[El-errata] ELSA-2026-500374 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Thu Oct 8 08:57:36 UTC 2026


Oracle Linux Security Advisory ELSA-2026-500374

http://linux.oracle.com/errata/ELSA-2026-500374.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-uek-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-core-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-debug-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-debug-core-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-debug-devel-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-debug-modules-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-debug-modules-core-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-debug-modules-deprecated-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-debug-modules-desktop-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-debug-modules-extra-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-debug-modules-extra-netfilter-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-debug-modules-usb-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-debug-modules-wireless-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-devel-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-doc-6.12.0-207.111.5.1.el9uek.noarch.rpm
kernel-uek-modules-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-modules-core-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-modules-deprecated-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-modules-desktop-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-modules-extra-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-modules-extra-netfilter-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-modules-usb-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-modules-wireless-6.12.0-207.111.5.1.el9uek.x86_64.rpm
kernel-uek-tools-6.12.0-207.111.5.1.el9uek.x86_64.rpm

aarch64:
kernel-uek-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-core-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-debug-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-debug-core-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-debug-devel-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-debug-modules-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-debug-modules-core-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-debug-modules-deprecated-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-debug-modules-desktop-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-debug-modules-extra-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-debug-modules-extra-netfilter-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-debug-modules-usb-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-debug-modules-wireless-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-devel-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-doc-6.12.0-207.111.5.1.el9uek.noarch.rpm
kernel-uek-modules-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-modules-extra-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-modules-core-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-modules-deprecated-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-modules-desktop-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-modules-extra-netfilter-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-modules-usb-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-modules-wireless-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek-tools-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek64k-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek64k-core-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek64k-devel-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek64k-modules-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek64k-modules-core-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek64k-modules-deprecated-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek64k-modules-desktop-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek64k-modules-extra-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek64k-modules-extra-netfilter-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek64k-modules-usb-6.12.0-207.111.5.1.el9uek.aarch64.rpm
kernel-uek64k-modules-wireless-6.12.0-207.111.5.1.el9uek.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/kernel-uek-6.12.0-207.111.5.1.el9uek.src.rpm

Related CVEs:

CVE-2025-21817
CVE-2025-22108
CVE-2025-38205
CVE-2025-38206
CVE-2025-38266
CVE-2025-38525
CVE-2025-38621
CVE-2025-39925
CVE-2025-40074
CVE-2025-40102
CVE-2025-40210
CVE-2025-68299
CVE-2025-71142
CVE-2026-100070
CVE-2026-100071
CVE-2026-100075
CVE-2026-100079
CVE-2026-23459
CVE-2026-43197
CVE-2026-43198
CVE-2026-43344
CVE-2026-45897
CVE-2026-45901
CVE-2026-45963
CVE-2026-53078
CVE-2026-53089
CVE-2026-53090
CVE-2026-53092
CVE-2026-53102
CVE-2026-53113
CVE-2026-53250
CVE-2026-53313
CVE-2026-53364
CVE-2026-64031
CVE-2026-64058
CVE-2026-64205
CVE-2026-64210
CVE-2026-64216
CVE-2026-64290
CVE-2026-64427
CVE-2026-64507
CVE-2026-64520
CVE-2026-64562
CVE-2026-64563
CVE-2026-64564
CVE-2026-64567
CVE-2026-64568
CVE-2026-64569
CVE-2026-64570
CVE-2026-64571
CVE-2026-64572
CVE-2026-64574
CVE-2026-64575
CVE-2026-64576
CVE-2026-64577
CVE-2026-64579
CVE-2026-64580
CVE-2026-64581
CVE-2026-64586
CVE-2026-68082
CVE-2026-68093
CVE-2026-68096
CVE-2026-68102
CVE-2026-68106
CVE-2026-68107
CVE-2026-68108
CVE-2026-68110
CVE-2026-68111
CVE-2026-68112
CVE-2026-68113
CVE-2026-68115
CVE-2026-68116
CVE-2026-68117
CVE-2026-68118
CVE-2026-68119
CVE-2026-68121
CVE-2026-68123
CVE-2026-68125
CVE-2026-68126
CVE-2026-68128
CVE-2026-68129
CVE-2026-68131
CVE-2026-68132
CVE-2026-68133
CVE-2026-68136
CVE-2026-68138
CVE-2026-68139
CVE-2026-68142
CVE-2026-68143
CVE-2026-68145
CVE-2026-68146
CVE-2026-68148
CVE-2026-68149
CVE-2026-68150
CVE-2026-68153
CVE-2026-68154
CVE-2026-68155
CVE-2026-68156
CVE-2026-68157
CVE-2026-68158
CVE-2026-68159
CVE-2026-68160
CVE-2026-68161
CVE-2026-68162
CVE-2026-68164
CVE-2026-68165
CVE-2026-68166
CVE-2026-68169
CVE-2026-68180
CVE-2026-68181
CVE-2026-68184
CVE-2026-68186
CVE-2026-68187
CVE-2026-68188
CVE-2026-68189
CVE-2026-68192
CVE-2026-68193
CVE-2026-68194
CVE-2026-68197
CVE-2026-68198
CVE-2026-68199
CVE-2026-68200
CVE-2026-68201
CVE-2026-68202
CVE-2026-68205
CVE-2026-68206
CVE-2026-68212
CVE-2026-68213
CVE-2026-68214
CVE-2026-68216
CVE-2026-68217
CVE-2026-68218
CVE-2026-68226
CVE-2026-68227
CVE-2026-68234
CVE-2026-68235
CVE-2026-68236
CVE-2026-68243
CVE-2026-68244
CVE-2026-68245
CVE-2026-68246
CVE-2026-68247
CVE-2026-68248
CVE-2026-68249
CVE-2026-68250
CVE-2026-68251
CVE-2026-68252
CVE-2026-68253
CVE-2026-68254
CVE-2026-68255
CVE-2026-68256
CVE-2026-68257
CVE-2026-68259
CVE-2026-68264
CVE-2026-68266
CVE-2026-68267
CVE-2026-68269
CVE-2026-68271
CVE-2026-68272
CVE-2026-68273
CVE-2026-68276
CVE-2026-68277
CVE-2026-68278
CVE-2026-68279
CVE-2026-68284
CVE-2026-68286
CVE-2026-68287
CVE-2026-68288
CVE-2026-68289
CVE-2026-68293
CVE-2026-68294
CVE-2026-68296
CVE-2026-68297
CVE-2026-68299
CVE-2026-68300
CVE-2026-68301
CVE-2026-68303
CVE-2026-68304
CVE-2026-68307
CVE-2026-68309
CVE-2026-68310
CVE-2026-68311
CVE-2026-68313
CVE-2026-68315
CVE-2026-68317
CVE-2026-68318
CVE-2026-68319
CVE-2026-68320
CVE-2026-68325
CVE-2026-68326
CVE-2026-68328
CVE-2026-68329
CVE-2026-68336
CVE-2026-68337
CVE-2026-68338
CVE-2026-68339
CVE-2026-68343
CVE-2026-68346
CVE-2026-68348
CVE-2026-68349
CVE-2026-68350
CVE-2026-68351
CVE-2026-68352
CVE-2026-68353
CVE-2026-68355
CVE-2026-68362
CVE-2026-68363
CVE-2026-68365
CVE-2026-68372
CVE-2026-68373
CVE-2026-68374
CVE-2026-68376
CVE-2026-68377
CVE-2026-68386
CVE-2026-68388
CVE-2026-68391
CVE-2026-68392
CVE-2026-68394
CVE-2026-68398
CVE-2026-68402
CVE-2026-68403
CVE-2026-68405
CVE-2026-68406
CVE-2026-68407
CVE-2026-68410
CVE-2026-68411
CVE-2026-68413
CVE-2026-68414
CVE-2026-68416
CVE-2026-68419
CVE-2026-68422
CVE-2026-68425
CVE-2026-68427
CVE-2026-68428
CVE-2026-68429
CVE-2026-68430
CVE-2026-68432
CVE-2026-68433
CVE-2026-68439
CVE-2026-68442
CVE-2026-68444
CVE-2026-68445
CVE-2026-68446
CVE-2026-68450
CVE-2026-72015
CVE-2026-72017
CVE-2026-72030
CVE-2026-72032
CVE-2026-72040
CVE-2026-72045
CVE-2026-72046
CVE-2026-72051
CVE-2026-72065
CVE-2026-72070
CVE-2026-72101
CVE-2026-72103
CVE-2026-72111
CVE-2026-72113
CVE-2026-72114
CVE-2026-72115
CVE-2026-72116
CVE-2026-72117
CVE-2026-72118
CVE-2026-72119
CVE-2026-72121
CVE-2026-72124
CVE-2026-72125
CVE-2026-72130
CVE-2026-72137
CVE-2026-72175
CVE-2026-72183
CVE-2026-72213
CVE-2026-72244
CVE-2026-72253
CVE-2026-72254
CVE-2026-72299
CVE-2026-72305
CVE-2026-72334
CVE-2026-72402
CVE-2026-72413
CVE-2026-72438
CVE-2026-72496
CVE-2026-74258
CVE-2026-74268
CVE-2026-74289
CVE-2026-74291
CVE-2026-74294
CVE-2026-74334
CVE-2026-74352
CVE-2026-74425
CVE-2026-74436
CVE-2026-74440
CVE-2026-74441
CVE-2026-74442
CVE-2026-74443
CVE-2026-74444
CVE-2026-74445
CVE-2026-74446
CVE-2026-74447
CVE-2026-74448
CVE-2026-74450
CVE-2026-74453
CVE-2026-74454
CVE-2026-74455
CVE-2026-74456
CVE-2026-74457
CVE-2026-74458
CVE-2026-74460
CVE-2026-74464
CVE-2026-74465
CVE-2026-74469
CVE-2026-74470
CVE-2026-74471
CVE-2026-74472
CVE-2026-74473
CVE-2026-74474
CVE-2026-74475
CVE-2026-74476
CVE-2026-74479
CVE-2026-74480
CVE-2026-74481
CVE-2026-74482
CVE-2026-74483
CVE-2026-74484
CVE-2026-74485
CVE-2026-74486
CVE-2026-74487
CVE-2026-74488
CVE-2026-74490
CVE-2026-74492
CVE-2026-74495
CVE-2026-74496
CVE-2026-74497
CVE-2026-74498
CVE-2026-74499
CVE-2026-74500
CVE-2026-74501
CVE-2026-74502
CVE-2026-74504
CVE-2026-74505
CVE-2026-74507
CVE-2026-74508
CVE-2026-74509
CVE-2026-74510
CVE-2026-74512
CVE-2026-74515
CVE-2026-74516
CVE-2026-74517
CVE-2026-74518
CVE-2026-74519
CVE-2026-74523
CVE-2026-74531
CVE-2026-74532
CVE-2026-74535
CVE-2026-74536
CVE-2026-74540
CVE-2026-74541
CVE-2026-74543
CVE-2026-74546
CVE-2026-74547
CVE-2026-74548
CVE-2026-74549
CVE-2026-74550
CVE-2026-74552
CVE-2026-74553
CVE-2026-74555
CVE-2026-74556
CVE-2026-74557
CVE-2026-74564
CVE-2026-74565
CVE-2026-74566
CVE-2026-74567
CVE-2026-74569
CVE-2026-74572
CVE-2026-74574
CVE-2026-74575
CVE-2026-74577
CVE-2026-74579
CVE-2026-74580
CVE-2026-74581
CVE-2026-74582
CVE-2026-74583
CVE-2026-74585
CVE-2026-74586
CVE-2026-74587
CVE-2026-74588
CVE-2026-74589
CVE-2026-74590
CVE-2026-74592
CVE-2026-74594
CVE-2026-74595
CVE-2026-74597
CVE-2026-74598
CVE-2026-74599
CVE-2026-74601
CVE-2026-74602
CVE-2026-74603
CVE-2026-74604
CVE-2026-74606
CVE-2026-74607
CVE-2026-74608
CVE-2026-74609
CVE-2026-74610
CVE-2026-74612
CVE-2026-74613
CVE-2026-74614
CVE-2026-74615
CVE-2026-74616
CVE-2026-74618
CVE-2026-74619
CVE-2026-74620
CVE-2026-74621
CVE-2026-74622
CVE-2026-74623
CVE-2026-74624
CVE-2026-74625
CVE-2026-74626
CVE-2026-74628
CVE-2026-74630
CVE-2026-74632
CVE-2026-74634
CVE-2026-74635
CVE-2026-74636
CVE-2026-74637
CVE-2026-74641
CVE-2026-74642
CVE-2026-74644
CVE-2026-74653
CVE-2026-74654
CVE-2026-74656
CVE-2026-74657
CVE-2026-74658
CVE-2026-74660
CVE-2026-74661
CVE-2026-74662
CVE-2026-74663
CVE-2026-74664
CVE-2026-74665
CVE-2026-74666
CVE-2026-74667
CVE-2026-74668
CVE-2026-74669
CVE-2026-74670
CVE-2026-74671
CVE-2026-74672
CVE-2026-74673
CVE-2026-74675
CVE-2026-74676
CVE-2026-74677
CVE-2026-74678
CVE-2026-74680
CVE-2026-74682
CVE-2026-74683
CVE-2026-74688
CVE-2026-74689
CVE-2026-74691
CVE-2026-74696
CVE-2026-74700
CVE-2026-74701
CVE-2026-74704
CVE-2026-74705
CVE-2026-74710
CVE-2026-74712
CVE-2026-74714
CVE-2026-74717
CVE-2026-74718
CVE-2026-74720
CVE-2026-74722
CVE-2026-74724
CVE-2026-74725
CVE-2026-74726
CVE-2026-74730
CVE-2026-74732
CVE-2026-74735
CVE-2026-74736
CVE-2026-74739
CVE-2026-74740
CVE-2026-74742
CVE-2026-74743
CVE-2026-74744
CVE-2026-74746
CVE-2026-74748
CVE-2026-74753
CVE-2026-80521
CVE-2026-80525
CVE-2026-80527
CVE-2026-80528
CVE-2026-80529
CVE-2026-80530
CVE-2026-80531
CVE-2026-80532
CVE-2026-80533
CVE-2026-80534
CVE-2026-80535
CVE-2026-80536
CVE-2026-80539
CVE-2026-80540
CVE-2026-80541
CVE-2026-80557
CVE-2026-80558
CVE-2026-80561
CVE-2026-80569
CVE-2026-80570
CVE-2026-80572
CVE-2026-80574
CVE-2026-80576
CVE-2026-80578
CVE-2026-80585
CVE-2026-80586
CVE-2026-80587
CVE-2026-80589
CVE-2026-80590
CVE-2026-80681
CVE-2026-80686
CVE-2026-80691
CVE-2026-80695
CVE-2026-80700
CVE-2026-80702
CVE-2026-80703
CVE-2026-80704
CVE-2026-80706
CVE-2026-80707
CVE-2026-80711
CVE-2026-80714
CVE-2026-80715
CVE-2026-80716
CVE-2026-80717
CVE-2026-80722
CVE-2026-80723
CVE-2026-80725
CVE-2026-80726
CVE-2026-80727
CVE-2026-80728
CVE-2026-80730
CVE-2026-80731
CVE-2026-80733
CVE-2026-80736
CVE-2026-80737
CVE-2026-80739
CVE-2026-80742
CVE-2026-80744
CVE-2026-80749
CVE-2026-80754
CVE-2026-80755
CVE-2026-80756
CVE-2026-80757
CVE-2026-80759
CVE-2026-80762
CVE-2026-80763
CVE-2026-80764
CVE-2026-80765
CVE-2026-80766
CVE-2026-80767
CVE-2026-80774
CVE-2026-80779
CVE-2026-80780
CVE-2026-80781
CVE-2026-80782
CVE-2026-80783
CVE-2026-80784
CVE-2026-80788
CVE-2026-80789
CVE-2026-80790
CVE-2026-80791
CVE-2026-80792
CVE-2026-80793
CVE-2026-80805
CVE-2026-80806
CVE-2026-80808
CVE-2026-80809
CVE-2026-80812
CVE-2026-80814
CVE-2026-80815
CVE-2026-80819
CVE-2026-80820
CVE-2026-80824
CVE-2026-80825
CVE-2026-80827
CVE-2026-80828
CVE-2026-80829
CVE-2026-80830
CVE-2026-80836
CVE-2026-80837
CVE-2026-80838
CVE-2026-80839
CVE-2026-80840
CVE-2026-80841
CVE-2026-80842
CVE-2026-80843
CVE-2026-80844
CVE-2026-80845
CVE-2026-80847
CVE-2026-80851
CVE-2026-80852
CVE-2026-80854
CVE-2026-80855
CVE-2026-80856
CVE-2026-80860
CVE-2026-80861
CVE-2026-80862
CVE-2026-80863
CVE-2026-80864
CVE-2026-80878
CVE-2026-80887
CVE-2026-80888
CVE-2026-80889
CVE-2026-80890
CVE-2026-80892
CVE-2026-80893
CVE-2026-80894
CVE-2026-80901
CVE-2026-80903
CVE-2026-80904
CVE-2026-80906
CVE-2026-80907
CVE-2026-80908
CVE-2026-80909
CVE-2026-80911
CVE-2026-80912
CVE-2026-80913
CVE-2026-80914
CVE-2026-80915
CVE-2026-80916
CVE-2026-80917
CVE-2026-80918
CVE-2026-80923
CVE-2026-80925
CVE-2026-80930
CVE-2026-80932
CVE-2026-80940
CVE-2026-80941
CVE-2026-80944
CVE-2026-80945
CVE-2026-80947
CVE-2026-80949
CVE-2026-80963
CVE-2026-80964
CVE-2026-80965
CVE-2026-80967
CVE-2026-80969
CVE-2026-80971
CVE-2026-80972
CVE-2026-80973
CVE-2026-80974
CVE-2026-80976
CVE-2026-80977
CVE-2026-80978
CVE-2026-80987
CVE-2026-80988
CVE-2026-80989
CVE-2026-80990
CVE-2026-80994
CVE-2026-80996
CVE-2026-80999
CVE-2026-81000
CVE-2026-81001
CVE-2026-81002
CVE-2026-81005
CVE-2026-81008
CVE-2026-81011
CVE-2026-81012
CVE-2026-81013
CVE-2026-81014
CVE-2026-81017
CVE-2026-89438
CVE-2026-89439
CVE-2026-89440
CVE-2026-89442
CVE-2026-89443
CVE-2026-89444
CVE-2026-89448
CVE-2026-89451
CVE-2026-89453
CVE-2026-89461
CVE-2026-89462
CVE-2026-89469
CVE-2026-89472
CVE-2026-89476
CVE-2026-89477
CVE-2026-89478
CVE-2026-89479
CVE-2026-89480
CVE-2026-89481
CVE-2026-89482
CVE-2026-89483
CVE-2026-89484
CVE-2026-89485
CVE-2026-89487
CVE-2026-89488
CVE-2026-89490
CVE-2026-89491
CVE-2026-89492
CVE-2026-89493
CVE-2026-89494
CVE-2026-89495
CVE-2026-89496
CVE-2026-89501
CVE-2026-89502
CVE-2026-89508
CVE-2026-89510
CVE-2026-89511
CVE-2026-89515
CVE-2026-89524
CVE-2026-89525
CVE-2026-89526
CVE-2026-89530
CVE-2026-89531
CVE-2026-89532
CVE-2026-89533
CVE-2026-89535
CVE-2026-89536
CVE-2026-89538
CVE-2026-89539
CVE-2026-89540
CVE-2026-89541
CVE-2026-89542
CVE-2026-89543
CVE-2026-89544
CVE-2026-89545
CVE-2026-89547
CVE-2026-89548
CVE-2026-89549
CVE-2026-89550
CVE-2026-89551
CVE-2026-89552
CVE-2026-89553
CVE-2026-89554
CVE-2026-89555
CVE-2026-89557
CVE-2026-89558
CVE-2026-89559
CVE-2026-89560
CVE-2026-89561
CVE-2026-89562
CVE-2026-89563
CVE-2026-89564
CVE-2026-89565
CVE-2026-89566
CVE-2026-89567
CVE-2026-89569
CVE-2026-89573
CVE-2026-89574
CVE-2026-89575
CVE-2026-89576
CVE-2026-89579
CVE-2026-89580
CVE-2026-89581
CVE-2026-89582
CVE-2026-89583
CVE-2026-89585
CVE-2026-89586
CVE-2026-89587
CVE-2026-89588
CVE-2026-89589
CVE-2026-89593
CVE-2026-89595
CVE-2026-89596
CVE-2026-89598
CVE-2026-89602
CVE-2026-89603
CVE-2026-89604
CVE-2026-89606
CVE-2026-89607
CVE-2026-89608
CVE-2026-89618
CVE-2026-89625
CVE-2026-89626
CVE-2026-89627
CVE-2026-89628
CVE-2026-89634
CVE-2026-89636
CVE-2026-89640
CVE-2026-89643
CVE-2026-89644
CVE-2026-89645
CVE-2026-89647
CVE-2026-89649
CVE-2026-89650
CVE-2026-89651
CVE-2026-89652
CVE-2026-89653
CVE-2026-89655
CVE-2026-89656
CVE-2026-89657
CVE-2026-89658
CVE-2026-89659
CVE-2026-89660
CVE-2026-89662
CVE-2026-89663
CVE-2026-89666
CVE-2026-89667
CVE-2026-89669
CVE-2026-89671
CVE-2026-89673
CVE-2026-89674
CVE-2026-89676
CVE-2026-89680
CVE-2026-89683
CVE-2026-89684
CVE-2026-89685
CVE-2026-89686
CVE-2026-89688
CVE-2026-89690
CVE-2026-89691
CVE-2026-89693
CVE-2026-89694
CVE-2026-89696
CVE-2026-89698
CVE-2026-89699
CVE-2026-89700
CVE-2026-89702
CVE-2026-89703
CVE-2026-89704
CVE-2026-89706
CVE-2026-89707
CVE-2026-89708
CVE-2026-89710
CVE-2026-89711
CVE-2026-89712
CVE-2026-89713
CVE-2026-89717
CVE-2026-89718
CVE-2026-89719
CVE-2026-89726
CVE-2026-89729
CVE-2026-89731
CVE-2026-89741
CVE-2026-89744
CVE-2026-89746
CVE-2026-89747
CVE-2026-89749
CVE-2026-89751
CVE-2026-89752
CVE-2026-89753
CVE-2026-89755
CVE-2026-89756
CVE-2026-89762
CVE-2026-89763
CVE-2026-89765
CVE-2026-89768
CVE-2026-89771
CVE-2026-89776
CVE-2026-89777
CVE-2026-89778
CVE-2026-89783
CVE-2026-89784
CVE-2026-89786
CVE-2026-89787
CVE-2026-89789
CVE-2026-89793
CVE-2026-89796
CVE-2026-89798
CVE-2026-89799
CVE-2026-89800
CVE-2026-89801
CVE-2026-89802
CVE-2026-89803
CVE-2026-89807
CVE-2026-89816
CVE-2026-89817
CVE-2026-89818
CVE-2026-89819
CVE-2026-89821
CVE-2026-89822
CVE-2026-89823
CVE-2026-89824
CVE-2026-89842
CVE-2026-89843
CVE-2026-89844
CVE-2026-89845
CVE-2026-89846
CVE-2026-89847
CVE-2026-89848
CVE-2026-89849
CVE-2026-89850
CVE-2026-89851
CVE-2026-89852
CVE-2026-89853
CVE-2026-89854
CVE-2026-89855
CVE-2026-89856
CVE-2026-89857
CVE-2026-89858
CVE-2026-89860
CVE-2026-89861
CVE-2026-89863
CVE-2026-89864
CVE-2026-89865
CVE-2026-89872
CVE-2026-89874
CVE-2026-89876
CVE-2026-89877
CVE-2026-89878
CVE-2026-89879
CVE-2026-89880
CVE-2026-89881
CVE-2026-89886
CVE-2026-89890
CVE-2026-89891
CVE-2026-89892
CVE-2026-89893
CVE-2026-89894
CVE-2026-89897
CVE-2026-89899
CVE-2026-89900
CVE-2026-89927
CVE-2026-89929
CVE-2026-89930
CVE-2026-89931
CVE-2026-89932
CVE-2026-89940
CVE-2026-89941
CVE-2026-89942
CVE-2026-89944
CVE-2026-89945
CVE-2026-89947
CVE-2026-89948
CVE-2026-89950
CVE-2026-89951
CVE-2026-89952
CVE-2026-89953
CVE-2026-89965
CVE-2026-89968
CVE-2026-89969
CVE-2026-89970
CVE-2026-89973
CVE-2026-89974
CVE-2026-89975
CVE-2026-89979
CVE-2026-89982
CVE-2026-89983
CVE-2026-89984
CVE-2026-89986
CVE-2026-89988
CVE-2026-89989
CVE-2026-89990
CVE-2026-89995
CVE-2026-89997
CVE-2026-89998
CVE-2026-89999
CVE-2026-90000
CVE-2026-90003
CVE-2026-90007
CVE-2026-90011
CVE-2026-90012
CVE-2026-90015
CVE-2026-90025
CVE-2026-90031
CVE-2026-90032
CVE-2026-90033
CVE-2026-90034
CVE-2026-90035
CVE-2026-90036
CVE-2026-90037
CVE-2026-90039
CVE-2026-90041
CVE-2026-90042
CVE-2026-90049
CVE-2026-90050
CVE-2026-90053
CVE-2026-90054
CVE-2026-90055
CVE-2026-90057
CVE-2026-90058
CVE-2026-90060
CVE-2026-90062
CVE-2026-90063
CVE-2026-90067
CVE-2026-90068
CVE-2026-90070
CVE-2026-90071
CVE-2026-90072
CVE-2026-90073
CVE-2026-90075
CVE-2026-90076
CVE-2026-90078
CVE-2026-90088
CVE-2026-90091
CVE-2026-90092
CVE-2026-90101
CVE-2026-90102
CVE-2026-90103
CVE-2026-90109
CVE-2026-90110
CVE-2026-90112
CVE-2026-90114
CVE-2026-90115
CVE-2026-90119
CVE-2026-90125
CVE-2026-90126
CVE-2026-90128
CVE-2026-90130
CVE-2026-90135
CVE-2026-90137
CVE-2026-90138
CVE-2026-90139
CVE-2026-90140
CVE-2026-90141
CVE-2026-90147
CVE-2026-90148
CVE-2026-90150
CVE-2026-90151
CVE-2026-90157
CVE-2026-90159
CVE-2026-90160
CVE-2026-90178
CVE-2026-90180
CVE-2026-90184
CVE-2026-90185
CVE-2026-90186
CVE-2026-90187
CVE-2026-90188
CVE-2026-90189
CVE-2026-90190
CVE-2026-90194
CVE-2026-90196
CVE-2026-90198
CVE-2026-90201
CVE-2026-90202
CVE-2026-90203
CVE-2026-90207
CVE-2026-90213
CVE-2026-90215
CVE-2026-90216
CVE-2026-90218
CVE-2026-90219
CVE-2026-90220
CVE-2026-90227
CVE-2026-90228
CVE-2026-90230
CVE-2026-90235
CVE-2026-90241
CVE-2026-90243
CVE-2026-90248
CVE-2026-90253
CVE-2026-90254
CVE-2026-90255
CVE-2026-90262
CVE-2026-90274
CVE-2026-90275
CVE-2026-90279
CVE-2026-90283
CVE-2026-90284
CVE-2026-90285
CVE-2026-90290
CVE-2026-90293
CVE-2026-90294
CVE-2026-90302
CVE-2026-90307
CVE-2026-90308
CVE-2026-90313
CVE-2026-90314
CVE-2026-90316
CVE-2026-90318
CVE-2026-90322
CVE-2026-90325
CVE-2026-90329
CVE-2026-90334
CVE-2026-90344
CVE-2026-90352
CVE-2026-90353
CVE-2026-90354
CVE-2026-90357
CVE-2026-90358
CVE-2026-90360
CVE-2026-90361
CVE-2026-90362
CVE-2026-90364
CVE-2026-90368
CVE-2026-90372
CVE-2026-90373
CVE-2026-90375
CVE-2026-90380
CVE-2026-90382
CVE-2026-90383
CVE-2026-90385
CVE-2026-90387
CVE-2026-90388
CVE-2026-90389
CVE-2026-90390
CVE-2026-90392
CVE-2026-90393
CVE-2026-90395
CVE-2026-90397
CVE-2026-90398
CVE-2026-90399
CVE-2026-90400
CVE-2026-90402
CVE-2026-90403
CVE-2026-90404
CVE-2026-90407
CVE-2026-90411
CVE-2026-90413
CVE-2026-90414
CVE-2026-90415
CVE-2026-90416
CVE-2026-90431
CVE-2026-90434
CVE-2026-90435
CVE-2026-92477
CVE-2026-92481
CVE-2026-92484
CVE-2026-92489
CVE-2026-92494
CVE-2026-92495
CVE-2026-92496
CVE-2026-92497
CVE-2026-92498
CVE-2026-92501
CVE-2026-92502
CVE-2026-92504
CVE-2026-92507
CVE-2026-92508
CVE-2026-92509
CVE-2026-92510
CVE-2026-92511
CVE-2026-92512
CVE-2026-92515
CVE-2026-92521
CVE-2026-92522
CVE-2026-92523
CVE-2026-92524
CVE-2026-92525
CVE-2026-93037
CVE-2026-93039
CVE-2026-93045
CVE-2026-93046
CVE-2026-93048
CVE-2026-93049
CVE-2026-93051
CVE-2026-93053
CVE-2026-93054
CVE-2026-93055
CVE-2026-93056
CVE-2026-93061
CVE-2026-93062
CVE-2026-93064
CVE-2026-93065
CVE-2026-93067
CVE-2026-93070
CVE-2026-93073
CVE-2026-93093
CVE-2026-93097
CVE-2026-93098
CVE-2026-93101
CVE-2026-93102
CVE-2026-93103
CVE-2026-93107
CVE-2026-93108
CVE-2026-93109
CVE-2026-93110
CVE-2026-93117
CVE-2026-93119
CVE-2026-93130
CVE-2026-93137
CVE-2026-93138
CVE-2026-93140
CVE-2026-93145
CVE-2026-93149
CVE-2026-93150
CVE-2026-93151
CVE-2026-93161
CVE-2026-93162
CVE-2026-93163
CVE-2026-93165
CVE-2026-93172
CVE-2026-93173
CVE-2026-93174
CVE-2026-93177
CVE-2026-93178
CVE-2026-93182
CVE-2026-93185
CVE-2026-93186
CVE-2026-93188
CVE-2026-93189
CVE-2026-93190
CVE-2026-93203
CVE-2026-93204
CVE-2026-93205
CVE-2026-93206
CVE-2026-93207
CVE-2026-93209
CVE-2026-93210
CVE-2026-93211
CVE-2026-93212
CVE-2026-93213
CVE-2026-93219
CVE-2026-93222
CVE-2026-93224
CVE-2026-93226
CVE-2026-93228
CVE-2026-93229
CVE-2026-93234
CVE-2026-93239
CVE-2026-93240
CVE-2026-93242
CVE-2026-93247
CVE-2026-93250
CVE-2026-93252
CVE-2026-93256
CVE-2026-93262
CVE-2026-93264
CVE-2026-93268
CVE-2026-93269
CVE-2026-93271
CVE-2026-93274
CVE-2026-93281
CVE-2026-93287
CVE-2026-93288
CVE-2026-93781
CVE-2026-93782
CVE-2026-93783
CVE-2026-93784
CVE-2026-93785
CVE-2026-93787
CVE-2026-93788
CVE-2026-93789
CVE-2026-93790
CVE-2026-93791
CVE-2026-93792
CVE-2026-93793
CVE-2026-93794
CVE-2026-93795
CVE-2026-93796
CVE-2026-93797
CVE-2026-93798
CVE-2026-93799
CVE-2026-93800
CVE-2026-93801
CVE-2026-93802
CVE-2026-93803
CVE-2026-93804
CVE-2026-93805
CVE-2026-93806
CVE-2026-93807
CVE-2026-93808
CVE-2026-93809
CVE-2026-93810
CVE-2026-93813
CVE-2026-93814
CVE-2026-93820
CVE-2026-93822
CVE-2026-93823
CVE-2026-93824
CVE-2026-93825
CVE-2026-93826
CVE-2026-93827
CVE-2026-93828
CVE-2026-93829
CVE-2026-97408
CVE-2026-97409
CVE-2026-97410
CVE-2026-97412
CVE-2026-97415
CVE-2026-97416
CVE-2026-97417
CVE-2026-97419
CVE-2026-97420
CVE-2026-97421
CVE-2026-97425
CVE-2026-97427
CVE-2026-97428
CVE-2026-97429
CVE-2026-97430
CVE-2026-97438
CVE-2026-97440
CVE-2026-97441
CVE-2026-97442
CVE-2026-97443
CVE-2026-97444
CVE-2026-97445
CVE-2026-97446
CVE-2026-97447
CVE-2026-97448
CVE-2026-97449
CVE-2026-97450
CVE-2026-97451
CVE-2026-97452
CVE-2026-97453
CVE-2026-97454
CVE-2026-97455
CVE-2026-97456
CVE-2026-97472
CVE-2026-97473
CVE-2026-97481
CVE-2026-97483
CVE-2026-97484
CVE-2026-97492
CVE-2026-97494
CVE-2026-97495
CVE-2026-97496
CVE-2026-97497
CVE-2026-97500
CVE-2026-97505
CVE-2026-97507
CVE-2026-97508
CVE-2026-97509
CVE-2026-97510
CVE-2026-97516
CVE-2026-97517
CVE-2026-97518
CVE-2026-97520
CVE-2026-97521
CVE-2026-97522
CVE-2026-97523
CVE-2026-97524
CVE-2026-97539
CVE-2026-97540
CVE-2026-97541
CVE-2026-97542
CVE-2026-97543
CVE-2026-97544
CVE-2026-97545
CVE-2026-97546
CVE-2026-97547
CVE-2026-97551
CVE-2026-97552
CVE-2026-97555
CVE-2026-97556
CVE-2026-97557
CVE-2026-97560
CVE-2026-97562
CVE-2026-97564
CVE-2026-97568
CVE-2026-97572
CVE-2026-97573
CVE-2026-97575
CVE-2026-97576
CVE-2026-97583
CVE-2026-97584
CVE-2026-97595
CVE-2026-97596
CVE-2026-97598
CVE-2026-97600
CVE-2026-97601
CVE-2026-97602
CVE-2026-97604
CVE-2026-97605
CVE-2026-97606
CVE-2026-97607
CVE-2026-97608
CVE-2026-97611
CVE-2026-97612
CVE-2026-97613
CVE-2026-97616
CVE-2026-97617
CVE-2026-97899
CVE-2026-97900
CVE-2026-97902
CVE-2026-97904
CVE-2026-97905
CVE-2026-97907
CVE-2026-97917
CVE-2026-97920
CVE-2026-97921
CVE-2026-97922
CVE-2026-97923
CVE-2026-97925
CVE-2026-97929
CVE-2026-97930
CVE-2026-97931
CVE-2026-97936
CVE-2026-97940
CVE-2026-97945
CVE-2026-97951
CVE-2026-97953
CVE-2026-97957
CVE-2026-97958
CVE-2026-97959
CVE-2026-97963
CVE-2026-97964
CVE-2026-97965
CVE-2026-97973
CVE-2026-97976
CVE-2026-97977
CVE-2026-97978
CVE-2026-97979
CVE-2026-97984
CVE-2026-97985
CVE-2026-97986
CVE-2026-97987
CVE-2026-97990
CVE-2026-97991
CVE-2026-97992
CVE-2026-97993
CVE-2026-97994
CVE-2026-97995
CVE-2026-97996
CVE-2026-97998
CVE-2026-98006
CVE-2026-98007
CVE-2026-98008
CVE-2026-98009
CVE-2026-98010
CVE-2026-98011
CVE-2026-98012
CVE-2026-98014
CVE-2026-98015
CVE-2026-98016
CVE-2026-98017
CVE-2026-98020
CVE-2026-98021
CVE-2026-98022
CVE-2026-98023
CVE-2026-98025
CVE-2026-98026
CVE-2026-98027
CVE-2026-98028
CVE-2026-98029
CVE-2026-98030
CVE-2026-98031
CVE-2026-98037
CVE-2026-98039
CVE-2026-98041
CVE-2026-98045
CVE-2026-98046
CVE-2026-98051
CVE-2026-98052
CVE-2026-98054
CVE-2026-98055
CVE-2026-98056
CVE-2026-98057
CVE-2026-98059
CVE-2026-98063
CVE-2026-98064
CVE-2026-98066
CVE-2026-98074
CVE-2026-98075
CVE-2026-98076
CVE-2026-98077
CVE-2026-98078
CVE-2026-98080
CVE-2026-98081
CVE-2026-98082
CVE-2026-98083
CVE-2026-98086
CVE-2026-98088
CVE-2026-98089
CVE-2026-98090
CVE-2026-98091
CVE-2026-98092
CVE-2026-98095
CVE-2026-98096
CVE-2026-98097
CVE-2026-98098
CVE-2026-98102
CVE-2026-98103
CVE-2026-98104
CVE-2026-98107
CVE-2026-98108
CVE-2026-98109
CVE-2026-98110
CVE-2026-98111
CVE-2026-98116
CVE-2026-98122
CVE-2026-98123
CVE-2026-98126
CVE-2026-98127
CVE-2026-98128
CVE-2026-98129
CVE-2026-98130
CVE-2026-98142
CVE-2026-98151
CVE-2026-98152
CVE-2026-98154
CVE-2026-98157
CVE-2026-98158
CVE-2026-98159




Description of changes:

[6.12.0-207.111.5.1]
- selftests/mm/khugepaged: include kselftest.h in khugepaged (Sherry Yang)  [Orabug: 40099804]

