap
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46236
- media: rc: xbox_remote: heed DMA restrictions
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46205
- staging: media: atomisp: Disallow all private IOCTLs
* Noble update: upstream stable patchset 2026-06-12 (LP: #2156619) //
CVE-2026-46232
- HID: playstation: Clamp num_touch_reports
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549)
- xen/privcmd: fix double free via VMA splitting
- Buffer overflow in drivers/xen/sys-hypervisor.c
- ALSA: usb-audio: Avoid false E-MU sample-rate notifications
- ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch
- usb: xhci: Make usb_host_endpoint.hcpriv survive endpoint_disable()
- usb: chipidea: otg: not wait vbus drop if use role_switch
- usb: chipidea: core: allow ci_irq_handler() handle both ID and VBUS
change
- ALSA: usb-audio: Evaluate packsize caps at the right place
- driver core: Don't let a device probe until it's ready
- firmware: google: framebuffer: Do not mark framebuffer as busy
- arm64/mm: Enable batched TLB flush in unmap_hotplug_range()
- drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array
- device property: Make modifications of fwnode "flags" thread safe
- um: drivers: call kernel_strrchr() explicitly in cow_user.c
- Revert "ALSA: usb: Increase volume range that triggers a warning"
- PCI: epf-mhi: Return 0, not remaining timeout, when eDMA ops complete
- lib/ts_kmp: fix integer overflow in pattern length calculation
- media: i2c: imx219: Check return value of devm_gpiod_get_optional() in
imx219_probe()
- ALSA: aoa: i2sbus: fix OF node lifetime handling
- ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes
- mfd: stpmic1: Attempt system shutdown twice in case PMIC is confused
- nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4
- nvme: respect NVME_QUIRK_DISABLE_WRITE_ZEROES when wzsl is set
- parisc: _llseek syscall is only available for 32-bit userspace
- sched: Use u64 for bandwidth ratio calculations
- selftests/mqueue: Fix incorrectly named file
- selftests/landlock: Fix format warning for __u64 in net_test
- io_uring/timeout: check unused sqe fields
- iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned()
- io_uring/poll: fix signed comparison in io_poll_get_ownership()
- io_uring/poll: ensure EPOLL_ONESHOT is propagated for EPOLL_URING_WAKE
- ALSA: core: Fix potential data race at fasync handling
- ALSA: caiaq: Fix control_put() result and cache rollback
- ALSA: 6fire: Fix input volume change detection
- ALSA: pcmtest: fix reference leak on failed device registration
- ALSA: pcmtest: Fix resource leaks in module init error paths
- iio: adc: ad7768-1: fix one-shot mode data acquisition
- tools/accounting: handle truncated taskstats netlink messages
- arm64: dts: marvell: uDPU: add ethernet aliases
- net: txgbe: fix firmware version check
- net: ks8851: Avoid excess softirq scheduling
- drm/arcpgu: fix device node leak
- extract-cert: Wrap key_pass with '#ifdef USE_PKCS11_ENGINE'
- tpm: avoid -Wunused-but-set-variable
- LoongArch: Show CPU vulnerabilites correctly
- power: supply: axp288_charger: Do not cancel work before initializing it
- randomize_kstack: Maintain kstack_offset per task
- mmc: block: use single block write in retry
- mmc: sdhci-of-dwcmshc: Disable clock before DLL configuration
- arm64: dts: ti: am62-verdin: Enable pullup for eMMC data pins
- firmware: google: framebuffer: Do not unregister platform device
- crypto: talitos - fix SEC1 32k ahash request limitation
- crypto: talitos - rename first/last to first_desc/last_desc
- tpm: tpm_tis: add error logging for data transfer
- tpm: tpm_tis: stop transmit if retries are exhausted
- rtc: ntxec: fix OF node reference imbalance
- mm/damon/core: use time_in_range_open() for damos quota window start
- userfaultfd: allow registration of ranges below mmap_min_addr
- KVM: x86: Defer non-architectural deliver of exception payload to
userspace read
- KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state
- KVM: nSVM: Sync NextRIP to cached vmcb12 after VMRUN of L2
- KVM: SVM: Explicitly mark vmcb01 dirty after modifying VMCB intercepts
- KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode
- KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested #VMEXIT
- KVM: nSVM: Always inject a #GP if mapping VMCB12 fails on nested VMRUN
- KVM: nSVM: Clear GIF on nested #VMEXIT(INVALID)
- KVM: nSVM: Clear EVENTINJ fields in vmcb12 on nested #VMEXIT
- KVM: nSVM: Clear tracking of L1->L2 NMI and soft IRQ on nested #VMEXIT
- KVM: nSVM: Add missing consistency check for EFER, CR0, CR4, and CS
- KVM: nSVM: Add missing consistency check for nCR3 validity
- KVM: nSVM: Always intercept VMMCALL when L2 is active
- io_uring/poll: fix multishot recv missing EOF on wakeup race
- perf annotate: Use jump__delete when freeing LoongArch jumps
- mtd: spi-nor: sst: Fix write enable before AAI sequence
- amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2
- check-uapi: link into shared objects
- HID: apple: ensure the keyboard backlight is off if suspending
- wifi: rtl8xxxu: fix potential use of uninitialized value
- taskstats: set version in TGID exit notifications
- apparmor: use target task's context in apparmor_getprocattr()
- bus: mhi: host: pci_generic: Switch to async power up to avoid boot
delays
- crypto: arm64/aes - Fix 32-bit aes_mac_update() arg treated as 64-bit
- crypto: atmel-ecc - Release client on allocation failure
- crypto: hisilicon - Fix dma_unmap_single() direction
- IB/core: Fix zero dmac race in neighbor resolution
- ktest: Fix the month in the name of the failure directory
- seg6: fix seg6 lwtunnel output redirect for L2 reduced encap mode
- f2fs: fix to do sanity check on dcc->discard_cmd_cnt conditionally
- ksmbd: use msleep instaed of schedule_timeout_interruptible()
- ksmbd: replace connection list with hash table
- ksmbd: reset rcount per connection in ksmbd_conn_wait_idle_sess_id()
- wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor
- wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling
- ALSA: aoa: Use guard() for mutex locks
- ALSA: aoa: i2sbus: clear stale prepared state
- mm/zsmalloc: copy KMSAN metadata in zs_page_migrate()
- media: rc: ttusbir: respect DMA coherency rules
- ALSA: aoa: Skip devices with no codecs in i2sbus_resume()
- block: relax pgmap check in bio_add_page for compatible zone device
pages
- iio: frequency: admv1013: add dev variable
- net: mctp: fix don't require received header reserved bits to be zero
- driver core: Add kernel-doc for DEV_FLAG_COUNT enum value
- ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path
- ALSA: caiaq: Don't abort when no input device is available
- ALSA: caiaq: fix usb_dev refcount leak on probe failure
- ACPI: scan: Use acpi_dev_put() in object add error paths
- ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO
- ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug
- ACPI: video: force native backlight on HP OMEN 16 (8A44)
- iommufd: Fix a race with concurrent allocation and unmap
- spi: rockchip: fix controller deregistration
- ksmbd: rewrite stop_sessions() with restartable iteration
- iommu/amd: Use atomic64_inc_return() in iommu.c
- iommu/amd: serialize sequence allocation under concurrent TLB
invalidations
- KVM: SVM: check validity of VMCB controls when returning from SMM
- wifi: mt76: mt7925: fix incorrect length field in txpower command
- wifi: mt76: mt7921: fix ROC abort flow interruption in mt7921_roc_work
- ALSA: usb-audio: midi2: Restart output URBs on resume
- ALSA: usb-audio: Fix UAC3 cluster descriptor size check
- USB: omap_udc: DMA: Don't enable burst 4 mode
- USB: serial: option: add Telit Cinterion LE910Cx compositions
- ALSA: firewire-tascam: Do not drop unread control events
- powerpc/kdump: fix KASAN sanitization flag for core_$(BITS).o
- xfrm: provide message size for XFRM_MSG_MAPPING
- selinux: don't reserve xattr slot when we won't fill it
- selinux: shrink critical section in sel_write_load()
- selinux: prune /sys/fs/selinux/disable
- LoongArch: KVM: Fix missing EMULATE_FAIL in kvm_emu_mmio_read()
- spi: syncuacer: fix controller deregistration
- spi: sun4i: fix controller deregistration
- spi: ti-qspi: fix controller deregistration
- spi: sun6i: fix controller deregistration
- spi: zynqmp-gqspi: fix controller deregistration
- staging: vme_user: fix root device leak on init failure
- LoongArch: Fix SYM_SIGFUNC_START definition for 32BIT
- parisc: Fix IRQ leak in LASI driver
- hwmon: (ltc2992) Clamp threshold writes to hardware range
- hwmon: (ltc2992) Fix u32 overflow in power read path
- clk: rk808: fix OF node reference imbalance
- hwmon: (corsair-psu) Close HID device on probe errors
- cifs: abort open_cached_dir if we don't request leases
- cifs: change_conf needs to be called for session setup
- extcon: ptn5150: handle pending IRQ events during system resume
- gpio: of: clear OF_POPULATED on hog nodes in remove path
- hv_sock: fix ARM64 support
- spi: microchip-core-qspi: fix controller deregistration
- udf: reject descriptors with oversized CRC length
- thermal: core: Free thermal zone ID later during removal
- thermal/drivers/sprd: Fix temperature clamping in
sprd_thm_temp_to_rawdata
- thermal/drivers/sprd: Fix raw temperature clamping in
sprd_thm_rawdata_to_temp
- spi: topcliff-pch: fix controller deregistration
- clk: imx: imx8-acm: fix flags for acm clocks
- cpuidle: powerpc: avoid double clear when breaking snooze
- ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk
table
- ASoC: fsl_easrc: fix comment typo
- ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error
- ASoC: qcom: q6apm-dai: reset queue ptr on trigger stop
- ASoC: qcom: q6apm: remove child devices when apm is removed
- dm: don't report warning when doing deferred remove
- dm-verity-fec: correctly reject too-small FEC devices
- dm-verity-fec: correctly reject too-small hash devices
- lib/scatterlist: fix temp buffer in extract_user_to_sg()
- nvme-apple: drop invalid put of admin queue reference count
- openvswitch: vport: fix self-deadlock on release of tunnel ports
- s390/debug: Reject zero-length input in debug_input_flush_fn()
- PCI: Update saved_config_space upon resource assignment
- PCI/AER: Clear only error bits in PCIe Device Status
- PCI/AER: Stop ruling out unbound devices as error source
- PCI/ASPM: Fix pci_clear_and_set_config_dword() usage
- power: supply: max17042: avoid overflow when determining health
- mptcp: fastclose msk when linger time is 0
- mptcp: use MPJoinSynAckHMacFailure for SynAck HMAC failure
- mptcp: use MPTCP_RST_EMPTCP for ACK HMAC validation failure
- mptcp: sockopt: set timestamp flags on subflow socket, not msk
- f2fs: add READ_ONCE() for i_blocks in f2fs_update_inode()
- f2fs: fix fiemap boundary handling when read extent cache is incomplete
- f2fs: fix incorrect multidevice info in trace_f2fs_map_blocks()
- KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value
- KVM: arm64: Fix initialisation order in __pkvm_init_finalise()
- LoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang()
- LoongArch: KVM: Cap KVM_CAP_NR_VCPUS by KVM_CAP_MAX_VCPUS
- LoongArch: KVM: Fix HW timer interrupt lost when inject interrupt by
software
- LoongArch: KVM: Move unconditional delay into timer clear scenery
- LoongArch: KVM: Use kvm_set_pte() in kvm_flush_pte()
- LoongArch: Use per-root-bridge PCIH flag to skip mem resource fixup
- fs: prepare for adding LSM blob to backing_file
- dma-mapping: drop unneeded includes from dma-mapping.h
- dma-mapping: add __dma_from_device_group_begin()/end()
- mmc: core: Optimize time for secure erase/trim for some Kingston eMMCs
- mtd: spinand: winbond: Declare the QE bit on W25NxxJW
- gtp: disable BH before calling udp_tunnel_xmit_skb()
- printk: add print_hex_dump_devel()
- net: stmmac: avoid shadowing global buf_sz
- net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY()
- wifi: mt76: mt7925: fix incorrect TLV length in CLC command
- KVM: arm64: Wake-up from WFI when iqrchip is in userspace
- Upstream stable to v6.6.137, v6.6.138, v6.6.139, v6.12.85, v6.12.86,
v6.12.87, v6.12.88
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-43490
- ksmbd: validate inherited ACE SID length
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46196
- tracepoint: balance regfunc() on func_add() failure in
tracepoint_add_func()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46110
- net: stmmac: Prevent NULL deref when RX memory exhausted
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46090
- ALSA: aloop: Fix peer runtime UAF during format-change stop
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46291
- crypto: caam - guard HMAC key hex dumps in hash_digest_key
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46299
- hfsplus: fix held lock freed on hfsplus_fill_super()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46169
- hfsplus: fix uninit-value by validating catalog record size
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-45991
- udf: fix partition descriptor append bookkeeping
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46007
- hwmon: (powerz) Avoid cacheline sharing for DMA buffer
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46065
- fbdev: defio: Disconnect deferred I/O from the lifetime of struct
fb_info
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46194
- f2fs: fix node_cnt race between extent node destroy and writeback
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46168
- mptcp: fix scheduling with atomic in timestamp sockopt
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46189
- RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46133
- RDMA/rxe: Reject unknown opcodes before ICRC processing
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46114
- RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46127
- RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46176
- RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46178
- RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46145
- RDMA/mana: Validate rx_hash_key_len
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46126
- RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46144
- RDMA/mana: Fix error unwind in mana_ib_create_qp_rss()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46121
- mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46131
- KVM: x86: check for nEPT/nNPT in slow flush hypercalls
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46139
- smb: client: use kzalloc to zero-initialize security descriptor buffer
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46112
- RDMA/hns: Fix unlocked call to hns_roce_qp_remove()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46292
- pmdomain: core: Fix detach procedure for virtual devices in genpd
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46304
- nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46135
- nvmet-tcp: fix race between ICReq handling and queue teardown
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46161
- md/raid10: fix divide-by-zero in setup_geo() with zero far_copies
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-43492
- lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46124
- isofs: validate block number from NFS file handle in isofs_export_iget
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46303
- isofs: validate Rock Ridge CE continuation extent against volume size
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46106
- eventfs: Hold eventfs_mutex and SRCU when remount walks events
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46294
- dm: fix a buffer overflow in ioctl processing
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46107
- dm-thin: fix metadata refcount underflow
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46129
- btrfs: fix double free in create_space_info() error path
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46143
- ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46293
- clk: microchip: mpfs-ccc: fix out of bounds access during output
registration
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46301
- spi: topcliff-pch: fix use-after-free on unbind
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46273
- ibmveth: Disable GSO for packets with small MSS
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-43495
- net: wwan: t7xx: validate port_count against message length in
t7xx_port_enum_msg_handler
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-43502
- net/rds: handle zerocopy send cleanup before the message is queued
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46120
- ip6_gre: Use cached t->net in ip6erspan_changelink().
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46142
- net: libwx: fix VF illegal register access
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46184
- sound: ua101: fix division by zero at probe
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46132
- net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in
rtnl_fill_vfinfo
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46190
- mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46150
- fanotify: fix false positive on permission events
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46296
- spi: s3c64xx: fix NULL-deref on driver unbind
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-45834
- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-45835
- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46138
- Bluetooth: hci_event: Fix OOB read and infinite loop in
hci_le_create_big_complete_evt
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46186
- Bluetooth: virtio_bt: validate rx pkt_type header length
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46123
- Bluetooth: virtio_bt: clamp rx length before skb_put
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46193
- xfrm: ah: account for ESN high bits in async callbacks
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46172
- ipv6: xfrm6: release dst on error in xfrm6_rcv_encap()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46116
- xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46157
- ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46146
- ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46167
- usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46151
- usb: usblp: fix heap leak in IEEE 1284 device ID via short response
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46180
- wifi: brcmfmac: Fix potential use-after-free issue when stopping
watchdog task
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46122
- wifi: b43: enforce bounds check on firmware key index in b43_rx()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46125
- wifi: mac80211: remove station if connection prep fails
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46307
- wifi: ath5k: do not access array OOB
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46187
- wifi: rsi: fix kthread lifetime race between self-exit and external-stop
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46152
- wifi: mac80211: drop stray 'static' from fast-RX rx_result
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46163
- wifi: b43legacy: enforce bounds check on firmware key index in RX path
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46136
- wifi: mt76: mt7921: fix a potential clc buffer length underflow
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46173
- exit: prevent preemption of oopsing TASK_DEAD task
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-31499
- Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-43496
- net/sched: sch_red: Replace direct dequeue call with peek and
qdisc_dequeue_peeked
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-43088
- net: af_key: zero aligned sockaddr tail in PF_KEY exports
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46287
- net: txgbe: fix RTNL assertion warning when remove module
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46306
- flow_dissector: do not dissect PPPoE PFC frames
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46113
- KVM: x86: Fix shadow paging use-after-free due to unexpected GFN
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46063
- x86/shstk: Prevent deadlock during shstk sigreturn
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-43109
- x86: shadow stacks: proper error handling for mmap lock
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46179
- ASoC: SOF: Don't allow pointer operations on unconfigured streams
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-43497
- fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46108
- ipmi:si: Return state to normal if message allocation fails
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46128
- ipmi: Check event message buffer response for bad data
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46177
- ipmi: Add limits to event and receive message requests
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46149
- scsi: target: configfs: Bound snprintf() return in
tg_pt_gp_members_show()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46101
- netfilter: reject zero shift in nft_bitwise
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46099
- net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46276
- drm/amdgpu: fix zero-size GDS range init on RDNA4
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46033
- crypto: authencesn - reject short ahash digests during instance creation
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46083
- spi: fix resource leaks on device setup failure
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46003
- net: qrtr: ns: Limit the total number of nodes
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46086
- net: bridge: use a stable FDB dst snapshot in RCU readers
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46026
- net: qrtr: ns: Limit the maximum number of lookups
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-43491
- net: qrtr: ns: Limit the maximum server registration per node
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46282
- iio: frequency: admv1013: fix NULL pointer dereference on str
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46084
- RDMA/mana_ib: Disable RX steering on RSS QP destroy
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46091
- media: rc: igorplugusb: heed coherency rules
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46069
- wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46021
- thermal: core: Fix thermal zone governor cleanup issues
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46280
- lib: test_hmm: evict device pages on file close to avoid use-after-free
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-31715
- f2fs: fix UAF caused by decrementing sbi->nr_pages[] in
f2fs_write_end_io()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-31709
- smb: client: validate the whole DACL before rewriting it in cifsacl
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-45997
- scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-43499
- rtmutex: Use waiter::task instead of current in remove_waiter()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46062
- ntfs3: fix integer overflow in run_unpack() volume boundary check
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46072
- ntfs3: add buffer boundary checks to run_unpack()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46052
- ceph: only d_add() negative dentries when they are unhashed
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46023
- dm mirror: fix integer overflow in create_dirty_log()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46075
- crypto: atmel-sha204a - Fix potential UAF and memory leak in remove path
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46077
- crypto: atmel-tdes - fix DMA sync direction
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-45986
- crypto: ccree - fix a memory leak in cc_mac_digest()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46019
- crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46103
- can: ucan: fix devres lifetime
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46056
- Bluetooth: hci_event: fix potential UAF in SSP passkey handlers
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46015
- tcp: call sk_data_ready() after listener migration
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46040
- inotify: fix watch count leak when fsnotify_add_inode_mark_locked()
fails
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46070
- md/raid5: validate payload size before accessing journal metadata
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46051
- md/raid5: fix soft lockup in retry_aligned_read()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46046
- ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46094
- ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46076
- KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46082
- KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-45987
- KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46005
- xfs: fix a resource leak in xfs_alloc_buftarg()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46024
- libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46037
- ipv4: icmp: validate reply type before using icmp_pointers
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46031
- net: ks8851: Reinstate disabling of BHs around IRQ handler
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46027
- net/smc: avoid early lgr access in smc_clc_wait_msg
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46053
- net: rds: fix MR cleanup on copy error
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46038
- net: qrtr: ns: Free the node during ctrl_cmd_bye()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46012
- rxrpc: Fix memory leaks in rxkad_verify_response()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46004
- ALSA: caiaq: Handle probe errors properly
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46079
- rbd: fix null-ptr-deref when device_add_disk() fails
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46016
- remoteproc: xlnx: Only access buffer information if IPI is buffered
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46285
- mtd: docg3: fix use-after-free in docg3_release()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46050
- md/raid10: fix deadlock with check operation and nowait requests
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46061
- jbd2: fix deadlock in jbd2_journal_cancel_revoke()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46078
- erofs: fix the out-of-bounds nameoff handling for trailing dirents
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46049
- ALSA: ctxfi: Add fallback to default RSR for S/PDIF
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46002
- ext2: reject inodes with zero i_nlink and valid mode in ext2_iget()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46047
- net: qrtr: ns: Fix use-after-free in driver remove()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46009
- PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46011
- media: mtk-jpeg: fix use-after-free in release path due to uncancelled
work
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46102
- net: strparser: fix skb_head leak in strp_abort_strp()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46098
- net: caif: clear client service pointer on teardown
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46088
- ALSA: control: Validate buf_len before strnlen() in
snd_ctl_elem_init_enum_names()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46058
- media: amphion: Fix race between m2m job_abort and device_run
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46073
- hwmon: (powerz) Fix missing usb_kill_urb() on signal interrupt
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-45989
- of: unittest: fix use-after-free in testdrv_probe()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-45996
- spi: imx: fix use-after-free on unbind
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46092
- wifi: rtw88: check for PCI upstream bridge existence
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46089
- zram: do not forget to endio for partial discard requests
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46080
- ocfs2: split transactions in dio completion to avoid credit exhaustion
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-23468
- drm/amdgpu: Limit BO list entry count to prevent resource exhaustion
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46064
- ibmasm: fix heap over-read in ibmasm_send_i2o_message()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-45994
- ibmasm: fix OOB reads in command_file_write due to missing size checks
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46022
- misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46041
- greybus: gb-beagleplay: fix sleep in atomic context in hdlc_tx_frames()
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46286
- leds: qcom-lpg: Check for array overflow when selecting the high
resolution
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46006
- drm/nouveau: fix u32 overflow in pushbuf reloc bounds check
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-45993
- LoongArch: Add spectre boundry for syscall dispatch table
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2026-46018
- ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES
* Noble update: upstream stable patchset 2026-06-11 (LP: #2156549) //
CVE-2025-54518 // CVE-2026-46174
- x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op
cache
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373)
- ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA
- ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk
- ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC
- media: rkvdec: reduce stack usage in rkvdec_init_v4l2_vp9_count_tbl()
- ALSA: asihpi: avoid write overflow check warning
- ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF
- ASoC: SOF: topology: reject invalid vendor array size in token parser
- can: mcp251x: add error handling for power enable in open and resume
- ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx
- ALSA: hda/realtek: add quirk for Framework F111:000F
- ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list
- ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex
- ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx
- pinctrl: intel: Fix the revision for new features (1kOhm PD, HW
debouncer)
- platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug
- HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3
- ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10
- ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585
- ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J
- soc: aspeed: socinfo: Mask table entries for accurate SoC ID matching
- arm64: dts: imx8mq: Set the correct gpu_ahb clock frequency
- PCI: hv: Set default NUMA node to 0 for devices without affinity info
- drm/vc4: Release runtime PM reference after binding V3D
- drm/vc4: Protect madv read in vc4_gem_object_mmap() with madv_lock
- net: stmmac: Fix PTP ref clock for Tegra234
- dt-bindings: net: Fix Tegra234 MGBE PTP clock
- tracing/probe: reject non-closed empty immediate strings
- e1000: check return value of e1000_read_eeprom
- xsk: respect tailroom for ZC setups
- xsk: fix XDP_UMEM_SG_FLAG issues
- selftests: net: bridge_vlan_mcast: wait for h1 before querier check
- gpio: tegra: fix irq_release_resources calling enable instead of disable
- ALSA: usb-audio: Improve Focusrite sample rate filtering
- usb: storage: Expand range of matched versions for VL817 quirks entry
- USB: cdc-acm: Add quirks for Yoga Book 9 14IAH10 INGENIC touchscreen
- usb: port: add delay after usb_hub_set_port_power()
- scripts: generate_rust_analyzer.py: avoid FD leak
- USB: serial: option: add Telit Cinterion FN990A MBIM composition
- Docs/admin-guide/mm/damon/reclaim: warn commit_inputs vs param updates
race
- KVM: nVMX: Fold requested virtual interrupt check into
has_nested_events()
- net: sched: fix TCF_LAYER_TRANSPORT handling in tcf_get_base_ptr()
- checkpatch: add support for Assisted-by tag
- Revert "perf unwind-libdw: Fix invalid reference counts"
- net: ethernet: mtk_eth_soc: initialize PPE per-tag-layer MTU registers
- scripts: generate_rust_analyzer.py: define scripts
- KVM: x86: Use __DECLARE_FLEX_ARRAY() for UAPI structures with VLAs
- rxrpc: Fix key quota calculation for multitoken keys
- ocfs2: add inline inode consistency check to
ocfs2_validate_inode_block()
- Revert "wifi: cfg80211: stop NAN and P2P in cfg80211_leave"
- scripts/dtc: Remove unused dts_version in dtc-lexer.l
- fuse: Check for large folio with SPLICE_F_MOVE
- fuse: quiet down complaints in fuse_conn_limit_write
- smb: server: fix max_connections off-by-one in tcp accept path
- ALSA: usb-audio: apply quirk for MOONDROP JU Jiu
- crypto: testmgr - Hide ENOENT errors
- crypto: testmgr - Hide ENOENT errors better
- platform/x86: asus-nb-wmi: add DMI quirk for ASUS ROG Flow Z13-KJP
GZ302EAC
- drm/amdgpu: Handle GPU page faults correctly on non-4K page systems
- ALSA: hda/realtek: Add quirk for Samsung Book2 Pro 360 (NP950QED)
- ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IMH9
- net: sfp: add quirks for Hisense and HSGQ GPON ONT SFP modules
- arm64: dts: qcom: hamoa/x1: fix idle exit latency
- HID: amd_sfh: don't log error when device discovery fails with
-EOPNOTSUPP
- net: increase IP_TUNNEL_RECURSION_LIMIT to 5
- netfilter: nfnetlink_queue: nfqnl_instance GFP_ATOMIC ->
GFP_KERNEL_ACCOUNT allocation
- netfilter: nfnetlink_queue: make hash table per queue
- thermal: core: Mark thermal zones as exiting before unregistration
- KVM: Remove subtle "struct kvm_stats_desc" pseudo-overlay
- PCI: Fix placement of pci_save_state() in pci_bus_add_device()
- ima: verify if the segment size has changed
- ima: do not copy measurement list to kdump kernel
- ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow
- btrfs: tracepoints: fix sleep while in atomic context in
btrfs_sync_file()
- Upstream stable to v6.6.136, v6.12.83, v6.12.84
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31706
- ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31712
- ksmbd: require minimum ACE size in smb_check_perm_dacl()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31575
- mm/userfaultfd: fix hugetlb fault mutex hash calculation
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31582
- hwmon: (powerz) Fix use-after-free on USB disconnect
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43073
- x86-64: rename misleadingly named '__copy_user_nocache()' function
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2025-21709
- kernel: be more careful about dup_mmap() failures and uprobe registering
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31606
- usb: gadget: f_hid: don't call cdev_init while cdev in use
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31731
- thermal: core: Address thermal zone removal races with resume
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31677
- crypto: af_alg - limit RX SG extraction by receive buffer budget
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43107
- xfrm: account XFRMA_IF_ID in aevent size calculation
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43119
- Bluetooth: hci_sync: annotate data-races around hdev->req_status
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31696
- rxrpc: Fix missing validation of ticket length in non-XDR key preparsing
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31697
- crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31698
- crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command
failed
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31699
- crypto: ccp: Don't attempt to copy CSR to userspace if PSP command
failed
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31700
- net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31701
- ALSA: caiaq: take a reference on the USB device in create_card()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31702
- f2fs: fix use-after-free of sbi in f2fs_compress_write_end_io()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31704
- ksmbd: use check_add_overflow() to prevent u16 DACL size overflow
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31705
- ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31708
- smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43350
- smb: client: require a full NFS mode SID before reading mode bits
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31711
- smb: server: fix active_num_conn leak on transport allocation failure
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31694
- fuse: reject oversized dirents in page cache
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31714
- f2fs: fix to avoid memory leak in f2fs_rename()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31716
- fs/ntfs3: validate rec->used in journal-replay file record check
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43075
- ocfs2: fix out-of-bounds write in ocfs2_write_end_inline
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43076
- ocfs2: validate inline data i_size during inode read
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31595
- PCI: endpoint: pci-epf-vntb: Stop cmd_handler work in
epf_ntb_epc_cleanup
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-23444
- wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-23442
- ipv6: add NULL checks for idev in SRv6 paths
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31594
- PCI: endpoint: pci-epf-vntb: Remove duplicate resource teardown
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31576
- media: hackrf: fix to not free memory after the device is registered in
hackrf_probe()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43058
- media: vidtv: fix pass-by-value structs causing MSAN warnings
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31577
- nilfs2: fix NULL i_assoc_inode dereference in
nilfs_mdt_save_to_shadow_map
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31578
- media: as102: fix to not free memory after the device is registered in
as102_usb_probe()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31580
- bcache: fix cached_dev.sb_bio use-after-free and crash
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31581
- ALSA: 6fire: fix use-after-free on disconnect
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31583
- media: em28xx: fix use-after-free in em28xx_v4l2_open()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31584
- media: mediatek: vcodec: fix use-after-free in encoder release path
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31585
- media: vidtv: fix nfeeds state corruption on start_streaming failure
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31586
- mm: blk-cgroup: fix use-after-free in cgwb_release_workfn()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31686
- mm/kasan: fix double free for kasan pXds
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31587
- ASoC: qcom: q6apm: move component registration to unmanaged version
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31588
- KVM: x86: Use scratch field in MMIO fragment to hold small write values
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31590
- KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31596
- ocfs2: handle invalid dinode in ocfs2_group_extend
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31597
- ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31598
- ocfs2: fix possible deadlock between unlink and dio_end_io_write
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31599
- media: vidtv: fix NULL pointer dereference in
vidtv_channel_pmt_match_sections
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31602
- ALSA: ctxfi: Limit PTP to a single page
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31603
- staging: sm750fb: fix division by zero in ps_to_hz()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31604
- wifi: rtw88: fix device leak on probe failure
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31605
- fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31610
- ksmbd: fix mechToken leak when SPNEGO decode fails after token alloc
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31611
- ksmbd: require 3 sub-authorities before reading sub_auth[2]
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31612
- ksmbd: validate EaNameLength in smb2_get_ea()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31615
- usb: gadget: renesas_usb3: validate endpoint index in standard request
handlers
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31616
- usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31617
- usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31618
- fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31619
- ALSA: fireworks: bound device-supplied status before string array lookup
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43072
- drm/vc4: platform_get_irq_byname() returns an int
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31622
- NFC: digital: Bounds check NFC-A cascade depth in SDD response handler
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31623
- net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31624
- HID: core: clamp report_size in s32ton() to avoid undefined shift
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31625
- HID: alps: fix NULL pointer dereference in alps_raw_event()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31626
- staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31627
- i2c: s3c24xx: check the size of the SMBUS message before using it
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31532
- can: raw: fix ro->uniq use-after-free in raw_rcv()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31629
- nfc: llcp: add missing return after LLCP_CLOSED checks
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31407
- netfilter: conntrack: add missing netlink policy validations
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43079
- perf/x86/intel/uncore: Skip discovery table for offline dies
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43080
- l2tp: Drop large packets with UDP encap
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43345
- net: ipa: fix event ring index not programmed for IPA v5.0+
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43081
- net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31673
- af_unix: read UNIX_DIAG_VFS data under unix_state_lock
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43082
- net: txgbe: leave space for null terminators on property_entry
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31681
- netfilter: xt_multiport: validate range encoding in checkentry
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43085
- netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43086
- ipvs: fix NULL deref in ip_vs_add_service error path
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43089
- xfrm_user: fix info leak in build_mapping()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43091
- xfrm: Wait for RCU readers during policy netns exit
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43092
- xsk: validate MTU against usable frame size on bind
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43093
- xsk: tighten UMEM headroom validation to account for tailroom and min
frame
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43094
- ixgbevf: add missing negotiate_features op to Hyper-V ops table
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43098
- nfc: s3fwrn5: allocate rx skb before consuming bytes
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43099
- ipv4: icmp: fix null-ptr-deref in icmp_build_probe()
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43103
- net: lapbether: handle NETDEV_PRE_TYPE_CHANGE
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-31684
- net: sched: act_csum: validate nested VLAN headers
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43074
- eventpoll: defer struct eventpoll free to RCU grace period
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43104
- drm/vc4: Fix a memory leak in hang state error path
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43105
- drm/vc4: Fix memory leak of BO array in hang state
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43110
- wifi: brcmfmac: validate bsscfg indices in IF events
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43111
- HID: roccat: fix use-after-free in roccat_report_event
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43112
- fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43113
- wifi: wl1251: validate packet IDs before indexing tx_frames
* Noble update: upstream stable patchset 2026-06-10 (LP: #2156373) //
CVE-2026-43120
- RDMA/irdma: Fix double free related to rereg_user_mr
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149)
- vfio/pci: Use unmap_mapping_range()
- gfs2: Improve gfs2_consist_inode() usage
- Input: uinput - take event lock when submitting FF request "event"
- MIPS: Always record SEGBITS in cpu_data.vmbits
- MIPS: mm: Suppress TLB uniquification on EHINV hardware
- MIPS: mm: Rewrite TLB uniquification for the hidden bit feature
- virtio_net: clamp rss_max_key_size to NETDEV_RSS_KEY_LEN
- Revert "mptcp: add needs_id for netlink appending addr"
- netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR
- Revert "arm64: dts: imx8mq-librem5: Set the DVS voltages lower"
- arm64: dts: imx8mq-librem5: Bump BUCK1 suspend voltage up to 0.85V
- arm64: dts: hisilicon: poplar: Correct PCIe reset GPIO polarity
- arm64: dts: hisilicon: hi3798cv200: Add missing dma-ranges
- net/mlx5: Update the list of the PCI supported devices
- net: qualcomm: qca_uart: report the consumed byte on RX skb allocation
failure
- rxrpc: Fix key/keyring checks in setsockopt(RXRPC_SECURITY_KEY/KEYRING)
- rxrpc: Fix missing error checks for rxkad encryption/decryption failure
- Revert "PCI: Enable ACS after configuring IOMMU for OF platforms"
- usb: typec: ucsi: skip connector validation before init
- drm/i915/psr: Do not use pipe_src as borders for SU area
- rxrpc: Fix anonymous key handling
- ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6
- rxrpc: Fix rxkad crypto unalignment handling
- Upstream stable to v6.6.134, v6.6.135, v6.12.82
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31429
- net: skb: fix cross-cache free of KFENCE-allocated skb head
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31645
- net: lan966x: fix page pool leak in error paths
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-23302
- net: annotate data-races around sk->sk_{data_ready,write_space}
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-23330
- nfc: nci: complete pending data exchange on device close
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-23374
- blktrace: fix __this_cpu_read/write in preemptible context
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31634
- rxrpc: fix reference count leak in rxrpc_server_keyring()
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31638
- rxrpc: Only put the call ref if one was acquired
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31639
- rxrpc: Fix key reference count leak from call->key
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31642
- rxrpc: Fix call removal to use RCU safe deletion
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31646
- net: lan966x: fix page_pool error handling in
lan966x_fdma_rx_alloc_page_pool()
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31648
- mm: filemap: fix nr_pages calculation overflow in filemap_map_pages()
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31651
- mmc: vub300: fix NULL-deref on disconnect
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31655
- pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31656
- drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31658
- net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31689
- EDAC/mc: Fix error path ordering in edac_mc_alloc()
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31430
- X.509: Fix out-of-bounds access when parsing extensions
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31660
- nfc: pn533: allocate rx skb before consuming bytes
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31661
- wifi: brcmsmac: Fix dma_free_coherent() size
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31662
- tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31664
- xfrm: clear trailing padding in build_polexpire()
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31665
- netfilter: nft_ct: fix use-after-free in timeout object destroy
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31667
- Input: uinput - fix circular locking dependency with ff-core
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31670
- net: rfkill: prevent unlimited numbers of rfkill events from being
created
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31671
- xfrm_user: fix info leak in build_report()
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-31672
- wifi: rt2x00usb: fix devres lifetime
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2026-43336
- lib/crypto: chacha: Zeroize permuted_state before it leaves scope
* Noble update: upstream stable patchset 2026-06-09 (LP: #2156149) //
CVE-2025-54505 // CVE-2026-31628
- x86/CPU: Fix FPDSS on Zen1
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958)
- Revert "rust: pin-init: internal: init: document load-bearing fact of
field accessors"
- arm64/scs: Fix handling of advance_loc4
- HID: logitech-hidpp: Enable MX Master 4 over bluetooth
- btrfs: don't take device_list_mutex when querying zone info
- tg3: replace placeholder MAC address with device property
- objtool: Fix Clang jump table detection
- i2c: tegra: Don't mark devices with pins as IRQ safe
- spi: geni-qcom: Check DMA interrupts early in ISR
- dt-bindings: auxdisplay: ht16k33: Use unevaluatedProperties to fix
common property warning
- wifi: ath11k: Pass the correct value of each TID during a stop AMPDU
session
- net: fec: fix the PTP periodic output sysfs interface
- tg3: Fix race for querying speed/duplex
- net: sfp: Fix Ubiquiti U-Fiber Instant SFP module on mvneta
- net: enetc: check whether the RSS algorithm is Toeplitz
- ASoC: ep93xx: Fix unchecked clk_prepare_enable() and add rollback on
failure
- net: introduce mangleid_features
- net: xilinx: axienet: Correct BD length masks to match AXIDMA IP spec
- netfilter: ipset: use nla_strcmp for IPSET_ATTR_NAME attr
- netfilter: nf_conntrack_expect: honor expectation helper field
- netfilter: nf_conntrack_expect: store netns and zone in expectation
- Bluetooth: hci_sync: call destroy in hci_cmd_sync_run if immediate
- net/mlx5: Avoid "No data available" when FW version queries fail
- net: hsr: fix VLAN add unwind on slave errors
- iio: imu: bno055: fix BNO055_SCAN_CH_COUNT off by one
- hwmon: (pxe1610) Check return value of page-select write in probe
- hwmon: (ltc4286) Add missing MODULE_IMPORT_NS("PMBUS")
- dt-bindings: gpio: fix microchip #interrupt-cells
- hwmon: (tps53679) Fix device ID comparison and printing in
tps53676_identify()
- hwmon: (occ) Fix missing newline in occ_show_extended()
- mips: ralink: update CPU clock index
- sched/fair: Fix zero_vruntime tracking fix
- riscv: kgdb: fix several debug register assignment bugs
- USB: serial: option: add MeiG Smart SRM825WN
- MIPS: SiByte: Bring back cache initialisation
- MIPS: Fix the GCC version check for `__multi3' workaround
- mips: mm: Allocate tlb_vpn array atomically
- iio: adc: ti-adc161s626: fix buffer read on big-endian
- drm/ast: dp501: Fix initialization of SCU2C
- drm/i915/dp: Use crtc_state->enhanced_framing properly on ivb/hsw CPU
eDP
- drm/amdgpu/pm: drop SMU driver if version not matched messages
- USB: serial: io_edgeport: add support for Blackbox IC135A
- USB: serial: option: add support for Rolling Wireless RW135R-GL
- USB: core: add NO_LPM quirk for Razer Kiyo Pro webcam
- Input: synaptics-rmi4 - fix a locking bug in an error path
- Input: i8042 - add TUXEDO InfinityBook Max 16 Gen10 AMD to i8042 quirk
table
- Input: bcm5974 - recover from failed mode switch
- Input: xpad - add support for BETOP BTP-KP50B/C controller's wireless
mode
- Input: xpad - add support for Razer Wolverine V3 Pro
- iio: adc: aspeed: clear reference voltage bits before configuring vref
- iio: accel: fix ADXL355 temperature signature value
- iio: dac: ad5770r: fix error return in ad5770r_read_raw()
- iio: light: vcnl4035: fix scan buffer on big-endian
- iio: imu: bmi160: Remove potential undefined behavior in
bmi160_config_pin()
- iio: imu: st_lsm6dsx: Set FIFO ODR for accelerometer and gyroscope only
- iio: gyro: mpu3050: Fix out-of-sequence free_irq()
- usb: quirks: add DELAY_INIT quirk for another Silicon Motion flash drive
- usb: ehci-brcm: fix sleep during atomic
- cdc-acm: new quirk for EPSON HMD
- firmware: microchip: fail auto-update probe if no flash found
- dt-bindings: connector: add pd-disable dependency
- nvmem: imx: assign nvmem_cell_info::raw_len
- gpio: mxc: map Both Edge pad wakeup to Rising Edge
- thunderbolt: Fix property read in nhi_wake_supported()
- usb: gadget: dummy_hcd: fix premature URB completion when ZLP follows
partial transfer
- btrfs: fix the qgroup data free range for inline data extents
- usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo
- spi: cadence-qspi: Fix exec_mem_op error handling
- drm/amd/pm: disable OD_FAN_CURVE if temp or pwm range invalid for smu
v13
- s390/perf_cpum_sf: Convert to use try_cmpxchg128()
- s390/cpum_sf: Cap sampling rate to prevent lsctl exception
- MPTCP: fix lock class name family in pm_nl_create_listen_socket
- drm/amd/amdgpu: decouple ASPM with pcie dpm
- drm/amd/amdgpu: disable ASPM in some situations
- drm/amd/display: Disable fastboot on DCE 6 too
- drm/amd/display: Keep PLL0 running on DCE 6.0 and 6.4
- drm/amd/display: Fix DCE 6.0 and 6.4 PLL programming.
