From patchwork Wed Jun 10 16:47:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Bruce Ashfield X-Patchwork-Id: 89685 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 52C1FCD8CB2 for ; Wed, 10 Jun 2026 16:47:52 +0000 (UTC) Received: from mail-qt1-f177.google.com (mail-qt1-f177.google.com [209.85.160.177]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.25393.1781110062777662197 for ; Wed, 10 Jun 2026 09:47:43 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=ZQ7l0kSR; spf=pass (domain: gmail.com, ip: 209.85.160.177, mailfrom: bruce.ashfield@gmail.com) Received: by mail-qt1-f177.google.com with SMTP id d75a77b69052e-517dc520840so12568641cf.3 for ; Wed, 10 Jun 2026 09:47:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781110062; x=1781714862; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=OZNSNou/RZEWG6sA5Ti9kr5P0FNrYZDSgPsmrfDZg14=; b=ZQ7l0kSRNgR3L6sp7v6ZBXjWQh4lS7UAyjTKrnHLyMZZMN5Rwbb3HMH5zuT/lhC7ld DFAJSy299qYeh81WHd2Nk+b9OsSPrfiWMuWLARkGE+54KqCGhZK//oLv9AoctQG04BxE bpM7W4Eu1YekWAQgoe4VWwtvviqBqWtkVCuLwR9WU1+k/za6aig6jQ5AZfVoLnXSP+0p RQ70MqyzAU/5360pM8S5dr8arLf8wNRNgRoZSG38MqTsRpz6RIgYl3+6JChz5EgCycu3 9iXDkUtE1MaGhRWx6ur8Rqe3IuyjA0U57it1zSWJApC0k9bfD2L858c6f/oOKADFZcss 0biA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781110062; x=1781714862; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=OZNSNou/RZEWG6sA5Ti9kr5P0FNrYZDSgPsmrfDZg14=; b=B6/d7Dc43hGSerewFoUIoY4pHRYhEnoB57N/z7vK+B7RqfSMavlJdU+B2NssFjAfgT X8nXiI5jradR4z6fGYsExhxGBSb9/X96bj8+XrXI3GIPwtQMoM+MdRKbLWvh4P86ErmF 4H57lcF7BXTYmeeaagpjAYGJ/FTjPzEdaJt4yHwMmuEDuyRVu1VvqQdn8H/WjeSaU6kf djlh81Uiy/Rtd4BYLY6QSjl8MLZBJ4FUqL9dzkgyz8ja268BlyJU4PiR4DTV5MpcpoA/ L9BG4JDsooVL7nQmP0vCf5LqX/KUK8XOGwqGwq67pwdjBx9OJlZplGm99jylHgTL6eT9 uOGQ== X-Gm-Message-State: AOJu0YzmW8Qodlx0pX3pcRkInp+MnrNLJg8vbw0qbPPNogaetO2iWSmF gfttCpInP3vqRsKH74G5JNji6dgdJznvw5Mn7Enl0Z+2Kbsej3YfjBSPHboiK+Y2 X-Gm-Gg: Acq92OGkGNq3kcE6MkQgSevGzh4/H710TnPkgmPU2Gd7OE9mMflIZdat4BYwc20lWG4 gE7+C/3vGbYDDH4Vapw+h8F0h7RhfOjLVRCplLA4UB/SVwWyXoIRW1YaHAZ1krdFEQRi1U4Z9HL wTeb7TKO7ZLn0qvUfuRJJJqBYy2jniD5weXBod7DGbZT7GzdYP0YKjNy2YcCxlLwXBHAfEsfLMh X8VU1g3KGBSJndLOF58P7tabN907Ew5Zr6GtYj0q3Lgy8NYmi1IYZIanUdAXgPTxgEk+qy6mlvu AFT1fNoYJpe000mmG+tl2YEkbog3k2anKVfdVMvjaPlGwyZ3pkL0XMBQ1miZ7ETXefxTmQRdnIO LKxVlOo+sSXHGcQjxxz2qwVRS6Q+fOSADxvfNN7oRYq0OO9SxFdXHLYcW7x1rIuFGZlJMRHHoQx NhV37XdflgxA1uh0hSZJPCTtFfPChHUAdJHT7tivrd/dIApKfl/WEm9wwOchc3sW3ud1YlAHnxy NnRFrNqNwO6usWdRkn23Lnl8JecND+JL3ugrOyO/WDE6RW3rYRiTG9AwYs9DdPmS/AYgAQlQqUt OuDy+Xaar1m6hOaSZ4OJDB3InF10rVvRhWG0SArwvpxNHnWSOG/NhfE= X-Received: by 2002:a05:622a:53ca:b0:517:7e6e:708f with SMTP id d75a77b69052e-51795c9f69fmr408398531cf.52.1781110061341; Wed, 10 Jun 2026 09:47:41 -0700 (PDT) Received: from bruce-XPS-8940.localdomain (pool-174-112-62-108.cpe.net.cable.rogers.com. [174.112.62.108]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-51775d9efa1sm214422401cf.20.2026.06.10.09.47.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 10 Jun 2026 09:47:40 -0700 (PDT) From: bruce.ashfield@gmail.com To: richard.purdie@linuxfoundation.org Cc: openembedded-core@lists.openembedded.org Subject: [meta][PATCH 01/04] linux-yocto/6.18: update to v6.18.34 Date: Wed, 10 Jun 2026 12:47:34 -0400 Message-ID: <20260610164737.1869790-2-bruce.ashfield@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260610164737.1869790-1-bruce.ashfield@gmail.com> References: <20260610164737.1869790-1-bruce.ashfield@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 10 Jun 2026 16:47:52 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/238373 From: Bruce Ashfield Updating linux-yocto/6.18 to the latest korg -stable release that comprises the following commits: 18ad16ce4a6b Linux 6.18.34 50bb3435a5e6 security/keys: fix missed RCU read section on lookup 239172639075 drm/msm: Restore second parameter name in purge() and evict() 306ba9d0e5aa LoongArch: kprobes: Fix handling of fatal unrecoverable recursions a1a39f227c80 ksmbd: fix durable reconnect error path file lifetime 6836f694126e io_uring/nop: pass all errors to userspace e334cbf3388f net: gro: don't merge zcopy skbs 8129611d4ede pds_core: ensure null-termination for firmware version strings d1d76bbb6d7a net: airoha: Disable GDM2 forwarding before configuring GDM2 loopback 719007c3492f tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR fa627a5eaa83 net: mana: validate rx_req_idx to prevent out-of-bounds array access bc0020490f88 octeontx2-af: npc: Fix allmulticast skip logic for LBK and SDP VFs 76dd50b7888d selftests: net: Fix checksums in xdp_native 04ef7592eaad drm/xe/oa: Fix exec_queue leak on width check in stream open db86ac6d8daf ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() decacc6308c5 gpio: aggregator: lock device when calling device_is_bound() 3e657619cf72 gpio: aggregator: remove the software node when deactivating the aggregator 80d94cf1773a gpio: aggregator: stop using dev-sync-probe ea28b286649b gpio: aggregator: fix a potential use-after-free 4669f84adcb1 gpio: cdev: check if uAPI v2 config attributes are correctly zeroed e47f7060eaf6 tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction 1861d369efd6 bpf, skmsg: fix verdict sk_data_ready racing with ktls rx 26f1d4522060 net: ag71xx: check error for platform_get_irq 585f9f6aef5c crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks 2417df5e7bb4 net: shaper: rework the VALID marking (again) 5a2c2aa139c8 net: shaper: annotate the data races b5bd4249e430 net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA a0f5268c77eb Bluetooth: btmtk: fix urb->setup_packet leak in error paths c7860b6a6d2d Bluetooth: btintel_pcie: Fix incorrect MAC access programming d6c8b3ebdcdb tracing: Avoid NULL return from hist_field_name() on truncation 8bf00d3ac425 cgroup: rstat: relax NMI guard after switch to try_cmpxchg 3aab4a58d23f ALSA: seq: Serialize UMP output teardown with event_input 95c82d498d74 wifi: wilc1000: fix dma_buffer leak on bus acquire failure 55c479aae99b wifi: mac80211: fix MLE defragmentation 2d8379834800 wifi: mac80211: bounds-check link_id in ieee80211_ml_epcs 425d32d6288d erofs: fix managed cache race for unaligned extents 91d13e92b983 pds_core: fix debugfs_lookup dentry leak and error handling 784dd2bdc622 pds_core: fix error handling in pdsc_devcmd_wait ce23832071af net: airoha: Fix NPU RX DMA descriptor bits 0c277d203684 net: phy: honor eee_disabled_modes in phy_advertise_eee_all() bd731994cff1 net: phy: honor eee_disabled_modes in phy_support_eee() a9224862d597 bridge: mcast: Fix a possible use-after-free when removing a bridge port 981aea209977 net: bridge: Flush multicast groups when snooping is disabled eae62c5451e6 RDMA/rtrs: Fix use-after-free in path file creation cleanup 8c63698737b4 RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port d5b11e15ee67 ASoC: soc-utils: Add missing va_end in snd_soc_ret() 09deb063eecf platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL f6dfd64bfd9b platform/x86: intel-hid: Check ACPI_HANDLE() against NULL ed864a7b881c platform/x86: hp_accel: Check ACPI_COMPANION() against NULL 7ea5aad8d351 platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL 098419a4b062 platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 09ec063d87c2 net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer f71fc35b5e45 net: dsa: mt7530: preserve VLAN tags on trapped link-local frames 89bed786f231 net: dsa: mt7530: fix FDB entries not aging out with short timeout f1739debda62 kbuild: pacman-pkg: make "rc" releases adhere to pacman versioning scheme ad8e3d096fa1 drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP 1f83545f432d igc: set tx buffer type for SMD frames 89964ddb322a ice: ptp: use primary NAC semaphore on E825 0010296879df ice: ptp: serialize E825 PHY timer start with PTP lock 6a01413a4e8f cgroup/rstat: validate cpu before css_rstat_cpu() access 83b8a0f72ecc drm/mediatek: mtk_hdmi_ddc: Fix non-static global variable 8ea34da68964 drm/mediatek: mtk_cec: Fix non-static global variable 926a08cf19be wifi: ath11k: fix peer resolution on rx path when peer_id=0 6c9e9272bc37 drm/xe/pf: Fix CFI failure in debugfs access dc26e00860a1 drm/xe/vf: Fix signature of print functions 2c890e71ae26 drm/xe/gsc: Fix double-free of managed BO in error path 181e67bc11c5 dma-mapping: move dma_map_resource() sanity check into debug code 3a74aaad0473 wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it 9e360e610a73 wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled bed1fc32e0eb hwmon: (lm90) Add lock protection to lm90_alert c98107817b0f hwmon: (lm90) Stop work before releasing hwmon device cdd1aaf0ee96 drm/msm/snapshot: fix dumping of the unaligned regions 0c9e4d9484cc ALSA: hda/realtek: Use ALC287_FIXUP_TXNW2781_I2C for ASUS Strix Gxx5 df19b6af1716 netfilter: nft_inner: release local_lock before re-enabling softirqs 0fa225896f4b spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() fecfed41da73 ASoC: amd: acp-sdw-legacy: check CPU DAI name before logging 7e91d3a1a98a btrfs: fix squota accounting during enable generation ca56ffdb017b btrfs: check for subvolume before deleting squota qgroup b422609291f6 btrfs: relax squota parent qgroup deletion rule 22d558df51d9 btrfs: check squota parent usage on membership change a1296bb9f44a btrfs: remaining BTRFS_PATH_AUTO_FREE conversions 76ad957a72c7 btrfs: don't search back for dir inode item in INO_LOOKUP_USER 16141bef6fb1 btrfs: use the key format macros when printing keys 35f69e993d00 btrfs: add macros to facilitate printing of keys 76b995bc57bd vsock/virtio: fix zerocopy completion for multi-skb sends 782693eb53f8 io_uring/net: punt IORING_OP_BIND async if it needs file create c53cac053d62 ALSA: scarlett2: Add missing error check when initialise Autogain Status 1ddf678bb75b ASoC: codecs: fs210x: fix possible buffer overflow 36de63965464 scsi: sd: Fix return code handling in sd_spinup_disk() b4dc0056397f net/mlx5: Do not restore destination-less TC rules 81c8a9f75a42 tls: Preserve sk_err across recvmsg() when data has been copied 1370acb8bc39 ovpn: disable BHs when updating device stats f7808b7ddcf2 x86/xen: Fix xen_e820_swap_entry_with_ram() 2378d25675da gcc-plugins: Always define CONST_CAST_GIMPLE and CONST_CAST_TREE 097d62df3831 ovpn: fix race between deleting interface and adding new peer 8298834912d7 ovpn: respect peer refcount in CMD_NEW_PEER error path e5460eb7238c ovpn: tcp - use cached peer pointer in ovpn_tcp_close() 2bc34520ce5c net: phy: DP83TC811: add reading of abilities af855f4c966a net: tls: prevent chain-after-chain in plain text SG eca989eab4b2 net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring afa9036b8c99 net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot 6dcd072a5ae3 powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() f4e37f3df436 drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN eea43d5ed450 drm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx 3a7b59d2385d Documentation: intel_pstate: Fix description of asymmetric packing with SMT 3ad2d8be6e4d x86/mce: Restore MCA polling interval halving 15dba511d569 selftests: ublk: cap nthreads to kernel's actual nr_hw_queues ff58e5ef1b46 drm/msm/dpu: don't mix devm and drmm functions a184aec79013 drm/msm/dsi: don't dump registers past the mapped region d235f8f7b264 ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics d2ea0b8aef87 net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint 97a8e89cdef3 accel/qaic: Add overflow check to remap_pfn_range during mmap 76410790f149 block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() 086695145000 HID: quirks: really enable the intended work around for appledisplay 0943f81e1b31 block: recompute nr_integrity_segments in blk_insert_cloned_request 0d48654af4d1 block: don't overwrite bip_vcnt in bio_integrity_copy_user() a52486394493 net: shaper: reject QUEUE scope handle with missing id 77ec90d41c59 net: shaper: enforce singleton NETDEV scope with id 0 d7c2bbbaa2c4 net: shaper: fix undersized reply skb allocation in GROUP command f817ce8d1943 net: shaper: set ret to -ENOMEM when genlmsg_new() fails in group_doit 5098b223f0f0 net: shaper: reject duplicate leaves in GROUP request d6128451c591 net: shaper: fix trivial ordering issue in net_shaper_commit() d947e6685ff4 net: shaper: flip the polarity of the valid flag e1b429d8e712 wifi: ath10k: skip WMI and beacon transmission when device is wedged d94127d04017 wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() acde4692afcd wifi: ath11k: fix error path leaks in some WMI WOW calls 9bc70fe995da net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference c373b34877af net: ethernet: cortina: Carry over frag counter 3cd05250a2df net: ethernet: cortina: Drop half-assembled SKB cfd62907f3cd net: ethernet: cortina: Make RX SKB per-port 77bb293049d6 netfs, afs: Fix write skipping in dir/link writepages f17b9121bb99 netfs: Fix netfs_read_folio() to wait on writeback 551b5c71ee31 netfs: Fix folio->private handling in netfs_perform_write() 3d9601c029b9 netfs: Fix partial invalidation of streaming-write folio 6080fa3ecfbb netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() 22ae28aae436 netfs: Fix leak of request in netfs_write_begin() error handling d4f4bc87c765 netfs: Fix early put of sink folio in netfs_read_gaps() 616578e40dcb netfs: Fix write streaming disablement if fd open O_RDWR 0b18cd70ebab netfs: Fix read-gaps to remove netfs_folio from filled folio 003aa0dd26c9 netfs: Fix potential deadlock in write-through mode ef9b521212e4 netfs: Fix streaming write being overwritten 185ded4112cd netfs: Defer the emission of trace_netfs_folio() fb6ec883b48b netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone afeb32d9bf9a netfs: Fix overrun check in netfs_extract_user_iter() b63971238beb netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call 884c4c4f35e5 netfs: Fix netfs_read_to_pagecache() to pause on subreq failure 5366199be46f netfs: Fix cancellation of a DIO and single read subrequests 9c6f23cf3a07 powerpc: fix dead default for GUEST_STATE_BUFFER_TEST 822bb1614ec4 powerpc: 82xx: fix uninitialized pointers with free attribute aed60070ed7b ASoC: SOF: amd: Fix error code handling in psp_send_cmd() 510db031ba6e tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key(). eba8af785fde zonefs: handle integer overflow in zonefs_fname_to_fno 9525e3a6fbb1 nvme-pci: fix use-after-free in nvme_free_host_mem() fea4b46f84c5 nvme: fix bio leak on mapping failure 18c0456ea261 irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT 06ee55f78fbe nsfs: fix wrong error code returned for pidns ioctls d168a71fc1d6 ublk: reject max_sectors smaller than PAGE_SECTORS in parameter validation 617a2564d863 irqchip/ath79-cpu: Remove unused function ace6b3e033c6 fs: Fix return in jfs_mkdir and orangefs_mkdir e37ea2c6f17f fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap 56b4cfcf1518 fprobe: Fix unregister_fprobe() to wait for RCU grace period 36dc0cea30db ASoC: sdw_utils: Add quirk to ignore RT721 CODEC_MIC 5afefecfe054 ASoC: sdw_utils: Add quirk to ignore RT712 CODEC_MIC fe59ae27d734 NFSD: Fix infinite loop in layout state revocation e9405f704127 phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access 994358adc098 net: ti: icssm-prueth: fix eth_ports_node leak in probe 7df3e1dfee53 net: lan966x: avoid unregistering netdev on register failure d91a9a049698 ice: fix locking in ice_dcb_rebuild() 34ad3c782644 ice: fix setting RSS VSI hash for E830 eb5991d4c8ba idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() a248793f00ab net: shaper: Reject reparenting of existing nodes bfe08fe5624b net: napi: Avoid gro timer misfiring at end of busypoll 77e7818eb347 tcp: Fix imbalanced icsk_accept_queue count. 