FlawAtlas
Search the atlas
SUSE-SU-2026:23068-1 Not scored

Security update for the Linux Kernel

The SUSE Linux Enterprise 16.0 kernel was updated to fix various security issues: The following security issues were fixed: - CVE-2026-23259: io_uring/rw: free potentially allocated iovec on cache put failure (bsc#1259866). - CVE-2026-31443: dmaengine: idxd: Fix crash when the event log is disabled (bsc#1262652). - CVE-2026-31561: x86/cpu: Remove X86_CR4_FRED from the CR4 pinned bits mask (bsc#1263059). - CVE-2026-43091: xfrm: Wait for RCU readers during policy netns exit (bsc#1264267). - CVE-2026-43114: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (bsc#1264601). - CVE-2026-43168: ocfs2: fix reflink preserve cleanup issue (bsc#1264537). - CVE-2026-43172: wifi: iwlwifi: fix 22000 series SMEM parsing (bsc#1264543). - CVE-2026-43204: ASoC: qcom: q6asm: handle the responses after closing (bsc#1264531). - CVE-2026-43216: net: Drop the lock in skb_may_tx_timestamp() (bsc#1264319). - CVE-2026-43230: net/rds: Clear reconnect pending bit (bsc#1264539). - CVE-2026-43244: kcm: fix zero-frag skb in frag_list on partial sendmsg error (bsc#1264321). - CVE-2026-43262: gfs2: fiemap page fault fix (bsc#1264422). - CVE-2026-43266: EFI/CPER: don't go past the ARM processor CPER record buffer (bsc#1264418). - CVE-2026-43273: ceph: supply snapshot context in ceph_zero_partial_object() (bsc#1264446). - CVE-2026-43275: scsi: ufs: core: Flush exception handling work when RPM level is zero (bsc#1264303). - CVE-2026-43281: mailbox: Prevent out-of-bounds access in fw_mbox_index_xlate() (bsc#1264534). - CVE-2026-43304: libceph: define and enforce CEPH_MAX_KEY_LEN (bsc#1264993). - CVE-2026-43308: btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref() (bsc#1264712). - CVE-2026-43309: md raid: fix hang when stopping arrays with metadata through dm-raid (bsc#1264827). - CVE-2026-43353: i3c: mipi-i3c-hci: Fix race in DMA ring dequeue (bsc#1265089). - CVE-2026-43424: usb: gadget: f_tcm: Fix NULL pointer dereferences in nexus handling (bsc#1264678). - CVE-2026-43445: e1000/e1000e: Fix leak in DMA error cleanup (bsc#1265041). - CVE-2026-43451: netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path (bsc#1265009). - CVE-2026-43496: net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1266000). - CVE-2026-45839: bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() (bsc#1266399). - CVE-2026-45845: net/sched: taprio: fix NULL pointer dereference in class dump (bsc#1266393). - CVE-2026-45849: net: mscc: ocelot: extract ocelot_xmit_timestamp() helper (bsc#1266690). - CVE-2026-45859: netfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation (bsc#1266714). - CVE-2026-45865: mctp i2c: initialise event handler read bytes (bsc#1266694). - CVE-2026-45873: netfilter: nft_set_rbtree: check for partial overlaps in anonymous sets (bsc#1266715). - CVE-2026-45895: quota: fix livelock between quotactl and freeze_super (bsc#1266882). - CVE-2026-45905: xfrm: fix ip_rt_bug race in icmp_route_lookup reverse path (bsc#1266685). - CVE-2026-45913: net: bridge: mcast: always update mdb_n_entries for vlan contexts (bsc#1266891). - CVE-2026-45915: fat: avoid parent link count underflow in rmdir (bsc#1266896). - CVE-2026-45917: ipvs: do not keep dest_dst if dev is going down (bsc#1266900). - CVE-2026-45930: net: mctp: ensure our nlmsg responses are initialised (bsc#1266730). - CVE-2026-45944: iommu/vt-d: Clear Present bit before tearing down context entry (bsc#1267203). - CVE-2026-45973: RDMA/mlx5: Fix UMR hang in LAG error state unload (bsc#1267025). - CVE-2026-45981: s390/cio: Fix device lifecycle handling in css_alloc_subchannel() (bsc#1267204). - CVE-2026-45994: ibmasm: fix OOB reads in command_file_write due to missing size checks (bsc#1267432). - CVE-2026-46003: net: qrtr: ns: Limit the total number of nodes (bsc#1267210). - CVE-2026-46015: tcp: call sk_data_ready() after listener migration (bsc#1267439). - CVE-2026-46023: dm mirror: fix integer overflow in create_dirty_log() (bsc#1267449). - CVE-2026-46026: net: qrtr: ns: Limit the maximum number of lookups (bsc#1266876). - CVE-2026-46027: net/smc: avoid early lgr access in smc_clc_wait_msg (bsc#1266744). - CVE-2026-46033: crypto: authencesn - reject short ahash digests during instance creation (bsc#1266692). - CVE-2026-46034: vfio/cdx: Fix NULL pointer dereference in interrupt trigger path (bsc#1266757). - CVE-2026-46036: vfio/cdx: Serialize VFIO_DEVICE_SET_IRQS with a per-device mutex (bsc#1267470). - CVE-2026-46038: net: qrtr: ns: Free the node during ctrl_cmd_bye() (bsc#1266695). - CVE-2026-46040: inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails (bsc#1267472). - CVE-2026-46064: ibmasm: fix heap over-read in ibmasm_send_i2o_message() (bsc#1267497). - CVE-2026-46068: crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx (bsc#1267592). - CVE-2026-46086: net: bridge: use a stable FDB dst snapshot in RCU readers (bsc#1267524). - CVE-2026-46089: zram: do not forget to endio for partial discard requests (bsc#1267445). - CVE-2026-46102: net: strparser: fix skb_head leak in strp_abort_strp() (bsc#1267502). - CVE-2026-46121: mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock (bsc#1266932). - CVE-2026-46127: RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() (bsc#1267236). - CVE-2026-46130: dm-verity-fec: fix reading parity bytes split across blocks (take 3) (bsc#1267629). - CVE-2026-46132: net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo (bsc#1267616). - CVE-2026-46137: mptcp: pm: ADD_ADDR rtx: fix potential data-race (bsc#1267570). - CVE-2026-46147: KVM: arm64: Factor out pKVM hyp vcpu creation to separate function (bsc#1267689). - CVE-2026-46149: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (bsc#1267648). - CVE-2026-46158: mptcp: pm: ADD_ADDR rtx: always decrease sk refcount (bsc#1266880). - CVE-2026-46168: mptcp: sockopt: set timestamp flags on subflow socket, not msk (bsc#1266869). - CVE-2026-46170: mptcp: disable add_addr retransmission when timeout is 0 (bsc#1267714). - CVE-2026-46189: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (bsc#1266918). - CVE-2026-46191: fbcon: Avoid OOB font access if console rotation fails (bsc#1267690). - CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks (bsc#1267656). - CVE-2026-46207: vsock/virtio: fix length and offset in tap skb for split packets (bsc#1267691). - CVE-2026-46216: drm/xe/hdcp: Add NULL check for media_gt in (bsc#1267234). - CVE-2026-46234: vsock: fix buffer size clamping order (bsc#1266904). - CVE-2026-46245: drm/amd/display: Fix dc_link NULL handling in HPD init (bsc#1267678). - CVE-2026-46249: octeontx2-af: Fix PF driver crash with kexec kernel booting (bsc#1267683). - CVE-2026-46265: RDMA/hns: Fix WQ_MEM_RECLAIM warning (bsc#1267662). - CVE-2026-46287: net: txgbe: fix RTNL assertion warning when remove module (bsc#1267954). - CVE-2026-46292: pmdomain: core: Fix detach procedure for virtual devices in genpd (bsc#1267943). - CVE-2026-46306: flow_dissector: do not dissect PPPoE PFC frames (bsc#1267986). - CVE-2026-46321: tun: free page on short-frame rejection in tun_xdp_one() (bsc#1268024). - CVE-2026-46324: netfilter: nf_tables: Introduce functions freeing nft_hook objects (bsc#1267995). - CVE-2026-46327: dm: fix unlocked test for dm_suspended_md (bsc#1268031). - CVE-2026-46329: erofs: handle end of filesystem properly for file-backed mounts (bsc#1268038). - CVE-2026-52913: batman-adv: v: stop OGMv2 on disabled interface (bsc#1268985). - CVE-2026-52915: netfilter: ip6t_hbh: reject oversized option lists (bsc#1269001). - CVE-2026-52916: batman-adv: frag: disallow unicast fragment in fragment (bsc#1269002). - CVE-2026-52921: netfilter: ipset: stop hash:* range iteration at end (bsc#1269024). - CVE-2026-52922: batman-adv: dat: handle forward allocation error (bsc#1269030). - CVE-2026-52925: vrf: Fix a potential NPD when removing a port from a VRF (bsc#1268987). - CVE-2026-52926: batman-adv: clear current gateway during teardown (bsc#1269025). - CVE-2026-52927: netfilter: ebtables: fix OOB read in compat_mtw_from_user (bsc#1269027). - CVE-2026-52930: ipc/shm: serialize orphan cleanup with shm_nattch updates (bsc#1269003). - CVE-2026-52934: batman-adv: tvlv: reject oversized TVLV packets (bsc#1268994). - CVE-2026-52937: tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR (bsc#1268983). - CVE-2026-52941: net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint (bsc#1268966). - CVE-2026-52942: netfilter: nf_log: validate MAC header was set before dumping it (bsc#1268967). - CVE-2026-52947: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (bsc#1269115). - CVE-2026-52953: iommu/vt-d: Fix oops due to out of scope access (bsc#1269133). - CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). - CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). - CVE-2026-52967: smb/client: fix possible infinite loop and oob read in symlink_data() (bsc#1269181). - CVE-2026-52970: netfilter: nft_ct: fix missing expect put in obj eval (bsc#1269229). - CVE-2026-52974: net: tls: fix strparser anchor skb leak on offload RX setup failure (bsc#1269233). - CVE-2026-52981: neigh: let neigh_xmit take skb ownership (bsc#1269254). - CVE-2026-52984: net/sched: netem: fix queue limit check to include reordered packets (bsc#1269272). - CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul (bsc#1269289). - CVE-2026-52988: netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase (bsc#1269362). - CVE-2026-52995: net/rds: zero per-item info buffer before handing it to visitors (bsc#1269124). - CVE-2026-52998: netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check (bsc#1269118). - CVE-2026-52999: netfilter: nfnetlink_osf: fix out-of-bounds read on option matching (bsc#1269119). - CVE-2026-53000: netfilter: nat: use kfree_rcu to release ops (bsc#1269117). - CVE-2026-53002: netfilter: conntrack: remove sprintf usage (bsc#1269112). - CVE-2026-53003: pppoe: drop PFC frames (bsc#1269111). - CVE-2026-53004: sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks (bsc#1269106). - CVE-2026-53005: af_unix: Drop all SCM attributes for SOCKMAP (bsc#1269107). - CVE-2026-53006: ipv6: fix possible UAF in icmpv6_rcv() (bsc#1269104). - CVE-2026-53009: ice: fix double-free of tx_buf skb (bsc#1269098). - CVE-2026-53011: net/sched: taprio: fix use-after-free in advance_sched() on schedule switch (bsc#1269094). - CVE-2026-53012: nexthop: fix IPv6 route referencing IPv4 nexthop (bsc#1269154). - CVE-2026-53013: macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF (bsc#1269095). - CVE-2026-53014: net/sched: act_mirred: fix wrong device for mac_header_xmit check in tcf_blockcast_redir (bsc#1269092). - CVE-2026-53032: bpf: Fix NULL deref in map_kptr_match_type for scalar regs (bsc#1269138). - CVE-2026-53035: bpf, sockmap: Fix af_unix iter deadlock (bsc#1269190). - CVE-2026-53038: ima_fs: Correctly create securityfs files for unsupported hash algos (bsc#1269391). - CVE-2026-53062: dm cache policy smq: fix missing locks in invalidating cache blocks (bsc#1269658). - CVE-2026-53063: dm cache: fix write hang in passthrough mode (bsc#1269659). - CVE-2026-53064: dm cache: fix null-deref with concurrent writes in passthrough mode (bsc#1269132). - CVE-2026-53069: net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master (bsc#1269186). - CVE-2026-53074: bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb (bsc#1269688). - CVE-2026-53083: bpf: Fix RCU stall in bpf_fd_array_map_clear() (bsc#1269964). - CVE-2026-53085: bpf: fix mm lifecycle in open-coded task_vma iterator (bsc#1269879). - CVE-2026-53088: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb (bsc#1269185). - CVE-2026-53101: wifi: mt76: mt7921: fix potential deadlock in mt7921_roc_abort_sync (bsc#1269415). - CVE-2026-53104: wifi: mt76: Fix memory leak destroying device (bsc#1269157). - CVE-2026-53106: bpf: Do not allow deleting local storage in NMI (bsc#1269990). - CVE-2026-53107: wifi: libertas: use USB anchors for tracking in-flight URBs (bsc#1269991). - CVE-2026-53121: amd-pstate: Fix memory leak in amd_pstate_epp_cpu_init() (bsc#1269198). - CVE-2026-53123: md: wake raid456 reshape waiters before suspend (bsc#1269643). - CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr() (bsc#1269773). - CVE-2026-53132: vsock/virtio: fix potential unbounded skb queue (bsc#1269290). - CVE-2026-53134: netfilter: nft_fib: fix stale stack leak via the OIFNAME register (bsc#1269819). - CVE-2026-53157: net: phonet: free phonet_device after RCU grace period (bsc#1269241). - CVE-2026-53175: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush (bsc#1269714). - CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake (bsc#1269886). - CVE-2026-53183: mptcp: allow subflow rcv wnd to shrink (bsc#1269376). - CVE-2026-53184: udp: clear skb->dev before running a sockmap verdict (bsc#1269689). - CVE-2026-53185: zram: fix use-after-free in zram_bvec_write_partial() (bsc#1269660). - CVE-2026-53186: RDMA/srp: bound SRP_RSP sense copy by the received length (bsc#1269663). - CVE-2026-53189: mm/huge_memory: update file PMD counter before folio_put() (bsc#1269797). - CVE-2026-53210: tee: shm: fix shm leak in register_shm_helper() (bsc#1269727). - CVE-2026-53212: netfilter: nft_tunnel: fix use-after-free on object destroy (bsc#1269672). - CVE-2026-53214: ipv6: Fix a potential NPD in cleanup_prefix_route() (bsc#1269588). - CVE-2026-53218: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (bsc#1269273). - CVE-2026-53221: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() (bsc#1269318). - CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997). - CVE-2026-53225: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() (bsc#1269711). - CVE-2026-53227: net: openvswitch: fix possible kfree_skb of ERR_PTR (bsc#1269877). - CVE-2026-53230: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (bsc#1269270). - CVE-2026-53233: netdev: fix double-free in netdev_nl_bind_rx_doit() (bsc#1269801). - CVE-2026-53235: net: add pskb_may_pull() to skb_gro_receive_list() (bsc#1269286). - CVE-2026-53236: tcp: restrict SO_ATTACH_FILTER to priv users (bsc#1269994). - CVE-2026-53239: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (bsc#1269677). - CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (bsc#1269675). - CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988). - CVE-2026-53247: net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown (bsc#1269235). - CVE-2026-53250: xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata() (bsc#1269808). - CVE-2026-53252: Bluetooth: fix memory leak in error path of hci_alloc_dev() (bsc#1269307). - CVE-2026-53260: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req() (bsc#1269731). - CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval (bsc#1269577). - CVE-2026-53268: netfilter: conntrack_irc: fix possible out-of-bounds read (bsc#1269257). - CVE-2026-53270: ipvs: clear the svc scheduler ptr early on edit (bsc#1269240). - CVE-2026-53273: tee: optee: prevent use-after-free when the client exits before the supplicant (bsc#1269713). - CVE-2026-53275: ipv6: mcast: Fix use-after-free when processing MLD queries (bsc#1269810). - CVE-2026-53289: ice: fix NULL pointer dereference in