- drm/amd/display: Adjust DCE 8-10 clock, don't overclock by 15%
- drm/amd/display: Disable scaling on DCE6 for now
- drm/amd: Disable ASPM on SI
- drm/amd/display: Correct logic check error for fastboot
- bpf: Improve bounds when s64 crosses sign boundary
- selftests/bpf: Test cross-sign 64bits range refinement
- selftests/bpf: Test invariants on JSLT crossing sign
- bpf: Add third round of bounds deduction
- selftests/bpf: test refining u32/s32 bounds when ranges cross min/max
boundary
- arm64/scs: Fix potential sign extension issue of advance_loc4
- usb: ulpi: fix memory leak on ulpi_register() error paths
- Upstream stable to v6.6.132, v6.6.133, v6.12.81
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2025-62626
- x86/CPU/AMD: Add additional fixed RDSEED microcode revisions
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31450
- ext4: publish jinode after initialization
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31466
- mm/huge_memory: fix folio isn't locked in softleaf_to_folio()
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43054
- scsi: target: tcm_loop: Drain commands in target_reset handler
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43056
- net: mana: fix use-after-free in add_adev() error path
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43057
- net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31695
- wifi: virt_wifi: remove SET_NETDEV_DEV to avoid use-after-free
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31720
- usb: gadget: f_uac1_legacy: validate control request size
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31721
- usb: gadget: f_hid: move list and spinlock inits from bind to alloc
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31722
- usb: gadget: f_rndis: Fix net_device lifecycle with device_move
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31723
- usb: gadget: f_subset: Fix net_device lifecycle with device_move
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31724
- usb: gadget: f_eem: Fix net_device lifecycle with device_move
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31725
- usb: gadget: f_ecm: Fix net_device lifecycle with device_move
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43342
- usb: gadget: f_rndis: Protect RNDIS options with mutex
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43343
- usb: gadget: f_subset: Fix unbalanced refcnt in geth_free
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31726
- usb: gadget: uvc: fix NULL pointer dereference during unbind race
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31728
- usb: gadget: u_ether: Fix race between gether_disconnect and eth_stop
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2025-71269
- btrfs: do not free data reservation in fallback from inline due to
-ENOSPC
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-23389
- ice: Fix memory leak in ice_set_ringparam()
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31729
- usb: typec: ucsi: validate connector number in ucsi_notify_common()
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43324
- USB: dummy-hcd: Fix interrupt synchronization error
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43327
- USB: dummy-hcd: Fix locking/synchronization error
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31730
- misc: fastrpc: possible double-free of cctx->remote_heap
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43332
- thermal: core: Fix thermal zone device registration error path
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43328
- cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error
path
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31737
- net: ftgmac100: fix ring allocation unwind on open failure
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31738
- vxlan: validate ND option lengths in vxlan_na_create
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31740
- counter: rz-mtu3-cnt: do not use struct rz_mtu3_channel's dev member
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31741
- counter: rz-mtu3-cnt: prevent counter from being toggled multiple times
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31747
- comedi: me4000: Fix potential overrun of firmware buffer
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31748
- comedi: me_daq: Fix potential overrun of firmware buffer
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31749
- comedi: ni_atmio16d: Fix invalid clean-up after failed attach
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43340
- comedi: Reinit dev->spinlock between attachments to low-level drivers
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31751
- comedi: dt2815: add hardware detection to prevent crash
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31752
- bridge: br_nd_send: validate ND option lengths
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31754
- usb: cdns3: gadget: fix state inconsistency on gadget init failure
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31755
- usb: cdns3: gadget: fix NULL pointer dereference in ep_queue
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31756
- usb: dwc2: gadget: Fix spin_lock/unlock mismatch in
dwc2_hsotg_udc_stop()
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31758
- usb: usbtmc: Flush anchored URBs in usbtmc_release
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31759
- usb: ulpi: fix double free in ulpi_register_interface() error path
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31761
- iio: gyro: mpu3050: Move iio_device_register() to correct location
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31762
- iio: gyro: mpu3050: Fix irq resource leak
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31763
- iio: gyro: mpu3050: Fix incorrect free_irq() variable
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31767
- drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31768
- iio: adc: ti-adc161s626: use DMA-safe memory for spi_read()
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31770
- hwmon: (occ) Fix division by zero in occ_show_power_1()
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31432
- ksmbd: fix OOB write in QUERY_INFO for compound requests
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31772
- Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43334
- Bluetooth: SMP: force responder MITM requirements before building the
pairing response
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31773
- Bluetooth: SMP: derive legacy responder STK authentication from MITM
state
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31776
- ALSA: ctxfi: Fix missing SPDIFI1 index handling
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31778
- ALSA: caiaq: fix stack out-of-bounds read in init_card
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31779
- wifi: iwlwifi: mvm: fix potential out-of-bounds read in
iwl_mvm_nd_match_info_handler()
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31780
- wifi: wilc1000: fix u8 overflow in SSID scan buffer size calculation
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31781
- drm/ioc32: stop speculation on the drm_compat_ioctl path
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43007
- accel/qaic: Handle DBC deactivation if the owner went away
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43333
- bpf: reject direct access to nullable PTR_TO_BUF pointers
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31415
- ipv6: avoid overflows in ip6_datagram_send_ctl()
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31422
- net/sched: cls_flow: fix NULL pointer dereference on shared blocks
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31421
- net/sched: cls_fw: fix NULL pointer dereference on shared blocks
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31417
- net/x25: Fix overflow when accumulating packets
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43012
- net/mlx5: Fix switchdev mode rollback in case of failure
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43013
- net/mlx5: lag: Check for LAG device before creating debugfs
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43014
- net: macb: properly unregister fixed rate clocks
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43015
- net: macb: fix clk handling on PCI glue driver removal
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31675
- net/sched: sch_netem: fix out-of-bounds access in packet corruption
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43016
- bpf: sockmap: Fix use-after-free of sk->sk_socket in
sk_psock_verdict_data_ready().
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31425
- rds: ib: reject FRMR registration before IB connection is established
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43017
- Bluetooth: MGMT: validate mesh send advertising payload length
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43018
- Bluetooth: hci_event: fix potential UAF in
hci_le_remote_conn_param_req_evt
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43019
- Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43020
- Bluetooth: MGMT: validate LTK enc_size on load
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43023
- Bluetooth: SCO: fix race conditions in sco_sock_connect()
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43024
- netfilter: nf_tables: reject immediate NF_QUEUE verdict
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31424
- netfilter: x_tables: restrict xt_check_match/xt_check_target extensions
for NFPROTO_ARP
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43025
- netfilter: ctnetlink: ignore explicit helper on new expectations
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31414
- netfilter: nf_conntrack_expect: use expect->helper
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43026
- netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43027
- netfilter: nf_conntrack_helper: pass helper to expect cleanup
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43028
- netfilter: x_tables: ensure names are nul-terminated
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31416
- netfilter: nfnetlink_log: account for netlink header size
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43329
- netfilter: flowtable: strictly check for maximum number of actions
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31680
- net: ipv6: flowlabel: defer exclusive option free until RCU teardown
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43030
- bpf: Fix regsafe() for pointers to packet
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43032
- NFC: pn533: bound the UART receive buffer
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43035
- net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to
zero to prevent an info-leak
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43036
- net: use skb_header_pointer() for TCPv4 GSO frag_off check
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43339
- ipv6: prevent possible UaF in addrconf_permanent_addr()
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-31423
- net/sched: sch_hfsc: fix divide-by-zero in rtsc_min()
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43040
- net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX
fields to zero to prevent an info-leak
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43041
- net: qrtr: replace qrtr_tx_flow radix_tree with xarray to fix memory
leak
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43043
- crypto: af-alg - fix NULL pointer dereference in scatterwalk
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43330
- crypto: caam - fix overflow on long hmac keys
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43044
- crypto: caam - fix DMA corruption on long hmac keys
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43046
- btrfs: reject root items with drop_progress and zero drop_level
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43338
- btrfs: reserve enough transaction items for qgroup ioctls
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43047
- HID: multitouch: Check to ensure report responses match the request
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43049
- HID: logitech-hidpp: Prevent use-after-free on force feedback
initialisation failure
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43050
- atm: lec: fix use-after-free in sock_def_readable()
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43051
- HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq
* Noble update: upstream stable patchset 2026-06-08 (LP: #2155958) //
CVE-2026-43052
- wifi: mac80211: check tdls flag in ieee80211_tdls_oper
* Noble update: upstream stable patchset 2026-06-05 (LP: #2155660)
- perf: Extract a few helpers
- perf: Make sure to use pmu_ctx->pmu for groups
- cxl/hdm: Avoid incorrect DVSEC fallback when HDM decoders are enabled
- hwmon: (axi-fan-control) Use device firmware agnostic API
- hwmon: (axi-fan-control) Make use of dev_err_probe()
- hwmon: axi-fan: don't use driver_override as IRQ name
- sh: platform_early: remove pdev->driver_override check
- bpf: Release module BTF IDR before module unload
- bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN
- HID: asus: avoid memory leak in asus_report_fixup()
- platform/x86: intel-hid: Add Dell 14 Plus 2-in-1 to dmi_vgbs_allow_list
- nvme-pci: cap queue creation to used queues
- nvme-fabrics: use kfree_sensitive() for DHCHAP secrets
- platform/x86: intel-hid: Enable 5-button array on ThinkPad X1 Fold 16
Gen 1
- platform/x86: touchscreen_dmi: Add quirk for y-inverted Goodix
touchscreen on SUPI S10
- nvme-pci: ensure we're polling a polled queue
- HID: magicmouse: fix battery reporting for Apple Magic Trackpad 2
- HID: magicmouse: avoid memory leak in magicmouse_report_fixup()
- net: usb: r8152: add TRENDnet TUC-ET2G
- HID: mcp2221: cancel last I2C command on read error
- HID: asus: add xg mobile 2023 external hardware support
- module: Fix kernel panic when a symbol st_shndx is out of bounds
- ASoC: fsl_easrc: Fix event generation in fsl_easrc_iec958_set_reg()
- ASoC: fsl_easrc: Fix event generation in fsl_easrc_iec958_put_bits()
- dma-buf: Include ioctl.h in UAPI header
- HID: apple: avoid memory leak in apple_report_fixup()
- btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create
- ALSA: hda/realtek: add HP Laptop 14s-dr5xxx mute LED quirk
- ALSA: hda/realtek: Add headset jack quirk for Thinkpad X390
- objtool: Handle Clang RSP musical chairs
- usb: core: new quirk to handle devices with zero configurations
- spi: intel-pci: Add support for Nova Lake mobile SPI flash
- xfrm: call xdo_dev_state_delete during state update
- xfrm: Fix the usage of skb->sk
- esp: fix skb leak with espintcp and async crypto
- af_key: validate families in pfkey_send_migrate()
- dma: swiotlb: add KMSAN annotations to swiotlb_bounce()
- can: statistics: add missing atomic access in hot path
- Bluetooth: L2CAP: Validate PDU length before reading SDU length in
l2cap_ecred_data_rcv()
- Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing
sock_hold
- Bluetooth: hci_ll: Fix firmware leak on error path
- Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb
- pinctrl: mediatek: common: Fix probe failure for devices without EINT
- ionic: fix persistent MAC address override on PF
- nfc: nci: fix circular locking dependency in nci_close_device
- net: openvswitch: Avoid releasing netdev before teardown completes
- openvswitch: defer tunnel netdev_put to RCU release
- openvswitch: validate MPLS set/set_masked payload length
- net/smc: fix double-free of smc_spd_priv when tee() duplicates splice
pipe buffer
- rtnetlink: count IFLA_INFO_SLAVE_KIND in if_nlmsg_size
- platform/olpc: olpc-xo175-ec: Fix overflow error message to print inlen
- ice: use ice_update_eth_stats() for representor stats
- ipv6: Remove permanent routes from tb6_gc_hlist when all exceptions
expire.
- ipv6: Don't remove permanent routes with exceptions from tb6_gc_hlist.
- tcp: optimize inet_use_bhash2_on_bind()
- udp: Fix wildcard bind conflict check when using hash2
- net: enetc: fix the output issue of 'ethtool --show-ring'
- dma-mapping: add missing `inline` for `dma_free_attrs`
- Bluetooth: L2CAP: Fix send LE flow credits in ACL link
- Bluetooth: Remove 3 repeated macro definitions
- Bluetooth: hci_sync: Remove remaining dependencies of hci_request
- Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock
- Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite loop
- Bluetooth: btusb: clamp SCO altsetting table indices
- tls: Purge async_hold in tls_decrypt_async_wait()
- netfilter: nfnetlink_log: fix uninitialized padding leak in
NFULA_PAYLOAD
- netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check()
- netfilter: nf_conntrack_expect: skip expectations in other netns via
proc
- netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in
process_sdp
- netfilter: ctnetlink: use netlink policy range checks
- net: macb: use the current queue number for stats
- regmap: Synchronize cache for the page selector
- RDMA/rw: Fall back to direct SGE on MR pool exhaustion
- RDMA/irdma: Initialize free_qp completion before using it
- RDMA/irdma: Update ibqp state to error if QP is already in error state
- RDMA/irdma: Remove a NOP wait_event() in irdma_modify_qp_roce()
- RDMA/irdma: Clean up unnecessary dereference of event->cm_node
- RDMA/irdma: Remove reset check from irdma_modify_qp_to_err()
- RDMA/irdma: Fix deadlock during netdev reset with active connections
- RDMA/irdma: Return EINVAL for invalid arp index error
- scsi: scsi_transport_sas: Fix the maximum channel scanning issue
- x86/efi: efi_unmap_boot_services: fix calculation of ranges_to_free size
- drm/i915/gmbus: fix spurious timeout on 512-byte burst reads
- PM: hibernate: Don't ignore return from set_memory_ro()
- PM: hibernate: Drain trailing zero pages on userspace restore
- spi: sn-f-ospi: Fix resource leak in f_ospi_probe()
- ASoC: Intel: catpt: Fix the device initialization
- ACPI: EC: clean up handlers on probe failure in acpi_ec_setup()
- drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib
- hwmon: (adm1177) fix sysfs ABI violation and current unit conversion
- sysctl: fix uninitialized variable in proc_do_large_bitmap
- ASoC: adau1372: Fix unchecked clk_prepare_enable() return value
- ASoC: adau1372: Fix clock leak on PLL lock failure
- spi: spi-fsl-lpspi: fix teardown order issue (UAF)
- s390/syscalls: Add spectre boundary for syscall dispatch table
- s390/barrier: Make array_index_mask_nospec() __always_inline
- ksmbd: fix potencial OOB in get_file_all_info() for compound requests
- ksmbd: do not expire session on binding failure
- ALSA: firewire-lib: fix uninitialized local variable
- ASoC: SOF: ipc4-topology: Allow bytes controls without initial payload
- can: gw: fix OOB heap access in cgw_csum_crc8_rel()
- can: isotp: fix tx.buf use-after-free in isotp_sendmsg()
- cpufreq: conservative: Reset requested_freq on limits change
- platform/x86: ISST: Correct locked bit width
- KVM: arm64: Discard PC update state on vcpu reset
- hwmon: (pmbus/isl68137) Add mutex protection for AVS enable sysfs
attributes
- hwmon: (peci/cputemp) Fix crit_hyst returning delta instead of absolute
temperature
- hwmon: (peci/cputemp) Fix off-by-one in cputemp_is_visible()
- media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex
- virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and
napi_tx is false
- s390/entry: Scrub r12 register on kernel entry
- erofs: add GFP_NOIO in the bio completion if needed
- alarmtimer: Fix argument order in alarm_timer_forward()
- scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done()
- scsi: ses: Handle positive SCSI error from ses_recv_diag()
- net: macb: Use dev_consume_skb_any() to free TX SKBs
- KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO
SPTE
- jbd2: gracefully abort on checkpointing state corruptions
- irqchip/qcom-mpm: Add missing mailbox TX done acknowledgment
- dmaengine: sh: rz-dmac: Protect the driver specific lists
- dmaengine: sh: rz-dmac: Move CHCTRL updates under spinlock
- LoongArch: Workaround LS2K/LS7A GPU DMA hang bug
- xfs: stop reclaim before pushing AIL during unmount
- xfs: fix ri_total validation in xlog_recover_attri_commit_pass2
- ext4: fix journal credit check when setting fscrypt context
- ext4: convert inline data to extents when truncate exceeds inline size
- ext4: fix fsync(2) for nojournal mode
- ext4: make recently_deleted() properly work with lazy itable
initialization
- ext4: replace BUG_ON with proper error handling in
ext4_read_inline_folio
- ext4: avoid allocate block from corrupted group in
ext4_mb_find_by_goal()
- ext4: reject mount if bigalloc with s_first_data_block != 0
- ext4: fix use-after-free in update_super_work when racing with umount
- ext4: fix the might_sleep() warnings in kvfree()
- ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths
- ext4: always drain queued discard work in ext4_mb_release()
- arm64: dts: imx8mn-tqma8mqnl: fix LDO5 power off
- powerpc64/bpf: do not increment tailcall count when prog is NULL
- ksmbd: fix memory leaks and NULL deref in smb2_lock()
- tracing: Switch trace_osnoise.c code over to use guard() and __free()
- tracing: Fix potential deadlock in cpu hotplug with osnoise
- mtd: spi-nor: core: avoid odd length/address reads on 8D-8D-8D mode
- mtd: spi-nor: core: avoid odd length/address writes in 8D-8D-8D mode
- libbpf: Fix -Wdiscarded-qualifiers under C23
- mm/damon/sysfs: check contexts->nr before accessing contexts_arr[0]
- xfs: avoid dereferencing log items after push callbacks
- xfs: save ailp before dropping the AIL lock in push callbacks
- dmaengine: idxd: Fix not releasing workqueue on .release()
- dmaengine: idxd: Fix memory leak when a wq is reset
- phy: ti: j721e-wiz: Fix device node reference leak in
wiz_get_lane_phy_types()
- dmaengine: dw-edma: Fix multiple times setting of the CYCLE_STATE and
CYCLE_BIT bits for HDMA.
- dmaengine: xilinx: xdma: Fix regmap init error handling
- dmaengine: xilinx: xilinx_dma: Fix dma_device directions
- dmaengine: xilinx: xilinx_dma: Fix residue calculation for cyclic DMA
- dmaengine: xilinx: xilinx_dma: Fix unmasked residue subtraction
- dmaengine: xilinx_dma: Fix reset related timeout with two-channel AXIDMA
- btrfs: fix super block offset in error message in btrfs_validate_super()
- btrfs: fix leak of kobject name for sub-group space_info
- btrfs: fix lost error when running device stats on multiple devices fs
- dmaengine: idxd: Fix freeing the allocated ida too late
- futex: Clear stale exiting pointer in futex_lock_pi() retry path
- ALSA: hda/realtek: Fix speaker pop on Star Labs StarFighter
- kexec: Consolidate machine_kexec_mask_interrupts() implementation
- [Config] Enable GENERIC_IRQ_KEXEC_CLEAR_VM_FORWARD by default.
- kexec: Include kernel-end even without crashkernel
- powerpc/kexec/core: use big-endian types for crash variables
- drm/msm/dsi: fix hdisplay calculation when programming dsi registers
- perf disasm: Fix off-by-one bug in outside check
- net/mlx5: Fix crash when moving to switchdev mode
- bonding: add ESP offload features when slaves support
- bonding: Correctly support GSO ESP offload
- net: add a common function to compute features for upper devices
- bonding: use common function to compute the features
- bonding: fix type confusion in bond_setup_by_slave()
- xdp: allow attaching already registered memory model to xdp_rxq_info
- net: add generic percpu page_pool allocator
- net: do not consume a cacheline for system_page_pool
- xdp: register system page pool as an XDP memory model
- net: add xmit recursion limit to tunnel xmit functions
- net: prevent NULL deref in ip[6]tunnel_xmit()
- ata: libata-core: Add BRIDGE_OK quirk for QEMU drives
- usb: typec: altmode/displayport: set displayport signaling rate in
configure message
- rust: kbuild: allow `unused_features`
- ceph: add a bunch of missing ceph_path_info initializers
- drm/amd/pm: remove invalid gpu_metrics.energy_accumulator on smu v13.0.x
- tracing: Fix enabling multiple events on the kernel command line and
bootconfig
- qmi_wwan: allow max_mtu above hard_mtu to control rx_urb_size
- xfs: fix returned valued from xfs_defer_can_append
- iio: imu: inv_icm42600: add support of ICM-42686-P
- iio: imu: inv_icm42600: fix odr switch when turning buffer off
- perf/x86/intel/uncore: Support more units on Granite Rapids
- perf/x86/intel/uncore: Add per-scheduler IMC CAS count events
- cleanup: Provide retain_and_null_ptr()
- usb: gadget: f_ncm: Fix net_device lifecycle with device_move
- KVM: x86: Co-locate initialization of feature MSRs in
kvm_arch_vcpu_create()
- KVM: x86: Quirk initialization of feature MSRs to KVM's max
configuration
- KVM: x86: do not allow re-enabling quirks
- KVM: x86: Allow vendor code to disable quirks
- KVM: x86: Introduce supported_quirks to block disabling quirks
- KVM: x86: Remove VMX support for virtualizing guest MTRR memtypes
- KVM: VMX: Drop support for forcing UC memory when guest CR0.CD=1
- KVM: x86: Introduce Intel specific quirk KVM_X86_QUIRK_IGNORE_GUEST_PAT
- KVM: nVMX: Add consistency checks for CR0.WP and CR4.CET
- KVM: x86: Introduce KVM_X86_QUIRK_VMCS12_ALLOW_FREEZE_IN_SMM
- drm/xe/sync: Cleanup partially initialized sync on parse failure
- ice: fix devlink reload call trace
- io_uring/uring_cmd: fix too strict requirement on ioctl
- erofs: fix inline data read failure for ztailpacking pclusters
- mm: merge folio_is_secretmem() and folio_fast_pin_allowed() into
gup_fast_folio_allowed()
- mm: thp: deny THP for files on anonymous inodes
- sched/fair: Fix zero_vruntime tracking
- mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN stations
- drm/i915/dsc: Add Selective Update register definitions
- drm/imagination: Fix deadlock in soft reset sequence
- ata: libata-scsi: Return residual for emulated SCSI commands
- ata: libata-scsi: report correct sense field pointer in
ata_scsiop_maint_in()
- soc: microchip: mpfs: Fix memory leak in mpfs_sys_controller_probe()
- firmware: arm_ffa: Remove vm_id argument in ffa_rxtx_unmap()
- Bluetooth: MGMT: Fix list corruption and UAF in command complete
handlers
- nf_tables: nft_dynset: fix possible stateful expression memleak in error
path
- bonding: prevent potential infinite loop in bond_header_parse()
- drm/i915/psr: Compute PSR entry_setup_frames into intel_crtc_state
- perf/x86/intel: Add missing branch counters constraint apply
- Revert "LoongArch: Add machine_kexec_mask_interrupts() implementation"
- cxl/port: Fix use after free of parent_port in cxl_detach_ep()
- driver core: generalize driver_override in struct device
- driver core: platform: use generic driver_override infrastructure
- bpf: Fix unsound scalar forking in maybe_fork_scalars() for BPF_OR
- HID: apple: Add EPOMAKER TH87 to the non-apple keyboards list
- kbuild: install-extmod-build: Package resolve_btfids if necessary
- nvmet: move async event work off nvmet-wq
- ALSA: hda/realtek: add quirk for ASUS UM6702RC
- i3c: master: dw-i3c: Fix missing of_node for virtual I2C adapter
- xfrm: add missing extack for XFRMA_SA_PCPU in add_acquire and allocspi
- xfrm: fix the condition on x->pcpu_num in xfrm_sa_len
- xfrm: prevent policy_hthresh.work from racing with netns teardown
- Bluetooth: MGMT: Fix dangling pointer on
mgmt_add_adv_patterns_monitor_complete
- net: bcmasp: remove eee_enabled/eee_active in bcmasp_get_eee()
- net: bcm: asp2: fix LPI timer handling
- net: bcm: asp2: remove tx_lpi_enabled
- net: bcmasp: Add support for ASP 2.2
- net: bcm: asp2: convert to phylib managed EEE
- net: bcmasp: Remove support for asp-v2.0
- net: bcmasp: streamline early exit in probe
- net: bcmasp: fix double free of WoL irq
- net: bcmasp: Add support for asp-v3.0
- net: bcmasp: fix double disable of clk
- platform/x86: intel-hid: disable wakeup_mode during hibernation
- iavf: fix out-of-bounds writes in iavf_get_ethtool_stats()
- team: fix header_ops type confusion with non-Ethernet ports
- ALSA: hda/realtek: Sequence GPIO2 on Star Labs StarFighter
- spi: meson-spicc: Fix double-put in remove path
- drm/amd/display: Do not skip unrelated mode changes in DSC validation
- spi: Group CS related fields in struct spi_device
- spi: use generic driver_override infrastructure
- hwmon: (pmbus/core) Fix various coding style issues
- hwmon: (pmbus) Mark lowest/average/highest/rated attributes as read-only
- hwmon: (pmbus) Introduce the concept of "write-only" attributes
- x86/cpu: Enable FSGSBASE early in cpu_init_exception_handling()
- ovl: fix wrong detection of 32bit inode numbers
- net: macb: Move devm_{free,request}_irq() out of spin lock area
- dmaengine: fsl-edma: change to guard(mutex) within fsl_edma3_xlate()
- dmaengine: fsl-edma: fix channel parameter config for fixed channel
requests
- LoongArch: Fix missing NULL checks for kstrdup()
- xfs: scrub: unlock dquot before early return in quota scrub
- ext4: validate p_idx bounds in ext4_ext_correct_indexes
- LoongArch: vDSO: Emit GNU_EH_FRAME correctly
- spi: tegra210-quad: Protect curr_xfer check in IRQ handler
- media: nxp: imx8-isi: Fix streaming cleanup on release
- rust: pin-init: internal: init: document load-bearing fact of field
accessors
- ovl: Use str_on_off() helper in ovl_show_options()
- ovl: make fsync after metadata copy-up opt-in mount option
- virt: tdx-guest: Fix handling of host controlled 'quote' buffer length
- net: add proper RCU protection to /proc/net/ptype
- landlock: Optimize file path walks and prepare for audit support
- landlock: Fix handling of disconnected directories
- idpf: check error for register_netdev() on init
- idpf: detach and close netdevs while handling a reset
- idpf: Fix RSS LUT NULL pointer crash on early ethtool operations
- idpf: Fix RSS LUT NULL ptr issue after soft reset
- ASoC: ak4458: Convert to RUNTIME_PM_OPS() & co
- netfs: Fix kernel BUG in netfs_limit_iter() for ITER_KVEC iterators
- xen/privcmd: unregister xenstore notifier on module exit
- futex: Require sys_futex_requeue() to have identical flags
- dmaengine: idxd: Fix leaking event log memory
- net: bcmasp: Restore programming of TX map vector register
- net: bcmasp: Fix network filter wake for asp-3.0
- idpf: nullify pointers after they are freed
- Upstream stable to v6.6.131, v6.12.78, v6.12.79, v6.12.80
* Noble update: upstream stable patchset 2026-05-28 (LP: #2154496)
- drm/vmwgfx: Fix invalid kref_put callback in vmw_bo_dirty_release
- drm/vmwgfx: Return the correct value in vmw_translate_ptr functions
- drm/logicvc: Fix device node reference leak in
logicvc_drm_config_parse()
- irqchip/sifive-plic: Fix frozen interrupt due to affinity setting
- scsi: lpfc: Properly set WC for DPP mapping
- scsi: pm8001: Fix use-after-free in pm8001_queue_command()
- ALSA: usb-audio: Remove VALIDATE_RATES quirk for Focusrite devices
- rseq: Clarify rseq registration rseq_size bound check comment
- scsi: ufs: core: Move link recovery for hibern8 exit failure to
wl_resume
- ALSA: usb-audio: Cap the packet size pre-calculations
- ALSA: usb-audio: Use inclusive terms
- perf: Fix __perf_event_overflow() vs perf_remove_from_context() race
- ALSA: pci: hda: use snd_kcontrol_chip()
- ALSA: hda: cs35l56: Fix signedness error in cs35l56_hda_posture_put()
- btrfs: fix incorrect key offset in error message in
check_dev_extent_item()
- btrfs: fix objectid value in error message in check_extent_data_ref()
- btrfs: fix warning in scrub_verify_one_metadata()
- btrfs: fix compat mask in error messages in btrfs_check_features()
- bpf: Fix stack-out-of-bounds write in devmap
- PCI: Correct PCI_CAP_EXP_ENDPOINT_SIZEOF_V2 value
- memory: mtk-smi: fix device leaks on common probe
- memory: mtk-smi: fix device leak on larb probe
- resource: Add resource set range and size helpers
- PCI: Use resource_set_range() that correctly sets ->end
- KVM: x86: Rename KVM_MSR_RET_INVALID to KVM_MSR_RET_UNSUPPORTED
- media: tegra-video: Fix memory leak in __tegra_channel_try_format()
- KVM: x86: WARN if a vCPU gets a valid wakeup that KVM can't yet inject
- KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block()
- drm/tegra: dsi: fix device leak on probe
- ext4: get rid of ppath in ext4_split_extent_at()
- ext4: subdivide EXT4_EXT_DATA_VALID1
- ext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1
- ext4: get rid of ppath in ext4_split_extent()
- ext4: get rid of ppath in ext4_split_convert_extents()
- ext4: get rid of ppath in ext4_convert_unwritten_extents_endio()
- ext4: get rid of ppath in ext4_ext_convert_to_initialized()
- ext4: get rid of ppath in ext4_ext_handle_unwritten_extents()
- ext4: correct the comments place for EXT4_EXT_MAY_ZEROOUT
- ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting
I/O
- ext4: drop extent cache after doing PARTIAL_VALID1 zeroout
- ext4: drop extent cache when splitting extent fails
- mailbox: Use of_property_match_string() instead of open-coding
- mailbox: don't protect of_parse_phandle_with_args with con_mutex
- mailbox: sort headers alphabetically
- mailbox: remove unused header files
- mailbox: Use dev_err when there is error
- mailbox: Use guard/scoped_guard for con_mutex
- mailbox: Allow controller specific mapping using fwnode
- mailbox: Prevent out-of-bounds access in fw_mbox_index_xlate()
- ext4: convert bd_bitmap_page to bd_bitmap_folio
- ext4: convert bd_buddy_page to bd_buddy_folio
- ext4: fix e4b bitmap inconsistency reports
- arm64: dts: rockchip: Fix rk356x PCIe range mappings
- clk: tegra: tegra124-emc: fix device leak on set_rate()
- usb: cdns3: remove redundant if branch
- usb: cdns3: call cdns_power_is_lost() only once in cdns_resume()
- usb: cdns3: fix role switching during resume
- drm/amd: Fix hang on amdgpu unload by using pci_dev_is_disconnected()
- ALSA: hda/conexant: Add quirk for HP ZBook Studio G4
- hwmon: (max16065) Use READ/WRITE_ONCE to avoid compiler optimization
induced race
- ALSA: hda/conexant: Fix headphone jack handling on Acer Swift SF314
- net: arcnet: com20020-pci: fix support for 2.5Mbit cards
- eventpoll: Fix integer overflow in ep_loop_check_proc()
- media: dvb-core: fix wrong reinitialization of ringbuffer on reopen
- nfc: pn533: properly drop the usb interface reference on disconnect
- net: usb: kaweth: validate USB endpoints
- net: usb: kalmia: validate USB endpoints
- net: usb: pegasus: validate USB endpoints
- can: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a
message
- can: usb: f81604: correctly anchor the urb in the read bulk callback
- can: ucan: Fix infinite loop from zero-length messages
- can: usb: etas_es58x: correctly anchor the urb in the read bulk callback
- can: usb: f81604: handle short interrupt urb messages properly
- can: usb: f81604: handle bulk write errors properly
- HID: Add HID_CLAIMED_INPUT guards in raw_event callbacks missing them
- x86/efi: defer freeing of boot services memory
- platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data
- platform/x86: dell-wmi: Add audio/mic mute key codes
- ALSA: usb-audio: Use correct version for UAC3 header validation
- wifi: radiotap: reject radiotap with unknown bits
- wifi: cfg80211: cancel rfkill_block work in wiphy_unregister()
- wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
- wifi: mac80211: fix NULL pointer dereference in mesh_rx_csa_frame()
- IB/mthca: Add missed mthca_unmap_user_db() for mthca_create_srq()
- RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah()
- net/sched: ets: fix divide by zero in the offload path
- scsi: target: Fix recursive locking in __configfs_open_file()
- Squashfs: check metadata block offset is within range
- drbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock()
- drbd: fix null-pointer dereference on local read error
- smb: client: fix cifs_pick_channel when channels are equally loaded
- smb: client: fix broken multichannel with krb5+signing
- smb: client: Don't log plaintext credentials in cifs_set_cifscreds
- scsi: core: Fix refcount leak for tagset_refcnt
- selftests: mptcp: more stable simult_flows tests
- selftests: mptcp: join: check removing signal+subflow endp
- ARM: clean up the memset64() C wrapper
- hwmon: (aht10) Add support for dht20
- hwmon: (aht10) Fix initialization commands for AHT20
- pinctrl: equilibrium: rename irq_chip function callbacks
- pinctrl: equilibrium: fix warning trace on load
- platform/x86: thinkpad_acpi: Fix errors reading battery thresholds
- pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()
- hwmon: (it87) Check the it87_lock() return value
- e1000e: clear DPG_EN after reset to avoid autonomous power-gating
- drm/solomon: Fix page start when updating rectangle in page addressing
mode
- net: ethernet: ti: am65-cpsw-nuss/cpsw-ale: Fix multicast entry handling
in ALE table
- xsk: Get rid of xdp_buff_xsk::xskb_list_node
- xsk: s/free_list_node/list_node/
- xsk: Fix fragment node deletion to prevent buffer leak
- xsk: Fix zero-copy AF_XDP fragment drop
- dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ
handler
- atm: lec: fix null-ptr-deref in lec_arp_clear_vccs
- amd-xgbe: fix MAC_TCR_SS register width for 2.5G and 10M speeds
- can: bcm: fix locking for bcm_op runtime updates
- can: mcp251x: fix deadlock in error path of mcp251x_open
- rust: kunit: fix warning when !CONFIG_PRINTK
- kunit: tool: copy caller args in run_kernel to prevent mutation
- net: dsa: realtek: rtl8365mb: fix rtl8365mb_phy_ocp_write return value
- bpf/bonding: reject vlan+srcmac xmit_hash_policy change when XDP is
loaded
- octeon_ep: Relocate counter updates before NAPI
- octeon_ep: avoid compiler and IQ/OQ reordering
- wifi: cw1200: Fix locking in error paths
- wifi: wlcore: Fix a locking bug
- wifi: mt76: mt7996: Fix possible oob access in
mt7996_mac_write_txwi_80211()
- wifi: mt76: Fix possible oob access in
mt76_connac2_mac_write_txwi_80211()
- indirect_call_wrapper: do not reevaluate function pointer
- net/rds: Fix circular locking dependency in rds_tcp_tune
- xen/acpi-processor: fix _CST detection using undersized evaluation
buffer
- bpf: export bpf_link_inc_not_zero.
- bpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim
- smb/client: fix buffer size for smb311_posix_qinfo in smb2_compound_op()
- smb/client: fix buffer size for smb311_posix_qinfo in
SMB311_posix_query_info()
- ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu()
- amd-xgbe: fix sleep while atomic on suspend/resume
- drm/sched: Fix kernel-doc warning for drm_sched_job_done()
- nvme: reject invalid pr_read_keys() num_keys values
- nvme: fix memory allocation in nvme_pr_read_keys()
- net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless
qdiscs
- net: nfc: nci: Fix zero-length proprietary notifications
- nfc: nci: free skb on nci_transceive early error paths
- nfc: nci: clear NCI_DATA_EXCHANGE before calling completion callback
- nfc: rawsock: cancel tx_work before socket teardown
- net: stmmac: Fix error handling in VLAN add and delete paths
- net: ethernet: mtk_eth_soc: Reset prog ptr to old_prog in case of error
in mtk_xdp_setup()
- net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled
- net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled
- net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop
- net/sched: act_ife: Fix metalist update behavior
- xdp: use modulo operation to calculate XDP frag tailroom
- xsk: introduce helper to determine rxq->frag_size
- i40e: fix registering XDP RxQ info
- i40e: use xdp.frame_sz as XDP RxQ info frag_size
- xdp: produce a warning when calculated tailroom is negative
- selftest/arm64: Fix sve2p1_sigill() to hwcap test
- tracing: Add NULL pointer check to trigger_data_free()
- net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared
blocks
- net: tcp: accept old ack during closing
- scsi: storvsc: Fix scheduling while atomic on PREEMPT_RT
- ACPI: PM: Save NVS memory on Lenovo G70-35
- scsi: mpi3mr: Add NULL checks when resetting request and reply queues
- unshare: fix unshare_fs() handling
- wifi: mac80211: set default WMM parameters on all links
- ACPI: OSI: Add DMI quirk for Acer Aspire One D255
- scsi: ses: Fix devices attaching to different hosts
- ASoC: amd: yc: Add ASUS EXPERTBOOK BM1503CDA to quirk table
- ASoC: cs42l43: Report insert for exotic peripherals
- scsi: ufs: core: Fix possible NULL pointer dereference in
ufshcd_add_command_trace()
- scsi: ufs: core: Fix shift out of bounds when MAXQ=32
- ALSA: usb-audio: Avoid implicit feedback mode on DIYINHK USB Audio 2.0
- ALSA: usb-audio: Check max frame size for implicit feedback mode, too
- powerpc/uaccess: Fix inline assembly for clang build on PPC32
- remoteproc: sysmon: Correct subsys_name_len type in QMI request
- powerpc: 83xx: km83xx: Fix keymile vendor prefix
- xprtrdma: Decrement re_receiving on the early exit paths
- net: dsa: realtek: rtl8365mb: remove ifOutDiscards from rx_packets
- drm/msm/dsi: Document DSC related pclk_rate and hdisplay calculations
- drm/msm/dsi: fix pclk rate calculation for bonded dsi
- bonding: handle BOND_LINK_FAIL, BOND_LINK_BACK as valid link states
- net/mlx5: IFC updates for disabled host PF
- net/mlx5: Query to see if host PF is disabled
- net/mlx5: Fix deadlock between devlink lock and esw->wq
- net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery
- net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL
slave xmit
- ASoC: soc-core: drop delayed_work_pending() check before flush
- ASoC: soc-core: flush delayed work before removing DAIs and widgets
- ASoC: simple-card-utils: use __free(device_node) for device node
- ASoC: simple-card-utils: fix graph_util_is_ports0() for DT overlays
- net: sfp: improve Huawei MA5671a fixup
- serial: caif: hold tty->link reference in ldisc_open and ser_release
- mctp: i2c: fix skb memory leak in receive path
- can: hi311x: hi3110_open(): add check for hi3110_power_enable() return
value
- mctp: route: hold key->lock in mctp_flow_prepare_output()
- amd-xgbe: fix link status handling in xgbe_rx_adaptation
- amd-xgbe: prevent CRC errors during RX adaptation with AN disabled
- netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop()
- netfilter: x_tables: guard option walkers against 1-byte tail reads
- netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path
- netfilter: nfnetlink_cthelper: fix OOB read in
nfnl_cthelper_dump_table()
- regulator: pca9450: Make IRQ optional
- regulator: pca9450: Correct interrupt type
- sched: idle: Make skipping governor callbacks more consistent
- nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set
- nvme-pci: Fix race bug in nvme_poll_irqdisable()
- i40e: fix src IP mask checks and memcpy argument names in cloud filter
- e1000/e1000e: Fix leak in DMA error cleanup
- ACPI: OSL: fix __iomem type on return from acpi_os_map_generic_address()
- ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock
acquisition
- ASoC: detect empty DMI strings
- net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled
- octeontx2-af: devlink: fix NIX RAS reporter recovery condition
- octeontx2-af: devlink: fix NIX RAS reporter to use RAS interrupt status
- usb: gadget: f_mass_storage: Fix potential integer overflow in
check_command_size_in_blocks()
- cgroup: fix race between task migration and iteration
- ALSA: pcm: fix use-after-free on linked stream runtime in
snd_pcm_drain()
- ALSA: usb-audio: Check endpoint numbers at parsing Scarlett2 mixer
interfaces
- net: usb: lan78xx: fix silent drop of packets with checksum errors
- net: usb: lan78xx: fix TX byte statistics for small packets
- net: usb: lan78xx: skip LTM configuration for LAN7850
- ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK PM1503CDA
- KVM: SVM: Initialize AVIC VMCB fields if AVIC is enabled with in-kernel
APIC
- USB: add QUIRK_NO_BOS for video capture several devices
- usb/core/quirks: Add Huawei ME906S-device to wakeup quirk
- USB: ezcap401 needs USB_QUIRK_NO_BOS to function on 10gbs usb speed
- usb: xhci: Fix memory leak in xhci_disable_slot()
- usb: xhci: Prevent interrupt storm on host controller error (HCE)
- usb: yurex: fix race in probe
- usb: dwc3: pci: add support for the Intel Nova Lake -H
- usb: misc: uss720: properly clean up reference in uss720_probe()
- usb: core: don't power off roothub PHYs if phy_set_mode() fails
- usb: cdc-acm: Restore CAP_BRK functionnality to CH343
- usb: roles: get usb role switch from parent only for usb-b-connector
- USB: usbcore: Introduce usb_bulk_msg_killable()
- USB: usbtmc: Use usb_bulk_msg_killable() with user-specified timeouts
- USB: core: Limit the length of unkillable synchronous timeouts
- usb: class: cdc-wdm: fix reordering issue in read code path
- usb: renesas_usbhs: fix use-after-free in ISR during device removal
- usb: mdc800: handle signal and read racing
- usb: image: mdc800: kill download URB on timeout
- mm/tracing: rss_stat: ensure curr is false from kthread context
- mmc: mmci: Fix device_node reference leak in of_get_dml_pipe_index()
- mm/kfence: disable KFENCE upon KASAN HW tags enablement
- mmc: core: Avoid bitfield RMW for claim/retune flags
- ASoC: qcom: qdsp6: Fix q6apm remove ordering during ADSP stop and start
- tipc: fix divide-by-zero in tipc_sk_filter_connect()
- kprobes: avoid crash when rmmod/insmod after ftrace killed
- libceph: reject preamble if control segment is empty
- libceph: Use u32 for non-negative values in ceph_monmap_decode()
- libceph: admit message frames only in CEPH_CON_S_OPEN state
- ceph: fix i_nlink underrun during async unlink
- ceph: fix memory leaks in ceph_mdsc_build_path()
- time/jiffies: Mark jiffies_64_to_clock_t() notrace
- i3c: dw-i3c-master: Set SIR_REJECT in DAT on device attach and reattach
- scsi: ufs: core: Fix SError in ufshcd_rtc_work() during UFS suspend
- scsi: hisi_sas: Add time interval between two H2D FIS following soft
reset spec
- scsi: hisi_sas: Use macro instead of magic number
- scsi: hisi_sas: Fix NULL pointer exception during user_scan()
- Revert "tcpm: allow looking for role_sw device in the main node"
- drm/bridge: samsung-dsim: Fix memory leak in error path
- drm/bridge: ti-sn65dsi86: Enable HPD polling if IRQ is not used
- device property: Allow secondary lookup in fwnode_get_next_child_node()
- irqchip/gic-v3-its: Limit number of per-device MSIs to the range the ITS
supports
- ice: reintroduce retry mechanism for indirect AQ
- ixgbevf: fix link setup issue
- staging: rtl8723bs: properly validate the data in rtw_get_ie_ex()
- staging: rtl8723bs: fix potential out-of-bounds read in
rtw_restruct_wmm_ie
- media: dvb-net: fix OOB access in ULE extension header tables
- net: mana: Ring doorbell at 4 CQ wraparounds
- ice: fix retry for AQ command 0x06EE
- tracing: Fix syscall events activation by ensuring refcount hits zero
- batman-adv: Avoid double-rtnl_lock ELP metric worker
- parisc: Increase initial mapping to 64 MB with KALLSYMS
- nouveau/dpcd: return EBUSY for aux xfer if the device is asleep
- arm64: mm: Add PTE_DIRTY back to PAGE_KERNEL* to fix kexec/hibernation
- hwmon: (pmbus/q54sj108a2) fix stack overflow in debugfs read
- parisc: Fix initial page table creation for boot
- parisc: Check kernel mapping earlier at bootup
- pmdomain: bcm: bcm2835-power: Fix broken reset status read
- net: ncsi: fix skb leak in error paths
- net: ethernet: arc: emac: quiesce interrupts before requesting IRQ
- net: dsa: microchip: Fix error path in PTP IRQ setup
- drm/amdgpu: Fix use-after-free race in VM acquire
- drm/amd: Set num IP blocks to 0 if discovery fails
- drm/bridge: ti-sn65dsi83: fix CHA_DSI_CLK_RANGE rounding
- drm/i915: Fix potential overflow of shmem scatterlist length
- tracing: Fix trace_buf_size= cmdline parameter with sizes >= 2G
- cifs: make default value of retrans as zero
- xfs: fix undersized l_iclog_roundoff values
- s390/dasd: Move quiesce state with pprc swap
- s390/dasd: Copy detected format information to secondary device
- lib/bootconfig: fix off-by-one in xbc_verify_tree() unclosed brace error
- scsi: core: Fix error handling for scsi_alloc_sdev()
- x86/apic: Disable x2apic on resume if the kernel expects so
- lib/bootconfig: fix snprintf truncation check in
xbc_node_compose_key_after()
- lib/bootconfig: check bounds before writing in __xbc_open_brace()
- smb: client: fix atomic open with O_DIRECT & O_SYNC
- smb: client: fix in-place encryption corruption in SMB2_write()
- smb: client: fix iface port assignment in parse_server_interfaces
- btrfs: abort transaction on failure to update root in the received
subvol ioctl
- iio: dac: ds4424: reject -128 RAW value
- iio: frequency: adf4377: Fix duplicated soft reset mask
- iio: chemical: sps30_serial: fix buffer size in sps30_serial_read_meas()
- iio: chemical: sps30_i2c: fix buffer size in sps30_i2c_read_meas()
- iio: potentiometer: mcp4131: fix double application of wiper shift
- iio: chemical: bme680: Fix measurement wait duration calculation
- iio: buffer: Fix wait_queue not being removed
- iio: gyro: mpu3050-core: fix pm_runtime error handling
- iio: gyro: mpu3050-i2c: fix pm_runtime error handling
- iio: imu: inv_icm42600: fix odr switch to the same value
- i3c: mipi-i3c-hci: Use ETIMEDOUT instead of ETIME for timeout errors
- i3c: mipi-i3c-hci: Restart DMA ring correctly after dequeue abort
- i3c: mipi-i3c-hci: Add missing TID field to no-op command descriptor
- drm/bridge: ti-sn65dsi86: Add support for DisplayPort mode with HPD
- gve: defer interrupt enabling until NAPI registration
- ksmbd: call ksmbd_vfs_kern_path_end_removing() on some error paths
- wifi: libertas: fix use-after-free in lbs_free_adapter()
- platform/x86: hp-bioscfg: Support allocations of larger data
- x86/sev: Allow IBPB-on-Entry feature for SNP guests
- gve: fix incorrect buffer cleanup in gve_tx_clean_pending_packets for
QPL
- net: phy: register phy led_triggers during probe to avoid AB-BA deadlock
- drm/amd/display: Use GFP_ATOMIC in dc_create_stream_for_sink
- mptcp: pm: avoid sending RM_ADDR over same subflow
- mptcp: pm: in-kernel: always mark signal+subflow endp as used
- selftests: mptcp: add a check for 'add_addr_accepted'
- selftests: mptcp: join: check RM_ADDR not sent over same subflow
- kbuild: Leave objtool binary around with 'make clean'
- net/sched: act_gate: snapshot parameters with RCU on replace
- can: gs_usb: gs_can_open(): always configure bitrates before starting
device
- usb: gadget: f_tcm: Fix NULL pointer dereferences in nexus handling
- KVM: SVM: Limit AVIC physical max index based on configured max_vcpu_ids
- KVM: SVM: Add a helper to look up the max physical ID for AVIC
- KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated
- mm/kfence: fix KASAN hardware tag faults during late enablement
- iomap: reject delalloc mappings during writeback
- ksmbd: Don't log keys in SMB3 signing and encryption key generation
- drm/msm: Fix dma_free_attrs() buffer size
- drm/bridge: ti-sn65dsi83: halve horizontal syncs for dual LVDS output
- net: macb: Shuffle the tx ring before enabling tx
- cifs: open files should not hold ref on superblock
- crypto: atmel-sha204a - Fix OOM ->tfm_count leak
- xfs: fix integer overflow in bmap intent sort comparator
- xfs: ensure dquot item is deleted from AIL only after log shutdown
- smb: client: Compare MACs in constant time
- ksmbd: Compare MACs in constant time
- f2fs: fix to avoid migrating empty section
- ext4: fix dirtyclusters double decrement on fs shutdown
- btrfs: always fallback to buffered write if the inode requires checksum
- net: stmmac: dwmac-loongson: Set clk_csr_i to 100-150MHz
- arm64: mm: Don't remap pgtables per-cont(pte|pmd) block
- arm64: mm: Batch dsb and isb when populating pgtables
- arm64: mm: Don't remap pgtables for allocate vs populate
- dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list()
- ext4: always allocate blocks only from groups inode can use
- rxrpc: Fix recvmsg() unconditional requeue
- dm-verity: disable recursive forward error correction
- ipv6: use RCU in ip6_xmit()
- rxrpc: Fix data-race warning and potential load/store tearing
- btrfs: do not strictly require dirty metadata threshold for metadata
writepages
- riscv: Sanitize syscall table indexing under speculation
- dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()
- tracing: Add recursion protection in kernel stack trace recording
- net: add support for segmenting TCP fraglist GSO packets
- net: gso: fix tcp fraglist segmentation after pull from frag_list
- net: fix segmentation of forwarding fraglist GRO
- net: dsa: properly keep track of conduit reference
- drm/amd/display: Add pixel_clock to amd_pp_display_configuration
- drm/amd/pm: Use pm_display_cfg in legacy DPM (v2)
- drm/amdgpu: Add basic validation for RAS header
- drm/exynos: vidi: use priv->vidi_dev for ctx lookup in
vidi_connection_ioctl()
- drm/exynos: vidi: fix to avoid directly dereferencing user pointer
- drm/exynos: vidi: use ctx->lock to protect struct vidi_context member
variables related to memory alloc/free
- x86/uprobes: Fix XOL allocation failure for 32-bit tasks
- platform/x86/amd/pmc: Add support for Van Gogh SoC
- binfmt_misc: restore write access before closing files opened by
open_exec()
- net: stmmac: remove support for lpi_intr_o
- mptcp: pm: in-kernel: always set ID as avail when rm endp
- s390/xor: Fix xor_xc_2() inline assembly constraints
- s390/stackleak: Fix __stackleak_poison() inline assembly constraint
- s390/zcrypt: Enable AUTOSEL_DOM for CCA serialnr sysfs attribute
- mm/mempolicy: fix wrong mmap_read_unlock() in migrate_to_node()
- io_uring/kbuf: check if target buffer list is still legacy on recycle
- NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd
- sunrpc: fix cache_request leak in cache_release
- nvdimm/bus: Fix potential use after free in asynchronous initialization
- LoongArch: Give more information if kmem access failed
- NFC: nxp-nci: allow GPIOs to sleep
- net: macb: fix use-after-free access to PTP clock
- parisc: Flush correct cache in cacheflush() syscall
- Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp()
- Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access
- smb: client: fix krb5 mount with username option
- ksmbd: unset conn->binding on failed binding request
- kprobes: Remove unneeded goto
- kprobes: Remove unneeded warnings from __arm_kprobe_ftrace()
- btrfs: fix transaction abort when snapshotting received subvolumes
- btrfs: fix transaction abort on set received ioctl due to item overflow
- btrfs: fix transaction abort on file creation due to name hash collision
- iio: light: bh1780: fix PM runtime leak on error path
- batman-adv: avoid OGM aggregation when skb tailroom is insufficient
- net: macb: queue tie-off or disable during WOL suspend
- net: macb: Introduce gem_init_rx_ring()
- net: macb: Reinitialize tx/rx queue pointer registers and rx ring during
resume
- mmc: sdhci-pci-gli: fix GL9750 DMA write corruption
- mmc: sdhci: fix timing selection for 1-bit bus width
- pmdomain: bcm: bcm2835-power: Increase ASB control timeout
- spi: fix use-after-free on controller registration failure
- spi: fix statistics allocation
- mtd: rawnand: pl353: make sure optimal timings are applied
- mtd: rawnand: cadence: Fix error check for dma_alloc_coherent() in
cadence_nand_init()
- mtd: Avoid boot crash in RedBoot partition table parser
- iommu/vt-d: Fix intel iommu iotlb sync hardlockup and retry
- serial: 8250_pci: add support for the AX99100
- serial: 8250: Fix TX deadlock when using DMA
- serial: 8250: Add late synchronize_irq() to shutdown to handle DW UART
BUSY
- serial: uartlite: fix PM runtime usage count underflow on probe
- drm/amdgpu/gmc9.0: add bounds checking for cid
- drm/amdgpu/mmhub2.0: add bounds checking for cid
- drm/amdgpu/mmhub2.3: add bounds checking for cid
- drm/amdgpu/mmhub3.0.1: add bounds checking for cid
- drm/amdgpu/mmhub3.0.2: add bounds checking for cid
- drm/amdgpu/mmhub3.0: add bounds checking for cid
- drm/radeon: apply state adjust rules to some additional HAINAN vairants
- drm/amdgpu: apply state adjust rules to some additional HAINAN vairants
- drm/amd/display: Wrap dcn32_override_min_req_memclk() in DC_FP_{START,
END}
- btrfs: log new dentries when logging parent dir of a conflicting inode
- btrfs: tree-checker: fix misleading root drop_level error message
- cache: ax45mp: Fix device node reference leak in ax45mp_cache_init()
- soc: fsl: qbman: fix race condition in qman_destroy_fq
- wifi: mac80211: Fix static_branch_dec() underflow for aql_disable.
- wifi: cfg80211: cancel pmsr_free_wk in cfg80211_pmsr_wdev_down
- firmware: arm_scpi: Fix device_node reference leak in probe path
- Bluetooth: LE L2CAP: Disconnect if received packet's SDU exceeds IMTU
- Bluetooth: LE L2CAP: Disconnect if sum of payload sizes exceed SDU
- Bluetooth: SMP: make SM/PER/KDU/BI-04-C happy
- Bluetooth: ISO: Fix defer tests being unstable
- Bluetooth: hci_sync: Fix hci_le_create_conn_sync
- Bluetooth: HIDP: Fix possible UAF
- Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user
- Bluetooth: qca: fix ROM version reading on WCN3998 chips
- net/rose: fix NULL pointer dereference in rose_transmit_link on
reconnect
- mpls: add missing unregister_netdevice_notifier to mpls_init
- netfilter: ctnetlink: remove refcounting in expectation dumpers
- netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct()
- netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in
sip_help_tcp()
- netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case
- netfilter: nft_ct: drop pending enqueued packets on removal
- netfilter: xt_CT: drop pending enqueued packets on template removal
- netfilter: xt_time: use unsigned int for monthday bit shift
- net: bcmgenet: increase WoL poll timeout
- net: mana: fix use-after-free in mana_hwc_destroy_channel() by
reordering teardown
- sched: idle: Consolidate the handling of two special cases
- PM: runtime: Fix a race condition related to device removal
- net/sched: teql: Fix double-free in teql_master_xmit
- net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check
- net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check
- clsact: Fix use-after-free in init/destroy rollback asymmetry
- net: usb: aqc111: Do not perform PM inside suspend callback
- igc: fix missing update of skb->tail in igc_xmit_frame()
- iavf: fix VLAN filter lost on add/delete race
- wifi: mac80211: fix NULL deref in mesh_matches_local()
- wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough
headroom
- ACPI: processor: Fix previous acpi_processor_errata_piix4() fix
- net: macb: fix uninitialized rx_fs_lock
- net/mlx5: qos: Restrict RTNL area to avoid a lock cycle
- net/mlx5e: Prevent concurrent access to IPSec ASO context
- net/mlx5e: Fix race condition during IPSec ESN update
- udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n
- net: bonding: fix NULL deref in bond_debug_rlb_hash_show
- netfilter: bpf: defer hook memory release until rcu readers are done
- nfnetlink_osf: validate individual option lengths in fingerprints
- net: mvpp2: guard flow control update with global_tx_fc in buffer
switching
- net: dsa: bcm_sf2: fix missing clk_disable_unprepare() in error paths
- icmp: fix NULL pointer dereference in icmp_tag_validation()
- hwmon: (pmbus/mp2975) Add error check for pmbus_read_word_data() return
value
- hwmon: (pmbus/isl68137) Fix unchecked return value and use sysfs_emit()
- Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ
- USB: serial: f81232: fix incomplete serial port generation
- i2c: fsi: Fix a potential leak in fsi_i2c_probe()
- i2c: pxa: defer reset on Armada 3700 when recovery is used
- x86/platform/uv: Handle deconfigured sockets
- i2c: cp2615: fix serial string NULL-deref at probe
- mtd: rawnand: serialize lock/unlock against other NAND operations
- mtd: rawnand: brcmnand: skip DMA during panic write
- drm/amd/display: Fix DisplayID not-found handling in
parse_edid_displayid_vrr()
- drm/i915/gt: Check set_default_submission() before deferencing
- lib/bootconfig: check xbc_init_node() return in override path
- tools/bootconfig: fix fd leak in load_xbc_file() on fstat failure
- xen/privcmd: restrict usage in unprivileged domU
- xen/privcmd: add boot control for restricted usage in domU
- cgroup/cpuset: Fix incorrect use of cpuset_update_tasks_cpumask() in
update_cpumasks_hier()
- s390/idle: Fix cpu idle exit cpu time accounting
- s390/vtime: Fix virtual timer forwarding
- PCI: endpoint: Introduce pci_epc_function_is_valid()
- PCI: endpoint: Introduce pci_epc_mem_map()/unmap()
- PCI: dwc: endpoint: Implement the pci_epc_ops::align_addr() operation
- PCI: dwc: ep: Use align addr function for
dw_pcie_ep_raise_{msi,msix}_irq()
- PCI: dwc: ep: Flush MSI-X write before unmapping its ATU entry
- drm/amdgpu: Replace kzalloc + copy_from_user with memdup_user
- drm/amdgpu: Fix locking bugs in error paths
- btrfs: print correct subvol num if active swapfile prevents deletion
- bpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic
tearing
- x86/acpi/boot: Correct acpi_is_processor_usable() check again
- PCI: dw-rockchip: Don't wait for link since we can detect Link Up
- Revert "PCI: dw-rockchip: Don't wait for link since we can detect Link
Up"
- ata: libata-scsi: Refactor ata_scsi_simulate()
- ata: libata-scsi: Refactor ata_scsiop_read_cap()
- ata: libata-scsi: Refactor ata_scsiop_maint_in()
- ata: libata-scsi: Document all VPD page inquiry actors
- ata: libata-scsi: Remove struct ata_scsi_args
- ata: libata: Remove ATA_DFLAG_ZAC device flag
- ata: libata: Introduce ata_port_eh_scheduled()
- ata: libata-scsi: avoid Non-NCQ command starvation
- workqueue: Add system_percpu_wq and system_dfl_wq
- Input: synaptics_i2c - replace use of system_wq with system_dfl_wq
- Input: synaptics_i2c - guard polling restart in resume
- arm64: dts: rockchip: Fix rk3588 PCIe range mappings
- ima: kexec: silence RCU list traversal warning
- ima: rename variable the seq_file "file" to "ima_kexec_file"
- ima: define and call ima_alloc_kexec_file_buf()
- kexec: define functions to map and unmap segments
- ima: kexec: define functions to copy IMA log at soft boot
- ima: verify the previous kernel's IMA buffer lies in addressable RAM
- of/kexec: refactor ima_get_kexec_buffer() to use ima_validate_range()
- drm/exynos/vidi: Remove redundant error handling in vidi_get_modes()
- btrfs: zoned: fix alloc_offset calculation for partly conventional block
groups
- btrfs: zoned: fixup last alloc pointer after extent removal for RAID1
- btrfs: zoned: fixup last alloc pointer after extent removal for DUP
- btrfs: zoned: fix stripe width calculation
- btrfs: define the AUTO_KFREE/AUTO_KVFREE helper macros
- btrfs: zoned: fixup last alloc pointer after extent removal for RAID0/10
- ksmbd: check return value of xa_store() in krb5_authenticate
- ksmbd: add chann_lock to protect ksmbd_chann_list xarray
- ALSA: hda/realtek: Add quirk for Gigabyte G5 KF5 (2023)
- ALSA: hda/realtek: Implement sound init sequence for Samsung Galaxy
Book3 Pro 360
- ALSA: hda/realtek: Fix the speaker output on Samsung Galaxy Book3 Ultra
- ALSA: hda/realtek: Refactor and simplify Samsung Galaxy Book init
- ALSA: hda/realtek: Add quirk for Samsung Galaxy Book3 Pro 360 (NP965QFG)
- ACPI: APEI: GHES: Disable KASAN instrumentation when compile testing
with clang < 18
- nvme: fix admin queue leak on controller reset
- HID: multitouch: add quirks for Lenovo Yoga Book 9i
- HID: multitouch: new class MT_CLS_EGALAX_P80H84
- idpf: change IRQ naming to match netdev and ethtool queue numbering
- i40e: Fix preempt count leak in napi poll tracepoint
- drm/xe: Do not preempt fence signaling CS instructions
- wifi: mt76: mt7925: Fix possible oob access in
mt7925_mac_write_txwi_80211()
- i2c: i801: Revert "i2c: i801: replace acpi_lock with I2C bus lock"
- drm/xe/reg_sr: Fix leak on xa_store failure
- net_sched: sch_fq: clear q->band_pkt_count[] in fq_reset()
- ata: libata-core: fix cancellation of a port deferred qc work
- ata: libata-eh: correctly handle deferred qc timeouts
- ata: libata: cancel pending work after clearing deferred_qc
- ata: libata-eh: Fix detection of deferred qc timeouts
- Upstream stable to v6.6.129, v6.6.130, v6.12.76, v6.12.77
* Noble update: upstream stable patchset 2026-05-28 (LP: #2154496) //
CVE-2026-43067
- ext4: handle wraparound when searching for blocks for indirect mapped
blocks
* Noble update: upstream stable patchset 2026-05-28 (LP: #2154496) //
CVE-2025-39930
- ASoC: simple-card-utils: Don't use __free(device_node) at
graph_util_parse_dai()
* CVE-2026-46244
- netfilter: nft_inner: Fix IPv6 inner_thoff desync
* CVE-2026-43185
- ksmbd: fix signededness bug in smb_direct_prepare_negotiation()
* CVE-2026-46289
- lib/scatterlist: fix length calculations in extract_kvec_to_sg
* CVE-2026-46119
- libceph: Fix slab-out-of-bounds access in auth message processing
* CVE-2026-46135
- nvmet-tcp: fix race between ICReq handling and queue teardown
* CVE-2026-46185
- smb/client: fix out-of-bounds read in symlink_data()
* CVE-2026-46195
- smb: client: validate dacloffset before building DACL pointers
* CVE-2026-46115
- block: add pgmap check to biovec_phys_mergeable
* CVE-2026-43501
- ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
* CVE-2026-45988
- rxrpc: Fix re-decryption of RESPONSE packets
* CVE-2026-46043
- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
* CVE-2026-43493
- crypto: pcrypt - Fix handling of MAY_BACKLOG requests
* CVE-2026-43071
- dcache: Limit the minimal number of bucket to two
* CVE-2026-31685
- netfilter: ip6t_eui64: reject invalid MAC header for all packets
* CVE-2026-43117
- btrfs: tracepoints: get correct superblock from dentry in event
btrfs_sync_file()
* CVE-2026-43114
- netfilter: nft_set_pipapo_avx2: don't return non-matching entry on
expiry
* CVE-2026-31607
- usbip: validate number_of_packets in usbip_pack_ret_submit()
* CVE-2026-31659
- batman-adv: reject oversized global TT response buffers
* CVE-2026-31649
- net: stmmac: fix integer underflow in chain mode
* CVE-2026-31657
- batman-adv: hold claim backbone gateways by reference
* CVE-2026-31637
- rxrpc: reject undecryptable rxkad response tickets
* CVE-2026-31669
- mptcp: fix slab-use-after-free in __inet_lookup_established
* CVE-2026-31668
- seg6: separate dst_cache for input and output paths in seg6 lwtunnel
* CVE-2026-43011
- net/x25: Fix potential double free of skb
* CVE-2026-43037
- ip6_tunnel: clear skb2->cb[] in ip4ip6_err()
* CVE-2026-43341
- net/ipv6: ioam6: prevent schema length wraparound in trace fill
* CVE-2026-43038
- ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
* CVE-2026-31682
- bridge: br_nd_send: linearize skb before parsing ND options
* CVE-2026-31436
- dmaengine: idxd: fix possible wrong descriptor completion in
llist_abort_desc()
* CVE-2026-43384
- net/tcp-ao: Fix MAC comparison to be constant-time
* CVE-2026-31448
- ext4: get rid of ppath in ext4_find_extent()
- ext4: get rid of ppath in ext4_ext_create_new_leaf()
- ext4: get rid of ppath in ext4_ext_insert_extent()
- ext4: avoid infinite loops caused by residual data
* CVE-2026-31478
- ksmbd: replace hardcoded hdr2_len with offsetof() in
smb2_calc_max_out_buf_len()
* CVE-2026-23428
- ksmbd: fix use-after-free of share_conf in compound request
* CVE-2026-23450
- net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock()
* CVE-2026-23455
- netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()
* CVE-2026-31402
- nfsd: fix heap overflow in NFSv4.0 LOCK replay cache
* CVE-2026-43383
- net/tcp-md5: Fix MAC comparison to be constant-time
* CVE-2026-43378
- smb: server: fix use-after-free in smb2_open()
* CVE-2026-46243
- smb: client: reject userspace cifs.spnego descriptions
* CVE-2026-43414
- scsi: qla2xxx: Completely fix fcport double free
* CVE-2026-43407
- libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply()
* CVE-2026-43406
- libceph: prevent potential out-of-bounds reads in
process_message_header()
-- Edoardo Canepa <edoardo.canepa@canonical.com> Fri, 03 Jul 2026 12:54:09 +0200
linux-hwe-6.8 (6.8.0-134.134~22.04.1) jammy; urgency=medium
* jammy/linux-hwe-6.8: 6.8.0-134.134~22.04.1 -proposed tracker (LP: #2158430)
[ Ubuntu: 6.8.0-134.134 ]
* noble/linux: 6.8.0-134.134 -proposed tracker (LP: #2158432)
* ext4: writeback causes kernel oops when low on space (LP: #2158377)
