From patchwork Wed Sep 9 07:32:16 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97701 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5A32BC79FB9 for ; Wed, 9 Sep 2026 07:32:35 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.6367.1788939147755955351 for ; Wed, 09 Sep 2026 00:32:28 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Gp4nzjFO; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-48449f62b93so703615f8f.0 for ; Wed, 09 Sep 2026 00:32:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939146; x=1789543946; darn=lists.yoctoproject.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=CNmaDJFKWSGQNr6IwGq/suh4y+It43WSG5rAtv39PY4=; b=Gp4nzjFOfXx/Hni657+tvCDzsBmHLhjectbfbF9SGGh7lvPMgqhDI8/AeQUmTfs1JC Y+jUdrnREL8lZ/MV1ghb4ge1h/+xyDMnloKIgvaKtH8GQsRkryn6PZHYfMJKNsbBHJuG wHoQ1t2Nm8q3wWccAuBdXV7/Tzf9Kg3AyInX8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939146; x=1789543946; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=CNmaDJFKWSGQNr6IwGq/suh4y+It43WSG5rAtv39PY4=; b=g8FK8Gr73t+K2i5phrUStKE4UYopNZPfnEw6I9lbf0wL7WrOmu32uCTsQqCFphYTA/ dWK1ACmadbiAOuNlvdANjmIBlrsHU1kHWO1m8srHiHB377xXhacVohSAP9uy9dDZuEYj Z5sOPNgw2paUK/NuoBg8u22fbLR6onPB5vNb8lZPxXMejdNXQr/SiV9iBbu9jriERgVi 1Q5JxPlf8d6pWqnZLZAyBURdMH9OChOcWAtkDJ0T4qGMAaJgrJxlOLGFBbjVpvvR3dUZ rWZU5oWFs3KMtp6nlPSsV0aggV+gy+qW6H7OE2iWFIzGUPLS3YNOxbWQyEuZXVUCFol6 Ih7Q== X-Gm-Message-State: AFuF++kFKEl6R326dfZ0RHlYdKQNb1ICRP5o+9LQST3JLaOT5l83/erb 1KYqP9dd0S2oSN6yzmKyoiJKojq1H8BbRd4oYi86D4oir9kD/cRyy7BhQQ2j75nersz0WkENpr3 f+EkgNPc= X-Gm-Gg: AYBFou1kJjhdNvhGhg0qtj4KggzjwRu69JtHvdaxZMXcH86nfAJfU0d0Pd3u599ykPe +BVLf+gPwkSM5DwOd42zuGPWLyxZQFVfalMdf6St84zH3UxSmAqyoF7NColhmMPQpPIWT6uYisr tu0pULjwhsvIqfra7QeVbK6yRn9xyUuI577fLS/uO1wP6JouMzgmIkv8e5f0bb0T4ms3zkVsniK 5CIWnHjqh1JSMHbsNJgC9eBi0AfYuOkV/v/ukffKECKZUQOy+X1XxtPo1jJuj+GyDg4i36Dtsj+ 6tF9DNB2uSYLTMILjkvrlofP5hCpCuiJp7e0C+AajQ6cVV40Tx+zeqKFkN0yxD4coAeFcyVdAm3 DmcqjzE54p5TAseU8grz9FqTycmn4TX9x2eWJfPRNpLuANPPDblIx1g37xcnSxlr0pxkEGng2Ke WJ0UgwthWXxVxcwfylIZKpb0zuN66othaQzEpPwoHr0KGtInKr83JoIjw7VdTE87KFt4H5AK08z P1Do8/ZgyfxcOxLIUNXS1m8KFquR819gZOgJv9pbOE+8Ly11nmj1hq3SI42gkIoMtWl2biUGkE= X-Received: by 2002:a05:6000:29d6:b0:485:8224:1a3e with SMTP id ffacd0b85a97d-485a2418480mr10368615f8f.15.1788939144042; Wed, 09 Sep 2026 00:32:24 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885b1320sm40931457f8f.27.2026.09.09.00.32.23 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:32:23 -0700 (PDT) From: Yoann Congal To: poky@lists.yoctoproject.org Subject: [meta-yocto][wrynose 1/4] yocto-bsps: update to v6.18.41 Date: Wed, 9 Sep 2026 09:32:16 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:32:35 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/poky/message/13964 From: Bruce Ashfield Updating linux-yocto/6.18 to the latest korg -stable release that comprises the following commits: 2fe596715f840 Linux 6.18.41 6a7ecc25abe6f posix-cpu-timers: Prevent UAF caused by non-leader exec() race 9f7268928ac0c posix-timers: Expand timer_[re]arm() callbacks with a boolean return value 221fc2f4d0eda Linux 6.18.40 478c4d24193fe RDMA/bnxt_re: Avoid repeated requests to allocate WC pages b87cbd4d198ae RDMA/bnxt_re: Initialize dpi variable to zero 81e6faa5b6405 ksmbd: fix durable reconnect double-bind race in ksmbd_reopen_durable_fd 1badb6866482d perf callchain: Handle multiple address spaces 275eb39930947 seqlock: fix scoped_seqlock_read kernel-doc 453cb79a15641 perf inject: With --convert-callchain ignore the dummy event for dwarf stacks 2764d031efd6d PCI: Fix Resizable BAR restore order 2fb74141ec54e PCI: Fix BAR resize rollback path overwriting ret 7425e7d82cb93 perf symbol: Fix ENOENT case for filename__read_build_id a888f3d5970ff pinctrl: airoha: fix pinctrl function mismatch issue 267fdd9b6530c bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized 779480ea79551 iommufd: Move vevent memory allocation outside spinlock 73b5d5cb1f5a1 iommufd: Propagate allocation failure in iommufd_veventq_deliver_fetch() ea7a76d7d614b KVM: arm64: nv: Re-translate VNCR before injecting abort 459adfc6cd35f KVM: arm64: Deduplicate ASID retrieval code 9d360fb820a3b samples/damon/mtier: fail early if address range parameters are invalid ec976851ad934 mm/damon/core: trace esz at first setup 3b91c35961fa5 mm/damon/core: always put unsuccessfully committed target pids ba37cd4d8a751 KVM: arm64: Fix propagation of TLBI level in kvm_pgtable_stage2_relax_perms() 19d9996435db8 KVM: arm64: Ensure level is always initialized when relaxing perms c3a3d39867190 btrfs: fix incorrect buffered IO fallback for append direct writes 998ee7f01ecfa btrfs: fix false IO failure after falling back to buffered write a4497a122e27f crypto: qat - fix restarting state leak on allocation failure 6c78081d047c5 btrfs: remove folio parameter from ordered io related functions 1a648c50a5057 btrfs: replace for_each_set_bit() with for_each_set_bitmap() 99d4ae3fbb5b1 btrfs: concentrate the error handling of submit_one_sector() 382fd8004cc60 crypto: atmel-sha204a - fail on hwrng registration error in probe path 952db4b985c79 usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile 69faa3779250d usb: gadget: f_fs: initialize reset_work at allocation time 8a2fdbf92cdc7 functionfs: use spinlock for FFS_DEACTIVATED/FFS_CLOSING transitions 5fb0b09180a0f functionfs: switch to simple_remove_by_name() 4744f07f6bb7c functionfs: don't bother with ffs->ref in ffs_data_{opened,closed}() 901c036cf6254 functionfs: don't abuse ffs_data_closed() on fs shutdown c3e6860252102 new helper: simple_remove_by_name() 509b51327320b usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect() b78826a657998 usb: atm: ueagle-atm: remove function entry/exit debug messages 6e5ef54b884f4 usb: atm: ueagle-atm: use dev_dbg() for 'device found' message 41a4e80d5af04 usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup() e534790c4c272 usb: dwc3: Support USB3340x ULPI PHY high-speed negotiation. bce232923aa9e xfs: use bio_reuse in the zone GC code adadb181ad42a xfs: only log freed extents for the current RTG in zoned growfs 47c0e07433021 xfs: add a xfs_groups_to_rfsbs helper 57454944737f3 bpf: Allow LPM map access from sleepable BPF programs 8fccaeeb9e9c5 bpf: Consistently use bpf_rcu_lock_held() everywhere 0b92ad64d6e4b bpf: Keep dynamic inner array lookups nullable c447be8d88c30 bpf: Introduce struct bpf_map_desc in verifier dccb3c557879d bpf: Consistently use reg_state() for register access in the verifier 60eed44674295 xfs: initialize iomap->flags earlier in xfs_bmbt_to_iomap 607217f7ad419 hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length 7676ea09beb5d hfs/hfsplus: prevent getting negative values of offset/length f9b4b03ccc9c6 proc: protect ptrace_may_access() with exec_update_lock (part 1) 07bf18dc63f78 seqlock: Change do_task_stat() to use scoped_seqlock_read() c897fd63762e0 seqlock: Introduce scoped_seqlock_read() 497c6bae51674 proc: protect ptrace_may_access() with exec_update_lock (FD links) 903d78e5aca77 proc: rename proc_setattr to proc_nochmod_setattr b56400364aed5 ksmbd: validate NTLMv2 response before updating session key 74c2f0ffb81c8 ksmbd: Use HMAC-MD5 library for NTLMv2 51c5f7e84cfed ksmbd: Use HMAC-SHA256 library for message signing and key generation bd27d9504d200 ksmbd: Use SHA-512 library for SMB3.1.1 preauth hash 427faaa52b0b3 ksmbd: track the connection owning a byte-range lock 6a37bc484f12e ksmbd: centralize ksmbd_conn final release to plug transport leak c7c884a1305aa ksmbd: fix path resolution in ksmbd_vfs_kern_path_create e205f3e7e8c31 ksmbd: use opener credentials for FSCTL mutations 90a93fb3230c9 cifs: SMB1 split: Add some #includes ff943e1f3d31f cifs: SMB1 split: Rename cifstransport.c 36da806f7fbae Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() 6d0eeebe22ba7 Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister ef382a6baf0a9 media: nxp: imx8-isi: Fix use-after-free on remove 4278953ff0cd4 media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code 49cd5ac6de8de crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() 4b51ee8a40fe4 staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() 5d76bc296bb58 staging: rtl8723bs: fix spaces around binary operators 48323ebaeeeed staging: rtl8723bs: core: move constants to right side in comparison 73cc54326de45 PCI: Skip Resizable BAR restore on read error f33837a754473 PCI: Move Resizable BAR code to rebar.c 2242c75b63286 PCI: Add kerneldoc for pci_resize_resource() 4b5322f0002aa PCI: Fix restoring BARs on BAR resize rollback path c18646165f21f PCI: Free saved list without holding pci_bus_sem 534f20cdddc31 PCI: Try BAR resize even when no window was released dbb1d8507dd92 PCI: Change pci_dev variable from 'bridge' to 'dev' 0d1c263e6fd73 PCI/IOV: Adjust ->barsz[] when changing BAR size 0dfad346c293e PCI: imx6: Configure REF_USE_PAD before PHY reset for i.MX95 e53d54b92f0c2 PCI: imx6: Fix reference clock source selection for i.MX95 1228926e1e4d6 binder: cache secctx size before release zeroes it 79ac87bb1a4c8 binder: Use LIST_HEAD() to initialize on stack list head 7ed120b1a007b vfio/mlx5: Fix racy bitfields and tighten struct layout f8272331da877 ALSA: hda/tas2781: Cancel async firmware request at unbind 6438d0707087e firmware_loader: Add cancel helper for async requests 1ed7ff33cfc8c ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417 ad5c5bdb0f580 ALSA: scarlett2: Allow selecting config_set by firmware version 2745574697ee4 iio: hid-sensor-rotation: Fix stale or zero output when reading raw values 7f680924c5c2b ACPI: NFIT: core: Fix possible deadlock and missing notifications cf5f93228e7ab ACPI: NFIT: core: Use devm_acpi_install_notify_handler() d57d2aae87b23 ACPI: bus: Introduce devm_acpi_install_notify_handler() 34f4d0e4e5065 ACPI: driver: Check ACPI_COMPANION() against NULL during probe 3b2628f7682ae ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup 83f29da85dc9d crypto: xilinx-trng - Remove crypto_rng interface f84c0bae0e8dd mmc: sdhci-esdhc-imx: fix resume error handling 174dc8103ab7b mmc: sdhci-esdhc-imx: make non-fatal errors non-blocking in suspend 5b8f11cbe8ad5 mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend 4f96903e2fd22 mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt aa276aa6cbfbc mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore 52990f6b57526 mmc: sdhci-esdhc-imx: restore DLL override for DDR modes on resume eefcd3ca245c1 mmc: sdhci-esdhc-imx: remove unnecessary mmc_card_wake_sdio_irq check for tuning save/restore c02237966c199 mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe() method 8d94498cc4453 mmc: block: fix RPMB device unregister ordering cf7258f57d180 mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout 4b5de4007e5bf mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout de2bc884d8870 mtd: rawnand: fsl_ifc: return errors for failed page reads bf9848a22a8e5 mmc: vub300: defer reset until cmd_mutex is unlocked 04ebd3766861f mtd: mchp23k256: use SPI match data for chip caps ac2d9f6b4f905 mtd: onenand: samsung: report DMA completion timeouts a59cfa165aee3 wifi: mwifiex: fix permanently busy scans after multiple roam iterations b8df3a993f690 wifi: mac80211: free ack status frame on TX header build failure 90576bd6921a9 wifi: ieee80211: validate MLE common info length 584657c5fc58d wifi: cfg80211: validate EHT MLE before MLD ID read 3c1e92f75e11a powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access() 82753ac86cb3d reset: sunxi: fix memory region leak on ioremap failure 3fb7edd2018bb ipvs: reload ip header after head reallocation d4ec18f48ce78 ipvs: fix more places with wrong ipv6 transport offsets 39151f0708c84 memstick: ms_block: reject a card that reports too many blocks a75d2b5249e38 macsec: fix promiscuity refcount leak in macsec_dev_open() fd701fc0d0652 llc: fix SAP refcount leak when creating incoming sockets 6744ab60dfac5 Bluetooth: btrtl: validate firmware patch bounds dbd14f736be02 net: openvswitch: reject oversized nested action attrs 6926d13865aaa regulator: ltc3676: Fix incorrect IRQSTAT bit offsets 688bd4c6144d2 riscv: vdso: Do not use LTO for the vDSO 55b26abb1fa1e wifi: brcmfmac: cyw: fix heap overflow on a short auth frame bdc0b8bfdc142 wifi: mac80211: fix memory leak in ieee80211_register_hw() 65446b85595a4 wifi: mwifiex: fix roaming to different channel in host_mlme mode 816559409e340 wifi: rt2x00: avoid full teardown before work setup in probe 262da8b6ea03d net/mlx5: free mlx5_st_idx_data on final dealloc 9b8df4da2cf79 powerpc/pseries: fix memory leak on krealloc failure in papr_init afa0db5322c5f mmc: sdhci-esdhc-imx: restore pinctrl before restoring ios timing on resume d94160a5d1ac3 selftests/landlock: Fix screwed up pointers in the scoped_signal_test ba481c0b53760 selftests/landlock: Skip scoped_signal subtest with MSG_OOB if not available 4ff3960f35271 pmdomain: imx: Fix i.MX8MP VC8000E power up sequence 9a0464fcfae4f pmdomain: imx: Fix i.MX8MP power notifier c844b7d9a9586 cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed 8131a91fe2dea selftests/rseq: Fix a building error for riscv arch 3dfec7490f3a2 s390/mm: Fix type mismatch in get_align_mask(). c6b4d454865a8 s390/diag: Add missing array_index_nospec() call to memtop_get_page_count() fad36954b2959 tracing/osnoise: Call synchronize_rcu() when unregistering eadd0c2c76aee riscv: Prevent NULL pointer dereference in machine_kexec_prepare() 38cc4867540ae drbd: reject data replies with an out-of-range payload size 91ec52dd2a5d9 ata: libata-core: Allow capacity transition to zero for locked drives 7a9a69641b68a ata: libata-core: Skip HPA resize for locked drives 52007bfdce531 fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list 1155a9d0a2e0d fs/resctrl: Free mon_data structures on rdt_get_tree() failure ccdf1770a4ba2 cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable() 5f5783c7806fc arm64: smp: Fix hot-unplug tearing by forcing unregistration 26b131b2d5b55 net: macb: drop in-flight Tx SKBs on close b2f426a9a2288 dibs: loopback: validate offset and size in move_data() 2cf10d0425622 macsec: don't read an unset MAC header in macsec_encrypt() 83fb4c2c5344f ipvs: reset full ip_vs_seq structs in ip_vs_conn_new 247d055504dcc ipvs: use parsed transport offset in SCTP state lookup 61a7ff4a62003 llc: fix SAP refcount leak in llc_ui_autobind() 685fb410d90e5 selftests: net: make busywait timeout clock portable 5df30f05db965 octeontx2-pf: fix SQB pointer leak on init failure 77caf2d6eba7c mac802154: remove interfaces with RCU list deletion f0745496f7c17 s390/monwriter: Reject buffer reuse with different data length a5a367756926d irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure 018d7ad26cb8b mm/compaction: handle free_pages_prepare() properly in compaction_free() 2faf0198168d2 riscv: probes: save original sp in rethook trampoline d8d4fa0c4f818 hwmon: (asus_atk0110) Check package count before accessing element 07f5eb6d268a3 net: wwan: iosm: bound device offsets in the MUX downlink decoder 1286a41563337 ata: pata_pxa: Fix DMA channel leak on probe error 1dce4f4bb3c1c net/mlx5: HWS, fix matcher leak on resize target setup failure 82fc886e244c7 orangefs: keep the readdir entry size 64-bit in fill_from_part() 2c76c01a505c1 tracing/probes: Fix double addition of offset for @+FOFFSET b4427ee3667c5 hwmon: (max1619) add missing 'select REGMAP' to Kconfig 6c52226072a3c fhandle: reject detached mounts in capable_wrt_mount() e2b7ee61989f2 net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked 5889064919a1e net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked 99a6f37b113c4 net: lan743x: Initialize eth_syslock spinlock before use ac58088d70b8a fsl/fman: Free init resources on KeyGen failure in fman_init() f0aad157576da hwmon: (occ) unregister sysfs devices outside occ lock 715cce38424fb net: liquidio: fix BAR resource leak on PF number failure 664480021f6a4 hwmon: (w83793) remove vrm sysfs file on probe failure c6c990f7208c9 hwmon: (w83627hf) remove VID sysfs files on error and remove 8dc6c7e8c9678 rtc: mpfs: fix counter upload completion condition 6e21d1253ef13 rtc: renesas-rtca3: Fix PIE clear polling condition in alarm setup error path 6c98ccdb9a096 bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp() f5c5065963024 ipmi: fix refcount leak in i_ipmi_request() a66d45e0ce6d7 espintcp: use sk_msg_free_partial to fix partial send ddbb6e3dc9bb4 ipmi: Fix user refcount underflow in event delivery a65f49b6f7ece LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect() 20ac8131f8c90 LoongArch: Fix nr passing in set_direct_map_valid_noflush() 612cda6630f2e pwm: rzg2l-gpt: Fix period_ticks type from u32 to u64 4b73889941b95 selftests/bpf: Add simple strscpy() implementation da7f17c2d5bb4 KVM: TDX: Account all non-transient page allocations for per-TD structures d0cc2c74060be drm/xe/userptr: Stub notifier_lock helpers when DRM_GPUSVM=n 6cec36c795c03 net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants 55da782eb4545 platform/x86/amd/pmc: Avoid logging "(null)" for DMI values 35267819b2507 gve: fix header buffer corruption with header-split and HW-GRO 2059c28bd725b ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit cb5cca1d2a908 ieee802154: ca8210: fix cas_ctl leak on spi_async failure 314f21c9dd0dc ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation 1905ebabe638c ieee802154: admin-gate legacy LLSEC dump operations 19c148cb82d11 octeontx2-af: Free BPID bitmap on setup failure 234cd54fc500f net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink 03d8843b143eb net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink 68cadc3698c7d net: ipip: require CAP_NET_ADMIN in the device netns for changelink 9571af2eec802 net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink 0b2f9c908f930 net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink 6596baf804110 net: ena: clean up XDP TX queues when regular TX setup fails ab625256882e0 selftests: net: fix file owner for broadcast_ether_dst test b3d8354078461 net/sched: act_ct: preserve tc_skb_cb across defragmentation 3f85fcd520aa7 net: ixp4xx_hss: fix duplicate HDLC netdev allocation e89b8829693e6 net: wwan: t7xx: destroy DMA pool on CLDMA late init failure 121c5f31c3fb7 net: ethernet: ti: icssg: guard PA stat lookups 3118e97dae533 net: sit: require CAP_NET_ADMIN in the device netns for changelink 5d7bd8790309b gpios: palmas: add .get_direction() op d3b9026ef78da gpio: mt7621: avoid corruption of shared interrupt trigger state 4e16bc75c7502 gpio-f7188x: Add support for NCT6126D version B b6e040b5143cc gpio: mt7621: be sure IRQ domain is created before exposing GPIO chips ac761e66708d5 gpio: tegra: do not call pinctrl for GPIO direction 0630f2c3c16c0 gpio: mt7621: more robust management of IRQ domain teardown 6cb15b81ff545 cpu: hotplug: Bound hotplug states sysfs output f77117530fc3f cpu: hotplug: Preserve per instance callback errors afd147e59b32a selftests/ftrace: Drop invalid top-level local in test_ownership ea6a188ee805e posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu() 633cadbc0b832 locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() fcff712d0e3d1 wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() b33ac2d39953e tracing/user_events: Fix use-after-free in user_event_mm_dup() ed3cc4218070d net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete 0e8115a7ed9a9 Input: ims-pcu - fix type confusion in CDC union descriptor parsing f516cba88bf95 Input: ims-pcu - fix race condition in reset_device sysfs callback 383934c249a98 Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing 9c964fc9507ae Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging 99c428d7ef644 Input: ims-pcu - fix firmware leak in async update 05ac85da12198 Input: ims-pcu - fix DMA mapping violation in line setup f28c5cabb2df0 Input: ims-pcu - add response length checks c8d3d83f2eaaf Input: ims-pcu - validate control endpoint type 6329d1af316a4 Input: ims-pcu - release data interface on disconnect 87e2f89dea078 Input: ims-pcu - only expose sysfs attributes on control interface 6aacc18004b1a Input: ims-pcu - fix use-after-free and double-free in disconnect df87532e92122 scsi: elx: efct: Fix I/O leak on unsupported additional CDB 9b871369cbb45 scsi: elx: efct: Fix refcount leak in efct_hw_io_abort() cb7bdae7fba40 scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE 004ccd2d3b4ac scsi: target: Bound PR-OUT TransportID parsing to the received buffer f1516c56ac540 scsi: xen: scsiback: Free unsubmitted command instead of double-putting it 255fb7b0cdc94 scsi: xen: scsiback: Free the command tag on the TMR submit-failure path d0a8a6660d58e scsi: sg: Report request-table problems when any status is set ed08497977820 scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() d495b403d5b35 scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path 257321a1c036d accel/ivpu: Reject firmware log with size smaller than header 4e370b5289624 accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap() 7aa8f3dba5342 dma-fence: Make dma_fence_dedup_array() robust against 0-count input 089e05b644d5a dm-verity: make error counter atomic c8d743bb0e98a dm-verity: increase sprintf buffer size f15eaa3801f2f dm-verity: fix a possible NULL pointer dereference 2a0858cba1dab dm-verity: avoid double increment of &use_bh_wq_enabled 5dfd804263527 dm-integrity: don't increment hash_offset twice aa5113e7155f4 dm-integrity: fix a bug if the bio is out of limits 0c4e9bb1d4101 dm-integrity: fix leaking uninitialized kernel memory 92e3c93d60be1 dm_early_create: fix freeing used table on dm_resume failure ee458c3c18343 dm-stats: fix merge accounting 461d36b5ddafc dm-stats: fix dm_jiffies_to_msec64 1247615aadb74 dm-pcache: reject option groups without values e0b0163a65758 dm-log: fix a bitset_size overflow on 32bit machines d61c12573ed97 dm-ioctl: fix a possible overflow in list_version_get_info 021dab70eb37d dm-bufio: fix wrong count calculation in dm_bufio_issue_discard 1fcb5e29dd7a5 dm era: fix out-of-bounds memory access for non-zero start sector 7f76245960a33 dm thin metadata: fix metadata snapshot consistency on commit failure ac2136dc4441d dm thin metadata: fix superblock refcount leak on snapshot shadow failure 8a3c44a003176 net: sparx5: unregister blocking notifier on init failure ffd17a393921a block: fix IORING_URING_CMD_REISSUE flags check in blkdev_uring_cmd 2977b5fe401c1 block: fix race in blk_time_get_ns() returning 0 af382ffca93e5 block: remove redundant GD_NEED_PART_SCAN in add_disk_final() 0b6252afcd196 bpf: Add missing access_ok call to copy_user_syms c4f626ddf2350 bpf,fork: wipe ->bpf_storage before bailouts that access it 0993dc5fc619c bpf: Reset register bounds before narrowing retval range in check_mem_access() b06a4a397ac82 can: bcm: add missing rcu list annotations and operations 35f0ac19efb1a can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure cd830e0bc25ee can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF 37beb16e08cae can: isotp: serialize TX state transitions under so->rx_lock 7bef39ba76eb7 can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER b88a511308779 can: isotp: use unconditional synchronize_rcu() in isotp_release() 765ba1c91823a can: esd_usb: kill anchored URBs before freeing netdevs 5e4c8e08ce957 netdev-genl: report NAPI thread PID in the caller's pid namespace 26355295ce21c nvmet: fix refcount leak in nvmet_sq_create() 2944113ad5fbc nvmet-rdma: handle inline data with a nonzero offset 2eaa3ad450141 nvmet-auth: reject short AUTH_RECEIVE buffers 59cef6abc924a nvme-apple: Prevent shared tags across queues on Apple A11 0ffc032294a29 NFS: Charge unstable writes by request size, not folio size ebe0a55d954fa sctp: validate STALE_COOKIE cause length before reading staleness d44b828eb551b spi: uniphier: Fix completion initialization order before devm_request_irq() 9b092f9e6b34d time: Fix off-by-one in compat settimeofday() usec validation ada4b9a5087ea tpm: Make the TPM character devices non-seekable 95bdf3950d668 tpm: fix event_size output in tpm1_binary_bios_measurements_show 8ca2a19a987a7 xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink e0f688ccb20f1 xfrm: use compat translator only for u64 alignment mismatch 5b0c4c916f202 xfrm: nat_keepalive: avoid double free on send error 16d3ccdabb8de xen/gntdev: fix error handling in ioctl e497fef9ad7e9 ufs: core: tracing: Do not dereference pointers in TP_printk() 0ced34b4bbc04 tcp: Decrement tcp_md5_needed static branch 33a1bee413628 tcp: defer md5sig_info kfree past RCU grace period in tcp_connect bccae122dab8f ice: fix ice_init_link() error return preventing probe 8bd84316bbaf3 i2c: spacemit: fix spurious IRQ handling returning IRQ_HANDLED e6a395a71f465 i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() 2f3f471a448a5 i2c: mediatek: fix WRRD for SoCs without auto_restart option 5d3240f42a667 i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ) 6d2c973926d06 i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) 500716a007b2e hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig 1dcd7565e5909 hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig 3cd6f93f3d593 ksmbd: fix integer overflow in set_file_allocation_info() 6cc1518357369 smb: client: use kvzalloc() for megabyte buffer in simple fallocate fe623f9515bb0 pkey: Move keytype check from pkey api to handler eafc5aca71564 platform/x86/amd/pmc: Don't log during intermediate wakeups e628d9169f9e1 platform/x86/amd/pmc: Add delay_suspend module parameter 27d16a19ae74f platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops d8bc45c4c1a45 platform/x86/amd/pmc: Check for intermediate wakeup in function cea03d67db3a8 platform/x86: ISST: Restore SST-PP control to all domains 1e41ca4a7fba2 platform/x86: dell-laptop: fix missing cleanups in init error path ddbc4a8a4fe29 dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK 7926c1e4be863 dmaengine: tegra: Fix burst size calculation 933654508b2bc sunrpc: fix uninitialized xprt_create_args structure 934d1cd40e289 tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt ba33b4f9d3423 tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() 781f28bd982cf tpm: restore timeout for key creation commands 36ca587f55a2c irqchip/crossbar: Use correct index in crossbar_domain_free() 0d078152fcab7 taskstats: retain dead thread stats in TGID queries 9ac007affa77c mtd: maps: vmu-flash: fix NULL pointer dereference in initialization 3fac46068fe4c openrisc: Fix jump_label smp syncing ff7bcc9d71bf4 mtd: rawnand: Pause continuous reads at block boundaries 0fd20c1905abc mtd: spi-nor: spansion: use die erase for multi-die devices only c0806df5cf806 mtd: spi-nor: swp: Improve locking user experience 433e5e70cdc1e s390/pkey: Check length in pkey_pckmo handler implementation 693bf91d4db13 s390/pkey: Check length in PKEY_VERIFYPROTK ioctl c9ef79e34bc1e fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() e5824d5b841d9 net: thunderbolt: Fix frags[] overflow by bounding frame_count fc74244e0cc25 bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path 3ebe0ee6527e8 bus: mhi: host: pci_generic: Fix the physical function check 012683accbb7d fpga: dfl: add bounds check in dfh_get_param_size() 2174c68f623b7 ocfs2: reject non-inline dinodes with i_size and zero i_clusters 5e512d370a01b ocfs2: reject dinodes whose i_rdev disagrees with the file type 4db3b6a2a8ecf ocfs2: reject dinodes with non-canonical i_mode type 499714de42ab4 ocfs2: add journal NULL check in ocfs2_checkpoint_inode() 671889c553ea5 ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec bd73971fad89d ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits d5d5a21fb33cd ocfs2: avoid moving extents to occupied clusters 4bbfcf9c7e46c mtd: rawnand: fix condition in 'nand_select_target()' a8874c34c4a97 net/9p: fix infinite loop in p9_client_rpc on fatal signal ace3a0c839f3b mtd: rawnand: pl353: fix probe resource allocation b6337e3687d3d ocfs2: use kzalloc for quota recovery bitmap allocation bf53557a96d4c openrisc: Add full instruction cache invalidate functions 8d263bae573dc scsi: sas: Skip opt_sectors when DMA reports no real optimization hint 83405848e4030 scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished() a7bbf83dfebdc power: supply: bq257xx: Fix VSYSMIN clamping logic 8d610017c992d 9p: skip nlink update in cacheless mode to fix WARN_ON d8dcbbfa0d695 mtd: slram: remove failed entries from the device list 4e4beef747c68 kcov: use WRITE_ONCE() for selftest mode stores da5234df09416 mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE 749e2051da3b0 powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors 07ed8b1785480 fs/proc: fix KPF_KSM reported for all anonymous pages b6a6fb6803d52 proc: only bump parent nlink when registering directories 4d67bdef35c32 fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry() 43b987ed35be9 fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole() 40a04601a3f66 mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error f18c561eb9c51 mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs() f322955d9a1c3 riscv: cacheinfo: Fix node reference leak in populate_cache_leaves 1caee6e084a96 mips: sched: Fix CPUMASK_OFFSTACK memory corruption bd2e9be9ebb64 selftests/landlock: Test SCOPE_SIGNAL on the SIGIO/fowner pgid path 193e6471e985c power: supply: charger-manager: fix refcount leak in is_full_charged() 1f18aac263722 landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path ff05a98150ebb ntfs3: fix out-of-bounds read in decompress_lznt f3624cc069195 ntfs3: validate split-point offset in indx_insert_into_buffer aaa1f956c0fc4 ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head 0fad25687d4d3 ntfs3: cap RESTART_TABLE free-chain walker at rt->used be306b8d9143a fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} 908c9243ba309 fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow 7adb38279812c fs/ntfs3: validate lcns_follow in log_replay conversion 50b5e83384e7f fs/ntfs3: bound attr_off in UpdateResidentValue against data_off d240cd98f5f7b fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass 09fddd52c1b0c fs/ntfs3: bound DeleteIndexEntryAllocation memmove length ccd6b70798737 fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename 640627f07c79b mm/damon/core: make charge_addr_from aware of end-address exclusivity 722e6c54bde63 mm/memory_hotplug: fix incorrect altmap passing in error path 1697d253f51cf mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch 9227b387eee50 power: supply: max17042: fix OF node reference imbalance a3d81de441233 power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak a39d281f207b9 mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages d3fd2d358df0c MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf() 11a3bc25f2c30 MIPS: ip22-gio: fix device reference leak in probe 2c551f14f55e4 MIPS: ip22-gio: fix kfree() of static object 620a37ea7d626 MIPS: ip22-gio: fix gio device memory leak 51aad3d89a2dd remoteproc: qcom: Fix leak when custom dump_segments addition fails 69e18135e2a00 SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing 46d59ff421824 lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure 1161c4b5bd004 lockd: Plug nlm_file leak when nlm_do_fopen() fails 66014ab165cb0 sunrpc: harden rq_procinfo lifecycle to prevent double-free 65b23bec1fca6 sunrpc: wait for in-flight TLS handshake callback when cancel loses race 3f9ee75a97a76 sunrpc: pin svc_xprt across the asynchronous TLS handshake callback 30d490bb2c4cd nvdimm/btt: Free arena sub-allocations on discover_arenas() error path f4ca396bdd60b nvdimm/btt: Free arenas on btt_init() error paths 78955fdce8ff6 jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() 7199c78c3a3e3 Bluetooth: SCO: hold sk properly in sco_conn_ready 77eb0cf57009e Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready 96dd35f1942cd HID: playstation: validate num_touch_reports in DualShock 4 reports 88ba845468508 mfd: tps6586x: Fix OF node refcount d8e2f3e1bc207 cifs: invalidate cfid on unlink/rename/rmdir 3256c05d5a9db batman-adv: tt: prevent TVLV OOB check overflow d2b657c9653fc batman-adv: mcast: avoid OOB read of num_dests header a90f4fff90253 batman-adv: frag: fix primary_if leak on failed linearization c945f6007e785 batman-adv: clean untagged VLAN on netdev registration failure 8f54162e07d3e batman-adv: frag: free unfragmentable packet 2c989ab8e2054 batman-adv: fix VLAN priority offset 6a65ac8a81e90 batman-adv: tt: avoid request storms during pending request ee878decf9e57 batman-adv: dat: fix tie-break for candidate selection 9e16b6751a820 batman-adv: ensure minimal ethernet header on TX 8f76277d02176 batman-adv: dat: ensure accessible eth_hdr proto field e5e18886aadd3 batman-adv: bla: reacquire gw address after skb realloc 3b4c70c40f2e1 batman-adv: dat: acquire ARP hw source only after skb realloc b8afcf799b2cc batman-adv: access unicast_ttvn skb->data only after skb realloc 85a71a81854e0 batman-adv: retrieve ethhdr after potential skb realloc on RX e6b43acd34b21 batman-adv: gw: acquire ethernet header only after skb realloc fa1ebae4206e6 s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init() 8514585aa9553 cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF() 221ee479a49fb cpufreq: schedutil: Fix uncleared need_freq_update on the .adjust_perf() path 5ab0eba9c8819 perf/x86/amd/lbr: Fix kernel address leakage 046f6244da9b6 perf/x86/amd/brs: Fix kernel address leakage 394e2bdf7594e x86/boot: Reject too long acpi_rsdp= values f7c67c97b37c1 x86/boot: Validate console=uart8250 baud rate to fix early boot hang 1a1d6e3ef6cf5 x86/video: Only fall back to vga_default_device() without screen info 19ffeb30fdfce tools/power/x86/intel-speed-select: Harden daemon pidfile open 16a42c88c4667 mfd: sm501: Fix reference leak on failed device registration 6dd51d84a9502 leds: uleds: Fix potential buffer overread 3a134c3fb5f0d selinux: fix incorrect execmem checks on overlayfs d61a80b17254b selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() fc633a598206d selinux: check connect-related permissions on TCP Fast Open e9cdf741ffcb4 soc: fsl: qe: panic on ioremap() failure in qe_reset() c6854d9f4e1bd soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy c4d6442ac3ed0 gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path 1c4f67c89fd27 netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() 679ced28a9dc2 netfilter: xt_nat: reject unsupported target families b2dbbedfa935c netfilter: ecache: fix inverted time_after() check 3cd9a5792cbea netfilter: nf_conncount: fix zone comparison in tuple dedup a58230f3a7c4f netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag 2bcf2c5052fb5 netfilter: nf_nat_sip: reload possible stale data pointer 02b6b0e892aea netfilter: nft_set_pipapo: don't leak bad clone into future transaction 0ca505346c5e2 netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst 07f9ddbf5e799 netfilter: xt_cluster: reject template conntracks in hash match a1b672a3b5372 netfilter: nfnl_cthelper: apply per-class values when updating policies aff589556ed77 netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read ca028334343a1 ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback e42d8322b67f2 ASoC: mediatek: mt8183: Release reserved memory on cleanup 4b068759d3087 ASoC: mediatek: mt8183: Check runtime resume during probe 51c367230e30e ASoC: mediatek: mt8192: Release reserved memory on cleanup e0f276f1918a2 ASoC: mediatek: mt8192: Check runtime resume during probe d3abaedf6a584 ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control 121577383b5cf ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get 4ebe2c3a7db63 fbdev: tridentfb: fix potential memory leak in trident_pci_probe() 009a8514745b1 fbdev: nvidia: fix potential memory leak in nvidiafb_probe() 58bc18e03481b fbdev: vesafb: fix memory leak in vesafb_probe() d81860691e4cf fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() e1ca9b8559e0f fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() 12fe6a56506ed fbdev: uvesafb: fix potential memory leak in uvesafb_probe() ad54698255a4b fbdev: s3fb: fix potential memory leak in s3_pci_probe() 146b708bc75f1 fbdev: i740fb: fix potential memory leak in i740fb_probe() c2c795a320e7e fbdev: radeon: fix potential memory leak in radeonfb_pci_register() febb5b4f67ace fbdev: efifb: fix memory leak in efifb_probe() 9423e1f105270 fbdev: sm712: Fix operator precedence in big_swap macro d684ce2db92b1 fbdev: hecubafb: fix potential memory leak in hecubafb_probe() e8c9aae8c9508 fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() 6854cf33dddb2 fbdev: metronomefb: fix potential memory leak in metronomefb_probe() d5436e18e4fc2 KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory 4ead4def04659 KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN 5c50db5bcbb90 KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR 884b44256041e KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() 09f35145f3a4a KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions 5000bcae71c86 KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2 7099e7148f81c KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers 7996013b85687 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state d1379888cc423 KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails 97542f15dc4cf KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs ba06690b28be9 KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs df72596278b0e KVM: s390: pci: Fix handling of AIF enable without AISB d19dca8194ebe KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling 79fdd2aa774e4 KVM: arm64: vgic: Check the interrupt is still ours before migrating it 5fb75c5272950 KVM: s390: pci: Fix GISC refcount leak on AIF enable failure 9f8eaef40e955 powerpc/pseries/Kconfig: Enable CONFIG_VPA_PMU to be used with KVM 33d79ad6ecedf LoongArch: KVM: Return full old CSR value from kvm_emu_xchg_csr() f3efcef6648ba LoongArch: KVM: Fix FPU register width with user access API 45f2e6505fcf6 LoongArch: KVM: Check the return values for put_user() efe27b19a15c3 LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt() 199b570d7fca1 LoongArch: KVM: Validate irqchip index in irqfd routing 1ee200a1764f8 ARM: dts: stm32: stm32mp15x-mecio1-io: Move expander gpio-line-names to board files f550bf32b9a06 ARM: dts: stm32: stm32mp15x-mecio1-io: Fix expander gpio line typo 7da4d1a6b7400 ARM: dts: stm32: stm32mp15x-mecio1-io: Move gpio-line-names to board files 804821b69b2d1 ARM: dts: stm32: stm32mp15x-mecio1-io: Fix GPIO names typo c632a27f35cff arm64: dts: imx8ulp-evk: Correct Type-C int GPIO flags bd938c985ab34 ARM: dts: stm32: stm32mp15x-mecio1-io: Enable internal ADC reference ead9f10428c73 arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc a98bda2305f3f ARM: dts: stm32: stm32mp15x-mecio1-io: Move divergent mecio1 ADC channels to board files 4fd52ac541ce1 ARM: dts: stm32: stm32mp15x-mecio1-io: Fix ADC sampling times 68f9773754f05 arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Ringneck e2e3fb995175c arm64: dts: qcom: sdm630: describe adsp_mem region properly 508e55e81870d ARM: dts: imx6ul-var-som: fix warning for non-existent dc-supply property e8dc96a42571e arm64: dts: s32g3: Fix SWT8 watchdog address 89edae4161412 arm64: fpsimd: Fix type mismatch in sve_{save,load}_state() 5526d1997aea6 net: ife: require ETH_HLEN to be pullable in ife_decode() 908391d801b24 octeontx2-vf: clear stale mailbox IRQ state before request_irq() eebf439aa7a13 octeontx2-pf: clear stale mailbox IRQ state before request_irq() e62adb157c2ea net: atm: reject out-of-range traffic classes in QoS validation 22100a8f73d4a net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() 61a55fa24a5d7 tipc: restrict socket queue dumps in enqueue tracepoints d34deef34c99b ASoC: SOF: topology: validate vendor array size before parsing 0c4fbdaca225b ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get 711d912b18763 ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc fb4293173db2d ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put d8715b5a8fdb2 vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter 3a2b47d1b4b3d mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() 2d8b3c3e12997 mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() b65e46eed9e52 idpf: add padding to PTP virtchnl structures 1627e7d5c9b09 smb: client: fix overflow in passthrough ioctl bounds check 327595e7c34e3 drm/xe: remove duplicate include 3de77d2f34c2b octeontx2-af: fix VF bringup affecting PF promiscuous state ee3f7566bcf33 net/mlx5: Fix L3 tunnel entropy refcount leak 1550b07bca2bb selftests/net: fix EVP_MD_CTX leak in tcp_mmap 346e2d666a29a regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK 14e03ecd3b1b5 dm era: fix NULL pointer dereference in metadata_open() 5b0427ba582d1 SUNRPC: pin upper rpc_clnt across the TLS connect_worker 13965a7b190f3 SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED b784cd1c24d89 cifs: validate DFS referral string offsets df0e3e70f6995 s390/zcrypt: Remove the empty file 8f48cfe657409 ipvs: ensure inner headers in ICMP errors are in headroom 7510451a58c27 ipvs: fix PMTU for GUE/GRE tunnel ICMP errors d73f4249776dd ipvs: use parsed transport offset in TCP state lookup d340e351a0a74 ipvs: pass parsed transport offset to state handlers 238c612357b5a netfilter: nft_lookup: fix catchall element handling with inverted lookups f60ec3058a854 ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer() 27506827a01f6 ipv4: igmp: annotate data-races around timer-related fields d269eb67d2e58 ipv4: igmp: annotate data-races around im->users 9ce741c22df4f ipv6: mcast: Fix potential UAF in MLD delayed work 75e984fe0cb9e ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() 3bfcce441c552 gpio: mvebu: free generic chips on unbind 7cc438c99bba3 perf/x86/amd/core: Avoid enabling BRS from the SVM reload path 9579d625171a1 octeontx2-pf: check DMAC extraction support before filtering 7aa0e64fea778 net/sched: cake: reject overhead values that underflow length 72119397cdff6 net: mdio: select REGMAP_MMIO instead of depending on it 762116dfa7286 drm/v3d: Reject invalid indirect BO handle in indirect CSD setup 267809e2c56fb accel/amdxdna: Fix potential amdxdna_umap lifetime race 1cd434ac1c222 tracing: Make tracepoint_printk static as not exported 5e15cf51982f8 gpio: dwapb: Defer clock gating until noirq 6c736c5ccf4a3 gpio: dwapb: reduce allocation to single kzalloc d7b5497e0e45b gpio: dwapb: Use modern PM macros a3010b732d620 net: usb: lan78xx: disable VLAN filter in promiscuous mode e8a4c9fc437b1 net/tls: Consume empty data records in tls_sw_read_sock() b3eeb586f94c7 accel/amdxdna: Use unsigned long for nr_pages in amdxdna_hmm_register() ec5e96aee75d2 ring-buffer: Fix event length with forced 8-byte alignment 0c602cb8f148a Bluetooth: L2CAP: fix tx ident leak for commands without a response bfc9e7be289df Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() b69b1ab121fe8 Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length da4d8eea0c5f3 Bluetooth: sco: Fix a race condition in sco_sock_timeout() dfc8373893b18 Bluetooth: MGMT: Fix adv monitor add failure cleanup 23a83bac3356e Bluetooth: 6lowpan: hold L2CAP conn across debugfs control 026c236f0eefe amt: fix size calculation in amt_get_size() 3bfb96d9bc6a7 net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket 6f9b23eb92a89 net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload 1b12612c367e4 net: qualcomm: rmnet: validate MAP frame length before ingress parsing b066420e57f34 qede: fix off-by-one in BD ring consumption on build_skb failure 1e71a40d10154 net: microchip: vcap: fix races on the shared Super VCAP block 5c7e3755abf66 net/mlx5e: Fix publication race for priv->channel_stats[] 60fddda7207d8 net/mlx5e: Fix HV VHCA stats agent registration race 420aabb32da43 net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation 6a802de97a8bf net/mlx5: LAG, MPESW, Fix missing complete() on devcom error 4eef84b09a383 netfilter: xt_connmark: reject invalid shift parameters b29b67c729de0 netfilter: nft_set_rbtree: get command skips end element with open interval 3d441be2b1c5e netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop e702f6dd5d21e netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt() a597a722fb71a netfilter: xt_u32: reject invalid shift counts 4a4a1d41c6e90 gue: validate REMCSUM private option length b153cfe84b134 net: usb: net1080: validate packet_len before pad-byte access in rx_fixup 66f57dc92aeb6 arm64/sysreg: Fix BWE field encoding in ID_AA64DFR2_EL1 a6185c21d5510 selftests/hid: Cover hid_bpf_get_data() size overflow 91ac1d7fd51e3 selftests/hid: Load only requested struct_ops maps 61a959b82f1ae HID: bpf: Fix hid_bpf_get_data() range check 4c65c3d9f660b arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range() dd395744e4ed8 HID: core: Fix OOB read in hid_get_report for numbered reports d354e523c6f74 HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() 793b55c3f36f5 ata: libata-scsi: limit simulated SCSI command copy to response length 232a2f2fce9b9 ata: sata_gemini: unwind clocks on IDE pinctrl errors 86652704a7fd4 cifs: Fix missing credit release on failure in cifs_issue_read() c9170c83b0e0f uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline 2265b2b1c5aaa x86/uprobes: Keep shadow stack in sync for emulated CALLs adc7dda728ca3 drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays a0a56b4480a0d drm/xe/hw_engine: Fix double-free of managed BO in error path f9a9abd7bbdab drm/xe/userptr: Hold notifier_lock for write on inject test path 78b1074966d29 drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() a9b89752c2726 netfs: Fix folio state after ENOMEM whilst under writeback iteration 1bb33d959aabc netfs: Fix writeback error handling 7838131e296df netfs: Fix writethrough to use collection offload 8ab75e445c161 netfs: Fix netfs_create_write_req() to handle async cache object creation 1f38f65bf965f iomap: guard io_size EOF trim against concurrent truncate underflow 08b2145470667 ovl: fix comment about locking order abe3536a4bedc minix: avoid overflow in bitmap block count calculation ce6aced2e8554 afs: Fix unchecked-length string display in debug statement 158c5a0b1dfc0 afs: Fix the volume AFS_VOLUME_RM_TREE is set on 657449e5581a4 afs: Fix premature cell exposure through /afs 2ffb70a8a0198 afs: Fix lack of locking around modifications of net->cells_dyn_ino 8afb1a787a280 afs: Fix vllist leak 5492799ec5d27 afs: Fix missing NULL pointer check in afs_break_some_callbacks() 0acbc09d2aca0 afs: Fix callback service message parsers to pass through -EAGAIN 63d3f283858fa afs: Fix reinitialisation of the inode, in particular ->lock_work 5ea289ca751c4 afs: Fix misplaced inc of net->cells_outstanding b5bc1e5d5ce57 afs: Fix bulk lookup malfunction due to change in dir_emit() API 083a0ddc9cd49 afs: Remove erroneous seq |= 1 in volume lookup loop 6eb0d929202a3 afs: use kvfree() to free memory allocated by kvcalloc() aa24cec5b3470 afs: Fix double netfs initialisation in afs_root_iget() 8530206911fd6 afs: Fix error code in afs_extract_vl_addrs() a2038514e6937 fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid 374fd8122421f net/sched: hhf: clear heavy-hitter state on reset fba8e250ce5f3 net/sched: dualpi2: clear stale classification on filter miss a203f2c3892b1 pinctrl: meson: restore non-sleeping GPIO access 47120164c63d3 gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe 5a5ac2852cd32 ksmbd: fix use-after-free of fp->owner.name in durable handle owner check d020e7f27bf65 ksmbd: reject undersized DACLs before parsing ACEs 6b1304ce6cff0 net/sched: act_bpf: use rcu_dereference_bh() to read the filter a03387e1f6251 selftests: drv-net: tso: don't touch dangerous feature bits df9ffdceac053 cxgb4: Fix decode strings dump for T6 adapters 124440df267dc virtio_net: disable cb when NAPI is busy-polled a8323fb2ab6cd sctp: fix addr_wq_timer race in sctp_free_addr_wq() 4e8d498d32b6c irqchip/ts4800: Fix missing chained handler cleanup on remove c5d75800539bc irqchip/gic-v3-its: Fix OF node reference leak f0069a262bd41 tracing/probes: Make the $ prefix mandatory for comm access 62988204162fc tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry() 898cb5a7c4154 tracing: eprobe: read the complete FILTER_PTR_STRING pointer e0881f5cc4d71 tracing/events: Fix to check the simple_tsk_fn creation f148f86c65b8f tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg 3b51d6f07a199 tracing/eprobes: Allow use of BTF names to dereference pointers acbf1ecc22f3c drm/panthor: Interrupt group start/resumption if group_bind_locked() fails a9d098b346db5 drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced 1497a438ea34a drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick() dd0b2976b7c0f drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom() b4b3458ef88df bridge: stp: Fix a potential use-after-free when deleting a bridge 9b7d05cbaa601 net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF ef940e042f329 net: gianfar: dispose irq mappings on probe failure and device removal 58ba00999898b net: libwx: fix VMDQ mask for 1-queue mode 86d379fcf1b79 net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy 0a7d9c7c5f1f2 usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() d8a01d27873e0 ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump 83df3e2594cd7 eth: fbnic: don't cache shinfo across skb realloc 898ca04b096b9 hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero 489291b6b5697 hwmon: (pmbus) Fix passing events to regulator core 36554592e2f5c hwmon: adm1275: Prevent reading uninitialized stack 1797eb92f0b39 ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280 f14c3926fee38 ASoC: codecs: lpass-va-macro: add SM6115 compatible 3d3638fe92137 MIPS: mm: Add check for highmem before removing memory block 4e9f4ca9dc73c MIPS: DEC: Ensure RTC platform device deregistration upon failure bca3100f55028 sctp: add INIT verification after cookie unpacking ad6215d76b644 sctp: fix SCTP_RESET_STREAMS stream list length limit 1681cc7974a61 net: enetc: check the number of BDs needed for xdp_frame b17751a2ebc4a qede: fix out-of-bounds check for cqe->len_list[] 8dba7a94a269b seg6: validate SRH length before reading fixed fields 8d501b1411548 net: pse-pd: scope pse_control regulator handle to kref lifetime e94d53a9ac22c gpio: htc-egpio: use managed gpiochip registration f4af803269ccd gpio: mvebu: fail probe if gpiochip registration fails 46dee20d30b70 riscv: Fix 32-bit call_on_irq_stack() frame pointer ABI 8e0b7f94fb394 ACPI: RIMT: Only defer the IOMMU configuration in init stage 776f70bafd45c spi: sh-msiof: abort transfers when reset times out d6cd34d17b951 tracing: probes: fix typo in a log message f28d7b5f1578a ALSA: FCP: Fix NULL pointer dereference in interface lookup d990a01b853e5 net: hns3: differentiate autoneg default values between copper and fiber 2d149a20275ac net: hns3: fix permanent link down deadlock after reset 92d05883ef337 net: hns3: refactor MAC autoneg and speed configuration 43a6c6fb6ec50 net: hns3: unify copper port ksettings configuration path de051b146022c selftests: tls: size splice_short pipe by page size 6727f580cf462 dt-bindings: net: renesas,ether: Drop example "ethernet-phy-ieee802.3-c22" fallback 9075efb9b2c1d net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync c1e7286d05318 ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count 7a7c7263bbbc4 LoongArch: BPF: Fix off-by-one error in tail call ed295077a2214 LoongArch: BPF: Fix outdated tail call comments 0a8a729481c8e LoongArch: Move struct kimage forward declaration before use 2f3c0895fb20a net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove b15a3cc68e245 net: sungem: fix probe error cleanup b84dd48f9da1e net: mvneta: re-enable percpu interrupt on resume e0ac054416bf4 octeontx2-af: Validate NIX maximum LFs correctly 9dc3cf8a35906 net: phy: realtek: Clear MDIO_AN_10GBT_CTRL_ADV10G bit 0c11a1da41a64 net: dsa: realtek: fix memory leak in rtl8366rb_setup_led() a69ccea6d7eb6 rtc: cmos: unregister HPET IRQ handler on probe failure 5fd1f0512748d rtc: ds1307: Fix off-by-one issue with wday for rx8130 d0bfd7004a87f smb/client: preserve errors from smb2_set_sparse() 5b6165d7ec384 ACPI: processor_idle: Mark LPI enter functions as __cpuidle ea43e7a231aa2 thermal: testing: zone: Flush work items during cleanup 4e62be1490d23 eth: fbnic: fix ordering of heartbeat vs ownership 123b559aa6bb6 ipv6: fix missing notification for ignore_routes_with_linkdown 419017dd2dda2 ipv6: fix state corruption during proxy_ndp sysctl restart ae58dbf1d78d7 ipv6: fix error handling in disable_policy sysctl 2bf70e0306f8d ipv6: fix error handling in forwarding sysctl b060606bc7e46 ipv6: fix error handling in ignore_routes_with_linkdown sysctl 56c26538f0e58 ipv6: fix error handling in disable_ipv6 sysctl 2140c2f3f2e7b net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle ff127c0aa5279 net: usb: lan78xx: restore VLAN and hash filters after link up a9e6707322ef2 veth: fix NAPI leak in XDP enable error path 4106295280670 net: dsa: sja1105: round up PTP perout pin duration 7557df1b60f20 net: do not acquire dev->tx_global_lock in netdev_watchdog_up() 03b743586a246 net, bpf: check master for NULL in xdp_master_redirect() a0904f7d27035 alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs 94defb18ac792 alpha/PCI: Add security_locked_down() check to pci_mmap_resource() 04117aea9bc11 NTB: epf: Fix doorbell bitmask and IRQ vector handling 56ec2a08d27b5 NTB: epf: Report 0-based doorbell vector via ntb_db_event() d2a41c85beb56 NTB: epf: Make db_valid_mask cover only real doorbell bits 60a6689b9a5df gpio: davinci: fix IRQ domain leak on devm_kzalloc failure 33e1875d6b5b5 netfilter: nft_compat: ebtables emulation must reject non-bridge targets d3e9a7e2ce9dc netfilter: nft_synproxy: stop bypassing the priv->info snapshot 329f2626ee5cb netfilter: nf_conncount: prevent connlimit drops for early confirmed ct a73e7ac3f3b69 netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init() 49fa1be621dde bpf: Disable xfrm_decode_session hook attachment 4d919c9b77099 md/raid5: avoid R5_Overlap races while breaking stripe batches 3db13f82ba314 md/raid5: use stripe state snapshot in break_stripe_batch_list() 828fad4fd418b ipv4: fib: Don't ignore error route in local/main tables. 630ce3806b706 eth: bnxt: improve the timing of stats c0057e5f762b9 eth: bnxt: rename ring_err_stats -> ring_drv_stats 33168db149d01 eth: bnxt: gather and report HW-GRO stats b0d0eb13a0441 ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). 77bb0bbfcc4e7 ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE 1f6a4aec0d366 rtc: msc313: fix NULL deref in shared IRQ handler at probe 68115a7a336fc i40e: Fix i40e_debug() to use struct i40e_hw argument de80d04b13dec ice: dpll: fix memory leak in ice_dpll_init_info error paths eaffdd113f560 ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info 854065a75e375 rtc: isl1208: Balance enable_irq_wake() with disable_irq_wake() on cleanup 4cc632fe63df8 ice: call netif_keep_dst() once when entering switchdev mode 04c082b7dc5bf ice: fix AQ error code comparison in ice_set_pauseparam() dd6d8e4412f80 ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs() 9415a94cf6227 PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0 e1e7c72a2301d PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0 9cc0f8e63e8c3 drm/edid: fix OOB read in drm_parse_tiled_block() 5e4c4ab99abc9 gpiolib: initialize return value in gpiochip_set_multiple() 7550becf33014 power: sequencing: fix ABBA deadlock in pwrseq_device_unregister() 9697db03e0103 bpf: Fix effective prog array index with BPF_F_PREORDER 3bdfa0e435f31 bpf: zero-initialize the fib lookup flow struct b05337635be3c bpftool: Fix vmlinux BTF leak in cgroup commands 68b41e68a6229 bpf: Fix stack slot index in nospec checks aa33b44f70bfe rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 56e5f8a409f8c rtc: abx80x: fix the RTC_VL_CLR clearing all status flags 93f95538b611a dpaa2-switch: do not accept VLAN uppers while bridged ea24f911ead85 ipv6: ioam: fix type confusion of dst_entry a6450f7cfae57 ipv6: ndisc: fix NULL deref in accept_untracked_na() 2066e692ec7a1 net: airoha: Fix skb->priority underflow in airoha_dev_select_queue() 1d51aff78f078 net/sched: act_ct: fix nf_connlabels leak on two error paths a103cdb0681e7 net: emac: Fix NULL pointer dereference in emac_probe 2855ec137a224 octeontx2-pf: mcs: Fix mcs resources free on PF shutdown da603b606ceb3 octeontx2-pf: Clear stats of all resources when freeing resources 5636f0f3bd99b octeontx2-af: mcs: Fix unsupported secy stats read ceef83f0eaf9c net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths a0c5fdeb5fa25 tipc: fix use-after-free of the discoverer in tipc_disc_rcv() 5dda4f164a633 net: marvell: prestera: initialize err in prestera_port_sfp_bind 9200c8149910d selftests/mm: fix exclusive_cow test fork() handling 55fc2f99d0979 selftests/mm: allow PUD-level entries in compound testcase of hmm tests c8add1d06512b selftests/mm: clarify alternate unmapping in compaction_test 0caa28e978941 selftests/mm: skip uffd-stress test when nr_pages_per_cpu is zero 471b62966c782 selftests/mm: ensure destination is hugetlb-backed in hugetlb-mremap 9dbfd514148dd selftest/mm: register existing mapping with userfaultfd in hugetlb-mremap a8673dbd3d4a0 selftests/mm: free dynamically allocated PMD-sized buffers in split_huge_page_test 31b28910abe34 selftests/mm: size tmpfs according to PMD page size in split_huge_page_test fff7d3ea3a4c4 selftests/mm: fix cgroup task placement and drop memory.current checks in hugetlb_reparenting_test.sh 8c65c58868ecc selftests/mm: fix hugetlb pathname construction in hugetlb_reparenting_test.sh 58cd8ff69e33c selftests/mm: restore default nr_hugepages value via exit trap in hugetlb_reparenting_test.sh b805de2abfa34 selftests/mm: restore default nr_hugepages value via exit trap in charge_reserved_hugetlb.sh 37e3e8a2c3bfd alloc_tag: fix use-after-free in /proc/allocinfo after module unload 502b3ae43f798 irqchip/crossbar: Fix parent domain resource leak 002ebbcc8414c mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx() 7e23965d44f06 netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak d32e4301a0e5e netfilter: nf_reject: skip iphdr options when looking for icmp header 8e935c51b65d9 netfilter: nft_flow_offload: zero device address for non-ether case 4c61d28634fbf netfilter: flowtable: move path discovery infrastructure to its own file 13c6ba6e0f216 netfilter: nft_meta_bridge: add validate callback for get operations 5baa149abb41a netfilter: nft_payload: reject offsets exceeding 65535 bytes 12088da6add5b netfilter: ipset: make sure gc is properly stopped 8087bb360a936 netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() c4d257734e91b netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types a0afd353c2f7e netfilter: ipset: annotate "pos" for concurrent readers/writers 7228cc8ff6265 netfilter: ipset: Fix data race between add and dump in all hash types 6d92dbd73d19a md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry 2c5384c40a4ce md/raid1: honor REQ_NOWAIT when waiting for behind writes 119903c320830 md: merge mddev serialize_policy into mddev_flags 2e414af05a7cf md: merge mddev faillast_dev into mddev_flags 9408c233a5bbe md: merge mddev has_superblock into mddev_flags 5464ee6442376 mac802154: Prevent overwrite return code in mac802154_perform_association() de3bd9809af75 ieee802154: fix kernel-infoleak in dgram_recvmsg() d22e278cd0679 ieee802154: Remove WARN_ON() in cfg802154_pernet_exit() f4860dd988b10 ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns() 5d17ebdf6c236 ieee802154: Restore initial state on failed device_rename() in cfg802154_switch_netns() 3b40ebc19ad02 ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() 45465b0e01354 ACPI: resource: Amend kernel-doc style 7ae67f0e1c16b thermal: intel: Fix dangling resources on thermal_throttle_online() failure 679fd0bf4f8ab arm64/hw_breakpoint: reject unaligned watchpoints that would truncate BAS 4c16176fc11a6 ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints a762b9865f494 selftests: vlan_bridge_binding: Fix flaky operational state check c6d3bcb0f934d flow_dissector: check device type before reading ETH_ADDRS 68af74ad696ce net: macb: add TX stall timeout callback to recover from lost TSTART write 112b5eff24e04 net: airoha: fix foe_check_time allocation size 5ffb2b4987cc9 devlink: Fix parent ref leak on tc-bw failure 02c884d9aaca3 devlink: Fix parent ref leak in devl_rate_node_create() 0dafdaaf8684b dpaa2-switch: fix VLAN upper check not rejecting bridge join c7fc9adf4e006 virtio-net: fix len check in receive_big() 0d95587d662a5 spi: rpc-if: Use correct device for hardware reinitialization on resume f37f2f804796e PCI: iproc: Restore .map_irq() for the platform bus driver 53c23d56b46b1 ALSA: usb-audio: qcom: clear opened when stream enable fails 25a867aa5e67a ALSA: usb-audio: qcom: reject stream disable with no active interface 207bb4ce8fe7d sctp: hold socket lock when dumping endpoints in sctp_diag a6cfb924ad74e net: psample: fix info leak in PSAMPLE_ATTR_DATA 3d45d40b872ae octeontx2-pf: Fix leak of SQ timestamp buffer on teardown 290ad0a548915 drm/amdgpu: initialize irq.lock spinlock earlier 96ac562a9ea30 drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm 211bb9d8f17c4 drm/amd/display: Fix mem_type change detection for async flips 0e27d92f69b8e drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free 7bcd4ef375fa3 ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode ca297485271c6 perf dso: Set standard errno on decompression failure 05b11debdffe0 perf bpf: Validate array presence before casting BPF prog info pointers c8cb4a92eda6e perf cs-etm: Bounds-check CPU in cs_etm__get_queue() b389a5b215e35 perf cs-etm: Require full global header in auxtrace_info size check c13532ff67fae perf cs-etm: Validate num_cpu before metadata allocation 87d23f25b5e97 perf machine: Use snprintf() for guestmount path construction 6d99379c58f7f xfrm: validate selector family and prefixlen during match 7248ae02a9453 xfrm: annotate data-races around xfrm_policy_count[] and xfrm_policy_default[] a1a3360a0c44b xfrm: Fix xfrm state cache insertion race 1467ca02ddac4 ALSA: usb-audio: qcom: Free sideband sg_table objects 507a7b07f3fa3 i3c: master: Add missing runtime PM get in dev_nack_retry_count_store() 34cd92141a024 i3c: master: Update dev_nack_retry_count under maintenance lock 95028569589f4 spi: dw: fix wrong BAUDR setting after resume 355e51eeffc6b drm/xe: Fix wa_oob codegen recipe for external module builds 2024940522ef4 drm/i915: clear CRTC color blob pointers after dropping refs 1348bf64c1978 gpio: mlxbf3: fail probe if gpiochip registration fails 7d3532a0b11a2 perf cs-etm: Reject CPU IDs that would overflow signed comparison a56f29ad8aacf perf: Remove redundant kernel.h include f8898d2eb71ae perf bpf: Bounds-check array offsets in bpil_offs_to_addr() cafd80d81f08b perf bpf: Reject oversized BPF metadata events that truncate header.size 1935d213aeb23 perf bpf: Validate func_info_rec_size and sub_id in synthesize_bpf_prog_name() aea30b437ebd0 perf sched: Replace (void*)1 sentinel with proper runtime allocation bc27041e8971e perf hwmon: Fix fd check to accept fd 0 in hwmon_pmu__describe_items() 661f60a8a5cf8 perf tools: Use snprintf() for root_dir path construction 5d080b7324f07 perf dso: Set error code when open() fails on uncompressed fallback path debfcd673a6d1 perf dso: Fix heap overflow in dso__get_filename() on decompressed path 95bf4dbcd5022 perf tools: Fix uninitialized pathname on uncompressed fallback in filename__decompress() fa870f951793d perf tools: Add O_CLOEXEC to open() calls in DSO and ELF code 3ae7947101b97 perf tools: Don't read build-ids from non-regular files 2c19e40753ec1 perf symbols: Break infinite loop on zero-filled notes in sysfs__read_build_id() 137eabe3c18ff perf symbols: Validate p_filesz before use in filename__read_build_id() ca3393e258f63 perf symbols: Fix bswap copy-paste error for 32-bit ELF p_filesz f231387f3d2bb sparc: led: avoid trimming a newline from empty writes 17955f1995bf9 accel/ivpu: fix HWS command queue leak on registration failure 85873b1bd3664 apparmor: fix label can not be immediately before a declaration 38d3d33bf42c2 i3c: master: Prevent reuse of dynamic address on device add failure c4f2afcdc5470 i3c: master: Defer new-device registration out of DAA caller context 3891c061341fb i3c: master: Ensure Hot-Join operations are stopped on shutdown 57490b302b984 i3c: master: Consolidate Hot-Join DAA work in the core 0bd450d40f874 i3c: master: Move rstdaa error suppression fd32e8d4a2933 i3c: master: Add i3c_master_do_daa_ext() for post-hibernation address recovery b07a318afca16 i3c: master: Introduce optional Runtime PM support 882ee831366a1 i3c: master: Replace WARN_ON() with dev_err() in i3c_dev_free_ibi_locked() de2106d99b87a i3c: add sysfs entry and attribute for Device NACK Retry count 0d66830f302fd i3c: master: Make hot-join workqueue freezable to block hot-join during suspend eb9db96a5deb3 i3c: master: add WQ_PERCPU to alloc_workqueue users 45bbc1e1fe626 i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring d22ab94261c7b i3c: mipi-i3c-hci: Switch PIO data allocation to devm_kzalloc() 973fda38b124c i3c: mipi-i3c-hci: Allow for Multi-Bus Instances 5625b8767ce3e i3c: mipi-i3c-hci: Quieten initialization messages 2791dd42d41e3 apparmor: fix uninitialised pointer passed to audit_log_untrustedstring() fdf610a9a9e72 apparmor: don't audit files pointing to aa_null.dentry b58d240883dfe apparmor: put secmark label after secid lookup 66a6c61369d41 apparmor: aa_getprocattr free procattr leak on format failure 22dc9433d458c apparmor: fail policy unpack on accept2 allocation failure 3b918f6f52390 apparmor: Fix return in ns_mkdir_op 566d1ef98a711 apparmor: remove or add symlinks to rawdata according to export_binary fbfdb5a94a487 apparmor: fix NULL pointer dereference in unpack_pdb 57b1bd4486d56 apparmor: fix potential UAF in aa_replace_profiles b427061ca4983 apparmor: grab ns lock and refresh when looking up changehat child profiles 9111f76e8dc8c apparmor: fix rawdata_f_data implicit flex array ae02e603c0b39 apparmor: aa_label_alloc use aa_label_free on alloc failure d821601323456 apparmor: check label build before no_new_privs test ad965f36d2986 security/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref() 045dbe89ac317 apparmor: fix refcount leak when updating the sk_ctx d8ea44f6090c0 apparmor: fix race in unix socket mediation when peer_path is used ef488d7429d23 apparmor: fix shadowing of plabel that prevents cache from being updated f79519f636059 Revert "PCI/MSI: Unmap MSI-X region on error" 514b84b1bf30f PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability 11016555d7510 phy: freescale: phy-fsl-imx8qm-lvds-phy: Fix missing pm_runtime_disable() on probe error path 872f9a63a108e PCI: mediatek: Use actual physical address instead of virt_to_phys() f77c490c45d46 PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port() 9ca0a78a5d561 dt-bindings: phy: sc8280xp-qmp-pcie: Disallow bifurcation register on Purwa f1f5f8d334e91 perf symbols: Add bounds checks to read_build_id() note iteration in minimal build cc6cd3fe8b8b1 perf symbols: Add bounds checks to elf_read_build_id() note iteration a3e758e741228 perf bpf: Fix metadata leak in perf_env__add_bpf_info() on duplicate insert f593775fecf5a perf bpf: Fix map data leak in bpf_metadata_create() on alloc failure bafb6bfb346fe perf bpf: Add NULL check for btf__type_by_id() in synthesize_bpf_prog_name() fe4d8ad2e96f4 tools lib api: Fix mount_overload() snprintf truncation and toupper range b0385203a09f0 tools lib api: Fix filename__write_int() writing uninitialized stack data 41b3a92310450 perf tools: Use snprintf() in dso__read_running_kernel_build_id() fbaf9bdfc0917 perf hwmon: Guard label read against empty or failed reads d34b42ee0c74d perf symbols: Bounds-check descsz in sysfs__read_build_id() GNU fallback bc2fc12ce6e4d perf hwmon: Fix parse_hwmon_filename() strlcpy buffer overflow f830bb8d221f3 perf hwmon: Use scnprintf() in hwmon_pmu__for_each_event() 76dfa13a0acb1 perf hwmon: Fix off-by-one null termination on sysfs reads 56b17c84394f1 perf tools: Fix thread__set_comm_from_proc() on empty comm file f2e5262589d94 perf intel-pt: Fix snprintf size tracking bug in insn decoder 45e7900e1555c perf symbols: Bounds-check .gnu_debuglink section data 4f883ab5bc7b7 perf symbols: Fix signed overflow in sysfs__read_build_id() size check 490473192ac2f tools lib api: Fix missing null termination in filename__read_int/ull() 09962b811ef14 perf pmu: Fix perf_pmu__parse_scale/unit() OOB access on empty sysfs file a6eec54329b43 perf pmu: Fix pmu_id() heap underwrite on empty identifier file e274dfa05904f perf cs-etm: Queue context packets for frontend fa9eb50ddfea3 perf s390: Fix TEXTREL in Python extension by compiling as PIC b5a0a4a564d21 xprtrdma: Return sendctx slot after Send preparation failure 007b4da2f38dc xprtrdma: Repost Receive buffers for malformed replies 469b22376ee73 xprtrdma: Sanitize the reply credit grant after parsing d7a2870dde3bb xprtrdma: Fix bcall rep leak and unbounded peek 345652531400f xprtrdma: Resize reply buffers before reposting receives 47b3dc59e09e9 xprtrdma: Document and assert reply-handler invariants 7471e66373a44 xprtrdma: Check frwr_wp_create() during connect 28743571c17b5 xprtrdma: Initialize re_id before removal registration d0479c2b12974 xprtrdma: Fix ep kref imbalance on ADDR_CHANGE 6d52921f47020 perf hists: Fix snprintf() in hists__scnprintf_title() UID filter path 56ad33189ed5f perf bpf: Use scnprintf() in snprintf_hex() and synthesize_bpf_prog_name() c32fe40b0c745 perf sched: Fix idle-hist callchain display using wrong rb_first variant 77051ef66e4ad perf sched: Bounds-check prio before test_bit() in timehist 2e0dd50e5a4da PCI: rcar-host: Remove unused LIST_HEAD(res) b9e8406651dcc perf tools: Use perf_env__get_cpu_topology() in machine__resolve() 504028f561b19 perf tools: Use scnprintf() in cpu_map__snprint() to prevent overflow 2a8244988316a perf tools: Fix get_max_num() size_t underflow on empty sysfs file 3f4476a089a6d platform/x86/intel/vsec: Restore BAR fallback for header walk d6565e08166c8 platform/x86/intel/vsec: Return real error codes from registration path 4df30a4dc0e97 platform/x86/intel/vsec: Switch exported helpers from pci_dev to device 817ab332d37ce platform/x86/intel/vsec: Decouple add/link helpers from PCI e6523bcafeb61 platform/x86/intel/vsec: correct kernel-doc comments c0d97519c9dfb platform/x86:intel/pmc: Relocate lpm_req_guid to pmc_reg_map b95e1facc5b7f platform/x86:intel/pmc: Rename PMC index variable to pmc_idx 3e86797c0699d platform/x86:intel/pmc: Add support for multiple DMU GUIDs 4f129fc6f756f fs/ntfs3: resize log->one_page_buf when adopting on-disk page size d3491b23bc207 PCI: meson: Add missing remove callback a5c0ba31eef9e PCI: meson: Propagate devm_add_action_or_reset() failure f0aaa198e068b pwm: rzg2l-gpt: Add missing newlines to dev_err_probe() messages a57692ad365f3 PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro f161ef7b0dd2f nfs: use nfsi->rwsem to protect traversal of the file lock list a6f147b23e361 NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write a70375f0b793e NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors b694c7de94bc5 nfs: keep PG_UPTODATE clear after read errors in page groups f84949dd17847 NFSv4/pnfs: defer return_range callbacks until after inode unlock 53442c7d0c888 xprtrdma: Decouple req recycling from RPC completion becc90a04780a xprtrdma: Use sendctx DMA state for Send signaling e7ae0883c8c89 xprtrdma: Post receive buffers after RPC completion f043dd58fbd79 xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot b7bc8e7f09ae4 xprtrdma: Avoid 250 ms delay on backlog wakeup 44b73b4b7eff7 pNFS/filelayout: fix cheking if a layout is striped f3f21b94cf980 sunrpc: Fix error handling in rpc_sysfs_xprt_switch_add_xprt_store() e8dc126e80395 clk: qcom: a53: Corrected frequency multiplier for 1152MHz c0e6bb2b0408f dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor 9f1ef67c041ef dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc 329ec20a86091 dmaengine: Fix possible use after free 7d49f0ddaf5a4 dmaengine: qcom: gpi: set DMA_PRIVATE capability 8e2c460a8f0e4 mshv: add bounds check on vp_index in mshv_intercept_isr() eaf937b501fd0 clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks 032692e4525a0 dt-bindings: clock: qcom: Add X1P42100 camera clock controller c7c8bab87d0df perf tools: Fix int16_t truncation of max_cpu_num in set_max_cpu_num() e16012f8f63d3 perf timechart: Fix cpu2y() OOB read on untrusted CPU index 330219fe8523f perf c2c: Fix use-after-free in he__get_c2c_hists() error path 01564c1a260f6 perf stat: Introduce perf_env__get_cpu_topology() to guard NULL env->cpu c05ba5b57505a perf mmap: Fix NULL deref in aio cleanup on alloc failure c4406dbe5d8f4 perf sched: Replace BUG_ON and add NULL checks in replay event helpers b1f7683632712 perf sched: Use thread__put() in free_idle_threads() 1517402d0a81c perf sched: Clean up idle_threads entry on init failure d6b586bb8f489 perf c2c: Bounds-check CPU IDs in setup_nodes() topology loop 2f9f7224e7691 perf c2c: Bounds-check CPU and node IDs before bitmap and array access 278e30717c356 perf stat: Bounds-check CPU index in topology aggregation callbacks 21a9b87ada08d perf mmap: Guard cpu__get_node() return in aio_bind() 652cea73b7b7b perf sched: Fix register_pid() overflow, strcpy, and BUG_ON 068e9b6a07bc0 perf sched: Cap max_cpu at MAX_CPUS in timehist sample processing 1d25a8418c890 perf tools: Add bounds check to cpu__get_node() 89489a31f4443 perf sched: Fix thread reference leak in latency_switch_event ea486d61b1663 perf tools: Guard test_bit from out-of-bounds sample CPU 18961e0f8966e perf annotate: Fix crashes on empty annotate windows 93f3e84fc74e6 perf: Fix off-by-one stack buffer overflow in kallsyms__parse() d78b16d078149 dt-bindings: dma: nvidia,tegra186-gpc-dma: Make reset optional a498063f95bdd dmaengine: imx-sdma: Refine spba bus searching in probe da40583823153 thunderbolt: debugfs: Fix margining error counter buffer leak 038a0f01dda59 drm/amd/display: Add missing kdoc for ALLM parameters c5388a957cf1d fs/ntfs3: fix mount failure on 64K page-size kernels a318932065883 fs/ntfs3: add bounds check to run_get_highest_vcn() 097fcf945d93a HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter 26fa946925a09 clk: at91: keep securam node alive while mapping it 0147c544cbc6e iio: tcs3472: power down chip on probe failure 1cddef80a180a iio: accel: mma8452: handle I2C read error(s) in mma8452_read() 9ac3675bf8757 iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling 3d57672119525 iio: magnetometer: ak8975: fix potential kernel stack memory leak 6ec473b360342 iio: light: si1133: prevent race condition on timeout f835b69fbeaeb iio: light: si1133: reset counter to prevent race condition fd6b65ade1190 perf header: Sanity check HEADER_EVENT_DESC attr.size before swap be62602fe0797 PCI: qcom: Disable ASPM L0s for SA8775P de93ef83f99e8 powerpc tools perf: Initialize error code in auxtrace_record_init function 96c8f732cadf7 clk: renesas: rzg2l: Rename iterator in for_each_mod_clock() to avoid shadowing fdee9f207a48c gpib: fix double decrement of descriptor_busy in command_ioctl() 3d5e4cc0d9dce char: tlclk: fix use-after-free in tlclk_cleanup() d72ece584c448 gpib: Fix inappropriate ioctl error return 92f8b1d833834 perf test amd ibs: Fix incorrect kernel version check 2b2b1613b734b usb: host: max3421: Reject hub port requests for non-existent ports 02d03c61e8a7b usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() 43078449ad623 staging: most: video: avoid double free on video register failure 45652323ce74b perf inject: Add --convert-callchain option 28ebd287a7fad perf build-id: Fix off-by-one bug when printing kernel/module build-id fc5ce5606db57 PCI: dwc: Fix signedness bug in fault injection test code 7d881615fb637 mailbox: mtk-adsp: fix UAF during device teardown 91353d63bbf61 mailbox: mpfs: fix check for syscon presence in mpfs_mbox_inbox_isr() e6bc4e127707d coresight: Fix source not disabled on idr_alloc_u32 failure 67d0475e78b39 soundwire: intel_ace2x: release bpt_stream when close it 5732869c70d42 clk: at91: sam9x7: Fix gmac_gclk clock definition f28906e7e32fd perf pmu: Skip test on Arm64 when #slots is zero 210c202c0576b phy: phy-can-transceiver: Check driver match and driver data against NULL 226feccaac818 clk: qcom: cmnpll: Account for reference clock divider 6abdf27fbcfb3 coresight: fix missing error code when trace ID is invalid 5bb87456dcd66 bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() 601a9b2e3b2fb rust: alloc: fix assert in `Vec::reserve` doc test b773c7161cea7 PCI: loongson: Do not ignore downstream devices on external bridges e1b79f77336d1 perf sched: Add missing mmap2 handler in timehist c788955b4a145 platform/x86: xo15-ebook: Fix wakeup source and GPE handling 2ce4d93768d2c x86/platform/olpc: xo15: Drop wakeup source on driver removal 1d495446ec7ac PCI: Check ROM header and data structure addr before accessing 78f264c0cb2ac PCI: Introduce named defines for PCI ROM 10021c2d33061 PCI/ASPM: Don't reconfigure ASPM entering low-power state 48dde5c56426c coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore 65d87f28daec3 coresight: ete: Always save state on power down 1ac8f4c112aa9 coresight: etm4x: Remove the state_needs_restore flag a454f61747c97 soundwire: fix bug in sdw_add_element_group_count found by syzkaller d3896c944338c soundwire: don't program SDW_SCP_BUSCLOCK_SCALE on a unattached Peripheral c3ca7c6741af3 coresight: cti: Fix DT filter signals silently ignored fb940466fd4d3 perf debuginfo: Fix libdw API contract violations bb3d592c7d6c4 staging: nvec: fix use-after-free in nvec_rx_completed() 466c7f87de52d i3c: master: svc: Fix missed IBI after false SLVSTART on NPCM845 db2d8b6525bdd gpiolib: acpi: Only trigger ActiveBoth interrupts on boot 02e2dadd62eae eventpoll: Fix epoll_wait() report false negative f938bc8fde518 eventpoll: rename epi->next and txlist for clarity 430dac191905b eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers d8f88803152f0 eventpoll: extract ep_deliver_event() from ep_send_events() 4fd51f413d7b5 eventpoll: split ep_insert() into alloc + register stages 25e85dc040a6c eventpoll: rename attach_epitem() to ep_attach_file() baebd892f8a2c eventpoll: expand top-of-file overview / locking doc f04166c8677aa eventpoll: rename ep_remove_safe() back to ep_remove() 13bf9879b778b net/9p: fix race condition on rdma->state in trans_rdma.c 9c1c120471a67 9p: avoid returning ERR_PTR(0) from mkdir operations ae1f3460833d3 ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write d35e4032f16d7 mfd: cs42l43: Sanity check firmware size 706fe1ce4f3a5 mfd: rsmu: Fix page register setup 35d3d6ff2bc1e ksmbd: fix use-after-free in same_client_has_lease() aa0c43c13c0bf RDMA/bnxt_re: Fail DBR related page allocation UAPIs if the feature is disabled 0fe155aa844e4 RDMA/bnxt_re: Move the UAPI methods to a dedicated file 95d46a8d3ba9f RDMA/bnxt_re: Avoid displaying the kernel pointer 104a7ff382a58 RDMA/bnxt_re: Free SRQ toggle page after firmware teardown 5a48dd5150d7c ionic: Fix check in ionic_get_link_ext_stats 4c55003566c0b net: ethernet: oa_tc6: Remove FCS size in RX frame 93e133b9193cb net: airoha: Fix always-true condition in PPE1 queue reservation loop d774cdbda6634 tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) 0d8a12d714312 tipc: fix UAF in tipc_l2_send_msg() db1616263a2c5 KEYS: Use acquire when reading state in keyring search 66919a6d72b9e powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus 527cd14a416f2 powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down 73711688479df powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del 92f38fe85198a MIPS: mm: Fix out-of-bounds write in maar_res_walk() fe09dd288722f bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check 81567d2b3f4dc sockmap: Fix use-after-free in udp_bpf_recvmsg() 073d957252696 net: remove addr_len argument of recvmsg() handlers 4e40056bb5c82 bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() 264d6a79c96ee udf: fix nls leak on udf_fill_super() failure 5e8627b7a7b7c bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket e803077769248 selftests/bpf: Initialize operation name before use 9f32d4c2de85f selftests/bpf: Fix typo in verify_umulti_link_info 74badb5e2b00a smb/client: always return a value for FS_IOC_GETFLAGS 21303c4a2b727 cifs: remove all cifs files before kill super 7a59146cb9ade ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() 87d1eaffeec41 netfilter: nf_conncount: callers must hold rcu read lock 98a965cb1e767 ALSA: seq: avoid stale FIFO cells during resize 287d506d4e086 ALSA: seq: oss: Serialize readq reset state with q->lock f01fb6138f8eb kcm: use WRITE_ONCE() when changing lower socket callbacks 4d48c08a0bf6c net: airoha: Fix debugfs new-tuple display for IPv4 ROUTE entries dcac6e4221f39 net: airoha: Fix register index for Tx-fwd counter configuration 36edab340a067 net: bcmgenet: Use weighted round-robin TX DMA arbitration b91b241a4eefe landlock: Fix unmarked concurrent access to socket family 1bb02353e79f7 dpll: balance create/delete notifications in __dpll_pin_(un)register 77a1ea975c877 dpll: guard sync-pair removal on full pin unregister 8008ef973f012 dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister() 6564ce3a2f9c2 dpll: send delete notification before unregister in on-pin rollback f1e1c6eb82482 dpll: fix stale iteration in dpll_pin_on_pin_unregister() 20575400fc1ba dpll: Enhance and consolidate reference counting logic ebe4bd3560a7a dpll: Support dynamic pin index allocation f7aebaee2961b net: wwan: t7xx: check skb_clone in control TX 34bd255dba321 net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show() 1d072cc3ba433 octeontx2-af: npc: Fix size of entry2cntr_map 417bd36a085d7 bpf: Fix setting retval to -EPERM for cgroup hooks not returning errno 3d90b15fb1918 net/mlx5: Check max_macs devlink param value against max capability 8d5f4be134882 bpf: Run generic devmap egress prog on private skb 450e48271827b net/sched: sch_dualpi2: Add missing module alias 6d585d0dc6743 net: ethernet: mtk_wed: fix loading WO firmware for MT7986 446fe8ce699ce net: watchdog: fix refcount tracking races 697db22a9dcc4 net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check 62ce489acb428 net: mana: initialize gdma queue id to INVALID_QUEUE_ID bd851b10daee7 net/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen 755108bb7a508 net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen 0500af8630c32 net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen a05d638b60746 virtio_net: do not allow tunnel csum offload for non GSO packets ce311bd2e3659 tcp: clear sock_ops cb flags before force-closing a child socket 67cec2f1eb9e5 handshake: Require admin permission for DONE command d0503357653ee power: supply: core: fix supplied_from allocations 7f4aa81f5bb27 ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO 0c22c00924359 iommu: Avoid copying the user array twice in the full-array copy helper 1c9246a199e19 spi: xilinx: use FIFO occupancy register to determine buffer size dae23c545eb5a ALSA: seq: Fix kernel heap address leak in bounce_error_event() 1749fef4bda0f ALSA: usb-audio: qcom: Guard sideband endpoint removal 2ba2373151936 crypto: rng - Free default RNG on module exit fb4d57b83356d crypto: cavium/cpt - fix DMA cleanup using wrong loop index 5f99a396f706a crypto: marvell/octeontx - fix DMA cleanup using wrong loop index 4941205f5fa39 cxl/test: Add check after kzalloc() memory in alloc_mock_res() a27481516d32f cxl/test: Unregister cxl_acpi in cxl_test_init() error path 7e401233f9bb7 tipc: reject inverted service ranges from peer bindings 3cfa3d8e0dc16 tipc: prevent snt_unacked underflow on CONN_ACK cebaefe1aceb6 tipc: require net admin for TIPCv2 netlink mutators 66dbb13eeb2fc net/sched: sch_hfsc: Don't make class passive twice 51a1d9836acc7 net: pfcp: allocate per-cpu tstats for PFCP netdevs ed8605c6f39b9 sctp: validate embedded address parameter length a090880c1f544 bridge: cfm: reject invalid CCM interval at configuration time bb4a5b3c91af3 net: fib_rules: Don't dump dying fib_rule in fib_rules_dump(). 0a8b5b74f0e6b net/sched: cls_flow: Dont expose folded kernel pointers 10e05634ddc19 net: dsa: qca8k: fix led devicename when using external mdio bus e098c9c6477df ASoC: tegra: tegra210_ahub: Validate written enum value 0f1510e84d7bf ASoC: fsl: fsl_audmix: Validate written enum values 9131e4b023e0d ASoC: codecs: hdac_hdmi: Validate written enum value cb527e063a32e ASoC: SOF: Intel: hda-sdw-bpt: select SND_SOF_SOF_HDA_SDW_BPT properly d3ff718c0c715 RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one 4b87a2497276a RDMA/mlx5: Fix undefined shift of user RQ WQE size 1bc1487f7a7f5 RDMA/mlx5: Remove raw RSS QP restrack tracking f704db4b0318a RDMA/mlx5: Remove DCT restrack tracking 3a1687e0506be fs: efs: remove unneeded debug prints 7e694ac97591c Bluetooth: vhci: validate devcoredump state before side effects ec4d352747a62 Bluetooth: hci: validate codec capability element length 7f206a8d8d822 Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path a0fd1086a57b9 Bluetooth: hci_core: Fix UAF in hci_unregister_dev() e8815ae9dcdc5 Bluetooth: hci_event: fix simultaneous discovery stuck in FINDING f1b4df9c260c5 Bluetooth: eir: Fix stack OOB write when prepending the Flags AD e284bb94ad451 Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device c86c861c64b58 s390/process: Fix kernel thread function pointer type 0eab19ab9cb1b ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset() c83255f3cf22d arm64: dts: allwinner: a523: Add missing GPIO interrupt ad6963c3bb458 pinctrl: airoha: an7581: fix misprint in gpio19 pinconf 5985ddfd3e83f pinctrl: airoha: an7581: add missed gpio32 pin group db3cd694ded4c pinctrl: airoha: generalize pins/group/function/confs handling 0234e8fc296e7 pinctrl: sunxi: a523: Remove unneeded IRQ remuxing flag 46fbafe3d2d56 bpf: Tighten cgroup storage cookie checks for prog arrays d416dcefdbac9 vfio/qat: fix f_pos race in qat_vf_resume_write() 1201dbb260507 of: cpu: add check in __of_find_n_match_cpu_property() d2acea4f47475 cxl/test: Zero out LSA backing memory to avoid leaking to user 42a9a76f314ef cxl/test: Fix integer overflow in mock LSA bounds checks 91ad3088ee1b7 selftests/bpf: Fix bpf_iter/task_vma test f00f5c0dd5531 ext4: fix kernel BUG in ext4_write_inline_data_end c998a09c7144e bonding: 3ad: fix mux port state on oper down f0ada4846d11b bonding: 3ad: fix carrier when no usable slaves cb20a9b50efe0 bonding: 3ad: add lacp_strict configuration knob 47636f0a70b36 netlink: specs: rt-link: missed broadcast-neigh 6b2c271d2c394 tools: missed broadcast_neigh if_link uapi header 484b3b9aa7986 ext4: fix ERR_PTR(0) in ext4_mkdir() 88cb304c0be0c ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails 8b55e7ec116ca ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() 3ef0cfa77a3d5 vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler 54556d5394382 vdpa/octeon_ep: Fix PF->VF mailbox data address calculation 86e0b37738dea tools/virtio: check mmap return value in vringh_test 321c73baf54d9 vhost/net: complete zerocopy ubufs only once 646614dcb1607 vduse: Requeue failed read to send_list head f9d9220234451 virtio_console: read size from config space during device init 79366023aa891 virtio: rtc: tear down old virtqueues before restore 1f5f94c6c6b2e vhost/vdpa: validate virtqueue index in mmap and fault paths a2d0a57538fd0 vduse: hold vduse_lock across IDR lookup in open path 3d56f3fb201ff ASoC: codecs: aw88261: fix incorrect masks for boost regs ecb9be4fc8be0 spi: meson-spifc: fix runtime PM leak on remove da6f86ff4f2dd NFSD: Handle layout stid in nfsd4_drop_revoked_stid() 37e85be551c4d IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified e6d83f877d5ab ASoC: sma1307: Fix uevent string leaks in fault worker 701ea71c17c92 igc: skip RX timestamp header for frame preemption verification 2aa37c8ef1092 btrfs: fix deadlock cloning inline extent when using flushoncommit f85410ebf20bb btrfs: annotate lockless read of defrag_bytes in should_nocow() 18285888cb41a btrfs: zoned: always set max_active_zones for zoned devices 943f5917c53ca Revert "btrfs: fix the file offset calculation inside btrfs_decompress_buf2page()" ba641829c11cb btrfs: zoned: don't account data relocation space-info in statfs free space bd5e90b0f5a09 hwmon: (it87) Clamp negative values to zero in set_fan() ebb579c5c0f0f vfs: add FS_USERNS_DELEGATABLE flag and set it for NFS de590cdf7efec fbdev: sm501fb: Fix buffer errors in OF binding code 0678fed27def9 wifi: ath12k: enable IEEE80211_VHT_EXT_NSS_BW_CAPABLE when NSS ratio is reported 47e5302722e09 gpio: mt7621: fix interrupt banks mapping on gpio chips 90a9c909c5b75 ALSA: aloop: Drop superfluous break 3b15d02be05e7 btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() 7ec839c7c0bc1 wifi: mt76: mt7996: fix potential tx_retries underflow ad12fdaaed16c wifi: mt76: mt7925: fix potential tx_retries underflow 3b6e6fefa57f4 wifi: mt76: mt7921: fix potential tx_retries underflow 6b8e35685c18c wifi: mt76: mt7915: fix potential tx_retries underflow 6356a829a1edc wifi: mt76: fix argument to ieee80211_is_first_frag() 42f34c478fcdf wifi: mt76: mt7996: limit work in set_bitrate_mask 1a399103cacc9 wifi: mt76: mt7996: fix reading zeroed info->control.flags after mt76_tx_status_skb_add() dfb27e5dd9e4d wifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write_txwi_80211() 06e65d6cf8049 wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb() c386e90a7ce8d wifi: mt76: mt7925: validate skb length in testmode query 856fa6a21586f wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX a10e4959a73be wifi: mt76: mt7925: keep TX BA state in the primary WCID b8bf7c221b364 wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links bd3b91ff13006 wifi: mt76: mt7996: add missing max_remain_on_channel_duration c7a83899203ed wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link 3f0ea6d14fa44 wifi: mt76: mt7925: clean up DMA on probe failure ce9d5a021cfca ARM: configs: Drop duplicated CONFIG_EXT4_FS c788617705c3a sched/fair: Fix cpu_util runnable_avg arithmetic a2e8b5264f92e hwspinlock: qcom: avoid uninitialized struct members bbd664b7c77f6 vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() 648a3960e3664 pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 44cff0737127b pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 f775e7bda9a4f scsi: target: Remove tcm_loop target reset handling c2bd9fdb448d6 scsi: target: Fix hexadecimal CHAP_I handling 0404baeb9e430 pinctrl: qcom: Fix resolving register base address from device node 298821692d447 watchdog: unregister PM notifier on watchdog unregister 637ef4961470e configfs: fix lockless traversals of ->s_children f25d6e4ec4c25 firmware_loader: Fix recursive lock in device_cache_fw_images() 9e82497138abe ASoC: amd: acp-sdw-sof: Bound DAI link iteration 1279bdab5fa1f ASoC: amd: acp-sdw-legacy: Bound DAI link iteration e8d89baf92170 spi: ep93xx: fix double-free of zeropage on DMA setup failure e123f0ab02d05 IB/mlx5: Don't mangle the mr->pd inside the rereg callback fd284b12810e4 IB/mlx5: Pull the pdn out of the depths of the umr machinery 8119fe468b01f IB/mlx5: Remove unused mkc bits in mlx5r_umr_update_mr_page_shift() d4f84bfa089fe IB/mlx5: Properly support implicit ODP rereg_mr f5657d399b7ef IB/mlx5: Don't take the rereg_mr fallback without a new translation c213b71a2d416 btrfs: don't force DIO writes to be serialized 920dcf1cb8dae thermal: testing: reject missing command arguments dde04550fd6ff cpufreq: Documentation: fix conservative governor freq_step description 6cb635ad1006d ACPI: IPMI: Fix message kref handling on dead device b7474f4432dd9 bpf: Fix NULL pointer dereference in bpf_task_from_vpid() 84932636d020b powerpc/8xx: implement get_direction() in cpm1 8daa1a64711ed kunit:tool: Don't write to stdout when it should be disabled 8b0510cc3a4a0 bpf: Fix NMI/tracepoint re-entry deadlock on lru locks 74ac1ce1f4afd ALSA: seq: Clear variable event pointer on read c04e0cde2fa38 riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe 834d4cc067fa6 riscv: cpu_ops: Change return value type of cpu_is_stopped() to bool 4b2b6bc7f5ebe ALSA: seq: Fix partial userptr event expansion af8f0ea1f0a3a wifi: wcn36xx: fix OOB read from short trigger BA firmware response f03782f7f41f2 wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication 1b5d8a248c3af wifi: wcn36xx: fix heap overflow from oversized firmware HAL response 495e7e832c670 bpf: Update transport_header when encapsulating UDP tunnel in lwt efe57b72196ae bpf: Check tail zero of bpf_prog_info 58513d6d12410 bpf: Check tail zero of bpf_map_info 2eb39de4962f8 bpf: Clear rb node linkage when freeing bpf_rb_root f6183983ce1ff RDMA/siw: Fix