1c24cf1fd67f test_kprobes: clear kprobes between test runs ae8a5c6b0316 kprobes: skip non-symbol addresses in kprobe_add_ksym_blacklist() c647e2a21bbb netfilter: bridge: eb_tables: close module init race 524b6337277a netfilter: x_tables: close dangling table module init race cc989ef1c044 netfilter: ebtables: close dangling table module init race 739d5dac7b2d netfilter: ebtables: move to two-stage removal scheme 86ee5bc9c0f0 netfilter: x_tables: add and use xtables_unregister_table_exit 89ebafe7910d netfilter: x_tables: add and use xt_unregister_table_pre_exit a9b2f73f6ba7 netfilter: x_tables: unregister the templates first c32a7e0e3c73 btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() 373f65b448ed ALSA: hda: cs35l41: Put ACPI device on missing physical node fecae8b1fb2d ALSA: hda: cs35l56: Put ACPI device after setting companion e984dc22e2c2 ARM: integrator: Fix early initialization 9e472874c954 firmware: arm_ffa: Fix sched-recv callback partition lookup d1e38551fade firmware: arm_ffa: Snapshot notifier callbacks under lock 419cef661ae8 firmware: arm_ffa: Align RxTx buffer size before mapping 3c51d99449dc firmware: arm_ffa: Validate framework notification message layout 0a5dbac5ef53 firmware: arm_ffa: Keep framework RX release under lock f39bc7ebe75e firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies fd2b01637e56 pinctrl: qcom: Fix wakeirq map by removing disconnected irqs for sm8150 3f4d82780001 kunit: config: KUNIT_DEBUGFS should depend on DEBUG_FS 91e4446b35f6 kunit: config: Enable KUNIT_DEBUGFS by default 96b8b9d0dead riscv: mm: Fixup no5lvl failure when vaddr is invalid f3216d930c0f riscv: errata: Fix bitwise vs logical AND in MIPS errata patching 1aa01b46fe3b firmware: arm_ffa: Unregister bus notifier on teardown for FF-A v1.0 07907b897bb7 firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue 1418765d28ab firmware: arm_ffa: Skip free_pages on RX buffer alloc failure 820245d86ce5 firmware: arm_ffa: Check for NULL FF-A ID table while driver registration 4894847fcec1 HID: uclogic: Fix regression of input name assignment e912d5dc0096 HID: intel-thc-hid: Intel-quickspi: Fix some error codes 1fce9dcb3a66 pinctrl: qcom: Fix GPIO to PDC wake irq map for qcs615 e917713f0134 pinctrl: meson: amlogic-a4: fix deadlock issue 8d1c6b603327 pinctrl: renesas: rzg2l: Fix SMT register cache handling c4cfa8ee7737 pinctrl: renesas: rzg2l: Fix incorrect PUPD register offset for high pins during suspend/resume a7fee1322683 ARM: dts: renesas: rskrza1: Drop superfluous cells d27b29e474a6 ARM: dts: renesas: genmai: Drop superfluous cells 00aca89f5e34 pinctrl: qcom: ipq4019: mark gpio as a GPIO pin function eb3cd9bb5904 hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors dd12c6dbe2ac hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() a203125c0e81 hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() b2998ae90331 hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple fa7ca363069a hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR 97a9cf2a8217 hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer 2279c342d94e hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer 75c862adf3d3 hwmon: (pmbus/adm1266) reject implausible blackbox record_count e9b8f85daebf hwmon: (pmbus/adm1266) seed timestamp from the real-time clock e37dbe150515 batman-adv: tt: prevent TVLV entry number overflow 730de8733dd9 batman-adv: tt: fix negative tt_buff_len 179eb62506a0 batman-adv: tt: fix negative last_changeset_len b93ca6012712 batman-adv: tt: avoid empty VLAN responses 7cac9c9ef4b7 batman-adv: tt: reject oversized local TVLV buffers 4cc85aec8d3c batman-adv: tt: fix TOCTOU race for reported vlans 2d2d365d0b9d batman-adv: tp_meter: avoid role confusion in tp_list 72d670d7a492 batman-adv: tp_meter: fix race condition in send error reporting b285bc0a97f4 batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown 770bf0a35f06 batman-adv: tp_meter: directly shut down timer on cleanup dc2ae5fbd2da batman-adv: tp_meter: avoid use of uninit sender vars 6921a7683ae9 batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface 45384612f296 batman-adv: bla: avoid double decrement of bla.num_requests c6de1a5a9c40 batman-adv: bla: fix report_work leak on backbone_gw purge 5895ad21c705 batman-adv: frag: disallow unicast fragment in fragment 90ae3eae06b7 batman-adv: fix tp_meter counter underflow during shutdown 3eb8bcb82339 batman-adv: fix fragment reassembly length accounting 9cceea8eeba7 batman-adv: dat: handle forward allocation error ae7aeb0ce3c0 batman-adv: clear current gateway during teardown 8a3707653ab6 batman-adv: mcast: fix use-after-free in orig_node RCU release ca3ff3d2a0af batman-adv: iv: recover OGM scheduling after forward packet error ede47988ac56 batman-adv: tvlv: reject oversized TVLV packets 23d4ce84df4d batman-adv: tvlv: abort OGM send on tvlv append failure 1be1e99cbd5b batman-adv: v: stop OGMv2 on disabled interface 1ecde19bfce6 drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async 7ca695b31222 drm/amd/display: Validate GPIO pin LUT table size before iterating 6bbd703ea1c1 drm/amd/display: Fix integer overflow in bios_get_image() d35563813296 drm/bridge: megachips: remove bridge when irq request fails 95306db11956 drm/bridge: it66121: acquire reset GPIO in probe 3ed448c1dc78 drm/amdgpu/vpe: Force collaborate sync after TRAP 8fadd01cf461 drm/virtio: use uninterruptible resv lock for plane updates 35671087a272 drm/v3d: Release indirect CSD GEM reference on CPU job free 0f8efc45740b drm/v3d: Fix use-after-free of CPU job query arrays on error path 942968260e61 drm/msm: Fix shrinker deadlock 508fd8ab158a device property: set fwnode->secondary to NULL in fwnode_init() 22d9b9739b8e LoongArch: Remove unused code to avoid build warning f27a3b9aadfb LoongArch: kprobes: Use larch_insn_text_copy() to patch instructions 9e3f18883a98 fwctl: pds: Validate RPC input size before parsing 1012896f4225 RDMA/siw: Reject MPA FPDU length underflow before signed receive math d7a076fb596c spi: ti-qspi: fix use-after-free after DMA setup failure be409d2bbe9c spi: sprd: fix error pointer deref after DMA setup failure 8e027db9fa31 spi: ep93xx: fix error pointer deref after DMA setup failure b9ff86310062 scsi: isci: Fix use-after-free in device removal path 78a369a065f1 phy: qcom-qmp-ufs: Fix kaanapali PHY PLL lock failure after SM8650 G4 fix 58f4a7bd8d73 phy: tegra: xusb: Fix per-pad high-speed termination calibration a1f50f5aaa69 phy: exynos5-usbdrd: fix USB 2.0 HS PHY tuning values for Exynos7870 4bb4764f2c51 spi: qup: fix error pointer deref after DMA setup failure ecdf21536c6d drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe bee400ad4f42 virt: sev-guest: Explicitly leak pages in unknown state 4f087193b5ff riscv: kvm: return SBI_ERR_FAILURE for pmu_event_info() when OOM 77071943c752 riscv: kvm: return SBI_ERR_FAILURE for pmu_snapshot_set_shmem() when OOM 94ade38f317e KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235) 7023900b4988 KVM: arm64: vgic: Free private_irqs when init fails after allocation 0680f5119265 KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits 240373425e2d arm64: probes: Handle probes on hinted conditional branch instructions 798183376d9d tracing: Do not call map->ops->elt_free() if elt_alloc() fails 5e7d9d0805e5 cifs: Fix busy dentry used after unmounting 2dd9304727c7 wifi: mac80211: consume only present negotiated TTLM maps acdff9907478 af_unix: Fix UAF read of tail->len in unix_stream_data_wait() 6cfae4914439 wifi: cfg80211: advance loop vars in cfg80211_merge_profile() 50884c2afd7a ice: restore PTP Rx timestamp config after ethtool set-channels 0b9431b972a0 ice: fix setting promisc mode while adding VID filter 9c9d00d81b41 ice: fix locking around wait_event_interruptible_locked_irq f1bafd35f11b igc: fix potential skb leak in igc_fpe_xmit_smd_frame() 8864b664d044 octeontx2-pf: fix double free in rvu_rep_rsrc_init() 47a4cf2229be octeontx2-af: CGX: add bounds check to cgx_speed_mbps index 5b906f31e977 lsm: hold cred_guard_mutex for lsm_set_self_attr() 9dcd4f5c99b4 rbd: eliminate a race in lock_dwork draining on unmap dfef79e09ed2 ixgbevf: fix use-after-free in VEPA multicast source pruning 7725cd3b4717 ipv4: raw: reject IP_HDRINCL packets with ihl < 5 dc31c6947652 wifi: iwlwifi: mld: stop TX during firmware restart 6fe92651b44f wifi: iwlwifi: mvm: fix driver-set TX rates on old devices 614cacec60fe wifi: ath11k: clear shared SRNG pointer state on restart a3529032afe2 ice: fix VF queue configuration with low MTU values c618cf8926c0 vsock/virtio: reset connection on receiving queue overflow 440447699c68 vsock/vmci: fix UAF when peer resets connection during handshake 29b643351012 mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient abdd03229414 ipv6: ioam: add NULL check for idev in ipv6_hop_ioam() 2bc60c175568 ring-buffer: Flush and stop persistent ring buffer on panic 610ff6bc2f44 ring-buffer: Fix reporting of missed events in iterator 0e47fc1c9181 qed: fix double free in qed_cxt_tables_alloc() e0c3dd7b30cc l2tp: use list_del_rcu in l2tp_session_unhash d73dcd1520d6 fs/ntfs3: handle attr_set_size() errors when truncating files 358692462555 net: ethtool: phy: avoid NULL deref when PHY driver is unbound 61f53c1e58d6 net: ethtool: fix NULL pointer dereference in phy_reply_size 752ea4a105e6 cgroup/cpuset: Reset DL migration state on can_attach() failure 1aed73795392 tracing/fprobe: Check the same type fprobe on table as the unregistered one f0ad68d2f0ad tracing/fprobe: Avoid kcalloc() in rcu_read_lock section bb92f356d2b7 tracing: fprobe: use ftrace if CONFIG_DYNAMIC_FTRACE_WITH_ARGS 52cc572c9565 tracing: fprobe: Remove unused local variable 45c7c4e3db8b sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path 6e73ec10b2a3 sched_ext: Fix missing warning in scx_set_task_state() default case 689bbf48c1f4 netfilter: nft_inner: Fix IPv6 inner_thoff desync 952e988163c2 netfilter: ipset: stop hash:* range iteration at end 15d464265120 netfilter: nf_queue: hold bridge skb->dev while queued 57b0ac5e1b46 netfilter: ip6t_hbh: reject oversized option lists dac025c4e8f9 net: pse-pd: fix sign on -ENOENT check in of_load_pse_pis() f8a5a76b4a68 net: ifb: report ethtool stats over num_tx_queues 1604a2d68414 net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover 49eff79967fd net: phy: skip EEE advertisement write when autoneg is disabled 3d4ef05266ab net: bcmgenet: keep RBUF EEE/PM disabled 84bc87beb4cd phonet/pep: disable BH around forwarded sk_receive_skb() 8b4c412e001b Bluetooth: serialize accept_q access f1febe93ef07 Bluetooth: MGMT: validate Add Extended Advertising Data length 051922ab709c Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer 192cb0f1ca70 Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths 5506aec79513 Bluetooth: bnep: Fix UAF read of dev->name 61f2410a96de Bluetooth: ISO: drop ISO_END frames received without prior ISO_START added1213395 Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() ffb6dbb49c96 net: wwan: iosm: fix potential memory leaks in ipc_imem_init() 0fa24311bd42 selftests/mm: run_vmtests.sh: fix destructive tests invocation 738d18f1da35 mm/page_alloc: fix initialization of tags of the huge zero folio with init_on_free 09ce923071e7 mm/memory_hotplug: fix memory block reference leak on remove 62153767e8fc mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_special() 2fff0cdd9422 mm/memory: fix spurious warning when unmapping device-private/exclusive pages 24de676da63c ipv6: ioam: refresh hdr pointer before ioam6_event() 24840b3139d7 drivers/base/memory: fix memory block reference leak in poison accounting b737c6612c60 io_uring/waitid: clear waitid info before copying it to userspace 5fb947ddae55 spi: amd: Set correct bus number in ACPI probe path c32a1fbe0f9a efi: Allocate runtime workqueue before ACPI init fcbd0a5fd812 ALSA: scarlett2: Allow flash writes ending at segment boundary 61c5017c64e2 ALSA: asihpi: Fix potential OOB array access at reading cache feff0251386a ALSA: pcm: Don't setup bogus iov_iter for silencing cba8dab72e9b ALSA: ua101: Reject too-short USB descriptors ca560f7566df hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX 9803e75c9813 smb/server: promote S_DEL_ON_CLS to S_DEL_PENDING when close d65104a4a815 smb: client: use data_len for SMB2 READ encrypted folioq copy bf4ebdb19ff9 smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() a8d17d22db59 smb: client: require net admin for CIFS SWN netlink 6827647fd2dc regulator: tps65219: fix irq_data.rdev not being assigned 18d8db24b0a5 ksmbd: validate SID in parent security descriptor during ACL inheritance 0e198f09cb2a ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow cd5c1b75d2f4 ksmbd: fix null pointer dereference in compare_guid_key() 302e02f9ba49 mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break() 48fa96538bd2 sysfs: don't remove existing directory on update failure 141ffb83abe9 drm/vblank: Fix kernel docs for vblank timer ed39ecd3a96c drm/atomic: Increase timeout in drm_atomic_helper_wait_for_vblanks() a0582cc92398 drm/vkms: Convert to DRM's vblank timer 60918357456d drm/vblank: Add CRTC helpers for simple use cases fa4b91eea433 drm/vblank: Add vblank timer 18a08b87db71 Revert "ice: Remove jumbo_remove step from TX path" 523cd0ea0324 Revert "ice: fix double-free of tx_buf skb" 515de0a3b6c1 ata: libata-scsi: do not needlessly defer commands when using PMP with FBS 4e6eada8de38 ata: libata-scsi: do not use the deferred QC feature on PMPs with CBS f207ebd5656e ata: libata-scsi: do not use the deferred QC feature for ATA_DEFER_PORT 62ee00c1042c ata: libata-scsi: improve readability of ata_scsi_qc_issue() 9d11e4b1db1c mfd: bcm2835-pm: Add support for BCM2712 ed915823d469 arm64: dts: broadcom: bcm2712: Add watchdog DT node 375d5a17dc8d dt-bindings: soc: bcm: Add bcm2712 compatible 91f89c1d83e8 smb: client: reject userspace cifs.spnego descriptions 5da69a65b282 ksmbd: close durable scavenger races against m_fp_list lookups aae4a47073b1 spi: spi-dw-dma: fix print error log when wait finish transaction e8ec80430bfa bridge: mrp: reject zero test interval to avoid OOM panic 0638bf16b7a7 sched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting 3f0543bdf446 sched: Employ sched_change guards dc184ac2f0ba cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() da3d241c5b92 fuse: fix uninit-value in fuse_dentry_revalidate() 488d2c76bd9f iommu/amd: Remove latent out-of-bounds access in IOMMU debugfs b9a4184271b9 iommu/amd: Fix illegal cap/mmio access in IOMMU debugfs 814326e86e92 drm/xe/hdcp: Add NULL check for media_gt in intel_hdcp_gsc_check_status() Signed-off-by: Bruce Ashfield --- .../linux/linux-yocto-rt_6.18.bb | 6 ++--- .../linux/linux-yocto-tiny_6.18.bb | 6 ++--- meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +++++++++---------- 3 files changed, 18 insertions(+), 18 deletions(-) diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb index fea34b09c6..09adce37c1 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb @@ -15,13 +15,13 @@ python () { raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") } -SRCREV_machine ?