- ext4: get rid of ppath in get_ext_path()
-- Alessio Faina <alessio.faina@canonical.com> Mon, 29 Jun 2026 16:10:30 +0200
linux-hwe-6.8 (6.8.0-131.131~22.04.1) jammy; urgency=medium
* jammy/linux-hwe-6.8: 6.8.0-131.131~22.04.1 -proposed tracker (LP: #2157194)
[ Ubuntu: 6.8.0-131.131 ]
* noble/linux: 6.8.0-131.131 -proposed tracker (LP: #2157196)
* Packaging resync (LP: #1786013)
- [Packaging] update annotations scripts
* CVE-2026-46244
- netfilter: nft_inner: Fix IPv6 inner_thoff desync
* CVE-2026-43185
- ksmbd: fix signededness bug in smb_direct_prepare_negotiation()
* CVE-2026-46289
- lib/scatterlist: fix length calculations in extract_kvec_to_sg
* CVE-2026-46119
- libceph: Fix slab-out-of-bounds access in auth message processing
* CVE-2026-46135
- nvmet-tcp: fix race between ICReq handling and queue teardown
* CVE-2026-46185
- smb/client: fix out-of-bounds read in symlink_data()
* CVE-2026-46195
- smb: client: validate dacloffset before building DACL pointers
* CVE-2026-46115
- block: add pgmap check to biovec_phys_mergeable
* CVE-2026-43501
- ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
* CVE-2026-45988
- rxrpc: Fix re-decryption of RESPONSE packets
* CVE-2026-46043
- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
* CVE-2026-43493
- crypto: pcrypt - Fix handling of MAY_BACKLOG requests
* CVE-2026-43071
- dcache: Limit the minimal number of bucket to two
* CVE-2026-31685
- netfilter: ip6t_eui64: reject invalid MAC header for all packets
* CVE-2026-43117
- btrfs: tracepoints: get correct superblock from dentry in event
btrfs_sync_file()
* CVE-2026-43114
- netfilter: nft_set_pipapo_avx2: don't return non-matching entry on
expiry
* CVE-2026-31607
- usbip: validate number_of_packets in usbip_pack_ret_submit()
* CVE-2026-31659
- batman-adv: reject oversized global TT response buffers
* CVE-2026-31649
- net: stmmac: fix integer underflow in chain mode
* CVE-2026-31657
- batman-adv: hold claim backbone gateways by reference
* CVE-2026-31637
- rxrpc: reject undecryptable rxkad response tickets
* CVE-2026-31669
- mptcp: fix slab-use-after-free in __inet_lookup_established
* CVE-2026-31668
- seg6: separate dst_cache for input and output paths in seg6 lwtunnel
* CVE-2026-43011
- net/x25: Fix potential double free of skb
* CVE-2026-43037
- ip6_tunnel: clear skb2->cb[] in ip4ip6_err()
* CVE-2026-43341
- net/ipv6: ioam6: prevent schema length wraparound in trace fill
* CVE-2026-43038
- ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
* CVE-2026-31682
- bridge: br_nd_send: linearize skb before parsing ND options
* CVE-2026-31436
- dmaengine: idxd: fix possible wrong descriptor completion in
llist_abort_desc()
* CVE-2026-43384
- net/tcp-ao: Fix MAC comparison to be constant-time
* CVE-2026-31448
- ext4: get rid of ppath in ext4_find_extent()
- ext4: get rid of ppath in ext4_ext_create_new_leaf()
- ext4: get rid of ppath in ext4_ext_insert_extent()
- ext4: avoid infinite loops caused by residual data
* CVE-2026-31478
- ksmbd: replace hardcoded hdr2_len with offsetof() in
smb2_calc_max_out_buf_len()
* CVE-2026-23428
- ksmbd: fix use-after-free of share_conf in compound request
* CVE-2026-23450
- net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock()
* CVE-2026-23455
- netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()
* CVE-2026-31402
- nfsd: fix heap overflow in NFSv4.0 LOCK replay cache
* CVE-2026-43383
- net/tcp-md5: Fix MAC comparison to be constant-time
* CVE-2026-43378
- smb: server: fix use-after-free in smb2_open()
* CVE-2026-46243
- smb: client: reject userspace cifs.spnego descriptions
* CVE-2026-43414
- scsi: qla2xxx: Completely fix fcport double free
* CVE-2026-43407
- libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply()
* CVE-2026-43406
- libceph: prevent potential out-of-bounds reads in
process_message_header()
-- Manuel Diewald <manuel.diewald@canonical.com> Tue, 23 Jun 2026 12:24:25 +0200
linux-hwe-6.8 (6.8.0-130.130~22.04.1) jammy; urgency=medium
* jammy/linux-hwe-6.8: 6.8.0-130.130~22.04.1 -proposed tracker (LP: #2151947)
[ Ubuntu: 6.8.0-130.130 ]
* noble/linux: 6.8.0-130.130 -proposed tracker (LP: #2154560)
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465)
- Revert "UBUNTU: SAUCE: Fix skb_vlan_inet_prepare() usage"
* Kernel regression (6.8.0-117.generic) (LP: #2153556)
- net: bonding: update the slave array for broadcast mode
- bonding: do not set usable_slaves for broadcast mode
* perf_cpu_map__merge fails to compile on ppc46el, s390x on noble linux
(LP: #2152194)
- SAUCE: temporary fix attempt for size eceed
* Some powerpc test from ubuntu_kernel_selftests timeout with 45 seconds
(LP: #2141536)
- selftests/powerpc: Lower run time of count_stcx_fail test
- selftests/powerpc: Give all tests 2 minutes timeout
* Noble update: upstream stable patchset 2026-05-01 (LP: #2150809)
- auxdisplay: arm-charlcd: fix release_mem_region() size
- hfsplus: return error when node already exists in hfs_bnode_create
- rcu: s/boost_kthread_mutex/kthread_mutex
- rcu/exp: Move expedited kthread worker creation functions above
rcutree_prepare_cpu()
- rcu: Refactor expedited handling check in rcu_read_unlock_special()
- rcu: Remove local_irq_save/restore() in
rcu_preempt_deferred_qs_handler()
- rcu: Fix rcu_read_unlock() deadloop due to softirq
- audit: move the compat_xxx_class[] extern declarations to audit_arch.h
- i3c: Move device name assignment after i3c_bus_init
- fs: add <linux/init_task.h> for 'init_fs'
- i3c: master: Update hot-join flag only on success
- gfs2: Retries missing in gfs2_{rename,exchange}
- gfs2: Fix use-after-free in iomap inline data write path
- i3c: dw: Initialize spinlock to avoid upsetting lockdep
- tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure
- tpm: st33zp24: Fix missing cleanup on get_burstcount() error
- btrfs: qgroup: return correct error when deleting qgroup relation item
- btrfs: fix block_group_tree dirty_list corruption
- smb: client: fix potential UAF and double free in smb2_open_file()
- xen/virtio: Don't use grant-dma-ops when running as Dom0
- ACPICA: Fix NULL pointer dereference in acpi_ev_address_space_dispatch()
- io_uring/sync: validate passed in offset
- cpuidle: menu: Cleanup after loadavg removal
- cpuidle: governors: menu: Always check timers with tick stopped
- md/raid10: fix any_working flag handling in raid10_sync_request
- iomap: fix submission side handling of completion side errors
- ublk: Validate SQE128 flag before accessing the cmd
- x86/xen: make some functions static
- Partial revert "x86/xen: fix balloon target initialization for PVH dom0"
- PM: wakeup: Handle empty list in wakeup_sources_walk_start()
- perf: arm_spe: Properly set hw.state on failures
- PM: sleep: wakeirq: harden dev_pm_clear_wake_irq() against races
- s390/cio: Fix device lifecycle handling in css_alloc_subchannel()
- crypto: qat - fix warning on adf_pfvf_pf_proto.c
- selftests/bpf: veristat: fix printing order in output_stats()
- libbpf: Fix OOB read in btf_dump_get_bitfield_value
- ARM: VDSO: Patch out __vdso_clock_getres() if unavailable
- crypto: cavium - fix dma_free_coherent() size
- crypto: octeontx - fix dma_free_coherent() size
- crypto: hisilicon/zip - adjust the way to obtain the req in the callback
function
- crypto: hisilicon/sec2 - support skcipher/aead fallback for hardware
queue unavailable
- hrtimer: Fix trace oddity
- bpf, sockmap: Fix incorrect copied_seq calculation
- bpf, sockmap: Fix FIONREAD for sockmap
- crypto: hisilicon/trng - modifying the order of header files
- crypto: hisilicon/trng - support tfms sharing the device
- bpf: Fix bpf_xdp_store_bytes proto for read-only arg
- scsi: efct: Use IRQF_ONESHOT and default primary handler
- EDAC/altera: Remove IRQF_ONESHOT
- mfd: wm8350-core: Use IRQF_ONESHOT
- sched/rt: Skip currently executing CPU in rto_next_cpu()
- pstore/ram: fix buffer overflow in persistent_ram_save_old()
- soc: qcom: smem: handle ENOMEM error during probe
- EDAC/i5000: Fix snprintf() size calculation in calculate_dimm_size()
- EDAC/i5400: Fix snprintf() limit calculation in calculate_dimm_size()
- arm64: dts: tqma8mpql-mba8mpxl: Fix HDMI CEC pad control settings
- clk: qcom: Return correct error code in qcom_cc_probe_by_index()
- arm64: dts: qcom: sdm630: fix gpu_speed_bin size
- arm64: dts: qcom: sdm845-oneplus: Don't mark ts supply boot-on
- ARM: dts: allwinner: sun5i-a13-utoo-p66: delete "power-gpios" property
- powerpc/uaccess: Move barrier_nospec() out of
allow_read_{from/write}_user()
- soc: qcom: cmd-db: Use devm_memremap() to fix memory leak in
cmd_db_dev_probe
- soc: mediatek: svs: Fix memory leak in svs_enable_debug_write()
- powerpc/eeh: fix recursive pci_lock_rescan_remove locking in EEH event
handling
- ARM: dts: lpc32xx: Set motor PWM #pwm-cells property value to 3 cells
- arm: dts: lpc32xx: add clocks property to Motor Control PWM device tree
node
- arm64: dts: amlogic: axg: assign the MMC signal clocks
- arm64: dts: amlogic: gx: assign the MMC signal clocks
- arm64: dts: amlogic: g12: assign the MMC B and C signal clocks
- arm64: dts: amlogic: g12: assign the MMC A signal clock
- arm64: dts: qcom: sdm845-db845c: drop CS from SPIO0
- arm64: dts: qcom: sdm845-db845c: specify power for WiFi CH1
- arm64: dts: qcom: sm6115: Add CX_MEM/DBGC GPU regions
- workqueue: Factor out assign_rescuer_work()
- workqueue: Only assign rescuer work when really needed
- workqueue: Process rescuer work items one-by-one using a cursor
- smack: /smack/doi must be > 0
- smack: /smack/doi: accept previously used values
- ASoC: nau8821: Consistently clear interrupts before unmasking
- ASoC: nau8821: Avoid unnecessary blocking in IRQ handler
- ASoC: nau8821: Fixup nau8821_enable_jack_detect()
- drm/amdgpu: Use explicit VCN instance 0 in SR-IOV init
- drm/msm/disp/dpu: add merge3d support for sc7280
- regulator: core: move supply check earlier in set_machine_constraints()
- HID: playstation: Add missing check for input_ff_create_memless
- drm/msm/dpu: fix CMD panels on DPU 1.x - 3.x
- media: ccs: Accommodate C-PHY into the calculation
- drm/msm/a2xx: fix pixel shader start on A225
- platform/chrome: cros_typec_switch: Don't touch struct
fwnode_handle::dev
- media: uvcvideo: Fix allocation for small frame sizes
- platform/chrome: cros_ec_lightbar: Fix response size initialization
- spi: tools: Add include folder to .gitignore
- Revert "hwmon: (ibmpex) fix use-after-free in high/low store"
- PCI: mediatek: Fix IRQ domain leak when MSI allocation fails
- Documentation: PCI: endpoint: Fix ntb/vntb copy & paste errors
- PCI/PM: Avoid redundant delays on D3hot->D3cold
- PCI/P2PDMA: Release per-CPU pgmap ref when vm_insert_page() fails
- Documentation: tracing: Add ring-buffer mapping
- docs: fix WARNING document not included in any toctree
- Documentation: trace: Refactor toctree
- Documentation: tracing: Add PCI tracepoint documentation
- PCI: Do not attempt to set ExtTag for VFs
- PCI/portdrv: Fix potential resource leak
- quota: fix livelock between quotactl and freeze_super
- net: mctp-i2c: fix duplicate reception of old data
- mctp i2c: initialise event handler read bytes
- wifi: cfg80211: stop NAN and P2P in cfg80211_leave
- netfilter: nf_tables: reset table validation state on abort
- netfilter: nf_conncount: make nf_conncount_gc_list() to disable BH
- netfilter: nf_conncount: increase the connection clean up limit to 64
- netfilter: nft_compat: add more restrictions on netlink attributes
- netfilter: nf_conncount: fix tracking of connections from localhost
- module: add helper function for reading module_buildid()
- kallsyms/ftrace: set module buildid in ftrace_mod_address_lookup()
- PCI: Mark 3ware-9650SA Root Port Extended Tags as broken
- iommu/vt-d: Flush cache for PASID table before using it
- dm: use bio_clone_blkg_association
- nfsd: never defer requests during idmap lookup
- fat: avoid parent link count underflow in rmdir
- tcp: tcp_tx_timestamp() must look at the rtx queue
- wifi: ath10k: sdio: add missing lock protection in
ath10k_sdio_fw_crashed_dump()
- PCI: Initialize RCB from pci_configure_device()
- PCI: Add PCIE_MSG_CODE_ASSERT_INTx message macros
- PCI: Add defines for bridge window indexing
- PCI/ACPI: Restrict program_hpx_type2() to AER bits
- ipc: don't audit capability check in ipc_permissions()
- ucount: check for CAP_SYS_RESOURCE using ns_capable_noaudit()
- of: unittest: fix possible null-pointer dereferences in
of_unittest_property_copy()
- mptcp: fix receive space timestamp initialization
- octeontx2-af: Fix PF driver crash with kexec kernel booting
- bonding: only set speed/duplex to unknown, if getting speed failed
- inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP
- nfc: hci: shdlc: Stop timers and work before freeing context
- netfilter: nft_set_hash: fix get operation on big endian
- netfilter: nft_counter: fix reset of counters on 32bit archs
- netfilter: nft_set_rbtree: check for partial overlaps in anonymous sets
- PCI: Add ACS quirk for Pericom PI7C9X2G404 switches [12d8:b404]
- net: hns3: fix double free issue for tx spare buffer
- procfs: fix missing RCU protection when reading real_parent in
do_task_stat()
- smb: client: correct value for smbd_max_fragmented_recv_size
- net: sunhme: Fix sbus regression
- net: Add skb_dstref_steal and skb_dstref_restore
- net: Switch to skb_dstref_steal/skb_dstref_restore for ip_route_input
callers
- xfrm: fix ip_rt_bug race in icmp_route_lookup reverse path
- serial: caif: fix use-after-free in caif_serial ldisc_close()
- octeon_ep: disable per ring interrupts
- octeon_ep: ensure dbell BADDR updation
- ionic: Rate limit unknown xcvr type messages
- octeontx2-pf: Unregister devlink on probe failure
- RDMA/rtrs: server: remove dead code
- IB/cache: update gid cache on client reregister event
- RDMA/hns: Fix WQ_MEM_RECLAIM warning
- RDMA/hns: Notify ULP of remaining soft-WCs during reset
- power: supply: ab8500: Fix use-after-free in power_supply_changed()
- power: supply: act8945a: Fix use-after-free in power_supply_changed()
- power: supply: bq256xx: Fix use-after-free in power_supply_changed()
- power: supply: bq25980: Fix use-after-free in power_supply_changed()
- power: supply: cpcap-battery: Fix use-after-free in
power_supply_changed()
- power: supply: goldfish: Fix use-after-free in power_supply_changed()
- power: supply: rt9455: Fix use-after-free in power_supply_changed()
- power: supply: sbs-battery: Fix use-after-free in power_supply_changed()
- power: reset: nvmem-reboot-mode: respect cell size for nvmem_cell_write
- power: supply: bq27xxx: fix wrong errno when bus ops are unsupported
- power: supply: wm97xx: Fix NULL pointer dereference in
power_supply_changed()
- RDMA/rtrs-srv: fix SG mapping
- RDMA/rxe: Fix double free in rxe_srq_from_init
- tools/power/x86/intel-speed-select: Fix file descriptor leak in
isolate_cpus()
- mtd: rawnand: cadence: Fix return type of CDMA send-and-wait helper
- crypto: ccp - Add an S4 restore flow
- crypto: ccp - Factor out ring destroy handling to a helper
- crypto: ccp - Send PSP_CMD_TEE_RING_DESTROY when PSP_CMD_TEE_RING_INIT
fails
- mtd: parsers: Fix memory leak in mtd_parser_tplink_safeloader_parse()
- RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send
- RDMA/rxe: Fix race condition in QP timer handlers
- svcrdma: Increase the per-transport rw_ctx count
- svcrdma: Reduce the number of rdma_rw contexts per-QP
- RDMA/core: add rdma_rw_max_sge() helper for SQ sizing
- cxl: Fix premature commit_end increment on decoder commit failure
- mtd: parsers: ofpart: fix OF node refcount leak in
parse_fixed_partitions()
- mtd: spinand: Fix kernel doc
- power: supply: qcom_battmgr: Recognize "LiP" as lithium-polymer
- RDMA/uverbs: Add __GFP_NOWARN to ib_uverbs_unmarshall_recv() kmalloc
- pNFS: fix a missing wake up while waiting on NFS_LAYOUT_DRAIN
- scsi: smartpqi: Fix memory leak in pqi_report_phys_luns()
- scsi: ufs: host: mediatek: Require CONFIG_PM
- scsi: csiostor: Fix dereference of null pointer rn
- nvdimm: virtio_pmem: serialize flush requests
- fs/nfs: Fix readdir slow-start regression
- tracing: Properly process error handling in event_hist_trigger_parse()
- tracing: Remove duplicate ENABLE_EVENT_STR and DISABLE_EVENT_STR macros
- fbdev: of_display_timing: Fix device node reference leak in
of_get_display_timings()
- fbdev: au1200fb: Fix a memory leak in au1200fb_drv_probe()
- clk: qcom: gcc-sm8550: Use floor ops for SDCC RCGs
- clk: qcom: rcg2: compute 2d using duty fraction directly
- clk: meson: gxbb: Limit the HDMI PLL OD to /4 on GXL/GXM SoCs
- clk: qcom: gcc-sm8450: Update the SDCC RCGs to use shared_floor_ops
- clk: qcom: gcc-sdx75: Update the SDCC RCGs to use shared_floor_ops
- clk: qcom: gcc-qdu1000: Update the SDCC RCGs to use shared_floor_ops
- clk: qcom: gcc-msm8953: Remove ALWAYS_ON flag from cpp_gdsc
- clk: qcom: gcc-msm8917: Remove ALWAYS_ON flag from cpp_gdsc
- clk: qcom: gcc-ipq5018: flag sleep clock as critical
- clk: Move clk_{save,restore}_context() to COMMON_CLK section
- clk: qcom: dispcc-sdm845: Enable parents for pixel clocks
- clk: qcom: gfx3d: add parent to parent request map
- clk: mediatek: Fix error handling in runtime PM setup
- dmaengine: mediatek: uart-apdma: Fix above 4G addressing TX/RX
- dma: dma-axi-dmac: fix SW cyclic transfers
- staging: greybus: lights: avoid NULL deref
- serial: imx: change SERIAL_IMX_CONSOLE to bool
- serial: SH_SCI: improve "DMA support" prompt
- mmc: rtsx_pci_sdmmc: increase power-on settling delay to 5ms
- iio: pressure: mprls0025pa: fix scan_type struct
- watchdog: starfive-wdt: Fix PM reference leak in probe error path
- coresight: etm3x: Fix cpulocked warning on cpuhp
- Revert "mmc: rtsx_pci_sdmmc: increase power-on settling delay to 5ms"
- mfd: arizona: Fix regulator resource leak on
wm5102_clear_write_sequencer() failure
- mfd: simple-mfd-i2c: Add MAX77705 support
- mfd: simple-mfd-i2c: Add compatible strings for Layerscape QIXIS FPGA
- mfd: simple-mfd-i2c: Add SpacemiT P1 support
- mfd: simple-mfd-i2c: Keep compatible strings in alphabetical order
- mfd: simple-mfd-i2c: Add Delta TN48M CPLD support
- [Config] Disable new Delta TN48M CPLD support by default
- drivers: iio: mpu3050: use dev_err_probe for regulator request
- usb: bdc: fix sleep during atomic
- pinctrl: equilibrium: Fix device node reference leak in pinbank_init()
- ovl: Fix uninit-value in ovl_fill_real
- iio: sca3000: Fix a resource leak in sca3000_probe()
- pinctrl: qcom: sm8250-lpass-lpi: Fix i2s2_data_groups definition
- pinctrl: single: fix refcount leak in pcs_add_gpio_func()
- leds: qcom-lpg: Check the return value of regmap_bulk_write()
- backlight: qcom-wled: Support ovp values for PMI8994
- backlight: qcom-wled: Change PM8950 WLED configurations
- dmaengine: fsl-edma: don't explicitly disable clocks in .remove()
- io_uring/cancel: de-unionize file and user_data in struct io_cancel_data
- fs/ntfs3: prevent infinite loops caused by the next valid being the same
- fs/ntfs3: Fix slab-out-of-bounds read in DeleteIndexEntryRoot
- ACPI: CPPC: Fix remaining for_each_possible_cpu() to use online CPUs
- powercap: intel_rapl_tpmi: Remove FW_BUG from invalid version check
- kbuild: Add objtool to top-level clean target
- selftests/memfd: delete unused declarations
- selftests/memfd: use IPC semaphore instead of SIGSTOP/SIGCONT
- ACPI: PM: Add unused power resource quirk for THUNDEROBOT ZERO
- cpuidle: Skip governor when only one idle state is available
- selftests: mlxsw: tc_restrictions: Fix test failure with new iproute2
- net: sparx5/lan969x: fix DWRR cost max to match hardware register width
- net: mscc: ocelot: extract ocelot_xmit_timestamp() helper
- net: mscc: ocelot: split xmit into FDMA and register injection paths
- net: mscc: ocelot: add missing lock protection in ocelot_port_xmit_inj()
- ipv6: Fix out-of-bound access in fib6_add_rt2node().
- net: sparx5/lan969x: fix PTP clock max_adj value
- net: usb: catc: enable basic endpoint checking
- xen-netback: reject zero-queue configuration from guest
- net/rds: rds_sendmsg should not discard payload_len
- net: bridge: mcast: always update mdb_n_entries for vlan contexts
- selftests: forwarding: vxlan_bridge_1d: fix test failure with
br_netfilter enabled
- selftests: forwarding: vxlan_bridge_1d_ipv6: fix test failure with
br_netfilter enabled
- netfilter: nf_conntrack_h323: don't pass uninitialised l3num value
- net: remove WARN_ON_ONCE when accessing forward path array
- ipv6: fix a race in ip6_sock_set_v6only()
- bpftool: Fix truncated netlink dumps
- ping: annotate data-races in ping_lookup()
- icmp: move icmp_global.credit and icmp_global.stamp to per netns storage
- icmp: icmp_msgs_per_sec and icmp_msgs_burst sysctls become per netns
- icmp: prevent possible overflow in icmp_global_allow()
- cache: add __cacheline_group_{begin, end}_aligned() (+ couple more)
- inet: move icmp_global_{credit,stamp} to a separate cache line
- octeontx2-af: Fix default entries mcam entry action
- bonding: alb: fix UAF in rlb_arp_recv during bond up/down
- net/mlx5: Fix multiport device check over light SFs
- apparmor: fix NULL sock in aa_sock_file_perm
- apparmor: return -ENOMEM in unpack_perms_table upon alloc failure
- apparmor: fix rlimit for posix cpu timers
- apparmor: remove apply_modes_to_perms from label_match
- apparmor: make label_match return a consistent value
- apparmor: fix invalid deref of rawdata when export_binary is unset
- apparmor: fix aa_label to return state from compount and component match
- drm/amdgpu: Fix memory leak in amdgpu_acpi_enumerate_xcc()
- drm/amdgpu: Fix memory leak in amdgpu_ras_init()
- drm/i915/acpi: free _DSM package when no connectors
- ASoC: codecs: aw88261: Fix erroneous bitmask logic in Awinic init
- drm/amdkfd: fix debug watchpoints for logical devices
- drm/amdkfd: Fix watch_id bounds checking in debug address watch v2
- spi: wpcm-fiu: Use devm_platform_ioremap_resource_byname()
- spi: wpcm-fiu: Fix uninitialized res
- spi: wpcm-fiu: Simplify with dev_err_probe()
- spi: wpcm-fiu: Fix potential NULL pointer dereference in
wpcm_fiu_probe()
- s390/kexec: Make KEXEC_SIG available when CONFIG_MODULES=n
- efi: Fix reservation of unaccepted memory table
- btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not
found
- x86/hyperv: Fix error pointer dereference
- ASoC: rockchip: i2s-tdm: Use param rate if not provided by set_sysclk
- drm/amd/display: Use same max plane scaling limits for all 64 bpp
formats
- MIPS: Work around LLVM bug when gp is used as global register variable
- ext4: don't cache extent during splitting extent
- ext4: fix memory leak in ext4_ext_shift_extents()
- ext4: use optimized mballoc scanning regardless of inode format
- ata: pata_ftide010: Fix some DMA timings
- ata: libata-scsi: refactor ata_scsi_translate()
- SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths
- SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path
- ASoC: dt-bindings: asahi-kasei,ak4458: Fix the supply names
- ASoC: dt-bindings: asahi-kasei,ak5558: Fix the supply names
- perf test stat: Update test expectations and events
- perf test stat tests: Fix for virtualized machines
- perf unwind-libdw: Fix invalid reference counts
- perf callchain: Fix srcline printing with inlines
- libsubcmd: Fix null intersection case in exclude_cmds()
- libperf: Don't remove -g when EXTRA_CFLAGS are used
- libperf build: Always place libperf includes first
- rtc: interface: Alarm race handling should not discard preceding error
- hfsplus: fix volume corruption issue for generic/498
- fs/buffer: add alert in try_to_free_buffers() for folios without buffers
- hfsplus: pretend special inodes as regular files
- i3c: master: svc: Initialize 'dev' to NULL in svc_i3c_master_ibi_isr()
- minix: Add required sanity checking to minix_check_superblock()
- btrfs: handle user interrupt properly in btrfs_trim_fs()
- smb: client: add proper locking around ses->iface_last_update
- gfs2: fiemap page fault fix
- smb: client: prevent races in ->query_interfaces()
- tools/power cpupower: Reset errno before strtoull()
- s390/purgatory: Add -Wno-default-const-init-unsafe to KBUILD_CFLAGS
- perf/arm-cmn: Support CMN-600AE
- arm64: Add support for TSV110 Spectre-BHB mitigation
- rnbd-srv: Zero the rsp buffer before using it
- x86/xen/pvh: Enable PAE mode for 32-bit guest only when CONFIG_X86_PAE
is set
- EFI/CPER: don't dump the entire memory region
- APEI/GHES: ensure that won't go past CPER allocated record
- EFI/CPER: don't go past the ARM processor CPER record buffer
- ACPI: processor: Fix NULL-pointer dereference in
acpi_processor_errata_piix4()
- ACPICA: Abort AML bytecode execution when executing AML_FATAL_OP
- md-cluster: fix NULL pointer dereference in process_metadata_update
- cpufreq: dt-platdev: Block the driver from probing on more QC platforms
- s390/perf: Disable register readout on sampling events
- perf/cxlpmu: Replace IRQF_ONESHOT with IRQF_NO_THREAD
- xenbus: Use .freeze/.thaw to handle xenbus devices
- blk-mq-debugfs: add missing debugfs_mutex in
blk_mq_debugfs_register_hctxs()
- sparc: Synchronize user stack on fork and clone
- sparc: don't reference obsolete termio struct for TC* constants
- bpf: verifier improvement in 32bit shift sign extension pattern
- clocksource/drivers/sh_tmu: Always leave device running after probe
- clocksource/drivers/timer-integrator-ap: Add missing Kconfig dependency
on OF
- PCI/MSI: Unmap MSI-X region on error
- crypto: hisilicon/qm - move the barrier before writing to the mailbox
register
- mailbox: bcm-ferxrm-mailbox: Use default primary handler
- char: tpm: cr50: Remove IRQF_ONESHOT
- pstore: ram_core: fix incorrect success return when vmap() fails
- arm64: tegra: smaug: Add usb-role-switch support
- parisc: Prevent interrupts during reboot
- drm/display/dp_mst: Add protection against 0 vcpi
- spi-geni-qcom: initialize mode related registers to 0
- spi-geni-qcom: use xfer->bits_per_word for can_dma()
- media: dvb-core: dmxdevfilter must always flush bufs
- spi: stm32: fix Overrun issue at < 8bpw
- drm/v3d: Set DMA segment size to avoid debug warnings
- media: omap3isp: isp_video_mbus_to_pix/pix_to_mbus fixes
- media: omap3isp: isppreview: always clamp in preview_try_format()
- media: omap3isp: set initial format
- media: mediatek: vcodec: Don't try to decode 422/444 VP9
- drm/amdgpu: add support for HDP IP version 6.1.1
- drm/amdgpu: avoid a warning in timedout job handler
- HID: apple: Add "SONiX KN85 Keyboard" to the list of non-apple keyboards
- ASoC: wm8962: Add WM8962_ADC_MONOMIX to "3D Coefficients" mask
- ASoC: wm8962: Don't report a microphone if it's shorted to ground on
plug
- spi: spi-mem: Limit octal DTR constraints to octal DTR situations
- media: amphion: Clear last_buffer_dequeued flag for DEC_CMD_START
- media: adv7180: fix frame interval in progressive mode
- media: pvrusb2: fix URB leak in pvr2_send_request_ex
- media: solo6x10: Check for out of bounds chip_id
- media: cx25821: Fix a resource leak in cx25821_dev_setup()
- media: v4l2-async: Fix error handling on steps after finding a match
- drm/amdkfd: Fix GART PTE for non-4K pagesize in svm_migrate_gart_map()
- drm: Account property blob allocations to memcg
- hyper-v: Mark inner union in hv_kvp_exchg_msg_value as packed
- virt: vbox: uapi: Mark inner unions in packed structs as packed
- drm/atmel-hlcdc: fix memory leak from the atomic_destroy_state callback
- drm/atmel-hlcdc: don't reject the commit if the src rect has fractional
parts
- drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release
- media: rkisp1: Fix filter mode register configuration
- HID: multitouch: add eGalaxTouch EXC3188 support
- HID: elecom: Add support for ELECOM HUGE Plus M-HT1MRBK
- ALSA: hda/conexant: Add headset mic fix for MECHREVO Wujie 15X Pro
- gpio: aspeed-sgpio: Change the macro to support deferred probe
- ASoC: sunxi: sun50i-dmic: Add missing check for devm_regmap_init_mmio
- spi: spi-mem: Protect dirmap_create() with spi_mem_access_start/end
- ASoC: codecs: max98390: Check return value of devm_gpiod_get_optional()
in max98390_i2c_probe()
- hwmon: (nct6775) Add ASUS Pro WS WRX90E-SAGE SE
- hwmon: (f71882fg) Add F81968 support
- ASoC: es8328: Add error unwind in resume
- modpost: Amend ppc64 save/restfpr symnames for -Os build
- ALSA: usb-audio: Add iface reset and delay quirk for AB13X USB Audio
- jfs: Add missing set_freezable() for freezable kthread
- jfs: nlink overflow in jfs_rename
- wifi: rtw88: fix DTIM period handling when conf->dtim_period is zero
- wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_config_trx_mode()
- wifi: rtw88: rtw8821cu: Add ID for Mercusys MU6H
- dm: replace -EEXIST with -EBUSY
- dm: remove fake timeout to avoid leak request
- iommu/arm-smmu-v3: Improve CMDQ lock fairness and efficiency
- wifi: libertas: fix WARNING in usb_tx_block
- iommu/amd: move wait_on_sem() out of spinlock
- wifi: rtw89: wow: add reason codes for disassociation in WoWLAN mode
- PCI: dw-rockchip: Disable BAR 0 and BAR 1 for Root Port
- wifi: ath11k: add pm quirk for Thinkpad Z13/Z16 Gen1
- wifi: ath12k: fix preferred hardware mode calculation
- ipv6: annotate data-races in ip6_multipath_hash_{policy,fields}()
- ipv6: exthdrs: annotate data-race over multiple sysctl
- ext4: mark group add fast-commit ineligible
- ext4: move ext4_percpu_param_init() before ext4_mb_init()
- ext4: mark group extend fast-commit ineligible
- netfilter: nf_conntrack: Add allow_clash to generic protocol handler
- netfilter: xt_tcpmss: check remaining length before reading optlen
- openrisc: define arch-specific version of nop()
- net: usb: r8152: fix transmit queue timeout
- wifi: iwlwifi: mvm: check the validity of noa_len
- net/rds: No shortcut out of RDS_CONN_ERROR
- gro: change the BUG_ON() in gro_pull_from_frag0()
- ipv4: igmp: annotate data-races around idev->mr_maxdelay
- net: hns3: extend HCLGE_FD_AD_QID to 11 bits
- wifi: iwlegacy: add missing mutex protection in il4965_store_tx_power()
- wifi: iwlegacy: add missing mutex protection in
il3945_store_measurement()
- ipv4: fib: Annotate access to struct fib_alias.fa_state.