endpoint/socket association handling 04255bda8d795 arm64: dts: imx8mp-kontron: Fix GPIO for display power switch e6ab22200e449 arm64: dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as well f3ef944c55991 arm64: dts: lx2162a-clearfog: use rev2 SoC dtsi b5087fc4ef1f8 arm64: dts: imx95: Correct PCIe outbound address space configuration ab4b5a07e1c1a arm64: dts: imx8mp-kontron: Reduce EERAM SPI clock frequency f9173e0fc026c RDMA/irdma: Initialize iwmr->access during MR registration 54cab78df0375 RDMA/irdma: Fix OOB read during CQ MR registration 844a1ae78e220 ALSA: hda: fix Kconfig dependency of HD Audio PCI 47831b503ecb7 IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path() fe5414d6b3995 RDMA/hfi1: Open-code rvt_set_ibdev_name() 77b4bfc1ce32a netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp d53eecbca16f0 netfilter: conntrack: revert ct extension genid infrastructure e6665d36b37b4 x86/cpu: Remove obsolete aperfmperf_get_khz() declaration dd0d22fdae4cb ALSA: usb-audio: qcom: Initialize offload control return value 8ebc31b86dccd netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock 5c9c67cf7a3d1 netfilter: synproxy: fix unaligned memory access in timestamp adjustment b171119082bab netfilter: synproxy: adjust duplicate timestamp options 4dbb71c046f72 netfilter: synproxy: drop packets if timestamp adjustment fails dce1e3cf735d1 netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags 7b819a84f1d5f netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures c3ebf67cf8a96 ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release() a087b2d3411e7 ocfs2/dlm: require a ref for locking_state debugfs open 3fa7139b5f427 ocfs2: reject FITRIM ranges shorter than a cluster 0e389fc290c35 ocfs2: fix buffer head management in ocfs2_read_blocks() 3fe2d0d21c8ae lib: kunit_iov_iter: repeatedly call alloc_pages_bulk() bb44a7690a4d5 ocfs2: rebase copied fsdlm LVB pointers in locking_state 9af58d10d0d8c of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails 9a030fcb4b192 drm/amdkfd: always resume_all after suspend_all b8d15e85596ad cxl/fwctl: Fix __fortify_panic b64120d54278e xfrm: fix NAT-related field inheritance in SA migration ac9e29b191a03 perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains 58cbb1c2aadf8 perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems 4e18e9361aab0 perf/x86/amd/core: Always use the NMI latency mitigation f5102e0fc3c6d iommu/vt-d: Fix RB-tree corruption in probe error path 7f229d27bf27c vhost: fix vhost_get_avail_idx for a non empty ring 73f9f54d71749 bpftool: Use libbpf error code for flow dissector query 4beed798daf4d drm/amdgpu: set sub_block_index for mca ras sub-blocks e82d515092a0c ext4: fix fast commit wait/wake bit mapping on 64-bit 8cbd587e8cdb6 lockdep/selftests: Restore sched_rt_mutex state on PREEMPT_RT 8d5ed4810e479 lockdep/selftests: Restore migrate_disable() state on PREEMPT_RT c3b073a209a9b configfs_lookup(): don't leave ->s_dentry dangling on failure 778bb4939d457 riscv: dts: sophgo: sg2042: use hex for CPU unit address efe71fbced524 riscv: dts: sophgo: sg2044: use hex for CPU unit address 5a1168ba0a95b lib/test_meminit: use && for bools 3777588848520 tick/sched: Fix TOCTOU in nohz idle time fetch 5cf2c85b12312 bpf: Reject exclusive maps for bpf_map_elem iterators 0830287cc6cb7 driver core: Use system_percpu_wq instead of system_wq 5e406928404d6 nvme: fix FDP fdpcidx bounds check 36bdda0c86d51 sched: restore timer_slack_ns when resetting RT policy on fork ffa974b2f50ad ext2: fix ignored return value of generic_write_sync() 8d763babb2a2f mm/fake-numa: fix under-allocation detection in uniform split 61f1972972824 bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs d81370c6c4f5f scsi: ufs: Fix wrong value printed in unexpected UPIU response case 846052542cfa6 scsi: pm8001: Fix error code in non_fatal_log_show() 0de14eae6de88 libbpf: Skip max_entries override on signed loaders abe383999640f libbpf: Skip initial_value override on signed loaders b6862b6a25c6a libbpf: Reject non-exclusive metadata maps in the signed loader 3a0f73d27a8d3 bpf: Reject exclusive maps as inner maps in map-in-map 91ca9eab008b9 scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans" 5c53406098b59 nvdimm/btt: Handle preemption in BTT lane acquisition d292b30e1b746 x86/cpu: Keep the PROCESSOR_SELECT menu together 901802925ebed ARM: imx31: Fix IIM mapping leak in revision check 617a5a67ce016 ata: libata: Fix ata_exec_internal() cfcea221db933 wifi: ath12k: fix NULL deref in change_sta_links for unready link eb9b89baf3087 wifi: ath12k: fix incorrect HT/VHT/HE/EHT MCS reporting in monitor mode adf0eb748d21d HID: wiimote: Fix table layout and whitespace errors 2d642797dd1c1 ARM: imx3: Fix CCM node reference leak f0742d09eb6ba NFSD: Fix delegation reference leak in nfsd4_revoke_states 9e565962d999e ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble 8ec64276ecd24 spi: atmel: fix DMA channel and bounce buffer leaks ab4d04bf8b2f3 ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback 803087a16a4ea libbpf: Skip endianness swap when loader generation failed f3389fbaff1a1 libbpf: Skip hash computation when loader generation failed a441c0794ac28 selftests/bpf: add verification for BPF_PROG_QUERY attr size boundaries a7131340d0f95 bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat 5ac9e793ba258 raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path b7313f23ea5a7 md/raid10: reset read_slot when reusing r10bio for discard e04e384274f83 rpmsg: use generic driver_override infrastructure 0e2f0833556c8 Drivers: hv: vmbus: use generic driver_override infrastructure d2cf52ba2803b cdx: use generic driver_override infrastructure b41923dbf6769 amba: use generic driver_override infrastructure ff4e38a37ba53 media: qcom: venus: relax encoder frame/blur step size on v6 bc7c166cc1012 media: qcom: venus: relax encoder frame/blur dimension steps on v4 ffe754288750a media: qcom: venus: drop extra padding in NV12 raw size calculation f8f48c851a0d2 Revert "media: venus: hfi_platform: Correct supported codecs for sc7280" 5420eebf3b3c1 RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path 02558c86b6b76 RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe 4779f435627b2 RDMA/umem: Add ib_umem_is_contiguous() stub for !CONFIG_INFINIBAND_USER_MEM bae436a78a058 arm64: dts: st: Fix SAI addresses on stm32mp251 5da012c605fd5 EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info 9a84ced0243c7 EDAC/igen6: Fix call trace due to missing release() ed5c94cf4ee9e drm/msm/dp: Fix the ISR_* enum values bdaea74abcf0c drm/msm/dp: fix HPD state status bit shift value 6d536a9107172 sched/deadline: Reject debugfs dl_server writes for offline CPUs 4f3c17f14cf90 crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm 5eac10c521396 crypto: tegra - Fix dma_free_coherent size error 5231093c08295 crypto: inside-secure/eip93 - Add check for devm_request_threaded_irq 8572232ed74f5 crypto: hisilicon/qm - disable error report before flr ce7a2e26e144f ocfs2: kill osb->system_file_mutex lock 3852478d34c7b ocfs2: don't BUG_ON an invalid journal dinode 070f356ea4f41 rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() 598ed7393a639 dax/kmem: account for partial discontiguous resource upon removal afdb92d9c374d arm64: tegra: Add #{address,size}-cells to Chromium-based /firmware e545fcba3660c ARM: tegra: Add #{address,size}-cells to Chromium-based /firmware c87339cc08aa0 libbpf: Fix UAF in strset__add_str() 39e8be33387e3 bpftool: Fix typo in struct_ops map FD generation for light skeleton ed7ba8d048a4c libbpf: Harden parse_vma_segs() path parsing 340936ebf5aec drm/nouveau/bios: specify correct display fuse register for Ampere and Ada 2ab7c96d8c3fb drm/tegra: Fix iommu_map_sgtable() return value check 79240eee5a400 gpu: host1x: Fix iommu_map_sgtable() return value check 142b34f7e329c drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() 8c0d3cf0d5108 gpu: host1x: Allow entries in BO caches to be freed 6b617b6ccb6eb drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove 40a2a91da02c4 drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered 05d85fd32e4fe rtla/actions: Restore continue flag in actions_perform() b7ac7ba19a0b8 rtla: Introduce for_each_action() helper dc266f6c4e262 iommu/amd: Fix premature break in init_iommu_one() 10753da2d659d net/sched: cls_bpf: prevent unbounded recursion in offload rollback 0db1949084e85 ipv6: guard against possible NULL deref in __in6_dev_stats_get() dc1470299d11d workqueue: drop spurious '*' from print_worker_info() fn declaration 3e8aed5edaeeb nvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools 140d6fff4ed26 nvme-multipath: fix flex array size in struct nvme_ns_head cba2ee57fd302 nvmet-tcp: check return value of nvmet_tcp_set_queue_sock ba3209704b3cd nvmet-tcp: fix page fragment cache leak in error path 24639c4dc466e init/initramfs_test: wait_for_initramfs() before running eb9280ea8dbd2 pinctrl: cs42l43: Fix polarity on debounce 2739d234d8952 pinctrl: cs42l43: Fix leaked pm reference on error path 95e0b4bc29ab9 pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table c418c956c21c9 selftests: Fix Makefile target for nsfs 11165fe2c5ea0 ALSA: seq: midi: Serialize output teardown with event_input 6dc781778b595 ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data de236b813d8b4 ALSA: xen-front: Connect event channel after stream prepare 56694f00fbe10 ALSA: xen-front: Reset event channel state on stream clear 02f156309de0d mtd: spi-nor: Drop duplicate Kconfig dependency c4bb92b3ef54c mtd: spi-nor: debugfs: Fix the flags list 3880ee7c88d78 driver core: Guard deferred probe timeout extension with delayed_work_pending() 0a294feec21b6 driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout() 2c12b0dfcedad mips: n64: add __iomem for writel call 8db227dd895a8 mips: ralink: mt7621: add missing __iomem 0c83d13f9b3f1 MIPS: DEC: Remove do_IRQ() call indirection c9a3ceeddc6ad MIPS: Fix big-endian stack argument fetching in o32 wrapper c9670fd84df12 PM: sleep: Use complete() in device_pm_sleep_init() 80f8e2302e639 pinctrl: meson: amlogic-a4: fix gpio output glitch 9420871183eab RDMA/counter: Fix incorrect port index in rdma_counter_init() error cleanup 66f44ec974ab3 RDMA/hns: Fix log flood after cmd_mbox failure 16138ea9833d6 RDMA/hns: Fix warning in poll cq direct mode f67fbbfc3beb8 IB/mlx4: Fix refcount leak in add_port() error path e59a6aa89e0fc RDMA/rxe: Fix a use-after-free problem in rxe_mmap 424d51d33c754 RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs 7a551951ebeb5 pinctrl: spacemit: fix NULL check in spacemit_pin_set_config 394ed8ad05889 bus: sunxi-rsb: Always check register address validity 090f5fb1e3e23 RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed c11039512df49 pwm: imx27: Fix variable truncation in .apply() 13db458099f28 cpufreq: conservative: Simplify frequency limit handling 3fcbfc50dd52f cpufreq: Documentation: fix sampling_down_factor range 376951c51cdd0 crypto: eip93 - fix reset ring register definition 4a6f5cc42c7bf of: dynamic: Fix overlayed devices not probing because of fw_devlink ae62edb00c0eb Revert "treewide: Fix probing of devices in DT overlays" 2df37ead6d84b driver core: Use mod_delayed_work to prevent lost deferred probe work 62c8cc825f49e device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id() b0444205ba39e kernfs: fix suspicious RCU usage in kernfs_put() 29de8448174cf writeback: drop now-unnecessary rcu_barrier() in cgroup_writeback_umount() 2469039f0fd68 arm64: dts: qcom: lemans: Add eDP ref clock for eDP PHYs baa333b2700a7 tracing: Bound synthetic-field strings with seq_buf 09a2a7d041a78 arm64: dts: qcom: sm8750: Add power-domain and iface clk for ice node 4ba44339fd3ac arm64: dts: qcom: sm8650: Add power-domain and iface clk for ice node 3c808cac676c5 arm64: dts: qcom: sm8550: Add power-domain and iface clk for ice node 0d0ce8c7025ac arm64: dts: qcom: sm8450: Add power-domain and iface clk for ice node a8be1bc8d124f arm64: dts: qcom: kodiak: Add power-domain and iface clk for ice node dc36463b283d9 arm64: dts: qcom: sc7180: Add power-domain and iface clk for ice node a2303478e7301 arm64: dts: qcom: monaco: Add power-domain and iface clk for ice node b3e05859cb516 arm64: dts: qcom: lemans: Add power-domain and iface clk for ice node 11daac2817dca firmware: arm_scmi: Fix OOB in scmi_power_name_get() 15e7368de5842 media: rockchip: rga: fix too small buffer size a88f6da618e8b net/sched: sch_drr: annotate data-races around cl->deficit 276e731b1b577 nilfs2: Fix return in nilfs_mkdir 16bf3154f8a80 tools/nolibc: getopt: Fix potential out of bounds access c67c672047667 regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions 75c0bc011abdd bitops: use common function parameter names 407aeb8c1aee8 sysfs: clamp show() return value in sysfs_kf_read() bac3e70c2fb10 firmware: arm_scmi: Read sensor config as 32-bit value 1f60c3cc302d2 firmware: smccc: Fix Arm SMCCC SOC_ID name call 3024229e4a5af riscv: dts: spacemit: set console baud rate on Milk-V Jupiter 63aa7dda9a1ed staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy() d57e67ea48e4d media: atomisp: gc2235: fix UAF and memory leak 2e3e4cc0dd349 media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() 5d6f34dc4f056 arm64: dts: imx95-19x19-evk: Fix PCIe EP vpcie-supply 084d7d5668f30 arm64: dts: imx8qxp-mek: Remove unnecessary PCIe EP vpcie-supply 6a576739ce4c9 arm64: dts: imx8dxl-evk: Remove unnecessary PCIe EP properties 0da72a88dbbab firmware: arm_ffa: Honor partition info descriptor size 5e353d9497f95 selftests/mm: Fix resv_sz when parsing arm64 signal frame 6a357ceb21100 iommu/arm-smmu-qcom: Fix fastrpc compatible string in ACTLR client match table bcfc49f1bcf1b selftests/bpf: Fix test for refinement of single-value tnum e4d599a286b5a selftests/bpf: Reject unsupported -k option in vmtest.sh 7471006cd854d drm/syncobj: Fix memory leak in drm_syncobj_find_fence() be2c137f23d15 RDMA/hns: Initialize seqfile before creating file 65572fbd86033 RDMA/srpt: fix integer overflow in immediate data length check 5100febf8e9d6 RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference ffa85a2c19793 RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure 2cd221fca036b RDMA/hns: Fix arithmetic overflow in calc_hem_config() 65e344925fa30 IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier b61af0268e3d1 ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD 5c1196b5a3bf3 net/sched: sch_htb: annotate data-races (I) d8cae30582f06 net/sched: sch_htb: do not change sch->flags in htb_dump() 68eae3592438d spi: hisi-kunpeng: Use dev_err_probe() for host registration failure 21650fe221ea9 crypto: ccp - Treat zero-length cert chain as query for blob lengths cb414aff28e18 scsi: hisi_sas: Add slave_destroy interface for v3 hw 8b42290df1765 net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats() d29b9c38f6eb4 clk: scpi: Unregister child clock providers on remove 69bc4a3998742 thermal: hwmon: Fix critical temperature attribute removal a0f64cf8bfcb3 evm: terminate and bound the evm_xattrs read buffer 4c57df82af833 drm/hisilicon/hibmc: use clock to look up the PLL value 28b91fd2adc4f drm/hisilicon/hibmc: move display contrl config to hibmc_probe() 94ab8a6e02bae drm/hisilicon/hibmc: fix no showing when no connectors connected 689bb48c828ca drm/hisilicon/hibmc: add updating link cap in DP detect() 27af16a44f590 arm64: dts: qcom: sm8450: Fix ICE reg size 886fb63981a92 arm64: dts: qcom: kodiak: Fix ICE reg size 2e2e5888764ba clk: scmi: Fix clock rate rounding 8200ffd8259f0 rust: alloc: fix `Vec::extend_with` SAFETY comment 9fe7605c1c143 arm64: dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to host 02367b12b303a uaccess: fix ignored_trailing logic in copy_struct_to_user() e003f3a4be738 bpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries 8960088511ca1 soc: mediatek: mtk-mmsys: Restore MT8167 routing masks lost during merge 0dd1cf48a4217 iommu/amd: Fix a stale comment about which legacy mode is user visible feb10ab7abc24 media: venus: scale MMCX power domain on SM8250 9e642727b97dd media: iris: scale MMCX power domain on SM8250 e725aedd26e96 media: qcom: camss: vfe: fix PIX subdev naming on VFE lite f9f1a2cd912da nilfs2: fix backing_dev_info reference leak 712714f818d83 dlm: fix add msg handle in send_queue ordered 4695cfab48f90 ARM: multi_v7_defconfig: Correct QCOM_RPMH and QCOM_RPMHPD 6acd2fbd00f9c crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents 9b21d5bd33a7f crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve aac63bbea8fd5 crypto: atmel-sha204a - fix blocking and non-blocking rng logic c5c79d92da0f9 crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one 25b0061adc1c1 crypto: ccp - Reverse the cleanup order in psp_dev_destroy() 46696b0b21234 OPP: Fix race between OPP addition and lookup 8fe4736532639 alarmtimer: Remove stale return description from alarm_handle_timer() 224d7300b5691 drm: renesas: rz-du: mipi_dsi: Fix return path on error 4a8cde6f7281e vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). 470984f1c2ed8 Revert "arm64: dts: imx8mp-kontron: Add support for reading SD_VSEL signal" 5f7777f0da030 Revert "arm64: dts: imx8mm-kontron: Add support for reading SD_VSEL signal" b9c6ad49a942d arm64: dts: imx8x-colibri: Correct SODIMM PAD settings a5e026d5b9487 arm64: dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc 6173c83d4d791 arm64: dts: rockchip: Add #{address,size}-cells to Chromium-based /firmware 2b553fcec1cd8 ARM: dts: rockchip: Add #{address,size}-cells to Chromium-based /firmware d003d9bb44da1 drm/panel: Clean up S6E3HA2 config dependencies and fill help text 76a4c3af3253d drm/gpuvm: take refcount on DRM device 02b001d89157a dt-bindings: vendor-prefixes: Add Displaytech Ltd. a402b3d093815 pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path c599af2eacd66 dts: spacemit: set console baud rate on bpif3 796ff973077c7 lib/vsprintf: Fix to check field_width and precision 53baa6b90f499 crypto: qat - fix heartbeat error injection 928f758f8f214 memory: tegra: Wire up system sleep PM ops 2b2a17af8d8c7 media: v4l2-common: Add YUV24 format info 4534f70aa7042 media: cedrus: Fix failure to clean up hardware on probe failure facbb592e22dd watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure 1917015aa0a1d watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5 d6e8d6b2f8f04 watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH 29fd4f4c73e2b Documentation/rv: Replace stale website link 19eb0ab0bdffb ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint 5435fd3edcb11 wifi: ath9k: fix OOB access from firmware tx status queue ID 7c79be7e63447 pinctrl: mediatek: eint: Drop base from mtk_eint_chip_write_mask() a83e77d1e52c0 soc: xilinx: Shutdown and free rx mailbox channel fbeea02c3564d kconfig: fix potential NULL pointer dereference in conf_askvalue ad445de67359f wifi: rtw89: add bounds check on firmware mac_id in link lookup 01155ded5d4da wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer 7a1ab5fdcae89 wifi: rtw89: Correct data type for scan index to avoid infinite loop 1ef3d1338d94e wifi: rtw88: fix wrong pci_get_drvdata type in AER handlers aefc30e4a829c wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers cc77f0d91e321 driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() 543ed0f61d565 drm/amdkfd: Validate CRIU-restored IDs before idr_alloc 1638e178e4915 dt-bindings: pinctrl: nvidia,tegra234: Add missing required block cc6ef5ee7d88a arm64: tegra: Fix Tegra234 MGBE PTP clock 228db770fb086 wifi: cfg80211: fix grammar in MLO group key error message 123e1cd95ba54 arm64: dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg warning d8367ee271aba arm64: dts: qcom: sc8180x: Fix phy simple_bus_reg warning d72ae2c63b683 arm64: dts: qcom: ipq5424: Fix USB simple_bus_reg warnings 8f8233d544aca arm64: dts: rockchip: Fix gmac0 reset pin for NanoPi R5S 58d0b4c55cdfd arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Cobra 6005cdd9f48fd Documentation: proc: fix section numbering in table of contents d10227f899c90 selftests/bpf: Use local type for bpf_fou_encap in test_tunnel_kern 595710e6838c3 selftests/bpf: Use local type for flow_offload_tuple_rhash in xdp_flowtable 2dfe817167af0 drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro afea00ffcf41c dt-bindings: timer: Remove sifive,fine-ctr-bits property bc4737e55ec41 selftests/bpf: Fix off-by-one in bpf_cpumask_populate related selftest 392c03362c278 libbpf: Report error when a negative kprobe offset is specified 06dc892561f5a drm/radeon: fix memory leak in radeon_ring_restore() on lock failure d9dfa176899d4 drm/radeon: fix integer overflow in radeon_align_pitch() daf5d03ddb8cc drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() 41a60487b5b04 drm/gpuvm: Do not prepare NULL objects 353f26c74660b drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges 626fa93d194db drm/tidss: Drop extra drm_mode_config_reset() call ab487bb0402af drm/rockchip: Test for imported buffers with drm_gem_is_imported() b3ec263a719e0 drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove() 0d60b835bca42 drm/rockchip: dw_dp: Switch to drmm_kzalloc() 68dc52f308a17 accel/amdxdna: Fix leak when pinning ubuf pages 8e644d9a8c8dc clocksource/drivers/sun5i: Handle error returns from devm_reset_control_get_optional_exclusive() d50d320e88b4c openrisc: mm: Fix section mismatch between map_page and __set_fixmap 24186d6f9b07e fbcon: Use correct type for vc_resize() return value 6617df8c24631 fbcon: fix NULL pointer dereference for a console without vc_data 231414253b648 afs: Fix uncancelled rxrpc OOB message handler 8b4d1854295b0 afs: Fix further netns teardown to cancel the preallocation charger cc848a080f7a6 afs: handle CB.InitCallBackState3 requests without a server record 23b3d457d8387 afs: fix NULL pointer dereference in afs_get_tree() b83ecf80e28af afs: Fix netns teardown to cancel the preallocation charger 8cd8cf3052fff rxrpc: Fix double unlock in rxrpc_recvmsg() a89a13aea38ae rxrpc: Fix leak of connection from OOB challenge f9be514984471 rxrpc: Fix the reception of a reply packet before data transmission 8db6a2c95e369 rxrpc: Fix ACKALL packet handling 647e8e69c6ea3 rxrpc: Fix oob challenge leak in cleanup after notification failure 7940e5c535489 rxrpc: Fix rxrpc_rotate_tx_rotate() to check there's something to rotate 0fc5b37faec26 rxrpc: Fix potential infinite loop in rxrpc_recvmsg() 2b69b61057eb0 rxrpc: Fix leak of released call in recvmsg(MSG_PEEK) 0d643a46fdea6 rxrpc: Fix socket notification race 844b8525ce503 rxrpc: Fix UAF in rxgk_issue_challenge() 9ada3931beb37 rxrpc: Don't move a peeked OOB message onto the pending queue d3b642cf95d48 rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc 35a967ff8b24d rxrpc: serialize kernel accept preallocation with socket teardown 2ecd118fb6913 serial: 8250_omap: clear rx_running on zero-length DMA completes c37095c431c39 serial: max310x: implement gpio_chip::get_direction() d354716245192 serial: msm: Disable DMA for kernel console UART 03fd857c33456 dt-bindings: power: imx93: Add MIPI PHY power domain d97a6b4a5a4fb dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties 79982331c1738 media: uvcvideo: Fix sequence number when no EOF 19cb644d0ca59 media: uvcvideo: Relax the constrains for interpolating the hw clock bf58be93c51ba media: uvcvideo: Do not add clock samples with small sof delta aed8111f2392d media: uvcvideo: Fix dev_sof filtering in hw timestamp 0f64f808fb4ee media: uvcvideo: Fix buffer sequence in frame gaps 1a9baac645769 media: uvcvideo: Avoid partial metadata buffers caf800e0cab94 media: uvcvideo: Use hw timestaming if the clock buffer is full 6b2c0cd5f9689 ALSA: hda/realtek: Fix speakers on Legion Pro 7 16ARX8H with codec SSID 17aa:38a7 2f33044aedd7a ALSA: hda: Fix cached processing coefficient verbs ae7f5b05d225c ALSA: hda: conexant: Remove mic bias threshold override 12e43f99242b0 ALSA: hda/realtek: Add quirk for TongFang X6xx45xU e0a71cbf0c190 af_unix: Drop all SCM attributes for SOCKMAP. 9b6c12e1a6be0 iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 a4fb0954f3dc2 iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 62dde71ca2c8c exfat: preserve benign secondary entries during rename and move f3a0dd2d88e83 selftests/bpf: Add tests for stale delta leaking through id reassignment 985b8a0e52c58 selftests/bpf: Add tests for delta tracking when src_reg == dst_reg d75376fbc8563 bpf: Clear delta when clearing reg id for non-{add,sub} ops 19836e8145de9 selftests/bpf: Add a test cases for sync_linked_regs regarding zext propagation 07259d661c9d4 selftests/bpf: Add tests for improved linked register tracking 564e4ce9fb401 selftests: bpf: Add test for multiple syncs from linked register 3659deaf7bf69 media: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work c401492e01c7b crypto: sun4i-ss - Remove insecure and unused rng_alg 088ee46c18d99 nvmet-tcp: Fix potential UAF when ddgst mismatch 2ed3c9d955e8c nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path 588718101e844 iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry c646431865f4b KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU d7860b682da55 crypto: algif_skcipher - force synchronous processing de5a46f3b2c8d tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). e0caf7c3d49c7 smb/server: do not require delete access for non-replacing links bbf04810b2a06 nvme-pci: DMA unmap the correct regions in nvme_free_sgls 40e44eff5116d perf trace: Deal with compiler const checks 30bbd7e8999d1 perf trace: Don't change const char strings bc29e0699b35d perf diff: Constify strchr() return variables 292f32503eda3 perf list: Don't write to const memory d03adc7039c39 perf list: Signal changing const memory is ok 4283a813d7089 perf tp_pmu: Address const-correctness errors in recent glibcs 018533cfe83cf perf units: Constify variables storing the result of strchr() on const tables e7d3f92238a3d perf hwmon_pmu: Constify the variables returning bsearch() on const tables 5bcff7ce5c3b1 perf tools: Use const for variables receiving str{str,r?chr}() returns ee8ab4e8e7029 perf metricgroup: Constify variables storing the result of strchr() on const tables 8bac35a8fd98f perf trace-event: Constify variables storing the result of strchr() on const tables a816153dd8575 perf demangle-java: Constify variables storing the result of strchr() on const tables f8cb25b1d5ed2 perf session: Don't write to memory pointed to a const pointer 5f6d997641de9 perf bpf-event: Constify variables storing the result of strchr() on const tables 3b540ba9606bf perf tools: Switch printf("...%s", strerror(errno)) to printf("...%m") 659a56ba86a96 perf list: Remove unused 'sep' variable 33250aa5cfade perf jitdump: Constify variables storing the result of strchr() on const tables 972c65697792c perf time-utils: Constify variables storing the result of strchr() on const tables 9ae21594ee518 perf strlist: Remove dont_dupstr logic, used only once 110ce8fed0f8e perf strlist: Don't write to const memory Signed-off-by: Bruce Ashfield Signed-off-by: Richard Purdie (cherry picked from commit 0995536b708600a923032c7eb27b3b59d8ceed2f) Signed-off-by: Yoann Congal --- meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend b/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend index 88161841..b37de5f9 100644 --- a/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend +++ b/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend @@ -8,4 +8,4 @@ KMACHINE:genericx86 ?= "common-pc" KMACHINE:genericx86-64 ?= "common-pc-64" KBRANCH:genericarm64 ?= "v6.18/standard/genericarm64" -SRCREV_machine:genericarm64 ?= "08d2d1aaeb84ad2774df573efc336bb7ca773d40" +SRCREV_machine:genericarm64 ?