[6.12.0-207.111.5]
- Rename ONOS kernel flavor to OSP for OL9 and OL10 (Vijay Kumar) [Orabug: 40055216]
- tcp: Remove hashinfo test for inet6?_lookup_run_sk_lookup(). (Kuniyuki Iwashima) [Orabug: 40052306]
- LTS version: v6.12.111 (Sherry Yang)
- mptcp: fix bad accounting in __mptcp_subflow_push_pending() (Paolo Abeni) [Orabug: 40078583] {CVE-2026-97522}
- mptcp: close race between scheduler and state change (Paolo Abeni) [Orabug: 40078588] {CVE-2026-97523}
- mptcp: avoid unneeded actions on subflow reset (Paolo Abeni) [Orabug: 40078594] {CVE-2026-97524}
- SUNRPC: Restore NUMA_NO_NODE for svc thread allocations in global mode (Ameer Hamza)
- workqueue: Update documentation as per system_percpu_wq naming (Mallesh Koujalagi)
- ocfs2: validate directory-index entry counts when reading metadata (Doruk Tan Ozturk) [Orabug: 40020935] {CVE-2026-89492}
- ocfs2: validate dx_root extent list fields during block read (Joseph Qi)
- sched_ext: Fix inverted ops.core_sched_before() invocation (Tejun Heo)
- svcrdma: Reject Write/Reply chunks with segcount 0 (Chris Mason) [Orabug: 40072707] {CVE-2026-93228}
- svcrdma: Adjust the number of entries in svc_rdma_recv_ctxt::rc_pages (Chuck Lever)
- sunrpc: Add a helper to derive maxpages from sv_max_mesg (Chuck Lever)
- svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id (Chuck Lever) [Orabug: 40021075] {CVE-2026-89535}
- svcrdma: Release transport resources synchronously (Chuck Lever)
- rpcrdma: arm rn_done before publishing the notification (Chuck Lever) [Orabug: 40033153] {CVE-2026-89798}
- sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir (Luxiao Xu) [Orabug: 40021120] {CVE-2026-89543}
- rpc_pipe: don't overdo directory locking (Al Viro)
- rpc_mkpipe_dentry(): saner calling conventions (Al Viro)
- rpc_populate(): lift cleanup into callers (Al Viro)
- SUNRPC: fix gssx_dec_option_array error path bugs (Chris Mason) [Orabug: 40021135] {CVE-2026-89544}
- sunrpc: defer rq_argp and rq_resp free until after RCU grace period (Jeff Layton) [Orabug: 40021143] {CVE-2026-89545}
- SUNRPC: Update svcxdr_init_decode() to call xdr_set_scratch_folio() (Anna Schumaker)
- SUNRPC: Introduce xdr_set_scratch_folio() (Anna Schumaker)
- ip: orphan prefetched skbs before multicast forwarding (Zhiling Zou) [Orabug: 40021224] {CVE-2026-89564}
- ipv6: ip6_mc_input() and ip6_mr_input() cleanups (Eric Dumazet)
- ipv6: adopt skb_dst_dev() and skb_dst_dev_net[_rcu]() helpers (Eric Dumazet)
- ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv() (Andrea Mayer) [Orabug: 40021207] {CVE-2026-89561}
- ipv6: annotate data-races around devconf->rpl_seg_enabled (Yue Haibing)
- cxl/ras: Fix cxl_rch_get_aer_severity() wrong severity register (Terry Bowman)
- ACPI: TAD: Add locking around AML evaluations (Rafael J. Wysocki)
- ACPI: TAD: Split three functions to untangle runtime PM handling (Rafael J. Wysocki)
- ACPI: TAD: Rearrange RT data validation checking (Rafael J. Wysocki)
- bpf: Disable preemption in bpf_get_stackid (Jiri Olsa) [Orabug: 40033158] {CVE-2026-89799}
- bpf: Use stack id functions instead of __bpf_get_stackid (Jiri Olsa)
- bpf: Factor stackid_new_bucket from __bpf_get_stackid (Jiri Olsa)
- bpf: Factor stackid_fastpath function from __bpf_get_stackid (Jiri Olsa)
- bpf: Factor stackid_init function from __bpf_get_stackid (Jiri Olsa)
- cpufreq: apple-soc: Fix OPP table cleanup (Haoxiang Li)
- acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks (Terry Bowman) [Orabug: 40021333] {CVE-2026-89589}
- efi/cper, cxl: Make definitions and structures global (Smita Koralahalli)
- efi/cper, cxl: Prefix protocol error struct and function names with cxl_ (Smita Koralahalli)
- erofs: skip sufficiently large global buffers when resizing (Nikhil Gurudasani) [Orabug: 40021393] {CVE-2026-89602}
- NFSD: Prevent client use-after-free during close_lru reaping (Chuck Lever) [Orabug: 40034294] {CVE-2026-90037}
- NFSD: Prevent client use-after-free during blocked-lock reaping (Chuck Lever) [Orabug: 40034286] {CVE-2026-90036}
- NFSD: Consolidate the revocation-path client unpin (Chuck Lever)
- HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes (Jiangshan Yi)
- HID: mcp2221: fix OOB write in mcp2221_raw_event() (Florian Pradines)
- HID: sony: clean up device list on probe failure (Doruk Tan Ozturk) [Orabug: 40034309] {CVE-2026-90041}
- HID: sony: use guard() and scoped_guard() (Rosalie Wanders)
- HID: universal-pidff: stop the device when force-feedback init fails (Baul Lee)
- HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind (Doruk Tan Ozturk) [Orabug: 40021493] {CVE-2026-89625}
- btrfs: do not overwrite NODATASUM flag when removing NODATACOW flag (Qu Wenruo)
- btrfs: fix extent map leak in NOCOW direct I/O write (Shuangpeng Bai) [Orabug: 40021561] {CVE-2026-89644}
- btrfs: rename extent map functions to get block start, end and check if in tree (Filipe Manana)
- btrfs: add btrfs prefix to main lock, try lock and unlock extent functions (Filipe Manana)
- btrfs: use BTRFS_PATH_AUTO_FREE in can_nocow_extent() (David Sterba)
- btrfs: prepare btrfs_punch_hole_lock_range() for large data folios (Qu Wenruo)
- btrfs: pass struct btrfs_inode to btrfs_sync_inode_flags_to_i_flags() (David Sterba)
- btrfs: parameter constification in ioctl.c (David Sterba)
- btrfs: update include and forward declarations in headers (David Sterba)
- btrfs: expose per-inode stable writes flag (Qu Wenruo)
- btrfs: move btrfs_alloc_write_mask() into fs.h (Filipe Manana)
- btrfs: move BTRFS_BYTES_TO_BLKS() into fs.h (Filipe Manana)
- btrfs: move btrfs_is_empty_uuid() from ioctl.c into fs.c (Filipe Manana)
- HID: apple: preserve keyboard backlight across T2 resume (Andre Eikmeyer)
- ceph: properly decrypt filenames in vmalloc() buffers (Sam Edwards) [Orabug: 40034317] {CVE-2026-90042}
- NFSD: Guard admin state-revocation walks with NFSD_NET_UP (Chuck Lever) [Orabug: 40034301] {CVE-2026-90039}
- ceph: force a cap message when a deferred revoke can't be acked immediately (Max Kellermann)
- ceph: Remove fs/ceph deadcode (Dr. David Alan Gilbert)
- NFSD: Prevent client use-after-free during delegation revoke (Chuck Lever) [Orabug: 40021620] {CVE-2026-89659}
- nfsd: disallow file locking and delegations for NFSv4 reexport (Mike Snitzer)
- NFSD: Prevent client use-after-free during admin state revocation (Chuck Lever) [Orabug: 40021626] {CVE-2026-89660}
- nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache (Jeff Layton) [Orabug: 40021653] {CVE-2026-89667}
- nfsd: fix stale s2s_cp_stateids IDR entry for async COPY (Jeff Layton) [Orabug: 40021687] {CVE-2026-89676}
- nfsd: update mtime/ctime on COPY in presence of delegated attributes (Olga Kornievskaia)
- nfsd: fix netlink dumpit error handling for rpc_status_get (Jeff Layton)
- nfsd: fix clock domain mismatch in clients_still_reclaiming() (Jeff Layton) [Orabug: 40021710] {CVE-2026-89685}
- nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown (Jeff Layton) [Orabug: 40021778] {CVE-2026-89708}
- nfsd: dedup nfs4_client_to_reclaim inserts (Jeff Layton)
- nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage (Jeff Layton) [Orabug: 40021748] {CVE-2026-89698}
- Revert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND" (Chuck Lever) [Orabug: 38686996] {CVE-2025-40210}
- NFSD: Make nfsd_genl_rqstp::rq_ops array best-effort (Chuck Lever)
- NFSD: Rename a function parameter (Chuck Lever)
- nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() (Jeff Layton) [Orabug: 40021727] {CVE-2026-89693}
- nfsd: validate sockaddr length per family in listener_set (Jeff Layton) [Orabug: 40021754] {CVE-2026-89700}
- zram: set default primary compressor in zram_destroy_comps() (Sergey Senozhatsky) [Orabug: 40021806] {CVE-2026-89717}
- zram: switch to guard() for init_lock (Sergey Senozhatsky)
- zram: fix out-of-bounds access in writeback_store() (Longlong Xia) [Orabug: 40021808] {CVE-2026-89718}
- zram: use zram_read_from_zspool() in writeback (Sergey Senozhatsky)
- zram: remove entry element member (Sergey Senozhatsky)
- zram: fix out-of-bounds access in read_block_state() (Longlong Xia) [Orabug: 40021813] {CVE-2026-89719}
- zram: fixup read_block_state() (Sergey Senozhatsky)
- usb: gadget: f_fs: Fix Use-After-Free in AIO error path (Neill Kapron)
- USB: gadget: ffs: fix mm lifetime handling (Gabriel Prostitis)
- cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read (Terry Bowman) [Orabug: 40021856] {CVE-2026-89731}
- cxl/pci: Remove CXL VH handling in CONFIG_PCIEAER_CXL conditional blocks from core/pci.c (Dave Jiang)
- cxl/pci: Remove unnecessary CXL RCH handling helper functions (Terry Bowman)
- cxl/pci: Remove unnecessary CXL Endpoint handling helper functions (Terry Bowman)
- x86/xen: fix init of balloon stats again (Roger Pau Monné)
- xen/balloon: improve accuracy of initial balloon target for dom0 (Roger Pau Monné)
- x86/locking: Use sfence for wmb() if SSE is available (Yao Zi)
- x86/locking: Remove semicolon from "lock" prefix (Uros Bizjak)
- mm/slub: fix missing debugfs entries for caches created before sysfs init (Li Xiasong)
- mm/slab: move and refactor __kmem_cache_alias() (Vlastimil Babka)
- mm/migrate_device: clear stale mapping after freeing swapcache (Arvind Yadav) [Orabug: 40021923] {CVE-2026-89755}
- KEYS: trusted: Fix TPM teardown ordering (Chengfeng Ye) [Orabug: 40021952] {CVE-2026-89763}
- mm, swap: ratelimit bad swap entry reports (Breno Leitao)
- mm: fix possible NULL pointer dereference in __swap_duplicate (Gao Xu)
- crypto: iaa - unmap dst before software fallback on decompress (Vinicius Costa Gomes) [Orabug: 40020455] {CVE-2026-80945}
- crypto: atmel-ecc - avoid stale fallback key after set_secret failure (Thorsten Blum)
- KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests (Sean Christopherson)
- KVM: SVM: Move SEV-ES VMSA allocation to a dedicated sev_vcpu_create() helper (Sean Christopherson)
- KVM: SEV: Disable SEV-SNP support on initialization failure (Ashish Kalra)
- KVM: SVM: Invalidate "next" SNP VMSA GPA even on failure (Sean Christopherson)
- KVM: SVM: Use guard(mutex) to simplify SNP vCPU state updates (Sean Christopherson)
- KVM: SVM: Mark VMCB dirty before processing incoming snp_vmsa_gpa (Sean Christopherson)
- net: advertise TCP MSS from the configured MTU, not the learned PMTU (Jiayuan Chen)
- crypto: virtio - bound the akcipher result length (Bryam Vargas) [Orabug: 39982162] {CVE-2026-80836}
- crypto: virtio - Drop superfluous [as]kcipher_req pointer (Lukas Wunner)
- crypto: virtio - Drop superfluous [as]kcipher_ctx pointer (Lukas Wunner)
- crypto: virtio - Drop sign/verify operations (Lukas Wunner)
- vlan: fix skb_under_panic and races when toggling HW VLAN offload (Eric Dumazet) [Orabug: 40013132] {CVE-2026-80925}
- net/packet: defer vmalloc TX_RING free until skbs finish (Kyle Zeng) [Orabug: 39982175] {CVE-2026-80841}
- tcp: clamp route advmss to TCP_MIN_MSS (Yong Wang) [Orabug: 39982195] {CVE-2026-80847}
- ipv4: use dst4_mtu() instead of dst_mtu() (Eric Dumazet)
- ipv6: use dst6_mtu() instead of dst_mtu() (Eric Dumazet)
- inet: add dst4_mtu() and dst6_mtu() helpers (Eric Dumazet)
- ipv6: add some unlikely()/likely() clauses in ip6_output.c (Eric Dumazet)
- ipv6: pass proto by value to ipv6_push_nfrag_opts() and ipv6_push_frag_opts() (Eric Dumazet)
- KVM: SEV: Add an anonymous "psc" struct to track current PSC metadata (Sean Christopherson)
- KVM: SEV: Make it more obvious when KVM is writing back the current PSC index (Sean Christopherson)
- KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if CONFIG_KVM_AMD_SEV=y (Sean Christopherson)
- fuse: fix race between interrupt and resend (Miklos Szeredi) [Orabug: 39982400] {CVE-2026-80860}
- usb: xhci: bail out of setup if the controller is inaccessible (Breno Leitao) [Orabug: 39982230] {CVE-2026-80861}
- usb: xhci: simplify handling of Structural Parameters 1 values (Niklas Neronin)
- usb: xhci: use cached HCSPARAMS1 value (Niklas Neronin)
- usb: xhci: add USB Port Register Set struct (Niklas Neronin)
- netfilter: nft_set_pipapo_avx2: add missing vzeroupper (Eric Biggers)
- bpf: fix the return value of push_stack (Anton Protopopov)
- xfs: initialise args->total for parent pointer updates (Javier Tia) [Orabug: 40078705] {CVE-2026-97551}
- fou: Fix use-after-free in fou_create() (Luoxuanqiang) [Orabug: 39886929] {CVE-2026-74496}
- net: appletalk: fix NULL pointer dereference in aarp_send_ddp() (Weiming Shi)
- i2c: smbus: reject oversized block transfers in the common path (Weiming Shi) [Orabug: 40073050] {CVE-2026-93287}
- ALSA: us122l: Prevent write upgrades for read mappings (Kazuki Hanai) [Orabug: 40079109] {CVE-2026-97931}
- net: usb: pegasus: don't rely on id table pointer arithmetic (Gary Guo) [Orabug: 40078670] {CVE-2026-97540}
- media: as102: do not rely on id table address comparison (Gary Guo)
- usb: serial: spcp8x5: don't store usb_device_id (Gary Guo)
- usb: usbtmc: don't store usb_device_id (Gary Guo)
- wifi: ath9k_htc: don't store usb_device_id (Gary Guo) [Orabug: 40078677] {CVE-2026-97541}
- usb: xusbatm: don't rely on id table pointer arithmetic (Gary Guo) [Orabug: 40078663] {CVE-2026-97539}
- xdrgen: Fix union declarations (Chuck Lever)
- perf evsel: Add per-thread warning for EOPNOTSUPP open failues (Ian Rogers)
- Revert "perf tests: Fix flakiness in BPF counters test on hybrid systems" (Sasha Levin)
- Revert "slab: reset slab->obj_ext when freeing and it is OBJEXTS_ALLOC_FAIL" (Sasha Levin)
- Revert "selftests/mm: report unique test names for each cow test" (Sasha Levin)
- Revert "selftests/mm: skip COW tmpfile cases when fallocate() is unsupported" (Sasha Levin)
- Revert "selftests: harness: Mark test fixture objects __maybe_unused" (Sasha Levin)
- Revert "nvme: apple: Add Apple A11 support" (Sasha Levin)
- Revert "nvme-apple: Drop the PRP null check chicken bit" (Sasha Levin)
- Revert "nvme-apple: Prevent shared tags across queues on Apple A11" (Sasha Levin)
- Revert "nvme-apple: Reset q->sq_tail during queue init" (Sasha Levin)
- Revert "arm64: dts: qcom: sc8180x: Fix the PCIe iommu-map entries" (Sasha Levin)
- Revert "arm64: dts: qcom: sdm845: Fix the PCIe iommu-map entries" (Sasha Levin)
- Revert "arm64: dts: qcom: sm8150: Fix the PCIe iommu-map entries" (Sasha Levin)
- Revert "arm64: dts: qcom: sm8250: Fix the PCIe iommu-map entries" (Sasha Levin)
- Revert "arm64: dts: qcom: sm8350: Fix the PCIe iommu-map entries" (Sasha Levin)
- Revert "arm64: dts: qcom: sm8450: Fix the PCIe iommu-map entries" (Sasha Levin)
- Revert "arm64: dts: qcom: sm8550: Fix the PCIe iommu-map entries" (Sasha Levin)
- Revert "arm64: dts: qcom: sm8650: Fix the PCIe iommu-map entries" (Sasha Levin)
- iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized (Nicolin Chen)
- crypto: ccp - Fix possible deadlock in SEV init failure path (Atish Patra)
- smb: client: fix UBSAN array-index-out-of-bounds in smb2_copychunk_range (Henrique Carvalho)
- xfs: actually recover intended file sizes in xfs_xmi_item_recover_intent (Darrick J. Wong)
- xfs: advance the findparent inode scan cursor while holding ILOCK (Darrick J. Wong)
- xfs: bail out on bitmap errors in xrep_agfl_fill (Darrick J. Wong) [Orabug: 40078682] {CVE-2026-97542}
- xfs: compute dquot checksum after resetting dd_lsn in repair (Darrick J. Wong)
- xfs: count escaped corruption errors in scrub stats (Darrick J. Wong)
- xfs: destroy seen inode bitmap when we fail to add a dirpath (Darrick J. Wong) [Orabug: 40078684] {CVE-2026-97543}
- xfs: don't leak dqacct if rhashtable insertion fails (Darrick J. Wong) [Orabug: 40078687] {CVE-2026-97544}
- xfs: don't leak new_bp if xfs_btree_bload_drop_buf fails (Darrick J. Wong) [Orabug: 40078689] {CVE-2026-97545}
- xfs: don't modify file attributes or poke fsnotify for dry runs (Darrick J. Wong)
- xfs: don't spin forever on zero-length dirents when salvaging them (Darrick J. Wong) [Orabug: 40078692] {CVE-2026-97546}
- xfs: fix backwards skipping logic in xrep_quota_block (Darrick J. Wong)
- xfs: fix bnobt repair space reservation disposal failure (Darrick J. Wong)
- xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN (Lin Jiapeng) [Orabug: 39972815,40078696] {CVE-2026-80530,CVE-2026-97547}
- xfs: fix name string recording in slowpath pptr tracepoints (Darrick J. Wong)
- xfs: fix replaying dirent removals into the temporary directory (Darrick J. Wong)
- xfs: initialise error in xfs_defer_finish_one() (Javier Tia) [Orabug: 40078708] {CVE-2026-97552}
- xfs: log the tempip after we convert it to extents format (Darrick J. Wong)
- xfs: preserve owner on in-memory btree creation (Darrick J. Wong)
- xfs: report nonexistent parents as a filesystem corruption (Darrick J. Wong)
- xfs: reset parent pointer args before each dir tree unlink repair (Darrick J. Wong)
- xfs: signal inode btree xref error if get_rec returns an error (Darrick J. Wong)
- xfs: snapshot old AGFL before rewriting it (Darrick J. Wong)
- xfs: snapshot scrub stats when rendering them (Darrick J. Wong)
- xfs: truncate quota file correctly when repairing quota file (Darrick J. Wong)
- smb: client: fix heap overflow in DACL owner/group rewrite (Bjoern Doebel) [Orabug: 40078720] {CVE-2026-97555}
- smb: client: avoid leaking refcount when cifs_sb_tlink() fails (Bjoern Doebel) [Orabug: 40078724] {CVE-2026-97556}
- smb: client: avoid leaking refcount in cifs_queue_oplock_break() (Bjoern Doebel) [Orabug: 40078730] {CVE-2026-97557}
- smb: client: fix file type corruption in wsl_to_fattr() (Paulo Alcantara)
- smb: client: fix file type corruption in cifs_reparse_point_to_fattr() (Paulo Alcantara)
- smb: client: fix one-byte OOB read in smb2_parse_native_symlink() (Paulo Alcantara) [Orabug: 40078747] {CVE-2026-97560}
- smb: client: pin DFS superblock in iterator callback (Karl Mehltretter) [Orabug: 40078757] {CVE-2026-97562}
- smb: client: reject userspace cifs.idmap descriptions (Aohan Mei) [Orabug: 40078772] {CVE-2026-97564}
- selftests: mptcp: fix an UAF in mptcp_connect.c (Gang Yan)
- mptcp: syncookies: remember the request backup flag (Matthieu Baerts) [Orabug: 40078794] {CVE-2026-97568}
- mptcp: subflow: no need to copy thmac during ulp_clone (Matthieu Baerts)
- mptcp: options: handle MPC data + csum reqd + no csum (Matthieu Baerts)
- bnxt_en: Propagate RX ring init failures in bnxt_init_nic() (Joe Damato) [Orabug: 40078806] {CVE-2026-97572}
- bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset() (Joe Damato) [Orabug: 40078811] {CVE-2026-97573}
- bnxt_en: bring back rtnl_lock() in the bnxt_open() path (Michael Chan)
- bnxt_en: Only restore LRO if the device supports TPA (Joe Damato)
- media: v4l2-ctrls: validate AV1 tile counts (Michael Bommarito) [Orabug: 40078824] {CVE-2026-97575}
- media: v4l2-ctrls: validate HEVC tile counts (Michael Bommarito) [Orabug: 40078826] {CVE-2026-97576}
- media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity (Michael Bommarito)
- media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer (Michael Bommarito)
- media: v4l2-h264: Fix memcmp() size in B1 reference list comparison (Xu Wang)
- media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity (Michael Bommarito)
- media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity (Michael Bommarito)
- media: hevc: add bounded tile-count helpers (Michael Bommarito)
- hwmon: (pmbus) Clear generic status alarms with CLEAR_FAULTS (Vishnu Razdan)
- hwmon: (gpio-fan) Fix use-after-free in alarm work (Fan Wu)
- hwmon: (chipcap2) fix channels in humidity alarm notifications (Javier Carrasco)
- hwmon: (applesmc) fix key backlight workqueue leak on register failure (Cong Nguyen)
- afs: Clear stale peer app data after address list changes (Chengfeng Ye) [Orabug: 40078852] {CVE-2026-97583}
- afs: Fix incorrect free in candidate cleanup in afs_lookup_server() (David Howells) [Orabug: 40078858] {CVE-2026-97584}
- perf: RISC-V: use BIT_ULL for u64 overflow masks (Xixin Liu)
- perf: RISC-V: store available counter mask as bitmap (Xixin Liu)
- s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm (Harald Freudenberger)
- s390/crypto: Fix use of mutex in atomic context (Harald Freudenberger)
- s390/crypto: Fix skcipher_walk return code handling in aes_s390 (Harald Freudenberger)
- s390/qeth: allow bridgeport queries despite OS_MISMATCH (Nagamani Pv)
- KVM: PPC: Book3S HV: Set irqfd->producer only on success (Leixiang)
- mac802154: fix use-after-free of sdata via queued RX frames (Ibrahim Hashimov) [Orabug: 40078888] {CVE-2026-97595}
- ipvs: reject invalid states in connection template sync records (Kyle Zeng) [Orabug: 40078891] {CVE-2026-97596}
- ipv4: fib: bound automatic table ID allocation (Zihan Xi) [Orabug: 40078901] {CVE-2026-97598}
- ieee802154: hwsim: serialize pib updates to fix double-free (David Carlier)
- ieee802154: cc2520: fix FIFOP work use-after-free (Fan Wu) [Orabug: 40078912] {CVE-2026-97600}
- ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink (Zhiling Zou) [Orabug: 40078919] {CVE-2026-97601}
- inet: frags: invalidate queues before flushing them (Yilin Zhang) [Orabug: 40078925] {CVE-2026-97602}
- fbdev: vfb: defer cleanup until the last reference (Weiming Shi) [Orabug: 40078939] {CVE-2026-97604}
- erofs: preserve LZMA decoders on resize failure (Nikhil Gurudasani) [Orabug: 40078947] {CVE-2026-97605}
- fs: autofs: fix memory leak in autofs_fill_super() (Jeffin Philip) [Orabug: 40078951] {CVE-2026-97606}
- scripts/sorttable: Mark long_size as __maybe_unused (Nathan Chancellor)
- vdpa: solidrun: Free IRQs after request failure (Xiongweimin)
- vdpa: ifcvf: Put device on unsupported feature error (Xiongweimin) [Orabug: 40078955] {CVE-2026-97607}
- netfilter: report NLM_F_DUMP_FILTERED when all is filtered out (Ilya Maximets)
- netfilter: nf_log: unregister loggers before per-net teardown (Chengfeng Ye) [Orabug: 40078958] {CVE-2026-97608}
- net: openvswitch: fix use-after-free of the flow table mask array (Norbert Szetei) [Orabug: 40078968] {CVE-2026-97611}
- net: mpls: clear inner_protocol when the last label is popped (Fourie Zhang) [Orabug: 40078972] {CVE-2026-97612}
- net: mana: Reserve extra CQ slot for the fence completion CQE (Sahil Chandna) [Orabug: 40078976] {CVE-2026-97613}
- net: hso: fix TIOCMIWAIT race (Johan Hovold)
- net/sched: act_api: release all action references on NEWACTION failure (Luoxuanqiang) [Orabug: 40078985] {CVE-2026-97616}
- ring-buffer: Check resize_disabled before publishing the new subbuf order (David Carlier) [Orabug: 40078989] {CVE-2026-97617}
- ring-buffer: Acquire the lock with irqsave in rb_wake_up_waiters() (Sebastian Andrzej Siewior)
- io_uring/net: let io_recv_buf_select return the length of the buffer region (Gabriel Krisman Bertazi)
- drm/i915: Fix memory leak in query_perf_config_list() (Thorsten Blum) [Orabug: 40079005] {CVE-2026-97899}
- drm/drm_exec: fix up contended obj when num_objects is 0 (Sunil Khatri) [Orabug: 40079009] {CVE-2026-97900}
- fs: don't return -EINVAL for successful nested thaw (Moritz Tanner) [Orabug: 40079015] {CVE-2026-97902}
- exec: do_close_on_exec() before taking exec_update_lock (Jann Horn)
- cpufreq: initialize policy rwsem before sysfs publication (Runyu Xiao) [Orabug: 40079019] {CVE-2026-97904}
- cpufreq: zero-initialize policy cpumask before sysfs publication (Zhongqiu Han) [Orabug: 40079023] {CVE-2026-97905}
- Bluetooth: btrtl: Don't leak return code when parsing firmware format v2 (Rongrong) [Orabug: 40079032] {CVE-2026-97907}
- Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev (Xu Rao)
- ASoC: sti: initialize IRQ lock before requesting IRQ (Runyu Xiao)
- ASoC: sprd: validate compress buffer sizes against fixed allocations (Tianchu Chen)
- accel/ivpu: Limit firmware log name prints to field size (Dawid Osuchowski)
- accel/ivpu: Validate firmware log buffer metadata (Magdalena Schulfer)
- accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr (Magdalena Schulfer) [Orabug: 40079055] {CVE-2026-97917}
- tracing: Keep the entry count when the histogram stats allocation fails (Donggeun Yoo) [Orabug: 40079065] {CVE-2026-97920}
- tracing: Let histogram values keep the percent and graph modifiers (Donggeun Yoo)
- tracing: Free histogram the field rejected for a bad modifier (Donggeun Yoo) [Orabug: 40079067] {CVE-2026-97921}
- tracing: Free histogram var refs regardless of how often they are referenced (Donggeun Yoo) [Orabug: 40079069] {CVE-2026-97922}
- tracing: Free histogram the var ref when its initialization fails (Donggeun Yoo) [Orabug: 40079077] {CVE-2026-97923}
- tracing/user_events: Don't destroy fields when event removal fails (Henry Martin)
- tick/broadcast: Plug clockevents replacement race (Thomas Gleixner) [Orabug: 40079083] {CVE-2026-97925}
- tunnels: Drop stale dst when building an ICMP error for PMTUD (Ido Schimmel)
- ufs: validate cylinder group metadata before caching it (Ali Ahmet Memis)
- ufs: create the root dentry after loading cylinder metadata (Ali Ahmet Memis)
- watchdog: sunxi_wdt: preserve boot-enabled watchdog (James Hilliard)
- dm/amdgpu: fix malformed link_settings debugfs output (Harry Wentland)
- ALSA: usbusx2y: validate URB actual_length in interrupt callback (Tristan Madani) [Orabug: 40079099] {CVE-2026-97929}
- ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf (Tristan Madani) [Orabug: 40079104] {CVE-2026-97930}
- ALSA: ctxfi: Fix CA20K2 S/PDIF passthrough (Roman Prucha)
- rust: allow unknown_lints in generated bindings for Rust < 1.88 (Miguel Ojeda)
- tracing: Fix memory corruption from the histogram stacktrace modifier (Donggeun Yoo) [Orabug: 40079129] {CVE-2026-97936}
- ipv6: fix fib6 walker UAF on seq stop (Zihan Xi) [Orabug: 40079142] {CVE-2026-97940}
- x86/mm: Fix user-space data loss with MADV_FREE and THP (Vernon Yang) [Orabug: 40079153] {CVE-2026-97945}
- crypto: x86/aria - add missing vzeroupper in AVX-512 code (Eric Biggers)
- crypto: x86/aria - add missing vzeroupper in AVX2 code (Eric Biggers)
- powerpc/eeh: Fix recursive locking on devices without EEH sensitive driver (Shivaprasad G Bhat)
- powerpc/ps3: Fix repository.c build failure (Thorsten Blum)
- ksmbd: prevent out-of-bounds reads in share config responses (Namjae Jeon)
- scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands (Maurizio Lombardi) [Orabug: 40079174] {CVE-2026-97951}
- scripts/mksysmap: fix escape of '$' in the __pi_ pattern (Lorenzo Stoakes)
- sunvdc: unmap LDC cookies when the descriptor send fails (Stian Halseth)
- openvswitch: fix wrong flag value in get_ipv6_ext_hdrs() (Eelco Chaudron)
- net: hsr: enable promiscuous mode on interlink port with fwd offload (Md Danish Anwar)
- net: stmmac: fix TX descriptor availability check for TSO traffic (Lorenzo Bianconi) [Orabug: 40079183] {CVE-2026-97953}
- net: stmmac: add TSO check for header length (Russell King)
- net: stmmac: add stmmac_tso_header_size() (Russell King)
- net: stmmac: fix TSO support when some channels have TBS available (Russell King)
- net: stmmac: TSO: Simplify the code flow of DMA descriptor allocations (Furong Xu)
- octeontx2-af: fix PF/CGX debugfs PCI bus lookup (Ratheesh Kannoth)
- net: phy: mediatek-ge: disable EEE on the MT7530 PHY (Vladislav Karmanov)
- net: phy: add phy_disable_eee (Heiner Kallweit)
- net: phy: mediatek: Re-organize MediaTek ethernet phy drivers (Sky Huang)
- cxgb4: clip_tbl: Fix spelling mistake "wont" -> "won't" (Colin Ian King)
- net: hinic: fix mailbox segment buffer overflow (Aamir Ahmed) [Orabug: 40079196] {CVE-2026-97957}
- net: sun4i-emac: fix missing of_node_put() for phy_node (Liyouhong)
- net/sched: cls_api: Don't replay RTM_GETCHAIN in tc_ctl_chain(). (Kuniyuki Iwashima) [Orabug: 40079199] {CVE-2026-97958}
- net/sched: cls_route: Fix in-place replace (Victor Nogueira)
- net/sched: cls_route: Reject handle aliasing (Victor Nogueira)
- net/sched: cls_route: free emptied bucket on filter move (Victor Nogueira) [Orabug: 40079204] {CVE-2026-97959}
- perf/x86/intel: Correct pt_regs->flags update for PEBS path (Dapeng Mi)
- perf/x86/intel/ds: Factor out PEBS group processing code to functions (Dapeng Mi)
- perf/x86/intel/ds: Remove redundant assignments to sample.period (Changbin Du)
- perf/x86/intel/ds: Clarify adaptive PEBS processing (Kan Liang)
- perf/core: Check sample_type in perf_sample_save_callchain (Yabin Cui)
- selftests/powerpc/tm: Fix tcheck() reading uninitialised CR value (Thibault Ferrante)
- net: stmmac: initialize ptp_lock at probe time (Lorenzo Bianconi) [Orabug: 40079216] {CVE-2026-97963}
- ppp_synctty: ensure a writeable skb header (Qingfang Deng) [Orabug: 40079219] {CVE-2026-97964}
- vxlan: initialize _md in vxlan_xmit_one() (Eric Dumazet) [Orabug: 40079222] {CVE-2026-97965}
- octeontx2-pf: reset HTB scheduler topology before freeing queues (Ratheesh Kannoth)
- hwmon: (corsair-cpro) Remove debugfs entries when probe fails (Linmao Li)
- hwmon: (aspeed-pwm-tacho) Propagate reset deassert errors (Pengpeng Hou)
- hwmon: (gpio-fan) take fan_data->lock in gpio_fan_shutdown() (Cong Nguyen)
- hwmon: (corsair-cpro) Create debugfs entries after hwmon registration (Linmao Li)
- net: ks8851: Fix receiver error in 100BASE-TX mode following software power-down (Marek Vasut)
- net/micrel: Fix typos in micrel driver code comments (Yicong Hui)
- net: dsa: lantiq_gswip: fix GSWIP_MDIO_PHY_FCONTX_EN value (Jan Havran)
- net: dsa: lantiq_gswip: move definitions to header (Daniel Golle)
- net: dsa: lantiq_gswip: prepare for more CPU port options (Daniel Golle)
- net: dsa: lantiq_gswip: deduplicate dsa_switch_ops (Daniel Golle)
- watchdog: msc313e: Sync timeout value if WDT was running at boot (Tzung-Bi Shih)
- watchdog: msc313e: Fix undefined behavior (Tzung-Bi Shih)
- watchdog: msc313e: Fix spurious reset on suspend (Tzung-Bi Shih)
- watchdog: msc313e: Enable clock before accessing hardware registers (Tzung-Bi Shih)
- watchdog: msc313e: Fix clock leak and spurious timer in settimeout() (Tzung-Bi Shih)
- watchdog: msc313e: Avoid division by zero (Tzung-Bi Shih)
- watchdog: fix hrtimer start when pretimeout is zero (David Arcari)
- mptcp: remove unneeded READ_ONCE() annotation (Paolo Abeni)
- net: macb: destroy the phylink instance on the probe error path (Nicolai Buchwitz) [Orabug: 40079249] {CVE-2026-97973}
- Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset (Jiajia Liu)
- Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset (Jiajia Liu)
- Bluetooth: btmtk: Declare MT7920 (MT7961 1a) Bluetooth firmware (Ivan Hu)
- Bluetooth: btintel_pcie: fix tx_handle bounds off-by-one (Kiran K)
- Bluetooth: btintel_pcie: validate packet_len before skb_put_data (Kiran K) [Orabug: 40079258] {CVE-2026-97976}
- Bluetooth: btusb: Fix UAF of btusb_data by rx_work (Luiz Augusto von Dentz) [Orabug: 40079261] {CVE-2026-97977}
- eth: ice: don't dereference pointers from TP_printk() (Jakub Kicinski) [Orabug: 40079263] {CVE-2026-97978}
- ice: add missing xa_destroy for sched_node_ids (Jacob Keller) [Orabug: 40079266] {CVE-2026-97979}
- idpf: account for VLAN header when parsing RSC packet header (Joshua Hay)
- ALSA: hda: Report a change when only the channel status bytes move (Hyeongjun An)
- ALSA: hda/common: Use guard() for mutex locks (Takashi Iwai)
- ALSA: hda/common: Use cleanup macros for PM controls (Takashi Iwai)
- ALSA: hda: Introduce auto cleanup macros for PM (Takashi Iwai)
- drm/logicvc: Drop the select of the nonexistent CONFIG_DRM_KMS_DMA_HELPER (Karl Mehltretter)
- net: ethernet: cortina: Count RX descriptors for freeq refill (Linus Walleij)
- net: ethernet: cortina: Count RX drops once per frame (Linus Walleij)
- net: ethernet: cortina: No mapping is a dropped rx (Linus Walleij)
- net: ethernet: cortina: Count dropped frames as NAPI work (Linus Walleij)
- net: ethernet: cortina: Finish RX updates before NAPI completion (Linus Walleij)
- net: ethernet: cortina: Fix budget accounting (Linus Walleij)
- net: ipv6: Clamp to IP6_MAX_MTU in ip6_dst_mtu_maybe_forward (Alice Mikityanska)
- net: ipv6: Fix UDP length overflow with PMTU discover and big MTU (Alice Mikityanska) [Orabug: 40079279] {CVE-2026-97984}
- af_unix: Return immediately when manage_oob() returns NULL for 0-length buffer. (Kuniyuki Iwashima)
- af_unix: Update last skb marker in manage_oob(). (Kuniyuki Iwashima) [Orabug: 40079300] {CVE-2026-97985}
- virtio_input: stop callbacks before unregistering input device (Karl Mehltretter) [Orabug: 40079307] {CVE-2026-97986}
- virtio_input: reset device if input_register_device() fails (Xiongweimin) [Orabug: 40079311] {CVE-2026-97987}
- virtio-pci: return IRQ_HANDLED after non-zero ISR (Andrew Stellman)
- vdpa_sim_net: check TX pull result before RX copy (Linfeng Sun) [Orabug: 40079323] {CVE-2026-97990}
- vdpa_sim_blk: reject out-of-range sector starts (Linfeng Sun) [Orabug: 40079328] {CVE-2026-97991}
- vhost-vdpa: protect config_ctx from being freed under the config callback (Yu Zhang) [Orabug: 40079332] {CVE-2026-97992}
- vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx (Yu Zhang) [Orabug: 40079336] {CVE-2026-97993}
- vhost/vdpa: reject VRING_NUM larger than device max (Jia Jia) [Orabug: 40079341] {CVE-2026-97994}
- virtio_console: do not free control-out buffers on remove (Jia Jia) [Orabug: 40079347] {CVE-2026-97995}
- virtio: fix use-after-free in unregister_virtio_device() (Karl Mehltretter) [Orabug: 40079351] {CVE-2026-97996}
- ASoC: mt6351: Publish the OF module alias (Hpp Iscas)
- netfilter: ip6_tables: set F_PROTO when proto value is nonzero (Florian Westphal)
- netfilter: nfnetlink_log: cope with concurrent instance destruction (Florian Westphal) [Orabug: 40079359] {CVE-2026-97998}
- ASoC: Intel: SST: Publish the PCI module aliases (Hpp Iscas)
- ASoC: bcm: bcm63xx: Publish the OF module aliases (Hpp Iscas)
- hwmon: (ina2xx) Parameterize ina2xx_data in ina226_alert_read() (Jared Kangas)
- hwmon: Introduce 64-bit energy attribute support (Guenter Roeck)
- libnvdimm: Replace namespace_match() with device_find_child_by_name() (Zijun Hu)
- hwmon: (ltc4282) Make sure clk_init_data is fully initialized (Geert Uytterhoeven)
- ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev (Edward Adam Davis) [Orabug: 40079373] {CVE-2026-98006}
- bpf: Reject non-scalar bpf_loop iteration counts (Kumar Kartikeya Dwivedi) [Orabug: 40079377] {CVE-2026-98007}
- net: macb: fix NULL pointer dereference on unbind with fixed-link (Vineeth Karumanchi) [Orabug: 40079379] {CVE-2026-98008}
- net: macb: rename bp->sgmii_phy field to bp->phy (Théo Lebrun)
- net/sched: ets: clamp quantum in parse and fallback paths (Jamal Hadi Salim) [Orabug: 40079383] {CVE-2026-98009}
- net/sched: drr: clamp quantum in change class (Jamal Hadi Salim) [Orabug: 40079387] {CVE-2026-98010}
- net/sched: pie: clamp psched_mtu in pie_drop_early (Jamal Hadi Salim)
- net/sched: hhf: clamp quantum in change and init paths (Jamal Hadi Salim) [Orabug: 40079394] {CVE-2026-98011}
- net/sched: sfq: clamp quantum in change path (Jamal Hadi Salim) [Orabug: 40079398] {CVE-2026-98012}
- net/sched: fq_pie: clamp quantum in change path (Jamal Hadi Salim)
- net/mlx5: E-Switch, prevent mc_list repopulation during vport disable (Lama Kayal) [Orabug: 40079405] {CVE-2026-98014}
- net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put (Yael Chemla) [Orabug: 40079408] {CVE-2026-98015}
- net/mlx5e: Fix use-after-free race in sample_restore_put() (Carolina Jubran) [Orabug: 40079415] {CVE-2026-98016}
- net/mlx5e: Fix ETS zero BW reporting when one TC holds 100% (Carolina Jubran)
- net/mlx5e: Fix setting RS FEC after remapping (Shahar Shitrit)
- net/sched: defer qdisc freeing after failed creation (Weiming Shi) [Orabug: 40079419] {CVE-2026-98017}
- net: mctp: i3c: serialize probe with bus removal (Xingwang Xiang)
- powerpc/kexec_file: Use inclusive range checks in add_usable_mem() (Thorsten Blum)
- pds_core: don't release PCI regions for VFs on reset (Nikhil P. Rao)
- pds_core: fix cmd_regs access racing BAR unmap on reset (Nikhil P. Rao) [Orabug: 40079430] {CVE-2026-98020}
- net: reject oversized tx_queue_len at netlink parse time (Jamal Hadi Salim) [Orabug: 40079434] {CVE-2026-98021}
- net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations (Jamal Hadi Salim) [Orabug: 40079442] {CVE-2026-98022}
- vxlan: reject dynamic fdb entries that reference a nexthop id (Seungwon Bae) [Orabug: 40079446] {CVE-2026-98023}
- s390/ism: folio_put() after error (Alexandra Winter)
- net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow (Jason Winter) [Orabug: 40079453] {CVE-2026-98025}
- ionic: use netif_txq_maybe_stop() in ionic_tx() (Nikhil P. Rao)
- octeontx2-af: mcs: Clear stale X2P calibration state before calibration (Viswajith Murali)
- net: bridge: mcast: properly convert mglist to rcu (Nikolay Aleksandrov) [Orabug: 40079458] {CVE-2026-98026}
- net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size (Jakub Kicinski) [Orabug: 40079463] {CVE-2026-98027}
- eth: nfp: drop the replaced rule from the list when reprogramming fails (Jakub Kicinski) [Orabug: 40079467] {CVE-2026-98028}
- eth: nfp: bound the ntuple rule dump by the caller's buffer size (Jakub Kicinski) [Orabug: 40079470] {CVE-2026-98029}
- eth: nfp: migrate to new RXFH callbacks (Jakub Kicinski)
- net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size (Jakub Kicinski) [Orabug: 40079473] {CVE-2026-98030}
- bonding: use skb_cow_head() in bond_do_alb_xmit() and rlb_arp_xmit() (Eric Dumazet)
- nexthop: Initialize extack in remove_nh_grp_entry() (Ido Schimmel) [Orabug: 40079482] {CVE-2026-98031}
- selftests/bpf: Fix flaky bpf_nf test when random NAT port is 0 (Jiayuan Chen)
- bpf: Reject untrusted allocated-object pointers (Ning Ding) [Orabug: 40079500] {CVE-2026-98037}
- bpf: Require MEM_PERCPU for percpu kptr stores (Kumar Kartikeya Dwivedi) [Orabug: 40079506] {CVE-2026-98039}
- thermal: sysfs: switch to use scnprintf() to suppress truncation warning (Andy Shevchenko)
- bpf: Don't predict JMP32 pointer vs zero comparisons (Eduard Zingerman) [Orabug: 40079510] {CVE-2026-98041}
- bpf: Mark faultable stack helpers as sleepable (Kumar Kartikeya Dwivedi) [Orabug: 40079520] {CVE-2026-98045}
- bpf: Mark bpf_btf_find_by_name_kind() as sleepable (Kumar Kartikeya Dwivedi) [Orabug: 40079522] {CVE-2026-98046}
- net: bcmasp: fix tx_spb_ring_full() checking same slot cnt times (Justin Chen) [Orabug: 40079537] {CVE-2026-98051}
- net: bcmasp: clear txcb->last before writing each descriptor (Justin Chen) [Orabug: 40079541] {CVE-2026-98052}
- ASoC: Intel: avs: Fix unbalanced module reference count (Cezary Rojewski) [Orabug: 40079546] {CVE-2026-98054}
- ASoC: Intel: avs: Do not ignore -ENOENT when loading a topology (Cezary Rojewski)
- ASoC: Intel: avs: Clean up the bus when fetching ML caps fails (Cezary Rojewski) [Orabug: 40079548] {CVE-2026-98055}
- nvme-tcp: defer TLS inline send to io_work (Xixin Liu)
- nvme-tcp: open-code nvme_tcp_queue_request() for R2T (Hannes Reinecke)
- nvme: remove stale namespaces by NSID range during scan (Mohamed Khalfella) [Orabug: 40079550] {CVE-2026-98056}
- ring-buffer: Add checking nr_subbufs to persistent ring buffer validation (Steven Rostedt) [Orabug: 40079555] {CVE-2026-98057}
- bpf: Mark sched_process_wait argument as nullable (Kumar Kartikeya Dwivedi) [Orabug: 40079562] {CVE-2026-98059}
- bpf: Fix NULL-ptr-deref in btf_var_show() (Jiayuan Chen) [Orabug: 40079569] {CVE-2026-98063}
- bpf: Fix NULL-ptr-deref when showing a void BTF type (Jiayuan Chen) [Orabug: 40079572] {CVE-2026-98064}
- ALSA: caiaq: Fix potential double-free at error path (Takashi Iwai) [Orabug: 40079576] {CVE-2026-98066}
- selftests/alsa: Fix the step check for INTEGER controls (Hyeongjun An)
- arm64: trans_pgd: clone only the linear map that exists at runtime (Breno Leitao)
- net: gro: Fix nesting of TCP GSO SKBs in skb_gro_receive_list() (Hw He)
- net: stmmac: reconfigure RX packet parser table in stmmac_hw_setup() after reset (Lorenzo Bianconi)
- bonding: do not clear curr_active_slave prematurely when releasing all slaves (Eric Dumazet) [Orabug: 40079606] {CVE-2026-98074}
- bpf: reject BPF_PSEUDO_FUNC reference to the main program (Eduard Zingerman) [Orabug: 40079610] {CVE-2026-98075}
- tracing/probes: Fix use-after-free on field name/type of events with multiple probes (Henry Martin) [Orabug: 40079616] {CVE-2026-98076}
- netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() (Joas Antonio Dos Santos) [Orabug: 40079621] {CVE-2026-98077}
- ipvs: fix reversed sequence option serialization (Kyle Zeng) [Orabug: 40079625] {CVE-2026-98078}
- btrfs: do not force reloc root creation during qgroup_account_snapshot() (Qu Wenruo) [Orabug: 40079634] {CVE-2026-98080}
- btrfs: send: fix lost error return value in will_overwrite_ref() (Avi Weiss)
- btrfs: zoned: finish active block group cleanup if call_zone_finish() fails (Johannes Thumshirn) [Orabug: 40079639] {CVE-2026-98081}
- btrfs: return proper negative error code for update_raid_extent_item() (Qu Wenruo)
- btrfs: fix the possible bioc_list memory leak during error (Qu Wenruo) [Orabug: 40079643] {CVE-2026-98082}
- btrfs: fix transaction use-after-free in raid stripe insertion (Shuangpeng Bai) [Orabug: 40079647] {CVE-2026-98083}
- ASoC: ux500: Program the MSP FIFO watermarks (Linus Walleij)
- ASoC: ux500: Allow repeated MSP prepare calls (Linus Walleij)
- ASoC: ux500: Remove obsolete PRCMU QoS calls (Linus Walleij)
- ASoC: ux500: Request the MSP MMIO resource (Linus Walleij)
- ASoC: ux500: Deassert the MSP reset during probe (Linus Walleij)
- mfd: db8500-prcmu: Fold dbx500 header into db8500 (Linus Walleij)
- arm: Handle KCOV __init vs inline mismatches (Kees Cook)
- mfd: db8500-prcmu: Remove needless return in three void APIs (Zijun Hu)
- ASoC: ux500: Validate MSP DAI configuration (Linus Walleij)
- ASoC: ux500: Correct MSP frame and bit clock setup (Linus Walleij)
- ASoC: ux500: Propagate MSP setup errors (Linus Walleij)
- ASoC: ux500: Fix MSP stream lifecycle handling (Linus Walleij)
- printk/nbcon: Change nbcon_irq_work to IRQ_WORK_LAZY (John Ogness)
- ALSA: ump: do not touch legacy_rmidi before it exists (Qingyu Zhang) [Orabug: 40079657] {CVE-2026-98086}
- ALSA: ump: Update rawmidi name per EP name update (Takashi Iwai)
- ALSA: ump: Copy safe string name to rawmidi (Takashi Iwai)
- ALSA: ump: Copy FB name string more safely (Takashi Iwai)
- ALSA: rawmidi: Show substream activity in info ioctl (Takashi Iwai)
- ALSA: rawmidi: Expose the tied device number in info ioctl (Takashi Iwai)
- locking/lockdep: Invalidate stale class_cache entries for zapped classes (Eric Dumazet)
- perf/core: Skip empty AUX records with only format flags (Leo Yan)
- scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues() (Ivy Lopez) [Orabug: 40079664] {CVE-2026-98088}
- perf: RISC-V: check cpu_hw_evt before dereference in overflow IRQ (Xixin Liu)
- bonding: alb: fix uninitialized transport header access in alb_determine_nd() (Eric Dumazet) [Orabug: 40079670] {CVE-2026-98089}
- btrfs: restore active device pointers after failed sprout (Guanghui Yang) [Orabug: 40079672] {CVE-2026-98090}
- btrfs: detach failed sprout device from transaction update list (Guanghui Yang) [Orabug: 40079676] {CVE-2026-98091}
- drm/xe/oa: Remove sysfs entry on idr_alloc failure in xe_oa_add_config_ioctl() (Lu Yao)
- ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close() (Wangdicheng) [Orabug: 40079682] {CVE-2026-98092}
- ASoC: amd: renoir: fix disable_pdm_interrupts() to clear mask bits (Wangdicheng)
- s390/boot: Fix physical memory search range (Vasily Gorbik)
- ALSA: hda: restore MFG widget enumeration after core split (Xu Rao)
- ALSA: hda/core: Use guard() for mutex locks (Takashi Iwai)
- staging: fbtft: make dirty_lock IRQ-safe (Sh_Def)
- af_packet: Don't cast tpacket_hdr.tp_len to int in tpacket_parse_header(). (Kuniyuki Iwashima) [Orabug: 40079695] {CVE-2026-98095}
- ipv6: sr: restore network header before routing and forwarding (Eric Dumazet) [Orabug: 40079699] {CVE-2026-98096}
- tipc: Dont send random pad bytes in RESET/ACTIVATE messages (David Laight) [Orabug: 40079706] {CVE-2026-98097}
- tipc: fix NULL deref in tipc_named_node_up() on empty publication list (Tung Nguyen) [Orabug: 40079713] {CVE-2026-98098}
- ip6_gre: check tunnel info before xmit in ip6gre_tunnel_xmit (Eric Dumazet)
- ipv6: mcast: fix RCU list diversion in ip6_mc_del1_src() (Eric Dumazet) [Orabug: 40079730] {CVE-2026-98102}
- ppp: ppp_synctty: simplify tty disc_data access (Qingfang Deng)
- ppp: ppp_async: simplify tty disc_data access (Qingfang Deng)
- igmp: convert struct ip_sf_list to RCU (Eric Dumazet) [Orabug: 40079734] {CVE-2026-98103}
- net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted (Jamal Hadi Salim) [Orabug: 40079740] {CVE-2026-98104}
- net: ethernet: oa_tc6: Fix for the wrong data type (Selvamani Rajagopal)
- net: ethernet: oa_tc6: Disable tx queues on fatal error (Selvamani Rajagopal)
- net: ethernet: oa_tc6: Improve the error recovery (Selvamani Rajagopal)
- net: ethernet: oa_tc6: Protect skb pointer used by two different kernel instances (Selvamani Rajagopal)
- net: ethernet: oa_tc6: Add the OA_TC6_ prefix to standard registers (Ciprian Regus)
- net: ethernet: oa_tc6: Export standard defined registers (Ciprian Regus)
- net: ethernet: oa_tc6: Handle the OA TC6 SPI protected mode (Ciprian Regus)
- net: ethernet: oa_tc6: Interrupt is active low, level triggered. (Selvamani Rajagopal)
- ASoC: ab8500: Validate and program TDM slots correctly (Linus Walleij)
- ASoC: ab8500: Correct digital interface format setup (Linus Walleij)
- ASoC: ab8500: Repair the DAPM capture graph (Linus Walleij)
- ASoC: ab8500: Reset the audio block before configuring it (Linus Walleij)
- Bluetooth: hci_mrvl: Fix wrong return value check of wait_on_bit_timeout() (Gongwei Li)
- Bluetooth: L2CAP: clear FLAG_DEFER_SETUP only for same PID/PSM (Pauli Virtanen)
- Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect (Pauli Virtanen) [Orabug: 40079748] {CVE-2026-98107}
- Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan (Pauli Virtanen) [Orabug: 40079753] {CVE-2026-98108}
- Bluetooth: hci_core: Fix race condition during device registration (Aleksandr Nogikh) [Orabug: 40079757] {CVE-2026-98109}
- Bluetooth: btintel: bound firmware ID by TLV length (Laxman Acharya Padhya) [Orabug: 40079759] {CVE-2026-98110}
- Bluetooth: btintel: validate version TLV value lengths (Laxman Acharya Padhya) [Orabug: 40079761] {CVE-2026-98111}
- workqueue: reject watchdog thresholds that overflow jiffies (Jiacheng Xu)
- workqueue: replace use of system_wq with system_percpu_wq (Marco Crivellari)
- Bluetooth: btintel_pcie: Clear automask on spurious interrupts (Kiran K)
- sched_ext: Fix timer pinning and return value in scx_central (Wanwu Li)
- s390/ipl: Fix NULL deref in dump_reipl without re-IPL parm block (Vasily Gorbik)
- s390/ipl: Fix NULL deref in kdump without re-IPL parm block (Vasily Gorbik)
- s390/time: Use jiffies instead of jiffies_64 (Heiko Carstens)
- s390/vtime: Use __this_cpu_read() / get rid of READ_ONCE() (Heiko Carstens)
- ksmbd: rate limit unmapped SID errors (Namjae Jeon)
- ksmbd: propagate DACL parsing errors (Namjae Jeon)
- ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF (Yilin Zhang) [Orabug: 40079779] {CVE-2026-98116}
- OPP: of: Fix potential multiplication overflow when calculating freq (Colin Ian King)
- perf symbol: Do not use debug file as the binary type (Adrian Hunter)
- watchdog: msc313e: Fix NULL pointer dereference in PM callbacks (Tzung-Bi Shih)
- vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del() (Baul Lee) [Orabug: 40079802] {CVE-2026-98122}
- net: amd-xgbe: discard rx packets with bad FCS (James Nugraha)
- raw: annotate disconnect-side IPv4 match writers (Luoxuanqiang)
- sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration (Henry Martin) [Orabug: 40079806] {CVE-2026-98123}
- smb: client: transport: Fix debug printing in __release_mid() (Andy Shevchenko)
- smb/client: fix integer truncation in collapse range (Huiwen He)
- smb/client: fix data corruption in emulated insert range (Huiwen He)
- smb: move copychunk definitions to common/smb2pdu.h (Zhangguodong)
- smb: client: batch SRV_COPYCHUNK entries to cut round trips (Henrique Carvalho)
- smb/client: mark file sparse before emulating insert range (Huiwen He)
- smb/client: validate new EOF for zero range (Huiwen He) [Orabug: 40079822] {CVE-2026-98126}
- smb/client: validate new EOF for insert range (Huiwen He) [Orabug: 40079827] {CVE-2026-98127}
- scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add() (Milan P. Gandhi) [Orabug: 40079831] {CVE-2026-98128}
- scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add() (Milan P. Gandhi) [Orabug: 40079837] {CVE-2026-98129}
- sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START (Xin Long) [Orabug: 40079843] {CVE-2026-98130}
- net/sched: act_api: fix skb sizing and action leak on reoffload delete (Victor Nogueira)
- net/sched: act_api: size the RTM_GETACTION reply from the actions (Victor Nogueira)
- net/sched: act_api: budget all shared attributes in notify skbs (Victor Nogueira)
- net: iptunnel: fix stale transport header during tunnel decapsulation (Dong Chenchen)
- tcp: use GFP_ATOMIC in tcp_send_active_reset() (Eric Dumazet)
- net: icmp: avoid invalid transport header access in icmp_send tracepoint (Eric Dumazet)
- drm/cirrus-qemu: Validate BAR0 size during probe (Slawomir Stepien) [Orabug: 40079874] {CVE-2026-98142}
- drm/cirrus: Use video aperture helpers (Thomas Zimmermann)
- ufs: do not treat unreadable directory blocks as empty (Ali Ahmet Memis)
- bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic (Jiayuan Chen) [Orabug: 40079901] {CVE-2026-98151}
- selftests/cgroup: Fix cg_run_in_subcgroups ignoring arg parameter (Hongfu Li)
- sched_ext: Fix nonexistent field in sched-ext.rst example (Liang Luo)
- nvmet-rdma: fix queue leak when connect backlog is exceeded (Xixin Liu) [Orabug: 40079902] {CVE-2026-98152}
- nvme-rdma: fix -EIO cleanup order in queue_rq (Xixin Liu) [Orabug: 40079913] {CVE-2026-98154}
- accel/qaic: Address potential out-of-bounds read in resp_worker() (Youssef Samir)
- drm/virtio: Fix a NULL vs ERR_PTR() bug in virtio_gpu_user_framebuffer_create() (Dan Carpenter)
- EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation (Jad Keskes) [Orabug: 40079927] {CVE-2026-98157}
- EDAC/igen6: Fix channel address decode for non-hash mode (Qiuxu Zhuo)
- EDAC/igen6: Fix channel selection hash (Qiuxu Zhuo)
- EDAC/igen6: Fix interleave boundary condition (Qiuxu Zhuo)
- RAS/AMD/ATL, EDAC/amd64: Only load ATL when needed (Yazen Ghannam)
- ARM: ensure interrupts are enabled in __do_user_fault() (Russell King)
- ARM: 9484/1: enable interrupts when unhandled user faults are triggered (Yuanbin Xie)
- mm/damon/core: avoid infinite kdamond_merge_regions() internal loop (Seongjae Park) [Orabug: 40033139] {CVE-2026-89796}
- Bluetooth: btrtl: Add the support for RTL8761CUV (Max Chou)
- af_unix: Unlink scc_entry in unix_del_edge(). (Kuniyuki Iwashima) [Orabug: 39972794] {CVE-2026-80521}
- l2tp: fix tunnel and session refcount leak on seq_file release (Eric Dumazet) [Orabug: 39972719] {CVE-2026-74735}
- ksmbd: use memcmp() to compare ClientGUIDs (Namjae Jeon)
- ASoC: meson: aiu: Validate written enum values (Hyeongjun An) [Orabug: 39886372] {CVE-2026-74294}
- ASoC: topology: Check PCM and DAI name strings before use (Cássio Gabriel) [Orabug: 39886361] {CVE-2026-74291}
- ipv4: fib: Don't dump dying fib_info in fib_leaf_notify(). (Kuniyuki Iwashima) [Orabug: 39886353] {CVE-2026-74289}
- bpf: Guard __get_user acesss with access_ok for uprobe_multi data (Jiri Olsa) [Orabug: 39886262] {CVE-2026-74258}
- RDMA/bnxt_re: Proper rollback if the ioremap fails (Selvin Xavier) [Orabug: 39886234] {CVE-2026-72496}
- coresight: platform: defer connection counter increment until alloc succeeds (Jie Gan)
- md/raid10: fix writes_pending and barrier reference leaks on discard failures (Abd-Alrhman Masalkhi) [Orabug: 39886086] {CVE-2026-72438}
- sctp: fix err_chunk memory leaks in INIT handling (Xin Long) [Orabug: 39886018] {CVE-2026-72413}
- bpf: Mask pseudo pointer values in verifier logs (Nuoqi Gui) [Orabug: 39885989] {CVE-2026-72402}
- Bluetooth: ISO: fix malformed ISO_END/CONT handling (Pauli Virtanen) [Orabug: 39885808] {CVE-2026-72334}
- bpf: Reject redirect helpers without a bpf_net_context (Daniel Borkmann) [Orabug: 39860076] {CVE-2026-68337}
- drm/vc4: hvs/v3d: Fix null dereference in unbind (Gregor Herburger) [Orabug: 39859967] {CVE-2026-68303}
- tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (Cen Zhang) [Orabug: 39859926] {CVE-2026-68289}
- net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (Yehyeong Lee) [Orabug: 39859921] {CVE-2026-68288}
- drop_monitor: fix size calculations for 64-bit attributes (Eric Dumazet) [Orabug: 39859917] {CVE-2026-68287}
- drop_monitor: perform u64_stats updates under IRQ-disabled section (Eric Dumazet) [Orabug: 39859913] {CVE-2026-68286}
- ppp_async: drop the errored frame instead of resetting its headroom (Vlatko Kosturjak) [Orabug: 40079934] {CVE-2026-98158}
- of: dynamic: Fix overlayed devices not probing because of fw_devlink (Saravana Kannan)
- driver core: Export get_dev_from_fwnode() (Ulf Hansson)
- drm/amd/display: clean-up dead code in dml2_mall_phantom (Brahmajit Das)
- wifi: mt76: mt7921: skip unknown CLC firmware records (Laxman Acharya Padhya)
- wifi: mt76: mt7921: validate CLC firmware records (Laxman Acharya Padhya) [Orabug: 40079939] {CVE-2026-98159}
- Revert "ARM: 9481/2: breakpoint: CFI breakpoints only on demand" (Sasha Levin)
- Revert "bpf, s390: Clear fetch destination on faulting arena atomic" (Sasha Levin)
- ksmbd: remove stale channels from all sessions on teardown (Gil Portnoy)
- bpftool: Strip all -Wformat* flags from bootstrap libbpf build (Andrii Nakryiko)
- firmware: stratix10-svc: fix FCS SMC call kernel-doc (Genevieve Chan)
- netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state (Florian Westphal) [Orabug: 40073059] {CVE-2026-93288}
- ASoC: amd: yc: Add DMI quirk for HyperX OMEN Gaming Laptop 16-ap1xxx (Lin Xianglin)
- scsi: core: Do not block on tag allocation in scsi_eh_lock_door() (Zizhi Wo) [Orabug: 40073071] {CVE-2026-93781}
- ASoC: rt5645: Perform the initial jack detect at probe (Rudi Heitbaum)
- spi: dw: fix wrong RX_SAMPLE_DLY setting after resume (Jisheng Zhang)
- ata: libata-core: Disable LPM on WDC WD141KFGX-68FH9N0 (Niklas Cassel)
- hwmon: (corsair-psu) Fix linear11 calculation (Guenter Roeck)
- vhost-scsi: flush backend after device ioctls (Jia Jia) [Orabug: 40073076] {CVE-2026-93782}
- ASoC: amd: yc: Add DMI quirk for HP Victus Laptop 16-e1xxx (Zhang Heng)
- Drivers: hv: vmbus: add VTL2 redirect connection ID (Hardik Garg)
- ata: libata-core: Disable LPM on WD Green 2.5 480GB (Niklas Cassel)
- ALSA: hda/realtek: Add mute LED quirk for HP Victus 16-e0xxx (MB 88ED) (André Pragosa)
- ata: libata-core: Disable LPM on some WD drives (Niklas Cassel)
- ALSA: usb-audio: Add quirk for Corsair Virtuoso (later revision) (Robert Abrahamse)
- Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame (Jiale Yao) [Orabug: 40073080] {CVE-2026-93783}
- wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie() (Deepanshu Kartikey) [Orabug: 40073087] {CVE-2026-93784}
- cifs: validate idmap key payload length (Li Qiang) [Orabug: 40073095] {CVE-2026-93785}
- powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash (Vaibhav Jain)
- ice: pass the return value of skb_checksum_help() (Michal Swiatkowski)
- ALSA: hda/realtek: Add mute LED quirk for HP Laptop 14s-dr1xxx (Madhavender Singh)
- ALSA: usb-audio: Add dB map quirk for Razer Barracuda X 2.4 (Markus Lindner)
- phonet: check register_netdevice_notifier() error in phonet_device_init() (Heminhong)
- drm/gma500: return errors from Oaktrail HDMI I2C reads (Pengpeng Hou)
- ksmbd: preserve VFS inherited POSIX ACL mask (Namjae Jeon)
- wifi: mac80211_hwsim: reject undersized HWSIM_ATTR_TX_INFO (Ibrahim Hashimov)
- regulator: core: clamp voltage constraints before applying apply_uV (Kamal Wadhwa)
- smb: client: bound dirent name against end of SMB response in cifs_filldir (Jay Vadayath) [Orabug: 40073128] {CVE-2026-93787}
- wifi: mwifiex: replace one-element arrays with flexible array members (Georgi Valkov)
- ALSA: hda/realtek: Add HDA_CODEC_QUIRK for Samsung 750XBE/730XBE (Zhang Heng)
- wifi: iwlwifi: acpi: validate WGDS table revision index (Emmanuel Grumbach) [Orabug: 40073135] {CVE-2026-93788}
- ALSA: usb-audio: Add FIXED_RATE quirk for JBL Quantum650 Wireless (Daniel C. Ribeiro)
- wifi: iwlwifi: bound aligned TLV advance in FW parser (Emmanuel Grumbach) [Orabug: 40073140] {CVE-2026-93789}
- ALSA: hda/realtek: Add quirk for HP Pavilion x360 (Takashi Iwai)
- drm/amd/pm/si: Don't schedule thermal work when queue isn't initialized (Timur Kristóf)
- arm64: kprobes: Allow reentering kprobes while single-stepping (Pu Hu)
- wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif (Emmanuel Grumbach) [Orabug: 40073149] {CVE-2026-93790}
- wifi: iwlwifi: mvm: add a check on the tid coming from the firmware (Emmanuel Grumbach) [Orabug: 40073156] {CVE-2026-93791}
- arm64: fixmap: Allow 256K early_ioremap() at any offset (Yu Peng)
- wifi: iwlwifi: mvm: fix a possible underflow (Emmanuel Grumbach) [Orabug: 40073161] {CVE-2026-93792}
- wifi: iwlwifi: mvm: validate TX_CMD response layout (Emmanuel Grumbach) [Orabug: 40073170] {CVE-2026-93793}
- ASoC: Intel: sof_sdw: Add quirks for new Dell laptops (Charles Keepax)
- smb/client: flush dirty data before punching a hole (Huiwen He) [Orabug: 40073176] {CVE-2026-93794}
- blk-cgroup: fix leaks and online flag on radix_tree_insert failure (Tao Cui) [Orabug: 40073183] {CVE-2026-93795}
- ALSA: hda/realtek: Add quirk for HP EliteBook 830 G8 (8AB8) to enable mute LEDs (Marcel Kłos)
- wifi: iwlwifi: pcie: null RX pointers after free (Emmanuel Grumbach) [Orabug: 40073195] {CVE-2026-93796}
- wifi: iwlwifi: mvm: fix sched scan IE sizing (Emmanuel Grumbach)
- wifi: iwlwifi: mvm: parse beacon notif per layout (Emmanuel Grumbach)
- wifi: iwlwifi: mvm: fix an off-by-1 boundary check (Emmanuel Grumbach) [Orabug: 40073204] {CVE-2026-93797}
- wifi: iwlwifi: mvm: validate mac_link_id in session protect notif (Emmanuel Grumbach)
- btrfs: fix reloc root cleanup in merge_reloc_roots() (Filipe Manana) [Orabug: 40073215] {CVE-2026-93798}
- wifi: iwlwifi: mvm: validate sta_id in BA window status notif (Emmanuel Grumbach) [Orabug: 40073224] {CVE-2026-93799}
- spi: dw-dma: Wait for controller idle before completing Tx (Wang Yuwei)
- btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol() (Filipe Manana) [Orabug: 40073232] {CVE-2026-93800}
- btrfs: only account delalloc bytes for regular file inodes in btrfs_getattr() (Dave Chen)
- cifs: Fix support for creating SFU fifo (Pali Rohár)
- ALSA: hda: cs35l56: Fail if wmfw file is missing (Richard Fitzgerald)
- ALSA: hda/realtek - Add quirk for HP Victus 15-fa0xxx (MB 8A50) (Rohit Sinha)
- ALSA: hda/realtek: Fix speakers on MECHREVO WUJIE Series (Chen Bowen)
- smb/client: zero-initialize stack-allocated cifs_open_info_data (Chenxiaosong) [Orabug: 40073242] {CVE-2026-93801}
- cifs: Fix support for creating SFU socket (Pali Rohár)
- smb/client: reduce fallocate zero buffer allocation (Huiwen He)
- ASoC: rt712-sdca: reset codec at io_init to fix silent headphone (Tianze Shao)
- wifi: rsi: validate beacon length before fixed buffer copy (Pengpeng Hou) [Orabug: 40073246] {CVE-2026-93802}
- netfilter: ipset: mark the rcu locked areas properly (Jozsef Kadlecsik)
- wifi: libipw: fix key index receive bound checks (Pengpeng Hou) [Orabug: 40073254] {CVE-2026-93803}
- gpio: dwapb: Mask interrupts at hardware initialization (Liang Hao)
- wifi: mac80211: ibss: wait for in-flight TX on disconnect (Anjaneyulu) [Orabug: 40073260] {CVE-2026-93804}
- wifi: cfg80211: validate rx/tx MLME callback frame lengths before access (Catherine) [Orabug: 40073269] {CVE-2026-93805}
- ksmbd: validate SID namespace before mapping IDs (Namjae Jeon)
- ksmbd: mark invalid session responses as signed (Namjae Jeon)
- ksmbd: find bound sessions during reauthentication (Namjae Jeon)
- wifi: cfg80211: validate assoc response length before status and IE access (Catherine) [Orabug: 40073276] {CVE-2026-93806}
- wifi: rsi: avoid reading TKIP MIC keys for non-TKIP ciphers (Pengpeng Hou) [Orabug: 40073284] {CVE-2026-93807}
- wifi: mac80211: validate deauth frame length before reason access (Catherine)
- wifi: ralink: RT2X00: init EEPROM properly (Corentin Labbe)
- ALSA: usb-audio: caiaq: validate EP1 reply lengths (Pengpeng Hou) [Orabug: 40073293] {CVE-2026-93808}
- ksmbd: fix credit charge calculation for SMB2 QUERY_INFO (Namjae Jeon)
- drm/amdgpu: flush pending RCU callbacks on module unload (Perry Yuan) [Orabug: 40073297] {CVE-2026-93809}
- ASoC: amd: yc: Add Alienware m15 R7 AMD to DMIC quirk table (Jetha Chan)
- netfs: Fix decision whether to disallow write-streaming due to fscache use (David Howells)
- cachefiles: Fix double fput (David Howells) [Orabug: 40073302] {CVE-2026-93810}
- xen/gntalloc: validate grant count before allocation (Yousef Alhouseen)
- freevxfs: don't BUG() on unknown typed-extent type (Farhad Alemi)
- xen/front-pgdir-shbuf: free grant reference head on errors (Yousef Alhouseen)
- ksmbd: Fix acl.sd_buf memory leak and invalid sd_size error handling (Qiang Liu)
- ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr (Qiang Liu)
- drm/arm/komeda: fix error handling for clk_prepare_enable() and callers (Gustavo Kenji Mendonça Kaneko)
- ALSA: hda/realtek: Add quirk for HP Victus 16-e0xxx (88EE) to enable mute LED (Shubham Nayak)
- ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr (Qiang Liu)
- netfilter: nf_conntrack_expect: zero at allocation time (Florian Westphal)
- drm/arm/malidp: use clk_bulk API in runtime PM resume and suspend (Gustavo Kenji Mendonça Kaneko)
- btrfs: tree-checker: validate INODE_REF's namelen (Weiming Shi) [Orabug: 40073319] {CVE-2026-93813}
- spi: core: Abort active target transfer on controller suspend (Praveen Talari) [Orabug: 40073325] {CVE-2026-93814}
- ASoC: tas2781: Update default register address to TAS2563 (Baojun Xu)
- fbdev: pm2fb: unwind WC setup on probe failure (Haoxiang Li)
- ALSA: hda: Add Lenovo Legion 7i 16IAX7 17AA3874 quirk (Kamlesh Chhetty)
- eth: mlx5: fix macsec dependency (Arnd Bergmann)
- rtc: bq32000: add delay between RTC reads (Adriana Nicolae)
- blk-cgroup: protect iterating blkgs with blkcg->lock in blkcg_print_stat() (Yu Kuai)
- net: au1000: move free_irq out of the close-time spinlocked section (Runyu Xiao)
- regulator: da9121: Use subvariant ids in the I2C table (Pengpeng Hou)
- PCI/sysfs: Use kstrtobool() to parse the ROM attribute input (Krzysztof Wilczyński)
- PCI/proc: Fix race between pci_proc_init() and pci_bus_add_device() (Krzysztof Wilczyński)
- ksmbd: treat read-control opens as stat opens only for leases (Namjae Jeon)
- ksmbd: break RH leases before delete-on-close (Namjae Jeon)
- ksmbd: start file id allocation at 1 (Namjae Jeon)
- ksmbd: deny renaming directory with open children (Namjae Jeon)
- ksmbd: apply create security descriptor first (Namjae Jeon)
- ksmbd: treat unnamed DATA stream as base file (Namjae Jeon)
- ksmbd: use connection ClientGUID for lease lookup (Namjae Jeon)
- ksmbd: align SMB2 oplock break ack handling (Namjae Jeon)
- ksmbd: validate SMB2 lease create contexts (Namjae Jeon)
- ksmbd: fix lease break and ack state handling (Namjae Jeon)
- ceph: harden send_mds_reconnect and handle active-MDS peer reset (Alex Markuze)
- rtc: aspeed: add AST2700 compatible (Tommy Huang)
- rtc: mv: add suspend/resume support for wakeup (Xue Lei)
- f2fs: validate inline dentry name lengths before conversion (Samuel Moelius)
- ALSA: hda/realtek: Add quirk for Lenovo Yoga 7 16IAP7 (Chris Aherin)
- md/raid5: let stripe batch bm_seq comparison wrap-safe (Chen Cheng)
- mailbox: imx: use devm_of_platform_populate() (Sebastian Andrzej Siewior)
- mailbox: imx: Add a channel shutdown field (Sebastian Andrzej Siewior)
- md/raid5: account discard IO (Yu Kuai)
- mailbox: imx: Use devm_pm_runtime_enable() (Sebastian Andrzej Siewior)
- PCI: plda: Protect root bus removal with rescan lock (Hans Zhang)
- PCI: mediatek: Protect root bus removal with rescan lock (Hans Zhang)
- PCI: rockchip: Protect root bus removal with rescan lock (Hans Zhang) [Orabug: 40073356] {CVE-2026-93820}
- PCI: altera: Protect root bus removal with rescan lock (Hans Zhang)
- PCI: iproc: Protect root bus removal with rescan lock (Hans Zhang) [Orabug: 40073373] {CVE-2026-93822}
- drm/amdkfd: Properly acquire queue buffers in CRIU restore (David Francis)
- ALSA: usb-audio: Add quirk for YAMAHA CDS3000 (Jean-Louis Colaco)
- drm/amdgpu: Use system unbound workqueue for soft IH ring (Timur Kristóf)
- drm/amdkfd: check find_first_zero_bit before __set_bit on kfd->doorbell_bitmap (Xiaogang Chen)
- drm/amdkfd: Let driver decide buffer size at AMDKFD_IOC_GET_DMABUF_INFO ioctl (Xiaogang Chen) [Orabug: 40073385] {CVE-2026-93823}
- mfd: rsmu: Add 8a34002 support (Matthew Bystrin)
- leds: trigger: gpio: Use GPIOD_FLAGS_BIT_NONEXCLUSIVE (Piotr Kubik)
- mfd: tps65219: Make poweroff handler conditional on system-power-controller (Akashdeep Kaur)
- leds: pca9532: Don't stop blinking for non-zero brightness (Tobias Deiminger)
- leds: uleds: Return -EFAULT on copy_to_user() failure (Yousef Alhouseen)
- ALSA: hda/conexant: Add pin config quirk for Lenovo IdeaPad Slim 5 16AKP10 (Galen Hassen)
- tls: reject the combination of TLS and sockmap (Jakub Kicinski) [Orabug: 40073391] {CVE-2026-93824}
- ALSA: usb-audio: Add quirk flags for SC13A (Ai Chao)
- spi: Add NULL check for spi_get_device_id() in spi_get_device_match_data() (Guoqi0226) [Orabug: 40073397] {CVE-2026-93825}
- gpio: pisosr: Read "ngpios" as u32 (Rob Herring)
- scsi: bfa: Reduce kernel stack usage in bfa_fcs_lport_fdmi_build_portattr_block() (Arnd Bergmann)
- fuse: set ff->flock only on success (Zhang Tianci)
- HID: hidpp: fix potential UAF in hidpp_connect_event() (Jiri Kosina) [Orabug: 40073406] {CVE-2026-93826}
- virtio-fs: avoid double-free on failed queue setup (Yung-Tse Cheng) [Orabug: 40073412] {CVE-2026-93827}
- ALSA: hda/realtek: Add quirk for Lenovo Xiaoxin 14 GT (Viktor Menshin)
- exfat: fix handling of damaged volume in exfat_create_upcase_table() (David Timber) [Orabug: 40073418] {CVE-2026-93828}
- sparc: Disable compat support with LLD (Rosen Penev)
- bpftool: Pass host flags to bootstrap libbpf (Leo Yan)
- i3c: mipi-i3c-hci: Tolerate i3c_master_add_i3c_dev_locked() failures in DAA (Adrian Hunter)
- smb: client: fix races in cifsd thread creation (Fredric Cover) [Orabug: 40073426] {CVE-2026-93829}
- net/sched: act_csum: don't mangle UDP tunnel GSO packets (Alice Mikityanska)
- apparmor: propagate -ENOMEM correctly in unpack_table (Maxime Bélair)
- net: hns3: improve the unused_tuple parameter setting (Jijie Shao)
- e1000e: limit endianness conversion to boundary words (Agalakov Daniil)
- vsock: use sk_acceptq_is_full() helper in all transports (Raf Dickson)
- ptp: ocp: add shutdown callback (Vadim Fedorenko)
- net: stmmac: xgmac2: disable RBUE in default RX interrupt mask (Nazim Amirul)
- sparc64: uprobes: add missing break (Rosen Penev)
- Bluetooth: btusb: Add Realtek RTL8922AE VID/PID 0bda/d923 (Zhang Chen)
- Bluetooth: btusb: Add TP-Link UB600 for Realtek 8761BUV (Nils Helmig)
- ASoC: rockchip: spdif: Restore regcache cache-only mode on sync failure (Bui Duc Phuc)
- ASoC: rockchip: rockchip_pdm: Reorder clock enable sequence (Bui Duc Phuc)
- ASoC: rockchip: rockchip_pdm: Handle runtime PM resume failures in set_fmt (Bui Duc Phuc)
- Bluetooth: btintel_pcie: Add 50 ms delay before MAC init on BlazarIW (Kiran K)
- Bluetooth: L2CAP: validate connectionless PSM length (Samuel Moelius) [Orabug: 40073441] {CVE-2026-97408}
- Bluetooth: btusb: Add support for TP-Link TL-UB250 (Cris)
- Bluetooth: btusb: MT7925: Add VID/PID 0e8d/8c38 (Chris Lu)
- Bluetooth: btmtk: Disable remote wakeup for MT7922/MT7925 (Rongrong)
- Bluetooth: btusb: Add Mercusys MA530 for Realtek RTL8761BUV (Hrvoje Nuic)
- Bluetooth: btusb: Add Realtek RTL8922AE VID/PID 0bda/d922 (Zhang Chen)
- Bluetooth: btusb: Add support for Intel Lizard Peak 2 (0x8087:0x0040) (Ravindra)
- Bluetooth: btusb: MT7922: Add VID/PID 0e8d/223c (Chris Lu)
- spi: xilinx: let transfers timeout in case of no IRQ (Vadim Fedorenko)
- hwmon: (pmbus/lm25066) Fix PMBus coefficients for LM5064/5066/5066i (Potin Lai)
- dmaengine: dw-axi-dmac: fix PM for system sleep and channel alloc (Tze Yee Ng)
- dmaengine: altera-msgdma: Use memcpy_toio for descriptor FIFO writes (Adrian Ng Ho Yin)
- PCI: Avoid SBR for Qualcomm WCN6855/WCN7850 WiFi, SDX62/SDX65 modems (Jose Ignacio Tornos Martinez)
- hwmon: (dell-smm) Add Dell Latitude 7530 to fan control whitelist (Armin Wolf)
- HID: multitouch: Honor ContactCount for Yoga Book 9 to suppress ghost contacts (Dave Carey)
- sctp: Unwind address notifier registration on failure (Yuho Choi)
- nvme-fc: Do not cancel requests in io target before it is initialized (Mohamed Khalfella) [Orabug: 40073446] {CVE-2026-97409}
- platform/x86: intel-hid: Add HP ProBook x360 440 G1 to button_array_table (Nikolay Metchev)
- ata: libata-pmp: add JMicron JMS562 quirk (Xu Rao)
- ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IRH8 (Moritz Baron)
- ALSA: hda/realtek: Add quirk for HP 255 15.6 inch G9 Notebook PC (Furst Blumier)
- vdpa/octeon_ep: Use 4 bytes for mailbox signature (Vamsi Attunuru)
- vdpa/ifcvf: handle dev_set_name() failure in ifcvf_vdpa_dev_add() (Evgenii Burenchev)
- net: lan966x: restore RX state on reload failure (Guangshuo Li)
- net: dsa: qca8k: Add support for force mode for fixed link topology (George Moussalem)
- btrfs: use lockless read in nr_cached_objects shrinker callback (Ben Maurer)
- btrfs: use on-disk uuid for s_uuid in temp_fsid mounts (Anand Jain)
- hwmon: (adt7462) Add of_match_table to support devicetree (Kory Maincent)
- hwmon: (raspberrypi) Fix delayed-work teardown race (Shubham Chakraborty)
- PCI: Avoid FLR for MediaTek MT7925 WiFi (Jose Ignacio Tornos Martinez)
- fbcon: don't suspend/resume when vc is graphics mode (Lu Yao)
- btrfs: protect sb_write_pointer() with invalidate lock (Kangning Liao)
- netconsole: take target_cleanup_list_lock in drop_netconsole_target() (Breno Leitao) [Orabug: 40073452] {CVE-2026-97410}
- wifi: mt76: transform aspm_conf for pci_disable_link_state (Jiajia Liu)
- wifi: mt76: mt7925: add 320MHz bandwidth to bss_rlm_tlv (Javier Tia)
- wifi: mt76: mt7925: populate EHT 320MHz MCS map in sta_rec (Javier Tia)
- wifi: mt76: mt7925: add Netgear A8500 USB device ID (Lucid Duck)
- platform/x86: msi-ec: Add support for MSI Pulse GL66 12th Gen (Luis de Carlos)
- wifi: mt76: mt7925: handle 320MHz bandwidth in RXV and TXS (Javier Tia)
- platform/x86: dell-laptop: add Inspiron N5110 to touchpad LED quirk table (Gleb Sonichev)
- tls: Flush backlog before waiting for a new record (Chuck Lever)
- net: ibm: emac: mal: fix potential system hang in mal_remove() (Rosen Penev)
- pds_core: quiesce DMA before freeing resources (Nikhil P. Rao) [Orabug: 40073460] {CVE-2026-97412}
- configfs_depend_prep(): pass configfs_dirent instead of dentry (Al Viro)
- RDMA/mlx5: Create ODP EQ for non-pinned dmabuf MRs (Jason Gunthorpe)
- xprtrdma: Add request-pool slack for delayed recycling (Chuck Lever)
- RDMA/rtrs-srv: Fix integer underflow in process_read and process_write (Aurelien Desbrieres)
- ASoC: mediatek: mt8365-afe-pcm: fix possible NULL-pointer dereferences in mt8365_afe_suspend() (Tuo Li)
- NFS: fix eof updates after NFSv4.2 fallocate/zero-range (Dai Ngo)
- btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF (Zhang Cen) [Orabug: 40073476] {CVE-2026-97415}
- btrfs: balance: fix potential bg lookup failure in btrfs_may_alloc_data_chunk() (Zhengyuan Huang) [Orabug: 40073481] {CVE-2026-97416}
- riscv: panic if IRQ handler stacks cannot be allocated (Osama Abdelkader)
- netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() (Rosen Penev) [Orabug: 40073485] {CVE-2026-97417}
- ALSA: es18xx: check control allocation before private data setup (Ruoyu Wang)
- net: microchip: sparx5: clean up PSFP resources on flower setup failure (Haoxiang Li)
- hsr: broadcast netlink notifications in the device's net namespace (Maoyi Xie) [Orabug: 40073494] {CVE-2026-97419}
- net: cpsw_new: unregister devlink on port registration failure (Guangshuo Li)
- bpf: NUL-terminate replaced sysctl value (Dawei Feng) [Orabug: 40073499] {CVE-2026-97420}
- RDMA/mlx5: Fix state and counter desync on loopback enable failure (Li Rongqing)
- RDMA/umem: Be careful about boundary conditions in ib_umem_find_best_pgsz() (Jason Gunthorpe) [Orabug: 40073503] {CVE-2026-97421}
- wifi: nl80211: Increase ie_len size to prevent truncated IEs in new peer notifications (Thiyagarajan Pandiyan)
- ipv6: use READ_ONCE() for bindv6only default in inet6_create() (Runyu Xiao)
- drm/amdkfd: Unwind debug trap enable on copy_to_user failure (Yongqiang Sun)
- ipmi: si: Use platform_get_irq_optional() to retrieve interrupt (Rosen Penev)
- ALSA: hda/realtek: Add quirk for ASUS VivoBook X509DAP (Andrei Faleichyk)
- clk: keystone: don't cache clock rate (Michael Walle)
- net/mlx5: E-Switch, align disable sequence with switchdev-to-legacy transition (Shay Drory)
- RDMA/irdma: Fix typo in SQ completions generation (Cyrill Gorcunov)
- net/mlx5e: Verify unique vhca_id count instead of range (Shay Drory)
- drm/amdgpu: fix buffer overflow during vBIOS update (Morris Zhang) [Orabug: 40073529] {CVE-2026-97425}
- drm/amd/pm: bound pp_dpm_set_pp_table() memcpy (Asad Kamal) [Orabug: 40073539] {CVE-2026-97427}
- drm/amdgpu: harden FRU PIA parsing with bounded helpers (Stanley Yang) [Orabug: 40073545] {CVE-2026-97428}
- drm/amdkfd: fix UAF race in destroy_queue_cpsch (Alysa Liu) [Orabug: 40073549] {CVE-2026-97429}
- drm/amd/display: Check for sharpening case when calculating max vtaps for scaler (Samson Tam)
- xhci: Prevent queuing new commands if xhci is inaccessible (Mathias Nyman) [Orabug: 40073554] {CVE-2026-97430}
- usb: xhci: Improve Soft Retries after short transfers (Michał Pecio)
- thermal/drivers/qcom/tsens: Atomic temperature read with hardware-guided retries (Priyansh Jain)
- dpaa2-switch: fix handling of NAPI on the remove path (Ioana Ciornei)
- net: dsa: sja1105: flower: reject cross-chip redirect (David Yang)
- dpaa2-switch: fix the error path in dpaa2_switch_rx() (Ioana Ciornei)
- dpaa2-switch: rework FDB management on the bridge leave path (Ioana Ciornei)
- ALSA: seq: oss: Reject reads that cannot fit the next event (Cássio Gabriel)
- ASoC: codecs: rk3328: Use managed GPIO and clock helpers (Cássio Gabriel)
- ntfs3: fix out-of-bounds read in ntfs_dir_emit() and hdr_find_e() (Alessandro Schino)
- fs/ntfs3: validate index entry key bounds (Zhengyuan Huang) [Orabug: 40073602] {CVE-2026-97438}
- nvme: refresh multipath head zoned limits from path limits (Yao Sang)
- fs/ntfs3: preserve non-DOS attribute bits in system.dos_attrib (Zhengyuan Huang)
- powerpc/fadump: Add timeout to RTAS busy-wait loops (Adriano Vero)
- iommu/rockchip: disable fetch dte time limit (Simon Xue)
- net: wwan: t7xx: Add delay between MD and SAP suspend (Jose Ignacio Tornos Martinez)
- net: qrtr: fix node refcount leak on ctrl packet alloc failure (Xu Wang) [Orabug: 40073611] {CVE-2026-97440}
- ACPI: PCI: Clear _DEP dependencies after PCI root bridge attach (Chen Pei)
- ACPI: scan: Honor _DEP for ACPI0016 PCI/CXL host bridge (Chen Pei)
- ata: ahci: fail probe if BAR too small for claimed ports (Liyouhong) [Orabug: 40073616] {CVE-2026-97441}
- ASoC: codecs: pcm3168a: Drop CONFIG_PM-conditional preproc directive (Cezary Rojewski)
- ASoC: qcom: q6apm: return error code to consumers on failures (Srinivas Kandagatla)
- wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi (Miaoqing Pan) [Orabug: 40073621] {CVE-2026-97442}
- net: ibm: emac: Reserve VLAN header in MJS limit (Rosen Penev)
- libbpf: Also reset {insn,data}_cur on realloc failure (Daniel Borkmann)
- iio: accel: mma8452: switch to non-devm request_threaded_irq() (Sanjay Chitroda)
- perf/ftrace: Fix WARNING in __unregister_ftrace_function (Rik van Riel) [Orabug: 40073628] {CVE-2026-97443}
- iio: light: stk3310: Deal with the ps interrupt issue in PM (Miao Li)
- mmc: renesas_sdhi: Add OF entry for RZ/G2E SoC (Lad Prabhakar)
- tracing: Disable KCOV instrumentation for trace_irqsoff.o (Karl Mehltretter)
- ARM: tegra: p880: Lower CPU thermal limit (Ion Agorria)
- mmc: renesas_sdhi: Add OF entry for RZ/G2N SoC (Lad Prabhakar)
- mmc: davinci: fix mmc_add_host order in probe (Osama Abdelkader)
- soundwire: only handle alert events when the peripheral is attached (Bard Liao)
- gfs2: page poisoning fix (Andreas Gruenbacher)
- soundwire: dmi-quirks: Disable ghost Realtek devices (Charles Keepax)
- soc/tegra: fuse: Register nvmem lookups at probe (Kartik)
- libbpf: Add __NR_bpf definition for LoongArch (Tiezhu Yang)
- drm/nouveau/bios: skip the IFR header if present (Timur Tabi)
- ASoC: Intel: catpt: Complete coredump handling (Cezary Rojewski)
- scripts: modpost: detect and report truncated buf_printf() output (Alexandre Courbot)
- host1x: bus: Fix missing ops null check in error teardown (Shayderrr)
- pinctrl: renesas: rzv2m: Use -ENOTSUPP instead of -EOPNOTSUPP (Claudiu Beznea)
- net: sfp: add quirk for OEM 2.5G optical modules (Wei Qisen)
- hfs: rework hfsplus_readdir() logic (Viacheslav Dubeyko)
- ACPICA: add boundary checks in two places (Kang Chen) [Orabug: 40073635] {CVE-2026-97444}
- ACPICA: Enhance buffer validation in acpi_ut_walk_aml_resources() (Kang Chen) [Orabug: 40073643] {CVE-2026-97445}
- ACPICA: Fix NULL pointer dereference in acpi_ns_custom_package() (Weiming Shi) [Orabug: 40073651] {CVE-2026-97446}
- ACPICA: Enhance OEM ID and Table ID validation in acpi_ex_load_table_op() (Kang Chen) [Orabug: 40073657] {CVE-2026-97447}
- ACPICA: Add validation for node in acpi_ns_build_normalized_path() (Kang Chen) [Orabug: 40073661] {CVE-2026-97448}
- ACPICA: Add package limit checks in parser functions (Kang Chen) [Orabug: 40073667] {CVE-2026-97449}
- ACPICA: validate handler object type in two places (Kang Chen) [Orabug: 40073672] {CVE-2026-97450}
- ACPICA: Improve argument parsing in acpi_ps_get_next_simple_arg() (Kang Chen)
- ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op) (Kang Chen) [Orabug: 40073678] {CVE-2026-97451}
- ACPICA: Prevent adding invalid references (Kang Chen) [Orabug: 40073685] {CVE-2026-97452}
- ACPICA: validate byte_count in acpi_ps_get_next_package_length() (Kang Chen) [Orabug: 40073691] {CVE-2026-97453}
- ACPICA: add boundary checks in acpi_ps_get_next_field() (Kang Chen) [Orabug: 40073697] {CVE-2026-97454}
- ACPICA: Fix use-after-free in acpi_ds_terminate_control_method() (Kang Chen) [Orabug: 40073703] {CVE-2026-97455}
- ACPICA: Fix condition check in acpi_ps_parse_loop() (Kang Chen) [Orabug: 40073708] {CVE-2026-97456}
- drm/amd/display: Initialize dsc_caps to 0 (Ivan Lipski)
- drm/amd/pm/si: Fix updating clock limits from power states (Jeremy Klarenbeek)
- drm/dp: Add DSC virtual DPCD quirk for Realtek MST branch device (Imre Deak)
- net: thunderx: fix PTP device ref leak in nicvf_probe() (Haoxiang Li)
- ipv6: addrconf: fix temp address generation after prefix deprecation (Fernando Fernandez Mancera) [Orabug: 40073713] {CVE-2026-97472}
- net: hsr: require valid EOT supervision TLV (Luka Gejak)
- ALSA: usb-audio: Add quirk for Novation Mininova (Uwe Küchler)
- irqchip/gic-v4: Don't advertise VLPIs if no ITS is probed (Mostafa Saleh)
- iio: adc: qcom-spmi-iadc: balance enable_irq_wake() on driver unbind (Stepan Ionichev)
- mips: cps: Assemble jr.hb with an R2 ISA level (Rosen Penev)
- drm/panel: simple: Add AM-1280800W8TZQW-T00H (Dario Binacchi)
- powercap: intel_rapl: Fix memory leak in rapl_add_package_cpuslocked() (Sumeet Pawnikar) [Orabug: 40073718] {CVE-2026-97473}
- thermal/drivers/tegra/soctherma: Switch to devm cooling device registration (Daniel Lezcano)
- clk: socfpga: agilex: implement l3_main_free_clk (Adrian Ng Ho Yin)
- s390/zcore: Removed unused variables (Heiko Carstens)
- ALSA: seq: Remove arbitrary prioq insertion limit (Cássio Gabriel)
- netlabel: fix IPv6 unlabeled address add error handling (Chenguang Zhao)
- wifi: rtw89: pci: enable LTR based on pcie control register (Dian-Syuan Yang)
- rcu-tasks: Fix possible boot-time tests failed for the call_rcu_tasks() (Zqiang)
- char/nvram: Remove redundant nvram_mutex (Venkat Rao Bagalkote)
- crypto: atmel-sha204a - remove sysfs group before hwrng (Thorsten Blum)
- usb: host: add ARCH_AIROHA in XHCI MTK dependency (Christian Marangi)
- serial: 8250: fix possible ISR soft lockup (Marco Felsch) [Orabug: 40073758] {CVE-2026-97481}
- usb: gadget: aspeed_udc: avoid past-the-end iterator in dequeue (Maoyi Xie)
- USB: cdc-acm: start bulk-IN polling when ALWAYS_POLL_CTRL is set (Dave Carey)
- usb: gadget: goku_udc: avoid NULL deref of dev->driver in INT_USBRESET log (Stepan Ionichev)
- usb: core: hcd: fix possible deadlock in rh control transfers (Oliver Neukum) [Orabug: 40073767] {CVE-2026-97483}
- usbip: vhci_hcd: fix NULL deref in status_show_vhci (Adrian Wowk) [Orabug: 40073772] {CVE-2026-97484}
- HID: bpf: Add Huion Inspiroy Frego M button quirk (Nikhil Chatterjee)
- isofs: handle set_blocksize failures (Christoph Hellwig)
- omfs: handle set_blocksize failures (Christoph Hellwig)
- hpfs: handle set_blocksize failures (Christoph Hellwig)
- jfs: handle set_blocksize failures (Christoph Hellwig)
- qnx4: handle set_blocksize failures (Christoph Hellwig)
- minix: handle set_blocksize failures (Christoph Hellwig)
- bfs: handle set_blocksize failures (Christoph Hellwig)
- affs: handle set_blocksize failures (Christoph Hellwig)
- ntfs3: handle set_blocksize failures (Christoph Hellwig)
- befs: handle set_blocksize failures (Christoph Hellwig)
- spi: dw-mmio: Add ACPI ID LECA0002 for LECARC SoCs (Thomas Lin)
- net/sched: sch_drr: make cl->quantum lockless (Eric Dumazet)
- net: bridge: remove stale rcu_barrier() in br_multicast_dev_del() (Eric Dumazet)
- net: usb: qmi_wwan: add MeiG SRM813Q (Jan Volckaert)
- nvme-core: align fabrics_q teardown with admin_q in nvme_free_ctrl (Maurizio Lombardi)
- bitfield: wire __bf_shf to __builtin_ctzll (Yury Norov)
- thunderbolt: Verify Router Ready bit is set after router enumeration (Gil Fine)
- wifi: mac80211: don't call ieee80211_handle_reconfig_failure when not needed (Miri Korenblit) [Orabug: 40073812] {CVE-2026-97492}
- thunderbolt: Increase timeout for Configuration Ready bit (Gil Fine)
- firmware: arm_scmi: Validate BASE_ERROR_EVENT payload size (Sudeep Holla)
- firmware: arm_scmi: Validate SENSOR_UPDATE payload size (Sudeep Holla)
- thunderbolt: Improve multi-display DisplayPort tunnel allocation (Alan Borzeszkowski)
- thunderbolt: Don't access path config space on Lane 1 adapters in tb_switch_reset_host() (Pooja Katiyar)
- bridge: Add missing READ_ONCE() annotations around FDB destination port (Ido Schimmel)
- drm/amdgpu: validate and share PSP fw_pri_buf copies via psp_copy_fw (Candice Li) [Orabug: 40073829] {CVE-2026-97494}
- 9p: use kvzalloc for readdir buffer (Pierre Barre)
- drm/imagination: Populate FW common context ID before passing to the FW (Brajesh Gupta)
- arm64/daifflags: Make local_daif_*() helpers __always_inline (Leonardo Bras)
- 9p: invalidate readdir buffer on seek (Pierre Barre)
- iommu: arm-smmu-qcom: Ensure smmu is powered up in set_ttbr0_cfg (Anna Maniscalco)
- sched/fair: Reject misfit pulls onto busy SMT siblings on asym-capacity (Andrea Righi)
- ALSA: usx2y: Drain pending US-428 pipe-4 output commands (Cássio Gabriel)
- drm/amdkfd: Check bounds on allocate_doorbell (David Francis) [Orabug: 40073835] {CVE-2026-97495}
- drm/amdkfd: Fix OOB memory exposure in get_wave_state() (Sunday Clement) [Orabug: 40073839] {CVE-2026-97496}
- drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id (David Francis) [Orabug: 40073845] {CVE-2026-97497}
- PCI: Wait for device readiness after D3hot -> D0uninitialized transition (Bjorn Helgaas)
- mailbox: Make mbox_send_message() return error code when tx fails (Joonwon Kang)
- iomap: don't make REQ_POLLED imply REQ_NOWAIT (Christoph Hellwig)
- drm/mediatek: dsi: Add compatible for mt8167-dsi (Luca Leonardo Scorcia)
- RDMA/mlx5: Use QP port when decoding responder CQEs (Chenguang Zhao)
- media: imon: Add iMON VFD HID OEM v1.2 key mappings (Alessandro Baldi)
- crypto: atmel-ecc - add support for atecc608b (Thorsten Blum)
- ASoC: Intel: sof_sdw: append dai type to dai link name unconditionally (Bard Liao)
- crypto: ecc - Unbreak the build on arm with CONFIG_KASAN_STACK=y (Lukas Wunner)
- scsi: pm8001: Reject non-fatal dump when controller is crashed (Kumar Meiyappan)
- scsi: pm8001: Reject firmware update in fatal error state (Kumar Meiyappan)
- clk: samsung: exynos850: mark APM I3C clocks as critical (Alexey Klimov)
- soundwire: intel: Move suspend tracking from trigger to pm suspend (Peter Ujfalusi)
- drivers/of: validate status properties in reconfig state changes (Pengpeng Hou)
- integrity: Check for NULL returned by asymmetric_key_public_key (Stefan Berger)
- net: dsa: realtek: rtl8365mb: add support for RTL8367SB (Mieczyslaw Nalewaj)
- wifi: rtw89: phy: check length before parsing PHY status IE (Ping-Ke Shih) [Orabug: 40073866] {CVE-2026-97500}
- HID: multitouch: Fix Yoga Book 9 14IAH10 touchscreen misclassification (Dave Carey)
- media: video-i2c: use vb2_video_unregister_device on driver removal (Arash Golgol)
- media: chips-media: wave5: Add range checks for dec_output_info (Ricardo Ribalda)
- drm/gud: Add RCade Display Adapter VID/PID pair (Sophie D)
- net: phy: motorcomm: use device properties for firmware tuning (Chunzhi Lin)
- hfsplus: rework hfsplus_readdir() logic (Viacheslav Dubeyko)
- PCI: intel-gw: Enable clock before PHY init (Florian Eckert)
- drm/amd/display: Fix CRC open failure during active rendering (Tom Chung)
- platform/x86: sel3350-platform: Retain LED state on load and unload (Brodie Abrew)
- mmc: davinci: avoid NULL deref of host->data in IRQ handler (Stepan Ionichev)
- mmc: core: Add validation for host-provided max_segs (Shawn Lin)
- platform/chrome: Resolve kb_wake_angle visibility race (Tzung-Bi Shih)
- net/mlx5: HWS, Handle destroying table that has a miss table (Yevgeny Kliteynik)
- watchdog: lenovo_se10_wdt: Fix use-after-free and resource leak risk (Mark Pearson)
- watchdog: imx7ulp_wdt: Keep WDOG running until A55 enters WFI on i.MX94 (Ranjani Vaidyanathan)
- watchdog: lenovo_se10_wdt: Add support for SE10 Gen 2 platform (Mark Pearson)
- ASoC: ti: omap3pandora: update board check to use DT compatible (Ethan Nelson-Moore)
- media: qcom: camss: avoid format string warning (Arnd Bergmann)
- PCI/sysfs: Add CAP_SYS_ADMIN check to __resource_resize_store() (Krzysztof Wilczyński) [Orabug: 40073891] {CVE-2026-97505}
- dlm: add usercopy whitelist to dlm_cb cache (Ziyi Guo)
- drm/bridge: tc358768: Set pre_enable_prev_first for reverse order (Parth Pancholi)
- clk: renesas: cpg-mssr: Add number of clock cells check (Geert Uytterhoeven)
- crypto: omap - add omap_des_unregister_algs helper (Thorsten Blum)
- crypto: ixp4xx - fix buffer chain unwind on allocation failure (Ruoyu Wang)
- rtase: Fix flow control configuration (Justin Lai)
- wifi: mac80211: explicitly disable FTM responder on AP stop (Johannes Berg)
- media: em28xx-video: fix missing res_free() on init_usb_xfer failure (Haoxiang Li)
- net: dsa: mv88e6xxx: enable .rmu_disable() for 6320 family (Marek Behún)
- net: dsa: mv88e6xxx: define .pot_clear() for 6321 (Marek Behún)
- PCI: switchtec: Add Gen6 Device IDs (Ben Reed)
- net: dsa: mv88e6xxx: fix number of g1 interrupts for 6320 family (Marek Behún)
- media: dm1105: fix missing error check for dma_alloc_coherent (Zhaoyang Yu) [Orabug: 40073902] {CVE-2026-97507}
- drm/panel: Enable GPIOLIB for panels which uses functions from it (David Heidelberger)
- drm/amdgpu: Prefer ROM BAR for default VGA device (Lijo Lazar)
- drm/amd/display: Find link encoder for flexible DIG mapping cases (Ovidiu Bunea)
- thunderbolt: Don't create multiple DMA tunnels on firmware connection manager (Alan Borzeszkowski)
- thunderbolt: Set tb->root_switch to NULL when domain is stopped (Mika Westerberg) [Orabug: 40073909] {CVE-2026-97508}
- thunderbolt: Keep the domain reference while processing hotplug (Mika Westerberg)
- thunderbolt: Keep XDomain reference during the lifetime of a service (Mika Westerberg) [Orabug: 40073913] {CVE-2026-97509}
- thunderbolt: Release request if tb_cfg_request() fails in __tb_xdomain_response() (Mika Westerberg) [Orabug: 40073917] {CVE-2026-97510}
- thunderbolt: Don't disable lane adapter if XDomain lane bonding isn't possible (Mika Westerberg)
- thunderbolt: Avoid reserved fields in path config space for USB4 routers (Gil Fine)
- s390/cio: Purge based on the cdev's online status (Vineeth Vijayan)
- net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (Erni Sri Satya Vennela)
- media: rc: mceusb: Add support for 04eb:e033 (Riccardo Boninsegna)
- spi: spi-qcom-qspi: Fix incomplete error handling in runtime PM (Viken Dadhaniya)
- media: chips-media: wave5: Fix Reports from Kernel Lock Validator (Brandon Brnich)
- soundwire: validate DT compatible before parsing it (Pengpeng Hou)
- soundwire: intel_auxdevice: Add cs42l43b to wake_capable_list (Charles Keepax)
- bridge: Do not suppress ARP probes and DAD NS unconditionally (Danielle Ratson)
- firmware: stratix10-svc: change get provision data to async SMC call (Siew Chin Lim)
- kcsan: Silence -Wmaybe-uninitialized when calling __kcsan_check_access() (Marco Elver)
- ASoC: fsl-asoc-card: reduce WM8904 PLL ratio to meet frequency limit (Shengjiu Wang)
- wifi: rtw89: disable CSI STBC for VHT 160MHz (Dian-Syuan Yang)
- wifi: rtw88: Add NULL check for chip->edcca_th in rtw_fw_adaptivity_result() (Panagiotis Petrakopoulos) [Orabug: 40073944] {CVE-2026-97516}
- wifi: mac80211: always allow transmitting null-data on TXQs (Johannes Berg)
- wifi: nl80211: reject beacons with bad HE operation (Johannes Berg) [Orabug: 40073950] {CVE-2026-97517}
- hfsplus: fix issue of direct writes beyond end-of-file (Viacheslav Dubeyko)
- wifi: cfg80211: reject duplicate wiphy cipher suite entries (Yuqi Xu) [Orabug: 40073957] {CVE-2026-97518}
- PCI: Stop setting cached power state to 'unknown' on unbind (Lukas Wunner)
- tools/nolibc: avoid call to wcslen() in _start_c() inserted by clang (Thomas Weißschuh)
- tee: optee: Allow MT_NORMAL_TAGGED shared memory (Hirokazu Honda)
- usb: gadget: udc: skip pullup() if already connected (Xu Yang)
- ima: return error early if file xattr cannot be changed (Goldwyn Rodrigues)
- ALSA: usb-audio: Propagate write errors in generic mixer put callbacks (Cássio Gabriel)
- pinctrl: renesas: rzg2l: Handle RZ/V2H(P) IOLH configuration in PM cache (Lad Prabhakar)
- iio: adc: rtq6056: add i2c_device_id support (Kevin Tung)
- gfs2: move quota_init qc iterator increment (Jie Wang) [Orabug: 40073971] {CVE-2026-97520}
- gfs2: fix quota init duplicate scan (Jie Wang) [Orabug: 40073975] {CVE-2026-97521}
- drm/amd/pm: Check SMUv13.0.6/12 metrics integrity (Lijo Lazar)
- drm/panel: jadard-jd9365da-h3: set prepare_prev_first (Dmitry Baryshkov)
- drm/amd/display: Fix DPMS using partially updated pipe context (Dominik Kaszewski)
- drm: rz-du: Ensure correct suspend/resume ordering with VSP (Tommaso Merciai)
- bus: fsl-mc: wait for the MC firmware to complete its boot (Ioana Ciornei)
- drm/gem: Consider GEM object reclaimable if shrinking fails (Boris Brezillon)
- ksmbd: fix use-after-free in oplock break notification (Abdifatah Suruur)
- LTS version: v6.12.110 (Sherry Yang)
- ACPI: processor: Add cpuidle driver check in acpi_processor_register_idle_driver() (Tony W Wang-Oc)
- integrity: Eliminate weak definition of arch_get_secureboot() (Nathan Chancellor)
- slab: reset slab->obj_ext when freeing and it is OBJEXTS_ALLOC_FAIL (Hao Ge)
- x86/Kconfig: Reenable PTDUMP on i386 (Alexander Popov)
- pinctrl: mediatek: common-v1: Fix error checking in mtk_eint_init() (Dan Carpenter)
- tools/build: Use SYSTEM_BPFTOOL for system bpftool (Tomas Glozar)
- net_sched: add back BH safety to tcf_lock (Eric Dumazet)
- net_sched: act_tunnel_key: use RCU in tunnel_key_dump() (Eric Dumazet)
- net_sched: act_vlan: use RCU in tcf_vlan_dump() (Eric Dumazet)
- net_sched: act_skbedit: use RCU in tcf_skbedit_dump() (Eric Dumazet)
- net_sched: act_ctinfo: use RCU in tcf_ctinfo_dump() (Eric Dumazet)
- net_sched: act_ct: use RCU in tcf_ct_dump() (Eric Dumazet)
- md: fix sync_action incorrect display during resync (Zheng Qixing)
- md: add helper rdev_needs_recovery() (Zheng Qixing)
- kselftest/arm64: mte: Use the correct naming for tag check modes in check_hugetlb_options.c (Catalin Marinas)
- kselftest/arm64: mte: Skip the hugetlb tests if MTE not supported on such mappings (Catalin Marinas)
- net/sched: fq: clamp quantum and initial_quantum in change path (Jamal Hadi Salim) [Orabug: 40081010] {CVE-2026-90050}
- Bluetooth: btmtk: hide unused btmtk_mt6639_devs[] array (Arnd Bergmann)
- xsk: Fix offset calculation in unaligned mode (Eryk Kubanski)
- erofs: fix managed cache race for unaligned extents (Gao Xiang) [Orabug: 40081005] {CVE-2026-64031}
- cpuset: fix warning when disabling remote partition (Chen Ridong) [Orabug: 40081001] {CVE-2025-71142}
- nvme-apple: Reset q->sq_tail during queue init (Nick Chan)
- nvme-apple: Prevent shared tags across queues on Apple A11 (Nick Chan)
- powerpc/vdso: Remove unused clockmode asm offsets (Thomas Weißschuh)
- phy: qcom: qmp-combo: Add missing PLL (VCO) configuration on SM8750 (Krzysztof Kozlowski)
- perf test: Don't signal all processes on system when interrupting tests (James Clark)
- fscrypt: fix left shift underflow when inode->i_blkbits > PAGE_SHIFT (Yongpeng Yang)
- ACPI: processor: Update cpuidle driver check in __acpi_processor_start() (Rafael J. Wysocki)
- md: keep recovery_cp in mdp_superblock_s (Xiao Ni)
- pinctrl: mediatek: common-v1: Fix EINT breakage on older controllers (Chen-Yu Tsai)
- pinctrl: mediatek: Fix new design debounce issue (Hao Chang)
- pinctrl: mediatek: eint: Drop base from mtk_eint_chip_write_mask() (Chen-Yu Tsai)
- cpufreq/amd-pstate: Fix prefcore rankings (Mario Limonciello)
- platform/x86: lg-laptop: Check ACPI_COMPANION() against NULL (Rafael J. Wysocki)
- net/sched: sch_htb: limit htb_classify inner-class filter hops (Jamal Hadi Salim) [Orabug: 40041293] {CVE-2026-90053}
- tcp: fix corruption of urgent data on multi-segment retransmit (Jiayuan Chen) [Orabug: 40041301] {CVE-2026-90054}
- usb: atm: usbatm: fix invalid ci_range initialization (Deepanshu Kartikey) [Orabug: 40041308] {CVE-2026-90055}
- net: fec: only stop PTP if it was initialized (Bui Duc Phuc)
- slip: remove slip_hangup() to fix use-after-free in slip_receive_buf() (Eric Dumazet) [Orabug: 40041322] {CVE-2026-90057}
- net/sched: bound qdisc_pkt_len to prevent qdisc soft lockup (Jamal Hadi Salim) [Orabug: 40041330] {CVE-2026-90058}
- net: stmmac: selftests: Account for the UC filter list for filtering tests (Maxime Chevallier)
- net: stmmac: dwxgmac: Account for the primary MAC address for UC filtering (Maxime Chevallier)
- net: stmmac: dwmac4: Account for the primary MAC address for UC filtering (Maxime Chevallier)
- net: stmmac: dwmac1000: Account for the primary MAC address for UC filtering (Maxime Chevallier)
- net: stmmac: selftests: Check multiple MMC counters (Maxime Chevallier)
- selftests/arm64: Treat KSM merge_across_nodes as optional (Usama Anjum)
- selftests/arm64: Print missing MTE TAP headers (Usama Anjum)
- ALSA: control: Don't add invalid kcontrols to LED layer (Takashi Iwai) [Orabug: 40041339] {CVE-2026-90060}
- netfilter: x_tables: replace pr_{info,err}() by pr_info_ratelimited() (Pablo Neira Ayuso)
- netfilter: xt_HL: add pr_fmt and checkentry validation (Marino Dzalto)
- netfilter: xt_cgroup: Make it independent from net_cls (Michal Koutný)
- netfilter: nf_tables: move hardware offload step after building the chain blob (Pablo Neira Ayuso) [Orabug: 40041351] {CVE-2026-90062}
- virtio-net: Ensure that TCP packets don't overflow gso_segs (Alice Mikityanska) [Orabug: 40041355] {CVE-2026-90063}
- net: wangxun: use BIT_ULL() to prevent shift overflow on 32-bit archs (Jiawen Wu)
- net/smc: release the internal TCP sock on IPPROTO_SMC socket creation failure (Yifei Chu)
- net: ethernet: sun4i-emac: Fix IRQ error handling (Bui Duc Phuc)
- samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-multi-modify (Xu Wang)
- samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-modify (Xu Wang)
- libceph: validate banner payload length (Aleksandr Nogikh) [Orabug: 40041366] {CVE-2026-90067}
- ceph: revalidate ki_pos for O_APPEND writes after cap acquisition (Xiubo Li)
- ASoC: dapm: Fix off-by-one check on the second enum channel (Hyeongjun An) [Orabug: 40041369] {CVE-2026-90068}
- apparmor: policy_int make sure list heads are initialized before fail path (John Johansen)
- apparmor: Replace sprintf/strcpy with scnprintf/strscpy in aa_policy_init (Thorsten Blum)
- tpm: st33zp24: Validate locality read result (Ruoyu Wang)
- tpm: st33zp24: Return zero on status read failure (Ruoyu Wang) [Orabug: 40041375] {CVE-2026-90070}
- net/sched: sch_teql: restore skb->dev on the slave failure path (Victor Nogueira) [Orabug: 40043379] {CVE-2026-90071}
- net/sched: sfq: clamp quantum to avoid signed overflow soft lockup (Jamal Hadi Salim) [Orabug: 40041381] {CVE-2026-90072}
- net/sched: hhf: clamp quantum before hhf_change() to avoid overflow (Jamal Hadi Salim) [Orabug: 40041385] {CVE-2026-90073}
- net/sched: fq_pie: clamp default quantum to avoid signed overflow (Jamal Hadi Salim)
- net/sched: sch_codel: clamp default mtu to avoid disabling CoDel (Jamal Hadi Salim)
- net/sched: fq_codel: clamp default quantum and mtu (Jamal Hadi Salim) [Orabug: 40041392] {CVE-2026-90075}
- net/sched: fq: add overflow bounds to quantum and initial quantum (Jamal Hadi Salim) [Orabug: 40041397] {CVE-2026-90076}
- net: core: check skb_frags_readable before uncloning in skb_copy_ubufs (Mina Almasry)
- net/sched: act_skbmod: fix length calculations and avoid invalid header warnings (Eric Dumazet) [Orabug: 40041403] {CVE-2026-90078}
- net_sched: act_skbmod: use RCU in tcf_skbmod_dump() (Eric Dumazet)
- maple_tree: fix argument name in header (Liam R Howlett)
- maple_tree: catch race in mas_alloc_cyclic() (Liam R Howlett)
- selftests/mm: skip COW tmpfile cases when fallocate() is unsupported (Usama Anjum)
- selftests/mm: report unique test names for each cow test (Mark Brown)
- selftests/mm/cow: modify the incorrect checking parameters (Hao Ge)
- cifs: fix clearing stats for fastest execution of each smb2 command (Frank Sorenson)
- octeontx2-af: Fix TL3/TL2 link config ENA clearing (Naveen Mamindlapalli)
- net: qualcomm: rmnet: restore skb->dev on deaggregated frames (Xiang Mei)
- gtp: add synchronize_net() in gtp_newlink() error path to prevent use-after-free (Cen Zhang) [Orabug: 40033099] {CVE-2026-89789}
- Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop (Hyunwoo Kim) [Orabug: 40041440] {CVE-2026-90088}
- Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path (Chris Lu)
- Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX (Chris Lu)
- Bluetooth: btmtk: Do not discard the subsystem reset timeout (Ismail Tarim)
- Bluetooth: btmtk: Do not report success when subsys reset fails (Ismail Tarim)
- Bluetooth: btmtk: Fix short read errors in btmtk_usb_reg_read() (Greg Kroah-Hartman)
- Bluetooth: btmtk: Add MT6639 (MT7927) Bluetooth support (Javier Tia)
- Bluetooth: mgmt: fix 'hdev->discovery.uuids' NULL dereference (Pavel Shpakovskiy) [Orabug: 40072795] {CVE-2026-93247}
- Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN (Pauli Virtanen) [Orabug: 40043384] {CVE-2026-90092}
- arm64: ptdump: Make note_page_flush() range aware (Wei-Lin Chang)
- mm/ptdump: split note_page() into level specific callbacks (Anshuman Khandual)
- mm: rename GENERIC_PTDUMP and PTDUMP_CORE (Anshuman Khandual)
- mm: make DEBUG_WX depdendent on GENERIC_PTDUMP (Anshuman Khandual)
- powerpc: Add preempt lazy support (Shrikanth Hegde)
- s390: Add ARCH_HAS_PREEMPT_LAZY support (Heiko Carstens)
- s390: Add missing _TIF defines (Heiko Carstens)
- arm64: Enable ARCH_HAS_NONLEAF_PMD_YOUNG (Yicong Yang)
- scsi: qla2xxx: Fix an loop timeout test (Dan Carpenter)
- net: page_pool: Remove zone/policy GFP flags when allocating XArray entries (Rongrong)
- bnxt_en: Fix call to hardware monitoring event handler (Guenter Roeck) [Orabug: 40041473] {CVE-2026-90101}
- rtc: pcf85363: Add error checking to regmap calls in probe() (Cosmo Chou)
- NFSv4/pnfs: key the data server cache on the NFS version (Junrui Luo) [Orabug: 40041479] {CVE-2026-90102}
- nfs: move the nfs4_data_server_cache into struct nfs_net (Jeff Layton)
- NFSv4.2: fix LAYOUTSTATS send buffer exhaustion (Junrui Luo) [Orabug: 40041485] {CVE-2026-90103}
- net/smc: free pending qentry in smc_llc_flow_stop() before memset (Mahanta Jambigi)
- net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition (Mahanta Jambigi)
- net: sched: fix 32-bit backlog wrap in gred, bfifo and plug enqueue (Jamal Hadi Salim) [Orabug: 40041523] {CVE-2026-90109}
- inetpeer: randomize RB-tree node comparison using SipHash (Eric Dumazet) [Orabug: 40041529] {CVE-2026-90110}
- net: qlcnic: validate unified ROM sections before loading (Pengpeng Hou) [Orabug: 40041540] {CVE-2026-90112}
- net: add missing ref_tracker_dir_exit() to net_passive_dec() (Tetsuo Handa)
- net: ipa: balance runtime PM reference on remove error (Ruoyu Wang)
- forcedeth: stop the tx_timeout register dump past the requested window (Marek Czernohous)
- net: thunderbolt: Count delivered packets in rx_packets and rx_bytes (Fan Ye)
- net/sched: add get_fill_size callbacks for actions missing them (Victor Nogueira)
- net: bridge: Reject descending VLAN tunnel ranges (Ruoyu Wang) [Orabug: 40041548] {CVE-2026-90114}
- xsk: fix NULL pointer dereference in __xsk_rcv() (Cen Zhang) [Orabug: 40041552] {CVE-2026-90115}
- xsk: avoid double checking against rx queue being full (Maciej Fijalkowski)
- xsk: Get rid of xdp_buff_xsk::orig_addr (Maciej Fijalkowski)
- RDMA/ucma: Allow path records to exactly fit the output buffer (Serhat Kumral)
- ALSA: ice1712: Fix the card leak at probe error with the auto-cleanup (Xu Wang) [Orabug: 40041562] {CVE-2026-90119}
- ALSA: core: Add scoped cleanup helper for card references (Cássio Gabriel)
- clk: visconti: Make sure clk_init_data is fully initialized (Geert Uytterhoeven)
- clk: ti: Make sure clk_init_data is fully initialized (Geert Uytterhoeven)
- prctl: fix PR_SET_MM_AUXV losing the forced AT_NULL terminator (Bradley Morgan)
- rtc: gamecube: check return value of devm_rtc_register_device() (Linkai Gong)
- i2c: ocores: Disable clock on failed resume (Ruoyu Wang)
- irqchip/renesas-rzg2l: Fix loss of interrupt (Biju Das)
- rtc: zynqmp: Return optional clock lookup errors (Pengpeng Hou)
- smb: client: fix request buffer leak in smb2_new_read_req() (Christopher Lusk) [Orabug: 40041584] {CVE-2026-90125}
- rtc: pcf8563: fix clock provider leak on unbind (Yi Ding) [Orabug: 40041588] {CVE-2026-90126}
- vdpa/mlx5: fix wrong list iterated in add_direct_chain error path (Li Rongqing) [Orabug: 40041594] {CVE-2026-90128}
- virtio_pci: fix wrong queue index for admin vq in intx path (Li Rongqing)
- vdpa_sim: fix cleanup after worker creation failure (Linfeng Sun) [Orabug: 40041605] {CVE-2026-90130}
- virtio_balloon: disable indirect descriptors (Michael S. Tsirkin)
- i3c: mipi-i3c-hci: Fix missing STAT_IBI_STATUS_THLD in PIO mode (Jian-Ming Liao)
- i3c: mipi-i3c-hci: Refactor PIO register initialization (Adrian Hunter)
- i3c: mipi-i3c-hci: Switch PIO data allocation to devm_kzalloc() (Adrian Hunter)
- i3c: mipi-i3c-hci: Quieten initialization messages (Adrian Hunter)
- net: add missing ref_tracker_dir_exit() to alloc_netdev_mqs() (Tetsuo Handa) [Orabug: 40041613] {CVE-2026-90135}
- bonding: initialize err for empty target lists (Ruoyu Wang)
- mlxbf-bootctl: fix the build error with FIELD_PREP() (Nikolay Kulikov)
- platform/x86: hp-bioscfg: fix password encoding bounds check (Guangshuo Li) [Orabug: 40041618] {CVE-2026-90137}
- vsock: use sock_error() to consume sk_err after a failed connect (Nguyen Dinh Phi)
- vsock: don't check the listener's sk_err in vsock_accept() (Nguyen Dinh Phi) [Orabug: 40041620] {CVE-2026-90138}
- vsock: avoid timeout for non-blocking accept() with empty backlog (Laurence Rowe)
- platform/x86: dell-wmi-sysman: Fix instance ID bounds (Hyeongjun An)
- net/smc: hash socket only after full initialisation in smc_sk_init() (Mahanta Jambigi)
- 8139cp: fix Rx and Tx not being disabled in cp_suspend (Karl Mehltretter)
- vxlan: mdb: Fix use-after-free in vxlan_mdb_flush() (Baul Lee) [Orabug: 40072799] {CVE-2026-93250}
- ALSA: hda: Fix connection list comparison in proc output (Xu Rao)
- fuse: check for NULL root inode in fuse_fill_super_submount (Baokun Li) [Orabug: 40041625] {CVE-2026-90139}
- fuse: check attributes staleness on fuse_iget() (Zhang Tianci)
- fuse: convert readdir to use folios (Joanne Koong)
- fuse: support folios in struct fuse_args_pages and fuse_copy_pages() (Joanne Koong)
- fs/ntfs3: validate ef->size covers the record's name and value (Weiming Shi)
- fs/ntfs3: fix out-of-bounds read in read_log_rec_buf() (Konstantin Komarov)
- cuse: wait for pending RCU callbacks on module exit (Baokun Li) [Orabug: 40041628] {CVE-2026-90140}
- net: bridge: vlan: fix inverted default vlan notification (Nikolay Aleksandrov)
- tls: fix RX desync on overlapping skbs (Maximilian Immanuel Brandtner)
- net: dsa: mv88e6xxx: Fix PCS link check on CMODE read error (Ruoyu Wang)
- vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes (Xiang Mei) [Orabug: 40033013] {CVE-2026-89776}
- ipvs: fix integer overflow in ftp helper port/address parsing (Joas Antonio Dos Santos) [Orabug: 40041631] {CVE-2026-90141}
- f2fs: fix to avoid pinfile fragment on fragment:{block, segment} mode (Chao Yu)
- f2fs: cleanup w/ f2fs_need_rand_{blk, seg, seg_blk} (Chao Yu)
- f2fs:Fix incomplete search range in f2fs_get_victim when f2fs_need_rand_seg is enabled (Liu Jinbao)
- f2fs: fix to parse temperature correctly in f2fs_get_segment_temp() (Chao Yu)
- net: hsr: free learned nodes on device setup failure (Xin Xie) [Orabug: 40079963] {CVE-2026-100071}
- pppox: drain queued packets on channel handoff (Qingfang Deng)
- net: dsa: b53: fix error propagation from b53_fdb_dump() (Vladimir Oltean)
- net: kcm: Hold RCU read lock while running BPF parser (Junseo Lim)
- ionic: fix completion descriptor access with 2x desc size (Prabu Thayalan)
- drm/xe: tests: fix error message in xe_migrate_sanity_test() (Dan Carpenter)
- clk: ti: mux: resolve parent clocks by DT index, not by name (Mathieu Dubois-Briand)
- clk: ti: use kcalloc() instead of kzalloc() (Ethan Carter Edwards)
- clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate() (Onur Özkan) [Orabug: 40041649] {CVE-2026-90147}
- nfs: fix ENXIO on O_CREAT open of existing symlink over NFSv3 (Michael Nemanov)
- NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease() (Zhansong Gao) [Orabug: 40041651] {CVE-2026-90148}
- pnfs/blocklayout: Fix device leaks on parse failure (Zhangguodong) [Orabug: 40041658] {CVE-2026-90150}
- NFSv4: remove callback IDR entry on client allocation failure (Ruoyu Wang) [Orabug: 40041662] {CVE-2026-90151}
- nfs: refactor pNFS functions using clear_and_wake_up_bit (Arnaud Bonnet)
- nfs: replace atomic bitops sequence with clear_and_wake_up_bit helper (Arnaud Bonnet)
- smb/server: fix session leak in ksmbd_session_register() (Tanze)
- ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size (Hang Nan)
- ksmbd: disconnect on SMB3 decryption failure (Namjae Jeon)
- bpf: Reject negative optlen in cgroup getsockopt hook (Junseo Lim) [Orabug: 40041687] {CVE-2026-90157}
- m68k: nfcon: Do not call console_is_registered() in nfcon_device() (Andreas Schwab)
- bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks (Junseo Lim) [Orabug: 40041692] {CVE-2026-90159}
- erofs: fix unused pcluster_pools for higher page sizes (Ojaswin Mujoo)
- erofs: support unaligned encoded data (Gao Xiang)
- erofs: convert z_erofs_bind_cache() to folios (Gao Xiang)
- lwt_bpf: Restore reserved headroom after xmit program (Junseo Lim) [Orabug: 40041696] {CVE-2026-90160}
- smb/server: preserve error status in smb2_handle_negotiate() (Zhangguodong)
- smb/server: fix invalid pointer dereference in ksmbd_stop_durable_scavenger() (Zhangguodong)
- smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request() (Zhangguodong)
- ksmbd: free preauth sessions on connection teardown (Namjae Jeon)
- ksmbd: do not advertise unimplemented CA support (Namjae Jeon)
- ksmbd: validate ipc response length before dereferencing its fields (Yunseong Kim)
- smb: server: fix leak of ksmbd_ipc_login_request_ext() returned buffer (Enzo Matsumiya)
- ksmbd: Do not skip lock checks for single-byte ranges (Guangshuo Li)
- hwmon: (emc1403) Drop hysteresis for low limit temperature (Marius Cristea)
- hwmon: (emc1403) Rely on subsystem locking (Guenter Roeck)
- hwmon: (coretemp) Fix core_data leak on CPUs without PTS (Szymon Wilczek) [Orabug: 40041745] {CVE-2026-90178}
- block: mtip32xx: synchronize ioctls with device removal (Hongyan Xu) [Orabug: 40041748] {CVE-2026-90180}
- ublk: reject non-power-of-2 zone sizes in SET_PARAMS (Yao Sang)
- null_blk: serialize configfs attribute updates with device setup (Niklas Cassel) [Orabug: 40041769] {CVE-2026-90184}
- null_blk: serialize configfs attribute stores with the lock (Zizhi Wo) [Orabug: 40041774] {CVE-2026-90185}
- null_blk: reject per-device queue resize for shared tag set (Zizhi Wo) [Orabug: 40041778] {CVE-2026-90186}
- null_blk: free zones array on device power-off (Zizhi Wo) [Orabug: 40041782] {CVE-2026-90187}
- null_blk: free global tag_set on init error path (Zizhi Wo) [Orabug: 40041786] {CVE-2026-90188}
- null_blk: register configfs subsystem after creating default devices (Zizhi Wo) [Orabug: 40041791] {CVE-2026-90189}
- null_blk: use DEFINE_MUTEX for the file-scope mutex (Zizhi Wo) [Orabug: 40041796] {CVE-2026-90190}
- mailbox: pcc: Fix command timeout due to missed interrupt (Huisong Li)
- Revert "mailbox/pcc: support mailbox management of the shared buffer" (Sudeep Holla)
- mailbox/pcc: support mailbox management of the shared buffer (Adam Young)
- mailbox: pcc: Always map the shared memory communication address (Sudeep Holla)
- mailbox: rockchip: disable pclk on probe failure and unbind (Linmao Li)
- mailbox: qcom-cpucp: handle NULL data in send_data callback (Jia Yang)
- mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler (Jia Yang)
- perf dso: Guard against cache underflow on short reads in dso_cache__memcpy() (Arnaldo Carvalho de Melo)
- perf dso: Use stored fd error instead of stale errno in file_read() and file_size() (Arnaldo Carvalho de Melo)
- perf dso: Guard close() against invalid fd in dso__decompress_kmodule_path() (Arnaldo Carvalho de Melo)
- sched_ext/scx_flatcg: Fix cvtime true-up on slice expiry (Tao Cui)
- crypto: lskcipher - propagate errors from unaligned crypt (Karl Mehltretter)
- crypto: hisilicon/sec2 - fix CCM algorithm long packet failure (Zhushuai Yin)
- bpf: Fix pending_pos walk on 32-bit ring position wrap (Israel Téllez García)
- ACPI: scan: fix bus ID cleanup on device_add() failures (Hongyan Xu) [Orabug: 40041803] {CVE-2026-90194}
- ring-buffer: Remove trace_buffer::cpus (Vincent Donnefort)
- riscv, bpf: Fix missing sign-ext for signed 1-byte and 2-byte kfunc args (Pu Lehui)
- HID: multitouch: reclassify HTIX5288 to WIN_8_FORCE_MULTI_INPUT_NSMU (Lin Xianglin)
- ASoC: SOF: validate topology volume range before allocation (Pengpeng Hou) [Orabug: 40041809] {CVE-2026-90196}
- tracing: Have trace_event_update_all() only handle module that is loading (Steven Rostedt)
- tracing: Remove "__attribute__()" from the type field of event format (Masami Hiramatsu)
- ALSA: core: Fix use-after-free in snd_card_do_free() (Aleksandr Nogikh) [Orabug: 40041814] {CVE-2026-90198}
- fs/ntfs3: reject out-of-range evcn in mi_enum_attr() (Zhan Xusheng)
- fs/ntfs3: fix integer overflow in MFT cluster validation (Zhan Xusheng)
- net: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg race (Jijie Shao) [Orabug: 40041824] {CVE-2026-90201}
- scsi: ufs: core: Set task state before io_schedule_timeout() (Bart Van Assche)
- scsi: ufs: core: Remove redundant host_lock calls around UTMRLDBR (Avri Altman)
- scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (Chandrakanth Patil) [Orabug: 40041828] {CVE-2026-90202}
- selftests/bpf: Fix for veristat file/prog filters processing (Eduard Zingerman)
- Squashfs: check block offset is not negative (Phillip Lougher) [Orabug: 40041834] {CVE-2026-90203}
- ocfs2: fix circular locking dependency in ocfs2_init_acl() (Krystian Kaniewski) [Orabug: 40072806] {CVE-2026-93252}
- bpftool: Fix double close in map dump (Yuan Chen)
- x86/pkeys: Fix pkey_alloc() return value when pkeys are not supported (Bijan Tabatabai)
- selftests/cgroup: Preserve CPU hotplug write errors (Rui Qi)
- selftest/cgroup: Clean up and restructure test_cpuset_prs.sh (Waiman Long)
- selftest/cgroup: Update test_cpuset_prs.sh to use | as effective CPUs and state separator (Waiman Long)
- cgroup/cpuset: Remove remote_partition_check() & make update_cpumasks_hier() handle remote partition (Waiman Long)
- cgroup/cpuset: Fix spelling errors in file kernel/cgroup/cpuset.c (Everest K C )
- ALSA: seq: midi: Serialize input teardown with event_input (John Keeping) [Orabug: 40041851] {CVE-2026-90207}
- clocksource/drivers/armada: Unwind timer clock on init failure (Yuho Choi)
- clocksource/drivers/clps711x: Do not unmap clocksource MMIO (Guangshuo Li)
- s390/debug: Fix deadlock during unregister (Peter Oberparleiter)
- xenbus: Unregister reboot notifier on init failure (Yuho Choi)
- power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address (Henrik Grimler)
- power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address (Henrik Grimler)
- power: supply: bq27xxx: bq27520g4: fix REG_TTES address (Henrik Grimler)
- power: supply: bd99954: Drop bad register fields (Matti Vaittinen)
- PCI/ASPM: Disable/restore ASPM on every function for multi-function devices (Krishna Chaitanya Chundru)
- PCI/ASPM: Cache L0s/L1 Supported so advertised link states can be overridden (Bjorn Helgaas)
- spi: img-spfi: don't disable runtime PM on DMA deferred probe (Felix Gu)
- selftests/bpf: vmtest.sh: Preserve command quoting when running in the VM (Vineet Gupta)
- selftests: harness: Mark test fixture objects __maybe_unused (David Matlack)
- selftests: harness: Restore order of test functions (Thomas Weißschuh)
- bpf, s390: Clear fetch destination on faulting arena atomic (Daniel Borkmann)
- kunit: tool: fix _list_tests filtering wrong variable when list has TAP prefix (Mohammad Abu-Khader)
- super: fix dying superblock warning messages (Karl Mehltretter)
- PCI/ASPM: Use pcie_capability_clear_and_set_word() for ASPM disable/restore (Krishna Chaitanya Chundru)
- firewire: core: fix memory leak in error path of build_tree() (Takashi Sakamoto) [Orabug: 40041872] {CVE-2026-90213}
- firewire: core: validate parent port count before allocating nodes in build_tree() (Takashi Sakamoto)
- firewire: core: consolidate port counting in build_tree() (Takashi Sakamoto)
- firewire: core: add KUnit tests for failure of tree building (Takashi Sakamoto)
- firewire: core: add KUnit tests for successful tree building (Takashi Sakamoto)
- firewire: core: add KUnit test skeleton for node tree (Takashi Sakamoto)
- UBI: fix two issues in the ubi.mtd MODULE_PARM_DESC (Ran Hongyun)
- ASoC: xilinx: formatter_pcm: fix stream_data leak on open error (Rosen Penev)
- mtd: ubi: Release device reference on busy detach (Yuho Choi) [Orabug: 40041880] {CVE-2026-90215}
- ubi: Fix rollback for explicit UBI device numbers (Yuho Choi) [Orabug: 40041882] {CVE-2026-90216}
- UBI: fastmap: Pass to_be_tortured when reusing old fastmap PEBs (Zhihao Cheng)
- UBI: Preserve torture flag when rescheduling failed erasures (Zhihao Cheng)
- ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready (Liangcheng Wang)
- ASoC: pxa: Use devm_clk_get_optional() for extclk clock (Bui Duc Phuc)
- ice: clear the default forwarding VSI rule when releasing a VSI (Petr Oros)
- RDMA/cma: Fix WARNING in res_to_rt (Zhu Yanjun) [Orabug: 40041893] {CVE-2026-90218}
- RDMA/cxgb4: Free debugfs on registration failure (Fan Wu) [Orabug: 40041897] {CVE-2026-90219}
- dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal (Guangshuo Li)
- nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing (Yun Zhou)
- nfc: digital: Do not dump a NULL response in command completion (Linmao Li)
- nfc: pn533: hold a reference to the request skb during send_frame (Yinhao Hu)
- nfc: llcp: bound SNL TLV parsing to the skb and add length checks (Doruk Tan Ozturk)
- nfc: nci: fix double completion race in nci_data_exchange_complete (Zhenghang Xiao)
- nfc: llcp: read llcp_sock->local under the socket lock in getsockopt (Breno Leitao)
- nfc: llcp: avoid userspace overflow on invalid optlen (Breno Leitao)
- nvme: reject passthrough of driver-managed Set Features (Chao Shi)
- nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() (Yang Xiuwei) [Orabug: 40041932] {CVE-2026-90227}
- nvmet: fix NULL pointer dereference in nvmet_execute_identify_ns_zns() (Guixin Liu) [Orabug: 40041939] {CVE-2026-90228}
- nvme-apple: Drop the PRP null check chicken bit (Sven Peter)
- nvme: apple: Add Apple A11 support (Nick Chan)
- nvme-apple: Never set the opcode in the NVMMU TCB (Sven Peter)
- nvme-apple: Don't set a DMA direction for commands without a data transfer (Sven Peter)
- nvme-apple: Destroy the admin queue on removal (Sven Peter)
- nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() (Guixin Liu) [Orabug: 40041949] {CVE-2026-90230}
- nvme: Add the DHCHAP maximum HD IDs (Alistair Francis)
- nvme: introduce change ptpl and iekey definition (Guixin Liu)
- nvme: add reservation command's defines (Guixin Liu)
- s390/irqflags: Add out-of-line definitions of arch_local_irq_*() for KMSAN (Ilya Leoshkevich)
- s390: Drop unnecessary CONFIG_IMA_SECURE_AND_OR_TRUSTED_BOOT (Coiby Xu)
- integrity: Make arch_ima_get_secureboot integrity-wide (Coiby Xu)
- powerpc: Use str_enabled_disabled() helper function (Thorsten Blum)
- powerpc/vdso: Add a page for non-time data (Christophe Leroy)
- ASoC: qcom: q6apm: keep the graph start count in sync with the DSP (Jorijn van der Graaf)
- spi: sprd-adi: Fix probe succeeding without registering the controller (Babanpreet Singh)
- phy: qcom: qmp-combo: Drop qmp_v4_calibrate_dp_phy (Esteban Urrutia)
- phy: qualcomm: qmp-combo: Add DP offsets and settings for Glymur platforms (Abel Vesa)
- phy: qualcomm: qmp-combo: Update QMP PHY with Glymur settings (Wesley Cheng)
- phy: qualcomm: Update the QMP clamp register for V6 (Wesley Cheng)
- phy: qcom-qmp-combo: Use regulator_bulk_data with init_load_uA for regulator setup (Faisal Hassan)
- phy: qcom: qmp-combo: Add new PHY sequences for SM8750 (Wesley Cheng)
- phy: qualcomm: qmp-combo: add support for SAR2130P (Dmitry Baryshkov)
- phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs (Esteban Urrutia)
- iommu/amd: Fix incorrect device ID in invalid PASID error message (Vasant Hegde)
- powerpc/configs: enable CONFIG_RAS to fix EDAC support (Michael Walle)
- sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE (Runyu Xiao) [Orabug: 40041973] {CVE-2026-90235}
- SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6 (Weiming Shi) [Orabug: 40033068] {CVE-2026-89784}
- arm64: Disable KCSAN instrumentation in delay.o (Marco Elver)
- xdrgen: Fix opaque and string encoders for unbounded members (Chuck Lever)
- xdrgen: Do not declare union XDR functions in the definitions header (Chuck Lever)
- xdrgen: Address some checkpatch whitespace complaints (Chuck Lever)
- xdrgen: Implement big-endian enums (Chuck Lever)
- xdrgen: Rename "enum yada" types as just "yada" (Chuck Lever)
- m68k: Fix backtraces for non-running tasks (Karl Mehltretter)
- iommu/vt-d: Tear down scalable-mode context on probe failure (Lu Baolu) [Orabug: 40041987] {CVE-2026-90241}
- iommu/vt-d: Clear Present bit before tearing down copied context entry (Lu Baolu) [Orabug: 40041992] {CVE-2026-90243}
- iommu/vt-d: Fix UCTP context table slot when copying root entries (Desnes Nunes)
- fbdev: kyro: Validate overlay viewport coordinates (Danila Chernetsov)
- fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() (Myeonghun Pak)
- perf synthetic-events: Fix divide by zero in perf_event__synthesize_threads (Ian Rogers)
- perf python: Check counts_values size in set_values (Ian Rogers)
- perf python: Add support for 'struct perf_counts_values' to return counter data (Gautam Menghani)
- perf python: Remove python 2 scripting support (Ian Rogers)
- perf test: Fix skiplist leak in cmd_test (Ian Rogers)
- perf test: Support dynamic test suites with setup callback and private data (Ian Rogers)
- perf test: Send list output to stdout rather than stderr (Ian Rogers)
- perf test: Rename functions and variables for better clarity (Ian Rogers)
- perf test: Sort tests placing exclusive tests last (Ian Rogers)
- perf test: Add a signal handler to kill forked child processes (Ian Rogers)
- perf test: Run parallel tests in two passes (Ian Rogers)
- perf test: Add a signal handler around running a test (Ian Rogers)
- perf test: Display number of active running tests (Ian Rogers)
- perf test: Introduce workloads__for_each() (Arnaldo Carvalho de Melo)
- perf synthetic-events: Fix uninitialized pthread_join (Ian Rogers)
- perf stat: Fix evsel_list leak in cmd_stat (Ian Rogers)
- ARM: dts: helios4: add SATA regulator supplies (Rosen Penev)
- ARM: dts: helios4: add vcc-supply to GPIO expander (Rosen Penev)
- ARM: dts: helios4: add vcc-supply to EEPROM (Rosen Penev)
- arm64: dts: turris-mox: fix usb3 phys (Tomáš Macholda)
- riscv: cpufeature: Clarify ISA spec version for canonical order (Guodong Xu)
- net/sched: cls_api: fix teardown of an adopted proto on insert-race loss (Victor Nogueira) [Orabug: 40042004] {CVE-2026-90248}
- iio: light: gp2ap002: re-enable irq if runtime suspend fails (Nikhil Gautam)
- iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes (Nikhil Gautam)
- Bluetooth: MSFT: validate evt_prefix_len against the response length (Ali Ahmet Memis)
- Bluetooth: btmtksdio: fix usage_count leak when autosuspend_delay is negative (Guangshuo Li)
- Bluetooth: btmtk: add MT7902 SDIO support (Sean Wang)
- Bluetooth: btmtk: add MT7902 MCU support (Sean Wang)
- mmc: sdio: add MediaTek MT7902 SDIO device ID (Sean Wang)
- Bluetooth: MGMT: free the mesh send cancel command when it is cancelled (Linmao Li) [Orabug: 40042019] {CVE-2026-90253}
- Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths (Linmao Li) [Orabug: 40042022] {CVE-2026-90254}
- Bluetooth: hci_conn: fix the SCO setup context lifetime (Linmao Li) [Orabug: 40042026] {CVE-2026-90255}
- Bluetooth: btintel: Fix diagnostics event detection (Zijun Hu)
- Bluetooth: virtio_bt: avoid OOB read of build info string (Hyeongjun An)
- btrfs: retry verity reads for not-uptodate Merkle folios (Chenyichong) [Orabug: 40042045] {CVE-2026-90262}
- scsi: sd: Fix sd_done() sense handling condition (Yang Xiuwei)
- perf trace-event: Fix integer truncation in do_read() and skip() (Tanushree Shah)
- Bluetooth: btusb: QCA: Fix populating devcoredump fields on unenabled devices (Zijun Hu)
- Bluetooth: btusb: Record matched usb_device_id into btusb_data (Zijun Hu)
- Bluetooth: btusb: refactor endpoint lookup (Johan Hovold)
- Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() (Zijun Hu)
- Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event (Zijun Hu)
- sched/fair: Check CPU capacity before comparing group types during load balance (Ricardo Neri)
- ACPI: video: Release PCI device reference after lookup (Yuho Choi)
- regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling (Kamal Wadhwa)
- coresight: etm4x: fix leaked trace id (Levi Yun)
- coresight: etm4x: fix underflow for usage of (nrseqstate - 1) (Levi Yun) [Orabug: 40042070] {CVE-2026-90274}
- coresight: Change syncfreq to be a u8 (James Clark)
- coresight: etm4x: fix wrong check of etm4x_sspcicrn_present() (Levi Yun)
- md/raid1: don't set array_frozen in raid1_takeover() (Bruce Johnston) [Orabug: 40042074] {CVE-2026-90275}
- md: avoid stale clone I/O accounting timestamps (Yu Kuai)
- md/raid5: round bitmap stripes with sector division (Yu Kuai) [Orabug: 40042080] {CVE-2026-90279}
- phy: qcom: qmp-usb: Fix possible NULL-deref on early runtime suspend (Loic Poulain)
- phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend (Loic Poulain)
- phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend (Loic Poulain)
- phy: qcom: sgmii-eth: vote for both voltage rails with correct current loads (Mohd Ayaan Anwar)
- phy: qcom-sgmii-eth: relax order of .power_on() vs .set_mode*() (Russell King)
- soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() (Linkai Gong)
- hugetlbfs: release subpool on fill_super failure (Chenyichong) [Orabug: 40042090] {CVE-2026-90283}
- pinctrl: rockchip: Reset the pin count when recalculating SoC data (Simon Glass)
- firmware_loader: do not queue completed sysfs fallback requests (Mukesh Ojha) [Orabug: 40042094] {CVE-2026-90284}
- scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path (Manish Rangankar) [Orabug: 40042098] {CVE-2026-90285}
- drm/amdgpu/gfx6: Use PFP on the compute queues too (Timur Kristóf)
- drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets (Timur Kristóf)
- perf trace-event: Fix buffer overflow in read_string() (Tanushree Shah)
- phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table (Gerald Loacker)
- phy: sunplus: fix error handling in sp_uphy_init() (Felix Gu)
- arm64: dts: ti: k3-am64: Fix MDIO clock reference for ICSSG0 node (Meghana Malladi)
- ext4: fix spurious message about orphan cleanup on RO fs (Jan Kara)
- drm/amdgpu/gfx6: Fixup emit_cntxcntl() (Timur Kristóf)
- mfd: iqs62x: Reject zero-length firmware records (Pengpeng Hou)
- mfd: rave-sp: validate received frame payload lengths (Pengpeng Hou)
- arm64: hibernate: Restore DAIF state on error (Vladimir Murzin) [Orabug: 40042116] {CVE-2026-90290}
- arm64: hibernate: mask DAIF before restoring hibernated kernel (Ada Couprie Diaz) [Orabug: 40072825] {CVE-2026-93256}
- wifi: mac80211: skip default WMM setup for AP_VLAN links (Felix Fietkau)
- RDMA/erdma: restrict the driver to little-endian systems (Leon Romanovsky)
- module/dups: Fix use-after-free in kmod_dup_req lifetime handling (Petr Pavlu)
- module/dups: Inform duplicate requests about the result directly (Petr Pavlu)
- module: use strscpy() to copy module names in stats and dup tracking (Naveen Kumar Chaudhary)
- module: replace use of system_wq with system_dfl_wq (Marco Crivellari)
- RDMA/siw: Fix use-after-free in siw_accept() (Shuangpeng Bai)
- IB/isert: post the full-feature receive buffers after session registration (Yehyeong Lee) [Orabug: 40042125] {CVE-2026-90293}
- IB/isert: delay the final Login Response until the session is registered (Yehyeong Lee) [Orabug: 40042129] {CVE-2026-90294}
- cpufreq: imx6q: fix out-of-bounds write when probed more than once (Karl Mehltretter)
- cpufreq: imx6q: fix devres accumulation across driver rebind (Karl Mehltretter)
- drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz (Jernej Skrabec)
- drm/sun4i: dw-hdmi: Drop TCON TOP port reference (Jernej Skrabec)
- drm/sun4i: tcon: Drop remote endpoint reference (Jernej Skrabec)
- drm/sun4i: crtc: Propagate layer initialization error (Jernej Skrabec)
- drm/sun4i: hdmi: Don't leak sync polarity bits into packet control (Jernej Skrabec)
- drm/sun4i: tcon: Drop TCON TOP device reference (Jernej Skrabec)
- drm/sun4i: tcon: Set output mux for DSI and LVDS (Jernej Skrabec)
- of: property: add of_graph_get_next_port_endpoint() (Kuninori Morimoto)
- of: property: add of_graph_get_next_port() (Kuninori Morimoto)
- drm/sun4i: vi scaler: Fix coefficient selection (Jernej Skrabec)
- clk: rockchip: rk3576: fix source muxes for SPI0..SPI4 (Alexey Charkov)
- ocfs2: synchronize heartbeat callbacks with o2net teardown (Cen Zhang) [Orabug: 40042162] {CVE-2026-90302}
- ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults (Yuanbin Xie)
- ARM: 9481/2: breakpoint: CFI breakpoints only on demand (Linus Walleij)
- RDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ (Yehyeong Lee) [Orabug: 40042181] {CVE-2026-90307}
- RDMA/erdma: Hold QP references for AE and CM processing (Cheng Xu) [Orabug: 40042186] {CVE-2026-90308}
- RDMA/erdma: Hold CQ references when processing EQ events (Cheng Xu)
- modpost: prevent leak when early return no suffix .o in read_symbols() (Robertus Diawan Chris)
- scripts/tags.sh: Prevent binary files appearing in cscope.files (Sergei Litvin)
- arm64: dts: qcom: sm7225-fairphone-fp4: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies (Manivannan Sadhasivam)
- arm64: dts: qcom: qcs8550-aim300: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies (Manivannan Sadhasivam)
- selftests/mm: fix ternary operator precedence in ksm_tests (Sayali Patil)
- selftests/mm: fix ksm NUMA merge test for systems with memoryless NUMA nodes (Sayali Patil)
- selftests/mm: ksm_tests: use kselftest framework (Mike Rapoport)
- ksm_tests: skip hugepage test when Transparent Hugepages are disabled (Li Wang)
- selftests/mm: add new test cases to the migration test (Donet Tom)
- bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed (Pu Lehui) [Orabug: 40042198] {CVE-2026-90313}
- remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry() (Mukesh Ojha) [Orabug: 40042201] {CVE-2026-90314}
- remoteproc: use rsc_table_for_each_entry() in rproc_handle_resources() (Mukesh Ojha)
- remoteproc: Move resource table data structure to its own header (Mukesh Ojha)
- arm64: dts: qcom: agatti: Add missing CX power domain to DISPCC (Imran Shaik)
- drm/omap: dsi: Do not copy isr table (Andreas Kemnade) [Orabug: 40042210] {CVE-2026-90316}
- riscv: dts: sophgo: cv180x: Allow the DMA multiplexer to set channel number for DMA controller (Inochi Amaoto)
- fat: release buffer head after rebuilding parent (Chenyichong) [Orabug: 40042219] {CVE-2026-90318}
- rapidio: clear mport->net when rio_add_net() fails (Guangshuo Li)
- pps-gpio: remove dead capture_clear code (Calvin Owens)
- pps: pps-gpio: split IRQ handler into hardirq timestamper + threaded handler (Michael Byczkowski)
- pps: clients: gpio: Bypass edge's direction check when not needed (Bastien Curutchet)
- pps: don't try to wait for negative timeouts in PPS_FETCH (Calvin Owens)
- lib/string: fix memchr_inv() for large ranges (Bradley Morgan)
- ocfs2/cluster: keep heartbeat local node stable (Cen Zhang) [Orabug: 40042238] {CVE-2026-90322}
- o2hb_region_dev_store(): avoid goto around fdget()/fdput() (Al Viro)
- ublk: check for ublk_unmap_io() returning 0 (Caleb Sander)
- block/kyber-iosched: flush per-cpu latency buckets over possible CPUs (Tao Cui)
- block/blk-iocost: collect per-cpu latency stats over possible CPUs (Tao Cui)
- block/blk-stat: drain per-cpu callback stats over possible CPUs (Tao Cui)
- blk-cgroup: skip dying blkg in blkcg_activate_policy() (Zheng Qixing) [Orabug: 40042245] {CVE-2026-90325}
- phonet: pep: do not write beyond optlen in getsockopt (Breno Leitao)
- net: stmmac: Skip PHY attach if custom PCS is in use (Zxyan Zhu)
- iio: light: tsl2583: return zero in write_raw() on success (Sang-Heon Jeon)
- iio: light: isl29028: return zero in write_raw() on success (Sang-Heon Jeon)
- iio: light: tsl2772: fix ALS calibscale readback (Yuanshen Cao)
- perf intel-bts: Fix off-by-one in auxtrace_info minimum size check (Arnaldo Carvalho de Melo)
- perf intel-pt: Fix off-by-one in auxtrace_info minimum size check (Arnaldo Carvalho de Melo)
- perf auxtrace: Fix queue grow overflow and old array leak (Arnaldo Carvalho de Melo)
- perf thread-stack: Fix heap buffer overflow on branch stack wrap copy (Arnaldo Carvalho de Melo)
- HID: lg4ff: validate report length before fixed offsets (Jiancheng Huang)
- HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure (Chao Huang)
- HID: i2c-hid: Fix "(null)" output when reading report descriptor fails (Ai Chao)
- HID: synchronize input before cleaning up a failed probe (Yousef Alhouseen) [Orabug: 40042259] {CVE-2026-90329}
- HID: i2c-hid: Refactor _DSM helper and add i2c-hid-acpi-prp0001 driver (谢致邦)
- tty: clear cdev pointer after cdev_add() failure (Karl Mehltretter) [Orabug: 40042272] {CVE-2026-90334}
- serial: amba-pl011: unprepare console clock on unregister (Karl Mehltretter)
- MIPS: ptrace: Fix syscall skipping via PTRACE_SYSCALL (Thomas Bogendoerfer)
- powerpc/irq: Fix missing r2 clobber in PCREL inline assembly (Saket Kumar Bhaskar)
- powerpc/smp: add NULL guard for cause_ipi in smp_muxed_ipi_message_pass (Gou Hao)
- firmware: coreboot: Validate table bounds (Laxman Acharya Padhya)
- firmware: google: Add bounds checks in coreboot_table_populate() (Titouan Ameline de Cadeville)
- wifi: mac80211: disconnect on CSA to channel 0 (Johannes Berg) [Orabug: 40042307] {CVE-2026-90344}
- wifi: mac80211: skip unused probe response countdown offsets (Catherine)
- wifi: zd1211rw: reject secondary interfaces to prevent conflicts (Slawomir Stepien)
- wifi: mac80211: send TWT teardown to peer after setup TX failure (Catherine)
- perf/cxlpmu: Fix 64-bit write to 32-bit HDM filter register (Davidlohr Bueso)
- iommu/arm-smmu-v3: Convert to use atomic poll timeout (Pranjal Shrivastava)
- wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump (Linghui Wu)
- wifi: mt76: mt7925: Fix EHT Beamformee SS subfields to meet 802.11be minimum (Shengwei Lu)
- wifi: mt76: mt7925: advertise EHT 320MHz capabilities for 6GHz band (Javier Tia)
- wifi: mt76: mt7915: report RX chain signal for all RX paths (Felix Fietkau)
- wifi: mt76: mt7915: fix chainmask handling for non-dbdc phys on band 1 (Felix Fietkau)
- wifi: mt76: mt7996: fix reg addr remap when addr is 0 (Stanleyyp Wang)
- wifi: mt76: mt7915: release hif2 reference on probe IRQ failure (Felix Fietkau) [Orabug: 40042331] {CVE-2026-90352}
- wifi: mt76: mt7915: fix ext PHY use-after-free on register error path (Felix Fietkau) [Orabug: 40042333] {CVE-2026-90353}
- wifi: mt76: mt7915: fix double hif2 init on the non-WED path (Felix Fietkau) [Orabug: 40042337] {CVE-2026-90354}
- wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement (Felix Fietkau) [Orabug: 40042341] {CVE-2026-90357}
- bpf, x86: Fix trampoline stack size for 128-bit arguments (Yonghong Song) [Orabug: 40042343] {CVE-2026-90358}
- perf machine: Check snprintf truncation for guest kallsyms path (Arnaldo Carvalho de Melo)
- perf machine: Free scandir entries in guest kernel map creation (Arnaldo Carvalho de Melo)
- perf machine: Reset errno before strtol in guest kernel map creation (Arnaldo Carvalho de Melo)
- perf machine: Don't abort guest map creation on first inaccessible dir (Arnaldo Carvalho de Melo)
- perf machine: Check snprintf truncation in machines__findnew() (Arnaldo Carvalho de Melo)
- perf machine: Use snprintf() for guestmount path construction (Arnaldo Carvalho de Melo)
- perf machine: Guard against NULL strlist in machines__findnew() (Arnaldo Carvalho de Melo)
- perf machine: Fix NULL parent dereference in fork event processing (Arnaldo Carvalho de Melo)
- regulator: core: use system_freezable_wq for init complete work (Joy Zou) [Orabug: 40042348] {CVE-2026-90360}
- wifi: ath11k: fix leak in ath11k_service_ready_ext_event() (Jeff Johnson) [Orabug: 40042352] {CVE-2026-90361}
- drm/msm/dsi: Drop dev_pm_opp_set_rate(0) (Konrad Dybcio) [Orabug: 40042355] {CVE-2026-90362}
- drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) (Konrad Dybcio)
- perf: arm_spe: Make wakeup range check overflow safe (Leo Yan)
- ACPI: processor: Unregister cpufreq notifier on init failure (Can Peng) [Orabug: 40042360] {CVE-2026-90364}
- ACPI: processor: idle: Optimize ACPI idle driver registration (Huisong Li)
- wifi: mt76: only consume the WO drop bit on WED v2 devices (Felix Fietkau)
- wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields (Felix Fietkau)
- wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV (Felix Fietkau)
- wifi: mt76: mt7915: unwind state on add_interface failure (Felix Fietkau) [Orabug: 40042380] {CVE-2026-90368}
- wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config (Felix Fietkau)
- wifi: mt76: check txfree done event on the WED hw path (Rex Lu)
- wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie (Felix Fietkau)
- wifi: mt76: fix stranded frames in mt76_txq_schedule_pending (Felix Fietkau)
- wifi: mt76: mt7915: write RX header translation bit to the correct register (Felix Fietkau)
- wifi: mt76: mt7996: don't report a zero TX bitrate (Felix Fietkau)
- wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss (Felix Fietkau) [Orabug: 40042386] {CVE-2026-90372}
- wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear (Felix Fietkau) [Orabug: 40042389] {CVE-2026-90373}
- wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset (Felix Fietkau)
- wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[] (Felix Fietkau)
- wifi: mt76: fix non-AQL packet accounting for MLO stations (Michael-Cy Lee) [Orabug: 40042393] {CVE-2026-90375}
- wifi: mt76: mt7996: fix capability of EHT-MCS 15 in MRU (Shayne Chen)
- wifi: mt76: mt792x: Fix memory leak in SDIO TX path (Eason Lai)
- wifi: mt76: mt7925: fix msg len mismatch between driver and firmware (Jared Huang)
- wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete (Eason Lai) [Orabug: 40042406] {CVE-2026-90380}
- wifi: mt76: add init_wiphy callback (Sean Wang)
- wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 (Zhi-Jun You)
- wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length (Lucid Duck) [Orabug: 40042409] {CVE-2026-90382}
- fanotify: report full event length for FIONREAD (Chenyichong)
- misc: sgi-gru: remove interrupt-context page-table walks (Usama Anjum) [Orabug: 40042413] {CVE-2026-90383}
- misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() (Abdun Nihaal)
- powerpc/crash: Fix possible memory leak in update_crash_elfcorehdr() (Jinjie Ruan)
- locking/lockdep: Fix NULL pointer dereference in __lock_set_class() (Naveen Kumar Chaudhary)
- md/raid1: create serial pool adding rdev to array with serialize_policy=1 (Martin Wilck) [Orabug: 40042420] {CVE-2026-90385}
- md: merge mddev serialize_policy into mddev_flags (Yu Kuai)
- md: merge mddev faillast_dev into mddev_flags (Yu Kuai)
- md: merge mddev has_superblock into mddev_flags (Yu Kuai)
- i3c: master: Fix device_register() error path (Adrian Hunter)
- i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices (Jakub Kicinski)
- swiotlb: Preserve allocation virtual address for dynamic pools (Aneesh Kumar K V) [Orabug: 40042428] {CVE-2026-90387}
- iommu/dma: Check atomic pool allocation result directly (Aneesh Kumar K V) [Orabug: 40042430] {CVE-2026-90388}
- md: scope memalloc_noio to allocation critical sections (Chen Cheng) [Orabug: 40042433] {CVE-2026-90389}
- md: skip redundant raid_disks update when value is unchanged (Abd-Alrhman Masalkhi)
- md: remove unused mddev argument from export_rdev (Chen Cheng)
- md/bitmap: resume array on backlog_store() error path (Chen Cheng) [Orabug: 40042436] {CVE-2026-90390}
- clk: qcom: Return expected ENOMEM error on dynamic allocation failure (Vladimir Zapolskiy)
- clk: qcom: gpucc-qcm2290: Park RCG's clk source at XO during disable (Imran Shaik)
- lib/test_hmm: fail dmirror_fault() when the mirrored mm is gone (Stanislav Kinsburskii)
- bpf: Fix potential UAF when reading bpf link info (Pu Lehui) [Orabug: 40042441] {CVE-2026-90392}
- bpf: Fix potential UAF in bpf_netns_link_update_prog (Pu Lehui) [Orabug: 40042446] {CVE-2026-90393}
- power: supply: sc2731_charger: cancel work on remove (Hongyan Xu)
- power: supply: isp1704_charger: cancel work on remove (Hongyan Xu) [Orabug: 40042456] {CVE-2026-90395}
- arm64: dts: qcom: sm8650: Fix the PCIe iommu-map entries (Manivannan Sadhasivam)
- arm64: dts: qcom: sm8650: add OPP table support to PCIe (Neil Armstrong)
- arm64: dts: qcom: sm8550: Fix the PCIe iommu-map entries (Manivannan Sadhasivam)
- arm64: dts: qcom: sm8450: Fix the PCIe iommu-map entries (Manivannan Sadhasivam)
- arm64: dts: qcom: sm8350: Fix the PCIe iommu-map entries (Manivannan Sadhasivam)
- arm64: dts: qcom: sm8250: Fix the PCIe iommu-map entries (Manivannan Sadhasivam)
- arm64: dts: qcom: sm8150: Fix the PCIe iommu-map entries (Manivannan Sadhasivam)
- arm64: dts: qcom: sdm845: Fix the PCIe iommu-map entries (Manivannan Sadhasivam)
- arm64: dts: qcom: sc8180x: Fix the PCIe iommu-map entries (Manivannan Sadhasivam)
- arm64: dts: qcom: sm8250-xiaomi-elish: correct the board ID (Dawid WróBel)
- firmware: qcom: scm: Fix tzmem state on probe retry (Mukesh Ojha)
- firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published (Mukesh Ojha) [Orabug: 40042461] {CVE-2026-90397}
- firmware: qcom: scm: instrument SMC call path with tracepoints (Yuvaraj Ranganathan)
- firmware: qcom: scm: add trace events for the SMC call interface (Yuvaraj Ranganathan)
- firmware: qcom_scm: Support multiple waitq contexts (Unnathi Chalicheemala)
- firmware: qcom_scm: Add API to get waitqueue IRQ info (Unnathi Chalicheemala)
- arm64: dts: qcom: sc8280xp-crd: Fix the pin index for misc_3p3_reg_en (Konrad Dybcio)
- clk: qcom: gcc-qcm2290: don't park QUP RCGs upon registration (Dmitry Baryshkov)
- arm64: dts: qcom: qcs404: Fix DTBS Check errors in usb controller nodes (Krishna Kurapati)
- arm64: dts: qcom: sdm632-motorola-ocean: Fix LED default trigger property (Konrad Dybcio)
- arm64: dts: qcom: msm8998: Don't pull-up I2C pins by default in sleep (Konrad Dybcio)
- rcu: Mark accesses to ->rcu_urgent_qs and ->rcu_need_heavy_qs (Itai Handler)
- wifi: ath11k: fix stride mismatch in mac_phy_caps_parse() (Jeff Johnson) [Orabug: 40042465] {CVE-2026-90398}
- wifi: ath12k: fix stride mismatch in mac_phy_caps_parse() (Jeff Johnson) [Orabug: 40042468] {CVE-2026-90399}
- selftests/zram: fix kernel_gte() for POSIX sh (Cheng-Han Wu)
- md: recheck spare changes before starting sync (Abd-Alrhman Masalkhi) [Orabug: 40042470] {CVE-2026-90400}
- tools/nolibc/powerpc: mark ctr and xer as clobbered by system call (Thomas Weißschuh)
- md/raid5: protect lockless recovery_offset accesses during reshape (Chen Cheng)
- md: add a new recovery_flag MD_RECOVERY_LAZY_RECOVER (Yu Kuai)
- md: rename recovery_cp to resync_offset (Li Nan)
- md: allow removing faulty rdev during resync (Zheng Qixing)
- md: ensure resync is prioritized over recovery (Li Nan)
- md/raid5-ppl: fix use-after-free in ppl_do_flush() (Sajal Gupta) [Orabug: 40072848] {CVE-2026-93262}
- md/raid5: protect bitmap batch counters aka seq_flush/seq_write consistency (Chen Cheng)
- bus: mhi: host: Fix controller cleanup on EDL sysfs failure (Yuho Choi) [Orabug: 40042474] {CVE-2026-90402}
- bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET (Manivannan Sadhasivam)
- wifi: rtlwifi: pci: fix error path in rtl_pci_probe() (Abdun Nihaal) [Orabug: 40042477] {CVE-2026-90403}
- platform/chrome: cros_ec_debugfs: Unregister panic notifier (Hongyan Xu) [Orabug: 40042482] {CVE-2026-90404}
- platform/chrome: cros_ec_debugfs: Clean up console log on probe failure (Hongyan Xu)
- PCI: starfive: Fix unchecked pm_runtime_get_sync() in probe (Ali Tariq)
- PCI: starfive: Fix Runtime PM handling and teardown ordering (Ali Tariq)
- wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event() (Jeff Johnson) [Orabug: 40042486] {CVE-2026-90407}
- spi: davinci: switch to managed controller allocation (Fan Wu)
- nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request (Guixin Liu) [Orabug: 40042498] {CVE-2026-90411}
- IB/isert: reject login PDUs declaring more data than was received (Yehyeong Lee) [Orabug: 40042503] {CVE-2026-90413}
- IB/isert: reject PDUs declaring more data than was received (Yehyeong Lee) [Orabug: 40042507] {CVE-2026-90414}
- RDMA/cxgb4: free STAG index when TPT entry write fails (Leon Romanovsky) [Orabug: 40042511] {CVE-2026-90415}
- RDMA/mlx5: Send cong param changes to the resolved port mdev (Leon Romanovsky)
- RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs (Leon Romanovsky) [Orabug: 40042517] {CVE-2026-90416}
- scsi: smartpqi: Fix AIO retry marker cleared by SCSI core between dispatches. (David Strahan)
- nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch (Ryusuke Konishi)
- nilfs2: prevent out-of-bounds read in super root block parsing (David Lee)
- nilfs2: fix infinite loop in nilfs_clean_segments() (Joshua Crofts)
- clk: rockchip: Fix the fractional part denominator on RK3588/RK3576 PLLs (Alexey Charkov)
- clk: mediatek: mt8135: Fix inverted gate control for devapc_ck (Akari Tsuyukusa)
- clk/x86: pmc_atom: add kasprintf return value check (Longlong Yan)
- clk: palmas: Manage external-control prepare with devm (Myeonghun Pak)
- clk: tegra: tegra124-emc: put EMC node on register failure (Guangshuo Li)
- arm64: dts: allwinner: sun50i-a64-pinephone: Fix mpu6050 mount matrix (Ondrej Jirman)
- wifi: mac80211: fix per-STA profile length in cross-link CSA parsing (Catherine)
- RDMA/efa: Fix PBL chunk length computation (Yonatan Nachum) [Orabug: 40072857] {CVE-2026-93264}
- iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs (Nicolin Chen)
- iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up vintfs (Nicolin Chen)
- iommu/tegra241-cmdqv: Use request_threaded_irq (Nicolin Chen)
- fs/ntfs3: reject restart table growth beyond U16_MAX entries (Weiming Shi)
- staging: rtl8723bs: use kfree_sensitive() for key material (Ivy Lopez)
- remoteproc: Prevent crash handling to race with rproc_del() (Bjorn Andersson) [Orabug: 40042565] {CVE-2026-90431}
- remoteproc: core: Attach rproc asynchronously in rproc_add() path via schedule_work() (Jingyi Wang)
- remoteproc: Allow shutdown of crashed processors (Bjorn Andersson)
- remoteproc: core: Drop redundant initialization of 'ret' in rproc_shutdown() (Peng Fan)
- w1: ds2482: Fix signedness bug in ds2482_w1_triplet() (Babanpreet Singh)
- spi: oc-tiny: switch to managed controller allocation (Fan Wu)
- isofs: release zisofs block pointer buffer head (Chenyichong) [Orabug: 40042575] {CVE-2026-90434}
- powercap: intel_rapl_tpmi: Handle PMU registration failure during probe (Sumeet Pawnikar)
- RDMA/mlx5: Fix integer overflow of user QP buffer size (Maher Sanalla) [Orabug: 40042579] {CVE-2026-90435}
- crypto: keembay - publish OF module alias for OCS AES/SM4 (Can Peng)
- crypto: keembay - Initialize completion before requesting IRQ (Linmao Li)
- scsi: ufs: debugfs: Reserve space for a string terminator (Li Qiang) [Orabug: 40042587] {CVE-2026-92477}
- power: supply: sbs-battery: Use a per-device serial number buffer (Babanpreet Singh)
- tools/build: Allow versioning of all LLVM tools defined in Makefile.include (James Clark)
- tools/build: Add bpftool-skeletons feature test (Tomas Glozar)
- pinctrl: mediatek: free EINT resources on unbind (Justin Yeh) [Orabug: 40042597] {CVE-2026-92481}
- pinctrl: mediatek: eint: Fix invalid pointer dereference for v1 platforms (Nícolas F R A Prado) [Orabug: 40080999] {CVE-2025-38266}
- pinctrl: mediatek: Fix the invalid conditions (Hao Chang)
- pinctrl: mediatek: Add EINT support for multiple addresses (Hao Chang)
- cxl/region: Fix use-after-free in find_pos_and_ways() error path (Alison Schofield) [Orabug: 40042608] {CVE-2026-92484}
- selftests/bpf: Fix memory leak on subtest_states reallocation (Feng Yang)
- selftests/bpf: Fix incorrect error checking for pthread_create (Feng Yang)
- ARM: lpc32xx: only run SoC init on LPC32xx hardware (Karl Mehltretter)
- arm64: dts: rockchip: Fix Gru WLAN sideband interrupt (Fabio Estevam)
- drm/panthor: return PTR_ERR() from devm_drm_dev_alloc() (Osama Abdelkader)
- fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init (Weiming Wu)
- netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet (Florian Westphal) [Orabug: 40079957] {CVE-2026-100070}
- drm/tve200: add OF module alias for autoloading (Can Peng)
- leds: pca9532: Fix phantom device registration on missing hardware (Cosmo Chou)
- PM: hibernate: Fix memory leak in snapshot_write_next() error path (Malaya Kumar Rout)
- RDMA/erdma: complete object teardown when the destroy command fails (Leon Romanovsky)
- RDMA/erdma: Support non-sleeping erdma_post_cmd_wait() (Boshi Yu)
- RDMA/erdma: Fix incorrect response returned from query_qp (Boshi Yu)
- RDMA/erdma: Add the query_qp command to the cmdq (Boshi Yu)
- RDMA/erdma: Refactor the code of the modify_qp interface (Boshi Yu)
- RDMA/erdma: Add erdma_modify_qp_rocev2() interface (Boshi Yu)
- RDMA/erdma: Add address handle implementation (Boshi Yu)
- RDMA/erdma: Add the erdma_query_pkey() interface (Boshi Yu)
- RDMA/erdma: Add GID table management interfaces (Boshi Yu)
- RDMA/erdma: Probe the erdma RoCEv2 device (Boshi Yu)
- xfrm: Fix skb double-free in xfrm_dev_direct_output() (Sanghyun Park) [Orabug: 40042619] {CVE-2026-92489}
- perf cs-etm: Avoid truncating AUX buffer sizes to int (Leo Yan)
- perf cs-etm: Flush thread stacks after decoder reset (Leo Yan)
- firmware: arm_scmi: Unrequest devices if driver registration fails (Sudeep Holla)
- firmware: arm_scmi: Roll back partial protocol table registration (Sudeep Holla)
- cpufreq/amd-pstate: Toggle auto_sel in active mode on shared memory systems (Marco Scardovi)
- ARM: dts: allwinner: a10: Fix PMU interrupt (Andre Przywara)
- ext4: check dir entry fits before reading the hash trailer in ext4_search_dir() (Xiang Mei) [Orabug: 40033089] {CVE-2026-89787}
- ext4: fix buffer_head leak in ext4_init_orphan_info (Guanghui Yang) [Orabug: 40042630] {CVE-2026-92494}
- RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap (Selvin Xavier) [Orabug: 40042633] {CVE-2026-92495}
- wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() (Jeff Johnson) [Orabug: 40042635] {CVE-2026-92496}
- wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() (Jeff Johnson) [Orabug: 40042638] {CVE-2026-92497}
- wifi: ath11k: Correctly copy the hint BSSID in WMI scan request (Jeff Johnson)
- wifi: ath12k: Correctly copy the hint BSSID in WMI scan request (Jeff Johnson)
- wifi: ath6kl: avoid buffer overreads in WMI event handlers (Jeff Johnson) [Orabug: 40042640] {CVE-2026-92498}
- ext4: drain in-flight DIO before buffered write fallback (Baokun Li) [Orabug: 40042652] {CVE-2026-92501}
- ext4: clear stale xarray tags on folios skipped during writeback (Gerald Yang) [Orabug: 40042656] {CVE-2026-92502}
- thermal: intel: int3400: clean up ODVP on probe failures (Pengpeng Hou) [Orabug: 40042660] {CVE-2026-92504}
- iommu/qcom: Fix inverted fault report check in qcom_iommu_fault() (Mukesh Ojha)
- iommu/qcom: Remove sysfs device on probe failure path (Haoxiang Li)
- firmware: arm_scmi: Fix requested device removal race (Sudeep Holla)
- RDMA/core: Fix potential use after free in ib_dealloc_pd_user() (Patrisious Haddad) [Orabug: 40042667] {CVE-2026-92507}
- RDMA/core: Fix potential use after free in ib_free_cq() (Patrisious Haddad) [Orabug: 40042670] {CVE-2026-92508}
- RDMA/core: Fix potential use after free in counter_release() (Patrisious Haddad) [Orabug: 40042675] {CVE-2026-92509}
- RDMA/core: Fix potential use after free in ib_destroy_srq_user() (Patrisious Haddad) [Orabug: 40042679] {CVE-2026-92510}
- RDMA/core: Fix potential use after free in ib_destroy_cq_user() (Patrisious Haddad) [Orabug: 40042683] {CVE-2026-92511}
- RDMA/core: Fix use after free in ib_query_qp() (Patrisious Haddad) [Orabug: 40042690] {CVE-2026-92512}
- RDMA/core: Add rdma_restrack_begin/abort/commit_del() operations (Patrisious Haddad)
- RDMA/erdma: Fix CEQ tasklet use-after-free on removal (Myeonghun Pak)
- PCI: j721e: Fix incorrect max_lanes for J7200 (Takuma Fujiwara)
- RDMA/srpt: Pass the mapped task attribute to target_init_cmd() (Leon Romanovsky)
- bpf: Preserve unique-field state across nested structs (Kumar Kartikeya Dwivedi) [Orabug: 40042698] {CVE-2026-92515}
- ACPI: battery: Adjust charging status validation check (Rafael J. Wysocki)
- riscv, bpf: Fix memory leak in bpf_jit_free (Pu Lehui)
- libbpf: Search /lib64 and /lib in resolve_full_path() (Ricardo B. Marlière)
- ext4: skip extra isize expansion during mount to prevent deadlock (Yun Zhou) [Orabug: 40072873] {CVE-2026-93268}
- ext4: fix out-of-bounds read in ext4_read_inline_dir() (Xiang Mei) [Orabug: 40033082] {CVE-2026-89786}
- ext4: fix circular lock dependency in ext4_ext_migrate (Yun Zhou) [Orabug: 40072879] {CVE-2026-93269}
- ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root (Chen Pei) [Orabug: 40042713] {CVE-2026-92521}
- ACPI: processor: validate MADT IOAPIC entry bounds (Pengpeng Hou) [Orabug: 40042718] {CVE-2026-92522}
- ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer (Zhu Ling)
- RDMA/nldev: validate dynamic counter attribute length (Pengpeng Hou) [Orabug: 40042724] {CVE-2026-92523}
- irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc() (Kemeng Shi) [Orabug: 40042728] {CVE-2026-92524}
- selftests/bpf: Silence array bounds warning in global_map_resize (Viktor Malik)
- arm64: dts: imx8-ss-audio: Fix LPCG clock indices for ASRC0 (Frank Li)
- kcsan: avoid unintended access checking in NMIs (Marco Elver)
- RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters (Zheng Tan) [Orabug: 40079979] {CVE-2026-100075}
- RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[] (Ibrahim Hashimov) [Orabug: 40042732] {CVE-2026-92525}
- RDMA/hfi1: Propagate sdma_txinit_ahg() errors (Danila Chernetsov) [Orabug: 40042738] {CVE-2026-93037}
- arm64: dts: amlogic: meson-axg-s400: enable mipi_pcie_analog_dphy for PCIe (Yan Jun)
- arm64: dts: amlogic: meson-axg: Add missing nand_rb0 pin to nand_all_pins (Yan Jun)
- phy: starfive: Fix runtime PM cleanup in JH7110 DPHY RX probe (Can Peng)
- phy: starfive: Fix runtime PM cleanup in JH7110 DPHY TX probe (Can Peng)
- ASoC: meson: Keep link pointers valid on realloc failure (Linmao Li) [Orabug: 40042744] {CVE-2026-93039}
- dmaengine: dw-edma: Clear stale requests on termination (Koichiro Den)
- dmaengine: dw-edma: Serialize channel state checks (Koichiro Den)
- dmaengine: dw-edma: Serialize abort state updates (Koichiro Den)
- dmaengine: dw-edma: Terminate all descriptors without callbacks (Koichiro Den)
- bpf: Reject arena frees below the arena base (Yiyang Chen) [Orabug: 40042768] {CVE-2026-93045}
- drm/msm/a6xx: Fix RBBM_CLOCK_CNTL3_TP0 value in a730_hwcg (Puranam V G Tejaswi)
- driver core: soc: Unregister bus on early device registration failure (Yuho Choi)
- software node: Fix software_node_get_reference_args() with index -1 (Alban Bedel) [Orabug: 40042771] {CVE-2026-93046}
- perf ui hists: Fix uninitialized stack memory free on pstack allocation failure (Ian Rogers)
- mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() (Zhouminqiang) [Orabug: 40042781] {CVE-2026-93048}
- mtd: mtdswap: Avoid freeing registered blktrans device twice (Ruoyu Wang) [Orabug: 40042802] {CVE-2026-93049}
- vfio/pci: clear vdev->msi_perm after freeing it on init failure (Xiang Mei) [Orabug: 40033019] {CVE-2026-89777}
- char: xilinx_hwicap: unregister class on init errors (Myeonghun Pak)
- ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove (Pei Xiao)
- ppdev: prevent overflow when setting port timeout (Linmao Li)
- cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64) (Breno Leitao)
- misc: ad525x_dpot: use driver core groups for sysfs files (Pengpeng Hou) [Orabug: 40042817] {CVE-2026-93051}
- misc: rtsx: add missing write register handling (Gleb Markov)
- misc: bcm-vk: Use acquire/release for msgq_inited (Gui-Dong Han)
- speakup: keyhelp: guard letter_offsets possible out-of-range indexing (Pavel Zhigulin) [Orabug: 40042827] {CVE-2026-93053}
- accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() (Christophe Jaillet)
- uio: Fix stale info pointer in failed registration path (Yuho Choi) [Orabug: 40042832] {CVE-2026-93054}
- UDF symlink pathComponent header OOB read (David Lee) [Orabug: 40042840] {CVE-2026-93055}
- tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 (Karl Mehltretter)
- usb: gadget: f_uac1_legacy: remove broken string configfs attributes (Xu Yang) [Orabug: 40042848] {CVE-2026-93056}
- ACPI: processor: idle: Expand _LPI package sanity checks (Rafael J. Wysocki)
- crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping (Thorsten Blum)
- drm/msm/a6xx: Fix stale rpmh votes after suspend (Shivam Rawat)
- gpu: host1x: Avoid stack over-read in debug output helpers (Mikko Perttunen) [Orabug: 40042864] {CVE-2026-93061}
- gpu: host1x: Fix offset calculation in trace_write_gather (Mikko Perttunen)
- wifi: iwlwifi: mei: pass correct argument to function (Avraham Stern)
- wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments (Emmanuel Grumbach) [Orabug: 40042869] {CVE-2026-93062}
- wifi: iwlwifi: mei: check SAP message length before reading it (Avraham Stern)
- wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser (Emmanuel Grumbach) [Orabug: 40042876] {CVE-2026-93064}
- wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs (Emmanuel Grumbach) [Orabug: 40042878] {CVE-2026-93065}
- perf jevents: Add more components to the metric sorting order (Ian Rogers)
- arm64: dts: qcom: sm8250: correct frequencies in the Iris OPP table (Dmitry Baryshkov)
- arm64: dts: qcom: sm8250: sort out Iris power domains (Dmitry Baryshkov)
- arm64: dts: qcom: sc8280xp-x13s: Fix the drive-strength of mclk pin (Pengyu Luo)
- arm64: dts: qcom: msm8996-xiaomi-gemini: Fix up ti,drv2604 enable GPIO (Konrad Dybcio)
- drm/bridge: tc358767: clamp the reported AUX read size to the request (Maoyi Xie) [Orabug: 40042883] {CVE-2026-93067}
- remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev (Uday Khare)
- cpufreq: schedutil: Fix self-contradictory comment in sugov_iowait_apply() (Zhongqiu Han)
- cpufreq: intel_pstate: Fix setting minimum P-state at init time (Rafael J. Wysocki)
- drm/amd/display: Remove unused-but-set variable hubp from (Gleb Markov)
- media: ipu6: Do not free aux device pdata after init (Ruoyu Wang) [Orabug: 40042892] {CVE-2026-93070}
- media: bcm2835-unicam: Fix asc leaked in error/remove path (Eugen Hristev)
- media: i2c: rdacm21: Fix missing media_entity_cleanup() (Biren Pandya)
- irqchip/renesas-irqc: Fix generic interrupt chip leak on remove (Qingshuang Fu)
- PCI: xgene: Drop unnecessary OF node reference (Yuho Choi)
- PCI: xgene: Drop XGENE_PCIE_IP_VER_UNKN (Marc Zyngier)
- cpufreq: spear: Fix an IS_ERR() vs NULL bug in spear1340_set_cpu_rate() (Dan Carpenter)
- dax: read holder_ops once in dax_holder_notify_failure() (John Groves) [Orabug: 40042905] {CVE-2026-93073}
- libnvdimm/labels: Bound the on-media label size before the shift (Bryam Vargas)
- firmware: arm_scmi: Unwind P2A receiver mailbox setup failure (Sudeep Holla)
- firmware: arm_scmi: Unwind TX receiver mailbox setup failure (Sudeep Holla)
- firmware: arm_scmi: Drop handle on protocol bind failures (Sudeep Holla)
- firmware: arm_scmi: Protect device request lookup with RCU (Sudeep Holla)
- firmware: arm_scmi: Use channel ID for transport teardown (Sudeep Holla)
- firmware: arm_scmi: Reject out of range DT protocol IDs (Sudeep Holla)
- firmware: arm_scmi: Avoid IDR updates while cleaning channels (Sudeep Holla)
- firmware: arm_scmi: Free transport channel on IDR failure (Sudeep Holla)
- firmware: arm_scmi: Clean up channels on setup failure (Sudeep Holla)
- firmware: arm_scmi: Quiesce notifications before teardown (Sudeep Holla)
- firmware: arm_scmi: Unregister device notifier before IDR teardown (Sudeep Holla)
- firmware: arm_scmi: Publish channel state before callbacks (Sudeep Holla) [Orabug: 40042953] {CVE-2026-93093}
- x86/entry/fred: Encode frame pointer on entry (David Stevens)
- wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate (Baochen Qiang) [Orabug: 40072893] {CVE-2026-93271}
- hfsplus: validate thread record before delete key rebuild (Kyle Zeng)
- fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() (He Wei)
- fs/ntfs3: fix KMSAN uninit-value in ni_create_attr_list (Nirbhay Sharma)
- fs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr() (Konstantin Komarov)
- fs/ntfs3: Add more checks in mi_enum_attr (part 2) (Konstantin Komarov)
- cxl/pci: Honor -EPROBE_DEFER from component register setup (Dave Jiang)
- cxl/mbox: Break poison list loop on an empty payload (Dave Jiang) [Orabug: 40042965] {CVE-2026-93097}
- cxl/memdev: Fix firmware upload exact-fit handling (Guzebing)
- rpmsg: glink: fix deadlock in endpoint destroy during driver detach (Vishnu Santhosh) [Orabug: 40043408] {CVE-2026-93098}
- rpmsg: glink: remove duplicate code for rpmsg device remove (Srinivas Kandagatla)
- media: v4l2-async: Unregister sub-device if asc_list is empty (Hans Verkuil) [Orabug: 40042980] {CVE-2026-93101}
- iommufd/selftest: Avoid selftest dirty bitmap size wrap (Samuel Moelius)
- isofs: fix out-of-bounds page array access on empty zisofs block (Xiang Mei) [Orabug: 40033028] {CVE-2026-89778}
- ASoC: apple: mca: increase SERDES reset delay (James Calligeros)
- RDMA/hfi1: Initialize debugfs after probe completes (Leon Romanovsky)
- RDMA/hfi1: Stop flushing the global IB workqueue (Leon Romanovsky)
- RDMA/hfi1: Create workqueues before device initialization (Leon Romanovsky)
- RDMA/hfi1: Remove redundant PCI device ID validation (Leon Romanovsky)
- RDMA/hfi1: Free RX data on late probe failure (Leon Romanovsky) [Orabug: 40042982] {CVE-2026-93102}
- RDMA/hfi1: Preserve unit 0 on allocation failure (Leon Romanovsky) [Orabug: 40042986] {CVE-2026-93103}
- misc: rtsx_usb: avoid USB I/O in runtime autosuspend (Sean Rhodes)
- pmdomain: bcm: bcm2835: handle genpd provider registration errors (Pengpeng Hou)
- ALSA: hpi: Check transport errors during HPI6000 adapter initialization (Evgenii Burenchev)
- xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full (Xiang Mei) [Orabug: 40033062] {CVE-2026-89783}
- hwrng: ks-sa - Fix runtime PM cleanup on registration failure (Yuho Choi)
- crypto: ccp - Fix memory leak in SEV INIT_EX path (Atish Patra)
- RDMA/rxe: Avoid reprocessing the current packet after the QP enters the error state (Allison Henderson) [Orabug: 40043004] {CVE-2026-93107}
- RDMA/ipoib: Drain RCU callbacks during module teardown (Leon Romanovsky) [Orabug: 40043008] {CVE-2026-93108}
- RDMA/mlx5: Drain RCU callbacks during module teardown (Leon Romanovsky) [Orabug: 40043014] {CVE-2026-93109}
- RDMA/core: Wait for RCU callbacks before unloading ib_core (Leon Romanovsky) [Orabug: 40043021] {CVE-2026-93110}
- iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE (Mert Seftali)
- clk: qcom: camcc-sc8280xp: unregister CAMCC_GDSC_CLK (Brian Masney)
- bus: qcom-ebi2: use managed resources for clocks and children (Pengpeng Hou)
- soc: qcom: rpmh-rsc: manage PM notifiers with devres (Pengpeng Hou)
- perf metricgroup: Fix metric expression copy leaks (Yu Peng)
- drm/panel: samsung-s6d16d0: Power off on prepare failure (Laxman Acharya Padhya)
- usb: renesas_usbhs: Fix power-off ordering on unbind (Biju Das)
- usb: mtu3: allow system suspend during active gadget connection (Fei Shao)
- platform/surface: acpi-notify: Check ACPI companion before use (Linmao Li)
- platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL (Linmao Li)
- usb: fix UAF when probe runs concurrent to dyn ID removal (Gary Guo) [Orabug: 40043047] {CVE-2026-93117}
- USB: make to_usb_driver() use container_of_const() (Greg Kroah-Hartman)
- USB: make single lock for all usb dynamic id lists (Greg Kroah-Hartman)
- usb: gadget: aspeed_udc: check endpoint DMA allocation (Ruoyu Wang)
- usb: ljca: bound bank_num in ljca_enumerate_gpio() (Maoyi Xie) [Orabug: 40043056] {CVE-2026-93119}
- usb: gadget: configfs: fix out-of-bounds read of qw_sign (Michael Bommarito)
- usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths (Nuno Sa)
- serial: qcom-geni: do not advance stale DMA completions (Guangshuo Li)
- serial: ma35d1: Fix OF node reference leaks in console init (Yuho Choi)
- selftests/sched_ext: Fix bpf_link leak on early return in prog_run (Liang Luo)
- hwspinlock: propagate errno when registering single lock (Wolfram Sang)
- remoteproc: qcom_q6v5_adsp: Fix reference leak for device node (Felix Gu)
- platform/x86: lg-laptop: Fix LED resource handling (Armin Wolf)
- platform/x86: lg-laptop: Convert ACPI driver to a platform one (Rafael J. Wysocki)
- platform/x86: lg-laptop: Drop debug-only ACPI notify handler (Rafael J. Wysocki)
- platform/x86: dell-wmi-base: Fix resource leak on module load failure (Armin Wolf) [Orabug: 40043088] {CVE-2026-93130}
- platform/x86: dell-privacy: Fix race condition (Armin Wolf)
- ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling (Lorenzo Pieralisi)
- ACPI: RISC-V: Check acpi_get_handle() status in riscv_acpi_add_prt_dep() (Lorenzo Pieralisi)
- ACPI: RISC-V: Fix riscv_acpi_irq_get_dep() loop termination (Lorenzo Pieralisi)
- panic/printk: replace other_cpu_in_panic() with panic_on_other_cpu() (Wang Jinchao)
- panic/printk: replace this_cpu_in_panic() with panic_on_this_cpu() (Wang Jinchao)
- panic: introduce helper functions for panic state (Wang Jinchao)
- printk/panic: Add option to allow non-panic CPUs to write to the ring buffer. (Donghyeok Choe)
- leds: pca9532: Fix inverted GPIO output polarity (Cosmo Chou)
- iommu/amd: Fix false positive in SB IOAPIC IVRS validation (Wei Wang)
- iommu/amd: Add support for Hygon family 18h model 4h IOAPIC (Fu Hao)
- iommu/amd: Prevent SB IOAPIC from overriding IVRS validation errors (Wei Wang)
- iommu/msm: Return -ENOMEM on memory allocation failure in probe (Vladimir Zapolskiy)
- iommu/mediatek-v1: Fix off-by-one in MT2701_LARB_NR_MAX (Akari Tsuyukusa)
- bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation (Yuho Choi)
- bpf: Fix use-after-free on mm_struct in bpf_find_vma() (Sanghyun Park) [Orabug: 40043111] {CVE-2026-93137}
- efi: fix stale reference to efi_recover_from_page_fault() (Breno Leitao)
- bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux (Daniel Borkmann) [Orabug: 40043114] {CVE-2026-93138}
- perf dso: Fix kallsyms DSO detection with fallback logic (Tanushree Shah)
- perf vendor events amd: Reintroduce deprecated Zen 5 core events (Sandipan Das)
- udf: Mark LVID buffer as uptodate before marking it dirty (Aleksandr Nogikh) [Orabug: 40043120] {CVE-2026-93140}
- usb: gadget: r8a66597: avoid double free of ep0_req in probe error path (Hongyan Xu)
- usb: typec: ucsi: unregister debugfs entries on teardown (Bjorn Andersson) [Orabug: 40079995] {CVE-2026-100079}
- thermal/drivers/rcar: Fix error checking in probe() (Dan Carpenter)
- perf data convert json: Fix trace_seq memory leak in process_sample_event() (Tanushree Shah)
- arm64: dts: qcom: sc8180x-lenovo-flex-5g: Describe the display power net (Konrad Dybcio)
- arm64: dts: qcom: sc8180x-lenovo-flex-5g: Rename regulator nodes (Konrad Dybcio)
- arm64: dts: qcom: sc8180x-primus: Describe the display power net (Konrad Dybcio)
- arm64: dts: qcom: sc8180x-primus: Rename regulator nodes (Konrad Dybcio)
- clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister() (Herman van Hazendonk) [Orabug: 40043146] {CVE-2026-93145}
- clk: qcom: gdsc: propagate gdsc_enable() failure for ALWAYS_ON domains (Herman van Hazendonk)
- clk: qcom: gdsc: propagate gdsc_check_status() errors from gdsc_poll_status (Herman van Hazendonk)
- timekeeping: Account for monotonicity adjustment in ntp_error (David Woodhouse)
- y2038: uapi: Use 64-bit __kernel_old_timespec::tv_nsec on x32 (Thomas Weißschuh)
- clocksource: Unregister subsystem on device registration failure (Yuho Choi)
- selftests: timers: leap-a-day: Fix -w option and update usage comment (Jiangshan Yi)
- irqchip/gic-v3-its: Fix its node leak in gic_acpi_parse_madt_its() (Kemeng Shi)
- irqchip/gic-v3-its: Fix memleak in its_probe_one() (Kemeng Shi)
- selftests/lsm: Fix memory leak in attr_lsm_count (Wang Yan)
- selftests/bpf: Fix memory leak in msg_alloc_iov (Feng Yang)
- selftests/bpf: Fix memory leak in msg_alloc_iov error path (Malaya Kumar Rout)
- ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() (Evgenii Burenchev)
- staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() (Dawei Feng)
- staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown (Ayush Mukkanwar)
- staging: octeon: replace pr_warn with dev_warn in fill and rx paths (Ayush Mukkanwar)
- staging: octeon: ethernet-mem: replace pr_warn with dev_warn in free functions (Ayush Mukkanwar)
- staging: octeon: fix free_irq dev_id mismatch in cvm_oct_rx_shutdown (Yuvraj Singh Chauhan)
- staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown (Ayush Mukkanwar)
- staging: fbtft: Use sysfs_emit_at() to print to sysfs file (Dan Carpenter)
- greybus: audio: bound the topology section sizes against the fetched size (Bryam Vargas)
- staging: sm750fb: Add missing Kconfig dependency (Rongrong)
- staging: sm750fb: gate dualview dataflow using g_dualview (Ahmet Sezgin Duran)
- staging: greybus: audio: correct sscanf() return value check (Alexander A. Klimov)
- wifi: mac80211_hwsim: avoid NULL skb in stop queue drain (Cen Zhang) [Orabug: 40043162] {CVE-2026-93149}
- bus: qcom-ebi2: Fix clock leak on probe failure (Ruoyu Wang)
- bus: qcom-ebi2: Simplify with scoped for each OF child loop (Krzysztof Kozlowski)
- arm64: dts: qcom: hamoa: Fix clocks for HSPHYs (Konrad Dybcio)
- arm64: dts: qcom: sm7225-fairphone-fp4: Fix address in fb node name (Luca Weiss)
- cgroup/cpuset: Make nr_deadline_tasks an atomic_t (Waiman Long) [Orabug: 40043171] {CVE-2026-93150}
- PM: sleep: Fix off-by-one in wakelocks number limit check (Tuhaowen)
- bus: ti-sysc: Fix /chosen node reference leak (Yuho Choi)
- nvmet-rdma: fix response resource leak on queue teardown (Shin'Ichiro Kawasaki) [Orabug: 40043174] {CVE-2026-93151}
- nvmet-rdma: factor out response resource cleanup (Shin'Ichiro Kawasaki)
- nvme-apple: Use acquire/release for queue enabled state (Gui-Dong Han)
- crypto: keembay - Fix AEAD unregister count in error path (Myeonghun Pak)
- crypto: rk3288 - fail ahash requests on HASH idle timeout (Pengpeng Hou)
- crypto: sa2ul - stop probe if context pool creation fails (Pengpeng Hou)
- crypto: atmel-sha204a - fix heap info leak on I2C transfer failure (Lothar Rubusch)
- crypto: atmel-ecc - reject hardware ECDH without a public key (Thorsten Blum)
- crypto: atmel-ecc - clean up and improve ECDH comments (Thorsten Blum)
- crypto: atmel-ecc - replace min_t with min (Thorsten Blum)
- crypto: qat - clear AES key schedule from stack (Giovanni Cabiddu) [Orabug: 40043210] {CVE-2026-93161}
- crypto: qat - cancel work on re-enable SR-IOV timeout (Giovanni Cabiddu) [Orabug: 40043215] {CVE-2026-93162}
- hwrng: core - fix rng list on registration error (Manos Pitsidianakis) [Orabug: 40043217] {CVE-2026-93163}
- perf vendor events amd: Update Zen 5 core events (Sandipan Das)
- perf/x86/amd/uncore: Add group validation (Sandipan Das)
- perf cs-etm: Fix thread leaks on trace queue init failure (Leo Yan)
- perf cs-etm: Queue context packets for frontend (James Clark)
- wifi: rtw89: fix HE extended capability length check (Pengpeng Hou) [Orabug: 40073017] {CVE-2026-93281}
- platform/chrome: sensorhub: Fix memory overread in ring handler (Tzung-Bi Shih) [Orabug: 40043223] {CVE-2026-93165}
- selftests/rseq: Replace glibc-specific __GNUC_PREREQ with portable check (Hisam Mehboob)
- csky: Fix a4/a5 restoration in syscall trace path (Hanlin Song)
- iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure (Sanjay Chitroda)
- soundwire: qcom: Fix port exhaustion check in stream_alloc_ports (Srinivas Kandagatla)
- dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe (Vladimir Zapolskiy)
- dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers (Suraj Gupta)
- dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure (Vladimir Zapolskiy)
- mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug (Gregory Price) [Orabug: 40043241] {CVE-2026-93172}
- mm: name the anonymous MMOP enum as enum mmop (Gregory Price)
- mm: change type of state in struct memory_block (Israel Batista)
- mm: convert memory block states (MEM_*) macros to enum (Israel Batista)
- mm: add build-time option for hotplug memory default online type (Gregory Price)
- bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks (Sechang Lim) [Orabug: 40043245] {CVE-2026-93173}
- selftests/bpf: Mask socket type flags in mptcpify prog (Guillaume Maudoux)
- selftests/bpf: Systematically add SO_REUSEADDR in start_server_addr (Alexis Lothoré)
- bpf: Copy per-CPU map value padding in copy_map_value_long() (Leon Hwang) [Orabug: 40043250] {CVE-2026-93174}
- tools/bpf/bpftool: Reset vmlinux BTF after struct_ops commands (Chenyichong)
- tools/bpf/bpftool: Reset vmlinux BTF after map commands (Chenyichong)
- drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup (Asad Kamal) [Orabug: 40043260] {CVE-2026-93177}
- drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup (Asad Kamal) [Orabug: 40043266] {CVE-2026-93178}
- regulator: tps6594: Fix device node reference leaks in multiphase loop (Uday Khare)
- regulator: tps6594-regulator: refactor variant descriptions (Michael Walle)
- regulator: tps6594-regulator: remove hardcoded buck config (Michael Walle)
- regulator: tps6594-regulator: remove interrupt_count (Michael Walle)
- regulator: tps6594-regulator: Constify struct tps6594_regulator_irq_type (Christophe Jaillet)
- perf tests: Fix flakiness in branch stack sampling tests (Ian Rogers)
- perf test: Fixes for check branch stack sampling (Ian Rogers)
- perf test: Extend branch stack sampling test for Arm64 BRBE (James Clark)
- perf test: Add syscall and address tests to brstack test (James Clark)
- perf test: Refactor brstack test (James Clark)
- perf tests: Harden branch stack sampling test (Ian Rogers)
- perf test brstack: Speed up running test by using tr -s instead of xargs (James Clark)
- perf tests: Fix flakiness in BPF counters test on hybrid systems (Ian Rogers)
- perf test: Fix perf stat --bpf-counters on hybrid machines (Namhyung Kim)
- perf test: Use sqrtloop workload to test bperf event (Tengda Wu)
- perf tests: Skip metrics validation if system-wide recording lacks permission (Ian Rogers)
- perf test: Do not skip when some metrics tests succeeded (Namhyung Kim)
- perf test all metrics: Fully ignore Default metric failures (Ian Rogers)
- perf test metrics: Update all metrics for possibly failing default metrics (Ian Rogers)
- perf tests metrics: Permission related fixes (Ian Rogers)
- perf test stat_all_metrics: Ensure missing events fail test (Ian Rogers)
- perf test: Update all metrics test like metricgroups test (Namhyung Kim)
- media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define (Sean Young)
- media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define (Sean Young)
- riscv: kexec_file: Fix crashk_low_res not exclude bug (Jinjie Ruan)
- riscv: kexec_file: Split the loading of kernel and others (Song Shuai)
- pinctrl: bcm2835: Don't remove an unregistered GPIO chip (Daniel Mccarthy) [Orabug: 40072906] {CVE-2026-93274}
- perf/x86/intel/uncore: Keep PCI PMUs working when MMIO/MSR setup fails (Zide Chen)
- sched/fair: Fix overflow in update_tg_cfs_runnable() (Chen Yu) [Orabug: 40043282] {CVE-2026-93182}
- mm/mm_init: fix incorrect node_spanned_pages (Wei Yang)
- drm/lima: call drm_mm_init() with a valid allocation range (Henrik Grimler)
- clk: imx: scu: drop redundant init.ops variable assignment (Brian Masney)
- arm64: dts: imx93-kontron: set memory node to 0x80000000/1GiB (Frieder Schrempf)
- ARM: imx: fix device_node refcount leaks in imx7_src_init() (Weigang He)
- ARM: imx: fix device_node refcount leak in imx_src_init() (Weigang He)
- clk: hisilicon: reset: Use devm_kzalloc to initialize hisi_reset_controller (Min Zhang)
- ASoC: fsl_audmix: rework runtime PM handling in probe (Shengjiu Wang)
- ASoC: rt700-sdw: always drain jack work on remove (Runyu Xiao) [Orabug: 40043294] {CVE-2026-93185}
- clk: nuvoton: ma35d1: fix ma35d1_clk_pll_determine_rate logic (Joey Lu)
- clk: nuvoton: ma35d1-pll: convert from round_rate() to determine_rate() (Brian Masney)
- clk: nuvoton: ma35d1: fix PLL_CTL1_FRAC bit field width and fractional calc (Joey Lu)
- clk: nuvoton: ma35d1: fix ignored div_u64 return values in PLL freq calculation (Joey Lu)
- clk: moxart: remove unused variables, fix refcount leak (Alexander A. Klimov)
- clk: versaclock7: Fix APLL clock leak on probe failure (Myeonghun Pak)
- cxl/pci: Remove incorrect mbox.valid check in cxl_pci_type3_init_mailbox() (Wei Hou)
- cxl/mbox: Clamp mailbox output allocation to the payload size (Richard Cheng) [Orabug: 40043297] {CVE-2026-93186}
- media: cec-pin: Fix event FIFO ordering (Gui-Dong Han)
- soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() (Weigang He)
- HID: roccat: bound device-supplied profile index (Michael Bommarito) [Orabug: 40043301] {CVE-2026-93188}
- HID: nintendo: Fix imu_timestamp_us double increment per report (Christos Maragkos)
- HID: core: quiesce input in hid_hw_stop() to prevent use-after-free (Philipp Weber) [Orabug: 40043305] {CVE-2026-93189}
- platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count (Maoyi Xie) [Orabug: 40043309] {CVE-2026-93190}
- x86/cfi: Use symmetric SYM_START and SYM_END in __CFI_TYPE() (Jens Remus)
- sched_ext/scx_flatcg: Fix cvtime_delta race and add hweight scaling to bypass charging (Wanwu Li)
- smack: restrict smackfs/{direct,mapped} values to 0-255 (Konstantin Andreev)
- smack: deduplicate smackfs/{direct,mapped} file_operations (Konstantin Andreev)
- smack: simplify write handlers of sysfs entries (Dmitry Antipov)
- smack: fix incorrect task context in smack_msg_queue_msgrcv (Konstantin Andreev)
- drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure (Maxime Ripard)
- drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format (Nicolas Frattaroli)
- drm/v3d: Clear queue->active_job when v3d_fence_create() fails (Maíra Canal)
- drm/v3d: Replace a global spinlock with a per-queue spinlock (Maíra Canal)
- drm: lcdif: Wait for vblank before disabling DMA (Paul Kocialkowski)
- drm: Remove unused header in drm_dumb_buffers.c (Yicong Hui)
- Smack: Fix error in capability bypass (Casey Schaufler)
- mm/damon/core: skip aging from repeated aggressive merging (Seongjae Park)
- batman-adv: fix TX priority extraction for BATADV_FORW_MCAST (Sven Eckelmann)
- clk: meson: align gxbb_32k_clk_sel number of parents with actual count (Martin Blumenstingl) [Orabug: 40033895] {CVE-2026-89947}
- perf sched: Fix register_pid() overflow, strcpy, and BUG_ON (Arnaldo Carvalho de Melo)
- batman-adv: bla: avoid CRC corruption due to parallel claim add (Sven Eckelmann) [Orabug: 40043346] {CVE-2026-93203}
- batman-adv: dat: atomically update mac addresses (Sven Eckelmann) [Orabug: 40043351] {CVE-2026-93204}
- ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE (Sean Shen)
- ksmbd: fix durable reconnect error path file lifetime (Junyi Liu)
- ksmbd: fix use-after-free in smb2_open during durable reconnect (Akif Sait)
- of: unittest: Fix memory leak in unittest_data_add() (Zilin Guan)
- mm/damon/tests/core-kunit: catch test failure in test_merge_regions_of() (Seongjae Park)
- mm/damon/core-kunit: handle region split failure in filter_out() (Seongjae Park)
- mm/damon/vaddr-kunit: check region count in three_regions test (Seongjae Park)
- mm/damon/paddr: drop last same folio access check reuse optimization (Seongjae Park)
- mm/damon/ops-common: use nr_accesses moving sum for quota score (Seongjae Park)
- mm/damon/vaddr: drop last same folio access check optimization (Seongjae Park)
- nvmet-auth: Synchronize timeout work during SQ teardown (Kazuki Hanai) [Orabug: 40033982] {CVE-2026-89970}
- net/mlx5e: xsk: Fix unlocked writing to ICOSQ (Dragos Tatulea) [Orabug: 39785088] {CVE-2026-64210}
- ksmbd: zero pipe read compound padding (Namjae Jeon)
- xhci: fix lost bounce buffers on TDs spanning several ring segments (Arthur Gautier) [Orabug: 40034133] {CVE-2026-90015}
- afs: Fix leak of ungot volume (David Howells) [Orabug: 39982279] {CVE-2026-80878}
- drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE (Zhenhao Wan) [Orabug: 40033166] {CVE-2026-89800}
- drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE (Zhenhao Wan) [Orabug: 40033173] {CVE-2026-89801}
- drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op (Zhenhao Wan) [Orabug: 40033176] {CVE-2026-89802}
- drm/nouveau: Use write-combined maps for coherent (Faith Ekstrand)
- drm/nouveau: unsubscribe the channel-kill event before the fence context (Marek Czernohous) [Orabug: 40033181] {CVE-2026-89803}
- drm/amdkfd: Reject zero-sized AQL queue allocations after size halving (Sunday Clement)
- drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore (Vladimir Marioukhine) [Orabug: 40033196] {CVE-2026-89807}
- drm/amdgpu: use AMDGPU_GPU_PAGE_SHIFT instead of PAGE_SHIFT (Sunil Khatri)
- drm/amdgpu: Skip accessing psp rum time db for APUs (Kanala Ramalingeswara Reddy)
- drm/amdgpu: fix autosuspend cleanup during removal (Guangshuo Li)
- drm/amdgpu: check thunderbolt before switcheroo registration (Yang Wang)
- drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used (Thadeu Lima de Souza Cascardo) [Orabug: 40033273] {CVE-2026-89816}
- drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value (Kavan Smith)
- drm/gud: validate TV mode names before creating enum property (Tao Yu) [Orabug: 40072728] {CVE-2026-93234}
- drm/gud: NUL-terminate TV mode names read from the device (Deepanshu Kartikey) [Orabug: 40033281] {CVE-2026-89817}
- drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check (David (Ming Qiang) Wu) [Orabug: 40034374] {CVE-2026-89818}
- drm/amd/display: validate plane degamma LUT size for private color prop (Harry Wentland) [Orabug: 40033287] {CVE-2026-89819}
- drm/amd/display: avoid divide-by-zero in __is_lut_linear() (Harry Wentland) [Orabug: 40033293] {CVE-2026-89821}
- drm/hibmc: Use drm_atomic_helper_check_plane_state() (Thomas Zimmermann)
- drm/hibmc: Fix list of formats on the primary plane (Thomas Zimmermann)
- drm/ssd130x: fix column and row end address in partial updates in ssd133x (Amit Barzilai)
- drm/sun4i: fix refcount leak in sun4i_backend_init_sat() (Xu Wang)
- drm/ssd130x: fix column and row end address in partial updates for ssd132x (Amit Barzilai)
- drm/i915: Guard against NULL driver_data in i915_pci_probe() (Deepanshu Kartikey) [Orabug: 40033301] {CVE-2026-89822}
- drm: fix race between partial drm_dev_register() failure and ioctl (Danilo Krummrich) [Orabug: 40033312] {CVE-2026-89823}
- drm/panel-edp: fix i2c adapter leak on probe failure (Johan Hovold) [Orabug: 40033325] {CVE-2026-89824}
- drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure (Johan Hovold)
- drm/panthor: fix firmware control interface bounds checks (Osama Abdelkader)
- f2fs: fix to zero post-EOF data when extending file size (Chao Yu)
- f2fs: fix valid block count leak on data block allocation failure (Chenchangcheng)
- f2fs: fix to off-by-one issue in f2fs_zero_post_eof_page() (Chao Yu)
- f2fs: fix to migrate all curseg types during free_segment_range (Daeho Jeong)
- f2fs: avoid NULL checkpoint thread access in sysfs (Wenjie Qi)
- f2fs: return writeback error from collapse range (Wenjie Qi)
- f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set() (Zhan Xusheng)
- f2fs: reject overlapping move range after len expansion (Hao-Qun Huang)
- f2fs: return symlink writeback errors (Wenjie Qi)
- scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started (Nilesh Javali) [Orabug: 40033428] {CVE-2026-89842}
- scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak (Nilesh Javali) [Orabug: 40033433] {CVE-2026-89843}
- scsi: qla2xxx: Use coherent DMA buffer for D_Port diagnostics (Nilesh Javali)
- scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition (Nilesh Javali) [Orabug: 40033442] {CVE-2026-89844}
- scsi: qla2xxx: Drop vport reference under lock in report ID acquisition (Nilesh Javali)
- scsi: qla2xxx: Fix NVMe abort reference leak on repeated abort (Nilesh Javali)
- scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry() (Nilesh Javali) [Orabug: 40033449] {CVE-2026-89845}
- scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (Nilesh Javali) [Orabug: 40033454] {CVE-2026-89846}
- scsi: qla2xxx: Avoid double completion in async IOCB timeout (Nilesh Javali) [Orabug: 40033465] {CVE-2026-89847}
- scsi: qla2xxx: Quiesce response IRQ before freeing request queue (Nilesh Javali) [Orabug: 40033471] {CVE-2026-89848}
- scsi: qla2xxx: Fix response queue over-consumption in __qla_consume_iocb() (Nilesh Javali) [Orabug: 40072775] {CVE-2026-93242}
- scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path (Nilesh Javali) [Orabug: 40033477] {CVE-2026-89849}
- scsi: qla2xxx: Don't query firmware state while chip is down (Nilesh Javali) [Orabug: 40033482] {CVE-2026-89850}
- scsi: qla2xxx: Fix FCE trace enable parsing in debugfs (Nilesh Javali) [Orabug: 40033490] {CVE-2026-89851}
- scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state() (Nilesh Javali) [Orabug: 40033496] {CVE-2026-89852}
- scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump (Nilesh Javali) [Orabug: 40033504] {CVE-2026-89853}
- scsi: qla2xxx: Fix cs84xx use-after-free on host teardown (Nilesh Javali) [Orabug: 40033510] {CVE-2026-89854}
- scsi: qla2xxx: Serialize flash version read in reset handler (Nilesh Javali) [Orabug: 40033519] {CVE-2026-89855}
- scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation (Nilesh Javali) [Orabug: 40033523] {CVE-2026-89856}
- scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject (Nilesh Javali) [Orabug: 40033529] {CVE-2026-89857}
- scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions() (Nilesh Javali) [Orabug: 40033532] {CVE-2026-89858}
- scsi: qla2xxx: Check entry_status in qla24xx_modify_vp_config() (Nilesh Javali)
- scsi: qla2xxx: Initialize NVMe abort_work once at submission (Nilesh Javali) [Orabug: 40033541] {CVE-2026-89860}
- scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition() (Nilesh Javali) [Orabug: 40033546] {CVE-2026-89861}
- scsi: qla2xxx: Fix Name Server logout detection on FWI2 adapters (Nilesh Javali)
- scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check (Nilesh Javali) [Orabug: 40033553] {CVE-2026-89863}
- scsi: qla2xxx: Bound i2c->length in I2C bsg handlers (Nilesh Javali) [Orabug: 40033557] {CVE-2026-89864}
- scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers (Nilesh Javali) [Orabug: 40033561] {CVE-2026-89865}
- media: chips-media: wave5: Guard bit depth check with initial_info_obtained (Jackson Lee)
- media: zoran: Avoid freeing a registered video_device twice (Ruoyu Wang)
- media: vimc: fix pixel format lookup in enum_framesizes (Arash Golgol)
- media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure (Uday Khare)
- media: venus: fix payload size calculation in parse_raw_formats() (Mohammed El Kadiri)
- media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() (Mohammed El Kadiri)
- media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link (Biren Pandya) [Orabug: 40033583] {CVE-2026-89872}
- media: v4l2-ctrls: Allow unknown HDR10 white point and luminance (Ming Qian)
- media: v4l2-async: avoid deleting unlinked ASC entry on link error (Xu Rao) [Orabug: 40033590] {CVE-2026-89874}
- media: tda18250: fix possible integer overflow (Ilya Krutskih) [Orabug: 40033594] {CVE-2026-89876}
- media: saa7164: fix cleanup on resource allocation failure (Guangshuo Li) [Orabug: 40033603] {CVE-2026-89877}
- media: s2255: check firmware size before reading trailing marker (Huanglei) [Orabug: 40033609] {CVE-2026-89878}
- media: s2255: bound JPEG frame size before copying into the buffer (Hyeongjun An) [Orabug: 40033614] {CVE-2026-89879}
- media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure (Valery Borovsky) [Orabug: 40033619] {CVE-2026-89880}
- media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak (Valery Borovsky) [Orabug: 40033625] {CVE-2026-89881}
- media: rc: sunxi-cir: Unregister rc device on probe failure (Myeonghun Pak)
- media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks (Guoniu Zhou)
- media: nxp: imx8-isi: Correct color map between V4L2 and ISI (Guoniu Zhou)
- media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing (Guoniu Zhou)
- media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup (Johan Hovold)
- media: platform: mtk-mdp3: Fix SCP device refcounting (Guangshuo Li)
- media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common (Christian Hewitt)
- media: intel/ipu6: fix async notifier cleanup leak on parse error (Cong Nguyen) [Orabug: 40033642] {CVE-2026-89886}
- media: i2c: ov7740: fix use-after-destroy in remove (Biren Pandya)
- media: i2c: ov02a10: fix endpoint parsing use-after-free (Biren Pandya)
- media: i2c: imx415: Return test pattern write errors (Narasimharao Vadlamudi)
- media: i2c: alvium: Fix: Correct name of register in alvium_set_ctrl_auto_exposure (Martin Hecht)
- media: go7007: defer the ALSA v4l2 put until card release (Shuangpeng Bai) [Orabug: 40033655] {CVE-2026-89890}
- media: em28xx: fix use-after-free of dev_next->devlist on disconnect (Jiangong Han) [Orabug: 40033662] {CVE-2026-89891}
- media: em28xx: defer audio-only extension registration (Diego Fernando Mancera Gomez) [Orabug: 40033667] {CVE-2026-89892}
- media: cx23885: cancel NetUP CI work before teardown (Fan Wu) [Orabug: 40033672] {CVE-2026-89893}
- media: cx231xx: reject geometry changes while the VBI queue is busy (Bryam Vargas) [Orabug: 40033679] {CVE-2026-89894}
- media: cobalt: Avoid freeing ALSA private data twice (Ruoyu Wang)
- media: cedrus: fix memory leak in cedrus_init_ctrls() (Dawei Feng)
- media: cec: Serialize exclusive follower delivery (Ruoyu Wang) [Orabug: 40033696] {CVE-2026-89897}
- media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash (Yi Ding)
- media: cec: extron-da-hd-4k-plus: add sanity check (Hans Verkuil)
- media: cec: disable delayed work before freeing an interrupted transmit (Biren Pandya) [Orabug: 40033703] {CVE-2026-89899}
- media: amphion: Remove obsolete frame_count check in venc_start_session (Ming Qian)
- media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref (Valery Borovsky)
- LoongArch: Avoid preempt count underflow without probe (Jérémy Jean)
- LoongArch: Do not save/restore percpu base register in rethook trampoline (Guan Wentao)
- LoongArch: Do not select HAVE_RUST when KASAN is enabled (Nathan Chancellor)
- LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY (Zeng Chi)
- LoongArch: KVM: Free init resources if kvm_init() fails (Chaithanya Lagisetty)
- LoongArch: KVM: Fix TOCTOU race on pv_features (Tao Cui)
- KVM: s390: Restore sigset on error path (Christian Borntraeger)
- KVM: s390: pv: Fix rc/rrc offset for PVM_DUMP (Christian Borntraeger)
- KVM: s390: Zero initialize irq in reinject_machine_check (Christian Borntraeger)
- KVM: s390: Take srcu when importing watchpoint data (Christian Borntraeger)
- KVM: s390: Free guest debug data on vcpu destroy (Christian Borntraeger)
- KVM: s390: Fix old_data leak in guest debug error path (Christian Borntraeger)
- KVM: s390: Fix memory leak in guest debug handling (Christian Borntraeger)
- KVM: s390: Fix length check __import_wp_info() (Christian Borntraeger)
- KVM: x86: Ensure runtime reads of disabled_quirks are resolved once (Sean Christopherson)
- KVM: x86: Serialize writes to disabled_quirks using kvm->lock (Sean Christopherson)
- KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock (Carlos López) [Orabug: 40033803] {CVE-2026-89927}
- KVM: x86/mmu: Fold kvm_mmu_zap_memslot() into kvm_arch_flush_shadow_memslot() (Sean Christopherson)
- KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU (Yosry Ahmed) [Orabug: 40033811] {CVE-2026-89929}
- KVM: nVMX: Service local TLB flushes on failed nested VM-Enter (Yosry Ahmed) [Orabug: 40033821] {CVE-2026-89930}
- KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit (Sean Christopherson) [Orabug: 40033827] {CVE-2026-89931}
- KVM: nVMX: Decouple INVVPID operand checks from flushing of vpid02 (Sean Christopherson)
- KVM: nVMX: Always flush vpid02 on first use (Yosry Ahmed) [Orabug: 40033829] {CVE-2026-89932}
- iio: light: opt4001: Fix reversed GENMASK() arguments in fault count mask (Nikhil Gautam)
- iio: light: opt4001: Reject integration times with a non-zero seconds part (Nikhil Gautam)
- iio: light: opt4001: Fix incompatible pointer type passed to div_u64_rem() (Nikhil Gautam)
- iio: light: opt4001: Fix power down clearing bits of the wrong register (Nikhil Gautam)
- iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() (Sanjay Chitroda)
- iio: srf04: fix pm_runtime handling on probe error path (Cong Nguyen)
- iio: pressure: mpl115: Fix runtime PM cleanup (Can Peng)
- iio: pressure: dps310: fix NULL pointer dereference on ACPI probe (Rupesh Majhi)
- iio: light: ltrf216a: fix runtime PM reference leak in error path (Vidhu Sarwal)
- iio: light: gp2ap002: Disable regulators on resume failure (Laxman Acharya Padhya)
- iio: light: cm32181: return zero after writing calibscale (Giorgi Tchankvetadze)
- iio: gyro: mpu3050: fix sign of raw angular velocity readings (Cong Nguyen)
- iio: dac: m62332: Fix regulator reference count imbalance (Erick Henrique)
- iio: chemical: sgp30: Handle IAQ thread creation failure (Linmao Li)
- iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF (Fan Wu)
- iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable (Moksh Panicker)
- iio: buffer: Tie IIO dma fence lock lifetime to the fence (Lars-Peter Clausen) [Orabug: 40033869] {CVE-2026-89940}
- iio: buffer: Make IIO DMA fence release RCU-safe (Lars-Peter Clausen) [Orabug: 40033873] {CVE-2026-89941}
- iio: buffer: Fix potential use-after-free in anonymous buffer release (Lars-Peter Clausen) [Orabug: 40033875] {CVE-2026-89942}
- iio: adc: pac1921: fix wrong channel used in trigger handler read (Cong Nguyen)
- iio: adc: max34408: add missing 'select REGMAP_I2C' to Kconfig (Joshua Crofts)
- ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get (Xu Wang)
- ASoC: loongson: Fix error handling in ACPI property parsing (Binbin Zhou)
- AsoC: intel: sst: fix PCI device reference leak on probe failure (Haoxiang Li)
- ASoC: hdac_hda: Fix hlink refcount leak on component registration failure (Haoxiang Li) [Orabug: 40033880] {CVE-2026-89944}
- ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure (Haoxiang Li)
- ASoC: cs35l34: drain threaded IRQ before runtime suspend (Runyu Xiao) [Orabug: 40033885] {CVE-2026-89945}
- ASoC: cs35l33: drain threaded IRQ before runtime suspend (Runyu Xiao)
- i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure (Linkai Gong)
- clk: qcom: gcc-mdm9607: Drop incorrect BIMC PLL and related clocks (Stephan Gerhold)
- clk: qcom: gcc-mdm9607: Fix halt_reg for gcc_apss_axi_clk (Stephan Gerhold)
- clk: qcom: gcc-mdm9607: Fix enable_reg for gcc_blsp1_sleep_clk (Stephan Gerhold)
- clk: qcom: gcc-mdm9607: Drop incorrect system_noc_bfdcd_clk_src (Stephan Gerhold)
- clk: qcom: gcc-mdm9607: Drop incorrect apss_tcu_clk_src (Stephan Gerhold)
- clk: rockchip: rk3588: Don't change PLL rates when setting dclk_vop2_src (Heiko Stuebner)
- clk: qcom: gcc-msm8939: Fix enable_reg for gcc_blsp1_sleep_clk (Stephan Gerhold)
- clk: qcom: gcc-msm8916: Fix enable_reg for gcc_blsp1_sleep_clk (Stephan Gerhold)
- batman-adv: bla: prevent CRC corruptions after claim flush (Sven Eckelmann)
- batman-adv: bla: fix freeing of claims on meshif deletion (Sven Eckelmann) [Orabug: 40033900] {CVE-2026-89948}
- batman-adv: dat: avoid unaligned fault in IP extraction (Sven Eckelmann)
- batman-adv: mcast: linearize skbuff for packet generation (Sven Eckelmann) [Orabug: 40033910] {CVE-2026-89950}
- batman-adv: mcast: ensure unshared skb for multicast packets (Sven Eckelmann)
- batman-adv: fix stale receive device on merged fragments (Zhiling Zou) [Orabug: 40033913] {CVE-2026-89951}
- mtd: rawnand: validate ONFI extended parameter page sections (Pengpeng Hou) [Orabug: 40033917] {CVE-2026-89952}
- mtd: mtdoops: free page bitmap when the backing MTD is removed (Xu Rao) [Orabug: 40033921] {CVE-2026-89953}
- mtd: afs: validate v2 image info bounds (Pengpeng Hou)
- s390/vfio-ap: Fix required lock not held during update of ap_matrix_mdev object (Tony Krowiak)
- s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap (Tony Krowiak)
- s390/vfio-ap: Fix NULL deref in status_show() during queue probe (Tony Krowiak)
- s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed (Tony Krowiak)
- s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL (Tony Krowiak)
- s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove (Tony Krowiak)
- s390/vfio-ap: Fix stale do_remove flag across iterations in vfio_ap_mdev_cfg_remove (Tony Krowiak)
- s390/vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm() (Tony Krowiak)
- powerpc/crash: stop watchdogs before booting kdump kernel (Sourabh Jain)
- powerpc/pseries: Move H_WATCHDOG definitions to a common header (Sourabh Jain)
- powerpc/pseries: Handle and log pseries-wdt registration failures (Sourabh Jain)
- powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population (Muchun Song)
- powerpc/kexec_file: Prevent kexec range truncation (Jinjie Ruan)
- powerpc/kexec_file: Fix null-ptr-def in extra size calculation (Jinjie Ruan)
- parisc: Fix alignment of asm statements in head.S (Helge Deller)
- parisc: eisa: Fix infinite loop when parsing invalid IRQ value (Pei Xiao)
- nvdimm/btt: reject an arena whose nfree is below the lane count (Bryam Vargas) [Orabug: 40033966] {CVE-2026-89965}
- mm/hugetlb: fix missing migratable flag on same-node hugetlb migration (Ma Wupeng)
- Revert "irqchip/mbigen: Fix mbigen node address layout" (Caina)
- nvmet-tcp: reject unsolicited H2CData PDUs (Shivam Kumar) [Orabug: 40033974] {CVE-2026-89968}
- nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU (Shivam Kumar) [Orabug: 40033978] {CVE-2026-89969}
- nvme-tcp: check the data direction of a C2HData PDU (Yehyeong Lee) [Orabug: 40033994] {CVE-2026-89973}
- nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails (Niklas Cassel) [Orabug: 40033999] {CVE-2026-89974}
- nvme-fabrics: fix DHCHAP secret leak on parse failure (Xu Rao) [Orabug: 40034002] {CVE-2026-89975}
- ALSA: pcm: Fix race between non-atomic ops and trigger-start (Takashi Iwai) [Orabug: 40034011] {CVE-2026-89979}
- ALSA: harmony: initialize locks before requesting IRQ (Runyu Xiao)
- ALSA: rawmidi: Return the error from snd_rawmidi_input_params() (Hyeongjun An)
- arm64: mm: Fix the lockless page-table walk in show_pte() (Karl Mehltretter) [Orabug: 40072757] {CVE-2026-93239}
- i2c: mux: Fix channel node leak on adapter add failure (Ahmad Byagowi) [Orabug: 40034021] {CVE-2026-89982}
- i2c: core: fix debugfs UAF on adapter removal (Vasileios Almpanis) [Orabug: 40034026] {CVE-2026-89983}
- perf trace: Refactor augmented_raw_syscalls using bpf_for (Viktor Malik)
- perf trace: Factor out BPF loop body (Viktor Malik)
- perf/x86/intel: Fix kernel address leakages in LBR stack (Dapeng Mi) [Orabug: 40034030] {CVE-2026-89984}
- rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers (Lad Prabhakar)
- rtc: rzn1: Fix weekday underflow when alarm crosses month boundary (Lad Prabhakar)
- memcg: make the v1 soft limit knob inert (Shakeel Butt) [Orabug: 40072764] {CVE-2026-93240}
- Input: aiptek - validate raw macro indices before updating state (Pengpeng Hou)
- mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave() (Eric Dumazet) [Orabug: 40034037] {CVE-2026-89986}
- kprobes: Protect kprobe_blacklist with RCU (Masami Hiramatsu) [Orabug: 40034043] {CVE-2026-89988}
- irqchip/stm32mp-exti: Fix the unit of the hwspinlock timeout (Junan)
- ima: Check for ERR_PTR from dentry_path() in validate_hash_algo() (Bradley Morgan) [Orabug: 40034047] {CVE-2026-89989}
- ata: ahci: work around lost interrupts on Marvell 88SE61xx (Hajo Noerenberg)
- ceph: lock mutex in ceph_mds_check_access() (Max Kellermann) [Orabug: 40034051] {CVE-2026-89990}
- block: flag zoned disks with GENHD_FL_NO_PART (Damien Le Moal)
- cpuidle: dt_idle_genpd: kfree() the original name allocation (Linkai Gong)
- dmaengine: dw-edma: Initialize IRQ data before requesting IRQs (Koichiro Den)
- dmaengine: dw-edma: Complete descriptors before pausing (Koichiro Den)
- dmaengine: dw-edma: Fix HDMA channel status register access (Koichiro Den)
- dmaengine: fsl-edma: tracing: no ptr dereference during log output (Martin Kaiser)
- dma-direct: return struct page from dma_direct_alloc_from_pool() (Aneesh Kumar K V) [Orabug: 40034065] {CVE-2026-89995}
- dm: fix resume-vs-remove race (Mikulas Patocka) [Orabug: 40034073] {CVE-2026-89997}
- dm: fix race when loading and unloading a table (Mikulas Patocka) [Orabug: 40034078] {CVE-2026-89998}
- HID: wacom: validate report length in wacom_intuos_pro2_bt_irq (Ibrahim Hashimov) [Orabug: 40034086] {CVE-2026-89999}
- HID: rmi: fix OOB access with undersized RMI reports (Wei Jie Law) [Orabug: 40034090] {CVE-2026-90000}
- HID: bpf: serialize device reference release in struct_ops destroy path (Sean Shen)
- ftrace: Synchronize the initialization of ftrace_ops (Steven Rostedt)
- futex: Prevent rcuwait use-after-free during requeue PI (Yao Kai) [Orabug: 40034103] {CVE-2026-90003}
- mm/damon/core-kunit: check region count before testing in split_at() (Seongjae Park)
- mm/damon/sysfs: kobject_del() target (normal), context and kdamond dirs (Seongjae Park)
- mm/damon/sysfs: kobject_del() region and target (error) dirs (Seongjae Park)
- mm/damon/sysfs-schemes: kobject_del() scheme region dirs (Seongjae Park)
- mm/damon/sysfs-schemes: kobject_del() scheme quota goal dirs (Seongjae Park)
- mm/damon/sysfs-schemes: kobject_del() scheme filter dirs (Seongjae Park)
- mm/damon/sysfs-schemes: kobject_del() scheme dirs (Seongjae Park)
- scsi: pm8001: Use rollback index when freeing MSI-X vectors (Runyu Xiao) [Orabug: 40034111] {CVE-2026-90007}
- scsi: target: iscsi: Reserve a terminator byte for the login payload (Sujal Tuladhar) [Orabug: 40034118] {CVE-2026-90011}
- spi: Fix DMA mapping ownership on partial map failure (Honghui Jiang) [Orabug: 40034123] {CVE-2026-90012}
- spi: bcmbca-hsspi: disable clocks on resume failure (Can Peng)
- spi: bcm63xx: disable clock on resume failure (Can Peng)
- spi: bcm63xx-hsspi: disable clocks on resume failure (Can Peng)
- ublk: clear VM_MAYWRITE on read-only ublk char device mmap (Kanishka De Silva) [Orabug: 40033117] {CVE-2026-89793}
- thermal/drivers/qoriq: Disable clock on resume failure (Can Peng)
- thermal/drivers/imx: Disable clock on runtime resume failure (Can Peng)
- staging: rtl8723bs: fix OOB read in rtw_action_frame_parse() (Muhammad Bilal)
- staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr() (Muhammad Bilal)
- usb: gadget: fix null pointer dereference in usb_put_function_instance() (Jeffin Philip)
- USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl() (Lovekesh Solanki)
- usb: gadget: f_midi: initialize work in f_midi_alloc() (Jeffin Philip)
- usb: gadget: f_midi2: fix use-after-free in string attribute show path (Ivy Lopez)
- usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs (Aleksandr Nogikh)
- usb: typec: ucsi: displayport: Fix OOB altmode array index (Jameson Thies) [Orabug: 40034208] {CVE-2026-90025}
- usb: typec: qcom-pmic: cancel reset_work on stop (Fan Wu)
- usb: typec: qcom-pmic-typec: drain cc_debounce_dwork if port_start() fails (Fan Wu)
- usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop (Fan Wu)
- usb: f_mass_storage: Bump local buffer size in fsg_common_create_luns() (Andy Shevchenko)
- usb-storage: ene_ub6250: fix race between scan work and probe (Liu Qi) [Orabug: 40034248] {CVE-2026-90031}
- media: usbtv: keep device alive while ALSA card exists (Shuangpeng Bai) [Orabug: 40034258] {CVE-2026-90032}
- clk: qcom: gcc-mdm9607: Increase delay for USB PHY reset (Stephan Gerhold)
- ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output() (Hyeongjun An) [Orabug: 40034265] {CVE-2026-90033}
- usb: image: mdc800: change kmalloc() to kzalloc() (Griffin Kroah-Hartman) [Orabug: 40034274] {CVE-2026-90034}
- drm/amd/display: fix division by zero in get_estimated_bw() (Hari Mishal) [Orabug: 40034282] {CVE-2026-90035}
- fsnotify: inotify: pass mark connector to fsnotify_recalc_mask() (Sun Jian)
- objtool/rust: add one more noreturn Rust function (Fujita Tomonori)
- entry: Fix seccomp bypass after ptrace with TSYNC (Jinjie Ruan) [Orabug: 40021398] {CVE-2026-89603}
- fsnotify: Fix stale object mask after concurrent mark updates (Youngjae Kwon) [Orabug: 40021347] {CVE-2026-89595}
- hugetlb: only adjust reservation during unmapping if mapcount is 0 (Guillaume Morin) [Orabug: 40021338] {CVE-2026-89593}
- wifi: mt76: mt7996: validate default EEPROM firmware size (Laxman Acharya Padhya)
- mm/page_vma_mapped: use huge_ptep_get() for hugetlb (Dev Jain)
- netfs: Fix netfs_read_folio() to wait on writeback (David Howells) [Orabug: 39754667] {CVE-2026-64058}
- landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation (Günther Noack) [Orabug: 40021202] {CVE-2026-89560}
- openvswitch: Fix CT limit teardown use-after-free (Yuqi Xu) [Orabug: 40020918] {CVE-2026-89488}
- net: openvswitch: fix kernel-doc warnings in internal headers (Ilya Maximets)
- net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() (Norbert Szetei) [Orabug: 40034342] {CVE-2026-90049}