- Bluetooth: hci_conn: Set link_policy on incoming ACL connections
- Bluetooth: hci_conn: use mod_delayed_work for active mode timeout
- Bluetooth: btusb: Add new VID/PID for RTL8852CE
- Bluetooth: btusb: Add device ID for Realtek RTL8761BU
- octeontx2-af: Workaround SQM/PSE stalls by disabling sticky
- wifi: rtw89: pci: restore LDO setting after device resume
- wifi: ath10k: fix lock protection in
ath10k_wmi_event_peer_sta_ps_state_chg()
- net: usb: sr9700: remove code to drive nonexistent multicast filter
- vmw_vsock: bypass false-positive Wnonnull warning with gcc-16
- net/rds: Clear reconnect pending bit
- PCI: Mark ASM1164 SATA controller to avoid bus reset
- PCI: Fix pci_slot_lock () device locking
- PCI: Enable ACS after configuring IOMMU for OF platforms
- PCI: Add ACS quirk for Qualcomm Hamoa & Glymur
- PCI: Mark Nvidia GB10 to avoid bus reset
- myri10ge: avoid uninitialized variable use
- nfc: nxp-nci: remove interrupt trigger type
- RDMA/rtrs-clt: For conn rejection use actual err number
- ata: libata: avoid long timeouts on hot-unplugged SATA DAS
- hisi_acc_vfio_pci: update status after RAS error
- scsi: buslogic: Reduce stack usage
- vhost: fix caching attributes of MMIO regions by setting them explicitly
- tracing: Fix false sharing in hwlat get_sample()
- remoteproc: imx_dsp_rproc: Skip RP_MBOX_SUSPEND_SYSTEM when mailbox TX
channel is uninitialized
- mailbox: pcc: Remove spurious IRQF_ONESHOT usage
- mailbox: imx: Skip the suspend flag for i.MX7ULP
- mailbox: sprd: mask interrupts that are not handled
- remoteproc: mediatek: Break lock dependency to `prepare_lock`
- mailbox: sprd: clear delivery flag before handling TX done
- clk: microchip: core: correct return value on *_get_parent()
- m68k: nommu: fix memmove() with differently aligned src and dest for
68000
- soundwire: dmi-quirks: add mapping for Avell B.ON (OEM rebranded of
NUC15)
- staging: rtl8723bs: fix missing status update on sdio_alloc_irq()
failure
- serial: 8250_dw: handle clock enable errors in runtime_resume
- usb: typec: ucsi: psy: Fix voltage and current max for non-Fixed PDOs
- fpga: of-fpga-region: Fail if any bridge is missing
- dmaengine: sun6i: Choose appropriate burst length under maxburst
- dmaengine: stm32-mdma: initialize m2m_hw_period and ccr to fix warnings
- misc: bcm_vk: Fix possible null-pointer dereferences in bcm_vk_read()
- misc: eeprom: Fix EWEN/EWDS/ERAL commands for 93xx56 and 93xx66
- staging: rtl8723bs: fix memory leak on failure path
- serial: 8250: 8250_omap.c: Clear DMA RX running status only after DMA
termination is done
- fix it87_wdt early reboot by reporting running timer
- binder: don't use %pK through printk
- watchdog: imx7ulp_wdt: handle the nowayout option
- phy: mvebu-cp110-utmi: fix dr_mode property read from dts
- phy: fsl-imx8mq-usb: disable bind/unbind platform driver feature
- Revert "mfd: da9052-spi: Change read-mask to write-mask"
- iio: Use IRQF_NO_THREAD
- iio: magnetometer: Remove IRQF_ONESHOT
- MIPS: Loongson: Make cpumask_of_node() robust against NUMA_NO_NODE
- fs/ntfs3: drop preallocated clusters for sparse and compressed files
- fs/ntfs3: avoid calling run_get_entry() when run == NULL in
ntfs_read_run_nb_ra()
- ceph: supply snapshot context in ceph_uninline_data()
- libceph: define and enforce CEPH_MAX_KEY_LEN
- thermal: int340x: Fix sysfs group leak on DLVR registration failure
- include: uapi: netfilter_bridge.h: Cover for musl libc
- ARM: 9467/1: mm: Don't use %pK through printk
- drm/amd/display: Avoid updating surface with the same surface under MPO
- drm/amdgpu: Adjust usleep_range in fence wait
- ALSA: usb-audio: Update the number of packets properly at receiving
- drm/amdgpu: Add HAINAN clock adjustment
- drm/radeon: Add HAINAN clock adjustment
- ALSA: usb-audio: Add sanity check for OOB writes at silencing
- btrfs: replace BUG() with error handling in __btrfs_balance()
- drm/amd/display: Remove conditional for shaper 3DLUT power-on
- rtc: zynqmp: correct frequency value
- ntb: ntb_hw_switchtec: Fix array-index-out-of-bounds access
- ntb: ntb_hw_switchtec: Fix shift-out-of-bounds for 0 mw lut
- xfrm6: fix uninitialized saddr in xfrm6_get_saddr()
- xfrm: skip templates check for packet offload tunnel mode
- ipmi: ipmb: initialise event handler read bytes
- xfrm: always flush state and policy upon NETDEV_UNREGISTER event
- net: usb: kaweth: remove TX queue manipulation in kaweth_set_rx_mode
- net: usb: lan78xx: scan all MDIO addresses on LAN7801
- net: ixp4xx_eth: convert to ndo_hwtstamp_get() and ndo_hwtstamp_set()
- net: ethernet: xscale: Check for PTP support properly
- wifi: cfg80211: wext: fix IGTK key ID off-by-one
- Remove WARN_ALL_UNSEEDED_RANDOM kernel config option
- [Config] Remove WARN_ALL_UNSEEDED_RANDOM
- Bluetooth: L2CAP: Fix invalid response to L2CAP_ECRED_RECONF_REQ
- Bluetooth: hci_qca: Cleanup on all setup failures
- Bluetooth: L2CAP: Fix response to L2CAP_ECRED_CONN_REQ
- Bluetooth: L2CAP: Fix not checking output MTU is acceptable on
L2CAP_ECRED_CONN_REQ
- Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ
- tipc: fix duplicate publication key in tipc_service_insert_publ()
- RDMA/core: Fix stale RoCE GIDs during netdev events at registration
- net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets
- RDMA/efa: Fix typo in efa_alloc_mr()
- net: usb: pegasus: enable basic endpoint checking
- RDMA/umem: Fix double dma_buf_unpin in failure path
- net/mlx5: DR, Fix circular locking dependency in dump
- net/mlx5: Fix missing devlink lock in SRIOV enable error path
- net: consume xmit errors of GSO frames
- dpaa2-switch: validate num_ifs to prevent out-of-bounds write
- netfilter: nf_conntrack_h323: fix OOB read in decode_choice()
- rpmsg: core: fix race in driver_override_show() and use core helper
- clk: renesas: rzg2l: Fix intin variable size
- clk: renesas: rzg2l: Select correct div round macro
- ASoC: SOF: ipc4-control: If there is no data do not send bytes update
- ASoC: SOF: ipc4-topology: Correct the allocation size for bytes controls
- ASoC: SOF: ipc4-control: Use the correct size for
scontrol->ipc_control_data
- ASoC: SOF: ipc4-control: Keep the payload size up to date
- fpga: dfl: use subsys_initcall to allow built-in drivers to be added
- dm-verity: correctly handle dm_bufio_client_create() failure
- media: mediatek: encoder: Fix uninitialized scalar variable issue
- media: mtk-mdp: Fix error handling in probe function
- media: mtk-mdp: Fix a reference leak bug in mtk_mdp_remove()
- media: verisilicon: AV1: Fix enable cdef computation
- media: verisilicon: AV1: Fix tx mode bit setting
- ARM: omap2: Fix reference count leaks in omap_control_init()
- KVM: nSVM: Remove a user-triggerable WARN on nested_svm_load_cr3()
succeeding
- arm64: Disable branch profiling for all arm64 code
- HID: hid-pl: handle probe errors
- HID: magicmouse: Do not crash on missing msc->input
- HID: prodikeys: Check presence of pm->input_ep82
- HID: logitech-hidpp: Check maxfield in hidpp_get_report_length()
- arm64: dts: apple: t8112-j473: Keep the HDMI port powered on
- media: verisilicon: AV1: Set IDR flag for intra_only frame type
- media: radio-keene: fix memory leak in error path
- media: cx88: Add missing unmap in snd_cx88_hw_params()
- media: cx23885: Add missing unmap in snd_cx23885_hw_params()
- media: cx25821: Add missing unmap in snd_cx25821_hw_params()
- media: i2c/tw9903: Fix potential memory leak in tw9903_probe()
- media: i2c/tw9906: Fix potential memory leak in tw9906_probe()
- media: i2c: ov01a10: Fix the horizontal flip control
- media: i2c: ov01a10: Fix reported pixel-rate value
- media: i2c: ov01a10: Fix analogue gain range
- media: i2c: ov01a10: Add missing v4l2_subdev_cleanup() calls
- media: i2c: ov01a10: Fix test-pattern disabling
- media: qcom: camss: vfe: Fix out-of-bounds access in
vfe_isr_reg_update()
- media: ccs: Avoid possible division by zero
- media: i2c: ov5647: Initialize subdev before controls
- media: i2c: ov5647: Correct pixel array offset
- media: i2c: ov5647: Correct minimum VBLANK value
- media: i2c: ov5647: Sensor should report RAW color space
- media: i2c: ov5647: Fix PIXEL_RATE value for VGA mode
- media: i2c: ov5647: use our own mutex for the ctrl lock
- dm-integrity: fix a typo in the code for write/discard race
- dm: clear cloned request bio pointer when last clone bio completes
- soc: ti: k3-socinfo: Fix regmap leak on probe failure
- soc: ti: pruss: Fix double free in pruss_clk_mux_setup()
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation
- clk: clk-apple-nco: Add "apple,t8103-nco" compatible
- media: i2c: ov01a10: Fix digital gain range
- clk: tegra: tegra124-emc: Fix potential memory leak in
tegra124_clk_register_emc()
- s390/pci: Handle futile config accesses of disabled devices directly
- dm-integrity: fix recalculation in bitmap mode
- dm-unstripe: fix mapping bug when there are multiple targets in a table
- arm64: dts: rockchip: Do not enable hdmi_sound node on Pinebook Pro
- media: venus: vdec: fix error state assignment for zero bytesused
- media: venus: vdec: restrict EOS addr quirk to IRIS2 only
- drm: of: drm_of_panel_bridge_remove(): fix device_node leak
- mm, page_alloc, thp: prevent reclaim for __GFP_THISNODE THP allocations
- selftests/mm/charge_reserved_hugetlb: drop mount size for hugetlbfs
- xfs: mark data structures corrupt on EIO and ENODATA
- media: verisilicon: AV1: Fix tile info buffer size
- iommu/vt-d: Flush dev-IOTLB only when PCIe device is accessible in
scalable mode
- mfd: core: Add locking around 'mfd_of_node_list'
- xfs: delete attr leaf freemap entries when empty
- xfs: fix freemap adjustments when adding xattrs to leaf blocks
- xfs: fix remote xattr valuelblk check
- KVM: x86: Add SRCU protection for reading PDPTRs in __get_sregs2()
- PCI: endpoint: Fix swapped parameters in
pci_{primary/secondary}_epc_epf_unlink() functions
- md/bitmap: fix GPF in write_page caused by resize race
- nfsd: fix return error code for nfsd_map_name_to_[ug]id
- nvmem: Drop OF node reference on nvmem_add_one_cell() failure
- usb: gadget: tegra-xudc: Add handling for BLCG_COREPLL_PWRDN
- bus: fsl-mc: fix an error handling in fsl_mc_device_add()
- dm mpath: make pg_init_delay_msecs settable
- tools: Fix bitfield dependency failure
- powerpc/smp: Add check for kcalloc() failure in parse_thread_groups()
- iio: gyro: itg3200: Fix unchecked return value in read_raw
- mm/highmem: fix __kmap_to_page() build error
- rapidio: replace rio_free_net() with kfree() in rio_scan_alloc_net()
- ocfs2: fix reflink preserve cleanup issue
- kexec: derive purgatory entry from symbol
- Revert "PCI/IOV: Add PCI rescan-remove locking when enabling/disabling
SR-IOV"
- PCI/IOV: Fix race between SR-IOV enable/disable and hotplug
- arm64: Fix non-atomic __READ_ONCE() with CONFIG_LTO=y
- btrfs: continue trimming remaining devices on failure
- remoteproc: imx_rproc: Fix invalid loaded resource table detection
- perf/arm-cmn: Reject unsupported hardware configurations
- scsi: ufs: core: Flush exception handling work when RPM level is zero
- usb: dwc3: gadget: Move vbus draw to workqueue context
- usb: dwc2: fix resume failure if dr_mode is host
- mtd: rawnand: pl353: Fix software ECC support
- tipc: fix RCU dereference race in tipc_aead_users_dec()
- drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set()
- net: cpsw_new: Fix unnecessary netdev unregistration in cpsw_probe()
error path
- PCI: Fix pci_slot_trylock() error handling
- parisc: kernel: replace kfree() with put_device() in create_tree_node()
- staging: rtl8723bs: fix null dereference in find_network
- cifs: Fix locking usage for tcon fields
- MIPS: rb532: Fix MMIO UART resource registration
- ceph: supply snapshot context in ceph_zero_partial_object()
- LoongArch: Make cpumask_of_node() robust against NUMA_NO_NODE
- LoongArch: Prefer top-down allocation after arch_mem_init()
- LoongArch: Guard percpu handler under !CONFIG_PREEMPT_RT
- LoongArch: Disable instrumentation for setup_ptwalker()
- net: ethernet: marvell: skge: remove incorrect conflicting PCI ID
- net: wan/fsl_ucc_hdlc: Fix dma_free_coherent() in uhdlc_memclean()
- octeontx2-af: CGX: fix bitmap leaks
- net: macb: Fix tx/rx malfunction after phy link down and up
- tracing: Fix to set write permission to per-cpu buffer_size_kb
- io_uring/filetable: clamp alloc_hint to the configured alloc range
- net: intel: fix PCI device ID conflict between i40e and ipw2200
- atm: fore200e: fix use-after-free in tasklets during device removal
- ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data()
- fbcon: check return value of con2fb_acquire_newinfo()
- fbdev: vt8500lcdfb: fix missing dma_free_coherent()
- fbdev: of: display_timing: fix refcount leak in of_get_display_timings()
- fbdev: ffb: fix corrupted video output on Sun FFB1
- fbcon: Remove struct fbcon_display.inverse
- cifs: some missing initializations on replay
- ASoC: amd: yc: Add DMI quirk for ASUS Vivobook Pro 15X M6501RR
- net: ethernet: ec_bhf: Fix dma_free_coherent() dma handle
- net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash()
- x86/kexec: Copy ACPI root pointer address from config table
- arm64: Force the use of CNTVCT_EL0 in __delay()
- net: nfc: nci: Fix parameter validation for packet data
- tracing: Fix checking of freed trace_event_file for hist files
- tracing: Wake up poll waiters for hist files when removing an event
- NTB: ntb_transport: Fix too small buffer for debugfs_name
- drm/i915/wakeref: clean up INTEL_WAKEREF_PUT_* flag macros
- arm64: Fix sampling the "stable" virtual counter in preemptible section
- gfs2: Fix slab-use-after-free in qd_put
- io_uring: use release-acquire ordering for IORING_SETUP_R_DISABLED
- thermal: intel: x86_pkg_temp_thermal: Handle invalid temperature
- OPP: Return correct value in dev_pm_opp_get_level
- cpufreq: scmi: Fix device_node reference leak in scmi_cpu_domain_id()
- perf/x86/core: Do not set bit width for unavailable counters
- genirq: Set IRQF_COND_ONESHOT in devm_request_irq().
- platform/x86: int0002: Remove IRQF_ONESHOT from request_irq()
- media: pci: mg4b: Use IRQF_NO_THREAD
- firmware: arm_ffa: Correct 32-bit response handling in
NOTIFICATION_INFO_GET
- arm64: dts: qcom: msm8994-octagon: Fix Analog Devices vendor prefix of
AD7147
- arm64: dts: mediatek: mt8183-jacuzzi-pico6: Fix typo in pinmux node
- arm64: dts: qcom: qrb4210-rb2: Fix UART3 wakeup IRQ storm
- arm64: dts: qcom: x1e: bus is 40-bits (fix 64GB models)
- media: chips-media: wave5: Fix memory leak on codec_info allocation
failure
- drm/amd: Drop "amdgpu kernel modesetting enabled" message
- drm/amdkfd: Fix signal_eviction_fence() bool return value
- drm/xe: Unregister drm device on probe error
- HID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients
- wifi: cfg80211: Fix use_for flag update on BSS refresh
- PCI: Check parent for NULL in of_pci_bus_release_domain_nr()
- netfilter: nfnetlink_queue: optimize verdict lookup with hash table
- netfilter: nfnetlink_queue: do shared-unconfirmed check before
segmentation
- netfilter: nft_set_rbtree: fix bogus EEXIST with NLM_F_CREATE with null
interval
- power: supply: pm8916_bms_vm: Fix use-after-free in
power_supply_changed()
- power: supply: pm8916_lbc: Fix use-after-free in power_supply_changed()
- RDMA/mlx5: Fix UMR hang in LAG error state unload
- IB/mlx5: Fix port speed query for representors
- platform/x86/amd/pmf: Prevent TEE errors after hibernate
- crypto: ccp - Declare PSP dead if PSP_CMD_TEE_RING_INIT fails
- power: supply: pm8916_lbc: Fix use-after-free for extcon in IRQ handler
- clk: qcom: gcc-sm8650: Use floor ops for SDCC RCGs
- clk: qcom: gcc-sm4450: Update the SDCC RCGs to use shared_floor_ops
- clk: qcom: gcc-x1e80100: Update the SDCC RCGs to use shared_floor_ops
- dma: dma-axi-dmac: fix HW scatter-gather not looking at the queue
- iio: pressure: mprls0025pa: fix interrupt flag
- objpool: fix the overestimation of object pooling metadata size
- ipvs: do not keep dest_dst if dev is going down
- net/mlx5e: Use unsigned for mlx5e_get_max_num_channels
- AppArmor: Allow apparmor to handle unaligned dfa tables
- apparmor: Fix & Optimize table creation from possibly unaligned memory
- apparmor: avoid per-cpu hold underflow in aa_get_buffer
- drm/amd/display: Fix out-of-bounds stream encoder index v3
- btrfs: use the correct type to initialize block reserve for delayed refs
- Drivers: hv: vmbus: Use kthread for vmbus interrupts on PREEMPT_RT
- i3c: mipi-i3c-hci: Reset RING_OPERATION1 fields during init
- APEI/GHES: ARM processor Error: don't go past allocated memory
- ACPI: resource: Add JWIPC JVC9100 to irq1_level_low_skip_override[]
- powercap: intel_rapl: Add PL4 support for Ice Lake
- alpha: fix user-space corruption during memory compaction
- ACPI: x86: s2idle: Invoke Microsoft _DSM Function 9 (Turn On Display)
- ACPI: battery: fix incorrect charging status when current is zero
- perf/x86/msr: Add Airmont NP
- perf/x86/cstate: Add Airmont NP
- bpf: Recognize special arithmetic shift in the verifier
- firmware: arm_ffa: Unmap Rx/Tx buffers on init failure
- gpu/panel-edp: add AUO panel entry for B140HAN06.4
- drm/amdgpu: fix NULL pointer issue buffer funcs
- ASoC: SOF: ipc4: Support for sending payload along with LARGE_CONFIG_GET
- media: chips-media: wave5: Fix conditional in start_streaming
- media: chips-media: wave5: Process ready frames when CMD_STOP sent to
Encoder
- drm/amd/display: Fix dsc eDP issue
- drm/panel: Fix a possible null-pointer dereference in
jdi_panel_dsi_remove()
- media: mt9m114: Avoid a reset low spike during probe()
- media: mt9m114: Return -EPROBE_DEFER if no endpoint is found
- ALSA: hda/realtek: add HP Victus 16-e0xxx mute LED quirk
- PCI: Add Intel Nova Lake audio Device ID
- drm/amd/display: Disable FEC when powering down encoders
- drm/amd/display: avoid dig reg access timeout on usb4 link training fail
- hwmon: (dell-smm) Add support for Dell OptiPlex 7080
- HID: logitech-hidpp: Add support for Logitech K980
- ASoC: SOF: Intel: hda: Fix NULL pointer dereference
- spi: geni-qcom: Fix abort sequence execution for serial engine errors
- ALSA: hda/realtek - Enable mute LEDs on HP ENVY x360 15-es0xxx
- wifi: rtw89: 8922a: set random mac if efuse contains zeroes
- wifi: rtw89: ser: enable error IMR after recovering from L1
- wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()
- wifi: rtw89: mac: correct page number for CSI response
- wifi: ath11k: Fix failure to connect to a 6 GHz AP
- ipv6: annotate data-races over sysctl.flowlabel_reflect
- ext4: use reserved metadata blocks when splitting extent on endio
- Bluetooth: btusb: Add support for MediaTek7920 0489:e158
- net: sfp: add quirk for Lantech 8330-265D
- PCI/AER: Clear stale errors on reporting agents upon probe
- scsi: ufs: mediatek: Fix page faults in ufs_mtk_clk_scale() trace event
- riscv: vector: init vector context with proper vlenb
- HID: i2c-hid: Add FocalTech FT8112
- 9p/xen: protect xen_9pfs_front_free against concurrent calls
- soundwire: intel_auxdevice: add cs42l45 codec to wake_capable_list
- most: remove usage of the deprecated ida_simple_xx() API
- most: core: fix resource leak in most_register_interface error paths
- usb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke()
- serial: 8250: 8250_omap.c: Add support for handling UART error
conditions
- mfd: intel-lpss: Add Intel Nova Lake-S PCI IDs
- ACPI: x86: Force enabling of PWM2 on the Yogabook YB1-X90
- drm/amd/display: Fix writeback on DCN 3.2+
- drm/amd/display: Fix system resume lag issue
- drm/amd/display: bypass post csc for additional color spaces in dal
- spi: spidev: fix lock inversion between spi_lock and buf_lock
- Bluetooth: L2CAP: Avoid -Wflex-array-member-not-at-end warnings
- Bluetooth: L2CAP: Fix result of L2CAP_ECRED_CONN_RSP when MTU is too
short
- kcm: fix zero-frag skb in frag_list on partial sendmsg error
- net/mlx5: E-switch, Clear legacy flag when moving to switchdev
- net/mlx5e: Separate address related variables to be in struct
- net/mlx5e: Support routed networks during IPsec MACs initialization
- net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query
- drm/tests: shmem: Swap names of export tests
- KVM: x86: Return "unsupported" instead of "invalid" on access to
unsupported PV MSR
- media: amphion: Drop min_queued_buffers assignment
- media: rockchip: rga: Fix possible ERR_PTR dereference in rga_buf_init()
- media: i2c: ov01a10: Fix passing stream instead of pad to
v4l2_subdev_state_get_format()
- media: ccs: Fix setting initial sub-device state
- platform/x86: ISST: Add missing write block check
- bus: omap-ocp2scp: fix OF populate on driver rebind
- media: stm32: dcmipp: bytecap: clear all interrupts upon stream stop
- drm/buddy: Prevent BUG_ON by validating rounded allocation
- xfs: remove xfs_attr_leaf_hasname
- mfd: qcom-pm8xxx: Fix OF populate on driver rebind
- mfd: omap-usb-host: Fix OF populate on driver rebind
- xfs: fix the xattr scrub to detect freemap/entries array collisions
- pinctrl: intel: Add code name documentation
- vhost: move vdpa group bound check to vhost_vdpa
- clk: rs9: Reserve 8 struct clk_hw slots for for 9FGV0841
- mm/slab: use unsigned long for orig_size to ensure proper metadata align
- drm/amd/display: Increase DCN35 SR enter/exit latency
- drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify
- mm: numa_memblks: Identify the accurate NUMA ID of CFMW
- drm/amdgpu: keep vga memory on MacBooks with switchable graphics
- most: core: fix leak on early registration failure
- Bluetooth: L2CAP: Fix stack-out-of-bounds read in l2cap_ecred_conn_req
- Upstream stable to v6.6.128, v6.12.75
* Noble update: upstream stable patchset 2026-05-01 (LP: #2150809) //
CVE-2026-23249
- xfs: check for deleted cursors when revalidating two btrees
* Noble update: upstream stable patchset 2026-05-01 (LP: #2150809) //
CVE-2025-71267
- fs: ntfs3: fix infinite loop triggered by zero-sized ATTR_LIST
* Noble update: upstream stable patchset 2026-05-01 (LP: #2150809) //
CVE-2025-71265
- fs: ntfs3: fix infinite loop in attr_load_runs_range on inconsistent
metadata
* Noble update: upstream stable patchset 2026-05-01 (LP: #2150809) //
CVE-2025-71266
- fs: ntfs3: check return value of indx_find to avoid infinite loop
* Noble update: upstream stable patchset 2026-05-01 (LP: #2150809) //
CVE-2026-23241
- audit: add missing syscalls to read class
* Noble update: upstream stable patchset 2026-05-01 (LP: #2150809) //
CVE-2025-71239
- audit: add fchmodat2() to change attributes class
* Noble update: upstream stable patchset 2026-05-01 (LP: #2150809) //
CVE-2026-31411
- net: atm: fix crash due to unvalidated vcc pointer in sigd_send()
* Noble update: upstream stable patchset 2026-05-01 (LP: #2150809) //
CVE-2026-23243
- RDMA/umad: Reject negative data_len in ib_umad_write
* Noble update: upstream stable patchset 2026-05-01 (LP: #2150809) //
CVE-2026-23242
- RDMA/siw: Fix potential NULL pointer dereference in header processing
* Noble update: upstream stable patchset 2026-04-17 (LP: #2148714)
- scsi: qla2xxx: Fix bsg_done() causing double free
- PCI: endpoint: Remove unused field in struct pci_epf_group
- bus: fsl-mc: Replace snprintf and sprintf with sysfs_emit in sysfs show
functions
- bus: fsl-mc: fix use-after-free in driver_override_show()
- ASoC: amd: yc: Add ASUS ExpertBook PM1503CDA to quirks list
- gpio: sprd: Change sprd_gpio lock to raw_spin_lock
- ALSA: hda/realtek: Add quirk for Inspur S14-G1
- ASoC: cs35l45: Corrects ASP_TX5 DAPM widget channel
- romfs: check sb_set_blocksize() return value
- drm/tegra: hdmi: sor: Fix error: variable ‘j’ set but not used
- platform/x86: classmate-laptop: Add missing NULL pointer checks
- ASoC: Intel: sof_es8336: Add DMI quirk for Huawei BOD-WXX9
- ASoC: amd: yc: Add quirk for HP 200 G2a 16
- platform/x86/amd/pmc: Add quirk for MECHREVO Wujie 15X Pro
- platform/x86: panasonic-laptop: Fix sysfs group leak in error path
- ASoC: cs42l43: Correct handling of 3-pole jack load detection
- ASoC: fsl_xcvr: fix missing lock in fsl_xcvr_mode_put()
- gpiolib: acpi: Fix gpio count with string references
- LoongArch: Rework KASAN initialization for PTW-enabled systems
- Revert "wireguard: device: enable threaded NAPI"
- mm/hugetlb: fix copy_hugetlb_page_range() to use ->pt_share_count
- mm/hugetlb: fix hugetlb_pmd_shared()
- mm/hugetlb: fix two comments related to huge_pmd_unshare()
- mm/hugetlb: fix excessive IPI broadcasts when unsharing PMD tables using
mmu_gather
- cpuset: Fix missing adaptation for cpuset_is_populated
- LoongArch: Add writecombine support for DMW-based ioremap()
- fbdev: rivafb: fix divide error in nv3_arb()
- fbdev: smscufx: properly copy ioctl memory to kernelspace
- f2fs: fix to add gc count stat in f2fs_gc_range
- f2fs: fix out-of-bounds access in sysfs attribute read/write
- f2fs: fix IS_CHECKPOINTED flag inconsistency issue caused by concurrent
atomic commit and checkpoint writes
- f2fs: fix to avoid UAF in f2fs_write_end_io()
- f2fs: fix to avoid mapping wrong physical block for swapfile
- USB: serial: option: add Telit FN920C04 RNDIS compositions
- bnxt_en: Change FW message timeout warning
- bnxt_en: hide CONFIG_DETECT_HUNG_TASK specific code
- ALSA: hda/realtek: Enable headset mic for Acer Nitro 5
- drm/amd/display: remove assert around dpp_base replacement
- ASoC: fsl_xcvr: Revert fix missing lock in fsl_xcvr_mode_put()
- Upstream stable to v6.6.126, v6.6.127, v6.12.73, v6.12.74
* Noble update: upstream stable patchset 2026-04-13 (LP: #2148260)
- Bluetooth: btusb: Add USB ID 7392:e611 for Edimax EW-7611UXB
- crypto: octeontx - Fix length check to avoid truncation in
ucode_load_store
- crypto: virtio - Remove duplicated virtqueue_kick in
virtio_crypto_skcipher_crypt_req
- scsi: qla2xxx: Allow recovery for tape devices
- scsi: qla2xxx: Query FW again before proceeding with login
- Revert "netfilter: nf_tables: missing objects with no memcg accounting"
- netfilter: nf_tables: missing objects with no memcg accounting
- vsock/test: verify socket options after setting them
- selftests: mptcp: pm: ensure unknown flags are ignored
- gpio: omap: do not register driver in probe()
- net: tunnel: make skb_vlan_inet_prepare() return drop reasons
- Upstream stable to v6.6.125, v6.12.71, v6.12.72
* Noble update: upstream stable patchset 2026-04-13 (LP: #2148260) //
CVE-2025-71233
- PCI: endpoint: Avoid creating sub-groups asynchronously
* Noble update: upstream stable patchset 2026-04-13 (LP: #2148260) //
CVE-2025-71231
- crypto: iaa - Fix out-of-bounds index in find_empty_iaa_compression_mode
* Noble update: upstream stable patchset 2026-04-13 (LP: #2148260) //
CVE-2026-23169
- mptcp: fix race in mptcp_pm_nl_flush_addrs_doit()
* Noble update: upstream stable patchset 2026-04-13 (LP: #2148260) //
CVE-2025-40005
- spi: cadence-quadspi: Implement refcount to handle unbind during busy
* Noble update: upstream stable patchset 2026-04-13 (LP: #2148260) //
CVE-2025-71232
- scsi: qla2xxx: Free sp in error path to fix system crash
* Noble update: upstream stable patchset 2026-04-13 (LP: #2148260) //
CVE-2025-71235
- scsi: qla2xxx: Delay module unload while fabric scan in progress
* Noble update: upstream stable patchset 2026-04-13 (LP: #2148260) //
CVE-2025-71236
- scsi: qla2xxx: Validate sp before freeing associated memory
* Noble update: upstream stable patchset 2026-04-13 (LP: #2148260) //
CVE-2025-71229
- wifi: rtw88: Fix alignment fault in rtw_core_enable_beacon()
* Noble update: upstream stable patchset 2026-04-13 (LP: #2148260) //
CVE-2025-71237
- nilfs2: Fix potential block overflow that cause system hang
* Noble update: upstream stable patchset 2026-04-13 (LP: #2148260) //
CVE-2026-23229
- crypto: virtio - Add spinlock protection with virtqueue notification
* Noble update: upstream stable patchset 2026-04-13 (LP: #2148260) //
CVE-2026-23222
- crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly
* Noble update: upstream stable patchset 2026-04-13 (LP: #2148260) //
CVE-2026-23228
- smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection()
* Noble update: upstream stable patchset 2026-04-13 (LP: #2148260) //
CVE-2026-23220
- ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error
paths
* Noble update: upstream stable patchset 2026-04-13 (LP: #2148260) //
CVE-2026-23230
- smb: client: split cached_fid bitfields to avoid shared-byte RMW races
* CVE-2026-23272
- netfilter: nf_tables: unconditionally bump set->nelems before insertion
* CVE-2026-31418
- netfilter: ipset: drop logically empty buckets in mtype_del
* CVE-2026-23392
- netfilter: nf_tables: release flowtable after rcu grace period on error
* CVE-2026-23278
- netfilter: nf_tables: always walk all pending catchall elements
* GRO managed-frag use-after-free leading to local privilege escalation
(LP: #2154172)
- net: gro: don't merge zcopy skbs
* AppArmor Vulnerabilities (LP: #2151747)
- apparmor: Fix incorrect profile->signal range check
- SAUCE: apparmor: pass big_resp to handler
- SAUCE: apparmor: remove redundant kref_init for listener->count
- SAUCE: apparmor: fix NULL pointer dereference in unpack_pdb
* AppArmor Vulnerabilities (LP: #2151747) // CVE-2026-47337
- SAUCE: apparmor: fix NULL pointer dereference in bind_map_addr
* AppArmor Vulnerabilities (LP: #2151747) // CVE-2026-47336
- SAUCE: apparmor: fix use of unintialized variable in net opt level
* AppArmor Vulnerabilities (LP: #2151747) // CVE-2026-47335
- SAUCE: apparmor: fix possible NULL pointer dereference by adding a NULL
check
* AppArmor Vulnerabilities (LP: #2151747) // CVE-2026-47334
- SAUCE: apparmor: fix sleep prone memory allocation under a spin_lock
* AppArmor Vulnerabilities (LP: #2151747) // CVE-2026-47333
- SAUCE: apparmor: fix dfa unpacking size of the notification filter
* AppArmor Vulnerabilities (LP: #2151747) // CVE-2026-47332
- SAUCE: apparmor: fix size check against type instead of pointer
* AppArmor Vulnerabilities (LP: #2151747) // CVE-2026-47331
- SAUCE: apparmor: fix changing rules list without a lock
* apparmor: LLVM/clang build failure due to uninitialized variable in
notify.c (LP: #2148809) // CVE-2026-47330
- SAUCE: apparmor: initialize variable used in uninitialized context
* AppArmor Vulnerabilities (LP: #2151747) // CVE-2026-47329
- SAUCE: apparmor: fix name validation bypass on notification
* AppArmor Vulnerabilities (LP: #2151747) // CVE-2026-47327 //
CVE-2026-47328
- SAUCE: apparmor: fix glob memory leak after kstrdup
* AppArmor Vulnerabilities (LP: #2151747) // CVE-2026-47326
- SAUCE: apparmor: fix inverted NULL check after aa_get_buffer
* CVE-2026-46300
- net: skbuff: preserve shared-frag marker during coalescing
- net: skbuff: propagate shared-frag marker through frag-transfer helpers
* net/rds: reset op_nents when zerocopy page pin fails (LP: #2153962)
- net/rds: reset op_nents when zerocopy page pin fails
* CVE-2026-46333
- ptrace: slightly saner 'get_dumpable()' logic
* CVE-2026-43500
- rxrpc: Fix conn-level packet handling to unshare RESPONSE packets
- rxrpc: Parse received packets before dealing with timeouts
- rxrpc: Fix potential UAF after skb_unshare() failure
- rxrpc: Fix rxrpc_input_call_event() to only unshare DATA packets
- rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
* CVE-2026-31676 // CVE-2026-43500
- rxrpc: only handle RESPONSE during service challenge
* CVE-2026-43284
- xfrm: esp: avoid in-place decrypt on shared skb frags
* CVE-2026-31419
- net: bonding: fix use-after-free in bond_xmit_broadcast()
* CVE-2026-31431
- crypto: scatterwalk - Backport memcpy_sglist()
- crypto: algif_aead - use memcpy_sglist() instead of null skcipher
- crypto: algif_aead - Revert to operating out-of-place
- crypto: algif_aead - snapshot IV for async AEAD requests
- crypto: authenc - use memcpy_sglist() instead of null skcipher
- crypto: authencesn - Do not place hiseq at end of dst for out-of-place
decryption
- crypto: authencesn - Fix src offset when decrypting in-place
- crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl
- crypto: algif_aead - Fix minimum RX size check for decryption
* CVE-2026-31533
- net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
* CVE-2026-31504
- net: fix fanout UAF in packet_release() via NETDEV_UP race
-- Mehmet Basaran <mehmet.basaran@canonical.com> Mon, 01 Jun 2026 12:13:17 +0300
linux-hwe-6.8 (6.8.0-124.124~22.04.1) jammy; urgency=medium
[ Ubuntu: 6.8.0-124.124 ]
* GRO managed-frag use-after-free leading to local privilege escalation
(LP: #2154172)
- net: gro: don't merge zcopy skbs
[ Ubuntu: 6.8.0-121.121 ]
* apparmor (LP: #2151747)
- apparmor: Fix incorrect profile->signal range check
- SAUCE: apparmor: pass big_resp to handler
- SAUCE: apparmor: remove redundant kref_init for listener->count
- SAUCE: apparmor: fix NULL pointer dereference in unpack_pdb
* apparmor (LP: #2151747) // CVE-2026-47337
- SAUCE: apparmor: fix NULL pointer dereference in bind_map_addr
* apparmor (LP: #2151747) // CVE-2026-47336
- SAUCE: apparmor: fix use of unintialized variable in net opt level
* apparmor (LP: #2151747) // CVE-2026-47335
- SAUCE: apparmor: fix possible NULL pointer dereference by adding a NULL
check
* apparmor (LP: #2151747) // CVE-2026-47334
- SAUCE: apparmor: fix sleep prone memory allocation under a spin_lock
* apparmor (LP: #2151747) // CVE-2026-47333
- SAUCE: apparmor: fix dfa unpacking size of the notification filter
* apparmor (LP: #2151747) // CVE-2026-47332
- SAUCE: apparmor: fix size check against type instead of pointer
* apparmor (LP: #2151747) // CVE-2026-47331
- SAUCE: apparmor: fix changing rules list without a lock
* apparmor: LLVM/clang build failure due to uninitialized variable in
notify.c (LP: #2148809) // CVE-2026-47330
- SAUCE: apparmor: initialize variable used in uninitialized context
* apparmor (LP: #2151747) // CVE-2026-47329
- SAUCE: apparmor: fix name validation bypass on notification
* apparmor (LP: #2151747) // CVE-2026-47327 // CVE-2026-47328
- SAUCE: apparmor: fix glob memory leak after kstrdup
* apparmor (LP: #2151747) // CVE-2026-47326
- SAUCE: apparmor: fix inverted NULL check after aa_get_buffer
[ Ubuntu: 6.8.0-120.120 ]
* noble/linux: 6.8.0-120.120 -proposed tracker (LP: #2153733)
* Packaging resync (LP: #1786013)
- [Packaging] update annotations scripts
* CVE-2026-46300
- net: skbuff: preserve shared-frag marker during coalescing
- net: skbuff: propagate shared-frag marker through frag-transfer helpers
* net/rds: reset op_nents when zerocopy page pin fails (LP: #2153962)
- net/rds: reset op_nents when zerocopy page pin fails
* CVE-2026-46333
- ptrace: slightly saner 'get_dumpable()' logic
* CVE-2026-43500
- rxrpc: Fix conn-level packet handling to unshare RESPONSE packets
- rxrpc: Parse received packets before dealing with timeouts
- rxrpc: Fix potential UAF after skb_unshare() failure
- rxrpc: Fix rxrpc_input_call_event() to only unshare DATA packets
- rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
* CVE-2026-31676 // CVE-2026-43500
- rxrpc: only handle RESPONSE during service challenge
* CVE-2026-43284
- xfrm: esp: avoid in-place decrypt on shared skb frags
-- Manuel Diewald <manuel.diewald@canonical.com> Tue, 26 May 2026 14:15:46 +0200
linux-hwe-6.8 (6.8.0-117.117~22.04.1) jammy; urgency=medium
* jammy/linux-hwe-6.8: 6.8.0-117.117~22.04.1 -proposed tracker (LP: #2151068)
[ Ubuntu: 6.8.0-117.117 ]
* noble/linux: 6.8.0-117.117 -proposed tracker (LP: #2151070)
* CVE-2026-31419
- net: bonding: fix use-after-free in bond_xmit_broadcast()
* CVE-2026-31431
- crypto: scatterwalk - Backport memcpy_sglist()
- crypto: algif_aead - use memcpy_sglist() instead of null skcipher
- crypto: algif_aead - Revert to operating out-of-place
- crypto: algif_aead - snapshot IV for async AEAD requests
- crypto: authenc - use memcpy_sglist() instead of null skcipher
- crypto: authencesn - Do not place hiseq at end of dst for out-of-place
decryption
- crypto: authencesn - Fix src offset when decrypting in-place
- crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl
- crypto: algif_aead - Fix minimum RX size check for decryption
* CVE-2026-31533
- net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
* CVE-2026-31504
- net: fix fanout UAF in packet_release() via NETDEV_UP race
-- Manuel Diewald <manuel.diewald@canonical.com> Wed, 06 May 2026 15:19:52 +0200
linux-hwe-6.8 (6.8.0-116.116~22.04.1) jammy; urgency=medium
* jammy/linux-hwe-6.8: 6.8.0-116.116~22.04.1 -proposed tracker (LP: #2150046)
[ Ubuntu: 6.8.0-116.116 ]
* noble/linux: 6.8.0-116.116 -proposed tracker (LP: #2150048)
* Linux kernel 6.17.0-22.22 breaks amdxdna (LP: #2149766)
- Revert "iommu: disable SVA when CONFIG_X86 is set"
* Revert "netfilter: conntrack: fix erronous removal of offload bit"
(LP: #2149762)
- Revert "netfilter: conntrack: fix erronous removal of offload bit"
-- Stefan Bader <stefan.bader@canonical.com> Fri, 24 Apr 2026 15:53:11 +0200
linux-hwe-6.8 (6.8.0-114.114~22.04.1) jammy; urgency=medium
* jammy/linux-hwe-6.8: 6.8.0-114.114~22.04.1 -proposed tracker (LP: #2147980)
[ Ubuntu: 6.8.0-114.114 ]
* noble/linux: 6.8.0-114.114 -proposed tracker (LP: #2148397)
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465)
- SAUCE: Fix skb_vlan_inet_prepare() usage
[ Ubuntu: 6.8.0-112.112 ]
* noble/linux: 6.8.0-112.112 -proposed tracker (LP: #2147982)
* Canonical Kmod 2025 key rotation (LP: #2147447)
- [Packaging] ubuntu-compatible-signing -- make Ubuntu-Compatible-Signing
extensible
- [Packaging] ubuntu-compatible-signing -- allow consumption of positive
certs
- [Packaging] ubuntu-compatible-signing -- report the livepatch:2025 key
- [Config] prepare for Canonical Kmod key rotation
- [Packaging] ubuntu-compatible-signing -- report the kmod:2025 key
* Remount ext4 to readonly with data=journal mode may dump call trace
(LP: #2147400)
- ext4: fix stale xarray tags after writeback
* Compile error due to nonexistent struct member with CONFIG_PCI_EPF_TEST
(LP: #2147065)
- SAUCE: Revert "PCI: endpoint: pci-epf-test: Limit PCIe BAR size for
fixed BARs"
* BUG: kernel NULL pointer dereference in amdgpu (LP: #2144577)
- drm/amdgpu: validate the flush_gpu_tlb_pasid()
- drm/amdgpu: Fix validating flush_gpu_tlb_pasid()
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841)
- x86/kfence: fix booting on 32bit non-PAE systems
- platform/x86: intel_telemetry: Fix swapped arrays in PSS output
- pmdomain: qcom: rpmpd: fix off-by-one error in clamping to the highest
state
- pmdomain: imx8mp-blk-ctrl: Keep gpc power domain on for system wakeup
- pmdomain: imx: gpcv2: Fix the imx8mm gpu hang due to wrong adb400 reset
- pmdomain: imx8mp-blk-ctrl: Keep usb phy power domain on for system
wakeup
- rbd: check for EOD after exclusive lock is ensured to be held
- ARM: 9468/1: fix memset64() on big-endian
- hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
- binder: fix BR_FROZEN_REPLY error log
- binderfs: fix ida_alloc_max() upper bound
- KVM: selftests: Add -U_FORTIFY_SOURCE to avoid some unpredictable test
failures
- tracing: Fix ftrace event field alignments
- net: usb: sr9700: support devices with virtual driver CD
- block,bfq: fix aux stat accumulation destination
- LoongArch: Set correct protection_map[] for VM_NONE/VM_SHARED
- HID: intel-ish-hid: Update ishtp bus match to support device ID table
- HID: multitouch: add MT_QUIRK_STICKY_FINGERS to MT_CLS_VTL
- HID: intel-ish-hid: Reset enum_devices_done before enumeration
- HID: playstation: Center initial joystick axes to prevent spurious
events
- ALSA: hda/realtek: add HP Laptop 15s-eq1xxx mute LED quirk
- netfilter: replace -EEXIST with -EBUSY
- HID: quirks: Add another Chicony HP 5MP Cameras to hid_ignore_list
- HID: Apply quirk HID_QUIRK_ALWAYS_POLL to Edifier QR30 (2d99:a101)
- ring-buffer: Avoid softlockup in ring_buffer_resize() during memory free
- wifi: mac80211: collect station statistics earlier when disconnect
- ASoC: davinci-evm: Fix reference leak in davinci_evm_probe
- ASoC: amd: yc: Fix microphone on ASUS M6500RE
- ASoC: tlv320adcx140: Propagate error codes during probe
- spi: hisi-kunpeng: Fixed the wrong debugfs node name in hisi_spi debugfs
initialization
- wifi: cfg80211: Fix bitrate calculation overflow for HE rates
- ALSA: hda/realtek: Fix headset mic for TongFang X6AR55xU
- wifi: mac80211: correctly check if CSA is active
- wifi: mac80211: don't increment crypto_tx_tailroom_needed_cnt twice
- platform/x86: intel_telemetry: Fix PSS event register mask
- platform/x86: hp-bioscfg: Skip empty attribute names
- net: add skb_header_pointer_careful() helper
- net: don't touch dev->stats in BPF redirect paths
- tipc: use kfree_sensitive() for session key material
- net: ethernet: adi: adin1110: Check return value of
devm_gpiod_get_optional() in adin1110_check_spi()
- drm/mgag200: fix mgag200_bmc_stop_scanout()
- hwmon: (occ) Mark occ_init_attribute() as __printf
- ipv6: Fix ECMP sibling count mismatch when clearing RTF_ADDRCONF
- gve: Correct ethtool rx_dropped calculation
- spi: tegra210-quad: Return IRQ_HANDLED when timeout already processed
transfer
- spi: tegra210-quad: Move curr_xfer read inside spinlock
- spi: tegra210-quad: Protect curr_xfer assignment in
tegra_qspi_setup_transfer_one
- spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer
- spi: tegra210-quad: Protect curr_xfer clearing in
tegra_qspi_non_combined_seq_xfer
- spi: tegra114: Preserve SPI mode bits in def_command1_reg
- ALSA: hda/realtek: Really fix headset mic for TongFang X6AR55xU.