= "358a6b85383d690246c3c1b53ceb711b3b2146dc" From patchwork Wed Sep 9 07:32:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97698 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EF37FC79FAA for ; Wed, 9 Sep 2026 07:32:34 +0000 (UTC) Received: from mail-wr1-f48.google.com (mail-wr1-f48.google.com [209.85.221.48]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6490.1788939147624589548 for ; Wed, 09 Sep 2026 00:32:28 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=qwjwbbLt; spf=pass (domain: smile.fr, ip: 209.85.221.48, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f48.google.com with SMTP id ffacd0b85a97d-48589798dbbso4555800f8f.3 for ; Wed, 09 Sep 2026 00:32:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939146; x=1789543946; darn=lists.yoctoproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=wzUPttZKRpxVuPS0sLeKxdU88VZ950RqKa0oi4xAfsk=; b=qwjwbbLt0IFQsASUe1z78273c4uYuojdmOVgPJIls5wbNEzr38CbhPbiInXGdBpDIV EKBKZhbgKybpZMvnafiJuzK+Fw8+NZEcGsq2LCRhF1oPEQaPBtrGMgDWIWtVyglnhmyJ b6mThuFkd3mAbqKvjiyPaQkkoKPUV80/Mr1Ps= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939146; x=1789543946; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=wzUPttZKRpxVuPS0sLeKxdU88VZ950RqKa0oi4xAfsk=; b=QE21abR9sK0EkSA9yHNXmAgYMklcKrpMWCWWYRNdp1NjCtT5R/EVwySG6QHo8Klw2n 02nV8AMqmtW+4weQY3uJrQOk8D5vxcIHRT4T8rKxXR3Xn+hx/UDbIwYG3m29c3/rnte6 y6Gkb2xjvIj4LJihpYph5I4qCt9n6Be40WiKD5RCc98Xq1w0gfLcRBzO1gF1t/p/ZrOu vEyIEDOWVOhowG7qLa5YUmTsSlYXY3qelm1MIoET7tRUSwjivANBg3jzHoF0/uz1mU/T 76kX2tTgq0rlYECf2hSOaFjLwsKsJmKMzqRMlq6sVpLColHy9wV+MUL2T4sPXTD+Lx0t ZuHg== X-Gm-Message-State: AFuF++lNQal93Aiw2+It5pwX3+6VBgkrx4Y4e7mrLM/mv/8tQwtk+kF4 brYVpXV+9ehT+g9yYTwYtGlWAYTC3hT5Sj9MkAT2okgW6Rfj51gkNb0UjfGswDWgwR1TTCO2+Up pPOwF1yw= X-Gm-Gg: AYBFou1H0HQWIeJa7fFriAT4zsSMpUBYV9uixvNmaLkZom6JShr2OLpMad11z+bTXBq TfJkZV/dXsQEtXkKasKqC+wmO1Oanj1quU0YKTkhmQI0afwdeV+BIMNlqng527OZ7KYC1aTh77s diIOvRdfWeq+fZb4t8VKjpmC/wiVo4BnmsumJqKbHbc26jl6UHLMR6d3+ApRIhE+cgTmYjyS2rA 14VTo9ZxkDvzGYW0i8rZdtBmCqnqsCs0ui/bNvxidfDPSAlEWV8Fc6YWx/Y9sbhZx1403GjGZR6 09oU224qmRLIWe7Dxgdckaincyx0xA3CKySJueFa1D8z38p3V4HjZPCtq2vvL2ML/AWRulgwokR vyCpvyTBzLzRbasimjp90ubJL/NCW20dKxMpkh+YlutJSdSyPKyFrXcUg9vgqOr8Q0jRaVn0CEV w0CE67ECOKSZJ6yhse9GKJVuBL8XtMNIZja2zW6eOmqMaRMeZbajl1FxrXyjVW407t5XNCrnz6g nYHLe0Q/QYAhvW1wE1fsh8+47IOubR5M8YpkZEv3/Zm09eP/Zeb8iefJdRtiTiA83eqnb+rN7s= X-Received: by 2002:a05:6000:2408:b0:482:e4bc:51b3 with SMTP id ffacd0b85a97d-48587091985mr38491641f8f.1.1788939144934; Wed, 09 Sep 2026 00:32:24 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885b1320sm40931457f8f.27.2026.09.09.00.32.24 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:32:24 -0700 (PDT) From: Yoann Congal To: poky@lists.yoctoproject.org Subject: [meta-yocto][wrynose 2/4] yocto-bsps: update to v6.18.43 Date: Wed, 9 Sep 2026 09:32:17 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:32:34 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/poky/message/13962 From: Bruce Ashfield Updating linux-yocto/6.18 to the latest korg -stable release that comprises the following commits: 7b923c78b50d2 Linux 6.18.43 bfe7f9993467b x86/bugs: Make Safe-RET robust against interrupt injection 856a9b51680cb Linux 6.18.42 0f33b1c457c21 KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug 846ed916cfa0c gpu: Fix uninitialized buddy for built-in drivers bcb29986bbba8 net: stmmac: fix dwmac4 transmit performance regression a0d1a11b90a51 net/mlx5e: Fix NULL pointer dereference in ioctl module EEPROM query f282242906c12 usb: gadget: f_tcm: synchronize delayed set_alt with teardown aeebcfa8237c3 rust: device: avoid trailing ; in printing macros e94e820df37d4 rust: allow `suspicious_runtime_symbol_definitions` lint for Rust >= 1.98 6ce0db97fb37a mm/damon/core: disallow overlapping input ranges for damon_set_regions() 4b6f1d6d5d078 mm/damon/core: validate ranges in damon_set_regions() deead12d2e650 i3c: mipi-i3c-hci: Fix handling of shared IRQs during early initialization 811b581fae651 i3c: mipi-i3c-hci: Fix Hot-Join NACK 4fd5b33faf092 pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI c389893bb4037 pmdomain: imx93-blk-ctrl: convert to devm_* only dc8347f263b21 net: ipa: fix SMEM state handle leaks in SMP2P init 4c1e8ccd8655e ata: libata-core: Reject an invalid concurrent positioning ranges count 9466dc5e377f0 bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline() a88c2a70ea0ad bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c c73b8795b45f4 octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF 4467fa514482b octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify ae5ae3d5bfaa6 net: mana: Optimize irq affinity for low vcpu configs 6d13eaa13341a net: mana: Validate the packet length reported by the NIC 7b7bb07efe41b fs/resctrl: Fix use-after-free during unmount d48cf914c739e fs/resctrl: Move RMID initialization to first mount 682d3c2cd20e0 fs/resctrl: Move allocation/free of closid_num_dirty_rmid[] 8c5925f0fa128 x86,fs/resctrl: Rename some L3 specific functions 696c34a1964f4 x86,fs/resctrl: Rename struct rdt_mon_domain and rdt_hw_mon_domain ad4ea2a169a48 fs/resctrl: Split L3 dependent parts out of __mon_event_count() 5b82af744e06c mmc: vub300: fix use-after-free on probe failure 73d397ab54f2a mmc: vub300: rename probe error labels 8ced1d242c34e dm: avoid leaking the caller's thread keyring via the table device file dd73cc92a55d7 cred: add kernel_cred() helper af7a4c2caa7a1 accel/amdxdna: reject command submission on devices without a submit op 62dae36be7a62 ovl: use linked upper dentry in copy-up tmpfile 043acb00e4edd dmaengine: dw-edma-pcie: Reject devices without driver data 277a035cda47d dmaengine: dw-edma: Fix confusing cleanup.h syntax 19360c25135fc mtd: maps: vmu-flash: fix fault in unaligned fixup b8271be34bce1 kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES 3d561f46fa784 mm/sparse-vmemmap: fix vmemmap accounting underflow 8af652cd99460 remoteproc: xlnx: Check remote core state 6fc1919a6f2ed cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size 89b2ae039d188 cxl/pci: Remove CXL VH handling in CONFIG_PCIEAER_CXL conditional blocks from core/pci.c eeab775069920 cxl/pci: Remove unnecessary CXL RCH handling helper functions a64661dccb2eb cxl/pci: Remove unnecessary CXL Endpoint handling helper functions 5d964cb2b7bc8 SUNRPC: Return an error from xdr_buf_to_bvec() on overflow b50b2cb87e7ac SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists a112b91dd6349 sunrpc: allocate a separate bvec array for socket sends 3120f21df3fb0 NFSD: pass nfsd_file to nfsd_iter_read() 6876f767b0490 pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP 7185c5262435b gpu/buddy: bail out of try_harder when alignment cannot be honoured 9634fd144cdc1 drm: drop lib from header search path. 65677f7a20c48 gpu: Move DRM buddy allocator one level up (part two) 09755dc62b026 netfilter: nf_conntrack_sip: validate skb_dst() before accessing it a1a94a00b8844 netfilter: nf_conntrack_sip: remove net variable shadowing d01c913febead netfilter: nft_fib: reject fib expression on the netdev egress hook beeda5bf78577 netfilter: nf_tables: remove register tracking infrastructure 1de827e24d0ad arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers 0d810ff7a6f65 arm64: dts: qcom: correct RBR opp entry 690fb82c4122f VDUSE: avoid leaking information to userspace 7764e9c727d58 vduse: take out allocations from vduse_dev_alloc_coherent db5c554b36d50 vduse: remove unused vaddr parameter of vduse_domain_free_coherent 82e48ad2a1326 vduse: return internal vq group struct as map token b1f38c3ec620a xfs: don't replace the wrong part of the cow fork 3bca70235a706 fuse-uring: fix race between registration and connection abortion 40879c39d6740 audit: fix recursive locking deadlock in audit_dupe_exe() 91b64f0be4163 audit: use 'unsigned int' instead of 'unsigned' eef6914f2b456 audit: widen ino fields to u64 c5772ced573ea landlock: Account all audit data allocations to user space a95b62759f3b9 landlock: Fix formatting 682a0066dde05 drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources 81ea8e8221853 fscrypt: Avoid dynamic allocation in fscrypt_get_devices() 337022d9dfac4 ksmbd: validate ACE size against SID sub-authorities f1eba60db813e ksmbd: bound DACL dedup walk to copied ACEs 847ecd4eb3c11 ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL b6d3cc6a52441 ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl 17e6b8c4319fa net: qrtr: ns: Raise node count limit to 512 7dd26adf7e7d4 ublk: wait on ublk_dev_ready() instead of ub->completion 5a15eaa50f92b drm/xe/uapi: Reject coh_none PAT index for CPU_ADDR_MIRROR 5488d3a69d205 dm-verity: fix buffer overflow in FEC calculation 3f31bde63f9ae dm-verity-fec: replace {MAX,MIN}_RSN with {MIN,MAX}_ROOTS d47281b9a4472 dm-verity-fec: fix reading parity bytes split across blocks (take 3) a556189c06756 dm-verity-fec: fix the size of dm_verity_fec_io::erasures 22400725de070 bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops 15a7cb71a5748 drm/amdgpu: fix check in amdgpu_hmm_invalidate_gfx ab7b40c638e0d drm/amd/pm: fix smu13 power limit range calculation 6405c4e75b3bc drm/amdgpu: fix aperture mapping leak 08fee493e0261 drm/amdgpu: invoke pm_genpd_remove() before freeing genpd 68eab5a64ddbc drm/amdgpu: fix resource leak on ACP reset timeout ffb33d466a68c drm/amdgpu: fix division by zero with invalid uvd dimensions 8c6d84a54823c drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() bd868c077f675 drm/amdgpu/vcn4: avoid rereading IB param length 7eebef042c12d drm/amdgpu/vce: fix integer overflow in image size f7e9eeaccca54 drm/amdgpu/soc24: reset dGPU if suspend got aborted dc3f5da1ba8e2 drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() 76c977d396f12 drm/amdgpu/jpeg: fix jpeg_v5_0_1_is_idle detection 058373af59551 drm/amdgpu/jpeg: fix jpeg_v4_0_3_is_idle detection 042c047e8bc9c drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() 05aea3344c422 drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() f70bd5235d9ef drm/amdgpu/gfx8: drop unecessary BUG_ON() 987bedd3ea89d drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() dfd9bf09fd8fe drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() 7e22de67e545d drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() e75f71143b68b drm/amd/pm: make pp_features read-only when scpm is enabled ada47af5c215e drm/amd/pm: fix amdgpu_pm_info power display units 7b263cf1dd4c0 watchdog: s32g_wdt: remove incorrect options in watchdog_info struct 79370b573e92e vxlan: mdb: Fix source list corruption on a failed replace f60bac115d8dc vsock/virtio: collapse receive queue under memory pressure 5f5a41a48dbf9 tipc: clear sock->sk on the failed-insert path in tipc_sk_create() 234f9ffbd9b2c tcp: challenge ACK for non-exact RST in SYN-RECEIVED fadaff3f66e12 tcp: initialize standalone TCP-AO response padding 4a4f3aa6af205 rtase: Workaround for TX hang caused by hardware packet parsing 6866abf59976d pppoe: reload header pointer after dev_hard_header() 460b9f0609d26 ovpn: hold peer before scheduling keepalive work b08526bf0bbf8 ovpn: fix peer refcount leak in TCP error paths 100a23b1613e9 openvswitch: fix GSO userspace truncation underflow f80ba170d7b3a mctp: serial: handle zero-length frames to prevent rx buffer overflow f20dedce0429b mac802154: llsec: reject frames shorter than the authentication tag 59c1d5463b7bc mac802154: hold an interface reference across the scan worker 472aba2603ca7 ila: reload IPv6 header after pskb_may_pull in checksum adjust 919d0accf2600 ice: use READ_ONCE() to access cached PHC time 5e496f2b615ce ice: reject out-of-range ptype in ice_parser_profile_init 91e0249f3ef62 gve: fix Rx queue stall on alloc failure 18705cace0619 ksmbd: defer destroy_previous_session() until after NTLM authentication 6098b55f6a0cf smb: client: handle STATUS_STOPPED_ON_SYMLINK responses without a symlink target 34f2a2f32af57 rbd: Reset positive result codes to zero in object map update path 63d78b546eefc super: fix emergency thaw deadlock on frozen block devices e4406cbdd915f ice: fix PTP Call Trace during PTP release b3efb4744abf4 ptp: ptp_s390: Add missing facility check 9a8a247f0f17b s390/ptff: Export ptff_function_mask[] 4afc58ea75b96 proc: Fix broken error paths for namespace links 4056cc19071a3 net: pcs: xpcs: fix SGMII state reading 80d977f280b4e net: hip04: fix RX buffer leak on build_skb failure a4dfd46cc8f08 net: gro: fix double aggregation of flush-marked skbs ec6d91a1bf2eb net/x25: fix use-after-free in x25_kill_by_neigh() 40f9a124ebbe0 net/mlx5e: Use sender devcom for MPV master-up 900cd6d8119b7 net/iucv: fix use-after-free of a severed iucv_path 33736ff5e7c97 net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() f8c498585d2a0 geneve: require CAP_NET_ADMIN in the device netns for changelink 5d07b178bef51 net: slip: serialize receive against buffer reallocation 730c7e5fea7f0 vxlan: require CAP_NET_ADMIN in the device netns for changelink a48a889b60f73 phonet: pep: fix use-after-free in pep_get_sb() 03157872da5ed net: stmmac: intel: skip SerDes reconfig when rate is unchanged 1b44a5f584bff iommu/vt-d: Disallow SVA if page walk is not coherent 7037e7bdcd26f iomap: fix out-of-bounds bitmap_set() with zero-length range f139498c5ebdd io_uring/rw: fix missing ERESTARTSYS conversion in read paths 65bf73bee1a4f ftrace: Add global mutex to serialize trace_parser access 95376fe9c145b fscrypt: Add missing superblock check in find_or_insert_direct_key() a019b074903b3 fs: preserve ACL_DONT_CACHE state in forget_cached_acl() c78e38745ff1b fs/super: fix emergency thaw double-unlock of s_umount 89b9121c3b016 binfmt_elf_fdpic: only honour the first PT_INTERP d309f8b52b34c ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP c4d77740eca21 ASoC: fsl: imx-card: Skip sysclk reset for active DAIs in shutdown 1a644db2cf59f amt: fix use-after-free in AMT delayed works 8f5a3abc54ba2 libceph: remove debugfs files before client teardown 3b2f1937f5fce libceph: reject zero bucket types in crush_decode e67e8b694872c libceph: Reject monmaps advertising zero monitors 0060ec912292a libceph: refresh auth->authorizer_buf{,_len} after authorizer update 4716a64b7cc27 libceph: guard missing CRUSH type name lookup 1732d89dfcd74 libceph: Fix multiplication overflow in decode_new_up_state_weight() 4e7ebfaa0d14c libceph: bound get_version reply decode to front len 7d03e08b763fd ceph: fix writeback_count leak in write_folio_nounlock() a7c2dfa610a12 ceph: fix refcount leak in ceph_readdir() a4228b93706fb ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() 3bf0e349cbb4f sctp: close UDP tunnel sockets during netns teardown be6aae9d1b91c sctp: avoid auth_enable sysctl UAF during netns teardown 85aca407c560a sctp: don't free the ASCONF's own transport in DEL-IP processing 3db217a4c2bdc mm/huge_memory: set PG_has_hwpoisoned only after new folio head is established ac7a6f61f56fe mm/kmemleak: fix checksum computation for per-cpu objects f2b2933599241 afs: Fix afs_edit_dir_remove() to get, not find, block 0 d64f6c02495f3 mptcp: pm: userspace: fix use-after-free in get_local_id 6cd3c3d631555 mptcp: only set DATA_FIN when a mapping is present 6c936b5ad557e mptcp: decrement subflows counter on failed passive join 35c4b274d4cc4 Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates" 64ab0964c7db9 arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates 9cd4b1a52eff3 arm64: make huge_ptep_get handled unaligned addresses 9025946adec9a tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() 3b3be8653c594 tracing/probes: Fix potential underflow in LEN_OR_ZERO macro 949ac1aeb37b8 tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args() 6b5098d745811 tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() b6a4575f22925 tracing: Fix union collision of module and refcnt for dynamic events cf5a82bef623b tracing: Fix resource leak on mmiotrace trace_pipe close 8464427e1c177 tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev 1f2e7cd0ff976 tracing: Fix context switch counter truncation 1da310b94504d misc: nsm: pin the module while the device is open 8f068342096b0 misc: nsm: only unlock nsm_dev on post-lock error paths caba30eb8bd32 intel_th: fix MSC output device reference leak 59dd34854202d mei: bus: access mei_device under device_lock on cleanup 5118872357279 selftests: ntsync: correct CONFIG_NTSYNC name b2a3eeb57ba24 serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms 4fae473b856b4 serial: sc16is7xx: implement gpio get_direction() callback 635be8b097f0c uio_hv_generic: Bind to FCopy device by default cf26dd2d84158 comedi: comedi_parport: deal with premature interrupt 9bb71b59e0aa3 x86/boot/compressed: Disable jump tables 4f2db41a09eba firmware: stratix10-svc: fix memory leaks and list corruption bugs 3ff7c1dbf722c rhashtable: clear stale iter->p on table restart d43c5c0c93552 cdrom: fix stack out-of-bounds read in CDROMVOLCTRL 4427a33faabb4 LoongArch: Retrieve CPU package ID from PPTT when available 38b025fcdc45b LoongArch: Move jump_label_init() before parse_early_param() 6ab0abb5a2e0c LoongArch: Fix oops during single-step debugging a94d6726ec868 LoongArch: Fix address space mismatch in kexec command line lookup c404b1f30b252 objtool/rust: add one more `noreturn` Rust function for Rust 1.99.0 8ccfb3b315a0e rust: allow `clippy::unwrap_or_default` globally 6db0c42c87c46 rust: time: fix as_micros_ceil() to round correctly for negative Delta 12be1d75e9b29 rust_binder: only print failure if error has source cc3bbff10b1a7 platform/loongarch: laptop: Explicitly reset bl_powered state when suspend 1cd4e9b7967da binfmt_misc: set have_execfd only once the interpreter is opened 2bc6bf70d4105 exec: fix unsigned loop counter wrap in transfer_args_to_stack() 780b04d09c941 Bluetooth: RFCOMM: Fix session UAF in set_termios a42f5536ea9c0 Bluetooth: hci_sync: Protect UUID list traversal 91eff666c9078 staging: rtl8723bs: fix inverted HT40 secondary channel offset 875479f18835a staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() 0dbaff14fd6a8 wifi: ath11k: fix refcount leak in ath11k_ahb_fw_resources_init() efe9de178e4b9 wifi: brcmfmac: set F2 blocksize to 256 for BCM43752 044fca8f45ba9 wifi: brcmfmac: make release_scratchbuffers idempotent 9cb72f67e1502 wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses 263816e92e8d6 wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses ab4d213393e84 wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses e511e93abd6ee wifi: wilc1000: validate assoc response length before subtracting header 9375a4ea41216 wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper 18965470d41e6 wifi: ath6kl: fix use-after-free in aggr_reset_state() 58c6c8dc2e022 wifi: ath6kl: fix OOB access from firmware ADDBA window size 1395327a96614 ALSA: timer: don't re-enter an instance callback that is still running 426c0ff1c433d ALSA: timer: drain a slave's callback before its master detaches it 3bc4de57fc7d1 ALSA: hda: codecs: hdmi: disable keep-alive before audio format change 6a10025c7fd09 ALSA: seq: close a re-opened queue timer in the destructor 2ec8f95a08fed ALSA: hda/realtek: Fix speakers on Lunnen Ground 14 4091b216d11b3 media: vpif_capture: fix OF node reference imbalance 1349af7f87df5 media: vivid: fix cleanup bugs in vivid_init() 492c97cb50fea media: vivid: check for vb2_is_busy() when toggling caps 26e7a8ac286f3 media: vivid: add vivid_update_reduced_fps() 3780ad3810718 media: vimc: fix reference leak on failed device registration 86ece01fba2d5 media: vidtv: fix reference leak on failed device registration 16ae8c166e787 media: verisilicon: Export only needed pixels formats b88c929188e3c media: vb2: use ssize_t for vb2_read/vb2_write 072a883061a46 media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely cf9732fd6c4f2 media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() 3068ab802fc98 media: v4l2-ctrls: validate HEVC active reference counts 836cfffb2ddbb media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() 7e6521dd747ec media: ti: vpe: unwind v4l2 device registration on probe error 127fc44e83256 media: tegra-video: vi: fix invalid u32 return value in format lookup 118c2f5d1d363 media: synopsys: hdmirx: Fix HPD lane hold time b5184b3f0e9d4 media: sun4i-csi: Return queued buffers on start_streaming() failure 931abe1deb65b media: stm32: dcmi: unregister notifier on probe failure ed342a86bb2f9 media: stm32-dcmipp: Return queued buffers on start_streaming() failure b7936e8cbec1b media: saa7134: Fix a possible memory leak in saa7134_video_init1 a7a141e4e93c8 media: rzg2l-cru: Skip ICnMC configuration when ICnSVC is used 894e83509c669 media: rtl2832_sdr: Return queued buffers on start_streaming() failure 2c71bda6edc63 media: rtl2832: fix use-after-free in rtl2832_remove() 64cb15878b35e media: radio-si476x: Unregister v4l2_device on probe failure a58d01a0ed397 media: qcom: camss: Fix RDI streaming for CSID GEN3 c39a1d9fde82b media: qcom: camss: Fix RDI streaming for CSID GEN2 4e451100b35ee media: qcom: camss: Fix RDI streaming for CSID 680 cb16b79a2be2c media: pwc: Return queued buffers on start_streaming() failure 9afd605dcd96c media: pwc: Drain fill_buf on start_streaming() failure 08ddfd628a2db media: pci: dm1105: Free allocated workqueue 4e077bcb5e1f6 media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding 28ae75dba701d media: nxp: imx8-isi: Fix potential out-of-bounds issues 659a7cea0be80 media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path 4702afbd56f1d media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure 9e61258fbc3cf media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe 181a0aeefd56f media: nuvoton: npcm-video: fix memory leaks in probe and remove 2147acb948a94 media: nuvoton: npcm-video: fix error handling in npcm_video_init() 264b5380c4f8a media: msi2500: Return queued buffers on start_streaming() failure 1391b75bf0119 media: meson: vdec: Fix memory leak in error path of vdec_open 18e3b838e09d7 media: marvell-cam: fix missing pci_disable_device() on remove cf48e9db85652 media: iris: Fix use IRQF_NO_AUTOEN when requesting the IRQ d56044558a757 media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges 00a98fb2a6fb2 media: imx219: Fix maximum frame length in lines 7337c88205ed0 media: i2c: alvium: fix critical pointer access in alvium_ctrl_init c68c4ce72feb6 media: cx23885: add ioremap return check and cleanup f468b7ee5d633 media: cx231xx: fix devres lifetime f24ca8b53fe15 media: chips-media: wave5: Move src_buf Removal to finish_encode 9924cb548ee77 media: cedrus: skip invalid H.264 reference list entries 000e51afb6068 media: cedrus: Fix missing cleanup in error path 73504935e4365 media: cedrus: clean up media device on probe failure 6efe665356ec8 media: cec: seco: unregister adapter on IR probe failure 0459a4304cff8 media: aspeed: fix missing of_reserved_mem_device_release() on probe failure 391fe3e36e59f media: amlogic-c3: Add validations for ae and awb config 73bd277986537 media: airspy: Return queued buffers on start_streaming() failure a096a6aba6011 drm/v3d: Reach the GMP through the hub registers on V3D 7.x a2212fef8e187 drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict 6deaa31720185 drm/vc4: Prevent shader BO mappings from becoming writable b1379f0c42b88 drm/vmwgfx: Validate vmw_surface_metadata::array_size 2b85e19792be4 drm/amd/display: Fix missing DCE check in dm_gpureset_toggle_interrupts() a38f2724eb93a drm/vc4: Shut down BO cache timer before teardown ee44ea4f7e309 drm/amd/display: Fix flip-done timeouts on mode1 reset ba7b6444097a7 drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved fd2de80f28a07 drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge 490ceacd2162d drm/amd/display: Fix backlight max_brightness to match exported range 9c0432044d34b drm/amd/display: Force PWM backlight on Lenovo Legion 5 15ARH05 51ea665c30c42 drm/amd/display: dce100: skip non-DP stream encoders for DP MST 0b9fa4272e24b drm/amd/display: consolidate DCN vblank/flip handling onto vupdate_no_lock 679f23f0a3606 drm/amd/display: set new_stream to NULL after release 123692ebc1ea7 drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) d8dc3a9e815d6 drm/amdgpu: Fix VFCT bus number matching with soft filter 312278b309191 drm/amdgpu: Release VFCT ACPI table reference e64b2f1e826af drm/panthor: return error on truncated firmware 22aa7fb4e7d0b drm/ttm: Account for NULL and handle pages in ttm_pool_backup b2d8b66c67393 drm/virtio: Don't detach GEM from a non-created context a4a1866d50c49 drm/gfx10: Program DB_RING_CONTROL e163c5a0946de drm/amd/pm: fix smu14 power limit range calculation e3bcd3bf7eeca drm/i915/mst: limit DP MST ESI service loop 726f27bca93e6 drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU 37951ce1567cc drm/i915/gem: Do not leak siblings[] on proto context error 1173190412fb9 drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() 5df5a59c32b46 drm/amd/amdgpu: disable ASPM on VI if pcie dpm is disabled 8b2da44446f9d drm/i915/bios: range check LFP Data Block panel_type2 cbec6a57959ab drm/i915: Return NULL on error in active_instance d20b5c139b290 drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() 09da54636bac1 drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() 51fd520871651 drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() 4c09483325360 drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() 3d2ef8d389495 drm/i915/hdcp: check streams[] bounds before overflow 1f876bd8adc79 drm/i915/hdcp: require monotonically increasing seq_num_v 35be0e2c6862a drm/virtio: bound EDID block reads to the response buffer 4ee77643e6194 drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference 8a77ccf9cb992 drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips abce3276c57e3 drm/amdkfd: fix 32-bit overflow in CWSR total size calculation fd1691ec62701 drm/amdkfd: Check bounds on CRIU restore queue type and mqd size 50319efb865f7 drm/amdkfd: Check bounds in allocate_event_notification_slot 14a631dca9df0 drm/amdkfd: Use kvcalloc to allocate arrays 6253bb56bb2eb drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM c45fafa69fe3f drm/imagination: fix error checking of pvr_vm_context_lookup() b983a35dad370 drm/imagination: Fix user array stride in pvr_set_uobj_array() c88fdbf3da26e drm/imagination: Fix double call to drm_sched_entity_fini() c1954c66662de drm/xe: Hold a dma-buf reference for imported BOs 038d0b80ab778 drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds 90a8a938e0cae drm/xe: Return error on non-migratable faults requiring devmem 3e1f909556aa6 drm/radeon: fix r100_copy_blit for large BOs fbb9effc81683 drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() 45db277b2e1e3 drm/i915/gem: Add missing nospec on parallel submit slot 748d425e53c31 drm/displayid: fix Tiled Display Topology ID size 5452eb5c16630 drm/sysfb: Return errno code from drm_sysfb_get_visible_size() 154795885e8f0 drm/sysfb: Avoid possible truncation with calculating visible size 4e109faa9ea2b drm/nouveau: fix reversed error cleanup order in ucopy functions 315d2e5741a81 drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 3fb10ec43c25a drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT 9c2b01508831b drm/amdgpu/gfx9: Fix Ring and IB test fail after mode2 f835eda74cf65 drm/sysfb: Avoid truncating maximum stride 7daefc6d51952 drm/sysfb: Do not page-align visible size of the framebuffer ddba17b3dfa0e drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO d068a2f53afc8 drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older b3a01cda0ae16 drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2) e28420e36542a drm/amdgpu/gfx: fix cleaner shader IB buffer overflow d5c70523cafa2 drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers e2c29d51c0f65 drm/imagination: Fit paired fragment job in the correct CCCB 1e5827839ad0c drm/dp/mst: fix buffer overflows in sideband chunk accumulation 533d9e2bede4a drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers c0384d6872f4d drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() 943fa73ea0efa drm/imagination: Count paired job fence as dependency in prepare_job() 6ab29a8683572 drm/rockchip: analogix_dp: Add missing error check for platform_get_resource() 50cd8a7e98dd2 drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() 86ab4d93b3d47 drm/tidss: Fix missing drm_bridge_add() call 300a2d970a535 drm: renesas: rzg2l_mipi_dsi: Move rzg2l_mipi_dsi_set_display_timing() aa8ad3e0d1fe9 drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay 786d690257ec7 bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() 3a924139cf526 net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets() 391a23c503856 mctp: check register_netdevice_notifier() error in mctp_device_init() 74ecebfbf1555 ptp: netc: explicitly clear TMR_OFF during initialization 16df2d154ec82 rds: tcp: unregister sysctl before tearing down listen socket 1db34097998cc ipv6: Change allocation flags to match rcu_read_lock section requirements 684d4d0bda95a ice: prevent tstamp ring allocation for non-PF VSI types a32604e8d9e2c ice: fix LAG recipe to profile association 3a81345467674 ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV 5d54d603cf3e9 net: ipv6: fix dif and sdif mismatch in raw6_icmp_error e60e6009d3bae octeontx2-pf: tc: fix egress ratelimiting d612754a515cb net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation a7e430349fc5e net/mlx5e: Report zero bandwidth for non-ETS traffic classes cdddc8188db46 net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule 87b39a8c875ca net/mlx5: Fix MCIA register buffer overflow on 32 dword reads 5f2ef3d53d374 net/mlx5: Refactor EEPROM query error handling to return status separately 953d47cfe529a raw: annotate lockless match fields in raw_v4_match() 8150c48fb978e net: qrtr: restrict socket creation to the initial network namespace 0d57d43d7c4c6 hinic: remove unused ethtool RSS user configuration buffers 8fc45a2a7cc24 ppp: annotate data races in ppp_generic 19fe119dfa93f ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup e037a41938c69 octeontx2-vf: set TC flower flag on MCAM entry allocation 15a1c5f2ed2ee net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM 55515c1b1285a net: stmmac: enable the MAC on link up for all supported speeds 1bcb737fb884d net: stmmac: reset residual action in L3L4 filters on delete 370dde2b70e58 net: stmmac: fix l3l4 filter rejecting unsupported offload requests 55d2a8d184e24 net: stmmac: xgmac: fix l4 filter port overwrite on register update 40413da850363 net: stmmac: cores: remove many xxx_SHIFT definitions 4a3eea468a041 net: stmmac: socfpga: Add hardware supported cross-timestamp 01d45e6b2c500 net: stmmac: socfpga: Enable TBS support for Agilex5 dac8c2ab943a2 net: stmmac: socfpga: Agilex5 EMAC platform configuration d67136a931e5f net: stmmac: remove xstats.pcs_* members 9f27c4f0ae35b bpf: tcp: fix double sock release on batch realloc b43bb9ab60035 drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem 1b8fb5a20508b tipc: fix u16 MTU truncation in media and bearer MTU validation c8e4b2a567efb iomap: correct the range of a partial dirty clear 279339aa8bdcf drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create() d18d9b2c29a12 drm/xe/i2c: Allow per domain unique id 4fdb0f162ccdb vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets 18957373920ca sctp: auth: verify auth requirement when auth_chunk is NULL ae0ec759865e0 net: dpaa: fix mode setting b5ded444621b6 net: hsr: fix memory leak on slave unregistration by removing synced VLANs 17bb59682b8e6 net: bridge: vlan: fix vlan range dumps starting with pvid 0a347ca1d6a2e amt: make the head writable before rewriting the L2 header ca0e8b661957f amt: re-read skb header pointers after every pull 9ec22c8113d8c ovl: check access to copy_file_range source with src mounter creds 31f5f7c959c3e ovl: port ovl_copyfile() to cred guard cde234a493f6d ovl: add override_creds cleanup guard extension for overlayfs 35f0b504394e0 cred: add scoped_with_kernel_creds() 3139b806923b1 drm/panel: s6e3ha8: fix unmet dependency on DRM_DISPLAY_HELPER 790da254031cc ovl: fix trusted xattr escape prefix matching 00ebbf030d8c4 wifi: brcmfmac: fix 802.1X-SHA256 call trace warning d5628f39fccc1 wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() 95b0cf02731c7 wifi: mt76: mt7925: fix crash in reset link replay d14238523ca4c wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() 313343ab8cab7 wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv() c058786b09cfa wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() 871549814eb4d wifi: mt76: mt7915: guard HE capability lookups f1ee53e08fdd2 wifi: mt76: mt7925: guard link STA in decap offload cc4d2f8b984c2 ppp: annotate concurrent dev->stats accesses b52ff80948d1c ppp: don't store tx skb in the fastpath cb9d3e0b55699 ppp: enable TX scatter-gather e740e90ca8e7f tipc: fix infinite loop in __tipc_nl_compat_dumpit d536bf205c71f nexthop: initialize extack in nh_res_bucket_migrate() 961e9b1e33445 gtp: check skb_pull_data() return in gtp1u_send_echo_resp() 023c5e0d0294a selftests: drv-net: increase timeout fa065685c8a91 selftests: ovpn: increase timeout e2b3d426c7ee5 selftests: ovpn: add IPV6 and VETH configs 69eab5c4d9aa6 selftests: openvswitch: add config file 340c389fd3d5d selftests: af_unix: add USER_NS config fbd91910c5025 tls: device: push pending open record on splice EOF a8bd8c109da5a net: mctp i3c: clean up notifier and buses if driver register fails 1a10fe1aa9c01 sctp: validate stream count in sctp_process_strreset_inreq() c984a4184f810 pds_core: check for workqueue allocation failure cf0ed2ba202f5 pds_core: fix auxiliary device add/del races 0e87fe52b560f pds_core: order completion reads after the ownership check 3a831f40e88d3 pds_core: yield the CPU while waiting for the adminq to drain 9e0f80fac50ab pds_core: fix use-after-free on workqueue during remove 19ef775c91c6b pds_core: fix deadlock between reset thread and remove 11092d79eb2b7 sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid 2d34421bfa261 net: txgbe: fix FDIR filter leak on remove 245bfe72a5ad4 net: Call net_enable_timestamp() before failure in sk_clone(). 