= "058dc6c42aff140a8fa55c732809d896223fd6fc" -SRCREV_meta ?= "3fe9b5c19ed6f8883e7d12a89a0ea882e3facfef" +SRCREV_machine ?= "70ee73bc5040b0150d134f5830dcbb83f8f550f6" +SRCREV_meta ?= "3a459546a712ea2b92d6b5a5cfd175dd1851896c" SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" -LINUX_VERSION ?= "6.18.33" +LINUX_VERSION ?= "6.18.34" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb index de87b6bdd3..3723c81c72 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb @@ -9,7 +9,7 @@ require recipes-kernel/linux/linux-yocto.inc include recipes-kernel/linux/cve-exclusion.inc include recipes-kernel/linux/cve-exclusion_6.18.inc -LINUX_VERSION ?= "6.18.33" +LINUX_VERSION ?= "6.18.34" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}" @@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native" KMETA = "kernel-meta" KCONF_BSP_AUDIT_LEVEL = "2" -SRCREV_machine ?= "32bc3dcadb49e9a4f4474ec743e2c5ddd7f44a27" -SRCREV_meta ?= "3fe9b5c19ed6f8883e7d12a89a0ea882e3facfef" +SRCREV_machine ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" +SRCREV_meta ?= "3a459546a712ea2b92d6b5a5cfd175dd1851896c" PV = "${LINUX_VERSION}+git" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb index 78ee98fec9..09c2093e16 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb @@ -17,25 +17,25 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base" KBRANCH:qemuloongarch64 ?= "v6.18/standard/base" KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta" -SRCREV_machine:qemuarm ?= "9b84e2ac85be6a214946c65debaab56e3bebd546" -SRCREV_machine:qemuarm64 ?= "32bc3dcadb49e9a4f4474ec743e2c5ddd7f44a27" -SRCREV_machine:qemuloongarch64 ?= "32bc3dcadb49e9a4f4474ec743e2c5ddd7f44a27" +SRCREV_machine:qemuarm ?= "1fa8e29233b43f22ce5dd26e3bc08ad79784a7ca" +SRCREV_machine:qemuarm64 ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" +SRCREV_machine:qemuloongarch64 ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e" -SRCREV_machine:qemuppc ?= "32bc3dcadb49e9a4f4474ec743e2c5ddd7f44a27" -SRCREV_machine:qemuriscv64 ?= "32bc3dcadb49e9a4f4474ec743e2c5ddd7f44a27" -SRCREV_machine:qemuriscv32 ?= "32bc3dcadb49e9a4f4474ec743e2c5ddd7f44a27" -SRCREV_machine:qemux86 ?= "32bc3dcadb49e9a4f4474ec743e2c5ddd7f44a27" -SRCREV_machine:qemux86-64 ?= "32bc3dcadb49e9a4f4474ec743e2c5ddd7f44a27" +SRCREV_machine:qemuppc ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" +SRCREV_machine:qemuriscv64 ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" +SRCREV_machine:qemuriscv32 ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" +SRCREV_machine:qemux86 ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" +SRCREV_machine:qemux86-64 ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4" -SRCREV_machine ?= "32bc3dcadb49e9a4f4474ec743e2c5ddd7f44a27" -SRCREV_meta ?= "3fe9b5c19ed6f8883e7d12a89a0ea882e3facfef" +SRCREV_machine ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" +SRCREV_meta ?= "3a459546a712ea2b92d6b5a5cfd175dd1851896c" # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll # get the /base branch, which is pure upstream -stable, and the same # meta SRCREV as the linux-yocto-standard builds. Select your version using the # normal PREFERRED_VERSION settings. BBCLASSEXTEND = "devupstream:target" -SRCREV_machine:class-devupstream ?= "83657f4189612e5cbcabc3058acd36c0bd120729" +SRCREV_machine:class-devupstream ?= "18ad16ce4a6b2714583fd1e1044c6ea8e53b3519" PN:class-devupstream = "linux-yocto-upstream" KBRANCH:class-devupstream = "v6.18/base" @@ -43,7 +43,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" -LINUX_VERSION ?= "6.18.33" +LINUX_VERSION ?= "6.18.34" PV = "${LINUX_VERSION}+git" From patchwork Wed Jun 10 16:47:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Bruce Ashfield X-Patchwork-Id: 89687 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6C3F3CD98CC for ; Wed, 10 Jun 2026 16:47:52 +0000 (UTC) Received: from mail-qv1-f45.google.com (mail-qv1-f45.google.com [209.85.219.45]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.25395.1781110064305253393 for ; Wed, 10 Jun 2026 09:47:44 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=niRPFX+6; spf=pass (domain: gmail.com, ip: 209.85.219.45, mailfrom: bruce.ashfield@gmail.com) Received: by mail-qv1-f45.google.com with SMTP id 6a1803df08f44-8ccf6a63a45so86278106d6.3 for ; Wed, 10 Jun 2026 09:47:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781110063; x=1781714863; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=bsMIPhEEM3EPxS5Jg4LksgDL2wCoSh5mosZYpA0dAOA=; b=niRPFX+6pXN2zvRBukflCxLHBFY/nzpt+0OrdtIpgeqMOzl14pWV8iWkvjqTRsTZTU tbuthKA64EH2Xa2c5IMkJtrAN8mwVMzu8cstKVD6iry032zSZZspAnBPsMoc3v+KPD6D UaJQKW0e1V1LgMGkpZqeQfRUqrt6q6ZRcQOyEHP94S2skww/TzkEHZ/7gRcp/1hdmn9b tSnpggbVybe4A8mESk+yxApCqpQ79k21bbxd6brRxSVNtDgXN0B6ydpVaU4OK6kCNHWX DGBEKWlEc3PWt83dNpz4/pfA3RHBI7KmfswlhZOrGEPEwY0GooVeBWeyDo6z+6Q3G2UK e1JA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781110063; x=1781714863; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=bsMIPhEEM3EPxS5Jg4LksgDL2wCoSh5mosZYpA0dAOA=; b=BjF4AIeUBoKs2/i2AKCQCuddOY/6vk4QgnbbsYZzzeeinWKN4uy3aR2jIdQqqkDe3B pkApTu6fM9cu3zH6nVwkrbFX7BVxPCFnunveGUiEJ+HsgFFHMkLkbhiVknibiP7xT1xI tCoO5sbQhMnM5xocxRmhqrXtaRgaXd1/vJhIzy8+em4VVh7xWmrJVejpe9WfEU+GkPBV +CPauELH1idvaUVcaLyGExl5fADMCxVbfzeVUF8B2WsWOtGNZXc4sM2Z1F4/pzXx7Iwf KU0dl+UevfMr5COKg8od4AG40ffMa7t7uX266ZMuh+nRHuCvgd16u9nrE/Epd8viYG6b pz5A== X-Gm-Message-State: AOJu0YxdfbjOfUjpTebqFCewRJoNUr0zWFKCRkZLddVe+0r7ukUViRCa Hlburw0Df2sRqb8jaJHFGmGgW/N2KDCwS5OUEjsD32opjhx4VkqakRn5Kpm7iTlv X-Gm-Gg: Acq92OGs7WFoH9DasqkQfZ3kw3c2xgJBHGBKCyuj7IFn9qFTRVQVVO8k1sRTFvvB9mb /vscYqhTLi4uRVXtLW8W1OTuuPI/Z9MpdiFZZbdOlgEfNeyBgK6Pv1J/fFG/e1mvv7QVg4EMyGf 6RQFESfr0fr82l0RFSspSGIB0BhNzcRNZn0jLW0XCMMdP9IUEGZaygUCLnQK83PbopmiX4moWKc 72/C5QzgU7uf342nxn2Z14Wp1uwufaG2/7ntvVGKCSgAKL4MatfIn2P6kluTtR9G68tf0Reyujk LhTiwjJ8bgmCVxVVseHWU4+OkASeAlonrLmiTgvuUMP8zyMH8RSrC6mtWABBONpid7UvVWbPvcl X4sjxdZq0+mVBRKT1K77huuqDAAdmZY5OoiKcIDMOXUYSb8FkkWnyE2DO/pKwip8ICeW+8viD7M 0QXP457iCHEdLewoTA2YWaSpjC9H0g/Gy52izVQR54+h9jnUUaEogk4kYk3tvYuwSPXr1SwL6IU HB5+g6AmNievHL2uc8kteXg33M7bgj50pbChh6TuRCzDLvwo+hGd5KhHGQ8+8ZMG4figsnMVTS7 +oaXblbvmG+WXbJB3YJ2B/sQtuzqWTBE1TgC4tmRRfOHxkLtqu9Z1CA= X-Received: by 2002:a05:622a:989:b0:517:61d5:2f7b with SMTP id d75a77b69052e-517eaadc92dmr163661cf.56.1781110062881; Wed, 10 Jun 2026 09:47:42 -0700 (PDT) Received: from bruce-XPS-8940.localdomain (pool-174-112-62-108.cpe.net.cable.rogers.com. [174.112.62.108]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-51775d9efa1sm214422401cf.20.2026.06.10.09.47.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 10 Jun 2026 09:47:41 -0700 (PDT) From: bruce.ashfield@gmail.com To: richard.purdie@linuxfoundation.org Cc: openembedded-core@lists.openembedded.org Subject: [meta][PATCH 02/04] linux-yocto/6.18: update to v6.18.35 Date: Wed, 10 Jun 2026 12:47:35 -0400 Message-ID: <20260610164737.1869790-3-bruce.ashfield@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260610164737.1869790-1-bruce.ashfield@gmail.com> References: <20260610164737.1869790-1-bruce.ashfield@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 10 Jun 2026 16:47:52 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/238374 From: Bruce Ashfield Updating linux-yocto/6.18 to the latest korg -stable release that comprises the following commits: acb7cf4c1184 Linux 6.18.35 918450ad6010 KVM: arm64: Reassign nested_mmus array behind mmu_lock 2bbc395e81bd KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry adc6fc240a61 tools: ynl: add scope qualifier for definitions f54b30f3316a usb: core: Fix SuperSpeed root hub wMaxPacketSize 830c8a9b467e thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() 21bfa15a89d8 drm/i915/psr: Use DC_OFF wake reference to block DC6 on vblank enable 00869f2320dc mailbox: Fix NULL message support in mbox_send_message() 5372f6f10b0a xhci: tegra: Fix ghost USB device on dual-role port unplug 58b2c0f096b3 net: phy: micrel: fix LAN8814 QSGMII soft reset 972ea882d4bf mm/slub: hold cpus_read_lock around flush_rcu_sheaves_on_cache() 56857385f313 hwmon: (pmbus/adm1266) serialize GPIO PMBus accesses with pmbus_lock 6b94f9f5fe28 hwmon: (pmbus/adm1266) serialize sequencer_state debugfs read with pmbus_lock 192516d72774 hwmon: (pmbus) Add support for guarded PMBus lock d8fdf33d6fcf USB: serial: mct_u232: fix memory corruption with small endpoint 062dcc0b324a USB: serial: digi_acceleport: fix memory corruption with small endpoints 284105c40fc3 USB: serial: cypress_m8: fix memory corruption with small endpoint c73c62a4bd52 usb: dwc3: xilinx: fix error handling in zynqmp init error paths 9327252e0462 xfrm: iptfs: reset runtime state when cloning SAs bb50838a2a06 cpufreq: intel_pstate: Use correct scaling factor on Raptor Lake-E 7cb2daed3509 cpufreq: intel_pstate: Add and use hybrid_get_cpu_type() 8f72a2509163 mptcp: reset rcv wnd on disconnect 82e742b9d2cc mptcp: cleanup fallback dummy mapping generation 0d9b9d7dbef9 octeontx2-pf: avoid double free of pool->stack on AQ init failure fe93e907b1af arm64: tlb: Flush walk cache when unsharing PMD tables bb37498a99e4 mptcp: do not drop partial packets a84164847b1e mptcp: borrow forward memory from subflow c67f986fc02c mptcp: handle first subflow closing consistently 134c517dfa63 net: devmem: reject dma-buf bind with non-page-aligned size or SG length b2beed6ad149 selftests: mptcp: drop nanoseconds width specifier c5e7d4865292 Bluetooth: hci_qca: Convert timeout from jiffies to ms 8264178afb5c Bluetooth: hci_qca: Migrate to serdev specific shutdown function 0acba63d7d46 serdev: Provide a bustype shutdown function 8bf7dbb741dd rxrpc: Fix RESPONSE packet verification to extract skb to a linear buffer 46cb765e2e5a rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg fed725cace3a x86/mm: Disable broadcast TLB flush when PCID is disabled 81181a39bde9 platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error recovery 1730c91a8b9a platform/x86/intel/vsec: Make driver_data info const 4b0e87f9b50f platform/x86/intel/vsec: Refactor base_addr handling 71b88acec0a7 serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq() 7f8b194ed720 serial: 8250: dispatch SysRq character in serial8250_handle_irq() 5f2172d799f3 serial: core: introduce guard(uart_port_lock_check_sysrq_irqsave) 237dc8c08de3 serial: zs: Convert to use a platform device 81984447eac4 serial: zs: Switch to using channel reset b1ceeaef4fbc serial: zs: Fix bootconsole handover lockup 2ff0401ffdda serial: dz: Convert to use a platform device 2c5b693d918c serial: dz: Fix bootconsole handover lockup 24b7be239b0b serial: dz: Fix bootconsole message clobbering at chip reset f059b4c493df drm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO fa372f4e8aef drm/amdgpu: fix calling VM invalidation in amdgpu_hmm_invalidate_gfx 1eb86334e391 drm/amdgpu: fix lock leak on ENOMEM in AMDGPU_GEM_OP_GET_MAPPING_INFO 275396bf71c4 drm/amdkfd: Check for pdd drm file first in CRIU restore path 5cf4a41aa0d7 drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger 2f9c3c161692 drm/amdkfd: fix NULL pointer bug in svm_range_set_attr 348e01e64a87 serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma 8e39badab090 serial: zs: Fix swapped RI/DSR modem line transition counting 10ddd1a320e1 serial: sh-sci: fix memory region release in error path 654f45a8569f serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ 78d0d6f69bd6 serial: qcom-geni: fix UART_RX_PAR_EN bit position 9a91692fae5c serial: altera_jtaguart: handle uart_add_one_port() failures ffa7dce35b64 drm/amd/pm/si: Disregard vblank time when no displays are connected c9ae7e7e3bc9 drm/i915: Fix potential UAF in TTM object purge fed64e47a32f drm/i915/psr: Block DC states on vblank enable when Panel Replay supported 0dfa42cfe4db drm/gem: fix race between change_handle and handle_delete 164dc7bf1760 drm/hyperv: validate VMBus packet size in receive callback 9c698b2c43c2 drm/hyperv: validate resolution_count and fix WIN8 fallback 4a3a19c98a82 scsi: target: iscsi: Validate CHAP_R length before base64 decode 594a40360012 scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf 89c81d1228c0 scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() 35461d237441 scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 14dd80a20a72 scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker d548179adcc8 thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow 31b98e503ecc thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() c7d421123b98 usb: gadget: f_fs: serialize DMABUF cancel against request completion 607730a41477 usb: gadget: f_fs: copy only received bytes on short ep0 read 5933063935e8 usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports f8f5a8f48c7c usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling f928630f450b usb: gadget: f_hid: fix device reference leak in hidg_alloc() e6f8be12f030 usb: gadget: net2280: Fix double free in probe error path caec0145e597 usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind f06bcaba2970 USB: serial: mct_u232: fix missing interrupt-in transfer sanity check 6c0cf56f00f2 USB: serial: mxuport: fix memory corruption with small endpoint ea2b792330b4 USB: serial: keyspan: fix missing indat transfer sanity check ae03453f2c80 USB: serial: cypress_m8: validate interrupt packet headers 22823a319fb2 USB: serial: belkin_sa: validate interrupt status length f7c3fcd63405 USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL 38ba1a464c0d USB: serial: option: add MeiG SRM813Q 62fbc1396108 usb: typec: ucsi: Don't update power_supply on power role change if not connected d62d97c9c8c2 usb: typec: ucsi: Check if power role change actually happened before handling f34effb0b545 usb: typec: tcpm: improve handling of DISCOVER_MODES failures 02d9d8b79e18 usb: typec: tipd: Fix error code in tps6598x_probe() a90139ff1eba usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize 75f6d3da2cc6 usb: usbtmc: check URB actual_length for interrupt-IN notifications 88d459e5b5a4 usbip: vudc: Fix use after free bug in vudc_remove due to race condition 5b78d8b9a832 usb: storage: Add quirks for PNY Elite Portable SSD 94b05aec1985 USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers 69f9f2b30af0 usb: musb: omap2430: Fix use-after-free in omap2430_probe() 3bc65566331a usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval 7118304b1a77 usb: chipidea: core: convert ci_role_switch to local variable 9fd48937046e tty: serial: samsung: Remove redundant port lock acquisition in rx helpers 66f8bfea055b tty: serial: pch_uart: add check for dma_alloc_coherent() b4bebb6e0a44 counter: Fix refcount leak in counter_alloc() error path c7e670cb2538 comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() 269f5be6a6e4 comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() fdb74898d91d Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 7f95f4792c0d Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem 639fa8af506e misc: rp1: Send IACK on IRQ activate to fix kdump/kexec 94215d55b094 ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops 6617ee91062b Input: xpad - add support for ASUS ROG RAIKIRI II 3d63b8077f5b Input: xpad - add "Nova 2 Lite" from GameSir 2ffd8b0dd448 ALSA: hda/realtek: Fix speaker output on ASUS ROG Strix G615LP c093468aea82 xfrm: esp: restore combined single-frag length gate c4609fff0665 ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks 35be14ea8298 ASoC: qcom: q6asm-dai: close stream only when running b98ab51c45c5 netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check b9027ff112b6 ALSA: firewire-motu: Protect register DSP event queue positions befcb15c1f05 ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 aa0c7e59192b xfrm: ah: use skb_to_full_sk in async output callbacks dc6dcba80d72 xfrm: ipcomp: Free destination pages on acomp errors 448bb92ca101 xfrm: route MIGRATE notifications to caller's netns 22d41b176b99 nfc: hci: fix out-of-bounds read in HCP header parsing 8b1f4f618fd8 iommu, debugobjects: avoid gcc-16.1 section mismatch warnings b8338111e141 HID: wacom: Fix OOB write in wacom_hid_set_device_mode() 59139473a7a7 spi: spi-mem: avoid mutating op template in spi_mem_supports_op() 96a4713ae041 net: skbuff: fix missing zerocopy reference in pskb_carve helpers fc32be9ac278 ip6: vti: Use ip6_tnl.net in vti6_changelink(). 