- PCI/ERR: Ensure error recoverability at all times
- ALSA: hda/realtek: Add quirk for Acer Nitro AN517-55
- PCI: qcom: Remove ASPM L0s support for MSM8996 SoC
- HID: logitech: add HID++ support for Logitech MX Anywhere 3S
- ALSA: hda/realtek: ALC269 fixup for Lenovo Yoga Book 9i 13IRU8 audio
- net: phy: add phy_interface_weight()
- net: phy: add phy_interface_copy()
- net: sfp: pre-parse the module support
- net: sfp: enhance quirk for Fibrestore 2.5G copper SFP module
- net: sfp: convert sfp quirks to modify struct sfp_module_support
- net: sfp: Fix quirk for Ubiquiti U-Fiber Instant SFP module
- drm/amd/display: fix wrong color value mapping on MCM shaper LUT
- drm/xe/query: Fix topology query pointer advance
- ALSA: usb-audio: fix broken logic in snd_audigy2nx_led_update()
- gpiolib-acpi: Update file references in the Documentation and
MAINTAINERS
- Upstream stable to v6.6.124, v6.12.70
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23214
- btrfs: reject new transactions if the fs is fully read-only
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23213
- drm/amd/pm: Disable MMIO access during SMU Mode 1 reset
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2025-71225
- md: suspend array while updating raid_disks via sysfs
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2025-68823
- ublk: fix deadlock when reading partition table
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23191
- ALSA: aloop: Fix racy access at PCM trigger
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23215
- x86/vmware: Fix hypercall clobbers
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23182
- spi: tegra: Fix a memory leak in tegra_slink_probe()
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23190
- ASoC: amd: fix memory leak in acp3x pdm dma ops
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23254
- net: gro: fix outer network offset
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23180
- dpaa2-switch: add bounds check for if_id in IRQ handler
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23256
- net: liquidio: Fix off-by-one error in VF setup_nic_devices() cleanup
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23257
- net: liquidio: Fix off-by-one error in PF setup_nic_devices() cleanup
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23258
- net: liquidio: Initialize netdev pointer before queue setup
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23206
- dpaa2-switch: prevent ZERO_SIZE_PTR dereference when num_ifs is zero
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23204
- net/sched: cls_u32: use skb_header_pointer_careful()
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23205
- smb/client: fix memory leak in smb2_open_file()
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23176
- platform/x86: toshiba_haps: Fix memory leaks in add/remove routines
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23216
- scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count()
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23193
- scsi: target: iscsi: Fix use-after-free in
iscsit_dec_session_usage_count()
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23260
- regmap: maple: free entry on mas_store_gfp() failure
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23179
- nvmet-tcp: fixup hang in nvmet_tcp_listen_data_ready()
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23261
- nvme-fc: release admin tagset if init fails
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23178
- HID: i2c-hid: fix potential buffer overflow in i2c_hid_get_report()
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2025-71268
- btrfs: fix reservation leak in some error paths when inserting inline
extent
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2025-71270
- LoongArch: Enable exception fixup for specific ADE subcode
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2025-71220
- smb/server: call ksmbd_session_rpc_close() on error path in
create_smb2_pipe()
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2025-71222
- wifi: wlcore: ensure skb headroom before skb_push
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2025-71224
- wifi: mac80211: ocb: skip rx_no_sta when interface is not joined
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23262
- gve: Fix stats report corruption on queue count change
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2025-38201
- netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23198
- KVM: Don't clobber irqfd routing type when deassigning irqfd
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23264
- Revert "drm/amd: Check if ASPM is enabled from PCIe subsystem"
* Noble update: upstream stable patchset 2026-04-10 (LP: #2147841) //
CVE-2026-23187
- pmdomain: imx8m-blk-ctrl: fix out-of-range access of bc->domains
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543)
- net/mlx5: Fix memory leak in esw_acl_ingress_lgcy_setup()
- can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
- net: bcmasp: fix early exit leak with fixed phy
- net: mvpp2: cls: Fix memory leak in mvpp2_ethtool_cls_rule_ins()
- ipv6: use the right ifindex when replying to icmpv6 from localhost
- ice: stop counting UDP csum mismatch as rx_errors
- net/mlx5e: Report rx_discards_phy via rx_dropped
- net/mlx5e: Account for netdev stats in ndo_get_stats64
- net: bridge: fix static key check
- net/mlx5e: Skip ESN replay window setup for IPsec crypto offload
- scsi: firewire: sbp-target: Fix overflow in sbp_make_tpg()
- ASoC: Intel: sof_es8336: fix headphone GPIO logic inversion
- gpiolib: acpi: use BIT_ULL() for u64 mask in address space handler
- dma/pool: distinguish between missing and exhausted atomic pools
- pinctrl: meson: mark the GPIO controller as sleeping
- riscv: compat: fix COMPAT_UTS_MACHINE definition
- rust: kbuild: give `--config-path` to `rustfmt` in `.rsi` target
- ASoC: fsl: imx-card: Do not force slot width to sample width
- scsi: be2iscsi: Fix a memory leak in beiscsi_boot_get_sinfo()
- ASoC: amd: yc: Add DMI quirk for Acer TravelMate P216-41-TCO
- gpio: pca953x: mask interrupts in irq shutdown
- scsi: qla2xxx: edif: Fix dma_free_coherent() size
- mptcp: only reset subflow errors when propagated
- selftests: mptcp: check no dup close events after error
- selftests: mptcp: check subflow errors in close events
- selftests: mptcp: join: fix local endp not being tracked
- scripts: generate_rust_analyzer: Add compiler_builtins -> core dep
- drm/amdgpu/soc21: fix xclk for APUs
- drm/amdgpu/gfx10: fix wptr reset in KGQ init
- drm/amdgpu/gfx11: fix wptr reset in KGQ init
- mm/kfence: randomize the freelist on initialization
- arm64/fpsimd: signal: Mandate SVE payload for streaming-mode state
- arm64/fpsimd: signal: Consistently read FPSIMD context
- btrfs: prevent use-after-free on page private data in
btrfs_subpage_clear_uptodate()
- net/sched: act_ife: convert comma to semicolon
- pinctrl: lpass-lpi: implement .get_direction() for the GPIO driver
- drm/msm/a6xx: fix bogus hwcg register updates
- writeback: fix 100% CPU usage when dirtytime_expire_interval is 0
- mptcp: avoid dup SUB_CLOSED events after disconnect
- ksmbd: fix recursive locking in RPC handle list access
- bpf/selftests: test_select_reuseport_kern: Remove unused header
- can: at91_can: Fix memory leak in at91_can_probe()
- net: phy: micrel: fix clk warning when removing the driver
- net/mlx5: fs, Fix inverted cap check in tx flow table root disconnect
- net/mlx5: Initialize events outside devlink lock
- net/mlx5: Fix vhca_id access call trace use before alloc
- bcache: fix improper use of bi_end_io
- bcache: use bio cloning for detached device requests
- bcache: fix I/O accounting leak in detached_dev_do_request
- gpio: rockchip: Stop calling pinctrl for set_direction
- mm/memory-failure: improve memory failure action_result messages
- mm/memory-failure: fix redundant updates for already poisoned pages
- mm/memory-failure: fix missing ->mf_stats count in hugetlb poison
- mm/memory-failure: teach kill_accessing_process to accept hugetlb tail
page pfn
- gpiolib: acpi: Fix potential out-of-boundary left shift
- rust: kbuild: support `-Cjump-tables=n` for Rust 1.93.0
- pinctrl: qcom: sm8350-lpass-lpi: Merge with SC7280 to fix I2S2 and SWR
TX pins
- [Config] remove PINCTRL_SM8350_LPASS_LPI
- Upstream stable to v6.6.123, v6.12.69
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23148
- nvmet: fix race in nvmet_bio_done() leading to NULL pointer dereference
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23166
- ice: Fix NULL pointer dereference in ice_vsi_set_napi_queues
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23151
- Bluetooth: MGMT: Fix memory leak in set_ssp_complete
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23163
- drm/amdgpu: fix NULL pointer dereference in
amdgpu_gmc_filter_faults_remove
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23159
- perf: sched: Fix perf crash with new is_user_task() helper
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2024-58096
- wifi: ath11k: add srng->lock for ath11k_hal_srng_* in monitor mode
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2025-40039
- ksmbd: Fix race condition in RPC handle list access
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23093
- ksmbd: smbd: fix dma_unmap_sg() nents
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23102
- arm64/fpsimd: signal: Fix restoration of SVE context
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23170
- drm/imx/tve: fix probe device leak
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23168
- flex_proportions: make fprop_new_period() hardirq safe
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23156
- efivarfs: fix error propagation in efivar_entry_get()
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23167
- nfc: nci: Fix race between rfkill and nci_unregister_device().
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23173
- net/mlx5e: TC, delete flows only for existing peers
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23150
- nfc: llcp: Fix memleak in nfc_llcp_send_ui_frame().
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23164
- rocker: fix memory leak in rocker_world_port_post_fini()
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23172
- net: wwan: t7xx: fix potential skb->frags overflow in RX path
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23212
- bonding: annotate data-races around slave->last_rx
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23160
- octeon_ep: Fix memory leak in octep_device_setup()
* Noble update: upstream stable patchset 2026-04-08 (LP: #2147543) //
CVE-2026-23146
- Bluetooth: hci_uart: fix null-ptr-deref in hci_uart_write_work
* CVE-2026-23394
- af_unix: Give up GC if MSG_PEEK intervened.
* [SRU] MIPI camera is not working after upgrading to 6.17-oem
(LP: #2145171)
- SAUCE: ACPI: respect items already in honor_dep before skipping
* ADATA SU680 causes repeated SATA resets and I/O errors on Ubuntu unless
link power management is forced to max_performance (LP: #2144060)
- ata: libata-core: disable LPM on ADATA SU680 SSD
* intel_idle: add Clearwater Forest SoC support (LP: #2144006)
- intel_idle: add Clearwater Forest SoC support
* Noble kernel 6.8.0-108 does not compile when KASAN enabled (LP: #2144914)
- mm/kasan: fix incorrect unpoisoning in vrealloc for KASAN
* Generic noble linux throws warning from file tegra-i2c.c (LP: #2143152)
- i2c: tegra: Use internal reset when reset property is not available
* [SRU] Duplicated entries in /proc/<pid>/mountinfo (LP: #2143083)
- namespace: fix proc mount iteration
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465)
- firmware: imx: scu-irq: Set mu_resource_id before get handle
- efi/cper: Fix cper_bits_to_str buffer handling and return value
- ASoC: codecs: wsa884x: fix codec initialisation
- xfrm: Fix inner mode lookup in tunnel mode GSO segmentation
- net: bridge: annotate data-races around fdb->{updated,used}
- net: update netdev_lock_{type,name}
- vsock/test: add a final full barrier after run all tests
- net/mlx5e: Restore destroying state bit after profile cleanup
- btrfs: store fs_info in space_info
- btrfs: factor out init_space_info() from create_space_info()
- btrfs: factor out check_removing_space_info() from
btrfs_free_block_groups()
- btrfs: introduce btrfs_space_info sub-group
- btrfs: fix memory leaks in create_space_info() error paths
- selftests: drv-net: fix RPS mask handling for high CPU numbers
- ASoC: tlv320adcx140: fix word length
- textsearch: describe @list member in ts_ops search
- mm, kfence: describe @slab parameter in __kfence_obj_info()
- dmaengine: xilinx_dma: Fix uninitialized addr_width when
"xlnx,addrwidth" property is missing
- phy: fsl-imx8mq-usb: Clear the PCS_TX_SWING_FULL field before using it
- phy: phy-snps-eusb2: refactor constructs names
- phy: drop probe registration printks
- phy: broadcom: ns-usb3: Fix Wvoid-pointer-to-enum-cast warning (again)
- i2c: qcom-geni: make sure I2C hub controllers can't use SE DMA
- HID: usbhid: paper over wrong bNumDescriptor field
- scsi: core: Fix error handler encryption support
- ALSA: pcm: Improve the fix for race of buffer access at PCM OSS layer
- can: ctucanfd: fix SSP_SRC in cases when bit-rate is higher than 1 MBit.
- x86/kaslr: Recognize all ZONE_DEVICE users as physaddr consumers
- phy: rockchip: inno-usb2: fix communication disruption in gadget mode
- phy: freescale: imx8m-pcie: assert phy reset during power on
- phy: rockchip: inno-usb2: fix disconnection in gadget mode
- phy: tegra: xusb: Explicitly configure HS_DISCON_LEVEL to 0x7
- usb: dwc3: Check for USB4 IP_NAME
- usb: core: add USB_QUIRK_NO_BOS for devices that hang on BOS descriptor
- USB: OHCI/UHCI: Add soft dependencies on ehci_platform
- USB: serial: option: add Telit LE910 MBIM composition
- USB: serial: ftdi_sio: add support for PICAXE AXE027 cable
- nvme-pci: disable secondary temp for Wodposit WPBSNM8
- hrtimer: Fix softirq base check in update_needs_ipi()
- EDAC/x38: Fix a resource leak in x38_probe1()
- EDAC/i3200: Fix a resource leak in i3200_probe1()
- tcpm: allow looking for role_sw device in the main node
- x86/resctrl: Add missing resctrl initialization for Hygon
- x86/resctrl: Fix memory bandwidth counter width for Hygon
- mm/page_alloc: make percpu_pagelist_high_fraction reads lock-free
- LoongArch: Fix PMU counter allocation for mixed-type event groups
- drm/amd/display: Bump the HDMI clock to 340MHz
- drm/amd: Clean up kfd node on surprise disconnect
- drm/amdkfd: fix a memory leak in device_queue_manager_init()
- drm/nouveau/disp/nv50-: Set lock_core in curs507a_prepare
- drm/vmwgfx: Fix an error return check in vmw_compat_shader_add()
- dmaengine: apple-admac: Add "apple,t8103-admac" compatible
- dmaengine: sh: rz-dmac: Fix rz_dmac_terminate_all()
- dmaengine: ti: dma-crossbar: fix device leak on dra7x route allocation
- dmaengine: ti: k3-udma: fix device leak on udma lookup
- io_uring: move local task_work in exit cancel loop
- posix-clock: Store file pointer in struct posix_clock_context
- ptp: Add PHC file mode checks. Allow RO adjtime() without FMODE_WRITE.
- selftest/ptp: update ptp selftest to exercise the gettimex options
- testptp: Add option to open PHC in readonly mode
- arm64: dts: qcom: sc8280xp: Add missing VDD_MXC links
- hyperv-tlfs: Change prefix of generic HV_REGISTER_* MSRs to HV_MSR_*
- Drivers: hv: Always do Hyper-V panic notification in hv_kmsg_dump()
- btrfs: fix missing fields in superblock backup with BLOCK_GROUP_TREE
- dt-bindings: power: qcom,rpmpd: document the SM8750 RPMh Power Domains
- dt-bindings: power: qcom,rpmpd: add Turbo L5 corner
- dt-bindings: power: qcom-rpmpd: split RPMh domains definitions
- dt-bindings: power: qcom,rpmpd: Add SC8280XP_MXC_AO
- pmdomain: qcom: rpmhpd: Add MXC to SC8280XP
- ata: libata: Add cpr_log to ata_dev_print_features() early return
- ata: libata-core: Introduce ata_dev_config_lpm()
- ata: libata: Call ata_dev_config_lpm() for ATAPI devices
- ata: libata: Print features also for ATAPI devices
- ice: initialize ring_stats->syncp
- ice: Avoid detrimental cleanup for bond during interface stop
- igc: fix race condition in TX timestamp read for register 0
- net: usb: dm9601: remove broken SR9700 support
- selftests: net: fib-onlink-tests: Convert to use namespaces by default
- can: gs_usb: gs_usb_receive_bulk_callback(): unanchor URL on
usb_submit_urb() error
- amd-xgbe: avoid misleading per-packet error log
- tools: ynl: Specify --no-line-number in ynl-regen.sh.
- veth: fix data race in veth_get_ethtool_stats
- octeontx2: cn10k: fix RX flowid TCAM mask handling
- serial: 8250_pci: Fix broken RS485 for F81504/508/512
- comedi: dmm32at: serialize use of paged registers
- w1: fix redundant counter decrement in w1_attach_slave_device()
- Revert "nfc/nci: Add the inconsistency check between the input data
length and count"
- Input: i8042 - add quirks for MECHREVO Wujie 15X Pro
- Input: i8042 - add quirk for ASUS Zenbook UX425QA_UM425QA
- scsi: storvsc: Process unsupported MODE_SENSE_10
- arm64: dts: rockchip: remove dangerous max-link-speed from helios64
- arm64: dts: rockchip: Fix voltage threshold for volume keys for
Pinephone Pro
- x86/kfence: avoid writing L1TF-vulnerable PTEs
- comedi: Fix getting range information for subdevices 16 to 255
- iio: adc: ad7280a: handle spi_setup() errors in probe()
- kconfig: fix static linking of nconf
- riscv: clocksource: Fix stimecmp update hazard on RV32
- ALSA: usb: Increase volume range that triggers a warning
- net: hns3: fix data race in hns3_fetch_stats
- be2net: fix data race in be_get_new_eqd
- net: hns3: fix wrong GENMASK() for HCLGE_FD_AD_COUNTER_NUM_M
- net: hns3: fix the HCLGE_FD_AD_NXT_KEY error setting issue
- usbnet: limit max_mtu based on device's hard_mtu
- drm/amd/pm: Don't clear SI SMC table when setting power limit
- drm/amd/pm: Workaround SI powertune issue on Radeon 430 (v2)
- selftests: net: amt: wait longer for connection before sending packets
- net: dsa: fix off-by-one in maximum bridge ID determination
- octeontx2-af: Fix error handling
- net: openvswitch: fix data race in ovs_vport_get_upcall_stats
- vsock/test: fix seqpacket message bounds test
- x86: make page fault handling disable interrupts properly
- of: fix reference count leak in of_alias_scan()
- of: platform: Use default match table for /firmware
- iio: accel: iis328dq: fix gain values
- iio: adc: ad9467: fix ad9434 vref mask
- iio: chemical: scd4x: fix reported channel endianness
- iio: dac: ad5686: add AD5695R to ad5686_chip_info_tbl
- mmc: rtsx_pci_sdmmc: implement sdmmc_card_busy function
- wifi: mwifiex: Fix a loop in mwifiex_update_ampdu_rxwinsize()
- octeontx2: Fix otx2_dma_map_page() error return code
- slimbus: core: fix runtime PM imbalance on report present
- platform/x86: hp-bioscfg: Fix automatic module loading
- perf/x86/intel: Do not enable BTS for guests
- selftests/bpf: Check for timeout in perf_link test
- mm/damon/sysfs-scheme: cleanup quotas subdirs on scheme dir setup
failure
- iio: core: add missing mutex_destroy in iio_dev_release()
- iio: core: add separate lockdep class for info_exist_lock
- mm/rmap: fix two comments related to huge_pmd_unshare()
- arm64: dts: rockchip: remove redundant max-link-speed from nanopi-r4s
- iio: adc: exynos_adc: fix OF populate on driver rebind
- dmaengine: stm32: dmamux: fix OF node leak on route allocation failure
- mm: kmsan: fix poisoning of high-order non-compound pages
- phy: phy-rockchip-inno-usb2: Use dev_err_probe() in the probe path
- ASoC: codecs: wsa881x: Drop unused version readout
- ASoC: codecs: wsa881x: fix unnecessary initialisation
- ASoC: codecs: wsa883x: fix unnecessary initialisation
- nvme-fc: rename free_ctrl callback to match name pattern
- nvme-pci: do not directly handle subsys reset fallout
- nvme: fix PCIe subsystem reset controller state transition
- net: phy: fix phy_uses_state_machine()
- pnfs/blocklayout: Fix memory leak in bl_parse_scsi()
- drm/vmwgfx: Merge vmw_bo_release and vmw_bo_free functions
- ALSA: hda/cirrus_scodec_test: Fix incorrect setup of gpiochip
- ASoC: sdw_utils: cs42l43: Enable Headphone pin for LINEOUT jack type
- selftests/landlock: Fix TCP bind(AF_UNSPEC) test case
- xfs: Fix the return value of xfs_rtcopy_summary()
- phy: ti: gmii-sel: fix regmap leak on probe failure
- LoongArch: dts: loongson-2k0500: Add default interrupt controller
address cells
- LoongArch: dts: loongson-2k1000: Add default interrupt controller
address cells
- LoongArch: dts: loongson-2k1000: Fix i2c-gpio node names
- LoongArch: dts: loongson-2k2000: Add default interrupt controller
address cells
- HID: intel-ish-hid: Use dedicated unbound workqueues to prevent resume
blocking
- HID: intel-ish-hid: Fix -Wcast-function-type-strict in
devm_ishtp_alloc_workqueue()
- xfs: set max_agbno to allow sparse alloc of last full inode chunk
- selftests/bpf: Test invalid narrower ctx load
- mm/page_alloc/vmstat: simplify refresh_cpu_vm_stats change detection
- mm/page_alloc: batch page freeing in decay_pcp_high
- ata: libata-sata: Improve link_power_management_supported sysfs
attribute
- igc: Restore default Qbv schedule when changing channels
- vsock/virtio: Coalesce only linear skb
- platform/x86/amd: Fix memory leak in wbrf_record()
- drm/imagination: Wait for FW trace update command completion
- ice: Fix persistent failure in ice_get_rxfh
- sched/fair: Fix pelt clock sync when entering idle
- drm/nouveau: add missing DCB connector types
- drm/nouveau: implement missing DCB connector types; gracefully handle
unknown connectors
- dpll: Prevent duplicate registrations
- mei: trace: treat reg parameter as string
- s390/ap: Fix wrong APQN fill calculation
- net: sfp: add potron quirk to the H-COM SPP425H-GAB4 SFP+ Stick
- gpio: cdev: Correct return code on memory allocation failure
- dmaengine: ti: k3-udma: Enable second resource range for BCDMA and
PKTDMA
- exfat: fix refcount leak in exfat_find
- accel/ivpu: Fix race condition when unbinding BOs
- btrfs: fix racy bitfield write in btrfs_clear_space_info_full()
- vsock/virtio: Move length check to callers of virtio_vsock_skb_rx_put()
- vsock/virtio: Rename virtio_vsock_alloc_skb()
- vsock/virtio: Move SKB allocation lower-bound check to callers
- vsock/virtio: Rename virtio_vsock_skb_rx_put()
- vhost/vsock: Allocate nonlinear SKBs for handling large receive buffers
- vsock/virtio: Allocate nonlinear SKBs for handling large transmit
buffers
- net: Introduce skb_copy_datagram_from_iter_full()
- vsock/virtio: Fix message iterator handling on transmit path
- Upstream stable to v6.6.122, v6.12.67, v6.12.68
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-38591
- bpf: Reject narrower access to pointer ctx fields
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23035
- net/mlx5e: Pass netdev to mlx5e_destroy_netdev instead of priv
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-22996
- net/mlx5e: Don't store mlx5e_priv in mlx5e_dev devlink priv
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23000
- net/mlx5e: Fix crash on profile change rollback failure
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23053
- NFS: Fix a deadlock involving nfs_release_folio()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23050
- pNFS: Fix a deadlock when returning a delegation during open()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23005
- x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state whenever XFD[i]=1
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2024-58097
- wifi: ath11k: fix RCU stall while reaping monitor destination ring
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-68365
- fs/ntfs3: Initialize allocated memory before use
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-37926
- ksmbd: fix use-after-free in ksmbd_session_rpc_open
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23030
- phy: rockchip: inno-usb2: Fix a double free bug in
rockchip_usb2phy_probe()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23025
- mm/page_alloc: prevent pcp corruption with SMP=n
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-71186
- dmaengine: stm32: dmamux: fix device leak on route allocation
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23078
- ALSA: scarlett2: Fix buffer overflow in config retrieval
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23142
- mm/damon/sysfs-scheme: cleanup access_pattern subdirs on scheme dir
setup failure
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23075
- can: esd_usb: esd_usb_read_bulk_callback(): fix URB memory leak
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-68725
- bpf: Do not let BPF test infra emit invalid GSO types to stack
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23097
- migrate: correct lock ordering for hugetlb file folios
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23108
- can: usb_8dev: usb_8dev_read_bulk_callback(): fix URB memory leak
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23080
- can: mcba_usb: mcba_usb_read_bulk_callback(): fix URB memory leak
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23061
- can: kvaser_usb: kvaser_usb_read_bulk_callback(): fix URB memory leak
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23058
- can: ems_usb: ems_usb_read_bulk_callback(): fix URB memory leak
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23085
- irqchip/gic-v3-its: Avoid truncating memory addresses
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23116
- pmdomain: imx8m-blk-ctrl: Remove separate rst and clk mask for 8mq vpu
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23098
- netrom: fix double-free in nr_route_frame()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23063
- uacce: ensure safe queue release with state management
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23056
- uacce: implement mremap in uacce_vm_ops to return -EPERM
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23094
- uacce: fix isolate sysfs check condition
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23096
- uacce: fix cdev handling in the cleanup path
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23091
- intel_th: fix device leak on output open()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23088
- tracing: Fix crash on synthetic stacktrace field usage
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23090
- slimbus: core: fix device reference leak on report present
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23128
- arm64: Set __nocfi on swsusp_arch_resume()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23107
- arm64/fpsimd: signal: Allocate SSVE storage when restoring ZA
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23073
- wifi: rsi: Fix memory corruption due to not set vif driver data size
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23135
- wifi: ath12k: fix dma_free_coherent() pointer
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23133
- wifi: ath10k: fix dma_free_coherent() pointer
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-71200
- mmc: sdhci-of-dwcmshc: Prevent illegal clock reduction in HS200/HS400
mode
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23089
- ALSA: usb-audio: Fix use-after-free in snd_usb_mixer_free()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23076
- ALSA: ctxfi: Fix potential OOB access in audio mixer handling
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-71199
- iio: adc: at91-sama5d2_adc: Fix potential use-after-free in sama5d2_adc
driver
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23101
- leds: led-class: Only Add LED to leds_list when it is fully ready
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23064
- net/sched: act_ife: avoid possible NULL deref
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23086
- vsock/virtio: cap TX credit to local buffer size
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23069
- vsock/virtio: fix potential underflow in virtio_transport_get_credit()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23119
- bonding: provide a net pointer to __skb_flow_dissect()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23084
- be2net: Fix NULL pointer dereference in be_cmd_get_mac_from_list
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23124
- ipv6: annotate data-race in ndisc_router_discovery()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23121
- mISDN: annotate data-race around dev->work
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23126
- netdevsim: fix a race issue related to the operation on bpf_bound_progs
list
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23059
- scsi: qla2xxx: Sanitize payload size to prevent member overflow
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23110
- scsi: core: Wake up the error handler when final completions race
against each other
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23071
- regmap: Fix race condition in hwspinlock irqsave routine
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23068
- spi: spi-sprd-adi: Fix double free in probe error path
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23123
- interconnect: debugfs: initialize src_node and dst_node to empty strings
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-71198
- iio: imu: st_lsm6dsx: fix iio_chan_spec for sensors without event
detection
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23113
- io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23062
- platform/x86: hp-bioscfg: Fix kernel panic in GET_INSTANCE_ID macro
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23131
- platform/x86: hp-bioscfg: Fix kobject warnings for empty attribute names
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23087
- scsi: xen: scsiback: Fix potential memory leak in scsiback_remove()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-71197
- w1: therm: Fix off-by-one buffer overflow in alarms_store
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23105
- net/sched: qfq: Use cl_is_active to determine whether class is active in
qfq_rm_from_ag
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23103
- ipvlan: Make the addrs_lock be per port
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23120
- l2tp: avoid one data-race in l2tp_tunnel_del_work()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23083
- fou: Don't allow 0 for FOU_ATTR_IPPROTO.