ice_reset_all_vfs() (bsc#1269694). - CVE-2026-53321: io_uring/napi: cap busy_poll_to 10 msec (bsc#1269724). - CVE-2026-53355: net: rds: clear i_sends on setup unwind (bsc#1270249). - CVE-2026-53369: udf: reject descriptors with oversized CRC length (bsc#1271818). - CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). - CVE-2026-53388: fuse: re-lock request before replacing page cache folio (bsc#1271825). - CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (bsc#1271904). - CVE-2026-53392: NFSv4/flexfiles: reject zero filehandle version count (bsc#1271826). - CVE-2026-53393: nfsd: reset write verifier on deferred writeback errors (bsc#1271858). - CVE-2026-53394: nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race (bsc#1271859). - CVE-2026-53397: nfsd: fix posix_acl leak on SETACL decode failure (bsc#1271869). - CVE-2026-53398: NFSD: Fix SECINFO_NO_NAME decode error cleanup (bsc#1271870). - CVE-2026-53399: nfsd: release layout stid on setlease failure (bsc#1271832). - CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of (bsc#1271908). - CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (bsc#1271964). - CVE-2026-63795: 9p: avoid putting oldfid in p9_client_walk() error path (bsc#1271955). - CVE-2026-63802: blk-cgroup: fix UAF in __blkcg_rstat_flush() (bsc#1272282). - CVE-2026-63809: bpf: NUL-terminate replaced sysctl value (bsc#1272296). - CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1272176). - CVE-2026-63831: mac802154: llsec: add skb_cow_data() before in-place crypto (bsc#1272184). - CVE-2026-63836: batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (bsc#1272246). - CVE-2026-63912: xfrm: esp: restore combined single-frag length gate (bsc#1272836). - CVE-2026-63919: xfrm: input: hold netns during deferred transport reinjection (bsc#1272907). - CVE-2026-63923: octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify (bsc#1273005). - CVE-2026-63952: memfd: deny writeable mappings when implying SEAL_WRITE (bsc#1272468). - CVE-2026-63968: ipv6: fix possible infinite loop in fib6_select_path() (bsc#1272466). - CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff (bsc#1272678). - CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp() (bsc#1273035). - CVE-2026-64025: bpf, skmsg: fix verdict sk_data_ready racing with ktls rx (bsc#1273117). - CVE-2026-64061: netfs: Fix early put of sink folio in netfs_read_gaps() (bsc#1272505). - CVE-2026-64091: batman-adv: tt: fix TOCTOU race for reported vlans (bsc#1272514). - CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (bsc#1272242). - CVE-2026-64157: netfs: Fix partial invalidation of streaming-write folio (bsc#1272462). - CVE-2026-64158: netfs: Fix write streaming disablement if fd open O_RDWR (bsc#1272524). - CVE-2026-64187: xfs: fail recovery on a committed log item with no regions (bsc#1272204). - CVE-2026-64188: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (bsc#1272150). - CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize (bsc#1272207). - CVE-2026-64357: xfs: fix exchmaps reservation limit check (bsc#1272612). - CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (bsc#1274072). - CVE-2026-64561: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (bsc#1273231). - CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (bsc#1271526). The following non security issues were fixed: - accel/ivpu: Fix wrong register read in LNL failure diagnostics (git-fixes). - accel/ivpu: Reject firmware log with size smaller than header (git-fixes). - ALSA: hda: codecs: hdmi: disable keep-alive before audio format change (git-fixes). - ALSA: hda: conexant: Remove mic bias threshold override (git-fixes). - ALSA: hda: cs35l41: validate and free ACPI mute object (git-fixes). - ALSA: hda: Fix cached processing coefficient verbs (git-fixes). - ALSA: lx6464es: fix period byte count for 16-bit streams (git-fixes). - ALSA: pcm: wake linked drain waiters on unlink (git-fixes). - ALSA: scarlett2: Allow selecting config_set by firmware version (stable-fixes). - ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417 (git-fixes). - ALSA: seq: close a re-opened queue timer in the destructor (git-fixes). - ALSA: seq: Fix division by zero in initialize_timer() (git-fixes). - ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes (git-fixes). - ALSA: timer: don't re-enter an instance callback that is still running (git-fixes). - ALSA: timer: drain a slave's callback before its master detaches it (git-fixes). - ALSA: ump: fix double free of out_cvts on rawmidi error (git-fixes). - ALSA: usb-audio: Clamp frame size in implicit-feedback mode (git-fixes). - ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set (git-fixes). - ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() (git-fixes). - ALSA: usb-audio: fix stack info leak in RME Digiface status (git-fixes). - ALSA: usb-audio: fix use-after-free in ump_to_endpoint() (git-fixes). - ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (git-fixes). - apparmor: fix use-after-free in rawdata dedup loop (git-fixes). - arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU (git-fixes). - ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() (git-fixes). - ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI (git-fixes). - ASoC: cs35l56: Fix potential probe() deadlock (git-fixes). - ASoC: cs35l56: Use complete_all() to signal init_completion (git-fixes). - ASoC: cs42l43: Correct report for forced microphone jack (git-fixes). - ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP (git-fixes). - ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup (git-fixes). - ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup (git-fixes). - ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (git-fixes). - ASoC: tas2562: fix broken entries in the volume lookup table (git-fixes). - ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (git-fixes). - ASoC: tas2562: fix DVC coefficient write order (git-fixes). - ASoC: tas2781: bound firmware description string parsing (git-fixes). - assoc_array: trim the final shortcut word using the current chunk end (git-fixes). - batman-adv: bla: reacquire gw address after skb realloc (git-fixes). - batman-adv: dat: ensure accessible eth_hdr proto field (git-fixes). - batman-adv: dat: fix tie-break for candidate selection (git-fixes). - batman-adv: fix batadv_skb_is_frag() kernel-doc (git-fixes). - batman-adv: fix VLAN priority offset (git-fixes). - batman-adv: frag: fix primary_if leak on failed linearization (git-fixes). - batman-adv: frag: free unfragmentable packet (git-fixes). - batman-adv: mcast: avoid OOB read of num_dests header (git-fixes). - batman-adv: tt: avoid request storms during pending request (git-fixes). - batman-adv: tt: prevent TVLV OOB check overflow (git-fixes). - bitops: use common function parameter names (git-fixes). - Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister (stable-fixes). - Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev (git-fixes). - Bluetooth: btintel: Validate length before parsing diagnostics TLV (git-fixes). - Bluetooth: btrtl: validate firmware patch bounds (git-fixes). - Bluetooth: btusb: Add USB ID 2c4e:0128 for Mercusys MA60XNB (stable-fixes). - Bluetooth: btusb: validate Realtek vendor event length (git-fixes). - Bluetooth: hci_qca: Clear memdump state on invalid dump size (git-fixes). - Bluetooth: hci_sync: Fix advertising data UAFs (git-fixes). - Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks (git-fixes). - Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback (git-fixes). - Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback (git-fixes). - Bluetooth: hci_sync: Protect UUID list traversal (git-fixes). - Bluetooth: HIDP: reject frames without a transaction header (git-fixes). - Bluetooth: HIDP: validate numbered report payloads (git-fixes). - Bluetooth: ISO: clear iso_data always when detaching conn from hcon (git-fixes). - Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release (git-fixes). - Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos (git-fixes). - Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis() (git-fixes). - Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp (git-fixes). - Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (git-fixes). - Bluetooth: mgmt: Translate HCI reason in Device Disconnected event (git-fixes). - Bluetooth: RFCOMM: Fix session UAF in set_termios (git-fixes). - Bluetooth: SCO: give the socket its own sco_conn reference (git-fixes). - btrfs: do not trim a device which is not writeable (bsc#1272568). - bus: sunxi-rsb: Always check register address validity (git-fixes). - can: bcm: add missing rcu list annotations and operations (git-fixes). - can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (git-fixes). - can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure (git-fixes). - can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured (git-fixes). - can: ctucanfd: add missing MODULE_DEVICE_TABLE() (git-fixes). - can: ctucanfd: handle bus error interrupts (git-fixes). - can: ctucanfd: mark error-active controller status valid (git-fixes). - can: ctucanfd: unmap BAR0 using base address (git-fixes). - can: ctucanfd: use self-test mode for PRESUME_ACK (git-fixes). - can: ems_usb: validate CPC message lengths (git-fixes). - can: esd_usb: kill anchored URBs before freeing netdevs (git-fixes). - can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure (git-fixes). - can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure (git-fixes). - can: isotp: check register_netdevice_notifier() error in module init (git-fixes). - can: isotp: use unconditional synchronize_rcu() in isotp_release() (git-fixes). - can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer (git-fixes). - can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() (git-fixes). - can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents (git-fixes). - can: peak_usb: add bounds check for USB channel index (git-fixes). - can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error (git-fixes). - can: peak_usb: validate uCAN receive record lengths (git-fixes). - can: softing: fw_parse(): validate firmware record spans (git-fixes). - cdrom: fix stack out-of-bounds read in CDROMVOLCTRL (git-fixes). - comedi: comedi_parport: deal with premature interrupt (git-fixes). - crypto/xxhash: set downstream CRYPTO_ALG_FIPS_UNAPPROVED (bsc#1262160 jsc#PED-15986). - crypto: introduce downstream CRYPTO_ALG_FIPS_UNAPPROVED (bsc#1262160 jsc#PED-15986). - crypto: qat - keep VFs enabled during reset (stable-fixes). - crypto: qat - notify fatal error before AER reset preparation (stable-fixes). - dm cache policy smq: check allocation under invalidate lock (git-fixes). - dm cache: fix missing return in invalidate_committed's error path (git-fixes). - dmaengine: idxd: fix double free of wq, engine, and group structs (git-fixes). - dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() (git-fixes). - dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ (git-fixes). - dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA (git-fixes). - driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout() (git-fixes). - driver core: Guard deferred probe timeout extension with delayed_work_pending() (git-fixes). - driver core: Use mod_delayed_work to prevent lost deferred probe work (git-fixes). - Drivers: hv: vmbus: Set DMA coherent mask for VMBus devices (git-fixes). - drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (git-fixes). - drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (git-fixes). - drm/amd/display: set new_stream to NULL after release (git-fixes). - drm/amd/display: use proper context for logging (git-fixes). - drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) (git-fixes). - drm/amd/pm: fix amdgpu_pm_info power display units (git-fixes). - drm/amd/pm: fix smu13 power limit range calculation (git-fixes). - drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge (git-fixes). - drm/amdgpu: fix aperture mapping leak (git-fixes). - drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment (git-fixes). - drm/amdkfd: free MQD managers on DQM init failures (git-fixes). - drm/amdkfd: hold event_mutex while checkpointing CRIU events (git-fixes). - drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs (git-fixes). - drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (git-fixes). - drm/gfx10: Program DB_RING_CONTROL (git-fixes). - drm/i915/bios: range check LFP Data Block panel_type2 (git-fixes). - drm/i915/gem: Do not leak siblings[] on proto context error (git-fixes). - drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (git-fixes). - drm/i915/gt: use correct selftest config symbol (git-fixes). - drm/i915/selftests: Fix GT PM sort comparators (git-fixes). - drm/i915: ensure segment offset never exceeds allowed max (stable-fixes). - drm/i915: Return NULL on error in active_instance (git-fixes). - drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM (git-fixes). - drm/imagination: Fix double call to drm_sched_entity_fini() (git-fixes). - drm/imagination: fix error checking of pvr_vm_context_lookup() (git-fixes). - drm/imagination: Fix returned size for DRM_IOCTL_PVR_DEV_QUERY (git-fixes). - drm/imagination: Fix user array stride in pvr_set_uobj_array() (git-fixes). - drm/mediatek: Check CRTC state before freeing (git-fixes). - drm/mediatek: ovl_adaptor: balance component registrations (git-fixes). - drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick() (git-fixes). - drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced (git-fixes). - drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom() (git-fixes). - drm/panthor: Interrupt group start/resumption if group_bind_locked() fails (git-fixes). - drm/panthor: reject firmware sections with oversized data (git-fixes). - drm/panthor: return error on truncated firmware (git-fixes). - drm/panthor: validate firmware interface structure sizes (git-fixes). - drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove (git-fixes). - drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered (stable-fixes). - drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem (git-fixes). - drm/v3d: Reject invalid indirect BO handle in indirect CSD setup (git-fixes). - drm/vc4: hvs/v3d: Fix null dereference in unbind (git-fixes). - drm/vc4: Prevent shader BO mappings from becoming writable (git-fixes). - drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size (git-fixes). - drm/vc4: Zero the tile state data array before each BIN job (git-fixes). - drm/virtio: bound EDID block reads to the response buffer (git-fixes). - drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker (git-fixes). - drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure (git-fixes). - drm/vmwgfx: bound DMA command body size against suffix pointer (git-fixes). - drm/vmwgfx: drop dma_buf reference on foreign-fd prime import (git-fixes). - drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size (git-fixes). - drm/vmwgfx: reject DX_BIND_QUERY without a DX context (git-fixes). - drm/vmwgfx: use check_add_overflow for shader size+offset bound (git-fixes). - drm/vmwgfx: validate DRAW_PRIMITIVES header size before division (git-fixes). - drm/vmwgfx: validate external BO copy bounds for