947013fd7c8c l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname 9f7ebb45a83a xfrm: input: hold netns during deferred transport reinjection a35daeabb433 ipv6: validate extension header length before copying to cmsg 853f6ea482df ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). 751db1b802a0 ipv6: exthdrs: refresh nh after handling HAO option 90983f841dfa ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params c512e1c819df ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() 6d00f5c7e5ff macsec: fix replay protection at XPN lower-PN wrap 5e1902866796 bpf: sockmap: fix tail fragment offset in bpf_msg_push_data e4892b1ecd73 wireguard: send: append trailer after expanding head d59cc66b7027 x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines 3f43865cb64d i2c: davinci: fix division by zero on missing clock-frequency bf769358419e Input: elan_i2c - validate firmware size before use 84ea928ed584 usb: dwc2: Fix use after free in debug code 94c92f9c886c usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles 459c4fa089f7 usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure b2723bd468c5 usb: cdns3: gadget: fix request skipping after clearing halt 0fee0ccac29e USB: serial: omninet: fix memory corruption with small endpoint 3412a95afaa5 iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() a3763ae33476 iio: buffer: hw-consumer: fix use-after-free in error path 390254cf509b iio: light: cm3323: fix reg_conf not being initialized correctly 5e4d34092a5e iio: chemical: scd30: fix division by zero in write_raw a5a05410cb34 iio: chemical: mhz19b: reject oversized serial replies cbd2d7e6bd4f iio: Fix iio_multiply_value use in iio_read_channel_processed_scale 8d4daa614440 iio: light: veml6070: Fix resource leak in probe error path ae01ec83841d iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL aefc19ca3dd3 iio: temperature: tsys01: fix broken PROM checksum validation 04a4d9822210 iio: ssp_sensors: cancel delayed work_refresh on remove aaf9d640e9ae iio: gyro: adis16260: fix division by zero in write_raw 15a0b3f33ffb iio: gyro: itg3200: fix i2c read into the wrong stack location 5cb8cede8baf iio: adc: ad4695: Fix call ordering in offload buffer postenable 7155e7fce429 iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw 944082fdb028 iio: adc: mt6359: fix unchecked return value in mt6358_read_imp 991d359faa95 iio: dac: ad5686: fix powerdown control on dual-channel devices 31de336a2c0d iio: dac: ad5686: acquire lock when doing powerdown control f541c9a1eb89 iio: dac: ad5686: fix input raw value check 69f7d101976c iio: dac: ad5686: fix ref bit initialization for single-channel parts 684bfd655b80 iio: dac: max5821: fix return value check in powerdown sync 88c9dd5170e0 iio: dac: ad3530r: Fix AD3531/AD3531R powerdown mode strings 2ce5ca7824a1 iio: adc: npcm: fix unbalanced clk_disable_unprepare() 0ee771fff32e iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux bb1b43e8a7ed Disable -Wattribute-alias for clang-23 and newer bbd989d6fd36 KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() b1dfaa6f7a95 KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer 75c8d1d72912 KVM: SEV: Check PSC request indices against the actual size of the buffer 9f0a9e780f02 KVM: SEV: Compute the correct max length of the in-GHCB scratch area 5300aedbee56 KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 e4ab26f81a63 KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests 2254972d4d69 KVM: SEV: Ignore Port I/O requests of length '0' c9b4198fbc6e KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use ec62e8480e82 KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC b1fc4a83dd44 KVM: arm64: PMU: Preserve AArch32 counter low bits 625153b917bc USB: cdc-acm: Fix bit overlap and move quirk definitions to header 667599e71832 rust_binder: avoid calling pending_oneway_finished() on TF_UPDATE_TXN f2f2671e32c5 rust_binder: Avoid holding lock when dropping delivered_death 74d6aae1df45 parport: Fix race between port and client registration 9749db57233b Input: xpad - fix out-of-bounds access for Share button d9019210c8c3 Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync 2b7651f58670 Bluetooth: hci_qca: Use 100 ms SSR delay for rampatch and NVM loading e6b78019664d Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() bc08c15746f2 Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock c318aa51830a Bluetooth: ISO: fix UAF in iso_recv_frame 6348dfed5b0f Bluetooth: HIDP: fix missing length checks in hidp_input_report() e8a5baff5be2 Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn 859d3ace791e Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() 388051f7389a smb: client: fix uninitialized variable in smb2_writev_callback 197476b12601 auxdisplay: line-display: fix OOB read on zero-length message_store() 0fcc34d0d8fe mm/rmap: initialize nr_pages to 1 at loop start in try_to_unmap_one 0995d1f79aed memfd: deny writeable mappings when implying SEAL_WRITE f1f0cdca932b mm: memcontrol: propagate NMI slab stats to memcg vmstats a3cc795129e5 ipc: limit next_id allocation to the valid ID range 0ba6c05156d9 mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() 0886c6f257fe hpfs: fix a crash if hpfs_map_dnode_bitmap fails 4064a30381fa Bluetooth: btusb: Allow firmware re-download when version matches 6728e80c9d29 HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse 8735a28f2dcd Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() f33b5a61673b media: rc: igorplugusb: fix control request setup packet f793b67d41e5 USB: serial: safe_serial: fix memory corruption with small endpoint 0edd1e21587b usb: typec: ucsi: validate connector number in ucsi_connector_change() 9b496e3371c0 usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT e94933dc41b8 usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() b10eff5abe6a usb: typec: altmodes/displayport: validate count before reading Status Update VDO 052dbef45cb3 usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO 4505f33dab56 usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() f9d787fbe831 usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers a38ed87818b2 usb: typec: ucsi: ccg: reject firmware images without a ':' record header a58400f58f82 iio: pressure: bmp280: fix stack leak in bmp580 trigger handler ce582b22dd2f iio: imu: adis16550: fix stack leak in trigger handler e6bb3a49c5f9 iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer 278b0df1f736 phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X 487393023feb drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used c058cf6b84c1 drm/i915/psr: Read Intel DPCD workaround register dd4cbab2a446 drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register 600ad63124de s390/cio: Restore GFP_DMA for CHSC allocation 0171e01de47a Revert "x86/fpu: Refine and simplify the magic number check during signal return" ff0ca46b13b9 smb: client: validate the whole DACL before rewriting it in cifsacl efacf63ed087 media: rc: ttusbir: fix inverted error logic e250b672d40a media: rc: fix race between unregister and urb/irq callbacks 814be4a0924b net: skbuff: fix pskb_carve leaking zcopy pages ab9a10969a90 ipv6: fix possible infinite loop in fib6_select_path() dc36a04621dc ipv6: fix possible infinite loop in rt6_fill_node() b62e2b2b4a50 vsock/virtio: bind uarg before filling zerocopy skb 68667ee4c7da sctp: fix race between sctp_wait_for_connect and peeloff c4152b4e28b3 net: mana: Skip redundant detach on already-detached port da87896f34e0 net: mana: Add NULL guards in teardown path to prevent panic on attach failure 7f945f7f10f4 gpio: rockchip: teardown bugs and resource leaks e2fabb984bfd gpio: rockchip: convert bank->clk to devm_clk_get_enabled() 5d43c71fa8e1 gpio: virtuser: Fix uninitialized data bug in gpio_virtuser_direction_do_write() b6cdbb681ce1 gpio: adnp: fix flow control regression caused by scoped_guard() ae2eac5e9cfe Bluetooth: hci_sync: Reset device counters in hci_dev_close_sync() 47330cc875b3 Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close 41e29548b5e8 Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp f39049304ba6 Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success 1d4dcfe60fe1 net/handshake: Pass negative errno through handshake_complete() 25b2fcdea6f6 nvme-tcp: store negative errno in queue->tls_err 0866569fc36a net/handshake: Use spin_lock_bh for hn_lock c35064294eca net: hibmcge: disable Relaxed Ordering to fix RX packet corruption 7f97b8352ce5 net/sched: Revert "net/sched: Restrict conditions for adding duplicating netems to qdisc tree" 6fe1cb312038 ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() fd0de51c54fa ethtool: eeprom: add more safeties to EEPROM Netlink fallback c944cab3df82 ethtool: eeprom: add missing ethnl_ops_begin() / _complete() during fallback 3e656023a649 ethtool: strset: fix header attribute index in ethnl_req_get_phydev() 2008f9bb1ede ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure ab94e0d6664d ethtool: tsinfo: fix uninitialized stats on the by-PHC path d02342d9bb4f ethtool: tsconfig: fix missing ethnl_ops_complete() 912f8b23bc4b ethtool: pse-pd: fix missing ethnl_ops_complete() 49455e27838a ethtool: linkstate: fix unbalanced ethnl_ops_complete() on PHY lookup error d11c98484485 ethtool: tsconfig: fix reply error handling 0c02c190bcd9 ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES e976e3f2f200 bridge: Fix sleep in atomic context in sysfs path c9c2e609e839 bridge: Fix sleep in atomic context in netlink path 9ea8a648d912 bonding: refuse to enslave CAN devices e673889a35a5 Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() 75cf24709037 drm/xe: Restore IDLEDLY regiter on engine reset 164dcbec9632 ASoC: codecs: simple-mux: Fix enum control bounds check de9eb0b44fa9 ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE 43368636c663 tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() 5303925e3605 vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() 6dff77899b9e tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() 2a8c9994406b cxl/test: Update mock dev array before calling platform_device_add() 41d2dc766bf8 ethtool: cmis: validate fw->size against start_cmd_payload_size 0696709e951b ethtool: cmis: validate start_cmd_payload_size from module 0cbce444db75 ethtool: cmis: fix u16-to-u8 truncation of msleep_pre_rpl 4d42fb88ec61 ethtool: cmis: require exact CDB reply length e1dd697094f1 ethtool: module: fix cleanup if socket used for flashing multiple devices 9e70c8efb0ca ethtool: module: check fw_flash_in_progress under rtnl_lock 9f5108f5ee27 ethtool: module: avoid racy updates to dev->ethtool bitfield 61848c83b913 ethtool: module: avoid leaking a netdev ref on module flash errors d9defbf8b62b ethtool: module: call ethnl_ops_complete() on module flash errors 7877d8fbbec2 ethtool: rss: avoid device context leak on reply-build failure 7ddc3b3ddee8 ethtool: rss: fix hkey leak when indir_size is 0 33d05c22d6f2 ethtool: rss: fix indir_table and hkey leak on get_rxfh failure 39c01c405063 ethtool: rss: fix falsely ignoring indir table updates 6a775ec73210 ethtool: rss: add missing errno on RSS context delete f23e4d7324b8 ethtool: rss: avoid modifying the RSS context response 48fd840a26d3 net: Avoid checksumming unreadable skb tail on trim 03e9405c518c net: team: fix NULL pointer dereference in team_xmit during mode change c2af23b48f93 net: team: Rename port_disabled team mode op to port_tx_disabled a20e6ae5f05e net: team: Remove unused team_mode_op, port_enabled f2e077e8979f gpio: mxc: fix irq_high handling fbd0662f9c9a net: hsr: fix potential OOB access in supervision frame handling 2a15a03e58b0 net/mlx5: HWS: Reject unsupported remove-header action f0ac76e3d55e ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors e13922bb97b4 ALSA: pcm: oss: Fix setup list UAF on proc write error a7f4eefb6e14 ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() 475f2b37a78f scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues 981736924338 net/iucv: fix locking in .getsockopt 55cba6b883b4 net/smc: Do not re-initialize smc hashtables bcd0d19db3e6 net: netlink: don't set nsid on local notifications ca5e36629641 net: netlink: fix sending unassigned nsid after assigned one ef3b3ea864d0 vsock: keep poll shutdown state consistent aa308e9dbb9a tun: free page on build_skb failure in tun_xdp_one() 37a1c268c2c8 tun: free page on short-frame rejection in tun_xdp_one() 96bea2a7baac netfilter: nf_tables: fix dst corruption in same register operation bf8e8eac7ede netfilter: ebtables: fix OOB read in compat_mtw_from_user 052468b1c93b netfilter: xt_cpu: prefer raw_smp_processor_id f0fea2b6d545 netfilter: synproxy: refresh tcphdr after skb_ensure_writable 18abd88d19ea accel/rocket: fix UAF via dangling GEM handle in create_bo 45564a16a24f kunit: fix use-after-free in debugfs when using kunit.filter e1b8a53834dc HID: remove duplicate hid_warn_ratelimited definition bebc7dc0fb4b tools/bootconfig: Fix buf leaks in apply_xbc b4702049417f nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems 82ac903e0b51 xfrm: Check for underflow in xfrm_state_mtu 650bdd8fdfab nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() 912ebc49d440 nfc: llcp: Fix use-after-free in llcp_sock_release() 8b733ee4aecd bcache: fix uninitialized closure object dbc560858da8 net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked 91cc13978ab0 xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit 54ed418de62a net: mctp: ensure our nlmsg responses are initialised 41845bc5bb64 net/sched: cls_fw: fix NULL dereference of "old" filters before change() 0ca809ea8e03 Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size Signed-off-by: Bruce Ashfield --- .../linux/linux-yocto-rt_6.18.bb | 6 ++--- .../linux/linux-yocto-tiny_6.18.bb | 6 ++--- meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +++++++++---------- 3 files changed, 18 insertions(+), 18 deletions(-) diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb index 09adce37c1..00c0b090df 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb @@ -15,13 +15,13 @@ python () { raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") } -SRCREV_machine ?= "70ee73bc5040b0150d134f5830dcbb83f8f550f6" -SRCREV_meta ?= "3a459546a712ea2b92d6b5a5cfd175dd1851896c" +SRCREV_machine ?= "35a623d1a755631bbc73e11fa02eee0e1092188b" +SRCREV_meta ?