[6.12.0-207.109.4]
- workqueue: forbid TEST_WORKQUEUE from being built-in (Breno Leitao) [Orabug: 39955160]
- workqueue: avoid unguarded 64-bit division (Arnd Bergmann) [Orabug: 39955160]
- workqueue: add test_workqueue benchmark module (Breno Leitao) [Orabug: 39955160]
- workqueue: validate cpumask_first() result in llc_populate_cpu_shard_id() (Breno Leitao) [Orabug: 39955160]
- docs: workqueue: document WQ_AFFN_CACHE_SHARD affinity scope (Breno Leitao) [Orabug: 39955160]
- tools/workqueue: add CACHE_SHARD support to wq_dump.py (Breno Leitao) [Orabug: 39955160]
- workqueue: set WQ_AFFN_CACHE_SHARD as the default affinity scope (Breno Leitao) [Orabug: 39955160]
- workqueue: add WQ_AFFN_CACHE_SHARD affinity scope (Breno Leitao) [Orabug: 39955160]
- workqueue: fix typo in WQ_AFFN_SMT comment (Breno Leitao) [Orabug: 39955160]
- workqueue: fix parse_affn_scope() prefix matching bug (Breno Leitao) [Orabug: 39955160]
- firmware: arm_ffa: Honor partition info descriptor size (Jamie Nguyen) [Orabug: 39955160]
- firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies (Sudeep Holla) [Orabug: 39786528,39955160] {CVE-2026-64520}
- firmware: arm_ffa: Fix big-endian support in __ffa_partition_info_regs_get() (Sudeep Holla) [Orabug: 39955160]
- firmware: arm_ffa: Replace UUID buffer to standard UUID format (Sudeep Holla) [Orabug: 39955160]
- SUNRPC: Fix a hang in TLS sock_close if sk_write_pending (Benjamin Coddington) [Orabug: 39812836]
- tcp: fix potential race in tcp_v6_syn_recv_sock() (Eric Dumazet) [Orabug: 39331623] {CVE-2026-43198}
- net: ntb_netdev: Fix TX busy and drop handling (Koichiro Den)
- net: stmmac: selftests: Pass the IP proto mask in the TC selftest (Maxime Chevallier)
- Bluetooth: L2CAP: fix race l2cap_sock_cleanup_listen() vs. put_chan (Pauli Virtanen) [Orabug: 40043383] {CVE-2026-90091}
- erofs: Fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS default logic (Geert Uytterhoeven)
- ALSA: seq: midi: Optimize event_input locking with RCU (Takashi Iwai)
- ALSA: seq: Don't leak the extension cell pointer in the bounce payload (Hyeongjun An) [Orabug: 40043399] {CVE-2026-90220}
- f2fs: fix i_size when pinned fallocate partially fails (Zhan Xusheng)
- media: cec: core: Fix kmemleak due to missed rc_free_device() call (Jonas Karlman) [Orabug: 40034383] {CVE-2026-89900}
- LoongArch: Fix acpi_package_ids[] array overflow (Bibo Mao)
- pddf: psu: expose PSU firmware version via sysfs (Chinmoy Dey) [Orabug: 39976175]
- RDMA/nldev: Fix locking when accessing mr->pd (Jason Gunthorpe) [Orabug: 39886477,40028950] {CVE-2026-74334}
- RDMA/restrack: Fix typos in the comments (Kalesh Ap) [Orabug: 39886477] {CVE-2026-74334}
- tcp: clear sock_ops cb flags before force-closing a child socket (Sechang Lim) [Orabug: 39886287] {CVE-2026-74268}
- xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata() (Jason Xing) [Orabug: 39637697,40028941] {CVE-2026-53250}
- printk: add kthread for long-running print (Stephen Brennan) [Orabug: 37351898]
- net/mlx5e: MACsec, add ASO poll loop in macsec_aso_set_arm_event (Gal Pressman) [Orabug: 39203185]
- net/mlx5e: Fix misidentification of ASO CQE during poll loop (Gal Pressman) [Orabug: 39203185]
- net/mlx5: Fix return type mismatch in mlx5_esw_vport_vhca_id() (Zeng Chi) [Orabug: 39203185]
- net/mlx5: Lag, multipath, give priority for routes with smaller network prefix (Patrisious Haddad) [Orabug: 39203185]
- net/mlx5: make enable_mpesw idempotent (Moshe Shemesh) [Orabug: 39203185]
- net/mlx5e: Don't include PSP in the hard MTU calculations (Cosmin Ratiu) [Orabug: 39203185]
- net/mlx5e: Trim the length of the num_doorbell error (Cosmin Ratiu) [Orabug: 39203185]
- net/mlx5e: Fix missing error assignment in mlx5e_xfrm_add_state() (Carolina Jubran) [Orabug: 39203185]
- net/mlx5e: SHAMPO, Fix header formulas for higher MTUs and 64K pages (Dragos Tatulea) [Orabug: 39203185]
- net/mlx5e: SHAMPO, Fix header mapping for 64K pages (Dragos Tatulea) [Orabug: 39203185]
- net/mlx5e: kTLS, Cancel RX async resync request in error flows (Shahar Shitrit) [Orabug: 39203185]
- net/mlx5: Don't zero user_count when destroying FDB tables (Cosmin Ratiu) [Orabug: 39203185]
- net/mlx5e: Skip PPHCR register query if not supported by the device (Alexei Lazar) [Orabug: 39203185]
- net/mlx5: Add PPHCR to PCAM supported registers mask (Alexei Lazar) [Orabug: 39203185]
- net/mlx5e: psp, avoid 'accel' NULL pointer dereference (Cosmin Ratiu) [Orabug: 39203185]
- platform/mellanox: mlxbf-pmc: add sysfs_attr_init() to count_clock init (David Thompson) [Orabug: 39203185]
- net/mlx5: fix pre-2.40 binutils assembler error (Arnd Bergmann) [Orabug: 39203185]
- net/mlx5e: Do not fail PSP init on missing caps (Cosmin Ratiu) [Orabug: 39203185]
- net/mlx5e: Prevent tunnel reformat when tunnel mode not allowed (Carolina Jubran) [Orabug: 39203185]
- net/mlx5: Prevent tunnel mode conflicts between FDB and NIC IPsec tables (Carolina Jubran) [Orabug: 39203185]
- vdpa: introduce map ops (Jason Wang) [Orabug: 39203185]
- vdpa: support virtio_map (Jason Wang) [Orabug: 39203185]
- virtio: introduce map ops in virtio core (Jason Wang) [Orabug: 39203185]
- virtio_ring: rename dma_handle to map_handle (Jason Wang) [Orabug: 39203185]
- virtio: introduce virtio_map container union (Jason Wang) [Orabug: 39203185]
- virtio: rename dma helpers (Jason Wang) [Orabug: 39203185]
- virtio_ring: switch to use dma_{map|unmap}_page() (Jason Wang) [Orabug: 39203185]
- virtio_ring: constify virtqueue pointer for DMA helpers (Jason Wang) [Orabug: 39203185]
- net/mlx5e: Use extack in set rxfh callback (Gal Pressman) [Orabug: 39203185]
- net/mlx5e: Introduce mlx5e_rss_params for RSS configuration (Carolina Jubran) [Orabug: 39203185]
- net/mlx5e: Introduce mlx5e_rss_init_params (Carolina Jubran) [Orabug: 39203185]
- net/mlx5e: Remove unused mdev param from RSS indir init (Carolina Jubran) [Orabug: 39203185]
- net/mlx5: Improve QoS error messages with actual depth values (Carolina Jubran) [Orabug: 39203185]
- net/mlx5e: Prevent entering switchdev mode with inconsistent netns (Jianbo Liu) [Orabug: 39203185]
- net/mlx5: HWS, Generalize complex matchers (Vlad Dogaru) [Orabug: 39203185]
- net/mlx5: Improve write-combining test reliability for ARM64 Grace CPUs (Patrisious Haddad) [Orabug: 39203185]
- net/mlx5: IFC add balance ID and LAG per MP group bits (Mark Bloch) [Orabug: 39203185]
- net/mlx5: Add IFC bit for TIR/SQ order capability (Tariq Toukan) [Orabug: 39203185]
- net/mlx5: Expose uar access and odp page fault counters (Akiva Goldberger) [Orabug: 39203185]
- selftests: forwarding: lib: Add an autodefer variant of simple_if_init() (Petr Machata) [Orabug: 39203185]
- selftests: forwarding: lib: Add an autodefer variant of vrf_prepare() (Petr Machata) [Orabug: 39203185]
- selftests: net: lib: Rename bridge_vlan_add() to adf_* (Petr Machata) [Orabug: 39203185]
- selftests: net: lib: Rename ip_route_add() to adf_* (Petr Machata) [Orabug: 39203185]
- selftests: net: lib: Rename ip_addr_add() to adf_* (Petr Machata) [Orabug: 39203185]
- selftests: net: lib: Rename ip_link_set_up() to adf_* (Petr Machata) [Orabug: 39203185]
- selftests: net: lib: Rename ip_link_set_addr() to adf_* (Petr Machata) [Orabug: 39203185]
- selftests: net: lib: Rename ip_link_set_master() to adf_* (Petr Machata) [Orabug: 39203185]
- selftests: net: lib: Rename ip_link_add() to adf_* (Petr Machata) [Orabug: 39203185]
- net/mlx5e: Report RS-FEC histogram statistics via ethtool (Carolina Jubran) [Orabug: 39203185]
- net/mlx5e: Add logic to read RS-FEC histogram bin ranges from PPHCR (Carolina Jubran) [Orabug: 39203185]
- ethtool: add FEC bins histogram report (Vadim Fedorenko) [Orabug: 39203185]
- net/mlx5: Use %pe format specifier for error pointers (Gal Pressman) [Orabug: 39203185]
- net: gso: restore ids of outer ip headers correctly (Richard Gobert) [Orabug: 39203185]
- net: gro: only merge packets with incrementing or fixed outer ids (Richard Gobert) [Orabug: 39203185]
- net: gro: remove is_ipv6 from napi_gro_cb (Richard Gobert) [Orabug: 39203185]
- selftests: bridge_fdb_local_vlan_0: Test FDB vs. NET_ADDR_SET behavior (Petr Machata) [Orabug: 39203185]
- net: replace use of system_unbound_wq with system_dfl_wq (Marco Crivellari) [Orabug: 39203185]
- pds_fwctl: Replace kzalloc + copy_from_user with memdup_user in pdsfc_fw_rpc (Thorsten Blum) [Orabug: 39203185]
- RDMA: Use %pe format specifier for error pointers (Leon Romanovsky) [Orabug: 39203185]
- net/mlx5: Remove dead code from total_vfs setter (Vlad Dumitrescu) [Orabug: 39203185]
- net/mlx5e: Add flow rules for the decrypted ESP packets (Jianbo Liu) [Orabug: 39203185]
- net/mlx5e: Add flow groups for the packets decrypted by crypto offload (Jianbo Liu) [Orabug: 39203185]
- net/mlx5e: Recirculate decrypted packets into TTC table (Jianbo Liu) [Orabug: 39203185]
- net/mlx5: Change TTC rules to match on undecrypted ESP packets (Jianbo Liu) [Orabug: 39203185]
- net/mlx5e: Implement PSP key_rotate operation (Raed Salem) [Orabug: 39203185]
- net/mlx5e: Add Rx data path offload (Raed Salem) [Orabug: 39203185]
- net/mlx5e: Configure PSP Rx flow steering rules (Raed Salem) [Orabug: 39203185]
- net/mlx5e: Add PSP steering in local NIC RX (Raed Salem) [Orabug: 39203185]
- net/mlx5e: Implement PSP Tx data path (Raed Salem) [Orabug: 39203185]
- psp: provide encapsulation helper for drivers (Raed Salem) [Orabug: 39203185]
- net/mlx5e: Implement PSP operations .assoc_add and .assoc_del (Raed Salem) [Orabug: 39203185]
- net/mlx5e: Support PSP offload functionality (Raed Salem) [Orabug: 39203185]
- psp: add op for rotation of device key (Jakub Kicinski) [Orabug: 39203185]
- net: modify core data structures for PSP datapath support (Jakub Kicinski) [Orabug: 39203185]
- psp: base PSP device support (Jakub Kicinski) [Orabug: 39203185]
- net/mlx5: Add uar access and odp page fault counters (Akiva Goldberger) [Orabug: 39203185]
- net/mlx5e: Use the 'num_doorbells' devlink param (Cosmin Ratiu) [Orabug: 39203185]
- devlink: Add a 'num_doorbells' driverinit param (Cosmin Ratiu) [Orabug: 39203185]
- net/mlx5e: Use multiple CQ doorbells (Cosmin Ratiu) [Orabug: 39203185]
- net/mlx5e: Use multiple TX doorbells (Cosmin Ratiu) [Orabug: 39203185]
- net/mlx5e: Prepare for using multiple TX doorbells (Cosmin Ratiu) [Orabug: 39203185]
- net/mlx5e: Remove unused 'xsk' param of mlx5e_build_xdpsq_param (Cosmin Ratiu) [Orabug: 39203185]
- net/mlx5: Remove unused 'offset' field from mlx5_sq_bfreg (Cosmin Ratiu) [Orabug: 39203185]
- fwctl/mlx5: Add Adjacent function query commands and their scope (Saeed Mahameed) [Orabug: 39203185]
- fwctl/mlx5: Allow MODIFY_CONG_STATUS command (Avihai Horon) [Orabug: 39203185]
- net/mlx5e: Prevent WQE metadata conflicts between timestamping and offloads (Carolina Jubran) [Orabug: 39203185]
- net/mlx5: Refactor MACsec WQE metadata shifts (Carolina Jubran) [Orabug: 39203185]
- net/mlx5: Remove VLAN insertion fields from WQE Ether segment (Carolina Jubran) [Orabug: 39203185]
- net/mlx5: Lag, add net namespace support (Shay Drory) [Orabug: 39203185]
- mlxsw: spectrum_cnt: use bitmap_empty() in mlxsw_sp_counter_pool_fini() (Yury Norov) [Orabug: 39203185]
- net/mlx5: fix typo in pci_irq.c comment (Alok Tiwari) [Orabug: 39203185]
- selftests: forwarding: Add test for BR_BOOLOPT_FDB_LOCAL_VLAN_0 (Petr Machata) [Orabug: 39203185]
- selftests: net: lib.sh: Don't defer failed commands (Petr Machata) [Orabug: 39203185]
- kmsan: convert kmsan_handle_dma to use physical addresses (Leon Romanovsky) [Orabug: 39203185]
- iommu/dma: rename iommu_dma_*map_page to iommu_dma_*map_phys (Leon Romanovsky) [Orabug: 39203185]
- dma-mapping: rename trace_dma_*map_page to trace_dma_*map_phys (Leon Romanovsky) [Orabug: 39203185]
- dma-debug: refactor to use physical addresses for page mapping (Leon Romanovsky) [Orabug: 39203185]
- dma-mapping: introduce new DMA attribute to indicate MMIO memory (Leon Romanovsky) [Orabug: 39203185]
- net: xdp: pass full flags to xdp_update_skb_shared_info() (Jakub Kicinski) [Orabug: 39203185]
- RDMA/bnxt_re: Update sysfs entries with appropriate data (Anantha Prabhu) [Orabug: 39203185]
- RDMA/bnxt_re: Call strscpy() with correct size argument (Thorsten Blum) [Orabug: 39203185]
- RDMA/mlx5: Fix page size bitmap calculation for KSM mode (Edward Srouji) [Orabug: 39203185]
- RDMA/bnxt_re: Remove unnecessary condition checks (Kalesh Ap) [Orabug: 39203185]
- RDMA/bnxt_re: Use firmware provided message timeout value (Saravanan Vajravel) [Orabug: 39203185]
- RDMA/bnxt_re: Initialize fw with roce_mirror support (Saravanan Vajravel) [Orabug: 39203185]
- RDMA/bnxt_re: Add support for flow create/destroy (Saravanan Vajravel) [Orabug: 39203185]
- RDMA/bnxt_re: Add support for mirror vnic (Saravanan Vajravel) [Orabug: 39203185]
- RDMA/bnxt_re: Add support for unique GID (Saravanan Vajravel) [Orabug: 39203185]
- RDMA/bnxt_re: Refactor stats context memory allocation (Kalesh Ap) [Orabug: 39203185]
- RDMA/bnxt_re: Refactor hw context memory allocation (Kalesh Ap) [Orabug: 39203185]
- RDMA/bnxt_re: Add data structures for RoCE mirror support (Saravanan Vajravel) [Orabug: 39203185]
- RDMA/bnxt_re: Enhance a log message when bnxt_re_register_netdev fails (Kalesh Ap) [Orabug: 39203185]
- net/mlx5e: Add stale counter for PCIe congestion events (Dragos Tatulea) [Orabug: 39203185]
- net/mlx5e: Make PCIe congestion event thresholds configurable (Dragos Tatulea) [Orabug: 39203185]
- net/mlx5: Implement devlink total_vfs parameter (Vlad Dumitrescu) [Orabug: 39203185]
- net/mlx5: Implement devlink enable_sriov parameter (Vlad Dumitrescu) [Orabug: 39203185]
- net/mlx5: Implement cqe_compress_type via devlink params (Saeed Mahameed) [Orabug: 39203185]
- devlink: Add 'total_vfs' generic device param (Vlad Dumitrescu) [Orabug: 39203185]
- selftests: bonding: add test for LACP actor port priority (Hangbin Liu) [Orabug: 39203185]
- net/mlx5: Add RS FEC histogram infrastructure (Carolina Jubran) [Orabug: 39203185]
- net/mlx5: Support getcyclesx and getcrosscycles (Carolina Jubran) [Orabug: 39203185]
- net/mlx5: Extract MTCTR register read logic into helper function (Carolina Jubran) [Orabug: 39203185]
- RDMA/bnxt_re: Report udp source port for flow_label in bnxt_re_query_qp (Abhishek Mohapatra) [Orabug: 39203185]
- RDMA/bnxt_re: Optimize bnxt_qplib_get_dev_attr function (Damodharam Ammepalli) [Orabug: 39203185]
- RDMA/bnxt_re: Show srq_limit in fill_res_srq_entry hook (Kashyap Desai) [Orabug: 39203185]
- net: add helper to pre-check if PP for an Rx queue will be unreadable (Jakub Kicinski) [Orabug: 39203185]
- net/mlx5: Add PSP capabilities structures and bits (Saeed Mahameed) [Orabug: 39203185]
- net/mlx5: {DR,HWS}, Use the cached vhca_id for this device (Saeed Mahameed) [Orabug: 39203185]
- net/mlx5: E-switch, Set representor attributes for adjacent VFs (Adithya Jayachandran) [Orabug: 39203185]
- net/mlx5: E-Switch, Register representors for adjacent vports (Saeed Mahameed) [Orabug: 39203185]
- net/mlx5: E-Switch, Create acls root namespace for adjacent vports (Saeed Mahameed) [Orabug: 39203185]
- net/mlx5: E-Switch, Add support for adjacent functions vports discovery (Adithya Jayachandran) [Orabug: 39203185]
- net/mlx5: E-Switch, Move vport acls root namespaces creation to eswitch (Saeed Mahameed) [Orabug: 39203185]
- net/mlx5: FS, Convert vport acls root namespaces to xarray (Saeed Mahameed) [Orabug: 39203185]
- eth: mlx5: remove Kconfig co-dependency with VXLAN (Jakub Kicinski) [Orabug: 39203185]
- net/mlx5e: add op for getting netdev DMA device (Dragos Tatulea) [Orabug: 39203185]
- queue_api: add support for fetching per queue DMA dev (Dragos Tatulea) [Orabug: 39203185]
- eth: fbnic: Read PHY stats via the ethtool API (Mohsin Bashir) [Orabug: 39203185]
- eth: fbnic: Move hw_stats_lock out of fbnic_dev (Mohsin Bashir) [Orabug: 39203185]
- tcp: Don't pass hashinfo to socket lookup helpers. (Kuniyuki Iwashima) [Orabug: 39203185]
- uek-rpm: Remove DCCP from onos modules list (Alexandre Chartre) [Orabug: 39203185]
- net: Retire DCCP socket. (Kuniyuki Iwashima) [Orabug: 39203185]
- RDMA/mlx5: Enable Data-Direct with Relaxed Ordering (Yishai Hadas) [Orabug: 39203185]
- pds_fwctl: Remove the use of dev_err_probe() (Liao Yuanhong) [Orabug: 39203185]
- mmc: sdhci-of-dwcmshc: use modern PM macros (Jisheng Zhang) [Orabug: 39203185]
- selftests: bonding: add test for passive LACP mode (Hangbin Liu) [Orabug: 39203185]
- eth: fbnic: Report XDP stats via ethtool (Mohsin Bashir) [Orabug: 39203185]
- eth: fbnic: Collect packet statistics for XDP (Mohsin Bashir) [Orabug: 39203185]
- eth: fbnic: Add support for XDP_TX action (Mohsin Bashir) [Orabug: 39203185]
- eth: fbnic: Add support for XDP queues (Mohsin Bashir) [Orabug: 39203185]
- eth: fbnic: Add XDP pass, drop, abort support (Mohsin Bashir) [Orabug: 39203185]
- eth: fbnic: Prefetch packet headers on Rx (Mohsin Bashir) [Orabug: 39203185]
- eth: fbnic: Use shinfo to track frags state on Rx (Mohsin Bashir) [Orabug: 39203185]
- eth: fbnic: Add support for HDS configuration (Mohsin Bashir) [Orabug: 39203185]
- fwctl/mlx5: Fix memory alloc/free in mlx5ctl_fw_rpc() (Akhilesh Patil) [Orabug: 39203185]
- net/mlx5: Support disabling host PFs (Daniel Jurgens) [Orabug: 39203185]
- {rdma,net}/mlx5: export mlx5_vport_get_vhca_id (Saeed Mahameed) [Orabug: 39203185]
- net/mlx5: E-Switch, Set/Query hca cap via vhca id (Saeed Mahameed) [Orabug: 39203185]
- net/mlx5: E-Switch, Cache vport vhca id on first cap query (Saeed Mahameed) [Orabug: 39203185]
- net/mlx5: mlx5_ifc, Add hardware definitions needed for adjacent vports (Saeed Mahameed) [Orabug: 39203185]
- eth: fbnic: support RSS on IPv6 Flow Label (Jakub Kicinski) [Orabug: 39203185]
- net/mlx5: Don't use %pK through tracepoints (Thomas Weißschuh) [Orabug: 39203185]
- selftests: forwarding: Add a test for FDB activity notification control (Ido Schimmel) [Orabug: 39203185]
- eth: fbnic: Lock the tx_dropped update (Mohsin Bashir) [Orabug: 39203185]
- eth: fbnic: Fix tx_dropped reporting (Mohsin Bashir) [Orabug: 39203185]
- eth: fbnic: unlink NAPIs from queues on error to open (Jakub Kicinski) [Orabug: 39203185]
- virtio-vdpa: Remove virtqueue list (Viresh Kumar) [Orabug: 39203185]
- virtio: document ENOSPC (Michael S. Tsirkin) [Orabug: 39203185]
- net: Fix typos (Bjorn Helgaas) [Orabug: 39203185]
- RDMA/mlx5: Add DMAH support for reg_user_mr/reg_user_dmabuf_mr (Yishai Hadas) [Orabug: 39203185]
- IB: Extend UVERBS_METHOD_REG_MR to get DMAH (Yishai Hadas) [Orabug: 39203185]
- RDMA/efa: Add CQ with external memory support (Michael Margolin) [Orabug: 39203185]
- RDMA/core: Add umem "is_contiguous" and "start_dma_addr" helpers (Michael Margolin) [Orabug: 39203185]
- selftests: net: add netdev-l2addr.sh for testing L2 address functionality (Toke Høiland-Jørgensen) [Orabug: 39203185]
- devlink: Add new "clock_id" generic device param (Ivan Vecera) [Orabug: 39203185]
- devlink: Add support for u64 parameters (Ivan Vecera) [Orabug: 39203185]
- eth: fbnic: Create ring buffer for firmware logs (Lee Trager) [Orabug: 39203185]
- virtio: introduce extended features (Paolo Abeni) [Orabug: 39203185]
- RDMA/bnxt_re: Support 2G message size (Selvin Xavier) [Orabug: 39203185]
- RDMA/counter: Check CAP_NET_RAW check in user namespace for RDMA counters (Parav Pandit) [Orabug: 39203185]
- RDMA/nldev: Check CAP_NET_RAW in user namespace for QP modify (Parav Pandit) [Orabug: 39203185]
- RDMA/uverbs: Check CAP_NET_RAW in user namespace for RAW QP create (Parav Pandit) [Orabug: 39203185]
- lib/group_cpus: Let group_cpu_evenly() return the number of initialized masks (Daniel Wagner) [Orabug: 39203185]
- RDMA/uverbs: Check CAP_NET_RAW in user namespace for RAW QP create (Parav Pandit) [Orabug: 39203185]
- RDMA/uverbs: Check CAP_NET_RAW in user namespace for QP create (Parav Pandit) [Orabug: 39203185]
- eth: fbnic: realign whitespace (Jakub Kicinski) [Orabug: 39203185]
- fbnic: Add support for setting/getting pause configuration (Alexander Duyck) [Orabug: 39203185]
- fbnic: Add support for reporting link config (Alexander Duyck) [Orabug: 39203185]
- fbnic: Set correct supported modes and speeds based on FW setting (Alexander Duyck) [Orabug: 39203185]
- fbnic: Replace link_mode with AUI (Alexander Duyck) [Orabug: 39203185]
- fbnic: Retire "AUTO" flags and cleanup handling of FW link settings (Alexander Duyck) [Orabug: 39203185]
- devlink: Add new "enable_phc" generic device param (David Arinzon) [Orabug: 39203185]
- selftests: net: lib: Add ip_link_has_flag() (Petr Machata) [Orabug: 39203185]
- eth: fbnic: migrate to new RXFH callbacks (Jakub Kicinski) [Orabug: 39203185]
- eth: fbnic: Expand coverage of mac stats (Mohsin Bashir) [Orabug: 39203185]
- selftests: net: move wait_local_port_listen to lib.sh (Hangbin Liu) [Orabug: 39203185]
- tools: ynl: enable codegen for TC (Jakub Kicinski) [Orabug: 39203185]
- tools: ynl-gen: add makefile deps for neigh (Jakub Kicinski) [Orabug: 39203185]
- eth: fbnic: Replace kzalloc/fbnic_fw_init_cmpl with fbnic_fw_alloc_cmpl (Lee Trager) [Orabug: 39203185]
- tools: ynl: enable codegen for all rt- families (Jakub Kicinski) [Orabug: 39203185]
- xdp: Use nested-BH locking for system_page_pool (Sebastian Andrzej Siewior) [Orabug: 39203185]
- eth: fbnic: Add devlink dev flash support (Lee Trager) [Orabug: 39203185]
- eth: fbnic: Add mailbox support for PLDM updates (Lee Trager) [Orabug: 39203185]
- eth: fbnic: Add support for multiple concurrent completion messages (Lee Trager) [Orabug: 39203185]
- eth: fbnic: Accept minimum anti-rollback version from firmware (Lee Trager) [Orabug: 39203185]
- selftests: net: disable rp_filter after namespace initialization (Hangbin Liu) [Orabug: 39203185]
- fbnic: Cleanup handling of completions (Alexander Duyck) [Orabug: 39203185]
- fbnic: Add additional handling of IRQs (Alexander Duyck) [Orabug: 39203185]
- devlink: avoid param type value translations (Jiri Pirko) [Orabug: 39203185]
- eth: fbnic: fix tx_dropped counting (Mohsin Bashir) [Orabug: 39203185]
- xsk: convert xdp_copy_frags_from_zc() to use page_pool_dev_alloc() (Bui Quang Minh) [Orabug: 39203185]
- xsk: respect the offsets when copying frags (Bui Quang Minh) [Orabug: 39203185]
- selftests/net: test tcp connection load balancing (Willem de Bruijn) [Orabug: 39203185]
- tools: ynl: fix the header guard name for OVPN (Jakub Kicinski) [Orabug: 39203185]
- tools: ynl: add missing header deps (Jakub Kicinski) [Orabug: 39203185]
- eth: bnxt: add support rx side device memory TCP (Taehee Yoo) [Orabug: 39203185]
- eth: fbnic: add support for TTI HW stats (Mohsin Bashir) [Orabug: 39203185]
- eth: fbnic: add support for TMI stats (Mohsin Bashir) [Orabug: 39203185]
- eth: fbnic: add coverage for RXB stats (Mohsin Bashir) [Orabug: 39203185]
- eth: fbnic: add coverage for hw queue stats (Mohsin Bashir) [Orabug: 39203185]
- eth: fbnic: add locking support for hw stats (Mohsin Bashir) [Orabug: 39203185]
- tools: ynl: generate code for rt-route and add a sample (Jakub Kicinski) [Orabug: 39203185]
- tools: ynl: generate code for rt-addr and add a sample (Jakub Kicinski) [Orabug: 39203185]
- selftests: net: use netdevsim in netns test (Stanislav Fomichev) [Orabug: 39203185]
- selftests: net: use the dummy bpf from net/lib (Jakub Kicinski) [Orabug: 39203185]
- gso: AccECN support (Ilpo Järvinen) [Orabug: 39203185]
- RDMA/bnxt_re: Support perf management counters (Preethi G) [Orabug: 39203185]
- eth: fbnic: support ring size configuration (Jakub Kicinski) [Orabug: 39203185]
- eth: fbnic: fix typo in compile assert (Jakub Kicinski) [Orabug: 39203185]
- eth: fbnic: link NAPIs to page pools (Jakub Kicinski) [Orabug: 39203185]
- eth: fbnic: Replace firmware field macros (Lee Trager) [Orabug: 39203185]
- eth: fbnic: Update fbnic_tlv_attr_get_string() to work like nla_strscpy() (Lee Trager) [Orabug: 39203185]
- eth: fbnic: Prepend TSENE FW fields with FBNIC_FW (Lee Trager) [Orabug: 39203185]
- xdp: remove xdp_alloc_skb_bulk() (Alexander Lobakin) [Orabug: 39203185]
- veth: use napi_skb_cache_get_bulk() instead of xdp_alloc_skb_bulk() (Alexander Lobakin) [Orabug: 39203185]
- net: skbuff: introduce napi_skb_cache_get_bulk() (Alexander Lobakin) [Orabug: 39203185]
- eth: fbnic: Update return value in kdoc (Mohsin Bashir) [Orabug: 39203185]
- eth: fbnic: Consolidate PUL_USER CSR section (Mohsin Bashir) [Orabug: 39203185]
- eth: fbnic: Add PCIe registers dump (Mohsin Bashir) [Orabug: 39203185]
- eth: fbnic: Add ethtool support for IRQ coalescing (Mohsin Bashir) [Orabug: 39203185]
- RDMA/mana_ib: Implement DMABUF MR support (Konstantin Taranov) [Orabug: 39203185]
- selftests: test_vxlan_fdb_changelink: Add a test for MC remote change (Petr Machata) [Orabug: 39203185]
- selftests: test_vxlan_fdb_changelink: Convert to lib.sh (Petr Machata) [Orabug: 39203185]
- selftests: forwarding: lib: Move require_command to net, generalize (Petr Machata) [Orabug: 39203185]
- eth: fbnic: support TCP segmentation offload (Jakub Kicinski) [Orabug: 39203185]
- netlink: specs: wireless: add a spec for nl80211 (Donald Hunter) [Orabug: 39203185]
- eth: fbnic: report software Tx queue stats (Jakub Kicinski) [Orabug: 39203185]
- eth: fbnic: report software Rx queue stats (Jakub Kicinski) [Orabug: 39203185]
- eth: fbnic: wrap tx queue stats in a struct (Jakub Kicinski) [Orabug: 39203185]
- eth: fbnic: support n-tuple filters (Alexander Duyck) [Orabug: 39203185]
- eth: fbnic: add IP TCAM programming (Alexander Duyck) [Orabug: 39203185]
- eth: fbnic: support an additional RSS context (Daniel Zahka) [Orabug: 39203185]
- tools: ynl: add all headers to makefile deps (Jakub Kicinski) [Orabug: 39203185]
- RDMA/mana_ib: Add port statistics support (Shiraz Saleem) [Orabug: 39203185]
- RDMA/mana_ib: request error CQEs when supported (Konstantin Taranov) [Orabug: 39203185]
- RDMA/mana_ib: Query feature_flags bitmask from FW (Shiraz Saleem) [Orabug: 39203185]
- RDMA/bnxt_re: Congestion control settings using debugfs hook (Selvin Xavier) [Orabug: 39203185]
- RDMA/mana_ib: polling of CQs for GSI/UD (Konstantin Taranov) [Orabug: 39203185]
- RDMA/mana_ib: extend mana QP table (Konstantin Taranov) [Orabug: 39203185]
- RDMA/mana_ib: implement req_notify_cq (Konstantin Taranov) [Orabug: 39203185]
- RDMA/mana_ib: UD/GSI work requests (Konstantin Taranov) [Orabug: 39203185]
- RDMA/mana_ib: create/destroy AH (Konstantin Taranov) [Orabug: 39203185]
- RDMA/mana_ib: UD/GSI QP creation for kernel (Konstantin Taranov) [Orabug: 39203185]
- RDMA/mana_ib: Create and destroy UD/GSI QP (Konstantin Taranov) [Orabug: 39203185]
- RDMA/mana_ib: create kernel-level CQs (Konstantin Taranov) [Orabug: 39203185]
- RDMA/mana_ib: helpers to allocate kernel queues (Konstantin Taranov) [Orabug: 39203185]
- RDMA/mana_ib: implement get_dma_mr (Konstantin Taranov) [Orabug: 39203185]
- eth: fbnic: Add hardware monitoring support via HWMON interface (Sanman Pradhan) [Orabug: 39203185]
- eth: fbnic: hwmon: Add support for reading temperature and voltage sensors (Sanman Pradhan) [Orabug: 39203185]
- eth: fbnic: hwmon: Add completion infrastructure for firmware requests (Sanman Pradhan) [Orabug: 39203185]
- tools: ynl: add install target for generated content (Jan Stancek) [Orabug: 39203185]
- eth: fbnic: Revert "eth: fbnic: Add hardware monitoring support via HWMON interface" (Su Hui) [Orabug: 39203185]
- eth: fbnic: update fbnic_poll return value (Mohsin Bashir) [Orabug: 39203185]
- RDMA/efa: Align interrupt related fields to same type (Yonatan Nachum) [Orabug: 39203185]
- eth: fbnic: support ring channel set while up (Jakub Kicinski) [Orabug: 39203185]
- eth: fbnic: support ring channel get and set while down (Jakub Kicinski) [Orabug: 39203185]
- eth: fbnic: centralize the queue count and NAPI<>queue setting (Alexander Duyck) [Orabug: 39203185]
- eth: fbnic: add IRQ reuse support (Jakub Kicinski) [Orabug: 39203185]
- eth: fbnic: store NAPIs in an array instead of the list (Jakub Kicinski) [Orabug: 39203185]
- eth: fbnic: let user control the RSS hash fields (Alexander Duyck) [Orabug: 39203185]
- eth: fbnic: support setting RSS configuration (Alexander Duyck) [Orabug: 39203185]
- eth: fbnic: don't reset the secondary RSS indir table (Jakub Kicinski) [Orabug: 39203185]
- eth: fbnic: support querying RSS config (Alexander Duyck) [Orabug: 39203185]
- eth: fbnic: reorder ethtool code (Jakub Kicinski) [Orabug: 39203185]
- selftests: net: Add a VLAN bridge binding selftest (Petr Machata) [Orabug: 39203185]
- selftests: net: lib: Add a couple autodefer helpers (Petr Machata) [Orabug: 39203185]
- xsk: add generic XSk &xdp_buff -> skb conversion (Alexander Lobakin) [Orabug: 39203185]
- xdp: add generic xdp_build_skb_from_buff() (Alexander Lobakin) [Orabug: 39203185]
- xdp: add generic xdp_buff_add_frag() (Alexander Lobakin) [Orabug: 39203185]
- xdp: make __xdp_return() MP-agnostic (Alexander Lobakin) [Orabug: 39203185]
- xdp: get rid of xdp_frame::mem.id (Alexander Lobakin) [Orabug: 39203185]
- selftests: forwarding: Add a selftest for the new reserved_bits UAPI (Petr Machata) [Orabug: 39203185]
- selftests: net: lib: Add several autodefer helpers (Petr Machata) [Orabug: 39203185]
- selftests: net: lib: Rename ip_link_master() to ip_link_set_master() (Petr Machata) [Orabug: 39203185]
- eth: fbnic: add RPC hardware statistics (Sanman Pradhan) [Orabug: 39203185]
- eth: fbnic: add PCIe hardware statistics (Sanman Pradhan) [Orabug: 39203185]
- eth: fbnic: add basic debugfs structure (Jakub Kicinski) [Orabug: 39203185]
- eth: fbnic: add missing header guards (Jakub Kicinski) [Orabug: 39203185]
- eth: fbnic: add missing SPDX headers (Jakub Kicinski) [Orabug: 39203185]
- virtio_ring: remove API virtqueue_set_dma_premapped (Xuan Zhuo) [Orabug: 39203185]
- virtio-net: rq submits premapped per-buffer (Xuan Zhuo) [Orabug: 39203185]
- virtio_ring: introduce add api for premapped (Xuan Zhuo) [Orabug: 39203185]
- virtio_ring: perform premapped operations based on per-buffer (Xuan Zhuo) [Orabug: 39203185]
- virtio_ring: packed: record extras for indirect buffers (Xuan Zhuo) [Orabug: 39203185]
- virtio_ring: split: record extras for indirect buffers (Xuan Zhuo) [Orabug: 39203185]
- virtio_ring: introduce vring_need_unmap_buffer (Xuan Zhuo) [Orabug: 39203185]
- selftests: net: fdb_notify: Add a test for FDB notifications (Petr Machata) [Orabug: 39203185]
- selftests: net: lib: Add kill_process (Petr Machata) [Orabug: 39203185]
- selftests: net: lib: Move checks from forwarding/lib.sh here (Petr Machata) [Orabug: 39203185]
- selftests: net: lib: Move tests_run from forwarding/lib.sh here (Petr Machata) [Orabug: 39203185]
- eth: fbnic: Add support to dump registers (Mohsin Bashir) [Orabug: 39203185]
- tools: ynl: extend CFLAGS to keep options from environment (Jan Stancek) [Orabug: 39203185]
- virtio_vdpa: remove redundant check on desc (Colin Ian King) [Orabug: 39203185]
- virtio_fs: store actual queue index in mq_map (Max Gurtovoy) [Orabug: 39203185]
- virtio: Make vring_new_virtqueue support packed vring (Wenyu Huang) [Orabug: 39203185]
- RDMA/bnxt_re: Add set_func_resources support for P5/P7 adapters (Kalesh Ap) [Orabug: 39203185]
- selftests: net: Add busy_poll_test (Joe Damato) [Orabug: 39203185]
- eth: fbnic: Add support to write TCE TCAM entries (Mohsin Bashir) [Orabug: 39203185]
- selftests: net: include lib/sh/*.sh with lib.sh (Matthieu Baerts) [Orabug: 39203185]
- virtio_net: rx remove premapped failover code (Xuan Zhuo) [Orabug: 39203185]
- virtio_net: enable premapped mode for merge and small by default (Xuan Zhuo) [Orabug: 39203185]
- virtio_net: big mode skip the unmap check (Xuan Zhuo) [Orabug: 39203185]
- gpiolib: remove leftover spinlock bits (Bartosz Golaszewski) [Orabug: 39203185]
- dma-mapping: use macros to define events in a class (Sean Anderson) [Orabug: 39203185]
- RDMA/bnxt_re: Add support for modify_device hook (Kalesh Ap) [Orabug: 39203185]
- bnxt_en: Update firmware interface to 1.10.3.97 (Michael Chan) [Orabug: 39203185]
- selftests: TBF: Use defer for test cleanup (Petr Machata) [Orabug: 39203185]
- selftests: forwarding: lib: Allow passing PID to stop_traffic() (Petr Machata) [Orabug: 39203185]
- selftests: forwarding: Add a fallback cleanup() (Petr Machata) [Orabug: 39203185]
- eth: fbnic: Add hardware monitoring support via HWMON interface (Sanman Pradhan) [Orabug: 39203185]
- eth: fbnic: add ethtool timestamping statistics (Vadim Fedorenko) [Orabug: 39203185]
- eth: fbnic: add TX packets timestamping support (Vadim Fedorenko) [Orabug: 39203185]
- eth: fbnic: add RX packets timestamping support (Vadim Fedorenko) [Orabug: 39203185]
- eth: fbnic: add initial PHC support (Vadim Fedorenko) [Orabug: 39203185]
- eth: fbnic: add software TX timestamping support (Vadim Fedorenko) [Orabug: 39203185]
- Fix typos in GPIO TODO document (Shivam Chaudhary) [Orabug: 39203185]
- uek-rpm/modules.yaml.S.onos: Add Arista modules (Dara Stotland) [Orabug: 39960978]
- vrm: Add driver for Infineon POLs and controllers (Justin Oliver) [Orabug: 39960978]
- vrm: Fork PMBus core into Arista namespace (Justin Oliver) [Orabug: 39960978]
- vrm: Import PMBus core from SONiC kernel (Justin Oliver) [Orabug: 39960978]
- fan-cpld: rename minke-fan-cpld to arista-fan-cpld (Arista-Hpandya) [Orabug: 39960978]
- uek-rpm: clean up failed kernel installation (Sagar Sagar) [Orabug: 39971109]
- eth: lan743x: migrate to new RXFH callbacks (Jakub Kicinski) [Orabug: 39991891]
- net: Account VLAN RPS drops (Sherry Yang) [Orabug: 40007587]
- vhost-scsi: use kvzalloc for vq array allocation (Dongli Zhang) [Orabug: 40015355]