both stride paths (git-fixes). - drm/vmwgfx: Validate vmw_surface_metadata::array_size (git-fixes). - drm/xe/hw_engine: Fix double-free of managed BO in error path (git-fixes). - drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays (git-fixes). - drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() (git-fixes). - drm/xe/wopcm: fix WOPCM size for LNL+ (git-fixes). - drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds (git-fixes). - drm/xe: remove duplicate <kunit/test-bug.h> include (git-fixes). - erofs: set fileio bio failed in short read case (git-fixes). - fbcon: fix NULL pointer dereference for a console without vc_data (stable-fixes). - fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git-fixes). - fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() (git-fixes). - fbdev: efifb: fix memory leak in efifb_probe() (git-fixes). - fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). - fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). - fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git-fixes). - fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). - fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git-fixes). - fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). - fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). - fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). - fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). - fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git-fixes). - fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). - fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). - firewire: net: Fix fragmented datagram reassembly (git-fixes). - firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (git-fixes). - firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits (git-fixes). - gpio-f7188x: Add support for NCT6126D version B (git-fixes). - gpio: davinci: fix IRQ domain leak on devm_kzalloc failure (git-fixes). - gpio: eic-sprd: use raw_spinlock_t in the irq startup path (git-fixes). - gpio: htc-egpio: use managed gpiochip registration (git-fixes). - gpio: mlxbf3: fail probe if gpiochip registration fails (git-fixes). - gpio: mvebu: fail probe if gpiochip registration fails (git-fixes). - gpio: mvebu: free generic chips on unbind (git-fixes). - gpio: pca953x: fix cache_only and IRQ state on restore_context() failure (git-fixes). - gpio: rockchip: change the GPIO version judgment logic (stable-fixes). - gpio: rockchip: fix generic IRQ chip leak on remove (git-fixes). - gpio: rockchip: teardown bugs and resource leaks (git-fixes). - gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe() (git-fixes). - gpio: tegra: do not call pinctrl for GPIO direction (git-fixes). - gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (git-fixes). - gpios: palmas: add .get_direction() op (git-fixes). - HID: add haptics page defines (stable-fixes). - HID: hid-sjoy: race between init and usage (git-fixes). - HID: pidff: Add missing spaces (stable-fixes). - HID: pidff: Fix missing blank lines after declarations (stable-fixes). - HID: playstation: validate num_touch_reports in DualShock 4 reports (stable-fixes). - hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread (git-fixes). - hwmon: (adt7470) Fix cache updated before hardware write on I2C error (git-fixes). - hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read (git-fixes). - hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors (git-fixes). - hwmon: (adt7470) Fix PWM auto temp state array and bounds check (git-fixes). - hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks (git-fixes). - hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() (git-fixes). - hwmon: (adt7470) Use cached PWM frequency value (git-fixes). - hwmon: (asus-ec-sensors) add missed handle for ENOMEM (git-fixes). - hwmon: (asus-ec-sensors) fix EC read intervals (git-fixes). - hwmon: (asus-ec-sensors) fix looping over banks while reading from EC (git-fixes). - hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop (git-fixes). - hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop (git-fixes). - hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop (git-fixes). - hwmon: (lm90) Only report alarms if driver is ready (git-fixes). - hwmon: (ltc4282) Fix reading the minimum alarm voltage (git-fixes). - hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 (git-fixes). - hwmon: (nct6775-core) Prevent access to unsupported weight registers (git-fixes). - hwmon: (npcm750-pwm-fan): stop fan timer on device detach (git-fixes). - hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop (git-fixes). - hwmon: (nzxt-smart2) DMA-align output buffer (git-fixes). - hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop (git-fixes). - hwmon: (pmbus) Fix return value from pmbus_update_byte_data() (git-fixes). - hwmon: (pmbus/core) notify on the hwmon device, not the i2c client (git-fixes). - hwmon: (sht3x) Fix unaligned accesses (git-fixes). - hwmon: (w83627hf) remove VID sysfs files on error and remove (stable-fixes). - hwmon: (w83793) remove vrm sysfs file on probe failure (stable-fixes). - hwmon: occ: validate poll response sensor blocks (git-fixes). - i2c: amd-mp2: Unregister callback on adapter add failure (git-fixes). - i2c: imx: Cancel hrtimer before clearing slave pointer (git-fixes). - i2c: imx: Fix slave registration race and error handling (git-fixes). - i2c: iproc: reset bus after timeout if START_BUSY is stuck (git-fixes). - i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock (git-fixes). - i2c: mediatek: fix WRRD for SoCs without auto_restart option (git-fixes). - i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() (git-fixes). - i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue (git-fixes). - i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring (git-fixes). - ieee802154: admin-gate legacy LLSEC dump operations (git-fixes). - ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation (git-fixes). - ieee802154: ca8210: fix cas_ctl leak on spi_async failure (git-fixes). - ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit (git-fixes). - ieee802154: fix kernel-infoleak in dgram_recvmsg() (git-fixes). - ieee802154: Remove WARN_ON() in cfg802154_pernet_exit() (git-fixes). - iio: accel: bmc150: clamp the device-reported FIFO frame count (git-fixes). - iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (git-fixes). - iio: adc: lpc32xx: Initialize completion before requesting IRQ (git-fixes). - iio: adc: spear: Initialize completion before requesting IRQ (git-fixes). - iio: adc: ti-ads124s08: Return reset GPIO lookup errors (git-fixes). - iio: adc: ti-ads1119: fix PM reference leak in buffer preenable (git-fixes). - iio: common: st_sensors: honour channel endianness in read_axis_data (git-fixes). - iio: event: Fix event FIFO reset race (git-fixes). - iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ (git-fixes). - iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (git-fixes). - iio: imu: inv_icm42600: fix timestamp clock period by using lower value (git-fixes). - iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading (git-fixes). - iio: imu: st_lsm6dsx: deselect shub page before reading whoami (git-fixes). - iio: light: al3010: fix incorrect scale for the highest gain range (git-fixes). - iio: light: gp2ap002: fix runtime PM leak on read error (git-fixes). - iio: light: tsl2591: return actual error from probe IRQ failure (git-fixes). - iio: magnetometer: ak8975: fix potential kernel stack memory leak (git-fixes). - iio: temperature: Build mlx90635 with CONFIG_MLX90635 (git-fixes). - Input: ads7846 - restore half-duplex support (git-fixes). - Input: atkbd - validate scancode in firmware keymap entries (git-fixes). - Input: elan_i2c - prevent division by zero and arithmetic underflow (git-fixes). - Input: goodix - clamp the device-reported contact count (git-fixes). - Input: iforce - bound the device-reported force-feedback effect index (git-fixes). - Input: ims-pcu - add response length checks (git-fixes). - Input: ims-pcu - fix DMA mapping violation in line setup (git-fixes). - Input: ims-pcu - fix firmware leak in async update (git-fixes). - Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (git-fixes). - Input: ims-pcu - fix logic error in packet reset (git-fixes). - Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging (git-fixes). - Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing (git-fixes). - Input: ims-pcu - fix race condition in reset_device sysfs callback (git-fixes). - Input: ims-pcu - fix type confusion in CDC union descriptor parsing (git-fixes). - Input: ims-pcu - fix use-after-free and double-free in disconnect (git-fixes). - Input: ims-pcu - only expose sysfs attributes on control interface (git-fixes). - Input: ims-pcu - release data interface on disconnect (git-fixes). - Input: ims-pcu - validate control endpoint type (git-fixes). - Input: maple_keyb - set driver data before registering input device (stable-fixes). - Input: maplecontrol - set driver data before registering input device (stable-fixes). - Input: maplemouse - fix NULL pointer dereference in open() (git-fixes). - Input: maplemouse - set driver data before registering input device (stable-fixes). - Input: mms114 - fix multi-touch slot corruption (git-fixes). - Input: mms114 - fix touch indexing for MMS134S and MMS136 (git-fixes). - Input: mms114 - reject an oversized device packet size (git-fixes). - Input: rmi4 - fix bit count in bitmap_copy() (git-fixes). - Input: rmi4 - fix limit in rmi_register_desc_has_subpacket() (git-fixes). - Input: rmi4 - fix memory leak in rmi_set_attn_data() (git-fixes). - Input: rmi4 - fix num_subpackets overflow in register descriptor (git-fixes). - Input: rmi4 - fix register descriptor address calculation (git-fixes). - Input: rmi4 - fix type overflow in register counts (git-fixes). - Input: rmi4 - initialize attn_fifo properly (stable-fixes). - Input: rmi4 - iterative IRQ handler (git-fixes). - Input: rmi4 - refactor F12 probe function (stable-fixes). - Input: rmi4 - refactor function allocation and registration (stable-fixes). - Input: rmi4 - refactor register descriptor parsing (git-fixes). - Input: rmi4 - tolerate short register descriptor structure (git-fixes). - Input: rmi4 - use local presence map in rmi_read_register_desc() (stable-fixes). - Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). - Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git-fixes). - Input: synaptics-rmi4 - unregister function handlers on physical driver registration failure (git-fixes). - Input: touchwin - reset the packet index on every complete packet (git-fixes). - intel_th: core: fix null pointer dereference in intel_th_irq (bsc#1248480). - intel_th: fix MSC output device reference leak (git-fixes). - io_uring/kbuf: don't truncate end buffer for bundles (bsc#1271290). - io_uring/kbuf: fix missing BUF_MORE for incremental buffers at EOF (bsc#1261250). - io_uring/kbuf: flag partial buffer mappings (bsc#1271290). - io_uring/kbuf: propagate BUF_MORE through early buffer commit path (bsc#1261250). - io_uring/net: always use current transfer count for buffer put (git-fixes). - io_uring/net: improve recv bundles (bsc#1271290). - io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries (bsc#1271290). - io_uring/net: only consider msg_inq if larger than 1 (git-fixes). - io_uring/net: only retry recv bundle for a full transfer (bsc#1271290). - io_uring/timeout: add helper for parsing user time (bsc#1271291). - io_uring/timeout: honour caller's time namespace for IORING_TIMEOUT_ABS (bsc#1271291). - io_uring/timeout: migrate reqs from ts64 to ktime (bsc#1271291). - io_uring/wait: honour caller's time namespace for IORING_ENTER_ABS_TIMER (bsc#1271291). - ixgbe: reduce number of reads when getting OROM data (bsc#1269637). - KVM: nSVM: Clear EVENTINJ fields in vmcb12 on nested #VMEXIT (git-fixes). - KVM: nSVM: Clear GIF on nested #VMEXIT(INVALID) (git-fixes). - KVM: nSVM: Clear tracking of L1->L2 NMI and soft IRQ on nested #VMEXIT (git-fixes). - KVM: nVMX: Hide shadow VMCS right after VMCLEAR (git-fixes). - KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state (git-fixes). - KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs (git-fixes). - KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug (git-fixes). - KVM: TDX: Reject concurrent change to CPUID entry count (git-fixes). - KVM: x86/mmu: Check write tracking in all address spaces (git-fixes). - KVM: x86/mmu: Fix use-after-free on vendor module reload (git-fixes). - KVM: x86/mmu: Preserve nested TDP shadow page tables if they are used as roots (git-fixes). - KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs (git-fixes). - KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN (git-fixes). - leds: uleds: Fix potential buffer overread (git-fixes). - mac802154: hold an interface reference across the scan worker (git-fixes). - mac802154: llsec: reject frames shorter than the authentication tag (git-fixes). - mac802154: Prevent overwrite return code in mac802154_perform_association() (git-fixes). - mac802154: remove interfaces with RCU list deletion (git-fixes). - mailbox: zynqmp: setup IPI for each valid child node (bsc#1271395). - mctp: Fix incorrect tx flow invalidation condition in mctp-i2c (bsc#1266694). - media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). - media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() (git-fixes). - media: atomisp: gc2235: fix UAF and memory leak (git-fixes). - media: cec: seco: unregister adapter on IR probe failure (git-fixes). - media: cedrus: Fix failure to clean up hardware on probe failure (git-fixes). - media: cedrus: Fix missing cleanup in error path (git-fixes). - media: cedrus: skip invalid H.264 reference list entries (git-fixes). - media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). - media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). - media: nxp: imx8-isi: Fix use-after-free on remove (git-fixes). - media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code (stable-fixes). - media: pci: dm1105: Free allocated workqueue (git-fixes). - media: qcom: camss: vfe: fix PIX subdev naming on VFE lite (git-fixes). - media: qcom: venus: drop extra padding in NV12 raw size calculation (git-fixes). - media: qcom: venus: relax encoder frame/blur dimension steps on v4 (git-fixes). - media: qcom: venus: relax encoder frame/blur step size on v6 (git-fixes). - media: rockchip: rga: fix too small buffer size (git-fixes). - media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe (git-fixes). - media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). - media: uvcvideo: Avoid partial metadata buffers (git-fixes). - media: uvcvideo: Do not add clock samples with small sof delta (git-fixes). - media: uvcvideo: Fix buffer sequence in frame gaps (git-fixes). - media: uvcvideo: Fix dev_sof filtering in hw timestamp (git-fixes). - media: uvcvideo: Fix sequence number when no EOF (git-fixes). - media: uvcvideo: Relax the constrains for interpolating the hw clock (git-fixes). - media: uvcvideo: Use hw timestaming if the clock buffer is full (git-fixes). - media: v4l2-common: Add YUV24 format info (git-fixes). - media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). - media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). - media: vidtv: fix reference leak on failed device registration (git-fixes). - media: vimc: fix reference leak on failed device registration (git-fixes). - media: vpif_capture: fix OF node reference imbalance (git-fixes). - mei: bus: access mei_device under device_lock on cleanup (git-fixes). - memory: tegra: Wire up system sleep PM ops (git-fixes). - memstick: ms_block: reject a card that reports too many blocks (git-fixes). - mfd: cros_ec: Delay dev_set_drvdata() until probe success (git-fixes). - mfd: cs42l43: Sanity check firmware size (git-fixes). - mfd: rsmu: Fix page register setup (git-fixes). - mfd: sm501: Fix reference leak on failed device registration (git-fixes). - mfd: tps6586x: Fix OF node refcount (git-fixes). - misc: nsm: only unlock nsm_dev on post-lock error paths (git-fixes). - misc: nsm: pin the module while the device is open (git-fixes). - mkspec-dtb: Skip missing DTBs. - mm: zero range of eof folio exposed by inode size extension (bsc#1272920). - mmc: block: fix RPMB device unregister ordering (git-fixes). - mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe() method (git-fixes). - mmc: vub300: defer reset until cmd_mutex is unlocked (git-fixes). - mshv: fix hv_input_get_system_property struct (git-fixes). - mtd: mchp23k256: use SPI match data for chip caps (git-fixes). - mtd: onenand: samsung: report DMA completion timeouts (git-fixes). - mtd: rawnand: fsl_ifc: return errors for failed page reads (git-fixes). - mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout (git-fixes). - mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout (git-fixes). - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (bsc#1271866). - net/x25: fix use-after-free in x25_kill_by_neigh() (git-fixes). - net: mana: Add Interrupt Moderation support (bsc#1271368). - net: mana: Return error code from mana_create_rxq() (git-fixes). - net: mctp i2c: Copy headers if cloned (bsc#1266694). - net: mctp-i2c: fix duplicate reception of old data (bsc#1266694). - net: thunderbolt: Fix frags overflow by bounding frame_count (git-fixes). - net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() (git-fixes). - net: usb: lan78xx: move functions to avoid forward definitions (stable-fixes). - net: wwan: t7xx: check skb_clone in control TX (git-fixes). - net: wwan: t7xx: destroy DMA pool on CLDMA late init failure (git-fixes). - netfs: Defer the emission of trace_netfs_folio() (git-fixes). - of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes). - phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access (git-fixes). - phy: phy-can-transceiver: Check driver match and driver data against NULL (git-fixes). - phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask (git-fixes). - phy: zynqmp: fix runtime PM leak on probe allocation failure (git-fixes). - phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB (git-fixes). - phy: zynqmp: use read-modify-write for SERDES scrambler bypass (git-fixes). - pinctrl-amd: Don't clear S4 wake bits at probe (git-fixes). - pinctrl: bm1880: add missing select GENERIC_PINCONF (git-fixes). - pinctrl: cs42l43: Fix polarity on debounce (git-fixes). - pinctrl: devicetree: don't free uninitialized dev_name on error path (git-fixes). - pinctrl: equilibrium: fix warning trace on load (git-fixes). - pinctrl: equilibrium: rename irq_chip function callbacks (stable-fixes). - pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). - pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). - pinctrl: meson: restore non-sleeping GPIO access (git-fixes). - pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table (git-fixes). - pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 (git-fixes). - pinctrl: qcom: Unconditionally mark gpio as wakeup enable (git-fixes). - pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path (git-fixes). - pkspec-dtb: Fix dtb-al rename. - platform/x86/amd/pmc: Add delay_suspend module parameter (stable-fixes). - platform/x86/amd/pmc: Avoid logging "(null)" for DMI values (git-fixes). - platform/x86/amd/pmc: Check for intermediate wakeup in function (stable-fixes). - platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops (stable-fixes). - platform/x86/amd/pmc: Don't log during intermediate wakeups (stable-fixes). - pmdomain: arm: scmi: Fix genpd leak on provider registration failure (git-fixes). - posix-cpu-timers: Cleanup the firing logic (bsc#1271912). - posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del() (bsc#1271912). - posix-cpu-timers: Prevent UAF caused by non-leader exec() race (bsc#1271912). - posix-timers: Add proper state tracking (bsc#1271912). - posix-timers: Avoid direct access to hrtimer clockbase (bsc#1271912). - posix-timers: Expand timer_arm() callbacks with a boolean return value (bsc#1271912). - power: sequencing: fix ABBA deadlock in pwrseq_device_unregister() (git-fixes). - power: supply: bq25890: fix the -10 C NTC lookup entry (git-fixes). - power: supply: max17040: handle missing status supplier (git-fixes). - RDMA/mana_ib: initialize err for empty send WR lists (git-fixes). - regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (git-fixes). - regulator: ltc3676: Fix incorrect IRQSTAT bit offsets (git-fixes). - regulator: mt6358: use regmap helper to read fixed LDO calibration (git-fixes). - remoteproc: qcom: Fix leak when custom dump_segments addition fails (git-fixes). - reset: sunxi: fix memory region leak on ioremap failure (git-fixes). - Revert "Input: rmi4 - fix register descriptor address calculation" (stable-fixes). - sctp: validate embedded address parameter length (git-fixes). - security/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref() (git-fixes). - selftests: Disable dad for ipv6 in fcnal-test.sh (bsc#1272871). - selftests: Replace sleep with slowwait (bsc#1272871). - serial: 8250_mid: Disable DMA for selected platforms (git-fixes). - serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (git-fixes). - serial: 8250_omap: clear rx_running on zero-length DMA completes (git-fixes). - serial: msm: Disable DMA for kernel console UART (git-fixes). - serial: sc16is7xx: implement gpio get_direction() callback (git-fixes). - soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). - soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). - soc: xilinx: Shutdown and free rx mailbox channel (git-fixes). - spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure (git-fixes). - spi: sh-msiof: abort transfers when reset times out (git-fixes). - staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy() (git-fixes). - staging: media: atomisp: reduce load_primary_binaries() stack usage (git-fixes). - staging: rtl8723bs: core: move constants to right side in comparison (stable-fixes). - staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie() (git-fixes). - staging: rtl8723bs: fix inverted HT40 secondary channel offset (git-fixes). - staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (git-fixes). - staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (git-fixes). - staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (git-fixes). - staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (git-fixes). - staging: rtl8723bs: fix OOB write in HT_caps_handler() (git-fixes). - staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (git-fixes). - thermal: core: Free thermal zone ID later during removal (git-fixes). - time: Switch to hrtimer_setup() (bsc#1271912). - tpm: Make the TPM character devices non-seekable (git-fixes). - uio_hv_generic: Bind to FCopy device by default (git-fixes). - usb: cdc_acm: Add quirk for Uniden BC125AT scanner (stable-fixes). - usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (git-fixes). - USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (git-fixes). - usb: chipidea: fix usage_count leak when autosuspend_delay is negative (git-fixes). - USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub (stable-fixes). - usb: core: port: Deattach Type-C connector on component unbind (git-fixes). - usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (git-fixes). - usb: dwc3: run gadget disconnect from sleepable suspend context (git-fixes). - usb: free iso schedules on failed submit (git-fixes). - usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (git-fixes). - usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback (git-fixes). - usb: gadget: f_fs: Fix DMA fence leak (git-fixes). - usb: gadget: f_midi: cancel pending IN work before freeing the midi object (git-fixes). - usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() (git-fixes). - usb: gadget: f_printer: take kref only for successful open (git-fixes). - USB: gadget: fsl-udc: fix device name leak on probe failure (git-fixes). - usb: gadget: function: rndis: add length check for header (stable-fixes). - usb: gadget: function: rndis: add length check to response query (stable-fixes). - usb: gadget: printer: fix infinite loop in printer_read() (git-fixes). - USB: gadget: snps-udc: fix device name leak on probe failure (git-fixes). - usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown (git-fixes). - usb: gadget: udc: Fix use-after-free in gadget_match_driver (stable-fixes). - usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer (git-fixes). - USB: idmouse: fix use-after-free on disconnect race (git-fixes). - USB: iowarrior: fix use-after-free on disconnect (git-fixes). - USB: iowarrior: fix use-after-free on disconnect race (git-fixes). - usb: iowarrior: remove inherent race with minor number (stable-fixes). - USB: ldusb: fix use-after-free on disconnect race (git-fixes). - USB: legousbtower: fix use-after-free on disconnect race (git-fixes). - USB: misc: uss720: unregister parport on probe failure (git-fixes). - usb: mtu3: unmap request DMA on queue failure (git-fixes). - USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD (stable-fixes). - USB: serial: digi_acceleport: fix broken rx after throttle (git-fixes). - USB: serial: digi_acceleport: fix hard lockup on disconnect (git-fixes). - USB: serial: digi_acceleport: fix write buffer corruption (git-fixes). - USB: serial: io_edgeport: cap received transmit credits (git-fixes). - USB: serial: io_ti: reject oversized boot-mode firmware (git-fixes). - USB: serial: keyspan_pda: fix data loss on receive throttling (git-fixes). - USB: serial: keyspan_pda: fix information leak (git-fixes). - USB: serial: mxuport: validate firmware header size (git-fixes). - USB: serial: option: add MeiG SRM813Q (stable-fixes). - USB: serial: option: add Telit Cinterion FE990D50 compositions (stable-fixes). - usb: sl811-hcd: disable controller wakeup on remove (git-fixes). - USB: storage: include US_FL_NO_SAME in quirks mask (git-fixes). - usb: typec: anx7411: use devm_pm_runtime_enable() (git-fixes). - usb: typec: class: drop PD lookup reference (git-fixes). - usb: typec: tcpm: Fix VDM type for Enter Mode commands (git-fixes). - usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (git-fixes). - usb: typec: ucsi: cancel pending work on system suspend (git-fixes). - usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (git-fixes). - usb: typec: ucsi: Detect and skip duplicate altmodes from buggy firmware (git-fixes). - usb: typec: ucsi: Invert DisplayPort role assignment (git-fixes). - usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (git-fixes). - USB: ulpi: fix memory leak on registration failure (git-fixes). - USB: usb-storage: ene_ub6250: restore media-ready check (git-fixes). - usb: xhci: Fix sleep in atomic context in xhci_free_streams() (git-fixes). - usbip: tools: support SuperSpeedPlus devices (git-fixes). - usbip: vudc: fix NULL deref in vep_dequeue() (git-fixes). - wan: wanxl: Only reset hardware after BAR mapping (git-fixes). - watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() (git-fixes). - wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() (git-fixes). - wifi: ath6kl: fix OOB access from firmware ADDBA window size (git-fixes). - wifi: ath6kl: fix OOB read from firmware IE lengths in connect event (git-fixes). - wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler (git-fixes). - wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (git-fixes). - wifi: ath10k: fix skb leak on incomplete msdu during rx pop (git-fixes). - wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin (git-fixes). - wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() (git-fixes). - wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (git-fixes). - wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (git-fixes). - wifi: brcmfmac: fix 802.1X-SHA256 call trace warning (git-fixes). - wifi: brcmfmac: make release_scratchbuffers idempotent (git-fixes). - wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read (git-fixes). - wifi: carl9170: fix buffer overflow in rx_stream failover path (git-fixes). - wifi: carl9170: fix OOB read from off-by-two in TX status handler (git-fixes). - wifi: iwlwifi: mvm: fix read in wake packet notification handler (git-fixes). - wifi: iwlwifi: mvm: validate SAR GEO response payload size (git-fixes). - wifi: mac80211: fix memory leak in ieee80211_register_hw() (git-fixes). - wifi: mac80211: free ack status frame on TX header build failure (git-fixes). - wifi: mac80211: recalculate TIM when a station enters power save (git-fixes). - wifi: mac80211: tear down new links on vif update error path (git-fixes). - wifi: mac80211: validate individual TWT params before driver setup (git-fixes). - wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() (git-fixes). - wifi: mt76: Disable napi when removing device (git-fixes). - wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses (git-fixes). - wifi: mt76: mt7915: guard HE capability lookups (git-fixes). - wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses (git-fixes). - wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (git-fixes). - wifi: mt76: mt7925: fix crash in reset link replay (git-fixes). - wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv() (git-fixes). - wifi: mt76: mt7925: guard link STA in decap offload (git-fixes). - wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() (git-fixes). - wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() (git-fixes). - wifi: mwifiex: bound uAP association event IEs to the event buffer (git-fixes). - wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper (git-fixes). - wifi: mwifiex: fix permanently busy scans after multiple roam iterations (git-fixes). - wifi: mwifiex: fix roaming to different channel in host_mlme mode (git-fixes). - wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (git-fixes). - wifi: rt2x00: avoid full teardown before work setup in probe (git-fixes). - wifi: wilc1000: validate assoc response length before subtracting header (git-fixes). - xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit (bsc#1264267). - xfs: only assert new size for datafork during truncate extents (bsc#1264084). - xfs: rearrange code in xfs_inode_item_precommit (bsc#1237449). - xfs: rework datasync tracking and execution (bsc#1237449). - xhci: dbgtty: fix device unregister (git-fixes). - xhci: dbgtty: fix device unregister: fixup (git-fixes).