= "4dafe0e420087b6381728e68eeeff6d9af0a32e7" SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" -LINUX_VERSION ?= "6.18.34" +LINUX_VERSION ?= "6.18.35" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb index 3723c81c72..e2fd09a403 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb @@ -9,7 +9,7 @@ require recipes-kernel/linux/linux-yocto.inc include recipes-kernel/linux/cve-exclusion.inc include recipes-kernel/linux/cve-exclusion_6.18.inc -LINUX_VERSION ?= "6.18.34" +LINUX_VERSION ?= "6.18.35" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}" @@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native" KMETA = "kernel-meta" KCONF_BSP_AUDIT_LEVEL = "2" -SRCREV_machine ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" -SRCREV_meta ?= "3a459546a712ea2b92d6b5a5cfd175dd1851896c" +SRCREV_machine ?= "efc05d9af9f5b5a647e229c92542e413c3a9915d" +SRCREV_meta ?= "4dafe0e420087b6381728e68eeeff6d9af0a32e7" PV = "${LINUX_VERSION}+git" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb index 09c2093e16..2b1298dedf 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb @@ -17,25 +17,25 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base" KBRANCH:qemuloongarch64 ?= "v6.18/standard/base" KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta" -SRCREV_machine:qemuarm ?= "1fa8e29233b43f22ce5dd26e3bc08ad79784a7ca" -SRCREV_machine:qemuarm64 ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" -SRCREV_machine:qemuloongarch64 ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" +SRCREV_machine:qemuarm ?= "84b49a9fef57bf4ff3a2919591fde336fe7944bf" +SRCREV_machine:qemuarm64 ?= "efc05d9af9f5b5a647e229c92542e413c3a9915d" +SRCREV_machine:qemuloongarch64 ?= "efc05d9af9f5b5a647e229c92542e413c3a9915d" SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e" -SRCREV_machine:qemuppc ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" -SRCREV_machine:qemuriscv64 ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" -SRCREV_machine:qemuriscv32 ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" -SRCREV_machine:qemux86 ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" -SRCREV_machine:qemux86-64 ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" +SRCREV_machine:qemuppc ?= "efc05d9af9f5b5a647e229c92542e413c3a9915d" +SRCREV_machine:qemuriscv64 ?= "efc05d9af9f5b5a647e229c92542e413c3a9915d" +SRCREV_machine:qemuriscv32 ?= "efc05d9af9f5b5a647e229c92542e413c3a9915d" +SRCREV_machine:qemux86 ?= "efc05d9af9f5b5a647e229c92542e413c3a9915d" +SRCREV_machine:qemux86-64 ?= "efc05d9af9f5b5a647e229c92542e413c3a9915d" SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4" -SRCREV_machine ?= "9b4e099993ff056f132851e3d3ff67550e0e9090" -SRCREV_meta ?= "3a459546a712ea2b92d6b5a5cfd175dd1851896c" +SRCREV_machine ?= "efc05d9af9f5b5a647e229c92542e413c3a9915d" +SRCREV_meta ?= "4dafe0e420087b6381728e68eeeff6d9af0a32e7" # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll # get the /base branch, which is pure upstream -stable, and the same # meta SRCREV as the linux-yocto-standard builds. Select your version using the # normal PREFERRED_VERSION settings. BBCLASSEXTEND = "devupstream:target" -SRCREV_machine:class-devupstream ?= "18ad16ce4a6b2714583fd1e1044c6ea8e53b3519" +SRCREV_machine:class-devupstream ?= "acb7cf4c1184e27622be0faf89244d5001ed1e87" PN:class-devupstream = "linux-yocto-upstream" KBRANCH:class-devupstream = "v6.18/base" @@ -43,7 +43,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" -LINUX_VERSION ?= "6.18.34" +LINUX_VERSION ?= "6.18.35" PV = "${LINUX_VERSION}+git" From patchwork Wed Jun 10 16:47:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Bruce Ashfield X-Patchwork-Id: 89684 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6139ECD98C6 for ; Wed, 10 Jun 2026 16:47:52 +0000 (UTC) Received: from mail-qt1-f170.google.com (mail-qt1-f170.google.com [209.85.160.170]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.25396.1781110065488560591 for ; Wed, 10 Jun 2026 09:47:45 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=iD9U6TpK; spf=pass (domain: gmail.com, ip: 209.85.160.170, mailfrom: bruce.ashfield@gmail.com) Received: by mail-qt1-f170.google.com with SMTP id d75a77b69052e-51761d27612so81167331cf.3 for ; Wed, 10 Jun 2026 09:47:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781110064; x=1781714864; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=S5/H2Liv+ZHgwzjBjRrP8wc9UZa5fP8CeFAA9niK3UM=; b=iD9U6TpKYMLpGQ5vsO676koTaj7Z2pX8ihG6J/xVbKcbQwrJiO+W4jALO2IEoumE0L +/qharRYcH5EsdM+YCmOIO6yqxh/mhvcDIDOe0iDG98zl3/8bzDKdmDXleohfKyAG7eI yBimxPRe5JMy3Pycpx+3Rafg1S8n0y672bI19gapyDksYRti+Si8LDr9fH6RfTxqgQXV vdxpFDyen2vJ7X2/uzbKRPi8ClX4+Xdo9SxgFxLX2MF4csEJBGt5Yqh2J6GbhBhTPBGE 7zfuKnvaVV40cVRlo03vOPtJCSdrO3arwuZUFvOqx+RV7tooEZ8OgWUHK1wDH3/A+2Sr 59WA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781110064; x=1781714864; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=S5/H2Liv+ZHgwzjBjRrP8wc9UZa5fP8CeFAA9niK3UM=; b=Glujt1dm7XMPkCmPFTBdC76IQt5XH4cKlgZ7h0WYm9q+SCEvfMzI0TyG1RLHoCMHk5 Ss+wCNaUjaHxwek15HBITAUiTPRAhahhte0K+aWgzpvRxGjs/fBDGnzqE2R/Zqs1c9aW ceOGedAOiA4PHdTSNKcBONNdywHS+gUf7xxY73beFl94agTjOWwTTJ7yI45Ehdh1Gsjj Y6fLI7zmgxeBmmGZ6P8j1jXxyJJtou6cebTt8tcfOXroj2Po6oSFMjnCg5mEtdwFJ4Ux nuDj/UBIjnzummjc4YpPtrIyNMB1Qvt8FJtM7xvZv//lokaAr7J7VZYJrIclmbMuNhGE XhMw== X-Gm-Message-State: AOJu0Yy4E/L3J0juu3JRkNYbb8KB7B3YpCfAjbcRJTphG04t0rktW8/X EcuBd7hFV1d7yXL+P/T1UmLdtKrC3FaFJFckFFNs8FnbZbY/TO2Xkg8WjhR0aenf X-Gm-Gg: Acq92OE00UF8rO9czt+6PtrRATepp6eZSN3yJGpRgOK3Gr7KHTv7VM2TcjOvrntyBlV fmPw0G6Spid2/ay5IyVSgL5tr+iYYqOfDBjQDgnTqW+V6+vfLwmtMRdyivhaCMZFrJcoxwNxk9J UQbDIMaqpeo3Q1b5sD2Ik9XNis2WxrGXimTpegjKt/beEyK8mNolSoNNbGt2y433jjSfP3DtgGs 4WgDO6gi0Whi3As4uPXyTBGFHMWtzRBGJzrfTNTJLkeezD3y7EoIh8BoGoeyPg1FE7pue1kw2Ia jUfzVBmfSliE788Rd3Zo6phZB6kJnp9PY4YrdhBB5B+Vz/MUsx4WrTjd4I89kHUyZaqZmMc6rsY yXQb83uM/fGLA4DNOLMbRKjzQzZiwqza7Utb6rGIGjNYeoyNgWERhAjVIh8K4MV4xEh58hbibUt HlwlKB16m6sCbaruOaVx9HIoT3IeTqbDjd61uCpKa/RYul0cmdBGirG3WAjKghg0QwWX6Bgwer2 CKUI2f85uMCvONY99UJIpL9Px1H5EL0UisUM29kdxgRqgSYlardxM4z9ehdpNMt1onv/xzaDQLL b/BLEBLBQhg0lQGU0dnt/0QdZRqO1tDHgIujFKVia6jVydWKOqX9aJmfiGJGQzE+Aw== X-Received: by 2002:ac8:5a50:0:b0:516:d60f:6457 with SMTP id d75a77b69052e-51795b0cf8bmr349189871cf.4.1781110064138; Wed, 10 Jun 2026 09:47:44 -0700 (PDT) Received: from bruce-XPS-8940.localdomain (pool-174-112-62-108.cpe.net.cable.rogers.com. [174.112.62.108]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-51775d9efa1sm214422401cf.20.2026.06.10.09.47.43 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 10 Jun 2026 09:47:43 -0700 (PDT) From: bruce.ashfield@gmail.com To: richard.purdie@linuxfoundation.org Cc: openembedded-core@lists.openembedded.org Subject: [meta-yocto-bsp][PATCH 03/04] yocto-bsps: update to v6.18.34 Date: Wed, 10 Jun 2026 12:47:36 -0400 Message-ID: <20260610164737.1869790-4-bruce.ashfield@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260610164737.1869790-1-bruce.ashfield@gmail.com> References: <20260610164737.1869790-1-bruce.ashfield@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 10 Jun 2026 16:47:52 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/238375 From: Bruce Ashfield Updating linux-yocto/6.18 to the latest korg -stable release that comprises the following commits: 18ad16ce4a6b Linux 6.18.34 50bb3435a5e6 security/keys: fix missed RCU read section on lookup 239172639075 drm/msm: Restore second parameter name in purge() and evict() 306ba9d0e5aa LoongArch: kprobes: Fix handling of fatal unrecoverable recursions a1a39f227c80 ksmbd: fix durable reconnect error path file lifetime 6836f694126e io_uring/nop: pass all errors to userspace e334cbf3388f net: gro: don't merge zcopy skbs 8129611d4ede pds_core: ensure null-termination for firmware version strings d1d76bbb6d7a net: airoha: Disable GDM2 forwarding before configuring GDM2 loopback 719007c3492f tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR fa627a5eaa83 net: mana: validate rx_req_idx to prevent out-of-bounds array access bc0020490f88 octeontx2-af: npc: Fix allmulticast skip logic for LBK and SDP VFs 76dd50b7888d selftests: net: Fix checksums in xdp_native 04ef7592eaad drm/xe/oa: Fix exec_queue leak on width check in stream open db86ac6d8daf ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() decacc6308c5 gpio: aggregator: lock device when calling device_is_bound() 3e657619cf72 gpio: aggregator: remove the software node when deactivating the aggregator 80d94cf1773a gpio: aggregator: stop using dev-sync-probe ea28b286649b gpio: aggregator: fix a potential use-after-free 4669f84adcb1 gpio: cdev: check if uAPI v2 config attributes are correctly zeroed e47f7060eaf6 tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction 1861d369efd6 bpf, skmsg: fix verdict sk_data_ready racing with ktls rx 26f1d4522060 net: ag71xx: check error for platform_get_irq 585f9f6aef5c crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks 2417df5e7bb4 net: shaper: rework the VALID marking (again) 5a2c2aa139c8 net: shaper: annotate the data races b5bd4249e430 net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA a0f5268c77eb Bluetooth: btmtk: fix urb->setup_packet leak in error paths c7860b6a6d2d Bluetooth: btintel_pcie: Fix incorrect MAC access programming d6c8b3ebdcdb tracing: Avoid NULL return from hist_field_name() on truncation 8bf00d3ac425 cgroup: rstat: relax NMI guard after switch to try_cmpxchg 3aab4a58d23f ALSA: seq: Serialize UMP output teardown with event_input 95c82d498d74 wifi: wilc1000: fix dma_buffer leak on bus acquire failure 55c479aae99b wifi: mac80211: fix MLE defragmentation 2d8379834800 wifi: mac80211: bounds-check link_id in ieee80211_ml_epcs 425d32d6288d erofs: fix managed cache race for unaligned extents 91d13e92b983 pds_core: fix debugfs_lookup dentry leak and error handling 784dd2bdc622 pds_core: fix error handling in pdsc_devcmd_wait ce23832071af net: airoha: Fix NPU RX DMA descriptor bits 0c277d203684 net: phy: honor eee_disabled_modes in phy_advertise_eee_all() bd731994cff1 net: phy: honor eee_disabled_modes in phy_support_eee() a9224862d597 bridge: mcast: Fix a possible use-after-free when removing a bridge port 981aea209977 net: bridge: Flush multicast groups when snooping is disabled eae62c5451e6 RDMA/rtrs: Fix use-after-free in path file creation cleanup 8c63698737b4 RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port d5b11e15ee67 ASoC: soc-utils: Add missing va_end in snd_soc_ret() 09deb063eecf platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL f6dfd64bfd9b platform/x86: intel-hid: Check ACPI_HANDLE() against NULL ed864a7b881c platform/x86: hp_accel: Check ACPI_COMPANION() against NULL 7ea5aad8d351 platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL 098419a4b062 platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 09ec063d87c2 net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer f71fc35b5e45 net: dsa: mt7530: preserve VLAN tags on trapped link-local frames 89bed786f231 net: dsa: mt7530: fix FDB entries not aging out with short timeout f1739debda62 kbuild: pacman-pkg: make "rc" releases adhere to pacman versioning scheme ad8e3d096fa1 drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP 1f83545f432d igc: set tx buffer type for SMD frames 89964ddb322a ice: ptp: use primary NAC semaphore on E825 0010296879df ice: ptp: serialize E825 PHY timer start with PTP lock 6a01413a4e8f cgroup/rstat: validate cpu before css_rstat_cpu() access 83b8a0f72ecc drm/mediatek: mtk_hdmi_ddc: Fix non-static global variable 8ea34da68964 drm/mediatek: mtk_cec: Fix non-static global variable 926a08cf19be wifi: ath11k: fix peer resolution on rx path when peer_id=0 6c9e9272bc37 drm/xe/pf: Fix CFI failure in debugfs access dc26e00860a1 drm/xe/vf: Fix signature of print functions 2c890e71ae26 drm/xe/gsc: Fix double-free of managed BO in error path 181e67bc11c5 dma-mapping: move dma_map_resource() sanity check into debug code 3a74aaad0473 wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it 9e360e610a73 wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled bed1fc32e0eb hwmon: (lm90) Add lock protection to lm90_alert c98107817b0f hwmon: (lm90) Stop work before releasing hwmon device cdd1aaf0ee96 drm/msm/snapshot: fix dumping of the unaligned regions 0c9e4d9484cc ALSA: hda/realtek: Use ALC287_FIXUP_TXNW2781_I2C for ASUS Strix Gxx5 df19b6af1716 netfilter: nft_inner: release local_lock before re-enabling softirqs 0fa225896f4b spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() fecfed41da73 ASoC: amd: acp-sdw-legacy: check CPU DAI name before logging 7e91d3a1a98a btrfs: fix squota accounting during enable generation ca56ffdb017b btrfs: check for subvolume before deleting squota qgroup b422609291f6 btrfs: relax squota parent qgroup deletion rule 22d558df51d9 btrfs: check squota parent usage on membership change a1296bb9f44a btrfs: remaining BTRFS_PATH_AUTO_FREE conversions 76ad957a72c7 btrfs: don't search back for dir inode item in INO_LOOKUP_USER 16141bef6fb1 btrfs: use the key format macros when printing keys 35f69e993d00 btrfs: add macros to facilitate printing of keys 76b995bc57bd vsock/virtio: fix zerocopy completion for multi-skb sends 782693eb53f8 io_uring/net: punt IORING_OP_BIND async if it needs file create c53cac053d62 ALSA: scarlett2: Add missing error check when initialise Autogain Status 1ddf678bb75b ASoC: codecs: fs210x: fix possible buffer overflow 36de63965464 scsi: sd: Fix return code handling in sd_spinup_disk() b4dc0056397f net/mlx5: Do not restore destination-less TC rules 81c8a9f75a42 tls: Preserve sk_err across recvmsg() when data has been copied 1370acb8bc39 ovpn: disable BHs when updating device stats f7808b7ddcf2 x86/xen: Fix xen_e820_swap_entry_with_ram() 2378d25675da gcc-plugins: Always define CONST_CAST_GIMPLE and CONST_CAST_TREE 097d62df3831 ovpn: fix race between deleting interface and adding new peer 8298834912d7 ovpn: respect peer refcount in CMD_NEW_PEER error path e5460eb7238c ovpn: tcp - use cached peer pointer in ovpn_tcp_close() 2bc34520ce5c net: phy: DP83TC811: add reading of abilities af855f4c966a net: tls: prevent chain-after-chain in plain text SG eca989eab4b2 net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring afa9036b8c99 net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot 6dcd072a5ae3 powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() f4e37f3df436 drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN eea43d5ed450 drm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx 3a7b59d2385d Documentation: intel_pstate: Fix description of asymmetric packing with SMT 3ad2d8be6e4d x86/mce: Restore MCA polling interval halving 15dba511d569 selftests: ublk: cap nthreads to kernel's actual nr_hw_queues ff58e5ef1b46 drm/msm/dpu: don't mix devm and drmm functions a184aec79013 drm/msm/dsi: don't dump registers past the mapped region d235f8f7b264 ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics d2ea0b8aef87 net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint 97a8e89cdef3 accel/qaic: Add overflow check to remap_pfn_range during mmap 76410790f149 block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() 086695145000 HID: quirks: really enable the intended work around for appledisplay 0943f81e1b31 block: recompute nr_integrity_segments in blk_insert_cloned_request 0d48654af4d1 block: don't overwrite bip_vcnt in