[6.12.0-207.109.3]
- net: Work around Marvell NIC TX stalls (Wengang Wang) [Orabug: 39766659]
- uek-rpm: BF3: Restore some configs disabled between OL8 & OL9, like compaction (Jeremy Tang) [Orabug: 39931154]
- arm64: dts: amd: ubootenv and a35 gold uboot flash partition fix. (#37) (Rahul Shekhar) [Orabug: 39976184]
- arm64: configs: salina_gold: enable MCTP I2C transport and I2C designware slave (#622) (#36) (Rahul Shekhar) [Orabug: 39976184]
- spi: cadence-quadspi: salina: disable STIG mode (#624) (#35) (Rahul Shekhar) [Orabug: 39976184]
- mtd: spi-nor: gigadevice: add support for GD55LF02GF (#34) (Rahul Shekhar) [Orabug: 39976184]
- LTS version: v6.12.109 (Sherry Yang)
- mm/rmap: use huge_ptep_get() in try_to_unmap_one() (Dev Jain)
- mm: avoid unnecessary use of is_swap_pmd() (Lorenzo Stoakes)
- platform/chrome: sensorhub: Fix dropped timestamp events and log spam (Tzung-Bi Shih)
- udf: Fix i_lenExtents truncation on 32-bit kernels (Zhan Xusheng)
- timer: Keep debugobjects state consistent in migrate_timer_list() (Thomas Gleixner)
- taskstats: fix cpumask parsing cutting off the last character (Bradley Morgan)
- smack: fix cred UAF in smack_file_send_sigiotask() (Jann Horn)
- signal: avoid shared siginfo namespace rewrites (Bradley Morgan) [Orabug: 40072685] {CVE-2026-93222}
- sticon/parisc: Detect default STI graphics card for console output (Helge Deller)
- tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (Myeonghun Pak) [Orabug: 40020405] {CVE-2026-80930}
- xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc() (Zi Yan)
- w1: ds28e17: reject an oversize length on an I2C block read (Maoyi Xie)
- vsock/virtio: flush works in dependency order (Chengfeng Ye) [Orabug: 40020417] {CVE-2026-80932}
- wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (Runyu Xiao)
- wifi: rtw88: pci: fix resource leak on failed NAPI setup (Dawei Feng) [Orabug: 40020438] {CVE-2026-80940}
- wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (Abdun Nihaal) [Orabug: 40020440] {CVE-2026-80941}
- wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() (Abdun Nihaal)
- wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids (Runyu Xiao)
- wifi: rtl818x: initialize eeprom_93cx6 struct to zero (Stanislaw Gruszka)
- wifi: mwifiex: Detach sync cmd buffer on interrupted wait (Fabio Estevam) [Orabug: 40020449] {CVE-2026-80944}
- crypto: sun8i-ss - Remove crypto_rng interface (Eric Biggers)
- crypto: sun8i-ce - Remove crypto_rng interface (Eric Biggers)
- wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop (Fan Wu) [Orabug: 40020463] {CVE-2026-80947}
- wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (Abdun Nihaal) [Orabug: 40020472] {CVE-2026-80949}
- i3c: master: svc: bound IBI payload to the requested max_payload_len (Maoyi Xie)
- i3c: master: Fix info leak and UAF in device unregister path (Adrian Hunter)
- dm-switch: use WRITE_ONCE() in switch_region_table_write() (Xu Wang)
- dm-stats: fix a crash if allocation of per-cpu data fails (Mikulas Patocka) [Orabug: 40020502] {CVE-2026-80963}
- arch_numa: avoid false positive fortify warning in setup_node_to_cpumask_map() (Nathan Chancellor)
- PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (Naman Jain)
- KVM: selftests: Remove duplicate LAUNCH_UPDATE_VMSA call in SEV-ES migrate test (Sean Christopherson)
- rust: rust_is_available: warn for bindgen < 0.72.1 && libclang >= 22 (Miguel Ojeda)
- x86/sev: Fix broken SNP support with KVM module built-in (Ashish Kalra)
- iommu/amd: remove return value of amd_iommu_detect (Shiyuan Gao)
- ring-buffer: Fix subbuf resize race with ring buffer readers (Vincent Donnefort) [Orabug: 40021976] {CVE-2026-89771}
- ALSA: virmidi: Check card index validity at probe (Takashi Iwai) [Orabug: 40020509] {CVE-2026-80964}
- ALSA: serial-u16550: Check card index validity at probe (Takashi Iwai) [Orabug: 40020517] {CVE-2026-80965}
- ALSA: portman2x4: Check card index validity at probe (Takashi Iwai)
- ALSA: pcxhr: initialize mutexes before requesting threaded IRQ (Runyu Xiao) [Orabug: 40020527] {CVE-2026-80967}
- ALSA: mts64: Check card index validity at probe (Takashi Iwai)
- ALSA: mpu401: Check card index validity at probe (Takashi Iwai) [Orabug: 40020540] {CVE-2026-80969}
- ALSA: bcd2000: clear the URB pointers on disconnect (Baul Lee) [Orabug: 40020545] {CVE-2026-80971}
- ALSA: aloop: Check card index validity at probe (Takashi Iwai) [Orabug: 40020552] {CVE-2026-80972}
- ALSA: 6fire: bound the MIDI event length from the device (Baul Lee) [Orabug: 40020556] {CVE-2026-80973}
- mfd: sm501: Fix potential memory leaks during remove (Abdun Nihaal) [Orabug: 40020560] {CVE-2026-80974}
- seg6: reset IP6CB after IPv6 decapsulation (Zhiling Zou) [Orabug: 40020567] {CVE-2026-80976}
- net: skbuff: don't touch shared zerocopy state in skb_tx_error() (Norbert Szetei) [Orabug: 40020573] {CVE-2026-80977}
- net: fix spurious TX timeout after dev_activate() (Breno Leitao)
- net: cap advertised IP tunnel headroom (Zhiling Zou) [Orabug: 40020584] {CVE-2026-80978}
- net/smc: unregister the connection before draining the rx tasklet (Bryam Vargas)
- net/smc: fix use-after-free in smc_rx_pipe_buf_release() (Hidayath Khan)
- net/smc: fix socket refcount leak in smc_switch_conns() (Hidayath Khan)
- net/smc: do not dereference an unset send buffer on the SMC-D teardown path (Bryam Vargas)
- net: ntb_netdev: Count packets dropped on RX refill failure (Koichiro Den)
- net: ntb_netdev: Avoid double-accounting netif_rx() drops (Koichiro Den)
- NTB: ntb_transport: Reject oversized TX buffers (Koichiro Den) [Orabug: 40020616] {CVE-2026-80987}
- NTB: ntb_transport: Fail TX enqueue when the QP link is down (Koichiro Den) [Orabug: 40020620] {CVE-2026-80988}
- NTB: ntb_transport: Recycle TX entries before client callbacks (Koichiro Den)
- net: thunderbolt: Mark the connection down when bringing it up fails (Fan Ye) [Orabug: 40020626] {CVE-2026-80989}
- net: thunderbolt: Release the Rx HopID that was handed out on mismatch (Fan Ye) [Orabug: 40020630] {CVE-2026-80990}
- net: ravb: serialize PTP clock teardown (Luoxuanqiang)
- net: ravb: avoid dereferencing an invalid PTP clock (Luoxuanqiang)
- net: openvswitch: fix nf_connlabels leak in ovs_ct_init (Ruoyu Wang)
- net: openvswitch: fix flow mask use-after-free on flow deletion (Ilya Maximets) [Orabug: 40020650] {CVE-2026-80994}
- net: l2tp: do not propagate multicast notification errors (Zihan Xi) [Orabug: 40020658] {CVE-2026-80996}
- net: ipa: fix stalled modem TX queue after runtime resume (Jorijn van der Graaf)
- net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO (Ahmad Fatoum) [Orabug: 40020667] {CVE-2026-80999}
- net: tun: bound receive headroom (Asim Viladi Oglu Manizada) [Orabug: 40020671,40035126] {CVE-2026-81000}
- net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition (Fabio Porcedda)
- slip: fix use-after-free in sl_sync() (Aleksandr Khromov) [Orabug: 40020675] {CVE-2026-81001}
- xdp: fix zero-copy frame layout (Weiming Shi) [Orabug: 40020680] {CVE-2026-81002}
- net/iucv: filter frames in afiucv_hs_rcv() by ingress device (Alexandra Winter)
- ipmi: si: Fix NULL pointer dereference after failed registration (Seiji Nishikawa) [Orabug: 40020692] {CVE-2026-81005}
- ipmi: ipmb: validate write message length (Yousef Alhouseen)
- interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (Kuan-Wei Chiu) [Orabug: 40020703] {CVE-2026-81008}
- platform/x86: hp-bioscfg: warn on element type mismatch instead of failing (Muhammad Bilal)
- platform/x86: hp-bioscfg: pass validated element count to package parsers (Muhammad Bilal) [Orabug: 40020712] {CVE-2026-81011}
- platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed (Muhammad Bilal)
- platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() (Muhammad Bilal) [Orabug: 40020714] {CVE-2026-81012}
- platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password (Muhammad Bilal)
- platform/x86: hp-bioscfg: fix heap OOB read on empty password write (Muhammad Bilal) [Orabug: 40020717] {CVE-2026-81013}
- platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() (Muhammad Bilal) [Orabug: 40020720] {CVE-2026-81014}
- platform/x86: hp-bioscfg: bound ordered-list parsing by the package count (Muhammad Bilal)
- platform/x86: hp-bioscfg: advance elem past consumed array elements (Muhammad Bilal)
- platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS (Muhammad Bilal)
- platform/chrome: sensorhub: Bound the EC-reported sensor number (Bryam Vargas) [Orabug: 40020727] {CVE-2026-81017}
- platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path (Ma Ke)
- platform/x86: ISST: Return error during profile addition (Srinivas Pandruvada)
- platform/x86: ISST: Validate parameter for frequency and priority (Srinivas Pandruvada)
- platform/x86: ISST: Validate parameter for core power state (Srinivas Pandruvada)
- platform/x86: ISST: Validate logical CPU id and clos id (Srinivas Pandruvada) [Orabug: 40020738] {CVE-2026-89438}
- platform/x86: ISST: Use PP level enable mask (Srinivas Pandruvada)
- platform/x86: ISST: Just allow 2 bits for SST feature enable (Srinivas Pandruvada)
- platform/x86: ISST: Add a NULL check for sst_inst[] (Srinivas Pandruvada) [Orabug: 40020742] {CVE-2026-89439}
- mmc: via-sdmmc: stop card-detect handling on probe failure (Fan Wu) [Orabug: 40020745] {CVE-2026-89440}
- platform/x86: ISST: Validate socket ID in clos_assoc ioctl (Hyeongjun An) [Orabug: 40020755] {CVE-2026-89442}
- platform/x86: ISST: Validate level in perf mask ioctls (Hyeongjun An) [Orabug: 40020757] {CVE-2026-89443}
- platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (Hyeongjun An) [Orabug: 40020759] {CVE-2026-89444}
- iommu/vt-d: Force requesting ACS when tboot is enabled (Kevin Tian) [Orabug: 40020767] {CVE-2026-89448}
- iommu/vt-d: Fix no_iommu to disable platform opt-in (Kevin Tian)
- iommu/arm-smmu-v3: Manage teardown with devm (Shameer Kolothum) [Orabug: 40072617] {CVE-2026-93205}
- iommu/sva: Set handle->dev before the SVA handle is visible (Shuai Xue) [Orabug: 40020774] {CVE-2026-89451}
- iommu/amd: Put PCI device after handling PPR faults (Shuai Xue) [Orabug: 40020782] {CVE-2026-89453}
- PCI/proc: Warn on writes to kernel-exclusive config space regions (Krzysztof Wilczyński)
- PCI/proc: Use file_ns_capable() when checking config space read access (Krzysztof Wilczyński) [Orabug: 40072622] {CVE-2026-93206}
- PCI/proc: Avoid spurious runtime PM wakeup on config space accesses (Krzysztof Wilczyński)
- PCI/MSI: Enable memory decoding before restoring MSI-X messages (Farhan Ali)
- PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses (Krzysztof Wilczyński)
- PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] (Tim Harvey)
- PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() (Ali Tariq)
- PCI: plda: Fix use-after-free of event IRQs during teardown (Ali Tariq)
- PCI: meson: Fix GPIO state while requesting PERST# (Ronald Claveau)
- PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk (Mohamad Raizudeen)
- s390/dasd: Propagate partial completion length across ERP recovery (Stefan Haberland)
- s390/dasd: Guard sysfs discipline callbacks against unallocated private data (Stefan Haberland)
- s390/dasd: Do not complete a failed ESE read as successful (Stefan Haberland)
- s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks (Thomas Richter)
- power: supply: max17040: synchronize work cancellation on suspend (Jianing Li) [Orabug: 40020806] {CVE-2026-89461}
- power: supply: max17040: drop incorrect I2C functionality check (Jianing Li)
- power: supply: max17040: propagate register read errors (Jianing Li) [Orabug: 40020810] {CVE-2026-89462}
- power: supply: ucs1002: fix use-after-free on remove (Fan Wu)
- power: supply: twl4030_charger: cancel workers via devm (Maoyi Xie)
- power: supply: rt9455: quiesce delayed work before teardown (Fan Wu)
- power: supply: qcom_battmgr: terminate the strings from firmware (Hyeongjun An)
- power: supply: lp8788-charger: fix use-after-free on remove (Fan Wu)
- power: supply: lp8727: fix use-after-free in lp8727_release_irq() (Fan Wu) [Orabug: 40020837] {CVE-2026-89469}
- power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS (Jameson Thies)
- power: supply: cros_usbpd-charger: bound the EC-reported port count (Bryam Vargas)
- power: supply: charger-manager: register regulators before exposing sysfs (Fan Wu) [Orabug: 40020850] {CVE-2026-89472}
- power: supply: bq25890: Fix power_supply reference leak (Ma Ke)
- power: supply: bq256xx: drain usb_work before freeing the charger (Fan Wu)
- power: supply: bq24257: fix use-after-free on remove (Fan Wu)
- sctp: fix stream->outcnt underflow on duplicate RECONF responses (Jun Yang) [Orabug: 40020864] {CVE-2026-89476}
- sctp: distinguish sequence zero from wildcard in reconf lookup (Jun Yang)
- sctp: fix NULL deref on untransmitted RECONF completion (Weiming Shi) [Orabug: 40020868] {CVE-2026-89477}
- sctp: drop a chunk if its transport was removed (Hyunwoo Kim) [Orabug: 40020873] {CVE-2026-89478}
- sctp: stop processing a packet once its association is deleted (Hyunwoo Kim) [Orabug: 40020878] {CVE-2026-89479}
- nvme-tcp: reject a read that transferred too few bytes (Yehyeong Lee) [Orabug: 40020883] {CVE-2026-89480}
- nvme-tcp: fix host memory disclosure on R2T for a read command (Yehyeong Lee) [Orabug: 40020887] {CVE-2026-89481}
- nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone (Yehyeong Lee) [Orabug: 40020894] {CVE-2026-89482}
- nvme-pci: disable controller on admin queue IRQ setup failure (Myeonghun Pak)
- nvme: zero the discard fallback page (Yehyeong Lee) [Orabug: 40020899] {CVE-2026-89483}
- nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in error path (Ewan D. Milne)
- lockd: fix NULL dereference on lockowner allocation failure (Shuangpeng Bai) [Orabug: 40020903] {CVE-2026-89484}
- lockd: pin next file across nlm_inspect_file lock-drop (Michael Bommarito) [Orabug: 40020907] {CVE-2026-89485}
- hwmon: (max6621) fix temperature clamp range (Cong Nguyen)
- hwmon: (max6621) fix negative temperature offset and crit readings (Cong Nguyen)
- ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC (Christopher Tolang)
- arm64: compat: Fix decrementing LDM/STM alignment emulation (Karl Mehltretter)
- ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion (Hyeongjun An)
- openvswitch: only skb_tx_error() a packet we are about to drop (Norbert Szetei) [Orabug: 40020914] {CVE-2026-89487}
- openrisc: fix arbitrary kernel memory access via or1k_atomic syscall (Ali Ahmet Memis)
- ocfs2: fix readdir position truncation on 32-bit kernels (Zhan Xusheng) [Orabug: 40020926] {CVE-2026-89490}
- ocfs2: cluster: fix o2hb_dependent_users leak on pin failure (Joseph Qi)
- ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from drop_item (Joseph Qi)
- ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() (Joseph Qi) [Orabug: 40020930] {CVE-2026-89491}
- ocfs2: validate rl_used against rl_count in refcount block validator (Ibrahim Hashimov) [Orabug: 40020940] {CVE-2026-89493}
- ocfs2: validate lengths in dlm_mig_lockres_handler (Bryam Vargas) [Orabug: 40020945] {CVE-2026-89494}
- ocfs2: bound namelen in dlm_migrate_request_handler (Bryam Vargas) [Orabug: 40020951] {CVE-2026-89495}
- ocfs2: always run deallocs on copy-on-write completion (Dmitry Antipov) [Orabug: 40020957] {CVE-2026-89496}
- orangefs: skip leading spaces before parsing client debug masks (Zhiling Zou)
- orangefs: fix double-free of trailer_buf on readdir copy failure (Yifei Gao)
- ring-buffer: Hold cpu_buffer::lock when resizing a subbuf (Vincent Donnefort) [Orabug: 40020973] {CVE-2026-89501}
- ring-buffer: Free cpu_buffer::free_page with subbuf_order (Vincent Donnefort) [Orabug: 40020975] {CVE-2026-89502}
- regulator: qcom-refgen: correct the regulator type to CURRENT (Kathiravan Thirumoorthy)
- regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata (Xu Wang)
- regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (Xu Wang)
- RDMA/ucma: Lock the handler in ucma_set_ib_path() (Norbert Szetei) [Orabug: 40020988] {CVE-2026-89508}
- RDMA/cxgb4: Cancel reg_work before freeing device on remove (Fan Wu) [Orabug: 40020993] {CVE-2026-89510}
- qede: Fix NULL pointer dereference in TPA fragment processing (Vaibhav Nagare) [Orabug: 40020997] {CVE-2026-89511}
- remoteproc: scp: Fix device reference leak on failed lookup (Johan Hovold)
- riscv: acpi: Handle LPI architectural context loss flags (Peixin Xie)
- arm64: dts: rockchip: Fix rk3399-roc-pc-plus analog audio (Fabio Estevam)
- arm64: dts: rockchip: fix eMMC reset polarity on PX30 Ringneck (Quentin Schulz)
- arm64: dts: qcom: sm6115-pro1x: Correct touchscreen GPIO flags (Krzysztof Kozlowski)
- rpmsg: glink: smem: order FIFO read after availability check (Chunkai Deng)
- scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables() (Petr Vaganov) [Orabug: 40021008] {CVE-2026-89515}
- staging: media: tegra-video: vi: fix probe failure on skipped last port (Hao-Qun Huang)
- staging: media: tegra-video: fix of_node_put() on VIP parse errors (Hao-Qun Huang)
- wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (Doruk Tan Ozturk) [Orabug: 40021028] {CVE-2026-89524}
- udf: reject VAT indexes equal to the entry count (David Lee) [Orabug: 40021034] {CVE-2026-89525}
- svcrdma: Validate Read chunk positions before reconstruction (Chuck Lever) [Orabug: 40021039] {CVE-2026-89526}
- svcrdma: Reject inline replies that overflow the pull-up buffer (Chuck Lever) [Orabug: 40021052] {CVE-2026-89530}
- svcrdma: Reject connection when transport allocation fails (Chuck Lever) [Orabug: 40021062] {CVE-2026-89531}
- svcrdma: Fix unmatched rn_unregister on failed accept (Chris Mason) [Orabug: 40072695] {CVE-2026-93224}
- svcrdma: Fix pcl_for_each_segment for empty chunks (Chris Mason) [Orabug: 40021066] {CVE-2026-89532}
- svcrdma: Fix offset arithmetic in read_chunk_range (Chris Mason) [Orabug: 40021069] {CVE-2026-89533}
- SUNRPC: wait for in-flight client TLS handshake callback (Jérémy Jean) [Orabug: 40021077] {CVE-2026-89536}
- SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field (Chuck Lever) [Orabug: 40021085] {CVE-2026-89538}
- SUNRPC: reject duplicate CREDS_VALUE options (Chris Mason) [Orabug: 40021089] {CVE-2026-89539}
- sunrpc: init gssp_lock before publishing proc entry (Chris Mason) [Orabug: 40021093] {CVE-2026-89540}
- SUNRPC: harden gss_unwrap_resp_priv length checks (Chris Mason) [Orabug: 40021098] {CVE-2026-89541}
- SUNRPC: harden gss_krb5_unwrap_v2 against short tokens (Chris Mason) [Orabug: 40021114] {CVE-2026-89542}
- SUNRPC: Guard svcauth_gss_release() dispatch on rq_auth_stat (Chris Mason)
- SUNRPC: Check svc pool percpu counter allocation (Chuck Lever) [Orabug: 40021150] {CVE-2026-89547}
- SUNRPC: always drain cache_cleaner before destroying a cache_detail (Jeff Layton) [Orabug: 40021153] {CVE-2026-89548}
- sunrpc: route to a populated pool in svc_pool_for_cpu() (Jeff Layton) [Orabug: 40021158] {CVE-2026-89549}
- SUNRPC: svcauth_gss: enforce krb5 token minimum length (Chris Mason) [Orabug: 40021162] {CVE-2026-89550}
- SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry (Chris Mason) [Orabug: 40072626] {CVE-2026-93207}
- SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow (Chris Mason) [Orabug: 40021167] {CVE-2026-89551}
- params: fix charp corruption on allocation failure (Jiacheng Yu) [Orabug: 40021171] {CVE-2026-89552}
- nouveau/gem: reserve the bo in the info ioctl around the vma lookup (Dave Airlie) [Orabug: 40021175] {CVE-2026-89553}
- mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction (Harshit Varu) [Orabug: 40021180] {CVE-2026-89554}
- mpls: reload header after pskb_may_pull() (Qing Ming) [Orabug: 40021183] {CVE-2026-89555}
- md: do overflow check for sb->bblog_shift in super_1_load() (Coly Li) [Orabug: 40021189] {CVE-2026-89557}
- md/raid10: fix still_degraded being inverted in raid10_sync_request() (Yunye Zhao) [Orabug: 40021194] {CVE-2026-89558}
- mailbox: qcom-ipcc: fix duplicate channel allocation across holes (Anup Vishwakarma)
- libnvdimm/labels: Prevent integer overflow in __nd_label_validate() (Bryam Vargas) [Orabug: 40021196] {CVE-2026-89559}
- ipv6: use RCU iterator to dump route exceptions (Yuyang Huang) [Orabug: 40072698] {CVE-2026-93226}
- ip6_gre: fix hardware header length for NBMA tunnels (Zhiling Zou) [Orabug: 40021213] {CVE-2026-89562}
- ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit() (Zhiling Zou) [Orabug: 40021219] {CVE-2026-89563}
- ipip: fix skb leak in collect_md mode when metadata_dst allocation fails (Anton Danilov) [Orabug: 40021228] {CVE-2026-89565}
- jbd2: check need_resched() when skipping busy checkpoint buffers (Max Kellermann) [Orabug: 40021232] {CVE-2026-89566}
- jbd2: bound shrinker scans by examined checkpoint buffers (Max Kellermann) [Orabug: 40021240] {CVE-2026-89567}
- kasan: fix cache shrink race with CPU hotplug (Sh_Def)
- Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request (Ibrahim Abdelkader)
- Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative (Guangshuo Li)
- Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative (Guangshuo Li)
- Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection (Valentin Kindschi)
- Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb (Xin Chen) [Orabug: 40072632] {CVE-2026-93209}
- Bluetooth: hci_conn: re-enable advertising only for peripheral role (Valentin Kindschi)
- Bluetooth: RFCOMM: serialize security confirmation handling (Chengfeng Ye) [Orabug: 40021244] {CVE-2026-89569}
- Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready (Hang Nan) [Orabug: 40010342] {CVE-2026-80914}
- Bluetooth: hci_uart: Fix false success return in hci_uart_setup() (Gongwei Li)
- Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative (Guangshuo Li)
- Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378 (Lorenzo Stoakes)
- cxl/pmem: Format the nvdimm serial number as unsigned decimal (Alison Schofield)
- cpufreq: schedutil: Fix rate limit overflow (Sh_Def)
- coresight: etm3x: Fix cntr_val_show() to match cntr_val_store() behavior (Kuan-Wei Chiu)
- dm array: reject an array block whose value size is not the caller's (Bryam Vargas) [Orabug: 40021259] {CVE-2026-89573}
- dm array: validate array block headers on read (Bryam Vargas) [Orabug: 40021267] {CVE-2026-89574}
- dm raid1: reserve space for NUL-terminator in build_constructor_string() (Ilya Krutskih) [Orabug: 40021273] {CVE-2026-89575}
- dm-era: fix shadowed superblock leak on take-snap failure (Liyouhong) [Orabug: 40021281] {CVE-2026-89576}
- bpf: Harden bloom filter sizing and indexing on 32-bit kernels (Jérémy Jean) [Orabug: 40021290] {CVE-2026-89579}
- bpf: Disable preemption in __bpf_get_stack (Daniel Borkmann) [Orabug: 40021292] {CVE-2026-89580}
- bpf, x86: Fix per-CPU address resolution into an extended register (Vineet Gupta) [Orabug: 40021299] {CVE-2026-89581}
- bnx2x: fix double free in bnx2x_init_firmware() error path (Jiangshan Yi) [Orabug: 40021302] {CVE-2026-89582}
- Bluetooth: eir: Fix OOB read in eir_get_service_data() (Hyeongjun An) [Orabug: 40021306] {CVE-2026-89583}
- Bluetooth: btusb: Add ASUS USB-BT600 for Realtek 8761CU (Christoph Zwerschke)
- Bluetooth: btusb: Add ASUS USB-BT540 for Realtek 8761CU (Christoph Zwerschke)
- block: set QUEUE_FLAG_DYING unconditionally in blk_mark_disk_dead() (Lianqin Hu)
- auxdisplay: charlcd: cancel backlight work on registration failure (Hongyan Xu) [Orabug: 40021313] {CVE-2026-89585}
- ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes (Niklas Cassel) [Orabug: 40021319] {CVE-2026-89586}
- ARM: 9477/1: Disable broken eBPF JIT on the Risc PC (Ethan Nelson-Moore)
- alpha: marvel: Fix lock ordering in init_io7_irqs() (Matt Turner)
- alpha: marvel: Fix irq_set_status_flags to use correct IRQ number (Matt Turner)
- alpha/PCI: Fix I/O port accessor argument order in pci_legacy_write() (Krzysztof Wilczyński)
- ACPI: pfr_update: fix stack buffer overflow in query_capability() (Anirudh Prasad) [Orabug: 40021327] {CVE-2026-89587}
- ACPI: APEI: GHES: fix ARM section length accounting after header (Zheng Tan) [Orabug: 40022004] {CVE-2026-89588}
- ACPI: APEI: Fix ERST timeout unit conversion (Nirmoy Das)
- hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device (Ivaylo Dimitrov)
- fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration (Ang Tien Sung)
- forcedeth: fix off-by-one when saving/restoring non-PCI config space (Marek Czernohous) [Orabug: 40021353] {CVE-2026-89596}
- fbdev: uvesafb: unregister connector callback on init failure (Myeonghun Pak)
- fbdev: ssd1307fb: defer I2C transfers from damage callbacks (Sh_Def) [Orabug: 40021368] {CVE-2026-89598}
- fbdev: pvr2fb: correct user pointer annotation and sentinel initializer (Florian Fuchs)
- fbdev: omapfb: panel-dsi-cm: initialize lock before registering display (Runyu Xiao)
- fat: restore original value when fat_ent_write failed (Yemu Lu)
- efivarfs: Rate limit statfs() handler (Ard Biesheuvel) [Orabug: 40021403] {CVE-2026-89604}
- ecryptfs: show filename encryption options (Chenyichong)
- ecryptfs: release message context on send failure (Chenyichong)
- ecryptfs: reject too-small tag 70 packets (Chenyichong) [Orabug: 40021412] {CVE-2026-89606}
- ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet (Ji'An Zhou) [Orabug: 40021418] {CVE-2026-89607}
- ecryptfs: pass packet set buffer size to parser (Chenyichong) [Orabug: 40021427] {CVE-2026-89608}
- ecryptfs: hold msg ctx list lock when cleaning daemon queue (Chenyichong)
- ecryptfs: fix tag 11 packet exact-fit size check (Chenyichong)
- eCryptfs: bound the packet-length peek to the user buffer (Pengpeng Hou)
- fs/ntfs3: bound page_lcns[] index by the log record (Konstantin Komarov)
- fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame() (Samuel Page)
- fs/ntfs3: validate dirty page table on log replay (Xiang Mei)
- eventfs: Initialize ei->children and ei->list in init_ei() (Deepanshu Kartikey) [Orabug: 40021475] {CVE-2026-89618}
- HID: mcp2221: validate report size in mcp2221_raw_event() (Jiangshan Yi)
- HID: mcp2221: stop device IO before hid_hw_stop (Jiangshan Yi)
- HID: sensor: custom: Fix field sysfs group cleanup on failure (Haoxiang Li) [Orabug: 40021497] {CVE-2026-89626}
- HID: roccat: free buffered reports when destroying device (Xu Rao) [Orabug: 40021501] {CVE-2026-89627}
- HID: picolcd: clamp eeprom debugfs read to bytes actually received (Ibrahim Hashimov) [Orabug: 40021506] {CVE-2026-89628}
- smb: client: harden DFS cache against invalid target hints (Fredric Cover) [Orabug: 40072635] {CVE-2026-93210}
- smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV (Frank Sorenson)
- smb: client: fix ALIGN() overflow in symlink_data() error context loop (Frank Sorenson) [Orabug: 40021526] {CVE-2026-89634}
- smb: client: clear ce->tgthint in free_tgts() (Fredric Cover) [Orabug: 40021529] {CVE-2026-89636}
- cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0 (Frank Sorenson) [Orabug: 40021546] {CVE-2026-89640}
- audit: avoid dropping live tree ref on fsnotify rule autoremove (Jérémy Jean) [Orabug: 40021556] {CVE-2026-89643}
- btrfs: drop recovered reloc root refs on recovery failure (Guanghui Yang) [Orabug: 40021567] {CVE-2026-89645}
- ceph: do not repeat ceph_trim_dentries() if no progress possible (Max Kellermann) [Orabug: 40021571] {CVE-2026-89647}
- ceph: bound xattr value length in __build_xattrs() (Michael Bommarito) [Orabug: 40021579] {CVE-2026-89649}
- ceph: bound num_export_targets array for mds info v2/v3 (Michael Bommarito) [Orabug: 40021585] {CVE-2026-89650}
- ceph: bound MDSCapAuth path and fs_name decode in handle_session() (Michael Bommarito) [Orabug: 40021589] {CVE-2026-89651}
- ceph: bound copied dentry name length in NFS export get_name (Michael Bommarito) [Orabug: 40021591] {CVE-2026-89652}
- ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode (Jérémy Jean) [Orabug: 40021597] {CVE-2026-89653}
- ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock (Xiubo Li) [Orabug: 40021605] {CVE-2026-89655}
- libceph: reject buckets with mismatched CRUSH ids (Jérémy Jean) [Orabug: 40021609] {CVE-2026-89656}
- libceph: validate OSD extent maps before cursor advance (Michael Bommarito) [Orabug: 40021614] {CVE-2026-89657}
- NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup (Chuck Lever) [Orabug: 40021617] {CVE-2026-89658}
- NFSD: Prevent lock owner use-after-free during client teardown (Chuck Lever) [Orabug: 40021631] {CVE-2026-89662}
- nfsd: revoke copy-notify stateids before dropping their reference (Jeff Layton) [Orabug: 40021635] {CVE-2026-89663}
- nfsd: reject reclaim LOCK after RECLAIM_COMPLETE (Jeff Layton)
- nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE (Robbie Ko)
- nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops (Robbie Ko) [Orabug: 40021649] {CVE-2026-89666}
- nfsd: initialize DRC hash table before registering shrinker (Jeff Layton) [Orabug: 40072640] {CVE-2026-93211}
- nfsd: initialize copy-notify stateid before publishing it (Jeff Layton) [Orabug: 40021656] {CVE-2026-89669}
- nfsd: gate nfs3 setacl by argp->mask (Chris Mason) [Orabug: 40021663] {CVE-2026-89671}
- nfsd: gate nfs2 setacl by argp->mask (Chuck Lever)
- nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo (Jeff Layton) [Orabug: 40021671] {CVE-2026-89673}
- nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget (Jeff Layton) [Orabug: 40021677] {CVE-2026-89674}
- nfsd: fix version mismatch loops in nfsd_acl_init_request() (Jeff Layton)
- nfsd: fix reply size estimate for GET_DIR_DELEGATION (Jeff Layton)
- nfsd: fix nfsd_file leak on inter-server COPY setup failure (Jeff Layton) [Orabug: 40021695] {CVE-2026-89680}
- nfsd: fix dentry ref leak on V4ROOT export filehandle lookup (Jeff Layton) [Orabug: 40021704] {CVE-2026-89683}
- nfsd: fix cpntf publish race in nfs4_init_cp_state (Chris Mason) [Orabug: 40021706] {CVE-2026-89684}
- nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke (Jeff Layton) [Orabug: 40021713] {CVE-2026-89686}
- nfsd: drop the stateid, not the stateowner, on seqid_op replay retry (Jeff Layton) [Orabug: 40021718] {CVE-2026-89688}
- nfsd: defer vfree of compound ops to fix rpc_status UAF (Jeff Layton) [Orabug: 40021721] {CVE-2026-89690}
- nfsd: clear opcnt on compound arg release to prevent OOB read (Jeff Layton) [Orabug: 40021724] {CVE-2026-89691}
- nfsd: check client ownership when cancelling a copy-notify stateid (Jeff Layton) [Orabug: 40021731] {CVE-2026-89694}
- nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref (Jeff Layton) [Orabug: 40021740] {CVE-2026-89696}
- nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry (Jeff Layton) [Orabug: 40072710] {CVE-2026-93229}
- nfsd: add filehandle match check to nfsd4_delegreturn() (Jeff Layton)
- nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() (Jeff Layton)
- nfsd: validate symlink target length in NFSv4 CREATE (Jeff Layton) [Orabug: 40021750] {CVE-2026-89699}
- nfsd: size fh_verify server sockaddr slot by xpt_locallen (Chris Mason) [Orabug: 40021759] {CVE-2026-89702}
- nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations (Zhenghang Xiao) [Orabug: 40021762] {CVE-2026-89703}
- nfsd: sample writeback error cursor before async COPY loop (Chuck Lever) [Orabug: 40021765] {CVE-2026-89704}
- nfsd: return NFS4ERR_NOTSUPP for unsupported netloc4 types (Jeff Layton)
- nfsd: Reset write verifier when async COPY writeback fails (Chuck Lever) [Orabug: 40021771] {CVE-2026-89706}
- nfsd: release path refs on follow_down() error (Chris Mason) [Orabug: 40021774] {CVE-2026-89707}
- pNFS: Fix EBUSY check in pnfs_layout_need_return (Tim Menninger)
- NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path (Junrui Luo) [Orabug: 40021787] {CVE-2026-89710}
- nfsd: guard nfsd_serv deref in nfsd_file_net_dispose (Chris Mason) [Orabug: 40072643] {CVE-2026-93212}
- NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check (Mike Snitzer) [Orabug: 40021790] {CVE-2026-89711}
- NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock (Michael Bommarito) [Orabug: 40021795] {CVE-2026-89712}
- NFSD: Fix off-by-one in DRC bucket pruning limit (Chuck Lever)
- NFSD: Encode only the status in NFS-ACL v2 GETACL error replies (Chuck Lever)
- NFSD: check truncate permission under inode lock (Chuck Lever) [Orabug: 40021799] {CVE-2026-89713}
- zsmalloc: account for handle size in class lookup (Longlong Xia)
- ubifs: fix out-of-bounds read in signature length check (Ibrahim Hashimov)
- of: fix out-of-bounds read in of_alias_scan() stem parser (Abdurrahman Hussain) [Orabug: 40072645] {CVE-2026-93213}
- nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation (Ryusuke Konishi)
- media: vicodec: fix out-of-bounds write in FWHT encoder (Junrui Luo)
- media: cec: stm32: prevent out-of-bounds write on RX overflow (Weigang He)
- lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() (Vincent Mailhol) [Orabug: 40021840] {CVE-2026-89726}
- HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature (Xingrui Li) [Orabug: 40021846] {CVE-2026-89729}
- fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write (Daisuke Matsuda)
- usb: gadget: f_fs: Prevent deadlock during ep0 read loop (Neill Kapron)
- usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() (Jeffin Philip)
- usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() (Yun Zhou)
- usb: gadget: midi2: remove default configfs groups on teardown (Joshua Crofts)
- usb: gadget: snps_udc_plat: clean up PHY on probe deferral (Myeonghun Pak)
- usb: gadget: u_audio: Fix use-after-free on sound card disconnect (Sonali Pradhan)
- usb: typec: ucsi: use UCSI_TIMEOUT_MS for sync command completion (Huang Wei)
- usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive() (Xu Yang)
- USB: phy: fsl-usb: fix missing static keywords (Johan Hovold)
- usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed (Fan Wu)
- usb: dwc2: gadget: Exit partial power down state when changing USB pull-up (Francesco Lavra)
- staging: greybus: hid: fix SET_REPORT return value (Hao-Qun Huang)
- serial: imx: serialize imx_uart_ports[] lifetime (Karl Mehltretter)
- Revert "media: v4l2-dev: fix error handling in __video_register_device()" (Hans Verkuil) [Orabug: 40021885] {CVE-2026-89741}
- rapidio: mport_cdev: fix use-after-free in dma_req_free() (James Kim)
- powerpc/powermac: fix OF node refcount (Bartosz Golaszewski)
- misc: nsm: bound the device-reported response length (Bryam Vargas)
- device property: fix infinite loop in fwnode_for_each_child_node() (Xu Yang) [Orabug: 40022018] {CVE-2026-89744}
- cdx: Fix double free when sysfs file creation fails (Prasanna Kumar T S M)
- tracing: Fix use-after-free with same-name named triggers (Sh_Def) [Orabug: 40021900] {CVE-2026-89746}
- tracing: Fix use-after-free in trace_pipe read on sub-buffer order change (Deepanshu Kartikey) [Orabug: 40021902] {CVE-2026-89747}
- tracing: Fix logged instance name on creation failure (Vincent Donnefort)
- tracing: Fix crash passing ERR_PTR to kthread_stop() (Sh_Def) [Orabug: 40021905] {CVE-2026-89749}
- tracing/user_events: Clear copied tracing state before fork duplication (Jérémy Jean)
- hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() (Sanman Pradhan)
- x86/tdx: Fix zero-extension for 32-bit port I/O (Kiryl Shutsemau)
- x86/insn-eval: Move assign_register() out of KVM as insn_assign_reg() (Kiryl Shutsemau)
- x86/tdx: Fix off-by-one in port I/O handling (Kiryl Shutsemau) [Orabug: 40021911] {CVE-2026-89751}
- tools/compiler: match glibc 2.42 definition of __attribute_const__ (Joy H.J. Lee)
- mm: mempolicy: fix automatic numa balancing for shmem (Johannes Weiner)
- mm: memcg: stop reclaim when a limit update is superseded (Zhangguopeng) [Orabug: 40021913] {CVE-2026-89752}
- mm/zswap: fix global shrinker when memory cgroup is disabled (Hao Jia)
- mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec() (Breno Leitao) [Orabug: 40021917] {CVE-2026-89753}
- mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch() (Breno Leitao) [Orabug: 40021925] {CVE-2026-89756}
- mm/kmemleak: avoid soft lockup when scanning task stacks (Breno Leitao)
- include/linux/list.h: mark list_add and __list_add as __always_inline (Jordan R Abrahams-Whitehead)
- apparmor: fix out-of-bounds write when null terminating a label vec (Hyunwoo Kim)
- apparmor: fix cred UAF caused by begin_current_label_crit_section() (Jann Horn) [Orabug: 40021947] {CVE-2026-89762}
- timers/itimer: Zero-init old itimerval before copy to userspace (Jérémy Jean) [Orabug: 40021961] {CVE-2026-89765}
- powerpc/pseries/iommu: switch to Default DMA window during kdump (Gaurav Batra)
- fs: fix user path of nested backing files (Baokun Li) [Orabug: 40022021] {CVE-2026-89768}
- clocksource/drivers/timer-sun4i: Advertise a real minimum delta (Felix Yan) [Orabug: 40072668] {CVE-2026-93219}
- alpha: don't leak hardware-fabricated FP exception bits to user space (Matt Turner)
- alpha: fix ieee_swcr_to_fpcr setting FPCR_DNOD unconditionally (Matt Turner)
- drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths (Srinivasan Shanmugam) [Orabug: 39653280] {CVE-2026-53313}
- wifi: ath11k: fix memory leaks in beacon template setup (Zilin Guan) [Orabug: 39622112] {CVE-2026-53113}
- wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req() (Zilin Guan) [Orabug: 39622083] {CVE-2026-53102}
- perf/x86/intel/uncore: Fix die ID init and look up bugs (Zide Chen) [Orabug: 39343696] {CVE-2026-43344}
- drm/amd/display: Avoid divide by zero by initializing dummy pitch to 1 (Mario Limonciello) [Orabug: 38158557] {CVE-2025-38205}
- block: mark GFP_NOIO around sysfs ->store() (Ming Lei) [Orabug: 37650276] {CVE-2025-21817}
- f2fs: fix potential deadloop in prepare_compress_overwrite() (Chao Yu)
- md: make rdev_addable usable for rcu mode (Yangerkun) [Orabug: 38351780] {CVE-2025-38621}
- bnxt_en: Mask the bd_cnt field in the TX BD properly (Michael Chan) [Orabug: 37844489] {CVE-2025-22108}
- LTS version: v6.12.108 (Sherry Yang)
- usb: usbfs: fix use-after-free of usb_device in usbdev_release() (Miguel Peñaranda) [Orabug: 39982119] {CVE-2026-80824}
- wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (Lucid Duck) [Orabug: 39982123] {CVE-2026-80825}
- USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (Shuangpeng Bai)
- USB: serial: spcp8x5: drop broken carrier detect support (Johan Hovold)
- USB: serial: option: fix slab OOB read in interrupt URB callback (Jiale Yao) [Orabug: 39982130] {CVE-2026-80827}
- ALSA: usb-audio: Complete cleanup after system-resume errors (Will Porter) [Orabug: 39982134] {CVE-2026-80828}
- ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (Marouane El Moufid) [Orabug: 39982138] {CVE-2026-80829}
- usb: core: Strengthen error handling in hub_hub_status() (Griffin Kroah-Hartman)
- usb: core: Add lock to usb_wakeup_notification() (Griffin Kroah-Hartman) [Orabug: 39982142] {CVE-2026-80830}
- KVM: s390: vsie: zero stale crypto bits (Christian Borntraeger)
- crypto: qce - Remove unsafe/deprecated algorithms (Bartosz Golaszewski)
- crypto: mxs-dcp - fix source scatterlist length access (Thorsten Blum)
- crypto: qce - fix CCM AAD buffer underallocation (Md Sadre Alam)
- crypto: atmel-tdes - use scatterlist length before DMA mapping (Thorsten Blum)
- crypto: qcom-rng - Remove crypto_rng interface (Eric Biggers)
- crypto: qcom-rng - Allow zero as a random number (Eric Biggers)
- crypto: qcom-rng - Enable clock in hwrng case (Eric Biggers)
- mm/swap: reject swapon() on filesystem-level encrypted files (Eric Biggers)
- netfilter: nf_tables: don't queue packet path object notifications (Fourie Zhang) [Orabug: 39982164] {CVE-2026-80837}
- vxlan: keep the last remote linked during FDB flush (Kyle Zeng) [Orabug: 39982167] {CVE-2026-80838}
- batman-adv: reject unrepresentable multicast TVLV offsets (Kyle Zeng) [Orabug: 39982169] {CVE-2026-80839}
- ipv6: seg6: clear IPv4 control block on IPIP decapsulation (Kyle Zeng) [Orabug: 39982171] {CVE-2026-80840}
- net: bridge: mcast: fix use-after-free of a master VLAN's multicast context (Norbert Szetei) [Orabug: 39982179] {CVE-2026-80842}
- xfrm: bound nat keepalive state collection (Zihan Xi)
- xfrm: fix xfrm_state_construct() auth-trunc leak (Zihan Xi) [Orabug: 39982182] {CVE-2026-80843}
- xfrm: ah6: validate routing header segments_left (Asim Viladi Oglu Manizada) [Orabug: 39982186,40035125] {CVE-2026-80844}
- xfrm: avoid lock inversion in nat keepalive work (Zihan Xi) [Orabug: 39982190] {CVE-2026-80845}
- xfrm: drop ESP-in-TCP packets with no ingress device (Zhiling Zou)
- xfrm: espintcp: fix UAF during close (Sabrina Dubroca)
- net/tcp-ao: fix use-after-free of current_key on reconnect to another peer (Hyunwoo Kim)
- tcp: fix AO info use-after-free in tcp_ao_connect_init() (Qing Ming)
- net/tcp: fix TCP-AO key deletion in VRFs (Rastislav Szabo)
- x86/CPU/AMD: Carve out a Zen5 models range (Pratik Vishwakarma)
- gtp: serialize PDP context updates (Qing Ming) [Orabug: 39982207] {CVE-2026-80851}
- tls: device: fix out-of-bounds write in tls_append_frag() (Jiayuan Chen) [Orabug: 39982211] {CVE-2026-80852}
- usb: gadget: f_tcm: keep port count until LUN teardown completes (Shuangpeng Bai) [Orabug: 39982216] {CVE-2026-80854}
- usb: usbtest: disable dynamic ID support (Aleksandr Nogikh)
- fuse: fix invalidate lock leak on open O_TRUNC DAX failure (Baokun Li) [Orabug: 39982220] {CVE-2026-80855}
- fuse: fix invalidate lock leak on setattr writeback failure (Baokun Li) [Orabug: 39982223] {CVE-2026-80856}
- xhci: dbgtty: Fix unregister on tty_alloc_driver() failure (Lucas De Marchi)
- xhci: dbgtty: Fix unregister on tty_register_driver() failure (Lucas De Marchi) [Orabug: 40010371] {CVE-2026-80923}
- usb: xhci: Handle USB3 port events when there is one roothub (Semih Baskan)
- accessibility: speakup: unregister tty ldisc on later init failures (Haoxiang Li)
- fpga: dfl: fme: add error handling (Griffin Kroah-Hartman)
- HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (Jose Villaseñor Montfort) [Orabug: 39981986] {CVE-2026-80783}
- Bluetooth: hci_sync: Fix accept list UAF during suspend (Chengfeng Ye) [Orabug: 39981936] {CVE-2026-80762}
- Bluetooth: hci_sync: Use bt_dev_err() to log error message in hci_update_event_filter_sync() (Zijun Hu)
- HID: uclogic: fix use-after-free of inrange_timer on remove (Ibrahim Hashimov) [Orabug: 39981948] {CVE-2026-80766}
- HID: ft260: fix stack-use-after-return write in I2C read race (Raman Varabets)
- HID: ft260: validate i2c input report length (Michael Zaidman)
- HID: asus: fix missing hid_is_usb() check (Jann Horn) [Orabug: 39981968] {CVE-2026-80774}
- HID: asus: simplify RGB init sequence (Antheas Kapenekakis)
- HID: pidff: fix OOB write when hid->inputs is empty (Baul Lee) [Orabug: 39981976] {CVE-2026-80780}
- HID: pidff: clang-format pass (Tomasz Pakuła)
- HID: pidff: Use ARRAY_SIZE macro instead of sizeof (Tomasz Pakuła)
- HID: pidff: Rework pidff_set_time() to fix warnings (Tomasz Pakuła)
- nfc: nci: add data_len bound checks to activation parameter extractors (Bryam Vargas)
- nilfs2: reject invalid block index in GC ioctl (Ryusuke Konishi)
- nilfs2: correct return value kernel-doc descriptions for ioctl functions (Ryusuke Konishi)
- ksmbd: harden file lifetime during session teardown (Daemyung Kang)
- powerpc/hv-gpci: fix preempt count leak in sysfs show paths (Aboorva Devarajan)
- veth: fix OOB txq access in veth_poll() with asymmetric queue counts (Jesper Dangaard Brouer)
- ring buffer: Propagate __rb_map_vma return value to caller (Ankit Khushwaha)
- selinux: switch two allocations to use kzalloc_objs() (Stephen Smalley)
- smc: Use __sk_dst_get() and dst_dev_rcu() in smc_vlan_by_tcpsk(). (Kuniyuki Iwashima)
- ASoC: nau8821: Cancel pending work before suspend (Cristian Ciocaltea)
- Revert "PM: sleep: Use complete() in device_pm_sleep_init()" (Sasha Levin)
- riscv: Fix register corruption from uninitialized cregs on error (Michael Neuling)
- bpf: Fix use-after-free in offloaded map/prog info fill (Jiayuan Chen) [Orabug: 39622046] {CVE-2026-53089}
- ASoC: nau8821: Cancel delayed work on component remove (Cristian Ciocaltea) [Orabug: 39451975] {CVE-2026-45963}
- smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match(). (Kuniyuki Iwashima)
- smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set(). (Kuniyuki Iwashima)
- KVM: arm64: Prevent access to vCPU events before init (Oliver Upton) [Orabug: 38601895] {CVE-2025-40102}
- smc: Fix use-after-free in __pnet_find_base_ndev(). (Kuniyuki Iwashima)
- can: j1939: make j1939_sk_bind() fail if device is no longer registered (Tetsuo Handa)
- can: j1939: add missing calls in NETDEV_UNREGISTER notification handler (Tetsuo Handa)
- can: j1939: implement NETDEV_UNREGISTER notification handler (Tetsuo Handa) [Orabug: 38494826] {CVE-2025-39925}
- mISDN: hfcpci: Fix warning when deleting uninitialized timer (Vladimir Riabchun)
- media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode() (Xu Wang)
- exfat: fix double free in delayed_free (Namjae Jeon) [Orabug: 38158565] {CVE-2025-38206}
- jfs: Fix null-ptr-deref in jfs_ioc_trim (Dylan Wolff)
- ibmvnic: Use kernel helpers for hex dumps (Nick Child)
- jfs: add check read-only before txBeginAnon() call (Vasiliy Kovalev)
- jfs: add check read-only before truncation in jfs_truncate_nolock() (Vasiliy Kovalev)
- perf: Reject exited events as group leaders (Kyle Zeng) [Orabug: 39973604] {CVE-2026-74753}
- selinux: require a class's permission values to cover its permission count (Bryam Vargas)
- selinux: reject a permission value exceeding the class permission count (Bryam Vargas) [Orabug: 39973489] {CVE-2026-80755}
- selinux: more strict policy parsing (Christian Göttsche)
- selinux: use u16 for security classes (Christian Göttsche)
- selinux: make more use of str_read() when loading the policy (Christian Göttsche)
- selinux: avoid unnecessary indirection in struct level_datum (Christian Göttsche)
- selinux: use known type instead of void pointer (Christian Göttsche)
- HID: uhid: convert to hid_safe_input_report() (Carlos Llamas)
- nvme-tcp: fix usage of page_frag_cache (Dmitry Bogdanov) [Orabug: 39982234] {CVE-2026-80862}
- io_uring/io-wq: fix worker accounting when canceling creation callbacks (Vishnu Razdan)
- ext4: don't enable DAX on new encrypted files (Eric Biggers) [Orabug: 39982069] {CVE-2026-80806}
- KVM: x86/mmu: Check write tracking in all address spaces (Jinu Kim)
- RDMA/rxe: Fix OOB in free_rd_atomic_resources() (Peiyang He) [Orabug: 39982236] {CVE-2026-80863}
- RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp (Ibrahim Hashimov) [Orabug: 39982241] {CVE-2026-80864}
- LTS version: v6.12.107 (Sherry Yang)
- inet: frags: strip GSO state from fragments before reassembly (Xinyang Ge) [Orabug: 39972529] {CVE-2026-80590}
- LTS version: v6.12.106 (Sherry Yang)
- net: gro: properly validate BIG TCP aggregation criteria (Eric Dumazet) [Orabug: 40054426] {CVE-2026-80725}
- Bluetooth: hci_aml: validate firmware segment lengths (Laxman Acharya Padhya) [Orabug: 39981931] {CVE-2026-80759}
- Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync (Ali Ahmet Memis)
- Bluetooth: hci_event: validate LE Set CIG Parameters response (Laxman Acharya Padhya) [Orabug: 39981938] {CVE-2026-80763}
- Bluetooth: hci_event: fix LE list UAF on reset (Chengfeng Ye) [Orabug: 39981940] {CVE-2026-80764}
- HID: hyperv: validate initial device info bounds (Michael Bommarito) [Orabug: 39981944] {CVE-2026-80765}
- HID: sensor: custom: Fix use-after-free in enable_sensor (Haoxiang Li) [Orabug: 39981953] {CVE-2026-80767}
- HID: core: fix number/pointer type confusion on long items (Jann Horn) [Orabug: 40010352] {CVE-2026-80918}
- HID: nintendo: stop device IO before hid_hw_stop on probe failure (Jiangshan Yi)
- HID: nintendo: register input device after capabilities are set (Jiangshan Yi)
- HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() (Ibrahim Hashimov)
- Input: atkbd - skip deactivate for HONOR ZQC-P (Donglin Lyu)
- Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard (Cryolitia Pukngae)
- mptcp: pm: fix memory leak from alloc-during-teardown race (Shardul Bankar) [Orabug: 39981990] {CVE-2026-80784}
- ipv4: start using dst_dev_rcu() (Eric Dumazet) [Orabug: 38592180] {CVE-2025-40074}
- xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (Xiang Mei) [Orabug: 39839295] {CVE-2026-64581}
- net/ionic: avoid OOB TX partner lookup for hwstamp RXQ (Anand Khoje) [Orabug: 39981974] {CVE-2026-80779}
- HID: core: fix OOB read of field->usage in hid_set_field() (Baul Lee) [Orabug: 39981978] {CVE-2026-80781}
- HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID (Lee Jones)
- HID: magicmouse: do not keep a stale msc->input if no input is claimed (Jose Villaseñor Montfort) [Orabug: 39981982] {CVE-2026-80782}
- HID: magicmouse: re-enable multitouch after reset-resume (Christopher Kodama)
- HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C (Andrei Fed)
- drm/xe: Fix DPT allocation paths. (Maarten Lankhorst) [Orabug: 40010344] {CVE-2026-80915}
- ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses (Dawid WróBel)
- mptcp: pm: fix data race in add_addr timer callback (Luoqing)
- nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations (Greg Kroah-Hartman) [Orabug: 39982001] {CVE-2026-80788}
- nvmet-tcp: bound SGL data length before allocating command buffers (Ibrahim Hashimov) [Orabug: 39982005] {CVE-2026-80789}
- nvmet-fc: fix invalid free in LS IOD error path (Honghui Jiang) [Orabug: 39982009] {CVE-2026-80790}
- nvmet-auth: zero the AUTH_RECEIVE response buffer (Bryam Vargas) [Orabug: 39982013] {CVE-2026-80791}
- ipv6: fix use-after-free in ip6_finish_output2() (Luxiao Xu) [Orabug: 39982016] {CVE-2026-80792}
- ipv4: reject undersized MTUs in ip_do_fragment() (Yong Wang) [Orabug: 39982020] {CVE-2026-80793}
- Input: byd - synchronize timer deletion before freeing private data (Linmao Li) [Orabug: 39972965] {CVE-2026-80572}
- ndisc: ndisc_send_redirect() cleanup (Eric Dumazet)
- nfc: nci: free destination parameters when closing a connection (Linmao Li)
- nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (Samuel Page)
- nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (Samuel Page)
- nfc: st21nfca: validate ATR_REQ length against the received frame (Doruk Tan Ozturk)
- nfc: pn533: purge fragmented skbs during cleanup (Xu Rao)
- nfc: llcp: reject PDUs shorter than the LLCP header (Doruk Tan Ozturk)
- nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (Muhammad Bilal)
- nfc: llcp: bound the connect_sn TLV walk to the skb (Doruk Tan Ozturk)
- nfc: microread: validate target discovery payload lengths (Pengpeng Hou)
- nfc: fdp: bound the device-reported read length and fix an skb leak (Bryam Vargas)
- nfc: digital: clamp SENSF_RES length to the destination buffer (Doruk Tan Ozturk)
- libceph: fix OOB read in decode_watchers() via missing bounds check (Pavitra Jha) [Orabug: 39972905] {CVE-2026-80557}
- xfs: validate attr entry pointer before field access (Hongling Zeng) [Orabug: 39982066] {CVE-2026-80805}
- ext4: propagate errors from fast commit range replay (Guanghui Yang)
- ext4: clear error before retrying inode xattr space fallback (Guanghui Yang)
- ext4: stop retrying saturated xattr cache entries (Matthias Goergens) [Orabug: 39982076] {CVE-2026-80808}
- kcov: fix data corruption and race conditions on PREEMPT_RT (Tetsuo Handa) [Orabug: 40010346] {CVE-2026-80916}
- null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows (Rik van Riel)
- ocfs2: fix missing metadata reservation for large xattrs (Ian Bridges) [Orabug: 39982080] {CVE-2026-80809}
- ALSA: dummy: Check card index validity at probe (Takashi Iwai) [Orabug: 39982086] {CVE-2026-80812}
- xfs: don't livelock in scrub on a circular unlinked list (Darrick J. Wong) [Orabug: 39982105] {CVE-2026-80820}
- xfs: hoist per-bucket unlinked list check to helper (Darrick J. Wong)
- xfs: bounds-check buffer log item's dirty bitmap (Ibrahim Hashimov) [Orabug: 39972834] {CVE-2026-80536}
- xfs: don't use a xfs_log_iovec for ri_buf in log recovery (Christoph Hellwig)
- xfs: namespace the maximum length/refcount symbols (Darrick J. Wong)
- serial: sc16is7xx: enable THRI before filling TX FIFO (Luca Fresi)
- serial: sc16is7xx: use guards for simple mutex locks (Hugo Villeneuve)
- serial: sc16is7xx: rename EFR mutex with generic name (Hugo Villeneuve)
- serial: amba-pl011: synchronize DMA teardown (Fan Wu) [Orabug: 39973442] {CVE-2026-80737}
- NTB: ntb_netdev: Preserve RX queue depth on allocation failure (Koichiro Den) [Orabug: 39919081,40022771] {CVE-2026-74626}
- serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx (Ryan Wilbur) [Orabug: 39919154] {CVE-2026-74653}
- inet: frags: publish queues before arming timer (Zhiling Zou) [Orabug: 39919186,40022764] {CVE-2026-74662}
- inet: frags: save a pair of atomic operations in reassembly (Eric Dumazet)
- inet: frags: change inet_frag_kill() to defer refcount updates (Eric Dumazet)
- ipv4: frags: remove ipq_put() (Eric Dumazet)
- inet: frags: add inet_frag_putn() helper (Eric Dumazet)
- netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() (David Howells) [Orabug: 39785104] {CVE-2026-64216}
- hwmon: (ltc4286) Fix symbol namespace of MODULE_IMPORT_NS() (Nobuhiro Iwamatsu)
- gve: fix zero-length skb frag with header-split (Jordan Rhee)
- gpio: ml-ioh: use raw_spinlock_t for the register lock (Junjie Cao)
- rndis_host: add overflow check in rndis_rx_fixup() (Griffin Kroah-Hartman) [Orabug: 39982091] {CVE-2026-80814}
- ALSA: scarlett2: Use a private URB for the notification endpoint (Geoffrey D. Bennett) [Orabug: 39982096] {CVE-2026-80815}
- Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (Ali Ahmet Memis) [Orabug: 39982101] {CVE-2026-80819}
- PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems (Steffen Persvold) [Orabug: 40010349] {CVE-2026-80917}