Exploit probability Not scored
Published August 11, 2026
Required by Not available
Last source change August 15, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Micro 6.2 kernel-64kb
SUSE:Linux Micro 6.2 kernel-default
SUSE:Linux Micro 6.2 kernel-default-base
SUSE:Linux Micro 6.2 kernel-rt
SUSE:Linux Micro 6.2 kernel-source

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:23068-1

The SUSE Linux Enterprise 16.0 kernel was updated to fix various security issues: The following security issues were fixed: - CVE-2026-23259: io_uring/rw: free potentially allocated iovec on cache put failure (bsc#1259866). - CVE-2026-31443: dmaengine: idxd: Fix crash when the event log is disabled (bsc#1262652). - CVE-2026-31561: x86/cpu: Remove X86_CR4_FRED from the CR4 pinned bits mask (bsc#1263059). - CVE-2026-43091: xfrm: Wait for RCU readers during policy netns exit (bsc#1264267). - CVE-2026-43114: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (bsc#1264601). - CVE-2026-43168: ocfs2: fix reflink preserve cleanup issue (bsc#1264537). - CVE-2026-43172: wifi: iwlwifi: fix 22000 series SMEM parsing (bsc#1264543). - CVE-2026-43204: ASoC: qcom: q6asm: handle the responses after closing (bsc#1264531). - CVE-2026-43216: net: Drop the lock in skb_may_tx_timestamp() (bsc#1264319). - CVE-2026-43230: net/rds: Clear reconnect pending bit (bsc#1264539). - CVE-2026-43244: kcm: fix zero-frag skb in frag_list on partial sendmsg error (bsc#1264321). - CVE-2026-43262: gfs2: fiemap page fault fix (bsc#1264422). - CVE-2026-43266: EFI/CPER: don't go past the ARM processor CPER record buffer (bsc#1264418). - CVE-2026-43273: ceph: supply snapshot context in ceph_zero_partial_object() (bsc#1264446). - CVE-2026-43275: scsi: ufs: core: Flush exception handling work when RPM level is zero (bsc#1264303). - CVE-2026-43281: mailbox: Prevent out-of-bounds access in fw_mbox_index_xlate() (bsc#1264534). - CVE-2026-43304: libceph: define and enforce CEPH_MAX_KEY_LEN (bsc#1264993). - CVE-2026-43308: btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref() (bsc#1264712). - CVE-2026-43309: md raid: fix hang when stopping arrays with metadata through dm-raid (bsc#1264827). - CVE-2026-43353: i3c: mipi-i3c-hci: Fix race in DMA ring dequeue (bsc#1265089). - CVE-2026-43424: usb: gadget: f_tcm: Fix NULL pointer dereferences in nexus handling (bsc#1264678). - CVE-2026-43445: e1000/e1000e: Fix leak in DMA error cleanup (bsc#1265041). - CVE-2026-43451: netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path (bsc#1265009). - CVE-2026-43496: net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1266000). - CVE-2026-45839: bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() (bsc#1266399). - CVE-2026-45845: net/sched: taprio: fix NULL pointer dereference in class dump (bsc#1266393). - CVE-2026-45849: net: mscc: ocelot: extract ocelot_xmit_timestamp() helper (bsc#1266690). - CVE-2026-45859: netfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation (bsc#1266714). - CVE-2026-45865: mctp i2c: initialise event handler read bytes (bsc#1266694). - CVE-2026-45873: netfilter: nft_set_rbtree: check for partial overlaps in anonymous sets (bsc#1266715). - CVE-2026-45895: quota: fix livelock between quotactl and freeze_super (bsc#1266882). - CVE-2026-45905: xfrm: fix ip_rt_bug race in icmp_route_lookup reverse path (bsc#1266685). - CVE-2026-45913: net: bridge: mcast: always update mdb_n_entries for vlan contexts (bsc#1266891). - CVE-2026-45915: fat: avoid parent link count underflow in rmdir (bsc#1266896). - CVE-2026-45917: ipvs: do not keep dest_dst if dev is going down (bsc#1266900). - CVE-2026-45930: net: mctp: ensure our nlmsg responses are initialised (bsc#1266730). - CVE-2026-45944: iommu/vt-d: Clear Present bit before tearing down context entry (bsc#1267203). - CVE-2026-45973: RDMA/mlx5: Fix UMR hang in LAG error state unload (bsc#1267025). - CVE-2026-45981: s390/cio: Fix device lifecycle handling in css_alloc_subchannel() (bsc#1267204). - CVE-2026-45994: ibmasm: fix OOB reads in command_file_write due to missing size checks (bsc#1267432). - CVE-2026-46003: net: qrtr: ns: Limit the total number of nodes (bsc#1267210). - CVE-2026-46015: tcp: call sk_data_ready() after listener migration (bsc#1267439). - CVE-2026-46023: dm mirror: fix integer overflow in create_dirty_log() (bsc#1267449). - CVE-2026-46026: net: qrtr: ns: Limit the maximum number of lookups (bsc#1266876). - CVE-2026-46027: net/smc: avoid early lgr access in smc_clc_wait_msg (bsc#1266744). - CVE-2026-46033: crypto: authencesn - reject short ahash digests during instance creation (bsc#1266692). - CVE-2026-46034: vfio/cdx: Fix NULL pointer dereference in interrupt trigger path (bsc#1266757). - CVE-2026-46036: vfio/cdx: Serialize VFIO_DEVICE_SET_IRQS with a per-device mutex (bsc#1267470). - CVE-2026-46038: net: qrtr: ns: Free the node during ctrl_cmd_bye() (bsc#1266695). - CVE-2026-46040: inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails (bsc#1267472). - CVE-2026-46064: ibmasm: fix heap over-read in ibmasm_send_i2o_message() (bsc#1267497). - CVE-2026-46068: crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx (bsc#1267592). - CVE-2026-46086: net: bridge: use a stable FDB dst snapshot in RCU readers (bsc#1267524). - CVE-2026-46089: zram: do not forget to endio for partial discard requests (bsc#1267445). - CVE-2026-46102: net: strparser: fix skb_head leak in strp_abort_strp() (bsc#1267502). - CVE-2026-46121: mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock (bsc#1266932). - CVE-2026-46127: RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() (bsc#1267236). - CVE-2026-46130: dm-verity-fec: fix reading parity bytes split across blocks (take 3) (bsc#1267629). - CVE-2026-46132: net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo (bsc#1267616). - CVE-2026-46137: mptcp: pm: ADD_ADDR rtx: fix potential data-race (bsc#1267570). - CVE-2026-46147: KVM: arm64: Factor out pKVM hyp vcpu creation to separate function (bsc#1267689). - CVE-2026-46149: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (bsc#1267648). - CVE-2026-46158: mptcp: pm: ADD_ADDR rtx: always decrease sk refcount (bsc#1266880). - CVE-2026-46168: mptcp: sockopt: set timestamp flags on subflow socket, not msk (bsc#1266869). - CVE-2026-46170: mptcp: disable add_addr retransmission when timeout is 0 (bsc#1267714). - CVE-2026-46189: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (bsc#1266918). - CVE-2026-46191: fbcon: Avoid OOB font access if console rotation fails (bsc#1267690). - CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks (bsc#1267656). - CVE-2026-46207: vsock/virtio: fix length and offset in tap skb for split packets (bsc#1267691). - CVE-2026-46216: drm/xe/hdcp: Add NULL check for media_gt in (bsc#1267234). - CVE-2026-46234: vsock: fix buffer size clamping order (bsc#1266904). - CVE-2026-46245: drm/amd/display: Fix dc_link NULL handling in HPD init (bsc#1267678). - CVE-2026-46249: octeontx2-af: Fix PF driver crash with kexec kernel booting (bsc#1267683). - CVE-2026-46265: RDMA/hns: Fix WQ_MEM_RECLAIM warning (bsc#1267662). - CVE-2026-46287: net: txgbe: fix RTNL assertion warning when remove module (bsc#1267954). - CVE-2026-46292: pmdomain: core: Fix detach procedure for virtual devices in genpd (bsc#1267943). - CVE-2026-46306: flow_dissector: do not dissect PPPoE PFC frames (bsc#1267986). - CVE-2026-46321: tun: free page on short-frame rejection in tun_xdp_one() (bsc#1268024). - CVE-2026-46324: netfilter: nf_tables: Introduce functions freeing nft_hook objects (bsc#1267995). - CVE-2026-46327: dm: fix unlocked test for dm_suspended_md (bsc#1268031). - CVE-2026-46329: erofs: handle end of filesystem properly for file-backed mounts (bsc#1268038). - CVE-2026-52913: batman-adv: v: stop OGMv2 on disabled interface (bsc#1268985). - CVE-2026-52915: netfilter: ip6t_hbh: reject oversized option lists (bsc#1269001). - CVE-2026-52916: batman-adv: frag: disallow unicast fragment in fragment (bsc#1269002). - CVE-2026-52921: netfilter: ipset: stop hash:* range iteration at end (bsc#1269024). - CVE-2026-52922: batman-adv: dat: handle forward allocation error (bsc#1269030). - CVE-2026-52925: vrf: Fix a potential NPD when removing a port from a VRF (bsc#1268987). - CVE-2026-52926: batman-adv: clear current gateway during teardown (bsc#1269025). - CVE-2026-52927: netfilter: ebtables: fix OOB read in compat_mtw_from_user (bsc#1269027). - CVE-2026-52930: ipc/shm: serialize orphan cleanup with shm_nattch updates (bsc#1269003). - CVE-2026-52934: batman-adv: tvlv: reject oversized TVLV packets (bsc#1268994). - CVE-2026-52937: tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR (bsc#1268983). - CVE-2026-52941: net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint (bsc#1268966). - CVE-2026-52942: netfilter: nf_log: validate MAC header was set before dumping it (bsc#1268967). - CVE-2026-52947: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (bsc#1269115). - CVE-2026-52953: iommu/vt-d: Fix oops due to out of scope access (bsc#1269133). - CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). - CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). - CVE-2026-52967: smb/client: fix possible infinite loop and oob read in symlink_data() (bsc#1269181). - CVE-2026-52970: netfilter: nft_ct: fix missing expect put in obj eval (bsc#1269229). - CVE-2026-52974: net: tls: fix strparser anchor skb leak on offload RX setup failure (bsc#1269233). - CVE-2026-52981: neigh: let neigh_xmit take skb ownership (bsc#1269254). - CVE-2026-52984: net/sched: netem: fix queue limit check to include reordered packets (bsc#1269272). - CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul (bsc#1269289). - CVE-2026-52988: netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase (bsc#1269362). - CVE-2026-52995: net/rds: zero per-item info buffer before handing it to visitors (bsc#1269124). - CVE-2026-52998: netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check (bsc#1269118). - CVE-2026-52999: netfilter: nfnetlink_osf: fix out-of-bounds read on option matching (bsc#1269119). - CVE-2026-53000: netfilter: nat: use kfree_rcu to release ops (bsc#1269117). - CVE-2026-53002: netfilter: conntrack: remove sprintf usage (bsc#1269112). - CVE-2026-53003: pppoe: drop PFC frames (bsc#1269111). - CVE-2026-53004: sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks (bsc#1269106). - CVE-2026-53005: af_unix: Drop all SCM attributes for SOCKMAP (bsc#1269107). - CVE-2026-53006: ipv6: fix possible UAF in icmpv6_rcv() (bsc#1269104). - CVE-2026-53009: ice: fix double-free of tx_buf skb (bsc#1269098). - CVE-2026-53011: net/sched: taprio: fix use-after-free in advance_sched() on schedule switch (bsc#1269094). - CVE-2026-53012: nexthop: fix IPv6 route referencing IPv4 nexthop (bsc#1269154). - CVE-2026-53013: macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF (bsc#1269095). - CVE-2026-53014: net/sched: act_mirred: fix wrong device for mac_header_xmit check in tcf_blockcast_redir (bsc#1269092). - CVE-2026-53032: bpf: Fix NULL deref in map_kptr_match_type for scalar regs (bsc#1269138). - CVE-2026-53035: bpf, sockmap: Fix af_unix iter deadlock (bsc#1269190). - CVE-2026-53038: ima_fs: Correctly create securityfs files for unsupported hash algos (bsc#1269391). - CVE-2026-53062: dm cache policy smq: fix missing locks in invalidating cache blocks (bsc#1269658). - CVE-2026-53063: dm cache: fix write hang in passthrough mode (bsc#1269659). - CVE-2026-53064: dm cache: fix null-deref with concurrent writes in passthrough mode (bsc#1269132). - CVE-2026-53069: net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master (bsc#1269186). - CVE-2026-53074: bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb (bsc#1269688). - CVE-2026-53083: bpf: Fix RCU stall in bpf_fd_array_map_clear() (bsc#1269964). - CVE-2026-53085: bpf: fix mm lifecycle in open-coded task_vma iterator (bsc#1269879). - CVE-2026-53088: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb (bsc#1269185). - CVE-2026-53101: wifi: mt76: mt7921: fix potential deadlock in mt7921_roc_abort_sync (bsc#1269415). - CVE-2026-53104: wifi: mt76: Fix memory leak destroying device (bsc#1269157). - CVE-2026-53106: bpf: Do not allow deleting local storage in NMI (bsc#1269990). - CVE-2026-53107: wifi: libertas: use USB anchors for tracking in-flight URBs (bsc#1269991). - CVE-2026-53121: amd-pstate: Fix memory leak in amd_pstate_epp_cpu_init() (bsc#1269198). - CVE-2026-53123: md: wake raid456 reshape waiters before suspend (bsc#1269643). - CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr() (bsc#1269773). - CVE-2026-53132: vsock/virtio: fix potential unbounded skb queue (bsc#1269290). - CVE-2026-53134: netfilter: nft_fib: fix stale stack leak via the OIFNAME register (bsc#1269819). - CVE-2026-53157: net: phonet: free phonet_device after RCU grace period (bsc#1269241). - CVE-2026-53175: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush (bsc#1269714). - CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake (bsc#1269886). - CVE-2026-53183: mptcp: allow subflow rcv wnd to shrink (bsc#1269376). - CVE-2026-53184: udp: clear skb->dev before running a sockmap verdict (bsc#1269689). - CVE-2026-53185: zram: fix use-after-free in zram_bvec_write_partial() (bsc#1269660). - CVE-2026-53186: RDMA/srp: bound SRP_RSP sense copy by the received length (bsc#1269663). - CVE-2026-53189: mm/huge_memory: update file PMD counter before folio_put() (bsc#1269797). - CVE-2026-53210: tee: shm: fix shm leak in register_shm_helper() (bsc#1269727). - CVE-2026-53212: netfilter: nft_tunnel: fix use-after-free on object destroy (bsc#1269672). - CVE-2026-53214: ipv6: Fix a potential NPD in cleanup_prefix_route() (bsc#1269588). - CVE-2026-53218: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (bsc#1269273). - CVE-2026-53221: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() (bsc#1269318). - CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997). - CVE-2026-53225: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() (bsc#1269711). - CVE-2026-53227: net: openvswitch: fix possible kfree_skb of ERR_PTR (bsc#1269877). - CVE-2026-53230: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (bsc#1269270). - CVE-2026-53233: netdev: fix double-free in netdev_nl_bind_rx_doit() (bsc#1269801). - CVE-2026-53235: net: add pskb_may_pull() to skb_gro_receive_list() (bsc#1269286). - CVE-2026-53236: tcp: restrict SO_ATTACH_FILTER to priv users (bsc#1269994). - CVE-2026-53239: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (bsc#1269677). - CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (bsc#1269675). - CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988). - CVE-2026-53247: net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown (bsc#1269235). - CVE-2026-53250: xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata() (bsc#1269808). - CVE-2026-53252: Bluetooth: fix memory leak in error path of hci_alloc_dev() (bsc#1269307). - CVE-2026-53260: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req() (bsc#1269731). - CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval (bsc#1269577). - CVE-2026-53268: netfilter: conntrack_irc: fix possible out-of-bounds read (bsc#1269257). - CVE-2026-53270: ipvs: clear the svc scheduler ptr early on edit (bsc#1269240). - CVE-2026-53273: tee: optee: prevent use-after-free when the client exits