FlawAtlas
Search the atlas
SUSE-SU-2026:2799-1 Not scored

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP7 RT kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-10263: arm64: cputype: Add C1-Ultra definitions (bsc#1266290). - CVE-2025-40216: io_uring/rsrc: don't rely on user vaddr alignment (bsc#1259764). - CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). - CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). - CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). - CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). - CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). - CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). - CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). - CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). - CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). - CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). - CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false (bsc#1267816). - CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). - CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). - CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). - CVE-2026-31500: Bluetooth: hci_sync: Remove remaining dependencies of hci_request (bsc#1262993). - CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). - CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). - CVE-2026-31560: spi: spi-dw-dma: fix print error log when wait finish transaction (bsc#1263057). - CVE-2026-31592: KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). - CVE-2026-31593: KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU (bsc#1263124). - CVE-2026-31647: idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling (bsc#1263581). - CVE-2026-31664: xfrm: clear trailing padding in build_polexpire() (bsc#1263578). - CVE-2026-31665: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). - CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). - CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). - CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). - CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). - CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). - CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). - CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). - CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). - CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). - CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). - CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). - CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). - CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). - CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). - CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). - CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). - CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). - CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). - CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). - CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). - CVE-2026-43053: xfs: factor out xfs_attr3_node_entry_remove (bsc#1264084). - CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). - CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). - CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). - CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). - CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). - CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). - CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). - CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). - CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). - CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). - CVE-2026-43094: ixgbevf: add missing negotiate_features op to Hyper-V ops table (bsc#1264231). - CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). - CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). - CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). - CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). - CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). - CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). - CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). - CVE-2026-43171: EFI/CPER: don't dump the entire memory region (bsc#1264549). - CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). - CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). - CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). - CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). - CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). - CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). - CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). - CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). - CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). - CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). - CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). - CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). - CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). - CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). - CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). - CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). - CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). - CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). - CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). - CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). - CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). - CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). - CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). - CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). - CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). - CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). - CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). - CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). - CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). - CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). - CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). - CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). - CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). - CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). - CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). - CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). - CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). - CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). - CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). - CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). - CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). - CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). - CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). - CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). - CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). - CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). - CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). - CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). - CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). - CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). - CVE-2026-46150: fanotify: fix false positive on permission events. - CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). - CVE-2026-46162: ice: fix double free in ice_sf_eth_activate() error path (bsc#1266840). - CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). - CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). - CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). - CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). - CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). - CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). - CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). - CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). - CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). - CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). - CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). - CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). - CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1265211 bsc#1267651). - CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). - CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). - CVE-2026-46315: io_uring/waitid: clear waitid info before copying it to userspace (bsc#1267953). - CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). - CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). - CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). - CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). - CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). - CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). - CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). - CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). - CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). - CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). - CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). - CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). - CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). - CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). - CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). - CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). - CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). - CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). - CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). - CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). - CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). - CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). - CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). - CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). - CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). - CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). - CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). - CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). - CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). - CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: - accel/ivpu: Fix signed integer truncation in IPC receive (git-fixes). - ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). - ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). - ACPI: IPMI: Fix message kref handling on dead device (git-fixes). - ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). - ACPI: resource: Amend kernel-doc style (git-fixes). - agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). - ALSA: aloop: Drop superfluous break (git-fixes). - ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). - ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). - ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git-fixes). - ALSA: es1938: check snd_ctl_new1() return value (git-fixes). - ALSA: firewire: isight: bound the sample count to the packet payload (git-fixes). - ALSA: gus: check snd_ctl_new1() return value (git-fixes). - ALSA: hda/cs35l41: Fix firmware load work teardown (git-fixes). - ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). - ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). - ALSA: seq: Clear variable event pointer on read (git-fixes). - ALSA: seq: Fix kernel heap address leak in bounce_error_event() (git-fixes). - ALSA: seq: Fix partial userptr event expansion (git-fixes). - ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). - ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). - ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). - ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). - ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). - ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). - ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). - ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). - ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). - ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). - ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). - ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). - ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git-fixes). - ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). - ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). - ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails (git-fixes). - ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). - ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). - ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git-fixes). - ASoC: mediatek: mt8183: Release reserved memory on cleanup (git-fixes). - ASoC: mediatek: mt8192: Release reserved memory on cleanup (git-fixes). - ASoC: meson: aiu: Validate written enum values (git-fixes). - ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git-fixes). - ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). - ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). - ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). - ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git-fixes). - ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). - ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). - ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). - ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git-fixes). - ASoC: topology: Check PCM and DAI name strings before use (git-fixes). - ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git-fixes). - batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). - batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). - batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). - batman-adv: tp_meter: avoid window underflow (git-fixes). - batman-adv: tp_meter: fix fast recovery precondition (git-fixes). - batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). - batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). - batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). - batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). - Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path (git-fixes). - Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git-fixes). - Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). - Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). - Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). - Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). - Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git-fixes). - Bluetooth: hci: validate codec capability element length (git-fixes). - Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device (git-fixes). - Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable-fixes). - Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). - bnxt_en: Fix NULL pointer dereference (bsc#1268307). - bus: mhi: ep: Add missing state_lock protection for mhi_state access (git-fixes). - bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). - bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). - char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). - crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). - crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). - crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git-fixes). - crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). - crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). - crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). - crypto: ccp - Treat zero-length cert chain as query for blob lengths (git-fixes). - crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). - crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). - crypto: drbg - Fix the fips_enabled priority boost (git-fixes). - crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). - crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). - crypto: hisilicon/qm - disable error report before flr (git-fixes). - crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git-fixes). - crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). - crypto: qat - protect service table iterations with service_lock (git-fixes). - crypto: qat - validate RSA CRT component lengths (git-fixes). - crypto: rng - Free default RNG on module exit (git-fixes). - dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). - dmaengine: Fix possible use after free (git-fixes). - dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). - dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). - dmaengine: tegra: Fix burst size calculation (git-fixes). - driver core: reject devices with unregistered buses (git-fixes). - driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git-fixes). - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git-fixes). - drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs (stable-fixes). - drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). - drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). - drm/amd/pm: fix smu13 power limit default/cap calculation (stable-fixes). - drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 (stable-fixes). - drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro (git-fixes). - drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range (stable-fixes). - drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git-fixes). - drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). - drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). - drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). - drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). - drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git-fixes). - drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). - drm/amdkfd: always resume_all after suspend_all (git-fixes). - drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). - drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable-fixes). - drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). - drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). - drm/amdkfd: Use exclusive bounds for SVM split alignment checks (git-fixes). - drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). - drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). - drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). - drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git-fixes). - drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git-fixes). - drm/dp: Add eDP 1.5 bit definition (stable-fixes). - drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). - drm/gpuvm: Do not prepare NULL objects (git-fixes). - drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git-fixes). - drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). - drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). - drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). - drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). - drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). - drm/i915: clear CRTC color blob pointers after dropping refs (git-fixes). - drm/imagination: Count paired job fence as dependency in prepare_job() (git-fixes). - drm/imagination: Fit paired fragment job in the correct CCCB (git-fixes). - drm/msm/dp: fix HPD state status bit shift value (git-fixes). - drm/msm/dp: Fix the ISR_* enum values (git-fixes). - drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). - drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). - drm/nouveau: fix reversed error cleanup order in ucopy functions (git-fixes). - drm/panthor: Fix kernel-doc warning in panthor_sched.c (git-fixes). - drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). - drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git-fixes). - drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git-fixes). - drm/syncobj: Fix memory leak in drm_syncobj_find_fence() (git-fixes). - drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git-fixes). - drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). - drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). - drm/tidss: Fix missing drm_bridge_add() call (git-fixes). - drm/vc4: fix krealloc() memory leak (git-fixes). - drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). - drm/virtio: Fix driver removal with disabled KMS (git-fixes). - drm/xe: fix refcount leak in xe_range_fence_insert() (git-fixes). - drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (git-fixes). - ethtool: provide customized dim profile management (bsc#1261256). - fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git-fixes). - fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). - fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). - fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git-fixes). - fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). - fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). - fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git-fixes). - fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). - fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). - fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). - fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). - fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git-fixes). - fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). - fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). - firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). - firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). - firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). - firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). - fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). - fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). - fpga: region: fix use-after-free in child_regions_with_firmware() (git-fixes). - gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). - gpu: host1x: Allow entries in BO caches to be freed (git-fixes). - gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). - HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). - HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). - HID: wacom: stop hardware after post-start probe failures (git-fixes). - HID: wiimote: Fix table layout and whitespace errors (git-fixes). - hv: utils: handle and propagate errors in kvp_register (git-fixes). - hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). - hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). - hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). - hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). - hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). - i2c: core: fix irq domain leak on adapter registration failure (git-fixes). - i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). - i2c: mpc: Fix timeout calculations (git-fixes). - i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). - i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). - i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). - i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). - i3c: master: Prevent reuse of dynamic address on device add failure (git-fixes). - ice: ptp: don't WARN when controlling PF is unavailable (bsc#1267251). - iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). - iio: adc: npcm: Convert to platform remove callback returning void (stable-fixes). - iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). - iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). - iio: chemical: scd30: fix division by zero in write_raw (git-fixes). - iio: chemical: scd30: Use guard(mutex) to allow early returns (stable-fixes). - iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git-fixes). - iio: gyro: bmg160: wait full startup time after mode change at probe (git-fixes). - iio: light: opt3001: fix missing state reset on timeout (git-fixes). - iio: light: si1133: prevent race condition on timeout (git-fixes). - iio: light: si1133: reset counter to prevent race condition (git-fixes). - iio: light: veml6030: fix channel type when pushing events (git-fixes). - iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). - iio: magnetometer: ak8975: fix potential kernel stack memory leak (git-fixes). - iio: tcs3472: power down chip on probe failure (git-fixes). - iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). - Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). - Input: elan_i2c - validate firmware size before use (stable-fixes). - Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable-fixes). - Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). - Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git-fixes). - Input: xpad - add 'Nova 2 Lite' from GameSir (stable-fixes). - Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). - iommu/s390: allow larger region tables (jsc#PED-15880). - iommu/s390: Fix memory corruption when using identity domain (jsc#PED-15880). - iommu/s390: handle IOAT registration based on domain (jsc#PED-15880). - iommu/s390: implement iommu passthrough via identity domain (jsc#PED-15880). - iommu/s390: set appropriate IOTA region type (jsc#PED-15880). - iommu/s390: support cleanup of additional table regions (jsc#PED-15880). - iommu/s390: support iova_to_phys for additional table regions (jsc#PED-15880). - iommu/s390: support map/unmap for additional table regions (jsc#PED-15880). - KVM: arm64: Discard PC update state on vcpu reset (git-fixes). - KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). - KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). - KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). - KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). - KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). - KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). - KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). - KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). - KVM: s390: Limit adapter indicator access to mapped page (bsc#1268159). - KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). - KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). - KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). - KVM: SVM: check validity of VMCB controls when returning from SMM (git-fixes). - KVM: SVM: Don't set GIF when clearing EFER.SVME (git-fixes). - KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). - KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). - KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). - KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). - KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git-fixes). - KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). - KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git-fixes). - KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). - KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). - KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). - leds: uleds: Fix potential buffer overread (git-fixes). - linux/dim: move useful macros to .h file (bsc#1261256). - loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). - loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). - mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). - media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). - media: cec: seco: unregister adapter on IR probe failure (git-fixes). - media: cedrus: Fix failure to clean up hardware on probe failure (git-fixes). - media: cedrus: Fix missing cleanup in error path (git-fixes). - media: cedrus: skip invalid H.264 reference list entries (git-fixes). - media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). - media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). - media: pci: dm1105: Free allocated workqueue (git-fixes). - media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). - media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). - media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). - media: vidtv: fix reference leak on failed device registration (git-fixes). - media: vimc: fix reference leak