[6.12.0-207.105.2]
- Revert "net/mlx5: Add poll-eq API to be used by ULP's" (Praveen Kumar Kannoju) [Orabug: 39890589]
- uek-rpm: add embedded4only build option (Joseph Dobosenski) [Orabug: 39878288]
- uek-rpm: allow zero module embedded builds (Joseph Dobosenski) [Orabug: 39878288]
- uek-rpm: revise embedded module packaging (Joseph Dobosenski) [Orabug: 39878288]
- uek: kabi: update x86_64 kABI files for new symbols (Saeed Mirzamohammadi) [Orabug: 39809826]
- kvm: x86: SRSO_USER_KERNEL_NO is not synthesized (Paolo Bonzini) [Orabug: 39641707]
- LTS version: v6.12.105 (Saeed Mirzamohammadi)
- net: ethernet: mtk_eth_soc: improve support for named interrupts (Daniel Golle)
- net: ethernet: mtk_eth_soc: only use legacy mode on missing IRQ name (Frank Wunderlich)
- ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r (Ajrat Makhmutov)
- ring-buffer: Use current_context for safe per-CPU buffer swap (Tengda Wu) [Orabug: 39919009] {CVE-2026-74601}
- ring-buffer: Remove jump to out label in ring_buffer_swap_cpu() (Steven Rostedt)
- ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS (Eric Dumazet) [Orabug: 39969397] {CVE-2026-23459}
- binfmt_misc: use exe_file_deny_write_access() for the interpreter clone (Christian Brauner) [Orabug: 39969390] {CVE-2026-74486}
- fs: unlock the superblock during iterate_supers_type (Darrick J. Wong)
- perf/core: Fix group leader use-after-free after sibling detach (Aditya Chillara) [Orabug: 39919113] {CVE-2026-74637}
- perf: Unify perf_event_free_task() / perf_event_exit_task_context() (Peter Zijlstra)
- erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms (Gao Xiang)
- drm/xe/oa: Fix sync entry leak on OA config emit failure (Linmao Li) [Orabug: 39982343] {CVE-2026-80903}
- net/sched: cls_bpf: reject dev-bound programs bound to a different device (Jamal Hadi Salim) [Orabug: 39972725] {CVE-2026-74736}
- net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG (Siddharth Vadapalli)
- m68k: Define NR_CPUS to 1 (Uwe Kleine-König)
- net/sched: cls_u32: skip hash tables in u32_bind_class() (Zhang Changzhong) [Orabug: 39972734] {CVE-2026-74739}
- net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain (Jamal Hadi Salim) [Orabug: 39972739] {CVE-2026-74740}
- af_packet: Don't send zero-byte data in tpacket_snd(). (Eric Dumazet) [Orabug: 39973456] {CVE-2026-80742}
- ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (Rosen Penev)
- net/tls: Fail tls_sw_splice_read() after a failed async decrypt (Chuck Lever) [Orabug: 39982345] {CVE-2026-80904}
- net: packet: fix wrong transport_header when sending VLAN-tagged frame (Wei Fang) [Orabug: 39982351] {CVE-2026-80906}
- tcp: fix icsk_ack.ato bitfield overflow (Jiayuan Chen)
- veth: fix queue index used to wake the peer txq in veth_poll (Jonas Köppeler) [Orabug: 39972745] {CVE-2026-74742}
- macvlan: inherit needed_headroom and needed_tailroom from lowerdev (Eric Dumazet) [Orabug: 39972747] {CVE-2026-74743}
- ipvlan: inherit needed_headroom and needed_tailroom from phy_dev (Eric Dumazet) [Orabug: 39972751] {CVE-2026-74744}
- netfilter: ipset: let destroy callbacks adjust ext mem size (Florian Westphal)
- netfilter: ipset: fix list type element drift bug (Florian Westphal)
- netfilter: flowtable: publish GC-visible tuple last (Jérémy Jean) [Orabug: 39972759] {CVE-2026-74746}
- netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path (Alexey Velichayshiy) [Orabug: 39973465] {CVE-2026-80744}
- netfilter: ipset: fix refcount race between list:set GC and swap (Xiang Mei) [Orabug: 39972771] {CVE-2026-74748}
- crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req() (Vladis Dronov)
- crypto: ccm - Set rfc4309 maxauthsize from child (Herbert Xu)
- arm64: tegra: Add EL2 virtual timer interrupt for Tegra194 (Jonathan Hunter)
- net/x25: fix use-after-free of the socket by its timers (Baul Lee) [Orabug: 39919086] {CVE-2026-74628}
- ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup (Peter Ujfalusi) [Orabug: 39972801] {CVE-2026-80525}
- x86/mce: Set up the polling timer before CMCI discovery (Breno Leitao) [Orabug: 39973419] {CVE-2026-80727}
- x86/mce: Set CR4.MCE last during init (Yazen Ghannam)
- x86/mce: Remove __mcheck_cpu_init_early() (Yazen Ghannam)
- ring-buffer: Prevent resizing of persistent ring buffer (Vincent Donnefort)
- ring-buffer: Make ring_buffer_{un}map() simpler with guard(mutex) (Steven Rostedt)
- ring-buffer: Simplify ring_buffer_read_page() with guard() (Steven Rostedt)
- KVM: SVM: Serialize accesses to the owner and mirror list with separate lock (Paolo Bonzini) [Orabug: 39919026,39931893] {CVE-2026-74607}
- mm/ptdump: always stabilise against page table freeing using init_mm (Lorenzo Stoakes) [Orabug: 39919003] {CVE-2026-74599}
- mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF (Lorenzo Stoakes) [Orabug: 39919222] {CVE-2026-74672}
- ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer() (Vincent Donnefort) [Orabug: 39919013] {CVE-2026-74602}
- ring-buffer: Simplify functions with __free(kfree) to free allocations (Steven Rostedt)
- drm/vmwgfx: take fman->lock around fence list mutation in fifo_down (Zack Rusin)
- drm/amd/pm: fix pptable use-after-free (Yang Wang) [Orabug: 39886778] {CVE-2026-74450}
- drm/amd/pm: adjust the visibility of pp_table sysfs node (Yang Wang)
- drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini (Pierre-Eric Pelloux-Prayer)
- drm/amdgpu: remove unused function parameter (Yunxiang Li)
- drm/amd/pm: fix torn gpu metrics reads (Yang Wang)
- drm/amd/pm: Use macro to initialize metrics table (Lijo Lazar)
- drm/amd/pm: Use same metric table for APU (Asad Kamal)
- can: rcar_canfd: change the initializing flow for clocks and resets (Tu Nguyen)
- cifs: add fscache_resize_cookie() to cifs_setsize() (Frank Sorenson)
- smb: client: fix race with fallocate(2) and AIO+DIO (Paulo Alcantara)
- include/linux/fs.h: add inode_lock_killable() (Max Kellermann)
- ice: fix VF interrupts cleanup (Dawid Osuchowski)
- vxlan: use pskb_network_may_pull() for transmit path header pulls (Eric Dumazet) [Orabug: 39886859] {CVE-2026-74474}
- vxlan: Handle stats using NETDEV_PCPU_STAT_DSTATS. (Guillaume Nault)
- binfmt_misc: restore write access when removing an entry (Christian Brauner) [Orabug: 39886901,39931874] {CVE-2026-74487}
- fs: don't block write during exec on pre-content watched files (Amir Goldstein)
- fsnotify: opt-in for permission events at file open time (Amir Goldstein)
- fsnotify, lsm: Decouple fsnotify from lsm (Song Liu)
- binfmt_misc: don't leak the user namespace when the mount fails (Christian Brauner) [Orabug: 39886890] {CVE-2026-74483}
- net: pktgen: fix proc entry use-after-free (Chengfeng Ye) [Orabug: 39886874,39931868] {CVE-2026-74479}
- net: pktgen: fix code style (WARNING: Block comments) (Peter Seiderer)
- ksmbd: reject repeated SMB2 NEGOTIATE requests (Namjae Jeon)
- ksmbd: conn lock to serialize smb2 negotiate (Namjae Jeon)
- igc: remove napi_synchronize() in igc_down() (David Carlier) [Orabug: 39973386] {CVE-2026-80715}
- ata: libata-scsi: terminate deferred commands on time out (Damien Le Moal)
- ASoC: tas2562: Validate values for volume writes (Mark Brown)
- KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs (Weiming Shi) [Orabug: 39886991] {CVE-2026-74517}
- btrfs: zoned: fix missing chunk metadata reservation (Guanghui Yang)
- btrfs: remove fs_info argument from btrfs_zoned_activate_one_bg() (Filipe Manana)
- btrfs: add space_info argument to btrfs_chunk_alloc() (Naohiro Aota)
- btrfs: add debug build only WARN (David Sterba)
- iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace (Peiyang He) [Orabug: 39982323] {CVE-2026-80894}
- tcp: challenge ACK for non-exact RST in SYN-RECEIVED (Yuxiang Yang) [Orabug: 39859397,39931929] {CVE-2026-68118}
- tcp: reorganize tcp_sock_write_txrx group for variables later (Chia-Yu Chang)
- tcp: fast path functions later (Ilpo Järvinen)
- tcp: Pass flags to __tcp_send_ack (Ilpo Järvinen)
- eventpoll: pin files while checking reverse paths (Gui-Dong Han)
- ksmbd: validate minimum PDU size for transform requests (Namjae Jeon)
- smb/server: fix minimum SMB2 PDU size (Chenxiaosong)
- smb/server: fix minimum SMB1 PDU size (Chenxiaosong)
- ksmbd: rename smb2_get_msg to smb_get_msg (Namjae Jeon)
- smb/server: rename include guard in smb_common.h (Chenxiaosong)
- smb: move get_rfc1002_len() to common/smbglob.h (Zhangguodong)
- smb: move smb_version_values to common/smbglob.h (Zhangguodong)
- super: fix emergency thaw deadlock on frozen block devices (Christian Brauner) [Orabug: 39859441] {CVE-2026-68132}
- fs/super: fix emergency thaw double-unlock of s_umount (Chenchangcheng) [Orabug: 39969395] {CVE-2026-68150}
- super: use common iterator (Part 2) (Christian Brauner)
- super: use a common iterator (Part 1) (Christian Brauner)
- super: skip dying superblocks early (Christian Brauner)
- super: remove pointless s_root checks (Christian Brauner)
- net/sched: serialize qdisc_rtab_list against concurrent get/put (Aldo Ariel Panzardo) [Orabug: 39859461,39931864] {CVE-2026-68138}
- libceph: fix two unsafe bare decodes in decode_lockers() (Pavitra Jha) [Orabug: 39852161] {CVE-2026-68082}
- userfaultfd: prevent registration of special VMAs (Mike Rapoport) [Orabug: 39859558,39931866] {CVE-2026-68166}
- mm/khugepaged: guard is_zero_pfn() calls with pte_present() (Lance Yang)
- libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (Xiang Mei) [Orabug: 39859533] {CVE-2026-68159}
- libceph: Amend checking to fix make W=1 build breakage (Andy Shevchenko)
- ceph: fix hanging __ceph_get_caps() with stale mds_wanted (Max Kellermann) [Orabug: 39972806] {CVE-2026-80527}
- ceph: avoid fs reclaim while using current->journal_info (Max Kellermann) [Orabug: 39972809] {CVE-2026-80528}
- ceph: fix writeback_count leak in write_folio_nounlock() (Xu Wang)
- ceph: Convert writepage_nounlock() to write_folio_nounlock() (Matthew Wilcox)
- ceph: Convert ceph_find_incompatible() to take a folio (Matthew Wilcox)
- ceph: Use a folio in ceph_page_mkwrite() (Matthew Wilcox)
- ceph: Remove ceph_writepage() (Matthew Wilcox)
- xfs: check v5 superblock features early (Christoph Hellwig)
- xfs: check xfarray iteration errors when committing unlinked inode lists (Darrick J. Wong)
- xfs: don't swallow dquot recovery verification errors (Long Li) [Orabug: 39972813] {CVE-2026-80529}
- xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN (Lin Jiapeng) [Orabug: 39972815,40078696] {CVE-2026-80530,CVE-2026-97547}
- xfs: avoid UAF on sc->tempip in xrep_tempfile_create (Darrick J. Wong) [Orabug: 39972817] {CVE-2026-80531}
- xfs: don't return EFSCORRUPTED when scrubbing corrupt parent pointers (Darrick J. Wong)
- xfs: fix another iunlink infinite loop bug in online fsck (Darrick J. Wong) [Orabug: 39972819] {CVE-2026-80532}
- xfs: fix allocated inodes that show up in the unlinked list (Darrick J. Wong)
- xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair (Darrick J. Wong) [Orabug: 39972821] {CVE-2026-80533}
- xfs: don't zap the attr fork on repair when there are queued pptr updates (Darrick J. Wong)
- xfs: fix ilock leak on error in xfs_dq_get_next_id (Long Li) [Orabug: 39972824] {CVE-2026-80534}
- xfs: load next_agino from the correct xfarray in xrep_iunlink_relink_prev (Darrick J. Wong)
- xfs: nlink scrub must take IOLOCK before determining ILOCK state (Darrick J. Wong)
- xfs: pass runtime errors from xrep_iunlink_mark_ondisk_rec up to callers (Darrick J. Wong)
- xfs: set the prev pointer when reinserting an inode on the unlinked list (Darrick J. Wong)
- xfs: don't double-lock when deleting a self-referential directory (Darrick J. Wong) [Orabug: 39972831] {CVE-2026-80535}
- xfs: only check mergeability of bnobt records (Darrick J. Wong)
- xfs: zero i_nlink before repair puts inode on unlinked list (Darrick J. Wong)
- xfs: clear zapped attr fork state when bmap repair finds no attr fork (Maqiang)
- drm/amdgpu: disallow multiple FENCE chunks in one submit (Junrui Luo) [Orabug: 39972841] {CVE-2026-80539}
- drm/amdgpu: Fix UVD decode image min size calculation (David Rosca) [Orabug: 39972846] {CVE-2026-80540}
- drm/amdgpu: Fix UVD dpb min size calculation for H264 (David Rosca) [Orabug: 39982356] {CVE-2026-80907}
- drm/amdgpu: Fix UVD min buffer sizes (David Rosca)
- drm/amdgpu: Implement insert_end for VCE 3 (David Rosca)
- drm/amdgpu: Reject UVD message with dimensions above 4096 (David Rosca) [Orabug: 39982360] {CVE-2026-80908}
- drm/amdgpu: validate GEM_CREATE domain combinations (Candice Li) [Orabug: 39972851] {CVE-2026-80541}
- drm/amdgpu: check ASPM on the dGPU host link (Yang Wang)
- drm/amdgpu: fix nbif 6.3.1 l1 low power not functional (Yang Wang)
- drm/amdgpu: Reject UVD message with invalid number of h265 refs (David Rosca) [Orabug: 39982364] {CVE-2026-80909}
- drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE (Nathan Lucas)
- drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix (Nathan Lucas)
- s390/vfio_ccw: Implement a crw lock (Eric Farman)
- s390/vfio_ccw: Calculate idal length based on idaw type (Eric Farman)
- s390/vfio_ccw: Selectively expand io_mutex (Eric Farman)
- s390/vfio_ccw: Move cp cleanup out of not operational (Eric Farman)
- s390/vfio_ccw: Fix out of bounds check on CCW array (Eric Farman)
- s390/vfio_ccw: Ensure first IDAW remains constant (Eric Farman)
- s390/vfio_ccw: Ensure index for read/write regions are within range (Eric Farman)
- s390/vfio_ccw: Cancel existing workqueues (Eric Farman)
- s390/vfio_ccw: Limit the number of channel program segments (Eric Farman)
- s390/vfio_ccw: Free all memory if cp_init() fails (Eric Farman)
- drm/radeon: fix autosuspend cleanup during teardown (Guangshuo Li)
- drm/xe: Order ring writes before ring tail updates (Matthew Brost)
- drm/connector/hdmi: Fix out of bounds memory read (John Harrison) [Orabug: 39973476] {CVE-2026-80749}
- mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition (Pei Xiao)
- mmc: sdhci: make tuning_err a signed int (Haibo Chen)
- mmc: sdhci: unmap the bounce buffer before device release (Myeonghun Pak)
- mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (Zhan Xusheng)
- libceph: tolerate addrvecs with multiple entries of the same type (Kefu Chai)
- ceph: fix MDS random selection readiness predicate (Yiming Zhu)
- libceph: Avoid using invalid osd indices from primary_temp (Raphael Zimmer) [Orabug: 39972914] {CVE-2026-80558}
- Input: sur40 - fix V4L error path cleanup (Dmitry Torokhov)
- Input: sur40 - fix input device registration ordering (Dmitry Torokhov)
- openrisc: signal: do not restore privileged SR bits on sigreturn (Ali Ahmet Memis)
- ftrace: Fix off-by-one fentry site disable in ftrace_free_mem() (Josh Poimboeuf)
- ftrace: Protect direct_functions in ftrace_find_rec_direct (Leon Hwang)
- libceph: fix multiple unsafe decodes in decode_locker() (Pavitra Jha) [Orabug: 39972926] {CVE-2026-80561}
- pmdomain: arm: Fix -EINVAL from scmi_pd_set_perf_state() on state 0 (Praveen Talari)
- gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind (Cengiz Can)
- crypto: qce - fix error path in devm_qce_register_algs (Thorsten Blum)
- crypto: starfive - use scatterlist length before DMA mapping (Thorsten Blum)
- Input: hynitron_cstxxx - validate touch count and finger IDs (Jianing Li)
- Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (Dmitry Torokhov)
- Input: synaptics-rmi4 - block s_input when F54 queue is busy (Dmitry Torokhov)
- Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (Bryam Vargas) [Orabug: 39972954] {CVE-2026-80569}
- Input: synaptics-rmi4 - zero report size on F54 work error (Dmitry Torokhov) [Orabug: 39972959] {CVE-2026-80570}
- powerpc/pseries: lparcfg - fix kbuf[] underflow (George Wilson)
- Input: iforce - validate input packet lengths (Pengpeng Hou)
- Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (Zhefu Zhang)
- Input: psxpad-spi - set driver data before use (Linmao Li)
- Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (Richard Davies) [Orabug: 39972974] {CVE-2026-80574}
- Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (Dmitry Torokhov) [Orabug: 39973485] {CVE-2026-80754}
- powerpc/pseries: pci - logic bug (George Wilson)
- Input: cs40l50-vibra - validate custom data from user space (Hyeongjun An)
- Input: xpad - add support for ZENAIM LEVERLESS (Kadota, Kyohei)
- ASoC: SOF: topology: Use acpi mach from the machine driver (Bard Liao)
- drm/amdgpu: fix aperture iounmap skipped on device removal (Asad Kamal)
- drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12 (Qiang Yu)
- drm/amdgpu: reject oversized IBs with per-ring packet limits (Candice Li) [Orabug: 39972981] {CVE-2026-80576}
- drm/panthor: skip zero-sized firmware sections (Osama Abdelkader)
- fbdev: core: Fix pointer desynchronization in fb_io_read() (Mingyu Wang) [Orabug: 39972989] {CVE-2026-80578}
- ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (Dawid WróBel)
- ASoC: cs35l41: sort the register default table (Peter Ujfalusi)
- ASoC: cs35l45: sort the register default table (Peter Ujfalusi)
- ASoC: cs4265: sort the register default table (Peter Ujfalusi)
- ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() (Peter Ujfalusi) [Orabug: 39982371] {CVE-2026-80911}
- s390/qeth: validate user buffer length in SNMP and ARP query ioctls (Hidayath Khan)
- mptcp: fastopen: only mark MPTFO subflows with SYN data (Wyatt Feng) [Orabug: 39973010] {CVE-2026-80585}
- mptcp: options: reset DSS fields in case of unexpected size (Matthieu Baerts) [Orabug: 39973012] {CVE-2026-80586}
- mptcp: avoid combining some incoming suboptions (Matthieu Baerts) [Orabug: 39973015] {CVE-2026-80587}
- selftests: mptcp: join: mark tests with data corruption as failed (Gang Yan)
- selinux: reject an unclaimed class value in security_get_classes() (Bryam Vargas) [Orabug: 39982373] {CVE-2026-80912}
- selinux: do not cancel a policy conversion that never started (Bryam Vargas) [Orabug: 39973493] {CVE-2026-80756}
- selinux: reject a class permission count below its inherited common (Bryam Vargas) [Orabug: 39973497] {CVE-2026-80757}
- selinux: require every boolean value to be defined (Bryam Vargas) [Orabug: 39982380] {CVE-2026-80913}
- KVM: SVM: Ensure PSP module is initialized if KVM module is built-in (Sean Christopherson)
- crypto: ccp: Add external API interface for PSP module initialization (Sean Christopherson)
- net: mana: Fix EQ leak in mana_remove on NULL port (Erni Sri Satya Vennela)
- ipvs: separate destination availability state (Yizhou Zhao)
- igc: fix netdev not re-attached after resume if interface is down (Philipp David)
- mm/damon: adjust isolated pages stat for DAMOS_MIGRATE_{HOT,COLD} (Seongjae Park)
- mm/damon/ops-common: putback folios on invalid migrate nid (Liyouhong) [Orabug: 39919129,39931902] {CVE-2026-74644}
- ubi: fastmap: fix ubi->fm memory leak (Pangliyuan)
- mtd: ubi: skip programming unused bits in ubi headers (Cheng Ming Lin)
- f2fs: fix UAF issue in f2fs_merge_page_bio() (Chao Yu)
- selftests/bpf: Add tests for stale delta leaking through id reassignment (Daniel Borkmann)
- selftests/bpf: Add tests for delta tracking when src_reg == dst_reg (Daniel Borkmann)
- bpf: Clear delta when clearing reg id for non-{add,sub} ops (Daniel Borkmann)
- bpf: Fix linked reg delta tracking when src_reg == dst_reg (Daniel Borkmann) [Orabug: 39622057] {CVE-2026-53092}
- block: stop the timeout timer when releasing a never added disk (Chao Shi) [Orabug: 39973019] {CVE-2026-80589}
- LTS version: v6.12.104 (Saeed Mirzamohammadi)
- bpf: tcp: fix double sock release on batch realloc (Xiang Mei) [Orabug: 39969416] {CVE-2026-64575}
- thunderbolt: Fix bandwidth group reservation indexing (Xu Rao) [Orabug: 39973440] {CVE-2026-80736}
- thunderbolt: Bound the DROM dual link port number before indexing sw->ports (Bryam Vargas) [Orabug: 39918960] {CVE-2026-74585}
- sctp: clear new_transport when removing a peer (Qing Ming) [Orabug: 39918964] {CVE-2026-74586}
- sctp: fix use-after-free of cached ASCONF chunk (Yuxiang Yang) [Orabug: 39918968] {CVE-2026-74587}
- sctp: keep chunk->transport in step with the list it is queued on (Baul Lee) [Orabug: 39918972] {CVE-2026-74588}
- scsi: scsi_debug: Negate wrapped memcmp() result (Xu Rao)
- bpf, sockmap: Fix sk_redir use-after-free in send verdict (Chengfeng Ye) [Orabug: 39918976] {CVE-2026-74589}
- fsverity: Fix silent truncation in bpf_get_fsverity_digest() (Eric Biggers)
- fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions (Eric Biggers) [Orabug: 39918980] {CVE-2026-74590}
- ima: Instantiate file_truncate and path_truncate hooks (Mimi Zohar) [Orabug: 39918983] {CVE-2026-74592}
- sched/psi: Shut down rtpoll_timer in psi_cgroup_free() (Tejun Heo) [Orabug: 39918988] {CVE-2026-74594}
- fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() (Zhan Xusheng) [Orabug: 39918991] {CVE-2026-74595}
- ip6_tunnel: clear skb2->cb[] in ip6ip6_err() (Zhiling Zou) [Orabug: 39918995] {CVE-2026-74597}
- ipv6: fix Route Information option length validation (Yuejie Shi) [Orabug: 39918999] {CVE-2026-74598}
- ptp: ocp: Fix board ID over-read (Ahmad Byagowi) [Orabug: 39919015] {CVE-2026-74603}
- Revert "thermal/drivers/hwmon: Cleanup coding style a bit" (Rafael J. Wysocki) [Orabug: 39919018] {CVE-2026-74604}
- eventfs: Fix use-after-free in eventfs_remove_rec() (Shuangpeng Bai) [Orabug: 39919024] {CVE-2026-74606}
- KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (Sean Christopherson) [Orabug: 39973414] {CVE-2026-80726}
- smb: client: Fix use-after-free in cifs_try_adding_channels() (Shuangpeng Bai) [Orabug: 39919029] {CVE-2026-74608}
- tipc: read le->link under the node lock in tipc_node_link_down() (Jun Yang) [Orabug: 39919031] {CVE-2026-74609}
- tls: don't leave a full plaintext sk_msg ring unpushed (Chanyoung) [Orabug: 39919035] {CVE-2026-74610}
- vhost: reset the vring metadata cache on vring reconfiguration (Jun Yang) [Orabug: 39917524] {CVE-2026-74580}
- veth: fix skb length accounting after XDP frag adjustment (Sun Jian) [Orabug: 39919039] {CVE-2026-74612}
- vsock/virtio: avoid refilling the RX queue after teardown (Weiming Shi) [Orabug: 39919041] {CVE-2026-74613}
- vsock/virtio: read virtqueues under worker locks (Weiming Shi) [Orabug: 39919045] {CVE-2026-74614}
- vxlan: do not arm the ageing timer on a device that is down (Baul Lee) [Orabug: 39919048] {CVE-2026-74615}
- xdp: reject clones that overrun skb_shared_info tailroom (Zhiling Zou) [Orabug: 39919052] {CVE-2026-74616}
- Revert "drm/amdgpu: fix aperture mapping leak" (Asad Kamal) [Orabug: 39973598] {CVE-2026-80728}
- binfmt_misc: don't warn when the mount is completed from another user namespace (Christian Brauner) [Orabug: 39919056] {CVE-2026-74618}
- ovl: don't warn when the mount is completed from another user namespace (Christian Brauner) [Orabug: 39919058] {CVE-2026-74619}
- net/sched: act_gact, act_police: range check the fallback control action (Hyunjung Ko) [Orabug: 39919060] {CVE-2026-74620}
- net/sched: act_ct: fix sk_buff leak when the header checks reject a packet (Hyunjung Ko) [Orabug: 39919064] {CVE-2026-74621}
- net: atlantic: free RX pages of consumed but not refilled buffers (Yangyu Chen) [Orabug: 39919067] {CVE-2026-74622}
- net: atlantic: free stranded TX buffers on ring deinit (Yangyu Chen) [Orabug: 39919071] {CVE-2026-74623}
- netfilter: nf_conntrack: defer invalid log until after unlock (Zihan Xi) [Orabug: 39919075] {CVE-2026-74624}
- netfilter: bridge: release template ct on non-IP path (Zhiling Zou) [Orabug: 39919077] {CVE-2026-74625}
- ipv6: prevent in6_dev_get() from resurrecting inet6_dev (Kyle Zeng) [Orabug: 39919091] {CVE-2026-74630}
- net: smc: fix splice entry lifetime imbalance in smc_rx_splice (Li Daming)
- mm/huge_memory: fix huge_zero_pfn race (Lorenzo Stoakes) [Orabug: 39919099] {CVE-2026-74632}
- ring-buffer: Prevent subbuf order change when resizing is disabled (Vincent Donnefort) [Orabug: 39919104] {CVE-2026-74634}
- fbdev: bitblit: bound-check glyph index in bit_cursor() (Rik van Riel) [Orabug: 39919106] {CVE-2026-74635}
- tracing: Fix race between update_event_fields and, event_define_fields (Michael Wu) [Orabug: 39919110] {CVE-2026-74636}
- ALSA: usx2y: bound the hwdep mmap fault offset (Baul Lee) [Orabug: 39919123] {CVE-2026-74641}
- ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (Takashi Iwai) [Orabug: 39969546] {CVE-2026-74642}
- ring-buffer: Fix crash passing ERR_PTR to kthread_stop() (Sh_Def) [Orabug: 39973424] {CVE-2026-80730}
- misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (Eddie Lin)
- misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke (Junrui Luo)
- misc: fastrpc: Remove buffer from list prior to unmap operation (Ekansh Gupta)
- misc: fastrpc: fix channel ctx ref leak when session alloc fails (Anandu Krishnan E)
- staging: rtl8723bs: validate monitor transmit frame lengths (Mariano Baragiola)
- staging: rtl8723bs: fix missing shared-key auth challenge length check (Panagiotis Petrakopoulos)
- staging: rtl8723bs: fix OOB read in WMM_param_handler() (Muhammad Bilal)
- staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (Muhammad Bilal)
- serial: 8250_dma: Clear stale RX state on shutdown (Cunhao Lu) [Orabug: 39919158] {CVE-2026-74654}
- serial: qcom-geni: fix TX DMA buffer flush (Jan Sebastian Götte)
- nvmem: layouts: Add fixed-layout driver (Mathieu Dubois-Briand)
- mei: pull kvfree out of spinlock (Alexander Usyskin)
- ipv4: fix use-after-free in fib_nhc_update_mtu() (Chengfeng Ye) [Orabug: 39919164] {CVE-2026-74656}
- ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops (Zihan Xi) [Orabug: 39919168] {CVE-2026-74657}
- selftests/bpf: Adapt sockmap update error handling (Michal Luczaj)
- selftests/bpf: Ensure UDP sockets are bound (Michal Luczaj)
- pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP (Claudiu Beznea)
- kunit/fortify: Add back "volatile" for sizeof() constants (Kees Cook)
- kunit/fortify: Replace "volatile" with OPTIMIZER_HIDE_VAR() (Kees Cook)
- futex: Prevent robust futex exit race some more (Keno Fischer) [Orabug: 39919173] {CVE-2026-74658}
- crypto: ccp - Abort doing SEV INIT if SNP INIT fails (Ashish Kalra)
- crypto: ccp - Fix checks for SNP_VLEK_LOAD input buffer length (Michael Roth)
- KVM: SVM: Add support to initialize SEV/SNP functionality in KVM (Ashish Kalra)
- crypto: ccp - Add new SEV/SNP platform shutdown API (Ashish Kalra)
- dt-bindings: crypto: qcom,ice: Fix missing power-domain and iface clk (Harshal Dev)
- block: Reorder the request allocation code in blk_mq_submit_bio() (Bart Van Assche)
- KVM: s390: pci: Fix aisb calculation (Matthew Rosato)
- KVM: s390: pci: Fix resource leak on IRQ registration failure (Farhan Ali)
- KVM: s390: pci: Fix missing error codes and memory unaccounting (Farhan Ali)
- KVM: s390: pci: Fix memory accounting for pinned/unpinned pages (Farhan Ali)
- net: bridge: mrp: fix uninitialised bytes on the wire (Baul Lee)
- netfilter: ebt_nflog: pin the NFLOG backend (Chengfeng Ye) [Orabug: 39919180] {CVE-2026-74660}
- mac802154: fix netdev use-after-free in beacon worker (Zihan Xi) [Orabug: 39919184] {CVE-2026-74661}
- net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header (Qihang) [Orabug: 39973426] {CVE-2026-80731}
- net: octeontx2-pf: Fix UB in shift operation (Sergey V. Frolov)
- net/sched: reject overly deep qdisc hierarchies (Zijie Huang) [Orabug: 39919190] {CVE-2026-74663}
- net: openvswitch: reallocate update replies for mismatched IDs (Zhiling Zou) [Orabug: 39919194] {CVE-2026-74664}
- net: fix skb length accounting after generic XDP frag adjustment (Sun Jian) [Orabug: 39919198] {CVE-2026-74665}
- packet: synchronize pressure clearing with ring reconfiguration (Zihan Xi) [Orabug: 39919200] {CVE-2026-74666}
- net/packet: reset the MAC header on the packet-socket transmit path (Doruk Tan Ozturk) [Orabug: 39919204] {CVE-2026-74667}
- packet: use consistent hard_header_len in TX_RING send path (Qihang) [Orabug: 39919208] {CVE-2026-74668}
- packet: use consistent hard_header_len in non-ring send paths (Qihang) [Orabug: 39917532] {CVE-2026-74582}
- ipvs: clear IPv4 options after rebasing tunnel ICMP errors (Kyle Zeng) [Orabug: 39919212] {CVE-2026-74669}
- ipvs: properly update the overload flag on dest edit (Julian Anastasov)
- ipvs: add totalconns for dest (Julian Anastasov)
- ipvs: stop estimator after disabled calc phase (Zhiling Zou) [Orabug: 39919216] {CVE-2026-74670}
- ima: fix out-of-bounds read in xattr_verify() (Lincoln Wallace) [Orabug: 39919218] {CVE-2026-74671}
- Input: evdev - fix information leak in evdev_pass_values() (Dmitry Torokhov) [Orabug: 39919226] {CVE-2026-74673}
- vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (Joshua Rogers) [Orabug: 39919231] {CVE-2026-74675}
- vt: add permission check for KDSKBMETA ioctl (Joshua Rogers) [Orabug: 39919235] {CVE-2026-74676}
- net: usb: ipheth: fix carrier_work UAF on disconnect (Doruk Tan Ozturk) [Orabug: 39919239] {CVE-2026-74677}
- net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (Yi Cong) [Orabug: 39919243] {CVE-2026-74678}
- usb: gadget: f_ncm: Use unsigned int for ndp_index (Sonali Pradhan)
- usb: cdnsp: fix incorrect endian conversions for APB timeout register (Pawel Laszczak)
- thunderbolt: icm: Preserve USB4 proxy data-valid bit (Xu Rao)
- usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (Aleksandr Nogikh) [Orabug: 39919250] {CVE-2026-74680}
- ALSA: usb-audio: fix OOB write on Type II inbound URBs (Baul Lee) [Orabug: 39919255] {CVE-2026-74682}
- Input: evdev - sanitize event type index when fetching event masks (Dmitry Torokhov) [Orabug: 39919259] {CVE-2026-74683}
- swapfile: call cond_resched() before locking si->lock (Guillaume Morin)
- mtd: spinand: repeat reading in regular mode if continuous reading fails (Mikhail Kshevetskiy)
- mtd: spinand: try a regular dirmap if creating a dirmap for continuous reading fails (Mikhail Kshevetskiy)
- mtd: spinand: fix direct mapping creation sizes (Mikhail Kshevetskiy)
- spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (Larisa Grigore)
- net: fec: do not release NULL pages when RX buffer allocation fails (Mehmet Fide)
- hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt (Guenter Roeck)
- hwmon: (ltc4282) Clamp negative current limits (Guenter Roeck)
- hwmon: (ltc4282) Avoid overflow in maximum power calculation (Guenter Roeck)
- hwmon: (ads7828) Fix external VREF regulator handling (Qingshuang Fu)
- hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (Wilken Gottwalt)
- tls: don't abort the connection on signal-interrupted sends (Maximilian Immanuel Brandtner)
- sctp: clear control chunk transport if it is being removed (Xin Long) [Orabug: 39919274] {CVE-2026-74688}
- net/atm: fix slab-out-of-bounds read in vcc_setsockopt() (Eric Dumazet) [Orabug: 39919278] {CVE-2026-74689}
- ata: pata_sl82c105: fix bridge revision use-after-free (Hongyan Xu)
- net: thunderbolt: Tear down DMA paths before stopping the rings (Fan Xinran) [Orabug: 39919286] {CVE-2026-74691}
- net/smc: fix TOCTOU race between smc_listen_out() and listener close (Sidraya Jayagond)
- net: remove WARN_ON_ONCE() from sk_mc_loop() (Eric Dumazet) [Orabug: 39973434] {CVE-2026-80733}
- net: prestera: validate firmware header length (Pengpeng Hou)
- net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (Henry Martin)
- tcp: fix TFO max_qlen accounting across reuseport migration (Jiayuan Chen) [Orabug: 39919305] {CVE-2026-74696}
- sctp: fix addip_serial increment on ASCONF_ACK allocation failure (Luoqing)
- bnxt_en: Fix PTP PPS setting bug (Keegan Freyhof)
- bnxt_en: Refresh VNIC default ring on queue restart if needed (Shravya Kn)
- bnxt_en: Determine and store default RX ring in vnic structure (Shravya Kn)
- bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss() (Shravya Kn)
- selftests/ftrace: refactor eprobes test to fix argument checks (Martin Kaiser)
- hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (Guenter Roeck)
- hwmon: (nzxt-smart2) Check return value of init_device() in probe (Qingshuang Fu)
- net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers (Jamal Hadi Salim) [Orabug: 39919315] {CVE-2026-74700}
- net/openvswitch: check Ethernet header length in key_extract() (Cen Zhang) [Orabug: 39919319] {CVE-2026-74701}
- net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter (Toke Høiland-Jørgensen) [Orabug: 39919329] {CVE-2026-74704}
- udp: fix potential use-after-free in tunnel segmentation (Luoxuanqiang) [Orabug: 39919333] {CVE-2026-74705}
- xsk: require at least 16 bytes of TX metadata (Stanislav Fomichev) [Orabug: 39919341] {CVE-2026-74710}
- tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss() (Nathan Gao)
- vdpa/mlx5: Fix buffer length in create_direct_keys() (Christian Borntraeger) [Orabug: 39919345] {CVE-2026-74712}
- vhost/vdpa: reject overflowing PA map page counts on 32-bit (Yousef Alhouseen)
- bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() (Jose Fernandez) [Orabug: 39919352] {CVE-2026-74714}
- bpf: tcp: Avoid socket skips and repeats during iteration (Jordan Rife)
- bpf: tcp: Use bpf_tcp_iter_batch_item for bpf_tcp_iter_state batch items (Jordan Rife)
- bpf: tcp: Get rid of st_bucket_done (Jordan Rife)
- bpf: tcp: Make sure iter->batch always contains a full bucket snapshot (Jordan Rife)
- bpf: tcp: Make mem flags configurable through bpf_iter_tcp_realloc_batch (Jordan Rife)
- counter: microchip-tcb-capture: Fix DT channel validation (Babanpreet Singh)
- net/mlx5: fw_tracer, return NULL on create error (Michael Guralnik) [Orabug: 39919358] {CVE-2026-74717}
- devlink: fix net namespace reference leak in reload (Or Har-Toov) [Orabug: 39919362] {CVE-2026-74718}
- net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete (Jiawen Liu)
- net/sched: cls_route: fix fastmap use-after-free on filter (Jamal Hadi Salim) [Orabug: 39917537] {CVE-2026-74583}
- net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() (Mahanta Jambigi)
- bpf: Preserve pointer state for commuted arithmetic (Yiyang Chen) [Orabug: 39919368] {CVE-2026-74720}
- btrfs: fix memory leak in btrfs_do_encoded_write() (Dmitry Antipov) [Orabug: 39919373] {CVE-2026-74722}
- watchdog: bd96801_wdt: Fix timeout for enabled WDG (Matti Vaittinen)
- ipvs: return the csum validation for forward hook (Julian Anastasov)
- ipvs: avoid out-of-bounds write in ip_vs_nat_icmp (Julian Anastasov) [Orabug: 39919379] {CVE-2026-74724}
- netfilter: ipset: switch ext_size to atomic64_t (Jozsef Kadlecsik)
- pds_core: cancel pending PCI reset work on AER recovery (Nikhil P. Rao)
- pds_core: keep the health thread stopped during reset (Nikhil P. Rao)
- net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock (Shay Drory) [Orabug: 39973450] {CVE-2026-80739}
- enic: fix tx_hang_reset use-after-free on device removal (Satish Kharat) [Orabug: 39919383] {CVE-2026-74725}
- bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor (Xiang Mei) [Orabug: 39919387] {CVE-2026-74726}
- Revert "net: thunderbolt: Enable end-to-end flow control also in transmit" (Fan Ye)
- net: hns3: fix speed configuration residue after driver reload (Jijie Shao)
- drm/bridge: ps8640: propagate AUX transfer register errors (Pengpeng Hou)
- ARM: dts: BCM5301X: fix PCIe controller 2 second interrupt (Rosen Penev)
- ARM: npcm: Fix OF node refcount leaks in SMP setup (Yuho Choi)
- arm64: dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer (Daniel Drake)
- NFS: Pin the 'struct nfs_server' during a FREE_STATEID call (Anna Schumaker) [Orabug: 39919398] {CVE-2026-74730}
- s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() (Harald Freudenberger)
- drm/amd/display: Check for tg ops in dce110_set_avmute (Ray Wu) [Orabug: 39919403] {CVE-2026-74732}
- drm/amd/display: Add AV mute wait frames to dce110_set_avmute (Ray Wu)
- selftests/bpf: Fail unbound UDP on sockmap update (Michal Luczaj)
- mount: honour SB_NOUSER in the new mount API (Al Viro)
- LTS version: v6.12.103 (Saeed Mirzamohammadi)
- drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info (Thomas Zimmermann)
- drm/fb-helper: Fix a locking bug in an error path (Bart Van Assche)
- usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path (Andrei Kuchynski)
- can: isotp: fix timer drain order, wakeup handling and tx_gen ordering (Oliver Hartkopp) [Orabug: 39982402] {CVE-2026-80889}
- can: use skb hash instead of private variable in headroom (Oliver Hartkopp)
- rxrpc: Fix irq-disabled in local_bh_enable() (David Howells) [Orabug: 39969414] {CVE-2025-38525}
- rxrpc: Manage RTT per-call rather than per-peer (David Howells)
- rxrpc: Fix the calculation and use of RTO (David Howells)
- rxrpc: Adjust the rxrpc_rtt_rx tracepoint (David Howells)
- rxrpc: Generate rtt_min (David Howells)
- drm/xe/pt: Reset current_op in xe_pt_update_ops_init() (Zongyao Bai) [Orabug: 39859863] {CVE-2026-68264}
- drm/xe: Stub out new pagefault layer (Matthew Brost)
- drm/i915/hdcp: check streams[] bounds before overflow (Jani Nikula) [Orabug: 39859827] {CVE-2026-68253}
- drm/i915/hdcp: Skip inactive MST connectors when building stream list (Suraj Kandpal)
- drm/i915/hdcp: require monotonically increasing seq_num_v (Jani Nikula)
- drm/i915/hdcp: Move to using intel_display in intel_hdcp (Suraj Kandpal)
- drm/xe: Hold a dma-buf reference for imported BOs (Gote, Nitin R) [Orabug: 39859867] {CVE-2026-68266}
- drm/xe: Rename ___xe_bo_create_locked() (Thomas Hellström)
- drm/i915/vrr: require valid min/max vfreq for VRR (Jani Nikula) [Orabug: 39859831] {CVE-2026-68254}
- drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() (Ville Syrjälä)
- drm/xe: Wait on external BO kernel fences in exec IOCTL (Matthew Brost) [Orabug: 39886747] {CVE-2026-74440}
- drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse] (Thomas Hellström)
- drm/tegra: fbdev: Remove offset into framebuffer memory (Thomas Zimmermann)
- drm/fb-helper: Allocate and release fb_info in single place (Thomas Zimmermann)
- drm/amdgpu/gfx: fix cleaner shader IB buffer overflow (Asad Kamal) [Orabug: 39859885] {CVE-2026-68276}
- drm/amdgpu: give each kernel job a unique id (Pierre-Eric Pelloux-Prayer)
- drm/sched: Store the drm client_id in drm_sched_fence (Pierre-Eric Pelloux-Prayer)
- drm/amdgpu: Fix context pstate override handling (Tvrtko Ursulin) [Orabug: 39859881] {CVE-2026-68273}
- drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions (Timur Kristóf)
- mm/kmemleak: fix checksum computation for per-cpu objects (Breno Leitao)
- kmemleak: iommu/iova: fix transient kmemleak false positive (Catalin Marinas)
- mptcp: pm: userspace: fix use-after-free in get_local_id (Geliang Tang) [Orabug: 39859563] {CVE-2026-68169}
- mptcp: pm: use addr entry for get_local_id (Geliang Tang)
- mptcp: add mptcp_userspace_pm_lookup_addr helper (Geliang Tang)
- mptcp: pm: avoid code duplication to lookup endp (Geliang Tang)
- ALSA: hda: codecs: hdmi: disable keep-alive before audio format change (Kai Vehmanen)
- wifi: brcmfmac: set F2 blocksize to 256 for BCM43752 (Liangcheng Wang)
- wifi: brcmfmac: fix 43752 SDIO FWVID incorrectly labelled as Cypress (CYW) (Gokul Sivakumar)
- wifi: ath6kl: fix use-after-free in aggr_reset_state() (Daniel Hodges) [Orabug: 39859647] {CVE-2026-68198}
- wifi: brcmfmac: drain bus_reset work on device removal (Fan Wu) [Orabug: 39843564] {CVE-2026-64586}
- media: uapi: rkisp: Correct name version enum (Niklas Söderlund)
- media: chips-media: wave5: Support CBP profile (Jackson Lee)
- media: imx219: Fix maximum frame length in lines (Sakari Ailus)
- media: i2c: imx219: Rename VTS to FRM_LENGTH (Jai Luthra)
- usb: typec: ucsi: Fix race condition and ordering in port unregistration (Andrei Kuchynski) [Orabug: 39886749] {CVE-2026-74441}
- usb: typec: ucsi: split connector lock classes (Sergey Senozhatsky)
- usb: gadget: f_tcm: synchronize delayed set_alt with teardown (Cen Zhang)
- gpio: pch: use raw_spinlock_t for the register lock (Junjie Cao)
- lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled() (Harry Yoo)
- mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (Kiryl Shutsemau) [Orabug: 39886886] {CVE-2026-74482}
- fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes (Kiryl Shutsemau)
- mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() (Kiryl Shutsemau) [Orabug: 39982321] {CVE-2026-80893}
- drm/xe/rtp: Ensure locking/ref counting for OA whitelists (Ashutosh Dixit)
- drm/xe/oa: (De-)whitelist OA registers on OA stream open/release (Ashutosh Dixit)
- drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt (Ashutosh Dixit)
- drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs (Ashutosh Dixit)
- drm/xe/rtp: Save OA nonpriv registers to register save/restore lists (Ashutosh Dixit)
- drm/xe/rtp: Generalize whitelist_apply_to_hwe (Ashutosh Dixit)
- drm/xe/rtp: Keep track of non-OA nonpriv slots (Ashutosh Dixit)
- drm/xe/rtp: Maintain OA whitelists separately (Ashutosh Dixit)
- drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (Ashutosh Dixit) [Orabug: 39859869] {CVE-2026-68267}
- drm/xe: Apply whitelist to engine save-restore (Lucas De Marchi)
- drm/xe: Introduce xe_gt_dbg_printer() (Michal Wajdeczko)
- drm/xe/rtp: Refactor OAG MMIO trigger register whitelisting (Ashutosh Dixit)
- Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release (Pauli Virtanen)
- of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails (Chen Wandun) [Orabug: 39969419] {CVE-2026-74352}
- ata: ahci: Make ahci_ignore_port() handle empty mask_port_map (Niklas Cassel)
- ata: libahci_platform: Do not set mask_port_map when not needed (Damien Le Moal)
- HID: logitech-dj: Fix maxfield check in DJ short report validation (Hyeongjun An) [Orabug: 39969555] {CVE-2026-64427}
- spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX (Jun Guo)
- drm/vmwgfx: validate external BO copy bounds for both stride paths (Zack Rusin) [Orabug: 39973343] {CVE-2026-80700}
- drm/vmwgfx: use check_add_overflow for shader size+offset bound (Zack Rusin) [Orabug: 39982305] {CVE-2026-80887}
- drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure (Zack Rusin) [Orabug: 39886751] {CVE-2026-74442}
- drm/vmwgfx: bound DMA command body size against suffix pointer (Zack Rusin) [Orabug: 39886754] {CVE-2026-74443}
- drm/vmwgfx: validate DRAW_PRIMITIVES header size before division (Zack Rusin) [Orabug: 39886758] {CVE-2026-74444}
- drm/vmwgfx: drop dma_buf reference on foreign-fd prime import (Zack Rusin) [Orabug: 39982307] {CVE-2026-80888}
- drm/vmwgfx: reject DX_BIND_QUERY without a DX context (Zack Rusin) [Orabug: 39886762] {CVE-2026-74445}
- drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size (Zack Rusin) [Orabug: 39973346] {CVE-2026-80702}
- drm/amdkfd: hold event_mutex while checkpointing CRIU events (William Palacek) [Orabug: 39886767] {CVE-2026-74446}
- drm/amdkfd: Handle invalid event type in CRIU event restore (David Francis)
- drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment (William Palacek) [Orabug: 39887243] {CVE-2026-74447}
- drm/amdkfd: fix QID bit leak in pqm_create_queue() (Vladimir Marioukhine) [Orabug: 39886770] {CVE-2026-74448}
- drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (Gang Ba) [Orabug: 39973348] {CVE-2026-80703}
- drm/amd/display: use proper context for logging (Jiri Slaby) [Orabug: 39973350] {CVE-2026-80704}
- drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames (Ray Wu)
- drm/amdgpu: cap GTT size to physical RAM on APUs (Harkirat Gill)
- drm/amdgpu: restore UMD profile pstate after runtime resume (Candice Li)
- drm/mediatek: ovl_adaptor: balance component registrations (Myeonghun Pak)
- drm/panthor: validate firmware interface structure sizes (Osama Abdelkader)
- drm/panthor: reject firmware sections with oversized data (Osama Abdelkader)
- drm/vc4: Zero the tile state data array before each BIN job (Maíra Canal) [Orabug: 39886786] {CVE-2026-74453}
- drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size (Jose Maria Casanova Crespo) [Orabug: 39886790] {CVE-2026-74454}
- drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs (Alexander Kaplan)
- can: ctucanfd: mark error-active controller status valid (Avi Weiss)
- can: ctucanfd: handle bus error interrupts (Avi Weiss)
- can: ctucanfd: unmap BAR0 using base address (Avi Weiss)
- can: ctucanfd: use self-test mode for PRESUME_ACK (Avi Weiss)
- can: ctucanfd: add missing MODULE_DEVICE_TABLE() (Pengpeng Hou)
- can: peak_usb: validate uCAN receive record lengths (Pengpeng Hou) [Orabug: 39886794] {CVE-2026-74455}
- can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error (Maoyi Xie) [Orabug: 39886798] {CVE-2026-74456}
- can: peak_usb: add bounds check for USB channel index (James Gao) [Orabug: 39886803] {CVE-2026-74457}
- can: softing: fw_parse(): validate firmware record spans (Pengpeng Hou) [Orabug: 39973357] {CVE-2026-80706}
- can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents (Pengpeng Hou) [Orabug: 39886807] {CVE-2026-74458}
- can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() (Abdun Nihaal)
- can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (Tetsuo Handa)
- can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer (Oleksij Rempel) [Orabug: 39973362] {CVE-2026-80707}
- can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure (Marc Kleine-Budde)
- can: ems_usb: validate CPC message lengths (Pengpeng Hou) [Orabug: 39886812] {CVE-2026-74460}
- can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured (Lucas Martins Alves)
- i2c: imx: Cancel hrtimer before clearing slave pointer (Liem)
- i2c: imx: Fix slave registration race and error handling (Liem)
- i2c: iproc: reset bus after timeout if START_BUSY is stuck (Jonas Gorski)
- i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock (H. Nikolaus Schaller)
- ice: fix memory leak in ice_lbtest_prepare_rings() (Dawei Feng)
- ice: wait for reset completion in ice_resume() (Aaron Ma)
- net: openvswitch: fix skb leak on flow key update failure during ct (Ilya Maximets) [Orabug: 39886824] {CVE-2026-74464}
- net: openvswitch: fix skb leak on flow key update failure during recirculation (Ilya Maximets)
- net: openvswitch: fix potential UAF on meter attach failure (Ilya Maximets) [Orabug: 39886828] {CVE-2026-74465}
- phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB (Nava Kishore Manne)
- phy: zynqmp: use read-modify-write for SERDES scrambler bypass (Nava Kishore Manne)
- phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask (Nava Kishore Manne)
- s390/zcrypt: Validate length for CCA ECC private key requests (Holger Dengler)
- s390/zcrypt: Validate length for CCA AES cipher key requests (Holger Dengler)
- s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs (Harald Freudenberger)
- s390/dasd: Fix undersized format-check buffer (Stefan Haberland)
- s390/dasd: Fix potential NULL pointer dereference (Jan Höppner)
- s390/qeth: Check CAP_NET_ADMIN for private ioctls (Aswin K)
- s390/pci: Fix s390_pci_mmio_write syscall error return without MIO (Niklas Schnelle)
- power: supply: max17040: handle missing status supplier (Jianing Li) [Orabug: 39973377] {CVE-2026-80711}
- power: supply: bq25890: fix the -10 C NTC lookup entry (Xu Rao)
- cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized (Zhongqiu Han)
- cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init() (Abdun Nihaal)
- gpio: pca953x: fix cache_only and IRQ state on restore_context() failure (Bui Duc Phuc)
- i2c: amd-mp2: Unregister callback on adapter add failure (Myeonghun Pak)
- hwmon: (pmbus/core) notify on the hwmon device, not the i2c client (Vincent Jardin)
- hwmon: (npcm750-pwm-fan): stop fan timer on device detach (Hongyan Xu)
- sctp: prevent peer transport count overflow (Asim Viladi Oglu Manizada) [Orabug: 39886841,40035128] {CVE-2026-74469}
- sctp: reject stale cookies with mismatched verification tags (Yuxiang Yang) [Orabug: 39982312] {CVE-2026-80890}
- scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write (Ibrahim Hashimov) [Orabug: 39886846] {CVE-2026-74470}
- selftests/clone3: fix wild pointer access of getline due to missing init (Chris Gellermann)
- selftests/mm: fix potential wild pointer access of getline due to missing init (Chris Gellermann)
- spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure (Vijaya Krishna Nivarthi)
- tracing/filters: Fix false positive match in regex_match_full() (Masami Hiramatsu)
- tracing: Check return value of __register_event() in trace_module_add_events() (Masami Hiramatsu) [Orabug: 39886849] {CVE-2026-74471}
- ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() (Ming Lei) [Orabug: 39886853] {CVE-2026-74472}
- vxlan: use pskb_network_may_pull() in route_shortcircuit() (Eric Dumazet) [Orabug: 39886855] {CVE-2026-74473}
- vxlan: use neigh_ha_snapshot() in route_shortcircuit() (Eric Dumazet) [Orabug: 39886863] {CVE-2026-74475}
- vxlan: unclone skb head before modifying eth header in route_shortcircuit() (Eric Dumazet)
- vxlan: re-fetch eth header after route_shortcircuit() (Eric Dumazet) [Orabug: 39973296] {CVE-2026-80681}
- veth: convert frag_list skbs before running XDP (Matt Fleming) [Orabug: 39886867] {CVE-2026-74476}
- um: vector: fix use-after-free in vector_mmsg_rx() (Michael Bommarito)
- powerpc/ps3: Fix map failure path in dma_ioc0_map_pages() (Thorsten Blum)
- net: ipv6: clear suppressed fib6 rule result (Zhiling Zou) [Orabug: 39917529] {CVE-2026-74581}
- net: bridge: stop fast-leave after deleting a port group (Zhiling Zou) [Orabug: 39886878] {CVE-2026-74480}
- mm: memcg: initialize *locked in memcg1_oom_prepare() stub (Breno Leitao)
- mm/page_reporting: use system_freezable_wq to fix UAF during suspend (Link Lin) [Orabug: 39886882] {CVE-2026-74481}
- binfmt_misc: don't let an 'F' entry pin its own instance (Christian Brauner) [Orabug: 39886892] {CVE-2026-74484}
- binfmt_misc: reject a flag character as the field delimiter (Christian Brauner) [Orabug: 39886896] {CVE-2026-74485}
- wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (Catherine) [Orabug: 39886905] {CVE-2026-74488}
- tipc: avoid use-after-free in poll trace queue dumps (Zihan Xi) [Orabug: 39886910] {CVE-2026-74490}
- netfilter: ipset: do not update comments from kernel-side hash adds (David Lee) [Orabug: 39886915] {CVE-2026-74492}
- net/smc: fix socket use-after-free during link group termination (Luoxuanqiang)
- ipvs: do not propagate one-packet flag to synced conns (Zhiling Zou) [Orabug: 39973382] {CVE-2026-80714}
- igbvf: Fix leak in TX DMA error cleanup (Matt Vollrath) [Orabug: 39886925] {CVE-2026-74495}
- e1000: fix memory leak in e1000_probe() (Dawei Feng)
- dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ (Md Sadre Alam)
- ALSA: usb-audio: Clamp frame size in implicit-feedback mode (Sonali Pradhan) [Orabug: 39886933] {CVE-2026-74497}
- ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set (Sonali Pradhan) [Orabug: 39886937] {CVE-2026-74498}
- ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() (Baul Lee) [Orabug: 39886941] {CVE-2026-74499}
- ALSA: usb-audio: fix stack info leak in RME Digiface status (Baul Lee) [Orabug: 39886945] {CVE-2026-74500}
- ALSA: usb-audio: fix use-after-free in ump_to_endpoint() (Baul Lee) [Orabug: 39886947] {CVE-2026-74501}
- ata: libata-sata: fix ata_scsi_lpm_supported() iteration (Niklas Cassel)
- ata: libata-eh: Increase STANDBY IMMEDIATE timeout (Matt Vollrath)
- ASoC: tas2562: fix broken entries in the volume lookup table (Haidar Lee)
- ASoC: tas2562: fix DVC coefficient write order (Haidar Lee)
- ALSA: ump: fix double free of out_cvts on rawmidi error (Baul Lee) [Orabug: 39886949] {CVE-2026-74502}
- ALSA: seq: Fix division by zero in initialize_timer() (Norbert Szetei) [Orabug: 39886952] {CVE-2026-74504}
- ALSA: pcm: wake linked drain waiters on unlink (Norbert Szetei) [Orabug: 39973389] {CVE-2026-80716}
- ALSA: lx6464es: fix period byte count for 16-bit streams (Xu Rao)
- ALSA: 6fire: Fix UAF at error handling during probe (Takashi Iwai) [Orabug: 39886954] {CVE-2026-74505}
- bpf: lwt: Fix dst reference leak on reroute failure (Luoxuanqiang)
- Bluetooth: HIDP: validate numbered report payloads (Sangho Lee) [Orabug: 39886961] {CVE-2026-74507}
- Bluetooth: HIDP: reject frames without a transaction header (Sangho Lee) [Orabug: 39886965] {CVE-2026-74508}
- Bluetooth: hci_sync: Fix advertising data UAFs (Chengfeng Ye) [Orabug: 39886969] {CVE-2026-74509}
- Bluetooth: mgmt: fix UAF in pair command cancellation (Zihan Xi) [Orabug: 39886972] {CVE-2026-74510}
- Bluetooth: mgmt: fix pending command UAF in EIR updates (Zihan Xi)
- Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() (Greg Kroah-Hartman)
- Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req() (Greg Kroah-Hartman)
- audit: fix potential use-after-free in audit_del_rule() (Luxiao Xu) [Orabug: 39886978] {CVE-2026-74512}
- audit: fix potential integer overflow in audit_log_n_string() (Zhan Xusheng)
- sctp: validate Adaptation Indication parameter length (Charles Vosburgh) [Orabug: 39973393] {CVE-2026-80717}
- KVM: s390: pci: Validate AIBV and AISB before pinning guest pages (Farhan Ali)
- KVM: s390: pci: Fix NULL dereference on AIBV allocation failure (Farhan Ali)
- KVM: s390: pci: Reject adapter interrupt forwarding if already enabled (Farhan Ali) [Orabug: 39886986] {CVE-2026-74515}
- KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (Sean Christopherson) [Orabug: 39886989] {CVE-2026-74516}
- tracing/probes: Reject $arg0 in meta argument expansion (Jhonraushan)
- mm/vmstat: fold stranded per-cpu node stats when a node comes online (Gregory Price)
- mm/hugetlb: fix list corruption in allocate_file_region_entries() (Xiangfeng Cai) [Orabug: 39886993] {CVE-2026-74518}
- mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() (Zi Yan)
- fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes (Kiryl Shutsemau)
- mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE (Kefeng Wang) [Orabug: 39973307] {CVE-2026-80686}
- fortify: Disable -Wstringop-overread in tests (Nathan Chancellor)
- pinctrl: bm1880: add missing select GENERIC_PINCONF (Benjamin Boortz)
- erofs: cap LZMA stream pool size (Michael Bommarito) [Orabug: 39982319] {CVE-2026-80892}
- pinctrl: devicetree: don't free uninitialized dev_name on error path (Karl Mehltretter) [Orabug: 39886996] {CVE-2026-74519}
- pinctrl: microchip-sgpio: add missing select REGMAP_MMIO (Benjamin Boortz)
- rhashtable: clear stale iter->p on table restart (Cen Zhang) [Orabug: 39830599] {CVE-2026-64563}
- ksmbd: fix use-after-free in __close_file_table_ids() (Namjae Jeon)
- ksmbd: return success for deferred final close (Namjae Jeon)
- qede: sync udp_tunnel ports outside qede_lock in the recovery path (Denis V. Lunev) [Orabug: 39887009] {CVE-2026-74523}
- net: libwx: fix FDIR ATR queue mismatch for software VLAN packets (Jiawen Wu)
- net: dsa: mt7530: error out on failed reads in MT7531 PHY polling (Daniel Golle)
- net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend (Daniel Golle)
- riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove (Karl Mehltretter)
- accel/qaic: use sizeof(*trans_hdr) for transaction length check (Muhammad Bilal)
- tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions (Masami Hiramatsu)
- tracing/mmiotrace: Remove reference to unused per CPU data pointer (Steven Rostedt)
- tracing: Remove TRACE_EVENT_FL_FILTERED logic (Zheng Yejian)
- tracing/mmiotrace: Reset dropped_count in mmio_reset_data() (Masami Hiramatsu)
- can: isotp: check register_netdevice_notifier() error in module init (Heminhong)
- net: sxgbe: check descriptor ring allocation failures (Chenguang Zhao)
- net: sxgbe: free TX rings on RX allocation failure (Chenguang Zhao)
- scsi: target: Clear cmd_cnt when initial counter enrollment fails (Leon Romanovsky)
- scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req (Benjamin Block)
- scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE (Zheng Tan) [Orabug: 39973317] {CVE-2026-80691}
- net: phylink: put link_gpio if phylink_create fails (Christian Marangi)
- Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync (Pauli Virtanen)
- Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (Pauli Virtanen) [Orabug: 39887029] {CVE-2026-74531}
- Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (Pauli Virtanen)
- Bluetooth: btintel: Validate length before parsing diagnostics TLV (Zijun Hu) [Orabug: 39887031] {CVE-2026-74532}
- Bluetooth: ISO: avoid deadlocks in iso_sock_timeout (Pauli Virtanen) [Orabug: 39887037] {CVE-2026-74535}
- Bluetooth: ISO: fix leaking sk after socket release (Pauli Virtanen) [Orabug: 39887039] {CVE-2026-74536}
- Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis() (Pauli Virtanen)
- Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos (Pauli Virtanen)
- Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp (Jiale Yao) [Orabug: 39887047] {CVE-2026-74540}
- Bluetooth: ISO: clear iso_data always when detaching conn from hcon (Pauli Virtanen) [Orabug: 39887051] {CVE-2026-74541}
- idpf: Fix mailbox IRQ name leak on request failure (Yuho Choi)
- idpf: adjust TxQ ring count minimum (Joshua Hay)
- hwmon: (pmbus) Fix return value from pmbus_update_byte_data() (Guenter Roeck)
- net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller (Chenguang Zhao)
- net: ethernet: mtk_eth_soc: add consts for irq index (Frank Wunderlich)
- net: ethernet: mtk_eth_soc: support named IRQs (Frank Wunderlich)
- wifi: mac80211: validate individual TWT params before driver setup (Catherine) [Orabug: 39973405] {CVE-2026-80722}
- net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister() (Eric Dumazet) [Orabug: 39887055] {CVE-2026-74543}
- powerpc/boot: Fix treeboot-akebono CPU node lookup check (Thorsten Blum)
- powerpc/boot: Fix treeboot-currituck CPU node lookup check (Thorsten Blum)
- powerpc/boot: Fix simpleboot CPU node lookup check (Thorsten Blum)
- rtase: fix double free of multi-frag skb on DMA map failure (Yun Lu)
- hwmon: (adt7470) Fix PWM auto temp state array and bounds check (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read (Luiz Angelo Daros de Luca) [Orabug: 39887069] {CVE-2026-74546}
- hwmon: (adt7470) Use cached PWM frequency value (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread (Luiz Angelo Daros de Luca) [Orabug: 39887073] {CVE-2026-74547}
- hwmon: (adt7470) Fix cache updated before hardware write on I2C error (Luiz Angelo Daros de Luca)
- hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors (Luiz Angelo Daros de Luca)
- forcedeth: fix UAF of txrx_stats in nv_remove (Chenguang Zhao) [Orabug: 39887078] {CVE-2026-74548}
- net: bridge: mrp: fix Option TLV length in MRP_Test frames (David Corvaglia)
- hwmon: (nct6775-core) Prevent access to unsupported weight registers (Guenter Roeck) [Orabug: 39887082] {CVE-2026-74549}
- net: do not send ICMP/NDISC Redirects when peer allocation fails (Eric Dumazet) [Orabug: 39887086] {CVE-2026-74550}
- hwmon: (nzxt-smart2) DMA-align output buffer (Guenter Roeck)
- hwmon: (lm90) Only report alarms if driver is ready (Guenter Roeck) [Orabug: 39887092] {CVE-2026-74552}
- hwmon: (sht3x) Fix unaligned accesses (Guenter Roeck) [Orabug: 39973330] {CVE-2026-80695}
- hwmon: (ltc4282) Fix reading the minimum alarm voltage (Guenter Roeck)
- hwmon: (ina2xx) Fix various overflow issues (Guenter Roeck)
- hwmon: (ina2xx) Shift INA234 shunt and current registers (Jonas Rebmann)
- hwmon: (ina2xx) Add support for INA234 (Ian Ray)
- hwmon: (ina2xx) Make it easier to add more devices (Ian Ray)
- hwmon: (ina226) Add support for SY24655 (Wenliang Yan)
- hwmon: (ina2xx) Add support for INA260 (Guenter Roeck)
- hwmon: (ina2xx) Add support for has_alerts configuration flag (Guenter Roeck)
- hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 (Guenter Roeck) [Orabug: 39887094] {CVE-2026-74553}
- spi: spi-cadence: Move TX FIFO full busy-wait into FIFO (Srikanth Boyapally)
- spi: spi-cadence: supports transmission with bits_per_word of 16 and 32 (Jun Guo)
- smb: client: fix buffer leaks in SMB1 read and write (Dawei Feng)
- scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race (Xingui Yang) [Orabug: 39887099] {CVE-2026-74555}
- scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (Hyeongjun An) [Orabug: 39887101] {CVE-2026-74556}
- scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer (Hyeongjun An) [Orabug: 39887105] {CVE-2026-74557}
- pinctrl-amd: Don't clear S4 wake bits at probe (Mario Limonciello)
- netfilter: nft_payload: fix mask build for partial field offload (Xiang Mei) [Orabug: 39890484] {CVE-2026-74579}
- ipvs: do not mangle ICMP replies for non-first fragments (Julian Anastasov)
- ipvs: fix places with wrong packet offsets (Julian Anastasov)
- ipvs: fix the checksum validations (Julian Anastasov) [Orabug: 39982335] {CVE-2026-80901}
- netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH (Pablo Neira Ayuso) [Orabug: 39887121] {CVE-2026-74564}
- netfilter: nf_tables: make nft_object rhltable per table (Pablo Neira Ayuso) [Orabug: 39887125] {CVE-2026-74565}
- assoc_array: trim the final shortcut word using the current chunk end (Michael Bommarito)
- keys: make keyring key-chunk byte order agree with keyring_diff_objects() (Michael Bommarito) [Orabug: 39887129] {CVE-2026-74566}
- keys: fix out-of-bounds read in keyring_get_key_chunk() (Michael Bommarito) [Orabug: 39887133] {CVE-2026-74567}
- KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type (Fabrice Derepas)
- Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation (Sebastian Andrzej Siewior)
- drm/mediatek: Check CRTC state before freeing (Ruoyu Wang)
- netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (Xiang Mei) [Orabug: 39887138] {CVE-2026-74569}
- phy: zynqmp: fix runtime PM leak on probe allocation failure (Radhey Shyam Pandey)
- phy: zynqmp: fix clock error handling in xpsgtr_phy_init() (Radhey Shyam Pandey)
- phy-zynqmp: Postpone getting clock rate until actually needed (Mike Looijmans)
- btrfs: zoned: fix deadlock between metadata writeback and transaction commit (Johannes Thumshirn) [Orabug: 39887145] {CVE-2026-74572}
- btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag (Qu Wenruo)
- of: reserved_mem: prevent OOB when too many dynamic regions are defined (Sang-Heon Jeon) [Orabug: 39973411] {CVE-2026-80723}
- of: reserved_mem: Add code to dynamically allocate reserved_mem array (Oreoluwa Babatunde)
- ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare)
- ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup (Uday Khare)
- ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources() (Radhey Shyam Pandey)
- ahci: Introduce ahci_ignore_port() helper (Damien Le Moal)
- ata: libahci_platform: support non-consecutive port numbers (Josua Mayer)
- ata: sata_mv: accept 1 or 2 resources in platform probe (Rosen Penev)
- gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe() (Abdun Nihaal)
- dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() (Yuho Choi) [Orabug: 39887148] {CVE-2026-74574}
- dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA (Hongling Zeng)
- pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 (Konrad Dybcio)
- pinctrl: qcom: Unconditionally mark gpio as wakeup enable (Sneh Mankad)
- thunderbolt: Prevent XDomain delayed work use-after-free on disconnect (Michael Bommarito) [Orabug: 39887151] {CVE-2026-74575}
- netconsole: avoid OOB reads, msg is not nul-terminated (Jakub Kicinski) [Orabug: 39331620] {CVE-2026-43197}
- bpf: Reset register bounds before narrowing retval range in check_mem_access() (Tristan Madani) [Orabug: 39885096] {CVE-2026-72111}
- HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (Benjamin Tissoires)
- HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (Lee Jones)
- HID: logitech-dj: Standardise hid_report_enum variable nomenclature (Lee Jones)
- net: mpls: initialize rtm_tos in mpls_getroute() (Yehyeong Lee) [Orabug: 39887157] {CVE-2026-74577}
- netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge() (Lorenzo Bianconi)
- um: Preserve errno within signal handler (Tiwei Bie)
- kunit: tool: skip stty when stdin is not a tty (Shuvam Pandey)
- kunit: tool: Terminate kernel under test on SIGINT (David Gow)
- um: Set parent death signal for userspace process (Benjamin Berg)
- um: Set parent-death signal for write_sigio thread/process (Tiwei Bie)
- um: Set parent-death signal for ubd io thread/process (Tiwei Bie)
- um: Use os_set_pdeathsig helper in winch thread/process (Tiwei Bie)
- um: Set parent death signal for winch thread/process (Benjamin Berg)
- um: Add os_set_pdeathsig helper function (Tiwei Bie)
- LTS version: v6.12.102 (Saeed Mirzamohammadi)
- LTS version: v6.12.101 (Saeed Mirzamohammadi)
- KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug (Nikunj A Dadhania) [Orabug: 39859304] {CVE-2026-68093}
- afs: Fix uninit var in afs_alloc_anon_key() (David Howells)
- Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() (Pavitra Jha) [Orabug: 39838812] {CVE-2026-53364}
- Bluetooth: hci_conn: Fix not cleaning up PA_LINK connections (Luiz Augusto von Dentz)
- Bluetooth: hci_conn: Fix not cleaning up Broadcaster/Broadcast Source (Luiz Augusto von Dentz)
- Bluetooth: hci_conn: Fix running bis_cleanup for hci_conn->type PA_LINK (Luiz Augusto von Dentz)
- afs: handle CB.InitCallBackState3 requests without a server record (Nan Li) [Orabug: 39886717] {CVE-2026-74425}
- afs: Fix delayed allocation of a cell's anonymous key (David Howells) [Orabug: 39838822] {CVE-2025-68299}
- dpll: fix clock quality level reporting (Ivan Vecera)
- afs: Set vllist to NULL if addr parsing fails (Edward Adam Davis)
- net: ethernet: Remove accidental duplication in Kconfig file (Lukas Bulwahn)
- wifi: nl80211: fix nl80211_start_radar_detection return value (Nicolas Escande)
- rxrpc: Fix locking issues with the peer record hash (David Howells)
- rxrpc: Disable IRQ, not BH, to take the lock for ->attend_link (David Howells)
- gpu: Fix uninitialized buddy for built-in drivers (Koen Koning)
- net/mlx5e: Fix NULL pointer dereference in ioctl module EEPROM query (Gal Pressman)
- usb: musb: omap2430: Do not put borrowed of_node in probe (Guangshuo Li)
- usb: musb: omap2430: clean up probe error handling (Johan Hovold)
- USB: gadget: fsl-udc: fix dev_printk() device (Johan Hovold)
- USB: gadget: Use str_enable_disable-like helpers (Krzysztof Kozlowski)
- net: ipa: fix SMEM state handle leaks in SMP2P init (Haoxiang Li)
- net: macb: drop in-flight Tx SKBs on close (Théo Lebrun) [Orabug: 39884757] {CVE-2026-72017}
- fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list (Reinette Chatre) [Orabug: 39884752] {CVE-2026-72015}
- ata: libata-core: Reject an invalid concurrent positioning ranges count (Bryam Vargas) [Orabug: 39884802] {CVE-2026-72030}
- octeontx2-pf: fix SQB pointer leak on init failure (Dawei Feng)
- net/mlx5: HWS, fix matcher leak on resize target setup failure (Dawei Feng) [Orabug: 39884812] {CVE-2026-72032}
- ipmi: fix refcount leak in i_ipmi_request() (Xu Wang) [Orabug: 39884844] {CVE-2026-72040}
- bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline() (Breno Leitao)
- bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c (Breno Leitao)
- octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (Junrui Luo) [Orabug: 39884854] {CVE-2026-72045}
- gpio: mt7621: avoid corruption of shared interrupt trigger state (Sergio Paracuellos)
- gve: fix header buffer corruption with header-split and HW-GRO (Ankit Garg) [Orabug: 39884857] {CVE-2026-72046}
- net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) [Orabug: 39884874] {CVE-2026-72051}
- net: mana: Validate the packet length reported by the NIC (Dexuan Cui) [Orabug: 39884928] {CVE-2026-72065}
- locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (Thomas Gleixner)
- wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() (Maoyi Xie) [Orabug: 39884955] {CVE-2026-72070}
- dm: avoid leaking the caller's thread keyring via the table device file (Ingo Blechschmidt) [Orabug: 39885074] {CVE-2026-72103}
- cred: add scoped_with_kernel_creds() (Christian Brauner)
- cred: add kernel_cred() helper (Christian Brauner)
- cleanup: fix scoped_class() (Christian Brauner)
- cleanup: add a scoped version of CLASS() (Christian Brauner)
- dm-integrity: fix leaking uninitialized kernel memory (Mikulas Patocka) [Orabug: 39885068] {CVE-2026-72101}
- block: remove redundant GD_NEED_PART_SCAN in add_disk_final() (Connor Williamson)
- block: add helper add_disk_final() (Ming Lei)
- ovl: use linked upper dentry in copy-up tmpfile (Souvik Banerjee)
- nvmet-auth: reject short AUTH_RECEIVE buffers (Michael Bommarito) [Orabug: 39885160] {CVE-2026-72130}
- nvmet: Introduce nvmet_req_transfer_len() (Damien Le Moal)
- tcp: Decrement tcp_md5_needed static branch (Dmitry Safonov)
- tcp: defer md5sig_info kfree past RCU grace period in tcp_connect (Michael Bommarito)
- xfrm: nat_keepalive: avoid double free on send error (Qianyu Luo) [Orabug: 39885179] {CVE-2026-72137}
- xfrm: Use nested-BH locking for nat_keepalive_sk_ipv[46] (Sebastian Andrzej Siewior)
- i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (Vincent Jardin)
- i2c: imx: separate atomic, dma and non-dma use case (Stefan Eichenberger)
- dmaengine: dw-edma-pcie: Reject devices without driver data (Koichiro Den)
- dmaengine: dw-edma: Fix confusing cleanup.h syntax (Krzysztof Kozlowski)
- dma: dw-edma: Fix build warning in dw_edma_pcie_probe() (Abinash Singh)
- mm/sparse-vmemmap: fix DAX vmemmap accounting with optimization (Muchun Song)
- mm: prepare to move subsection_map_init() to mm/sparse-vmemmap.c (David Hildenbrand)
- mtd: maps: vmu-flash: fix fault in unaligned fixup (Florian Fuchs)
- mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages (Muchun Song)
- landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path (Bryam Vargas) [Orabug: 39885339] {CVE-2026-72183}
- landlock: Prepare to use credential instead of domain for fowner (Mickaël Salaün)
- mm/sparse-vmemmap: fix vmemmap accounting underflow (Muchun Song)
- mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch (Deepanshu Kartikey) [Orabug: 39885447] {CVE-2026-72213}
- remoteproc: xlnx: Check remote core state (Tanmay Shah)
- SUNRPC: Return an error from xdr_buf_to_bvec() on overflow (Chuck Lever)
- SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists (Chuck Lever)
- sunrpc: allocate a separate bvec array for socket sends (Jeff Layton)
- NFSD: pass nfsd_file to nfsd_iter_read() (Mike Snitzer)
- gpu/buddy: bail out of try_harder when alignment cannot be honoured (Arunpravin Paneer Selvam) [Orabug: 39885559] {CVE-2026-72244}
- gpu: Move DRM buddy allocator one level up (part two) (Joel Fernandes)
- netfilter: nft_fib: reject fib expression on the netdev egress hook (Theodor Arsenij Larionov-Trichkine) [Orabug: 39885588] {CVE-2026-72254}
- netfilter: nf_tables: remove register tracking infrastructure (Florian Westphal)
- netfilter: nf_tables: Remove unused nft_reduce_is_readonly() (Yue Haibing)
- netfilter: bitwise: rename some boolean operation functions (Jeremy Sowden)
- netfilter: nf_conntrack_sip: validate skb_dst() before accessing it (Pablo Neira Ayuso) [Orabug: 39885584] {CVE-2026-72253}
- netfilter: nf_conntrack_sip: remove net variable shadowing (Florian Westphal)
- ASoC: mediatek: mt8183: Check runtime resume during probe (Cássio Gabriel)
- ASoC: mediatek: mt8183-afe-pcm: use local dev pointer in driver callbacks (Chen-Yu Tsai)
- ASoC: mediatek: mt8183-afe-pcm: Support >32 bit DMA addresses (Chen-Yu Tsai)
- ASoC: mediatek: mt8183-afe-pcm: Shorten memif_data table using macros (Chen-Yu Tsai)
- ASoC: mediatek: mt8192: Check runtime resume during probe (Cássio Gabriel)
- ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable (Tang Bin)
- arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers (Abel Vesa)
- arm64: dts: qcom: correct RBR opp entry (Dmitry Baryshkov)
- octeontx2-pf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)
- octeontx2-vf: clear stale mailbox IRQ state before request_irq() (Runyu Xiao)
- VDUSE: avoid leaking information to userspace (Jason Wang) [Orabug: 39885722] {CVE-2026-72305}
- vduse: take out allocations from vduse_dev_alloc_coherent (Eugenio Pérez)
- vduse: remove unused vaddr parameter of vduse_domain_free_coherent (Eugenio Pérez)
- vduse: Use fixed 4KB bounce pages for non-4KB page size (Sheng Zhao)
- tipc: restrict socket queue dumps in enqueue tracepoints (Li Xiasong) [Orabug: 39885708] {CVE-2026-72299}
- rxrpc: Fix socket notification race (David Howells)
- rxrpc: Fix notification vs call-release vs recvmsg (David Howells)
- rxrpc: Use irq-disabling spinlocks between app and I/O thread (David Howells)
- rxrpc: Don't need barrier for ->tx_bottom and ->acks_hard_ack (David Howells)
- rxrpc: Fix CPU time starvation in I/O thread (David Howells)
- fbcon: Use correct type for vc_resize() return value (Jiacheng Yu)
- fbcon: Rename struct fbcon_ops to struct fbcon_par (Thomas Zimmermann)
- xfs: don't replace the wrong part of the cow fork (Darrick J. Wong)
- xfs: factor out xfs_attr3_leaf_init (Long Li)
- rxrpc: serialize kernel accept preallocation with socket teardown (Li Daming) [Orabug: 39886736] {CVE-2026-74436}
- rxrpc: Pull out certain app callback funcs into an ops table (David Howells)
- ALSA: hda: Fix cached processing coefficient verbs (Xu Rao)
- ALSA: hda: conexant: Remove mic bias threshold override (Zhang Heng)
- i2c: i801: fix hardware state machine corruption in error path (Mingyu Wang) [Orabug: 39760898] {CVE-2026-64205}
- audit: fix recursive locking deadlock in audit_dupe_exe() (Ricardo Robaina) [Orabug: 39859310] {CVE-2026-68096}
- audit: use 'unsigned int' instead of 'unsigned' (Ricardo Robaina)
- audit: widen ino fields to u64 (Jeff Layton)
- VFS/audit: introduce kern_path_parent() for audit (Neil Brown)
- i2c: davinci: Unregister cpufreq notifier on probe failure (Haoxiang Li)
- fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() (Sebastian Alba Vives)
- iommufd: Avoid partial fault group delivery in iommufd_fault_fops_read() (Nicolin Chen)
- iommufd: Break the loop on failure in iommufd_fault_fops_read() (Nicolin Chen) [Orabug: 39785853] {CVE-2026-64290}
- iommufd: Reject invalid read count in iommufd_fault_fops_read() (Nicolin Chen)
- mm/damon/core: disallow overlapping input ranges for damon_set_regions() (Seongjae Park) [Orabug: 39859554] {CVE-2026-68164}
- mm/damon/core: validate ranges in damon_set_regions() (Seongjae Park) [Orabug: 39859556] {CVE-2026-68165}
- rust: allow suspicious_runtime_symbol_definitions lint for Rust >= 1.98 (Miguel Ojeda)
- gve: fix Rx queue stall on alloc failure (Eddie Phillips) [Orabug: 39859431] {CVE-2026-68129}
- net: pcs: xpcs: fix SGMII state reading (Coia Prant)
- io_uring/rw: fix missing ERESTARTSYS conversion in read paths (Yitang Yang)
- drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources (Harry Wentland)
- ksmbd: validate ACE size against SID sub-authorities (Namjae Jeon)
- ksmbd: bound DACL dedup walk to copied ACEs (Namjae Jeon)
- bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (Jiayuan Chen) [Orabug: 39622003] {CVE-2026-53078}
- drm/amdgpu: fix aperture mapping leak (Asad Kamal) [Orabug: 39859330] {CVE-2026-68102}
- drm/amdgpu: invoke pm_genpd_remove() before freeing genpd (Ce Sun)
- drm/amdgpu: fix division by zero with invalid uvd dimensions (Boyuan Zhang) [Orabug: 39859349] {CVE-2026-68106}
- drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (Luca Coelho) [Orabug: 39868455] {CVE-2026-68429}
- drm/amdgpu/vcn4: avoid rereading IB param length (Boyuan Zhang) [Orabug: 39859353] {CVE-2026-68107}
- drm/amdgpu/vce: fix integer overflow in image size (Boyuan Zhang) [Orabug: 39859357] {CVE-2026-68108}
- drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() (Alex Deucher) [Orabug: 39859365] {CVE-2026-68110}
- drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (Alex Deucher) [Orabug: 39859369] {CVE-2026-68111}
- drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() (Alex Deucher) [Orabug: 39859375] {CVE-2026-68112}
- drm/amdgpu/gfx8: drop unecessary BUG_ON() (Alex Deucher) [Orabug: 39868458] {CVE-2026-68430}
- drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() (Alex Deucher) [Orabug: 39859379] {CVE-2026-68113}
- drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() (Alex Deucher) [Orabug: 39859801] {CVE-2026-68246}
- drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() (Alex Deucher) [Orabug: 39859387] {CVE-2026-68115}
- drm/amd/pm: make pp_features read-only when scpm is enabled (Yang Wang)
- drm/amd/pm: fix amdgpu_pm_info power display units (Yang Wang)
- vxlan: mdb: Fix source list corruption on a failed replace (James Raphael Tiovalen) [Orabug: 39859391] {CVE-2026-68116}
- tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (Daehyeon Ko) [Orabug: 39859393] {CVE-2026-68117}
- tcp: initialize standalone TCP-AO response padding (Yizhou Zhao) [Orabug: 39859402] {CVE-2026-68119}
- rtase: Workaround for TX hang caused by hardware packet parsing (Justin Lai)
- pppoe: reload header pointer after dev_hard_header() (Asim Viladi Oglu Manizada) [Orabug: 39859406,40035127] {CVE-2026-68121}
- openvswitch: fix GSO userspace truncation underflow (Kyle Zeng) [Orabug: 39859411] {CVE-2026-68123}
- mctp: serial: handle zero-length frames to prevent rx buffer overflow (Doruk Tan Ozturk)
- mac802154: llsec: reject frames shorter than the authentication tag (Doruk Tan Ozturk) [Orabug: 39859417] {CVE-2026-68125}
- mac802154: hold an interface reference across the scan worker (Ibrahim Hashimov) [Orabug: 39859421] {CVE-2026-68126}
- ila: reload IPv6 header after pskb_may_pull in checksum adjust (Michael Bommarito)
- ice: use READ_ONCE() to access cached PHC time (Sergey Temerkhanov)
- ice: reject out-of-range ptype in ice_parser_profile_init (Aleksandr Loktionov) [Orabug: 39859428] {CVE-2026-68128}
- ksmbd: defer destroy_previous_session() until after NTLM authentication (James Montgomery)
- rbd: Reset positive result codes to zero in object map update path (Raphael Zimmer) [Orabug: 39859437] {CVE-2026-68131}
- ice: fix PTP Call Trace during PTP release (Paul Greenwalt) [Orabug: 39859445] {CVE-2026-68133}
- net: hip04: fix RX buffer leak on build_skb failure (Fan Wu)
- net: gro: fix double aggregation of flush-marked skbs (Shiming Cheng) [Orabug: 39859452] {CVE-2026-68136}
- net/x25: fix use-after-free in x25_kill_by_neigh() (David Lee)
- net/mlx5e: Use sender devcom for MPV master-up (Manjunath Patil) [Orabug: 39859465] {CVE-2026-68139}
- net/iucv: fix use-after-free of a severed iucv_path (Bryam Vargas)
- net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() (Hidayath Khan)
- geneve: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk) [Orabug: 39859476] {CVE-2026-68142}
- net: slip: serialize receive against buffer reallocation (Sungmin Kang) [Orabug: 39859480] {CVE-2026-68143}
- vxlan: require CAP_NET_ADMIN in the device netns for changelink (Doruk Tan Ozturk) [Orabug: 39868465] {CVE-2026-68432}
- phonet: pep: fix use-after-free in pep_get_sb() (Breno Leitao)
- iommu/vt-d: Disallow SVA if page walk is not coherent (Lu Baolu)
- iomap: fix out-of-bounds bitmap_set() with zero-length range (Zhang Yi) [Orabug: 39859489] {CVE-2026-68145}
- ftrace: Add global mutex to serialize trace_parser access (Tengda Wu) [Orabug: 39859491] {CVE-2026-68146}
- fscrypt: Add missing superblock check in find_or_insert_direct_key() (Eric Biggers) [Orabug: 39859499] {CVE-2026-68148}
- fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (Amir Goldstein) [Orabug: 39859501] {CVE-2026-68149}
- binfmt_elf_fdpic: only honour the first PT_INTERP (Christian Brauner)
- ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP (Chancel Liu)
- amt: fix use-after-free in AMT delayed works (Shihuang Liu)
- libceph: remove debugfs files before client teardown (Douya Le) [Orabug: 39859510] {CVE-2026-68153}
- libceph: reject zero bucket types in crush_decode (Douya Le) [Orabug: 39859514] {CVE-2026-68154}
- libceph: Reject monmaps advertising zero monitors (Raphael Zimmer) [Orabug: 39859518] {CVE-2026-68155}
- libceph: refresh auth->authorizer_buf{,_len} after authorizer update (Shuangpeng Bai) [Orabug: 39859522] {CVE-2026-68156}
- libceph: guard missing CRUSH type name lookup (Zhao Zhang) [Orabug: 39859526] {CVE-2026-68157}
- libceph: Fix multiplication overflow in decode_new_up_state_weight() (Raphael Zimmer) [Orabug: 39859529] {CVE-2026-68158}
- libceph: bound get_version reply decode to front len (Douya Le) [Orabug: 39868470] {CVE-2026-68433}
- ceph: fix refcount leak in ceph_readdir() (Xu Wang)
- ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (Bryam Vargas) [Orabug: 39859538] {CVE-2026-68160}
- sctp: close UDP tunnel sockets during netns teardown (Zhiling Zou) [Orabug: 39859544] {CVE-2026-68161}
- sctp: avoid auth_enable sysctl UAF during netns teardown (Zhiling Zou) [Orabug: 39859548] {CVE-2026-68162}
- sctp: don't free the ASCONF's own transport in DEL-IP processing (Jun Yang) [Orabug: 39830605] {CVE-2026-64564}
- mptcp: only set DATA_FIN when a mapping is present (Michael Bommarito)
- mptcp: decrement subflows counter on failed passive join (Chenguang Zhao)
- Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates" (Will Deacon)
- arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates (Will Deacon)
- tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() (Masami Hiramatsu)
- tracing/probes: Fix potential underflow in LEN_OR_ZERO macro (Masami Hiramatsu)
- tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args() (Masami Hiramatsu)
- tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() (Masami Hiramatsu)
- tracing: Fix resource leak on mmiotrace trace_pipe close (Deepakraog)
- tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev (Steven Rostedt)
- misc: nsm: pin the module while the device is open (Xu Rao)
- misc: nsm: only unlock nsm_dev on post-lock error paths (Runyu Xiao)
- intel_th: fix MSC output device reference leak (Guangshuo Li) [Orabug: 39860419] {CVE-2026-68180}
- mei: bus: access mei_device under device_lock on cleanup (Alexander Usyskin) [Orabug: 39859588] {CVE-2026-68181}
- serial: sc16is7xx: implement gpio get_direction() callback (Hugo Villeneuve)
- uio_hv_generic: Bind to FCopy device by default (Ben Hutchings)
- comedi: comedi_parport: deal with premature interrupt (Ian Abbott)
- x86/boot/compressed: Disable jump tables (Nathan Chancellor)
- firmware: stratix10-svc: fix memory leaks and list corruption bugs (Tze Yee Ng)
- cdrom: fix stack out-of-bounds read in CDROMVOLCTRL (Xu Rao) [Orabug: 39859600] {CVE-2026-68184}
- LoongArch: Retrieve CPU package ID from PPTT when available (Rong Bao)
- LoongArch: Move jump_label_init() before parse_early_param() (Kanglong Wang)
- LoongArch: Fix oops during single-step debugging (Haoran Jiang)
- objtool/rust: add one more noreturn Rust function for Rust 1.99.0 (Miguel Ojeda)
- rust: allow clippy::unwrap_or_default globally (Alexandre Courbot)
- platform/loongarch: laptop: Explicitly reset bl_powered state when suspend (Zixing Liu)
- binfmt_misc: set have_execfd only once the interpreter is opened (Christian Brauner) [Orabug: 39859610] {CVE-2026-68186}
- exec: fix unsigned loop counter wrap in transfer_args_to_stack() (Christian Brauner) [Orabug: 39859613] {CVE-2026-68187}
- Bluetooth: RFCOMM: Fix session UAF in set_termios (Chengfeng Ye) [Orabug: 39859617] {CVE-2026-68188}
- Bluetooth: hci_sync: Protect UUID list traversal (Chengfeng Ye) [Orabug: 39859621] {CVE-2026-68189}
- staging: rtl8723bs: fix inverted HT40 secondary channel offset (Minjea Kim)
- staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() (Moksh Panicker)
- wifi: brcmfmac: make release_scratchbuffers idempotent (Fan Wu) [Orabug: 39859628] {CVE-2026-68192}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Lucid Duck) [Orabug: 39859632] {CVE-2026-68193}
- wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses (Lucid Duck) [Orabug: 39859634] {CVE-2026-68194}
- wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses (Lucid Duck)
- wifi: wilc1000: validate assoc response length before subtracting header (Huihui Huang)
- wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper (Doruk Tan Ozturk) [Orabug: 39859643] {CVE-2026-68197}
- wifi: ath6kl: fix OOB access from firmware ADDBA window size (Tristan Madani) [Orabug: 39859651] {CVE-2026-68199}
- ALSA: timer: don't re-enter an instance callback that is still running (Norbert Szetei) [Orabug: 39859655] {CVE-2026-68200}
- ALSA: timer: drain a slave's callback before its master detaches it (Norbert Szetei) [Orabug: 39859657] {CVE-2026-68201}
- ALSA: seq: close a re-opened queue timer in the destructor (Norbert Szetei) [Orabug: 39859659] {CVE-2026-68202}
- media: vpif_capture: fix OF node reference imbalance (Johan Hovold)
- media: vivid: fix cleanup bugs in vivid_init() (Guangshuo Li)
- media: vivid: check for vb2_is_busy() when toggling caps (Hans Verkuil)
- media: vivid: add vivid_update_reduced_fps() (Hans Verkuil)
- media: vimc: fix reference leak on failed device registration (Guangshuo Li)
- media: vidtv: fix reference leak on failed device registration (Guangshuo Li)
- media: vb2: use ssize_t for vb2_read/vb2_write (Zile Xiong)
- media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely (Sakari Ailus)
- media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (Mirela Rabulea) [Orabug: 39859671] {CVE-2026-68205}
- media: v4l2-ctrls: validate HEVC active reference counts (Pengpeng Hou) [Orabug: 39859675] {CVE-2026-68206}
- media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() (Sergey Shtylyov)
- media: ti: vpe: unwind v4l2 device registration on probe error (Myeonghun Pak)
- media: tegra-video: vi: fix invalid u32 return value in format lookup (Hungyu Lin)
- media: sun4i-csi: Return queued buffers on start_streaming() failure (Valery Borovsky)
- media: stm32: dcmi: unregister notifier on probe failure (Myeonghun Pak)
- media: saa7134: Fix a possible memory leak in saa7134_video_init1 (Ma Ke) [Orabug: 39859694] {CVE-2026-68212}
- media: rtl2832_sdr: Return queued buffers on start_streaming() failure (Valery Borovsky) [Orabug: 39859698] {CVE-2026-68213}
- media: rtl2832: fix use-after-free in rtl2832_remove() (Deepanshu Kartikey) [Orabug: 39859703] {CVE-2026-68214}
- media: radio-si476x: Unregister v4l2_device on probe failure (Myeonghun Pak)
- media: qcom: camss: Fix RDI streaming for CSID GEN2 (Bryan O'Donoghue)
- media: pwc: Return queued buffers on start_streaming() failure (Valery Borovsky) [Orabug: 39859712] {CVE-2026-68216}
- media: pwc: Drain fill_buf on start_streaming() failure (Valery Borovsky) [Orabug: 39859716] {CVE-2026-68217}
- media: pci: dm1105: Free allocated workqueue (Krzysztof Kozlowski) [Orabug: 39859720] {CVE-2026-68218}
- media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding (Guoniu Zhou)
- media: nxp: imx8-isi: Fix potential out-of-bounds issues (Guoniu Zhou)
- media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path (Xiaolei Wang)
- media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure (Xiaolei Wang)
- media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe (Xiaolei Wang)
- media: nuvoton: npcm-video: fix memory leaks in probe and remove (David Carlier)
- media: nuvoton: npcm-video: fix error handling in npcm_video_init() (David Carlier)
- media: msi2500: Return queued buffers on start_streaming() failure (Valery Borovsky)
- media: meson: vdec: Fix memory leak in error path of vdec_open (Anand Moon)
- media: marvell-cam: fix missing pci_disable_device() on remove (Guangshuo Li)
- media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges (Marco Nenciarini)
- media: i2c: alvium: fix critical pointer access in alvium_ctrl_init (Martin Hecht)
- media: cx23885: add ioremap return check and cleanup (Wang Jun) [Orabug: 39859741] {CVE-2026-68226}
- media: cx231xx: fix devres lifetime (Johan Hovold) [Orabug: 39859745] {CVE-2026-68227}
- media: chips-media: wave5: Move src_buf Removal to finish_encode (Brandon Brnich)
- media: cedrus: skip invalid H.264 reference list entries (Pengpeng Hou)
- media: cedrus: Fix missing cleanup in error path (Samuel Holland)
- media: cedrus: clean up media device on probe failure (Myeonghun Pak)
- media: cec: seco: unregister adapter on IR probe failure (Myeonghun Pak)
- media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (David Carlier)
- media: airspy: Return queued buffers on start_streaming() failure (Valery Borovsky)
- drm/vc4: Prevent shader BO mappings from becoming writable (Linmao Li) [Orabug: 39868504] {CVE-2026-68445}
- drm/vmwgfx: Validate vmw_surface_metadata::array_size (Ian Forbes) [Orabug: 39868510] {CVE-2026-68446}
- drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved (Zhu Lingshan) [Orabug: 39859765] {CVE-2026-68234}
- drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge (Mario Limonciello)
- drm/amd/display: dce100: skip non-DP stream encoders for DP MST (Andriy Korud) [Orabug: 39859769] {CVE-2026-68235}
- drm/amd/display: set new_stream to NULL after release (Xu Wang) [Orabug: 39859774] {CVE-2026-68236}
- drm/amdgpu: Fix VFCT bus number matching with soft filter (Mario Limonciello)
- drm/panthor: return error on truncated firmware (Osama Abdelkader)
- drm/gfx10: Program DB_RING_CONTROL (Alex Deucher)
- drm/amd/pm: fix smu14 power limit range calculation (Yang Wang)
- drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (Joonas Lahtinen) [Orabug: 39859791] {CVE-2026-68243}
- drm/i915/gem: Do not leak siblings[] on proto context error (Joonas Lahtinen) [Orabug: 39859794] {CVE-2026-68244}
- drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() (Shahyan Soltani) [Orabug: 39859797] {CVE-2026-68245}
- drm/i915/bios: range check LFP Data Block panel_type2 (Jani Nikula) [Orabug: 39859806] {CVE-2026-68247}
- drm/i915: Return NULL on error in active_instance (Joonas Lahtinen) [Orabug: 39859808] {CVE-2026-68248}
- drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() (Alex Deucher) [Orabug: 39859811] {CVE-2026-68249}
- drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() (Alex Deucher) [Orabug: 39859815] {CVE-2026-68250}
- drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() (Alex Deucher) [Orabug: 39859819] {CVE-2026-68251}
- drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() (Alex Deucher) [Orabug: 39859823] {CVE-2026-68252}
- drm/virtio: bound EDID block reads to the response buffer (Bryam Vargas) [Orabug: 39859835] {CVE-2026-68255}
- drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (Xu Wang) [Orabug: 39859839] {CVE-2026-68256}
- drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (Thomas Zimmermann)
- drm/amdkfd: fix 32-bit overflow in CWSR total size calculation (Yongqiang Sun) [Orabug: 39859841] {CVE-2026-68257}
- drm/amdkfd: Check bounds in allocate_event_notification_slot (David Francis) [Orabug: 39859851] {CVE-2026-68259}
- drm/amdkfd: Use kvcalloc to allocate arrays (David Francis)
- drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM (Icenowy Zheng)
- drm/imagination: fix error checking of pvr_vm_context_lookup() (Luigi Santivetti)
- drm/imagination: Fix user array stride in pvr_set_uobj_array() (Shuvam Pandey)
- drm/imagination: Fix double call to drm_sched_entity_fini() (Brajesh Gupta)
- drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds (Matthew Brost)
- drm/radeon: fix r100_copy_blit for large BOs (Pavel Ondračka)
- drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (Xu Wang)
- drm/i915/gem: Add missing nospec on parallel submit slot (Joonas Lahtinen) [Orabug: 39859872] {CVE-2026-68269}
- drm/displayid: fix Tiled Display Topology ID size (Jani Nikula)
- drm/nouveau: fix reversed error cleanup order in ucopy functions (Junrui Luo) [Orabug: 39859875] {CVE-2026-68271}
- drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (Mario Limonciello) [Orabug: 39859878] {CVE-2026-68272}
- drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (Timur Kristóf)
- drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older (Timur Kristóf)
- drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2) (Timur Kristóf)
- drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (Ashutosh Desai) [Orabug: 39859887] {CVE-2026-68277}
- drm/imagination: Fit paired fragment job in the correct CCCB (Alessio Belle)
- drm/dp/mst: fix buffer overflows in sideband chunk accumulation (Ashutosh Desai) [Orabug: 39859891] {CVE-2026-68278}
- drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (Ashutosh Desai) [Orabug: 39859895] {CVE-2026-68279}
- drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (Vitor Soares)
- drm/imagination: Count paired job fence as dependency in prepare_job() (Alessio Belle)
- drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (Sergey Shtylyov)
- drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (Biju Das)
- bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (Chengfeng Ye) [Orabug: 39859908] {CVE-2026-68284}
- ice: fix LAG recipe to profile association (Marcin Szycik)
- ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV (Vincent Chen)
- net: ipv6: fix dif and sdif mismatch in raw6_icmp_error (Li Rongqing)
- net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation (Alexei Lazar)
- net/mlx5e: Report zero bandwidth for non-ETS traffic classes (Alexei Lazar)
- net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule (Yael Chemla)
- net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (Gal Pressman) [Orabug: 39859936] {CVE-2026-68293}
- net/mlx5: Refactor EEPROM query error handling to return status separately (Gal Pressman)
- net: qrtr: restrict socket creation to the initial network namespace (Aldo Ariel Panzardo) [Orabug: 39859939] {CVE-2026-68294}
- hinic: remove unused ethtool RSS user configuration buffers (Chenguang Zhao)
- ppp: annotate data races in ppp_generic (Eric Dumazet)
- ppp: enable TX scatter-gather (Qingfang Deng)
- ppp: convert to percpu netstats (Qingfang Deng)
- ppp: use IFF_NO_QUEUE in virtual interfaces (Qingfang Deng)
- ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup (Eric Dumazet)
- net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM (Yun Zhou) [Orabug: 39859947] {CVE-2026-68296}
- net: stmmac: enable the MAC on link up for all supported speeds (Vadik Likholetov)
- net: stmmac: reset residual action in L3L4 filters on delete (Nazim Amirul)
- net: stmmac: fix l3l4 filter rejecting unsupported offload requests (Nazim Amirul)
- drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem (José Expósito)
- tipc: fix u16 MTU truncation in media and bearer MTU validation (Cen Zhang) [Orabug: 39859949] {CVE-2026-68297}
- iomap: correct the range of a partial dirty clear (Zhang Yi)
- vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (Harshaka Narayana) [Orabug: 39859954] {CVE-2026-68299}
- sctp: auth: verify auth requirement when auth_chunk is NULL (Luoqing) [Orabug: 39859958] {CVE-2026-68300}
- net: dpaa: fix mode setting (Michael Walle)
- net: hsr: fix memory leak on slave unregistration by removing synced VLANs (Eric Dumazet) [Orabug: 39859962] {CVE-2026-68301}
- net: bridge: vlan: fix vlan range dumps starting with pvid (Nikolay Aleksandrov)
- amt: make the head writable before rewriting the L2 header (Michael Bommarito)
- amt: re-read skb header pointers after every pull (Michael Bommarito)
- ovl: fix trusted xattr escape prefix matching (Chenyichong)
- wifi: brcmfmac: fix 802.1X-SHA256 call trace warning (Shelley Yang) [Orabug: 39859972] {CVE-2026-68304}
- wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() (Lorenzo Bianconi)
- wifi: mt76: mt7925: fix crash in reset link replay (Sean Wang) [Orabug: 39859979] {CVE-2026-68307}
- wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() (Lorenzo Bianconi)
- wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv() (Lorenzo Bianconi) [Orabug: 39868486] {CVE-2026-68439}
- wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() (Lorenzo Bianconi) [Orabug: 39859983] {CVE-2026-68309}
- wifi: mt76: mt7915: guard HE capability lookups (Ruoyu Wang) [Orabug: 39859988] {CVE-2026-68310}
- wifi: mt76: mt7925: guard link STA in decap offload (Guangshuo Li) [Orabug: 39859990] {CVE-2026-68311}
- tipc: fix infinite loop in __tipc_nl_compat_dumpit (Helen Koike) [Orabug: 39859995] {CVE-2026-68313}
- nexthop: initialize extack in nh_res_bucket_migrate() (Xiang Mei) [Orabug: 39837137] {CVE-2026-64576}
- gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (Xiang Mei) [Orabug: 39837140] {CVE-2026-64577}
- selftests: openvswitch: add config file (Matthieu Baerts)
- selftests: af_unix: add USER_NS config (Matthieu Baerts)
- tls: device: push pending open record on splice EOF (Rishikesh Jethwani)
- net: mctp i3c: clean up notifier and buses if driver register fails (Myeonghun Pak)
- sctp: validate stream count in sctp_process_strreset_inreq() (Cen Zhang) [Orabug: 39860001] {CVE-2026-68315}
- pds_core: check for workqueue allocation failure (Nikhil P. Rao)
- pds_core: fix auxiliary device add/del races (Nikhil P. Rao) [Orabug: 39860008] {CVE-2026-68317}
- pds_core: order completion reads after the ownership check (Nikhil P. Rao)
- pds_core: yield the CPU while waiting for the adminq to drain (Nikhil P. Rao)
- pds_core: fix use-after-free on workqueue during remove (Nikhil P. Rao) [Orabug: 39860011] {CVE-2026-68318}
- pds_core: fix deadlock between reset thread and remove (Nikhil P. Rao) [Orabug: 39860014] {CVE-2026-68319}
- sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (Ji'An Zhou) [Orabug: 39860017] {CVE-2026-68320}
- net: txgbe: fix FDIR filter leak on remove (Chenguang Zhao)
- amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN (Prashanth Kumar K R)
- pds_core: reject component parameter in legacy firmware update (Nikhil P. Rao)
- wifi: mac80211: recalculate TIM when a station enters power save (Andrew Pope)
- iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (Li Rongqing)
- iommu/amd: Bound the early ACPI HID map (Pengpeng Hou) [Orabug: 39860036] {CVE-2026-68325}
- wifi: mwifiex: bound uAP association event IEs to the event buffer (He Wei) [Orabug: 39860040] {CVE-2026-68326}
- wan: wanxl: Only reset hardware after BAR mapping (Ruoyu Wang)
- nfp: Check resource mutex allocation (Ruoyu Wang) [Orabug: 39860049] {CVE-2026-68328}
- wifi: mac80211: tear down new links on vif update error path (Xiang Mei) [Orabug: 39837133] {CVE-2026-64574}
- iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (Guanghui Feng) [Orabug: 39860053] {CVE-2026-68329}
- dpaa2-eth: put MAC endpoint device on disconnect (Guangshuo Li)
- dpaa2-switch: put MAC endpoint device on disconnect (Guangshuo Li)
- gtp: parse extension headers before reading inner protocol (Zhixing Chen)
- bonding: fix devconf_all NULL dereference when IPv6 is disabled (Zhaolong Zhang) [Orabug: 39860073] {CVE-2026-68336}
- net/packet: avoid fanout hook re-registration after unregister (David Lee) [Orabug: 39860079] {CVE-2026-68338}
- netlink: specs: rt-link: convert bridge port flag attributes to u8 (Danielle Ratson)
- Bluetooth: btusb: validate Realtek vendor event length (Pengpeng Hou) [Orabug: 39860083] {CVE-2026-68339}
- regulator: mt6358: use regmap helper to read fixed LDO calibration (Daniel Golle)
- hwmon: occ: validate poll response sensor blocks (Pengpeng Hou)
- smb: client: validate DFS referral PathConsumed (Chenyichong) [Orabug: 39860093] {CVE-2026-68343}
- hwmon: (asus-ec-sensors) add missed handle for ENOMEM (Eugene Shalygin)
- hwmon: (asus-ec-sensors) fix EC read intervals (Eugene Shalygin)
- hwmon: (asus-ec-sensors) fix looping over banks while reading from EC (Eugene Shalygin)
- drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook() (Mostafa Saleh)
- wifi: iwlwifi: mvm: fix read in wake packet notification handler (Shahar Tzarfati)
- wifi: iwlwifi: mvm: validate SAR GEO response payload size (Anjaneyulu)
- ASoC: cs35l56: Use complete_all() to signal init_completion (Richard Fitzgerald)
- ASoC: cs35l56: Fix potential probe() deadlock (Richard Fitzgerald)
- ASoC: cs35l56: Don't use devres to unregister component (Richard Fitzgerald)
- ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI (Shengjiu Wang)
- ALSA: hda: cs35l41: validate and free ACPI mute object (Guangshuo Li) [Orabug: 39860100] {CVE-2026-68346}
- ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state() (Denis Arefev)
- ASoC: tas2781: bound firmware description string parsing (Pengpeng Hou) [Orabug: 39860104] {CVE-2026-68348}
- btrfs: free mapping node on duplicate reloc root insert (Guanghui Yang) [Orabug: 39868528] {CVE-2026-68450}
- btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps (Leo Martins) [Orabug: 39868497] {CVE-2026-68442}
- btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8 (You-Kai Zheng)
- wifi: carl9170: fix buffer overflow in rx_stream failover path (Tristan Madani) [Orabug: 39860106] {CVE-2026-68349}
- wifi: carl9170: fix OOB read from off-by-two in TX status handler (Tristan Madani) [Orabug: 39860110] {CVE-2026-68350}
- wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read (Tristan Madani) [Orabug: 39860114] {CVE-2026-68351}
- wifi: ath6kl: fix OOB read from firmware IE lengths in connect event (Tristan Madani) [Orabug: 39860119] {CVE-2026-68352}
- wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler (Tristan Madani) [Orabug: 39860123] {CVE-2026-68353}
- firewire: net: Fix fragmented datagram reassembly (Ruoyu Wang)
- wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (Manivannan Sadhasivam)
- wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (Manivannan Sadhasivam)
- wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() (Dmitry Morgun) [Orabug: 39860132] {CVE-2026-68355}
- watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() (Tzung-Bi Shih)
- hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop (Guenter Roeck)
- hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop (Guenter Roeck)
- hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop (Guenter Roeck)
- hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop (Guenter Roeck)
- hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop (Edward Adam Davis)
- wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin (Gaole Zhang) [Orabug: 39860151] {CVE-2026-68362}
- wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (Cheng Yongkang) [Orabug: 39860155] {CVE-2026-68363}
- usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits (Zhang Xincheng)
- RISC-V: KVM: Serialize virtual interrupt pending state updates (Xie Bo)
- crypto: rsa-pkcs1pad: Don't WARN on an empty digest (Doruk Tan Ozturk)
- USB: serial: option: add TDTECH MT5710-CN (Chukun Pan)
- USB: serial: keyspan_pda: fix data loss on receive throttling (Johan Hovold)
- USB: serial: io_edgeport: cap received transmit credits (Sunho Park) [Orabug: 39860163] {CVE-2026-68365}
- USB: serial: ftdi_sio: add support for E+H FXA291 (Tim Pambor)
- usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer (Muhammad Bilal)
- usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown (Fan Wu)
- usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() (Sonali Pradhan)
- USB: gadget: fsl-udc: fix device name leak on probe failure (Johan Hovold)
- USB: gadget: snps-udc: fix device name leak on probe failure (Johan Hovold)
- usb: gadget: printer: fix infinite loop in printer_read() (Melbin K Mathew)
- usb: gadget: f_midi: cancel pending IN work before freeing the midi object (Fan Wu)
- usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback (Wang Jinchao)
- usb: chipidea: fix usage_count leak when autosuspend_delay is negative (Xu Yang)
- USB: storage: add NO_ATA_1X quirk for Longmai USB Key (Huang Wei)
- usb: core: port: Deattach Type-C connector on component unbind (Chia-Lin Kao) [Orabug: 39860190] {CVE-2026-68372}
- wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() (Huihui Huang) [Orabug: 39860192] {CVE-2026-68373}
- usb: core: sysfs: add lock to bos_descriptors_read() (Griffin Kroah-Hartman) [Orabug: 39860197] {CVE-2026-68374}
- mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (Weiming Shi) [Orabug: 39837113] {CVE-2026-64569}
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [Orabug: 39860204] {CVE-2026-68376}
- net/sched: act_tunnel_key: Defer dst_release to RCU callback (Jamal Hadi Salim) [Orabug: 39860208] {CVE-2026-68377}
- drm/i915/selftests: Fix GT PM sort comparators (Emre Cecanpunar)
- ksmbd: validate compound request size before reading StructureSize2 (Xiang Mei)
- ksmbd: pin conn during async oplock break notification (Qihang)
- smb: move some duplicate definitions to common/cifsglob.h (Zhangguodong)
- drm/xe/wopcm: fix WOPCM size for LNL+ (Daniele Ceraolo Spurio)
- can: j1939: fix lockless local-destination check (Shuhao Fu)
- riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus() (Mark Harris)
- s390/checksum: Fix csum_partial() without vector facility (Vasily Gorbik)
- bpf, sockmap: Reject unhashed UDP sockets on sockmap update (Michal Luczaj) [Orabug: 39860227] {CVE-2026-68386}
- powerpc/vtime: Initialize starttime at boot for native accounting (Shrikanth Hegde)
- powerpc/time: Prepare to stop elapsing in dynticks-idle (Frederic Weisbecker)
- powerpc/85xx: Add fsl,ifc to common device ids (Rosen Penev)
- drm/i915/gt: use correct selftest config symbol (Pengpeng Hou)
- smb/client: handle overlapping allocated ranges in fallocate (Huiwen He) [Orabug: 39860231] {CVE-2026-68388}
- Bluetooth: hci_qca: Clear memdump state on invalid dump size (Ruoyu Wang)
- Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (Pauli Virtanen) [Orabug: 39860238] {CVE-2026-68391}
- Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync (Pauli Virtanen) [Orabug: 39860240] {CVE-2026-68392}
- Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update (Cen Zhang) [Orabug: 39860244] {CVE-2026-68394}
- Bluetooth: qca: fix NVM tag length underflow in TLV parser (Xiang Mei)
- ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (Takashi Iwai)
- accel/ivpu: Fix wrong register read in LNL failure diagnostics (Karol Wachowski)
- ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning (Rosen Penev)
- ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts (Rosen Penev)
- ata: sata_dwc_460ex: use platform_get_irq() (Rosen Penev)
- ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered (Rosen Penev)
- net/iucv: take a reference on the socket found in afiucv_hs_rcv() (Bryam Vargas)
- ipv4: fib: free fib_alias with kfree_rcu() on insert error path (Weiming Shi) [Orabug: 39837127] {CVE-2026-64572}
- ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (Norbert Szetei) [Orabug: 39860257] {CVE-2026-68398}
- cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq (Rafael J. Wysocki)
- firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context (Pushpendra Singh)
- ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (Uday Khare)
- ASoC: cs42l43: Correct report for forced microphone jack (Charles Keepax)
- ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() (Vijendar Mukunda)
- ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (Christian Hewitt)
- wifi: cfg80211: bound element ID read when checking non-inheritance (He Wei) [Orabug: 39860270] {CVE-2026-68402}
- wifi: brcmfmac: initialize SDIO data work before cleanup (Runyu Xiao) [Orabug: 39860274] {CVE-2026-68403}
- wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (Cen Zhang) [Orabug: 39860282] {CVE-2026-68405}
- wifi: cfg80211: reject unsupported PMSR FTM location requests (Catherine)
- wifi: cfg80211: validate PMSR FTM preamble range (Catherine) [Orabug: 39860286] {CVE-2026-68406}
- wifi: cfg80211: validate PMSR measurement type data (Catherine)
- wifi: nl80211: validate nested MBSSID IE blobs (Catherine)
- wifi: cfg80211: derive S1G beacon TSF from S1G fields (Catherine)
- wifi: nl80211: free RNR data on MBSSID mismatch (Catherine) [Orabug: 39860291] {CVE-2026-68407}
- wifi: p54: validate RX frame length in p54_rx_eeprom_readback() (Xiang Mei) [Orabug: 39837122] {CVE-2026-64571}
- wifi: libertas: fix memory leak in helper_firmware_cb() (Dawei Feng) [Orabug: 39860297] {CVE-2026-68410}
- wifi: mac80211: fix fils_discovery double free on alloc failure (Xiang Mei) [Orabug: 39837118] {CVE-2026-64570}
- wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure (Xiang Mei) [Orabug: 39837110] {CVE-2026-64568}
- wifi: mac80211_hwsim: clamp virtio RX length before skb_put (Bryam Vargas) [Orabug: 39860301] {CVE-2026-68411}
- wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (Abdun Nihaal) [Orabug: 39860308] {CVE-2026-68413}
- wifi: cfg80211: cancel sched scan results work on unregister (Cen Zhang) [Orabug: 39860312] {CVE-2026-68414}
- xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert (Xiang Mei) [Orabug: 39837148] {CVE-2026-64579}
- xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() (Xiang Mei) [Orabug: 39837153] {CVE-2026-64580}
- RDMA/irdma: Prevent overflows in memory contiguity checks (Aleksandrova Alyona)
- selftests/alsa: Fix memory leak in find_controls error path (Malaya Kumar Rout)
- mtd: fix double free and WARN_ON in add_mtd_device() error paths (Xue Lei) [Orabug: 39860318] {CVE-2026-68416}
- RDMA/siw: publish QP after initialization (Ruoyu Wang)
- RDMA/hns: Fix potential integer overflow in mhop hem cleanup (Danila Chernetsov)
- RDMA/erdma: initialize ret for empty receive WR lists (Ruoyu Wang)
- RDMA/irdma: Prevent rereg_mr for non-mem regions (Jacob Moroni) [Orabug: 39860329] {CVE-2026-68419}
- RDMA/umem: Add pinned revocable dmabuf import interface (Jacob Moroni)
- RDMA/cma: Fix hardware address comparison length in netevent callback (Or Gerlitz)
- firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (Unnathi Chalicheemala) [Orabug: 39868501] {CVE-2026-68444}
- btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (Filipe Manana) [Orabug: 39860334] {CVE-2026-68422}
- btrfs: reject free space cache with more entries than pages (Xiang Mei) [Orabug: 39837106] {CVE-2026-64567}
- mtd: nand: mtk-ecc: stop on ECC idle timeouts (Pengpeng Hou)
- mtd: mtdswap: remove debugfs stats file on teardown (Pengpeng Hou)
- IB/mad: Drop unmatched RMPP responses before reassembly (Michael Bommarito) [Orabug: 39860339] {CVE-2026-68425}
- arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234 (Sumit Gupta)
- soc: qcom: ice: Allow explicit votes on 'iface' clock for ICE (Harshal Dev)
- Input: ims-pcu - fix logic error in packet reset (Dmitry Torokhov)
- Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (Seungjin Bae)
- xprtrdma: Clear receive-side ownership pointers on release (Chuck Lever)
- crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin (Mikko Perttunen)
- gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings (Mikko Perttunen) [Orabug: 39860347] {CVE-2026-68427}
- dmaengine: sh: rz-dmac: Move interrupt request after everything is set up (Claudiu Beznea)
- can: isotp: serialize TX state transitions under so->rx_lock (Oliver Hartkopp) [Orabug: 39885144] {CVE-2026-72124}
- can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER (Oliver Hartkopp) [Orabug: 39885147] {CVE-2026-72125}
- can: bcm: track a single source interface for ANYDEV timeout/throttle ops (Oliver Hartkopp) [Orabug: 39885107] {CVE-2026-72115}
- can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() (Oliver Hartkopp) [Orabug: 39885115] {CVE-2026-72117}
- can: bcm: fix stale rx/tx ops after device removal (Oliver Hartkopp) [Orabug: 39885111] {CVE-2026-72116}
- can: bcm: add missing device refcount for CAN filter removal (Oliver Hartkopp) [Orabug: 39885099] {CVE-2026-72113}
- can: bcm: validate frame length in bcm_rx_setup() for RTR replies (Oliver Hartkopp) [Orabug: 39885103] {CVE-2026-72114}
- can: bcm: extend bcm_tx_lock usage for data and timer updates (Oliver Hartkopp) [Orabug: 39885123] {CVE-2026-72119}
- can: bcm: fix CAN frame rx/tx statistics (Oliver Hartkopp) [Orabug: 39885119] {CVE-2026-72118}
- can: bcm: add locking when updating filter and timer values (Oliver Hartkopp) [Orabug: 39885132] {CVE-2026-72121}
- KVM: x86/mmu: Fix use-after-free on vendor module reload (Phil Rosenthal) [Orabug: 39860351] {CVE-2026-68428}
- KVM: nVMX: Hide shadow VMCS right after VMCLEAR (Hyunwoo Kim) [Orabug: 39830594] {CVE-2026-64562}
- KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN (Venkatesh Srinivas)
- seqlock: Allow UBSAN_ALIGNMENT to fail optimizing (Heiko Carstens)
- seqlock: Allow KASAN to fail optimizing (Peter Zijlstra)
- seqlock: Cure some more scoped_seqlock() optimization fails (Peter Zijlstra)
- fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race (Kiryl Shutsemau) [Orabug: 39885310] {CVE-2026-72175}
- drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker (Ryosuke Yasuoka)
- netfilter: nf_tables: revert commit_mutex usage in reset path (Brian Witte) [Orabug: 39451770] {CVE-2026-45901}
- netfilter: nft_quota: use atomic64_xchg for reset (Brian Witte)
- netfilter: nft_counter: serialize reset with spinlock (Brian Witte) [Orabug: 39451756] {CVE-2026-45897}
- selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs (Daniel Borkmann)
- bpf: Fix ld_{abs,ind} failure path analysis in subprogs (Daniel Borkmann) [Orabug: 39622050] {CVE-2026-53090}
- net: airoha: Move airoha_eth driver in a dedicated folder (Lorenzo Bianconi)
- platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug (Guixiong Wei)