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23095
- gue: Fix skb memleak with inner IP protocol 0.
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23125
- sctp: move SCTP_CMD_ASSOC_SHKEY right after SCTP_CMD_PEER_INIT
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23099
- bonding: limit BOND_MODE_8023AD to Ethernet devices
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-71194
- btrfs: fix deadlock in wait_current_trans() due to ignored transaction
type
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-71185
- dmaengine: ti: dma-crossbar: fix device leak on am335x route allocation
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23026
- dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-71188
- dmaengine: lpc18xx-dmamux: fix device leak on route allocation
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-71163
- dmaengine: idxd: fix device leaks on compat bind and unbind
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-71189
- dmaengine: dw: dmamux: fix OF node leak on route allocation failure
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-71190
- dmaengine: bcm-sba-raid: fix device leak on probe
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-71191
- dmaengine: at_hdmac: fix device leak on of_dma_xlate()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23049
- drm/panel-simple: fix connector type for DataImage SCF0700C48GGU18 panel
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23144
- mm/damon/sysfs: cleanup attrs subdirs on context dir setup failure
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23145
- ext4: fix iloc.bh leak in ext4_xattr_inode_update_ref
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-22997
- net: can: j1939: j1939_xtp_rx_rts_session_active(): deactivate session
upon receiving the second rts
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23031
- can: gs_usb: gs_usb_receive_bulk_callback(): fix URB memory leak
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23032
- null_blk: fix kmemleak by releasing references to fault configfs items
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23033
- dmaengine: omap-dma: fix dma_pool resource leak in error paths
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-71196
- phy: stm32-usphyc: Fix off by one in probe()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-71193
- phy: qcom-qusb2: Fix NULL pointer dereference on early suspend
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-71162
- dmaengine: tegra-adma: Fix use-after-free
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2025-71195
- dmaengine: xilinx: xdma: Fix regmap max_register
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23006
- ASoC: tlv320adcx140: fix null pointer
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-22999
- net/sched: sch_qfq: do not free existing class in qfq_change_class()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23010
- ipv6: Fix use-after-free in inet6_addr_del().
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23054
- net: hv_netvsc: reject RSS hash key programming without RX indirection
table
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23011
- ipv4: ip_gre: make ipgre_header() robust
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23001
- macvlan: fix possible UAF in macvlan_forward_source()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23003
- ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23141
- btrfs: send: check for inline extents in range_is_hole_in_parent()
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-22998
- nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23037
- can: etas_es58x: allow partial RX URB allocation to succeed
* Noble update: upstream stable patchset 2026-03-26 (LP: #2146465) //
CVE-2026-23038
- pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node()
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058)
- NFSD: Fix permission check for read access to executable-only files
- atm: Fix dma_free_coherent() size
- mei: me: add nova lake point S DID
- lib/crypto: aes: Fix missing MMU protection for AES S-box
- counter: 104-quad-8: Fix incorrect return value in IRQ handler
- drm/pl111: Fix error handling in pl111_amba_probe
- drm/radeon: Remove __counted_by from ClockInfoArray.clockInfo[]
- gpio: rockchip: mark the GPIO controller as sleeping
- pinctrl: qcom: lpass-lpi: mark the GPIO controller as sleeping
- net: Add locking to protect skb->dev access in ip_output
- nfsd: Fix a regression in nfsd_setattr()
- nfsd: Fix NFSv3 atomicity bugs in nfsd_setattr()
- nfsd: set security label during create operations
- csky: fix csky_cmpxchg_fixup not working
- ARM: 9461/1: Disable HIGHPTE on PREEMPT_RT kernels
- alpha: don't reference obsolete termio struct for TC* constants
- dm-snapshot: fix 'scheduling while atomic' on real-time kernels
- NFSv4: ensure the open stateid seqid doesn't go backwards
- NFS: Fix up the automount fs_context to use the correct cred
- smb/client: fix NT_STATUS_UNABLE_TO_FREE_VM value
- smb/client: fix NT_STATUS_DEVICE_DOOR_OPEN value
- smb/client: fix NT_STATUS_NO_DATA_DETECTED value
- scsi: ipr: Enable/disable IRQD_NO_BALANCING during reset
- scsi: ufs: core: Fix EH failure after W-LUN resume error
- scsi: Revert "scsi: libsas: Fix exp-attached device scan after probe
failure scanned in again after probe failed"
- arm64: dts: add off-on-delay-us for usdhc2 regulator
- ARM: dts: imx6q-ba16: fix RTC interrupt level
- arm64: dts: imx8mp: Fix LAN8740Ai PHY reference clock on DH electronics
i.MX8M Plus DHCOM
- netfilter: nft_synproxy: avoid possible data-race on update operation
- gpio: pca953x: Add support for level-triggered interrupts
- gpio: pca953x: handle short interrupt pulses on PCAL devices
- netfilter: nf_tables: fix memory leak in nf_tables_newrule()
- bridge: fix C-VLAN preservation in 802.1ad vlan_tunnel egress
- inet: ping: Fix icmp out counting
- netdev: preserve NETIF_F_ALL_FOR_ALL across TSO updates
- net/mlx5e: Don't print error message due to invalid module
- net: wwan: iosm: Fix memory leak in ipc_mux_deinit()
- bnxt_en: Fix potential data corruption with HW GRO/LRO
- net: enetc: fix build warning when PAGE_SIZE is greater than 128K
- arp: do not assume dev_hard_header() does not change skb->head
- ALSA: ac97bus: Use guard() for mutex locks
- NFS: trace: show TIMEDOUT instead of 0x6e
- nfs_common: factor out nfs_errtbl and nfs_stat_to_errno
- NFSD: Remove NFSERR_EAGAIN
- bpf: Fix an issue in bpf_prog_test_run_xdp when page size greater than
4K
- bpf: Make variables in bpf_prog_test_run_xdp less confusing
- bpf: Support specifying linear xdp packet data size for
BPF_PROG_TEST_RUN
- powercap: fix race condition in register_control_type()
- powercap: fix sscanf() error return value handling
- ALSA: usb-audio: Update for native DSD support quirks
- ASoC: amd: yc: Add quirk for Honor MagicBook X16 2025
- ASoC: fsl_sai: Add missing registers to cache default
- scsi: sg: Fix occasional bogus elapsed time that exceeds timeout
- bpf: test_run: Fix ctx leak in bpf_prog_test_run_xdp error path
- ASoC: rockchip: Fix Wvoid-pointer-to-enum-cast warning (again)
- btrfs: tracepoints: use btrfs_root_id() to get the id of a root
- crypto: qat - fix duplicate restarting msg during AER error
- netfilter: nft_set_pipapo: fix range overlap detection
- vsock: Make accept()ed sockets use custom setsockopt()
- btrfs: only enforce free space tree if v1 cache is required for bs < ps
cases
- riscv: pgtable: Cleanup useless VA_USER_XXX definitions
- idpf: keep the netdev when a reset fails
- net: sfp: extend Potron XGSPON quirk to cover additional EEPROM variant
- ata: libata-core: Disable LPM on ST2000DM008-2FR102
- drm/amd/display: Fix DP no audio issue
- ALSA: hda/realtek: enable woofer speakers on Medion NM14LNL
- spi: cadence-quadspi: Prevent lost complete() call during indirect read
- ALSA: hda: intel-dsp-config: Prefer legacy driver as fallback
- Upstream stable to v6.6.121, v6.12.66
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2025-71184
- btrfs: fix NULL dereference on root when tracing inode eviction
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2025-71182
- can: j1939: make j1939_session_activate() fail if device is no longer
registered
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2025-71160
- netfilter: nf_tables: avoid chain re-validation if possible
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-22994
- bpf: Fix reference count leak in bpf_prog_test_run_xdp()
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-23140
- bpf, test_run: Subtract size of xdp_frame from allowed metadata size
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2025-71192
- ALSA: ac97: fix a double free in snd_ac97_controller_register()
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-23021
- net: usb: pegasus: fix memory leak in update_eth_regs_async()
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-22976
- net/sched: sch_qfq: Fix NULL deref when deactivating inactive aggregate
in qfq_reset
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-22979
- net: fix memory leak in skb_segment_list for GRO packets
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-22977
- net: sock: fix hardened usercopy panic in sock_recv_errqueue
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-22982
- net: mscc: ocelot: Fix crash when adding interface under a lag
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-23019
- net: marvell: prestera: fix NULL dereference on devlink_alloc() failure
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-23139
- netfilter: nf_conncount: update last_gc only when GC has been performed
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2025-40149
- tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2025-68803
- NFSD: NFSv4 file creation neglects setting ACL
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-23047
- libceph: make calc_target() set t->paused, not just clear it
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-23136
- libceph: reset sparse-read state in osd_fault()
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-22992
- libceph: return the handler error from mon_handle_auth_done()
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-22991
- libceph: make free_choose_arg_map() resilient to partial allocation
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-22990
- libceph: replace overzealous BUG_ON in osdmap_apply_incremental()
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-22984
- libceph: prevent potential out-of-bounds reads in handle_auth_done()
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-22978
- wifi: avoid kernel-infoleak from struct iw_point
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2025-71180
- counter: interrupt-cnt: Drop IRQF_NO_THREAD flag
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2025-71183
- btrfs: always detect conflicting inodes when logging inode refs
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-23020
- net: 3com: 3c59x: fix possible null dereference in vortex_probe1()
* Noble update: upstream stable patchset 2026-03-12 (LP: #2144058) //
CVE-2026-22980
- nfsd: provide locking for v4_end_grace
* CVE-2024-50004
- drm/amd/display: update DML2 policy
EnhancedPrefetchScheduleAccelerationFinal DCN35
* CVE-2026-23274
- netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
* CVE-2026-23351
- netfilter: nft_set_pipapo: split gc into unlink and reclaim phase
* CVE-2026-23231
- netfilter: nf_tables: fix use-after-free in nf_tables_addchain()
* macvlan: observe an RCU grace period in macvlan_common_newlink() error
path (LP: #2144380) // CVE-2026-23209
- macvlan: observe an RCU grace period in macvlan_common_newlink() error
path
* CVE-2026-23112
- nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec
-- Stefan Bader <stefan.bader@canonical.com> Thu, 16 Apr 2026 17:30:16 +0200
linux-hwe-6.8 (6.8.0-111.111~22.04.1) jammy; urgency=medium
* jammy/linux-hwe-6.8: 6.8.0-111.111~22.04.1 -proposed tracker (LP: #2147888)
[ Ubuntu: 6.8.0-111.111 ]
* noble/linux: 6.8.0-111.111 -proposed tracker (LP: #2147890)
* CVE-2026-23231
- netfilter: nf_tables: fix use-after-free in nf_tables_addchain()
* macvlan: observe an RCU grace period in macvlan_common_newlink() error
path (LP: #2144380) // CVE-2026-23209
- macvlan: observe an RCU grace period in macvlan_common_newlink() error
path
* CVE-2026-23112
- nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec
-- Stefan Bader <stefan.bader@canonical.com> Tue, 14 Apr 2026 17:37:42 +0200
linux-hwe-6.8 (6.8.0-110.110~22.04.1) jammy; urgency=medium
* jammy/linux-hwe-6.8: 6.8.0-110.110~22.04.1 -proposed tracker (LP: #2143476)
[ Ubuntu: 6.8.0-110.110 ]
* noble/linux: 6.8.0-110.110 -proposed tracker (LP: #2144887)
* ITS mitigation is not enabled on affected CPUs (LP: #2144730)
- x86/bugs: Rename CONFIG_RETPOLINE => CONFIG_MITIGATION_RETPOLINE
- x86/bugs: Rename CONFIG_RETHUNK => CONFIG_MITIGATION_RETHUNK
- [Config] rename config options RETHUNK and RETPOLINE
[ Ubuntu: 6.8.0-108.108 ]
* noble/linux: 6.8.0-108.108 -proposed tracker (LP: #2143478)
* linux-riscv-6.8 is FTBFS because of missing patches (LP: #2142235)
- riscv, bpf: Unify 32-bit sign-extension to emit_sextw
- riscv, bpf: Unify 32-bit zero-extension to emit_zextw
- riscv, bpf: Simplify sext and zext logics in branch instructions
- riscv, bpf: Add necessary Zbb instructions
- riscv, bpf: Optimize sign-extention mov insns with Zbb support
- riscv, bpf: Optimize bswap insns with Zbb support
* ADT test for linux package failed with "fatal: unable to connect to
git.launchpad.net" (LP: #2143033)
- [Packaging] d/t/ubuntu-regression-suite: use https to clone
* Coresight fails to build on 6.8.0-102 due to missing function and arg
definitions (LP: #2142337)
- SAUCE: Revert "coresight: catu: Support atclk"
- SAUCE: Revert "coresight: catu: Move ACPI support from AMBA driver to
platform driver"
- SAUCE: Revert "coresight: tmc: Support atclk"
- SAUCE: Revert "coresight: tmc: Move ACPI support from AMBA driver to
platform driver"
- SAUCE: Revert "Coresight: Set correct cs_mode for TPDM to fix disable
issue"
- SAUCE: Revert "Coresight: Set correct cs_mode for dummy source to fix
disable issue"
* efi: Fix swapped arguments to bsearch() in efi_status_to_*() SAUCE patch
(LP: #2141276)
- SAUCE efi: Fix swapped arguments to bsearch() in efi_status_to_*()
* Fix conntrack use after free when ovs hardware offload is enabled
(LP: #2139322)
- netfilter: conntrack: remove skb argument from nf_ct_refresh
- netfilter: conntrack: rework offload nf_conn timeout extension logic
- netfilter: conntrack: fix erronous removal of offload bit
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789)
- xhci: fix stale flag preventig URBs after link state error is cleared
- Revert "xfrm: destroy xfrm_state synchronously on net exit path"
- xfrm: flush all states in xfrm_state_fini
- leds: spi-byte: Use devm_led_classdev_register_ext()
- Documentation: process: Also mention Sasha Levin as stable tree
maintainer
- USB: serial: option: add Foxconn T99W760
- USB: serial: option: add Telit Cinterion FE910C04 new compositions
- USB: serial: option: move Telit 0x10c7 composition in the right place
- USB: serial: ftdi_sio: match on interface number for jtag
- serial: add support of CPCI cards
- USB: serial: belkin_sa: fix TIOCMBIS and TIOCMBIC
- USB: serial: kobil_sct: fix TIOCMBIS and TIOCMBIC
- ftrace: bpf: Fix IPMODIFY + DIRECT in modify_ftrace_direct()
- spi: xilinx: increase number of retries before declaring stall
- spi: imx: keep dma request disabled before dma transfer setup
- drm/vmwgfx: Use kref in vmw_bo_dirty
- Bluetooth: btrtl: Avoid loading the config file on security chips
- smb: fix invalid username check in smb3_fs_context_parse_param()
- ALSA: usb-audio: Add native DSD quirks for PureAudio DAC series
- HID: hid-input: Extend Elan ignore battery quirk to USB
- pinctrl: qcom: msm: Fix deadlock in pinmux configuration
- platform/x86: acer-wmi: Ignore backlight event
- HID: apple: Add SONiX AK870 PRO to non_apple_keyboards quirk list
- platform/x86: huawei-wmi: add keys for HONOR models
- platform/x86/amd: pmc: Add Lenovo Legion Go 2 to pmc quirk list
- platform/x86/amd/pmc: Add spurious_8042 to Xbox Ally
- HID: elecom: Add support for ELECOM M-XT3URBK (018F)
- LoongArch: Mask all interrupts during kexec/kdump
- samples: work around glibc redefining some of our defines wrong
- wifi: rtw88: Add USB ID 2001:3329 for D-Link AC13U rev. A1
- drm/panel: visionox-rm69299: Don't clear all mode flags
- USB: Fix descriptor count when handling invalid MBIM extended descriptor
- clk: renesas: cpg-mssr: Add missing 1ms delay into reset toggle callback
- clk: renesas: Use str_on_off() helper
- clk: renesas: Pass sub struct of cpg_mssr_priv to cpg_clk_register
- clk: renesas: cpg-mssr: Read back reset registers to assure values
latched
- HID: logitech-hidpp: Do not assume FAP in hidpp_send_message_sync()
- objtool: Fix standalone --hacks=jump_label
- objtool: Fix weak symbol detection
- sched/fair: Forfeit vruntime on yield
- irqchip/irq-bcm7038-l1: Fix section mismatch
- irqchip/irq-bcm7120-l2: Fix section mismatch
- irqchip/irq-brcmstb-l2: Fix section mismatch
- irqchip/imx-mu-msi: Fix section mismatch
- irqchip/qcom-irq-combiner: Fix section mismatch
- crypto: authenc - Correctly pass EINPROGRESS back up to the caller
- rculist: Add hlist_nulls_replace_rcu() and
hlist_nulls_replace_init_rcu()
- inet: Avoid ehash lookup race in inet_ehash_insert()
- iio: imu: st_lsm6dsx: Fix measurement unit for odr struct member
- arm64: dts: freescale: imx8mp-venice-gw7905-2x: remove duplicate usdhc1
props
- arm64: dts: imx8mm-venice-gw72xx: remove unused sdhc1 pinctrl
- arm64: dts: imx8mp-venice-gw702x: remove off-board uart
- arm64: dts: imx8mp-venice-gw702x: remove off-board sdhc1
- PCI: rcar-gen2: Drop ARM dependency from PCI_RCAR_GEN2
- uio: uio_fsl_elbc_gpcm:: Add null pointer check to
uio_fsl_elbc_gpcm_probe
- clk: qcom: camcc-sm6350: Specify Titan GDSC power domain as a parent to
other
- clk: qcom: camcc-sm6350: Fix PLL config of PLL2
- crypto: hisilicon/qm - restore original qos values
- s390/smp: Fix fallback CPU detection
- s390/ap: Don't leak debug feature files if AP instructions are not
available
- arm64: dts: ti: k3-am62p: Fix memory ranges for GPU
- firmware: imx: scu-irq: fix OF node leak in
- arm64: dts: qcom: sdm845-oneplus: Correct gpio used for slider
- phy: mscc: Fix PTP for VSC8574 and VSC8572
- sctp: Defer SCTP_DBG_OBJCNT_DEC() to sctp_destroy_sock().
- ARM: dts: renesas: gose: Remove superfluous port property
- ARM: dts: renesas: r9a06g032-rzn1d400-db: Drop invalid #cells properties
- Revert "mtd: rawnand: marvell: fix layouts"
- mtd: nand: relax ECC parameter validation check
- mtd: rawnand: lpc32xx_slc: fix GPIO descriptor leak on probe error and
remove
- task_work: Fix NMI race condition
- x86/dumpstack: Prevent KASAN false positive warnings in __show_regs()
- tools/nolibc/stdio: let perror work when NOLIBC_IGNORE_ERRNO is set
- soc: qcom: smem: fix hwspinlock resource leak in probe error paths
- pinctrl: stm32: fix hwspinlock resource leak in probe function
- i3c: fix refcount inconsistency in i3c_master_register
- i3c: master: svc: Prevent incomplete IBI transaction
- interconnect: qcom: msm8996: add missing link to SLAVE_USB_HS
- arm64: dts: qcom: msm8996: add interconnect paths to USB2 controller
- interconnect: debugfs: Fix incorrect error handling for NULL path
- perf lock contention: Load kernel map before lookup
- perf record: skip synthesize event when open evsel failed
- power: supply: cw2015: Check devm_delayed_work_autocancel() return code
- power: supply: rt9467: Return error on failure in
rt9467_set_value_from_ranges()
- power: supply: rt9467: Prevent using uninitialized local variable in
rt9467_set_value_from_ranges()
- power: supply: wm831x: Check wm831x_set_bits() return value
- power: supply: apm_power: only unset own apm_get_power_status
- scsi: target: Do not write NUL characters into ASCII configfs output
- fs/9p: Don't open remote file with APPEND mode when writeback cache is
used
- ARM: dts: am335x-netcom-plus-2xx: add missing GPIO labels
- ARM: dts: omap3: beagle-xm: Correct obsolete TWL4030 power compatible
- ARM: dts: omap3: n900: Correct obsolete TWL4030 power compatible
- x86/boot: Fix page table access in 5-level to 4-level paging transition
- efi/libstub: Fix page table access in 5-level to 4-level paging
transition
- mfd: da9055: Fix missing regmap_del_irq_chip() in error path
- ext4: correct the checking of quota files before moving extents
- perf/x86/intel: Correct large PEBS flag check
- regulator: core: disable supply if enabling main regulator fails
- scsi: stex: Fix reboot_notifier leak in probe error path
- staging: most: i2c: Drop explicit initialization of struct
i2c_device_id::driver_data to 0
- [Config] remove MOST_I2C driver
- dt-bindings: PCI: amlogic: Fix the register name of the DBI region
- RDMA/rtrs: server: Fix error handling in get_or_create_srv
- ARM: dts: stm32: stm32mp157c-phycore: Fix STMPE811 touchscreen node
properties
- ntfs3: init run lock for extend inode
- scsi: ufs: core: fix incorrect buffer duplication in
ufshcd_read_string_desc()
- cpufreq/amd-pstate: Call cppc_set_auto_sel() only for online CPUs
- powerpc/32: Fix unpaired stwcx. on interrupt exit
- wifi: cw1200: Fix potential memory leak in cw1200_bh_rx_helper()
- coresight: etm4x: Correct polling IDLE bit
- coresight: etm4x: Extract the trace unit controlling
- coresight: etm4x: Add context synchronization before enabling trace
- clk: renesas: r9a06g032: Fix memory leak in error path
- lib/vsprintf: Check pointer before dereferencing in time_and_date()
- ACPI: property: Fix fwnode refcount leak in
acpi_fwnode_graph_parse_endpoint()
- scsi: sim710: Fix resource leak by adding missing ioport_unmap() calls
- leds: netxbig: Fix GPIO descriptor leak in error paths
- PCI: keystone: Exit ks_pcie_probe() for invalid mode
- arm64: dts: rockchip: Move the EEPROM to correct I2C bus on Radxa ROCK
5A
- arm64: dts: rockchip: Add eeprom vcc-supply for Radxa ROCK 5A
- ps3disk: use memcpy_{from,to}_bvec index
- bpf: Handle return value of ftrace_set_filter_ip in register_fentry
- selftests/bpf: Fix failure paths in send_signal test
- watchdog: wdat_wdt: Fix ACPI table leak in probe function
- watchdog: starfive: Fix resource leak in probe error path
- tracefs: fix a leak in eventfs_create_events_dir()
- NFSD/blocklayout: Fix minlength check in proc_layoutget
- drm/msm/a2xx: stop over-complaining about the legacy firmware
- bpf: Improve program stats run-time calculation
- powerpc/64s/hash: Restrict stress_hpt_struct memblock region to within
RMA limit
- powerpc/64s/ptdump: Fix kernel_hash_pagetable dump for ISA v3.00 HPTE
format
- fs/ntfs3: out1 also needs to put mi
- fs/ntfs3: Prevent memory leaks in add sub record
- drm/mediatek: Fix CCORR mtk_ctm_s31_32_to_s1_n function issue
- net/ipv6: Remove expired routes with a separated list of routes.
- ipv6: clear RA flags when adding a static route
- perf arm-spe: Extend branch operations
- perf arm_spe: Fix memset subclass in operation
- pwm: bcm2835: Make sure the channel is enabled after pwm_request()
- wifi: mac80211: fix CMAC functions not handling errors
- mfd: mt6397-irq: Fix missing irq_domain_remove() in error path
- mfd: mt6358-irq: Fix missing irq_domain_remove() in error path
- phy: renesas: rcar-gen3-usb2: Fix an error handling path in
rcar_gen3_phy_usb2_probe()
- net: phy: adin1100: Fix software power-down ready condition
- cpuset: Treat cpusets in attaching as populated
- usb: chaoskey: fix locking for O_NONBLOCK
- usb: dwc2: disable platform lowlevel hw resources during shutdown
- usb: dwc2: fix hang during shutdown if set as peripheral
- usb: dwc2: fix hang during suspend if set as peripheral
- usb: raw-gadget: cap raw_io transfer length to KMALLOC_MAX_SIZE
- selftests/bpf: skip test_perf_branches_hw() on unsupported platforms
- selftests/bpf: Improve reliability of test_perf_branches_no_hw()
- crypto: ccree - Correctly handle return of sg_nents_for_len
- RISC-V: KVM: Fix guest page fault within HLV* instructions
- RDMA/bnxt_re: Fix the inline size for GenP7 devices
- firmware: stratix10-svc: fix make htmldocs warning for stratix10_svc
- staging: fbtft: core: fix potential memory leak in fbtft_probe_common()
- btrfs: fix leaf leak in an error path in btrfs_del_items()
- PCI: dwc: Fix wrong PORT_LOGIC_LTSSM_STATE_MASK definition
- drm/nouveau: restrict the flush page to a 32-bit address
- iomap: factor out a iomap_dio_done helper
- iomap: always run error completions in user context
- wifi: ieee80211: correct FILS status codes
- backlight: lp855x: Fix lp855x.h kernel-doc warnings
- iommu/arm-smmu-qcom: Enable use of all SMR groups when running bare-
metal
- RDMA/irdma: Fix data race in irdma_sc_ccq_arm
- RDMA/irdma: Fix data race in irdma_free_pble
- RDMA/irdma: Do not directly rely on IB_PD_UNSAFE_GLOBAL_RKEY
- ASoC: fsl_xcvr: clear the channel status control memory
- drm/amd/display: Fix logical vs bitwise bug in
get_embedded_panel_info_v2_1()
- hwmon: sy7636a: Fix regulator_enable resource leak on error path
- ACPI: processor_core: fix map_x2apic_id for amd-pstate on am4
- ublk: prevent invalid access with DEBUG
- ext4: improve integrity checking in __mb_check_buddy by enhancing
order-0 validation
- virtio_vdpa: fix misleading return in void function
- virtio: fix typo in virtio_device_ready() comment
- virtio: fix whitespace in virtio_config_ops
- virtio: fix virtqueue_set_affinity() docs
- vdpa/pds: use %pe for ERR_PTR() in event handler registration
- ASoC: Intel: catpt: Fix error path in hw_params()
- ARM: dts: samsung: universal_c210: turn off SDIO WLAN chip during system
suspend
- ARM: dts: samsung: exynos4210-i9100: turn off SDIO WLAN chip during
system suspend
- ARM: dts: samsung: exynos4210-trats: turn off SDIO WLAN chip during
system suspend
- ARM: dts: samsung: exynos4412-midas: turn off SDIO WLAN chip during
system suspend
- resource: replace open coded resource_intersection()
- resource: introduce is_type_match() helper and use it
- Reinstate "resource: avoid unnecessary lookups in find_next_iomem_res()"
- netfilter: flowtable: check for maximum number of encapsulations in
bridge vlan
- netfilter: nf_conncount: rework API to use sk_buff directly
- netfilter: nft_connlimit: update the count if add was skipped
- net: stmmac: fix rx limit check in stmmac_rx_zc()
- mtd: rawnand: renesas: Handle devm_pm_runtime_enable() errors
- selftests: bonding: add ipvlan over bond testing
- selftests: bonding: add delay before each xvlan_over_bond connectivity
check
- mtd: lpddr_cmds: fix signed shifts in lpddr_cmds
- remoteproc: qcom_q6v5_wcss: fix parsing of qcom,halt-regs
- md/raid5: fix IO hang when array is broken with IO inflight
- clk: keystone: fix compile testing
- perf tools: Fix split kallsyms DSO counting
- pinctrl: single: Fix PIN_CONFIG_BIAS_DISABLE handling
- pinctrl: single: Fix incorrect type for error return variable
- fbdev: ssd1307fb: fix potential page leak in ssd1307fb_probe()
- 9p: fix cache/debug options printing in v9fs_show_options
- NFS: Avoid changing nlink when file removes and attribute updates race
- fs/nls: Fix utf16 to utf8 conversion
- NFS: Initialise verifiers for visible dentries in readdir and lookup
- NFS: Initialise verifiers for visible dentries in nfs_atomic_open()
- Revert "nfs: ignore SB_RDONLY when remounting nfs"
- Revert "nfs: clear SB_RDONLY before getting superblock"
- Revert "nfs: ignore SB_RDONLY when mounting nfs"
- Expand the type of nfs_fattr->valid
- NFS: Fix inheritance of the block sizes when automounting
- fs/nls: Fix inconsistency between utf8_to_utf32() and utf32_to_utf8()
- platform/x86: asus-wmi: use brightness_set_blocking() for kbd led
- ASoC: bcm: bcm63xx-pcm-whistler: Check return value of
of_dma_configure()
- ASoC: ak4458: Disable regulator when error happens
- ASoC: ak5558: Disable regulator when error happens
- blk-mq: Abort suspend when wakeup events are pending
- block: fix comment for op_is_zone_mgmt() to include RESET_ALL
- nvme-auth: use kvfree() for memory allocated with kvcalloc()
- dma/pool: eliminate alloc_pages warning in atomic_pool_expand
- ALSA: uapi: Fix typo in asound.h comment
- rtc: gamecube: Check the return value of ioremap()
- ARM: 9464/1: fix input-only operand modification in
load_unaligned_zeropad()
- dm-raid: fix possible NULL dereference with undefined raid type
- dm log-writes: Add missing set_freezable() for freezable kthread
- efi/cper: Add a new helper function to print bitmasks
- efi/cper: Adjust infopfx size to accept an extra space
- efi/cper: align ARM CPER type with UEFI 2.9A/2.10 specs
- ocfs2: fix memory leak in ocfs2_merge_rec_left()
- LoongArch: Add machine_kexec_mask_interrupts() implementation
- net: lan743x: Allocate rings outside ZONE_DMA
- usb: gadget: tegra-xudc: Always reinitialize data toggle when clear halt
- usb: phy: Initialize struct usb_phy list_head
- ipv6: add exception routes to GC list in rt6_insert_exception
- btrfs: do not skip logging new dentries when logging a new name
- btrfs: fix a potential path leak in print_data_reloc_error()
- bpf, arm64: Do not audit capability check in do_jit()
- btrfs: fix memory leak of fs_devices in degraded seed device path
- iomap: account for unaligned end offsets when truncating read range
- sched/fair: Revert max_newidle_lb_cost bump
- x86/ptrace: Always inline trivial accessors
- ACPI: property: Use ACPI functions in acpi_graph_get_next_endpoint()
only
- cpufreq: dt-platdev: Add JH7110S SOC to the allowlist
- cpufreq: s5pv210: fix refcount leak
- cpuidle: menu: Use residency threshold in polling state override
decisions
- livepatch: Match old_sympos 0 and 1 in klp_find_func()
- fs/ntfs3: Support timestamps prior to epoch
- kbuild: Use objtree for module signing key path
- hfsplus: fix volume corruption issue for generic/070
- hfsplus: fix volume corruption issue for generic/073
- wifi: brcmfmac: Add DMI nvram filename quirk for Acer A1 840 tablet
- btrfs: scrub: always update btrfs_scrub_progress::last_physical
- gfs2: fix remote evict for read-only filesystems
- smb/server: fix return value of smb2_ioctl()
- ksmbd: use rwsem instead of rwlock for lease break
- Bluetooth: btusb: Add new VID/PID 2b89/6275 for RTL8761BUV
- Bluetooth: btusb: Add new VID/PID 13d3/3533 for RTL8821CE
- net: fec: ERR007885 Workaround for XDP TX path
- ipvlan: Ignore PACKET_LOOPBACK in handle_mode_l2()
- mlxsw: spectrum_router: Fix possible neighbour reference count leak
- broadcom: b44: prevent uninitialized value usage
- netfilter: nf_conncount: fix leaked ct in error paths
- nfc: pn533: Fix error code in pn533_acr122_poweron_rdr()
- netfilter: nf_tables: pass context structure to nft_parse_register_load
- netfilter: nf_tables: allow loads only when register is initialized
- netfilter: nf_tables: remove redundant chain validation on register
store
- net/mlx5: fw reset, clear reset requested on drain_fw_reset
- net/mlx5: Drain firmware reset in shutdown callback
- net/mlx5: fw_tracer, Handle escaped percent properly
- net/mlx5: Skip HotPlug check on sync reset using hot reset
- net/mlx5: Serialize firmware reset with devlink
- net: enetc: do not transmit redirected XDP frames when the link is down
- net: hns3: using the num_tqps to check whether tqp_index is out of range
when vf get ring info from mbx
- hwmon: (tmp401) fix overflow caused by default conversion rate value
- MIPS: Fix a reference leak bug in ip22_check_gio()
- drm/panel: sony-td4353-jdi: Enable prepare_prev_first
- x86/xen: Move Xen upcall handler
- x86/xen: Fix sparse warning in enlighten_pv.c
- spi: cadence-quadspi: Fix clock disable on probe failure path
- block: rnbd-clt: Fix leaked ID in init_dev()
- HID: input: map HID_GD_Z to ABS_DISTANCE for stylus/pen
- Input: i8042 - add TUXEDO InfinityBook Max Gen10 AMD to i8042 quirk
table
- can: gs_usb: gs_can_open(): fix error handling
- ACPI: PCC: Fix race condition by removing static qualifier
- ACPI: CPPC: Fix missing PCC check for guaranteed_perf
- mmc: sdhci-esdhc-imx: add alternate ARCH_S32 dependency to Kconfig
- dt-bindings: mmc: sdhci-of-aspeed: Switch ref to sdhci-common.yaml
- ALSA: vxpocket: Fix resource leak in vxpocket_probe error path
- ALSA: pcmcia: Fix resource leak in snd_pdacf_probe error path
- ipmi: Fix the race between __scan_channels() and deliver_response()
- ipmi: Fix __scan_channels() failing to rescan channels
- firmware: imx: scu-irq: Init workqueue before request mbox channel
- ti-sysc: allow OMAP2 and OMAP4 timers to be reserved on AM33xx
- clk: mvebu: cp110 add CLK_IGNORE_UNUSED to pcie_x10, pcie_x11 & pcie_x4
- powerpc/addnote: Fix overflow on 32-bit builds
- scsi: qla2xxx: Fix lost interrupts with qlini_mode=disabled
- scsi: qla2xxx: Fix initiator mode with qlini_mode=exclusive
- scsi: qla2xxx: Use reinit_completion on mbx_intr_comp
- fuse: Always flush the page cache before FOPEN_DIRECT_IO write
- fuse: Invalidate the page cache after FOPEN_DIRECT_IO write
- reset: fix BIT macro reference
- exfat: fix remount failure in different process environments
- usbip: Fix locking bug in RT-enabled kernels
- iio: adc: ti_am335x_adc: Limit step_avg to valid range for gcc complains
- usb: xhci: limit run_graceperiod for only usb 3.0 devices
- usb: usb-storage: No additional quirks need to be added to the EL-R12
optical drive.
- serial: sprd: Return -EPROBE_DEFER when uart clock is not ready
- libperf cpumap: Fix perf_cpu_map__max for an empty/NULL map
- i2c: designware: Disable SMBus interrupts to prevent storms from mis-
configured firmware
- nvme-fc: don't hold rport lock when putting ctrl
- platform/x86/intel/hid: Add Dell Pro Rugged 10/12 tablet to VGBS DMI
quirks
- block: rnbd-clt: Fix signedness bug in init_dev()
- vhost/vsock: improve RCU read sections around vhost_vsock_get()
- mmc: sdhci-msm: Avoid early clock doubling during HS400 transition
- lib/crypto: x86/blake2s: Fix 32-bit arg treated as 64-bit
- s390/dasd: Fix gendisk parent after copy pair swap
- block: rate-limit capacity change info log
- floppy: fix for PAGE_SIZE != 4KB
- kallsyms: Fix wrong "big" kernel symbol type read from procfs
- fs/ntfs3: fix mount failure for sparse runs in run_unpack()
- ktest.pl: Fix uninitialized var in config-bisect.pl
- ext4: clear i_state_flags when alloc inode
- ext4: fix incorrect group number assertion in mb_check_buddy
- ext4: align max orphan file size with e2fsprogs limit
- jbd2: use a per-journal lock_class_key for jbd2_trans_commit_key
- jbd2: use a weaker annotation in journal handling
- media: v4l2-mem2mem: Fix outdated documentation
- mptcp: schedule rtx timer only after pushing data
- usb: usb-storage: Maintain minimal modifications to the bcdDevice range.