4122792923312 soreuseport: Clear sk_reuseport_cb before failure in sk_clone(). f97d199287689 amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN e695cb9becbbb arm64: Correct value returned by ESR_ELx_FSC_ADDRSZ_nL() f5b8b8ccf9a4a pds_core: reject component parameter in legacy firmware update b5fcd1da05622 wifi: mac80211: recalculate TIM when a station enters power save d06fea9b85f03 iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() e5ebe8544df1a iommu/amd: Bound the early ACPI HID map d21464d93f8ba wifi: mwifiex: bound uAP association event IEs to the event buffer a0980682d84d2 vhost-net: fix TX stall when vhost owns virtio-net header 59cbe6cfa0fa2 wan: wanxl: Only reset hardware after BAR mapping 3b1d4fc3b73ea nfp: Check resource mutex allocation 0f7eaeb950adb wifi: mac80211: tear down new links on vif update error path d053eb7e09e10 iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() 76fc5604308a1 net: airoha: Fix DMA direction for NPU mailbox buffer f112df0744e2d dpaa2-eth: put MAC endpoint device on disconnect 46e3bed4b0710 net: airoha: Fix potential use-after-free in airoha_ppe_deinit() 26ac2d3602347 dpaa2-switch: put MAC endpoint device on disconnect c9165e199f569 rxrpc: fix io_thread race in rxrpc_wake_up_io_thread() b78547914bee5 gtp: parse extension headers before reading inner protocol 9591042533140 rds: drop incoming messages that cross network namespace boundaries 992dce02bdabb bonding: fix devconf_all NULL dereference when IPv6 is disabled 1bc55c29cd858 net/packet: avoid fanout hook re-registration after unregister 9f4f75df77c89 netlink: specs: rt-link: convert bridge port flag attributes to u8 4264dbc84ca0a net: phy: marvell: fix return code 8881daaafadbe Bluetooth: btusb: validate Realtek vendor event length 9d208de7a8f64 regulator: mt6358: use regmap helper to read fixed LDO calibration 538d862cc0dbd hwmon: occ: validate poll response sensor blocks 2f0f661998941 ovpn: use monotonic clock for peer keepalive timeouts 5b96227c0e8b2 ovpn: fix use after free in unlock_ovpn() 47cd68e050a63 selftests/net: ovpn: fix getaddrinfo memory leak in ovpn_parse_remote() c5bf6b39be235 ovpn: avoid putting unrelated P2P peer on socket release 2fdd6d196c656 smb: client: validate DFS referral PathConsumed d6959dd79088a hwmon: (asus-ec-sensors) add missed handle for ENOMEM dd6f730be95b5 hwmon: (asus-ec-sensors) fix EC read intervals 22e449c1dd543 hwmon: (asus-ec-sensors) fix looping over banks while reading from EC d5913f97b5b60 drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook() d0a57f19fe286 usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect 2d5dec517b539 wifi: iwlwifi: mvm: fix read in wake packet notification handler eae7fdf7d4469 wifi: iwlwifi: validate payload length in iwl_pnvm_complete_fn 70a6de303c9b3 wifi: iwlwifi: fix pointer arithmetic in iwl_add_mcc_to_tas_block_list a076b0c457c71 wifi: iwlwifi: mvm: validate SAR GEO response payload size cdf895bfd8035 ASoC: cs35l56: Use complete_all() to signal init_completion 3c26e8bb14cc6 ASoC: cs35l56: Fix potential probe() deadlock 1ddb3e0e502a1 ASoC: cs35l56: Don't use devres to unregister component 9153fa1ee99bf ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI 08433c71f1598 ALSA: hda: cs35l41: validate and free ACPI mute object eca9fcf9f5d89 ASoC: sun4i-codec: Set quirks.playback_only for H616 codec 41ae2b7d37c3d ASoC: tas2781: bound firmware description string parsing 797dc567146c7 btrfs: free mapping node on duplicate reloc root insert 9304713b70e7e btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps 39f196f64bd38 btrfs: fix u32 to s64 type conversion in dirty_metadata_bytes accounting f49ff44831d52 btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8 4503829843353 wifi: carl9170: fix buffer overflow in rx_stream failover path fab6ff91d5b8c wifi: carl9170: fix OOB read from off-by-two in TX status handler 9aee949c68dc6 wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read 33b5342d20806 wifi: ath6kl: fix OOB read from firmware IE lengths in connect event eb636fbc44314 wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler 0177e578d7a88 firewire: net: Fix fragmented datagram reassembly 51516fda914cc wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET 9a9b0ea72d8b9 wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET a154ca3c441a6 wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() 8681e5addf717 watchdog: airoha: Prevent division by zero when clock frequency is zero 7d1658b066de3 watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() 305c23993e43d hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop 205cff797a947 hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop f36e12cc8cfe9 hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop 56d2deb644837 hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop ec477af3a7e8d hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop e5394605f9a98 wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin 48a69cedde738 wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request 593072aae7fc8 selftests/bpf: Keep verifier_map_ptr exercising ops pointer access 938bcf99f53e8 selftests/bpf: Adjust verifier_map_ptr for the map's excl field fe7892d46921e usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits 958624d638603 Revert "drm/amd/display: Add missing kdoc for ALLM parameters" 03eb7a8099474 RISC-V: KVM: Serialize virtual interrupt pending state updates 731acda5ba777 wifi: mwifiex: fix freeze for 60 seconds caused by request_firmware 0905b3ce1deb7 usb: typec: ucsi: Add duplicate detection to nvidia registration path fe8cde072293c usb: typec: ucsi: Detect and skip duplicate altmodes from buggy firmware 67d2626827e3c USB: serial: option: add TDTECH MT5710-CN 601f75671b8fb USB: serial: keyspan_pda: fix data loss on receive throttling cbe00048b69d6 USB: serial: io_edgeport: cap received transmit credits c1611c6744e3a USB: serial: ftdi_sio: add support for E+H FXA291 1f03658f3e9b2 usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer dcf3e2f164435 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown 40c706a0224bd usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() 12b3edca90d4d USB: gadget: fsl-udc: fix dev_printk() device 66956a5a4258c USB: gadget: fsl-udc: fix device name leak on probe failure e5ecfb7767526 USB: gadget: snps-udc: fix device name leak on probe failure 4cde0b38cc0cb usb: gadget: printer: fix infinite loop in printer_read() f45089eaad0a0 usb: gadget: f_midi: cancel pending IN work before freeing the midi object e239ea91b4818 usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback ace1a0adfc786 usb: chipidea: fix usage_count leak when autosuspend_delay is negative 8eca14198c202 USB: storage: add NO_ATA_1X quirk for Longmai USB Key 0950ac52426b0 usb: musb: omap2430: Do not put borrowed of_node in probe 7714fb896ed30 usb: core: port: Deattach Type-C connector on component unbind fb1b50ab69921 wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() 217774e143d7b usb: core: sysfs: add lock to bos_descriptors_read() 5f6e7b32bd1fb mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n a8d20ba0ab518 sctp: fix auth_hmacs array size in struct sctp_cookie fed1b1ddab41a net/sched: act_tunnel_key: Defer dst_release to RCU callback 51c2fcc4cd2e4 dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() e666af5dcc905 tcp: fix TIME_WAIT socket reference leak on PSP policy failure 6875ee2bef48f accel/amdxdna: Fix use-after-free of mm_struct in job scheduler f6b522033bc83 drm/i915/selftests: Fix GT PM sort comparators c23abdb922c39 drm/i915/wm: clear the plane ddb_y entries on plane disable f0e337e7db67c ksmbd: validate compound request size before reading StructureSize2 6ecb252efa0b4 ksmbd: pin conn during async oplock break notification 5e5f298d0af64 drm/xe/wopcm: fix WOPCM size for LNL+ 35ba43b541117 drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves c1b19d8556265 drm/xe/vf: Shadow buffer management for CCS read/write operations bf293b5bcff41 drm/xe/sa: Shadow buffer support in the sub-allocator pool 65129a03a8018 drm/xe: Allow the caller to pass guc_buf_cache size cfb66ad4aa8e5 can: j1939: fix lockless local-destination check 3f398d45f3c75 riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus() 1d9a2f01b3c4e s390/checksum: Fix csum_partial() without vector facility 5b06cf93341fe drm/panthor: Check debugfs GEM lock initialization 250474c69bc3f bpf, sockmap: Reject unhashed UDP sockets on sockmap update c3e61df6fabca powerpc/vtime: Initialize starttime at boot for native accounting 5c3a1cede86fd powerpc/time: Prepare to stop elapsing in dynticks-idle c1bbd0a6906b8 powerpc/85xx: Add fsl,ifc to common device ids 00ba4bf879824 can: raw: add locking for raw flags bitfield 479425744b219 drm/i915/gt: use correct selftest config symbol 7e08ab7a061b1 smb/client: handle overlapping allocated ranges in fallocate cefb44c367b2b Bluetooth: hci_qca: Clear memdump state on invalid dump size d5b3b484b62bb Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds ca58ad287bfc5 Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync 83b7e67698d0b Bluetooth: hci_sync: extend conn_hash lookup critical sections 57059ff14d81d Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update a087ed960fce5 Bluetooth: qca: fix NVM tag length underflow in TLV parser f4e23e661a259 ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC b133f007ba02c accel/ivpu: Fix wrong register read in LNL failure diagnostics 1842d45f461a7 ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning d28920db56960 ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts 678d874e6ae11 ata: sata_dwc_460ex: use platform_get_irq() daa80b422ed92 ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered c7a1509123720 scsi: core: wake eh reliably when using scsi_schedule_eh 2c77ed279c4bb udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf() c75a950e77356 net/iucv: take a reference on the socket found in afiucv_hs_rcv() cb8be318b4432 ipv4: fib: free fib_alias with kfree_rcu() on insert error path c9574b8a8edeb ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF 88f87cb4b52ed cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq 640a33e77f91b firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context fb343716fad46 ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup 7f2cb99eaf53c ASoC: cs42l43: Correct report for forced microphone jack 9f393d8160435 ASoC: amd: ps: replace bitwise OR with logical OR in IRQ return check 3b2d32f528152 ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() f33ad19e3e3d6 ASoC: amd: ps: disable MSI on resume in ACP PCI driver 4801f6690f984 ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop b39b08e6bee81 firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation cf5708c9d78c9 firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit() 11ac7a5e75f51 wifi: cfg80211: bound element ID read when checking non-inheritance 5c342437ea44b wifi: brcmfmac: initialize SDIO data work before cleanup a424985c3ef2a wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock 44eda4a8d1dcd wifi: mac80211: avoid non-S1G AID fallback for S1G assoc fbaa8c31ef940 wifi: cfg80211: reject unsupported PMSR FTM location requests cfbda103aeae6 wifi: cfg80211: validate PMSR FTM preamble range 0caf6416bfbb3 wifi: cfg80211: validate PMSR measurement type data 0b6efde0ed970 wifi: nl80211: constrain MBSSID TX link ID range f8c547e543e12 wifi: nl80211: validate nested MBSSID IE blobs f649dc9c5e657 wifi: cfg80211: derive S1G beacon TSF from S1G fields fb052a6e2fa86 wifi: nl80211: free RNR data on MBSSID mismatch 133684982dd0c wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock d38f5d868a0a4 wifi: p54: validate RX frame length in p54_rx_eeprom_readback() 2aa1789880fa5 wifi: mac80211: defer link RX stats percpu free to RCU 6cda91bbb8dc3 wifi: libertas: fix memory leak in helper_firmware_cb() 5baaa1042f71d wifi: mac80211: fix fils_discovery double free on alloc failure d62b55b7c7dc6 wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure 6dc76371a9a36 wifi: mac80211_hwsim: clamp virtio RX length before skb_put e67dc2b8d5ac4 wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan() f442e581a8893 wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() 9293574ac208d wifi: cfg80211: cancel sched scan results work on unregister 7acc5ed2f3360 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert ff636d7b7cba6 xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() d8aaf06b29f5a xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() 9845a35986a65 xfrm: clear mode callbacks after failed mode setup 9e632a70f2044 RDMA/irdma: Prevent overflows in memory contiguity checks 124382a2a9756 selftests/alsa: Fix memory leak in find_controls error path f98ae09c727dc mtd: fix double free and WARN_ON in add_mtd_device() error paths fcc9d50022bcd RDMA/siw: publish QP after initialization e221dde026af2 RDMA/hns: Fix potential integer overflow in mhop hem cleanup d842ef03d9145 RDMA/mana_ib: initialize err for empty send WR lists 14e519f93a48c RDMA/erdma: initialize ret for empty receive WR lists ec675b4cdfd37 RDMA/irdma: Prevent user-triggered null deref on QP create 1cd56258fe1a0 RDMA/irdma: Remove redundant legacy_mode checks ca1c29f05274b RDMA/irdma: Prevent rereg_mr for non-mem regions dbb945b80a3a4 RDMA/umem: Add pinned revocable dmabuf import interface c4ef25de94d73 RDMA/cma: Fix hardware address comparison length in netevent callback d7fc6f351c478 xfrm: reject optional IPTFS templates in outbound policies 2907e9d0f05b5 sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx() 57acd51928333 sched/ext: Avoid null ptr traversal when ->put_prev_task() is called with NULL next 996c5c19d5b5a firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() 8edc925251780 btrfs: fallback to transaction csum tree on a commit root csum miss a84ca16ce07e7 btrfs: use bool type for btrfs_path members used as booleans 60a23d4ea169e btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() 5e1b2ca6b3493 btrfs: reject free space cache with more entries than pages 0ac9c7d9ccfd7 mtd: nand: mtk-ecc: stop on ECC idle timeouts fdb53a9b26071 mtd: mtdswap: remove debugfs stats file on teardown 98d2d468b4faa IB/mad: Drop unmatched RMPP responses before reassembly 59114e0ff6e3a firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits 33e1b0d25ca0d xfrm: fix stale skb->prev after async crypto steals a GSO segment eae16fbc7ce20 xfrm: propagate -EINPROGRESS from validate_xmit_xfrm() 23bbb9eafec7a net: plumb drop reasons to __dev_queue_xmit() 4cc4d6fb08e75 net: dropreason: add SKB_DROP_REASON_RECURSION_LIMIT 4c22b4e3ff502 arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234 0b9858484d096 arm64: tegra: Remove fallback compatible for GPCDMA 903f2edc04770 fuse: fix writeback array overflow when max_pages is one afe9cda0862aa Input: ims-pcu - fix logic error in packet reset d03a740e087de Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() 6cbed4be9a6ca xprtrdma: Clear receive-side ownership pointers on release 0892b427c4b8b crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin 5f4de3c717d34 gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings ec9f66c91bffd dmaengine: sh: rz-dmac: Move interrupt request after everything is set up eca8b44d51fc6 can: bcm: track a single source interface for ANYDEV timeout/throttle ops 136de17f38630 can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() 6be3e1fedf03e can: bcm: fix stale rx/tx ops after device removal b024c21c9066f can: bcm: add missing device refcount for CAN filter removal deb6a697cce3f can: bcm: validate frame length in bcm_rx_setup() for RTR replies bd46f55dec608 can: bcm: extend bcm_tx_lock usage for data and timer updates 8104bcdb2612f can: bcm: fix CAN frame rx/tx statistics 19b1994069dd2 can: bcm: add locking when updating filter and timer values ec9daa8fd1b6f KVM: x86/mmu: Fix use-after-free on vendor module reload 8001d2ce9d9bd KVM: nVMX: Hide shadow VMCS right after VMCLEAR dd50ad7935d57 KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN f3477a6a4164f KVM: x86: Check for invalid/obsolete root *after* making MMU pages available 865dfe76c150b seqlock: Allow UBSAN_ALIGNMENT to fail optimizing 3958b1aeef43b seqlock: Allow KASAN to fail optimizing ec46baf830825 seqlock: Cure some more scoped_seqlock() optimization fails 8e39ed92d7c5c fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race 89890a5fcefad drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker f6410d18c1e2d netfilter: nf_tables: revert commit_mutex usage in reset path 0c8a9022f4c56 netfilter: nft_quota: use atomic64_xchg for reset cd968dcdec6ae netfilter: nft_counter: serialize reset with spinlock 55904f1a4689a selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs ce01a4e5cfac7 bpf: Fix ld_{abs,ind} failure path analysis in subprogs bffc0b27e457c platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug Signed-off-by: Bruce Ashfield Signed-off-by: Richard Purdie (cherry picked from commit 0afedb9b1195525861f9140d6f33e9cd4118b199) Signed-off-by: Yoann Congal --- meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend b/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend index b37de5f9..dec64c20 100644 --- a/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend +++ b/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend @@ -8,4 +8,4 @@ KMACHINE:genericx86 ?= "common-pc" KMACHINE:genericx86-64 ?= "common-pc-64" KBRANCH:genericarm64 ?= "v6.18/standard/genericarm64" -SRCREV_machine:genericarm64 ?= "358a6b85383d690246c3c1b53ceb711b3b2146dc" +SRCREV_machine:genericarm64 ?= "19b324105e674270fa4f09ec74c6229a3901893e" From patchwork Wed Sep 9 07:32:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97700 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3113AC79FB5 for ; Wed, 9 Sep 2026 07:32:35 +0000 (UTC) Received: from mail-wr1-f54.google.com (mail-wr1-f54.google.com [209.85.221.54]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6491.1788939147996486548 for ; Wed, 09 Sep 2026 00:32:28 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ZGS1Oy4X; spf=pass (domain: smile.fr, ip: 209.85.221.54, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f54.google.com with SMTP id ffacd0b85a97d-47de0093c42so5143027f8f.3 for ; Wed, 09 Sep 2026 00:32:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939146; x=1789543946; darn=lists.yoctoproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=A46aV2vhDv6X7NjpdetB8tkDbuYVh6SvSMt3x7YoIls=; b=ZGS1Oy4X2fWuRIa3DLBqHM9YbRJUNRoITDgOmC3+tmRbYvskd+mVnwXsb5ThrQysuY zplVFpAdpc8uo8PyJREo77EVduS8x+ePSvG2MqnDbIuipf5Kwq9t45ANcdSWIrdWeEBZ 9w5g+uo6KfpeCQ8o3DeyjpJvs2gzy0mILAbFY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939146; x=1789543946; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=A46aV2vhDv6X7NjpdetB8tkDbuYVh6SvSMt3x7YoIls=; b=AUNTocKnRo3DGfT59LsA7eNCsvR7tavUYrNZv7v13828NG1t2YAVSSjtWx24ErCHQf NK4eK3Ekpkhwxih4L24+/gmtW0gy0RTJMqlc26tqw27/luwF66vWdr4gITlSQax9ol0e FC4TlpsLK1CwdUJ//VlvVLA0OgLdgcJImLVVSzoozkgrn1+Rdd7hyMNq5WFIkVa47+L4 1MuULzRK1VHWAiQ2oyGbTPNAkiYycW7jPdnE+VAZXRQqUQWoc8AhsipdfaSeLb365Ei7 BpakdigO1k+O4JwGPzng1dNoe5HvQNvJgw4QApDdL/LX+Xm714mWPQ4KfkxgjYSDTp4l 9XMw== X-Gm-Message-State: AFuF++mXnYxNqtfcfCoBvqVU/2EbtLV5uSM9CYmzx2E42QFFl1/0T8gZ kF5WjzvqqWJzB2W+tPFruWa30Tmobfmo4169z7Jtzg3E/XWZezg7e5z+w1FGmGCeQaHhJdHGGhq cLEIrj8g= X-Gm-Gg: AYBFou1KgwfY7rf6PaIg6OfwZ9yYz2UUXDNmgXk+rggiR2gKeIGacn+dn5oRraZL8GD XXMjuEorVHbEupNEA2BeWB/Xy6kJdhBmbVYh6rCqlvGZAWYn/3ZIeq6Hayuw7Yt0xCHyhSt40eD 7EZDF8IPaRZSfUznsUSzVCD94E1ow9rVIn5gfp+DAftLmZ/s8/ZVH3KvpQQ4A9KVpBQC4joqoSc j/SXx997bytlt5fQm7NpNikk2OL0jxUBGDyoRideKp2y1sHLBd3wj6vKd0bBfBnPMd/TRzYOiLc 4RHOpnb66ysAXG3f5eBfGO/E00L9TSvK8kxEu+YJkgOjh3ypYVfoqdQnOJjEtsynwoE7VpZ1yRI px9cy/7/EauN0+i3dHlXaz5+MpTo2GlsrGvk5fTsvR+axt3GhVt2f/q6FIHJ8oOeJMwTP/FUsGt kEuIfqikHosdMt1JHtHgYyTgOxxQpY1XsyuV4eBAG0CN7MJflm+jCY9A+iPa8j6VldsOq0Kkj/T QIeTvu5qgErVmYGbezKB/yVQzlarDdG7Bx9Q+b97KG1X5q+nyNENiOnctlDzdKEZm3rgvYdKdY4 X-Received: by 2002:a05:6000:240e:b0:485:8f9c:2879 with SMTP id ffacd0b85a97d-4858f9c29e1mr26419729f8f.6.1788939145722; Wed, 09 Sep 2026 00:32:25 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885b1320sm40931457f8f.27.2026.09.09.00.32.25 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:32:25 -0700 (PDT) From: Yoann Congal To: poky@lists.yoctoproject.org Subject: [meta-yocto][wrynose 3/4] linux-yocto/6.18: update to v6.18.44 Date: Wed, 9 Sep 2026 09:32:18 +0200 Message-ID: <71b2c1b656b5f78d5f9ab5a33ba34c9db3a947ac.1788939085.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:32:35 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/poky/message/13963 From: Bruce Ashfield Updating linux-yocto/6.18 to the latest korg -stable release that comprises the following commits: 1efe5d048a391 Linux 6.18.44 358b5dcf1fd7f drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info e7731507270c2 drm/fb-helper: Fix a locking bug in an error path 7bc7af179916b usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path 10be509fa8fd9 can: isotp: fix timer drain order, wakeup handling and tx_gen ordering 0902f06a6c0bb can: use skb hash instead of private variable in headroom 157b1e3384d7d drm/xe/pt: Reset current_op in xe_pt_update_ops_init() b1a71151317c4 drm/xe: Add page reclamation info to device info 6107b64cfccef drm/xe: Stub out new pagefault layer 184de3d31f728 drm/xe: Use SVM range helpers in PT layer df1582c0a101e drm/i915/vrr: require valid min/max vfreq for VRR 894d4a7395662 drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() 21976fe525849 drm/xe: Wait on external BO kernel fences in exec IOCTL b8ad916ba4e18 drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse] d256dac008d1d drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC 8fa8b0a463729 drm/xe/vm: Prevent binding of purged buffer objects 1ba553ee0b521 drm/xe/bo: Add purgeable bo state tracking and field madv to xe_bo 0015b054b06d3 drm/xe: add xe_migrate_resolve wrapper and is_vram_resolve support 005b9b4431606 drm/xe/pat: Add helper to query compression enable status 3cb42a973f889 drm/amd/display: Exit idle optimizations before programming dbbe08d73b8bc drm/amd/display: check GRPH_FLIP status before sending event b485bfb455551 drm/xe/guc: Fix buffer overflow in steered register list allocation 30b2d0843a410 drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions e06c39cc1c48d drm/amdgpu: Fix context pstate override handling 4d49ca777cf1a drm/tegra: fbdev: Remove offset into framebuffer memory 3f58077457985 drm/fb-helper: Allocate and release fb_info in single place 165613191ad9d userfaultfd: prevent registration of special VMAs 02d378828af8b wifi: brcmfmac: drain bus_reset work on device removal d6f322d68abfd media: uapi: rkisp: Correct name version enum 5c6d5d2484cab media: qcom: camss: Fix RDI streaming for CSID 340 f730ee0ef8fac media: qcom: camss: csid-340: Fix unused variables 276420a86e75f media: chips-media: wave5: Support CBP profile 3f7b3728dd901 usb: typec: ucsi: Fix race condition and ordering in port unregistration 58d9caa64f9c6 usb: typec: ucsi: split connector lock classes 2bf24a7e190aa net/handshake: Drain pending requests at net namespace exit 6e7b52bd13948 net/handshake: Close the submit-side sock_hold race 68eba6519cbd6 net/handshake: hand off the pinned file reference to accept_doit b913801ad9b9a net/handshake: Take a long-lived file reference at submit 5ddfc47e1228d net/handshake: Fix null-ptr-deref in handshake_complete() 97e745b4ea055 net/handshake: convert handshake_nl_accept_doit() to FD_PREPARE() f00dd592abe77 file: ensure cleanup 10827847c40c1 file: add FD_{ADD,PREPARE}() 10065fb891651 mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios be11b4bf498a3 fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes 2b9a07002c2f2 mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() fc0c76b0450f2 drm/xe/rtp: Ensure locking/ref counting for OA whitelists 9783d8662b565 drm/xe/oa: (De-)whitelist OA registers on OA stream open/release f5966d9006623 drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt d43abc858f082 drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs c2cfee9bf8d46 drm/xe/rtp: Save OA nonpriv registers to register save/restore lists 4bb92418e749f drm/xe/rtp: Generalize whitelist_apply_to_hwe cc716d3ac560f drm/xe/rtp: Keep track of non-OA nonpriv slots f73e97080debd drm/xe/rtp: Maintain OA whitelists separately 7982678fa21ed drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists 542d3b9fa8ec6 drm/xe/rtp: Refactor OAG MMIO trigger register whitelisting 2b70bebc70948 HID: logitech-dj: Fix maxfield check in DJ short report validation 6be3dbe45b287 spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX 042ca38779554 drm/vmwgfx: validate external BO copy bounds for both stride paths cfd163169af3b drm/vmwgfx: use check_add_overflow for shader size+offset bound 1eb4f796695be drm/vmwgfx: enforce cursor size limits for MOB cursors 96efee36453b6 drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure 7e40e6120fb23 drm/vmwgfx: bound DMA command body size against suffix pointer dc0be7662b7b0 drm/vmwgfx: validate DRAW_PRIMITIVES header size before division a8434b145b1e4 drm/vmwgfx: drop dma_buf reference on foreign-fd prime import b79e82ea18236 drm/vmwgfx: take fman->lock around fence list mutation in fifo_down 10460699c312e drm/vmwgfx: clamp dirty-page range with min, not max e479240a1e076 drm/vmwgfx: reject DX_BIND_QUERY without a DX context 282f261cb035e drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size 6a52f48157fa7 drm/amdkfd: hold event_mutex while checkpointing CRIU events 6189ceca5ce75 drm/amdkfd: Handle invalid event type in CRIU event restore 6dc0b4b39ed4f drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment 5f0f2ddeac738 drm/amdkfd: fix QID bit leak in pqm_create_queue() 9e52212aff8ed drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE 02647d9834073 drm/amd/display: use proper context for logging 3c2ae9509717c drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames 1860818feb4db drm/amd/pm: fix torn gpu metrics reads 45ba7f091abf4 drm/amdgpu: cap GTT size to physical RAM on APUs d330ac90d85f3 drm/amdgpu: restore UMD profile pstate after runtime resume 18d21c9d04b00 drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini 0f1ff05c58e17 drm/mediatek: ovl_adaptor: balance component registrations c835f2b0b7167 drm/panthor: validate firmware interface structure sizes 2a761b9be5863 drm/panthor: reject firmware sections with oversized data da898bb6faf32 drm/bridge: display-connector: Fix I2C adapter resource leak 57667eb7548fa drm/vc4: Zero the tile state data array before each BIN job 6cd5acf6f87c0 drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size 58d2bb394e884 drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs e8b797940536c can: ctucanfd: mark error-active controller status valid 7d1619f56a75a can: ctucanfd: handle bus error interrupts 46fc5aecde5cd can: ctucanfd: unmap BAR0 using base address cae2880f8ffae can: ctucanfd: use self-test mode for PRESUME_ACK aa5e790bf185e can: ctucanfd: add missing MODULE_DEVICE_TABLE() 2427ef427bdd7 can: peak_usb: validate uCAN receive record lengths 92d0de80ca222 can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error 1acab790b7cec can: peak_usb: add bounds check for USB channel index 2ee477e541a6d can: softing: fw_parse(): validate firmware record spans 185cb1fa38142 can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents 2e90b2b406077 can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() 54258ea8d61fc can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking 8604a3b81b9d0 can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer 996eb21acdc9c can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure c311f17c261fd can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure 0b23144c59c12 can: ems_usb: validate CPC message lengths 26cf99713a96f can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured affd62f5719a7 i2c: imx: Cancel hrtimer before clearing slave pointer 12a4f0950a158 i2c: imx: Fix slave registration race and error handling 7a5db225ab5a6 i2c: imx: mark I2C adapter when hardware is powered down 82233ff0e36df i2c: iproc: reset bus after timeout if START_BUSY is stuck 19b783335d62e i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock 40dd717445998 i2c: qcom-cci: drop custom suspend/resume and rely on runtime PM helpers d9b5419df0654 i2c: spacemit: request IRQ after controller initialization 6a5cc2b4e6faf ice: fix memory leak in ice_lbtest_prepare_rings() 326c89ea2685a ice: fix VF interrupts cleanup 7e8789f5b5d8a ice: wait for reset completion in ice_resume() e0ba8eaef2a0d net: openvswitch: fix skb leak on flow key update failure during ct 9c7246cc509fd net: openvswitch: fix skb leak on flow key update failure during recirculation 90623c9499627 net: openvswitch: fix potential UAF on meter attach failure 74b30e7ef4618 phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB 79a312664118f phy: zynqmp: use read-modify-write for SERDES scrambler bypass 4211450f0fecb phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask 013a4484f061a s390/zcrypt: Validate length for CCA ECC private key requests ad93a1f1a4565 s390/zcrypt: Validate length for CCA AES cipher key requests fbb0410986e8a s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() a57fd7fcdb63e s390/zcrypt: Fix buffer over-read in cca_cipher2protkey 672b12940e3f1 s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs e16e0fc54120c s390/dasd: Fix undersized format-check buffer 86cdfd061509b s390/dasd: Fix potential NULL pointer dereference bd63c7879eaa8 s390/qeth: Check CAP_NET_ADMIN for private ioctls ef1aa7cfb8c63 s390/pci: Fix s390_pci_mmio_write syscall error return without MIO b039f13e095d2 power: supply: max17040: handle missing status supplier 6d89f33a64675 power: supply: bq25890: fix the -10 C NTC lookup entry 63d6c855b27df cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized 437b38a08c0a8 cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() efbcecdecefc2 cifs: add fscache_resize_cookie() to cifs_setsize() 466ab0c41d5f5 gpio: pch: use raw_spinlock_t for the register lock 2e4bc8422cdee gpio: pca953x: fix cache_only and IRQ state on restore_context() failure 1883a09a37fed i2c: amd-mp2: Unregister callback on adapter add failure 7a91d07939e07 hwmon: (pmbus/core) notify on the hwmon device, not the i2c client 30ae663746378 hwmon: (npcm750-pwm-fan): stop fan timer on device detach 4ba5bf7ed50f2 sctp: prevent peer transport count overflow a0d1693923f41 sctp: reject stale cookies with mismatched verification tags 2047ed09bf134 scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write 5b4d4d5a29f92 selftests/clone3: fix wild pointer access of getline due to missing init a0bc578641d74 selftests/mm: fix potential wild pointer access of getline due to missing init 2e047b4171de4 spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure 581e5166f0780 spi: spi-qpic-snand: write the feature value before executing SET_FEATURE c26a6477e149c tracing/filters: Fix false positive match in regex_match_full() cbb5ed3be9cae tracing: Check return value of __register_event() in trace_module_add_events() 