[6.12.0-207.100.1]
- x86/bugs: Enable IBPB flush on BPF JIT allocation (Pawan Gupta) [Orabug: 39786491] {CVE-2026-64507}
- sched/fair: Disable affine wakeups at NUMA domain levels on Exadata (Daniel Jordan) [Orabug: 39810704]
- block: flip iter directions in blk_rq_integrity_map_user() (Caleb Sander) [Orabug: 39836233]
- x86/alternatives: Guard struct alt_instr kABI layout (Saeed Mirzamohammadi) [Orabug: 39860416]

[6.12.0-206.100.3]
- can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure (Guangshuo Li)
- ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes (Norbert Szetei) [Orabug: 39887268] {CVE-2026-74503}
- sched/deadline: Use revised wakeup rule only for running dl_server (Gabriele Monaco)
- scsi: ufs: core: Cancel RTC work in active-active suspend (Guangshuo Li)
- net: airoha: Fix register index for Tx-fwd counter configuration (Wayen Yan)
- netfilter: nf_conntrack_expect: restore helper propagation via expectation (Pablo Neira Ayuso)
- Enable Time slice extension (Prakash Sangappa) [Orabug: 39047408]
- rseq: Increase struct rseq size to match mainline linux (Prakash Sangappa) [Orabug: 39047408]
- selftests/rseq: Make registration flexible for legacy and optimized mode (Thomas Gleixner) [Orabug: 39047408]
- selftests/rseq: Skip tests if time slice extensions are not available (Thomas Gleixner) [Orabug: 39047408]
- rseq: Don't advertise time slice extensions if disabled (Thomas Gleixner) [Orabug: 39047408]
- selftests/rseq: Add rseq slice histogram script (Peter Zijlstra) [Orabug: 39047408]
- rseq: Lower default slice extension (Peter Zijlstra) [Orabug: 39047408]
- rseq: Move slice_ext_nsec to debugfs (Peter Zijlstra) [Orabug: 39047408]
- rseq: Allow registering RSEQ with slice extension (Peter Zijlstra) [Orabug: 39047408]
- selftests/rseq: Implement time slice extension test (Thomas Gleixner) [Orabug: 39047408]
- entry: Hook up rseq time slice extension (Thomas Gleixner) [Orabug: 39047408]
- rseq: Implement rseq_grant_slice_extension() (Thomas Gleixner) [Orabug: 39047408]
- rseq: Reset slice extension when scheduled (Thomas Gleixner) [Orabug: 39047408]
- rseq: Implement time slice extension enforcement timer (Prakash Sangappa) [Orabug: 39047408]
- rseq: Implement syscall entry work for time slice extensions (Thomas Gleixner) [Orabug: 39047408]
- rseq: Implement sys_rseq_slice_yield() (Thomas Gleixner) [Orabug: 39047408]
- rseq: Add prctl() to enable time slice extensions (Thomas Gleixner) [Orabug: 39047408]
- rseq: Add statistics for time slice extensions (Thomas Gleixner) [Orabug: 39047408]
- rseq: Provide static branch for runtime debugging (Thomas Gleixner) [Orabug: 39047408]
- rseq: Expose lightweight statistics in debugfs (Thomas Gleixner) [Orabug: 39047408]
- rseq: Provide static branch for time slice extensions (Thomas Gleixner) [Orabug: 39047408]
- rseq: Add fields and constants for time slice extension (Prakash Sangappa) [Orabug: 39047408]
- Revert "Sched: Scheduler time slice extension" (Prakash Sangappa) [Orabug: 39047408]
- Revert "Sched: Add scheduler stat for cpu time slice extension" (Prakash Sangappa) [Orabug: 39047408]
- Revert "Scheduler extension change under Oracle Extensions and modify enum value" (Prakash Sangappa) [Orabug: 39047408]
- net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover (Matt Fleming) [Orabug: 39203117,39870622] {CVE-2026-64122}
- net/mlx5e: Fix deadlocks between devlink and netdev instance locks (Cosmin Ratiu) [Orabug: 39203117,39870450] {CVE-2026-45907}
- net/mlx5: HWS, ignore flow level for multi-dest table (Yevgeny Kliteynik) [Orabug: 39203117]
- net/mlx5: Prevent flow steering mode changes in switchdev mode (Moshe Shemesh) [Orabug: 39203117]
- net/mlx5: HWS, Fix pattern destruction in mlx5hws_pat_get_pattern error path (Lama Kayal) [Orabug: 39203117]
- net/mlx5: HWS, Fix memory leak in hws_action_get_shared_stc_nic error flow (Lama Kayal) [Orabug: 39203117]
- net/mlx5: HWS, Fix memory leak in hws_pool_buddy_init error path (Lama Kayal) [Orabug: 39203117]
- selftests: drv-net: hds: restore hds settings (Jakub Kicinski) [Orabug: 39203117]
- net/mlx5: Restore missing scheduling node cleanup on vport enable failure (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: Fix QoS reference leak in vport enable error path (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: Destroy vport QoS element when no configuration remains (Carolina Jubran) [Orabug: 39203117]
- net/mlx5e: Preserve tc-bw during parent changes (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: Remove default QoS group and attach vports directly to root TSAR (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: HWS, Fix table creation UID (Alex Vesker) [Orabug: 39203117]
- net/mlx5: HWS, don't rehash on every kind of insertion failure (Yevgeny Kliteynik) [Orabug: 39203117]
- selftests: drv-net: wait for carrier (Jakub Kicinski) [Orabug: 39203117]
- netdevsim: Fix wild pointer access in nsim_queue_free(). (Kuniyuki Iwashima) [Orabug: 39203117]
- vfio/pci: Do vf_token checks for VFIO_DEVICE_BIND_IOMMUFD (Jason Gunthorpe) [Orabug: 39203117]
- net/mlx5e: Expose TIS via devlink tx reporter diagnose (Feng Liu) [Orabug: 39203117]
- net/mlx5e: Fix potential deadlock by deferring RX timeout recovery (Shahar Shitrit) [Orabug: 39203117]
- selftests: drv-net: Make command requirements explicit (Gal Pressman) [Orabug: 39203117]
- net/mlx5: Fix build -Wframe-larger-than warnings (Zhu Yanjun) [Orabug: 39203117]
- mlx5: access ->pp through netmem_desc instead of page (Byungchul Park) [Orabug: 39203117]
- netdevsim: access ->pp through netmem_desc instead of page (Byungchul Park) [Orabug: 39203117]
- netmem, mlx4: access ->pp_ref_count through netmem_desc instead of page (Byungchul Park) [Orabug: 39203117]
- netmem: use netmem_desc instead of page to access ->pp in __netmem_get_pp() (Byungchul Park) [Orabug: 39203117]
- netmem: introduce struct netmem_desc mirroring struct page (Byungchul Park) [Orabug: 39203117]
- netdevsim: add fw_update_flash_chunk_time_ms debugfs knobs (Jiri Pirko) [Orabug: 39203117]
- devlink: Fix excessive stack usage in rate TC bandwidth parsing (Carolina Jubran) [Orabug: 39203117]
- RDMA/mlx5: Refactor optional counters steering code (Patrisious Haddad) [Orabug: 39203117]
- RDMA/mlx5: Add DMAH object support (Yishai Hadas) [Orabug: 39203117]
- RDMA/core: Introduce a DMAH object and its alloc/free APIs (Yishai Hadas) [Orabug: 39203117]
- IB/core: Add UVERBS_METHOD_REG_MR on the MR object (Yishai Hadas) [Orabug: 39203117]
- net/mlx5: Add support for device steering tag (Yishai Hadas) [Orabug: 39203117]
- net/mlx5: Expose IFC bits for TPH (Yishai Hadas) [Orabug: 39203117]
- PCI/TPH: Expose pcie_tph_get_st_table_size() (Yishai Hadas) [Orabug: 39203117]
- net/mlx5e: Remove duplicate mkey from SHAMPO header (Lama Kayal) [Orabug: 39203117]
- net/mlx5e: SHAMPO, Remove mlx5e_shampo_get_log_hd_entry_size() (Lama Kayal) [Orabug: 39203117]
- net/mlx5e: SHAMPO, Cleanup reservation size formula (Lama Kayal) [Orabug: 39203117]
- selftests: drv-net: Test XDP_PASS/DROP support (Mohsin Bashir) [Orabug: 39203117]
- net: netdevsim: hook in XDP handling (Jakub Kicinski) [Orabug: 39203117]
- RDMA/mlx5: Fix incorrect MKEY masking (Leon Romanovsky) [Orabug: 39203117]
- RDMA/mlx5: Fix returned type from _mlx5r_umr_zap_mkey() (Leon Romanovsky) [Orabug: 39203117]
- net/mlx5: Expose cable_length field in PFCC register (Oren Sidi) [Orabug: 39203117]
- net/mlx5: Add IFC bits to support RSS for IPSec offload (Jianbo Liu) [Orabug: 39203117]
- net/mlx5e: fix kdoc warning on eswitch.h (Moshe Shemesh) [Orabug: 39203117]
- net/mlx5: HWS, Enable IPSec hardware offload in legacy mode (Lama Kayal) [Orabug: 39203117]
- net/mlx5: Fix an IS_ERR() vs NULL bug in esw_qos_move_node() (Dan Carpenter) [Orabug: 39203117]
- netdevsim: remove redundant branch (Dennis Chen) [Orabug: 39203117]
- selftests: net: prevent Python from buffering the output (Jakub Kicinski) [Orabug: 39203117]
- netlink: specs: define input-xfrm enum in the spec (Jakub Kicinski) [Orabug: 39203117]
- net/mlx5e: TX, Fix dma unmapping for devmem tx (Dragos Tatulea) [Orabug: 39203117]
- RDMA/mlx5: remove redundant check on err on return expression (Colin Ian King) [Orabug: 39203117]
- net/mlx5e: Add device PCIe congestion ethtool stats (Dragos Tatulea) [Orabug: 39203117]
- net/mlx5e: Create/destroy PCIe Congestion Event object (Dragos Tatulea) [Orabug: 39203117]
- selftests: net: add netpoll basic functionality test (Breno Leitao) [Orabug: 39203117]
- selftests: drv-net: add helper/wrapper for bpftrace (Jakub Kicinski) [Orabug: 39203117]
- netdevsim: implement peer queue flow control (Breno Leitao) [Orabug: 39203117]
- RDMA/uverbs: Add a common way to create CQ with umem (Michael Margolin) [Orabug: 39203117]
- net/mlx5: Expose disciplined_fr_counter through HCA capabilities in mlx5_ifc (Carolina Jubran) [Orabug: 39203117]
- RDMA/mlx5: Optimize DMABUF mkey page size (Edward Srouji) [Orabug: 39203117]
- RDMA/mlx5: Align mkc page size capability check to PRM (Michael Guralnik) [Orabug: 39203117]
- net/mlx5: Expose HCA capability bits for mkey max page size (Michael Guralnik) [Orabug: 39203117]
- net: netdevsim: Support setting dev->perm_addr on port creation (Toke Høiland-Jørgensen) [Orabug: 39203117]
- selftests: drv-net: Add bpftool util (Mohsin Bashir) [Orabug: 39203117]
- net/mlx5e: RX, Remove unnecessary RQT redirects (Tariq Toukan) [Orabug: 39203117]
- net/mlx5: Warn when write combining is not supported (Maor Gottlieb) [Orabug: 39203117]
- net/mlx5e: Replace recursive VLAN push handling with an iterative loop (Gal Pressman) [Orabug: 39203117]
- net/mlx5e: CT: extract a memcmp from a spinlock section (Cosmin Ratiu) [Orabug: 39203117]
- net/mlx5e: Remove unused VLAN insertion logic in TX path (Carolina Jubran) [Orabug: 39203117]
- eth: mlx5: migrate to the *_rxfh_context ops (Jakub Kicinski) [Orabug: 39203117]
- net/mlx5: Fix spelling mistake "disabliing" -> "disabling" (Colin Ian King) [Orabug: 39203117]
- net/mlx5: Add HWS as secondary steering mode (Moshe Shemesh) [Orabug: 39203117]
- net/mlx5: HWS, Shrink empty matchers (Yevgeny Kliteynik) [Orabug: 39203117]
- net/mlx5: HWS, Refactor rule skip logic (Vlad Dogaru) [Orabug: 39203117]
- net/mlx5: HWS, remove incorrect comment (Yevgeny Kliteynik) [Orabug: 39203117]
- net/mlx5: HWS, remove unused create_dest_array parameter (Vlad Dogaru) [Orabug: 39203117]
- netmem: use _Generic to cover const casting for page_to_netmem() (Byungchul Park) [Orabug: 39203117]
- page_pool: rename __page_pool_alloc_pages_slow() to __page_pool_alloc_netmems_slow() (Byungchul Park) [Orabug: 39203117]
- page_pool: rename __page_pool_release_page_dma() to __page_pool_release_netmem_dma() (Byungchul Park) [Orabug: 39203117]
- page_pool: rename page_pool_return_page() to page_pool_return_netmem() (Byungchul Park) [Orabug: 39203117]
- mlxbf_gige: emit messages during open and probe failures (David Thompson) [Orabug: 39203117]
- selftests: drv-net: Add test for devlink-rate traffic class bandwidth distribution (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: Manage TC arbiter nodes and implement full support for tc-bw (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: Add traffic class scheduling support for vport QoS (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: Add support for setting tc-bw on nodes (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: Add no-op implementation for setting tc-bw on rate objects (Carolina Jubran) [Orabug: 39203117]
- selftest: netdevsim: Add devlink rate tc-bw test (Carolina Jubran) [Orabug: 39203117]
- devlink: Extend devlink rate API with traffic classes bandwidth management (Carolina Jubran) [Orabug: 39203117]
- netlink: introduce type-checking attribute iteration for nlmsg (Carolina Jubran) [Orabug: 39203117]
- net/mlx5: fs, fix RDMA TRANSPORT init cleanup flow (Patrisious Haddad) [Orabug: 39203117]
- RDMA/mlx5: Check CAP_NET_RAW in user namespace for devx create (Parav Pandit) [Orabug: 39203117]
- time/timecounter: Fix the lie that struct cyclecounter is const (Greg Kroah-Hartman) [Orabug: 39203117]
- RDMA/mlx5: Check CAP_NET_RAW in user namespace for anchor create (Parav Pandit) [Orabug: 39203117]
- RDMA/mlx5: Check CAP_NET_RAW in user namespace for flow create (Parav Pandit) [Orabug: 39203117]
- RDMA/uverbs: Check CAP_NET_RAW in user namespace for flow create (Parav Pandit) [Orabug: 39203117]
- net/mlx5e: Fix error handling in RQ memory model registration (Wangfushuai) [Orabug: 39203117]
- selftests: forwarding: lib: Split setup_wait() (Petr Machata) [Orabug: 39203117]
- RDMA/ipoib: Use parent rdma device net namespace (Mark Bloch) [Orabug: 39203117]
- RDMA/mlx5: Allocate IB device with net namespace supplied from core dev (Mark Bloch) [Orabug: 39203117]
- RDMA/core: Extend RDMA device registration to be net namespace aware (Mark Bloch) [Orabug: 39203117]
- netlink: specs: ethtool: replace underscores with dashes in names (Jakub Kicinski) [Orabug: 39203117]
- net/mlx5: Add IFC bits for PCIe Congestion Event object (Dragos Tatulea) [Orabug: 39203117]
- net/mlx5: Small refactor for general object capabilities (Dragos Tatulea) [Orabug: 39203117]
- RDMA/mlx5: Add multiple priorities support to RDMA TRANSPORT userspace tables (Patrisious Haddad) [Orabug: 39203117]
- net/mlx5: fs, add multiple prios to RDMA TRANSPORT steering domain (Patrisious Haddad) [Orabug: 39203117]
- RDMA/mlx5: Support driver APIs pre_destroy_cq and post_destroy_cq (Mark Zhang) [Orabug: 39203117]
- RDMA/core: Add driver APIs pre_destroy_cq() and post_destroy_cq() (Mark Zhang) [Orabug: 39203117]
- mmc: sdhci-of-dwcmshc: Drop the use of sdhci_pltfm_free() (Binbin Zhou) [Orabug: 39203117]
- selftests: drv-net: import things in lib one by one (Jakub Kicinski) [Orabug: 39203117]
- netdevsim: fix UaF when counting Tx stats (Jakub Kicinski) [Orabug: 39203117]
- eth: mlx5: migrate to new RXFH callbacks (Jakub Kicinski) [Orabug: 39203117]
- netdevsim: account dropped packet length in stats on queue free (Breno Leitao) [Orabug: 39203117]
- net: add dev_dstats_rx_dropped_add() helper (Breno Leitao) [Orabug: 39203117]
- netdevsim: collect statistics at RX side (Breno Leitao) [Orabug: 39203117]
- netdevsim: migrate to dstats stats collection (Breno Leitao) [Orabug: 39203117]
- net/mlx4_en: Remove the redundant NULL check for the 'my_ets' object (Andrey Vatoropin) [Orabug: 39203117]
- netdevsim: remove udp_ports_sleep (Stanislav Fomichev) [Orabug: 39203117]
- net/mlx4e: Don't redefine IB_MTU_XXX enum (Mark Zhang) [Orabug: 39203117]
- pinctrl: Constify static 'pinctrl_desc' (Krzysztof Kozlowski) [Orabug: 39203117]
- pinctrl: Constify pointers to 'pinctrl_desc' (Krzysztof Kozlowski) [Orabug: 39203117]
- pinctrl: amd: Constify pointers to 'pinctrl_desc' (Krzysztof Kozlowski) [Orabug: 39203117]
- net/mlx5e: Add TX support for netmems (Dragos Tatulea) [Orabug: 39203117]
- net/mlx5e: Support ethtool tcp-data-split settings (Saeed Mahameed) [Orabug: 39203117]
- net/mlx5e: Implement queue mgmt ops and single channel swap (Saeed Mahameed) [Orabug: 39203117]
- net/mlx5e: Add support for UNREADABLE netmem page pools (Saeed Mahameed) [Orabug: 39203117]
- net/mlx5e: Convert over to netmem (Saeed Mahameed) [Orabug: 39203117]
- net/mlx5e: SHAMPO: Separate pool for headers (Saeed Mahameed) [Orabug: 39203117]
- net/mlx5e: SHAMPO: Improve hw gro capability checking (Saeed Mahameed) [Orabug: 39203117]
- net/mlx5e: SHAMPO: Remove redundant params (Saeed Mahameed) [Orabug: 39203117]
- net/mlx5e: SHAMPO: Reorganize mlx5_rq_shampo_alloc (Saeed Mahameed) [Orabug: 39203117]
- page_pool: Add page_pool_dev_alloc_netmems helper (Dragos Tatulea) [Orabug: 39203117]
- net: Add skb_can_coalesce for netmem (Dragos Tatulea) [Orabug: 39203117]
- net: Allow const args for of page_to_netmem() (Dragos Tatulea) [Orabug: 39203117]
- selftests: forwarding: Add a test for verifying VXLAN MC underlay (Petr Machata) [Orabug: 39203117]
- netmem: fix netmem comments (Mina Almasry) [Orabug: 39203117]
- selftests: net: add netconsole test for cmdline configuration (Breno Leitao) [Orabug: 39203117]
- net: ethtool: add dedicated callbacks for getting and setting rxfh fields (Jakub Kicinski) [Orabug: 39203117]
- net: ethtool: require drivers to opt into the per-RSS ctx RXFH (Jakub Kicinski) [Orabug: 39203117]
- net: ethtool: remove the duplicated handling from rxfh and rxnfc (Jakub Kicinski) [Orabug: 39203117]
- net: ethtool: copy the rxfh flow handling (Jakub Kicinski) [Orabug: 39203117]
- net: ethtool: Don't check if RSS context exists in case of context 0 (Gal Pressman) [Orabug: 39203117]
- net/mlx5: Expose serial numbers in devlink info (Jiri Pirko) [Orabug: 39203117]
- selftests: netconsole: Add support for basic netconsole target format (Breno Leitao) [Orabug: 39203117]
- selftests: netconsole: Do not exit from inside the validation function (Breno Leitao) [Orabug: 39203117]
- page_pool: fix ugly page_pool formatting (Mina Almasry) [Orabug: 39203117]
- net/mlx5e: Convert mlx5 netdevs to instance locking (Cosmin Ratiu) [Orabug: 39203117]
- net: Add support for providing the PTP hardware source in tsinfo (Kory Maincent) [Orabug: 39203117]
- selftests: drv-net: Fix "envirnoments" to "environments" (Sumanth Gavini) [Orabug: 39203117]
- net: enable driver support for netmem TX (Mina Almasry) [Orabug: 39203117]
- net: add get_netmem/put_netmem support (Mina Almasry) [Orabug: 39203117]
- netmem: add niov->type attribute to distinguish different net_iov types (Mina Almasry) [Orabug: 39203117]
- selftests: drv-net: ping: make sure the ping test restores checksum offload (Jakub Kicinski) [Orabug: 39203117]
- ethtool: Block setting of symmetric RSS when non-symmetric rx-flow-hash is requested (Gal Pressman) [Orabug: 39203117]
- pinctrl: mediatek: airoha: use new GPIO line value setter callbacks (Bartosz Golaszewski) [Orabug: 39203117]
- selftests: net-drv: remove the nic_performance and nic_link_layer tests (Jakub Kicinski) [Orabug: 39203117]
- devlink: define enum for attr types of dynamic attributes (Jiri Pirko) [Orabug: 39203117]
- selftests: net: exit cleanly on SIGTERM / timeout (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv: net: add version indicator (Mohsin Bashir) [Orabug: 39203117]
- selftests: drv: net: avoid skipping tests (Mohsin Bashir) [Orabug: 39203117]
- selftests: drv: net: fix test failure on ipv6 sys (Mohsin Bashir) [Orabug: 39203117]
- selftests: drv-net: rss_input_xfrm: Check test prerequisites before running (Gal Pressman) [Orabug: 39203117]
- selftests: net: add a virtio_net deadlock selftest (Bui Quang Minh) [Orabug: 39203117]
- selftests: net: move xdp_helper to net/lib (Bui Quang Minh) [Orabug: 39203117]
- selftests: drv-net: Test that NAPI ID is non-zero (Joe Damato) [Orabug: 39203117]
- pinctrl: airoha: fix wrong PHY LED mapping and PHY2 LED defines (Christian Marangi) [Orabug: 39203117]
- netlink: specs: rename rtnetlink specs in accordance with family name (Jakub Kicinski) [Orabug: 39203117]
- pinctrl: amd: Add an LPS0 check() callback (Mario Limonciello) [Orabug: 39203117]
- selftests: drv-net: test random value for hds-thresh (Taehee Yoo) [Orabug: 39203117]
- selftests: net: use Path helpers in ping (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: replace the rpath helper with Path objects (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: use defer in the ping test (Jakub Kicinski) [Orabug: 39203117]
- net: skbuff: Remove unused skb_add_data() (Yue Haibing) [Orabug: 39203117]
- selftests: drv-net: fix merge conflicts resolution (Matthieu Baerts) [Orabug: 39203117]
- selftests: drv-net: add xdp cases for ping.py (Taehee Yoo) [Orabug: 39203117]
- selftests: drv-net: use env.rpath in the HDS test (Jakub Kicinski) [Orabug: 39203117]
- selftests: net: report output format as TAP 13 in Python tests (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: add tests for napi IRQ affinity notifiers (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net-hw: Add a test for symmetric RSS hash (Gal Pressman) [Orabug: 39203117]
- selftests: drv-net: Make rand_port() get a port more reliably (Gal Pressman) [Orabug: 39203117]
- selftests: drv-net: test XDP, HDS auto and the ioctl path (Jakub Kicinski) [Orabug: 39203117]
- net: ethtool: fix ioctl confusing drivers about desired HDS user config (Jakub Kicinski) [Orabug: 39203117]
- netlink: specs: Add FIB rule DSCP mask attribute (Ido Schimmel) [Orabug: 39203117]
- selftests: net: Add python context manager for netns entering (Xiao Liang) [Orabug: 39203117]
- selftests: drv-net: rename queues check_xdp to check_xsk (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: improve the use of ksft helpers in XSK queue test (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: add a way to wait for a local process (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: probe for AF_XDP sockets more explicitly (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: add missing new line in xdp_helper (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: use cfg.rpath() in netlink xsk attr test (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: add a warning for bkg + shell + terminate (Jakub Kicinski) [Orabug: 39203117]
- net: ngbe: Add support for 1PPS and TOD (Jiawen Wu) [Orabug: 39203117]
- net: wangxun: Add periodic checks for overflow and errors (Jiawen Wu) [Orabug: 39203117]
- net: wangxun: Add support for PTP clock (Jiawen Wu) [Orabug: 39203117]
- selftests: drv-net: add a simple TSO test (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: store addresses in dict indexed by ipver (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: get detailed interface info (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: resolve remote interface name (Jakub Kicinski) [Orabug: 39203117]
- netlink: specs: Add FIB rule port mask attributes (Ido Schimmel) [Orabug: 39203117]
- net: move stale comment about ntuple validation (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: Test queue xsk attribute (Joe Damato) [Orabug: 39203117]
- io_uring/zcrx: add selftest (David Wei) [Orabug: 39203117]
- selftests/net: Add selftest for IPv4 RTM_GETMULTICAST support (Yuyang Huang) [Orabug: 39203117]
- selftests: drv-net: add helper for path resolution (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: factor out a DrvEnv base class (Jakub Kicinski) [Orabug: 39203117]
- net: ethtool: prevent flow steering to RSS contexts which don't exist (Jakub Kicinski) [Orabug: 39203117]
- netconsole: selftest: test for sysdata CPU (Breno Leitao) [Orabug: 39203117]
- netconsole: selftest: Add test for fragmented messages (Breno Leitao) [Orabug: 39203117]
- net: provide pending ring configuration in net_device (Jakub Kicinski) [Orabug: 39203117]
- net: ethtool: store netdev in a temp variable in ethnl_default_set_doit() (Jakub Kicinski) [Orabug: 39203117]
- net: move HDS config from ethtool state (Jakub Kicinski) [Orabug: 39203117]
- selftest: net-drv: hds: add test for HDS feature (Taehee Yoo) [Orabug: 39203117]
- netdevsim: add HDS feature (Taehee Yoo) [Orabug: 39203117]
- bnxt_en: add support for hds-thresh ethtool command (Taehee Yoo) [Orabug: 39203117]
- bnxt_en: add support for tcp-data-split ethtool command (Taehee Yoo) [Orabug: 39203117]
- bnxt_en: add support for rx-copybreak ethtool command (Taehee Yoo) [Orabug: 39203117]
- net: ethtool: add ring parameter filtering (Taehee Yoo) [Orabug: 39203117]
- net: devmem: add ring parameter filtering (Taehee Yoo) [Orabug: 39203117]
- net: ethtool: add support for configuring hds-thresh (Taehee Yoo) [Orabug: 39203117]
- netconsole: selftest: verify userdata entry limit (Breno Leitao) [Orabug: 39203117]
- netconsole: selftest: Split the helpers from the selftest (Breno Leitao) [Orabug: 39203117]
- tools: ynl: move python code to separate sub-directory (Jan Stancek) [Orabug: 39203117]
- netdevsim: add debugfs-triggered queue reset (Jakub Kicinski) [Orabug: 39203117]
- netdev: define NETDEV_INTERNAL (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: test drivers sleeping in ndo_get_stats64 (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: assume stats refresh is 0 if no ethtool -c support (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: test empty queue and NAPI responses in netlink (Jakub Kicinski) [Orabug: 39203117]
- page_pool: add page_pool_dev_alloc_netmem() (Alexander Lobakin) [Orabug: 39203117]
- net: Document netmem driver support (Mina Almasry) [Orabug: 39203117]
- netlink: specs: Add FIB rule flow label attributes (Ido Schimmel) [Orabug: 39203117]
- selftests: net-drv: stats: sanity check netlink dumps (Jakub Kicinski) [Orabug: 39203117]
- selftests: net-drv: queues: sanity check netlink dumps (Jakub Kicinski) [Orabug: 39203117]
- selftests: net: support setting recv_size in YNL (Jakub Kicinski) [Orabug: 39203117]
- net: ethtool: Add support for tsconfig command to get/set hwtstamp config (Kory Maincent) [Orabug: 39203117]
- net: ethtool: tsinfo: Enhance tsinfo to support several hwtstamp by net topology (Kory Maincent) [Orabug: 39203117]
- net: Add the possibility to support a selected hwtstamp in netdevice (Kory Maincent) [Orabug: 39203117]
- net: Make net_hwtstamp_validate accessible (Kory Maincent) [Orabug: 39203117]
- net: Make dev_get_hwtstamp_phylib accessible (Kory Maincent) [Orabug: 39203117]
- page_pool: allow mixing PPs within one bulk (Alexander Lobakin) [Orabug: 39203117]
- vrf: Make pcpu_dstats update functions available to other modules. (Guillaume Nault) [Orabug: 39203117]
- page_pool: make page_pool_put_page_bulk() handle array of netmems (Alexander Lobakin) [Orabug: 39203117]
- netmem: add a couple of page helper wrappers (Alexander Lobakin) [Orabug: 39203117]
- xsk: allow attaching XSk pool via xdp_rxq_info_reg_mem_model() (Alexander Lobakin) [Orabug: 39203117]
- xdp, xsk: constify read-only arguments of some static inline helpers (Alexander Lobakin) [Orabug: 39203117]
- ethtool: regenerate uapi header from the spec (Stanislav Fomichev) [Orabug: 39203117]
- ethtool: remove the comments that are not gonna be generated (Stanislav Fomichev) [Orabug: 39203117]
- ethtool: separate definitions that are gonna be generated (Stanislav Fomichev) [Orabug: 39203117]
- ynl: add missing pieces to ethtool spec to better match uapi header (Stanislav Fomichev) [Orabug: 39203117]
- selftests: fix nested double quotes in f-string (David Wei) [Orabug: 39203117]
- selftests: nic_performance: Add selftest for performance of NIC driver (Mohan Prasad J) [Orabug: 39203117]
- selftests: nic_link_layer: Add selftest case for speed and duplex states (Mohan Prasad J) [Orabug: 39203117]
- selftests: nic_link_layer: Add link layer selftest for NIC driver (Mohan Prasad J) [Orabug: 39203117]
- pinctrl: airoha: Use unsigned long for bit search (Kees Cook) [Orabug: 39203117]
- net: netconsole: selftests: Check if netdevsim is available (Breno Leitao) [Orabug: 39203117]
- docs: networking: Describe irq suspension (Joe Damato) [Orabug: 39203117]
- selftests: ncdevmem: Add automated test (Stanislav Fomichev) [Orabug: 39203117]
- selftests: ncdevmem: Move ncdevmem under drivers/net/hw (Stanislav Fomichev) [Orabug: 39203117]
- selftests: ncdevmem: Use YNL to enable TCP header split (Stanislav Fomichev) [Orabug: 39203117]
- selftests: ncdevmem: Properly reset flow steering (Stanislav Fomichev) [Orabug: 39203117]
- selftests: ncdevmem: Remove default arguments (Stanislav Fomichev) [Orabug: 39203117]
- netlink: specs: Add a spec for FIB rule management (Donald Hunter) [Orabug: 39203117]
- netlink: specs: Add a spec for neighbor tables in rtnetlink (Donald Hunter) [Orabug: 39203117]
- net: netconsole: selftests: Add userdata validation (Breno Leitao) [Orabug: 39203117]
- net: netconsole: selftests: Change the IP subnet (Breno Leitao) [Orabug: 39203117]
- pinctrl: airoha: Add support for EN7581 SoC (Lorenzo Bianconi) [Orabug: 39203117]
- Documentation: networking: Add missing PHY_GET command in the message list (Kory Maincent) [Orabug: 39203117]
- netlink: specs: Add missing phy-ntf command to ethtool spec (Kory Maincent) [Orabug: 39203117]
- selftests: net: lib: Introduce deferred commands (Petr Machata) [Orabug: 39203117]
- ethtool: rss: prevent rss ctx deletion when in use (Daniel Zahka) [Orabug: 39203117]
- selftests: net: move EXTRA_CLEAN of libynl.a into ynl.mk (Jakub Kicinski) [Orabug: 39203117]
- selftests: net: rebuild YNL if dependencies changed (Jakub Kicinski) [Orabug: 39203117]
- selftests: drv-net: add missing trailing backslash (Jakub Kicinski) [Orabug: 39203117]
- pinctrl: amd: Fix two small typos (Marc Ferland) [Orabug: 39203117]
- pinctrl: Switch back to struct platform_driver::remove() (Uwe Kleine-König) [Orabug: 39203117]
- pinctrl: qcom: add the tlmm driver for QCS615 platform (Lijuan Gao) [Orabug: 39203117]
- net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (Dongli Zhang) [Orabug: 39558732,39919263] {CVE-2026-74684}
- uek-rpm: enable Nexthop SONiC drivers for ONOS (Vijay Kumar) [Orabug: 39597630]
- platform: nexthop-sonic: add SONiC platform drivers (Vijay Kumar) [Orabug: 39597630]
- uek-rpm/modules.yaml.S.onos: Package PDDF platform drivers (Darren Kenny) [Orabug: 39597630]
- uek-rpm/config-x86_64-onos: Enable PDDF platform driver configs (Vijay Kumar) [Orabug: 39597630]
- platform: Port SONiC PDDF drivers (Test Com) [Orabug: 39597630]
- rds: tcp: fix uninit-value in __inet_bind (Tabrez Ahmed) [Orabug: 39668598]
- rds: tcp: cleanup if kmem_cache_alloc fails in rds_tcp_conn_alloc() (Sowmini Varadhan) [Orabug: 39668598]
- eeprom: optoe: set clientdata before publishing sysfs files (Vijay Kumar) [Orabug: 39721366]
- eeprom: optoe: remove eeprom bin file on sysfs_create_group failure (Vijay Kumar) [Orabug: 39721366]
- eeprom: optoe: fix heap OOB write from stale writebuf sizing (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: raven-fan-driver: read fan ID pins at correct offsets (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: check parse result in scd_set_debug (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: restrict /proc/scd to root-only read (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: fan-cpld: don't hold cpld->lock across work cancel on remove (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: minke-fan-cpld: fix uninitialised cpld deref in probe error path (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: tmp468: fix out-of-bounds read of names[] in probe (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd-mdio: fix mdiobus_free(NULL) and mii_bus leak on error (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: enforce register offset bound instead of advisory ASSERT (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: overflow-safe range check in scd_lpc_mmap_resource (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: rook-fan-cpld: only unregister LEDs that were registered (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: minke-fan-cpld: unregister slot_count LEDs, not fan_count (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: fix SPI controller devdata UAF and invalid kfree (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: don't panic on over-long xcvr attribute name (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: remove partial xcvr sysfs attrs before freeing on error (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: init master->list before the master-add error path (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: use strscpy for LED name to guarantee NUL termination (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: bound fan_count against speed_*_steps[] arrays (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: bound derived MMIO offsets in master/port add paths (Vijay Kumar) [Orabug: 39721366]
- arista-sonic: scd: fix user-controlled format string in gpio/reset add (Vijay Kumar) [Orabug: 39721366]
- src: handle ioremap error in raven-fan-driver (Arista-Hpandya) [Orabug: 39721366]
- Replace sprintf with sysfs_emit in sysfs show callbacks (Arista-Hpandya) [Orabug: 39721366]
- scd: add sysfs knob to control watchdog panic (Mohan Yelugoti) [Orabug: 39721366]
- scd: update scd driver to EOS latest (Mohan Yelugoti) [Orabug: 39721366]
- platform: remove old tricolor LED handling (Justin Oliver) [Orabug: 39721366]
- scd: add bus_speed attribute to i2c buses (Samuel Angebault) [Orabug: 39721366]
- Modify arista-drivers for arm64 compilation. (Vivek Kumar Verma) [Orabug: 39721366]
- minke-fan-cpld: seperate slot and fan initialization in cpld_init (Arista-Hpandya) [Orabug: 39721366]
- x86/bugs: Make Safe-RET robust against interrupt injection (Borislav Petkov) [Orabug: 39784619,39853774] {CVE-2026-68480}
- net/rds: harden rds_rm_size (Manjunath Patil) [Orabug: 39812332]
- KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Sean Christopherson) [Orabug: 39830589,39832725,39832878,39844799] {CVE-2026-64561}
- net/rds: remove cached rds_sock->rs_conn and rs_conn_path (Sharath Srinivasan) [Orabug: 39832353]
- Revert "rds: cong: Make rds_cong_wait an array to reduce lock contention" (Sharath Srinivasan) [Orabug: 39832353]