bio_integrity_copy_user() a52486394493 net: shaper: reject QUEUE scope handle with missing id 77ec90d41c59 net: shaper: enforce singleton NETDEV scope with id 0 d7c2bbbaa2c4 net: shaper: fix undersized reply skb allocation in GROUP command f817ce8d1943 net: shaper: set ret to -ENOMEM when genlmsg_new() fails in group_doit 5098b223f0f0 net: shaper: reject duplicate leaves in GROUP request d6128451c591 net: shaper: fix trivial ordering issue in net_shaper_commit() d947e6685ff4 net: shaper: flip the polarity of the valid flag e1b429d8e712 wifi: ath10k: skip WMI and beacon transmission when device is wedged d94127d04017 wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() acde4692afcd wifi: ath11k: fix error path leaks in some WMI WOW calls 9bc70fe995da net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference c373b34877af net: ethernet: cortina: Carry over frag counter 3cd05250a2df net: ethernet: cortina: Drop half-assembled SKB cfd62907f3cd net: ethernet: cortina: Make RX SKB per-port 77bb293049d6 netfs, afs: Fix write skipping in dir/link writepages f17b9121bb99 netfs: Fix netfs_read_folio() to wait on writeback 551b5c71ee31 netfs: Fix folio->private handling in netfs_perform_write() 3d9601c029b9 netfs: Fix partial invalidation of streaming-write folio 6080fa3ecfbb netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() 22ae28aae436 netfs: Fix leak of request in netfs_write_begin() error handling d4f4bc87c765 netfs: Fix early put of sink folio in netfs_read_gaps() 616578e40dcb netfs: Fix write streaming disablement if fd open O_RDWR 0b18cd70ebab netfs: Fix read-gaps to remove netfs_folio from filled folio 003aa0dd26c9 netfs: Fix potential deadlock in write-through mode ef9b521212e4 netfs: Fix streaming write being overwritten 185ded4112cd netfs: Defer the emission of trace_netfs_folio() fb6ec883b48b netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone afeb32d9bf9a netfs: Fix overrun check in netfs_extract_user_iter() b63971238beb netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call 884c4c4f35e5 netfs: Fix netfs_read_to_pagecache() to pause on subreq failure 5366199be46f netfs: Fix cancellation of a DIO and single read subrequests 9c6f23cf3a07 powerpc: fix dead default for GUEST_STATE_BUFFER_TEST 822bb1614ec4 powerpc: 82xx: fix uninitialized pointers with free attribute aed60070ed7b ASoC: SOF: amd: Fix error code handling in psp_send_cmd() 510db031ba6e tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key(). eba8af785fde zonefs: handle integer overflow in zonefs_fname_to_fno 9525e3a6fbb1 nvme-pci: fix use-after-free in nvme_free_host_mem() fea4b46f84c5 nvme: fix bio leak on mapping failure 18c0456ea261 irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT 06ee55f78fbe nsfs: fix wrong error code returned for pidns ioctls d168a71fc1d6 ublk: reject max_sectors smaller than PAGE_SECTORS in parameter validation 617a2564d863 irqchip/ath79-cpu: Remove unused function ace6b3e033c6 fs: Fix return in jfs_mkdir and orangefs_mkdir e37ea2c6f17f fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap 56b4cfcf1518 fprobe: Fix unregister_fprobe() to wait for RCU grace period 36dc0cea30db ASoC: sdw_utils: Add quirk to ignore RT721 CODEC_MIC 5afefecfe054 ASoC: sdw_utils: Add quirk to ignore RT712 CODEC_MIC fe59ae27d734 NFSD: Fix infinite loop in layout state revocation e9405f704127 phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access 994358adc098 net: ti: icssm-prueth: fix eth_ports_node leak in probe 7df3e1dfee53 net: lan966x: avoid unregistering netdev on register failure d91a9a049698 ice: fix locking in ice_dcb_rebuild() 34ad3c782644 ice: fix setting RSS VSI hash for E830 eb5991d4c8ba idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() a248793f00ab net: shaper: Reject reparenting of existing nodes bfe08fe5624b net: napi: Avoid gro timer misfiring at end of busypoll 77e7818eb347 tcp: Fix imbalanced icsk_accept_queue count. 1c24cf1fd67f test_kprobes: clear kprobes between test runs ae8a5c6b0316 kprobes: skip non-symbol addresses in kprobe_add_ksym_blacklist() c647e2a21bbb netfilter: bridge: eb_tables: close module init race 524b6337277a netfilter: x_tables: close dangling table module init race cc989ef1c044 netfilter: ebtables: close dangling table module init race 739d5dac7b2d netfilter: ebtables: move to two-stage removal scheme 86ee5bc9c0f0 netfilter: x_tables: add and use xtables_unregister_table_exit 89ebafe7910d netfilter: x_tables: add and use xt_unregister_table_pre_exit a9b2f73f6ba7 netfilter: x_tables: unregister the templates first c32a7e0e3c73 btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() 373f65b448ed ALSA: hda: cs35l41: Put ACPI device on missing physical node fecae8b1fb2d ALSA: hda: cs35l56: Put ACPI device after setting companion e984dc22e2c2 ARM: integrator: Fix early initialization 9e472874c954 firmware: arm_ffa: Fix sched-recv callback partition lookup d1e38551fade firmware: arm_ffa: Snapshot notifier callbacks under lock 419cef661ae8 firmware: arm_ffa: Align RxTx buffer size before mapping 3c51d99449dc firmware: arm_ffa: Validate framework notification message layout 0a5dbac5ef53 firmware: arm_ffa: Keep framework RX release under lock f39bc7ebe75e firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies fd2b01637e56 pinctrl: qcom: Fix wakeirq map by removing disconnected irqs for sm8150 3f4d82780001 kunit: config: KUNIT_DEBUGFS should depend on DEBUG_FS 91e4446b35f6 kunit: config: Enable KUNIT_DEBUGFS by default 96b8b9d0dead riscv: mm: Fixup no5lvl failure when vaddr is invalid f3216d930c0f riscv: errata: Fix bitwise vs logical AND in MIPS errata patching 1aa01b46fe3b firmware: arm_ffa: Unregister bus notifier on teardown for FF-A v1.0 07907b897bb7 firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue 1418765d28ab firmware: arm_ffa: Skip free_pages on RX buffer alloc failure 820245d86ce5 firmware: arm_ffa: Check for NULL FF-A ID table while driver registration 4894847fcec1 HID: uclogic: Fix regression of input name assignment e912d5dc0096 HID: intel-thc-hid: Intel-quickspi: Fix some error codes 1fce9dcb3a66 pinctrl: qcom: Fix GPIO to PDC wake irq map for qcs615 e917713f0134 pinctrl: meson: amlogic-a4: fix deadlock issue 8d1c6b603327 pinctrl: renesas: rzg2l: Fix SMT register cache handling c4cfa8ee7737 pinctrl: renesas: rzg2l: Fix incorrect PUPD register offset for high pins during suspend/resume a7fee1322683 ARM: dts: renesas: rskrza1: Drop superfluous cells d27b29e474a6 ARM: dts: renesas: genmai: Drop superfluous cells 00aca89f5e34 pinctrl: qcom: ipq4019: mark gpio as a GPIO pin function eb3cd9bb5904 hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors dd12c6dbe2ac hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() a203125c0e81 hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() b2998ae90331 hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple fa7ca363069a hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR 97a9cf2a8217 hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer 2279c342d94e hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer 75c862adf3d3 hwmon: (pmbus/adm1266) reject implausible blackbox record_count e9b8f85daebf hwmon: (pmbus/adm1266) seed timestamp from the real-time clock e37dbe150515 batman-adv: tt: prevent TVLV entry number overflow 730de8733dd9 batman-adv: tt: fix negative tt_buff_len 179eb62506a0 batman-adv: tt: fix negative last_changeset_len b93ca6012712 batman-adv: tt: avoid empty VLAN responses 7cac9c9ef4b7 batman-adv: tt: reject oversized local TVLV buffers 4cc85aec8d3c batman-adv: tt: fix TOCTOU race for reported vlans 2d2d365d0b9d batman-adv: tp_meter: avoid role confusion in tp_list 72d670d7a492 batman-adv: tp_meter: fix race condition in send error reporting b285bc0a97f4 batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown 770bf0a35f06 batman-adv: tp_meter: directly shut down timer on cleanup dc2ae5fbd2da batman-adv: tp_meter: avoid use of uninit sender vars 6921a7683ae9 batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface 45384612f296 batman-adv: bla: avoid double decrement of bla.num_requests c6de1a5a9c40 batman-adv: bla: fix report_work leak on backbone_gw purge 5895ad21c705 batman-adv: frag: disallow unicast fragment in fragment 90ae3eae06b7 batman-adv: fix tp_meter counter underflow during shutdown 3eb8bcb82339 batman-adv: fix fragment reassembly length accounting 9cceea8eeba7 batman-adv: dat: handle forward allocation error ae7aeb0ce3c0 batman-adv: clear current gateway during teardown 8a3707653ab6 batman-adv: mcast: fix use-after-free in orig_node RCU release ca3ff3d2a0af batman-adv: iv: recover OGM scheduling after forward packet error ede47988ac56 batman-adv: tvlv: reject oversized TVLV packets 23d4ce84df4d batman-adv: tvlv: abort OGM send on tvlv append failure 1be1e99cbd5b batman-adv: v: stop OGMv2 on disabled interface 1ecde19bfce6 drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async 7ca695b31222 drm/amd/display: Validate GPIO pin LUT table size before iterating 6bbd703ea1c1 drm/amd/display: Fix integer overflow in bios_get_image() d35563813296 drm/bridge: megachips: remove bridge when irq request fails 95306db11956 drm/bridge: it66121: acquire reset GPIO in probe 3ed448c1dc78 drm/amdgpu/vpe: Force collaborate sync after TRAP 8fadd01cf461 drm/virtio: use uninterruptible resv lock for plane updates 35671087a272 drm/v3d: Release indirect CSD GEM reference on CPU job free 0f8efc45740b drm/v3d: Fix use-after-free of CPU job query arrays on error path 942968260e61 drm/msm: Fix shrinker deadlock 508fd8ab158a device property: set fwnode->secondary to NULL in fwnode_init() 22d9b9739b8e LoongArch: Remove unused code to avoid build warning f27a3b9aadfb LoongArch: kprobes: Use larch_insn_text_copy() to patch instructions 9e3f18883a98 fwctl: pds: Validate RPC input size before parsing 1012896f4225 RDMA/siw: Reject MPA FPDU length underflow before signed receive math d7a076fb596c spi: ti-qspi: fix use-after-free after DMA setup failure be409d2bbe9c spi: sprd: fix error pointer deref after DMA setup failure 8e027db9fa31 spi: ep93xx: fix error pointer deref after DMA setup failure b9ff86310062 scsi: isci: Fix use-after-free in device removal path 78a369a065f1 phy: qcom-qmp-ufs: Fix kaanapali PHY PLL lock failure after SM8650 G4 fix 58f4a7bd8d73 phy: tegra: xusb: Fix per-pad high-speed termination calibration a1f50f5aaa69 phy: exynos5-usbdrd: fix USB 2.0 HS PHY tuning values for Exynos7870 4bb4764f2c51 spi: qup: fix error pointer deref after DMA setup failure ecdf21536c6d drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe bee400ad4f42 virt: sev-guest: Explicitly leak pages in unknown state 4f087193b5ff riscv: kvm: return SBI_ERR_FAILURE for pmu_event_info() when OOM 77071943c752 riscv: kvm: return SBI_ERR_FAILURE for pmu_snapshot_set_shmem() when OOM 94ade38f317e KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235) 7023900b4988 KVM: arm64: vgic: Free private_irqs when init fails after allocation 0680f5119265 KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits 240373425e2d arm64: probes: Handle probes on hinted conditional branch instructions 798183376d9d tracing: Do not call map->ops->elt_free() if elt_alloc() fails 5e7d9d0805e5 cifs: Fix busy dentry used after unmounting 2dd9304727c7 wifi: mac80211: consume only present negotiated TTLM maps acdff9907478 af_unix: Fix UAF read of tail->len in unix_stream_data_wait() 6cfae4914439 wifi: cfg80211: advance loop vars in cfg80211_merge_profile() 50884c2afd7a ice: restore PTP Rx timestamp config after ethtool set-channels 0b9431b972a0 ice: fix setting promisc mode while adding VID filter 9c9d00d81b41 ice: fix locking around wait_event_interruptible_locked_irq f1bafd35f11b igc: fix potential skb leak in igc_fpe_xmit_smd_frame() 8864b664d044 octeontx2-pf: fix double free in rvu_rep_rsrc_init() 47a4cf2229be octeontx2-af: CGX: add bounds check to cgx_speed_mbps index 5b906f31e977 lsm: hold cred_guard_mutex for lsm_set_self_attr() 9dcd4f5c99b4 rbd: eliminate a race in lock_dwork draining on unmap dfef79e09ed2 ixgbevf: fix use-after-free in VEPA multicast source pruning 7725cd3b4717 ipv4: raw: reject IP_HDRINCL packets with ihl < 5 dc31c6947652 wifi: iwlwifi: mld: stop TX during firmware restart 6fe92651b44f wifi: iwlwifi: mvm: fix driver-set TX rates on old devices 614cacec60fe wifi: ath11k: clear shared SRNG pointer state on restart a3529032afe2 ice: fix VF queue configuration with low MTU values c618cf8926c0 vsock/virtio: reset connection on receiving queue overflow 440447699c68 vsock/vmci: fix UAF when peer resets connection during handshake 29b643351012 mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient abdd03229414 ipv6: ioam: add NULL check for idev in ipv6_hop_ioam() 2bc60c175568 ring-buffer: Flush and stop persistent ring buffer on panic 610ff6bc2f44 ring-buffer: Fix reporting of missed events in iterator 0e47fc1c9181 qed: fix double free in qed_cxt_tables_alloc() e0c3dd7b30cc l2tp: use list_del_rcu in l2tp_session_unhash d73dcd1520d6 fs/ntfs3: handle attr_set_size() errors when truncating files 358692462555 net: ethtool: phy: avoid NULL deref when PHY driver is unbound 61f53c1e58d6 net: ethtool: fix NULL pointer dereference in phy_reply_size 752ea4a105e6 cgroup/cpuset: Reset DL migration state on can_attach() failure 1aed73795392 tracing/fprobe: Check the same type fprobe on table as the unregistered one f0ad68d2f0ad tracing/fprobe: Avoid kcalloc() in rcu_read_lock section bb92f356d2b7 tracing: fprobe: use ftrace if CONFIG_DYNAMIC_FTRACE_WITH_ARGS 52cc572c9565 tracing: fprobe: Remove unused local variable 45c7c4e3db8b sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path 6e73ec10b2a3 sched_ext: Fix missing warning in scx_set_task_state() default case 689bbf48c1f4 netfilter: nft_inner: Fix IPv6 inner_thoff desync 952e988163c2 netfilter: ipset: stop hash:* range iteration at end 15d464265120 netfilter: nf_queue: hold bridge skb->dev while queued 57b0ac5e1b46 netfilter: ip6t_hbh: reject oversized option lists dac025c4e8f9 net: pse-pd: fix sign on -ENOENT check in of_load_pse_pis() f8a5a76b4a68 net: ifb: report ethtool stats over num_tx_queues 1604a2d68414 net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover 49eff79967fd net: phy: skip EEE advertisement write when autoneg is disabled 3d4ef05266ab net: bcmgenet: keep RBUF EEE/PM disabled 84bc87beb4cd phonet/pep: disable BH around forwarded sk_receive_skb() 8b4c412e001b Bluetooth: serialize accept_q access f1febe93ef07 Bluetooth: MGMT: validate Add Extended Advertising Data length 051922ab709c Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer 192cb0f1ca70 Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths 5506aec79513 Bluetooth: bnep: Fix UAF read of dev->name 61f2410a96de Bluetooth: ISO: drop ISO_END frames received without prior ISO_START added1213395 Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() ffb6dbb49c96 net: wwan: iosm: fix potential memory leaks in ipc_imem_init() 0fa24311bd42 selftests/mm: run_vmtests.sh: fix destructive tests invocation 738d18f1da35 mm/page_alloc: fix initialization of tags of the huge zero folio with init_on_free 09ce923071e7 mm/memory_hotplug: fix memory block reference leak on remove 62153767e8fc mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_special() 2fff0cdd9422 mm/memory: fix spurious warning when unmapping