205feb72e5beb ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() ee799977d7941 vxlan: use pskb_network_may_pull() in route_shortcircuit() 94dee751aad62 vxlan: use pskb_network_may_pull() for transmit path header pulls ff89415d34c3a vxlan: use neigh_ha_snapshot() in route_shortcircuit() adeed09eeb3b6 vxlan: unclone skb head before modifying eth header in route_shortcircuit() 1235e017aa11c vxlan: re-fetch eth header after route_shortcircuit() b24ba0bbffe3e veth: convert frag_list skbs before running XDP 3bd35a5e272a1 uprobes: Fix NULL pointer dereference in hprobe_expire() 180ff4c81faf0 um: vector: fix use-after-free in vector_mmsg_rx() e4b98f9778dfc powerpc/ps3: Fix map failure path in dma_ioc0_map_pages() 4ef801b838d85 net: pktgen: fix proc entry use-after-free dc3ab04220667 net: ipv6: clear suppressed fib6 rule result 0309ebbc57000 net: bridge: stop fast-leave after deleting a port group 332a546b4ee56 mm: memcg: initialize *locked in memcg1_oom_prepare() stub b11907c905fa0 mm/page_reporting: use system_freezable_wq to fix UAF during suspend 63b361f228866 io_uring/net: initialize mshot_len for send 4dad8ca637d44 binfmt_misc: don't let an 'F' entry pin its own instance 840bb9c49c3e7 binfmt_misc: reject a flag character as the field delimiter 255a758697da8 binfmt_misc: use exe_file_deny_write_access() for the interpreter clone fdc1d702bf300 binfmt_misc: restore write access when removing an entry c9dcfe6b8b713 wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames bed792737b5f1 tipc: avoid use-after-free in poll trace queue dumps 88752b811f72a of/address: Fix NULL bus dereference in of_pci_range_parser_one() 4ae701848e4ba netfilter: ipset: do not update comments from kernel-side hash adds f807a63d0d956 net/smc: fix socket use-after-free during link group termination 2060764e0f46c mshv: fix hv_input_get_system_property struct a60b5da05e318 ksmbd: reject repeated SMB2 NEGOTIATE requests b5ee5b266f833 ipvs: do not propagate one-packet flag to synced conns 3b5aee6fcbf6b igc: remove napi_synchronize() in igc_down() 845a9cdd9b03b igbvf: Fix leak in TX DMA error cleanup b10bb77e91e97 e1000: fix memory leak in e1000_probe() b0bdca3a49cf3 dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ 2db4535d6af79 ALSA: usb-audio: Clamp frame size in implicit-feedback mode 04595233e5606 ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set b5305a0d0bb8e ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() 7ba01e0d3539d ALSA: usb-audio: fix stack info leak in RME Digiface status cc014ebf80317 ALSA: usb-audio: fix use-after-free in ump_to_endpoint() 79f8720029f26 ata: libata-sata: fix ata_scsi_lpm_supported() iteration 9562ddbc6ed8f ata: libata-eh: Increase STANDBY IMMEDIATE timeout 0a02b0c878071 ASoC: tas2562: fix broken entries in the volume lookup table 35d5f1852e390 ASoC: tas2562: fix DVC coefficient write order cac7d2066b2f0 ASoC: fsl_easrc: fix m2m_init error path to use goto instead of bare return 6df5b32881602 ASoC: fsl_asrc: fix m2m_init error path to use goto instead of bare return 032746c2dd9a4 ALSA: ump: fix double free of out_cvts on rawmidi error a26a2e52736f9 ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes 5260e195c53e8 ALSA: seq: Fix division by zero in initialize_timer() 2940cc3cf43c7 ALSA: pcm: wake linked drain waiters on unlink 4969533a1b950 ALSA: lx6464es: fix period byte count for 16-bit streams 7484669d1fbab ALSA: hda/realtek: Add quirk for TongFang X6SP45xU 11e2953d9f4c7 ALSA: 6fire: Fix UAF at error handling during probe c0d3b81f703b2 afs: Fix UAF when sending a message d703f022a28a2 afs: Fix afs_fs_fetch_data() to subtract transferred from len b53face003b4d afs: Fix afs_fs_fetch_data() to set call->async 5c7fdcbecbab2 bpf: lwt: Fix dst reference leak on reroute failure 27cc0e603355c Bluetooth: HIDP: validate numbered report payloads 2ebf63aa557a6 Bluetooth: HIDP: reject frames without a transaction header eb1d8318764de Bluetooth: hci_sync: Fix advertising data UAFs c569def320aa8 Bluetooth: mgmt: fix UAF in pair command cancellation a33bc07b4730b Bluetooth: SCO: give the socket its own sco_conn reference 814f82f432dc6 Bluetooth: mgmt: fix pending command UAF in EIR updates 6936b367ee6d4 Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() f14d41dbc2fdf Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req() cae0dfed5d307 audit: fix potential use-after-free in audit_del_rule() 185c784c98094 audit: fix potential integer overflow in audit_log_n_string() 17b412468c7a4 sctp: validate Adaptation Indication parameter length c0837aeace961 dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister b878ba7e28144 KVM: s390: pci: Validate AIBV and AISB before pinning guest pages e137d082325bb KVM: s390: pci: Fix NULL dereference on AIBV allocation failure 1abf9ce39a862 KVM: s390: pci: Fix missing error codes and memory unaccounting 70871b121f81d KVM: s390: pci: Fix memory accounting for pinned/unpinned pages 6837f0ae85fd5 KVM: s390: pci: Reject adapter interrupt forwarding if already enabled 7668c58dcf465 KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active 5acc92947baa2 KVM: VMX: add memory clobber to asm for VMX instructions e768ea3a422d1 tracing/fprobe: Roll back on enable_trace_fprobe() failure 3b2e08e0ede72 tracing/probes: Reject $arg0 in meta argument expansion e0fa737783b5b mm/vmstat: fold stranded per-cpu node stats when a node comes online 126a70bf1a08d mm/hugetlb: fix list corruption in allocate_file_region_entries() 32134cf9211b8 mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() 7d3e1d3a0dce9 fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes c091462e46f75 selftest: fix headers in fclog.c 9668ffe0e2a5e mm/util: don't read __page_2 for order-1 folios in snapshot_page() 2be94d6b20789 mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE 2205263b1e013 fortify: Disable -Wstringop-overread in tests 96b0aa79b0e1e pinctrl: bm1880: add missing select GENERIC_PINCONF 5aaa06dfc10f8 erofs: cap LZMA stream pool size ad0ad3c228b6f pinctrl: devicetree: don't free uninitialized dev_name on error path 93d934668047f pinctrl: microchip-sgpio: add missing select REGMAP_MMIO 6da8f37419dd4 iommu/iommufd: Fix IOPF group ownership UAF 564ac339c0f8b iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace ee2212b482320 iommufd/viommu: Publish a vDEVICE only after vdevice_init() succeeds 294b464b2be7e iommufd/viommu: Release the igroup lock on the vdevice_size error path 062aa5dcc49a9 mshv: Order pt_vp_array publish against irqfd assertion path f50f5d3972da0 mshv: Fix level-triggered check on uninitialized data fc362bfcb060e mshv: adjust interrupt control structure for ARM64 72a90ce4918b5 mshv: Fix race in mshv_irqfd_deassign cfc686a1174aa iomap: add a separate bio_set for iomap_split_ioend 9be4a66f019ea ksmbd: fix use-after-free in __close_file_table_ids() 213b4568f6e5d ksmbd: return success for deferred final close cebba11df714b drm/i915/hdmi: Poll for 200 msec for TMDS_Scrambler_Status e51becb8f3377 qede: sync udp_tunnel ports outside qede_lock in the recovery path 51c52e493346f spi: spi-nxp-fspi: add per-SoC SDR/DTR clock rate limits for all supported SoCs caeaaf23f7c36 sched/deadline: Use revised wakeup rule only for running dl_server 5a73e8c632c31 octeontx2-pf: Set correct sequence for carrier off and tx queue stop b90916156b472 net: libwx: fix FDIR ATR queue mismatch for software VLAN packets 6bf322ab07418 ptp: netc: fix potential interrupt storm caused by incorrect unbind order 1e0dfb7e7a5d9 net: dsa: mt7530: error out on failed reads in MT7531 PHY polling fd9586881d478 net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend 54e07a158f7ae riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove b297559dc2f29 accel/qaic: use sizeof(*trans_hdr) for transaction length check 01bd01b61ad9e riscv: drop __init from vec_check_unaligned_access_speed_all_cpus a20a0010eb648 tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions 9b604041f1009 tracing/mmiotrace: Reset dropped_count in mmio_reset_data() fc97dcb42fb46 fprobe: Fix module reference count leak on error in register_fprobe() 84b5aa55de7c8 drm/i915/dp: Ignore the sink's DSC max FRL rate without a PCON DSC encoder 50edffd0854fe can: isotp: check register_netdevice_notifier() error in module init b4f8c33593f25 net: sxgbe: check descriptor ring allocation failures 42b87cfd9666e net: sxgbe: free TX rings on RX allocation failure 69a258a5a322e scsi: target: Clear cmd_cnt when initial counter enrollment fails 54c6fb24c6021 scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req ff333def31476 scsi: ufs: core: Revert "Delegate the interrupt service routine to a threaded IRQ handler" c249cfe1d8df2 scsi: ufs: core: Avoid IRQ thread wakeup during active UIC command e504204489993 scsi: ufs: core: Cancel RTC work in active-active suspend bdd8a1297ef10 scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE 613aaeeaf8cb1 net: phylink: put link_gpio if phylink_create fails 5ea70ad040c1b x86/boot: Add volatile, clobbers and zero-length test in memcmp() 5576afebf726c Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync e8f9fef362bab Bluetooth: hci_conn: hold conn reference in abort_conn_sync() de17305393ec8 Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists c618a9a5b08ea Bluetooth: btintel: Validate length before parsing diagnostics TLV 3b921533e8aa9 Bluetooth: ISO: fix refcounting of iso_conn e941799c31f68 Bluetooth: ISO: ensure no dangling hcon references in iso_conn 82e982f54f962 Bluetooth: ISO: avoid deadlocks in iso_sock_timeout e76a0ae6542ae Bluetooth: ISO: fix leaking sk after socket release 4e9b5e8669b36 Bluetooth: ISO: hold sk properly in iso_conn_ready 09a69828ae594 Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release cde36776cfe64 Bluetooth: ISO: Fix not updating BIS sender source address dfce8d30fc5be Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis() 1fc2132950c23 Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos e8e9cff6d80ee Bluetooth: ISO: lock sk in iso_connect_ind 3120664aa3330 Bluetooth: ISO: Fix data-race on iso_pi(sk) in socket and HCI event paths f1f167991a68f Bluetooth: HCI: Add initial support for PAST 72d5bb1d77d7c Bluetooth: ISO: lock sk in iso_sock_getname 58e3c5289ad23 Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp 63c0f396a18b7 Bluetooth: ISO: clear iso_data always when detaching conn from hcon 4e1f45de5b313 ice: suppress DPLL errors during reset recovery 6ebbf198e76ca idpf: Fix mailbox IRQ name leak on request failure d44081c61dc92 idpf: adjust TxQ ring count minimum ae7120102e1bb hwmon: (pmbus) Fix return value from pmbus_update_byte_data() 276f1f180f55d net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller 2c148a31ca01f netfs: release readahead folios on iterator preparation failure 291ebecdf315d netfs: handle single writeback rolling buffer allocation failure 627826ef42080 netfs: clear PG_private_2 on copy-to-cache append failure b558e07708d88 wifi: mac80211: validate individual TWT params before driver setup f82a2ded3d7a9 net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister() acbf711a20669 powerpc/boot: Fix treeboot-akebono CPU node lookup check b407b98cf665d powerpc/boot: Fix treeboot-currituck CPU node lookup check 3d24f2e5641b2 powerpc/boot: Fix simpleboot CPU node lookup check db986098f3088 rtase: fix double free of multi-frag skb on DMA map failure 5a6b0ccb8b018 hwmon: (adt7470) Fix PWM auto temp state array and bounds check 96ad57d317635 hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read ddd689bd72264 hwmon: (adt7470) Use cached PWM frequency value 1d6b54dbe8850 hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks d5d4034bb6f6e hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() 82d65f7ef11ed hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread 3e06ff0c79ea3 hwmon: (adt7470) Fix cache updated before hardware write on I2C error 28548ecc2b458 hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors ae20a8a4de06a forcedeth: fix UAF of txrx_stats in nv_remove 2e0c6761c0553 net: bridge: mrp: fix Option TLV length in MRP_Test frames 1b722740ac5c2 hwmon: (nct6775-core) Prevent access to unsupported weight registers 5ec5f00fc606a net: do not send ICMP/NDISC Redirects when peer allocation fails 2332d35aaf206 hwmon: (nzxt-smart2) DMA-align output buffer 075fce376cf85 hwmon: (lm90) Only report alarms if driver is ready c498adfd4c3e8 hwmon: (sht3x) Fix unaligned accesses 08aee6d45eefc hwmon: (ltc4282) Fix reading the minimum alarm voltage b60e8486c04de hwmon: (ina2xx) Fix various overflow issues e627f4ad9eea2 hwmon: (ina2xx) Shift INA234 shunt and current registers fdfde077e025c hwmon: (ina2xx) Add support for INA234 8da94361f9ae1 hwmon: (ina2xx) Make it easier to add more devices a42d727dae570 hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 e28d478c003d7 spi: spi-cadence: Move TX FIFO full busy-wait into FIFO d3337eefab626 spi: spi-cadence: supports transmission with bits_per_word of 16 and 32 fcc3d77fef02c ASoC: tas2781: Use correct calibration data for SINEGAIN2 register b2851429afc5b smb: client: fix buffer leaks in SMB1 read and write 9e24b47ef81d4 scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race 72815741715bd scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer 3ef209ca0b4b6 scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer 8e0996418590b pinctrl-amd: Don't clear S4 wake bits at probe ceb00cb87a22c xsk: drain continuation descs after overflow in xsk_build_skb() 411554cb868b8 xsk: use a smaller new lock for shared pool case 05e283466b86e xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx 814c5b1590037 selftests/net/af_unix: test listen() rejects wrong socket states 643ec3e24a490 selftest: af_unix: Create its own .gitignore. 0372a52191127 selftests: af_unix: Add tests for ECONNRESET and EOF semantics 5c170577049f9 af_unix: fix listen() succeeding on sockets in the wrong state b1d480fce05f8 rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() f6787fdffcae5 rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled 4147866087fbe ASoC: SDCA: Ensure that Control Range is large enough for header 16b553c46e347 netfilter: nft_payload: fix mask build for partial field offload e6f4b4b40db87 ipvs: do not mangle ICMP replies for non-first fragments ce96c40a049be ipvs: fix places with wrong packet offsets 00eb23829fd08 ipvs: fix the checksum validations d186f77d18bdf netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH 63ba12b664a2c netfilter: nf_tables: make nft_object rhltable per table adf1a3ba27ad1 assoc_array: trim the final shortcut word using the current chunk end 3d9f16c0b643c keys: make keyring key-chunk byte order agree with keyring_diff_objects() e9417d21a22ad keys: fix out-of-bounds read in keyring_get_key_chunk() 6469ad3005087 KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type 31d491f9da948 KVM: arm64: Reject guest_memfd memslots when the VM has MTE db1c4a8e9080f mshv: Fix sleeping under spinlock in mshv_portid_alloc a920ead0bc2f1 mshv: Fix duplicate GSI detection for GSI 0 b215cb70e14c7 Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation d397787dbc4bf Drivers: hv: Allocate the paravisor SynIC pages when required 74d20e3cf88e4 Drivers: hv: Rename fields for SynIC message and event pages 82cdbb6155a2c arch/x86: mshyperv: Discover Confidential VMBus availability 6e70eba930a24 drm/mediatek: Check CRTC state before freeing f74554e67ccf0 netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() ec81ecd2ac093 phy: zynqmp: fix runtime PM leak on probe allocation failure 86fb88ac8c915 phy: zynqmp: fix clock error handling in xpsgtr_phy_init() dff474e723ede btrfs: raid56: fix an incorrect csum skip during scrub 4d4ef6627304a btrfs: zoned: reset meta_write_pointer on zone reset deddd28fd83c2 btrfs: zoned: fix deadlock between metadata writeback and transaction commit 762561c438599 btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag cfa7e27348773 of: reserved_mem: prevent OOB when too many dynamic regions are defined f5edba9bc69d0 ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup 3cbfb9b886dc1 ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup 3fd94b9ffe997 phy: qcom: m31-eusb2: Fix return value of init call 9355f526c821f ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources() a0f288ebe6d8a ata: sata_mv: accept 1 or 2 resources in platform probe 8229a53888540 selftests/seccomp: Fix pointer type mismatch build error 99dc2c143dfc0 selftests/lkdtm: rename STACKLEAK_ERASING to KSTACK_ERASE 094145989b31f gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe() 3808bab5d95ae iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE 0679c0c189d25 dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() 9086b488f2737 dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA 2ef9bb422dd6d pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 3e55d28095476 pinctrl: qcom: Unconditionally mark gpio as wakeup enable 54a62153c765c thunderbolt: Prevent XDomain delayed work use-after-free on disconnect d01e88d421a6d mm/slab: prevent unbounded recursion in free path with new kmalloc type 3e957c9b160cf lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled() 98f57011e6cd1 HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report bc3bba4656ad2 HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write df0f33293c0a3 HID: logitech-dj: Standardise hid_report_enum variable nomenclature 302eb87651326 ALSA: hda/realtek: add quirk for HP Dragonfly Folio G3 2-in-1 e8362523fd1b6 drm/gpusvm: publish dpagemap early to avoid device mapping leak on error a5cdd2407dd89 net: mpls: initialize rtm_tos in mpls_getroute() 85b94a74a0b83 netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge() 9bb3714e09986 kunit: tool: Terminate kernel under test on SIGINT d36086cd1826e kunit: tool: skip stty when stdin is not a tty 285641eb82f0e netfilter: nf_conntrack_expect: restore helper propagation via expectation Signed-off-by: Bruce Ashfield Signed-off-by: Richard Purdie (cherry picked from commit 6ce984c0a3a68c2fdc3c32bc185b6729d09e7829) Signed-off-by: Yoann Congal --- meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend b/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend index dec64c20..cea5e3df 100644 --- a/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend +++ b/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend @@ -8,4 +8,4 @@ KMACHINE:genericx86 ?= "common-pc" KMACHINE:genericx86-64 ?= "common-pc-64" KBRANCH:genericarm64 ?= "v6.18/standard/genericarm64" -SRCREV_machine:genericarm64 ?= "19b324105e674270fa4f09ec74c6229a3901893e" +SRCREV_machine:genericarm64 ?= "e53bc6de014bcdd6615eeed206ef14ebe67c423b" From patchwork Wed Sep 9 07:32:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 97697 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E7080C79F8C for ; Wed, 9 Sep 2026 07:32:34 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.6493.1788939149154879492 for ; Wed, 09 Sep 2026 00:32:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=r3akadr/; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-4843cedd129so393404f8f.0 for ; Wed, 09 Sep 2026 00:32:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1788939147; x=1789543947; darn=lists.yoctoproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Y5+I2TsX3ZmAG9Oomp71FZ8qHIajxVdgCm1p5G36l7o=; b=r3akadr/hGJHwWZXt/DhcWTht0RBKHF73d8KeY7Ml0RZFgBHFJaqkH+3HPubfn29hm CVYkV6FDp5rVO1V37xTMEL2trXc0TJ4BT3OoJt1+1JeRjEfHHXkUI7gSzrBJXGZ6SWlk Ybf4AkHIEGCXs7+LBuPZQmu7BJBfDk7PcWvIg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788939147; x=1789543947; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=Y5+I2TsX3ZmAG9Oomp71FZ8qHIajxVdgCm1p5G36l7o=; b=qKNF8ux6G8ClYSHP2SGCAFThdMR7+/V84OksIsGCmaFjCOBbvWNJR+XhBJMIj0eLnj WIveGJJBSvUX5T0Okxxfc1a2kIZA2m4Yewmnusm7Zdsprimr1I1P4DfwPeh/Nt4pN2PD VP37vbKRN3EK6iUPL2kpJxSUDoyLlwP75YtZIwYTOLT266mSxDDHCpX5g1sF6U87Ox0l v2Lh281/BDM8FZVxe5hu71WlzVJGK91Q3CHlg17i+W6ij9UBJw3fzbbeFw2OfLHlfCIS v9KizdkOXPTXKk3UGQwHrHSYPa+M7u0pdtTr1hQnkk/LliqHyWUgvv4YhNtzrWcp9JTF Z/cg== X-Gm-Message-State: AFuF++mk1rnkY0PgYqVJAXvd7dlQKKt4qT3btdJzEc/+sq/sXKcRha73 h/MXPlXKp6KEYlwbufmGQMhnyX2Tp03Z/odfulOe0byw7W0iQKiMj2c83wuN2BgmWbEkM3Pm3j0 0I3HSniU= X-Gm-Gg: AYBFou0MIIuYPEhNRtvw3HSvk74ORJYfvRITOT5K8zHrspJ9o2Tk2IrYauFFSm0UTct uPjS6IIFuNvX+87DlXxaz3onKWjxrFcM00s9zP+kjq5vP8lHwDuc/A2Cu0WMrU2X7x/VRmdzWIi svXbIN+MFO6sdxBbWPJ88d5zaQCctKb6CvPm829kCiSTndbycMVprX2MeEDXe9a2AEwkrhQsWF5 a4ht7dIsT5uacBaBfyuV2PERiJDxokvjA32sBZQEBq2gFLfz+KTYN3rkt1Y8edNxWVhQcut+qXh CMem8/E1ShfXLzzKtFps7Er5kWKmnyy5iDmD5bNl8lEkYNaNU5mMp6Bp7rrSd/N1Nwp6D4C+zC6 9+AvsoQJ95oYoy5k3vST+a5fY2vu579yCBx6gdcYsSp94jn/4R0l4nl0YyogutGmqxRh7UBREXM BrrZVNLgYRpTSFkwgaYu5O5ODWSCJCprrU0DoLC7S8HfV9mgyzIghl7w/yWJYVSRw+wZeJmZiIB YustMzgtTUbWs1od5CsUz6oGlsHphrunCnooxE3ttu7RmJWsCoxUXTB6i3lZaOIihBDsJssHS4= X-Received: by 2002:a05:6000:29d0:b0:485:ac39:36ef with SMTP id ffacd0b85a97d-485ac3937c0mr4463814f8f.5.1788939146703; Wed, 09 Sep 2026 00:32:26 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885b1320sm40931457f8f.27.2026.09.09.00.32.25 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 00:32:26 -0700 (PDT) From: Yoann Congal To: poky@lists.yoctoproject.org Subject: [meta-yocto][wrynose 4/4] linux-yocto/6.18: update to v6.18.48 Date: Wed, 9 Sep 2026 09:32:19 +0200 Message-ID: X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 09 Sep 2026 07:32:34 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/poky/message/13965 From: Bruce Ashfield Updating linux-yocto/6.18 to the latest korg -stable release that comprises the following commits: 5bbb9c9f8f808 Linux 6.18.48 c49f04e8d2b94 inet: frags: strip GSO state from fragments before reassembly 7519e95095c9b Linux 6.18.47 3ce832e2bd431 net: gro: properly validate BIG TCP aggregation criteria 5b4f2bec7bea6 ptp: vmclock: prevent read-only mappings from becoming writable dba60d26e9dda futex: Avoid private hash use-after-free on final put e1534d49a7b8b Bluetooth: hci_aml: validate firmware segment lengths b7d9edcf9fe6e Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 1f6d1f2611af0 Bluetooth: ISO: zero the sockaddr before returning it in getname 753af97d8d423 Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync fe93a697a7a92 Bluetooth: hci_sync: Fix accept list UAF during suspend e3f82e8f2a591 Bluetooth: hci_event: validate LE Set CIG Parameters response 39a3afb91be3c Bluetooth: hci_event: fix LE list UAF on reset 608f8fd8c0f7b HID: hyperv: validate initial device info bounds 849e537160bbb HID: uclogic: fix use-after-free of inrange_timer on remove 8406d4b69d48b HID: sensor: custom: Fix use-after-free in enable_sensor 1fa1591efd417 HID: core: fix number/pointer type confusion on long items 5efcd7bbfaaec HID: nintendo: stop device IO before hid_hw_stop on probe failure 268679f501386 HID: nintendo: register input device after capabilities are set 51cfd1adbe7a4 HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() 942b89f7824f8 futex: Fix might_sleep() warning in futex_pivot_pending() 86d12b34bafc9 futex: Fix race on the initial mm->futex.phash.ref allocation fdf538b2e6965 futex/pi: Plug private futex exec() race 4da67def9efe6 futex: Sanitize and document task_struct::futex::state transitions 2b92e5562653b futex/pi: Reject cross-mm private futex owners f303f6a4c9099 Input: atkbd - skip deactivate for HONOR ZQC-P 936ea65543da0 Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard 0ea8f06454012 xfrm: fix sk_dst_cache double-free in xfrm_user_policy() 39fc615e355b6 net/ionic: avoid OOB TX partner lookup for hwstamp RXQ 4529c03c3da8f HID: pidff: fix OOB write when hid->inputs is empty 9a1d7c5f0d82e HID: core: fix OOB read of field->usage in hid_set_field() ace7fc4d38799 HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID 15b60ade825c8 HID: magicmouse: do not keep a stale msc->input if no input is claimed 62ec3c591ee81 HID: magicmouse: re-enable multitouch after reset-resume 02a88f8308ae7 HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C b6baab796d11f ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses 9fe5eebb664ec mptcp: pm: fix memory leak from alloc-during-teardown race 6fa2064761ec0 mptcp: pm: uniform announced addresses helpers 714c6d11aceaa mptcp: pm: rename add_entry structure to add_addr defc59e74c1b4 mptcp: pm: use for_each_subflow helper f31650243c1ab nvmet: pci-epf: put CQ ref on create_cq mapping failure 20be486d1c225 nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work() 9c95f7e66c62e nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations 6d27199ebe8cb nvmet-tcp: bound SGL data length before allocating command buffers 8bce9cd08aae4 nvmet-fc: fix invalid free in LS IOD error path b26189d284421 nvmet-auth: zero the AUTH_RECEIVE response buffer 23a475ff24d29 dmaengine: fsl-edma: Add error handling for devm_kasprintf 364edaedf4125 mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf() 3dc98e5fe82d0 ipv6: fix use-after-free in ip6_finish_output2() d9d1a676b033a ipv4: reject undersized MTUs in ip_do_fragment() f034150305791 drm/xe: Fix DPT allocation paths. 20892d2923e48 nfc: nci: free destination parameters when closing a connection 0d4b5cfab6891 nfc: nci: fix uninit-value in the RF discover/activated NTF handlers 2f08dbce3b376 nfc: nci: fix out-of-bounds write in nci_target_auto_activated() 9620a91f8d643 nfc: nci: add data_len bound checks to activation parameter extractors bfcca5f42c9aa nfc: st21nfca: validate ATR_REQ length against the received frame 2f5d093194ec2 nfc: pn533: purge fragmented skbs during cleanup e969e98410051 nfc: llcp: reject PDUs shorter than the LLCP header 2d239590d1845 nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers e87527b506c40 nfc: llcp: bound the connect_sn TLV walk to the skb d0902a7c45432 nfc: microread: validate target discovery payload lengths db7e464b35096 nfc: fdp: bound the device-reported read length and fix an skb leak a56773e649ea9 nfc: digital: clamp SENSF_RES length to the destination buffer cb8246e5846db libceph: fix OOB read in decode_watchers() via missing bounds check 184c1a80421a5 xfs: validate attr entry pointer before field access e0e7f464d6ce8 ext4: fix incorrect function call when initializing s_resgid 458776af0061a ext4: don't enable DAX on new encrypted files f3d2fa3a99336 ext4: propagate errors from fast commit range replay 5f46f084f74b5 ext4: avoid tail write_begin walk for uptodate folios fb5980fbe44fc ext4: clear error before retrying inode xattr space fallback e447f7edb99bd nilfs2: reject invalid block index in GC ioctl 4902a5cba21ae ext4: stop retrying saturated xattr cache entries e11f5b48c8270 kcov: fix data corruption and race conditions on PREEMPT_RT 164ca33cf5366 null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows 6176313622e34 ocfs2: fix missing metadata reservation for large xattrs 15ccf53709859 io_uring/uring_cmd: don't skip completion for a synchronous multishot cmd 45c945107e007 io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec() 4074ae2f1da9e io_uring/io-wq: fix worker accounting when canceling creation callbacks b6a768aa975b9 io_uring/cmd: fix iovec leak when the async cmd is not recycled f20c2c32ec1c5 ALSA: dummy: Check card index validity at probe 3da64f2ed902b io_uring/futex: don't mark futex wake requests as inflight 61dc1a37e04d4 nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist() e971d956353d3 rndis_host: add overflow check in rndis_rx_fixup() 4305e4b52acc0 ALSA: scarlett2: Use a private URB for the notification endpoint 65aceb45ca91d ALSA: FCP: Use a private URB for the notification endpoint 7596354148c5a iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages d2ab08437e913 iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown d4b1a13b1eff2 Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept 0c55707bd5d0d PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems 159d162fe80bd xfs: don't livelock in scrub on a circular unlinked list a05a1b663464b xfs: hoist per-bucket unlinked list check to helper 8d678be8e58e9 xfs: rtsummary scrub should treat rtbitmap corruption errors as an xref error 00e2baf0b5ea9 xfs: add a xchk_ip_set_corrupt helper 755d0b7ee3563 serial: sc16is7xx: enable THRI before filling TX FIFO c5a12344a043e serial: sc16is7xx: use guards for simple mutex locks 450fe8f6f1f8c serial: sc16is7xx: rename EFR mutex with generic name 1f99e9ab748fc Linux 6.18.46 b7ce4b3bc1068 ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r 192f44513a03b firewire: ohci: initialize page array to use alloc_pages_bulk() correctly e5e6ce7009a6c drm/vmwgfx: Set surface-framebuffer GEM objects 7e351209dc2f4 erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms 67ac7e01c26be spi: virtio: mark device ready before registering the controller a7d172b27aa3e drm/log: Fix infinite loop when scale is too large for display a6325e2807dc2 drm/client: Remove drm_client_framebuffer_delete() 329731b3119f0 drm/client: Deprecate struct drm_client_buffer.gem 0763282e689e2 drm/client: Inline drm_client_buffer_addfb() and _rmfb() 60f1a2ecdf8b9 drm/client: Move dumb-buffer handling to drm_client_framebuffer_create() 841bc853a2b11 drm/client: Remove pitch from struct drm_client_buffer 16a2716910ecf drm/log: Fix out-of-bounds read on empty message length 948f346fe36e1 drm/xe/oa: Fix sync entry leak on OA config emit failure ed5470771c7ed firewire: ohci: fix NULL pointer dereference in ar_context_release 384d9f04b38f4 firewire: ohci: split page allocation from dma mapping adb3e7c26a51a net/sched: cls_bpf: reject dev-bound programs bound to a different device 1f493c44a2f04 accel/amdxdna: Skip unmapped range in aie2_populate_range() 72e4e3d7efc3b net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG 6cf600b276a55 regmap: sdw-mbq: don't call an unset readable_reg callback c27eed546ae20 m68k: Define NR_CPUS to 1 31f26a95eeee9 net/sched: cls_u32: skip hash tables in u32_bind_class() abceabc4408fc net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain 98c5914d6b7bd af_packet: Don't send zero-byte data in tpacket_snd(). 