[6.12.0-206.100.2]
- afs: Fix lack of locking around modifications of net->cells_dyn_ino (David Howells) [Orabug: 39885900] {CVE-2026-72372}
- afs: Fix dynamic lookup to fail on cell lookup failure (David Howells)
- afs: Simplify cell record handling (David Howells)
- afs: Fix afs_server ref accounting (David Howells)
- afs: Use the per-peer app data provided by rxrpc (David Howells)
- rxrpc: Allow the app to store private data on peer structs (David Howells)
- afs: Drop the net parameter from afs_unuse_cell() (David Howells)
- afs: Make afs_lookup_cell() take a trace note (David Howells)
- afs: Improve server refcount/active count tracing (David Howells)
- Bluetooth: hci_core: Fix not accounting for BIS/CIS/PA links separately (Luiz Augusto von Dentz)
- Bluetooth: Add PA_LINK to distinguish BIG sync and PA sync connections (Yang Li)
- net: qrtr: ns: Raise node count limit to 512 (Youssef Samir)
- drm/amd/pm: fix smu13 power limit range calculation (Yang Wang)
- ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL (Guan Wentao)
- ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl (Haofeng Li)
- vsock/virtio: collapse receive queue under memory pressure (Stefano Garzarella)
- proc: Fix broken error paths for namespace links (Jann Horn)
- serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (Jiangshan Yi) [Orabug: 39868564] {CVE-2026-68434}
- drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) (Timur Kristóf)
- Revert "drm/amd/display: Add missing kdoc for ALLM parameters" (Sasha Levin)
- usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect (Diego Fernando Mancera Gomez) [Orabug: 39860411] {CVE-2026-68344}
- net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets() (Lorenzo Bianconi)
- udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf() (Robert Mader)
- wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (Peddolla Harshavardhan Reddy) [Orabug: 39860409] {CVE-2026-68408}
- wifi: cfg80211: define and use wiphy guard (Johannes Berg)
- wifi: cfg80211: pass net_device to .set_monitor_channel (Felix Fietkau)
- firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits (Seth Forshee)
- Revert "arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc" (Sasha Levin)
- net: airoha: Fix skb->priority underflow in airoha_dev_select_queue() (Wayen Yan)
- LTS version: v6.12.100 (Sherry Yang)
- posix-cpu-timers: Prevent UAF caused by non-leader exec() race (Thomas Gleixner) [Orabug: 39807437] {CVE-2026-64560}
- LTS version: v6.12.99 (Sherry Yang)
- mm: refactor mm_access() to not return NULL (Lorenzo Stoakes)
- LTS version: v6.12.98 (Sherry Yang)
- ext4: fix fd leak in EXT4_IOC_MOVE_EXT cross-sb validation (Yun Zhou)
- LTS version: v6.12.97 (Sherry Yang)
- selftests/bpf: Add simple strscpy() implementation (Ihor Solodrai)
- tools/testing: add linux/args.h header and fix radix, VMA tests (Lorenzo Stoakes)
- dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() (Ivan Vecera) [Orabug: 39860212] {CVE-2026-68378}
- Bluetooth: L2CAP: fix tx ident leak for commands without a response (Stig Hornang) [Orabug: 39887241] {CVE-2026-72333}
- Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev (Luiz Augusto von Dentz)
- Bluetooth: L2CAP: Fix regressions caused by reusing ident (Luiz Augusto von Dentz)
- crypto: ccp - Fix leaking the same page twice (Guenter Roeck)
- ice: drop udp_tunnel_get_rx_info() call from ndo_open() (Mohammad Heib)
- i40e: drop udp_tunnel_get_rx_info() call from i40e_open() (Mohammad Heib)
- crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked() (Borislav Petkov) [Orabug: 39838809] {CVE-2025-39936}
- Bluetooth: hci_sync: Fix attempting to send HCI_Disconnect to BIS handle (Luiz Augusto von Dentz)
- Bluetooth: hci_core: Remove check of BDADDR_ANY in hci_conn_hash_lookup_big_state (Luiz Augusto von Dentz)
- udp_tunnel: fix deadlock in udp_tunnel_nic_set_port_priv() (Paolo Abeni)
- crypto: ccp - Fix SNP panic notifier unregistration (Ashish Kalra)
- crypto: ccp - Fix dereferencing uninitialized error pointer (Ashish Kalra) [Orabug: 39838818] {CVE-2025-39729}
- crypto: ccp - Fix __sev_snp_shutdown_locked (Ashish Kalra)
- afs: Fix afs_dynroot_readdir() to not use the RCU read lock (David Howells)
- afs: Fix afs_atcell_get_link() to check if ws_cell is unset first (David Howells)
- net: airoha: Fix channel configuration for ETS Qdisc (Lorenzo Bianconi)
- rtnetlink: Make per-netns RTNL dereference helpers to macro. (Kuniyuki Iwashima)
- ksmbd: fix durable reconnect double-bind race in ksmbd_reopen_durable_fd (Gil Portnoy)
- seqlock: fix scoped_seqlock_read kernel-doc (Randy Dunlap)
- dibs: loopback: validate offset and size in move_data() (Dust Li)
- perf/x86/amd/brs: Fix kernel address leakage (Sandipan Das) [Orabug: 39885534] {CVE-2026-72237}
- bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (Matt Bobrowski) [Orabug: 39760895] {CVE-2026-64192}
- KVM: arm64: Fix propagation of TLBI level in kvm_pgtable_stage2_relax_perms() (Marc Zyngier)
- KVM: arm64: Ensure level is always initialized when relaxing perms (Oliver Upton)
- KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers (Marc Zyngier) [Orabug: 39885665] {CVE-2026-72282}
- mm/damon/core: always put unsuccessfully committed target pids (Seongjae Park) [Orabug: 39885319] {CVE-2026-72178}
- selftests/fs/statmount: build with tools include dir (Amir Goldstein)
- fscrypt: Replace mk_users keyring with simple list (Eric Biggers)
- fscrypt: Fix key setup in edge case with multiple data unit sizes (Eric Biggers)
- slab: recognize @GFP parameter as optional in kernel-doc (Randy Dunlap)
- default_gfp(): avoid using the "newfangled" __VA_OPT__ trick (Linus Torvalds)
- add default_gfp() helper macro and use it in the new *alloc_obj() helpers (Linus Torvalds)
- slab: Introduce kmalloc_flex() and family (Kees Cook)
- slab: Introduce kmalloc_obj() and family (Kees Cook)
- btrfs: fix incorrect buffered IO fallback for append direct writes (Qu Wenruo)
- btrfs: fix false IO failure after falling back to buffered write (Qu Wenruo)
- exfat: preserve benign secondary entries during rename and move (Rochan Avlur)
- exfat: fix incorrect directory checksum after rename to shorter name (Chi Zhiling)
- exfat: move exfat_chain_set() out of __exfat_resolve_path() (Yuezhang Mo)
- exfat: add exfat_get_dentry_set_by_ei() helper (Yuezhang Mo)
- exfat: rename argument name for exfat_move_file and exfat_rename_file (Yuezhang Mo)
- exfat: remove unnecessary read entry in __exfat_rename() (Yuezhang Mo)
- crypto: qat - fix restarting state leak on allocation failure (Ahsan Atta)
- crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG) (Tycho Andersen) [Orabug: 39785896] {CVE-2026-64307}
- crypto: ccp - Fix a case where SNP_SHUTDOWN is missed (Tom Lendacky)
- crypto: ccp - Move SEV/SNP Platform initialization to KVM (Ashish Kalra)
- crypto: ccp - Register SNP panic notifier only if SNP is enabled (Ashish Kalra)
- crypto: ccp - Reset TMR size at SNP Shutdown (Ashish Kalra)
- crypto: ccp - Move dev_info/err messages for SEV/SNP init and shutdown (Ashish Kalra)
- btrfs: check and set EXTENT_DELALLOC_NEW before clearing EXTENT_DELALLOC (Qu Wenruo)
- btrfs: remove the COW fixup mechanism (Qu Wenruo)
- btrfs: remove folio parameter from ordered io related functions (Qu Wenruo)
- btrfs: replace for_each_set_bit() with for_each_set_bitmap() (Qu Wenruo)
- btrfs: concentrate the error handling of submit_one_sector() (Qu Wenruo)
- usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile (Neill Kapron)
- crypto: atmel-sha204a - fail on hwrng registration error in probe path (Thorsten Blum)
- usb: gadget: f_fs: initialize reset_work at allocation time (Tyler Baker)
- crypto: atmel-sha204a - drop hwrng quality reduction for ATSHA204A (Thorsten Blum)
- crypto: atmel - Drop explicit initialization of struct i2c_device_id::driver_data to 0 (Uwe Kleine-König)
- usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect() (Mauricio Faria de Oliveira) [Orabug: 39884643] {CVE-2026-68456}
- USB: iowarrior: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39786002] {CVE-2026-64341}
- usb: iowarrior: remove inherent race with minor number (Oliver Neukum)
- bpf: Allow LPM map access from sleepable BPF programs (Vlad Poenaru) [Orabug: 39786045] {CVE-2026-64352}
- bpf: Consistently use bpf_rcu_lock_held() everywhere (Andrii Nakryiko)
- bpf, arm64, powerpc: Add bpf_jit_bypass_spec_v1/v4() (Luis Gerhorst)
- bpf: Convert lpm_trie.c to rqspinlock (Kumar Kartikeya Dwivedi)
- hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length (Tristan Madani)
- hfs/hfsplus: prevent getting negative values of offset/length (Viacheslav Dubeyko)
- HID: pidff: Use correct effect type in effect update (Oleg Makarenko)
- HID: pidff: Rework pidff_upload_effect (Tomasz Pakuła)
- HID: pidff: Add missing spaces (Tomasz Pakuła)
- HID: pidff: Fix missing blank lines after declarations (Tomasz Pakuła)
- HID: appleir: fix UAF on pending key_up_timer in remove() (Manish Khadka) [Orabug: 39786073] {CVE-2026-64363}
- treewide: Switch/rename to timer_delete[_sync]() (Thomas Gleixner)
- proc: protect ptrace_may_access() with exec_update_lock (part 1) (Jann Horn) [Orabug: 39786094] {CVE-2026-64371}
- seqlock: Change do_task_stat() to use scoped_seqlock_read() (Oleg Nesterov)
- seqlock: Introduce scoped_seqlock_read() (Peter Zijlstra)
- HID: multitouch: fix out-of-bounds bit access on mt_io_flags (Trung Nguyen) [Orabug: 39786077] {CVE-2026-64364}
- HID: add haptics page defines (Angela Czubak)
- perf/x86/intel/uncore: Defer ADL global PMON enable to enable_box() (Zide Chen)
- proc: protect ptrace_may_access() with exec_update_lock (FD links) (Jann Horn) [Orabug: 39786111] {CVE-2026-64375}
- proc: rename proc_setattr to proc_nochmod_setattr (Christoph Hellwig)
- ksmbd: track the connection owning a byte-range lock (Namjae Jeon)
- ksmbd: centralize ksmbd_conn final release to plug transport leak (Daemyung Kang)
- ksmbd: use opener credentials for FSCTL mutations (Namjae Jeon) [Orabug: 39884648] {CVE-2026-68457}
- ksmbd: fix path resolution in ksmbd_vfs_kern_path_create (Davide Ornaghi)
- vfs: make LAST_XXX private to fs/namei.c (Jori Koolstra)
- ksmbd_vfs_rename(): vfs_path_parent_lookup() accepts ERR_PTR() as name (Al Viro)
- smb: client: resolve SWN tcon from live registrations (Michael Bommarito) [Orabug: 39786199] {CVE-2026-64401}
- smb: client: Improve unlocking of a mutex in cifs_get_swn_reg() (Markus Elfring)
- mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host (Jose Fernandez) [Orabug: 39786239] {CVE-2026-64416}
- Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() (Siwei Zhang) [Orabug: 39802881] {CVE-2026-64557}
- Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister (Pauli Virtanen)
- Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn() (Siwei Zhang) [Orabug: 39786211] {CVE-2026-64405}
- Bluetooth: separate CIS_LINK and BIS_LINK link types (Pauli Virtanen)
- Bluetooth: hci_core: Enable buffer flow control for SCO/eSCO (Luiz Augusto von Dentz)
- Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock (Runyu Xiao) [Orabug: 39760900] {CVE-2026-64206}
- Bluetooth: L2CAP: Fix not tracking outstanding TX ident (Luiz Augusto von Dentz)
- netfilter: ebtables: zero chainstack array (Florian Westphal) [Orabug: 39786231] {CVE-2026-64413}
- netfilter: ebtables: Use vmalloc_array() to improve code (Rong Qianfeng)
- media: nxp: imx8-isi: Fix use-after-free on remove (Xiaolei Wang)
- media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code (Frank Li)
- io_uring/rw: preserve partial result for iopoll (Michael Wigham)
- io_uring/rw: ensure reissue path is correctly handled for IOPOLL (Jens Axboe)
- gpio: sch: use raw_spinlock_t in the irq startup path (Runyu Xiao)
- Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (Marco Elver) [Orabug: 39838967] {CVE-2026-64434}
- crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() (Giovanni Cabiddu) [Orabug: 39786297] {CVE-2026-64438}
- staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() (Alexandru Hossu)
- staging: rtl8723bs: fix spaces around binary operators (Nikolay Kulikov)
- staging: rtl8723bs: core: move constants to right side in comparison (William Hansen-Baird)
- PCI: Skip Resizable BAR restore on read error (Marco Nenciarini)
- PCI: Move Resizable BAR code to rebar.c (Ilpo Järvinen)
- PCI: Fix restoring BARs on BAR resize rollback path (Ilpo Järvinen)
- PCI: Free saved list without holding pci_bus_sem (Ilpo Järvinen)
- PCI: Prevent resource tree corruption when BAR resize fails (Ilpo Järvinen)
- PCI: Use pbus_select_window() during BAR resize (Ilpo Järvinen)
- PCI: mediatek: Fix IRQ domain leak when port fails to enable (Manivannan Sadhasivam) [Orabug: 39786365] {CVE-2026-64461}
- PCI: mediatek: Use generic MACRO for TPVPERL delay (Christian Marangi)
- PCI: mediatek: Convert bool to single quirks entry and bitmap (Christian Marangi)
- PCI: mediatek: Switch to msi_create_parent_irq_domain() (Nam Cao)
- PCI: controller: Use dev_fwnode() instead of of_fwnode_handle() (Jiri Slaby)
- PCI: altera: Fix resource leaks on probe failure (Mahesh Vaidya)
- vfio/mlx5: Fix racy bitfields and tighten struct layout (Alex Williamson) [Orabug: 39786400] {CVE-2026-64472}
- ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417 (Geoffrey D. Bennett)
- ALSA: scarlett2: Allow selecting config_set by firmware version (Geoffrey D. Bennett)
- ALSA: hda/cs35l41: Fix firmware load work teardown (Cássio Gabriel) [Orabug: 39786423] {CVE-2026-64481}
- ALSA: aoa: check snd_ctl_new1() return value (Zhao Dongdong)
- iio: pressure: mpl115: fix runtime PM leak on read error (Biren Pandya)
- iio: pressure: Remove redundant pm_runtime_mark_last_busy() calls (Sakari Ailus)
- iio: adc: ad7380: select REGMAP (Samuel Moelius)
- iio: hid-sensor-rotation: Fix stale or zero output when reading raw values (Zhang Lixu)
- ACPI: NFIT: core: Fix possible deadlock and missing notifications (Rafael J. Wysocki)
- ACPI: NFIT: core: Use devm_acpi_install_notify_handler() (Rafael J. Wysocki)
- ACPI: bus: Introduce devm_acpi_install_notify_handler() (Rafael J. Wysocki)
- ACPI: driver: Check ACPI_COMPANION() against NULL during probe (Rafael J. Wysocki) [Orabug: 39785136] {CVE-2026-64227}
- ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup (Rafael J. Wysocki) [Orabug: 39786501] {CVE-2026-64510}
- rust: block: fix GenDisk cleanup paths (Haoze Xie)
- mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe() method (Sergey Shtylyov)
- mmc: block: fix RPMB device unregister ordering (Ao Sun)
- mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout (Pengpeng Hou)
- mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout (Pengpeng Hou)
- mtd: rawnand: fsl_ifc: return errors for failed page reads (Pengpeng Hou)
- mmc: vub300: defer reset until cmd_mutex is unlocked (Runyu Xiao) [Orabug: 39973230] {CVE-2026-80659}
- mtd: mchp23k256: use SPI match data for chip caps (Pengpeng Hou)
- mtd: onenand: samsung: report DMA completion timeouts (Pengpeng Hou)
- wifi: mwifiex: fix permanently busy scans after multiple roam iterations (Rafael Beims) [Orabug: 39884680] {CVE-2026-68469}
- wifi: mac80211: free ack status frame on TX header build failure (Zhiling Zou)
- powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access() (Junrui Luo)
- reset: sunxi: fix memory region leak on ioremap failure (Zhao Dongdong) [Orabug: 39884698] {CVE-2026-68475}
- ipvs: reload ip header after head reallocation (Florian Westphal) [Orabug: 39884702] {CVE-2026-68476}
- ipvs: fix more places with wrong ipv6 transport offsets (Julian Anastasov) [Orabug: 39884706] {CVE-2026-68477}
- memstick: ms_block: reject a card that reports too many blocks (Maoyi Xie)
- macsec: fix promiscuity refcount leak in macsec_dev_open() (James Raphael Tiovalen)
- llc: fix SAP refcount leak when creating incoming sockets (Luoxuanqiang)
- Bluetooth: btrtl: validate firmware patch bounds (Laxman Acharya Padhya) [Orabug: 39884715] {CVE-2026-68479}
- net: openvswitch: reject oversized nested action attrs (Asim Viladi Oglu Manizada) [Orabug: 39789563,39816011,39819142] {CVE-2026-64531}
- regulator: ltc3676: Fix incorrect IRQSTAT bit offsets (Abhishek Ojha)
- wifi: mac80211: fix memory leak in ieee80211_register_hw() (Dawei Feng) [Orabug: 39884720] {CVE-2026-72004}
- wifi: mwifiex: fix roaming to different channel in host_mlme mode (Rafael Beims)
- wifi: rt2x00: avoid full teardown before work setup in probe (Runyu Xiao) [Orabug: 39884725] {CVE-2026-72005}
- powerpc/pseries: fix memory leak on krealloc failure in papr_init (Thorsten Blum)
- selftests/landlock: Fix screwed up pointers in the scoped_signal_test (Thomas Huth)
- selftests/landlock: Skip scoped_signal subtest with MSG_OOB if not available (Thomas Huth)
- pmdomain: imx: Fix i.MX8MP VC8000E power up sequence (Peng Fan)
- pmdomain: imx: Fix i.MX8MP power notifier (Peng Fan)
- cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed (Farhad Alemi) [Orabug: 39884738] {CVE-2026-72010}
- s390/mm: Fix type mismatch in get_align_mask(). (Gerald Schaefer)
- tracing/osnoise: Call synchronize_rcu() when unregistering (Crystal Wood) [Orabug: 39884743] {CVE-2026-72012}
- riscv: Prevent NULL pointer dereference in machine_kexec_prepare() (Tao Liu)
- drbd: reject data replies with an out-of-range payload size (Michael Bommarito) [Orabug: 39884748] {CVE-2026-72014}
- ata: libata-core: Skip HPA resize for locked drives (Terrence Adams)
- arm64: smp: Fix hot-unplug tearing by forcing unregistration (Jinjie Ruan)
- macsec: don't read an unset MAC header in macsec_encrypt() (Daehyeon Ko) [Orabug: 39884764] {CVE-2026-72019}
- ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (Yizhou Zhao) [Orabug: 39884768] {CVE-2026-72020}
- ipvs: use parsed transport offset in SCTP state lookup (Yizhou Zhao) [Orabug: 39884772] {CVE-2026-72021}
- llc: fix SAP refcount leak in llc_ui_autobind() (Shuangpeng Bai)
- selftests: net: make busywait timeout clock portable (Nirmoy Das)
- mac802154: remove interfaces with RCU list deletion (Yousef Alhouseen) [Orabug: 39884784] {CVE-2026-72024}
- s390/monwriter: Reject buffer reuse with different data length (Gerald Schaefer)
- irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure (Haoxiang Li)
- mm/compaction: handle free_pages_prepare() properly in compaction_free() (Zi Yan) [Orabug: 39884794] {CVE-2026-72027}
- riscv: probes: save original sp in rethook trampoline (Martin Kaiser)
- hwmon: (asus_atk0110) Check package count before accessing element (Hyeongjun An) [Orabug: 39973027] {CVE-2026-80593}
- net: wwan: iosm: bound device offsets in the MUX downlink decoder (Maoyi Xie) [Orabug: 39884800] {CVE-2026-72029}
- ata: pata_pxa: Fix DMA channel leak on probe error (Xu Wang)
- orangefs: keep the readdir entry size 64-bit in fill_from_part() (Bryam Vargas)
- tracing/probes: Fix double addition of offset for @+FOFFSET (Masami Hiramatsu)
- hwmon: (max1619) add missing 'select REGMAP' to Kconfig (Joshua Crofts)
- fhandle: reject detached mounts in capable_wrt_mount() (David Lee) [Orabug: 39884821] {CVE-2026-72034}
- net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Bryam Vargas) [Orabug: 39884826] {CVE-2026-72035}
- net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Bryam Vargas) [Orabug: 39884830] {CVE-2026-72036}
- net: lan743x: Initialize eth_syslock spinlock before use (Andrea Righi) [Orabug: 39884834] {CVE-2026-72037}
- fsl/fman: Free init resources on KeyGen failure in fman_init() (Haoxiang Li)
- hwmon: (occ) unregister sysfs devices outside occ lock (Runyu Xiao)
- net: liquidio: fix BAR resource leak on PF number failure (Haoxiang Li)
- hwmon: (w83793) remove vrm sysfs file on probe failure (Pengpeng Hou)
- hwmon: (w83627hf) remove VID sysfs files on error and remove (Pengpeng Hou)
- rtc: mpfs: fix counter upload completion condition (Conor Dooley)
- bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp() (Abdun Nihaal) [Orabug: 39884840] {CVE-2026-72039}
- espintcp: use sk_msg_free_partial to fix partial send (Sabrina Dubroca)
- LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect() (Hongchen Zhang)
- batman-adv: clean untagged VLAN on netdev registration failure (Sven Eckelmann) [Orabug: 39885498] {CVE-2026-72229}
- rust: block: allow(deprecated) for fetch_update for Rust >= 1.99.0 (Miguel Ojeda)
- batman-adv: ensure minimal ethernet header on TX (Sven Eckelmann) [Orabug: 39885511] {CVE-2026-72232}
- batman-adv: retrieve ethhdr after potential skb realloc on RX (Sven Eckelmann) [Orabug: 39885524] {CVE-2026-72235}
- s390: Revert support for DCACHE_WORD_ACCESS (Heiko Carstens)
- net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants (Jamal Hadi Salim)
- platform/x86/amd/pmc: Avoid logging "(null)" for DMI values (Daniel Gibson)
- ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit (Shitalkumar Gandhi)
- ieee802154: ca8210: fix cas_ctl leak on spi_async failure (Shitalkumar Gandhi)
- ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation (Michael Bommarito)
- ieee802154: admin-gate legacy LLSEC dump operations (Michael Bommarito) [Orabug: 39884867] {CVE-2026-72049}
- octeontx2-af: Free BPID bitmap on setup failure (Haoxiang Li)
- net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) [Orabug: 39884878] {CVE-2026-72052}
- net: ipip: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) [Orabug: 39884882] {CVE-2026-72053}
- net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) [Orabug: 39884886] {CVE-2026-72054}
- net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) [Orabug: 39884891] {CVE-2026-72055}
- net: ena: clean up XDP TX queues when regular TX setup fails (Dawei Feng) [Orabug: 39884895] {CVE-2026-72056}
- net/sched: act_ct: preserve tc_skb_cb across defragmentation (Zihan Xi) [Orabug: 39884898] {CVE-2026-72057}
- net: ixp4xx_hss: fix duplicate HDLC netdev allocation (Haoxiang Li)
- net: wwan: t7xx: destroy DMA pool on CLDMA late init failure (Haoxiang Li) [Orabug: 39884904] {CVE-2026-72059}
- net: sit: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) [Orabug: 39884910] {CVE-2026-72061}
- gpios: palmas: add .get_direction() op (Andreas Kemnade)
- gpio-f7188x: Add support for NCT6126D version B (Paul Louvel)
- gpio: tegra: do not call pinctrl for GPIO direction (Runyu Xiao) [Orabug: 39884921] {CVE-2026-72063}
- cpu: hotplug: Bound hotplug states sysfs output (Bradley Morgan) [Orabug: 39884933] {CVE-2026-72066}
- cpu: hotplug: Preserve per instance callback errors (Bradley Morgan) [Orabug: 39884939] {CVE-2026-72067}
- selftests/ftrace: Drop invalid top-level local in test_ownership (Cao Ruichuang)
- posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu() (Zhan Xusheng) [Orabug: 39884945] {CVE-2026-72068}
- tracing/user_events: Fix use-after-free in user_event_mm_dup() (Michael Bommarito)
- net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (Doruk Tan Ozturk)
- Input: ims-pcu - fix type confusion in CDC union descriptor parsing (Dmitry Torokhov)
- Input: ims-pcu - fix race condition in reset_device sysfs callback (Dmitry Torokhov)
- Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing (Dmitry Torokhov)
- Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging (Dmitry Torokhov)
- Input: ims-pcu - fix firmware leak in async update (Dmitry Torokhov)
- Input: ims-pcu - fix DMA mapping violation in line setup (Dmitry Torokhov)
- Input: ims-pcu - add response length checks (Dmitry Torokhov)
- Input: ims-pcu - validate control endpoint type (Dmitry Torokhov)
- Input: ims-pcu - release data interface on disconnect (Dmitry Torokhov)
- Input: ims-pcu - only expose sysfs attributes on control interface (Dmitry Torokhov)
- Input: ims-pcu - fix use-after-free and double-free in disconnect (Dmitry Torokhov)
- scsi: elx: efct: Fix I/O leak on unsupported additional CDB (Haoxiang Li)
- scsi: elx: efct: Fix refcount leak in efct_hw_io_abort() (Xu Wang)
- scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (Bryam Vargas) [Orabug: 39885016] {CVE-2026-72083}
- scsi: target: Bound PR-OUT TransportID parsing to the received buffer (Bryam Vargas) [Orabug: 39885021] {CVE-2026-72084}
- scsi: xen: scsiback: Free unsubmitted command instead of double-putting it (Michael Bommarito) [Orabug: 39885027] {CVE-2026-72085}
- scsi: xen: scsiback: Free the command tag on the TMR submit-failure path (Michael Bommarito) [Orabug: 39885032] {CVE-2026-72086}
- scsi: sg: Report request-table problems when any status is set (Xu Rao)
- scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() (Abdun Nihaal) [Orabug: 39885037] {CVE-2026-72087}
- scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path (Haoxiang Li) [Orabug: 39885041] {CVE-2026-72088}
- accel/ivpu: Reject firmware log with size smaller than header (Jhonraushan)
- dm-verity: make error counter atomic (Mikulas Patocka) [Orabug: 39885053] {CVE-2026-72096}
- dm-verity: increase sprintf buffer size (Mikulas Patocka)
- dm-verity: fix a possible NULL pointer dereference (Mikulas Patocka)
- dm-verity: avoid double increment of &use_bh_wq_enabled (Mikulas Patocka)
- dm-integrity: don't increment hash_offset twice (Mikulas Patocka) [Orabug: 39885063] {CVE-2026-72099}
- dm-integrity: fix a bug if the bio is out of limits (Mikulas Patocka) [Orabug: 39885066] {CVE-2026-72100}
- dm_early_create: fix freeing used table on dm_resume failure (Mikulas Patocka) [Orabug: 39885070] {CVE-2026-72102}
- dm-stats: fix merge accounting (Mikulas Patocka)
- dm-stats: fix dm_jiffies_to_msec64 (Mikulas Patocka)
- dm-log: fix a bitset_size overflow on 32bit machines (Benjamin Marzinski) [Orabug: 39887252] {CVE-2026-72105}
- dm-ioctl: fix a possible overflow in list_version_get_info (Mikulas Patocka) [Orabug: 39885078] {CVE-2026-72106}
- dm-bufio: fix wrong count calculation in dm_bufio_issue_discard (Mikulas Patocka)
- dm era: fix out-of-bounds memory access for non-zero start sector (Samuel Moelius) [Orabug: 39885082] {CVE-2026-72107}
- dm thin metadata: fix metadata snapshot consistency on commit failure (Ming-Hung Tsai) [Orabug: 39885086] {CVE-2026-72108}
- dm thin metadata: fix superblock refcount leak on snapshot shadow failure (Genjian Zhang)
- net: sparx5: unregister blocking notifier on init failure (Haoxiang Li)
- block: fix race in blk_time_get_ns() returning 0 (Mike Waychison)
- bpf: Add missing access_ok call to copy_user_syms (Jiri Olsa) [Orabug: 39982245] {CVE-2026-80865}
- bpf,fork: wipe ->bpf_storage before bailouts that access it (Jann Horn) [Orabug: 39885093] {CVE-2026-72110}
- can: bcm: add missing rcu list annotations and operations (Oliver Hartkopp) [Orabug: 39885127] {CVE-2026-72120}
- can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure (Oliver Hartkopp) [Orabug: 39885136] {CVE-2026-72122}
- can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (Lee Jones) [Orabug: 39885140] {CVE-2026-72123}
- can: isotp: use unconditional synchronize_rcu() in isotp_release() (Oliver Hartkopp) [Orabug: 39885150] {CVE-2026-72126}
- can: esd_usb: kill anchored URBs before freeing netdevs (Fan Wu)
- netdev-genl: report NAPI thread PID in the caller's pid namespace (Maoyi Xie) [Orabug: 39885153] {CVE-2026-72127}
- nvmet-rdma: handle inline data with a nonzero offset (Bryam Vargas) [Orabug: 39885156] {CVE-2026-72129}
- NFS: Charge unstable writes by request size, not folio size (Benjamin Coddington) [Orabug: 39885164] {CVE-2026-72132}
- sctp: validate STALE_COOKIE cause length before reading staleness (Weiming Shi) [Orabug: 39794430] {CVE-2026-64551}
- spi: uniphier: Fix completion initialization order before devm_request_irq() (Kunihiko Hayashi)
- time: Fix off-by-one in compat settimeofday() usec validation (Wang Yan)
- tpm: Make the TPM character devices non-seekable (Jaewon Yang) [Orabug: 39885171] {CVE-2026-72135}
- tpm: fix event_size output in tpm1_binary_bios_measurements_show (Thorsten Blum)
- xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) [Orabug: 39885175] {CVE-2026-72136}
- xfrm: use compat translator only for u64 alignment mismatch (Sanman Pradhan)
- xen/gntdev: fix error handling in ioctl (Xu Wang) [Orabug: 39885181] {CVE-2026-72138}
- ice: fix ice_init_link() error return preventing probe (Paul Greenwalt)
- i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() (Luoxuanqiang)
- i2c: mediatek: fix WRRD for SoCs without auto_restart option (Roman Vivchar)
- hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig (Joshua Crofts)
- hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (Joshua Crofts)
- ksmbd: fix integer overflow in set_file_allocation_info() (Ibrahim Hashimov)
- smb: client: use kvzalloc() for megabyte buffer in simple fallocate (Fredric Cover)
- pkey: Move keytype check from pkey api to handler (Holger Dengler)
- platform/x86/amd/pmc: Don't log during intermediate wakeups (Daniel Gibson)
- platform/x86/amd/pmc: Add delay_suspend module parameter (Daniel Gibson)
- platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops (Daniel Gibson)
- platform/x86/amd/pmc: Check for intermediate wakeup in function (Daniel Gibson)
- platform/x86: dell-laptop: fix missing cleanups in init error path (Haoxiang Li) [Orabug: 39885195] {CVE-2026-72144}
- dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (Frank Li)
- dmaengine: tegra: Fix burst size calculation (Kartik)
- tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt (Michael Bommarito) [Orabug: 39885218] {CVE-2026-72151}
- tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (Jarkko Sakkinen) [Orabug: 39885220] {CVE-2026-72152}
- irqchip/crossbar: Use correct index in crossbar_domain_free() (Bhargav Joshi)
- taskstats: retain dead thread stats in TGID queries (Yiyang Chen)
- mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (Florian Fuchs)
- mtd: rawnand: Pause continuous reads at block boundaries (Miquel Raynal)
- mtd: spi-nor: spansion: use die erase for multi-die devices only (Takahiro Kuwano)
- mtd: spi-nor: swp: Improve locking user experience (Miquel Raynal) [Orabug: 39885229] {CVE-2026-72155}
- s390/pkey: Check length in pkey_pckmo handler implementation (Holger Dengler)
- s390/pkey: Check length in PKEY_VERIFYPROTK ioctl (Holger Dengler)
- fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (Sebastian Alba Vives)
- net: thunderbolt: Fix frags[] overflow by bounding frame_count (Maoyi Xie) [Orabug: 39885236] {CVE-2026-72157}
- bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (Manivannan Sadhasivam)
- fpga: dfl: add bounds check in dfh_get_param_size() (Sebastian Alba Vives)
- ocfs2: reject non-inline dinodes with i_size and zero i_clusters (Michael Bommarito) [Orabug: 39885242] {CVE-2026-72159}
- ocfs2: reject dinodes whose i_rdev disagrees with the file type (Michael Bommarito)
- ocfs2: reject dinodes with non-canonical i_mode type (Michael Bommarito) [Orabug: 39885246] {CVE-2026-72160}
- ocfs2: add journal NULL check in ocfs2_checkpoint_inode() (Joseph Qi) [Orabug: 39885250] {CVE-2026-72161}
- ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits (Ian Bridges) [Orabug: 39885257] {CVE-2026-72163}
- ocfs2: avoid moving extents to occupied clusters (Kyle Zeng) [Orabug: 39885260] {CVE-2026-72164}
- mtd: rawnand: fix condition in 'nand_select_target()' (Arseniy Krasnov) [Orabug: 39885267] {CVE-2026-72165}
- net/9p: fix infinite loop in p9_client_rpc on fatal signal (Vasiliy Kovalev) [Orabug: 39885273] {CVE-2026-72166}
- mtd: rawnand: pl353: fix probe resource allocation (Bastien Curutchet)
- ocfs2: use kzalloc for quota recovery bitmap allocation (Tristan Madani)
- scsi: sas: Skip opt_sectors when DMA reports no real optimization hint (Ionut Nechita)
- scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished() (Martin Wilck)
- 9p: skip nlink update in cacheless mode to fix WARN_ON (Breno Leitao) [Orabug: 39885289] {CVE-2026-72170}
- mtd: slram: remove failed entries from the device list (Ruoyu Wang)
- kcov: use WRITE_ONCE() for selftest mode stores (Karl Mehltretter)
- mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE (Muchun Song) [Orabug: 39885300] {CVE-2026-72172}
- proc: only bump parent nlink when registering directories (Krzysztof Wilczyński)
- fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry() (Kiryl Shutsemau)
- fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole() (Kiryl Shutsemau) [Orabug: 39885307] {CVE-2026-72174}
- mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error (Seongjae Park) [Orabug: 39885313] {CVE-2026-72176}
- mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs() (Seongjae Park) [Orabug: 39885315] {CVE-2026-72177}
- riscv: cacheinfo: Fix node reference leak in populate_cache_leaves (Xu Wang)
- mips: sched: Fix CPUMASK_OFFSTACK memory corruption (Aaron Tomlin)
- selftests/landlock: Test SCOPE_SIGNAL on the SIGIO/fowner pgid path (Bryam Vargas)
- power: supply: charger-manager: fix refcount leak in is_full_charged() (Xu Wang) [Orabug: 39885334] {CVE-2026-72182}
- ntfs3: fix out-of-bounds read in decompress_lznt (Tristan Madani)
- ntfs3: validate split-point offset in indx_insert_into_buffer (Michael Bommarito)
- ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head (Michael Bommarito)
- ntfs3: cap RESTART_TABLE free-chain walker at rt->used (Michael Bommarito)
- fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} (Michael Bommarito)
- fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow (Michael Bommarito)
- fs/ntfs3: validate lcns_follow in log_replay conversion (Konstantin Komarov)
- fs/ntfs3: bound attr_off in UpdateResidentValue against data_off (Konstantin Komarov)
- fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass (Michael Bommarito)
- fs/ntfs3: bound DeleteIndexEntryAllocation memmove length (Konstantin Komarov)
- fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename (Zhan Xusheng)
- mm/damon/core: make charge_addr_from aware of end-address exclusivity (Seongjae Park)
- mm/memory_hotplug: fix incorrect altmap passing in error path (Muchun Song) [Orabug: 39885445] {CVE-2026-72212}
- power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (Ma Ke)
- MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf() (Maciej W. Rozycki)
- MIPS: ip22-gio: fix device reference leak in probe (Johan Hovold)
- MIPS: ip22-gio: fix kfree() of static object (Johan Hovold)
- MIPS: ip22-gio: fix gio device memory leak (Johan Hovold)
- remoteproc: qcom: Fix leak when custom dump_segments addition fails (Wasim Nazir)
- SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing (Chuck Lever) [Orabug: 39885461] {CVE-2026-72217}
- lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure (Chuck Lever) [Orabug: 39885463] {CVE-2026-72218}
- lockd: Plug nlm_file leak when nlm_do_fopen() fails (Chuck Lever) [Orabug: 39885466] {CVE-2026-72219}
- sunrpc: wait for in-flight TLS handshake callback when cancel loses race (Chuck Lever) [Orabug: 39885470] {CVE-2026-72221}
- sunrpc: pin svc_xprt across the asynchronous TLS handshake callback (Chris Mason) [Orabug: 39885474] {CVE-2026-72222}
- nvdimm/btt: Free arena sub-allocations on discover_arenas() error path (Abdun Nihaal) [Orabug: 39885477] {CVE-2026-72223}
- nvdimm/btt: Free arenas on btt_init() error paths (Abdun Nihaal) [Orabug: 39885481] {CVE-2026-72224}
- jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() (Junrui Luo) [Orabug: 39885485] {CVE-2026-72225}
- Bluetooth: SCO: hold sk properly in sco_conn_ready (Pauli Virtanen) [Orabug: 40033001] {CVE-2026-89774}
- Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (Pauli Virtanen)
- HID: playstation: validate num_touch_reports in DualShock 4 reports (Benoît Sevens)
- mfd: tps6586x: Fix OF node refcount (Bartosz Golaszewski)
- cifs: invalidate cfid on unlink/rename/rmdir (Shyam Prasad N)
- batman-adv: tt: prevent TVLV OOB check overflow (Sven Eckelmann) [Orabug: 39885488] {CVE-2026-72226}
- batman-adv: mcast: avoid OOB read of num_dests header (Sven Eckelmann) [Orabug: 39885492] {CVE-2026-72227}
- batman-adv: frag: fix primary_if leak on failed linearization (Sven Eckelmann) [Orabug: 39885494] {CVE-2026-72228}
- batman-adv: frag: free unfragmentable packet (Sven Eckelmann) [Orabug: 39885503] {CVE-2026-72230}
- batman-adv: fix VLAN priority offset (Sven Eckelmann)
- batman-adv: tt: avoid request storms during pending request (Sven Eckelmann) [Orabug: 39885507] {CVE-2026-72231}
- batman-adv: dat: fix tie-break for candidate selection (Sven Eckelmann)
- batman-adv: dat: ensure accessible eth_hdr proto field (Sven Eckelmann) [Orabug: 39973050] {CVE-2026-80599}
- batman-adv: bla: reacquire gw address after skb realloc (Sven Eckelmann) [Orabug: 39885516] {CVE-2026-72233}
- batman-adv: dat: acquire ARP hw source only after skb realloc (Sven Eckelmann)
- batman-adv: access unicast_ttvn skb->data only after skb realloc (Sven Eckelmann) [Orabug: 39885520] {CVE-2026-72234}
- batman-adv: gw: acquire ethernet header only after skb realloc (Sven Eckelmann) [Orabug: 39973058] {CVE-2026-80601}
- s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init() (Sumanth Korikkar)
- cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF() (Rafael J. Wysocki)
- perf/x86/amd/lbr: Fix kernel address leakage (Sandipan Das) [Orabug: 39973063] {CVE-2026-80602}
- x86/boot: Reject too long acpi_rsdp= values (Thorsten Blum)
- x86/boot: Validate console=uart8250 baud rate to fix early boot hang (Thorsten Blum)
- tools/power/x86/intel-speed-select: Harden daemon pidfile open (Unknownbbqrx)
- mfd: sm501: Fix reference leak on failed device registration (Guangshuo Li) [Orabug: 39885542] {CVE-2026-72240}
- leds: uleds: Fix potential buffer overread (Armin Wolf) [Orabug: 39885546] {CVE-2026-72241}
- selinux: fix incorrect execmem checks on overlayfs (Ondrej Mosnacek)
- selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() (Tristan Madani) [Orabug: 39885550] {CVE-2026-72242}
- selinux: check connect-related permissions on TCP Fast Open (Stephen Smalley) [Orabug: 39885555] {CVE-2026-72243}
- soc: fsl: qe: panic on ioremap() failure in qe_reset() (Wang Jun)
- soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (Siddharth Vadapalli)
- gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path (Guangshuo Li) [Orabug: 39885561] {CVE-2026-72245}
- netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (Xiang Mei) [Orabug: 39794441] {CVE-2026-64554}
- netfilter: xt_nat: reject unsupported target families (Wyatt Feng) [Orabug: 39973243] {CVE-2026-80664}
- netfilter: ecache: fix inverted time_after() check (Yizhou Zhao)
- netfilter: nf_conncount: fix zone comparison in tuple dedup (Yizhou Zhao) [Orabug: 39885566] {CVE-2026-72247}
- netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag (Xiang Mei) [Orabug: 39885572] {CVE-2026-72250}
- netfilter: nf_nat_sip: reload possible stale data pointer (Florian Westphal) [Orabug: 39885576] {CVE-2026-72251}
- netfilter: nft_set_pipapo: don't leak bad clone into future transaction (Florian Westphal) [Orabug: 39885580] {CVE-2026-72252}
- netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst (Haoze Xie) [Orabug: 39885590] {CVE-2026-72255}
- netfilter: xt_cluster: reject template conntracks in hash match (Wyatt Feng) [Orabug: 39885594] {CVE-2026-72256}
- netfilter: nfnl_cthelper: apply per-class values when updating policies (David Carlier)
- netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read (Muhammad Bilal) [Orabug: 39973067] {CVE-2026-80603}
- ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (Srinivas Kandagatla)
- ASoC: mediatek: mt8183: Release reserved memory on cleanup (Cássio Gabriel)
- ASoC: mediatek: mt8192: Release reserved memory on cleanup (Cássio Gabriel)
- ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (Peter Ujfalusi) [Orabug: 39885607] {CVE-2026-72261}
- ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (Peter Ujfalusi) [Orabug: 39885609] {CVE-2026-72262}
- fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (Abdun Nihaal)
- fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (Abdun Nihaal) [Orabug: 39885616] {CVE-2026-72265}
- fbdev: vesafb: fix memory leak in vesafb_probe() (Abdun Nihaal) [Orabug: 39885620] {CVE-2026-72266}
- fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() (Abdun Nihaal)
- fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (Abdun Nihaal)
- fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (Abdun Nihaal)
- fbdev: s3fb: fix potential memory leak in s3_pci_probe() (Abdun Nihaal)
- fbdev: i740fb: fix potential memory leak in i740fb_probe() (Abdun Nihaal)
- fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (Abdun Nihaal) [Orabug: 39885642] {CVE-2026-72272}
- fbdev: efifb: fix memory leak in efifb_probe() (Abdun Nihaal) [Orabug: 39885647] {CVE-2026-72273}
- fbdev: sm712: Fix operator precedence in big_swap macro (Li Rongqing)
- fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (Abdun Nihaal)
- fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (Abdun Nihaal)
- fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (Abdun Nihaal)
- KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() (Weiming Shi) [Orabug: 39794445] {CVE-2026-64555}
- KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2 (Oliver Upton) [Orabug: 39885662] {CVE-2026-72280}
- KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs (Sean Christopherson) [Orabug: 39885670] {CVE-2026-72284}
- KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs (Atish Patra) [Orabug: 39885675] {CVE-2026-72286}
- KVM: s390: pci: Fix handling of AIF enable without AISB (Matthew Rosato)
- KVM: arm64: vgic: Check the interrupt is still ours before migrating it (Hyunwoo Kim) [Orabug: 39885682] {CVE-2026-72289}
- KVM: s390: pci: Fix GISC refcount leak on AIF enable failure (Haoxiang Li)
- LoongArch: KVM: Return full old CSR value from kvm_emu_xchg_csr() (Maqiang)
- LoongArch: KVM: Fix FPU register width with user access API (Bibo Mao)
- LoongArch: KVM: Check the return values for put_user() (Maqiang)
- LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt() (Bibo Mao)
- ARM: dts: stm32: stm32mp15x-mecio1-io: Move expander gpio-line-names to board files (David Jander)
- ARM: dts: stm32: stm32mp15x-mecio1-io: Fix expander gpio line typo (David Jander)
- ARM: dts: stm32: stm32mp15x-mecio1-io: Move gpio-line-names to board files (David Jander)
- ARM: dts: stm32: stm32mp15x-mecio1-io: Fix GPIO names typo (David Jander)
- arm64: dts: imx8ulp-evk: Correct Type-C int GPIO flags (Krzysztof Kozlowski)
- ARM: dts: stm32: stm32mp15x-mecio1-io: Enable internal ADC reference (David Jander)
- arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc (Judith Mendez)
- ARM: dts: stm32: stm32mp15x-mecio1-io: Move divergent mecio1 ADC channels to board files (David Jander)
- ARM: dts: stm32: stm32mp15x-mecio1-io: Fix ADC sampling times (David Jander)
- arm64: dts: qcom: sdm630: describe adsp_mem region properly (Nickolay Goppen)
- arm64: fpsimd: Fix type mismatch in sve_{save,load}_state() (Mark Rutland)
- net: ife: require ETH_HLEN to be pullable in ife_decode() (Yong Wang)
- net: atm: reject out-of-range traffic classes in QoS validation (Zhengchuan Liang) [Orabug: 39885699] {CVE-2026-72297}
- net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() (Michael Bommarito) [Orabug: 39885703] {CVE-2026-72298}
- ASoC: SOF: topology: validate vendor array size before parsing (Cássio Gabriel) [Orabug: 39887262] {CVE-2026-72300}
- ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (Peter Ujfalusi) [Orabug: 39885715] {CVE-2026-72301}
- ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (Peter Ujfalusi) [Orabug: 39885717] {CVE-2026-72302}
- ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (Peter Ujfalusi) [Orabug: 39885720] {CVE-2026-72304}
- vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter (Zhang Tianci) [Orabug: 39885725] {CVE-2026-72306}
- mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (Xu Wang) [Orabug: 39885729] {CVE-2026-72307}
- mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (Xu Wang) [Orabug: 39885733] {CVE-2026-72308}
- smb: client: fix overflow in passthrough ioctl bounds check (Guangshuo Li) [Orabug: 39885738] {CVE-2026-72310}
include (Anas Khan)
- net/mlx5: Fix L3 tunnel entropy refcount leak (Li Rongqing)
- selftests/net: fix EVP_MD_CTX leak in tcp_mmap (Wang Yan)
- regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (Timur Tabi) [Orabug: 39885748] {CVE-2026-72314}
- dm era: fix NULL pointer dereference in metadata_open() (Cao Guanghui) [Orabug: 39885753] {CVE-2026-72316}
- SUNRPC: pin upper rpc_clnt across the TLS connect_worker (Chuck Lever) [Orabug: 39885757] {CVE-2026-72317}
- SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED (Chuck Lever)
- cifs: validate DFS referral string offsets (Guangshuo Li) [Orabug: 39885760] {CVE-2026-72318}
- s390/zcrypt: Remove the empty file (Rongguang Wei)
- ipvs: ensure inner headers in ICMP errors are in headroom (Julian Anastasov) [Orabug: 39885764] {CVE-2026-72319}
- ipvs: fix PMTU for GUE/GRE tunnel ICMP errors (Yizhou Zhao)
- ipvs: use parsed transport offset in TCP state lookup (Yizhou Zhao) [Orabug: 39982267] {CVE-2026-80875}
- ipvs: pass parsed transport offset to state handlers (Yizhou Zhao)
- netfilter: nft_lookup: fix catchall element handling with inverted lookups (Tamaki Yanagawa) [Orabug: 39885768] {CVE-2026-72320}
- ipv6: mcast: Fix potential UAF in MLD delayed work (Eric Dumazet) [Orabug: 39885775] {CVE-2026-72322}
- ipv6: mcast: Replace locking comments with lockdep annotations. (Kuniyuki Iwashima)
- ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() (Eric Dumazet) [Orabug: 39885779] {CVE-2026-72323}
- gpio: mvebu: free generic chips on unbind (Rosen Penev) [Orabug: 39885784] {CVE-2026-72324}
- perf/x86/amd/core: Avoid enabling BRS from the SVM reload path (Sandipan Das) [Orabug: 39885788] {CVE-2026-72325}
- octeontx2-pf: check DMAC extraction support before filtering (Suman Ghosh)
- net/sched: cake: reject overhead values that underflow length (Samuel Moelius) [Orabug: 39885791] {CVE-2026-72326}
- drm/v3d: Reject invalid indirect BO handle in indirect CSD setup (Maíra Canal)
- net: usb: lan78xx: disable VLAN filter in promiscuous mode (Enrico Pozzobon)
- net: usb: lan78xx: move functions to avoid forward definitions (Oleksij Rempel)
- net/tls: Consume empty data records in tls_sw_read_sock() (Chuck Lever) [Orabug: 39885802] {CVE-2026-72330}
- ring-buffer: Fix event length with forced 8-byte alignment (Hui Wang) [Orabug: 39982271] {CVE-2026-80876}
- Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (Weiming Shi) [Orabug: 39794420] {CVE-2026-64549}
- Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (Pauli Virtanen)
- Bluetooth: MGMT: Fix adv monitor add failure cleanup (Cen Zhang) [Orabug: 39885810] {CVE-2026-72335}
- Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (Cen Zhang) [Orabug: 39885813] {CVE-2026-72336}
- amt: fix size calculation in amt_get_size() (Eric Dumazet)
- net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (Xiang Mei)
- net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload (Jamal Hadi Salim) [Orabug: 39885822] {CVE-2026-72338}
- net: qualcomm: rmnet: validate MAP frame length before ingress parsing (Xiang Mei)
- qede: fix off-by-one in BD ring consumption on build_skb failure (Shigeru Yoshida) [Orabug: 39885826] {CVE-2026-72339}
- net: microchip: vcap: fix races on the shared Super VCAP block (Jens Emil Schulz Østergaard)
- net/mlx5e: Fix HV VHCA stats agent registration race (Feng Liu) [Orabug: 39885836] {CVE-2026-72342}
- net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation (Feng Liu) [Orabug: 39885840] {CVE-2026-72343}
- net/mlx5: LAG, MPESW, Fix missing complete() on devcom error (Shay Drory) [Orabug: 39973250] {CVE-2026-80667}
- netfilter: xt_connmark: reject invalid shift parameters (Wyatt Feng) [Orabug: 39885847] {CVE-2026-72347}
- netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop (Zhixing Chen) [Orabug: 39885851] {CVE-2026-72348}
- netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt() (Feng Wu) [Orabug: 39885855] {CVE-2026-72349}
- netfilter: xt_u32: reject invalid shift counts (Wyatt Feng) [Orabug: 39885859] {CVE-2026-72350}
- gue: validate REMCSUM private option length (Qihang) [Orabug: 39885863] {CVE-2026-72351}
- net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (Xiang Mei) [Orabug: 39794411] {CVE-2026-64547}
- selftests/hid: Cover hid_bpf_get_data() size overflow (Yiyang Chen)
- selftests/hid: Load only requested struct_ops maps (Yiyang Chen)
- HID: bpf: Fix hid_bpf_get_data() range check (Yiyang Chen)
- arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range() (Anshuman Khandual)
- HID: core: Fix OOB read in hid_get_report for numbered reports (Lee Jones) [Orabug: 39973610] {CVE-2026-80604}
- HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (Georgiy Osokin) [Orabug: 39973072] {CVE-2026-80605}
- ata: libata-scsi: limit simulated SCSI command copy to response length (Karuna Ramkumar)
- ata: sata_gemini: unwind clocks on IDE pinctrl errors (Myeonghun Pak)
- cifs: Fix missing credit release on failure in cifs_issue_read() (David Howells) [Orabug: 39885873] {CVE-2026-72356}
- netfs: Drop the error arg from netfs_read_subreq_terminated() (David Howells)
- drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays (Michal Wajdeczko) [Orabug: 39885878] {CVE-2026-72360}
- drm/xe/hw_engine: Fix double-free of managed BO in error path (Shuicheng Lin) [Orabug: 39885880] {CVE-2026-72361}
- drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() (Francois Dugast) [Orabug: 39885882] {CVE-2026-72362}
- netfs: Fix writeback error handling (David Howells) [Orabug: 39885885] {CVE-2026-72364}
- ovl: fix comment about locking order (Amir Goldstein)
- minix: avoid overflow in bitmap block count calculation (Michael Bommarito)
- afs: Fix unchecked-length string display in debug statement (David Howells)
- afs: Fix the volume AFS_VOLUME_RM_TREE is set on (David Howells) [Orabug: 39885897] {CVE-2026-72371}
- afs: Fix vllist leak (David Howells) [Orabug: 39982275] {CVE-2026-80877}
- afs: Fix missing NULL pointer check in afs_break_some_callbacks() (David Howells) [Orabug: 39885904] {CVE-2026-72373}
- afs: Fix callback service message parsers to pass through -EAGAIN (David Howells) [Orabug: 39885907] {CVE-2026-72374}
- afs: Fix misplaced inc of net->cells_outstanding (David Howells) [Orabug: 39885915] {CVE-2026-72376}
- afs: Change dynroot to create contents on demand (David Howells)
- afs: Remove the "autocell" mount option (David Howells)
- afs: Fix afs_atcell_get_link() to handle RCU pathwalk (David Howells)
- afs: Make /afs/@cell and /afs/. at cell symlinks (David Howells)
- afs: Add rootcell checks (David Howells)
mountpoints (David Howells)
- afs: Remove erroneous seq |= 1 in volume lookup loop (Li Rongqing)
- afs: use kvfree() to free memory allocated by kvcalloc() (Zilin Guan)
- afs: Fix double netfs initialisation in afs_root_iget() (David Howells)
- afs: Fix error code in afs_extract_vl_addrs() (Dan Carpenter) [Orabug: 39885920] {CVE-2026-72378}
- fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid (Christian Brauner) [Orabug: 39885924] {CVE-2026-72379}
- net/sched: hhf: clear heavy-hitter state on reset (Samuel Moelius)
- pinctrl: meson: restore non-sleeping GPIO access (Viacheslav Bocharov)
- gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (Vladimir Zapolskiy)
- ksmbd: fix use-after-free of fp->owner.name in durable handle owner check (Gil Portnoy)
- ksmbd: reject undersized DACLs before parsing ACEs (Haofeng Li)
- net/sched: act_bpf: use rcu_dereference_bh() to read the filter (Sechang Lim)
- cxgb4: Fix decode strings dump for T6 adapters (Gleb Markov)
- virtio_net: disable cb when NAPI is busy-polled (Longjun Tang)
- irqchip/ts4800: Fix missing chained handler cleanup on remove (Qingshuang Fu)
- irqchip/gic-v3-its: Fix OF node reference leak (Yuho Choi)
- tracing: eprobe: read the complete FILTER_PTR_STRING pointer (Martin Kaiser)
- tracing/events: Fix to check the simple_tsk_fn creation (Masami Hiramatsu)
- drm/panthor: Interrupt group start/resumption if group_bind_locked() fails (Boris Brezillon)
- drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced (Boris Brezillon)
- drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick() (Boris Brezillon)
- drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom() (Boris Brezillon)
- bridge: stp: Fix a potential use-after-free when deleting a bridge (Ido Schimmel) [Orabug: 39885951] {CVE-2026-72389}
- net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF (Jamal Hadi Salim) [Orabug: 39885955] {CVE-2026-72390}
- net: gianfar: dispose irq mappings on probe failure and device removal (Rosen Penev)
- net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (Petr Wozniak)
- usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (Xiang Mei) [Orabug: 39794386] {CVE-2026-64540}
- ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump (Pengfei Zhang) [Orabug: 39885961] {CVE-2026-72392}
- hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero (Guenter Roeck)
- hwmon: (pmbus) Fix passing events to regulator core (Guenter Roeck) [Orabug: 39887269] {CVE-2026-72395}
- hwmon: adm1275: Prevent reading uninitialized stack (Matti Vaittinen) [Orabug: 39885969] {CVE-2026-72396}
- ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280 (Luca Weiss)
- ASoC: codecs: lpass-va-macro: add SM6115 compatible (Srinivas Kandagatla)
- MIPS: DEC: Ensure RTC platform device deregistration upon failure (Maciej W. Rozycki)
- sctp: fix SCTP_RESET_STREAMS stream list length limit (Yousef Alhouseen)
- net: enetc: check the number of BDs needed for xdp_frame (Wei Fang)
- qede: fix out-of-bounds check for cqe->len_list[] (Matvey Kovalev) [Orabug: 39973081] {CVE-2026-80609}
- seg6: validate SRH length before reading fixed fields (Nuoqi Gui) [Orabug: 39885984] {CVE-2026-72400}
- gpio: htc-egpio: use managed gpiochip registration (Pengpeng Hou)
- gpio: mvebu: fail probe if gpiochip registration fails (Pengpeng Hou)
- spi: sh-msiof: abort transfers when reset times out (Pengpeng Hou)
- tracing: probes: fix typo in a log message (Martin Kaiser)
- net: hns3: differentiate autoneg default values between copper and fiber (Shuaisong Yang)
- net: hns3: fix permanent link down deadlock after reset (Shuaisong Yang)
- net: hns3: refactor MAC autoneg and speed configuration (Shuaisong Yang)
- net: hns3: unify copper port ksettings configuration path (Shuaisong Yang)
- net: hns3: clear hns alarm: comparison of integer expressions of different signedness (Peiyang Wang)
- net: hns3: use hns3_get_ops() helper to reduce the unnecessary middle layer conversion (Jijie Shao)
- net: hns3: use hns3_get_ae_dev() helper to reduce the unnecessary middle layer conversion (Jijie Shao)
- net: hns3: use string choices helper (Jian Shen)
- net: hisilicon: hns3: use ethtool string helpers (Rosen Penev)
- dt-bindings: net: renesas,ether: Drop example "ethernet-phy-ieee802.3-c22" fallback (Rob Herring)
- net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync (Eric Dumazet) [Orabug: 39885998] {CVE-2026-72405}
- udp_tunnel: remove rtnl_lock dependency (Stanislav Fomichev)
- ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (Shengjiu Wang)
- net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove (Shitalkumar Gandhi)
- net: sungem: fix probe error cleanup (Ruoyu Wang) [Orabug: 39886003] {CVE-2026-72406}
- net: mvneta: re-enable percpu interrupt on resume (Yun Zhou) [Orabug: 39886009] {CVE-2026-72409}
- net: dsa: realtek: fix memory leak in rtl8366rb_setup_led() (David Yang)
- rtc: cmos: unregister HPET IRQ handler on probe failure (Haoxiang Li)
- rtc: ds1307: Fix off-by-one issue with wday for rx8130 (Fredrik M Olsson)
- smb/client: preserve errors from smb2_set_sparse() (Huiwen He)
- ACPI: processor_idle: Mark LPI enter functions as __cpuidle (Li Rongqing) [Orabug: 39973088] {CVE-2026-80611}
- thermal: testing: zone: Flush work items during cleanup (Rafael J. Wysocki)
- ipv6: fix missing notification for ignore_routes_with_linkdown (Fernando Fernandez Mancera)
- ipv6: Convert net.ipv6.conf.${DEV}.XXX sysctl to per-netns RTNL. (Kuniyuki Iwashima)
- ipv6: Add __in6_dev_get_rtnl_net(). (Kuniyuki Iwashima)
- rtnetlink: Define rtnl_net_trylock(). (Kuniyuki Iwashima)
- rtnetlink: Add assertion helpers for per-netns RTNL. (Kuniyuki Iwashima)
- rtnetlink: Add per-netns RTNL. (Kuniyuki Iwashima)
- ipv6: fix error handling in disable_policy sysctl (Fernando Fernandez Mancera)
- ipv6: fix error handling in forwarding sysctl (Fernando Fernandez Mancera)
- ipv6: fix error handling in ignore_routes_with_linkdown sysctl (Fernando Fernandez Mancera)
- ipv6: fix error handling in disable_ipv6 sysctl (Fernando Fernandez Mancera)
- net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (Jamal Hadi Salim) [Orabug: 39787016] {CVE-2026-64530}
- veth: fix NAPI leak in XDP enable error path (Eric Dumazet) [Orabug: 39973093] {CVE-2026-80613}
- net: dsa: sja1105: round up PTP perout pin duration (Aleksandrova Alyona)
- net, bpf: check master for NULL in xdp_master_redirect() (Xiang Mei) [Orabug: 39794404] {CVE-2026-64545}
- alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs (Krzysztof Wilczyński)
- alpha/PCI: Add security_locked_down() check to pci_mmap_resource() (Krzysztof Wilczyński)
- NTB: epf: Fix doorbell bitmask and IRQ vector handling (Koichiro Den)
- NTB: epf: Report 0-based doorbell vector via ntb_db_event() (Koichiro Den)
- NTB: epf: Make db_valid_mask cover only real doorbell bits (Koichiro Den)
- gpio: davinci: fix IRQ domain leak on devm_kzalloc failure (Qingshuang Fu)
- netfilter: nft_compat: ebtables emulation must reject non-bridge targets (Florian Westphal) [Orabug: 39886026] {CVE-2026-72416}
- netfilter: nft_synproxy: stop bypassing the priv->info snapshot (Runyu Xiao)
- netfilter: nf_conncount: prevent connlimit drops for early confirmed ct (Fernando Fernandez Mancera) [Orabug: 39887247] {CVE-2026-72418}
- netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init() (Mathias Krause) [Orabug: 39886032] {CVE-2026-72419}
- bpf: Disable xfrm_decode_session hook attachment (Bradley Morgan) [Orabug: 39973255] {CVE-2026-80669}
- md/raid5: avoid R5_Overlap races while breaking stripe batches (Chen Cheng) [Orabug: 39886034] {CVE-2026-72420}
- md/raid5: use stripe state snapshot in break_stripe_batch_list() (Chen Cheng)
- ipv4: fib: Don't ignore error route in local/main tables. (Kuniyuki Iwashima) [Orabug: 39886038] {CVE-2026-72421}
- eth: bnxt: improve the timing of stats (Jakub Kicinski)
- eth: bnxt: rename ring_err_stats -> ring_drv_stats (Jakub Kicinski)
- eth: bnxt: gather and report HW-GRO stats (Jakub Kicinski)
- net: bnxt: use ethtool string helpers (Rosen Penev)
- ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). (Xiang Mei) [Orabug: 39794378] {CVE-2026-64538}
- ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE (Gil Portnoy)
- rtc: msc313: fix NULL deref in shared IRQ handler at probe (Stepan Ionichev)
- i40e: Fix i40e_debug() to use struct i40e_hw argument (Mohamed Khalfella)
- ice: dpll: fix memory leak in ice_dpll_init_info error paths (Zhaojinming)
- ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info (Zhaojinming)
- ice: call netif_keep_dst() once when entering switchdev mode (Marcin Szycik)
- ice: fix AQ error code comparison in ice_set_pauseparam() (Lukasz Czapnik)
- ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs() (Dawid Osuchowski) [Orabug: 39886049] {CVE-2026-72425}
- PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0 (Manivannan Sadhasivam)
- PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0 (Manivannan Sadhasivam)
- drm/edid: fix OOB read in drm_parse_tiled_block() (Xiang Mei) [Orabug: 39794407] {CVE-2026-64546}
- power: sequencing: fix ABBA deadlock in pwrseq_device_unregister() (Bartosz Golaszewski)
- bpf: Fix effective prog array index with BPF_F_PREORDER (Amery Hung) [Orabug: 39886054] {CVE-2026-72427}
- bpf: zero-initialize the fib lookup flow struct (Avinash Duduskar)
- bpftool: Fix vmlinux BTF leak in cgroup commands (Chenyichong)
- bpf: Fix stack slot index in nospec checks (Nuoqi Gui) [Orabug: 39886056] {CVE-2026-72428}
- rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (Ronan Dalton)
- rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (Antoni Pokusinski)
- dpaa2-switch: do not accept VLAN uppers while bridged (Ioana Ciornei)
- ipv6: ndisc: fix NULL deref in accept_untracked_na() (Weiming Shi) [Orabug: 39794394] {CVE-2026-64542}
- net/sched: act_ct: fix nf_connlabels leak on two error paths (Michael Bommarito) [Orabug: 39886062] {CVE-2026-72430}
- net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths (Wayen Yan)
- tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (Weiming Shi) [Orabug: 39794396] {CVE-2026-64543}
- net: marvell: prestera: initialize err in prestera_port_sfp_bind (Ruoyu Wang)
- selftests/mm: fix exclusive_cow test fork() handling (Aboorva Devarajan)
- selftests/mm: allow PUD-level entries in compound testcase of hmm tests (Sayali Patil)
- selftests/mm: clarify alternate unmapping in compaction_test (Sayali Patil)
- selftests/mm: ensure destination is hugetlb-backed in hugetlb-mremap (Sayali Patil)
- selftest/mm: register existing mapping with userfaultfd in hugetlb-mremap (Sayali Patil)
- selftests/mm: restore default nr_hugepages value via exit trap in charge_reserved_hugetlb.sh (Sayali Patil)
- irqchip/crossbar: Fix parent domain resource leak (Bhargav Joshi)
- mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx() (Sebastian Andrzej Siewior)
- netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak (Florian Westphal) [Orabug: 39886067] {CVE-2026-72433}
- netfilter: nf_reject: skip iphdr options when looking for icmp header (Florian Westphal)
- netfilter: ipset: make sure gc is properly stopped (Jozsef Kadlecsik) [Orabug: 39886071] {CVE-2026-72434}
- netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() (Jozsef Kadlecsik) [Orabug: 39886075] {CVE-2026-72435}
- netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types (Jozsef Kadlecsik) [Orabug: 39886079] {CVE-2026-72436}
- netfilter: ipset: annotate "pos" for concurrent readers/writers (Jozsef Kadlecsik)
- netfilter: ipset: Fix data race between add and dump in all hash types (Jozsef Kadlecsik)
- md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry (Abd-Alrhman Masalkhi) [Orabug: 39886083] {CVE-2026-72437}
- mac802154: Prevent overwrite return code in mac802154_perform_association() (Robertus Diawan Chris)
- ieee802154: fix kernel-infoleak in dgram_recvmsg() (Aleksandr Nogikh) [Orabug: 39886094] {CVE-2026-72441}
- ieee802154: Remove WARN_ON() in cfg802154_pernet_exit() (Ivan Abramov)
- ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (Xu Rao)
- ACPI: resource: Amend kernel-doc style (Andy Shevchenko)
- thermal: intel: Fix dangling resources on thermal_throttle_online() failure (Ricardo Neri)
- arm64/hw_breakpoint: reject unaligned watchpoints that would truncate BAS (Breno Leitao)
- ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (Cen Zhang) [Orabug: 39886099] {CVE-2026-72443}
- flow_dissector: check device type before reading ETH_ADDRS (Yun Zhou) [Orabug: 39886101] {CVE-2026-72444}
- devlink: Fix parent ref leak in devl_rate_node_create() (Cosmin Ratiu)
- dpaa2-switch: fix VLAN upper check not rejecting bridge join (Ioana Ciornei)
- virtio-net: fix len check in receive_big() (Xiang Mei) [Orabug: 39794434] {CVE-2026-64552}
- spi: rpc-if: Use correct device for hardware reinitialization on resume (Quang Nguyen)
- PCI: iproc: Restore .map_irq() for the platform bus driver (Mark Tomlinson)
- sctp: hold socket lock when dumping endpoints in sctp_diag (Xin Long) [Orabug: 39886108] {CVE-2026-72447}
- net: psample: fix info leak in PSAMPLE_ATTR_DATA (Jakub Kicinski) [Orabug: 39794437] {CVE-2026-64553}
- drm/amdgpu: initialize irq.lock spinlock earlier (Thadeu Lima de Souza Cascardo)
- drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (Mario Limonciello) [Orabug: 39886115] {CVE-2026-72449}
- drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (Yunxiang Li) [Orabug: 39973107] {CVE-2026-80618}
- ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (Sen Wang)
- xfrm: validate selector family and prefixlen during match (Eric Dumazet) [Orabug: 39886117] {CVE-2026-72450}
- xfrm: annotate data-races around xfrm_policy_count[] and xfrm_policy_default[] (Eric Dumazet)
- xfrm: Fix xfrm state cache insertion race (Herbert Xu) [Orabug: 39886121] {CVE-2026-72451}
- spi: dw: fix wrong BAUDR setting after resume (Jisheng Zhang)
- drm/i915: clear CRTC color blob pointers after dropping refs (Guangshuo Li) [Orabug: 39887272] {CVE-2026-72452}
- gpio: mlxbf3: fail probe if gpiochip registration fails (Pengpeng Hou)
- sparc: led: avoid trimming a newline from empty writes (Pengpeng Hou)
- apparmor: fix label can not be immediately before a declaration (John Johansen)
- i3c: master: Prevent reuse of dynamic address on device add failure (Adrian Hunter)
- i3c: master: Make hot-join workqueue freezable to block hot-join during suspend (Adrian Hunter)
- i3c: master: add WQ_PERCPU to alloc_workqueue users (Marco Crivellari)
- workqueue: Add new WQ_PERCPU flag (Marco Crivellari)
- apparmor: put secmark label after secid lookup (Zygmunt Krynicki)
- apparmor: aa_getprocattr free procattr leak on format failure (Zygmunt Krynicki)
- apparmor: remove or add symlinks to rawdata according to export_binary (Georgia Garcia)
- apparmor: fix potential UAF in aa_replace_profiles (Maxime Bélair)
- apparmor: grab ns lock and refresh when looking up changehat child profiles (Ryan Lee)
- apparmor: fix rawdata_f_data implicit flex array (John Johansen)
- apparmor: aa_label_alloc use aa_label_free on alloc failure (Zygmunt Krynicki)
- apparmor: check label build before no_new_privs test (Ruoyu Wang)
- security/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref() (Andrew Morton)
- Revert "PCI/MSI: Unmap MSI-X region on error" (Yuanhe Shu) [Orabug: 39973601] {CVE-2026-80620}
- PCI: mediatek: Use actual physical address instead of virt_to_phys() (Manivannan Sadhasivam)
- PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port() (Ryder Lee)
- tools lib api: Fix mount_overload() snprintf truncation and toupper range (Arnaldo Carvalho de Melo)
- tools lib api: Fix filename__write_int() writing uninitialized stack data (Arnaldo Carvalho de Melo)
- tools lib api: Fix missing null termination in filename__read_int/ull() (Arnaldo Carvalho de Melo)
- xprtrdma: Return sendctx slot after Send preparation failure (Chuck Lever)
- xprtrdma: Repost Receive buffers for malformed replies (Chuck Lever) [Orabug: 39886143] {CVE-2026-72464}
- xprtrdma: Sanitize the reply credit grant after parsing (Chuck Lever) [Orabug: 39887249] {CVE-2026-72465}
- xprtrdma: Fix bcall rep leak and unbounded peek (Chris Mason) [Orabug: 39886148] {CVE-2026-72466}
- xprtrdma: Resize reply buffers before reposting receives (Chuck Lever)
- xprtrdma: Document and assert reply-handler invariants (Chuck Lever)
- xprtrdma: Check frwr_wp_create() during connect (Chuck Lever) [Orabug: 39886152] {CVE-2026-72467}
- xprtrdma: Initialize re_id before removal registration (Chris Mason) [Orabug: 39886154] {CVE-2026-72468}
- xprtrdma: Fix ep kref imbalance on ADDR_CHANGE (Chris Mason) [Orabug: 39886156] {CVE-2026-72469}
- PCI: rcar-host: Remove unused LIST_HEAD(res) (Lad Prabhakar)
- fs/ntfs3: resize log->one_page_buf when adopting on-disk page size (Jamie Nguyen)
- PCI: meson: Add missing remove callback (Shuvam Pandey)
- PCI: meson: Propagate devm_add_action_or_reset() failure (Shuvam Pandey)
- PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro (Li Rongqing)
- nfs: use nfsi->rwsem to protect traversal of the file lock list (Yangerkun) [Orabug: 39886164] {CVE-2026-72472}
- NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write (Mike Snitzer)
- NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors (Mike Snitzer)
- nfs: keep PG_UPTODATE clear after read errors in page groups (Clark Wang)
- NFSv4/pnfs: defer return_range callbacks until after inode unlock (Dai Ngo)
- xprtrdma: Decouple req recycling from RPC completion (Chuck Lever) [Orabug: 39886168] {CVE-2026-72473}
- xprtrdma: Use sendctx DMA state for Send signaling (Chuck Lever)
- xprtrdma: Post receive buffers after RPC completion (Chuck Lever)
- xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot (Chuck Lever)
- xprtrdma: Avoid 250 ms delay on backlog wakeup (Chuck Lever)
- pNFS/filelayout: fix cheking if a layout is striped (Sagi Grimberg)
- clk: qcom: a53: Corrected frequency multiplier for 1152MHz (Phillip Varney)
- dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor (Nuno Sa)
- dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc (Nuno Sa)
- dmaengine: Fix possible use after free (Nuno Sa) [Orabug: 39886177] {CVE-2026-72476}
- dmaengine: qcom: gpi: set DMA_PRIVATE capability (Icenowy Zheng)
- perf: Fix off-by-one stack buffer overflow in kallsyms__parse() (Rui Qi)
- dmaengine: imx-sdma: Refine spba bus searching in probe (Shengjiu Wang)
- thunderbolt: debugfs: Fix margining error counter buffer leak (Xu Rao)
- drm/amd/display: Add missing kdoc for ALLM parameters (Srinivasan Shanmugam)
- fs/ntfs3: fix mount failure on 64K page-size kernels (Jamie Nguyen)
- fs/ntfs3: add bounds check to run_get_highest_vcn() (Konstantin Komarov)
- HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (Rosen Penev)
- clk: at91: keep securam node alive while mapping it (Yuho Choi)
- iio: tcs3472: power down chip on probe failure (Aldo Conte)
- iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (Sanjay Chitroda)
- iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (Guilherme Ivo Bozi)
- iio: magnetometer: ak8975: fix potential kernel stack memory leak (Joshua Crofts) [Orabug: 39886189] {CVE-2026-72481}
- iio: light: si1133: prevent race condition on timeout (Joshua Crofts)
- iio: light: si1133: reset counter to prevent race condition (Joshua Crofts)
- PCI: qcom: Disable ASPM L0s for SA8775P (Shawn Guo)
- char: tlclk: fix use-after-free in tlclk_cleanup() (James Kim) [Orabug: 39973116] {CVE-2026-80622}
- usb: host: max3421: Reject hub port requests for non-existent ports (Seungjin Bae)
- usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (Seungjin Bae)
- staging: most: video: avoid double free on video register failure (Guangshuo Li)
- mailbox: mtk-adsp: fix UAF during device teardown (Sergey Senozhatsky)
- coresight: Fix source not disabled on idr_alloc_u32 failure (Jie Gan)
- clk: at91: sam9x7: Fix gmac_gclk clock definition (Mihai Sain)
- phy: phy-can-transceiver: Check driver match and driver data against NULL (Andy Shevchenko)
- PCI: qcom: Set max OPP before DBI access during resume (Qiang Yu)
- bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (Sumit Kumar)
- rust: alloc: fix assert in Vec::reserve doc test (Hsiu Che Yu)
- PCI: loongson: Do not ignore downstream devices on external bridges (Rongrong)
- platform/x86: xo15-ebook: Fix wakeup source and GPE handling (Rafael J. Wysocki)
- x86/platform/olpc: xo15: Drop wakeup source on driver removal (Rafael J. Wysocki)
- PCI: Check ROM header and data structure addr before accessing (Guixin Liu) [Orabug: 39886206] {CVE-2026-72487}
- PCI: Introduce named defines for PCI ROM (Guixin Liu)
- PCI/ASPM: Don't reconfigure ASPM entering low-power state (Carlos Bilbao)
- coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore (Leo Yan)
- coresight: cti: Fix DT filter signals silently ignored (Yingchao Deng)
- staging: nvec: fix use-after-free in nvec_rx_completed() (Alexandru Hossu)
- gpiolib: acpi: Only trigger ActiveBoth interrupts on boot (Mario Limonciello)
- eventpoll: Fix epoll_wait() report false negative (Nam Cao)
- eventpoll: rename epi->next and txlist for clarity (Christian Brauner)
- eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers (Christian Brauner)
- eventpoll: extract ep_deliver_event() from ep_send_events() (Christian Brauner)
- eventpoll: split ep_insert() into alloc + register stages (Christian Brauner)
- eventpoll: rename attach_epitem() to ep_attach_file() (Christian Brauner)
- eventpoll: expand top-of-file overview / locking doc (Christian Brauner)
- net/9p: fix race condition on rdma->state in trans_rdma.c (Yizhou Zhao) [Orabug: 39886218] {CVE-2026-72491}
- ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write (Aleksandr Nogikh) [Orabug: 39982398] {CVE-2026-80879}
- mfd: cs42l43: Sanity check firmware size (Charles Keepax) [Orabug: 39973126] {CVE-2026-80624}
- mfd: rsmu: Fix page register setup (Matthew Bystrin)
- ksmbd: fix use-after-free in same_client_has_lease() (Guangshuo Li)
- ionic: Fix check in ionic_get_link_ext_stats (Brett Creeley)
- net: ethernet: oa_tc6: Remove FCS size in RX frame (Selvamani Rajagopal)
- net: airoha: Fix always-true condition in PPE1 queue reservation loop (Wayen Yan)
- net: airoha: Add sched ETS offload support (Lorenzo Bianconi)
- net: airoha: Introduce ndo_select_queue callback (Lorenzo Bianconi)
- tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (Eric Dumazet) [Orabug: 39886246] {CVE-2026-72502}
- tipc: fix UAF in tipc_l2_send_msg() (Eric Dumazet) [Orabug: 39886250] {CVE-2026-74255}
- KEYS: Use acquire when reading state in keyring search (Gui-Dong Han)
- powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus (Aboorva Devarajan)
- powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down (Aboorva Devarajan)
- powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del (Aboorva Devarajan)
- MIPS: mm: Fix out-of-bounds write in maar_res_walk() (Yadan Fan)
- bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check (Sechang Lim) [Orabug: 39886254] {CVE-2026-74256}
- bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (Weiming Shi) [Orabug: 39794416] {CVE-2026-64548}
- udf: fix nls leak on udf_fill_super() failure (Al Viro)
- bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket (Leon Hwang)
- selftests/bpf: Initialize operation name before use (Leo Yan)
- selftests/bpf: Fix typo in verify_umulti_link_info (Jiri Olsa)
- smb/client: always return a value for FS_IOC_GETFLAGS (Huiwen He)
- cifs: remove all cifs files before kill super (Zhangjian)
- ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (Takashi Iwai)
- netfilter: nf_conncount: callers must hold rcu read lock (Florian Westphal)
- kcm: use WRITE_ONCE() when changing lower socket callbacks (Runyu Xiao)
- net: bcmgenet: Use weighted round-robin TX DMA arbitration (Ovidiu Panait)
- landlock: Fix unmarked concurrent access to socket family (Matthieu Buffet)
- dpll: balance create/delete notifications in __dpll_pin_(un)register (Grzegorz Nitka)
- dpll: guard sync-pair removal on full pin unregister (Grzegorz Nitka)
- dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister() (Grzegorz Nitka)
- dpll: send delete notification before unregister in on-pin rollback (Grzegorz Nitka)
- dpll: fix stale iteration in dpll_pin_on_pin_unregister() (Grzegorz Nitka)
- dpll: Enhance and consolidate reference counting logic (Ivan Vecera)
- dpll: Support dynamic pin index allocation (Ivan Vecera)
- dpll: Add notifier chain for dpll events (Petr Oros)
- dpll: Allow associating dpll pin with a firmware node (Ivan Vecera)
- dpll: add reference sync get/set (Arkadiusz Kubalewski)
- dpll: add reference-sync netlink attribute (Arkadiusz Kubalewski)
- net: wwan: t7xx: check skb_clone in control TX (Ruoyu Wang) [Orabug: 39886274] {CVE-2026-74263}
- net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show() (Guan Wentao)
- octeontx2-af: npc: Fix size of entry2cntr_map (Ratheesh Kannoth)
- net/mlx5: Check max_macs devlink param value against max capability (Dragos Tatulea)
- bpf: Run generic devmap egress prog on private skb (Sun Jian)
- net: ethernet: mtk_wed: fix loading WO firmware for MT7986 (Zhi-Jun You)
- net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (Aditya Garg)
- net: mana: initialize gdma queue id to INVALID_QUEUE_ID (Aditya Garg) [Orabug: 39886278] {CVE-2026-74265}
- net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen (Victor Nogueira) [Orabug: 39886283] {CVE-2026-74267}
- net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen (Victor Nogueira) [Orabug: 39973147] {CVE-2026-80630}
- handshake: Require admin permission for DONE command (Chuck Lever) [Orabug: 39886294] {CVE-2026-74270}
- power: supply: core: fix supplied_from allocations (Lucas Tsai) [Orabug: 39886297] {CVE-2026-74271}
- ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (Guangshuo Li)
- spi: xilinx: use FIFO occupancy register to determine buffer size (Lars Pöschel)
- ALSA: seq: Fix kernel heap address leak in bounce_error_event() (Ji'An Zhou) [Orabug: 39886314] {CVE-2026-74278}
- crypto: rng - Free default RNG on module exit (Herbert Xu)
- crypto: cavium/cpt - fix DMA cleanup using wrong loop index (Felix Gu) [Orabug: 39886318] {CVE-2026-74279}
- crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (Felix Gu)
- cxl/test: Add check after kzalloc() memory in alloc_mock_res() (Dave Jiang)
- cxl/test: Unregister cxl_acpi in cxl_test_init() error path (Dave Jiang)
- tipc: reject inverted service ranges from peer bindings (Michael Bommarito) [Orabug: 39886325] {CVE-2026-74281}
- tipc: prevent snt_unacked underflow on CONN_ACK (Michael Bommarito) [Orabug: 39886330] {CVE-2026-74282}
- tipc: require net admin for TIPCv2 netlink mutators (Michael Bommarito) [Orabug: 39886334] {CVE-2026-74283}
- net/sched: sch_hfsc: Don't make class passive twice (Victor Nogueira) [Orabug: 39886338] {CVE-2026-74284}
- net: pfcp: allocate per-cpu tstats for PFCP netdevs (Samuel Moelius)
- sctp: validate embedded address parameter length (Xin Long) [Orabug: 39886345] {CVE-2026-74287}
- bridge: cfm: reject invalid CCM interval at configuration time (Xiang Mei)
- net: fib_rules: Don't dump dying fib_rule in fib_rules_dump(). (Kuniyuki Iwashima) [Orabug: 39886349] {CVE-2026-74288}
- net/sched: cls_flow: Dont expose folded kernel pointers (Jamal Hadi Salim) [Orabug: 39886357] {CVE-2026-74290}
- net: dsa: qca8k: fix led devicename when using external mdio bus (George Moussalem)
- ASoC: tegra: tegra210_ahub: Validate written enum value (Hyeongjun An)
- ASoC: fsl: fsl_audmix: Validate written enum values (Hyeongjun An)
- ASoC: codecs: hdac_hdmi: Validate written enum value (Hyeongjun An)
- RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one (Leon Romanovsky) [Orabug: 39886379] {CVE-2026-74296}
- RDMA/mlx5: Fix undefined shift of user RQ WQE size (Maher Sanalla) [Orabug: 39886383] {CVE-2026-74297}
- RDMA/mlx5: Remove raw RSS QP restrack tracking (Patrisious Haddad)
- RDMA/mlx5: Remove DCT restrack tracking (Patrisious Haddad)
- fs: efs: remove unneeded debug prints (Maxwell Doose)
- Bluetooth: vhci: validate devcoredump state before side effects (Samuel Moelius)
- Bluetooth: hci: validate codec capability element length (Samuel Moelius) [Orabug: 39886389] {CVE-2026-74300}
- Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path (Zhao Dongdong)
- Bluetooth: hci_core: Fix UAF in hci_unregister_dev() (Jordan Walters) [Orabug: 39886393] {CVE-2026-74302}
- Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (Weiming Shi) [Orabug: 39794382] {CVE-2026-64539}
- Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device (Zijun Hu)
- s390/process: Fix kernel thread function pointer type (Heiko Carstens)
- ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset() (Richard Fitzgerald)
- bpf: Tighten cgroup storage cookie checks for prog arrays (Daniel Borkmann) [Orabug: 39886400] {CVE-2026-74305}
- vfio/qat: fix f_pos race in qat_vf_resume_write() (Giovanni Cabiddu) [Orabug: 39886403] {CVE-2026-74306}
- of: cpu: add check in __of_find_n_match_cpu_property() (Sergey Shtylyov)
- cxl/test: Zero out LSA backing memory to avoid leaking to user (Dave Jiang)
- cxl/test: Fix integer overflow in mock LSA bounds checks (Dave Jiang)
- selftests/bpf: Fix bpf_iter/task_vma test (Yonghong Song)
- ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT (Yun Zhou) [Orabug: 39886405] {CVE-2026-74307}
- ext4: fix kernel BUG in ext4_write_inline_data_end (Aditya Prakash Srivastava) [Orabug: 39886409] {CVE-2026-74308}
- bonding: 3ad: fix mux port state on oper down (Louis Scalbert)
- ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails (Richard Fitzgerald)
- ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (Richard Fitzgerald)
- vdpa/octeon_ep: Fix PF->VF mailbox data address calculation (Srujana Challa)
- tools/virtio: check mmap return value in vringh_test (Longlong Yan)
- vhost/net: complete zerocopy ubufs only once (Qing Ming) [Orabug: 39886415] {CVE-2026-74310}
- vduse: Requeue failed read to send_list head (Zhang Tianci)
- virtio_console: read size from config space during device init (Filip Hejsek)
- vhost/vdpa: validate virtqueue index in mmap and fault paths (Qihang) [Orabug: 39886420] {CVE-2026-74312}
- vduse: hold vduse_lock across IDR lookup in open path (Qihang) [Orabug: 39886424] {CVE-2026-74313}
- ASoC: codecs: aw88261: fix incorrect masks for boost regs (Val Packett)
- spi: meson-spifc: fix runtime PM leak on remove (Ruoyu Wang)
- NFSD: Handle layout stid in nfsd4_drop_revoked_stid() (Chuck Lever) [Orabug: 39886432] {CVE-2026-74316}
- IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified (Jason Gunthorpe)
- btrfs: fix deadlock cloning inline extent when using flushoncommit (Filipe Manana) [Orabug: 39886441] {CVE-2026-74318}
- btrfs: zoned: don't account data relocation space-info in statfs free space (Johannes Thumshirn)
- hwmon: (it87) Clamp negative values to zero in set_fan() (Nikita Zhandarovich)
- fbdev: sm501fb: Fix buffer errors in OF binding code (David Laight) [Orabug: 39886445] {CVE-2026-74320}
- btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (Filipe Manana) [Orabug: 39886449] {CVE-2026-74321}
- wifi: mt76: mt7996: fix potential tx_retries underflow (Ryder Lee)
- wifi: mt76: mt7925: fix potential tx_retries underflow (Ryder Lee)
- wifi: mt76: mt7921: fix potential tx_retries underflow (Ryder Lee)
- wifi: mt76: mt7915: fix potential tx_retries underflow (Ryder Lee)
- wifi: mt76: fix argument to ieee80211_is_first_frag() (Bjoern A. Zeeb)
- wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX (Sean Wang)
- wifi: mt76: mt7925: keep TX BA state in the primary WCID (Sean Wang)
- wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links (Javier Tia)
- wifi: mt76: mt7925: clean up DMA on probe failure (Myeonghun Pak)
- sched/fair: Fix cpu_util runnable_avg arithmetic (Hongyan Xia)
- hwspinlock: qcom: avoid uninitialized struct members (Wolfram Sang)
- vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() (Hui Zhu) [Orabug: 39886459] {CVE-2026-74327}
- pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (Luca Leonardo Scorcia)
- pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (Luca Leonardo Scorcia)
- scsi: target: Remove tcm_loop target reset handling (Mike Christie)
- scsi: target: Fix hexadecimal CHAP_I handling (David Disseldorp)
- watchdog: unregister PM notifier on watchdog unregister (Yuho Choi) [Orabug: 39886463] {CVE-2026-74329}
- configfs: fix lockless traversals of ->s_children (Al Viro) [Orabug: 39886466] {CVE-2026-74330}
- firmware_loader: Fix recursive lock in device_cache_fw_images() (Dmitry Vyukov) [Orabug: 39886470] {CVE-2026-74331}
- ASoC: amd: acp-sdw-sof: Bound DAI link iteration (Aaron Ma) [Orabug: 39886474] {CVE-2026-74332}
- spi: ep93xx: fix double-free of zeropage on DMA setup failure (Felix Gu)
- IB/mlx5: Properly support implicit ODP rereg_mr (Jason Gunthorpe) [Orabug: 39982282] {CVE-2026-80880}
- IB/mlx5: Don't take the rereg_mr fallback without a new translation (Jason Gunthorpe)
- thermal: testing: reject missing command arguments (Samuel Moelius)
- cpufreq: Documentation: fix conservative governor freq_step description (Pengjie Zhang)
- ACPI: IPMI: Fix message kref handling on dead device (Yuho Choi)
- ALSA: seq: Clear variable event pointer on read (Kyle Zeng) [Orabug: 39886490] {CVE-2026-74339}
- riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe (Rui Qi)
- riscv: cpu_ops: Change return value type of cpu_is_stopped() to bool (Hui Wang)
- ALSA: seq: Fix partial userptr event expansion (Hyeongjun An)
- wifi: wcn36xx: fix OOB read from short trigger BA firmware response (Tristan Madani) [Orabug: 39973161] {CVE-2026-80635}
- wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (Tristan Madani) [Orabug: 39886494] {CVE-2026-74340}
- wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (Tristan Madani) [Orabug: 39886498] {CVE-2026-74341}
- bpf: Update transport_header when encapsulating UDP tunnel in lwt (Leon Hwang)
- bpf: Check tail zero of bpf_prog_info (Leon Hwang)
- RDMA/siw: Fix endpoint/socket association handling (Bernard Metzler)
- arm64: dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as well (Alexander Stein)
- arm64: dts: imx95: Correct PCIe outbound address space configuration (Richard Zhu)
- RDMA/irdma: Initialize iwmr->access during MR registration (Jacob Moroni)
- RDMA/irdma: Fix OOB read during CQ MR registration (Jacob Moroni) [Orabug: 39886513] {CVE-2026-74346}
- IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path() (Jason Gunthorpe)
- netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp (Pablo Neira Ayuso)
- netfilter: conntrack: revert ct extension genid infrastructure (Pablo Neira Ayuso) [Orabug: 39973165] {CVE-2026-80636}
- netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock (Fernando Fernandez Mancera)
- netfilter: synproxy: fix unaligned memory access in timestamp adjustment (Fernando Fernandez Mancera) [Orabug: 39973168] {CVE-2026-80637}
- netfilter: synproxy: adjust duplicate timestamp options (Fernando Fernandez Mancera)
- netfilter: synproxy: drop packets if timestamp adjustment fails (Fernando Fernandez Mancera)
- netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags (Pablo Neira Ayuso)
- netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures (Fernando Fernandez Mancera)
- ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release() (Joseph Qi)
- ocfs2/dlm: require a ref for locking_state debugfs open (Zhang Cen) [Orabug: 39886520] {CVE-2026-74348}
- ocfs2: reject FITRIM ranges shorter than a cluster (Zhang Cen) [Orabug: 39886524] {CVE-2026-74349}
- ocfs2: fix buffer head management in ocfs2_read_blocks() (Dmitry Antipov) [Orabug: 39982286] {CVE-2026-80881}
- ocfs2: rebase copied fsdlm LVB pointers in locking_state (Zhang Cen) [Orabug: 39886533] {CVE-2026-74351}
- drm/amdkfd: always resume_all after suspend_all (Alex Deucher) [Orabug: 39886538] {CVE-2026-74353}
- xfrm: fix NAT-related field inheritance in SA migration (Antony Antony)
- perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains (Sandipan Das)
- perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems (Zide Chen)
- perf/x86/amd/core: Always use the NMI latency mitigation (Sandipan Das)
- vhost: fix vhost_get_avail_idx for a non empty ring (Michael S. Tsirkin) [Orabug: 39886543] {CVE-2026-74356}
- bpftool: Use libbpf error code for flow dissector query (Woojin Ji)
- drm/amdgpu: set sub_block_index for mca ras sub-blocks (Yunxiang Li)
- configfs_lookup(): don't leave ->s_dentry dangling on failure (Al Viro) [Orabug: 39886547] {CVE-2026-74359}
- lib/test_meminit: use && for bools (Alexander Potapenko)
- tick/sched: Fix TOCTOU in nohz idle time fetch (Frederic Weisbecker)
- driver core: Use system_percpu_wq instead of system_wq (Nathan Chancellor)
- sched: restore timer_slack_ns when resetting RT policy on fork (Guanyou Chen)
- ext2: fix ignored return value of generic_write_sync() (Danila Chernetsov) [Orabug: 39886553] {CVE-2026-74362}
- mm/fake-numa: fix under-allocation detection in uniform split (Sang-Heon Jeon)
- bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs (Deepanshu Kartikey) [Orabug: 39886555] {CVE-2026-74363}
- scsi: ufs: Fix wrong value printed in unexpected UPIU response case (Chanwoo Lee)
- scsi: pm8001: Fix error code in non_fatal_log_show() (Dan Carpenter)
- scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans" (Martin Wilck)
- nvdimm/btt: Handle preemption in BTT lane acquisition (Alison Schofield) [Orabug: 39886559] {CVE-2026-74365}
- ARM: imx31: Fix IIM mapping leak in revision check (Yuho Choi)
- ata: libata: Fix ata_exec_internal() (Bart Van Assche)
- HID: wiimote: Fix table layout and whitespace errors (Jonathan Neuschäfer)
- ARM: imx3: Fix CCM node reference leak (Yuho Choi)
- NFSD: Fix delegation reference leak in nfsd4_revoke_states (Chuck Lever)
- ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble (John Madieu)
- ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback (Zhang Yi)
- md/raid10: reset read_slot when reusing r10bio for discard (Chen Cheng) [Orabug: 39886580] {CVE-2026-74376}
- rpmsg: use generic driver_override infrastructure (Danilo Krummrich)
- Drivers: hv: vmbus: use generic driver_override infrastructure (Danilo Krummrich) [Orabug: 39973277] {CVE-2026-80676}
- cdx: use generic driver_override infrastructure (Danilo Krummrich)
- amba: use generic driver_override infrastructure (Danilo Krummrich)
- media: qcom: venus: relax encoder frame/blur step size on v6 (Renjiang Han)
- media: qcom: venus: relax encoder frame/blur dimension steps on v4 (Renjiang Han)
- media: qcom: venus: drop extra padding in NV12 raw size calculation (Renjiang Han)
- RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path (Tristan Madani) [Orabug: 39886583] {CVE-2026-74377}
- RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (Tristan Madani) [Orabug: 39886587] {CVE-2026-74378}
- EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info (Zhoumin)
- drm/msm/dp: Fix the ISR_* enum values (Jessica Zhang)
- drm/msm/dp: fix HPD state status bit shift value (Jessica Zhang)
- sched/deadline: Reject debugfs dl_server writes for offline CPUs (Andrea Righi)
- sched/deadline: Always stop dl-server before changing parameters (Juri Lelli)
- crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm (Herbert Xu)
- crypto: tegra - Fix dma_free_coherent size error (Herbert Xu)
- crypto: hisilicon/qm - disable error report before flr (Weili Qian)
- ocfs2: kill osb->system_file_mutex lock (Tetsuo Handa)
- ocfs2: don't BUG_ON an invalid journal dinode (Zhengyuan Huang) [Orabug: 39973185] {CVE-2026-80644}
- rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() (Dan Carpenter)
- dax/kmem: account for partial discontiguous resource upon removal (Davidlohr Bueso) [Orabug: 39886591] {CVE-2026-74379}
- libbpf: Fix UAF in strset__add_str() (Carlos Llamas)
- bpftool: Fix typo in struct_ops map FD generation for light skeleton (Siddharth Nayyar)
- libbpf: Harden parse_vma_segs() path parsing (Michael Bommarito)
- drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (Timur Tabi)
- drm/tegra: Fix iommu_map_sgtable() return value check (Mikko Perttunen)
- gpu: host1x: Fix iommu_map_sgtable() return value check (Mikko Perttunen) [Orabug: 39886594] {CVE-2026-74380}
- drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (Felix Gu)
- gpu: host1x: Allow entries in BO caches to be freed (Mikko Perttunen) [Orabug: 39886597] {CVE-2026-74381}
- drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove (Ion Agorria)
- drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered (Svyatoslav Ryhel) [Orabug: 39982292] {CVE-2026-80883}
- net/sched: cls_bpf: prevent unbounded recursion in offload rollback (Jiayuan Chen) [Orabug: 39886600] {CVE-2026-74382}
- ipv6: guard against possible NULL deref in __in6_dev_stats_get() (Eric Dumazet) [Orabug: 39973194] {CVE-2026-80646}
- workqueue: drop spurious '*' from print_worker_info() fn declaration (Breno Leitao)
- nvme-multipath: fix flex array size in struct nvme_ns_head (Nilay Shroff) [Orabug: 39886605] {CVE-2026-74384}
- nvmet-tcp: fix page fragment cache leak in error path (Geliang Tang) [Orabug: 39886611] {CVE-2026-74386}
- pinctrl: cs42l43: Fix polarity on debounce (Charles Keepax)
- pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table (Joey Lu)
- ALSA: seq: midi: Serialize output teardown with event_input (Zhang Cen) [Orabug: 39886615] {CVE-2026-74387}
- mtd: spi-nor: Drop duplicate Kconfig dependency (Miquel Raynal)
- driver core: Guard deferred probe timeout extension with delayed_work_pending() (Danilo Krummrich)
- driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout() (Danilo Krummrich)
- mips: n64: add __iomem for writel call (Rosen Penev)
- mips: ralink: mt7621: add missing __iomem (Rosen Penev)
- MIPS: DEC: Remove do_IRQ() call indirection (Maciej W. Rozycki)
- MIPS: Fix big-endian stack argument fetching in o32 wrapper (Maciej W. Rozycki)
- PM: sleep: Use complete() in device_pm_sleep_init() (Jiakai Xu)
- RDMA/counter: Fix incorrect port index in rdma_counter_init() error cleanup (Tao Cui)
- RDMA/hns: Fix log flood after cmd_mbox failure (Wenglianfa)
- RDMA/hns: Fix warning in poll cq direct mode (Wenglianfa)
- IB/mlx4: Fix refcount leak in add_port() error path (Guangshuo Li)
- RDMA/rxe: Fix a use-after-free problem in rxe_mmap (Zhu Yanjun) [Orabug: 39839300] {CVE-2026-64582}
- RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (Jacob Moroni) [Orabug: 39886628] {CVE-2026-74390}
- bus: sunxi-rsb: Always check register address validity (Samuel Holland)
- RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (Shiraz Saleem)
- pwm: imx27: Fix variable truncation in .apply() (Ronaldo Nunez)
- cpufreq: conservative: Simplify frequency limit handling (Lifeng Zheng)
- cpufreq: Documentation: fix sampling_down_factor range (Pengjie Zhang)
- Revert "treewide: Fix probing of devices in DT overlays" (Saravana Kannan)
- driver core: Use mod_delayed_work to prevent lost deferred probe work (Zhang Yuwei)
- device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id() (Stepan Ionichev)
- tracing: Bound synthetic-field strings with seq_buf (Pengpeng Hou) [Orabug: 39886631] {CVE-2026-74391}
- arm64: dts: qcom: sm8650: Add power-domain and iface clk for ice node (Harshal Dev)
- arm64: dts: qcom: sm8450: Add power-domain and iface clk for ice node (Harshal Dev)
- arm64: dts: qcom: kodiak: Add power-domain and iface clk for ice node (Harshal Dev)
- arm64: dts: qcom: sc7180: Add power-domain and iface clk for ice node (Harshal Dev)
- firmware: arm_scmi: Fix OOB in scmi_power_name_get() (Geert Uytterhoeven)
- media: rockchip: rga: fix too small buffer size (Sven Püschel)
- net/sched: sch_drr: annotate data-races around cl->deficit (Eric Dumazet)
- regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions (Chen-Yu Tsai)
- bitops: use common function parameter names (Randy Dunlap)
- sysfs: clamp show() return value in sysfs_kf_read() (Greg Kroah-Hartman)
- firmware: arm_scmi: Read sensor config as 32-bit value (Sudeep Holla)
- staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy() (Jose A. Perez de Azpillaga)
- media: atomisp: gc2235: fix UAF and memory leak (Yuho Choi)
- media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() (Zilin Guan)
- selftests/mm: Fix resv_sz when parsing arm64 signal frame (Kevin Brodsky)
- selftests/bpf: Reject unsupported -k option in vmtest.sh (Roman Kvasnytskyi)
- drm/syncobj: Fix memory leak in drm_syncobj_find_fence() (Liviu Dudau) [Orabug: 39886636] {CVE-2026-74393}
- RDMA/hns: Initialize seqfile before creating file (Junxian Huang)
- RDMA/srpt: fix integer overflow in immediate data length check (Sara Venkatesh) [Orabug: 39886638] {CVE-2026-74394}
- RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (Prathamesh Deshpande) [Orabug: 39886642] {CVE-2026-74395}
- RDMA/hns: Fix arithmetic overflow in calc_hem_config() (Alexander Chesnokov)
- IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier (Prathamesh Deshpande) [Orabug: 39886648] {CVE-2026-74397}
- ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD (Linmao Li) [Orabug: 39886652] {CVE-2026-74398}
- net/sched: sch_htb: annotate data-races (I) (Eric Dumazet)
- net/sched: sch_htb: do not change sch->flags in htb_dump() (Eric Dumazet)
- spi: hisi-kunpeng: Use dev_err_probe() for host registration failure (Maqiang)
- crypto: ccp - Treat zero-length cert chain as query for blob lengths (Sean Christopherson) [Orabug: 39973214] {CVE-2026-80652}
- net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats() (Eric Dumazet)
- clk: scpi: Unregister child clock providers on remove (Stepan Ionichev)
- thermal: hwmon: Fix critical temperature attribute removal (Rafael J. Wysocki)
- evm: terminate and bound the evm_xattrs read buffer (Pengpeng Hou) [Orabug: 39886656] {CVE-2026-74399}
- drm/hisilicon/hibmc: use clock to look up the PLL value (Lin He)
- drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (Lin He)
- arm64: dts: qcom: sm8450: Fix ICE reg size (Kuldeep Singh)
- arm64: dts: qcom: kodiak: Fix ICE reg size (Kuldeep Singh)
- clk: scmi: Fix clock rate rounding (Cristian Marussi)
- rust: alloc: fix Vec::extend_with SAFETY comment (Hsiu Che Yu)
- arm64: dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to host (Chen-Yu Tsai)
- iommu/amd: Fix a stale comment about which legacy mode is user visible (Sean Christopherson)
- media: qcom: camss: vfe: fix PIX subdev naming on VFE lite (Wenmeng Liu)
- nilfs2: fix backing_dev_info reference leak (Shuangpeng Bai)
- dlm: fix add msg handle in send_queue ordered (Alexander Aring) [Orabug: 39886661] {CVE-2026-74401}
- ARM: multi_v7_defconfig: Correct QCOM_RPMH and QCOM_RPMHPD (Krzysztof Kozlowski)
- crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (Weiming Shi) [Orabug: 39794400] {CVE-2026-64544}
- crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (Thorsten Blum)
- crypto: atmel-sha204a - fix blocking and non-blocking rng logic (Lothar Rubusch)
- crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (Tycho Andersen) [Orabug: 39886669] {CVE-2026-74404}
- vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). (Kuniyuki Iwashima) [Orabug: 39886675] {CVE-2026-74406}
- arm64: dts: imx8x-colibri: Correct SODIMM PAD settings (Peng Fan)
- arm64: dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc (Weixin Guo)
- drm/gpuvm: take refcount on DRM device (Alice Ryhl)
- pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path (Felix Gu)
- crypto: qat - fix heartbeat error injection (Damian Muszynski)
- memory: tegra: Wire up system sleep PM ops (Ashish Mhetre)
- media: v4l2-common: Add YUV24 format info (Nas Chung)
- media: cedrus: Fix failure to clean up hardware on probe failure (Samuel Holland)
- watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (Felix Gu)
- watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5 (Balakrishnan Sambath)
- watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (Gao Yingjie)
- ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint (Jihed Chaibi)
- wifi: ath9k: fix OOB access from firmware tx status queue ID (Tristan Madani) [Orabug: 39886681] {CVE-2026-74408}
- soc: xilinx: Shutdown and free rx mailbox channel (Prasanna Kumar T S M) [Orabug: 39973222] {CVE-2026-80654}
- kconfig: fix potential NULL pointer dereference in conf_askvalue (Xingjing Deng)
- wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (Tristan Madani) [Orabug: 39886686] {CVE-2026-74410}
- wifi: rtw89: Correct data type for scan index to avoid infinite loop (Shin-Yi Lin) [Orabug: 39886690] {CVE-2026-74411}
- driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (Danilo Krummrich) [Orabug: 39973281] {CVE-2026-80677}
- drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (Srinivasan Shanmugam) [Orabug: 39982260] {CVE-2026-80870}
- dt-bindings: pinctrl: nvidia,tegra234: Add missing required block (Krzysztof Kozlowski)
- arm64: tegra: Fix Tegra234 MGBE PTP clock (Jonathan Hunter)
- wifi: cfg80211: fix grammar in MLO group key error message (Louis Kotze)
- arm64: dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg warning (Krzysztof Kozlowski)
- arm64: dts: qcom: sc8180x: Fix phy simple_bus_reg warning (Krzysztof Kozlowski)
- arm64: dts: rockchip: Fix gmac0 reset pin for NanoPi R5S (Diederik de Haas)
- Documentation: proc: fix section numbering in table of contents (Baolin Liu)
- selftests/bpf: Use local type for bpf_fou_encap in test_tunnel_kern (Gregory Bell)
- selftests/bpf: Use local type for flow_offload_tuple_rhash in xdp_flowtable (Gregory Bell)
- drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro (Yang Wang)
- libbpf: Report error when a negative kprobe offset is specified (Aaron Tomlin)
- drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (Yuho Choi) [Orabug: 39886697] {CVE-2026-74416}
- drm/radeon: fix integer overflow in radeon_align_pitch() (Werner Kasselman) [Orabug: 39886702] {CVE-2026-74417}
- drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (Werner Kasselman)
- drm/gpuvm: Do not prepare NULL objects (Jonathan Cavitt)
- drm/tidss: Drop extra drm_mode_config_reset() call (Tomi Valkeinen)
- drm/rockchip: Test for imported buffers with drm_gem_is_imported() (Thomas Zimmermann)
- clocksource/drivers/sun5i: Handle error returns from devm_reset_control_get_optional_exclusive() (Chen Ni)
- fbcon: fix NULL pointer dereference for a console without vc_data (Ian Bridges) [Orabug: 39886713] {CVE-2026-74424}
- afs: Fix further netns teardown to cancel the preallocation charger (David Howells)
- afs: fix NULL pointer dereference in afs_get_tree() (Matvey Kovalev) [Orabug: 39886719] {CVE-2026-74426}
- afs: Fix netns teardown to cancel the preallocation charger (David Howells) [Orabug: 39886723] {CVE-2026-74427}
- rxrpc: Fix leak of released call in recvmsg(MSG_PEEK) (David Howells) [Orabug: 39886731] {CVE-2026-74432}
- rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc (Jeffrey E Altman) [Orabug: 39887263] {CVE-2026-74435}
- serial: 8250_omap: clear rx_running on zero-length DMA completes (Matthias Feser)
- serial: max310x: implement gpio_chip::get_direction() (Tapio Reijonen)
- serial: msm: Disable DMA for kernel console UART (Stephan Gerhold) [Orabug: 39982301] {CVE-2026-80886}
- dt-bindings: power: imx93: Add MIPI PHY power domain (Guoniu Zhou)
- dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties (Chen-Yu Tsai)
- media: uvcvideo: Fix sequence number when no EOF (Ricardo Ribalda)
- media: uvcvideo: Relax the constrains for interpolating the hw clock (Ricardo Ribalda)
- media: uvcvideo: Do not add clock samples with small sof delta (Ricardo Ribalda)
- media: uvcvideo: Fix dev_sof filtering in hw timestamp (Ricardo Ribalda)
- media: uvcvideo: Fix buffer sequence in frame gaps (Ricardo Ribalda)
- media: uvcvideo: Avoid partial metadata buffers (Ricardo Ribalda)
- media: uvcvideo: Use hw timestaming if the clock buffer is full (Ricardo Ribalda)
- time/jiffies: Change register_refined_jiffies() to void __init (Su Hui)
- time/jiffies: Register jiffies clocksource before usage (Thomas Gleixner) [Orabug: 39859302] {CVE-2026-68092}
- crypto: hisi-trng - Remove crypto_rng interface (Eric Biggers)
- crypto: crypto4xx - Remove insecure and unused rng_alg (Eric Biggers)
- crypto: crypto4xx - Remove ahash-related code (Herbert Xu)
- af_unix: Drop all SCM attributes for SOCKMAP. (Kuniyuki Iwashima) [Orabug: 39621760] {CVE-2026-53005}
- af_unix: Don't use skb_recv_datagram() in unix_stream_read_skb(). (Kuniyuki Iwashima)
- af_unix: Don't check SOCK_DEAD in unix_stream_read_skb(). (Kuniyuki Iwashima)
- af_unix: Don't hold unix_state_lock() in __unix_dgram_recvmsg(). (Kuniyuki Iwashima)
- af_unix/scm: fix whitespace errors (Alexander Mikhalitsyn)
- af_unix: Set drop reason in unix_stream_read_skb(). (Kuniyuki Iwashima)
- af_unix: Set drop reason in manage_oob(). (Kuniyuki Iwashima)
- af_unix: Set drop reason in unix_release_sock(). (Kuniyuki Iwashima)
- net: dropreason: Gather SOCKET_ drop reasons. (Kuniyuki Iwashima)
- x86/mm: Fix check/use ordering in switch_mm_irqs_off() (Stephen Dolan)
- iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (Vasant Hegde)
- iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (Vasant Hegde)
- crypto: sun4i-ss - Remove insecure and unused rng_alg (Eric Biggers)
- vsock/virtio: bind uarg before filling zerocopy skb (Jingguo Tan) [Orabug: 39754453] {CVE-2026-63970}
- vsock/virtio: fix zerocopy completion for multi-skb sends (Stefano Garzarella) [Orabug: 39727131] {CVE-2026-53365}
- nvmet-tcp: Fix potential UAF when ddgst mismatch (Sagi Grimberg) [Orabug: 39789576] {CVE-2026-64535}
- nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (Shivam Kumar) [Orabug: 39789572] {CVE-2026-64534}
- timekeeping: Register default clocksource before taking tk_core.lock (Mikhail Gavrilov)
- iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry (Michael Bommarito) [Orabug: 39886745] {CVE-2026-74439}
- iommu/vt-d: Cleanup intel_context_flush_present() (Lu Baolu)
- KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (Hyunwoo Kim) [Orabug: 39785845] {CVE-2026-64286}
- KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (Hyunwoo Kim) [Orabug: 39785848] {CVE-2026-64287}
- crypto: algif_skcipher - force synchronous processing (Muhammet Kaan Kilinç) [Orabug: 40054415] {CVE-2026-74578}
- sched/fair: Only update stats for allowed CPUs when looking for dst group (Adam Li)
- bpf: Prefer dirty packs for eBPF allocations (Pawan Gupta)
- bpf: Prefer packs that won't trigger an IBPB flush on allocation (Pawan Gupta)
- bpf: Skip redundant IBPB in pack allocator (Pawan Gupta)
- bpf: Restrict JIT predictor flush to cBPF (Pawan Gupta)
- bpf: Support for hardening against JIT spraying (Pawan Gupta) [Orabug: 39786495] {CVE-2026-64508}
- tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). (Kuniyuki Iwashima) [Orabug: 39637728] {CVE-2026-53260}
- iommu/vt-d: Clear Present bit before tearing down context entry (Lu Baolu) [Orabug: 39451910] {CVE-2026-45944}
- smb/server: do not require delete access for non-replacing links (Chenxiaosong)
- LTS version: v6.12.96 (Sherry Yang)
- xfs: don't zap bmbt forks if they are MAXLEVELS tall (Darrick J. Wong)
- xfs: fully check the parent handle when it points to the rootdir (Darrick J. Wong)
- xfs: clamp timestamp nanoseconds correctly (Darrick J. Wong)
- xfs: set xfarray killable sort correctly (Darrick J. Wong)
- xfs: don't wrap around quota ids in dqiterate (Darrick J. Wong) [Orabug: 39785773] {CVE-2026-64256}
- xfs: fail recovery on a committed log item with no regions (Weiming Shi) [Orabug: 39760869] {CVE-2026-64187}
- xfs: fix null pointer dereference in tracepoint (Andrey Albershteyn)
- smb: client: reject overlapping data areas in SMB2 responses (Shoichiro Miyamoto) [Orabug: 39838902] {CVE-2026-64257}
- usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks (Neill Kapron)
- fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req (Ji'An Zhou) [Orabug: 39785783] {CVE-2026-64265}
- fuse: re-lock request before returning from fuse_ref_folio() (Joanne Koong) [Orabug: 39785785] {CVE-2026-64266}
- fuse: fix device node leak in cuse_process_init_reply() (Alberto Ruiz)
- RDMA/siw: bound Read Response placement to the RREAD length (Michael Bommarito)
- RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg (Zhenhao Wan)
- Input: maplecontrol - set driver data before registering input device (Dmitry Torokhov)
- Input: maplemouse - set driver data before registering input device (Dmitry Torokhov)
- Input: maple_keyb - set driver data before registering input device (Dmitry Torokhov)
- Input: mms114 - fix multi-touch slot corruption (Dmitry Torokhov)
- Input: maplemouse - fix NULL pointer dereference in open() (Florian Fuchs)
- Input: mms114 - reject an oversized device packet size (Bryam Vargas) [Orabug: 39785797] {CVE-2026-64270}
- Input: touchwin - reset the packet index on every complete packet (Bryam Vargas) [Orabug: 39785801] {CVE-2026-64271}
- Input: mms114 - fix touch indexing for MMS134S and MMS136 (Dmitry Torokhov) [Orabug: 39785806] {CVE-2026-64272}
- Input: iforce - bound the device-reported force-feedback effect index (Bryam Vargas)
- Input: goodix - clamp the device-reported contact count (Bryam Vargas)
- Input: elan_i2c - prevent division by zero and arithmetic underflow (Ranjan Kumar) [Orabug: 39785818] {CVE-2026-64275}
- Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (Bryam Vargas) [Orabug: 39785822] {CVE-2026-64276}
- Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (Bryam Vargas)
- Input: synaptics-rmi4 - unregister function handlers on physical driver registration failure (Haoxiang Li)
- i2c: stm32f7: truncate clock period instead of rounding it (Guillermo Rodríguez)
- i2c: mpc: Fix timeout calculations (Andy Shevchenko)
- i2c: core: fix adapter deregistration race (Johan Hovold) [Orabug: 39785830] {CVE-2026-64279}
- i2c: core: fix adapter debugfs creation (Johan Hovold)
- i2c: core: fix adapter probe deferral loop (Johan Hovold)
- i2c: core: fix NULL-deref on adapter registration failure (Johan Hovold) [Orabug: 39843575] {CVE-2026-64589}
- i2c: core: fix irq domain leak on adapter registration failure (Johan Hovold)
- dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning (Mikhail Gavrilov)
- udmabuf: fix DMA direction mismatch in release_udmabuf() (Mikhail Gavrilov)
- KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (Sean Christopherson) [Orabug: 39843614] {CVE-2026-64604}
- KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits (Sean Christopherson) [Orabug: 39785842] {CVE-2026-64284}
- KVM: VMX: Refresh GUEST_PENDING_DBG_EXCEPTIONS.BS on all injected #DBs (Sean Christopherson)
- iommufd: Set upper bounds on cache invalidation entry_num and entry_len (Nicolin Chen) [Orabug: 39785851] {CVE-2026-64289}
- iommu/amd: Don't split flush for amd_iommu_domain_flush_all() (Weinan Liu)
- selftests/mm: pagemap_ioctl: use the correct page size for transact_test() (Zenghui Yu)
- mm: do file ownership checks with the proper mount idmap (Pedro Falcato) [Orabug: 39785858] {CVE-2026-64294}
- selftests: mm: fix and speedup "droppable" test (David Hildenbrand)
- mm: fix mmap errno value when MAP_DROPPABLE is not supported (Anthony Yznaga)
- riscv: mm: Unconditionally sfence.vma for spurious fault (Vivian Wang)
- NTB: epf: Fix request_irq() unwind in ntb_epf_init_isr() (Koichiro Den)
- exfat: bound uniname advance in exfat_find_dir_entry() (Bryam Vargas) [Orabug: 39785862] {CVE-2026-64296}
- module: decompress: check return value of module_extend_max_pages() (Andrii Kuchmenko)
- NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (Benjamin Coddington) [Orabug: 39785867] {CVE-2026-64298}
- audit: fix potential integer overflow in audit_log_n_hex() (Ricardo Robaina)
- tracing: Prevent out-of-bounds read in glob matching (Huihui Huang) [Orabug: 39785871] {CVE-2026-64299}
- i2c: core: fix hang on adapter registration failure (Johan Hovold)
- regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() (Xu Wang)
- watchdog: apple: Add "apple,t8103-wdt" compatible (Janne Grunau)
- EDAC/i10nm: Don't fail probing if ADXL is missing (Vasiliy Khoruzhick)
- spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (Carlos Song)
- spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (Carlos Song)
- arm64: fpsimd: Fix type mismatch in sme_{save,load}_state() (Mark Rutland)
- crypto: talitos/hash - fix SEC2 64k - 1 ahash request limitation (Paul Louvel)
- crypto: talitos/hash - remove useless wrapper (Paul Louvel)
- crypto: talitos/hash - rename first_desc/last_desc to first_request/last_request (Paul Louvel)
- crypto: talitos/hash - drop workqueue mechanism for SEC1 (Paul Louvel)
- crypto: talitos/hash - use descriptor chaining for SEC1 instead of workqueue (Paul Louvel)
- crypto: talitos/hash - prepare SEC1 descriptor chaining, remove additional descriptor (Paul Louvel)
- crypto: talitos - move code in current_desc_hdr() into a standalone function (Paul Louvel)
- crypto: talitos - move dma mapping code in talitos_submit() into a standalone dma_map_request() function (Paul Louvel)
- crypto: talitos - move dma unmapping code in flush_channel() into a standalone dma_unmap_request() function (Paul Louvel)
- crypto: talitos - add chaining of arbitrary number of descriptor for the SEC1 (Paul Louvel)
- crypto: talitos - use dma_sync_single_for_cpu() before reading descriptor header (Paul Louvel)
- crypto: qat - validate RSA CRT component lengths (Giovanni Cabiddu) [Orabug: 39785884] {CVE-2026-64304}
- crypto: qat - protect service table iterations with service_lock (Ahsan Atta) [Orabug: 39785888] {CVE-2026-64305}
- crypto: qat - notify fatal error before AER reset preparation (Ahsan Atta)
- crypto: qat - keep VFs enabled during reset (Ahsan Atta)
- crypto: drbg - Fix the fips_enabled priority boost (Eric Biggers)
- crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (Eric Biggers)
- crypto: drbg - Fix returning success on failure in CTR_DRBG (Eric Biggers) [Orabug: 39785892] {CVE-2026-64306}
- crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD) (Tycho Andersen) [Orabug: 39785898] {CVE-2026-64308}
- crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT) (Tycho Andersen) [Orabug: 39785900] {CVE-2026-64309}
- crypto: ccp - Do not initialize SNP for SEV ioctls (Tycho Andersen) [Orabug: 39785902] {CVE-2026-64310}
- crypto: tegra - fix refcount leak in tegra_se_host1x_submit() (Xu Wang)
- crypto: pcrypt - restore callback for non-parallel fallback (Ruijie Li) [Orabug: 39785905] {CVE-2026-64312}
- crypto: ecc - Fix carry overflow in vli multiplication (Anastasia Tishchenko) [Orabug: 39785909] {CVE-2026-64313}
- crypto: caam - use print_hex_dump_devel to guard key hex dumps again (Thorsten Blum)
- crypto: caam - use print_hex_dump_devel to guard key hex dumps (Thorsten Blum)
- crypto: af_alg - Remove zero-copy support from skcipher and aead (Eric Biggers)
- isofs: bound Rock Ridge symlink components to the SL record (Bryam Vargas) [Orabug: 39785922] {CVE-2026-64317}
- partitions: aix: bound the pp_count scan to the ppe array (Bryam Vargas)
- btrfs: do not trim a device which is not writeable (Qu Wenruo) [Orabug: 39843585] {CVE-2026-64593}
- nvmet-auth: validate reply message payload bounds against transfer length (Tianchu Chen) [Orabug: 39785930] {CVE-2026-64319}
- nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (Bryam Vargas) [Orabug: 39785933] {CVE-2026-64320}
- nvme-multipath: set BIO_REMAPPED on bios remapped to per-path namespace disks (Igor Achkinazi)
- dm-ioctl: report an error if a device has no table (Mikulas Patocka)
- nvme: target: rdma: fix ndev refcount leak on queue connect (Xu Wang) [Orabug: 39785937] {CVE-2026-64321}
- hwrng: jh7110 - fix refcount leak in starfive_trng_read() (Xu Wang)
- udf: validate sparing table length as an entry count, not a byte count (Bryam Vargas) [Orabug: 39785939] {CVE-2026-64322}
- udf: validate VAT header length against the VAT inode size (Bryam Vargas) [Orabug: 39785943] {CVE-2026-64323}
- udf: validate free block extents against the partition length (Michael Bommarito) [Orabug: 39785947] {CVE-2026-64324}
- x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled (Reinette Chatre) [Orabug: 39786413] {CVE-2026-64477}
- block: skip sync_blockdev() on surprise removal in bdev_mark_dead() (Chao Shi) [Orabug: 39785953] {CVE-2026-64326}
- usb: gadget: f_fs: Fix DMA fence leak (Paul Cercueil)
- usb: typec: ucsi: cancel pending work on system suspend (Paul Menzel)
- usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (Fan Wu)
- usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (Madhu M)
- usb: typec: ucsi: Invert DisplayPort role assignment (Andrei Kuchynski)
- usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (Badhri Jagan Sridharan) [Orabug: 39785962] {CVE-2026-64330}
- usb: typec: tcpm: Fix VDM type for Enter Mode commands (Andy Yan)
- usb: typec: class: drop PD lookup reference (Shuangpeng Bai)
- usb: typec: anx7411: use devm_pm_runtime_enable() (Myeonghun Pak)
- usbip: vudc: fix NULL deref in vep_dequeue() (Sam Day)
- usbip: tools: support SuperSpeedPlus devices (Chenyichong)
- USB: usb-storage: ene_ub6250: restore media-ready check (Xu Rao)
- USB: ulpi: fix memory leak on registration failure (Johan Hovold) [Orabug: 39785970] {CVE-2026-64332}
- USB: serial: digi_acceleport: fix write buffer corruption (Johan Hovold) [Orabug: 39785974] {CVE-2026-64333}
- USB: serial: digi_acceleport: fix hard lockup on disconnect (Johan Hovold) [Orabug: 39785978] {CVE-2026-64334}
- USB: serial: digi_acceleport: fix broken rx after throttle (Johan Hovold) [Orabug: 39785982] {CVE-2026-64335}
- USB: serial: option: add Telit Cinterion FE990D50 compositions (Fabio Porcedda)
- USB: serial: keyspan_pda: fix information leak (Johan Hovold) [Orabug: 39785986] {CVE-2026-64336}
- usb: mtu3: unmap request DMA on queue failure (Haoxiang Li)
- USB: misc: uss720: unregister parport on probe failure (Myeonghun Pak) [Orabug: 39785993] {CVE-2026-64338}
- USB: storage: include US_FL_NO_SAME in quirks mask (Xu Rao)
- usb: sl811-hcd: disable controller wakeup on remove (Myeonghun Pak)
- USB: legousbtower: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39785998] {CVE-2026-64340}
- USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD (Erich E. Hoover)
- USB: iowarrior: fix use-after-free on disconnect (Johan Hovold) [Orabug: 39786006] {CVE-2026-64342}
- USB: ldusb: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39786011] {CVE-2026-64343}
- USB: idmouse: fix use-after-free on disconnect race (Johan Hovold) [Orabug: 39786016] {CVE-2026-64344}
- usb: gadget: f_printer: take kref only for successful open (Xu Rao)
- usb: gadget: udc: Fix use-after-free in gadget_match_driver (Jimmy Hu)
- usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (Maoyi Xie)
- usb: free iso schedules on failed submit (Dawei Feng) [Orabug: 39786033] {CVE-2026-64348}
- usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (Xu Wang)
- USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub (Rodrigo Lugathe Da Conceição Alves)
- usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (Haoxiang Li)
- usb: cdc_acm: Add quirk for Uniden BC125AT scanner (Jared Baldridge)
- net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() (Maoyi Xie) [Orabug: 39786041] {CVE-2026-64351}
- bpf: Validate BTF repeated field counts before expansion (Paul Moses) [Orabug: 39786049] {CVE-2026-64354}
- bpf: Restore sysctl new-value from 1 to 0 (Dawei Feng)
- bpf: Reject fragmented frames in devmap (Zhao Zhang) [Orabug: 39786051] {CVE-2026-64355}
- xfs: fix exchmaps reservation limit check (Gao Yingjie) [Orabug: 39786055] {CVE-2026-64357}
- xfs: fix pointer arithmetic error on 32-bit systems (Darrick J. Wong)
- xfs: fix unreachable BIGTIME check in dquot flush validation (Alexey Nepomnyashih)
- xfs: release dquot buffer after dqflush failure (Gao Yingjie)
- xfs: use null daddr for unset first bad log block (Yousef Alhouseen)
- serial: 8250_mid: Disable DMA for selected platforms (Andy Shevchenko)
- media: mtk-jpeg: cancel workqueue on release for supported platforms only (Louis-Alexis Eyraud)
- nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers (Deepanshu Kartikey)
- hfs/hfsplus: zero-initialize buffer in hfs_bnode_read (Tristan Madani)
- HID: sensor-hub: Add sensor_hub_input_attr_read_values() for multi-byte reads (Srinivas Pandruvada)
- HID: lg-g15: cancel pending work on remove to fix a use-after-free (Maoyi Xie) [Orabug: 39786070] {CVE-2026-64362}
- HID: letsketch: fix UAF on inrange_timer at driver unbind (Manish Khadka) [Orabug: 39786080] {CVE-2026-64365}
- HID: wacom: stop hardware after post-start probe failures (Myeonghun Pak) [Orabug: 39859298] {CVE-2026-68091}
- HID: hid-goodix-spi: validate report size to prevent stack buffer overflow (Tianchu Chen)
- tools/mm/slabinfo: fix total_objects attribute name (Chenyichong)
- tools/mm/slabinfo: Fix trace disable logic inversion (Xuewen Wang)
- mm/slab: do not limit zeroing to orig_size when only red zoning is enabled (Vlastimil Babka) [Orabug: 39786085] {CVE-2026-64368}
- X.509: Fix validation of ASN.1 certificate header (Lukas Wunner)
- perf/arm-cmn: Fix DVM node events (Robin Murphy)
- clocksource/drivers/timer-tegra186: Fix support for multiple watchdog instances (Kartik)
- posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path (Xu Wang) [Orabug: 39786090] {CVE-2026-64370}
- cpufreq: pcc: fix use-after-free and double free in _OSC evaluation (Yuho Choi) [Orabug: 39786099] {CVE-2026-64372}
- cpufreq: Fix hotplug-suspend race during reboot (Tianxiang Chen) [Orabug: 39786103] {CVE-2026-64373}
- sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT (Steven Rostedt) [Orabug: 39786107] {CVE-2026-64374}
- cpufreq: intel_pstate: Sync policy->cur during CPU offline (Wangfushuai)
- firmware_loader: fix device reference leak in firmware_upload_register() (Guangshuo Li) [Orabug: 39786115] {CVE-2026-64376}
- cpufreq: qcom-cpufreq-hw: Fix possible double free (Guangshuo Li)
- OPP: of: Fix potential memory leak in opp_parse_supplies() (Abdun Nihaal)
- writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() (Baokun Li) [Orabug: 39786119] {CVE-2026-64378}
- smb: client: mask server-provided mode to 07777 in modefromsid (Norbert Manthey) [Orabug: 39786123] {CVE-2026-64379}
- smb: client: fix atime clamp check in read completion (Xu Rao)
- smb: client: harden POSIX SID length parsing (Zihan Xi) [Orabug: 39786127] {CVE-2026-64380}
- smb: client: use unaligned reads in parse_posix_ctxt() (Zihan Xi)
- smb: client: Fix next buffer leak in receive_encrypted_standard() (Haoxiang Li) [Orabug: 39786130] {CVE-2026-64381}
- smb: client: fix double-free in SMB2_close() replay (Henrique Carvalho) [Orabug: 39843598] {CVE-2026-64597}
- smb: client: fix double-free in SMB2_open() replay (Henrique Carvalho) [Orabug: 39786135] {CVE-2026-64382}
- smb: client: fix double-free in SMB2_flush() replay (Zhao Zhang) [Orabug: 39786137] {CVE-2026-64383}
- smb: client: fix change notify replay double-free (Henrique Carvalho) [Orabug: 39786139] {CVE-2026-64384}
- smb: client: fix double-free in SMB2_ioctl() replay (Henrique Carvalho) [Orabug: 39786141] {CVE-2026-64385}
- smb: client: fix query_info() replay double-free (Henrique Carvalho) [Orabug: 39786143] {CVE-2026-64386}
- smb: client: fix query directory replay double-free (Henrique Carvalho) [Orabug: 39786145] {CVE-2026-64387}
- ksmbd: use opener credentials for ADS I/O (Namjae Jeon)
- ksmbd: use opener credentials for delete-on-close (Namjae Jeon)
- ksmbd: add per-handle permission check to FILE_LINK_INFORMATION (Gil Portnoy)
- ksmbd: enforce FILE_READ_ATTRIBUTES on SMB_FIND_FILE_POSIX_INFORMATION (Gil Portnoy)
- ksmbd: run set info with opener credentials (Namjae Jeon)
- ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY (Gil Portnoy)
- ksmbd: require source read access for duplicate extents (Namjae Jeon)
- ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation (Davide Ornaghi)
- ksmbd: serialize QUERY_DIRECTORY requests per file (Namjae Jeon) [Orabug: 39786183] {CVE-2026-64397}
- ksmbd: add a permission check for FSCTL_SET_ZERO_DATA (Gil Portnoy)
- ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE (Gil Portnoy)
- smb/client: Fix error code in smb2_aead_req_alloc() (Dan Carpenter) [Orabug: 39843601] {CVE-2026-64598}
- coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer() (Junrui Luo)
- fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked() (Deepanshu Kartikey)
- fs/ntfs3: zero-fill folios beyond i_valid in ntfs_read_folio() (Konstantin Komarov)
- fs/ntfs3: fsync files by syncing parent inodes (Konstantin Komarov)
- fs/ntfs3: rename ni_readpage_cmpr into ni_read_folio_cmpr (Konstantin Komarov)
- Bluetooth: L2CAP: validate option length before reading conf opt value (Muhammad Bilal) [Orabug: 39786204] {CVE-2026-64403}
- Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() (Muhammad Bilal) [Orabug: 39786209] {CVE-2026-64404}
- Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (Pauli Virtanen) [Orabug: 39860413] {CVE-2026-68085}
- Bluetooth: fix UAF in bt_accept_dequeue() (Yousef Alhouseen) [Orabug: 39786577] {CVE-2026-64406}
- Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() (Maoyi Xie)
- Bluetooth: bnep: pin L2CAP connection during netdev registration (Yousef Alhouseen) [Orabug: 39786216] {CVE-2026-64408}
- Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (Sergey Senozhatsky)
- netfilter: ebtables: terminate table name before find_table_lock() (Xiang Mei) [Orabug: 39786223] {CVE-2026-64411}
- netfilter: ebtables: module names must be null-terminated (Florian Westphal) [Orabug: 39786227] {CVE-2026-64412}
- netfilter: handle unreadable frags (Florian Westphal) [Orabug: 39786235] {CVE-2026-64414}
- netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump (Pratham Gupta)
- mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup (Zijiang Huang) [Orabug: 39786237] {CVE-2026-64415}
- mm: shrinker: fix NULL pointer dereference in debugfs (Qi Zheng)
- mm: shrinker: fix shrinker_info teardown race with expansion (Qi Zheng) [Orabug: 39786243] {CVE-2026-64418}
- mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show() (Shakeel Butt)
- mfd: cros_ec: Delay dev_set_drvdata() until probe success (Andrei Kuchynski) [Orabug: 39786247] {CVE-2026-64420}
- net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes (Wyatt Feng) [Orabug: 39786253] {CVE-2026-64422}
- ipv4: igmp: remove multicast group from hash table on device destruction (Yuyang Huang) [Orabug: 39786258] {CVE-2026-64423}
- netpoll: fix a use-after-free on shutdown path (Breno Leitao) [Orabug: 39786263] {CVE-2026-64424}
- io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item (Runyu Xiao) [Orabug: 39786573] {CVE-2026-64425}
- gpio: eic-sprd: use raw_spinlock_t in the irq startup path (Runyu Xiao)
- NTB: epf: Avoid calling pci_irq_vector() from hardirq context (Koichiro Den)
- fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns (Yunpeng Tian)
- debugobjects: Plug race against a concurrent OOM disable (Thomas Gleixner)
- coresight: etb10: restore atomic_t for shared reading state (Runyu Xiao)
- Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (Samuel Page) [Orabug: 39786285] {CVE-2026-64433}
- audit: Fix data races of skb_queue_len() readers on audit_queue (Chi Wang) [Orabug: 39786288] {CVE-2026-64435}
- net: af_key: initialize alg_key_len for IPComp states (Zijing Yin) [Orabug: 39786292] {CVE-2026-64436}
- ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL (Gil Portnoy)
- crypto: amlogic - avoid double cleanup in meson_crypto_probe() (Dawei Feng) [Orabug: 39843603] {CVE-2026-64599}
- staging: rtl8723bs: fix OOB write in HT_caps_handler() (Alexandru Hossu)
- staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (Alexandru Hossu)
- staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (Alexandru Hossu)
- staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (Alexandru Hossu)
- staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (Alexandru Hossu)
- staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (Alexandru Hossu)
- staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie() (Alexandru Hossu)
- staging: media: atomisp: reduce load_primary_binaries() stack usage (Arnd Bergmann)
- media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe (Ricardo Ribalda)
- staging: vme_user: fix location monitor leak in tsi148 bridge (Hao-Qun Huang)
- staging: vme_user: fix location monitor leak in fake bridge (Hao-Qun Huang)
- smb: client: restrict implied bcc[0] exemption to responses without data area (Shoichiro Miyamoto) [Orabug: 39786331] {CVE-2026-64448}
- staging: vme_user: bound slave read/write to the kern_buf size (Michael Tautschnig)
- tipc: fix out-of-bounds read in broadcast Gap ACK blocks (Samuel Page) [Orabug: 39786339] {CVE-2026-64450}
- 6lowpan: fix NHC entry use-after-free on error path (Yizhou Zhao) [Orabug: 39786343] {CVE-2026-64452}
- usb: dwc3: run gadget disconnect from sleepable suspend context (Runyu Xiao)
- USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (Alan Stern) [Orabug: 39786351] {CVE-2026-64455}
- hwrng: virtio: clamp device-reported used.len at copy_data() (Michael Bommarito) [Orabug: 39786355] {CVE-2026-64456}
- virtio-mmio: fix device release warning on module unload (Johan Hovold)
- netfilter: ipset: fix race between dump and ip_set_list resize (Xiang Mei) [Orabug: 39760881] {CVE-2026-64189}
- mm/damon/ops-common: handle extreme intervals in damon_hot_score() (Seongjae Park) [Orabug: 39786361] {CVE-2026-64458}
- PCI: imx6: Fix IMX6SX_GPR12_PCIE_TEST_POWERDOWN handling (Richard Zhu)
- PCI: host-common: Request bus reassignment when not probe-only (Ratheesh Kannoth)
- PCI: altera: Do not dispose parent IRQ mapping (Mahesh Vaidya)
- PCI: loongson: Override PCIe bridge supported speeds for Loongson-3C6000 series (Ziyao Li)
- usb: typec: tcpci_rt1711h: unregister TCPCI port with devres (Myeonghun Pak)
- usb: xhci: Fix sleep in atomic context in xhci_free_streams() (Lianqin Hu) [Orabug: 39786378] {CVE-2026-64465}
- binder: fix UAF in binder_free_transaction() (Carlos Llamas)
- binder: fix UAF in binder_thread_release() (Carlos Llamas)
- Bluetooth: btusb: fix wakeup source leak on probe failure (Johan Hovold)
- Bluetooth: btusb: fix use-after-free on marvell probe failure (Johan Hovold) [Orabug: 39786392] {CVE-2026-64470}
- Bluetooth: btusb: fix use-after-free on registration failure (Johan Hovold) [Orabug: 39786396] {CVE-2026-64471}
- Bluetooth: btusb: Add USB ID 2c4e:0128 for Mercusys MA60XNB (Zenm Chen)
- vfio: Remove device debugfs before releasing devres (Alex Williamson) [Orabug: 39786403] {CVE-2026-64473}
- vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc (Junrui Luo) [Orabug: 39786405] {CVE-2026-64474}
- vfio/pci: Fix racy bitfields and tighten struct layout (Alex Williamson)
- vfio/pci: Release the VGA arbiter client on register_device() failure (Alex Williamson) [Orabug: 39786408] {CVE-2026-64475}
- vfio/pci: Latch disable_idle_d3 per device (Alex Williamson) [Orabug: 39786411] {CVE-2026-64476}
- vfio/pci: Use a private flag to prevent power state change with VFs (Raghavendra Rao Ananta)
- ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (Cássio Gabriel)
- ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (Cássio Gabriel)
- ALSA: usb-audio: Roll back quirk control caches on write errors (Cássio Gabriel)
- ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (Cássio Gabriel)
- ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (Cássio Gabriel)
- ALSA: usb-audio: avoid kobject path lookup in DualSense match (Darvell Long) [Orabug: 39786415] {CVE-2026-64478}
- ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (Hyeongjun An) [Orabug: 39786419] {CVE-2026-64479}
- ALSA: ice1712: check snd_ctl_new1() return value (Zhao Dongdong) [Orabug: 39786421] {CVE-2026-64480}
- ALSA: gus: check snd_ctl_new1() return value (Zhao Dongdong)
- ALSA: firewire: isight: bound the sample count to the packet payload (Maoyi Xie)
- ALSA: es1938: check snd_ctl_new1() return value (Zhao Dongdong) [Orabug: 39786431] {CVE-2026-64484}
- ALSA: cmipci: check snd_ctl_new1() return value (Zhao Dongdong) [Orabug: 39786436] {CVE-2026-64486}
- ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (Maoyi Xie) [Orabug: 39786438] {CVE-2026-64487}
- ALSA: ymfpci: check snd_ctl_new1() return value (Zhao Dongdong) [Orabug: 39786446] {CVE-2026-64489}
- ALSA: virtio: Validate control metadata from the device (Cássio Gabriel) [Orabug: 39786448] {CVE-2026-64490}
- ALSA: virtio: Add missing 384 kHz PCM rate mapping (Cássio Gabriel)
- iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (Liviu Stan)
- iio: temperature: ltc2983: Fix n_wires default bypassing rotation check (Liviu Stan)
- iio: temperature: Build mlx90635 with CONFIG_MLX90635 (Pengpeng Hou)
- iio: resolver: ad2s1210: notify trigger and clear state on fault read error (Stepan Ionichev)
- iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (Andy Shevchenko)
- iio: light: veml6030: fix channel type when pushing events (Javier Carrasco)
- iio: light: tsl2591: return actual error from probe IRQ failure (Stepan Ionichev)
- iio: light: opt3001: fix missing state reset on timeout (Joshua Crofts)
- iio: light: gp2ap002: fix runtime PM leak on read error (Biren Pandya)
- iio: light: al3010: fix incorrect scale for the highest gain range (Vidhu Sarwal)
- iio: imu: st_lsm6dsx: deselect shub page before reading whoami (Andreas Kempe)
- iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading (Jean-Baptiste Maneyrol)
- iio: imu: inv_icm42600: fix timestamp clock period by using lower value (Jean-Baptiste Maneyrol)
- iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (Runyu Xiao)
- iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ (Runyu Xiao)
- iio: gyro: bmg160: wait full startup time after mode change at probe (Stepan Ionichev)
- iio: gyro: bmg160: bail out when bandwidth/filter is not in table (Stepan Ionichev)
- iio: event: Fix event FIFO reset race (Lars-Peter Clausen) [Orabug: 39786461] {CVE-2026-64496}
- iio: common: st_sensors: honour channel endianness in read_axis_data (Herman van Hazendonk)
- iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (Maxwell Doose)
- iio: backend: fix uninitialized data in debugfs (Dan Carpenter)
- iio: adc: ti-ads124s08: Return reset GPIO lookup errors (Pengpeng Hou)
- iio: adc: ti-ads1119: fix PM reference leak in buffer preenable (Guangshuo Li)
- iio: adc: spear: Initialize completion before requesting IRQ (Maxwell Doose)
- iio: adc: lpc32xx: Initialize completion before requesting IRQ (Maxwell Doose)
- iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (Biren Pandya) [Orabug: 39786477] {CVE-2026-64503}
- iio: accel: bmc150: clamp the device-reported FIFO frame count (Bryam Vargas) [Orabug: 39786481] {CVE-2026-64504}
- usb: gadget: function: rndis: add length check for header (Griffin Kroah-Hartman)
- usb: gadget: function: rndis: add length check to response query (Griffin Kroah-Hartman)
- drm/i915: ensure segment offset never exceeds allowed max (Krzysztof Karas)
- rust: kasan: KASAN+RUST requires clang (Alice Ryhl)
- perf/core: Detach event groups during remove_on_exec (Taeyang Lee) [Orabug: 39802877] {CVE-2026-64556}
- rust: Kbuild: set frame-pointer llvm module flag for CONFIG_FRAME_POINTER (Alice Ryhl)
- LoongArch: Add PIO for early access before ACPI PCI root register (Huacai Chen)
- platform/x86: intel-hid: Protect ACPI notify handler against recursion (Hyeongjun An) [Orabug: 39843612] {CVE-2026-64603}
- ACPI: NFIT: core: Fix possible NULL pointer dereference (Rafael J. Wysocki) [Orabug: 39786505] {CVE-2026-64511}
- ACPI: CPPC: Suppress UBSAN warning caused by field misuse (Jeremy Linton) [Orabug: 39786507] {CVE-2026-64512}
- perf trace beauty fcntl: Fix build with older kernel headers (Florian Fainelli)
- mm/khugepaged: write all dirty file folios when collapsing (Pedro Falcato) [Orabug: 40060378] {CVE-2026-68086}
- block: fix queue freeze vs limits lock order in sysfs store methods (Christoph Hellwig) [Orabug: 37650414] {CVE-2025-21807}
- block: add a store_limit operations for sysfs entries (Christoph Hellwig)
- bonding: fix xfrm offload feature setup on active-backup mode (Hangbin Liu)
- nfsd: change nfs4_client_to_reclaim() to allocate data (Neil Brown)
- nfsd: move name lookup out of nfsd4_list_rec_dir() (Neilbrown)
- apparmor: advertise the tcp fast open fix is applied (John Johansen)
- locking/rtmutex: Make sure we wake anything on the wake_q when we release the lock->wait_lock (John Stultz)
- NFSv4/flexfiles: reject zero filehandle version count (Michael Bommarito) [Orabug: 39753893] {CVE-2026-53392}
- NFSv4/flexfiles: Add data structure support for striped layouts (Jonathan Curley)
- NFSv4/flexfiles: Remove cred local variable dependency (Jonathan Curley)
- nfs_common: rename functions that invalidate LOCALIO nfs_clients (Mike Snitzer)
- nfsd: add nfsd_file_{get,put} to 'nfs_to' nfsd_localio_operations (Mike Snitzer)
- fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() (Mingyu Wang) [Orabug: 39753923] {CVE-2026-53402}
- f2fs: fix listxattr handling of corrupted xattr entries (Keshav Verma)
- f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs() (Chao Yu)
- f2fs: fix potential deadlock in f2fs_balance_fs() (Ruipeng Qi) [Orabug: 39884658] {CVE-2026-68460}
- f2fs: bound i_inline_xattr_size for non-inline-xattr inodes (Bryam Vargas)
- f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode (Chao Yu)
- f2fs: validate orphan inode entry count (Wenjie Qi)
- device property: initialize the remaining fields of fwnode_handle in fwnode_init() (Bartosz Golaszewski) [Orabug: 39884662] {CVE-2026-68461}
- mm/vmalloc: take vmap_purge_lock in shrinker (Uladzislau Rezki) [Orabug: 39452440] {CVE-2026-46093}
- gpio: rockchip: fix generic IRQ chip leak on remove (Marco Scardovi) [Orabug: 39637612] {CVE-2026-53226}
- gpio: rockchip: teardown bugs and resource leaks (Marco Scardovi) [Orabug: 39785165] {CVE-2026-64241}
- gpio: rockchip: change the GPIO version judgment logic (Ye Zhang)
- drm/amd: Fix set but not used warnings (Tiezhu Yang)
- bcachefs: avoid truncating fiemap extent length (Mikhail Dmitrichenko)
- perf: Fix dangling cgroup pointer in cpuctx backport (Guan Wentao)
- userfaultfd: gate must_wait writability check on pte_present() (Kiryl Shutsemau) [Orabug: 39786514] {CVE-2026-64514}
- nfsd: release layout stid on setlease failure (Chris Mason) [Orabug: 39753911] {CVE-2026-53399}
- nfsd: fix file change detection in CB_GETATTR (Scott Mayhew)
- bpf, arm64: Reject out-of-range B.cond targets (Daniel Borkmann)
- LTS version: v6.12.95 (Sherry Yang)
- bonding: do not set usable_slaves for broadcast mode (Hangbin Liu)
- bonding: annotate data-races arcound churn variables (Eric Dumazet)
- net: bonding: update the slave array for broadcast mode (Tonghao Zhang)
- locking: rtmutex: Fix wake_q logic in task_blocks_on_rt_mutex (John Stultz)
- net/tcp-ao: fix use-after-free of key in del_async path (Ji'An Zhou)
- crypto: qat - remove unused character device and IOCTLs (Giovanni Cabiddu) [Orabug: 39786548] {CVE-2026-64529}
- crypto: qat - Return pointer directly in adf_ctl_alloc_resources (Herbert Xu)
- crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (Thorsten Blum)
- Documentation: ioctl-number: Extend "Include File" column width (Bagas Sanjaya)
- Documentation: ioctl-number: Fix linuxppc-dev mailto link (Bagas Sanjaya)
- drivers/base/memory: set mem->altmap after successful device registration (Georgi Djakov) [Orabug: 39785174] {CVE-2026-64244}
- serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails (Stepan Ionichev) [Orabug: 39753867] {CVE-2026-53384}
- NFS: Prevent resource leak in nfs_alloc_server() (Markus Elfring)
- NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (Michael Bommarito) [Orabug: 39753889] {CVE-2026-53391}
- nfsd: reset write verifier on deferred writeback errors (Jeff Layton) [Orabug: 39753897] {CVE-2026-53393}
- nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race (Jeff Layton) [Orabug: 39753900] {CVE-2026-53394}
- nfsd: check get_user() return when reading princhashlen (Dominik Woźniak)
- nfsd: fix posix_acl leak on SETACL decode failure (Jeff Layton) [Orabug: 39753904] {CVE-2026-53397}
- NFSD: Fix SECINFO_NO_NAME decode error cleanup (Guannan Wang) [Orabug: 39753908] {CVE-2026-53398}
- i2c: core: fix adapter registration race (Johan Hovold) [Orabug: 39753915] {CVE-2026-53400}
- fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (Steffen Persvold)
- fbdev: modedb: fix a possible UAF in fb_find_mode() (Tuo Li) [Orabug: 39785177] {CVE-2026-64245}
- fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (Ian Bridges) [Orabug: 39753927] {CVE-2026-53403}
- riscv: kfence: Call mark_new_valid_map() for kfence_unprotect() (Vivian Wang)
- riscv: mm: Extract helper mark_new_valid_map() (Vivian Wang)
- power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (Xu Wang)
- KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (Ashutosh Desai) [Orabug: 39753935] {CVE-2026-63794}
- KVM: x86: hyper-v: Bound the bank index when querying sparse banks (Hyunwoo Kim) [Orabug: 39785185] {CVE-2026-64247}
- 9p: avoid putting oldfid in p9_client_walk() error path (Yizhou Zhao) [Orabug: 39753939] {CVE-2026-63795}
- ocfs2: reject oversized group bitmap descriptors (Zhang Cen) [Orabug: 39753941] {CVE-2026-63796}
- rpmsg: char: Fix use-after-free on probe error path (Yuho Choi)
- fpga: region: fix use-after-free in child_regions_with_firmware() (Xu Wang)
- irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove (Qingshuang Fu)
- pNFS: Fix use-after-free in pnfs_update_layout() (Xu Wang) [Orabug: 39753952] {CVE-2026-63800}
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Doruk Tan Ozturk) [Orabug: 39753956] {CVE-2026-63801}
- blk-cgroup: fix UAF in __blkcg_rstat_flush() (Michal Koutný) [Orabug: 39753959] {CVE-2026-63802}
- hdlc_ppp: sync per-proto timers before freeing hdlc state (Fan Wu) [Orabug: 39753962] {CVE-2026-63803}
- pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next() (Xu Wang) [Orabug: 39785195] {CVE-2026-64251}
- gfs2: fix use-after-free in gfs2_qd_dealloc (Tristan Madani) [Orabug: 39753966] {CVE-2026-63804}
- KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (Sean Christopherson) [Orabug: 39753971] {CVE-2026-63806}
- exfat: fix potential use-after-free in exfat_find_dir_entry() (Michael Bommarito) [Orabug: 39753978] {CVE-2026-63808}
- MIPS: DEC: Prevent initial console buffer from landing in XKPHYS (Maciej W. Rozycki)
- bpf: use kvfree() for replaced sysctl write buffer (Dawei Feng) [Orabug: 39753981] {CVE-2026-63809}
- block: Avoid mounting the bdev pseudo-filesystem in userspace (Denis Arefev) [Orabug: 39753984] {CVE-2026-63810}
- f2fs: keep atomic write retry from zeroing original data (Wenjie Qi)
- f2fs: validate ACL entry sizes in f2fs_acl_from_disk() (Zhang Cen)
- f2fs: fix to round down start offset of fallocate for pin file (Sunmin Jeong)
- f2fs: validate compress cache inode only when enabled (Wenjie Qi)
- wifi: iwlwifi: mvm: fix race condition in PTP removal (Junjie Cao)
- wifi: rtw88: usb: fix memory leaks on USB write failures (Luka Gejak) [Orabug: 39754018] {CVE-2026-63821}
- wifi: rtw88: increase TX report timeout to fix race condition (Luka Gejak)
- wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (Bitterblue Smith)
- wifi: ath11k: fix warning when unbinding (Jose Ignacio Tornos Martinez) [Orabug: 39754020] {CVE-2026-63822}
- wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer (Elxreno)
- wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (Zenm Chen)
- keys: Pin request_key_auth payload in instantiate paths (Shaomin Chen) [Orabug: 39754023] {CVE-2026-63823}
- KEYS: fix overflow in keyctl_pkey_params_get_2() (Jarkko Sakkinen) [Orabug: 39754027] {CVE-2026-63824}
- err.h: use __always_inline on all error pointer helpers (Arnd Bergmann)
- block: invalidate cached plug timestamp after task switch (Usama Arif)
- kernel/fork: clear PF_BLOCK_TS in copy_process() (Usama Arif) [Orabug: 39785201] {CVE-2026-64253}
- fbdev: fix use-after-free in store_modes() (Ian Bridges) [Orabug: 39754035] {CVE-2026-63826}
- NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR (Koichiro Den)
- apparmor: mediate the implicit connect of TCP fast open sendmsg (Bryam Vargas)
- net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) [Orabug: 39754044] {CVE-2026-63829}
- net: skmsg: preserve sg.copy across SG transforms (Yiming Qian) [Orabug: 39754048] {CVE-2026-63830}
- mac802154: llsec: add skb_cow_data() before in-place crypto (Doruk Tan Ozturk) [Orabug: 39754052] {CVE-2026-63831}
- mtd: spi-nor: macronix: add support for mx66{l2, u1}g45g (Cheng Ming Lin)
- mtd: spi-nor: macronix: Add post_sfdp fixups for Quad Input Page Program (Cheng Ming Lin)
- af_unix: Set gc_in_progress to true in unix_gc(). (Kuniyuki Iwashima) [Orabug: 39686465] {CVE-2026-53361}
- KVM: SEV: Unmap and unpin the GHCB as needed on vCPU free (Sean Christopherson)
- KVM: SEV: Move sev_free_vcpu() down below sev_es_unmap_ghcb() (Sean Christopherson)
- ntfs3: reject direct userspace writes to reserved $LX* xattrs (Konstantin Komarov)
- selinux: fix overlayfs mmap() and mprotect() access checks (Paul Moore) [Orabug: 39452299] {CVE-2026-46054}
- lsm: add backing_file LSM hooks (Paul Moore)
- fs: constify file ptr in backing_file accessor helpers (Amir Goldstein)
- batman-adv: tvlv: avoid race of cifsnotfound handler state (Sven Eckelmann)
- batman-adv: tvlv: enforce 2-byte alignment (Sven Eckelmann)
- batman-adv: dat: prevent false sharing between VLANs (Sven Eckelmann)
- batman-adv: tt: track roam count per VID (Sven Eckelmann)
- batman-adv: tt: don't merge change entries with different VIDs (Sven Eckelmann)
- batman-adv: tp_meter: handle overlapping packets (Sven Eckelmann)
- batman-adv: tp_meter: prevent parallel modifications of last_recv (Sven Eckelmann)
- batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE (Sven Eckelmann)
- batman-adv: tp_meter: restrict number of unacked list entries (Sven Eckelmann) [Orabug: 39754065] {CVE-2026-63834}
- batman-adv: v: prevent OGM aggregation on disabled hardif (Sven Eckelmann) [Orabug: 39754069] {CVE-2026-63835}
- batman-adv: frag: avoid underflow of TTL (Sven Eckelmann)
- batman-adv: frag: ensure fragment is writable before modifying TTL (Sven Eckelmann)
- batman-adv: fix (m|b)cast csum after decrementing TTL (Sven Eckelmann)
- batman-adv: ensure bcast is writable before modifying TTL (Sven Eckelmann)
- batman-adv: tp_meter: initialize last_recv_time during init (Sven Eckelmann)
- batman-adv: prevent ELP transmission interval underflow (Sven Eckelmann)
- batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (Sven Eckelmann)
- batman-adv: tp_meter: add only finished tp_vars to lists (Sven Eckelmann)
- batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (Sven Eckelmann)
- batman-adv: tp_meter: fix fast recovery precondition (Sven Eckelmann)
- batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (Sven Eckelmann) [Orabug: 39754075] {CVE-2026-63836}
- batman-adv: tp_meter: avoid window underflow (Sven Eckelmann)
- batman-adv: tp_meter: initialize dec_cwnd explicitly (Sven Eckelmann)
- batman-adv: tp_meter: initialize dup_acks explicitly (Sven Eckelmann)
- batman-adv: tp_meter: keep unacked list in ascending ordered (Sven Eckelmann)
- KVM: SEV: Ignore Port I/O requests of length '0' (Sean Christopherson) [Orabug: 39754368] {CVE-2026-63940}
- KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ (Sean Christopherson)
- KVM: SEV: Ignore MMIO requests of length '0' (Sean Christopherson)
- KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (Sean Christopherson) [Orabug: 39753975] {CVE-2026-63807}
- virtiofs: fix UAF on submount umount (Miklos Szeredi) [Orabug: 39753855] {CVE-2026-53381}
- media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (Ruslan Valiyev)
- ksmbd: reject non-VALID session in compound request branch (Gil Portnoy)
- serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero (Viken Dadhaniya)
- vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (Yi Yang) [Orabug: 39753870] {CVE-2026-53385}
- iio: adc: ti-ads1298: add bounds check to pga_settings index (Sam Daly)
- iio: light: veml6075: add bounds check to veml6075_it_ms index (Sam Daly)
- fuse: re-lock request before replacing page cache folio (Joanne Koong) [Orabug: 39753882] {CVE-2026-53388}
- rxrpc: Fix the ACK parser to extract the SACK table for parsing (David Howells) [Orabug: 39637359] {CVE-2026-53151}
- net: phonet: free phonet_device after RCU grace period (Santosh Kalluri)
- phonet: Pass net and ifindex to phonet_address_notify(). (Kuniyuki Iwashima)
- phonet: Pass ifindex to fill_addr(). (Kuniyuki Iwashima)
- hv: utils: handle and propagate errors in kvp_register (Thorsten Blum)
- Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (Dexuan Cui)
- fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh() (Jann Horn) [Orabug: 39674292] {CVE-2026-53341}
- staging: rtl8723bs: fix buffer over-read in rtw_update_protection (Salman Alghamdi)
- bonding: fix NULL pointer dereference in actor_port_prio setting (Hangbin Liu)
- net: bonding: fix use-after-free in bond_xmit_broadcast() (Xiang Mei) [Orabug: 39205989,39556377] {CVE-2026-31419}
- bonding: 3ad: implement proper RCU rules for port->aggregator (Eric Dumazet) [Orabug: 39621644] {CVE-2026-52975}
- bonding: print churn state via netlink (Hangbin Liu)
- bonding: add support for per-port LACP actor priority (Hangbin Liu)
- net: bonding: add broadcast_neighbor option for 802.3ad (Tonghao Zhang)
- xfs: fix error returns in CoW fork repair (Gao Yingjie)
- xfs: remove the expr argument to XFS_TEST_ERROR (Christoph Hellwig)
- dlm: prevent NPD when writing a positive value to event_done (Thadeu Lima de Souza Cascardo) [Orabug: 37844552] {CVE-2025-23131}
- regulator: core: fix locking in regulator_resolve_supply() error path (André Draszik) [Orabug: 39489557] {CVE-2026-46252}
- ACPI: scan: Use async schedule function in acpi_scan_clear_dep_fn() (Yicong Yang)
- selftests/bpf: Add test to ensure kprobe_multi is not sleepable (Varun R Mallya)
- bpf: Reject sleepable kprobe_multi programs at attach time (Varun R Mallya) [Orabug: 39300836] {CVE-2026-43010}
- agp/amd64: Fix broken error propagation in agp_amd64_probe() (Mingyu Wang) [Orabug: 39662072] {CVE-2026-53325}
- net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (Weiming Shi)
- i2c: stub: Reject I2C block transfers with invalid length (Weiming Shi) [Orabug: 39760891] {CVE-2026-64191}
- RDMA/bnxt_re: zero shared page before exposing to userspace (Lord Ulf Henrik Holmberg) [Orabug: 39918956] {CVE-2026-74584}
- debugobjects: Dont call fill_pool() in early boot hardirq context (Waiman Long)
- debugobjects: Do not fill_pool() if pi_blocked_on (Helen Koike)
- debugobjects: Use LD_WAIT_CONFIG instead of LD_WAIT_SLEEP (Sebastian Andrzej Siewior)
- debugobjects: Allow to refill the pool before SYSTEM_SCHEDULING (Sebastian Andrzej Siewior)
- Reapply "selftest/ptp: update ptp selftest to exercise the gettimex options" (Petr Machata)
- ip6_vti: set netns_immutable on the fallback device. (Eric Dumazet) [Orabug: 39589884] {CVE-2026-52909}
- net: Drop the lock in skb_may_tx_timestamp() (Sebastian Andrzej Siewior) [Orabug: 39331700] {CVE-2026-43216}
- iio: light: bh1780: fix PM runtime leak on error path (Antoniu Miclaus)
- drm/v3d: Skip CSD when it has zeroed workgroups (Maíra Canal)
- drm/v3d: Store the active job inside the queue's state (Maíra Canal)
- drm/xe/display: fix oops in suspend/shutdown without display (Jani Nikula) [Orabug: 39637326] {CVE-2026-53142}
- io_uring/net: Avoid msghdr on op_connect/op_bind async data (Gabriel Krisman Bertazi)
- gpio: Fix resource leaks on errors in gpiochip_add_data_with_key() (Tzung-Bi Shih) [Orabug: 39300677] {CVE-2026-31732}
- gpiolib: Remove redundant assignment of return variable (Andy Shevchenko)
- gpiolib: Extract gpiochip_choose_fwnode() for wider use (Andy Shevchenko)
- fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (Jann Horn) [Orabug: 39637409] {CVE-2026-53167}
- wifi: mt76: mt7921: fix potential deadlock in mt7921_roc_abort_sync (Sean Wang) [Orabug: 39622080] {CVE-2026-53101}
- wifi: mt76: mt7921: fix a potential scan no APs (Quan Zhou)
- wifi: mt76: mt7921: avoid undesired changes of the preset regulatory domain (Leon Yen)
- LTS version: v6.12.94 (Sherry Yang)
- netfilter: require Ethernet MAC header before using eth_hdr() (Zhengchuan Liang) [Orabug: 39637278] {CVE-2026-53131}
- vsock/virtio: fix skb overhead overflow on 32-bit builds (Stefano Garzarella)
- Revert "selftest/ptp: update ptp selftest to exercise the gettimex options" (Petr Machata)
- mptcp: pm: fix extra_subflows underflow on userspace PM subflow creation (Tao Cui)
- tcp: secure_seq: add back ports to TS offset (Eric Dumazet) [Orabug: 39103122] {CVE-2026-23247}
- tcp: use EXPORT_IPV6_MOD[_GPL]() (Eric Dumazet)
- net: introduce EXPORT_IPV6_MOD() and EXPORT_IPV6_MOD_GPL() (Eric Dumazet)
- vsock/virtio: fix skb overhead accounting to preserve full buf_alloc (Stefano Garzarella)
- vsock/virtio: fix potential unbounded skb queue (Eric Dumazet) [Orabug: 39637282] {CVE-2026-53132}
- ipvs: skip ipv6 extension headers for csum checks (Julian Anastasov) [Orabug: 39451540] {CVE-2026-45850}
- ipmi:ssif: NULL thread on error (Corey Minyard)
- ipmi:ssif: Remove unnecessary indention (Corey Minyard)
- mptcp: fix missing wakeups in edge scenarios (Paolo Abeni)
- mm/hugetlb: avoid false positive lockdep assertion (Lorenzo Stoakes)
- RDMA/umem: Fix truncation for block sizes >= 4G (Jason Gunthorpe) [Orabug: 39637285] {CVE-2026-53133}
- RDMA: Move DMA block iterator logic into dedicated files (Leon Romanovsky)
- RDMA/umem: fix kernel-doc warnings (Randy Dunlap)
- RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (Jason Gunthorpe) [Orabug: 39589882] {CVE-2026-52908}
- RDMA/umem: Add helpers for umem dmabuf revoke lock (Jacob Moroni)
- RDMA/umem: Move umem dmabuf revoke logic into helper function (Jacob Moroni)
- RDMA/umem: Add ib_umem_dmabuf_get_pinned_and_lock helper (Jacob Moroni)
- mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison (Ma Wupeng) [Orabug: 39637537] {CVE-2026-53207}
- netfilter: nft_fib: fix stale stack leak via the OIFNAME register (Davide Ornaghi) [Orabug: 39637291] {CVE-2026-53134}
- sched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task() (Tejun Heo) [Orabug: 39674249] {CVE-2026-53328}
- hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf (Anton Leontev) [Orabug: 39637515] {CVE-2026-53199}
- mailbox: Fix NULL message support in mbox_send_message() (Jassi Brar)
- driver core: reject devices with unregistered buses (Johan Hovold)
- fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (Mingyu Wang) [Orabug: 39655977] {CVE-2026-52946}
- drm/amd/display: Use krealloc_array() in dal_vector_reserve() (Harry Wentland) [Orabug: 39674252] {CVE-2026-53329}
- drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (Harry Wentland) [Orabug: 39637295] {CVE-2026-53135}
- drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs (Leorize)
- drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (Harry Wentland) [Orabug: 39637300] {CVE-2026-53136}
- drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (Harry Wentland) [Orabug: 39637306] {CVE-2026-53137}
- drm/amd/display: Bound VBIOS record-chain walk loops (Harry Wentland) [Orabug: 39637310] {CVE-2026-53138}
- drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range (Priya Hosur)
- drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 (Yang Wang)
- drm/amd/pm: fix smu13 power limit default/cap calculation (Yang Wang)
- drm/amdgpu: restart the CS if some parts of the VM are still invalidated (Christian König)
- drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups (Maíra Canal)
- drm/xe: Clear pending_disable before signaling suspend fence (Tangudu Tilak Tirumalesh)
- drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (Andrew Martin) [Orabug: 39637328] {CVE-2026-53143}
- drm/amdkfd: fix NULL dereference in get_queue_ids() (Muhammad Bilal) [Orabug: 39637330] {CVE-2026-53144}
- slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: Initialize controller resources in controller (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: Fix probe error path ordering (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: Fix up platform_driver registration (Bjorn Andersson)
- slimbus: qcom-ngd-ctrl: fix OF node refcount (Bartosz Golaszewski)
- thunderbolt: Limit XDomain response copy to actual frame size (Michael Bommarito) [Orabug: 39637336] {CVE-2026-53146}
- thunderbolt: Validate XDomain request packet size before type cast (Michael Bommarito) [Orabug: 39637341] {CVE-2026-53147}
- thunderbolt: Clamp XDomain response data copy to allocation size (Michael Bommarito) [Orabug: 39637345] {CVE-2026-53148}
- thunderbolt: Bound root directory content to block size (Michael Bommarito) [Orabug: 39637350] {CVE-2026-53149}
- thunderbolt: Reject zero-length property entries in validator (Michael Bommarito) [Orabug: 39637355] {CVE-2026-53150}
- sctp: stream: fully roll back denied add-stream state (Wyatt Feng) [Orabug: 39619337] {CVE-2026-52929}
- sctp: diag: reject stale associations in dump_one path (Zhao Zhang) [Orabug: 39619277] {CVE-2026-52917}
- rtase: Reset TX subqueue when clearing TX ring (Justin Lai)
- rtase: Avoid sleeping in get_stats64() (Justin Lai)
- pmdomain: imx: fix OF node refcount (Bartosz Golaszewski)
- mmc: sdhci: add signal voltage switch in sdhci_resume_host (Jisheng Zhang)
- mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (Lad Prabhakar)
- mmc: litex_mmc: Set mandatory idle clocks before CMD0 (Inochi Amaoto)
- mmc: core: Fix host controller programming for fixed driver type (Kamal Dasu)
- mm/hugetlb: restore reservation on error in hugetlb folio copy paths (David Carlier) [Orabug: 39637364] {CVE-2026-53154}
- io_uring/wait: fix min_timeout behavior (Christian A. Ehrhardt)
- io_uring/kbuf: don't truncate end buffer for bundles (Jens Axboe)
- octeontx2-af: fix memory leak in rvu_setup_hw_resources() (Dawei Feng)
- nvmem: layouts: onie-tlv: fix hang on unknown types (Andre Heider)
- nvmem: core: fix use-after-free bugs in error paths (Bartosz Golaszewski) [Orabug: 39637368] {CVE-2026-53156}
- net: mv643xx: fix OF node refcount (Bartosz Golaszewski)
- net: bonding: fix NULL pointer dereference in bond_do_ioctl() (Zhaojinming) [Orabug: 39674283] {CVE-2026-53337}
- net/mlx5: Reorder completion before putting command entry in cmd_work_handler (Nikolay Kuratov)
- misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (Mukesh Ojha)
- misc: fastrpc: fix DMA address corruption due to find_vma misuse (Junrui Luo)
- misc: fastrpc: fix use-after-free race in fastrpc_map_create (Zhenghang Xiao)
- misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (Anandu Krishnan E)
- ipc/shm: serialize orphan cleanup with shm_nattch updates (Yilin Zhu) [Orabug: 39619341] {CVE-2026-52930}
- Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (Cryolitia Pukngae)
- Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (Zeyu Wang)
- i2c: tegra: Fix NOIRQ suspend/resume (Akhil R)
- i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (Guillermo Rodríguez)
- i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (Vladimir Zapolskiy)
- fuse: reject fuse_notify() pagecache ops on directories (Jann Horn) [Orabug: 39637413] {CVE-2026-53168}
- fs/qnx6: fix pointer arithmetic in directory iteration (Arpith Kalaginanavoor)
- pidfd: refuse access to tasks that have started exiting harder (Christian Brauner)
- inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush (Hyunwoo Kim) [Orabug: 39839050] {CVE-2026-53175}
- IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (Michael Bommarito) [Orabug: 39637427] {CVE-2026-53176}
- bnxt_en: Fix NULL pointer dereference (Kyle Meyer) [Orabug: 39637431] {CVE-2026-53177}
- ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write (Chancel Liu)
- timers/migration: Fix livelock in tmigr_handle_remote_up() (Amit Matityahu) [Orabug: 39637444] {CVE-2026-53180}
- vsock/vmci: fix sk_ack_backlog leak on failed handshake (Raf Dickson) [Orabug: 39637446] {CVE-2026-53181}
- wifi: nl80211: reject oversized EMA RNR lists (Yuqi Xu) [Orabug: 39637453] {CVE-2026-53182}
- mptcp: add-addr: always drop other suboptions (Matthieu Baerts)
- selftests: mptcp: add test for extra_subflows underflow on userspace PM (Tao Cui)
- mptcp: sockopt: check timestamping ret value (Matthieu Baerts)
- mptcp: allow subflow rcv wnd to shrink (Paolo Abeni) [Orabug: 39637456] {CVE-2026-53183}
- mptcp: close TOCTOU race while computing rcv_wnd (Paolo Abeni) [Orabug: 39754145] {CVE-2026-63867}
- mptcp: fix retransmission loop when csum is enabled (Paolo Abeni)
- ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow (Karl Mehltretter)
- ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O (Karl Mehltretter)
- ARM: socfpga: Fix OF node refcount leak in SMP setup (Yuho Choi)
- udp: clear skb->dev before running a sockmap verdict (Sechang Lim) [Orabug: 39637458] {CVE-2026-53184}
- zram: fix use-after-free in zram_bvec_write_partial() (Cunlong Li) [Orabug: 39637460] {CVE-2026-53185}
- RDMA/srp: bound SRP_RSP sense copy by the received length (Michael Bommarito) [Orabug: 39637466] {CVE-2026-53186}
- mm/damon/ops-common: call folio_test_lru() after folio_get() (Seongjae Park)
- mm/huge_memory: update file PMD counter before folio_put() (Yin Tirui) [Orabug: 39637476] {CVE-2026-53189}
- drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (Harry Wentland)
- drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (Xu Wang) [Orabug: 39637480] {CVE-2026-53190}
- io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries (Clément Léger) [Orabug: 39637484] {CVE-2026-53191}
- ALSA: timer: Fix UAF at snd_timer_user_params() (Takashi Iwai) [Orabug: 39637488] {CVE-2026-53192}
- ALSA: timer: Forcibly close timer instances at closing (Takashi Iwai) [Orabug: 39637492] {CVE-2026-53193}
- USB: serial: kl5kusb105: fix bulk-out buffer overflow (Hyeongjun An) [Orabug: 39637495] {CVE-2026-53194}
- USB: serial: option: add usb-id for Dell Wireless DW5826e-m (Jack Wu)
- USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (Adrian Korwel) [Orabug: 39637501] {CVE-2026-53195}
- USB: serial: io_ti: fix heap overflow in get_manuf_info() (Adrian Korwel) [Orabug: 39637505] {CVE-2026-53196}
- xfrm: espintcp: do not reuse an in-progress partial send (Wyatt Feng)
- ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL (Gil Portnoy)
- pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init (Judith Mendez)
- drm/i915/gem: Fix phys BO pread/pwrite with offset (Joonas Lahtinen) [Orabug: 39674334] {CVE-2026-53356}
- KVM: SEV: Decouple the need to sync the GHCB SA from the need to free the SA (Sean Christopherson)
- KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying (Sean Christopherson) [Orabug: 39674302] {CVE-2026-53345}
- mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (Inochi Amaoto)
- rust: kasan/kbuild: fix rustc-option when cross-compiling (Alice Ryhl)
- rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES (Alice Ryhl)
- rust: x86: support Rust >= 1.98.0 target spec (Miguel Ojeda)
- tracing/probes: Point the error offset correctly for eprobe argument error (Masami Hiramatsu)
- accel/ivpu: Fix signed integer truncation in IPC receive (Andrzej Kacprowski)
- accel/ivpu: Add buffer overflow check in MS get_info_ioctl (Andrzej Kacprowski)
- accel/ivpu: Add bounds checks for firmware log indices (Andrzej Kacprowski)
- soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get() (Manivannan Sadhasivam)
- Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (Michael Bommarito) [Orabug: 39637544] {CVE-2026-53208}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (Yuqi Xu) [Orabug: 39637549] {CVE-2026-53209}
- tee: shm: fix shm leak in register_shm_helper() (Georgiy Osokin) [Orabug: 39637551] {CVE-2026-53210}
- netfilter: nft_tunnel: fix use-after-free on object destroy (Tristan Madani) [Orabug: 39637554] {CVE-2026-53212}
- drm/xe: fix refcount leak in xe_range_fence_insert() (Xu Wang)
- drm/vc4: fix krealloc() memory leak (Alexander A. Klimov) [Orabug: 39637560] {CVE-2026-53213}
- drm/virtio: Fix driver removal with disabled KMS (Dmitry Osipenko) [Orabug: 39674308] {CVE-2026-53347}
- clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration time (Pengyu Luo)
- clk: samsung: gs101: Fix missing USI7_USI DIV clock in peric0_clk_regs (Kuan-Wei Chiu)
- clk: qcom: x1e80100-dispcc: Stop disp_cc_mdss_mdp_clk_src from getting parked (Hans de Goede)
- KVM: VMX: Update SVI during runtime APICv activation (Dongli Zhang)
- netfilter: ctnetlink: ensure safe access to master conntrack (Pablo Neira Ayuso) [Orabug: 39331275] {CVE-2026-43116}
- ipv6: Fix a potential NPD in cleanup_prefix_route() (Ido Schimmel) [Orabug: 39639429] {CVE-2026-53214}
- net: mvpp2: build skb from XDP-adjusted data on XDP_PASS (Til Kaiser)
- net: mvpp2: refill RX buffers before XDP or skb use (Til Kaiser) [Orabug: 39637567] {CVE-2026-53215}
- net: mvpp2: Add metadata support for xdp mode (Lorenzo Bianconi)
- net: mvpp2: limit XDP frame size to the RX buffer (Til Kaiser) [Orabug: 39637570] {CVE-2026-53216}
- net: mvpp2: sync RX data at the hardware packet offset (Til Kaiser) [Orabug: 39637574] {CVE-2026-53217}
- netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (Florian Westphal) [Orabug: 39637577] {CVE-2026-53218}
- netfilter: nf_log: validate MAC header was set before dumping it (Xiang Mei) [Orabug: 39619383] {CVE-2026-52942}
- netfilter: x_tables: avoid leaking percpu counter pointers (Kyle Zeng) [Orabug: 39637581] {CVE-2026-53219}
- netfilter: nf_conntrack: destroy stale expectfn expectations on unregister (Weiming Shi) [Orabug: 39674311] {CVE-2026-53349}
- netfilter: revalidate bridge ports (Florian Westphal) [Orabug: 39637585] {CVE-2026-53220}
- ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() (Eric Dumazet) [Orabug: 39637591] {CVE-2026-53221}
- net: guard timestamp cmsgs to real error queue skbs (Kyle Zeng) [Orabug: 39637598] {CVE-2026-53223}
- sctp: fix uninit-value in __sctp_rcv_asconf_lookup() (Michael Bommarito) [Orabug: 39637608] {CVE-2026-53225}
- gpio: zynq: fix runtime PM leak on remove (Ruoyu Wang)
- r8152: handle the return value of usb_reset_device() (Chih Kai Hsu)
- net: openvswitch: fix possible kfree_skb of ERR_PTR (Adrian Moreno) [Orabug: 39637617] {CVE-2026-53227}
- ipv6: sit: reload inner IPv6 header after GSO offloads (Kyle Zeng) [Orabug: 39637621] {CVE-2026-53228}
- net/mlx5: Use effective affinity mask for IRQ selection (Wangfushuai)
- net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (Dragos Tatulea) [Orabug: 39637626] {CVE-2026-53229}
- net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (Dragos Tatulea) [Orabug: 39637631] {CVE-2026-53230}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Mingyu Wang) [Orabug: 39621561] {CVE-2026-52947}
- net: phy: clean the sfp upstream if phy probing fails (Maxime Chevallier) [Orabug: 39637636] {CVE-2026-53232}
- netdev: fix double-free in netdev_nl_bind_rx_doit() (Jakub Kicinski) [Orabug: 39637640] {CVE-2026-53233}
- net: ibm: emac: Fix use-after-free during device removal (Rosen Penev)
- net/mlx4: avoid GCC 10 __bad_copy_from() false positive (Yao Sang)
- net: add pskb_may_pull() to skb_gro_receive_list() (Ji'An Zhou) [Orabug: 39637645] {CVE-2026-53235}
- tcp: restrict SO_ATTACH_FILTER to priv users (Eric Dumazet) [Orabug: 39637647] {CVE-2026-53236}
- ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (Richard Fitzgerald) [Orabug: 39674315] {CVE-2026-53350}
- gpio: mvebu: fix NULL pointer dereference in suspend/resume (Yun Zhou) [Orabug: 39637652] {CVE-2026-53237}
- netlabel: validate unlabeled address and mask attribute lengths (Chenguang Zhao) [Orabug: 39637661] {CVE-2026-53238}
- xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (Sanghyun Park) [Orabug: 39637665] {CVE-2026-53239}
- dma-debug: fix physical address retrieval in debug_dma_sync_sg_for_device (Li Rongqing)
- iomap: don't revert iov_iter on partially completed buffered writes (Brian Foster)
- tools/rv: Fix cleanup after failed trace setup (Gabriele Monaco)
- spi: cadence-quadspi: fix unclocked access on unbind (Johan Hovold)
- ALSA: seq: dummy: fix UMP event stack overread (Kyle Zeng) [Orabug: 39637671] {CVE-2026-53241}
- time: Fix off-by-one in settimeofday() usec validation (Naveen Kumar Chaudhary)
- signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() (Aleksandr Nogikh) [Orabug: 39674318] {CVE-2026-53352}
- ipmi: Fix rcu_read_unlock to srcu_read_unlock in handle_read_event_rsp (Rui Qi)
- sctp: purge outqueue on stale COOKIE-ECHO handling (Xin Long) [Orabug: 39619310] {CVE-2026-52924}
- net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (Yizhou Zhao) [Orabug: 39637678] {CVE-2026-53245}
- ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() (Eric Dumazet) [Orabug: 39754154] {CVE-2026-63870}
- vxlan: vnifilter: fix spurious notification on VNI update (Andy Roulin)
- vxlan: vnifilter: send notification on VNI add (Andy Roulin)
- net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown (Lorenzo Bianconi)
- ptp: vclock: Switch from RCU to SRCU (Kurt Kanzenbach)
- ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (Eric Dumazet) [Orabug: 39637693] {CVE-2026-53249}
- Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls (Seungju Cheon) [Orabug: 39754158] {CVE-2026-63871}
- Bluetooth: ISO: Fix not using bc_sid as advertisement SID (Luiz Augusto von Dentz)
- Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync (Luiz Augusto von Dentz) [Orabug: 39637699] {CVE-2026-53251}
- Bluetooth: fix memory leak in error path of hci_alloc_dev() (Bharath Reddy) [Orabug: 39637702] {CVE-2026-53252}
- Bluetooth: bnep: reject short frames before parsing (Zhang Cen) [Orabug: 39637704] {CVE-2026-53253}
- Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (Dudu Lu)
- Bluetooth: RFCOMM: validate skb length in MCC handlers (Seungju Cheon) [Orabug: 39637710] {CVE-2026-53254}
- Bluetooth: MGMT: validate advertising TLV before type checks (Zhang Cen) [Orabug: 39637715] {CVE-2026-53255}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (Zhang Cen) [Orabug: 39637719] {CVE-2026-53256}
- net: fec: fix pinctrl default state restore order on resume (Tapio Reijonen)
- net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (Yizhou Zhao) [Orabug: 39754148] {CVE-2026-63868}
- hsr: Remove WARN_ONCE() in hsr_addr_is_self(). (Kuniyuki Iwashima) [Orabug: 39674322] {CVE-2026-53353}
- net: Annotate sk->sk_write_space() for UDP SOCKMAP. (Kuniyuki Iwashima)
- pcnet32: stop holding device spin lock during napi_complete_done (Oscar Maes)
- wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (Deepanshu Kartikey) [Orabug: 39754152] {CVE-2026-63869}
- drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (Yicong Hui)
- devlink: Release nested relation on devlink free (Mark Bloch) [Orabug: 39637732] {CVE-2026-53261}
- l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() (Lee Jones) [Orabug: 39637736] {CVE-2026-53262}
- 6lowpan: fix off-by-one in multicast context address compression (Yizhou Zhao) [Orabug: 39637740] {CVE-2026-53263}
- net/sched: act_api: use RCU with deferred freeing for action lifecycle (Jamal Hadi Salim) [Orabug: 39637746] {CVE-2026-53264}
- netfilter: bridge: make ebt_snat ARP rewrite writable (Yiming Qian) [Orabug: 39637752] {CVE-2026-53266}
- netfilter: nft_ct: bail out on template ct in get eval (Jiayuan Chen) [Orabug: 39637758] {CVE-2026-53267}
- netfilter: conntrack_irc: fix possible out-of-bounds read (Florian Westphal) [Orabug: 39637762] {CVE-2026-53268}
- netfilter: synproxy: add mutex to guard hook reference counting (Fernando Fernandez Mancera) [Orabug: 39637767] {CVE-2026-53269}
- ipvs: clear the svc scheduler ptr early on edit (Julian Anastasov) [Orabug: 39637771] {CVE-2026-53270}
- netfilter: xt_NFQUEUE: prefer raw_smp_processor_id (Fernando Fernandez Mancera)
- ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers (Gil Portnoy)
- erofs: fix use-after-free on sbi->sync_decompress (Gao Xiang) [Orabug: 39637779] {CVE-2026-53272}
- erofs: tidy up synchronous decompression (Gao Xiang)
- erofs: add sysfs node to drop internal caches (Chunhai Guo)
- soc: qcom: ice: Return -ENODEV if the ICE platform device is not found (Manivannan Sadhasivam)
- tee: optee: prevent use-after-free when the client exits before the supplicant (Amirreza Zarrabi) [Orabug: 39637781] {CVE-2026-53273}
- net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (Nicolò Coccia)
- ipv6: mcast: Fix use-after-free when processing MLD queries (Ido Schimmel) [Orabug: 39637789] {CVE-2026-53275}
- i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (Mingyu Wang) [Orabug: 39621567] {CVE-2026-52948}
- wifi: remove zero-length arrays (Johannes Berg)
- net: phy: micrel: fix LAN8814 QSGMII soft reset (Robert Marko)
- ARM: fix branch predictor hardening (Russell King)
- ARM: fix hash_name() fault (Russell King)
- ARM: allow __do_kernel_fault() to report execution of memory faults (Russell King)
- ARM: group is_permission_fault() with is_translation_fault() (Russell King)
- USB: serial: mct_u232: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754235] {CVE-2026-63898}
- bpf: Free reuseport cBPF prog after RCU grace period. (Kuniyuki Iwashima) [Orabug: 39589888] {CVE-2026-52910}
- LTS version: v6.12.93 (Sherry Yang)
- net/sched: act_mirred: Fix blockcast recursion bypass leading to stack overflow (Kito Xu) [Orabug: 39838946] {CVE-2026-63981}
- ethtool: cmis_cdb: Fix incorrect read / write length extension (Ido Schimmel)
- usb: core: Fix SuperSpeed root hub wMaxPacketSize (Michał Pecio)
- memfd: deny writeable mappings when implying SEAL_WRITE (Pratyush Yadav) [Orabug: 39754398] {CVE-2026-63952}
- mm/memfd: fix spelling and grammatical issues (Liu Ye)
- mm: perform all memfd seal checks in a single place (Lorenzo Stoakes)
- x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines (Alexis Lothoré) [Orabug: 39785154] {CVE-2026-64235}
- x86/alternatives: Rename 'apply_relocation()' to 'text_poke_apply_relocation()' (Ingo Molnar)
- usb: typec: ucsi: Don't update power_supply on power role change if not connected (Myrrh Periwinkle)
- thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (Michael Bommarito) [Orabug: 39754209] {CVE-2026-63891}
- usb: typec: ucsi: Check if power role change actually happened before handling (Myrrh Periwinkle)
- usb: musb: omap2430: Fix use-after-free in omap2430_probe() (Xu Wang)
- usb: dwc3: xilinx: fix error handling in zynqmp init error paths (Radhey Shyam Pandey)
- ALSA: firewire-motu: Protect register DSP event queue positions (Cássio Gabriel)
- iio: dac: ad5686: fix ref bit initialization for single-channel parts (Rodrigo Alencar)
- iio: chemical: scd30: fix division by zero in write_raw (Antoniu Miclaus)
- iio: chemical: scd30: Use guard(mutex) to allow early returns (Jonathan Cameron)
- mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() (Seongjae Park) [Orabug: 39785162] {CVE-2026-64239}
- mptcp: do not drop partial packets (Shardul Bankar)
- mptcp: handle first subflow closing consistently (Paolo Abeni)
- mptcp: introduce the mptcp_init_skb helper (Paolo Abeni)
- octeontx2-pf: avoid double free of pool->stack on AQ init failure (Dawei Feng)
- arm64: tlb: Flush walk cache when unsharing PMD tables (Zeng Heng) [Orabug: 39755009] {CVE-2026-63875}
- mptcp: reset rcv wnd on disconnect (Paolo Abeni)
- mptcp: cleanup fallback dummy mapping generation (Paolo Abeni)
- ring-buffer: Flush and stop persistent ring buffer on panic (Masami Hiramatsu)
- ice: fix VF queue configuration with low MTU values (Jose Ignacio Tornos Martinez)
- mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient (Li Xiasong)
- selftests: mptcp: drop nanoseconds width specifier (Matthieu Baerts)
- net: hsr: defer node table free until after RCU readers (Michael Bommarito) [Orabug: 39754839] {CVE-2026-64123}
- platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error recovery (Lukas Wunner)
- mm/memory: fix spurious warning when unmapping device-private/exclusive pages (Alistair Popple) [Orabug: 39754857] {CVE-2026-64131}
- ALSA: scarlett2: Allow flash writes ending at segment boundary (Cássio Gabriel)
- ALSA: scarlett2: Return ENOSPC for out-of-bounds flash writes (Geoffrey D. Bennett)
- Bluetooth: hci_qca: Convert timeout from jiffies to ms (Shuai Zhang)
- Bluetooth: hci_qca: Migrate to serdev specific shutdown function (Uwe Kleine-König)
- serdev: Provide a bustype shutdown function (Uwe Kleine-König)
- x86/kexec: Disable KCOV instrumentation after load_segments() (Aleksandr Nogikh)
- x86/boot: Disable stack protector for early boot code (Brian Gerst)
- iommu: Skip PASID validation for devices without PASID capability (Tushar Dave)
- xhci: tegra: Fix ghost USB device on dual-role port unplug (Wei-Cheng Chen)
- USB: serial: digi_acceleport: fix memory corruption with small endpoints (Johan Hovold) [Orabug: 39754247] {CVE-2026-63901}
- USB: serial: cypress_m8: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754407] {CVE-2026-63956}
- serial: zs: Convert to use a platform device (Maciej W. Rozycki)
- serial: zs: Switch to using channel reset (Maciej W. Rozycki)
- serial: zs: Fix bootconsole handover lockup (Maciej W. Rozycki)
- serial: dz: Convert to use a platform device (Maciej W. Rozycki)
- serial: dz: Fix bootconsole handover lockup (Maciej W. Rozycki)
- serial: dz: Fix bootconsole message clobbering at chip reset (Maciej W. Rozycki)
- drm/amdkfd: Check for pdd drm file first in CRIU restore path (David Francis)
- drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger (Eric Huang) [Orabug: 39754177] {CVE-2026-63881}
- drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (Eric Huang) [Orabug: 39754181] {CVE-2026-63882}
- serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (Shitalkumar Gandhi)
- serial: zs: Fix swapped RI/DSR modem line transition counting (Maciej W. Rozycki)
- serial: sh-sci: fix memory region release in error path (Hongling Zeng)
- serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (Viken Dadhaniya)
- serial: qcom-geni: fix UART_RX_PAR_EN bit position (Prasanna S)
- serial: altera_jtaguart: handle uart_add_one_port() failures (Myeonghun Pak)
- drm/i915: Fix potential UAF in TTM object purge (Janusz Krzysztofik) [Orabug: 39754187] {CVE-2026-63884}
- drm/hyperv: validate VMBus packet size in receive callback (Berkant Koc) [Orabug: 39786541] {CVE-2026-64527}
- drm/hyperv: validate resolution_count and fix WIN8 fallback (Berkant Koc) [Orabug: 39786536] {CVE-2026-64524}
- thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (Michael Bommarito) [Orabug: 39754215] {CVE-2026-63892}
- thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (Michael Bommarito) [Orabug: 39754219] {CVE-2026-63893}
- usb: gadget: f_fs: serialize DMABUF cancel against request completion (Michael Bommarito)
- usb: gadget: f_fs: copy only received bytes on short ep0 read (Michael Bommarito)
- usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (Seungjin Bae)
- usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (Jeremy Erazo)
- usb: gadget: f_hid: fix device reference leak in hidg_alloc() (Guangshuo Li)
- usb: gadget: net2280: Fix double free in probe error path (Guangshuo Li)
- usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (Kai Aizen)
- USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (Johan Hovold) [Orabug: 39754231] {CVE-2026-63897}
- USB: serial: mxuport: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754239] {CVE-2026-63899}
- USB: serial: keyspan: fix missing indat transfer sanity check (Johan Hovold) [Orabug: 39754243] {CVE-2026-63900}
- USB: serial: cypress_m8: validate interrupt packet headers (Zhang Cen) [Orabug: 39754251] {CVE-2026-63902}
- USB: serial: belkin_sa: validate interrupt status length (Zhang Cen) [Orabug: 39754255] {CVE-2026-63903}
- USB: serial: option: add MeiG SRM813Q (Jan Volckaert)
- usb: typec: tcpm: improve handling of DISCOVER_MODES failures (Sebastian Reichel)
- usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (Heitor Alves de Siqueira)
- usb: usbtmc: check URB actual_length for interrupt-IN notifications (Heitor Alves de Siqueira) [Orabug: 39754259] {CVE-2026-63904}
- usbip: vudc: Fix use after free bug in vudc_remove due to race condition (Michael Bommarito)
- usb: storage: Add quirks for PNY Elite Portable SSD (Sam Burkels)
- USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (Stephen J. Fuhry)
- usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (Michał Pecio)
- usb: chipidea: core: convert ci_role_switch to local variable (Xu Yang)
- tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (Tudor Ambarus) [Orabug: 39786544] {CVE-2026-64528}
- tty: serial: pch_uart: add check for dma_alloc_coherent() (Zhaoyang Yu)
- counter: Fix refcount leak in counter_alloc() error path (Guangshuo Li)
- comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (Ian Abbott)
- comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (Ian Abbott)
- Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (Nicolás Bazaes)
- Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (Dmitry Torokhov) [Orabug: 39754270] {CVE-2026-63908}
- Input: xpad - add support for ASUS ROG RAIKIRI II (Dmitriy Zharov)
- Input: xpad - add "Nova 2 Lite" from GameSir (Qbeliw Tanaka)
- xfrm: esp: restore combined single-frag length gate (Jingguo Tan) [Orabug: 39754277] {CVE-2026-63912}
- ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (Srinivas Kandagatla)
- ASoC: qcom: q6asm-dai: close stream only when running (Srinivas Kandagatla)
- netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check (Hamza Mahfooz) [Orabug: 39754281] {CVE-2026-63913}
- ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (Geoffrey D. Bennett)
- xfrm: ah: use skb_to_full_sk in async output callbacks (Michael Bommarito)
- xfrm: route MIGRATE notifications to caller's netns (Maoyi Xie) [Orabug: 39754285] {CVE-2026-63914}
- nfc: hci: fix out-of-bounds read in HCP header parsing (Ashutosh Desai)
- iommu, debugobjects: avoid gcc-16.1 section mismatch warnings (Arnd Bergmann)
- HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (Lee Jones) [Orabug: 39754293] {CVE-2026-63916}
- ip6: vti: Use ip6_tnl.net in vti6_changelink(). (Kuniyuki Iwashima) [Orabug: 39754297] {CVE-2026-63917}
- l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname (Michael Bommarito) [Orabug: 39754301] {CVE-2026-63918}
- xfrm: input: hold netns during deferred transport reinjection (Zhengchuan Liang) [Orabug: 39754303] {CVE-2026-63919}
- ipv6: validate extension header length before copying to cmsg (Qi Tang) [Orabug: 39754306] {CVE-2026-63920}
- ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). (Maoyi Xie) [Orabug: 39754310] {CVE-2026-63921}
- ipv6: exthdrs: refresh nh after handling HAO option (Zhengchuan Liang) [Orabug: 39754314] {CVE-2026-63922}
- ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (Srinivas Kandagatla)
- ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() (Justin Iurman) [Orabug: 39754321] {CVE-2026-63924}
- macsec: fix replay protection at XPN lower-PN wrap (Junrui Luo) [Orabug: 39754325] {CVE-2026-63925}
- bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (Yuqi Xu) [Orabug: 39754328] {CVE-2026-63926}
- wireguard: send: append trailer after expanding head (Jason A. Donenfeld)
- Input: elan_i2c - validate firmware size before use (Dmitry Torokhov) [Orabug: 39785157] {CVE-2026-64237}
- usb: dwc2: Fix use after free in debug code (Dan Carpenter) [Orabug: 39754332] {CVE-2026-63927}
- usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (Peter Chen)
- usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (Peter Chen)
- usb: cdns3: gadget: fix request skipping after clearing halt (Yongchao Wu)
- USB: serial: omninet: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754336] {CVE-2026-63928}
- iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (Benoît Monin) [Orabug: 39754340] {CVE-2026-63929}
- iio: buffer: hw-consumer: fix use-after-free in error path (Felix Gu)
- iio: light: cm3323: fix reg_conf not being initialized correctly (Aldo Conte)
- iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (Advait Dhamorikar)
- iio: temperature: tsys01: fix broken PROM checksum validation (Salah Triki)
- iio: ssp_sensors: cancel delayed work_refresh on remove (Sanjay Chitroda)
- iio: gyro: adis16260: fix division by zero in write_raw (Antoniu Miclaus)
- iio: gyro: itg3200: fix i2c read into the wrong stack location (David Carlier)
- iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (Salah Triki)
- iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (Salah Triki)
- iio: dac: ad5686: acquire lock when doing powerdown control (Rodrigo Alencar)
- iio: dac: ad5686: fix input raw value check (Rodrigo Alencar)
- iio: dac: max5821: fix return value check in powerdown sync (Salah Triki)
- iio: adc: npcm: fix unbalanced clk_disable_unprepare() (David Carlier)
- iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (Christofer Jonason)
- Disable -Wattribute-alias for clang-23 and newer (Nathan Chancellor)
- KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() (Sean Christopherson)
- KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer (Sean Christopherson) [Orabug: 39754362] {CVE-2026-63937}
- KVM: SEV: Check PSC request indices against the actual size of the buffer (Sean Christopherson) [Orabug: 39754364] {CVE-2026-63938}
- KVM: SEV: Compute the correct max length of the in-GHCB scratch area (Sean Christopherson) [Orabug: 39754366] {CVE-2026-63939}
- KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 (Sean Christopherson)
- KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests (Sean Christopherson)
- KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (Michael Roth) [Orabug: 39686463] {CVE-2026-53360}
- KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (Sean Christopherson)
- KVM: arm64: PMU: Preserve AArch32 counter low bits (Maqiang)
- parport: Fix race between port and client registration (Ben Hutchings) [Orabug: 39754374] {CVE-2026-63942}
- Input: xpad - fix out-of-bounds access for Share button (Dmitry Torokhov)
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (Doruk Tan Ozturk) [Orabug: 39754380] {CVE-2026-63944}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (Muhammad Bilal) [Orabug: 39754382] {CVE-2026-63945}
- Bluetooth: ISO: fix UAF in iso_recv_frame (Muhammad Bilal) [Orabug: 39754384] {CVE-2026-63946}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (Muhammad Bilal) [Orabug: 39754386] {CVE-2026-63947}
- Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (Siwei Zhang) [Orabug: 39754390] {CVE-2026-63948}
- Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (Siwei Zhang) [Orabug: 39681272] {CVE-2026-53358}
- auxdisplay: line-display: fix OOB read on zero-length message_store() (Stepan Ionichev) [Orabug: 39754394] {CVE-2026-63949}
- ipc: limit next_id allocation to the valid ID range (Linpu Yu) [Orabug: 39619306] {CVE-2026-52923}
- hpfs: fix a crash if hpfs_map_dnode_bitmap fails (Mikulas Patocka)
- Bluetooth: btusb: Allow firmware re-download when version matches (Shuai Zhang)
- HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (Hlleng)
- Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (Thomas Fourier)
- USB: serial: safe_serial: fix memory corruption with small endpoint (Johan Hovold) [Orabug: 39754411] {CVE-2026-63957}
- usb: typec: ucsi: validate connector number in ucsi_connector_change() (Greg Kroah-Hartman) [Orabug: 39754415] {CVE-2026-63958}
- usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (Greg Kroah-Hartman)
- usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (Greg Kroah-Hartman)
- usb: typec: altmodes/displayport: validate count before reading Status Update VDO (Greg Kroah-Hartman) [Orabug: 39754427] {CVE-2026-63961}
- usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (Greg Kroah-Hartman)
- usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() (Greg Kroah-Hartman) [Orabug: 39754431] {CVE-2026-63962}
- usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers (Greg Kroah-Hartman) [Orabug: 39754436] {CVE-2026-63963}
- usb: typec: ucsi: ccg: reject firmware images without a ':' record header (Greg Kroah-Hartman)
- iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (Greg Kroah-Hartman)
- batman-adv: tt: prevent TVLV entry number overflow (Sven Eckelmann)
- phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X (Horatiu Vultur)
- drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used (Jouni Högander)
- drm/dp: Add eDP 1.5 bit definition (Suraj Kandpal)
- drm/i915/psr: Read Intel DPCD workaround register (Jouni Högander)
- drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (Jouni Högander)
- HID: core: Fix size_t specifier in hid_report_raw_event() (Nathan Chancellor)
- HID: core: introduce hid_safe_input_report() (Benjamin Tissoires)
- HID: pass the buffer size to hid_report_raw_event (Benjamin Tissoires)
- HID: core: Add printk_ratelimited variants to hid_warn() etc (Vicki Pfau)
- inet: frags: flush pending skbs in fqdir_pre_exit() (Jakub Kicinski) [Orabug: 38847669] {CVE-2025-68768}
- inet: frags: add inet_frag_queue_flush() (Jakub Kicinski)
- mm/page_alloc: clear page->private in free_pages_prepare() (Mikhail Gavrilov) [Orabug: 39343575] {CVE-2026-43303}
- batman-adv: bla: avoid double decrement of bla.num_requests (Sven Eckelmann) [Orabug: 39754760] {CVE-2026-64095}
- batman-adv: tt: avoid empty VLAN responses (Sven Eckelmann) [Orabug: 39754743] {CVE-2026-64090}
- batman-adv: tt: fix TOCTOU race for reported vlans (Sven Eckelmann) [Orabug: 39754747] {CVE-2026-64091}
- batman-adv: tp_meter: directly shut down timer on cleanup (Sven Eckelmann) [Orabug: 39754752] {CVE-2026-64093}
- s390/cio: Restore GFP_DMA for CHSC allocation (Peter Oberparleiter)
- batman-adv: tp_meter: avoid role confusion in tp_list (Sven Eckelmann)
- batman-adv: iv: recover OGM scheduling after forward packet error (Sven Eckelmann)
- batman-adv: tvlv: reject oversized TVLV packets (Sven Eckelmann) [Orabug: 39619356] {CVE-2026-52934}
- batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface (Sven Eckelmann) [Orabug: 39754756] {CVE-2026-64094}
- batman-adv: tt: reject oversized local TVLV buffers (Sven Eckelmann)
- batman-adv: tvlv: abort OGM send on tvlv append failure (Sven Eckelmann)
- batman-adv: v: stop OGMv2 on disabled interface (Sven Eckelmann) [Orabug: 39619260] {CVE-2026-52913}
- perf: Fix dangling cgroup pointer in cpuctx (Levi Yun)
- net: skbuff: fix pskb_carve leaking zcopy pages (Pavel Begunkov)
- ipv6: fix possible infinite loop in fib6_select_path() (Jiayuan Chen) [Orabug: 39754449] {CVE-2026-63968}
- ipv6: fix possible infinite loop in rt6_fill_node() (Jiayuan Chen) [Orabug: 39754451] {CVE-2026-63969}
- sctp: fix race between sctp_wait_for_connect and peeloff (Zhenghang Xiao) [Orabug: 39754455] {CVE-2026-63971}
- net: mana: Add NULL guards in teardown path to prevent panic on attach failure (Dipayaan Roy) [Orabug: 39754460] {CVE-2026-63973}
- gpio: rockchip: convert bank->clk to devm_clk_get_enabled() (Marco Scardovi)
- gpio: virtuser: Fix uninitialized data bug in gpio_virtuser_direction_do_write() (Dan Carpenter)
- Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (Heitor Alves de Siqueira) [Orabug: 39754465] {CVE-2026-63974}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (Luiz Augusto von Dentz) [Orabug: 39754467] {CVE-2026-63975}
- Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (Zhenghang Xiao) [Orabug: 39754470] {CVE-2026-63976}
- net/handshake: Drain pending requests at net namespace exit (Chuck Lever) [Orabug: 39754474] {CVE-2026-63978}
- net/handshake: Take a long-lived file reference at submit (Chuck Lever) [Orabug: 39786532] {CVE-2026-64523}
(Al Viro)
- net/handshake: Pass negative errno through handshake_complete() (Chuck Lever)
- nvme-tcp: store negative errno in queue->tls_err (Chuck Lever)
- net/handshake: Use spin_lock_bh for hn_lock (Chuck Lever) [Orabug: 39754480] {CVE-2026-63980}
- net/sched: act_mirred: Fix return code in early mirred redirect error paths (Victor Nogueira)
- net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop (Jamal Hadi Salim) [Orabug: 39839075] {CVE-2026-63982}
- net: Introduce skb tc depth field to track packet loops (Jamal Hadi Salim)
- net/sched: act_mirred: add loop detection (Eric Dumazet)
- net/sched: act_mirred: Move the recursion counter struct netdev_xmit (Sebastian Andrzej Siewior)
- net/sched: fix packet loop on netem when duplicate is on (Jamal Hadi Salim) [Orabug: 39754484] {CVE-2026-63983}
- net/sched: Revert "net/sched: Restrict conditions for adding duplicating netems to qdisc tree" (Jamal Hadi Salim)
- ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (Rahul Chandelkar) [Orabug: 39754488] {CVE-2026-63984}
- ethtool: eeprom: add more safeties to EEPROM Netlink fallback (Jakub Kicinski) [Orabug: 39754491] {CVE-2026-63985}
- ethtool: eeprom: add missing ethnl_ops_begin() / _complete() during fallback (Jakub Kicinski)
- ethtool: strset: fix header attribute index in ethnl_req_get_phydev() (Jakub Kicinski)
- ethtool: pse-pd: fix missing ethnl_ops_complete() (Jakub Kicinski)
- ethtool: linkstate: fix unbalanced ethnl_ops_complete() on PHY lookup error (Jakub Kicinski)
- ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES (Jakub Kicinski) [Orabug: 39754495] {CVE-2026-63987}
- bonding: refuse to enslave CAN devices (Oliver Hartkopp) [Orabug: 39754501] {CVE-2026-63990}
- Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (Zhao Dongdong)
- ASoC: codecs: simple-mux: Fix enum control bounds check (Cássio Gabriel)
- tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (Eric Dumazet) [Orabug: 39754509] {CVE-2026-63992}
- vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() (Eric Dumazet) [Orabug: 39754512] {CVE-2026-63993}
- tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() (Eric Dumazet) [Orabug: 39754515] {CVE-2026-63994}
- cxl/test: Update mock dev array before calling platform_device_add() (Li Ming)
- ethtool: cmis: validate fw->size against start_cmd_payload_size (Jakub Kicinski)
- ethtool: cmis: validate start_cmd_payload_size from module (Jakub Kicinski) [Orabug: 39754518] {CVE-2026-63995}
- net: ethtool: Add support for writing firmware blocks using EPL payload (Danielle Ratson)
- net: ethtool: Add new parameters and a function to support EPL (Danielle Ratson)
- ethtool: cmis: fix u16-to-u8 truncation of msleep_pre_rpl (Jakub Kicinski)
- ethtool: cmis: require exact CDB reply length (Jakub Kicinski) [Orabug: 39754520] {CVE-2026-63996}
- ethtool: module: fix cleanup if socket used for flashing multiple devices (Jakub Kicinski)
- ethtool: module: check fw_flash_in_progress under rtnl_lock (Jakub Kicinski)
- ethtool: module: avoid leaking a netdev ref on module flash errors (Jakub Kicinski) [Orabug: 39754522] {CVE-2026-63997}
- ethtool: rss: fix hkey leak when indir_size is 0 (Jakub Kicinski)
- net: Avoid checksumming unreadable skb tail on trim (Björn Töpel)
- gpio: mxc: fix irq_high handling (Alexander Stein)
- accel/ivpu: prevent uninitialized data bug in debugfs (Dan Carpenter)
- net: hsr: fix potential OOB access in supervision frame handling (Luka Gejak) [Orabug: 39754529] {CVE-2026-64000}
- ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (Cássio Gabriel)
- ALSA: pcm: oss: Fix setup list UAF on proc write error (Cássio Gabriel)
- ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (Eric Dumazet) [Orabug: 39754535] {CVE-2026-64002}
- scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues (David Jeffery) [Orabug: 39754539] {CVE-2026-64003}
- net/iucv: fix locking in .getsockopt (Breno Leitao)
- net/smc: Do not re-initialize smc hashtables (Alexandra Winter)
- net: netlink: don't set nsid on local notifications (Ilya Maximets)
- net: netlink: fix sending unassigned nsid after assigned one (Ilya Maximets)
- vsock: keep poll shutdown state consistent (Ziyu Zhang)
- netfilter: ebtables: fix OOB read in compat_mtw_from_user (Florian Westphal) [Orabug: 39619328] {CVE-2026-52927}
- netfilter: xt_cpu: prefer raw_smp_processor_id (Florian Westphal)
- netfilter: synproxy: refresh tcphdr after skb_ensure_writable (Chris Mason) [Orabug: 39754552] {CVE-2026-64007}
- kunit: fix use-after-free in debugfs when using kunit.filter (Florian Schmaus)
- xfrm: Check for underflow in xfrm_state_mtu (David Ahern) [Orabug: 39754557] {CVE-2026-64009}
- nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (Lee Jones)
- nfc: llcp: Fix use-after-free in llcp_sock_release() (Lee Jones)
- arm64: debug: always unmask interrupts in el0_softstp() (Ada Couprie Diaz)
- arm64: debug: remove debug exception registration infrastructure (Ada Couprie Diaz)
- arm64: debug: split bkpt32 exception entry (Ada Couprie Diaz)
- arm64: debug: split brk64 exception entry (Ada Couprie Diaz)
- arm64: debug: split hardware watchpoint exception entry (Ada Couprie Diaz)
- arm64: debug: split single stepping exception entry (Ada Couprie Diaz)
- arm64: debug: refactor reinstall_suspended_bps() (Ada Couprie Diaz)
- arm64: debug: split hardware breakpoint exception entry (Ada Couprie Diaz)
- arm64: entry: Add entry and exit functions for debug exceptions (Ada Couprie Diaz)
- arm64: debug: remove break/step handler registration infrastructure (Ada Couprie Diaz)
- arm64: debug: call step handlers statically (Ada Couprie Diaz)
- arm64: debug: call software breakpoint handlers statically (Ada Couprie Diaz)
- arm64: refactor aarch32_break_handler() (Ada Couprie Diaz)
- arm64: debug: clean up single_step_handler logic (Ada Couprie Diaz)
- arm64: Introduce esr_is_ubsan_brk() (Mostafa Saleh)
- net: cpsw_new: Fix potential unregister of netdev that has not been registered yet (Kevin Hao)
- net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Victor Nogueira) [Orabug: 39754569] {CVE-2026-64012}
- net: mctp: ensure our nlmsg responses are initialised (Jeremy Kerr) [Orabug: 39451860] {CVE-2026-45930}
- drm/v3d: Release indirect CSD GEM reference on CPU job free (Maíra Canal)
- drm/v3d: Fix use-after-free of CPU job query arrays on error path (Maíra Canal)
- Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (Greg Kroah-Hartman) [Orabug: 39754574] {CVE-2026-64014}
- uek-rpm/config-x86_64-onos: Enable Nexthop SONiC config options (Dara Stotland) [Orabug: 39583981]
- hwmon:(pmbus/xdpe1a2g7b) Add support for xdpe1a2g5b/7b controllers (Ashish Yadav) [Orabug: 39583981]
- hwmon: (pmbus/core) Add support for NVIDIA nvidia195mv mode (Ashish Yadav) [Orabug: 39583981]
- hwmon: (pmbus/adm1266) add rtc debugfs entry (Abdurrahman Hussain) [Orabug: 39583981]
- hwmon: (pmbus/adm1266) add powerup_counter debugfs entry (Abdurrahman Hussain) [Orabug: 39583981]
- hwmon: (pmbus/adm1266) add clear_blackbox debugfs entry (Abdurrahman Hussain) [Orabug: 39583981]
- hwmon: (pmbus/adm1266) add firmware_revision debugfs entry (Abdurrahman Hussain) [Orabug: 39583981]
- hwmon: (pmbus/adm1266) serialize GPIO PMBus accesses with pmbus_lock (Abdurrahman Hussain) [Orabug: 39583981]
- hwmon: (pmbus/adm1266) serialize NVMEM blackbox read with pmbus_lock (Abdurrahman Hussain) [Orabug: 39583981]
- hwmon: (pmbus/adm1266) serialize sequencer_state debugfs read with pmbus_lock (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: don't clobber msg->len to signal block-read completion (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: defer RX_FULL until all trailing bytes are in FIFO (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: preserve PEC byte length in SMBus block read setup (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: skip input clock setup on non-OF systems (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: use numbered adapter registration (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: cosmetic: use resource format specifier in debug log (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: cosmetic cleanup (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: switch to generic device property accessors (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: remove duplicate error message (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: xiic: switch to devres managed APIs (Abdurrahman Hussain) [Orabug: 39583981]
- i2c: i2c-xiic: Replace dev_err() with dev_err_probe() in probe function (Enrico Zanda) [Orabug: 39583981]
- i2c: xiic: Add atomic transfer support (Manikanta Guntupalli) [Orabug: 39583981]
- i2c: xiic: Relocate xiic_i2c_runtime_suspend and xiic_i2c_runtime_resume to facilitate atomic mode (Manikanta Guntupalli) [Orabug: 39583981]
- serial: 8250_fintek: Add support for F81214E (Ravi Rama) [Orabug: 39583981]
- spi: xilinx: use device property accessors. (Abdurrahman Hussain) [Orabug: 39583981]
- spi: xilinx: make irq optional (Abdurrahman Hussain) [Orabug: 39583981]
- spi: dt-bindings: xilinx: make interrupts optional (Abdurrahman Hussain) [Orabug: 39583981]
- x86/CPU/AMD: Ignore invalid reset reason value (Yazen Ghannam) [Orabug: 39583981]
- x86/CPU/AMD: Print the reason for the last reset (Yazen Ghannam) [Orabug: 39583981]
- xfs: resample the data fork mapping after cycling ILOCK (Darrick J. Wong) [Orabug: 39776790,39812085] {CVE-2026-64600}
- arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (Mark Rutland) [Orabug: 39779060] {CVE-2025-10263,CVE-2026-53354}
- arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU (Will Deacon) [Orabug: 39779060] {CVE-2025-10263,CVE-2026-53354}
- arm64: errata: Mitigate TLBI errata on NVIDIA Olympus CPU (Shanker Donthineni) [Orabug: 39779060] {CVE-2025-10263,CVE-2026-53354}
- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39674326,39779060] {CVE-2025-10263,CVE-2026-53354}
- Revert "arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC" (Saeed Mirzamohammadi) [Orabug: 39779060]
- Revert "arm64: errata: Mitigate TLBI errata on various Arm CPUs" (Saeed Mirzamohammadi) [Orabug: 39779060]
- rds: ib: move gc_count reset before free_percpu (Manjunath Patil) [Orabug: 39818507]
- rds: fix lfstack_pop_all sequence reset (Manjunath Patil) [Orabug: 39818507]