device-private/exclusive pages 24de676da63c ipv6: ioam: refresh hdr pointer before ioam6_event() 24840b3139d7 drivers/base/memory: fix memory block reference leak in poison accounting b737c6612c60 io_uring/waitid: clear waitid info before copying it to userspace 5fb947ddae55 spi: amd: Set correct bus number in ACPI probe path c32a1fbe0f9a efi: Allocate runtime workqueue before ACPI init fcbd0a5fd812 ALSA: scarlett2: Allow flash writes ending at segment boundary 61c5017c64e2 ALSA: asihpi: Fix potential OOB array access at reading cache feff0251386a ALSA: pcm: Don't setup bogus iov_iter for silencing cba8dab72e9b ALSA: ua101: Reject too-short USB descriptors ca560f7566df hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX 9803e75c9813 smb/server: promote S_DEL_ON_CLS to S_DEL_PENDING when close d65104a4a815 smb: client: use data_len for SMB2 READ encrypted folioq copy bf4ebdb19ff9 smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() a8d17d22db59 smb: client: require net admin for CIFS SWN netlink 6827647fd2dc regulator: tps65219: fix irq_data.rdev not being assigned 18d8db24b0a5 ksmbd: validate SID in parent security descriptor during ACL inheritance 0e198f09cb2a ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow cd5c1b75d2f4 ksmbd: fix null pointer dereference in compare_guid_key() 302e02f9ba49 mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break() 48fa96538bd2 sysfs: don't remove existing directory on update failure 141ffb83abe9 drm/vblank: Fix kernel docs for vblank timer ed39ecd3a96c drm/atomic: Increase timeout in drm_atomic_helper_wait_for_vblanks() a0582cc92398 drm/vkms: Convert to DRM's vblank timer 60918357456d drm/vblank: Add CRTC helpers for simple use cases fa4b91eea433 drm/vblank: Add vblank timer 18a08b87db71 Revert "ice: Remove jumbo_remove step from TX path" 523cd0ea0324 Revert "ice: fix double-free of tx_buf skb" 515de0a3b6c1 ata: libata-scsi: do not needlessly defer commands when using PMP with FBS 4e6eada8de38 ata: libata-scsi: do not use the deferred QC feature on PMPs with CBS f207ebd5656e ata: libata-scsi: do not use the deferred QC feature for ATA_DEFER_PORT 62ee00c1042c ata: libata-scsi: improve readability of ata_scsi_qc_issue() 9d11e4b1db1c mfd: bcm2835-pm: Add support for BCM2712 ed915823d469 arm64: dts: broadcom: bcm2712: Add watchdog DT node 375d5a17dc8d dt-bindings: soc: bcm: Add bcm2712 compatible 91f89c1d83e8 smb: client: reject userspace cifs.spnego descriptions 5da69a65b282 ksmbd: close durable scavenger races against m_fp_list lookups aae4a47073b1 spi: spi-dw-dma: fix print error log when wait finish transaction e8ec80430bfa bridge: mrp: reject zero test interval to avoid OOM panic 0638bf16b7a7 sched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting 3f0543bdf446 sched: Employ sched_change guards dc184ac2f0ba cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() da3d241c5b92 fuse: fix uninit-value in fuse_dentry_revalidate() 488d2c76bd9f iommu/amd: Remove latent out-of-bounds access in IOMMU debugfs b9a4184271b9 iommu/amd: Fix illegal cap/mmio access in IOMMU debugfs 814326e86e92 drm/xe/hdcp: Add NULL check for media_gt in intel_hdcp_gsc_check_status() Signed-off-by: Bruce Ashfield --- meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend b/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend index ec18aba..90e7c10 100644 --- a/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend +++ b/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend @@ -8,4 +8,4 @@ KMACHINE:genericx86 ?= "common-pc" KMACHINE:genericx86-64 ?= "common-pc-64" KBRANCH:genericarm64 ?= "v6.18/standard/genericarm64" -SRCREV_machine:genericarm64 ?= "6bf211598fd7bc81856d3d84b0cc610e2bbe81db" +SRCREV_machine:genericarm64 ?= "3bf75f8b9c97212d54aac12c3575b42cc504b4d8" From patchwork Wed Jun 10 16:47:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Bruce Ashfield X-Patchwork-Id: 89686 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8ECCACD8CB9 for ; Wed, 10 Jun 2026 16:47:52 +0000 (UTC) Received: from mail-qt1-f175.google.com (mail-qt1-f175.google.com [209.85.160.175]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.25149.1781110066702529339 for ; Wed, 10 Jun 2026 09:47:46 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=B9KIWc7A; spf=pass (domain: gmail.com, ip: 209.85.160.175, mailfrom: bruce.ashfield@gmail.com) Received: by mail-qt1-f175.google.com with SMTP id d75a77b69052e-5177945a22eso47771611cf.1 for ; Wed, 10 Jun 2026 09:47:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781110066; x=1781714866; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=eHk0fk9xdjS8onrNoyPfXKYelCjAL5xiZAQq9xP9wo0=; b=B9KIWc7AFIqiXXb79z+ZdICkxeVNZHO086MkBK0TPPaid4FIW4KGFk7GcYWWSJIJgN +qjHDkWymASz8mGETm89+TDnKAgogNOZYokOJ7HCCqw9ep8ihNyPHZihDQxYty0d2yIV /m76rlGV2Wr4iZcbjbvWa8VXJ8iSLWgn7wZRxDbKCUy5C+z4NvYmfS+HJ2SJ58PZt+FP 9eFY9i7b9dKD4U9guLUiiBgFQm7oVOfTdqn7WOKZ0L2tVno7+erSJrTqG0Nl9LnpkaYZ LVXBDPC5kPhsSqOkcpz4NJRp3UFuuhhzpswEPQ3FyaXVe1yZibypdFym1FhyagU+/zk5 jWCw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781110066; x=1781714866; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=eHk0fk9xdjS8onrNoyPfXKYelCjAL5xiZAQq9xP9wo0=; b=ssx0+wwTmxV1CGw34vUSjZvZH/hRaPyAcLINZPNJDnxdoiSYRVXE7QQunK6LgE/qWH ttJWGgFj/aa9fryf8uqnBr49exNOiz8vz1d7t8O7o5h2CGmKpFMkmFH0lOD94uAb7te1 DeZ4rpDKM2zs/CiTUoOzp9Yoe5nye0LWiuPt2zcMcBkXjig0BcekJwc0k/9SS2FM5LYy 4QXAMKBXtOsJVHj5xWO5QBGXeLHaF4kGSdsJg+dHNhxG1gwLZzapM1Xb0spg9oF5HI7L D5EBkZbaTgrV+8A7VvnrcuoChqYmDndwMbaGbGSFN0jGMCDbWGDAN+jR6QHNzp1016sz POkg== X-Gm-Message-State: AOJu0Yyus20NkEuXul9bTnsXG9bHyas8SvDZvgYmhG84cuZTaHM7RY+m TVrZKHpnGRv4fspyblVV0HwI8EYRbsIsByD/wp9MTo8Od09z38uvdPGkrbDIB264 X-Gm-Gg: Acq92OEzyxk4y3kLmmimy4zdVPLORTbzmIhAHHRm5gfFMnM2DC+LRS+BqNa/7kwXiXS vcobgHEdJnE78iDsM5W7fBTUNytpN19h1UxqEHxv7Arep3g7oyYwZmuCofTSi7u6PjYQoLi/pOa F7k2dY21Kuk6sIvsP3PXe1W3L+trkRXTxGS1e59K1w25Q9+4/FWYdTMX01w5Ygy7FgzC7rx4Cme vvFd/m2x7/ikQocdrODIKBuST/Z9jCXOCkw8k+YEUK4faVkrnW9WPEO6i/H5awy6nDC12cZod1g DRDmb/Ks6N7MKCsK30aesElkfx9LojVv0CtpKvmPdlBcDgV2z9N3JHLNaofdgtkEEJX8zGXW9rO iTXLygKLm7uE/PtXHHH7F4GtijuPOBLQf4pDGOvsu6euWDYny6YgeazG12zQUPFqjmmCeW257qy 0u+KEDEuJfFPRAjSN64Pz9hTIumS6f5K3ck2ZUM1zQkOD7dhpBMruM16040e61f2jhTN3ZI5o9H brWSo+pfChJsKlCxleRkUt8AT+q00V7enpYb8Y7TYRPLQa/u3APUNbtSU/eeGsaX/E55IZWqxmf ozGH3BDTsOoGshy+QBPasRJQyPg4+4xuitS8+1YQ82U5UKQ0SA4XurA= X-Received: by 2002:a05:622a:1794:b0:517:899b:7f76 with SMTP id d75a77b69052e-51795be1484mr388503591cf.35.1781110065228; Wed, 10 Jun 2026 09:47:45 -0700 (PDT) Received: from bruce-XPS-8940.localdomain (pool-174-112-62-108.cpe.net.cable.rogers.com. [174.112.62.108]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-51775d9efa1sm214422401cf.20.2026.06.10.09.47.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 10 Jun 2026 09:47:44 -0700 (PDT) From: bruce.ashfield@gmail.com To: richard.purdie@linuxfoundation.org Cc: openembedded-core@lists.openembedded.org Subject: [meta-yocto-bsp][PATCH 04/04] yocto-bsps: update to v6.18.35 Date: Wed, 10 Jun 2026 12:47:37 -0400 Message-ID: <20260610164737.1869790-5-bruce.ashfield@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260610164737.1869790-1-bruce.ashfield@gmail.com> References: <20260610164737.1869790-1-bruce.ashfield@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 10 Jun 2026 16:47:52 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/238376 From: Bruce Ashfield Updating linux-yocto/6.18 to the latest korg -stable release that comprises the following commits: acb7cf4c1184 Linux 6.18.35 918450ad6010 KVM: arm64: Reassign nested_mmus array behind mmu_lock 2bbc395e81bd KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry adc6fc240a61 tools: ynl: add scope qualifier for definitions f54b30f3316a usb: core: Fix SuperSpeed root hub wMaxPacketSize 830c8a9b467e thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() 21bfa15a89d8 drm/i915/psr: Use DC_OFF wake reference to block DC6 on vblank enable 00869f2320dc mailbox: Fix NULL message support in mbox_send_message() 5372f6f10b0a xhci: tegra: Fix ghost USB device on dual-role port unplug 58b2c0f096b3 net: phy: micrel: fix LAN8814 QSGMII soft reset 972ea882d4bf mm/slub: hold cpus_read_lock around flush_rcu_sheaves_on_cache() 56857385f313 hwmon: (pmbus/adm1266) serialize GPIO PMBus accesses with pmbus_lock 6b94f9f5fe28 hwmon: (pmbus/adm1266) serialize sequencer_state debugfs read with pmbus_lock 192516d72774 hwmon: (pmbus) Add support for guarded PMBus lock d8fdf33d6fcf USB: serial: mct_u232: fix memory corruption with small endpoint 062dcc0b324a USB: serial: digi_acceleport: fix memory corruption with small endpoints 284105c40fc3 USB: serial: cypress_m8: fix memory corruption with small endpoint c73c62a4bd52 usb: dwc3: xilinx: fix error handling in zynqmp init error paths 9327252e0462 xfrm: iptfs: reset runtime state when cloning SAs bb50838a2a06 cpufreq: intel_pstate: Use correct scaling factor on Raptor Lake-E 7cb2daed3509 cpufreq: intel_pstate: Add and use hybrid_get_cpu_type() 8f72a2509163 mptcp: reset rcv wnd on disconnect 82e742b9d2cc mptcp: cleanup fallback dummy mapping generation 0d9b9d7dbef9 octeontx2-pf: avoid double free of pool->stack on AQ init failure fe93e907b1af arm64: tlb: Flush walk cache when unsharing PMD tables bb37498a99e4 mptcp: do not drop partial packets a84164847b1e mptcp: borrow forward memory from subflow c67f986fc02c mptcp: handle first subflow closing consistently 134c517dfa63 net: devmem: reject dma-buf bind with non-page-aligned size or SG length b2beed6ad149 selftests: mptcp: drop nanoseconds width specifier c5e7d4865292 Bluetooth: hci_qca: Convert timeout from jiffies to ms 8264178afb5c Bluetooth: hci_qca: Migrate to serdev specific shutdown function 0acba63d7d46 serdev: Provide a bustype shutdown function 8bf7dbb741dd rxrpc: Fix RESPONSE packet verification to extract skb to a linear buffer 46cb765e2e5a rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg fed725cace3a x86/mm: Disable broadcast TLB flush when PCID is disabled 81181a39bde9 platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error recovery 1730c91a8b9a platform/x86/intel/vsec: Make driver_data info const 4b0e87f9b50f platform/x86/intel/vsec: Refactor base_addr handling 71b88acec0a7 serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq() 7f8b194ed720 serial: 8250: dispatch SysRq character in serial8250_handle_irq() 5f2172d799f3 serial: core: introduce guard(uart_port_lock_check_sysrq_irqsave) 237dc8c08de3 serial: zs: Convert to use a platform device 81984447eac4 serial: zs: Switch to using channel reset b1ceeaef4fbc serial: zs: Fix bootconsole handover lockup 2ff0401ffdda serial: dz: Convert to use a platform device 2c5b693d918c serial: dz: Fix bootconsole handover lockup 24b7be239b0b serial: dz: Fix bootconsole message clobbering at chip reset f059b4c493df drm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO fa372f4e8aef drm/amdgpu: fix calling VM invalidation in amdgpu_hmm_invalidate_gfx 1eb86334e391 drm/amdgpu: fix lock leak on ENOMEM in AMDGPU_GEM_OP_GET_MAPPING_INFO 275396bf71c4 drm/amdkfd: Check for pdd drm file first in CRIU restore path 5cf4a41aa0d7 drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger 2f9c3c161692 drm/amdkfd: fix NULL pointer bug in svm_range_set_attr 348e01e64a87 serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma 8e39badab090 serial: zs: Fix swapped RI/DSR modem line transition counting 10ddd1a320e1 serial: sh-sci: fix memory region release in error path 654f45a8569f serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ 78d0d6f69bd6 serial: qcom-geni: fix UART_RX_PAR_EN bit position 9a91692fae5c serial: altera_jtaguart: handle uart_add_one_port() failures ffa7dce35b64 drm/amd/pm/si: Disregard vblank time when no displays are connected c9ae7e7e3bc9 drm/i915: Fix potential UAF in TTM object purge fed64e47a32f drm/i915/psr: Block DC states on vblank enable when Panel Replay supported 0dfa42cfe4db drm/gem: fix race between change_handle and handle_delete 164dc7bf1760 drm/hyperv: validate VMBus packet size in receive callback 9c698b2c43c2 drm/hyperv: validate resolution_count and fix WIN8 fallback 4a3a19c98a82 scsi: target: iscsi: Validate CHAP_R length before base64 decode 594a40360012 scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf 89c81d1228c0 scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() 35461d237441 scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 14dd80a20a72 scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker d548179adcc8 thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow 31b98e503ecc thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() c7d421123b98 usb: gadget: f_fs: serialize DMABUF cancel against request completion 607730a41477 usb: gadget: f_fs: copy only received bytes on short ep0 read 5933063935e8 usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports f8f5a8f48c7c usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling f928630f450b usb: gadget: f_hid: fix device reference leak in hidg_alloc() e6f8be12f030 usb: gadget: net2280: Fix double free in probe error path caec0145e597 usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind f06bcaba2970 USB: serial: mct_u232: fix missing interrupt-in transfer sanity check 6c0cf56f00f2 USB: serial: mxuport: fix memory corruption with small endpoint ea2b792330b4 USB: serial: keyspan: fix missing indat transfer sanity check ae03453f2c80 USB: serial: cypress_m8: validate interrupt packet headers 22823a319fb2 USB: serial: belkin_sa: validate interrupt status length f7c3fcd63405 USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL 38ba1a464c0d USB: serial: option: add MeiG SRM813Q 62fbc1396108 usb: typec: ucsi: Don't update power_supply on power role change if not connected d62d97c9c8c2 usb: typec: ucsi: Check if power role change actually happened before handling f34effb0b545 usb: typec: tcpm: improve handling of DISCOVER_MODES failures 02d9d8b79e18 usb: typec: tipd: Fix error code in tps6598x_probe() a90139ff1eba usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize 75f6d3da2cc6 usb: usbtmc: check URB actual_length for interrupt-IN notifications 88d459e5b5a4 usbip: vudc: Fix use after free bug in vudc_remove due to race condition 5b78d8b9a832 usb: storage: Add quirks for PNY Elite Portable SSD 94b05aec1985 USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers 69f9f2b30af0 usb: musb: omap2430: Fix use-after-free in omap2430_probe() 3bc65566331a usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval 7118304b1a77 usb: chipidea: core: convert ci_role_switch to local variable 9fd48937046e tty: serial: samsung: Remove redundant port lock acquisition in rx helpers 66f8bfea055b tty: serial: pch_uart: add check for dma_alloc_coherent() b4bebb6e0a44 counter: Fix refcount leak in counter_alloc() error path c7e670cb2538 comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() 269f5be6a6e4 comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() fdb74898d91d Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 7f95f4792c0d Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem 639fa8af506e misc: rp1: Send IACK on IRQ activate to fix kdump/kexec 94215d55b094 ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops 6617ee91062b Input: xpad - add support for ASUS ROG RAIKIRI II 3d63b8077f5b Input: xpad - add "Nova 2 Lite" from GameSir 2ffd8b0dd448 ALSA: hda/realtek: Fix speaker output on ASUS ROG Strix G615LP c093468aea82 xfrm: esp: restore combined single-frag length gate c4609fff0665 ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks 35be14ea8298 ASoC: qcom: q6asm-dai: close stream only when running b98ab51c45c5 netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check b9027ff112b6 ALSA: firewire-motu: Protect register DSP event queue positions befcb15c1f05 ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 aa0c7e59192b xfrm: ah: use skb_to_full_sk in async output callbacks dc6dcba80d72 xfrm: ipcomp: Free destination pages on acomp errors 448bb92ca101 xfrm: route MIGRATE notifications to caller's netns 22d41b176b99 nfc: hci: fix out-of-bounds read in HCP header parsing 8b1f4f618fd8 iommu, debugobjects: avoid gcc-16.1 section mismatch warnings b8338111e141 HID: wacom: Fix OOB write in wacom_hid_set_device_mode() 59139473a7a7 spi: spi-mem: avoid mutating op template in spi_mem_supports_op() 96a4713ae041 net: skbuff: fix missing zerocopy reference in pskb_carve helpers fc32be9ac278 ip6: vti: Use ip6_tnl.net in vti6_changelink(). 