on failed device registration (git-fixes). - media: vpif_capture: fix OF node reference imbalance (git-fixes). - misc: fastrpc: fix DMA address corruption due to find_vma misuse (git-fixes). - misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). - misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git-fixes). - misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). - module: fix init_module_from_file() error handling (jsc#PED-16303). - module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). - module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). - module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). - module: warn about excessively long module waits (jsc#PED-16303). - modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). - mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git-fixes). - mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). - mtd: rawnand: pl353: fix probe resource allocation (git-fixes). - mtd: slram: remove failed entries from the device list (git-fixes). - mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). - mtd: spi-nor: swp: Improve locking user experience (git-fixes). - net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). - net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). - net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). - net: mana: Add support for PF device 0x00C1 (bsc#1268237). - net: mana: Add support for RX CQE Coalescing (bsc#1261256). - net: mana: Allocate interrupt context for each EQ when creating vPort (git-fixes). - net: mana: Create separate EQs for each vPort (git-fixes). - net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git-fixes). - net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git-fixes). - net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). - net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). - net: mana: Optimize irq affinity for low vcpu configs (git-fixes). - net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). - net: mana: Use GIC functions to allocate global EQs (git-fixes). - nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). - nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). - nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). - of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes). - page_pool: Move pp_magic check into helper functions (bsc#1261562). - page_pool: Track DMA-mapped pages and unmap them when destroying the pool (bsc#1261562). - platform/x86: intel-hid: Protect ACPI notify handler against recursion (git-fixes). - platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). - PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). - power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). - power: supply: charger-manager: fix refcount leak in is_full_charged() (git-fixes). - power: supply: core: fix supplied_from allocations (git-fixes). - power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). - powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). - powerpc/fadump: define MIN_RMA in bytes rather than MB (bsc#1236743 git-fixes). - RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). - RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). - rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). - rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). - rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). - rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git-fixes). - rtc: mpfs: fix counter upload completion condition (git-fixes). - rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). - s390/pci: check for relaxed translation capability (jsc#PED-15880). - s390/pci: Fix dev.dma_range_map missing sentinel element (jsc#PED-15880). - s390/pci: store DMA offset in bus_dma_region (jsc#PED-15880). - scripts/submit_branch: add SLE15-SP7 submission script. - scsi: storvsc: Replace symbolic permissions with octal (git-fixes). - scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). - selftests/bpf: Add BPF_STRICT_BUILD toggle (bsc#1269617). - selftests/bpf: Allow test_progs to link with a partial object set (bsc#1269617). - selftests/bpf: Fix test_kmods KDIR to honor O= and distro kernels (bsc#1269617). - selftests/bpf: Make skeleton headers order-only prerequisites of .test.d (bsc#1269617). - selftests/bpf: Provide weak definitions for cross-test functions (bsc#1269617). - selftests/bpf: Skip tests whose objects were not built (bsc#1269617). - selftests/bpf: Tolerate benchmark build failures (bsc#1269617). - selftests/bpf: Tolerate BPF and skeleton generation failures (bsc#1269617). - selftests/bpf: Tolerate missing files during install (bsc#1269617). - selftests/bpf: Tolerate test file compilation failures (bsc#1269617). - serdev: make serdev_bus_type const (stable-fixes). - serial: 8250: dispatch SysRq character in serial8250_handle_irq() (git-fixes). - serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq() (git-fixes). - slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). - soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). - soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). - spi: at91-usart: drop dead runtime pm support (git-fixes). - spi: dw: fix wrong BAUDR setting after resume (git-fixes). - spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). - spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). - spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git-fixes). - spi: meson-spifc: fix runtime PM leak on remove (git-fixes). - spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). - spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). - spi: xilinx: use FIFO occupancy register to determine buffer size (git-fixes). - Split off kABI workaround for bsc#1267458 (bsc#1267458). - staging: most: video: avoid double free on video register failure (git-fixes). - staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). - thermal: hwmon: Fix critical temperature attribute removal (git-fixes). - thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). - thunderbolt: Bound root directory content to block size (git-fixes). - thunderbolt: Clamp XDomain response data copy to allocation size (git-fixes). - thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). - thunderbolt: Reject zero-length property entries in validator (git-fixes). - thunderbolt: Validate XDomain request packet size before type cast (git-fixes). - tpm: fix event_size output in tpm1_binary_bios_measurements_show (git-fixes). - tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). - usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). - usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). - usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). - usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git-fixes). - usb: host: max3421: Reject hub port requests for non-existent ports (git-fixes). - USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). - USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). - USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). - USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). - USB: serial: option: add MeiG SRM813Q (stable-fixes). - USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). - usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). - usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). - usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). - usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). - usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). - usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). - usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). - vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). - watchdog/hpwdt: Refine hpwdt message for UV platform (bsc#1269199). - watchdog: apple: Add 'apple,t8103-wdt' compatible (git-fixes). - watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). - watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). - watchdog: unregister PM notifier on watchdog unregister (git-fixes). - wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). - wifi: ath11k: fix warning when unbinding (git-fixes). - wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). - wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). - wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). - wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). - wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). - wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). - wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). - wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). - wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). - wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). - wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). - wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). - wifi: rtw89: Correct data type for scan index to avoid infinite loop (git-fixes). - wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git-fixes). - wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). - wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git-fixes). - x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). - x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). - X.509: Fix validation of ASN.1 certificate header (git-fixes).