before the supplicant (bsc#1269713). - CVE-2026-53275: ipv6: mcast: Fix use-after-free when processing MLD queries (bsc#1269810). - CVE-2026-53289: ice: fix NULL pointer dereference in ice_reset_all_vfs() (bsc#1269694). - CVE-2026-53321: io_uring/napi: cap busy_poll_to 10 msec (bsc#1269724). - CVE-2026-53355: net: rds: clear i_sends on setup unwind (bsc#1270249). - CVE-2026-53369: udf: reject descriptors with oversized CRC length (bsc#1271818). - CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). - CVE-2026-53388: fuse: re-lock request before replacing page cache folio (bsc#1271825). - CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (bsc#1271904). - CVE-2026-53392: NFSv4/flexfiles: reject zero filehandle version count (bsc#1271826). - CVE-2026-53393: nfsd: reset write verifier on deferred writeback errors (bsc#1271858). - CVE-2026-53394: nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race (bsc#1271859). - CVE-2026-53397: nfsd: fix posix_acl leak on SETACL decode failure (bsc#1271869). - CVE-2026-53398: NFSD: Fix SECINFO_NO_NAME decode error cleanup (bsc#1271870). - CVE-2026-53399: nfsd: release layout stid on setlease failure (bsc#1271832). - CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of (bsc#1271908). - CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (bsc#1271964). - CVE-2026-63795: 9p: avoid putting oldfid in p9_client_walk() error path (bsc#1271955). - CVE-2026-63802: blk-cgroup: fix UAF in __blkcg_rstat_flush() (bsc#1272282). - CVE-2026-63809: bpf: NUL-terminate replaced sysctl value (bsc#1272296). - CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1272176). - CVE-2026-63831: mac802154: llsec: add skb_cow_data() before in-place crypto (bsc#1272184). - CVE-2026-63836: batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (bsc#1272246). - CVE-2026-63912: xfrm: esp: restore combined single-frag length gate (bsc#1272836). - CVE-2026-63919: xfrm: input: hold netns during deferred transport reinjection (bsc#1272907). - CVE-2026-63923: octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify (bsc#1273005). - CVE-2026-63952: memfd: deny writeable mappings when implying SEAL_WRITE (bsc#1272468). - CVE-2026-63968: ipv6: fix possible infinite loop in fib6_select_path() (bsc#1272466). - CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff (bsc#1272678). - CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp() (bsc#1273035). - CVE-2026-64025: bpf, skmsg: fix verdict sk_data_ready racing with ktls rx (bsc#1273117). - CVE-2026-64061: netfs: Fix early put of sink folio in netfs_read_gaps() (bsc#1272505). - CVE-2026-64091: batman-adv: tt: fix TOCTOU race for reported vlans (bsc#1272514). - CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (bsc#1272242). - CVE-2026-64157: netfs: Fix partial invalidation of streaming-write folio (bsc#1272462). - CVE-2026-64158: netfs: Fix write streaming disablement if fd open O_RDWR (bsc#1272524). - CVE-2026-64187: xfs: fail recovery on a committed log item with no regions (bsc#1272204). - CVE-2026-64188: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (bsc#1272150). - CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize (bsc#1272207). - CVE-2026-64357: xfs: fix exchmaps reservation limit check (bsc#1272612). - CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (bsc#1274072). - CVE-2026-64561: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (bsc#1273231). - CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (bsc#1271526). The following non security issues were fixed: - accel/ivpu: Fix wrong register read in LNL failure diagnostics (git-fixes). - accel/ivpu: Reject firmware log with size smaller than header (git-fixes). - ALSA: hda: codecs: hdmi: disable keep-alive before audio format change (git-fixes). - ALSA: hda: conexant: Remove mic bias threshold override (git-fixes). - ALSA: hda: cs35l41: validate and free ACPI mute object (git-fixes). - ALSA: hda: Fix cached processing coefficient verbs (git-fixes). - ALSA: lx6464es: fix period byte count for 16-bit streams (git-fixes). - ALSA: pcm: wake linked drain waiters on unlink (git-fixes). - ALSA: scarlett2: Allow selecting config_set by firmware version (stable-fixes). - ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417 (git-fixes). - ALSA: seq: close a re-opened queue timer in the destructor (git-fixes). - ALSA: seq: Fix division by zero in initialize_timer() (git-fixes). - ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes (git-fixes). - ALSA: timer: don't re-enter an instance callback that is still running (git-fixes). - ALSA: timer: drain a slave's callback before its master detaches it (git-fixes). - ALSA: ump: fix double free of out_cvts on rawmidi error (git-fixes). - ALSA: usb-audio: Clamp frame size in implicit-feedback mode (git-fixes). - ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set (git-fixes). - ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() (git-fixes). - ALSA: usb-audio: fix stack info leak in RME Digiface status (git-fixes). - ALSA: usb-audio: fix use-after-free in ump_to_endpoint() (git-fixes). - ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (git-fixes). - apparmor: fix use-after-free in rawdata dedup loop (git-fixes). - arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU (git-fixes). - ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() (git-fixes). - ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI (git-fixes). - ASoC: cs35l56: Fix potential probe() deadlock (git-fixes). - ASoC: cs35l56: Use complete_all() to signal init_completion (git-fixes). - ASoC: cs42l43: Correct report for forced microphone jack (git-fixes). - ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP (git-fixes). - ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup (git-fixes). - ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup (git-fixes). - ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (git-fixes). - ASoC: tas2562: fix broken entries in the volume lookup table (git-fixes). - ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (git-fixes). - ASoC: tas2562: fix DVC coefficient write order (git-fixes). - ASoC: tas2781: bound firmware description string parsing (git-fixes). - assoc_array: trim the final shortcut word using the current chunk end (git-fixes). - batman-adv: bla: reacquire gw address after skb realloc (git-fixes). - batman-adv: dat: ensure accessible eth_hdr proto field (git-fixes). - batman-adv: dat: fix tie-break for candidate selection (git-fixes). - batman-adv: fix batadv_skb_is_frag() kernel-doc (git-fixes). - batman-adv: fix VLAN priority offset (git-fixes). - batman-adv: frag: fix primary_if leak on failed linearization (git-fixes). - batman-adv: frag: free unfragmentable packet (git-fixes). - batman-adv: mcast: avoid OOB read of num_dests header (git-fixes). - batman-adv: tt: avoid request storms during pending request (git-fixes). - batman-adv: tt: prevent TVLV OOB check overflow (git-fixes). - bitops: use common function parameter names (git-fixes). - Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister (stable-fixes). - Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev (git-fixes). - Bluetooth: btintel: Validate length before parsing diagnostics TLV (git-fixes). - Bluetooth: btrtl: validate firmware patch bounds (git-fixes). - Bluetooth: btusb: Add USB ID 2c4e:0128 for Mercusys MA60XNB (stable-fixes). - Bluetooth: btusb: validate Realtek vendor event length (git-fixes). - Bluetooth: hci_qca: Clear memdump state on invalid dump size (git-fixes). - Bluetooth: hci_sync: Fix advertising data UAFs (git-fixes). - Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks (git-fixes). - Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback (git-fixes). - Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback (git-fixes). - Bluetooth: hci_sync: Protect UUID list traversal (git-fixes). - Bluetooth: HIDP: reject frames without a transaction header (git-fixes). - Bluetooth: HIDP: validate numbered report payloads (git-fixes). - Bluetooth: ISO: clear iso_data always when detaching conn from hcon (git-fixes). - Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release (git-fixes). - Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos (git-fixes). - Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis() (git-fixes). - Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp (git-fixes). - Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (git-fixes). - Bluetooth: mgmt: Translate HCI reason in Device Disconnected event (git-fixes). - Bluetooth: RFCOMM: Fix session UAF in set_termios (git-fixes). - Bluetooth: SCO: give the socket its own sco_conn reference (git-fixes). - btrfs: do not trim a device which is not writeable (bsc#1272568). - bus: sunxi-rsb: Always check register address validity (git-fixes). - can: bcm: add missing rcu list annotations and operations (git-fixes). - can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (git-fixes). - can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure (git-fixes). - can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured (git-fixes). - can: ctucanfd: add missing MODULE_DEVICE_TABLE() (git-fixes). - can: ctucanfd: handle bus error interrupts (git-fixes). - can: ctucanfd: mark error-active controller status valid (git-fixes). - can: ctucanfd: unmap BAR0 using base address (git-fixes). - can: ctucanfd: use self-test mode for PRESUME_ACK (git-fixes). - can: ems_usb: validate CPC message lengths (git-fixes). - can: esd_usb: kill anchored URBs before freeing netdevs (git-fixes). - can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure (git-fixes). - can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure (git-fixes). - can: isotp: check register_netdevice_notifier() error in module init (git-fixes). - can: isotp: use unconditional synchronize_rcu() in isotp_release() (git-fixes). - can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer (git-fixes). - can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() (git-fixes). - can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents (git-fixes). - can: peak_usb: add bounds check for USB channel index (git-fixes). - can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error (git-fixes). - can: peak_usb: validate uCAN receive record lengths (git-fixes). - can: softing: fw_parse(): validate firmware record spans (git-fixes). - cdrom: fix stack out-of-bounds read in CDROMVOLCTRL (git-fixes). - comedi: comedi_parport: deal with premature interrupt (git-fixes). - crypto/xxhash: set downstream CRYPTO_ALG_FIPS_UNAPPROVED (bsc#1262160 jsc#PED-15986). - crypto: introduce downstream CRYPTO_ALG_FIPS_UNAPPROVED (bsc#1262160 jsc#PED-15986). - crypto: qat - keep VFs enabled during reset (stable-fixes). - crypto: qat - notify fatal error before AER reset preparation (stable-fixes). - dm cache policy smq: check allocation under invalidate lock (git-fixes). - dm cache: fix missing return in invalidate_committed's error path (git-fixes). - dmaengine: idxd: fix double free of wq, engine, and group structs (git-fixes). - dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() (git-fixes). - dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ (git-fixes). - dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA (git-fixes). - driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout() (git-fixes). - driver core: Guard deferred probe timeout extension with delayed_work_pending() (git-fixes). - driver core: Use mod_delayed_work to prevent lost deferred probe work (git-fixes). - Drivers: hv: vmbus: Set DMA coherent mask for VMBus devices (git-fixes). - drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (git-fixes). - drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (git-fixes). - drm/amd/display: set new_stream to NULL after release (git-fixes). - drm/amd/display: use proper context for logging (git-fixes). - drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) (git-fixes). - drm/amd/pm: fix amdgpu_pm_info power display units (git-fixes). - drm/amd/pm: fix smu13 power limit range calculation (git-fixes). - drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge (git-fixes). - drm/amdgpu: fix aperture mapping leak (git-fixes). - drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment (git-fixes). - drm/amdkfd: free MQD managers on DQM init failures (git-fixes). - drm/amdkfd: hold event_mutex while checkpointing CRIU events (git-fixes). - drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs (git-fixes). - drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (git-fixes). - drm/gfx10: Program DB_RING_CONTROL (git-fixes). - drm/i915/bios: range check LFP Data Block panel_type2 (git-fixes). - drm/i915/gem: Do not leak siblings[] on proto context error (git-fixes). - drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (git-fixes). - drm/i915/gt: use correct selftest config symbol (git-fixes). - drm/i915/selftests: Fix GT PM sort comparators (git-fixes). - drm/i915: ensure segment offset never exceeds allowed max (stable-fixes). - drm/i915: Return NULL on error in active_instance (git-fixes). - drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM (git-fixes). - drm/imagination: Fix double call to drm_sched_entity_fini() (git-fixes). - drm/imagination: fix error checking of pvr_vm_context_lookup() (git-fixes). - drm/imagination: Fix returned size for DRM_IOCTL_PVR_DEV_QUERY (git-fixes). - drm/imagination: Fix user array stride in pvr_set_uobj_array() (git-fixes). - drm/mediatek: Check CRTC state before freeing (git-fixes). - drm/mediatek: ovl_adaptor: balance component registrations (git-fixes). - drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick() (git-fixes). - drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced (git-fixes). - drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom() (git-fixes). - drm/panthor: Interrupt group start/resumption if group_bind_locked() fails (git-fixes). - drm/panthor: reject firmware sections with oversized data (git-fixes). - drm/panthor: return error on truncated firmware (git-fixes). - drm/panthor: validate firmware interface structure sizes (git-fixes). - drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove (git-fixes). - drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered (stable-fixes). - drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem (git-fixes). - drm/v3d: Reject invalid indirect BO handle in indirect CSD setup (git-fixes). - drm/vc4: hvs/v3d: Fix null dereference in unbind (git-fixes). - drm/vc4: Prevent shader BO mappings from becoming writable (git-fixes). - drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size (git-fixes). - drm/vc4: Zero the tile state data array before each BIN job (git-fixes). - drm/virtio: bound EDID block reads to the response buffer (git-fixes). - drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker (git-fixes). - drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure (git-fixes). - drm/vmwgfx: bound DMA command body size against suffix pointer (git-fixes). - drm/vmwgfx: drop dma_buf reference on foreign-fd prime import (git-fixes). - drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size (git-fixes). - drm/vmwgfx: reject DX_BIND_QUERY without a DX context (git-fixes). - drm/vmwgfx: use check_add_overflow for shader size+offset bound (git-fixes). - drm/vmwgfx: validate DRAW_PRIMITIVES header size before division (git-fixes). - drm/vmwgfx: validate external BO copy bounds for both stride paths (git-fixes). - drm/vmwgfx: Validate vmw_surface_metadata::array_size (git-fixes). - drm/xe/hw_engine: Fix double-free of managed BO in error path (git-fixes). - drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays (git-fixes). - drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() (git-fixes). - drm/xe/wopcm: fix WOPCM size for LNL+ (git-fixes). - drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds (git-fixes). - drm/xe: remove duplicate <kunit/test-bug.h> include (git-fixes). - erofs: set fileio bio failed in short read case (git-fixes). - fbcon: fix NULL pointer dereference for a console without vc_data (stable-fixes). - fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git-fixes). - fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() (git-fixes). - fbdev: efifb: fix memory leak in efifb_probe() (git-fixes). - fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). - fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). - fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git-fixes). - fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). - fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git-fixes). - fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). - fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). - fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). - fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). - fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git-fixes). - fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). - fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). - firewire: net: Fix fragmented datagram reassembly (git-fixes). - firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (git-fixes). - firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits (git-fixes). - gpio-f7188x: Add support for NCT6126D version B (git-fixes). - gpio: davinci: fix IRQ domain leak on devm_kzalloc failure (git-fixes). - gpio: eic-sprd: use raw_spinlock_t in the irq startup path (git-fixes). - gpio: htc-egpio: use managed gpiochip registration (git-fixes). - gpio: mlxbf3: fail probe if gpiochip registration fails (git-fixes). - gpio: mvebu: fail probe if gpiochip registration fails (git-fixes). - gpio: mvebu: free generic chips on unbind (git-fixes). - gpio: pca953x: fix cache_only and IRQ state on restore_context() failure (git-fixes). - gpio: rockchip: change the GPIO version judgment logic (stable-fixes). - gpio: rockchip: fix generic IRQ chip leak on remove (git-fixes). - gpio: rockchip: teardown bugs and resource leaks (git-fixes). - gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe() (git-fixes). - gpio: tegra: do not call pinctrl for GPIO direction (git-fixes). - gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (git-fixes). - gpios: palmas: add .get_direction() op (git-fixes). - HID: add haptics page defines (stable-fixes). - HID: hid-sjoy: race between init and usage (git-fixes). - HID: pidff: Add missing spaces (stable-fixes). - HID: pidff: Fix missing blank lines after declarations (stable-fixes). - HID: playstation: validate num_touch_reports in DualShock 4 reports (stable-fixes). - hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread (git-fixes). - hwmon: (adt7470) Fix cache updated before hardware write on I2C error (git-fixes). - hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read (git-fixes). - hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors (git-fixes). - hwmon: (adt7470) Fix PWM auto temp state array and bounds check (git-fixes). - hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks (git-fixes). - hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() (git-fixes). - hwmon: (adt7470) Use cached PWM frequency value (git-fixes). - hwmon: (asus-ec-sensors) add missed handle for ENOMEM (git-fixes). - hwmon: (asus-ec-sensors) fix EC read intervals (git-fixes). - hwmon: (asus-ec-sensors) fix looping over banks while reading from EC (git-fixes). - hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop (git-fixes). - hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop (git-fixes). - hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop (git-fixes). - hwmon: (lm90) Only report alarms if driver is ready (git-fixes). - hwmon: (ltc4282) Fix reading the minimum alarm voltage (git-fixes). - hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 (git-fixes). - hwmon: (nct6775-core) Prevent access to unsupported weight registers (git-fixes). - hwmon: (npcm750-pwm-fan): stop fan timer on device detach (git-fixes). - hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop (git-fixes). - hwmon: (nzxt-smart2) DMA-align output buffer (git-fixes). - hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop (git-fixes). - hwmon: (pmbus) Fix return value from pmbus_update_byte_data() (git-fixes). - hwmon: (pmbus/core) notify on the hwmon device, not the i2c client (git-fixes). - hwmon: (sht3x) Fix unaligned accesses (git-fixes). - hwmon: (w83627hf) remove VID sysfs files on error and remove (stable-fixes). - hwmon: (w83793) remove vrm sysfs file on probe failure (stable-fixes). - hwmon: occ: validate poll response sensor blocks (git-fixes). - i2c: amd-mp2: Unregister callback on adapter add failure (git-fixes). - i2c: imx: Cancel hrtimer before clearing slave pointer (git-fixes). - i2c: imx: Fix slave registration race and error handling (git-fixes). - i2c: iproc: reset bus after timeout if START_BUSY is stuck (git-fixes). - i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock (git-fixes). - i2c: mediatek: fix WRRD for SoCs without auto_restart option (git-fixes). - i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() (git-fixes). - i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue (git-fixes). - i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring (git-fixes). - ieee802154: admin-gate legacy LLSEC dump operations (git-fixes). - ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation (git-fixes). - ieee802154: ca8210: fix cas_ctl leak on spi_async failure (git-fixes). - ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit (git-fixes). - ieee802154: fix kernel-infoleak in dgram_recvmsg() (git-fixes). - ieee802154: Remove WARN_ON() in cfg802154_pernet_exit() (git-fixes). - iio: accel: bmc150: clamp the device-reported FIFO frame count (git-fixes). - iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (git-fixes). - iio: adc: lpc32xx: Initialize completion before requesting IRQ (git-fixes). - iio: adc: spear: Initialize completion before requesting IRQ (git-fixes). - iio: adc: ti-ads124s08: Return reset GPIO lookup errors (git-fixes). - iio: adc: ti-ads1119: fix PM reference leak in buffer preenable (git-fixes). - iio: common: st_sensors: honour channel endianness in read_axis_data (git-fixes). - iio: event: Fix event FIFO reset race (git-fixes). - iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ (git-fixes). - iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (git-fixes). - iio: imu: inv_icm42600: fix timestamp clock period by using lower value (git-fixes). - iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading (git-fixes). - iio: imu: st_lsm6dsx: deselect shub page before reading whoami (git-fixes). - iio: light: al3010: fix incorrect scale for the highest gain range (git-fixes). - iio: light: gp2ap002: fix runtime PM leak on read error (git-fixes). - iio: light: tsl2591: return actual error from probe IRQ failure (git-fixes). - iio: magnetometer: ak8975: fix potential kernel stack memory leak (git-fixes). - iio: temperature: Build mlx90635 with CONFIG_MLX90635 (git-fixes). - Input: ads7846 - restore half-duplex support (git-fixes). - Input: atkbd - validate scancode in firmware keymap entries (git-fixes). - Input: elan_i2c - prevent division by zero and arithmetic underflow (git-fixes). - Input: goodix - clamp the device-reported contact count (git-fixes). - Input: iforce - bound the device-reported force-feedback effect index (git-fixes). - Input: ims-pcu - add response length checks (git-fixes). - Input: ims-pcu - fix DMA mapping violation in line setup (git-fixes). - Input: ims-pcu - fix firmware leak in async update (git-fixes). - Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (git-fixes). - Input: ims-pcu - fix logic error in packet reset (git-fixes). - Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging (git-fixes). - Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing (git-fixes). - Input: ims-pcu - fix race condition in reset_device sysfs callback (git-fixes). - Input: ims-pcu - fix type confusion in CDC union descriptor parsing (git-fixes). - Input: ims-pcu - fix use-after-free and double-free in disconnect (git-fixes). - Input: ims-pcu - only expose sysfs attributes on control interface (git-fixes). - Input: ims-pcu - release data interface on disconnect (git-fixes). - Input: ims-pcu - validate control endpoint type (git-fixes). - Input: maple_keyb - set driver data before registering input device (stable-fixes). - Input: maplecontrol - set driver data before registering input device (stable-fixes). - Input: maplemouse - fix NULL pointer dereference in open() (git-fixes). - Input: maplemouse - set driver data before registering input device (stable-fixes). - Input: mms114 - fix multi-touch slot corruption (git-fixes). - Input: mms114 - fix touch indexing for MMS134S and MMS136 (git-fixes). - Input: mms114 - reject an oversized device packet size (git-fixes). - Input: rmi4 - fix bit count in bitmap_copy() (git-fixes). - Input: rmi4 - fix limit in rmi_register_desc_has_subpacket() (git-fixes). - Input: rmi4 - fix memory leak in rmi_set_attn_data() (git-fixes). - Input: rmi4 - fix num_subpackets overflow in register descriptor (git-fixes). - Input: rmi4 - fix register descriptor address calculation (git-fixes). - Input: rmi4 - fix type overflow in register counts (git-fixes). - Input: rmi4 - initialize attn_fifo properly (stable-fixes). - Input: rmi4 - iterative IRQ handler (git-fixes). - Input: rmi4 - refactor F12 probe function (stable-fixes). - Input: rmi4 - refactor function allocation and registration (stable-fixes). - Input: rmi4 - refactor register descriptor parsing (git-fixes). - Input: rmi4 - tolerate short register descriptor structure (git-fixes). - Input: rmi4 - use local presence map in rmi_read_register_desc() (stable-fixes). - Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). - Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git-fixes). - Input: synaptics-rmi4 - unregister function handlers on physical driver registration failure (git-fixes). - Input: touchwin - reset the packet index on every complete packet (git-fixes). - intel_th: core: fix null pointer dereference in intel_th_irq (bsc#1248480). - intel_th: fix MSC output device reference leak (git-fixes). - io_uring/kbuf: don't truncate end buffer for bundles (bsc#1271290). - io_uring/kbuf: fix missing BUF_MORE for incremental buffers at EOF (bsc#1261250). - io_uring/kbuf: flag partial buffer mappings (bsc#1271290). - io_uring/kbuf: propagate BUF_MORE through early buffer commit path (bsc#1261250). - io_uring/net: always use current transfer count for buffer put (git-fixes). - io_uring/net: improve recv bundles (bsc#1271290). - io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries (bsc#1271290). - io_uring/net: only consider msg_inq if larger than 1 (git-fixes). - io_uring/net: only retry recv bundle for a full transfer (bsc#1271290). - io_uring/timeout: add helper for parsing user time (bsc#1271291). - io_uring/timeout: honour caller's time namespace for IORING_TIMEOUT_ABS (bsc#1271291). - io_uring/timeout: migrate reqs from ts64 to ktime (bsc#1271291). - io_uring/wait: honour caller's time namespace for IORING_ENTER_ABS_TIMER (bsc#1271291). - ixgbe: reduce number of reads when getting OROM data (bsc#1269637). - KVM: nSVM: Clear EVENTINJ fields in vmcb12 on nested #VMEXIT (git-fixes). - KVM: nSVM: Clear GIF on nested #VMEXIT(INVALID) (git-fixes). - KVM: nSVM: Clear tracking of L1->L2 NMI and soft IRQ on nested #VMEXIT (git-fixes). - KVM: nVMX: Hide shadow VMCS right after VMCLEAR (git-fixes). - KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state (git-fixes). - KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs (git-fixes). - KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug (git-fixes). - KVM: TDX: Reject concurrent change to CPUID entry count (git-fixes). - KVM: x86/mmu: Check write tracking in all address spaces (git-fixes). - KVM: x86/mmu: Fix use-after-free on vendor module reload (git-fixes). - KVM: x86/mmu: Preserve nested TDP shadow page tables if they are used as roots (git-fixes). - KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs (git-fixes). - KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN (git-fixes). - leds: uleds: Fix potential buffer overread (git-fixes). - mac802154: hold an interface reference across the scan worker (git-fixes). - mac802154: llsec: reject frames shorter than the authentication tag (git-fixes). - mac802154: Prevent overwrite return code in mac802154_perform_association() (git-fixes). - mac802154: remove interfaces with RCU list deletion (git-fixes). - mailbox: zynqmp: setup IPI for each valid child node (bsc#1271395). - mctp: Fix incorrect tx flow invalidation condition in mctp-i2c (bsc#1266694). - media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). - media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() (git-fixes). - media: atomisp: gc2235: fix UAF and memory leak (git-fixes). - media: cec: seco: unregister adapter on IR probe failure (git-fixes). - media: cedrus: Fix failure to clean up hardware on probe failure (git-fixes). - media: cedrus: Fix missing cleanup in error path (git-fixes). - media: cedrus: skip invalid H.264 reference list entries (git-fixes). - media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). - media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). - media: nxp: imx8-isi: Fix use-after-free on remove (git-fixes). - media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code (stable-fixes). - media: pci: dm1105: Free allocated workqueue (git-fixes). - media: qcom: camss: vfe: fix PIX subdev naming on VFE lite (git-fixes). - media: qcom: venus: drop extra padding in NV12 raw size calculation (git-fixes). - media: qcom: venus: relax encoder frame/blur dimension steps on v4 (git-fixes). - media: qcom: venus: relax encoder frame/blur step size on v6 (git-fixes). - media: rockchip: rga: fix too small buffer size (git-fixes). - media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe (git-fixes). - media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). - media: uvcvideo: Avoid partial metadata buffers (git-fixes). - media: uvcvideo: Do not add clock samples with small sof delta (git-fixes). - media: uvcvideo: Fix buffer sequence in frame gaps (git-fixes). - media: uvcvideo: Fix dev_sof filtering in hw timestamp (git-fixes). - media: uvcvideo: Fix sequence number when no EOF (git-fixes). - media: uvcvideo: Relax the constrains for interpolating the hw clock (git-fixes). - media: uvcvideo: Use hw timestaming if the clock buffer is full (git-fixes). - media: v4l2-common: Add YUV24 format info (git-fixes). - media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). - media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). - media: vidtv: fix reference leak on failed device registration (git-fixes). - media: vimc: fix reference leak on failed device registration (git-fixes). - media: vpif_capture: fix OF node reference imbalance (git-fixes). - mei: bus: access mei_device under device_lock on cleanup (git-fixes). - memory: tegra: Wire up system sleep PM ops (git-fixes). - memstick: ms_block: reject a card that reports too many blocks (git-fixes). - mfd: cros_ec: Delay dev_set_drvdata() until probe success (git-fixes). - mfd: cs42l43: Sanity check firmware size (git-fixes). - mfd: rsmu: Fix page register setup (git-fixes). - mfd: sm501: Fix reference leak on failed device registration (git-fixes). - mfd: tps6586x: Fix OF node refcount (git-fixes). - misc: nsm: only unlock nsm_dev on post-lock error paths (git-fixes). - misc: nsm: pin the module while the device is open (git-fixes). - mkspec-dtb: Skip missing DTBs. - mm: zero range of eof folio exposed by inode size extension (bsc#1272920). - mmc: block: fix RPMB device unregister ordering (git-fixes). - mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe() method (git-fixes). - mmc: vub300: defer reset until cmd_mutex is unlocked (git-fixes). - mshv: fix hv_input_get_system_property struct (git-fixes). - mtd: mchp23k256: use SPI match data for chip caps (git-fixes). - mtd: onenand: samsung: report DMA completion timeouts (git-fixes). - mtd: rawnand: fsl_ifc: return errors for failed page reads (git-fixes). - mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout (git-fixes). - mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout (git-fixes). - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (bsc#1271866). - net/x25: fix use-after-free in x25_kill_by_neigh() (git-fixes). - net: mana: Add Interrupt Moderation support (bsc#1271368). - net: mana: Return error code from mana_create_rxq() (git-fixes). - net: mctp i2c: Copy headers if cloned (bsc#1266694). - net: mctp-i2c: fix duplicate reception of old data (bsc#1266694). - net: thunderbolt: Fix frags overflow by bounding frame_count (git-fixes). - net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() (git-fixes). - net: usb: lan78xx: move functions to avoid forward definitions (stable-fixes). - net: wwan: t7xx: check skb_clone in control TX (git-fixes). - net: wwan: t7xx: destroy DMA pool on CLDMA late init failure (git-fixes). - netfs: Defer the emission of trace_netfs_folio() (git-fixes). - of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes). - phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access (git-fixes). - phy: phy-can-transceiver: Check driver match and driver data against NULL (git-fixes). - phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask (git-fixes). - phy: zynqmp: fix runtime PM leak on probe allocation failure (git-fixes). - phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB (git-fixes). - phy: zynqmp: use read-modify-write for SERDES scrambler bypass (git-fixes). - pinctrl-amd: Don't clear S4 wake bits at probe (git-fixes). - pinctrl: bm1880: add missing select GENERIC_PINCONF (git-fixes). - pinctrl: cs42l43: Fix polarity on debounce (git-fixes). - pinctrl: devicetree: don't free uninitialized dev_name on error path (git-fixes). - pinctrl: equilibrium: fix warning trace on load (git-fixes). - pinctrl: equilibrium: rename irq_chip function callbacks (stable-fixes). - pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). - pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). - pinctrl: meson: restore non-sleeping GPIO access (git-fixes). - pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table (git-fixes). - pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 (git-fixes). - pinctrl: qcom: Unconditionally mark gpio as wakeup enable (git-fixes). - pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path (git-fixes). - pkspec-dtb: Fix dtb-al rename. - platform/x86/amd/pmc: Add delay_suspend module parameter (stable-fixes). - platform/x86/amd/pmc: Avoid logging "(null)" for DMI values (git-fixes). - platform/x86/amd/pmc: Check for intermediate wakeup in function (stable-fixes). - platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops (stable-fixes). - platform/x86/amd/pmc: Don't log during intermediate wakeups (stable-fixes). - pmdomain: arm: scmi: Fix genpd leak on provider registration failure (git-fixes). - posix-cpu-timers: Cleanup the firing logic (bsc#1271912). - posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del() (bsc#1271912). - posix-cpu-timers: Prevent UAF caused by non-leader exec() race (bsc#1271912). - posix-timers: Add proper state tracking (bsc#1271912). - posix-timers: Avoid direct access to hrtimer clockbase (bsc#1271912). - posix-timers: Expand timer_arm() callbacks with a boolean return value (bsc#1271912). - power: sequencing: fix ABBA deadlock in pwrseq_device_unregister() (git-fixes). - power: supply: bq25890: fix the -10 C NTC lookup entry (git-fixes). - power: supply: max17040: handle missing status supplier (git-fixes). - RDMA/mana_ib: initialize err for empty send WR lists (git-fixes). - regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (git-fixes). - regulator: ltc3676: Fix incorrect IRQSTAT bit offsets (git-fixes). - regulator: mt6358: use regmap helper to read fixed LDO calibration (git-fixes). - remoteproc: qcom: Fix leak when custom dump_segments addition fails (git-fixes). - reset: sunxi: fix memory region leak on ioremap failure (git-fixes). - Revert "Input: rmi4 - fix register descriptor address calculation" (stable-fixes). - sctp: validate embedded address parameter length (git-fixes). - security/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref() (git-fixes). - selftests: Disable dad for ipv6 in fcnal-test.sh (bsc#1272871). - selftests: Replace sleep with slowwait (bsc#1272871). - serial: 8250_mid: Disable DMA for selected platforms (git-fixes). - serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (git-fixes). - serial: 8250_omap: clear rx_running on zero-length DMA completes (git-fixes). - serial: msm: Disable DMA for kernel console UART (git-fixes). - serial: sc16is7xx: implement gpio get_direction() callback (git-fixes). - soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). - soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). - soc: xilinx: Shutdown and free rx mailbox channel (git-fixes). - spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure (git-fixes). - spi: sh-msiof: abort transfers when reset times out (git-fixes). - staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy() (git-fixes). - staging: media: atomisp: reduce load_primary_binaries() stack usage (git-fixes). - staging: rtl8723bs: core: move constants to right side in comparison (stable-fixes). - staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie() (git-fixes). - staging: rtl8723bs: fix inverted HT40 secondary channel offset (git-fixes). - staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (git-fixes). - staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (git-fixes). - staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (git-fixes). - staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (git-fixes). - staging: rtl8723bs: fix OOB write in HT_caps_handler() (git-fixes). - staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (git-fixes). - thermal: core: Free thermal zone ID later during removal (git-fixes). - time: Switch to hrtimer_setup() (bsc#1271912). - tpm: Make the TPM character devices non-seekable (git-fixes). - uio_hv_generic: Bind to FCopy device by default (git-fixes). - usb: cdc_acm: Add quirk for Uniden BC125AT scanner (stable-fixes). - usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (git-fixes). - USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (git-fixes). - usb: chipidea: fix usage_count leak when autosuspend_delay is negative (git-fixes). - USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub (stable-fixes). - usb: core: port: Deattach Type-C connector on component unbind (git-fixes). - usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (git-fixes). - usb: dwc3: run gadget disconnect from sleepable suspend context (git-fixes). - usb: free iso schedules on failed submit (git-fixes). - usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (git-fixes). - usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback (git-fixes). - usb: gadget: f_fs: Fix DMA fence leak (git-fixes). - usb: gadget: f_midi: cancel pending IN work before freeing the midi object (git-fixes). - usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() (git-fixes). - usb: gadget: f_printer: take kref only for successful open (git-fixes). - USB: gadget: fsl-udc: fix device name leak on probe failure (git-fixes). - usb: gadget: function: rndis: add length check for header (stable-fixes). - usb: gadget: function: rndis: add length check to response query (stable-fixes). - usb: gadget: printer: fix infinite loop in printer_read() (git-fixes). - USB: gadget: snps-udc: fix device name leak on probe failure (git-fixes). - usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown (git-fixes). - usb: gadget: udc: Fix use-after-free in gadget_match_driver (stable-fixes). - usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer (git-fixes). - USB: idmouse: fix use-after-free on disconnect race (git-fixes). - USB: iowarrior: fix use-after-free on disconnect (git-fixes). - USB: iowarrior: fix use-after-free on disconnect race (git-fixes). - usb: iowarrior: remove inherent race with minor number (stable-fixes). - USB: ldusb: fix use-after-free on disconnect race (git-fixes). - USB: legousbtower: fix use-after-free on disconnect race (git-fixes). - USB: misc: uss720: unregister parport on probe failure (git-fixes). - usb: mtu3: unmap request DMA on queue failure (git-fixes). - USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD (stable-fixes). - USB: serial: digi_acceleport: fix broken rx after throttle (git-fixes). - USB: serial: digi_acceleport: fix hard lockup on disconnect (git-fixes). - USB: serial: digi_acceleport: fix write buffer corruption (git-fixes). - USB: serial: io_edgeport: cap received transmit credits (git-fixes). - USB: serial: io_ti: reject oversized boot-mode firmware (git-fixes). - USB: serial: keyspan_pda: fix data loss on receive throttling (git-fixes). - USB: serial: keyspan_pda: fix information leak (git-fixes). - USB: serial: mxuport: validate firmware header size (git-fixes). - USB: serial: option: add MeiG SRM813Q (stable-fixes). - USB: serial: option: add Telit Cinterion FE990D50 compositions (stable-fixes). - usb: sl811-hcd: disable controller wakeup on remove (git-fixes). - USB: storage: include US_FL_NO_SAME in quirks mask (git-fixes). - usb: typec: anx7411: use devm_pm_runtime_enable() (git-fixes). - usb: typec: class: drop PD lookup reference (git-fixes). - usb: typec: tcpm: Fix VDM type for Enter Mode commands (git-fixes). - usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (git-fixes). - usb: typec: ucsi: cancel pending work on system suspend (git-fixes). - usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (git-fixes). - usb: typec: ucsi: Detect and skip duplicate altmodes from buggy firmware (git-fixes). - usb: typec: ucsi: Invert DisplayPort role assignment (git-fixes). - usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (git-fixes). - USB: ulpi: fix memory leak on registration failure (git-fixes). - USB: usb-storage: ene_ub6250: restore media-ready check (git-fixes). - usb: xhci: Fix sleep in atomic context in xhci_free_streams() (git-fixes). - usbip: tools: support SuperSpeedPlus devices (git-fixes). - usbip: vudc: fix NULL deref in vep_dequeue() (git-fixes). - wan: wanxl: Only reset hardware after BAR mapping (git-fixes). - watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() (git-fixes). - wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() (git-fixes). - wifi: ath6kl: fix OOB access from firmware ADDBA window size (git-fixes). - wifi: ath6kl: fix OOB read from firmware IE lengths in connect event (git-fixes). - wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler (git-fixes). - wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (git-fixes). - wifi: ath10k: fix skb leak on incomplete msdu during rx pop (git-fixes). - wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin (git-fixes). - wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() (git-fixes). - wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (git-fixes). - wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (git-fixes). - wifi: brcmfmac: fix 802.1X-SHA256 call trace warning (git-fixes). - wifi: brcmfmac: make release_scratchbuffers idempotent (git-fixes). - wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read (git-fixes). - wifi: carl9170: fix buffer overflow in rx_stream failover path (git-fixes). - wifi: carl9170: fix OOB read from off-by-two in TX status handler (git-fixes). - wifi: iwlwifi: mvm: fix read in wake packet notification handler (git-fixes). - wifi: iwlwifi: mvm: validate SAR GEO response payload size (git-fixes). - wifi: mac80211: fix memory leak in ieee80211_register_hw() (git-fixes). - wifi: mac80211: free ack status frame on TX header build failure (git-fixes). - wifi: mac80211: recalculate TIM when a station enters power save (git-fixes). - wifi: mac80211: tear down new links on vif update error path (git-fixes). - wifi: mac80211: validate individual TWT params before driver setup (git-fixes). - wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() (git-fixes). - wifi: mt76: Disable napi when removing device (git-fixes). - wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses (git-fixes). - wifi: mt76: mt7915: guard HE capability lookups (git-fixes). - wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses (git-fixes). - wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (git-fixes). - wifi: mt76: mt7925: fix crash in reset link replay (git-fixes). - wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv() (git-fixes). - wifi: mt76: mt7925: guard link STA in decap offload (git-fixes). - wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() (git-fixes). - wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() (git-fixes). - wifi: mwifiex: bound uAP association event IEs to the event buffer (git-fixes). - wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper (git-fixes). - wifi: mwifiex: fix permanently busy scans after multiple roam iterations (git-fixes). - wifi: mwifiex: fix roaming to different channel in host_mlme mode (git-fixes). - wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (git-fixes). - wifi: rt2x00: avoid full teardown before work setup in probe (git-fixes). - wifi: wilc1000: validate assoc response length before subtracting header (git-fixes). - xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit (bsc#1264267). - xfs: only assert new size for datafork during truncate extents (bsc#1264084). - xfs: rearrange code in xfs_inode_item_precommit (bsc#1237449). - xfs: rework datasync tracking and execution (bsc#1237449). - xhci: dbgtty: fix device unregister (git-fixes). - xhci: dbgtty: fix device unregister: fixup (git-fixes).

View original source

05 / REFERENCES

Further evidence