37c5ccaaacd48 regmap: sdw-mbq: Fix swap of timeout and retry times f51a540b14eec ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers 82d9269f01ebf net/tls: Fail tls_sw_splice_read() after a failed async decrypt cef4c5b9aca24 net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling 5ffaa5d7f56ab net: tap: fix wrong transport_header when sending VLAN-tagged frame f9297abbcaba7 net: packet: fix wrong transport_header when sending VLAN-tagged frame 0af3afd054e7b net: phy: realtek: fix EEE advertisement write on the internal PHY MMD path 17e3181d740d1 tcp: fix icsk_ack.ato bitfield overflow 73f8dd22b1e53 veth: fix queue index used to wake the peer txq in veth_poll 96fa90b74385b macvlan: inherit needed_headroom and needed_tailroom from lowerdev 5f33188457bbc ipvlan: inherit needed_headroom and needed_tailroom from phy_dev 1072f0f442820 eth: bnxt: keep the aRFS rmap updated when TPH is enabled 394f1b16c5d1b eth: bnxt: cancel IRQ notifier before freeing affinity mask a26a1be1b6541 netfilter: ipset: let destroy callbacks adjust ext mem size 29c011b3537d7 netfilter: ipset: fix list type element drift bug d9d3050a70efe netfilter: flowtable: publish GC-visible tuple last 4a923fe60939a netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path cb20da33839f2 netfilter: ipset: fix refcount race between list:set GC and swap 9e75e7da43740 ASoC: tas2781: fix clang build error for goto bypassing cleanup variable 24d0f33f5415f gpio: ml-ioh: share the register lock across channels 7a03413f31c19 perf: Reject exited events as group leaders 6c85d169eeecc riscv: ftrace: Fix ftrace_modify_call failure on kprobed functions a3a676495c641 ovpn: finish crypto callback cleanup before peer release a47a080d06ee9 ovpn: fix NULL dereference when killing missing key 99a18e1d979e0 crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req() 3e4bf50c94511 crypto: ccm - Set rfc4309 maxauthsize from child d9ecc9787e118 arm64: tegra: Add EL2 virtual timer interrupt for Tegra194 a4e340971fe8c NTB: ntb_netdev: Preserve RX queue depth on allocation failure 08437c5156b0a net: ntb_netdev: Introduce per-queue context 2a7d8fc0fd50e ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup 8c685df5c3b26 drm/amd/pm: fix pptable use-after-free 2895aeb4327c9 drm/amd/pm: adjust the visibility of pp_table sysfs node 7755be923e325 mm/page_table_check: skip special zero mappings 4ae625d16eefb ring-buffer: Prevent resizing of persistent ring buffer 54fc67500ad1b ring-buffer: Store bpage pointers into subbuf_ids 27d7fcaf237df ring-buffer: Add helper functions for allocations 2ca6b43edf83f sched_ext: Take cgroup_lock() first in scx_cgroup_lock() f786e6652b931 sched_ext: Reorganize enable/disable path for multi-scheduler support 0907f81536f7d sched_ext: Update p->scx.disallow warning in scx_init_task() 4a7e941ca29a6 futex: Fix race in futex_pivot_pending() during private hash resize 870f8392b284e can: rcar_canfd: change the initializing flow for clocks and resets 45bf067681ad5 can: rcar_canfd: Extract rcar_canfd_global_{,de}init() e7a4ca927857a can: rcar_canfd: Use devm_clk_get_optional() for RAM clk f8c8c81707d17 can: rcar_canfd: Invert global vs. channel teardown 562d4befa9357 can: rcar_canfd: Invert reset assert order 867aed6a48487 binfmt_misc: don't leak the user namespace when the mount fails 4c8d7595a10a6 ata: libata-scsi: terminate deferred commands on time out db488d653d896 ASoC: tas2562: Validate values for volume writes 5f0a99ea72120 KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs ef60eca789ee6 userfaultfd: wait on source PMD during UFFDIO_MOVE ea563ed2b10ae mm: replace pmd_to_swp_entry() with softleaf_from_pmd() 54a09573eb440 fs/proc/task_mmu: refactor pagemap_pmd_range() 549148d5aa4e3 btrfs: zoned: fix missing chunk metadata reservation 58ae8b7e8dc88 btrfs: remove fs_info argument from btrfs_zoned_activate_one_bg() d9e9753dfd43b ksmbd: validate minimum PDU size for transform requests 15a2fedb5dff3 smb/server: fix minimum SMB2 PDU size 23d34ce118857 smb/server: fix minimum SMB1 PDU size 5649004f71613 ksmbd: rename smb2_get_msg to smb_get_msg 29dbb4e29e1f1 ksmbd: Fix to handle removal of rfc1002 header from smb_hdr df3cf61adbe68 smb/server: rename include guard in smb_common.h 9d154c3c0f5d9 smb: move get_rfc1002_len() to common/smbglob.h 8ddc2eb0d2da9 net/sched: serialize qdisc_rtab_list against concurrent get/put 89df5d71f83f8 libceph: fix two unsafe bare decodes in decode_lockers() 590b07ceea138 libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE 89a50fb32d69a libceph: Amend checking to fix `make W=1` build breakage a3bc6b3e9ef3f ceph: fix hanging __ceph_get_caps() with stale mds_wanted 79d95b43ca090 ceph: avoid fs reclaim while using current->journal_info bb13785d54999 xfs: check v5 superblock features early 04228b8ba196f xfs: check xfarray iteration errors when committing unlinked inode lists 33b56c6c465aa xfs: don't ignore runtime errors in xrep_iunlink_reload_next 38a4dbe588bd0 xfs: don't swallow dquot recovery verification errors 0f27b22343b63 xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN cd1f876d1bc2e xfs: avoid UAF on sc->tempip in xrep_tempfile_create e75150d494dcd xfs: don't return EFSCORRUPTED when scrubbing corrupt parent pointers b6baf0db357fb xfs: fix another iunlink infinite loop bug in online fsck fc7d8a5c5fcc7 xfs: fix allocated inodes that show up in the unlinked list c36d7f68f1c2e xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair 73ffd2620df3a xfs: don't zap the attr fork on repair when there are queued pptr updates 514a5d42d4188 xfs: fix ilock leak on error in xfs_dq_get_next_id 9680b1929d897 xfs: load next_agino from the correct xfarray in xrep_iunlink_relink_prev 8b52fa8fb3abb xfs: nlink scrub must take IOLOCK before determining ILOCK state 7d1d82c463e22 xfs: pass runtime errors from xrep_iunlink_mark_ondisk_rec up to callers ab4e133370763 xfs: set the prev pointer when reinserting an inode on the unlinked list ce2a7006ec5ed xfs: don't double-lock when deleting a self-referential directory 983588e756a30 xfs: only check mergeability of bnobt records 62c0b1435dfe2 xfs: zero i_nlink before repair puts inode on unlinked list a9114c6d4ec2f xfs: fix transaction block reservation in xrep_rtbitmap 90a49b8fcf821 xfs: check cowextsize in xrep_inode_cowextsize 069c0eadc8df0 xfs: clear zapped attr fork state when bmap repair finds no attr fork aeadf3fd2dc3c xfs: mark nonzero sb_gquotino as corrupt on metadir filesystems f8288214459ea xfs: bounds-check buffer log item's dirty bitmap 8a0ecae2ecda9 xfs: fix off-by-one in rtrefcount btree root level validation ec19cea4ef1ce xfs: propagate errors from xfs_rtginode_load 71aa45f7bfe46 drm/amdgpu: disallow multiple FENCE chunks in one submit 25ee120f3803a drm/amdgpu: Fix UVD decode image min size calculation 38914cb2c6afb drm/amdgpu: Fix UVD dpb min size calculation for H264 c76e5cca0675b drm/amdgpu: Fix UVD min buffer sizes 86a5cb0203221 drm/amdgpu: Implement insert_end for VCE 3 339deb76ee485 drm/amdgpu: Reject UVD message with dimensions above 4096 220aa2589d732 drm/amdgpu: validate GEM_CREATE domain combinations a082bd76c5f25 drm/amdgpu: check ASPM on the dGPU host link 916e8a1550be1 drm/amdgpu: fix nbif 6.3.1 l1 low power not functional e304c3e0d9ce2 drm/amdgpu: Reject UVD message with invalid number of h265 refs e3e6a631dcb1c drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE cd99fa1cbaf5a drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix 5045fb4c70bfd drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank() 95c1de6923b06 s390/zcrypt: Fix CPRB memory allocation in zcrypt misc code 7902be374cbfc s390/vfio_ccw: Implement a crw lock 3b224d3c50a38 s390/vfio_ccw: Calculate idal length based on idaw type b6aecea4b2b24 s390/vfio_ccw: Selectively expand io_mutex af1759d8e6e6d s390/vfio_ccw: Move cp cleanup out of not operational 4c2e1d359d7a2 s390/vfio_ccw: Fix out of bounds check on CCW array 08ef2a8211569 s390/vfio_ccw: Ensure first IDAW remains constant 649badf3a2fd8 s390/vfio_ccw: Ensure index for read/write regions are within range b7ae0f7993867 s390/vfio_ccw: Cancel existing workqueues 06f4d6e5a8af6 s390/vfio_ccw: Limit the number of channel program segments 32e3d364a7b82 s390/vfio_ccw: Free all memory if cp_init() fails 45aa38567c798 eth: bnxt: make sure we populate the qcfg defaults on old FW/HW 0382ed41c6645 eth: bnxt: always set the queue mgmt ops 31ef57083e785 drm/radeon: fix autosuspend cleanup during teardown 361114857813d drm/xe: Fix xe_device_probe() failure 7b90db6f024b8 drm/xe: Order ring writes before ring tail updates 198b4a89b9033 pmdomain: mediatek: Fix mt8183 hang on boot 8f7f7a6d5aed8 mmc: loongson2: Fix sg iteration in data reorder functions e5b527804a1ea drm/connector/hdmi: Fix out of bounds memory read b5060ff2f5460 mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition 78e59ab343372 pmdomains: mediatek: Avoid setting RTFF's CLK_DIS before NRESTORE 7c0d1767ce464 mmc: sdhci: make tuning_err a signed int 970b9c83a07c4 pmdomain: mediatek: fix remaining %pOF after of_node_put() 36d1b69c5c698 mmc: sdhci: unmap the bounce buffer before device release 0418b7ed2c1c6 mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit b37e84280045b libceph: tolerate addrvecs with multiple entries of the same type 4490fad7992a7 ceph: fix MDS random selection readiness predicate 4f392fec07556 libceph: Avoid using invalid osd indices from primary_temp f3854719fba9f Input: sur40 - fix V4L error path cleanup 5c1c5227c93f1 Input: sur40 - fix input device registration ordering a88d688be8d7f openrisc: signal: do not restore privileged SR bits on sigreturn f634598e8fb7b ftrace: Fix off-by-one fentry site disable in ftrace_free_mem() f8fe843a96344 ftrace: Protect direct_functions in ftrace_find_rec_direct d1bba38574d09 libceph: fix multiple unsafe decodes in decode_locker() ebdecef6fd842 pmdomain: arm: Fix -EINVAL from scmi_pd_set_perf_state() on state 0 bc7934d0acd4f gpio: ml-ioh: use raw_spinlock_t for the register lock 9e678cffc11c2 gve: fix zero-length skb frag with header-split bd4e5a97edf8c selftests/ftrace: Convert ELF entry point to file offset in uprobe test 23e9f32c0c7d2 gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind e9482feeed66d gve: fix NULL dereference due to missing ptp adjfine a134e4b8102c0 crypto: qce - fix error path in devm_qce_register_algs ef92c0ad0268e crypto: starfive - use scatterlist length before DMA mapping 38e7d5c1ade04 Input: hynitron_cstxxx - validate touch count and finger IDs 70f9aad394355 Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue ff0849705d292 Input: synaptics-rmi4 - block s_input when F54 queue is busy 6b06aab79ff16 Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer b28593a05afdd Input: synaptics-rmi4 - zero report size on F54 work error 828a8d1a9107a powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak 2bdec532202b3 powerpc/pseries: lparcfg - fix kbuf[] underflow 8dbfd8e32a13e Input: byd - synchronize timer deletion before freeing private data a64a8b6b31cd6 Input: iforce - validate input packet lengths e7b8a107ecad5 Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard 8d622c58205ad Input: psxpad-spi - set driver data before use 83c265bfc084d Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet 9b184c8337c6e Input: synaptics-rmi4 - fix F55 transmitter electrode count typo 652e952850d9a powerpc/pseries: pci - logic bug 52a818c586ae2 Input: cs40l50-vibra - validate custom data from user space 455dbb5bdd814 Input: xpad - add support for ZENAIM LEVERLESS 6635d544bd6bc ASoC: SOF: topology: Use acpi mach from the machine driver bcc66461f574a drm/amdgpu: fix aperture iounmap skipped on device removal dffacbe8118fc drm/amdgpu: fix JPEG v4.0.5 queue reset failure in DPG mode e45356f6adae4 drm/amdgpu: fix JPEG v5.0.0 queue reset failure in DPG mode 4550b90bd2e6c drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12 1474f3970d1af drm/amdgpu: reject oversized IBs with per-ring packet limits 25556a46ae6ec drm/panthor: skip zero-sized firmware sections 7ff87a01ae3a8 fbdev: core: Fix pointer desynchronization in fb_io_read() 2fe7a89b2b5b7 ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses cc61f0fa2c714 ASoC: cs35l41: sort the register default table 3298f13d1f126 ASoC: cs35l45: sort the register default table d7bd683b0d90c ASoC: cs4265: sort the register default table f2435a46dfa1a ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout 8cba53b862e14 ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() a308364774794 s390/qeth: validate user buffer length in SNMP and ARP query ioctls 75e564b2ced1c mptcp: fastopen: only mark MPTFO subflows with SYN data 3f8e5eb0c4999 mptcp: pm: fix data race in add_addr timer callback 1fade1b2ac5b1 mptcp: options: reset DSS fields in case of unexpected size a04dcc784959e mptcp: avoid combining some incoming suboptions 0cb3846c26c11 selftests: mptcp: join: mark tests with data corruption as failed 473f1a5ab2abc mptcp: reclaim forward-allocated memory on RX path errors 9b46fba7528f5 selinux: reject a permission value exceeding the class permission count 841aea4d5a25e selinux: reject an unclaimed class value in security_get_classes() 1b4ff94ae7c58 selinux: do not cancel a policy conversion that never started acd5b09be98fd selinux: reject a class permission count below its inherited common 42a7107f99d86 selinux: require every boolean value to be defined 1a4c3ffe2a48b ipvs: separate destination availability state 9ff46bf75bfad ubi: fastmap: fix ubi->fm memory leak 075036cea14ae mtd: ubi: skip programming unused bits in ubi headers bb03b56d1d754 block: stop the timeout timer when releasing a never added disk e2c3337c2238e ALSA: hda/realtek: Add quirk for HP Dragonfly Folio G3 2-in-1 (103c:8a05) bf3be28f6721e Linux 6.18.45 1eb0dc458b6e8 netfilter: flowtable: ensure sufficient headroom in xmit path 99ec511f258e0 netfilter: always set route tuple out ifindex 9977321835c7a thunderbolt: Fix bandwidth group reservation indexing 40d2ffb74094c thunderbolt: Bound the DROM dual link port number before indexing sw->ports ca33df36aa014 sctp: clear new_transport when removing a peer 07daf4f975010 sctp: fix use-after-free of cached ASCONF chunk 2b3b5eec8b2c3 sctp: keep chunk->transport in step with the list it is queued on 3bd46d33e3fd5 scsi: scsi_debug: Negate wrapped memcmp() result a14e4ef1d90c3 bpf, sockmap: Fix sk_redir use-after-free in send verdict 3c6d4ffa0c6db fsverity: Fix silent truncation in bpf_get_fsverity_digest() 2a5cfcad1d56e fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions 4917e3ebcab50 mm/filemap: __filemap_add_folio() restore index before retrying dd21c96a71e87 ima: Instantiate file_truncate and path_truncate hooks 102fb2dacf450 sched/psi: Create the psimon kthread outside of cgroup_mutex 8037c5b2b2a44 sched/psi: Shut down rtpoll_timer in psi_cgroup_free() 653e888a24c87 fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() 4eb15c465337b ip6_tunnel: clear skb2->cb[] in ip6ip6_err() 3b2231e358d26 ipv6: fix Route Information option length validation 7f740664aec1f mm/ptdump: always stabilise against page table freeing using init_mm 5b926fb04cb9e ring-buffer: Use current_context for safe per-CPU buffer swap 2e37f2bf11142 ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer() 5fd91dd4a1434 ptp: ocp: Fix board ID over-read 8d34019d14136 Revert "thermal/drivers/hwmon: Cleanup coding style a bit" 5635211b44969 eventfs: Fix use-after-free in eventfs_remove_rec() 66bc868a33cf1 KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page 47976eaaf0a4e KVM: SVM: Serialize accesses to the owner and mirror list with separate lock 1ffacbadc1453 smb: client: Fix use-after-free in cifs_try_adding_channels() c3f2347a47754 tipc: read le->link under the node lock in tipc_node_link_down() 3fc5044796dd8 tls: don't leave a full plaintext sk_msg ring unpushed 68787940274ec tls: rx: restore msg_iter before TLS 1.3 optimistic retry f1e21108e3ddf vhost: reset the vring metadata cache on vring reconfiguration cdf745b7a777f veth: fix skb length accounting after XDP frag adjustment 38c7763fdc533 vsock/virtio: avoid refilling the RX queue after teardown bd43a7ec668be vsock/virtio: read virtqueues under worker locks 46bb297ad7768 vxlan: do not arm the ageing timer on a device that is down fab820f1691a9 xdp: reject clones that overrun skb_shared_info tailroom e708fc1566ebd x86/mce: Set up the polling timer before CMCI discovery 846b92e26c8ab x86/CPU: Add a tlbi= cmdline switch 69298af46f397 arm64: remove redundant concurrent ptdump UAF mitigation fe79571f40434 dibs: initialise dibs->lock in dibs_dev_alloc() a2e326c52c4bc Revert "drm/amdgpu: fix aperture mapping leak" 24e95a24f151c binfmt_misc: don't warn when the mount is completed from another user namespace be161fa31e3e9 ovl: don't warn when the mount is completed from another user namespace 92f00f1d4d204 net/sched: act_gact, act_police: range check the fallback control action b47bb899e04b5 net/sched: act_ct: fix sk_buff leak when the header checks reject a packet 782cc40b7ade4 net: atlantic: free RX pages of consumed but not refilled buffers b13202d401e1a net: atlantic: free stranded TX buffers on ring deinit 0424186d570aa netfilter: nf_conntrack: defer invalid log until after unlock c58d34fe8b7e4 netfilter: bridge: release template ct on non-IP path e9bfe12b1d04c net: devmem: prevent net-iov / page mixing 4bc522b33438f net/x25: fix use-after-free of the socket by its timers ece6426b61241 net/dibs: Correct freeing of dmb_clientid_arr 680fbd7942185 ipv6: prevent in6_dev_get() from resurrecting inet6_dev 0b7d54cedea5c net: smc: fix splice entry lifetime imbalance in smc_rx_splice b65c11bc62216 net: phy: mediatek: fix TX blink masks using the RX bits 105d04edbec83 mm/huge_memory: fix huge_zero_pfn race 152a00440dc6e tracing: Fix NULL pointer dereference in module event cache removal 62978cf634797 ring-buffer: Prevent subbuf order change when resizing is disabled bc9db0d879c65 fbdev: bitblit: bound-check glyph index in bit_cursor() ed49684e69f84 tracing: Fix race between update_event_fields and, event_define_fields a979a642402d0 perf/core: Fix group leader use-after-free after sibling detach 5884851a096d8 drm/v3d: Serialize the scheduler timeout handlers 7779249561d14 ALSA: us144mkii: re-anchor capture URBs on resubmission a6b79dff1cc1c ALSA: hda/tas2781: fix ACPI reference handling bb30e35c36ed0 ALSA: FCP: fix OOB write in fcp_meter_ctl_get() f75d6f61f0d9c ALSA: usx2y: bound the hwdep mmap fault offset d217d723c5e43 ALSA: usb: Fix UAF at delayed release of MIDI2 EPs 976da5475472e mm/damon: adjust isolated pages stat for DAMOS_MIGRATE_{HOT,COLD} e16b8d640ec99 samples/damon/mtier: error out for zero quota goal target values 460181e4bb47a mm/damon/ops-common: putback folios on invalid migrate nid 6dd7a06894d6d ring-buffer: Fix crash passing ERR_PTR to kthread_stop() 688c71bed6852 misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free af6345159abcb misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke 9bf22a7d950ce misc: fastrpc: Remove buffer from list prior to unmap operation c5a03c2cadd2f misc: fastrpc: fix channel ctx ref leak when session alloc fails cd02b93863159 misc: fastrpc: Fix initial memory allocation for Audio PD memory pool 8b3e4ed9c35d3 staging: rtl8723bs: validate monitor transmit frame lengths a28a4b0592e4a staging: rtl8723bs: fix missing shared-key auth challenge length check e5b7610008f4e staging: rtl8723bs: fix OOB read in WMM_param_handler() e167a38a8a8f5 staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() 5974cb66681ea serial: amba-pl011: synchronize DMA teardown 759ead98a39fb serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ 2a0ee25f75cdb serial: amba-pl011: fix indefinite RS485 post-send delay 3ce24bc4d1153 serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx ae05d9e50b6b9 serial: 8250_dma: Clear stale RX state on shutdown 1c31e2377f4c1 serial: qcom-geni: fix TX DMA buffer flush dd6946a70ddbd rust_binder: do not query current thread for all ioctls 9dbe1d0111893 nvmem: layouts: Add fixed-layout driver da59844f561d1 nvmem: apple-spmi-nvmem: wrap regmap calls to satisfy CFI 104c2e8b8e38b mei: pull kvfree out of spinlock 63996ffc594d1 ipv4: fix use-after-free in fib_nhc_update_mtu() a59edda6eda12 ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops 94166072975aa selftests/bpf: Adapt sockmap update error handling edee58a9c460a selftests/bpf: Ensure UDP sockets are bound dc0c462fa838c Bluetooth: btusb: Add TP-Link UB600 for Realtek 8761BUV 373d425f7638a Bluetooth: btrtl: fix RTL8761B/BU broken LE extended scan 8545f4ef9eae6 netfilter: nf_tables: avoid softlockup warnings in nft_chain_validate 7b8c53263f887 futex: Prevent robust futex exit race some more cf8a9672fc25c iommu/vt-d: Gather the unmapped range before freeing its page tables 643b410bdfa48 dt-bindings: crypto: qcom,ice: Fix missing power-domain and iface clk 8d817ef1aa4e9 KVM: s390: pci: Fix aisb calculation cf895cd72e404 blk-mq: reinsert cached request to the list 97e2d08de282e blk-mq: pop cached request if it is usable 59b07ccca4c05 Revert "drm/amd/display: Fix backlight max_brightness to match exported range" 5912cf1822fbe net: bridge: mrp: fix uninitialised bytes on the wire 47a119ec8a7e2 netfilter: ebt_nflog: pin the NFLOG backend a0e76de6a2f28 igc: fix netdev not re-attached after resume if interface is down e6cd416a899ed mac802154: fix netdev use-after-free in beacon worker 9f904dd3e4557 inet: frags: publish queues before arming timer dbb30dc943a93 net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header 99ae2239069ed net: octeontx2-pf: Fix UB in shift operation a4b14a4df29d3 net/sched: reject overly deep qdisc hierarchies 23716dd9d8d46 net: openvswitch: reallocate update replies for mismatched IDs 5f30f9c302cea net: fix skb length accounting after generic XDP frag adjustment 2c7b5eb87b2b2 packet: synchronize pressure clearing with ring reconfiguration 971aa7d99242b net/packet: reset the MAC header on the packet-socket transmit path 27e068d1b35db packet: use consistent hard_header_len in TX_RING send path 5bb10753d428a packet: use consistent hard_header_len in non-ring send paths 75eec935444db ipvs: clear IPv4 options after rebasing tunnel ICMP errors 0f88fe0552bee ipvs: properly update the overload flag on dest edit 59b90c17bec5b ipvs: add totalconns for dest e7f34f29b3302 ipvs: stop estimator after disabled calc phase 27f3924061592 ima: fix out-of-bounds read in xattr_verify() c5bf8cd148cfe mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF bd3c4108a56de Input: evdev - fix information leak in evdev_pass_values() b664592e9ba8c vt: stabilize tty reference in kbd_keycode with tty_port_tty_get a1c31e026c93e vt: add permission check for KDSKBMETA ioctl 2c7496124e94c net: usb: ipheth: fix carrier_work UAF on disconnect 58733b1dd46bb net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() d328fdc607fa1 usb: gadget: f_ncm: Use unsigned int for ndp_index 2dfefdd498ab4 usb: cdnsp: fix incorrect endian conversions for APB timeout register 6e4c09bea8e9c thunderbolt: icm: Preserve USB4 proxy data-valid bit 2f73a065791d2 usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() ebfd1e82ab0a6 usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg 04b71290fb419 usb: quirks: Add ShanWan gamepad to quirk list 1740fd2aaa8fd usb: core: Add quirk for 255-bytes initial config read 0a235379825e1 ALSA: usb-audio: fix OOB write on Type II inbound URBs 4034ef247a9dd Input: evdev - sanitize event type index when fetching event masks 8b444b126cd8e net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() fad7cecb5c2c0 net: fec: do not release NULL pages when RX buffer allocation fails c768fb2e43c8a hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt de58b90a4d141 hwmon: (ltc4282) Clamp negative current limits 124bd4b006199 hwmon: (ltc4282) Avoid overflow in maximum power calculation 678a76c8fd33d hwmon: (ads7828) Fix external VREF regulator handling 5ee1f603a64bd hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination 29fe74c9aa69d watchdog: at91sam9_wdt: prevent timer rearm during teardown 6d1d3ca6c8f4a tls: don't abort the connection on signal-interrupted sends 18d704bdd8093 sctp: clear control chunk transport if it is being removed 9f77c1ab38218 net/atm: fix slab-out-of-bounds read in vcc_setsockopt() fc3021284050e s390/ism: Fix UAF of sba and ieq during ism_dev_exit() 8fa684db8709b bnge: Fix resource leak in bnge_init_nic() error path a837deeaa37cc ata: pata_sl82c105: fix bridge revision use-after-free 4dd71cb0d23d4 net: thunderbolt: Tear down DMA paths before stopping the rings 78e5ebcd1c10e net/smc: fix TOCTOU race between smc_listen_out() and listener close c8f256dc84920 net: remove WARN_ON_ONCE() from sk_mc_loop() 363e048a9d0a6 net: prestera: validate firmware header length 02226af693627 net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length 12afa450a6a6c netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() 25d40cf9dab15 netfilter: flowtable: consolidate xmit path a66e869cf0c90 tcp: fix TFO max_qlen accounting across reuseport migration 6c24ec01fb768 sctp: fix addip_serial increment on ASCONF_ACK allocation failure 1e8f24b1e3fee bnxt_en: Fix PTP PPS setting bug aab3b5f4d8ec8 bnxt_en: Disable EOP for TPA on all chips to prevent data corruption 6a2e50924e57e bnxt_en: Refresh VNIC default ring on queue restart if needed f1a4e95e296b2 bnxt_en: Determine and store default RX ring in vnic structure 965c45be24e15 bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss() 88664c48d7d1e net/mlx5e: fix BQL reset on SQ re-activation beb47092fe8fc bnge: use int for bnge_fix_rings_count() return value 4901b23b5ca7b net: stmmac: resume PHY before hardware setup when opening the interface 99b7bcee01589 selftests/ftrace: refactor eprobes test to fix argument checks a7a00ecf54243 hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations 2e5ea8272ceae hwmon: (nzxt-smart2) Check return value of init_device() in probe 9fccf43f05317 drm/xe/uc: Apply RCS/CCS yield policy to SR-IOV VFs d6222af7274f0 net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers a8139285c8925 net/openvswitch: check Ethernet header length in key_extract() a06e4611d4551 vhost-scsi: reject feature changes after endpoint 2417a498cf3fe vhost-scsi: Validate T10 PI scatterlist counts cd2f1d9fe8a50 net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter 64d322c288577 udp: fix potential use-after-free in tunnel segmentation 5fd121971912d xsk: validate metadata when processing requests 1a1534cc3b419 xsk: move xsk_tx_metadata_request() to xdp_sock_drv.h af511afa1d297 xsk: validate launch-time metadata size 0ba2e1eb07a82 xsk: clear metadata pointer when no timestamp is requested 5ec4f525373bc xsk: pass TX metadata pointer by reference 642c6e73fce17 xsk: require at least 16 bytes of TX metadata b0b7202f751bb bnxt: fix memory leak in bnxt_queue_mem_alloc error cases ad9ffc61fafeb eth: bnxt: support qcfg provided rx page size cd5485a702efd eth: bnxt: store rx buffer size per queue 9c1406e2ecd2e net: pass queue rx page size from memory provider b3fecb888e94b net: add bare bone queue configs 96197286b0ac8 net: reduce indent of struct netdev_queue_mgmt_ops members 34debe05685d1 bnxt_en: Do not set EOP on RX AGG BDs on 5760X chips 5ba1a458c5e26 tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss() 821f6416e6978 hwmon: (pmbus) Fix type confusion in notification logic 11720d869be1a hwmon: (pmbus_core) Use guard() for mutex protection cde8931a25392 vdpa/mlx5: Fix buffer length in create_direct_keys() a1c236b385d85 vhost/vdpa: reject overflowing PA map page counts on 32-bit cefcbbe20846a bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() 846ce792b6dd2 counter: microchip-tcb-capture: Fix DT channel validation 80094352bd40b net/mlx5: fw_tracer, return NULL on create error 7b02c6d2a3cd2 devlink: fix net namespace reference leak in reload 1efcc71140094 net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete 0e7a8cf8895b0 net/sched: cls_route: fix fastmap use-after-free on filter 10cb31b2b74cb net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() d8a6f79935205 bpf: Propagate untrusted pointer state in commuted arithmetic c2da73a1f715f bpf: split check_reg_sane_offset() in two parts db6382ed3361b bpf: Preserve pointer state for commuted arithmetic 24a8f2c29aebb btrfs: fix memory leak in btrfs_do_encoded_write() 26e968526eb53 watchdog: bd96801_wdt: Fix timeout for enabled WDG b3ff48c4ea8b2 ipvs: return the csum validation for forward hook a69a4b3fff581 ipvs: avoid out-of-bounds write in ip_vs_nat_icmp 1e8a5467a7a7b netfilter: ipset: switch ext_size to atomic64_t 970e9494f44af pds_core: cancel pending PCI reset work on AER recovery ef8e37ac448d4 pds_core: keep the health thread stopped during reset ff9e7d5e3500b net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock e506e704b7474 enic: fix tx_hang_reset use-after-free on device removal 2faf75a8a0650 bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor 35ddcc856b5b3 Revert "net: thunderbolt: Enable end-to-end flow control also in transmit" d512823059af8 net: hns3: fix speed configuration residue after driver reload 8701a643db231 drm/bridge: ps8640: propagate AUX transfer register errors d47212d866906 ovpn: fix incorrect use of rcu_access_pointer() 54dd83f24b913 ovpn: ensure TCP vars are initialized first f34949d63cbbe ovpn: disable IPv4 redirects on MP interfaces e774f7d8fc733 ovpn: hash floated peer by transport identity only 9a776388ef8d5 ovpn: zero-initialize sockaddr before learning a floated endpoint 61fb3cca40ff9 ovpn: ensure socket is owned by ovpn before deref sk_user_data 157164812a0c5 ovpn: rehash peer in by_transp_addr table on CMD_PEER_SET d20c181088984 ovpn: skip rehash for peers already removed from by_id 9e5e88fbfc87d ARM: dts: BCM5301X: fix PCIe controller 2 second interrupt 92b9d92a35a0f ovpn: add missing rtnl_link_ops->get_size callback d740dea9e2557 pinctrl: qcom: ipq806x: mark pci reset as a GPIO pin function 23c94a468efe3 pinctrl: qcom: ipq806x: mark gpio as a GPIO pin function 913d2295b772e selftests/sched_ext: Handle sleeping task affinity changes in numa test ce0212d230bd6 ARM: npcm: Fix OF node refcount leaks in SMP setup ccf6738adcafa xfs: handle NULL b_addr in xfs_buf_free d90599a42f6c5 arm64: dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer d71dfffa512e7 NFS: Pin the 'struct nfs_server' during a FREE_STATEID call bd45b89d7346f arm64: dts: qcom: sdm850-lenovo-yoga-c630: lower PSCI cluster idle df9d22383d7c0 arm64: dts: qcom: purwa: Fix GPU IOMMU property 7a6e90afb696c arm64: dts: qcom: rename x1p42100 to purwa 1e2b408c1a769 arm64: dts: qcom: Rework X1-based Asus Zenbook A14's displays 387edbe4706b6 arm64: dts: qcom: rename x1e80100 to hamoa d089f32d34f82 drm/amd/display: Check for tg ops in dce110_set_avmute 8aba384bfc8aa drm/amd/display: Add AV mute wait frames to dce110_set_avmute 50359c42e0eba selftests/bpf: Fail unbound UDP on sockmap update 62fefb817bb3b sched/fair: Revert 6d71a9c61604 ("sched/fair: Fix EEVDF entity placement bug causing scheduling lag") 4043e196dc882 sched/fair: Separate se->vlag from se->vprot 9a3eef676cd8b mount: honour SB_NOUSER in the new mount API 79a45d44323b3 KVM: s390: pci: Fix resource leak on IRQ registration failure Signed-off-by: Bruce Ashfield Signed-off-by: Richard Purdie (cherry picked from commit d73679f9104c507abf7756795c879a94a393e647) Signed-off-by: Yoann Congal --- meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend b/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend index cea5e3df..3fd33fcd 100644 --- a/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend +++ b/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend @@ -8,4 +8,4 @@ KMACHINE:genericx86 ?= "common-pc" KMACHINE:genericx86-64 ?= "common-pc-64" KBRANCH:genericarm64 ?= "v6.18/standard/genericarm64" -SRCREV_machine:genericarm64 ?= "e53bc6de014bcdd6615eeed206ef14ebe67c423b" +SRCREV_machine:genericarm64 ?= "5b1e83ae84e1bbe2ab8197bf2ea3c24302f7d1e3"