- media: pvrusb2: Fix incorrect variable used in trace message
- phy: broadcom: bcm63xx-usbh: fix section mismatches
- USB: lpc32xx_udc: Fix error handling in probe
- usb: phy: isp1301: fix non-OF device reference imbalance
- usb: dwc3: of-simple: fix clock resource leak in dwc3_of_simple_probe
- usb: dwc3: keep susphy enabled during exit to avoid controller faults
- usb: renesas_usbhs: Fix a resource leak in usbhs_pipe_malloc()
- intel_th: Fix error handling in intel_th_output_open
- cpuidle: governors: teo: Drop misguided target residency check
- cpufreq: nforce2: fix reference count leak in nforce2
- NFSD: use correct reservation type in nfsd4_scsi_fence_client
- f2fs: fix age extent cache insertion skip on counter overflow
- tools/testing/nvdimm: Use per-DIMM device handle
- KVM: x86: Don't clear async #PF queue when CR0.PG is disabled (e.g. on
#SMI)
- KVM: x86: WARN if hrtimer callback for periodic APIC timer fires with
period=0
- KVM: x86: Explicitly set new periodic hrtimer expiration in
apic_timer_fn()
- KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE
- KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN
- KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation
- KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN
- KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed
VMRUN)
- KVM: nSVM: Clear exit_code_hi in VMCB when synthesizing nested VM-Exits
- xfs: fix a memory leak in xfs_buf_item_init()
- PM: runtime: Do not clear needs_force_resume with enabled runtime PM
- r8169: fix RTL8117 Wake-on-Lan in DASH mode
- nfsd: Mark variable __maybe_unused to avoid W=1 build break
- svcrdma: return 0 on success from svc_rdma_copy_inline_range
- s390/ipl: Clear SBP flag when bootprog is set
- gpio: regmap: Fix memleak in error path in gpio_regmap_register()
- drm/amd/display: Use GFP_ATOMIC in dc_create_plane_state()
- selftests: openvswitch: Fix escape chars in regexp.
- crypto: caam - Add check for kcalloc() in test_len()
- amba: tegra-ahb: Fix device leak on SMMU enable
- tracing: Fix fixed array of synthetic event
- soc: qcom: ocmem: fix device leak on lookup
- soc: amlogic: canvas: fix device leak on lookup
- rpmsg: glink: fix rpmsg device leak
- platform/x86: intel: chtwc_int33fe: don't dereference swnode args
- i2c: amd-mp2: fix reference leak in MP2 PCI device
- hwmon: (max16065) Use local variable to avoid TOCTOU
- hwmon: (w83l786ng) Convert macros to functions to avoid TOCTOU
- ARM: dts: microchip: sama5d2: fix spi flexcom fifo size to 32
- wifi: rtw88: limit indirect IO under powered off for RTL8822CS
- wifi: cfg80211: sme: store capped length in __cfg80211_connect_result()
- wifi: mac80211: do not use old MBSSID elements
- i40e: fix scheduling in set_rx_mode
- net: mdio: aspeed: add dummy read to avoid read-after-write issue
- net: openvswitch: Avoid needlessly taking the RTNL on vport destroy
- platform/x86: msi-laptop: add missing sysfs_remove_group()
- platform/x86: ibm_rtl: fix EBDA signature search pointer arithmetic
- amd-xgbe: reset retries and mode on RX adapt failures
- Revert "UBUNTU: SAUCE: selftests: net: fix "buffer overflow detected"
for tap.c"
- selftests: net: fix "buffer overflow detected" for tap.c
- genalloc.h: fix htmldocs warning
- firewire: nosy: Fix dma_free_coherent() size
- net: dsa: b53: skip multicast entries for fdb_dump()
- net: bridge: Describe @tunnel_hash member in net_bridge_vlan_group
struct
- RDMA/efa: Remove possible negative shift
- RDMA/core: Fix logic error in ib_get_gids_from_rdma_hdr()
- RDMA/bnxt_re: Fix incorrect BAR check in bnxt_qplib_map_creq_db()
- RDMA/bnxt_re: Fix IB_SEND_IP_CSUM handling in post_send
- RDMA/bnxt_re: Fix to use correct page size for PDE table
- RDMA/rtrs: Fix clt_path::max_pages_per_mr calculation
- RDMA/bnxt_re: fix dma_free_coherent() pointer
- blk-mq: don't schedule block kworker on isolated CPUs
- blk-mq: skip CPU offline notify on unmapped hctx
- selftests/ftrace: traceonoff_triggers: strip off names
- ntfs: Do not overwrite uptodate pages
- ASoC: stm32: sai: fix device leak on probe
- ASoC: stm32: sai: fix clk prepare imbalance on probe failure
- ASoC: qcom: q6apm-dai: set flags to reflect correct operation of
appl_ptr
- ASoC: qcom: q6asm-dai: perform correct state check before closing
- ASoC: qcom: q6adm: the the copp device only during last instance
- ASoC: qcom: qdsp6: q6asm-dai: set 10 ms period and buffer alignment.
- iommu/amd: Fix pci_segment memleak in alloc_pci_segment()
- iommu/apple-dart: fix device leak on of_xlate()
- iommu/exynos: fix device leak on of_xlate()
- iommu/ipmmu-vmsa: fix device leak on of_xlate()
- iommu/mediatek-v1: fix device leak on probe_device()
- iommu/mediatek-v1: fix device leaks on probe()
- iommu/mediatek: fix device leak on of_xlate()
- iommu/omap: fix device leaks on probe_device()
- iommu/qcom: fix device leak on of_xlate()
- iommu/sun50i: fix device leak on of_xlate()
- iommu/tegra: fix device leak on probe_device()
- HID: logitech-dj: Remove duplicate error logging
- PCI/PM: Reinstate clearing state_saved in legacy and !PM codepaths
- SAUCE: Revert "arm64: dts: ti: k3-j721e-sk: Add DT nodes for power
regulators"
- arm64: dts: ti: k3-j721e-sk: Fix pinmux for pin Y1 used by power
regulator
- powerpc, mm: Fix mprotect on book3s 32-bit
- leds: leds-lp50xx: Allow LED 0 to be added to module bank
- leds: leds-lp50xx: LP5009 supports 3 modules for a total of 9 LEDs
- leds: leds-lp50xx: Enable chip before any communication
- mfd: altera-sysmgr: Fix device leak on sysmgr regmap lookup
- mfd: max77620: Fix potential IRQ chip conflict when probing two devices
- media: rc: st_rc: Fix reset control resource leak
- parisc: entry.S: fix space adjustment on interruption for 64-bit
userspace
- parisc: entry: set W bit for !compat tasks in syscall_restore_rfi()
- powerpc/pseries/cmm: call balloon_devinfo_init() also without
CONFIG_BALLOON_COMPACTION
- firmware: stratix10-svc: Add mutex in stratix10 memory management
- dm-ebs: Mark full buffer dirty even on partial write
- dm-bufio: align write boundary on physical block size
- fbdev: gbefb: fix to use physical address instead of dma address
- fbdev: pxafb: Fix multiple clamped values in pxafb_adjust_timing
- fbdev: tcx.c fix mem_map to correct smem_start offset
- media: cec: Fix debugfs leak on bus_register() failure
- media: msp3400: Avoid possible out-of-bounds array accesses in
msp3400c_thread()
- media: renesas: rcar_drif: fix device node reference leak in
rcar_drif_bond_enabled
- media: samsung: exynos4-is: fix potential ABBA deadlock on init
- media: TDA1997x: Remove redundant cancel_delayed_work in probe
- media: verisilicon: Protect G2 HEVC decoder against invalid DPB index
- media: videobuf2: Fix device reference leak in vb2_dc_alloc error path
- media: vpif_capture: fix section mismatch
- media: vpif_display: fix section mismatch
- media: amphion: Cancel message work before releasing the VPU core
- media: i2c: ADV7604: Remove redundant cancel_delayed_work in probe
- media: i2c: adv7842: Remove redundant cancel_delayed_work in probe
- media: mediatek: vcodec: Fix a reference leak in
mtk_vcodec_fw_vpu_init()
- LoongArch: Add new PCI ID for pci_fixup_vgadev()
- LoongArch: Correct the calculation logic of thread_count
- LoongArch: Fix build errors for CONFIG_RANDSTRUCT
- LoongArch: Use __pmd()/__pte() for swap entry conversions
- LoongArch: Use unsigned long for _end and _text
- compiler_types.h: add "auto" as a macro for "__auto_type"
- kasan: refactor pcpu kasan vmalloc unpoison
- idr: fix idr_alloc() returning an ID out of range
- tools/mm/page_owner_sort: fix timestamp comparison for stable sorting
- samples/ftrace: Adjust LoongArch register restore order in direct calls
- fjes: Add missing iounmap in fjes_hw_init()
- LoongArch: BPF: Zero-extend bpf_tail_call() index
- nfsd: Drop the client reference in client_states_open()
- net: usb: sr9700: fix incorrect command used to write single register
- net: macb: Relocate mog_init_rings() callback from macb_mac_link_up() to
macb_open()
- drm/amdgpu: add missing lock to amdgpu_ttm_access_memory_sdma
- drm/msm/a6xx: Fix out of bound IO access in a6xx_get_gmu_registers
- drm/gma500: Remove unused helper psb_fbdev_fb_setcolreg()
- drm/mediatek: Fix device node reference leak in mtk_dp_dt_parse()
- drm/mgag200: Fix big-endian support
- drm/nouveau/dispnv50: Don't call drm_atomic_get_crtc_state() in
prepare_fb
- blk-mq: add helper for checking if one CPU is mapped to specified hctx
- mptcp: Initialise rcv_mss before calling tcp_send_active_reset() in
mptcp_do_fastclose().
- ALSA: wavefront: Use standard print API
- ALSA: wavefront: Use guard() for spin locks
- ALSA: wavefront: Clear substream pointers on close
- ext4: fix string copying in parse_apply_sb_mount_options()
- jbd2: fix the inconsistency between checksum and data in memory for
journal sb
- btrfs: don't rewrite ret from inode_permission
- mm/ksm: fix exec/fork inheritance support for prctl
- usb: ohci-nxp: Use helper function devm_clk_get_enabled()
- usb: ohci-nxp: fix device leak on probe failure
- scsi: ufs: core: Add ufshcd_update_evt_hist() for UFS suspend error
- f2fs: use f2fs_err_ratelimited() to avoid redundant logs
- ARM: dts: microchip: sama7g5: fix uart fifo size to 32
- fuse: fix readahead reclaim deadlock
- PCI: brcmstb: Fix disabling L0s capability
- lockd: fix vfs_test_lock() calls
- mm: simplify folio_expected_ref_count()
- mm: consider non-anon swap cache folios in folio_expected_ref_count()
- pmdomain: imx: Fix reference count leak in imx_gpc_probe()
- net: phy: mediatek: fix nvmem cell reference leak in
mt798x_phy_calibration
- drm/amdgpu: Forward VMID reservation errors
- drm/mediatek: Fix probe memory leak
- drm/mediatek: Fix probe resource leaks
- drm/tilcdc: request and mapp iomem with devres
- tty: introduce and use tty_port_tty_vhangup() helper
- xhci: dbgtty: fix device unregister: fixup
- usb: xhci: move link chain bit quirk checks into one helper function.
- LoongArch: Refactor register restoration in ftrace_common_return
- f2fs: remove unused GC_FAILURE_PIN
- f2fs: keep POSIX_FADV_NOREUSE ranges
- f2fs: drop inode from the donation list when the last file is closed
- f2fs: fix to propagate error from f2fs_enable_checkpoint()
- f2fs: fix to detect recoverable inode during dryrun of
find_fsync_dnodes()
- media: verisilicon: Fix CPU stalls on G2 bus error
- mm/balloon_compaction: we cannot have isolated pages in the balloon list
- mm/balloon_compaction: convert balloon_page_delete() to
balloon_page_finalize()
- powerpc/pseries/cmm: adjust BALLOON_MIGRATE when migrating pages
- KVM: nVMX: Immediately refresh APICv controls as needed on nested VM-
Exit
- media: amphion: Add a frame flush mode for decoder
- media: amphion: Make some vpu_v4l2 functions static
- media: amphion: Remove vpu_vb_is_codecconfig
- mm/damon/tests/vaddr-kunit: handle alloc failures in
damon_test_split_evenly_fail()
- mm/damon/tests/vaddr-kunit: handle alloc failures on
damon_do_test_apply_three_regions()
- sched/fair: Small cleanup to sched_balance_newidle()
- sched/fair: Small cleanup to update_newidle_cost()
- sched/fair: Proportional newidle balance
- RDMA/rxe: Fix the failure of ibv_query_device() and
ibv_query_device_ex() tests
- mm/damon/tests/vaddr-kunit: handle alloc failures on
damon_test_split_evenly_succ()
- mm/damon/tests/core-kunit: handle alloc failres in
damon_test_new_filter()
- mm/damon/tests/core-kunit: handle allocation failures in
damon_test_regions()
- mm/damon/tests/core-kunit: handle memory failure from
damon_test_target()
- mm/damon/tests/core-kunit: handle alloc failures on
damon_test_split_regions_of()
- mm/damon/tests/core-kunit: handle alloc failures on
damos_test_filter_out()
- mm/damon/tests/core-kunit: handle alloc failures in
damon_test_set_regions()
- mm/damon/tests/core-kunit: handle alloc failures in
damon_test_ops_registration()
- mm/damon/tests/core-kunit: handle alloc failure on
damon_test_set_attrs()
- virtio_console: fix order of fields cols and rows
- pwm: stm32: Always program polarity
- tty: fix tty_port_tty_*hangup() kernel-doc
- firmware: arm_scmi: Fix unused notifier-block in unregister
- ext4: filesystems without casefold feature cannot be mounted with
siphash
- drm/amdkfd: Fix GPU mappings for APU after prefetch
- wifi: rtl8xxxu: Add USB ID 2001:3328 for D-Link AN3U rev. A1
- smack: fix bug: setting task label silently ignores input garbage
- wifi: ath10k: Avoid vdev delete timeout when firmware is already down
- wifi: ath10k: Add missing include of export.h
- wifi: ath10k: move recovery check logic into a new work
- wifi: ath11k: restore register window after global reset
- dt-bindings: clock: qcom,x1e80100-gcc: Add missing video resets
- dt-bindings: clock: qcom,x1e80100-gcc: Add missing USB4 clocks/resets
- clk: qcom: gcc-x1e80100: Add missing USB4 clocks/resets
- inet: Avoid ehash lookup race in inet_twsk_hashdance_schedule()
- block/mq-deadline: Introduce dd_start_request()
- block/mq-deadline: Switch back to a single dispatch list
- perf annotate: Check return value of evsel__get_arch() properly
- arm64: dts: exynos: gs101: fix sysreg_apm reg property
- clk: qcom: camcc-sm8550: Specify Titan GDSC power domain as a parent to
other
- soc: qcom: gsbi: fix double disable caused by devm
- wifi: ath11k: fix VHT MCS assignment
- arm64: dts: qcom: sm8650: set ufs as dma coherent
- perf: Remove get_perf_callchain() init_nr argument
- bpf: Refactor stack map trace depth calculation into helper function
- perf/x86/intel/cstate: Remove PC3 support from LunarLake
- drm/imagination: Fix reference to
devm_platform_get_and_ioremap_resource()
- power: supply: rt5033_charger: Fix device node reference leaks
- power: supply: max17040: Check iio_read_channel_processed() return code
- libbpf: Fix parsing of multi-split BTF
- locktorture: Fix memory leak in param_set_cpumask()
- crypto: iaa - Fix incorrect return value in save_iaa_wq()
- drm/msm/dpu: drop dpu_hw_dsc_destroy() prototype
- leds: rgb: leds-qcom-lpg: Don't enable TRILED when configuring PWM
- RAS: Report all ARM processor CPER information to userspace
- vhost: Fix kthread worker cgroup failure handling
- vfio/pci: Use RCU for error/request triggers to avoid circular locking
- net: phy: aquantia: check for NVMEM deferral
- perf tools: Mark split kallsyms DSOs as loaded
- perf hist: In init, ensure mem_info is put on error paths
- sched/fair: Fix unfairness caused by stalled tg_load_avg_contrib when
the last task migrates out
- platform/x86:intel/pmc: Update Arrow Lake telemetry GUID
- nfs/vfs: discard d_exact_alias()
- NFS: Initialise verifiers for visible dentries in
_nfs4_open_and_get_state
- drm/plane: Fix IS_ERR() vs NULL check in
drm_plane_create_hotspot_properties()
- regulator: fixed: Rely on the core freeing the enable GPIO
- drm/nouveau: refactor deprecated strcpy
- drm/amdkfd: Use huge page size to check split svm range alignment
- block: return unsigned int from queue_dma_alignment
- fs/ntfs3: check for shutdown in fsync
- wifi: rtl8xxxu: Fix HT40 channel config for RTL8192CU, RTL8723AU
- wifi: cfg80211: use cfg80211_leave() in iftype change
- wifi: mt76: mt792x: fix wifi init fail by setting MCU_RUNNING after CLC
load
- gfs2: Fix "gfs2: Switch to wait_event in gfs2_quotad"
- Bluetooth: btusb: MT7922: Add VID/PID 0489/e170
- Bluetooth: btusb: MT7920: Add VID/PID 0489/e135
- Bluetooth: btusb: Add new VID/PID 0x0489/0xE12F for RTL8852BE-VT
- netfilter: nf_nat: remove bogus direction check
- iommufd/selftest: Add coverage for reporting max_pasid_log2 via
IOMMU_HW_INFO
- iommufd/selftest: Update hw_info coverage for an input data_type
- iommufd/selftest: Make it clearer to gcc that the access is not out of
bounds
- hwmon: (dell-smm) Limit fan multiplier to avoid overflow
- drm/xe: Restore engine registers before restarting schedulers after GT
reset
- mmc: sdhci-of-arasan: Increase CD stable timeout to 2 seconds
- scsi: ufs: host: mediatek: Fix shutdown/suspend race condition
- scsi: smartpqi: Add support for Hurray Data new controller PCI device
- exfat: zero out post-EOF page cache on file extension
- x86/mce: Do not clear bank's poll bit in mce_poll_banks on AMD SMCA
systems
- perf: arm_cspmu: fix error handling in arm_cspmu_impl_unregister()
- wifi: mt76: Fix DTS power-limits on little endian systems
- usb: gadget: lpc32xx_udc: fix clock imbalance in error path
- mei: gsc: add dependency on Xe driver
- serial: sh-sci: Check that the DMA cookie is valid
- powerpc: Add reloc_offset() to font bitmap pointer used for
bootx_printf()
- xfs: fix stupid compiler warning
- NFSD: Clear SECLABEL in the suppattr_exclcreat bitmap
- drm/amd/display: Fix scratch registers offsets for DCN35
- drm/displayid: pass iter to drm_find_displayid_extension()
- KVM: arm64: Initialize SCTLR_EL1 in __kvm_hyp_init_cpu()
- soc: apple: mailbox: fix device leak on lookup
- interconnect: qcom: sdx75: Drop QPIC interconnect and BCM nodes
- i40e: validate ring_len parameter against hardware-specific values
- idpf: reduce mbx_task schedule delay to 300us
- platform/mellanox: mlxbf-pmc: Remove trailing whitespaces from event
names
- net: dsa: fix missing put_device() in dsa_tree_find_first_conduit()
- vfio/pds: Fix memory leak in pds_vfio_dirty_enable()
- md: Fix static checker warning in analyze_sbs
- ASoC: codecs: lpass-tx-macro: fix SM6115 support
- iommu/amd: Propagate the error code returned by __modify_irte_ga() in
modify_irte_ga()
- mtd: mtdpart: ignore error -ENOENT from parsers on subpartitions
- mtd: spi-nor: winbond: Add support for W25Q01NWxxIQ chips
- mtd: spi-nor: winbond: Add support for W25Q01NWxxIM chips
- mtd: spi-nor: winbond: Add support for W25Q02NWxxIM chips
- mtd: spi-nor: winbond: Add support for W25H512NWxxAM chips
- mtd: spi-nor: winbond: Add support for W25H01NWxxAM chips
- mtd: spi-nor: winbond: Add support for W25H02NWxxAM chips
- perf/x86/amd/uncore: Fix the return value of amd_uncore_df_event_init()
on error
- mm/damon/tests/sysfs-kunit: handle alloc failures on
damon_sysfs_test_add_targets()
- mm/damon/tests/core-kunit: handle alloc failures on
damon_test_split_at()
- mm/damon/tests/core-kunit: handle memory alloc failure from
damon_test_aggregate()
- mm/damon/tests/core-kunit: handle alloc failures on
dasmon_test_merge_regions_of()
- mm/damon/tests/core-kunit: handle alloc failures on
damon_test_merge_two()
- mm/damon/tests/core-kunit: handle alloc failures in
damon_test_update_monitoring_result()
- kasan: unpoison vms[area] addresses with a common tag
- drm/amdgpu/gmc11: add amdgpu_vm_handle_fault() handling
- drm/edid: add DRM_EDID_IDENT_INIT() to initialize struct drm_edid_ident
- drm/mediatek: Fix probe device leaks
- drm/i915: Fix format string truncation warning
- drm/xe/bo: Don't include the CCS metadata in the dma-buf sg-table
- drm/xe: Adjust long-running workload timeslices to reasonable values
- drm/xe: Use usleep_range for accurate long-running workload timeslicing
- drm/xe: Drop preempt-fences when destroying imported dma-bufs.
- drm/imagination: Disallow exporting of PM/FW protected objects
- gfs2: fix freeze error handling
- sched/eevdf: Remove min_vruntime_copy
- sched/eevdf: Fix min_vruntime vs avg_vruntime
- serial: core: fix OF node leak
- serial: core: Restore sysfs fwnode information
- mptcp: pm: ignore unknown endpoint flags
- f2fs: clear SBI_POR_DOING before initing inmem curseg
- f2fs: add timeout in f2fs_enable_checkpoint()
- f2fs: dump more information for f2fs_{enable,disable}_checkpoint()
- gpiolib: acpi: Switch to use enum in acpi_gpio_in_ignore_list()
- gpiolib: acpi: Handle deferred list via new API
- gpiolib: acpi: Add acpi_gpio_need_run_edge_events_on_boot() getter
- gpiolib: acpi: Move quirks to a separate file
- gpiolib: acpi: Add a quirk for Acer Nitro V15
- gpiolib: acpi: Add quirk for ASUS ProArt PX13
- gpiolib: acpi: Add quirk for Dell Precision 7780
- serial: core: Fix serial device initialization
- media: i2c: imx219: Fix 1920x1080 mode to use 1:1 pixel aspect ratio
- wifi: mt76: mt7925: fix CLC command timeout when suspend/resume
- soundwire: stream: extend sdw_alloc_stream() to take 'type' parameter
- ASoC: qcom: sdw: fix memory leak for sdw_stream_runtime
- vfio/pci: Disable qword access to the PCI ROM bar
- iomap: allocate s_dio_done_wq for async reads as well
- mptcp: ensure context reset on disconnect()
- Upstream stable to v6.6.120, v6.12.62, v6.12.63, v6.12.64, v6.12.65
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2024-36347
- x86/microcode/AMD: Fix Entrysign revision check for Zen5/Strix Halo
- x86/microcode/AMD: Select which microcode patch to load
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-40164
- usbnet: Fix using smp_processor_id() in preemptible code warnings
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-40325
- md/raid10: wait barrier before returning discard request with REQ_NOWAIT
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68206
- netfilter: nft_ct: add seqadj extension for natted connections
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71068
- svcrdma: bound check rq_pages index in inline path
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71135
- md/raid5: fix possible null-pointer dereferences in
raid5_store_group_thread_cnt()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-38234
- sched/rt: Fix race in push_rt_task
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68811
- svcrdma: use rc_pageoff for memcpy byte offset
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68810
- KVM: Disallow toggling KVM_MEM_GUEST_MEMFD on an existing memslot
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71109
- MIPS: ftrace: Fix memory corruption when kernel is located beyond 32
bits
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68770
- bnxt_en: Fix XDP_TX path
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71072
- shmem: fix recovery on rename failures
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68374
- md: fix rcu protection in md_wakeup_thread
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68378
- bpf: Fix stackmap overflow check in __bpf_get_stackid()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2024-57795
- RDMA/rxe: Remove the direct link to net_device
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-38022
- RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device"
problem
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71140
- media: mediatek: vcodec: Use spinlock for context list protection lock
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71105
- f2fs: use global inline_xattr_slab instead of per-sb slab cache
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68772
- f2fs: fix to avoid updating compression context during writeback
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-22111
- net: Remove RTNL dance for SIOCBRADDIF and SIOCBRDELIF.
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-22022
- usb: xhci: Apply the link chain quirk on NEC isoc endpoints
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71141
- drm/tilcdc: Fix removal actions in case of failed probe
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71127
- wifi: mac80211: Discard Beacon frames to non-broadcast address
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71088
- mptcp: fallback earlier on simult connection
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71065
- f2fs: fix to avoid potential deadlock
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68345
- ALSA: hda: cs35l41: Fix NULL pointer dereference in
cs35l41_hda_read_acpi()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68344
- ALSA: wavefront: Fix integer overflow in sample size validation
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71077
- tpm: Cap the number of PCR banks
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71130
- drm/i915/gem: Zero-initialize the eb.vma array in i915_gem_do_execbuffer
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71138
- drm/msm/dpu: Add missing NULL pointer check for pingpong interface
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71083
- drm/ttm: Avoid NULL pointer deref for evicted BOs
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71079
- net: nfc: fix deadlock between nfc_unregister_device and
rfkill_fop_write
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71129
- LoongArch: BPF: Sign extend kfunc call arguments
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71093
- e1000: fix OOB in e1000_tbi_should_accept()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71084
- RDMA/cm: Fix leaking the multicast GID table reference
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71096
- RDMA/core: Check for the presence of LS_NLA_TYPE_DGID correctly
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71136
- media: adv7842: Avoid possible out-of-bounds array accesses in
adv7842_cp_log_status()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71143
- clk: samsung: exynos-clkout: Assign .num before accessing .hws
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71078
- powerpc/64s/slb: Fix SLB multihit issue during SLB preload
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71089
- iommu: disable SVA when CONFIG_X86 is set
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71081
- ASoC: stm32: sai: fix OF node leak on probe
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71153
- ksmbd: Fix memory leak in get_file_all_info()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71133
- RDMA/irdma: avoid invalid read in irdma_net_event
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71086
- net: rose: fix invalid array index in rose_kill_by_device()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71097
- ipv4: Fix reference count leak when using error routes with nexthop
objects
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71085
- ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71095
- net: stmmac: fix the crash issue for zero copy XDP_TX action
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71137
- octeontx2-pf: fix "UBSAN: shift-out-of-bounds error"
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71101
- platform/x86: hp-bioscfg: Fix out-of-bounds array access in ACPI package
parsing
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71094
- net: usb: asix: validate PHY address before use
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71132
- smc91x: fix broken irq-context in PREEMPT_RT
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71154
- net: usb: rtl8150: fix memory leak on usb_submit_urb() failure
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71091
- team: fix check for port enabled in
team_queue_override_port_prio_changed()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71098
- ip6_gre: make ip6gre_header() robust
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71082
- Bluetooth: btusb: revert use of devm_kzalloc in btusb
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71131
- crypto: seqiv - Do not use req->iv after crypto_aead_encrypt
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71087
- iavf: fix off-by-one issues in iavf_config_rss_reg()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71071
- iommu/mediatek: fix use-after-free on probe deferral
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71111
- hwmon: (w83791d) Convert macros to functions to avoid TOCTOU
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71113
- crypto: af_alg - zero initialize memory allocated via sock_kmalloc
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71149
- io_uring/poll: correctly handle io_poll_add() return value on update
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68778
- btrfs: don't log conflicting inode if it's a dir moved in the current
transaction
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71119
- powerpc/kexec: Enable SMT before waking offline CPUs
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71120
- SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in
gss_read_proxy_verf
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71148
- net/handshake: restore destructor on submit failure
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68788
- fsnotify: do not generate ACCESS/MODIFY events on child for special
files
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71125
- tracing: Do not register unsupported perf events
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71104
- KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV
timer
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71116
- libceph: make decode_pool() more resilient against corrupted osdmaps
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71121
- parisc: Do not reprogram affinitiy on ASP chip
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71102
- scs: fix a wrong parameter in __scs_magic
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68804
- platform/chrome: cros_ec_ishtp: Fix UAF after unbinding driver
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68771
- ocfs2: fix kernel BUG in ocfs2_find_victim_chain
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68808
- media: vidtv: initialize local pointers upon transfer of memory
ownership
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68769
- f2fs: fix return value of f2fs_recover_fsync_data()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71069
- f2fs: invalidate dentry cache on failed whiteout creation
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68796
- f2fs: fix to avoid updating zero-sized extent in extent cache
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71107
- f2fs: ensure node page reads complete before f2fs_put_super() finishes
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68782
- scsi: target: Reset t_task_cdb pointer in error case
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71075
- scsi: aic94xx: fix use-after-free in device removal path
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68818
- scsi: Revert "scsi: qla2xxx: Perform lockless command completion in
abort path"
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68797
- char: applicom: fix NULL pointer dereference in ac_ioctl
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68819
- media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71126
- mptcp: avoid deadlock on fallback while reinjecting
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68820
- ext4: xattr: fix null pointer deref in ext4_raw_inode()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68814
- io_uring: fix filename leak in __io_openat_prep()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71147
- KEYS: trusted: Fix a memory leak in tpm2_load_cmd
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71151
- cifs: Fix memory and information leak in smb3_reconfigure()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71108
- usb: typec: ucsi: Handle incorrect num_connectors capability
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71114
- via_wdt: fix critical boot hang due to unnamed resource allocation
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68783
- ALSA: usb-mixer: us16x08: validate meter packet indices
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68776
- net/hsr: fix NULL pointer dereference in prp_get_untagged_frame()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68773
- spi: fsl-cpm: Check length parity before switching to 16 bit mode
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68777
- Input: ti_am335x_tsc - fix off-by-one error in wire_order validation
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68806
- ksmbd: fix buffer validation by including null terminator size in EA
length
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71150
- ksmbd: Fix refcount leak when invalid session is found on session lookup
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68786
- ksmbd: skip lock-range check on equal size to avoid size==0 underflow
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68789
- hwmon: (ibmpex) fix use-after-free in high/low store
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71112
- net: hns3: add VLAN id validation before using
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71064
- net: hns3: using the num_tqps in the vf driver to apply for resources
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68775
- net/handshake: duplicate handshake cancellations leak socket
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68816
- net/mlx5: fw_tracer, Validate format string parameters
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68795
- ethtool: Avoid overflowing userspace buffer on stats query
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71122
- iommufd/selftest: Check for overflow in IOMMU_TEST_OP_ADD_RESERVED
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68815
- net/sched: ets: Remove drr class from the active list if it changes to
strict
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68799
- caif: fix integer underflow in cffrml_receive()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68813
- ipvs: fix ipv4 null-ptr-deref in route error path
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68785
- net: openvswitch: fix middle attribute validation in push_nsh() action
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68800
- mlxsw: spectrum_mr: Fix use-after-free when updating multicast route
stats
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68801
- mlxsw: spectrum_router: Fix neighbour use-after-free
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71066
- net/sched: ets: Always remove class from active list before deleting in
ets_qdisc_change
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68787
- netrom: Fix memory leak in nr_sendmsg()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68809
- ksmbd: vfs: fix race on m_flags in vfs_cache
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68817
- ksmbd: fix use-after-free in ksmbd_tree_connect_put under concurrency
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68767
- hfsplus: Verify inode mode when loading from disk
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68774
- hfsplus: fix missing hfs_bnode_get() in __hfs_bnode_create
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71067
- ntfs: set dummy blocksize to read boot_block when mounting
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-71118
- ACPICA: Avoid walking the Namespace if start_node is NULL
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68780
- sched/deadline: only set free_cpus for online runqueues
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68798
- perf/x86/amd: Check event before enable to avoid GPF
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68794
- iomap: adjust read range correctly for non-block-aligned positions
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68346
- ALSA: dice: fix buffer overflow in detect_stream_formats()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68766
- irqchip/mchp-eic: Fix error code in mchp_eic_domain_alloc()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68756
- block: Use RCU in blk_mq_[un]quiesce_tagset() instead of
set->tag_list_lock
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68753
- ALSA: firewire-motu: add bounds check in put_user loop for DSP events
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68347
- ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68764
- NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68349
- NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in
pnfs_mark_layout_stateid_invalid
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68325
- net/sched: sch_cake: Fix incorrect qlen reduction in cake_drop
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68354
- regulator: core: Protect regulator_supply_alias_list with
regulator_list_mutex
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68758
- backlight: led-bl: Add devlink to supplier LEDs
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68765
- mt76: mt7615: Fix memory leak in mt7615_mcu_wtbl_sta_add()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68763
- crypto: starfive - Correctly handle return of sg_nents_for_len
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68740
- ima: Handle error code returned by ima_filter_rule_match()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68362
- wifi: rtl818x: rtl8187: Fix potential buffer underflow in
rtl8187_rx_cb()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68741
- scsi: qla2xxx: Fix improper freeing of purex item
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68742
- bpf: Fix invalid prog->stats access when update_effective_progs fails
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68759
- wifi: rtl818x: Fix potential memory leaks in rtl8180_init_rx_ring()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68363
- bpf: Check skb->transport_header is set in bpf_skb_check_mtu
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68744
- bpf: Free special fields when update [lru_,]percpu_hash maps
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68364
- ocfs2: relax BUG() to ocfs2_error() in __ocfs2_move_extent()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68366
- nbd: defer config unlock in nbd_genl_connect
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68367
- macintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68755
- staging: most: remove broken i2c driver
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68371
- scsi: smartpqi: Fix device resources accessed after device removal
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68372
- nbd: defer config put in recv_work
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68746
- spi: tegra210-quad: Fix timeout handling
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68379
- RDMA/rxe: Fix null deref on srq->rq.queue after resize failure
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68380
- wifi: ath11k: fix peer HE MCS assignment
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68724
- crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68727
- ntfs3: Fix uninit buffer allocated by __getname()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68728
- ntfs3: fix uninit memory after failed mi_read in mi_format_new
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68757
- drm/vgem-fence: Fix potential deadlock on release
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68732
- gpu: host1x: Fix race in syncpt alloc/free
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68733
- smack: fix bug: unprivileged task can create labels
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68254
- staging: rtl8723bs: fix out-of-bounds read in OnBeacon ESR IE parsing
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68255
- staging: rtl8723bs: fix stack buffer overflow in OnAssocReq IE parsing
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68256
- staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68257
- comedi: check device's attached status in compat ioctls
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68258
- comedi: multiq3: sanitize config options in multiq3_attach()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68332
- comedi: c6xdigio: Fix invalid PNP driver unregistration
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68265
- nvme: fix admin request_queue lifetime
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68266
- bfs: Reconstruct file type when loading from disk
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68259
- KVM: SVM: Don't skip unrelated instruction if INT3/INTO is replaced
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68335
- comedi: pcl818: fix null-ptr-deref in pcl818_ai_cancel()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68261
- ext4: add i_data_sem protection in ext4_destroy_inline_data_nolock()
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68336
- locking/spinlock/debug: Fix data-race in do_raw_write_lock
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68263
- ksmbd: ipc: fix use-after-free in ipc_msg_send_request
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68264
- ext4: refresh inline data size before write operations
* Noble update: upstream stable patchset 2026-03-04 (LP: #2142789) //
CVE-2025-68337
- jbd2: avoid bug_on in jbd2_journal_get_create_access() when file system
corrupted
* CVE-2026-23111
- netfilter: nf_tables: fix inverted genmask check in
nft_map_catchall_activate()
* CVE-2026-23209
- macvlan: fix error recovery in macvlan_common_newlink()
* CVE-2026-23074
- net/sched: Enforce that teql can only be used as root qdisc
* CVE-2026-23060
- crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN
spec
-- Edoardo Canepa <edoardo.canepa@canonical.com> Fri, 27 Mar 2026 10:37:26 +0100
# For older changelog entries, run 'apt-get changelog linux-hwe-6.8-tools-6.8.0-136'
Generated by dwww version 1.14 on Mon Aug 3 02:00:52 CEST 2026.