[6.12.0-206.92.1]
- rds: Prevent kernel-infoleak in rds_notify_queue_get() (Peilin Ye) [Orabug: 39772649]
- rds: do not leak kernel memory to user land (Eric Dumazet) [Orabug: 39772649]
- net: lan743x: permit VLAN-tagged packets up to configured MTU (David Thompson) [Orabug: 39765744]
- net: lan743x: avoid netdev-based logging before netdev registration (David Thompson) [Orabug: 39765744]
- Revert "arm64: acpi: Enable ACPI CCEL support" (Will Deacon) [Orabug: 39760492]
- virtio_pci: fix vq info pointer lookup via wrong index (Ammar Faizi) [Orabug: 39751599,39786359] {CVE-2026-64457}
- iommu/arm-smmu-v3: Fix section mismatch warning: httu_quirk (Dave Kleikamp) [Orabug: 39738971]
- IB/rxe: unlink pd before free it (Wengang Wang) [Orabug: 39674346]
- IB/uverbs: enhance authorization checks for ib_uverbs_share_pd() (Wengang Wang) [Orabug: 39674346]
- net/rds: zero per-item info buffer before handing it to visitors (Michael Bommarito) [Orabug: 39621714,39638196] {CVE-2026-52995}
- uek: kabi: update x86_64/aarch64 kABI files for new symbols (Saeed Mirzamohammadi) [Orabug: 39621432]
- net/rds: Don't drop the ball when RDS_MSG_CANCELED is encountered (Gerd Rausch) [Orabug: 39563153]
- PCI: Always lift 2.5GT/s restriction in PCIe failed link retraining (Maciej W. Rozycki) [Orabug: 38120425]
- mstflint_access: Update driver code to v4.36.0-1 from Github (Mark Haywood) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.35.0-1 from Github (Mark Haywood) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.34.0-1 from Github (Itay Avraham) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.33.0-1 from Github (Itay Avraham) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.32.0-1 from Github (Tzafrir Cohen) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.31.0-1 from Github (Mark Haywood) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.28.0-1 from Github (Itay Avraham) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.26.0-1 from Github (Markus Theil) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.25.0-1 from Github (Mark Haywood) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.24.0-1 from Github (Chris Moore) [Orabug: 38074277]
- mstflint_access: Update driver code to v4.21.0-1 from Github (Mark Haywood) [Orabug: 38074277]

[6.12.0-205.92.4]
- f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() (Yongpeng Yang)
- ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (Ji'An Zhou) [Orabug: 39637848] {CVE-2026-53242}
- MIPS: smp: report dying CPU to RCU in stop_this_cpu() (Jonas Jelonek)
- LoongArch: Report dying CPU to RCU in stop_this_cpu() (Huacai Chen)
- Revert "net: bonding: fix use-after-free in bond_xmit_broadcast()" (Kevin Berry)
- block: fix handling of dead zone write plugs (Damien Le Moal)
- Bluetooth: MGMT: Fix backward compatibility with userspace (Luiz Augusto von Dentz)
- Revert "PCI: qcom: Advertise Hotplug Slot Capability with no Command Completion support" (Sasha Levin)
- apparmor: fix use-after-free in rawdata dedup loop (Ruslan Valiyev)
- mmc: dw_mmc-rockchip: Add missing private data for very old controllers (Heiko Stuebner) [Orabug: 39637850] {CVE-2026-53152}
- sctp: disable BH before calling udp_tunnel_xmit_skb() (Xin Long) [Orabug: 39621968] {CVE-2026-53070}
- net: ipv6: Make udp_tunnel6_xmit_skb() void (Petr Machata)
- dm cache policy smq: check allocation under invalidate lock (Guangshuo Li) [Orabug: 39637853] {CVE-2026-53265}
- locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (Davidlohr Bueso) [Orabug: 39637851] {CVE-2026-53163}
- locking/mutex: Remove wakeups from under mutex::wait_lock (Peter Zijlstra)
- ksmbd: fix out-of-bounds read in smb_check_perm_dacl() (Hem Parekh)
- ipv4: account for fraggap on the paged allocation path (Wongi Lee) [Orabug: 39738617,39743884] {CVE-2026-53366}
- inet: add indirect call wrapper for getfrag() calls (Eric Dumazet) [Orabug: 39738617]
- net/mlx5: Add vhca_id_type support to IPsec alias creation (Patrisious Haddad) [Orabug: 39653091]
- net/mlx5: Add vhca_id_type bit to alias context (Patrisious Haddad) [Orabug: 39653091]
- scripts/sorttable: Fix endianness handling in build-time mcount sort (Vasily Gorbik) [Orabug: 39489132]
- scripts/sorttable: Allow matches to functions before function entry (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Use normal sort if theres no relocs in the mcount section (Steven Rostedt) [Orabug: 39489132]
- ftrace: Check against is_kernel_text() instead of kaslr_offset() (Steven Rostedt) [Orabug: 39489132]
- ftrace: Test mcount_loc addr before calling ftrace_call_addr() (Steven Rostedt) [Orabug: 39489132]
- ftrace: Do not over-allocate ftrace memory (Guenter Roeck) [Orabug: 39489132,39751008] {CVE-2026-23052}
- ftrace: Have ftrace pages output reflect freed pages (Steven Rostedt) [Orabug: 39489132]
- ftrace: Update the mcount_loc check of skipped entries (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Zero out weak functions in mcount_loc table (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Always use an array for the mcount_loc sorting (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Have mcount rela sort use direct values (Steven Rostedt) [Orabug: 39489132]
- arm64: scripts/sorttable: Implement sorting mcount_loc at boot for arm64 (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Use a structure of function pointers for elf helpers (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Get start/stop_mcount_loc from ELF file directly (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Move code from sorttable.h into sorttable.c (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Use uint64_t for mcount sorting (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Add helper functions for Elf_Sym (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Add helper functions for Elf_Shdr (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Add helper functions for Elf_Ehdr (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Convert Elf_Sym MACRO over to a union (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Replace Elf_Shdr Macro with a union (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Convert Elf_Ehdr to union (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Make compare_extable() into two functions (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Have the ORC code use the _r() functions to read (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Remove unneeded Elf_Rel (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Remove unused write functions (Steven Rostedt) [Orabug: 39489132]
- scripts/sorttable: Remove unused macro defines (Steven Rostedt) [Orabug: 39489132]
- xfrm: hold dev ref until after transport_finish NF_HOOK (Qi Tang) [Orabug: 39262397,39727259] {CVE-2026-31663}
- xfrm: hold device only for the asynchronous decryption (Jianbo Liu) [Orabug: 39262397] {CVE-2026-31663}
- KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (Hyunwoo Kim) [Orabug: 39531622,39727258] {CVE-2026-46316}
- fs/binfmt_elf: validate reserved VA ELF notes (Jianfeng Wang) [Orabug: 39681042]
- mm: enforce resource limits for reserved VA mappings (Jianfeng Wang) [Orabug: 39681042]
- ipv6: account for fraggap on the paged allocation path (Wongi Lee) [Orabug: 39686467,39727239] {CVE-2026-53362}
- xen/ovmapi: terminate values passed to xenbus_write (Joe Jin) [Orabug: 39726311]
- xen/ovmapi: free queued events on release (Joe Jin) [Orabug: 39726311]
- xen/ovmapi: prevent duplicate app registration (Joe Jin) [Orabug: 39726311]
- xen/ovmapi: avoid raw user pointer access in get_next_event (Joe Jin) [Orabug: 39726311]
- xen/ovmapi: reject oversized posted event payloads (Joe Jin) [Orabug: 39726311]




More information about the El-errata mailing list