947013fd7c8c l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname 9f7ebb45a83a xfrm: input: hold netns during deferred transport reinjection a35daeabb433 ipv6: validate extension header length before copying to cmsg 853f6ea482df ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). 751db1b802a0 ipv6: exthdrs: refresh nh after handling HAO option 90983f841dfa ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params c512e1c819df ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() 6d00f5c7e5ff macsec: fix replay protection at XPN lower-PN wrap 5e1902866796 bpf: sockmap: fix tail fragment offset in bpf_msg_push_data e4892b1ecd73 wireguard: send: append trailer after expanding head d59cc66b7027 x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines 3f43865cb64d i2c: davinci: fix division by zero on missing clock-frequency bf769358419e Input: elan_i2c - validate firmware size before use 84ea928ed584 usb: dwc2: Fix use after free in debug code 94c92f9c886c usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles 459c4fa089f7 usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure b2723bd468c5 usb: cdns3: gadget: fix request skipping after clearing halt 0fee0ccac29e USB: serial: omninet: fix memory corruption with small endpoint 3412a95afaa5 iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() a3763ae33476 iio: buffer: hw-consumer: fix use-after-free in error path 390254cf509b iio: light: cm3323: fix reg_conf not being initialized correctly 5e4d34092a5e iio: chemical: scd30: fix division by zero in write_raw a5a05410cb34 iio: chemical: mhz19b: reject oversized serial replies cbd2d7e6bd4f iio: Fix iio_multiply_value use in iio_read_channel_processed_scale 8d4daa614440 iio: light: veml6070: Fix resource leak in probe error path ae01ec83841d iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL aefc19ca3dd3 iio: temperature: tsys01: fix broken PROM checksum validation 04a4d9822210 iio: ssp_sensors: cancel delayed work_refresh on remove aaf9d640e9ae iio: gyro: adis16260: fix division by zero in write_raw 15a0b3f33ffb iio: gyro: itg3200: fix i2c read into the wrong stack location 5cb8cede8baf iio: adc: ad4695: Fix call ordering in offload buffer postenable 7155e7fce429 iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw 944082fdb028 iio: adc: mt6359: fix unchecked return value in mt6358_read_imp 991d359faa95 iio: dac: ad5686: fix powerdown control on dual-channel devices 31de336a2c0d iio: dac: ad5686: acquire lock when doing powerdown control f541c9a1eb89 iio: dac: ad5686: fix input raw value check 69f7d101976c iio: dac: ad5686: fix ref bit initialization for single-channel parts 684bfd655b80 iio: dac: max5821: fix return value check in powerdown sync 88c9dd5170e0 iio: dac: ad3530r: Fix AD3531/AD3531R powerdown mode strings 2ce5ca7824a1 iio: adc: npcm: fix unbalanced clk_disable_unprepare() 0ee771fff32e iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux bb1b43e8a7ed Disable -Wattribute-alias for clang-23 and newer bbd989d6fd36 KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() b1dfaa6f7a95 KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer 75c8d1d72912 KVM: SEV: Check PSC request indices against the actual size of the buffer 9f0a9e780f02 KVM: SEV: Compute the correct max length of the in-GHCB scratch area 5300aedbee56 KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 e4ab26f81a63 KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests 2254972d4d69 KVM: SEV: Ignore Port I/O requests of length '0' c9b4198fbc6e KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use ec62e8480e82 KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC b1fc4a83dd44 KVM: arm64: PMU: Preserve AArch32 counter low bits 625153b917bc USB: cdc-acm: Fix bit overlap and move quirk definitions to header 667599e71832 rust_binder: avoid calling pending_oneway_finished() on TF_UPDATE_TXN f2f2671e32c5 rust_binder: Avoid holding lock when dropping delivered_death 74d6aae1df45 parport: Fix race between port and client registration 9749db57233b Input: xpad - fix out-of-bounds access for Share button d9019210c8c3 Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync 2b7651f58670 Bluetooth: hci_qca: Use 100 ms SSR delay for rampatch and NVM loading e6b78019664d Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() bc08c15746f2 Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock c318aa51830a Bluetooth: ISO: fix UAF in iso_recv_frame 6348dfed5b0f Bluetooth: HIDP: fix missing length checks in hidp_input_report() e8a5baff5be2 Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn 859d3ace791e Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() 388051f7389a smb: client: fix uninitialized variable in smb2_writev_callback 197476b12601 auxdisplay: line-display: fix OOB read on zero-length message_store() 0fcc34d0d8fe mm/rmap: initialize nr_pages to 1 at loop start in try_to_unmap_one 0995d1f79aed memfd: deny writeable mappings when implying SEAL_WRITE f1f0cdca932b mm: memcontrol: propagate NMI slab stats to memcg vmstats a3cc795129e5 ipc: limit next_id allocation to the valid ID range 0ba6c05156d9 mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() 0886c6f257fe hpfs: fix a crash if hpfs_map_dnode_bitmap fails 4064a30381fa Bluetooth: btusb: Allow firmware re-download when version matches 6728e80c9d29 HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse 8735a28f2dcd Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() f33b5a61673b media: rc: igorplugusb: fix control request setup packet f793b67d41e5 USB: serial: safe_serial: fix memory corruption with small endpoint 0edd1e21587b usb: typec: ucsi: validate connector number in ucsi_connector_change() 9b496e3371c0 usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT e94933dc41b8 usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() b10eff5abe6a usb: typec: altmodes/displayport: validate count before reading Status Update VDO 052dbef45cb3 usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO 4505f33dab56 usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() f9d787fbe831 usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers a38ed87818b2 usb: typec: ucsi: ccg: reject firmware images without a ':' record header a58400f58f82 iio: pressure: bmp280: fix stack leak in bmp580 trigger handler ce582b22dd2f iio: imu: adis16550: fix stack leak in trigger handler e6bb3a49c5f9 iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer 278b0df1f736 phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X 487393023feb drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used c058cf6b84c1 drm/i915/psr: Read Intel DPCD workaround register dd4cbab2a446 drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register 600ad63124de s390/cio: Restore GFP_DMA for CHSC allocation 0171e01de47a Revert "x86/fpu: Refine and simplify the magic number check during signal return" ff0ca46b13b9 smb: client: validate the whole DACL before rewriting it in cifsacl efacf63ed087 media: rc: ttusbir: fix inverted error logic e250b672d40a media: rc: fix race between unregister and urb/irq callbacks 814be4a0924b net: skbuff: fix pskb_carve leaking zcopy pages ab9a10969a90 ipv6: fix possible infinite loop in fib6_select_path() dc36a04621dc ipv6: fix possible infinite loop in rt6_fill_node() b62e2b2b4a50 vsock/virtio: bind uarg before filling zerocopy skb 68667ee4c7da sctp: fix race between sctp_wait_for_connect and peeloff c4152b4e28b3 net: mana: Skip redundant detach on already-detached port da87896f34e0 net: mana: Add NULL guards in teardown path to prevent panic on attach failure 7f945f7f10f4 gpio: rockchip: teardown bugs and resource leaks e2fabb984bfd gpio: rockchip: convert bank->clk to devm_clk_get_enabled() 5d43c71fa8e1 gpio: virtuser: Fix uninitialized data bug in gpio_virtuser_direction_do_write() b6cdbb681ce1 gpio: adnp: fix flow control regression caused by scoped_guard() ae2eac5e9cfe Bluetooth: hci_sync: Reset device counters in hci_dev_close_sync() 47330cc875b3 Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close 41e29548b5e8 Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp f39049304ba6 Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success 1d4dcfe60fe1 net/handshake: Pass negative errno through handshake_complete() 25b2fcdea6f6 nvme-tcp: store negative errno in queue->tls_err 0866569fc36a net/handshake: Use spin_lock_bh for hn_lock c35064294eca net: hibmcge: disable Relaxed Ordering to fix RX packet corruption 7f97b8352ce5 net/sched: Revert "net/sched: Restrict conditions for adding duplicating netems to qdisc tree" 6fe1cb312038 ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() fd0de51c54fa ethtool: eeprom: add more safeties to EEPROM Netlink fallback c944cab3df82 ethtool: eeprom: add missing ethnl_ops_begin() / _complete() during fallback 3e656023a649 ethtool: strset: fix header attribute index in ethnl_req_get_phydev() 2008f9bb1ede ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure ab94e0d6664d ethtool: tsinfo: fix uninitialized stats on the by-PHC path d02342d9bb4f ethtool: tsconfig: fix missing ethnl_ops_complete() 912f8b23bc4b ethtool: pse-pd: fix missing ethnl_ops_complete() 49455e27838a ethtool: linkstate: fix unbalanced ethnl_ops_complete() on PHY lookup error d11c98484485 ethtool: tsconfig: fix reply error handling 0c02c190bcd9 ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES e976e3f2f200 bridge: Fix sleep in atomic context in sysfs path c9c2e609e839 bridge: Fix sleep in atomic context in netlink path 9ea8a648d912 bonding: refuse to enslave CAN devices e673889a35a5 Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() 75cf24709037 drm/xe: Restore IDLEDLY regiter on engine reset 164dcbec9632 ASoC: codecs: simple-mux: Fix enum control bounds check de9eb0b44fa9 ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE 43368636c663 tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() 5303925e3605 vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() 6dff77899b9e tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() 2a8c9994406b cxl/test: Update mock dev array before calling platform_device_add() 41d2dc766bf8 ethtool: cmis: validate fw->size against start_cmd_payload_size 0696709e951b ethtool: cmis: validate start_cmd_payload_size from module 0cbce444db75 ethtool: cmis: fix u16-to-u8 truncation of msleep_pre_rpl 4d42fb88ec61 ethtool: cmis: require exact CDB reply length e1dd697094f1 ethtool: module: fix cleanup if socket used for flashing multiple devices 9e70c8efb0ca ethtool: module: check fw_flash_in_progress under rtnl_lock 9f5108f5ee27 ethtool: module: avoid racy updates to dev->ethtool bitfield 61848c83b913 ethtool: module: avoid leaking a netdev ref on module flash errors d9defbf8b62b ethtool: module: call ethnl_ops_complete() on module flash errors 7877d8fbbec2 ethtool: rss: avoid device context leak on reply-build failure 7ddc3b3ddee8 ethtool: rss: fix hkey leak when indir_size is 0 33d05c22d6f2 ethtool: rss: fix indir_table and hkey leak on get_rxfh failure 39c01c405063 ethtool: rss: fix falsely ignoring indir table updates 6a775ec73210 ethtool: rss: add missing errno on RSS context delete f23e4d7324b8 ethtool: rss: avoid modifying the RSS context response 48fd840a26d3 net: Avoid checksumming unreadable skb tail on trim 03e9405c518c net: team: fix NULL pointer dereference in team_xmit during mode change c2af23b48f93 net: team: Rename port_disabled team mode op to port_tx_disabled a20e6ae5f05e net: team: Remove unused team_mode_op, port_enabled f2e077e8979f gpio: mxc: fix irq_high handling fbd0662f9c9a net: hsr: fix potential OOB access in supervision frame handling 2a15a03e58b0 net/mlx5: HWS: Reject unsupported remove-header action f0ac76e3d55e ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors e13922bb97b4 ALSA: pcm: oss: Fix setup list UAF on proc write error a7f4eefb6e14 ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() 475f2b37a78f scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues 981736924338 net/iucv: fix locking in .getsockopt 55cba6b883b4 net/smc: Do not re-initialize smc hashtables bcd0d19db3e6 net: netlink: don't set nsid on local notifications ca5e36629641 net: netlink: fix sending unassigned nsid after assigned one ef3b3ea864d0 vsock: keep poll shutdown state consistent aa308e9dbb9a tun: free page on build_skb failure in tun_xdp_one() 37a1c268c2c8 tun: free page on short-frame rejection in tun_xdp_one() 96bea2a7baac netfilter: nf_tables: fix dst corruption in same register operation bf8e8eac7ede netfilter: ebtables: fix OOB read in compat_mtw_from_user 052468b1c93b netfilter: xt_cpu: prefer raw_smp_processor_id f0fea2b6d545 netfilter: synproxy: refresh tcphdr after skb_ensure_writable 18abd88d19ea accel/rocket: fix UAF via dangling GEM handle in create_bo 45564a16a24f kunit: fix use-after-free in debugfs when using kunit.filter e1b8a53834dc HID: remove duplicate hid_warn_ratelimited definition bebc7dc0fb4b tools/bootconfig: Fix buf leaks in apply_xbc b4702049417f nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems 82ac903e0b51 xfrm: Check for underflow in xfrm_state_mtu 650bdd8fdfab nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() 912ebc49d440 nfc: llcp: Fix use-after-free in llcp_sock_release() 8b733ee4aecd bcache: fix uninitialized closure object dbc560858da8 net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked 91cc13978ab0 xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit 54ed418de62a net: mctp: ensure our nlmsg responses are initialised 41845bc5bb64 net/sched: cls_fw: fix NULL dereference of "old" filters before change() 0ca809ea8e03 Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size Signed-off-by: Bruce Ashfield --- meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend b/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend index 90e7c10..7505946 100644 --- a/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend +++ b/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend @@ -8,4 +8,4 @@ KMACHINE:genericx86 ?= "common-pc" KMACHINE:genericx86-64 ?= "common-pc-64" KBRANCH:genericarm64 ?= "v6.18/standard/genericarm64" -SRCREV_machine:genericarm64 ?= "3bf75f8b9c97212d54aac12c3575b42cc504b4d8" +SRCREV_machine:genericarm64 ?= "d6f3a955dcf77a71454a2d70f291bd39d06422ff"