Exploit probability Not scored
Published July 8, 2026
Required by Not available
Last source change July 9, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Live Patching 15 SP7 kernel-livepatch-SLE15-SP7-RT_Update_17
SUSE:Real Time Module 15 SP7 kernel-rt
SUSE:Real Time Module 15 SP7 kernel-source-rt
SUSE:Real Time Module 15 SP7 kernel-syms-rt

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:2799-1

The SUSE Linux Enterprise 15 SP7 RT kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-10263: arm64: cputype: Add C1-Ultra definitions (bsc#1266290). - CVE-2025-40216: io_uring/rsrc: don't rely on user vaddr alignment (bsc#1259764). - CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). - CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). - CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). - CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). - CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). - CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). - CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). - CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). - CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). - CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). - CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false (bsc#1267816). - CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). - CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). - CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). - CVE-2026-31500: Bluetooth: hci_sync: Remove remaining dependencies of hci_request (bsc#1262993). - CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). - CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). - CVE-2026-31560: spi: spi-dw-dma: fix print error log when wait finish transaction (bsc#1263057). - CVE-2026-31592: KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). - CVE-2026-31593: KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU (bsc#1263124). - CVE-2026-31647: idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling (bsc#1263581). - CVE-2026-31664: xfrm: clear trailing padding in build_polexpire() (bsc#1263578). - CVE-2026-31665: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). - CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). - CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). - CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). - CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). - CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). - CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). - CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). - CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). - CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). - CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). - CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). - CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). - CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). - CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). - CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). - CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). - CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). - CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). - CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). - CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). - CVE-2026-43053: xfs: factor out xfs_attr3_node_entry_remove (bsc#1264084). - CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). - CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). - CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). - CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). - CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). - CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). - CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). - CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). - CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). - CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). - CVE-2026-43094: ixgbevf: add missing negotiate_features op to Hyper-V ops table (bsc#1264231). - CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). - CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). - CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). - CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). - CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). - CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). - CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). - CVE-2026-43171: EFI/CPER: don't dump the entire memory region (bsc#1264549). - CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). - CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). - CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). - CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). - CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). - CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). - CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). - CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). - CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). - CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). - CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). - CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). - CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). - CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). - CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). - CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). - CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). - CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). - CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). - CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). - CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). - CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). - CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). - CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). - CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). - CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). - CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). - CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). - CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). - CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). - CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). - CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). - CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). - CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). - CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). - CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). - CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). - CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). - CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). - CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). - CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). - CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). - CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). - CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). - CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). - CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). - CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). - CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). - CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). - CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). - CVE-2026-46150: fanotify: fix false positive on permission events. - CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). - CVE-2026-46162: ice: fix double free in ice_sf_eth_activate() error path (bsc#1266840). - CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). - CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). - CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). - CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). - CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). - CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). - CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). - CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). - CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). - CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). - CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). - CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). - CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1265211 bsc#1267651). - CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). - CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). - CVE-2026-46315: io_uring/waitid: clear waitid info before copying it to userspace (bsc#1267953). - CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). - CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). - CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). - CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). - CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). - CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). - CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). - CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). - CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). - CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). - CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). - CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). - CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). - CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). - CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). - CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). - CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). - CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). - CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). - CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). - CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). - CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). - CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). - CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). - CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). - CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). - CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). - CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). - CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). - CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: - accel/ivpu: Fix signed integer truncation in IPC receive (git-fixes). - ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). - ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). - ACPI: IPMI: Fix message kref handling on dead device (git-fixes). - ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). - ACPI: resource: Amend kernel-doc style (git-fixes). - agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). - ALSA: aloop: Drop superfluous break (git-fixes). - ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). - ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). - ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git-fixes). - ALSA: es1938: check snd_ctl_new1() return value (git-fixes). - ALSA: firewire: isight: bound the sample count to the packet payload (git-fixes). - ALSA: gus: check snd_ctl_new1() return value (git-fixes). - ALSA: hda/cs35l41: Fix firmware load work teardown (git-fixes). - ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). - ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). - ALSA: seq: Clear variable event pointer on read (git-fixes). - ALSA: seq: Fix kernel heap address leak in bounce_error_event() (git-fixes). - ALSA: seq: Fix partial userptr event expansion (git-fixes). - ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). - ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). - ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). - ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). - ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). - ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). - ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). - ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). - ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). - ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). - ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). - ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). - ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git-fixes). - ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). - ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). - ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails (git-fixes). - ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). - ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). - ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git-fixes). - ASoC: mediatek: mt8183: Release reserved memory on cleanup (git-fixes). - ASoC: mediatek: mt8192: Release reserved memory on cleanup (git-fixes). - ASoC: meson: aiu: Validate written enum values (git-fixes). - ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git-fixes). - ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). - ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). - ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). - ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git-fixes). - ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). - ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). - ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). - ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git-fixes). - ASoC: topology: Check PCM and DAI name strings before use (git-fixes). - ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git-fixes). - batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). - batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). - batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). - batman-adv: tp_meter: avoid window underflow (git-fixes). - batman-adv: tp_meter: fix fast recovery precondition (git-fixes). - batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). - batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). - batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). - batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). - Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path (git-fixes). - Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git-fixes). - Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). - Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). - Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). - Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). - Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git-fixes). - Bluetooth: hci: validate codec capability element length (git-fixes). - Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device (git-fixes). - Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable-fixes). - Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). - bnxt_en: Fix NULL pointer dereference (bsc#1268307). - bus: mhi: ep: Add missing state_lock protection for mhi_state access (git-fixes). - bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). - bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). - char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). - crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). - crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). - crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git-fixes). - crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). - crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). - crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). - crypto: ccp - Treat zero-length cert chain as query for blob lengths (git-fixes). - crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). - crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). - crypto: drbg - Fix the fips_enabled priority boost (git-fixes). - crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). - crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). - crypto: hisilicon/qm - disable error report before flr (git-fixes). - crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git-fixes). - crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). - crypto: qat - protect service table iterations with service_lock (git-fixes). - crypto: qat - validate RSA CRT component lengths (git-fixes). - crypto: rng - Free default RNG on module exit (git-fixes). - dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). - dmaengine: Fix possible use after free (git-fixes). - dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). - dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). - dmaengine: tegra: Fix burst size calculation (git-fixes). - driver core: reject devices with unregistered buses (git-fixes). - driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git-fixes). - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git-fixes). - drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs (stable-fixes). - drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). - drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). - drm/amd/pm: fix smu13 power limit default/cap calculation (stable-fixes). - drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 (stable-fixes). - drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro (git-fixes). - drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range (stable-fixes). - drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git-fixes). - drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). - drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). - drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). - drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). - drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git-fixes). - drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). - drm/amdkfd: always resume_all after suspend_all (git-fixes). - drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). - drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable-fixes). - drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). - drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). - drm/amdkfd: Use exclusive bounds for SVM split alignment checks (git-fixes). - drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). - drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). - drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). - drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git-fixes). - drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git-fixes). - drm/dp: Add eDP 1.5 bit definition (stable-fixes). - drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). - drm/gpuvm: Do not prepare NULL objects (git-fixes). - drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git-fixes). - drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). - drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). - drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). - drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). - drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). - drm/i915: clear CRTC color blob pointers after dropping refs (git-fixes). - drm/imagination: Count paired job fence as dependency in prepare_job() (git-fixes). - drm/imagination: Fit paired fragment job in the correct CCCB (git-fixes). - drm/msm/dp: fix HPD state status bit shift value (git-fixes). - drm/msm/dp: Fix the ISR_* enum values (git-fixes). - drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). - drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). - drm/nouveau: fix reversed error cleanup order in ucopy functions (git-fixes). - drm/panthor: Fix kernel-doc warning in panthor_sched.c (git-fixes). - drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). - drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git-fixes). - drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git-fixes). - drm/syncobj: Fix memory leak in drm_syncobj_find_fence() (git-fixes). - drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git-fixes). - drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). - drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). - drm/tidss: Fix missing drm_bridge_add() call (git-fixes). - drm/vc4: fix krealloc() memory leak (git-fixes). - drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). - drm/virtio: Fix driver removal with disabled KMS (git-fixes). - drm/xe: fix refcount leak in xe_range_fence_insert() (git-fixes). - drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (git-fixes). - ethtool: provide customized dim profile management (bsc#1261256). - fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git-fixes). - fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). - fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). - fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git-fixes). - fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). - fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). - fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git-fixes). - fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). - fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). - fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). - fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). - fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git-fixes). - fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). - fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). - firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). - firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). - firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). - firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). - fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). - fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). - fpga: region: fix use-after-free in child_regions_with_firmware() (git-fixes). - gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). - gpu: host1x: Allow entries in BO caches to be freed (git-fixes). - gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). - HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). - HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). - HID: wacom: stop hardware after post-start probe failures (git-fixes). - HID: wiimote: Fix table layout and whitespace errors (git-fixes). - hv: utils: handle and propagate errors in kvp_register (git-fixes). - hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). - hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). - hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). - hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). - hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). - i2c: core: fix irq domain leak on adapter registration failure (git-fixes). - i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). - i2c: mpc: Fix timeout calculations (git-fixes). - i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). - i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). - i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). - i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). - i3c: master: Prevent reuse of dynamic address on device add failure (git-fixes). - ice: ptp: don't WARN when controlling PF is unavailable (bsc#1267251). - iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). - iio: adc: npcm: Convert to platform remove callback returning void (stable-fixes). - iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). - iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). - iio: chemical: scd30: fix division by zero in write_raw (git-fixes). - iio: chemical: scd30: Use guard(mutex) to allow early returns (stable-fixes). - iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git-fixes). - iio: gyro: bmg160: wait full startup time after mode change at probe (git-fixes). - iio: light: opt3001: fix missing state reset on timeout (git-fixes). - iio: light: si1133: prevent race condition on timeout (git-fixes). - iio: light: si1133: reset counter to prevent race condition (git-fixes). - iio: light: veml6030: fix channel type when pushing events (git-fixes). - iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). - iio: magnetometer: ak8975: fix potential kernel stack memory leak (git-fixes). - iio: tcs3472: power down chip on probe failure (git-fixes). - iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). - Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). - Input: elan_i2c - validate firmware size before use (stable-fixes). - Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable-fixes). - Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). - Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git-fixes). - Input: xpad - add 'Nova 2 Lite' from GameSir (stable-fixes). - Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). - iommu/s390: allow larger region tables (jsc#PED-15880). - iommu/s390: Fix memory corruption when using identity domain (jsc#PED-15880). - iommu/s390: handle IOAT registration based on domain (jsc#PED-15880). - iommu/s390: implement iommu passthrough via identity domain (jsc#PED-15880). - iommu/s390: set appropriate IOTA region type (jsc#PED-15880). - iommu/s390: support cleanup of additional table regions (jsc#PED-15880). - iommu/s390: support iova_to_phys for additional table regions (jsc#PED-15880). - iommu/s390: support map/unmap for additional table regions (jsc#PED-15880). - KVM: arm64: Discard PC update state on vcpu reset (git-fixes). - KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). - KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). - KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). - KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). - KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). - KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). - KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). - KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). - KVM: s390: Limit adapter indicator access to mapped page (bsc#1268159). - KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). - KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). - KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). - KVM: SVM: check validity of VMCB controls when returning from SMM (git-fixes). - KVM: SVM: Don't set GIF when clearing EFER.SVME (git-fixes). - KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). - KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). - KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). - KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). - KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git-fixes). - KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). - KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git-fixes). - KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). - KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). - KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). - leds: uleds: Fix potential buffer overread (git-fixes). - linux/dim: move useful macros to .h file (bsc#1261256). - loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). - loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). - mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). - media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). - media: cec: seco: unregister adapter on IR probe failure (git-fixes). - media: cedrus: Fix failure to clean up hardware on probe failure (git-fixes). - media: cedrus: Fix missing cleanup in error path (git-fixes). - media: cedrus: skip invalid H.264 reference list entries (git-fixes). - media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). - media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). - media: pci: dm1105: Free allocated workqueue (git-fixes). - media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). - media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). - media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). - media: vidtv: fix reference leak on failed device registration (git-fixes). - media: vimc: fix reference leak on failed device registration (git-fixes). - media: vpif_capture: fix OF node reference imbalance (git-fixes). - misc: fastrpc: fix DMA address corruption due to find_vma misuse (git-fixes). - misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). - misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git-fixes). - misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). - module: fix init_module_from_file() error handling (jsc#PED-16303). - module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). - module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). - module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). - module: warn about excessively long module waits (jsc#PED-16303). - modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). - mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git-fixes). - mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). - mtd: rawnand: pl353: fix probe resource allocation (git-fixes). - mtd: slram: remove failed entries from the device list (git-fixes). - mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). - mtd: spi-nor: swp: Improve locking user experience (git-fixes). - net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). - net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). - net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). - net: mana: Add support for PF device 0x00C1 (bsc#1268237). - net: mana: Add support for RX CQE Coalescing (bsc#1261256). - net: mana: Allocate interrupt context for each EQ when creating vPort (git-fixes). - net: mana: Create separate EQs for each vPort (git-fixes). - net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git-fixes). - net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git-fixes). - net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). - net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). - net: mana: Optimize irq affinity for low vcpu configs (git-fixes). - net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). - net: mana: Use GIC functions to allocate global EQs (git-fixes). - nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). - nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). - nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). - of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes). - page_pool: Move pp_magic check into helper functions (bsc#1261562). - page_pool: Track DMA-mapped pages and unmap them when destroying the pool (bsc#1261562). - platform/x86: intel-hid: Protect ACPI notify handler against recursion (git-fixes). - platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). - PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). - power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). - power: supply: charger-manager: fix refcount leak in is_full_charged() (git-fixes). - power: supply: core: fix supplied_from allocations (git-fixes). - power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). - powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). - powerpc/fadump: define MIN_RMA in bytes rather than MB (bsc#1236743 git-fixes). - RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). - RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). - rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). - rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). - rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). - rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git-fixes). - rtc: mpfs: fix counter upload completion condition (git-fixes). - rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). - s390/pci: check for relaxed translation capability (jsc#PED-15880). - s390/pci: Fix dev.dma_range_map missing sentinel element (jsc#PED-15880). - s390/pci: store DMA offset in bus_dma_region (jsc#PED-15880). - scripts/submit_branch: add SLE15-SP7 submission script. - scsi: storvsc: Replace symbolic permissions with octal (git-fixes). - scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). - selftests/bpf: Add BPF_STRICT_BUILD toggle (bsc#1269617). - selftests/bpf: Allow test_progs to link with a partial object set (bsc#1269617). - selftests/bpf: Fix test_kmods KDIR to honor O= and distro kernels (bsc#1269617). - selftests/bpf: Make skeleton headers order-only prerequisites of .test.d (bsc#1269617). - selftests/bpf: Provide weak definitions for cross-test functions (bsc#1269617). - selftests/bpf: Skip tests whose objects were not built (bsc#1269617). - selftests/bpf: Tolerate benchmark build failures (bsc#1269617). - selftests/bpf: Tolerate BPF and skeleton generation failures (bsc#1269617). - selftests/bpf: Tolerate missing files during install (bsc#1269617). - selftests/bpf: Tolerate test file compilation failures (bsc#1269617). - serdev: make serdev_bus_type const (stable-fixes). - serial: 8250: dispatch SysRq character in serial8250_handle_irq() (git-fixes). - serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq() (git-fixes). - slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). - soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). - soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). - spi: at91-usart: drop dead runtime pm support (git-fixes). - spi: dw: fix wrong BAUDR setting after resume (git-fixes). - spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). - spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). - spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git-fixes). - spi: meson-spifc: fix runtime PM leak on remove (git-fixes). - spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). - spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). - spi: xilinx: use FIFO occupancy register to determine buffer size (git-fixes). - Split off kABI workaround for bsc#1267458 (bsc#1267458). - staging: most: video: avoid double free on video register failure (git-fixes). - staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). - thermal: hwmon: Fix critical temperature attribute removal (git-fixes). - thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). - thunderbolt: Bound root directory content to block size (git-fixes). - thunderbolt: Clamp XDomain response data copy to allocation size (git-fixes). - thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). - thunderbolt: Reject zero-length property entries in validator (git-fixes). - thunderbolt: Validate XDomain request packet size before type cast (git-fixes). - tpm: fix event_size output in tpm1_binary_bios_measurements_show (git-fixes). - tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). - usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). - usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). - usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). - usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git-fixes). - usb: host: max3421: Reject hub port requests for non-existent ports (git-fixes). - USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). - USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). - USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). - USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). - USB: serial: option: add MeiG SRM813Q (stable-fixes). - USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). - usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). - usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). - usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). - usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). - usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). - usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). - usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). - vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). - watchdog/hpwdt: Refine hpwdt message for UV platform (bsc#1269199). - watchdog: apple: Add 'apple,t8103-wdt' compatible (git-fixes). - watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). - watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). - watchdog: unregister PM notifier on watchdog unregister (git-fixes). - wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). - wifi: ath11k: fix warning when unbinding (git-fixes). - wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). - wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). - wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). - wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). - wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). - wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). - wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). - wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). - wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). - wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). - wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). - wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). - wifi: rtw89: Correct data type for scan index to avoid infinite loop (git-fixes). - wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git-fixes). - wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). - wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git-fixes). - x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). - x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). - X.509: Fix validation of ASN.1 certificate header (git-fixes).

View original source

05 / REFERENCES

Further evidence